pki-ca-10.5.16-3.el7>t  DH`p]_G$ƨ3`;+l p |D̀{sl1g6JRf:4:PbEXVޣW3Ou1Eman3< tK9fsg Bt̫t5K4> r<g !H 3=4#j=C񩺃Y !Ρ}Up_K\ 5[|H8(0ih~E2 5WݑF%€#e @?;grp1w\@,%WdI񞓝ݟ@qTx\h;k>Bh뱪~$+*ZVG'ԟ> u0:I[{LVMy_{]_Υh -rී`mc&|.R SQh `vQqp[ߺXLyJb5]l.I:7f8np4)Z=,"6ȷ{sD>.ve*pPV@澷7E]KƠ>prp6Lhx _Sɉ|`iQ0i4 `y.#7F~zV붍an,6 M8G7T`+9P DRy[䮕I'w{Ѵȅ=|t%>7l?\d   B        ( F L Tdd d td d nd q(dvd}ddPX | 0 (^8h9H:}GQ8dHVdI\XdX]Y]\]d]c`d^}bdefltduddv w8dxdXCpki-ca10.5.163.el7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.]Lrx86-02.bsys.centos.org$GCentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m)@1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~->E,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤]LR\4>]L@]L;]L;]L]L;]L;\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]L;\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]L;]L;\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]L;\4>]L;]L;]L;\4>\4>]L;\4>\4>\4>]L;]L;]L;]L;]L;]L;]L;]L;]L;\4>\4>]L<\4>]L;\4>\4>\4>\4>\4>\4>\4>]L<\4>\4>]L;\4>\4>\4>\4>\4>\4>\4>]L;\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]L;\4>\4>\4>\4>\4>\4>\4>]L;\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]L;\4>\4>\4>\4>]L;\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ec475f75fe4cd7ddcb268edf34a48bada246d2d37741363a87888ff9296052f9a02d78fd73c85cec42ec4c1823cac0c97fec0e80ca98ee88a49c90029c59e4fb20c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.16-3.el7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.16-3.el73.0.4-14.6.0-14.0-15.2-14.11.3] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.16 in RHCS 9.5- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.16-3.el7    pki-ca-10.5.16LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.16//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(|$æG9~jU:1bڕ,܏d/^ǯq{h2qBSʎO]p>oX|]Bhjc(MfDL|MCEo'9ͷCѾxڳZCfQs]DQ<-cLJQZtۉbaN/dѭl> hI9~uXVhy+4@sM޺\* /9~n( ]_dl-gUD~KhԀ݈~ :}a@umG7;%,%?[!AmOX\|3ȧx8^9 ̆3:6mu{,M|tYk2Bь!Wo&_6==r'Ee' U2#|8rBB JeN'CXUo['ț‹flhaS7řÊs;!S֗Sh{nE[d|i=ľ4ԗyoo u*@/R q71A}eګ_;+_Rqư-}2BiጘHS@@!k9 KlHtr - = B QHv?VQQT(ZkQMۮv摱|iX =57ߦ3fֹ+ǬFMc9k^H[˜r9i&|S: ^g{Ї%Ψl Áfo%>WT<6{'Tx2{ӗ%ɘ6h"HAHk;=%_DN#=*kU ]*W*%ۏAn%lUEi/T>1K\YmY?k#5f˸K^\ʼcv6<GYtDRiɅ^Zi 3A_CnvW| <rC*j;ޣ$'[:(x (cIŦ柮Z}A!ZE+4CZ "Wzs8#~Y)•F6AЄ@zTSK[&[C[h1Tۗ;:rG~Kakݽ哀5gN{ 9j06=-AЄk R0v2qq:~x')=i P6ԑ4ٯ04 BmUnZcp)"ÂZV$\|_\!g&ت' cJ萡YY[jf@5:OgupD3ĤzA|깧Kec%.,3dܸ^5xe3pXtd%ikA9/SN C"f;5#KfMQH5rT+K^1YHyU厁DG ;X}!x2 j8G>rʏzS~EɢiT^>yD5GV`fzo֤y{y,4)r܍|΀x"e-ܰ,.‡mw8(j.=I(ݝ#;ـ݂DQ̫ZtOa}8G%~2n(1RȌw^O!t`9 !d`*x$nj>-p%:|Ԗ9k H.2tYȉ?GQh /޳w Iw!ՖV? вe^ۓ䄀q` ]&Egܴsԛ~o)x>Yz¼ %ڀ%=Rv)-)l!^\J R>;g.`_ḿ : t g}uwoNI]B%q TB8 +HdꃭwǜCޕQ z`Fp̠3>JckBpܨ- Tɔڇ,C .9ܺ稗HFCb,V>%.jfgs<%7 [8@X1-K54hw.萒ZIi@6ߜujAxz(Z9^̻GAݘNij4 XWqL⺝,Jy q,CWgWVkF ^xzU*k)mJ H(Ad7$8*YM ھvxJiHU[3(3`brU􅻳 鲆0W)2g$aFO@gၠϫh(-7T7"GC IF.3 ! qCұ2[d/5bio*{q8c1䎥[JEGvs'a`:˴%P4{A#a>\:C- MBŜhS{[! uj曟p Iv e#pgs5N4 Y P X9\wv@ku6,8K?lFdL2nJɲs,`lv8~+]dH/E̗KNe@@q#䗔HnT)M/yݵ?7,sB!&[tvpFE)5L13ʪTm,;Pr5?:v%L(!f@jG8F_L+= ժU2l5:BA"l CK{G vS)E,=rhYg$6Y@<92//1G*'D6dqe8 (i\g CU4\a&d9J@3&y8D9EGf;kL,c*!?l֥LC>0g(z4sA{uV@_n ֈlp=iy>}Na2%RV:Mڏ.5',[\  kFq&.}:H$1*4OCi]>^ g]1#ɏʇ8R}i.ҿ 5-%(J8u]-k --u($SU9wbAU\vyd]-H+ʶ-.8u]^%0c:<:p8} ̛3~1P[FХq bӜ/͂ޘ6ܗf̽au2]ݏu֎mw"S_ ٱi(|-/OI<^$DH`tJAZVx^X;avq35X7lo{7=j[Z3|vPb\fso$W u4 ǥ9sTR/tl;"?7zG{co}-|U ˛Ըj@i04/JeTx K;וo[#;Ǽs$fTw{R#pw6 9zfP{WD+㓁xL7y eGŲh ]mN l$6\[L63Q>{ЭJ|"o(eo 8C 0=%}qC,bzL_X2ɩk4;)p]@7[[4E\% `~P7}N֏d rᾸfe-WIea=1:h`*(1k&}"m[Fr4*ܟ-ʫF}5oÀ] Ҭ8!j48+;fny8R"`=OA+0z%lZ%97 FbU>]WG70-vxnt?3]!J}xZ@,mdxD6w7!x돼%AVuJ&7F ZjWX {Gi5U}I<> grFx1!Ã[q*Navoa@_)OԵ%k@02\*W$Mt2\W/VJ OGĶ=R.#MdC>[Hnަ^co|LRw]ӣ}Cuj H_c-HmDd|6Hл-%cJi״liuXW5*+bWNiT2B{m[0 ozE/yC<#6uA!Z o~?55SVêd݃㡌\⌽!%\+W]bSm5PfZ"05|0L~h-S%گ@2W=J~ q5sơp ~̀ k$e'y!4/"Qi {F2RNADapQa?md䀦do5zm7!6uoX8NȕX"YLv 5|ҁpgyd! y*i1]·U*Ndp0K_[QsNmKϸv`[A ;O QGZ,UrڻWGMiwK#vbZ s!r2(~rq DQ H0_yF v2Ke\!h3~F l߆ ^`įp)h5,﬌ Ay2 o Ig ɪf rP줰!㗝$aBQS=S7קּߊф +峆(˸e ,٤3"/XP,=Aњ#;oEvi=l+"𜰄\H2 v~qi r(%@4VEFv֞c4Oμkjl q ,Ep98ӞN<\#*6 w}n(w kPs7¨;*PWڅop @Vk95j[+czG#V@dE` +~<-wH}S'k ΓɠvRX-TC :NRpc2`Gm:5d-T.Nc+8z>HJO!\aYRl g?PlH{5K z>'+pt~u]| {Ňm!T.]\UotQ6"mzʠ 7aBVVWfLUbg=p7,t4@!ul7PįKr9s%{x-q ctGM^<7`PH@|cYgFFw!?rD LIa? ͟uklę l@A7r g^ &b7B{V-~VL$2b 9Wrg= ?]1vģgDSLB79cw6'+aJT:G͏)H:d@iN='pn+@k RUe"1S!少~7nSrB z415**9f9Əe-kp}"r ۶Y>KN~'(sMgo⾈1(dj0gQp<0yW3&q:M/Dp{'J8=@QȮvp^ſi^c=T1eԒΔ? 3G1֝yuv; =}&VR%akOz f"7&U L:Lu)C*N Nծܓ`*ʚ-nPJ_{%7b{(ޛ[p/y x_+¸U0@pt`]{-3y烈n\'R84Q 2aHC!u#ݯIxk~c4X9TQtMa)+[pAP kV˸,y5,jH /a "hr6#UXoKR|]N/8 Á3qdզd2AE:GugLޔbqQ0o\~C0bu1<) MSvO6c7#fP6&e观/Q{g{̽h0_S8d_EȌ Ms5O!0'ٵ(RoqwfTQD|:Z"_SC<FJlosW P j]pQsDZB3DMɤ~гcCg%ME3|}s[} 2 k 281oаQ#Jj"~=yf /vUT',.L,[b-zXʒڑn JQfSb*I/vEQn]ӉX%=Uۚ:y3'>>";g,oV߹x!BS8ne,c[b21=?sI߇-D;53US ^gMf)ҿ&3XwBZ82\K ;MZբ;aޤjI: ?$2Ɇ+IWΝüa$@t/a 3J[l 虱Ie7PhKup *HNؒbe|"4s$ jd}sִD#B5WY(&s3\ť,ZV}Ӫ2+H'ד5!aU X:I$XbL'ہY໒H aPXD)=܃%Nli^4!Q'Hܡ4%!Jp ^QVRIiu_R5jT,m`K6ײS#UlP\ZrXhaB"`ÓZP)\ku^WNtuT=#̇X'23A;Yj }b-"em!{\!o 7Eo s 7)M 6Q9؆GWO&0/ m$M"]B*90G˙ӎj(/M|yEi\EQ(ƪ9cw $hJ7@!DSlcVj%uX^IY(fI0!}w R2= 1)^Q +mͮ?Y䂀۞{%5kс]6Jr9c&H<GE*e$[ ;1gI)Q= MLLz^@}V淊/uMrP%G+1m(_3=R`VPn8:@jYR6rc3t(uX Y27-a#ͩ(3[a)Lߦ8m/9t`lIOpzupe3X% 3`Z2 wVA-XVqyE}f}=da4G%1ͮ 21,+Љ=}a! v9.BOzKe%g`T/qÊO *+VF8JڂL"f} e2^a;'vHL{4ֺ/}*$wю1U6)Dem#BԂ\{6ѵ8wE(v7YQtIuN>N?AxJ G1!L`[Q7a{x Y.-"Hs=i)ɓ8PjF{*"$>UF* /#{LGBZԐ XiAI;vLfNk/5O(^ MrPouj6%z3&Q1 k*1υﵻwqlheE~|($~Dˍ$6hzd\lGq(ޣI5'_-O)a;raDԃ{g!,]eJZl4H/oمzs#3+{ 5Ο-pxW ksM&i*(Y^R&9c4a(| 0M%fٖR6WdW0^x7G;f;ٌ+mQWsGM^xx KY1ϘnK[,\:65. M3ieGX>|*vht\#/ 'a0s?|>9%03<Ȭv |> J@Q= m77)E0.Ert^KRV8EA1[=ֆ徝ᒟnf(y;\AT)]8.\(c2Ju-|a؇sİ} ~ V)s{{ n_PAL!>ٸZMR/<>Pm! Ju{So4Ղl ؛5h>JRY_ ;+UY:zL+($F]T"=sDy?d& 0fqk&4Cf,z>6 ?wN^>F2| ڸrl<ˌ)OxHb-dيHTkL=Q%`e4b3Y.smQpnRss|Y gGc^&ii1UP49NsAKeÉӘ'gg*dlK27Hdg]i)OyJOy0dڭ'+h _?JQ#'E`IW$~trgV<R>WNȭiN)FD~z6hzy8%v0xmr({Ҳ`0B_~!er5+8*kQ96:6rbsΡz!VyֳsR_Gakp<`2i­ {bS|VR흵2rsͿRe*!}e*R0C \%C젛;ɂvWTBhh\{igZHBGB΄w@!S|e_Liϗ4tvIY`hP 邝-Τk@J߬Fɪ/}Qv'@0f ۮۅ8zoz/4P$tΞpGrGZ ULCƕ8l[BN/'rd@+Jc⣐Jљv켡ՙ̘R!CaAxB 8ǹUX*N5}4Zf&wޙ}kuݹ_;11:/_=d2ܪ 7þ+# MgbY>kE:%u^n;AGypV^w 8{6:(l`Oc@}p@P/2FZ+杵6QJBSAFB^삙~Z^0! t=Fl̨hcBD@MYG8u0/S*9ّ]AGa!׫E3|S:К,lWn#aG4E)K_S.wnV~+aJ"3][+ш|AX|Gm_`Z̵v 'g@ &6dV -Rjnm^93kƟ&Jqwh5w2qL'(׵5Tpi:}>5'&$eAe`ynC}<ϱ* FDlע#|EͥS+[# L[0*J_wVAƃb~@ !5 "h+۵\O I_b+Qo^Jw[{u& ! >Eg?ZesIwcLMg g#Y# j`3ĥ{ӊy|MZ\Hl9 oԌXfqQ(c`*0ySH-u8_ A91DuzƈR `Z:&zV1CCSI9Zllj*`f͔g`~ޓ獈9lԩCN^aiL/ .wMml gⱋ*^%ye[]!tPf3@!jF);MjȗhCZ=p@S<3 ,qni;Z.'̔ +Ћ$#Ы0?8ܑ6YvO+M1Z΢sjaԔ DJV%L{h$?h;Yڅy! wnQi{e.\ښ,7q Z=~߆;/3n_o)Sક{e3#5Dt3!>IkEnh{8Ύ^8>xgV&q)ȘU@BxtWY4_ޢ;.YeoWGHHdlDMMwh {RLbFR=y akd<'d ~{rR;B"EF+N ?ߪυ:E<ݒC/|j"Vapaύil^*KpsLo\47ъ s].WE0Qw ;7,,Ϲс⢾3ܝ !3L^QF47vō?HWRBJ@A#YxNt|]`)זyW&2ޞ"^5O~n?N ծP2N׼@?;4ѾC|\)rLq@ ]ڳ2(ByTG74z .Nm*gsc06)GmR7ubuԆrY$J| " &rPm_2Fq8 3_mWa|ƽAWؒOAěW~~W4 b*/JV.ϵ}j T-y,; P d(ͭ9twhI9fE3HQ3M6 [Ә/1jF[TlF {$}.΍o/T.:c=%MkqE_;2씶Uw}&kXVǪX0ip钰SNMR^ _*f,ca%v6O^ۛLtS4`фUG@o(\}3@ZټG*L/L]pmZV`n~>HpX& #6-ݯ[.>RE~Ci8*@BqJ['L ME uo3I0,|-L|8`N=.;8:A!+]DŽ)??j_̛Z$TIOFs$>c_l3vΰ/4_Fl<@TŻ~3sp^,+6S"X[fSs)AFiG)$ӸGB²=Gؒ{b)!;sWyWr3ND=MssS%>T^6%\q[0ꖺz$dӮk}'οɑTE]U\x_ݜXr*H'.Z5"!♠gZcw?&¿A7Sy o%BpK k?kq5Oo˔ ҕ_КaeJJGA{d8*DPz1r,|qWkTT|m(Reu6޿Bw?K5Hvx[;;.glD@?XhPXFΩᲳsK!uGo BERh?``ffVGS9 8b3k teAri+ gӜ?+ UcPᖧ4#^VgR=TXmpf{Eyk fM #֕n0IQT>]"JoR$<~4ɋ{ŗ8dj7 `N@n W5YYݵU叕RܺP;;xS7|q8Ʊb75:@ [bLP7Ş{zljaվ_ՂGBg%y|\W͛F񚨒#j~ 6]:jTY]I(xҋ(ϵoSUÓu>i&u1f_Հ5IߞӮ^OcJ#3}P*iq\ώ3er6{ hQ' بElj6tYil$h mSh{fqEjpԩo=XUOMIeA)A;586:s5J| gF=q 1$3> '7V܉st>glN9?Lc /EBzw|]UU .N&VDaE7n%^̺DJ9rj4s AEgt*\g:t9`\s#ְ٬y%<9tqjY9xT\PZԃ=ca^8RidXs ;G{څ~ s}4+rFDh5z/x6c5&7qzTͩ<}@؉56Qw`#:W(k)ȚăcӭŤ] XcI"p;\!Ϭ?^YFЌ  ھ$)B|2c _M_p-iW{:'hȞV~Vd-$6m씝gT͞ sDA uU}W$ ~')Մ^R<(["YpjU{cĽbIe[ 8m$l FGubIQW6#v2y{F'H1!v#5$-yn#`2X6~(V7X}y1!8[NmK:[>UXD>Uza *5zX2_ ioYDhw6-2+&b{`HzМ0f7UzCOP' B"CKI->Wtxyi0Y;L`d}%8Pv69o5o:hau6c9s)@!Eo,7Fj4.3ZaM $ NEO\;U"~ۭ\ڂe:$ׁ2Nbz@0cL*?v?Aӭ#Hιr8a+gV店J#,m A$_Iw R`Cf'M=LLfqQ {/ь/}!g~NE0H_ؕ3)< +{EgC,\ /k :}׭,3F ;NpԵP}f:{~u dihS}tDFqnAbw{H-K , i[kΊbvNBt5nx)ôaD"MFuZ$UdLG7u _"$^y0aנ\nr]ѥ:23WzAMCl A[- }{q,2Y'({(ʧ2rQ4},2!m =BPѤ񦢁{=/qj  pmOҔ%tYta7zaH# Z㶰CE+4nK6G8{t7u r";J-S`+^4IQOeDҫeml[R*|thy =dB^|(J%: h)lÿI毳nn;7rhqU-7On'Xop5[ LST%hxI!Lv1T+45~yUh蚐:T Q{O TLm'Rr:yS{B>p-rF*Aqp%}~KxutnE8[ Leڐe3u^Cɖ9CϵO'aha7ޡBY9"i@ wsТ{RR{Mh-c.[JPdvY+F޺4~^\p_PijXFNE+nk`'FuuFO㜕ÇB,IX 7W"W3yAhJBBMd6'8@x,4Ef1Dw%"q[ոeWxk29qdo  ݴC@'ߌaCd56Y«c.tyШ}µQ l:TT~SN.:h#$p)bM$3;l'h$-o"dLӱJQ˨',3^68,x΂,C }=.B)́UR%:Ϊsz-Dfc]R[|-*/JP_ǖm,Qh -1"29TcO1׈dV":+~`(Է#6¾r2(A9_7e>)Ƶ @XwE2b78 @%g˳"_<{!`ķ103A+]1?4~3~wvK&HKtWܿ:ظ%^E[uQ2oXm>gRO"H9wu ;O6ƢS\~ 5UE1!V8'sw]oꍛDd>T.vayfh2I`#d[.q]5G*J~r+nޅ߃쉨e~o&C"JF%$7'G |OQT,{kp܌WR!~w:/CZ;_DڵxPfBκ<ŎV*uFI $\>؇6 "h~{K kvïe;M)q~M(gChap O)'J  8նvY2rP5`Frqv7}7OEQVSaʼn(;BP8\BZyd3e@^ChD &x)G:fE%g҆KԐe 4ǔi*oQ({jz<忄6Y~=++HTٟh 3" /RT|Sw6)s#+W|X_!˩ p4[o) ғ{j W{epJO䃺ܠ"G~tOra6t<NzHa߇b'5j;B 9(޹R'<[eWJ7: XjHoXe y&WԞ5+®'0A1rbuM=gk odZܔ.MSy3(6&~.r $̙' :B=쮄GJmC~|'i)} Cmvu⍵NʳJvRg~Z69qNFu;YJީv"_;rX'Y9FJ[J?#[8MEMb3Cʫ wD.iP}A}\BA\H=LjG,*/g աbv}/pStZIL17R(.oLV8R _X% "I )>߯ #;v 2Pj*tQXn I=Z,3dwZH0/r@7؁&~|ͳ5WG삡:Bqϗl*$FGd'zg2 1ouY=//RGDSy%8n1[.GL_ S I~twڦq2തc'[(vm;ؙ\o k*YUGEF(#IrGp5U&C+rtD4;w6ҟDBԶgk3#2|S [LpPA;TeЊJN/f-^bW'( * =錽)b33M%}"AI!]AtYӘ9-w=Xa%%HzF *ڂ< Ў@ Av*hq?2}/Ȍs`2Ao8 q%cm܃11`ú=\2x-fC9P< w3(rÛsm(&[̊ ̏Ivi1*{|TߙW= Vwܧ"n(V-E\~?2 TCc@׶j^U"s(#_~;4V2C4&$E[= mjdAc~yd\榰2Jxr*aӁx2WQ/$#oI^.aRV,o{'HūrLՇxn!azyXĀP*ڌ)Z~ v;>2}dSz6Es4֗Nz&a:˫QLSz:PDB|fyl=y$K27' 8 : ƀ{A6qpÞإ5 dCDN-mJL]!&P"ԻJ>$*6_Ps>t2\ZEԵBy(~UM0G^ł+f4V%JiJxs(uo[n- "]:Y il.CIַ0c kk!ME(p/O½5ZKvZL%`䛶,fǥʸf$Df%3hI-Oԅdp }ӂ*̩@@9U34=&[J>ȠVoYL/$b-ˀК)pF>sIQMVBY 9̴>#Qd| t0Q(WqjhhêCoZbԇhOʲa,)Wkn#NJvnCf l:`)qPꛢAx/H;dV0d& DtJŁYߓ;|HLLyc:%I/$O)ϹDy nd3lZ{(6Hb@Yn4cÙIc r"RSUJY q,Ipt^ 5vhJ6dAtK};%_uW3i+*0ڟ[ ~b=.fSNWG>LWϼ W܊nO0-s9p$atÐ33sLUė=[UO:t vR 0P/DƮM}.UUy'ҧްUn9i_&"U "N!U_톭U] iLoYM2A"e-D$3H`nE~+ߊX12F[ּw:oA\#%R1J-- gmCcϷ4"AUXSApwԅN'.Xl¨q?1"1L) j]3yiX*P1d1cLx `w9-/7Vҵ͎\iqfPE$L4 A@z݁$pqXPW7}I@(=V<@,=eZ7Fxr_WjLj'(t !> 1%XW˞6< 3Lpkbj|d*RG֋`]~ D5 M`j(IE"dI80(l,2HѪD5`pˌ˦͆~EMqwo6| j3/Ysj\g_#mzR,Ksn88A5KL{m$Nw crJPXL]+a73XKZ&~^ j= 2ך(*wU8BnȨP񍪠:_oP]]F:/ Gǜ5@VauqՃXT90stYMnW:45AhW t|MQF~HOH3=aւ3P43eGص9QhPq_s9ĮHVl4A-!3QT\q|̀'K⠙5xH@:kҕ/}~t*OBʝoA8F~6cmW>`(u;>^ѷͩlt2aZ$r*Ȉ}8 fxvV A g$͘ ByXMK&JG>W}" vngk޿C*x/-8_RxrI&8x?MI];MPGd<ғ|m6'z<~L~V@ɖ(2ͼTk΁ѝr@-n$'|O[N~wnN-QxxM )S/ɳ}RQ3b6K+H`#qid4)Q N<&ٮrC1Vɵ2%JjPAFA`z!'IƵA5t@$g4S*qQ]&^R]HԱ܁myaDz)@+!q4RLyFdJVE;@HZH`cE݀x8 fkͳo/6+nI4޵QUa&dpU 43LAeS7zBDMȾeK7#S;*֜|\-A#5Z,k+ -lؤCaL,Au9#ijVܤߤߕ%HlȿIq qk|sP;קW.ONw?g\mL!Ξu7eh&[0&{hZܠ}Qv鞅2D%W`e( 5=9ԉ[wgO:[G^p黸xP`a$_#xgTLIe,9 K?-F4)JM@isR1^\DlcVʽ8T An]'}%ގ:d^[5fD(}|÷6މT7Y$@2Fy)ҩWShjm}s4 ٱv:HmDC=_EDp8fOI~pWNJE~Tfp9 p>YN/.EB( i((ZR-;Y *i%'ɽ]_]G 3Iy["ǟ"7KPj߆N#yckud!v}DW#6m"U$ lk}g/\'i9 YC:*hN]b9!;Gθ#%]@;J*%j%4a GR3/2]Wa/<|[h04΍My_k/\%8]^C$pA TtWfY/2RgIeE؀D}2Z` KS~;' 9 4?L[/ 6S8؞Ӱ[DMm+˿kr֝\9IVۿ &WXפ#%5ɡI)Q ndsTKKCqR.){LN]i֎-#\+¹g̳)<%6O7ݤĭ,OeK>(V4n)A;$&aT_OG큵98(XJwZZu\+r{{.x0es#l*TP޻M=N~ Ղo."$-`eiC-a"ԓd뚔Q`sEeFiP56FuNwf;RH;Ay똚yH/Yl?P.Ц埫Zr,`}|պ :޼Ր";"ܺ{OK)LzXP^?j0<Val(LhҔn|󢶖e:BDww~l"Tah\c[8kiC`=J0 s0bln bjO.KN o.dI uwts>@܀mj؛I:CZt-<D+Z]J{aWmң^ EX(K"lo /$m|r)%Y,|/l E!j6aZFax7m>afvhY v4[k?e  0WHLhi4#x"Hug|Y% ݃ ikE\Ջ%Q}Jv:ߓR;uNT|mbS~#Jګr@M[Q?o҅;~^#Hq@$ųJ ՋYv5u)<sl#/xF]g5 e^^ɗf0d@> ~ft\ǴuDOu3յY,Axs%;w\t(] ̫o^*뢞~d7@y#88jR灮U_0Ǜ "~ MK>+P4m5/ɿb2.p!=Ut ŨBwtAz l%rS1mVd mMqʬzi|YyLuõ4ӯ>rPp{uVy-Lk~< g ;٨@vӿ{>fA1hմ4;ɓ]v0ˁI{j@pP.w?[Y O`W6/IGǫؒ]Jjal $Jþs4G' a egbQw>`kyϷF|: If(4Vֈtic蘍o!}_D&dZe2Žt}UM (H(-di\5  ـi>11S6K걄ejzw.( $(E x$l#a!S,"ވؑaM5Y0g f%M9f\hB& !pv`vc >&%%m3L%)b쒝]dLh!oJQ^XA gі*R&@ih;ճҔT G2vA"ÃSqU4{Qy'~B:dfjO4S)O PfiE/!qovG) ,R~ܫi.Fܛ-2%L*UT듳:CM GZ(ztRVօ`L7Xjhú'QsE}iz$KhpLR I3ht(6F̽^Ӝߓ!k`S\pgW8%UvײK]k+BaH7Ձv24wt˶I#[1 ?;߾0|Rin+_G 5L T8+>V'{c]%%daj;R*WEn6չpw"K.!zB l2:ؽH#p%;8:F5"`7_!wX6Ųl[gD;}tf)!p[G{\G4"=:R^7qaKF9|RttǸA'-Jv6-)ieH:h{g拑vkܽ!)13cZBtj]P id/8Nr;p!iނ1^_-INSl/$HytwŽQIݳr)V2vDlGb$i?mCWhH'U y;be͸͍}x6j~6euFǿٴ|"bŪ ŮMxmDMg=ڕ/$ݪk߇!