pki-ca-10.5.17-6.el7>t  DH`p^$ƨ>k43/+1o3qy_.]+ %ʅQE8$5u*Ra˭?۰-lܡIviiIW#/W]2ҒtEj'S;ߊ{HE rC]H3o̽!;>f㫣_؏0-]jJ^H$"En`@(C"w.6vesC9Q4x@Eb|!pWR@Ls3y޹m`r=8J*,MBN$tCf7c1aef2659b34959a861d1bb37caa5dc08c494ce^$ƨXUQH.=ՅE0ɐ=>UaLo;$T`>"woRH~!9^gIsXwr['u Rt6E&g+#wNO@,kE1);'Vm֙J$9jCHenY&Oa">֑{f{#,X QFjQsJ l'\H^*F{0@y+TbLpamEO~jh!6x%L`<]⢺ouixTr' :˓C]](+;2VS'ypI"%7?d   B        ( F L Tdd d td d nd q(dvd}ddPX | 0 (^8h9`:G`dHf<dIkdXm0Ym4\mDd]rd^<bd#e(f+l-tHdudvh wdx<dCpki-ca10.5.176.el7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.^x86-02.bsys.centos.org$CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m{)@1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~->E,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤^]S ^^^^G^^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ^^^]S ]S ^]S ]S ]S ^^^^^^^^^]S ]S ^]S ^]S ]S ]S ]S ]S ]S ]S ^]S ]S ^]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e10a6e5f84427dd59080c4531e9b593ec90a428b6dc9efe781e05da36c7be1c489341ad74a7e119b4577661ebb446d01817e3f85ca2f328d3104443a75f9adb720c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.17-6.el7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.17-6.el73.0.4-14.6.0-14.0-15.2-14.11.3]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.17-6.el7    pki-ca-10.5.17LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.17//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(}Tj[H:Z@S4%!1L&&oJti7h D8:Tuق읤]<*PZ4-`-ha8C|rt7DTkij.{M6{{&6oΌdCe*(a^.`c0ĸ`+l uJu~9V{lr 枵&gCⓂISv8Jo#$˹g9t*k⊂o¸Nk$eLˉ, пSZcԷ=XM=$h+&39ܬmD aeW_'58R sԉX{k9tϫ%YC9IUb& U(8b6R&YfD-Y# aUصɲ>b^6ߌǞG')p$r4jLpLfT bɥUœ_4w5$(<w]a:rOCaTz:c<^~HkO9}c f0VcnYhHKGkG~"ғE(x&?0*G J<$>Hq!i9z|2)xʑ ݥoN;&:cq"4cTx <m. 듫&KGygap[!X:1Ev 즪&!GSvW;b)%R?LTњS ݂͡ (eN ~w+Tv(>hXrE0"Y9EGq-Nl*+W:T rnd:Te5b>K_bXlz#r`zJA"J p u P99R DxD;|:Q&[WHN"t>bk֢*Hd>rbm P`OS~xuU-_|X2JjU_6g-S[4K]B`];'q6j[È )Ƌ Dc!y2J8a'T~w&WV[5"bTt?BDS$V !nf"˄{@/W"Mf~d` zR(0R}[x-}d 'Ϟ[}vg$g7} pKCD'0L= \B*95lж)fO퍺!=:%S2T&.EQliÍ:'7FA_ +5l),nFYhiy 3]oli񰤋LLr%aoxXȊ 2 0Њƅ˘g+| -(Mlm /spp\ Ѣ M^^AWe{(/?H\p5d6fw4!KBp C^3AM17w d pg<; A(u  Mkl/٦d3 @NIBFm$0R)pbpc \b^[zNyRV*xMX`[DN5_Om'}rJU^;YsA5IE87vRv :׍Kk9--5Lڡ8Q2!qMn{AqBۻ\+LJt6NB 5d͑ ?P]OfW^&{D@iEό?(55ۿ:S~q^7uBm70[ t^:JR@3wO)+цO!fl,*ԧ,RNUWiΥE*#cJwi;]g Ȏon\!,f]B"} ]*BT@P MR [^g|g/D/Omt,s'U]*#&@{Tk -DjkfN5}*-e޵d--1S]S aco7V r8}(<&(uiJWڇ^ gk/2I萏z'I˭9FDO` m^.s "3#ѭz!_nގ ИtFeUpy={9R>|UGPd*} 8aN}MzJBxgyL@Sb)!9{Z}x0H-- zS=]k>p~*^ O9̟޸aiA,oc+)(: @A2p Pe22"#"wcro >!{TyY+&rX6wd&bث3Z4^Y0FFZc,+nY/E^d :\N_t"T_s[ )Z >/ߨC.,]\0:[O ~t7ɜ5^kv$öidY49&SgA2/GoU)!?teYt<6R^Đ,Q&|:\+G |&{ } Q'c*P4Y8/J$#%_/N7R]sXC˵ d ёgP~iZ JުԫH gCob[I,tUI*<1nĜU> Θ e6SpFȚ,SPa0hZmOc*R*ه_⊽OɻR 0t߮pF ̯OulQ0S?XBgSD$CoݢKuMtᜥPn {qT'0.4kxK+s tDfpDq*V7tqY2MvU?c}y% w}đaOn˓GoWl-F4])jw K.~Yk? lty~{:`Bȼ:/Rv^B1"LCK%Ʈ950JUg}Ԝ.zX8{l{QBA9D̦A\s{].%$lf @ӨPB^2um'% zN3&/HKWU/*8 &Y6'0rҿ|$iY8`` _>DK\ݠcQJɪ G1"hZy H^.=;Yk4_&lL07RrW"8l*MnL}\͜А+t.}muOub-.4ʓք_~H$@RDyFebl@ ?aV>/wQ>/ZV ?|E i+s>T)kn6zY:ҹ6Z TdK2aGznM*)!5q=Րj ,K}itȢ \GEXҲ |v! 1y7Ҽ䚣ք}:ss&\eX}x.mxp9LFc[Aumx27tCG/;?J9CsEuy.؍rkko@88Y NR3\p$|^mAY:.V&<jpKo1A PvH%‹4'i#7Om7 k/t^?ZcrdeM:֢\4r[]탅R-("ΙxhN)TDw&5]V,6)|80{5+m9[mcVl76>X DHfm2$eL()u*} B&RWp8f"Eda7'uLqԤ⤖r2D2S n%9^7z[0[9P3Y=G`մurN&i_@{ ̑{v6.dW@ ӲA2ܳіyLȥ O!yV87cQb9dYPlsMz11x+cD_^ˢt w$Q5A! Җā<Pn&SLC*cB%z=.U;I<$7O8t+yxfeվ/Sk7Z5EXQ7pNui}^V+q(b!*G~S/܁Y^`뼌GG7t]czM8@kίu"5o͔fj=BQ"\8 4,C;f*GAP LdG83!SJ~ܵݹuN˓ΠxW){DsNQ CؑLxi% >]dH2+rz S'=fgm:T R_ϋ{#rwe/26UiYsFTuܚCL`-uu7ObDnw0 c zH`5 =n2iL#A 130tX4[1^l3y3nz"$l@b*v: #B' 3FQgH1 JbDuC]}qNK Сp3f~0׾A'o䔒~ 84IRШAW ˄ MH55=K^Ot̑qeK1?]W.2rQf *r u0 31г֊ BRna8y35ľyE36SzUa9˩(U%ɛua6-fa 뙶xQT+䁡A*Xݞ- <؍WKo46w@GPEXX2y\/DrېYFd~xue}ĩLʀhdDR;xc%A!BðPaT=(ML16ZBr|fوk^ҋ) zq)HG߫k1Iܫ)SSkX֘ ؝{|&GM`&-XI2]>D"+&-;֝?~"X_YIH~>їpC+)_Lfezo0"*1ǘI:Ä0Ѳ&5~֥!HY,_pbͿzHxSeI)*opDžs:t=u~xI6*9{8Q|s1lZu~9-bg.q"~WPxe~Na\Hĕ+ YP4HeF?wl9h)ioFO +%T'U9ݬ =گFOh<@aqnY6@c-OUn*:Ksx/vE 6RDG310LM*-2|o g 識'%j-`y86"&ԍ1-[|T`Ϛof#l|NDExL$)!@kgX.hG-G֋Gp9as1]bOVv(.5uT[y9|s 4_:K$*7/BJ}4'[ I'#&!r/">J",fxvi:=kTl{ =( cDBjNϷșI:;\#olL58h9' HkRfLxC+#9!aL/Bg@Y/5d3RëYK 3L)>KsZc{N2[2ݽ* ԣt"?c옱Do,Ph 4up {0<(&䜙 3ZPlfUXR(fj 5 -VF$4beLmqR}FLw~&UAN.ퟃ=ߤG@BTK@>%S[[~|19!Ζdm$#9a$Q>!pK p/9@xi ǐus_)+vǞNh[2UC:~ɔG&`` J̦˭n ֖ע3!X8e,>DTO&a2PH^gȰ6#dZdu#E>:WV YzW0ȿڟs Ȕ_w["uO!ɨLpro+˔Dm{@Rs4gj/TB>֥n=.ǐ wlnO&>So07A[$=~= e@GN,EcA?T̾4 ʺ4 X;m/q Z4=p*әS-y?B\x/ Ƴ;?Ɏr{Uۛ}F˛+ޭy07 v}E>W YBA,ȅ$:lVUQ.p#q,Ur]T2q>8in׮.a9ɴZsTHG33r[Q]5J~Ji9::6pd^U?(Xr+-;45[f$'B:h~7^ڗ&N}R4j#md4-KF֞)OIc[NT9W2/Ou_6Ә^'K:0Zda=L;,sd12[&Cx&8/i,xx z.f0LQF!폤%㦲vqsNirz W)vq7 Uc vnZE2f]8&`ۢ8QOC _Im$igh:8ceEii &fs 8ꥌr~6ҒAf 1E yz?efr/O}-/NI?iЖ<̾2́@'ߏF}ú]~1J֍Q.8ȊpSb!4;Eʑ9 "ȑd]@QebGfeFWշɍ+%)\Խyc#]\ qGث.N }9Ǽ*dMV4C{(-ϒF_'sLݕg:*)KR?[€(*nvam2,!;ʷIȝD_O2O^ wѝC#,4ȝ!JSͺuw(bH]DbF7|}$Јz-v0kA Tt8lO^r{Hܼ}VVij\"IY04IJoF6Wqi…n]]~K$)r}w} U6Ŏ7K'gp!OL5X{nG-,Z+FTɬrWzO@PtNˋ|^=I1K h%L" ґm NA܋oe]@((:H"rIFyJ(vUL1lmA(@l*u_2rXy):Yy *K*[г=3o0ĚuTQ*(nRJst4,^*ªE܉IV 7T=}m[{ү5*fvn6QtɆuKK6K*\+ˆJv\- L!_j !4ssi*OL g4ǕrI>^Hp 0lYgݻc6\LkV[)x46d?fzZSHR҉bȬʥCjm;YI[ mT $z294 ?aaŘAl UI3}Ti;Bq 5 A8vE @%<A^Аxܬ92ڵTw1xKqT<؁wRqz&HC^,P]'b}[/-:*VjA@y,l SbxoSACNIe ^lA7Y&&/¡@$cj l EG$ﰬ.5d=x2IEk؄=yk׼ sg'tM}rg3ï"VszZb ;_590{; 'ͅܕ4FܚYA}l4:^lƩn0Du\f4X;ZyҲ=XY4)2@%Dw8P9Z[ gaX qwgK>Y10lm1;G(BYvE=[OtpJ57 @|ؚ  z.yi;?NljI!\?I5e堉ضƑ1:C0$zPm.{3m.ժ"#*d8o-$3pbU|Q5wmɐp/>_fzlCX{#r&plOsU-]'BPKƣ_fwU y8Q*OZ7s#:.~:L H{B>l(NchtT Rx+a,Q}ׅq69; rBƿyd5'b{c`!S:='.^8ee}vD(|o =1'nzRr=݂D}hfA - p/;٘:ȻHi"퐹)z?ᔜC˺3XǑ*tOOp]1HlrqYzXmfIadUIӈ1H?Eٲ|]_„ ?$; a W\Nl|x8Q3D౛5PmJ kq8 :'-x Sy3I%Mj3QLS>}U{n7ZŪu ?W TzєdԾJm"֘B_rlK]LW 8_?YlR+B+kLXJl@rn&hM-0BԄH@O֫/AI<)y*ә1|-y bzCo}{ qZ 1('sU0?HC.o x7@ J*T&xj6+bhNլ8  *|$Yî/uS| Y.M7_(Bs1< -Rhɀ^yI#l"-geHZלZvrRd8VpeRƚT=jIDHYQ; R̡]*>QldTnAA_Y6%Ӫn_$ևBYbOܥBt Mx,=[P3.^1zR^n%U߳ k@VVmK^2CrwF'y;Url"PmAa5f02eV)UY93~HѧXRq>d=ڕyNgP=8ɘPɓ rÛW=nv_K7oK,Mpfy:;\̑LdrKt!9ή3Af'Q* ;:l'@\ee={nb~/dLȮbxwt'nu&oujDMR_:@Ofj*:I!vA~u<\!cNj5P[㐍d!?\$eЕ*qN?lI}֒ણd ks߂W?jH.&/TAV]5.@(‹&d ڹbJ8_,D2A/o)aڐT a= )cT8G(#ZO:QF64;Aeʳ>4=H:ޯ-~N4tޚh[}g'c`DYչ[VGr^B!@nS;FMzOwp:(+illoKUoW~" _{,9դKA#.ѦUrG%3PQY᎘g% .߄#MP5AߓwH3XQ `Jprڸ.i}>R{>,7Yd7<ĶX̮i}O#%/]+F;أo7M&sW jE1=&WspdTYFjl!HYQToJr?&joT`- kΪ5iA#ᮧPfU?N/n/Yև47ͩBSy[X8@ xC8ikP.v6C\V̍X(}B, ad(+o_%G^ *z>>(V[wgf`m Lp Oւ 驒C􏋁r> 6d!4D /bXIiXicHU+xRm\EO{f,AWj!9-^~ŠۨF;:GTϊ )-tFkj L$U@&Ea@9=N`H;M7mATfgfGdڟXz:.II$ K,W7+oJ*TF`c BÚX1w۶XZv1NY9VvǑYT?\3ﲠhâ-i`%^jK̔љ:߸-z\C{=EPdXQ;ꢴma=}2A|$eX@k`ah_3|Wǖr–z86]YAI@u ɜ^YB4upwfO`vqa\&aӶ1—PapL>֎S&{6&xI - rCy82M}!~Wa]qOo,ۜ6d_}m%/E!%C N|ƥqjW46`$k,P#gWߏ)4 烥3nWyS]p)q)b$_GP2)  qaЃ\ ~Gd0sx|da H,b~+BUWX#4)$ϥ!AMHҫڷxb 3d W]ԻAjlq'ʲ#o\UoTq]ˇ}Mo4 xw,91Ѐlx$6؉JZh$H*5v1[jdR&x * G֡VILL*FJڝoH!C!(*;>r=T! .@K gj` _hRe,tr Q-l)s-! v]"0NH/`SYQtN8ýLbjq"DX&":ˣ_>t+3,d!peV>u"Vʱ$' R:o^z<%v)cziCj]Q,f0dˬ󔫁 }RIh|5''ppLL ?c pl^ݛ;vtRԁM=ZM HĥBFNE}_zνEƵpxX s ݇hs!PF!:nTcJ F@q.ֵ `oQH'^:cè\|&8$ 1gpRcƚڈ7l7{BP0CYTM|-'Wܓ}g}YRuĒ3L3z(R0&F<.-@]WiI0 +dc9@H8Vsw;23#:s!PNȕ#XD`O:k'djťqD#L06rL-ZL"R1UapͶPeaNЮ9/b3zSnٕyǨu(_T-ݎnON/RUqVrS4FdIv>ܪ"-^ r"NvڥG±1G6ġi|A,/J`M=e|3"p HTӏױ@+(@Y5u?'QYU~1שkh1jY n3L|4>/,HdMy$GYٮcln"Tx JY!X-3M;mskf'DHOMc"&ҀD|G$DNЅ}>>PErB \ !,/^1c(K|'bGc hg<ƿ7F;q֣@ }&$~3gQ)rP-ypda$|r S1] 07#[Iuo/iJVQ$4&=gSu/WrUְX{<_yY7i ~@o7h>ɿN"S P0 U^D$-}VLR n4XMu6Q ۿ: aN2R/8[ 3 s2Ǖ8I7ZuQD8n|ycڃLLҺuR@q󭶽ls,]pA0*ӗk^v>A[/@v`m4b?.&ZT©ɳOP9Ӎ4KaZm<h{]^r:iYZ&9lk)〉C~Iځr-y>_3"v~v0e}Kn,HXp WPS 7[]8EUv@] cF񬁓 rǓ D"Y&l E<_)$b5.~iAѴ&\JNѿ{ @&rjU>ͽI"|^ }6v G7J0b\EH%JB=蠠N_w À wsPkwe=U\͝APc\σA3sn%wFɔa=X}O̔_Ui"P5yR-W-7Q7{s ֻtb!xP@'Lg/5p:'  NT$fPm4Ⱦu~FA4.r ~?YMjnoXRCn:ˎ̆1hhj^ǞT_X],^zWY`80ӡ!MB>jd A 4cjyf2r yr@s;<'q<YXy'%t JXM5^A; ]. heAʜ!W)\SzUM!T|ӚUQϰJ|ԝ ~iwS3vnl (U;0;WAKZ\0°mrr&A~/]m?ܢw1юҨ^@D@4#Tc -U T"=.X:+TTFKB_zP:E⏚#3dz-嚙AEd Fk-kA;55#Z e_e$ҁmpYJ/IWluֽjR8нZA?@'d;mp26 t(u=t|HW(qk-2̖Ob &|egd-?1,:+hf2衑~Uk*gt[X(;504Ruӭ$:@0>Ee!&M&g|2>&˪}5'd 6՞2ɽ:UA:<3ѵ熵D,>+6-P%ʋ҃mI7p#&7,u,*&g}Og.0ouYBҀC:6OG]jՔZG6)(~&"WMEӝIȿQ' E!}NYx-ll- ͅY4-#&&A7p#$3D}~1 0=pl g%EYP5r5:QPo*6AbI|@= C; ;.u Gh=*ڞ2`BT\@.U.Kv,BFL4=o42W}IuZthW6A|\O(B詾}5.Gr9 lw'nP"IV&kI_4F'i5:D'~?¾%5hj5g8IqޛEXٔ#9iʈ= vJoڈsG+W[j 5ԭւD; g^I,>GD}+bJ\5 vI+'%} ^;j33lGxۢt03@lF,_>%X5XQ.V&#+~X6K(XN ,:yCo%;uW5UZj}9 )iEطo\#_3WXlcB4X>m`v2@_?d wa Gsӳo"1U#y颞0 i:}qG&왵>643Ֆk ;-&iMy)ZdʵSem%Ӡ@?քRd~'izrOvkIglN?I arI99$\$]Opbj*KK"TUȭ gǴ*|oGB2>/JY=UNŏ85U1b4/:Jmg~Gl(7g{ <%@ȜsoX[ 8Z߼TnJ |~NHC'YI<00 # 9:@+ i2ϮgظߠOIe:Jxiy%&9O{SͺqB{x$T$Nӆ놀 ת&~4;_ҰhWc)~23D4,Ѽ@afA2"|EvׇBͭrx1c{zsp+@ LU3OзԿ$o5}H\:x~omb&(x/^#ϧ/[:WgAr278V6 hg:أtw`KzWl;4"o%~;4vT A_8AHp̹#~F u=2pK2)>+˿H }'肵J/[ay15ZDCᛶ._$կz:xRYGf>q\Lr!q+G{,BLqT}|b"`7D`qs 7Y> Ased"Ue3 4v5Ag9^!7M}f[/# a,C7`  eRT.)6W62YE3̕--E{ztlrz'|W0YlxPUI`:X@|ql%|V:k^ "1,lC%GNT`F#6HҮa_bǁg3ggzݞRgʁ!gpPϴR6zonzb@(ĉ ]{VXb}_POfx7,"eSE- T)?~ `Z6Z9Ekb&'HK'%,EpJ s(Q|4r |U85fyB%B5=h.w?|w*[:au`ETkؘR?l_qM\gWbNf+,rJ˽"If]D V% f.RܫTnտdc5g m9=r1TI,mTMbQBWچ#Ċ9w@kU#Fe#NY8MOCYoDM=Xe(m_@} `-s4DPPU[>@ɿ juSYLi>S":Yn&7 ʔ'9D_AYB~+,[ysh0an}Ҡ柈dFM4Ue&@!%alqxRGu)?eFZg=w=6_HI]}ԋC~H ޼gԄx3M7gSXT 950?.'2G7u"7A:!4GIwOBP7߂48Qڬb.t,DM02rD.ʫXqT"hۢ P&ޤ_>jRD "?l0(CHBԃtB-_z4O4r2"ѧx[Մʼ_eu-K4;2vja6 U|CDX\!Xw^jvIb[G]5'h#CQbneqJ#+#Cv{FٗQP,D:]h4j3>G<!~{N`J_ Y+ʭY"uѨN:X6JvPT vL3T .0 .ΙORSbQkYǀ X =4>|zw #cv.; )DhBP Ba[j)m H:w\\{:F<HsS+;4jM'n_i|k(Nv/)r:&'h^Oj㞜R+n;a1wKo 'x' 2)~QX;vR%:]V8oe@a500).H0?(1ݜdEq#ո:"[{C?h0houCd0T 40rtќ4yXF覆sE0'_r7JϝTZO}mHnQl:)bD2Fp$ rO SznmůLrTG =<=)=':.WBv_z;4Kvw8V.]cwY~YY|aAӓpXiȲRvh,Lmhջ^ɾol ?j,wcˣ4T BW"I6xPNƽmщ֓8ek!7di=PV~ӸJ:5g%3A'hX[.LfCO_oĶ0S)Qv둬Jle:uTP~cQޞ#T97X xŵxUu)DU9MN&>vHc$=d-.nB[HDcA:jpLD-=7qCi.޷7!,G]#C!?7UͣY D,W4΅je$_QKxk' &#'VEg-SDHpC#;鳝-^]zXWU.XTAU>sqH:·J=H?QTTC2hc[tBLɸ1C-DZ ެ@Wu)i[כ)0i6Ux~%iy'hTUwZal'2ӢP+s_QiMK=JW.]r4H[A /U>EA޹^]%N1e&)FSad1Z)[μ/O*By_$7FI1un.v8~~J~J @}.gQ E#\y"dX$`]5$8߽: e" (7]|Jdܧ<ҠE[+9'(TZ Zn'N9W^^eチKZ4}wlك -Zr| @%f'ޭN+ w3>=)mSC YϑJ,և*E{1V6g=zOCöu'BTm0&1g=<$;A y5lZJ@ #onyU ˁC"ߨ~ Ĭ ]C0Q ؗ;S*D6i`q;Z.ẍ1̀< ;'_o.9脄xGXQhXdj'TRLQ˲ Բi}>#e!#-G3w_w*ciYރ}K΄UO"G KS|](mW$ ƅ-)KNSSQ1C@"8Wi/Sv:m5C$=8JxM*4ht!K\YhGICbER*y!r,L6Yuh#^Ն E,#)5ƴ'9Zts: D63Zi׀(P3 ,v6 _ۯ~^N,|a(U o[{.7СBRC2{B9S#6CI AHQ.gX:]Bx|:n׫ C h{fL~ e`79 OeU|nj [دhF?w"xE#ITw}2&S|Z:fkzD :sH0K*#:9Sl4 r4> if/dI_#XNR+[_8ۍ0H [ :0\9AUf ˆ6TNR4EpqZr $6 ,? 3hկ8Uĥ]d8{kuLVMxbOF2$Tl\S.]9TDQ%0L/?HuayaS%C(jPp65'S[ q&ke6{na4KxVdFF?E7y}m3Oc%26y*Nrf968 ⩙K_k:$$w]1gX-Js!vƱVQyhMf4K'x0",gB%}u2# ]dHȉyWSs#"'ľZGi9c 0K*Σu4!pd<,"-d풦sVVR2ϬrYW<$E{)>raoUvC\A33S {hzavZ4"TD?))4kG7 1Q}YeI;>D;Mya|K@sVȣH)!i.lJ %.vӴL5eËY+]Y2$KtܙOCc4!#I[G)Βl핋iHV= e)0M4T\0EXJj8GؑKn՘j$gf KE?}RB61N7>`اz5/YWI9t@ʐE 1sw)'K*Qыi&yøKu @J/"1wl*âС؎k8VAҜ=8zYHDhÑ'˝W_gXfW NS܍A;~Em;X^>j*Er+vL\:>rgJmc6Ιf@I r%akè,C`Iӆ$&G%t\2puZ t[[鮶ymBd=%KmW\gD c]}j͆Kz9LזABM=Τu6uLRcd("0k1s@T}wqH%hyENtcY9VE 6jkTJKLYDW<ԻbSq悛OyBNDy!brhyc Y M\[$ Ѹ.s$2vjU1-B)FW`zza $_kQ|pGf`&Dˏ"nie1PԥM8K[(ƃnh{v7* GT7%=(Vx(`aDdA"%ʹl z~eyW4?{o(Re7D[^GFe<6GAycb}r"Ʋy+?v5WEN]kJ #tzVb.^QU6' %NT'2M$O³bx7nmF5}:rrp[_\LȎgXPX߱:ߝZYH$x9gk\-|2TE{֭|_AZ7g HӆyD'vWh%'tE/fIM.n&̚P.kn#dmoԶ2FHG!oL`47vs^0v/<6":rC~VIO7<6w[Yw2 ƍu[QtF8!{hJ=  Ӱz (FLe=q lpù1^ysś2H^1$Ft#HK uBp M:PLM~l}ө4gn4 xb]>{f`标wm}vN P‘0gOmlk9=z^4ұ.qzff7vUCB 7Q Z^EID;#m-d/`vYK휴\Ǻ>C6I>Sݮ{#w'>\&8t ;߄h0z%i ,ˆ~gb<-۹5ya\MCF2bx uWHU3 /Aj.lMjs!{LYN> <r5WGh ø & Zkp !BR<r0<$M_=)́tKD/V͖ :tz_:4y #vZN^@ܞ9|(Ĥ:voPԁ>@we{H=GJkpSmH 'e)hTS?ukv )yASi6mfkdܢ<^JW>:% =U@!>^>5 -ܠ!9oWE~( m3tG* ؋@O12 gktpmoё@Οkx Z>Qv+xRM^qeK(i={7b9e>4#9b*7EE /LE׬wZ TgߘzIU(V".K: g,V:Kĉ%m7~Ϛ uI|H#ƊbyTCҾ'J&k x:8Y+^]/saPGzDu|LNY4&YڙªiwxKf:30~/KE5Z ؎tHĜDѰ]dA1!S5/Z87p,g7Xr{x3ɪ:J(ke9n(LxP2G4GV$q9\%]4YIz☉*2B:.K ]1deg,b\T+:@6X#ꑒ* ws < !,?c[xA}n>vx*۵'9>W5&c5CMpq[F*G/ɩ.a@,'uC0A'ϐEfXɩdTR{T|: 9܋7!TFNG|VtMF.?W  񪬓ҿe{]6HXCvxTt>'vFkf}tK9Ƥ,QdKܪd8UЙ#1\c z`:(G9 g.v\Jʮ]uhe.x5uÆK AbHi VVv*wVT/[۝8i$(9Dp[U^X]ɍgbex\kL=]eI$.