pki-ca-10.5.18-17.el7_9>t  DH`pai$ƨ "dVCJsʿNʝ7!o{UA{pYʭ ڀ7|{7^vdDąf!^묓bM Yޔ+<"@Y],±26K?[Eaa7QTؑ3e#;{ ~ycBQV+ j[&fgmq6l=*ku9u:pE Jʐ Z}wq)EPhDcpnc}xgVsro6%E7eIH Z'jU[:~֙PF*?%%Ҳh'ᏨdKWG(%DzjWq:Bh?nD:s/Aebȃ^n%HJ:ޒ^SH ot%VgOEmglnjuY5X1$-26a8687f0fb784ab15a35e0156a820b6848287e9ai$ƨgԝr Q!L) \]IU~iv;hu cPxapظ2&2wy2!+.ȤvBbH#7{v"BZCq܄\-.MRtU(;}P8U_P\:qt]0'oWG°wI|S1gbAP=۷DW/[ِ֧C9!ˆߢy,2y.O6K`aIL,zg+OpI,"RM&偛^6bBU2K7ܰ?ܠd   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9:G8iHiIiXY\i]i^bdĨeĭfİlIJtiuliv wTixiܜCpki-ca10.5.1817.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.ah#x86-02.bsys.centos.org%'CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤ah#^2ah#ah#ah#ah#rah#ah#^2^2^2^2ah#p^2^2ah#pah#p^2^2^2^2^2^2^2^2^2^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#ah#^2^2^2^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#pah#p^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2ah#pah#pah#p^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#p^2^2^2ah#^2ah#ah#ah#^2^2ah#^2^2^2ah#ah#ah#ah#ah#ah#ah#ah#ah#^2^2ah#^2ah#^2^2^2^2^2^2^2ah#^2^2ah#^2^2^2^2^2^2^2ah#^2^2^2^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#p^2^2^2^2^2ah#^2^2^2^2^2^2^2ah#^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ah#^2^2^2^2ah#^2^2^2^2^2^2^2ah#p^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e9cbfdc3566c0952afd82435b45a9aea630dda80013e074896353f9552f4b0c018cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-17.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-17.el7_93.0.4-14.6.0-14.0-15.2-14.11.3aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-17.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(1"ks"9Xo&ۏ_|cJ_.&08T/ͽD 9p 'Nd'}NzE#/SRpx~\tsji{?(=5$6 uy7TX^{}Vz=O分~ZI4u}6@ Or Ô{3`ĴEFhCa2bvp@ܐϚ0|菮~S8% s&3^q-^2zESp#HPAVqR㚑 )(ut1-# (kO(TEjcP8A䫑pG-95{X/__Yd9O @bX6 XC<ۺ0D+M# ~<LD:S>BX{ݝ(ypN\⇼/ 7k)X> y jϘkx;!DR3oXFOMN)_67.ξjTXoS'[2< 6dd/,TF9 vߧ(ӑ_! ں#/0 60K"XPpظj?;צ/} ++Y2.0Sn /<7Es@s^XiK50nuED+$.r6S;8,-:p 'hvq G2o&x}x4hG{^.aO Î\[YT-(\3Ӣ?To7!{a |g|c|@*AV`mwp*Vm{qk^kHL =›%D%6 F?w{kF(/|H\ի:<<~$g_&Q Ybx/̽j0z?cO\mI_WQG3Me27>0oQAք +zUpk{%2bC1)Iէ 7y"tVL4=y5=+NѸ /(H+:MݢmکjHƴ;&E^nJ8=b;X:'#0_Y4Q ú(V 8 miLv9btayObgJMUp\X*G~ e*n>vJZ_C_;[6rE7rL:-dibS=lwe, 3UZzu<ѫxXW0LV}tK˪)u7RdwE>\EwX_6Mb]7 W7͇r1 7\YÆЎ} JNvO/VwSR6鶳5΁=ҽ1E=_j,m~$nT.E!DpyxXAKcxKqg`.3E` E"zs;\rgVB^` Qa%b{GPg4׋r?蓢6Wdz#5f !,Y.-\tٯiyVdEZeLԥ S)>lD?wY\HG;}V۰'n;cg~Ĩ&ϪYlD 4tkPKjkȲgIcZdqXڦ3"?{k)ň}V՝lO|CmF2>j5xٴ'H 푴FJo gf= Ask;d3tYUVWٝk*k} 2A)2y~ˌWx3mʵچMsNxɴ0wB"]R.~uv>~b =S&i4U{.ބvAٓ0c޴aVJN)xOIU1|)Í-sƮWvQҘ금:g-$Ӻ MMmdZ5wr4014[0Tl?AcruRk'~W/2üse%{Ǚ v[hw짽K}!%<,6l~ 9]Ju9To0Z'z'I ;"r9OLz()I:~y p0.ډҏQV}{d^I̓ FhY*Px\9Da2جt\D*6H)rr |oLޠM")_[A'Yj*~O]c+<f8SAłI So7Z0;Pnǎ\5jᜤn!zUxa( ;#uUBV28ޥ`B@QEax56F% MޜBd+bkui+|};Ę[X6 G1AAyJM?>×$2pi.=GqьsX!(!MH՟N_p@#y6/A2Ԟw4i&g 5d^\i pixEW;sFy-ғ8+nׯ4Rrx~f8൴o)TX4Jn>sw+vԉBFۭjpؼ)$*w{O*uºהءfxf;&fo'{Pd<>,J7(NnB2H%r*uӯqaX;yrӾDPR3:o4L.otDhb%]qKIR gzcwr7O/ ˛B#>yȡ8ܶd!Zd=,ifoW3{uk)[ l x> ]OOrSm.fI4+^\0"I2C&fGKӹ TpaJ]eh!1$cӭvp;?($F.xLah#-E0YOZNn2ȼ>Yd[l4iO\(lv#KV9G"2 a HhZz:M*`;״ka;Y&7c5~´gf}8\ӝJt6lHnOq`UToCʽ'_5FGa:$Q7tM0_4mbo ź?KK)mg]nnTNxb;%^6w2j F 7Yu&qFUwYxM>A&d5snmYlАAT5^:k&LX-i:㲵~ :Y֔td;ȍ/t)Uoi9lf[ 6)4@ uqk13,98D{vZ)GfJ/oRiIٶRk}KH_"zm_D?>)fEȖ=,| ځdƀ_G%o.tT3mٱeKiĤ>EAi5WSRKK쌕Y6~^'R_ , gB*tUK<4o<ܑi0U$reTDfgm=g3Et=[uK?U-. e H^#hW肋¢L!4.3)OR! GˋŖEL @X3C %!\zoOӱ*Gyte2|~MkxB˫lPO{qŕ ؞s*==샰)R5LrjڱGġxU1(bo;x*Ud# LX\Z&S%k΂lR?f7{T݃q*]X^V,Im?` tV2\99 j?ۦiBot.FwQᩊWX1F? /܎WĘ=y41?S`*4u97`dN1I I3f2젢*;.S < Ƶ 3TF9͆p]#bhT&術AXsX~rO&XSh&.p]ӦKJOeN]_m Scq/+NZ^89Dd@7vv%+R dԥ߇lPQWu`LgVulߥK椏O?@qIHqv30(,rY>Dg4ʲʴK<ٺeRGtw4+g]Jz"ڗ!!OKh$l2@`v@Yml+2Fm-5VMmN{8>aVa>(B<@7Z&(l蓮f2^lJ +m׼d/׆P,J~D @8v]W,(PҴǖ{OY4/:?ԁwͥ޺)/0kNuܦPl=y`J(io2$}Gg\c͜Hj4W]:7Q، 51$KBq߱i1ol:RE1^+ѢeJיtz ,_UtP?(`]ioɣ71Jh9Dmku 򪯢wckWŢ]}G,c4m-]P8p.@u\HdwWkwƾsE0k2ռ6 0=UC,M3Pu&5hϑ"O/b.9,k1kK S0rj]%1}8'Jp5Β7ޯ")MU:Q#5yyT=攷L۪B͔X={.z;k񠟴+׃+$b4(: mQA=mB&~+w4U_ txʞ+*^CKCV4J~*'w߭~М}w\nY[o6#exOvwGG0uWs^uK8^YWkInenz' ̧nzloB,N핥Ko]v1e#ѯsYe)ꑃq,Qkv ݯ 4d DRe ɰ}*x[eN=:$`=iuu^r>XąRС8rqv ֢&1d![$4N j*wYqӛ׺-KhU ]BSΕ\wVÐ_ 2 hMfϽU D"G3@LmN+C,Q*т kp$9Zծ ?4ʛPߒeY^dr[-Y,)A:9IY2b;v ̓0qd#@>Zz%(g=xC?Neiay+Z,r*mv\#K"":&l]ƙr3%`$)nA5CG>2"8VkZGGVWojL@&5TzUP mW׭tOHDueacpU[h-vdg2VEHlӦZrwɽ<_gs _8[i\إhQ~)O$7ѶKiQ(^8h}X zY͸T޸%L %gީ;9;(v x䑳>V̗_苁JڟЋ0R\FFiXK8Ah_#JJZ"/to!LI QjpܺKQߚ=O.+^$ǹSsg7ϙbMnh1g!{_tJBⷫ6_0q3%&fh(׽_G\ r$AZv6c$$rrpКb&iM@Ӕ7=v +\{~-}M)aI`+LNYIe"Ẅ́5~򽥏P,[1`٥"H=.c.^ltv͆"vv9 FKj<-Ӽ+$8ji>:*- S(fPBqê6\&!zy'@;> !5¢] $R0$](%tjrGS' e8Ӱ"&pAt. ;5NZ g3O@C|] 6XX,0[4N?VSXHU{C!9il7Mt4SoښcƿVzB53y4"p#Y(\ #8IKZz$8|A~qd_yr@. S#O$`X"f$5F^D #x&|:}&t|>i>f_$Vk D0Ɛ*3 E#, Ҋ8lky QZ-:h$MBRFaZ b|Sɀv g>Lw8ئ!$k56(VvZٿDy*0%bj C`J"i WqR_2G_;4-Wi?y[%#QbOoe.蒋DFF;W ;Sr+?;8/PYYY( 5~zɐ/*`wO;"SwMxQOׂ%8kزk7c+ e{! 7]!ՁyD1 ';e@/ bֿL̾Dw&}S8!fd{>cFA\0!켿g!Ko>/,}~xg$BO?MO*ܵtt"hT&s[t!3ŏ5E+`S'uUKHE8<_ْllo `G-+3v Ľ_V 6} ^ajjEz$;edq'(47CӉLD}|W-0%mᮚ}pKל 3g Y>I5$W-څ3S&8lEߎK6m0)ZW(UK`ݑx~OX&W9 $6 3D74.ʙfavvvz}- M&5aN隸C 9zXz7ِ^NQNYTJ>3==2҇D\$AV74硠@XZi]7/"~,T*TۆtMI?z'49kE n0rxIWHo@pYHd)[hg5xP^3DJe[VǓG # VZH>lZfH.Ij'^| 08.ރjOm xnNNr']o C9\9Y}r~J4@Mnh1,gԦI-fלХ`s CGhdBSux#@B8G  qLcH^|GO]9LnxT%Z`ֆ;92ej6rE}ɞ2'aRYć /;!(3 DN#qARq$dP:~2K\-o72nh/LGCSF=}!vs< ^gt8=Th vx9\zFے>ߩ!8%ۧJ @8D#8 [ r66PUk0K/ ԺE%@@۹ uI 5x7n bhCڧ>IG/ȱe'*(,k7hR) ֆ'L>J)*p3}V&cK*3:^/ªQώ\TogݫI5-ipy"cKMu;\4Z a\ /#L4-3ciTDzgKBYVa$*G𣹌AG {̹?BIf  Swe?-DO+^#/ џXJ#[3R2dgRkIνB6N節kZkPIS>&u= Z3򚴂I,cWtύ[iy8yh^ґTRW (rz*)J3_F{W rVBg˚`Ce0 zlЖ$l |4Q1'G 2! r\؍ ގq5e.m@`kmƆh: К7u~ n3 Od &=<9D?mCwZ4Os\Ipn_x29@3C1S Miת1yyT/#Ǽy4}}wJe'b}Żrxm! R;SM`.M}F % a4t-&}fa7NGl\mo)?bցgId $݌䴛Ԙbﲅ-P5 vI\Q jKG_ J ʧj~Q~+qfUlΌ8 {-ZԺ.T; o\X6Rk'$HXwrTlle/ptJ&qi)hkb+A_l6<!p"d Oo}[w4 |OcґX).bѐ#;:1H@*g gB_0Xuu7G̝a֍[X5"dDì$v#&Cߵ7aCr.CX[ -}{URE:S yPLp1wNWgO`9IvxoK2d@Ȱ@gR1xaa#J? xQhBgVdV[Ἢ ӵDZK~XDϖK8ˬ?fC͛pM<'+VF&g5Zp7t_hk3%}Nl7!*pD/-TۄPݥBfJnNGf` 'Z_CegKg-V}j1?prL7&Tƫqv\pgfᑭQл 9 Onl; \e,aHW0!h.ݛE!l~c;?kیS~ h~- 'MA9dN {Oe=۔`: iɌ Orlҗ2;y,;fR`(dW;8^t>{9f$zy%*<׃heײI4.&s*г?5(:bǐY|qvax>HUl}p|?ܠ+psf}j۹ դ|BH@C=Y$[6S]'$ mWۖЧSoVz]]kIE*F7 +Ys3b`}+ueޔr+x-^]M4,0b&0 :Έݽ-ғ%<#m.T$Y3SoܩBww_ȧ'".=W-yᔡ=:Te\O:nnGIg$"!7zZ4} F<[r VT|@])/ KD?PeΑțaǏR} P6Sp?JHۙuPeN2gC|Kq 6%I_A9h DA|?‚"lX}5fZjgOOg?ڿ&*k{M9MyYM$?& 64 W~;PfԂQfuvkm,P$z=9I5?ŧLiNaݏ `Sm]~W>-M_M>h1~mٔx[V׿Ŀ-K+G dH i"(4bT%OlL52cgBۉ>w!rš7̢ LM6eX\/},3koFq;nSv֞W 1;xFA~0EU%YOI,:z/Ry=(?Қ؃u=z%os]ٳ@Rf GwY̆{țV8/,]U|0p|A)6W{eVQ{ڶ(I $bA`rc7/跏ʼ~A8dЈr}..tsS ^&9~SqN㿖lMK\R܂ۏѡgf+„~Rz\<ٖל׀eA,"vd=;JU)ԉ2m")ibhǙwS}5&$6ihA%FTTyLb, 8 ~%/|z_&ȍ1Rqf~oI-TTӽ )_yENR+έfU'V +O ]24x\}ylRU;<NBX(=OBs$00LwGg_ǙkE@v'M͉67"wĚ_)\ cF߁knmLMZ*^7>?6w 3H]jR_oa`+XXN'Hb[= ;UNQ,&Di/%pN_M'A]H9Ś?),rwq + .!Ǵ־ዎcZO1qH o"4Ua,m-x. VYBRlt >`؊%W\3Z|[кNmpOTVwpbaU}XOU- YeUI Mx}Xt5Rs-]/o'ɨi,;C4NY%X'aƦV橌g~AOxmBۚ"QM3 >D)~r>Ee)^56Ǵ1W%δkb$9+1 Y+krnczY%X=O>Ԧ@b|+jŮ/kN`22%F}#xő<a29{nwжD )yXE@o3* _o"f ŷDJO`D{ szLGH>bu\mGo؋#߅O75~ hڷw{)sR%4|,#)+p](EW$?o居?v nhչCTogfmG%z&uLчԛ+~3m=poFBO?ݜOǃTfL. 2cx=[9?y׃ƙKbg䦻D_@y:m框e/M' 44Z̸5wLYeb R@u$gwMHɚR6m#Q8U yW| '= @t,YһRpy˴&TZ% ET9_ڿ]*D^Uj) 8 L 5K,-e R/m`K*hꀼ~P@aVBϭB?ݨ\&yEc_Р*ym@([-uyo(Nd6PYoV`=|+ڱD!^lNnБZ&wu ;n҃$L`p 2."C$.vwD Jm"IecgS~%YR%5<BuK"E^ H؜;]Ԥo ?rdH  }"(HăQc$gQƓFU':2pBT \" "'I#O/߂c!eH2 ici&Gxy9W>Q':h6ML5}< f!<B~9Zq M\^(vj쳌1ɆuT#v տݰ^P;IׇEWv0&8jOR\huF97Y`o (chwJ)Zdk/d0r[kɱ e<Ѯ:F nqb #4QŐ;;A'@XŅ3b@?O Riࣶć1Ոs#{ץang5Sl( _;%(Y[NSSh}(% F -(ʡL *87&heEu[@WwUqyVmV{eJ"c0r\iLR4aI5(OoZk|Gbt "oOD 3p!0i/Rx]{Lvj‚zi>@v8V^4-nePPg`cVSBIQf-K`A%hNBYY7rxq,]r*7z C7k3YAjftmglKf5ꂹM]7˫kLu`NE \3+Wן(䐰`,M˵jCy܍Nl"f9қ?7s|w $޷)9|c@{$LUЋ{ hD( YH6ZQ ECĎ u=vxm8"WY1#u!qhH Ql컠k7xpD2=k)IQ夡&)Y¼J\XD"d@@ƌH AS/ ׸P"nFgONodL{*[!ڱHf#62Z>ٖ8bRq6: "CP5 E2#`H `Hrh֖23Z #sy52a|AfFDɂ51$;!Z[RA?՗X0:OX0fbFh]ճ'h 0Ųț8I8"՛݊@2T%~14GUA)v@tP/iꚦ_42q&B:I٩ '㢙S;Ъfc @ź }OclD/9-ng4D2#05c2P3-.[3djq@uƼ&N$Z2|m^kR~,8J@%3΢"66l]c8hiW+mn` '˒pgMwx)mR͔9[֞&(1v CCpSnxntɧCգqxCtUey")kQULʍ=5' \ZuS'nAO>1뇕^7QC=Px3jQ6 UНPaT myf>fuaҒYvD2 Q(c=ڄZ* _)MREcнªK!4b]*ލ_G^O8Fe=vm6.Qʡooa̢#3͊)Uخ 8Zr k}su۱v킜$/*]2`]%Y侩:3Hu 2? /Fm۰|$eYÓyz`,eP>yI \U Pf`N%)/)vsb3bÖnbT1)Bqa(<[i*= l%6Tn-4F@K\i̢LÒ O!62@xTɍ(,iDFMŢÖɈnnPihqӋ&_/H;iM\| t3Fvs{ҟiSF&8gq`&l+tuӊa]|Q~-5瞓Đɑe|ffpCg>txRd;X>z]g8:=mzZ7.B/,!<\~[^mFtڄne5{:Ue`}KMj*O!IGزے@P: S:6d@<^-6cMm۠G*= lh\j˳DT. 7YZ#L)/z5bXOLyH@”ۼmQKQ>@Zp"q{!noLm!8k"̗p޴Vkhnh5D+Pt)ψmUOS&\fޢ]L'ͮeF4?eueը~ `-TH ղ-.IF&量5"g2DpB*;D~3qld+wQltߋ6 :NA_VVdxbu8|ֻ' 0w[YjV7j|<&=muK09mcy nOxbJؗALj]n0 'ن '*@Q7NiIbQzD`W{5'ג~SpAH  ~'P+8؜ ->o钧%-F|sSCLu06O1ԏv 4Z\_i+>jT< ᝛iWY׽p筸1׿r7W Q/v9ǖ_w=z |B= e̙{"7tfjk9?,- әd-e'Ӌ@C@-~S> g1pzh(,2Frdq>yU$+fugD&*u &*k$ReW|q>(QV/_^@w&\6swnI^!Tg𻟒ݣWCz)H^?7lSP/LҔ2 6TRS$h 4C4 -z#cߗ)'j9C5GݎO{GSSCΚ6-YqA3簽\ma'w0-*3Cv.{g~)O~|P45&u M%3s#]y+kG 9{>? \ C#͙dv:NOpL<0a"7WʟI: uT/\8Hw7k[}`0&NsX%sMJp(F"3/PnM6=>Vw})V] z̋U+*i 8*cQ}oЂu dTtab7DXHOMcAwm_H>GdAT. ˋǼ0b!1Pr||N,h}! ,U2nTNI1`3,IDeb "C%*)i_ !u^ _q8T_/'$Q(<^ߖ 0ef%-\U.q1uv;܋Vݜ9Tׄ{${$S/t= zgYWg)ؠ{W*) r5GrB+A㤁>2w"pfiCU .5K.`ZaK2P:N!(ݺOE'MgݝF{)bSr"FOP7D3-=%pP5Xzq2w:ɵ'/V-vPWdzבFAuR{9%Zk}n׀JOa8$R>vnfʠMn?[4D[ڲHTXX@1P?YxWa&Y۶|cD_a)7k(C-.,)c4c |#p9'!0gdTGg6nRx8UGH|3Edw5inGFM,1}ݑ#C  C[cLH㧇? _Kc8fzXvbjRم{dcZuE ļ Us/շJs]qƬ1)8?9۩e[Y Lccf`u"1@؜0- `2&cs8x y1~;ծzv*HG$FWңW@1]{Ht7jZ&[Sk:^ZTuv]y5 9ƘkG?'/8ArbC.d06(4[(ws!ڬRpx~c" 'W yӈ[ՑriVQr6 1zΕcYø)MB9Ngf[ː5=rҲ8C]&ebo&fI5Db5I$0Xb/^&1n7FJ.ATmg9\MS\٥nr0 C;^g"ynNPv80|F(@"P_s`'; %L+dXNme]- :{cY!E+"$k =AX3b&Ce挊S9h4Uy)M5}Ζd25`?IOvp>?yC*Gql A6Ee*bݛ Z˒ܱ2|SD4:Kb4x&Yn 8SlEs LH<һYEod}:Honvٷ(af-#mM4|ϝ?ܰUI_VvZ9ի}SEr8+niorkjr\֠E%B!˥) ]t$/xF/,1JaHNmIw4D'`@3޿`IG@P-oXKdO=Er!/Gx足OKz=1iNk0$zXlQW#<%KcA$ di3Տ4bK3]Z ɳ @_Ꮚns61*WQK(n7I<*^V- 07 I{[a?E,zjMXAF{u9l-@x ; 롖V#*gnٌ3OW?ܣ{ Nku"" /'teigekl?C-#\|9 BFFvă#p r,8oZJdnJѯRnkm/!QA)rSa/g>@<1+H iևZc/$'+f(8=Z^,KMY@$s:QfIN죳!Bb9xD e?4#@Up9Etdo`$ϸɻsBq=2zٚGmkdEjeG/ޠJnE9g5*=K*{ tGUc)$= H;m[SN"үYUT~FŹ&2 􌠛}!.>Ŝʾj%'ሉ I}J44rRZY'rf,l!tFޅ0$Q1Ёۢ-Ttԛ]Xu,fFGmqɗS^,2i5N0R$|lK;Ƈ{,ZIƹJ RH_7zSI>L ;}wuRE!Ц:e9抓("^wp;'թfA^C~^#Q4'G:LC4ʞqj+T$qz sF3FA;[;7lWEF5SA[dd],Be:Q" _,o;uh#r;1=?~˼i5ĖLrWg‚2eWR3 EukL=&S2hcl 54gB︗|1 ;.8h wxhI뾅nj`m.~H2#A Ը$&F")(J'A w'.ݽq-?6ؕ^:St^!M&g~eA$D}x/>R:)`/;tJ_##~`wtP^ iQc*dKnj.{ORZ21Nfi  W_@*D\c`|%u4ұRtJ}N+P\MHsmf[E%K6[.9c ۮՙ#$p u ]V+%)Szt MfY kXhˊݵ'Z>VіofsDWG2uCjvGZs!BWqGn:vCW8!8ߘ1n;y2?("]G ,څ Q[]\ن2p q u'ŧeyN^LQ*qI8>/7Iw5R H;_{SdWʅ'BYs-{,b ՔaZ1$F6.ZkCa-bgRܽq cd.pKL[).<\v:) lp!".)Q}޳]s`Prfq|l]$\FbHǭn0V?_=롕+P?D] E_"MimQ{1)ORr(vNM $ޏ"Zsz)rJc[]~L]Ti\cOuT˃#4c08ۀ 4b xhe#ykbwJ0鈢<;3|an@btb[<$2 w{Cyxaz/Bgf.@]2FRʹvN91c=<MkΖRzjF9_jȢ;WRbEf!%0X(=.5^H@ͨX)jk=(¸BlPF ]ϋ,EI>eF{G]Sw!Wl (s /@%)n0 X}k)n 8݇5w%OTB2(W7++F0VڰP"5F5#h?)D&8ǰ= vPTfP:** &+t .6t(er{I?FAs^1IJ=MRjbX7n>ĉP1yWr(BMYʩPGg6rUlNDu!CYUۨ,J92+E+Ǜcsp#Pz? $qzmTddt07΢T\*Κ$@}8޺"VhA)L4czbUj{WW~#YMpM2y0iTmdS6=svw],f[ar2;ٱUȱ4 &Vrr6hB}6AxNlJSK)_N#哷H-}t4FnOiK>5y<ȝ]#t;5fAU# uhaՈ\FK)x^%xQ*'T㽈R˘%貑mi¦WErJt*`:0=1e:u9ݾڜt6$OR=un)JL')ϩs$8cL-{uZ@ 5vC?o9]J;׍L4b_Ta&e_+%5uḧ֯_d=b%6 ߑtnec)gtr k!60قLaî~wY\M)iD^u%V[)W>ͦQx-:JsdDCrn9@AO[x {Qgԇ,z.}IxdRBS帥%?i-&fșUxČQFzi]{#rS$O&$: mmP5GXyd+T9 .%p͋ҁUFw+w~b# h7,#ăM㨴gbJN=B4{~,$Ze-|H R82Sən~K;Xd>;;,^MOƵi&߶m$mK}dUMd=vO1 wϓ n3p] Ǹ3gly'b5+mzGl!(̐{ME5kۋ,~dzF8~kʙ4Tq?oKaD ]PϤM{25Ρ&.=q?rӂ>vRd瑖 ])Κ6[^Nn /l~ ̀2{ 3~pE=lKUVώNŘ7wEs*:b@DܢgiAD'cǡ3}v3R^@~؟DfKjpmB3)߂2g@zR=`] fؼ5C;wT ;g}zɳaR}[Ȋ=qf&ɖ=KnD,c` >2$-X[#<0ͺqH?o`=1}  ?_YCȓP7 qkM\i92*3}lC5om*cD c^n.o&\c)ܗfp洮x c,3glnrTU _R&ń% 5*neS 7-:SG*rWKR95}$# M Is6*,b{x4N-&GYGxb %]MXXUW7|p,Ui dHKA v)s _9mx} yFU3ҁa?ɇ *hN\ژo䫦 .lj|DM"BYdGb[CdXdRpzg]jY.VngM(* oZ܃sz +PoFs[ e@"q[S AvMɐd|McGQjx~i&.$d_+ {@-Sc{2u Pzl#EZݓ5°kv7SUցyӍPXxLbk+kj',_2k3TunSul 09WU0;=؁:MV?/$PqsO2w̢ J8H=R "n$f)"#/i7EC˩?Րﻰ^#;] x+UI/6.Dyʨ[9i7٨ uSt{^ 8gS_Nݳ4lG,wu (Q\Pޮ" 蛤 ]q|/ſ ({7|ȧZ\åI5!`CI?;kY3s& kNg Ae>X" 犜ӻv; x>o83>x`3Hqr=U/[IMb f 'WHF$Klqw?1FbgO~րdy9IgSc"^@-bt,MPơ[r}sؐodՂ &pn Y_pOj@J E4w.v:bClvf9C s%i[#k\(*DǧU/ >L3|? J9dŦ F*~Ku/5 ~4 W-[`~ =<.5%}~'V»+&4BRWW^_".s+Ń@W;qPn\"WOo vvNĵzԓLՖ2fCXw1aq:C)`ˣx3z׳b/Ci|DnxuIxggڇDA P1w`q̬ZB`2QǛcW#%06,KFn:`M]`Wv$Ll5lmONl%M>>ތ>'R982)um`iMǭCԌ ɣ}5, ?T`Y<ܨVVlh")Qaf>憗I'caJ?]