pki-ca-10.5.18-19.el7_9>t  DH`pay=$ƨ9E+zƹ9ӀzG(jxi%\~98}ۯH{'˾RK nSeL(e> NUo3n^\.VKhșjVgة!36d{Y0HTDE9 F+]D-y΁&:_?L16N%v*tM&t\M3amND—gЕ".8zgMYX}&'H}%>V07XS;xҽ-QVL;E=d],cYY aw 92-,e(znOΑVbF| |׷Wmjx ލ(YnGWWGW,V|,nOvGw,K2.$UG ($Qcވ! w"HSXc?4f(,P(31T7h{'7ba06c3a1b28c423e809efa2478f89999cc787ca|ay=$ƨV.)h`a(>栬9 @0a!Ϥ Um$^UE;7{)s -Dk^~䙔M-"R`mhtԹ_yz&*-ƪ=$YIN1㱆0Jo=,1q=鳁jLȓ֍bU#(GǃKGrIx5?6ku۩I99vv@\38]i'.ˊmf~B;Lб^G~ -0JY}#oq$&T>7|?ld   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9:QG8iHiIiXY\i]i^ljbdpeufxlzt˔iu8iv w ixihCpki-ca10.5.1819.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.aYx86-02.bsys.centos.org%'CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEGl]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤aYm^2aY^aYYaYYaXaYYaYY^2^2^2^2aX^2^2aXaX^2^2^2^2^2^2^2^2^2^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aYY^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aYYaYY^2^2^2^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aXaXaX^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2aXaXaX^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2^2^2^2aX^2^2^2aYY^2aYYaYYaYY^2^2aYY^2^2^2aYYaYYaYYaYYaYYaYYaYYaYYaYY^2^2aYZ^2aYY^2^2^2^2^2^2^2aYZ^2^2aYY^2^2^2^2^2^2^2aYY^2^2^2^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aX^2^2^2^2^2aYY^2^2^2^2^2^2^2aYY^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aYY^2^2^2^2aYY^2^2^2^2^2^2^2aX^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ecb205508d65178180edc404e3e22c868599218569da061d52228b013c6081dc38cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb643811c199c1d988747ba4d5689f9167fd42a8ed07039e28dbccc4b744f4cccd469e8f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-19.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-19.el7_93.0.4-14.6.0-14.0-15.2-14.11.3a*@as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-19Dogtag Team 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 11): - ########################################################################## - Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu) - Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail in FIPS Mode (cfu) - Bugzilla Bug 2018608 - Invalid certificates with creation of subCA (pkispawn single step) [rhel-7.9.0.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-19.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(݀#0K O^gɁ2}с\MTF"(FzFoC [dBl5JZƍGIcyB7Ա}-8t}8ۢ V* P?EZY?p053UpdmRw KsJm0,/xӉÌpE8jTP^rUj24pc*: !A'] mAZ?d>Liq}Zk$B >4kcG[!'ç`:+u벮W-Ēw, \4dJ[{52) OtXͣ }xw;;޹d# : M9w'},ȕ- a4mUH~CWnUK[PGӣ?6xh|Ln#-8l$GR!IJ"L7M'μQ`1q*gdy=CZ@7@9EseMkNVۀQfҰ?},Bbv[Kz{i(N7{l{[2<90y~Ī"SjNM%XK4[c6k\ !eK9ujM<ݳ;vI%g4FXo6dWEGu0r!MnMH?Z,'[/l VzH~XZ8:ϴ &~A[Nso$ ә|4%d&vE&lǶ%\XHqi l̤= ־0mBff: 9[ 'r֊bEؤuDQfG^XTh!-.^ Z sv@dќA>~q/u+aMϯ8e'#!y0)ݏ7ޮ 8@)5k)?ӞJ:O׽" 5GlQ6a)\kvoP[f˨=dMpu Eym>fo2s:8(Ҧw5 rE`*T{\+ϾT2, aY0=.E5IingPXz} ٶ,Gv;`RD!iZQ3z5 Rh 3űʹg !`N[C궈,! g|FɜcL x|kǓ!M2.ÁfPmTVz_Mky^y{60떑RP1|b ~%;|{HyEd)Hzድq#9gVFnPC:D]·Ugl ߘ֠ugP?3`mTVc}#I5}'Rܤ̤/M\ ,Z1ֳ4(Zꊢ ?\XUj+fqG^9?S#.'1Ӫ s@ gD:HpܧmVt)!f8}F+†FrYβnN+eG!ƃL-XH-)m+Z1M_b(Գ=,/dי?|nE6TOu'FiHy6ǃ Edg i.JU}qOk xLsN~(ZQ`ʫ%BIaC`Mck04K"je;S5ÕCoƤe mPXT$ ?kltonDߢk̆WIRt)0#7{ )Reɤ#{sS>K_+* g lj+IPHЀ0\r# dz7OIt֨#ڻWQa),W6ו5h=ڋMH{`"V;p0g43+hN <. i}FQw'hz ),0ӕz/|g{j<(bߍ&%z*G+6E0\c p`t 6@n5->W@:VW0.ql b!IQp3֟,=C]t!%~_mk=mjއhz50,l*dq$u^Z;+f7 Y[s@NwoDPgQ5!T/ .XKn;ZO5IQ=?)'vE\P|u|'<RAP*مbՎε|V} JUmֵ=^kNYm\ѿP ɫHk{}cpKm#ͲV'XQ߬@Q5HmO#|@b'@1{5Q89#S=F5fnu~ݙ1(|d E,z2k\6X_m}5B]{dagݟ^duc# ]XyLCNJ6Y`=sy⑕"O7%@nuzc;kn"RwoH89f6>)Q;Uфˠ}KM\spG <-P09c{-fa ]14;kU28=~B0 uzz~BF'HC-6LXuhH&qx/Z93Gr e60SIaeS""/Mu-?ACq"AaF&7j0{2-u߳jbWP*yFR㏕K=03fb?uX!Mo`R[KaDB,ds tEاq3["Xd7iY١AgkȻsA\n٤o@rv܇:Sa hW-PVOX#z2r{acw+>0RiX y/8\ڨ F:lD6w{n#ayqխhd](UZwY罞7) ar[mDUr#$vv66C@avc Jb(L<ߍ!癲E6Ȟ{"˰]ͬH Re+= 97uc5GA*)"RrJP50sc}‡Bؽrzd[TH/Dqk]fя}k Y*p/$[$tB)nzòcZEp\Ugqh)`%3I%˸z`:rey 3f~63X'Jebr#cFO@Aw6Lӟ Kv%.d2Z->B}0j& E3KuHP(|Hݽ7[]tvﳬGĠg[4OᝆF)J=tI1(f| 56P?Sp0lq uo/l'J&&9 >%M(G5`kpUVvBRK?eڴ[v: _Wz]gv+Фi [\'[*"\-Tk"?>Q7>cLs9:A!1 PcI59 hSr+|$B㜁,n3b^K^7vD{scqJrf:K@pʆ}>{cPt 5ډȮ  N ?ʛBg'WrSn0nw2}?@pA5Y!j;,H`yV nʹ~o4cP_0<ӊ1'l%}@] @ibzm%6zry|s84!p| Vv3,i$Bď<8vތ^יG&UFrcIiH®~1b'RMK ^Hx2*gzR [/yfF3(+]֕Fd;;)bYwA٬f+Sd1Q zgܳ&*[a+\bOK -\k jppwZP؂ݸ\>%}cH Mn18w-TnZ&0gKNc@zфDѭ8wWJGCF2ɬިGXc 9BCaO$;$Q07k6G0Ke%}0 d ПgD+|ǶwZܘ^BΧ*5sx@5QXÐ۵dQӐf)}pBD<ڻǟ2,R % B"$pʅClזbB^%TȢ07}ڱ]? ekJj.ȖrH60]ɕ b'NWݏ~aUE F4w}MAOfHAyj#d-ڛ+mƉ !lmsTݻ,Sr̭>mS *"gt"ruXեlzvk|׀ʿ6SFf4fjHy7tKJwh1h<єWfJۤ_S$nF>Rc2:-97aTQRI ede}ƣ9 h~%} r?;g[%ۂ1>S;Jg.-J, ܉Ly#CHðU4hMH@ewAnrQrjnΉs/w1'lSL*4伥-A7gn=Yp }ծL|!HaczI)5֓VF`Ӏl_(4֛sqaV*oDM唾؍r> (l$a9zzi ey)0H {"G8ό D}3Jْˀ5/@%-Ĝx{&Uv_uA O)VSM\w#\2HKHQ;QgVZ:&R1n2k]>$!M׭Ӷw?qVMZT.mďΟ}:dS2??676{bCŷ:$/{ qx&:/.\&~.SSJ<ϏTBK,l4Z 8YՈ鉯YDjl@xO6GͫD':%9;`*ɢOeX7:vM{Z/H}k!Y\ymz#蜃Ԧ\Bt{%/#:k@G6>E9d QJO*'y.N/pBb' vR; dW#ۖznt#C׮N^AU\+Xk9Nw)9؜%yeUJ5oy\ H cf-O6]f(xя. 4k[cE r )mKĉ\8IH ײD>&lHx 2,;}|4?ZTi`Td325Nk# Tx4-*Cm9$!BjGd^*3N | Zmj Gf[)룥RydSbʝ]2GQ*.0nKyN`/myEbL <[Zqrt!ejTʛMG!l= Ej0lyg6BR;FWf)yS;r`puWKCi_(:g'7+\ <5JTDu~8 +ZES+\|Q`T>o4RtEFR ĩ_è4bij?}So# Ipٙ=S{.(np"kBĴe2AJ KN%z١!c@kP-woﭥMn kT8kqcht4{-}tC5ф?AN:Q"^9w4 i;$:'/Jي3Xx';MA>8*z7c_7Kr f}p#X:˳2j Q.cF|\]ѰL^17W&vM-MGCj*/t0;4 xTHy7P AIfM[&Tm=?mLОQMt b%.J]YQh&KߖM~;2BeT1GS``f|&m6~ Qt"$Bh,o-kthQ:թPft[L#p#,ecËB'm˕[ ҿ, 4(؈P6ĂM2>*Ӽ J]8&_$>H%)RR+YPQNɝΌtPuP+h;iWXL2ScOp'J{Os(3]wW?Vg~ѱ$} >DhҨz$`1取qfSGLlKxRLv/qWX2|oRj4{Z _9I5 R h96D6c!C5~0]_>TCHbAI!"<+8K"^iY҉ܫf^;DL*5ϸ`ݛ6Hw]7 V}YAяiQ%yMMoX p;pɥm EӈN̮s20S}]f*<~ wmr Po${ ~8[@6M-*Y1sI*:ű!H*'<SPDXN9~43ؽϒM|y"jҌӯmUQr3v:).}%xl xBJMkz]i ;9Ep1Hx, :{1"UN/\}-^rlZNGA 9eZ D Ix~:Ox,. Vi+mHn+pt'cIѷ'fO5$(ԩo+psb;QQ͍ʥj(-bQw<-G?_lߒhdi;t 0؉i)Fxwz#4q_%RuS""-|>> ,_}lP[,Яz|>]&]W9.hNQoJ`+JDP11D_ !o\@9t$%0'Ûnv>Dih6@DcK'MX?S17a}GͶ:9~`2)IHqdIPC+ՔS#t>$esHS󕞨4b0ͻĵD.%nm֐L }1>X;'ٓS]NX9SP|b>. "3O'"[_;!MP?&)WTv(ͦb"Z*M|:Rϓzn>\s808l&³ b8MoMR%o"ln/BXh$`1_|Vbv#G%?%̘8rQ|.֥ұ?oH}wk=H&aT3:xm_2ՔZ??p~xne r\HcszF>ZPJK/RNAk.L_懲Zm&;Jհ]zԖSBuG<6Q(UgDYJp|c Ҹb`Aw#0QbTelCMv)t2G?zT|CAJ?(5j%>@МDo, xRGbK,P:av`ԧLH|c"OJ::ʶс$ UKW퀑X` mEGXUͣl&T(ZY1O9V|\tyftJ\<Űn9e#uc[< eZ {ޤ7/(qD:VNTÔT C&cp ;YHM=cDg`))VפQ9/4>̐:>~pቴFva"1mvdQ[ 3m@e&Iɫ$,+^Hly nIgQ^a~0E0J#?"j{~ XM^Clo FgUE7ErOµ.(*~3=]SX 2؏B9IdA 4%Hns&sI-V5Nh@ WrP~ԆFĻz]{k':CX<xx8">Qϼ>dԳm]=btSCf@9-e܎טa&`X׶Tl|:E-2YX<ъFjd"L HF"$"ss=d^ ֻ! ( 0bA̒ԊI SlQlSd.?Br\1`֕G^ڌQ-;ayD (S1$2K_P"̘Qo3_T,BZ0v[sg|d)0βPVi% <ἳ8z8 Xg;0,խi`@J#8|)=JQm(!jpC ub n@85 5b@cZ'_&m\Thbt/$EA?iE,'ObuƎ1tRrGj\X$&Sz= i叾0t{ ȝVv%"H@V(OTء5Ё;i|&ͳnizH9o@W11[fG-F4d| qKۼeGQ}ʗ7uP9n}(|]H m=`vB*K0 NŻ =q sm,@t.X?u"B>gꇻP9+ؘY4Y>TxO9[1Dvܑ\UՀpLjt/0c'Jb4&){8vB̴wKNL]K w.wv 'leu5+G;ξ!?&KBJT? .#ҫ`[*:1D*EN5Ep7ov:4 K,С3P]Y߅Cژe췒b+~m{ԕBiuY7\I'^OyL^QޘV{} Kt1h6g jYݠ&gfCR`!C)p}K+7.KN3c>J̗+qg[ "~ƉMh [YN2 cGp(WYgzYnDo[ wV%_>hrDCo-FԘIucKcZGՅMOd*j$ 12Le-ZKݖ9F1İr9ƪH~BMNw&7X |Xolr][ČK7sȾZ O:m>p|2PRo|5(ӭ }U]648E@Mo%e2DSŚaip|<,|&'M[Nj ~=gX0tKI%3 |G`,㔲h/va)\'{6 TɄ9wyʨp]Ik֑ gEJ%b6}xFiJ ;i[elFd!DZJ6zC#S*WP"~(Q}f%Is/,3Ǧ$6[>UKw=HYk2\}8쾝&pw۹QdjCl}:PgH!h %v0Ѻ͜Iah0{ J}l mDXm~5(\8UyS]3Fnxs`jwigsva4ؖYSPNG_mĔir kZyf_[[`u]`|?t[;@b$Hj>`1^A˵pYWA+PR߳q) /(=.MXQ>,1QQ^F{9|xJ \{VKdVk ~ISf\r4;{lDۚ=]@4$RSE=(ODLaS}Ś1^WgGc+|#e2-j(Q|o& (AqsO[pnR|O'$`~nKG(uڽ2#9NM9ƏD8%aBo]ó7̶ڣgd%-"kQTLe?h;}|39Q4}Y;$,|$2gRgQAΒ4<*GpQT?{חH뵘]JUXVI)n:$߀!8oPMNXb.:H/ erK$"rl0+a>{" M6nfSЪT 0Rm¡4p+-gVᬛsgD+9iƗ2MԷilI , KRƁ (#13q+.EETE=go۰k^AaRyBWp?;8܌ Y6pu`x_ۦ37rPpet=QFʑiC $-oJC`v *s>voW9lB"ϡKZ%r̯]3$6v54dG6ԑ[*9V!!{}1N}|ak%Edr&PU^'3RQeF;˪RZ;J/&l ~lꔕ`m+`c=4|@ȕ'@ N5ŗ)iAr;O@6ek#_,27NcSvWu6 o*G?K}GKGkˊ60KZѺjwAM0`zOi2}QBw !񐕁*R ȋT)j`U6xr1J\s,mkD|\au^ʟIJ/WZ2a҃Sx{ ;l1_;̈SUwn-= NKnIS[_^9N!/D7R)pz;Tc1ߕ?ULN3^ [!U$P$0.S/Ngw֘RWq9ɇ12`a _ b0X:瓟"4DJiDD M ؊V (ƌNѹrzNOX<ÿ#)[::~c H'V=GZ l!Ut KgXDR@qd;r[h4Q'M0 Q>2G}x`||#ڰ/Kk$b$mMV*y4'٨c:Vپ'WI|h  $PQeBiQ(b6+P"ȹY`P}ąxRz'FYG;=w,uJ'V=K3_Y^ HGCbnLsŕW+lF`7nU*4}z6FzIKGT̬}})┐1D 4dfS$<.m yW&Qm9[C%nhG25+MlʵQ`H>RV9iǔ|'NX?ehۥTJh@aae]z9֕8 WB{"LzTn_5E].!u.UR9ǽvv sć$Bf4wP^Z*|n6׭] Qm)(2JgQ~)0,:=6ء*ݔd 9$[SBӷ(EF! c%stG,\IyGmӨt!LWWqD Ot zK`2Ipp[)be欼Jn\󗩬 $LX9!M39` V,̹gnCY R9Әa\-,0!IQg_hR\Uq F#hV67 ̅.mT߯szp8]rϷAvb* chEIUbrօ}VN&샷L%(rJX;Oo u'4myE\6+zQ 5dqb@ %{ P1Pb]qC'{c#ܼQ]i}̍Cؒ{浘Շc?G$fz1 R@Zmbm|_uthsߺ"o s(zr/(CyH Kȯ9ٺ{Y#ze/vIS@J11)8 Ko>N)r2xsEf`:ھ!1X 0}GC1SO Yۏ;q\@6 iV 1p&7H~%k/%6Zaf?Ƅ-E8>'V·*SD͆1+A$G[jG Zl /P;Rj}7P_ͤ矴j!kihe(EZ &> v[d1e}q >G&+۹Jhe~sKGL: 3w7EvaI V#\tkM bg~Ԩ, ;D6|/ţ2)Pe /G3a?ϚQ]Z*Lܰ7Q!Nry!&UϦD}L]Y&{^1LV{mciTjrA,;aoy-( F.zӆQ(/Ԙ_XՕ0,jrpgۙ%un_,A bC oyGfoOTc~nCbS `+;៻Jc's7o{863KjPm6UJvDm?=m!Hae:Nᯛ&Kǚ."6oNNݮtX;$RCfK4Tщ{-J)ЂCx,KbnN)nrtjmcW?% dg.C0tq3yU Ee["T244)NW~MKJ;px=}(,ue4_(y("Jen?mO~DWw\"06k+ܬ"R;دV/&)3Nbgs<:d/,?'X^qbr"Q4;q2v9.X8O1ai"0o0rAZfG(tpݿWvkLnJ.?@\ԑGUl.3jNTԤ 0v+~=`4h:An/? eH!'2aettAҒS]VSeݒzt96Bzuouqj|It8yX$i&?l{U] Դk%Z9(}tu=Plq -jy@v.S{00.[@.7%hDG߷*ZD/^\eĂ#y|犾bo&dHf."uJ8j]t9+sr;|l9])6HzUp,(mG"R٭IopO4Xhn ?n4=6ݟSJ%QO\̏+asEFw ed4.;Cw:CcN̋fm [g%k+ytE9oz[?} Vf7&O WYB |TCKV V|= x@p$#FKg*)ChN6 Wd<? e:]&J]!!dgX* ŗoCP-{\M3=ӄ7&̧^7l*ԚgjGE+d/X{zYBN/a_+]jU_WBd]gT݅iEtZ JGZ;YaF@<m˕f0yiXߦ4lg :N{;BF}zfԴ Djqe!jO!~fs.O?}hUy~G<(wW6kT꤭8i.넼 `K۞O6 9!O*4; P<m$$n"1_v6BiyI͉Izl53iPyN:*[r?L1& Z<+չ/q)եO'˳azoD#"h%R~+Ã*Hj wIQI/q. .xT-{1FF qm%M4XbL\,j_kKsY4;O@pwb 2ϳmdo=4%}Q2Fviݾ_YB?>Yϛ¤9ydeəKT>.r4]1tkl T5<D׳*1s2>(bw0h䢞8mOqR 48Re56Y` "y芼Gh8e\Lׄk4?Hrn ;u`h/:#B##.6uŠoށ<h^t' C+z!վ+"k DMڢM ]n-9oe.c^YTbrmaSv5A@0D;HpkbwWFa`h7PHnYӢe3[*8;vB1S'?Fܯ'g&b BJ B6}g! 3WEЬ`;4#ʛR: ;JnTu%DJ-dj\@TƝYA64K(tR5mF?'"LxmVժ鎺T NOALץ-<^H+^GQ(um/w'A* h'c@xXe#lrȾSˮh~Y y= ^A:M1m;dĒne Hg EJyYy 0à`AvFHyvِ ,sWwX7VT$Xc B*6(?*(KuH|$^gyxUˊGTl)h0ۋ آPU>C: K8--ڒ-s576WsDR]p%j "q[ÖSh71Jڭ֯Gm ߖ.{#7`v_ҝy,TM%tɤr GUj ,eIp?+}47%[v6+\Exn2M~X_I,*!Ӭj$I(3 q,MUE*/F]+3̓|.iAįE&G[%φd/'}4\#Y.>aW0^JFf'dIR<놃%lx ԇh`0 V^䭫E ZEht]o݂VA|x%׃yFij(8F8J|\-8[iX>RFB{"e*D,Zm y:4.K 6q}`@}ٵ~>P}/*ߥ =]gtGzbWrW6OcKcT˼٤I/rg#gOR5PTB3))$k6)tϯpHގ Gs<6yh+B]͵v{|&uIY W@kV̽b)m9=Ș0*[ru_MZ@]wD97S>(p@n{04TNР \htx͐>qA+"DKD#PKC( 7?GF/0>]10aLa A">F.Fr |+cHAz9+*>H0̀Dڻ5[E|XŦ1(Id>䕤tFyz'i=JƄ`tns@ꄒ.^NT_f Z sl;Uii,v0ᚽF6H_LR2MQ$G[7ѷzHYƯk06Fx;M@ŹVߞS n_,?J̊< k#[^F`ʼ?73O=4ի9x)!2ʌ`F>lx;1],# غ dozNbj{K$djf w92ZRyË$й߼0dg^r& Z.4Oԇ@F.z,X&APK|ÃM^PqS<ƜjXʴ}0$ V2eݛ]aE;>aGJ#B">oq\$[۽a\}TA ji#Ez ;pj u{Px,d_0LaXn@m7OwNB Ǩx9>Z~)@Ti$k c&Y- q~} $v˹|J$-cJRN3.NgשlrL|ChXUR BnMH1juyW1ҜF Ăb_^YܩҁhG`SI~gyhPKCe1ЉߓjkpF- ek'RH%OHή |# QC + 0![H۲_8iKuꨍ)H6{5v{u;I&򼐵4^\ Xd: ġN-hWh;ߺJCi@k)Y&-562IfmQ>'JS?>?I[EH=hyMq|[q#Kk4 57񎙕! ,I6" S|Bu4y؃e Y;!"Wuyog+긩r]ۓlK"M9/桿uo]lH!e$ǔyP˅cJ)(ä~Ss/g]AL~yޘOclM?T Yy\?\1ޘ+oTSF=)8/3يG&`'6KMխ!~6!9$C*((,FטU?+NaM\v9 h5z 99猴KBf)מ.>ZCNJ'>j]e*j!9⋰I10ݏZۉqy`V@RIlPҹ-@##60+/&edHy_rJxR'7 Ͱg:EAP ]؄t\)cjW&J3Oc~:X_7 5(2>4ȆOZH20 F8ADr:` p5>'~ z-pnҖov&B[HQ?7MQzy7,_+lkx7K kʜJsUP m37%™utq +0)5m`n.ԒlhGZUBc cB 29"\@PmCvO}>svx&g"\Uw-pZ7QDH XŮr\ :KQ N[qXdΦ\H;fޒ?V.I`Tq!n+CO* z2B,36yg¶5ǚHoBjV,*tekPއMEYPetS\( p}/5ޙt'7. ]/k6!@\ J|aݬ8R͢m} D'#3CO򬸤6{97gMpϢ5D-hkǿ_UF^K#aEnG4$Dg B!*¤c`j }omp+Phd٦ȓcv¤:,ʆx,vQԲK%qSz:ot=.SeV!qs#vDwl7ɒ{Yr`M{6 !?xA$9n2ۅc&)鹚D?g5Sϛ5n]܆RT* Ɗ" /9+84#A+C2r٧Ͳĭ^K iy'9‚]VHae3;hAA'`3怉b#W{7ОaE S!}}kqMj#0=z4Xz?^!XXl.9bmLO[alAj/p:>+ U7XVf=P0G$yg9+f79˶lvq.!eEDh, nDt[ +oRAtZ ?u- N1+R 5;vi=(}nrTV~4loqPc:'IU%@ሹ+2Lf籜 1~!,$)|J@y[]S/Denfǹzhc?4 ;mX<֕ ?+9;AQ&"{G;s8V/ tTs.xEZɍ҈VRߒ {(v)Ti7$aFM $r=(l,\FJo*[I OH5>$p*Z^t֤WZ5aq[,vkzcCӡj|g7UTM"h;K8Z4Dy4jf>3C9#5x7o6S0$3 7"Ɛd˖e2j zw& XE)&RM JV??GgO&Hkc8z"͍)q̒mg"R5._㜏 tTU50ssU!!PewC"f CL~{;R`X4O{>4wzXU;QSu|a0Z'1Lc➚2~_,E]yz(xA;U$4 UAu`@` rCYׯ/u UH2ƞg +|qtLFY)e # B^Qc)ϺG ޏU򩢻sۥw**﹘Sʚ#q Z#UՕ٫dy{MK4KAq.#Јĩi*FZ\t4>7.,C{6 LyhGNVkGcu<5MkdҹIGҺl1D;؁UPi玵:%FVCi/עBUMr>cpUvɨ{B +l:yB=mc*:ۣ}.\ {h Mʍr0~8ڬ'ЏdfJBQoOx#-4<ˋ$:%&TH J^hiOl eE[jr9ĝr 5'tT/,qMNPue(%4zv1bf/I@E5=[>[XFa/y<©bX--5X>y~ׅiL وcͤqvVŅɊBD|M"G$r&Ԍ SOH Fcrz>;2@_.*osƴƑUTD2 ZT9b{sһŁ@Q^ I|G*!Ss"板k̈WpEh;ː<%Lv3jzMQX4~¿]SFn.)`z {K/h‰):Y;',h';cS,)e:9hiܪ$B݆ߡ7 Jz]1(epȒ0@tm-Fh^;qh 0 T87"Ȅᩓ^ܯLp3\=M޾dQ}bR{|Ey6i؞!Zp:4‹]qR=7(eIF{S[kQ;essNƓaHW.Z- tj\};Vbfk+EMqx~>ܓ xokW`c =>"U̒y_BM(Ș"\AAn!mٖ؝;!sHg]Ӈǰs#p8 #eĻ:#;/Cm7l9-%Oʱ 3CgDE~m?\BHt:/rWّEӶ'1㕚%J:|ݨӆ r(7%)t~p?|{\qԠ֎$1BtG$lvs\ 9ؐTBܿxqK" ğVUZNќ>܊.H&u2nӗxYXjZ})ni̐}!>CV.Y\ft3vW^Z̙g}]JR2 Q1"-an\L*8 i 1x@5|PsC͈` }dHY.oM\[,H@(cO Slҹ9ܪ0+HTYˆK!