̍2_|*"\IH񡕖{p{ݿ¦zԭ]1$+d>: gC覌謹KI)g0B{d\ OӇ1a]{Y[pnۋgq<[a".:֡YXn!~*scxpG~ՅiQIuT-[? na&>>I)so_v.M4N] Lm#E+l0T_?NzR!o]D <6%;#&HsG>~ B8EfY|G\qƹ8, IAF܋"Vv=OysvĶ\(Eh56| *O )\߼XA5<\} 09C\S Dc&ryR%l4J$Md\QVf!OkEs-luY N$>F(Wqݞ6:fŢunf]' 4i!f+&,!_CKX~ؚL `JvJ ,Yr-"صWU!n26tc@Bv>K4D]VQv۰<,unM;,8EM̟ 'uڪ{,ʸ(tMB尢`ˀP]3[k.MuS0w͔6Yy?$rs=XOnM%Ayb-0[ Q hZlsna7,B$-;,XV?"@VԳ'[12nH7i#dnhe-Y8E9gL_r;angELJXSV.('w@t߮֍k|ɘkd ]k3! lafhBEalI/>z,³:mB%U=miŴc /vUׅgދg{zPq~߯#( d1~MNaFlU.9; Fkr460\(AQvCtKxak=b!0?DM]wyd)# 1L8.h.?S[2kw8䔠,rgGpeb b'@ շr&$<_+S3rS- ?mA=[ȴy G)n23BI@}*p,Tdt#bؑ401MhV'VE^%s(vT!:A}8m Kvs4elϚfÄ nu58zvRX=AGH-zbcU7LTd2R@m,S^ݨܳt9ς;T]rQ4'^JVh-뻯yUՉx۹+ uʇf޷|D>?xkLΑ( }x~*9B ϺM~xbdzB;#! 2#W=nY f:ln\`I%VakNz7@2zref%K2;VX„@fv} r< " o;JthȚYca :G)@d )_cXM8}ޣI](LȆru'tGƢ,+uf_khuM Qp%"ڻJw(?6DKүs9 eMZ!A(A`‹LpD8 pM@cR>mNtyudie51rvն`j߯Cy*Rae _~{tvixhP(غ,% d(P! =ݪ"U1qI4#HҮE5 ڦꐇGUSŹ;0x[ EB ,vxbܾ#7^aV2(nrj':ngr:ڨ;piHM;$H:YS'z)ex)&f $sOn> K?ScuL7.`U  N ;\LG6P,,|q8)z&$dwi ֍mJNg(("6h{Az\UQge,$)'?%uo3[q:%fnU+P4a?B9V+&g鉰 ^ ou{7dA{^ ٻנޓ"]](jY?6DZcF}t_FS`M`4 LbO~ 8JὨ{ BxԏDj8-Z?q|\ - {zxԟ<- Z[ާ q^'!c:A\2WK JoN:dք%J#K0gA!Ǜ8/TdqAoFL\zyxQނ\ բmf NK?FE^A}V#oC)_W1}O_ݭMa'3[͋.؝oTw1g4*592vMW |йLIE{ϑ"6C*2Q'w&^"O[˟CB{\xC*I7mcbrٯɅcC,{,@JY(')="p'-ǼB%9dE]؏Sᓲ?e'~dho+RzqoOijY"9O=q\ ;Л.o,q;0BP-Vy?6R8v07 @\@'a޾Ռ9;Ӿ'|ZI%p` >P! 6FʞEzPV.rC55R8+6NxT9'Ʌc QнU`e^Fr_*{m2 <ph\l]5ˈͮz^,9py|k>GndU1GG#5(G_L RI(v} Yilh*"N3Zl)_q~f}F 8 L0WZfMBЮaP4x%Gk1 FhzJHPBi|lgp~P&"11s8:w􋙦 G"ہR[_q9Ɛ<̆ 5Y?z`0tKtŒ 9$bTR6 9 4B@b^*D4WPpݡM NV1XzkS@%#9zS*|(lƌN@x#TcY$jg>1( &eC5d|a vWp.pj, Q(1 d}*-? {٭2vD6KKzՈn 1]oTL>uB0;ԋƝK5Oqm]jP:tOv,RU$a}# _†ʎ?#LߔZp9KӅH:N '(lNk1mZvv<3ʜN$ϑA*A.a 0qm͠?7ҹ %> I/f'B6=H)kRbhJbI؊VSYו.r _˞iGm P-'h31fAe96xa=aKJYtZ6ٰ(8:%>NDBJ_i? _(‹9_4/yf{k\#_a*'!vG̞ 1ޕ -r(gډO1DKv{2/Bom `7șm8 yW!Zyw*#{ؖexKaH@|h u@pL;7}Vp. Jnl zWTlYMmŒ!­ 46efmFի: r&܉}A}ϡV?k elf!+;iZ7)dQّ>*'G#̖DI\j2ݳ5U&%'-f%AOY¶G2xOye~4"R3xw,P S[h (7%l'mEiZR"  )bըdƀR lz8C{8L))X<sB j$K<0&n&Bqq"C9"<# GضKVrH֢2{"#~(+ K h(RIXE{>r1g p;k!v7Q4g V }J#NKL퉇k^0|/=xNK^fI%(Hd2ks]=T2%\I&:%%?N J9 Gzc;zTZfpb›JfoZJ{ mk1 N)!{ O D,e;f,?KkXf'&BQDŒzv%np7L)@IvuÍ^Pa͆=6me)NF>5iYVK`ـ: "@IN6jءU_QO)7l f/SJm=P3IF%0&sX?wQj+(K?QCs4fF7+) aڹ1xl hŸ汋LnOKÔ"jDӡ #;/'%p͊`ZK9a_Tr!RѺӗTTJDo o׎;OlY"mЧ2GLGTJb Xs.. ` \0 z }3i%s!V=VHս!;=f4U1pe}`_o`le5`N¼yjml{G>H.g9/U枖r;B#/ЖL *Y \H;ghDϼ+D8DvBhw K&Ѫ$_ġᜨ,a|/bsPQ6fD хX.7'SP7Pxi2V`u[h'-И(z .eiPeVd#ьZ+hx-4^[ r XqQ$}eD-c|@zruĐ:>oFEQ6]7[qލUCgԢ@ݫऱe#meDkNT1bbܟRň8=:%I>ލ~znnUm8pR-^`aY0@'hmn]11 FʒگHl^CTÎy\tvEr׳9h$1,,[3{4S}9;e?tw5נCAni";3M`DO;~_jͤAzJ₞<hdv t-2%1O^C`uZZ9U Le vrG '7LGTpFHLYE#=*1;q&b!=T F*_KyB _~';0^K<;8:n;9VOG_C>!Q!orͧ$3c#)hU71z<FQBhc+ͪ$;pbdx{#'~@HY[2Ɔ083bO=+T~;y3^;tA{=SFh`,%ߙ۲cr#Ǜ/[?*_, $o7ęQzZK fzI};]B_U^x K@{a=FS=(Sagڽ\NMg|5@7jt(LG9KHvŸ߲PO):h # 6$8Td_>-FpE28.G- L+`2]z⎅џxYܠ$z)t4#7A~}x"*Lv\B'6MrcFưdp~g~P fS3tn:e!DI+OJkw4ٕGdX8FdML|Q 2[pf)[gӺpX4G#PNLB^C\?)xNI#YkKCVa=>Z Dpru9J6{nl!QGE Z]#i#TY8ڭ qߥՇ,pBs䴓`8d1jy^&֤IWPx Y(NԶi@,*n7icuatkPVIgQ'+* ަ?gem*M;WҳKic:ߓ}# `m),`Qnʭ{2<բ8:LvEKRʁ}8X3p 8uJ!LE|r ^F-շTO`t^jCg&z&.M-L뼁dhXIԱ#YHJT=D.R= !({> "Cgh]ybSwHjK+qʁ[E=fh,~f Ì;~UwW[NmL@zsRtGpT^X;/xu:j)Z:|ʯ ("d|{BESȊJ/>̼vmK_rsCxaIΓ荰zl#l_܇xҖc5rx4Q( OCn׀|۬rĢ5S 7?&NoS~A5Qq_l"w=iTHݚB13(Cj#G}Xsf5,\Ru^С!WSqE"]j';%SUJ<'.f:Ȁ(/tmPӁygrDW*_s.RhA+SټX@N9[h>5w Y=+:Mɂ+T #.H,+= g5d-?C.5b 7?MbF]}-J{bࣻb4vvĹFm 2sC&mNGo?0E$ky{*UGL9+^0(Q,݋s@7&Qe%e"W97,S+h; P\ֿ~=XW,x)Ֆ͐&̛{W懐R|ɽ)/Y;H8+XhG8?,46\mKOIoŠ!+T-#L`>Ɵ#cod{sWp<ꈥ ?aϯg67Gc-dѷme9RTÎmjoaK~12>ϧH2M2QQTS`RөZ]v GyŊ5g3[;Jn$ɡ3J154nID_CO7`/l` RK%I(`ַ[RuA i\#\Ϣ6$,ZR?'ֵGDIW5j1p\ =8ĂZA:Svx2rBoF&JeG)yBk E$D&(蜃$ݘZ 'F_D5c*TwEI,Ddݒ1ĞW;pS;$͸{NVmvRy 9K*,t>raM~`9VOPā$=C,%rUȬpy{N귧jD0d z)\~b3@]})4`'sƻz;ҷ+ Be! t?E]tw1r\ -#Xt?}y?ߔo#vjf֐#Ic@R9{!ܞh%\?+y6sW^pRRsٳbhHk-^ݦ+*s0EȈ]|8in1enI<\/4dsI? |E #?]{F,d_Y(Xi[¥ 8/IK/o QiB&4sA߬.Dd;#y˓`X]VyM?*==j:?"t|.Se|l ̌|5 -1DPy~_\ F}K9r2/u'X/zUgK1E<=rn& 7Z {5Cvn B?%Noh 3 |=kqv,*.fh<; {/^C\CTiKl5/ZtM'E$+g$ ;XnG5+9#2UQ9x%.Tsa0?F\ #@8bi t~>ˠB?%^ a`hSI0f{1 !4oyjp =ճǁGsq0'~9u30D-4,Ǟk7K' "`3'!\ Fa<,z h. [(ڛf^X} >'r2d1BKH=uD.DԊN %OBvu:Zx}N&\hþ!b:Ę/ `OG抰 GZ^e"u~#r]!cyºy ˪܃PJ#_"hl\D{s4T6 x&~wY8/2!,-Sm^l+-xNHh̅!3q0[j#T]$ִb>jɠxda qVٕr['ʒm7b;zl᜙RS#NL .ĭC`UcQX_QU\ S_%]yHEO4!/"x1BtvQX\W?V(vMX Tّ/z~O? Д3&XIz̩F>,"2pzg:mͫ:z ĐĠ <`>RoPQ^:{_`Y-kχdwtEQ(JJ6=6,h6Dǔ ͗cU(> 9!`3aK.8Dv+nP":n9o$>+#JЛE1Ύ$q'\Ë-l|ݔ7CYN.c3D.b=Jr M~>w?RšRJ s$1I 3#y6t>Yf x1Y̞X¯gf[zV&Rs&6X#>96np\[jHQw|ꎅ{5)0V)Jyg$5 O7~j>EHl)w=D٪@.TnD_Rb6s"麯<€֎z_gTJשîN?U4#4l^x} Po/LuDxEK20\ IsjoYl= Y 4ALo6=LW9@ݰκFNî2$]<̼wPG-ݩg PA P W5C͚A ٣Mxoc\wp}~' (d}$̚q0>:|ٳ@,N5KY8_ "tGs]n|>}Ht:ڍasU x|X؋M\#̀uar&E􁬨O0͠VGqZ HW`8D=^#-K[ZnKxç~%7_ bYO?eoXEou5xׇJAމW,Yl k\3w h݆(gl3۔muF3bkn:hGqP.76{k ojCɹSz|`>xͤAK\v7X73jhX׉7_2[Qb kn 1G:YwA3I42S fE15]&u|yY}S:8;\Xj:c)?a9Զ4z3s]NlL|XX,D )5`ԭqxY̅` 5oSmn"ZbiiƩ$Ѵ'f#-`Qs>^)y3X"nkbMH褮o9!llmݲ\ADx]P_oSM!Bgұ-1@ρFCPom >R#g밺iWmgS[& Q|cZH.z(pH^hPb%M WY'$ Dh8DϴE5ȨUE$cHGW^А(xm j@s\2 lo2spLW.Dp㖌KS "NfEp@ v3jl)sř;.˦N5SAݕ n؈by4ۇVl ^~II@R/`y#59oǔ smbA1V@Pfڣ+sIBƭ8[љ%.סv%4hD~V_"zi;^¾DaPLNaEupA̔cD<XPՅ KP\%ȳ{dt!whԟhjApJX jƄ-Ò#*KPLЗqw y-q&7ݩV+3TqD;Mqv9Ƿ@ۅJ3ؖSK^ {>cSx.:+w8o"*\+0@'Jw: (+ B}7-KlWa$`iFu3F)wI&T`4~~2?%όLhh9tɊGj3Pw!H)> #ڦ]Tw*?7aeP4VGo`_d[:ۊ}N >8cxw*/f%~-~M9r6#trKSq̘G; NGy*mLSI79nlCkX{JZxNG$7Sst~N*Iq:o,2ϸ7r1 2="eVfl9$=q)X`E G/~7"Kd.bD)n "oo7RJʯ` 6rldlK D+(-ew8wb4,$sxzҝz@ڮ\LKDil>Xܖ  {BGk%w\ݣM̬Oݘ2&bL vIL/:A FHi&,vtU s/D2r 'U'īEFq>r"CG/g ?mE\sV'߬8!2JJQ|g퉳&$KE])JzZH#d0`&s5%>Pk R'X'JDp64ʘBex @F4h&f#>m|_!CKH>bo-q+Iu`AcDEEUZX8#^@f ^{,iԍ`~s{ 3ZH.J>soFG !7< :Bh\Ὺ{H""G@5X_1@=\ KIҙDDt?rQ+l5>m!{.o0q)rF ɓH&zUC^=l!{̮'ƀ۪6mBP8E21hOi(AR[.(PH17D?8FTA|2>!>{kǚsBqB9ܼ{Қ iؗG6Iw "t h%,athpei$eL(s - g&>:\k)!d—3K.坔ofXKB؅ݮCTo0#x1c{zqn7m2xR;Ѳ R&^O#)dJ2ATC@:sOs"t8{3 v]?Ccdn 1REveIxjL C{MmJfNPMgjq-?.΋PXc4nMo9N/ wVALqM*Cs>td`:h:IU-U i%Ɏ;;cDfY.je {ں\ۼܒoS.IsKU^3K) :cGy|_)j9❚Ut=[L3E[§4Bbf+M@Wjb1ā=Yu9gpE:qF^(+WʏPxs@R1Dc?pOln /X{3X$.jP~?\4Jfl Jv]"+ 5rXEoQ9Ԏz o6fE  2%LԢ3Jk?'/ <@yY/wsJJζ`Dt-u|υl> jDm-8 јc;6gʫ8{uFM)|8+;Z-dcKn`+{o.n\w@7KU3RWCܢKI'R0$q;&a V%,*ĐsDȹ[^=w֠k`ME M5&cW]1&-p"?%k:Js)HjjUTpZmm%Y]|y&P)s.Ք=YGAdž$(Sa¤C݊L@RPe`umUȣdJ~Bǫ-N/YEY:LT-*PM[Ry>Zj!{+s= 26pӅā>ֳ,D/dxfq| f3ȅU9%lp-f5PL)vT2}`|h Ë@izKV>,vA A?ua̰p#lشew T4V:4EkgZM]uѽB̐~2q-Z ^kP1z7oXbF l -bT`!A{z`/\ R]竷Y~m$a3\#Ow;3I5+U7o0Pjэ[c G61--vZe "Oiɉ2z63ݍ}|Aʃ'ŻǘSr6'Cr8:<$1YIŨ~X}-a|qB' V _' 3nl2Z.4YqGg\׸Rk aY8vƒƛ<[7yl> l:b) Xu?>i  #P EZ$3+9%cJ ? 3fع}t(ğ Fy2%.'WA6/((혃po̺zPԧ>}-)la.@u)v/CbQǾLo "(!v7<&9`vk%puּFIcB͢:f\z{Okl@9ny Im&kN+ ;Fi? 8Moꉏ$].V-dh]FA)Y87-uAv뉨/IuȴmgU;1o8ɻ߈*CW <[સ1*GtbT11&NAuQǵ0 7 n{D?aB[lTCVN@-Zu9'JIaO8 ӥN(DQjSO|]@S>8W*|ڤ%}M ~-D:xB>hZ= `|EFYG3Zk\D]Gjd@\\/Q9lWZVg 'e0q>}"6~u}_nmB7G-AJLVa0g\vN-bp&E]D 1wm|ULKƇbNؾn9@17¾@ 1Q#7K yLH7G(xm*J!&b g=XoӶ"ܽAKc WVhИc J`~]B1Ir)GK鴬{qD8nrǍʙF[nĂP\foRc >=_h0tJz%8x9gK󔔠;h@!C@r9X;}=zn`o<2}ŷ4mVx0\ k2u]eByWu6Evw+rZ@+Ģ;dxzlZ.z}h{Kd8%6'$=\ }!m'E#E{p1o.rƵs#oN2wy(1Q^Y s[|0bQz5 NsЮeoelyd. 'EGdJavLhrAa`;Fm"q~= _(#Do[Ӕ$Q@w2󬅂~#| eG#:R顯^_$ގnrGd>.pXC+Ow1ڝ4Im2 Fr R~+_^J!KΤbB7L-վy +I7!s~^@]ᦞkٿkO%VG~œֱj?ZfbӠFoD(# ORWT+XTa-i'.eNs 5C ?nt.b%F@o@ e\=sO ߎ8)NI) Jôd)`^,mj4? r Clxnz,]t\g{E_>(1: hX:+{8> kF_ۡY*灁: tTFp eLXJ8iyQ0OJCTg\HcJjJ$hj:cҍ6Yye6*vp r .,]D̮>{ rY:=m9zyIUbnYO&iB>uc^BM_lȦjj E-. )dg^R=t-ZN q6`~RrT,&q JQZꁙCosRxZps> #^L[AY>ɜJg0~J}px5x)K5 Q%jƟ 鈸qM_Hr C`?cL*-[Yd) 1(ѳ@JEḭŅQ(wTv#J{)8#h'rZ*E6IX;/K`~`Ɨ+~TJwG%N'˼Uܔ++5hͰ%#$TPRe* LӲ%1Ie.wNW(YZ}>z(-pSbOpfHG^n4gѨi1872i3͢&тNH&Ӄg~)ȫV(^A!jm32ӕ00λ~Г8=crV!^\t˭S0)Uyfq' XJl[Ec[KB*mGy/zs z|k n')f2'\mf^<?V *1{$DTGGõ|o= ?E 0\q /22}ŷ#p%=zwp+-=Jr';eNh)rE%hWT?GC \^g,fI>UFYNja$xլ6G>c¢R|:"ٌe~YU,vy^ .,ڂGm#@)!ɫs<рP| S\:?\UwC<[%=?rO6E(S1W6OL=QX: t"nrQaLepyikiϧ#ti Tg=ލ;)IaleE1vUz̫<)0 0:Ƽt O<_4Aϻ;ZuBxXysZ"`]DޱϓZ)p/\P^q^[O8}ҽX_ ߅X /;/ mT>b,M',[qkF_ Lq[m2#̹-Gu]k-%q→ ge/aW*Wۮ%v\nׂ<[w#O 'Ad+ED'Jutmj!9ҦMT!>oMaJDŽ'2(Bevߴģe:P hB+~b>WX}:ƚy%֜AJgHlyP.Z!I;}Y'PgZ HqM#⇝ 4uCڔ/]dK(}yr ? jg\,n`!?xGMs3Rn*l[N8T/C~װqs2ٓ ßmɎ|>KI}2YƋAaF@݁*]U3))yɟhg"\H:ͨ~)d}[13hq30K;N6Y-1;=N1{V}F? $jڜHoscӯ6{%he20RJ}۲'>.I!3;f!yQHŦ_igsa9>3Y$@M-8L_dYv1Dl4OZ<B<^g΀N(-Бd]'vA?w)nd F=1Zni2 4t{AP, mO.bsC=X3$G2vD`T4\ B9^xүlPk 23>}p=wsEbM 28(B9x9BԩMcMゾ7Z}cgj#&gfxAbsd WD{.khGqz,&S삶1q%g3]6UC ]oV\dQOO伋BpN??-hB7*dۺ2W=Ŝ߄w۟;Ɩj!l>m@m.LrKI{LܾZvbv 9P%}ez}),VI*>yf[Zb(x{ ɴ8h.~tfh(;O ɏWih\9bU\/%^FYʳط@hCS{ k,d)Y5D&,=K~Sj/ = Y\ !>V#'N򝚧S%S"t::-bهls˥Qߔ:j30,;Օ:/F܌2! 50x Lȼq Dc >'SZsiA5/3\q|Pm50KFz]%`jl0(n۪"TO#i7EM|z젋]ZGrxT!\oӻF(wJok{e2rlw@vQu8f=hfb´"T+QXQ#!jCa>l sfƂ,nJU=VbBlh v2ejG8*ҸQk*y Hp;j5ʐmio[`wmAC#!.ySJV "Іa?|/. 6Ymr閠a">30dkMn׭%fx {GXN|}ך)Y[tlƒziYw0&G 8[DM۹ ߲du0ˎeP:Ht]b |! C aU< Ws;c~[[E^7nwdau9vTU Yo 䆛#J`,VbMD >[ )e3dJA8بޕuȥѪcT78n|akr$abO5E r%Gwe_b %K+Ԅu &$luEKl)yJ2,YődBg!"7бĥwCSY'w7vzźnJsq\[ Be',} y72(mOɄ#!v\3'a[eLxcYסPTP9(W4qr TO/(7uGzф^(8>|'w:Py(HwGn&\|%W(wc,ꂯ)a^q"M` -B}P4}evJ\0 RoZ艶BE[%,{zjϯ{O'WB9߆Ɵ*-[@K~q %ǔ{;ʔeE0)m:`66`Ɯ^bmgF%B #ˡ`W^;B$6"FG#buvHS:u% PUAƤ!uiUՃ pJe0B5RCX]е&SB"'0wE,g3VWbY"CG *OJӥ8)d/:-U*tu0|ؠg~%G^04 2. Д^ÿnŊ! ֧dX&eS0N~GS!UHu]dԐJIʟT g+_6%W8ZNj)Of |s;9 -cbO?T̗$օwO_:3Ey_b8gllnNk;x&Y9 %n[` BoCo5'w/ޏzk9J5t@{)piM |A\?\z+IO &ne3]k7I.ҾWή"Je>ʍrK|\"Hݛ|+b>U-0.,:(vvj2A[3}qk\]>mZL []np'5a޴<f~轛{mTOmo*bgD4SFzP,? {}x3^EaKL>Н Ji3iiO%j$ٯ^T/=/E6RFb9?7 x^6sn ٻ}r0,(Ih l/sGn,Ab1Rcq {`w"#^+h]ŷ]ȣQVO W Fnp0O}f'`^]jQhʻ02  0򄷲<22vO]W<8`q$eʠP2ƺeR`:Bԯ !$wm9vBit1'b Ki$XZl׷ =i6ꫧFc p8GY,}a(:"A0.jξΡEjM$ >OoC$sǯ>Ph|%Cr1TQ0 4a=ڒ/'=n1th ITzoY\ɔhQK#\H1 8a"U(# ZLs.89>0Uy X&uLW MڪAﲭȉ^t2+T֊Io.]J[pxQ,~S׭E~=7I^<3V3e1t DJLwô.^ n`[t^J;,jB$虍î+x(4TI׊9q?Ud<hDMqf@[|Rq󀏭?waosRBTxGIȖ~u;Boe#_-!mGJ"ru:01;x}ŶI7tS>5&[\t X N:wOR"˄lD%3-˜5(mdL]d$GVL [I`K`Msr"U1]8m`PxˎL/I%'4]ry<`xϼ.(}F(Sh#V>m(#.4C,\hxnRb^KDP2l^@Ȇ)!kt 3WqU+z/΀{cCX7xSb*i}7ιNnX 1 a<Ē};& O d^9u:`pC Yp͡RXKi`qؚԴKdZ"6-X6yQ4k5-aMBe|^[wшx:g(֑LXv )(|/<2WSdUN*øUv-F1$1% :j "׺rcY ڶͭT߷I?CH(pN9Sx Ľ1_/w%Te+BY!bEJF[P2LkhA$H7iRQm#9/p%VWos_շi΍hcEHy-G8{M/@oY SѲ#E_h32T#,/gx#kX\Э9AU!*S!h m~c Πa j^vLFb: U@0~| @؜U* pw c^)%uwgmN,N`mck֒c{*J k 6\1Z˂ WNjI 9-ζ%h4?FrZ] mb#qu A.X2:T3%槕SRaYOJiRI!vѕ7BR?%״p(P>xtV+M3ᘝB#j^ء㼒Ak/ۢ~֪Vb/afxV 3C6ʉ>K\|I!5?DDb+w& 2<㗙='V[ s|~N[F#yR=!?iDt;Ix<&_Z(Vɬ {D?`!wH[ L߫ת9D3BhevTHZC®P`u]WR"LHב]5՜MQxc f^m|l%`e~8)Uu{[Oק( JX[S2 ڇ"‚@T"P.Gr~P;/08ЮVL UG%cw=|lQ?>x=4]ݍF͍VN1^H{*ԓ.kc?͌ZqhBB,_ T>*w띅I"Q&V뤒IbRI5]h+ Ȣݯo6`6+;s fх}OAEmɄgci/P.yP$ԻUqmR&4 /n%5WܧK~<}q%%}Q<z^nkrLJ~{>8jXːcm̢@0MH[Ze4&֯cQͬc/uJ#VFޤ"o|t,gtoGƏ eBp> £|( l?EkA甝xyq:r#s*\tV )`_bp[Tieh)\)`'\:,,n}Hih~8@Rb2*QS⯽YrƦف u\OU؎CVBҏjqVd$w{9`"#-壥AXE)qfa I2<@VLQw#̤Dw@Z$4{R!!6#4VSvz |qw:KR Izַa|5h,^gу^$c\%!J^`D$" W# +5zAː Y4qvlbs`]\ahk)V"J,d4抆4aif15,@D5Z߳WDOP{JZ%P(;r22Nk]\zY Lqф.:+)pwN:FF3ãqʨO.( $g`\EȡrlֺNjTbЁ+2d58dz+% u[CG-IoB b`e hSpp=۾[G~k["c£m~~P>cK^!to֔+.;tXM؋i+4Sշ'T-]v-: 0\A٠BCY7vCq6u2e}. ssכ%LRF^3KסV'vxZD Y3V({l24<ݣElRئ 48U|g&>-Tu2!E?JOn( }]˂*tJSi%`֎썢,[F{U,ѓ+_zs^3V;.\#f'OyxYV2YX<ԻvU.qIWѨ_`]8=VR*ڏd/Mo3L HaA):&P#{ Ir2Wy}{:%q>z8@&(0_ϲ}~PWC,U/R=O~$@t/c31 oc:p@ʍ3M&EeMiu[PYho@m2BV;, y4^s0i/ <bi"A,Qa"RzSnq# #f}c!70TrD4%Ľ>UWa!S )mڏc;jP1į|N{H[g<7>xf7UkiM`Ia:ֱ)",}y! ԗ87e3<ׁ\9ʪO}TYzA?4ӵF/~G'?3kUV9^HI'Jp6k3vN1+A-8dȀld] W %V.jr ˷[hY&ނJ رDb|3NoJѺio g+#9%PƝt6\Z4dqXLxG LwNvMzfjheIJwpF|LB]T﷼l$dce4/ x嗾&gdS@مƘ@]YB^Y=򮤐q髡&9.&êkq1NͳJ'vgByglQ(G#A\{C$<冢8ݴ4KB 8n|GKWOe >WtX=-g@u|-/%|)vP+ԄdckC[ %: Q@ܔ¡$g,N6bO$*_wnYmc -OW u_wUzA|$O;CũUZKk}%N',]Ыmc"2Y%{Q6=Yy-,!f(ui[q:IEmPVƫނKp&NK1eg\}  zd1|YyIzܢj<^E* 5&.oP[-dhHYD\>ʨx͠PԮ`lbW=Vk<#VdyaU^#"*'ʩ`t'5jѵ jK sb@?2Dn %B6~FG;$ۡ+zb/QQo5^Y3Je?$U}'+1/,g,,j1Stb_/n=p2/^lBvL˥0by[ m`+2}YnW1֏ rഃhMÎVylGPcܱ#%T,k,A'<{VX3G7c;cgtk|SMyJˈ%]x`ؽ}'9yOU(mzU#5o#aObGϠdžZL]nkœ!tR1x`V_ Tɛ*qK=LxW=*"%uyf4lX`'/ݧD)QLQ{=5']=bYwl"='@N` 1q1˔6r{Dȕ&{K(gI?9SDWc j'i%o_ǝ)_dn7.'r Op_ ˌ)I0q#oCb jxf+땪tT@~N) V>KkeG:;*N h W=Gi}u/nO} +"͒H'2Q;J4X5>jDI_TwV1rbYS*z^Dɫ0`Kc}pYӉ pC&;N٭@ s^[>{TeJB O[?xaD*jo2c:ݡfT&E6Ã( 0:Bq`@ҤNw5Ԯ^K ?y 2 i~qϧEO 96eZmͣ^էZp7o"Ot43ɸ1'3}&]ú2j7to'"4j$ xfzW?Q!