pki-ca-10.5.9-13.el7_6>t  DH`p\I$ƨlg2RpڻbHR#`&ΉS?=R4qI 33ڴc}9F-D3vdo }xX  04ڏEy /)bz=Dm^# V~r۟F;M%sk^}t c"Y/!"v-KaZ~t?*vI"¿!+6 H NFpXؠiP; 3c_ oXc@ 2qc D&D*[kgQ|vNxĆEbK#knP̻n}TzGReqOB_-vD@M t,8!U*8W-0zB^ޡSҮﵤyeOXdORrIvf3%3uXpά'8VojZ*~˓Ns{4<_4V s~&7>Rcfbfe9e9a96562280e0d3c345eca1b52c8b3b67abO(\I$ƨZ*Vs%kOʛp/cj(י uH])F@V #Oq͊w _tѿ3 >Ѻb;GzvB7ZV챼h!Kաoī$WewѓOM?%՟]2q [άDyɛܭhptIљޭ溕Q+rh=syB{M#grsb-m 7?d   D        ( F L Tdd d td d nd q(dvd}ddT\  4 (d8l9@:GJhdHOdIUdXVYV\Wd]\d^vbzFd{e{f{l{t{8dudvX wdx,dCpki-ca10.5.913.el7_6Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.\.x86-02.bsys.centos.org$CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m)?1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~->E,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤\.[!T\.\.|\.|\-\.|\.|[!T[!T[!T[!T[!T[!T[!T[!T\-\-\-[!T[!T[!T[!T[!T[!T[!T[!T\-\-\-\-[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\.|[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\.|\.|\-[!T\-\-\-[!T[!T\-\-[!T\-\-[!T\-\-[!T\-[!T\-\-\-\-[!T\-\-\-[!T\-\-\-\-\-\-\-[!T[!T\-[!T\-[!T\-\-[!T\-\-\-\-\-\-\-[!T\-\-[!T[!T\-\-\-\-\-\-[!T[!T\-[!T\-\-\-[!T\-[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\-\-\-\.|[!T\.|\.|\.|[!T[!T\.|[!T[!T[!T\.|\.|\.|\.|\.|\.|\.|\.|\.|[!T\-\.}[!T\.|[!T[!T[!T[!T[!T[!T[!T\.}[!T[!T\.|[!T[!T[!T[!T[!T[!T[!T\.|[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\.|[!T[!T[!T[!T[!T[!T[!T\.|[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\.|[!T[!T[!T[!T\.|[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!Td6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ebc9f4fe357967b70735e8b1091f8429563a9849391c931795aad650fa346f84f1c0db21c1fc4acad6d16f5e0260cba0977a50fc158e19852e36dea21e4cdfd8e0c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.9-13.el7_6.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.9-13.el7_63.0.4-14.6.0-14.0-15.2-14.11.3\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.9-13.el7_6    pki-ca-10.5.9LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.9//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,~] b2u jӫ`(|h4=>θ6% k,7T"! 7Ɨ>jK3FH i (6B7Dn!HP7; 0~\; |C l ?qC +~K#s`'X1#s@m0DJ6pv;ັ3:<ė2b%l&. ;Ci<+ECa=۝gT1^]u'(U2Ϊ۪9kK xH8 HyR޳[&$ k/G1Q/2/e%:0-%A2[[UMbuÒ~5,pvcYGc>h>\I ׳3S bwi{sXƔ0aq%S9Ր |+Z ,:xlaB|>GDͶ&k:@mv9kr}f2'/~  Z+@Cl3V,HfUn\G}*|ݴ%tU)P+v>o:M2TZ🃓:MWK|.RP8AުgYuJoc-,]tr\>{HtzLa+˞:U=>@Z K^)7!q;Y$'˩5Ǖ5x;b躃 ՘Q1H2`eOs/XtdO/@GXqJdܭ= S8|S? [s3K$TEBHp:!$7`ŕ>ږvGE-'k_2.J X7](*^`biYcPEc! lս@AWٽ~G&h& l @y X$w*ɜA$޾r*?_|1,9Ohxq)tXLeʲ["㾩Gh&qt|/I[ /*nxQ;+ f|#&}լ uob|0V]uj)oL&3A#="}-a>?CĪ~C^KbK!gh!Tgs\#]_qˍ!,H8VI.`5J`dv:2r@ZWA?ƙkYS^j%uwQfI *\g#W+o}z剕[B{_*LZ(}4zjI:,6ТXAQÀ4(o͔1y)g=T!(/^]+3CXoNC͒>汰9RyJJJR,*=¥RĚH̬K(4NՂ>v_ӗY~GBsjsS^)m4Z%๜h3>Udvec{xT('DDR姝& ܁˓'B^dJ/rHahBu* E5q0%3mRY>i˃("FTw>]<(ۖ A kg l*wF1Ma:{E.`168#`vxvU"cJTWx7a0^@be \/=NVҊAyx377aDvHX`LBTub5Հr}ֶRut ?.RXdMGgUjXx:uz =t`cu9čZQ@B Q; 8m={eo[qc+CSp3v|U2+'}򍅎}u;ǟ0 r]Sx줩G Og9m;@$ ^ie,Sd-MZlcoJESQ:XƮWG01P2]|D,;RRGFo g*@W 0#|?2}Ny)NJn}k1yg>cĢ Z] ob.ϾwxleO-󜻉4OWX4*1Iy{ߜI2jRqla0P a3s)lx&Jb_>4z%0?93Id=k529r֜\8dDA0X2ry!=?P3P׽U5Yu7.G4? 5a^4ݛsТ͘\ LnhQE`]e]2u )@D~b^+E@T LO &E*VIu[SqNڌ;MXX^<WIw/ ܧvYf']K3_mzѴC6!<E)6ֿIeBV|ux){6p}3g2sQ7xș4J-m3epsvP*z0QCf,Y!#@a@fJ<`_Ҿ PLV=@hHRp#jMn9j3=JXq"ӫA큚Àmu! T1Q|zFn]B6:rn[ㅻ:gt"0 nYVlL$Ny#K[-"YEʿT5=zM* :Nm.=f4JTWlN$ܵ=7nb_iPvwlM7(UJAxhJxyA`tkx_%S:}gՒ ?%T#N`Y0(a r\;H5ÿCVydJ|M`!_<=kEcrQ}8*V`hx1'^FzCdʼnQr_HZd)K%.LJ0&yԮәw!Tkft|UO 33 ?lD Kք:VW,dN~"e$앯~GC:2U)EFܰzEm7{BfK!t$F3D_,I[B0 c nυ^os]f ( :nA/& M&qL$'gY[9Ѽi-*3M~ w4[E`g@?Ӥ,QXk Ջri&R.pC΅L iBh l+sz`汣GP[î|oQ1{=8vOGsp8bf5%fc^= ΩlC;Ts{ٶ =@ ^rnxD.LM/ 4_1TZs ;x\w/Njs65,&# mǡw1(06a 'Yg; \b紝s. T'03h8|I1EHu۸ޮ7/@xpz~"c6? ڐp4U+;fpj\w'/o*ACZk<hsӘξvZno%{=ԉ)S@I4[4xB;eys*ך}Fg|n|Mk>1[e2׏ ڳ' _3L#&lc"gX}e~T(*b\ai=pR2E#y"~6@ϡgUOtVjрv[ m>b-52~Qj-ZBawM> z!uhOx,$iZZT5ǕGeBN-# %ɛ%ɫd.6эn=_0z{`W2z rewj,Iʹ5鉾WkF/hG.=8!8GKD~jK;Gy|_=SӇ>H⁤&-tcF]#Cc"mcVm|h=!,@ ` Ë&+˼Ph%4Cd E]Pqp",<2 zQJFsCM#NxZ wت9輪~2'EW8;&[HQQ<9~[o[#yٴ.D[dl8nkP`}W 5X׾-`xH`ڐG0[g&CMY|̧ie_*]=0cvTE?ֱP/IElޞ?Ɲn0ƆDzX6̸EgXTɖ8]$]LӛmNEz.GʂFY&XB7kȔ*zJ@栀7P{/}Xb)giX,ٻ`HAp!yCm?J|^t$g^r싚S@ ,$u- |0~ yA{ /3!d|ܷl KG " ZJs0#r6Pr5(y2O]Ֆ'N症\#obNs dKmY߳#fwZ4=! AثSC4A͔.1Kjq nC}"(©/,R/Yq ~SGi.uZGZi毒@Ѷ͵[dN# gRsKcy)p8@1NFT x:))d`a8ҷr [^CXnazY6d@Ƨ\ݏ)c'21yï=)]־eЮP7 Q=Bdx=E `w%DW%8,'PԜh.u^ )ݙv=lH!RϺ1rHd J/i9.h8 Yyڢ~^*q~3DJi,c,pNWOYf W8кʒ礳 D)oA0sG!+ҏ=g4K"F7#4>HL*!Uթ[I+}q:Ȍ! 32\7W5cg)/kolGȟeUX͡%] ir5πNu<"rCw .':) tۃRۘrto,K :Wڽ~EHxY=Az*f%թ!;kf@w{Fß= f3gHqAK@?H #Sۛ0My%_x: mn;?ysp9aUci9lLt'0vOݽYzmU'jt޵)_LX@xfJk_gG,8iVkpz0iNUD9`S-珸0OWC4^p=H"~V]fB#6|Wh;_fǍGNi6Eѻ(WC7g3RDw?jeq{}) qD?G@Q<|>U ܧeb W͜/YWrIf{-9w:)ƅ E8-LvXp^:S៰r3DofJ/SOKs]w.Vviс4Bݿ[b䵏z39gaX>+uF_&* ec4Mtch`V8: tPSKXS8emƭ[s>]fRuSt7ƹDaab\8&͒0 I}';cuv/s:K^eDNnC7~Gݯ6!UP9 CiDŽl.EɊ,C,/#`qeR@ٖ6, vY(x%B(ezȫAgCo#Rj %kxPO~odFʗn>wh6'ϱfQt^ˋG;fy*X;Pbwg_%ڱP2D?#њ2Q[Nk$E m үud-|H.f_bE\SӘI.;D\7I^P>׳/}U1Q{2leڴ:%f,T}NKf׻x:U6CE;l4@zg/`ZhoUk&K(^pc"j{}W&.?p$9-BxW6DVڱFpEl4&d|duxO2;Z}R.$ڞu}׬7ӾsɈևcW#T<> 'S&D4ny\u3!0]5v9*G1&Ȱb]#6b 8f,&ԂFMm zZ=ê7 QH> jcs?”G RȆ3J73&H)^Rٯ:YDVsݻfvFk$EZ{ Px[XBDؗzb4V1)SO΁%w.@$$ +*YXаqDNT|'jKazĵkzq9.ҳJpY-;gB kzdJ/75PcQsV,2^u/Z _3A_NX a! ^6R>nT );R"ͼ5 #g^BǮupko[j ~GjH<0C-dN4Xyˮ dͨSULJ$l;5:N00Pm-=\_`HiQ">gab!} |d?c>,,|sc?2+i?6/[edv")(<#2alvϹSۘn;)/']ϵ!d\/1+A%:l.7Ԃ)g7d`*Plu psrVЀ{{̊%+#q ܺ47y922X"P!oKݿf_pQ5~5O!QlY)i+gzK<6fl*Tb\QJ;j4b!&k8>'1@ nߧ܏kKㆄOQm.>Yژ0\͛e}u^Cؽ_<њf^Dݴ߄$)vQ 1n2cҔlM^,UX5`w +*4fN$vPf`T8PSAfDne:̑ԻZ=CCzDK ~ho]* e6;X[GKz,| va8P"J,5!)f:(I?lN<܊WҪl̏P*,A5R{ɑ oьPxKUfid q3x`]OL !]IfI-ҚkfS%[@@I596IڍA6n{^gvf܊8 VI ӷ+qDZ76"`UrTҌmu%xs`4)^]8rRxo uC{uU-pNkЏbgnwI82ח,TZں`hdIg_C8L=W td`N\rt\NS%^GLgx=%]`jHaN^Ӏ;#yb"VW2U5!0!~ZY>،B47Uޫl@򹆭~SP% ц[žeUv$DJ^`#ފy e/&&=;Lr`4wezl)A{Z+y} >8& k̽Ǟb6qӻOgD5r#PM%%Wpa(!փ3PK>4{N>bf< MN7J_V<5\O@91-L!E|BB{P7<,X>25 $m0ƲVI\'A(PI 9wkE}#ʧCa[ qaI'i-iZ{#d=Bq@My5-9gU#;84Y WameF\f s A}~̈́1m=q[|v{|P87Bj΍u2*+rFfi8f?m"H*kLdo3`~N+P̓ĵ(7~G=j֔uE3~]|-xs%t4@Wߙ%o{VqX{1MkA!-oc7L$HuC^+1/vIhCs XV=LyN sfr+ bWu_ܸ&Zs6{"=\:iZR\sqwQ9-,j́NW@O@% c`- xMb?³+L.-Pj''\0C8l&e<9Åo+oAO"\,n awqt#EV-aV0ktl:%42/^hQ -fRĉ:/fq`:oWy>kohڄl#룃Y)~n[(03V:*׵Ye/0"V |;u,:` >QXY~hk%^?2qjd{BKҠ%O[d4:=;Kd6oi4Auueg( ᪚J2bXgwh<ŷN;Er ;6{j V!8CNBE"d!LGư.q?lQܵ7$ "r'#[1q;,bu wc#>*q[2(O+31!|1n"s7`]@͜7\Q CċRc>{Lj)'OME :V"CpyqLh"U*٫ UYG-] 20F<X+O+C]6KxaOV;*+oڵAS xHnYG;ύG9@b)0K̻;rd0C̷ Z쭝Gw%$ٮ_3dNrV%4Mc{#!bbR_͒`iPi L-!Ia{7hmtݒwLdx-!)`AD8O{tş,#ܙkӞ֘ԅ߆휏ѕht=+r| ?PM1QƮ_}c3F%;ȖV8CY/H񂱛Iofpm&|!+m(pP\;;޽=dpO77A38Z^J>sָĥ q{DT ]B_>CN"&Q}g`L0nxH@90TQs_NHT:f"'WֆpycJ"&^uIn 7NS82do*ו" ̭' 2DZ9jhw}b Uh-pItDSѺA=q *C1ޠQӼstw,͌bxq?!MpCӃYhq?4lOS!KJμnpX?)?&^9O cE3\ZgzM3b-d;.LάJ=~$A-m7fdf۾8 -YZ8sD |B=uo L+>.x,cT\I"I2{2Ufr!s|)@6^+˃q>N*Aݿx t\aLJFh(Es;F8Q6a4 G;bΪŚGm#{iĠ.Oy~>xtn9IЎ ?"!͸,Y*ڜqq%bZeX<PRZb=fF"N)R=ej?.!6[?m 0יz+GT\+R7{òx(va^8 ۆ! `hl]T`'Z(Lǃa5Gz\'x+x]%(ۀE* סV\{O!s1@y)N-P>[{J L֨Zf#_GT&;El8,rQ 6D`tKHl֠ϙz T0ɇcU,M8$4i ki>6Cw$ Ůb57Tj[i7?ђqIܻ3iH&na#ŪGفцT &d/q|Lٱ!mmqUgNR0]$y"V:}K`W`׶o:1)Lڍ(3y2,.}6ljWc ǎ\8P!jZw|)! gK?D@N2dE.J|bjpo H4i֢m7,9"O s-DZۀs|^JϽzX_r kMuR!Kz!@,6z|Ί606ҡ3{C U'1abb8+?`1Yhbt5=:'6 # --!(b/ [M=#t4|[7Mu78c>tO6НY & w/)V)8h1(p/ > J{AVg1:%K?e£3z6|%F,9V ҫrRהe/@jqN %& O*ܓV6uX, 5+6q(OEY1 4sG4-n3aldvz] Egg?wF'?&" 7rSd&7qz0bhwLpn:{0-`Wʮ} ٘ +qy6Lq,< nu9=FV@f9F|XN8z)vD眹~tVScQ T 2}+Hj2NbMsluT$!ͱfqoeGqBW(/p d!:h صeu]I)\fׅͲyѼn$vR6yk{0Pg{ӇRseCx(actѠWcvۓo&2_g2X 岃ܡj9RE+dڔPņ T8}2eI0+'?O `* a@3фxf2 xdүⲺ88Ay#WsMypݜ~i%NRB̳:xyƩƍ8fɱZ7um {` SOE]bv \ֽ : BثcD݅pSH4S˼oX ڂ}~k{y L\b½C:aPltw ঳S`hZ~T@EݵHSXl@3n9;}Fyo `eMD*_6FCk7dz/P4pF)ӬM!굙É*|QZ4PP$TEl׭@zYJ5 EZ% I'+\K}i}  \ 8U*3Q@_;j 8Xr,o^N*}fK_` !>?VN|+R{2;{yv/p];).q i1_"j9rRv;_ځ=Z`ĠT%&@ =^L IQB]:%j^aRE\:(B_GS !EO*Ok%J,*GSbל?Zw B'j).c^ηjsˀrrߴl_g~hP]%:A-gQd=蕨A`7`x9a}>Xb! ;lh>~zGaaV<=Jâ"K _NY{Av'I"bobX=]0TzT=8,i~G.` -r*#z}µ2LmҮʮ"C.|7v KA$OrYcnz]3pTDB=FPs[sa !k-^H@gmZr.O:gNn 02~u"5ejRxb\Uٕ=f5O!y~]4!Z9>\w̾u5enu܄S]"`Dž08a:qI#P !=E7w H '"UoV~: }='jվYBہP>?4R(|0Mgה+/E\4 {O:v'.!#4f\L!22{$ܔriiw/AzU":>>3n^5\NװArP0x 1ez*^Ed 3-0*6HPfh}[㳩,?TXSJ[[$db/$l)T(+9] n7 bKy| 5-/XWG= >+0OdMfc+1Y\412Ed mE +Wʏ9.I98 5%i+}T \>K)(d!g|@iv,u%Te/uyDA&c+zD죲϶V f9?8cRjEahp;L>cf P;-UyNL!.9?/_.V +@]#T]M9'a..:+X]nH)nRHyySVw'Gߌ˹й"9/=:o80'% Kh-P] PδZUY7DpA虲A'>9*V̳³%2ryekOkM&ϟ0dI̡ĞJU[săy-C7Dsxc.{[aJq :'}[uVݬJ|"Xyt(K,i1z&&OF^Y@9>mHą, Ҟ,P x>Qnߨt8I"V#m G*#ܒaߐ:v8pL!譌vm%jzBιeVi(IH ĵFiCX,F$ƥ׀B$ _̴V`}jQ|ʻW8gY1b}ħ_ b>(MwyAVopajTN"wn;2_)3|#~S\16ìGQ%v_~rڐzjp*3o7Eο,+JUX̠lO9d ΟTL)#{ը 5Jjw4MdːKpU!PRZq dj~gX_9XD.䖅%GMUGep*E1)0pcY2ĵv[!bC(q_4cBO.Oo83Tl4(H"ǺUr"g1y,+ӬNc)ĒOdSUN&:W:S;DT(ݫNڹEڶTai2?D*DfN{Mt1X[؃1x朌o7WzK4k9R(봬L{bo%.tEVb.?c_y!GJ;tT͌@\Pc}!w:Exa?䓨'7#'s3hP&JEI4 y4:i5)j6N,nOө]5mRiಌhiloZCXf]E+zMQ,Qz/O] Xj]S|E"!̃<\TBb;?#OEN"Z|(ISɱhgJV_)Ƭ.%Ue8לHvcPAĄI7gHx_Ο* 88T !T*7BXА3ӷFn;4~Us>z6`؍V7D@Mc9p 5^j'*@~CH'K7 ?-i333l-eIK\}dd(nx=~e"i>dM!ies6#gʫT"]nn=9[WG@ryL6K}b׽1o36څqX]bB,tFV'c 5ܐ{jcRC#5?% 3Ld2o,S¼ʵcqn;zZUɤ#bkf"9(Ԁd_hhŀT`ƍ\LHlIRyu> E-bLiORchqt-g&]5el;oK_PiC-4K@gD80R^`u#[*@H~i6-PT,+"$NJ"ONjJB[f$dJUK2M5hsƲԚ_gz7Q5(GP`^BXg}oP]AZ0U7Uic?|EO^& ԓ,0]e.Wވh.Fb,{މa'C֖I< @C#5nh;<ކӟٰ-䖣5*櫱_sW ?oŴWm 6u!o\MXF;˱ҶC 0ؿDS7XM]>Lz9H>ܲ2f]c9DwTnN)St<¡͢JFMzf=>@M܈בP-4 Kx/C\qĝ7\՛V$*lRϕB\N(D]Su{N+ndK;[ip&xWyn5^O4j4ι.cycĂf }okAv )'TuWXLJY @$K t dlȮPoS6`7W@дfݴ%B#am1s*O*̸q،M1F3N"8&4kvZv<>eFL;V񈹟[^ͷwrƕDKekQ\;''_UwTdb I)gid4 9n5Tx-]d<{Y񥞂t,dR>\5<^rkضpF\$Ё0.Fx@wܤ{&y}vN('k?۲Ayoak'CP(@ֹ̼h>5!27hB SJ!Vd7s[JG)!?tcy3lpLaUn?Y0X,!J# q{D) Dûw] 5n-|vLڻ挡.}K9Odnp2vYI2z2LCFkT\lq6`i5C0[g Zf;ϞdH 6Rj,Wv,9m><^2K.wP/J(@;_.ҦQO$Ek ȅ((Y{E.4+oSD$>6A f4OLݍUt eSWZ$7lC^pbPy\BWmŐ- O\1{9-+h[֕dkuϦ+l 0u2 r{^TQݿ*I,Ȩj ?М{@쭏),|MDXhݹ)5 y9Y@":eRߪ9rm9;ƿ|qmyDyNޣLGS/U+)c0.8f=ț N©TkvmxUe< oIN)Knε/[@#^2lkXNjIoO>E&٧%-:xF$m:"Q{]YGwYk lࡡZ2LG=X~}|U$U</aK \3w4sx'[FTg2 bInMPh9IanT0KJ" &_OU#=Tq'V aN5pPβʋW/qvv+]amX{I! ~B>N\Wn`h?I\j(ɧtL~3P./$Y)Z8|gH4!LJȬ]~K-M?pL| z CoF!5)Lms_nke_i *4oQUFZS4 I[60mڃ%o2"@ Ω =|Y!gu1D2W~T$9-baESm0Z.f#Likq(ڸ8DSnA a"!hA\@qYdd$'1/)D<-L[&_AZ/oT16qVe4 =(dտM[96]+amҸ ۫DXwyT &x)?xGDt#=r_Oߺ8ex9;МΜ@aV^Kn 7&[솵zni@?3+v[)W(861:]Ǝ'Ώ߬{-;ZG!.70sW{ yZ :ʕ1:~k.rK/)s9S]DпIW8h71fuwq ŵ#}XtSC #⭷W bLO0Zp4 0nBG!ʙSM5jV/[܊a,)c!X>7Kw,V[ޙQ9j` St,pX+XHi76K~B Cs)LkLuIr\]G!3kACϧXPc}(,66C(S9S`BU39]~ti.1fy(սӵLt 1!NbdG?(?P0bUO83ϫ*(SIx_-Wp,aa=)'v=plgNؾ,\PFe !Q)H񐭵đtNqxQl8-M @:F貂Y3$s<bo{i$i̐V{27e<w#LņP/CI#pP$Ci7@`]AD Mr>S\;.[aŧ*u>S6X{A:AHoaݮ@BO7ՏEF؆)+i.jők)ZTuWYla6dEVo>5PVlu(D:u mM%OX%fRU8ɻ_s|O5"8*ލd`HDhU5SG}¶ Z pӃ\uCH&GV2h45!lBT3؎ 8heaﴪd^RƝICq3\w7G43pj ǯςZSy1n\;ܺtZe$U+BPv.5M <eNBM\gF_c/i i e|xy}L=ȦIlwCZY$ ;_&rсc %on WYXPް> z7-Og+NZ>bJO2=d/|p "Ysz*Y7PD~>[b WLe^M(b rDYK Ǔ?5[V̋U5~yu0- :yZ:˅hCp{Vv7$N=-lIMGf/)#qg6w$YRL*$&9 -#N[evN|uN=Zu@1ژr^*ZBd}AU7O<@4XYs0+3k&~У,K[|܄%&Ynb^RHT!*yGNk;^(dڥ$yV%nh5ҵ\83?u#Kt7ZM&ІcTU3/ŝgbVrJ%0[eErh/{N QԀBE,UbT*>,n8a=J?78BeHCek!v[:B$Q脋z$z2ch:~g QԹS՛V+0&"6"cnNG*)SP9:Id$nɁ;*i8<0Ժ-MzP}-o;̦..'J{^-N>qv}) V H*Jޯ= ~D(#6[3Pljȸ^)ip/li:xʋw丟#Z$&Qkf0r2ch4* +G5|{9G!ɉCΎ`[؆ZqE+te%j$G0kr)K;}0vS C&ΟRer~$'Dp*sg}︑Grf{1K> h;)M^nBGMݥ*|@OY:;f +8g߮`Ts5?S^lh@E7 [܄EZ~J`Ђ¾gOx}߲.xm. Za~ShG[˦'!O]4EDKS$s, ݤP@0A,ՂזWH,ce:~zx|n4D|'AIt- uqKyp_pu^gf)lQ<Q@]؂b.G޲4"1_W5˳hT\)g-VZ&c*lHA·=XdJ@\ߪ Dv:q Û#?7 al15S2)h͠(.]ۭS53H+CG}cF9cvhg'C45jW`U~^A\3׿M܁aY)lp} Sv(L\ee>A-rqָdX&%Sˀ[= ^ u-3%q6Va/?BV I$іTA4V-VXX R?}`ZU+0OF| z킣sb`Gl4az^]xk'c{=xa SɚkQ 0SڂդGp7_8)cpjRlj(OкHM2\/Pٱ5+rdw2q6Ϡr W^\P8l[1RՍJB#drd9"ƠYJ5ă]7`b\ÙRc8lq82&553Fs ?xl ԍS_^k@6KYq&,9 E(!y*ّzP3~nrժ7_(`;*#Y9dP)eǥԟYfv,[%q}_P !+mF4]d=Q@KW'(䊍'j:`mo Xl0=(P4Ԡ1(vgZr<,%ŹFڒN7 cIl8Xs.nM|Hba>4G3bw10R|?_zqêR_$ sj-M\{զrLxyhuDaKxXBzZڲ:Ss~Zu%rmVgywז>St$>qa{Ev OcZ븓WGFm;aڹvML!$LoFR<9Cߓ>#hM־]-TN &'IF ,#%N9_$*q [nwJ+~W2']8.\fb<Z}DUN@ߐ: #-Mw?k*4 ;KPFɡU%|}c Ip;6ide(Z-ؙg~n/c$7ц5uc+`Q+0^o69q:Bӫ)*4033InpV~ cWyc^aّyY2=$fCҴKN(Q[p?V{}Q\~.H%F|<abϠ`gdt:^Q:8'U`(&,)w,w@)Z>l$HFq,^Nn"Y~UYu>NCkDw.,r qo}nef4RkvB٠p`qhYAjbdtGj *!SV; ]Ɏ?HP] # udEt\Y -N^ܽ-هf@K@9Ԕ^j&,P2.3iduYz椼}/ܝIvܲw,?