pki-ca-10.5.18-27.el7_9>  HLk|d} $ƨ(#{$M9mR/NQ: #(,:;N'{Z:Nݐu}8UDzQ '[417IjaWoI?9i )u5;<7{g"^GEB\"!(WAK8M=Աlf7_fֿ7Y{|vv>W?\(K25mi1&_ Ҽm~:xBăMwh8% . HQ5z XUGh8:-jswMpc:i7e+P0Z3A، u:_;<׋ F I(Ӗ^Yj_WB5+o@:?UrnEX{ƾ_`[(k?Pѡ|ALGOd7sw)f)5rsSt 갿mH373f5eebb0cf2529e037bc226e5bad5e46934e1ed| $ƨh2:dsfz}xy -|q裧Ǹ%C0<׵(6{ƆFhEߤ3מ~c-930,lE:Ly }U)g`>{ٔeV@F@w5 Dn၏ff(L}(\U%+L4QӁ6V^01$+rU2+~rg&~ѫQkUXs*m^e蛧Vg鐨kxGxW䚈Q!.uB)@\-yrncף@O4o*m[ӅЁ:뷱u@$٦"~/k@e0I G%CRT9XȈu@.r_+uV-*QDh~{meO-,İ*2$^V+[9V"ZɸisDtf3$ty`ElS 'hce%q(5+itf9&>7?d   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9: GiH4iIiXDYH\\i]i^b1defltiuiv4 wxixiCpki-ca10.5.1827.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.d%x86-02.bsys.centos.org%'CCentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEGl]P'n,1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤d%^2d%zd%vd%vd%)d%vd%v^2^2^2^2d%'^2^2d%'d%'^2^2^2^2^2^2^2^2^2^2d%'^2d%'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%v^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%vd%v^2^2^2^2^2^2d%'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%'d%'d%'^2^2^2d%'^2^2^2^2^2^2^2^2^2^2^2d%'d%'d%'^2^2^2d%'^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%'^2^2^2d%v^2d%vd%vd%v^2^2d%v^2^2^2d%vd%vd%vd%vd%vd%vd%vd%vd%v^2^2d%w^2d%v^2^2^2^2^2^2^2d%w^2^2d%v^2^2^2^2^2^2^2d%v^2^2^2^2^2^2d%'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%'^2^2^2^2^2d%v^2^2^2^2^2^2^2d%v^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d%v^2^2^2^2d%v^2^2^2^2^2^2^2d%'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00eb1fb39880b0892b22d2e1701953f5278759e28dcd72e50309e442548b27f0faa8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefe0cdc0a0a32d688202334a77982bb2d63244aa5b8570dab545db1c29342b3895a2024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb643811c199c1d988747ba4d5689f9167fd42a8ed07039e28dbccc4b744f4cccd469e8f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a10a6cf49b1f62522a0f22ea1b12339ed6fb418b2e1fe1a30902aaa70226c4d7821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-27.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-27.el7_93.0.4-14.6.0-14.0-15.2-14.11.3dOdc1cY!@cD @cob@bf@a*@as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-27Dogtag Team 10.5.18-26Dogtag Team 10.5.18-25Dogtag Team 10.5.18-24Dogtag Team 10.5.18-23Dogtag Team 10.5.18-22Dogtag Team 10.5.18-21Dogtag Team 10.5.18-20Dogtag Team 10.5.18-19Dogtag Team 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 23): - ########################################################################## - ########################################################################## - # RHCS 9.7 (Batch Update 23): - ########################################################################## - Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter a list of tokens [RHCS 9.7] (ckelley) - Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu) - Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)- ########################################################################## - # RHEL 7.9 (Batch Update 22): - ########################################################################## - ########################################################################## - # RHCS 9.7 (Batch Update 22): - ########################################################################## - Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter a list of tokens [RHCS 9.7] (ckelley) - Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu) - Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)- ########################################################################## - # RHEL 7.9 (Batch Update 21): - ########################################################################## - Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status [RHCS 9.7 bu 21] (cfu, ckelley) - ########################################################################## - # RHCS 9.7 (Batch Update 21): - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 19): - ########################################################################## - Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen) - ########################################################################## - # RHCS 9.7 (Batch Update 19): - ########################################################################## - Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [certificate_system_9.7.z] (ckelley, mharmsen)- ########################################################################## - # RHEL 7.9 (Batch Update 18): - ########################################################################## - Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen) - Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley) - ########################################################################## - # RHCS 9.7 (Batch Update 18): - ########################################################################## - Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [certificate_system_9.7.z] (ckelley, mharmsen) - Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)- ########################################################################## - # RHEL 7.9 (Batch Update 17): - ########################################################################## - Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen) - Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley) - ########################################################################## - # RHCS 9.7 (Batch Update 17): - ########################################################################## - Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [certificate_system_9.7.z] (ckelley, mharmsen) - Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)- ########################################################################## - # RHEL 7.9 (Batch Update 15): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - Bugzilla Bug #2082717 - SCEP manual approval failure (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 14): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 11): - ########################################################################## - Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu) - Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail in FIPS Mode (cfu) - Bugzilla Bug 2018608 - Invalid certificates with creation of subCA (pkispawn single step) [rhel-7.9.0.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-27.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(3,q JAԍgu2Fs[puև<@c ?C;D>w&6W l%-~9Vu~_zW29o9рJmX6WE<]gn~W_c2:7OF ǞR[!V3jOQ6kkZRS%?Xh(%&/ވy-GV u,ǞsiRY.E.DTWїJ 3E*zTmOszH\d /=-,aѿEzkܞӵz(3 yD{Qyo::^}Y4A[R6a01dLԫr]i)ub=V>7XGVm?x3g-PpQ_0Hԓ kexs/I/oϙ4D'&N #kx<z=>#deyQED]epr '݊0PU鐻iiǷnaͥ:& )?Vksaˆ+)Ɵ LyYKrv.yH 8S⃁%9W3R.`2#Oث9)!915T3Uȃݓ_yzTH5q_ȩ]Vk|I#ϠQ UO0!W\fyɱܬqOni0JZla)/U/9r<폍 䞲2ȂL$cO* BH6W㮆yIى&Pȵ!R. %ƴ#Bs]҄"1&TS\\TI4] kh-ǽ ?KlQ`41.I[Ktv4l=,Cj&>IBEH.DV[jp;{ے>*-7e܃n {@_qDM9p1:[v(IYC> \$(rRm~fN_|} xœ}¯ڢKEd?ӏIΉ(Fݐ:6$VLesU" SS$Ko>ڛ(t겲YfyH"?>@:ܵQ͈DkB+hTFQFSzZ]:NjQyWRȈc;*1J lm)8gG^]Co7ůDYdXo S-FaJd3f?T=b ,#hrR2HQ_sbE{T`߂?]Bvbrڹ29,XAC|ki4rѹ8wnHmI( ŒNat0S!t"=O7pA%k a!a W"[ɿqrwWgْKuTB-f3Hu1,ЋW3r:T Ic݉\^Xd=0Ďi[]kB2{w*1lhֹof-ǽd* +z.G“QqHxˤY𞿙Ҟ&&k7幉;ڙ/N12N4LlM5![XV$+9L迦aKFD%n1ѕKsr(!{nW@}0C#}Ou {-m=A|7٭hPP^nIǨF]}DZI2YFyX&I2fDv q.n{5a6m&qħ 0VU F+M5pe({SQi.ˉFqÍgO1%~G]Jܲ]5pM{p691X47lk>O E3]Ͻ2zTQ4U%v) 97DP`D2du s5FXqz@`="5*!Ʊ6wHR=:ۜmb g}QTQ S(Dgt.u'QliD/s+ @׵I8s9HXHAx4 I1uwn2eu跚"f[|#/- qz 5gaf O?e 0,0b8"ـ]ݡFb⢄YPxaQeYk0zm;I$3FoEB2RՑ}?%?KFY'-"5‚ ۃ'a@M,٦C3/ATS<1K:;!m~VJU$ʞxz߂YTZĥ86j? [ F] ]lEUn.S6n8haޥBvAN&=c3xOn&1i|I#1TmMa f1det SWKBbᢇ ]7źCw]>+k)WHxcH=dXU@mу=BmiS<5XN!gE37he6SNliZ玫b^Z'CjLWH)QWYg= {dw;}?"^Ox͑ӅP%QV伏 "T%,appBEu~*:(#ҕAuEzqQn--9:a~1,>pKY+=peu?{hD} Ϥ4MOoPd :LUu٢-b 1X,ɈZ,W 7g'eZ@({n=\5Pܪ1Rvc齋X"\q6w1Kz ;3]Th*8OE[h@kTy?fO#?cТBa&MGoypRy{Mv +èl=Ymb]Tr7{/gTڭ^^5 Ҝw`jc= ~ÝH1EI"u&#辞ZaeBlõ1ڧT41. FHtN$=[2T3//J>Հd er (sMGaI>%SXH,&Gx*8/Sߊ~}_bcm6_?=̀K/*N±;9Da5'^X,t2EgA )o!h Ӑ^K`- ^7 4FPmy=ӭ]U4OmAke=01|zӠβgp;7zS!ZV\^< \S#S2"};uPy]I X1QZBݕR b|pG|bf*IYpjaಞMiCR6e\OWM,dW!̥ZА:F|^gp f@ugIμ({Ča><5<ޞCCfoNx|bZ"Ź#A1Ŀ+ß{H;GŠkM&vZgOYXj5G/}_KO;n)z(uiP>R;v҆gbdz5xEs i-yDzrTD*{\|o"pD:&ܵ@Ɏd: %:| gr 1$-أjazGdޮי{V8쫮@ @sU ^;ywi7>p0(&] Q t:_|aclír=9~X[  KfJ*=Dž+҉ Igp%I$5OVZ" ?~?(!Ĝ/\qVF\ҋb&4{0H'^`Nj|j^*LXݺ-WfC;%"#\ҒոTb*zߊos8Ц0"L0S޼BK+TfU^MPFܬNt+r=K0q4Ot10Z8=Y\E{W?+} ]f8AAfמ-:Dȡ8h1?f#.$}B4?ȉPxObn42s@進b+#/1cWxMS$$# ͭ]\| %1t2C%y9r+'1? cϕT$!+W㿮4*]8([L/g!G'eeAݫ먚! x^,FrQy&½F~d]\} ܟRRꎁ_Qk`&Ni%D9X2(xb1U)̻^`3&P 1(j75Rϵ#.*@ѯ#`?F-P4Uׄu$ t##iftUabj kX4n֬ن)_ /×zLU$8ϧ Pa)ǿ*V[^$ !I~5~6Y[ޟxX/uU>A/NPb+ w0GfK2(R_#;/~-4]Gs݉Mt.)'l䕝*tONw:;q<' țKjP(E vAӖ̘U9dyb>3n7wDɮiI Jc6p0j3".Έw7T=LC pPޤ;hC%m |i<#_7Oyҽѿv0@:[?WmѬmd:oxhyf")7.B)W=?a)&2߶/΍Uٸ G#h^o$5"yfaa_%^dQc;%Nj='1wp[RPMaݑzYC6Xˣ)*D3+J\NI5zz9sjw8se@X,#04:s6T=i|0ׄ| 1a.x&A1%cI.;=XM0[(KF((}KՈ218OW#XtHʝ3owͨ8+e~7( 05A7koGQuwפREo4Y*<-, c`7rISL%C3 9i=Y—7a-I'.C9fiϺԓ`4dJ;E/ 8zL*w;/2Qv3y"N 2uq8O͉u< %t=DSd/Qeҽ/+%#H-M82K$"?Ye,xhe m'0\XE~pK%h֯-]$DNAQl<"$aa{l.ly{cb.IB7q>4Ar/ÖxCJHUF8Tv>i[ZfXE~)oa $xVS/.D/θjBI^RkE<Ɲ"d̴ڕ`E!: _.#g9Yοzy-)L|MR2S\ az6ѧeM=U {x5ּ qUcV==qOw">li? I_K,O(-Xi$(%` 27n$}Ԇ<ѡ +=.vТ*QzV9ՀCJ2CWFp4j@Y; dS+!g P™w"ftmE֚Pf { t7>}\TiI CϧJ%7d{8Pu 91m]9bjz+Mǜ>9҅A@W"#&@*wދPAKC*M|oray,{C ;&`S4a$""ԡ0L|V HEc7/@-3 6׽,֙ '#_I3$9=Zҕ ,1qK~>H R +j^G}OonAΫq/K%PAbm+2&"[LV[E8%Ӛ(V;(GSL>تv5ŐnaS19)1!hThsB}MN@һl/xU%&8]X4]"D͂WU.㺙_Qcqx؀Hp`SYB5B^M-]C|(fbx"A)'He+d՝82oڂmeW3Nը φ>XeQrVJ,A^yaËS2;7OM'YDx8/&`>k[ľ#sP"-(wvTOlc2n/;%e$2]jKv~F}{5b$IK { #ݩҐLK (.e:PfS0-QIY*2fT7sF`I|D:)6-$Cne`Hb T],M0BfB3|UgEKТjV [.|hՉ0w>/ꐲ fmϷ[\S?ncT.c{-*)2_poxhL =q[MWgi@L*W{ nSU=#yL>(μUŶ-lsϬSC' jnj*W 4XV +6ހEA<$x@1/êF w86+EnQ(#:G? ;N0G^|R(9a4cBhq(VKJzW`'_0z87Zk@"7%׫]^b `_SQ<;&'<8~ۨ ɸ%nYVrzl{GBtkfodVӉql|AM2nM)в %wgtK#* l’7 {C+;Ⱥ;d ΔkX,;t^y/β;Nh®5}רK0(TI]7+V22I!!,#FN,Gcػ  ꢪA`qM[gmKO#z+GֽFeh74)%?PghgbS=Wˣ/՗Xܚ4;R&S9y+(Y$806|.yN+# ˤJ;\~pۧ ;ֈ†b4:yLF rci?[/ M tn6_&8W$0"3YyGz0?@`siE]ޏ[@T.i"G@5SV[LJ,K~j{X|~U3qlX鷻C;4EnqQ͸+n[} %\mIe}x|a}0/frqC,y|+nvR~ ך?Մj܎iV )]qjZiҴ 0i!ʁ =:3G(A5s&l&M I[|Ey~jh_Ga|٨k|dқhֵ^fQsƃ(jDK(%,AF*hqzveo+՗{C:nuLME#{# Zm$42h:nLn'gGgz#ZNApkEBMSv2=(6*(\Azi߳ OK%]ŗFkHD!s%)YQYz(h+{I6z\B^$_eG <@$rUz$u;wM@C&g1aEdSa:v obӈJ =!2 9Axټ:J{`Ofإ@*-Xth(3+ܤ(nzgN{pd7;Kb~KC_n+E'L-TJR=TA@-ԯV-@Vզð/`'?ӱk&4)+'ES+!9LƝ*u^ݍ,ЕNpiSb>A"Xu$뱇5Eͬ՚{! WcPeb?TlmvSX6k;V8f.!^IVmAB?LUwv$Z 3_Yp# HZSuJG.[ll8#=ߘ|dʠMBK:a~@;Mr\|/7V5pKb2K)PFHk%[ 5:Rg$;_gڭ}wW)mt|+BxxO:ǐ*р8_|7Y#Ux h5 i ߮~_fDJd@1+%m]9,4}|`P?!Z-N,āKXẋ}<>J~ JpÅ40{\"a]ꖾ{kVhmdl"uC8"^nйES f' ~v~qL-}XP:U]"y'0=="k4ӶFnR4\%B̠Ì;k^aP92d#_>M}zi9]ntOAUzt<:=P~X밫yo5SF(s@n%Z "qZiw:$:'id%vUi:Ta3 A56ȼduV`6?G".PmV`5v wֆ-@q3Z{tvib70p727)E?H+*sΘGqF0 VyʕIqnfK#D1q&*?hQ9>2.Y{gNnBbs쑂s1bޯ@'G<_F<cBxE)H 0{Dk8Rhڏ\Bs_qؾc<73}nSwNבwBƕ*XJM&qb3h}^(e#~@ }D=)r1.Wc8) >_Cvl(N)n1anO81k\M hʸR?uNҕ(nݬYa u2ݖ,Wxp<4ERWrdkE 1YһXRBYm.'s<;y ,L4F?EZ|zLoc20 >nWX%9 Z{MG=RUƐ0o%G>8X{>|xʘ^g<9S;5IO nDUe^z VP”ݖ;kz~)>20g$~ocgJ]=)'U WݹeT0%:9uY;.Frأ <{} Vj]Ĵ9vbAzZ'6&+li+;1Pެ靀P)^b>ڼ)0&j[e(0"̹m<9\N.UO<㕥. 9u0i~\ }WeuWŵ]N#k<ڴ1o[0ߝ"jFLjl70UoN/88,WN&K_kX˓ h)<{JI\F),kHv2QDVtΪs(IkXDhŒ1- 1_7^/-6oze:%$)RnQT6 AAzfim.~YuVtQʭv؆|gE H󉢾J.d2j U(*DΎ6~O)_7iTGG+Rs7 P9>؎Ն}?| Ұ?@Y8!_+;SW"!f^nQVj$b Tq2]̘?AL"SˢT"!WX닳JYњ'gNWs腨[ZT|Oz݇ٹ~֧6(UwMGᴬǎ ]l`dFVP>1H|uT`aALZ?,v 54䞮nZi*( jM8FXLyzT42&3;@y&mM?!{^J 1sQl^_ EpjrY(K ǧ5IN}(ukQPS/0,gYwԭ 88gUz7olI9-3~%Ȝ3*=EW)+:XV.܎QQ[via^Bɖ[}> Ł +G'GvUGGo{C3џ͉Ik铟5dӵ!WEPbW9 5ff$˅d]?o/7hӈ[ f6AdG3,-0+Ysی9V~^-~nѼ;[Ka0\x:o}GOC߉KEǝWz =QI8hqP%l,~jIo.˜dnf 6vX+XO߻OQ9Ǟyv@c*ڤpzzPjjKҗGGI8aS65iɰ~iG& ηRwy?/N/CSegca12=6k5w4=Uөl^@91~ 576az~́&<쨙]q/wpx_A;I j>% Q]G2:N; Qq>ޤQFhN*"?Ri>$@o/oCI [ 8ܒfS4e ւs~@͠wC=6'PIC) s$~p לC--ZcR.'\5;ncR,ꫴP3+U$SVϦ:2PsRm3G~`Ё/#5TNQat2urA|e{p}W|Aw CC.xqDqy 13h*P`}H{[fYS٬&5HpоvY=cdttz[6ke&},3J?h-bEH'BD/ WG)'%da,5፹u$/ҡܩQkCհ|\* m0#vɍIZV6)k%.aHAoܣD?SЂv*nYOh/>O'F]T OGnwqG 5>qeQudM2Wg@5Hս 8^dp~=wY-SDK Ν0.!̿Ei|4^FBuTA2f2 ϷGY!]YDD4D;g6t!=DطPy輯pkKȕ4:ZA +NoPCrTL83{&t%=;jK>`B{ϟ8rTe xBLCg$*iMyE֒amlyh?"  'R#[fAl25b%Th9ʟmk}=L퇠@>OWQ}?so)~q(V@^pzo#M-2,g eojK~\ 0#Ge$9{ ,n*ٱ3ZiRavQH#3]o%]kh[e:34l S{8%˗ 2䋥v aSϏY6|[TsAk= <o>cY&&;|3v*H;,o5Q8Fpμ#7? cb :YxIl\ٰy=dUn ,wl*o^TzS&;ii{0E14 U}_S*YM>[4=Ec3f7"2Z\W}X//^A6WdsBX8ߞK&J}JB{?>=+h s9 Чs/#\it8ٌx*h9I[ rChk}CF6=u1/h6̈ % :M 0O9ʈ,ÀVFD6SZ`oVom5hHNjUCaO88r͹lN͗J;z/ܞwBNݲk2{mBS~(wlrw_"fZD؏xQq'^ iiR/ APo9@HL !=d#2M)'n:k{U1\!ےIQ$}tr:4H膔D6PDا(c͸vo3,5dQMQ6h#ISN3r)2o5- ({a<_&$if?XbWY_dQluhW҃*ևC iQ:uHu/nO[kwxL1GH9WoP R<ʴfH=f|e6 ByA]wp`ͱj@j/xhTY0RWXՇHuqsH\?OF_'_fL˩eQn*Ϻ+LOhl ĵQpߩ|HX#w(#Զ]DH8" "eҔ0Ia[ =Ri2jö37Bf&V֍x(\7tV0_KFGd37S`ɢmNJ&7ԄSy$ |ǃ(>^P j-|@p c% 9Q z;JV5~i d+IN {T<TӭaםyV2lv]\؋ڑ!&PhGrQAWnjhřb1y~ n6AT  9A3"ǥ=1dcZWnX&q8 ՠN_O>[KsH~w>фkվ[N<~rSR b,A)9!MT2Vb*"!2@%Us.B|jbKe/84H5o$!o]O9 *˫;j_>Tsa/_ [ܲ M{s6b 94xPī,Boik0IE.1K' QA烷ST%<|'I\nz=ݖ.oW+DnK1 s@>bXa&B7j~VK+a2E(cY1 CPB>g`y%#fe-Q4|.)T`P8쮟U&׋,!4#;?w3Mg,m3S'}$A\J[kzL}}{ Z>ue'5M\;P8-AMe?