_x$7< zO;^A[ %facĭ:AU+z ک2Y/=0n!E8l :5hG1r{7f2(OtYpL/X~FVCJqָ<܌Q'^;s2荾Q\cxR>^f5N+'c9# nfb(d+1Y2oJٛjoi_xG3y!RG;o{ǨBmTQ"ӟ/Gxx}[L"ѕh(\7Ǜ_eL#g&q(G:i՗.UmJV.qW2?EfEP`]Tˆ(TslB v-i=/.E!6GJW7*m,ɐ.VX!j8EU!AJ4aHfcJ'Gl Lܾ4Vܧ~.NZ{4yLca3ķyȝ+l>#0kGDWL?"/+4eIp¹ p,쌚hj#]`iDsͳ箏8lDB <g Ri`;{ɺBfɁbr2Q>|׃-ΘnDe?b_S<%{u8tݎh+=\/R:=IPK gj:CVY̋25կ 㵆%WJA%)]bYg!FL/pD팻+aY9UU"C -EF\y}2 syX|N"ղ9ʉLNQ{NG" u"mF \fR+3'J>Zm% V &c+v4)I X]>'9pn$5+y>>mA&`Z+uYx 5}&lxdYz|Mp-߫a/:4RGoRnV';dWר-Z8HXcmuINe ? 5;RСŐߪ[ 2BDc|e,v?qAu7JypK6"q rhX\3"x9<%]pg#٢W:eЂ^հ,\r/H:Z/RHg1KtvǥIdp7ȿd/w~ا|J(+8n_&KjD f!}_KԂRHÞ{ 3)I-RvZnnϽMq1M<7 ff-UɹkX'}h0$H_ , r KYVO)nJv8pT)N. YAkG% l or|E7Zn@-WTl,]QP m9ܬdv簕S%`+Cm>ty.:LBrʅ00k0,-N3ԉKݕm?@d0i2HR`+r'<~tp㌘w5Ml_RGS7'W9tm,nRۉ_7KXݠjBoW`0hzSTph*y(x̾L}{#sZG{+djcٿoE:8PLݯ1+Z"r.}A$TUk|%̲cK bVE|CCyi5f wwΞc%banPCxȅ9iyR>^ǐ~*Y7{fZmqz@[4, iyJAPs[2ܠpFG*c\1MvY.fh_JmNR+ T r,TB3?atmC:NCG:W xjLCBP}x {\U0l>"uwZ:,sJςc3>Cn*_x#Py蘲tCiFlˑ^~yzCZ@۾δ:_(e %5+)o* GMn?7>SIYE \[|wDlOQ w3/eV;TNCKw!ZltA /j'd-| @y;=$ocWm=!ErK;P*r:O;Pr'Ћm% Y-]TT`7Ѣ0gr/aFz7㚉%{U8[VҊ|Gf+n 0-Ee'?rCy_:J+NjCOݓ^dJ 6 OL76es<4X!Qjz3}vTqĐA2g.릫p cjzjZwU$u|HYxaak\]OFR~%(L gRAG`%'t3φ }U}8Dn*ITދ5we.5:RU{`gʈu7 eG6H3!] 6eb5o){odnUE" U!@ep}&)qq883>K7ýKTj)J=iXZ|e[̷ӛ 5|N;x:M\!']n!Q]lhY}tZ.'Jy܆-<.;2GWkV(n{0@W(ZWS*Pi. _bZX5`*\`Eƒ/`D4تԭl~eB":"|űQJY#kس7oR PIKeYA# 0XςU΂']RTHtʏҎǀ/*.1!Hz`.ϩEYs3yfD;D[lvɖM:)O@R0@)Ľn*2 PY}؉-E9)ED,q$EjI0 !q-A zߓff_FAkFjqG@Wfo{}6&P@:D UȀ$zLzhp%~ζ)nYz`|/y? BeWG'ˢG$Z㻻)B2_M 6Z$jLb/z wkيbp%Ž wN*"bSGO){mB]!ѶgkP4*9*6g8UunYD.yOFu*6:By] AGjN$ΰ{# 7MG' A$_eNtzZx&ŧ8m{=$(4w3P/ lórYju h$@ ^[:R4b|>b 8>mfCзdV >xYYkH@?ў/%ILjlZ|76 D/dž'Yn_7x { \fMSԛ 2+{|̼*VghܣuA3c-k-աO-8baS't_Yaߟ;gp5 ! g!#a j}_s5Q% ~:w>tHhlOrHR/}}G"t+iA(V~~}:ƘRTu&%5"2f8WCsc2Yx6dM l'ǶFzrHYD$P&te˜?1C .ᙊc3QAtg|dκaׯF G?˖T~"Y0s}}ISA49\4gt,M{K< ) d a|'%SI_;8Pk,-T]8 0NM.ŋz.Z%r`~R፨ ܎=P)rJ(ÀE6蝝BDm3\s `:A\hU1˯'>^m~gժYklmϠC {J:驨5ʉ6F4f9PHnQB2_}yxZ^I]31ҕ̅v=WؗK8+ םe mt5 g~˩Up#~!cONS(/EiXVEr%P߂3Yx 5DBZJc+Ꜽ@IZɐAP|"p^M?10(4錐3q"auV7"D:ddq', {$B 6q=1ք&y[qDDp] cӁ;ڭ@y#1D6q]m{Ѐ|;e$}E*&TjR046N4i4!-e|MS`ePd5 Q~%K(Gl{eXw`J`/"< u~-AQI[C1h ĮKxͲY +׀ӎ5JГ\"<ړ#;˔u^<4jV_fb"oKL x$ ey;m%25'A̡.]_Kp^NiZ6Su$e[g!3Jݻ _@ѳ(]( op@3#y,곀ZZ+UzӾ|Ei$Aq^˂b:EI(e.2$~AX4*E ƬqA{Mkކz802c .8 pR,R_X^ @AeB=>/,WGv(B,S^t6/q,H@իf3dO*n. d>q/"/lU蠋)RW?0^'u=f1 y8 sBp".it56.(0ZL0>.>tQV,ZTDa2S]$n`Zɐmh_Iݲ]HW-Sy^aC(?0-D~AJ%FTO fi6niү X+ 7<0ar;zR9O-Kf(I\OTYd2cpq:6? NbAjw3yddUZ&4z4Ŀs%9s0f'uA@'$@3o0=#"Tr9PTv(L\'FlsFHzy@kވ1PnxM DIp\pn'ZS$IDPUƆQ z5* WE Ϛ *# ?g^؛Lh{-]aީW~ƹQ.3Dbu&x݉ Wpd6fP(?+Qb{~e6#kD.bgz_"ҽ?W &|_.qCxC;\ ]Ebvٹ.APzqZLHkT{%4$ -4>ogy$*y%=} 9 5?͊(4r7+RV7B]1 zÝ$mR:>;7Dd%K_Ƭ CcXe:buWyMN^>7w{zx/$O!o9rJCumqu{oy_nYR+TI.m49 jA˺ot~`b Cx+))byFlJa7 v`#1I7`npi?8B&u‹f+O R:8V^g (Fbvh$YF^YdP`vy  I_+rds0Qf,z"^wцpyA}u` Sٙ/:Dhf9cA ٭ؚ?:N1>Y DB>nf L"}Ob-6B8ڌ8Ԍꛖ5iʉ56l[`[1m\}w{zLkfI^U6ıǴxﻧ^kގQ2J~Tre4 :jeU;15^XϮ1X¦ME8~ 2Yr4=#50}QfXBaH"ga|Y6p=o|QFOoCq fV&K9YQؐh2K[\2JBX0ckhQD!j'.\ JZ N0R%[MqgL~o[wp ŗN|m}Sκ:sZ6&ZZ$:Y/2zDvr}kRv!w&oEsfXtDfb*PcLKGsmm<=3\tN~[8W s>TqBNW7NF&JEo͑eϊ߶4୏& )ϱxTn ~h2G8;vtoUL)1ʔU,d +c'apOb~ l#Ug-=m1- fL3zxfkʈ~j- >m nh%j*7:ۃ\ץv(ȡy&C0DR$^ߎȌ34{2vod`ӗFF׃Hg{-QeYұofxjB.c6y-zh+"* - F { 414" kaqKx AV>)߫9_Fu fA܄k$ux/ɥcIC9Zc@]>G/ph釖Pi^N_ Z I,iiozj\~ffρxPH9BQN biZhT !!8íT &wLrȁm߾d-ci&-Zi?ʈ+]Vzl5CQN>#ğ:!8BpRCVvLdl`%Uj%ɒkǺ2K(l ,L]8^j+S:ČG#ۤGtwʋxASEB$qծ{hn`H(p0Ӗ7ބq!WɵJOxs<Qz7RDYxrM\[`Lb`uE~#.akN0ՖtSʑ]>LP! %6U>k7_%dm\b\\^݈_vp)`(ր#ro*7l%@6<8.˓F?>%Ήe Y}4+FiH$e_=\Wۅ,3`uX߸cdPƝ%/R7Mڬr u&NYjq3WrW#`3r/QxTs ›Ƅ$Uv[X/v ~@3筙_ *Uo_ wvʬhqw` ct4$QZ[IPij_`57.zm,hKw*8LwHwȶ`4=Kg׳A R*y@lMZUN[G闗E 1e00Sh=QbDv5s-gy;F0AVԥذZyɳIjFG>f}jN*ޏ'ɱg/|FY ጵIm짩 j@q=5ܕl ceJUeӪNNY|S#N[+`WJ[Jp}f=g5gaWp_qȰu; TȇēY^Wݐ$È~yC{ϝB15ܰf/ q %Rg!KP c5ĺO2#,syP9xw5pܿ q2cPy6YoXOyxU8b-PuRN;')8uxL'Xi?5|W U)na>'%@X[*_!uf!RjO1ضʲ.hEZ6aF 'RY_jehN`!XH#_urGX.oY?*W1v1Sc ӗ,1`Muz'5 Α㓭;d-m/.S(͕2UMI/4 ݑQ+Om&/k2"z1'o;bFУK7vo9hĭ25[Kj~ ]ݵ&lmnom>xT?A_1{C8%M柚Ep/;-pcM_VRe(2zy3d H#I Tb6mlZ͝gcFHchckl<;9 7AVngA6 _Rss:5e2*R0[{]DXԝ;KGy n>]16X'<\5Y'z 7IOg\Z ɉ0sCdD.N uLvSf὏('yLzvC+cWZ-ơ+BfaC^@mĂHe{^PÏX37SCfPF:wck3-T{qL弣iۍg WC`i-o|ZȌB:סVMQcgE r4m *LhF{ ð>&â+Zl@ 'n-p3i4CL8p)\/JxuԹUpHJ(2xu Эc(JcS1FA,+.^,a!⧍ؤE%lPHK{nN-~<^x'ۨYXOd=j:\_AEj._ƘͥD͛L\&x&Xif|; ;>oL@\p4b #Kq{v>ҚP䶩ٖ|9 X^Ej<~]*r-r X6]"akP]_nwfS[ :7XѪíEKΫ`KD5R56Y.^;b]F`^YDq^Ž,RnOy@*Fc̢?a'@L㽺9{|?tô~ɉn0] ?1R͔l"T\"v ;R㺍E8 "*VЏ筷I3(K&~HqIln4\`[TbnWA]r7ԩ;9(,Hhw:V/~l4.D?"=4P@vm2.ad'UfJYА-6 n ] ,mTȎ4iU3*zIGfcU[r^lg ɩ>#еBFX7},*׿ #> T12D6;@7?i53+|=!gq F7g6m,w0kB;:Ya2bXփrUM W{?gEA(,;V>p 1TϠpQU-BܓEMV}ƴU,?oY8v˷*uJJ`߿]-Kج&s KA閕og.|& Qw&Њ;pqlr~yzZнp"G;úYn Z^iy$zt5ffQw 78J,&*q2nX?p"/*(Iћ7!ۆ(C&@`N3&8 d@ӷ> [g󮟞<t{LJ "A/Fiw8"i-OF}9׶,=Tf jY, L;RwF%lb>zΛiz [6^|z/)C|ņ%;š-r=|o|eBק)_ꊧP*E"v) I$,!}ݩ?;\u4\İƺ鏧UnL,Ө,0sR8|t{*ǴN#jd`LV+b4Tz )$}ɼu@(?3{%+H$)s}0yTq*}g{8<19j18N],/O]'6't$*hin7x!q eq|RȨw)ij"vÑ7;C^ $c9^3 %5YpJ^L x}SxN2L^r Gd]1wt+|O;k #u%tLx7Z |_ZamH&Rs+ނjˮcTP5n\mQbԄg,se. Q3L; yY0p>rDTo=͛4 DaC&.7 5tI;@d"q8)3mb3~jLU9 j_U[63PR U~ 7o[8+$jWj4H{g] []<XզHQky V/H[S}椓&TDiR hE 7+}$hv@ "⾇CP "B };D%_ D>0E*dυ@QZ} ;n$TJ {.*UT) ttpA԰G=zwePjʤ@n% DeOua2fv|3XY.I94"Zts zhp)!JmHbٯ]uL00)KǏc$#n Ya;/2oE:)a-c6GSX&U GPmaқE!O.`ץ&Ps fw/5;3JtVҧ Z#b{q,^=*QZnfc̵GDY3eA.C UӒ#+ KXlwW< yL5Q1NDp6Z8!AF a٢ l $I.F,tݒ }0:iUiC%шJ _zn%7o- PY_yWH޻ i~A3M˴IGX,:vשwwcʆlq(HmᖆfBGzF+܀A џ#RC+R[-HW/Of2[Cg0}{i@?޾\:/SRy,2s֩e:Z+M3뼁qrXr)x;_XJ}0qR-k؄wWx!9a(q% Y<n:!w;_Z,x)+]N t Tޛ[x)%PM 0{ ,a(9ZL}Q=m D-G^>]zrtqSA:+A5*h" -~@D*UśP2 侾Mz*x \8Ts`G"d~@$8RYUSSucbk VMpd8{q}Ta N:z($}!YzS1TԦY}9NhqE6&߶T_dC޵%;~Vf?|Vl2Ʊb+mt !L dh5ggQg6:6-:q/HWF'u l)Qng}WUۻuo[uj̖(S189Ou/fT&\"J6 ĨTqDcv_ж>H<}>ye;ou&d-Χa½obP꾷cqax87y+,@ B3! KoJ0ȚUj.~ꞂNXLa{l{;E 3cxUXL21{LV,&1/gNȩ0АWML {U 7f|?i8gK/hD5r7kZ-6P}]SZc_w*BӟSEB .j[vR4 KeThIlfL005 }n*8H "dqbS`%8k\%OCbe`CE!h)`_P@V#,O9 n=hʲ[f7SNrZPfa?1寝j|krL+{53jNaqܳ)6ùJe@JnnL[|Z|n GNA!X xPntvt#NuSbz0ju "<'L@hh"_>\G`99b.N@,HI~SHokaFɛp~!5ϐ99\,_ Zi YTPyI_nŸ.pEqAKo-/`53:)X"Y%u(^YW>qeS;#rNvp<h9S/BH0#Z9|*%Rx":LZ[B :zio5\=stZoA #7r zJ2o^8qFw!F:46pS_ zzְҤ_3`|K̾*W653F dS  `e6օ}WXvQV4jwu^qXCQDI`wƛ _qM¨.Gr(bieĦR5Brbpb'~n3?İ gvNDqxet$-H;? [84ɿј7 ِpt@d! ?IjV!u$sqeIe00qz2Jgzuthgb}`E $۩s+ d2O~lnÓYP͚wI$hOE{4Fm}j ̱ؤrffC:[FkZ5"!}x{*>K}$"0A(b&AaxfR~peESOLU=fXRY{ g'd'B7x%wP4KSQ0˰/cэut\?QXϦ98b C0.bK~(R G?.Aj-tv--"%vʢ6_58N!H@޷絭yE2}+B_Dx3̢G읇^8~υ׃DA5.\*+Vw5,"6{!_ylX-aW=h1)A"d/XU$gPkZ:&g$/KAJɐ BnF,f9U|xz2$\L '{d셈72I"0Mhg/?u4I߈y]n݆¿(ѪoJe`fnjBJ_`ҽ'P s#\f6N 'hykf/*@%{Vu`ѳ2ugDq: d)0TMB JĂA6o{UE;31^RX%ob1[[iu  kw ѣ!Cص1"g5™}4A_!hKyzMCoE!0tw 8_\O׃.n[FI=M'c'W~gҭȀ^ۀ`˹Y*AڄJ>xQy8R YCF,}B>3(U-h[xƈeNhɇn6ځ6:095tkuJFg:>C)A 5-{>PT(]}09@ݨ~@5 KJq"MHa{o<'ؙ-[6Ab 5Ϗ?4a@ä 'Lj,2@ޓ8PC8ٌf.|@ Mȶ('360&KlJ%wSH:5Q9 ULb{c*@@I'On}"N? h s#M*{jU!<c6!;S1 nAR}>48vHJ\ p@$v{XuKh,^TxsP68VgrE:>'jI 4CrN^4 W| ܌!(*? AZdz)IԭS_Lw7BarC#Y>Cr(PYu"+,;玃ZB`\bN++i"U rg8cCn&+yUbED_hcv&VC{ Fv/U@;VKIڳSVf)K*J .aɠWs#cV o4ΐܥ hj{W]t)^J|(P" \җ8e~oe@^80ǂi4ـy9V]2 6*[=~NrB2z m^ӮiR[ ٨,5r4!l$/c$_Ej6I7HDQٺ_$=ktQ\ 5y\G7K7&%Nx DGD2YNKq@ȑûҀVTf +CӴ#ny7srmy! Ӈ7_j^¹(:͕Ϋ:FOiEJqڰ]|`9>Y鉯DI~SaU4vOmYJ/ğSfȘy'$C59f3* *"+E^3GBS:]jPѩہ䇏 tL%Ω1ɡ>s(IYN1 Q'bt}EyOܙp)FʆߋдϷpȾ ˚y9=_vYeq\|U!@kyt`W\8^p@p`LrȵW,(f%rz!hP o O4ֈTxR09լg__FnmUd)PdpX-6 Y#k)?[Z6M@k/`P}~υDV*Mmޜ: ] P4chD8v&DXs`{Q{{%%Ն&ڏnI*b / L)4A!U0 LGȀӛ;΢v# jf.|Wȉ^K|8ۅp,9sw:|6|Q@eZdP_٨^nʺb0EQ-;]H#|gfh,ZqI"-˞n \c8 kL8gI8Bip~d>&vU(B1v*U> )TOXBaQܪWFɅbfhI]lȢqJwS9cgO5$q~fnƻuCx,!|/$;'@J0=eָ!UKe4_Akp! ܝWX++Lx36J745®dN݁ubʈK_qI@o={W=}/}}S)MQ<W"~K:+|ۍXz iX%y%/H5K )#*q3+*Nb2v; *H"\ԕO*-@e ;M[ xQV' i)?K|FFzl $_Օo. eOADFB*"tJ- 5 Ud>QgΣ|^x7hh>XiIt O̍I|ׄk#O˴|n0J4SV*9'g,Irkq)2|YW ' AE#2VKX_KX0(28` |߀Ѐ"3BnQ}@%kH1Q2:o~ rM.Cq4 'ҵ˵]$T4o5b̟Pj\7suƽ4RHǓoZ4-)YBUwg{vÆS486*jߢ{ho;(wgm$3 ,]`P^ޭ0_3ge rF:0SL!E@ҧeƪ?2I>@+uo1^xI]ĞX^N۪H}Zg֮V~!6 vM'̀ju&xo`J_6 ¡EQǎ*}yf*C /i^mJT=.w2ߔp^0*N%oDIk׀ƻn!հg }>N <.6 "KFJJž)W+u h9+avȘ_)$_1o=GV{2[0QV P}uJ 2[cj:PM,n]-k'SʷkK+~U1D Bfk9G9]u%9Jr,s (uKG]KG?KAtU]JGjBտ4C> K2Sxc2xTg$|Y(V*cHL!zMy57%2!,WeApeˎ&,!,І|a.҉EH2(҉ 1pא9ȕ uTMzK !S2[JhVS)y; #1dK"M%[xF#ZDUX6el 9&ŋ$5^X"`Nl8)kz{H b}UFf6&wy8˟(HA\}%!Dȟ}% PWq7hrXE!XؖA!S%[hGqI5pCjy[T_v/B+~HHe⋱ C_\qy"(PJQ/5,QP3hזM]/NэNhdVH=TV'y/w ~TV/N^|ݬ;}->E*xME8UuU2 +)@ TDz Uc*Ǖw6Ne ل "WЬ 5y}$GQ'c H]R3AnYQBLyu0-gxކse-vPrؐDg]:!-Ol$w!kH65nҨ `@L? (j|`Hrq^wbojJl7$ tO 06a l,_Hd{`v5+oMqMmE!)XNL֯!sKo%(F+ qdlbl6orޙ()@^Nr1Ebey+aUtqvɣʏONovTҾZ)fksGeְMi3!ǻ$$uﮓ'ҌbT-tz:~a^9Gr^[ Y={FR~;IO,77-Ъ]7'{Bv!Ez2FnwYL. ĭ H0Fr1aaM_S.4O6PpI5sm0?t|;PVvꏾT,k<+҉TY+(izTQ)H} -Z V"Ǧ^4ba wߒ؝񩹳 ~$[#_K&W7;n5 }N"]Is!^X=WqӌR@K vDoL|U7\@`peA ”Pp̧yM.Õ7`GO}$QBoRP6E&M7 "b;He& ošoOO]xYRC?dp X%1pҮ.%X]TLSzU9"lS9hO v Fa=v%;}*moq?o1bI9٘^ƽxٚS'XAj՟PeTSZxZvRLzr@ ́pq $0jM t Tмsm& _b&<#"4bMKpSDyZ`ƶ|\G⾃#38Ӗyҫ 9y&N(iTv{hZ? 2 aU<0LZJVF{81/A^9ٯq!t_؎ nLWZn}j?D̋ŀ '2B%4 *^ۗҘ>!xY뷞%-~ *~/1 OB_CHo~|Z7qQNPuCrvkPIY\PZi}.qL:oGژw\/IU&i\H^ m9=IBI ^vG;̛[/<0SqzWLiCg樫ZB70AWH iZN 1E` B@!Vt9}JfA xF[^8/58u'8;%cm8ܻb  m$oJg3% ޵6 1akºYRB7̏Us:PN-rn%XXaci@ۮ ( |8u/Af\b8w|MGd$qN m5v&<7^M_eJFל6$Q4 ȥɻj58`7V>01|unp(3,~AR-v1hB4 ~"#6s ׆!eJɳE_9 Z2_xQW Zr8=Y]Zs9$4;uEHKj5e;A>NPz<.^OIm*a#;VMO9 ܩ3 siS0Ҵ̱ukO(• Q*a۲_ŽC̠T?L7Q\'䌏qoD~GkXi<'Ǟ ZӧߑN %.;s@gERQ):P8P|E.Ym?9Fy^gH4 j fͽ¨ck?;<<+h'by#d_T 2y,H9جjk -s1R[ ]N5'ڧ\L5 .+ֲ+e]2>cVSs-Sǵީed%E Ќy#SK{dkyf&' (.FAI]m.MBd[K\r~,A+s[! 6T>kD9 /ѻI+:9ޢ%Vߌyr*cQ 1Z 9j! ,1Qmg`[@{0eBĚb=K>d^OV~QsDu&GB ~H"Pr=VezPPydq(*sn,y_V wMkN h؝۬LxM9-wAmւBEBΪ/Rcڭw𐗴J݂znu7 !~:=G82, 4+""XOnQ;f˜3^\%ӱR<0{aԱ9d(+rHKcqAJ%ʗl| z?*Xڪ a0.=Β\x/CΝ1POr@MW~gR9X,-jՊ< s"u¢'){J& 7'x2h~M_ UiEFJNvG)_ɗ^P4r x`y3?SϵwT]4uyBpW@h Ô4IDǿ93:_S/F`EʃHI`UoGnD ]Q ax ^0ٗpT w=;!$We9\_P) 6uJ4(x_z޼_r F:Ge>)ll xb( PiM|l[@4ŠRbcD Tiݐ'ikS6J( ڧPHM^1`6f_ ~A4\sfB øR4Y M6Z*#$'ML[RUŌLy 4 /*pP[JdyRKy!t=-XbO"arCv3鷆2ّOo">H~v#>Qjt@ꃍCK! کL=TN{lE[o7\)FmQcV (QlmU箼C ~#C -: )"G(:qB|2+Ck"ז̛f𘰞!i1⺍nY[:؂: Gk3{Y&tt"x&~Ĕ^ j< |xsR9'8τOs[kБP-1EAX+I5O?# c["5;6H"l;0IJPqQh2ܷj V|yM)ƤUX irbtǰ R!1ĶzܦtlCjKN2^4:_4 GakWd 46? Rfc b:?vV?aP) ktif@ oԩh_Ff5uCX'Ѫ@jr~a-:x3РJ-Maqԃ6pj*D?J B`3J{UJ,zbXV&hZ6<wLej0Cx@uB8y? (ڡUZA ДEjr|¨&{ěfƗׅV^2go'N=t@v$qh^+sI<MrtX r8\(Ao:9g5u?x>x^PݨN>ዴӔSd eqjvlMGm> %*:oKKLߩj'3*¿E2jv_g{{5 a\vQƴxUM7? s?Uej/<6Axю&OD|oxrD!Rbw(2}.yؾ S aqHEC1d-SY$p+j /Bx:ƵWb0Ӽfn @Ͼ[ږZOOd=Z10̼1Եh<>%/2^ؚ]Me08 $5OO[32,pzcc!*NƤ@8txhu(Uba 25jMfEt\pa*|%0Mϵ:U#%m`0_G]dŧ sQv#8'eyTlYCHܿZpXAf3zLl5mu> Gzͻ*g<Ǫˆq, HTS,igV7ޙ*wg mWL]>xJsq ՆNt &r 2ׄbO%niit^+-bC^A{@"e: WEQ9 ~}%\z6@w,K ,{PRjBR̓(Ohoz$NAd>[ڊGGq|j5t`7,;Qmvq- :aY80K)*Lj-;_o xL@2[afA=m|YnMi r8J[.|~b/uBM| Bӊ6k["I1 5f(*4x~5KР.u  S21-}Z^kYY_BX\Q*֟A"2(K?KMXܑ!FM7A"#Ĉ,za|Fq%D9bvִ_LQ5 dI>>Q{⚠"xܜ&<4.ygsWpk,ʯWWx\V9T^䭍~ՁLH"1Hs #$)9tџU4(5kJƱ{F;4k^ݶvܼmVoxAxEe,*3M6^3/ց2p\NOi͌꧄|^πqwpm/P,e\:]TFDős0NZ mz6GWwl]4]Ԝklw1Io>Tbv7:*&aȪ#2W+poQ5]Y\IUW0MXYtOFGt+D ۹B@gՅRqA"o;fU1gQdoiCqc6ЉBnHbb\½ (yER'+Of31ϳ{|hjQx>#LhKp)xG݋(cE\ 4V7@T*PjGǛ)YFٹ"Իi ϒ>ș ȉS˰%{ !p\U [ QJ`0aet1uRJ۴$W=中92m|{_+QA9({DTTV!KO{3.hm4wxW[82ۋd_㍝qGeAꩭ<)@)lP~} >;4\dFPDͼ"O,QVm:4xDA^z **" Ɓ mKd3Tl'nn+ٹ4,|uҌyk.v hG鬇50w?i҅Wj$#tYh+%@xEg[:Itsc6r>xJV53I|/{fS^1u+CQ#-2[ʪ dyhN yݚM!}qiә$|[ Z '2WyT(/|JbRo=c|f _@U`-Pzp>Ծ6hE=?إ'i.BcayݿLO?ۍ҉G9l(``R$֜[%"r@weO菚e٭7$ǿ1l\R&DCՎINwHІ +ģmV4XF=p|FLJ gBEC2MU\LSD]f= [VÑqbNHm.|c;l-a/[uY2//Zcp 2 }G05M:$X-$mE,P OnSgN-bqP30]oeEJџc`{@K4ܞUQ\W *O LuN7>n{5m#yV LvPtL4)?oDRYe\#"7 Og &1Bv 62ǖNfu.U~G>ϞpvnNձAHx;V]nL[bFڙLo[!e@C,bʣjyi$}zv?/c,>㲑 *AsTD}8TFݦr} ׭r}H9- \^eZ9=mw8}M,0ht.Fo?XMp{*(Y8eqF$POCu&n ޼.&M*QӲȧ;AD:@#ٔh~Sc]UDJEf޿K~ƪNMNn2p<̍}*qHp%N6*EmZ[D+M5)l@A^o quh[Qx `'05]'$8&Nvr:n}djre}/w2b!AY恡zʝbCև8Ug2.39gdv>Ǣ:t,Bs嚅Ebj|96= Cߊ5@>VI![.4 3Y} ٟ7F^9ɣO7#7;y"(￲l.Mk;j^}3@PTh1e=+؆GM8l4d8Yׯh{eؒs!eg$lHteih0,:W9e:oD:89L^% >-1s87wg4i.LӉ<\LNRK_?w˭Մ2~$K`Pth5ۓ}FI͏˃M Ko<3vIj.Du.!o=WUNȰ&%i-;5KBQ:&z|׋,SgfVn"Cg9$'EB#ۮɕϖ2mX6< 314UR(Tn)Xqkvx3I.;#?eHN*le& eӸIHpD]fmcLtbsnPŪ " `T&{6Nç/-ck nYwƱڕZPq9$uuJI!͑`PkYkEP(w'Bv\M@Od4;)q8+$lL4 cz8!ͩܫItu6VSX79eHd:6@oYO 潙عz|ɛ8ڜNm׳~rXJ:%Լt6xmF50,Q~=dWm"7IX?OK STu>*gk 9hkd0@rdJbLQ]=T y:x%穵XQd_}R+Ϩc@c1wޣI9n-5C2䀇{%{rȹZPM'P+)o6j@aoZPN35!n^U!qn(0{ЄմyWncnu䗲b2-.ώS:̘\nMꂁ=e\Hc ej7oa\dt?GWW:z[eo`S|<_s,fknDgw^vy4g+#+`bAN@ Z’ |rs%03 j [PvXdgo) VC,TiKW%8K wەAs>B j;$;ELzIYߧ{5 vE1?3[k zĄG|D6ĀRfYsJ~۔