~*3?0D'>ؚ ,mb` i^Kq& $R;7Lް'a{,TPe.) e&/fɱwB\߂ܼb.%<@N%]{:0^w q=W'z鿮1n۟\9%f_m)TH|qn(tz_sU+pQ Y:﵂4gq4NxGı4&8ң&$Ui|eÝ#;ϋhM-1WaQ޳p !HI&M 4PΤ>p,BJZ8Ka'v Yب: {.zpE0'.U |ڼlj|_GB1ae򻆐%wu!]x]t+/`؝JgU̦`Hd6oKB,q8nBݜ=gKT\3f.\9j{wGf{6%t?!.#8/+qA¹!+AF_&Ub;$H 2U00#KnXFg1LOY?iٙRЍ!`f V "@"þbfLn釐k2=l(TngIH!#dvNx :KP%Vڳ^ <:NN"픑" hy¢yDU {Ogs.CPڛ?tSb֞iΫsZe-X$b nf?hkXk*뀇nʓn AژͥTB p "@=rŧMvػ=Xm'O*ߡI/mv>(ouGH'eG{{rL6(L번Y 'çbTQpJi~{IQ-hFNϧdB y[R0=}eso)dӵ;IeVOnrYM7]RK_-$bN2&z6vsHŎ]:~Ak I ]>)L e[dCVہS3VL't u8eK86 hdu*51'G=gQ.ze,HhRTNX5o,6MNo6mZla89lI a!df!OV`?Qѫ_t.8ٙgG>9xw)>+eCv?IH:`=: 6廙rqi,n-!)vQ`:xrXV+kwG>I捫oM 64|^=1 v*keREPi0;6%wH7 'eP,zSAi@\(O Ȝ$aHźV"^ceE h&[o\{5;9#tXs!4dc6t#67~KQLQA.}n=# iB5Μf =MHL$HH{k\HtqU1~^*}8x8\q,jjd효Z<;s9i#;̋_5$?T)m554G=g ~]c#!aid~ (q`$exofW|r\7 0;rssp'Y7=d$`D?)?adXC q['r!9ٳDmW!IԊ,[^P)CȯRx ^EʰSMYʵ;1_hz^(a.G,aDfs4h6&"|aگY1;%$1nw?97h+Si$z\<`_w(Ҕ#q ֎5q\>_=˧LWÀ6͖ӧ(Zn=XkTekFiЊRM 1N5mؽj"m6Wی91_|t#.k5 Uv˧=E$`DcZ7Y*̐ԌvTޯi M(-җw7 Q?r4͙ 1Mkeye"' +6ٌB;P?i[;ܞMh18zN`xSmWbNwPdCvCMCYzc+v-ʚ%At޳ [嗚u%bWM̹{B\/yxJpl˲CSYf<;_7IE nl |9q2F[isk]r]kcor)ÖK?v$,zs΢lcBu}nvh}ݡE#(`cѪ/X0AuL|0"njM&zpFUԖH\R'#nP#Js`B=rIMH7sq(HNkŠ0Θfhw5j@4+pZ#r⳨ 5I8VB@FNN p/'F()#E#+ 5uR}δCh1WOSvE萊Cu.yZ^:Jl'?`xRi=9EOYy&6]鯓nצ6rP|T~HF-g}mQWf2L%Gz oԟzYNyZ>i,g^n 5a`c9|cFjDŽKM0U;ԻbT2^X5Y йO\Ը[>O`I` }lXF/r\ܼ󌌢58`mB'0+а!jewN<q#wZ,뤣1\X,"Lg ܳqY͆rXCoKjiFܟcI^E˞uygrS(R?>Y[W@0ʹP޾8ԋyG2Uo'i!:\e{ '1ׅJ炾0sQ8dA:_+J+)=@٧Jk=(k ~BMFYY~L}.i@_]t^AގBwN_'vk-h˕&S-g'*0] ♿o M?6kB$ IٛZ_r@?_@/Ȫ5iQA*^c▄\Kb]a6}Yv^H(>pCf+W= 5m5wM .UBk< ?k] چnCO9bw| 4'}{1ir8vL?b28=%ϓ#eH9o0ݳeƇ'B̧glsdIT_=,kf K* *~ő~uEPGvA ˋ_EDzdp'NVV n\~\v @< 5/"AZsռoamU.b8I@0nfzFNA_l~i'O:/4qZQUw:=ipq*">"Lg s6?5p@!"I衲aIj!㗛GT!ct18-1Aҁ|4'ژE* R/ @]>\B̴[fNO o{\,ezXq@LfAcokb/mC%(|"i >&VlF}b3Z7%㫔+yn_G>3Zc7 ̸6Qڂi:h 1`FH'JJ7j$̠.hAeESW!*wOuIJOP`Ikw}| i\)Qt0y ^ c8b6X6̾q]X͋+m˩-+7 u/9w\LRӟ6Ұ.}y7CTkO;vt43 0-Is,T4_B";m/ JxX|CB5ÌD:Iy$}6$\gX>j-WW,z{hѭ7N")13|K`$a3Ĺ 'Ƶ=Ln-,0Ҡk֎O8| ƙF-+ۋz],m$!/X!̐[/}!0s<'A 뿋l4 -a&-~epcO;qeqŎ]!wl@`xig:#g֞TIBY]ɡ4|izNwT&pVu~!ڸV[˻˻>\R\5(96kh$xEuc)]@o4>4Q R־W|hґ>RjQ&[t(JB Z#<&pmd{NoVꀽvm%n={$!ij2S7FZGv(bljXMxCiju8Nh0{ j+ N]>oܘd+2*-3B-ƺxE@7CC݅m1ec`S |gxY'#cR;pmcZ]tQʑtJ7 LG"{>@#=0VlD3*dJVt\V$[!G.>j \KnO*~ Gd'1nZVrZg,''LsN2+9XIK6}LDbw-=_>ձG„v5<^(eh`DeBdG39fǔsJ ,0@sI8G3SCFt ͘erx%: / ] E!8K#`켃~PNTm2|Y9 5vxHG-v0rX,{X0pYVw>@GYDzn*!7@9XzoG Kn"҆<%ɭG% + D WNyEêẕĦ7Jɹ br +oET}pe,'%O[`]i R;)/ $4]wYͯ \ AOZΗ*cuͣ!9o |ɷLMKxײqW @fOFmޚ + 7 Mňھu踋4+>qtכ%ƐJT OmȒ`eTPK 43ʚqϯYՖTtNvQ,/af``[C%av o &՜{|_q.du.(g5آW$\z2jG 6jcvL#U.񧼚Ĭz`4*攗~>P ZsMՖЀX] 5J$} K U3 ;@(K 7)y&Y*! t a mG1/FH]ƫ'ʮEc_FZ2"|&pwn װjggʨab>4K\=˗pjɕg} 5 A"菷L'ó!ؑoV<,>Tu<}OXCu5Ti̺iDgCx ,+[T=a[iܙ RiBa2nJMjC"V(["'SA22T{Է}!?jփ'8Q ]g\nxi ^2nޝGLXx?KT#cRSDcM,1v{0xQv$ azW>9GKD~d\52vkg >kwo_3JU uѩ 0;=0+,l?ZTk=OK|psmo I) 6rXV V.;Cώ^_uߋhOj\T?싳%=T$iAo+gwv'bvon~sHe9o:@/<#0i/eAZ[@U AgBqVs_VNZY/w,O!W!ОLWj~xWALKћvj*ͷM+༦\,-b¯Dnr>vc#^b^eg]JY*` x`kV"PNI)B{<ɓl t!dP.9w>fx`^YurGP151G*c #%#YAr|x(-XUM"Cź7Ve#y7󸅄.xHa&}MoS熇KM7\Ď[ Hw/yQ_Pno/Zz^R?xYw`37q[guǸ rw(~0~ Uؔw⮸Q1ߪ[Z IU8id@7~wkA &5­VFJ{r}`D"Н@윝77YUMZd0lvA(RθGQ 5b]J.H!vP'eSxi撳 w=fsYrA"qu3ؗςvZ4(5JRn;VDAޏݮIQ<_pЂ6QypÙf9VYQ&"G.!ޟSXX}=p';XT7hZ)@u+sYp=)W݇?Ĝu(!R4c7r@D &IuO #ȽGG8}ln[_8 *uڹ=CP5o(w5ru^H.縹g;t Rg_ ( C)E-K uHh@Ȋ0-+1+#ؠp<hV ]ԚAI4kx{:%*N{+QiAZh9zWk@B_!!cw(c Pކ_ Y V#"? g\IAX*sQϏQB53+59o*&up7\f \؝-#8>?(Xg7:ksۇB㰂mn.H)󼴬` pvիt.;cS~D6QCFw;w+ 4=۸#GCz? wU'"C07ӔɩqjC9jxyƃArie$a m&r?S 4|v/Kr\0Y䖠(!| xxWpOm,ĈB,xG@XS'0~1XBOQX)4cCRck!XθWgG9v>oAy` ;偛oao.@Ndò'ʠyMVt kw$L^ { 2qJgڜ lEi _]U>W`å}ڬSÌt!Xzb;^V( % A}2zZM 3a3,&_R<˗S -*8ﳃǬF ?SjpM ph׾۔4B/Bx gt&\n1ܙt9@Tv~q꽂Vp"gY>`' w {DzҧSiiASzZvoRǗ%Wdd\ *31i8,%Gp.4^J$9k-adrHlmٖ)u5DY4 >qsg{sd1?;V v]4Ka0GTg8Or!/?jpcR.cwar[N\J\p?dS<NZaYmu%Jnpa֡U;@et]$5#H3[Շnkcx>~-1% s}^F`}*L% nʵ/;2V&90q.;{ɟNy܆l)af&nGDtJF.R -S Ƿw95H :\`ݞaMƞ)SpŁWJJ$ {Q1;@xA8ұY9gt &tV&Lydڵ_얐~e.(E@@+S9,C0 5w6HeY$RX-fڦ2),]S(GM;Kt=6deϟlf잿>XKf5]ЊloxŃ>9j^^s8[.Ņ=aٶxi#կ]v ,\Κݷ{=**Q1.bOK¼X/swr/.yrz%G LL':vDžYQSWu{[۳R9"MTހt^T6N^7Y]2ny}ƪt-jy5dem= ~\/J i Tjg@i_:Bx2"<]?z5Uh4ц0P$Q+yb(lAam~[8&0~Oi;r/ǁ@P,wԼᩈZK"xX7 K5WQ?p/^NC1^ ?Qd;4MyN>cYt{E^fo=W'a iٙ4 rƼk-뚑xE(Ƭ!׳{W?E.i"| nP߂ȸp✐x"uκ;:x{^[qed,GFS(DGPSԚ1xe!h( ,sDOb:ֆbYDؐ0u0^K;Q$FLUJ+ZWLz2XBLpoV|40 6Wؑ}ͮS`.(@{sl~]A7_K\hWNXSviWPMMkPޯ 5zxH- SGS<>ݟ)Yujm:~e*б SD'ݣȏ=AŁbr2&˔K]b\oN͎V>5+ b1f XH,IpA@JWR<b4o𾰎FpKQ H*+79ƭF=,-0 @Ä1 ǤMZ"j{ P;B 𦃒H:CZD#۹_ C3(~M:;m큙+VZ쉱< ̝atsFH/f=_J}2(9ܘBF&r9-T YG6MDށ2q]F $G^66e> ;,7LqA7"_OA 3ĸn4:$<|]3c+C>ZXV5.֥f^/\mW8&e?R3F<0p=F3+غDctaxbf~l=H (Ҭf3F%Ux~Mv ߐ!^R4S}MYBOmhwyG/"J^@$;b xTi!cэK앙ӳ%₃A?gZuLܣٓ5ʐ!~cGa6.9@i~vѧnvKbv ͝\>N!y.45`\}{{2 |wtdUFBOȊ #n%urCuFQpPsA/wv64K(l #_uC(Ԫr ~bez$ܞΛ8m$6wߏib}4xuT6-E:ïjd_%lr@sxj фv om| S6?mcCݐ`"ޡ8Z-@6?j0ᚂ1!yK\ eX ]/wqa(ܽ*+=\|ESGRU\ #I[Nò)"Ga瓍P]{DjQh׭wetrRh̡,8Ptᦃ7Ch{=A-(+zѿHϮtz |GyX_uT犎8@'v#6 j Hk(VIتӭʨK;@brW`ry-N`͍}CKx@adIyeLr(0E J4vAJDbf#c4Ҹ rȎo 8Pȓ0%ﱋ|ZszefK?3П F)BB),Z4gj=qja7E٪hzjT9&|pnYmz%}2HCWFys61%/ti \`6*$y6Aj\GP8M݌͒4g{0ҹ* ^,cd jZ'Ԇ`59z`I&RɁayr`Ub$@y|~0l9&\$~I !Sվ@T݂݀ჩ15E1[ijojyL0䲦M5,cANERv/c2`!Ԭy ݡ :&F c`QcJ6޴WaLl50/`> h@}FMZ?rm+Zdo034Z v́ ,S2]jD"!Jaa7)Vs4Jr.^4f?xKc{2m[<]&- Pdaޢ'u`DUڬISʠnAn_đ&>Q; ;E *y@K&RCt2U7o sR bB>56RF`,P?q~[lEy2'De1[gM7JZ{ⶌqOWK?Yެ~<3,ӣ'п9&#ksR!19Li]Tb@/ých6JiSwף+sG*jzԫ/+q`6Qnt5YNSOv8,Pv3o^/`#|6á2,ds yYeyM;2q o<+G"d7`j4FAw. Ƹr|JdF </y\6k N@ؕ|%t?YASTX)u3( \Map0 %E-s?m.`{*٣:-8<ȁ:QXcl$nv=:nd:X1uFV %2N+7aInԩ5/ INENŔĝ⁊Eu }Vkɾ3:l O=Dgkd=stB}mnE2&,s--գI#kyK!&aܽ@7]Q3!~j51eR婃h LARFЧSA\k=iיP艉HȍtʛBL[Nw@+N`y Y_eCDŽPPXL^taBʀM2e63,Շv.Dki88$+W'DL1C؇Kl@s4Ksy$0Ut6qɇ6T(8Zo`u{1z'LX"iԝ=zG}Ag.P2̽㤉RT٥/e$7|[un`D?0-㻶2I2LYgc>xgd85|l>ﵮ0‚ bA3K ƢР mі< _.I[M6=Q1&>9TjAO!M>DR*BnACJVdXZ:9O@,Gd)>LpCYG{EPX!]H;рx|h%"f AI9u7w_Aur|~d󍤰^~{ aJ\+ TO̼!{+k/%ZgpS9ظˋ` }a+~0oۮDmJݜPӏR$e/_Îp׼E`e9 exe% yO.e&wa:n-< SsO^++a"5tsq/K$RXOy.Bʗ7c҉-V»8ՒyJ2~m-eWθ wȜuewPvU\)&FnhjjˇO7}{r o_/R?? iDyCYbZT UUn|_2< XHWL>bbvVͦ4{>?vrs] \f j93rap+dXw(H8ʇNKAc h\eEh{Bu0DH B'gH:U|( YM$@8 Ղ9&庩 þW!$,`FYϙ}^[AF,bQeO)bESx`\cB"x>(by3V~Nmh[!R A1_e܀wC]6+ht35߹T=G| k@O S[CB_s)| Z]nl._}iNXB!tKy+$؎Ե=%c:d ]Woy?oM#y 2H^l .sIbQM`&,<{;;Y'x;t͚ZA27];Upm2kXI&D/@?C)OR&A=ܯN*9/E)alHq+$祾=qp&ک 4^>7lKI/gb6aڝCՍbhyb鈡hILg m0nue$Jɑ Uºlk,mE-RresXjF(bz͓czؙ!+'t)Gj؜5aVM 稸;ڄNjm38RW \Xo8 6BB StwxxՋkJG( xudrO>e6AByc#]?tž@>L"}'3jq:W!ˊoA-*+&x lnv@; )+Ein@7&SbHo^vBն: VFAH,.;\!ҥZID uWMM[rC n|kDw#ԿRUcKpDfH]`` `|lvIPZ{ KQٚܜ/Z&c0v`4qtkr^zT TNkü J=G!iq"Dժʒ]M;[MVCv,V(O2LKӨ%kc$믝$_΍d<L %ZTV!p`tte*sJN0RG0,ԗd<}S&n9qj.8~~}|gQ?uK:bZd&֪"p|y1ae 3\/ ~ԛi\]'$oQFulmM-*:h8]ͰR{Q VN(^^ъ yc<.]7 wDn 1om ް=~U*b=nƀKo܏ĵP2_p#R5-)Dķ!ţlBY+Lwdܘ_2ICm%5-G V8E# ]ֹ~\'jTG0->SZ? \-tE&Ew#"ЛVh^Շ1!B̏zWvִ 5Y,[ 7ʕЊMK-XoaArZoC3UbTaMWh2X<6N#dcPғ;fiOpc߹=x Uן6 LE9A8u\]9Eu\إA2/gc@&Qi:(qS™yN @|1%#J:lT7UʗFiìvR!W ,576Z&DKmw2c^d9ϭςPMLc6D9]FAE\PZʦ6ۑW|$rjE}!G5rHX\oxua놃^u ftAHuB7bSXTfi>UDʪy<E碫xorn'c ZK#L2' w1Ij"ƀ6!iWCAI[s6QFڍ.LD-iaQ ė ܐ[؅LSMB9 \$xjR̴_Lg*+A- SBz߻qW=d Kq3zD"sYC4̓m:w9Qp:ʻs'R9vZA";,V/6}ǚ|X5[N^W2sP6iY/D8 Gmr3GZCKR|]oD'L,ilqQE׋et&'Jq^؊f/(Ĩ1хb82FCMVkaLSpqYz)rx0J8nW׷ O̗4h>\F9u/ʛ$Hō'1o6]"%&|]w3JcgІt) bXp;`eP 2t043|KBT6yaϴ.7]]3? XăRl-p'r[&Z\\$C{W\Zە}@ Z騿w"f@F@L 5,Oّl2^\jw[r*69"ҥ'8I !x 7BijfA3F8zghV+*\YH:UlQ!+P¯ΒGf ԟ8L%9;>BVІ˂ /KݻUa>-𫛺Ք8*=/nSE(+=n#~uuT_6R-ό}!٫'*=Dc*:8|h1=ID3 Ux%6[qHg9U#0~_ ީ4ɒl+g .WSq!G F~` M0t{t1[f1_} mǬz3gI&INOxfO'١N\ *&qE-aYN$6!kA\pA9 E- F䚂a|Pozoש=<ɧ~/hl')3KrƏb@dD5 C7r"x\TN"gxh ͩgA)~IdRnw?6IrW L[v1Q,zpc#;z0)#zorR*-D@| )m^SF)^335udO3_!"8xL}d ԸrStj!0㽺('yZL *S /x؋d#;u$ey|]VY6?1}a_y7$ϾzmmVqf1U6-- J_wF븃!}<"B3ߣܘ:1JUDjB㺟/!6 m;ևWs{&́J:.ȩM&nX ;ȶYbX 5r[">K0( `G#XNw>{"OtT)D$ G,ͦVb-|x*||I`1I R 젨3#p7|8`(#%1Leh YJ53|Й֋[Rg0[pi֏vH5MtRv2,k1Hd1%) 8ٝX.I*w>H0dwO:~ӻm~MJUdh|~bĐgčo校/⨺&?. .zw"A (o~A: nlqsR3KDS}R? ]w@3 R2:Tdz~(&z ҀgT<;Q+W{.➽(=Fw/5Җ+]UdjKnֆ@yt1'FX1Zkp `rWG@yg*vQSN( $ o-L?~ҥۊB9%¥"}!O/bNdnW"ρ$o>-k L[ bߡ(.nHzd":ų Ga5xFe0<6Uv=jWTI ml E)sxGP̂4uNhXDxdQ$K(*H}3kmLF25e xFVhKē33rܘ`ngQ^'hJܶQu`4 PE! O X9`]Z@RZߓd"FJlN*VѰV vc# +* mSS}aQrJ^fp /t⍫4-Q8r?8_??.Cl=j[5GYM>լ(#P3ug@KؐwbQ; D% tnL4Kt߳]M蚷h41fd)1QI ? ij缢/S*(ȌPV]{^9wxn>4D ?&.V/cxX??NـIwis/q8)n}4af:2<"'rUaQ Mwr@WLh>1?mz5 Ewtźޝ nJ<6.0 Y\Dԫ[?* Ž= w5r2VY;:OQDԏ/Tb.%)? -U\BSY规61?(GI}w>` Vc[K s1?Gz?TC 3Vf(.lU?/NJhj܍ .yNޓ-Xܵ4 ۑ^xlf#e8 zyR MGƒ ۞KϡSC:w4^P$p(AɱR+#[V-pWxm?j/{kq'mp)-HY<~>(\>FBl59#o┍3fHdOUKI%ՑxTa)-sm֣0&tS$r3cZj收Uw \CLcABwWb'.ʾj174PbZ9HMk,m}`lFܰhtj*ZDN1gFn<^7 h/ŝ>ɪg\3Z_#{|}BWDeT(g[/4vsώMiSDjJOj \:jIT~"&?Vs]l}jAiSRY4. S6ݴ}dg;=Ԓg7*V뇱Z ު9 }|yL<v#+G!Vܳ+5yc*>HXkf|1=Y| 9oHCb+H%/ ăq|dTB*1wʋU~>>r J?hR&k BP2(.sSB#:`>=WeU`$P\@ybПkY1E ` yIE8r$Y0ԭRR-#=6$j]\$Ы (KO-WI NdUb jYe7ˮHf__L|43D +tH!t1$:7m8zFwΏ4 ΃=R^ABW t=n-"\Ty@<8o`í Fkݨt|_m:и;mLـ  5 (!_W,!Ԝ@v%yolnHx2D+>2͈aĖ3kT6DyG: ZGT^˩dA3dR,ԓoa=ۿSq2w Y~ "6E}Sߘr/|-Tsy*g4dVa[G4JuЃ hٱN֎׎DzhӸM8|X 7Лx3hgEǻ߄L ~n Řm6%0LOA.F3b {:b2QM w٩'`4:s;52p|ACKqoA'UҟL Ѳ }3;\\@q/O@&%Ko{Դ:9PEYiQ8u@.)})+ E&0wΰzWØ RhSs C^H\_AUr "n)B/,i>M=NTEЛ m [P*R7{(0W7إK>zgi|{abšR1+9".qޢj ȳ3uT`IKSڒt{#zՒr?^5Vr<(Is@T|9/ CX3mzmMt/L+_MWLH"nKOؼ!~1\ot>9.NmOr-ʝ6^w#f9٩d?u/ݐ&ha0Ar\$MVB RؗC(k1VKs'~&(aLKeucJGBͼ\@=#kg3c% M%3g׀ #y*E*)E7 ]ܯR_'lr8\rKRuB';dtX˼*:s!:L%v d$e)MX=SN#3_@]櫛6)ɶ 7ޟ~Ak/㴆N圄R|=,R&Z15s7^}^!V"8mHհPSWV=̭ṁ!Tw2?5[$ [yCB~߽{T,]GA|BYMEv~G~Ba;.(iX{x vrH*PxsG-$_oWw8R,SGmP˂  WHUiw(c!dv:ouZ54J3ՑYN UcP't`ؒ TKNChil&=3sű'#ZY)m X;2sf2U;l|Fb%(9G!;'QPwcdbm֒fHzEa@0: z㒺Ip|hwT,Eu%'m"f7t.{HzM6ܥzJd.xO#57aG?¬՚ &c8VOKy&2.e4y޶A4Ba720T\T¿˻i/jL ނS\60RzfPT =. |bl6oVBOv5WnW襫# R#+10W#8飽J((Ϻ~fT݀rƑ-hO{"Ֆ0~,{3r4 ~ ud - E-Uj,Y1YR9wVb4^!SD?g}jcRP̫0L3a"v#@Ը R%ʀcp9gh+Mqu缒nf% Q܇l\vĽ = fMXc]t@Muu)[4e\C٥wpN(όT$C>_IV/U؎l+`; hrJeELvdƎ68*S'ag|j.;]Cdv1L'b(: m ޴-,Y-:ǬyqiNn r.TC], Q!-%BcUsBXD|&WapѦŝЌi<ѦC{XY<8{*GFAQţ'(͈A@41դ7=ya0 ';t,ț Ah,,W /u2zVZh]3Tu{OL[d_cՈ Pi\W-K~_RY{D*3A^>? q%Z2HT]ӕвh3bmB.߲Bα2\aAX4zMzV@e*{B%D ُm]>ФGg8ޕfD~,W2_F$@e7XϬ% ub,>(ZHC}A[B%Z 8{. Ȃ;~IZ3f#۝}&:=I^Z4DՋ;è;EN!J1~b|B8bńm Us4Eo-Lfc.5jET <8ǩL, CQ~,q!I&:z[Sc=kZEiC@[tR*pbX'Ų1X(둧1ª/1!WxLG `酁+wJ%~hphK"YU% !8KAϫU260_iQc܄1qÞ"4Y8h Ȝ-|Cl ,dBP篅'~4$В.P}$-[Q@=࿻eT 6 KWRr5 H ,(P zŧ|K.E F=X-,> rL Kͮ8jt|GP,_+5RUZxYb8 n>uu5˵t1b:n!uk^{}¥ s@ Xu &3#dLP+Қ509GWq}gһ$Ja{۲̱5oGhչf)m@:&+ÁAzCDSIg*ƦnPMR|YB팠m똃$fŧM6{uΤZ [FNsm*P\Fr P [}>㥿Rl=Dstb)rNyW>ߢψ=t-s}fCܡ.,A ,oM"0oyXEb' ATDc@g`j=lLmeӋIfmS))K$, VnXƤ2}{fzQTP_\֏zkԡԅz gm^%p` R>t(O}s- 7ّ㝪/5 T(NҾA`YiT*ܴ1ئ.v1 $*+HK0O1uoϤ;0bk$}ݩq^>~IG9HPd( .PSϗ %@SJ JtQPn@mhAD~蠦gs&֎ T~2I&&VY,qG/#5lK|~?rlV"@zK\=Ӱ3d`8qFX|Hxq]<0ܙqREz3IyTuB9u}i 6\;5eS1:vrc;w *_42С(h:p`IsZr5T@Sνr0(٢؝  !!8~ }vC<}V_\tYoR',?֣í_VQS\xӹ\,~r,uEk).'  o/I."(wBظXb ǔylT,HHJ!hM`:J0]~P3^?~ xݮ;FzfP RuB{)-5>!4M]} SFWuC2RA(s?(Kn;.=*SªX?Wݗ@1lDz}$Xms՗Ds"c3tosLdQr1ca&aaC90j>6{M+1u1"-s f}.O=6SbOؠ[<cѨXag%C˜<NY_w) "9 Jk'غ6&iN}3(.36ߧq Lاv`:Q6]CNЄWڊF=@70&Z g|N+o7ݢ"i+ }G"4e~jnGnBNoKOh⾔S(B=}~+n̪u2Z+sމtpA0f2fgtFXE}җH"t-MnhQ&F5Ďvܨ $|S$%0Mgt"=]5L`7j@W> Kʱp|CIQ[,/4^]wd`~ѥé˟KgԞLQ>vQ/~OY`4"_pRCTZJOaJus (LiuhϸL-8c7)o6I f Sb>ɣFZUAzV)yl!R1:b9~%.ߩ~lŒnҵl?ʖȑ+Tvd"@NSצpxTF]Y $+62MoNV젚Tv;Nc=aԤJ*҄J9oP 5Yɂ[-M1mA^XRwD yL7Ir|h/{9]EctAG Ns,CΔ_"O6K^df'CP9 [r*"oݑ@OƵem7o+1ҪZj5N1wyJfR"R}H{W֌.w`ϥVZ20?4ELX(Fi@>|*(L/o:aDl&\Ja[Vi~/aF l c{hH F] 65.('Ëd>ׇZAaIBL@NvEoɘWޘ:[S?HN :t-"eR*Wq~ˋć|a,Gc%GW7Nre'XT;Eez{s1iؕ6}W0A=yBua͝^J_ܺ;oʧ<¹2Sq") @PPMo.LGJX ^I!ehf;{NjԲb س{O,#Keb:zC3 k+@Ł\h'*՛ER'f7`8';nvaFx:ÀlgMVEh݁#UJ3F|"W2D\+^xVe[ yR ȘDZ4L*&:yX s?AHe$jxuNE I$멧Xi.%MF/5A4/@z_Rfݨv@jqb3Pl)abk26Hɛ8'SXT$/ :wg[fIC=zw)d+9-cl?*YSfƌeq|d N\d ģ܅G1읣a)k!cmU0[0uoLngsEZE%7'5  :KSa#![[ D2kƕLyIb><r@hF^,<Ƶ3Ϝ ]~ $[ώ)9vrwy(n3.2Xhv\+%6dGxC&/Vh3X=?dȡ4cj'\h%S Bލa5)Moĩtyq­>S}&^emXdl$>v%W& ;Jm.vNWp,Gۣ|`8[#7o1ef'K#2~]4zH}3QN J,Jmk5؁p %HXqu-Z5S ːeFx}>-ƌasUnp.V 5Zh\&+.D8Ն>O>k?A4Ҫ/qhѣ`\8nͫ1kSᐓRP,s%xx,,i pf Y1KVsO"Z3H~mv%TsP"w(}19+ y.:lBn' ȷבhU |pAwӴ˷r|Sk, &ENܬۏ4yLvqqAPIT'$cU2q̟{S_4 LDKvYB 34?x vD|_|~yf`mxG|s4U5g׻Mo^ܩ Sw;gXD*an͢nɆ't!