նs.JHǡuJFY^ODK2F:!{ 3G \ڮ)WW2 G=:p`1a,)Oa\=##ջ$9,~\CӋkJjhAO@IQSS3PB|[V'1שlU)D5|]Q0_,56讟KMZ&T,p ii~96flZ92'm]BtK>5nW 37۽DZX/" X$'oHxAt$u&C-oVux|}8 }-9z;eOyH:‰t{iiPnqPp^HM7TcS-@=$@*߃+Djz`#C?tcA!ғ΀Iߙ'&+%y'\v2^O'+EPֿ/ a·}n-?wrpEyi# lj5Н(Dx@9?/~t/!+]5;Gg4 BD?f7%kS 8aߋRDD9⟇&G?dθsʮ'I6I*CMIVJSf!g)'0YR, ūaQ[wK58.*Z eq☱PZ-3O@U6-6pu6u=+TBܺ?D`N|l 6|/C/Ҥ[g9mS2A*.fcܾhGJnv|wk*,7^2c>YIwtphNY j͠{ُ'SE 4?//aDˌ:&,Ӡ6K$wTXYTSF?(өi$9 VGw0apFMr9/&Lc4k_#LIQ隩@[biN=PVG`^_7R}|aH[Td!,,/GnA ZB6̮dh]+*DgFaH$>xV,ӘjsSWP޼>StjԲe6[ޢN*սΔ>w>747n֡i!$ w,ϼznO\țɬKό %T-(}+tbFxfAɢ'SBAl ƼS]D:<(=BA~xAjQx7Kr9jFf\ !JLؿ1j(B(.b=%<ʭ\J69gi~C]ق2JJm n|YъN\Ek]Ǝ| Q+|meM֛7gEvԢH 3o&yE N >QLv.ol[e ,R[>sR[$L.Xirz%K&Z NZ4a }Fˌ\dtKr3W¹D+_bHqY *蹟Euk3?J{ l[FOV$ ^E)Y/?|譣`3S<8'xdu"nMR:(\uFϱFq &'/`]RwE0s<' K?>MSxO]D}]̍4vvzѬy`d G^SWTߩ%nVOwcۥƧ͖beM9eȩ`9K3S%?sJX [ّ6sL7'Cx MuBgNv?gF a*d4ZP paG.)ǥ.J'35R *w5(L4Vau葤Qt?yh]I8Y8z:fw1߯'4B <uGT{nh|udU+hlA7;"q\]Riވv|dJB&XY iA ߕ6}eR i % ےn)BNt{ck^Ř.C)9EVPP䕉hk[FaX;9@z$+ƙ7>m!X?@sV;ޅa#]8Au*=,0UQ ĸ͊3ε[e|Ň"mcv9 ˡ50W9d 홒>)Vky;ZT,0f+i['J`3f]rW$Gaݢ@9I^woև9y='/2֏qh| #g{zY{Ԣl* ̉Sm}(TwR69lGA%G˫E@ I]M>wm55eHbhFvPúdA\86+n|DǺj&o0I{TƑrKڬw;qs5@{ĵv8S=~z2_܀Po9o 8>êGGSbԸX>!#*mu=Bz>RY(N),)7fdSkȭ8\:cn {Hc`:'Qɟ8Ӈi_U㤈AYv?,E:>um l!szFB[N]8T$3}}#scW.bvPC"L8ľFG[v r䶟GsM fqQ;)҆;A + &=6UDڪ7D{^ȷbfrɞ*RFZw7f[3ǿ; N2m.Mcx^BUgWS(%_\ح*d; B%vQFا=N=Y4TU`HdS "iؗ7[2{ !N>b ZnA\ȃ5SuVRj |xJv-'IyW|HlE&.W ,S ~|7 Gyaj4N`P((4GE~7k(R;M+Op^t!4@M]9.u &m+z' MG|\?j"K h  Sɮ0EdfsEԸ#[ݠ=IDƭiuݜvrk+g$F7}nF wGAD ^g^⊁j`j> usmr:b Y)vb>%'<:LYO)u}=b v^ Ͼ3qƚ/>Q}瑃r]4}#R6624uE6%SZeh%l+_6IYYYj ڳҐvz],%P^Pn FT+RG_(`i\o^.k Ze`EgƯXz1sڗ8ȈF1L<-}&1 b`M2Qr٘H#+{ >-ا# !Ih.H+-5#⿇9Hcj[jҊz:aNK?Cزz/ưVS^n`dd| < .?.}xvac*F(HG P<+ .GZ7"8:~l>!ą_̂`n$".aEW DZFľhF(KdQ N>Fk`I^Ta|X%o_fƦ xAau6L oǰVT@(yiCΪԦq>R=ۑ??aW;]s/|:\S7}/͚ OS@ZmD٢\*H|#+ԧ.RK ) {?{Xn?mW5y&Y`\vx|?9TCCdh#YŽ=HN9@"PO:;]P3z'}Z:l(TO &+of8q&664r`Ő޵ifE6 KϏxf_zWR!Pcc1JyW Z暛! Ӕ}J7jkX(sE Pwɮ @7oլMVF}wתDM$jRq KN>[0EHmPK|2U|SrM.]&sĵr|(^rp-ڧ52zsR]Ow_i}PxOK#AaF*ρ<~Mӵn+=E ʹaxVѠ^v;+eR ͧȷ!@)|*Uޝ, ,'C|9c=Xϳby\5?r .+e  ķC[eoR Ke?qQ&nqF|ʬηɳV@he{ohÇWH➜se^6w:VYΆ?_?c8E\+z/M ѷ"-2rQ/s)L3ZV!QITxfmH8Ymdž, ˥ y;EX.s@ C_HRI%'BǤ]Hp. ֔Jiط7)lD/B{+i{aXWTv~AO&N ɢo=Ũȣ O})yŸK/Enc!.?R$/ NG }HHQ~R; 2u*֔2+Yt^TK[$^A2\dH>GJc+_H˨op%Z3+ &ˌ,MG,?Bq]~!c͢=~q05?g7UlXgCM`j5}ͳ9;]LaБdM.Ǝˋ.k8Q5zUSI1(=?g$?(&7|ľ\Bc9Gut%H#l sYa Ag1^H9L+NK\ך<3_*Uc1G>ʦSƦjSļ!eHn3d4Ӧ}A͍x$2a& /t;ZMB½0G!@@Do/V ᙪ9+~btW!z7oo\ϭ+aNԐTxKN&-!{R}j]Q(ʘ@ݬvEn 3Ɏ VB)4)#$q 4CTJՎ/mhgTE{!U 哋wpdl|y)4:NP|%Y>Ϋm,EXQ{ Ye ;vL,O\z@hf$t*KzZDc04WxΖՂ|bXQv(nARAĊZ7NRv/RQΠ쮻'BY{iBixTJRΘ֔[z>w|0:'X? k,6lA*[Srr15C%C='2g$6 Q0VnGQ'6edOIq?Jä5EX?%#ߣ"<ޜN\k傌*ixFja><( ӦI XtHHtַd8 g˵<}X6%cF x#IdƏU;tfn~ U_R,еfJؠL(Q PyXb&NȳHN*Vn SUDKdp`-ke?w}wC,^>}b7TSG#-5aťAZ:<_K*V?Z)H@q%7l^Ғ"?݁=єVw/x8qBsQEFof7LI]1^Km$[3!3ǖFav#+u*O>Mx-R`9wg;Te@?^yGK>Ud+ V;m^IR{ C솻Hq[sS̀1IrNJB-@%԰!ܲOZyuGbsdKf!of2U͵Si$OhZ,0켿3OUBw#?Cm`ћC]%0ѧ"|oU>xp f٦:r fX0-[E2'U ? ۨ%aVↁcn9dB"v,86sJ"MKtզC#J84cm2=\tf荈03q% oy$>NdWy}we.)%V@D8~*S.[tPzja;ԜdTIF0Ʀ?w E`WZLۭoV)Uy'kFf=7{M)6ħYq'r#eEyp0"_%D0a:҄Zd#K0]3YX"_ _j~Bxշܚ:B6̲صx Zl*BRxǗ9:p}ڍQ^3PY״zjaUs 2."/YlF26,'0adHqcJn'wX Dud)UvyQ 7!#20.fy X &6K3':zϳ,,n!2G;5/s!+R i:`]6ۿE$ g ./pY:y0lZDAEF^m0;8 HIX'p:L_$?6QxvxzgOKtnD.W Oh߉2zd)|2̞:C_tXjmz&{ݲg ߦ&Eq`n7ҹ?/n {eCByqS\ LTE-Nm7C0LD4.\.TM`H'6=esL#]G;qmzqw?,=8UWv=6W׶p9D DG:g#Fl W Gv=)hgԷpWtD_Rg TNIĝNex GOe#Ed7X۽YD&3 /?&L6֚eB[.9jX.ft%wn`sf!8͑n*wSͦn Pp- 1^ܻƧ}!X]mP]p9LLU^g#¢骊0I'I"FWM3R;ĔpWɇMKVRfF> egy$(?kwf1 ;r/E8 }le+OfTDɥUuzOv;#䢿f/'k= 8"zjbV0J(ˇE/ EJ;y"2 M>0yl".gb[ML,J߆*wMgJm%ԏe_KnI ӄCYT6Ap6~?W`x쀩Lm$M0{bsMm{3u|74 XYr Z|ռxv:玾e >τ s0;FR锗b|HXI8bWV>m>Ka?3WfPslDk"/Yѣ QqWX&c,]wāW^mwٕV&b.y8N74eG+7.21 PwE>!`X@yȪgxKc+;*HϫņaSnΖԋ2<TdsT`w `ڟF d&!zzO5<'Ev_EXj oaӢyNϼ=_4HO'cxۖA0W FqA&EB׋@IK> SMՑ$ LTR.xFNk[-{چ:ODh25}&E%b tWDFv^_V.S:_"ؔD9-P<+ 1 Sʯo&}K[ f6>OI_1iV>2bU`\`Jɖ'+ .)gyy 7U"F^̮^^Ñ-Ǡ5#)ͺGD t̗$(rAkSOYL38^*.vfTUC(p}{Ac,XmiiʏvIz~ǂseKMGtXB[30OuY.AmldYW&bXmqm*o8zӭh%p֥KCѕ>ÿh֡I1h&(uymLjN^%,֓ S˥YW_a+z>zރ޵NئMt3Pa{\t)8Uϋ9aIcbj㬗f6P@7"tKSk9nP/i[RxZU:\ *ɢ1oCQ.M"c͚ܹV/jVJ(Dq;8,J p(" 35 ?,M84W%HuK.Rq= ċ Oj \mzniFFn7C⣵%_0I̻xt恘U@ff;nPo=TVbG~mqQ": V+WnJة*=@X 12F'84`;g;c[#0:xf*CWP߬65@w DUzEjT_ CdĞ[YU%x3_.f4;q%ÐAKeeLR~A /|w 4g}faʇER ҜA"_Qv-,ft>v)s;i#<>J2:Ks >ʏ*|Ycۭ5>E OFOIDڔh@W@pZ˚B}zb _ .m*dY,4Bȗcvx?[J &ٴ:u ߯Rxh*z C=sGI2x)gE;v2U͕'R=DTXVzu#c~ewzX7e:dT3+fqQQVK)Eef~ѱ&:zVs܋w[$B3X%/1V$y`w{EHhZ4{G}E8uURfA>ݾsyĪ6CRVKB G D Heȹ6G`ayHtp'E?CݗzWgH]G[vZ}]^{uQ-6G{OؗǮR4)cf=a4xf|ۓK[z€b̥[:PN,ܺ+'R*h-Ukds;klFolnz-ߢ†݂R eX648s@5_iD|[WQv5(}#3;?kI05xn67@nB6i۹->`ǭ| "]Mf˭H8-6yn]>~#{kCo)f"ivx3}O/0!G޶N;휻"zDMО46pҀbb":zŌ>ͼ2%M)W=JY;f?c?GП4 ]-,퇯+4;Ӎpt*VW(^1ՂlQ.t=4:h/UtT[:9h1ȡ>5wm|Xĉ[h˨@> l*I J:x^ؔE]G9{C,ibi #r@-fMq)j}pYHƋzyK E^tWrXp,VjMs6ə[Ēؚo渳Ss0vX=?k QY`YJRPYOk3!|hx #v/yq;~@c֔{vED^YcT4ns[ػ^PiKq 0'Sʼngv(qd ;u&"sAl.gcd,|>'ZU@ 1D7X:^(4(DM4<8S=Q(`^kb⸘xb (K$mE>\,&>^D fʶ#8wG/V*e9y2s/A2,%ha=^u.YH65U]&=ymX^XȜh>g9WYb[tf&F B(.yOPjaeVಽV$gLW̞g  o ?jZ9܋l' H!@8Iصs>SZ%H73]{>ZimҳZ+ȟK?*ʹl矹&/,ѰzxGy\ *ތOWz%,%IqwvÓ+6\" ʄxVS$6-f¡~ZK.N"qq*0U6K M)s%Cnn '0PIH ^В/G3U,],Rҁ}ͳ vh2ӎw7g8Ɓ{&p+ b.r)R1UBp(2)5w F!CJw@;+`ZXcx6x˛34yw!/uF-pV ጐH#>Gs2u 8~h\-1u-(b 4Gbϴ:!w[ǔ|m۴ĸ-H_W!?xi.U^J[o >g^ƱoŌ6ס /BP&CW2KWjG0akR,: S]8VMT_=?MuQo;?Lpoլÿx>G:'9r£ >:MHa6Nglm\Vȏ [k$XdX!:Ct&#s2dVihz{-<D潶vHhMshխ»G>$aB.΀ q¯grk."Q'tHN`& rUAќbAA_%>?ޤ@ MNͲ],y\npnGy}y4𒳝Pt8NYKގhՋ~@q+q]YɵȴHQI{wԃ<03BʗDKsfN{Qg)bv!ZBc8Mb~f4%4:G'2𽹚{ !kYi B:Wul.Hj|"HipQ٧IkʊLl${K5zNAOZ NY6<ÌCq',:˳⪐wjр$q?rX@~ znСܵy%(HikwCnzzNƴa^^^Y^qm&z[;qPt~2O+Bcj!$*ߪUhPУa[RRBD% -S+IWJ,)# CKu5+ivZP-Ai٥}H$sv&><_kdn-Q(\@ʰMʼnV@[rYމTv*8oEɻ̡fƬvOR- 3wjFC`DD> _v±D KA6u.z/dF@ː'bz#Ob1mJ1K?6!kimkta ׮n-{5\I^Õ_:w&v_jjͥ)NI c&ʄPtZzϗ"f]_f8n:/x`_FkkRzA1eN#+P';49V W%f2NO3]s(ejz3VT^_?"vGxҝjnSG@>|6m $QGF}3+ns%YUS !F\GBb޷%%p]&Ҏε^I zp@|L O{?^GOAj(cd~53ŒA59sܓ-`8pO!<3jT9.V #400(J2y>h!nrK-=ݑf&TϗN)D,a"<"$ˡt,}a#:@,s"T/ByB]/ʀlc(_s ܜ~d΃[4[5?"0qss[o7a;ɓ̋RS_O&U;JV #woCەk*mg5;A܎,fko]+A"o'!iV- omu5,GI٦Z1{/g? c R.0i+bH#WMz+5HvZ4Y)tOV >魮f݅ 1ר7GP5t _֜Ƀ-9lG/x(Ѓ^ PƩc-VaS|N9nx0,R{N {H1۵#. Pd_<ՙ!C̯abSz ?ͲgL{<2bm:Y0(%ԹnF/x*u9hNm xPSϏƼF}VS;ȉ'ߡfZMec8[/╊z1Rem>fnnC|qT긐CYuV{=!({4 atucBz 'o+NhGBzx7uUMs@Tnh<0 fBT2y̯Zj'|c!Vօ~'Z "*4AXS=U:a Y0"j0r.OIO`F}ŇlOO*2_ &mg$|Oljq=>`}HiaA%{XǢem <ؘxkf$t$ D;)o#;%m8Һ}tƒ X':]}AqDj|ɿO{r# RfeAء 3@02Tټ'癘0$ {)XK4 #m<6Д% ԻkPsJ;I7 P3*f&}x]?@Ȫ|bm!/n̙c.v\T5"8}9swQY.;fmv:RxRtϐ'*˨["Vɶ7E 뽠t9G#҇f{}a0)J%ɫŋw5rI[%e Չz^] 5)F2xy{ɤTu4xE瓦zxA!F舟h Y?C6TWIJwghܦBrd?y.$NW3D%06|DM'TE5TlT Bۢ6 %9<3 3(,{0 lcOHi r.AՅ/D -o+Y<ep̥ƌ/s-5EP]H1@UCoQ\v~ʭ4NBS,fF+  zEt2CM1ѬgX(flԩk* bβ!V!PvaJQ'p*%  F<*FJ,}z=.49ߎ˯`[Px@K" ŽF)Sfbf3T{kCZ3֩HnMr4(i>C̙7zNA[!%VԞgqKZyzPCn󻫱\RfoA%pGc"oţtD[Tt"±+E( m$uZp oeaV}Cq' Ǖ 5`s,EH+?_J &l۫cj;2:<]y;S_Wp6~8n)!d K3"Gzm=kOQ->MbSBvMNO$>_g`%1 e26pq e%Y)CTʛua`P,*EQ8 ۲q|k1[LE!`ę(we3hc1^fcڃwZ.}K0(XB`w~aT=K v@Jf ]&b%*4/\&ǒC;lVZs8s]Li/O t ;h2| Hd2Z0z5NZH]08c]ƣ۳x U.qX3[=NkLZ](~& ??BZj(&A`ػ50kMWF?V7s*aG_-Dx0 Ø?\S8G`,77Ɉ;p݉u{zݳJn]|ѾX;䋈δn0wW;7,IC98f홋"ۿ 8rڹS we4@˚(=KЊrDKH9 `U$ѝjMAQtu}GUنB>;6U-GYQz %J("*?I,8CBh^7g :aR}x }e^+ɵ?0<)Mn k;N)Нt*2f{֢wΝB(OdG¬!x(|^|7k6VS_aEDDǝFM寸^E oF0v. oK w#q5{2i>|''p-Z?3^H/u̹ `0HVl[4V8w&~^+U˽xD?:9 :on}+dK$. bܔ%z 6֊]6"׉Dj6/9HF2GxȜoBR7iU,ɏkmx5'b4kO% .qh/NO+z3}7CAQ:?L+/_6oJT>wұP: ; o"&krՋ#%Qۚ;WPi»"rMYx˅!?Ȁ1RPbY uxKe[Vd\-3HBO$wee'P|0sbe\ď$O?oiąٟ 8iDt4ev*+Ym>-jdhG3DM`r6hΠܣ ;0i :҃m ɐ m;ڼK أp&EX.@=ӂ ݡIJ,á(tF/gES6@ I<(6k&Hlq[ٛ$ ]}UqoVt-T3"U&,_vt'pxA-~7ۿz7PkhZ!N;ɡ1᫦s"nqf1A&H1 t9` ]y=w&I[E)c6>+2ֵt  kDtph ]]q$ >5J|q{w{, y%垦(d*-PH^Qwc1bTrp*VOϣŗoXr}&>E0&hƶ+úH1yuz2i.该♌Ʋ^i'b-U>Ő IdO';bӂۨ~먷ĦT e񛗟._uʮ3Ϸ6C-t/-S~^ @ ?J)!tj{· zN>,?"kkd\S0 -Or8O0GjtOzB[N1\ySvw.tPgD[_VO ?oWlŐwV{m A4z3-Q~h{5c Hų{o")LeUGܫS z[_a'<W1K]zaxe@=WGc2~射ʼn\.`h >gȵu˿h;Вcұ4hh{ w&NS=OtnH!%TEJq)Fit(9~S S,% sFaK^5*EGoաj4㘜- ,"  ]›+F"2!/.CaDt,eֲMsVE`/횿0cÉ[ړ!@ ~Ay( m_=dlP,ZO" "p;h?h|%M[6xj/ ql~Wqs%6TXwإ2@e v}_W `ߘ-lHnV KJłpaW"!E%R,kvNWKnC>hqj_Bײ%r>x\Kig*?ymg{[ buZmb샸FB8|xWH!dukV@Pe8,j.#zc;jNsԀr 1RM-,i 0UǕ\fpi"[2C,M?9'[h\DتeC* ,rGoƂj{]zCnCMbÜ(n5]n%X+ĺͷ1PC-B/[8rGkD){?jv2`9|CaSEѠ1+SĨV(7ӻ3#6<\"0T8dbO֊W^]N?֐Zl&tO&/t=ZGxIr7/y7Qo)Bw5y{lr)|J5UPE/⒁+@3R0km K]W6!rMMyawBkSX4Vͮlc`}*kƣC.7ZGU;y&GZ@]5HP `Iɣ(DHXR{?ߝ,-H[y8zTCc` ?b\ [s]zݳ݁~IVH9zb ];NT`wKz>70W>E9W_9pmyjFXd2|C"E7!g~R-yl#Ggn3Y{ka!w[jk `ɦsWKCqGC+Mlm_f! 4GCrD#0NS1-skpG#RG/j;֦ Sg@!ADY`VTL |=Fc Pr* )qQ(xa*ɢ۴o?#wsL5) Zly殚d%wZ sbI~Ox8*єVΈd!66KΩ[i^ǫ{m߿Eit.5FL+)Q*^Tm!J/\1bHrI X{ k\ZkjeU.dCXq"zp&lb3Uxd 4( 7rXPՈTxX3r+/ϬLi@V#M X`KG3Zbȸ/pŖ-gbh\z-P2JD^u$_ lLzJp |.B+.@RiLd,%1JI9MR8T/>D9 9˱PCED$Fv!#W8WӁڀO+[ &fUkMzm]MM^qŞA|hpkoF,_HP̝mH7nOkE)p+.L(̾"(]p_Z4u]6ȟ{t&G5-AlieYW'z [Si2~Е6q˰.xJZ&JށHHޣ$=6JlN3A~v>爏k8 H*>HFM|yh~򘭅M dkͻ*+ǏyWfj懈MML~P0!qA:jOC- g&*"t  7S]SvZ$Zޢ>+lQx e2Q+//M,:n:Q0J @ry4Q('9[kٕ#ϓ3 z=68;vT3׊繮YݜH1SSnZNe݀*Zi (HjefX mԳ/Ԏplz%\^B;CbhMT=eW amV[C< +nieߟ9u_jt$R;M;#?F ;q&c~Q3[F ̣ezt%[>5m5R;zmjMGfmٜZgYkdn,h[ 4֧P_,B[|$f>̻X6|8W4τIX-;T=2'8K}mJKz][?4@KYQ6:ε? gES1kK)c6bn n_ F Os(t@<ܠc^SzD &e-Q"j7y:,b(MR4٣+ ٰV0Ml@喎Dl];UNV{QW>8'k?]{mQqUAR8gx% cT1,&H\pWx wS}P *Fס6x+8r1@rXl2dDGG8v"jܷuvgl޺a5lYzaf"^Z&|C%\Fi;f$Cڹjz_2o/*WIJ/~.%F}ag_F貿;~PNZJ+ GdC~ꔥ&Hn['1(Mi_ku/H@[sb@w&]ZUƧ5-~GFTwk,O}Ia~l'mW Z&fh>b Gɳ}2xIoL] ^|@w7TSdKVC#Èn\R#pnԔmxNj 9xA紖bIS!K9ElbdVC'M+#ߵk'Mt?H>Tď!aت)B\ PTs]18J CrvFxt)-cT0&YďqǝWn\KŜ}vBgWI0LM`*UX'?wQEmXa`+~w_&>hG%anۯ%bu0aȾ /+ _Gfp HRnfGhMU (BGrx-pd<NO;昩lG:)$L,Bբ)F:(e7w;-mbbup,9 >:%rRЅzֵ#׉SHQ "e4p ~XP#(z?3i_^Ն.hu6iTԫFƑQc0jlcLE:?D­! Y0h%`m\7H%~g)mrX[SWiQ:ūJ6}1{h 9ᵪHcpp-+|™%Ͷʃ z击)ո ls?j:/-s 6qυ5s 2SNh,$HӤ #ߒ Ց{WÁ.yܟb#LÒUa3}ZLW"-j2I{[AH[o 3 Rw#cCvFr<[>i 39#G_Zpjj3ᢗ7_H^5U4FeL_P WZz"oW8WUI["v:@:ZtM_ Y!f{Kb>|󢔬sQU ,kN_N_4µϾzz`ޚn{zpH:ums9f Wq$ L'jgn0 ы#ZY@16UXaڬW_htrRY\i$ʍGx_u7-p-2 ~#ogEWdрh"^c!lhn9l-FgM{T3fk3CU+ Zƒl 91!KT0i7k/yO:]~)甯}sP UV1d[lA2#UTQn68X;,ǝ ~`;k/4rɜvo2K /UQߓabכ2}t"fv%e_ms0e,ZUT(B~B(UmVi"u)&q@r5Qb(R}Q*bVQ09@0[j|x2WCLIg!} cs2 8K|g[ZGlں4ϙ+AEỌѩ6).@Mt5U}ZEQ9T,PWX-);Į@wy.Ӊ$:f_oPEe6W\hNϼ K 1yZx<ҝ(O/Arx jűX,I>tQ\-_"XktlhjrLFͶT(qB7|C42>bYIn\YBTG~:^7kJ+/)/)% yHeq" r9Wi뢼Me1+}.x[f›&'&3/h˦P'%XS$}iq#md 0l edB=H&0#QF;*..hPMc2q#Z׭>oQHU؋eOS?g Tc6yax*QB;PŐ@Q:c;a -vmb3ce ~ppjiWTU~^F|A,$EX 1ږևJËjP?.p]>P\7 v5Cs=2yC bAe8Seok@W`r'yE2|KrƳl0W>DZ-aSظ_ߓzzGsG3+\?rwB﹫jZ Yy+l*?IAnar.&*R2i"@nQ1bD?O ʔjWD ŘXi fDK.D{QdZ:^•2Ԉ̓>┻$7 -5 ulb9ntF>^*K\} 3U avSsM^ir0;꾋xJ%#iWM$m-us(0b!!MKW3œOFk-dTׄ&L6!||CDŽgDŽpOTɖjXzx[ݶ4)U2p|WTTȬB5R{d8b[b*p˶142hiREz@^X7BnU笏<+CmPP^;lv(kYAG㎓B dH-O.hniID*B$ )m-\SVm.pPtSi^tW,C裩A57YVQCBͺOX٢ߙ@]:Za$?͊&q%Gy{Y3U=mO;z Af7IP3K3Wc2Mc3cٿ {,ʪB(zCBhMz tw}%zjf Y.L!cVu@$.e:ԓ5@1ik(߹m9$L~ WvFȻNT^-6+Bw-d'OBhRoou! h ]|r 7AKiqs'i2 Ҝ_vk,'ED/H IUV[{cہQJL'4~J߼7Jd oRxj̤kö`pv$Vywހ{mqjB-cj[^ wXAsT=!PL+YAZ:z. +ґsQ*bP~Cz{'H%WU'GaGlj-q,̰Q[<j1ByىqP֍Cۼ[.miᢷ1A4 Iv"7>(`\IRI*`V[ÙWǁnb"1I `,2;O5X`Bؔt~LSN=3ǎ0 L$GВhKhxqfۃZ) LM3`i4R"gmoH"'Y9Z$yQ0W^#X~{0# R$N v2$feG i9VroXr9G\Y_.&A;J 'ތ k( síCۦ"ĨMm g0lC KJ^ I!A!M ՞Nրkwm$Y6==%YE\^3>5NnTR?7"d]vM}.&u`tIC x,'n++U /tɡӖ;FN\-a[I~ū$iUSS{.4 f>n G(O^.ZR{vflJ}!ϣLXjwZhb}fncw|̐Ld9?%: wFu}uiN ,-1 >T/Û"֛2Xpt8a(Ou/Yߋ\</>4kR JX?V2aC=LlTqˬJՀ7L_S~B׬ ?PK`Zӄ♃JX<(:6{S  0 C3`ՏU Ki.hi<.h (=Do1:Nl#rR|uX '[d :Gz,QLV=|[Anhi^'!]s(i]y _6HJvGSt{یD_j};]1nw''i8 !;H3IFHj_R_AAAS;R[TxȒ|{ |nx䎀΄*fGUEdKu i;=J<)m)G仼̳9l=P{'M3Sq/]ŏYh ! J솴nNs} t<̀!(OhCC`onQךRc}L  匕b'FFm-ǧc#Q[%+n;C 2¸[Y|S`rQt<<&C PbFs4]y7>RGzAㄧFf!n/N< I ֽYm,D '@ c?tD 4KtUUo'Q:/lX68[uobSXbT\yϽ^HYbaz?|U&'ryq)>t=;(r4%GR$U=N ?Oz8zn-ȰAhlu:Х夫Xt>ߎS,fn-"͔j,ڋkWO˽LQ~ÒҦDT% BA@j3Ok{ $8-0PoгTbFRIuڡJY5hFb߭tN(+h*`%H!24x]y-L^2Ug7\4%{la:d4O>Jߺևx+L3kݰX|l;rE6{:KLuPs D%9[Ud\yqK!VkB} |4I}0Upc[y]@idM%Xo'I+hYTݳ8Jٙ҇J~} O \~ތ;֍P7yDѰ&cIJO/U4`eaBaǶ8!(w~pT¹-RuXswLt[kFkA.E1@?=(C_{զJP*=9W~%"DڃޘӢށ2.B/Ⱦ@!g\P-DnRebա Ꜭ3@ *"!_$WGdΤO4" oq6Y9wB&JzDVoH̭xZt)~jMke u *So>nOW:8 }G?3cjz^r*Ne zyEH#{Hx,íRk_yX j)fGU_ ) [KVԚ'I ͽ=k;I>M a> qhBĠkP*Cwo؝go`qh߬ A`&P' x%$R꒎r* Bĵ>ÊyOG!q3>TZU%cOX_>Ӈ^<1b8meV[\mq6C枉0jL^i'A6t4g@-Hoq?M,=Xz0mn\$кSQf_ɀjܓZcw~n0ݰt|{ǺZ*e%Gn8fHQTic;L`s=s[3r̢:vaI󿫻P˶|O_=}I`6FӮAgVtp-oA;*20ڮ/&j5lӅ墊L=XfbaZ,>V;\cEiB"/@h&詖 k*WU|9 SG4VwTy9i3 tMļ}Oo #.