#H:{v^9UD*,(N'NQ"J;MꟀ дCkALѫE !eZj;yO5,v5aR-Tq<>%>WFR8"G9W'S,UK~!,/i@X0%Gt$(0 .1ZNzGJdR:zT (F̖:dB*I_cM2y@+@ vY/J5[[L,ʫyny{" $֧*[cg N1ƼFKB;v+Z..ؕaިYۅ;TbA[tSPZ]5N}J1LL/a\VA mqP6W*45549v rIdM؆ta'GjŌNW(>Mv%ʔ@ԛ܌KVcIxHx!=~@lI0Ȧǚ3bb_ ssu4^Yy@yiZuREv5,U16^p%H+ρCOX#R)l[qE}%w[} wSfCBXq_4B LւU$CXBV aH颎<ܾF+Y6U*xG1˦]$a b9oVcZcιW= `޲ɭr= =zb]:-}kKӽ0c< g[Ȯ$=v;m^-GOmLzgx"0BT \l &:C9-,B`AK4tڪ RʢDh' (uא ˔>̎l+Ч":^1a=Tx>'O!zK' CXI󃻰iKAM 5GZհ= uT`X|:z_B%!ΌUVy( RCK*36Ugi젴CSAZGsnre;PH-r^ B3stMyR.-EdYEv]Ӏİy*kqtWʢLwk<6F~ؤ,Z3ȫ8oYYj`_} ӓTYjwAr.jCDW)㭢1"$괬3O@%/6+2OԿ)pD(q&E,04+}OYqS"ev\@g7?ZL+š nLN$99xŽ:^o[E}ƚ9a. `a 0{m"g;8zW|V(t|1/ Oϣ5]5}Q6Sf.Bz[ P[ъAt$:ۼ"Tbt4y#IiqcvLӜ|3'7č3.6!ِxVlFuuDdl7|V1HF9+O]:t" 79ZQ~=]INiWWY':?P:U{)WDkt^6 -cBiy. $bܛ3"m:'doѿr XȎ&VTEK3TLlj ?+Z ¨G rw-gu6r͸ƨb{T3! #^ }xJԩH `)`iX*5 @ 0'kz^3ILrO_,<޼/kr{"Ns%k|+d% b F",Q}liX$ QZnf;r3ׂ$ɽ|ƒǴKZpaPbp.FLڜBV y<=QG(aXZ{ oc;yaRn[UzВS%Cn4𖒪 62Yq e˚kcE…E.>k,D^2nZ5qӓG6=mЪ֪rXJ/ޡH1J1n}ǁ0\)Norai 7V+Q21P]d%M|*}Nķ@-Xgr>\*x`" K*,%ϫ'Er+tL,nԝ&WLg @;)tCgxC .=MWNQ8nrMZ}P::^47jJ9e3_1|랯_+`;|K̻c6XRdDN>2ҥ[\0t7UZL)"AX쑢}"+P@%1UKKW^WqvJXBzᾄ" h^1Hwcׄ(/9&"ӽL%uw(qqpH눀Z|. #|`LMdҹX^=< {Bl-.[Nr^Wg#EJ0Ѩ"p\kR̪kgRgbԘ}5= .E{je yma.ķ~~ %S~qP^lĩ64w N#΂TOR.5}j]I!I _c! .sUClI%36iU|P4Nßׄ:$v+G_]L"d/4K=dܲlޫrR0@8 ;t +A`N$pn,HM/Džʆp5~>U2LjWO_[!Eq vyBdMhT3w7Vw HxDq.#̀*ƙK&n$z3|0RIzXG+#"9È-uƛ)i*΁N 1<:Rz܍qшůLz s8|Ct<]> 0ЦJfKt$b88sKn-%-9f'g2@C.hrF%$?!^riN)ѫ`Iܲg ro 8X`Ǻڲ0e_>$=)ZUeWBN%;hRaR+xr0N$uL8-[+mKc|K< eRȆ+%}ߪj~m\+Zǖos>;)aCI<9-W#ֻ6ۙnr* oJ\#SFwO7n3?2r<3BEoD^)k,' ^8龐dR|("z`rbhOeh#Ig`2SfA>ĪEՏd_%:d? Ώ<:']B!KbތfI>>dHfr/VGxŒr%#wMs+yuJ~h &47hՏPUss5^c=W$9 UCcb0WkrF* Z'= 9D (Na}y _:zQRVSْ>aTU- TaWKuǏq}N4)QZC\P3;ɬ`װFSW/\>94_;!#;GPК$ kVR05~}UW1UG' P:^[AvB'2u2?Ż@;gwX| b19`2k[ ?+5#i u_'%Id&TdT*_Z%e:- 9 YPm=ӯ`C)F|=R +li>ȷ4&7.J5JJύ4+ < #{PB9ioA=g{b#D흳Se'+`1qGn-LdωkTe&p Pkff{5gyRnW j:pkrǍt}ƮgJa v?)% K*QIg?T.B瀂 fթ,ͯ5^9#ZaVUHQW}A|Tڻ U<Нp$)Savl *rp(ysaDph uiH`S4a)$+ڌ袭4f=c7!pqH9z%?ҨYݴٞ-Qk_PkX$w*tYᒯ-sf L1$I(tSWQ7AlEnLw8orv垬cbihF*"5zyEV\Ĺ3ou =FORMD}n!6mOCt>W{HFH.Tw5aKU/6,3[{O"JX$!]yM:3tTVj`=ҰEzU%7 k~:4!;6  fC*ӄ!޺=s zsDxh~',cf4QCM7EMVX36A #x7r9f~mvluxJСP ]xv4[C ³EU`f }5)RU[kw@ A,YEqa(zzP({܁cVB}Ss( }/~&/;!4eFetFJgq)>\ -6^۹6ڤJD]K :m,!at/PcݯXXA2>Z Gya ӗ˨8UInn{㞻!OQ8%SVǁJaqø`é8}shHHEb)(z^"V/"gH۠L=VqTZtcEӮa@3qq"WGybBoJ&qka+w=z$ |ۂ ~LE]b ?6㎝y[I­)C믰/@أ5X0~ph&2B)23;+?=j͢e)l8TT!щJ&u\k^汦Wݔex>ș곗Q.@Z9K' u3q3.4^{fa|f=2 mlPEڎx{kX%;W7gZ]74t~1i"oJL@{]_F P6ѕXVF7MDn^o 0sAz? o(wo)?3;j .:^ "4+dFX)QpnfmgNvTsoݔn*{gz"WiJ0+GV#չk#[?h]$9^MZ^:O)-6茣nꨖ7-w?<EK$CYQN>PT';t&<ڗ %'DX̕S1@x*[0sk.l,beaGknf :.)QPeA)xBJUF\kHd s+\6_#h #u<346eԵ91]~1d!`IRFzSrP4xOONg7bejOZkDW ؾ(F&6(g0w\ .^ /Ƴ_sjZ!қ}`jD,7ê﨔c]ď8!Y>Y1Hh:p ~pG-k5JΨ:`q<Un ?sL+8hlՔ*-*z&ӕv ېJcS+u÷4r&W ~PEsy8aLL ,?V4l$w|}BS4>xڥ^bԌ23EON0'f yvr3`&U qAuR|$ +"}iH0NcHݯdFI> _U &v'BFw" }po:gl]t|LCɐqm uSgcY!rvL{)Nƪg+  MF^\Š+wt4@TlxE 7J'x N~ J1̛E~يJFVf6hf ht5*&0%CG" J/ PS֬˰l;m(foUYl\Iپؾ%U1VhQp,gd nj(nnE;"9J\.q!~4˳\r2t0 З,ݐ4j/km?;/K"c`Nsum%NvrGnL:): Q#p`h[@3 `NB', $?w<`+%KI2ǧ9;'-lN|v-ct=<.%פ 8QDP<,(R緼n#)E_4q CZ!?vŇEkJu8qo{o'NLW>٦v.UrG5/ R]IBJ'iU]9v=3Q){kCr;OcT>o霥7 >S|Q1R@!i<ӑGVnxT ut}Qsp'MU={b=j:f`7ϙ~.Pk7:00(HֆH8FL|xgc)?V3W?u֯ (fm!mW L?veoMJ*3wNa{ {\Xt#CùMpb@*;΁ŝ<%z$\u7_dcƂ7 2ݱbm.`hMUwY;yYzC-]4+;rq|~2,tsDrQϗe7xL~NZ::.V޸`HpډxL]7C-Z u2\&_܌1HwoswNg/;",$=d~m> Q\ SZ^f"ѥ!6M5{HLR%-#wDPgWRH48z4A1Z)8H.m3t:;4/|‹tWB.tDA"{wOtY" .CZ_7[N1ɵ#hV_RHԹ-!w]mm"Dwp;yMgo d/R,P&fOS>v s}=4*@|H`RPAU_=8F$40qJ E|}E:Yߨ#1ckeτa8Xy0f x-?QEٲx;r= _o&xPCI8|B!>R'ٱ,sE{фo;sTNe=4 kLVϞXg1Y8! g?N%C{!tXITٺP~VHWhhex/i~! Vs0|jL^eCAH5Ov YNK@t@3(+wT 1qU9FvڱD; R"Ւo_Tе֡j;"$o_Z$ʕT76-XlJzPڮUm Nb"N|Ϥ&)..Pkق2ɳG9s"a`Ә^CsMp>.CibOwrhzzhLQVPeDPuF$UW%a|v"aj%)J&H%bXZMB(8.=»t6KÐY(>i1f#;jz!lR@s9O3'm :qYz"%?<`>ĭP#NhkAgd1`Sw0P? {Xg% 0,`?W3SkNYKޱ|g#~TMcF5&<4!~&A) 2Jrwwz@4J $% `pMkM Nxj](c0׊z #5ga!({"gr\xuL<4] ye,2z4edSs<481Ys ij#Kaʩ yZ -(N]qH%cWPS {p`{ H`h1tK,_+)d# pD7"sZ$넶y’Rm<-vwǬ%xsaD;O&|F0xp3BhȭJͰb{_P6Utz\"XĞaazEG={Nu"ᦥ-?1VJ^)*IUD&WQ!uA6S3uCڙ]Z}|%$bTT8(S*v&UKAGc0l>LNV>)Ա#a,R0) )N3w1B5zZLf\2f/Lb[ ꑱdhlٞ0XF@aEM-2:N,vH^Ӏ֋cN>Ta$H;CsRWnhEW~ai_ֹ,@S ǍZd"ɝ}|5b$+'n[Υ vf%mpu&m&uSGT Qbf>CZ#,7&YP8ڎ7Ct\( B#2]L,gq[_yby`a5Yc%]y46aXX( [\f'㰝"^%|_hUC6:4" %0O Fnj4mM )5*3tHXX3 ip\8frS4Hu묎jpX)THű]B6l?B3Ԝ&n&3vbwWpxF]g 8ԭ.Koϑp_>غ!E녏YTuHCҕ{&@nׅQmۙ}Z /MC UŽH-ezdB'^CUN^ p]7wE$MiI@rRI4z櫓y;ٰfKH`MY0BلB( wj]ԏ// ˤGK[}k6}|=#$(q|r7oEu56jњ5BwG|BGV0gcC)Q9͋/7̛CP!Әm8ky%|+e4b*9X[ +Kf^W"K ]jUD7M!\ jvv+UfYO tta7AHzzZi"s"[TXPJHqܮ%GqPSh >1Ese Ge'v/B'/Pb{%/G{M˛G2e:ns͖ #2H'/ _bTs#X9VqagW'~)woJ"okG`6s%atקWMƸ"A&LK+͕X}yV*uI$U;2fʠ<QokBl赆E17m)|N.o8HZwuI玙e1g&b"'LLX-\o_pI[6A[#RsLg5;w5&#V7:Z ;2q%)O43 ,j'RFfdcw8: M#!:Cu)ÖnP y@߮ j}g!]u;y^;, myB;l'nx"  Ke)d%w|r l+9{6v,b (q>~ŶQ`!PUDKm?1nYcJ قa&pWlaSqU܄T.L`%@,@Pw#.3"]h#0ajzD۶"\ϱpoCU)o"@2A -8?ڦ h[Fvp:j"}vc(6%WiV/cxߺa\IQTDLP{`Xfz[ vB^D rX9F04hTo<$X/朗C'gEd=6?k[%UPڕ=̮4]-#Q1zLG+lwZJu.PX!31-O|*E㴘 ”B(FJK㳌F8.ÁcX o字$3O>h%rtC4,cbE'J{;>#tY)Po]im`;Ǹnl]'䎲7#ᝰ1HIRLo<.L.Cmpnc) dSJc Or&zLNa%6uHpdJT*".bE65اpyZQ vdˣ|_:DtK@{:qHkf\W1%o 3Lϓm+cGP*p@oH $X\P$x+'WJYe\Ujȉx} ss) ;D_9"QvRȴDALnS^#Q ɿMA|jW?P= 仕MX()T2^)S(C/ SJ .F<;4|;ZӥL}ھ[7RROgVr/+ټ0r#ÊQ*Kyv{Ox}KQbla~Dڬ}'*Ć I.jP~Z֕2H˽qziO+wn#5/M1D4*"ݠӺD8BGdU¸E ,&r 05$qf yNRQFG_KC\~GG]S9O 88}XπJ50n#[+#B]7Â_LEKIpbz'A"1k!qQtѩoi "fӛOzpR;- &MB%tic{yxZG0  ecnfV;ԛgߑk\ Oߔ2?|#mxDO/H3v=%\xڊAk<3'ݞ7֬k |q °PH5* g}og)TQAU(ښJbt5A=)LѐHdOSPZ0&)V}A}i'V\tXdimdW ?e@%+l$B,]! !U EIw;5M\3]F+C5qr>̲=TLmT1&EFb٘ϫ8F4Un~n]&q#8h2;,Ps!ЏG*` Sԛ3)=KXEѥH 7Sc*<RP6\ 15z_.5ч %Za˳TJ.NceBJja1 :ڊ|G?,v"/K 8l4㙣T֞Qq{(׌>%4Z1muG֡x$gY ([Ecd! QF|#PH#.[!΅\Bt&꟪>_Ws9a.d0A8bH]&EB1N '5cڦɓv J_ KE{h4 馞@:ys„;p.3ɜQkY KHE,55Tt5 -䧱dg|-p>iS+ .g(eP21 7L~X%}ymY41ړηhiŃe (+۪J2~r\)R gL e1!.&uroq+ {3; E-FB3Il:~~9A˾X-Y(lxCR-`ųvTNO̦R_f-BVM-ًY [*/"nLz$Z$dwp&}L>+\2̔JMe~B Ѣ(1OvdK^~-Cz+A-\0,; XJ\#> _ $S@'/vŶi >Ga'T,) P)4;jSOE=8,J۝ͮSgt;k o7C|\+Llo] { ;7ŹHT3%S6/!1&* 6[ڗ bc ksxA<&z̜\^U0r -c+^iU;a!lupkAm_ ‰*)w)a$%@@I/}1;H'* 64ׯ{)d}'{0EY;:c#L2 ]pwOkq.Lhm0=^9bD aOo@;Y}ibhuQ'|3W܈.?B bAtI9FmUIWruW$4;笒e%RlN|U=>έCnf~5]@plpA1JqzuaM'yA,M;h5ms0Sa9Rv3`EiPET2_bS4!6#=wuW#ߺ{/l# ۴D 2?4d& jc}&a"vc{E?F~7 >T[PL-|9wt]ܥ&3\ԍO6 m~YyQQb-(Tc ^3 SUg.*dgjI">5| }] s:ts]1Q [rq]K~Q]p㼼h5h<\^0])H}Rk?f: aM$({l}wea V̗YP[K^" 4c&(&.r%ombjnƄ]mpT71spO:\1bcs%$L_g\Z.>X-vܑϻHvd-q~#|+w=nĦhh|>7oo\Q=!\srs}kK#]f!] <w32 zӸ K\z)>1؂ בs0䌝n{yLgT,Y:˳:?9O~ ӥ 0_&j6Wܵ9:0X=e\|GU{:T^kg15Ҙy^"! SОTH3mt9f*2^t^g Bru`pC Oɿ:\gI;l֘ϣt/o0Wߖq\N`5R/{$3.nsr|%p>f(-V bɭ0|D.0{D9]HΫMxQНdR!<X_q}d1R b`ZJ )x/T瀦 ("8:Ue#JUFH\@`h5 BoQĀqvNpT,JGsPNU{=h" fKKq[Yw֩;~ӷ>e#^3?&fMTA0a{'S J(Zng^9Գo>/O)N31-q|_AlEO K oRɿTx̪Tً0b`|3m:2"iٜWAmWMsEa$btO-t[=V}.`R> !9:LQf.pf~fX9t"3wxƆG= j+eOrNBzǞ9ar8J+х v\4˫eRs .:8IkNN`I{% E?v[RX1ߙzU'_8>ZwnXШ CjPA80,{շMC@dCŒmy⠹GȲRk_|0`]]ɊE5 I\:#*? 3"nNr:>t8U93e} 4CC^)YOWfz%=hE|[ZvCԻY6nI?>&J/?w^%Q&\꼺؀G{}m?H+:T3L6 #W#ᅧ 9H܊(}Eɜև :_司PqnYfAq|n;MEGDb :m-?-HgBom׳dnci+ز'=#պ紗b>s*Mx7E+%e8 nA4 5bЍGI& >Cj̥EcYx(p"8RO젔PaRkyPk`>60nD2Lw.XI#Eyt8;\@Ŝ,0.Pr omA# wH2My$k2 Pi߲w ѵ~D!-Yy-v_}Rԋ8HhYr~}CIqf;x5豐qA O(pHvXUZ2h#mt,Qo>-:Ϫcף-fK V?O Ӫᡫt>'v; C"dê:0xXKJdh3O_lQ_!B)RRc5g ^ R#IwYfK1(35e֭k, ݘd⇣#OLo}dnU%7T@adPlsFWhFs!!] ",ǖ7vI-~/|:>۫}<^E2LmyY  #'_aivÈ9 K-W۝uG;N 9 dQ AQ,YџNGОn(؇,y׼lu>l Hhx(r fOr?o1O~'_/BG-x2Wc2vQ-v_ӈ3}5O–t[D#RrJ o# wZ "su)[PA,3?͠0:M{ I[j|yPLPGAˬ[O58[8ay1ޖˁϢڏNFc"xA=/2S]i'4oJ2 ŅHes7RuW"51s8dJ[ԚE" z-Kj.,LLϺ!'֗*?j׏s;0)$ABкd]%7 | fg xc[C_4btUw(>yF`q<7(Dqlghy42]#e;E7P],Tz c<[[>@ dv7fۉ}0л*tp6QS?=6*a[QKPł nZӸl0bUR0f-Ί&Ϻ?7T鹼Pˆ*pBim}ҢD_{אeP 9p25*ZUު،94! jBGxpa})Y4R\~kbr@69j zIf,B5yBkDYI|pue"HDHno >*%X]>N q̈́`_ NpY3^agzbAIBBxy׎y]4kb)þF? c;x%qKg^mjin;2#u?nˬH-J{z>M^kMy$0ޞߧ̀?bF h9x-iyǵvVGM N5mx:_Wv Ȓs;֏㄰lǝ[H2Td<:/N$@a@U$-sZF?JƋn*6q׫ 8Ay|cԔP 0|1gbp2/ UCj`g[ Hn64՜#? B8=s.k}96 Dv 'B|iӉ j<tFDC~Ih$..= ^4yV8_jo$PNGo鉆#ط&_@-]l0~#h%Y(uGX7I(ľ_>:>+)q崣{C^J>Z>/R.%j-ч?ynI4㲇Cw6Z< غ24O|&,n)ӈ9Պ'Zմ"7gcd)V'<|9ѹ9QR,n3qD2PIGcVS]N= A _,)nz\RKGu-0XdjEڨ7бl,|P= l;K wD*tF-PB otD~AErs!y|a[ CDx'&6QVаN\֤ E<8fj3AMWa*͠7~uR1y+k쀻1u9|k8d7̖C_r&֦0D[LDvUrCȨfRNxt/Ɇk抎!L%[Uޏsv:%nGEhBne#t0$i3Q=âs<Ľ}+u{A[q6cLmM8k]ZbSx}hYL&˩X}@P!nY?A%P8ʫRP!$uۅTZKf7JqtXc{8vOq {ʒ c龃SM#P%r1|!UWP0i ?ˣ l\b&bޕ,DHףP=Di@DTpԃ.TmxӎUjI6nY1!=O!Y\h4npI jv'%Qx4qˤ><ȋ@I_92a %0&T^짢D g,XXԿ 3x7D$zppd^QVsZ2rpMt""")l0)0|mDiN>P@MdYc>s(9\do%8Eش Hw#]t+ιfYs#QB/<hmC$]BvPz+w-tg"fRP?HJ.2#{/$x: MfHF!!/^h.Hv٪ӖDhour%uI7R_*'o+ \'',[b<\|՘ XfJedR2 1NHӛq~:W ŵl,8N,)Nvd" sv~ THhKE{U@!H1/4AH, `Qָ15B^CHBq#t77fPh.#z͝f8-)吊W!b4a*ܸ$1BVO?]=TrS;:#+l[~)G 4K]ZTnF'k%!GT;+C )uSLF [8bѦgu(8PII%ſ m3F>$ |")3j7 Q3)ҧ[/ÊN<2=n >,-'Rh\8#Bdgi}: ͛S Lk^3`[!'J3,UDn}9_ “_[~eEv\J,ҲX"A>. ًKֆ\O`Q4\G kʃ.LeBԖ_ej<`;vk:/eZL!Ra,b[x I|p&6VMLeu$M^|6uO}IG:瘿S9 ‘kuC&%u0n/cZb n[(D2边 6A_ȷPGVXWd(w)W8/ny $f'RE}֌Ś.Rƕ5-jVG!89T :݌D g C…~VTw0bdϑrd1J?Ӷ;!@Gg%H\At?c @jSh…=8AjzQ 1iRKl zWHF Wf&'kVPr<=bm@5!L.Q?Q^]i2C 09>0j$v@ϑɁ1[yn &;:cp̈́Xi  i?9xb4Dfq0w#;*4nd,46uD|xs6:]&cy<- ,fj\h-tTۤ; [.Z7rq=ɕc,yyc@ Qً?Ly5ݘߟtM$:U`2|vb}G9^^f D5ВtY~"eP<3!j#Ώ5:ke#(XdT}UM[#deڭɤ6i1t@!d`P;ƣ6TfV+ ޔUjڂr NY֨e5Bd˱7=)gzTQt`ê6]Y\ }<6Psy-׬Fh8:3G0ߘZ4/n9Q@NrJIow |7$I:}OG({FUXU(c̈́E(p?m]Oj-w7TAJd{9,Zx0 ;wBC߆ $5Yd>Mn:>KEJ=⇽d,dk՗l杢edz)|ZNO9U59">:oWQ/0FZ;0OtH/wRnW &qPn< 9E^| :W6źEZw4+-7E9Rgh ~6Kﴧ92M> W*0硡9Ճԕ,Hsvbo}8 "W> Kb*KDql+âU"9;&u!a\WnٮzMH07U3ߖRFe7nwD՜Mp'R]&fg `x~rlQ}u$ut!U?2 arN78e($/hh(IЗrMIq}w_I!w1"k__IBSjs~CmAG^K[-2,fG[w)].3#<QcDK* KAeb ?d:1u0Mΐ?z ] FFy|;tjmoÎ{[ãh1tmzq PБea_7B܂33@[.yUG"FLs&bk2XG] vc#^cQ[DwoCF.ID}Ш{:]BW(rQ9ר$7Emto֬9K7~+ӎa/j㋋uČq@f?}Z$A&3ۺ3B"-).V)+=sG;a0Q6f &eDZy!."TpUJUu|jp;B/ۆ @$VؼR ,Wntf2ַ{2CD <Jq,@Kl;Rnp/Z-5?~{]=}2N4h8#]H0r.v-EG |g%IJt9 ģp"Va?-Xr ZBC?ru%W~*ݛ ^eUyqvOD(: F`T?ncTŠ]7d(\ʘeL/ZI> IԶrx r>r˒mQJ1s- ecf@8Mkp.(FF( GGL@!`sB#odDtin*2M fߛsBgArMXJ +mC%ހT$bQ*h{R8=nR4E?wA3=fBrue7JHZ( Z|#x#pMa^vbє#VHz.ͮ2u O^:՗=j$R5H*R mfx%ɡ@l\~C-:0&%^.$[g(H£) p[y ;+aևԁ_s-7}kEMxk v3ɂ;q; zBTesiE!,X ]X/5AGw -{s5ꦍAysv vʹ)U5듳5Rr>#OQ#hr3oS76ӛq΋X9=9 TUxy@9f-"Mwl>α.yfNZ%myu;M{@204yyn _ ?EN`ZЩ7zd\Θ.V&\9{1 H@y㊪rDn\"bX ɂfLv.e+/xY Ux£͕B*]UBubZ:] Z~ u큥[&͜>"T-yA_-5XPi uZ);|OTUJvq,Bdz'Vy˜G!0s&1G[Lɹ}e6vBZJAP솯E!WVB_~ڳ jPL _jPг|&plmu::X(hVfYZv4HS e$!:AoBni:kh348QM}US8IgTX=:VJ z.6H5bft G $E;cG/&+ )ϯ7t.ƣ̩n {JaMcV zj堼>VZ,.n(i/ܭ8$rS$ )y?PrPBsmM\= G1Jŗ zM3>@q@zȇ-|GrD#/E=QͶ^NKPz)ݭyFf-=w][S֢-c0 c](#a{IhJMNWwW- @'Zlb.a y#.]Ǯ ĈT7| {U)^FAO2-;cnvi-x>eqcޗJ4< r[Vj/yMyS`pvwՈ&aI",SOI7`[X@]N(pLd AtRi|JYg25ܾFXVj׻sworۚه꛵%/RJK-C턶LVf*1V>o&&|\VC=i8Sj::1Vgkq^5 >~*XI~^<7-Ib|y(ox`˩Z9:"!3f[iRQp(0.\$p zb  F Rr*L_ [+ ŹaZʚalE@n:3]]SZS6 mT]O cn ΒG+2F-vP\φ%.Ka5@ Bs譃nf q5)h"_=)3'WϺ"?{eG?>cl wi90Enܶ=ԲF}O&F?f X<}Y3|/QQgLE=I#F`N6~롉*Q_ޢCN 7 :]r(ž}ԉʦUWi9 ^^7/3 eh+xLwV>=^- FҴ\+ Ghr3kp_o|Y,:\@Wo.{Hw:m$\Y&Qڵ KcT=bNZե%Xlʎ1M(Rbkښb5R 9uM#8/l;L٫R~--k_T3 .RSઅ܀X";+ Yu1T}>fGvWE? H`9H<9ՠJnFBլt~X}"]%XyԼ~Nv3qqvO+t\}7:V,\ rP-:ss*ML9s,a"^ly4hΩO KK/;j/d;T2:6r\|>Z$ܽgxH'u9-λR>δ,qb"|6|Ay!M%_zY%c+Q_QQLwR[=h<~2<[ 8<|w.6VgnRwp9h{z HfTLS2BzlbmVs[1FlaS k _nc oi&lerzЋsxWZH7~I_:>KQK=ʴŠĝC` mՓ cBmJO&gzչ%}<q|9i/I©OX#m WR Si  o/ r񹩤zwֹeR Ӓ+E 5](:xv XY`ײ鉉ˏd MX&g\= Y*lŠ`@<UǼ RtO.7G H#¿[b P٩ ڤl 6LxDVԁK"w]?ee' {> ̮V)EfIPu" ŸH%a}gQe/bJauwdl$]p!$mSC[UuG"=U + DAYu$VJt[d#^ 9zЩM 4KQI%8dPޯqwfSX|An0 m7o`T `$wTtC'Gw]ɑXAf^g@H Nt)X䉻9LB.q1PQ q2BόDׇ(@ENW9=QLBq 2.="boD/Ngޗni<+3u].m2#,Dٵ5Y.*$Hv֓_֝1 G!gsl V+U-DٰBA TQCGޑWsЏԬJ#k <ǒ vX kY_4 èî bAt밴e,aUmT&LAG+- 3Ë[T}h\vkpZnlCa˕'(^4^G&'4gKX԰Bmt 7 ln)झ(jS|<2'>hXY3Nja+WQ5_kc/8Q_ 1S[&8li_//8J4Ni-\d߶_<| W!^tv%NuNQjqS< 3Y*ńRMky}sXЍ*pЉ ȋHSHJ޸s'܄4u Fz]B#W^K L)=C !ݩ€N_N0 ,q B_33:F1K 'ar; iPmD.##!oHe2ի3^_G@!#j3R/[.XA,B'K6atimoJ*4(i}oS Wτ%eYJ~RtGPf asNQhPL.V"Xo+bιa-ؐ&ZLCEz`4"@+Jzp(9KqnW;|/KFz9U; T'=qEt;(\﹊ x*_WyKDl1@Cg.{)VjTyRrA i^FrYShJZ=;٣bO:[V0GT2 =;nᙙ;ȥtOO{_ pQBhsLۄ 8%KcV >=?