&b5#qh`dwحrHL ""mcd|ЇD6~v0D~~Q='Mxd $A}@RVi:ȪaM۹bnNQ_0GQ/M#;e']B5ˆ?x4l,tW4P@ǓArt:H$>Q943l?( Enp'b} ._mZڸ &3шJAd\U1/?fҥJמBV" e3Wé{k4!WX&$V%n)B}Q)ת?%Qk 1 /[kCIڍx`\$aq/,@ Y1X*ʬaW/*cg+Ix\W&ĮGԍBGϖ;[Q.WI8-?BƚH. ZX2=i@Xn!o]Jex@d-E,fM!D |k{)WV&vq1zMH^EDZ/{[N{N[+Vh(xp8R>IڧSOQ^AӐ&BvM.EMOtN{CYx]b> >߼ZtocEOEg &Z&`)nدs~D}VjİՄ .1Бm?AS'Dgg*ꅊ]tCO)>Dw/A9)Fc`6B|[j9I%OaGzY7;ĢI8qx :"׆,5MnIq ZWe]x+ dC9o5kH~B I`RvtǗx"hl5%2,n$,D؇UVۼ;> j.gLNp@}ptӛ?f˄]nif{O+Ңv PIiŰ\\^'ОR\$pM^F+:_B@QWgV@{)>RKӤ(CE<AAunlEX*[] RGC/{%GPCwK酠%XyUEM[PnM˙#} dD/7 H>@񩟼Z]`9ZHU$޽^}$<7J"'xcӱުte&c3A[e.%Phֶol ]׏oH.o=&&PM]NHYV: ,(C2uF/[s5 ӕ-U.}:I?둟ZWc\٢ 8:f/ Y[B 6}o+-zSvx&X$Y}}b~i}A>?r[45[:M2iْ$N-58CRlh'.a:(SW}!-/MAVqL㹺mS:9{@ Ru T,_°0-h[v$.&tJ@ÈmD|a9,y0V*xI7/}=Q_K2F.)dhu4.mp/ʤwux6uţ.)E' To%Uv [¤Izec&]b7ƫ^x A͚v@[ J:VqI?aF䂺L8rn/֤L:&(eӵgjäeѶeA& Sbs~AqE}MϠ7덎}ln>q Tw(~bOfB0:lsyp‡pW=dJ?mSӍR_ QdaQ{Ҁ+ሼ:F+bg+ ') ?P }h-H6'Kw_ԁ8ѱx# %Q2VNr)~uX~:eD(fhV<9(3xn9??sҔf6 S_`%F0Gr,8D%]Gg:!x4{zӰYLLN1's=PJ9Ӳ!"NH&rgS#Z4ZeGHSFc2wc#TW T+t0VrFBr 4NiMV3U31գ+& `9U^Entmo܆'Ø\ RI|/&ÏtHz0?F:(TV@Sf|GO:yOg;pE`ǜ ,> i3@]kLsTַsP{y~D"C=XB=qW _2%la"i!w9h(a{Hǫt߇+m 9faL = qs; 2*N_a(s#l G5KK(eH)\Ջ9_S>5t3 2n<) A43h=`cHѫFkaǁsYqˮԠ9 j'=8:ck K ຨ%:pw^/m#}@==}HG>oi_2 ߡ-;VkFj״U~Gi~OUxzqᙒY` lSšAC,>;\*DO ewv-kivTRulstd%⽐(qA ݅+k"8Tj@AϣSoב]#oe_$1KƩX>7\xF"t "5Дܱ; *TGKzˊSnk3+"RN߬7/B>Uew^}LL39Ya̾xTjqgl .lq},WR؂K JPC|yXa`#c>gL֘qxίMkJtyY% ^{#Ux؀̱b-phAel)K[ %hU7ଏpvVhA{, J[mJy5>ϳ1="w-h6RV(ldbtY< {(,/XLrJ#9{@@h;КZ*iK&2kN‡ݷJϩ!뗢X²Zjy09Bɔͯ:H cosD;:)b`~;^Ff$ ZNaB_8m1r9&;RtrgSA6 A5$v#pєI ^nSϯ, 󙰦[݌,Iq;$M:fጢ'O~F貶wփEgDqNv6h4,>C s iKy.X~ߨ/%*w6F ,(DȞafyEgr~꿖s %/pލo2C64LB0ۍ٥wN!18WO5:SL˳w32tu*T1%fS$5/ K@σ(]Ôc4GRicwڽ4~"j!`罶RmI–dyYEUrSj%jYC,BV%.N>w pWW¨ŮEL .HM$rkvimz^c?ȳX8xҷ`Km<"}w5h 5#]pkXKg֙ey9.^}>ƌdj0[bO(È/!4D'k9:4?R6}BnbmIA=H*vϹ|Y8z*qpLДW;A6jrs3=y$gDzdUqrj@Liٵ|nvL-ѨG>^cJ3\K̦vod.ɉm1n!V}?aXG(דfHֈb:ӥuŰiOlkA]ܖ ;%J(rAxx hDWw[ #+sagfʒ{@ӻzfQVU?)$KQ P@ֻ,jK>q "Yo% ?PL=>tegR<4]:1Ms:7Nŭ-D;w'h*#=\& [4դ߫0!}KiiAn-UyLK9AW~XtC괻5NC^Jg'\sz#4J?DApls9p!(z;jGD w/OQƙ8wckS2(01ssNbk2쩥{n*d&~(;}}OH-0HygI-"k1 xwgB6Zٰ_L(stX'c+YH/*hYO:-Z!h攋4XG[ѧr;!҅կmS*^Dnlu=p|MҟM|QGa=cpivy`,ਗ਼$<߈ YQ&- ŻŔ5!|+[n_BفRkMoOCą_PM_s`bR7 }8pi!fEt| PKyY c.AKN'v'4х-h|pTA2>ܿs_2cOR+fȓ#b.-Lzf,fxξ(Ep|>+o :Q#O,3}gml!dJTOvFg3 ZϤ9hLHg3U\+qtu7d[ee ztY?X)<[` DQ٨"v;I~饬xϗ{TW<- %'`JL%?P@Bf?cNo w"큛- d/lKe9XM%Nxf-ɡ"KێwΠ`?]U &.|f@=ќ sn[M7r6 `-ߛ VN\&i>IˊV܈Az΢{(]zzUt<œ~S"dp\R czJ"3@kũa}"j'$3gh̒Wl@@74n ܹK+,?Kchv PZ{OOv#ƌCΙ$@3= 59[[1\^&&s/,䛝eAsiM6xuRw&NhqlQu-CQN$TbwBZ-}9;Z݋ 96^i=2-=MGm8P[(y;dd%޵`o]wd %"\Eu $j6rӱD:QoGbTf1P{pmc2Ɗ{|ݟy [ \~7FM|U ?_s3",`}ä^͍- s}e(yGcL{}sl(wd@숡Ze9oeV=JA&ĝr;%~,Œ`ku 8ڨXG VޡzS{%"L" ^ũK3V2L o?g\/w@7"mLDA6qHjnFor5N[ޣb!5_ݳFW=o@)8"~af9[!PA?@e_.{u_GY`yڴ ;XY9Z6znP힑s1ݮ jCo{|bpjA+O,e`(@t/ %SB9VJUBʐN"@I > 5ߪoD[ I$惡dzv[[+%O2T?2֋LfÞpFTk2ڪIdı_A<`­p99{/0uh%s+Ui#Ί@*X]2V*tSn%IKo2dj5 $-=̖8>E/Bzx;Jb֋Ƨ n`R3ܭH{IQp!̌F~=}KRR! =E9́%8_<%8_He8 ֛5g =ܦPE]~ `e!h YeViȠ7tУU2'23G%ۄȚ^QEufa&îݘ].F:;0&CPgkZ1DR1q pqUv"Zʒېv^ɐ((Ι(8P3DGSkm}dÉ%R{G"R`6Gȯ8@_5- | 7>^!3U>t(PavW=x|&`ӥhmYs묧4V$9wΖ#;рěbmE{3`I3Ql/o;jz~gF;q; ؛0s7Faл8skA7.;9]Wb&{\ǤD cS&gË)>Z ?x75M9~ 95ʞ ~|T9pIaTV*;.UCIs4M2#&:|‡S 1lPeՉHR .exM,]m}W9U -ygv%ËZ[ SoIf*SP9T"7͞Ua[T' O<o4}bHc,Y8OcA:Y:;&{뱪&c{WMcA#!b1K>Vvhɸa6N_ΤٞN[JV3W}D@G;0ϴZjL=x+ 3nȐVaa=TrҐ{4,uwJjӟ4\Yx !x3}mIE|֏Ui!}'VamMfsΞS?K"ċ @6,ʛ!pb>6z!1+oSԦ.Z/X|tDV$[ =C5!|Z%)rT|{>#آX6cgd13&e)<3(O谹͎Tbl >Cr!Puzjco?:`/}6(M̕ aB"s$C;ΩHko~/E_t!*D#7\7X̌* v_Q͠Jca$ + L˩93d| .H$㵑;9֡Cd`Bp-;_SCi*g 5Bp=G,K[RLᗾvfK7LdO)iIh<]kFi^RqpGI ?lL>4LFdy}tL9tEV5*rtp:tWGL%xd]!O h%,$莺ctyo4 CBGiЗUVDd{LA*6 ij1h8R;H6 wLWbޮtY] mv1!ml(;%.htW|?k6Qy`[MB;$} ߥOp,?qcфlAEa5]}<3MqxfTľt8Lߦ+H M {5$wiׂK--0D^Kt-xu/n{io5gH2髆 F 7(Ua9N\fo;̷dtnd3='Vi0d[u7P0:g`!=}q+{6b N+*J7EԷk7BLg;=S. z6+tG?/,aI(dh&3"oC81VY> '*OתW#5 ϋзqdK5׾chՙ-B<<֤LYoE.݇}%gZGÎcfIiWPWrx*T[>|sx~/6{~^Oze'wīe kv|5\5~b單ϰ޾}D_*&g~;`&/X5!-U|kdFbW5>]3$RY߁{%_?y4re'8c'S9>+J(b(/YN\XHj50VTBv3Rx|ZgVe8(clM a}lúzϩ xIhLh94D_Pa*O[u((lE C!AkG3q0 Sq`]_݆<@LkG8e@x_xunqAM[ߠI[u֫zyu31 .{vvJ.9c]ݑMfFy-O|$/fg$,I7 9,mT]TN.EGyh #pNkuT}=ߠ9X..fr-KL` ;Z%YA)dǧ"Cҧ#, VP[c_3jFJ\9:p~Aj3B/SRI:R U€RkX8 p`&Z6~ h9"iB$->Wd ffZ =Ƨz݋q *h;y`8_8lCmw/n>mVGQ-ixH<y\EzΒwa6P 8nUAO!4sԜiCr+;r8 k$ܱ@`\ +0 6=zi1վC/jP2=XY.|b>]K>^ZSI:pmC+I:^F"$\uG7|wY%J6`Vf{l"_ɔEСm@O]tNbd۲o_^ P&KލDv@I25EZ#;=!0/Ɇ{A֐w[i9-7ߥ'.lwWa4^z{oLآ;p,ck0wm"kw)NP3E~](݀MI˷BzDPE"Zijaoxm:C ᖡt&C3& | RL15)$_⦿OYuYra;Ho`aw,T \O~,4TX d9ݬ!$t2v(z?'KǑ8xs{ʨӞq23 pB0,+p$r$qɻ)& U8 {+)'.*sP|w(̓E d%UdhXu?C~/=ĔyOl hUx<K#EP;iΓx6U:+ W*j57@uR /,Qc~g8jڙSkGMBκNqdF`] x,dؘ*yz :W1Xr }GZmKԎt`JSC6"G Z6gE_CɀB"})?=k͞R\~q>c;ϑLvRr>&Jw*Ywlea`̉Dˢ$fgW6 3 ~JCt_diFEeQ$qν3ZIFZ UR$9a*[$OL_/ A1x}.U; :LN7w0Q3,bYi~d'BRUD] Q֋:K_o n()j,,1fwȗ-̡BBS&LZ՝@MwBj߀`!׻ZY7$~P3[waȈ E 0b§_'lB O9 (+ 66Jͻ(~Fpi3yx$.5\txG|$"=Xz /צ:֧VyuKOo4&[2J.$`cRo>gWR^@QYi4qANcuO1 Iٔ'vˉ>@Z2_cā f{pw̼YCtB<9H] K؆GU]=hXb[OXS5 $ClTb&YJu7<xDwӘ-.~+r 7I9!nt8pp|sNȲC+ >-s Bx'](oodd~h,19λhΐz׋7O(' y뀶3kA G_;93EUvQEC?p$ j4NWps~:_L~ARUBPkrWAؚb4|l2(otfxFNIs?{cQS7aE19F.R=b>!Xm$z@5&bHGC! B?fx&;K|`g]:ۣw)㋼`:~5^2Y'\<+/jpz5lO@Bv8E', ](z>v ]!_L D92HO]0!53ZS篵feg2!R$8?=q:lK ¨ҬDTsK_(!2˧nqm[w衁cz^D11-DN[䞪 ^ͫ)KDCYdAR>Dj8sdDH5l+̎9>c]tހE6Đ:K)CA:c#t P S̵ݪ-saY Hby0sj\%&]nL2*Xk uFj 1DAMOt=ns0FM_۽- ,'"[!`VLϣHw.hfԴru4FDE,76Em 5f ]tkY1өԥַ=jWn̪B ?D4P%@gݣ&cCy -.?ęU=cK#Xm,}ɠMh/F#!yiwQz ҹ]5 ]"I%T"Vh*GWW 3'+c!g8ۘ3}A2s_ 51 k9 |箌}vˉ@O7uu?VOj=ne]I>`atĎk;o6,6ګi7C]`xm/7¡d۰#yf >s*zR)^aNk;!S$5Qy LRaL)'y56VH%Z !lx̚Zrp$_B=^Fٮ,OhZζ#y%/ic;5$mBijw8?cw{xtB<-h *~j[Kw# X낭?桕qВaqp hEhb`y""(s|_]Y(ܕJ%=B[0fɡt}tG&S٤PlPɈzeS 9$FPZQg!-HBdhx_w"L඲-N鐦(?Fa7m_5d{h |`i t9z  g洷 3S(Az=ŘJ2l E^[~T=H[?ϩTr )"J Qqg|ͳ; lc#cwjrA| ww`_aVy|+ed@uC^DL/DOWWTɜTl7Q8+ٱhi;ept-;h;O/#}EDK赍Kk2TcdLspw# ZGp#D  X*5+q37h4{ ܰ`+O\bVxx;U؃"Z*jȵ؛S}/.7.Pwst,,=67UJ{t҃׹"z-GNL29}i#;9"4`T|DV1D72_f3XXzw|ثx/٭q:%/8ܓ-Yy2*z[uӶF_({.Ḭ+]2kТM>`LT ӖCnPgϥqI&&nu$5tx.G.' s}P^sĮI 4L1BSO@!;J3͌ N&pqYT ĭ2 禠+d][I` l?^^j%ケ7ZJ /wY9_|;s!+0̃P3k뭈ePU,PaLnsP;ģHCv34.fU8IQ?&¨xCẉ=r8K*`!|v1 I7ctNb~eKJbأ,g(&nZKP* .*(ECRF kGVL{ԣ#nОf lJrQYQXq)(rC/\/PweS`ioƐK+뉿3{mTҲ6s%*݌n"[[<"j ȳst{Wƾ&T~H4@tB9/J♦$]rllmZXk#{"uĆ=0+ْT k`//m_`R e:5_FPa S~x8mJ @0ۏw0+Ϲ ԰,]tr58'&ѳa|wTkI:')i{cup|E\!&H[K檲DYX5x]oYE-K6ShT_@:jdi\R?0_o%p:bnXWS)vTP#O:B lep >.x' }ʃ.x+,UVK8C#hvhiʟnlO_qAÆc~tBze^n_֡[xFrKVnAtvL]qS13xk]xC<̗<ւqq|JwڬwΈ*`#Yʏp)ܚJRHNف7vrZzIWNDe TUuC:բ:<4Y=¦/?+HԪ$gFcиծOfĵ<>Sф)XaLi:sSZB~mk Pĩ&'V֕Qm/];% ӂ h8hfßǗsDu 5zB[4~{Wzy vRb2WbD\;wnw"ʁ_:%|6BP*o~W-,^>qS1'A-JԖ<H(zu~EZWi$A vSۃr} d*2\Z[-FK׆`;\ᘜ8  q'"@S+VyH:2ɀvFXA^R^#q .0Bu%i_Q`sccCfT7׋3BR&{74T{Z(MڱQ#]ǮX4TYY?Fo-ѯVpހ.}3M4@5ueV3H;hꭾeI˟זc^Z[I]"_sdRY a<a9 g 3kP&0Yڟe¥J>~1[Šc'noQ:qk:Wjِ60*I64<.%<L3<1y9۠+PDwr'Ѣ0(,-'j!{gIS܎vZ/;a{`/"B&"^cgT\ wkQ0ix#v  &cyʱ,sx>l$DFX&}N Έ6nHdkR"P [pF8Ō5Jsq>NzfE!gc%7HѓZF/˳ V Uݐ sX]#Z+ssN:e,k0᣽s`Q\G]of uJ!ncA U1G'o(AtmB-LQ1 8ڱ BR\ӓ.@6tnS3ш=CIoU#^J/f0%'Cpkz_ZF]gwY"u m¨FxQ@ *Xi'*>zq^xvdP8ug 'дc@-e.6nET%cٶUv_#RS]M+lrgaZWZEdQzЙ5%7&qc7J˚C,v2^'si9 miFF⋤͖Ѯ3&Dx%=Cr^X^00u ]ZHKld"pN@|UhߚxѮ7y,n96BcdF{n&2:Pig1ɜ6--˨aGڔXEV[one/jËv9hy8F؎m ޖVlH>+)5f/n)4^/nTx X[s9p&h|)Б]PQ',` 8@--W<>XU@`10o) au @_j% z$ )]ac*(W6z 苋zv%rPzb1et2cU\)d&#/B>Pr{sJycV3cPD6pvFYMG>ɿ؇]{iRAJ}?6RD 6z]w-Hy( 'X) 747]yE A@=^Z'qCRjd dyfzAs $l0 7+m*08Y}IeRt/>z!4;q=`VؑC9M*_ rbk%^Ջ.4Yb40vx. [fM:VETIuH WºrO ! 6IP*F#c,^EH҈Ny 3^Lji }5 _ 3&<j! .R ^٬ rH7Ozhgi/Tk}t qVU* |puY幚lTk^aJfR V]De حw:ڧvY!5u_.{a=S@=-NNFO3˩ UD-kiE*;P2Am3a5sr6G#jzhgR9%QM%J bghk r=x:e,,kcr6^ Jhr<oYD}e\>g%^+L\vg>;hu&S)H Q,\C_47 ~쨗Vl1. /e^\2z߅xg 8],(TH_8$>hXl$U'ڳV$"Z[Ğ^u1÷L fEe'Q/9L: A]" M< ܌c y2kt~y/˧A}#%îo71" :C+<el&?'PY#SzQf efלmR ,{(n@S cUgP&,IooKwv$ *Jͅ:O!Y]b0z8+Yp|?XB F 3kH\t.ѧ1t@@u Fz{3xIh' h DI,心 \ nWAl b8Aym*QypdS\1IЧ \=C4 bhmF*&ΰق ۦo.=ܽYo!Q3̰xS T߉l(Q> XB՚I(w׎6WTd yPiRbs=1g%H(x6K 5s#(lm"06 f߿߬<*VdYg9#xp{\6@$7,žő+pkښ74[~-qr}dy%]Bq&nT]19AHkU~ *ZhYpOBړ: &g%z("҅P[t*yJG=0g$(뗾K2rO##Ѱ(^hDžES,.*6X9QqsMbcpOps9c"hrGIVHjf27DU=Kmmm0=ŬR'M \5S=!ܕ^PoF7% ! x4z2!܌B]d01^nzW)`gg0zE9򺫛kRLd(oͨ;%i[,%b'0FjA8&n)vwWHwK!Ei_o۫}XTԆ4ً0P]=_ͫAˬKSg i4ؼ3-KnWI[FBO*D#;9E),e?+-Z :tgY그DkV? a"$rQOa0I!)d@z|9t'qO Uv0 `_P_ >7rluAu9ukNIdV^b;YʼVaUb"sQ0_K [Iޠi? 7d˒Y@Dj=K-ť x0CX14!_/?{]U.~UbC=q,=cFtu6Ղ.`Wzr0|bY,Yʻ@!=j c3:t 82BNtm(BڪK4Y+'ny6Ts|Zh;MW-kNmd>ڕ; 6TdUF@HV*1ZS9\3drh2_sZA> I,Aon2q&D}] I_U+Ǧy$! m:_|ŧ%] C 3;7gx 8_sJTAE{-/2E}'%xq3~`-/Sb+H%ߙyMNg6tsoƳTH1mToCP(Q,jWE1*U]˲tg̰},7[1 )?jݳNB"KួQ})`?1}^n*+g3ϐGV^FhB[Ӆoc ̛J9Fo Ol.ZΕԈäTqa>(2-cSPi!L4V{+y )uP|Eh˂wUk"AW 僣2o.Z\U1?UL6rpⲪWpzrm}6& bBb7 6IH"w ~TJv4G]=z$Z`ifOo ʴ!٦fy2>$v#1mt"'RE2jqʬD$nPj^%=AMѭOSwy @ dI@5YGxȿp +I@n,!eA {5R?ĝ4Z4uc}¼yZ*+m4?_`Ud+mHnpYIKps3w2mĕp% )+iC *ր!JnZQJ!n{(O믅`LT5+Ƴ9Y*[bqo$(7jD@ӿlFq>ZֲYo{~L cKfCE>S|LS^7x̶]R#/K8Ćv>R[8gd,ӽB> cȒ?^fSD"ɭbGC44 Pmc}FcaK^,}ZPs{mݲ6JCK8(Zl`-] ̶3$Ɇ&5/:JGD<>ccf%dVS}@߇56$9-c\ӊy{9\pj_+A{K922* Vzdt@b3Mhn2˺рƂp?Y*=;1OuBP"+733ԳZ0yts=r͑mdmgQ.jǓMwĒe]nfh?Iw+}[H Z{Ox?=?G`?,:qD-~"q ?:tlC@bO. J6plV{}P0HfÎV vmQIc tҚƃCƺG37F@CQ̪܌>LH(FCΏ.Uy3tļ ?()Kxo`өkQΖH8)p|_.W!unB__$&R. 7.x/;j'仓ωd)sSwu` .(-^m== S?U 4漁АpKD@Ģ₨Kno]"Gͪ<uzǑ!żmƍߖ[p{NI/%eȇZo1_p-u ֹ>Ġܚ$|?K\|Z^'XrpX6BGYgfԂ;.yS ͜b;a襧4Y2g9,p9ʾY(0@g;k5Ls|ˬE1VZ+ې|~)vベbsƴJ ì=V+*r' ,C`</6 QlA6h{j%Ey~ V9f+Hq]q|LVLYF 9<[iuW0~)a)M꤁x!Ïn{-4 L[!SŋFhT\=rQH,RV*tjE0TF靲/ieu=@֋pnne݌J/'c/k=n7VSreHWTQGYxS$4_~ڶR?i ݥ9ktWQkOV+;a\fHQ;qoSu)K.A\N7 Ϥo `]ewpD+U񹵝)=yx(PQۇOJu~9dzMC&s3Mt %Xp\|L~1`+yKޡ98LΑ9 Ɣo([m UvY ;ߔő:9Z+ï4X>q@ډk3r\/ulmdt%$.Bo,+%=O_ߑY}r"xax AΥt ak"L$Fj׆MLG#WN- c([r\RV/x ‰qF Vjz`4-:*,E(tT⃓ͬ+Y#eÌ'04M%ƙ$\19Eȡ%]L+V M AL"t&y)H$JuޮYl,MEheg`2*eTjG "@P/ /7`4GgԓsV2*є23w;0Xߖ6F̶h 28F-$b <okʽ(]ZbWzkCtqtAh0S@Ap7*(*Qq ԋL4)F-WdɂPm>Rgn" ,ҕ#òk,i_n yV`ܤ>:Y?ynoS7Z%)4 K.̆gd<84p!=x:)FcHCU{l!rDנPc{Ji aQW=Fv"奙iE"F5p&V%#r+:z!n, Ȱnu|К™ `ZBZv7@'D.$ %Zݱh:Ī} QU(W 47F$ P#Y5Ѝ{lm*/Fq#W\ 5_ wIL;qeKOp8z{3|f_׆Gnu"Y(] %ΞC r_C4J3v:腱aCP7gGT"GCzAd%p. jT/ᦲ*=HݴkDKmCkB 7dyڟ } "=GT Q>"X,4C=(Ɖ(n|&xuxdRc 8b //pG4 6C*WV]>N G8Nxf_؀WM& mW ~gb6i([ߝʫy<' .m &å /D vRifR1dnTRlF*Ʌ<#">bU]S;m`漵)S1sv^,7U@7_ mv&4p &ra^TDnef&g38K9J?;SA(n~`it8U+:qV|b-D\G09Zrۧ#u M8KةHpFyWeD [zM`.ŌK4 \'£ ZDB #GF&mԐt4i"1!nVdv^z Π'{9e;пR، . 㦌3ӂHc' c ;?|-{Dh/ K~AIJMy{|H~c-L(?@&,9c=~C f_Mg8{Sɐd-\n0^Zhmx.A|5A?q8W:2 u+hA @՞;Щ&8 =8MXPhEFj K9b|Z{iS05rHԉ((;b,O"gGW?nJ\sT))4tRcSg:&P*" 0z/w'+N#VJ'%ƘNQO*{q9^ݑ5;pOѪ]t9 ;IuXuSLrl"^И`V#y0Ŗ"ϜɄZ1-:3 j[@\ͪ.ͿxIpʣwz&CrjqOkMX'&mNk++[ QaU\ްdg2/ 7F&߱"Xb' ] |:N0u_%`vrkvE vI855(=78K 3MqXJ9_ۀ»-45`&%>oֽ 0nALgkeRPA6 cENIW$ƽg3-NQXXpv Y$M=JDATl!8vELc6y1@wSnqJsĂ{ "!tK$Q ytw4uތ^M)knjP|f+l^nAB{6N Ԟ vm]"\"?ω=] ۼ3;w܉! |KK}ptdVy)-_CںToU}? <Gzf4r"|"AU3-c5.o %DDr,?~)Mr[@uSV&AD|ƼR0:c>/g7yGrhTږuV?6!i&:`r\0N{ eGAWaskeQ!ǒxWpNIE*-C!Fhp b+!m[PKPrD)zMHHWt9 .H,/J]Ypez[xV:||we:dTƠ(;sr:7m~h>OxUBFPAd"y\^dA@qi\zQuPib_l^3%''՜6ēvj6d$^)ܕO jR9z;#|B]^ ETKvXU8`|ѯ LjV-NmSI6JdC6l=d5¿d1p~%8HL{{KYCyKGbz6*Co-@!! J`nIðGvWӜvO#qT80_7FG&_Gt.7DjIA3ATv\m`bĩ&\s ~P;ќsPzt<&*@= @# N 9z-)& .$?a&H`S%m-i} a QVW|Zj*2ѯjZ\ :F{kmNwVT@=Wԝt/t`y(UϞ6(28CG"+!|ob!ΛLKiwR:mX}d) .JN u+j8ZX<VډD-`9nOO#j8GJ=5cڹNhk52lItFETNafED@0;XAAyr5I싥'{!Ts"}[Lq b ,G?۫Xg<.] C7"*s-(V@FAz=Sq.!2ݭHI hk$۵$\T =C=7׻;}aCt|NoE$u_T Tw57e`tvd*} c^3]٦b]:5]\F66 G,-ѫ}a1h v}=^$T5nZ4;i$#H)֡]S(H$4_@ &kB~ZJ96NmIY^16* }whn{>TztSGEK ۇ n#:D zhϊC`͢B( JU] '.F\D7dhyDe<^ dk‡0u)t,:v*|fʸ9%=I><@]\.p\({VN0Λb3g1Y|f+&C*8EBd<UO P +9Ep02v;N_<8 O0iJ8Pi\cQK4kevNA~ LG; 54j&V=`[Nf U!_Ө&Կ:R;AybԪzaI/JB-7s&n:CU p:,6`}4SvR<-/DZjE8-ls /|R`[Y#࡬`Ɍ  y Sݨ\ b_oŃ -P v S=$ЩLe 4l]]޶1Tކ؍"Ǭv+2k+S,Yܠ٢&:miT:R2G To\g:t4iqeN~RFQ?fGIS.X v@mpIʵ(JH;,ڮ USl9GE ?*T y h vtC--$*Gjq}̭ZgaNqw#‰탶D 57snƷ:5XVnBVEY.C߬=8VT$YrJ$bs3w+ϛX %j&H.3nVdW QgR~ԙ,tLu"pL?8m袛Wx Um3ϲ)E.C4:=}s8!iO`FEeTlq41K@=?cb^Ld 6;quy9%P]e]@pj!R9(j5,9ka'u׬{ېdg00CCqoJvm*[B-Ԥ&;rf[N;䏝e#wCI-d_ОMIPg|<[N !"I :)ޮp7׆iR Ŧ}l.xɵIӞ^6#R9T+/YF|X|~r[nŚ./KQ%7>́ ]3+D9kH@ɃB#k10|xƞ'PMaiyIlA(k&ߡ$Z=%I GRJɸf g{"nX󥕍ûbHBkhabCuΕD@ B[ɔt$Wgg{ݭ~+ =25ӛ!U{؏VvDzւI,ZT )eEo㌳ \ם tzPN@RAѬj<'X 0t*}01/7d ,PDP[A6>1KKfd-ؼ SEr%\_:`j|ڤ:3h¢3'{iRF'3@[uuxd㬠g5:Y͸#LcÁ4UANk=YSw,1#uƬaW/!fSY1yZЯV,8=HtS:SfRyV(+ڵ؁I[~6FwʦcZC 6\2kS5ࡳ3+I;V]}51n?hoʹyz n秦[b֫C-xӇ =WmJ}2G/1=@>vC]z#c >dkG0fة'kzbs*/ďqH9تROՐ뷝kT,0K*Y0S BQā] }΃em# 4c64uI >~9Em@ѼMjá5?]Һٍolo _%jOf:c1X- lK6Zz?~;kauO8{tMX\ Ep?ӥMrq"C`.,s- E㜡vfOxIP]!,nUjGQмQmX8=lIE) ^G"B8$yh6+QcM&~a)FK9VyZfgⵉׄ6ɟWN.g 8`1-qs63dh%B!Rھ.q3&?,)8kq"a+(q-J-W:V:1SP{3L``{cT 3zMR2y*\Ci٪cMp="&9zRv6N7c,kӢ <ژ?w H4 uՃ;ɧ.7P+70LXc~&t t4zW jv::$T`U^ρ?4ǻ$ oL65!A><=aiu|hIn[uʪWUZҠSx̀rDB@֛GKg#/2nŊabaʶdyut C#aʼbNx6 ÎГLm 1XoOW +fc Y#0‹y GFu f Kr6ɈˬE#^Q6<| =@h}SgW*H "r"^l}8D9*\VKYm9ܫ#aeFȆ/a1zZvdċ`qz'R b Z~CERvXj@zXYz(+ 8ܯJB/wY|-LuOZGO@OPeC/CsvьlN˅qMsw E{'nj!В$/ %dT—O< m=bd3A!KyHDt26R% $ 4?*҃!، TV'ţi&F7줞i : jYre{ðϼ ̓vBhOuRsW:kfN'b1? N\)չV v/W;qflglZhN]2L^ĒiI([{= ܿ`.ݰctu;ͺBr- hE9_ =͚D>m⏅8Ŭd`k <{ o: D!TIb+U?%Vp)0 to[5JT9jƷ[f(kT=PϭubDy"0-0-ohTa~El|"Mw`.sE{5*&z Lzؤo圌bB5nSEC e\ĚyRP͢>߾&NM$" {,C4Ο E7G4 nU, OzvHЅB/צЏ[jc12ٖ4ZD <|II# n{8/~L L5n~f1Ϸ wDI})^dv1C/)b^_*SMUuZY O9|*Jx>/ZCAowV \ع髦z4COCTʴ܉kP9? -_C:>ٯ +=U 8[a´L\Y$샇7:0'*^j W [߼܃ ȅj)B ;$*}$Gc$iԐ'r,4d0)h Y;/3 mwYKF2orTɴ` Z{WrUYцi@%+rA)&yq/" :g(ֆQI4o'(f:V(YuC'٫^a2ӨJE>0ϙ@ @W} O[Gm\oG!Bχ1f+zzG%JS`YQENFf ccU C7GW8E3*#Vab^Mil"Ql!cM0mR4!s)BG(٪o \T+]19&/ak_lnS!ٔIwh:1Ƚ)^N q,TS:/QeC<FRqoB:>%Pq@qx5_ۀvW_por\hkݡ*C"?G!by%Q|S7,R\P\J"tD[-W뜼h̹̀CɅ'qU/^=*v~*FbLN-L^b%*f5i3r `圫yq/t {64Մ6%?ߴ;ߞ-!