لwLLf(㰻faL7=v *}ZN;fν4jjk=;1 a[jDF:oeg-wΥ|k$IQrM+4 >/F@"‰|(QX)+aV%Ԗid} ax{]m!hLO .ɬUR^6סbsaA[!{kQhβt V 0آ 8[ %|P/9} aէe IfD/͉[3^6]eAJqg}u_jyggAX Hb1U0aG/MeK)#sU*[0ʏzVrhJ)NZ7QWd k4'V:;d'NTzhWxZUлIX; 2U 0aD?^L"(#Wh;T M#{,s5t)y#ZPNS=$MR0.xũxoR:;G@ Y@FWgxq L",Y/rI`~H*Kc^57$~jO<_!'ݤOq~.ơmUTÕwν\!vG )a3%^`+mfy&-A / F+@bo,eO#BzԮXF,ۥiNIŲXͻV( B܃S^>W,((gs<@=5rbiub_`b\bE閶8>wJs(J-$qU\C֠ j ~3=Nhŷk1w_cf=F1PW7C&}=0f_N@ٜg.£/4#[Ѝ(xs۲k6VEH-q Iq {6IQL3A<f[Sv+2(EA #온|I]%V\3\;{"gX43 YuL'U'$v{mnhjB0x + 9v!uJCXϣFEÄCQ> eB&)yF|~[2Hxh]((74e.@$mfw(5qùF1-g4xEM:wN;t{tn ]#n031S3eBeqy}ƛS?  l KRHyxQ2b"]#]F~5YNhtJ7 8J>uũRt|Jι-]X}<,QHi.}$ݶ2nΫ;eh>% }h a0{zY FtBoX{ڏpݵ̯߶Ʃ5%ML{Uy^VtS"~I|\cHq_mNxU8BP!db1b]|xHfW,l{ †?%a WE(-XYèk^  :V 7}^La vzLY NĀ2h u(3P߿r#cC_q`,V]Ehjc1)c >fRcLVEn^Ľci,b8v64K!LYKt~Onv]][AE*XåWb?F)6`!UgbS!Dt OswA;8vj=8S"laYdUĎ[6}euhaں<*mXM(j;NaU^3mv)tV`̄ܵ?)ܧ|Z˕e Z-pi3g ) ?"e}rAŹrS0BD">.Z3zr Gzݟkw{JAx( f4tK: J@;,yǵmGAT;($Dw@~n΢4½85I-)5W  8r䯢 aC;m|:3{>:(AG} /b /Wd'K ,̯Y[pqyj5p`1AAFX"C\#0eBFK,ϊ_mݹ/5QOMB_1(:ҾQ$A  =2_(|?t{v%V2`L I) (4WvT8}W0)^. ,ȸzZc35o-']8J-ICo{6Udm|j7P5wȰ#U؃&Fسn-{Iϛ&j8uGRC{HqeA [miaȅ %ow[l$ѻ)ze$W#V*+עp,X~~H5}<{vOd/G y>9 h٫HMw9]"N [#(z2eu,͓kj QtxZsNfX-7/!`YYϋPk:@8弞k(P#82 LajD4c*bۀPӱ*UtelEdѸG$S#%n-şbV$r!^K64pѠK-Al(C9 cͽO rD3ok`Ha[j,v? wӔ҅ޢ3M ;X=g_5~RJb-ь|\BCG ̓fɛj?bnS ԠD"{LNۆP,GñF ]XrƤxWY`@(|%L!QiP>}27e#A5->\;(ps9q-|/qI{o۝}Y<ڹh읷6~‡fS}eȺb>dM6ފ$JWHZaM^87Κ1B$@"r$ EN/JǕ$A%N0zɁaGo `UVTx~E^q%& 1)7+rasKBRq?+K$H6ɯvxoY`oς"E&8vK*<H;$HVV| -6u}|HrzfCҴ2C]"k2Ѷ\ D, R7ܗLT `?d7 c?b²qi&Jћ+'19/D!b8Ϧ&pO RJ6o/tû\֭X@M-Z7~8IXj]z-ua¿GoFU--W:ʂA_r7_FH!;ߛƚm&Y`p+-Meׯv/]?K!]P"p}ڤ[?U)%u5eU|(LD6t.Y@?q=Pu΍X870(w{k{E`YOx(Qs;I$yĄVt0^ X!4"L#r\GQ8DE"")b#=La9VJq5$4A::k=B W,*vAlZ=|sl`/UeED=YQ7? pfP' _8 5TZ&!hmt&wNt݇s%ySIk|tC x# q* 9"3ZwRFTJR|tD!ݖP++/t~Y%Ia+r$ F-V,Hzݪ :wj F{vKAJB7{ [ݖS/:Z]kΘå]ĝ "JWwbۭW@1=`Ұ}sY4">GȉUq6h.[ވ_5} m0 "]B_aNX+5V:QehQ6q}c/fƒٖ3m;GzLA#f^ɲS-b`Llj0ll31 H ޥ,X*LD0X&Cd'6 em-sHhWO,2*h?:Ys[ul*f0wq.&Gyj d7MQp\S>uwHPAXw\(>HΡbz'o>OB]#Gɇ,\v.mraZDÏPOJ ~C4:>g%:47AY2;A0Li~UvBq,b/;)M;_+nBy= `SUD k%{%5reG;\ıĢ~RXL)y}B] }[Yv*dm~8~_1~|6f|LtTAavWYU阔uຳCwpmxx%%~nN`3s_,1tn⠘OTM8#ՉGBGQl{ll8p= Ƙn$?QrS/@P-dA6Qf9a Yq#ۗp^#^sV9Gl`MJIAQ$X8t%Dt PkuL)߫(3B#^q6Oo8 ymt9謐..$k  zjXUJ'"Xʄļ!@3җ;Vc>^`G(/RZm2crp\&ܶq.|EuE GG١2eΜ9]gޘ"źf6G-WL FךDcLmhGE9܍Pd7yv] i,+> >^@K?D}IYj7<2YqM- iC{) W?lj[˕b=1Rb n6!mC|V}zQpJ,J2 &_&:/t9?ycL=em4RUoqnK]5;\=e>?Q n|c5XɅNZ}&v\u ~jG=k/&}և~=4(-{Fr PBaL@QD̿ (*o G!+j,t&p]ќb'' 4k"xBzfU3/i:L#V)U+86H{=6 S-A݃EQcˆ63uZ~^B:Zۖu,I >Jּ=FY3 N U1[Wkv=(-9ȬnA.x MIG%zfB+msg sTrʿ1~ xnmzVLVgc|yu^5@Q[o ??K_\;5O pK[x6V%4(?fjzPWo2}c!pn>\)dN(;_Q&V~l;~;;P q-|}Dt`9e7jF2јF4>dA2nZZ-&ˌ)'ÝO7ڶ~Y㈙ _PLU\!4 sP"AL%7ԷHYv@,qt#B K7޲U4(;5ֽ(B3t ?0?2ZeQҋ!jݦ_2TyBXfP{.0' aC^9F S8fqvXhW RysvT[i<ٺدru_omq*Jal?)A5dlڔ(Vh9KaXcP{V !׊CpXtfE=5UQ8?d^k朶ASٝgI]U>! hd9HY+ +$>.vkJl{|o0T0h? 9뒈moHuQa&/p}Y K,H'ho-P&|Δ~S/PBF/֟pW<H,KU/ K(jʈyx3d1aWM 8ֈJS,!0bt ?WMNѣGfc}Q&c(VQ%a :@YZ& ='M;-kg>0Ci7ۀZt)@x h_$nK{3&O NUs[I32^e ]wՎG#4[zM|}ktJ[NrS }C 뵬踴qhRvCKwejᓢ Mh74ևucSۡ1Y 2c P`qMFH71c& V:8rLq;qh绱ma*_{ H TYCp^ƬŇ ɸ] o:1g\s' > S=_a.)^`!,2mө:¿beۏb5;܏RC1RC2Ygn*x TE A(ħh7A;ɫGoEI'Ǧ#jYNŻ! >ENc"hդNxF,03Ea(c{7EIbp^f~w2 Rũ 򀎁)]1H#``6!Je]qT(>[il$TZpsu󖐚.FK_34s9[7lH8kʈ+$z}e /-k/;RM)Nw67cF̷}2)p ?`0n_|1^>\FBkxܬU&JAzB[g% EOPUg+'c[tj.|d}@%suM2_;bG;r~)Ф]\eDDQF N} iFO1N q?^ŭUMjIXƄM<!BT'#)># N#T; =|e3|-oKR=!5N3M&Ydy"7tqXy$վFsMLOM@ߔϭ89Q13y0j(\Qpu}%IKӃߩЃG^T%QZ71D1q32ǐoEJ(! jd,yn2%7U S@jݩtWP\C}fr*^;>x.Ui,XzIlÔ_^$%n;&O,uҢaR! Kp]1ݲs/|~cra(,&ELutx9;``ѵK=)gAtz14vm$<,YRSgf ˂s$8 S u1zBoj4xl$*HVLw bAvN))ء*`)-*WId;^|emnf!=s7{דԅEOW^x<–e/8P:{Q=/T;!qm3;-xrzae!Z/ʈ3ne=ĆOӫh}hi CJF?|\'{3S,F2XPR%)3=$G}mMGPU%v__%p;6{H]n5VRM0UBa5ZfR=xNo2@!_y2"xpy@.9jpMˇ=TryYцeohoBf?O^u)/wϧxxس VkU/.Re9ȫV9 7J,ScwL䙟}JSFR<Owy\-p5]#^S% ֮ Wec5ʯOdxWO|uE=sAr?,bh*4Gq(h$Hp*e͇T5'#owvk+ lx8{ /{vxH,}+#*xj{e4ޞ!sREհc16tIyl"s|<^ԧHqWb'u3 P< 4|Wb¿ '18JQ'Es $yDI (c'&ࠟV݋$Dy]PyhkLĞ*tbqT}KxR1fT:ՄI :jR.tgT,m̸*q7b{sf4Ӡʩߥĸètn8&n9aۙE% [KcԨ8C.7 >27T "nF92</hJ^ kC1YT6ArKhE@g@o5ɴ:µ3bvG c^ lT>@I(jpm߂?y3/(uGClj}5~2E"+Yva?!Gː3j+E5o\*wq'TiI#Ip^ƘZN]f5ysD-C(?P *'"!^? BunV>>WM3n.Z#=pr^M-{gޖo 7IZXBe: ߒҔƄHՍɠX[%ӑW8#QuuJ]|η]6pq* 3՜祘ӝ#wbf*B fOo]z Y*Om!-h9>^KziLaǖ+I_\0 IQ$ 3{5Q L] (+A ˈ컆*3歖12bSv<)ȫxGp6Sh2Q}tHlPb-JM!p9f sL$f74x$04_ 5FiucWR_,xxJ\:baH#aybˊ"7xo^Y}/%yd˕ؑ⸁>I+_kl ߻&:ᣯc"`? U7$6&RX PsAʖK<' J~RPb՞Ճ_n QDJ^{~w7R(5ZaȅQr;]Kf\-Zra>M6xoG`#jAL&@p,#F8){~I,\Kc+IHxd KlIvGth'kl!^7[[̾-]gQ;N_*Ș oͤi\&&f~}gRv5,wG \̻. k I ts1ְV䧙.[Q[X=]!06Vpz5bWO| 2nJdŦU6i54"&_l$PU\0YH!4 1DurDIwK$]"?fLNq(iʃ ~G@̐Mwft)qo&{dAeCYBD۠[k3]v+m H-'/ƴ!p%T[.T}jPǿ@ *hD7+t4tH,آ| ο-*1Q^O{%g|:L@f{"ۻ?@h6|i<3Dhn%Sqԣ>ߗRJ ^)eZ_9QfO@,tP:n,}F#~aF/}2W<zQLݚ{<Pk!"ρ2[ger6 ˎQ`iΊ`=55+6DjpH gtBw &Y cr+rF xުؾ~ఘi(!M""b`^[ z$*yKUOV#RD(QSoW-#*Pu U Aj'KP$,%}0H0vOcDX 5oVOb͘E:.TrB|GFP8onԠNpQAl>- yI޻<9@XDA.I`vF^ =A4.D:u'j@!bꃾR1?ް;}1 $n8(h .x+`4Il1r-38ڛm)?hJrEHK/OG*wd?2Z&wzƿ*:ɂPw 6*[qWb*X kNy s<"eQ:03`h@Nx:h_*ly׮ _wG}ھQĚ+<`Fg]C`]1k][mC+zߴH#JÒq f qPNlM{)YCK Y"BvVĖw 8oiX'Сvhɶs}LNQzwt3lA1hGK)fZIY mSX#i7=9RzucYc;c0"B7MWt?hд@AsRQw<+ěӵ!1216鵲$bJW*EXfDcBoVɚNsq)5NGmlFOṃӷ.mσOx{ `n1߂x<JӓmWh7XVu$WKvθ$Gg|5#R"iaѧf6ǾHSމw}F*ECos@TW/mP>~1wcҨ*ݝ@u}'oT:PQڜ^^u]x[a' V=U}K{dj tg` <V'5ԿH(FBxV_L yS4$#"$Zt3 \'y-/D#\ڦ6ja X/QxWow 5 ơ3 a7sD8*wB=}"gOL0K=ҷQ½],6nܖ6Z3ӱ΂''~Ӕ51fX%]#hn2lCS2lXQ(G|g yXD>nq>~oeR7Uы9囶|&4\9yo3d*;xܫKxt4RW!D>m% ]A( NQq>q UAS+ z܋](vY5RꊔbnI7T3yAr=ygԭ4AvR.M%$Yq+D_ݲr.&GnZ^|yk`elsvM|AT\D#r/ +q%!Cp->` CAq `~ ^j:h IeoY]U/ 4ޚ*TM Jzh$L bc9 뺳SѲߞLhj?+?,S$ч{^R*en3ح)EC FoɜӨeʱhJ\"rppf ],@d井&8SxjW['8vȪ޼AjYf. gH[@>fwⶖ"ζP|$\9Id4f魉3 ~ ơCh1q@Ȁ5yh1&9+ L a9KZ) %O @czxӇ6]oNK5Hb[)@]* (k_.}03A<-^)I9qWܬ$j^Q3B|;JkFQbICm=a06l+) \H:qHLA]11P{:?31fy#jGk1e!`)飀KL wI_ׇ%g|:z(@cKbW@\XeD!,N(eB1oC@f,' ]8xNR}*%\/ Y%M:ba!CF'Ix?O Q;3m%G@ 5`YªT+ȼ',iFa'Z {QRzh=8 s aÕCj?7OӖ֜4;ɿUt1%&Чy֕l}a OS?D%|B)a-8 X -%Z_)r|#3`]t"tfW~z.//N #T# po c=^`%d&׬5;>-19ת_i.iY4[>ws}X?\-5#* _|j_yNCj!̧wDa#SEH)}[_;m\oi2k#oqXNa5geL WSH-ӢZ-4!|Gߤ h0m_.[qdpWqq\9u8x  g,qI!XyYe Tu oKC_irӻª tKv& u^Z5q *؛Um"a';+aot ϶eE6Jb_XM35TW2/uW'"m6@$SUT5wa쫫 ?7]p;dNpLxm]qLZP _7ɯ<#L<-5 P2^=̀iFC^u.s %BnT2-Fs7|\IC6aԍ1ƁDgaÊn<}*8łI]npBh En,T0>V1ԥmnÒ(+efVц\xس>йIQWB?65_-]PLK/n$Bu2s# ?J*id$S?fԞ^1jg;7nM֛"2 ~9xFzA9[‹#:pz|9{(ġ [`sz Z"*="3TVYDh)16K=Y ORT7J ¶EݔGj8TGdl<MPg|F HvVB*g? xn8q9t>XͶq3܅գ@k Ć}2~l1% ѕc="&1H^aKZJi[?"<|N ˻߼[q.l9Z><ՃXe#7F¢\YW:;jyf/76bDГtBW>H.hq{rC9lݚ4M_It #"TsC`@5$N|wX]u~f7aܯy˘"!ۡ)@ ͥ%M2=eav"h #+/Q~_Tר/|&xe .(f,\6?99TLg\vߢl7Iތ*c{&Zv \/?@Yl (.P 2 jC9 f/ڛm4v19R/):{5F$/'f,$s.d1-T.:x_W صmP,_k+z̩ VۍdޛrAHMLfZy{ig C.B[G-yw Blu,Z 0fh5b\lݗ?2ujm^kewhb-7#!OP||VC^JۛŃN(P'?龏n*Gh35ں%W9YmU(18+8S5ը FPfY@KJ(2GM6&5^ >⣠.l:ڵrCK0?W07cmpm>i؝3%#^ߞZ}u,7?v tx 2 QZ)hUPi27pB xJ(#Z;wlj3c|KMP0i.EYbꚻb\lU&׬)_@Vx&9xZ ttFޛY T]im)Yᓛ[ޯWղ4z1eB] ٥v e:kJ +0)p $ZAӟ G"zp16Qqz+ov&X:{(;~+N3GF%΂r2%"7]^x`Qt?C#v ;pJ9g GUp 5'$Ըinb;3z/fdЍ|RuRÄFd5ZZՅk,ٛ[zwx*qKAe.$\#b53;y3 @" (}4<1J#^\R0;JNq;}^} ܬ;1`وO\GsQdDNa8E d 1fbk mNJO.,Kddz7h51CZЈ۳?*Im]I[a_0ŘYuu;+j7bN+>g:iުYhz,]ۺyaj&B%̥ٳ2. ]7 7z[teZW?UCey NQlYSt βφ3*PE9 up f>:XjFkuL# {Rql#\!Y҂ _3s&B Ci}oOF-;ݙ˂2M[6G|*r+u;i⮫8:x,/K4ÿib|-֛KQ$'J̶B 4ܣpIOW3M%j&iI?<݃0+͵}XRgPgez(t 空.g_Oxo^H* ~F V}KJhҬLcye':tB־0^Us#%?v_vj휁iCrEGXtn $WrʚyH "~tb\Z8vYAzف$>qC&!F^șI$[%D-HsoI⑭k47 t &9EbllT;x}.ޑRԄn%\>f[ٲW6,>(c>Y 5ink-'&@M:Ooh:W11aq{ǶFg r@57*-=DymHtEs7+,zS#tnn |ET?2ފ!b:uk` X-Gk{rEH Mv,F01#G;NEfr[D˽ds9P'\VL#tfE?Sڔ/I9 ]§vu XXH.̪>i;Hs :9NayުWYEط~+g>~(nmA&s@(cM(8x3֖N\EYKYG2p*W]d|Ib-dJ. C_XXr%S(#Jr"z>qw}^IڨI$<?/ұ.閿iV3X.GŶ=:uVϞ~QFSe7yZ=ݧH7!BMf' Qx׿b F֔%Kĝ:CIWd% ֤y2=T̋Mg-49C3'0t,H_A,V͒ W)zYCR(dmz6&{DN8,܊}0縕+=FU[i$UJnm^xc={:9yٜ" RgU,*lnkj|/U,`tDn 79F!={Β/ŪoΜpل-Š@$zS'=_w'n\ Mz=vŚzl?F5kPLC'_7ni)̏+R 5ݣ}ւ(3~֋y$.6pM9 ۆ$G}FC9 `/U3SKBIb܏;1tXwr73nF&AƒypH"@v* 財/~H KCTס\:s5 ĭVyAY.:jL bâvY[Rx*ʴQn*vi8۴x5(p#>׿KB |ឌ- @ njn#8,44yyUL[5zXW|2%O UWtil>ʫSZ|^LFɰ$!eD^4fhyg(Qc9xWdQI9_23߼W݇P꓎OA)glR&tDO8L$V)CP3Q l)]C=ZG$*Ac; \\Ozzh k%pwOX&!ve=LZ9Z ՘Ϗpa?Z35Td`X6UbG!B[=ӺH7sG~`Y<2~aAJ2z8aFfza7$"xL a{4jGe%6h%7"H.W,;|%|Xbu`tG8Z-84Y!O9J!'^k<ɪD4s`QDvf.ŨO#G?%g5ﶛ '$*L1XcH]΀!I}ۂK=8r/a557*_ Į,g`<(1p&G\£yR#vH Clwhgǁ:i ᭢x O c#;c_ANsK"_ f۫49G T\;V/6CxÿQL ~j'ix$*cEq/bH]ļd CB)U.!OqZv) *CKaX sU* 3~{IǞԾ^SƈvY*{5n`SE~!eI&18|x2siUxU*Ҹ"B8ҏ]+.3U[s·쬝C9YYioK@dy~:8)_B.ɢQщUKᔝ.B@AUAIπRJ.U93ԭg( 6|jy `6uqxɇaa_I8v+C̬r}Ա~!hf}M<b҃mj.-xX|1pm|L6?9>UI{䳻]A)|zWAdyB-a h!H oU~\TN킡4<0Ȳq 'ƅ+IHd4#`9v5e `& 3h \nF 67>aaum=wf~ف;Cӭ_͗rqUݼYCW۴-R_7yGfB3'JxxNV0G-,7r>/d;`ߊ:l(Mz|#{ד8}Bv!u-~%(hxgd檫tkNgv &LI$e]f^HqVѦx+@\4z!z d'f7QʍLeӱXdZ-p}+Sawt>Ժlmⲥ.d12:f@bQF,p~$,f_X t*LeI/&}_fZ^j)!ak rC`KǷ4HZM5tcT]QJF.3_.  qF_$1&.ܒFe&&ikCM5NDALwtaUU=*"H2[3fȏ#T} =HkX޿M]9*9/_ G |Iٸ2& ,2zc'//J53h~%=ܞR  1OWnnj]& IwL/4x/df7*xҞȎ۶""A3K$oPcwN_ ?UQZ+W6e=Z< ~)w*cyINo>c-`ǻgdi "L8[5STǑm/e6U@ƍ.`bƉ+G<$z < `̐^X{+ƑLIs /$;B4ɸ8>D %i{hvĉ ΥuzZǝϛRɶVB:Cne7ʼr0$H[ªEjmA"hPdxr-Ҿu꥽ڲl㲌˫2+ibeĹj?;ƬWw F]›ސHƁ *`y3rOzz,hiEeΆPF[qHj1(-iH.ej Y~(WQi^h:d[t쥗ӫ`X0X9]#/f@W%U fZbQo'1 2m]qx85ᡫ/6-flcXe:\i`^S Xk6,vwFsNuS|3}N#l2\@y-2QW r&*pDǤbzM$A8P7awT{KӢ ٌ; ó~ [(k/7ptOQmp2}KRE{H]URs,u>2"'bm)x; Fg +w esҽ6pB5ep[02F]vZ&?9XXw\֮u$sB˧@1Ow~Xh~`DCj bZ  ȑl[u)9dp)7`73%*Hm|"xL~WҴ}z#ߓB\CVVBA+XEs ~.9ٱdEmUx'Hp^ގ^FTmf,iQt .|Z[naP&_1Ѫf,J;T+An <6S) 'W ?Kgk LgڶG@& m_5KJBM=jey̓O3k>~3@N)x!vެTf>4 EIC[ B^. 9sRhFġ1!5 @*Q}EF#ѱj>sFEG$Վ~qwoD }X'!?J o):jd֩ "oތ"ޓO ý0r(WK'?ڑLk*Mo39U;oܐNL- p:={pW͟@{52@:bG׳L*R`Ujtw(j1>KsmIJsSF,!sQX^UvZDR4 +:O~k6T(\)1D$NeE6&#C>T/O^ ;$v1jDr`ܔ{Ig.sި 7`ݜ74$ji'べâ@O9+8F3sk uSޅblЈtKTέYIfo5dڀ;`=Kx~~Y ŹEILCAs#n- ׸wW n̈.>lC_ϠQqU滉T׭"J,n [N~<QYr '()X_7~|:\;`,zxWⶍvWM;ʛ[5込nFN>Ff?qn, TRmg &ji7 %JgÇdY[n', ^0j@ TW9 Bl@* }a`AvsXl7chk :њ /;hƷ"&_RQŗdOXհ [DxXdqT Z/Nާu:uMԾ%$R8 i"0w^Qoq"ħ$e@uoy}Fm>.E`fКE-K5 wdX`4Js$N K馥E.[&Mnj! .߲'ػkW(F{eO毿 bgpg'2FCGPS߫ozsBQÌFpˠV[sX.yC{%pIFǿ d>%/^ڠ84D>PHI'p]lQw-7;aI9k/ * ^v<0G0-W&vvOzۿMje*fc. œۻվ~qNXQ07Ƴ&i )$8O %ڟW{/auo5wCțû' ~~5!|Ni4EN%_5LѲF+e O!,(|oGLT'>?MC9`P`U MZ-p0mS%ǶڪY:jz6hȳZU@x:~|Wt(٫ۻTnxB0kgҌ|d}1M] VQ#|?=͒at{&:`qrg_jR˴'& h=p`Z 3}\("iT `(R`f~E<7G"3z6|v{m6L45d2x{$5Df-Z/#=M@>Bn!LY/lA.rAɁ~Z92䞓E;?> (nal\e4\x/u".gJC̬͠V>n1o7zJ5ް%1?-Ж4Ja[p.3wcfB5F[O,8eoEc,]oH)x0FaKN޲s6Wmeх.c̣ÉVH 5X2;w&"nAf;WLL(#dl_Mᤀ ԩq~:fƚ=8qQ0] Jໞao:=`#ynsiMk˄^TjiUM*(2uu%NTd0: 8'KMMbJ@EM9!OTmʒ sCu >:RbDLˊxY7Zq/e-YUE!wW ή3S'I1ӂy'}e׷.()H:uhas{qh-Z,ݣ~n,|o!G0 ~p+܆{v ~"ٵms Vm3d[¹CN{;U04xYPA?X-. 68ųj&6諆ǷxKG37\"H[ &蝋70<,eSrf.Dw5Zs?(!rxl^H;O$%.=v xhi_r'XMB8/ijǏݩ:n%Id{ @f  ;{TX2inyq 敘) Ȉ_)v|s8+9M/ -aMi3]m7_.fmbFu n"tϱ 6Ue g:䴆.e©wK'pXKz3MjZ,`嚊@ cZY;\ⴲˑ NPV?Ʊ[#h#]$:+7YZBVO^kԿRI{P1rG}M؉NSPuyP:z)FԻej }_:l)U'?KsP1СIΫ(ڀvҴr.>BuOQv8Ǯ\UpQ0\]3lը bcSs&Z~ N }(rR|/AqE: ,!ɽj͂xS0128i^2cVGYCѩaQr=6:?!3r.Lr^}~=0Hp&Ǻv+~K_T]6; CIƹY2|?hp6:/vnL|ð*WS"X2c}?OTfvU6ڙ[`y0Om ؞4T h x;1a];DžІVo< ל.&$.ɔ{O (xjYaYg{`AlKJ?l{0KJtL}FLT24hD '|8ɀ|WEMs{; ⬰&q& fb: y!6gZd(SɲSѷd'kPQLݤG.Ife^*P@ز(/Sr#Ekag;>kȉwoAY [c)?i;4IK7?mU v9oKL<_:L ͗s&휪b^DhqH@Pcfr)je2OiyYᏡ^@ _#-ɓK/TS`-5$Oې륥z98n=*җ0#Ƽ4Xwҵ[%LqM l'e>'N-BdPhن<8DIW&Y ݉ UƳQm< W[27bw=tvJz}?Y*6~.A$bs/0"HA|;"=b-2 IcQW19t@n)xaX1|/PcY.@!|d9J鮩Bw(?]R Zi48֚/eTjH<ܭ `4n4Z#0z}>D> TwTg뚋hn|0{˲"VD`1ѲN53p4Sj5i[P".b«[L!M_s*qFcKֳn&kAuܘ1![-Z9defH^GkBj])?5 Q]|l^LHFp*̤ 2]nTgA?l)M`8KtnGlk6뭶b 7:_Yt,w$3 (v?dDf-6ZDdpfE _K2q=G~\-%_e廪RWF)&48] nf$8 F,apFgz^찫ў}2CιJR8fzk tf|֍q](ܥ`u&"7bc6* zh1M緎0i_ds)][t c@@!,#6WО?Jlo{y!:RbAVoKs)[OU>,K%ӏb?ngD8q!=b /jOuvE F}(>rMGdgk+Y]}VHM;&4~DrިqjGvLvGk |_hwdk ts4m:0r;e!6ےq&C\.6ʏ<00 wlNć^^!Cjq56(ـkUW3&0:zY,ԑKlLdL:h`dup|3$"[>'e=Ӆ~E /_:SDJYƜϏ3Y*bD,ڀ8g^|?tX;,1գ$E1OTJhF]nyܹz5W&S۷Q`;Yx5ON3 g uN|Vm&Hm VbOa8;d;ɐiQx3։ju]0$whm(uQ|&YK!%i9E"4?h;; c"{P DrR/X,jk?ѳrA9ZCAS 2b̆ߊ}imECI &#(_< W,qYANۜ{C`J ]V6dR{y#ybL6uw+K6BD(d}l'1̦! &_:p8a xYUMsV۪BE-5~ò:`9ܸV赋WsY-X42}3KwcW:6R9~K,86ϢјН#jŃ^*?H2KΟTm) c.T&f_"%s)#0ÿlB tj?4)3,yI(h;xt|A|((=&ZJA杤 g)TbX?RŮʅ~thKSEMEذϦ'CRa?S -euҳWhW§M3b7 it+ΟQU[q?#K8!lD~%FGbi1tDl-*_NL>OdbA3$qwLtNN lTe P;k0l N4(C- lW!K@k8;bbX  IQ"묭73y3l+uY[:1)!MRPVZ(F5"*/ o_yWdW4h1岨8TЁZ¼l{V&I]y­ "$-۬8 qMEɋD"^1h(Wu>x&?