s_sܕ(JA?9Oém%l%9d7ԹԋtL8Mud 1&'NXAf|/AQcۼ81T*H/Ux$/w+Y3aFpxk\ꪋ1<ˆp.<nK:UтisnZ C"%qg?Pzh0ڭyj7~Lj G";*gZ?1]ά\L&%+q * gWTH'!BL9J]Hӟawǣ,?_0 |} DDH(e*)r;&?@Hh:DG[?32V'ҁ;:R'؆j 8J-BI!0@}PdFb{dg."|W)apM?x 0dWnpo5F4GeRo|HѠs"eEqoS>)AW];s )d?u3Nh /c#*Ly4P$[;nMZ@k|mHw}Z.GU@%_ٽ TCCMxᲶ^)QQ)+, ;;aBÈɩn[IH5AȨp;H?fEez=wЉɟN IӸhP&Lzb#G9,?KsU⡧Fi149ӆs]>({=[.p7dSI>1Q(sz+ O06C^> j5!Ir2 We_t*p 7F4S]lpHd7.fj m߮.hm-g3 sZ+mNl$.@e5e.QwY7|1P{9z2zX./FNBxr| л Q}[?xpL*$igPZC l.Y>U$d>-{ai';LA}0ύ.0!1ڊC9`mv/uϖi1PAcy]=CPnsݭ*p#wPЙKQN McYŌ\eVyG/l$O`[_'tul8V֨$U}NY׋?d[vٍ7_EKẺ☘A;^S[35G l~24?>nNoJ?%Cu0.9V!aQd-F6"^`%hA ρyܹ#pwYyPW\aI5.NTnc[x>i*7ԑ;Ky2(|7Cb"l"Άof@kfL`% &>79(K=vs&Aliτ "O saJ4 Gp@qmIV,=D: y ҅ϋ&#xqDcXZMa4.Zt'WCa;+H/l6֌,L OҋX[zj ʧS{:$:VhW?5Ga}uPd"P[m63 z3S =X{!늅 ?+ XA%at~rk.'y':ēthvovrdxo~! 7XkۅS5NZ#a;;E:xZo!j/MQ'!$U)@vgs>kntt~lVHXTXF;p[|ERbS&_A?s}\LjxK` +Tq6'ɲY._lJexYI{g9&-C@ }kۘJSĊI3 UB/m[m;͘!AT^I{'zEm^6 Wc#)_$GUt/|/) yCtu`dnl*3 K9Z]\MwCޫ@{M}X7uR+M)iR8p"Du lPASFmg |~!L6<]Kd7Cl^k ޟ1@فEY,`=G65Klq%~lB5'CNPȨPɟ19/, O2vvinmt%z[^ϝX)V:s\Tz4Ii`\խlT`As+ % 8J9=jxxp.qma/~E_ ~r iOiPRi{OeoGKeC,|$M\H}^hyiie7$ ͓lHVȾձ RĎ]VeG]Ikؖ-8+Qgf"(LbecLPq֕)Tl(77RHjtp[_nK<ט'nsRاwѸNHS&2b˴|>I3eZѫzym-caߌc)4" H6~ Nk0jPs0Nc(0e1r[1LaQq@&CiDˋhF$^!HoQ sYV@o_gztc8(m˼#ET"eTfVmd{(_ [Chk=eOzKBnrX"%u"M0Ψ$F2%:'5zٚ!4+o H彊C -|9a+{F[mf ""t\ `plV76GY{\3TɌϼTͱ<J7^J~9gu ,u[cQ_X awgs` jNCTq`k̒Sj3A_U:ꤩ&pwO+忿ඝwud> ǏZٮ"c Fx8Ɛ&4:ګõ;|Z8AH'q X2+Jz/M5ݳ˛ɦ&$&@خ`Pd (ƻr |VEr8@d7gR|. K& lDbc<tPX%)ĭVt3^4/};խ8fO=Ȱ[؄2 W\,VZ A @u<]:uJ?ONs@yG]ՋPDjQ}E _/ϪBg:4{Y+\= r^35 ʲ+ K燮,ܶOA-*GuumYs\.a8vCʔLNeس#?BC ~MhiҚUܠmRl a%ĆnܳZ_Efosd N[bƙPm GK)smyae`iXl'OZɾv>Hӕ{@9GmKne۶r6&h; }eQ!݁k_߸u ,7{g.# {i곴.)o8r;PAԷ h>bxϰxVw pc'/'B?[J<{-[і5O=*]$`t+EνOmꊂ 4B4ўV-2s7\_Ϻ)&<.`v^ QL>;8{6K7M#kxWtjʫfpwttP~"p;В}ˁɐXU b:Ga:D_TLJ!}sz24B?P(2sKG:H!TPj&2?sab/U> sxm}P,2BJ21U8*>)Gtp {x\SSM{=\}ך:9Zv>Y1܏N!zdo# 4Lv)WR|)p'`z BW-Oz_/FSYbv&K=&=" !y|1Tjz%^ $~h~|HQq̞(:+iT<!Ҳ\k}AQZ"ŵnv9~${@zX;(Aޙqo;W|]|HSF-ʜP/cR1ݿ*P{m{Y( wbє[:` yԙR9,-NЌ{W9nymCIǔHo9x lҭi"犣cq.;=֨XT--]JoJřڭAGʋ,ܢ+r\\w8aV{g氋*4[9}xd 6 U#X<18-0 W'q,^\(HY_'TFXZz2r_(4p N:YJtO}D\D!w$1 !b;R40Jf/'G@j?51Qt$"ègä}Q74b3F!m C1_oV^k3[x=)]|#ôc`}})z 4=e$Ua+oqF?I6٧reB@k~P"-z5 ihѰ>c[TQhl;?ԍ cT!tje2a†q:  md0!3px#vµWR:ū f`>wZSAs1Zk .|Kk/R[}c1@]=a}FM2Ӧ2[;Y e _׈)X1Z!wJ kC1U*EOFy"`{CwlMɭǓ~Svsꏷ%Tㅝnl-MW8''+1C/ ߁).7H'2YDL]ͽ 5 ){g{jl\9CKcї$/O@p=쮮TAeB^-Iy$zLs]A̽cIu P$15F )b_&4#|+bYݿh3P 凧#Npɪ Cyʬ'NMSV!~ƢΑ :MkpoD6eU U `=|(ҳ],d*L+:\]`LY'l4KsEÏ~a10Z0FpdJc`XNT y%+3ҢnyjkO긯'5F1 Vz*q7Kyg^";T`7-n Rl^Z&jml~ٹ2/ic{zv~М)L|M8ZpؖX ;D9hG`BX` O0Hq3%fh/&+1o &h2*ٻFA5* -H9kGL*Bf4<;/nr55k04){W^yxf7:79vʌW@Th>d3=7T#EQLS=yjb񁩳T| dB\)K#[+%(1'Cmv"t^TVYoik܂ [0b _$B9W6YF]uUTܱpyw Z؛qlj,|"r~l=O0ĵp(IœPE&~^2#[=ˮ#b9UOSm+=U^#%vm(u_TĝҮJh}=n@T1)=4ّA[֑+?(>K&[/m`(bF0@61)G tg?D5T/¹s:FSu(m$(oSB.jpH *!IctOǍEx}nNeʓpB2R-2NÓQErf*hćL>ފuF*0R[p| t$.~ uCoMEE[ +<'6Aapm:.G)Bfm!j ܳ!Y/Hwr\I'@/ oT_5V`kU|5]YTD^l$3HKxBJQȀ&jXz'u2<'~{%RKJG^jŠjVg~-uqRh=]&VLgo@@B?բ~uF颂] (Wμ(Zv")}GtM%h{'I2b*Oŝ UfW,iޘFQJmŬW䰥4% j }F0Q4t$xQPN "ŕY mt7FJ0L ULqA,kp)lu=óAB}ɡwUMCn!B[hpG.R߿(<&ZPn{4$x.7 kPw8LsAez!Ps 1=CLz!A_3i `u)mMVM6+v*)#)}H‡t#W`jj{uKlg>xjch*Gqǰ&-s޶uKƞ-\|O'0L @4~ko4tK1_H[glIn</77fHEK/CRh$e_/mc24>;SJJnFYQZdOA7#dQ}5߾ LH{43A&,ᢵ!Yma3J5(|m% mKckRUmB=ъ u|KpVDTO S#eD VjɄMWņyZ_RH~Y,uDD5\yOV+m1 pS{'T1HVڂPY^#f ":m1ryl}lm_Zi"*צ4D߸$)nkTW"%,\ /ud(yVd?B۷ߋaG3oϻt(NM5rrIvM֎2N$:q1Y EX*- ]&CWa^ԇ{x^bMeF{#̙ au{f-L qanW#dhc nsT68/w4j?2rѯ9̲eDL^uߐR,+aoBǸ"f\ #Tg4pEda]HPdqE _%r3@Hcr9!CJ~ӿ;r-g#X+v`mO?_ƭ\)3.>+Hf[=7^VD$X:Uat'GT7"X_ ;:I_њ;1V D;7vXTdBI3z֟e֘j?@/KZd-kλ*2@tV%̑:~_ .'*h*\iq(w>+'-iZ5|zS=m8ǿWbylxj?ɯbBF$=26V}x QL&z쾚R~{VyKVƛ(ӛJ`\'aA͏ñ#hDYzXӉ-8j-0*C:7Jkۺ$IR!D9ok }J-{Dz32:D|B⺚E8|sr׈9~P ^sP*n2 K ŧ M$eUҭ}uo_8-8Fy c̜Lm$e)tksMCY"atax$3J'`J!4<{W(޹!SW$/ tهr?Ry;/ɛ]3$C{ c`#cb3mB7^x!A><8Ǒn(&o A)."aFP),39Xv#uq9<܃6Q/g>H:.ylɾi fsJ$MR&3B|lpgP_o2 ɐ@9#)Qڠ@d&8)+\9CDxÐ.}͏.ܦ6 46,mI%t̨Wozٻ@Iyd>W/xW}ZNϝ̸d5X݀ &Q}q,)!['h7k&qk4{bzS'6_q E3ǽ.x}چ<~n DN o}h?ulYwtR1(dVu%-DaGIn$O0) C]|$gsxUS+Ɠp8Xrf()y챚?ۚ(ى#Rnۂ-I T矆@p\ŁyG-"o=8OӁz9gEvظSoKVC/ >?l+ʚo!$UQq·'NW8%V:f|KFP>o֥4\t |~ /̄a mN"-a#&%5D\ ^D a%(񤩒lifaeO'#'+$T컥<3 W+a0%cZHf9V#_ڤ`kJo]ޑoyj LhdLdztÏWU{`5xl;x_)A$ ^\𽟏67 d=WYy])k?G}xx]"Z籈GGeفCk֏+ 0vu0q/×~ݹL~th+1Xwx_AY ds A>\,zc>zaJl1>`zc)n{WuoI1G&r0>6jmN" ي^pmgOcśf;13`ʐDZYR=bk5 DGL- >ڞG]V}7˱?_[2%'hk>UP¶k )bqt=LxNveG~]}X76)ޖ$8݃6CF~37?pِSQM\9GbbCD+_;@]"trws^BYbV%#¿T-,Ffw.gd[BKK O9`C FXW1՟(8su l3rS sWU,;AOƘ<*[uƔ/K6YMT tR!&'^zy@╻^&cNyü꟒:ȨH6YɕNr4$Ucv~gwIұ8\hXmZÅ=٤:S=ᛩA 5@1?mt6J3gWĘI8ER/e3: dC`-ElѯG lZ[sMrP2=U0I&d&@<={U8"G (`0|fV䁉a1uLo( ?'IBF`A]$TQѾT$o7/݅%PW Mv}v'{WCC& `_N=?xO(KF)dhbV=ǙxP V-4Y7 t]ZK!-61TQ/= >ԙ+"Z8N!Ž-efnp0 8J-cp縚bz #>ڠH @)rfۙO5|J S8(&GԘs ?^X_7#^`¼fT|0-jM_"~TC[ԐjηpGºڨ'oŝ/V*q0u@-- B- S|a ~^`p֖4H֦̉iPm0ί:V2 QͬQq5}h@Gͮp"a)9۟+] _ĔHHWt~}H V&wryYZ.Pz2~_gpրļqo *C.PZZsJ~OèIdׄhdDjZ\ M &M+"<#:?j2XtAqƃz!mI+sr%8%6T܀Cͨŧ.^ T#%2:5ٙՌRdv ErObe@OҼX# e6rťS1P.[{ސ.00>Ux*ymA(/<h @YKJpn=Vt9  ! Dj`C (vroqU@U@<1jY\$CAsxm9l<+bVu IK$1].s=V# }f1xkљ\l*ԦAXcG XqTn%3?pϥ&eet{""P#pS(xp3]cU%K 2(4q~ߎB cRI /s`K7kZ3'qэ E$76x.TDI,"yDaϓȶvGʏO@t}3Uuphd}Y1 ]?n$˼]1\),')\`툱ǎbVڅ$,oT=Jwa DZG͸irӬSz,{ǵApKE=*8Ԕ5VmP)7lL>S PyYGvT";ug fvj|?:5Erf1VC.H.~3w]v?WMi!>fEY>8|VcPffZ׸VݞP0KCX=UЫd.%>Q;2(b ҝ G-xPۤVٚ] BB7i&P5,ݢeorr1 qtxuD'j ULUeAtHxkE'ȧ\h!3] \*JȳmҦiPo}E7q흼qX]'c "S{%@f<9 r4ap{ 6H"*Q>.$?DG*o| NiW'n1L2cx~RW=h借kXVƯ׹Ԕ[@'kB{m ~9= uBq<>amYܾ# 0q#p#[fun@Q/-[.P6!oij#7=dxJ SA еB aB~` *:/WvOyyx (W9U_S(;NIDDNXF_O¼IP]cRP%ĝ$_8ǘ1lJ9^Fɷ>q7Wjпim1F4E.-i\*&Ei<vmS:;I5H`W%!܉7SC fAr9 #-PcE& vY4T6TnvPIz؅4 7J bu npy. ]88},؉T,lz.Voё_29ŭe>Q=es{dYp" dTpŋ'r?'Sm &&uRwo2 k}gyuaWE 1*2qGb"cJ u*Xyc*63M첻ĭ*:M/DǛ-S u۝+eu1'Œq3~"":Ob:MC9brHkk·79SBX^+D.GZmT`S|PCy%啘0|+=I~j ƢHZjj+SHRcױ+hϢhwHRC܈ƴ!.}"c=>d?LZQ+E'$#Rr ucFZ5̀^aXd6'PȆmAC5=^%Pf =ILÅ_R"-{)\yۍC6 X @y] h% o]`!jP.,ml l'=~ݖѱa:gu6)w€eF># Nʒw\b6// ƪ}hZx6~|C 4DR ,^$ʡ>'R__[n%i1ݓ~)>,1p;5h-6VV6 |>U-z,z1U% &2ߘ74r)l~O!IHK@>;lgx&%~! BUH3D4bA9bfI|Ј԰ލR͐N vuSu=:35pٿ^v]!n5Ɩe9Rx'@aT <30+!;%u$rC&CIiW+d^R9PQωJLc E@۷KP?;݇O-TV+u_:{:}Ϻ:F(y?ܙn[ط^u-Ҏع&n-o -Ts2˖Iv|9¥&S]ŝA"T TV^znS==ꔮm<Pq/t~*v>aO/-!=2oisf3嚵^3t|T#Bv+ZšxfР7x5oˣ>A.:,t @NV@=XnLhZSKTvGL ufAFQt܌o6Os>WTh.E{Hf7Oky!ps[RKk]{H_zt%H\tP }=\/Qĉ &}`Si̔uO nm8˞xGX8sS"YKPcoGz7'4c)Pw. DBL>7xڕ\Bf7c,! _$&^6vN-%*Y2i'L@wD"E2z(D1o dn`ѧ@8cp{ID}l9utxwtnc4Q@C*xZٝ&]ۆh6H0ZL?VH[):B|CނE1A-6׌W0ٍlKp|{/`R)k#]KhY!:_ Ml,?U"qr ڿ*)y{T;kc(Pc\B\iʖ ğșA|yߊ,MP - l-B;>2ڄNh{1KK{crGleӺJͺ+ٵ&jO+8\vimcFPZ/9z;Kq;D==T:iuo!+I,1#[_Q` Xo4q44һ./ ^dN'z.ho"cySuW%;C(nljulW7bnٌSL2cMyĿ3^8 eM%qXҁ+OY$)8‚C]::7SC/,p-K&״zO~DҶ{}{eM|9>,x˽QW[b{{GRYƣ. D8$h|N8bwm\ IR0<(JKZR%&+uͯf earCg _wJ+*62 W`}6e1V@{6?[G^SJqZ"=/:p0W=8gG}S {JMyGդl+pea90 V }U:._@`qΑ g"ܙWL&i%b$كYnHgR\hNؠkL"ig b1\$ HxQ={g- e˛]BUka/f'V^Oybϯe`}R~-FDy(uƳ| hAbH.e]g6&mɛ()E,Mj_[۵kq8i(o-FIJ4#1jy6T,vEe2$bZ#kSo-62Ă"< 4ix)P0VD FPά |{1q!e2%U ")r ~Ui }aaZ_8-b+~GBN$;+0C rCs[3GVlb zBxMDBexB͗~ l(y">h5B˜I.Le<@du%moVX)}i;I~=z1пOɗ~&nwZ"apPκy)T!7u֪uwB0LRT rF51,X4PhepӌGi2vH=w+d ⿊4ݾ1v>B'ݢj?lwdoUжūM; &jpg-m>Ǩ_7d~$rʻT*=:SoJvC fGr57M\Kr~x#]IUlYޙ MDL o %hHT׋$Rm'rfũ8\jQye;4 &1u q ZID3W,s@44wMETڟ z/%-Et%^u-?>"kctF3ҩ_XυghXMζw Σhmw &K;yFY^/0i{gj3=ZRظ<ZuUNeqz#''q7uMju5]c!q&;) -mX:BVK7(pIdj$ F|B0.X?NTz0ILm"g1k7~|Bף:s#&{ c;9T$Q]^з/nD} 3(*&ly(PAW|͠koGi;{RwӢ k I>Dz)ɾ1u5 i*Ǵjά-"Ɛ+&N80A717/٧ ^-s͔Id@/$侐nL/)Gsv@GTPPLHg{kǔI@B jmS4~r r6~%.qK$fFV0 Q"21 J܏ZVV&B_Cx%IЗ$vu P5e?A}`x8Lmщ ^miB#`]=UN r. YB=59^8æE\*#NM5F)eYXnzEH>WrFa&3]Ub֢B;o_Y6jHyG* bR=R,ԶSN wlJLaFʘUgLj3:cDz5W)iƉXuɜe p?+,Ƽ>ɚ㬋OnMk~yFN><$Rgbө=^x/UhA([KIG}RK=q%⼐ikv(\T)sȴQL}>{˭wK4{Gt;*c!mI\O=q Mt H*IF\ZȡJdTZ*;2Ƅ=7?>G{vɖV5 ?)g "Ӡ,rd&`HV$62?k#ߠ]o5V>vY[n.fUmב<l8qw FR S哎׆uuuUȀ}U*I e5vQYNOOCA6%"}BT OQKT4H+h0%IyW0\y8(wt׆=vZՖе^1{Ƕ&~E`Hߧ 4]O4_ݡ\%l;ۑ7ozXe|mģxjZh8zfz-Red;Kl9n!=ίMJ!ć6s:ʦ,!PMn  PZ s|_E7jP54{6ѯx" 5"Bm}j}$pe'DF-ч M"r)1mb GdWW%;3fH; 'OSvFIӈ5>(v(2ܧ)sI,T7Z2 xZY>uJ-eoyT,gCgl"kz>z/ar{l>/o9>jʚ-㗧W֕Z  /Pϟx1#gfʃ,V~nm6*(&:|'5+%qK0mfn +B8g>炊o?iCk\!dR4.T=Q` 6@ŜGkg[+yffnɖ4yZ(HJQnԶoӻ~wBMc! {Ɵa 47H?QجA|:_%8gye-^SK6[󕱳*FAn;/5a|#*Y$#ʲ!0f0+F3wr=IGja_;Z_;R'wbgyZ %( D@IU!ՅrlZM`: I2ͩ-cÓUoWqJ1' ˃CFpb\6qE" ]bc; BY9I@ӯ鞧%rL{}UFqI  ;ۯ6^M7MC0Zk ^ֈ<q$ḯɗ,R]!z6xL<CgB`:v+kZbкu~.. V3.c sJXo?I.gr-9TgT~mZ>6u!}wDXG4G/sdm4XKɓJ &3[ M ӏ NHy\Fbi=Y rֳS[&b4`x]^J5+B@@&pN YjyV~Wu)1EGE!/H"{|Í!1ilrӃH?ʃÏU-: fv1xRzguF_'ad5 =mC"d Vn1TSץL %h? :ޞؽ֚l,Q@ I6>|82q,b~*z; AwwF䲺vA4.+xE@C4H9;*e}aQ7s 79*#(I*}ے@\6;&\ڨ@c;WY>>f8`=4E>`Yʳ摱 1/ҫ-L4AkLT5v|pHF]24gH1r MzWWb4hEf"JBR4Ȥ5/C`s]Q}m NvvqjY(I7.Ń1Gx\e"؉({NJǙLiZhj+& CXnoiFU:mdSM'z2 fZ^~y/bydw6 1Y1Bm#&!K1רncڜsՎ7Da7#RQ/% ]7zC@hu~ "FZVzaeaп-ǯ]YBI=BsWdQ=w=> \>v+l??^4%Sē?jGZqd:#t* |s` [TS8ߵ '_*ì^!9Q̍Ū2v|ɕdALA 䒯)Q}{DR=ٚsQۗz?riAl0nK{NQcmٓȭ3>ٯ4W{R/߲vKmї H뽁-hcްܚ̭^[A&_t(UvB%m-,V>3.!9M'^52fɩ=VcD|"=yVG&wָPK_T,cj+x`P?Th]ȒR3Ap;X;ZJэT3xo<؋<' J ډ^D*TOE8_84֡VJ>TUGRH*O$zLQ?y~'v[exhKn|ZF`]b&;рĜ YqB u:rMJ;AˁC>~9cRylO6]?V[ )W*Ĵ/^"}Z \FY"j}b{Gп_e` 'fKgÁPx1|Y3ϸFZԺ{7-c4 `COιAdƳTS'ox5oK9"HxAMggOCK)o$C/|`-jM%y#aQW0+&19jTxO3| u* E5)b@xjC~Oe];_|8Rڨ/v5> ]h;uO ! )I1JXSm-] iFF}>G˻.:T,zV|b+|Y%b}9io[1壨fq]X_8_"C@bkմIe>8Œe؈8 (D:^ڃ>#OF%ZʄSEh>NL8e''hRX=:7!ggW P*4unZJ/#P/0Gn/wTpz?-oh w:C*2أBVUA|A4OC![k3DkyH_Re =Oi᥀>$~~m(=>YH|}by-."| G''#JND]Z|RiD6s!ᴤ]N1>,Ԓd h+\mR_ԵA@ XTl6E% S!6ݽ7r%bXqhDoоv y[o-U ah8C .1'ޚ͇'㋛ uN32țU~xe nho["V rs_$Z:^Ν'o'I\YL9|X~K;dWhBFx !F`MЪEչYyܦñweuC2 ~ӇE! Ct2yc,ArʝXla$4H0KF78kaQ!0]lRaG9G ]Ӹc% 7KӠo? (G50Ǒ93n2v8ReY@V F~Dpx` v١G.Z'#‰-"wy2 oc`Y[~ibd^]X)?k"qrQiO]626.#qR 1! "UN`oUxt8 y/iK%woHa&Q{Vtjt$55{'EO _Q!j 7:XI#|_K ;^ 5)=@t-]1ꬢ$ۡz ;ZS*ru3(f'4^ U_T2Ҟ9DaTpk#>:= z&:IZ"KW4jlbu1\W^& ݅/M7*k"ymqR·!_4#.N~}%CŖ,8ԶvK2iy\U20Hc;=2T_ װ]wHT=( jY0Jh`EGskWfֹOMpXxA}/RY{Gl>{*WE:>UC$m]x? :&5ڌd"S*΀eNSt5.a:i{SPU1ӒW궕B3}CNf]eo]w{7)w'pR["\Ч | 6ne/M]~ḪJ_ ;5!XMXfjˁ eZ*Y{F蘭K&AhwT=;gNo2i$C At_(B ۄ#ɪ*uY%EOEőӤ)iLRՄaJeib߁;aς҆E+oGi 7|Kd`x2 -ra1SoxN4OX1[ӧ^RH]?L0l~C 4Łؙ!|f+҅75J*?=^4]MWC_[(/a?e6h4z5%gAm~ZdtEg#v*#N M:`mx"ݿrK,t4oghн5*k4-RA!'pYxK b6UUZGj5e9US1DPptsY]W ^ ۦ]`.,+ծu슡W[Vy Մ<ϋqn]c'yHfdzŶX3:yN ,]㋢KNw-0j g6"Z 6JbR.IN0Q/`%(md򴍝*s<S蛢jBR \mA" ?J|t^6⪧++9D9:ޟQqsBm*l >3NQ00$ ȎFl7ۄu[$!_6`0ӮTn%%)p0 mkB^"bS~n7&a!`d"y`eb]Sz^6זȰ= ͊7a<&TtJ.#meGN:ֻ\ .}U;6¬oH>t -M0'^)֗En'ܵ kn}~$s Dڂ0܇JJrVכOQ0>]yΛ~Κ$V{$ S{Z y&?|'OobU*&O3}4-ѓMC(C Ӄ "<$%.1I(qU) ->? CvܤE]J,ģ.OI|,:V( 498Ğ?rF^̜9ɜX^:&?@:4Ym?IxeyVhq'#%AvPQF́|:WFPM)f' E FTQ1fBQ Kl=nj4!cxXxȉC(%]3p9YQ~>5 @/1"ݐ%14Ճl^:dҮk2%"ZX_=^lnMX0 JP;Z>8nCj00 օH<IZۑ׷/JyL[F$wR6O/td`qp+|i}Dhe^L:(vA)2/ s2yo`o1gdz-dt+98q0 ` mmVoqMwpkѢrRFm7| ƕ49q-@}.="'.RHSJP8+orxwO0ܮgHx4e@z8֟sx]p5*vMQ]ڜ80239\e,^HJn |^8MJƌ9"32-ahӵ###wEGܡt#A 5;?ߓ}XX-$Lζƅ~!IxHf&-RuN&<t&Ss(>Sd}r>ܾ~*'d ia56 ]S`Ql{vY(HUpD6| 9S_+>mnɐ3{$U3+sLDMQͶbQi rs"Ί4R\Ǐlq/gMMkx h퐂5/Enދ[J"P{Xj5f=-Ub֧ NXE,$&i@Πx1KICk)av!UbJR{ﮧ&Xk27(֐Uȿw;`d1PAS#A,5QDͥ:|쀡e0 4rpo hegjVr,&7ʉՏ9p:Y&,"ƤFTkP1$~ZwZGDWezōGƀh P _U掷xmu:I- m$,V}ss&[ʾH4,]C꧵o_.27lA!W؂9bfVu4> OU)ٿuF=R)R$,#tKD)rM9{Ϧox}gT§o_ V^ax{>-I=*޴廼 j>< .-xGZ]Һ` Rl?XM%'P:(r+^p{ݴ94A%8i(*Ա}FqF{#CvѺ&vzG\gXsP}o] 3ĵ  `Y8@tԋخ6/nJUWwIKRgNOV@!_@)Ń~`q"iθa&%8I0\HHm.o8m>.~ r$qp7όѠ+y["jUx1|$$$5 GUyc*5#5z, GO,@rԈjyF id''橁]5pJpר߇qSIQH0BPh)`M-2vT0S&kxPeJ;Y@֗]uAlJ"]cG`Kj_G+lG8H^#+[rԐ#oW/=I-.>iH0Y^%F.o9kpF Y3ۣ~3߯JT)nwޓC/]Cz|2YԱNzF9H,ס Z+ >|-m2ȫF=JTd Ύ<njmu~}Gf?^p_\7(bIAuo#@%,/uM):S!!9ӶOf;V*m3䋻+.mJyHn"ڙYQnj*/?2 (ydZa ~^=LW.'Ub<V%YbFqyNXr(] .H8iu:Ȗ-ҕ%֋p7JĘVAu1-}0~j_˘H*xH(~KlH1_3<iM~gJnNbxnժ'=<`2)ڄ@6_V جe7I,Hba`0uIYTؠÓ8A_rx4w}=qfWMt(Z,V|`[Z;,Jc%L;t2XVq!ouI)"C'}>x}Gj<N4TȲ)O-G3;~ϢQP.R>=z(;'W+FJW_Gt.* Z]8y\sңaAx3T v6X+y-CE .5YzL}Rd ~>tu9.ʖO9F+ bq.Q4!n>`Q%g6؟. >DђFGzvf P)P F: ؘt NJq85JLs}%s՟֔b03aq =Jmuey-vh}lGeIʦGbpZT`6Xeu@3FL6ҮWfy9MD{bz_4ʖx[uoSi8JeoK)ĹՏ`#i;93uDs0lf 1#jO~L i-bt$;|>Ї|[@=M~XnEh_P3PF>kM0dBUaE˸8 °A%'k{nΞ[PՍ-aAzNLkk D dNr०%5j5<>.W+䔅[ޓ9Q4_/YE^=oq'\N1SNj\nhB8#F3Pť窧D