|ȹEc Q*ŏLБZmNAR]vdMrv!rl2é;.B+Bmz2xN+Lg*m>P`xi H#/AF~^q]6" d)9^L\:q[&ozWWpi↌$ATb~6vd;&eEj|Ďcp@gFS&eV]\er4xnx;*VB906[ZK\zuY ?$Xc(Ad@tr'%z}D)R*+yi3ܯ-`ӼU+ҕT9b S9 3Q#z}y(|R+0Ϗ/ ;𚞽ƌn*He =ˑepB4/g Sid?ܠ!~@:2}j fG޹~UqFdRN:VrOJ%S9[ٳ(("(l}ˬwVPeb`ч{Mo>^ە*?˰>914,"[@8~~֑*@w mّЇ+@⧱D:< ":$/)G|r%lt1o"8C>Z9o_qDa/ A}9# TUBէnXb K$Tm?<0xmLr-LL Eʍ C|_ ?I+_hRp|}6q*Hc_ht s +^ !%CѺ9hB^f}U5f$_{fL]Ew;]І) mY|}` R[ ŻaHbJk>B3SOas,JPl|k^1CQnDb-"=(^IQXs$P&D]Ktnmd 5LKˑX.8>T+J|=o;*Mt2}~H ht8\OL=`ݵT!nZVsND"b/=ןohCSw;h @Ba+""AE5 8u,C ߝ4ǐ`D%yznî4 %Ǝ6s/>qkfbGr& uAJVpp]ƈ7k{$C%x58oH%A˘"@'0fF ~ZC牃Mω)0y:d1Hq_ t,PL(N@q)4)R%=ײ=BAeޚj>. -J}(G " K9Ǿk$BJÄ:wnF7L־ͻۊ"Vo7#7>8-B"{9XyE~wx>0p2.Ŵ$ތtkV]Zh `5'+uk:R~IϏr6]Ƌ"0#qm_+8VըRg o4e rhgF3J=T>#ɶA;s̴$i@2͂_޺z#Sd;L*1͸J_p?Jh$7rMh16Y'_[iJfC.!!?k[5NjsiD^mWi&iZ⚓`Ƈ\x(sqqḦ9pe-d*W2mU|'o^k߾w|0+6f۳ -A9 ahl))AQ}l #B'@ =Xܻű!`,/u[~6Ʊل|;§I7{*6 ka#bw[LT9 {4ˊ/pJ!Ik$b«CeEi%VvRj+LbxZ-v0=M`"E^A YޠɵH"eQ5P;T-1mw1# ^8YLuZe3"q앉E3{4ڲ88󡀢S̑1<r.s2Z|Pqd/u(T-03]_N1ZlU]VL8/k|/LRf5$|;V"7p?0f*}/nd&*i*@3{C˒*uK$[Ӄ:ٲ-m34.&"D5P }P4Jw)WJ\mUGE]x"ڕDCF\ydHXrtj:C*!ىZQi\D H4""}G|o٣]*?b:C{i+Z Y=RӁOӇxtiVmK! L6>,b:-5e+~w۷M.>,Ƶ*Q-+)QRD?SZ Lb@ K>ZюXQLkOyeHxdۦy5h15~65VH"w-d(&&QsuIhlkވɊgړ;T*83C"V7[5Eƹ]~S/oѽ>b{\T(R\gBϔ}8ROXZ00ʁwɬS!A9_E#[>/Bą_CK%w> ?쿏; ^VUkR2Z^BciX7cGL}}_Yќ #ذnρX}ШVb?$% WN^B1G9I BѨ(Uw^Esm{=} ތׁgkL"QvսpdkW]=r7KtLb1\%MH WRhpБZS}Oz 8K(w6c✨nɮ܊蕓pCuP Eټ ,df߻1scjMX?Dz+}R^ gM"Cu,G88P{'nr}Y~dVZ1 oƙI0/&Z6NE툫-*DA Gbq+T}LR-7[=FEY gQ0DMv9oa,6PaTXbNب][MUe#=~rу 5>Z2ź ^j'l)nuZ^O r*m[蜘դ\}H8̞RZE^EL}u5rpo.8K}G8!^a0&VGZ}m_>]Y *hY$ 7ezz̗)&}B|iL_uPV+;'<D2lC[N? 7dt| JywP5SiBSU(r9%;UriSdey׿a+=U\qi'OAe}6!2{cz'o|071;>xĒo/Wii2 ~}]"<+`ib7["'NC]g {\XH˚S iW2p鑬گBzM,G0I$pXSL5nDpgH=sK@^%+;X Yvgn 6[ }BFk%! 0 M^sl@w2,j0CрF0<wq68;GKWֵȐ-N?Pk+ bzIV{]5"=sHߊ#:e塊'=jS>06ǒI|#b2yRB튤'ZS""9U5vl ʼntgזk*fnC+oj @MdWgʢr~N!h'@tŒ7@'uyu/:13`t%~Ч+P$>.VFiw,̵2δ-@#k~>--#-@D' m>*y 2T**q0kޥ#\87 3%:tZ&Ÿ(je4#|/ /5@7*=*h K^\ҩD_qI5% u6U>V :cv5oG[38L!xp/'d1|NUSUmUm]ax6K%@, X\5;fmϿ! *qgjHjU"Ϣ),=0 /l/!W5;"|Gը6,/]R\388@uB7'tTs0Td׌ѺK?!! ~z ZV"  a3rG҄ J0)JܒzR3Djӭ6>V-mN.}B_.*^ ̩Ɨ;DWHj4pоjGϹbe65b?dsڇX]k4G?k|sh쓌:#!Ԓ1@r>B&'ׯ4a0}+u^ {,E̒MBdBbdqM+Ac[RnF4C (B۩SCDC~@64ݬk31ѹ,<tL>}?NR)gGpl|'87k7UϜN˗QKӃ.Ց2F\j=á/atpp8D@1)tHZNX/#(f$JȱUstxig rO5h"5J+םľ=Vr 0yW@HL-i7k {NӋ+M?]cQ'`sHJr&A.gD[LQ/A ]?jxlڐ>K4;O`g"*6/^X0B|!]^t)Bb!jp@y<8b tVzH v0]"4JlCb/}iQP%<@hb!="kzV̎Tϴݹ0]ޯwXxnak' DRKS=*ѿFu;uzڣ$avO]Wrtwꍿf#͎]݅5TҒeJ̔jbd%P؛QC0l; HBE,~u2I`]Xln$W~uVL;37ei. F9kDgm: Jz52ys1Z*.Wؗ?[Cw%݁1Ǐx?l%~d?\)S؀Ix;ыECe 9Y`}, Sgo fC8{eAHи>f#ؗ'xӽek}kvi 4S?E~P{ #UBS€eh_>l?+sb/oD tkG֊swz0@N@$ QY(e6kgȟEO`0%U<UL5ngqVfO&9V-y* /pO8 tOƗX&)e98eaBdd߅ >,?j؆h{h%X}Ю)"Ǎ$YCf"xue6yf7zUNMtCYG6*tI*$Om>Q?Szo,1%N~ I >6*}"P{+:;4KWыC9PaNBF7;įjcs؞OVk\%~|OB\kőqj%'9oyyoo7 $É19A W[C>Y3R]6}&55}2uYqf?huǼ:;>_)7 XTCF(/y( 6A]eRAk]7.iNK<_D6e\N.eh'jh,Z``̺Y`Gp#|+u1LvPx<ΗhzX޷*PM\<2Ϗ?F;x|xHag; +N'IQW_s]z+)Ѵ_wEjԚRZEZS]sO Mʆ^aXM0T$۩iN@4g=!rhLfo^\AFDp)_PMN+o"bb= 79i<] pbC L,hMk}ج;.rJ^%]2, bVzM /hѦ(^ca~b_I224}dFDv49a]m, G{Պ1DMtA|b6΅ҶKlm7 ~C_,_ɿB\; a6nu> 0<HJstZ_8m'B5?;ц(i96`щ dC f,Fz*nh-# y)n (څAQmQ\c266%!8{:٘m/?ɞQ)bМwԽo+(LG, pyߏ=u)wjJPbժtܼ-[nyAJyJcέI8fK;:L@M즼GcWװJX&^qwCov\ _$0#ޮ7~i+Cr9ke`m(̈́g7Z+![0andT;&+_N&t򷸎mPOTUi# I'_gz2YOaFwpc*%F $HMϹ,.dN^N?2#?26U_GWfꢩTf L":3Ĩ ~@|"l :;jl U6~X>x"|EkcN9o_q hczrՈKj/M^sb7P)t;y4zcT]s˴2t%WntIupe!&zNjN=Bt+.;qؚKlJdF} k!Iaa|5Εȓf0O5-Q6{۷AB+7=vA =Cڡ;0Y~Oͼ(Xl[YH؀T40 >i 7DDK*݈os5LOcꝧ(eZ= DN**n@!a am7"et%ikF*<8 3q@V%DܳMށ˳iN\DXm 7y>}dfĤ\#U_P}2I/1 ?HtX*3 osRdtHj4KEYo*WG\9Tu$]dq侻9d}\'[ ^xEj…vU(dgN("oɮhKj[L$uQ¬y㕥 fT-j0l̛FjIa4y9u 2@Z/<&$6z'e2 9h\C[Vmws-HqV*QxOME*h(mM==}InSk`uَj@EBoco@B3ukWWDYor.FMJνu]*b/ 9כnU~5&pBi|>:a>xX/^n08{^?$RQ~>{i|N2W.&b=̯A9 jj X:9 J(KrD$!kc8q&3=Í -K-rgOdzN?ffC:590ҔiS'6~lJ>羑OL#ډ}̼hWoCʈ&Q_(Â$`+xOEj|1*i}ܭÐIQ / 3L=~' ?F]ʧcBo鼱K=:- cDE#5|R3G9-RxA%90fgFkDlkrV+At>v16o: yZzOW1A:~7^5򣕁B-[Ę2R{eb ^u?fa*$] }]-;򸫬 <-+@zPJIY 8kgs(+pTp@4YLq 5wY-7C R Ѳ"̭NfTF<9~=~8vNgY/@jCSU8i[d%i6n$Nx*@^Z\L$i -)`6dDRyC=D@e;mTQ)N@pB{~dRh %亥L=“aN3eJtB⎮BZ׆~5Ǫt~犳7 .MiMO'*՝-̢$Ӎyn5?M3X! i^䴻hdcS鉠}sRi8L@Tn,͊t9]i/),@0I.jV'(g%vt?1 enO;b[IG_acs}>Ѳ}a .vJKi8x=,p݇颅5Bl 7UaG5|vsR>z&gCN9oٳx.4r5HA{D% o:쑵=UUe J8( :vA!NJJsXVccH= 5Bvx ԻF'}f| B>%GŜUc:@iX z!8"|AqK~H;*3+Œ<5aZ1{]ma@)ęX]y .s3F9j'cs7ey~3nSpZ,rpu=>Y뉀DA?~y!, W 'JD(yrBS8/ti*zV Qn$,ʛ@=P<*M)W5/iS %rNS?}i"C wCK1gӻSQO;ꔫ-|䯨 N>lXsHy`7ZuRY.P Q cj'2zdwNfOY|HݫuH 9=0xeBjE( 3jZ= "֝9lcX 6~^/-JQM3YWX'P<#ep )c/pa"ȚZ:YGt=v:"xysEҽCKeE9lt:o`cTH!g2!s2G\aĖFb:/W?>.s,A 1DE!"dLYv ܀ch!+Mi&)E B0H1d;zK@FA$qͷa Zy77hs,R"?5$h% )Q,Mjj`8OiWgFfV>~6xp7." 8r|8P[ bxzWDk 5*GgAFBh֭z8j4-.0t0>)BIeqK ~Z=_ǟ>恷oRM(mhʘe_I6h=jEO03fy"7XV?oPqNA>TR([GM)ME_SvṈ*%[wg_`)qo 3 nl^#J5$/:^_1ˏ2ds2f_?^0*$nkS6vߢ1s^*\yjQ6qʅ%o sGܒjV7J`\ ϫh jwH^J5S9$_(c fKLϿdԬ9S|%𒙅'o'\: P:b9`?KrMx&M9{b,88>اv[["ߐX1Ҝ++ƛL5K@aA$=8В۵}M|v@DL gKߍV;Yu2;@B l= Ug `A:y(&p+6Y6:Wo\mS\gn԰ͻuޑ9nYw.NNN#cm,&M~!WG^[ )0U +ȡ ) }SZ' M&b%&j"NAdC`;d/iR,~zZ 4qʗm6AtƺTyh F*`$ %rDoA@v]YY\py,pIk1 Ȝ%RrC"Kf;z>OTEB;e!0gl hD8oǖho@*3x̕g5Є_3$qAM/輪Dtf=2 lܓt{狡?As9紏]{bfg{ }7Wt<4ZSH˯\{b)iA6[Lm}R4X $!;!ˌg9R.x_x$J5Fd }so* l1SQqmW HsC:PVr9ۦ~CM.!( fpW2RttW)sā#LlZTLj2gmcgI0Uy;oezZf(A͠#,tkͤ$-9̓ οR5+vUiw^4` ߣK3r.XE `; J\H,¼ed83/e(kOsi\$jxa#ْcQ:*DPF H;n%L?nByL? ƕѧK=ql9t[Cm#kz/6$cA?5G P7]8( 1U2]hK8ɻm<=Wx.:Qge[c R v +$X~I_F>kV3 ,V;+̣Vʸ  +ꢙK%2Y1'oc\Xs^b,|B ;V贈 vw&"{_T2fx .{Dn0P{Bqx9$W%шN+ڵ}':(Oqqw ~$&C))OփXnS"(}aTL[jϟcx6L*#./ި?r!QBF$]Vmct;O2YnA6}L뎛((u!]wR:]KH \9*(WsmBNf>d7::Iz[%ebkdžd|Ww}ܰ}WA%9-),-E.c캔iȭ=)n" lBP<6N@.Ou[à0QeaZrBEC}"DіZl$]רzt+תyb5G9c~@ "`ӿWzX@EC/x.q7m|y>'V k}fX\x9Q@J! Kz"<;W`^-7DzXTF.2:L)ZfRcG1仯r1.bQ:Mꀙ^_?ajd-5#>zGD *"Ņ~^9K2!J1$&Ѳj{٣gÎ?xԇv/G$XrDt. v @Ztφ Zu)B5Ϣ~VVNXT ' '{>+$ 7!\ڸ`U=ykp@Zdi ie֍>Sz69T~<B;}IwzSjH" {4&F 4(O7qiC轔9h0C)pV@L7e peyxJ!;c51~' $k&`|FˍfGMV:ԕ]pڈu9q=3@";МŢΌU HqZd762{ߜ,cƭ!1#HנSI3+m[y kJ4/w6+"efXb/d~w v&\rmB l m4褛4B%Ë_sZۻrU6K3~Et.)-xdJ;uX~_B n爀|$m=YYt8ĜsW" 6 ug`h'5$Ч\)8W _iop^x_uuWJu8W :KIfؖv,{;ĵz}g)?W9;37}ac@KtY:N}RE+svFr\oyWV*N )byϭ!ŀr~Yr~}7%H=e;Ï?֗/)Twfy-M`4SgiC3qY@E!mI?e}%MER$jyA%'i$.S12󜣉4٨ٚM"cƋDK{#]x}d/NdvB]utBc{ȐYiumM19p<ڴCl2kr"W2T zP :(2\@K=v)^}1̫Kc|LF,E%Va\@RtoJkdo׷א@j?zp5M#1zyMHgB]jE?p>< X)`oQNR`M^BeSL3#XaeJޏ¤͖\En'O㜄t,*eny1,2H# 9R_i^b^4,!a&~[bb a'G# =]W6Xp҆/(+|.D}wd@YIvI0 afmzK1֞6{>}9\z!]?GUlBUYbj]TdUQQ<(RaYe5KMk2B\ loQ+{n x5GWATolk>({-w?l~N#ԁͺՖKsC雇>K+̵OǦ+#6Edz>Á2m}qK:xj%2੨A M $Y\W#nJ,bS }NuPju 2aQ`67TP45dۃNLVn>狭=zi>j23"A|xkCQ;k ~*=s W.8ձwСi\Yy _}]&plUJm [28ͩXXl(m}Tu4SX- k4MNE|H2n1߃~%vFf^ATNYۏ^Zs\V:_%L|O&Gi{VN?CYQ'"y<¼)18!`n*,+%s[uU Xvmev{؊MSvHg{c@#$> 7KNB]v'm}͇XX.ͲV.[3Ѝ?ȠW"E9][F&4uVaBˆa;kْ8'ܞP0ZHSwY[X5Hߋ\uƅRXf݀\ᓶmm׎yeK?Q;a-ϞRQdwUa~ApX2a u%ۊчK9hʭ0a3BZk34Q1=ۇYe^آa@Pdgȋ$|ڢ_kʿ7{J4  Ur{x 4((Mݍ HVa\gOէo*(y,eP;sρSl]OZ7|sgI+ȏ֖d%kKx l{[GGg"hY wbc4Ż_GD+^.W*(8vc^>. Ӗ|㢾q-:˴_TO6\p QM _Om85g{ Ie[>YT=J! QgZgb* y?2G!N'0 xK>\:R`q/u.XT[.S0 FLN!Qq K\xK>+Dj S Th21\L\RB4qz}0 ݒ}O) <;sQA=L -gIW+1ZޅCn1Cme~_ؤ88d-GbPj!,w7m4E5k\F;" a0v`R]њ,zx)Td 2Z9߅mv.ڏ0{k/폢ˊQTp RO-ggs?&kmєhq }hDuEo*=fohgQj|J=itNs<^;gFY1,*ympF\4XT9y4mɝ?4ICp3Źk06r=>V#qqoJO gKWߋ:D+m\KQP1i#+>06{) _kqay|1kImx犸zeD"^kǑNTz eܘH/ɪ. xu8 p´ioY_Eh}'Cma5Ƃ ^RzKe/F: o=s04`jRD]q 1e]*"VS+3{GK*~ M % {űmڣk?O**27j>FD3>&@zՍ1YZkv  HNmϟPkr K*n>)M41H6 ^ɀ!ډm?`.X3|t~{>d%a&Fvx{'+39\0pG/;y.a.PXr$>ݧg--vHv,Rjn/2;dj6\&Ff1}j_$HF~W~!*P yT$͕M|x\1l케Xs_N90Ļ1dˆ6Dsh,RZIyXQgi֑Tʤ3#hC"`]3l=9OgҍSrAv+ɧ:s|T9Gi.y ɜ. h=R NTeٝ #~KD\FZUrxh.#5Ic\.I@\,fqWa~BGR>V6'l [6,kw2؇5!@*٩kk nkr!c}vIԮct[`ynC/A*:yU.z!ow+HBs,fe_=Uiԏqw<`'2{$\^ FQ-sdgIr-1闆 pJc+zMG;*ג|LW[~*"g:* H~klAWGǣʪlAF!2AqNW}ϲq#F8bay)%WЂڃfG']y?L,~.xPGv^KҡxOxP3rmü֒]S1{g=!u @sUXS6£p 797,uO5qJxg XG֢~,jXYh/x$4苭DzO5u(Zg˲{ЛKL]uh*r%ͰsC5ȱB2!!i7p MTϡ Ml8!gVqk]=`C@Tt_)A|3/&H3*PJt©~oZ:E"4WY33OPٳAf^J n%/jH.*Ґ+VRzXm 뭵 (>`&ݒv='k+ ./fAJtf MλǤ\ZD`hT8#(K-&9;Ӷ#mTl’tWxAs+W@qO\Ǧ??UWu[EP W9X9HC}sm)ݦB/H WSJ[$dzxvomO" ߸Wa/I0/rH:V*ä5X6kI+R sow2̿nO;Ch7V%M`*SSj(7),={?Q7Y;& G`Udzs W<7mtpUTu:Vp.ÐPh:5'RurX_A@T8_#m vGfe_?SL" =Te(2v7!S}:t0D?mG;4s0}UYIncTa0({MFx Š7ѦX߿I>ӹRx7JƆ]U+!32CsAvoTrU<獲E2e {xAMVGhՕXSأx9~?1[ zEsoz#+BbG9pTMi<ɇ\$밗gscnH!tJm?1;FY]1o"I}1cx=aqY@ x g5k7x5yVv&f܇Jt8}ڿ>W硓?soT< 0' L `X4E j7]yiee iO3SPʊYLTH(\4:h9@@L9Қgvt1*PQZ./hVj-ivp*@p[l93J٣&42!(jE?,VJ̰[u#nX8e;:,\< `3(tPq67eQ9Hap(Asm)>S?Rm)fQi)Qs8/p,@ݘIF- ?Ǥ J2=:W2RX}E! 51BUέGFb`3Fy ABH'Bj(sowB$}j6V@Wr:<  pčza7(äiL&Rihאx`eG_,uF#OT'k\ͺ%9@Ā%xmkk~yNݠkrUfA/ C\f#7G~&P}N$ȗ)P-4eN!`U+_=I2aBSڕ/zX0J䬞an4GԾbҏ/U_stu3gEket澿r+_QD; IaD i+]Uխy%9Q/Y.L-igh ,VSar7_/ vh Ή4+2rh%Ȫ/vELF`s5G _$JnZ@cJGꓧY/z;&tGxj9LG$J~f?!I#-<Bo3qw?,)DªXhOQTh/0nj;D̈́JoY^Mqc(j2 -2JJ5Ĵȥ'xex+CUV2fe>9J7H6 ܠE%GE"7p/^ʻS,kW}g\Oi(RUn5qi?~5GcHzW,6} Ia)w1c(0 Z}EX \6&RO@xn`އu闬xsrU4dYsͶfI5Wn5,D˰4; Sw#|?g' yV aE\`3a WX#Fc&r ` ښ V$pM V6J=cey;CZt?DžlC#Rȡ0]^cZI I!0[ c :{n:OMU" [: 0 Z*4cJX }ه f7v?G::G03 45z4cb*`UXYw:m :'8fBw(ff6ciHnO+(yǏ)X@IĐIY=3<=kzcg%JhIFgta|б+I@iƪ"'f7(Q V4E>gerBXGv[{C7ꘓu|^ӿ L° .ɼ h7LeO*.37Pй9p8/u.~ IIþ xt !zBPPaфG%$E3G;C3#gˆT WgCשC ݘC5nwJ A/ơicXmc;A,j 2ی'd?rb`'g=x-|.ZeHm7@5+oXAh7NjLAÒfKŨh>IFͻΔkyvUQsd̿*[M,;}б.Ru]B俏oXx%12m\dA9ө 6彀mBPv&oy2~Kh(AzQOuk#oc\ᔡ=/).ɀ-{lMWN1Fωn3 |sw׋Qjژ3\ݒƻ3 FLv+[]φ}h`ouC.^|\|{ĸvEyp]PIK2I+-U\͡%Q9$Rc?Cx+I7CxX3ɯL?8oS墰orA/3XT$u6$}3 } Z.k ^ pD{D ϡ%YzM`wOxǶ9f+mc雸$!Gc~εgN]8b) 0inb=27pBx QQ0Ci.bbȼ|ZNS` `$Cǚ.q֚>0B@K4*~K̨Z.pZEeb,d89ײU樊` O'SS҄`1lkFjd3X61@b@Ny ҹ._TlS@޵8*A Xc|Y4Y-'5c a.,Ih1}ג{ ۫vs{2Gs u [skjP ls+ԩ7;䠣-f(̻ԑCÎA5ěLpsflۏ2!tsv0*Ca4 5}W;eBE՝'>2趐0Ld1// h_`a\YI nAkHPɃKh7^`,3~ ܢ A8*ZY˹sC9<5u~HXZ&hh13u^v+@;?! p%TaO(e;XL1|d I٘PΉ-HW6)'YzkE,/†R)qawN*)>JsY!8ȅsÎMH՝y5ߢ;GԖC0χD9YaDCE8k~{9iBFVN;#}jɍӒ@nF _Iا䯮X6YK֐Q#b;:@.Bz>&j#)irH]]{Yl`J9[ R33q@bz2ҶAڍLx{=>յ |1 .꜎m(pVbjr_Cفt.ioA)9T;%snNJCs=Qv &ӝFE+LYcS, Tx|(}[3}/'tַ.OWR*}&gy7:^Ȝ uJ1T#H5}60$|6;JyA <뀟:^f>b g-kKhvns̗xrrm[r? X`^9JV$/@8&+kEHsė3hC?jEFVBl`.Y- z{ɥ}D`yg1 X s}9ek(;U|龮4wbRv+({)[_F1&s97V.睏ww5 r`LQ`\4klbef3HXLZuYZJ |t7MFU\mZ8dAkc౦4Xխ\HPV\Lq ^)eR`wC34s}hZQ FzE -ܐJ o^FJ`].ͣz}]o7\͑?,$ߣkhg30ki>;a?ʦ ]fN jR-"1Vc䚽_MALd2MȱUo'cB(baվ8|YrI[ ؄z"%kgI|(ײ61w{/_*aP f}vy#I); )9d"*ѳN'keS#|eCegSXsU*Xrݴm9S\I iϨoTXQc+oQU~H|݂ѮfJi8Lym`Z mQE8M9`0PgPjm sVᥳ=PL˞byRO޵q1Hs?%c(uam*yݤ7A>L%]m.5\KC3B`fy Ӕ>dT=)i-7EX/"]XO ȗ6w5D2bOWՃ<&MѬl>d2Dmw9[Z⤫'fzBtKЦ"Qn%J6Yxy9\9ܵe5cw-5^=nQ2`e ^=rQی#@R')^>0ѵf5v?3fƞkq,Lǫv=PŐ~9wMs.#{ݛ^ܺCD4b2tT8p9_S~hT8=xE $&,ć5ֆK3KvEEҹm@]kW߬h/iH*ޕ2Rv>X8oyg^j9HjyQ&Kr~,dTmɮ]n!-5N.S G5i6[ .}eA_Rh1"; * ULl Tt1#\"oW*@gJCNVq|Qq͝ޛ3={F;&N70~qodؔ<4]V. 7%r2FC]W.(x* 2C"HknѺkP=P@ZX$'}1ٴ'VxCQ ;?^u a1Ӿ} y_< K, (Jkw lȖ)!W ,Jӿ +oU&<ؒ,JWyz!b^>-+5m0;Hm%O @Pe@R´ň,ED*R7. 0;kIom+MB$]mI_'ג`.YUeIFTyz)BLeLksJcnނHVM[F n@w1Qޓzpd68)RɏSPm)z~;;EULG~c99d6.O,Z}Xa.Oܻ ȓNqX#SʫqpQ7Œ|*gć8," EX+ j|J'oPKqGe.5d:ܣ4*pyt>B(%hH4i84c8.GmHZq~&UKRث @-Ryn&mJg9${b'hmj>]\OUUlhO0Ie)!;vEsa u f_խno#w.:|yPvaآ4h0H\F7}? Un6G=sE*-r**m⤥q0kk /-JFWhl+b$ʁ`kj̥YBl1ѼQ w+9^qa  ].[[> Apx{cDMFoTPuFAK,[Wxl1P)Xw]߱sk~ґcÁ;c!s ;4+kfʉ^t?I3Ñ 8|X5dtpt vFKʈE6zcZ"Y@vpP9jٍ:E %0<=+YRhdH@&0 LS4#~ch!!%cFM~,. fqIWaͤ.3jH된>K/-[He bO4샚 ~YCoi, {a4 Jnʲ_=(#6^5k/GD?#l$^e ,\N;Y%𻲙{2~Ab`aA[12ւ,Y*6K;'zl#9r#> W!e} mrygbqdo[N G u-tk'xj~ߢwޮVT'#V%-Sx HJr hʲ ي٧R_U_߻VᲟbPaW7B؜3cy= 2Ua͗7m7VLE=cJ7er?C .VY0qwwP CyfhJidZOCiք!jY>/A$,F*I0qe2jqnؘ,UDs)argQ7;{-hf0~$ˠSևAI6KJ@SYe|qm^g=7mff<"!-c3CD!!l 40'شV/v_I7H׻'z=W Np%v<;g1h lxR(e#pbDRpxaOR Ɩ,*G*~t3vѪJҾRDnõ.Vv.8y,߆ڈybƿOuZ@+5&9("F;˶|[JA>2 &Be u.!hL+DxBx GCY&ASڰum2rLAe7yw@k@ 9(Ċ^hR. IM _jlj}t#uCf(?D[F:Mq$*s-P i`]BL{K-/NLV^s`!kxـZD/|p:t6S%Ϧ""ZtlRNQ% q&p̋Du1)]g?WWcH] Y-KF_bQ=FMG1>)hI!Dgb˭ܛ@}jp$PwejXzz>1X2*ȑ\&LUyl儳?(5KErhq 3SUKD[<8-'AߣzQ= N+-A&/ /K7c,(b1&0~5gpp:e?6}HZKB[enf~S;ѓkG*J\ŗ4?7݌esgK(`1pJ\\cQ@C+WHI@&\J:]:_ Ra"˰:a~+YQ=7a}g59y;T]b+o=~a承bGyyҷP+f^^J.uhXⓗ`-3Xw4ixH=T]rI)eIae#kxd[G󺩵{t(S0]^0dQ;Ov%puˠ7lUe]՚n W7|x]Z GoQGzZ}FrӇHU{r6n}"E)<0%:C5i?d1On ̾wY$hd{ca):8"v/;;+ߩ^puEȖ[Wr|Ii{Aԉ lFʁ\I xJ`A}ֹRTkJ!4 C42AYcfNkվ>X]? >Q˹CIqJfaX4."JH/uT%!iƊJe9 =6t=<3=Ur޶12s#L| +Ry`_$PV9+ڮ0۫@--h;Ѽ2C9:b99ONû~gʜ@M"OL}f[=p[M⍛ul?)5iN+"i *Eb4qI`rPŸVn_MxYꒌx6!^E!\Fɰ/laHwwhb?q3,I`1`4*n4=/ kZ)Wb=bls8:{9ʽўrVh\l͜~ĵ+0%z5bj+,lOf;g4- ,M.irHjppOk#ݧ`_ӰնMpn%V1<.I:C.rXsxg*LZ)Yq~!r?s%h,WA*yq3w /[# v9j*Rh,TQLTsm^lj!^N=♗yZjؚYRFȵ-N0>Ց?v7GMߥxmdY/_TT4q &Tâ#w+inB)J5ùȅsHٕ}\mz#Vsmuxxo _د7, ?6 oѢ? ʀ:WYfY7q)"re& 34|jU*rqWqtLot8tn1 Vnw*UFuc,ۚ~&Q(Cbݳ,J:-yr+6SQ8Y,WgH#N㥷tLqIŞ崙;[>q]?GLAКkH*atu5]_瘙Mp(Hʯq[NA%˓ mN gոӕY.|2zGsJ" ،Kү[A:v %k}a-ߨi0`1k! Xǥ}K Ӵ@tF،^Nu42np d 0szj CNkUCxSfN'͓IjZ!mgW]ο/,n͋N7FbbɚBjS}#=26#BEX9 &xW\pDAb>2W:Ƣ:2v q+e?I:J M*dZWaK )-8Ԩ#Wz0~cZ&L~]-_+w`e q3m#۳0PCYJdnfg9ر$ D(ص݋Z+D)-r$2$*0duU=|'lvGݾF>8K63ru..J5fIeVaԅ ]j _z{Uƶ~ ̬ )Ϟ?KL`c%|iԇFgSf8/A:Cb|3ŪkRP,2/et-~G]$amh2q Xoga O?hHcQϐ+B:|YpPd8K`1"j˫lo- /^gT,2(a4'S z* X8FC#!a梧1pV1:.6 ZQn_- 2{7*szj/"!]wS⚽ڪeXϥR~{A]0SIJ3YplRar1y:{ sgVg_Z:SkptGDk,>hꃁ69fk^1e !©Z֩d#=E$- V2Hh'e64MX4 :6ךI_e/;F[4~7BA4x:*t)Uu=Ep VUeټݩE(G,%i>ăqj1/J}:bI\h[zV2#Мmq9YuaK&Қ<m4W3PJd@O'<㯺 Cp PQg`iv *s3: g-0i:{J+;SpO ?VqڅS s;Xg*&Ɣa0 "HKrce*N)<ΦS>'ٟX>5f}?uE?He頾W^tU7R͢ jy/xX EC$?x:Lٜ7+Ꞿ5%:-z !W;SEܵ:ûyXh(O60\Wh"s p0%0 CRU?-s׮s?Ê \17/EډUTnQx>" v,] ZpA@,0|R$X<@`vKU$cHq + =v ʸR1?Ό,]bL*Ӂ^Os{{E.+ QW}D/ЂIܕO정fʭu NxX]ֽl&厡jV2ko a)d%p@};(r!}1 7ԫ[Ȇ`U%V]"KsR5 ԪDgc3HO$M^"c0'-~Dyr#رw+/boJI/C*mdW_pH U]+mȋxev#E'6ߤ-1N]8'HW`Eb;3,Bl!