/+7*u>''K0wI'#u̘#hf)P+` )KCl [8v"v)`E*ޛZ[c־Y8Dd <O=Oo]_:0$~3g}D0ivt!ڤt6g;=R.k A&~CC272?MPk lV^9`{Gg?$%Pe1NDn/X<[C<64KN`AU,~ s[l؞o5V"Aޝjd7G^GLwm1uQݵ>|04=l勢jX{O5Օ9۞$_l#"B0M0r̶3)@jaΩV=faK'n -QIlrhmң :n/O 5MfįtE(3hO)x\R@ z/&šXw$W̪r64"јmݝ!<4s4Vv=>+[>mY) Ug ||; u7Vӗ72\ŏ vylZZHxMP;:}bwYr-J=,#iWc;1F ZrV>cjЂ G+to&}BTw ;X*dK"]CZ5n.y1t%~=N2:>"Z .gЛaT@ S™A 2\S kYyeIG%"7GF<+P8c{B"V }xgT[U"osjClDHSB2ukSxiyLوߜuBTAԁqR.\U49(G% K܎nBnFy 3M_XBƝN+va~%֋nFT5j3I_D.@cdz}V;&r?FK[{):*;6?eAK>\H T#kUI{YEKOٲWV8gHeϮ=k +`S)ol}[2`Z[1Z8u>Wl]u tcbbBFPHeNGHU+ +7)oڙ5)ܙSy$e;}!H@5$I%:ԶJ-JF;x8/.oۖZhה+ \xE>}F?aP^X?xN)1O"tW59!޶E@{_r]1jʡph1%ԦةzO)?*-t@MVWQWYetFd=B(,!xUf"1<63TGqf}dL"0Ato}%@ׅc.8!w)RCعi[1SC+{\رN-?+a3By3W+wq)9E±udVePijۯE?_ V#!EcmG:B}^-f6&3Wnpz_ఘcO/1鏎}OԬ1qqҶFAlp{ 3w`䟸XO "Gq1=7F`.ԐU[b2cX@s+!ot#xCí5c9ĕO5$3s%iP iHpKT$GK3_:q/gZ)p WD~4>xn]giŎv\ev4hxdvd⨱ +BY"G?a?qn1ASio#2?'t🿞M|rg-I2"zrvDI *Ó93WkC_ t4nזmgڃy `vRʤg6 7UqY{jmr-i/NYD#U֌&07L@#s!^UEa㕭Pdz{4N }e|Xoe2{2I@Lw# ;'C!ϱlS]Hf~J]Z_s e-ѝL~w<'$KHR SsWrC-Hj:S`IȯX9 _R͠O{ tC6ddB0ϜDDլ]QB]u-aL $f)T_+1=2a].l+uO-0Mp!#LR# _Nb*;QHƻΘ\KGqC8E˦/mS}N\E-Ȼ +Raul!ڨ(C:R;Bԏ!/ _~M‡`ԧ fn|[ZSBb WZ+ƹj||r"dy3|iծU8kʎ!Ŏ!A -nu ;@#: dK|C[Q7`z=Z@aF&Xc؊]˝E0]51sAms|a:%  52lBV0fiAOTSAt?'3ء%죮*N-,BDM(l@u5}'Ћm% Y-5?: s0c.6_xײ!"J Kk]n,ZlE lnT'$xw=O-껄)IF(3t2n2і;mLgp^n P~K2M9wKPli5XK398TrQQ?hеʠrb0̛&\mf˚?sNzpZ3XqބꜗltH39~qȷ*}Nʇ[&2($6kFбӱ/_JNT[M+QnSH5P1eW@Wsb~غȞ+,Ni1S&:8"D o܍+ǩQ^y}CHԜf`GBGz¬jP#wb pTDKzghUe;@uv|^2$2., bCcjP4Ú-ڠ9}<* UF s$W 㙿߯+FIMT!rӖBS K )ΪgNjĒGb>n'dĹe`ޟe}8Ic|]H+(JT+ ^^B^)zx\+̞B"0z$MN.D8'.2W^rE:.;ys $}oSJ݆n:DB w*NB׏Z"6It  #,Jd."餦YQA5~#1. qN@1PI  cY,.ΦN0ʅl] RfLy (4hXJM"E#Ժ+h0IiX< &Xqt3=M%!eäs@lhqrpG1҉mۑGeQĤ5S糆0Hl+Zɑ.ӷ?_ 0cV]fVi)=Hw=ٝ;Y%UWJf塯gFul=~|>554F6:"b?rvQ |DaFxWRU~r$wBەS8ɥ)%;r-93N 9o ώ=M{OCa DZA%Ipl;R*lj@/t7\­s XO%M?KtlKTꮣ߿K>QEo`Tڡ8 .%hz4ēWu֓nW o}F 칼L V0\ 7M^Lu'_cG$Pt9˕QQ݆HȘ:Tbզj+6FΏh]W 8S;#V,frM$%֎**]%թNO)`\6O'j]dQ[=*[Wَ +one^(pMQsDYݶRORH 6C7A`Ȳu ;v(9c1r,X8Htwy@Nh-Uz]r4IC"LI+ͦ &㢮Hf!!̡u>@ކ.QW$ѭ1љYA8􄘲m8 |jS*m-HQa&8+'XJkp{ 2g;G,WϹAon1UxG8 pKڏEpO`=]R+$;%Xx?!l7-2sj+|&BF8džI'HW-N "ԴԱ"#̎vXro-7)6!9LUEs*#_c>y)V1%b|<brT1A p;I2~ݛϢ>a/ܤw7݃&;XݝN""+Hn0:qk^EʰLDgK0;5ӳjl2vbx~ `zvZ+'u>[v%>< rcNAņWK3n/؝UO ײѯO+5<GMd-wP;3MwWVQ\D? TNq#uZ g7#bC Be(\`UrHe4*ҙy.\\>m6"R5DdtHkKЁwW2 i8pPz\x>ҥS;z)1*cÆ{(]%[-󫳏F}Ht8NE@Z=bCŠ`:@",(@ 9O}V)3̡ RZIN1Pz8 /B??c!7d+WA`s 9(}̓$$s1nXlg6m;rn3-2hD$a()3>g,XD]zp<0b0c.|.p5Blh`ߪfJONsR21 ap54qa=*xg _$s|ˮ&Ǔcpԡ<)N&}gq(hÍލ-ve~dJtѓ=FIXšx/o2ǥ5W`uKI'49HN)𯅚`zs~[Q6$E?z5Fe<a.\p.'_ß;i㨞buEL}#~7΃ұirbಥ !E]ő.wջ/Gf.kDgbU'PH ›i#+_$CesT-VhWjq Pb n XĪj)ƜˍvK 4oD FT^J(!>7 ^,@=]f2I{gp$<`7}$KN笆_B߸p1=-o䎸[tt5SݮR(4g.[N17J"ט%)=uzRR#!&`xWMyL?{PDC+t+x 6~b _9]AUޅ@|ᶾ} #sJ(Hsy ?#)Ꭱ?/%Fw- Pqԫ0C&y (M5E.@?S՝wu{ c{Ǵw ڈ~9MoXo~f}1!Dp }l&rz1+wwg1~=:"AwimvIFĦCx%4;?o,k$N_WGu}RCT++ k6nDH 遛EsU4R)'U=I<5kQ3h=y۩:Yeax,Z)2P܄.G v#fף d/ bW]h.lYޕeW3h!vyC_8,k~[3t~ILWk9~a+.1D)\xT),WyB.&ٻx9 QsⒺ64cWxڢ.Ìy5<("O8q2G͜&.q)tv+8ZSM]*$qC+]E*e<%[.lػBbg?3D|Cn[mN ЍbFJcͨ ʋ:10++ + M6-RWtȡʅ飯)noyc#{z9Di ^1*ȠŠKnآw%ԓ"{vO ;Y~av }Sӆ6lrA`~Ep/$߄TfQZ{)8l4tQًRr >g@Ú.2 /&R#yhIy?hs|&٤aܵ\9UMێ%L ։7:Dz4u^BA@y1oLeS` J -S/ FhdåFYqM5.]p@p-O¸y*ma׮Q!,>A%"ԩG~AO@mkY8owv c1$J}:]H1_}fu$Lbv28ӊ] xlThYŸ%p%.hE%?b%߉ 5MFneX&7\[lȠ~!tDZW(y2.{eVav ~ssw 1\W> h |ƈ!n> u4%O+ uINJU!'JLGkӉ|:2mN_{|Huo Ų7Zp}64{pi?v[;ܺ^,0q9 sȲ) 2cR+:#*iG|R QF\EIƺ,Yh651 UOe$D<"zR _ 򶽼s5jJ'FyRyG E"O /M $ˆ PMGt`]d}_q&*jgcEw/hY%XEEv1AjVRVNx6:2z]hʻb~fymNfijg%Ty\÷Qi]\s}~ZJ4P~_@[$~$Ӻe++ B*vt%]\&W=oGo FEGgd/soF0 [wL[8.5#Z%'ରEA RF8K D :*<I)Liseֆ2"r+"Q?`b. *T9~.|ˠqvP9'6t"Z@p(V i VܾeH&ғ*m*ozGjp3VV^V.a(cRHJU2(?Gƻ3+ONDxh#ډ&3 k!suUcT-rHgb#x.j>nrDPQ%X6UtӥRs&x2e OSX[0iTy(Q7NdnU-PL j"R Q6 ^UBuSL歷dzsRꘫYV脞]\AhDo-Z*V$}&Z+{KD愈h1x*hꢞSq8~b !'wBGv_g&XHֵRϜLl"|6TڒxA ~L0$}!]|< PUbgݰ2e vWDӥs\Hu_T@2ڢޝ:hbӘ2t#jf?4u5={mt T{Qith]$ p nm{$^R1$ Ϟ!^aEMD7eܛ]`WA3Zb6iI!h{'kԚǵԪjdlyw,:(+:6uOxLMftq 4"3B{"B#E% _pI)i O܉mB9߾\^ ~#BVn#@dl^$IsX^q+h*u߿V,e ,#ig)bbƨ(ig 1~o18a<^aEk+y֨t^P$Axm\F=K|T!}2:kT\oxn`x޳`ϙ-3&ߦ4'VƓzn/k6݃ZPr6 ̀$}612uֈq)/0 R(P Ř'o&5C$Li5q/`_-m%NY -Gf遁`RL$LCCӤm[/es 52٠nPLjD-Gjk䝭|ˆAfGAԸFt%B]G{wX@}AMqk\URfZ-G)SȈ-J5߷!=9\$DS9a c(ruBT0`5-&8Cv) 'ظ* ӂ#.r0hu5a3'ǩ@"sz_9&v ch*+"~U? 9qmaz@+r\T2plr:ҟf1)դAdPe㘡B3S*Z,XSwjZ-CR9'~sX'WSFp*Ip\&@:ԚAp8eOnKsϣEά1 e/1xI\. MRa|IP6(+c/][9{OiZRme0%@]T j:?ʗ79x"bܼ j8!$gE۲ܬߟ88tm8[7izt ܯ|*ϬG^+Wž,jϹ8$%1ǁA/0A. 6*ļ8T|RAp)zk v$DZ>Xy#Ot Zj dq \#iU>Yڟ&\[׷K,f)f|l9gjt<nkgŢEuT[Mt0c#[B,2VKfMҏXF6۝E2O&ޖ J[uB}ޢ6.sx0_hx7L4Iӛ㌶6P#.|?ƛm1=FɌfmI&APnzJ撃o2xgJ![Js_1;=t^# 2mO}4/X"`"&UCCf$ҖjJ2Iu,a$:`<3m S=b#wR8 4u&c~6SӠ({B:51_e!,Z&m5`8epq4|B뭌XHe"7I`=2@`qaŇ\Lv`f[KeUxݬr":6uݮeq=+s`ɆpB0:߾>^US9I"Z32<ánwx+lٮ 9tqDRmoHelg-ڹ@”Ll_Z`70=ųLNf 3nbz9}:2G.b"`ߖaD,hFsjζėo j[ [YXM~ "'Lhm8Z(iP"l`AުݥZE>f/aO}d^,3yp=pbxT0̹euoKQ%lM&_*G7]oEt524; IvQ"YnyGbN ;no']㹧)lpg;Xr o Au+V:%: Ѵ"QD~։{BmO1!,/S[JB`0;FzLPAGT &sPqhw>tVy~~>:)|k#U/]܊Z> #  A븽#_JMbui&wj!^Q=eiAW3켢Ҩ/9'=J#ZAI,YdZ&5վw@QB? '@9]w\ W&xO~Zc̥Θ쉫WQ7fn.pqvc MrjRXnimu x.]7GA~"|~kWsoV\5(׸ Bv8"?ϟˬM):͚o2=BڂMihKkGLn |Ņ 2_""aH2Ƹ7J0Hxe8 Au5z|<\+u\@$"j*y/ JvZQdH.ٹHU,s}DK]z". (*H,c6^ B[,-S˙m]`lko;Pl_/ᶆgfVR83XjF쀷IuSqXl!Lnhh^Z}boR#2c鍞q#:Qj M5m^'4Zy'RU7: ҲsbCN3DZɟ ~gS4k98vDah"!#tmcgwpI'skN%Qtax݇!Ĭ6`[\uy 6FU<5ӸN?'v.ve y,7h Xc*2HKTq&:ڡ nM@r4(1sj$θ` + 崪WeDi+42LxYjk:(!`r7R:;ݤCZR4 }C|au;1xhdt)B"l#݁Se p,7Yvc)rL *IF<: ~! ߘChu96%rXfZ5{ȗJϼ[GTR2J_勮H 7OШT/!6{z |Qg2Ԧ> bB,N(yYO5 ʝ"PvRld67ɘiI7E jIYu+ 5za۟k1,w)Q΍nXBq>||5ɌSy"[>9!b T W+K~4JpX,ISյj-y":s+㯸 Zޭk_Q-֨I Ȭ˻ѻ9rΣR;N/8v^ڲ|Y,4qCܠx<5wBMfsO1E]A {JO@Ъڞ >f**̳@4\hZxy۾#rwܼd6SI`]gp"է@PJpQG~\#?ɢ_݊OC,z1((2kےHr$9vYgVzpΦC(y~J}vKG98$9KqN1ኡWA#X0IRFж&YIȇD0PIv@L2kVD |1ad3P~p4\"M/Y0zz)pРw[A¸ vPKK rKoC=<'\ a2UDX~1+n0V{1hEriا'ZT VSw ]$5/` |z. _Q 8^.K>'d\Wd?xG;#Q)%d "ND[0q7骝:bX$\NxBuB3k7~ZL(Tp6?v:=1bۺ..9yd(^^ĩ͘ܙ*/޷ȯ 172i/8蝆\Wߢh"v5 mW@@Czr` $[*VhʉAv CƮ4Qah-!NAɘ|g8 OBI0ss 7.-p"90m""=cf7Q>`u;ISP&ǹin-暔F┹e⩌k q jfq8)7 C\8Ude} L=@J[ū2jЏv,V0-'Hm~p.-5?(! JtL]xf$I` GE ڟ;g۹=M6{QH]3!76-$-)yopbZ~}e+XeHaCN62,a&mex<ާs$'mmh6ժīpFJy#кOk:a ;h80t"`rB + ^B 05+m$ F{e(oW~ iZz4uV w5ƚ~[QlRg墲ÓȞ?՚鲆5V8;@_7F[Qms!)D;yk8;%ǨMF]kjre8e UV Ust8D*Qo ćѓ|R-:٣ COWd6캮q e,Mf.{HV#H\CR8 ^'H>Rıs_=;3ؔ>IcpDW鮑X}yۘ*gRjC^g{/E] ͘W{f^ǴD$? *f E3fP瀡K'" |a[IQn6(55IZZH.\*m{ifZt],_QP11N vCLӎG=Q+1DP 3iXrDk}OtVUka}W3˙gޢ < SdWd\ga0ɂ5vN\"~P tOr@)'>v8X\vgaA;Z+,owÏV.OK.ndwdShb<6{V9vQ@<ݎ)6[uSCԃr4x+Miq`iÜ-;,ky\6s9q۝-z+B+9+ : PCďp0o8(nxlAz'qoQ{ߘD]BތO!|6; VRuՖ k% LsFlԐvKXL-W 2ާ?Bi囀 bM揝(x!G ?kzPiZ~ [W6{%^58vF7LzVjvuE&]V;.=&8\;>j{5b 5uB4 XCGƐxhбUȿSܱR+a0$XU 3e&ͩ1[(9>)ą$lK#=l;֎+#/H^ <ĔƟRX:l2:(IDK p1}7*L&zHIKlMZ‡Y I$h3ݒB~& ;şjOvU j453ޅY1(Id,|qfS L[~6a?kˠL?u"jog(ڇPzں|ڍUP~K%sJTk~opaW] ŹF0e4g&4Rm]I9'~qrB)O(Mbm >$"Ь4_/!n;OLH7q.5/qR)WٲX6n׫{^?ыݺx÷(T(m"i c51@g,$&nkD@e`<&|Iܯ %!,52;@/=+ԅE1ģd1l_s?%wnx,L@6ǫJۛ 2󛆞Pf5uj?1%ogYse;zbl/uϚ&"(HX*5~Ty,&jBu#`E|QoӍO"G Hw [E|tG> ̓G?ѵ@+ Xv- zbO Mצ.jCohd'@~D/#AسqǘDZ#x(^M^ك}?8 j(^ u~K.o_aw=E9dC6N˕#gwUY/i19Z/9q7A@n9 +s@}陧X*k 5^#b)19;]k iuӿUDўHTEd/DBL3L!Z͚LMda[%HCsJ9 \#tXPe5mG̳c!fkmQ,̹Y^ׁn u }9ݶdzEHƽۛ@G!^!P|HB`*XwO lm4$GgT+~d.|1sL3uu]s=;M\gas?دCּ?mmY^vwV,Na}p^akj +ym+F~f1{,[WXCW ރx'J)gy~ɴ@0Q S>j+r/Uoutؾ@2eO!cJiCy>J'O4T !Q:ȯNL3^/^[[g^_hU(Bq,`CZ:L]+yZrbsC8 /d2aj_:n(ydnz9#lS-[SOЀ(.lkmqk" 2nMm+$5n ħٴC*}H "!RQ5(=3+_5 O%9qAG_.A EsD+Y6cy6J@@rm@WfbwthƵT߿M` GO{>U?H%;F+"ĥ@Ɗ#Wb Fa^&z9!ѷ3'! Q;kGX_5:rwfK%g?J? a;MMH}j` 慚z@D@W(ʾ?$anĥ9"Ay:D'Kl \Vce;}p ui78؟쇥sL(Gɿ[ZYJՔF\}b9*jehv,Y\>kF4J6ʵ[dJv8L)}yk1ڣ(1u;ͫnO;TL,o;b1Djp yk|sno>^,d%A&l[Z_<2yh :tJ9JƁV(^d;reDXEx'-5AkķyJ-"WqhZuCN }@n@Pj֡L۞& ݼ|Y yTUi4߂ٖR;{xe3\ڑ+290Aw+}0NOMBFlvm}Mij/ZɊ$I~s//J>&OuBBVg ?Dsy1tB@\ǝpup@{yf htssXZ8!PڔgյWaXHdޙ;7GH9\e-d5, Q* Y ^3G?3jbpt5B \3{{e@N:'.#8\1hDb!Ix]@}$ᖈ&OpopGej!gbK,L?-xJv>*CLas+#Mjy~/;&c-lၮI!2LXjf[4vFDBʒsזM#^|']2y.O?&vʔעV5i=|~i'H.U'yuVK[|Bg F^SSEĪP3e; ǎtE9; q(n \Y540OFl;oN#d'I* ?Ƥ_;)XUq,(DD*o6C14֧uu݂ի&o1(Q{k,~ń3Ey{;eEs;U^EZk |"?szz L$mS,1sՎybݼ@Ƃ.-8݌ʈh8!a>˾q_ vr\߁T7;SA\׭:40O\eV{׆ Һ\|.`wFA<-'xIj]+Dt}u =9 ȴkn6?Дi9+v[^Q~Uou=΁=+ woF =Gm]+1V}TJ/o#*S_=8خZ>n)ct, qUrY# V In=ba߲W>Awm(|)a$_ }+]-A&44oWԹ㧥#R*"`fW>Z;*yVe\ub\jb_ٔ3 T"1wn׵vF6AI^3{=#*G"fоLoW=|ViJ/ RM݄-gݹ&>b[q44O' 6. *-R 4b43R1>3srsliuMݭq༦a@ $&ZI b4%n=<2`WLq_€,v8{ `9GaIK%::6ty) 9Δ\R卉Z* _ɑ&'{u/ *>,!?$)&P]EXD\p^DB6tB"gnE"bPDmCSੵ,bF'c<]RB{ΡlZB&H ^? 3"+Լ!CƬz mD~Dru^ y9NW}@kbPY=oez;zܹת.6)$RN;g+ 9y416t\WYz 73s8 MMbĿPԟ{[WO"a־>[1`T?YEϹ77odJJp߶ISxbb;:߮@w8ȇ#%3Ii  nR5>Tmdvq./?rھ.E2_ޘ.ڢOݾ'{l|x|P0>8Y{7K!I|w0i:h |jY6*י9Dic kJ)w/M^ @Xh=, x(C".pff,}y&RKCYu[f*CrY9>vd ^(;AA[$/ك>$r⩝$",i!n~~p<#b*!)M&mxeG(ꅽ=$=Q5f5@T8yq #ʉpzґ*4\3/# XjyXWKyimI>>xY/;`@kNm,$C\ZoAe1Ұ&gfhA!cx.oe;ɓDRLm/~W&DŽ0)Hhj-pQ_Ll݄: wmRF4CCO!tK&u10 ,kGTSVrn+?HTtH7PL 0EfR4kG]1kQ`E[,;V'ǖS ljbޏK3Lχ(++&kSlBmU6ެRvvfT:IMP c-M~hG *:/B!030HBsd\ 0z{11ڥ[BFXg џL+[wy p_L}_pOy`?g`9KqZTzk攘75^n6DY *\AϕÞ|iw^*D2Qxmn<^2a,To-CE+S& 8B'(݄YcL H1A`a/m^bts,jzo\諂Nnm@7(uŨ~"fqnsЖpILQ>E4Fs0ylh1Ԣ#hY`'I,*ߪkɚvŕ_h4ҋ/3 hlLގLdOޛ2WB]|||n?%䘐D}$Ϲ4Q$T$\ިA;v2llhf~8lp8s窎yG^%`j(9̛zA`¶4}2=iP_H֘=lъοvzLl<3U`hΎzm%^U,O{PeuiQPa*Mp/ppT"k$n!r xb!if(gNfd)6o_fŕ4}lS06:]]$rRsC{5Z(b]DB`v6z') -ÿe$PK3^M],][%۵3i`GcirhCb*xHGyd$V//9|=ΪRCCw*ŕM_aIaUrxi8QR_iPc`@BMtgp>^[?o)\ ho? P5f}EI8) SNF]up>V TkJ䌁y:\c4w=_ hv]H괅*a1jq(P"$ 32J[|06 `On~ :fvE +d…fHQGYC'նWfRJ=bl4;8] &z]e^;x7Ӣ'd:`armYe)4 i:FO=;w.3@Q+qSGJʕ'Pq jI(`Yk IJ}Ix*@0tN dJ(R<_aZ*8fpwT;,fC"яW=a}8Fp2 .wZč;m_h1rkAI_q# OMQB?<[}ȓ%!4|u%Wpn9\>˾5ncؙ5e[AaJfOM+@NXÆ޷:=7ӜNF<"ZѾ4E-eT됵ҊN ;܍7>NR dD%|moJ9nEv,̱Ay ɂ i (oh憤tfk]c]%NfٴrㅌkmMS!F|L" Cw߱uD?'t1@MN)B m-jF ~_ ,hjӣ2ݳeD/HhCׯoQ[M͞3Ґ$PSWږgmz ofŅ-X5 n,ԕYgRw6k b:QV[%^Flx/@ҥ=Ýl/K>4G* -{Q0$Mk{:!u'9.JbF,5`n{=>v:d^%\ɢ jK3yҪ1/?ƚ% :SƝ}H}5g(l&&f.a"u{2R,\:ຮꨩm;qT_ f!G%Zdvi,1@GRbYd ^ n.yy%(GlM)!m]}8&$~PDqkۦkSnNU7VP*Rۑq]נ]o#jR6q UN+AnA2y3ϋK4/R٩\Jj<#C-_Y Fy5ayAe$a #כR:Bu' _ |wS$]c<-Af 'ble{{5 @\7 ä<ڏgD]?z Ֆgif]ZaЮr?OFa6M#d|MeNPac/x#j(=;C I Z3EzVqD0$f/?=Z9Mx3G6Ji:BE-chl؆.q`A/Sxp}/DFw@}h'Ƚ'rK(n!9>㱢G*)ϝ߅|gS"e6)C(c7˕<5 bheyp*$ѝ$m /N`|}& /!!#BH=;IdExF`- 2Q$ȵ::̱>6TY蹧w1ܟ,rkJ.dS*7%Ri|'r#Mm r)?v^n'XfJ6e"bbDoy!nidl5Q)?%,Í[:o1܆f Oy*zZi a֬gdUk6>] ub-ۀr?[ZYUҡ&.ӱ-L`8FnxmzߚXiGuRcb$ؓyy AKWSL{1נS}IJ^ W7`a<Cu5уkf+ճ.z8w)nٿ1/"p~vۍFit*ȶz$kgĪ92vC*|q@ϭ>`| Cưhqoy'tƗ sJ\0InO!`;\uW=Q0tЯ|KO(Mf .K :"G"BXZl'AC"vD8U}`Uyɴ( '#e~,[L![k W1p{E$!> z0b%&myi+5} N)a1 L`o j.1GFipr/9 MT "nfaH"U ҭZḦ́?1vx픴x_='-d, vwۙV8 UZUmV^tK<8<q^mv1QgRpXn9c.!dr]YJG&lZT(z 2+,Qo:H%;=!lrzKIW6\B#bVρ. Vf.+Wߺ3)qQp+W[iy \|E|8ݪS1( =Cʂ !F;}_Lw8ɐƫtw|_\%;? ` p8rʅbxby .S(-!0..$oYSE -h% R 'r%,s$6XNh'#߰SHϹijOTN}U>^>Q0^v]PDu0;űYɴhA_ Ur\n emQ[˰,Ox}I4~ @{hVJ1abcë#BM#'HuyMwu孇`MAXp,ܥx>3s}tP JEؕ0߶QeRĀh)oN9;V(Spp@$߮.\ "O8W:;ںECTU' T0q^^Z7]ׇw !Xws{tGx:;}fPOMbCOCve839b:n,B ecyam(抪sZRqW+&pȽD_{nM-RH7t\=xomnVC5]+5fѝ}׻M3L -iEݡxxMl¡!Rڊ߃=VUr<6Y7jϱK&$;UWFc"`[;#Ik./!Q`噃4i)Ĝh"XgᲷ՛ /rE"1>/zQ.=12c$0-?PrļJQɱ+ǮhGh64n.|7fN$uzѻ>1&^ Ԋ)9`ҼW֏ٝ4X3"6لw ֘k(hQ )iwܼY+l+KhMKJMQ _=y-sG(YIssSD4HoŁ/÷O:ᦙވfDmfd9A$N^whﶯ uc8م廬o& r=|4ǦEhɾyc=qA_j 5hS=:zx!\G:z!J"[%*̴;f83 +0)Ql} ts!.R.hՠW?.;6Qt)sJjT{(@Q,mҹ$]> ZXlpU%|P ^Mp&d>I P&54Xv ƴ09 ڔ[bH1,ȯEA~h8qacK+-?84|Ő8kS"v ?|7Gr]eDDH;8$$ՎTщ=%_O ePXcA3ɤğ(%00JjKϸP)/@HN9?Hsr/AYP<Ȧ Yv)V`s{fY&M{Z#yDA&$bcN^L$$V`fv˓I?&+i 8z#GT98Cq՞0Qӝ'Xp?$F~*X+|QVk4_&7莆< 0q |8*oV.TI y~iqZש"dd$|]JIB@)LvS7*hhL(y];씏60/I43?:p@N W(ՅUr#*[p[3B@ *\[=>UR# OӚm A}6? 2U|72D]{\)ԓ{:9RҍBD`opH g sv8SLCywFlm@b6Wf2kT^ED(:] ,3ck. K EmF [IeeiGp{|'υ Jsy+$^rJE ;7ٯ%RivS\LAEDo`Sƴkĭ'g?BCBbdvdAز󥴆J8 )vW͈c3/huSqd.L_+b +ϭn'Y8ٞ;_'У)BqQ!߃IO}S"zpI fmHRX]irٛ3*u)Ѐ{;90q'bP-y0bG @5P.L/Kls0(JOؚ05qsHNUʊxrѽ( ܦfn`JubjChy?ș<,@ihQp Tc20ىOj@ɔy#/ ,k wrFâ%h+Y|E)Ӡ t:;LskgkX$ 6}U"Vm .(b'~fM˷caBuhЄo5Gza}~zoCr7 q}羄Zlړ ׻d k*gIb-јbfj) yc`R -;>FrG|d$ɲV,sclY(<{fԙTS xݣn!4^m @s2u-F8Cd$F!BXW,UoufcSw;;d`l RDD^|qQM7{b lq MJ'#kzG5_R}p\D{!4k[ Tk/E5+m ӆ>qq4- tze /Oרѕ0|:;XbC˯d5{[Q H;+t%1̑нz'Pu^=q;q6Yf>&HM3O?9첷CK*k/ =t0wCQ#-n\l/y%+T" Pj]ɫ8'/\҅zD]@?`¡o kGd? >~O]HTPk>kPS ?:`8]?@jQs# vOiCofc ͠%D>z$.\g&+( O GS7 hj{¥줊+a c [%.+o>i^8;)xR#q7Cw@fZ r[ztX3FIh:2$Tk%+7z7{_`;߬G$UeHtT>HٷxG+`& o1nÁ]aP7\i fh/*WdZ+@\b1&_ҷY@HR`]5&ȈԦ~)04 WND& KXC^_4oTEy.(;n>v@zޛ}:v/%@՜QWrU$:Ti甔,-RBca!