̓$@?,2DQ@Dxm'ֻӐo.?Aic]DОdw& Rp|7l_[!g0Z7~]@LiXX`:UK{B5fbY NW3 ĵ_)z1eGIxu3גNy;4i=^@t G§OrUPf`zvP4>ۧnގtYHp| y2Tv7@TPs#ezלD(l6DdУb 1+Dn:uf5$U}6oyž8k(b Fog2ept˚,4f\@OCh}Ydzy ^I蒉Tn-8M?oPuy:~K&姙 M9g$& -yPnH>ڰn-'m3 8~ (3 Z~*i=Z qsNڐ&=ZZl|jlU̥#UA-m[b: Hl rR7G.T fϰ^62O,ѧ1P40OX zRZ6 7qkMKuY>fE^O쐝i#m5N܏lb5>֘J97[̀r KF*e[s1oJ\A__wee",3Qhn#iCpl  쌧3yV&n ӷI.ɼSR^ m[Xq@U;̪~jx@6 0IHXr}Yn x%496[X'Nd_# ,]%a.ӎn^cV&M9;\ `5лKBD3NRXtӍF!yY.|b;~l5LZq-H!wQ#N>Ȗk 򒼲f5 LfUأuas=ݱn[;I|Kjvj0gZ4\n`ʫh(^/loD(hWAA2`3\%Xz!ʒdWdMwAgTe,V#=/zn;C3PT~7 '7EZR pS,d0IqAW;_Pt-8p-q Tp$ (B)hw~avu=` q 4`pXC})t ,iH 4}[-|ok}[G(>!pBT>59lܻ䥚Xߘ s#G3/vCBa!pu 3 n4J<Ե: ^x*巩dC8J1LeCd ׶N"Bm=t*I qFۼ)vl D&vd\UZaG=}S\>upe:o:8bܹ \Mí8_&j[!/ۥ74xah 5ű1"2̲`6s5 + dq":Ħ(Vq0\* Ɖɞզԏ#IkҮh͐{mhCt6d߮\CvV)f8IЧU9VC(Ȋ"WaUj EľZJtl >#ܳtx7"FL ~ _+B#fۼbU9:@(Ilm+ Pk'X8d+3pD! 9~^9XL?l넀8q+ZOsOƇ& 5q@ 3p<7^MrϬ cuX0yMsl9EgC@"oszaZʙ*oZK-Easa $^VrjH1#RsNPCi}2Ғش3D_mp}jo @XUZ4l/: @C<rC8G)^ 'E:SJ{I\3ok rPNw|ڄҺzHq,7}O3@lF~ tj4S5:ڮ Qi q̧Ne : l9e;(p?iR F)+^7;lO"4>W., *H]F=*F3E jC4Lcq6bTK&KlނJ +hvQ^쨲D'q}9_>SǗ16I%2lO2}͍.vI攨x*ajL+XOMll`ԇ[@_/ȬPm:wYEjI^daP l{|A1?ytg'm¦x&w?O_PWJj < 39>we եN&!Bg8O#-}}wGbw. ..j룧%hfv`/X~%(1una#MpCf 77JUdn"+s4 *\):.x[+Aw8]E!RIލγ0YHoʆS371>q}-A"$gcBxx *Db\~.Gpșp9ﮣ5 dK=A`rE0ǚ͡@8&ox۹;FC!7y=Zd,;kW wWT`ŀ7OsVTpX&=~i8$K$]}FbUyӄr="1c$MNB(fj( ᠔ZLvܡ9#Ý(Hz> .!ZE,*܅)xـ#JftiU͆&Q6M%obG<npűV7d&tA~0"7 91eSdX,2!=@ eOWEuZBҾȭfZ&9v$e"襼9+ tkv+‘+{b@ӹl!1opn0T,)40 \:Bt,0%jS'VH@ɆO@>FZqrXB^\lEBvl?S6xSg1Cj恖%"%#ݬ1_$:5ZDj9霳ȝFEt5!B`’,d93w8PF-v[V GI%aBSDw?Py]1XaQeʤiƠCs("/臔Iں3* 6oovG%M"MW8w`(=dy`֪x̚l1#H\G[ C"l`^GG8y\AqO?;0PP}bM4żZAA_D榒' @](([--'0,TCN[)!UN[ibbp$c2>+37?XᙤRqi lS}%[̨c75~݃gKLDU^W)19RDq|Ss68b^=Z Veň杛yF-d} +hZg=a7/e ^2G_=q~lCE{4 8oZiQO Pٵ=?@dO4qmw嬳`KA p4C͵ !* k[C5Z5Ѩ1$*BMm\]H6>mb ئsJVeIJ 7g54H웿d~@tdS\zca"~]H?Tl<# -8} c7-"(>eVq 2x·:_&ݽPe qs>ݫ3ZqJG{P65EjdܬZj"!/-^?b@ƿ_z gMDsכ=bz9yht]WTЊ#h6i牎^bh\~ {HOzh">əY̫A~HY޶`dT#Z'-;ho؍ 1 Ạ#uHJp{Z4Oe# tp5#@c a;yc=r,5Aϰrbw`xi.o&j{_CV?O_<9~RH(8Dbr:4ʎ1 '+1B(HSA 4 @C]쌕ޒ[6[PN?<>]Pbj F>*xX'^։*=bxUQ, 63Se6^`I^{\`>4:u O;; D,ώ3_HQX䔑+j[d1IK&/(giF6Cf ɔ1$M^e-DdDajP8MN+MRK T2VEؘ/g+\K|u{ϭ%mHfܥ6 =kNʽԙc,=l^œh no@}q(ljM|4pQW#P %˰12V֎vćL+s:Lkd8ZmyLECS|aҔ@crWu N 7vUe4g%kMJlި¦7w8(m]H.+kgcw;$;ӈVkkDbQa]t J\ە- p,{ uƁ:GjPM6IaNqy[PpDES{cб<)1U> QddX-t7C |;og4 , 眇O੭)-&6Oa9=ϸs=uH(-{򲬍@Q3wlkb{#%Ch9I*u|nFA}Y ?LSɉd ]5]#k[{#^Le%A B%@zs"Y<15T2kաTM:Ô{;$ ˣɬ"&gy9F+> W8C]4uNSz@~CT`D¼?{^؏p&5}E;L?>]C(O7ŮEIDoYl³6#]Ӂa%Q/;ƾQku Us\6zZx0~(B+EP9*ép۵̮%xY0]dҢ4~:B~%z 7hx^mtf4l8w D }N֎Aa]^)J:Ft Y"vaP '=q68}\UWm;B@ހʑ <]qV *d e~WxeXa5&=\s}ޗ#oؑV򙮢r <N;| {@Y0GHսc$2Dp8"gERG8:|8uw /?ZnF 9W@[!0U_UV %t ϥ WxeН$v׌%de^逰__Y$+bWw?U*zD:׾Qeh prn" ,/꺺RCPD Q~5JhZ(Nj9 :FV@{^Wh DkB܃v~*>pձlW H_+{tga++-~,dΟ^եĮRXٓ7W&j񝧆w(`Y.fΣWZ@ =oL>EWtbmV D̬]=`XeX35:VH:+rTOJFB qc y|>3ϔ-SsZr@qEzNzl6VJ`"(U+u̲ΧeG>2~!X#}%(,o^e$̞">,:ˈG'#gP bqJ|bw~Pr?VOм{yDb3Ǒ[/`]s'HDR^S`CAkM 5 ͘uHϪW`o~,!2=^M\Y P12ݵ H;ẅ́kUۥ]kTn`_rܰŚǴ)HvL_Qz(xqau#}=ec]GQ㍓!P*Xd>~G )B LuSp*GT 1Cc;" #'nYY~P,P D[mS[=Ogc3bf4'fV<PC? +'ڭ|]*OM}vpS96}Chqpg^<iGd>]QW϶>i/季q/m3B򜷙w! e,uȝ|Ù&[_-'B4͒9d(O*+'9ٸ-< Ab|fS(&Ng=^Q~,j&QQso1eãP{ PLWj/]IGYU "Z6ܰY]W([4~ZڍK(%&Š0A|zKʆLq_5x9sUv9>o`=깓1Eh|Ulzx6~aP z~3w E >8&\rV>^H$"b:=^v*6/3@g!D{XyY/kCUdI0&p)t1i8 _;/Ni?d a4U\t!&X\PSTXFj^/,MMwÖ t˓櫈Q$ ZSQb{`B`L(oCAIz[8= 9D8Blz`U `ڋ^쉄řViwcN(:罽_UWZ^fD5?iCnb֙gS:Szx._~ݩIz–,yBb{ѵ>8'>Ѕ2ǸlpE/M Joy*n4H.&>Zd܁Kņ=MI\[MD\ e4\ࢻWC".LBZƢSV z$jWAu]G Sg8ƏBtxMHA]0+9'(C2N(W^إS5\_F7(NYb/"Ə~qDrvv7YLwv=%g4&L#晙Epy"H< ۯa&+bf%x2 !g)|/턡CUZwq`d!o bH1xYwwPJ.Cx}zߚ2})_߬ 4(cT?lt)m/OV:PЅ:ͳ'!\/|WGCOw8DNLh0܊XӺlJ+^胜IE9ಝni!8F$JC؍Y\_M=%F5v@3b-j]N:Zz'ڋuI|HG+sno gvIacx9܄VNXeD!5aʱf)>2WQl?x^)!T,q9s !J~,j1A!rQ_Pq@x!XZ_ĭϸu{ uSCW-wQבl&=~sz6l4Ϫwp4h '7P5.$o(3E bHM N` 4ܬ")6)S<+Jxsǯa[eLw%UQ5+gGt=By,-Tܯ=;޽ċ() *Q጗$&'pq~(WhIE/b|VAO.Gzwo_bP`2!Ɣ=, 4|<dśB_J X%rrЗ<iϫ :_!!o41%TdȾĎ(q1hk 6Pf͍SxAsέ2![&`ȇhEM{0KNPᤳP5L 0 Z"Uݗ5vNsh)aY9!j4t%?S<K@U^q-b@=2Rl{w N/(_SH-FUh5>a(KzYw q <|787 M;6桝 I5Tas(`: C୘R(.rIǝڰRc/uE*P3aQ`XHdtiwkR>F.+Gsq+ VM;I9bvzXi'y eE>~_+ֈP ޻(;+*..rVQbin/W|Z.v>n4ű7{<GT4$e{oJ6ok[cE9pbf᣻ 09U΢p8o戮tB$z7s OXM e%~fR9o'" V `~:XP8j~Y r ؛6nՌGλhA(KZy ̦nқJy'!pp[(I]b{)_H+K8=ksH\?ˍu5D ֪DepaaE߼QyS` M-).nig5rCK~ah釛 tw龩 q- ;T`*Atź @S0kDܕVkK]5\!匆rAi PX/ 8^7v CS58nG뛟'~dHY%_mX#d*[y]pbәQBYμb@}bzRj)Ե橥 &0!贅_uӏxyu!W#vgJF7ǚ#8'" KϹS}<\Pe-لm1(8P鱟%eb;Ttl{A+j6#{m_U}6Y. muF߯Z@wBX(-RIT_w"(~y?Y2W%$D cv*(Vj<"` "S@=|F{>[ _ޗf^Bvʧ`=!fSWϣIZr1#iAFd*^?HwhckYpoDSv>I10R~% hq x 90F@`(0vHPi^yvihR-3бbɨ%yP,3LqDwd2U%i]Ot/w腔 BKjb :DWd=1Q 2~ d;2|\R': 3ёaSLH¿sufF5"t yzA6G&Ylf]%M3 L=ӵuY )x~ڰ,_?@S(AކvV@ev$SqH K@k?ɠX<,9Qj kt R <4 y*;@)%xc˺wGދStie!U():Aj8%& eNⷳ;4vj.o)_m8Ki&l@#9dОxl{hyb`df[G֔)'eHr;a!j &|,=D;KkByT`W𰓣>@BhF3H"ƿ-Xl_p& ϝ:B歛-5 5S4ÏQr 0 4 HFa-mmheo_KCPO(̬`#wCrgS&M%>:OL0uշU%e82BGR~0ڞIAkԜ;XWN4<0h" ˕Ԛ#8+9J#8%}Ao:߻S }Rg3U;<`%Kh͵~^Z=7 U1 LnidI{u?*kq^~Wio/{-amF%Ūۤ\o3ZF11\59\^wލ[odd ]6rxfmF Wr fxz= 4yħ&Li&ќQ'~K:{P6herǏCt<^;YdĒ|x ) oo֓z ؼ}Ů"w٘tƦճFۂhf k.%H&yWp>)..!ںfVN9 L3ԇLoѳ .n8 l(@K`@:=7=HY7frOSb9?4Cd%FCT9m +Bvؼ*e |/[0[GV/gWbSXry wV@<: gh80̤!tmL3群r KjZF&s2հ\;'}N]̥ I>IZ<6Eɮ;IA6YwgLOMXDC=B0xƛG6yhV§yb}HstMSwP{[n?0_!OXu0O_1S=e `/eY+zP:_ќJ~C;gbO+!SeQ5x=@Á2D@!7uOv/L؂^}]"{;Rs'LmҠ`|t;&)~Aqzsd <[ױ) zRqRpMhMB"_@2'0l>Y¿ֱϼ]=U?3Ͱ+|AXc=x_#TIА,Dm&q[u5b%KDG j ihbo.V.UI$J95$aiC*PܐPP\u=w\n#YֿG4Ũu2MC[jBzX^Xic3a:AQ5U( ja]oI/v GuՈ~AGg6w|mZ17D^vg@Mo2g.⌏D 96s{|"z߭BG;&kk5D8V~A|(b"pAT Re5krKSJ(,j[y sذP ^ z45eϳ3>9#BO vŜjzB]h_eTk9%9қ꫐\#e&ƺzQ<`' :eݘOmr{ l0JScA2[ז'BZF8p&/~l ?UX4dncQ/f0;5yfd7$2)oѭ3Sܲɬ2f*3Wʟ@(DkP74K_'a:BibNuWғ4M> 6x\ 4[&Y&niFU)8DÃ$nDVSHQ\0gr w ʙc$ՌLDڈoyf`̓9=[hI*0˝`Mbt&$8fvm_EI4.6|fˁ86R+ln),CTJ2ȏ^~?w*ACѥU9 |x{=';9<:ɦUl`CՠvvzC֢DyEqfq䋖W{16Ivu8ۓwXzqOTɞECO7nYK" 2s ʙk^'Fuy].Ub#ˆPrM'X!*Kjn49hW^lbT y(Lq'(Q^ ?a`sV0D-Ig~}kpT+7 GpLS]_P(V$sQr42r&ݨs=IZ-hn;ȚpoEiQ!{NsU >U$ܧ5i)Lpk33Dd6 );7\ A*Ɩ|4xhAA]IC$iwnCq5{)~4M<NKaT>ͷA 6Rs#c,IfZyTh )~Qg b.4_kLjx& ,Xe߹"NܵCEA1!!밍Ph1xڶ|,۔|EZB>J1RR %K9,Ll 'M 1_K~U.m? }8xaZ7 ,*xb'֨@y1-V^F四, DRIC,Q5wI-am͍f?Ww곚Bq?:}:ޅW_wCRw;<ƣy+Ɯ>;";oC},㼽8#hsm- A}K 80s4_10)bQtFO9T/ڰs Ozbmh ;$Q\m_VArWs7X'F4֊yM-/ pPW+@2{VRR됶:`dކ$e+3}!Ïg oQMo Q:fs<5h&3i@h{wOdRsa6dsO!70fWܴT^_hh.mnǬnyD&foѷ G^N8v+xs;t \[rGWk[\Fh[LAl ŒĬώ,MG%>]w\}B-A'^;yA-@M@?ƖٶŊ J"RC\* OI>3RLe|QHZ>s5|dl' * !9XWWۄ|Bfv-0=Qg%iķ^B,W-txZ?lQq߂ Tj?sxs^;$Z25}ce@Sf64<)B!F+vF Mvy2ۺ1Aȗ)Jc^V~,EmigM-IU|'pjׅ@['7նr8L~eIAYxꮍ_1=C#>lu͖8d_:@)wɜe:k~aa|se CP3 |j#\ ˖~HeC>v~SV]^:c yD:/ +]Ks@7#m2 Bb3YOFw Tu/tt6ar&ܪl,̴4ҏ,)*Y0ݴU 笢 `_*|~В,ӂd^![9@6uN5h9H3'$=Lƌ#%*eF>KH B[o$xxH RS= w r.;QFtOg(*!REL?U "+UlcT[YJQ OIH m{!~2(3QY Q3vw3M|=G?qTj'\c`PS0>ڀ݀chúUEyNV8}"Ǹ~xq sVr;F%cP 78 6fb˱'ٍ”..BӪynfUA,9EA($Cyؼ()N~B-uiS%d~>Q!͗Ҟ$7&֘~V7e,}GXFtܳ1Z{'s|uxl?iMJ?HWiiLuKְ$nqG*7vg9-_3 -Q)AhĹwaEAi * A]LEfq"y7ð?{\XAQ"2t!hupK[T2jK8@I}ӊܩ} lw r`Mf_r0Rd(p8CD.m?F{eI݋f -nFre*`cY1Aq^Qc\ty<- 4r~J܊!yKtt|]LI.^/ԟY͂RFj]İ&euOZ/!I]PgBYpS[քJ1.iI}#X&F8gx|l›jzM)? 0S9V2 H j K-,"x0%}9Cgriתܴ1` \ɄViN__1tN:Q7%D$ո4e1.΀]ԩK77%wG+ʖ ՟hm/ժ #,yBOz71lwMefiN7`=6+HX5Ta],Z<n2ǻnt+ʵpW9m8I1 u$.>hX)cx3̴#y֪K/"NoaN# |h:ޢ)Z[2Š_;5CzйJ)?R;Thze FŎZPu ᛆ_L X#FE-:0пj.V7n>r| ֎~ o 7e\_}0pr?'$[9vkO3oD/q5fSHu)&j%azpxg m=4}W6Z3S!툗7yRhq _%bUjįQœ݆@Nө@&g\^̏sk-9? (Gygci5%@_{ px0FJ& ^$0g3[#ObQs(@5]k:̑8x ,iM_+?+px H=9saN,hS;w+⨬pA !@>'C)ۑ ӲR`XjgHYMt}>2,$b~{u?>oyzʈa3l+aQ-SRUJ;f KӣՐOAXz}k}4FwÇHa6rddѿ ڴT9mJBq}o&ST==0{cQ\VA-$$َؙ]EoO~1:I}1eeDV8%T"cC\ʜޓ~C 1g{A/~RgT~foN,,?,\;&=̪s MVH+~Tn˺c  wfjZhh@fsk'=YW.=Q-kiG+uݰ"ƞRXLd" |q,V^zMƬOULm֗ÚRZ63^DN. XNЯJk0~ 9 O,1-0C˜W =#$Z]`JC^7#]b3~jJ7]*9>җlJ DJj\!MGrGқ ܱYtg>M1#"#2yCv,($!lbQxݝ ezssIyb>I* @/:Eu,<1\[w,^mM j5;ǠCt\pY},EWtdN9s>*AyQH৩ 1jkT[/bTN9/ktH= K)]wMpí7IsyEV+ ?P4$hcG[ÿT+0OG4تG¥ k&/EMƵ}RAuRS?p,)2fHa6r S &^=<jyT,t ¬;H<IL20Y O~:C^<:-*\|v7'H9%JCPQIb>-2q4C0lynȎL-'q '[SWLɱ:<W j &>L^AgJ%iL:̳p:Owښ~>>kWA HrÌ! M;J{6i.fU*Jޢ$A-kbR߱ux S17Jh8I_T 6]8qLHs|34Dv)*g6H^޷+0r$HހbGC)}e# - &+[ !iuyƃs@ h-kmȆH y.Sߕ$;6-Mq@!RCSZײrFIsHC^&?ie'}HNp]i-ua.\1,>IZq=X&rɸ}ַI9E˗`1ݔ,aIѬ9Lieyˤ7RgE-e3;; 8-$Lz 4pRߡӧ\E'ucH`vҤ* T(^=2WҔ{)Js-NuJ9_ i%2 ɉI&҆pڬi6EdFxiasg\m l2ʵ[)zt ɅĜie G2Ǹ蘕_Zu?Z 492[ nݞ#fz&ч: cS,n+voȇ9rTmq{gjL<s$7s/e((2ݘ Qnaa7t% /9]&  u`(Ԗ(OАc%], Yݗ{Z|ƔU4+C#WrMİdum;|Tf6V$'$HD|+B+?=&Lv6ν9>&B%'hj(Y 9m0em46yov<8FKB18peA9kt⋴jh 1Dr;]J<#$!Yl?iCC]&m0^6 JTbeCp2--ЄzI?(6*ocJ<q6 jޤ ZQr@GY /vWUBց0)eH|V TۦZ$c65M$W70C f !d*EG:t/FdZ˝:#Oa038P}p{oBnv,jü_Fw\gU?4(U"0j;+ƣOѓĸ f*?ʄdK.QQX(ԙ?'3lY&*Arx)~_]Ztt69FգS!)#+~CM`\60b[킖ap̕(=c Тg-'v0ʛ=,`wa5 f69SDπ%'p)iдG 0\`+f9̓0KKlF12ʃpG#|<6 SfdbSZ ƂCol" e7pHG]7!{LhnC ׷NМv.Xu_; Lۏ]Xw{N CAuiCE=;[‰a1תlv>OH/d]4 )H 6TvDbCywePQØ [1@kNpNme*5N?ͫm (]7Imӊ-yGQI}WIv8`.ÙNju %E%v8d˅ڷ {K[PM}U^ߥ c+S;a`"ѫr,iڞQ9#@ջ~=B2EgȧA:$Vae ʋ+:*x9wLrSW|,\`cV{i1Vg`?MP5Qi>loўw/ڗ,p$53fH2X뎓2z43a,W$ƈZ -|gĪ!\@oMV5)Հm1hQ:9CBdOK?eS#LfMِO3Qs-ot?)|l>"n& ^~0>R=$L=TyoQM,k,o<& `5ݏh82G .hqD o ѭO,j#nlHQQQUkM6;4yl%|*dFx9vFaE ]5FVf.Fӯ>bP@\BT"׌wϩ#w^ ;c9s!/kx$V:9 ț'/0 /O B@S)eȊW|\A>YOWl#qw'Qۈ9AM "X玊p5%M9j-;'0WvբZ(ChM\Cd:y)dk9tZ4WN=Z+IQ h1){¢hD0rYР[ پ4W20[9$%If*.;>vta~Х -)l,)8KL8E/ExNEamZ- Y0?2^GW'GŴ"UC[BCa^)TP&t|^׍wRqo[LW[W6$)_kq5OJ 2p/ cK˫fFh!4WX[s:^}C)*#Փ'c~ 'y5qj"A5JfF?gJ:K1}9g?Iֹ' qim&h̶kF3G|߁ٳh%<{ C pN`}~Gw[ tjYXAa8.)Mf*ۍM,KgǦ),W^%e4 ˩L*f+լw;o0}!ܴn,3ѣp@X~5ɔvېlıBa7ZV][ 'c'L8c"tBQO 3Q)9xXK9$tdk<6Pm't;5s? giOib ې7nj8}[&0X=E;(#Hi1^4K(+( ĭ& D N,LQF^@}n*T3cJɥ+> <1 e|UCAͮSj#2X?`Q4N@BMpN<!q(ldVz(m^ XS °/QqE'N}pjNspC :KIo n_Y>%Vw- bۥI(9/0u/15F̯!^4'_\"Z8g~ss7rSX(=Ǩb_nsn|p_Z3]&M#6Dm.\NSTh3er`R˔n 1&#mL_w8S䶙`֝8AU*%i'݁(Jɴ)2Lٰ>v/;9L;o*j$G7еk>%?NZ06 Xk$}Vq"5XՕ0}Omdvq^¨DkTTῧυ;:ԈCqq=*` & ~:x?~yucpA C)C/BTw0>az/Y[ )K;/R\h/$45ܼdXrjF?\߽ES^o&U,9[T0cЦ..oq|Fᮧb5P;D0P9gqQJyA"*:sX * X0TJ) 1f|W@m'L p-$\BS(Xc^ - [Mj,٦# \mж]ss|)}&-=!+Țc7gi`H؟*+8TVȣM4ϸQtv*cK]RbDfa2OkGZtAZ|Ɩ ym=[w 쓃5Wk溜ɕ0WRO) %d(8:éN=]qr h?`PuTL_4[ѵ ܯ Ui44e>e7p i],b*9tLpTix>~ѧ bQrGӈCYPc hP8Ku/o Jpʏr8^ ,=K>P8ZۅmބԼMm VpJҤ?p.GT8W~x>lAUL1Ц}e*V`}<-' "EHxc maU=r:e?+Mz9xVZ:2pB S\DғjO G^TED1Sj}|%q5"gp~zB]2P΄\}:uX_{Ǟ z J (l{"$a9FààoH_4wRU[Li%qXudd'C %NN n/$ۋ yD~/Dx]l\> 5\m0D }֣hB?ܙxzu^d.⾝ԫĖtm6y5 /FcϮ0G7G!0nah޹)7-zK24B %pWZۛkv(H)FqF`{?} )ivf҈7NUv}Gyv3W3!j(PLM]QO.h I׮ S))lSv>q϶, ~*NKRAʫ_YvW^#>t`L4w:9tcØF)x*6QCɓ*,} VI 5Ǘod1霺_BЖ̱dh(W2d> vc2+kj061Hekltyi+%% M4l;d:R i.lEOj5ܧ PV٥ذ_){`+ht]~.u!.hnI7M|C.Pa!Pyis$smpmO6NTHkMtV1zM X4bj7H9+8aN~ͮItтl bIhp"vGٳ5Ӝj!MR0 $﫞oLk+ !`_+i k^\1kZ'W*ztc.@ɏ[ì,VvR 5criO\k"|S[<H)p\BݼЬd*;I!1Ż'0 u#}I}vpC݀µt'Cą}F?LQe0[q8%qtv#ӓ]"0]tV *+rE';.@!PU3Is~H+;oWҼ|V; SSW\ĩX 5Zm,4>-7$7i&7:y֛mEާe4@^G/|"TU|\%Z󜦽RAWAmuVP[[YXЙm詾8 Ǽɪh]j:y vf1;s~|=q2FZыRCc(]LsϚFIb}:(I |2u)2MtDȳ!=j#d-zR!~y]=욛HPG/[> +HHL IQ݅^jh+JFP:RT9f8=̩u,o6h+ ڳ֗lmVA ( 7(M b:ҪiY3rEhn9L`bzQz;ŝ3#}"*k$mE}TihMu ÉݤU G  @Sdy й&xX:J$WFe|;I4~1ΰS;fwV"DJ 'dះ?DS _KABKU.il Dóد&XcJ(,LLM $2|\IA55V3.b߳PEk^N|aWbviJ֏->6 9jc`=VvmnSCRF-sGI˔ *ULG <'XyGI% L`*Y {+&J))p?:G ?h@63 8(2b Qy i75{潅V (#8f1:'8Jse gXtVx vkCx?N)~!W'x%p{|7sc`!V ѥd!ߑ[ LN_ ϰ3Qlole"Hui5Vmtj庅 UKQ^Y!j,I%3A PG$Z}$=^M4L܎}RIv Ưdn³#QNMݩC wcgH- nUKYEm%Y~1խ2vԶ~{+a'r9OX4~$u{*hhgJZsKef݄ʍ{Me_X{IO?\!`mtTR~`8FgZc݌'W 1wٳjD,q2- ~Zm3~&Blf[-~·!Ґ!8겧26v!zj1= eV k?f9MZP&ݔCo/bqUzA/0KwR/ Bxm\66j«__2?kX^KMYfM˴Rl ՕSQk4l&':1Rv۾YP$zہzw@rNjA '~*c !jy"AQi`G_9;9IJǘ3std#":~ZnHA@MEcϲ `z羖 wH? =DY+SjxK9ZK& P80^Fz͈seÙJ|GOϓuߞ2gW u,#&6On&415<%z6Y5|cwL$>jʥ̤u7,b@ :_-]l ~ IqE3_xS]Uy>ޜ+?J ͭS9rtī`*&#/} Y{iN,R95)P]͑>}$~xU\>%RہY %JcT 8ư4'~vc 's RWIe.rN2vТ!J%GO"!;ê$qFxfZuFC+-^Xw pL,)vq8rS5)[j[zۣJ2;+!!FP&t]nr~'A`u(^D3LwH`N:VռLLŻ*vs $[QAŒiIš\n+(Wqǝ2k4*ئ0j2$1 羳%<k*#wr<%V>t8 _h%rRvBc9aZr-g%.J'a ԠqI&ur / svP g,y?xZyqL1A :rK(D6͎K?kDu+GɀXqHm<$($'o[ESg&}WwC;  Mܺ2ɥnf*:ԡQAS&[{Amljk>$`\ ozr gJZWS1$Ÿ((>C1 ]"`4 ^YO3t&=JRCܙ) o( %MؠT, _{O$9"4b rlǤfTQh81R{\4oEhLZ R )PRswӱ¢~ڇِ"vu "[Ga;:˥6QL0lYS8 KvŔ#Ï pPm[+3 MG=P\6!R̎:[?޶0C./I^ҲjQ].36}M(g*9}ˈҡ)K`^5"P2n9lT):CT( 9ZD@BSd"jf>QWⱸ# d.ywU"ʆ nKP(x7 {dR֊ 5u$< ]J,+unPو\ǡ6إ:{ⷹߙ(P)OR@UCR2јF+d`X‡?@ Kb_Z/DW7 ux RM2XEox}^8.b#[%٣#PphH Ӕ h")64 bHϢK69rl FöȎؕY-U戫мIouH^;d9 h- ę.&T܅,fbrJf欩 k8N o632|Nc e09?W'lq{w[rX8z Ơ]򦍇yG#:O MOS0NyCoYL r%lUΓ2a` EVHwZ ?