openCryptoki-devel-3.8.2-lp150.3.1 >  A Zҽ/=„n&ǡgL"aI1cCplO1ŏ'0͹F n]_ȧZzdYfhY`燐UY t)v$@9џIMص;~5d}?Q .V x\l¶<bƎk*ҙezf+*}w[b9cc60fe15a6d2bd1eeeb58828220037fbc4af01c3410099ae73d07aa8dbb76cbc15f4c9bd6e6728001b91421e14f84250767ca4xZҽ/=„okۨojr,->~H [ 0! 3eWYNkMñ+ ^haUHh~J)//-IŇsS 89CuQ%$4}xYS~dM7XهL ;I8%S^x.G(O:S\*ydMډtٽ*=҅]q4 ;=f&DQ5D7^tcqUVwfh%Yʯ3\VU4lJn|XW >p;Fx?Fhd % rpt  8 D P h . 4Lj(8,9,:\,FCGCHCICXCYC\C]D^DWbDcENdEeEfElEuEvEzFFFF"FdCopenCryptoki-devel3.8.2lp150.3.1An Implementation of PKCS#11 (Cryptoki) v2.01 for IBM Cryptographic HardwareThe PKCS#11 version 2.01 API implemented for the IBM cryptographic cards. This package includes support for the IBM 4758 cryptographic co-processor (with the PKCS#11 firmware loaded) and the IBM eServer Cryptographic Accelerator (FC 4960 on pSeries).Zҭcloud137openSUSE Leap 15.0openSUSECPL-1.0https://bugs.opensuse.orgDevelopment/Languages/C and C++https://sourceforge.net/projects/opencryptoki/linuxx86_64A큤AAZҨZҨZҨZҨZҩZҩfc5f8f8c7134201b2ee5c01935257d7b72ed903198a618bd6be84e6c0609065c12cb16baf5ff8344392cc7a9ce280d2f63567f57cd21c2f944e2fe33596a0a59062c601d87522f12d445fa7829c8f3c14158106f45d70ce662d9c25427c3e314rootrootrootrootrootrootrootrootrootrootrootrootopenCryptoki-3.8.2-lp150.3.1.src.rpmopenCryptoki-developenCryptoki-devel(x86-64)    glibc-devellibopenssl-developenldap2-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)trousers-devel3.0.4-14.6.0-14.0-15.2-14.14.1ZZw@ZY.@YX@X@X@X~@X2@W@WE@W@WW^@WEW@V<@VqU@U@U#U#U#Tp@T T TT@TT@TT@S@S @S[S[S[SSR@R@R@P+N&@N&@L@mpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.comjjolly@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comcrrodriguez@opensuse.orgcrrodriguez@opensuse.orgcrrodriguez@opensuse.orgp.drouand@gmail.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comsfalken@opensuse.orgjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comro@suse.dejjolly@suse.comro@suse.dedvaleev@suse.commeissner@suse.comcoolo@suse.comcoolo@suse.commeissner@suse.de- Added ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch (bsc#1086678)- Re-enabled ARM architectures now that gcc6 is in SLE15. (bsc#1084617)- Upgraded to version 3.8.2 (fate#323295, bsc#1066412) * v3.8.2 Update man pages. Improve ock_tests for parallel execution. Fix FindObjectsInit for hidden HW-feature. Fix to allow vendor defined hardware features. Fix unresolved symbols. Fix tracing. Code/project cleanup. * v3.8.1 Fix TPM data-structure reset function. Fix error message when dlsym fails. Update configure.ac Update travis. * v3.8.0 Multi token instance feature. Added possibility to run opencryptoki with transactional memory or locks (--enable-locks on configure step). Updated documentation. Fix segfault on ec_test. Bunch of small fixes.- Removed ARM architectures from the build list until gcc6 becomes available for SLES. (bsc#1039510).- Updated to version 3.7.0 (Fate#321451) (bsc#1036640) - Update example spec file - Performance improvement. Moving from mutexes to transactional memory. - Add ECDSA SHA2 support for EP11 and CCA. - Fix declaration of inline functions. - Fix wrong testcase and ber en/decoding for integers. - Check for 'flex' and 'YACC' on configure. - EP11 config file rework. - Add enable-debug on travis build. - Add testcase for C_GetOperationState/C_SetOperationState. - Upgrade License to CPL-1.0 - Ica token: fix openssh/ibmpkcs11 engine/libica crash. - Fix segfault and logic in hardware feature test. - Fix spelling of documentation and manuals. - Fix the retrieval of p from a generated rsa key. - Coverity scan fixes - incompatible pointer type and unused variables.- Added libica-tools to the BuildRequires due to repackaging of libica.- Modified the spec file - Changed libca3-devel BuildRequires to just libica-devel - Check for systemd in the 32bit postun scriptlet.- Upgraded to version 3.6.2 (fate#321451) - Support OpenSSL-1.1. - Add Travis CI support. - Update autotools scripts and documentation. - Fix SegFault when a invalid session handle is passed in SC_EncryptUpdate and SC_DecryptUpdate. - Updated spec file to use libica3-devel instead of libica2-devel.- Upgraded to version 3.6.1 (fate#321451) - opencryptoki 3.6.1 - Fix SOFT token implementation of digest functions. - Replace deprecated OpenSSL interfaces. - opencryptoki 3.6 - Replace deprecated libica interfaces. - Performance improvement for ICA. - Improvement in documentation on system resources. - Improvement in testcases. - Added support for rc=8, reasoncode=2028 in icsf token. - Fix for session handle not set in session issue. - Multiple fixes for lock and log directories. - Downgraded a syslog error to warning. - Multiple fixes based on coverity scan results. - Added pkcs11 mapping for icsf reason code 72 for return code 8. - opencryptoki 3.5.1 - Fix Illegal Intruction on pkcscca tool. - Removed the following obsolete patches: - ocki-3.5-sanity-checking.patch - ocki-3.5-icsf-reasoncode72-support.patch - ocki-3.5-downgrade-syslogerror.patch - ocki-3.5-icsf-sessionhandle-missing-fix.patch - ocki-3.5-icsf-reasoncode-2028-added.patch - ocki-3.5-added-NULLreturn-check.patch - ocki-3.5-create-missing-tpm-token-lock-directory.patch - ocki-3.5-fix-pkcscca-calls.patch- Removed reference to pkcs1_startup from pkcsslotd (bsc#1007081)- Added ocki-3.5-fix-pkcscca-calls.patch (bsc#996867).