-![m4E;:HoaµYTj4qwMWep=*2[n,q! wg^߯jj~2qq3H>L#%em>j#܉"/OZA1xe9Q!VZ!IsArEYTɦV ;ՔHWu0Pa8-'%M(D±Xy4O:a +Ѓ&Rd:vVdJ:ү) >Jھ7GOfe"|`/8gSޗSxj\sr:ZNxc̜u.'S2uc9Y8'kq |@(,$#} ^ üg²:ΰ \_aa1Z=jr1JY|.mA&7 rnu3f3k)(!WcơPm\ب_]  ps>.aݹs_#+<%iѣ+|\՝V"8>M] d]uF&דםԞ-z%nŊ¹_qZ$ȏ&vLSғ0>=%Kup݉5C:z+ 'j+nt|UWK`E3%!QT:%.oG"x|bq8gUڥܭx\pXJ_lBCЫvK'h %R_7^BR!l+ْ{|jN֬l:jJW+rrW렦nDu4rSAp582}ڲ;{K=VX"^X|':n( @"NS2Sm^<وoRBN>|`$+a}we4}cVnf{Q k` 2YQoTd)&/Le*ع@]-riU `DGK'3j<ʧ>1ī,*+Lzcz,|&,:):n%/Ynq;i 4T3P *&OJ,/ыhU{偏7 :81VY}8 EIs p瘛1؅s"BlK[.r{ wY[Pe0li<@4 wdI/J8!4y(T}[[ԏ[+>)ѯd|DPi6Mçf)#*E*(܇wqb- 760Ws}$[Egm+p>Yx艼<>A&^4P @2*G"p"clٜmh|}j韠c=H]{:9,wXO=G>; (df Uhx=Jb"U~#AHvW`c.,ha:xL nK_Ÿ/Fb-vcsiBՉS6x UPXiz>:%K N#KR5<3:vj?]j^eUHຨغFoiaUh-`[Bf1%;FU|3;He2Y?m^.𥪌Iŷ7x-rLt(_=4K_+ 6̪1ZJS 5n#N9 tjYPCu |dܑ#o…ơ~҃:5WRSŶi+b+bt_LUH=:iy'z /Ft%ׁ)u|I@'0^Xj]%b2B$wǝj8Bg/Pm]Amv0&5 i=Mct2v,=V8h juI*z+텶ݳ,3[O 3QAL< yx; jvr`Vι3*}y-!hƆg5TS)5i 'v.ŝ/6 Vn3"H&OJ=DV6;K VЦ!% Cgǀxo$^k>JJPWF͡;>7<ʵhujzYqiw}RXqJDE\-oBLݓڢ|^``nv>$CmVLN<0. />m/ (򚆊p"^KFH(s|p!ճJt}ƃtuf\Q~.ђGTru0BIDT}G#;$SΌ)%/Eڿx5X\HHIKv6#M)|fk.ŌBoz')F0ۏ_-cR m1bglL'메;J)YfKB,vބU!ph~z{8c,R tDh2i,5O i~G,/55.Z#oCpˈmSZӖ`U$bwW> xqbbue@U>muXI?SP V(rzt y1i\c LwA[$`%֤WֿbJ6Kh̆ 99 WzT xw0)Ol_7WZ*Ze1^Fu]_>xHtǬ !FZŦtܝH"r#竫)Oza`M^(W#C/DA4& \ˈxϳznc䥗u]]}q3v1C3K y$`²iax,4sl*&('?F]ԧ Gت&Lzih`i٘Ԧ~L!FsU8>"(kU  uxMO`A(߿!7~ddֵnN2ߜoRR,& "c;6ߗu?:P׻mSǿ|eUj(&9 n.opt(Q?O\F5rriڳǓ vv٤F`}}5~14#XȵhT0lumSZH2.epl;Fy 2o?l[OnPnRW ]z P@0`4-v :\|Xs63"|VM#s-io4^Q=P wAӱ=: Z뀥%vex|^gP)ξpS/Nen nbn,0|`\tV[8 ӕ!2?&UjRׅ~u+&'{T7jx=F$ n$ (wL5AĽ4f]qw!UЄi&s_-EٌHe.2BypH1RaEN>hS!]kd25i"AK>5c8Af3E9'mµ\Ƨ="ԝop+db AT(p3錇{Jxkr5bƋnڂO<4?>"Ilz"A0Na@1dˈ b j'jIn̂o,ξ!eɷBU37@׮ GwjN>4эtlo )sV ie0Yl{*ĐFLcY9C?.T5%8\wb>^1 Xctg$ƙƧ7Le|jNk2ހ3*3wf[8Tt$Ơ21D;.Oxg.ϐXkh5qa?$AK|EP?5`ݸ|ED RQ$[7I|=S5O1NnjqzG7-P=z7k?_ (tT8H9,#<Y.s #/>+2D Ў$>ӢMCL#3{ǤBt7>R ?Doj:]H7]{{ j(݊_ktشQ$doÂZ3[.1*p:Fႉ/e/B'"a \>T g1Hh4hfTM60# Bx JО3c|c%BPCsIY,\;$25`~‚N-+BXT>Y{kZi/&/Xִ](I0PK=IZ.NقQQY_vЉ3Gc᫺ی?zr՚ym$3m5?`jr-j{E:'rH'jzMQ.,~q9.M]8,ԿB43–bbpJzLR㉠$z5l1KruU?eKYgz2@Wk vq4S6LVJ>ң2E `,L\D/G]1Р._|]A$,oeMU.ubfݴj9Ӈ?< Ti+/u%P$ɉZ؎TJ6ߝue4}/wfc0 tDUB{|хa&;;G#mt9 (o,6uRȩUGٺn[8f$,R+XtOu ͷ?כʠ>?Ca $?Fy xY$DŽ/rFml8/PZ1@40_PN3Iў]=1TVEƒC%wN'kvoE¯L怠ahevl^l (Y-XXoR9~xGjAzך pR(TV5Whm'j Ȱ\gvK1|@ Fu9fvj1@)<'P[_kB9٩[՛%&iMPFX5ɫRl0ihhRi޻v}Fpf5 ;yqG`Wl(*ĤEMs0G |wUsx 0Q8>W;>\0"FXut?D'ݾg{'e6Ւ@պ(.4ɕVr4cA3 LݩRZyv,m}HF\tfEEL8;!v5[`8ay]7ADاBL0#J&Jqz/I*vl4hQ]Q;5Gbfi[ W4c \CSʕf?ogZQV!y\!"yR'MDzpiM Eύo̧q8`)|*1̶.).G f'IB$5dr L y3`ہvqqU51SH,9p*B5R,lA{:^  .p-eMoܶ  :P1 E#c5x3lp9H.Yψ/Ϲ-]dձg]'Q=qm`]\T@3#~Iwy3͙P{D C<Mno?s.:^,aԣwj{X_x9ʈVѻ(d]eCg6'|xe$ޒ7Zn79zq]]< _UCe婠Y,@.$4AH/&'PY(2e$lкp*6Z6fb׏*b쏞`U c⇯ij_/%/!~NHnjArUWْT6on0(AϊK28hO̷x6r,!@_IL^)şJ)p^cS+qL)]iwY:QhYPa0F)fx`/_ e,F_wQƤIT5´Qxq5$lް,"!wSF\ }][ xAjƔ6k\{jXjϯ%^ODR}U xٚwN'a SqRc܀WG{MA#(AYM)IɚS0`I7R_b2-asb!qJP6^ジEJ୨>zŒv{܀Sdwx%O*8Kfט3)/R$JҡG] ޿e=B:2t8uޖsK2=4hCH`Á0OEƾ&5H.EVxw/zIjaSm4~*hzE\D#S̰-i|Ye3 tb1&=kbEsW:3 s~!)] #)H+mÑ{x膟Lja$8o?.XբrQfL&H^`rY ]d̓F(Xէl*㖩 /ʀΌ࠽>M4 |"G(3 ׾3.@FQEWiSdd2an@ 7gti5͠QوEo_[@ N@0~$oe)D·XL+mӮݕ\ֿEL}AS gyϩ)>/Gݼ m岲%v~@@^2ju{ ,Mu#*Hf&5^S(bOS sDYF7Uw ccv{}jDo h5)ѩՊBF1+Xq •QZ@ @[;JuTgߙ G"ɚk;ڼR?9q 1d] %.vsl+[\9@̙įߧCM>J݋v%snUO)ag=䉮^}A]HhAF[{i5 h+$'YE)N5U;IJ$M @vBYO쬘~ 拽Wٶl鷰Kպӝ:Ī8q@>5up:B>&2a_R&/7\FO>>D@@[? 4MJ{U qK!ق=C)Z-;|ui{8(Hnl:ƹHZ@.`_,E˒_+"yklb2$bcK$'r6Ê`g ҕk)]EDG;pr :e7! RK,+JOey^ D a%>Z6/ lc# ]nMj\A"n64fP=1+9/V>y;Kz4>3¥c ֶr_0"Js^)?x?4]Bc ե NxbkmGص[&Gpڮ&}"'|M =(^j}oߠvSL 0hPj+ 6a[]B A Mfɤye̖kZD(xe"'Ba, [i!%̌d)a,錁IC4 ^"-LqAJP+snăms-ʯA%Θ*zVw(J s="^eT9I.bKXi>V=]`F`3Ho2|~fj2`?*" ?#7w(s~|j6&yDHS@Tx`̄TP sc;vy3d~Eb9QHf!xG-Z%=Qݻ2Q]N4’JWIu)5i<[_]!?jaQ犰8p#.4A!1۞j+020zEh,Ĩqu8LӚa nbțkrr54wf^a* VjJMX@HgeNGVpoX]M L~ ~3 .&bs3'o% %83[ZLa9|jq1>Nq*6f Qz|&[Wbg`IԷ]k5\<Ӱwy*&2.H_ظ#{)sKuldwV0ŪZ-nm5!dC[A$ٽXDځ:TNO-2~$tևH(&}kZ:x$LF$jXE@O{I`UܞySJqqaWsUɓ3[R1괩9>/J0"dgY-ǣm`jTk!AgDgS]fV WZ~p\`z h l&UvT(B4xZkBego(&Xђ*1 d5C1ėN׸2ʼn.-`@eNGul͍PTa%}ԥi-+uߓǿ\7[/eAf ޾[z~*ex.U+^g3VPw<4ޚ 90aΣ^ ҝ4: ܬF\-aڧ9>b|oTEe<떭 Pz-,MSuQ6߸ܹв:tȈB $NY◔ V]P]][!4KMag@ަ'Kv<"O8`nm:g` ȂxLc&p.HEX⚠\dʎѸ3?:Z*- ՝҅Fy`nH_Jaőw`8~pq4$mR4qT#; >jVwi*:Ժ59 8#8BGusYŽ/e.c6s{!Q[bz@ȯ7p7 @rV-m ֤;{I5aGPƃWM?a|=PpNVѭ9 'jID [SYGzn[ o-&ח'KNn 0*@; %/ҳ@^2jc'R/Z7_|^\+Crr#;oӝACgdlS@cw|q޼W+Z E mݒ'VGۋЧPYTHcw2e9l%8uO)^gkk,K-v5_\22]R3ď= {v{-}y `&ʖP/>&;_X ue94-NY]ID3j%eaCN>f!4&4M^J h$0=DI0=)ϻ{N3NNfH19+țDkO\j^i)=6KTblc7I^c[7ĺj0B#3)eb+MT@s:!1D7a  ؒ2U^/4bwN(ʐ>aq: N :VC {$zH x%4NS ,5q 5̢g VCj[*KWҽ)(ܸP39+@r[#/^ܪP~j- _G31DבC}u|4HZN:1cE+X¤hLHzFBjr0FƬVm?}E 'I>X1|I^vz.mkrSA!4C. >u ]]íK- Cm-4W9a(4'og0V wyG ɠ.j/SՅ9G_ Cu*wA3RZr@TfMr {u8`YTx'ЉC}UZ0Jq+ =Ө3J(k:S+V82_%S$wE'NbHId& 4EdI>>r5Xڞf%OU7x;#N* LT(TY[y4{jQL$ /aղf(1 ݉ߣ } jdWP\y4+_mwn+ԾJ& /Nt $-/ FBPIܭ$YidsX45'~[ RGU|#|tαS LLU Q7lM-Z";Z'n ^_5@-"$'x|Y9&)Ł89>N{55w1B&Mx:}. WMןWL\]sTT檱 ,pa{@!>)GN"X'jc 'RCZVY]?KcvĴvN,92&6YB.ـ>_-OU9/S}y.`X"3s3 ,zt,*״`kn>M0}DY`'7Zor~[&|⇴&w)x4'D},cO1[#oș;}^R[Ռ'#]AR+~#k616fxZn,iF睻‹":aEfX}i,#de BUiH|A0Dc+žTfd=ӟom:gMIjKBn=?At;?ft=a5qHd@ γmÀP6W%&ma]^DYpj&Q}")gf^}=/ֶ *?+M?R5o.zyƘ}~>E6XpXϹ K m٢ǫI:kΧ*!}ji pyU{&P'!+wi>i5YAhX ;A6`h~'-nPjܱgAxRB`,lUw|tH8uV'w3 5_QWsYr) Ȃԏ-^{' !,y)!y%rbhT.0)!n^+26A*;n?=}*vY+Qsi _FJ椕 bF'Y+"d[3 1BNM5mxA4JLطؽTZ 6$(q?Vs#LgXQkTc_uP(X^4 |:np%vairLZ2D, >\;1ou ;mag^HYcw-/:b.P"Q ƒx!yYN̠z_=6UìIPzޘ! ZiOoػ7*>>nR-SpzL\op`O>ޮOeod g%\ߡ4JA>ʝ5*ݭJ8=`4`[Ja xX<"a53ɾ@́{ں³<6bJ6b r񖷾(_DqiJ؅Ɇ : 5]^| rk=Ir!PI6951$I X9> T \Zҧ$.|VӑCVuG,4\ouG| 5?<w/o|viyBxMl&W˽([BaV3Ɖ5Qn }G*h]q+K]vu1 Y"]&1E!״Ovia-q言Ͳa \}9C'QLOo`>FJtkNS^{\ ɰ }K'81]1'‹D`C6v/3Wb]D$$"};;G<(H!dЅĴlYΚfחwzvRDea+t *wӤh.Q_L4#iflg=tRʹ0>;,h8j3ZAe* !2tMCA9 gT活NH6i ׁ/"[]Z[E"ZGE*Y*lDPUpn襎9NoK빔|0FnU- ppgV9T$A̳!U0YX 9->Ll[%lc|OUKe ƔsNÒT&3o[w,{*G2"|W%tl!&Kذ=  {X aBOyӧ/|FD+CHI(ﲓQE.Iqlx\'u_|(%X]h)Ge!~$~C p0F}Iw$p*:KEh]8+pƕTZ" *5.j*fî#UdlGRE-}XN>)m.>,}薈3; %`(5C ,5 \m=. GJ19i$1x(j zIn2JWP m"ZwlT'16s-<W/->P*'!Hzëd@+G\יy! G5М:gQwaXL<%w [uFٲ6XBi,t{@C Y+qĔvk%@{PJrY^4&VpB:U a vH+l&x pGiFڭ*|*UbfOlV Gvh[_LLJŀZlrPyk>4*MoژlOU jGWQx^J=SgKxӰ=e8 MeAXЕXRd[ ۪4!ˇ ?&FϞJ|JFx"0ca?̦}? '*@:zX5P[KO'OXX zMmAHe1&s$eW5;ōy@bF=ognױ2 كA !ږjrIٽbV'LoW">nRB=| A5_eI6*è_o{˳_cmؑޝ.;x@‹L@}.co(mځctJYv¤8fuC@X/Wus{Ǘ^'@ ퟦDoPOGOǸ= rZ=s;K݃=΃wz_YbxQ>Lt&Uy&_\&+)؊.S7#QPmaքLuV⫏^F]b=OI]p'h[ I+º\#X61lN 廉|Zd8|췮Bv?g*7gBBɒ"tqu \u0ؙE]Q/>ؤYEhc/?ф0YIЧ&O0hJ-"1- =+YbL\iC9.lSyMv1,.j4`ڊfèb/F~1S{g3ii~r軥!dۘ KA1 31|tJ?ĈRbR , 7†TDsqoPMk^Ţ] JTр~RjP_>=^.@TkǞvAb۰h֍7/dc6ȚӤGiG( Ug}ME B=Ά)y@4j8= R؃ S󍨹ȁCHnho&jf\;v[1͡0e\"vpF,3Z.MY默G Q,ZA4h}q!ٔjv BnN㑨^6'?mTўѰ4˥&bF7P㋁(Jzr搖j, @V.rt"/s9Y)E mNzsWs#;`^~cKW-2 fP*I|1w.whH$&\Uy#TFpss3_`nRqlZhԣBiHɤ喀)L-jzqZPۿ/mRT$BƥLc?ENZVt@L-RmWe [RqwJa.){V'"ax<̟Qaz:#AF1xYڸS78h7׭ ݐ [Qx6˝X6l$<r%C]I'=,1ؖX؅ [xIp8E^7e{m{ 5Y8W(*IN&N-3!!q?". e} iŹQFWBDdΧt]2LN[\?AiFyO. bEK>k\6e<+ҾXĴ-ôo10s"Lds k6tjY<..ݎؒM3*Qx5~9m" C҅}}Xyoa'Dmwm`;7QCBP1k^oHH}B=dg \heH*n BV3%{;_APYΈ Q,r|MjJa80] p<ӏ;E`6\LBlpSegZG:؇YPZqsj {e(|5B{<b'a7:jz[^!Mg~+HϹDKdb=j}^!DHNmYӮl2^8<|MWVx'X`u(e7x'ttd.HsCb5>'mєK>;RmHߞwI4XLogީb$b[7jzОHK \(!}v"GvyGt֣o1W ct˷Ll,&Ưad[ಐ;?W(>jw`vN]x/d·V(_fa#C FԏmEX ڰs].} 5,9C"$ñt<Ŋ( (7w$Ɉ<p՚A.Zq)]Y+:71t3AXs PFjA~G/>%h+]Rn(DnsCCF2qlyջbWK;i4e+Mje1\qbu#*?Ȭִ Hm Y JH9 6"3fA[=Y1UTA+N!ųhuhإ'vH xs_Wչg z18Rx*]H˲ߨ7U i|DRAz \kZbyOǩ e}sv `WNV|+`K gr+EV `u;Po&%gɌmnt+ .ȟІ,Ɠz | M S?q1Ȑq6ɪ+KyTp3><#G0x"?0( 64'߱WJ ae[dܱy`)p(%;d h"+M}m4ϗ77^i;:Z7Z".8ҷa;Bԕ0MRpuAxۂ'[[E2H{R̾}L9hG/ЂR]"/o7a/|h*;k^rTra"+-y2TVG/ӌ @m_/3v7cuM8 0sjLlIs(N;5c݌-t P)4uA{҈o'1ZW犍3er)o:b*Lk&gDmMED$q i t[ћRsk?,V,mL+ _jmmخ'L4T ᄔN'ޚK`?oBPF6MҳAk{Ϸ wFǷ ~%Qeɷ$rt֕AkpWDh%hPK&lQ3y+ec1@XzOWD@O1E!0X ǂPRqJ&ٙ Uw]_SS4F@%bzJۑ?k Tj;b36>IJw{98? `ywTs4_SUCbp5&a Be>m)D]t{i(С~K-fCEd{eh) 1U)9o4!R(<`bp?X7VQk mbB\ ?F\X3To;sakOݾbs~{Ŵ$^wy,2թѧ l<ϛW[P}{F*,.TEJX{oa>)Άm }yoiUDJ <|GimR5C9w)P3) eax& 8^N'ShCdA pW (l@1xv$R[.+ %HiO0lWȦvۍhR?~:WAN:4Vy`="H@6R!VGlub*|z YWhIl%ӐE( _ |liJ2ų)% /QO31OKudni;!d9Pj,=q4I7U$^#` (*(b2&3\%X .s:V%g_p߅Hg nY~3\ 7Dy0)falU ǻr&8${]9 j;'ඡכ.'ZCX SIҔG@ LQRҬ9L0!h[u81Tb O*"wFrT>/ޝfq;?ڄH>%aOVY_vN=PSLn}7#L-+SzLMDWi%YmpTLwLMd{ˈEE#vS%F- #!A+bt$UE:w t@K0 >-jAY@3圉^o7❩ AAHeZڇPlůz;B  hCx/`[4Lm "/za*=@ kPyC L{sNi1}# vaSd[s\Yմ$/&ams ËC3X)gy\rlZlOhevoǻ̺?܀h=!L(3@Vjeӄ$9Fz)b. ٘"b~pCM3%S#iI8ۍ rn#*T'` $j0>8tkBhܯbNv)qɟ l̾/E5l_SbStIh4+5gȱﺰ_0f9`+dRuiVBCyw3y%7U"Z!xm:T˿ļBgHĸX'![>;mJUᰡb|Ι00ϽNAMPnN{ӋkPm7 _RDB86U8R?rR[..(EM_1#Uڏ(ۣ徒^`&#nj<}D- ЌqaGGYt˩8sXOtEh񗈥t5q;8pH%{AЫ5u;hі;yi*'i腒& .zSVnY.  įhjI\rnb׎>vYpGV,s73#4LF`—Wn|- U<'4I Na;M N2]=Owۜ0}\k>M͵{a0LOj M;εEv բjBon *{OIUX;,W=\$^tԉ&nw:u h3B蓷j]aF{t-5DOU– fMCx1Q% :ܞf|[L5j Tdnw}vktee/Q7҂|t<'?ס Om '~˨,;x45䝼'ZL̨* ?#VWx0bC1t/J1 e 0-Wh;ZKLͲ+к|*v(njE 3]߂%u2U949sYdY*sO-o vC2V RxLP(|ԛx| ԳZ!e55M静qI8ְLc*V#Ǿ.j<3VWdU ^Б̴*N-,.^maw0}s٥(܎izK(fMt3ƻ=n)JH7a9 G2I3l~\WӀ% c2V#>\(He2yj>Md1(@ X"!a\uؓwoC.*a2p[f'ΝG0D69BcSY)IВ.ncE43E:J I[PHk8c]haAzVG":cUK945vܣ8ogjӢVENhȓZr;6{ g+ũX?mxSP8 ~p~b9JѮB*4f,Ʉ1ZOD]?ijb]vh]ft@ȎÉz"n{ 89hD=p\$f%fΓ~j4BG40ʿ,t"?@_5tA49 hy;2AhKΑe<sb$j7UPVe=1B*tws\UK'6pJ: 7ͶևH}2Fj; dX4i-"C|<! l2+s;֨t aw%5v>D6ltGd2QkS9O]XU!%2`)ZphA/pt$ ;T|bqNFFGN6w7!~tl赽9g(fs€a|t=XΣ>IDh7Xܻi,W- UpfkG{v- f^g9ܻ3Tjk'ľ<ȲBö W[)7Lz:_@\unjAKabW܉b/p:Hx*=au`+  B[C3+f~݈bx$B}#^btL \Vi@PjɥKN;P@ܐ[`@tn$*A nOdЫwb̮UX):Βk&*>.,j`B[d%s #o@rt,jO x3 a * <ݲ3iC"<!q#a2,"&^/EܛڷұO΂}[O#T^*;ZܔוNAOTʀCJte G~*oжN *YbxA[DUw"Mkkx X#CLYd$EIQQ%?я8TYɅŋН&g5Nu\WvtIehY8 {E;9PDj(b#U7?e^+'1< „/eJgͫfK_Jߖo3JQuRMi\(0-;oM u_9&*yw*%jtCGl =-!OSgz29؝OY|kF\FHD}ɉc@G<ҪUC^{p EXlp1>F!`b"C[ra sW#Zsĵ3Dڿá],|eCjP=iBJWi%JufD^-~ 7Qf3]tWI5R/7nUT4%k<'MJg/G7a!F%&G ]2Т=U;BK9i&Ӯ@c:{Q^?J;@p<}AD΍6WiKrƙ.Hr62w{n@ɮWG[X;ŞKh H@wf#y6A5vM$wn궀*⭍ ;GC:dd)Xh8aO"c t$8=zX~r3bo=s4oސL>tqўpq1I#7R0Zx{SƝ^cDF<, ʍOW,m֫%"qW2V^$#m5l| ecRD$#i*A3ٜqwsx(gBX苑_TL׍=t8/1ҚW[J;nj 7{J 473uR:ߧ>BNԒR~+!xmY6ؖZl."'$#\Hl&`7=ag^Fqa9eiv,ժB'B1ybY5ǻQ3j3_qli GxA?W}P"̋0յEi_M5 Ln}//?.Iݽ$Gv 5fW:'D#0P< —1 U @0b*M\<,c܎79l\84/# ϿPo߹\ oT~%+,k2|]~c-L[hz2bcGA} qʲ LOº{p4qIRf*7Ӹ-\b;*%̦_e8 Fؿu$o3S*(O 怄lMV%G M=mȒ":&;7o^ALENq{[bJd ˧~Zfp͝ Ldvji .OP̤gz7VBUԕX}Y!G2AlmER9BDV|hGEhf~C|J?f?'F|8J[;<£%j3xx׸^nIga #<]ۼj)U7eZIQk)%Z%R+Kr7& H>k͌[:s6cy$4Y܈\ڹ0=.܍#˱Y@|liO=Ts!;x)xMΦ1mH$Z<.m#Qfkp!)-ܹat'*)v LXbuH&H0 Og9mG9\*p U-ov}1AWպ2c'u4EL^H,hz{bE8(twCQtFK+<38 gHi=Cހ*]F|ОB')De}ѻ7MX\Ȕ[[gtVdTm>/(KNrkC!8OF(^XۆZvAyԍ(ށ45uB&IIVڰnВum!jp|hU?Խ.Fm!ud" 11 9@l{y?׼^**ߴ昸Ҕ$t R꽀7VsFNxU[GONB7^l I+& LߢYADA^M̔gvMxOP?{ռm4)_S/7V*܇#+1A{ţ)I _y=KCkE%d5YDך)ZI+_rea@̲{&z꒿#yXkož'^JkUu](G'Ο 2F06{&[mE\u]W ?6Ol"-U.54ygn=8ji#Pd:=IʾbEuUr!kd$i<8^tڲ{.o_h]# }DŽS4 t$).e74a_z'Šdjġ&PHl< m[{~nN4Hvg9-ɑwi2 Sl7O \YʰDÁqZ7oYISI$XkX0I7I5?faFWTHz'j[=ٺFlMG1r(jYuXR-BEmnKG~yэкe>xE2Y2Im}X-C7C7-&M4FSc! 3h:Il^;ʓ δ"`}@'W$?9>ﭦAvtY 7K#9(qAn^6.bgz7V'6K,#2Ik3w‹S, >\wG&XJ-m7y/F 6MSŠ|`/68 LB|`w'sFhjLC+ (Rw< vRB@V(؋@FOdq7݀-jh-꽌8])H.#oRԾ(֯ʩǬJMyD㗆QM'> <9nVZh TW]:@_H/mԡzu]:9Ak'f)yy'2|9T 9dsOC?X :ՕX<$@^~ZxnW@j7•?Չ/ Aܨ:L&rlDBQPGd8$*phX ˂Y4!/]?TL].͓XŒޘ+'EXN-O8K$\Ԭ'&$\ɗ{WYuPuΓ|ٰlLX8o;W/af<;eoxY֣d ]+l8C+w>|l> W)Z3@N ӏ jNEyY1{Ӷ!tP'8tcYr;am.!)uH[͘=z0d61vEf;ҤʊѩlɅ}ĆmC46:yE^tLBz%Q<4K HFRytʼhIV #g xҔ._HCJ[E?Q\p)z܆PMgHq o>öDu0f-ճ x[yGAA>tʡ3Qґi*c*qM# Mql6Fq}5Q-,PMD8[] u8@T3-GU%5\ßHPUCa؏ g)dii}A.t$/́< orp&y<,hf%wUk>ײݯWޠxy?rެe>Κʗ Dh/X?] QVvc$6(\th.|;mn>:P31S1Gi4_euo'~] ᯐJl E%k\t1`vbV0vJ*g2=8s%s۸Cd#B*>s=}L9o峌,״=mL5V!lY[/5 6'#{4 Iu =v~LZSZqaYͩk%SoTI/E,l`QNM@MW@H^Ŝ1-A :>0Jʄrt!w<㦑%hg\8˕`$[l~u}@$Mb1]T.' g6yhBi EhJ"ۛ/V0.˕h'?wyuϜx)]\CEB 0 mb4b fN&3}Qx۞xm-?.qMnYa WKyr"IRou/@8OSxIHz>bvo9@U$N{*x7?XZUEpG+)}5a]5/h󉦱 A ҉ܧLO Ι<(s,Lzb~1*l4d M^ q]Xq-q>g+ ,7U(ޖ4i¡Koo,A!+ :5iPM6 ۶FB&;K/<^*Gcmq'wPUVf$ɂ̃{gO@w)y=28ۨupc?W\2 ẃQ|;iզ<(YHr2<9٘xhWTUHA/M&hOc|N`Qн\jEL8la1=UfO.X5!s=WY6ԛL7d"bl ud?Rd0Q"EDQ1hsXG~2x8gc"O'dE+&~m.--8Vx:s]o;nN4(s~)|8&84<5g}g]HF)ʩ W\q/oJ9AT5_+[,KäWbNvnYI.9z]^"!=Vc24<抱⮄yА([4XU$2He9DvMAmOaT?6Ǭ)U;KJ`G9P>"&Mfh OTeC۾Y|~rlMwmem_KlFï'( נRXf1q^wZz\|d52:x$D&,K5<g%~ yGRڛ䏞$WU0׿8ngcO;;]>!pCO ŇHp&Tݧ?y~riCʬc*'qi3M{g.5bRaԇGl @0HZPJ){YI#⏱0?Ak-:_kNStۘr.5[BzWE tײN!1Q+u9VWqaCgkǹkJ9azˍ :6oCqL[)O[Iʛ9:)#zėGOɲx^YhM@hPg%=!ih@% [4?pOÆSE֛TS՞w2N#-]ag/RAeLݒ)Ayviz0 kY&UE\q%(V0~!/y?q}9i(Xqx3bv ƅcZpwPOyuN;<[l(b5) Q~ˤchG\|TAUdtY}ܰ  M[K&' بאi6#?!3cYD.޺ IԤBts3ˠQ|eh x3,quޑ=R>k<ul^-ڷ>EH|.u|i+~EUN9};ԋ#s1eV^Ȁ@yvPڵv+9O%4"ʤX6_9w? t3,>]I:w5uXҶ@Hd]BJam%\QT*t-{msT!\bN`  :~HJKM"̙2S{6ko{&i|pVFt* mӋwјzt6}v-?yDgO9^BQJ+kjDz)FӠYH5'Iuqe?@Q\&LoƪZ}┐;,S{<]]Cc.LOk+:x3)Jٟ35.x"/r;" #3r}] Jx;3 i}5T5F, N cT 18R2Uyz}KAn)E.]+,eE-!?ϓ$cH _@3w6PruQ1#aYGe%J5(r_F/bîeYL ܑ%8RZ4y;Zru(`psBk?>a'f]-7쩳~̙ab, w7 `!)2_֢zf4)FH6K\.-6v&! 