ϱӏ$_`!W8VZPNJB̶^b@c-7TΗ'K5}k<ܖz0RJG;]{I/bAvvw|u̡jPfg\x]->$Gb8[-yy&aI6̀I/½nwAў r-:rtn*SLO\/Wg`&)[#@y{ԿN~l^zY~rk- )c}"=-iDȯEJV<**9 Ęfo{aZayP52~v;(?rcZ^kK[|N.+Ebj~@Q [<cǀʝ-ˡ +pG4^8 gj5mL8I]A6s&V].0knFj㑔It!td!DS*,\+%rd=N¤  r\;4YvxxĎc@}Pٵ s/lȧ JƱ(af6F?o8z4{.6SgUn!%\XV'1eOI0/6ӥʂtʧ`W"@y4nD$k=6NҩWA+|jPFJ~y=PiDvj +?杧HFyq AKՖ%lɸꔲ}wƷ Zp Q^[GEy#@۫Jk+$ U#؋ʏ]>#eSᐲ?+G %:W`F7UC~0_4$(j#Y Gѳ11]im>S:ϖ+W_о)v,0 ,}Q(Nj΅u[Zy):'۵HLh Q^ͻFs|]e 0c +6"UP)XeG!t F٠;C\`g9$"y9>mvW >;1]; uICujɞShfJ* _uԷ ͹C_ݨ7{+m@5e?,[$, |V:z;|A;IWP{f'G'hufBMe$a~Co8HJjy*†uE3YX% oHD^Ԏ$i ys j=.N;oґޏ.43G4` MuU`gl7$`3g]+ypNFܐa vUEtzK~(ށt'^:#F)BapIkX6^ւ #h)Rh Vp 2TR)DH3 Jl9޼__EaLM}HA1|+_Ja-46[YOJw7d 1]evo>Xz 0*vsA%$%v빤Ch+:G@w*A; wIN2Ś$:\Z^"dFRx檴)C@:~]S"+t|3 Yc1X/5~"JCQ ){fί;jf9azCz4p8SB$PiK,`=c$뜢Y"s=iwiM*.Yx|Z^whF;wuk7W9}rd6g[٩\mHYIP<D<  BKm`"󵘨 >⵮0QMI'&duioAJj>/.Zo>ǶoDD!{XSu4P˕A=Tj먊%3ŶE >,dn|ǭK9a <9liS@g? @C I$Ӏ$,! m`Le)M`&DuXে[ ㅾ+BN^+8'\﷔i9b FhϰXL6ZOfCGxN qcS S[E eƹbb7juy~PPM)m9ll|%tvF"=#$[)%VfåFvhU@Z(Z -K G7؊B)]vܖr5, I殕Fl+<UT?Ă60S]1EgZD'8X8Pt] B ڗjvtl1\Hicuо$gthPڪ6Z'mދZ~`\1B\/qk9e) h^CKE J =pݓKu$}գ\q;gfi=}8jpIKhhv cCʲPU*2a-[TZ\BApXYs} YyUyNU8lYe.G9[ޖנ~NyP(@}`LnOą7\j;ja;^Ie^r7ftPI`Wڑ$krjJP ( G! ⡈6W=~|`vOǩ`("0 sBX!CN? N8a& )*a6&Oh-!kזjw<I:X\D@ip 1\z> ޞݼ"`]j^\ɵ} ]U; 1ͩb v/-bE0$aR3ow?E}Ubj6~>}y`nq}k}+yZVjZL3|>kRO򫿣ć+KlB4զ/>qSuϯq4>`(bꁛUm6&WF߉>츖j/xb[`T?c2S4ջvA< `uaPm->'^S^'g0#8DytzgG_eGN\{p)[oZ/oD\ 0륭닾N7A4rJv9Yާ;.lj03e(>Rn%qEu(vp܋"z~MNLtﰼL>,  SטּpY LDX D(H:UO|g[f0&1 r[95eenաrtp&aR AI-S["ox,;ϳkqu9Hmbh>,z-Mr_9^px<Ś3@%&ڱ>gbLUH&*[仵'dP">J ώ=0ޏ#.vTtq&SDavH%ZYT=ݛh( W:jO? 6ZjuN\6¿!7cIKsBgo[p }+cS]O' (ړ"Vᐸh4*S ʍ%.hdMbwaOfWu͕mx Djq8LKc7 GtXueK##|7Q<]% ?&_]Z z!Tqךab!Ӄ %櫒`j*;clzӊ2*v/-ïn(`jx$-F9^%nkC"._AJӖkqMZ tQZ UJ_azj$;F%sG7X 7nciI}昸 oa~ε_V!G ڲ2!Xҝ ]ldj!XC#`~M\oLhQX h>ޢRYP[ɂ\G/ gDN]ܫ!E"[[5ecZyY:`ID),,Do`ШLxT%Ympg31vC>(=*r2 C#ʳt8#+^`Z :8HL06jIYQ x)v_3@ꗁuys߿(̑Wbm?=W/Nk{M4*Hy`Vhv/ 5u]1vLD2/&g?ۮ0@BK(7D6q=SP@p(:v- ^Ĺ Ki(<*([-YϛՉ5dU[{'+(Ǟz bd4Q1=B1S8N>V</$\3@d;Y.+Zviizc~mgi_%7r Pۼ{JT*<8ׯ1EOZ=Re-*&Jn^taQŽĖ<uCr4dE?i n [XUpr^K=q6s ,[p2*G-Pqd6n.9 - V^FB9qƬS8m,s| Ê6>趝 I!ϾLK-\ulAl/6iLJ:R'm/^EDh3-xp˟$lUcu}pGEۑ`0 X/wҒ;`NxLr@uJʵblc!x-zӖ($% a7%bgr THy<'7EcXPpQp'2eԈS. "y W%)Bi$q/^6K^;^}d.b gugndqhSEpT*͢73,GA{g̡(nb PR2O0%3|Iew p70p@\ rQ5uNUEHi~kmKF!Ӭ+zg;Jg @NA& Lf:2\o/.qZbU?&OXԶsnY T1@.f_͓d#TlQDv1cn AD %ӁN[ ppH#ǸӯG h?/k}I:W=3zށ;llB'Kr n- 6r«ē a7:uolMqW8CmЌEb&W %otqOΌ/M"=lEUnu 2L$JQ)H]+`KFt xmXMF8@,ti?*~EW,"иC94 wHxtm! ۉs!=&awj\5eGujE1RFSUYD;7fj9WŤ:^C)˓ 2);vܸrƧZðM%Ug r/ ɰ9ƓYp<ׅb/0_.Vp$UY;cKWJ[nUUCSD>) ' n&OтLU;N60֗(,6m~.%`7Aan׋ ɵe`-g6CKSK4Ik S]lu[&n`/]U*nCxߪ=]s.~T|X1cmb;Z&hFVu ^H{<<0<\'%QVN2p4]', T.?,?oMxO2e&Rt=oqOb뺔ZrD5񤠘JxȋM`5-Pl6,$iQ8UŇʧw鶫^:88b70xS6`Բ; kɭ6FGaNb2(n\:Ӣp}8XW{hdbQ+y[}?D X{f$ p 43VEfȶ!%P܈!v6۶y<Qly8Es$~B"F3>Ոx9>wKxkѲer+6v_LugW&bo%yTTstcz{i0?yJ%PIAnjN1,\#9o%C:|7Wȉ/à]=bu{V~v4Dc!.FZϭ?[/K]'ѿ >mHߊd'귱Y[EF8##>ͪ[_k 901El-!v~EuQp kXl38)d5Y%h1‚$X_c z(#Hk=l6Kwoc&mW&2O/݈E WHZkkpڅ:]slyez5z 0t P͢3g A_ZP3:.Lop*E H1AZvdwKoSC rAp|eH78STrGD6vENAZ!mޟ,'x\s ',8/oH*}(w$ƀ %=?xx/DT)\ٟpg$MvL<}ԆS1a,<EpχΦWid _q~RTp"{0!p| u)-/XYjkDMa{ \\"P4їíxe `U9$)AT 0XzE x#O0UΦ@ HXڈj:һMq9(kV 22tH,7<'*vWJ<Tl*ޢnGkt P l,9/"n~Mۧ 'qL>$y9dwűiu ^7gc:ѥOʸRҘԍ\޵9zf }h`1 'dpdF? #H*llK'ȃ7Ht<}Ahν|K`j>{N-X&8aWUV.h{]Kjr62WY7};b~w=.ˆ!7ǽp%>*9p"pSv]*+,E\rI'uw҄+H+D|,Mb\`?qd8!a.w $v_-\37/_o-Bʫ舚ʚ] %>yd^q +DM>S%Lj.*; B'Ο^ȡEћ8"5A)P?} >'R!mɐ" ,k(u\u].=OfĜAn֝LW[ǃHk! K|tS@YaV0"Wl9dx;vH_-FPoW-cX֫cq!Kp]f~CUy!j -d#YFL3&N+YJ9V)/k8é l#*U:}E“ph 1JSbᱦ2>ya';!#'ƨ;|/$p֑s='[T藐Os°h-jn*09x^֛luAߘz,"/S{ PmK2bxvbTgN>kaOHA/eYn"9~ .Vx C)bj'L9e[#5`\ mȖ9P{?xsjfbq5/@"&Jc35E(:x},ݧ@'c5{~ъEy|7E::[:I+T[! Um#Uqd\enN3l?m6w5M $K+7"ez QxIgFij/Dqܕ)lmCN).3!/+<˝`ȷ`P&#HDs(YM7s+ro=ӑREA'),!edoDdf%΄ad["tDgr\+Cu)l(buT/l`iɕC`&72R^C^<)U{$r/ 1@)"Ąx|hT֠*:԰vK=ÄD$oL%ĉ?9V^-g{8 pm6W(R,[|HfHGf]dH!+#rt%GW0hR!;#*c&rv;?ue1ʇnlnJu蔾S7Pqtj|LNBt.@l:/h4W>M&`}WO6 1O|MwA \6,~u͑~C3櫺M6d. $G׾V`5Q1:j8zrxa KֲIJpx@ l5 h>n@V_b~  9 V, hVTtL-W^ڼ ]tvCY0VS _~tGR( cX_pLqQ壽xc Q!m]ܕ+Wo{fz7|_3rzfȌ䈠9̆;NMgA[$zŃߺ>vܥrŹY0'+t, ]n6ۙɯu`H bLVhdbtgE3$GFT.k!ϣtRKqx7,9rűt1xF؃6a *'\,!dL4PvcEfLN͟zaS*TUW՛+.o\Dtv鞢ɗ[1\vEK& 0Æh,F& K;tQdvRetģpࡁNs[2W%rK? :p4wIp̭,+s2ǀ vuMRxtbQ϶#WI"r0M`lOZIhR 9Ίc\``wXZV  L*/S#FK\Y#D,M}'(\NESN)PL~\+xćBc{+n uvn=隐=dTi!S:mMjׄ@I;7D5)Fbnӥa4Ku0| }K+ -"ˢW-ڦ9\;A_GOUxcog%%:b*a7Lu{* BB2&br!+Br_P(~˶섴~4MZ3ZqND~E:8iKM^E"=*YP2TBNj'80Ôm(=R7e1epx,eZgbuiJ;J]V?{j "~o5ab ٞB9+ʫd’Zfw eLP_MHp} E.Hbxd$Hr464 L40X@Jd\6g,liQ/H0a].yfH:"t$#alMr<`\ 1Y :IN:[t`-Eӷ<ق+pabNh鍺+&.#s^s7#!k}]MGV̖lGu1Inߜ %>(3"*.WB3M.>.!V{ jpYB WM n;Wֿ8H{Ĥӛ"KDti(c`Цyl_? "b`IbCN8{dA)ovx 1$8-tDca.Gv^(Uh 9oՋ36ؾtYV#FwۀG.-y0ׂ=K#YRX)w83yX?&QL9@ '+jkcbު_0227X}( :jXIVi^ሪEq~0=GSpqDl[xq0ԂC\9ή@S*h{7@xYzL`_{~7CmA)Wl8_{ZȞcQRzJH1c/aX4$*IiTuH+fm$l]O^@2l-VڌEޟ/ ]{$75& 7|(FS9 ^R'(3 C )LJJN0$6.%mh z4_P~r<L$[6SWVJi:_ȼERJL&h1=?o:-,{񋛀6}_2ըRPܬCnoU d_Л]S38^Wnw,>4)e9`t` "U^3#t yyΙG}K(FrB %ӸT?g:mtNSi2ՑG*cuՎ%{*T9՝WN !6\E-hKl#uM=ҧY`FoٚCT1s0"'".%] g۟]-WL)IQIEV_`dsk~s umY38v>!yp(7)e /'Pڕ46bo!!3F,+OGP^c')[\{ؚAfeP r(ZY'&9ͳNZ\=Cc`b>@ IRÄxȠj&NcFWP\(XE'=djŲOV 2lvRlX w,+k xr:sg YIľ0&&. EtX ʀ [}o%Ks[=1:[(S&"_.8oƌ W '[П15:B^ͧMoC }&1ȑCE ʐ]PȒ 2qH۸̡̲ .o?Gxl@ghM !(x,Ա QA+T4놿7u /#&vUdtG%?<VS9 wt+ZHlnmv9B w2+d}WY<řBHRJ#~e)vÑZ k;(݌Q06Xmu/BGydea2ӯQ^CJ[=j#T :i17|Li1f.GΥi+;3mOŨ;)4![=lw׺tQOBG.|g6_(jPYCtb;#ʠmԵlpޙ$kT럆*|m 9h ca'&s=gI XhIe3QLW.?lBTyl 8d{ğYZâA5Ҽ(F8va~CAqKdoxnhiT,%EjI_ʻL" J^E|1z=Y M[zoKFӃ>/oW1&CdEcZf-}#LU{m2- )Z 2ӟ75 G0#cLTp[nZ .i,޶}*g=.G fųF4♹na-ȯ7Nk>('i{H~jϻj1E`[D0<ez1H˦sЀa/E>}-`,(Lˠ\u,~vD^n}{]5lWRI 8 vBIk [zjѿoW:^ut"[_a7΋p̵͘OF!vk6:w@2< T&`_UP#?K?$񊔸|4M[*K5t!d#_! I7Vv|`Iz%7_pGlK Poz 1}6HHs-yE%bP"{(/fd De;ܻTj[zAųzث ƒ-}b5,ᆙģ{ 8G/%"W x3lk }?92.T')A= i(S[k7`B{: .2-.sSR޶xO%N!DpM\آB12Bjlkޟ#v7d&| e}xX.wao)¬4&TL#'\gAZ7rg%l!{oWg "a8 > j+J2aÍϧ,rWt”EE=YcuBaqET?Yd/ݐ*u]HAr)8qMͭ2[+%YRn$JVLڇQ\ʣ qڄeuV YD7$ /dH#kSB,- P6 ;arU^] "N s n=&!{FH t3'~'1xK̀8oDDKa4 i$~scNH:9_ʪ[V/ijV`eCS9VX . _P^˃eD2J7p6WyG 0G>% !͛lRq̓mLfVn}z(2X#!;(ιNf6$ xIN%t&1$4+Ylx5CZ13U2/o Q836; >A,XłNBz۸[>PE%[Hbu.^\絃%ct|j( D 9bKgĶ'Q#9rd)%Rz . I^GVj߀)7ep-fRfu?s%<Ή܇X'~Қ*F5}9P5^6y\ /(^s zw+<+M|,;c5 iH/}keN硔+A]7}|bE=1i֛nY'U*bȒQu;˰0Pt#ԯ]T6Wvt{I, K(3ç[L2gY:QPM-| G}&uK<g+ւ}c,25!|oDÒ!6xg/*-.m$nwFQdg0>h1c:9*caݳv8*0L'czR'ʫ5ۼ-"m̌&׹\$oxNnl==ɢGE@2M7%F+7@@τIU.;+@=C-,H.r@ #)Ԏ}wvS@B&sj2,s >OLEP'qly0ri f(Ϛ6⌞Ź}6$H+,n8e2Pn#": bބclrݦXjҢ%-y* d>cg3%x{Z #z05t ԥ׸IYk2"xW'vKM+@uLRO-g\ WUZ9ጲ7ᒡi=ٰ< Hs>h$4פ:N^QM_fEmmh-}l x;gHJōc"\ ލx OVg{. dctBFuv۹ dx>1)tf(b;#0ȩ6;6ux`]ٻRAap$W>E*6x1dW+w6dPTAC:C+,m+ aS;cVNߡ,]\!}^YcTr@Noq9ԪmVdlvD?a(p!hѕOI:x'8A9kBK$f&/?m!ZvJ4xǸSJSMXY5^ƨeʥԛQ &`!Zx@VkD,tntרCLf%DȖI&TUh`nRtl?tE@Вa#hϢ!0j#>&K[@>WW<߱JJ}}ŗK2uz.E/BP|!MܞEz#" 2}Y|&83  Sctc6UY($Up}2cf4rTP9 fl*,-Y!V1eJފּ;]' U䧇c5]˷g&~qV:FfaA XեW΅MTUR殐a>!m#褀/;GԢG<"FS9ơZwfǤ%hT!n_ _eIɛ06;|3VM.9נjVUM85}_וmؔqZOAӛbrՇnj~XծTЅ ԺU5ja"&ԦԲNn4\*[Hi3RpT|P͋S-4JjJhw󪄳bv G"7g!'1ɝmG4ktrA Ui {#̸t$j?)#Ɉ F|͋fg{c[#Y?%HZ" t?8gT BArz݋Ok}VzD-KyaRy 0EDDd@>m&MlԚDO6Φ. QIsXx%Àf 7O*kU$ Q#h8c2`3LgzJ"ۨD[8,l(wB/Ln}Y'HЧl2AFx1$*i“ Rڛ`Fy1iSM"0Ղ?FC$ vQ]rRڽZ+<7V| ;)%,$OtLg#ڠ^gfOf})rth mT񋛟9]/UI"q&B 3*wɘybz_BLETTI%&Oe&siq=[l0GFU%k0S.6ynI xTeڨ!X}$l)Ah7R$SH9uQ=gSVzdg_dLl.S~uPQ,|`rWS 2|(cH3`\ycY!1 B2F&oVUas&ڽ0E]?v%]#&inVcgut,K BH"ZQR8>DtgR8T!~lEdx]2,f_MgKuو0$uzÉ8FnnI}`Nu2adȢ9C ж1@0_f-5YKl._UY1"6VRtmИA֡?qBsPAvM{q]K6T{tĤT?e"GﳈH{QP|ZPh4bi1>̴zB m\ #I64JݛbǛtTQ /3a$8_ 0` cN5x.u}s}hb\oġ;p$ͤj wn@]R7N7JyP*0 |,xUAp<&o&,|Iom=SӾ'w͘ܢQ,9ӶZP4 r F{R^+W.til>bBo͢Cy> }X6Vd1wُŞ%~ziN̢fSN+Ñr}+&LE0'=Aq%[?29U}ZcG^۟r%W-,8CnpQx7`'٫dyCx(v%.*^!|{|7oE}g G1*hNy|d&PʕT/pF:羛I2!$[> :H D*I՞ϨkSI_5#̞L)Fa*%$v&P6xH#"u'5AǮvaы*`kXҪB$%3X6JkΔ-YyxBpu4a|6'tc(b;^^?F">x[ryl" om*g$3Rӆj8\~DžKmqbndi,-NqMQ>Ig [Atz? |U`w7\;$ѱ[*LQ 0rAO4aAfx] ̩LjJZC\T"2?-3cJ1 @jƟZ+gJ &ܭLPl2#U$<@G~[n`g2(mJci oϸ4i̊e)E`̕^Pzm<ЉD)BfM>l]%o7Nv8;bnlO96ЯY-Yʲ/1?1roFӔ dǙIxb<(2~=u@AӘQ#mI3ZX9ft5݄,O 5uA ,[D9s4QaafXU%-"?xS8y}Μ(\^}JAF*kkjB+Bvz 2Џ:Klw2I܄;uh+F=%wTq"w=GˋU$cMB8y.S3ukgP>bd8"# )ZF+ ʣlrUo=B"4Y (H^1<unJ7&{h~ iwI ȏ\EbdG.7QtGXg⢄-Qb֧1נZ aQ_n^)WA)R L~gZ@D=`X׾QRpyXPG Vq(S^`9@=DBj&>&x"( @VyLC3s@Y]\k}cNJov\G2W8 .߱\$ W,+\3*Kǩ 5uvb{ձ XwpQ<"OG3K{[ɓwd:ò!h9&Nm2l. 1'.]m斍?|h9IʗAYcH^WHC4]6Q?V3 Տ xQGְD"C+o$*^I(oCĽ3Rbrzs.}q|$e@ciE >V~f. \B.R- D-Ϸd[+AK\$W!,(2= l9g'GTqdeڝ3D듞TU}HUq=xk YYКVMH*G,.Wwmwf笷 Y QQw%{'Jeų=fd/ U+`nnn2|""M&;0y:"EC—T!o yH+ ҄u]rsMB[l$ɉx'c)Qj:؆.Mlxn\ƃ [g~@B4d؝}ǗuljzvTG迾,;]zlPr#j=oe4^M#shYcʒ@vXqs0elj6 Ug+vJ~9fpߖi ,Z¢*,gYUOB,."Gy ShGmbK@5vt!u}KG"e$yq6^s)^A"uw gxGS]=HOqFIBV+I7(G(-N.)kx؄I$;S杉F`1J_XӅiȘY3w0֮;=R @z]kt=QưywE2ᙀZ)6fT5}(~9FZ[ԋtI%V&^zq͈פ1LZlY?5y\y%'11HNgkBP6J蟮|FDRo^8a84;ޭin/:M㤡XbUFQ᭼%F E{r# ǎ_ƽ5yT6L `5HiSKN3L /h t 0RAO.lZj B/jy^-|k͵b(^V@"iy}HԽ*u!75-ۢD#RFDS<\}#[זDUqꢧ5ATr=% SˊKԬנB"k;+ևT%\x=[[~Mb'*v^4Ehl_)Z j9w R qnZe0q!\)$V3 [)'~<3\f -4Կp]4x.pCDZV3{lZ?_Q/(B#}0T'ingQ_%|XLpvYc=4} t6uom,s7:VfXKC5ކ3}( ^',77NK8׈8aۦ"jVa!Q=? ߭Ҭ;GE3Bd=wc@[ o!{81 5\C'`OޞɟWM8[fҞoip݃;p|a 4~@x&P!͘sc3!w4 %@4Z7@nEySr<HߏJHx9YV,> Ftn]Q~"]uMֳCk_[QAN @~0?l]&lUkc, i([1mMg6S}nZ\ NAZ xK ]-B)X|g[٣d•72WMJ;z5xy^;WdA5n<<%ħ+frR1uɋu{@LrYW$Ӽ5xOO7W B.hYgH,O.Vp+ʾmFs%+ G3!P"#OLI[-ʱ40y WK dRyk ~ON8:7> KM.!N<՜p7H[d$.{k/ѯ f$1hyqHQL{|^7[>D]89&aGzEH+*zE"C >N^"7)Q#}^V.7u9-Cz Ch V\:t,ivoJY\ɬ)NXCv$~n֏X87TS8-`3Fx⚌~>JpL1a=Ey_/>{e59kj&c*[+'vPMZHޒz'7^} Gs{?z>z&&=V ?OP[C*_% K5fneu^$P3[$/?{raV6;ُtZ8Z+680&=ЖTE:~-i;]h \uDcfg_54v6cup,Ës61`g!>0; (fLrKړ;ж`(xQt?w-.tCL4r(bUra:N.fx9NOKt t,oYpqUlhpaԚlgsZ%wtDL*XGu !xvӚA_ǹk7QFdN Q/|~8YN]_>):BHmBQD£3N6T4g̈́&!8~cG|w37Ah4?FI GjF]T >*]+@[' /.$;gkyQLn'ۏX,;WK֟ bxn&/4F@s hql␽Sa^G0ژCμ4-uƒv#ѣ ne*db?\Sٕ=;&lSm;.%eYMbw `݀q%ϕD =92Ѿ4/ b$ҩڈFRm H&'8;ZY,(m6Ajӄ6;qq4B茮m֝m'T&WqMqq,!<+&@#R.'nd^Yԕ36'\X_7-i3In$ eKJc砕hxqX+PQ}$J56$:p:B3Y E ѿ&[O僝X9"b_ZZb, ͡fwk\H `M6qoXѢU[P+jj}@]3} ˭>#`h3>_DzDE5Lj;+az*al48Zz½VõFm ;aB=gS&;+s9 ~naٶ\]RtW"N7WL[ W'=0/Ѵmn7`7ז/_!U=Κ.nk YȬs qilmxU}hʕW]w ZkوIj% tb9&kP/ / \:QkcYrrSh[PWtӹU 0l+a 6Ê(;4(Ґ܆J1; 4TDҒކ)O+MGHiSU &-Mo,a)uC[ Y:A3Yb,kҗьc!da|Ga@6cq2f_R("+R3V? ė$ԧ_50)rKμԯ^KĝC;<ս( ##`GL~/ )Ư /%P=W燥Tp]Eʳc~I@Cv`:ى:&M_D2ꇡrzBrY2|&5HD+vBڳNjr<:%k6CTrngE}AnsF5Z?e yi/ KNOXgk< ,6lfXD/ү; Ge~X[wx}e  4U Dk/Ż;oFvgyjmrH GܴՉ32-NWP(7/xCۿԃG3>LoDž fp@ޖ_FEƝ92AˈJ쯖&BL;7~@(Nǔ9uBj7}䩪毴A9$a?Wn!i SH7K G}of ePGjˏ5r"[+DD;bګgh٭iz ]PeHnQD >LWج@k v?˲ߙ@T?;9؅S 65P-bl $s=Cbl9Y>QBNnr'UB(oֳp=q 27v(gF,[*+Wr" 5J Dvqd ʀ3xS!|M kxbkć!*RW6ŏTkX5Yj- ƂqJ9=VtKO!L~~9ͺ\9^T|&hpEa E.LNtD]@bp[, ͣmZ)b/[(&F@Kcy7[rJUMie(VV-IX"Wu&H-I9K!Bg6Ӱ{] Zbfd#> d -|H/[hYE%t-SCG;;ȹ%*.TH/`=Icزk^(Бjc4_l|Nj-(F'5u5[q@ʄjWyO[햟 l-Ȩp5ԀV qlPމ? ^cHF~ V#4A37Q(aMIz\orcgF{7_(73y&H9vFp2΢Hr7ݨ*S-m9f-"S);ʼnűϱ0ϫ^X9ڇ汧թn|7 ΈŽEBup乹Q>'A' t9ޞ 7^TՌZ\~9B -j㭎9USOI<.=|.tkD0E?IqwzQ.j!BDJc*B֞ s'b-g*2"Gs=@&k?H ),8r igI,mt$eiF`IzNΉ.HQII[.F7gmzol  $Ix4b{Q=0d`hXE3Bݷu|+xkL= 5Ot rj%RI`W9&%Q' S n݄>ׇ&頒~yM! X}3H֗qXĖ[]S>a>LxàyyIQ-(H[=!t 7vI. uEv){=YDO=ɡ.4y-=4z'fVɬay ̉|RIAL)HȇP"=O_N*gNZ1a|FWbx=Ʉ9oa<<pTI{\az1ҥmÀ {MLk;ƃ_ۇ+nɟ.2kCu~lcuţ ߒY&Pg =S>m'riDԫL}ɱp֞]ݾ.QY"գxnҢH(b\M,/kCg*I\ː3ܨbLt1mz3U| \'hNQ#Uvxb0URVig-=XJA$z^ݛM<0 L"pZH%~EK=Xk.¦Xߑ<`OJM}abBv"04S^Z/].?Ҵp1k,T7/sHw+e/Q;_{vAD7ѻ+e\_Tq  3|]7QewױմH0C3*s!G+=*q`tY`@r!R?;0% YήHD"ŞR[ 6T,>խ<__T֑x'^{Wv7/Y^u{vK W&F'f BtLN>vױ#mdv-Y%?RF2}ZO9oRm>px6N m󁓰SBݰ<" U퉚|"I)<}gv<:n*}g0T$:jgYreXENh`ʳ31bOUpPY=5*+V>n KӤ;{𖮖w"LKn`aAj oaϰ?,pueR?ceoDZ!Z8( )jHD-#ށOt o84Rqq^{^İ;SJUY^'|"9M&r1*vTӉr$Iz6 v(wKYg?YD~G)D =7nNy1(/+(9{^EZ'g`=ۜbfqFA"!rɘnd}}gƒׂ̉67$ܧiOzӗ130V:v 1 D_' (CGƹs1[`n/dSvekÛr-nV)O1Btʹҙ049-wJM݊y}7p2K;\$*Up#)\8A4&x7^^`4^LTYZ5eVoc" RC{sle;Fȕ}}p ')ci+.(m(t&<̃I=P4g;^/ᄉMŎj.$H1PyA-ūK18M2m8<iAL}vfyg=̀۠Ck:,v{9.׸AqL)Cax-,%U Www>JV+M+fbcLWɈўV~9,*)۹:YĚ>H;$`k[w\^HB fo$bn"%$WEkuXL]^\3Y9sN?]5Dcyѧ L&g>SMk$`N?s3ncpF1%g2xMGnz&\]12=vKyCz5bn |v 9@p7["k-Cb$MxA`ZȝoX= zH\V⁣VWXB,DXQj7Q?bH2ěB`w[)C?LiH~$B{`aۡba=vfp|OFĐmQ_^`.rsxn_!