ioa.^(B4 l}b1#_)>Y1͏EƒuE42a`ڊieua58 x/7IGF܉jM~nlm?9Z#<3/aá˼f1ёX.o5+D2)k[ jS *Ǥ}9rXȖ(k.Hd?>꠯C[ʌÇ_6SdG&Ʈ8grsUW= цd?ُ&<0AE+Fۣ(>?%@$ʼnQ`e7ֿeLgd&؈WJܖ*;{ZW_ǬԤ )b@7iF}W`Rz "n\.f37jF m!"W`#6 \I-B _ Rpt.h ^<]';l\Rw#Ђ{L[&e|IGbc@A,FlڮD,bIPHL[(M [<]vbp 5uX$u ̮[;wk2C^χ2-}]M.}ӱWtc)Q'=R]˓yP;[*{Cz/<78Q𗌨s4 7}cAF_eI+l皁z՟MÔGmڼS۞Jd\6OO]_!=àƃ4m rS3,A(-ZA ^qM;f]rׅ_K}th$ .J8Lr{Z`S>ݦNBm|Wϕd2!عk'XV?ؒsQH1)z$wfcrH4Rr^vb@Y.$ 0_lu- YNmyH=/IbfFn1!$@.!ܴܟHTОˆf|;eӷz+)g;g*'$/"2h<:շ$U<Y0B EQͺ!g\E-뫖de3x~ }샼3mq>t(^?YUdw}k#HĦFpI/tBs>[tRm ^z-puA걛[kƉs lSQWlaꈯ>e]%q'YARXXo32VX ˥mR|0#!b~[fhLGDx\]VמGo|]`++ZXDUly}O0+Q%x >c11qbPٴ"gS#N+;"Rۜi= Ԯpof-h"O `Xu7|0i Evy]yXd]iD.4{RmX)X6| ,VHlk/~#y~Wol@Ǯ[6 ^EG@P7x0z:z?0yeJZ]{I>H)DѲ8jqW$f@OԤc4ÆkDOR >=Au<#(n eb*f;Xx9xe*\j=KχHj׿G:a#i;l 8n3Yߙ= +,&c)vY:-TҮ?m3&E"4V4Tl0ه*4N >OyF3Eie.<4c_^N#$dhAtyvm~ťW f 9M\"΁4#;h Yފ+A5IygQ8RӗFx*+̈l\[ykl1`b1ۍsZ$N`[h] X@ >$^Mՙ$,-PfOdžZ>*X,/ j﵍G_A߾ lACRAkj\JX"*'<0(X;@йu.[ug-٣[2i~Iv5_E"qϬruD"#;Fa?465dc-ruݸjl^eg. T[vz6!V1 _z8ly* sr f'{ \I-fc][oH׽[ҥ>4ckfNBΥ8 <݌>\iO6|}Mb^Hgz$(c2|j AGJeehƒ{p@)u|/EO"yb_7\Aq˪$$BT{O!CxC #6}TpCuLypDG/&"L^HPp) m}cDZKE& VEݩ̿m|/⳹h71,_aylO7:y8T<gNi- H&×̓׊zT|# tTsEA!Z<Ț }K- 1S|C}DEMz&fH*醶怌קk6}l$;}׼#k,0Ԥ9*Hb+zVhR5 -05/!^d} hٜ5\:nkOYR -tZ<ӣ3 N^=褳)YԐmǴW+uvXHΐ#Z~9G斛/D%A:$ѷ{p`+:}]Ծ|(}y&y(ҪS]_g"p.׀mc\&4^܋Ig/״~r6u~Ľ! Go! /]@/Isyኺ*(4JN-IĀ+,w$UlSR8['񱂤nlt\n/2D=|w?q(o0M4]6TMg}ESaj!E6XgsAa]Ya&y`t#&֒XUKsa̎z=0n!1- OVoA$y:zZ^}Bmw$JSkA?JP1^΀mckƦT BOsi 8w;d*O̫8Q0pHsJ  h㳙b6yZiUnDݕ2ѿm=$yVz Ěۣ>k$F$z>Djutaj.8'vTӆ 9b۹  0vs65Bz~;0hFn ޿ t;pN0gv1=VvWJ5V"cEK(4w>iX~K>L^˝pH~gsK,WEn4A_`TY$A<)Z*8XY=@O y޸0F>acvdfy6W'<6܄;shopW__VÉa0YvKX 星O$. PZa1$b1%PxAF,wXwM/U(M_ N)Q{|ŗ q֑M.5I+=C"hY0-^7@RwSӝ{O4b8%6ޣTpَ&ĵyc̅"~*@GT+VK_?}=/P&7I(│Q>DgG 5E[K?|Moj%$9ܲoqX[?k.њ_AԲ~w;ϑ~l6ɝZ\.natM n ȉHaz?'xx}eWE@K젛XVl>h \{QIALlx9K-z[{| k Sd2QgZ&5I;~3Al^BZu=C:NsZ&3J TRTJ+izI7F ~(vpZMᙌ=va4NS[<-a?&Q K`MKEyɗ2):BQY/>Rgah- TGғ|*H(jQc mbElJ, n)ӯ%7Q<$)l#cGy6l= =(×XTLsC+l`. btG 72> ^#F_yb{4au Z!囔ݍ$]zzn?e3Ɣ,j @TT:˒fqj"N;G_\Ǜ@uFJ\d-,S!Wϒ&&~5xpE5d i E”WݴFX^n?3@nE(inj7dr>X!<,c.Ǹ7jHi$#p(g>a,q\D[kujѽy#:9 YGhEn㴶mF:W HQvnCm;OAatca-TU~YQ9X&ff=swF?tkʠ{"g:M@|S+}y.O5Eǫ&?;u&~B!ϵ!2Fn_)/Fd$tGduOQނϷ `C_0K^{C-L Pљ[@xFd M&Iry/;p5U8QHWZ׭j*Z r;P@Y|ͧD ido4J huO kuqprdV["tg]ߟ`?ڸ4E?k8WX=W)dH}%t2RPjs.*]軿+YNiQA҇U}c*"G:_Sn&uE'XI!]=a-,`CjMoFgk%wVMvFѦQ*5%8=Q!_+BZ^.ChFvd-pD }Pja6MhUBM\rV)D "P~=*{9d+V}6^usu \;#?*[t#.3?URJk lWX(%G6ȶ Iw3J,E hDэ)ى{Ul4k;` `^U2MM%>,&~ph`uEÐNmȇrL{}WA%Iw]rV?6/%k GK╟ٱ "ΚR)Z$R4zvl鈫ܷmn˦ف0߲VYj_>y715*x7#)wgs57Q6QdPO Han6*':kX:eU]xJ:(*TmXƮ-"E4_ [b0EXٞ|yUZKwL>Rz]nQ(9t{΄DLzcE^=v,iYӊ1 x +e~22zYI/Λg9i@< `ÂD] KLHm5\ 0-msaYgvS5%rƞ:5 ̘WB&bc]Oi|򔏥zI>reX{@36ox՗gR k`| ۍM- a9v3'\aY# <"2}%e)vŐiﶳiSj LkK&rDI36vGfYZBm޵~!Sܸe\ =q16nNf/ߍ[ UXYy>(3o!$D]`1CO*0ҟqdB:`qwnRs/iL iD 'PAq/8Y4m2ZC*W}M{U%7uAuYy 7IP8^1#hI* XU])%p!\nh5pUYN@HM m U%mm@٠%ǹsd"f ʀu{zjaԼ6qؼ|ֵA ˀx,-*+9bJ#F'mQ$ "Տ>3jCX`k(e$xPO:AReᶗVahzfg:3P¶̱J^k@ͭ.Z[{kÜ;t%6!M.@-Ṋ쓥0OƧKi/! e=mpZqH(6ȍ?*ay&nVۄ:8es)efl`rJWalmF[(KQ$t`xЁLd8'a.u]! ?@[!R{J{ճP>ڃx8r+A׫,?pK 95`Z.suL炙QsdeqO:9F xrZ<Wc͘r}q?033Đez/v)&:i-#(`ߢ SY1?/8j5cI~ԘaڒH{?Q\R2Yl{SMU]K87>::0> ~{4J&v*.?wK6560ornZ"zI;嶊9;UpU1'/BkzAW*J5hQuCά-äLEQ.a?簉RtH1PwJSV, p]# pQ"Pv]aN,7EBd$`Px[?P/*$Co~g|jW~BÕ];o!4E/Bq&6 {H T&ómN9aXHb@3~E;:$t{JaL毶]޿nr8}N+ b-4DP$X K^X}U@WBkΟg  ZRHĉ:[C ٨u2!a)YOOkC~8qHDc!j,-{[(=K 5Lv8Q\c}18ǴK3%A+Й*qS z3Wo6:`SFYoνH)ûFlhh⣘H i1Ԓ(;^5n`N%L0;x6`blY\c'eNջV@K&i7 kuFWzHdA qWe1俬EC83?oint$l8Y xQӏnU e*ݡts5t½/O  έKl^硃1 ,|[Rnx[ pGV._ߞJ\U+T/[6 hm7fy g $1A9B+v}X| AUs'g5<ԇԛMJݹBG)!r3HW[v#!G j{J\RgzjBQN-Q'ڂ/3a@ulV5S(bzm,C!6!f}6}g#^RrN1oSE/W*v g,`g=]dE7 YGYugBq܁Q 2&2ׁYL@JΜ9p-{瞌p䯤dR"`PKhZԏ ݷ{fDDq!~<,`G8L_eF Φ(QC<RY8r)$y:o⼫u<3"dR󱹅wٱSiέ#gcpϾ`jwCo9kz_'y%TP#NNщKv(:LXSf|L,MU18r?pUhhP 4[R.+)A{mڦmk^8=@LY썵v C י3I` s]Go=%ʽ;ۄAl,dp`\FLBEz{ Z:4 Kxυ0f9dM=RC!}vJXeP{eYX>MFHY8 Uys)Onck W5#yr"$3ۿW\)HE<ԟĹYyv|Dlm}wXhdǕfC* N_67P֤Q9p{fxx>sG{ FS$Tro{ŷ?C;XTGvEDG ٺg`2lٷ^pb;cx/U!+ 'vdV/;6VRk"ָK X騠Ʈ?DxRX8#!gQh^6j5 zNw)10'yyj3螙ɑOCamH-G2\hKq݄0+,b zpVռ``yC ~GVqJK֎Cߕ/ 0$f̨_Yw9qɷ%qzB.~/ q'3=CXK Dmz)wDF0Zq/?ӔR/au.ôMHu]74&MX43xVі;m͖hAod} Ȃq݆IJ36u)LwVXEi\Cяk~lЪ۱nBp ը4^klx+8Fk KF1ӱ[<5 ,tb\gp]@7NܬJlkN=ƨY+)nA*  ٢jD]8Oߤ=gT9{87zQ3ہc $-Xǔ$>myL̜vmsnBZh{]xو{S?nDeg}KEsrX_}&Ӹ-%q 3g ]zD(k~g5G/"u;_E.=(J`bEq#i1M+lsqul*U.0fOcMJ>}Ĝ_̲`8ST(ytw{f@ o|'t\Z)eF.sl3SeػztuY -+ fz5 E[>rTn^[,B^ f{ᎀB:$C5n=< PK4e^4,DfC%M 5`ź:T"ُmu@)UN7{o:Ö_NZI(H4FI;^!5DٓdFk8\<*m-lEml']TٖPQ'w TM*Yzc'qen!Cf7,`䚨hY1)-ˬW[V$XN.s&HW.`8[j9_ M^d^Wޔi&4A&km<%2<9_}KPcfĵ|.h0cj₴# K&6/?Xdވv?FL;7|= ,z"UGMzxUETzƄn&P{ #,?.Uc]%.&)Gq-j`yޜq#z޿#qlfa_KfhxC7Q96x`l2`U״ԕN1#,&3 eAd uS賙Oqq5 3$" 3Zx`eOJ SL,@jKl1S 9ӀԒZ$A,8<6e|$)^(9 ֤ [}zYrBܜ.&SHFYO_݌<, hޖ&Ȓ{~&3?.OC8MGbdfIv_%UkK>]YӪ",_zc]/K;.&;-cTqn}Ҥi3L-l8S@{b]!|5ߒ]J­[PUt& ytZ/`Ƅr@*XCX ӈ(S# |:~q ?;b;qt_.hp|Edd 9'6;41Y lPQ[_HaRe~'^N6&#dw|UkqtoR rc{x:hͼ"KLכP2n2"侀wG^qNz#JMLj{GB0DDg=E-nnv yr竽\Z .Ģ4Wn_YXd⟙dlu=K)yHeK#`z[ѻW֝&Rod|78.T-5ppO&6.-G` .FwZ*?)mPkӎk<dB 2QSi^86\Q[D@,`9 J+^߈K9rdwwgO&yk*>m Qw86zP !~@էQ˽uȐ8$YfNy>.wTZvXάzB"-gopfHUH>kd)AU>h ;CH6c0[բz06X42(9?ރ: >BR&A_uGrs+NQ|>Y5 1`Zݙ%dYٛJڮ~lBT#qC_$_#8X?X.U,&r5A9- u< (\C /dnU0uw<O 6Am~kkAnŗ9. >c buC0Gܿ.Kχjf14GaJLB"OIhm/r.'9?l/VƜ &0qñ=\eakҠb؄xo{. ,<w9sO %X.{Y7F^M$NZԆ]LL) njGb"2:Kð KJxtc"$%Co<;0w7,%ޏTT &L(0**<-S?Y*%%^JSWgS_}QWT;omF9}Ǥ~Rw^yO|-R>` T؇$ /zRf5|&Ms.2#Kύ$ mt!bhOH6\z>YP -:`G^+fYnI.%焝Taoff1§3~'?&lބ }L [_'^3>ֆo<${=c`n0nofMAb '@7TCB:Ur$XU1] 4kd5 dg:?̜"d!%0XM7]jFH_q_/m8arԘ2a"kYY]uGhJf8 nCމ"ޚ¬@ 6*/tQ_8"uo7dM)J\B;7~t 4QɝMUШ#:F`w*%gVl ג_@+ǽ$v+'#`Fԉ74I$X_n1eVgj='IT6+IB-axvZ3S~YMHpIp>!n\ _B$CVZ|YTB C͘rt̡ avʹli1G#C\lDYN[3sK:yjRshk˭ Dl(Pcp~5s$AjOZE8i(/Kwpe^$&ji0Oy0Dd{'͹` qnGrtT{)ubrmkp28uddqLlYj7XĚ*ʘi%^bkc!7N6}N, `,1"әHsKz\Oqt.ȍ S;X@'ti^ii$ݠǗUgek/ftr{ i% & D!/H*E A=k{Bfڷ3tw=ᩩd~Hс+H(0-!$(Qf1R sC% hs)f pk2OT:B3"8>& Dxք )PrA]jcRI}ǡfr""O! ;mIk^4zހPv#`/:"ɴ_j% p,b1ٌ:Q6zH@]T4Pz+D02Q_!c>6{ͭd<GM[O/FM]}AP]_ L[Ov=S4K~ΖvtL:c n&z|:v4Ĥ"T܀g}ȳ;NDi,3d>>~0#WMوk=@!ޤQq ȩQ=Yf!. k/6|4ff?FԕtxZc1o~TBZoƠ6&C-ʰ)`kNA!8BơE |;bM7m=g m2ٹ]-'!C Qq *=6%Ch(M?mFuc-4x81;7B*T³;?SJ!rE9gη/j[nU1)QD k'OߍSIES8ʽ1=2?OJ/!DC~P7yvc  U>N?NO4u-ؼ|'0M@I\HCG bx& 7`]JrgPsxqY'A!#:FJAPڝ^0\b^6xTm܀d~{s2/HFKy-@HԲPglpu!J cu@"X=^'%g8{q4,y$ӊfvxuu_ XH~iºw Rf,B7 <2()`m4 NgG( S g99j2ǖ>$ NYcq$>V0Uy~:@ n(-jne<o;2jGG ǟ\(j;]#Ae|uT)@B̷@lY[xsC 9MȪ YkH'?Гֻ9&-:ЃHKąOnDAGGxo"sqd/7WWZ{<3 (?PP6 w%(픰qEY`fGU_i=dQ ~z[ɨa7ѷ"!lf[-rXzk.7t![,Ii"f / id!c|چ, #B+HW]X>SU1<"1nSgxP{8 c圔0DWewPδbFnU!MRrDVb-{c-ɯݤL4-Ls_k~&0*'Jn|M rrhTBx3Ktj'G7GlZ2x>SM~k2s:oږ'+hfԍ4KƛCD}qU}Qle8{#hM#:Ϡ~YY(o4i'7k-g)cP^b4AE?^Òt*+iˆr6F[IcA |-ua8(Cۍt ;g'E/=s-%(W cLsiǦؑG* U0t}靷q:=*j~$:R%aZX)p02A Yn!$s؁h S nx]X, )!Qq~\ bi{P Cs7h)kA|Q/-7Ϸ㸔>Vm5 Tf,@ݘ~:z~Rx$g.CchG#?UEZ {O`Pxjn eK]~Gl8bQ'D=y#bvGxɤ~^$ᳬG@T(r*|OOuvPQY%I T?|6\o(˳?`.; ޻62AF6Mqi!c7NF>F^.b, 0s#}xܼ~lIdg"P\C캧lEjOBZEDmUb ʸ! %/ ҥ:ڶgV< 9(ّ!h?2em=ç*7= `V޶4|/~|N]t %51j+?_\y[%>"ils]h"etT>p-TJ:(4D;;Αd`.V#ީ } D!w}O|yPe[eꮭg&E(,oo)CE*+wVW2 8xд6 KҲ3bK#^jٸe^,] w8= 0B* :/AWr;Fc*j1]F\Fz 'W!C["aB` On2WFlӹ8^0bunJuRՀsPtң7j;@ gG²ݖ(?g Dg[;|":5Rw+;봝"Ĕ^(S$7Fͧ&i80̎ǝmG\kAL,#rQX֬` C;3+@='EsLThLRztr`iHX!R!0֗4h=\h]Wi7AMAZbȠw1 Q5bac =C_ V]>@m^ftӱSRŷA&V^Vwu_EK UGӶk7Y@3YmSJyh3,=9 Jf/OQn3dřFK6[t) cV ~.!ͫp<ߡ[hVe'VS"V$ ?2cB'@wX )wyzᬄ5\Ӆ޸w} mqd`0s#fW7(er9H{2qsK/(x$fkSޙjbq 9exr)A~H\rY@ٕD=\@V[=ӑt 6 6#IACE:f8QQ&_Pz׹=a;Dx\/kkǀq.V^4sNgYSC6ܩLa\ji/gSTWf|lu Hm-MG jnmò12dHKt _#`=KYv#a,3-raSҼJ(mhdϽy}sEq6]7{b=H`k H !9%L7{Nʩ+mx7׋FAd$3҇BD_Rd%j:Iq >$O'y{4?)߆Ս(" P`09ty˖A6#2 S;^ PJLXDfվU-&~;,6bpZ6FB&t5Uve־d͆2ZM)BxO",nikO3^?-NES_ڠ/8Wga0e |I-"ֿv6 cxG/ra8XFUHL6`$'lX7u"GJZrݜ! %xvM&VQ26=X6 _sHgz/G7-_  u遪>hBchqtIm.JtKO ' qvE`6W_ˠI8q7E#K1V鵪ʫ.쎨D'"PeЙE g`J[΂+h /]<f"aCB@0Hp5Vƚ%Xxhquͳ U RsPL:|j_bs|nrX"\,-/W)L .0-Kd7RK~>Uc؞ks|e-4sȶg e!~Ӓݮb=#fNBQK&!9?w * VAl3۬ fd|`RtbSmq@ṅX1ygP)vVt&]f:Rt<?M+EOX)+~/ZHksQ}?}5HtVmL8COI+XaLpՐZ (̏Q0cN70I;mN5"cCUYh* ץBr*^qi4,mQBq 2eb1bqk2IޫVvBE0lR}k.xkjƹ.U Mnв/\_'3kM e,f7Lo*3Vuנ{,L|R` ~PVAoЭ`LM6 ɚlF֕c[f⋐%A_J[34b)?`4< WG-#;tRq;@_ChsNx/>5<RB+aO'1,(:TFSȳ0Ktf`{ŶS$nt,D\ݓh&rѻ?#IYiwȤٗyS2?VOwe"͇-NLOʋn€#|__n?A nJ 6U6It-ou7bzo5)}2C?>N fS3>Q"%D+>VeZeuosSKU79ޘH*#&S{\0ZmMȹ8`Ub͚֭m@PU(H>a2>(+"vG̙\bDs^~e/r xwde䛬R1՜詳ɱAfNdKO*`ș zcB, =ڷ7/,nbEP2KG03'5b0]'`ZPul.>-ή](Ta% g/V>Qm p8}F֗7mP\2hJ9PޣTBq1:wLmlg8{&jC'%)|%_΁@P:3=KMDR!]M$3Z4LR-5dg [mׅCƂ0 cj, g_I/ vwG0G}!Y</D`2㍀K$o}yF_SaΌy5|I 9*(e©; [ 5W'.~*j&=zȾXrxL >L&bʕ9)=Mo kyư g'a[=ee#.3$B=T,o_j@f1$r9V=[U 9ϭ \q_h/LBkUVTvkEǣJ6UU t/Rza"2ʇykWi-$YjJ tHsh)F̥i:jӔ7OlYiW`&o`ĢZF@=(g/cP$S  DXIcoI/k߃fT9-XdSN-nL_7V+kZ13߰$uj`hٹƒ'Ѭ0T/~?{EuYA.m  :"?XN+D&$E0-qm {4 1j獃j| s"*xltD; 1C-M==sT#2"JșrWD ŨC'.'ôgpS;m:ػpUJe?N zhϳK,QxH!hi|Ibn#ֳ3MI | NW`f 6YaTgE"p.w/q uM~`& b3@|yl[fqisTGCvol'2b?fI@gVP2 kZޣIٳH9Fh?=k 3XU$^=:0'U֚֙#Fa`@6I$}_kXQ\m=һt$x#IhyiF&DePc$ 8KXedR. s;Xх@U/Hrz{Fm /Sđ6ވ6"~HtDzeO:? W?]6pٲ.멞W"׃)^y>0eҥdL&6D=Qhof֣v´NBHp,lJ wz\> 9 r˛J#|󣔰զ]Ւ]lفHOvFͷ. EHfXXJFDH¬Ԣ::'*x|b#N-i4|/h1a%*k{Ԕfka '_Y|#>+F/\v0e)Zd>^f?6g査йe|\ACd/RC,Xn=ЈZ6t?vlXh S>86Hwx|hqТB(,ۜ3:(҇_f+ =hnl//wSᦼ!U g8&nߕE ׻5 !'R> I =&=lhT&Z7?QHB]H FBeM3^LA:)_YLI5|Æmzov._3wm `Fv5|͆?A}@\x2T~d +Aȟ3?D#;NB*tV5ƥN]Q7>ȫ%ٰtsk`ϯ(MQ)CW{,f$BT-Mo]#@v!lR`FAU|zcS;/"ji-ʭ"9%K_/<ѸXrv%_GH*;\A}j:/gQΕϣ&x/(.Bũ6s@Q="{XY;z+Fg]mTͨ4:.T234˳p_<Җ1ɭ6'bS1`#DҬjH `nMp[w,4XV_sgzjsieSO v?X:0.hvVE \<W"RD#Bo) 8W=CB i{*(<54@ʩH23cFail>˻'v{/Y @գ"Dt:PP 3Eރ6eiIwS?^7 Y,e SXRWoT 0 Gd]5꺴DKYqҗxmcy'%njdLTw7,Ð.%jrM*a'0>4~qEȾg}_MG{Q %Ӣn* y,\h,nP%].k~ЅXF<uX`ޟm~?i|lr/uLule= _1^ǰ[K.vR=Y1tyr(=sW<>ewRJO :(ܑy*kLF.Y1Ϊɠ|v]H,xߞoDE#TQ" KLٱCѩ6r=g+UjHdHgjʸ29 Jf?YU-bi2([٢ȸ`H)غ w QV&`ﳭU,AcR}2: h-O* -ou:#*`X (Ңu,{\׺'ImHzK%b=<F@oEj [^i߉񗉀&u3uH ("%a$@u)tP8aQ0teښb詆тBP<Ӎ}K}{dgkۋUo VH'qz7[&& 5& Q_~9dA6 +S ŠI puY_9蝉;~ nJ˷)tAb:&{,[lBxu㪦 [h՗~eJAxo(.|CU $y&8LxgXM͒ڔ|BIu3M.-et_8.8[?FaĮ&m(mm~;8ey!K M&&/C w2ܒr+ޛ^_&YF 4}I:n3ڊ)Oer32]ƶKHi+E/3_"'3a ;(m={~[b 7V> $v~Ml,aa 's)&??"Ý~yo_F尝Wr7:e@*rwe_ڰQQlI BXHh[8;^BHByM_i=K7~O{q| oK AB_&UQUТ-G uP0}KM> Lo Af{DjWG U7xǞf?(gq]ߌ6ĥх30ƷK}tpd%S`$s"]!{\,V4hr6Q{_撓fi 0z\̝8Z2-֙c]H}G(_A=YM,䨒ޟ2d|k]7;q'[YfC=?`&7鵼Aɡ5:T-D-#)9@/-M[t!>FԨLy ]ֺ>qYb&t*W`hO/7pUհ.9O sa8 +H cȑ.P훆:hcC!,CaY,kN`)ZաAkҖ>:v4@ЌyYy*>7<a *]9`p;Dݘ|>{Ϝ$˲%p>+ݳ g.Hfŏ8U0Eވۉ>־YkSr\K4 43N!og&:ҾLJճOdi_pyEiS~Dheϖ<*9pI]-]Tr>NQpK txg F !5WpkpiФڜXOX:d: ) ب ؋v5Bc4w&!߉1( (V̮7+$HX:2MtFmx v!Q 7L7Ȍ=%X)lFIx7H _Y*h2+K e Yj>fm9Iv‹?$H3 %r})=yJf(@vNJy,lT"h)Xa(Pw ֚0/5"o.BxH56UI3:J~KⷀL7FD9@G89hp}z =jM}{<5Lb=h|1ͻ{[ BB::;G؊yn\!k?PcYg طؤOM)D/?Kjn$21lYk >6ضiDvGЕ!^}a;v>G~XǤZmðS.[笭p柡˧ jp.װ#w$2MN /+f4aGR48(w&o͜ :} y"[7UWR9@}ଙk_?,-t&/ƗڇFK\|BaT[W5ĹAjIʾX6K.rZIߌ2hIr׀]pw;1,5cI Kڥ&;fqΞTj{S6Y9ܖ&ZzsudUXW&WE!Α!>N!u >j̨_B5Cܴ-.?2I6WG4Kmmy4IE0Q=pL0GOqu#H&LӬ ys*t 9@"QsWHF E\ ASy 1#nw{!Xq?[fO B5fH.1!g~NNdK&{&}"5"xmchyl>*Q /HtzqC솮le%E.wKҍS`eR9)a!f7w 3 Rt!}5wgpnDˬT&V&|wwa!0/T3m1{II+TR0O5elQlbjs>¶H Z@au !&egcD}{61GElt(!kN#WҖi:):0 Xg[PP;_a;55.3Z>yWū4{DfP3#l&S<ćIrAmgSAJNkD,7T>`5̶K@O5-u`;fMh0J*@0,ۅltQ$.,^|Jks|1uad3"ۚ9F`zg]5=T'Ux>t \H]d/`m`3|g.݊,@qǺPW&cb 6+苜_Fo'́=}M$[xծM9;#piAu^F;ۂ)/VS) /Kr^ZKYMEpֿƳjfp+b➥Ui$0&tu-o}ѩ1aꃍExxmcٓsxnއxW"hs$Uk )c G~CpoAn?Uq.OwАhLj2cORnu٥r a<8=fE2,L:q>H/{ڍ1TũU\?͂`ٚ`!֨UD@kIɱVf"޽!4XˁїDjsML'd>KEP9: ;Dt<ycmaׄ[. Á(!^}{NtXiHK٦ؽDi 6All{ң4u;~WcqB'϶y :N{lhVI)Wu-[>_TCŶxvX{Z&r5ڟXDN񟁬9ҟq cNx0RnH+k٨Su/B:D L]q+Fw0`k+-$l dN3xlyhZQ#>2_9;g]tzb͋IURP'\.1)w=$gc zyX??> +s&`JKʖ)-aM~ij| 9"(Qj5o(0D)J\Zq@Lʺ G@H ;'@6Ux ڜ4&ZW9:m hIY x׌^DΛqd7cFtvvʓҲɥ7U݆ hJ /\"pߚ/ r  _KT:Մ2E^@\jd-[]śf!& y v4WG;l%~yB&E{*`}f"n8"[RIaj4xBsiLn&)&Og#"6CtU`YQ{*S\LՈϴ(F`j^9e-. YvW_+SIUyTZTъwעZG$0G 6ۊU[*%k> KIc~?7aj`.[k,}`¯6]Tv+Gv)oWlڿb>S@z&Y /2ݎ8 !AB1;57u[mRɁwx;~M" ULc=9mGΛYe/}4 녡@-Й%;@(ީ-HuCW|KTi GLU9Xa;SkbE'Hk(ܼY NcPl&HBRP@|NyMaC*>^%l##͎FzzLwCȪigb#nk 3S>m0gpc=#}GCSs=[!]KGʱ-~OY[lH:PR@+ !J'^n/incJjƜgk6AwUƳ-޴Th-:1It[M"4qT̕3>je@IY?aziuAF=rFDwyY Je}h$%_jl_ 6^yiNξ4nQwt uaR +k52=8\Xs&Vw)#}3k:#ѡ{#aܢېKͪ{wx)8ΫجJaoy~qA`GQtX`,2fw|Um4:'@.سi-sF,upלm80́E-2 QX1ӻ5Tu:6łP dpZX/ O_1L>|Uv6:ٯiEIu^oyB $d^YH&b #}]V6%k 0ls,]ќ{:pI3kdVČS@@5\c-*d \_xtH3Y pcπl<j y}CsA@NsLwA'dǸdn^A[~>P#,O6<-}ҼexDd J/}> [_="èJgGfҜ..)|yw|@.RB1y`ԗ3dh- sh:Q7bl>NuN}x4KƯ: ZsSiʘϡ9q$FP|.XSj4wqrp(=c&p=0Vă#YG+6PZ2oIpQǽ{Ƚ9=E~4Zz$rZ$ KS dfԢO{7L M :|!O^NTT$6> ⥩#鮹+' `d]c&wݖmf=].MATZة&lmq NZ3ͣo"?@!pîƧ$╠UuK=`VS']v!f}(‡XNHtEXKT Nء!">h{A`)y3퉏z_RjHzaxal3%S[;Io5.⠞aORaF#r#v+@cx;ԋ3 JM;˺i۾ɏYQE6V-I(3DyGRh(hg@xN5TV:/bsj:ㅈ.mF+Ȅe6Ϻj}~ɸGH q҉ Q="$3ge'Xj5% q=B9(wPFd.)[csB*5k_4Y,dD,Z19laah$M: pDm͙EDO/&FI6y4]XKm$-I ]b3Wgj3xг>UJh}ZgbF-Y2~>~|xH 0o.ʗtz n+pۊϤ^ӭDB;Bb_`kq!ym`IF;.dBN C?})3QNF^a:x` *Sw [8u{U.