}dGnkj-zF]Q,L:E xka* .I<6QDJ"@5okkIfC_f9Ɋ=}݊93(u ,"7%'/ye'ߠGu[N1pH+|w ,yv[\z {gioa=AK~Gx_PZlzTDFӏ¸_Cj~d]eSD {T#vYLe^N5L.N Qn82GI\ڵsɱ䤔̂ͽ$'"QҮ-s]oe#awmJ'|'*獸 ?눺Q4_};n귙/rI܍n|F%#V:id{ 2Is&9SVxсO/^K;ONdQ=STfelEVQBbѣRdor|*w` t` @^x9y' \EG >c‚2+d4_"GA;ehF]/CJ^lj d+"oZFd a AbSaxoU|pIyI VCaT8A]K[ 7,fقp,2Ec*MBǠ WؼlmnySPy3{MYܝ-~|ҙ0ͫ\YK 8dVTT}~pJs~ӐO :a~)Rԉw 6VUl~lWTm,G#}{̴#9IxNr/>ݖQ\Lq1$بFYM>"[͒KAHsBVP з GrpgGͧsۇ6"~T=Y2i`Cs *߸]Ԯz`LRA)w2ß 石r? |;ķ6S#@H=km$3TEe - y׀ (+ڬ.kCa6-QulsSDKP=^|糯6MR:K8xHE# шi$@}ç #oJ ,Ӯ@?rc(:Q*++Laf'.;eyA]Egȡ:Q,dE)nhZ-O\[dtڋwH|縛<6;Ob,ѠRc^IQ_tRlZǾaY+N=i`ف.Q_-',$xdueYv@ĞUii;B)eâ@~{EHқ\d幙bTpm}~ƭ(⑤kLrϹi|jZ z^f3u@+!(KR,8geuq&z U-AG 1m[Y :U!~j]#h'H7gZ5B&/<018Pz<*S?W ֕)Z dŜ$ 4c*`lh .a&vd`@Ȉx^V&ܮ:})|&쿱|RHפMR+ŽSnf,S'C_DZ`9o4Dy-=,4˔K i3:U?_XW '!9C=7eQCdXȩh48me7:&=--R΃YOi'QHy9}ϙ]ijkCQb?jhli\&zM)m8xj*_Jݼr'W7:zePFb~`?[m?R,-v~f~aDTI>]^A#qwu7Uh|xvJ`.l G8Q垏~0EHH|j7FƍhD; N+T-HxqP  {Y&M9+G3G^ߧmGh%o=(鄚TnǶ(ޱ%s]i7mxV湠u$"׍EtvX=d;},Ơj@-U~\=`20/P< RNĂUp Z`]DJjGB{NAz(ꈣmSt9tܨE82s-V[I-1cRL]SL`U-Z)K?sd`kQP|;U/KA%T:-ZDOFl! i.jb_fBݪ|)s @9(PifnkrPt @j/Eo{+~v6uB&djД'EfH Ig}$Ϣ1g cK,2c!__vV~Q޿0~1Bja)XP n /Sa?<,q;KJȢbX^8D)zbNC8xĶh^3vǫ u ĝ+ͺ)RMDRZMnNQYAϗlxA9NDeTR)hVZ>5 ]Gq : mƪ>HbT36!}0K8fۈtp@bBLLl UE 3_* ͺs/d9K:"j mprV*Jh! atiLv$鿽1D^>S"Z{ne7˒OΆ^u/K_w\m"ZKм֟OrE-BsVo|52CSdj<4dX B󙎲~c|ly=%Tj3 ‡4&i,0w D.ߛn 4[-" jď>fܦG\Ra3[JX6V.CE;ķ30cD.\Xb32!]jչ0+oʎ㢶tNhqTC0x6r LANϼ6Ѻ_&βHbb*oAg_W-5ϵZg|ylI+ Or4dǀ݁e_ +{ U.ä3ov]]gGN%4-\osBibCY̭UW'X/R^K! @gcơJƙ^\L=v=4HJU%Yƹh?h);n 4@/dGU摚g|kXK! +ԝ4BOLP~m~?!DkEyj M]쎕t-%S IQ|k 3$n#6SkHKC~ZǐVK+,KZ?ObjUfJ3b͆)՛ԅvSD&hgdXv VUZP? l:MU-'#컲gYgzё>E@&\vWY+gex3byoxE#Hdkge.k5qhxTH<+e% \-͆jCӭˢ %kgfWF3ְtᄩ+`Pcc@tr"^*LC2P59$&ߩ(/w6HiOJ93dc=;no.m1hR|39?8oD1 T1i7d0개T=uE飣Gͥm2p>_NU=OYI-V3n x )9AB^<e?!0xY49 Vd>M]J@]c\>Ѽ%]ģ_j 2>xbiR5WG*^ŝ{ӛ9-Ta%@H#5/Wbd n%[bDIsSX_'Y[M3y.c5Fm%<B 3C;BZ&D\/Y8Ks'u:evpO"<6I 4k }ݎº+d%Aw~ dn ٨:F +DWK>tW<]/ͱuNdxG*q`"\ڀn8LR5"A3 ά$2fycPybs~mmʤIapPU@N %q Z!p{@A~"@ekB RBس @1*2&a3oEqP(?k [R&ʤ b}#ΚcLQ0Փ]! Ð.=oȉ KTF/05,=QTpVx;_2d ̓+$=xAwEzڬϛh%I =M5ĸLbX\ 9㿑$;}hc|f@g~h( Άw7\KN/,g[J6JMK:m0uO?y+ QVǷI""[ ٮ0骎쳃n4E#~Q<lZ}ŏip+\8湜NnjTTUKBA4[9qM77ټtVTeJgJֹt3r-{Ohӷcqߒv]j4^ST<=NYy$˲leUѻ= "EդI$ͷ<˄f37d~ SXLE=;3GURl[M'ޏ^Wwǟ޻+vu(9M]c{ipݩdd2@*t0ԋF3*-j97ökۊ6YG5ۗՏVe?C}r "E5#H^_VtH9ehߔOܧĤ:6X R%SaK7 gD¢r:v^|+H`&s%Ւ!&p%*w HXV[2'Uڌ B,c^/K@n٠Uk[3# e"y^H2P0`r_K򏠑Twvaj:)U]. ܸU8rM_['W ?8w?7^l4C=0I<Θ5i\L%Yӭ9+Nfg bIp*Mi>hK1>mu5q9'clےu?f#xG"5UI0=6@զBdZ1U/8~Rpz{'ƩO ~ EnպMeFanK-ǽ<2\SH46DdbM~.|L3ܷbJu)\bpz o?C! ޼x%6Peף(qcEz鑑vYj (:\Fw@k9ThhZf 6@<fńbcv i^Ò 索cn!aciQ~C̐?+ q 2#\-J0I7#4C*2o*ɦp "Kf {Vq"4q?v][ :aìjH_ly; tmq=.7nG 'y*״q0\5I>;!qH.oݺ9R4*\#[N[ N^:I4qGLG!RgB+J &)K>):O-\Lr,ڨ`=;0E+N@]? VRk!׈ -ٴ`KCFDM1r.%IH*֢ucم:='tqKQN:j73RT$8;T%0;,#e%4ϼ6tDTipWQ& Dlkt/Ru=z ;cOòdfV^tOf/N{0p01ƱLK W#Іo$Fy'6ܞo#8(k@P+arB)t+i"*_Đ& XhDIm!Pi'Qs BdJXN3h|%$M R`}4m|@iH[*ٟ9}fw N6I b.\(YG 5>tί jyaT?!9yAw4*A4!]E #!nmLгMv2t6oSC[ eU78hWQdif"M YǵkkIRS7A#oǁֆs2ah?!h/ S"iյmp{cPׄ\81BE@V;d?}i,ջۼD3z]`xD)Ef35)T^>֊'S Y(=OJiM*FN)_婿 '$HCO G&f̤CbyijU$ <8x2 /ENR]ZxK%*BŦwRC@y՛!ňIWZak!(ps]X% RkA[?T,{Mslz &!Y[b]M4B,xL*@>{ #7W'k/ C 5o &yݱo)Tz?2\mYʙ'':J%kh g8ơP&V4x5|bv)Wێ|1]Q2K?<ߴCx$:VzoIܭRcC[f⦍7敭qEo_5ݜVȑq[f咬;;Fix5 3;jԆ3%u?.PC?%;pc1nǢŻ}l ܚpOr@x7{˾L|HYZݵ/|{Y_w*sr[Kt~lA{[X_ۓ^QƤE.wgCA>'/ċݡv( Hǭp mb|E'sSeosxg! S2GgV$Ua Se-f/FTl ӛ](C;S;h3(kwX+{ l4 vUh%~ :vI*7WL,Qf;8pѰ"0CNXP1%<47R@]j9'3jx$5>>;'/}nBm+$e]ƒv]|n(@H`!S#v}_84yJJuf%cjZ2\8bjk\kB+)ڋ>;4Po`?0 ù}Zr/ ؆A̷\3;FP`;j*?]vɘI.lMY´o( E& a*lLls?;w}i؜V976-Bۚ\x3獬1U#=T|Y fڤ@rtRc[ ؄Egu"DE;mWN̥glhF+\P v~+& Ȣ9PWxhW?1`.#KJYW`{ k)MW⓮/ ѝHZ.o$o_,ll-us^$ iĘ˴W&\ؖQeP?zsk˔&5]E$iPddTd6.NZ+AU78 f?>~1tA*N5OHVgiIqT0MZ͝e f2e|~: x2 `\rw  v !":($;ML,u%nkuF!AJm}CƔmw {K;%b\ :P [|%jr> !+C9Q bs,dݖ3:_&q_G!yF(z'u}{f[ج #(GEj7C tG<[Y$..L*f!BbKIpަb9{!*j*?kb+vAL?“ܚT~F; -s} QusDZ>hc49A{wcFp'p`2R(hvC&rl\t85jaGu]]$ՇU\:#w:ͥYTZ 9rhkJA:_k 0J{n؁ptP౉Iå^*vnvrxO<  edgQc|?W:ڿ-$۔G^5\4D娾b^ssݏo(*VZo p!?Myy8OGM3W :-S8s1 pdz]xN~2ims>~*LH]8ߜi闠CsUx`3F#b;0g]aac8u4 ^TN+̟mk`SA:ld5KϺTVB!"Lg@HR>4ز%Tמcznh?"gOyϭRΉct@&)V7DEEPU'{N:uݩ:.!shi'x~:M.lB; -SCT) Sr#$}/k'&Ѳy,=;|nѸmMev (զnޤ>պޢuE܃_ RK\>jľ?Ώ^]e=wҬK ,ydQ0_0  Pj@8kdNk-efd3kTis eEWh[Wke8!֜(#|13)gT)fNn:ΘFaC y̦4v!z2ED0R~C;w  n,oQ5Wf8AĕWL5w-Qջ O@K)IA<1ო)vRg)0Ve]"G#!<bTbꀜjO::Uȋʑ ۜ7`Ph]#AL8b'ʼ,@N4xdFp0E xLHR,sǩKUVѱ-wĈY1qyfw=L.Bb36_tg?^H=q[Uބc%0 '%:ZU` XQQXQS%;1;b=7c)$/9LV)]bti!g}5s#Zy@0<,aS s]3j5#eآ c35pMpNã)W((zeA0D 3oIw$sn߳vb6RD%^jTOvѽ uyV: ֹv_SmTͅ'F^/B'C {Lo>ip2=ŞM}ᄄ]A]%0 d}kF;D?KFdS5=:VY6M"]<IЫ< }Ht{5pX$uc?Tө[,}7Xvr u,<7VmIu,_j?iLW"o<;-L-I%eQ2Y0Sf}qAj/ƼADtwSaq rk >w^3QZB#~;PiS|(qS\uu8"XQۖRD,|HJ!@.XfZ2ң#S#䄘2h2wqeZ@9CpRtc<pJAt"ٍR X# 506) B*V!l73B(X%O3HAD<Ϻˠ2%H%p p}% ,]p[f*,Kq9bO'@A;jLhlf.> MS0Osk10z*.Ph3Np5 5l `1.i|77A n"#pH Fy,c E Apn\7V{PiKt3jrd΋ь4. gD繵U%KItwԆk9}ǧ&s/C0oz[kB9 ݆s3D=PBljR%sTt] yE-d\*zf&Me5"Lghz2s9I=i.K-՘ MoGgPJZdBGVam;w=v茈[& hB-7c$6i/ƹK*&[aϻul\t3 H:,&0±A׻Az$.rR c Z2HoMB~Yh?j]ΑԢohtE._u 2AaKC.]a8e`Q3IIXfesfniEl@]*+ Sߞ:i2}2 o6%`bՄBeP%]n%f<9> ?i:1asL7w`?ER, !eY Us -jغSEFʪBXIӖ5HBq&PFt`Ӏ:D <(OmX+Pqi}(LRpI{w&qѸ4S|w4P-AKA YLyy /A*^i3:ObAY}F*H63_}X_;9 ^SZ"wnFjk%+,?+d dEDz|\zb4$2FzD9qWp1A9( 8g`MOQ>/TUJcs5w fȯ4c‹7d8axLh:ʲCzMxʏޱ #Wt==ic#֍j {\CҮ3 v ^aڏ=fP~Av#VH=bq!pR+*4& sk{B0f~iO9 -^gUkVphRzFAe (`G9Py00E^au 0Ÿ) [4a-k;(=\|z9#?U"76F݋e/6۩٭!*V .Ӳ=8ӫ93џYͺr +:[4Ƚ+[G#˲4g=]Zu{Kl@L }O9uz:Pk U6'hG%q5w*3,I<iZ%WT0s2HxK 9RcְESY{2w'btu:CE&K{`=~|f{b7saof57fX;#u>ۤn7{S->缧?>VP6oqAgmpQV,#mLOM`}bݨ;&iiU_;@V3k+6mRU-哋ڜ,hy:v>aKW1=@QդNٹ1@F}e-ΦݤԘL kc> z ns; >t`L߈[z,,9+ΰP0.A2B>xk+ð`Ս Vqb.n@PE8EQԣywV̳8]䫍9 ʲ+FW;:/%3R^Ya8B6`ht'R˲ &D6G~?}!<̝ˏ-6 "1EDؑ(9Hڻ͇UPXw6s X繛8E唍n̨"g;Z2 5Pb"7eǤp˓1%Kr{Yզh* << Y=/Yyտ-p%gpUf7xVXwD8;{C' N2(ধ󍭼&eo_8(֫c~ujtޯwcl8MNI=FLȿ4(R &bjrt,FHB\z[w`'5{G͓avb)R` <|)pqĈ϶6C~ |UDQD]93J':*/e&s'&^"cTka,G$4o < D@*kA)maeV2;H_aDd*zs"_Y% n9@2/RQ4U2!7IڠTg%e8djEkj"8:qu]3 vӉ(ywX,5O&~U@gS$Cڜ HAǩӔ=A=9N7W>\o1BEܶεv%lGyP3rܓK],^nҽ&-@>tMdͽiX l$O̳km}HߟU/aKkMivtor\TS/5nqntPkTXS ixѮS}^J e. vd5m"?::nt9/:t75}ZhGh:U%DuO-tѹR8]pO# -bCݍT=&0s3g[/}ȆUgFx Aq[$PY<|sڰgAcS#hgO'螕Ǵ Ym:G(q2zFDLvRܼɪ j_j嫥scc)ai):5:kO?gNFlъI+&IE4 w8=,<ߏ8L]I}˺e '?}V=j@d>d. - =r&GnS"i\߿-7( "? |SU&ygw%TWV\ZBʱ{cՈgcymfӳHmOqnvK]ym_k.>A2sNHJL39pQ"^aͺPw( .vnB@";K0Q;ӆcpj{2GI bUtxFi?ĦZŬv՜ߎb&EeQ&oٮcF~@0⿞D3jRł{Y'v%}k` O63mL=OcjbUmw*OdI;m-uViSUCJu^o^:ĽL+|E`P4\w2rn[e 7-\:b"X(R Ff4PB)xU-!]9 pH] /RtZo7ׇ&Ti5\p{Yc`$> &k=J(=Yr<^tp]o՜Lz.O@C%MHӋfr19víf׊_Pf5EڞAQ{!e5v?.qVf, ?cPlsW|kCRLQ{~?W5ѯnZ6~U@O$tp:XKBHEHvzm>ldfQ ;fR4DVɄy/{ˉ9+H_F{+b(kiW!;khƔ{bش#w$(EXNBуO v_ض5()"ixP@ Hٲebp=ي9?X%DFuV_̭VpNJt<^{x}/nWyVe4ݹe*`[$5<86Z}|&CkN6<ܻ#'Ozj6jn]Exz҇nXqZr@ѮG5䓈D^|OpF?.=k,kKGVHL!^Onl49Z¤;(1! gO`@K^H%풪umvL0\' vBEm,Z!;x ]&J͐tUq{HT*τ)-./NOX]'D^MrE2!T6[V 'pVg`p[lˇe ctX*Rq|כ{WEQxYʨ,G8]1SMzdC_U3Xc-^ BjNT=ə>kvZ.MZi6gDdKNJpmMiշKN,YH˔l[= g]3EXm}p XKԒc3^5$Nߝs.U˱d-\KKhI(\mb?c'*rO<`lUSky!lIw --5"?{j4%jȻu.wfaZkdA+[^Q[w8Wk?_ ƭ/s,";.@zI9/腣r͐Njy8{e.GT7Ma MOxڔ/ ȵqf 3rʍBۿX\v2@a4)(j7P|06tA^[E2Ԭ JƄ8FE+N /$۰gٯ@NFҦ9 p=E04A 򦮠whgmnˇ'g>v@U+< `u>pKm%=A!*FMlJKӷ=%R$z+3x,\ڥIGHqFS,'a7&ۅMQOׯ)*o;[ D81Z] Z(NڵC ? e"wQH J#u/oGB&5/?0荓^Ā@1XT[YEk`_AC{Jl2(R׽_9gALK|'rcoĤVn&9q]MEw0٩Zn[Mj_\)i۔ ݬ-UpP gep41z&Ў'[\bH!.)ㄓwok`oĂIi`t8NQ,-&kM~όL zʢ\ =w!Ov#/L**Jqp{lit32v9iǷf33dYLe˰? |ú"6 T.<31r%5=p걦/uu>f8Qv- ,2D/)qTKl@Zz} d-J +s3w0> UJ qf*`s |~;EQ0ۡ݅FHp"BhVze6u$u?UҳW蕝C|gwׇ͛&U}_70znPPc^!m@ X/j&@EDdS])S$(^AZ `Jm̈9@W6^,Y0>=R2 Zbh>GyWa]LI=X\)ވe2엻VdmyxclT (}]Īl8ԫbOO6O!yf׺}\6>v5.J)P!@kl9mN=?RuZDx4M;ʮ;plml␩vlomM;O7DXǪZp^oPH2U3VBᑢ3fc0i1C~v1](&=dvN^ )8ӊS2s 7@<]o3!^˃= ILLcLq,Ɂs 4.sx:AC͇ _AtY^KPMn rca#1ŕ2<4%Crٕecg'a` !!9bW G 9GPG0<рqC#zM+N x< [A5EQ魘9hDWU:xġÌ|z|QIf>oW6L)j+oJʨ/.%ܵߦobnI&K.,u(0]7njRZ9Wk6w&e{C:;y|iEdmȂ|Ӟ['e+qww2ȧM1R<ױuk1p.oTEąDn~ȃle1!tPuNcP/[lj2+Έ\oAN\\ulJF1p{+d*C40~*ԒW6ᔴ}']/@CNs : mxopU;t*1?-F(80lAY?f+^8 5{H# ѡ?M_ |Zgq2: IPhK3ELA*r֔L?a_N_I^%SdT]=[ aT˄d%DԔl@`x >R<҄*fl!NQi߀G06[ڸ6\7_@tiF% Y %A:x.B6/dLKpldU:|z!;ed1J(7[߱zyHĠ\]L53{i [ oݽ~DCyv7?OY;dtFLX?O`RV`v]Z?BV(Doz$-enrbA'U.q `0=pKJ fxzFFLYUPf;R^1oM |^`ݡ5`bpE:wc& ťk;NiG)ŤȯeUqQhQr 1`ݧTːf a ?*d@y3_>9cust7Usa4#들X75aXj؎6^PT2GN*l‘]H ^hBk#}Tɉ~Z0-GU ,n`m_l݊JPOnw?gmTh>/5 7tr'Ks>T--d&a_ ܤ$&7Pm) U<A"~"tZ@'.WbU "&g:J#Lpv;&Wv+9bL_GH4&WBgS)َHBY:Δ`9,7w8v&i_*`03ufϑԓ>q 8fiXNR,'S'_JU?طiGөvǛWVƽiw14ٕ*.vP8qήaKiαd.i.6Vi,>GD'yf͵$ck21!=9AtWqӵl)z kuc墼ZحXCqcI \ Ac8PjKn*ϐ? [ӷNg2h)Y80.xiӛZ7!R ~r^xo 4hWE ``FzmnuEX&\ ]A0= ~=J׫,@FpㅖfZZ$tjN&\?t']I4M6gu&b-PS2)ϵH<-dӼGZ&z@l 3o_tZk^Cg\ĔGDƤ.uӟ|\d^/ڞ*F9FJM-$mW7&x.D,^P(-&k\#{|w;.{s}.cL8TORV{kgPǒO'窑n rB|m(Փ9laFA.BkS˒=$eOgs+tMiљeG+.q׊^V9bs 8:~$\~Z&fk\̏iʡ;2-51,E=iBc/зҖmjt:y"}8:Ru2xɤZKEGKHJ[h0L'H_ﺽD 4}Ua_xKOi1}DԀ]エ/dbxh%^lS MZNݤ'4,ϵ&d75شfS#{2( 1wfU;E(lh!#Qk M<3a.pǡK hz9UR6=e iy DAT`[S慟Ke\e1-hNJ<=+yUK/bd977DbvMW.vDV›w؊*J=hHMd4;U[x!WEboo\t6Wҭ[̬Y(HRȼh]n#_E$b=P" cwcd <] 56Jh:63x Ur.ÂQJ[TkR,@Mχ5Թ8/)<"ꋫRڢA4Ώ=7]rJ,Jm;ݟXk:$dG2xu$/7$0(ٜP_ } 3èY7l_.+ g?6 f:E"{qzq(Cć0P&-9LhMԯ#_(seQEd p)6Lv7 lD %[⮧ -v}.t,5[c)"e Sy&04gp\9~}z%-^~-96_[l;mMG:,g*#;?TuvVekt-)"HVPsͬAAD*Vb++R(X5dQ} Zgג1Mow؉3q;rf_6eJZl{وxz8=y\6h퇰Gf DVԤ!PU4vnx2DE㡳tVBKs&SmKUu˘zh ˞!v~S u%z~G O{JkW]tK ܎U@Z V]bX6yr+v(x+4 4@2?`}ħ/Obz!O =v`lS#qE-ݠYl1ZLL G$fؑOL~[Oo/{H0R v!Q##-=!l*^הGKiGEB,.mK([V5Ne>$jM87f~Is|麁T2N@#҃R5ʛL7r"3aH=4آ6f+Au]S$z[rQRMl+X2TF@Vƍ7D( c>NI-1&Jk=9q G_" n |o-䩍ԛ"{$ֵtر'߃L~x_e&Bd oJDVo1R--PH_<V>+՛%$ɱh?}CcKkgf5[qӦG=],J90Co]?YPvi4W`d-țG7c m̿w$'!F~0`e8Rp0B1.=#V݄'%3#'wf5;SpjW_<7)^' r$ho1mP0Y[ZOO&kq7-sOAw1_kN8}Q"SnȦC@5Nw䜵u#M';NI /Pl)t B7,.S96)}46 n?d+HdQE!m Ny`Ǔed6?m:~[1";ͨ3!7`[jZ,ҥ`%~8xpg$W:u[ 2؍ D-Y-d<~z#~<ҘcO,80.M.c6-k1N . X^dP ?<ᓳ)!\;&Qk,jPMRJ$ ŅOoSDO~k+/^eN]Wr"yOx =$KeXQЕz/¹+D_j$$Hrktb+7) gqse'tQ9ssY/)S1\O0a`kCIkWu?sٔٛ2` MBROUZH',;ӍӦxtG3b ^yxU&#'m^$J~[874K1%H;"yLu1dPjOﻖ ;!6H!WT~g)l%8;2Oҽ+ߋR*.Q@IyOǚXc!"Sʱ;kyJPM2Rb XҷivyZ^C}r;fCQUsdݞN#ʣ_3VrZ3 rOE ]R.EOwiTZ9s`1@lBTʹ9:P ($j`/&R8zdXuO4& o7@,_10aL=qU_Zt)=vssMЮEO0ȲQBY.WD/Wv!73דh\c8奥k@}Ag9t/gG8;tx |iZN~hGDaz~?b((Tw,t~ě~ E@D/) 3_AW!\Kח]H8G,k ub>!JAa^ބ}rTHE,Nʬņ[?yj:r|>o誷E뱿WMe<D#W&H@~atc+ WL*o?|pi\ܾ$"AQJk|x! .*4%bF(.ys1le)F1@e*Ȥx=Y[L.p";2323`= UOA&[#9mI'qЈ|ۯ٨Pee{Ho)7g&#/V;=zQAQ v.k-",$f`r3ROe`]M5X?#薛Lh'(3)SR^rr:1\0s@9T]㡐ift^Gc GDYU2ͨb+mgZvwksLt$j*Cܭ@Ɂd/hc'KDD=t y?V5W ٜj|(qԃ:yqa]z}0v;7$*,cEx*.  )'NhZ>Rww7\W)kϑ^~ZM)x8#WIm /uwAg速(.|VTbmQ>?'zʗ&F" hQp&uҰsBQ?K.o[#s SDQߞ: +Bl'1WkXn=9 y\?3 "mv($e,Je-Up9l`,2*7߀> @Y$1~6>c;VgNK|H-N|mZ}f0M-dt/J Pgx+Ƕ2[e!+28X-&"똻|Wڨ&e;Igad9'^pKg ! h?"d}:+Yϊr), eE,lMk0?5!$L*S~u I:X*ځr [] \H JMamݝGTjAZ5aw; O" s{hCVޢ"G"_rY|a.1B!d+*G͋|U5{_%T8 *{ɷgZV;55pD?N4e ^ 17 率 J_mZiR C]89{~ eC7nE1;޲3Y^ r/^Я.4|t`Ӧ;ӞQT`_>̦_ռYe4L(+",B W{m?2ysBeD=`z,F Ʈn`A 1γ7ShOIʏ]̫?ZPCnȈ-O fWQMЉv5\]l&~M@Beydoρ"L\Ac cl;IHd̩>4L(7o\lf$Ԇw=_&fq]^qim> 6{ѸTkJ~;v"ob>u?'T٨ȋ7%ovbe|J^2+_w+ u;ٵxP7@z3,lT0L/I _J@Q~ὊWE$ag)rwu\M}ħ,/@p,4}K T^T!˽v#wH%4}yR4_,7L~:*iox%k2p3MTwUřη r/޹noд_bi¼z *AВHQ0B`l<gw[1Ɯ"qq@a"z@SS`|%\F&@}{ Gm1( M2k2vqcl4EwO"iW2 6RYx4"N %y:p8U ȋQ{fans&KT\ˠbt(sjzQm-79)١%rMX[| o5 V/qP]Y)l{LC0js2x(|q+lO}?F,;wos4B0G{_x]ofUWLZmc\F"Jut~Zvq™uw]se՚Y]py\C;^-L\lD;pY76{Yצ1$cLGF8\E&K. WNyѹ>bE0i lD/]xy Z =Es]!>s$u]zrི֗ ޕW9t9_uD$Ȍ~T@#XhA"艸S͛F] SNSR}-bxfD]{-0nGuFȄWPl{ (([\=~(w̶?=7ADR{X;; k=^ w貇_ojzѿB4)o RFY]Ϻx醈ļ\2jM-ۻ)4<{9ș=FݍR1FZ'x 9Ts,AܼTMӐS Jٮi6q; cqO^iD&W@ғ{քfi9sG~0N yb0 |c,:}ԇ Ĝ4¾~GH@Wo.`;cV]lͱLz0W,%p/~\eXARI,:33M5 z/2(Bwe3`-G^<7hck3D٠dpB׆3AAka?m D8't/0eIg!^<,,Te ]\d`nنnm3al/+n@Qt2tG.]Y'̿ 4q̷Qeعuʟ?hX#Qϧ푽fW͒ft$洐+ Ny3HplT][:N!5Vt-quîf 2-NUl]|E%!A,vQ{KcWkE=۷138q|FcoC)?9iq+%Vk~j؆B ;#(3-8_BX2SUm =J%-nw E"Qf+Wgt ߮!gH,=,Q?ñ _b;"8L{+췝TpGVz2f0%\f%ϖQ x/6w8Eb2oEG->+{(B0j]uu5 ob`M!4DP}{zX98J mn1Ζ$Y)j+_YBTCгrWVJIjK,xrém,T0ykZvBS~6 DczϏT˲  9KzIv7h&pN}f/%jgƯ&抅sVު) cMd.]q7?CL- Np<$.*`{tJo?#N*rA&{y-kw|kL>{##WUܚDZ*66N#x2쀍^tW Z" %Z\o}`6}䌠 dY0űEa?S7;F/ #s҄ez#:p]E#hC/dcI%pD=EŨz.(Ӷz3 +B2"r{gА˷+A辽,Ӎ˹K gW="juIX(,?8 :ϟ.tA5țֽDJm\5} \(/ k 6i 3vCm~a]WPtvG1%6Zx fCpQ2 zq\3q(1?B:{H"9zn D*7x^g!