/q8D__>c>vti~=Pb^qō($] a E"+ DiK) >{5Ce-N%3|ɧJ9=4wgj;[BCΔ\읉hravxngLY[k5 -߅KYWW0U\>kO hQjzePu۸(m,׉FOeċj7]ϐeVSypE%g"l/- Zי#yeϳLąM3@gQ4A]Cħ+h'GȀ#YCwwy"AY.5w}PK@Cyħ~ k 13B[(Z+<$'-DƍՅ.ɈxNQ-|qkCN#~fSo@ ޘ6x M]4 eCS͖{!-%c`ِkfHYiXwg.[zM$_S~. K(wxL7'IfȀ×++R;ΘFWuuogZ1qN^}ΚeWEnZ܉5c d2+/)2nWܱy}Ey=; e 01\92fVZ*¬hKŜ wMχ8Cd& *AŠ}G=bl$Ơi8T)E&B ksg\߽3UZ=SVl^4_3WS?OwŰifS0uӁ1tYbD8=oLWȍ.#D[.<,'eA\QW9?K_?cfeİ/x*U"J^YE}ʜwe؅-X  318hSVof_Za;;Ӫ㙜%~jx|9yv=%Mn1S8&F@,2QU,/c:8 o1i{{JJyM}?.+EwԔ`wI2KCU,*ng#]3c1]n<`)&.JT]gY#mR|{T# ?9AaUn9X~!]6m}E_K7/ڶ}WURm㗟jNN/%dOH$ڨR!CN6\C(IdpDwKJq&N:e^N@`%W$pr3t.9y~[6"*$nͽr"o2y4U48.|^)Ft<PO8daxՓ}R~X}} SoR5%Oǡ^^ah>nA2Ѻ^Ë T[_!HtB{5=*7 :O"Elpi$brw:.gE[sḬ^tMZS9YxFܵ U8]ȞWݚZghbk"Ax~kg]7ė+f~<@p4V N'*a7'crrF e &XرOC-䋎7oC8_Ŭ&[xH AUcW& BL7P [*adܞK=~kt0k6#Ze#?0d@iupcUZ% ?1(ϧps,ay&˅­=\J Gu)^̤GYh" F^fdHey_hیNJ!'c)\׉Tr+6H *Ro7c" /6FzGUWCg k{;&,(-_Ux+") cA:ң{sT9znllu*|W_B-ހ-^5ه{|m{h#M(n3 eeAbE :l{xhqѝIYwcoD73a"rE%udm;o;1=IFmYpS6'I[Yf /-YʼW)m{9fwl _}O=)uJji(ܺdQtO CIfFnjФUh<īwZtVٍZ0^ǐPgWz+B,8e!N| u@MZBL XG},F1q&54g]5~hgJEѸ~)GL|C,SME>|#tNhR$ ֚CQĕ!tG1ޞc.hD;Ǡoh1%>G_`24:H0'tJ 4\ScEۑ K蜊h3K=*9ruZ_hgwE\!AW2*do|GKi}|/!p2Uεʤ|RϱxexZisn-ZQn#q9v&Zɏ4jl@:{c2-%{Ɗ3 jPρ-l">V@*g1;!Zў bulGuV]%ޡxy93G\LJ^©AbB1vTKvS #a\Vz6jhgȀ1CT Onzb?4j֡AL$sjWN#ػ`e`kQ\EYېAUY#%WiBty(+ky$[øgy478(8|#v읳Ԏݺ3wb~^:ή,b.moL %$i%Ew)̽0\)d Me}16 ;vt.ӣI,0ӂ=zyy{^4i %*{rLJ[AH(K xd};{Y[iD8JmA{d??Yh^ Z@+9W*ֳ2 k!C ׼PXcA_I%H]WM€}?^fe|e!Td@Px4Ffv|chQ) rV4Qf/6<2?{n3dHKwu_ h-hW+ieAibggv&9E_ӱA_xgofk`dPű>GP;ͬg{ 94Ao.3N/{!! jeIh>lfJ0GuO[6п϶="Bxq]ڡ{PE|q UŽll w˕SlE+@Urֱ#jc5{4.>)"(DtfoP}UIӯ䑵J%I@ϐ|d;U*0WЯ{$W!ڬaG HN엄ŗyYpI>Ur QH-Mh`-(f_ CF`lLV2،\L QV;4]nA-PuC J⺱ʙ>LmɏHζft>$q41>|VLҲoZtMawX09iD/)*X>!FEmPwStd -%Ġ[K{J.…IgS+^i..*y;oRJF[bυxW.7 ~IJWo.m23|0[r-Mf9Q 1tM=P1+Zߝ@&Pf s+@!![  2j{b[acoAKG8GK4I;JuE0?~᧍!0)EEiC:٢V`&7S `#fSWoC| 7bk%m{FϽi1,O~iLQt=>zv~TR $H&?錭/UK2Ch@%ʱS_nue:p܍qš$eWPv_5oI5êܨo- ڌ*^[ zJ> v|('T+񣧩Hzf]#/ބqВTs;@dz\>ו4w! q*j}IAEKM2\ 2wq|Jk+6ek³4*Dݣ_T1"b<*S4M UG.P(gгʬ(&[73d KJkV+:uMQQ+]S Z_6-j+#xϙfE E'jTxl +wT^G`R~tKQN ]!I~}>|G TRYjbpcI R3Ւ6UbE :@i=!lf@`5qito})W4_RD(eJw 6n6o[Ţ2â/lR*-'X-*Nd'E@Ik6|sh]\f#:2n;"2P ß1($9Lِ嚰D-iy~"M, *#\o-lgzrĝ[Tƻϥa`~p%=Zئ*Bw $܊!l'+]onHX/u» yR:nE8mu5.Q9{c.T:EYXaLtIIiȱt^r`loղvnWƥ́TS\cЮ,8Pu؜π?* ļ &wfz^D"7)i5S鰹;݀Kmp)1ʓpqRmf+ɫj20iAgz˕ޫv&-`4f(Z$x/2i ZP<}0sMK~MAKUzt ۯH#>?<Hz5hj8/E<^lgLp9:BXpcS1%a0(%7P[ZxZN}bhBkğ=m.ذU$Bsb~&O/g1;)k?_pGHg8cN0")8Nx0Eo'ٌTm P;,,95hDir7?82&d܄|G@QZۏx%@m[x7|dxW F0ڶn(OR*- !2/*1NQ=w*Q8~ٯ*7 JΆJV9xLBJ@zێ LY!Mf$NVqܭZO Ὀu'a]rΥ`LYiG4q?|{Gw⻑+} 1Sh2ͯp_-ދCwvߵe PC Z^_+ *hv:E'>2`R9Lق ijՆgU`0%$Eߋ>D:[x 8qdU[·17v](bKt6:BZeL8N78 6ēk@aUlRv"0xϠ1QY]HBa3~M-o+jm`:JzL?h+fv?v6(:V ~8daF{2hԣF0o:ynLzA6.ds2|u:| _5;2Yx qxYSW;y\By< 's-AIZ.2ug dh(qugRz;ké͝([}{ yFby/%A>ُ%d{awFy*u٫|OV-[s߂VD-X7q $&t vAYjN ;^yq3v6%ۭ+ ?/XT{ &z%!0h2$&F eQ(f TZ^pvMdAf&zKPGM BMx6K!-Q|KZ6"aSX[]9šdA f̨S" <.+T7pswBRhg]I*B>g=LjV5R,YsW%W(F*)(0*;~A)r[+hsC⧿տHH[ۄ MR"ιx PǤ,Hqe+XFdD,tgg:WfnxMJlsfQP&>4\6TÅ\;=ޔgh@Py1޷48A$mw8M_'.ھrl׼\z ŸLT!s= gשׂ.n}/, ]a 9h n*1CT.r[L{D0̈́ H=ηC?2*g~nL$y=O2 ]u:H;o&7UwC[MQ᫵g-ssJ7̺z(\; zW<96JŦ9,KmZö݂R<Щ m'rڸfzՏpjI}8G7/t-f&@* :>D#O'5+PڤQlZn26]Zsd_ ޫ>\!3:8B ȼ}i2Pk\jrTȾX'4 tt-, /e'}|+O}i5T3kc֗Mm!mbM&T~, eϪ04Dp Ű oENJ, 捏4S]w۟^0:b?]-5,}d!S Ywa9GCө+VS=Y6~+[b |yŸKҊ({!;:ֱJ赀 DY}C 1B9MYHh6tMIu DπD|p l&dεwÓ4{m0:%$%;Gpkt05Lʺܖ&t@ %p>Lx2Φ:@ϕ7 0`L  W{G'}4h0Y .-ch849| Evi?@QDJ^~RۅEk; [%e6"@B62n|sTҞYY՛E9C4Xi P<;鰙(yޥH ŀŏ,(}FD+ah9OyVuWƀVq QLpT\&:=۟6Tf+Qp* LcL $Fw2= t(=Žuf!ڐi{oͻZ+9iQ%uFOX;_JxN }= (iަh{}v(+ޘ^cPrfexxPد -:+vI7<*GƾX(n ! $>σW,,5Z7}2T#" fnȜK)*<`Zg!<_#0+zeyh1IC`;Zn\PlenV{Ծ~k# Hh;85K)@L7ŸZD-};DܴKrd%\mIw,hz.E-0YZ*&2p]:BUYP_gyLgktXf+=Q-fs3;ڲ]o,VAN6ۘYCD=0RC*}g!KުJ\hIdoRzoо LUR T] [e&ޝY3 W aZR՜b>Uo&Iw?yȪ4l3&ֲzR ~4eɬT`?U 'Rb7AHjͱC]*?mr{oشU7wCLΉy[| =Wc Lc_}jV'qa-#tlX!={FOas%ֲ1I?$@ S=[u>'[ǏkODkw{HEN}3Ls㕷jN-+ p8HQUQB>z *ٌd:vֽF%QRP. 6S;\jV_7l-Sz 1Fmtآ=/Mª 5ryIA>3?Oz`#M^h[5OSW|-|i0k+$t~o܎q,ӛ(yK!K:8uD 7fW$y"|91Ùq_}:~wAJ,71_ͬ 󈱸L=N!MxW Chy8)K!Mv\+ kcF`s֛&[rb%= piPׅ^d7!ڋR$o|cV%>-xQrC >RwMr`o$1m= (Tm&nv#%{k5"ZtƓ> j'FZ``bJ% `xȫO OARu2|&'\нǑGOo y3JAc͟Tm?͏DqItLF1DЍKB>8}?C6j絾[?/䡝^;Ut1|*%T.nc|n=]6Ŭ]-Վ}Q@d9WG .5ހE#} $>i'#٭(Խ؏gX5SMT߬Ivu+z[=m ~"xCPI{mYZc7Bscf%͍,7:J5ū RE0jߐ[#gM-m{N]_0v krKRКmJE~;zEs7+,LilHGʟɹY/W4 :~ʆf;Dc+>aB-`~ޡjm~ӁQZ)pô(n(>R!*4OL:* l,0 8}#FyDJ) Je(YoY f+:i8xB^)sF7}Z%y]sls1'P3d$Ifo#cR/GQ:+o\xAq:$Ȋ3+xz-Xj.l“[RNSȞTXͫy8JZ';W]B KiuWҥ4O$̀"R6o ņV:4F/ M]o//'Gi-A4BXjtcRK>͟ht|/3EQ|V۪\tW U&Ӄdsc?q`SqְN[g(Uջ6]Jlf[~hhA湋=AX&*툈FF7$$ ;N޽aA=#T#|λ/ :bH*a{B;nMN1ag;o BwwL@y}rj~ G:f^-Pا]iG٬(٪0bufNv=[s-W0OĊBX:nًLV1JӅuXt(%ċ {tҗ5B|x\}>J6,~ScN'aZ߈'7oF)"GwBid}tzJ:v@nszZ7 QFF#@H. v&dZיqdG"!or- ._3;r+w?7dW M:EMPX,>=; pkJ[n5Dmv.]!o7(GWԊ&TW uNě_gzz* K kg iUЁ4 sva~1ޮ-E2iA?3(27PXTR4a>S?β,L|Wsj3i IFh VSl/ uΨf#jOFvA'3+hm%{Lܪ }3ԏDǥ0ʖlN4$lG#Vv}7zgÖ+f1VW/"I 2is3"xتArЫ(lîebL7[OL'y)N@+e1GŞ8[󕜇2\?RBçeԸEfz8Xg-EmzWȥW7g`ILH\ooƃMI7Aik$Ͱ1+۱ 쒩lv^%+:30'YTkmևMQѾp&!lA&adC `&QT$ƾyׄlo(^]@C yc|읚AePy kOG7Q2n=l6i,f#7ldm=QqwQ9;b-ep^ţl_@ wo}Q)S<JlOSC˦+B¹7xtsGx)U*#,k%0hvvWq.& #0WhQ^43Q0M*6)(h0^6\J7d[ :NbFF l(ARu:pgfqz̔_3bPe&#yr@!RIN)Q{ߟ9`D*>^̬EBymIJ6z*;ϡ ZBA]i3?'7+wfQ4KfTDn3Ĝ?@8{#䊇e BE ò rIA#1zz5SA>7Xϼs-Dh9l#+[1h4fC$(/oCVܮ͉xH0nM|.8q%NQinb(z8BnqKBW^([yp8 x zsOo3v_brwiwI炎1f w?0$~"U)`Br"(H^]"RT{ u‎Q?6nhF*elݏWrR7ݟ.e.d%jDLƟrjLY܁V}FWV9A'Ղ¾c`PBADj'#!> 94ۃׇ¼TF"jxqM7 t0(4ؗ=ܜ\sB8] {,D7sԴCĒMWdF# GA =}ٗ\S$2jБ3#b@5śZN(gi}f-)zX\u2š;!wc$Kik*"lAGf MxOe$Iu"I#C:n͞iۂ+Nz=ՄɏI)T,#,=?,[BNtܘ%$,}w45 Oc}|*a$_Cg$a/17,R\!n4gZ0M,b̯7*kS^@)sѻ55vD {ki$LMUR6L5a}z9y?fi¿*Nk.xsU;)QYu"C#/V7m:I!Mc((r+ů#p0g3| :m+t\z u.I U髷P}(J$h=Q,y]uPI@Ѱ6;Tq6$ ǎyt36,D^ iF$hjQ5>Wjx*wQ7I Up'# w}sA@yUMjW O#RH[iQ|XfLM]B%s?(V0kZ3X6A#|x;նI p A66Ǧ0d)=D+,Wj:.-b! yǿLˮ EF7n_BxlMdm Xw(5;>)quU1J{ 2UIP{k[ԢSb*}EK$gDP-#e%Ţ2kp 65+L]n@Nkj5+g ~c~*ϊEcWK޴ҍ pGTN~ V[Fi0yoe *GU;Ep6rd|9S{KP?_E'|(}[9bd-J砡a.GE *.&levL`\nh4pJW|5K7j8kA Qsw3* vͩ\bXW6 UkSULLRIt?B] )UDzTx塞-A-cUV"+əװSכn H2vz7.Fa1>pc/t:"qPde1BEAK,%\zi*]j4X҃ym~#yӺ+qr ۚ cOȑfȑr }+0 z]/|KaOěì AM2l/o-Ե &Rs4oj\3BE3 ;Vb;cx/U!+ 'vdV/;6VRk"ָKXK̒xaQ T-P2Č3Z;ʠv6{K{3-7v\&m/bIZw=%~exhV7esݠ(L۟;%4k^/'T|'_:*Zq̲5 5Aݨ?p^lK D'#Q>> j?όsCpo 093k&{exj:Ev߀;%OX/? Ub l3X/mt? ז`T#!F0Y+eZ B$)BWDК o#OVYփoL/ Al@G*FUmXm< R2ڼ`&k+R@)i2p3 %i3psf::Egs5S:Еvr>V>~qu᢫7J2Ƀ}c`AGb`&Kz6keVj(Сj<-WHw`9CP>|BRwzbu2Ri{%_B6yMа- kJIi".J* y09*2Ⱥ-NP-Tŕof{2UQ*w][VN Ykt>_ڗM[ty oAŘ֊5hikĀѯ0X(8{53$ffcA4Mģ*j.Kn }|ԳWd)~"AwׯVdDhV WW"U[R0 wIٮ)-3ON&,lW $7$-U+m+(|r+ DeQWOVY %(7]`suG퇶u eD2Z}zsG&,wyɒr-}/>肫,pM]L:0aNw? X2Uc:f9tjW7R")b<5y9twSԶW =iH+)DS.CL>}m!l{op=+XG)2t@+Ӟ%bERmk!31heWoF߭*i.\>;HIu/ў߃n9^*xx^⇏0_3C[dL:b,Bf{monTp5MH,:LUCEjT-eM _|QI%#)YNr,O[3[j&Vp#Bz:IsN5W %<\835nP>(R7"eEMc3j].ҷb &1Hx#YFHi.N-Yp)huac׆+mH) R;£8#5=фn; dz 3ᇜBı` ]^5b ~0XtrVZ\f`o@)z:|pbh8ܽ%a$W59h}j~B/E86(W z8@-0P:m.)lָc֍\uN]Rt OmlnLA_~s,w8|pk n  so7̢8l#8͘A"!oOgo9݄Zr]כ'G6X}d[L,H E#va]Nf(cw{2xN x`ؾ9C% Cܜ6e>hq+M!xz[^_Z'X Ә^xN'V];Ri#D?;w9?nrg걠}}}Mϟ$|sVQGwVx,|&iPW.p|1f*ӿgݤ|@pǵG1֢͡Cچ"nqzzr](@0_\g9BiފSn1E:I&BMAy} oF[ndSFQŒ)=)8cZ |i2'gkY`EXthUA0 wlYfo i{xmͦuܹZߢ{9yeNpx|~tfiHB')!lŠ qs-xMQ*~PqhNU"(#)V7G.nQCJ"t~t(]<OJMHޱ)h D`~iHnm 9DzQB{J9'.>>ǚIZBo1^'3,J \߹^Ҕ`Ipq7Wo*ASwȉ(dL!=ɘ=,̡LQԳ)pPCI>ڇet*@]p纑ER(R F"(>0|>wP& CÙV.з Dczˆ@0&g+ұk3wl";+9#%m9tE9D;`r!H uH~r\ v?:h1 >6 WMxW%o;8xBcGeTA}!LI܋d%\595?~)pYڳ]W~=EoDpIɥ0 QG ٴuJȯ-?Izc. Qb4t:~}'hbE#ʃn I)_hgԜU^ c谟X FXI)Vξ?䮕2 FөfTwr gg]'%'6AuGH_5ҳU& fVHvGT|[}idnuWүkMc&,Y.+ 3!}+gvZ,Cଖ/}SJhVB3ae4DOf%&(Dy 12M)yԒX0٣&/{m0StibOh іFE/8O~>FͲ ' }>$ sIJr07KY]G NF[x Y9f eRZ9X8 @1 KUTSeU ;0 M E 9:=%V!$͓0[]j2(sv9 ChO[Soΰ\ڒIy ᭽$0\݈ KteÀ D [wv!CS tOWUImfޒ/\{`a1Wv@?uO:roxlsǭCEUS+${m^B&.wV\i#e}UHXS ;FTh=EU/A8eb ӻ${H>͑kgɹ_\U4n= tC[Ba5.f)&7Ƞx7}"l: W34=+irя깏['vP%cKߡXީIY.;Ul;9ȟi)\=?8'H|?cz @45,H5D(sDY",u/dyņE &QtgYMEO,Xŀ QOaA]qq2fӛJm%]+lIh6MՃG1W'$7cPrPFtm=IbrdВOahjN暭as5;б%FDՌA^$bhc-_.^ct 4ԷOL Rk2VF黚eD+ 0C P18]@1nڬ_n^4XR@〫iՀL|3 u^7G pk=T ,4N_VhV34/3;PBh) UoaO'J% ;cv GKohUdvq|W[噜W^7mݏSNM+NO3=,p ukϗxvM:6CWc@$AB|xi`0gࡒ46%y<,V)Ik ǣ0[}.$u@xx⏿Ltwqt$az&8U68+zNm{vKӌܧ5:'O{ 5Ö};sxDh74k*b4s&כhw Ow/ S)A=% H*^_GIFɗBEwy/Sy[V)gĠS -Ķ}X~؂aCf &k~ERgQ'_3Opz؅S5R, ]k_mh;x$`nn{->1/[{ϸW_E_pe@PdjQO7{3XtL$uH-vkΦZ܊_BUr9ؚoB6Z*E♎y$:whȍVQѬCFY(6b^V5 zc*v=wDCz{K(s\D$FZ#lbO4 H=sK ћofZsblR| M=槄[d"%oE,LXc]Uկ"b#EFa^\yhO:Ɵ%id,/Svd nRf~ǒl3>nZ%!F8vsrpPwDT挲bdXţ N/oh*老51?˻!M);嬠> d0`yC,,~9Ft(1ࢮ* PneWQU2aPYKpxޤJ5xi,Rnlѻ IγV֢84w;9A@'0'ȩYeɰmUxRQ$ӷK|P2ʮGA4É#/LQfC&O׫ ͩhvG9 *`0~#hr @`=o/^+S!+=x4*j6׌Ӳ>&i ȩH$4>̋ܙD ǖ]xp2cJ<%XED7& x|,\u Ž B[k=V s9+w&\3Cc'r&/* R%*ZmFB\+S٪&A}ip~y#<Op+wVh6 sHbٙ ?k N`Ox%toC&$+d-C`l$0>Bb9nj'L rd4ﰨ;82KOEw[lv` -9|IG^+=ǐUgg$2ce<+^7P8f.i2ՄHղp bugO RkN=vʛu!ӊwkGk-a罷:ye{$42r Ł2ud&i*zʥ0BmN &,H,E㎐r %5?F-&t-b^<|rGDR٠޴orD2D1\V'c2_d58)Fw<.LxW|K*PHe(zڵURZexPkaKoX{2X"6e䑋ӎW-Wm\ ~)>B_\7RO褍@ - [r# RyOzyM,zc \k)S;i-lH|Ŷw@0Bݦ{Ch V Uaz8fOzBbdyw;au^vp9KZ&O`aWW Ǽ,Etb ԫ_dMsv⃰N+o[HA|OJ+lr`1nJo:^TH9i}6 $D"jݓ'${F}8li@7u.X ǖbvl c8QDX-H,j\gݳPXvjF|]6t_ݢ$usBSe%y>h84ܬJ.1caZH"K_DYo3`-ޡ=YЩ(/98$.-QE97RBt1k&Nʖ@Kͦ0μKJb~Q7߈֛H@AĨy`44:ݓ~üp>j/oo7L\7+ %*;!:۫<}<-%9F%hAhe #mZq lm"|֗B%d<֏cg.Z]lh2\4/$e%$HKc4SfWϼ&a." &p-wm=d9 7-J׶+`?}>iJwix ܔ6=a\5jB ;'۝2v6'D5c#d$,g'KBT*o#r6eƚ@9g+]Yc(^5, z&bOV9([:bZQ/KxMD7sƫZPl4X<謼+\8|૚I@7^0^U}j Us5*ařSl~05+Q@B6(K$(-JM{e[bu1'Ova<+ - µ^_6 ?Qv^gjWzp dD -f`rbsomxSEMjD85;J .; f>$0 abQ ^[M{۬Ii#c|t.6dE^*gW?,72?ƿ5i8Қ2"fQ̛26ngnZ? QEeR_7UalYy?j~r,{0#h7A,X6PZ36#Mԋя C:vؐ*rg_Jƹh׎'눊f$N%tqsζ8MZ{>:If #1Nly^1p/L/ʗT>fIlɚu [UtÄjj#5-ex<9LdB<;?`5|&;Qvx* ߦa!#Y,t6 .F_?\g&>5ڹ56xATAk8K/ֳ_d=+C4 S$i!ZhOw4gbdjVh"I%wwHy2-b 2  fPޢVwqWL٠P|2sT?/{;9w>Io(??9dƝ0^6'hXx}oЬw <*9sQXz0YͷsxiJn dxIs[e1BRPmAS^np@Yed2NUudK,1,).U_,ث Ņrj\ =m>JbmKGֱ7?nz͘p2R4U#gC>5+Kqq~Sc pRҧ L]gma 9$d=7 #E{Seu[2$PGqI2!q=pyB#֘`5ih49*rOk>I7f9ǃ80USn2>-m-1vzeeL~8⨯wqs ;Ic"-$?7'L҉>魦,%tȔURYgl5Е)l$ iE9^~0,y%|:jo&^T04mZ0gSS`DU"X\D *ᄂQJo7+gق5?,4wM P8 XbS6Y}'h;O@)W<{ ?vX iPqӆ&,D-$&*j= 䙈疧ҏb. n -6ӂ8,7Y֌j$G'}f.oWCX|4v6&z﬈}i)7kU$Ka<:s調v(iv"CEv 14t3{~OY+-l:s𼛇*t?b=r#\P1@C$pYG=,ƍiY  F VF14RD<qq&*kQ3R; C )pgimm>j _atlʚI1Я]{Qb'5(lҚ#=TXE㰭c*-3mO{ ~MkL?fL??[esa:sH|qaRГ[m]&1A.HSH8(2+eRxKvZ]2yEW=7P`8# sz_FI +q RhQɉ yS9I#L.޵BOlPI[a)qsQF>ʪ.rP=5ء5D- >j{T|)_.(+}@ʖr%ufgrU֤#(yb,OzC24Dⴁ-|j 9sm_ZK \z7W삱H51pJzZ t9h4dl*̳4M8'/ [ZЀ>hYYuw Zg€hzlbq}JZ>sIr ܞoGS>DmMsۅp}f;_)<jUN_Ьb}/fGn*j_dƤQM}]׀5"In8a?NW܄j1*NT*Fjd 42hECUAbKoƆpogٔF$ȷHBǽY"9d_Uy~^NS E̓u)UހVu‚y?GAjv`h Pt鐣%,Wb׻ϚYb6ͫEE?cP8t*ʩUs,#Ť#?-6am_jn-cjj-~e(ZĐM΅@2%yckM+'FTrL{2t7YY۟|y9A¹yhmJvy}(h.o |k^Bȕ{Vc $E72d=:@d˭Cb؛<'g5 P&G TX8yEW3K>JiF/r,,v4>0qfB\H/a|>Ϋu=Z"׼)6V  CܱNJMu^}6LB0ܵ[y1[ z݈tci1 :(ltw&&@z{䇙Xj3|_B| 2Աp]&8,n]2-}Ntk_*rsq1F)4Q4Td̚ULRtcxEΰoY O0Օ)NeXC-@1נ]wO~\ p hN{&p/7oђ(o!npllC2nt"mw1X LH FBKJA9'UmyNw#xƔȾ (&[RyŧȈŖN{xg5l7O\"!,+ł]ad{)tjjݜn_?9bhA)Mک(UTL-=L{=*LwDU"Lf<YJ-՜iy(lb)]4WY7>a4}@&tW<= 8#LODLqb_M$lx:-p"O]KV E,P/`Bܸ'O k\x7=ߤ=R|'DS C}(Q_eWDU#nkKWuIkqħT`Cfc" o-AunOOh{O׫DP 㔏ī]0ɵcy'.B6^T–A`9WWC޶AnĖ`\猓]O0GRRpeg"7{u< ژ\?ҰVᱱ++ ?Wr\ՈT }ד}dU\[}l|S>rE_ ߴ>}ճ. \768uɎ'Cj.n*D7ST^?f)aGt:xK$P>laB*]{lxx"‹٭iͰ$Yß)wd#@y?>qG%>k#ܸW PKLijSBMp^Oh=ّ5Ko$'~_q͞IP):.jO5@YY7Ȯc$qo'WٶO[_OXXvH!!w,$dQ,-Tr sC@}MeB*'\4ȶC[C4*q_blݼ] y۽`&RjT=,45X>}"R@>߈7ђ 뎒Yދi=_|r hJzYB#Zf4Ox ?omi_6&7B(/prt{O4[8&=E68?0.XtuD:᯽Ȳsm Dz?F)E"*q)|oF}~MsIux(#frj/#kYYQn7ͼtH{To|!Ha]aKcloV[#MK>/~y+'>R>d[EWa-EEHHj߂y7Z 'WGvVD'o&jP؎c2ܒwZm0R>)^&?"TU 8ZZEv6I9 nE?]*` ROqP. ⛠B~vY|oYiY ZjG!1uv~fpڤ%g;͘ b7Ǡ/o8!8 fL,(gb[{1qq]st}-;nG9 ;v_rL\]_7ATLr NoG*Q!@/[q@R;5l=.ŶR\^+z %w}rcvK#"MҺ8Q#w09AUvNş8"5ov&h ش;T25RIY9ҝ;1Ȯ`9TjD{hjDCE.)29Wj>uTۙD+.Dٺ%Ο\ܧC&.k4߀\9fbȥ-I6 S#cD_CއLY52VA%wp cC)0#l\*n4%$ qD; ,to9 ev-޸W׬bV_~ tYH?;raD8MNJD.{ysUbj+!:;nRȠ"JX3}bb nD7 !+%20sh]^#ۻ͑/ e:!a f{uز#{C&XͦS=) :꜖d_>g9lǪgx _&ץ 6 s҇҃AKK{˹tTt/@q ZZE |G%tǐ23OXXRz)֩ni8VN]3CGce OZ ;녑n\$4+ &8aybO('2io!5>:5Q,}*uKrÄ6C2äJ {zX 'KߊbeI ޔa_Kb# T! E#LiM6 ӭ gY#=!J$[! 6bInJ`Km 6_)cW~%͎x9?]zBgR?چZ-zr/lԨ jaIxLr &V~)8yh t;[%ضBZa%{M3BIOk0x3t3׭laj[gA^FZ i V)K63N킟KEg|Qj<% aE٣CZXf GMlTa'X^Sʛ݇"O+6ھ%ϩvK= &35+q6{Kr_ٞ(:^Ttk< VJ Y#,.mcZ$*,`|nt?k[F[%S]Q6_| JE-R(s~^N1_) Lcs?c|lIo>FhψBwhabɰᅦ; rff9_Geo P; t uaR SC쮭ߟlQʗڻiEglM?Aս0ϒ±lM\,[yC^(T+iQ}ZЯ|5]gnΔտa, G)ʎ}J딳 MLqZŌ,iiB n hF|V^ (]؛u8 tޠ*qS?.0"5V8 _~e iwձBn  <eIq͡}`̊2Pҙ,\Eec:o\|Fj '.oFz F4ϏtL5RkTiv_;z˃qdDP{7{r3D¢ҿd^0x* 4<)O&K]am-NԂ q ˋivKSK8(BKlJƑǜz|E_~Д.%8~1FַM+u^-=N &m)(PŃR[Z~Zu#ڑ;Hi"70Zګ|X9e_X:Ћ3)SԖz<g{/^mpGNpE% Q*#5S"afMz.g$ ";a[7R#߭L1~.'ˣ~49i5ưf' OdXݮfS@V e8e(qYc(^_RUE2Og?}P _ldpWרf*yʨ@2sa6 \ep(xH;앛&U~_ux`)ҹu/1qaE!M-w( 0c43+P~]F#fˍ.jlG AW'l#x/)]D}[tH9̯$q!`5ʩC_U!9k3zbR7i8@cRa{ qx-tO+FM.+\}*65}sa+ZXߖ {U?K'8c?bH Zp~#ԀjYˡC&quL }DlJ榑ל)'ɩC4){a#}7kՋYUK˱oϽ%iBze.:8JTHHlE8RzQ@ ԫjJmQ%6utմWeο8%O8pCj92<WM!2Oi\ s0 ސٚ*0E]lp.TC:(;R/en aݸ)J u+[p^~N bI:ڡ'JЉx]o(6)$2t,I23ǒ+3O:jV3yZ8-3H[m HK$x"QSbBGy*6\{Ϭj@bC7'YdjИS>'s8Iܙ](*nm۔JtЀ<)DV54O BZ~_VZ۴nIzˡ3WX޶cЎ:Ef:942۲C9W012%זJ<:n#v f.=haRFt cԣ[V fnp| ̳7lL_ ҽK_1+GH5EXҎSg&k: sXfgu*[\X2?jYo%Hg2'-$ד6dR(BMܨ pDR@O$xȭۢ#VXTq6< ?// p1fG?YHN.2'u!rvNx.L0#'\56_tE6%T&PӍ2/?x"j$:.+[D_ 2z|X]sۆ5Apm :v"F dGBahaXsD2skʕ=B]J?V_F>I5S&lkd(OIԊY_=SPV5LDK̙KZ]B:1/J87i oa+9Le/le5sY D"* IaK)jFP?