*?Niϱa5SO#] ˶6w%ׅsrbL}6R/AP||-KIbٵ{bcgtŢ8 m%Dm̱mF ;ѓ!k6vBvN~cpờL‚Hp~Yp;~5JG S-%*GN܋dO++!f m3VC`^oer<[\n?+%(aZ(LrxqC;xOQVm oRW>f֏AV Ը]ԿYA<Gs\xxZ-k2u:l:$ 8&gq'ci K!Q *aʘcB« l QRJu@Z7Kuhn>_#oYnJ&POCkI%Z4Ss7},`mҘsr(o8䤗id*`'+Wb5<7V [(E"8[ǝm Z{\Ep W_vUPbgj'CpYn ޵vfm,'3B?d;CmTW+t"]z@TpzOl7{ZtwigO@Rk&( ׭A#76[ s 0R^T`avC$֯ R<"o7Į}b%ΧQ%3VVi[)YA d3rhe|O=arFB` aCNu4Yt6mg,돓2_!ݗ)V#ޡ@kx˅ef<7X!MG ,u@W* -8sḫYFiN[ɏ& 47O.]ȭ7h ɱJCy!l=2r}=ߜjUJTE[],WLrg,:adԄu)pod?m&6'"]A!yd^LLQH5bA4i`}=ጞuv8V,RU{c川"^wb؝_7UMNge5[PB32(U_`IB0`m̻"čkL~m/-S(ڥD7| .*so cd Ta\2 SN?f `tǿ3I˼"Y@ei5nD\vO?:9£w58Dm@hX"~7},Kxv!U]t}FsQ\ ĀVha5 IS;@%hk9ArI'P@pzWT2EQ*SрF"|M1,bk-ȁ:fa4 |j3- E9Fa·nN9+  rW+Oծck0s;T6s zҁ*MX'Q4gr>?&G;lBYg13GxFTFЋ((V[ V|\!H[x~0y<叱y?[z"Opy{cr YI>nc>:Z!vKTP-1wo}>X~k9_;^jv-\piYXADS#L6XIG0LΏr e~Zڗ,&^>jls}ʎUmrhp*&xF=t>3~5 èyᲓ>sҖ7\"_aYrCLqNѢ$z5qZQs"JY > GwݽU \AOZo2JqB+Pr+:TPmuseij ~?$Z9 .?WtmVtSEN$'H%_ }3w!9T0И&9{ScKheh]!iMn;} {ʹ K|n|2P&iyx9 La+a-ޏ%aI# |m*$xk$<8b+[<79AU#BɼPf5VA΃Z!g]O8OawT(:t)zI\>0qܤ#;E'{vv41ۗbCO_ _X.fƢq'ksxϝ1,Wږ|-me4kG̬:<Fb.b )-5GqkrB?]+5 T(u+փ[ :GI`7exu #ŻFkZuWр#mN\)Fȼ H2+ջt1 )Zn6B):lvr˻[@_]vO^O7m [;?"_ޡ݄7#y<4!dn7LUYP٫~\.SԝeЃH1kb,2?MH]O%f1hIJ )4D.Wa=x/ڥHU?9†{.tq_B XY215HcѧN~#(}Ɣ|K*jT'ܥj]ydk| ua882M(ϴ{0b שiER{'ЦD=dp ;'܎js\oFz?m,)[^j' _H~H`҉(gMm ֬yes/ipQ0Zb :+Η*ƅ³-*ErT4ٮQn79/r@{'d2Pj͕(3Kڋ8X)H6PC(bj;Dʢh&rF&"XMHeH[!Fu74 D}ٝ Ri_"^(`pA5 y,RkC5xG5t)^RMTf1E6$3.FTH8[RF "7BTP V{K(Ʋw%IpSTh0{XAkRD8M'uB&&сY7 k'PΉ&?f; h4u0x@*l$ n3 r$NSt>R OҔ ɣ'6>5!`<l2ӱQiJC!b'|~ K_+1=jZV!̗T/&WC{(l>TMq06xBr܏i0sA`!~czj 4L|ά4z`Piy>[Ӽw`Ž1F- n)_^ŇX91vw5cLXk' b3xAsxq£K齧 EP\ԑ@im[ YQ a[C= vIʀ@\v&xc0(HHI!xz!,K-<"rWi6,(3Vr;}rO]#|K@%6c% <WN٣l[wՠ){yBH O<ӋJA~Os>^$R;RhrL&xw7Iꞓt MhoeUȂUX# (DDªiǑ%wn'gk 9*rVM̉KhRDD"Z|e/yK*/I 8r^?Ju,Ւ{woV,rzOXr8^s+ mzWchaG1ͪsO0CFpq~Qa=gDr俭N ȟ(U(z= =L,ĹsmT@oyq$E쵗q]l 'QX} e[4%'t9"*g%.kh?|Ѫ'q<"ly&)x'Ԭ.`X_~Pl'\ ^u m25-pHA>M M5>pකdI}PCzzK'$& EǮTF3!q/fC61s@ R-&Q% ]eew+bHrw(la-AʰHAw7B^)iJ5ӞGZN|@kzcCqzʉHr(hAP@O[zCXiyH냔g #N/L1/U@Rvu& LD{%Cͻks*j*\,npdTTNՄEWZ) ,+kTl eyL:3>KH\% <5(%*wKWO)p;g\3b%T,Tjpx?!{MƾV恪W5įѹپ_rW"!:Nݓf*lj o#h _^^]݌ϦHmY%^3ÍϷWG-1&,e]c}&_v*б[uB4 yh8449Jn<|a.Ĭ]^u9PE҃ bgsxH(ٞvAj0z[ =55xn5ecZpP+.b&wEgk\o:e$ʣF \x] 'ifQ..F,-lTkZy:TAy6 Rxp#f#4ZOv^Wadr:滗6XWhdNĦ?|{6)>u4sGɀ䯩.ԏ\ jsya 3tkP"4fhw r$p3u=C!;a%CiͿ^=E0#nA]Q$W=$}Y8O#mg;RhKvB<7loO =|(ťTi5p ryV j[۱G,lT2OX:-[#SZ #DN O̵{s3G{9Md=x T-wͩ%ddM49͢iE.#PeHptYTˆT@ v!;D]CA%;ȿT^_쥙&PTK2BQw=OJ>!~LSf.ʿAj7?9o84,j Jc؊ v"rkPmq* C_W.ʹ'tUm}AH 癰Z B GgD5#EH|o ntפU3DEVxve߇?GLYG (mJҡq3(lܹJ>b%h4w7Iu>eTQER-m,ݷ!7j͆xjecW< eo`9&>"" 4nWpK\_h\Ee3_|°8x.lK uUkTABY/ :h_-1$I,0&Wtؑ>MS㠊'k|E 4-6bTB-A6{g*x}_Jˈ#ނ݋R\Z_GaJd G]5)'O2@ѿʲZQJD5GBȁ^:VC*i,S~ :@f`X4J1)62?xx.H+8C"mx$m9)ȳͿhk[Xy?uk}_? !P]6)Is)S/AD(mzaxwE6WP1s+)9.=;$As_ݰ85j90iu}Pɷ(DpU+˜k<7{P)dsJ^ܾ/ͲbP/*To]DV1DkГ*_ !V1a1DDsqgȴ B6)s,}+ZUlIĔ++6U<c=챬0ZY}6>[t,r!ܻ}-hDxb+ũɶÕynn(4F1;"4 ACjn=Šܮ2͟ZMP"Rp伄Ԯo1;x":T8R{"{1 O=7m5%L1gxP;EW躄u[9#sXxţ.rpթ㈩l0'\2qJ2҈%C{,Wk7 MgKTS6l詾D@qHfp"g2QGB K GG`foi<9HLWKs$&􌅚BYp swdWZ oQ0s<;|qZl-#LM JCT>xI{aѰoPZ;B8T] bo>J9i!dz4QGt(:IB Cx\q޵-QE;NZ,ߣz ]/=x1VAGQ٣ Ϲ1AKRX[d@ub|jomC4?Ѧaj4Lt u`.t N`2DJ2s9Pr߳Zˉ؅ 9<Bwxw[(+p?3" x|xuulAH6 i߾ʪEʘ1m:ypx૎B! ggx%qx 74gѧ"+e䣢 2!rYXZ4LM3~>˸Ѓlll[HA.A;, E_{[jnumaMSPe&sy[6ȸb:ѐZ1Z)6g „W}_ɇ `i|H,0v'V#PR$Ù|O(Dw׈55x/r5E΅Jv>&3fqi-c6j:]=b=,;\L J V3:JNw%TvvwKhH2 ;ֺGKS=>:Q³ox?ҊHWy,,GUjmjՅd4Jjdm͸lT %K%^qk`9WP z"#-tT-@y@4 p%[WO@OV{N4@fHƻ@N%ݲ3Wihy֡8jB)a=ʢ񇸰r@$ LՊ]ҾoWMwZ8ysEY9h`Jj-7WY p hWyWx$z!@Vb+6mu)\𡤮uHЄ^!P.p3c>j|8o/Iw4e6!;d}v7C8A9ܡ6x2VU ͧtf԰~ W7س_ ҟ0Vs3:!6l/_pJLoX?*܋N`D@RB(ynCQڨkNr1^xDU+`۬Y yZ6{x)J1jhk*M$L({oPnVCb.\xNKHWD0m2$իZ$؝Tղ_[ֽG2m#l/vGODʔ>@E-`MZT-I{ ơ нG# ]|(78> Mwӝ@M @)taQ;4O+yA 4ޫ:gIsj ge~- :KLZٓ^q }LE olNF6~>.tG <(i yCր`fU(.LL(%yiBv}leHTNiJVF sJ,EyG]AXz :}T~`26<76}>7 aBH0ҤSK_ `"zX":1 0u3_;@ˇ@r[ې{ s sܮUc WBe8lגfE% y 0x5yȼA~h_҃p#}Q)rk1uoFKu,@>n]T2Ut',"kA| *6JsmzCr>?)7w.ə/vnM p>޼NxۏjrI_X!d dŌ"̪8Q_dQwlɗꚄ";Y`vt={/yM|jIhյExn']w]wh-ٓ%5?4\vj5w+j!Ry)Fcy5Ko%FYlsgzl tn~̨KNQ؜G/S/%0=[~HzH}7ڸW9#! L-m'-h̋͂ފ*zl|˱RϜm/VÚ e+H/ݕ}>G eRxrR|* Ͽ>޹-w2][@9'8/g@b}di}Dx]_bnO9Umeqj%~ӔWCAuoy}ogنu}fѵ% Ob(O ]/5d 2PꝄH$QA2?Z[WՂ7X2?"4ܜ6ө"՟U?%O9 T90z'M7 =9Vm;@" HM&HugꭧEqZ.`WEVaC~iՆc+oɁx/luFB@?qSQ-Pڑ}i!! ApK.{kXpp6mǖh n_&-p3v}P%˹M$MeTi1] Xu'²ߡ˯sb`4H9bPٞӀ½}X 07r#(4{~ܵ !MBl(m]j=ں9U Ԡj5l4/YSJP!~NVS3ncbGDCgu-lA5 ǀ#SkKh2a*>s1d:<$ӻA׷6CQuz}{aDp0a;l*)Ȭ!ejC9w(,~m?R~b8VM#g}b3Ob fࢽo$C@W= v7txzSJ ڐuED m _1h:hQ.LevwU@bD2vwŽC$7j( SeU S-gk,6*3R$.g<~,!MA=3 e$%H).1oG0\[I^sUY[p pRg27/kАP'yOce:nD?5EK٦WY8"P9?@)]pw ~0XF3&|s+x auWtCjvݶ4[<{?#z, Oȗ.4!^Mq.eLtiꑕ1z)QF&EX0R$t׆2p2eP8[-\˪l{ѵI$6Ozb?Wh 1nW'_z X$NV-Ț!kL3%&6]}9<>XC$B_THJw淏8(;¦ЪL\m4*{H'X?p*%7Ӕ@v[s0C Qm.)Z.|Pq"qc "7 Kb>/$lC10(1Fqz'yvB@<[KCk[s5c ڕ>`rκl(FrP8 nt~& ׄ`0U9'Xd~nVyrijC7 GK}|-ͼ.ނTY;ÜsShI*(Ŵep~]NE}co5,w%*MDh+pKFy嚓S^Nfk w.z^՗DfwN0R6 6lENrV9lVj5XV;SDi'+o/z}>M]IpH>BZ0ҝ#QHR*x8@^l@S]J:mj3 7fއ!:?'F/pF$T֜N}̮ K d2+n8P$'a}-r|mL?|sj˳]!B93LN;GiM=EuEoΧL\D("e@,$h6t,v{u'.;I_ g~`asb='gC!8C7:zyc,f2S/H( e3^γ;)nt" 9$B5Ld'=Z+RdE!)OXF׏,OkLt{@ x ]f9]Wix>"C]?u"׍$KHzIIDP{k0L2&,\Q",;h=4/'<&=, )lŘv^{E[| @ܭ|$'H18~ylwE`7/-1YxbMM/~کe[Ih2rFxPD\6=Dry%I)> r8z&Q^ $@qsSي\tt[G(NJ.TlK\){2b|D԰ N沿m9O ʕQ!|2MٰogqO4Ng*`l95OPyH|X`QMzӡEoj8+C;^DDгuЩ/)JTGb΄xHPob@? #n0Tت_C (z07qbWsKgP(3rqqb#c ^[hu%6?z`lO\7=W(@ȵ`ho*w-hz(/O_сWQ!ZJ˞; BXvFLӀ/4ȫƄ]A=ڐ?$vU*O7)yic[sSe< cMkB L}.>yҶzZo^Aɸ[j{?ڂP>Xe(N)I*d4b[{N[/}CAjgHA4q/{&NL8a=I%cmζ+hz]#8j^-q^t->DL7q'\ +](#ɑ<,|x Ԗ\9y^,1FXiN6v2~WL]b 9We hb?: &JnfI\p]}`ل= "|8\l*zq(]L"}*6|7s`*Yl¿R5)QX_X# +څ5*.͈ZWLT"ŰZӽ G4Js49PõL{z_6GxC Z3IGgbT#$5?4}Oug>1kCһ%[1[͒Ug+-bWZk] hr.F쳈3^o6&;1A?&,à|/e!,}3.r8M**JCf=^ԙtygaxۑTl&zoBϥU)%6[YmCkQ-adZ*дm2!rq+j/[ 6. (06)pmםYѐOI}7PĀ)ZA@UVI4A~L |)?UR= mڃ j@)PѬb=l| )Rz 㱚9%D9/ 6;II"Q;3w7}YF< vBl8NU+v]fg+1!Y}|"%[lr,\oo"[g9*o(_ b^.#vlO.cO X az{:@isDʹ3% Im#k׈F/=\;RO(\| ]9C=u8 ^fS#tN,V'| *iFn0uWYvzEUnh~ǯW4-R`E?Ҕ[5O/y U] iсǫ ٯLfOn8%>(m3"e}RuKSү $NpJ\؛hle&w^Z9 ""؀ @5_Tn=͙'!zKDgw)t︄G`BM3`ܱ=/&;u#&bW/îUX1:SWCG c%W !ސՆL+_ԉ;}}j0/熽ytؑb(90VyM9zT`m),e9 c(^Ѡ~c`1.3O"֔߯\RKV%M}^pGʱkeTIhԙn%X1ŭO:b@y@N|c|p[@!|flI/۩F6ƴgۧyEsu[w=&ԖtP%~8Jq,>d!etON-r{n^O#-IJP I]l<؍PϬaP ` hz.q'WNwP&v ~r@l#=W<%QNyaq*Ofoi"+O!ډ'tM$bheJTd3$7ꖕ(d_w( 껈""@;/>&ۋ (Il; ajtl/6 NĒ? :ro6 !m_&u06#7WAAh@,2}C DJ*^l1JLkɕ›ky q  8v2ף3ru(#-llqpea+gbx9y2NzCB0e|îCZnvP#)i\1׼.n@ۙĹe_|<#ׯzui2v*>j쮱.F ݻ+7-^TxD meDA7Q9(?0w(k_tQC Y~[!? ƢÇcv*j=&Ѡ`:V}Geg`.3| k=􊺲 )H-s5gnDesylS^,z,7Oܠjk}?Y،&.Zm}v Lne5 >f:b-K}kllzlr!@5A 0`YƲ! \)}kQabt\|^+戶4=6~@I\^Z:ugs6'VS!Y$g9+ʍ556d'*՞!-]v6:U-wARs*y#\j 7lJ8rͤK\\צmttal!u\lxVHѶN[ڏ @ސ@IqW"/lMmhSQ#PT|~hYb673]E7JC8:ݽuW86@9YE\b̖/}Pe/9Ht;z֕bF ^9!}͢\jd [m% d@:lv BO T«o0mNКVeޥR>}7m"y[V?}e,=¦9<8nØB[?wD;Lれ}k&hyd@+f‚T/d{J-@+0x5p{,_O&Pg1Fb*/Y:ܧyn@ -83/#А&3rw"9JV.ZJj c YIXfI|,4BBVf>#p)av%O|:DP g+DX|pB{Q\Nnǔ<E[#Z@_(,[ ȍH o@» $Ua!, [}`̊{P\#yg%GMZCjTؑ-V@[^-y}o@Rp ExƳ^kQ!b=J 9\[&GU_OǰzFe FR^n; &|\~ɿم;~ CBhh"UN TTi(_,oOزӚ 4' Oop12l.ceaz.sNB k^y4/ /NnRuezV8n| [r #èU4 HCGL$Ʊv!)~ ]?08TkHŮ7cfja%xbD+x+4XZkOWNHR?1[u`ȺτD2X@ V{(u kDFWM-?E%X L+ik?Ă'&z6@!\w2"D8=`& F꣬;mXf h@'(k'#zs_L2d'Itlp-.7Ϙ=aaEKIqu ̪~5.u ZI ?5܄+7$Wh"/1`|"i:Q~['˒ W=pDŽJW:H%-^RF+t1v4;PHR5 B2Kd)9H=c*:sp{Jg3+I=`DڿS`αܗ؍844=rPwRfK6m 2=H~[0XЛiʈ7epx[(9>*VhSTrisX^ɅG%탦+ڌ }4'VGX(tM9JixyH޺rD{EdStsUF<7b$!;`> ncowC/^g4,K\;-)8f%Gk ^hb=.$E0P5J тKFr7#,;|Vlgav0m8NHCFr.+nI 35 6:]/Ϯh?X nmXp!QTj.N4'd\L 5 CzC!"0վ~'9CtoMI0+cct`~_ d-xsMNq1{tHoXKyް /.щ$[ 6}͟Q3@@|Jn2tGuD]6tՀF,no's3m:!L266ߪjJ75z-@cjOz\v^j^5iֈ.E !R4.R9U) ]Xle)&.E,P'Bpls󶷫Sg4cف ̈́._nx{hcMl-L*J9@dX?3Eʣz ޭJpJ{ yXhH 7 nR6d^g,V\ $k$Q [G Ksdf`RS._aaCzgI=[,O o)wVmGO0xdZKrtzo{8F`čoO0 Wjӿ EkErErM{Ra*فbxV[|a[(1ʁ%jObl@_gԠ0j{*Nܽ_$eF %{ V##'="VkŀM670E ߀i n{eu"*#xtb!FDν'{1Pт$VTns-zgjmђci+8O8+ϴtNe§\AC EX f+%wjM"/8X#A#|=R[kJ ~__ Η%@?@UE95$?̢ }Q&-,W'ǫKl5dO9!ދ\fl"IjlIٔ`@^ f'y7(K' o 20o hЍĨ^EiK;hbս-IhfVIH:_-`Gc2Box ؉wmh&ڗ$G٭}TP`:su=¤q[ޅFL~)%= F}ɀIWǭPPWan!*8 Msy狕|y._٦0>:WPHf2~eO`YEL+Am` AŴa+CFr{OL̚LBFz6*L%^6: 7xj_SpL6(,p b yS;~V8?0O|-G.hۣYgށe-1pym)#V SpC{j4)|/|pr놱B Yt཯2 XePj_*rg\ !{tԽ٣^W2djD2{Sk?R,$nDY;"K VO քzB*bIO^Mi3hGIg9㋐&? sbh@0}t[]V~+9 )wJzv3%L_^룳SQ%|Pؾ͔8*CnMpN0t'!Gs"r }6ggjr~vO&.c-߱AcS(-ҸxS":x' KBۙ'ce:?.?U9M|5iDuKVBB3GNH{98.V⑳!cypM ׫f'wAP7CARbB_r֯R =Ʈ:~ZB>Vl' 4BEUg_ W@<֙%\R,5D_7HGbcͫ'&O2]yVnr,kTB_|QեSg"$Ĩ֒XgbӊGJõR˅jU\FGba8&:X1Y"u&< "7ȜC(ATɲnmQ5jt,¾GE hjAQ"wQM7j-'6QF~9ij:7bύ6a{94t/Ϋ,?TPN&>KQr;snP[fyd%#"xą@(Yã%CzU)&( )#ß?SPTn.raÉ{@!?|VS*,AN(w݊?2; |*ln_jQBwرd3:tcNXZd \sZj`o^M Z@L[b@ v<˗UNœ]iHuBdg b'n ] \nvo%us Ib)q\ro|\]>x-DU8VIdc`]6]<u@ȔR8Y;{)I(Z1h֟ʈFi+lX_ 4ђjY4^ZFdهbxBJbv1Y!Ch?Klv:u&Ag(#.c(*z鐵%*Q+jX`w:z vD9ed=o;%Fo%l~?HA "v&CVy+2P\t_[DVD!U)Ֆ LgS(]bscSuO]%`YO\.j ꒇBY.G»6x(2wv8DDz^Q7;!/ey @ʞ4;EeFN3shVJQ&oa; Гr[̓b N7c~yLs`:{if*jB%HW&%ĺnFi͔_̈/Xm2NCo,BEfGxydpcIg@e@,J& 7oWi7 Z0f=\D6E~ ǽLꮧj7Y s~z.-cݼ _r O?6cUlAraޮmf]ctM< ə EᡛhVro3\:,xgۼi*K]:7|ve|^yk ت.h|J?__WbBE|O%".į&_%4,^w:[KlT|`XĹ}IlZx2K7t ^7:_UUmO,"%;i[+&c&ޙLsFwOM~_"qaJrK.lMYsti9< #^ :VR11!]GT bD޳vo:epU2]Ѳ F/LG-axZz|אAjƊv$|EZ 6W}>Al& u^6jsL Ze=TuP4}Pjo1Y_n@%udu'کp_]0ԩQ-bы(QU CDU0r ԡK,U+Z`ZPlQf.Qx.Z\ ~uWɽ[5טGc7}zOoyiuwN07k1ȶ+O6L'K SpJ.،RQ iB?9VyD-ۃJIhUGsvmoC"CkϦBC]gIxF.IKs:{mW*IcKtQu2L/} \YB+Ϻ %롸כl\n߻s z4ʬ-t ~] [hs5.\e"%6/|5QUkk ݺJCInĺD9&c-PA.\F]ꑋH|ڣ n_ Pg|\8Ą<*u,V`4d%~ lyrI=P8M~]͟ }7Bea2j8 QPč-L %7iRB!TstdHj}K,R5; 4U\p9&}3͚A|loQ`ߖbuWA8zT]2k09^"UsW=.D"|#ėN81 ua'ܭkdfV%}ynT8r((QWK*`$"mZdnK R0PV5=+_Y\_|7am@7XQOټYť zM>%KW:su(~aܯ]ҺaIM1*Et4>H7 @p0A-/Gd l~Ysv2R|WSj 8ѭ]cwj9C!CÉ݋+h%P 3J !F:wL6(aG FPT,4Iξ("d³ډ87"kVtЋIEf U(ᡙ; ̀@qU|_9u8MI) $smM-X*Ib@' .l}>aXmT.'`}Vxғ;H+Ul@wii_O}ymT]2 _c Vî*P*ERoQ7:ˬ7Y4_ ҭr+&d)sA#uf&.idF`aژ;@m-WRe?\ Gw_ O/H ;svu5dhn.Wǩ,rxI.vˆ":ZY]9|`2LfV:N}L)̗| #` O~H@(zDMa:kp%$bILxhvaUƬ2eVLh+sbK˲ dQH6&og8T42>{6Ƭ[ag}[&A;(inJ)ͽpnM 7 b αQՀ6rj!SP9`hc4ӼG/̛X-Gzg)D׷ T(\VkЎZsS s%8օxB%}HR`zJNBE8 i ӿX#KqTpN3 с:xbKTe2"W:(anZ7V5[ fn Rk!m;A8^$8OҋZ(ۋĻ"t@$ *x/w-_3 Z {aW=oSDz $bIn+9E|"FCR3>qCyٚ n71@,eD-|o7kdD=1P?0lƅT-[ew~fԦ֗f`o (Nc4*w dz>_rbMu~qJӺk9®Os?"jZ _xZ=K=׳6BB=9ĩ^e֍To+)녡iM{x|">̹Ø}l3!2Pw3H+9K5F4+P(.g Rb &Vy7 o '0)N& dn^:DKTdE{} SN?UbncC؂,1 1H׎]i5kg-+/pHM04 p-+6_j.LE=xt^&4;0 d[aR-ju4կCdO/Ĵbi__4C5tu}BWTm! osb wIa'H /Dz-ԌӚG6ODcs"]M9o;PWX>_s+b 2LMGz4Bae_ s{6.@]-d0?=48ɶ+:&RϔQ|D35&vqeH&U?j2Yuh0-z r8TLQ^Ƅ>N_e̸^K8gY4!- Yf)HT7BvnאgOi8-x&`w 'H @ޮ5)祎pmpEƨ6h-G[V6MG0O.'Dy7>ZG6go*xڨҗw+Zsѥ0#Y,u4 t;*?edZӦ;ʼ}ҬS'(u.O5S %<1GY5A<3q,\\õ)^-!r'^@KRjsgp/J\/F”~"~ K 򋴎p}%I8dۙP*Ą1/tBuW;Io"(v6uأ%jp!m艂̭wUGq[S2#5A ؂;ZV9v_M 쪸!wq pnQ[xIAG+5\ 7ZEoN|9'WN4Mǚ'[cvoRHHڮH 6Q7ׂ%[44 |C;FAj̨)ሺQ ,ko$7GDI~y8+OVc9ksr_$Ģgٲ~)#f%h)T 0A-W\xF XЯ0#1eU4߷1F|y^=R+3#@)cs i_cLRS}Mhg2ZcKkbHVTߥn6wH +)LZj'yQހ8e^FSOvdVJ:+OeWԈa޳m8wYKd$Ӭ[WY;9Ғ,\N8LvpI9GqvX ȭkZFk4NCMג F f-(1 G*v~CB/dc7|S{MC\3g9YSD{0!1=5w&JQk*y~ȹ?,f& F WEW#NWfAFC~27U.lgs|j?QP+^qϙA YZ8|;p\(\E(E^^lM}~d;= *mCHhL~o}F4 ^2a''^KEݸ3սÚ7$> Fߪ_ Wo!@dZ]vyۭ4h'=Zyu?ݎ R%ڃ¿HՔN՜9xY&I"޷c_ҲKx$Sɛ06?3J-Z'E&hb F[:ɭg#\f 5$m̩:?ԋ0_RB*&+?3 ڏ78F_AM*-b`z 4ZaJ(4D](UYy;r(4fbQv.(;qD`D,CsF7sAUra#uʮz`BBdr^+ !3$搜eSSHc j.+m'tk[5S%_3aBq%0q4">1t}$,,_tV4)Ձ_0ܪKc8q+i7ʰo#ai4Wznu?7*%ԩK/ 1C"W}xekoYH~TI+n1ۮJ?Wxꄆbk,hET;#ue&8P.B9hR:ꛭxrח8.:UY+E(ֿIh-vvcإ7l{󥟍DjXmuortĶ} ^=sR%z**[~BgPƫ{saXirR1^B0uhTJz}jn3:Kw9]BygVC7׎pśw!M7f6Iw_<0t,V=lIb2G@}$IdD$Sic[{Vs t3@GV+brɞ H1C, V{,)Cl\s{zf0Fsv#ߎn- vQ[-ýf,sOÙE9)rb> {)7eI+!mm(M\ssфsȕk2dn:v.$]gcfGv24Gx=:H䗕;oS!5N3dDocO{WM ٿO-g("yw%y;YMbPzCGQ^8syFê`*@,hy$lmNq3X&K隁5X$%c=u|0 SL79/zOl),ˮT~67m%A2 SIFpW³[6e-ӯ@@{9,sxhՐ$qx -Lmw2tXH| $s!C9Fh&x;wa K#[SXQ/7ՕB[0,i0D WJq yS6gʋ!e`+e<9Lך<׺*}3Kzҫ >k5ȆxK+[w`=:atF9lEB].F*讑Ίu宊8̓ػ>-;nF^i#pI2pbNForQJߋ?O9 jɦ1Oh:8:MW<*c,+0/J@ .6(esς͙㕡23gs?&)9"Ue2kwU;WO\2Ӝ{H{K] ^M 4ilgx @E%-1oke CaGc6 _CINJPťzF~hU%oQGХ)W}=LiN*\+ t #J6T5Y/&T_n3F"7i{쀕{O{# 2ONaq7NgbwMT95aNby~-=(V1J ԥEj|gnKT~@xLRw&0?:Rz;q\ ĪyWs<zC11#PRXvrYU9`5Ps [kM4͠R@ шT%ɑNXV+9)hSeR31eN"sa0fwq,TW#fa ^kϤmC2>yȐI;^;$wSFNL@a[U;(LkHV S8k*s\)bx{E}nޮ9 l߇#~ҭ}zR8)*a|;OUZ#xc 9I \b4 " Pj~_yr'4 ܝA⢿諜eci<&hqv?ܔhK^ʖ/nx=PZ p_ 'iPYQ$mOYl׀mŠ($~%h薟|aPKذ T1=gFʺ6srrJl%F5AzҰkbɂ$7cCdΤV$s+6[!