> r|ltP/X>LN,LV;l2Q{]3| XM@k_xŪtNDGRS ۩mѤpjDRr' >BQioWv3#72GG'7X)Pd %D8S95bRy"Ze~k&vݤ,bF\ċht)[qalZI Ҳ/<6Q=@:-oEly>)H8xsY=Oznv1(iB#:7O' Zv􆵛岳h6|߸̎rTFEbqt OSvm5鷦M56\dXYQ+!*`ae(ϭ!B(K1`dYgql')) ίIȇe|x*Ēָ4a`W.͗c̹o~Ž^Ѱp\3 ׵`&[6Vao9ma2mҎcT X;>$#"j)5|*8HðYW?&10ͧ K:2~3'ȇCz.Gt<䍲Vl^/Yo0XE瞃j}N =ڊdZ }q0L7R%M.Gv}2 7~ݾU"dLє&MV=H}ގ)*4<4=gVpN iƅ`8=* bFfw!jw Ob~ҖѢQLMUTYL -3iX^^zCyjS9,3#f/1H47bЕC)*ԕG1k5JUx}z> ,]}+z"\%uT|H?+&˝>yˑo >M\į/h:-.lyս.5~)ѪZڏwR n_'1})< 11X}|Q"6hNB~'Ch/>:a d?K%rJôл]R~ܽYފO]A/ŒGlHאWj4byOX[yuW^v9Xi87DenƸ';o'C 42  ˀҷGJ U*`, 1:{jR5 ?fo& htF}<"|WE<9M5 aBM+xj9,"B?țqa6aF( Kk1lI]RAMB4a`QPX&T Df0oȲE\"WO`砾M7aAܓ`2D8hі Jh*aevMu^8lx?^i+PVgMs~ [i/őڷ!X)߻Q-[eتr%.z8Ju[FAKg~G}4grd`H\!ˆЌqUG}l@?r) Kv=)CEk_CݢI9T kcK\Yw*!F lC~jmD3]\0nX cʆ"7_O2bfk SŖ"-]`x{nk>]yf]Fbm:xĐM8@ű>C,&gJXYd=eɍĿGhDxmA~KD C$%25`$ו\CF9/-+!)ٴ4_] N2[pg٠e_¬a:Z̑#4Bc i MGAlw u\c<2Z}P=S`NVDuu$a5_ş؎Al Bq AaPf!@p{nqs%wk% x:pnw?Gc8UuW=t|Kհ)O{2'_Y}??ַļd@p1D͢sTX-À+{m Q"09~|"Q͈eKeuYtEzT);JՎyaOn+* }=2H&.E ?s]OJB5F:[եK1[KAv7)4Zi'1MNi*)zTf+o6V9HLѸsk92("X)`" "P@})B);H~sdXB6DUe(m6v;Wfmc8] {Ef3Z1D&܌O(Mkk\ryWyZ~:TF.Om. (jOsUl^ȆhK< YoV̹"h"[FNWYdm]8<ܕb9^ kS  lcFr,kbJmjP\(K75 `qby)7%*e# Ug@, t]Vj;F\ -wo璢qOuDhήe9WtuTg #3uমD GYjjebQ oQ[D|%+e-WFPg>EmZH ˶&?'ſT|P:61lC1eS#.2rkt5X&ǰdd+1[2a}: g98<4o<)ɪ$ OiOw<}.!5@-RhK)Wжͨ Qk7EILsbڸx)ejZvSxY/jdL, :{7^˴{D㺷a+3;Ah$E~v (VWI]@e%A}lD@[xQB7}ȁdV#^Lfp/Ac:/ƃZv__i,T*ߦm"ZM u-'4VNI#d7?ʈW[T@4g513EFzK9QļS^t${]?VOJtCEpA޷[e!j"+|TS=&՜`CJp˸CQ  V3V|(qm<;CUᦦjvBg}Yfgs~\ l& v9Juͼ`>c 1UQ u8HPY?SsG*AG}:ZX4z@*RZg;bL{smIR9gj8;Kb{E2!Y!!Vܜ$=3z^X!̂Z-kJ)CcF;`LZQ0M&E +9\Ϋ@H@( UkHq6}+5ՇVuȅCœқyba?KqxirM*ԯ(\`L:-20tlʹ\s."5(F*XêIOd/}=g-[hS OwNF8{މdfƝg3mN6 ֝zsY6weiǠ* ;eSd챠BvIIaqfg>ԖfwS|zxܤrYLtd0ZΡFwrLNH4̬;F^i~VQkAph}n=W<q3,Vmwh4er|-QFn6*yw!-@FҡPqѼNg(1(.~0|uCc KSJ7G*T#r_m{rnZL|dg9Y3, yO!Z{˻ }Eq~L4kR6QέԔ##Kt&*8CG[J^x+IxE_ɜsfzz3Ntw7,ܦ>  x_ r_sgco|B@E";NCSYГ?| A1m85XQВpE:5b1ybktHqyg-{-{Ų \7L8`#¯?u7֙e}J(YcΧ{ /VnoukIihMmRSҫP^.;E~쬀TU_t};A:!}u\!*78:lC)(DO=j߱o*L1(;E@B|:KS3+T oyL5JbXphm -w|A1FUJ1[Րi|\Y t"{@3$ tKo4,*)lpk`FL :k =*KAzbx&BJd*![`h1?, ?%5f1S7?e.Ub=sʡj6!BiNminYaNPJUwtʵKg]7 1wW_7&%rAuUWD/Lp@6#w?[v =}/{P̥uSK%#|YG?OuDX{j|V1'hMRȟuAkmn#2ӽz*5ܩȼjrNzn'~|Ad^khxqMy`Fļs0\GshFq2SmU 8jiL^X푛x̗ZQCN {Ih<^LcܡM򸚭N|@Gb}1ZCZlZLٴ"y旲T{fqb˞orTLx\<@B惦S{X!QK*ar>\EwuN0e-EdfuT|jJt`U*P-,A.Kw}c@OX7 $Wܞa Q[dH]=+ɦNl fFj"*z?2yP4ڈmH0. 41ۨzY&6hw5j.qy)1q񀁨kMb]uZC <2,_'^*SHd2 3扦ϘҠR,/V.hU"*&fyZ&" 4B NR y@TN})TfN-C{M[4^dr˹X j9wQzٵ=X-iL ;c%ՅLMt87<JCU|>::eeMYs EIb|}KHmױR5<|dQ^#UuVpo{1Of>57Q*˿U,ok;zߕHv v/ (Jr0 a>=)4# E%RzbUoQ ^PXSB-֠%J+ ;5ں ;۪[!;IRN v5cOy[P >Z?#b=$~%5OBc3z iv5Eu$l&${P8$C { 跲նwxO\v7 ޷-l[ lJx7\:+!J`lz]KycG[6r_'}9{]P $rt3FԮd*>8/{k9|=UYG#ibgҸbkA`MZyQ^SK?{^_CL}Q׳ ke!+A A,`vyod,i įX4B2va>NG(5d2H9sZxD(w~F}U뽰8'oB.T~{+J|'.mt |s*饿/ ;`l\`#ߙ-Ck>*nU<жE d411(H Siva6aiYE̒:XEڑ}mG:JXP;92+櫇 kBOF$+ߛ,Y^U7MzU@iɢ IGVz5^)sCp uZǚ+`IP wԈZthF7=- ,1'OX+>泟~Fhyi K*h9.\R6Q]G&;2bV< aof#|m 7L@o&R{NY *0me(bQ\'IjHLj.Z`zmYS"K ,\-In8{P4dg}#%l:58`yeb:%_teq~H[tJ"`REj6D"6+7D#T6j UoGgb'$ω,zK2{kd@fz;Z+8'tOCC ^_K6BNJT+U%%H=>Y7.yQ- חJkSARe(*!iŞUJ#5{]3 W63{Pe$)M7 T-<!&I \LIP%v++z³K} jmchZ/izB(_h]FBXϽܙټG^'AF"10ӼQmSsgQ@TR'Uڴ^n3pQLF4OŽ R4F5Ne>ALS=*~6ӕ6nۊﰏNBg=&4qH7!y7 kT- ֯S$Ț!H, hO=^i:ަlE}.M>6١d?QX(ѮCcZ/x| sO%"s)de3$n߄ 9iJuC3&#é,* غ{p ,tEj4Z;+'jQi?m6ppt-hx|җ4z@C'ڢ %}hǐx c$z)NՅOV 6ۚ:Uý(AEnsc#߾f2%T'~fŦFaVzG vi67{>V@<׹nfx&i=2P$+N8jyZVbD' 481.HuF;%fo zMu9vn7 GmQ?4H8&L@z0Q02zV]+to75Ѕ/pAɵ@11C<K=D uQ=IϯUG:&'Ghmr ojp_S.pWsUKTnz#ؽ[ "6FA"4e -gUENw`7#[i- Ibv hCu˳]R#pPF}vJ\$= ỳluڲNI%+ky`Nx)B2FĜ2|+V\( a fu  -U=|(n8-\1 UBժb-~l# ; x)ԍpO`J0 vX'H[S[&uWmCfvf,tzWX|sv VM}j> ;vOJkfO2".g0]Va l4\׆{߯*%f(bÊw~1bS}k=fi.׵5KHŅu1PfIFwFy87.ԛS eVIl JHZPTeI".7,IUb:)WYet;'Y~k&J՜-`]zv=o=˞!-XHwn %Pz%Fɱ[n1%)UY}8xs?"rF2W: 2k"-x oa4"S46ckCp' n?Z;t ų`GŻ>m"$1Sv>ں|Xطcʣ >Rp?vCH㰨×JneM ;Yߘ=ھaA*M8$G,џsY/ h!U7"$'Aef>,Rr=Da?~'Av\ovM{(Ub*}~Udf!}+̔&t2;w[;oˆs9#ٰë/a* Vm _j>>JGNP2$C|sg0;k#v:ݠ%]/P'fy('ߣ%r5u Ci>31zq 5,UWC@;[:E.=8Gv#["5؜svU~ق}8<G &>iiV5Nќ%~H3e2"v6KMOl>rpoZEŊSJ3||+OCjC.ZDDžےO!ږs 8H8uq2sĎEX.{ )t>Zwex6kY?`B[6@RQ >mDWO|%dA V|X=!e֫Gz {#W{ ۯeJLXqSJ^qK~`2DҤ);PFw2ZԍK0u4\TZ٧X0L_ԉ4Cwv}a6߇#%&- &hedQsJO+ >4n+,;0J.iҷkX%j?Uf;e\"To< \O/͞ac|O+u3h [hcmA K6hH:߿ovx%5,76jVg։@.rB*VG$,4ƃ;U]usSIF &m)nrZi:ks>E\V.Lf1əD`֌x4ui(X ,+P')W\?,K\p~i-(d/MXMuV{aG.4 ЂFiƾ>}7>Q~Jq&fcs k[`.ю 7&Q!&~*]R"poٷgոjrRv`)B=?/:[OP/nˣN45I@o] zHlz|o& $J/nlv`U/ʤf1߿pm%ܾ"J`'!O4ԣFSX"jp>4[P<e|TIFE8d5:dp7_xn.]7)eٸ&+NRC+CxIvZiOANR#ƀOSBPoB3V=M5wFgbW5Cڰ3l^z3WR6o t%|PG_mƅ2h MY0zЄnwVy>! eVzy0Ȟ0nQ3oOD꼱yrWp U=(}gYI9,ln:R*U4:0F& 5qn>9u7 q)=/`o^3A5LNoEk`<^vO~Sz*_=IK~2J tkJ(_J* qƩ-sJVTMv)@aIb4Wy ̶X9$p&;)*ZkJo##ً޴f;-@XJ\6tq|%zTV-Cz`z60clJpDhD@9钀:LSYg4+ͤ1pSw p"gPg>=c)}+Hy/;~iԥOO(𡞌9T9`q6I_]>N [<T=ME{v@ޣg`ŊhCEt\ԉdWmlkoKtqdBv?we|QL89>#:HzxZg6__yyISrAWLM \A#4kkxTeo~'=JLP\4h f"X89.P@|,JT6[1Y|PSp}ʺG%~>w:tT^v?՜ůޣZ^ nyh]3V&32o7go fa:6&Y'mťtV̂ggrULAȧ;OVMwodpnlĪ\!Qn* W ^:.jL*?aL)լ4@VGm@MCIOl8P71W6λں#8ް+xzl0ar~ v!;JtQ!TP^q;GUZ1moz-BlJRmR$i5g |^0 TY7-Ãqʛf&?J#sė|MT!V³wAH8^:ئ)mJI%<zi|3K:J(NȄ1EO=m2 W5[s|%ՠHa&1+)oS<ڒ2؆dXAGkYH#ccH:)4Qc Tr *SDG(TearX*2J qS恷BHS?Ix=LVK^{&vWP(\¹ҩXyy*ns7=?abxsM'9W];[EK0HD߮<[$[_6<.=←\*J>DoO,幛W69&^#cE'A,Ÿ@HKU2-}.j$|OCϾupjnMm+Rk3-7h Y3GpīTdÈTMt HtxZf~1ki"Nb),h~Xi5B@{K.V=/pFxc'4cSN[lUw@>uhOb5,썫8+rI֭+k>+ƦE@&hpAC]X'Ǹ¢d\D%Qjl՚\rBn6.~=טU :d>TЊ2a_!*(FQ2'0 n;Ç;\H~f'I|^$̢P 9ʋ?=/4Kq|ף=,l0Gz ^5Ce.vW ʻ }:mSa* 7T:ҽvѲג{Kr]p7Pa]8!~?`3glSZp#.g/aV@,e_3cTC(Qș^M! rH J!d%['(]Ӊ" * k$tî'5b",ohùդ3D*K[(Nzpyi a2)wpDeS ?4B-聵$yϷ&v%~r΂E)):IuKzE@ZHZ-/켂)~Oa;%! .E^LUZV̼nnf(V~Pzj2m=%DdZԾ)eZ[*>{SM ,1< *.y ԜNGt0@V8GDQyui`7z+V:w7i1,y{4k@w;_JMۥQUmM@}4,ԑ)! 㩗B*SŽ*8s[QlR K_&?İYHl=n9YAѶGkJqD!f'Hq hWc{\>k8}8ir{&!:z!sGn)Ep+(cun%cAqIW.l6W_f$ө( Fx e]@xE,|r8m -) įb2(3z&nԸAN;4~g<2kuJ7l7UfK ,2j !x :vjU5LnP'[!U2m@d;l4g2s:,ѺFBbqûjEGnт1?rUH3-/?ޙٔʕmtZ[Aו1/yyׁoAU[kacDe|&+4~-Sxgx8;=Ȥ2.ɘzI˵z6@.ޙp}GȎ#yŃ0>{ޔKuTǎpu$K}×%2d8“d2aIu0Sxż0pS͖OLe$;џ -2~ޤ$/٩UFnjZ~A EonDX@PwSKfc1s֦hoՙ&L0:hA &39r t$5]g(١$GBnFkb6#GPfhꖥoRm3V7oa|rN,9BBw$,>qpLvqDY;G̑3R<|͠w'2I,KgHѸ)/+*؎ Un[/GJmL%և ugK BqC8kP٤?UNKu;}E5Q}[#$ OsM* pS[8pՁ AȕD(/jU>^qZ(+<67wngLayO w03Zw,:KKġ_:qתŢc0tbNwqg,mu>dbw>p7EA^UxCevtLxg|#;wy>‰&3s'0$XVZ"yrBrjhϐcte =857˾,is@ב̬<0ڃVM\Q2d?Mv/rZF-<%W,ir]juHYBWWݷ%_ $az4Y#[Rh8V wqcӢGg_-{OƬя(_Wkf` w~e&-?f9q|I[ ɵE#YlY<֨<%&]楔r6`N.܏ t%`= O|aDo%H|N+}W3Oa;)u"2qḋcѲ-n_%o rk}R)֚euk{өH`͇CA:@A\ԕd>zdc !s)ڸvmc| O?oܚ(ڜZd/am;2?NeoH{2I ,7%>>H(D HCPݲךѧ@*"@`S~uNEs.)CPJR ##LEoX3wl&hY1kb $pZKOD{m2 3z 5*j:c./p_d ^ͭ9Ӥ% }#-K>]AEq;Eg;U9Рj9鐒NL=84N>G!4/ p,zՅcsk]>zA5n \GGfC|4urT5|O=-+:wKPwDIrz$ѝ$~7 ہIC=^6K{j!L c9鬦br*w>!̞K6"ؒ63tArZU )Yv/F[ص1F]Iyy$ϝxL.=S"V+B"3f` 56 ߐS6eu轊W^&Mt5 lT6?ؾ K3d8"?R͒S~{㜡 @[w"$OcAV& ̨ |+Rۀr TwVO߮T!{cX֐;iH; RpXۭ\9[ׇ=.g |>"Va :d4/(ֵ" %ܚ3HriaTp3)|Ȟw&/w];`yOXLF]I+i4@*Q"- Kf0S$; kp~CZg.{$jgs(z>toEշ|:] xJ{Nj9xa? \6W'_v$ _Χm%ڲ^Yߝ]'h4,~mv{22):1<ν&͇I>E'޸{ųERfK'5)>`E0p̋Т'(hsU0e졍u,L?>͘I&V ѻ"viC! *Ό|*rtИ܀_Ѥg ÞTDvc!PxHSz=RjIv=- ;jNC *bbq?̓Be8^!!I0ߒk zNv ˹/[i<={ycjN1A#x`_*WZZlp<ގ߲d,2&uGYci} K=/nQ! ܲp+ 4롤"1fewx YZ-#THDhD"22&"u꭭pj8FO݄J/o,R%^zn&(dKUiOEM-JV8@‚ݐK_X%kW)3V>vl AYϛal@t#¦ =b"xd~y8:6X}h"N.BG/(z@XSEa6-TkށjfV^c(TOw>^?ⅵ/mS+\-4ʔ*]3OӷqZOδ\81|%v~u "t!cw\gBAU+y`Da5:%fG+ë8{"Ȑauh% ?۲:ü7QU،f)ez9ߎ6ߩMdU(a@ 1EӞ±jSK"5}LBL;_Vs/)~Kţ%@%[mfa͸*BRBI  K^'ʛ*e@<$tk`&ڧvxF3[lM_f%@PZn!n2Ur9{nN՞$ILhԫXUvút!AcY{b>,9Tvjs(Q6/j1 T0>Y[U1T;6Քk5@\i"gsT'V`r:-FoKi ]8G56!U,ѹs$j)-'y^ Az!m֙>%i(__37M'J#iNC5iG%bq!c|+é3L'6uxt=t W['vvz{W&7V):>x[I`-|.LRAAF;'xb]FAE a{ BMmF@~\1?d*~71r 6ˏn>+up=y:_ X({yɣKDBqXwVvVбsncam>9eY'eMHCЙSV7 #T\C2r, Ǭo|` )Bq'"`ֶQ* Z1uW  WꚊ&+891TSFQtՁS)\yh,JyӉ)E Z^PEk>/Z)YD z+v0x74 2acΖNUƯBFEe$?daJ@2_Ei|@!VTC1G"Ci,GE*v%9-*{~Muu-ӱ!;ok|{i֕\3 Z[sM*~9ӳl BvJwp:]HT?sŌUP`gk->w ꬋN( ӂvyg$J@a9 qNF;7+PHh *H~ (Ȋϛ<]ٌ"@_:޳r"MYF_G`QHR\M:`&/4ݎhCҏ k3EWEq_b;s{~ҭ B_k꜂dK#}}=Q"_ɩ&rhT{'t*K$XFO\@6 9xhb.}:9'y<3ٮWQMkѕ+#}^k/w!mܟM3hS\9uH-YVJ&K Nþ H$K(w !6]ϤHC_NrpA|-,{iMREA{&AƖh*! 4oy>J_^&pdbCGu6||Pw;X|:wu9X76'p>|r Wfp}S2 : u ɛ}J|(V͗5>f6uMiʿvDn hCݦ?zB?\-uoͻȡ$m/f_^Ǵ6QkPȒ#wtQ"uѥD圩0>.cC E"H.0 [PZ^l^ "Bq`K'K'b| ʖ)s0nġc?d>z6qdrYHUڢCµ~c+:u\Xk,ic{{1T}jWN$ ?f)Fkq<\xIBvQ-2! H|-DQ: dxC٬?}K#rKMַ&9vHniq6TqJ8vx\$Hӻ.YC=f~HW<;.#3C֋i-G $ qU dQτ|BͰrM}1*$̼o۔59ښ#g<%7~)p;ħ>R"Fߚ]*62PN59F7bipt1{ d;uM#dOJ1k:#!F dI9+Z2>uBau%bޖbv&L27B { V˃ms]hqt@#h/- N}/xO~ʦ.fWĐL-TT$qǮF#sV$ք{T UQT $ ,q\Tx_g zr/SlH}ҿ5"1eX8iERjiHTT.E.zp1öD-́N.Z涠pv>Nfrb{'.r;0$~5I؛ 7ށn@1] :r~s1ȴQh$CgQp|N3=tLIݧ2U_soE@χآۂ 7D1T],e4KJ*S9N9պ۵q]!-[JonA3wk~`7=LP>Jf#`wA~68 71*vrZÛشl^XӑY2[HjxQ`ي w- = udSbGOx/oQw 14;5FFiR@ժ#A%e@]F+L݋q+8]jzLj#*\8w>~=|mUO  Ȉ[m\BW>H,1DX^Y~ʬ.dnc4C# _f!g+@&?QvbpjTa2PחEgq2>cZ 8+bӻb}1=8Q5լ1nkM]7 4ψUӧ 7$Ԕ7)%|6ktZƫa(;ck@V hkl0ȃ݇CH@f_Pn՝|ךDmKݙs#љ=(0qDNrNk)b_as7` hh]񌸸4^@ƠNW Swѯ Lr5C8Cygg:Y$l(h~ ,8GꑶFL3f }oZ+~Τt>sL+W_Z;ѓl.{cZ䣵mtՙdk 2sJPnrQ$T;03\ҁX,jRR zÇ]-?)("H#7w4g0 VPa/x鬔ڣ#. ^uH"MӸ%OG((?E>:]w sJdjgۄ|ᵘ%W4qSVCjG8bh~ͣ=}l LEű{S>^"I@9u#7_6*t~|xdXUmЂXV ~K˥7e]sf@(xS#;:_YdN^RqŒq Iζ.a=c ^>'UB^RTFHuQ ;^z7 !L{},!ɱ_~gf?ߪmF1>SrX{|oOIj+17 : G]mLAa}-@ +[IA\f@*l|/ϖ4;dW/ W"y@SdnnQ=? CWz(҉/|%Pg/EvQL640 r#^D9m`/Ϡ +gy-]0%$|6u[ܒHk(ʩޤIǗKc(Qﲚ붋*A Qmu9K~3'Ǖbm89ؤ>5 gF+IZч`zD6?!h14+a.۩bǕ .cBUj.>pvy# BzU;D?-@L.1DiR2x6W6}$,lF=}9T2h f<MM-$߰M?)k҂lWZ4t9gڗr1Y'Gc@ 2G3 Ho|?a s/#m)!gBv;3~G|LOrE=C!WA\E߯ Yn6a.!j[{Nmp8 NvDp9wr{R+*N}GC'p0U A¤ar%oʥpCLͬ`.%Eo(o+IƓkX3S➜!UV:+ )?C 3~ㆍq<`wKKrs];jIЏD%4D3Gpd%F, BSclMkB#mx/f fD*(v#M{G2y<ޙ/r'2S;:mO Ն&q>ƪ %2XۥQRu/2]$Ai%<<ˣ#䣓7&c=yjMsn|yWfoе+Z|LoISz"Pذ87V |:{쟜`P|3Ƶq&ÐhT'Mǡg1iS*h1ê6RQĄNϏk$H&ENhXx8zπN L&f:ְEk,N?)ɧWfNaҿ [)f/Zo(Si)u(ؕdbo6e'Tt HÒSVya7?a]GM+|t;yd Ti}Ҳ 2| iTnrhhԋ ~!^`ei^"LE l;R_*Dn:}%rBΈwZJK ӄЅ:}_BeO13kAI: ?h0o"CNh' Th%*-ٹTN:n6}Q'HF\X`@~ڔoYQV^0&r=Vn>2P8^2lWR@|KЧ=͠FɆ<{SٖV\|S( QBh!-HwXlD8`@7Pdfn3Hye OD&I ҩGT>_RW_,@rTq; m;*ܧ2ѿyͷ2X(@,Q h2zO-M+u=#|GնVW&ܘ0m2t($B41 ÆvS"9~v?ݣ@hJCB[Z%`: ٷ h0>[eɀ"oSD.qȽWSvS5\2<WU/%c7+±ܳgS)IOՋ*7J L~qR0EB:$e+nw:xz2+4MV8Mq`09 ev9A,B!b>N|;ʗZFZZaf@A}FMޮQ=R*z;(QǗU3=F#Bslq/BS/D( OeG%=7v; ZvNGi`hZ*!Ij< D=Z8G4+PP佩yH_ iml=:VR֊8>2/TXӨ7;hS={jM_TL>ScthebW#*o@vBDZO$RH&u"1HCvYf;SyZ&X2OgPxWgz&!fwsn߉ŧȸ\/TU#h{1ԉ^ %.jjEA!prϮ Dqێb,r*LRZS_ä"Vw:P-tA80XyM1}6OcWH HeYNrJω!sK/~ å^w~6a]{i6 xI]kY꠻pO-@aae9"X;ds@RꘫVO&YG V7`37 A0/]mɢR_ʯrBcِEQRиd. 0rˎA]\R36GG+(mt{В,k\7=pfsuJQ3(@j0G0(  \k,[%3s{(3XpbՕR}]q}6)vVW$f7O٬kK%\0^:V1W^DPd]YyBLS}OF7JO 纩%l5, ;EG}'u$*;+3dudad 6ncT2fN%fn0ѺML2/qbl@G=Eg-W񇘐1vKU%(iHS W356~[JsᢀKVSkp&fnʓZP/-K08mtuui4٨,DKeCm\c}7$f0ۮ*~F/]9CUi4o{ oE`8/PwDLiZuXe݆DǗzuOT[D&A|GnT,ڃۺ1_>#3*܊żvUZF';hG '3Q2%M[b"`̀ӎ+ X`?#a庶s//;]Y xpY~sʷ{efS>s!LHlwS?:жm馏/a}qrT\eOT3Wcھ dzmDuGf|_\~a#p]Qv^s2Kl:حY&I}6)\mr. ~j#Ob Us(9{c-#K) #OQҷ8%pq"Ӂp31IeLt7Mu)ÍKA' <7 ̏H-ܟtiЄ]j֞fF3<~2v8(TNr0˵v2h5M-=(&rJPQZ,HDQTpV*L\3~:hbnƍN}p~(I?{!*]ν9 R.4+ha9^W:]|$$WUbN4`2S8ξgdQ# "WV0pT{8.H}EUp*:V$;Fo D> <޾RzulY;8J%.g%Iv=B]p۾1ٛصWD:3c^|="|SxɵNCj=, G5!#ft*E/R۔Խ..+&(TY (㏾OpÒEVcɲ6\ Ō!pp<*jM }żQL𭪤ݐ[uiG Ub4_1'q3Ou.atKZ+ZD TiTtYmʋ mi8xM֯=cL&557as<7@Bi,tu: &O5嶰VMC-07D}UbZY[#R zO ߯ƊF/Y1~T̤-CsXCQb!.a0UDyl!j˃PRj;bq[*_K+?wsBMTY"fӒ^0 XWςΛpT /s-Hu 5/!P1 u넧0 ?RWɬ9&^Ӡģ .96p|UZ\d8@ÿݫ)r`:!A0׏SP}Lf8{!T H]5#bF̨L~@oKIr6a9V='Gc^?2+`צiK˭X)D LP2-nSp?6nh=Fyo|A;9;vDh.$!7%?ka=am:!Y^>f!-kq %,ezr#(_ v0ȐhepKt."Oܧ=~JH08]A̲ R7P IM>T[(#Ts6tphRaE5MQH#3ihs$v|V2\o6ꉐ4ctKi/jG\吗;r>ahHPm;60bDD<;e=b9=/ B ڌg4Ee(US)aā(Y |x"ďoiUb[}6Mw@'SQl7L8+av%;oO'hK⌍=oE;6\(4оPRkR)&*K_\S6Wʤ*.(H餏 1%>+̅Q}Xɂyny٩_C1]cl`_)3/'nkfR ozT.Qrr_o467g=,τZ-f xLP!t(lZ7kK{cX\Eʏ_Xs >AL#Y,;v$gfՍxzw O!y`6MW+X^r벌ڢjD=+FA=f-{LZY!Ctو)uɦ41UTk4= d UZ8qwFg$1.it܀PE;mn/K,=!M9*r!Mb; Y0k0Cƒ|"'ǒ3"}z?nsЭQh?Nk’Q5"z5sTI+"Ho(P7jɈ~nMF+Wr瀃{ iUJXDjf􋤧jJZnS%tE>gQ$w9N@mߓ{*1љjRJAk>Kmf_\hΊ*Mתr>G{bt3 o91d[C"dq-+%q递Q>3D7ߋ(Iz罤Oy;<~a,ekN 6R@Ț z0P 8pgP,8{[4vBԷK7bh@!1St -MXϋLƪf,x \*ƋG@s\0գCy|æ@'m* >tiν ']@& @%Ѵ?p/ozDP \2f1zZPےw33-!p;&`dK'檭q}tH (5@(V@oS9Hjꢯ9W5'/ZZc̪`=P1`xc -~v(gm.p]7nڂ ureF)3s8/8*8In#=-\q]=d|=c`ʔmOiVk01iu5i3+hj?lCM"z^|o߻J[C[eH8^1}f" NDq _& #xↅ/OLnIVK[]ނ&)o7W4T z/w]>g>9P345f%p#;IQ^3hw=UQ.GE|͓MwcH6 *?I7Ve}#b?yNF[uh08mքKRTb5GSLc?p;ԴVـipOpR3_ W3UW̙nMHj`9l />Uȱ}v"+03 Q$aO"L5A_>:P6כ/-2KNA, )x( SIk*1K$ ?