/,2H` \K9EDiHwG(@G/1;Z4҈vϘau O1JJyOɅjusCڕY_/0rDUrJD(h!Nodl#“YꕟDuѢ1SB]\ԧλ!NŢ 1Қ6`/bX&3qp\QWK?zOw eK J-!8AlBOkm=- \D X`k6xW*]ޑw!I0 i! =CstCM7PQIm#%_' B'as&Pi`QX+Ue6gMg mzqc^8kZz-Ǣa>HWBe¡8gTJЅc #sHf":kU߈z53rp+ZT& kwx`ї͑KDtE'_BppoSy3Zη}BT+ED QF̘#y*SА_>u=(w dƦ<5mI|ݳKbb*ia ԍ7WD@kVIڡ͆#џ|(T,>b vS gv*N:(D /Sػ0i S)ڥ_{bZ.Q+Q>pm|yqT/ \Z5oxLDңl~зr#F&DZfkݭa>c6"=@/9+]7Bg~9:8RiHb^\R=Cyw.A~-qP qԪmcրm\%E{j'9.7ޖbQf]Yx\\3 ,~د]ŃߑiO"ܞR䂣d@{ʝW˃X;hioMV疦.l޾j$=&HTsVd* UXصV kQ'ue\fa3Aן=`/ī"#|@S)Op$4^DgOf]7£â@ɿ+ q6_~ѯ\%cmQB͠,.B}]R/8߁DԲCG|[ &q\Be' 𥷄:>yqx\$uyk> ac@ր$jdt*ђ]A!1=FVKza oH+ oT8vf[mhGQ' @3L "y&=M@u~XNsJnT]XC8Q''p7JI(% z00=To~W,gwsF&=N1|@cLfgᾶ3IVY' {<[j>w$V[?)VYWKB]6*AƷ"c̳Ϣ޸G8ٖADd:hfLQR ́@@+ۍCx(|\f SNj7B˘V}ƾ՟\Lƒ2x :S%`7$bm5<-#Go2h~J8WH_Z|tqG ZT7X4,X?\K7_Ҷpk<3!V mw 9>ȫcL3&=V<2>04=b8u5% B`ي(%)pyǴ'ގ-U͝$؍P7T'#[Pb]PvgAv2ZD1'7d0asEBd)e;kaMַh͐fTbhs>5ls3Z \tsZί =k~*ﯪw b3<%9O?dDؘL_K;deVFXa]o aݜ.߭,8-FWAܷnQװlyU)<, fyG‚uLwDv`:*B9QLqS菸ڵ!HtS嬆0E2rԦvUϝ|EhlvaH|`/Mþ6ٶ0)T|.G?ה-ݶ1Z-GxRAvxޤ}m[ˋЫJKTzX3n:vmwJ1n-ϏeAIb✎5xny6* D7IXРv s|R-ޑ %$"`XLإӎpIdLNb?=>\ !@tz0Zt if y Cd=fjV a5Y:UD$8872˧%#\fD(R2AQ: VFiPKHLa\Dӷ2s pdI-`s} I;UMk3mӣDWT}`s =bl0;;#g=# anp~w[Y+PȄiUÙbH/͇24m|Ñ0ߌm$=df4lŤLy02@sC f H]HVm }v3nOhj߾r4\f d\`yP!gg-Fq? Fj-+%=n#fps T6 7wEfMNT+߰=QX ˛bXNPx* G*jgv6"89iR@Mu7K*z (/X oÙ=\4=vAv62;ݛƥwhQfjF5j^ 61xpir42Ysk ߜٲJP))Z \p_AFl{#Zmߦٳ.p#@X~ejLRn_'an5F Jς$a?>=BI!Qj*~-0{8d/y_CvOюvI\iiMڸ"!,):i#"?~$ v/JY9{7Qd('@U/#kﻯl`bXKCҬ3#>X(T t |bL[wI;^X\,@A,e3kQFˤ+>Z^w!~EADD$k\憘E^)3&yJ"zV~kQP% d\Ag-|E.l!r }*?TPʹ* SZ_z=0y&Rv{FZđƒ].("l~$ r=Nc?yѶظIe3pyKMh?cc&~7}4P&DL^ d:EX}b'äx@^3IOOhw] ۊz`B(o*Py9l# ;9i`A& 5fZxe4~gNHhy#о4iT+}P%;Vˣb5rQNVD@i6G= $u$*S&z"EvQT¹C-!PiZ9d(RM] iR++F.@k CCCN2U?Mq;r =Y4 JV$4vdV y]D7˹K=~#q.ӝbh\1B`%BЩ"NIa!5xPnk}(,p]k B5籩QƢv˯Su(S*4Bl!u%U?%)5ҙd]" ,aXQ$VH5Ik~)].[1&iռpv7L8.hQ}9aoE_n1ق 2/7_cbw(l^Q{j;εd FE/$Ŏj-l՚Zt6E F̽KcǸ|[/-Y.)z%3wx0{٫7.8Y0JNQu Uj Ay21ZA`JS)"AEyv4!䀅} iӪ,3 36:${4uL!9oD$$֋*F` \~DĎdi9yx+塗ЍCOzWAjN]WtOY 85gƗҌ*CNBv])3xTLأj{t/C;><=UMB>zLkq"k:9h +, 4« zNtz})SEz@#'XZG M@Z(co)$CN(H@^sW5{ ,%c4xPB(c3FNN'6'tfj"۳%Ed*q |_ofFάnal>*}k)?uV̄ 0jB"C )g 6$sM  u$D]א:I7af"3I=8! [+Ԯc9nb>ZlT3TXִo7dʤ4m;f)5'\N ( OuaEV,xC8a86|ۧPb.>\5tYyFoVv߈)c;2WQ$!UXb>2YO=d*hu>wc4^zXkN gTL  }Ҏ!J3=bTQPgG i=R@'e<%C'j UٸO)K (u։`!-p0<3!'a?Ja~ATGWS 8v Ӽ zeo "W^E|xNqO#+mS.qz7bXoDδP/7ea,a76e9Ni\lY0Mf{->VMl{j,5/삘b9ivH2ڕtI%R?U z'"%@D8~̕ mr<Z'3As')eԆ@tYd)YN<M8ZЦ)!Y6铌# 6f.$x'} 0?sԃa^ăyTJ*sp?"JR-}d}^=ѝIH;$hZ:M$&>Q96Ɩ@N[4,-J lEM]x;F$n_Rc-Ŗ`Zl,Ee^MYܕF٥n\A4Eh` t`D1[zD/wZܠ]?|2tWr!W( C|F3YCU1nt28G\u~lV5"BDrxz b\([87/ <Ӗ +Y 3f\][(lx >Rԇ jE^!XhX|aw EFL7˖bk&e@+X mZm7hn>z =R]מ MyfOؘB'Q\OؖkH+8=W׊}|@jKJ9k>LE@XS#I%O(m 2>֐ΫL`˸Ų !%qpv1Raf U?^o{AoBEM2dhOyltbcun,߿YeD`?|+7(O"vr=o=1ٰۇ"14 @We$@2BأooeH@""IӽؖdcLw2ȱQʙο~xgP"$ vW`ªDsc?]M~Sw~/:_En 1J,Nـ1 oBnuo1{hUg케s-m=aV!4rxQ`s'{'}29ُ<\ץX7xYvg.t wU:sދ0sc gɰpJt)upWv>WnɅn%@Ik#*⍥ZuH n{VT3% ylc4ޚVy+9@,"dbSLWI/X]L:-+E2 w:y.+:vʇ"3)vNd[胝I=A͆-Ty~Z|MDW%=7{rUb Hr],@3cՆ݈h(EX˨VUY< *X#AlKmEPn˞~:$ku)IZ e5MR턿 ]*jpf~,{H%{hكl<R5rꫲ\:\gU,w ݃(8Fmdw;\zU jvj\ot!A̍.I}fDDZWkY8&tKā3 8vFp34Po_)EQ}V}}(MBDw 9L6 6thKmNf|T# 2O'!2H45KڍVnZ@MUsB(2ʫQj]6MxIO1i뽫,.oIF 4IO8\D"os,,%@GP4C?I<oShX˘3T-/}%ֺ LVY(F鹜_= O ܷ Q 5UUj&phϝٚ"ID-s//V¦QygG'tbe29]2,iY-i2 { ,)x#8C_k0<ޒ۱sXW - *1a:z)K \g[ɝV?_R[`@ImXI=X!Ҍڹ?* pxc% ܂)7xOi$a*.p$R&m/hO19-buOߣjeP]薥.3NAi ÊeBپy;֨Uefr jf݂r(hI< ,AW+ݽTQ4B@u}K^g-^23(YbP6LGO&ۛ^?Ҡ>* akw]iN5P!z&V ڄ8e t),COۿ(LyC`nsJ~W1Sb}/d~gRoYYZRK"CU.xE@{N-Bڢ rAW`Y`:1,Ip]W} ؁vr 1ل[8Eب!6:m'. p[iu gk-xwsmoSĮ'GԱ'E|&Tks0NvV.{::-B9:UȺ'"ĈPmSHcX#6f2]֧{K27ȫ\k߂PY^˼fO1셿԰[ԛ)Ucf28f${'$~><+·F5/bQxvϨSW®oFpO.6#M^ 6==P&כ9Sz7~@-YpLOWw<0qt,xRqV}+Aeb+Fvg!SL[f7+1-:NԟŴh4,q?3=^Y_DoAVX (OrXI4tnO%g$B(@B inD)>8 A tnA-{s{,GLeC+23/}$E0@^' DɁ[}stŰyys[ |5j\y}}Z, ꐄ]b܅$Xo[ьtvs|M|~j#U,)}|.PA:o=;k25Y`ʁiXMdXX w7 {%^[8u`M{?=ӹ =gѣҎZ0y V:;\NCY T=jRJj-C\1\&=šDs˂ ʩ4Hӭw: LKw=W*-0ɶxs4uO 'CxΤD ,^| N/Zv!r{S4Z]A2@y^i lX=x: =q!)90K#0'5^8?zL@aakoR]+GrI)fgg5 +ͣ>·J~m4&w#!+ʽȵ]O#U~ w=JV+,j(ki$Q\͏v`5@=?~2x+l9(6Dݳ<ݯ^@#d4!G_nfB<'+q}wHc˅J}?va7[NMKL2[[N8AwLG鞪x \2 EjA1ˠ7qX]tM7TTN\8Slh0VJP68>2A25f ] SM@+Et &oy5xEsPՔt߹8Rzʂ#`ݫOF`zīqݢ^U7ځk;=/g,VYJYb¢}ي(?1gz "XK9t p`C;u Gb,x LByXD?T|]϶蔘+fd( xqcb0JhlpŨ5x}V׆Zm98gQDIΓfڃ͡is'\ۏ.3Ox>BX e\F\ ͊,h:Ѳy` 1|[̢yx->fysCRf=ۚ8N9q2-0F n w KKِ6ru}B]l0.ᡅo :uTV: aG]pz(Z{ AaYopC n|}γ^4缵UD?d̻y8-ͺ2Si ᪀kzD$"^l^kI:0oC Aiy׋5S:;Px`ޜρHtSTk{y&pp9Gnª=WيF˻=.ZZ(D0 ~p c9J';"2XU-ȎS.$Tk"-c f3i?ZfYL?+:l2E& (mJ#Zo?bz"`H1N0^0_ȍLxLO<3vDIu󐗲q::r z6Q%yhȟ9!.X^$BqcҦvRA"}2.`A ]#,_(roO$1miGb)Wÿ+ }&e{xJnjdd+ ,\ [ =nISUvM}mMfC2Pjs/6xt >Z2>\hw]cu8w6v,]޺ 9^3@X?mK00?pϧ[0N@DMً?(=f§m ۴t&Au(&6L%Wq: IոVp4*RrI4 siG a$wGX,,Bc4' *mqv_a XՖ9jަˡYˤ+{ ܄*%]rfWf`/a>͔K7䅭8kZgՕ"t@ʪ1PoCgM0SrπNdp;NS Ki`yOC L1Ř'\C^qߝR.;Pw^#GYrv_ӑ4ߐ[""rSy-B^͟H(uO"Fon|L|t68~P8gÓL(emA<5Jݮ64&TiHoq;AW,XĶ1Cte,:{9]L.ܓUMI-ۖR9Aχok^r(%"qV9uwCrvRHXT7~v~WvJq]lBU"K?˅udkiÑ&: %sHp ENfz_Ƙ/p}Ns :Zlcs!̛*Ai3nUuL\&YoL @5߃b\e }'?Es1|2Z5:+`D(9S.K$͝ ND.Y noe7=2B\ @H\>wwdPL;M\ =i%}+BQG];Hׅ9ߺE aecʸ*iZsmy%: +ws)a 19-8@msR9ًAcx<s0[KPWc>Լ5m=7LɚSK3^W [;}֒QWתΟ_I5S'Ŭ(>9`]fQdO1V>}I=||AVmbس|L$Fm;7?؃]3{ +ڠ0eaFV/z!r12F5 LR94 z5I"+X17Pfҽ|ǷeGl{g'׎=6c >)b1C,,/ETTCXpP)VcQ_hꏤT;߂&r^'K. +zZ_T@qlX ïyeLKU:ljAlأeRF;QWv&NdVEfx-t&Q%'>3޾TaԲ\&|7ݳgF7e_Fۊ|Nx^;Ey-Iw,1 H+;7/n)H2eDBC\<ձS2RjRj QYPzw„fZ㏙OBK-u2jbldF >##w;@3Ȧ[4 DS|ɼzM$<,#++kɦyϙ}$P'BhM2y77rloؑd:V v윋38Ragy(ϝ!(icWE - I͜"'MؘGKE_Sh?حqGJbPW.<\6HNd>0Al>=sX[5lߞ!, dʎR*8wIZ| $0U/mrQ2muϧ3-ߠtQl1͜&#J+Pt&{uqVԗE,᭛TQi}q.1 yKYiګH'lIdzn/CvޓhzNY-wm{ϔ7(-+J9xz~x|n~]/05{$-fM&MXtx~klBf.#HD h6F&FIa&U=׃t֋x1yGM75rxjN5ZLV.z -.MoJn !(*'0Q()ڪGZ󱚬wZL>r#GH66#qϵ >KlrO=T{Qr0)9]> *)wÃ皽62q`5Sh/=LM*QA\4&v&_ZMvo |A;!ERgɷ$Z\]bZLIa-̹::~Te#Jhp #O&=dیnq@'3km}SZa=W&YK].Evg[yUM:UCfV:A.<o&H_fϐ/oŒ</hu#8(-xJ%F!h87wtKS>Lp=X!m Y:_}Zz+gυk4E8bt%gử؁o&[zOyXomȅBkY Ea˰}T0I z0/R~Or;ƞ  CK/>Q0Q5r)L~{'Je%k϶Nȶpn3!'NpA1I-Bu0܍سLO<¼^§e,2VipJx+4boyNewc?B_Y5EQįPUU'n'ӄLy|N!s[~USB7Rz*!\e&ye/@ٴ#Y ,gfgú鵾P&~݊i[ TolXFS oxޱ~!g8AˆjP\`L/S:Š=Sj%H9.\ L0[ 6/y8e3q~-?kAaYUH2ON׎hv Zb/֊!v"Tl6PE$6d<3-ɦp8~vFR,š7o'). ?D&B|^W\)t.Nbʑ$mww;C,wCQ 5kncBj$b4hyCtrH\*>\ĹTgV/ OY$ ~^ig*r ?"s)BRWn޳c½6,@7=9J ai> ͻJ!.1~YrX̲D至83CM@L{/yz O˲nʤy9%8{5iSXnrK7 #>Ill jb @Vz .ȦR⼸ӗD{Vsn#v|vaiB8@G:E.'/?aGBWcdQڦ~D?$p&,*(X|Tv۷{!$ߘ4@ZP(먭YSPnU\mүtҸi'nz+be2ܒlԧDRCQh)i¦2^ꅈA%N>l7*O0MǓ<졈q{BB:`0c`-FD= 9Jӄ{yHw9:3<{6yjh%P$1ݠN|'2rpr1`1OV)$Jdy{O3q,4,]2>:#_o* $\ߞl8$YSXMsxSY#kC\ÝS#gu*/AFSB͵0WFs#xL%D^ǁ^k{;Z 7*(H?DarCa}ql*" YxBzueS5K؇ ӪL(uMO9 Q3)>,?:lz=u1ܲ}W{L,/W4${ a|^u&-AC|*wveݦ28\=-*('Jف,17܇ '52GCX_: D7j.σP6Wp与蘬o:L;eٵ\L`2xSYDvHP۶ ,ʱ&d knE  c,GQxOK:sYǪDLٽ?n`C 0 ?DK *.\?R ;dÖh(+kV@,cC),vô ok_1N?Iip)їUbcǐz>0#NO?IwځNQ-@^b|Me 8vq>@EӓJ'[PP,[N4>~4%^[ gMӷrd zƺ@ k3=5}-mج!~kZ͞Ox1b~}%]t7 FU4}-Hh_YDB9-FY8.Yх}7iK(WLggjm3 ~=^_]+c+F@}kDԈjv|H98CZe WOۓpxvu,.raDA(2_:dxd2+'eHQˀ =-o! .z/#Le `{;铸}&6(!z- #;%ȃʆD}JT%zQ˘o(lx}1Wezၶ$1Uee<`"n㫍9ĒjQ(e+$e[VOb8^.+[ո;0~bez+N;^dځj[oˆ. VAanܧ-{]eŸNGeZzvr7Dnqa$450xy  :E/pb_z鰥E!9. /Ԑb zOqwŅDk `mƱ$=ǭDp9669WmjM-n-ց8P>0u=70B#zopA*٭j_Ͼ#Md 'gnKٍ1]:cQd떉 PHM E&ʧd2#/M uɦ;D,9GZ9v&k$O-rлzk'S?e'![b.K|݉v-}%[4'Ԡ|R[ߚ쾯g+ؼgٸȫjqɹ1Qq멂fh)]L?(Er9񈺆¸>y_u{"Ų3qr%:z("}ȍQ`Zl} 9c(}@׺h61yERcc#[>DJfwlz`n2_vmY/OaۭB$Yex;NYѩ!7s"sdODO gzcHa[fX 6'w::GDzہmSe'YI/M0ʌ';jUwͬ7GۄRh2k gLbEMЕK1<dp{'F[ŋgc $0.>vV9#_ uze "wұ"AN8퐯[)qÃ!\ߜ;']߱C}Y(5\Gym5M2 GuPr(}MEiQtXP4(>2h h=(on5TsL^Փ9Hc=#0IO#R5sy}ao'ϗ=l)p>)wf w7enVZ_\W5t0wN?Dq)#},d[qטSڑBmfF9sL\h^;RZ8"MK j9v8X^[%]6 5 A?X!brX&w˓-~D4+I`Tvd-bT9[*x9Z[4% `ba|\v;4Lǫ]AJ@\amtL"Gf.8?,;)^%P'Ӈ`19Mxѭ=[O-|;?bV'~ѻ0Êj!aB-2R8V6 <զeߝg:299N0,ai1.<S!+( (]zȲe9D 9:YR{Z &䒙 oD {hN[AZW6AD2t=BTt<v9'zBϖF{ njJn:∁#Ǟ۾r?pA45rʦ+I~`^YDOH'WkJh+nܩ..hYk(I{ZKs^RS8WAo(z(ǻ`З\T1WנDRv5/!&/N(`:OIj Oۮ@۹1?D@0l A,ٸJ,[गE%y̖*Gn&T 7J/DwNp5Δ{cܣiy4ǥU@Z΅i1I̲K%v"VhPjy6(c'ũgW(Br5]0a9PԦgrK Of?S/鈥|j,(#]{VOWf1 B=Ҡacssop =2hft6dc+ ȧe"$Tڹ4χXV-^Q|W1׸; 8(BpYmΟ)~ ݪ7t;6f%9> _a| eL{JTEԘ 3t~}qF/XU_J4qT}:$RrFL'9Vf}(=*^jS°&`8+Y )V?2eU~ۅ7"F|X~qٖ>:̲ER=>K s("]w|ٛ͏J˕!#KN|3&X3qDOdHQK=5ڦ.]8 WF` lUJWQw#yD G3`:p3G *ڪ#I2x.m4 ;&+91|N:LjVbwl n>FG C>[zNC1[,sw/%=kUe*pvfգfn$׺: ZpQ[Po+%:_#cH"Br 3]+I5t |s%r_k>B(s;MцetsuuYq@ jq-h[ob&bDR(fI悡o64~N2񂵔PF/ɢ@pFV!Sod uJDohX?3)9\ `n[mQp@8xe ۵P)PPZ5̷KF$ΰ3rh?]`gL(/9cΎrR36 )N).cCP}X%)LbynK݁`7UQ5G @%q2HVB3i_ROX D6KDžm%}vXWyDE!''uF{|@ O=VWzRQR z~}SSm,;3K&'<=CUFwn7_NST|YSQ&"0Ueh/;rIlԟ\ %' ~2O|?@>̙3hY4:_T gP[M#V>õ f탳D5w9\xtĆ>1'wXЇL楗Z'9-iF`RRP i >s"ZXLַ+;}̽k}/ X@nymǩuFnSŏa 6 ;6qԳ@?Yn-L6/MfT op:R]t|?RYҋ]$^@y3 mC3.Dm"1W) 5>e'wQ}bkGwK^+ `d~< .FBzi!7{#w?ƾf7L t $`X"SxZG26&f'߻WݦabWZ*F4}V6G9e\<ՉrY8/x'K< Z}h4] 50fQnfRU3 :M!<
9ʳd}S^>e}G]K&lܤ{Fոig}!ہ vB3aԀ^>Y&a.'GӸhejq9#hw:Pk2ȐN3UdOƳ.S[SET0y0$/Y1ͅ GvA`56p؂>D˜}:AΒ"+*l1|-ҥHgcH Xl :;v95Ŵ۱4Boڽ3E9a0ُ^V bc `YM8YXI?&eC'kCω;v ;یo_}4UFZr&d{'&r,zȸIяIT/^<\D@"hmL S#Zsv~jRs`$ɜ ,Mx4ꣷ Ã<fBw%su2M_r>R!2g/ʇߩFRb'*Go$_,!Eָ\lp`܇,/Y{Ta>nf-K0PV]77a ȃ,?{0s %}$;0n/ˤg:>n)C=!*4g89id RGD j9D:1|}FT>I4nk$ Sܫzmrvsõ۰2_|;B5U8l\aRu n;Z^84>E Dv#6NO`銛^*.iW` ]P1Sfj_4#l7[9v@b6"fThl.M!iW i]vg&?&a|&ȯ-o@PEǗ WRh̪]]ױ2GoKJxDsXA7xay*X ) e/ P{]F4 qh^+&wLxsMlnn}^JL bؖԚM0}V \|̧Әsh+O^V 0ja7,.RFc cEMhz,2tL'mыUV͎dYF+6V0) IJEM/6?7 '6?崷 ʥEsJDGb n%@}lQeMY*Y#&\ 1007(e|Bբ{*> -O|2[uiHaԌXh~t278fN˞~P]jvz]h2֡=TT-ӽ6?9j~#_ON%NX# :j!ܠM[j[2q; ]cgߞ M ӱ!#ց}%UKJ@:RJ3Ӕ58 wz wTjU`<UNАk3N\ Z' ]dZaW JW7} LxEГj w&%hH´]Nlz4xU1ƒ;̔eZb2HΉWZXVN6Y433,cTasPR82x`(qm|>xp&DE?|j,D)9as s o,v B:9+rTn eM n j&2X+;LJQE/؅{K@I klB.{cU6z&-{f5"T zDDS7Üߦt2*sPw 2 qGMt~pҿts26/Cg9X_̸`ʐoI Y/Ԕ>+!yתȊY`9u܃ C 6DėR N? de.֖vXgJ,3i~޾.!ez0p\8O)^w$Q+'Ŷo{ MLVx6d"'B i$`EbVSE޵oˏU,}[ᐝޯӻy}[r~& $HMA_Fd8\ fDw:$N4d:m(Q*e;֬PcW(e7ƣ&e`Hs\oRFU?Ӏ8opnse"_[Yp@9lj]yI2SCN JVO,$d3>9_h= @PHE¼jJmTF"訯yϲϼS1%@!+>h6 UZ2Wޗ1a7SQ}jp0wF5 DI?9ZClZOx$)* }]d)LӬ˞тN 27lٳbB+FRoppUpDr=f#l7^ɍ5iF0a_doxϔxR9jA4A6IEy0QĪ]h4LKJP^/o6\1!jK&[PwqoYw溛.uCIQ o[ƊJ08 blLn]}я>\z ЬeU}T) }@oT*8O\x6-)BZ{h,O2Y'!q~b1Upvu C t8!:qrw˭R cBim)kSO Y̆܀B S(|3uX m+bхIa|2 ԗ$I Tns)J*^}\2@V`2'M09K):uS Ӓv:݉B}(i KM(YJ(ӀP5wzi~lZzXrO:Gr'BdWFI-t':M;`ӱpے@9Cz81.1Ȯ<ܯ+>zLvp)R w/gP:k.oh=@>4r yOufէ.rh=obYےV-vl ET1ul"^ ҷ+RE[HȤ[ݾ wi֬"V1T5le~NܜrA5^bի6Fg H2H"YhYΆ=scNEK`&e\3eQd8֔ BO$Q>2OG/@9xR-?ǝ ~XRZF'(&zY`p= mKz),l}8ׇCR! E*ɑm*YcBq6+[haƮ5&[ \Hƫv[X 61Y6XPf]z~բKCr~1vutu itђ!E *\Ve1KW7#{m3XҴE%?ZǬ25Fr6S* ?  ;YHK(| Ƕ4s``Nj$AX`N!,EU_=L"{򽾕BC`aYZujx6HAh3X^7Ee4 QDrv![Wڰ&FW hǩPǸ h67k Gep˟?ƵG|FaʐԐt <wg[p4E݊2,f{;_~dTKd9oU;FBĶt֗vlJԎp- 8AD34wぇPojzJ2yr <̕1bw/zL @cox 1YlG=\Ë~`V8~ *Dxfi"w}dX-/H=uc#,*m#<}))=TRff85[WLub 05raw siytY?}!fנ!q~//Hi+ף x!bB3@N_~m7 V?."\~γDNc1.DŽ&<|EWlFҾcx]?#l$@t{:'TjPNay+ mV zadBH\l,c|^D^VPoNI7k)ƹ z@~A "K7RAdAR<br~YUv?~ml,Q#.+; @a(%iߌ%39&bv,ѵV )Ԕ֡|@]-V ؁jpDRU19bFV+ g"Ѩ $9—=<;sl-W,U ƏoX|WT@ɳ?$ѩʬ9ژ{Gro˖){6o%Ou0BV/e߼ƽrQP}jԋ|bOjpbZ)^œĝ2|Rj:nu<~ umH (wִj񿬯cx x^V#8GәQ[9"wd*Fm,'liް0/tm`Rqp(Jqu=JkܦȵCӨ ?,sDIMFTݛr+` q@*h:Qo v#B-iMF9E!L3ȵ,FG S&(D!gIC9fO4C1|(_6WOIn f~nHٔ1Vu/\l8"wH~P(pl4Q@f/Lb&VRYs9=d 0ۤkx:]/vsV _iAvFh%· &^:Ԑ%\ڧy~9_=0Xjt9km"C;/^wuJ7e e?_kUC[Z}IcFh!SjȄ5 9*K1t+WwpL$ؕF3Le:v}P#s 2)տaSa Ou5նYeEO<%EڿW[!b]xqƄ1ЂdJ(\Pʴ$SJc;p[f(kL&:T u~J\[j`5\aUCj71j]Lʹ(ϙmQF,# p(͠؏\;UW~HH|4n#})\k]Qce8'恥)Ɩ$w]s4ͿXaE0EZpL}(j$C~V<8AJCxC =k= S,\C }`&ȇ`4VPIx2hwvЄ3/yz,&q)Ml1A^\e~""*| 8'D"tdw80ڔxSZm}a5^rW Y(G^)tU3)rtM:yEmܨ+J U مd/--9Md;Cm%!@Q`BLyb}*SL &oqUwG^[}_,D=2Y̳^50pqb||Vr:t !U&p/`E%MXZ+ Ћ;`%Ak{T^t@=|i⣠d˹;Yׄ^Wo2_(ܜC R8/s5GIM(-DR!,+Ry6&F䝮FɨbH3f=<0uugB#'-Dz?4TP23(džz+w#r'!<ѧ99tvA`q=Z݄?'`˦DQt_,? (oVLQ|?PQ:׍#(}?9Y]c,f=+gݥX3\2]GKK(.dO0HgUφ0P>3FL kYޱ9` ׭^gzz6N96GQ:[Jh01B՘֜;YhB n?Gd~EPڻh-kTDЮʣV?)ߜ4[PvodM.-w?ЈBP03Oͩ@̰f.B"4 -#=p9_te,6=,C &K>1 VGG_ K̨9|p?6)r:KI4l@7FO+?<+<-m) p:;Ϳ[V d%? ,9%Z(^f֑͢NrӁرj;ZrXYa'=䁄׶OFr9BaݷSnN_#<(º|? O2o0Էbr sޕ%'nG;OUbA #x79ͤ1 > Х#vQ3&87cb)|'\{qjG6֬~8)])a/@=,h1nh 1UHYS ȝWea#Zwd*kHHͫICZ>b7]GQ.@2|i69e9=91@a؄\Z4Yف S7A}K$q,90h$u5>H>|4L,ꢥXL bwW\lշrj_h=x~~v#ރYF&psV@p@aHwێ"{ FsqN7]dW}xOv!ty~QThr+}ʽv&A]˷ }zA~ W9sa7鏐M0(""1b]yU'XDp4sӢM|tvEe=ԆpJAB9VRj=M;3@%q[݆t Kf/կ#5ԬSkpNx]$FR:澝`,e,p.|rYJ!ߛmw7g _.Y̡i& -)XbNP D-6h:mno E"0=KrfqDa2sCky* UeYѢlQBh zXkkq2B9}#ά䑞/j q Ƞg#91˴2[4Pjm W+:qa?IM?/f`i| ~p2qD(4kfw[݊b71cu 'NIVЎu_%GN@@Uw2wBN<ՅG'>Uƃ%F6ӱySH/'\%%I{n֠ @_Lb r+NӺŹ0-Ha"O {4)e>Jou[hdsӍ\Gg)<$^@=˩zY vg ,pq"\r+1mJq%/Gj4ƛ*K3y_nWB>sOؔ/e6.y+DRD c!=1lg~.rƯbDrjoC!$:x$l=b.?EOit n+˷/2M8>|%9|R|* Rq@Á3:dn!$K[ѳqNx XB_N^pe= ۨ$ l,.+N}c^;Șogי6/bt!﷎wn%e:0sh$PB7 Z kՎgCn_~2Ҁ:W}؛(_z1埆h{ 3簺)Y ΋1Uq-q}m~u+Vݣx!/%=;h=#>*3v ܚ{t `Ȝ]!n~_8@qZDѮosԊ`K|CF 2uS?x8aq vtxr30"XWzm?%)of~(6C=11:YGOsG^a=._vVJ3uJ]6 *B!YԞYf(W0r(F~sִсFgL,MrS UAфV,C sczQU|:=;[\pJ UP4it-~gs$:!mbO%ABs)۞ݮA&<.I(@ O_MN.f, 4K-3 AucauM>1X,PB,s-}y@+Ր v!BH*|̭}~Hle ;oj%?^9oo-P .DDU*0чqr®ݗÙnl{@dlb;1'tS`7vU/{ ɨ: }q7H7{ 2S:)>_9^~ c@F T/1IwnC@9wslmBX԰F9ͦD9Ikjݑ$ 试"$ CZcQCnZnO֦8+=@ lsA=띵U?= vl]ST!O2e}L #M-'g$>x{[ Úćt\0U)LЅ[1#0(5l|c Gw;޺?_T q]tx810 :MT( ^l܃P^QH~cnk18T+KZ#Rј* =S?x9p'|Jߜ#[p =8ˡ>b,i?pȽsJ҃&~,x//3?fT.Eَ,]Ö.|(_+Ao^ -’G4-e7 2bt.$'F,KQ†ikѷnt?l_z*?[|U?bAjQU0cu%d(|G'[ٕRst09N F$s]2P[iW@ EϬz'ѱ{ˣH #y!svňVDh[h '^C#׌KžZk qY#H &:jᚹ4 $)2qu|A)]suT#J.Ug}#+/%u)W  #U=r:P<0r#}Ռ~1ݺ]ƴs>BP׋{tBV4/f^q-N"H)r:+CDB3-#h obQ,>N`GiŻ<T7JL_ Yt{6?A:Z} O)AϺ$Ҳ x5H$FҌ/?4jKp۔衉%{nDW7pDLD<_ǸgAasov}J$=7ط3*m[lM2-~.am w")=mT` YF"=pXWIAo\ uޗP|M[ޞ7%M jqXE uq7 BY&|ER!!Gn, nOyVw6(L0uI'`IwU BLՕ>yD' !@IcۼȖ=Dd z6Dnc^Ugjj5j;0'd_7ADA+8%f~* -aDNjMH(8VLgW> gC.mvm~μ[\*~Gi`](BFP:@w  1<|.jmb`D>Ev/+dI9"썔_͍Oê:nké~ }$f-%2r#iQx<ՙlvDxr1NiǢ)M@a|.ɷ׌"7gk|y!6}+6L#uw,f뺒 :DW}ND/32ZT%BEnGGH_Dt`騵:F4uG]VC+YlVMK*[*/N sxL"E-eR=L[F/seS7&G>.NVY^-&o"fJ- WJ|D`C@AQ}8?pNp5L}aV[Ide0AHƈJbA]g~,TFjA;"ɵj(G͎z3>`-?aQxhJb=B׹YS%'¦k8 ^(-kj (e@o4&A<Ƌ`(P9jw[ކxU#1"~liCTc.jecQG@Q4eJ0Y בW)09/. Ghp x۟ ?"eBrp(Ɣ?;a!G$'~5B=xn4ڮvڊ(y 2i;y4"njT n/8 0BLDF%%iӁy -l5ed5jjB?