Ғ0ݞ{ˋD{gQ40o؝`e#ZtKuT n%WrcqXLn sNXfNW#[ Pc<0Zoz C[;G;DkfClIN Cğ7 zy:| H~(K/PNR_eB"2oS0YHB*=EwO e:3/@tyPΐ >['w3͈)#*oғד}`UUZlu7z`!?`C5؀0B?ƬˮT5Kb`RUftfh}]{R2N#}Gcv룡M=.z 6*)JI f`*%gk}nf`@Jx{wĤ:Ë ?d7-Q# ;+{jfbmy6үv:ҥNw CNB Cj)v=w{xD_)K֩xgԳս'+5K)ఓZBphZqсioVRGOL^ΰlӵ#QߗOiA>)6xRÞEі8a7 ƅ{iGJןmsJ@dcU g!JimEB|dQ卨rcGQ|q/@dSM:9D6Q;7A)/FvqEo UOd~>{V፧zݹy>; &5kΏls'Ĥ%E721\2gtF5YE?2r]05YTDoRœT:ڀ"uP4:kL S ֚o6σ ZⰆ%SR'xL2fYe6HaZ=uio `I9X6g? GV!tOZo[Z{?&E9TCqfuRBF VTFATF=<'}Y22IN]g0Ber+} E*p=$yytI_Ct _^hL{hmrixzٶ,wy Z /{,(|D?.{V=.z0 .7eX@N*Xi G+ģQuK2=6ok6$/՚&G ٠k2ӧ/rEZVoyPhveڑy؅pJ=T[15 C]p.'UaÉ& )vJhٷ` 1ٸƄmFUnmcg5H{)zJS #aUJQ?;v3*ʉTQBIZp۹#HպGgR6Tf]龆-*8)úu󛥸 p?FspXlxPmΦbE@yjV=)Ϯ|Y3YI%LwDuO$ɕ"sJ;P27GsB1%q2(6ߪ5q"𭈎nŭ7v8.#J9OXA XӬ:f c "X [eQ)6Ԁs4TŠץϫK.f )[<'Em>Y7*.IQ{x^[#[ݖi@$9){oDA{McxL()i.Ke,757w22Κhӳj3/lxFѶ`S`@ޮh B/x*"û. 0e?!@ObN{ QfN,*;LKeMLf!uvȥ^4|_(&yq-?!͌ģ0>9j;.={ O&qȥIw? #PU]61+KFuߑ-e޷IPDd_3 fjQUb&k.tB;]jK ^lbx4F.hiw9uIPv?6N6UWWӼTH^v\-%T&sTWR/EYl H)ͦ 56G&f^lQmxVlAdzbfٿEyk.ziv}$"g/Nėr:`;m3Q]e@zddd8[z$H1p],Xe|& u/'[`Wل H)tydS^Neֳ?!'CKzfH܅]bR &;O ZX>gKi+\O.DOWSFnO9'LTa-Vx.P<ȹKYq1!ݹ nBXH[zKtF @ڮe(S'?ErR8lYm.k'']Tb LXVQ3J5uv76?[@#+e fXds7⓵ z<~F+ZWnؠ Zʂm(p:nzEsoc\(L6iR W8p}MĜ?A/کeΊLi\ rrkv, ݙ9B]<ket-S$$V]$˦f(^14N* "{ vlD@#hik>Қ<,X7.[(m`n ke%@̴ @)-֭mR.-F68tSq/eo,41'#:b)P&CR-{:'m@ȋz)DFV,PSj֒uTB @~%CnxpP?Nq,ggu0h9ZPQI1ObM*;!H!aSƭg JQE"Zs;Z'}3[%/Tc,,y9f֏ٙY)CP"XJ |@|9'vfV8O.Dws$T 5V si6ѣ)8>~2Ӷv͂eb$}$h99C]em\ 0xy12 υ.SmdiʣE!(U|p,$cS~1Y,gH~RkF P4#iedYy/^`;'D1,GWϏ`Z}]< ĎHEm v"KEU] ixW!~D9G51$uLW nuTX: ÿ+jb _15APo-N+k)}j-~/-<{ovYHAltAga} 6R];[ sbUpz Zh g /emiSHejK>KD; U࿵p)9ctw:Z?:d(:d=<~ʔ/;P!AR;6+cM}|a1tg.=\p/ټLO#E~ LK"OLn0A:96鹗w zev:J ?ֳao3&HfNn|) _$mXG<.:Mi S[ Bd6bvdJgSR/% RW>a66'-> ;cBR%5/I8 u6*Vm65qNZiNzEv3Tk؜aGNiQ4Ztn )[;Ho̻+QRn#q`mtDƀXc4)m˫}p:j'*f^#Юh\ZBp޵z(.ٛx>-GL!SԒJyUzpEx<8!MM,W;F5dXx3 EPs_cr4?.-CrLZc|bHC>@=/4#X; PQ bA|HAHcS95O.凙q-Ah0bAoEQ:Ν2 ׎LflHpSѺK`M;.={aEl}}ѯv2C`:hGi˿Y3DUQ Dahi#A N9l7 @٪[&T$*f=fiMPXĒH1l ^3ԑ`Z0NHF VOZ|[<3zCbN4SuƖ]j+!\+-l5%`K#P4ft ؎:dzP`]lR3s"v 4tcg/bETcyt%?? -DՄvBo7md[h_>aA9/Gg6qW`=:CzU<ΠPӽ!@#\WN=MжK39?CH{D[G!w8˩ xlsYOv\I~P_TFLq , ˗ٹx|lbC>SH2T[ogB1.]p=Im :XWHI-JhMzGJ_G/a \,}KJ@*=a{,NM;gOIE'3 8M&>a^AiiGuJ 28Hɓ2"56EImL']Oh?= ġb9f7P(24X7~ɲ'sn; T#s5tNt]K#}/U%Iӧ#oN-1'}ebCO.0s-h0xHdnz3f~Qw*? "I͟QZ)sˌ t rS:b <7;WZߒ3 $NriȤ_9{[,nJM7`2^zE]RuEߵ~XA~hhC*Dt<78]:SX~H:L ~"mMb tU 91oj7S#mJ;[R] x(=WQ \:=G FOQ|QbÁfnD4m <_X;Upwtio@ GAoAȑEu}VVЫ<ы~D5 - }Q}ryʼgf׏4}LJ"U0 |'jyPӧW( ח=fr9N&S}Tu S 7d\""Y ?ŗ* H*ê~We͆OOc5mcCK!(Lzo$LԇU1]~#vgO`6%!'l2x>\ÏMM"?+VDd,¥e*Bɝ &'^r=!NxL~XGTDZ 5$!(b[~ /. Rl~e^ΐ4IH6s^*F<=e̎vTo "U!tT}.Nnb1дLĞ? ȉ ! {4x7nz3ʸ e]7"$8ȋ O^%%2GϡANaMKk2vZUϟ7G cY, 瘓z,5/$<ӜZSPUg6>?au~ToO!xvX>8SHf]H%c[+j(%鯝5p ,UKf@$R8=~J2t|Njo"Q!4\KLVؾ{ກ L CafR9CĐ$:a৕L8-MQ暉B[zBS]P .MxE/1AtɞIOIKsZo%SDFטC1=CA1"2{a?#0tW*_xogb`#Y3΁u2N)F*K6hԫJ5+>@>e2E9Aqȝ@&n\EM_?dG3:^!RqgN9]xB !7ܼ@]YFLRnUc_m ʊJ6ɆQF\/𘘜0#p NZrc] U>rd8nd&H~[+5='a>c+@.ޜk;ލUxO=6X\$8iG:. QI%V*nD0(ʨCH?DB8s"+ *f-#ڭ$r (_mjKLA3ͫ(ko^S?Gt}6Җ}~qExi0/99aXgɠqJXL@e߼i*69Dd߷UHU3w^.@HWjv,Q"P7<6bc T.5 V7+짤j:]|;O, cZ| _9>YϰwlD3YAû? 5p|Z,l6 E9A(=;~9vS$BN6'3is:|~r'Q ,YX{ OWRˮT℮v/|Af^<Zg:K%uj⋹&t=I@.Lܓm>iQ7@@ɪ,KF vo&&W郇z]s'3RqN##}QIπ+,B %B` %#ha A25<' Vtؠ8Pg3,vܣ' +"C.rzج=S3琁\~2]9rF!Q(tQ@ƒ緃dtB?HE(Ѽ 575oQhKľ{ ojac>wP0 dd_GU$㍘2<_YUЭ_gC-Nu̐*`Ҩ\U䲃 Wqo)e)mBO?7[$?+Fׯj6.)@@l>N(PP sڋ.A 1h\#l4$I$5L_bCK2-Z'=;aiq8m7 jp^ޚUanv?U^Y֥ȽAd8Q_)+=i՘CŊBRٟ]\ITV-m?=ƙ'O-W7 QXmZZ@ Qb0+^xIDhM &O>l/VPKYOf4>N 4N)tܮo=w;Ө`'9XrU=ؼ "$,-̸*1/BN:cA _Fvi77o nNEtNגl^z]Sp=qE.k*ڣ T OT{bϩ&Zai|stƤO|[@10LrmjH+\Ȕ'Jٕ^x!2îW6hd +۽A#Bdڎ%=U)ckpW~!%3xANY#~θ*ZjFFd}=ɏmSp dbml4B ]0a)}vUvV$x;=%JQ %fڔ@ნ.5Գ~[.! 7~YqdVT9`H٩Ɩ>^Q~c Wdk6CrZQW:+ך0n>wzQ S,?kB *&7$O]z{X 2{7HkF&L_׳FI\I{>y Ir 0ܚqƦ}/K$&t4 ? =qJcX'~5$AN) XE-s\J}bkibE0k^;Y3E_{C1?IU?Sq-E峥s備tQ7#FR7cʭY ^p*-\jQ¨Mj5s^I^<;V@UX!WJU 5  UՑ+2n;Qafmi hZ <)8^s 9OĆSAUr+ D^2ǝ^*iei 44&C4ۗs>y <04V^Lpo`zdM2!P]JC5!kDJ7403*&cVkt"wY*0/% R$nbKÁ~'htX)efG"h[%C HqD-lJ9~?;294MS~ۗ@"`\9s<+%FpDf M!h\v+#%ġ̈[ܭȇ2W>;n37AaAm@ԗ,'<$(RGN3CT$aFPZ6Aˬ 0\3,stt`哠&.9hZN oJV"IP 層TbO/nTv^,|iÀg@2MndM qqP%~t,O41^k3&?+erfC"t'DaA}r+S51?t71gP}pW TN<'?N_B4blCJ2C$^ ]WT!Sލ]F4ʒDSmѕ@dmCf *%#W! Xr62 Փ ~pʯr_#R}0YgX0.Pp¸Ƹ :K(X~xcy㧁Xvm i]0Evat(.yT UTj)ѣ=L1Iʬv > 2yJV542ԿoA(Rz@ȮR~[8^q-Ϣ<**oUwmqpY?&VwY mlxk DC:"KH9J28@e+=NfR.&F# /ڞ^OKa}>TPu`̫ȜV܄+jӠevug:5]>R'j@ng /:󓓢ʘE u~˳\5wUP {ݨʺRwk*$39)@AY}V+_ĿsN7WJ9Y13.j*}VVLH0(@wo}C tnf6@`\ nmLȓ7~E#̕z[$fo[(#NraQHNlyx$S1먲7 Uy *[觺4vb%"ڙI$+ۨ}xr8P^` 8_ ލ.3fd{':Fʵd@}ݜգoԙ A8,#FF؇>l'1 }bo- I hHǕᆽ=@xdira'󟷸kAUmR OE3Ё6W}E2ewuW!\50KOƑ}Zp'Q$#j"cSkE1h"8or~3$=mY< DzhDi*U_HINq H(},v9#>'o"l!^K`f4Bi^b4`"م8H +ֵz˷[?rB9W'M5 DnyCz,sz F`3\l ![rKî<][qrt4U)s*ʾ ͇ H.ҌP.#U\UL8]]i^r͸%'jtؓXtN9Kgs) V^~xzh9'#2;$i(3:Io_sQI fS.>U׫.]s1sCԁ;wm^@-g Xzr;|[9uŗcRӗ֖i4Q9{!$@y ;í*"]]jUFd,uu_2 T0(W+˩;b/'VaJУ=Hwl i,AS}F cV5 &,7OC+#l{W>1ruo/js﹓/;%t`E,N3~H|X+&Lp$GǁM3#j *ulEQtJ֎3/@JXB6&J?Kc{ \m`$|hȷDРqgt?2}D댔e{F4@zgU@ȲM)ioзG|jZWYC@` G4@pʹMNxvWP*$2Xe&_"Cj1:a"IqQW)a!&SR=*oЎpQ3_ rvOVz5*K5:7HL??mwoBg)MOLZRZ&a~ 67Q줨8 Ru\au -#OdόꥼVp4 4:S Z+^C^-@wR8@AE Z'%+hHڶv"'pa@Jy |~%b h׸;kԳ I\MAWA|MVjЍQyv*bY0uI}_˚mC;GxȆpMsi]X٦OFi)~9\!D|-ԭltJl*\(x`D5,ѓ7\ U\Т 7]`~M빴'gm2 B2;_o1Ӓk8[;ڢB@A^?<8.\;Q^uMy=bظB3G gG #Fu%ꆉRm82 &vjbBFyDc=|Wf7T){T@jU"tTepWQΙL(>hʥCV];^#>AfCJ&).U/U ne7h0u'dɡЈ [!n0흚 ܱ%{ olIJf0MQod]ĉ!ipʐE뽴j(H3[Pm6 klCZ0&' g] s٥%s&xAftZNa8jݲ c˅Ffo28z|~62%ˌʏTmE6n*tOrMuv# _0T}7s5*\HF\iMҩW  &m/G}T>#wW@9rH[`e1m]#"Z\Kt6?e"KޤONSS%A|aIQdT n|=0m7e1;w 㠗Pݫ/ZБZ{>PX@[I)00M/̯n.yQ{$|=%nY*[ ?%~u-[* n߼,PmKG8`t]r2'z*SmeIBޱߜx^GX'?T˭*"*\YJ}}΄ lw?;+L]=׭)֑eL-;'RĻVUX1Sg?]l5:3z-<Z' ?`~nyTh g x^UDdc7-P$V'̏~sl{N@v}ΦM:n+ = %Ǻx ~x*ܼ9 RTQHy rM ' Uϫn M3<=慍NX0EmMleWj.uRN/LF=Ergo d8H, "O1i5[N5pPX 2 F@{Ѽݧ< MKaUD_XdL}F1;>% e2M;M$6 or2aYvIZGo1԰;dw?dvff?ͭIMP$W(56dN3jZ(~=yRmdwѧtZJШ|m),M^ِ X?7N-"R$'D˞$S > YB:$bʒ`:~mT\\-p 3  -t `l)+{=Q<Əa|* X}b`r=Zc=?z {Q٠D uaxzr XwFc3 ڹe*QK)O GM#$DU"'&_4|~p#-gYksMDf)*z{ P̚y#+c$ڗ2CĦ<|,"+cS~6#~_꾽:VTjFd0wI%^/9qssJiݳƽE"[ķ?"=z 8ukWYU>@uډiUimLv H=S"I9tIBw&ўBy!(gd5L7g?w|Y2!Zm0s}cyY佥|#~`Ugw;ɟC{ q7Lj?2 Rva4ao̔-j VMW4܊Xt@JtG6B& sb}-aLM&iexrF!%MuQRjLӁ?rJBjIfO/i&E ?2oD9E,y>`9LթBkX7d OtxȆ',jtEʮie",+u,,fo34J1ս{  Zj{%z1S7,14~LV-ŶuAZ|=rkvsAO hO5:L "!zl :^}dns=(7J (n.*Fqd\K?_!O}^O-hΡ➹БFRFws -O8?3|+iMP/ś9&9A5 hτLSS1y;MsחP);:z@ȧd&7{q$'ܟ]\C+4]- G}Yt{!VSeT9S]?8=QATn ʗ3YȊնmnTl<-Gi}?#$3 2T=#:Ag=uNi1MO4`i> ` O HmD!t%{GL MP  7h;BgXdI!;cԣabbSSga#*݆z:j$*@bCMO۱!/ڗvT7Bkgӛ는I6 ٠Ԗ9OA6ܴCmKbOڢ O/YT\}4ǣ–\a䲲׭ ]X9ޡGV<90.KraEAD@?:bOʋ"L-z^^En,xx< iř2t) 'QHt>T*~\PpODJWOw/Z}S1cǗX8N7=el,*/{3:m|IUcXt\p 8ukA\Q9MV1Q7w9dQS<(˟6PC"Cž>t`ݑJUOtZ˦-)'f;lZEVX7=x4LY%6tH*!LB2 AjhTPJͼi.h|S-Eypp[ŎCRQB3%}4uނK\hg,rȻ6II={B$u!R-?g+E`0˝ůco"j̽Ǖ0%ݺlsuO0ܿYrWk!IIz9I ZhȥM\l;]seFyf8;UZR9Jۑ(weDJ)0Qvᅷb QFoq|O7TٶiЦ %ߧFH3 #(2FyPFNC,U1_ƿ V*i}":9eB t]xC彪:%r$ k+,D⯩m-bE:hN.+--.ca7٪J\)Vn)ܔĦs绂cͪ nf]M)Շ>'Ѿ315H]U$ MmOr8+_\(gFASiNMXҰI&"McH|HĮW?17dHeB4 ۖ+OnS;XE}+џ+pǑ%ctYhi25,aG7iA11y'p^HuTonn&RjNBA\(-#asT7 AyS:d*hL>a(oތ@EfLIIѳML,YowGfvM =;>ź:Wf/qpN&3tHo`B0j0o=a` ++)| uQ4| ;HFJ*=E% MfN(.::PT0u]}YvM&Er +T tPFjtbL4* t Ki蹫_ni:8|ggHS@ikyIdZ x*`v\~iQ젽a~}kkaخ@#!ĶY=M \T g5aw2_#B@J!sG:" BјTY͗õ(ޱ0 \gUɨuv`J3\BږEޤ~$ |/ D['{@#pb?uߵj%nܴ-x;yOyxjJjU?q(Yp`וsд2aY|W}gi;鯲 ׇ͹3-# ?uC]Ax?ý0\b)n<ԞBP"%Nt j\M|+zE.[̿N pcn l)b/ՔyB2yxӗv;X4Oq]v V} Ei4@;Vp0:U(/u0:AWހ $TEՀsI]bg wDNz~eѐVfZC9DB!w4I$}vBM҄ڶò"ʃC^Mk=?/NDŽpbZY%=BsnEєW/VTd|6l[S5C~c<?j ~uz1t[^ P3dހG圛696'⬬_CL9zP%T > F,GyՖ~?&(,['HRd{FGVVAݾ MH)0;_o5Gf* oގvҿL`pʍbޯE`|N`Uگp/#T)hU!;{*wk B\R"⫹`z3_8+dSyWOiV4 Jd/A}`vGRPMUWBPWsd'F!mN\ h"M6&~pHpda  D@ l(%H*-˧Wfӳ2YhY)w sr8xFX. CVyjDy*9ph)hz_(^Nn7 deV$ *9½>QرtPKu6R@(d/H -D cV@Na'A>FzV#rf&Eriղ}ܰI4bVG4>NHof& EV6u܊FAG; B3ϽoDM[A2'З(O*q@n>ʻ54vP. Bi-ڹR֭@A4cI3UAZ/P[-)U aHaI45?AJR~5Myq(<W@, cxJZL4WhuTd͵ڐhȮkFW\H9)"BNv{djR5Mć(:_J!_"n쭭 Ɓ29y<1f\1uLbm_/j}hS)1}9 ٺFjV1$,nVo,qZL%Ef3=Wa7΅g 'Sj8"(.lG΍! gso`k,2T;kX TП:M ꕂvVGK⻋BdBi F.T?z#";.{8ލB56vxyUX `x~YU8|@`$kk~/} $CPSJ?-uZJTrݎͶe<#?s6t *ׄ.G64%I9u,xR*g qjLJDQh!ZIoaa}0z1( C2.8%8Î/gƐEYH;ܗ8)X>SvM_8g dLP )9.5NF Ƭ_ZJziǹg"28"ʙa|\E̿Rb.ʽUN˙X72LYx=xRY*}qx:RSWH ": ࿉!>Juߍ 򐹚Q+hOEy;)iYZ"#°sq}@X3iU!c 9~ղSk%ȠD'^"Őo{2+pu}ߪ7AO\uF62b {U[%Õ=JVmAm Ƿi߃}<BcsKۨFIã P ?Ó٧9^ РtZEY'tC..-2OGʲZЄ+J'F3zT> Ԁ],uQZ@Vo x0UMe?Is'1Ѓ5%* Io/&FRp rڝ"=qe7*h`Zm*TB7#9zS4$8Zk;CLNdk#Wh/ KciT_ONn_/!U@;[g[' VbW Ðď`iA-FUQ g{ͣp.HNHgkwM8kkD=tk8FXфp w8-22ZN~@ 7툐Ä5D?nz^{npLˬuv'c7EBdt"YT=Z҉s:h1cVk lmQT1}"g^~X.&,誼Ԩ}2+v%q5o`s"x{%.S0Mv4(&dTV `X#Sa:sFRgﲂjYB|v@Dn%wƓZ0ՅhX1,]WnK/BCbхp:"9ۯs鮨3h Goan2H1f$H0eԹR&U(I# W!fS9;uh5 NDLFٺ!k >#ajK dD#0PZ˭tK7+XU.! SICy%6?K@ٸWYk |:Zoz~ +lenCZ2m_=:|4?eNiyz&R "V$/]Wac9IlC׹kx.^7Z^xM4,)a"i*Hr=il PMO2r9#2Մ&ِCw`{&ARIݝցKS yO$x3A c1EC}v&-ϽQT0Jm,؇Km18xɩ!u0`XϹN?BzcR7\ԇ_+8p z ;aticfj2JNbIA-dNY$q_a) j9X:)dFYs_)"޴;옆;#YVàU fZcN}*3Nm# r;ڤ6, nTO<Bnϡ7ʏ?EJdRHq2PWC#CܬHNr;ݴeXt)R6u3Tb+D5VGewQL-th/ZG)~xZ[R/wx>gyg6^~ԝx{Us-tݚNGY_-b>3t}E(qĦL lPāCo\=̮;N@JlmCjq\W;2'A!>{I^MǑB^o v|RT}ouJn P7tti41z8 E@b(4`R8Uf=מr%-o!_w&R7DR^@R ѱoyuOVp/C *rOʁ!ff, w2 i&g#=:hYP?_*džw˟Mش;ƛ/DS<0CHF8$m>ǪA)=7󺾩?u$g7 .P}F{b[|;>.h`bXKRΓW7pq`RyiNgjXQNB[Ü&B J:QT(A }.]|+uZ>inL>^Y6u %[Lhrjh DW+s(}%/?ߝfY0J"lu_ v/3ŶZ m$N6W؎vЧJf4ȍu<^)@LBm_]x6;1X5t&o|-ȹ/d3!Uzߜ+(߲g?rO[A۽ٸ3D/P1]W17 钯Gt׌O%Sљ5͉kwDdVpHCkhiNk8xLV˸]) ofƓDo"nZ_n03BoH{/JOr`a:Ugբe@w@ݺ6 #5 dśĈQT8?'$+32t֟)?!:r?Ol0MMO."\0\su]}w17dA_DfBd[ [6`$1o(0V#/M!0([QfUU|{Va^IJ,@wWM. HPdpg_$J}sF^cL*ӏ! !ځ,67ԅh{Ү"IsZSw,O|Jqͅ{I/bvΖUn#;_ SGF QkՍN1/1KBKqwqgEO~"B.^ CCMbͨvdӪ KX"UKuyWR"IwS]?~% ٨^djsj%8ןsMkwޕe1=Fv|*OF| ҴYlЬ' 8kHCp)i9' ę{T R=3;01j*G9k)@M-ק&AU"A@s\- OFp.>t(Agm6fSm\rs!E_Y\:*fnHCU'x.0CL҉5\_qu^{#m}]*ayюp57JclΔ.NB?ً*N{Hz:TciI&kTD8W=q` B1E!>V 0 5MjnwP oۀA3ѽ!xL3g}u^s9 F"Ҵ %=?{P%J# R*] 5wJ(Cė3[#WjtdCQcP(Clӿ8ҭNXPERKϹutX(Q7 ە(g!?/:#sO M杖.<{dʎ6nF}"H[ ϲ&.&PdRLN\e >" EɑJ[$u3軄B6`[lc'?)9Y7W_اP`@AfVOǙ}[[eң6.m2J5c}{*G./u`xB Pߪ^!qCdX& ߵQxR>O7wo9ii|nhĭst'9!ĴxG|7ؘ\R2j;ɛ-ohnO^~1vE +'3  $3Ynx\&Jc+8J$f3?r?OLj@*( n?%xWECW mNCYYB.Z:c {mRhnFyXA__V53SYo0M?(jLPDP2(A,b82x 0bN^>|K g\v'BsR\V@7[Df&f "E?Ǒsxfgݡ4/a1A,H `m'?-%"ZS%-6$LTئ99U##دYUoc$T i:rb`g?뛰{8|<_[ \;c!S'@! )H%W6]Vn9q_hOkdFwyGj>KoPPQۇ )aQNsc϶[fK)}_E5#3Ղtl t5kYPY9<&f ʩ-p>'&>~Tx,4qvmE9E5z0,)O)t#%Bjxxy>erׇc(cᬱ3p'ֺjqA]JajZXrJDN*-m]7i UtKppEƄIW*'fJi.w(x׆FyT,u8.e4:}$F$Vȯ̒*[9RX<{KGsϚ(cl.`D~aQi(X#{ ?suQgK|c)3R8=Le?E:)- b~r_~' I yzCrke@ @Yf?i+0àd{A<熦 9U>*Y=XJ^WC OlD[bA8>w`\oc||h;"02f"aLwp"Ȝ$Xne~4aryN6oHN <`puNZ=rر:ܕ,a:<^'Yno֒$b5rDmU1۞nݱeDvr&G"Ty8aRaQ5_qv7pueo]3z]at#˴+l낅꓿@%),)!лOnDcԠnӓN\)q#1tU)[ZŲ/:\ CUR5.s#) [mϗS< (;ޟ#rSnVhr[]]\+ /AwbDQ2MG杆C %2<,դHzƋKU)` S};G 4Ҕ@q)2] IFa) wXIdj:r;f8sBiR*Zk< %YFG<(L&[&'Aݮ<y=J_%p`#X#DR]?>~-~~dIόE9Yե+/ۙ#UJ0+!Ywd0)BZkxa=[Nxu#]A4tINL_gt+w4h-U- Eswi!Qϣ +Q?&Fju:2ܬQ⌑%tau\"O+:Kc(V!ZpGVJb!VكS.L38a='t\"oLqpr-|+q*T Giƍq3 ySw[=@ї*T5\GW5 B1Y"D1,ʮ1@KA5 +tZ;t_ܕ {*n#Iyȑ! >FQ)`,, }К&QA.ډit0F'9/ n}1^Ql*cufno2AQ =N6ͬ#e]Feo[TfclWOA^'v]g@$aB2 Uޢ,hZo|Cǖp [Z|9;BboKts[y1泷C݄᳒)J_3 } .; HCkE gdUnMd`O}ȀOa{r-֫$ Uت N婏ljId:OV~i6ӔDoWԜYHۏ*^k51yof[`: [m0"Vl!yvYЩܰkcOBZQ?a2dJu'C49 \Ehc"Z%FKFVߔKI܊o~ufhˑQ3jP@+?p1ʤ^%bƒӚZr% 5q ^(ctAPȜ{P ȀAXq`Eu>*µV?C/+LM]leɡ-h35'ԽjS+3H >J"+ᤱ 4:=ʲ>[DŽ!EMzԋ㡛lzpQaw&" ": !L~e%h^zm(TaSoB3teXk1;X-U{ hu W;K^-&ϵMP\Y G3YW~ɢD>eO i' ^A3OAOOsb{1F`RܔZQ52;<]QB )GmnMFzr\בiu@<O# 'Kwc=W:Pw7eF||5J[ JBr!Bw* T23fInH3Cg8۹QH #07AP5=]=vYd*to-cp`Π "7efsHf{4Xy|18- 9Tm{ 0EA+dv_JR)XwG|. ?Yl4R$FE0jT>KS(f53NnlBԫ.tEnXowV W#f |SL?tOӳ.Eق{NAʇ5b&5:xDYkC4@%ՉN'rdXhDkDc@36ihg` }!IG %>YnN ?}էQ|AXapR`λ 02L2RA#gY,!N|w[s/;Ep"S(~gvSX Nw=Qo|'E~9;*{`[d{Os#z6𩮭pth)e}23'bQaC$ԌdeSVPsl&&̶V>,/d|Ȱc[1/q~@Kޖbo&r_aȋPf2SJ<:p  _+;O;~iBF-M/BbQY$-P* 4JF6 e=Y1UcAn_ETkn!! يZ>K5h1`g ;Lg@˩YVy ˋ cWuAd>6wZD#:cOw\ Vk6~%[R2ocHR~$ޢ):р='UkZ}0PtUXrZYmayɲ1HRhLC[LjraAZ΢VZk&6(B1逬%mY)Ao{T5:ؿxI{էr~gbg:Xl"χ/v"tkk`~6cM A'/GEe/=H`WD!򪾔2̀XeG0u/ TvG}5[&œw7(>:8qOv7d"bX\3΅*=U e\Z#pl|}(l}rwItm w0~؊|Z)v*w)@q84d$i@J>Gm"7ȆjirƁ2<#sr}-Qzd3m~(#3IxZѴOlg]H-\zr=97KH6D[u^ @080=p0Ct9%w.XK+ZqЍv_zlTlWZͷR3gq{uI6d  0is%G9nBnV1Vhh#%MNET#([ oZ'3Jڶ- =R60js1縷>[V8*멬)-C1G+(HJ /[-:9'=qオxǹcEϵΘn~)$rF]SA;y5zVȻ `UH)O' {,] c"ˡD9gRSPj( bA, #AL6(<1M,a٘m.