>\'A֩=*:m 0}܊UhPLd{:!b*^BjE][UsWlGm jN9m1U9tAmJ5uj㿝iJ}~Xw8< *Sg7ZDFWXv%Y,/aMʂ"lQ?Ksb=g';I liM#JHEJyk`{ڌ5uj$x s)xa%݌te>k>xf br)n+z:K%d~NȻVsDDnJ۫+b*讒ʛܙ2nBE{e|x?^w9"_7Z<8_d;p!e!O-WUpN)Xl4aR7naìX+w\+U|r=4Cɒ.3i>sA\'U[c] n^⟯S5fyޅ/4zQ(f,27F9?N__}HYEW&7yd#=؄һr=JXlWܣ# if"S||];5xv`Qĉhmal?y.nd >Dw!U9>0B%̆2aGrGH{J2vj7Z 7]lIq\pZ(=5י}q :pML_}.<8 ^jUTOnVVxF_^:ڏ_h$$لpb4d,2NL񈾏:}EXP,wgR jfbO]Qf[VGU({a?,(Dzɾ`h]W6lQ"[[^ceҬLJ#-H ,dڊH{kpe|e8WN+ @OnFY XZeslwխ9Ј(P?~';Dʞ$4-o):=&^BY(Fթy’dr. l,(N H"y%s㝇HӶI /&+#ޛ}sCT 1 cJ dJft[n ױo5c<Y=ݹC'=ݾxT:|f)q(ToΑ"†Ǩi9&Er͹c/kT%on*ތɞb sX0_kd`88y:O]E ?@DȄs+f5uڇo6r󢝛e1$(x쁭V:wly` %yoO\N a~4X\^)_6-u0G`w*dJxSo~ ^Bl<|謂pUKB "v#H;=#_Vf={),R߀&UJj(B'Q8`v"w2X =(&8sDu(CF[uS~es{z]Y A[fO=s!Lb~P`٭ :d²Gü~Q &L]A .pB{ o}=4E< WE-u`\MG;évphβء:,GGJpd+ Wl;kuJ}C3c8N]+YB6I 7}yu kә)}mY#jgF:&42eMOp$,f-FWiwWWcdDWZUj{1FEx0DcfC;+~\zPĵ};v e8yY2~Cm%~ eLnss,ѩ OtK;ItI., 0_/nU:3N3/0W t*EG $fBP1t›ƄlaTH(oi}S ˭wF.@&F7;ϥƎkoSgƘl(^r&}#JC&.2Wr n7EH } *i9 WM<,vA9:`ԯ-)2++h|J1OA`2j@̏/M\KKq}SC%' [^f+DupPW$%[1oH2F~:#)2Y|(ҡl)JgIS {e\n_J<=^=\;XTo hcyBt0sbR)7&8_z=] 8aEe96-<BĔEOJުjXAJ8DAk~J8ibJ? FȧH`OΨGk ;NیŮ9g[(u•/fw9OOģ+?=U6Y!n#cBfql>S#>@;԰/jZ[/.N<<7m8$+m7Xm@5V1Wcl'@@"ܤҦ]msUra5[ч;;ohIXbgb\q&p!NpTӚb8MG8t֤T1~W1Rk!O*X[ZMm̖w!" ˻2 Ioj35r|R* ;vOp 9-sTUr;þ[x;*(>ƫ,xSKS0R2 )JY^0Z$Vqޣx!VWۄ;`gB0@֗`1䖌-o&FI>>2/,VE6 3]Ԟr2rɒG2OZ$E.OB!Q6o2gy\c_JbeDecxnZD#_ S} 6G)jA 6){02:M#- %. : lkNb;TB8ɞ*|ZB7%qnC5y} j~uKC:0ى=M )~K%J^yG'UZ7o-dsq qN&4S륎l𸖿)Wlf+jEb)먮.{/NJ@<.f`(#=Uǫ-Mu AxC9l [=lN'.A䇲PTU }lOGlgHV8nxhmxQhֈY 􂖿.\r=|ºF Tu;'H*im^='ڏ1쑨~!RU]9.?_muL3o]S_YgB^_Bj3Eތ*GLF-*k,`#m/PLv+;;p ICԗp9oV؍ VD H2l M]WߢC.IIJa썋qn*uX0(ɖqJ3{nҾGKhvgdCr'[eƇ憩Dv76eE :iW BjFF!I-Z+m;?g|MDn`v8Bxg؀o_ ?Wlf"pge\xWuz(wRlRUjd%P ;z ~{I7^BdD_,Ц Ggy5xQ% fwn6D*u~wmGmЂG0=0Qh6bR$bߦ^/WL'ěYo.wΝA 22JH\UwP0aX/e?z s=TnԇO*МgL[D{dLŸlL0B'H`uk娟&%[\iFJ2#PCv;O3)6! K[gţK%(Ԝr}9Y:@tYݟ}w|pۇ<[ —# ۔ $Q~;p\%}zk3{@5wN?xZ D!aX*{_Ȗ:z)ւu~+=QFbJ [Q|A6d 8^h/V0,I  u&o[Og=ar}E'H |1d1YwXDe:K`w{8OMXY7r$ Gh9 FI\@ڢ6gV#٥>"RxASzpI~j]^ x{,.@i+ Ĥ_k$@:U\א"@3݉ br{ JI$YyK6X)P"ؐY݉Z1Ai,+aIVgp<'lZ7YHl__T[i[d{c^ڋ7ѥ1vk0tA0e$' ״IՀ䀉L7Xq"n1ˇܸEW B2*2T/ABCD|Pn]Y wpѱ`C\ĖO[t!)7.g9U&& Uګ{,ƺNZ>$ ރ Fñ PYSiKoxx24ykOؗYS!h)N)=>}D#t4,J@Xn&S%/c$ÿI&El^vf86L ^{8Pw{4;2avs[3HScC=эOmDKkTҠ\˂:֕Q;{q}C]'J[?9x˽ zA{\ X_e[f+Mm݅mGE;$J(umHC{Ž(q4w? v5Bs5[9f~^.j%P0GVê]p{'*K-W]i?7 =ܛHOƯv. (OG7 ꉢcb yRXZ#noJ9(ÞП;ZJZN)w1LSG[^_OcNX,eUwɱnv[32'gYlUt&e09`- Tk%nhξ: =xN{H9֜7쓿gbɥx4Z߹|,YD ƺخȈף{Bڕ8vk oאTrA_Z݃nyJ k~i:vH6U/;-К^4 UY@ &mD>LsTAƑ8&(mRA 3/U~n) 7 sj!Ǭ`*y)2GD#zRBT'5 5La+*M}F Jpw6=-I=L+B\1]Nj:0Zx=t"O3*-rX,`2!I_/@ ͝H5рdu$ۃxEEFF/#"ErI!p7T Xs ΎܻkZ\GHfQ('db[~[7?'{{Xv=*t,>+[o]iL.'Zh # .~k6 ó%mubM KR槺uUf'Dl}g`Q J"n׳1BDg0ķ95+y8%krr] J0?!i{q]z P0%'&H`B\NAeL) x0}J)λi0 {D0o 0NV?%᳀R=";li ~W|̱i>ݓҤ~>Dz H-?X-VQBDBH'xdGM&^CMqJ0bFА<=qFoHdtڵG\A_ܚa[0'!+"ch7v%ͯlpހʠz`\ب*N{X䡌 2 O֟DŽ;$|Vn9g@sdPRuEuw 9XVyemG}b* sgT1KaN:Ht 䃕#įBO eJ\oDM-o3t_>pڹGfw;0Ѳ">@" DUzVdݱQh㻇K1J7MP쯪:VK:ٲ!? LNAKʷ>(*W-椘zc㌊sEId87eSE;TXOk  $ p,FXX;mvW ݵ)蹳.e/XbC4#vI?eK@\9s-.#I *RQ5D'VfEU ́]]lSVF.ʕ3? +170:e#B?|l(*tmn$4E& ;si3]0[x<2`E 05`O}0"l>Y~V^=[YX6tݷZxrZNLu^-uܬzTVu}6=Z'†@zMB(Yjb,.&\GNͤ9]}Ro-O8WN1@O-Y"=TsJ%F6I>|a\6Pd/!҃V |ȲS0uvCd5ve(Amk} [V[507jѱI( +am%2G(6^"zzɵ?D81H 5zu}f+ִQmt>]0aC`'IN ߀n$X7 xܞUJ~U5.cmo9t/N0|Hzv ?1CׯvnGXx( }B=NX*:wGwAT%&-V*02">$ 4W&$!3BM%ih#h0"ɩYytF)2F>Z+ȮkAh?~0eҭV_coxBT~OVJ*X6oukrʔڿGZHSF:a.RHWiabvhuNr£|.iYyUθ ->~7zY%Bj;aMm=`ߚ+y}q3ǩٴ@Ҏ+y ;ĴZ˰&4+'yRsȝ lǏ`բ=2CZsuCSA"ߜb⳺ VfQ{#c~GUIʹrF@1ըKը}oS ܌~ih(y7y6d*ȣ.R2jJ4"B jh:0!lƴ˜T yMsHkX=q)I\D3ߍ0mV?z2 lt [G^ x }Sܩ!(4ҺMB,ahBZR'Ge@l}Ɲ.5jȏHي#cdϳA(^Bv~$齻x'+$okbb3iR&?ܾ 7D{͵[bekWA^2 z쭝`;`i/]DUa#IOo86MK}fYtoN?0, 5F *L檆 Gւ܎ (baI1IvJ7̎a$Ig/dt1P`,ÁizeU!|u7S6Vfb ˝Pof^Ju($/m6;zFe5s~:zڂ38\S@mDTʌ&NkĭŃw x\[5&'"CADg@!v#hjsp̴:Ѧl<.3ߕD1!*p1A=B|*ekx-!,5A^Ќr, o%0 eNH.5N^90Q )V!n쌚KU`6đU "-NчIGMU'CmYM<~.ѡ/cDBƷut7x7ƫ|5oKF"KY`Fr X0(v axhL!A 2O]˶ RˡLpbtDhbKB{Z}GRz5ŶuD7.L ߶a (T2xs뮗Y DmY1P WLAL=@'lȃbMp#OcRҞ3dx >]a%#]*Nթ/oD96uZGbʃdK9 cٯMN}Gxr({.F)1c~y&΋ÒT.lS& H4mfuf~\k5̓9r[' L+#"B VsWOeNïoRVl^c[]gb6O3) @KǓ.(-{jf{o׼DŽet06w]q-!B*Pӳdy@,^oB j; @($7o7{z:".EwcP.\k/rA[egCbz/_vުS yycl aBF^E7`z$m=\E^ H~""ʢm> 0՗+_#!972jgr#/ID)%v-CAkۘe:$]2 m@w޳#4xmf-<1m)o癷n6YХ5R`s8UD{mmȆW+_^Lŏ~领@KkF5,-A \m;i9L5b d< *gQ}PVKd{F)E*2 3Ut0&F*=`Be:wU]KuoC'y7tڊ- ^m:_>𲤉w,fԲ/^#k!NUwu3>`tEbVfB]H\2IVǰ|;S< ʖ߆xʹh/'b d>+N6!7@3 -(Mc㘝z5]5֘|~XQj/;nFߨf+ʅ >S4UE>s kt]-kWuLzyN+"$}q ax^]\O+9&x4 UYf>;WC8뻇R1#³X4>D@" JiC~7p~Xyfm&q.`5k{ [\9?d%P1Fb/Wͮa/BvSN:~4^D5 Tf#rb ^=]z(:$ "UMӢtl-n3UoL=|l %(* )<]I Q,rV,_DauȂ!ߋ(8'Ш!0$Z[-*IsTo#p';xf`20G鳌o W-H5VR<௏.jTt߁c`.\(Y -C }]mmgOsp91A8/ O%bKEsm_l(Yt<\}:➝Ki}uMX8ۧCm/2}D"_疁:Oia٤l/g )K_b r={%k@L,Y8(H,9T9Q,+Yq aWri71rsǖ1s}=np?(;b\֞Ȫ,|;: MC?rDs NMB Oo1/^' g?>&zyQ_Vǹ[& `MjޟVҁ)O)ٳ\yCNAVsdqNtt)koRP*P\^HZit0iI's0T!Sv7\-&ZQ2Ngs2X#,I6mo_܍P"'"^[Ń;5!~jB^K^gk"נj4?H3KĸLccr?hFz`7)u+vEƠN2ȷ{qN\K`=Z4]"n@vۈJf0xX$"Vcb]umW *-r(sh1`ojW߉ˀXɉGktBCyd7aJ?&˾t@6<_[Z/M.c`M 6e@Š:jw'YgL?ߨk.~M^勒AM G?H BKZ],e7tp&5jMKCrKqQ'3f]v2S(uLRŐ}*K[pv햾HH7iOk#Szn[IЛ8=9=$3adTLFr6!%So_;HD.{Q3q f ƘzgR> -q1lْiZ>zQ&M:cp0v$h%;&M s9Q^-TH-:Fw)؈ږ=tg!Tlxe)1V+~\pƓSXis"#`z3upф27]z!0:zKrkÃ?+BI@`fDŃLj7̙) 2Vnt¯Yǜ|31;RuuF߄"8ޒ/"!csɲBz 1[Mx>d+ZO1y]ϰ! )'XI{ H#BnE_>2TkU\SO@brmbbuōyQX3Z*'5*M/6Pn`6*[H7\sèv@ qC˽ujߝ6؉nR N.v~a9N5-j @{TZ12ei:/@4u|! ~ /L쳡Z[֩-Pb0Cw^A ?WمjxϦ8SCIEVN cw(ţG*2D*#=dI Tv›Ԏ̓cKfIԁ$®< Xg=j+X9Px 3͗*0`}{dIt !n`-zPV5C*;;5fPrkV%T=t8j"޵6'yݙI),x|!ޞd(+Pd ~a!h&;6豪ESt\59ȉ^5+?7.{=G2E !:5֨ S?D n&2|a+4-#]2:hcwLP VĂ~||wt ZLX-ԡX\~ۻeN|H,V<:ߝNй/ñ^CϏ|ʝ5\stF~IU1< 4Cx.T\XvdGYv3R9Z.Veė]Ih5WRdJEd0{Bxg;W$HOckg+❍-GNXRdH^&яh9R GWLy^MQ=Cj§u-|| ra kː g;wYN.4+ӘM$UeYCx.|a }Qn̿76c緆9K²X{B5؆~ LgT Zi]XyqUbh׻҆䔚UiG׺\ռ:41߀)emNH"0G}g?dcK ^zB-] [hjdo8^BykP\M/g_1Bfuմ5[o+),տo2 EMhhy.I)nx6MLuDK*XyZnq^;\` |>p^nr$d=9 \>[<շ#i9ɕmDm|,q`er"cJ",x&<;\I9^~Wh1J|:: EfKT艺T]MISې]œI!dI]Fz-VsoT5Q0khlQz%A"a\):93ƲG;6.-W$D>nKcUpBmU7ܠ:; e)3'$~ ol }Mbi×,psndN] l dzц _HA4-Zș1+ 0i:JxQ5i~^^8jB%nت?ŢY!YiUk;!kX[9Qkv|WoMJ1IL)mqgć\+qB*O0_6m Iq՛'ܾ4aX=KX9]$"34A A0rcxX^P |J4dFa1ѐ*P͈ݜ9V94:MWq"ĈK xG3ͩistU3PN? :nͺ\3x>ۚScb۶|`Y;v~btP{;muñ+n^H)}~>8[ܦS`ڞƖ1_p{ۦpX݌fJ` NR GJSYۨ _uTy vixeQ)(q|.=ƙYLɮ\/!]#-S}\<ʛ8OZ,nRc0ZC;KZ&` 2? ,y38,Q 5gG%0@ 8P=_cT 2yֲTJ[)-r4fgRf1%?@-ӽC<4@1Ie#{䴻,UL)%':rS Y]9;ܧ-d.߮dp݇lb9Uk"VV2+\pwTnᤸ #$6fL%kXX/v2/;;tɶ{ } Y =ґE?Sд#B,z''*$P&'P-z A8ͱ/yn(# FE%鈼[]ɭtU, ۬{ԬѕڝKwK`7h JX z.C3@|KUDnYkGv" ux=.:]vV:܁2֡<6WsH7֪%;Βa= Qi׹X}+6$+t̚rYhj@f@Dj&4MO<@G?0*nV4b L#iWQ̎#֥TɠAn0 !QOC&3{^ 1ӫeTł"`*S-G25ȅvr)@TjZ|:z`x' delUri’X}> RN[ lzjrSG Oe&ogrT; ӿ]OJ`t"OM“^>n_;ekxlF¯pG @urgР=.ffJ@ Vj^ V.|tVI'0:\]1:@=4RA@twX@O9_!Pv˖Zٸ 0NDU 6ؙq^7p|-Ju錺4#Oi zEژl^cv & >nq evhJk 1eFV/sFLJ3UY`t?y 3d޸8= ']vyp^S6Hjx/vx> 9 ƴ(r9V:t 4&spH)6& c44g=y2e=uYޯ'<'o}^49nIm,6m0u{Rnx_գ2 KO/cIb*r=`ehR1I7܌7T 3ޫ|ZF9X|zM\ [Qs8ԡ X:w n%q(=],s=jwHv Ŧrh=nƔ1sog^$^f FzY<O}mb2!=Wo_T}65$2 >,ۭc|KixZ٠ۧ ⓶Sh 1{tE?2r@!{Ve>~u[^}F6id)[8霆߈Lx9:p^.fl`PGWm oC5u.HB*S$unh $M\xgRbQ⴬_x˜T@vf?1b\8z΄xK\Y5$vDad9#@gVz3zz3E7VoOɀA2jBFBɸ']b% 70⿀]!y)З5 Dn8aqHU: UIJTRCP5QP IxDGz%6 <e*Xf TٺeTN|w6>KA~>)=LB2 4EzUkO0wO&-e| mqG,Xcc#p2nN_s 9\P-Y[sV7Hu^O0szrL{8MbItĔ>@c}<3`; fjG"aTТKnxx=Jҽ^Y J2?DEc/sT{`5mDiJ`%aaE ]$ש]iW wKLa59FP.OVrls^z@x,g1 A6ݐ,V} %7vnYZYt琇LyMK5$$89VzBpV n4h&j 3(̭R!}D]l<<7 @O\ %{ϬbO ˠoGeɊ4σtMQ|njS( lϱ9Ɉ%۽˔H`=5z D~WUEoZC~Nw;9"RKΗ+<x3HTLW 4ZuXֱr]p "mG? >BV.n.OlQ_p1U@G({weA6gY I8hX4^s+[4p_!̵̹'y7o}ˤ9#rA9piAJE&PuNgNƯC(*` X8ţ@ TaH%8I5pMZ2 ܚq_k/ E \S֦4;J, {xOk3Y3n h?3Q!6~/ l#Ҋq="ؑBwEXEo4%'9r=x]Mด*>+#E"Fp- @rYVu1" ž E9֠t6{(~#!k,^ {38/yoR ģ[=0厙GW{Q:ЪT,ɪ2@2z9fhԁ@13Jk)<ԝ *nAVkG8‡Eb}>h<!SosnrTv HdO N }ADXOT#:oĘ(uQ7 <|UHĮfbX.")ft.QzbOy&=E"> |zeVd7 (Ƌ?$3s=4~p](Y%q'%Z`C m.P PR"?L/.o:wNfgDanF),u毲4DoVdvY;|'c_N-ιY#9Vg}pڙhXe_&%;)I bk4_k5o4hP/ qj_csUHvpz.9[]gX=[芎&[[} &z] ot }YķIv٩;D\9PXQ1TiR` Xf{%e^CnSB%45Ύ"_ۑϝ7) ΈTa A@Yw7^.2nYPa/xO\MՌ#h[OӍTZН<PΈ c:uIpؒ&[afrfPҝU{aǬK(Alo O D#ԅcqFk_ :C3sT4ͽ]U;, 8M8X-'C3Q 6s3xK_d$-Cw[zΞ> 0I,J۹arY<+w W/ Rlه K15N1ޡ+e_w(PoxETHoHjz&/DSx5/X7k F~6,ygEpvS[C5)𳻊^E\CT~e+Iͽ<{xwY]1֎2KL{dc͎E[c͉1>ΐ3/>U )MsX1]6"Ih)Xy8o[Ɉ*:U(h^{A¬y{^5GNG"o]Lyxx7ILwi]>/ UΙ`E832 hI}uɍKtj&|}.CVK>g Ř!D8%'r Scu%.rOoz%Znt0i D5H[W'6ٝ,.7X>s=ntH~rE:Sx.0l;h [/Eښ-&9#bg/ }m~yR畅v!<^AZyĔq9Ʒ1C,-c/{U,Fã/.iE X*drrtB?*%#aCk07_/KyFƄREҬf|X_Vȱۄ9/mq;qə?^zƿmTx VlF񷼖pmdf]rmN.Ň씊UtZW  WW}B61ɶJ]wՖ f1?|M^81rBUޗ9lr}k->-tdm(΋*7fHӻ;u䲊Lk k:M ntiAdxp8ONt@ de{Ox^67"O<-:/q-ThUl+W.<7j+@Pց)fFVp:!Fs_;TC8־ejs;A%M !Flm:kZV,=#vPhg|V8(QM[|Ig1o%cT5kU 3!韬9 "йCM6 blV&H\()[t׵ݷYL{&pYZ& ε<)ٝKg Y,&DhJTrVh~KVP7~*ڹQ_2JV r,AY&>pJn.y{3ހ^k&`^q@o (,"Ձ^!kZБ5۔5CǿF>^w|N`L4w]w_3#jO6eGsYՋZs 58yuBAwL!? 5|>xV͜zH4,=oi c&]TzH;Lz߮Ïlrf7qrlᩙFcfQ8['v uq: Fhs(:{4 ;ѽ,i*-e-KiƱ4#OPκx4qG!h#We@]MOC'Q??/evPv5_ Tq.my҅׆(墳DNI] M;d׽we#X|nW뙥 OMeȠ-*aEp4ܿ; XT*V5DByg?*鶛XUŷW?GxtUsSzG`pMV_I]OZeWYD~F߉퓜2z~P}g1y!!*".?щoL 3bڲl2q/?R780%TH޼$;Fу5{j"*vR_fgPu7:$*tڕd6R4ɅKn7>ʝ@6䫱-5>3ؕQVin@fb7:Yu:TQy eb4לAF˩vmdE<侮 /4L 2Lr">bvڻre0Ήtpo%[([c4*@}B D[@!:FilI+#nEOygb[z' DzV`m44 'mʶqƻ[H}gK}Tk3(pUwe LzV*G*dzםj<_DY+IYʨO53rx58F\9ܵO !WoU+N>FHD A &iI7Vq\@Ձ7,3*fO[OF-8?1bjQœ'FΒ25ޡL;YB $QRs哊XJ2.CkZ@ =.GxЏk2&FJpAhL8-Sx[=vz3rG$,7%S'XCTO{q E*.R":sS'jCบ Q+^Z~0-C|"M8U,٨$&! %yMp/@쫱|h3+J0D2$^-Jb$k,yB,t- $Րj;,~'cSo'X]X*8V;vrm9jL\۰}Vqu: ͓VY*ǒvD%^|u2]`{ЇbZDoϙ.x;s盞or + 6"͛A7J/H̶n@HמAaK0iNy ᔵ|'_ВcfT |e\Aapaݒ  =<,BvN%6.;x){ d;6gP6RqwT(ekf6.HN;h@/l/,2'2EI,ki!x&,Uϒ+OR&oდ,\g^hS=1\M^\Y_c}VS ㊎:=is,|t,W@j`p~*kͅEBSOQr2=\怓~yuK8l+/{"|GK9*ߥyn}ۍYoHb-ObPW`_6 kq\>/cI &_MK1x$սm=QPEVyl-H+cc?\A\YVt1az%}V59%Ł.TXil}x"n{_ՃY ػ!,ʘcR,5mwy^?\y{FOo,j}fQaSHl~9F`^ԦT;J Z=MsWe 1_).g#p4ڙ-+=u2X%> i 4fY>kB+}SLى7`YW!0tFv?8utת"^9YfС! #%;I_ߏuH/f)bZSB nV}f'yXQa2j8zݲ Lg78,J]!# A7$ڤ[53n4AٯvdW ؋j(3_p  BMDY)KDT>|A;"6)OSЉxڼ쌁DŠK+6FG CSdWĜFX Rɩ;8?H@6q$/dw`@eYOFڳ]oN VLFxDxR`Xg4s/`=c=(E}H:dC`&ݏ\]:Σ\ D1r%`-:˨\הu i洏ijעYIKyRd/Xa|z u]fc`i>=\VWH>54wA#u~+*܅`g]!m,'^Z絁Ntf?s׵?s,]LPoaU OeAU.&v(󿁯F$ s.SSn#kRrB|1E&qk«17D5Y?N MD,$PbjiB3VJC;ķO1pQL51KzLFzoЖ܅ 1`*|1#gjFzc I d{O^un>QD)#%@E(K̃@9ndU_ bf'0mW j)KE~x0y{8 ǐ|g'b|}+FWRw; P+ŏh+wAc+*g4)% !"/ c7ɦ,J.{ 7KV~xtcԛw}jTtHHKw/ i%H<' [fѢy $#gʌWg( *Tc48Mbɝfya8"Q^ruhGzҽtGjV?G# s+fօٗnYnvhnJ+oTuHz NvVkR1Q.4{ BPu( !wiG yu ^F3(a X-sCnRBisNUr p[,<9cEf`/%d4΋0'ZÎ\Ac&̹sWN~Ugn",YL&$Fwۛx׷f ݲg:pسTsI@hI<4͗TmlS'8TaY#`tБr\ aRD0 ?x4Up eh@KMn*0`tWc.5;ߛÅ%Y(0* rN~05THN!9-K>0NHiB>\ؠ:m-$p-\!ZZ+H6hbm~R~(8 x0s^>U-"\VQP) u4"ёbtSugdһTjMz]m?>X4:?)\Of x`N}KE^s%U; >r1 t:[pA-5i&e^6{g sJ 8 ^ZEfTsqz7بz:~ryk[mq$ߔQ\a ?U)?DmcN?邗ߵ +kRY!t,'T]Q)=#tl?Kt`x-t%qEPWt/>/YU]o)%Biq<=gEUmp/d i1~K7KLk 9nR~rm{ھNrĆL~kųԩ`IgKy>ڞ$;'3x=G DӼ@cL _̓:\^q~G؅ *BHiT6T\yW-qaB:a&#Ñ`Z⃙> x1u2ۨVCl҇/̦_s Pp'@~Ui#F7l Y\/TN|3 ԧu|xB/3JAx-|=ՒD;0{ »[ -=ћdǤs^4VKn]8J;8TɊiF 67}rmmBft[:[9[ǽT-Qy|ؒ: ˧I9Z qey U|)]`[qȤAM*1rv-i?mC},~ z[ `܀bRHF]5a|Dp :\Ơ'"Q(WK9B*68 ƬrNY\YPzCv#`(=\ ^ଓl*x} 9;}fH!]ɸf9ɥfg!I([_'T4*I_p.GutȀUzbA+'Ҩ-Jkć3tWCxbSb?pvqXإxFSfgwZ v>aلpm ]>,^f ge Z#qړ+wS (|ʉqY+X7=fp9Wf?Xչe^lp\.XŠxa`._G[.*׼,Z,_bxr_c; Odm?`x'xE1~#xN rW^F1]aa# *C%8Ƿ,o XvZّQНU,J49$HRPp-Y:2C4cQ6lOoh+GBS(ㆮEpn%[1r]l'K5ԍGܸZ@g€RZܠT''c@v!5'Z#]jEwŷ=6 ` ۍ2a06bEۨli):=LyF_rvH1rδl%$.jIA"*@wp&,Uk#&|5Iوdߛbg4{R!Pun`GnJVx.-Qud-Sh"ErM21 x@qp pQ]jOrO5HZYqEX |XE~~4%cɸ s{YSw˳ LAրe8ٹoeռ ZGiMd^Е5Y+)$-旃yկ' еAWh_+uۇ Z E^υ-9eV;85]YWKR]JiGr,9arU)JR,R 4>H$,R? )Od)ȧ"'J|}*=^RG%hIB؟ZI,Zh|v.s)d >c"91x?k\G;8Õ8" ̟/Uw[{0{!Ti/k1/6cZyDöb GVOFdM- |1LMCP=xe/T?rslߴ'2j&=ˌ--/5.^Z]8WeJ32= xs(|i/pI7lƯiZO0=h[OJ$}*BgwgG<߂d^2GS0SMuS|h!;cG V^W =en媛Ҷx=ERe/P!S(^H͔eɊKnQ֚7w݈F+!WgiZ`,LlLC>-5 3+^kת7`ux{ԳŌj0h˨5> D09L)Q]ڤXmc?FYp6x{d"FG X|V1G:KL&Z~F(ygPG hK2\JtH2c3,g`ʸN(x{ cU OLOuqޕ# ܚ_u9Hѧ6$yջE?T?( Êf.e‚lh/RJ-2! |O:@1Ջ'Rl)#\nָ߃ӜVV ; d o[y!DH][:)Z2L ps/䘲Z8['A܂ҧ"=Ãl.I+nM.޷ZO^3*ٛ=4u!{*u^F~6R_#jm͢ijiƛ0R+veC~4/jן#Bl~n1Ab_H8f0;AWWeqʷ YYuҧrvYAHɰJ6l"$s8Cu9!3V #9 Rv8)0>ؘNv-,^]eD@;pK`HԒL_ uPpwQr`j;ǷkCWOeRޫޯ& J8ue޼e8\D_ĭE]?+ҪNf0w:+R%.3h71beD9 ,yC?