7BdᜲR@(}Y,1]baJnm56\Rj`sW#| mT<=u5'qy7cAt*buxGϼ9jPxu &Q-w1je#՘n?ƛ20S?%K֫PUҘ GoaZqۓ$9^N/f{Ar\"g{Y]% -P[reQ /$8@x#tD]Q<=Ł+ϐˀ{~+n-+N {9`#N0w4.=_HX,!j۬i0TqmPAdCȉewIX}bV+z^l J;٦I⁵v9k3VO~C2{w(!*z .g1٬O,pg< w&ayu8Q2%Dgϻb0{W\m%6KR#$ !WFU2^N1t|!?`yXfB> kIޯRJ!F@qEyÉkʔd~v7Vwi? ?<>| )G3r?M~lyA"SFap-FXׄ99,1p͞?Hf4(z&~ҍzϠ"In*q2o3s,7;duzpi]=/xb}ض%.b4ܠ1"d Aސ|[p3uqe:S|x j7\bLӴGnig8d 2ٔ8.壴+|A<3,z|Nl!qh>"c{׹v;l ӟv.U‡e3Ipi h/MO+_oJYqs#qX[kU5ajShMǔ)EuY@ _Er)#KX8XC#"T=`rT9>lILav:zĎtR;l9Rd`p O`qوPGx7}fM))k\:egm~ r:I5f*6ggjҝ-79!6+0,+ƥ<gDm/sLPL!3@ ] t?^*/@aoӃ ?l~a]{Wm]2EIVR褍 >"t3Ro|pGU'7Lx"igczfr'~A267V *~رt漳m&>Tܪq|$ju)..! {za6g m&DR/-Mv5Tl8=jRxn͡ztX{p@Sa1 ^juAl D/ݹU<߰/ ?>AHзp}o:iSs7prRV:9ђ]A\셋npnQ"ϏV~5;thٌL#F= xu?2Ky|pDdp`wIiE18\#XjOJ ԊCԵ˝W[YDf b2 5rϡEXĴ+m@kU]n +jK1!z$_-UՕ7f8KlbJnR)PlthҌ1m=0UF*t1`0|o H'HiK"O"d|gS{$p:.@JA-r:0.^v; Oʢv}omJNSkurSIq!^l*-қ=Hdx9rUsDj}aH_N<b@Ik2=6;E\_ZgL ~[$},?UX,^2]/e00::00L0"gð#W{MnCwP[_=}sNi//y>$'Rϋ5\v221Y2?\m=a71^𮗧?mXkbCڟ.(E1JeN#7]nG ^AN@۝,g؃cJEuy8R@'yN,ܲ$] @)Qn>F{"UruCoӶRfV@k_ÝQN?SK-7]sey^8#OHح~Se0%82fTV&\Iag]z'NM7jo+$]5t^#H<02 \4g q-/fc/9P?0 cEȒ޵U0r0{7җr}nc,ye> &z<턭YvoKvlD<]3'<IZ`lϒΗS9-Pzd*'UhwX1[בrӰ׮9QP[r.uZ/4 tR&u}*.'ʂE7A/UgI%hf hLD ?ErLc޽vd=hD͇uߎ#O;~wC0{^iZ*Xbr~7Q(#q}@ x$;9R@;{-(OZʦE liy` !fۙi%7lW=z}5A}ڳڀJIbJ$=8;hol}Z*&}GZDy=wwCt3+aw :?Zt X@Jrm {POt&W&4XKx/c=Gr|raъso7oR@MãuC.kJ D{qf.mh6I?[wV1aiK4Bk>;DHkUth}D9{%V|XD3mS@ gO&WRa61qj%勈#hu[(W+88D~]. HMo)%^auȔE:s>MKRףb%zqŸQ(ˑ`m.,M+'$0 d$KHM*Z}Rۃ2\ qGXNoԐs~%"LH.ϥY3amkoEQ #vF\FX'3 fNYMNxA'1}: :_aj@s9 y Dǜ&_@ b}q)wުpX@,?4}:sC#F-a eez:Z\\\SͷZ#½-+/gTNЪн]~=,~a^p{+h!Ov+䙪~kCO|>*E5뼳Jq7qm| ܦȧ%0?>;:CܢOmkI!f !%r9r7ie'HUar~m[[Rn",31%+nptȆ5پ}=as-8rt(ܺEZ6'[=Ͳ<腯F}2JיbX@u^rXox˘3w|EJEnXDY42}{/^8 < .EgsBL"罄=*kӃy}aQ*qSPX֎56'I^7s3fo!L} Mw ڢ!Zte6y4+{ms}یX\9c&Ъ@A@\5MX83ІiL43N] ZfȩtNؔd)IѸg# Ovi>W^gi9[¨Cp{B/NJU`6O^6h5Gw'MC R:BhHt'cޜJ1|Lնl$m0R (cq"'׈IO'u‹WJFgD>a9_L{|mB[4f);֟8!yT͎'+Do*$iQW9HƢS&!@6tEDռQ 7f׺C,X'+-85we@jwWK!Է@4'![0F䔜w1 ˱Pgx'` .6g[9 F"hv5Yw Pd&ʈdV&P_F6 1_ $-aQfPp%ᚳ5/dԆC;^嗋 &^qV*1֮,Ǻ5z `v0>QI~ߔ|b Q  2!ip{1рL.[mm_aW:n8c,]-`Kרa}f&Pߛ'q,XȄ2>.#yc˥gB:Mk UY2 _ z,K{$ȝUm4S Np^\}HP|k &CΆBb ٣MȼE.3$rLՃ T0ɥޯ2퟊{*n7#3޾WaTuVTIx ^b?&/!4CFt=8o/ߤxEHI󩤐1gN uS`W>^-` =1Yf~NQ? r eW=MsJϏ`oKlYR%8ٸKySed,N|†ɼDp0z,yK| 6ߖ9sF%I4i'ìk?w)q%FČFr I S`[_|ս?gs# Jj-9X%#hsa~_t,צ'X7 dk/z5tRoZWDb<mFX*1NJ!"W04]_g*yI.y}Dp]|6|wH<$Xn;`)d;XXC;D+s\vVdM$yBL0rd xiO)6|k}Wg:fHϡ7wH#1J~})J5TrP)H16癠8C9__n$_e]3k1ȿ$ᷚ;\՝hpI1@} BT\Z)(9:pF -~LO%W > WRZ*Ny;"o B͞"LJwش3GT^۰6ʢ}"sA_Uε'gZ^Y/GVQ ݯ!0]!𞆋=Bv%dx4Rm=bm0U}&¤?"~*4T0;VӂKa -BҶMPc)4&Q[$R<|+N\nz_ Fqh T0Wwzf=uIjz?bCb>ʼxt#µLrܚ~K%AolNbQv $cNa0vyp-%Q*Ke խida…+0*e㢠h""xB:%^4%f^i_-UC$$Aq|t 0x]sko>gɭGf%Ԩ}~vVip̸E+頑ihwI3Fk?yKGR`euKұ.JeΒ^b%~n-xlEx`FN{G(NOFF{CƦꇸ1YF4N-xՂA6]qyL9Ui>c U{:?ģu"D-Gk} IaPbQH5Q_p+a)u&ݟ2^eˋ=Fa`8R0vClt]Ac*>?#{ZiR=}e@t9;CJfɌmh9tiG|3`KX%h>Qꑎ$swsʲ7*N6/=H<)-`Qt\X&r/.h.ۨ(:FI"d۹9cF+kPXW* ,|1 ӼI0$,vF٦e<ܽq٥aMLXykQh_'&k%?S;:G_V/ME~E鼑: 0Q xYxIZnݩ~w%@+%t0Pu1ՓrQ8poR~s-НB3nz?2-D\5r,pڽ[ Qߛ^KȧD AECWvanoR?U3k:kˡK[OPzowF\a>թ~` c1 %u3TǫŘǼ ΀RCAI'ߍ,tdџ@,A b QwV0lX;(oI|n1oa`iD3kNMyZ\o*x%{E9{ڢyӤ6IfOYyRx_fڸ+BH-|` tq)'zoVc7EMDp=c!q.tRS5;j風 ]X; o h1HDfV*RrqoZ%0oZX$̔^+H(㋙P=wTD4_(OЫ]g1:i d %#}v\4)D)'Œޝ-/ ѣC85:7>^>K e>A~՟J_[>sV62= o Q+jLew-z-8+vjMze+{d=*5HUB1@0_|5~.]pt#3_Skv# f &b5]z85Y>6S[-ŻwSƹ^jaWz% t}N|3Cb]MwyI6\jÔeLW;n&EUTlM3Ytpb bVoDp :ӠL, XI Ds2z֯z8ў<5c=$oS9L0̋m1>w|$5bj9<:ϣ^? xC7GPЧ=`KE֗vV;)h#kA6cJ">9L|S{:p^uNtO/{.,Κ۵'l&\?>Ffa~DZ6]Ak >Bx]Z3Ĉ{nZzkAHCLMKӷEHTӕnM"֌`mE @Y_@jg ;ͰoT\i]"5VrsY5vt`mzM&)k p\q,RL0ŨE#햔v?2:- ;p6yG]ffDi=f:PQD _ qwlZ'Uut#ig! J>ITʝzF&%>n'Ɯ唛cvoӳ-,-N1dKl/s5^*LsJQ%|""?v)~l df=bW~Obk -` w=E@;ʙ)𥍆')N# d *ӓbΜ^X{(dxRYFYn1ujdJOi(0ΘTS4@2xr䲗ee@@̵X78mA;jw:? 9x:8RU붨ÖD2.SbI!O&.s?;. -(D"PTi*,ew=ZXgGڦLʟ"bW^5}QS}m8L P'2$~Ka9 KSOjzGk%YZ0Y*%9eWu&-.̗yjK4<+ٓi]K9*7ϒR"?a.22#Et_ށa*[sDN Lfv~Lx2SX|vlj &/rOcL 98Mp:([p݌%˨X~6HnE xULLP:ꔃJBpcHtwAt#Lxa 78FXYOE7J0\Ce맕P7̷կO~7nW*O%<`YAEH!fJm&8l7` ~Κ6ɔ %/QU*(h᱑P*}BH_-P $e^}"*4sGZ@v m{/TMX_ <}^on~ H!} ZAګ!Q.9 7VweZL3) n"S?jFUb+n?7|W-4bfZC2?*w[y/wEJ\C[>i͞p;2&BzB&jda:mhGn,;-\ 0'/grF 7;d*kUB440Cg#!qԒ?{sGoAG 0/U)RJ$*-᛿4c߄]ؽ yj*(((33_*%h==Kj>wu[.{_E'hF͎D U%LjRwk=W*)lۚ5Bz_Xv7GQ53_EМDlw¡[d= u%z-tƦ$ mtS u@lp#|9M$]A aLd(6m_5Ρ\ohR8, ']~PwdiȑpMWC j5@Ȑkuj}}\+J2C >i6Y%{LGM^S6rWML<'X(6g6pwu4 R__8 ;4*Ȅ#.XaQ/XcYr#*.MJк᜴qi{V Q7Ϸ,aP怮c`˸Q7EYbSP"DJQ)p,щoQz# uOb*WK|ȼ%Bn~=1kPV@sRE k 8[?sڼ#e+ٍQ ^AW*b\PiTECL"1%"X/m^0Kl([f.BLAOFX}ߴH/|Uߢ:rGK7(0[< TU#!- :C{paX(>^r[`ӎ< ,ڒSnkaW[z!׋ {lR<y̖17[*%Wţ!=|.=ʋA7˳Pw)IK?gR֬^Rv(3(뾮  W$8qͽTepB2(߀x39ú(H?%bѨBMR8!2Oh*Jp\假~7@{/h^J]'!/=u Zj+`Ǝ=.iT5 {_ܪtml`a;gW,{2 TsW*M[(.=kS7Pkd-7ǭDYAHx= ϗ`:8ga'Rp%WV>)qo|I0dؿmZx_*?K&jl:rN;k4g%tlSxQ2(1XdXs}o7f.z6ɷRk351=tN⾸9\6snĭݡd8{%Ρ5jx.jY;\u 3Jz^@;*EU8oPw!f h@4P^o_ t9uת<ҹX&#n:/2;}ғ4?/eg&npDT4(:`4ea{7Kf ;f ϯߚ ⒑1*Ma O7:X[7\s*aKk8}}!E쉠Fj)F~pߣ?>e| A@,iQ5/J2g[ =t2=³pNa_MѲG_9. +Ru'{ǍME1ځЍi-1;B(̣"Ank[[Li-[l+2~J-ox<˥{-xUV^qK!$$CTןO\; 6%=aM} 8HrNЁ#Zy Gj.&,iW?S{-~| d5k PO\H`QKl[$gw6= ,95mĀKD=j˂*,_*[,!Dza6$Z &aʃe.z6?72*"j|zLP=o| ( &*pq<%#qn,ۏ'XV ӡ)ӝS)EŬ Ptb~T`i#`^7 F*V~QC6aXm]O1u=:0HW΂1jo },.\hsHcҏy;g_Op ٚG5+-2n#+bW" I"a M؄[㘛/+ # 0}h+6bK`M!AH$r:-<Fͬ"v^`Cm¾ PT"54~{ZҸqOcٕKȀ9K<(MQ2vt,Ro.R6Crи㽚HYjumɻ*8El'0%*<;LEöK= VȋbF@R]օQ!%B q:A+9@+i|@NvZp`3T6&M6+ ,SXbCjī8{Gֵ*e#~lZ/usAXD;k;%ŤXhzॎJfZPq79s3F4?#!$}^ P-.MvI67UuX%_j1sÐzq֗iԽF)r)lѰĐ[J_=J˩aumAȯgeCh# |^PЦd1p1LW_(N#&pKD?YVzu]½`wI|`S<2г>hO۾# "r;'-mKdlpzfęJfێP7TRĭNmʟd,S!gn֢M܂<@(PqaqO_~e׭ݢMDڡ{<]DP#=zV 0aZGŋy5u#VhQZqg dEJ@P{>EwNF4+c#P^w{^PS{%,3rM>@e2J0Q)>G%U*/oEL[dHCKnlbm9gVR⒑ơ2灷&*EF9\air}^K;*`ܝvOh!cc剔EO Rm(:ӯk-h',S<|xf:b|Rp3IJ (/,mV̖e,yڂ1kb\WOH86@`kI<kj ~^d`>v0 ±"Fo;˅VQȘIL/gmмMNW'%A)nо5k`q dIڤˍQ8zRdzlJ(NwD$[Eb5`ST-&@^@Jd*9ihOS};1u֩(ax+&dq'GɌJ- 물x /;UHKֆ8O8{߲l*7Uc7cIUk ˟)$`9rtx4e:bj %l+<] hguIKE05slL22B&7 ʪ*cs8hx[!{y}pdLxK ˡ8zaa3C3J隘g)}~Snw\G~*S_Ks/W,gVwg4dRe)j%B*K~"C Z> n NR)ȼYݝ&k`HKdz8лwbxS^dlWҎI5v[i[ U4፠ZkI'ސYyWAiϏ%/aCXs{4O L2(hGo?ZG45N)J* X&r kVM~:S4i+}](@ %l|\DrQ)Քe"3y0q]>CۋFOĻsv\m ?m#Q#תfIZ'Ș,7:Ztǃ A`#k;oz:JG96s Zx:PiC }oHɷq"1g^B@ؽn7Lj2KiadBӣ)y)P|m?lȜF?[nX^u1/\ @DCE vpUW\72DIlsztEMAltNN5'R|,S "Uo+ \B7M%1Ά:ސlH&eᱰ#ty M!!_B2"1#od(àwcDJcP5WūLpC3drgڐ:pْ3^> =1 `(]sro\OlJUagn]X &Z _QjsO򌖳#Cy,O{[e:^0K<fwVg4@Mpw^~,ddD8b {!I׋B# /l\" BcT #S'}LWm'2U_\Y bDT>ꓧ 1(m48ґ 1 b2,BV]>r ώ˄hʄH$ 'Y&5*ʂgRppc߻$WYQlSQp,k/Y0xǧpAq%lj0[b[ۻسr)_2ΎIx?F"F?^?a;odt^lf(Sp C2FD*j((τ}u߁Zix6΍o 1Ćw=ݒԮ!] PP2Q0OX.E6ߐ@|1}6R7jd|DDv,eAo@' xju*Qػww->Č 6K PzᐔeLÆ~eQ&.1ÃE[!W?Pil\=_ʌn="FDI̯{3$YSG`zN]T&%F L5E".p[SJEegsӮIri,a'vJOlxGK rzL:䐄.[sC&2/DGF?^IpBUf>O D/Kp=97$a5ӎY:޾_c譿O q'Zn]z ɐר }*l*A8ƨj(F1[3ؘf%Hz=? 9(T&"g+pe\}aITFn|ʾPFLW(ߵ.5jш Q%WQ5sjW)\Qu;5: G$ТfVe|/H~cwN<϶Pi`lz Jp@j2dN+'̙^u_VY=`,4&a"D"h?o}-s,m!T*TrwO ľ h5Yݢ4/ - /=86|9F$]9,SsK1I]uoc,8)uMS`8ͯБ353Ft"7=i qC[\fK]īGaB`S_sNdFHm2a>B-#8%G|fӗz87T*H|e=V86/DLߧatyڕzSإHh< sI Sk6@.ːGzBT^JN`4zRu}G(UP1%ZBf p=w@U!nzʆO8F,\)cb0 W"כD^dXzu%D_߁\%<'a-.l*ēb/E3* }k 8+aL"HzڝWV $좛m`[?}bŇŠ,Mx%P\3w2A.H[=֥oC9̧"vnܡ^׀*P)HX{.\y:un2/v5=ʃW?L}5FfrCHFtJUTzXrm=Cn:t:)'+}ǠKK~/Z~,w dM8(w)_у/L|lu.훡o0ւ(>}a %4̸0 ,~B.8?d|ܐ>J`NI9gY^ FOx޽Uş3sճ{bG؀+Ӛ|O!Z1lהPLyC)j.QXKjgjJ{=QA)Rw4`s9>xF%]Yj&Y w`0ءC*X|$gľoDe)͟5,AGJ#SFkŐ0 {; 0ȁ9k$1qT'c8+Te\rB ߊkI?߬1A*lBp䈉ڝP+wRס4o_{v5e`uΩ+Uuϣ If- +4ƶoEݶonL аOlW-kb=={Eμt@D\⸰|ډ)>C7hPa)DUU/c;.|C dOHrQl7t[X=4w11zwW&j}=$8~dznd´\^Xk"_W{Nr}>GGqwxܜN7^Ge q-) enel9N'J/\_=\c{EcJ3͟E|!I1N78+Rj|JTpG:ɇW<aj}K"| wy,R> Ӹ0GݸSf6o@-t7XmҲfb *,tgX(m/c䘀}H iƹa`  ڪuvˢG\22 g" 9Pjuثgl3cM*z輸+>vb`A^ ֧"ZV&YPKYk8zNqJLvBn//A,E8&D *v ;O0E~c4G4xRM5gGG4Wٝ'WjVL]@TysOC-d!\!^-y  w*!ӸX^3R Q6Wt?9Zy (fmDKFApL hpђ_kì7"2F"Ƙ QaLW?WL  [мCX f7VjKPvk$O+<\5 ?jdzˀP^;@ n}/?#sDG}5}y.o}ÿ`]o̭#GFp^k}[0%̗KXz0;D!e9B"GoVbEܺbFޣJF & my7ԤmdHfg?B 3.RtսQ(r\[*J̅dxEue@-loՃ(av0{Q68 6})^Z4`y7|ROhRA|v%;s8m9NAș ':zp 2ߤ7;{򷳥IׂYG eGafyAІȕ ?ΟV9o/9\t=딮| j^.| ^x(4(-}HD*]!~;cbt!-3iR*m>H][N["R~oDт,֔^1ƟBl3j%ߜژG^.jb$n&W&7'wjrQJ|<>feȧQ|b+iϔ/Xxo*y*/90 ܲy|v) 26#ՉB\WV "雽D42/9. :pa:M=~O= =eA>D'K,]Hgݒ%߳jB=+s>eܽ}oEH4Jr5T <6eW{%l}76֥TN@Pf)|T zҿB;#hˈ8uиn5vtԊjurZ_I5lk cꊐ"1KQDO(UnM Wò %^9YƕKu^9UWE{!{(%'RBO˷1,N%IރB.?si#/PTZWgj5.Iv6I?&1GӲt#|YGrB)ovZQgxL9?>HFs_¾` ExH|9״rB_HSD:&k|DTRRHmlrfYoXˌ 8?  {l`8kQATi3&`{kjoz#; ڼeOxC?` ) #Y>&, Xݯn=+ ^FV7Q6$KPmYمkp_+SYJvMcҸ&ߴk}mH#bҀ Sݳ\˹OVbĭ]xk3٫+\xqGvB,9I,ѣ/b/0;zMMp>}(ejpu#5, ![b6=L`f5k%%=6/eLy4']Y-oD qLW¬b [) ,..ΟSP{k?4rTy<;{uvApj]+7,3TX|U\͸_P^=Ȫ Mr A}*凈QYTF_N^lX*-)"@2 6SW S NŢAѾ5r*֡j;53}#Eo}_Gi ӽ `ŸӖZ(&f uM_%Ԃ:ŝz )L)ף'Bn$Ef̲'\IH9KkhOפt`Es8\iy *C-*i Nm#m3d$AxMh~BQ$kd>UKmURۋѓi:ELy#ĨǶU<$FH(i% oXNҕOR;۳=,htNI Z>Q*B겤%+&]WXÏe|Q^ov{u$9s?ăra A>3()>[A !]-t}Dk6fԪO*LBhؿ;*"5ir,ø[(*57Ɛ.R-3fz2{$MeK:q}M8ҔD`w $ p" b\Y]w4 ?u#D{uh0{rL!zI/xR"%S7/~5U[v}٫cHiFYƉ^2)'p SK3`'Ep:=øCGK;B;ڜM&{s!ul& RPzJylUmC 5׳"7JJ^4\Y6A\+Þ!~Dز%`ɚLk3N#87Fϥ*O0Wȴ[넒:u#o&ƙ_8'JX`0 6vR#q<2֗¢*Bb*JvHzbq~RυP΢vh=E2t9TkB| y)W&X r ȵIRqF{]a,;Qp53ogn 8l`g B?Ř'%q9 &]J̬Δ'胾ТĶw3S,L+\=([_%(FI(@݋xZ6|%O 圔qu{Uh%^y8^4Py4WMFau{YZbG9 A4}y/Wi9 hsZ):kj[\|CNmb5"0VOuR* fc.IWI5~q&k9yG΢LQva- #ϸfMy|w<\gYNuy!~Fԙ5q2q= h9 l ~0ϼʝO6-Rkq@(Zh{"~(ŀ/@S,U,޴`<r|)}10ٟT 7HΫ/{2uGll 'TzKQчՓ9-l?=.nq6]BeW2lũC88t05s箸T0@`˽4H{l@#OR|)%PMصqCR"ݶ, f`۶]6cc_, b/B*V&qx/QڴЀEy]WP<>[lo~bB8#ĭ,"I>*PY3:FEͬ&g\_oIp-e'v]XnFX(<7AZhuA7/cQKaiܯ'Uop@z;͕o`kӒbD䄮:qWׁ@ _̔l(rkDJ7,-sN'ӿ$vI%όULhyT'_&YzÄִ@1Cd> ӾsáA=<$Z6C{3Qj̇lnAo@I,R)BBcs4α:ҁVE}C{y΁W@*k Bg\3͠D[Al7Dl2[o l ]ê.ߣInϷFc.d 4exԽ'w>QyJ 9ïr6K䓭P6tm0zo{bAрvٻ>$8j|ø{YDk 9Vsu O> P`ҰjwNQ 0ɺ7gDX>«}{@'dl9֙mXi joM'_d'}"&>9 _?FL-ab^ !\eP\DlU'Xъ:PT CHw *+ogqVp* HaBZͦn|׾e Г41f1R_!g |=D$nHND{wjfYs3,ٳͪEo{sبMO MK\<%v['XP+4]Ƽ?GCŭ^,i*LU>4|cOZTXbonw%IUHU.2{4닿H^2;l`Js Yc~kգ/[[[֡~@'ͪɃe3l++Nr9w+/sҡuU!x21T+RčKcgӊ29Y C{W>CCԆm}[88v`/Kor#]9rYru %S9WꆹtJ2.x.u@/|N?NSN峽dRd&Es u& ,f~zLP(~_ds>)ip9YgVH: __&[)Lh*w;>Ov$"Vjj?+ Ul:<VSΓ^i|b$(5kXsueͱmc @ ԝЌs!B #qti r6#_M;3ǰ l{ڂ O(v49]aAl$]"?&mי3F*c599 }"l{[~1Nh˂\"C@x16h_^//y&U_ z1@au._ƭ_9dn?~+'ҡǤ8"c:40g8s1jեۭ#;ѿ7 ] 4~Qy{"x2>6žxw%DeC&ȉGbt;u3#mmEu(L^x/-gvQI,t$AV خN%1/i+P\*DjOMb+Ӝl-ŽPKmz^i1iZALvҠ%Ém?j&'U@% 1zmPؕ0TM?22K_%QK8 1ߖ0b-rUͥd]}'Z{ff1i%_ ` 66<K;U>!נu6X~-ЀsOj":IύuU ',H /bspmӂԎ@"MQd)+0}u4LWhs;@x0G:ʶduK*io8 VG e 8s|'}uhb !-Tóii`ouw]Um\Dҗ?*uO7JJ 4V8>kʚ0g~[6 #ns /q^1d t\}f~E1?DᒚE!/3zv*&al41|l +ѷET#LʱtavYG7`W+nxFl6ys;El&^N[mN daXQp]o&ʴS M^Qu%h ppJ*zEYP NC=uTwqHݭM5dInJsi^%*Vng#)вeYzA~=|Aa,Cq9x9E.ZS6#N-{f@-EPmZoſK-%YT ‰RXc@ r# {O:LOVTZ*I¶Ih[xa/7heu^;롢%0<2ĹQ/ YU\R1$GnJQnHG~{e@z=!;anﳷ=tޘ0g׿.J(T!okvrx띰ł ~ @Cʍ_E1'UUnd×,)%-2`UB13+mw/}V UȮV#DfF[T#C)m07eE "̞%]Ӆ3Y [Xgu*/R?!)wo۱{#uS%OoHfhhJ)®zV\0Wn[on%($D #`wo'|`۞*^>#D?p)|4}̫jyӌQ?!*R6"LVX:N켧Z@C k:c;] N7R%K7. [ogkQJUeFKHA0<٘E>PEҺZ4@Za'~Ke@/RY)R{A Hσp+"\i _bKJ+ Uaw@H#̂]W7b_cX6ܑɆTbNl7(i]o[nR? YH9-XbpzrduQ̧PgGϫ œf4Z.E. rD&:k`2r}4>>)bTK (+B8í7 'KNrԮGAժvC0gnG:+Xg36C4a+DD}FFr|J;\lUi k.nsSjXߙ".dū(߈LCg5{Jà`a!K[QsmIaگYb5ASYLuE\1SnB+σ4YHZ NxQfRiKkfMŔttčEam3 D{Ll_~96ZRή|-! dfkBΝqVR]"BzVd4ҢG<'tEB2h[) VdVZG(itJLW%;Y4c^BaT >鳊rc.[P숆Kˠ})!ҀD_:fiB3+/&vEWN 8#0^x_1_ Dnkug)dB[*#<:InpU <e1+n1 G O#V'"EK"y.1 =zkp7]]sY-sn7L 崙xBZKnJ62{kz)K\ýc\/MP`pKWLE~D׃u6~Y4 U^JNR{˞,:K5/8WTMI 'ůU_jcerq,L(yGN}]6+ ;i])bAՕrPX60ΒFa!gtuҾ@ ho 7IV<)f_(Sdwݰ(Pai sYKh9|_gT)kkFR#/@9j"]a)j#TJ7vCStX1o#K=s;x##<{J0Jz?9#[/Ed lNԣGMXǛO9D=tm47m}IX.sIx}\y:u>`PVfi8{1s9]RǰqO~|A`;F%tegF?TL:c;)D{ԇkewJ|x]2$1';); `劵V0y!º8˜T&@32.ƥ[Gd1I d3 mjfUBcA5,#z#Zwٌ*נKemf]@.ˍ%6RYUcI k/CnA`Pd(J=!0 љ 0k/ͩOuҐ$T9foBۇHӼ4q6x]cjx1`^o[{o[2O ܃9lm f'5SʨbO:,Ae{I6m9sXs]5[ E½:|)?)QK9H,gt>8;:~J:iQYEUYHӭYC2B.чP9F@lŭ75&L,Ѣz}1vSoޮo[/+L,Mx)VŠkʌԓ4~'DþuUr2%Fu*7vY Vg$4iGJ _/"h<3[^k3Y[4V(-Jut!ELnKMRBfEGmՅ-LtȘz Һ¸Y7 o/nhK˳3Yl=5.Izs(9jV F/]!(H,Z8eӶ_#j4IQbrۈtIO6rE5H]Z /rn׆&Պ3?R\ +IzS[0JAux7~z/x+5?b뇅9+]$Fӎt[%2=&- ~kK{NoOtLd.@Ľ,R JGAKo9CYI?4zHy7UC6W&mCɇpƲ|JhPrRϓH%\FAKRj-H؊@hE|DcrZU6vIW4KBDs B|Fx\ ~<&+V-ʛeyq7ƬOS,#ƞqACSd7gi˛ĭ"mCB(3E(lj(HhxYXi44JR'"Js~3B{t!FP~B2Y:  ^ kS= -Da(0; 䂖ouYry&[UILAChÚuݕ,m.gNuOϖ~b $_ղ^WDb%v1gǛhPk._l<:jMH;3~2m(cfISa=cAi^$'&y'n\QG7zp=\sD1+iP#zɪGBPz;19Aдb#M޷nbDn6Po2X'h:۵Lܔ<_[;rJ`IVUEbmzsZwP洋$*#w%, E@3#\mE|uxFcbZR'jED,nA\ ~P;"_I 0-% cNHl R}ZŢli` QR<> ռ(̐fE25=V*ۇ2 IO TaO\*85HC>ڀ׵a BGYMCxsyg|w α(ۣM;0g(WuQg=8D@+qۥDYx3 GGWYRMii N#W*ޖ]"7K-QWdpUycLJ&]3i\4XR3#!O;, KΑ1})7?Bb2;zm`bnIdqdDX!BT2ksjM ^GllT#1$uK4RK˟ Qa#KP\OC.2,W]f;1Ƶ7y,gf>4&?`**:/>×T#`q3QOMSp!