ע0ʷ mw{v2|[`ټ OHώ+K);2׊1ՅU6Ts9wۗڠ,}fΟ =џ&;,oMW'l_ ҊF ֢@;=xZ^e^t~vtZz8A@/ai^"yES&M'먴|x`DRޏZ)CD4Yj5m>`]gS:^y9"I+٪^߉CĔy/d#Ppi!H6( )XjnIlltB7 k4mh _VB iSY"@/d%9AҎ18re7eN m)IV-l KĥrE I@2Vb#ig[ǓNN ܯlƝǛ6  5;J#1G2K?{s tfr>Kδ>yFXMMbIIi޵ւn 8-"lj[:|6#?*.]8b;xZZSՂKՋda<鼙Ŵ!>bnJgT zH! pQa)TyJ4xxڈ;<\icg@uLWXGe-һ8m< ;c20 }Xl+NEM' iSx@+qpu%iCF$}ҞYU?V("dޯOEEh|5Wsa9\G⊬voX2PͲ&(QtI9S4=ϯC2so/͞^F X=jx.cOk=ƒx}IH^]:FvM:c3ϣm~w*}ox;e `9ݣ-iϑD[ֈQFgwAl,6lf$*`ߤo;AC,揃jR=}Y_+:o,WJ,? -/M!6K酅 /%/Ama3δ ["u+(q+l˷SoO rq\;C;e}ڍOZYt_* o|quץCNo+9ن(˥ !_ stPXֲ YUOFӴRa0Qoex:噋\o蓇ݾ[b,Vb! 3W0E?A೰gG37R7CzUB񋩢2U&7>^y@5)GG '-+ob'zp3OVh~8ѣy LXNd+ k'Dll|ylNW* s#= XXMtHFiTsmILaO l6M|W' 2ԋua_^2zfH;9w'\N /uf9搽f6"T&)r)C޲w|OϐO".xg@KoG-¯ QQ9u ?aXZSXQ|N:4"0=4AɰΔmy(Czl0h\Tݚt]-("4/*wfǺ 2-G-'iTNS0@&^g"ɾnd4Z&J7c\VӹVlpdҮ.uhd,:6B*@ekD( Е5<ǓH |8w)PZ@9{?\gѸ(bajNK lμ{vn;f #2*CR3yP*bH"2o0|<0 cɛZt Ч QS@OD@newQJ2>8xsyv(VW. S$p1츁 lCygVx6] ^deٟZ`&BCpR rKdNe"_͟w/Kbf@Pjz{*V\,^48C_ n:kĎmnpO59RؕWh(p^*;o'=`*'L0877p ㍛((hC+6Z `J6]vQbMZ@qC0o8$ [pW.d]> =ZTЊ*o.+Q>CR5r1_SLz}VYuGq* Y^<ɘn 97D|W:Me/!F yrtI5KN#c=+T_ ؼuV,ZH! V]AQI252^{Zu{Ukm(ФjL|} dUUJRu;N.l$ $zU?n9qM.*vz;ZfL^ /pgc=W".${HG)Z?-υ ه a"췱~btB)^ܡ%tL-Cq05}! r{$QSzwuI=C'<~~ʱᭈez1 ;]1= ݦ&_ԖH@c&3 xD[GbxJu\Ry+I4뗤Yn ꒞$΄B-ʊW2r,FCSꨎh$CE5} ⿭hW!Tb,lP:#FL/TH 7ٰ yes`vA#$id9dY#Q Pƪ1b%=`'+)o1]sNΫf= F|~mf#+5m*8F 2EV0UKNL<_Eu iL4B'ib^Fd]snmJ}d{=;152~ ݷS;u3-㌑R8!ϏߟZOkC7h1\E,jvyFV7%1-TX69M/+w:LI̞#R&VM!CTj觻!QTUʼbI8YKbpc(V_9P!]_pX,*LI%GkrCy#^x_ >i8af2"#X MTrE9j3Ee*j8F(.F #)P? r ņx%9-`<;*#$Cڌҫ"UqK-8 ҃[i9{eW %zײ.>>Q:&OV)g Sx`4GK;8DŽACEQ iGHCJ\WTo}k6F}p*ha:[:;9z?u;S!Ŗ嵜LThFڜB  Z#y6['/'_\|gtO9cا_T*VL-qL10Gy!m1 ;2g4:Z@}y9!Ĭ,*?}MJ] #i+AC 9 '4WXځ0c<7]M(Ov(b"fuv9rr5s)uU2y +l4Oơ+>3_ךVƥ6U$;|e,}? ;2~uk-Ùi%ܨ ؔI!18s1^G8J{B1)7_@}D[av>,ci-{\E# ,)zé,4FŢߤA9f[pqVz tƨ,Z#Դ7JI-JML\8`D>``o5f3ѮSDR"9Rϋ 8M8ϴZ+e(OfV{8u u+|LG-@<e"{{oI9{)tF>>9nqiu7(7ͮGB%73rmփ%}MqlGiDC\9ۇM2 VqԾ4-܏sʋ QV =LR77߮V,xp_ic׾$Eb1x%)+:Rqk zvz3{Jk: =SrA9,k;ځwx.WE]Nfar'}XY679f:T&kwiϊ4Rr\~S:,(-m{~lG%wE&E^%Pmpu57,FK(Tkpr<þŭ^& lPTn-xKK6a ѻ~8J'MM3IT)'Ҍʃq7e'M-(6͌f^zu9_K!zh5LH(C 4n3"Qp01fMތ`s sLj +Q5*Fy,"t([̏7]ds*݃ Qtߪ",#[HsoAh*:*Q8'a譅 1Ȝſ:պb:YEКSWy<Ȩ-lR9=gطYLIi_TO<=ej>?y}ypY"䐄.$5_y/m'~ݏiHWy<*&~!Pŋ'a@PX`;ɞnoGcS 0l(>o-n}oRwcK/UTڷqQ +KK׃G,`Na6x' 8MWx[|Ly{! Äc"|jzw/.Zy2qOmcO2+uَI #;8Y=%%9Ieh\UnDUoʕkY 6?s⹦HܚC[7 reRSH cD޴3} q& YmlOkց^5XLf.ὩHv@̖#0q=/ʳ|=(]6*J(h5Z H] 2$yc^kg]6e2$ O  /Q@@CrU]_$`>_,̊d&0nz_MVB0EELVQbn ,V\c?&az)}t@%4|<1 aVm X!,Q C Wݐ rZ}ѥӀdqQRt:*RW؊/Q 0r-v>& @\ƅFOl؛ʇtU_J(4 %9J Q,=mkˌ+> ~ _S[&X7Q_Cz) uMr'X{{J.AAIcy o3!q0-8>JxJ BUVy]OMH#]}ԟqv=Z$1"ꓑ͍\t*v 4*GVU,<mJ Dͳ,i01&Z|R +FΝIj BD&.Vxz[RXe]O"c0(r$B*~rT(=zc{|Q!C` @PMŮFdjRtABE'ޘy7,ѷwtY.-yC/VnPW70^^DgbcQW*|>#2UR6J[,06^bIK^nUz=@Rވx4"@ %x5y~#wKF-fa$eVw+;)1|M },VvFǰvx6 ܷzxpF9P|J3z}VGF;sj \?fԭd{@rZ擑GzYo? v5M! n`l TV"(Av:zMتl 6 XJ[#1Y$aھMND&yl_(iv4\RڟRA+k_2F>y /vHҫX#>#j PH6翧efqU8:Pby4.+$uUrg{$:/ XU,)Wo# f`6>UPu쁲E˅+HeWyk(?r^!_waFuXniܖ`q͈1 h" 9_H !%iQK<`=-j : o7Jsm` 9 ;ZOچ V7E0]vh|htQ>),]ZUD*2q[GUåKZ${-8`$$w tʹ}{ܸGW8 KM#~oO)k )ةI4yIg`OG%g_RRd > #9`#$Q\_3/R9\ T2UDaK竓mIDpݘΰ݀ýY{#N]o8Z ֕˺[> ,So^#D|jo`6ِka9O0P֫5)ykŒY޷ji:$|n$~E炐ɧJUR@Cmwoz\g>憀e!>!N*\?c&ڳ|ɉwv /}:5h,;fclyr÷ZT8yȂZ\9I1omR2ЊT - }|u?!:!*L Ru(ޥbˠ1؊wx⮋mZ :6{Qĥ*֯q-d{f(103NfIO OR|=&=Ѣ6#(j;W_ՖǾT֡"U9|oAp<5b$>&"$t·6C⦝1YY9&cqR5lxL@+*˕4V3ȭ=gynIͳH.ah]I Bf8F9jC^Lԩ8 R]z Z>shY0==,F|fyR!v,v;t^;7 0rswT6R^1Ѓ`3KkQ=; L͞+դP0% hBGp_.*ڦOVxȕ" Zdjbۼgl˾\:| 8=xt7fH%@:iֱ}2T-|HƶP2JݐVbT2r!0*w_S3"*=n©^ӻsjL/ctu^J<~IRZ ";%C$DyP+U3ul^2u­S- I;k,fz ڑ%7[iRmK=NDϠ'\Kܤm\j?4bVUțe%()3#V9jN# Jx]F%Y8'}]4)51eM7 IK#zfx!AknUNFHj?K9F C!8BrD'SuwtVV^ ;%GN-{`Q:rl~ƲZpCaybg">9ꊨ=\. k,ڀt}x~pm)δ޶]9"o׼WzkS{.ęZKVI"V;Wv׳5NÅ]Ô{NUd$!Yy`ABBZzG2 -<;Wmeip0HژIȊrV~G(bѮTu6"l9ſsÍzvٍLi w:CEQGBBjbQR/ 4pOURΐ Y:8u+b5҃`>Z"WRjrh(nG>#V)%s)@ӟud *xy&v>P9la)3XJf[8Kx dJUK tˏgYiGt*Ӳ A7@0+1!ֱ@Gg eXY\lc\OGc݃N~bKF荥sWՑ;ooFzNR w @\' )#r  eG0Z@1g50[7\AfM̔]mC[LcIjQ)5B{Y׽@ kً|S2?ɩtఓJ^i"Ѐ8Gr1OȦf@"X;."&HBSX LKzҒ(vbuݜNdXgzTɽ|Og{΀O<7JPɋpr#I8r߱|`N${6k&D AxKc,eYa~Ytڵŕ%ˎb3tL#̠4vCpQazK`6:ǹ/FLeWY</Tj,nKm& #&"5 9(RV)bkϦXEhi@!Q  өZ-qPWnIϻMW%C-_z06$?8_?ѦLlqCEHyi=\A)^rNv̂Cd?H@8Iۘ"YR'*)P!w5љ kzɸ~:S~ja*Oy1"ZTD_vqD.7pF8 JFr/_Ba`ؒ+%Czb!y^rı V:-"Wa2ޯul ɝD(ۜH\eg$?-rTN*,R./i+RtJxh p@wHQ4 c:YXuO0iL]n͐wI3x2ӀkCm9?\wT!D<9sEz0}qBFhwlQDU忤a| z0e͉e$2WT UIKo>YC@o!$b-HI"|i:b 0W~:3fA nŵrZYXYJ ܴEg8Ht#ˬtc-Nuqlj1m}%MމcN Tļ21.ỷ'\6r7b'̡T+ldx4[ P:,ԙ>,<9WG-gc'[*Rz\J;rfnM.:mۅvQDLW7>1,zl`k.ENa8LEurF +T5s? UtUX6^|})v.]=+RwONÎ=DC|U?h|+K]zYfowP}Cx-,-?׵^-)[ȋFE_ k~U˪a sPe8Kʏzl.|N}%T6^3q>eM J:alkRgy>`DBPYJehW.&b[$*ĦIeu'1b|"C|hʗ(Oe8=<8߼Q{V}U?q 0|!fw*ʳIWɅ} *LM Hf>o-U (-m*m/+p|Qaxx<5fс+%:m?I.lT^*yy2w<7t1wS^w"nN,z?POE ŸgfJK[ e9*#tb{60Vh 6D@rg4K[ܺd3jK X2#1CExո?Ɉ+6{zuL0ry:Kq{b\-W+ahϯ$\۟d4qP0R7SVLy5O9=UC:CXiI9aBEK0S'׺z^4B1!RQ~ i̤ 4 Шj*R~2{Mke;5!hA \_KurZ =ߑS3iI"xXP1i4ۤ= V#97BEx\@IS25i`̳e,}׃`mk>rN[D-6(.pVCo:2<n3d;+r`!,^윻1$DAqt# 7m)eӇ:r_9wm`cA'b1>eH% !z5x!xGS.όjooğ$3w^ H9V }hz-F.y{oT~(JT[(GOqD%z4C2Z8񚐫^,1z>'[:kWpGy໾O_G ? @~ { i:H{()5҇bR=y{⌫*)g]]ھ,t8ĄQDckX{hˤM֭=uY| InxEϺJZ@X@ V+D&ɚdR<IV; FzZ$0.(g4E fW]KV)kQ{|;zĕT _mdE9=@`$$5{}9'5Y+2o?:E&c_ǔƷ^Exr?WU G"Z\ġC'`W&]!$_S︎a-? UK6sp>`כ_nka(Wvcʸ\Ӟy$teWbabս B?/)z,jqd"s]3"]YM}bHn ]`->\YZ[)Fw%Crf~2t `V a@9u{blqO=ċAzn4 bϸ6Y[cq!t)\F3R^[0v$%=.:`7N'Ɂʾ8q,/ Eod]S>>e_;n[(DC wN9N%Worąh]?UVB4?8+VکtְD;7)]-itV(bMRF5!{M~%f垜 S9i o-7 (d ) ˉ7;&'^=)i r46\'{& v6[*]mM͔vp_x*:u[FG\-jX>\YcHgz3n˵2 ay/6n,%{LD(I#gtƞ^ Q`TS_r,߅1磄">^u6]$C2^C@A(E"뙷h'!fj5üNfnqAՂxAo%HAlj";WڡxJWg@P4[-HK7J+@!vh.p̋:2 V !-9ןmҔ; chRNI>G?"KRླ50Bĸk4FH[{a.rfp܅oF RA*8HvtػF}S* bm`oc TtP ElD ΄$% y1EElfr<_eЩHiS6Pg9:Vnh9\;5DI`SPҩ@vM/Gbr?SB,&J5eY&|,4|nkX߯TiVl[Vdb5qkܵTvZ4`%\VnEϳ-&^ڑ۟@ECqB6~eLz sk~OE:=?@I+̀uÐYv 'Pt^Z7X9љc?M8vxxoCvux4azX!gjdpշRXQ_9i_ٗͶ+|]>1 ԹI?ʬtvüFud; $@,? 5o(x7tb]6'v|hYfKEY@圧FRʒS d!E4-/ /`yG0Q{%uYWTřMJeؐBA狗nv|A#03i9oUqXI>3%/p٘EKr1Z0#6m~&T=S:-?86uACKy`rYS>h,O֐%r!9I6  hٹNc˼;ɲz4֐jDU> W 8\kDe(:gHņqҗ 5Fwt|E L|ju8>˚įC !o?2DMXd|j-IhD$f7kY pZ+؉OCu"7W ï?CZ[E[ ? /D Aro,;'Iud֜SZjijMġ6u1z@";oAP*3C0ukp:3LK"4uhAk:վ`n"G/cr TQFcBaw}u}!o("gՅ^@Gŷ>‘I%msJU :b 4ra0J<8au&nrojj `%#Xc2??htIk+WA|>(%G?2iXnC0 E|DQjA:߄Cxko+juܵy5Ƌ1S_lXU) R;),,s=5L+Sl:RO:ҘA˟t5-,eeYS&|XHD \f⼷Ń7|@m 28߳ t25\uUp[q4"G/D'1>9wZEb$yvS?er,yMe j++ "Viq%t¢ʇ$0y!J 6$t\֫ojDSۆ?v`b @6`!1 jOj˂#6Jp۴@/|1awٖB^MB!J$v ΩYQD4 'ŏk\[Os4?}%j(nf|=V0zB4FrX;X-`a6={\QT+]c;憩D(y!j%JTW(R>4< v\3:i0jf_@~*fB]Csoض̡Oxi 2*ka酸"K?`/ :PS lw&bU[3;x[xYz$p7_kG}'7Ђfꛡ:2lime'.-57| q=ZM_fr%D1}'Nif~owqz!,EWgK= 6NFQM ޸r.N 9:R`5Md_2~+[-ϰcu> YW)qNаM+@͕te,O,hݹHDA7f9*g+F-U[a..+eLm$ UluP1xf{4XD/oBZ+:J?=cơ;_D^uۂ 69IHxtMe;7`hۻ|xNV XnWj:AxF&h;#%jsFMYy0=GI`LO \j:589bۚ1qtep/$?daO.Y-Mb04sSPuH3e1co,dɈ&O:$VaW}WoZW< "7Y1zTRu݈b<)B,y`|lKnj[ oACטUsJ'O?z&D(6CUT{ 1Ā&%#-gZ(J劁!ܫJC[.C)L^2NKpsBR1}o<-A!>x"@3uJE9J_ Qo>aG~2)3?qwzZ.mv`+aolω=PLJRLWPJ饨l65B|PleY5Y-c22O'y'>@~QzQ֒C:R·6 "mȯuS7#Aμ .иȜ?ʆ0Õx1F"}TLNBg)o?BX{[,L0{kpS&F9$}K^$;u)ގȉ*"W7&Ӄ`4Zs`(.43vYz %E]v?-MZ ]0Aoz?. 9K\~׉Ol)p}RڛEVvaئa}a^;$FMUhUDZ p({[+_-]| kzrƋyU(/ 鴥3wR0޳>YqvN{ !*JEyN/֌52R\l [0Lٷ&wOWj5*&M \i3zzHe\Yli\H.ӬC{uIv[bm9Oeu*ԩ(~71󚽌O|} 7;Hka܈vȹt`C.W{%R7νK>  [#Cd{CD6ZxrE}gMPM8i9l2|rlWK!+_ Q)9u3s3caOp?k4HS_Kh Fsk-EqBڷV6vRޝ"pP )rf|1\-2\0Tz{n!U{ ߆wkbU#DIH4>3. g-x>* + {w2-Lj$7qZxN}%0<|.@dsW5Biu[oˠNTmݝyd*iӕV"ǿ^CtA $zAXeYM0`u۽Oe voI]| /Hs)*j ueD<llJZ>W6HNy!~V B>FQWXSX9=p_,T~ORm .DYuD"ڐƅI QAeqs%vɍ54RCXIM Vkaԅ] wt{,"2F>q5R9.m ='za[z;…Fc>f@ $FC=(%wmlnɛ j& MkBԷߟ| #1{WC94ٙ<yAʀzj> x wM{tAnBύ7+5`t_3ƛxM g-*M*CCJl:sH&_-ž kg"\.*" wL:B¢N$bƒluaZNT] ?r7L+q(1S2ކsǕz _QnP6ɶPFDUp@>s+htY }FZƋf%+er4X2Ôu`.Լ̌F6H,ӕF7kBo )$i-HqADs𒍏]؈b-iCJm|a/̇Dpk%e|B5wȯyudq#3Bin{ְ?,3ӻ~@!z$IJ-θaK+]e{x{2ٽ='8MzKi7ɹ8i3 "aMiJaʞ۬+syiXkLF>{ ٕiTǤ|jdxq[c ҭ' hxd.Ln[зwoA 8*f9;t\a9:xSZ( ?$!#l}ZK$JB㪋פ8_)|+)~E;HXЍF-pŒ8VvK1͡6YTDgdÒ^E;i#Yg>Tn!SܯHAgSN8᭕5!JēJ %sĚiB(tu-BQ"%f`4KK#InKQʻ5j@]UЌQ(5 ?.RKt;~t/x]PL#}ɗh6E T=QsARR]&(\aN:0H翊:':mBRPkoJ`@WDj^B _$ErԐfjӄ9r6p $}T0ګMYE'EK݅aa<p3UԬ~@gȜTo+~-+Njܮve1cY׏Em!qw[L"*%(T`16o J _h*f!q05^.0,V ~~ΐ8o SwN~[%I՗< ҧ:4/δFbM}W'1_~R߄.*qi\Ty;czug6 fŅZ2o(MPFyRaH܈TjKS\ݚ d QG7I6(I1y.YxUӴ恥A!-|V"G̡G+Ԙk: &I1d,cc:R&ۊ]]MH'ёO:vb_k(>ذ{Gz/jD_ݸ_ ~ӷSF:v!߼+~U>Z˔`QunC,+0*iӝcwS R۵XP}jut zϝEHG 5^|g{Wɞ_t{_khXE{xwffw^bxv'xyؖB1FLtR(tqMHi;,|FW6)[hL8+;@QCp6"JP…׫E\?QpD?#&A<4"Y@R:5e],=ַT ULY8?c~+2] [+N'$To,dX|C t(J朕cČᰈ]銆 j8?o[i<ƼNMޮiej/)ᒢd=5)-TojHJcNI;E2yN=T ӺC `R>k0YJ/:\B۾]S+3Fj\UNGn0.;A;vol!{\ uBrlՇeN߼ ba7joI`5΍Gwafes; |sΌ|鼺_Y6 W iYy2G-Ym7c}ÇbtWLJZ[硕/ zҤjGB;(P㸔[g,;O9sbQUM/RuTy<.+HTsdՐqqT^"?:QB|(BmFũ6Mć S;V>q,>^)su/0GL A4~=BtecS_{ygr?R9t*dQ ש '<͈9׬^Zӌ$ ۳5`& L]̐JEeGNE֤ aNd`|FW/1HJ.Ckc(yh޷joy_"ψ6 /KӬֻ(G"^glln\b6$C=: EAF)NEG5m(et[ە_i3BSGAW=B 1s$1bnNFnG،x|Y/Aɛi12mhV6Z̈CmiD5Ȼ :5;ԩX傏?|&8WSHKէUx4#P*Y@3B ?c 6PJ 0 5rgM0,:Er-demiI*"0FS([L_bE =*S3u c U跆6 ÙӨ{[&V6#)_eHiU2#}]G%⏆5zr"voMIU"3+Eld;`Zy8؇q0 7#T( *S5i~47yxh77WQ2c*~:*ݯ2GQ5lMl\X";C%ZCj>鉯Zpqˇ+Ưˠ#.$v //O%62@''qmduTiѮ#l y纋5{Tnړ\jnGMrxYg%ʍHC[v {Kml#6d R7ם mU5Wa!%UE֐ѿ=G``<ɒàr~ h(5rVkgY䱨DÞo:Q1RuexuxdQ݄C})drJ>0C~o;&gMV#sgR)U^zKAsF5#,#ZMg+;UMDN+ Sg>~{g HE唃tJN^S^o}Yߝ sr1Ҩ7gĨ=;s@!Qj!E:9)sߟ:/j4;DMw,vC2y){C\Gj p5ԳdM7}&Lj}7O9mKn HaR]YkH:۹Sta =6+ҪNN|2WET>W%t ӷTCpbbNSiCsY󿢔Ф_ @t`3mM-K0ب1q8+JJ@Ą|\;ex>:aa)S6y..5M=@b? K1߭w՗[auckE=F<=oA,:CA1<ۜOå:D؝/^ h xoRC*d΃ؠ(jaCW::Ek7 O Cz\Fᡄ~%.V]kq0'}LCԧO[N)'׍"~GCW"T<FC3B0j\1WTn/^Zzd۾* ^qO=QJ2pĺ&10)[f*hiض{'tq\E"w$~,Ph2CjrN=,СhޒV<ܯЛi)}d:' w%3/Ct U a^j1Z'D6g5<CbIꦐFsHu_(Jc(Nx͈Q+|ljq弭 Nf8dc?`PGap~䕯d(;;W9;DH!~^*(> ġYV8]}&\~Ri= 7#1&mbq_64>,,c*!}&2SӔq5 ٶ>}ײj`VވCunp=zVCX}gމiO%u6ϧDL-(Xs*Hu~&ծ`evzr7/s#ov9{F`1O9Ē2ORfЈkc.?<ݦ] iZpqisG!QerPbh}ʞu4od8\`PXࢉ0fatk^J=ny8ފ<ϑtm t$nrio=]7ёҼ;6cUVw Hȇ7.ek0y5CZ4-Ð]y0ԽY˜Mߩ;8>Yzѐ9ݠ=)kv~{jKr97](d'y'4b[^{^acGGK&V vm >"ahb@|]t,ͦ%9-Qj㥹3!"|4_ʕ $r3X8 WJ͈g=ڿO0m֊ 1ho'GBAU;l eNe2@ Y1t3cWGjizih3 y5Z}bn0*[j̒%N4+fO?$E s _1]:3ZV3D c$.4bR؆"kXIXd٩@apm ^9VnGX/ ˖!ց|(TcIЎ>2HÐS|tQh(]ZJ]PWǍ+.93 {@h{ٰ8dyIC| K!@n;jF8v'ᡉdNdvWaG|bsh;Mar!Z}v>ΰ1iY%`mu)ssF ΡQ+xcem ^v_QmUͱPTyv`woL\˨Lq~ 7 FGv#G @ˈE];h<-т҄_ r|}c?;:@5~~:n3qk0 c2Un:Y OSA,''|-|#p֥Z n2r+xP7W$O'*q^G wɏkӳ<YR8f,(M΢yA~z K^f݀;5kt fJ\u_q+aEZ=AW]L;E9K Z9{+r/kh=POe>7/dPjMl }/z&C`bΈ(+tk@Py#/zxOmwnc;kZ1<{'^2hx)Ÿ uVE :|35 Fh!#+g܋xh" xu, 8͋I`CGp5s@ԅK sN" &[=шbda^W> k.#.ð$\Kc8n7zImZPI9"FzsQј<}QY9N%88 f}Vo ?\k1Dh6HY7!TAe\cLzC܄mJm=5&nҢР=x Jd#3@ۮfNOA6eO)\X /3҇th!P޴b*V<#">/!oQϕr"z-lb(-:v q06EX\t8qk8L݁Ro= S{Mt@qC=ɫs zri<堊Mc kp:Ao#spTZ|Bg@Hy~aHR_9$ƒC pPw52pI !=)z8N=5g_ݍ`Q J} %Q5+CI}߆9gઁ:/4  D?$$4šb}TFxʗ_$/gBc,M% (ʹn!>ӊN`.{BE~x?H zTIE\I, m=cf$ Hv.WddXek؁ѝڙ43f_ɚҽNkSlaMC)0~"DcFʤE%JwLi.ϣ^Vgfð=IC%v\BUb# z2:b[ ~nD7 ApoT05WR6gaM>Yԕl7\A}HRЮD0*whT%+h4=A@wŋ\? HNGX") p*Vٔ,_ $ B TpfHrƒq^I؋?[!~wZC,JE $iWyexǂ]|yx3k;.r5 *59 R !!u[iOfH q.('wUSa$׾hSOk,#]r}t.LTb /EC5;n{\Q7s-e{ [k&Cc8e{ Z`"4#@.2 !/Ԝu`y:?bee'U9*_eItIcʚF\JpuS8jf&[Cͥ.*#頦%1 {tZ+3< 4Tлb; wƞTn| #_LgYbUZ>uyCkw K+wnXNj-i^/@~[S+a"e[P,*(K/BC<M<@?K !oZû>*EO$CpH^ {.ٚ#Gc_#{i$"=b_ =Gt(t9n`{].|~F%HxDϔ_+AٱXBBBJ J/o\t(;mũeѪ?q㎵j^.s4us`6-Z_>x@>!tBi_u^۹XGaF`jYޛљ$ H-S<$sաf[49H}ytl6ES~./QZ%٫1Hy;}˼[&f6T-6WW,_`q.O&42-N1@gX 6e5c_o̓ 7E耾-v,C[P>-];]~t G<0F1[8]pU_}Zg㲩i8/蓗_X]*=sDb{\ZFNw?HKg5oa$kd~hC]&@;wh]2xjʽ'ܑIA<-a'/@~qyd9tS&A]Xd41xZyUo,ٲJn@ARa7S;>n3ɂKi-8D ˂W Fw@Shk?ԭ(,I DDp ;[W3?DZ|3Pp\?_"%< *3%ϩ sb`zӉuMY៴6CqO핍'Wb{@9DkoQYɾZ٨AYh[`-;wOqbbح~J7`r}Rh0@^pX*aCyuFkY˱s o) gS]L+DJ"D^4П@!𫛚LEe&8͂3g,V_dj\2A45ƽ( *@Ln"*϶=z^r @KoG(XC)%p[+?aܜQm2^3Y2.O0CkRUKSO֢*,7~x4؛/5E2<0Ki@TɎuch2g@; j[Yһq$U2k1z?@hm6rAEv[i6I~JMf bbMdѻPYm\UeJo&řZ@'>~csMJm,TJȥ|,pD ÝS`x'Ö1eh?ixD;VUhb|O}N P_!S@;VT ?ϠJ˻Y, ( v#o.J,LpuԃAɀv$R;z R2nٴ$ q- h4 },yKݤF'[H=*ᅆǙ& 9/|qBMvB\Yi"0, sؗQ:O/+5/*)Tp&K-w@Q#!#8lS&a*߽ꘚM-bVf.׃`r1YZ)9}Y㐜F'dn^º~=Qr. 7+w9{H/Rlx4٬VZn@RMBE1½tp47{ʅJ=w`w v$+O# B\疳mk §)܍נ:D6$,rch TP|'tyDV[dZ!䦋bZ-jR̿:GīmODQav#ȶK_' TONg"z%҇[[Zj!z o9;HC~DH3/Y~U jW%52_[65P[hmm+AWqI}DJǂ.ާ=0sQ0 fmߵG5B|/8g(9szXHߧ|%(DbLeSt qJR[IZ|]jbt'opsؼO v|fslk@FY3[IILW/biK?aGQ_ͱuâ8HNLzhD}'F ^?