+?se&LM(ْ=#?ϼ/"y@QoofC{ºWI( Iz7uTS7a|}v4l' ԥŊN M%SL,iSC$"[eԡldzH+@mZa Xee\'kb4 H 6`X_!tE`)퀞H8n'S {tƇ} E:`JJX.r! ʤn˧[}p2Ȁ";_3q">"{CJV"+ŋ4 @xX$[IM-^r`UKTww(dqk$&D M$a}p̶z뿵ap/n%$ꢸo2^ף+Dp 8Q?|/%Gw4< g_F5/}Ỹum*-d&>La(yg8)X'Vߖ݌cu2lD8 )s DGG#]S&&ߒ9 է˯9]25ܠ3&ArkI@Lk4>`|t޼,jvD"3x]}9Y'hQ`b>+ sn(%əZ9EZjΛ/9 9l/uud;-D&6 wQ՟V! Sm)> Kn"X^*Z$X+ʯA'^b#3l}Kg?f@^+ɩ VH㭶:Ӊ^I+59쑻L|#*/ˎM!hAh؁O݈[7 ƃApdAwXkV 5 ; Z ?n/=moDTw|Ӿͱ>s# Y~esXbrO}D.~ˢF.IX/Rgy><W=S~4@4.ݹXY;= }rI2TK8>B'Eȯ({7Z` I@بJ\x}OXY@ݺ6~ŖC+H}  nH$7ձӈjrB 1e޳E)3sGˊ42S>nþ(J]~)%sHxFxD!eH_L.ƷHl"Қxׄ]JAm4m\ S뭨H\W%h!F ãx㓜z9{~'8RĚ7-fuBOvmRz6Ѻl؏߫S3T-ʘڊJ"Iu ШL49;#^ _*].!!m)t:0BFx,)FGD,j'iRsGhG"h,>">v"yҁ {wa{Vu -c1{jOKi~zA'ƍ}Dh D#N5œlQƨFQ1`Pj)tK*%?)I8#%8t RÓY*ԾaDiD.yM 1սF1-B| šbO\!J@HNw==0!sJBZGf/n1G[=09/Ný (ۻb0{NU%c-4q.0L+(7dѓaOlGY$IDG:4֒%dAsr*Aer*Q9T?~r>-aN7ݼ$ "MG$L5e@R,#)=I]\9(a1mQo‰_;?ξ\*:ȰpUY)ηI@B񮌢ڄ=KsbNԟk|7JW=Jhvbǯ\4煗@NvSSTݵZH|DrTĥ j/Ե&ZuA/~mN~$q~/ҿCY>Z ׳5hq,}>:v# ̞ j,Ze|܄?}v{[id*;ӲtedMxD83)XCֿl<襤*kZdBj,I60H(P}v(2n$Xg9 ə둊ױ@ۺ8klkxEF +PT ٢'뼋1/6uF-L/R!J¼B*@:%Bw@"tMx!ɹt8'Q oWr;2F+.ST:14 _^ 7AN:`/R1 |zO/nh-H&D{' WL 34泵1X%Cyld_cvIGN6rBYVH bj8dcN$"1$ Np-gKL"x6[q"}/q =w"07$y$Zl߈ DgoLYO%EO4qP5\ Yvv롕CTDv=O DhC283Ӿc`J3 o׫E yh%m7/3K*r_ vo!)Q\Ld᷏Q?167p{"nZbN´_q \ kz*}BRQ",K@uԫM_0͇yb%|Ҟj^pGɦœC X_@r\j&~36 Fj&FfgVy8@jMъ&@ Gq'ވÌk L-Pdsy5~ hx5Vɦ#cO}ݩ'[udBuBGwٌV/VFmm` I7^(w}X >{ 1wŽʊLjskV&_c<1qYK٬| s|]zdp$Ax.Aƻϣ L/g7^>6K1:$G(2䔚!tNT:"H@  yݍޢ_DV6}r0,$ra9&G7G,s4ԍuj]t~ȭ_%4KZhgE5$l`[G6՝b,5-JAϛnnm8޺ Q:O?B'sTt{ϓz,J/<)VS9*'"Dw{P=$f)[ 3R.їqN7 A5ֺ=CNCˑvq#&a!'5\*?~+!#fc#5֖"S 9%P6+C^ƲZˤx.2Ә fd26/Xc$^̀3 ?%xĐ 8p6$&Y6TWvxyLeF\wӠGݧ wBq~Mjp1Z'HmE|dRé&0#ӂK WhG{\LNn{m%Dnk [sY{]+.$Sno.oz,.a:#1fݼx{+=fXRۗf~I)ԧr.+xCI2x#ܘtݛ/J*e!CY(5u>eOaXh#Ɓe)c|MJb\=R|bwjS‚b+,FI%16EꟉ!.*Ȼ7EaV26ڶ8֓CS:'epRz9L^׉48*Ub6"NN3fiaWY|g//mfcWm*H7?8ek#%&?0b6ߊڊ  >g9MV/P5֣#F>LwZՍ{P(e,Fq0Ѱ9 |"t+e%^]"kی៼}]gfl+7  a@QC&'x?ĻL]-.n.? k dlRhTjv~?z)fOs_􂞳DFTۇ,/*N?2* )"o^`K>Em Er!Qch{+D'_O%X&ENچ؜ks:ˢ{W^.7=A+-ۜl+T"B/`dR5{RG;2+IZZh!bX|+PF.z՛n.JikyI9GaX\9j^Np p6Vɯ;u cxҎ|jgu_wG_jڹ%⡍,a|S_:L?Hi_닿WqB[vPعJ~y7xև\h:4N.M #%CwicCB wB7}fpADbAGMZ|f"7t}] ڙ1;n1]@#ƍ1TDא)*I8|68™:-(2=̄ {$qPaNyS783$d3)(q\>oojAt(FV+ԑm AI9ҭr ON `Sm>ԀQ!GRe/Zj4=[8-kbXnL|Dg1,~>T-xK+.PYEχoǷ쮈iU!O\qUhƴ`W,#}>VZOȕ.]ǡm MAm^/t>I xʄ˫w;6ATܰϝ{>@h{꒎a1VjNE1Ge ĎRqYkBdžBΥFwȑXfJoɍw_xoI \)2h1ԫg(nq~2i?tE8l\HWu$<}feϙIWChx@{sB9.utwj %]++8k\nFW,NU@fp1  ,5RqU6U vѷ7nG=D؞%ﰎh0HQmo4Cf2GGG G}nm+7Nflꣅ c Sy00<~ 圵Ɖ<EA<f4 %'KE<㩀Pu*C9Q0i4[J#*ō/']C(-Ob!Хi+c'$]YJC$0V 6@.)"$yWI1*rIXt(6>5$nG%oН#ی T/4zy?NEp[KT(5y+qn4S;S0-]bݼȍZK*Q"<֓ RIb᜚6߽z70%9?ga~ 3dM6 tY#x=@&ϩרR*2oB [ٷqѢ*[ =J6lRl[:Gtzْŷф njDQGe@3fG]=\%0[E${fB6{5nQc4">>- (mWUw3# s흯 ^g+z/C~+?~3;iiH_Iz&-Ha(9YޔťEѫ@侀&6XIF$ȅphO14L-K'g+ruܭJmk1(fGY:`!\=5n8.%>8!㛹e-@8Ak,f$Na fd$s&%{Qt*އkf"S_dC'yMd`j9)L͒2MM魦 ]]tons;Mc@톉$,cGϴsy&ؠd;_J)t'K.9ClX,SץL)>&?vJ˱x}6،0Ӆ@ vx`64{FBlIj7_xߜ0ߣmFY:Ǵt-޵Nv^(~وt`"\vJrQcmdZ~3Ɗ|FxnQr$Iy-NSY(n+M`q>~G0R"2U?ߒNK;Gv paBz15&6 )lȵGjR䎀 ecV2M)=>F&L=[K!iRk@XSDTdDQ{IfAM|)7o0z%qI'Eئ+91bW~Yzvi;Dd.sT1B}kG78f?KlCqRDʃIh*cM}-tm}rjJוQ8J֡l`I-YN (Wvm؍T|n7ǖYj38a.ͤ/9FFT)lcYh{Yւ:GT?s/)m_SMXx}PJ"or-@'hWn1e!*v@kҁ P)/js\kg#dܧYDI``ߓ`z!Į(ozKV[}D>^c+됞hf>߈I6lhafȧY_6Fㆷ̋SToE͟*AmT 5x8ay G7_K3@~c=S y 8@_G ]MK)ys!F4$K(6bLA(fXnS G#4"}Ae)ܸ,舳@+klnpx(5nk7ׂoMZf[-0yX2^rֿˠ8Ѹhw9Ͱ/Wx̱'8O= Ť8Pج K7Ă=obFtJC@pEX 3LS(Ί2؍>U7gN̑(i?,&vɅv?TĀQe d]h(L}.,b0m{ht#51ߏ\8+Dvq;6JH[1d~A|Is Ў%7uCn(ا"6Cyx OLdJ=v7q Ύ+I&2Q-NTH;I{(Mȳ6Pڡ~KY/#KKsJ,l9%P/HY LRgX94AС`6qэ͵:rGNYQA˺jNfIA7>63ge]L^N ;PV0>hDHvaK0D[?ՍgZUmn_Ex/i = .a@ρZkOfGY\bY#9Wf.>-Քr>nyfm>:D^gRt D< ¥뮟pIC:#T,nAڤ{& @l:#|sA#@;{ʙKC^v˭0WJ-R g9(}]uko1n*ym )2߇T|`tvgZBL?:k-6G-y>zSŹm<'HA)hhIjfjOR ʕbrUvK.'9 닫= EW-Cd_V$Or+Y@f^7fR^q A& xa \5[YMBMf%I(,&Z鐂mƈ,tx"9L:!ͽ.Qiezl;~Q?v {(c X\c ݴV{1T-o8mui#K xX-@UE<fHUTɞQKK }2SLT`(ҕeI/vbH6<,^ N-=#R[4 &&Q+Фh G^.H,'7hdPeyhf(n5 t .բugkӶsj.RCQPT`(Gjh(z7a!6b ={U-19^ZYh25yMu{|vYa1F'XR096Q\ ȈYtp2l9XB!eH I^򿠋hk)V{lZD nx8m>'V(18J!o"wž#y݆tx:%{)"FW"Rwd٨qkQYczh_BTY$LPAFgw7="0It4ӕk"g({7pGn+V9֣2مp5cE>?Йf\~_πҀ7c ղ( w[tx!VIDϟ M2 ?53r&<;A|w))sOCUolzSG /vĮe X𰝦]bD}B!=+{dDB삍dZ_?Dҫp7B/<b3{﭂L}d^N8Tbi;vl8w׸"diqWF0K>yo6Gyݲ߃9 l5wyC,3:܎Nnȵĥ [E_*t# 2H5HxKS)cI_[{~]UQQ͜PDr #eOqwohyڌT qX OH[?x(gq~f~9x&&T$>&drn@_32~)x岒&>pȚwM6cLQ\W~ʓfy٩niE֜o[%rGdexߣ fK֚9-'l:t@f֪?q̈́G[፮Cql&~0n< M$" d~%u߭I,A\cOḅ*R' ч'ҀӑhHm=-h hY 'رpV Owy$.]8[D@#zj~b -m٬cX7|(3b/e!!0o3+Rx_7&8]IWܖ}S \RCš7O{Xcx,g]X';B9.xPuq1(h\e[5N2$]zba "+z`Ofow:uR)0dNL}"{=e`*5UP1ĪKvxegWl9afOG|F7irImE෴Y9nʷ|#ʼb*{%"?op\j6b ƨܾ)TFmO𦷤hHH約dX)0X;l@@ʋ|k2ωNwk4ZMvn~n%| @!átJŴB#)$IP2TuVYn|hv7r!g L|+3xzap-X@$ӧ(z=nu[+CBF~ g2da{c`h&e_aQT#?Fz\< 1`jppULf5Kp( ?7tvPfaV{Y+ }"M lJ9- \lqٽG"؂I79bY%g7#o2kMݳSQCI^=ސ1Rh ,K&nZtkSYQjsOoq $Z ]8#R/+(@aZ"6}$Bw^s(wjT_0#y.B_:|zPp-ȕ_~\4x9!mɾv/iiےǽ,PPB i&S- rjevi>1ăBq;WNFW;uT' %Zvn-x~9 nAxYub#-(`A[BDz%줡JLxKE|T{ [–| nę^=$7AqouDe d\oPh0Xԩ>qKDwJ5i8_J| ` Ru+c1wfX,S/WT u Y4_nJ$acӄp HqH{hs{V><2t)M},Jh($  \hWxhE ',aO)xO:}md ҟZN> ›:;CiG0]=m^V/%gCAߝh2ޗXQ !;I-Ԙˆm|4`=h۔@UjOc&R 97?/q ȟ&kdƒ9v/ok? |Cu#uxdQ`(ضf\`td5P%)}m?kZdv5] "PGEB`YH#:,iHGѐt!XqQ8St䰰ի0{X .܉fl 5}Q7M8>ZevC4J,h @|A*K 1A[_}E5O3_CKrEQF}}2ƲɔFH-MKPUQgtVԻ8X'28tXGvtstf+D_CDh5ƂPm~{$1ҡd]7=<'h)[՗#|mb7:Hu' "R*T~{~7q3u`N͒reI38aUqLSs$^_kNBU)ut@Qf('b+\-30B6$V>K1ˉ%{_Xvm&/۵ 0D[*2~ڧg7æ+ )@|2Ud+;uiMNSoMx-%s! IZ:fŒVs%c=6 o+ݥ'pͱUk <g5;ĽՁ~A5ES;,vEۘ~ݭ qVOmaL8ZSU&N&kiXSb/\%G`l E۱v,6yn2Y;Z*rJ>v%m]:zΚ2m2[}$6h#s!KpQt]]<#HP,Bi;D5_\]*"fҤ+V*SW_1IJH} ڃzҳ*^Q}r(y}&,owlm|\,E*=gt7/bf'rm#H79b@hJ|4V`$TJNq x|H\(>-KA\TR Å_NL F<504 m^4bE*2]bI>J@+^|o3|ahC)1TLiRSQx9ͬX)yH;~͖em`St#htHIL!I̴k<[=q$ Ϋ1,{%x[Z,n۱P z1G$(鰏JDPHȅZq\0MVrt{/4=0oU $mZ;)+HfMMmn)e%ȨFIz(,Y6,˵Oʫz5n{/c5OęGpRz_MbhQe'ub+Ƅ e6iBGx?Ih[ pCK2=FcӮLLTFApC{X%7kS%OSolj:&\7u|'_@ŨDfwxPmY045U0P~aoDs7GA */o@FuqQeq +QB IحoQn!isK }N)wT4O}(i1`%\]4΁Fqw?P3zQCGΘO,!ȨpE:YBvˇXYB/ArCTRLVe(*.#D]M.<*[ ?S3ɦP}{tz+N.$GGny}[h&PW HS)LL >5Ĩ-K*3Pd T\yL> ;+Q;=v@N"dřkËIl0K%:11P9 ΛR΂Wjc.>弴]?ʉ\BYx68fZ{KX.R  \ޓ)ꄗ12%B*%|ݤ:K 2Z3R#CHk80fr".-ukNߞm T }sUm9>&+i`jK rָ;fM$C89X1nϭJz#t#k\,e~) =O1"M;3opQ/7'ٟC3T"==T"^tsSy4%{X~>X>7TQΑD/c)]Ǜ6ێgtKC %+j>F|UPO̪M'O1Lw/_*|BݴͶ$549&5H54* HSd.kW7YmL9Z5ЄSbMoaofS!~vVfw߾`)4gp˹ igEZF  臩% b"D?)eMyxl5|Aa]6&qLā`İObѓ_?V*]֩]&s& 6edX'Ee9-禨#S+ݧMBK?9v3$l;0rK_C\oH2XwKV'^0DjMBQ u!^ X>Z@Xɕ2O}4]bؑk_z^DKf"O`o~#z2o S1uQC_6D4n(SxJO*9HYNU&֛ l&ۂu(@0FCJWL8pZ5>޼1I`U-.CAYƣOϛ~-[z<N9Qi.Գޢ75~Ѡ$fLbnoXy͈6Ƴsf@C 9Uoն1xk0?Ҿ{CcSh|ᄡ&|l]P>}o |bӓuiUU3`hݧmNRh_Ə(eXMˢssf p'͞PZ)#orYOWd[T4h= O^=ҫ<$:B 'dݮ.i"7q~dD@ˌ aS3wmufB{Z{篴tdSr|`II#]I(D(+>W2M[gЂ"375zJPRdКߪy ,vW:u !"^q~ѕAPEu}ݨnR#`o+"P-lOJ rUX0c\ޚh,afbrV<9nh~J( *l+MƒăS aέ_rQ*BJwy bv ei!Ѱ):\?-ijedܿ:#A(}t3:4ʠt(% _SzSxasL?GnA$V D(:yIvMhJ4Dt^]acѨ!kXBjb;.?yRӸMjo<՜[J-+HmҠ֑-8hݏ=AJEi$ª jKnê:7'K7[#) )h.!VQ6i%p",=yנR>RjZ"-VACFAIy(Қ;u}u"Wz]ZUxlN#,^xX7&"DK :!>P6řse#d(x}&XܖmߪKhnYȦA7hPl D}/tB"p]@= GM.#/ I[Kd( f.89Vnʭa ujM Ks+VMxx,0пˋo>o1gY] saГD|f r +6MM1QjLd+*#H}~o [=rd|ӳBZ3ڍMms$|)JVWf:oHmi>|GDZ+wZO`s'ŚOש9;ĸ4u΅8PFUۦto {jD>k4YYS@%I $K%Eo3d9o  vREP#khw`v4oS&bŭ ~!hUv[1cd|ĄPP5W5ZKm`r 髽k5`9|RyĽj( T1lbZ\IplX5fR cر̦PAoGr?TLԞ:de t7NF{f/|ov9_iMмrH>ª/kLn~Or<+yrE#@sP+L(lH8 8].UHu@+0V9CKiQ=6[~3UZ:Ehm`Cռ,) T|MMk,8 ʔm6APE|G߫N*1pWnvSSuM{@/)B KLnw'TMnF Y̵;:S-=%##p@$v\|rs1ћ^E=;@VQȉHږϙvu?{<ּyP/W&;C>(i,BlSYyd$_z3RU 6eK;.Tj'_M 3bF9 8{ኮ4 "6 6[vo,BJ:YT Rqqg,#5߶!> }x;޵tQ~GmRmFO%7oc9x/nK3 J;i"i|n"Pc>MW鬋EΙ$C&ϫ_i[;^:`h9qDk\}6aM2Wm/-`=7>q\M:w4e5.&ȢoITJ À)IV8[ۍМN yA[UtKz V=!>7jnxLOEöMUвPmeh@!(??;&-h/W_<: -d~g9b= `TWk̿"U`= B,nf-R+~1&% ') sTa0{q Вᗻ U=q2z^4Έ܊ڢYjpUazlF׾²2evmd|Q cϐʮZV9y' ͙m?y3>iΉVn1b&Ӽ3CUބ>&~M.< |PO"7R^ҢE|1WcHcK ;UA^Up]KyF*~-yV%d.M@/WڹI*?cm'AND +.p O6}D2x5`r|,^Jf5}ѩD| 0:Z22)9rب"ùk֒W1ucYmpEo4@b޷y @&=t$w @>gZc#_ۀ)bC;G1"Zς#˗܀t-;q"EHgry`(h!ps ڂ.,( 9h乔ύnj3 kEVv*S{AB*^"|q@$c!TyXjrFTD `ιY-~*yn61v(piofz&?#,SQs1db5B}M߲\O9aP~ ,v[ܔ @>$wm2ZH}gEu8!VIt,|Uz9'gIDb˾ry9P +ޠ1W>ʠ#+JFI;b72ΧzL;x 6I$eF HZVPuoab){iB?D!n(&LQxԛ$mdHDWRWP>n:F.Ͽxkz,u"hRV^ }$>ê3O~+3xbr˖`C}?bZ=P^[(T (;gQfesǏp5z<~W*U'|<ϓZgM̱C48d.Ŧ%&5_( $I ;8#1P~>񴕵Hhso>$R'?7߇aGR+utXA(y4z":N|'$ZaEl̠ Lq-Jb߷1иGģYG PfS_)hѫV492Xjtq OhqHq0Uկd/0Ɵ΍_0dԲv[MraդXiϳkH0q>T$n [Gn;Slaxm/AdPAJ7'3VYPk au:{ix;9 ;{"}BС˭TJ-VyY8O!&cs-l,8<' %t(C$ƍ#-hkcނWgUdf]mLC7%o brOĩuI (3 E.2yb3c2yxNWdO^ß4#ZeO*|d(-GOTgƹqjFHy$knR)G-$g_+[_W"BD_ 9_a? 'Xხ꿏:pe*ث9TUfr@a-3ڪ^U\p^ ,Kl}t3 k)=RTܩ]csF%VZMZ۵k(1ta&. Ҧ 3ݹ%%叚] (A7mԨQZy*p>g ]=.E> *[q$e8ygQUS 8gk!Cm[A:?w?F@Gg[eXTBrJ/ԏ.hh|{1W)}EoBpHɎ kid @l3 Ǽ6_<`Ԁ\r4- PUav%-gyj#ޜ Ȭ̼E 22`;C5{.TUI ,zMA=NoAY4em<ɓiuZ>GK 7mx5+w6s;<ƶTE{pyr41"3b0j7qky-M)qu+d},=Y&W}KAXh$X_!6g:S ՚9J cWVOoSVpph'B a񧹁gnH[zjd GƎ 9 >A(/, ǻ) )Ih5ɍ Rwg'a#݉0*1sZf{r0 e PCƐ@D rP7ZpEZn e@n$M|k y͹ ٫jE8-)ď/]C${i6~&  |zlG UR8zrSxM-au6w)?!1>KX]d˕0B- 8,/_r q z}y~gu#Eqkoخ'|2*-ݍ#l4~Vd"aI8{+T ^)sTK/ OX _ԏdLC1ěp:ăR"IO6 NxZ13DxfG=Zd /04Gx70'k->A`Tpv9dܧbh% in>VvgݬX2XvX]QϿj,輀Cؽq0P =]jbF]`BXd&FJhYHz? P[˘eeƘ0wj(y=LR tJfz`|]kո`xGm|I5_1 ]uTJa4A%2oc1 ix*ծhzy$@x^=4VF9ʺ2z`gϯ̝t^kaba$HE $c>Epn0Vm 4T̹>FwYi83/=50V&!o]_pmہڕ"j} OmJ>+b 8Xn3āA$r%VjJ = q}|gg X)^ہN#V5R1ӿnO`sRO'+UH`d9#A6-U$*LX=|A_w2Ic2ժ1>OTѮОUGe^ث%VQk Rv*,4zcY%u"H1Gl" _4Y4Ʋt q7>˘WCHW8Hb^L-CTĿi3# 5~0Bɽ0YLVj)9@dF9ˈ0LӸy@-V\+Q@'rwwoĊb^Rf͚La C輮Pm^iSZi.ՓkR阕 ?o@;8u{37XWwzJ%hBʜ,[CY~BPF70N0yPUg< \@Xi]:0*wlXx&bq6`9*N. 1đgu_>4PUR>@@6xW(뿇}rTjJIUqGȠ %(d> LmW4ҿΕ}Κ4TY#j?ji9*TkXÆ&V߇ ҿw=I||`J#Q9KmlQ¹?< L?6kH!?3<҈C;u*d*mNJyK(p~9DuQ% 1 \R-")کl*lDRUbY3l1<=ikXmY',3Sre:gMB~NL0GE9_&GvXhz^[ py1)ijtGK"2HEһ J# -ؑ[Fb \N>"R}Z}u)|ZэE!p D|@v?8<</Ss}m|ZPs&v+%;G)tH6;jlCFIZs%Dg>,w4w_qY;0ޓW{q_Tv*)]fje3cnlZ;e@ihܣr}%#՜d :‹EcZdgo)ÜĊ؁Y% >A-UCBvw/QMɉ "S\|L$biOd4A͵1 60CPa%T#?~Q5yI>y66Y-?;KN|5I^82WATfH1+LWwƲk@N=gCTVyZɌqPJ1ѓ|mfC,ajcJ?waS}S[0#K gDox{!]_y'';K *v]}LH;'n-:zoZX1@ T(P?gU~چZS":-mؤLHSPzO,-'AjlB\PRZGbkuj'O#Km!l3K Y,fN46/gw!msy!ۏ-fj5WnaAI"WVe&}u{CGc8iA=h6Vȝd+Jq>vɶo{*b(Кvl+#%Hx$NKܱr_v@0;p5~ #]*iCF*w0tZ[u (DÒu SWs(HxT6.B=V@fv#D_ aYF;q5anc7`EǍ8/#Pi o]D1"ï6,F$EeXqDu#z#@g?}4TJ{q;ZG`3ؒe\8D p>z/#ɑZy*#Xz햁UpF:g)|GהMiWЮu-J7$kNԊ( >1 T$=}| ʃj7t&|.w*KpvU?l?22kQjP~(KQGc7y'ZbTCfYy% rWî{0o@ 83 XҢ?s[xQxxg2G,5!A +f'aOax8p9m:Ǭ[9^#CөiZk;E+F<,gDn䁞lx=ZPߺ٫t^z_|و@TN8j+b)녨{g~koOL`tGZ'8Ep}92vT5]<נxyչFT6C 8i!n'Ln V:(CaW[?Ԍl|'OP( ՉJ(q}q8m4>q<D1*svy!Srrևw՟ =dkP1"4:Ϣ:ǽ`?3r7,#7͙IC8Ȱ 00<܁B/::TNèsY I%$>=FoRe~; 6̓+MtTΪN)su<j5]}c E-e$ZxsqFse;tI=\RGV\bi/ɵgP>$D컙twGe1X.Y8!cҫXڅ갾_ }^%B q:RDngGFG;!$^( &,;F/1Ta{^bj8=@`U@s*[tW`VP79Y?{qPt>AVXWB̪(r38Hʊ|[*a螁`?5[<( Afcva#g)X4cC=`E7]s7ӨVd/},$F)9qsJ: ,EM‡Bͧ[i|&7zH`cA(Ǒ'[6N:!c^DduI.}! =ASߺƺ28;L'jMsGMۼUfR-0R1 .ι 0$T'U +OyY!xl^X5 5@BP0&Ӊ~nibH)iͼ;(J09 \AKǕ3Y0x^I,~*rb\^U.^Ǔ% 'ҧtow,rqֽ~~tqC! ^?ۼR{7Ub.d \NiifwaU<_eyؓ->8GgZ.~x%Ѣ @&|&L8Z!x?*E~$wpٕmv'|V4R#mY)nnQjr agJ-ٟEօ9uJSW4$Ye5 "j503z+]hfs"low: 2ğ֒l/f_5hTY78@ y A0up9p*]@(UrWMp 65)WPsRNWХ7n/F*o}{o'urJ \hQgv5\ >cO]5KC$a3A1?5Aҽˌhӯ]0yL/NQ)mRʛ =~a8 aT3 Z1t01O@[.ˤMЀX (/TL쮑FX1JfuT֕$k'*5q6 +R=ZtU j`6-_Šې}>F8Z_'ܠVe/h6X+^:to)w5mbP]`-V,C$.Wm&2Bc/p 3 e}ց9Ͽ,qS+'hєVߩF1uIEfl p%7u|5/73uⱈ_0Qd;ٗ֏+cBʹ|rPL3жrn+O^H<\=\,ѽ500G*Lm]ZB/?ܺU^ЋUJ߰,~;/SfI{5BL^KkYP9̪x?hgi/)|ئΟYwQy*Ǐ{t@gE sHÊ n [D[dVoF RSrS OJƃ*7Ϭ4zް] 9>4.%GckV8C@ܶT%r^ag݋R`"No%v=_I#JXdhp1ۛh_k{8oi㮭m<4P>U#L@ E_Y5dUY9K'21̹?//rxe{ 0Chkif xg:$5GU@O<]nXݘ<>[ė¶nUe]u ׭ͻm3̯'ʸBhrݯq9C/#pggZ`(K~{Ԓ ,e_SLN} -C! Gaga:يHX#pZ, دk 0$,8UP^. :n_trNE%AWYc"ML~wd}iNtC֐G[.~5}{]У+DWcu,lRPzˆ,'7B2 Em-ԓ6-NV4߁O8ơ"VlD+zhqV/i8J %(St~3K 5ceg7: a;+zuΖz!HmEYa0@t}p}0F[ܶ; ʷ@˛S/я@:3>l؅y 483>&ɹw)Y7.EG2Dś?XAOX^FY+.2>FW=X֦;rPYjP}p>7b=DBG|IϘ;N7NF3VjEyPIx=hSbI\[̀ۃQr9ġZ7ŴPM|O<sްjetkUJ$H19H~̈ LýސYwY-&wrP_AL2|΋%&R#]-4f+UHf<]0擙r\_|xj:uI7(tJxlY+TÖV4*>Ś~WB@d"éR"ۇFn{ tRfSrWpV="4u NYy \{(Ɍ͊x K!247țӑ(e +(}$iX_o\ەtvN(GGdGgRMa=ڕ-$Xsͅ M)ax`̈=`>h'7|Nv$u4`t{( !ACijQ) r7#G@M @]~9,\Ű%;.=8t FxT@3ᭆNE4ՑaڿrשlmZu8jKx%W.y,9xm7K8o9/T $cBO~u8]ڑo;!Ӟ?#?OBT˷QH#]E׺EBT$mu QYnx~Û5S786h_sz2|<Љ2Uvyғ 'A0G$'K?k(`ucHQ-ZyYx#eLzp̮w -5 Uq* #S~RaS8^-hmb|2® B*s ˕7^6 . 4Ԋ(y~2>F]ҁQ>ԗNi^\'^B| 飵kQ7G>P#ĭN)4\Abd5wLs&5cV~߼j w MjhEW 1 }ƑoNq##OX^4hoY9Myۛ[6zKe__1*=x$@nqC |oQz yS;<`| eYFnpV !v wХ;5wi"T.^dDR"J$*]NfhA)̃IS2uP #`hc#NP6 鎣.) CIު'Ky'IoTʹ#%ldRVM+;XЯ.#:1⾫`ĖYEM`/s?=kG6)p2u0tYcHcqJSd)iT$JC 'c)S³j T6H@FC Uq(--usGl h~9TWkHmJXW#Am RRB*\1Q`l,[⯋XDOGk 4~'lћ-pvABĈGNЁ6Z":Mďad`HErO/עSt9?kO^Ơݎ83 $L0JYnП ;=nd<Y[nY:Տpv?((ϴ6=ugCR*8qT+YV皗~cNCp&ݎ+M:z|Z8Dp ~mhoNX>E8q;qd"6©{ ,#ջ=X}d "m4̓k^ˮdLoJK;]@)i< -4* B3dGEB S^Lf2A#&|oG0+o f *ǰO.!9ju\'`û@,<@3TirOv>xSO?QunNnu m`~ԫBHLI#'j]n *>E/5Q+\z4b@[ku@~x|z(davSU`— K~90.L<=?T3 lgjyJ=Sre5u\߅jGnmR:R:q;+X!Ų::e&zZ|wۋqB9v{)yM0>!@v:$УLi]87PrW&91gaYLGwHZƽk^>:y uvn_e/K=`vEHwނL>SmMj# +yS &/m-%{6_ Heo?鴊_l$~(\ `-8{aS,,`2b0NѦwv8cz wQ Obl$Q\:J}j]Vvc8CP̰6Wв ƪџe 6 CRx;qwMҲaiL9Rd$Ώ*V@{j ABpLy%huHGC]f~\Kj~GH%8-%#t1i)(595/Jja7uK:3˺uw5笟~*aDCCC)S;;j.As[:uʃ!UTnHmL BKjЈR쾮bc PY9Pn[Mu2%ьכ21f0TdKZ~un9Vꎌ'\8Qat@U9Yg;(1ڲ$cԯ>5*fؘ֟4ȼ {z0ωpTKEA}EZ ^< "0̍[ݱBc_ϒpRԄEzH8AZO9>ZGk%?JjN9ZE(%(G-ל+QrK32Fsf~d5L4  |kWCC/?RiG/ٮ3^Nt#iaek$ ʋ`l/WB쯔_'^Z<c5r<3z\&:O2,fFR/\3[^ab7z=5:\-OF\s>2D| r]Լ *? eb,\% KZA{ '¥Џ^ ](nn0ԝU@ImA 3ϫeuc؏t\9|2a)!Kt"HR]˜\M9榘 ȍ%-.