(2Bk4I q t1qABd˥ Kd[2$QW؎ueH4%WG>U @NMJf{4vO{{ɞ_;\Vw r^~Ks3|񷱟eŭE׽IkROL)>黩lϕ)];>{2O+oQL >G+wWoUŒ q(Vg-FĻ3%-JʋB1 TކLz{::ʴx릹;xpqb $&G Ҥ,MpHh.>Hc!lH^59/J.U W-599OΤw׉51I [8ͦ >4Ka`{@ci?a/sS„ZbB?׌_'. ᴩF"˩ ҬoP%ק)ЩT418Gbj|`]8nO׀_i)%Op]>tk$*@o40θCTge'DOA\Y,%ެs2lv@@+gիF\Ѣ2e"KGB;:[ 2'T()e知?go.ufsPC_d]7]௉;2BF,Ykk9MWyM\P>Rf`f A-$_]΋+9Ul!VGG":rV9a(ee`YB*[ar4@$ c}8u(RwYa¯Ulo'|ձe`{?zxdBQ_5K)+לD; ~jj rHQrsCp'&Zb œ Ҕ/r!{r5S͸4~~rMǼ"zk8+8qNHH_x4vQskCrRTƙrfPCq;+*Լp,wNbz^vBfu) P{oK :aQ ^oŒ6f*vX`lmI"d6x2և$QߌGsUnl+} `Rc9Nڍɏ? u rw#01Dh~8VBcZ^#%yf}JN搘܉0Fmr?~ V{-X=NTH,샊\UBZۤl:!LE4M07zH3ү>I,'7X{IِJtӫ~i3pTp/@ &4ƸE%!딕ii{e&IQyZ_$oɎV3F蟶ZNPI30vгUYVfgδ,Z)3sHh?Ջ0JuY ř`P[}'ڲcN뾖qsS%/ +har&zû)PӮЧHl{tp3>7VvHi+WRvX [(C\Pk'c8-h99?Q4I}V)Iīe5LM'tޖ t.T}4WJv1Úl %];gU0A]q|84 8 8(*,]Q(vg~S`BޭD 8 X#=2:ISR_QN]-./T$r.[ GRM}jJnP\E5 x0VI`hO wyIc/gC F&SDXm},{Y'}#Za#$"@(ϸtODŽD)͋';&'MۃDm47H_@V?PL iJ nKKRvg1lQcK-֭@C5Lj5k*ad۵pL ^:}6-sj<ׁAe=ZF*"s;̮jS P^{Udl`n ݰ[Qk8,4͇^UJF  1bQnc:Hw \Cߦ浜bM {ZZHjOK.GL4Gs\ ?zAL7F$~ /wwrrPOYե*!.''eULl U@֐]j?aIz 2{a )M|o; fp؞$I:(*zI @Nyi  _Y͌'aZyөjbd6 jg#hG&q-n&.YwC: E 2($éqӊPb%4sK3c%zOl_fbU}`-[w#SF } 8T 7؃ǔRw6p^ȣ<-m_ؐ6\H#@H=]0gm5)J(Lx G6\]x@d%!=9J0CK[hVHy%T15J{_(Jn3WuOϖy${JTknDMSuha6  h8hO=vwybB%2td;Bjˠ!7@saEE~3.,/'UB?5nFE9Lz>4{bׇM$?}B 8C<#tPvUpF3L+ȵQW<4dNϵf]Ӵ//u`DVUPY 5ZBְ6T4?vvck-:@IN*h>YP )?ZRiW[A:&1aJ]%Hk*'vS(haE 5%BY*a"tI{=_9L_/I:G fCw06KLj &xH65oSF}1 ÈɤJ+e ӆH AIĨ$ܥyy" ДX2;TXP$A+#΄$# j>O_eG#TO-GN 鄾/,3| 6@Bh a(^gC æK-G6gf+ZSaMܳif¢S8]vI>3Ɋb"wM,Y@өou+"PA&Ӑj)l%뚿ڍ̬hEA~sl 9opγm.|Ӕ(LO `66l7fh0m PY%o}]V)Ycy/cO^mH$MP" <;r4;j/Q:ܨРԖp3̊7I)p@A-5p}a'֥Y\&IpG^k]sQPx|o/Mde>z>E\7(^pZ@堋ξ%(ڤz6S~=;'8}EtEGAb aBFPe͋H4균ZmKC{z4[n | R# J|15*;pz|жoa hY{xfFrA6AkQn;3Cud:#@&O=6]5Sk"^LzNSB:my=z4x\=K?iW. <;;SP2jt#>T f?O ;M(B#!o'S9tKV^ 05IJ^Rk3 n~P3𜨩uNB2գ$?n,OTHO$K`8}M`S-l{SwW9!=c'\1jYL6>N q&1ӀʋT#*4wVA=wɈ2,繝AhsN }0|8$D@ &gf5r, ׶r]SI-oEJ~D>}i3uEYw 1 /lRdQiŴTU-C37$ ݘqjE^f,9Ǽs,„^kl6Иh{> [E  ,@[~?8Ya8O K-BIkVa+dH`xJG벙(';d\\ӏ?r 0tE>`O,_p &fCԴANoyI|Z9fRfSƊdQEb:Q~5vwIفmAHߐgNxN-2&4-\_>bEz%Cj`A$}*RL󳜥 #,;e}\CkJ. ZvHpQ{ixHU]y XplE${tpcmJsb2N,htO~HxYkE" N*OQcm\ζ@% RUN{weNUf!ǁs/OXD&xdahv*)EcZ]`ǽޡ؀Ne7(e S H!FCȿ B͌`/I?AZ=$>E\y3,CqF]U9- 06(>^o-zi H`aʊL1Ħs͘~VlN< ?A7ϯލv( 55hX!Di2F gHVTk=XfWʁ/5Vp$yp1k(LB+[6iɟIjJ*Ac&Qf":0D=uI0YKHZO[Dzc#Jo "W;%p:^mv[QW o|؎1;W FDž'a$"iSwQBdfh5Wή$LXF``t?^~{]ǖR6_?6GOƔ2;>H,dPh6JK#zM 昼0SXM>-}͎Ĉ*6HsnQj@%C`rGݜXcVQ^w9[7POKxypҞΉT]EDo? 㚁k\E:)6o d kWnK}fˑR>/9ut+#z8J-5>%5+B!rǤ9I$N6m K6t`(o:_>ޓ#D[^rPh#~!b{b|pR8Ҿ@x` 1)1%JJwnGA-\ CڿJʶURc"XaBp) c> D0z^fkobr`tdƷPXpC)U3DAٟT|Rzc>9N<G02<hX5PmS7q-˛B/28Nsdy,AP {G3ģ6LWip K$EJoKlmk#oiPi`voך~/T;(BȎ 8ab]oPÌ|5۱LRԋ05!j]6i@F}0")$u=RG^آi"woB"03l82͑H>fƗ׫OhmBX0h; 4OX YQßVHjOфmY+ W =܌#@ VŜiߺʎvf,lDٜ*'fPa`E)́uLTu0?aQ*z+6`fB$ᅥ7L {fN+H!~ͪ.w0c'I+Nx (Cf-znMߣ~!nRB:tenCteWoi3IVҤ[\y3_;8jolx>0JE% EVeѸ=4AW$uwLڱYCJt Uf?ʐ;aa7>c~#'mj\UЙXa)ܤ 0YF]ŠZ{# + Ȩ3r .!_4b8[ /)W+e#:ǭD H(DnwcǀӤ4eaGO+}R*9>,1naV;1 +_ZSi}^:J(yxlBL: 'o8E_~셀CqeV#/$Qyqg".EbHWMH5)Tbiي{F\%OԺX5mň*6[Ĥ]F@@ҼXX#ugM|P>jIh?DjA.eA|\Pr&)q!=38+;]?]NL\ҙ́s{ DT^d;xe \vEu`S?r${y1;T&Oi ƅ2XL EoezT4 i?9?z:a^82C!;SP7Rmf ;0 tRVKuz[T~Q+X0sJY 6n,5I0C>@AAܙ h~ )sdy}|!Ngb1T*xEz| Zxq(Bm?^{MB$/vG QIdLCNpڢ8Oqs #G@,(z$ٹ!vNdCÏDda q Fӷ%iĤYW[F7k &1Zx4oe c\F (R iCNw JaHp%{+x{+Dg]%\ro*]ZYq<)h7ZM}-dDwCMlE?q$.h¡:q꿻Qvpϛe ]њ@@msC<@S8MA k8BH Uv=>{>~&d23nO2ѫ5R._QY̭`L)jkJ\{%},,j`2<y}pkۤKׇXNËcEFiRoRɝ:.G{@U谷TȠa|M刓Gp H 1iq/o" s oO@kz?N!vM_ԶvanwK@g1 m9GZl#|Kz/V#}Z G9_FXW2o)ˮ Xmq:cqų?$0`٣rZk{yĿM:ȶ ,"Sb Lh;h,b{ >gV( )yzXi m"EE|^vi;)uM)T}h X/\ 886g5f Nh>" , 48ڏڿT7>8lF洘Bn-$wx :6ݓB%ZxxtŲzkg7 *X \tGzwX2.,Q>mQQEjȶO@􂧢j_CDxMՁ*9pJ t:W)b)E, =Qh[xՀ EO5Ԅ_AC]ER-U43 r Hz0++bL͉i˥}W,Ţn>@]Ǽ!AݩgDJ l;wSy7G-04] (K\ˑ`c "/SZ+ܕkUng}&pѷ=γø7W>F-HSkbپzժ 'ajK6cxUi0*_ً;r$@.`ōB\D:^_*TMbMⲼĄ%klo>j" UY=y/a5/a #w`NNCi8>~qZAL0~'D[w&?Qvv!۵hu!qӜWLM9L͜e #Í{f2uId??Mrm7l=!sT*T8hC)#[IȭrY9XۗG3Ѵi)-!US)€9jgn绮aXi<t٨-\|3?C;}?،"u%QM+0r.V׶}65{O(m8"as2xPox -ƽ= @ZxA9bXbMv4}8!.]as Ac<¨ "fb`Amnd\CdӸ;/Üil;W%Ə0}8ֵ Rwvৡ\үw`wPjIt3eք_A\*7Z~+ǰ5M&ГӐqb@{{2\nA)`ulׯa-Ni (݁kÕ擂dZ:U"r=}hVf- A(_ 95}i'P{Hq;E?qh;Nʫzw\R <~vqö$'עJ@Gt`)m[{vPOD¯绽 Ѕ>.2gہ;tjVSO"Do(٧R%@Mk0S qh? El}O6C sW|&ܶ[_#~EؒuJڟ/l㼧pR+˹ \* @ ؄qֹ bU$2#4jQT̩sN+TeZnN_Qrt+MFز|,5lLb= W?l4ҸKB]oz.\SK$"jdWp2]j} nfov8V]ujla.ghlanϣ)E_iLiE![FO \'TW:1܀|ʘϤ))_>×V)* w+U::{^x´o3DR+پ}$Sg4K]m/ Ȫ٭0Σ@/rKaV" _ n}SBMbC hbW1?H_È;AH&I5Iғ؅"Qv xі u',-ӫv(@PPCW/5`Ie_u6-, %HJD=c|wlqӜϕ67ȝ,k*.w*Plto#.w8zrjID8ab(`Ee跍Sv)ShXgh`NI<Dy;٧)7z [.܈ {hUwyy8۾|}=īPv:}~KWD2s\"Br?@dGmD~gK 0S`e@$ TJaYcéO٠cb ߽ ⸈(w䛻b`BY ZgwV(`r=?GՅ/?~_.`@Z"6r |bѶ8%X%H}W\ҤVvM-7/%a -yC4$|W;menr  :D#`?I`ۭp=$k3FbZinhY-b V ˿ U8~&7dxц"ԓV`OrX`ϽP#\IvT aeX3q_ !=1]Q5y{ P핗dGĮeч~@TENo+JvqȾΔ=Viǘ0 P9luNfWDڣ1^ 6?i ;?b>ky[n.Q$$g uBpVUnavrƏFޑ TWv1 ^AǴi`4-D:ݢ4J1ʼn_"($[֎ [H\Q{됱Oy},t%㯁BJJvxbSp4 9$ 'du۪9zQ e.e8pY0C6\pC󸣂5yng Bz  ȀhSw;6CUN4mXbplY ST |B1F^`G7(FoO}58w _t:âƥI<,69lWw'%R? 'j28 G=SG၃,f\Khψoz9LF/DxHoq]=^T7A N#ɂq%'QLOa?zr^QpBmcx'k-Av27`c 2,k:DĿH\~7TԹWA'.93 :QRx+ƾ:Z+SThC<2tY5XЧ+z鮔JւN)@u &Z#Tx| ,{̴8ow g!jeY}KVIu 2;w/MWgN~P> BVםΤc,~'ppyMc`]k`5f{T{g8?)N[r|lYv< =%j^)a=4vkH?PҬB,o]0tR-=:wFMĶggaqdT4C)1"Id̃hf˄)Ntܽ/rUֽu/J =;"c1=^9Jz#9 j ӈG9P:^$ wZNxA\ڬSJp(%\> JͰ#|V7Ìv)F[SQK5f*KB ؋D|w.liS+6ZlSDO^k1!Z_'aXz5mॐ,a=%w,|-ud]Ijǯ(R>'C@N5y}7z[.z8uu6I5я*Z +on6(k\hJ]=02VY06*8"]=23r#Grɮ!UaP =ڸ,ߊr=Ցp:_0 %YVǗ=SܠdWuhW5 /e<#~瞲g?@|6Nu:=׽YӐ&`}^ͻp6`dI,)8O;!ϣd*$K?WiF:tXRU7xby7Hk"Tr(Bȣ]w h$_7[q5}9s]{JfP ןV8"d"QMMCn#C1z~dk {;Z6JtPUչX$GJ3$/96e21yTl:.E7Ma-ԜC{dqj, O5~E_[6ӸSMH$e 7a$=7wٰȯʼ/7R{(܈8QCg@i.<$UɹLjNjƺmU c=ZoE^{10!m cUsU>}3ɁtW1uD#lYūzʂ?z1iBNNL7!RF~8b9 XyWiYI=l=% $¹2s :#V@<8rRΕC̋$-Hݑا*ʨ ~Sx{U Лmыy (ri'-˻$ڸm[bG?^ڷ< :q3M9Lo3ϙO1T|5Z: Fj(smXW,P5wW))1޶fF6ltv#q׻ju48:k)WMP{!0 _ Ҏ#T8W6ۚiч>ـ{kc)Y6%Ul:a6혾 2J*zcpS³z :Kӂ27N6DݘJ@ ȶ<+~/P<Euk*__ [\ȨpcފƗ';'f}& i&_i0G[Zg0}:z䶲2pE1oa3 HZ| qR.hҫOڡko X>mr~)( {' el`%Dl30ТbKkVJ28e>F*[1xu:/WݷT tIݬ5k |ξFds]za ?fΆ8&<pT$ELhŠ\@NH"k 6eUCbԵwdPGdlJQ7(%ԍ ]1WFb:ٖAzvkk0`FnOJ {e 1mpyT!L#1xŊA3SOnc>3ڟF Rb>$4 C7#;K۸SdЋ\̶:5DeL:,i<}|Yë9g d|v* @mo~G}2>gxq,{ gK~=p5HnqCvPܒIJ0;&P^Qz%`S xo'3{bŗ EX }\kc[0:+sw@v_O-lMZԆ [I}F"PWk M?G ?i PYAZXʄ'?6ϖ%L8^;AH0MŸ^mxSw,_yB1 a`nx 'c_xv\\Cd: "H)ʷkF-P_W6P(t7<:PcchI#h'^46>H -t`+N՗@ꄈyՏ|e8v`,BHdA,Lx9: vU ҟOI*3rœA!R_ۙY& I:3v kF rvTb☄$\ߊQ%@LmK%bj.2zxYd FrqrnBϹ&y%3#y<7lsefd@e޺>)NF!=DP&,r0?)+$e\ Tz*_?-x1TNe3G-vښd"e*U"&%Qe87Xh#p]dK.y_(TU%pK m3j]OgaЋU'Qo΋[# ,9$lߨ{hzdn7F3p-ƪEyF䌒2OC`ҥ% zi^_:f=ՙ{^|7܁$9"čuqQ] RI_q R4drYWsSȌid7o `3I5I*(GD~UD -63WFrJo0ZD)i?s)c4x[YU*(ˤN'duk/,!R̳|aYWX U.c..l`-3-֩x[]A^Yh:h9F̈́.,?x HKzjI*!IjV{ 1-{}ֈQqhIڮTnPCs|itV%p' _Hk(g߰h} aOW6 d{lQuIUcu/)@%Uz\o{yAc]7 #*:PQERh GE}XZdFʷc}VI+'jEKgUStH޳ 7TtC61U|/]pV([ ԉd1?Y#]Coۊ\h& iq&7Z%8PP<0{JцS. _F!$Ơy9~ +׬aO2>G[L?^vƉJD}mT8e}#: /YCrGt^~´3,a?+C*9F !yE[[|twm83 gՀVPuOjK<@ {:6٣"Pf\AAFPHID-yn"xr%W翀+4ҬտKHேy:+JRn6!:A99O +=sOo,<+.л!'3bK߽z(ֱ]{ڤn%Ee+=_.b87e93bj\׃q 4$шKB)3b4g"#V\O\UTzG- 9\ $c LM\v#Eh0u=_ʻ~僪vaoٟ~gBu5#KJpg;{)9'$>I@y[HVWe7Iz+lvG"ĤLe?RG]ۡ0nt֪s[i_ޚq#' 6w( s1Q׀D6'H,6 }x)l9!;)%FFz1w1)*"Kċ0CT>[%t.uش1v 3OK{Sj2r4ygѕ& qu?=_P:ߴA|GmS3,] |KI,abX0C1<ȂɶW3ܦA-phtR[{RQ 48 kŌS}̓|ѬRi`֏Ra{3î˄qޤ; T9HQӅ◢E'&%vþl'Af؏}\]+O%yQ˺ʽpYTDNxL8q'tj.{'Yg0:Sp:΅!9u\`g?ov!EC9Sw}z]S{hQʆdX(6opؓ?;rQ_M:.AO7Pel:=4VioJOv)]uMܚAGH:dL) 8b>Xت7FpLO5f˄bf0d̓N;զ(q"hVXkwtOJ͖JmmS}ªz5[{ La2剙1u&H2@﹖wƋ(3sjsZ?8r1SWjfT̉[=1]GHQ~lHZ:cA)/LR.eHgG1"h-v\)/s*ְ:{FWxjn4U@H)2J fY 7ghD34c>,` ;:G G-K~4r`4zz#2zL~Y[ (M qH"C YdjHς"(3.˥UK[WJXDEӔA).B[;e!b)_K,/3:5]L{P^M1 +|A?RC.R ?p[fO?<q5xQ(._?JlcK*p .6a$2Z pG-$cDdz+Ц8D>wm((eL F$曳P|A݊[0n̮:Xb(7pFJU+(aC C`|Ndi'G %)e_?U!H8kIbo Q+h0!ڤHIΒd%UU4Ug)hj H-vmYIB\Yiox y[ 9UkՏDl~3%ҝW jZ#7p"2(\sEkciYKVR9Gs,>%@"N~Up;M#4XMօ̶q)2`Z*fH=ɩKPol$ةƈjv=Oc,ZيI֜GڧPI |뮿?7. m \$%Rp}5?hO2u<ĆP$[mc^C'= u SQ: AR\N$&;xpJҧ+>4|v%lMRø9կxEVI 'Һֶ2qA K)Iٽxtkp}Y2@y(m&GDց#\QŤُUfCc)Y7v  uMzh#͏ %V;kiɽ#|7xxk> |zcʷRLI-ojx@bڧ#K{ZbP&k2e'js! q"ߊ=$؇OTkRux+8rs2*}D_SPnRAqT7|)5K2|%6UTlUp`P_8(u~.Kf'6W(GRpv*}'S .uUבh "Wböx V/ȳebKZ $d k#J2l!&R|SѽdgYɐ͋~R f:lMdUqc>Iq8 ݺ08p8:ݐ) Piʄtsк'皋o+\Lb@o0)GK- |5؉T bLVy<\IDzyf|{FkQ#>3jcGxު}?*<ꧮ{}"͂tL~1> bJ׹wl%U;/F<lqR:( 5 {*G)_4n~rh7f> 2C/UfbGZ] 1!-]Nh'bf nzX$/xt723kvJ%a:Ȼ,g5[ _Dn'!z<MӱDm+۱iZHu:&!v$KRotDv6>gDښ˷CLY3?іhĆA&cYfݛ&@ @ Φ}Hk13OEʏnp* ; 5F D nFڋN!䙻#xUZO$(KYϗGpd=Yw"CwK' \}6'x@>h>HdEE,|4|#]2k(cV lV`pr軲πgG[{M[ F`NzdYg=&|h#MXHD)ˑ'sHtBrS`{溥3.zI)*{g\~B83cd-ig)3^t(iپ!K%GQE]!pꎶ qC=+UkV:{'Ɛd26 ўP$G#xbKɇSa%p#m+c+k4tZ,M)_/ &@wz<8[eԜ_2&-?ҡI0T!9lZly j*ģ3&ư@h5QS]3CE;*,*r+qn[6-وk(e^BtCU^d{HU2a]jHO 4mQ.ĶaX ˻څIL5+ΚGua}xxY왊ٷ1 @|^S{Wy'! ˃Y1 _^ﱹ^BgyK/oΣOhă6-ۃ=N$*&7oO2sR<JABOr+'>ěF&-=XK-cI+WpDa4:JmŖ n1a~7Anۈ/K{U5*N(K>ݢcPZ y\іRcio$_ae8>ٽߋ n)xf%:+/&;oM2ntw+DdFő€pKRV|Jm I  I 9P|[ø§?h?YY%[C y(yty)Ro9ot&zZz2lQw_sW#KXGjG[S2KZoOfʎX &ܸ`;U 26=.tͬy"zNDHB:¸;t9-z.T\BtJ~ t9'C Pfx8^gAvN+:y MBzEkGFVvz  7b<LWUבP~(3dg>]#vo]'. >ZsgTc(])K*Il}|mΠk!4ňrD.\V~GkCb`N9X5]u1jKOAN۩>(C'‘r- 3_<ӕnvhbـsS%YZ]|j_JZaGRJ37)2,Ss-Ӎz\1sd}unp[ޅv#Fx*Y!SK$]l[Jqa"P 64%4m[VG]Kѿ4 I8N@8(ẕb 9rLgj;)quZ]9Lbk$ުΎJOV tf،8p_!] fT` adI?\ ʯP l}j&W/\Yƣo+ެnL!)kpĵuBJ`peP B}|~ fd&c5VڠRH­(R?"V_UrVl^!$3H|.- BIwA\C"yp=*g]؀K8Oײy*ToQ #z?A'H2p2[ȭ_Fd+d|^c{.W`t/Sƻ)7YZbu|ǀ#qZf؉3hw_:/ Ji1/xQ:2NΥkr5Or׿ߏɇ\Klvfw8 _Lgx1J0!pJrI~0zVp%eVOG5fҀ1Ó?I*`eא,`T5" G˗9)w";;oK7F۱~ [5TI~f I֔S$ZOPC' FH(Ye5bsˊW2fLU`bKo0r#r2$l@+e.\hQz $Ӱy)ș(0E;1ؚl^<c} 1;(ˆՐsl <]xqSb9)NV O.c'+CU㶁!R=i&=7Gc!eZ LYtjNDS;X-tڕi'6θAƆ/+hLc8U,+aG?5`+0v܎#Z*hMy2+w_$JBCJb|WT eo*> eѤ>ޏ1]:ږi1-ZuD_A6y0ohEڇ_v;IMV<%}vm!YJR,W2Y7\ou'FEPI\fVA@[y|eN7wQ 6zɓ^UD^;>YډuE=faj~Yzi͟ǝ8\܂[-%NG#Crl|2q8iM_k"rAG"̀FÐ۔C6Mi._T>so*b. [j^PZK7hq~ !)I#Co"YIZ.5]ʡB1II i'Y,=2{jk@qRDeO*ٷu4 xs?s%߈ Z|BS|i4prla5>*Gx]h!< Py@ZjIWް*q{Zs1  & wK=wNc!rXdb8ѓQ"ՏR`Zd儓, mvK =Tͷ}8o# F.GvYLfSh޸ 'BI-|8q`DF4ŵvz)5] PVA 88}XoNR6J+uy+9Yݱb? F~&a*ԙ(1Vl`po"1X֛9Ҕa3Mᥐck4,s8fRCI 'X3sumgo*;8+O_˫,:g*9[qK|ot߹8UmmOLկ?xJ>UzPwEEɮz'u28p lUH8Dt[ H!cIVсp2~wM( I6V{ˇVvGhhSK z $[K'=ƭ:[e:WSM .*ݺ[N$6kЙ/hmco+@ ;$e 5l[,}%8+Ӓ߃,K91)) 5hdEXw"̩ɭzb0h݃ BCi ^3_-Zt?0->D K^\ J:Ej>َxm oڱJzZ-Z8=aQn ^ǡ rPw^݆IB%6*11qƋ$gc@&0av1^=/i.m%?-0=jZcYTHq#w"u6ε!A [Ήp2Jx+/r9M cy#aAiT=8-"לwLʞ=JN=r\seFjfL.'8ԡl=1ʦIvp i,5՟x~Z] a`r{2y |{Qzcn* s3!Koq iQS% ӹeM8a%)nB^ o$C*-Jv%yR}T1-W7β?5̄O]\տ}M"q%A|p.hMRѩ1lqh19ԱaV ()fLcqy!q)ųpH x"- Z,.-[a̿0CYlJö|zQ[[+\yl#kLJtfvW1^Ah+)rC\%Sd[PN 8LgK^e_(<:m4LZ2~@;)`P, Sn)6z SWoOӴI9/˯.[l^} |uNGb #hX"! A"ښTex睘g!! "N 0oX fjqa_L6 Er,Rx5R |J'?t :l'TF<-DEfMV7Dp GQvFԳ3˟څb`^k)ߞ-\hPEl({ χ<һD8o$"Ǧ&\v䇌b0HAvgFg쒆WOW,@Ujb`ߣ6m9LAgD;Kj}w\;х_|7[qͳoP=|[',}rg0q}߼t$Fc\ɣը(Հ#`Kq2-_AQϑYzD |2nTɼqys%=xFX_CBpj o+;ȏ2jvڱ꼢=ib=<(p3^/V4Sqj[rFJ4e.…);MnG_81uԫbDLYy7i<+^j=`џ =q"ƝZd?'4"1H5lI\,hq+: rj`SyPֿ.7iteHweyB(Mt32>Q!s۲J({aaym݄ާc%ć>C&&xkVtLQ]wťDϊ~뵆ٳպǓ`6) *~ 2> `.Ceh57оaph:WOV(]-ˆL 2stJB5Ru2GtA+%ɊԐKq|ceAjf/ӧL@n!b[Ҍ8s 2ݨ7̖Ս  ͐&TX}<5}ܿȶTMCA~|_@TJ(=g;Xv;zԷOcuJC BwAGkPHˍHKVҽ  ;}̊Mov UJ_5If|n* (ac IqTA=]wr]Ƈ;-§4s.Š2ioh &}ð8UJIzU̼N hXlf`BKE<QB&]&]+GBҝ50Z@*LAGatS+{+Kǟû` 8T⋛daS!rLvN$d -Oip(nXR`誫WImV XGc(i7$9H1!g8Anj[l}Pc&ro?)O_'=XFt>DdW3:*dQ׋WMtJsHtŌ'&)zXS?T`((PE.LZ4+8Za0N]pTؤ4Ȋ;w[LE1[ R"ا@J(CNJڜ &rqD~' KzSs>LBYbZSzXL^tdu;'7p0<4!ѐ2q9B2*)a -kWo"lO8`oFr?VȮEnCZkK"݌mSHӿzL7]&A0ƑtMꌊ`++;𻦭;2ZPzᆐ? @Ư ^eOߗTz_n%Y n߶lx9XpAيo싩Iǡ;I!ʸݖ,'ڎo6P 5ʤղP[]Pz.el2V}FUj&Q/c p&r#V YwVʒ lYZ}Y=KE?+T`4৪rf;?_PwEy!)H3(!W_3 9ppd(k6W+IefP OHBW"1*Ϥ󬨜P4d\cl ڱVɏ=A*[v55iN5e~,\yU&Ei'׶]+RNpYbŸ˼M~н?TeN0Y£@`0bٔarm툠rYޑ O-IǚW'L̵/'uV!97;ǭZS\kcN/ыgA3PQq`6Z5+|rj9Wb*KdvYuqK-opK𦂹HQ<a7$˕ߙT r0]) zJǪܖ1N/O)e*^FƢ%Y14s2$uJRڵsN`nvM*lv|񘒧$*| ɓ ׃ ߯1ҍ%94-inzq*|eIKmØU^4Ԏ7*0/jsTiN@y4ZԣBNss]fӡ/D. UeGZ' )y2N i욝GDVXn45ꐵ;T@ !~Aԫ+WÈwpt~ipC1M1{:_Um95Ȝ99D81N\ҜY=2uҰXt]c 1klGŭ1~hnAszlg`x&08 rؤ`HHnA"Ћq =,m)zBu:%Z8(Dύqsuo+儠Ex*cW0]^;X$tB^xH@^mZQ?ŵ_ЎMn0H`vK[̅YI!Ս\s>e=4 U:Tb8Vvz|>VY'C##6^;6fR`9LL[K%?׸ ދcM=am3ZcQxǀ܄Nr!mh?mlLCQ SRpwv0a`qGxN9%xφNQ7&M?ƃ2XGfN M#ŧ( >,dtoP9RxeR熫fucF?'\q'Mb[kܧ.WLLD › n}?W.kyzUQlYĪ={8޽ &3) ΄FW H3;w_Xr'%왢@/:ͅZd$h*gQ%D%gIk`zLO*AcTktc'TP1j>]lk<jChf#u*q+vDZ GԂ.