*A=o^|G]Xג\r~\l-ڀL)~.uk ` WY` n"XGYsv5N|:~#ͨ*okT9,C6Z-)X7WG8HD{k (P ɴ5x\J;p"$[yt`_D,/:|" UKwV[.RѰЉ? nڮc'UKORvXāf#! :蟺xGXCh턚XZ? +ckqOXl,x FObh\&uXBԖm">ivI 5IջG 2LSYr# W4tGaT\p[l>mKϊ=vY׹Bxo5=&(-Boz5:Q9ar{@i+7:qhiidg^O~ͣݎRfs6:Ԏå]Or+GⵞgT [N#ʼAI8#"s7ˇn/]\>)[&1eK [r#kбʌ~`fN &9IG 6wnbgg)HkJonI{R3L)ߧ̻*z}s]0&*%Arm0q IcJ7l RL; +:fů9:r%e [>a%֠=ŏ{yEh+ +ղ3Jzk9Ut S,a7vhY2X4-UH'V*O:/I*-0l4 YEbX\/XP:sH[ĤkCS}%Uuyl!Z+Oxڮҗhݴ K /IASO})v GU^M}YA9FoYpb,5; ;;m5-BaF+*4z¬Tȃծ(iHN)Pa.Dݠ=.Ӣ:}*E16|-f#K77sӚ+V.!acv5^D11fNb6AKq0yG&9}׋K(3QإҸ$m{{ M3բ\/}ds"»qef_)&ẹnΒYpPݜtIP[t B<{%XBŊ/bIo IXXh.Lvk (٢%t},|WW<$ss\ NƨewXuȇڪʟ&^uJYYI8@xA ]ǰ }ظUsf=ƬBл[y66 b bt`L>U|ׁJ_vCv:B#۾|s7mFaM)/E˾9L%¶ 1W9HL|o^nN;`n6nus ԡCw"!q5MfAA /= NKJm^ YT.]Q<ڨ3AYO(ſ18& R㎧VSL]ɰDd pH=BiU9/hlz>Q6LY4ܮeυ{|#o 7K98yTQW4uqԝR9yb;e~e;p NV 7$;,&G՚BM^Y+丛h)jkO ؗbוy49m9-'AI}dWg嶈d#|9SP)Ngp0I '/Et{W3X]^ZCx{ИduwIzI|o!(b +^<^8T5M'PN6uyO9vZnŸ~+TE@.M"?G1o! eGJ.p왟tl"=D4oD`{ ?Q=:5KєK÷[HfrKHǖnK6S`?n g>IO7.rҶ x!B)lƦ7m?dl!(Pmj)24N,eGDA(I-zj>CKzKsE{P EH&;[B,Vo3%!23~]şB}p4@P:uֵSJm"՝O%tBg&!mKp=Bkd[JWLN\X/jpIK3R T&ep=鬾! QWUre>f\pbO rOL{t^e% ;de6ÿVb (:2P _ tz<Tm;Q.bPSlPpew&kq$P]>/H(#ΔWDw?5/mTY۠,<&̚0G2/wX:H? E$:Hpine%g8onЏe@}-1i:m|IȽ7۾4֦EC?h}+!N~VwI?j Ru=ִ:3P:H:@U*w}jQuHc1j<ĎKwq.1nȤg(:v*BR%-  ~׸izI-yvIxp`TOY/)-sajS'$JAr\\6ཙ(@MѴ#90=ɄCE/a=M0};eml Sq%6SqCp/8D='PM=4JZcLq";֐3S)B B$9*RܜLUy Z9 K`Fk '䖕!:P擓rV+ܽ>iu]^5:v6bՍa#͜th{9*~@mj. m&7%gRVSu9ޠ[Vk!O (H׀֯[QUVKw%{P!*%6@ dy9H&hS.+u?*f=ϼ)^aԎ~{zUUVN`fKψ ֦vaa:"Wgi +!\_^Ao|B rJ;(V2j )nFp[5} aⰹ <1d&LZ_ھ+3btv_RvunݕCH^!#T}/Ah\eYȞ0 7f~onW`'=}cP+WRۓCr$y95YFI. >;"]v.lM !gs7Ncႏ#քCSd855W4+[[6,˱1(Ql+A?Ca_" `v;+V,WPe.uvO PdJQ}Ke{\pou~X%`{sV\?nTtr)(@ͣ`O%J%EO ?*LxE* MVBOM?NʿA1*Ӎ 8T65}EOlX+C5KUJnlChEHCp"A zA$]OI^:Ǟ4|!$P‡9L|C~]ieXl@3Y4B_M-q,FM+]KU{:e}ўnV:mޱ :?łWs)`#yL$y pґuI+Aֿ^*첶 $;A~h 3>U=-*BhMbb")ŽC}u%ݵ^74%߀Fu#i V26xhxIPX(PS_\Um#>'`wA oe]}CWoReBA!hBe4pp)u^1y \5_*{U[&=!#.!}8k|P^9U_V !Dy]~Ctv$ lQ=MQPC1nD!,Jo%~<=ew!sTR@^TP,̙ gHрyda/\hCZt6$a(Ѕ$l.N~zkff"U&A㗥cr[6N4ʾ'*oZاqc~&d)8#6bh_&4QȼM%~µ2#3 Uj vZ[*V1ia,@~KctIm5\}Rjۭ^y IDj3=8.ؙ(+Yc׈-&.f`xsZ5E+c.uS'X,#Su!i-N`i~6<:{gRT,{K;&h`N%ǧw9WFߖ9/h!*:/[W)p./<΄-ٙ 楙̢,{-[1Uiֿyc0WJdʵm6u.!AHy =-R zn\3nq8?-/e&3-2׹p?ng6t27Jk KBƔC=C~V)κ-i'' ! 7v]Isӏ׷Xu>`('*Ûb$eT~i_}Iƃ(ݢ }5 aJ+M`'oXV5pugᶷ2Uzu\HTN80~sz}2ɽLKyld zW$ KL xREva,ݦ:9.lB}.ɒ0E|$z1Pʭ\q4'ȊoSDW1{% +9DDwgMCCOx&1-|mU?f%/; |iYCKAX@ Kt;ηD MjU 7 4 Se)HA`#cc=='$9e_ֿ$^x\lB.`}Dg+^evҘPw--EZ!ŀ¸qIu #V)kGK* aL*mgTg2* b5g+cí3h&DbWAD|vV¹D4*Chi ?k^@^{j@/XA:Ff"?GEb7cdMص.Rit SeX)e*6+ݾ`4U>r2%fJ5=+>VԦfFQcX~OlmeD_VFD#aelh٠ xs}[2a.Ko'.2ENiԶWAMUZ:fyJxC qlظǨo}gA-wYFV; $LY ^ث?Xĸ"ڸ{JN'cmS/Eϖw+=oյeǦaN^sIĔ҆}|9#22YJzPABjt85 dm<@D 4ݫ0wqUdqN* hUwJ6Dn m#'98{3('1 U}v_Y2.6ЄMWE ?+$dNa~_"(~bژV٬L{Q֘-0xgd,6e\=gQ# tt|4$'& itϯy_c,Jrֲ/-q߄/O`fDtHwP;nw<+TmTK O5-2VQ8"CM=[ W.T~H8Ty)c{Nv,&yfgYy7/,&,{*X|hX=8w>͝&EY` % ]of<%ܸQ X+uI!bECg3My:*(4d5q:Zi t~!Mƕ򓺫(骥6Q'-Ù_HPf;yd#Ts)&߹Gr\vk/%Mu5Te/7md gB[#nG99Wݚ9č+2CU8 Ӛ&WpgTn(#2L_#$+xJFwuv'';K쳁M'…"24ktR G-7lWĮbL!-^c)&D mIAr(G͔efrlQ81B:O C?<}:FM<#T#P.cxBc+,G}&gg}êwb@z,l|^c^ J+:^8;hpƁ)wPRm'!A}eo(f+w o_(^#@'bZ<qr TG]YRAt`4d-˳P3M$mn<xsʜs|oFSCt xEK9tl.vH~UɨȽ!>^v(l1>TYa*VjPa5>![UՁY!ϙ{q9#2Yd 1wKWi/ 7 s€&XZmGqpfJ9w=%T%H9}:K_9er(LC[\4 i Ew m2YJKd-kg鶕(BJ gmAMU $u}aϵ!?M: d09M&WH/}cX$4QxStQƒ[0 iCߟҒÂ^2 ՓIPKfݍ,pZ寂O޺-FP ?|(׉M'RQYeU:[9ѓ"p7HBKqڋR͠N sRHU#v<[(;Ve;: U:n cu|Bz|bX?.joV(M{q?@0$6H~&}]*NA ̤0}cތL״-W;3|=m?:0mdSa/5OvU\mWG"m\G! v! ȘMsqsbAWFVv'Ngʊ2|@r6 ;C8(d~_AӿK4>{Ԙj AS"bRQ 8cǻ#gjdvjugD;G"p }/_$I $Ʀ3u]om>>ȉbs >䆊BXeu$C1irr> գW~ j5ݠgFX/fb׎a gi8vPPb 0P£"/4BgoV7>-9![:om&Wh,#p B0,J3{@I n]rh?N jЗ/no_Hz+{(zcK3m+Ǿ݀& jP`sF0vs4 *T&C-gK_jYytu_ׯ)΃8r Tgvٺpߴi݁eR6X5 -\,M2{pWI84:&$sc3\Q 4,&_S~Ask2Dgs02AqIªZ ?\IʧzKiNLoTs:ṁd;Z0? 2v4D.g,ܯ'FEt;,KQ0&9{df‹<9ߛU@ fX*9yg=C"T}6&!+=Σ7yZ1pi 5ڲQMMroGnփ aC/(,v縉6۹e ̭_qp:a9j4\/WșGBymsH'E,,M#( L&5v~`or>B vI(=w'JK[h^ o{RB@[]=i΋lr[1!us}'W,"f4u4ntӪln;]Uч{MP|1-Ɩp EzJz򾎤`:4 ̰Cxm& ǵ,-?B}e;z_H#ꑋ xuo|D>%̉"6NrB)EhXU4p&?.ڵCP $6\蕠$yv#5eU)|цZ ̸3 Z/PZ.&$WxCd{Rg~J3p'©~zL=(g .K:e~Unid/z)p.:i˜ $hi5 bi~e$ V[~>}61K˓5怄}2_r ) i<$jN9V[5Wmbl~VC;/Dk/ Ҭ:\ƼZV E_5 }W9kGHZśVŻd}-e0negOyÒ6(p晷Dz2[gjZAGR8*nrduFÏ:ACc۟xQX "9JXv9ʻQ$t7U?~fŐ}WRц\K+"IDw43e Sepj-vwf4ĸ 1"~Wp/SBa((%.KŘW7"RɔqT׸wuj%9^!d[͌"kucY)"AaT" q\oX! [ /x9'^{_&~hd\b[o\2G=,ONciJbbmf&Y91]Us@OH}@r_\woQpH;IgO@(1Ԑih烜 1㕼U=_@V^Sea x5C/SsV=:*G1gQC6Ѣ`LmXJ:cvK9[$_$DEުg >q1;6۷ k?&;s!3]F@r3дh24YRvcbipצ6z| 2xH4senf!'M@ a XSzN y!؆['8cih+8s?*ű"8k4Ѱe{7ۗ#MT' 7D ~P@nRZr}u@JOx* Ml(]v9@ gg*V'(sS:5] W_ef^-1`#3T†MϜWpltb?vMwzގ4!-Vȱ0y%7XM@`,5'z OkK^v*OTӎBkA9L5E`JQۄ.ЬI&tuӱ8+%Ƌ_'Xo^N?]-.et:ƛ9|S"DdVDX3 ++_94 p÷Y. ޥk&d'f̤]? 15zFAҚ2|IY GU-m]+|1rRvCA Bc6 #XחSy-G Y&/:]fS;w-Zu?pۉ(S'lK@׍t\2z*+ ł>9iN1bؿ2MJl~o|#KYhV b`)% rOW5b*WËq;) pBbae7Nql=T5M WW'DSbG q,Uژt}ZC*j‹m/ؒ_Y Rc=.fP@3g(fxDQ#v䷈骒 'v$`/rMauMcEN5;E5 nӆ{aHo¢%7F4=qt.ҥfWkr~%FYsR"CհWJ LhmHD=PzǾdKH|ʩ>ITxHF23ig%QF xpXj3?19oFޝ5nr_ peڣ|\}/b0;vIz9INc*ᱩMlq U܎oeF|Ӎlc&̮f.[JvB./Dm.n ]fpL!k^+pSRvW 7 ~}YgX'!->D&`(j{CU5 "u;xɁƒ@&{RIJ(p6OE~3e>k}i_ׯ\I 2Ø)V_"'Ru]}=H_2>7t+\i -xѱ\r~忢l/,`= ߌnq)b ``RK0gp36l=K}( F.Rmxbwԍ ezkll_b13'~OñD ͗6Ö~7·m7uR(BM̾8^dID\(oxykZC3U}=Ad*!>og4t(xD͎A -MJWK0# ۂFlB3P ;I:Q_jFN}Z!^_Jw 6Bxuېi1G(k| -B[Yީ4iNYFVAL`RSoe\gui7v΢ݔ "_I^)^H\uڣ:KY 9`$$5@FVK8i2clՉЩmXi3f<"Rž26,B 2dV"xK5Uҕ91ۓa灄k.~qI%P6{D7Cًiݭht{1DCB3J+Po]B9l?ŹnJ0%u /MUCrP-@5K{GvS9>=}PB&i(+B 1O fJR^d31\rֈRi+1C7AiJ$AxxpMz&GQ%q8Y_py~j)Mًm @ʏcAJ,dwuPw~N絓%Xz~JK /as-#OS)EbIAũf4]G+|$ D< Xmm>1( H;-QkRIS~'aExn7xq%W߫=aAț_fmJ{2B,`އ`R>*Ku'Nq&sFܙ%c|%"E%lde`O%k\x?1FB뾰?L"hj(b#9˺-};K;J'W?uk x/dDqz}ew@85mϢ4C&fˑ$vudqV#Ϝ:¡-)zPZHBҟ4&<Ȅ,L7>洵8P6YCoCSyc┣hrcؾ\R|B]K`1 (腩/HN=ΣZr'S?Ns{k`Ɂy(,-CZ^JV觿UdCuv OHN>~MD8=x$pXa ƛAI`y?:P2 MI(gUޢOk lѢ"Qq=G#߈S sƤ6lAPEJgƸ;'P\-E[]`e?0__Y[Ǭ_FZhc륖`uryђ`}O#<5e;Piozat.*M:(ˑԺM=~C `@򋛠~yTmFMdC8D^,$57-vJ:TbNF&)GǬWZ+LS+ ODeWMViD'Z`@0pNvX7($ͪY֙S=J_c;vJVm=?CMJwij0о"Ո*!$T=DLN:l5ͪ@ŏKu6E#6Y=84@ɇ@7|K)v$ݐ CgD(9`AᦎhuKRK\TF[~rȉl? nvt5Uh: qx#ȥ@"G)uz*̕ ,.rl*KSF4D/Xi9IBQe`it{3-+Є~;ֲU2MjqGګY1_,@ad% AVufrX[ YJv!X|@]JJ NYD^]r1biW֚lRlijN;BЎW kֱxoZ;W3 h1K*<9㏴)!;![u>Pl?}c։nVy'V4,[z\ ٤:#]Y:*r|~]Xlݢ*bGd~-*ZNƯ$ -{?:\+o%PNReŦoÇo1G[6F|h+ӞlfQ١7`g] yjH0Yv_߅' `pW Ʃ[wȮ..A$[f0WMo T n0Lc}nچV8i:sL"Ծ12z˙Q@"!}xkQ_tYj i5j 3ѯ{rn#랹9 j0m澰3#8K\WuQFe}>L ,kaU87MHo]ӻ:7ZS2VF#ed{.N>ލOĒ2=bg岾D}ht:eF@'oeR.I8꧋H0wN7:1EX_KG *70>tۍea jD?gx_ !X@5җY_$0W ў4xz% ׍+_ɏ2LUM`hlHol0*8f<+f{CˈA%hրl``"ѧ AXԸJȡMwmVڐJrsn1)ɲݷ139$tC#u)&a!%~q uPb \b [e%S|Ͻ2oUVcV*<*.R"T쎳Ӗ|l6}?v%;8 \h02lJ_t!21ԑd^ sQ'u\k)oگ3bAF>q KYʄ?ǏU$ZY {,,EYzZoJxE3zl-%Zgtއ.7yF &|Лl> >9"pgW- s: ka Uqm͗6CV$6aE#Op0ӱwQmQ[cYU7Uhiw h9IG뭎JC~!#_v^o])ww-¢Jy!bMB&e]ẴF|g1K\K9@5qX1cGS7Jo`|ˎh1+M*$߂^>}c c VK-)L N&- pQҵf]Sc#> T R#VZ !t3w-`r>Y7HuG7T66N~ ގ:I' 㸂k7 m,Ś? ΁dCOpPTȽ?t=$ۊ|X0J0~8 dʾ=Lbxk#FCZv}Zƒ|PpaF5/lnJUZE$_{{57#T COMcAo iN!bֻy < a;H 3yOnWN~eY_g^LG;!{GIy^nUqi ]M#3꒾pgV(1oU;H%K#RmօG=`Lt %[LhIcv sc?!yBE*]RINI}FAc2^x28X@LG ,XbB#y+<ȞVjPхڛdn+҄"!hf6;57L}L 0̆@ ;;@^'sV*e~v}z;uڗj/ y5Za3ff[jJs&rә2|=a;rRa6VI7&Ãh <B]wʧv=h{>ϫӿfH e0^ b^~ :Sfowe +'c'Vb2cZ4d=#]qtXߪO euW|>'@m:7 `I;4Ef;ij!%nЖZ88ZH{ @oo˲ _L's=6k%D-')Y#fǖm-[ј@LP*{r $+[ƉXDr BJ#!N`P"wX 8+6V}+%\rqL wu#]R.d7YVf22h˞j0)'i{_ikbհ;[ZcKL4 TO`$2 A`Cdݜ&Q9 {8`IE㜡Y uߖo' cռyZx5׶o3!UFe7u-(((m(i6| qa}V (CNw5WC!#Y9eAÒ/6>mtx 0eu''(ESϰօ\YE rA \s3Q1q{'k925ڈ-$#Ε<l(*YU6Y6$TNhG+J88]>UH^K~!7[K[~c?RQICT(qr}'mY{3_·t0m[(c06(Zdi?+(/bZ13U6}@Oqi*OϺ;eU@(u>K!k倮X#vDG)Ysk+YEސ|=T\'%Pj6 .Z;>e[?{<)J ̳3nZ8kC7uwy)Ѵ zbh,@? eOnCN@ m@f[ڢ>{f_4NP+טqb?"M۞!ƙV;ƃ+=ek 2$q!T0s6G(е[e}AƮ~Ah^Q] JP/ʢ4Nuh08(Nr 5?nʠ@9{OJ2oPg֬cGbiue`$#]?Z;wi|buKi\v*^pns')3wo /@ގ\>@KT3ySd"Jxt™ܜBQ Jm?%OЈBdLekxe*#Z{vÁk3-]QngV5N,eAHP|dV<V%6 <6 Hw=HJGJk@y&Rnta'Z,,waxpz8t?˰:OY,Y"\ʌ>u=8Y՞=Bc|npjm<,2[#RiZ(LGYQXs~v([^?FP@e$P?0M ~L< MK!!u U\ &;x'dx/L!dd}1fCً_sz#K}eꃎ K|_^}.'-lVU#^` BPzgBYvKK=:YC2-#ԉ)> m˃O*1]hZشl~-d5`KEF# Ux_9}~ yv 6FPahC%}Qv-k%>(Sp374(AY8n9+?`|B[8LsYʃ>{1 R6v׃=LQ Wsn^wzz#F4d. ”D dvGz`j[{u>D+HlYDtZ7ɳGMPhY[gUyC&vnKMXhX/:ɗ@kCoPGЭXH>?2yN_[ױ J?eՠ' 5Xʻ\EUM@틯vd,rZ;3C@(pu69GF~rAuƸկ5+L?@$mh 7^VZE EF,esƗ007Sr͗jΟw8k" 5IEUc=؝\+3 e*~H1'(J~BsLT ~(ʓ#]a*N};Dpcw1܍,0v ^j\ {|a⫼^G?`Mso$VeB `r/t/05E)@&k{O{RxAjg \l8=EmDE66ⲉK+xiE6=$)*]DW]yZC݅_sb;1g&%r%:Gk|gtFI%0IaŠy(hUL;7E7(;6|#9M+`J_d~R"3[ p6dYx:ڤ" 3 z:0 "W OCtzUGvnV5,kSOv>/b/Mu*5La@A$h\#-0$FfL]^yxd-vQ%"e@NMfp//IĥqrB]+ āQ7l¶0Vɢҵ8@ntk:N6W~#aM2Uy՗>AX;$lCDz'{6]mw8NxJa<PhEY$N|E`"' QZ%6BloA|G{ۨ {<X,; !*?9ն{RZ-$y&;#9B5J?u ")%m][5T$}5Hڬgy*GxE%-n4$ 52"JIkA+*]V:kekLj /Ek%b:Mt QO[&Jj^Ap.pnaLTbN74 d4M^F~Ƣe7yV Th+0dQĀa1io@1co*OoAZgb]csZЌO ⼚kOMs5/_0zp3Xo )nI3҉9G+'=(kOba!&j" t[ڳ9>D+fp](hrORZ9Ӣdxy2ԗv L-gր [O?WBH3M-mY/{ٙ˷ϘqOlfo}:DLj8XORN'rgSS 0xFe;OJ Ѫ0HbnI>;:=__g\4҃#ێ*4cnSڶr <ѽ]814Sq :N#NJP[(eLjE{"-aaq(aʥ=#!D_#UhhѥoZ+Crߣ[v}aH"TD.κx&J8)/qtUtyb>\X#q<Ƈ!W4)uI.i8d1D4KEE@u--CNz_.Vjq`_vW#;I'C˟ͼ;oh 5TɄ\gn?[/ ݷ;$L9s5RV+R"_OΌJ#UKG)H!;UPl{jTĐO&T60?wjK؇ 2T"s 9f4ys~HtLMP8(/G‰wmssMbK5b,A.>wWl簃-sߐ8^){Ԓ5,O41S#vx/F>8X@Q- p|Ri MPn:hgM~(-Sp Ix$ ucUvk4_%F|*"0K6o 1nG'\L|.qąvJU w)oꜽPl6PشY["8D%-*J1`F U?W ;PEOߡwޏ^K )Цmi,CVkkkGS;Iw%g՚ L3GɿBEZ CSL]d0zY?p2=saq /֍Mx0tV,Ӵf;c"xwoXE=.SfH0G硼=\E + 9SZ&d D7zeV(UmҼܻb6Ƴ/%-Oˀi" LiRlimto\wϒwAԩD儂 /Ae)p$.%xY2܆.EM@.bE@ogYDJKjt~Ej״c7:u\3dOfq,^XBb;~X vCynkm밄1$ܣ#S|#H늿K|n"͑)SK?"ߥuJا0C}Y!"K8QQy(6^pD 3oxZVvp!}D\+nf(XHSX^?YKw؝!jA&IGfO)xIqD#¶!Fk* $o4)a߻V齐R 1Fܷ(w:DM7y[]OiQ)u({վOٗ[o!ˢs@r [hW()RW%~߀:bĐKsu0hOnRG!p^Og;ѐOBۻݏ`^*j<^ҭrZ_up7-~(&r4K" cJLG8ퟳpB`$cfbrS7^78rMr9m*SM|Ь TEVL1PIŽEPGOXyT6׮j!ZӦmiY+fͅ \iZ%f8G}jᚖۘd] il^Ro9_T\d8%mɃsl?[xY=;:݁g>v~2Yܡ^wqb Ƀ$G3pcA% 7e9Գ6D! '0:F@>A.0rrll2%\z`WC'[A ,uXszwhIYc &"v{:w9&+}05QCBkU,ɫVSʻfMȆV{uc|eRc鬨svb {4| hcƉ,3x܀bVK7vMj8m,[`d(YoqIG5Q)ZF#1ޘ׳g׃e6m 1ە^+zZ\<2ט dܷDړ<W6F=/kA,;4VS+3u?gxbM{\# IKi!Ms| ۄLFHfz0^/V,m[۪3΀1wt=.l,LsOU^pȦk* _k~  b.#Z X<`̂U`,C+V+&;NFLVWZ-`!XjlsRW/C VDYnNrΛ"EA NLD.Ո JK\^ ʼmI Tk&0z*YDv*0Ԑ4,a'.l[zonɄunI# -VH3]5˘!"~4 w$ka WSRu*'S=xC|Y#AL>DNٮF_!:5ݣ."χ'+N4XwWF-u…}X.03H2Ci?WszFz+IBmD5u4M~VmT}QO5bfP׭ oK6;߯|x0 L^NeF I}u47|0,x beo*[*}c"4Qӷѓxܪ-xLƽ4ɢIYfq+]͇!{e0/bF 1?))?VYSHfY1rdѸLI0Lּ%a~c̄bP qSFnuMC4c:?Z[6":5QZ,E*Pex ] C$szFsZrd4L>?,;5;ñن7T<dhIp$o87Ϸ@cWԄcYs-`;ɶkH=li.;e}_ k/ "0>"\l}[D>mhx{2fu5prVy}n9mPUe ;+oNI1q̙>y]* ~ ۬ePhIU" +:eVO`Ou16CtxT @`3+9ðdToloW׎!G:o1fM'X=4/M+ ˉlNceMޠ0W5e)4f_[YZJ NU417OAh]p@yDbĸ1k d^(R!0 zi:ַW/f ~v)' kպ;m.|T )XtVDk)CQ!"%oL:5"8 Sr0,ćxiaD`͔E79{PE]ӧ팸,!9մl7n^lBA{@ Z,VPnGw6*dV߭NV^В˅Y+W]|e ɷ:XhX0H7wM0`מK2$nVu Gzr|DmGeX hGn `)*cuϗP7iPƝ4odrr|d۳<q$YDA3=[|%I\ؕ͹fBgBـkHdSAάq= I>eԨ4trxw,n(ZL|fCq ȽrjbJ[$v+*| uy.㫣oD*|?Q)js0!'}_/nmLBN pAOYw4 7ByHh/:w]c+͹77H?2^+N۝Y9ױ^$t{f*5m t;pZMj]uk{[3+UYz\'f]GrWN%~>.; . h ǓʉN/:3GᔍqLFJ.U4JFNG!G\Н疚)rW>ݴW=d^)9}8 f8e@^&tPamfhk蕲ؼ[2P⦶Gto#&x'yimXϼjer>ľtT@NRi>fcjX"ٱߜYE] 3z U,*9 4p8 oB3 \qu«m^7eӠeL0ސy.Kq uJw*;׉+E_Qެ:Z_w.+ 'TAypTݔ|tN?+K:t{WBJ^/#Aۻ8_%Bi7o!ߙ_ڙc>>c/1 B((bP*vDTUCߗ)YBc1(C/p  5% -Ԉ/xa/5gR/흅b>xT)trSQ,d(UǛrU`ϥ@+o:A%/ mNбRҧҊ';t  SE-+s}dp^>u2::cv@lhG2f%.2٥ 3^\6,EE)kIoH1t,҂r]Li'M%Y10T:uz\/Yא;gdgdD6͵H F2- +ZP>Z|Z^r(~ hפI/w'vB8hߐ>P,O0Y -%oۿ4&T%J~DkSǜ7o3W#2)Y*c?xsrZB<~X/vo/Ĺ$<$ O"#yA(mcI;z6Ue緤QD0Fi$.2r4Zof K^%\wDmJM/fpnىR4bbAS k#F M`~(ؾ8Wj1xr7Ѷ`"O}+@5a[  %'g@Ud 6a/ "40Mw+j6hx16We0( 1uuإ M1"% bt +TdJs[;U_gL$~+8bC>:: bQ[d5zo'[2(G$oN/fHz͓q2~/$.⁛'0iuuR Trs:,bA@"m=N˅X_`aMͻ&:py_}H jXލWt}P5^5X]4[>:&u9 1Zyf/`t LʛEZm-Fq!&ȏ b\quȞ_r}RqK_4+EW_5 eK~N7[n]Կk$h%)2 ߽sN~n6SMzl%v evos'D* &pJݣ9zg+45Iҥ ¿d8҃%彊7 wk,(v]Xz S`7T-hEG_ fʻA#!PAwOw^hJaKx{H5$25V;vx# FLFؕA$Ъ u0KS*HG)8 rF%EKj$MnJRܐ'#Xp0~I=2x[JV4lI#~AlM2@Ӯ|-&`",F~EKH +bk2ƗuJiu9cg&.[B)Tyt^Iz4Cy,y<J57D DUɜ9=\<0V_#oW>$Qq+55|?jHm'xd~ [䶑?mЫ>H5V_(+TflVS2+YMe}Ϛad3^T?5`lGi[YY4QTՃ0\rKRSu;l!-Xȡ{jtS`#9N|nXr*a 8AcY=I񻎽WVFD٦mҳUQAo#'+1i=bmh1Bm䊰Fn=.3G:/4ם귺])z V[av ,H) }q8z0L"`6V@$i*FAW.