__lNQ+{`D硗UuMmMc@jMoqG*V41Z1XkeSa8v@ mqĕEK!q˝ 2ږV6dxr5 :8T {8/'cZfl꟡7Y '@ 8ˤxZTJ͝d61VA;ykϝExko τw @OaסyVԿYpvE76x{YgUdv zC/TZua"Ba{V1I} EJCeJ ]n(>&W] (Bơ(g~BR/}kKbg=eO-g6iuܰ>V1Ɲ>5#LT~~]= q>I‰BʈJ#lCͼI07,3=7?H@+j$S N92qVkYd1n/mTr]xfc3wD@iL9,zdR`H5ڗjO3kÛP^c1_'$|R"{O qzKPt{ꝵڔ(&H0k@% n($4_M'벆w^Ğ^kr3,~Y<'bV՜6:qsctlrIcm^}HƐ m)?{SxU[U5tl! BJq|:>T?S8ħs(r[Rقff ^TWXEyIJ8@z5R26ۏ{/d8F<:+>a|'%CCvB_nC^>c{Go3DD!=WzOM^}ɬ}Sط;)G<{lec s쇩='ndvrQA 7J3">(I1f,*/AU2f( Oct)حS@QYA-TNIcb/MX2!_ɘ:Q^i]NQ4I>[?s%n!%^:3+. EHA-,*H mAcm;-z HuOC+&3ihoR-^ܤ\btjz3IcA lwPVPxuj{3+>/E?xMf5T{'m" )b,v|6UuBPZcO`Ts?RK|Cgܥ$U@gp_ eeiB(G}™ZuUZ>]a]JmB;|z4;E<ՒWQWx0 ?],J5T5WXR]qtXF,&]5(.I6`]1Yn?TJeFI4u<E}$ MZF۵s"/sEx6[K)-=uWE4(;cMٷ+jyze=tBC128ɺҁo`qOyp{5mqH6T'3d*T\?Ѓ}X KGC >Hl8HwI6|/`zvMp NMPdA>O'׿%0FOxhs&呺^iRts1[nIUx/wXdSRΐm+<*oo\B(駷( {e9=9!K:ڿЎ]#۬75.%PJ'-yFb.L#i2[Cޡ/CLܳ `/3cSZis*]}4hVEcԌ_C?)w""EGPbŠ)kl^hr]MQIm3e(ho "֌NP=ŇxeiY:8D{@q2 ,O V~Ŏe򼭐QUyb BsE/E?J5NjS[b^O/%>1R߇qQ{` _"OXhȩ ;7zX4أ&_8m{揍K5إ (ps!{CeFz2&YIHug<\wOnA Cz!{/.Tͽu.y0.I@ޘ!ʽdh*9>n^TԊE.t ( f>0JSQwY,M=ݑϛ:]Ev_RDu Rní퓣;dHg$ъ.R>j0C pa̺ HF!79d7a+%ļy0w`G[r4]]ԓSPO hIrЛ#c~h) JjƉ<(') {7 Wjf{h\AU3ւWpZ6 X H8g)nysÿk[<-^Tg$Gž՞15&J2LhN'OL#L 4؍!Thb $:: MҳFDbo08ޥ%,=y@b{؄a=|{l*޹E鴣%df55ð{*TU%f^PEE\:Zn>`?ChE8Xm{ EأE-(M z)E\I'7AyWvpZE:}@Z31tTrRL['HPяRW d~)*ֶP?=QE䍇@E $PH(x9M6]ck ER67asp7HuGX8 p!ѲE_gzi> (kE'Sѩr@H[c(ySyY)'ڦ@߀\T#Ir4Al-hvM+>b/~ ;ӱ{[EQ:$r9w/lpOX 9_ ;~@UxƸ&~s+ԫ# vɇUڤtb I.BTJ-QE2}n`;FPAJrB85\rIhhMdӲ*Tص *%+qYE 3s2e\2,%:PE˅y ѧXX{Xn iMmZ_Uݛڝ*W >s.xLJ{p mckƆ*,q_PF\b',o&p*\vu5 R|nk'bJd溴)1ɊpĔ(=M%("coaH;V8¯Ԟ$T0xNXT("^+@D~bc&bE2w6Zz!3kE+W= DD\+ l69Bw{Ez-8!7?Y#)1V pHܮOm !4K)#), n^eRoY\s}P(d嫃TM#% O؀s(f{4ߡk4 `ėq<f5it:5 |M4+tkja[کve7:`Ou69S" =r5 J)XW(/v@\4#~TRwd^seKѨo;4 ; H>R/ ~hܩe1E}KXPhy!2&\y6S탠{{nz5}]-":i*s;A8.,[qn q{F( ތgކy_Ը@/aAKXYxwރ26ͶdQ$-\p~>/ŽqІ";_ۅm dyOᾺ͇kuzÖP@Nٺ`g.>Z|9s4YE049DLw{X;Y@$wM(|l,m?/Zn5Ve#]b} (=Ī9Q8^}utUC5]uFLwK>(|pC%,Vf{V*نx;U6OID3TX4RR Fbz3Ij[!.'DbaLq?o=w*`EwHG:|WL8Tϭu6ڙ )nt@e#KޞvM<Yo#M˓'n@$i|0_}HөoQi59ͨd^R-y`#_?Dfbf%0q-m㮀-\jGRdK! pG߬WiG&LJ͸}~dgk9^^.OW0 bP[Fm4rC`'0]QkaSJBQϕܔBHr ©aJ^EePn>2+@CqVqFrMu9.:G% K9 9f'lGj8 JDd?J]9|$epr 4Ş?Jފ53l_%ڍoǘBAp4UIuHy kԒmP'FKЗfњW@ (=ݠP!G5u [o o0H2OZMֿhm\n+65nȷJi)GUX9iqzL^ٌ%^1hMgx1_Mi~qM,ު.c "xH%X'*v"A>3$LPD L9hŶUYfHdz#s^xNo*pwJUl3n5dMұU8 Q E]`SAVK P3]S,B6T2 :ӼY友7;' uIJ/ SܸnsHqLf'8Tg7b3Fofh{i'MW} zhID %A}OjcH?NPU5pxpe#k՘*B{ewbKw#X9b܉1 W̑:zH&DL6-o'  ] 9[DL->"r~ΊBڦ zF_t'ł􃥎/3]?WK޷._,.WlSxU ,"{HWfJ1,/؛8E&Dhoi)UC?5w$~&kt`1pFZI|.7qs?A-R!W^jt3@S.D}Dx\w7!e^)QNCH%^bνfۻ{DR+ n0 =h4l+"9K^=Wx$pC#_RnyHeJ3o1kಓPAKi;cjTb~J銬nƂqHn@?@s9!%-tTRKǫF ,P/2L߯=`ׄt@^t&6;{v$ QOكcGtw]TYD>>\`mz7f# }CS&lx~laMe(,K;ԨS+ *& Z,3K[ں>?qk ƣJ[5>u5P;@i+I)ito/2̢_OB HRJt7&W8M ,uBL/+hf$~@PϊvRn'LR}hL[ǃsu >a2M^ >7oK|Uuؼz܅j48x9EO|@[k!K@&V%B{"ߔUQf1Db;!lF'I8Zk`ek\ZtSQB*"32uY pIxϳ im ]4\**ÃCϻ(|A0[7soxҧung=*:?4w|cCy4og/,}ݲKG5fZOsf39[ `A6Q/FŸbP9Hyԋ#Lc ܰ:@RFd u}?8a|x!~=HG>ܦjާ3 =j$w=@ą F|[qZ 1'p8QM̠)>ƀ"r*rN  b)XsrdŘ8a'{wRY!~>O0auCifVɮJBM3PwIA*\>)o64ސ|Jyh xG! K*OK V {Xg+TśB|OrIVvIFqdK\RE4bڢVo4|#goap{y8^S(ŻұhԹ; {;7g G-7f>^- Cv}1["*'_r:j~:_@A,CKh[.k0+S2`A='8lAKRE1a "\AT7PH.7 ,I(Zfo0| jpJj RXg@^j^sn["&T !Jq\Q?&nόLU=쉶lII\=Z¼ ,:Ԣb (1zRmNn0g֕U4HMsΨI\e.Yd+b5]T`0cCEv!irh_`](G^K|e5eZNGS Gh@>NKZл~SOM¨,zU,u>Kң9>XL7?FdK٭NۃR)ʗ?+ChE.9i{p'{yP]tJJi$̰Tto.uw}EFo 9ӏuD6?; sabAXji1d .Ӡ:Y/M$׬ 9"?Z Z75jp'MXLPz{xJ&yWp*6iNWti!*SjZ45ek-՞)had~y1Zl^W|} VЬQi@əʹ#sj z7o̳[$Jq`k0@{}G‚Qr6=rg鲇RulNo\Fd[rf٠dԴYJ<ĺF"q+& XlUJ31X_]7ԔnSÓ+qCm" 357UWhVY+fyה貒! :{N4h]~U7nr.&r5"SܪJږCVaqz-RLׯf E ]$SwekkKĬ擸bmjثRv.0fǐ/(d>nW)H}z|ȑ](_Tt ? ?+cXQd^2 Y:F+:՟Ǎ~1g\ DutVyjtr, U+hhP,0W4 i߮ 8Y>)frƍq‹T{-3Hv^f^1ʗzrY_eVi(*3]i+CѮd-a v;Mxd}'.gOkyOk[PvTh#>z)..+G8d W7MQlYS@:e6yž,y ƫ)DM>c~ MhT+""vaMZRw*B|LW߯jwᱺ,ywsSi/(wﷆuMSMX j1_lv,]49' ½\eI K:Ϻme*̝8BةA}|A!buUMG;{FQ~04xW7ԸO6n뀨yf /\%K O(K]屰KWamK_M[@oWUO.;ZNhPeW9luwEsN"ej}5;e:eJUI-uCv%j}ÈDžK(mz'-CeZOs/tz&У,4fʧnlw 'Uqy ;s`葇y+ua2eYɑmpL?VҰ+[1DI:P)_@k< UBԺiʫ=khwk#2V;r+Օ;_1 R~:WwV皓ܼ𼙾!Us~|\KekEPs8T߼8닱J\ArBXB'.}{X]qWb8M†\BDPXeK q$Y+^ N&ށ %q܁(cuΝn{opM1uL'cբ$O#$+.U"ÅhbО =`/GjO%o72kg#)y,kR [U ^l\4n僧*4jݪ壞CsѿG6}D_ Mlyfγ;?15_)}W5_뉯džg,db[{mлSDh}`2f/喣!nQLdXMbUAKP^b}UQbB'뮮R~72-Jy-N†P=^Cr_Svnvuf?gڑ=hjN&9ûpx0C6YڐS-z9,<[- _҈v#tÔd"lbA7l`d$*B9/…_|C KH-BO%r X6^Lj䨽AQlcdnS=B#^Wr5 Mu5{!4.)3',$?Ƿhxg?܍Ëx KhnݧRhlՆs]ԁ2=Qd-[]F KM 7@ dh՜񭋾kGǴC~]]$QQ}-hެl>~ TWd'XDĐ| ΃TzXmcq5`CAaC ԁq3 i0M0(E#JP+pDwR8@s_?qB DA)NDP]J'0ڈT"MP%F6 %BF]zVO&hA%#( ctňɇj,]wVäҺ>XCr8wa4؛ioPjo`Oo _N`p UhzizQi ih 4Q0OMRr=[bo,$C (Or1qLay%Ȋctr8 J򩉲e6p}7KXRODD"f <u]Y8M^#EM-xxԜ]mx2QkEKcjmAY h6G u\㖡_^∟߲ɃY]fGf }e{lsGX]^(LC*&ɕ0E*vcO7XRP Dh.~ԍVاiTb3[`<y٨Th쵫ONm?QˏNFSduB~Fp>ME5;:nfc)Ɛ\3(Ca>e)& Q9ӯ9jMδDJ᜜aUVl0!S52h6L@`|d5"61iB4n[E heoKnHn qM_"ֶ)LBA'83SHj1&ǁ|580Qo O Ls0 MQ4QP/Zeh\8n=u .(Õuj,HkPBarP%as$=KNK΅J,]Z%-uFF*6 p"/5ecrzFd;u%!UW~;\X$K{Q9rs]yy*1ښ(Qi/;&C #$%Mg|zr!7G˔?qfٝ!0)>:]iʄ:ɈNygcZ6/p#N r95 Y;Idc2-ߴʐ>$35wȩ{)n};0^c yJd ț›l7xF: .trRp#;]-EBpC~*}Vwn(y="b| 4^2 uyJ[{ߔmIT0~k.Rs,De|TrX?9J'h{3?0~:Փ#9-1:PP>:DKue2@n(*eL`fɧ=r٦(D}Y 03OJmI)}U&q=xX/=W\-T-sŏ<&sϓolLH3ݻ]KRZҬ?PCU6a/ِ: o)_ȕy޻mjm. YT%moSUaCweP{=VY{ݕ鰎 >:h8RF!(`Oe{~ߗm* :R֥cx]ll\W%P^X_4G[G_ø /9g$xQp( o3h:0_˂.rjQʋb_T.ms@;G`Z ~xܪ(dh !n:WTrĬMMj[^+%a5n-GRރ'h,A ?}Yw$$k:1ًD1ԟpf$Zƭ5 й* k!ݛ JX}$?ׁdOҘ44S!ҹ܌Lv{ZҢԽ"+|kn%\;*1Dϙ +om\uʳۺ崛*1&D5=nx%\,P0x+E4ުuVm"Ӿ7D{ƴ"nSRI)4l: 6pI (iqw╫Ȩ{Ö1G itvjn+wmLF\GaE.}!^Lhl i#p2po$ON Ms,p$9EX>K~2);Ws+bdr7Ͻ]tKg/чXBRϻWx9 O"1IϣȢLR>O0͆ݤAza] ,RAȌuOzډ#Å7T13a}+^B.]{,Pb%qL,Jvea(>+o]2, >}WH3W!=JG/FhlXhǔǙa!yWX߈*{γynx+0%)d>gba~9SOn.@\ vtG N|F?Be?:A X{/#a7t k„G/k+TŤL߷E)ѠjVb[7F;"A!tZl9JhH;'D*(μ),tRi.Eg@^8UgoOX(,> ~NO|&or,&Yz w!wTZT&UTe <,bڴ lrQ7'˗:vcgt[ᚡDPGL.c39ƶ+(nȨqrr@ !䪍d,lL89OMQb+ dG|6WN^=CFqnt( [.&!3 sSywz!5I-iG獫k'w^Q{t^*]ͩRxW|^M jpyQ Jv? )@č" J, O/s+5h!.dd0&ǎ!(8PkPJ$S\s%,221+mȓ=Ag} C`Xp/go^<6_(|>T6S! $ 8l)ʰ:R\%!uuiax)8\6je4㚭OSYh;42 θΈ^r+s@c%:CY-6/2oܶj1锉)f/ۀ@i '~v2ZƩW$q+d՗RYIT74\W|:[oeC!> FI;`9k)[A*`VuRKJGPfcW i*0 !#ג]QߒJt}Tjr *Ŵ:zGaTQFb,Z\?i#ԘsF*l^UW8hFף@|W}β8Ae;bJ\(n=ݢw2H9y@{`!K# n)$nf YdTzIMŽ/:!g~;TsbaZ]!l 8w6̉N"l.̹ XGcwe= f\-0%y =;CX:ny!DŽb u+qJCAQ䴐s…`ligk̤]DSg/{_J=uyl֐J]@ºr9R:ζ'Jq)WqQ SB 9!u}#ju.oѾyŠ^2̈Z83CBG#z5n@Ed"sV^0]W]}ExgRcDY1&䳰<؀~,}_ ͋g?u~=(g_YdV{APHFN`\QZ2f! Q$v4Lj]ԄF*-(:*ӄb O;.c*0ފ֚R>lDXlH_&׎D| 4 ĹQB8q/PFZ/n-{5 ~2WaP1y&~%^uT$.<+$km GT`S0M6 |ᨱsӠCt5QI,qC%: : zN`wԯa Kz+t?:yQSu. HFtT3xUi#u4gl-P~ʈ(m(x}`kEV%}$}ٲv1K587Ka6?-~xԛ R|z0O"MG]O\r :~J@"@FwQ]}qB)Z-S^ėG{1?"H/yo91wacMq1DH;)zsa9MsTޘ|Qƶѭ9+G)֙8 uA4Zk#k*(`gQXCf-k'!Cl$zlnLBᛅbI7pE˘l,{pNn6CƜRAy"pa+JG/#:@+,Fz3$~9%Y%J{euwz`h\0yGL`l֪>gt!b8*%O1IdikgO42:AY;fPWuhP53mS"Ew%?ST5cz$DT4~a,0 7,T~I_hw|ӗdd2&H.sԴ^"X>͐8aބqU_g!jRqRy"n ܖX)"⭥oVZ[a^Ү9anS B=qOO% '$'ɪfva, ;M=}1d ^-^ΣzLGE;م1Thʟ:wxF)2ߑ@=ddǻ (9ky1>Y darpYz00'EM5 Vփ́dg[R"lI0w{q22rgJH6O_H(lR Y8oD蓯L AUإJ9-C(s]Nsn^W!$= dVqY ^yF|v.~2u 6'=!#)ֿmWې6 E~}_tee nE1Z^ۀdzlv`pWUB=Y֢N˧+J l1'B@Ht99 53rŕD %E(쪯x% Gj{aaF&W)}对œT.oUdD=/lڵ~@ڷ0P,'Ȍ; -TC1t}6BJX a5 dVi svx00i 7,.Y0U+Y&=[~; ]wl4$ 6(?FSַ>$)| ϛ]ɷx}:顚BT/5]K۵S%\xeZkN {郠IആoHvŤԸwEEhv^טv?@絘b$ig ${\7ţ_'@Kp2+1F2kd B1mZk@ck*N-"1nl9ID3Z_Yq OM|H;tjᶢLEpE įjcvI>zVXXw Fْ Jl b~N yk\Eh3eJ*q3 Zkwq`*9epw5q^] S[,gG`h@Ğnq\8naAՊlh_;5iM(㺷PVLvV^ Wt::2CUdiZˡp}-ɲbo?,Stτ C??R4iLCI3quwI S=tp GKq<|ROXp ;y;o7L\`B۾.|lI$yBl)X7~~Í5-b̲ _ɐʗ̼szkCL@>S)̺rRj/;\3yFIޯ'"Gvb(O?\9%e9c2n 0yҒ\ͫwO/a uR!j^i ۣ!,ʮ+2Ⱦ.X>l7Pو yd+,Uxqɫ4w I7 :0srIIgX(qB= |DczBe_ٹܒ9U< w3*ê(qFN=$F*3M&  /|g$IL+{M`'ɓXP s`Ns\Bm$tvV۾\q>& l&ou+&$ܘ_(QJj#jzKN28Ҝ ~П9Z|H%Frjsf,.@Rܶl^!(:LojZcWs ] |4̀qT4=c鯄^1vDWƾKk3^/wʁLδ%;4 (p.Ey_1g.^0Q4zRmwl߉Ћv+ eC@H*fz:Ђ= Ж"=bòQ䑛"ig>g3w&%гDV}h9·e) 0W;(SmDs:w\9 f?Kv Z;I4cZhUP hH0+25-MI\ܣdcźW+W XƜ [L5/%Lk PV;퇁 Ȳ҂4C=)i>L*,+ޫ]W̩99J -M,ۊ(LR31C00tOިG{+A`}b+uMD@ Mz涕;}GTn5`6d^:65j8ZiۨQ<*a|mn* .6[.p9@WBcT[6Z s(Y/(HuS<>6>pѰK|&2^rO7Jor{dVMqnW>1){r"g$<Z )ݬCK`7 {sTjbu%;XQ0eLA*E`T(I-$>c̑Փv :x\h2 TH12+&9C@ؽ.:Ob+Oq1ѮIH)m`oPJЋD'Q" *,uoLsX_s<9Ē>wrѾ FS:!g'0mRfZ{ybPWJ(S2ri̻>2gA0uCTTۓy$Ϣ[p'Gg lǹP3L}FL@Qu1 dE[N/ ͣoJYV,DL Èߖx]Q[OP랦O{F4xȝUb[l뱑XwP>|`K䷫u.n2ēɐDdnih#PxJ;c$=k& QLoi*H-qVtY.G/A" CH-cicD!<^ zG =|_ݛoQ'ECxć5dt܋`-P#8Ngn2qh1pNN%>V_±[흙-KKk24`  NƫmIUAHKuHjښY-blLۂ\Vtwm: T5׺hG# IsMש%T7r%H#>Od53,x>øZ]H?1㧣.[A LT* &ϱLq<#S\_Y5lFp/J`}(ƙ|ƨ)(CeW[Wp"i&m y+!h/P >Dmy*+b'E0"a^؂DRzo3=&?!,֙Xi-%FׯƵZM=)mT:_GMr/K!J|5-@]evZ.hX4ڢ+pn`ΎP(#$`1&WTOC87JviI IJTy160Go۸<5$|"7['֏H8t0<"qػL[J߈fmI⧬k4z0.*p|p]'i:bOൎܞY/[ߒy`B?nLt*"'ߥOU*8n2mx>^iZ}S4NEMlx!$\6ԶeVH_i]ե bWg&j.+tD~t(A8 lkV.}hfUH$}"u\UYҤ?|d*}oʢh+j E2ISuNjPK CMځvi?@\eKSu jLSX5mjq/3Y4Ñjj2 ,JDQïvL8i4 9r,{Ν\\P1b=-NLzp1-O'h!ll5Fr / ,uga޻ϋYS"nuM7&}\ы~ĿJf~`~VYVz U=×^3ڼG?wY |R~z*)cCw7t5346Tܪ~Vo"2$n՝3(6SXAޔPq42_DG(!cMzruaDcg5Ҽx G7s>&;JҚ+ZN!j/ב2Z\"qs!E2 a+`lQ13>d\(w(gJ0MOљ*׀M# 6hz@fuqO:UHr1 h903 |\.RXx]8dν:* m_@XurXv#:]Ѯii /æ9ᄑH- ?BKZTDؐ~Qgg|݋sdq=ڭkT& gbT1ʭw6#y`Xc_O}jslA \ FJÄSօNS&N1jGq?l]vdn=˵6s%6`>j4<3iBr<,[VnϗT\l#v|U QF1 j<])؛IR%3] ٰQnw+i#>zxm¥i@/{R $‡HfHp䜳zÛP'Tk$4SZiGZqxF6 vq]6-!vAwFk%G:.dH(c5TY  dW=9O> 7j@=JF4䎮{HaG_k8,,1A' ];+#.ob"EE_Vc_&(.4#ݛ?Ɇ:Q˹J yqޘ>Z|v%{F&PHkA1D~'#7{4%롎xB6w:HהCљ  R4ѷ GSl3wky/UgY_im2ԋPbiӻ:0b*#F>4{ 0&mnz6ɞ>ԟ6EiG[ksLriEF.S¤Ie A[G=K)ԆUq\S7 [< ˩SY>Wz I J[$Axut BS" 13ؑ&!!qXqozKO]CΑD)쳼oş1z\6xlVŮڬ5^؈'&{e~Eu+Ѩ[K'/ڐtM~?3Qϰ#I[>,2yy:vbQJژ %ϳl \aMŤ$^VT ^6^7QYCe{t'Vx0\\C 7FpځT\<'m!,br1jLfϾmnVt=>nE'#osI| 6fa ʖSkL+7IGHVlvN_ ?kߨa>_;& GB@+] DVdVϨ Ǵ5 dnFgoh( U8ʅr4 ]]͂-a1P-y$(ACÅ4ƝYw!|#'JX1:Mvם^IuG1J\ѓWvQr@@>Wj>C74A!7ZRy:4.ۣf72ֺ xºPs*xR VG:JIW+&MAcP01GϹ55c5w:Ɩi}-sHlv3%V], %A^EbcI\#o4'no'(9e9ng\jzMٚL'Ed!2#]Lttx)$Tב_{$Ȫ*$W }%ZnG@ֶv7_T%>#2 G.N$mXs)D[x$[ujֽ ˛UZ5 ^ZH.+̪>n^s})%sVB}3 ef/Իޘbi?ǂSk2hXcEK lH߮v,UA'2+O G_' ѵ*jh6˚%M%D@Y:v<.1XKb 8gtJMqJkEj=@[@N(}Tsg5u{2LPS߆[rmS,̊tЊp\jM.V I$sH3.ok*ANW.&F6**n% Z`DfuL\DS<9m4P^ yw3݊%.vA]\x h3JoCg>eK(w7a_߱ @荓CJy",\ B. {7XUT%F#*fe0I말4@ sڞ%DQ3"PPBXZQƽq)=EJ¡D#ۈNT_ ꦰ?r Ʌx tHp=g7v}f0-I0̧yySEFܺ={78dTdRJ-a BSo1Ymbڨ5RS&V@c26M9hF(q>8-Q9[nkesKkЙ+~,Q#ogt#wc(v@>Ӯ7-({OQ<w zD]>0k샣j ENO5rUP- MOtnhl5iB݂-6iDAOSz7_FUb!o^2p}S3LHM9 엛"#V!͐dJV$ cKH8K0^h[+17$L ?V=>:g}K8>*OP*(gنIjiUc4UB\$VḵaRIΔOT<, zPD`˳ ^'#`GP'J_I;#{Y \]c: K{9I_-c59ZAGSY߅Oۅ_}Vgb=3|R4* g8@H"B*4FL4$աГMP+$'mHMtM,wWY?3YQi^tEQ=`[_5BU$BT@lT ,`O>Ohٸh+6X4gZ.=͙ S-ҙuA ڦ9 *(߶767΍8Vf-kA뉯$WYXV=ƟwZ*<Ѻ0DCjkZPTԅ6ǬYzO:H}@{ls Nrʹ_c^t I9Oҹ>grc~KTg ya$u;#\CԮ^A28q%}d3]pa'n4S-tWsɦ^I8TP N뎛e|_z{0e gL9̮K]j,:m6-OU9ُrQoAKk;.] SaNڷ6 dsrig/ӡc;8n53\+ωWtȬ|P*~!F9! = Z=˿O[cՆՑ YflkБ^sݍ*ԅZd4c0Q|R}FRTZɿA_~:jho Xb_xn6c1`zpkď: LDU-6o1nZ M^CkUIԾі'm9; U=&flZ\es0M&HDWZ#64Ʊ3*3?d&+J]1*;&cOT}-F.{ݰH23Ҁn_0A{:B6˰R!fz9'Q’"ahПrXa֪Ȕ}avP빰#CB E݀űDT3֜)b UӒZo^.>:2zB̲&zIm9~~z/KujS zs*p eMH^;s7]do k*AӬ =ėJ `] eAg!Lwcݓ#0'/sZEAxߦg5eY:-p[EF^2Y|n1jK= j1v QQs4.krD;ս#;G5N0Ё @k#v3GPݛ (Y҆JةO׼4/>LZTRٛgXFG_9&O"VEk㾼Kxd~URYKP0)[G$gPӗƜ.篵GU*gbXIy'8gMKPJiгS|\p*Sʘ5g)x`RAӇ}d2ȇR<979VIdC=-J %bB$E],  mMͯteŪ ËK;"׮J&5FEZtH. A>)lUU/CQ3ٴxU╺lX69{<90cZ;5mk7x[3$$m/& k_g7ynbVDᕁnm& KV[FYd,2*j^ |HzHrrלYhd? /'h䆔x߇[Ij?lQ[ꈣ)|P`NJd|aXfblZN<1x1?llh)O -m'~t8^~=ƘŽtl΋OS^I2v5d2".a(:uտG+pfB Ia*Yb- kYFFJ/ gV=,-8Q)|F˒/{HWMipʳ6f`H08:SbDAG=NUh`=X ftm^﵃)bc P% Z$*;Zj[RzDVKt `tHRDh5$:IXpo viKCP SQ2{Gɥ~729j{&i7)`4X92ϞI=u( irtQ{dv2L\wx'퇎/-=$Eq|2f\@KC^:<^Us?hB}@ۏrga:( I@ĔB*ޖ>CtD%hV[zwl;vv8aIM-D49lRuw`3-tUN?9]^֒a?B Id~9 Gi6oP{&TZEfD4_@hX ms?BO{2ꗢ'th{T(QEr6u-7í K%z[5iu^f:g'&OT:BhL_oz7cR:[(_hmh&.#(BtSǮ5_._ 2ׁBqbT@ڭ/7vw$g*SInyj+Ȑh&^g;=ŏk;VJc#NhhJ"ۆuAoTDm3TZ)чWh|qITgϮ;Oվ%A-ו6Ay{҃btXm`t>\QP^V×k~5)̟CN>6K 2V$O࿫M- mGʿH2>M#Yu.8RW+uc^A\&o кP [U<潜OкVRy+q̛Ө_2lk84FStǐ4-KO!uaxAʌG\R_`>j#wR A/)2\FP+!oԄ֖~m˪`CR Pr<5R9?8oﳼs Djz`-ItzvlwۇR |5tUݯYd!yS؊xPk`jxBg] j-Fnu #fXUj? F xba  d›JPFInz!> ;-IIeaib|";S d$ieǠ$V x Z$~鷝.ͤU j2weKiƳ5$مF rUG#oVI|!-́JfɵhrW0G$5Ef"sDxh}u@3If[L$ϵ]\#}߸c%WsR9k3UiXx>Aڡǽu `И] |f_/b AZL 0G ʨ{q=+vr"J:FYԕâh!)zg {:`pZ|1m"OϿ5&˹P9=qKArpS7X' %g2MTE7 ҭ@]-0ҿPq}yl)~ &ƿVꨙ2(9 x7c(4;0ͪdGRcJ@dU+TyC-?2}?K@nh\HVp=)vS`ڍȘT}9-=?v> p@Y'Ck+IP i`2ݙƒ3{FRSzuW]1'y>,d_ ynD7 zK Er(F&=8y`$H 6xQh\"%68Tzl718|槳 Pz#+vWE*;%*gWd%l$^j쩼1L=vv'pi"P ppk`w"QTA^juH6a~T^N_2[ a^j3N)T.׼^V^$v+}Sax\8-'sحdΓ YN'E'Z x3y'z bDW\@S\>_24Ʊ dyH YoŮi\ܥN.-3ܺNdY wkt_j0n؂& ,9/[$fRy=|<)}\r̳j4iO\ݙ<5a {C_IMZk㏹!*<v?dZ}BqW}ˆR=T.{l:"2琣0z%*Tؿ +wj]~^H߰=Uָi5 XfX@й$2ZZBLtǍ , L3? ֭! % ?e#Z vEUlE,M`jV28+'L 9(+KMIxڋoe6[=fyhR4d1T2d M^2a;JNop?