*P{ZJA[:*lPbdvZO%*@+#cj U_/&3!B8P3zx68Rhoؑ2DK{5cw]lxD4UL[K 3p~I\-IxI_ķ5z,S- ,t8ѷjv]0o֯ld˲;:GDtv]p&%~D%Κz@_2B}TWLj @(qšv:O 3ȉg8k^ʴhj `NO|/AypkZ6%r"#NW\04TDYE2-'>fκ0\v%d"5.䢪08;hMK:\?폫&,B;'D6Kcr Pz'lN o,*|r.^7+JD "8|sў֘3WԙdAwaK6vB}GMKuȂÕL_CAOK!{錯\5[G|c0]oSEwb+d; ֽ#-%4G޷ߘB,w,eTGޫ׸֪H,Wnݔ! hpZo2Fy 1Զɮ$4m@ S0yo6f ~g;c, )2QطlMנּ I+,(!ۗ!i2M=,#qE][8v 5zZ6 0Ix 9?6 ?:D/ҧD~ \ٗ[tX<~ UBz5#:|kiN uU+-3 -Xȉ/;eI쿠\ccNO^{Zr`? ̓RϚ衟RhJR`r'3U̦UYuѨԡU `ݑ=KԎ`a'cE)n?`h]z-??GJ rx.mmϲr҇hF8GeBdCzhm0T]eɱefIe- $Bd9s.ޖ# j>oѹ [\G,N|GYLp_3JT?l0?~ՇӎQYu1^'܅ݚ{pn&VBU*O\)2KL.rۛPd2m!1b?v%LGmkcgb$Md^=Mlb~KR;XL6& 4i] XZZ8?E#F0$6޾ihS j8RirdJ_o[5s!JÑy1$'lJ>M˳NGB۳PF/ס/˚OXP9Anfd^ʨ6mYMn #LIi7gLH8siCSKT ߊ(1* T"74(MJ5'#S``N^Tg2' 9 'IT3\DBK?Q['6w±jPP]Vzk X#X=DD!ؒ-Rq5Mypj;%fjqu/Bؙsj{|ȬHpl0&ʢb"ܔ~9$!6rҙ”eԜ6)l{rY!_*qͱȯ W"n4b~c\xWkOOĚۇ?؀lp]AI`Bn]hESTy  w;BY`5zle7-M?x 䶅0K>UzN8=RV蓖eOxԜڮ:=r'-m)ٌ_MwoB-)W F;7=<9Ü˙5Aؑ~RD50;xh;3VjtAIA孿qءPz,WDK_=h]fW3˓H wnUDdxQ'򎄄cui B4\V d A3uU&%hTJ4*|&ӳ@ ^L ٌ'|nuU:E kZ()r51i.UšV !}Gr,`#̍ ӟ7QݤǏ>tɺIq7,s֐ŘP>Mg]XevCa: :z~q 9Qҕjt*@4ƥ̼Nt⣹plNpf_—K+EȃD4ʻEw_:y,1LU` dڶ-ӧ\ww3N{ ^u7ʩ36 I$=-ϺhQ>ɳF1}MOÁqun ju y3kf834EXWv"rVz0EI4"\b{NH cR!nCIGn."%mְ Zj"󓉖DVg+]p96BS/hLwy _ 2~,FYހ %۴Ay5<Ȋ;=dIH7kMg%%m+1 7`]NU>)GW%e~M w&5<:RaЖ kC]n Q 7 < UrT @3z:(dZ*9G-\ĄLG7b.1n/u3xpk؋6rATd%(s@N2*cz7\71z,Ɍ:ҳjFjM\i)z6HnKm2VQ3{_j sYԺM굍g;vhQ:79Yl$ۦdph!"hٴhi..!f[n{l\XCύ8oE3L?y9 5N$_Ap4{{>8S!X!*Llo*_=I]UZȗ$Y^ W.sH\UY`mO(nbW\U|6G.d$GAeUQ\MP-&6o?~^p +k|XUc!ivn0,R .i鼯b6 i0LDۓk)&Ǽ.쿖{c'kyNu#վ5#}%Εya(D # |-M-~NnFD?yZlqHB4]*@hXIA- Zi`BS=EhE+jGeK0ӟD>2Pqaglu%2~D/hgش.n+Ahh!-bCRVA2VJ"PEI ڮ.|\L Rmq]ӫثD 2ܞLN؞@Εmj:c i3dǖa;ȱ16 -/]]h,Kaeo ;Ϫ},3јX)OZYf9W(0SŲ0m - ۡ6ܪCRؚYp`wMΉ*q4ueYj(E%ɕ6bmB4ET<樂T8tt(x!+=M<_}.)}rtꨧ~U/ b*jo'N] ܝ~XY23Xؽӑj8Rf^.!7xS ܍o8|v8"ma< zYBdU5^/u xj%2[ *;.T{U_סA-B>>P  ;/5%pi%Ic RI {Ny+?|t՚1A?<ݽKV[{hP͈ոs= {]bme1]Zo6=c?ݹM|h ՀO!0,Q7%:A~XGUu})OA˿AnL ߄myH]5_FmYї]6]Iv2*'ť[0+xjf޷HeGFj,99=",cVJ pڑbk,Dᦠ.}PeTZX^5 +Q0wtL cAelm`Py&0^э OO!o^ij`n!v>\qSm;G=i^ק!b/~1R?; -,f.~r$.^k|:2]-8 'M%4WrG.8 xfE1ADtƎVQ2`ySиr:2 O"c'I$P8 `M0OHtnEFVݎRM?l651yG,-nOn ЖAO&GflŌCeV\ꌁN)Ku eŘ]3$2L {IES'g?8o~{ ocx̵!to\N >0: N{ۢ1e,W!k&&֓QoYd~fI+ 0f̧ tICC$>249)l`|T-sO2` a\L%<%DJuKN2<֏Ze@B-HI65coF)-z1[v]>,$-\Fk zn׆]w4IT 7 k đ?G4LD\u?|Ԑ)F0HlJlW50d{[" y]O~Pzr[ @@՜!:~1_c\N9(r7ZAn3̛:,QqWYTQܲ "Qv|\~iYzNl _3R2RϰE-r=3&6XyC k߹?T \ݛ],i:蚝)N*~wgMyS?~yD'D y|h3҄7{QcEdxx.u`mw(w3W5vIng"mDr#C*9)3rU`ƥ%sl2ԃrG5X*u~V&nbwH h@weoXxRa,."lĨמpfi p'!E#۪Y9g.d`7A6w 9CKv]*W2Mj¿Kb.tȖ6wqCVC_뽁}\oU~ ER4fjw%uߵYK@6?]wFN`f<)eU8VMŽ-a `Vғx>)_r*>E{'ڲVrʤOY6HRjPy߲BwPrW+y>?_4;IG~4lT'DWTEZ…5T.A%1= xZ 48|?cE%1wF.STψ{)3ke#yܦ[je{d1f J5C :{Sߝo[G>9|[E'8C)HU_?e#I^_%,,su }jbjG>'J^v9bJxwT6a,}DWm ZAj?wހ `xDCrgZ]Q?7$nrʋqyU E="㐞ŕZ+B]pY`rkTDVkX*L|x[LP$pZXaC-Kx>*0&BSDAa^D7fG[^Qu-:g*,CxYs CHA#-P'7FFL,2vvm z,B2 NDbT㋫i vuDF"٬4 #Gba3}5%kE9Չswߚ8|]t:ďrǢ4zq #(Wߑ cH-$fݤfӻRS9+1D5[˪C#IyX)%5{/H?E|ر-8DX 9wN**G$@LeYw9ydaM':' rBz{\? =d-˗Ax^!3'b掫ʩ"Qq3+&T͢MR:4Vu^c~Ѕy{rhǙM풺ѕ(s95s YA]l]NN0BC&w@wz_QDYi>2]Y(WgZod`64H -a˺:8mҊ LVw8 &16n)vv}h?-LkCOwp?("/_:sث!6(nF?%دalӒކɘLcf0>./piL|잦ʐ^A-c2FVrBt C[]c4. 1?Y8tʳ|'g -0ZQܹȕ_3c3g%j,WXxa.BͮBkw)KcӑnX;7ۉUFa`jvnZt ,5|܁g1H}G&Ձ3@#]ZI/齵Nυb/ &+$ΟJ _T-{fOž  q%k`'71EڊL*_Z%5D O60 pb0JW"pԹ=1%`U:Ẓz&2Q91&1M)zXs1':l [aEΟ˘ε{i)Py٪H>(֑T%xC~upሏC:-(sނ|XzUTk5K9)}y=%HNz@(JAT`|sIt_ %![oٳ3[3|_lF9ny֫kK`XoU/sH>*N]xwyXb= $m}8RlQͯYPw"mՇ3V{m\?M[XWxJ'L=p+<K BCgdzդ|Ҷ{\{5 ZS![lbmJʫįy|8c?jS3q0^Q3:PnK8ϙ3t܉IXjjM #-&` 0i8]јW8/0B:|Wz{|*ßf5"SoH&Bg"ΚMU%2z74=/5%sy*x b#V%Is"^ 9i̱ (0Bya ĠOl/`>#_lXpe9|hh APPYrtXQũca&CEIWԮPU8Ŭ͓2(fb ߈3YS=DF0m d5fۃ_T2j%\#W4wE1߲$0 3L l V(=丽:hm xp:ˌs.ZƲSמYKmG]1'FrYTP&r^GZa} @>x^81:w=g''#[r3gR䢘gnxГ3[io Q$mX~MJa$Xp|-CGpOg!- Q*DT"m%y$*$`$YbMZK Ѭi9$X9?aF!? *ſiDnj9 yIz",)[x"T-xTy .'fɚ̨^Q$myok(JbuUgKcO"ɕJ&1WHp;^ ?}ч_A[NBCw["n3^7ɥq"=I8\{b\5B\X+گ(=`ˮhޏC0ڒm=7WJ:DM 5zg%( \v, XZŵ\0+0> W(g;j+ă8sG&x2~<@ģBc?2U܍1Vm|d|8ہ'aACz۸Q&-P eV{@t4imkh˫“ZMŸK=~E1b@X/rR?ָؙRh4#-:\B!v^,jaL~i (XS=Ͱ=z8GDƴ~+qky0$`uMJ+3r2gH.fFand|(6곙:ʰBdbc݁JbjUsӎ{Q1g5RO1vdR oɔaσ&È܅ث4 K~#6 W@m$TGsRF 0܌J$!¹!N^361w}E ">|Q]n9[з%mk!u 6"dC$1[qg%ؙC^EIUqk ^zS~S>΃ T*!9Ԭ Z~6'}($\gQf_ʣ::X8vFیa؍C^9AቯB{gn?yHZyx*N_RlK|j3i);Aċݯ Gb*>z݅%W1Drfஐx2Hl yoڸ Q{S|Ys6(2敔# 廇k^qb Nu q1[jꔶ<guM2~n˧[j@UjkȦ΀%|Vh\k#pd<ﳴ-MN@m9Q84T X$*?2h9 #X Ԗq {H:+2IeeaK154?O2)!2g?F(^ۀI. C|F"I~+_ A({Puu%QlW}ZXmzMJ7>`~"<{LOڀ"W3ig3 8ˆ9@A.')S8חy1P{W IєDb*U|G%R [Zn uפ\DnN=@!:Dm#z'6DA_#` #zij%o*_[djHut*ДwaPs0c8Lڦ밁}^죂̳oPQdқ(TJ'g +>%'nsk(.aW2.3C'%d5ǻsA0h-e`ӶJh=ӳXtgKp= PiMhr]*sjᏦAN[v!Ġ-Q ~*8i^/Z|x#t~؂Tfx+zrK@J nxةp]ө"m֥}-G:z8?@@rejhĂU5΍ouhFĬU5Εg|FŕVc 0'>!0hҠ|?", BDle+DWKI+8N۴.+ kA["5`Y{їc6(> uW`#H(/mWgpεd7V5GBEzบE0U#' -N$W~7E?c񗅵Ov%% /.ۚ|Nr>{ɏdZNbz2NbFy UǕ)L2N݈~*9hAojWo*"9G9I@}Z=ʚx<>Ib^+HP֭[/la1C ʈWQSdj0ncYTO\NKNLd}g>?CLy#@zNϤ+H+hH61޻JR@Zm hV_4`,E!x"9^5{U'KnaC_Ff: calO*n8߹rN:;Deh 12?b76, $NUkE` 7}<:ڣ5ÿ(i>Cu03Ddz,H)U6l@[h(I;l pԿ88PֵS=8H`s,8u~$;1=X\ABF}JO H ԶCote #V0wtq]*UkNA{<"efc7Sm*d1dh̩)  @_<֨npyNW[tmMVf%wBpš}-&.[?9ǖƝ Anev l%L1~w6|hՎg4ܕъRjqaD0E'Ԯj7_k6c`Dࢀw݊cP0-utei]s_F$ØMLW5߲Vz}9w!m r4ZF꤅߯f[Nko FhXbz-jN/P] q梇#s{PrpCC!uKMM,'i n!ßqйj6> ʔav1Lƕف'V7( ЁJV7yR-ਊr|lO:Q@z.xcmlOJ)N@6I/JBe8#OMLN>[Q3$R; UEs=~]SpÏM?Cw"ʺdQBXڊB[6y7x3_@#.il$(},E yGbxt5ϡM+΁ l:5F盐/rcSDj= \@2U,"ܡZa)1g "V9X?k}3CRZg,ARI':"2N*p2)ª&$4׫_Ṣ:uHu"j'Ɔ!&V%z|\>g:u"t}[ ?.e}a%+*XOhAuOVXFA |9VM c+eUe ?"8cYeՎoxTMӺӜH׬$C7_.Bڎ_V4xb;3>G-S:px}"VCRv ) n)O(/P:ð8IQ6<* kN2nCƴ 4[LS&z*v8?{)SdEd<^t:OH8XShK dnAH4)8zC|9EL `TㆷPGFӛ<9ޙDhCqrx_@|'AM 8lMBKa$~M@`Ϥ{#&7Xt\O?dj?uIVy~eEp?? ~hq `;Vn{xDwn[aO@F,6 #M@1z6n0kplko 7ɱ`m[vyP~:iG=OUh;^׳| J~ʑ[_̙Nt@ʵVi/"9l 0^wEE]rQ) }x,Mݥa~8oöBkyJN#*`n3F 8QF!VAi>O%M"U( JLMuC` 0Wk Lc/?mAl=-6>A)#'&2qTR+fnrVWEKu'Qq-=+ *WCryi1O? Mb[9a;| s#hþѕulqg zw7(E!閶YKZF=i[Gpx0._NJY-.ZYezzV{EB8%Md20 m/9|*#{7Ol`zj 2c'h9%"{5oj}*r)o 0ޞ]"/YuͲ/%Yedn lԩ$(!Tg09!kK'ڕo/N} TR N3{?PңkRq.ٺ!czsXr85=bhskkpC"Msҝˎc‹`zHoVÌoAo4f^"l: =.{â=/?.oG!%"IEP.)E\Qm.lEtNa *Yg^{0v8A}XuBKZ'ZjPqj>h<'W|U/F@RJ(ag/&sFPG%֝y{izkN֎C͕a hrUMoќk ޸lT^ = W`y/Tۢu)@3(=Mʼn+}O3uKAxdzYV"h]Djywżv^&Xmp-isLI7]=AN#ZM5SJlh/K@IW nPchkY62]\}&mK I~D+) MXjMSw}`_毽֪&\g,^XKďڤK%zZ3 lt!tc+/sK8oBb! /Y\z,~PgU0\9##R\K5ǵl=e1I }:kwGeL8i:|Vӷ0BP}Ô/'ZjmhMe(rgkcn\H VDP$c5k EFacmpCcYOnFs-qZ7zw4]E7Y2{$!H,cJZycs8SqThLـMG7RW}KA?ho1_':;,so]r}bIe; ?իZ)Ȉzxzl6'wEYE!jʜ΃b(d3|ï>޴bb6&T𼷹R@ ;h؈ᓂ1 i\3 3 Q61Zb1"6f#0G•aF7Fe}?p瀺Y6yˣ;c2KD$|/djh[,3APOreZy/晠|h[SY:"L9N̫ڭ"ǛQ.jO:д \$6 (B;̉l=HGEtg@'ҁn/K!V5J[shRX?Gf bY>2{-I؍PE[ƒmLǡ9fT%l,lXjP!,:/R&fuoZ[\tz* ).Li?)kA]DBA$&eވA#)_ b6gPٙ!yZt p>A GxFq QΙ 4q+7S::/[G$ KFlj@͊Wf8h9dV BrAH5(1?Kؔsޑ }"Gd2=À*|F#I ꤏ@X`^sv=Qg6 %$mcBږ<`C@62_=c%sF_JRSx)ҫ~׸hOD6,jH8"N `%x+^̋Z3Q8&"7=$iPŚ}*^zXE#YGӭk9G* *yQ s%.un9V6kOPYg>ꐪGQمt/bVqUdCxMP I>/cX'E*e`0]^l"MH~OKN4bb}ɛ'|=C7>%'Άb?5*AtMH;LY@o#^?.vj^s;qV) kA!xݰ/i_拜r|:a k@ܢu,m== #G@12b5k1tZʞ +.d n EʁO &7:&:}z=t >; ԛ uo 1q@*T8cO>r#mbѬ̗*O]AFcZ|H/*dS{w5vLMGƘdXLqMdTi1~%&E'ݖ9|+e.!y`M]zé ."A|ʕ3Γ.i"qq`ji1lDvɖjGŕ鯿EA[1vet PJ[ED2)σ1_ũܼqܒCDmhUD\D##]0w"Is8YDpnʃjgeL 93_rgc{ig/y9g)4<[Ê/ <94Mʓ9*EOL>|m~opڊ ߝ}QefFDW|M'ڤ`S5dX2ts=b$ r&-iEA)bk`KK?Hvq$YT䞔Rr0 W iUJKA۞6hrvPNԸsE5ufd֓FOw ^M}cQ?|/'?MJ*-_*/u 5@~b/E܃N! :L UH43>5wR ]D|>oq(X-M z% Nj3$XdC̕?ock]OgYi)T/QeV#i]}jXYlJI͙V?K9?=VBɍnj63ldCS.N}:<4Ö#]*+4CK >d‹;g˶v:*l<Z#J,+U`H QOF+qF63;dh{AO)BQ\tg];2GzX_m^+7&c T> s\R$5l6/eV׼ε-{ )e9u1D$0TsQi ͙Hp [#T[ 5vJvi ;) [qϧld8#y97xSs 3[p]ھKiw[]HCGIJzʊ7!+!zSY^J6U"RT3"`*۹4p8޸\ M!+-੾||{ N’}F>Y=@"`* i̻OI6J~} pQKc> ,THJLgv+r8<3֠[0#R3dO˴t6)9mO^щ:F- }z8,ƒ /VFunUV-^ko8ߪ .I,DOEY(/ jĖz#s{ж E5+ᇟZƑd6~ 鏌Ggu{ ?ΒBfDppCn_0}΢f=1|xK@!U ve'rʢDy Uc1aG2Bm/dIU-;afsXBtίp:hX!* a& SZbzhü-Yq%i2@,s(@e'N^׏bX-ÙUb1g!+LoK_E>^D/M>V"zMqE^+ iɌOAXQ~37¿*V*&'d->"D'8E Jwfi0k󒑟߈s.# D%NKiPG6>hGP4)XDlr,rU f׸Ikbl3~*R  JH{~ʪG;K 5}JqÍ[f$ MJ GZnoGp8gn=j]uSTr?sǒ']O)՛\ g7/qsYY@&YR)Hou߫@W|+vY\+ JS> CN|<ݏb ɱ:(ʝ-|`K XU釂.Z]fK6n}O^ *þG0=6_H?@sͿlώ d krufmoCzܟ5pVU?؇b(KpaĂnR`6(H .OL##\"wU!g / ~!\GfMst[ɠR nx6ImN[Re% U `){]HJqsqDRwM~e4ZkPIA(`WF%-V1jnu)YC=Vbp 4c3STÚ&({fI0gk8V`&YZbd\*O i/wqdb^Q$ũtsO}2D*hZ@O@|8yAFY_a5D2}Q8Ud~ 9/Q3uNۧY@H,E=c5-N& lXfDLɚx8hΨy mTdqD󾚂C7ڙN(j`cq}&omMri\M~{H.ƫ7H T`MK w6ʹ(/ėSX[>-Oփ(G UC% _N7duݗe*Lg&!{*k`Y Oh(l|Ӓ( g~ȧSK  {Ok8(2SyZC*qO4;~U߅!sF}a>k\ewcAV'*Vg7wvtZ8CM.fuH}H7 ({k IKd9dz?`̯M|Tc˖n>!ێHQh`ܨSBO5z>- *.H> 拳 \\~>GK|D3ustd?@7nUbUv ,?,}OrWcB~ŵ $9hIZGhGBX^0.]&^Հ\N| u`G篼^u:6t=oV}:g=h  歋 PdSTE*(~I\:9^Otlje;:' 鬽 s/2ג+ U'ihN/bW*?/{G#au W"ox?g;)E}-R}s'zo˞k)R_[r(p_Ӵ04-M 4mZp xUD.vK}jy;4x; oa4U%Y8,eOA'Xk tһM!~cm[8b(,Xt"(`U˲g[IWR{XmͱıqA)z{z$R,࣒␒7~@ySGy-%*Y.1qqY)d\zh{YQuNj9;"aVGzxbG q'ژOu ,zB[S0@xDeS3 2z_Ǿƒv^E @m@C<h 1}uM[dnU~C(M.YdZwu\3ݼk}Y-C/o7b=Mvܬfq} >,aKTeVf_a;]?z#vkkaO?P^}q5M_qڇjҨ,b-Lԅ8w,3~b+T p17PPxn|n{Nπeq8\ ¸=SG ($I gHMr#լvDPɠAl@͘}Z>ٷ3Ux?ZY\wCyY|,gOmGp[Ҍ9|׏NTXblnɛt_/ P_/m NUڢÑF}8qTёme{ qsMNsZBpWqlbuzb@aO[=lTbc%l[1dksB,bi+UYd}B:;GJ&ʓZ\ǽ^{""CtE|8}Zh5?o.(pӦ!ogbH911t$iiA$KY,EZbUeðcjoutKJ5'?RȂmqt[Y~(*=Dc^]v*=4ۥ=׵>%"FHQ61fpS'w}&Xxu0h7yZ۴xou Ou,vjaвM0^@<`DQ b>C'f ?x5f . G" ﺭDl8^A Aq/_ߌa Ƶ(Kd%~Ï˰ͼiCtp[U ,?mۚ/l$蛈, 6SG38]vt͇qPWn#. Mu\`ĥ*cV|5^1}zzl &ώx2iRe720[ 2H: oinsְBcj=mmV{Ȯf˔ͧ юJoQyf!ǝzM+r:ʑDz7D;%F% ];Tk0-ܵo,Էb; )Y{}_-m;)cR n=R$P Zu2e ?)՞hJ 6KK ?nBSIR&Zc'|.ꆥ(],03fѽݭUπɶ9 ;LПvY+ˁ\FNt!jdM:tS^b%豗rjщVxeSR7aDV(4b=4W5noy1O^~!(/=DvwxI(I6_A rêz& oR0-D\{hw(wiAcEV37WU#Gг8*oQL2/WV!׽50 Q(s'6O~(![v# q2}7Kۯ#4$.n/^5:%m-?uv2>q% QCJ%Ar/߀RRݧ1Lo'S4D7^\_>ʙ[X4?xaK5?iKe J90!0j1;MM&<:hU\ <eܳш+A[J06ιRћ fQ$\ O70rfuALag:ih"boiMa1+Oh`Uކ;gЮ 끲OJQU|1wn*Pԋb-ZeBK(+|XSysCGIS'y86 / p]m.(H/ì7yX0^J(+Ɔ?Zko◈XvB0N(\2\z 7T04` "=@_ϯ=؟8l3#q +@;9J\R)%K~B~+Jm3%GBN!jb F3¬`(epRmI 0Չ +,? 61@ 1(m6 ->~J)l$r M&P#=x++( d{}_N"ZvObjx.jm@7p\yu%fgFpqR`;S:5\ ,7dmJ1:hz&}3C¾:7_qnj*GELB\5^4pYR҆g?shOҺeJ3v57ToƼE.40 k3eCY,8]FjV-aympSS&<`vrGEBٱi?yioZ9 # Ni@V>1I||0 ͢d'b3L"ޫ`=76ewt!ᯩ_ub@TMbI By5(Sbȑv`I9kX%Wvc&׼ҭq%\GUaO,{5쎳^@v8>xE 1&RRXPrp`i"X^K(r+H#ScQɸܿho?uIȣR][UOS3*xaN2+mPD{h:Y™̸+''V%Vfsѱ''L q8{:J[Z2HT"[Cw-@`>^ۇt/%Vt8h[)>?%upyf"qqlr\aK1l G)aI1XTEB[ dfO` ZmS,,_8q07k }J?:݂brk#;2dbibǟUs,vϜi+.l R̕%4!Z}ˎ#5_\U%2o\'P*JԲ)W 9Ȉ<04 Wo;әHC(X(2T=/?+j3gsS`~bWf& %J.ԀL7] -]CgѦݾhȜ!;JDWem~mr# 9a`3uwP֭ݶ^{3qFϏ> 6^ټ7(UbmPȗRuZK$aࠕ#.;_VLtA' Fp3&2GD.0 Md>Aǐ<@J'Ft]B_ \ٝ;y),SCU˦#]6I ph]< B@)Go 퐬XSx0^pZ^&>10`5r;-[? ra5Q[Z%)tmFq8d` wn^s_23W4L) jkVwLZ*'w:-Ǡ! xljAU<ةKcF>4^y}#ztZPؙdj ŘFqe#zp Y4vT' :MaKE 6ʼZ0 IXR6q Dƻ 1SɎ^N Rg|V'CD%KUŶP6}Gy/|!޲V~É-}t g%4*?Z w A"zwHe5 D豓K(w]#@2r_/O,4B^3 H r >@:DFUq_<6r57f PF~7&XZ N%ȸԙjb^blzE N7^P2ĦjJ>բo~- )c8B\5sq]96d(4 ,xd]n&;,͠"ld`.Et(-"l 珞«toOZ}Sɘ"m0q99+y<|3\8r8 |52j?Jt#FvPl!OÏ#SA8=䒼ۙxǸQlo*V(Z(Xڬ04Ġhj@M&2e3' ?goOoZHj B,Am״,d)˓UیQs7IWd4ZӚ&%w2JH½~hkGbh4у>bsܮ| I0BZX,Za*_ 7N(*['p狮Q,[*+]NVۊ)B-"3ǘFC|(uՇ]K>rn 4k]o\ipˈ'Mɡ(bpb8O1xY^?q1;{J*8BԤOq"JH(c-s%=5Rl$Y% τJSN`#|8rB䆼w?E)CԬkAz {O>=Є݇ neB.٪C =)1{wJ `X ˦W$eݾ%)Lrzm @AC(Y޵OF <z9q+$ۊMr G j؉O{GuMS f?̈́[,T_m Y@,ƨ3!}pFgq1RvӤ1FSI`n>_VB}p+HW#Ħ(ȜM Q}uy<ڴG/*8:9Jw>PԌKf4&žhb(U9= P$đh]T 7JR'yb?Xa6e3R!%y%xqT|QS5yiRz"Q;~a׈|{^D31Œ5i;ʈV|9LW4EB%~+!)2_ zE _&+ɗ[z5F.aa=+~u7xI|KRUApV(>ɃIo[Nrl~9o٦\h&=((ղ0ο|^`yWV^*a ~i헟Շ-ffs ;CiGH[=V P@ C[E2NxnXAm3rv;)A@aʱnA~ej :Yil5% f Ievs$%#Ш<$ָJBp ) uc@{S\O؅*07-((rw#' pMJt~wc$9H"_e. gmR8(oU]H k,FREomS!lHkcgCHTbM.)OWݹ%4K^ f>98T8 5JDcwꕴ3TUHxXR^^'ZT5wC$,PHnF,0-XxĹ'!'TruÝހ <A ;} >>Tcj-?eXA) Ϣ8EwrEnN)gpXEI'Q њ$̄1a;U܊' MWBE?ϓ LLy?\W‚C6Yti}6\_@L; g$iZ(yuPd6ݺ[[OgDa}p,YU$S=誜]wD~bC/$QbuE[Jg`_XwWn7} oRXVotDmsScpԱ(|`MRUJD:CbccE ;)~SO|ғ`Š1n+0pnEeMi1(A72W` wW~O;x/=%Ea ==Wvj%g#!/u_7a&yMOSz]tl_(wncY䃳j\C e)8]YTJZ e~H#_W#X>$OIػ36 b)A>hސaӽ7 d2",)m+| RwKs<&Fͺv@٭Н(Z|HV E 2F"DGH)pl %](@9u T0Q3@LOb;*C1[ݪFn%/ \dql@ tݏ&0\W#Rv40j88=m(͆<82lU+j~iTݕXQpM ߵcsEO͵it )o$=N}MZ22ӮϜj غ˺CG؎)$hǁ^;_`9iF1%Z'- 8 5QWϳ-6O˾NG]bI&3g l $H2|i`)ςdeQ9v?-Dj қyɵ!($Ы ~E{+1a3Ŀ\au_1`ry$O/s2nߖ[B@ fhv3]4(n&?eZՕ/Նs%s[-v'>M_:v3h8G`)˝g?}3?F#@0F鞷D0g~a0M*QYntzb=>I'K(;'9G\,./==3QǤB@Rmcz䚠R]'irK`\CAW]%GIv/uJn:LZUxb 2i,4H!g?ׯ ٴ+~8FK[GSDKo:'AVG^[BkRa2>‹OIOCtx)ʢ4qwsާ(G 9|^̟O/c-ËpsN4"[a&}E4H?&e8@2ȀܠLj^lƏl<4a O;^*78&`o)G#υ8@.OsrZ_ Ք>zʹ60ׅe