-u(pdjBF(שU$gYaόn7llųsf@|GE:. %1%qݲ|vyyԲpB9xrW%u\pRNƎ_luN1v jBE3T,rOdԓ0-bu$q C/(kT"E p lc䵽=\1TI) )@nK_xвX͖dWT3Be;r5 MinA3)P[\|%Nܯ0pNh`%A¢ ܧe/ `ƨ aoxI¾;ԪW23"CZ gnj?ZWFl'5]e*Lҵ Φ2p+=$כSsG#\ )+h#eӱ3(܍h=]<&װQh{)Z0q 1`$?1|xǽ$q>(d)귣DŽc7M#JzO|grp4͢} 7 fσ8,M9 r.kAa<̶6V-kެم*Q`^t3S$5OoG@j ѰOߠVi~׹-XؘdNp+rɚ\n}j 93s`mQ<~s'4uR B`P}0&>Hu 'zFZ/xD'f"-& K5FfJeUSm*0$1W3'𘇗 687h5dA gݑ njU䵄:UÍWKeBZhOzYcZJgRەaגLjƅ4g97z-vY*C! u`-^}D1JUk&yzR$/sWVh7ڮxP]/N2i+x]΀DjС>ȫUsoh;n |y(ԚoWhlq+fAh?V̞B'' #RBU𵩆Nؖ6mbX$-fϙs@v}SQ>Upw5*|l;;j|I:xpKA]$a K93B/nIԘWwƽmkL]t5yM"EܳD"$m=?>;~:#&=6-̮ipLl1iii*Ѳ]q| $  kEa84c}5 k3W@FM^%7”ƨ[ Eph_gKfwD5 -/^SIWR,1s{E=v,o$/+O>pĖlqy}Ih 8Rf̳>8,θ M( Ċ굧a}Ua;^o"YN/yHT#ӋODx;@..7Q**3 gH(b-碠]UcRAJG t̲蝴 ͇Җj-FĮGbM]sӘ=m#sԙh˖Jz$7LB`]괌 , ɑSDL`E.kh WI _.r~ޡ yLദaMsTMkdJf{[cH(wƓ%ovYO6I-Qe +&HwciFS+շ eGwW. Mj~+.sb'&Qbؓ58{ؔ)6|NAjfm-v~hw]f -˒2^rЉ*TeM0d:,YT QԟH" h6 :8v%"^#Cuq zϖ*\_+oBM&aמ- +m j'ğO~(*xeވ x3KQ Vg2ӈ/-1 [u3]s, ؖCx+Z%=|-ڧy)(H-tcBF;)VD;3c CꋈqpuY fbN; kݚp _vk({gI(Ga MU\M5K=DϔgSjʠ2Z˕e{on%FDzꘞt@w0'! z{T(u]:}v ń]xzHS#,j8-5e(#uYl2Ǯv鄏$ᙙ8^,ӘvRaILk'xJ%TwBe2W/!_="cg V#LrspbgLNrO\I@^;DB);[ URsv;W:ғ(C+Zie2jw@Hžc:L"0iR\;بxa,pS,&/'vT ڻ[n^G:D\Q-`sJ'&)koč2w64Q:@TI"$G1RyIG"VNERJXeمc|@*CoVX´G ^mL)KIZPﻫ&bA;mIwN:=5:51i|mv\ľaiׂss'SBCPS5 *Ŧ9 lI q= BFutmg"ĩ6'^ i MS_$++P߶`r5c-!sMR4!螈MXzx|QB6(G`#qM)1c%AG;|ڞUfU!t\5L eR=Jv])ЦYC;Ee,< ,sZF[ :0R-4U3by~g HkCM;*g!K)%kk10"Ƚi,l7F6 nc70V1vU`1B/6 XH_lH|! _X*S[63GsucBDj k.Tir@YM@U-\zeȯPw_~*4Ӗ1EBN5eg"f )!zâu(D w.7?gҾ,{/"&킺i=t9z\Xlc:0*n8 1ʗa $/LTu8n~@)卵cXO!-CߑQ[b&A %c&f_׍^Ќg}xꯙvz0+_""E hp{RgȕEG mv]܉4 `e4O^ĥ&l0ck](RH :R iGd?Ntuc'˴iIȍEF\*9` 3tZGXsBV$KϬ~_8фηAS=<;8)$VF9\"> 7bw')2>+e$#wM ! kdiz3 {&iM:AU-C`pJcCA4q6 k6'Z7y쿫 x<]g"HB'2@d8;u@XBIc1r/VLI2AW@o".QB/w1 #B",AU4G6M3OPuJ%EdyR(˨7 bk \eÞ$n!c@*Zh$ƻ(I !ki@?hI(;Gn=t G|>evqѰtf;k w$IkL858F+9_&z>pyi \*^zųUsNr},07;n\d6#~4$Jip]'AKG7njfqEzsW?mqB꙲VGje^{RMWvtYYKy-1LDG8w`APG񵉱瑎g_a;L⤽iwOMԛ~{0"LZujk$ } #lIJ\pߜ6= 畻T|vZhoR^rZb7W;2j"tvWrQ6?бDNĠD2ZU7d&& ]G̉TOi,zpTt2gTp.=eQg<K_! ;׳|2͗T(V{s0UILiBDδ3T%l( WCyp26# Ӈ@/ߍqLFHH+MYKؑ{q4bq̘XLQf0(pȗ ' 7Tm›Bxۻ2= {\xx"Tec+-.T~Jp(q!I}S8%BfMr} {S*+b|V;!+QJ%Σ; 5NU( cE/4p\n,69-γU@pS͐((nܬI6۞fWפ 3D$S=zgx5f}ӊceX_wUs(/Fƌ;##+\Vֵ) Wh͉-E'JpX7'13C.g٘+.'vxYH/[4$Qq&0SCQ[M@XlSg&p?}SEwI v񇴮5?J~MP~[S 3].Lak|e\;4w6z"cRz D`*Rx@? !@K}o-w!gF!5J&BHɨT|rhmT32 -פ|YFZ;f,aoX쁒k4yb?4Ap j㰛"H5d`9hܭ8pM4gLy4g,w?dC>2uay\eyYM \2BrB~Eyx fJ-+λ[خG ̡{Ȱ߾%DRnSHC3 $mWݮ {:erGk/8 y^E/R#VShfm! q&Nl+n]h% Y`G Wwa&Nm勥`"m lf y}q{Z-JTZ[f?I6pTk_ 3?IbF71hZF; ө髆yVcs],+ÒN0Vh{`u@/30fhDOTs&ϰg+ngفB( CHɍ&5Q]׫x1+Zҝa7SRPh2uT|x>]73/Gٶ>Ǐ -_N !8zZ) U!dqѻ_F߻qM}.`eg_p0'Drpa^f%\Z͹R:0> s$mi|`C}<~G^yuXǮލeȲ"|`?NP1+Ԩ~/T8љN%KOg^a#*a5O R%X/@6;፮G׹Jћѓ@gbM"]V l'wp1/ shvT r/Թj:=a /mBu?9Uw jCtPv v{@r p. tk W\I+qV"ND%f aqG0Q7;q)߉Onu#l$Ȁ Y ,FłX'gN)LnIvP#K\G92de!F!aP9a^YK3pXN(yү% Xn@t9ih5]Ũi%}͠`L* Xq?FV+zXQU븓<0o(@hQ]ba55݀%Xإ4ak8|@@qp*pCUag\rc¹ m/ "eY#? LnF0zljS=휵է"IsoQ)YZRI!GpeŢފ{#Kf0SH1}Ze'rn؃ U^tw&g*:Єܯ9Z_Lv$Dg>&B&??hSCn#?XŬ$E&,5վ UfGDx$FB\w'vC♬ ] mV׾M[b=Pdi*NF&kSAgmYbU@H3BH|:P@a9ELMnEډq@E^S>cSrLkM,P?;J|,V wժG|YEcEbH0Ux ȻcĊZm j#w)&y 5k̭w,Kf:0'2lr8O恄IZ =,%3au#\)d>E<) c)ɆX%&;`oFŎ!kXlA7nnXap:0dBQZ ׄǟpHlIC`[O:oYC(׻H<^uM늑!C/vF9g kT=UXyZԑq,SZ?A*$ Z#͖3qpB}{o@t=^ E]Pq-dDž+ehr8/65)ם)|f IIYCCj< 3vCԎ`/.hpk㉀@,t}f7l0hbAð9aΡ, N-O*SEE|C )nr>%.cwPO ,\F`f42˿>,$ji, ;~nc2{̃,x֢&E:dHe0å>hBT,3|O tՂҩFc̔b Zhi"Ct_TBH?QYߐZie|]w$=qjKb$rlln>@q6^J ڑ֡LF:lO % 9,үpz{a4qKb%Z,d o DɹÂr*";OkÇ\WY\!MG'=d,\9~)D_p1>,HYJygak(Oox}u<+ťQKI+Ua cR| hx gg1!lr W'7 8!pTagK[Opy}B2Β$0Ү:T ?yt,f{<`L؁m {`0[%񾇯 ߼= /] t*^:p/޹q9'E i3EGC(1}\:g[#ADJ-23zsN'CaSSY[7,K#d}!mR & RE6oXdZ|¨L|b; zDpC G#}BVmEFiн $c$ǺxsdXk c9JKG3-^.dL-ߢr_ױ5ܫFm4UɮrN7mF,l8GA)vUkl\AZ\p| r fhl Ǒ^]E [{E~h^ n˲"ӡoHcj߳0hx3w `1mq,.~'ϙctTJmA(*./86~ީ/jFxN՝ʅL.Ť8rDN7( <*fU% Ӧ.OLYM5\yu M99XCWZoF4L!-[F m[ԓz ?suQNgUco % կpH< IS<ݴ[/Z>KNHwQ{GABAb$߼u ܦ\CzE og ~(auer;ۑq>Z/Zw-+$RQ24jd f4ch'BЇh:kZcB?9;|%M7Hulܗ&ZR5Um+;@ VBbLb󼵖DBɋ+xcٜ,<%53]#B(/>}z4|RSEZtnwP}M4 (9+$OW`uTD#hO@0lv(]4< y;bV WDGyʬ v ߉}i4Ы]#;$6:|ys*C)nKOӫ`*r='Ad> >?OznόRUCܲP!oa+pEW퍚|-XXdNmP.m_\r%}xnɠ RC~~?0jeMNا)Njb z7MKnV_Șb (;tSc^\CA#)l]5x6RMw7@fX+_F%w%:3U>:-<#OorA8g^qv>P#б4i\ۓR<-M $yv_5yM5NqFSFFVߑOI仍h)FH2 ['ϱF]G- =t['&*! {\P?&@a$`)MCH0 cF3ÂKROK2|-qA+jst.%̪{z#M$c/'Mu'r WEWAr*,}Aݏ!F5hWi>BNΞ&5^n y[M^^Z~ ]y|Y.7랷tJx@J.YjiZb=y}^#hF݀Zjr5'BFAS֙+;ܯs*I~3@+eJzӑgp[̦Lxg*}*;HOqF>dV NNSxUR%?ոagx6ǺBHũ9Sm"/Oե#nP5-h\1 C3pR2[ܹ_IHkba0_)FVvPZh@\˛*=)Mn29W+;,eH{ i:E7kT⫱(B wښ:G,Ϛ<} _=lpBM*΄-2UIfPgHO/%搇-_úwYdX;FtM46|sYyEǶFq&W8{kGix0'~j^2k"I>I!5sSe$=}(ւ[Tݟ/إ|I !G2CNRJM=?\h,2ř!Zpc:n 4e6R$T?9|%܋k?7`̳ r'}ɂ[Nv!*|&GyAf|O\ 'CtPf|} %\>:V&Q*ѭWʶLgQ'v9 xqRYqz传'`q8E|ep_E K`g#ZA~UIEz]q2Ry ;2,q.퇷~6כ.1K8 |<׎XAIJC[v.֦? ݖ1O4ܔo2Uw545/eW a]n,[ ῾b_H<&qunzle_(1`ՊEH~O fp"a>B7K,IJiC\e-7mwl[" X$8҆"%jX)S<93_Ynޔb}bHttk/0#){*("E=q)D\׃ m=l)UbKiUƹs}r Z8K1p*[c%xb"%.yex n֋}DnjyiǺK P[f37TI03m&Tiʢ-^ tbՎ7W'aR2Tl ^x!@rt;&Ed8҆ ɲYqw)zR5[NDq!6SU=>%.g,qS욒+2o0dcDlvZ\?}ȭ)/?!^EdV|i.Eo1rO] 4PH^WV$)[~E&a;BL)%/irxHX| =[qnr,>_3ƨ4FbѤX.lW.,&,I~hrْ?! w}mXv[xyqe̳dG#Mp\kX17LVIѦSo " N3{+/ Á /vfj&Y_@y_me ߰`"sI.saTYp&G'b/zPcltfRnZa G>Aȯv<<(ZM)2ڄXɗZXWaB6m9ԻCу·4\0R7sVIn| CgAvQoD*>mަAT2H}>E{zcu q5gt5%kIw:gX*RfԛԷ #48kɵ=6lSI˰`sEzcF;"ffG̻-"1z;vHj&* 5\c_.LK+kEr8ھA*ffyK\+0fm^Ȧ>CvO~<[H$t7ݐAX_r6Str27 <9x;!ofQmM@_TMc/^%ޭVnk`ZlƵp4ZlYTծv+#:o[ș́x# |mN-ˮ̋s3HŰ>$IUWiNW?)*B֔C7ֿ +:$'0 e 9êŗ rtQz\!J\D=_ -< }X*FxGZX 3IC?T߁j XIF(|~T1*qSi/)k3]竃-jt;,v|uT3E]y)YSä-֗5cw ,BtMDsT'3P ѤR{ٮ0:7^tCϙ="E;Lf`Zm鄖VD(h~gcp1tzٚFB{a9# yVMeyZ?G6BDUf W`" @8d.W 3yO;km2@$VOrX} ӳ_ Η}t8Z湟^O"Br2pp*XW~.Iud@W0q׹`G6W /Wh1A{)rr][q Pdw 6ed1D:.t`€l1 $OIM aoћ "Cc(wdX.ϕ +D#S,ܽއ5M{ T%ɳ䯳&o4M8;ܸpU2Ol2L3 &U@MhEL߳Q8U<*C 6J.*oRP8Ǝ}a'2h>/ 0Z:sdI?(ZH>?EX!{_QR\: o|no Ӳ2~~LH³F^WS#4?_pgǪ;f`2Q͉LNSVZ LE֡oujmᰕ䉀fLUJ!EV[Urt+=:J:Lᷮ7G-SANT Kvf<+]A ^({0ܡ @F]ٴ,z 5H;fȊֈ,)-<]?n5? $]X@i3;Dvᩯii1=vKģu1ERnhk}=>)ȋ ,3hG*sʒ%`cB  `㧌@S@0~+di,_x.[8  39Ԙ>R(/ʣxҸtĠ͘ct$5AlFT[%Q[pł2Hp{b@^l'"vQk-gn' U^2%XLMH.{l$ YV n |%RqJfEZuZp , (=^Ԯ,vxO{s"eЖkwJ!mj٧t|:IA2i'GNJ_|HAͩeu(I۷K\$,C-]w \y:GfM)֭᧻|hV÷ WtũȊ+ɟ_3u+8IBX|{%փH`,7UeܵZ|Wi>c␔EBH( e42}6rt{D9:RRV'OUJ?qo :Ob`tzEvN;|$cfAY<"I7gۘiUfEn@S y֕`` $suM~2N* Mߏ%#>[a鍾9|*[\]Vkgcn뜾4fMZZ^B^sx"` ;_(B$i ّȸre\v@6 OPul==ˆRzju`B:V贩=,դ:nZ~I_ iB!-W8d)'Q{$p٘|*0`ߨ~V3BVgkC?At/󱰵̸Lx%x J'6Y _b/Ji%nMЈ)7H[ t10w'nL/peztG$ԈTEiAJ[c]~/Je(f"q>EMRіpʻTLnP)omAȽš77h 6zntBZL\MlBO a%t"Hx1Yo֓,{:7/9I4Q~(UFu82*?)TQG ّX.bWΆ#f=S%=Z$6tTq )4 UC~ 8S{-1CA@5o:l3<6|PPpLO'8Z&R _bJ?^u woRoko^c44{hUo1! D r>"2_:j-!H13bqiP[E&7^qg>(f]WUu asB% \#n!aπpKVu  L>w&75Ԫ:üCm{,^w30Xai۪]3\zXP;$5T2rm~HF*z-Y4dliѕiȱkYfh'Jq/cb?ru|5U#Tޫ;d9)qQrjw{)T*K'ԪĿpGUrܓ:+BTÎ+ BM7Ǥ/&6iەsSILq/V} Czvbc/5m0uis B[,٫rsȀѰg_s@OoTfzK#--,ڼ( 5C5P*SxB$Wr+rw('Z8aMW2Sbʦ՞^U:+XN&˩wdd4Bֻu4|^ ̾=[NͶ$ٵ>~H?*tȁxAl2oYDW  +),-v>xxirRT琩\LȰ3$̄ObQP|4ގuۉnS53"EhJju#UY/ml{e'-m+ۥ-EC[.Tm+z E #ܻ;G)n+4rbV4⏊ NC`z}l}|/HȘGwW\I^X a)mVkB/U05>-5`Kf~JL%ZtVS'D&WS*wk`H h"l[1Ճd{CZ[F*w>'b6+L6<$nqFCĥb|. FwsьDȾC? Xjp ͻ"EWJNLV{uv"_{\sQQcx%[8E@?`.flڱTM ^Dr'=V^GtgwODVpfz-/pIi׀/ Czxomz ]OέRȂ`X_s -xM6H]@̿nWLtvhhJ?"LK9z-8,,R0Bl56d„¯ Z-{"_ ٧"m% iEw1θ[>idb > pHTP)I &Gb35M.d* / Xyy͐ZGԴ(oG+c*K2pӳDg _` ZkaĜ ]~  xP/5ᔤo~<3|sHk]fP{6o.Nk9܅kH[Jvq2jyZ)umnCpP`.arсKcsa?dO`K9fOs pAKrLLX9(s*!0w.Lm{5%c$+\`Sukv֐Yx)K Ti996/qϼxMpOcdJn@UMvqHujAͻ彚zYgXӈ4e4runWߐ5FI^#!̲ pbP܏ɘG$3jЈ _Q/v#Ў.'h GR@0oe4ٲxPJ.61(~A dž*t-WiMb)urnmZhT9XrOxIP|?'ٍشrQ"Dz`pLl#Cfzhu>kH{[yC;5O5@O7H5G{l?5h8Y]a7mb~]7vWW B3X y̠=\"` F ]QTYַ1&䯂 P]˃`Ž3xߟL^M659'Il&&#L^S";UF<\qpG+yvk_tѤ ihiUz _WubSE~ٹ<8+ys.k[α%9  Y di#EzQ]`OзJƕI|ʣa,X }E~B)<1A7#C9~8=60(י۟ a%[lIߌ Z%Z#0KX=u̺OzÀʈ*DFpwo_kb  v&G"2@Vfs2.lc@،s-a`M oKcxd90prE[?v@mG͕~4̧Xe!;XPîN ,KD琣_0\&-q? gO&-7]pi}1 p,gM ܛ]/$mx7y`?l r FKU ql%QdF>[]Sa !Oeh1CZyjՃ^R~Bu|IJ Z]%b^F?rr0V TZ{_~bLBn Hy^?2󷅲i;1zԔ6K 2ݠ lDSh '>x9C#önBB9Iw_o2zK6+ntNknC_McV)ZGodB_V{0v׶ս"XvWoN1Lq8 &x DZHC~˄El~ ^c/+3`DA߽vjAB#.qct-K*E'kQ6)Y1О^O቏wRVNwey8' /9ΰsRƉ.F޺=xIKu=GQYZO1O.-`p,ZFXj`cPn=#zHr8hxH)=gHN.iN.ro't!F[ }"<1[Ƃhj̫MnzN\%s;܂4GgmR6^_1XE݀:6z E_5x۟FcCdhBYP۞:[pӑK("nkn4kw]73؆(Ěfu^]N*#*wOq5X!R!ǧc+)HjSKL(ohqtY=wXwɦ;sqxe%*,Z](>QNsl-|3DbLuPhG@y˾nPWT\l%ϭw`|!N֖L/-wCSKrF]\8BL[;7p3fch-r+$v8/fXՊaK<2ыM9e\s+>PS.A21 ܫ^QU Xbd"CƲ0XL(?AC#nӯw,Yg ׻#^+ߒNT5ВWdK ߧ5hނc쟠qkC'^{BRbH$jqAo$t(}ڑi?Y[ pe{# M>DfT=ܞ{^OeR'_ES5͹.0k10 a3zx#貃M RTX-MCTV fQ[ALpr[aPan/bGyqDv)έv2 gG[u?%)6차cv򆊢m1G儫#z&2lS[Ri%Kb/rFk&mUEuDkՋA| * ^/\uˉĊ5\0y`ISkݬQdjZuLZ%')K2Q+jW)ᡶֱ'2{U>P(-kF4e<|H9NXhVuĖoDdg8>W>'=%\Gxa@LT2:n'&a-u'o 6y# OѦ&12π2sNo1X&O{"0zL!-[ 14t>맥(h`5~ ֌t%QWjY+J SQ7TIpFh4K/v@:X/:B / )]ɦʁ߀"[!_"cN 1di_hN $Oi%4Ml #/XQBr&^,?%yrm_Th,x.Zgp9e,ˋLa,W}[#h: M~KS*zJf{`,XszBm%5bĭm/='S _ɖ r~*jXhزym~TߥP/s(S]y b,.(%EZ?YN8GL隮~_Yƹ^,c 2/d{! ~| yo$zNQ{0_ؐ}D,cӁh#O-N*~BJ _J{ϱg B8 tAJi_eDCV鞴GnD%ꤴto<~@guNl V' #sd_@ޕ\T-i 1OGSfɽqS )l2lxM!BpջؑbĹ3Pl+C[xaG GW6C1''^>zB9ݼ]亝P&NHUDCmh^%ا JIz\SoMeSDi֌W!aT0{{}hHZ/O n*IthɱL\3rϧ>xygp6,78f@,+'v7,] Csy?Y;/!cr`)j2(~oI@ d8e_M9CEd]&7S d$ȡ 9=!W8gaFk[; 7'C-LG>?jwn9cIOtн./{oCN|`).0= {OX,k*G'D#Ddc\\lWP*?XM^*r{RGqGp"src)E Z/#^6oy'Ra[R"NDyͦt9{2I`*4(KھY{}w gP%|*󴢗Gۯ%<-^ PL,ET>+L)Jڻr a|Z-)F6Du8[4l>WԹ-4%'$zso]|,{+G:)$ygR&s,p$natV9ב~T8:B4y.]"!5T2@q,3a+ta\L1I*y}|̆~ Ns I8 o@:(~q4x:.|SؾNZoH{lm%HrQDyvOYsuA~:BkҰV.Q)CJdWAb`rt=FeAy؄@O8= n?@zC R~[shl#(:(HeFl[p,tqU;LJx&HdݑzmuVX"t -k=h@i?pt*xp|I7"yTAġzBZf굴RgN~l#7sNx]~vOR- Kh|v !S ZXhjΡTB[V۸$2&Smľ27e `{xgF-*ݙ9H-8b_TK1grr't|4Uk7 J ̸@]#^{fI+kjؿN)`[' k^R BV:M!FXzX8 #s2$[(=u- tq\S4g+x} cz O)ߕWqT&Ȗc_kbt *cu!r[-u"!P{ZˣG7_Y$祧N5`YMLN!-%Dŝ[TqyjZ~>wzGtF!x@p'+ع Kڡ~ mC-ODc" [GẌ́ݹɭgk!7i^W*St%* k*G)=}Ԑd6Ф;W} W W#ۂWYVoFzx;qN~ɚJNj 3OБ %z E?i{,S7Jwru0&oMG\4" ťH#o=`I mJ)4 d:#" +\9[a.LVkarS4]D݊L@O,QѬc6q;2S VQ|0$/pگն#oRz~Y%EM{S elNv)wHһ 59#C QƗ9ɝ[ALPUK7_9 |<ᎦEɻ㧮@ɞ/=$`GثM6neaFlspU:Iwn.baq5rWlvCjx /u#6Aqzj$# ]za7=xO}"SO*D<[zpNBT }ֽ3l[8J`a>U gCj%>eO"d~_ wpfhCӆ1% OpFvT47FZs9&r.D{Yt_vRדA$HB  ־ppKF& [ `םܪȂђu 9w"0=<,5`έ-`qJ*hGLYwt'V_<{^l}"Y% 7Da RSЍV sµT~uDu#̤Iu6-B[HN7uWchhWlÅ607nU8@kuC1]%=u<7|9\Bׁ\$wz!h*u+cBZ&e $:hnt#+G qul(@0bCFj?6MGv%&|HYFX< @0Tj#<@wh 1vJ8|Il }@8;M)t1D7*P+^j+邸8NUSUQ[8؛=5^t@vjў(zkcUJ܌O>*uΡr!VCe{r4e'5W)QGLfفܵ)d Զ/'(KJjTe<~}FwZO$Lƭſv Uڕf+O羊HWi<`؂hc@WfGlvvͬy~9*lmOz75B;m_@+cCzvew@&0n. h0:Mί ݞS7>EVyWj<?^ÃP МUM.(t[V]&g긨.L]ĭ $Bf}bqTFdaM)d{|Ȯ}>;tH%T6r %O6OّA"/yªbs uqˣ]8Km6U\ɗm-)wpϷ{~}֕z٪uYrMJ6ajp>+.t)q(Yag91=@%]t3[ Ҟhxϧ?]jY !FZMXzD wWFP"5J7:xr᳚}/.&K)59#rg#9"哱E|=z \$[Y) K?2G ({9|=2Pl>7txȧpełBT%#ą*狰mfDeFT«cXQy,7r9E)f~dRSzԐ:ut܏6d骩iIg~|p8NzNR!]AS""0\#@|DUkv~Qս۩=~68+kbv&OIwD=Y86Ka _j4F7/Y597_usSzưFʀ"t5Ş sPu?I!r-D!\ꦼ'7 ѡ| TtR-c44I7e 0~;}AP^NಊhsEIeʌ*~';uܩbPHU<%#_!$[ѷ62cl:YRaC 9Nϼ0da)^- fS N+S 2Iqb6-764c|$!Ye٦LMw{5(e>(0?7Aik>sLc[|Y+Rh3ȟ )F-/B3t{w09|"z<*7Q xVq1% sa>3 tD0 2뼜-/,F+e]s@+PZ>(^HͽN&I)E}Ui ;Pzg[zQ>ޤPHz0: R튡fIa$c臘ze%=Cj0/u #m3͐3ɋHii=KS;Q{2=w!4w۱PSٶ]qe+] )ilz;۵mni| 1'R',~=tydgư0Rx r@DՉ38#J`ZN: KIb{_)L$ #g6@|Yh6e~%Tݧ4+,+X=GJB-Bp,G)a-!eB П,\O/MnTiJ1޶ #6x@Z!,i!?T-;]c'ƊrGO=jfxCvJd.q`XLA}K'-H1|#?# n@=PA>Ewȸsn o^c`k,Dr*!L.rq5ߥtUBg'a'os[RMєcf!w {_6)ZvSKc36ΤSnQ=̔XYߡ@r]J Ma, b]Iʌ1x֞1KfƖ1kO{WfeȄKTZqhTzkc~)cqW"<)I ;%JL^Hfaأn!wubq9Sx^i.-Ҟ?CMԶMȆM([ܯ A1ɉן.@u_`, E,b &-Yw[K鴾1ړB-<0P<^zd_źoNǶ:YV.i}ڡZ ^avVk )MTO/W01,8.,K|m]Eآ _G 1_ʰuy>lgo&yG^^Tߔ?EfQH8&f>I%*3Z^1~ BEV^QumOLذT CcpLVjH ܢ[F$ 8)VC!WQC(h-O= jje( zw0wIq1V8%Wj={؂Hyn@z\\;a0F\1CN&9A|w 5 (Ь⇙Ur A"MQ2mbyeQV $,zC$W 51@ß+9P1qe cأzm@ 9,Fл^nv%DVٰL0\Е|. Z DPTYTc+.N]ay!0f/QU/@pRU gPP4߅N0۱ߘ%zg~`Ti9ᅭ S,Ow_<&AO_bH5e*6(G  3e6[r}<{hN׍at-IVX_F鰈g\GV~-U7>$lO/>]RJaW/Bj}uac$'qg3젊> N7پ~s8߮e'OE*c۽t7S?768Z텍zh|W;2Ov%Ճ|f$XC=Å޶l1DSV[$z1ATMja9P JEjRUVhBۯ 2MXgWQc`Xc37^hZ93b3@ Xg<}{4 &aѺV^ Id&K@J- Tt]ʮ1+V.F:;LTr\%ٿ_.EcJ]`SqFw<ȎgJ#(n֐ߏ=O>6TB/7OzDV[qF’WUo =MV0Ss)[FroLFF0A""iPV/u%c]TgC<.w~Nc;PkTA1pf)N iP3Aܔ{:9"iց,Eo9osr `_U~S[b'3pVnxJzcߋЅEZEpoJDb\[ͼvK18_,'^Wu~O!kMD-B.Z !PhPW]%7 9[IR=1{cSbi^s%+!ĺ : >+C-G!z?ZsB33}N0 pя|@czzI Z-:=L=9Hů;UuҐXzѣlL K ablp@ovV,K45ʌ [+ 'i! f\B/IFJsO*Y TJ ?©;vI5O9aOH!n_BL#8݇W[r Zk* C7+֎ o4s%iq3UBA~9PR."55˵`tX3MduMU̮Um O#*/v7%iAͤ! 1AF3mox;u5jd)%n2OMH`=KIث[G%_ d/9/T&ߴ6BvÒV-$J洦q)V zWpC 'zI!!~nҍRw\CP0G+PMDo7#5.]M(޸ub M[>]q4wnyۗ`8uT&z$1'`j叫jPh:^@HW; c#[Hw a ,ǛĖJBW"uTZu -Pj7-SB ϕ}(Wd.MCߕvf sHqVKZO\)ړIc٤ȗwm\*[r2BI |.?diՌpx! bBkr}xL?k*+$k!e8ZdnE1a'4I4=p Y9<8'(?'ՓR1:!ҹB,JɉF w-lS$7B #abPGOpX nz]\o9ip,'~Z6i¡#~^z$H!3K[q{(.CD}|6<I~@:HYbn4%EUJy 9aosqFwG3 h PeU,ȫH^v&M,mwgq>)_I"V|ܪkԩJzD,itܵP=s!M|K(u_HMZ[7 @ PJf?