`1n?aW?rtץM?Z?i;*xÕ^xY!{bh8HCT~@kð^WxD(hCsOexǁ[H$[.ct,wÿ`cUXI5nJIqؓu䯕-:Sd -GD @*X9I#.ĸVAaHE,Hٲ匿LwS^x5krd ]\t-&$LZ[n4.*Peױi5K=BMͦ~KL,lĠ@_1H8&ḾޚPD;fjUd0 #0:k3{/5m?y0uUzW|v,~2y]-D:AM4-6mRu!5öm 'ퟯ#~mPFۣڧp`DW"\u1%# ˖>~>1 fzN3Y4; p9CO?-Yo4.81cIO4:(r8{=[߆79D3%X_T@8ZGo2ɄJ8Sn> ;c7Y)F,w'>rbFmjh +z2-> |o|ZB2ϫuMҦzPȈYO~"6ĴbdU*`.*z WL!iؿUe(T[y4;o $d*n~t潵z,5V dxLhv=uymYE)d@ck1ǎ\1_s0 *ݭQa^Beu;^d bǺA;0>B*s|~(#"P~Em2(F^䣜CxzK_,|+̻\K=pTC !f.2uDp;.V(Uw@ WXaڌ7ΰzF]9xo$ hCqI{y|hw/TsX;H rP‡qrKJjP}t6D-ӞpWNC3fzV \⦛21/oE04w&1:Cq9Ͼ32SG@7yx!)r%+;$N h Ms?v:\` 찞_ɬxjM2 C!J#F:`{Z`ƢgFc})'M󨷡9u4<?Tf$Ex䏍?&'-〲&.["I#fsw竁#UI6*AlqD! |ck/jP*戾&ѐaz^^3OD9nـ$*W7, &mgnAkau-`\KJls D& sŹ<?&}f4wj;k˩X/BTgkUxH@R6nda h˼`l$Sqr/_\p&ݼ~{ה}e'@3xdp-%+; v3/Ec_ f~T}nFaK™dmehdMo!zSk."k*rsnPY6w,Lh%,qZ 4ڄ,4 <ܱ\:<[`IZ?V,kuG 93TìglJ{1\vqAr&7Gx ϬGw$~ Z^1:v%i\_ alIUb) R8V ]YU "q 򎓇U͙ZZvr3G5D5wW=`m ],yVI+$-&^{0^э]$rLzGJH(N r|$|˞_vO+k^VJ00B\̯9P0ȇ<4k a{r'М 26G)JFIР,w^;Pk28(!>lZJ;( yht6 LVR5)iVDRDNWY;pgcE9N 1x`{d̸&*0vOC`{F ظ${=)A6.dp%>CI (d|NS" }PMC-'94 0Y{ m-(zegқp\()q==Y%Aِ-W~ ʠ4R‘ͱ>mܑǝڊs[3a*_h;Q4S۵;w'$- DK@8;gi1uȻq!3Dx,70av9h_I2lecE6vAKբ[VR; N jG{+?N{!ݠ&]jo:j1Wn!JCc蟔]:UWvS]i{9Xsb-wY"g~oT4;+0裳P]^o u;U…=&_L&XpM''KY32 { D!+Sx7lTwjFYpl,Y9i C:'0/ ˕S٘mP=?s+hq,:q,y%6|z nuԫ5DŽ^WDIZa/'kۗV]TW;/8aWF ztĵkzsr̿Ꜳ d*J$d&-|PДQrqvGk/UpC',!FkaK@RlWo~ F<NdJnŶc`ϢQ6;'d;C:}.]e7O?v-WFF~d&~;M kQBM Z!BP5\Lg}P]7^7'hԢP$'P8Xj3n|W*Anhs(v_`Veړ$Z5h@|i4ofKbٵoWST_KwЯR/PVr?b Y""t+;}y{:Y7*# IHo7˹L񪻋$!+ԳڤÁ+hTMP9 ?}DsHx3!ZFiE nDe*A0#c@γ>A3%ԝ>2jlj)dĴVbցG2(h;0A祡IDmΐF}x]U1᣶c˘x峄3^V\-#͊dp}e]"'Ʈ$ib3b|#p"qyycݣa0|ؑjQpg2t8,K TH鑯}& QCٜͧ;~"qeLIkw# 0['I\Ng(Vi<f?|H)oZ7xĴm \mX䝺 ͝|\*5=$f:K'g0>k5,NHK} 0[fiBw'.58݇-:E>4yRmEGeOԯ<9r#0E fƇэ'˕RzHn ȱx;cNw sԼqrj{ք䅅H-Kɕ>1C"pP엒hy&[36K`ZR:U)8#+M;IKz4׳;V}}1l X򜪔4&3bucqrz44 Gf+yߔu)R"FoPBRU=[B;!݆#qĴ@ZLI2D-)l+"䆪FicD>e#UEgqOOJ4oT~Lw-(FHFi|k"-6 hxJy|z&C,}Ba96]ҟkT3u(V#lC̋.;'\6ޗ%_I^i]#qúEB͊3 AЀc_5bƯE]hku@Jc̍Ng2EH6֘Gnݎ`Cn}Gģ2RjDK9 eFC^D.Q{@(3%:޹@N&/$1[r`f#D[hiX9Վ1ѻMv>JUI=5p;H5<U,yfGu-mýY+IHis?>`m 7lJӌjq)4ZtTMsgDFx<9u7S?N*DBp٢H:4C|Sc!iLac#j$zÚrR1te[ߏG9Stsl$` A&:IqUW\,4CՆƌqU ㋣MKa_D9L4nWf$l>ND tMQ(D^OgNk-- *v?{}*hϱK=5UbL1r۟jlt#lfhж.-BLi}|$\AJ u4Pәz@p7 ݋Ȉ-菭މN K-t5cnǷA5;l=(膍 >6 _D4 vEalw'`g).P`՚%p=gB@NcKO}X": uBOTNO>Զ+"-1[s3F?ZH,J(I;BK!KV.b&%2"E:mYp:Y:$G gw2@ZxV8<S8DQ ρY~|]ci.Ꙣ=oߦfB!,_୧v4/"^HHBrɿMXJujJk ߉%$uݵ@܌ o؏GZc\,PBk&51h28Ί,a#r.xՍXHp00l`W;3u?m2uҬ pAQ1IݨVE5Wf[A tk1ljmm` 5u{,#')+,i Ax♯;oK{Gc5QKwɄi.fQKߵ- fz0.A=]Jc|`ndHg~PT? WhIhZ`GX+U@ՊM ;!=6~є32: K燾ِ;kfȦk.~}h" k%l}_pdjl?[d(מ>q۽WXӵ'ʰ4P{?=)1N}*Gi ߘ%ޑ|bU^ :_Ǧ̹ںyy7xm]52 <i7_x1ȔN!r-yx%1+NIal|`ΛRQ@vvh¿ (ĸf,/%q.H.ИM5 ;%.W,1yBo\nvjǶj ǫt! 8iSKZVk"-ͮƺ(ҰfZ=Z BMGT3YZZiE[x| g_p{F|=B`zaKf{vjPZ+aΔ Vҹ5QuSQ)ʜG/¦[<8{hg l(Lo+" CkfL(s@v%=:İ断kH zͱ2SIvi6\ _~%䋢_K䶢]y`a5h9 @tLFU +z0BP YRJoͮoZ톶B({.U'R'eekF@ Ħ]Xx>BfJq%aጌ? 0- 6is 01'X&k,bjţBS-x4 }C[C c&RD%,w@C=;T։u=uk?? Tn~^rzfaRBb'qYN]Tלd'p#n `Q;w9{*JZ !t\'Q#?osw:i+l)C"]2\yRcӈӅ{ ^KLC3eGKvguUۃ*OA_qqf銦)K9=d^dA2Ybӣk"wNq\Y|؃8 z q*Ǥ[Mi灅GG3$l69ÅsDh fƄ+ 譭b6ԣ +AqX| n XTH|P"b Z#_vp |Iw\0Q_b&_N-]3O"w<($n`~L>Hb<(<#k T~Orp*xCNFxkqfU=̒U54 zlմ%0;0ZFz+u/-?wCܺ̕{vbp^^Dx?]/io#}uCIQ=kwb(b8?~3pT/dmR]̒YJ@d}^ s^@ y贉~읣nzJy{#"G%(CqY%|.I)ZIۻa9s%tJ/fԊ񜲫HarYF[dFjQfͤw PNFuOp&2Ѡ`,n[mWl[x6Ho?|D]!JsE 1V>u?eFh=hj*<صQ޼!50Q!J:hݏMnjoyTK)?M1eK-+-Xd&?㽔N{i qSG"u{6Or 'PcLd  l|KXrvc3>ؼTBz0sxԠlQ$,1q]aܘ0$r%eoJֵp1g,^׀H8S8{ j4)}>ƕ34U5+O x~ؚ x6v_̑TIGA+`z<_pbk|o4KnPj{yL ˮCāWA\bl` Fl̵>A*}M ^Ud1P'}vg8m(֠&b~<:o2a4~/\6# o+2v.ERK$-K10os? tM`9sMƯff9ѯ^/v/߹sp*pZ47&I=]LN92xH w/yPJ,q|lspH7Tix[e $k>4ƷP@nC /e:vʷ d$'32g녦.=@bу~.Ū_G.y֝rg‡ȕfu41QjUò(ý:6>hֻHI Ǻ@"jZAn5I w 0U!Ľ]qXjKP1 1=1][t(!]f$aO/b:&1 9rbLnݰ~NG.=QY^08/ !]vZu,X=<> .0$*_A[\DՕ瑀{E}op+"UJ#A\1-GbUuL#Mیu x Rh]CE-Z Uz)LCj?R]%&ւja!ܴV_C{T˯+aHvKJG[(=Dg8GmI5SBx(%#Ŝk>X6GymWM-ҏ%%g]g2g?f_v|0֣3 Sp7^4!ދY"NrUm~)ˢbۻeإ>ɔV@O\طfЋ9HS?rX?tRA&n4t?୙cȬlR ͣ~.yVҋmZ_X#-&/͍q}wNA?#^VA#mM[ܻ/>;13+eɘ=6t8$b N#;Hghk4%G% d7Bh;2qى J ֡;=t`#Sdqw\Fdd2+c06W^fމ?[2]3d[L%uȬ9/m,*qyȲss/)0ӷP 췫8ѹ+%Ĩ,fIeČ&sA۟~XԆF {Rn$y\HZpل:qDred,lgʹrb j*3j ;čb8%@Qb(Tlz9}B08 z#Ue+So8e \p6!&(t9ګg;X* 7eXxPda k dWF[: jR}nJ o)C` Z!;-D(Ed(#fQ\kYaRcWOKvۢ˃PF< x :>0ed!s (Ob>]_k:;=D,Hȹ%kḳu֛b N-i* 17W^˿Ú-nS~@o^+c$*s7?)jCL Q4#JZ}O4D#|Q x.vP A`wև2+/|,V޸{l[GhZ+r@7w]S4`U9>(e O_D!epǕʑٗK+ęLʡMM 9!o Ј`_!,%[>9zգJrwyNY+#{WKLC-.@z5CO;V*CEVaJ&Ng9 vkG4U`ckNæ("*Ub7~L2SeVNYg kaO^ndޫ{%j 2%0S46-q1H+?LY.S:0L)FgT@fq71hFa?XuN8OtdG Aڵt}a#o)4Z|w-')4ӲJXs ~1,t~MWnR5qPWnO [vȫ9af'}I;9-ʘ.B D|Eq8 o{?+48DBW$ڼEeoJZ)*sm@t(6}=*7rR'boH"iI5.ڵr>&a-sWt~ œ9Q[k.C~ ʦZ;+wb +*9}#4+-Ϋ|/~'ng[^|"])f:$W^:5J$"#S%/B,R-ʝJ 3p i[W >!ʅ"\i^=MJLMYN(ةr` GCg:%kFPr~}a迿h*%uɃ~˺BwÛ'y쟸d]jsnB rvt,T_brg5A@g\\x!h3JXXזO gp:sz MpߘQ;@P;0ixqX&Tͼxk W@Bea )reդ}qk:4X"E}_CP7-]O {j Ck'ݤ_T>cps(,}%VM{d ThU_녿 /y`u]PQT.:ȼRi!ĦoDY$@ktRZUYӨ,7SvZGW>d~ূhf8'9xnDmώoLJ·1縶m |,W\" R9nÃ{o> yeG(㫱}"yWȄ r;yy݌Cq) fc\X "#5wV=j(=yOt09Ge ԷXݵ &㳉Zچkw8S+[޴*nO K=\bU9J_뱃l&ա>^1OnI%"4B[ ")Mly[@!Hm<; %f[C<-i`O؈(7֑% o&8R NRW܋ȽP_seѩhG"fò7?ZOnw3C1y ي̍3!&]nd:ęƫL遾iMx·[8t9L6m~B /ݦzN/}g3ֵ"b(X*&mѓDojn_~W4c<]oWqo(g[ҍW-^\Do}F&3ۏI}he =_ܵo-#}QxHn{Q8BtǕ o# z3_c.3~޳v7ofw^: 0 B~Uo_d`)M0TB83( gQL3 Bq,HZǞq~`/ bׂO,|Oň!s~*?Yc7}vjW(+zQ!ǘٷ ߘ>άRfJ=]]TDyj<?DEhUtfN8ijogAc/y\C@$>yq 9 sw9`uP_[?'HN֡{SZ^Dʅtdus,zz<%O.`qnQjDZ}?׻,5)DZdǰQ8ɥZW?g2fսV;*IkjI<'l 4e2=$历 \_G"bZA_pMgQ̈%ȳگ$ρz{T`KJl#z@!r 5 TVW,`yb&|DP#ǣedggqKrZi^pTVƝѽlEwbJi|K(J/T=@'IT+RI3}|μO7I|9vWEhW'w_IۋF{7-f?:C5?ԚH{3; yNA N 1O摻PhӦ&[. .u10]W1JZ lP*m\CP`xGM- D@n3:[`=F3yjeed䱀Wt7&<Nc&[;L DVi ls\2K7[w jS^oS17@Bu]Kjx?,;BKgϔa-oR Z1y4R?Y+t<FJ В078ec)\QBlVaK( t~4˂u-k& sT>ۘ3*ic b`s<ت5=n,,6)"~=+؃!DBQyϴHO-C!С\V4 0 ل^;&qXI48]E)AO+H1 M{ WwNOqLmȲʥ=' lRs%KM妑^7 hhʅa2Z[MKJio M?7,1 : )eʆ0h-9Ey;EĴɨ#"i bz\2bcG[G6'D e*5wS blX7g9 d wM*h \uP܁Kȸ0^a5m$(ozK+Yhyx)[KZCOMlP^aSZ %hku:_kaMe͌C0з$5sü(P&}ֳ!{BCG+ m OxM-+\^o?"?q[;ӄ2|eTyAQ_ZeF'1"c 6LW@v[8PHĔ5s9 i ҙrN) a]8O< A6Bܗ[/m Q.A/75;q+Sõ FK>HQ6vIqskULE\t0Y#Z؎ke c('Ք51ny.}ZXߎvi^{=5bz%P-0.Evl!>Bn/-,Vb鮼h:HBǾ:= 1b.@lL ֚zP+wI%[׮6Z)6$jԳ}@esgۘo~H5ĶYJ nPnACXU8GHȁ= 8+xfgc:bRsq0"ΈD f}|,Mh4yzt$KwFGIU2i-ݟ" (}auDYQ^yH嘆R_TA[L7|ߢy+Z)8l ] ◵(Ĥ}#$c=݀`j1AuC+KyD 82PN&fEBᐓ؝kέBaT-H6Wk8O"-닱PqcE_kdTLgqKP.?q2GA.U>u)~ ;Y>U_zBd6e9wEwNѦe\{,l2liLÝ'L>d7O|F8y/cM'j5ZS(⻩BJ6ND(7l$tIJoy*k ̹E,/HtA% WJZɡcͨF!~!d%(CgB4,2DO;{yLRUfw/8f씙v='-nwLbYyIU'u7?*tO\gk:} ȥ?L'֋uI"`DZё!omA5፸ [͢럓tthH"vIGU c`LS}iϳ" Y0x.>?Z&YLŌ> FJ$,X9SNdd:ۣXR!C 2pfZk'$#;l`2v[.vjϝr~!ig]O `a'@ zCd\cj<,A5F|71nn-nnZb+nRi#홠#֘ } c}xNxK]VbLq:y2Ka:J/0 Cdžuu7o 5ME 鷸Lh/>4½2- 8c3j oC0N_C 'gHCK.o;OW}ɉföItۦ/5$1 s\aHbRWKf:L˜w>!z pEFɏVͮ%%jgӐL]S_olub[A=T n8<ƖxhV60o5LbA me:Nh? Rj3 2|k!Sf!ofŷ/ L'(c-y#b: )( ~ ƴVd}qyE^٫d1KG)):ک^#7*Qd{r#FˤbQC=V (0 يdNHeCe8X _˙˚Vܳe[9 ^MT9EJAlYuPas?@M A!2?:] |z=.OFl⧳$l*rQT$dI?ݸ&W$3.L:a_Sȣm B8KyBHÊ9U.*=NN>^;곥2NkDk2C ȉ jBhb"f&3QXòMo"y痈%Kǫ T !a(56Eas_s εU웶/yujbG|Z>6IxiI6-LoCqY"l~2iE7hʹ%= v0pы]N%w`[ 1K%QG`B;x$Pdzyo=hs%㉬ē%#'6g$ l't{([HH1/eA PVz>Va}PlLUg#˻ E[_. ZDX J|e-m1)c-?2js!.bE=𾧏f՚Lv)5 VI|81`~9V}8a-SJ!I Y~=Ex"U\:n7\ծ}5|&*g*4v`Hݽ Ed 98*4%n_9$pphI?%z@"D~|ȚMLWo6imSZY7Kwr6& /zRyγi G O|Äa4yqː"ɈYӶK# ~M qDf%iM8.M߮%}R-'|ͪ';=6Ӛ^{/) $zXJb qG۬Ƽ۩1ld1 Vv禒kT\3;[FU`B#p+yH2V8LAmiEɭ:ÝSW٫NDi}ն bIfYXݗ_k"CҏPu=ps{2Cj X۲f"H/Gy*n U Ɀd( 3t"0NP@Ċ6}+Dߑ E^fQAAK^tv2]8?"1 Gc:{A+=Xy=ԄYg; YC+g 80/YEU6BHm[RCO0:<[яSuΗQV:gNYSŤ]XfEg.OOay/GQ)yX1ĥk*ȍM6zDh)o-.Gz r," 9,=4Hљl~PXcO6nx- T> w=a2|K$4tזMy@xᯧ}ݗU4Ng0i]&k238jTA|L3 AulwVer wi/@µ'+,6j'YLtns3W<~1Gp:;Zrz\nMx<&U"^X@GTъ8:'x@V$[yj636:{/Y8nʠc#dO kEǛ6~6_qs Jώ5C=E_b[i3SSU_=xE0Wz " hpۘ>ګͥBWAr<@Cڜ*6} o]-{t&N5?vFH\_}BEwNJvE,7,h:iE1ps،byCm,x-ܻӣዘ@@].@|]z\KX"\.2vFy,İ}(D5F":]%\ L1k].{"zvbQ7@—tS?a/mvߪЋT]gəfo5+W¬~s]Iuc d+,'G"D("z/?p>''r/#`\> u3vJ@~TvtiO v2łWnen4A}uE%>՞3EgexoMLE׷;0UR} E9|3WXvb|+g&O,RCr/;)+ W=`h^&U.Iu̜D'_)c"[yAWƘmrcEҳd%=^tAQ:p/eϡ^1yr@7i-TN ҟi |輏2 EFA`fܟHYj@HSrԢ k>Óڢ&cm-O6æ0imU*A8zFf(#GwJECٻFu1hCaivw@J vJ#M.b`^Z穕()wp0yAlTuo \TЬ{&9qŧz >{5V^þDtqϛC~cW |X%#1T* ,^QG8B:׍6Jwe0'?}jy?Ugݲ"+9+)%i6z^ bh'XkCql/:((ӪBC/-_H&Fl{#*%hņ ,tX8$r)GUt]s Zx -ws$>6kI>U~IKA64,u-zf[#[r' lo-(b6;G!b u5*1.ԃFb6iFnh_iPA1Pޢ8 ć简7nE'|jhw{ۚ.ء!7{ܘUyݼ&~g[AAJV E}rVVH ע݆6$lz{ 4prջfѡ~H =*S=%5K*]̒!jvLZnt=TX\OI ӓQ;ݛ{9O)#'8zp$~K+>Yנ_rJRd UW7#?<4&ZL5ecrߏH u@RtܐA:\R-0+H‹Ď`Q%E\֎?E~iP+D_7R%QD7<^J4/փ4h1Fؑ=w#-9fW @_'76ڀf{Z^@d_ﺿWDQ cyR#mLd]^lv GUG!#pŊ3|A@}Mv[:J.Fr>dz欵vJm1|&y*<: wHNs%ȴa֝pHrrgCtj!3䕇 ]F/8B)JJB}гWUP+ 'de_텔.,?A1k9KΗ]i^ eoїKr0s +[tm9󪌽hX0I+a(.2Z @s?"Pֆ s[) "ZχH.#KQn%tH.nKߏl ߂Ǒ#&qCCB$ܦ prDjKJCMc?upM?+dSfǹ#u/{Y!B s\C&ȴC-Aj3?tx ۆ~x6r^` 9 `#V>wбCjNG@B_y $ŪlG25ќnOr@.O-?] [XTZ2P%(j[`BOJ Àָ[FV9\^.4ɑnဴ(('W`Ƃzu7L[m{~F5>y\sGZCqr:i@rrY֌u||~7oH_ỹ̡lb#u=%&=_2T,mL,U/n\z6<-\@O, ?"EdR.Lf`Ճ[ q4k!~܉%ʖK{8F.Z.>/q=-])G$!$o 2v2v@, o@lpbdNߛV!IBdMJ:Su1>Yv]ynMy.^硨ba<ü6b5 Y'.'X)ҙaK;n8`0_[H*PsⰍeOW>(v;"0e?b"_/J7f:AwEVgK@aQ P]]yh~:I&ŘYDCjxŸFl5Gr wh X\OioM)텚%Nk>}R W6i:x8rRiD5_bs/1ѝr/#$Mb&o]`4,-kJ{X,"LNg&e']1]yO+Uo\K'ACV?9bKs?2$v"2&H_n/S_ȍS #=NJu^*H :<0}F%0mWEU( /n}zUVg|ۃQt'xUTloߵ5Z IfPj(Hhgv8qN!~Z+M= 0q +aflA^CY4ݨk8Dm6>pg!&B0z[$>ͳuYEpð 9+79W/+0Zz܆1Q:0mZFOՍogz.YS&7%Ejn_o k,?Ǚ Z}tW)(T$x\STdrSCÕ} yKf鞖7S/d;llPTekY Kğ"z`<vh``Z#w?dZG*=)A$`u.>-ѯ݃ћ..y >]n7t.:' ܿ [b2G)smO%鿈8T]!)XNM䡌0@GO՞m0H!(U<&( #50oE}tʛ+O5wPxIyu4V^ wC2/2H ֡vL-90K_">m83IAhqQ~^i3L֩{ %TDٸ}]~0ڄ^faH]D(k_m $3pܾ3F 별6IvT&?A/@ ko[8EV5d"V b{;M@9YDEIyUȶx{+Ax/[φYo5ɨº5.Ͷ_| W26 S% ELCQ: lO/rxYJX`sۃ܋{ }Q rB_FŠRE780R: Bk N kh ܌LKCkX[Hp!P*֘Z ԇ7ei5c*~wȕ8pb%V18dyO*;Ծw))vyG W R YLʂK똝ͣIES jՃjS);jc3x< FlzkVyå?xT#j-rP٤ To/?({Ϋ㔠<{ \hC 1׋, Lip5 pWeI)o߱ZsIg-yW|9r= XgGO:#)YD-1K3,6 `fWu|}I;R?`2ʇӚh?8EȳE_IMڮuYlo0] P$&Ǒ)$.(X}tEYC1Ş&n;e'?{xٹ~F6morꄋѬ.B#Ѯ3 CwDbV:Cd tMŠ0QlNK=_X;#!|UKnM%Ro·vNԅs A6PTt\sO6g7|<D_cO98k>z@m4Avz>McQ!my݉_.'9 VYx|p8p+>ecZG<8<2uΙ̮IvC n}Wbo3IE׎tŇ^b jF.|ZPNfbCA-FTҲ]-=<}ĕ Ej^&g[n.I>wqE9#^tG_"BclxyIxX/F]R2]HnO.;d9#iw[$,<|W/T0h!D5dEoSM`\߼ /4!tMt7v [|Pe"=[2vK!x)o;pSukI)M+!pb%/ sNyhPll譏;U9_|h)2oߪߑ eh7Q?iwD:*K MOM ]wֽE\Yi:d'qץ|Șq—'k4±q>X!0,]vJdʒI"! {y9 ; #|rm.E@ҭ* Gg#Uf^K'8Y|/DҬ0Ֆm&_"dm_3zPq_> ΂I$eiI%?Rm^+ckҌ>z$Az':T'Fjϝ@v10κ (qYpZA|yh3% urI=•{XF!W'x\.5qrD iN-YՇu>F⤆RE$K2!ԉCr3XLeGj˩[mda-$z)fi5n.F8gSruR@mĻm[Tf}HŊ(J}gBao D>^WH!yX)`ªpmZ(>ܵvH12*+(%jlu O<0+RҤy'vf)ؐkWk)rD(BbJs5LaoeѦ%Xa_Mmos 4 +!c_])-̠)} 6!u6  ̶>2;P͟8 /eYP'y*ir5D]N,ZY8Y﬍7TDc#1 q [rPvkFhk.Hh(BME@w7ڮ6tG-mH'w$DYEMʲFu;/"?~i]ϖf}fltbH3.Q`~0+=PR%icP9թF'-Awkddz WA/l1#YqX%.}F QɡoK|c`tZa7 #;ѯq&w#2~DL3eP?w*-ݎG!.(b:` AJ )OS$~/|^+ی^0cjzьz-|dطrgBvc$(B$Q2(Q40)W[_xr&?PtǘEىn#2BwմZSLLj{r- rŶ@T+*hm}>k٪q*S ԏo Y?80X5}ꆩH\"mϡAd&c ١Q}' K*n}BIq- UiLͰ 21=OJB\]:wkθ <12@P1%GGF j@DQK/沍_''=kqv0}C kH囪i~KWoEKM"N&[A* h*puq:$)4d-t S/v+=2/q1kLX͋t6Ac]{ş̱AL:2<\A,ZkltF;./nú%:sB 1Ľ;quARNc7ѬNnq]!1 U!l`D~(u[&'SϜExpC?0Z %?~nYiylw70c{Wא0%8&0=(7֌fV>ZWA$gQB߯< FgRao/2'mr!Qi+5 $hhh^Rf $f "ܾi[[v 6iKǝexݞr-/hfZB#g~D4O[./I'KfkHѫ.H%Y2M\~`t qW*P&P1]YT$~],+>aAt·p$iCpbsn4D:G2fr V D&EdOgJ#'`'H iYG«J{cpO?tҖf6?~92"un@kX7՝#|KyޜͶ=9[]>T&d;) ?V&{TT,'bLܳԃ򜕓oI)ǚYQ@$S 9nV&sة*7*,-ZN2}ĢE0!;Ԑ~pcbvVt+ys\3h^!PNF 2o01ey~RX%GNMTGfe@&Yyð3JU А:BkCC^[tx󭴫*ŁvHtqMt>fZykڨ G= nIe@/^zY+a?a;dl^W5nN$Tx(90nMN[t \=NIÈd *5hAT*2HiK$ddE#mISKc^R%]&f7l *L$~R),32,m n,J6Bt1A8@ް}VMf҈Ei[X')P]L0Wq?8j;7g}v\ᷕ޾Qjr]Z` t2Nf]1ԥ EL)L% ;jRw2{@SEH 43Za eU^K4_`b1D\]7(kif^F)/םLr&71 A gx_LOrzF4SG{h&=}rcJF+78PA#W`J~% \(vo>!=y  gW##q.L'~5GtSEKGh8 G="|~2%8(x> sY^`C5JӪ#Uy4VHϩ bƎb[g;^mXo!9ƻ$[ ї/,rd!q:L(?,[PSt?}z9 &´Ed H]SDpd b9- raO/=u³'h+ 3 Z쿻r+g|%Gu 5ʖόpU:DKVe8@Q\HV\`c?Zziu OL Jݦj/ȑ^eQj&0hንQd/ )WLA|7r@+ =) ibTZ|6?J)t 8XyQGNL뵫D(tV؏3l':9( yUq6%e,nt֋k_ 'qMZަݓP:!O[u%t<6={9 ST:l\,͸%ON922ON*+a^.ZUev$d'c;juMܨ{n:y .jUŸr3 [_Uj?L<.M2B|A P.Q,+~7xе7R~R~&_"N]pj] #i`t ?_1Z܋dtVYbGa.gvUhZ8Z6|ކr"u_֌W'Y6'/MqNJ[æ`lȗݏ,+TG'&l?: (4HQ,RC>e`u %5I>$4*'Ƀ9긛 if5[zR;U({1 eJ¢Yk"g* pAf;b4E%Ch%l|)&59 p?|HX_ה+BϚݭ3("!A"lwEʶ9Α)IHnO'z&Eʨ.:M熏&a"Y-K!=A]:\A8C iEp4L9p+@2PU2ݼbrJC"c0Tg!n;l6ARly\{,ME|A9V˱C"UɌCcHM3Ff4EAl&ȉTwXVӗ fK`yo!Fjt7L-T}h{ڌ5FVwib]ƠP9$$$ɼc*QIʓ'l_Vr.O^8Lѭ\-AƩ@8bHRBd/%q¼emDUJ5ηnD~qG -+ΛŢpM:aO6ZaAԈkiv݉F&5e՝ڦk% hp.k 6) !iȒ?8r?[Ԫ8Ӯ}0Lj:jֈQS/d쉎Q'Ђ) $7"k7 YwzgQj9&7؎qh ?f1Z$K3@26or9y1j-xgIJUQ ։`ahjpQNw\ !DLi$x ufBo}颉B'=X&X2b6_F uAF XrCT$:f`#ؕ3BEY&HKrpSII{7(KHi"*rL&/7mM| ;Aywl_um.b=ثS:!