<4{R[H$нL#HfL;B5P8sy >F6&П(^!4opL&5 lW]RMxKRQ_Dpq+ g~nqԙ\2adc ۤ!k[(VC̕`[ ,w//հ5{^9 RSP8vFLW416?MM Ec=%"ԯʰ4lD7mjd'yp'++B:B>#=p?H|p"ldB/ (L%F$ }՝];bGʪ&t&7>i>19>Y@efppVƥ>kl~iLPv81T -\!!Jv 恩7NLf}9\)dv݄ߌ/igɕ6SgUNvŪwESX>;;F2NǀKt@x`glɥn+~8J"r&˂XPO$cRr6 62e[?Q _+Kh-m)pIOW Ī&mHձOS(GH[Axk3<@wP K'hU% ځʩ KZc֖ N2r"JCyVwWz-+mSrqAWcºZlc听p?ІARrѣ@]Ech$d~U7 7[9NҸx6PgIciEl^EJq%^OWelFeC'Jbyjfq zEHr۳f]~la%.} )vn.\wAyhog79VZfKtoz d(A.Ѝ-D(7*_(fܵ.q85צ,Mv;_Ad#$CE&V@\n] ԮZ]Cev4}~sk$V2$\*+ #;miU `ө x%4}Qg5C%%& J.CK!:ݏSqܮҬI|V9$ȯI*=NAO-ΑV^RQv^P'/U O>c@[$M;0Le|wG%d^O.=%Eq0nQ> U#9B V;#L5eZ Q LQ؃PrBX/Ngb ؼ*תWE%`;"*~,P)~=*_Nls;, #Ǜ,,m4sw}B@97وN/͔ 0Y0]XH$>F -Ԗz@! n 遧lz 3a+q MsR RCp&8YK@{`v%݊wůcgkǸV/,fʵ\ƫ:1$f5kug\R|Fgʚ=6V^^y5.ۃd;c{_UivؗCw^j!09^K*;+T_#„D핈NӛG9T+|-tF˗F$l'.bHFR3jA&6v@#/^4Zu P>T[I7_[2KQ!\ B9:mjKY= < fjzb+# [E-7hEԞkl.9?N̨ -q>dЕQ*QHM1ﯶnN6@ 8C+S!'Ml߮.H~W~׬f|X&\y%Ƶ|X Q66m E5#B4G}-'?^wFD Y$A*BsfS!a^W.-Q Y̲$͇h춝L :gHwJk/^}"Q0Hp> l)?sGxdU<+ ?`q-~IlS)Z7{X [vh/PBA8WUr?zϮku41L=bk2qy+x 8TB bm;3>hOd}"yǴhB:T %h\0yLWV?A2gt~89:AJ3its%M h=ayL[: u#Ga{* sy @AAQ*bAIBUGZw۰x\\vtmz%oFb?qz#V,WtMQq;'~d<dcI}#[&!f~8+t29Ccqd#-Fs\"8h~`RHΧK+ˆa3:%#9eHI%ܓI(^O00P2[<77Xgc@#C[?ۦ6Y(L]%pòv>ybˊGBVqhg.5E8ro$+>DDI|Ji`?fr ldqdr+m *@):G$l!PEZb9zA=ǣT{.|:; uYFdP&xqfW}8A`ՐpBH/wXA@,`/ÞX:g 3 Ρ^e|-?#-hHoUiaa:Wa2?卨 ΎGf|p[p lV|z)߹cU2+XSC**oSk앓ҫ0Oq 5קzlUYw>-d1'%m DinlOd[ 4q@ޱ5;^yzGwm{-8v1 2yJ '*$ ;v(0ZY#) "a9"* t$ T&9$(q58_&-f՚˖E],3RQWiC)3<&mXiCa$^:0lh }QYڠjaE}/VBأ 7%9AW͡*^9!{}^H9xDiT.+^+Pfxb:I8"z#r_7T~|foψou*_BeڀkyX$^N}D0s $C܌f)}u S/]G|-?e<& 'Cxz"Xwh 52>gDχ|_rh}G-ob|ch$!!$7Px*07ȣ硗D3町8Yv,.N:EDkjm8B TQ}wPVB8psIKJz.,~b Zn!wc"#R4A(p1ʊ}뙽O':Ph)6Pʀ]7o`u78,VFMj>gl [':l̈́%[(G⸏Hf0' NtD4OAXelQZoBn[,G[aD#R _tJDrSDàtEIr0LQȋ>L2'GFh#Ccn\=z/ ͡&(Wế6užVtD :O .ch"s,e4tV½`*+ن5Pz~H䑃6S twGޝڊ0ޮ 7-ӫ^;w`p+ /XyIrv9+M)#agwa>a"ǪE Ŝ=3GC05Fr;=~J-g 8wA}NG=Eq7$ZB<}MBOHH n#n k֜(R;_WIhz䧣arSz.)Dr?݂0Jb9s'M鵽> r.a#Ƒ•%Ⱥ]W;b$Re{WS'*2Dgv2UX5-yƷ$HFILY2KotL=!yi)[XweƟ8` P(ɂ 8pEƭMOl^etj-o@9 'Pc0.D,>_]>v:Wٳ9ex~ N$;㭤a1rtm>*7X,`y8 {? b:]4'5ԴW v z8Qs]l6½γ #nc>#T*v1njQ"HIZ4FJu)iE/hXzj𐆫z-ȧVKiz{'Es X0ۃoc YAT&o!W,,s*gG'x2&CeNХ}FJ@q~j3 Oދ FL@H(no| `GJ8#}Jx"Fݤ䁿2!LLjF+X ]K$'&NG;,ɼPNR}zaBPOyo(eKrʷ&9/~Xbս uW匒oF¤]MЋΥ%wSDA;%b_:;_~iYyn) q|o׻ܜ:#A#)&iNs!vo{(䥼!QY1WU(IZCayJ-_о*Eaֵ"'o6HH(0tm2X'y]%@ DcPP(j[2ss SRPj1ܮtWSx> sƔ ƈJ2>GTPx *SWZKQx҇4!}v>֮ЍsWIXٶsh M~>BЈ'nPZp\ȫ **TNE*@ȿa֒'Vv4@+&`]N\}-,GY͒Fma\2qAKaPo#&>/P)[?x?ƅr&.\jyyFJpWa,7xV5 UǕ S e8}ͧ~[`K!{,7Bael%M7e5,`6j?@gͳV[t0Iwez`8ɔbm?ir$2<uåWRX0= ݷ:K3geַyյ\}5H|!WaGXc &rVQhĺ FЦƎZX40PԠQ~39ApL&VFXSiKWɬg!k@0̺ٜum߶$Paɾ#ͥ@ck|_%~ϝ(*f@nT@dix}I`%-.%Qoi|X*rؗ!@)"<1jy_hg=ͅ?ĺB&VIy*`$I.Dd&ҪHԻ1=E7tۃ@tAنf[{&YLX65]VYD' p8ԉ*tRNNӖdLa[_p6Z[.~ZZ~d[|1U| WT%~vg/vZyeJ{PR?46IkmG9ܢ T4Ot)٫ TS s@r⻰6W̠᎘ڇt|AA81JTf6pYoJO?ĥ @@mb$Ǖ$0`vu_OMaݣ@, ĩroBp$x܄i{ubV x!qckOȁ`9{*R72X@J-pvBWzJjpN<= /SN+YY]z!6\d &Kf@fYkm`k"'{z2x<|m9Iߧ% S0A>2|TXTS"Uڔ5*xQҚL1:6\25.q3 P{ۛHZW7Cڨ /et2!} ~Ŋ]\sޘY%ׇۈT1~ /q?ZGeamȑDjG%O+-2ծ­æx֩A85HϭrxX&rw0Akky^u _E7ݯws'sl@Ҭ~)|F~€7ҡG .uS >"Єb}P0f3UբS!Q6'lTwŬj5蓺AY=%:2A乢\"nL#ab=L=;6LR*9[dTLL9+#X)pf]1%SgGm.Ί"I Ltkzcu<ѻĥmבNr$ }J2n뒋UMQK=|iqN晷cqh 1[v2K > w\xVW#<3wk<6 @XeBP>W5v ,X@oXjz3b̌АHOgaJ]4ՌaGj; 96?WG}A>6ҩƄޔ@XƊW竇Ao|Z#L ^[| źҁXxDoshT6"'])[ D咃"_MY*iHU_~REb@[a ccjrgC*NVL2mP2t~NANE@f r^|7ǝ"}X4XѐT׷M'P0iZ w^h<20DmMכ+s !S.L&"V/ ĎF@cr3YuwQl//>Z4Ϝaef>}R_߆ΖPgAvuJk\ͩ 2阀|8gܵm7l*iX=E~9V阧[yqQF_!oJ硻BXG=ksP|m(X^w6_z. &=R$7DY2F٬=yTo^@Tٰ(l(2*G|k$衕C;$;QkڲM9צ=hX_M}ҫ|f3ɭZe6oٖtX60gnս}i0>Zgu5!fJп&W#Bs5a]ܫ3Nw>6}l3amk·ۅ[%p"e=4SǠꉀvŦ'{$DLjBWkW[,jR=0.Ycۊnrr b/&..ǂ34HM7;.i*WgШo5B_YҬs S`Kaow[ CU790?7;<]A$':{`Ի@fPꇇ (3jJ (5'A_m񝅍 3 L %Z:އW{x!wU/ ܾ ?P4U/ޑr)1c+NC?./I+Z]/˞^4AI^ 1%V'qT51sM&/A"2bG$񐢑Fr<ƉA_JK 48emz'ˊjDA5u "rv*-;FVnuTx<[S{~qt >&#Գ9/xd,:Im6,4zrXl?ߚ}ϲA~z/V^MG= 1]4xzE]>!nPȇ8;'@tKmw"%^PG ِs"Un~T=Hv㙆4~Ź.V9S@&GߍAF eCٯ!ywb6\1˃l}u~V-b.+B9raXg,le7s4Y/WH!9!;LҞIY垕E-3v~r1{30~* O!_칂گ$;箧#T@=뼝0;LƼ,2>}F^ *ը ysy"DNI<ǻH8ꋊ$xUBQٚ7JD/oVA&P 0,TA>Vc-l}f缽 Ac2\ j k+&$$dkW"ΏU c_vx|qZ3Y+x&.#;8eRqEN#b/i-)+V"Iu=0AvZftWbjho-MsHpP3}2̫.tDZ°C)|>6RB\{RNǞ {O㠯 dIpYH_^܂Id HwK8,T$6|h7I _TC X':g"'EjV ‡ܱߍ Kh^ԾԸ zi?n"c8JaZj&SӁ7XwO+<a<3]6P/& 4]Ϙ޷gKMs7 ט4E-;.V`۰Y #t}Zoro'I$<VOeCO IIS`r3\4"}y|f}?]zPp[Q|c|1ch\ ~qޚ8wMAwZ ]e7 sQӞMd〄Zxί~w nW ᨻ"]}\^%:1.Pz/+WZʈТ!"mG)usXP5E5$-ҚҲH9+ ~B ys/]9wq5磕i1~=̳>RUB/!3 dhYzNg;o\lת m`3.FIty{I5 4 'ޝJnd_-r- @4)ט@l8D];555ރ|tBXxa ]Z :!N e`2Kpu;As(e@`-w@z֝D m^T RcAhb3mWtT #_O3ָunqڋ3=>~u'Ab"rஜiQȉwhN8J4\ ,rݢ ɆF 5 0.$T•+Cfäo՜|G,4W:>mk 90 aG'IFU1GQKLD?rDBoD6΃OOC4gWra5L%7bAeVyVՅ<9qp) vz%9zWng_ wGEh.6&sj^#Q^+2ˤd A{RK@|ܱnko_#rS/>?ڽ;~bؑ T'i 8VYtWix^vOg*8[hiIf6w2;I*Fz4-5,u$ %jA!Eytrڹo1m&$o:"0 q`U nc40њMH>V(yϽ]DS ;7hrDm9PEXps[NR9UeOʼAJ(,9* B/8+pn-U ,4cv" 頇Q⛅ &&*^Q_iOt6z+Kj-R9γh@tp>ã|F5@*֏24_eKf|8j:̅{Fcv O,u<+Đb@v[;tmq1A [L'`mm8ASɫ~+./7#WH|h{aP9xS=LwEټ̀vXJta% Qδ ,{K&ÀPߚzīgi>R3U.s 浾GX /3,B$u>ױ@#%`7 E!lr]b,^@qiU _r&8YyR_~=8.ϽVEG:az\:;'N%k"g7 Ć^1ħ^ zOf.~[f8nWCɇt53vJ7EԲX*j}+ @)>?o DŽ,U8e"9bg΄6(+rycJ|ɺ<20i2@o"Puo,:LۛFtA/MI&Ķ e/>d45coU?`)@yX^7p|ءU*")\wt]t8% \ ™sgD.24L?E+h<ĺThR^ uUdp{SQibTha.;bI+{ Q%_OȚW ÷zGjN2TaԆJ)A=}hs5Uz+Ǡ-dK,Ml N֬n/u2Bm]ⵦ궱msÞ . m$fKF#I)z]tJq;;=r#s]u&NXd?ka< one A$`RQ7Պ,V)nrtӨ;#F%[9@S@c;_g ݇tDBP1O/W "JP?pMehV\\G =noh挷>p3 *ot˖v*;VےUTmyWbD+OBdXO7ո||bN6X7&*ɘe隳:,Uf[5س+$\(LUZ4M(-cP"oLoIVpʔiŎ#$^RH›%~U&asu;UFR7jt?twJ0#ނ]pA"c1Y_^=ұiU}%RokU\vLRŚdM*9Ѕ#cOV}TgfeAT~,lAS+c.# 5Su-tqv>F dak,%Q8.y6|1%^m մ”lTwکW71H2=*KN]Et>k e +XrTDAwHkIDB dqvݛZh@ƵA]6X>X#[;/'_Ɋ\&A3Nn~\(ԑ~?cX4[xqngQCGBT, H/CӚv֓:J`ľ_nz6*v:T c1@8ؿ:g ?Vf*wK֟`ʥºM6FA7?LҘ ĭ?!j=ِL)4h!96F?p"GODvNt^ ȣq<-Ps`c9l0XP&,U藔@eo;s%6@Ū^YP &1wm<6 ]^9(HlUAڨX#"_R䗫qSޟ@#̖N&ԹwM#ttªz}dwj&A,bj.Q.GJ8G??#?^Svxbt׺>ov t'ME߬fEWYs+2ʼnwi |HbE,fcK"NHh@f fҽ#l|F=WƎh(4&M󒲀)S|mT>0_ϠZsΙJYgiԴ!f\ ;32w""^U̾?kPU D`UV%-ʡ=j YǗ0^\yٹ]{RS / (a2֚ؓᎇyKz7FK 4M9KD4_fNb%ɒHNp9ur , r<[[u13[ZQVx2 Bi)6DVGyg~=߸D{:-hYeqP" {={0koѼKietѩ(na08D,M nfjx,hD|jy6s)I9[F5EW:+dЈxk$kq߁p<J9&vso~uw%+Wϧ|33wdhM2Q՘# } bgvAu[w!8*c"n}[ kblp 0gB(NXbm c傂[7YõX`rYxL¡ <$Ej%iF u=P׺: UGjK~pyu~M*Ƨm @ j-Iֲ^Kc JB1Vvӕy3@- *SFYWw Y$k wS3twӅ|V| һ FX-kX،ZK\tӖb$9ȤSvv 'b9FI)*rݜD+A[u>&غD6P;|6ut5*;xa#V 1嵇mVI%2Zed?[k 'eax,ihԵdYŰ= ffQ_b*os:+LY|y UA(WmcDlw  < j\|!x&N4 *wn ܧBԖLBu]?Z U;3'!yۜhZ=Z~`Wk,.4pF\^iԂ [ഝ~w ~}ʥ`1{LϸBS47pd jFt=~(` *h ӕBAqMYb:gV:pLf?_Ya,|Rq]@Kr;M u;CX /桳*Sާ[9ܼ.U t=*=pQs=k?LbNt50CE)f3(S{9 γJd`EL1أM?w "~Ơq:%Z`[2aRqiχ\FOFeAB\cBBY۪5_/?~uV޲0Xd({/s0pX(D48qòx9{a+}o," {Ȣ0CeuǚuU-JgK~͖3zQw,-kUbm1XAO1+E'u~O\ړz Z3TsέIL+t& eh;/D(יrcեU\5RT 曉= uz覤XL64|VhT`Il(/ӛ٬Bi=~sw QQ}K EtwKڸ8$4qYJn5N=Kճ-v+ym &3ÑXfJ'JBJm#G L* رNr]BܐU y$ԔLc#3'9R|? \5@;6s6϶S猷U%˖A|17 Rq5&QuUd('霧 =эʝҤJ,iquUVJ,W|T>ºi&]d>ƹY6)[-o 1_;`f*UT1TuM[\S+a`P#QpẺ@.htHlW?aV/ЃNTOq#0l c 1 51lQ;Z>ct?̛Ds4^C1ܻV#0³ka*~s4BrA:nq nSP멫xK +;}H=h Aw`wVIX"B9N9z E /Z/Ddg *-Rl 'W݌ W iQ~Ӎ+"4UN6IPX \"al.>LU6M~ev| K)8u_uCEX ;PtA(}ѠVθn¹ir0.!IA[lANBY$h5&^˸:G09jzYRK+\>UՏcWʦ !j# X5K10Qɠg9:z'`4YY"Qn'~&ߢeA殘zb1U;A9ZEfh' ل#n$ qVC׮߸BT+E^ޜJ졤UyzWZ65%7E0GZ$4m77ⳃ),=7K Ln뵊vnQ+ƠN['"}_WɈ1r/b[NEԴoR6sqN=LM*Bh)cK+Q5Nh1t9M nR5Xj/ ؄}o6m=>VLP%TN֢p$v|x-ct]OSP2v%e,Y\f2٫͜$dǬ#8.BM_ϷyeCFi›:1>UH9?_gFVp]vECknC [k$TykI4 .c$2Vi,@|I|t鬜 ToBo@~d[7gyX +⛼Cif-CB)!рoa0m%9l"(w+'\|YFV&Mw:K.PWפYI*@pH&`'j ѦF%y-Y YbdgbˁX!ch~p(h]"! T3w?oJ]\_%aR3c$BWJLG D _)b '-sMM$ Ȁi LpCk1ivT ,U Bb\₥q> 9\VQ\P3; ؂mT,yb`3۠"!ycp1\ }8CVJ0k@ȥ1ɉ DFvo%yˀjF%!~2J 1:I߶>',w&\4S2CF70i.}y9#ɻuďhMjhE%$c ۩VVcB=~>.Mੌ΅v;CݍT Bu^Fw0E3vDįwvtkH#He3cXw=fgyx-^BMiUeYw<$]YfA_G轡rb_/ C+Xhva@,dC](4Q}+03YʑKط\|oI!EauQKƅs|7%}t ʔTaA tzkz^=\R#5]TBwf ciS5 ?Ncw(h\aس:d7/%t7p_]/I?B ;+Ncҗzu$KRYX%8Yg|uJ&`~>e,0mC}<`5SUܻP;e/`NlE `O=vv_ʏ#kUZO1A:H# BcX:LʝuATv n'd\{S1Ų0}[?{α g pc􆎢dT"C;τhv#& dISح *ƫ:[頁NܶZW1tKoVHBBӚ hqNT("\wՎ{3."vY"{lD,ib>!jh#⓹܃Պ"؎2 u?è޲) ]$B=}VWzK͕aG{6n&;V6a\Cc1ߪ݆zϟ5$d}2؞*6)C j|~˷7f&T`Iڀlmvk: ?&5Kw( X!$r4Z*ݻXϫ^Qer|%$2Er;Ou(2 `k\2OjvTnH1s3+#Ls=gvUL G ʼ8Y*A]q:Ʒ/p]ǒ^OL55HHWJvmnG_ƎNP#cNkOC1ޢ&.@)hpNF*}4t?{ $K;kQj7B8_[S}$OqŔl(nֱ~|cfY!Tr߹UO.7gV(ޕvM6Q 6q:VNA\_ s ~TŃ%uBS0.)q`_}_{sFj/P8eg|vFLKcRKӎ)WǍ8#okWn~11s9*RQ+d7ڶvb_Cd4Q4y"{#y>?KgNT-<3+W,`r2F_5j[2ҨczA`:=HYx 8*($gI "5v.oPU q\f)oaድ*wB)Yę"$YAX"x0h_~ù/s} (Q&P LYP7^+\ʇ9!s,t'8Ѡ<0qVShk`zBx'ı0ŬَJ3#Oq8ژ$ E=ŪB*4I[S-Z0Ei,k#K EdƂe:pNcry\?ޝCp#L>mtp9zVkl E[`AVb!w&Caj0,tf 3[B|xSwkn-W(wtaؕ7ۺjR<6)6C{6teN!8^c*[=hK԰@@I*TAh7f<%^Z8" ƶl|{Deu bX ~}퇝-ms`CXmr>Dij!H`?)"AJԥV\b' 2K:`^S1Idwlxl!!UnB6U3MD'O*`=I=e /JS'Y^"O\^Ka:^I BY åN9"`C׫GF:b.CyvN~ Y*z4 > 8(*Ā5+-Nu~GK#׵e5{:Ecp7gjFܴzmvZ<ؑ}AGR1a׼(zdܪ:O*BRچ^4kq~(vzҾJ؃K.H+_{2Z ,㙁*4]m KK[X[ d^ÈO28Nbv4"L"܀>,`5+uˈ }k?;??c cl'4&I1_]tk{k6u9 +-e<48>_n E.K:nPa&ˏ9;2&FR,¯-A#1-D0t}CK6J.Z1L?VJd6êY^Y@f.2qjKĦ3:ѥH܋TqgO԰>Ai`YA'-jf16جHi:Z'@Ќ ŒmasNoYe /@iscɫfĦO^i9riw1efYDtYo4(G]j@+Ȉ`i̕y:=\+xpW^7(DՓ=E42]/4c_J,NKVBȬ0N&ODAL'of.6ߣS0J8{') e' c.9n2hjtlFʑ7=;J~^&qcYPa` =c:҇(| p̱  yXg}Z mcfIa&5oo!X-̂Vb;#-b"3RQ(8U";E wG6&YUFfYVO^;\~&4mu qi n^Ɐ$u&s:%ϫ|n`dXKбc4U;ya",ԛ.hH@<`eaPsG\S^9K#QipssZzA-.{7/yh6A nG&@8#c;I b;yW#̏}1{MkOe^hUzu_4I`^/lS!uVB|$ǴD,"BdVeS7B٬}5dSg$H:I(SBa9}˭lxPapzumML@YF坃P7Դ x$'IPu?bHBZ2M˂ţ,8x;6*4.?RG^+\&ewr7w섔WܯOI,Q`F c)KޑTLN2-谨QDaۀB> CVu6|c,}ųLAlUwn3 hѯE+h V%|^fiuϤbNnF$߇ GQGZ7IƳYsl3j3wt}Q*Jq9u\9W,sҚRəF-^HLOϨ,1lC @u$8c;|#צ^g{|`\*5wJ# c| -Vl;;eSIwO *GkV 7;ׯZ47i̝/@L-!/h8D* !-ZN, ;'}fiCC#.+*o!seyR:_t= _uf@o&oCx'YU2Ff)f;9;{{|QbBwsCkh{AdG3>}F D!E ހs_ .쮶XJW?Yk(7w(3gpf䱒,b~V|iM|]!H?a'ω5X,  +6=Nr˄w+8~TfȭoQHopӻ]$cN.trz-xԉؽx4?X~᳁+)GW)c6&P"֠g\))iR& #s':<IF}b3($I|N:V]mjغ$#TY];]M܊N"oyYzAj4I8: awܥw7zCEhO[}z F1~ nau>`I[;;?g\zMq4^6;yHQ"D_ qէ-(7.m0OaI"=O8;bW&K؉c?h%| E#㣹Ui$8za@bŽB>ji16W"A=l/<2&HrcrXvvr&Xķd,/RT8qN ξLt>2d, #mf2@oPڐ4J(h?MuPDY*vB"U<^痪?fHe1Zo_tmN@VU >Ch&EeJ3Vvu3z3 Ny1xsymiE()/ٔC{ζO"CdU&r 6K'Xс,Sڼ$WY9nWA̵|0, 'SY4Z?CN;s6X⟎B,z\~WkЌ4Jk:b"1խ_/ǿm\?R27i!Չ"7,; , VmK'[cM'd~=>usGU9K^ /@1.>^ :_ Se&~e![PǑ4WmJ0wUo$ۍ@':yz D`ze zVIAV< 6oO$^+1 Үoj7Հ QϭE7b*h*ؚj-1v5An>adjWB*/OoYw P?ZFqgMCŜ XGṢ³n 1`ZFcrl>"@w q0<#<*BzR| )c_n 0JsdG@ Hk2c;VtLq2o{M7.3P_a EE&T #tWnw뻥r|e|W{ &tkYѿ͎?a'p%mbKPx ZA #M.D.4fTE~t"ƛ&j,.-r4`fck(+.=E,oy%\"\GG*$CH}8ٽ|B5m}Y9ekA/Ĭ#462&擈V4I!H᫮xuRwwY-ovAY^IFk+(BT֧)m^|/77T>c4?q0U8태nH w zj/=݀Cp``/xdVUdeGz1 /7Iw$49ڤùRꘗdT] -{ٖ ^$;C} }Į[g8BUDgN(”ӌ0f&&uꖮye1㳼u[ln t<`Zp)g_kjצi$"[XaA&\^_z_3M-B#v~ >ӓE-NWe$?9IyzU%Fuш|ufԕBr>ShMQFzmZXx$UG_x48xC+.g]+Yzb ğR`hTw $H{],/'Eө־OrdMT>{ӊqLM e2X3z!JE0=?0:СakKWs+h.F)Vzo!}=t܊uw+4,d՛^f̰$,jMd4a]%Zʩ׺?CpwpH1*EzOpm+-Q&?/,B,ŵf\GB+`n|E}>}?4oS qZn/yc1QϥMX|wrPS =4_zn}V ŪXJbÊsb~o7b ag@_c9 e|js,B3 sWB?Yڶ24l^Ўu$ɮA5to˯XޚIfT=[;!Hp"Rp1`,=/^ΩقΚ m"":nR݉8e1?1,WU-k) ow궠't)"s͢Z:LYcZkA&؈[tFHl N;DAbA%UiGd[m>['ЄSd.ㅶuviWxBK4SFSBeQUp/.% ati9EļKH^8lȰO~ >FOmW%Zi>$l;_oVڗh,gG۴#܂/\G: ̗DZ 1YhU>DӎCy ~7&tZ AM#;Fb;7ɇܔIX`d}c&3FLօ-\,\ zqU1wr\ڿc#&>WqP^C=Y (3:dhO|ϡ>&j5g.gH60{zS AY60^`jgtm~DL/B[iV򞎣dv[anus8&Hܐ gVŷ%hK|vd; cIfΧ3DzaSYeg6I8ߋ*S9Md=!BfjrF 5l7(bѤǸ]GXĩvOuŃUo3YG]=MضA AeJWI;mBIIE Y-/y ^㰀i-7ayjpXȇaKe s Y[v OM[O_\2^oW(dFX;<w. O3%swMN2:PYqao;eISn-W I7€ai~ɈCVPcCyfIWf{&-jӘCiY S9at( }-^:]u_yomwTzH9g6Lݶ(4+ %ʅswס x]#sE$PIÑ> 3{`1</`.TNOEmu7q]a,cj< ! 6㽹 e).g=~ڋ^3a,sxg8"=Ssu\ʠ TgfaRƺ d\/VеW0()d/!-TvY;߲kegh$ HTA:DsոW*)[geJo枟&>L4}WM{ZӰ/$"r__-`3Dm0 ^ a+Iڡ1/RQ -oH:4%8!}C˿MF)sδG[V'$0/61pvtͣ[7`&vWes,]L{bX?Ij? 'P^rΝenSǵkS%kJ&;ZtrVʼnJ^`y!hWS/_ 8OÔǝYQb)OX#6ʫشly={ ];4 =o*(cˆ-m*@}1{Ļœ/Ѓ|"9H:9~ Ȑf 9C|@kr,2 m1 am ; F`AK5ۄPcSgL.+P|YzQ\|=3祋$ipSy)hz1t_~ּᷬJ:0@rT_%\DW&|z7]!``'=*ו_֎"_Z A"y0e2?bg{>uib_V{]C`cƹ4.M?]m.vʛwa_ŇLyjvlrq`WS6 YZE#c/e -;z1DRL"No2Q(;S[9zO: 'fFsHp"XE):`(}Y7ZoriG ^Q2AWVOND߲aϔtĪ`)#¤,evduշgRvx 1EVuY9<[l􊀋9}נּUN)YgG:.TooKO'x5S477mu.*PmtL)sLݙ5>AA>5K$E VM<]qՆSa`dD2\{Tވ+dw6b^o`FSf썊k(񚪄Ό2'q%FWvFBΒ5O/Ѫ##zu& Oblf>ɺX ~ڃ[}nb)E늓og*$W!Unx8=2nr_о\'D;MITT6W"TBPC3@(jXDFk]Xt{un1ޓ1˧ZWu.2v Ds}/PLQX̴W'6R޴wȷ|* Ā 4Ulԍ)<iYTNgxAδ}8XmYN.8!}ʘ.67D! T+Cg>pa^&pjΤw ݽτVHT?sI?so(-{Qʂa=N7IizKz0]JZCh\(zt bˑlxoM;czC+[Uryq]k&ePFrCm9٣\Voxa Nȸ bGL0@f3a`0WS%Ix_,Øj~7L}eyÅcXlZwmT%lFݣ۳!{6$ڔ~' Jl>c@%Tg/'y vkLs<8$Y`8\Y=dIlAT{P1(б jCi҉9$ܙ{~0QF]E!zUuHw5>,sfd{}/iB6>) i3t-d̴~WdB:O-.wwp!iid՚<~BTU%n*ѭy}SO#]V R{&ɓftr2+a)=X0񏎽 NY{F+Sdb}Oѩ5Kr)a^0Њpj*|,]g&==>Oa]GHu+4FEW3d=tPO9,sX ;8?HJVT#rdžkܓe%skL5K8Kx7Ze7a [4*dH|N{e(r;C=xPB 9!2>LG.