ή߅~sZN6h~P{cSHȬHC~%>e|8FA|GӺʬgX+؀Xۚ,ZTaf8Ir@ܜtxAp+4\mbڳӐ\d&#ŷhN}jz";8!(`,ziV k Uix5]Щ*hnJc5W TKˀgQ0JF)hr w 7 LQSG,E^ÔM+*~gN̑d2K*7>wJQVr0OWen륟^Y.+#r$]BTdIRw4t]MmUZZmVIT_+G:-IQۺvm\ X9},ထY"Uo/Q+14i\^l"d;Fc 8c= %|s_bMnh :&֧o*A$̎SB0\y1EQPڣ)Vn#dL16/=~d%xpk1EmG[!j7 -|7&E_qP(ۡ1B2,J!bA٘tAiUv$#4> aq`<ȧ:\37k&L]oRvV$vi8-7)L@gw%OKM,V(OF)bҥ3de&Koe1ƊAiR2+}[.2C: Fx߄/2`?E.](c(qeZ؎,L0ZP)RRT]D>w1/"vօϨVSHe.܈QevLf98bzo֛ՋJER~L\%dFR*[JBsR6 xցQ:Ad*kS7TE!t`AX܆:fH&W9sX#FK|U ;{6h='j`dU"/49t緞":š:5o"v_INmB;$Z*+K7H;^})IFwhbE:on(,hT.=eD:@I,a+鞱=ҹٹ#v) UoS~ʡʦ:W= (Kv/_q1̺_rK6I߹=~I۳%w",(T ~:enGv: w;Y]}19-/rWVa]UTZEk)~` 19Q[oz:,[qERP𬟀D0>E\̪J@0wlcEbM\|ob%;f>\=1N 7A\4FVxd`DJ 6ja&՗(<$jg\:JOGnp=(AW7 n-?^8q 0pL$GZ?5H".~,2J&lyv߰: -_3yh 6XLT4íd`XАI۴R3⨯grxV^h/i;,t, 53p:6kUrP"o۠sdBHVkUPq|"vA;̢m|-~J2 |U<\=PƊ4>}S/ ]v>(j i=gmW0%G}ݨb DDX*E~:5s6F߇2&V̽DkuxˏޘD!4`(/us }Shq e=AIW߆,okn]8&&`}KjvZ~[N99UT.n E0* loXSF9fI^| H~u߬"6O7 }tX=R@TF܂ LE5!|øL/Ӱ[ sot%, $'2\wk;ےF#rcQSK żDQ8H;GsE-O Hkb+ 7i[WmfA{؜C~crPqWcd6~XcBgbϗ}&S3|AXh foNj}7vzi⺽CScFԳE?, օS̊' ꧌wiph=q:"A,sZZI[y$Vڱ9 x-UtT2@L7&>4@{=IXĦD?/PL##v;mQŗ/0\rP>Qf XiΐWLgqV4|iѦpHqNjͼQgnsF'E7cQ$Lx轵ᄥeģ)s~|NdҀguj|EV6z"*XN[ /<7q^uF6ń?=> cQ%]_3jYhh0d=rͶVWG\%O@M=ֺ 6i/2SV fqnTF}_TvF ĺP:"ƠWS-r^t;g~!@*A#u!E!E@h5:c16v"^[qq}@*GYLF(])c]鏴y&m3O3Ec1?c{@ƒQD;_W|ѷH$MCG=B@7eDmL\l|{ڳNu5\M 9|X8eatj2`ږInjYn3l)(\ƙe;Kwc$i56+6w$ ?T4)윕BHYyPtGs#燘$M[] ײ _)~tffG)I.ƺ.1 (Bü$vگzMG_[K쵳:K\I*Hk^#R=oOP204 X_\_ ȕKp볪cE({ ^UoGBMq‚i1ڷ> p$#`k#乷/(feq|z4V齅 OQ{ȩ2̍O,^oy'9=oIĒ(V*hG:55 LԖǟ$l (ơs񡴭顏o_4=Hx<$'JHT Xd)‡O<.'@m@}zt%U`wD) C&hY1ʊU9j3 _XqWl6d* &7~x%dAT`d@{y3GS"z/', LY~7+6x&@TLOh֔{Khx2>Fb`)8ɊLO'"$-.ʊ1H|r|*O儬;Et8 Lđ*T7Pҙb ?=Mϥqv%Ww{R-/rB̔RVbç(Dh}W>4L1`}B:WWudcf9µ WT(y{+0G8czYU6wz6Ιso3PDh"fFdrQeo 77fl#2v&Qh_{?a#3, )C@\V) Pt5skI] Z/#lŮ$oo`053ǝ^&! lkMC0ͥ\՟..3Z>' BTP ÃlofLTQrr*: cw!_FMդ*6‡sJ[4@)jb8~CBl.\Jךt9@y%WbБ?N烸;*툳7,Cv^mk)|&#e޽G#nضAivE/"$D|؈!UM[k)S0OB݁UN"$ cǤ8d`Fs}Gqa /LQ{<S@%zn̻HJ8]ck!BdV=`_keTO45;H|BS&QHwc֤5u /d7%ix ]A,}CX_4QJLpˉxC;h4 }XXC:'c@090:^\EHB {LX'Z^Lx2vҾM"e\:V冶 ~>%M.ţ>鳻%xC F1貎?UBzee:D fɦ]z-ot+_6ZY001 8Q8 &ZNP?DE '`?x2~:g }pK9%mKO6RħK$DҪD"mň|bH.r@|Z сMu5m㠂FKT:"RY%zm޵\ISϥm;^vjE3Sj~*LP4wB^űhڋ-S`#**3DB.)lqbG@.S, (PGy]ZF화 D2% z&DAKHgqQsn .Dϡ1ml烗1~u042ݳ7.=Yl:z=xQqJΔ{^J%L)?nS[CHW@̠,80͙=iMR,$X,K*#cyrtU{kBzOA!Pپ9@h+UZfZ-H?s'_PO OT"'=͝jG ës:PPg [-_7lH ]qIniL x\F[n_\:!{'_[?2`R\&f6BV~9׀ R*tik|=?sJ-[ڱ8o\?bnIT& ]([1bqrG?hf&wv=hU*I+F_I5jsN\t)7,c^#ёj:KD%7 q͇}XIx/" PgMo*Xrzr D3@( ^(1ãI~vK=U}( i!n,:cNHPXѸeR'f gJcF87f JFw8\-<'K/ciŔ<T,~,2l t %eܦoېL+EXP(;)L'-7V{ |G2J r7 RkI\N1{ (IDW;ި mY]#,J k’d'ˇ xc̡4Y_x>@`6V>n_-֜ۑX߼i rDa^dloXߦU ͦ oRԶKh̚B<],5Tp\U[qge.l_'ˮ_CDNFK}q$nk4i}x!y,&ؕg}]Xk kykg\dp u딝 `GW;87B`惍OX='I+U'Bk8 ZK>PnRDi;I/"(3MP'PTC0=qKQ?QEcV *{uєؼgA6+?m<6Ay?Mb[f]s\{(Y+p+N^l^Q*fѐT-`ljCvun L<$X]5`|v1׌"E hʸ"_{]d*75ç`}b϶BsFC}@vk<1w-s5 d,Y*?b`oFMtG`\?ćx=$";j&$ '[(G;"{$2AKR\2Ivi |?r*c1kqfPxԂ(֜揑 qz\/ET'tm? 앴_|FBdZǎ3NkQEm/ArXl^HG:?hzǷ†7A_UxNifwPHb^ d xz8LN}v|y;k1eRkgrYNo@7) k;R֯-%DrtJm K*"ʠ=8k̍P^o14)._Nn;T5 =|rt `Twc_vr:1e:oc^39$i+cg݆Znq7r`7Au);6&S7j؆u0 gɐՊD^v.; sR2\C_~"/+lN$Bza P 3X4QTwfd4K,/li+ִ;1 j22Mv.M%Ři =^Ӄ2(M4KWbrMmi7WVՠ 1+ۭoT@j+RݙN_O,8,3"AYsEA_/co*ax15 RZvWy_Dͱ!r/* l{-,geU6(b?n+@H旧ŰisG,}{&4 hZ &s?Y?]u]긛0?/- Ԫ ]%`c gPTĴ+:ZYr Gi4Vi#o.MJ1"ߏe.Af"/櫨/L)5.C4* ezg$uCۛ@l91s -CgufQZX$s\ LwQ30 3ȉ,1_roӖכi1 )mZ&xoӳƹOF]qsrI^'weʬΫqK!ز!:{BO]i >Ho .C5KM&4d_y6BE!FSt3\O>(FwOtc;hߢwKwV%0A( `,%f^C8D^9~:dKYɘSW֬%76Y}do78xr‚`:F- IBQܤ(zb8L7[?B-<+s%auS6Fu*eF]pa6OףH =^I(7YнHd"3k~ &ҔRTL xA_Ot758넠Ӷ 2JCY9٘'>q5O2I) ͎f21% ^s]v/Y68ú?hm,6"Wr$h})a&?iyG[dWt|Ni0gF^M Ow%UvnOnlqsh+B36\a.}tA "B֝OuUs;DJC|Z[uvwpGٔgm`1؈ 3ۓB~3pjZbӸMXs%fA h[#|AUbӜv6js[LΡ {rk>C}cqdoțBҝ.9wmR3fl=6݁/6Y>_m475U WzBufTϗ 2RЌǼCqT>ϲڦWp>Ӧ,,hhEyp{ J!Ǘdllj p='yK@KTy]"D ƲYX&f ,sI3e2_:F kN|b5Be 6*X>l2f/";C1g7vE9ɃA{ԀqӰK]:aXc{!Kz/oDW =2zeYA0~w8qpLeK/?ΒLeVϴ\)FYGS!'/vMen>Y=VH&γxSOV%%VV b=edt}UN!A*IEԥEK .0"k2](T9Ḙ5F{HM6ٗk 0{%F;3BZ}|G1dNmE2UY44~Xbf0FaU%"teږ2LjVM\CF ?$R7wH'û}$Z$B]D;XJD]kpX(kS!ݡJ Gx%?fEj.5QÕaFj9JswGFbP41Cbn^±v# ]%l_kP*x'WcZ+T~W8.rvo$HR|0VϨl}?Y)ղO(NTxr;ltx>2z][ ZA I{ QQF!%X qst"+ UHpKmuYe&,bwL*!"+{gFKyQg j J?T39P8CH2}1]*RZUҢM lE'b|-=r;B/> J&°j5k[O[ dJ"˘!cucfLy>7J֪77 j@Ƈ9D8iTzf hQ޷w&"' ̩#hA4& %|4=*cލlf#}f7E>J8A,QQ*h%!J7Or:,YŷÇ9GYS+ Jl/SK7F8YkO Z$-p S.c>;9@]!ݙ4jFcph{hlc ~r*tmdeU;+ن q;ƟXd5W=YN`޽#/8NbR^1x'yU8r-r5cVa3P/e{ta֛A9)O:MD54Dt1j1UBh3G (E4@gK!28Dj] t_ϼ=W-rLvpV4|I3Fc~l;h;jKSKX 4m3Ďr=6el:li/QY+/*_xv~F[) " lOaDN=Vů tJ(:yw}]epVEmQQÈ 7D2켛vW%ײ8fJYn>/"C~3O~F" :Jx3I` nV ?͜lD I1c '#?W]3ΛPga8]{/ŮRzpYTISehwldY@5|K Ύ8gVKtnq7/D!zhDtKH^@KmGۤrgWi٧Xrjfe`7 zeNȋsFroS=?XmT w^eyITo.'ƠAi<-;hLUAPb q}ޓh,/qUsX˻6opލoi+Y.Xpixe#trrlicY"/;NrgAbrYK S|kڄm IC<͇bܞsxRO&Mf 4sWx|0mHV)isMe'J+9qJP|\W yt}% B7csMb1+kNWBާU5O #WNDz7K5&] ͎>Hw)GZlqƗCiɯ&Obݿ&2XȮMn*1+ݴ[q`vu&yg e|=o"ԅ`j<˸5CEM/J'ݦ`Q@5Iq(a=Sե\H-_9S$f N4,r+TK感-b8Bͩa7Z dqS N*^Z*Inͅtp#z [nK(zL١tWBݲa({3v10N*62ȦQBa[$gf$QM:Nܮ<[#UBEMf{SPdžt33gǩ<3}_ Qn.JrVS%[\$I}z)gq | {+644Wq6`PJp8ȴ`fL'OneFY2 (ي-xssq?蜈= 8,yjEWת }fobYSesafbPW}mrPlSyg+$L!D15Pc57rSь%Yfm..gǭt Ax_Xy^&: قRaZ'{fj`CꈞrXJ+*Xr"?涇ۣ듈^wN~A^6d jpi/( G\͌XXdZ5)Jn\uZ3ݚG@R'#\6x$޵F!c)iUVFht0asسspNs˟s GQZ׾.Fc]KZzK^u{Tкx|0anhZh?N(D.Hjf2 $VCpBaMwV~nsҥ~lu%#]>ѿ% n"b1xY%^Oѭ6p6˩ sT? ѓb@hyx#1KpRC[DOdA%' i8#D;Q^$!N7F nМ[pi>%"}g -(wٸo >d6 7BHBٔ)T5J7X^}Fc8V,O&qu?jDc ᙋ2!MN\nV!Hog96W8o)B8aQ4}.Qfdc?16X iJCOZL$TqA "5A/.13|P۱( xsD=7b[d7ڌjv ϒح_krSՑb6`0=[[rA}dnHDG&i"NH7(e2F=t7갠`ߑۯ980C ͋bO:50AC< 8 xBrv (+v7L˒ejUnˀ1Re9Byc vh,`(]5=jfd͢a,X#)PW?jkӳ͸L a;AdLmZnm?ژH%WiU~I!"'V3p*^>R0rfCp(OԐVJԆn'r&#ͪSq2,*o Ef,( ) yK5a(2S~U"S U s+9 7eP/w>ïll9q>;bt*VU'Q NQgc^DBÌc\B6%?33f4Mebp 7V@J[V ~%25fH_Jm,QBfѼl"ӥװL~rZwE˰0 R `Au;cЧϮד?#ϳRLtqahv`*m#Uvenê-sy7=QI.jsFPp˚o62X~sjALE zcQ$m64*J6S"!\C%Q}4QC 9PT_8Cݙwšpoy]e#1H"QÐ(iؤ\qvL9k#@H "wBQu6-WAf!**Dx߻l΢F6*Z=L4BmA~ ݅Ա&#2ĦF]}w|B?jl>gX~EXΔ#< !K763 bTޘ}uRH`O| )'0U peS˱rA/|Gɭs[OaLX_[ {$\3o[`t4| Qժ&3B'@_݃mSʩ+ @ B:"# osoeEoS֯j)R&_]Y)1lnΆʏ3Y"04 Ԫ܊s;:Bĺ)Z{1R +r&2uҷB\=*(E$8c,å ݸ1oc11TBmSڜgo'BDwY(If'_$ۈ4͞^촓c7gImeӑU#A¯)2PE&$1/2 u =u)Ԡx$jl~I'MRgGQ* bC?w r5ⸯesوiCt%3*3ELPHfY|O!7#O”ւid$xTB6_Kڨ7V0x4`)qe-S+kl^j960CK31k e^ĀG<p-_uE3J+6 @,i^uo~WfihoR1z* tVсeސlj}B9He#]O_urL`)!\ E^NuVZf …'ʟ3Y?nڙ4܃tbE6M.&\RNP*aH շuAly]C7T\흝) D=zZg nuhS: UQVT{ K.Fnt u2m+I3 6ulO֖3[h9Y5}H/fk{D%T|s*bds’ݓyׄB;+9d:Ĕjh8nQ1P<CF72m l@Jibl *XW z?]2Vw1REF` Bɯ@9:ՒF6lplgg?Izvb7 j&\ڧ-؞W!s-=~OoK_zb)a| r tm4__Aփfc{th%Gt{Yj䲌Je+z|XrHsYzz)%B?m:yC=ݜo8  ]Mw<=t^NZfo V[f/t+aĭhR_[[ө8쉥1V!% 1mhY. o`x y֋= ?6=N)vmcabQoNŔHTh}"k!KXVEj{^ vǐsG#:Sa^YcSIz Aw6 'N*gW_ݙrU͵Bl@I} طR7RrnE{&iT쐔H!`_hcOJ0[yI#k8Z7w'q2xOUA3`gYI!O Bn"qd/hXgg p](#!p߳`c8OXxyډ`W'ܘ9CVϙպqʕ *R{!F$?3keKWrWАtL-nJ/B@ Ү2ghNQ0aEvbVI%$nobk 2i]٢ztXIHL7Z X?S x">Rrz>|,믦$gIVI{kzyB/t/3,~%$?i oLODav%Ժ -w$$ >VL,N5Tˁ@,ӡX䏜u (ś (ӝ \"p*7CoBn(!#b.z6 6 #"c^6YD3C$mW{gVtd}r[Y6Aj(Fu[tU*J;٧cP|)}UqӼn?X3i0[n"a:UGMK1`"e8LI_. ph|`hH0b`ErԐz7qʴ}Ӯ,6##X:+Rn&w6)chO/Y"*Kt7."o&m8;&Mw y _[hXE-#Rث۠+_2E)J#n7ɽDT>'?)#B,qw.PʹP$Zΰ3,a1I2G2S 2uH'FT.Dilg:Jincc.N9c^Ж @ʴ%fKڑR1Kc0sΝtΜ5ȕy9m(II;罋S k@9V4XB;Ŋ"ʚ*"g4E˫Y;Կq1 >AcfU*&Ւ$U->^ ._J bhKS5wf&<_?2r1ZfM!]pbA\nծԗI/9DRKkVC mԿd0gȝdsΖ}}bAnSX'sqUY7:e6:,^ B2eTeAJF"lôL!o_Cd_VZGP[l{DS dR=r+y[7X]Nᓢn`yI+%Q/BzH)ꠔsxV1%]]ኃzΜ1H5?HOvIݯ\ح[\drO{#AQ*v~WIGOQb&˽h9sIv8ɕ೛XZ"r! v-6#t< FgR}|2QC61xtв C"{]4g_)O{"C pLtfٽqQXu|\1\vb]ژŠaҢ78d.^ W4X@i%1UΔ6AZZ [ڤsCR ":˝43Hs$]ҥ#05*d:tzdHHYJj ;TuQ@ @?#!aSvN!lG wP$+.Ns &n͐==! !6/UH>Oow K]3v-)K䆛n%ЖN^`!Sh2=K8RߙD( /I'1 u47f8>x[I;]5#D0Uzrv#"uX()zJv 4oͺcc#tҭ}ݮgԨBxNQ54YPQ$ -IOQK݂]F(3K|W%b nbvT=N} tDC:4SR7 C*}mʸ k)!JhL; =(2SV.|ݻ4r9)Z p6sNwA4ՈT*:7?P>o_ҭ/O<#1C6Q gItET־BL \ fB2WnS75Ŝsw}6kʩ tҥZ~2!`qJ9 E%t7b(s|f_dUmU0*^X].}A 3!?֤sRC&F.kŒZѓYu*WP^KܡRNij8¹04RqחS;tֹܺpƆ5u+9Ҽ.MN]n|z~){]9e#iK konx܀Jd"ϝZS0{ G^˧B 4[@s[* N]hZ{SKH.‡ruw_e5 1K| .9(i*=y'84H!::+XM+Yz&$8, cGz$dG27ܜ]GF\pnْ ѻߵ?O{v,M3\[ѓ,x

j&OLS)$S[8! ;{Ғ汬TS~ ?9/۲lon1?4"ecpu>QS/Gm5KjL+*FJyK]WfOծWJLF %U0 (/Y{'ҩ;5+y yTOx*T(ܝՏM'?2N%iӾMG-`>PcEH'{h!y5MV{qb;a=7b xTuaJ8‰PO]`!+LtƳ%\k^_9"98w6?q,HA9?d&p6|&JpC˗DzЃA=LqφiQII1k UYo2 EĨZwI`\S o\D{2tUR {E6=lM-FTrux1&O/ ]Qt@HmB,m);yJ`ab;Jx<3v/ \AL\M5olAO0t:,?Z YIX;VJgZrGK#v&S%m~>SSnQV̂0NUHlXE:IU +- pFg0FbGb&ݲ ^'P䴮\41b1I]n%ȊnD*5GCʣ?֝ 8.1bI5$3 'w"|Vzy%I >KYWANKeʩv*a Yu9 sk<;1>"lrQG}h'nO|n) SU0J#-\ `d'3Ew=!Oy9oNe(I%Bƺ9v{XZ(qQ@yf8$LzNۜqrWt `#ܻhf*A;B8u`LT ih[M+"š]IKcf^1,2+(|'lQLoGqwB>%upH4 6입}솸Ÿi೵AsG6C|$1>ަC9:c3y[Pir bıg#g|7*:b#*zh9M;QkpR @>Qtwji#1L%O^FXRr7 xxz\|f+.[<46mapFL<V" TTGSYģS(IY°a߿՘(^6GT<3/d2z+ pYЃp.w!}R O> .h,&sú">Kl>.f98ׯg7[/[ӏ&29p:'rg )uw (PE2/;\RzVhio'՗.ڙM[B!W/}[%RZi# {V F\ ;XyV"rIf47ic6!m E~e-gYpTߺ~ڭ4{ {΢_M_x#EWRxZ|Z5xo7PjT[0A>d[G.Ce=Nxk|$9Q{K(ʰpf)h]')rSea$Cꉛwi,m4*DfȞT\hdXqD'XqDtj,*zaDd/BwjH#^H.[Rx8uBݾQOh$nQh zhg!n=7 $^.TxPfoQ9']G@j_ϳʭIcg7G%g "Pr/˙kF%N) Lx@鸺w45ؼ|E|2BĔeN'9ev% ,=)jBóityۡ;v!asyNoC1|/t䷷Z jiׇ_/pH(M8dSO3ޜ::vHˆ[J)>P)wh3^樽 m`L@ދLmA"aUbr1t޵McT|DS ZM0H?fSʶ )< luQ!?l2Za5?ҁ@ 3dz(^kV= :VN9ZdAdUbR&( @oT@'jHdhtgHNOuwGxCq4ovvdw <5e @G1ާ5=TjRO%Y]:7Y# x>RMAy?zoS<G?# lPv,%CQNF+>ޕKuwa$9zePm=__N>O:$fוjei5ZDZ5b̔b~$҈4ύHeZǐ~k}vر OSE2^fFNaZFQzo4P7%޾ VfɬwL?g霉deUN6 !c4%t0]OX6Z@r_^yʺ0/:wд0ui$Bn+<#bE Gj1z8mO@8exO:ngαE|&ڜ#|1Kl},!<+>)Gs9GcثcÇڇ.uܚB\* 锷O4/mJͯCCL6 ׏Bjy7"Bu28KW$3~}=5]᎗@%I_7X*vg +̃dN]~Z=3JBVb2S1wUl9˘u8X&>^OXW/箛.(Fv"@'oZ1 oT:xq6yqptX3Z?B2_- ri:B-@%"&=} ɡx;UfTU 4 &'bVKXNYbz{ŦvEE F H E ]9L 򥮿WP)"Vc*_3;Yx>o,C[ryV!m{Q唫x\S0,/,XM22Ӈjج/h%UUaf̅y5*"N`á57UQ<ʳ> p+oi]8UjsWMHWg)#kVst>g#D7VtR?_i]q6١zP>r+ Yk \kUx~EsE7w֠B`¯[@g3,]ݿ' LLl3=%ʾ VcO_ݎ-Bfӳ73ۉ=B3' 3)Dmg715 fN<$f/5 9AӍەL8ԮDMx b ԫ֕/F"98C$3iwΪ!ED1\.){y::$~RC<# /7~BKHjVЂ `Z<UPcU?`sÇqА&%?+46x*lgJ'3PN9vTDBTdP(QĠX,A-[EWcEue@#-E2wu7o7SvmI?/@:^]ֺU=]K)P0n >U@3mMBşih6d-"O4X`:HGw9'^V o[¿8D⃌A;.Ua/GՎ;yGyz$_ڐQ~r*\*@~.ifizD/^n,CV$pփQO_LfQ+:ô Ncհ* hY\IfA2Cǐy|}jYj; d&aT޻5D1=D6AU#`YpW;كuU3J\9tUS!V7G;s,~-(=T>Agu<e/yt(;%bU~c,ǐd&U@k ab{q]cT}o[;G1 >(Nk1misU8k5] EhجDB'}i.I\Pp5( hZo>;FBkʊC#Vc|`d\~Wb##RrӸ׺墾gOF:9BC[CHRrVk_ ,g=)hߝs^$=Nx{ hSi}98i7c4pSؾbvM8C@te+8D]-'˟ڧOgq7[}r™H <m.56tݎ`RL% BxFn$ b~PrT~";pV^CqM ^RAKަ릥OɜNؗXꎪf,/j=  qH5"c{^ĥ1p'GgVa~v-iZo{]ڝp2<Ύ0ǖ>Ek++ِbʱ<'iD V@5Y%oh#*-țqa~c2*D1r GhؐcǪ;$e$uҡs`AH[M!`2ߘ%} U'}I$ 5ɍ;\>OV'Eq@quP#v?'Zs/rcJ?al7~dw1_xfSlLunϏp.!f%`;WYz/J3zKya$TT/o?_a/9UXaMkN c:/N~edP<'hs½cpP%slOG"<)V4×˵^dȝ@j6 ٓ0 qn\ _77zQ| GVo!q1^p`~\hgkz]0l$߰ྮ:vڻ^羣UhК] e?h[؈o&qhF˳&|΃raC)'cЕy7ƻ)X3k(WU?5J |e;pdNVa*OC`*qqu:[<+7ǰTŸxj$?y*n.0{uY¡$Y|JvQ;0l|ww:vݔA 2}MnƔ|*myNaoࢁ1hOS r\+5QYԗ+{$S}e hͳ"x;Ea#wb.Cݺ~03/܌u Lꠈ^Sqb,_>X&cF8ʼn'a8`91ܗF1hp *Py*m('AHoXOX|Т/wj E>N;; 'O(}{ObbB<ȇ뱩ߖgp% ɠ5B/XE)v$&Vkl_r>LɣDixp b0ܳ8Qt,3+]ՓM4GǤ3EscBY3$*ۯm`(?i^R4l Lq-A0(zpnnJXیN7Z7Z@yMUp+7h}VWtXvz=hmao ?ߜMpiuZ.-awh\B>:J!ST^u*=Iqr>[T8f7#-zJ@\B}%WZN'g4>:d*J|5k=d {nԆy bRIR'S"P/Di"ުPJ :~MpmV@vWr/QO,hjrQ4Xم4!$rIg'cB$)Bj>*0Y|+K4 SL(?6C_{w JV9;2\FL#B7XvPmA%Dk 21DyJ~qAT`h$bK L#FiCG1wB"2?j8w"aKPYʈokE4/Q&Wp_]54G,q.'jC#RKG2q cfZ~,zt҂P#}7GFYR|nNm.['Bρ H )}2~O3 IpNEud@]r1FK f^M#.F} (loj"m|7JFS?3KԻRҜ.n,RGXI#뢡nĘ4K],zP<\FaAZ?Pl2U> o4hw ekst^LlxЦ?$B89e^eVŸ&,p:` h}in0=T{EYG#;E=SfW h ꠽nbϛ[,/ӛw`V,S"*Y5'@7:1t oЊLAX_n4-2yGcN-ɿ0"3/l`*!4;h-QF(U_oQ;8y`j]WKA+Ýՙmt6 O,f8+6t (-rY:"=/qP~G:_6li8TIp,tn tlȁ-߁D2$ad"pn1$ rP|+IΔ: 85ci6%/=U"Өibȵ"gVh~ϑrv.//哗ר<)LK;+8>bS-U Rce_)Vr)`M"QUYq)|ԾtLQuz:ӓZɹ&Vy_C8j~qpKf1i&M0b2RRV>Zw&@i7g#̓ #ESlL&ղr r:V9rU=TI!&M{sGLta񔞌T'(L$=){Ȳםt/AC'R36Gr/;fbiHNX{,75f,]؏@JNڑc)%ĥ^+UVR_f n"Pw>w s'e~:X8 Zc}i[.ZLc&}Geu/(P鮖S$~>[ [!,De-E53$Z@ 4umH]u|&^|}ޙm>2=<:OT˅+Nc x4% zUݟDPf#p].By.ІOQd"Y{iRH_oDɡ nI ' ,ǿ+xa']n[䬱 ?U¤E*e % ,C D]/CiUӯDwO{sH56vXD>55dLJKĿ q4ozRHPX^ۆ䜝nçݔn/;BCg]p2I;>nc'@MED3pyn(ŞmXkJz0ZiS܆! r3c|W w8H4 uCӜf=q Y"|{t({hvKӸBčIz2/O4gUt؜VK\XPF3kip?/˷/IyʯSA9EξJc/eClJ(B{1)n ,Y E6J<~P(Si ##éD[eSVv!gU\k 3܌]ET0r]84Oώ[35۾- ʫa&.83>z9Oᄈ[Is6]Vg`R^) ꦁϵŐ:ɢ{uwUyD ,Y$!1QzFZ|N Zwd"s_^2{Hg7G#eL 5ijnB)&$8&Cٌos͸3^oj,17pc"" ĸC.szOJs0_kx$ *VFbFj?^/x\&QoWnz xvzKOE, ,ʸI~2 O*ٔP8=~+ޯIY qi0G=lrW[ $<.1F )@3 T'`ß}96/y+5?hӓ >B+ש>CJ౻@"#84vwaץgp onM,4<;)NeSsCi:glLROĤ1#}|Uݒ2&QhQװ_לՓkD;x< Oe|@q/IGb*Be[^߂E8Ԁ o}[ӿ[2#6 ] 6}/<҂Zw ,oC\PYǓ[v+suJiOcSuK,';kļjF_5̮a"LEYYV@ox,=nz=ׁ 4dqA/%]t62q@zȜꁇS,ԏ!=Ik$c$h>l1kT*9-z x2HR@sƼ>|^[GF)ƒ s/bUditHUX}u@zk9/^,:'bDL:Ekܧt> kKʿkM\W?Q˰T`74YfK'[w4{n\*sa0m\k_َ8E@؂X?