={Y\|Mz=(V>o@Jۄ|pd4yuCDk7w2qZn@ۃ0 esSٱ9`Y^<@Y_nI,:s.3y!b # фkp@ĽSHU<>tTLfFoaي7dloBx!L1 vdިڠ}7.3Q#OVc DI{Ļl[͑ 57xsۏ +q&^JZMb@BP wٴE1g.+B;;+utW[X@M?rx8'B>%% kObr#[bhOJ&YfЄ}[?l* E_PSZcxngҭgl*:_[!q !Nvhz [.Yc_ mNv"LܟFF #M݉{ ? _OfB+n3uW [dM3A䵚9'>v]WLޯLw &1ߘjR[<̦j-?嗓%QwkRJ`IɓWԊʉ a؞8ÐxaD;1XGh$OcGPE%J3ͅτPTfן !ȼz?h}oZψK}iOjI/֕jucIHTh0yTxoo2Ro:r:GrmW`iUWZ= -~_*ۑ?ϙeuZ@cTWA[XLg~OЯ(qW!zl)IEHуMbWY>Z$n'$Jw#jQCTK?#F h:uF"qg橫P*Wr6jd/uٮ$Şf7;h<+*1oj<ep !D=Ye}}j=lP}K4c A`,UMs) @sROwcݭpA*O[0b? *uÏl^-ztV~>e\vDs}/|)EMīZh|O |lF%a0“6^V<^CK㱔lU:F<p'ijg.wvzj~MhH.!G ̓eiڔ@VzwH]VSVLYR-}7bt(BuuDXtEw8)#7*Hܺh1[o޻u=z1o"%v{i)pt6Un[3ڶ{6#9@Hˎh+eĢU@ 0^DI2!|d2옅F,âA^ͬq%Eǹ[k_y.9+0/)öU| Ũ\N w SaU1.XK?ј{;29|2Ut8r8.1PK :\Z1yY~alW~.U=CNtGoGsM5)l'^wnI][S6qfZѲkqo7D&.Ix),]v 򗬡T٪ aT윕o L{F3T+!ZI0`չO8z ^vm.ߧ#1){[M+Z`ZO^镴:K"'2[x<|}fw cwð|=n oh.;_xd幋*>C6<;O`ۗ g*6VCm4rN'>u/܄VpAİ]:(5;zs"*wCJ2:>"6PsW6LJ iSB٘kN>K{z~2F4)M{4&kQ|DӖ-EA/KHIS1jE w; oR!Cg `d-6ixSע@bz"?~z'S=jy˜qwet#)O*Ɣ>Skcsp_Rx~#m TV$oi=/`@1Sr{ K2B2v$R3"1T;Dec r8yqiSAҶPgcrx5ZHVMMպSs8?2:q}5I Oh 'e$LS'f{"l컊hVdQ GzCla0KRE5X8Ox0N"G?B[B[ۿ0~MKa~9@/6.w6GWpb/Df\7>|)XH8lG`HtC=5+2+MW P07ĭ4+08HNݼ԰ H&VB-w*S=\CRp[ NПBx^3]바(rѤnmOH0KV?o(pulIz}FT,5Cͦ2Yj/S7kܙG;D+қ9v[-DEqf [OGVo ;Js'*vm ,Nl݈ \=\R~:z G{Մ\ _zp?YtlGX-'FR*uqM$פ uSц8Y`\p# M99ʦ4%]KO13 u,vcLW'amH]IץZ J[`2L PQsbkQ-EMJx|B1BW̺L/(uzvEUt,2RcG`)DvąUhr'2XjՂۏf3&:z959߃;GUDc5f۴AhCP١z<cTBJ%#!6bmpiqF=n>jc9c'E* O,kg=?f3*ܦZzXV~{ Q֟0a\K_.-q/AS>lWH83ԣwyOb֩熠P3-.xl˝A|:iwAgcUu*bG(-Ρ 5zBʠFƲǿ_Ԥ_Y 2}孪\+ |"wqjh#JS O)*uPYApY8z?Z)ՍP@0~ H^lT׊&;Wx(Rl8]͢<6El:YXohj fD; :7=k: J;Y0l_n7 +l=ڼ\@T2V5:ҙ*͘^ GEi[1 Dm~o65q#϶˵2 ڳ~(&bHcY.E fDk/6w^m.aBV653P 6R9fjsU4(OxI09S!+ecqz38@^AT0 DT=fm`^[ݽ1Rw),؆ f:E*e3PjEa4 %/)mwZ.Z[vPsj2S)~>a8dJ9TÅ*v!]H%8lEW`XWŹ:v=>H#"z]rđ[ 8Т ;vabK[n~2gZ1-1 :Gb*珝8Bf쒆zU48,л-LYV);剩@^٫mLc!ђͳXOįnGRi6AOkiƜI=AB!{9 ZU{&sjY|AqNKS{~7Yta+ٹ3u.0ڶ{cí7ogT[ǰzk'v4F'>W}V! V4BRÓ!̫}Z=gaI8U":{ ;&fO {['8Sǂ o&,'zY*Z4:ޫKS\1U1x>G><"ᖭg7y4gk5 E(v p>)mH^iQ $.c!TcwQw}-T:?tNN9G|{k3vxIH~0ҁ~@|ZĿ Ŏ3&5q2K2)RE///8xy8V$ h}d[A؝N6$q׭v NE};!Vɿ2zy.=d繊)q I,tyĖU X3uDV 7zYdJݭ##?>²%+v2/P~' ([[у;]=R?1d+k8 ZTaq>LL9Vmq丐Xb?όdd9匂օCW+b (ltVC$΅ܬ@QxE!og1IKMxVa8$ wM %:'&s&,azݾ9:zM2r<|%q[pb6M$)M*Cފ{ a^g"0ci;Dt.;ut(⊖=Z{*.A epcGvHvtL҂0GJ6a@Õ-9Ŷ>-JO]1Ɣ :&Niz0U:4҉fFce7ϵ :he8T5MAHXZYMKvӖ1gXCj\BTt)'a̾4#W!0G Y|%lV9 JE m9=;ljfȵ5葒MaPsuyc?K wĿ)EtM&+syOJ|7 C_[6Rn;漣pW)Z~|`B9p9nHحF_&He6*$:VBv4^3ܙ7Xx`=BXj #*4Lʖ) O \:L zi}p$]ۖMɑ5iESۋ&_=l&H;mډݪ δF)7S7H ek6KTb<>nI_`}XOPPrOָq兺?29_ɉQ5}ms޵2"-Ų^wVU5ƽΡ`-qoō=8 qbfHbf%Nr a"a8c]*ȯH9#.E2VH]z\q'KeMG%alG3 ~SPzrJ9 ӯ=Яcg@+ <`'0Zg$M()_@9w)7{?Uwg q\t&QåƝc1P34oʁ81?*jBCWRk5 |#%FP0/bA#j8 uLT[=) o_ovoKSF= 1tGn`&@*o0%n:D9CZ> ! ɨ\\#@v(6%֯!S֐sxF Bn`RmKmiv81!jHg"YK L<}zSp*}5Ⱥbl wKpN 1 #倖JTqCxKo(!GT} a|@*kWₗ@NjVߥiu M?٦)7$ki&~CZ1 !U!,|+*H27G@2xtՅ? z`7HaD^aҸ!9A22 ^W5_aQy>jdNY:n5@|GPN`QujqsLm6Bv -NgW. 32>|gi7K LiIhUC!K*K>C00r$ QIGyVQ\I bG` @]!A=rH<5?= 7>O+l8ԮF88*SI-Xp8F,7. 6,|Im\I*=l*N%– ە9@=GU̓YܓL/Y~nHnʟQ14c2A4H3%ȗai}.*r#x(##2A+?4A{DNeh<̴|/Tr$ `hQ'9*Ès<_˱]N:N|o)&‘"j^;6Ņ{*"cCwN:Wa=Q6κ T̩OқԄY1^Fs)/WI.K% cʅ'AYU5AR8ڝSc@01 ' TrRX oH<4.M&Y`C:Y ҎiE})f-6Gc8G+ԛQE$P`IIQ:YcWךBF+ER8ݪLǿҼ}#-JveVhlD.7d"OB@l7lu'{흶 rA# $(X07)F #L8kh2~iE,Ӻ6EL;a|Hs4g({ GŽ -W(UFGez.F?+^t^&8^Zڙ%LܨֺXaF1 sxUI D%!mR@+\8?/HC qH2^Gz"&ETf1y:*\'b'<*fkcf+4w5񿌡%k 0iCrkܓ#id` "$_@ן+NEjG1eou)>& :hMe^X/3dHvV#}*v7 LSh4)`<>%6cℒJ;^'ܕ2;'*`E1RJAn L{2ԾJGٽJJ B&jRZZJP27p Zv_g%¸?1 0 oj0,S柾J աڭR\ ;سDŽ@4w: i{*`#=[q# 7%ꦫ@L=7|옸 ˧'Ru 2U)dp'.M2т$Bp}`1 5_N XwRU|MPLi0*r!bڋi^WdukjCal}`=cEaۄн_}ݹq`(bmgR\O(d"lyqmTЭSnO|lE[̜Y{tq |Hbi&vՒd,s)ߍ`'\g\woǺM'{ 43+`Юz}r3s8YE#EuZm[SWǑ.W;¢IVf `Wc8 oXkH6!+z!'ҬFҎ(!HQz.5\ٶ.Y|tT5sZ kTW!o[[uKoՓ)'* @Ƃwm]N{xb26[hd]d@J uj*ћ$ N'd)x=+ĥ8|5xErlmhio&|nYǯRء/g$?Qc񖁴sq~|Fvj;GXp)+G#1טV#ہ3uP(k#d8 |MX|bq?'1cb. 0/SJiY :h>t`W v/CxnQGH^hMTiS$__{`ZBc/QqEh|=G@|W((uٰ E4t^:%W݌=Y`a4Fx_1Ao#Hs7+bk21l}ÏMCw#l6HN=8 (sCoācDN H`ϐxSsʛL( ŵqP ˓OfVF "F%trJCskM9vmV au[[z2ό\K'h=Z Ŗ*944o/{LV$u2;š|f d>H9, ?7fN'|w}83ǟ@z\+k@ڶʙ :@ˆwOQ,/"n'6>쀒)a^4,UN9 ~mAuBz₈I%E)O}Aҫc[F0, 2ܯNȖw&$d18jpO <}0pÛڳyA/qa p|]sx͈g skS|rHO$RΧv9`As:88\w4}Gf-]@~7KCFoJ`(qB10T =- a~^.lzѨ4~zht,Op#W@Ɨb"SxYtWsks8X9I0Q 49˂;?0% nzBlO*[\QXfvtɟG%C-60\ &LC-tT$jS #NHL!=,̧~X= |="+-]\?&7v8UnNWRB/RN֑iGU̮M;R8] 5,V},գ^`xx]Q:%VL+kg8(,F0¶q:@\f\x6O u.~ʠ؍o"Eߏ\rRn.ѫbͯd;}JoxĨrn?K!6{wi*%SO`B/: <\|FޤnN1\] 4{lG%%ґs7Ho ,KD `2.&E&9g).4%hF0Q5gݘNz(̷o1M˱/]pl=a5 "v!?R8̀HTdMyjdܬӨtŌve_Phc b~%4rcĵG򫓭$8:s֭\"ζe|veKi"aBI'-xuPscdABĤ!|j~l#ъA6ftBLl^EYDQK5tq'@GrFxR^qSNm5 6FTE-C0.U[?S 5#d%]e▊(bkBqk($ifg 4S;db8e`i}_y~}ZBRFܲeN7EjVs`z9A:(a 4T0[‚s{} z 01&i>0϶#k.g|"CJJ=/-GrT=i %L֬ڸUa=_Ճ q dE|LbKt.1,F@4޴U;^"EEŠ0ES ,㤈K3phypyˇX EM9MB* 1-ഁ~d8z*gʎP[4{vcHɵqM|+&%5?V)VCsAR%TjMHI eɟ. fvl.<Ƌk4e&{zDPmfAMcdqi8oxl]y6nIlr.%4prr2 KkYXAPyj QwA 6ȥR<yX~=ay0w. k#M3uA\rtywLO3)m4 |ȅZIIGAGAV42y6#j3|ڊI:1H4ՔC\AE<}Dx*W^wWXnR6 XHv!~,C̊U88KJ)$Xұ0݄߽l\%?Mw),r|kY#ځtIDshH`0yKwHs;ХC+_&· nC/;VFG1>[:}pU@ߕ0`+p#׺~3ܧ t '+5'9J4kR-g0L8uԖ smdI6[q+4Mr/7}-+XsmØ6~Fv67=<᳔*!$dOLjR.έmmn" ſ5zUҴ ޻<3e}Cvw (2]*n""/-gI!ׅp!\MREW +R{Q-ggs e^5Ku=sS-} pI/4Oa>zE~$۩RBTC} ,X(Lbف:oN="Nvl++d| UN3UЙA!?ʹ.<{(⤁v<}!  >oDb+k@AxTz"HCU>i]u2ؓmrLCV`C*MQ Ϛ '`Q|b44̋|b5Gxǥ13;v̜xVw;1_Ε_NZ?"I<WW=zV tF,1>9F)JK6^oЮMM!+s͆NRބ5&<|իi@=d7x5(v4%8^'!I5TiHE)N zWpZlk`Ѡ@>Fn0 x +k E?k?Ddy ock/[//Pvij_c)j hgÅEwֿG!nHH4sy^OBA(eܜSߙpɬEqxOD/S0%y!D#2\bXgArZX"1F݁%*C\"Q67`htDDJ*\6I;&֫ن%h܂iwå=.G؅F,<ϐpNE{A 5\DQ^{o0rz-bƍ"iPw!]pьC: km~2[8 ‰XEg[Bi&2_Y#7U.dl'QR&2 DJ<2gDBZ~_bpGA??L/VظsimTfWP0!v7bn_ox_Q! =ᘝ]+T8?3R J7vxj RШ; p t2_ T?5S[79m9K!m"4"Gn *fiSEJ{D]lVݜH K[T3 RMWMڄo߾pM?2IGejm{\=) Q:k*w6K]X]\A1h]rpmI4::g;&/ZCbkٴuнrEȞ賧 8cZT ޞ{I9}њˮ/Cpd^&)IWz!-x˱XÞ,gyGpC<)ʄg!omQ,MosjzY Wt7Ϙ8To L۪Ցl>JC#|4c8lF8B=ڨY3bJѩl/A_F;qvFMszJ\!LkfT]8BF&+Z!=$X+` :\1Na7"{F@8}haHHPf6ډ{se(_ OnJ?2 HN*C1)yK7_qn7eF[>ilg8RcRz;n.N&hG'zQjcDRxأ;K%Lsmk(Q^ltVg;*Ln珲~ ] 3|2mQuD>sȤ 'u єGX ;Q?'l/x&D0q ҦPzx[Ԏ ͵Mߟ,7'BĿ hzd\&y&[E NQ 0 hZ<Յw?!W29R^z b8~'3Ce$̏U>Dp>!XZ*l`ꘊ`?`~JIԑ%ԑuhc,!!s_K,~hUmnAZ4 _1C Cāqd#q,e[Pn֔Z*LcI҇p4x3i p͖QXf i!7 Bc1et;DX7([~"‡Œ{5%oꩦ]Lpj@owi^b 37=kjuu1eJeh&mGE ;+l`79f~HS{ggM/ YFbjxM1Q3 b[5= N\ ҚNfzuO OS<X,/5 U=ڦB+w Fe뚟x#i4g؜rXj}8[B:sz4O%H/ur!OEMt]tuD\Kɻ%=/$rpW*-7KJ ߖpML ((#\e,!g`E;싩DݽE?xNA,/<.Aݧ?:Bp6j3*S9Hu&tu~y@Ɵ,ʀ#S?\6QGu/mm)7*d2jKSɅ̈Mw*H>O>]&o}x5{+pت- ًM4T~Wx='9cp9'cRqFkGŽ&ܔ2g_Ks#=sN{3e^1\kvVVk0ҔYoMjh 8𘨞`[H=JD r8QGQUZ+P)hFq:n6A4"O:@ŒrD;goÌF; 1rX&H~⺑jmD Hh*IQ*ߝHۺtk(LlުHk0f X~2& e&t ?u' kxPQi#NaJ7@gt`~t0>97LYąn>n.5Fw!hiF`Rf7aWdxX[Eq <2-bþQƳnyV%<!Ha E^m/xy@}lŨ;INUUX Nzu r ![% v5h1$"`FR)E˳XwUűOB+V}?tЬE=>f2'CM1'lcsKaPhܦh_Eu%>2~xF iB y* 0"#Km&=p%(\P;G}ĨrҚl[E] R8M#0]H;0N{j,S)1A,|JYbYXoZJ;fͻ(g!CS[2&lʎZwh ;zY{g4B֎]Lȷ88̈tzljz sx7x1.N rKm gdokIjHY(p!i2rڽwFAb ͫP?XCHC':xN?'/Z8-x@Zd`a]"]tلA0uZjs Ra|IuGXWf3EN y >`'BU gV %{QjT$+K h#,( i#S1Dx'n<'Ђ+*~. սl|W s4z72YuC-~:Y$Usf^hē[X҉x29:0ǜ͖صȈ̳faK $^4y#q*B]EtYG6Ǭ Ravn,$aaWX:5#\ `|_"VmH+<}ˍ)sm_rRb9FtK4{&{?QGVЊRO' (|#<"lZ)ظzI H AVdY - TswxBЫnZP{Fg]QYtP;b'^ .B I}$΀hIX8PF@XIZ/씩ֽ:[iƀ# MU e&r9de(S8@9ޣ_mن\7 \ݣ E;0{XDxnJdxο"38wȺTWOE\M=1LTV>Vsn$X4;9f1>^iѳCA|%z$S!d'ŭ*g3oQ҄W~Bz;83Q5Ixu~~?,P0#KEWCk;ч࣯=KyFD,pgsKzϦ| d .9(eK`[<K#Wp`I}7)B6GUq\40=n$&e_0A 0#kU'^Cr-#1a*5(nsc+6{ IQfZr7&?N 8t)6Pp:GGZej?0/Ӷr{.^vs?;}rEUE$EsQ*F1?NđoɒUb 1l= Gjd9%ўߤ[b!a|N8؝|b8l!8a/t!X8'z@CќY,( -"O^5<eK@D6%e˔ i;EQgCLHuYrNٗw[rW?8ʲ!ğ\so E4V1hj5+8VqN YWW,(bϼ(佇ۍ^Tojc{ ;3LfFgqf8˥#789 _.ZN"Yc R)-ЊCQ[학"됨%\e54Cvq(cG {v2 "Fp$!$% ~rټ ~[#Q.%&& M?fdSuv/0 Ho)Ω+gy▙ӖEG!2slIquEБ1ZP &P6T1b_Re%pek#tsJDI(s-" D$KY,&EsL^*__(`<N)i}Ȕ`'}nO, O=j*sȼSMˏruE* A;Q2Nrd}?WY׷A+We.3?m ibإRSam{G|꫋/cmIY9:30ҹO/zF@1wf 2xfͲG}9zRl7v(> fw at IcS۔0i08M("Zg9GF Fк(VsAXd%7@fyu'Sէ^\ V9] F-OE9zB5u0#N *UPs[J.ܓ@39(v2|=NARWUfzJ-DDOnC#iw!0@1+-[O&g&މ ִ9J_մ4bh& a!m̡M5&^pw͊;V ֠QƕlChyDpj;o~0>rlC2P^ >䫊lf#E? t"1YJVasQt⇿Zn7P.jdwnyb%xv:Bߞ;1/s=xgYFL؁_<<4FJ܆<ewnWB:ra&m4p* [}+ߢxd6B'^ҌUT$HSԈ=Nu iԕ$(; xlw? %U[ 9 y0c)YIlȁC`tHՙ0τ p+&S3v喠 ؁TtΫܜcD@=]G.f#2w_8Eŭ+ M4EOԈh$ξ%]@Ah6%Ε .n-ȃ\5rp}X/\8ZÊ{lNLnB3.ԚM'іƼ4?e¸ȿ4[QeЃɖb"F;*04o/ҥ}].9E'YGq<}ŕ1Z F'+>1 LkE)9Zd)@%!,nT 0 Uؐ:JH5RI]Be@"/t :^hwkl b( 0ZWۭ Y[xrtD\j^WWfӣA.()Ls h}I͝,Sj[0z]Lm6TRw}X\}j'|~o3^HpNc=DwY"6i^3DbRف#1{k}&&64 U}ą75kԝ?l3` X ѦW*)' 8PY-KIAChcy\6sU1n~ lŊTʴ]yK/!pέ2c⛼2r:7tgNUE{l+<%SM0[$@ "Z7Q|TyL}măb;PE㰘S1-o|z,EЫkCȳa*,e80Ws<ȧZ;A;Ҳ;-Bf5d{?&K܂Jh`b?b`?/sQ\%_a ;*yK]Q2|VmY_J7f{>MR{/As 3-f CT_Tl#J1Iu>ZSr-|Afݮ_CZ\hgBkmfP4Մ%t#74->^zQ?Y?9N3Ąnx>@J "R>hرL06,Q) c/@і` [nX$W{qHO Oj?{v1|AQ~e#NL Mrt,@5Y+/2i;HE|r|( u5--C Rn<߿CkhƸ:$(C,_2S3=bti˄ 5C~!ZEE<̕H ?`N*u?~mR{ke4{{́Us̤)/"W'(vB-;S(n0=2tأQ=<;8Xjo*@l0;߁~᜶V_iB8(ZZj)[,M$2{M]:"qT|R05Q/+2="4E,DT' lCך#q`!PqbYA "'QcfN/%OmT}Tq>jЈ2=^L)4WUSQ4|0˃x4{Qu|^Xd2kBlm/=Eup$'Q<&A`Xک- ꅛ$s)dZ'v!96h!DXLG e+}]30a`3tʃ׼7W֜S`Qj`oer9_s&J?[ul~5?gZ~g! u >OI$kwm$c!$Kx&Z. 3 #Ni+Yǜ^Ğ_>ωM5>qj|,S乲Jwv˸-]gg,f'Yƹ:q%lbTBt"C8 mTzg]\S%2˸F$oD22?zl^Rrٰ:Q|CLM01Ju[0DiKvl=4ZVؙ602YJ =>Z('셌,>`áה6Rg[ beg(j{SQ?S2 /wBBIz̦Yorp 3b`Pz]|J 'X #gv7m98Fܼ[ml ΅UJOg%PJX"C%*fLjыVKHSUJzYЫꌆYFO&rYu VNЀЗXP̦wlcU:&T "/'D1j3V d/dQ"#5O婰-Ky2+F._&U-f:# oo (oHY͊6A7PF>p}Nk [.ûDuE-GTfOkp *AtX4a:uqb! &L9mXĵ2@5߇I+!~VdRZP%Bz O*0p1FF_}ԙ$^,p#؛53즊pfm#_ՉǢ_ꋠz=35I //tKD-ӄʬDǸ61n^)`˱|G/.I_pgzYbTjED{4bwȗqq2]XH" CX;b`ٟ/ad{B'^e}x{Ҝ.[Z?Ci?J{uJwVD_T$?1_9`G7p#(|. CàiةfمKi} \pB(h&#,ԝ0)u{y@AiJQұrmҌ93&QZ*έ*uڎ-,fz{7aP݊h0"u"Z! aE>8$&H SJXS֯Il]}%& GK0¦q.ã̠VY4\wz}ǼTWn fQLGC,7 ]Ӭ )-䯐9ڈEؠzs(@Or9fl>bI=m=ӥ4g&8htOGt;Vl]WYmzd}.3ib_\ 'F_79Y|'\ͯQFD T NeuE#b;8ՈbR資󃶽g)GYX~ܳpR+Kw3 S8OW+0ޱp={;#|Th=KsIV ,2g^вhPP%?-JؐL2ֈh>Bx5$Lo̓C67 b{ko@sT Z^D[{ .!~X"+&R+Ӷ8vQorcXx.آv!y#CpQ:.h_r@H R@O$eqn~:ߚ(ؑF&DZ(Nv۷IPaDK/D]8rOϘ"Xy{0(L&;0Ф-j['< [z%D;:cy.a),,+u8ESZ I|=&q5^(ϘFHnn1.:XE?҃P.-fz@7#۷ƻzN+UOO-Y !kĶ R g"Ғ,>S_u . ~c4QD`!Sac82l}P!+Zphs:k,V5vD!ǒ2Kz+7Ƽ$F K)2t *>:n c{yZ1 I9]#ka >*;Wo V)Ih?O'+Kg8IߡX#eOS h}@bhG v70|= DkT K%s0̴V -훠m-U =SqAQhiTI|뉇 R gAul=fыO^dx!o nSY0Yau&䝭rCs&\ +^p7,L:Mlv}(PQ(=;trSn-K45?ڥZ3om[ s5Y-< 7,~b}K5wojENJ>PĺU\Z-V'paA07 }˱QX;$]h Ҹh~FBg>27@ =rۺ eszPM<("G%\'4Yy韺M4P)/Ǯ$s9ryDe{T0ZLNԦ+XSGwS`K?hIpB01O DJ3{ :2 R+%[geT#\NY&BI*f^N<ÑTz>8qLVȲmgv+OryexT9񧫝zgz+H`觫ւbۋeݖmL٩\T4<!hMM(.0XO5sNBo>C=YzK2|2" D2(#^O.}\eGvvVj3W>^yy`*g9hg2D7KPq\D]Rrˆ'D9; DŽ^{y  )h _ԽH5 G£̊axKµG=O/><# { Z2]~ʩ/6Q@SBtz"[U6McB*q)BX {'w0ڝsGUȍi"ܴSۖ }F4h_zo9&#OXB?vߐHN2/L iT_5t#Ba0Z+@OOd#䙑I~tLL/pXT21qЄg7[fI}||(Ex@zoEPe.3lK'SgKE?R>UjE|#Z'ZB8U%s¬} (ZBJ(|):( =L-9!i_1TZ ,v&XuZH-mzǟ }~kNܑJvZF?aU=OrOԹ >TЊڻV9hqgǝߍ[?i%`K,:cLfpu~l1)M!y}?gC-['%fV@R|@]:P)Sk8 >Cʹ!u躊VR͏<)V*FwU U̧DIRJ + HЊmV;Q52+!^{X >+>ծZs@RX[rs3=.6pOnE~ a9sV{wr,jѳƧH4@*}[4:!Ks3)O৚<\$f_y׏FK5طGgDgy MӀTGv($S$sm\ub@67t6Ľ,4D nG kJO:p˩دO>"#Zc]ak[ܔ[ æ_Tw)Яq|\(#킗DYۑnhZWE#{ b9_GO b5 KiǰrM00^Uv̌|U~>l D E2c;f % 6G[z} Fyp E-S./0(1a1X]֒k^LE Zu| uR^ƻgs,usCRƺ\&eG:VIz6O?JHN -vtgs=T>J_yC~t#7Y5kZw[q'4'D|6 UL}7Nð ׳꽸p[EJӘ}@E6]nƌ`F즨{} yRV 1Sx0Mx3!>O֡Y}Sr⭣4qD@⇂vrHHIfҧ7ucU!;Xv4OwGq7ih[&OPڒ働oۚl0t~{v ǂp >~ "[Arbk:|>A:"IT)n n{5F`)"2&a>r(9F]makNB+~+'9G1@g==nPEQq uk}:>mi!a4µ  4pv70#0Ql䳠.q^ C0.,&,WC5Or(CWsߵ;W8~{$F{f );,(5Mc]/s0,n upãI-C'Θ67Ϭ%ų!QmľaFcJ, @z.ʈ^bxwqT%JTg4S ?"{pų&K&0(:0;gO_  8!ίՑ[+^Ձo8kHe] 簕*B-1-V=<(gB.>Y$ *5rֶc L<-#ح\A9 6M<ޥ[3NJ%J^ʌƩ} N\0@oJ3]  P<%d"ɘI!./o8by]ye:`.}ׁL$)Mг O _6sYpu*k;{5|WMA:_=e&"Cquj d#U =fQlJWT]ƭ"RXǎ"犛*2gS00yAN3Ý\6q'd5 ,3d ~0r?|lBVbSRO,2~-'9'LRWDVAo #CsvC&CEik~?YUb=޵6!aŻXo+0UX7tɉMw|gU%1 e8UB?c"$-y^}8Rb(OM̷}8uGM~VObJ[ NRbQ۔彌eFibA?6+Eʫچy-dI:xh3w|#Pw܋eM@>kQFgRҵfEɦ8$3qi6!%}dA+I5aVr{ZB|_'Fj$`D+vÜ+CD6 Np`5  ]8u%ǒǯH`,C͖$1XD +ll+l%A̼ | Qo_wl>[J&# l,TP5oU̔[wG,GO&XLW&jʄ"yъxu& G9 Cs9S8>tYU2,Vd!%"C-jTyUnb9fy( &v]?vh#ueVGSFvoʄ\Rߞ" ##GhXy)愲v }ݲ / kSƖjzT{ Iϫ)r~}F(7aBC >=iJgpHqP"5#J:Qg8[y {)sʅQqW-61o4ɳ#܂ {f-fǜȟ;C9'IM_O_׍o}.!N= YTF>1<,VY$=$c7DZzC#18Y2ls4x/,ZyU+ 9_t'jv_BMf 7'U甯B_:@ oE՗{Vs!9 `yB\Η!|]t"#?0T ۯt Y6ocuzT%ڲ/_yߥ (HrWY⒫0r GA>4 fxTS)f_wzDi~w8.$:>!0v?ew]5]x*%_y *0\yv3b}Kg) ,á|[({YY3!\AF iXv>7X vhqkX(ETgτ Q#JXog4B*S`j4"qy6^rfPYT]5F, 䢮(Ods4F ĶrP$-+z\OOJ?6//_ψs`Kއ;k:B$`׸Eɽ[X3oaXu~ wXnZw]9 QvDDjL@X9 EU;gASJӓUyh}~fITf+aN28J&_S>:hR"jf-Ï&O{C>V| sJ#l̑tjMv]Q E$^-fxxXph@6C -u]@|4zh[ka)^GR1(Hsnq8!Q˅6'%7E>OazJU32A2ZÎ55߆*s# 8A)r~[Vʠˍ:L] ϡU2ʭB?