>w,mepFM;c" pƌixfe_[(Jî%s,_/J7]S uQr~FMθ6%ܥkh(>`kRf9DTlO%C~a7I*+}o)X_S2v塚P͖ иL:F,`ʫG\ =08B~^#%?q a)C b=9ybH7PA0ϩ+ɔ)]OόDzpk?N|-E("LBƹ//׶n3/ACCPf&G/s#׎P'2{cJtGb j^;dX%T*[a<ڮ$E8KDm0=Z.wӶw c:|`!T2Xy4 DHfO,?3/V X6p5>SH O9d'k{w\_12.vc MG'ɝ^U#d%Y o'R(r lLœsV F{vQbR ;t]FBTK⁞}=aG&f rsg'Ӷ[*Z. +e'hU5l%Դ'k*-mT/eBNN3^{ie ¾3vgy-7ݶ*F R+ ^Y/ӺwCh5rID- PZ=r$Ks͚ O:O}Vő{CLˬvǠ@1o*T@Js .h ǂ=d׫(LsYMl~_I=~!)#ȳSS.Pށ;caxakm 0z S:_tGa? fƐo[jH^f;KyZ> Ҧvxl+̽ޡֈɰuu$i}jgٮR}CTT V}#͛*4~۞8E9j̭L:Vg&sK.7+o\Z Q9_mK%Y,5:b%!WN{9Mi-ryϊ t+=9nzb{~ zsrxz=sԟ&1УƂ| ϕ c@; W~@ѨWqB(s +oMȨGy ^WUQڰ/AՃ>| Ey$qҖvnT2AD^he7=hzE}FiTG҂$XO&ۖmdP\AYA2aa_16@Qn'+8kVt$A~1c7 N\imdM Wk 3 #ԠP!ٶ }G#j%A4\[ k@ֳhsV8h'=;'$PJAFƙ ^ p!gPYԻ_ûfęBrcգtߍa=x.ZYу`vaVjI:pڂ9B$,')GȔ5v 9jq!"a1'LBZmܫ13$Z^USZp'C ʩdǙxEO%oeϰ̷fDq8J'1R7x¾ݪɏKNƄSl@L$wSֲ(`<.c#Hȕڲ$n+k)zyX$b*ų;9wgSݑdmOwV刭E["oFa|'AN=Kƹc8Gw*"4x|Zqzzq`7x :ʈ>`Vv#_pc}cA@͘%Gs͌u.X/<Ycӷr@⥱m[JR$M-Ot,Jc 32RV4l|lgTf߷{Z3]5".g\4EH-kwA73$m0)^[n6si68lZuz{FE}Azۄ#[AiaV`F&5go~,&NA4 Yn SJ[d^JN4 PDWĎR0n?[-Ig2ORKp~Mb-=?,G"XL萧rGk%<#d.k*1(&K:7Z Ek(@z?G|8 θRprXYr c߾nu/}m~5SNyMJ )w'\GB|| P YCt`MXl V3Go0ڝCTlw2Z(!|iH*+|(I)ZImP\ء75Z- 5aOs-4>ہ&Mko zX\ w.xj =v3CSlҮD3?H$SUN7e< UD'+"V8{bJ:|P0{~||*TS.q+$)_@YBֿKvwUD,Lf2Qyv u:қ,1ǫ(n9F^ѱv _j6i٢ШPKR&}[Qp7T`oe~Iێʸ9"odAg|g=8feF5ڕP}=Nn[wlMK3)ىSva^N ۙ̇lt]PuWo55 O*k·lPQ5%fPs|֣~5_W.JXI橍Taz9L\+xp3%Jר#`8dOR$[e޾z9\\`p;S՚S"e7Lķz11qاWLm5" N+ġyMN|\sF>Q3{ ŕቌǻe(Kl\:8iTBi)Mk`F&˰ V`h9m |X'&f:fq3T3D {Iulv5v^ *R ȇɒDgq )QJ}@Xi)uNc5Š:82 mlU[l%Ҁ ihi>/ԗ^>[5IIJ0؍2RƊC:󭑖0fcɵ&?=(37|1j >t:+18FyGDFt[ Oe 6Wԭ6kyQ?< {_&UjEޜ@arz2Qb%P"m׾& fq&0nփ 3ʜ4PKgX Gdn:C,ü̑MnmnDIza"[_ˠYռ77HC[MwH: USq+L*~rvդ|0YH!&HSJ T1`%G˞" th+?[E;ƈ'IaGҠ:i#*[q9QZfKOǦ;^x1v[ܫ,H^\OǗ%"_|'Sy)䞂\70ɦgFhg1fQ&lI2DsZ2N7kQXu4&XH GC&7XczDs`hBimE/e{UQxvߚ%=PsEXBձn$t oo=Ƨ#jc;B6ܡq =mu_$`=J#)i,|%+ ƒA‘b̡S$DOMj&h^[LsRZMIA3`@rlYUI'K}e4퀢շT ,hNH.g&K~P8_$x)/94/8-V2(*M1C"h1A Nɪ|ta"XR8TA?ƿn!T\JBGyBy$JМ^ 3:5FWd2^8[2a16pMp-7uC|YS7&Ҡ.Mh (5Դ4_v,Ylm $y Q[k҉@gSaTìHڗZJ Zxk?$!MRgClgz!nUS55Ps}Oյ) ߙ.I)H@m慙^ 6EBЙ9&徉](]d,I+UƁ@_eF3)=*ⵒ^c)80pHFkDМ|>y<" =OUÏ%ZOdάo@x1=zyGiŧiƐ~\bģP$ )4ZO¹sD=E&M=@Kc6}ۋK-V_%MY2])í01_1(IF S=|2-4C*^'p;V}FUBcX~̚RP1kչvDc%\{^mz B&!Ɉ95+/#^UYLʱAԎ_eB~Jm^ +H5sx\1ؠ+?Z+3 Mbn& RLAm y4rb[9BאCs؅Y"ͱ{(W7i*rIaGe;2ma?>HP: N[87FQׁk&կ@y{u?+[|hB΅ /ܟ>)r2ܫ/P.Y]VA-C 37gׁB*$#L0O3BdLr,z~X 23e АxA>J=2R}}mOg%h̞_hPҠ}QceRU̲./WàgF( >k9$[0:QBVQz-gi}m"A8ª@7thrs6)}#m~24H):o=0.?Fn8;ޝsOV;%#.0L v^B@K'e0Oi pFvn=<鉀<3CƐ x xP&L^P)cRdɭUOiWa; xmHϣg;ϭ:iazV<p+'p@wyiQG`<rݶp ͔vbxT+Z8(806]fPHU$mOޚ1HS˓JXwtXW8߂&X[|NM~z*y̨, e4Ha򆗣{d>9a^ҼU-in?(c!zf%fk%pT*-U \H13~ўhka1VL/l+{*`(񿱴/UFX$zb*}TLɣNw޴pzY76#TIkH& :R!3(-V!>Do8M0q;a"wo<}&S+Tb';b=dpƳdrTBWvzoX&q&:RŶ@6_FN0s7w3~%~G#jCN\IC{}k"c$?#9訳NsSȋ&Q{qQiHmL߶i.O/uɒ~Q)ib 3eil;FB4G$ lqHleSys "8\t,¦]vE= @IȎgkdS5?Oic[h $Qi/'--M>3JCKgyոVB/D e)1!? xf>:}/u#ۢ?m31~QW j|~A'Y^ݏqFZ{1[Zo| @9/ Ǥ姷+z\Pӿ"rb3#eq3ʆ憱%|}E;WpCcMP7K8f58{,gq$iȿڼ' Ԕ>THƮ&jx1rfý1}`||~w';ÔO$'eU seQa{Q:8Y, QC.#7G_o|5w\ʙ㾺-gT&ޜYEvR((Ѡ5գ.>^(Ԉ _n%od~|@fgWIT~ұ/xlțvndW3d >Y{*:Q/d “r@h_| dQu;[>cfœ ʧk]&U9Ί*9A2 S}_;!E'qtn$vT[(XnvLqVgOϦͶgZ&9ڴhD6l_./ haf>6@śs >Ԙ$y:HM/Zꎟ]I^nM5$ؔD`"$ 9'qh2֞g>mǁJn-a5'gV8 ht "% ׶38ѢOZI\_L'{L `@?eʫԯ\ٖ=H`\ZKY8ؾZz!$[Z4)]ݝ$xJ#z )n~!~a-̓'pnċ|͝w V yإ0Mf**y;N:3{OEEc,%k,|#=ߓbRhJp@i`MI\潭'&֋e FYޡrD(F.?95{/d5P ݡo]7ΆG^2^i0@x̆F"8:UeREye_vNڹ8tleT}e K= Wp'>8c2HV Gx5Y?Gyh5<@ m߭x4 ~mmaڢ'=5X-7%E,D &6K]yEXJb\h٠v!t{ˉHiZ{ cqZSwJ %?J)e̲x8Ce]ֹ?&ݖƵ_bAlߠ|ـ6$xd]H+P߭_Oj\ "vXD5YVeۚ[lZ~wB )ߨ?$;7;"c]!LAd*lkRC0/'PEC4ਝ>W VXsI4RToZaXφoasmVvuy% ?TczfAZM(,_LžNm+QzݡxUj}53txM݁xr *]6o,1^JepmM_}X@< !U۫5m6RKsac "$!0_M !*;*_(~R2&81LMe\QA?898S$= 66xb/i=o4+M)HJJC Y2&_jd= uhNܑ?|pn54Ql$N\ NVg!6fS Guܒ/c9c9:ں[Q_ryJPx$敂QRh hKy^#,%B|YGkPw"jp+o47O4D¢޾AhѧEU9~1!Y Xxv`Jx5KFNIidS@qcac\ar=*\-ؤ2#2|gǙ'*}aIl||] fz428~J(I ;4T$%җ;^Z#'- م e{c1DxߛY|( uD囡:C־ I;!"JRB%u:nfXo۩T)md y5,z cBf"Znې QRIׇ }aMvI8ؾ't h``'f:UKq,B !ʹ%~UR?!# #<}ש@?dAH=^+zZyb*%`bĿrn`K&Uw#hÜڌF$p-}c|%Y8'!QHO~6+ \.R'quT5SmyFYL-}&f&8Pnt@p\_lS~/29*,7<>6gGt/T,bD$ݍ%ePTEo,/][2B\ jH.k | W5@i7Qu?")HRtG2"R{Ϻ>6яSOAlk!RA< T^.h)Ol(82h^ U?K;>P~aGgk zL5@^Pimcpy¢ ̙}f@.pBq~ ^I aNSQ &KVB0d3-YidGLF$y\ @/NP~WrQ ЬtwZm[ˀj1JIصthAex! (s= ewQ)SM:>&bIgʻh!S3Hf!YWZθAŎar0tٙ#U&# _`u ah"Lk9*8n ɻHqCMD ҕz :HLFJCZJS&eIp%{Nͷll3`M "4|01 0є4s,ABVv]IS_>cB;{og&GqYw353B1Ah}WQ }㚍FpW(:Yn|L.r`dE˗T^7Ot7<3F nVhB7;\1)Jm˕J׆("2-lʓYh^y}^`{{_CûT.Wo%`J sk9Liyu@(StU^3i"k痧YV!~G+aaV׿ 3oʫmm(IyAB_dRUWlŀRo(ҥ2'Ƌ7ShJxJG搃MJixâQhl›[ؖ7'A7 :*6 p2}L&,a9QQԑGw]nUGᮥzQb)ZrPP=]j#a ×\td9d&.%kN\҃,`Kr1'dC`1d xͶ^ r~:(Wx9CĞf:#O~;jKpJ ްw1CYZڭ۞\0C?y=˱6@# k1,YPT{fk :paG.΂+u{fWCt(gydf;Sbf}8h7QVq,Vl7aMJT  H-p`I끑^}eȎ`a%pҀdi܂tݍTbu>Ip'm S0`lQDa jґxb (jWw55{2zxu juSw?}ְ7s*7ͻ)VV_\}<~dyynyImaAq8Y'5t%نʨ5rA+L-/}J(~.޴Ij@4@26I]]u;ނ}6V|ZXO&#_m{ˡK7S{obmBzBzg5@E|N{jZ4Ffh}Xt4!r's6n *?W  GΘC?q-dWfEШMb(4c<#0 rؓ҃rܘ7i¬ĥ%d1Qy>)4ΐy({(:e/mU GOkBA>q8cY5A}5C8SfҌލ8_wC֖f\ wL; rwPqkjIV%UZx~ aZwl/j'7":Fk21hwbaX\s}:v[ֺwĿ/.! FCoNo/A pb~E'=[qe,C,@Нˇrcįpu.ʞ,O>-Ӽ/-1:wGMT{ڝCZϢ/&NyKKVΕ%iiY X@`pY3qeiA(ajAvi *AĞ)>[vNErxߢZM_SS &_(O(r%V" &TPDW]^Զ4fcROlU 8O]HqwYc2L*!~HJ('@U 9x!W{G_i܃z}ƈR^FTxoYzul" ·g/Svu uq}>As+@PGGѴbvs_PǘAUxgK0W7lV0 e+4rmŠ!:hSǙHosf4h3WW'uCzZeSZV)sxKedN&$ieѳRs]N ѱC& yQ=0}L t.ӕ@[FŎ:J$r%AQFaYedo:&+L`2A[xyCآ!F`- X^UMvc54^2T@%W}9vøG%m&dkdƦV89U㌽B< zo[= IBkC òCtN'CL+yuO5"R*~Ah*]d]Ty^rx?>]vR .abaS;ycG glYtKJfνDY H1)U5=@#$GioPPK sCؿ3S^Cqt~I`9qգ\d3m0\dOs }+k⺖kǶH<~vV LLӑIJ(OB3aj0$ 薵I– #S}zmiPu.^C):\q@#w[7QtC _h#wĪ/g3NH!זf;ehZY|g*Oo@ovp.݆wCbdN2h1y2LɕU5%E ݆?Ƀ0 췅~MC4`ziFZA$ )r ! ^1گQO\jߗto&L=#fB 3kXS 4jNBjO ]Kxbm΢2(@(K\8ȣC BX"Zy5@HTąLrEUEx݈o]CrUbw .s֨G̠~}܊RsWy\g"+RGa=VbҔzeAqʁL:q'֘\ S@s[UI BPEq!ג~QoyL<#*Y ^vstiH4PRo2"t\ܪʥ:E1D>D}[uot1O]9&-ĬsUؓݏ:Ea7J͝#by?**ws1OCBя+@}rvO`7هz+EdD$].8.܋@y]9()ޯ{8tLZӊ#϶f~<0vxYyK]Amyڡ7okODZid a'-)]Ty;WkRzCv*8øj1"d,+'Q?: 4{c wF3ٝ u(F۠$K6q[1K΂ OT. Z(kEJi(si ETEzN0qR.6Vl(<<:- (`H!R"a4F9jn >ۻ4/Zmx{qֲ4L˗Ѵ(&A>{ЌOO)|QcUJ0q-QnɺH&P"xzel +0AB;`qB Q9b;{N*7wqPò.|W~ m2 LNx C<~ͦtysM$TœVE[dM߆7BSN:Cm;Za ΤdhZ\CDjTQg n$D=D4*o2N#9y \\ϼ**2*AV*tp55-j4,>E&m/3ef  1(`+巆fI> ?%{+I43C8:,#hg/\DޣM~Y}3O6H)UNعO]'.::y ܌yBH$U,eOV,~f'iUw1%~.-.s#s>K}k@3 YS4i䀔Wקdpx?N T2tFs@C0pd+}D fǁw*|dZQXc`9 DUV [fU|p$)2J-dOJ 7=]2^IoS+h.T}wr)\H,҇} U:x;sʘ7 J-*7[l攡{VsK L}S>|v_ީLZS?/Fdldrf{6\Fk@ByNT`+/5s>9?ʔH Sh>*+8݁AYWgGqjl+y"p)z_?g14gwוҷk1'ʢ62H>j]qKCKL=XBNeXu0B,3!5kDQ5vAiH H$(Qu ׵qUZh m%6j.ْ썤ގ^Ibjۛ~~>KFb'J`PRp? ֩@[nӟw7)=ϊmNkG8=o hpO`h<njQ[x)jp\d>Dd`J ㏀T&L`ot;9;u|bZԧ%̗g9TC,P골lWSagn^iya{g^4( .yA~м.H{5o_iXyb #=g%mӍ\&9XO2=\XqQn[T6OAxIR%bHsvZqlR`4R>δ~pRn : m(b6O!^<-Nƈql8pT!ŔkѳtBA(!ft(IAJ!Jd.l5~n?t#F3NUEIZ ͞z_vej|x7K(5,^0(hRy`-%F59tF r]砥d{34NA a- ;վfNqfs߀ygU*j:+i1Džy|'ZVLG(|Y-}}n8ёp1YnzqQ/9*'l @17{K*uAT|pn_Z..HVD)xeoA}(˾i[Hu &Sv߿C 05}+l:ĺ,L8"AuoAN֤xqE] byF܌vU "s S:KsH/ H|ϴc2#U(`k;`}w 64>OFP6mG5ݠ&aq7hwBP[qU+n \8$z.:8Iv+_Ɠv{䭥o}ILj2$z:_fu~9ڽ 4*ÚiҸ`</Azݻ)Er"!0d4OD%v/i@.WQ[v1UЙm8T^9V#hx 3TSzI f_TEΥ_@'4d-QՈ?+G2)'`é`C/#=l0\/&UPzUԈ~NLoŗ-A?KաBMNҿxJ/;/A 1 %{[2)C31hmµe"v`3,;dc_!º.1me&  /gI/? wU8I`o*z \+IIȧ?gKtc؅8}B6;?,N%[ ~^,&]Ufك%Utnڝy[SqhYfHV* N'm*r. Q!0Wa~aT0$dZ=#|Q\Yϐ1=bH1쟭DclKX< 9-f?\%@&4RTQZyY"xT0Q'ÛXؒ^+ԓv = {%A6!X4DS󔂖z9>M+ke?wy _X;Mn~_?A0T0[ O vWـuLzrIx/!l6K7.$B Ј vMݝJ4~;/d6T!cWOu|\>[d6wBTF\kq;rQwɷ%&]yf5?{,<̩ʬ~/鎻-d/ѐ0؇Mݷ >7x51O]^=Cyf`1KnF{Gc\iŖZlQu8ײօ ݇L0 50:<^fo=X ȹ5\ ;ݭ 8ݭ~p`JICa 7ȃ5ŠkU hTa `H]4+aF6=% NhҸ}ԮAlj,T>?gW?Ϝ}> Ͷ*/ӹ;<)Uie`NevF8[BSwKNϦ\oŨU z:w x˲7&%"m -I);W86x%.p@S.dP0ms} tnb$GK?Vd3Qu+%LR\$g 訢` 1gFza"#d[m\])slj.>޶_.pP>͹̖Ɵбↄ)2Cdy{L)DtYsaTynF'?u:& 썴VEgorezaB Rby!Z[b6] IaV€ EwNI)U3+Abm;zFrFŴ?сRh+H8> :7o]i3B~xdq%4tl߫q(]AG`GY:C ]v"&&T +Z.4zUxh~zxctc-)P ,"' }=cRQ8׸q`ւn< !C,6}0fG>xB#1 e_2r=)N!#瞙ajDdajoO3֌ⶴe7k|v&RPܱ~(DSDjtA4{ y]E3:J @cw=q]$(X !j%TBR?B]%5nksG[W(bDI x:+G#`))Ys"uDiؾ MXgBsu519PfEs/6Mw/5%xeS^_hM{*UOVˡV?8t;psI:EG?5$<)}Qrښl~BX@K[/z}TtW>Ca TLpY93}WsJ0,i>loȣ NQ;6JkQ2 5t6u^<^yXCG7EN2Т"w 쩗Wt+mz*-^ُ} hc-A[ʄ.]{7F*uvR9C;Ï4(;0.|K~U4EQMݑPx7sPke O{W Tm h7&%JܟxswX%\LeaXYM OnfLC^p ]OODbH蓏dZ0m>|k*<ojIi~fx:A lzza{7)Q4:!sC<7fSwX(jLz؏[*_V75`72Bֱ A LCY|HWU|7 !A mi*kruԙ418.H7,.'3SE}H4D="|Q*ϝwal0k* ƢWv zICbcf_QErK8@ ip5{ńEΕ6)+\r V Q'}Q )X6Myplɑ$"""eI@|u9j{)J+`oQ:*AfY.iR9%p04bܘ62!-zUzvu?=lD%ՇN "'B&&GV֢ع9 :r:~¿une%AJ¢#zSt(-3nY>Brd4ѬȗPJH|ӴL9S|_>yWljo~IG']b0,_.O]fn(㍉O· Ȱhai[oʋ1&93ZY8R-q/niڜOXS bZ:6XnF;:6isVV_bNhT'I gfYP+{,KI3*噘v:Y\.h^ۮL0򉵲nB~cɣ|GK%דą'2cwK"s0Yr~J`q}h7PI@uyQq ?,4%4 2IL_ q3{~ᐇ< #4T\q,?u4%p]V>}W.($a-}#V&nE0K-)?BWqR/ϩTj\\v ~uȞܮ03*c__!Yq5m^Q]?V '֗ySLl($>]Exeo>3Q8WmַB1rە%pqԼ=:Β*dl AkyS@vU1bv@Slj#%V|X= ;;`E\Ŷ BLg{ k̶>7^HxŒquqi](4<4|:)8G]U+) kzɟ+tVޤcsoRM-Ѻnx}쮹ɛ[#s/cmqx)jmPi C7bh%<2Ouyl;49ʾ!]IA _fBV@A7sߚm{! ft'tu$bY1B$ABP)mkkH=s**񃋛K4싨B5-5vx qr%~ ZvUHjeDcyd]Y#B,L߭0F? V4aZzҶiɯ9i9>0RXpWeny RETuI8Cm<6Qx'v߈庸ryR:f6c#;Q ]I W]Uw+p\2ˁjzq>S8wIQs)xmV<9zNL6lO80S˴hdF" pɬ u*?Ϥ0j[?v).흤.l}N8PQJ3Cf;.><`RL$1dq%ImIwe/ccU͒RV)躵~:s"B^v|,\ r{4&Q-~Ah8҆Jz-݅:ͦ*TIQAg{ضU4k=CHB%q{Ny 4ZZ*c˙ё}m3EOx/nqiiqw-.~R~0*PndeM>K%|UB;=:pV)Ng;lv_wv/bdQ}?"U!Hrq|N*'Ѯ V}V VjڡSMù0V!14o~jb3l #= s/RY Q {lcaaNw\ڛ:&,w -daͽ; 3"pާղ,a~-4jmT(`i zjr=Z:dŲ34\' oUL$Oߒ=Ũqe ܊=iWLArqs 4l/Ksl)?q7mZU=<3|Cv^ڙ*x%.ס2!Bp$O"8͚3BQwIf puUt*3Hɹpκl&?9XP'TX%x~y`#{:#"K4m헓q?Q@; $euhT6_gr$g"d*Z׭t tmLD%`F&-YE76 [&6;QaC)&ɏ]}eIQʄO,o7kN4084Y aVx!C܍99ad,'L m2'@ɑ`bЩxtz 'COBFgdH+-A %N$ՑxGmg’s_qxvćyv [ABԏ}N;Oۗ] a,7 JU=D ϠZnj .{*-r THD*w2NS~8ݰd`g$V, ۑ#|Ñ*p+2>Cx:&_%yPo>-uNVy9rT,ٽd))N}QWGQРr-qE)upqGH12\)kmqȢ4!?`.꿧sx$ nyK&֌YR ܜ2n:"]-OЫ<bB\:U*I)Z2-i0-K ,~DH.4V?)]`g/|:n#EӯDvs! oi/M*_?(`)*c^Ѥ 8ͧ5ɮtcVWCMaU8[ E|h8>fDM|$Sd`gKV!.]"u}| gX~? 鬫 `4N{`d~vYؼ\qJ>4jwfO`_TbR:fVX ~ 6(cDaP=&S  7I$r*͎ΪQ8]SF9XW6A1VRdIi]1>Xq[HѬH\"GMN?w65LP{j^Aeɇ6<#`D߮dTI`oVi7B$oD'>JΔnc;^Y̽V{E,7꺛ydڬb?U[e¨QMRM$]QfhU=~S (H{=ezli*|)SCJ6dB~WmD Z \䖄a:ɀ̏ng>>f`?<%Bd )4 ] T)ir~w[iq&wFZ@ l>6@mSvxM> ˀo>hN2i"9}+SFH8g1 `eLCsr0<`~GCcJQ(r $('Ǭ0AfvXmX; S#fb):>A:JBO_œH%b2-^Io;r݌=#V?:qQbF n A*9$h໮W aϞZk-F׹e紐Sj(Df 8#\do c8eگwHM, K^뤇K#Gq\?H~ U_`/2U4UV!ہOF^5b5; zKHJytb?8tLl#zBH5*VMzg)Hv]N`JzDx?'=觎\m3*k^)j#BxJGLں`ӷ"xd5aCIxv?| ~0kZ>_cyD`L1~1O T,o2doZ[|m|s#Fe/JD~uK1LT8syRL;3x8g[)\k5Ws=7\S$ JvKJSl,IH"tD+fЮpcG^9$Ѭ** TWR,$]**}C>a> AFڙO}H oIIv/UMp!:Y"Gg}4}ysZ=58dal(A^qutЀ F],'s?r(HY8j,uъǔ5PR=߭P6nHs[L M&X7 '3ڸ^#HȆ%dH1kyX/['`9 <ڐ@u}V9VmubyQ-Џ^('-6 (4!=6~`=ںg3%Ν%n>A )K_wzeU.'\zBilH_fVV;=0\V:k9EC΀@BmPu#:NӞ`w:0t^C(˘_TЫNW$SmM'vy3e{Wll?1_xjwE`g z'xR9{jsJwњwXAJO+Vb7[d%e4wH7Ԏ:YZ3[8/W3@TxsSIq1 ߛވCzG5ZXf\N m@ &W-82M՘[~DJ0ՒH_Y4"7!0dڎB;>djтbѽ; կhyľHj2>k&EwaM<;sżH?:!<֠ͼ#t G#D+Z R jBhDdi_Z Zlb% \?Rl @¦jW4ԡ\ (IY?Q6Jx9D՜R: 2*)w]X6ٲh<虞^&|xg7jM)6 2}. aEȜ%OϽ%-2] /7׃+=+zx2!!f2Պq؃~PթC x!oa 1#Dfđ*=(ɖѿh8(8kA$c{(Fkoϴêv,IL-sNogG ~6p\f6uhI>W4b0%$T>:VW$ɤ(Wlоr#q 5scy))TsU&s/4hpFXIi؟9䡣`7Ƭ%Uc_n)H;Ql|ffYL"&z3?*ƫ>+ERnrqc' MW }5HxNkYՄ+^F6q4aE"l`u%-:Z'TZB~UmBg^Y1Fm||4!ٖX]M tvxVvx ;W0/ 3Mwzr7?)p͗L)AjǬԙ+!D9DOpr%:*rh'fB03Y$RoebbқL&tA|r12{ASsPMҊ3 =[kzfZTmY8m]R'p R"NPNCV7_NZa~9H".f 5ru˨5m&R1P G:D(W u St;$eC5P}Iıj ڮ6$R}zFӒ)Gg֬{ct$#U}#[0.r-IL觚:$J$^/u im*'ڥ|咾+pTЋ= 00lv~zsΟ(kqlb0q/|qtT5A?lUy[Pޛ?3P5ѱΥMu*z2|:S\RK_-ڄH&TK,4C)u2TQTЭtߔyʵm`9Ą6I /tL./jyk& \0|JX&m 3wd-׷wZ[#_\tsSJ-T29Ve|{>} B(h\i7]zٷ¼*[/2H-s;*j@9ʧKO>=!tkDd)/Pe%KN8&k\m$na 2&h%T4XBOg U1S3hc`K86xIVsn]ƊPT$8;I F%]A‚i0Zh³b۝*P[Y߇!M|wԚn8nT F99 Օ/Kդ"Rv/$)U հIsIMUŌʴkI +G;b"X6-K鬷hsfaJݚrDP[PEPSRLYS*#;`?[327L][ R/<:>f;wnGyB~o0Њڛ1 8z.scW 8۪=A#JiYWumTpD/f,7eզ|$^7.f*W( z,&ukpfS{8nmL'y¢6JPDЪri~7-QED3u _G\9:e(MfYq:N8͝f$?DadJ' ZuzFSa J6 cK=8Fnﲊg2# ذ'f&4nzM?{K5bȑԿܞTYkwri#K-KaL!>Ay)0_%& ֆq/z.MpRҤyMUQ~$ GU^Qߝݣ4f-@sxF=_ s?uF>9Ud.'#]~^ۜvA qzLP./N23L|nG`灚mZ*vFo?2zhI9Y ^2ƒd[w4_) ȗBvZYmNb6bQ:jpN O`%{tx)փ5a fXMjq!3P+ m\iCGG~ []_;Vy;h|q4Aӥ>LC7'L0$xFuEGz)ݯ #⟏ QBB֛v4 ݫ?.qnVE*oT G 6 Bxl[:%#-RyFeEX+ oda5AJ4IOY#m\7`^rnKy9i|oQ"}-&I@36(ٽ@  ba%}-=<@vD#뚸"w?i:@eE2P,pHߢ9Su?pϚwU 8.Џ|>@)G8:a$}`遐O {,x!I Hdl|=P.!P Kσ[?*;iӚum22dS{g2il / ɀAzlZRuMr79D#Gued'Q~Y*i|^_$O c<,,/ fV~iK!UͶ3ޜωf*B ɇZ8ۄNc59AkxGn@a* QC|Y$BBkL؝1N|pf_"(iH]R쯝WiJIY`Nhp?ŋnBouX0 XE]DL޿(w[Kqb yݻ=xOxqN籔4џSBrA@tJ37 #M:ݷjf̂ªO) bX{,;^ c|RRb-mEG #xR.Ěrh_?iLq7x N6 OiŃ jT. a_:3 6ˍ[Z-͍RL o2 RNAQzz?| ־6-/ۊ5H ,P2 بPo{ {b]:OXǕ_Hl#SJѤ ŸxV͇+3#4;!]>II8i6qUU?vo5r,<.;\s&f%g4Hi}Yi[cB 8@i(#kr0~mS湬btUA6u9.:ݜRLo.Y- ~46"GC1l׷bYpSbyOM-}rR[jd$/5 9n}m4[`Bc Vvǀ ͻX.dafڽӻ z"/}.\Ow=cwvMz}q{CŽ'Fہf7t<W^k\~e8vG V|6 ӌds ɸ j约Po E/MPv)Ұq+"7we醨ck_bxY!x^VoN-P 2*d}:e*Ja+ߥ 4++'4&+I3wڀ`@PIQ̇p,X${e*O pWQ:W_;LOؔ*;f:d8cx0Hf7*&:?'YH潤*/c?3+-1mM h]<(t$B\L>irmuX*&vh0wlթj\jq֙#@{*"e]7K)z {Uٳ{Q/`jg]ݿ+)=-mW3O s6xD4y̬sUu~ 4juGTbUTGBr-Ւt ƀu ay#h;H5KYCkl0A _?ӎHTa)̠Y Xۗe5܇[2W`=4Ϸ~⓻<ض~(Bw-kKnaT+`/{W.zgt0o)b g̛^ERTc |lB@A?y  aԘ)J* #%Ի]AK? u鎨*k#'ќ^7ΧL.0kVj$*:%s/PwNsiPoeSesxb;bƍ0 p&--nQ0 L]nF_܏GjJb>u:cB`BP­v2N@H0:Xcn H+:gB0ٞ1W3&ݪUOirl;?񅲧BS7N^/?s@7 K&Δ qIV <^Q-m&:ЪY>E%}r#rmw%dOۉpr W78DNS\ k }.?!A[/L~Oۛ]ܪ eϐ[3cXB]W=NOE $j iဃ8[Jo ^G4UQ:7teNZ1Ɇ%$.ǣK/.եL!XFuԽ`j}CVjqvFg^`r%4"?uḭ Hb`]*ybSƬ-c,T( Nȁd*YeH;CL/ۥ6vZDs!m=byS)ȃ}C" X^L~V1F)Gab-Y{30\PGDS#![={D >sJ4ތw]ɠgj>',Q ()$+|AKBG}Pv@.fy$ Ni3hM\GS,4^9Adh) SyO_ }Tk `ݡe&?{˚َ̧({|; Xx\Xph\+ip!D MO[C%,iOEaE wspzsl=`D # ௳!1^9 ͝SiUH.8C/f[2 5 QoDQ[h=Ǟc.+~n C]&[/υK땞+oOteuȍQ"Lal/ǶWj