-]G!75_B/<3taF2U. !"s-'p3֤Ω5PWo=_7XjyMrb< |'OE퇻Yd#7}J >bO*fFh<F#D8WXRŭY?zLWC'I;'>A{"A XY]o$`%JH^B"W09o+ʚ,;:֨Oɐ*"Wϼ8[a (\bCPx{F%ފ "r܀Q02Q&xhw۵|oqhxcxdt'Wm2>C%劑`+q@q:k äS)k@jɤ8|?y!~tW C촄FK< Q=m6ŽZ^יZw8"r[%v 1kuܪeIE{f\u573xיk~Z|ϩp~~:$,p$3FC:qliUSI HZ< pe"-rYIwLG/Bj+,CM 8=g@%F#݉V *i#k^S˜hMtns&gu= L{xƊc:`͊l̴ęO+ep+/iQdk|]}%nE6I6l2ks—z-pgWA݌7ܦN˴DH`-\(a*)C˻ tGmHUgۦ8nFe *F>w?P068-j6Ē2|x鞏gk+Ox{H݇ m&Kb# \'E%H܎cUbxBf#;TS78i+B#B ;Ь6]ln4}Be_/cloa*UxW{7h}dIJHkP&^KI)uab2r5OQI8q/`9c4S7.Qnj–MHRE{mqMԗ[UYo9BGbwTг^[ 3Ư.7P7M^E~j-jH ([=wX${2@$/A#1C n JZPRUMŢʡ:,r[u-U`.W9 ~?Ѝ,o\bHlTޙarh sdz"D&MCd%za\3_?ף4jK|I~p>IH,Tt, S(*/0K h[f??\U:-$>& $3BnFi &[?^9 [ZƳ,ZxMKIwg”E*יNKaflxlTkUsz(6<,.rfPqL`3"F&#}\S4C1xSգ*Fz~ c;M.B7Hmw]*X^-$vh7ѡBv%9~X4BLPA&8ZB@6*-1r`,}QFFg =g//` oWX<sW??KUZsqq165̕o9v>@E 9<6khj3Ѐ@&;mrU)H/Š2)!gE\a̲EOtf9^yN^}@ aC`jf^PРk ZuP";=t]cŃs|!%^ T#݌Jp^ NX8k%I'SrVQkR]3q#K]{r&8S\=ޛPXb ʴcaB ^˔120 SD<댦cw/z,ɚֶ%nIwu|M[]4+N꩸uD=|֤oG[|ZqROW)3A,zY'zuq)J|' ѳ=N@ؙ(ihHc:pʠkA>IO>{3BԵЈc ҳn{[r:rYWFܭhzCԜ^/䨣K5ǖj\ԼW؀}jʾD M"ddi藛nSdavEKx&lVQ#au4ɰBNJk l 7}Ș߱|rT xRٜ\*k"Q߷ է 4Nۊ4M cb=i?/FצOۋ6gǯl7M#W`a/;wA?1݂Ҏ+&Y6-PpLr4f,S_$oDcrSp*?g@>,uVAR_Tv 힑MMEj $k|,uG r4=kh!,+fd5`՛If960Idڸ>SWàH_hQA~74Tbv pɾ4vI ["ڦ*uPN3< W+楚3HEk8,o(6adhI(]b 6STt\ܺރ־'d;GM(ᡷ@A xv(KpNO|Rs:R<׍~$q4n'yw8;Oȝ5[GӰNsgߧ5UQtō*4I_Mxy '( z@"5'ڱ[T}ft+@+;Rdj[]]¤SZ+T{S f_⿊]nwPK}BfM7j&ͅa$Ixn Tn_ y-uhJOMFq_Zrnd%o>QMb"GC=Tgb/]y`^#289TQؐ=fg*X qBS 㜔> 8%[mPxۂ5o<陃Zfa7=E+cGfߤ-(c$T2uZYmYiUBciPydyѲq5(TɝPIc"`Jk E{g%"d/_u,2|՛}3qCWp&T]N'seNl'H\D wre*×rWҿ%ݟ|7C&֣Sgg*%CJR7|llg$,G~ئUӘ9 ;@s @Ndq"Wtr䡸D5{"N0|%}OdXR֝vZY9o'5J*keg0,=k\Z8mwxoVg-4@o+-`1%]M Tִ'ĔX'ƙrHE.BeͷOE3 6WPk< s)# +/6 m QBAґ&gjQ}ށև&] 8k++8rߴ{=?J:,֘h2oaڣ4_9,[_n6a [6:c.z!KЗe<dNJ+Ĝ>8K# ӶHE qhobj^qVlQGwL"y^VC|"v >3󰩘{p/]X}L  O_}>P0uVŔSCƅr' z(i@y\{۟ a ޵᱄_Dڼ+X4mrAƟ_[a= <{W鿋|I$H^NT¤5ҴBtUaJEN UYȋݾxTb3 ݕ*<6D*nuT.~ ?v?p^[wH{[!][2y,G\YsbO+!tJfEgUuf)KKNI}# uIf -pY <q '%˜gHW KJdžV}0r^q`B.2i X' <Ia?Sk&)" V7C-aÎy6*hB`og6NHwӸ%ړBG34t!< [oSI9y"S`0sׯ1{MJz޿M!fK d3NԙҬPZD^9,Bf)rC.n㦡(\nmr|@b(QiIVIԤ %暸GEj^97d~3 R ,^kJJh1hqshm]a5mfAǭc4ִxS.Q=D7 aݨf8^Laۄ a03|[p2t3p= 0x1)7@iV eN.PV3DasuϕJV-xM"FAof[夜PYDP6ME.7$sܣit{С0voo*&N䡾<%Jg y*МOR i2:: eD̒lhXEțxp>z ^0>q Y4op-ߡ`CjH7'.љ~ka&_[a9tpKs 7:G7k<+:/ ;ktX)9UџrE瞇]\f6CN# RP{D&f;okLZq7O[Zx(JG-ԶNwy;I#Z3ovAƾ[zFSֶ85 ԽR%/|S=S>޼(0(4<78L}6YQT_8ISm ؽn.1A\GHͱ׹V,D\Y+!7&A&UTq̈Ew0AVZok!~cwO毾p b,(>ۡRGrw)o@bՉG"z{(oc;N*<˒_{[8&QDNΝ H0R?R50.4-O5*ߴӂ~sf'\ Tj@T Fimm~x \[W']ҸOzԢqa;h!~xz}҈1>2Oko:ԋN'k83FB)ZWMQ?~V!=k8mV OEdz5'Ԭ8,beG3q9I0%nH˝ZdޭͬVUe[qjU n6!ᚳ:Ke%dV(.1J)Jc2J,<$_yכj)]H[FRsv'O3L $'O6<#z)otuWsT@.YkPMQ*gE;yJKc ўdB(L2& G:H1<\_ق+Cӷm_3(=>\iD1,gR?Q[YuZx?z`qH8rX|0Q:&o7Bd2Fd͐>~^ǂu8yybsMvqTCFQ<&$7Wm0QeKHYiz*y .щ2,r[[hO\&a0 ɥkM" fR9@:(Z'Yڴ ]O6;J6j>ܶTkdr*Y Tv P9 eyY-I8\+"4V1!A4 i|Pw͂~ڶO GasƵ)/DqFCTݺapp .Zts}Ԙ-A$\'˺lK3EFH,EħzE i{Cr%R:}\MgM3\;Z)ۭ{=M‸Vrܵ3ۣM-'fM !>pT 1-&z{r'ἈpiWXI†-ٌy[wk4Y9A.7 p2 6Hr'RRV~qd"ѐӘ(n]uh#Dp ]KSіzN[1F-R2NsdXυV9عࠝrU&1\bX-eRS0] -iqĚ&WV"y( ^.?D$tZՃQ{pUMaCquf,BQj'!I9F!B7N嗦 :[l*"v,鎫"Jmp[=zf5"ɜ=pg"O?9ХR. #E?C]kэ_+_u #MF}mZ'cF+ʀ%Әv<ͪ_)𕀔}J7`+(xDc߬gubXica&n 7 %OKg>M8΄?|bŤՔ .}BX$<;|Ls*ScG _p7L!1F2=}?֦sW-)x+YQKe9^*K vA[S,HWԴXi{{f]Ɉ΁ŖºwYYFq { @P ?<[%$(C0CĮv!ʤ" =蝇fw:L{YСorpQc*RՎ鼔+RKXsCGSX]G &_:ꌆ1. >,E)_aFRNC_]o\YGWzs2k,p-S}mKQϣGMX (۰=ڵL n+ͰBLU K͐2Lx=Za N{NΫTLTX e<5XБ0x2-z4g m ύ½G46cSi7QgNtQc k7IBd[| E2m CڻLPp۽L[{΃]M>{SOZ\ ЩQqefȧfN!X i+u3 hIIP&֕lO&SB3SQտB{ƕ6޴` E<)o '\{-°#0,dHy%wZQ5#nSFNC-ƍP7qƑ}eecx1j&V=͡-yHy9t鳮 Lf֮a r[{fiH 07( @:̇'.J$*`% }i?kiH!eYD %E^:s=&WBTJۤ"#ԵS}sUL')/WjV0/ q9~RN=$^H蠿↎Am}7g83҅SQ6[ ל;J|RN(D3RG,ki]琱үˆٝ5 OGQ^)>1UQ#jӹ4Z;?(WP]Ͻ PrI'ӗLJ[Jm3~& X|"]FJ·"p%Lݖxbb݊xQ nx88khi5Ӧϭ{ $;.->q@Gko`Wg1W f;ο]lttV2;5u5>0!< aT針Ek2J4`,8֜hГt-cINN qb>MTJ\q$04FNO,p~7i&]!ă %hϯa)mX$wuiGF5ڀm=Y kP)PBv.Y]T E3"/v!gЪYi[&w&jQpaE|!f29|9g(",R4_\ǽi/ei1r^఑[_3o~OrJH$`76Wj &#zqg V|xƍݼ|AK [yDnYuPA'FEdTnh k^ቆ:w{u([/yKd0ʩ7QkK\eZ9 `\ pw[}0v>3z_< :R0sMV%^-C [ۜ{{Cdfg{1V\r)|A/*GWLsYG+c@BVo<0NoۡMUKU!1Ɔ_Ik#bhkN -sr/.˸&@$F% x\9 ׸ɡ=DtF^8޵@31ޜޅ@MH-R}No']cOze' d I\VI/qIaڷZHɠq~t!F.Ԛ/ ml:8!p7J|T=yur9t`T#2Cݶ)' -6Ǭ8uROGؾ{#23_oRy~YD5DῐB)>UThpKYC yN(i0y*hbdg9h5+ucq&VU_.u饽͋]^+jGd #Wd`Qu&f9ue {՟njPKƈ#<$]EtKwG) >3$TzId^z&qPםn'-)Z*ݱN+ΒwEDQtkO"Ș ڭQfÆƼ?H~i+”QNw+V~Jui\ ~(yDBȈcuVtJNFn?t1ȒշFLq-EO_u{UI_B>O:;9C`&p"#~7P LI R&`/ї-ydNk`0j_24ǕmyZ@,z/TqnL}قRW}{*M<QWwk:\^ zKh=FU9pC-@g\ ZD~gɕJ5 avrkƌG=`%\\_{mw^NL, t8lOND9Yկbe_k+)yo+q针U :‰P=qU E;qMBs <%%]ݢP|̮aİbO3v 5t*T!ԟc!ey(<?zu5ok[ˈHy:Tεw&Wɂ͙e*Lp @q$0+l${~nV)}@ rwr 1/72zv>2YBcwi Nx=VarS&O8_rDU a 5E!@{|%JT=,Ƣ`nҶ"@[_o= x߇]kTQpT֧ cC)onĂ{L-/j6XnN p,{,eui2-şP:-*t3Pn a#>jUQ+:Љ.mh,Q: 1fVf~ZȎuQ)UiGUx^ jj+n%KFb5 O!yԬpcc!B-߹fW=e%jܩh5%mƼw)S%x2^˽~󹨒kEwLN}m0O.ѦThCk#pw[]UC;8Z]2ݚcؽ;ϧMk&dȌR)D&v+w_rzJ'.C&r+>SI\_ fMcyDa(oB(P-n_mmY2|qs4!+Kw)Y/0~;I#99\Lk}ݶ72#j_BʯRHͣr+ӗ={6ꃪĖA58x,53Vα.:T9 Yt'whaʹ _JZ2Jt-;~T+6sdjg㹶`ߔT( to`A #|H*_} ԫk(S>[rOksG;p׎=c/nJ3@KX,-tXr|ĭ$LYHXp8o^ډ6"@pTG8˘QϔlK2&ے<4$2HHJA3aA?%tr@;ĞQdO[ RҊi#Z˚F Ay hC @JMc`ޕĖip -m1A5p$8pnݚV$)GmZ;YU k:׶<,ABgbjeYW r'I(~ʵ-il>lhZȠgӎV 57ue&Q5G{&"X{\2eB0naԊyw Z*lP@ч#ghÍJ $avvP) Q?T:ĦW.ҫ FF@oI$uզ@sYJD}g/B n(V,-Q xUo'2_GݧzbpGhHm*?%4ni""Z7S~S&`yXzΠӬWF*~ > < pټ)jJAàdXؽLF>DH9̽1XTnzMū+ѺeXydque6-uwW]Kp˘tD,nW8.YkcTS)pHjQ-̡Ѿ+A!(LJiIs N-f RT-i`)_N- ;z2[rG1 |vmKuJe_# k*+aZ N/F͑Ŗ!}ȠHҊ$e/J]Ir/.(FK?{~oE`;c02%S""2|>2"rkX:䃹 VEe9Mi٩Z! p`N})V^vg HEAC2E *pjg뜊WaBф+9r퐩ZSӚJHj tgAxEO8uG#0]ս+ʣҾ*3_/W79Cq"@0xS  4dfd'-8)ZݣM5v '?#(Gc@Z ܶ{Z0m's3}g`_^4Fx=ၹy3aD$n~O>#_13ޘ '#XIV:U xH 7XHr-n1uj"2;iƋi!Q `t""$cբC3lWޱl,3-aAe[)WS7DN9ũuOK[Ȭ; c5xz)`fpҚ52}~q807Ĝ_d* ,@P@P=2.C!>(Bn*5jaU`)z,}Md57D%ӡP|mfU6S a:+"_Λqfg=CՕL+y+N^!m_N>l[MuƋ5`,[vdEcW|)KpfyEW z~zʠ#Z"Bvw?ڡ>dP;8/D} (B1V'Uy$*U|%x%?:sȐaG8ɗ]uAshjM] $ngпr@<,aAIP4?JjY:EZc\:[V_迀u2 )!~/}6}^x{\:fXϵ6JmbvpLc9{Nb& Ft4t7#Yitﱇ袎R}D@42'{MQ!gLhg["BAxrW,H맒q13Bz3f `W/ [q&T\3)\άW="ع)toΏ yh1l}|ī+(bdxuH8e>i>NW bcx:C lj| O(Gvz7(V45yWr>/3sGr+>v'}C{ VIX+1HѨ~඄ߵ+JE/B'ꊑH9iĿY*g{mg HC%na2| qp9H O@ͧ putىY{ֈӢM#Z8`SjJ#ijYSO7tTVUk;$?%c?B ^hMt%_)ౖOI cIٓv4Y"B.Oyt)$9WI_MEXugq mH9J$nEQͤl=fo] wIS?59""N+{9R! MX'h cb-~O8SLK =a׾}9F)+rŸpW3ǡr%<<& SnRӢ˰B7Xٮq 8@uV|^4N;,gcj|EO(NPcay +B#{/[>UBCxHSi*[mt|ӊ%= [,[1Y&c5M>H/oħia/RDO&VJ)N/7_?&oP<焋bӬ?1-^6TY,h.=. |"ss$M pnC0^^dpoXf· 1%l"n]]*FppţyJ\X5n@ɡfA2!yٷ ox)6ʖaUr͘, Atx03c EZĀe|@k@n$v-Q^3yJM8ŀҁ?X:V(sֶN?F8‹,w'g*Cwp-jv__\t.R c3y5C|EPA/Ȩgb>g1:U.ۄh&Dٴ3T1?Hä*1o6NFyBc]ޓ w M~8"dOo K_D7':PuN""q9e-}ц_qcu7iYKT9` ^I>giT3ÞQ`k|o:ԩQ0yL@f[Jvby5&hG oǏHɻ3Ps|ʘ> Ɗ῵6 ٹ"`܂c?UC޿S վN6q? `X*X/#u3vB sRGlY~L9}r{W4$7lO([+}LW_} ^ϕOkdtđ#׼%|X/;><+yնsK y`pFJ.RR J[;ݨ;EvJ3m'^>QrG5i3>,Ku#"]\HkPVly.RH&9:$9_?sAgP1㓬adOcS!Cl9݄l77(* SqlMWɳne-bmh٥HUt^9^y-AѠnz~c?U1qχw&!^r=Ÿ'G; 1䵭ʏdNqH2uwk%% 8.OE %eMxrwj*^#G}A*e&0[f5N*[&-%DSi6oEv1pw9|Nس>;z8:! 2!ebI1+9jW_|!/E)-=0 tPmQ+Z3ˏHm&"FFM$?Li$_J[k1 9x@4$> G<:H/K#[TEy?aX+)ux:H3)in+*~w7N#fyyԮgMb\\41Q9ݍ}BDx}yb[kC#q{ů>f@w2v= 9X/P_E8qW==K郋2e7-ddJgޢԾƙL:ML͘DlxB,"pe楐yT6v kzn0v'%pi 1[ɷQ&#C༅D4H)Cs82Ey֛% ȡOy_jtd:x:XPe['sLK0O4tu'%'TKmn DX |xl\FuP%2we`Wq$sq; 96DPﳜɺr(2_̚J+}O_y  n>#d1?r+=9V湇ͷL}qN4S}\W[;|{'ڷX kOL8JSLP*⡠T)Zؘb GQ򇳖'١~+HG]} ,|=1 s$,,zm> IAW;zcdlJ;VLګ1"ߘvX=!>s}}6F JD#jwUY/A p27\ԶQH nZTXwxg-is(>AԤNc| Tj>Ņ ̀aN 1deRvɿE賨x ?ΰ!l[%bd goq»m^R t9 (HqNrSrj'V8zM ] J-TЁiۯRַKkFx`uUMͮ>'&f2K8ݴaM LJ)4ÙL܎&!@Z5L,tTۭRKn,֭{:&>$LFM$c%:֐5"lx;$#Jt!նT:x!Y҂%ϰYObqJ̠gC^H7G4O6|-PG떟AI:"|*K((=a ?6 'F#lT`gXUMf]`~foâ pL=H2!k*BZ}n%{{@ym3;V:5"XnK{mCIc+I`W` *6;g,7Ώ}W&O ~o?VM'$&*Ȑ'5N}l{ Z.<XOMEC iK IYmM ErifA2uEϏMA5œ >fM!7{+S8E [hUŸaR9p cE0)~3fGngt1P+ͪz_ؕSh/Y UZe!S]ÇgbBa0qCbȉ0mɒGxXFdʸ?2 !Ҷ.!1c.G(iiǢ5Գh]3 ֶ6i#›`[ 2pǶ[tbDSe L»;@[-?"^e8` ga)EV^Vh%3N2[Ⱥ5@ Dx*5MTi P]%k(CB?笽{.GLݳ!U;um9wh;79o`frTg=yISc ; ~5=- 1֡nN|rÁފK_i9$AƘ<P#"k¡( \*~Om2g !Vf_2/HN$A3-)!%3e9/UƀLYPs.j ey@\ Ᶎ۶-BA{g.UPOD  D?/_h&#,!+6VB=?[so#r!EC9ٷ 7lsQWF_ϻdT,M%Qb9U`/f:pBtGD)$cܰO},0` ?('`_  Mio,Rz.JWfȥ"ҩSRS*}c\ڞ42R*ég~iqӐU=ʦ~[yAIU{ ޖzž-SPU,''b! PMܽ#0HqXڋ#:Bx[b$L6EM6_B%ɼA`L=*SbNа!}a(V֍HNsM~cv$?aXBjL i ܫA.ֿlDF௨G`r|z-ϫ'KH"b QG31|1tuh\J olaܻNP EC6zD6s3TWCނeVSFΞnڠ9aptJ7q:Gamidorv~{ ?#5b.w0g BF >GQxi(|DN:} i!bhʺKnq9!D%1_fJk+`hOSQLswځiNׂ^;$Ӽ֯7"/c4T\Ee'p o!GwT6Rli  2'6VxJ4 Ti*JTN[p@&%w6F1$}N x=?[!ut-I9qXLG6J̩62?s5Pق^‘7weyuT7^J>;|1T䊳R9BO5_[ƒd9:A4[o$~o(3m>ll l8ÙK; ifi5DĮ e',>f'y1N) 2) ߌP+1uKkCכ`<@AKh⹷{K(۔]d%>PK_[mw{H销ذɛ=WIR:1UGݿY5+}ʦ=HnKw×3=T().+.VMYi"~ܗcW\;\?pFm'û;g `d^fǣਾb4WqذF&kٰ{a-AZ:jl @mh^9%ݯw+|i?"7r.aC5 n-WM G xOp^^btZ}*[5âyz᦭ZFi H-A ''Si=pڪco2|U[o!V7GyS gv)C~9y!f}MֹL]@Kp%Ke?Ք^zJ1>Ɖ`wr=x$O\XƠRa3`Sz`}b ů& eS!kB~ eA;miZl3! ;2? ;9K/Wm"!#aŏb}CV]tG6VZO!H.tyK@Pr9r';Mj7TZav@ƻʀS0P_b]=vfg.uR(c*-E j4jiJьww{~ne|to{?PO GԄ(Q:_:?N3+fA籱GvȇwS`@ hItR#?DFA=vFIqǞP7ݜsV'#~ϙYaNjġxUGprb^YPKA{nDe9D`Z)ñP8VNnᗃV~d hoykW3wFB4:Q۷uMŴBsU/&?ߨ@&PC3_e\ {Ve0n`Z'_^Y>ȋ(#jZΠcc? ⠳R$Vv2y(k)aKNO|drL Uo\b$ƥo \_+Nj_P,>pNޙ*uO9 ?G:׾ƒAּ1W 'gS'7%@8`YЂ/4ɜy"INfn %{S1o:M$ m@b@"Ψg:Ccb 2i\S[sTApvPc憹ɂGԀ2mPiN}docD&kL̦c/LMM',CW%8h+ r-~+^ir=5Q kEXư_(OO00:GՒ32hNq­"ДArm̃vҘy\DpK>j4`s"Ab1}2ڄ<#U7X/Zo*ysHl'`2Rzo PH6{ڒe $4EĵC˵X -zR *\N$:R _ysC`"K48l(beD47mB~jg0 9 Igŷuif3֦Es lC%R km!06Ut$J`PјmR;L3 :  ,ON( "N?Ί%W<u݇rRVpo4<-z[Rnh")_ԑb{PH-GAF9 PLړH]6!@z2FsN*p>_X{Yw^]:kaw[?j5ғ(ɆSeMt:h^5Z 'GGs}هZRR\G[i=.r.nz]jM9ann{ S nWËDuH-*TXޢ+#\K~8] ЧC)ٵl%2&8,Nł󨀻z6-$,Y@s-1U#) A b )UKR&PA޵2$:K(ܑI4SxEͦ43-"XKKW2l8!&2ѐ )w!٧i~#rzvC{ĵF{ "JSOܢnM?4VN6|GߕLb) ڷzwl2 6m? 2"!FHT^kiu1%Dfn~0D5:G6' Yo%9\4$O xyŇhkN LYrouXrG15;슢d%Ybwj^ޮBd [ЫLR7}Jx=iL3|G R0"rLF]٩0-Pģ7+W*Z^ .鲉 xt)#g/ " 0j@2!A_mqhk.\3+Io8ל|ZNqx@l&OM~RU tV+}ڜ.=S6.b8 H/H9KF9MI"󴐃*fT>X) qEE=Lx~ VPaK5)&&bB_mo`7͂{ kRܝuư]ZJ[K!ۘ/ek8]+?b͠XHCN P!N稆^#OVvec3T[b68zz2-0̹>{,=zhT!Tiڢ9QTt9Pl,(8<RZq(^iҏ1.vYc6ϖ}-WMil:g h8]'6( 0Mhz0G#Z~ۑ3aΙ]e?0rZ$!۾ZF&+2M1x -YU:@U"|߲P6W;+: @Huf1|T6YMl :dfJD p*ӽz" ^JLTNAR a]Y%kU3?`;{-(OdY \W~<[Q (Y+֝nZt}۰&IN<DXZ&(D |(1P Wn Ta)X G-<*Ӛ봈:v!GdP٫zS.C(C!](;]%.}D#ʓzIWA?qP#OK ׵b5|FbT7 ',^G5j%.6lC 7V-znRP\tBƨ18T>{ l" A >z\,5pAPgqcH*L ǡ!jc2%_ u[4z Z2?ϠK?..q]Bf6 bO"զ_lWiæv?#kPVUxZB^&<㷜=|R}dy}e h6צfBgЈo,X~J4f I!-iZӌ𱌣m8Fvߥ܏͉q {7m]?DROY=8@EBM\dW!l]Ϛ.\Goq䃨 8FR4l,BzAKpkpokq%"[$>+toANaDŽ3Lt< xR"tb;/]+F f%^ ө, 4s].r?̷&c'@!FU0q_K65[[seWz\F\|Ɇ3`&Oau¸jU ``ڧK5+/+(8> zjlPEU_ RBqO/ (*ڗ[gg~T}̓N3.A=qO/jg@`Vrb4MEt$PZͥy.[tIYJSՄT7[wV,?0/#tp!)6$vaI+-Q9!9ղ)S>2`dX PBKz$^LQR a;EQjYܻPY9cXIp9.tv{ ED %m4͛|x8͐:6$q'f)0a9 Ɔ/|]kT;CͷCs0QׅAy2{5@IQaj҆o6:5ASK"D')wMGt5絫QtTέS9+#ar$cҐGu*D8{t@̘^"IMFeԳMfpw.,㝔*]]b%9,J%`d<\f \72.FP#~~qpjN:p{~ V&?C5}z̤ƭ(&~Y~/. sPGF62C6Q*NϽ׾禎ã6K g鸻J8\@3Ob>.J) CŲ,G d\ksV`r4Ɣ]=ʊu`$:# LQ ms~'V Xcm ?X6ssh>oY6WU b 27O$wI]3EQ yt8~3!yb}AcHmCUNkësV<!Et/gԞQ`}r n 4tb@owdUNpYclQB10BhVq6No"|[%%˰%;OaSz-lCT==X'7ea8rIU|0W| ?E̿k! Ƶ}Weܷ>"5WeAt'e۴X +z"A_Dxƙ1 Q孛K v q3r{/^9zNCC3iMi GUwZS擿HF"jrƓa.l|_PN?`%Wpvk$5a.qP-e4L5O̕ SYRr,!%O>lURTdr{]o'>0`5>fkdGn 5GBr]`T"XI:jx~mv K-P2\C BE}VHT'9V}:%QC~{&Dګbꯠj'zveTq\}s4U,L=ph.F݇NXY%Z@"d T6AỰ(v.;(OnL:׍NH݆|iK@cK +)DNKYq !GqqPm 9 Aнhg[:o #ķ` [*Jcei/!T|tg2ok]O q^UH*@chIEhW#iiW|rsLn`y]'z-]e m7?H6Gq\~Ќ7c\ݫ6d^wD&}쁶r~f~Q~W I3 d)t t".E$}0)Ue I^?SC+T1R[5>AᲫY7:1ȡС.Fo0 v/u!<eI[)5RW7l'sWw8䦎u>W! {D |/W;/6Nl@x5vZ԰أLj+B-l[Kl킘QDRxCG|ibXlTx(x4abv?O |0Eu5ޭ4]Wr0"1r~5c,:B=0NHp拰WB2`#fpوkևIL8T'񽠿6bo3 CGr}cCǾ6eǗ2f; M&zj@% ڦ|p+*[=[%*]!֪6T Gm:C$Wzu>+qhƖ(j'/[c?5:k(XBb!$t[aڸҁ*?AJ25}yVk0rӬ'7#@~ P}8e0_ǖF!\qL_Ƨ'BLή'upHL&߈?; *W}^Q!EhNYz(yBXb[HIoJNCnZBm akfy2.ˁ# th%/ᮂ>_hmǠ,iIr)nU-rY?l/6id#o}vS*%c.&iYob%sJTOi}T&BᖮWISѪyM^3sל6h cIig<޾9WrFeT̙D,]4&/bHGP*>x]g6\n=\mU 1g"6-xVխWحxmLBj2$;n!*]POA5::HYiAZ?/ %xj]HaSCVWH@\|rv B5Tw #1^Wp@oBu8<4[7@,GӍoMظj\锯1nH9@l_iNvX}i׈ы`T% u > u**!yzZge=#(ݩ߉O#oMY?iZpUtlNRqfH#GP$]{Xk7/lobZ؏7n:E#^=Xļ4ol m0m'hG/qD":HL7RR'XotG%G>d?9_qm$cŃ"ySؚRW5xx'>Qm2j=5O5_x'Ad; WyZʹaCAKؖ55\3l9Z9߅.qd^bD` )ːZ*{=L)1uk'EE6Pj?2N،FVMm ,e eʜ7>t$E1dwZ|[Ƕf)$q^~oC[-͞i (c܃ľy;ގ Ր}IyPiӹf𕉾[j"-^bVb]X0B~,zS@pmQPĖ=nzZ86ino+31]VL\u5z#wP4*.LFlOc'J}̓^zȂgZݙ*{gTxnU#"md5x ayoVum&?Ғgfm\y>~J.z{KK gq D)T9sa(W,WHXy1yKd.M:ٹ\oiv1:PPCG x)䩷@L)[&%xN#$ rj!z>;yinWazi,wWUJ_6@:9gggIӑyO+Us9Նщ#uʬä92HA`YZlcd⭫pUP@d ILD[AJE߯zT~$s 8ک k K!j:>VmvV9=u5|hsi1r%{9& ꣛{@~ J(S39>FH,* ? oQ :IKh ƴ# 6.5QJ%i$a>X&]z;˜,v[K Ƶgy-oÂgTbmƏkdROoߧMںX ;nNE2dQʣX?D7A 2sS$i-=SI4iknU*xF IDstyziF֚cZ$|n5ݘq,!RAcje*Ff7"."K4_շm.$]lB]9h}{O¢๵[#ydRW,[}' ZZS',- 6E S`l,Q I9t.U noC ~Uɼ/;GzxPfSa)#7ݿ KέۑI-Sg6c ->lV&o?