ʰ"rMa=(C/#. (a5~/!RL,'T}@fG-|⅃(1M`wnV xh%CYL5/H2۹p;[!NZ*è~Ib_GI&-h_mɬFQwΐlh8V_M[(ukZ9" +] E -+vg<ސ'M [W}uOR$7L<sO22xx1 C8(D#|w'7v3Zj_IY]ܪV KMv\:AAW[n Ӡ:]g_Z(Y̜[Zg$c򘶦[-nРO(?J gsVW#ewQ-dи(|0ԠV>8Zu ҋw-'&K^΃ǥn2S4xJYJ{:Aϗ"lmQ'ܯJjnG^;`HrTEU=x][A)-# \WiУ!blӨ!g¤}@;8w"cZS6Ԛ2XXҀYFq1WD0Lq@Q.ìwSxKҁ.w>3ea'CR1ɡ6l 5F(sr [(^48uӎxt*޴w@#si`:WV?иH!o'(OtțOg)c>8J>el" R:@am7߸%dw= t8OΚ[ٞ_ s;C [ltB7̛_{MvRժ4ؾbʉEG6 g复l܈q`";s :0uq@< Fxw#|HN(RX\"B"kLIhlEAZ~P~#]rBE)H8kM̱tf8=R)c $C/ 15ufp C0?MbkϚx&xB[1o#KkVh^%>`t)B= 1X^~/ TY *46ɚ u] m`ZIB&gF%Ո)]UVipG,6-Y5hҖB hz5^Xʺ 0̊~2B֛<nCu!> ejeH8)$f8HYu`_bX $;9G (tWqLc9^h'޷T E(AX!2dF"{C B@cGcalX];:!s=Fǎ2οvt8fw&tNKYm{*N8}Kn-ʶVZh"l?HqW8]:e-kx~DhYZhɰ3I51?1w)ѯeM3<_O--E5w+|@u#G RU j Tb ΞPd$ ﯖS=r +h&J;a/P5 SKSqK!!E>*Asfـ56Y[:}TF],NpɃ ;ƔPr"yh)jJ4r`c̨Ը௻I* ѽ NEAz%rOd[#wx["NRg?^>eH>lޯzqʯ ?D&C>xkX( j_Y=;BWT`|Faud TQ1CKGQT)l\J>̧nqm59Y0hc}+c ^\s:C6Zaܪ٬fή4@쮭cW]Õ+5M;ɾ?c>]^[zhQ8#nE:PiQ-(Hvt9oD*ՔCfI K gE̦띔F2{ýut3ׇlߪczsi)U..W~Orv*WE/a}: x{I6}ј0CGNB"RsNv*&XM4fIHD#!KTxbޫ ^GtJ7R\deS\ J~Rm4 _sSmsdwN".=Uu0\#Oke >O9<B¿.p N|\)7matrvPyQ^U&mV?s51Eӗ,9R;u9@Yt;JUE%!x6 RWQ=Π3͉_4[|- xIgd`e<Ɗ}< *屖Q5OڗDu*#zf)dUy$yjKE80Ki|Vd2KjL;re=cO9sv y!a9D]5|vd(}'l(J NHQ˿; RD@ ?H.NΞ+~)ӌ@FHǢMmiZ$a>tC^+=+M6n͇'?au387pOol0&I~;,fA2? 㕛&niM |:w_;`X!FmF;>W 0=Vlkū]PrΗrޢ4+. m1V򩢕8`nl 4]8S7!b3frZz'~3Wc'U۱Msɛ-,3 h2cZ_CA/bcQ=7Њ&Ma+ K܉wrP!!l3pi|hk1`IӟւMRON^X/T=UF穬 HSB-A:OT heVd$l3AnEm|5ft]ƮQ* (jwGSzh|%hEyO %~"iV!AX!%Zn7S} 87<$ 7ayq@in}2L[c/}ӊ|xNa9$+ghOUU2K f6{\ c9Gi-y2oMG)ޓRzP{߃[[j@oW,UxZ2c4^)y%&!!`eK-'lal_h݊rӳR?}CtfMy6t(;ש:vyoU\G|y$jLzZB/ӷ<~8z07ROθ5™qX9MfDVgl 6<2%E";= P(>$$ .PZ"u`Md݇@#!ʢi.ZbE =1{Ԇ@W\vaT26mwܮ62N#-Fς͑NSiy|V~lc><RKk4k X;Fź*SD| wa>73?Oia\9'8;ul"*Oϕz zUd32dłB{KEB1>WPz6ŪF<pPw(װ$rPBL!)0m%%eULxLд8[i83~/{73 l=z˥[/N}*zjיǞd2F2pc Sl:lc7(睘ݘBN̦^sUG_MDh$pE+lI}81N My94eoAW@T$PX/ bݘA97`z ;ݝLy:PZkʧ /g*mNV!|ĤyRu?!sնUL֒ev:QVؐ.9Sܾ댇֨)+%.MW؋S5^gdߨ19dw(DyLMSȖ^d9^*~&z^YiS}TX7xpB;HʋebQ?S}&-n+3u%/[45K3ۇe¥j"6}7yb x0͕ХF<`U H=Υ(yٍlYg_{Lq & Xn+ ^R翺 T!d՜lq!Btc$a+x 5Xy~+U㚽¸HCL/PYRFVb"khTHC7yB#WUÖQeb`{ UfVg';!-`A5p)Q^GV(XgHɂ*oo6oos868xIEKxo8盅}vCG;NBC%kB@Nx{k?R -I1-(F3 UZa}ʘ|19o֜/ Lpɋ@26]xJ?DO_Ό̵ei~A}{hN'?9#-`@E0-!q Ȣzh!8K^)dx^먦Q$fy޿d%zٱW#i˪YHn#]V5f"`a%H wrh}rd\l&$P%,[_*SQt4Z8ՑE;ĤYf[ۙ#צ'4411"g*aE٥s.]*L=QdH<8ev#`lAkZQQzMAЯ!gfCZKן!1Swq9!bT̕z r,s*.Zs6aM}`) u=HRх{Dlg35d[088r!qdj !# rd?>~Si{<ZF VR }.d #sb|K7|IɃNcMD!%N.ʁBpH;ed-\>ԷbG E?0; ɗbVXGIa741(EN4t@}հ6(vn3 3n띿Nsw@\݋ f|/)3ɂ^qN֣#uN 죚USMjgxlR!cRe5]$S9jPz.Ŋ4N5 F?(Żk08ٰa{L _ bmù :<~r*SI>g^}s&vusr"BnjajgewuX tV9TCߜQ{hxF͋`Pڮ品We-FԎE+ܺJ",z$ms:u=t73Icg3qB\&EI&_,Qݳi[-sA V:4}ZR%RH#\| WTMA;Qj2. =d<6ۭ%0_n6FU݀GZbq/{'|{{4 G /e, e}Bu~XH(5Wq+ιHێ\~o>*HWba;tl,{CikT6= ,`> 3ڥG!>2ZSs@S/`If6*;;S&MLMzGyN0/q  I>N(&q`FH}PwO#!QS2 2XJbKFj*9MaE~?.p^O6x}j=6͖!"StdJ]L-Yk"uںgl+)УN5EֹdC>I5 ɗ´c] "YB-eӜ|rĸMǽh)YON(&2?yZBR.oU  J`)#辋uh^vP,V%^*SZ"Ŝ!Jپn6B3ﲾ[_jX$|'xSu"`!*CmI߼ قwRtc1!{5y <,^f6ދs?9c@P7JF3rM|$Xv.FEdCHRNt쪮"虞fOb_6↺kueNۺ2YQ&w']#-u]GBGyeH P:on3dQ+rCDLhdbc FItY8QfQ_˨4B.VHuUܺ]WIiCfs*ɓ!P'Dj QO(zGu(ykI&}.i(so QZ@3ޛ%` >wE }8R79p-^ Aޛ z Pz[t 2HdjabI!sԤ.b^# nTZrxG*;}\H:8a0C#b Mدt@;]VG{H3['03hgވ@l\ lTD:V $ z0Bi_݉"GQ䩮ۚ$u. _ B$닆rָkU,13p^ cP{2F d”ꌤQ blߟ,G#&}wZb9<PSD5 2q?@pz|rS5n]kdkK?dUK)Z0[U؅-qe# ?@\8uWucj+QU~#+V7ثĤ4[ތHMHjKjIG]<D+"c= ?gQ3POK26U_ [VB3)]^Н.Sh^J#KiVwLtɣ-B9Yn[D: iAJa3̉G{8wOVSZ2a*(&(Gȏ)~KEElȻeL0|̈́A1m'a3|S(|?\4\\JNXϪcMda x@M4+! 9#avde˒ md)U_[?0CK6 K5q45-vhyԍEGu1ldiy^pJ6Mc[eo`=wQz%!E IՔ!fMVH*/Fnuыl8`P<<dN2C2/ NgIJ-;{^D?)e?HH=q(v2Z9)2PaK;[r5'vAӘ}u;,H{F2_2$|ѓKMR m=8sd޽ ϒ}Us}I&52Y="Ucɥ\!}JWn.I0eX; 4 aPGM4+i,?`CP\۷)wJ~a ٫Qn7>QVq`QxkHUetKSk,Iƛ2/g8>JBst\p_-pNiNZ٣Mn3mV"n̔K|ԚBKsũX9isK5i'7xz7:sT-X]8V~&j}^"IH8l4]df0볒 T!8tWUU aL=Pɀ}]X#k~q 9"o39 /΂T17:DɤL׊'L nPig@oXWipТ$,aM;8;9RJژp`wk140_7>MSt 4CosŲ=R,/ZFudcwϤ*7ypU_t\̒wZuGwo Xo)bxi)"NQ`GaJ bУ JU7ġ0Ly9k5Gd&K#1f/63Jag$0?ۨ/.v, cF}v! #Qq5lm>iȪ\+bϟ&RVIڀ'd4[$~ 'Mɿtfx V I#gʦX3;zв=KbHebPDL8zPX6Ao{Nj4l M` 425/ӓ7Q4xsh\öR+ӊ7߻TЦ^b? N*=ba\m8H}kk6 \΍.|_$ؿ{)rjl9i;Wb= *rYuj?K?kT¤Z_m$qnSO,*{m Ӛ#QSޗgh.껪r1G Ov+Ŧ|| 4`tfn"^ԝ_X*I=M\Jp(B,D1m"4'.XHx+E[Bל=s p&x%5gdɪ]wmcf״ ![ ܷ0'n6@2E鹺ʘ\׸8blG9j7X" GF)YYC]!ЄnF.[jN)nY*Z3` |j.jտ.;BogϭikF>8 Zvr7rk,ZQ6Kcʈf#_:E/2AG4JwobWLX"ܔ[`10e!ҊN*i&7u&|S3nEyU7*o' gU75Ui;jqH%d\RU{,j,3ZnZ sl %̶bMh90.gn,<ړ%U-|ZmkYI][$[Yvr[(<];'^27 EogׂU&Vz o<1 By}h05ZpXWOHKzT3y\& <b9:tn#&M3ؾR7ˏP; ЌcM襉PH-3cS{=zbԃ'a"o*N8Rz"06tb'[bl9^N\F&Rcr?bN׈D=*#zA|LH[}=] yZ q ߕ;6;nA CIu)_bU l)&PC Y]23pM|/k~=΅ۅ7$TcnSj7J׿A<[-" FghnegUolGRr#ys%z`pjTX,VBScYөyϒL*<ldp*)[Gj*DRThDmF`.엊L4>k [!ocӚ 'p2-˜Dlrd>Bʳ'h4MtDUCE Ұom9P Ipa3~%C\* u 9*VGMRKulJr}!t'Q2.wb`\6TPHpmK5-#X{j.$I;^ xa}֊r,uCYW/ӇkL~F3('%m'A1iP; '*˥Ui/3ƾG:Ze&e91/ϻycpZYy.P4ÈOdUNjrƢ;)ȩL_Ίq'[?o~CC2M3w,%[-5+W=510BNg;rDv|2ѝDuSo*'~dWdޭ*$GQ5u TT;Z8߻K8@'- zjHBi"BtEA`۸EBs›Tt=¸e\Gc`OMlv6y9u;^!%JQWהai͔󞊊aՖx4ބYW{/1"eްIݮ)澪zt RD=?􋎶,gsžTNtawJu|i(\A ;nw-<82iL7G%"$RVAIP L&: <(Dq"c-A΁h~\bgχה+'zgڥ ΝOE/b3˜(_:gq$i#{"teP`of)RAzzJ8 5@xцJ2L4ȹf]fhQooB"f̯N>*$AJk}^g]IU~ʦZ]U})x?jJ4rrٽ t5JE _Sb~ u9}_,G8tMMpHEM`h\-H6v6L Q_(y_J:+%4SOZ5w^;ȣ,RneFAD;'ۤLpz~c'Xw53w/zs҃~3K]+AR65uŦ^$2QCL1)w@}9)E6o=,e[0X]K9~6gݿKSD|p3 !HE4-tyGSUS[eGYb=]w*M0@ws܅,iKXukR`wEQ-v)V` Z:CO{.ě}\]  = } NCB@1_".zC12hlTi@ BM YRB[p^fyObRfI9/̣/{+OS<=-}~R -ΖE]"QvX tbٝ6uȮgX;5E|*bL);}4FhHBSN׃^,Ic $Uz$f[ ;C/᧎?z7?bH,z)_˥r2q)KI6 ,PKvKfɶWtxS&21y;`-C@ ٝrx ;<ʚgm6>]hD;OðJ^{pLP^@tr4GY,}|apt(sVF?@@ 9V"[amFLfOr) fҵ]^IL@&'%}dFz8$ܶ&c GR!BoOa˄=A2A!4ӧ9{1q̤< |`̞s mOz ܬBgz8R~צּ^LԩA1ݸ 댕pWcG~e=ưb}{hjig[Ḋ{+( -nz+֣ecY2~^ g xwZR*!~/U'J2;QeG?*YzS/0K' '*/\D[7Zm?{ ;x G43QJn$QcPu4 Ha²gXO6{"=Y*5yoL 'ֿa[x|SIUihTt7^ZƼ!`i:D 3&4C!HSΏIwJ2c98ty0A0 i%qUGI<ǢA|?lMD#!_`R%vP-<*b͊C'5nT +|| ]|!nHgYTfoƘTF7^[2=zKnd -EӸPIgwP[:ҕ 1T|f3,L7 h^$`Yy)bFS"-=۷ɒ^ ;qG=jzpW]MZ\YB[C09<#'=OZXM^.|PA 1՗r VVl&Ƅfy rJM݄H[_4 &#g$SڒeeĉKiˬ兮5F(|jI[䓐#}Bv|I*aKŠi9pElG 9!%^'%?r#c6CAj5<;^ҏy;0|fڼ L9+kW?L0qv"KNL` t}zBidlhN!Z.2$o;5XC7޼Y(GH:R3D<*:ck-dl4c4RPxgw3?}EԬ]C A;4$0yK2ީwsKute- A8hR}^ rCZI'ر)^TiĚgE l ͹t2Qhjlc\ *S5+#sd~*X5_ ,!6Jϙq5予aiPМ~Fwg7'N"›k +k-mqUD ?tz+M}yŝkuz{V&ř¤"$lDp Z'%up_<^]굾Z cU=_+'D!aɇ9λjɊW休s(kSA͛zNKWw*;dFY-Wv}N:nw &!Q֞:Zqs7;=)qVxDE>$]jLI`n_nVt]O89Mec+b@+ ҾbL3`@4~Qؕ^+1"E C `CPZ  |\qp) 5 T\.7*Gi.d~n9SW&&yOO9k ]Ȯ#pwNtf>5Шk47nC[kMƅkA.||9_2K`ĶݾBT#MTa{>(q~-]Q7/u^>bHX(?_dXBMP NI|@!eD1̑ǢL /9F&4K ∐[ύȣ28leCLd >r.=-h֭f~(W(K?cQ;55%ݻn #%`NY S*qC0-2gՄf[ R@`@ǜ!Ƭ裰5?閫jNT{E[N!'b!PhQPAxk:d0zq(w/ɥ!zog nm[Dp +m{} Ͼ5>|ʠ4K^4`!t**Ĩ/wE'gڗI%e@~ 3r;X>:l&G=l-нz>0u^Q>]Ui\S\Ewli+,>A,G"LN+qeVŲЫ ~SgtZV +%)~pPF)OiYcW=9UkAxNJR7_C+ ziޛt򳲣fom8oS,i~lH8^ >:h>+ yrk /4$]Z>zYYG:tW%D{LPvn@RYqGv k$[_^ z6Dt̲v_N Gr&._tH++u3KhC';U.jͶtE5в}Ee"҃=A[lYJꛢ@;x-,Q'36'^]3[]0=OBJFJ(3sUD )0c w \q(@| 9'_R݇|ooWZc},g?5c̊E4 闉jh MyאFG tT'˧;L ¯idlݩpdS/ofFI~jq-MK0 b5 W0vx@z?kjۤX(PL pꂐF:|fH-7ukuT ؎E.D FG_{*f/ mh0@G,VKҹ,vmv tމڒE["kdK'vbEfW@3{cXEdN bT?Bku۩[`l_#†L_i.7⟴R t%;-άM2=(62;oL_N@+&AVb]A,]aPуz ;A0/݃GYTx߈Z jfR:xN*Ÿk|_k )r^5@nդw$1\f@%Kh XaI?ڍDT ڭU6׍rxm]n=";}qWl @ME&뚭q|[)H?p4bݜQ5X'tVcg$ ^o>;V1o0-Z[R)b#OZt3̡Iꏄh q>io! $s}sJM3/1%i(4-soq2 barGn%E |Bh1X'&hiF- geht3"ȱvG2@$y4C=&NĮ]mNl&+诛@ܥFLwdS#ڠe(<nbFYq WEZrgD2,^5B,#2Fap"7ٱ .#go`XY\o¯7aI=*5@/zז=%yGhB-['4Kٲy-o\>.UeE`-S*WBP !4`)oz'4B4? 8qFt)WbP}j#W-+CFXߢR*:c8Jc)+\qg.UTR 3?N@es]/4hE5St᝞4pqV1{y@~]/) M%uj'?y 늩'a-= @ii5IK>C]k2ʹj!,(qmⳂMQl|Vlț]u0cUk7wxoEV_cÇ LZIL5K@PC2lR5 DB;q lyكjiJȥ2O"f;ag|3A"g#YQ0}Ш\ӘNcg@HίW](I|".t@sS=g$K;'|3NJHnJ-HA%`)}4}B\j< GBEGZPE~F\k1 0?8/y'vA I%(tp`}rH*xB"a.--&U^ :#>@J}gk^"̊5TDo O&@5!Z|dJo9ND3?GHqn rG1Y7Fڭh$LsbB?[B%,z.FЛ |RƔ"ޣi( WˤJs4P!:wǷ I#?T0ngކyzJLFFY 6- WM7u(O#Ңy -pu"LfFWz]7`9BVqS/H}֍U!3Nhv°a)*.NC-=& L=:cAy^`>nzΟy僋we'x,:՘f~etc~-AHYR:zc ZkͿ|It!JD~܁A'ty2x6vX'K֑RW1NTH (>nW@`$Fz/HӐφ3@ّ~ ZH. h'f~K[Ȍ``gFJJ3$oFSKbl7=62HhmM.b@D ׌4k(w~ P >tόP(H[t>-E-3#m uN51Z2o)G,Xաbuk$b94 no h?\)_/(ź v?mJaۙ24X-;];Sb_O̚<~&)c0l?j{k D@fe͒sh_PEۄ~ /\faOEz5%WANmI*VlEڠTEEZ9m>;!E[7c:I6 [$˅Z8D]0DZIUh(z{gU.1Ex)5p!qJSD2, lSe9'APdMK@s^d0(jqel 6X ?7<,BW.;$\Nt<-p|ƍ,{ڹ4-[_,HвC I9/E#lb/|H?zn/f,9#Sل[N{TH>/b2[w:١؄ql QQB~LnfoS4JLaxq3-Ѥ>Dg\emz)$u=Q =K>td~cFh8,\aE#ˮ(}ѓGf8H~:|ưfXAzooF;bZdF[!@8 y,%$1l#NA M!SrrMdd`:qY9 sۖ -mVFhtnu (u$VwQ3.t/}3If[Q6\]-rO sxw (& KZAcB@*NXHPoP*Ʈ_5h<^iޥiohEm(6\je-)wj Q#T~b;sdg騘FGIyƥk(Jq](2Xy/55>~RmgOvim{Yg YMrQR֠tC> l=P^% *(6J gm0t?|l[R0}"a Nk|<7>$';ĴGGP]!}*hЁJR!ı6ڿ: 3JHzKn ߺuF!xHr}W5a^M7j G&Ϥ2 s{Q'!g-,:JdqGQh(G?Y)ا_>u׌^C-:MSt&?)m*E`ps.k &j\>&BZ ״ u%{D,Y}k~09'X SOO+iIEXy8qSND#)R!>(REfȸ?VF@sUz5}6r#R 0|D#D/ nA]35"B4/Fkc0wúP#}H/W.q͑RqWO 쇝]o'omuۉ[3\%mؽ c XwQjΪ7uc^K~+[2s*z,}ؤ8)p[b:ɼޤ4Rx &t3 ߤ%w+:w)ùήASI`gIʄJN(XEJ<l4cv?, Aj 4RǍz~kXq"W)ax)|f;ȣՕ8,3v#Mw}[a6gu\ }ޛ6t}u!#N v%9,Pk#m[wM'xƶPp,Z2BϬ㧍R;Ѵ?,4@*8J,d@CuLUsh,q9|* E^<5z2@civPx4 1ϕp߬ӜF|_5˦S/t\dwg CZAp'7IQIWt{觲L:@@Z{U 27 h60z,K\Q/# ajqD(e10[D?`{YL-h=g?x˜o:xBdy'g$Sf3@,eU) ،n9"1)JNv7qavѲLeĵQcWyֆn#v\MP7ٙ( E7Q\pAށ u!G&j5&%hv*{(~@u5Wsg*=6bM21~4l6 (D'eIvظRW ڽ~Ufc0M(Mφ<DU$m^IHa+r)Md X ]VYLoCoZ?; I^Nz2,\PvU=G?d#$l:7ӡB!E*Fĺi s T0S}'Gm!#9%doM$'QG*F}kZk;zO~ =/0 ɪ,gh^H"wۨ? Ls0'PA@0DM\Aٙ"#P%"; L[wL!Ouy悴ȺP4{\ʵ~/A{J 0.RVٰ|'~mWwlPgѰB@oYGdmΐ]SS{aB^u2:H b#X =BHby)mxMOfb);E2t‡oƬ,25vG|(axhPBDjM܏|jA?{ %;2S@jQsZeSU/w?HFùVΑ7 ɹ8YTxt&XT`y)i-9]6" C^7`6 ^П {à P}IA./}t0|d Y/ނSwQw8 vfPoډnF&Aobb]_ǮE?z|H4R_rQ4e\ NbC엞r(k4Rˢ̾Rwqpn[Sb*g@F"Q8u>8Xl83{)F/xV}YNLM+XBwy%yDw唀5zjк|q0!s [F9Awc\S擨lnLB@Z`o5÷8B*};(L`e"="Do)̅yƛw.$KOun, ?̲~)Cv2-oӞRQuQ KºG)Xcܒ7 ?j5e{g: өх2˓YoE.sK. iW5EUF!6<Uqʴ#aGY'lJ/ؾY'_ c.G%`5cE[s€ST٢#QOb /ex׮Fzd*?!/dkZqwb!Am4nOI 3G"N=1xP( a7R6Mh$z̢迪 "(nQ6t^iBvp&Ėԧ R.#6`}*}xIa~T+"E# O_ru;U>i=i'0B=yag%wer8{@n7^<`zZV/Hy -W RKt*&'x0Fj.u5F❆{fH3D&y}r1kv/J*k%?BPP(T6+ѹ Qm#`P0rLTX ZHsaB*ɀ{  kk9Haml*[|ӷR.{P"ɂNDx(`R$p;9eo΃ⓍJ[~گ_܈Mh?T֛jk9'~RN9gKׄ^9؂M!\ h(W rFT*14r,G[׽T /q4%Lj( O`j0;bmwV.T =7>~2 CsE82[b6UE̖o}gBm=mAt\q\>Ѕf ,rAA5ҭҚtS+5՞Q<;,.uv@+ljިF `}Z}&DX`#@1}0瓱B)L[ kq_C˞A;ebү $[c9lR%Yӣ4uPlk31<4O!Q0ĹY7+{|H|{GC!@f_V9ĀOP ИĜ_VtOpLfk>|C9 zmoG͉`IB/]gهKf[F ΦIa Nw O( VJ)"bЀ_17fC0kg̫n}IoSܠ1I:2 ߗ)SUY>x%YI*`Kg;Tø$(b'{\D9DJ9+kr_vsTYG+3pmD ︕x9d٨-wX>m[acRu &u :lV7R0 ǹN0,f_\{(qntP4g31&}殥SnфkoR)XsdXR2o-㼂d\J))ȚBކ?|3'*ZJX?`G5nE( kxsvzz‰ gDe>Ued. V*Y.m`C_/5[%>w*60'†m(I˙,€x֘Q=I_xG;tM?Ƽgq'+?wĕs*xYz1<+}F,, JEXfG)n-ekH.>E>a7l㝽ɋP?A ba. 7>bP]ׁ>O. iww^Y osX~ (*4Zh TDh @^t$e2Rg Dz)]0xfבE8Bt65K%|4k9_Gdٴ|U,&)v>! bmq3sėʎ $cW_ؐ.$IQ!#2DOoy.b%l`0a DZyC'&!Q%$/k1C Ete  GNywiޭ9 m-u 5O=(ܪŤޓ|af]e`AM~_@u/N zmUweN~yN@-yCe9]ex EOg@e >aP͕RyЭb>MCƻN|TyR5 z<7WtJs 6}3 SP{ $SOa P2-awU_ y sχh2sG+#@/`_Չq[ko'yX~ͣspkI,[q˒{=Me߉T 6,& RXA8ؤ8 6ZI06|H Ua̢psmB-Fr/ڢf=Xf`dUGZq]c1oUeOG4mh:WܘQ^;5O -8(9v(}Ij,7>ɘ~Z\!~IveaR3Wa-w~+>/!:p7hl,>T%/\l9*7PŕFnqV/#AjA} J*~ )}{8 m#ҬB!BbN29y`2O9B fqiءn]#?MR@ zs=VϷWv>g(>'߳k!< U}u !eJe,ܻEHvBU,B.SiQDkZ^^2~XZs˛5\i~F]]Pg߶ :rgK j7Q|ոcdZW"}߫%JG %c|6$%$ט #e GEÕ<MS؉ xP-3x&GlRcaJrkW=u^mYN,kՊ$RE1⸻A =m M/^01G"L!5[ `2Q|tnst0m#g$3"N0/*t9KֈxMbU|Ag0Pۑև}JoRk[kC+<}Z D/ݓvڐOj<|rյo(c?$ "5ƌhkYk ZQf{,^G.Rf0 fQAvkH{#Rԩl[6x"FhFÉإݵx?ܯa+5d Ac\+' V,(Vـjf ܊N5h2 tեju-0{wcP1(sf`Yٳ0z;>vI.IھGán(ںT^Lq B\Ί4,Km6o. QGb2`~[㣡ZYg ?4s$( ?Ί Jsp_ ̝C,FbDfŋ:sFA'.+bv~. JVm8-cQ/ /ucFgKNy<A??.OӁsqֺcx2~cg -j؋c*&d QzBy'KWu7)T2jAbRUqZTېT7T>B<)26bON!@*iy~?{]f*UdZv #L_ӝK)&W+)v ^ˠ{ ,ӎ% q5.o 7!6 ,ύwn6p2h5h!^vUkE#J!\D<:SqQ[QB!&7|56\PghR^x_ x'DAFJPygbm/ބ͸] 2]2}Pkݫs ChsUV < h׀|5J#ĩpJS(k^DaV ^5VbL 6]^B5&[~&Ÿ'AP9ڳʋ2C|WF=FDؤ:~<f1io7Y ΚBPʯr?PQ떜9S̱Tge?켽Zj$#jQnǏoOH'(WIly'‰\nO8aGܲV :PΘ.\մj|aS/jG%T3!||FqRl8;#Pe ̮.z-]oNTc8-7;мAb7C›r:v}Z4+Jw(ĆjHm(^)ҦM$~3<}8E+0b.!00 *iKGŁ[L"xܔNB:]W[BlDqP:\V.ֱL3Y`!RTk Rћ0ǓLjcu|>S{6-.3z ~O̭z?t1 wFd8 0Vӛa'.C'棁fC۪l7J#cI%v)>e$kRoIDLWj!s0/y vUꨵɁl#i28X5M^l"#Κ|F\WjOpUnFmRH͒ Ҝqic_e՗un]HC37DïbA4 *p%$`$:*b/&EQ?Tڮ`}nk_R &qPv{8g~jBU~b&EGQ[Ǎp>iE(8}#qT:;  m.|Am b}RiJXppI4sD3Ms r [6é%꧋.ڴ18:t9?€"@MW"uTEۉd lݓr3?3iݑ*Ai!˿zȬL]=̚4o&gxr-|o~mzx!V{mq&Ґ$O ʶ/s4HDak#H3M'a>/ }|E}p%quOxBűA|pl6#.NE=n<&~\(~}: rO W07wځ*ү d>^1ckjϜ +RτsZ28sH +磻4b_(%`*]7i)1)R" @qSjZ|>NB]1 D:Qk'ʥ -MyLd z_Y*03~5'n)qڀd tI7׷|z'CW pCx܇EpA.`{'??Wn{#hcF>/wM<;gVi%fߝe.oI< Lbz5Km=?bC Lz}:e˅\GJ1혮+,Ͻv&0x RO2)gz@vK" J̗'X%u΂P8 ?)b 9k3,( F7.FnYB[–{uvUuI KAgQv~_P\h#I_!y$C(nw($>7Ì:~7W-9㾻C%D.F0:]VU>-7czx &K=V#6de~Ϝȑx;'U9ı x ?^2ԍ;(:Kk/>)i!k\1X9B:=e~<&ؒCG"on5uX֙< Rh9we%zR],ϢYi3|E7!5/_WlywlđQ+vW# c9X}9]Q9' C 8#HiZOGa9 qF؂5Р-ze^b#IԨ=7B'I.ޕ |׈*T ]}w{fjHAMnA}74H>'9heF/T9%ymt @0({6H`L0rxFk{y"jw]7;ǣ=WeYv͒q)42Q9V&]@2㷍t@S$Zd줘S: YZ