i}!^7f'aSZIQַ`]5g |[;v 6F]OuzGod\/,>:̵;U߀rps4v)]M4kXcCQt19 #li*0o'up"OOexz/ei> ,lyo^vhcs 쭀Y/HBܪ2ԂŅH[f M@%t[?/(u qY"\7K_I5t6bDW@> ɐϹ%L F(ۉ*0'#pCd%E&0`MQ@ȹ%cN$՘vw?Ϋ;< tv|Xsmr`+v&t:I=𼾻J(iʫMnt"S&މ]_hSq/r(J {qBFƴʦ+}n]VpҬh546݇0^Ѕ,E]^g,r v^=%K8[i z\4(9}ڐHX9Լ(A(C@i-( pk8uW^ LhqU)뷺/+7彥a|pMpaQNh\\s|7;&@.[|IW'&檢R=TXN*wBV+c"$?a>e~&nxjZGfGOO2|DN6.eUCˇ⋰9k בkd#YlU'LXrԇ;lwU9&EMjC^FD@H#]Ȇ E`gz{Q;tTL4{V}˱u m5͈[׶oc̠W~L8M֖}6O!S&mu<xfV,oSݒ-ZoOAx7yFRt=Ҭ#xޱoylHXAymC9T;XA#M:PK!ԢL{ ے+0{U2# Fk&IS޻^6t";ϱ@<"I\;)9[h!oۣ/tW1g@VyRH Y15ބ/S \D!{@&cZ8r5mpġahn*m ,=9}a"ЙjFhA{KfYKn̜lc{"n#Z3^7jH>ֵrsB,]tqNyk^pwY&]r*ard?ݚsi)<>3eG:Bz\gѱDs쏣xqRjȚ99r9sf.W?iщ}9w#mV<7~fLVǠ|Y%PbT|ث[1ЂC&*IF D=}k~te&⍚>7txڣCDQ-3IpB欕0ZЈRq=:dŗ|_Wlݓ PW( --K py5 JZxnlR,)9?9UT uw,ByCOoT ۱CUɆ1c9:wW(Bآ)αp zi $Qh4}Zڏ-92L腜.ӛ')ZճDg?缎aSMMM=nɽyfqNJtjig``F _P%/7Nh&CExtLKJ!vu2X[VUo*Zl%=hk[E[9K;n3\ўP_O!ءӪzo07ZN3b Z񻨶eʻpၳ]pT6Ok5]yJ5śs_K* gG=j8xܒ^t&9w\ w:8Sl4 HS%IUr ʾ~G;gfyC/1z-74*Og=l%x/X#|p+1̺GfBe,vƊR-m9bBǝ /dMqѼ`zɘ9GT;MOeSSNb7֕'M^{䅹&?IEc]=k^Q0Jz"dy? HfZˎABpVP.>xl`%}ʅX5j"^xm{Lk2ȑo]8/q׍:!O?ńl 2B!NV=IXf $oUa?hEt.5# 5|N&$LumP8ï(=WmM:";W{Q~Q>'̢__6 :CX Hx7p a I+W9W/qJ# Q7 Y_N-+(>b8w%bM#B63u@}VG \/kێ>v0Ԟɥ7 ` z P5=QMo:!zO#!D >cK[`D2__fa.]/`:6!{++؝X 1QO:H*gd wIi|eeҍ\=H05d@3Y*D%.gS)R;H$gt>!+4Oyn"UD1XJb7 j钢WRTHb/c(=s(E)*ETI<k8!ab ڡ=kiWKWT IKBdQ[yF 8s$O[svțj,l oy| ٕ#TYI! (qd vK/ٖ֠bMt:[ qH Sl!+|Nb.`HS[JߖۜUC}tW. n[ݿij .氿$::乡LwM8q ^9]MCe/j̊6Sx*0O<^}&;)zw¬cT`> rB@Yè"3dB tͰzߓX쨀9X(F2$q7m 9ku1OcV#TٰTxFżsJu؛f_14*"2 "\S#373ǃNU^v<9J3bb{Zmpnr d:N͋h!U9эؙR^u1`ŠU D8?^#ͳG Rg4އT?9 (N~U1Mlj̀}Ek>}qS%CLi>' LBUCv.LB\[ͼM\\Cvֈgx$s]_6)yj0VΓJ~|TVC E/R X6$O8 CatC}nI=N3Ȗ[8X"8p%VA+v`,3ż~<ߍ[@!+Ծ;R \/!@#baP]\䍕 2!^$rU5&V^S,uHC$RqOGg=guZDZyיpSM~aY$lK+n6s/Xj~9b{WDafyn'ukO\k "~v$őAT AP[ğL\6:7]ǺnJ 0֧*.̬3}O1z?b46}7*Bp6y!@[T@T{sFLv#SUah(ȁ K{ eG2jzyYmE̽#< zni=;Fj;5sa*yK\H?nSHh|~,Syk=>Q7ci.Nٖbdv AשL% ,c"ɗ!:Gn*PDDJӐ*Jc!|ME}T}㞓=x;(X_zcoG؏eޙM$4%02- x]!y>EbHz`]aͲaӁMOSefl({ݝ#FWR='v S-nko`-SJ\{IPC%ɪE3i^|qͫ>v2y:v76YK@"ppmv%zq>ZPL{r!D26Ym5$L/?<յd* _|9\P@!?0f\Ad0}wh 43 V7/WʨԧmMU~ZJ_JW&mi4Aߒw5 ,B"j@vi$ \Kh=l$. 8`Vp{AB"8vbiD ?$٭3 /g>RGb$QZltwshorM)ho‘ftd?Ƣ{uUtP2x#a=NcbOSFQ>MO%@׈8o)M`#׼ruUH ke>)1v%- ^e],˰?6Dy.I 6 a_зRۭL8 hgh3Z)6,;; Ko:bՊe[3kbjWs>,4/ף#Ţ%ﺬ ˲Ch X'fŒgj1K\U ac *sjo&y[RwjcZú.k^ʃ6ݮ4U2m 屢12$9#4`A1zIl\7CI9$y]Y\ʘ!ҩ/Z~z3 :5?7FSyre3&;Ķ/[dth&p>xy岸X?ʐh;s8vMc̣G{,Fi# pJ'D.( ]u/Zm[mu^2e"Dd K["a%]-Ͼ~b%K-Y.]2>CSU@Y k'58De2[!=/'3Rpl;,C. PFZVӅq0=f+\s[ltߊT"i0a+O?ncZ"bsç^]HMۤ]Lg٫%'3/Y sOMce0䰂Z`Z?&i䣅m) ZWAh%QR޴pt ?pMcSiPIGWJ Xɪ}4AEt#J "%KN2G7[fxwcUkí; Wpzλ(B$&\1!]ӦP^yږЄ~\Oy<#340A|pW';ޫm'S ?8х;%V=xĦ{`?\ 5{U'yv*>P&_0JN;pci.LUI, Q_rmZ\z4R0.nwTb`Nj^o:~x.24b>\&cN7W*jehl@l },d5Qփ>j ^cn6 ˋ>e|\uGD'BdȈ7sWļ`,"+ 5#DHF;13M#`J ڷU<ڕ|?jKoaY@rRe9WѨtm z`.7>w5`M?>%svb=/ wc.\f"Y/K!2A\rCqRiz݂thC{ )e^ , =Af5QNg'&ZP>'c0K~Yu،ЧI~e(J7%%s1S(+Fxbpbc~HwNg1Y$"_ʮCT'pv2Ip5~³%N/0d65`J uXT۸W9)`hL*6X8{<Uk >X %TUjPkG`)m7(E\Ӗ1ICQa{Jzkfܛ Kp cG~Q?~Kw.4EЈ/3mE?w6K_YP<$Re< N?N =.~"bRB^zGyPƟm}3Dk%W\!+`3l >lcKN_+MWV tVU>PN7 "'յ6gzJ!Ӥ/_hEpF_q,pqaJ}0z5^QI5dRj[ -#u D.Fբ"fXITXGԷa}t ۀDn[$t?d(~X/*AU8M3;an Z;7!`D4Z[pj,scWXip 'ФY_kr-|JCcXZw=rRS|IpFK؀'۳Ю8q8Mk& Y_Y\:]SSbFĄTalaFK¿A:`z=V%a{Ƃ%:kZ:7/^ȃU .x9NV L [JH7ֈ%Kzlh@kSJ@v/z>BeL]>x)$d`NR}b:kȩj3<$X ~zm𿬯2{ǘـ[-R1g @Z [bpBOx2׌kaY1g5 >ـٲKӳ>gT%>|3*!U-!b oq;)8oT-a_Q oG#+ef(>Xy#`-JكY&{^e¸ܒB&tho>;IoרI("! $q^^"U@[%)i'I-r;qj;A54?%wgu),:FHUyXgz}?/#x#-1rbzAΗSD] 8M l>< *az"c=rz`!S;l-y^xdJVn\<:gR~fn_cp"BTOxtm">Ғ({)YRHo?tF[r{=e iy 8ӺjDS!0V߃;o u].UlޣT0^\(Qq} -"=W9_.ῶ)|7T)ghbHM bCI1oK7MmJ¼Mq2T>2MQm]v3v/VXXoC`Z>Y5hW<#@.Monfb)V`aѐ9hRi U #,)ci!Vjv[A.XJxR3hVtQ ?Nǣ[*_' kUc IhR.L|z1 6M-C)lrjo]T~8)Mݶ,[%yMyu/;DS*m>ح^reg6UQ_]'KY~?L˓{~v_KG$ o=3y"]QTɼ߲Ą`jg2#4p_ 6mِlz KSC]!t_ˆTS.Dy+7u7 z1o";odn! w?| ~_M>N7~+sX:F+ 5pPZfMv'i-n$ /*M&\ k~uHx8^.'֌a"넳7k&6㗠Zr 'Lkv겁,rK^M 嘢|x_|1k*5&9Du ˧b9}\~Wgbnv@c<"P+7tDV9f$aOf+.V}yk#Af[ͷ%? 5XulWݲ:2Mﴈ )g4I̒ŽQUꋣ&N?kXk yzQl Z4U;yb@BfP_[$z+³Yk^Ry>p2jVGvVLN˨$Jc S- Ƕl-j|Mר()ZW4Ro?@ygy5o@~W$sڞD˝AtB6':W(uz$pt.)szGtʁ@ .d@] 2cͫ9AAXuEi[d*c:^RL[lMjFpGLE:xfå8qvn"k9Z= djĢ-%z1$"왲#QRU? |r$(ԐߛDuiLd.UQ%h4xNS,ÄN[&V3jf#l=6;.ԭ 1s9l k;4)cZyOB6.c4y }dt U'"ᔪm.P/k6QZ&[R Äʄh* f=e$mE:2h>\Y㬎7ZrQ#1xڤ$%  ^icaLo^s71m"ׄRjEb Z;VyB%y3!7K,`PZ# wa+~QUǼnVo1_!Cn~:FL.G2IYZEH ^o8 yz.ba7_EsU 퇊RV#)s bp::U`k A{HħKiJ_9 2OOGGJ$ĬYq|kNq8=Yݑ^5 I>S|V>%91u{rw="p2(+a= :,j˕0G,w$4W*xzҁUO_<^k7N=ƪHzjoyޘGwY%yg=Hߤj2&l`j&dڤjwn+yv1{T=:+P6' MW@qn|G)}GcKB^qX(E%ls6 CjZd5c3s>/C>*ث`RF2ot@ # )B[ݡd㆖whWwK xc`c(#SIHcdQQ_8jzZzم;x~Gr7R'`1G,%=usՊjEyS#ӘǧZr' c5FjVcryI.W-Ω6Dg\3MW8-ދx#t`٧#ݩgi],wM+{UMdڄ&oֿ λ=q@:R!ӌ`.H]Fv\dvFf;A?'Ϯ7I&i.WV;:a=i%~4k Ɲg4s,?R6} lx EkA@vJ#9-KbB쪁KMg>QњJ^\)"G"R]e/ږ5CǠZ= yAh,]s>z􀨠E!(5>q=쵮ŋ_9yr1P`:J&/d5w ك*ʋNa2^XE.2)tokA oHO^緐ƦӇ] }OP!d6޲^[XIr`U4탋mYDZ)NJ' @u$꩸xPL$pr 50TIV {1CNRZ*HJ0::j_D86Ȑ13̽tdq=˕NhH [IEٗ 8,&_"yA3:}7-[ ~eP(̠,==w֧|x%q3΅N'p`/``%-@بӼ畖+` 6enӋ Ls91{Levb&t4UU4h|[c -4.N/?[>}{UݖL>ժK5,h( $h?~+ʏڻs`s6"Tnt3E k$L2룋l0SZho|Q-[1n1LƏ]ZV:Ati0 I&Lcg" {HrmOmM|t&@k>}o-|YFO:u`K :FFu3$CV}cO#>16QF}z%u*gt]~6þ;Xsk5^!nІXd6>F:Zͦbtlf8e0A«TKW-[(auO ]^ R %}p75*Ldr%l1,Jl։c,af e:]0瞗့C#z;Cby np}"]B [ﳆ2+7Ӯ/}ܔ<ܩ#exu[j96Z|Q5/ɲ/!GJµ)p\ ̺Ri߼}Wa*J;R*%޶gI7f7CsstX2ڛ䳛NƙQB9c?U莰h ț7˘֔p+xO$EsȂ(Q w7f"f͞GKN nwCģ['*)bk c_@BmҡQB@lUY ſU܍?_wj9K rq4)XoCc7]3W: H?ZA齽15B̻ !d;(rD⽾T<*znBP2e:@G3 qIe|VBħ" eW[5T+?kQZ=^+x7d&(X1grw 툆"WAx ʜsJ4#3Ys&nPqq[^ZtXC:_gx.Nn8om9nЀdk0]\ [[k5E (xxC> D0:ϵ[H!#/n%=IC3B m'$*Qpm7 ;kJa 膟G@i05l%Y_' jNGl4*ӆBAcH lK`)L:i&Kn g}IK(,lΜn8Pj6#(/nOy+k E/HS*4v.+Kh`B0l)[Y)s2󙔙3s;㸴ܻA} FcHzĴ%~erbXìMư;S2>_:EOz$Djg}PPȻ1Qnqb{ J \UelUq6p3wˀSTlCYet;N0~!q']-{49miurTL<Oupۛ=ݖŮ< (q;Gqm.ORor*CPyMlŪgf@1+U.h:BVёw"LeR 9ْ+/'6=~/k 4'M0߻#aD)>%M:'}ZA[Q|`gv0FJLjxmFЕ'\c>v|d"qSd]`a8j X\^ &>ď)\{9lB0vÕOO` Sy fh-\:2x}twmzØܳ_7b')޺kl\Ye|"MEy@߀\೺Ͱ49OjBz^%i<6a~8[kRՐSN16Gi C#+ *Rbd>4r?C H;u_*I寓zjdx V .<)-~p$Y2Ԭ3Q+eat rBF!KPl7e hpғ?3JPܴK(NCc/2z~)ȿXAm_[͗]:q u ੷Ƙ)5V49Ρ\5~i5Tke2ZG98z)ߩ+gU3)Hy "=;a31hiNYKdpE+wWSsS~9Z3x~1X> ~-{ D7DpY@`5D|62 F6kerõG@ IzB6hٓ_a(Sfk5dn()$k+JJtS1!dr/`ݛ{)׎04Pij/AqO%.d OM#]t7\ziA/%t!T97\gaה2DnSVrq.̜X>xZLj"Hn_j#_-,ϛm?\5OA^*ؘ->[ZI"[A_Sxźl26ݭH >Jf@pOw/NҞwob; >ˆUc 3UtkJRD" &AZߐlx3Q"|T,[\,! LIɝи^\va!]rj,+[汓˄ ri/vzNfSI^Obcn  GfL %A;S7spSMnm,OSHd>_ev#Ȭ*v>  YFi{kGe '/w@Mu>5DكēNpgIa>~h{ (~8* Mg,_1' O]ݧѝ ì^[fXkt]+i $ɗ[2H$.z#UcYN믙 1;Y#wY5&ls\j uOgl\,kϼn2><D1 \`]d-<1bafVC ˭@-+nYƙE npCjq\zv_].鍖5BsIuoQ.I?xL^๽ВK[xlQWA?|=EuhXic;)[ޔi)~LOw+tH|¶NQx)ջv{qhN6jϗp72v?!M? ҡ<*>:C7sz7F8FC "aɏ56|P$& qQ"kSZ0DTfH)0 -F532 dy &֠H%Ӭdk&nzbS`f$+#P_\nlD;*]VNI"KU]r {-]' Kz&cJ]bP//x:}yg9D|mM7;'w[BhhW]DKoPЃM *(aeՆ'@p:<8 keRGqB.[H&2#of-<dfY;uJ?\6xfv]~Y^p&&P5Jd ec:r%/sVvđ<ӥDVrd:+zZrq"|Xu.%/vf%j|'R{,ه;D/(/O. yn<瀫ĬggcFލfs),n)eģtbnG۔|4+9[ }㫫 afYM }aS1|e[(f/}dd G~ Cd1> +].Cǣ9Q}Pk#o'fcfkoxtH=u3끨1),tdYZ驲=!bڻ zwテIt֛JxYqeNp g$[Akty7R n/LEXs@OT9 +>W2,OzxSoyMORF'l}RIv/370PL4(X&bXYPRHrr`HFN w>?~u?dA q*\ 1,Z.`W ^wk|M1G?qKK~Dn☋dNnz8`ט@YH&a_&~glC$3njg_o7X-`G썦ރv pJ2W*:^\aE>7q84t t Nok<>@C_o)}4 c3y(oseDޑ;Z@PX,s)mu$vKFK/KL8[b%C2TSK̳ƆtaΈknG:П{JPJZaLӺ+"Ů8?ט,Bh'1]C_kroPPV=MZQ@ԋh D8k| B(o/u@M4ǩ cNDėL[BI_A1d{ wBlr\@Ջh7;#ٙ{øQ vr#(וv#*C1_JR-+'EY sKnf3p1<.wW֗gqQTS GGprp%h9 9hc0c{Aw(m|=}xFǨcG]Q8eTU^p1Z,s4/pFC~P^'|> |IZ;mu3GC/ZKE= }7"S[uepl*`¹³~]yDS \^kVy]rVάr^EoVO)Vf2p>c;ptMO,Е+Q47/v*azxz VLwEq6t01hŲ Zs . {}}?l̋4B^7!25T'ٙ .PehGpfrN5`˚魬75ā\N1͍N} c+sԸr;N\|?{ hי*J)UY/*, 8_NCWl\F<(58n^Y}[c.WWH,s_yV)&w9m#炷 [%R. H)@jC#qʸ']Ahq@E|`b#n2Df04d4[1+jЃT婯5H ~Ce!jk3a&FLys$ eRfe:n0pq'$%/a;|,`^9@3Y%$h{ uLk'i,Tp{ݎ-FPlLhBqKN)a`<a|<1sҚ> P@H1zGkՕӉ3b~y6G{G)$\OO!XR ;cd’ԃw5 HͼA)Ld\?\gNI,5pݶZZA4cm1)zlz 5TýJל/O;/"$߼V"_מnRw-D(1%W;ktfvZd?)aVq׼:0=J|=) N[DD!|"Հ " !n< ECxR6[oJpݪ k+/q Xx:=Ms,M('xsu&ue7Suߡ&rHkeк?{q34Uu.> TGEmwsƳ[ ,g:T_*ӽ/bLltJBxxxdyH [7ʯ֩ݳftHVQ#>_?t{y 7ƹ㙸Ku۟CV2D6ހPp֨/3dXR0wwZt.ȗQ v˲I<p _#(u6&UnyUxLH/z(2}m2B!A¸$.,}n; ^gO`UH61EqaiAڕ=p`]Hmd41Z ,"I?$;C1FZL?lGuزV@-Tf=,)t6|vZY:bl3TŎ᝼&A-')c=4#O`߮5W^4 {A81o}ܶW1@0COKHv.?74t]n,y7p p~A69[􃯢j<)0Нuyn yɤ==, |p4|;]_-<_lį9a>, JPOHs/Y \Ga?,Xn bݶvqGKc7H:oJd#?p5g2ar{i?kB|`- œF&y6{vJ[|-搭}YI)}O8QqYfVEd1m^Ӈ Ygڡl:SQ Gx َ A֟`o}P]Ά ͇.pYQXUN^yؓ(oz!JT* +?U>3: =}<_ P[+;IA| ){j7%3`:.sHG$Zr{CGqC~R(~)J@dn뿶g|Ur Zf0Ƈ!ÁO}İYۮxzh,^73#R6\|wE%iTR"tnLP5EuS-0g7nv߱VwzeX(x5j@.+>"@֌ һ[U /wWofD/(QHtDp} úIYօ%nx 8q78 ".j ze+]=d{~mw;YR|5.cGQ6n9Wzӈ,˶H//(dJֽѸClN'i?<OgAPtřV-hI$RmZHl/ :˃AsCq$|P-Ir a(0 8THJeܼ;m( {h %/gr@ϠcJj0n]Eb(=U)\&M%3 {Adž @dlD*[@bN8ݪuHrd՝lMNB͎^O1pW>CœtuzzZL?E4ͺIplF&6bW?IԴO ŋդd%9076&˶mIVq%8Qf`\+ =*% <]7TBoDzsٵ鸞EQ"9M1 vE<õͶ'×c :ٸ u?Xpp_\~IivW<%y0MlSP8ȻSRgHQz$eZVto p19QZ}@uV=^(;d!﫱תcIz$H\V ,VYq&99V+1vm݊;jK1J㴒(Tw`Ex$(\5>YҀ4f'ܾ?!s6StBO `N hԔ$`GHaǸYl(Q Iko*v p @N 85[-ӠF<"=<³3?x/}J jk? H f{C64S?DWe.xW$4fV!;D3oK˫5=%l>QJ^r#O.ztyqV%rp/h3K^yS<Ԧb oJ\wRNRJMCp)_D76G!atЫDk' aN7^Om|Y:]l4zsK\:_J nJ1)x$כ_Ԭ&"+o^7lk罌?֩_ed,$}ŷhG]z_XypaDnJM(7e7A7umR[| s0݋1;+\ fUIǞ0 ,w)Mߗ9dP hHЮy\rȳ&z,:kf暂G[ldyKf ymT(%4>M&aBSԌTZ <\NYYP@Ɲ[4-U+*Q$|PhqI+6 aw5ew()mqi2&յ/- xQ=4]Ef& 7`뇦2T7"?6r[Qz4s&;*Dܠ#@$ 5uZV~%qC_z2A5k;utA~3l\q>Mn3lJ="6PUF >)bKBij},c\e=$ /3?zXa*/ Y5xa?ަ”L h%ᠳrWE!˪2XYSmSIa^ڶsZܻ  ^:uj+J+9K)vƎޥ];^bgMms(^deɦ/1D0\̩\ݵ&{DۿE㳝;QFN~n.Yi2Jr \ӭ"j\%c(;RS{ֶ@𑎴"Cj3Jýc*Cj"˸ QzWzjzZrq]X-aFv}4g<^oUmjӁn%RFL ݳK΃Խ!|-u?v"jVST]!@'_++ߵ_&$dXS f-v񹙻tFWé vTH2ȉ@G%ajvpRwX`:r kMZpcMr <Ͼz4Y=С7:ȕ9g'=Ӌ*ck{ KY&_@"c~1:Efi/=1*?%ﵷy #-(>ԣUϨH-Y V\"^I$]ݩҡ!0`q)K1ָ21<IᐰIcl8=T/m;&X|j]B7;k:}aD @X9Z}BQ0wOx9ĎVs^iq%-^.;>A]FՃ8PӋ 1!ae"KbkYCS3!<#F BH`_qO{ x?Dv0 #;j^N o@U7p O .Y+OtܩfV4jSJf~H!*Yl{h4G9[%v֩忾ڨCU9Ҡ nla\%oc4/̑!۰u$gj,gUɧ쵻 gz&2¤v 1gqS &X{8Cf:@%m%X1n-[JM)<sDQ&=vVtFr*}lB`i3YyR"q{AVV:bgr}v-`v?exǶDSDb;bwh ܉# y7"4D-N$&@lQ qeZ?z(wY(X@O|!ʾݱsyOMm#O1ظjK: {Ga@2ǺM3gi[刅.ӱ;ūm侚ba8ğ'e7/,BTSw@Ԫr \᪋7%D4p+US=r='>k'Q$v=P-dl%4P6 'RRU VOR$KR@EZݹ›j1뗅lSq V[u0d)$qh&u6INH/a;/V?؅ jMn7o{҆ 􄦮RD{tE˅Cbt˧kzqTb\\FLdIzy/BAS؃4x0%CĊ{׉Ueї(Y^e"bD:FIZu7Wr,*eEB|m$;~$LC\jNc'r əƿ_9JbVǵWm,̗P Ԏ58C>_~֍atgȭڻ n(iUie ת7^&eqM]FyeEKZցh+G0dB}ȪĻ*h[ƙm_Y'7z!`S=({&%h2g/xCWhZF}]T$ (xo%*((OQ)f=[ ?1rzye>Xq*s&n (itg7I=lHkk3{7bh6n }9ta%rI-~R;*_?â}ڰaSo>5vGbO/F4I?vuчskfގMfձIO7KHNuO(.P͔|l&lE/yf2'W^a-Xkrxsw*M`2@ ѯ=d'^7a# Y%YŢY 6FKKR xcHR&hӾ_q,,*gMZ3U C竣(?Lw& }bi >MC%h.uh(8 }RFl|`E‾A0R p> 8ifgQ(jPXu7V,n&\)7apb3$ "Aű1hl(b{0DO((,HaұU"^YFvF_yp5=JFTQv*Ptq(?7w~QtIK-~}9хbIF} z=ns OG@{柮+#{SwGoSA]#fj E ͺuFԶ#d3\E!9j+54 0Zx ]WM& o`w!':p5&>_GfUFul)=7Sš2?D(h߬KA:p)x7b#S^;a!xq^TC#&uX;̚+nQ5)x.kА/ *@@\lگ=} O-P{ȝ۵BsBP:Bh$ Gqa[rVg %@cM E/> ES_Y|;坌J|fSvR2PT 8TQ=y5xĐ8[j È(/AjA&d h Po G/0ꏼ'n鲤ƉYK"xH OH=w{D H)N=ooUƷƽEtIAx} pNQLo6k4*a|2Ƥ ډ>\ A𓮥ӡe9FdgI?nNʍTiYc6y= ,VTms7;Oyx4 LDD8b@L|li;* z 2T8<1؝#xf4`CS4mj.k* %`$3&˿N\ ¦ӣ֛ kÁK DKfCL ~%dWgc`Pם,vfފ+tċ*V@eđNKfDVW`S+SBBs5HB[ɇjsY`2 J|}v +w0=d:yݧXN~<(NmAMi+ ^Or/`X)e{; yɧe<;H_oywPxAy չ~z2g St9}A.B{REOSl{0tzy{k%"&$&iidMK0._^:g6F4gA;*,mOexYNdan3Ku(Zh?q9ymoSj |qKCYz; hf4g$XLbxkMArTnJ)f]ekW?7=1 !1|4oWuMI}l!TROQU/],ɡm_ qAt23Gߎ ʙ'`;節 T)_*dNjsp Eܾ:^(MHׯ%s{r5W`TmrD?IĖga(JO;dlMIP"hfOK;}%C6f[@rGB5eB<_F` {VӟF빴 >>^}Jc_[ YMVl+ͣZOv:xUu=  IO'}AL |ٕ ;=]yoV8}O ɄWJ%ZXr/Ipʭ.앞]T:u+G1A0cbW}ѶP$qA3܎ aHOYjLEO)6ȇ WN{@(" 4zm8C+߶e  :U*hBdO|`)J ?J/d$] -ul`;!i\b\LM~EͼTuZ,|OFF  Lķ`219u1? F|:]\r>~LXc[\- IқfrW `mB[ez!tD,.v!"rȱ{EeKT;1)Ff|Xh_$}t7x[z2t0nĂ I. X )ZX7y, (z^]Mq~[;[-&煳LXOxJjPkn}VUهjNhE\I؟URs ~^ιE\kSS^}AKM,mln_"R+|tcb1˵ȕǯmE"b<ɟӱD[5k_ƟүBkŋ̴܊Zeow`3HD)jV bH+m10ͷD)| .⠯{#솻Vѓn5tҬ02=@8iX16{K@枾bH\4_(V\шtJExF^NGb7Ms.alc r(CHP}oS^Y SoU(u5,eٷA<;gK Xe}R_6|ɲY|H* BՇi:FeZ4anoycl7t=K:y" { y3xRf{l H4^2۶1nxbzw{Bf[F)luD0b|.ǵY!cz=o]&whL Ѿn\bƌVG]'10 5i"uM(o&ZҔq5x[x` it'HU'¾|:ֺ/4SWn_\I)n@sMN5)Ӂ#pWgg<,yHT q:JMl@z'-{""59>L"X}o ҩa[mtk_Ptl^[HBG(_vcϏ l' In'J٬fٓqqPLj Ҿ+ ^g9GGVڠm̠Z&7oim8e ,}UẢו9 2PD)wL%lDMYF`n:o+VX끩cq껞=Pa_ȍ\k٘:@Ik%,Ԧl66Qq>pwy^yH<* ERrV^D`5) -ؼ|N.,]G 7>ZC9{xfWkmwd9grpȅfcC3s%".ΔH[S(+W'O~xFa/*}DFY^ſ9^Rq@´Q߬7k ' P샴"'IZL{U*x@;01) &{Dbe]kH_:Ù~g&,ɱd>.fb9ZqG-n|,+[4|P ĂH]=腹9k}ci?`@~>6)/֘,ԋ晊~9CGMLdIXN`.{' ђ6Xv:0bMCEɫț}{A)I"wr+l↨O;W_BT_֨:<Lρ:.dA#_Y??[TU=|({]5K ^E)l`}L E幋c矁hai[D;*O/ǿ;┡Z,EiXW"ْdYƐGhH4f9#:̐*mlmT'LitO}t^)*|oo7(OEaۿF8/ݏ?cb/m=%t'Al.}K攷 !=s İH֡mcKY(γg*V$2v {Q٪UT߲֗T~m Yx NG0Μ{%}3zAG^, Pqjt}X~x"8mTlNҧt ̇LM(ambX.&%v> bKEDZ9^Fu!B"s-Xb G3KFj_ɟ Oʊ+hBeZ+ ZXUQx6kS ᢇ%9Cvmk ;o QRz %b<&g锇CDXBH_Q|7ǭWeD6:X !o>ma' X IH˴0ʛnF_Xң}Ԉ.x0#؊L ucbd0"a#(Mj5o%J*|yAy8pH`7#o1Q3bD(. YzO)۹aI\ܖ3X-*I= ˤWv~]SJO Tś7A\}(mP_3bA, ENx; Ɔ9=(iIWB2ắMw!Dվ_Y*tb.V<OgԹ/I\ةox:,6t:FkȒ&XCW+m̲U}MR[^$Xos{da%Q^z|@1|L4C6iG@jKm43!F©WH3Q;M.h4O\P6co"fո"5UKvuH@ؘ́ޜa)h:]zbxul^%rNKʅ `Ю&IK{OoRc%逩vwALf9$&%ns0\04عmdNmSKHTo),1İ6D1 ?l@Q!cCړ$ ="IU!t 35%qA/ccٳ9}{o=nϔ*GLTw}<.,Koyw6 bԡR BӦRN%ĩnP1o%F i6cIy hN-6 ?豭K9/^xCU3 j 6"%}Z?'A/j yxy@Vu<@Q|`G[cA{xdUI]H,W};Ţ0:nPC`wfKuN+3Nf b@Lh,K?w9d#3^h^a"5krί(b ޶T1GRLk {:;LSz-kB@ 1֬w J/B& e `eB?﹢p{Xپ]E7sՀ &3kB5斋ඊdzXձv!< 猞AwģBd|8D`Eb 'QAgZWrr^,8:Q{M]}Eѹ}l?(eĪ!#Y5iTElMI40B,v8hW3tBkPsDyO 0jCn"~.f`)?ofs4W.Z1kbFd@`87}T:Ԃ^vHk[1e:BftU*TqxL^ͤyi^7Hnk$ `I֎;+ʍ.V˔ZI451V'$کq )mF`-"m~DIC6p@$=1 ?~@*jkNΜwɤท+zBWE^/n 8a+>s]kfsj-zhуP aj8nJ5* $ :/X"%`'#!B?%aLJUY6B3uho߫:D7=cL]EAnd3ʸme6ZFk+MHI^Ukh% pwZ dT d9x ZPV~FCAa? .[l u #V'|;0FɉXgR{̓0o[ l(}8/zN C Ccn>G-ư½}'P{5"z/ Mƒw+pl`*NH5ёsML,.ԻT\aA,C5B02ɮQs Q ¿Eh\#pTK" N` eOH ac 5IY:Ybwڏ QU4cX nFq {6Wl5z`7^^lfG׺t[ۣQ9"3:ڀھsnldì[0z]QSY r,hCi).%լI=GnY%wc"G>{-gW|O ?%uS5[@w?EUo |m CAZ8?9W5Alk =dhJmcSo"x|,N$E.B>ϔ_?O,!D5bԵY~q;}d%6)ףШxǔ)n[a Q (hB?+o!x`5͆_]T\Je*gwңt(tw;o7h&&g~ۼ`V}Wd3 mN A DO-JWT^))Kf `Sk.Zǿ'T]m&O~Ew$$\4v F[e&oÃuzq84Ԣ_,Ĝ1vϯ(od' ^2nc?>!?hmk)?f at&C:┊lJBist9!:o_S ]qT[ec8/24Db"l RS6x>$;8V RY@M -xrDg"rav'XaEd.D<A>lyVICx"I8>B j+(3 ڊ,ͮtgܱz09*Ô`?;D-(mڪj: x?RƌIa"n6L.R5n#pEO\+LF|'Ii2M;˙KXQ&x7cMءw0ڃo+^VvnpWz]6N7j0 Yrz&p88ָ.< vgQZ`'݉)m_t&Fw`ElIG;V !:{xCsTuوKR