+N&+o"Tq yqڪ{Α1!A\*”<8p: 0j+Yf!n"=Jx\BS j]4ǥY[RPrkG3cQn 6AQ:+Z,.Iz^( *Y7 ֺMYyGZ {k ԍm1%ؘ:Ld(Dm~roq>(5FRtJd,qj$[8snO>(Ca3sY:*gڸ$agj Np4I|O}m@\ y(1vԑ/=s"9hc]LOJD2g/}'߮Ɲ{GQ3T?Cuv#569#g'̈mڛ6foD7[3C#}jav但H5\IL>a+Z,<$~fd C SxY ]xĖ%{'FyI+RN=qQ (y~i>AS3ˆOj&]!Dw[Q8klwܹ'+f(U蛹#TOA4}n!լc/T(w"6*A#-g)e>s,KǑoW[x578H$Vҧ8C=8@ J|'^}Clp0@>tH"NtzG=ez "3(EI4 ,ۉŚNl~ 3VTm5ZjR'|pr{s3!sX t/"77p[B%O脂z{%dWoϞv'6irꪪwvK_BAA.0~Eڇ@yQ[12k(e 'hro%?]u.+ 绑mZz^dW,İm=yޕ4;̾`XhfYnt6S,hoAEܑ]U]K?sB.I0~$z~:oI=9C}")Xț0w'*1g(0pAcPNH+` ӟti~ep&) e27 :R?VI[s%эγrܶi׍Ņ\ KkV]mJx5b9ΘVGdRr /](殥zuIRCj 57DQ*a,5hُ UB/$ͥkd1W YL}Yͪ1e֦b*(*ոYspQ'?raN6Qڿ%|r$`"m9ե_8@f"G´H@?w%)s/< 3KM$)>oL4?P_hh/ ')_ F TkS=ߣSD, h1__{F }8q$oJDEK[Fp]ќ/~ PGojyVN9NF.,BiqU!hkWj1症W׻J1Ơ[ =t 32TҘL焮O滯UtI ++a@}td(Mb"Iw\ݙcvg"/g~cS)hW| ٤So&'  qU3\-l&rE,Q`nu+kHkJLјrnoy۩ZVAñza`7y>sm~xb$uxCI`8D>AfCNI)IRi+84K\K+>~?ܢȬ-|{ݜlh/ݔv%ӱ#͢eMcg:1Vuk{#>'&%@~t**,S&&4h"u p{MFÜEfЬkTÊn%k^#`3qEȟa jE,mti/Y\]T' 9AR}{<a$qq?l2X?`iWߩ0%?6 E%wD#Vn̲kNm؈&¦Pco0\J,kuB=Dm?,UY -]NH Tji}!o8@l2QwnҰbeߤP"_2ܠyg&>)FT /Klhʙt~ˬ >]Rd^N%}aɉ 3kՒJF:XPAO >'Ə~"ů}RZV ݘO&'' WH;ؼ|V_dگ-/,DRH}qr"D~5k( ahvoȱYB;!{nTZF\tQ/1J(z"sW6Erަux*T+"0>>1s}0Lb|!KzPڗ(*I!{S^YT+ ӃjK=iNAR9z }2zlz` )!<88oYb*0Pm^n7{_vA$܈R}) Zǒ''x˄ ɚE <(uKc+s.|tڋ Y8XxDPŬ;BM+B\#l+:d2Dta2 {_drZHj~OEt^>5J+" ={QvwQ1 '_5b86N݆')TY˜@~*YCf(h@I GaPI) Fz`*nvYRJik?lA3t*LmQӣ?c:!wkuOcw}Km5_k`Uŏ|;vxv,mGI4#QN~ MV7ʕ4V]Vַh+%uϻk*~Y^;\ ڀKte$PNaPu[%&\eq㾚 r4`e| 7ivŐyϑe+2rXJR1Ϋ,t) ϟ_&_{pyg<7xNE;$1 =98-zz8L]Joa"]iέoCVn`HV)ę=aOs ><<>cf:rкilod/%Cm{3Z.~y8PUϊNIwmL2Ǔ 5v5='_Ar. KiDdnyEU|o4|d`ID=>Ak1Gf;T=Wkj[>:9))V^RawCF_ j ړ\˺b|W?T m?O\Ey#.E[)17=\xꤻ(n\ U˱_KY,B/cu4?4Bz::B. `==+*ŚaB=BɸB:GsoeD#IY5;s\W>3Akb}Rc%mC[D.:n2m|3ꟜjAp NP`ZdpFj8YR@gYU2NYת]dX/{_n̻PS=!z~^XGoDv%ȍ56?x"a@]$aC3{U4%ixg2-FƎmu=+N \Ҏ4+LZA/]rNaɢ+}CT s 8{MBE\(dPu 6KC-b&ʣ)db.4䲒c $gƪg@Yk>ܕk2WFhu.QC9dG)gjrSh=r V4|lGϷ鴚&D8M_#Lql\l;k([Azğ 0ڽ i՝A{B$m{AqQUx#/\1=fn[1@)sP$78`;m u6Nhpߺ`rpՇu5`zoZjnx0lLoK/*^W KSQ?~' @nުlJVഌB\)Ӻrj3=7% -\LGpM&MBKJV{3e;9ۺ?)xu͐T AkSL%R񵱣.W~ȅ>lWREd#\T+ԤH^Es?h(qJQQiqh(hes2M2 ^IADP/3MEkPDgQ9=Ra?O?*y_$gz]_ [b\EM[ı S1QQ(i%~uO~S@VTH^ɫp] e7`5?W|XZWky rU,RH q+=auKTj57~]\v#6UE>DoZ59rdIpB=^zR@5;N)߉&$}9NyJPd֍6 /(9QCS+BDp屨9cMu> *_=۰r$M a1`JwJA`p_J:khzjִHTL dzKo?#kRfq/Hom*K#WΥKhS#J8dvڴ\S1NEM^Tl=6J}w/Op'~wU%^ 'go/%m\NHM"+9fUGZ^H_iDsN KA=ڲ-EIwcg{s1NY։cA7h7 ؈X IL!%eU_2ccbѺ8\NgE3@EOԬ"U&J& oQqȟ 5*BEeHmQ0pѽx_@P22BGN5`|a ]4|M!OKԚH`^߂v w9=5\4wFb%=egTqH#re74`Vp ޱ2VI$}IMϡ! xT} ,ُ|)M-^Vul²3 Hʲ|҉(llB+?3;O(J{CM`N@$کLF@;3̘ng ^WؗтdSy2ZFiF=70r*.j1$hf&B}q(T@܃RR4g0^97Y!3YӂzC_Ћ8tA3۠Zfb#zv2\֜{Kfج(Fz< ,C]T$>>:y|yH Ø&Snx?7}d%\d yUjB15Vs58 YOMsoY6if1~N,(֖-gLGP5S`wo$cptk1~wpQy::rTV_!b C.>'2sXԿ39ĽoFAWt2 ɲa|E Wg3\NWa?M 2q jϗo.+9P=!0qUvl."ALD৒jry3K~?xgN\ˈg!i˟YT]!L#;[c x 1ѯq *px׼ (Qܩv"8oT$oK~ZN~V~~J̯FLتiw=M8lRppX($U ? xP"NeuW";VКn8])s^xpALS%{t^'*HI8Z2!l^zcNpG?!IEp!`C,W@;ZodݶZv8 ιTY1TE΄8A%o8 fn7-g3Nl դqL#2"QK $TQ˹VTeŜ݊ m"+Qk4>y`tC{ ,è;V `Ax(7tt lwz6n*U=83𵈰;*ˎ3_.Rla+)F-'937pID ȴ#M 8u*WM<+mNjϥ[oLtVd:kkGŌc=;¹y3-d[.MU ITȶPƓiVA c|g ffG=z  ꯹X7<&^*(>`$}Dt3K?X۠#f5+nw"؄0*us>dϿ8ӕ+celoR_%??gh3baو"y19OMϴOSN'1ݜw3=U/O֬iC%6uceO^f^B裁JzٰC˘)lǖp*s0*To;]RpQ3g;il4 _tg!S/~zCˌMna%Z;Q dC8ӧ ) \rbŊV2ǀO K3C.S4XQ(y;b͑巨 hݥ6NUdljCA.ԛ. sxx{_]+k|ӹeƚK"^rѴgeA"SǕ@B5A 'h\ӧJA5@EX9-wl~F&}d*wHNC cRi)N]Z>R A&g'l_X_3sX߲$ޒ˭ۅ'`ᡖ~M(\^N]94]o|%hl+v.TDGAZ~WZcZ}SrrJ^\I$8h~!f 0߲GE*:QH 2i[cs5`Z9ҀRvwEttS)'Ng9>AC44^كeBK6}v9m Aklz&K}qo8u+kwkf9uSRn\`նN:Z(DJӊ h<Bynܦ܆M.jo;*ei7U˿y{Zݔ"Dy$6LΫ}{I*Nĉ Vm^@u~ *\iKL[e|hbPCXv0oP(_ 2 ⬲"7Þ3L,`+߭PQ9 ^$ZzJnh5jjy]@`.臒S1CPBuAndK= ֻ l8"6x`X=w5fϿThq/:R>*[J6_`}xMEB}tnpz PX& {_;esce1}B 1U..-[2ʩ^dg-#F,?~PA|)0e8>xnkpao)V`(T? c2O8&{Zsi m z[ܼ5( wXsC>ej:ޮ:oX䦺HuaWQ{wJ玱VE(te# ]&*L.dPpnzUgn$s%E+"fP+N#! ȟ"?/&]6+UJ+Zb|&Nf8 w%lXb&rHz(jBX˪[z?0&T|9o6sx^)o >V"*{Yظ̝(@hAzo:K;\c>\,dNe=X!g>aN!*hH~DxEп`%V}tiNAEPjZݘG'/ :9UPwYiδ֬ӱp0rvGv8B4e&$dhY-^NjT ?MTS +ݸ? >I>1uCvOtykL|kz O2+]-W;(AwBe'@0 pAcU/^6:w=۝Lv*ugd1*9V 5U$gb%n%+}c]Ͳ+8Qy%!Q2@Y`+Ą5W^qZ0gL'~\B˰/}^#tkꦚ9؉]hTvu~bJgmö:&e9u~h"ATEg2HD$?LYLlWdBDZ"P[,ns'[#s6?s%nx\G2֒!'_QMl1,K1t8NnύQGz*(]*2ÄSVSwl֡:y׃)w!|7_PưLSRn ^G_@{$itrĮ*Jh.$MDfå2߉߈+-Q}{n|:R8\CV^pe ?H0`*l )`8{ S',*|]Q6 ֦yd,\ڬxS0?SwKj#i f P|`b1Ɨ˟W-pl[uMȅv.`j N/x&G޶;%~Y,Csr3" Dsy38kuk$0`Ӥd;;քX1C>o4WsR Z( *)O9gJ~]klb?ے5Iq7:nU>bۯbXX>v&!h xs!4Gk:R5o=) O4IbZu?Ea2R['񻃘{j>>}?\[bX2F>`hZ`=.8 шbWp\[CWAO/JSFv5l4\TjD` fš@ (kqFnNfj{Vi\\@l1$ Pem͚#V9ȫ4a)Cg㔚AJ) QBI_ AI ƨ?vgcF5+!6R0a(LW&JE=6Zm 2] ACbk7m~ߎ&tMȎI;_ӛ:żd{V+$q3ri=io(.V0?Qc4)G qzZL/έF.\=v@,LV2]:KuƵ)>.odZvg AP -%úTBz6$?x]h#? ?nMi]%k . dReE`=8ՐS{܆}5J/H52Ф_᫰ybX|VEYLSɔcHp1O0)XϢU#7nPPvPz{Z\(ĭ=Gh,V/b+ヱIyo^@]7"$6Q|T,4i!JNo6'7b*An ~ .:Lwf[hCQN[ *) q3ϟR)_/'.ZGv#PLJ@q(W_?2W.ɶԞ`uQ0-7ONAv! a!ųm!k@FmvK;uTZ OMko6-IЀB-e?)5P{z;+clWF%qq?.ApKCjLbcR^£f|oT-Թ(,Nnš%tJ)UD=ZN"3ap?6ˬ3s=*xt>̐=ⴡEIlܴT?zczN;>'O̹"-z8)/24 0Yҧ= *YV铦n㲟+˖0-.SGKOAͅgLWɐRWܮR$fr!C{`udšWbՠ]t-p?3t<6b ]òȹ=u Cա$s!S#wHbֈaRlD'|Z$Cv|HJ`dJjӿp&?Ϋ4k{ x+H04adGi.鲳㄂x@B)*MKUUˈoۺ6n1{+tU}CY7*rh1O8.<wt=l;'B%)G`gԘ甉 z"c/Fp>YS,ŢL+^-Ϯ'J\)Z'HCKh4NJ*<꣇ZWs~$$8Z"\HP!:q|i~*-MFT]ˆo\1v#ҽw{ 0[ XEԻ(ʳF8 ze{A`%vߡ1n3%gyp< s_lۛd j@KvpԽ2Ϻ%m>πݩOqI>െq 3sO{>4!pX^lz-2vdhlD%Jk-ax͇04;쎵\|OJ(saiJv"N-!h&޸-AAxWֱ!8ɇ)Ma,i0~s K3T 6?'lwDk(rxW+̴Bj&2r=?5nNj)}S1DNtńw,fV*mMPT&goxF]$x)Ö搘pY(2n#S:* TpBS 2rfIxQDv 6H1n mڱN>[jQ2W" n 2~zy/ cXx!75BA{߱Z d;[CC ʻ7L7iQ)D9Rp!8)-0LTn[ZԞ.8d@¯5qd@\ډ~/^fS/A&pa 4"΃.C)tJhɦ˪D eVWqWL'願Z$?c6Y]/ubzp:|[ne<𣥡4({gD;{&$% OnO>n{`%SnyfXH!$js^X޸VSFSˬ7xiX?䞓 >}04ȭ;/Yw9%̻{ˏhP<͊3ԻH;y/aTh3}2Nۻ ' !Sb y=ecsiȁߋO^t^{{ @}wEÞ#)B#{Eg7 kOptph8P QJzesl8иwQH$1;X. -ِbO xrvAz*&O5MBꤿ>7u1ﷹzL ;aSɼq(wg+K .inV6ĝXh4 NwX|c1t=J6P5 7x]2wpwcՋ $}z|XZ 'zQs0cEX މ!|+3X) UC"?-ox@"}u->)R eq(зY,R-i㬡_`3s%~IZҊlg:Z?pfh`Vvcrsr9BOtmz#H[?wJEy~%-"c:tu2) &. H?u X-i9UgQ"p%X̐#YH`Vh6i.քjYֈVNÁ( !8*Vc~ Ȅ_oV特 ZIU_S 3^?MP>^@v_;Yu|/#!% 7CV5`2ucF HX>@D|Jqjz t`v".G.@ki],0r\(l&nh.Oh5܋)G.+L{sj}=LJvHN-.O-d$S J?#~NujC)D 5khD=8{;Əi OQk"FV$ h_ M @vׇQ@j#=+,o ͢t*gk ?l_,CXD3ϺR,>ZZ삳lPא.p2{_E +^^h\vߴZoa;b0G?NڏcWœC)`ﴲ0?R?|"I3R8߹y6͆ m>XLddQ7 b<rC}Z/1`Ihjʐ:\> })ي:0ŗڡdC e 'aKik\ V|X+{_G$)7>! ,lEg!>b$v%bcZ$b ыYK?M*6kГøSlo[Xxtx64l8&YN%gcb֛XYj.GH a &U2D;f?%4L3;З\OM5]|(<6g-y15HAj1x*;A=ڲfP-\ ﹦/ד6$uOo̖[B<y̾)sN`%Ak#Py>PF WY<&;[.G>(}h4=x(/DkdBj9j5m5ƪ%Sq,gLx{2)X"K; 4ؙ?4?b-&`-MwPGeĂMYsysn~ZCX./HsSKI̥~xMj6@Ӧ=aHdXBCw%Ku< QƛA;fozAx/#DA4$c}csl2++vP*)"g_+(/j&mmۮىp{ׄ<8d6~ M~a[w!$ "BF?CƶHq/<z|֫YՙYhK?2D23pD?︉k;u 6[b搨" FZ\\Ify7"P 6NF&f:?)$<^-ӀT E Ԟ y'18}s&ODG`d\YppaJy]tK nހ2 I|R)ZXD$Bp |<I@j.opl[^ajCyOaAq_41~GɑZ^RH ~L'_Uۭ˥#̓тx~E Btх%9h+bwD~$o2Pc8)o1ˏH|PBbͥ#2E\pِލԍor ?_W,zzsK,>aOPY``8Y .Dd> 5@ʟx%M}$iWs!+BfUBC~!}I5\_m_3x@f1#[JCLM8L&);H˃ٜEs zY4LI0KSյnOqfcZbb,hyK jJ])Cv6ϋ۶=hQ:6vtE.ԥdjcCws]d!#2OFqLCKl3}yTEw#YׇLE9ڊp/@wJ?_a|_CbǞ5h~ymxWKo-F -:y 7OD˺C 5iʹ̏T|;g?7n@@r:FoXe6=){y4ZjfݥM>챒)Ba0'^l9Jj94wЀ.ҢA%iF!pLT.MرEUWafż34MÄNhLT9&pYդ~Y^d ҫ|d6zr0~I3q)h:}V F͕sR" u ?OaE[q?)t V&f Mm̭;N[*XDIy<&f4!բ N[E#)9s*3iWPoQV(U+#'c;@xYlcDRC-ЮH;y/_D׻ZdBQ\v,% 隗Ux@|xŵ^3+[7!GKԩ5B܎3͇u_x ljwDTncW.#l=*AW-o J=Q*\\O6D@3YJ䴛Ki*=pi(v՜XYR 7]_A#?',8 d<'dB nd™[ZĆ VQڦ3e ~ΣnEsҞ:#,j׎%~Inاʝw&@fs'(#MFҤf%aa@eCepq!&bCZn%1쒌_Y\2hJzrD9ЂGk'WU ڠa}N y."WPsuioT[IgbwIQWɦyzzIfP8aA8sq@[$tnE3m $`ؘr{א0a ]$TzJWL+Hy1j៷g+Ҝ!־#v;B1|3Ŀ96P=}K\ UWTt3 n>.)K@=ERIҤٰF>6͕ aOܪMic\4<wӥ]2;f:0`u~fNtF>LQ/v`IWp@?x^]aAqjLa^"xPA{aM7C..y26:LMoӋPDzsEl_=y$2sfc_v6Д8λ4ASo1\D?B;&a!Xie2*(js.X8N~vWYNMAփU47;TƻL,3XZl?zqVd4y2U4/JC9^{xsƻ%:ܭX1  X*5?2u^;6OiEO\:ořSȀ T&O|=֠I# x_u;/ Fy?^!5Wt _q G N 3 r0T63nbqlKbU3WŃ |Z#bvk^n&u~QP+ RT=(9^WӶQ B/bcH0~|͐ ̞y pjrw{hXPL%f8b ucE!Da`koS-uEk`1C{ٳX&C<∾! --L v$Й 8"CxBJ` UpW􎀏kc2M@ҏYiçv q4藮0jN`@#[{?@ıdB۸9jeo33+/[d`Gxu-Ѱ eނW3>j<Z5{푘g]ykj͈{ӈE;gKl*N|3v )C t`pƃ3(m`k 4rB꽨 4jw\Fi|XWwTqZ>?j|b񷹖FBl㿖0`لǚ!wi%,t` nzHSƥASg `z^ Ŋh@j"l{4)v:XCmG2WٟKhibekThbWm`6 eyJΔ1ißemS!٪9;W=fflv?ǵUP^;?PWTcxP>S] B6kǿ#lm!&zv@8tb1FM([z׼i@dg:Sl6U)PtȮ^wk 9 E=@#ƐtHf<~dAOxQϡE ,>b&+{M%P/e_F֠he!Y6 fCPmcRIA}.8 Fk_%ti:֕KxZA6杤{$C06E\iOpCv94xb-kRo\W/k=Ue뺐Ptkc >x&Qg|aG=T~_IËq} S6Q:,C-Ä[!yߎ'V1L1bMOzy%;s܆U`Z#v7w\[?@Êrx8 imCU怂&$SDb0]6y$,w"^7]20CG#1r7ax6BG`&A~ėNJsm*`&l_ψ2;PjnvdY,6ޙIdH]:0Uͦ+H4t%Y?| J.;n X3\jA3gO/`t$^cs/~nVGƕ8 ھN6ҙmR:i46oOPqnI^p(n"*-+55ʔ0Q)MgrB%9@'Ej$$mw3$~=K=TEd AN߃+*)ew] t7uj|qv)ިSAIxnKH'ZL(7%ɞxVTYqW]v)lM>(GBN8v{JKwxTzUYFk0]6_5E̎aߡړ벥=-QW`:w=fEwe,8U?=D›,'Vn$~!N]o@+O B/(sz{lc `TkpUga-JU= FZ?xj`9%*,s"4P{LgԱje:ƏJb:%(jO8n7}Mܵߖ$ՊO]hN_s 8_їo汋3SRq/vool2ix8{}"G(x KuUk%"u|ڧՄx2L Vƾ: qgLss.]Klu=i݊`/\n˦b [&<8Aʩ\Y!iWʸ)HR ^: - X%JrYle99&@6/Ԃ6U>0VW+*E!80? ͉HZ:ݢ # p1\ʺYBX40MY5h~=-5} <-]1.RO[G?'39|Wi.(Qga d1KMj:4wwPg>%Έ!X+"'muI۬i8[= ot)We#ݣ=QOnM_h!<~ú 蝹<10ިD %^/rҠE[S}KOT*\h05es68*Yvyٺá H7Z,zErX@m(Jc~/h/IB. RLX}34#OРۦε].>qO^ZgEn$+Dޏ`2O`ҰPۼXI W֦r̓kê`˰04mJqͦ t.,ĐO50b'+<8(ێ"m,m Bx$!mLR6du˨w{zd.a_^gMvL![8xXDQVd\FL6jc4Jq/lޢM"Z6ɪPTQzA/`_Š@\+ 7*PMuS BWvC6p1GFeLpl0Xc)_VFx(]y!7>3N%hbܕ: (nX`@+^ٹw aZw1" xc?2 HtJ)1R0 .-iy]4S(Aϒ; eҠ[˫ԀӏSٳym)­Qў0%-xeqqc=C{l9V68?6O?ɧWu"[V7ɩe ^' ʈt>nL<2 -Jz,R r9χխƚ 0M<9l}YKPgˢo<<^7F5Ϲhߌ3s/2m=lFeb[DB֕FS~dF>{Xcq%~,,7,<"IAdn?Iar%*]ڎ>ND,`BfũjD^pHNԘdY(DuB.F7V;Rv=pG EZñ-<|/ӱAkn**ޡL5Ntnı_k${'BCԹ27We3>@DFǾ+/Cҷ[*k(<7Hޝ2X@Xa8T@z)c[' >ۂ-. ̏edA%޺E֡~{ 2SGYdR 8" c ]fԺ/z< qԟͯYrbʼnHf>G+s7 V~PS?WhDzۙsa ~Z[%S%@gz5'̇?8,.C@4 ?'3o`h3iAV<1]Kc7!= U$$$IYm޲BM_m楚s79W Cl 'jl S>Ga%<%!ֶoՆX(f !^{nTyɛ*%YBs4h͉"|rFП7JP^95$%Kv!UqqHdW5иy ͌[sE_L/qY4[y) uD[I;\p,]ppu>Їں*<9`Ci9!k|D}]ybcf $Vn@[&ֆΌ۷"5¦S[0XLCz ]äU‰r;1gXr0:ւ*#(t f%l28vEcq19S[XoFcq 9?UjY2zK0sT3E:>aD.]J~>]e{fa\hƤh'6uəh1ۢ(\z9@BdB;l'v[x?ߟ߁- LKXa"3ERcokRO/Pl:[oBg RH1x~7KƢ0Np "1)楝o.% AcCG4E>fnwQ×/o`b''VFwϦ(Kb(ey\h3Uws'Kci8ػVLL(ZKwDHJDnVye ]nIL*1uCtq,#vh\@Ɨ *X Si:R\q/=g;ߙ62﴾ũs0oz6>0mRahi4nbk)4aZ^pzdL۲^ h3j̘٫,Ij6ihRw#.T5Q>1'h̦ēiL] +aGOO6O5$W3qwgN;!02܋U1 1ivV5]i-Jh6-\42y_uSB)RMh4GI <# V-́0y+%3Msx5lIүW;FW)ejoEGh(jG7 >3\`Zlݿx$)Ȝ"~Ѥq4ɜ u6l+Hm^AcQ鎙R$c"^(G5sBa {Zdr#scLN;y6'N4{5*&USc(3XOY ݵ m<;YGCo{Ɯ <$#mdiXѿSiqrX.h Ul<8*\[7ϖu^T Q6KV0UR *Np]qV[ Y+qS5!nTFyB,{ń&8{(4RPNV=wY[m{A)yW%gE x hq e]2" ;ߨV dZ*@:N3}V&S7~P:qeU(dOc|h?`&z[,Ue%XJȏ`Kl,814s1IgǰCh]YuT;scZ5[Ȼ`TRɸ'f)03H5ؘM~Q̨U>zGm&ۍ,j%]{6ӯ$u*F"iTڴJ.a\xLvP z1v\U=: "w0j)&[-ZU 5BV ^^Or Z=6e 1QP'ڟP/e\G.4#1Tm%>4bUbCZO wkVÏ]6&|TU$T原t('YBx+V9s{Z*D\f$7y^֩5>agf)W cl%_w{!0tܙ*m|q!,VPL/ȋ^ٰQA5^4qpE1k8*+} |ypqK#4;?44zX\>Nm1ЇZ=* CTM#|3Й[liC]lמz(fv-Sb%.X5Q<,Ycs\'\hn$n9 1P? F-~~^;|٭ }I'iȒȱ HEyK>{嚳[cwTCU=moF Q(RgL5ɜaB)dׄGtoj/Pɛ>t9+X,)op#ɀEv- xOeg`:l 97wM&`-ؖ7&"T {Ru[^2|7($suK5@DWXg>qXΥPB~b %G>+޺K9t> h}f306霆(Ʈst"+E̕Q=1OVZ !̂z!rn80x+L;@7 y^<\>2yZD&ba~-xf\\|<EISAUt)ᣕ6)CQ֠ EQ^SI"?{\3Ff3qP#:m5bF}>2Dp$䉲pUV 瞜@>@87] At2'׊6RY}2 UξOn^,I(@ԋC*h oƭ)0̅h ;*ĥQє$ȑLrZ?tE}ܠ4knf'zT&2ZC/j `Ev“Ncp%k[1=sB\1rjKB5-@9ãA W#.*l;!2sv#%GsϿ FKt@Zuä Xdd/9eUZB"52X>* ]1c֑ݼ;U)^JNԩ>\ِ,ˢr=]rNHH(dJR8j|MrE2k0">lRw$dQWJTa^Pzc&6> =l+hhwK@hnVB"c\4WR!ЙCfBEfg?H|"]+ĀݍtB$*n*oUq6׍8һʴAThJCR՝U'\b\b3# PnI9nza8Ns->Ng14ױrI`R!} p̧C1&QVC5brCr}[H|޵ufA[Չ#ら tjIeg c2r!0d 0ϹZ,Ŵ|%IEPWAF?]e ޑZm~ ?$[u|}-uI0{.Gİ_-'̀UZMydD>JM͞j,A ()B:R#9)PY2FOD1-eohvN-CD+bR⼜nCG_&jsUGr%ӎR̹30 ,?U%9]C풅]R.#t5-5E&sdVF`mA[X A̻?QAQQ?}̸'вs^S0=7j..R-jU +3BOj0Ckm01~< C^nۺwо_2Fյ.[+ ?\'=A-A7QOHtc)'zz\C`x ,FHA7L(0{+9W^ı?Xu0J|WXlƁfgn堔( { P9 usБPz9*e|c,y P šf& f?Ie*kPGugQ9t lMį1C"osy)q>+[w+P/(?9^eq g\ޮpt\*Uc$ʘ6qPd ֮xn>D٦e/ƔoNC5` Bش !3 52W$W&PW6h`z(iGCJ0-xjԶ60V^[W` GO)3'8c3֏ k`(d:?!G`A4?q!Xwl8z.<׋UbʎM|WWe˂_w>I 5#r#Vܞ0m<Hhq3H0liWGj$qTtNH[Hw|<8 8\jMmEQ̎vYhPn5/B}=)ۋIxG",v= *e,ּIkߺPy{:Nf"E!:m ژ ec\p{]1Wh֋8^Thiv8wKwn%75[EKkz>&v*?5JQ9z'1+EqY-O,}H\2W:O|GWFj@V~ni`qR$cAwç(PA2o 怷~J`{sQ i.F>z2i(rfg!9XOQ Ȣ*D^[o'[)4z1*(#DR oI$fߍ"}4^IJ+|I˻( r4Z}}&'QMAA aPYNpH?llUֶ塹ьzM0/(c4?_ f7l T2 9eV9iU^ -qF]c:,;o?]Kv kԺ4?;9Ǧizz6iXi`GvC$.`ukēvOν.ԭ畭j%mYqU s"dVRx EX",8ڹM\*z 5UY$R~V5>Y,>& b)plo- J/a{=`ᾮ(Ǯh(FsJg:)Ed{d (w6yՒx9&?rxִ "DfO[O5;4drMZUI&bFyu'+$(wI6c|%A.O㇇TM|gr˷ &j@4x0F,͔Fp-eTdR)Ί0ݡUlo6[+26HnѲ,rjcްaVWQ"nUFmT;i:8&EmccV󇄅?:sc`B fg~6׳oG4Fd/:|)e| j|?!=u̮!H"A<렳q1> iG T|mkiOƻ~X}m~{F\?LAU< 3p{]ʆfGb5d߆)dGWZ@Q<,@S5 1)6Ǿ3FK$up6($J[KAhUX; |`o~|أ$4!hM%?zy}N#_cao3*觱|L;hSX2f}S͹@ѣWkːŋ7S6oR4f"+7ъ"I\t.XDĥ8 y>8"׊?eZԿo *\?lHzĔ_)3pB_dv#y;нuȘ'eUq'ړ=p0{[.LILLΧ|N\)j%CA/h? YWh tq{twu-m#8wܷ0m &&>|F>vn:W#JƐ0VLnUZf*qm=G_a= NE9ǽQ$k J@5e5ZNWu4qz13# .II hѪ7-@ PEG8[J>&=$ ׶ m|T#L*~Y+;2된ZPeqh \%JCrLOA\vz{^䞨 ->Y`RYbV[s6o'I.6܍:~3pP  ?z Co\nDI0sJ1A^1n:B2IuD̺Բxy&lfo٭/ MW#R h8v G)qN/33S\-1!zz9X9F7GaVGu%"3ݰV{C|8AGrmjU%;lmne|', _Mr2zn8ocm4:9˒diOkOJ&L. O 7W Z#<ٌ89Q؝+n!`a%O%9~,)l+mX"O |银]Ar[4T_{O!T>¬c5 XhdjJdF_㡐w}$./߸ZQl+a4׀Ԥ<: YZ