ѨeWPjӉ*,i}@lV2N#l9vYbGrXQxX=t~=#2@NBь+Ô`<ώ~ gltMF2O*0igv֖;{h TO GL"|@M$'<3gy7k[QpDǭK. 90'} S\wmŀ=N7Oհ&</~fdLQ2T~!(iS_fD׳o=;T~=cW:@.`@dJR# ê*T[j^Fs1m&%H4Ym'4AAM^uM1-)ȍKU4q,%n 61 Orco'jEwzAowxٓl u 㴬[iMV^OBB! =t K3mB#Sјd- QH%z|Ht-?ςB 4+y+3oRo {؄,h%DE0ȆndDmaGtp ;p95?VAV)5eRJW>(m25"NxUrސCߦVAue#%5"<ʋi)y#Y5WciI%5ӄ7]9;'c-l(羑"C=:ʿf@ʪmg7^[قItnD8`"@,,y}Iu`ӐmEgѐ#iM;KLGpuKdvUL̡^^%DŮ7a2B?=O^+8[ mCYI9@1b*^4vwvM;Rmq(^:^H0W(2'^F,vԝ[[}83V${ɭG=De`Kh]|i/dThSIYd;Z]:F=E ՟#u/}wS„L_f&5N XW!}|S2l%yE3~`KybW b u ]9c.e֧+Ӟҽ[>G8C^+v̐&l$Lf-hA=mthZ`[stT7uĉ}YM^ >Dby+a&N]D7?NTqw-Yk yR;t:g_ ~ omIq!_l?Z;>Ts1S= 7-)D7gWˤpbca3ۅn|?O0&:N]>q#_` Ԕ6@LbQF6R>0pz(bXa1Sb4Ig^g`,+a Ëjn CCޕZ+ cw["wvϟYB"B̧h97 SM s:Mx#Sog,799~f/x[bI[e FlmF˷-&SL5? LhU $1VYِ{?-VXe9oPK2OEOedrq3(aUU3RÇRvgj~E+ ,^7dSjYPo=bPO+4NyGNv{堒6v >eS\p ;%M6f5}Є%ɥ4+v rh_( x_na?mJ̱3_WW:͠w@&QP*qnOuDD%r[(/b:u, +$­$K* aԢS"Ǣ9ci1ob (n/7*9cWB%rgOjvh{~\m(_Zplsz+2kN v~rvAEs:+sMhn,H;Q>l:|%˕4!ƞ2Au4uC8q. +)kG¶)~eXgfrpǫ\ّo6N8zIGzOv7mޤˏ{DZ wٹӽ/-~'}+bbFw4@13p® AQ ൿ&Xm<͡y`j:iW0Z᭾rrCNuvc"l%qf= -6AؚJ^/fXxDi=QՄH$PRKP5^혖^IҶLPf;3fُ,Nc 'Cع vbf{q_xɰTvBvN6Ey]H\s=ɻ%HsràlE@;֡Xa7`BbIWߟѐOdTI@9=*rEpY,[E%Fа0/U=k93ޕRyw'% 4$<_DV;jI'#IyTO:E,U#ּ?anu0 ,zFC*jϽvRlAxN*r-]q, $bddc9yiDuEu YVLM{ _XMlX/֙97#J f3"Xan%y*oxX͎h+1%XJw$Bݻޟxa/o[Pi K 8>68+uڪ#vFyUѹ~ʊW~OJfg9R1LVbTb5x rgTzpFZ'z*Yt-:\/% u]=%EAyR'{^>BaML}G?^2Fd}R <Xvثn{Mi%0a,ݩ*Lu Hr ]2jw*4b+~})0ә@K~p ',36C f.=.3qs+Yv +.zTo@ C>ԕhQPe#<1Q|UZ >~Y 5? 4{d|vUߟf'' Z$?dl|)dF[8S~bj,L2fTJ6)iU1, E h}r1s WHQKzP[HR"&7&eܨcloyZKd;*yoXLuy_ރW5iq:]rJ!rLT-g8kJ``Yq+5*8-ɖ[~"Fl8D!^Q5Rqe!s- $TMaܺ_X[}[:CۃBǺjl*D#ZT_ų+; =+qLWtg:S^qx)`#͢狌"KEHR+H*;X ޒ\"&ŵ6Wjʛ!LE97ɋ7!#G˿LV=Y--X|XBʋ'|@B#MqO貔R+#eUjF IxHB|bl~cvpStf]~H7+b_ٟ˕bKEѵU n3zjb~~dE [ᇉӀnp_%uo8TpOoT[yF!]g>0V'2GF rTm9H@i]Nq1JB ?Of{^g m&yy/uUZv9mktw| _l R)YK/oLAp9܈< ,xۤGv M a-nT Ll~﮻Iw$0X/B]3{VO{Er?4W {-5̨m#%WDwi{=:gp=Yv ~jO1#>jŪLx59?h3n"fܖkkjb!Pme G!DFhМK#ɸ-YkɄYmuhtގQZ?QEz mL9}6Z-8 H ~ a$q`"c>)6\ IA;.3Կ}Kjф|Sp>tŻM?J纊p?eܼdS5Xsi#V˦ZC8M.cG/q y@ h<ĤJtÔS;X Hj&w˨xN]0kGhgsd]V|@h-r/,EFDfǮV!͟MzIt|W& ߦQ}hJƋ/$@|{`ᶬX6f)HiV5б;VmOV$Jq kνsa rR&CF*51_Kd,P=Mr'1X/GsaAX25Sds~.ySddf7΁Z/ΏX,ꁒl,հ'fݹ>?)Lm`VEa }?%yG䷓ŨϺ\æ`jF qۭ$Hq 'ؘ?{隢~:tXG˱$o`"e%;"¥SnkΆ#ug/hf>&= 3lV}B6U+X=OHnq@p1 *? Sȱ4-!Mᅖh":rn~uѨue[\qK $8_bYXMlO-V\m83 H*Oc!3ͽΗ=~ sB1wfOF]!e_wy9eTEZl@9hds~Nz>^Mv7O3HAR=;K^ ֯L$\?dvܯLKj}5 ,)YEȊ|S"  Q N:HoO+O$b vK(ƪ-+-~KB ԓTr q|\^'4 N;EA[@0oW+e 47+ޛ?Q(׹B:&Aw ERU@w)L0K4ͭ|@:H#y Uƈ!*ANM^al]J`Nh4SmetP2IL7ȏs)XsËDVj$ ]̋$o7(FY&E+ sJ"z /ӮG̡' ƀrO1UzvļNuZXnJ2E+>S ?1vt8w,G|y1&&Qeg>Cߝ Ͷ3Zr=m熣kUꏥE8GѺG`Z>@'PH\Iw2!ҪKt9ץh|+n=:F,ySl9!1?.?p}?0 ǒ=wY P^Z~ mBB2'acMI;QD}Jn ͖biy͗6I"gUd0|bEZMyx:. $#Ԋ2fg ěk*ӠWjƯP\CZz`cA@Ʊ2_o` '8LxՌu!YdyFK+} ˙ )MZjþ6@nMT/^3`-l*0hRkg}oGI_Ak/ oq(zھyA%62k6X%aY{¯8qy3b.>-A7~16 U 1*K+V{'zq|qn?l#k{&x :RÌ'!!jm >gX6""7X9[}A.5 N+w%MS"YXľ lj;*.#%|O^]P*rUu-Mb=/怎79k:ב@ mSK׶ц̾ѡ¹^Sl=_A'ޝ8[PobRyPh`[$z)wXUKAtF|d]~UꇰQe BfE4?f )uHjAqeyOo^e&ӯzM Qt~+[Xi"FEp\s1˞%O%v(&]W 9Q]nOsO$:Nq]$<4i3#HCC2:SꔫD~WpEK9iZu9?h pݾ9NE0!>NF>X WJh%cL@,SM^F7}Lݲ A)e3*9PKK%>̙H}P8Qq=e폚HḶl5KkBRNCVu΄, d4zu'4O|^[ocͨ;?՘ixň9#I>o0y\J1eS.&$ V;nn?G ~tUr7A̓]5X #ME- .e8]9+v"#dGt2MdV&U1z&!2[^kE` !YE0grvᴩ*Q#鋜JêO ;Msi)pp}|+x7z9GTTwUdm~tUMK~L7˟OC,)1B BMQ>c>qTF?LBT NՖWCѿ63r E0&l 8e~`uw92nkgYzS.y%L$'$x"W u$qAd!If9Ap!YW®c-~e/d!1f^9k+/uֻeal0w cby=E,kX:E %L]Nw@{9i} $eL6](S,K/=Ni{h! lH\p}"{cMd~jݧTEeW\ӨP C5Xh|6z#Y%ChմERmdЖjP!nSVw{6{nA_Tr4@o^񆕺l' Gif"1ˍ9%KVUq XBG N)!M]ގt/P| `Z$8mL~Wta+ɾ0Ór4'LVqLZm5'aۼ*1WW3p}/ۯz1dS;)c o{p5G*:)zGF'>7~+:<ʾu "b9nԻy c;p`2Qdk\T_3r-^]j7U5x '"ɦY(n[1ش|ֆVCIoe!w@eϳ40W\Y>}Y;1OI,5}[-Jn;Ͷ]1jzڳ:Oj5#o&7{1Gi8f'Wl׾V LH zj/c4-B E 8팗#JD6n_.`p8_5j^;dOXY4. 35EEW[6n&JV|(ud]к -a'g%dW%Ym.tqIYR1!q n5ތ;i7EIE(fELIǕzl< (~` AO,gEܐ:H@M/7tS@jV_+Eܚ d1t_K)'7WƊ/md~IBq1 QzD>G8e3~Df2 -Vnn@` (zܓp9/2L&4^k$O=Zf"O +%0pm`Mde>[ʹ(6KeeJ!AS jZ a>%NmARj)ϣ\!Ї{6uнkժ&41mV[CHphX?$6x x4!p]{n蟦g: ֓pc))!ZL_[[6fAGwU\ P=|CŢ7ȅpb ,c5ߝc[v@_!fر(4rM ~ÿ9,<_Gv!Ln8#]xF}r>{ҵ0+uo%+0X%*.дbztFiN⁻ 9ϬXkۇ⛱σ]Qggu).Or`a1|8D!d٘WjG[<]t'޷hKHAefY+* Xc)@ܬ\+GM*<4"3Hʪ ` ԱԬ:^zJsBF;r dRR:EG$һ]yTWy>]X'25("eƏGnYExlЂ?ҥ M;q@ 'J< XƥPǪ286Dzr2`~Mq5^M! 8( ܛt*P2oUr~~ilW-w~SLԐә@uh?;AJ ϱ9'̣v*:j6b@_"j pz/3VK!`TcզNEnI}͔D/}>}3soiAؙ+=M(՜Ekߐ1,yH[rTjQF'9Mo+xR!;|q^H<tϗJ$]G]yG!͏cR=-ڄe~|,h$#2bP0#>g83Y묯l9'0v5t%Oxɽ: [{Qy2<<ؓЖc*ڍh;ʓ;CN~<ը.Y+rYZ$™{sy&|/@o,@M|+ Z.mUׄ?ަvo4aά 5voBe&Bw Qg+0:9 ͽt~iO"s# ݍp[^֢hvI.ޗѱyh`91@+gջ(,a$VT_=`P!fWu%oQzfdۑ*ݞ].܎"#xFO'kaWDz<=8߅WO_|g)gGD_~].̴4Nył곻 ,1{aX 6u{Ϡ1X]cO-R;y5C N${5̿X܊uMr?c8Oq\LfDG` :A,9) a|a:9Sٳhxj]y>v U. +\dt G:t613܈BJ%~Bt452qmn{oȘfy:>8Gq!y6~m)¤I uj3>?)FWv+`\qHE؞~(6{_F:D6IVϏpNOOBo @Y5!IXlM?rJ`I&trY58W&h `I@BC_aWr{<ܵqK(s15tMJfW&։PѦ ,]k#iX.Vknw\C6gy .PZcS`p]&U`,%/R!"3U-gF FhDwMJt<^g?S!bcM]RWABb`UxP\&kM]qz Zsu\ $';_(aOw]Vb*lbѼFM cp_1歓BvXo9*mɕWboO\P=j˦]&Dsm\hKc]Ѣo8$ahDCR2KW{qc<KJnXlU*AY2V;"-pUܶ((b 4Ttj9-rak"߅mTrKA N޵ zzxw.3O.&no8s"z$Em\ȴڰ8%Gԭ9at/`t_-5Ib֧vnL#.Xw)~rfY$Z8vWsso<RY$U&WOV" $LgEb=r`ICꈎc_yO!x5"1A9 YS#5wDY{zR5A|569&To$<5 n d}z'dqMS+3WQ% |3V[?h0F3ѨlvL"j[6.v]JOg|W+VtƖZ<$m-΄EoET:D'Gz 4UBtZ 63K#z`gD9BC G@Y}WEIblU%n/arv }D[Q(BnP|8g~`I8B YBL6 -1q: Gkc4'o9,, Ş"Ӝw.Evw"fDmISqB IfͷJMƯ?xvj/ %'ސqQ/[ q;`y*=|rX:z}.SC>$A/~{K[{ګĬ WtP(R,ש "mR'GӲ@t5H4wWSAt-(,rBDBhdB Q|Hw)g 4CM.5qnw7| ^wnP,Q &_6>hu߫bGr.{x)'uO1]ʧ 0ۀ[~kAeWJv“q a`Bf/ޱIao/Vt?֥}pB)EW7巘π b{_Xit4z=_̖N4m}I1%=l1>C#L,l!Nfj2|}"YDWfezؙUI`^8&P%R(*쒈Ԕ^U-ոd(JsgV1 Pr:u G9]. ?ŠPE P壘qE?6 Yϥΰq-<,TM9a@YSC+a܆d7|B)=\֯ϩٵGoÛpv5}恚P" 9ܕFYec kM6E7U =\ʞ V -+s7n6ƤPc4}TZw|x؈im.`,|2du:W!+ imx+l*G*=sH [vCh/8јp~Gdε3B̂yHZNZA-,PXpQ( K o3/ 곓ʅtȘQ6Q|# g{4f~P )Drp {#`0,:)'6 gVoXxY q"q 9eC0~ d._% 7ipg@z" џ RP]hviQ1īˆM"m^?z 5VM+Lt .L_ y"XLJzu8ط[_hnV D}\\Xټ,E [گK;AF-7^jSHZZGdй~XE9A=s{kӑ7-խ Ujf2p>.8s_S ;2]gLMdFJ|~9CaԜb)ĝ[m{N\V趭b(>g0,;+yJelU 'I xD91>TO9_7â wlOWx7*T=$*FW;< aK=HΜ22a:ťy9AL`2ZˬC $}$J[ngR ,2eӥ"]P!= bt TơS*AϤj',u0 }6q*nx$&kJ<#n7"{ {:{nT5[:Yn]nH-L#BínDWXae![-e釕˰2AF8UM;R03؄͗LMd3,9v6 P*ӧDd yCRSuWO63H+Wbz:4+EDygMYy83Z?G.xM`o@2jQuѸbbǓ ve 鏽M%i4=%VL #yI ~nblpu}}*bO]ac:?i ci7ڎ.y*p5+t؏ѷ8qp\&c)D ^DJqlM-z=y)?5P趺~|v>f=6CG}L 'Ad_CqDh,Xa;< C0qC_BU Ak|=^~w+| 6-V6h`\؈kX  `tgrrFt4_Xj zͧpe֔+d2v0C0cueH:'0hA8 Pz2PAyB<^=;Sìn, k7INǤfo%KaA|BR&zգVx ύ/BR*w g~j~~eCKhh)`%`ުap>}nxodPE_r,Nq/`M*")P.?` 3V}}@7#߱n T=|[י}RwLɄ s 5`)^, p̄;OҙCaJ`eLf;3YkP .i޳3 'GwvP($RO83KЉ {̤6`Q^r' $Yz^s1ԚV%S4/}$K4W tbx^ + q{9;=du Hx\^4$0nqs8HѠj qM:,w~Bi6\wArpbt"BC:q.;Vo`LD Ӯϥ ;ElieiжT;j6Ie/Iq[`)^缺 d$h}]$ kyU_ĊT~'{ɐ}!Zq [syI?zbakc r&yװ611F<ǚ̖if#5*^MY~!P0-[S) ;ޔ:4ױjV[bFoa;qf P6\0([Uy#;DŽRiw[ hn޷ōpQ_5m߼w&H;BS"2[܃nVCӐdw@_Ipĭc=}y84p?+9B\}`Sr~h؛$D=.d, !@JZ]N0滋]8|/0S^19X;`6և`Pc Ÿ0:\p%t-Ĵ-HN%-OQe80_)+iRJxǚbe/cFU.LfHVh(2FճnI^w9,ćs3ʘlNN2j.65<:)U[ z }+dI{@-e aF2.CUҽ e v r&-5/0Eʛ`9|؁SζTMy!{!7xs/ 8Xetzq[Bu僎de?SY U7hb@#(?A> n;_ ՙ}mEESL Hkܬ{eW P&Kܟ'l4%Rx4! uܫZVK89W5e\H +!Ch+K ġO$`&YaY_›VQq ]4茏l/#e-4zT3vSYF-1%ՙHC9I ZEtX],]d%@^3jIba_Ghr?]ʓqkgf8 EO!QR;m*΍"ϯ!ﺋeWbۈHzMure # E 披mŀ|)&ΒENbl0{|ٞ.nc=*Ke7<F by{?1{r oȄ,QW1#'_k/C0+&GiTbէ2 )e{V~qKNH8Kab:g UjV2 HDu 0V/3ԟ ZԨh5 Ք(RhtNzT9lE;}♃U> ck)m>9:ix| Z.[؈DNA]/-ȜdԺl_>mӕ)Fc |lNl 8ثSx7!>1@i a:vf{A!+w3#1QnW$"~c&7x>/O,<$o04L sGFQ m;0o(Ժ4 ?bYtovS:Ėz-ɽ>3/ sǐ'h&9LkܯZБH*יvo='ippLa(@EQ3" jɲD ;Ĕ8GbC]*F(a*( 2QJZQӱ0'+tHyRc6:tyȵ m4k0)?DG}Qۗ{[JB5>hƐԐΥ?P>BQ4@t yoqksAKk S\ӱZrr2JO a6#MrthVHh7C C*\ /BZ(iE6GJ[Mcw?ϰ`s1YiyWUMc\ߝ^7F/[!RO@D yw^sH1{\84 5])ޡnALlMh)+ykA(Ҙ|As'Nߍk-(xEJJ֝vgQdwi8.71XuX]}2{S q(獅 F&H0dQb!`p,n*^"kOé0eyѤ4αIm_#ٵ'_hPt6m46Wijmz,Qc% tנ7DmqtWƛbP[ эeZf7'$mKu}rBx zya6Ѭ C^l~ҋauplΓF6~MdT&AǬPo.ə2JC yg\B Qfm[$MSt} !R9?־;MЙ1OP)TSyݽD"~|a!k P҄ J@mۻc0Ӿ )>M>2_#Y:`?R+yt'@0r7"l%۔Z8KA8 Ƀ7\EΖKY|g% g11MM18ĮԽ{4UbNu ?걗q Sւ2.cGXq$C`~N%C`:['8P&{cVTHy:-S1h2kjpPvM \3ݱ/FKXxf/G̛ER`8ISDU]d`[1O1ã!#M`4#jXz~ԏP\g.#֕zm,T;`v9ʜͥf^+cLabNw |9L<ȃ6<-Nȵ>(IᬯG)3 ѐ}:!LO­[X@boUJJ2{n:ZFk` dZ +=zK'%ME7XmK *)U+_ih/<;]>BO6mG_#PW޿PeC<ˑI.+q N'1 CQ5Q[dKGOX~/6M퀟hqq%"{15V+$^3"+cw@3V'Q߳|t b?Nz=]/X"KQU^(q Ð1èȂsdI P5ՔBrkkZJ07LDL*PG܊+usQXҜ ] TF95p>؍u9ɱN?́2N{,»0u/T"ϔs kE/>dv:z Qe5'̖ēfj S4Ŕzɬc~9e@fs ;\GC$3ESluc9>^VEʜ3y|{rBIzӀVېWVs}4RʹHYJ@X}L9 2Y'V2+8!'ڭtfܔ.z7 M-2Kz1?-}t2q3 i}{W>\bid'UD,d/ݷ(c6 uw1v8kA-аWrrRĩ}+&2y-J,,8;߯V \}C_G^d|qrj~t%'g;}X5]F!qP~@7T[FX"CYNG6)l5iCvM?Ou{vsY,:r(n;1yțU*យ/ʓ >ľ l.Ǯ/i҅iV3u 8}jxq׵E G%[/?\9sgTi-nK^>=1 Awm8i$)Qwhoe9U+‚Yjdy!]O;gofc)PzC/4:TY[+SSr K#52nWa@'?Rlnf`=(ӹO|*S֘Ѽ `ཚ] -xfKt4Q.UzvhGX2j 7zC1/)9ɬz‚o`%5:8B"SRw28> nIe ?`1,B27*\h7  9mq8X#PX>iC92ZYThs7NZHywхel$L# O2͈ji1F4 ׬! F>F{v9W7_p9>寥A ђ62,|#nu*CiPmRqIȳ}8r lTLF;]c`BZ30nb9im5O0IF3Y\5G_|YCEIFy2y~dy6OeR~ǯ^m"kfk7}BvKOX acܬmM^Ĺ^$y!9)/'j\f~Zj6FUfҽ]Y >H:GIc4}6&^6yŽpvo`[R'Fh*gKA!Yi8}HHK^:J?gƚʎP/FoB5@y8D$\[=aZ(b>`p;EKad{!OMqI61ABb<-S딩0WV\ofL1* QGJ/ytaǖ<)02UvN;JOPd`z^iiv8<ؕR=KLі NU5+@mpS @#w@'a w.H]mmz65nBf$t^3hJd_լr6:oDwMGY"@=?A֘/LD"wM_q-pA_!|~8n9rRӬMRd 5;àyyhM-w[RȆJܕpM|,/49("T7.^22lAJ{F &uypB-g r c.ά[>tG`<הlU;\蟃_W1hbdqP2fYo+.C. 0T} xMTO^ΘrP2֊J NK>|jé(lV:o؈M"ۼk'b۶4E%; &ѡ.*rG<6ӘDZq<.\דFEؔ\&!.LiB!. LX(Wm"i=/,OkXKmzA<᳟TLu=fʉ%r7@ƙd7y]Q3O{點&Q5폣n7 ,=a4n(GCC 1&q'xEr7'KO2)0w"e1M Y: <^_>aiLDU.+,N=&FqȾ_ە{??v6̙/bObQB (g5Y| А4aC_\XmH1DgvF/_`+Ҫ\br6/f7Q0No_6r #/4193!\fɋ(ťT0 FˬXοp]IoOZ"s0ON%{{FSI fkϷ _Lg.܍*3QɌDv14=0c3q{'Ra*hG*!J1Q:L~G 0/]~uvIL󝒃Xq9 p͈0E2Ofʀd'h *پWv(K v +LZ+Y]\LzʪV1Y' ~CC!lk{UY77PѾQ#˱d(;Qܶl4hgGF MຟIചjSvܲ&OYilh*Ippp Sʳ6_^E}ݶȥRdhTOf`[ǐT-g2(LkpUP:MMSBuiЕi" ;$<J [/kr2(6޹S)O5-{#@A9Cƒ{;|M;D{e};rCV}4{c3av{I*7hA;+<)IiַΎAWO:L})mMVl„fxj|߃HZ+v;>1R>ikIi'`fc퍲5ODQPQ6wq5 a]ia*Mz(0n+3-&꘢MULN^PeYlo1U7u/Co=R ui!rG҇+M]4>OǪfod V}՞eSI߻#4Dq5os{ﱞb{64@ e+`9߫-w BVahh-y n:ņ<: 5c-=V"q] UDT 8}p|FDbvq~#kW 8ce:Z4-v@a`Ddk=!ȭ'QRgv X*r}$\.ܫI8^$4 b>)`(~RVTH 3W=MPVsۗz[U0$hRpYuHmؐXҐVKn=z*u3% AR}i‡їa_4k.o0S*F!0Œ"CZŐpL?볖|xKA5Hd-'7Pb AGm>\IZ:IQ ]H<ӡ2p`@)"5H+q.\3+aEf$҄[V}c9/7|bU]6V8D`Dpl.aj#qZ1+ p/Ps58R՘PBgrúVwI@}"..#`єu@͸{cxfeŚS3uլ,[sX ?eGMV:~9I%Txt\1y+[i_x,onb~E&v4}&kD(: ;\_1`c" * upA?@*&R> nɇFfƁ!$$pUGsޒ`o <>>ac!u X/ 9^/q#8ZBXwMzmT(̭XAʤȬu@? _.B\\>:k-_q) w#b7O̮`ոVJLgQa^@UFMSxM|o,ȗVL}glX kkh/{[yGVV; m8_p>w;bA8bU7Ba2fi=e%K|R\6@%p*ى@ΕZK(r ;*I0ɞk-7 _zR>gs0&2A2]Ő#r d̤!;{ݦN^Vvte$JU]e9RqW7E+gּShe9۹g5m%dz)TmoyN*((nMN`;8xl=z;.B t"`Ej/VDUϼr.fgz^݅ !)"6Q~ {nKˆLK#$-$CsCVȰfʚjw]>M|aDɝ7%m_35!rD:ee(OQƬ Y LJě۲ ;2X`%{sW֋/nž.4?qVRŋF<e?s?:I9?6*3PEh1LH!XŰUm ulЅV8(EBAyO_Vv5V뎼0█~1_ғtcd*j:O'.Sԋ2!cri&&|N xĂ~Y>$)nJϋꞰH,uM<˦,x"?mi aEZH%|TdQ-&S2hb dF2O?i+-2Idho">}ihkluIzlUN/6N+HN%{o>l3`N2@kuPq:,Lh2dZg.)6ȊR>\ d2b8T-aʵoKÕ#iaS6Vq#H+}Y{I;MLAZX'4-[GJK.~FyZQH.hBПiqpĮ"CZOR؆;78IZP;Y6Bc;HNtjQkA[eB }h xYcp*ݯAm]sc:9_6Dب;vx́+h(7b-Y=4w< C[T{B4`sLmp:~MêK3=9׆Lyfi=l&pYR>;~ xmgqNx5@j/`>&b<@}.ç;fB2297=k3[2b'7/8 qoˑ8zMFa|•CQ6԰a s}Vw 4ӕgLW] >oo FtAInV˄)tOvL`?kj#(:G` |zJ&S^l]S(8?wJWR =hJ>CH0TI^ocd4"$S$<>{ՠsT*s0Ot:t 'QeF# C ^͇fomwYǀ_Q-M(CBfCF[Gw6T׻TM2¸`gQ\WJy-[fUh"^N X[XW'wW?u#_cG-Be]>CKUd\y6m/3m=(oQX#BFv}_ oXjR*%{Ʉ.eڬ]98(deB+u7S@9%6 dzy$JZ*}L3M)IP۠Ⱦ0;&_;{]VLPfCӬק#v`a h ؂lݍ濟#/y+h՟rNk%OJn-([aɜJOFU+ ښ?;2%tmkA#״͝49\述r0 #MTyv2ΰp2IZEQڃgр"Ďtc&ZزS{|X Km I#>L)l"󸵼[0R=Uը].Sl@>F0LmƦ`!A]d i{ѬjfL\Ƅ*gy3HWu0ɟ dGlm\<@cمCzM_Q2&=U#|h7|4t㇩ #QFƄD)^~ 'ag͋{LgdyJ=GK($Lȶ?) BҠ&QTVHuvKU!*opgלٵ0&#w_g-3T0U6+oOWS^^Xɩy;S{@у=uc0l2rg {j?r!A.2bv\A8XPff'Gt:d3]oT1%a) B3[noai/̮l쁉,v ZQn남XڼEwL8$GP8_VSk<⋶GC8Oڼۡ l%L&nP_5͉e03s|h^ A=AT6rrTfN1K.978|E )~^2c c7QʀEhd9Rg4cVX.. .i$3VBpͿa:,5kM`qŠC=6&y}ڝ$,OH~m6m nNCͶe>u.Fo{ *8UnaKl+\6] zY}z82 E#FYIGY8j{> /^ZkNr]{4H)mјoJ(Ee0)mZI/6X@x@ ћ;K-y:I=6z]ׯC]}يRcKSfM]G^a ]ŀ|%׶mUF$Պ_}lks緬$^:Q`m:܉x YeыaC ,Ω0jQ|; @|ַ , N}pD%d%I%m?jm\$|f?Њ3ރTݩW3)?=f(HYDm/1"rteگ9>H&u_ hduDYܙPVSZJa^EYx^xLozZPՐM-t|\{q,ynDcxN0ORo#r,29Ψ9!8gbd<"wm\֚|'N1ٌn>|redfDE\*tqY&tA=4-9T+SQ-1Ê*\T_jI0o y &>e0DWOB9Et3<[(OYJ4|iG pkYɖJY"y{h@. {Д <6Z% _EAhNdh74uce]$L>LP7!U[}&^-+; N@"_}Yµs{j$&-y*t~?5Cd;*F̀iO@9mOr{&Vg \)d*M3CͿםV{TJGf|8qEs[JxT+壍R-_|rzf[h͜-ˀ P ݛtp#&,xNP#"9܏Ж'fhn'[?'Q8Ej]Ycx'֘OF[I Bwd;ه P,!=z'tz)xP&x[nF0tIC.'.BͣSy@4lbKɻ|#-<Ťjz@!VFϐj[Jh\A'3$Arh MơnG*N>M{kg@׋2 ~UCS@1NYVr_߿rKj OEFVycXk϶Ðӭ'UaNK^~&ҹ6|PTJ4ٓhjt]R!egawFS2]'+>W㱚tbuPrY[+7O }IJӼ0@8}( c Y /^Ti"{|ďaO.c|P(m(Nu&b {˼`i=kCV|=BWz2я%3*No윫g;,o`e1c̃ PH7Hr!