(lf/ćД(z7`QC9 *d%F(0tN1ϼ:D+:G;m h_Y)9- MeIy>aeA~^=IoqttQ)f v =P(gM΁4='4)ģœ`(L0*bՇYv>-礰T cVM^1µW\Z I.[a̖? wpZ>ߥ/o<#ލHlcGؔNh\GAK'bEZU5(c99`w{\PxBOTP ,nWPizZKO:ZdW.t648hl=ЧO.ACCH+^T2q+9ud3:7T(^nOH FI1uōM0Vʑzff MP(!*ũW E/-gȜ@eWX+XT*.}C} z>8Q:ׇZq/%/ٟ12uO.?oV%W/?? ^[;(9aW/$1_l|^gi݅3o;~aC\O{jsuWKBcL))],iVʭkgOgk:VtB×5]^4׷34; U hv%e0 th*N*rIKn'I02 ̿ʢ.x="r= z':5߀uVe؀޻)<uopbBWLiJNGea-]VJx/ers6S&4:%D`GOS4W3Bqhr0lK#Bܮ} C!9T&o"ؠ oO"i7_j?m$5(7&ڈl ֡0 RwReLq# <\GSmjA 1A8pe|/I_\IQ͊A-\8H:0}길2:ۣLA"h$z?5/Pʑlk;j߱!mk `S&F;)6Sl#pz2OE"4iޑMހ-Bjt*}{3jܖMŷ]l EYPۮn;AK 5(:[G/BiHЀ%5cEPA?|&(rB5d35+"&u͏T0(*dF|UM$6ps8rx3įXySg_l ۫ } PPw?ῷZd a4 f[ !'wU>d@w(o“MRC&{$;{| q?MV%r 5:rU{ b#L]cnH]ECo/J0Eig{M3#{ڠ^x?So37'=LT EuN'wC$AeAӍ󑅠ԧClEDjZ`_4P!eL)etDźn_PLt0xX@W&B?-@kx?Hgd'Q0û15_bi{y$~Ue| MQZ~;D_agyoZ^ |I+% 7>@4xS'ݬA” }vnR)ߌAբ:Xm eŝzU1aHrPw}EU +) ;""QI0V%pG$P ǖ!u)%8!4ZқpVn^ T5 /`]7:>^80'Ql)4VVS^X?nkQ\*'qpC뛘~#̘B:3Q}Ĕȫ a ڛ;6{._V^blIdXag׹ *2pXDGL&^T d](:`1y៹BXf,-5e@VG'};n_ss4 BƵU4$5AI0-Z Dp$]! 򬤺Y|Rw2Ӵ,.O+B]c/̇-ɪ $NlP g I!mXt/F ^%]!bu'B`$`Ŕ&8-(2e^H&WN>6`M%ll^SNhB4-O_L! > L.= ,6҅sї^%\C*RM˩al$idˍG]az1%? ջWTw{$}Q4tp0:~_i /H<{TpY9'XL3 $͈3z(e':.O* mOϓ@r "֔]h"ntծJcMf^`fiͨWٿ4SKk]-UIн{}\~=*վі%hbk[ӣK^}J]SߴgG%Ps=ӿG&YtIѨ`xǻZ D9<=o=ۗinE~C39<}mjXU?t4. Gcم-!Wh]B$9pߠM>:` 'E0*h޸k>W^MŃ أhwPwce]oywqoMT-X@׬v['UhBRΉ)h~|x-|9E*xě1in{1P֝\E 'Y&~0LB-M'Ui@,Q ՠ v3},%F;;WAi&zr0kNm۸MЈw}uǞ' -Y܋|?mx}}RܙEjژ4OSU^H}A c\^xW)ꣶgc 8-7 lI$k2Y^ @E8unK[,L{^[.A]u%rp8c23`c}{)[!=u9pWRuplܟY54+ #|^ 1RJKڡMEgd&e|Ȅ 8d+ 0 >AD0,zZtdke"LJA.z/;#uW\,\Vg ?f wm3)%]A<ޜJdaGեD1 ~`Y˕3h D]skNm豈U0RSZ9vHd Vҫ0|_TBt ^R=5T( T}"Ac,0g* 8J/ZS.F_PY+s{mdm5|OLrYr`%&eWk9p ]wNo@g]@X7J.d: us*w YA+@UsD np[:U5aײ̅ Tyn:ezcPk/}Lo^^^pX€؞fXN>Sk1WIkj#\mQ䇶߄ {f. .8Bۜn7fNK v:L̗b3Vh?pYgYȳ>kޙ#ɶ !h;k-A Z*tN;v{f}*νE~^?69>͟,WPxE>d)cL->PLۍ|U1HKTC ia09MGS°@c⹇%@W B3/Jvv+8rW{,\ e!^@x/\iBTҦv:_X~%\-|jLIɌop6+L}[ffr&gY,zF출Tћ\&˓p=?-+Yλ;&umRQTE? ;s)!iTaW RI%=w w?@W|.@}U+%y C*8w,bEl cV-.V1r&.y <71LE]UojeMVs-值4b +Cv568X! PO!p#e'*u`  wݜ4^k_o 8o{ۑ}oD]XŢ`X>B[؀0Q?}gЌU}֢qSTdL)zU\ijq[v|2V+{:BM @UKfN;:B'GxϼyPoOrgWBk-s1mAR.7|_|Ul\9+tS/ÑwH)$A*XI[:)&Eѯ[ )i~eEX€迟rۦ iGJߘI^L 30@F'HdY-7iCk>M6e9q#|BC7L/ns"0~[hx V4:Ǥ%Z]zNR/%{=Hޮ}2W<;G@e0\Ssh[SiJ)ӷOeMr'jQ `/(ӯ0m})7fcd1BvX fr#ks9:Fㅖ<4VH/^ *e'"%O MV K8wm_/EwoX[DYN 6'c)k4U{Js^YQaZZ`ȱoR힜T _37A6Me4G:Ą<2.n ItJ e^v f_<oXQ47)C!bE/Ѵx{jȫ*<)6r$\\+9%#tm]^@QdvO4680iD8G߂r- !3053Gj.Z|P<)(m9]vrG |LԒ18J3Yف~kfV\7mhޗ)c[tn5qHVi/w9 =TASStuQ!;f/mسEPgլRBdݮi%Dz+23%䤮B?)<%i֬K;|z$6-U缮&wJc8Sn̜ޢw?LT+?++6Kbpj(S70NzVM7aqWO*#ۇ.y&f36гsWa@1\rk!m 22BG8G_多Ȟut t:?O`HU)Mddy[r1 1.gR@ SM6k q'mp2]8h;ZpGv~dY^i+$t jE7E@k5gy17Gd}..K^%iؕm"Wq.t06?uCw4kFDXjS`Z@>8wx W56Yln!nZ|hSŏҩG we0V2*bj-oAF8I.tB&zf|I`b_$ 7Bܨ=t#۠γGl9pB4$?:m-d`!1_{VLtNoH2M=/B:R f/w8jF)⇓Jc~y# ƠҌ3gGHUm# 3GO`ll;LhPP qCH]fUl߿ KNГǵipj9~ska eJ=:Ѓ˄؏kd]~6Ůֆwߣ>6YvFO?ϛ=%HWlGtoLV&=[V݌>߃_5M>d^(JMKvUnND=.7"<hޅT!m$!b82!vj6ͣދX3A3B }/4,ZfXHwY˺JBabij5Ĕ_bV&ehȒ*dMZ>cp-uNhޫDɜk.w_8laν !EUB@Đ #>k䞡Y||pAqn*]t %vҠRE<7_8H46PmZ!؆߹G}}X.?M nMҊxZoNQ4/>Saf{@ ƣuYx1[e `WHMr7UۗT4k[@c_+[@ˌ yx GE|` lgI_>1TZ`;!o'h@#dqj4zarfd{pqhp%վa6\+C ) 54Y=쭁ȢO o7K[3J0 HsLcӂ-%*\=$&vx0Z;ZT򯛹=pb<>ӡukbe`~V) +70zY]]P xCתVͨл\'O}s& $sWU:٧hA{L8Xq), ܎#%,cs"|~^v{WQ@O:kNPkcd55)su\t{[||,V,V(zȡz~-Կc9#>"t0Wo]zQ\Kv#9)GAtqvܓ%RVfUt!pW "iN AH}!ٺQN㭜ˎOP7iJ@XڛkhB܁gRKRCEV.s #Gw:$!TK#mM1FcDK5˥b&K<֗SOwZ|UWq{ENtѥ۬(tzaLI9 }M-"s?cKFd$j".cPIy7j%,F-:S):˵] .u`JX6/`sJ4j5H)Q$ǦxhmA8[5h7k8i^b"s yDҾ!*zujs_ iM[[&:ykZB"BZQcbq}Se8<,Vee &ήbl!XfR-hTb=h>gם=юvOH4I±OvWL=ʞZ)ˊ|H3Ef3j=ov2xo,W5/[J7kLCMXl%qbSuzG.{o'ҡ›G4sy+oz ? ynv@~,5kxxg3^Dّ,4jq˅eF;e Ke5"X /dߥ29pV<ЎF1O&F2qOͫT,V9 s0B[tI\E:xHDCyַj*AEת;S1WAG[q¯`BnbN&f ɒ_Sg2_Eb[7R M/;͚;p >C-w\9EFjMԨ򧻳X2Y)28[SFH˻匾|9x({k' &BcoPd93ϻmZ6.\"s]hVAHl {8bu~`T R fщR/ I%Vi .Vj6[iiЯVOԅRjX]}pla bيb *^']&+hΡ0=ؚUJ~P-vWjiQ "5}!w8  %dF.dJ,R;G[dDV&'qLcW[ݙ5Lr'&'{>+w'dEZ"ʔqKohʔjx=3;yH )Ye8ҝz>4 [6 IƂ/Ca ܑoSxR\s=]$~]]ӌq՛NY:;uvi5[k0#[̺NҍÑ{f&VdZ&Eʥ7j_702G0D|+ѱ>*4ځ9_q?E|];aM Tt ScHceU &?/*|!&w;e2덲y#0L1fNb:GXAۇ4wO̚Fgl[H=gZ£Faan;3~$s m+n˙A]f?p6m ػ )rN^4c`tSFcDug! [mԵӃ[[TR븑 ΫHAqN+2?,3E_~>)M@# 7n5(囅Y_'Z (~i]v+bf6CWϫgxkh _tˆ CwMKBqLY0cګD@9'-h0^&FxCKr94r/*7ch-<[sBoGmߒJIDP<3=DuBqb_6w6~@eVs1Յ 1VDq??C1M\Lj^߽9$h>xm #D)+QpƖ!_5/ +o>QR3|Uc{gfd~'A5y6+8JpO8v0d ߀ I(r}P^4S2]a!ܩA ߘA] P?A îaY뽂w /X{Q0مHs;4V^vy~F%0CcWQ-Xx"VHѢWMgJFv t3w:j1 >b lTY]p,\jpIAUp)5DW1Ħ,Ok5}}1>bא]yvW-Xd-L4ZQT4A= ӽ=7JsYK6*"r-Cӌ$gbp () @w.=\꽸; c,8eHbp HA-. #%o[Әs2HKn;C##̸O%hN)f-2{ c}@?KE;\Ec҄`z5\R[>Bz7\-`dvKȎ頻W[! Fb3*d1H:,f+3d v;.^WfLƬ?ŴM=/I1xJuruEZ%;Qn*d1{ݘN0Ǜ͝o&Dd,1}y(CHv XN' L[M̷#ób !iThwSa: bݢ7VVm\obV}?fBb=^QT WF '׋#?_H #^%FIy82isq|AiN|}+2le΅^MdBZW X[3C{ۺΆ=J) AӨ7d?d(:-heD+8JfmIŒmcᜑj5md0j5p}RDӜ'pnvmn9 q1Za^}6|aM(t(w]Gm3r[Q7%psT/x^G4u+Ԓ~OEr+(|g~8phf?ZW{}֨2tszi=Wz?=YK U|@&MeP'%ѵf|>Y)5g"qGЛ ^i}bH39d?,H~TU59 "7ˠ;Ƭ|Q P/0bm~׿6DnNQƳ1O47>6ОӬMu4t3B!v ذl5F'^W]]pB xQm] ihP <)ʼnE=chJbn4 \mؠ^g͔οJJriu`!KZUBV58le_+FP? Aw_4F9YuoN J| E)VTCr%lv^%N+f^#ZnIr'ܗ[F]PSv;S(f\augzPuv`>s99ސH 6'[k@3@~^ԉv;uͣsSzfi<\xKEgH?k2t-_$y𵂫 -XUmQJ~Ģ#C;({(y!I!!xGAsirF)OM]X& Uϋ?]>VB7qX6C)YUg6ڼ/;QYP#n`E <OzzK>}x[60# ^#6rf{rfau_g~e @ "W4)*7IɣxbcY O2w.OXZD˓P-/vT Wa_ O~QRlϰ7`CU8M `{iL#dFΨnx"k0 {ȗ?t JC| Y8:t C׸0om0 1$S fMU̺& 3[SBiٖ9De.{51[Z~P1''PWS, {ֺȰR|O!5Ⱦr"ZeKq(>~!Cϙ> `uC#$NwTe:nYճ|OsK 寚'$C1LJuI`Gu[z_̅K/wG9v ܎jS VU@ߣ_͇;@zU*`XӴšWQ XY6(jo hI5 Ya8T_Lhᦨ>&S {C'NVfRQ6ġvlj|l>T,~Ԡ~NHo3(j,ʘ̙ 1薀Ǜ>4kjm<L>OGLێ0D8 reetŽ !|^Dl56 Nae7z{HvVo}?*E@PW; #FZY*87,(}kS;u}ڜ#)uζǦ{朚p>q vpֵ\%I3$p՛gV]U;beۿdd 45؄'J#A. 35p! * c.ZK|i ^e"/ ׏c={Q۪Wg}33KQV`$?,\J]+* 4 0*QyR"|<;'ӶWDESr‹piDBlGiO35Fi~/ׯԼQ0DmQo5{C O*EÑBO.7`KlSEf7lx$b\wSKI= /bkT;ݬ)|=yNΔpJ-G<U >ha+YxmjQ?Kssָ;];\nuq'5]/;>yQvަ턻$')&A -x.!TDru]=?O=?;KT~L a;Zb4B}pR(] xXs`pm! 6̔%K_ L2sR30܀:1<JP*-Z 8BdKK輸 a:];^B8}l@ϮD%@.\:= R:|[ =0а/7fQ#sEnYY/;V|`G^ބϽB=fm6/\pjKϝ糰y.kޙT&;bg·D|-38QB5T8? X{G/)#2D0H뗾(a ߢg)ͧ>!QWft{ *ؔ$\4~r\'p =8v) V͠2P G)VKJwRT ȶ"ީѪ5e~ޱ{D;ѯ"3JTSeX->l5KšԩÃvP?L9ج^.e[~&Pi|^i ZVJo ,Zf.vBY;Ÿ ~w(pHoA~z2PUwRmXkU媌$ ,Ãhlm7sQA` G! pN/ r}ĝ!>T R 4k77nlpPep[ZҪuZmGŒ0$uv,L@-FioݳCK3#\9 $,+! "\7Jx`u6\?/gTbZ|hH9~&uG}|:^% ~\yMݤub >NwrqďA-PxLō3Fsނhބ̸zvš)%|=M4<_w*Q/R\1=,~ &l>`(r0PL^i pKZIeC'RH% WAf+FPeJ VF|S.%eSE ѥ5kH+7 !j> Æ8??oMܕMԈ YMo$n?Fw&gW*nk[/FdYI7??FQFtu~ :6_adso5T Q!(JqQ3حX)xĭ\a?He?MU{<&iQL9Jɚ4FdD [ i5jǽ zT}״kn3lTϽ3{lפn/t&޺)Xj α񢬖 BJdSY-6SjԔw MWߕTdvj'h.fw >Z6E' H6Kf {t2F#S5'jD#ـk*'9$ZlKuWl༑`=ȕLsx\\nqc:NvH{R`(g139ǯ\F9'bf`3~Ss9`>P! 1<3wXWSnoګdm>{3ͧWua.Sr*zNntP:tovkny>%a7 -X~ ]r6s*kҎ[ɱ,GTn< >]9*$M§G3a SZ}j^ lL &Z":p,pf3+x$h Zj$gUؐ]c"J*y0&S9J&s|}µXqmTH|@*Ni|#!Ydey'KGܝmeN?xJrT\8o.ǫs.W}N^5ϼpno4.d hJ* 4x{݋W(e8ΎBY )h-d~cDV0( gyVAzqBis48 nELR9!Y˰&s37 !iw; 婴o23gcψLJKMZ)rj8< mOvG,ۉ8JSS~ftU]0_(f6b11lw h_.x܁#ҭ N[?o/L*V6B2Sy.>?}z1a\Y'!<3$ sǠ@zm ͈7Jj9G(sN|ޘ$3A}[.Wu7pz5&' l~]04)'Q='}%J:]δ H-Yr/i&˔w هޥuAViO=Ca+=k3AbX'jrT=ΏTόQP|_˪,ւE=LG%ӣުA=iU#q=:堈pK˸28OUtفWul7*xݴk<\4z@lМnT$[k>`q{#ZP^ZҿSр"={dFT_fK^ALDμ5yM =k}ai<Ӟo4>Mя#$֯`mp>M;~Vd{ Ud#C:| oDnOؘ-F+YcqLOtΗV<3h]ikZ|``nwI`fŶ^ExCkZjkH&:&2Tp8ޯJ 8Z0CzSw~EnV ūBmh7AtkwE*Uے*r(GٚQL+rY MM# 窓a`zfnV9Sjk/ݎRijeS0wK-p 1p9 :RU~RRl>S*FW9YC/Q.Gҙ@i.` 2VOz̒ H\ ^Wqv_8?Rmx8E LY) lNay+b"1E ;Yٹv@>Y?Ru+Jk'-V ۦ$yF)K_t 4㬿٘tih }˶W\QXp9ɖ\hcdwHNt[i<$v-t{)cTZڄ-w15~dq\c(Pj~(oxGI@]lr W,7./gԀ{_sC%wFgNC(ː+iSU0|2:.>uV ~U 4P+p&h- ,id28(@HL6oV|H'^]h ԰T)dplC㹝(cqT׎g{tHOg DgF{Q G( Q>|#> c jjN㋴d! ?}Ū_ $c>}igA).6(&K9+[!omfF#șK^WXs \\j`]IC[xo98Q)ĝ ZMUJV  XְgBS򻭾aqbEWQpKz7gȥvuٮ'0eԠ|$lVÙQq9(V"fUrI;?7-cT]gk'Wb̘,`i3Q>!CX}"K =U{6Nh}rN"E*K#%MvNj2w!ǹ[s/[|G,-W}01-4SmwJ`),R;B>MLc^en;.~:zd,N]n21ETVILli 6_]yBMrFq|&FVRzDX,S9$o`έLj*"As?%Wa4E؝zث^p9ofqi¤7y g; 'c͏5.huЮK@ )QkZ >t AgYQR!>+*)+ȻLvsS~]MpFj׽!N>|M]9Mzo:}D?9ܱJ;ܧn#CO\d<=*ʛbidov<^{=Opf\,r@ Y*üΉ9^)ig>g?>8x0>xxH JIZcVzэ^@V/fDX/uzY*A߅U }qh>m2 S.lH/ز sA>n}'JLYtB)"{ySoMjܢ7)"oMX}jDdLֻ!X֪l8H Wܦz;bY%j gҚ=^hpo`EMu͜hs G?amΧw ~߯mŷ95E- I?@ض_L,<2FW)vWM2ZOEASNA*3io'Ӏ=Rr"$ \IZIh9 nta;).^X Rce8\E|y*m\PYۯ@䥬,` ~8р[%Ƭ) •X|r\BɜLvpZXR"e?<'6YEYVV)ƙ:H[]sZcwGD9ɀpCi|W"{\G( \9܍ G *[Sj 'HɁjS9 %M]{Eqt1g^B jpQ66 |rufs!,,傎(VjQH~Q 'KzI&@.%YD6x>kߙOGVEO ʽ=HŹ P$S!_b G ts%3ٚj*aW_\Jې)Mg{ǧf} ^B Q?Ǭe4"xqkiF..c"ȀGM; DQ[ר{iocjgqT.H~urcfDi[`;<y9|i ޷Zz ĒDz3 j|pfd25@@%㤖:6$ma0>40߃3$ > h>][Hd/8C/'P`ˁ-)7(cNV'li>ywj/N.?աu)Rλ9ǽ*?9j#СD78**8kkD90j}tk$qˏP`Јo4'kWLi☾M ~x옡e?p1@/r 5Lc䆉5tIhg'U\'Q­ɴ$˽OPKF|XkcreKĔ1M,i'OGsE 5Z`h xQB_"`] Bnz XsOZ`*՞9g$pr" "XU.C;6(/?a"W(qzތy %m OC X,r-|"99%4 2]md c5=&* j!N.6>EVa÷ck#i=d#ֆfc4V^:G8t Z$ L=jXs0#DdSfK忧enVr2ZT;"Bڻ ʀdM6/oՐ}?t4:V mN~=Ed>eƽ4Gx֤ib" KBX~/2#bld5]J =G@u T[_0 =ۭ9tJA<C4qA ߚPr]{%'l*Q۾T[աimzM\kz:] U9O49 ÊB#Ų[K0b3Iy=NƊ7EM4FX{qO9M%yBxsJi!o[b*L9淔H hȵdaЁe"J ߰{w>UXz\;'x[k_J;k͏rJ.\kAq`N:~RrCQbMQ%vet05!SY'̺J2d޾ez}je$Ktj+ ĂnHiCX+hpѸエX4Q^.7{X>w;& AKKڄcZ~IUd'{S1mz  Fey Q̷P JTd؎e8u 8uoQ3iNH& TduV W#G'K\h'fY#OUB|&98y :vǾʆY9 *yb-Gsy^aNU wA'DWLK.dN{?~EUO1:}$N2.)/&|eރ5/4^d]Vg]8!!l޾&;Ctk^(9 =Pi&xvZoLFpBCfQX$ZXZ69%P Sؿ2f+tJ寇lq`bXo8)Jj4)$yxGa2X=$u(^ȄѷdK?%4Ը&+mt*igw vI칥-Rc^ɭTνS-F6go5-4ֿk7&J3ONmF܌XM]zXI,8oϙ}v|Mh&-(#j }y7yk\)(o1HPU* {"W:0|ߣ >Ncqz$r7MT ڙW fV&/v{?!J PP\f=[4`۳pkEF._Ro6p,ՙ9Oݔ7n-w6+JlEqăcs⬳Ir]2+$&ҋj\8?3anq4i&HWJH{$$Шu(NJVK-q,?d(^>gX5h4xπdH&ΗIԾKI!c%1Wd" TA[7GnU{AI JJ9߱?G2>e$2XN&7Tp vp91?{~ZVA&l\^_дZ)|9~k_zVo$O1Jvp?0A{rP\_UOKM/8Ԃ̈ZU۠)ᰣoV+4.}=f[= f@OԄ^/:Pb0PY7)ʦ8B@V|;zVsv'PH^aCo <x\.*z#KX72 92<6Nz1&>#$P/l_e@Je#:r G6*&2qe0`߰0bc|D~EF*ulZWk#ιp?:ʒF{pP|~\>Z4ߡ: z}MyRr t Hw;{?}4<Kcڰ0WIG@vJ,2'f=_u>X=b5>YڽQdٛM)}~+˓X{mU¹#Is_ԘF^MWډ[`w!A0٦a?I"<=Z2+J'H|H+N4bq"1;* gJo]! ѳpu[-mt'o9x,ê c.0?m.SS u*-NBu =WY>4r[ OZ %/?^O/)Pʂ"9?\kӣᅮTaÀb,N1'|)D%/y<%jz%߅ZMzx7i5OU  /RݦʕDEJm샛5 8qC\zooS|K5*/& iV >[n<g B6[? #Û;RM*D6/UD~zDYu#4`Zwt:Sn:Xlz@^|UAZ2sӰX*2Py{zQNޡ$1]n3nR-y `&_wpm.z.0&)52t)b@rk4D hoZ !-,v@i#8\'eS G֚{D8VlK[ -(<Rd~/U4=-sh,ꃃ\vgX:Q T ^%X 3\#:Ș sW ynHtQő(8>[ 졠=G;^[x_U0!'}*,]s9>Gd>_S G1/w,oz,B ɠ!GB'GhnK)`ĎksjV{^\Y=o4rRMM zv6yq}.W Ċ5bLUrz!s36G~݊kWϝwİ(T'cR6ZA* d񘂶dדMm/tznf]Vx>Bw à8O!(0&ULlzA Q>F;V*=b{eғ7X07KfuSܛ)8[D%H+{"2 >/܆XZ^d%G;%;ӧwݜe\63yr +XrˈD@N^EP%T`)sYfCfq(6jgez+Dw*nGͥڞn]%2mv&\gKb;m W ?9R]hc)= n^ ՘i.c矆COVJY%r>~'QJSw葨8%*Lf½օ>lq>yGKI.r;)s`z fݎ u?kU|p~ѡbC7ɬ˘ȭ0e>\뾀e/NvgFRut"8V/Dag4Zu{*àS##Bt1]+IS/mG0۬;I92&~ [ҚR]¬>^SosBtcrc/aK%7=[>ߣl6m h@:VoN,ת1e6@lyoy:;@YR 5*bV nh0g}{;h|3Sf.{Rc&).'}TW֚{{@e܅6[sx`ɪ r82(d@^7iӐz}#Z!7̩v$I1:+W'~F H߼OK8z:A[Ķ3ZHG뿹T6A$Mlo<&[BY]/L`wڲ S1#Ssy*qtr;OÅ(pa'F*ZڼRYw!"s*}Qqb.(xkaEC_ }3E V/=7oM.1(!*ܦֶ{6_'?+?HE^F꽔sFߌ p-JT* rIN;U!oFzP\XsvkD6=A=^z4`*HVZ#0J3”GTVZI.i.gTDnؓݓ#\b k>;} |TKDQS#<5lO[k+C.E250pZgj8 O(Brnκt0iEMw)oRL_:Z1T3nR/,>ō=ЋQ 7+T6* o mߘז˅ 0%h ?>3đ#)*ddGr8uO0f/FG1nv$ 4aҶ"cS矉.c hj_s2)>Һ}:mYLuoRGEU 7 v̚ 4oܮ!bna0,X0_erf|zլQ hYV>Yx9LeZ&jNqlU- +HM*px٠mD4-%/BtWt x 14HlJ%M>Nn8O-;̟I29&xqv4Lyl1J#:>ifs`,+ ,fy/ӣxsy~|8Hc b"zA43 sJR+tCdNu^ӂ#\^%6DbTf6jIz~1q;4ĸ8>Qs~U5kRt")ٳNsd8~/!$}ͣ 1qJ9gS>#µqC^Z'Փ!S)8=KUj:B7@(%N3q]rulV[8 M`\SQky\g pg@tKA=^iq-"0Dǥè< _JrLbAU\rFe t>ER +=r:ꈢKWxO#;NVY܆cB_|A4jZrjk}Il=J#)ٴ!bE-SWѹ9M)òGXmrh+8d6m5fדp~!($HTĔ%I`:eU@xِK_nr,u;+X0}$V;|">{"pPxE[֔3S:!,n:x* 2rCX7mx\廥=nyZ0aU{6C%4.fe0$;rNn;#{ܤ\~ _;%k[LY~GVׂ4_"BQQS'+oH6 ̝կ̉.aJɭ()o&9 lT)j<ƫega"@u#Qr3Bk/>;Q oP[u =T=6)[p6_Yҷ!30SF5\|5s@$_: w_M/I+/lQP=O jNY9\62쬣VSHD%ioq =EOf/5 arUQ*\}?bvr r?{:'h5E:ᨠ 4tbA?YR[(粑 床B–C+K7*9`N(tǴwJ7dRX:VMPǻ"v9VomvȪp}MQ~DZrqPn78ٞPFXJ' ţs婺TuF^m*ޭ7S`%6[ _Zc+LF) \\tY^Â3{FC$.s(y(8S [NP;jun·-1|QO|]ӂ_p+H/ޡ4*Ҕ%J%g[[b8X3k<Pg4h&1y̘N`w6dk.]luӶɒN%3s|l#S(IĢnp4h9(]9>S+6S4lĿPxgf-U0\LbthI5ƛ30u=Q%u_3~^<{(T,𐺼/Ŵϔp!FZ!#ނwUh XJy3t}H/WNk*+)?.Rq\Wag1\c(ڻBMc#ǰW 1vf X}4O8xK+=§>U2@(עީ=uG[>ԫV`bB%#2 zE^ktg߱}oԧQ)Xm]Xӧ9Y !R@ RStώ?m[;)і "ɔ`>/=*P&*h/y]H+IRyEu1%eŠT?HCy}I>ቒޙ2fCX1uB|a z9j|<^):Yg̈ a6EA/TQ3Wr&<-hOSs+d¤[[ǎG'9R x/+{6wH|J~s*-'"0z!K} rB-U̵AF\~UW%uUVU(-⾞ar\աzG㻼mױQ~!j;WbB64GFgIl 8Zz|6vn lTMNgwq.u:dJ錄;w;:Lzq+3%m=[G;4u9f>n=:$Ga3.BVNT򱮦 /5w̾9i#ImV Hl17)ϔ?[ej9_[ kޯ 2yk)M]_)}4Yk7t};