#2?IH-H$Xj?v=Q?e I8(k˕!ӥ+}H[Hg bo}?KR kaW,}рx66LyxңBO{K"oυ \ Tے0*{^Z;-gXEꗺvduI0zؖX=es,_ Džj%Z .-+CxAVVv;.dbeN_풪XԠ`GAH>O <=62˛04!G1i,jf= 屭mS#9 3Y;@rRģbRަZ@f֭-Mu#,ܬKup2'7A* U,ОK1i N½Px֬LL3r]=1zNEo%D)SV^> \v?J:ugWX<lͭ?r\uS|Dk{JQ݀U)yX۱RK׻#n/7aj+7m( >CNwCO}rm )J6^$l:~T3u|ORPavߌjJmbE6Y(FI $-zu=94Dj$bʌdMy֝ RUHakevz //#Q &z@oDžX~@wBkih2 L7݈aH[i(d .KoWGVڅk)gR ʳ Jjա@M:$m;z7~M38 ؐǾ B#*n5b$71pXBjw:F;%tp u!o!iS_J84ro F@/ |-oԤkQ't/pY(bo3T@jaN{'Df >| QX!E:^-*" ?noOpuM~/mTT_' /23|]M#%l~mgۯgn<}9OqX'BEsݡR! 6u# "]eybGrUuhZlKp!N1A/jxFk4Yqp$3]p.k .LF7Uº;MhNY6 O5Y:eH۱>L%\~8VEfqLE ![xfE k-Y/)z:+. D w[!7p`uJ cb+Q4 R,cTb2]ts4St@ gp+gh]q; IgS-ɽO_ )%HWЂ)հWV .SZvp8%.R4MEh/dNn(`5^ݗðeUCյaVCV%I ͏!tCD=|5ƕm%b1!F>(Vcڱĉ;೷>.ijr'<25QrBrկWֶ]e[ Q}KE[$K~invR?uUAH_&_L ƺ;#J *{G?~IR} "X<}R_4HPj.gx7_iam,p9A8>U/ nbٗ = I_if@ .n-P85SIyN |2*_2h*`}KvƁ.ePE!%4d P$7xqוm%u6 * f̥. y lMRR~߮b[ngWgv3!I`.9:[S`=f$MzTh hA$L(f01ZNg˄kiI[ixeYșT[/U1=n0RDS ~/AY"k!L:z.v$x ncM5sԘѮsu^>YDr/H)F<5֎U0%D@ * EaAT:KfL"L{̌u%xو D=É)]sr@rOmܲfm!|T69ܼWGKrDδpZ+NMy%gBNkz)+.\v҉U7v`;Ld%^ &Fjn9U&~cլ HSM[ie=vSťb TTAMƽD]-8 @N2(%ngHa)8bbyV7-YHF}o CҌLWyQcas9R Hqlܟ.{> NQ 8$0Ǔ2O$@Fg-qed1Q@"Mt>^ɪ::! 쉷v-Ep)?Qt7t 6_ \5ZWBF|g7f[0LU;F*tG#j#EEFl-8޵ BzXCwr.ΫY Xz"NwiɖJD檝^fRpvlHWUf. _ert"׬ZAQnzn7>޿#$VزR7 I":S+N;Yi0OZ%o_zBVĸ8TT]$non込5e~Fi)CKqEv9@u(zMܜjHC(qR?b;A~N0]!DHD^h#^sx;g17ınI$Ѯ̴uB}(ֈ MeCR{ eEi@^Դ^hKSiYoaIwuIq곒3E71 A#Mkh0] VPBYءV1:L )Jd cA<56.6/J/Ů`3Z^vT< "p*ď7!v#ip%lr ;.ؑ*sPžan:Hg(ۙ9Swq:?Õa~eJ\Bs`.ekYBƱfkA #$ m p#i#˻J?y UF4 {@=26FM4S{2Hߑ쵟:nȕ~;++ Wt0sڦ2lVm˄"zQ!6YNC JD a\Uv΄&pbH? ęH&)` kKB?(›;HN-{wQGWV*QA ƌzl:ս/i=Y/M/b8PϼSc2 e B6}Ֆ/ `v^`u b'Q2ez5V"[u?TᰂVqJN OU*}a'O5#M>VH0rO(BQ^ ܂aҘÞ?c".SA,Nbä9J b C"hFbV{ *[@Hx[;^q>`(;o.2. _߈ %AZR=Ly0|J. s̸YGDzT02O&\'bb[MX4V.fqHЊƁSQ_2g6Ʌ{c^֕-> kL&ԣdfh/Vt CHtJˑ>O==~33^6^ cqCNJj8|Gg,a:L ,ϡT0ռsߠ;8Ʃ{me4;?RL(@{I]&a \|knK5d"4?ago.IZ˴UA9r`)cuM}4C7m枀;qW.Ҷ{s]DDǡ]:2NdS 1!siwy>4s<~^S)S0BOBxxJvw{@AO澕 =X|r7jNBs6y\x_.TKΌNpCwջHHtTr Kr,MqB\^ai݌`q ~~uld_Ge?9-8n h@&j7ԁ50:%tS(r%:d!bXBHARJnIJhmYVFAkҰ,zTzqUCg;-4Xʖ$ͫ<%"e <ɓMgб*;pgEΗUļsydSDh>ُZ]X^."`4vhi6jvs:mҾ1N3T3<Sbk+.BsG:v \< vFgWg.˭a J6Gp'ٝ'lkO 60U 㺤FMe=:"#6_1<RNMٕR GJÖ67ʢa!H#= <,L|QMgA "ÄxP83*PI^ w+h??Xt_Udf$D?gFHS3b Ń\&=!g^r6[n==Z8 ޢSs!.8ݛ8Wt!K2jo&j-R ^ )τ@W@N ʅJ L]<吭$=/dafH) {c^~DiYJ| ikR}>fVǠ =g@;G`dsy*<r7#L^ZRTzÙA1GQ`o.B[u"_yKeDasy+<&lcy#qx^ )!/SߞF$X21QGl3ȱiJQ# M16>xER K~We0`ub$XBo jx@_8%sI:BoQjqr=x%<#[YU|t KƗCk1@^T\W$fz,TSQgdzwt`Aq =lB/?~؇; 2WWL[Æ:"g[InNJb,Bʋ1O%ԔB?r8TZvS}1YiXh7L5vTUPA`FRY3J,F-* uxTDh0њEL" 8ˏ |5{%돀FMsn۟dbRQ|;D⣽LTq}b[G?`eAy8莑XVJZ͋Z > 9F»37 3H3Oٝ4xLF6g6gF yZkIPYAcd|9 =Hߔ6LU C-gDwMB*7@g $w#Ug 'q#Zb3^K˱ JhLIJuity9|MXhʊѕ}hb ,4?.H#.y„u1-N2_[ȍ(W)6dl캛!ZfmQZ.lhrE0f>hvq]WobZ_J35/0yv+_pX%&zI|8 R"{8Pw:*ƆaZ`|:J,9`k[Ȍ= #_ᲣN/LX Rz@UP*%hl K{2 @2ϑYMm7[ŋ$r!ġ-Y@?Õgi46Ȇ)X$fz) k6-v%ݩ.aXzxZ3 麦ęMKk󠊗d+Ѽ $N]Ȗ.$ DJqTS9:N#c3!cOP &EI2v׻Qy< 7QBcJ1AZWჅZ9:#bA=?͘)K-c$36P剝Nعz/̹=B_.[5&Q}mT3KYrn%7 e?qoW9|`0:đ#ȍ9`>^8^v)fJ%n-/(nxy*HbS+Upu6䍾"ڵ0̍ZТ# t_vB9{%kZ7FڢKvh;˪!QϏ初U“j=ZNTx+_{/kæa/¦KC/4RI˛"tߊ(~)e;Q`5hLS2$(q n:T4Ym`'_`רh*b3!ȓvQ-xYD*a&zdjLFDtߘRnV3^Ẑk*PYvzb g|>XkU2-R7ˬ3;1rIp8>w2†Z. N.lz^J^soe)lM0|&3,)%OA70Ipt0cbE=5g>O`hr>y{+5jz8l|I͕lCʳx$p0·{ qk{$UQCvi/ۄTIݭR$H9WrV˝C6'"<<ك& i/2 V\t;I*! àW`c7!z{>dWmhhSX;8s^5yBp'R܃!X;j5/;=>IQt`JRW#Sr" j)N:uP\b>:6ZNc(cܴ5Wer8hF2Uńf#c=fTdsG\%sKn&?Zc(#֕i*D!cL]I $o:Taak<}FEWb!ՐZ.0YRmxԭPWU{֓< `N;CѫØeٰ )Ӊ`O4Dl~&Z/yܷ<ءnp#$lxcO@sXL?t:O9[43%,joc}dо)YKmW=`)MJöqa *FfŹH84M|wסٚOkl:OY5/vxeL欅+2-̎{DfD tf1z#4&M)_¤p KD^gZ^yjL4t̕Ŷ~uþ$V\Y) kaN i,8&7l\vސ1o"3z$@80"ZoFM"TFd װ*P]@5vB#%a2 T7Jf>1KcC訥m38v;|Dm-we%A>T$CDc#]^Tc Ɖagɉ3FNÅ)޹z[ 0a̾/qΊ}Cիr,x,@ J-VkVzo6h%4حl!S AڑL s i֦XZ =pv*_eA)Q>i8k./WVJ<Ʌ ;]f4J%(BT wD4ʕ"`J>E:GH͜<;7}2YӍ :ݟA3ʼnTQt cMneE F^3ol, 6q#O5j ZiCe&,Rm[Q qܖ!Ȩ丆]"p;-tJ&HW ,T+@BG?&^Bo:GKL|ŎD'鼪 Co+E(wq`-͞`X$rqJ}]4M 88l+qD>^c 'Xݵ6RcϚ!#!='8?N<'f1!jZ_1}*-8g.A mBnLSN.Сdl c| /H\ЌX֥.T*1h5NE ?z}RMtR,ޞׂna&dMÿti;ɜo |͆2peߣg6ښ85 >E`3LUS.=6u(>'cA]5$`VǏO>s ѾWʋ}܌!^,237סxp"gBU느>'=YYDRx-8\d=%@8MQG p`ε8M򨟷ܚP9+Kҗq<8! _Ժh81i.Rrb.vd[[s$5ͱbrxWEb]SSsw@Z>hV z0XqE@S_!{̘P`-FOˠvV,tpw<ʑ,mވ;VڲSb]QYG4w@nB׳u$Sv*8Uˈ#K ioQBg]6l4e{4Cu\G|q\W>ߧ. v6IRZGg]vI"o`%-Sis0^"6- WRzG3\ܥ;ގU[u%4_n"vWvvl}{lD14 Yشղh3QYD.7r^:9ہieU6ʐob4'[P!xLCk23ogŐ߬e|9P%{>rʞ8َ` v<5uc/{Xl( ߯)8ݯU)6 NF+(V"ln޳ds+EX[&V)ФX?h^1#QsW'B bFaHO=]'l_kX(:3F)'퐓 (O_XwU㭲/IV7]O6 2no@ccU cg%^Nqj7}N{;`4{ 7;'pDp$&ea.APӠR ~)]]-&*p)EG{|+pRx.:zvoXbD:\Q7p$S j1>5Vw,`W7$T ?@[ctU2^1,6 nطK~i+rB!AP#5Sb8r ,E'iYO8r$!B$˶LxkNUXpdp_: Ǯr,,hj)I$,w)ilD ySNrupiMK e޵*<=, d^T\7f}2Uq Ѿ;祿AuBM_=KiI5A⟍9ZRY?p @VsY~js-:*{IRLyjVU몜_J惡M$g)Zt p;ݞ"?$2,a^I ڭݟ^NB8DY7#WڦN@rX^VPPKp.i(d#cqg1q֙lHYGl?7Y"y!EZVMNY$B=޵9ߘmK{2=brc~M72+?.w8_^!4(d?22_׵ZhpC~ufObFÝ%q75) [6؇U[`9~+!^6u##ב2ē is$-4$z@+}@(6jSf>jrFEsvkv68&31Yh \QT KrwU=ˢFjY5ˑ PU2P:ΔoGw9$מ1Xd&5ޏwՎ^ IdO_ );&8#+pS7 #]?&+ ۸{L#~|5L ᐮ@n5`+ˠ#,b)1-"EB;M=AF}2YY~!vU%yG@;K$wif5phkJ>sKA7@Q ܛog]bx`|噡9h+܆JVR~]ylR-)J+D$çlOlڟLJ-5=Ա?KKOEkK1hҥ&W{A76ͼF.ߝ緭  %?.b־_>#0WKDFWQc`v1kmL)r|)=In̓4ԒL5= ji4g;qaF XwYNC DBf57\U6yȮsڀ\ \rآ_T^vەe֡RL (kV@VƸ"_qdځI-؋t`ė]^8@z~ƞ®5,j]joydZgt<&ZV|7Yo 5qvq6/4 E&m0O>]/9o)Z(4"BINܡ3*‚0 ffțSv-K1 Y_rS}\&2r9X D~pfu2 9C4Z 3hA×gTB8"% eW+b\nqR> QSͺn|Ү:w&}A4*|LDMN _DcQ.gGM2$yBȎk{bÄ_ 7sA2a#_􆈴ŷ"?1# _O`l8;i%hg帗rѭ[o6М145zՅqpC4kbp@SnV?)1)q"T:&%).E`E:N)XA{4+?v}kZ,{ ,ouT dh!NkPjJd ydB`a;KOisd2G8G i+yYP0 F/AJQ>xie} ٠ rdmtʈ9JoTh'4WnIWl7BReGVE|OJ-sR43>k6^ƌ2g5+04Ѯ ,WI j€Ojkgm)]Sp&*1^4HyJ$pHv*ԓUM x#{ٞ1ez|$o.rjZןųyS+PKHg}?1 {`|5CaFg,nLP•]~ aD$v7mD}%E5Yt:hkɣbu鑑H.aSiH`UUKAiR^Z K3Ä\ TQGl0a5P|Ҩby9JH~w=Aw4~:sCIRxJ#EDw+(ϴ!Om „$.ezLYF+ R/DcQ_d#{bZ=!9PXH-Ԁ[ެEc};5WcJ^X|HƑ-`5qM! 2xC A~ }896JՉHU ۉ9v p6vE0bN>t1Q‚+rxTzUZ`dý߳kκGPlvm+ܾUcƟxSr2ۣ. > i27i]+|s):[?Y;X ĭCXi1v#;렫ԉ!᪆\Bk+W) - |3Z Ǟ?1No'[j;y7 =V`H|3ZI&e,Z :O@n:} (_ SISHH_mWG[<*QIQͶ|n|A4)k$ }vw;4]0%퓰_*{7puf ӧ8П;iL7Pbÿ4U͆)d}9'X#FE;ܘ<g5|頧L?kcptW:A`W{bMP2hLzc6Z`%vHjjX.I it~BvV]ZCel-5&tȿE/7"2i)F)]Fă\߶8f\Gʍrђ 4kf[QX-I`nWA<` &m$T>ءoLEt+GVlڤ}hkPj@ |ġqcТ24)Y04~' Brͨ$ \M`JaQejbY|⩗:~Yj/ 'f:>g&gu_P٦$A[1M7bCjl{8CGrߩczyD";rì.iSb-+K!O#5zM)ƹ&CrC?&35[,^BHg0/U˯po{+#˅O6laoʓe>q(l#zCx^IO~Q]ǼSO3Q#fw3©3 GGJ9dv<E*?v:5>:Q0@کf^ravskY'ZTu}k5b\2z|.d5RS ,~xa{| |@SoWRTf^7sIn+UJhF=¿MEMUeMonZpK 2 rV=##ʯAe_&c[1/S$t;Tf X378N4ßx3EGGY؜c!%1 1Rw۶߰lfÍET2_ooXޜ!W#-JΡANkaQeǭxXK)l2L~2SDd5F37S\qЅ!lgXQxbvh*w=@b1Y!?]#Js3"4cx(FY")Ia:߁4\UVZ+fS}ܪ]d^Fi"Vh׃nK_K+Tڅg_!lm%xMϾASch+fU ZPX %(%W |BtB^W;vyVA^ShM+dzDJ.Cs4 0C($x^L+O}[Wo^,2\ KOeFla#݄ͯ=CىBy6s:Jh|vM2+j%eʎB[{' .:k667|1 $(ײPR lx%b+  ?̀-b`+6O~66H10 B +GyQ_ 9-U ٮ.pK]{X>Q8 u˾H I4)^aY&"yJ<)4e< *u S?Z@޲Y>x_k+;Kx Cr@aBxm|YA߀Pމv9㳝G嘆ū›'@>MQD5aI?:'/e۽)CZK)}_AbEɃL-ʓ> ۡ~kW;֠*ŵn;jS~DvUq\xÔxbr_0{O\XxL+>8sΰmW>]o$IXHZggW[:/!o2"lƟ|ycB:l:';/ [G}Q*A]@%Wedj@wc Gvz?sB&㈜T =ER%{!r%9 y(\CTog22E5+Q(!jv 8KM#"}A!:33YSa6L-FoXwJSaLdQZ%1Q( 1Äxky2G{6ުWY4ک;g9؜ek%$Hkެ]ӻr9MT|AxMRتJ@."w<\i21nK}d ¾Jken+}hXn26_8\ (<+d%r'atu bsYQe :nRlK(Hwc`hP=0D ltxwuMiQK5hȍRQ %-)_B 8rO{48rse} >ͩV89&d@ݘhvU պVf'X%>1][Qdj\:2*]06ւ'zsiu_wۍ)q2jrǗ1TArStGr"oCF(?%[fԨ_|J&=Љ£87zބS) AʁTғ_("3V. <=a ;_>x?9IPcŠ}gYqB&'R+g+^#AS0Nl{. FΤ)-o:|8O~m\Qyg.T(P}m7C.KEsA3B'@)BAv1iL#!6S=[M}L8wU(ęQm'ds}H`,Of CTb[1]4DXݑ Nu(ވ-/Fri48pf;KLs&aW&w_Ҫ/b e46D'a: Q[}0!ǫ'Es=! .R'YB]oTDvu Yթ|EW _m64 ɼUHGe1.SA)f2HbNtܶerK͕3T였J[b:%:9MHhXj3<s9.%z5b>XQxCe#5q$&x9ȺjrxH:sX8窴ޤʎ*>̣}1XM2vzYt}7U^mY5 0N#:C/K7* d)vPT/# ^!؇LV G^5nDcҼ8nú}Ky\ye\-L6̍3>-q&:k6J9M-WU5ͻi#ɻe BcZTX\h\}K"Q5Gj&jT$i)BܾU|EjwBXb!A1Elv÷K)Q{DnMdTq= aH ȲN/TӁ& Cָe1KduG6d %@b$`{kX^EK!zX;9! 8@߮.HWG+-PTjY`4mj;92mF8Ր(Ң,rmiԏ^'?%/udqpWI[fy+~J!D9Lba.3car6kI-_ن[ W f(FJH(A`*?{"r^J#+Sv)g){+>*ٗO\ cVt#5D("ʬć̷mer[!m)QWu:c#@ҺAD(:ߕ޼F'u[-]I@P ܜe0e']}W e,Q&w?8:@r/2:1/Өeb7l\k)a+'On09a! TSw)@E˟kUz`4vZva+l6eVh#J"\6xC)mnj6 6DB[iL:'b6lA۠5ArÆ]y;ۀ9u%QNueCV3 ANY{Á"/ ы:i R<EqEXph_H1pJG@&wH u<9XI%e7D8")+)pP]ҷǠ/аy5PfO:sS/ŒP":ΙE NzNΜ4;gGuWO,]8ka| <`bzFɴv ˄ͬ_BM܁"}ϑdS;HEs %ÔAZ0^bbbLb}gy1WǦ  Qe[rCSF5N7@]s\FB@*k x&\=IPFtsxdLc?f.siH9p弭xZ`Ϸ9}0~B#TLk/`i͍O:c0jk?v4޼giu&Jں즐Yb@Xnq._2JHXV BW&GOG% ɐQzamƿ)|έIuTe{:vU `$%o: 9g_ `]^~\{kVfO&_N5ұS-4 /)ne@ ꔃ)oe]RIP /sB?>|+gu$ (ߤV-gpP9]NnF+&`,oF,"B3l~dt F/T!$ m&AWΦO&16{&gL0է"#wPJ,G 2}<&݇:X̣|ZEJxol|?]q׌f+"/@Xhjg>M/i,o -63=W_*d:D'[@~r3|h[=c-t9U"n7tW*$LSl>!;D96P0~=1ϼ-);#D*7i# n&~.3@%L5qȋㄨZc? ~Pm: ]@E1I\xcJz66EA[WRs ,c_l'=B, W%[ό֝G@w<7j NrÃysGKk4F^/_$ˑ|­ j&)&e |تiݷ:Z& #Cxt.3%CagqtP:FVp-ORxRs<=ɔz2nynŔj>k_歳^Ff7PP}NpE]荲"Ծojq!3rbENJL|['pt7&+X`Թ9f7BX a4d&/Ӭݒy&0hXX׾}+WN*פxCn7g,NKI\ja@taHv6ź7:Ř4Li6uLИW_H~%tWxGdI~HFlNUi?pX~ N2 jjpQx`bB6Nne]D>ٰ]sb+ -f|i6|V58sV~/}m5v|k=_J Z *CL;$]ܔ?);b ]&^eirYL&͜ui%oxM[E9U%Yb9Ll&&Fy7,HdxpdX'#.EI8HXsf#X~pnȬ8%,,kHU#N,u= 6h~-ނ"Km%``0z ? -YbZlFyu`=vrU |0vQuʹBTm}ѵI@[CGצ黯k3RoqҎ1]B8b< ? 2+6kF2;f$>f11%,ɍw qSCT9E?ր'~w <`x' $JΡXhN E/Y-K^~[?|r1/Qs@rˁo "}]n#Xa%[x&oh&>h3ЉS"PA#x q ]>ët~WvшA VwR qJw~5B]Upczr\p|$|6IGꩽۮP4yL&aIcuD/Y {u}>' !4)|]Qdw&@T*iIm{2ԇ&Y«h *G==_CKtgD&53:m&<qM fI5o1畧|[?wIe/r\6HOcJl(PF^%  U|C 3'8["| (@%ևܔ3@>eQDd3cpr_俐vI(DJN jU&. ;DNe0i?f:7v` uSWx9.'W*'NUgf^[z4†k"Γ %/J|۝"n7Db dGC}yPZoD=D{mؑij+{qh6*mҬ'<}U'@ޟF% ~.[ }nB $Kpn7-/'xy,8(nѦAd]ʑx[˨1MmJiZ~¤'gJ3Xh+%\BF߭YRVoGB:xV¬ZAZ[eFoV&I}]W1r9 FX~e?nٸ=ܺmTh!HaUE&7ݟc5ԡYЗL)ZEO!,y&:(f3%go7c4kMUi**QR6"*(Hei){czi>=Bb;ݲ iÆv=FɟD|'iFǘG0ޯ8_wmoƿy'}nVӺ7CSiJ4cQܥ˝5/Xj\fGJ?~#xon3^SD ]46k φ)9N$hBXߺu֔D+Bd]3f ;m-y{s,-%owM!ͿvsjW `8eMxxG?`̩2r6,Qȥ.ʋg*VtK9'49пh|B:)-d=RWM)Xaf죰8(j3F{o:ic ߁>":H:h{0♛m:tvF|Z/w_^Q壹?|mT2@0fw?W/{ UK!VbHQ"^N -g4EBY΅W;Z?tXNʹq9-_=+Y7 iɹPL3n 7W\T{\hu{s>HғjFb`_=Re!'$T<.1)wQ~d9YfÓm)9O"*4F; mQ5fOڲu+b؎G*o|2k粑R4:,r !&m k4UDtkyNTZ@n{XȤ*!SY i?\g^ÁLQ~ߕ>UEAa-cuQbEaq(gkI=7nFJZXuk֯OP:%~ǯ2n_%O r@&%yclz5{W'C^dHCS|HB?sh3ZU~IJ@tn䁳AI) )eG [jE@_l+$,z% *2 'fAP1>*Q&Ӵ2eqDgx< _uH$1,4gd hl[|w^ܷf٬B=qWh]ߖT.nz|-&.*{ X֋/r /ssF.Roy̿$B`zOVNL V*GԚ;^< &f2oPa 4x/$moDi.b}=OQLϥ_TvYFBFCn}E3; d.7AT"Zdzh;ttcx-F6TZpveN 4ש&rZ ߟηU;]9*,Ȧ8vts w? 58m)N `TI8VO}H2DP@#_!*rs^T=u BJ/]Bwvό@wH#`LpElF/=E81t C'?,)F>AHe+ _ԥtjy4қTS,bHˆ} ̌Ud,řel(?GedʑXi _ 1XTpŅDpA6z MF ?>+)\oEdzNq=H/UbW~q3;ӆBAaQn*K"fG,x1w(c?iv¨u灾j[ CCi{ b|0/ aK A^d90ㅟ1=~yI WbQn7T:{ĪA*D8ASQG$ZO OeC+*QdΥ&;=+nT]f& a)J1pԼOu ,t":a`v+fM~Ig!K0Nm%9֏Pk8G 'ݘ}Hس Ը w^x i&-ˡ%Y̕5:q3Ms}exym qzM$E+ˢ:x0pq1E{!S9j(\R#΃ӝo= n'5)o+54V>n*v릍}<Hq= >̲=wvid7[e q͑! ?݂YF1u÷hU$ 8%$ΥxUxdnO6*r9k4#2P8p#Vc K6o{hfg @"j|~=-tÙC]j5EҤ>Arݶ2<8sY"r 峖3Jm[='A{.P^e֦MIY?ٸo O6vWWmH`rCO.쉱}K&RwRtho@B*9W0]CF̉/wj e?zH^XnB6"=yw<(FEGԟ? ޜTpVkb 1kXZd "i-cr4Rv5Ss汝`+ 2b6aJ O.FQFLpVz|u`aWy&j0 7jR0n3:OFӅ!xvY=6ύb2hlqg7jyX^)Lj t}"}3=SU*c!IkD3.UqE2y)Y50pĀCeE9µryZ{,-E`pᇇ%leEӪ~}NV]C, Jz^!*7zc ?oHv!(`0K6꾿mT_\dtZ<'J@~sHz>|2HM<ѝv_;_4#}qGz $c2 i)&s)f8ܵ^b{ _߀@׽L)y[>3l}>Ԍ^W*c!Kn ѨՍFp|@o Voҭˊg]R#(( !m.F{-RUYf6 f1 |4R5l>rb܎f!'rr5W>؈P C827{̌_t!{#14m|{75h <ȳnigB?Cf0ib`WFht☏B1_yj O[}ei7:^%`Jj4IAG Cy43?d(wwcj05C ( Sk}>4'`]q҆$v6;pdcD@eWb\ qar|u{/[ : jZPm[IgX@=ƶ3HoέC#\io%HP3xO)0R4C.7豏]/<>ƞv|ʥy8r~&5ZZD@ >5dVA6_ME!:˅9!&ΞZ堬rEa7:0y$VkʎC_%%!AP?T:Kw|5) ,Eg AL:ir^QM3_h2F '%b"{J!Cȷ9gX4XÌz1;SܚR^Vd45]=,rgVL=FKpQSj1PkG*&@=K%|5p 8jZKy nIHwq +C|Qn'MΟ ,{R+^ )v\͂iO;Di+YXsT/~|_ aM$+ܙ(OӡGph *-Vʿ"( pAd.S?,6*@P('Y,ۘ´Eg8#D}bO%#:7uDzV.^h]׾K`; </C?D}ڊx-OYس⎚;DruW *cVO `Uji I$u7n*[TH|20xTA{}bZز_ c  6>^e*;>eIe9#{a߿SwJPsb)cI!w(7<xT谣e/r\c!`˔taoImIOg%? ]Smgl^&!ފEե)ZS_Ν6&s'VnqVd_y"ڦ]۬ -Nቆ(*E쎆AOƈ-1;x|6R8E!^OpQ>N DZAME܁/PH5zeQtHZ |W^9O(n_2{E},p}PJt5<>nr/ޚ`cYi-YFTn||%BB("c]|Qk@,`i:TAPkymW70YΌ+Y} @Y<uBr`D`fzm0M_EJDD :j.={sJ-w&V*( b a Re59$v֦QT+ R|7v pLr@ZΨbDA۵(45?LB F(Hin -A6eM^J? /f_DzAJMiTwW_K7)dJwQR`Zqce@m_'?U 8.Jv<^#R˜M*ϴovnT]zdwT(0/zgk!W>ǠUDL5J0OTѿcFIYBhM kZTҦbWaiAA,"|>w(QpD~ n};bct8qd; Ӛ ֑IQEΘ&'3rOuY4ԭ'{WFaa;1!PV?>oƄn.<`u3;P}8h&,;z)+ff^ZT+{ddG9!µյ L`Hfvְwu#C~w_)Z^AָN@JեVԬP_s[JXƷ$i b )Jgh6.EJӰyFBVAܬyjc`p ڵָ QO;Mk) @KWnO}Xj!)cK_Bʯ,f* !% H8+(ɱa|$nP΂778$JЈNgѕW9q(EWz|[vGh\,.hRǙp-T*6s;!^GX]\_*XJ eCY>b;b4C,>zd'P|іnMx*>W # eC+Uy_>#;,g06'r+.䎜,'k(1R`g*Y6=:~ϸ%!49ޛrȅ ncDm"RocX,DL;"*b}™CXmn+XVNo=VTۉ빵6 I$aV([qG a19,SpUeG6b#Q1yLlGE`6HS3p}kz6UДn6S<$i'^[fW&$ѡՍ P kp%H ܲß[IuaՎ:ʾ=;wWuVzI%ᙂM>$G}>/jmnU(A"K#wAvAtbA`ܐoI 'NkXh2\a] hWjk>PoDmT9-L7 yɶw$'9f*Yѧ JFgm*Q9ċٷԦC:!Ÿitv|4o4'·+}ga)Y ʙi+DwK],|J"Ad@Mʾs4BPPj(*6-% 9`;aµjo%/ ƒ J#cW\bq PZZiq(jG\mu碇ǔ-?pƒ\WDJx⺊G/ë;YiH(bkg:~)qG=φmݔNjsT&y_%W<#LZ]j|U^ՙZ\?pk gM +]#/ƺ,*Wo`q6AX-^~v}⑑ |%lPG}A=SGo3##_FWx=y5 ZLY^EVC 7¤͙ GT_'(wZ_Fn2M=HA(٭ߓ Xn 6(q $)|j3IXGuNd_9ŀy>cN7^y$4SW +5B\ 2nĵxBMW3lwc`+ As89gGt;TQ=@ؽuPUۇd.NH[:u1Wƌ /J3O\ӄjY.S(כQ>9SF|w1duZM0p-mS+)=fcf-xGGd!cMz|ujI%{Iˊ M­ @>u\xe:K\%fGbxչű3tޔ3VxT 妖';Rq%υH?B)p=7?>94xf%LHEhv]ǩ IFs?K^gfe7dn\Y9'a}-sj MBSva3{!`PiYJ[2r:'C~ch%o+Y3su4mBm@Fkt1 :!b=/ikoBeHsӿfZM_W aʓ'o %V Fba'_Tv9Ȋ ? Ge+p9Rqd"IA\I 1z%ϓ2)d^C5=!Ll&=s?:^ͷ@6oxFp(r*YUAY5{mqGJ5Ʒ4`CKm~`Q`$H;ssۙGH""v"Y38XRߩ `и*OkGx3){/XmN`>.#ow#nYQ + WACtԮi™! @+@ ,oD!D{錌郄(,S"c4=*w2 v<[$'1"5 }oj]6MpsEœc@ 3؁$!쳼@ ?"UnBGl4l7 U1/Y RL*@}"0r.g9}U̖ ;'Il`|jrh!(2Xj1|hF P V1R'0%W}!W/Arׁa$!yO-_㗁8™#)-*L;gA06AT8dF<ȓG4 QDY5\8Vтhop=˧ t ѢD*_=wl=)Ow SDY1N]dU?G/|QhMx*Lܲ:q˰2پ{ XPn d{ u\_eB @+ qLOZ<؂t*s1חtqCgs@S|ud %X7Rѕs>\Qu23`G(ID9E65N` &ʠȎUG*݉^38+3MVs1s]\ akqdqR~c$w_m$.}DĒS7'j 'Qu0׷vx-t>Qb twr']vk-З26c8U5~dAzgVHĸrx2įJ<޲-h#I";  ng}zﲂ-^>YN'uqZA #@{7ۜ,#d"+I4/˚,I/P1^Q>IQE\7>}HKL)\?DZm 堄AVݼ5_cp# 顼%.ELuyz0 Hm-4ŀ$%I%x|Jjvpr{b &`\q/r l; ݯږ /*8g谺E=X֬gpI̹-Z[go.OG.q..HRY@)_l m4H }-om{x`k~U9S7ASFz !B+8:n tm)KZ)&IcDRV#{.@?  IjT$!sqp:j67„:\a rEEFM$G}CZQ[}/Y^[:ms>sPc-\@=BO@rh뗑 7t*[M8?UyzbZWa97Uqqd0rޖG Q}muv)=흢 \uɘ@dO?;!xf@8nq6Ks}2.9\>ӝs9ϓ֛!VT pK V͋4q|W);&aa*t*u]ww~1$)wwU /e B؛EoHa4(BDt(P)2c+q>ŬSI1a&u}wYD l@l&{prBzVV^38W񈎤T8cq w3F;Lr^DR41VLBF?Ivs Z~o_Cp[ { Vٹ]r}H4j0*:ɵ6cflW6>K $`YDG]>%Jibx)'{8m4Ч|̀@bj Oj<%YgI]uoK(1g(mUB?)Lh5ӥ 7v| /zMvo&1o6Mo4z9uh"('yYXv9@ݹk߲wIuIZ*pzdL#]K ,xDmص@e3ىjDSٛ4;={;;=(“J,f*L,shdOӿQ67 X kfDIy ?ElY^r00:L%1|F 쯸9l4"+w-ϫRG=rb9?#"XNJ l:Bol8{U$ / ~_\+BM_jVu)˱ n_.a6\˳ub,ڶ}V Q742ɞ%yݸ}+ײ'F3D'a/`js,<{+7R!*[{Ӕ];9{w0c8 Di r?2JDyX#OܾXڝE\7y-["]c2M[EɘWZ.7ObߖGZ9 mu8yCcsvB(ՖcP_53M2LrNq\7iW6.ӅH0kywmDl1]Gtp)k0He'O]lTF9KkERM=ӛ=q%m I:Cp\%f_ ,W8X]8 {RN|b Xk%{F^Nj!O,2C`foN\icG$ w:t Xۂ=e)Q7VW-32|8Xkl  [NBrpaQar-»y=t2ـk#=idSQ35#}l|L:떍Q/Yq"Ï!F3W@Iq(2/J{yX^5%GGHl(Wn%LHv]]VJdT\1X)zeh!i&Z`X)r؇DH7j 829q86O@u 'ƌ'u Yw.mP漄5׮Um GzTYއ3i,Е{HN$x9=[*.@S0vkiX~DBkKh~}_4o'ň\&VSsH1/Y@˶LS7k0YjrAŧ2k:'woȃI  BZ,Յ0)DQf'BrŜH^vpU^`w071M 1h*r8s7b3չt u O~[W VnwM΂WM_Trad(Y$C.c +%nI_3n+oV5~.pD]zaQzIk¥O՘˧/'斺m{Y@>~`ٞFM־5P3׊𰳃q+[N:O8.ܵAx#ZOzQIL3i[U7\"i9TyiOny0 #gV`mm3l(mVNݍRQ'6^qA8.H-ʧwEES3mqq^"/[O:qenȅ{ xfvd2Me)_6t,_Y(Q  'w8[/,JL&HyvD~B8IO^q뗇8nM>f2fOx T^epSky=R>^cB4`}mЦ_Bɼ4#0A|V)hpD^Xۆ})#AAʪ8 q6@t|?q}Q.$p{\4us)c_G\Ms!>+)xrl48_.V90ir/D|qA_J$BL.{O,35%Yq2aF2>m! <%z g=Q0>IB:ZD†3L1E77Z>9MUnZ B]cg6n-7?;jdmzC6Ff"1oG00~p:Y(ZeJ+NЛ,>4X6Ʌptc_ ۭ= U؛ !C}sCe#1WB|JD5A#(qW;mAmegB ]:G'xJXD(~whaR-tq8*~i*;D$UqUjrW?XlA2}jNdjQc g?h R+<~@-D(ʢysvS&bFߧ5GH~*y eX&mG*=(na>E;"g ,WG/PS+؄q K6>*HG|i~ʓ]`.yݣoe=.1ClTVJ1&P`ﯬF+}=6B‘Ofix^G|:lϭS D]q`ɉlJȣ4:!{r7 Z=E*־RtLq/ژȔþP6)$z% xu XslŽ'"yraw^b>vg 2a*j䅬za\~)Č,W |f/q0X#S':=pZ=k {XZexqZeNJ<8&kdI(ySg IZ,6"޿#|_[ àۏ@2to|Jmᐐ"P^:&Ms'G 1XF2#1|mgj-jf_@&pwKGH@CrE7cKT@Vz1b,l;/Vb l-xB[^-Pt.ұy}q 6wvYy8rLkvP $9ǯ&&y{kmOկ!z _]Kiu\ SR/RhAd.,WrbRaootM^3BlhrDKz:3?=/}Pޅu b$fdE~ÃtD A:Fa5$R:# EI=c=Lw~`vTD2N&D$ vk*c0"»n+ LiQ|v%s!ᩪr]PB~0Cg QTݰAF{71|l 9n/4Y+u;x2,X.B&h!i 8 YV49.!SV4J!Obt`d8M͘| *wÂ27&Pk8t`hu?׾ϼ.R{ǧ?/^Em0RG$hpxR1gJm) >bORb0 VD)K΍?hlT9,v&1WG'8@0[8fF'b6E,0q66'1^NhjoIݮf0G*}%$Ρ&l0)74`X:3N7@=(tl({9tƾ@vS&m5 lZc.y"egQ?(T\l-P8G;٭OMe=vFAɻ Q,n;Lɛ~WT0RS% /- J2 >~C8Qa6JXN/=4DeTmv T 'ì}=^b:!kҒi I_[3!P% 6‚W}.UyTmy7n;2NOENEϾ69'-~_?.TW[\TTJ߷4~1-5NSP(u9Bj,p^ʢdS&d¼˩.[nxyʶ.rs>[kIA%.AY:(}A3-wRJ<(#߆FmD a+\_9u`mYVAܲjVېDUlFYTKaRպ3_&ߩde nmi} .i(lͳ }]08 01`W٥ɦq)l"zUjN*ArƤS6\=4aǮ񑃅N 7@6p* q&{ZP;=йsmMS !isQi@087nˈyՍtY#Ɉwvw9IU(:yvpJL@[˝H;WtYfTLAg)Is |]yP _ڌ˔BCg58WaB%=w%ji|X6JU8! XIR7_^PY>㱣 TGrj1Å#!Hn?i%1]JDZj빽UarCF8`~N8F*5h-{] m! lźc%elf| ;j!E?ebț`,=xfm&{qzXeyT싰iLiR+ `;xT:Fh7 9%ģ2oA)>J Qhg e.Ū{7 /֑N6긎 d0Va0 'IGU>}u%MLJ=J;A6"l#X3(57PQJ#GU.qL{tmC"g9^~_ŒpE0?)񔣌 GЗ9ŋqƏ*@%sKDʵ[ӖlθXܩ9nP)M8,CD<{%u}HG?=C1b^!AX!GOFw7)H.aWHGR1s-+{ |A4WM[;=H #q|Nlר1ioVYp-٧L6%^$gkLo3\Oo7[-R!^MOWt)Wjh$G]~Z41m2z8ýKBR樑yi1@@4-^ZM)̂+,a>xx} &](F&)+=-8ӊWh/ޯfNjGwvu6 cjZx#-?HLngPqߺC}}9ņ"dZA׹E,ekÇ +ž!tqnuf&=XtuDZK 1w.U1}xiZ AҶkG6'~MtT O@)^yta}4"r;Vj=z$a}>{9 Պ]2UD"C~\μ֙%ڛ3M=;c4'((AP6^ՍW׉v"ICpVQ]t97H7i^TLjI00>ol1S)!b#)Ǥʦ?`$ʷz46ڍ.-Sx*ʌE"3>Gw h$wg@$ jRq!(ޅ;}zp()B)N.cFgO; x+psW"4[F{p*Ɠ7uѪ-c[qy{GӸ,׉1]=pe8].'!6o}@`Ⲿ;-0dQŇrPuLc ҲwTa,JeI b똼NGrT}f^/x_k/,s Dabh&-ԎČDS}TSmp~BAHdI̻)w;٭c(xNXc8ι :w)RǶQ b8[N}\>/QMvrc[C!_w(8iZ h/o#!:aƪGd$ԣgR, fy%CϫNP'UH)?o+~1L52 %rޕ4J/FRm~*eMX. ^p붲L@ &825=$!XK ]:=f,1h-uBUz$?֥2?ڕғi^6,׭NՎ([+@~D2%0T8Z9J{a +zz%K5 k%sT囯:fAN[ ()g 71܈s^ZFmyLfE20\̠Ș!zRN:\Iֻ |smn[@GJ$/@E-h [*ݠ)K9߈rE)a,3~ZdL^[ɑ3ݮэH2Q6gB{xM IYy1pͦy|ȺXr/_ ty:5wS\I'/΅|bEս]d9F91&q_߬!D|iQi !! e7RkVAlnv9=QFNxtN(oQqQZ,X.~!]6MB!]ۡcAȬj9 }H@duz!KO_Lf0xI7k P&{a(E!QٞE&mqbtZ8 Mh /UvL ,79\]&XjA0:nY ^"ĭ]fܑ`e?7*ޑh < "mk?2`Q^ſAE46LZ/;DD(iX?`NMG8AelZA(rmw2RDsG#B3U#X(g4D6׿.^7N1g5[FxAT-8adZY*oS>"W,s:| ¹d$*m'$03d[w54^=Zqm0LH:zߞY TN*m8q qI.amo[ƪxy8dfzx7 e0Xؕ7jdxW ]@Jfw .WTkLh5y-imrN̶ևd,)/Rk'=o҉ohIT2^uYM_,[B+m@!H55B)UMV% Ni(`^񾭞@ VZllk߿ϳ/dr4{wkK1ee%tm P^,,*jyC"u6D$A;%Æ@FHU8r&ԆR0q86P"l4;Ƃ&ӤNaR|Cr L;dª(Tu)JNV\[)? 1!̮(ӛi^#Q6I Iyz|JmkE|)/TMvuRjhwD"|jJ侃ڽ2@ e˃KiވLݭks-)EN{0 3j @'i}WGCy8<}ļޫ:E3TˣLsC4,4Ay>:Xk`6zњJ_'$\#ur Ep }񪄤'; эahCK Wa2#͂t!@Qa;(%\?'6w]ӛN 5N >F ٟ1JɗE_.HJgi2F5 d{-g5=8i8[6ŕYR<1-I, ][`v0$g`m$Ř f2SLe> J'Nc(S<9̗!vamh BY}JiymV.~~WȮn]?8i˕# ?} {~1 ,]7W%L%%[k8 c]ʕBJdĨ) pA`wȮ25(l5vm1Zx٠jCЖ|$:Ujv8S]щzILaE6~8#@Wͨh?+cjLnCk,tĠI\tN@_zYDy#P tKo;e9) ~4+'ou\_nP@O6 q\؝! ޘY46:.;yo":LoG=3AMޙV0thu?*S< (/ܶObeܫ-Z6W,H6~%bZ3%K+Vg}nrpx0}Y1GW$Al$ܿpFvT 4^tw3F=jd9 Q=|_[?{\<+Nfvv*hT.&i0HSZ ` <_KHgFeŏ %ӛ8=uŽB͕7^^P0pjVa5jѼ7O_sE#Z +_٩Ѣžzf nYe$R}x~bʍ^HR?jCDc3w`lq˗ ._'TAC@M֒+EЎ Mq  %^O|I\Zu4*/YOkuLH2fu`X_4瓷CD^n0SOm,Lڥy ӳk!ՙ֋."\o,CmC< G;&p= 9ؼeM!R+&x"Vjhp{zH 45-QU/v26iWE >zr$Ri,cV-ZMnε\A԰陵2񧭆[$*mO1ovJޛnRc@ﺹiOuAǷJ=oTyMd{qKy05Urk 'LJ=YH3mQNZ@V,Ksu33Ѧ`#9dH݈dV RfS)>TP(C!~K)$""|8"L |. 5%>ѭbȼfqj Ҹ*`r0iEp+ܝ>! 'so <((@;:@zh^KKR406r52'IGe>1_c< I] 9ILW4U5M892dB3-3ALSű'q(sq& I)l;rDk A!f[9٬voC/%.cQ`^~9aUSI!nnPE`R8@PxvR K"𴁪t׬vr* l6xw9w 9<~rEoT[_;Yv(:b3"yf&F]M/q$Oy|3ъƫOR.M%_3q5kJkOxoG-h*p4~Q_Hz3k-,.0; R;W$xa"/y]BD+( es+JOFc dM 5_pݍn)MTErL4x\Xo S()$!7#^In6fauʟpZA49eث5IcS:ŗnQdٟL>}SDG΁hFcAUkNyFȹ@͇'ce0v =ִP@or4F'60‘J]c=*BTP_ZHEIb4]6T|<(%.v$FUX37x,QcLC۶W3U*G6.8Kَi֙LnwڒE/1 Uk䏇xp)[K3^!TWFʆ1k46!R;6=3ouȉ7Jυ҉ƸZ}.&tI´GWZQcY_y/*5r}-&p W& cV ;Ol7==x_ZFNt~oAP<,__BiLnF~Sa&v+vP@5*3șIܰ#H1=JQ!UUn0Bt{ פO,R]ӗ=>zAWz:)h2_.nS_uSas.3sZɔ@'WBDY)E+ ' '˖M]vBm}̗ש UN<$J!"m}HŚ+VLOyK'8F"GNi#NTݳ&P0Gd5ּjQCҥj>Ah;+e T]\GwGS?h3#,~W 2-E:bR8]w }U՛3> N2Ru2Ib4xǷB%E{Pv ͖xyBlQlHkx41f׎==6 ɻN_Ol^NP$dE8oq՚@j[w-jM|+P%/} E|x(%๧H]h7ݔخI=ylR-C S?*|PezyIp 9"`\p"ܘO{Qq>- ˙)*Œd)^d&+*_1 ]2\g|DIS#{4V~_Hʴu e &[+)'| o^\Hi-8j{Q-! gaR aHf"ܨК~ ė~\O vCY1G@,J?s>O,zO]!s0Ŕ[ m݌QwT&RoPS;($pv}t5')sŴ#DHg23٘ B ecE}o+ZĊnE!1*w8.u[>eI\{XC/GǛ¬Ƭ1li2 չn&QGP5 )Mahġv% +8 |tK[Cr](dnErLK[ ,$/9ܖ$!|F֠&0ptR puN'r9=S̞&;,?`"êY85ńր6UED8iPUD4n(C ϴL$&i,)>=tuALkl47_"aPǝ\x o_fR~)v8ʭjƦZ&`y4[0D&{c;) u|j0u˒WZFx,2p:{۷MyNn[ )r~DK)zxûAnud4ޝۮngf+ˑw7A#,ذ#mch<z]Z:2Z`Ljn#$/瑍J3P>5]wR)qʝ}WuX2$l?~"b͜m{<{}*\`Md[M)+\CV\z-ڈ2(u;fFT*&N18'LȦbқYj]b(smQ<+kQ]:7@R; tEc2ₜ>1,-ZBM?sC";/H'"CD⭺z҆Y)PGJ9S{7 @?-;"'"k$t!6QU矏PlWWog,}/U~i#h,nU*dFABʻ5"' yPx AaZdy/;9"ttȟC$AD  M}Ӎ"},)6u$9\'yinԮzjIA%\Mc`Jwm4zg&Pks?byi/,mU6Aн_Kd /i0GhC 'xf+3ۤ( v2^cV_"%qл[yzO#}9 > QSY΢"* b>/~;&GECR?! +HW_v]-30MHw@nQH"ZR`CHWSR;p§3aanUg9Ҳ㵱GT/͔/pU3v`B5B7>t['E9[հSՋHuΟi&قN 'JR-=-y»+MS SStOߵD_-(vЂ:1eV^V]ת"( H\cֲ?ISc`Ю?O4'pio# M{n@a*OGU v0΂ *o00wt,ej &vHgǦk=TЇd:OE.J㚧ASoy's"}MWj WiDޏ!5eĉȣ7i(7 @r>'7\"7u6W'9yKI"]Z|$i7@r)PAfFI˸& %RnCed?,Al {Nc;:w&Yqi͏d[("`(faٯ=+3 V:E !e jBZY[ٳP٦ (`%}IWHY`Q,.#&hO[Z#3 IX& 3չt|-?e;q}i„StgD>.]l_+!DzUoc_k(N}1ݱ`N{8=yX1j$Z$ݙ*vʸ!b/4Q54 )s @x| g0"XuFHp`ؘl=rpg=s&ɰ#qi2 dgJn$jdbEY=ՍoϠS=RuT$˓gl34aEG$B" hRf#O;~![3XE\&I7'!l[ ؠs>n 4Plҽ @ANt4 ͻBKgc9o4vޢK(@kQ'T3]/s_s9 C)fM!lf_KxƠޤ2J-=+48iaFZl:,bPHSmч䕗s,-{ 6ډR9W{5ie iSJ8G޷ذƃIKXE,Ktc ,at sghtDC1QQL,'jjKNksHSa NOL^_M^w\!NN)Q b}ܤy^È؇ҠI|`B(0Ϻ1>RAreȭC0쫥@7֤>pMwѲ'VIkv5LЖOsdtz,p7!i khc,ϙdǪl>+`i٤x4qKC 3 oY1!HkhD1L%8?i?ntcdyO_t{qUvLkps!X//E9)6޻92Kᵨd^^Ȳ*jF:JA)0dx956q7.,9QXPrwW|G =<9Hl):Ubw-F-R 9!}3uU.cc\8N%1jeâT\˲@Uis0]7[6 dgyM76S)9mX/~lJ"wNz3!E0swM_(MܓRʅsߺk ugϱ8rs[MTm @џc;a*_}UGRⴙ$la+qxxAߚ4(,(޿uiH~X:߾0q5-N>v5HWGD$\5'z;0DT";`mLPW%RC9cוwU:"˹8Ur:<~#Ų (pcR5ӽn.͋ ߋ7gBgYVt #q)Ԍ2bpD`fa}1{CYW8JAQlEf]_HhVeFG m禨lQNV$+%WH42?He&֍k).Xn pD; v+pS@Q̒ޫޖs%ґL؝,RGQDP5Qpw` IxezVfyC_!c~QM\TM̈Ѕui>wRt^J>h!e"_/_Vlkv/M> yoL(~sZ5vY 8&(:R"`vE!@S$'6jl'ϵKb}D1{}Իx@IgBpd)FۭbȬ(EL /D@&afF)R:B^bƻW2ͬ:LJ "!v5`3%؏*tG=EMOݬTbGqMڲ%4.l_ZTGe &m #: =C5+5_蝽/W:9ٍUrbGHU+_p5\?fRbisZť 掍y|upO'0mgc%3gچ$ b>[ymO't yĭC nS~88 T69GȼP FAuQ _Ee'jQ*,h_ޢnP_[K#@)r'獧M+Cn 0XBkءXo]A[{kFZ %3-ͪ>HmVVTఢ0Q<**CԳ̛2m(w{SkDQ KM?"ﴆi|P#3n(ڬue#~P{ZW`!|{ӱFkgsgc W щPī犬n1̥A\'%&e#qZ:gB`_mşc;qлYC CHe]!A:$6/.~UFt<=$Is)N<~4%LL%^eط^EhW-{;9bsz90Tg/R]Vf]h$ux/iWmRPÕ4')aLw,G'M4LGVpl[љ'*"G0:cX?{g[mJ N^{ $t/Dz, %yum Y =96_A%מe,>QJ4#TM_eve sdG}Neӱ[ ԄJz)Ak@VExrLS:Eiwߵ?통.Q:G\@.5͂ǃD rw(zǞ`elϡg{QJrJ祻U h!4CFz-$ox.i2:5NY1榈F]pC}AÀїjfl@e[j2` ؽcT`AYgrRʼnbKb~b!\׼r">*@3-~npv!F/цR֪G^~8MYw[o)Qq_̬EҒr;&4b-:a@?P1ytm a2n0$~AY0U #˓߬K.{e*L(I4&}괅zI;!jkvQhb@w ˆg W ꄸ5agߊ t1U)U>Zv(vz:[0܉)j&Oly|g 4i?k3! E4 XBWN}jH0%՝%ԡ)N}H8:"`Ϫy`7dduZ~rF <;Cz6(ݾv -A%u߷9^]A$# !D%Be!W =g3 TB@KeMwMBcaP.gaZ"Dp mm^Gtt^Q5䉓]PF;X֛+ KmP5TgA+ z,6AFL\lo|'ڲNX b3gخ{ah3gCbNFT32 f=doomerc?%b q{K{y?nEi8i3*=#D>Hα0ؗ31!r=Йdui'&;!˚Cfgﺳm㬦i_*v".<&H]MtP $۫=sj=L['Z.H,J,Ogf: Bs ea6\ }k.[uG3@\4NAҋHs|sKZh'J.P?_N @%OI*AX iÀUX%i?r'9=hɏށR{~znXPE^Ɨ)q xNbY#{^Jq.g@8 IA6Ҩ+cJk6byNw|0XH@k ^ 7L DwLsw7C&BR8 aٜ ,Y2.~FT; @&V;w7@ w^} sգފa|pb-T! A<0cHa,ygdGb¶=3 Ex'fi&2AX|0~iE>_oGmy㊚ċ?0<>)kx/Žle}]H#`tvj" G<ƙGg4PO5\VWd0KHҴGKvA0\M6W::(mlB+MeJ~.ɐN :is/,۪6`' ]e?c]JGے]m~o QDݩ[/-" P&| {PDH F\C 7A:Ty fS=G a> 3K)$ wa(!~Les%hrR+dAjxJxqɡ2jix -.(fFT}XX XkxkW aez,e.Ҩ<.yWR,6 FT޽9swGcsr/uȶU\#)WH48b3;2)J\z1**:#BhQ8\jM5.#P?ca|D0:%9١o܁Ѧ͝2|'*>;Ig Dޡ`ʕHO(1t+5gSJuOsZFf,%XOE?}uDeέ=?Z.IB)8كp9><@ڞ[Ǹڻ,5s[DoQcoP^a:_i-qZD(ϑ]^tʠSkzmG(N:WjoF6&s*$kV/Ia??e@}ȯڪt"!O w2Re;akcպU=pF\]Ϙ}^dTx`^A=>$CҘ&m <,ʕL Ըau{m*ަYd\xTSxaⰤkl䟣.D:fY2 Y l XD'"` X-u'g?5~S6Db3P4 MhJ$p:Y:l][yT1t0 %^S雅YMsA|R)C4\ٰ+8].KǶKNB4_8lwcik.wV{VC ie_KX+LxlWܝJʾFY%5=] OtCԡaY]U؀ba 9}"ՙ*"M\ T@29zx#ŠyWjy [^-Q_}>`ye -K&P jW׃}.]!G'a?fɷb~+\XbWFgIy`@q([do M9>۫Lf=4&!W-ya&QhUF-*+<.}ۦn1-@sd8q(,Њׇ|f77[$G213m>9j$.PZ $/%cޙJw&OV7:.i{)us[u4%yk- .]g# s|d\#ؙ@g涗 Xʏ9*ыp;$[gE-;g\g3k?8R/zGӸlXbaf +[;Cajdy< -Tb"e]o_/fo R?uub,nߡo1fD,Is=v9Bbk۲gLYnƆS$3?7^0?8,]Z ~DOûu*%H$, @4/S;>(U&*6ɺh2(G6XˆݬˆL+#GO)J @KpƢ*mg!/4!jO*cУ4^3 sQӥ{PLv7'7Sel}?PϹ5ȻjI/ɮZT{"a ~;|h}dqFҶg9 qp郏x?w!W39m OKtEI!ܸ#L4T zrvQ-0R;F~ &}baQnJodD࿌<1 Jİf:@@S;WS $qvit./ȋy "~h"DXWݤsOӾøwI>Gg03VS+J,hAV%(4ss+ UCJq N"<'jy2jH \pUŵ`mx~f굑L}4P,) !gq$#XT?P*W= Z:{7BTG%y0@,S` ^Q6s#!.Rp0@.I1<3%8 ~uhڽ mwXȣ~щZW}-!5'k]vhhH ';oGT.v2{ltz>ih< "C!?at`0<6AR*& HNx%uɧC7Z1QƯzD~z:U,1j_HʿI]B6FtM3\^6bw4ޥ&ƮXK֎_PuC&GG47 u3>]rQsݷKhm Zk;R&CA9ף55{وd󱽼 {Gl| 0Y6 jl_rSCPU[hB'^AׂO#>&X R+Mwy9]GחkS7 `]Ͼ Be*A)УD3N@8|5!K`K"IϿLXBQ-kHA::2< vshPZ 0gJS4AKwM␘cbT;g.ycvX1ↄ eWȏSn|v7)5IAcyx]0+tUvj?Q 7' T;jTTIRmiBE(()Bb 54IL!݅C7ՋP}JRbφ ` FqtŦ+l`'6pZ# 6~$hO_u7)'^4CS8 iN? ڦO!yz;^q*ArXrOt(b܁jNbs':򑟋JTM#{>+ñ K e<^c+sm%!P6e4ȮX7NO@Ob5Ҥ>L5ꄳ 7$1$r8&deeE͙jdOK[S e- oj.(? D3a-x5Z{ `68)͐Kj]Z0̑IhL:p=+?"U>uln'S*sCW*);s4 0ed"yL͏fQ(\J la,,jA߷Ќs !K)7'6+wqI⛌?./gfRL;no5_0a5Xo:s0˹xb@po-?:m1T[4iY"#TYWR[ &Ȕ mNvSn{On'3\I!&VOln1c6? ejLKQb D Z]z̲A8;(*Xz:z{n˗"<1A{h PJ2vn1<.ɴ;cٓںuτ'Gry-ԋH?B"5ݟ}#8TsaΣmR]H6r|RŨ0oa' Dzt;N5H#o NxT@|u:"i$)X#ФrqJ%pmޯUEdNYݜSY .YH Iլ>P)3&>!80=IkfD3s RI;]ƐgWga"gvG&|KE ?[؄=!>"l{=,U@>j;yDwV+mj2CP&aXׂUpX$}95oJ.ȂJ:]PTFQ("@ns8ߔj3#{bV\8LW71]8Jk +`sgқ1ց0jFH֑K$ިO\X pMƖ.: YZ