- Added %doc FAQ to the spec file (bsc#991168).- Added ocki-3.5-create-missing-tpm-token-lock-directory.patch (bsc#989602).- Added the following patches (bsc#986854) - ocki-3.5-icsf-reasoncode72-support.patch - ocki-3.5-icsf-coverity-memoryleakfix.patch - ocki-3.5-downgrade-syslogerror.patch - ocki-3.5-icsf-sessionhandle-missing-fix.patch - ocki-3.5-icsf-reasoncode-2028-added.patch - ocki-3.5-added-NULLreturn-check.patch- Added ocki-3.5-sanity-checking.patch (bsc#983496). - Added %dir entry for %{_localstatedir}/log/opencryptoki/ (bsc#983990)- Upgraded to openCryptoki 3.5 (bsc#978005). - Full Coverity scan fixes. - Fixes for compiler warnings. - Added support for C_GetObjectSize in icsf token. - Various bug fixes and memory leak fixes. - Removed global read permissions from token files - Added missing PKCS#11v2.2 constants. - Fix for symbol resolution issue seen in Fedora 22 and 23 for ep11 and cca tokens. - Improvements in socket read operation when a token comes up. - Replaced 32 bit CCA API declarations with latest header from version 5.0 libsculcca rpm.- Upgraded to openCryptoki v3.4.1 (Fate#319576, 319585, 319592, 319938). - Changed BuildRequires for libica_2_3_0-devel to libica2-devel. - Changed BuildRequires for openssl-devel to specify >= 1.0 Contrary to what the README says, version 0.9.7 isn't sufficient. - Removed the redundant DESTDIR= parameter from the %make_install - Removed the following obsolete patches opencryptoki-run-lock.patch (/var/lock and run/lock are actually the same place) Also reverted the changed to openCryptoki-tmp.conf to match. ocki-3.1_10_0001-ica-sha-update-empty-msg.patch ocki-3.1-fix-implicit-decl.patch ocki-3.1-fix-init_d-path.patch ocki-3.1-fix-libica-link.patch ocki-3.2_01_fix-return-type-error.patch ocki-3.2_02_ep11-token-incorrectly-copied-the-public-key-object-.patch ocki-3.2_03_ICSF-Token-C_SignUpdate-was-sometimes-segfaulting-an.patch ocki-3.2_04_CKA_EC_POINT-is-not-required-in-the-ECDSA-private-ke.patch ocki-3.2_05_icsf_ldap_handles.patch ocki-3.2_06_icsf_sign_verify.patch - renamed: ocki-3.1-remove-make-install-chgrp-chmod.patch to ocki-3.1-remove-make-install-chgrp.patch- Get a new ldap handle for each session opened in the icsf token, once the user has authenticated. (bsc#953347,LTC#130078) - ocki-3.2_05_icsf_ldap_handles.patch - ocki-3.2_06_icsf_sign_verify.patch- Added /var/lib/opencryptoki/lite/TOK_OBJ token directory (bsc#943070) - Added ocki-3.2_02_ep11-token-incorrectly-copied-the-public-key-object-.patch - Fixed two public key object inclusion in EP11 token (bsc#946808) - Added ocki-3.2_03_ICSF-Token-C_SignUpdate-was-sometimes-segfaulting-an.patch - Fixed GPF when calling C_SignUpdate using ICFS toekn (bsc#946172) - Added ocki-3.2_04_CKA_EC_POINT-is-not-required-in-the-ECDSA-private-ke.patch - Fixed failure to import ECDSA because of lack of attribute (bsc#948114)- Fixed BuildRequires: libica2-devel - Added ocki-3.2_01_fix-return-type-error.patch - Changing doc/README.ep11_stdll to unix-style EOL - Added BuildRequires: dos2unix - Removed globbing in %files and specified libraries to include (bsc#942162)- Updated to openCryptoki v3.2 (FATE#318240) - Removed unnecessary patches: - ocki-3.1_01_ep11_makefile.patch - ocki-3.1_02_ep11_m_init.patch - ocki-3.1_03_ock_obj_mgr.patch - ocki-3.1_04_ep11_opaque2blob_error_handl.patch - ocki-3.1_05_ep11_readme_update.patch - ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch - ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch - ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch - ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch - ocki-3.1_06_0005-Small-reworks.patch - ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch - ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch - ocki-3.1_07_0001-Man-page-corrections.patch - ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch - ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch - ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch- Also create parent directory /run/lock/opencryptoki in tmpfiles snippet if it does not exists.- spec: do not use -D__USE_BSD, a glibc-internal macro which no longer has any meaning.- spec: use %{_unitdir} %{_tmpfilesdir) - spec: call tmpfiles_create macro, if defined in %post - opencryptoki-run-lock.patch, openCryptoki-tmp.conf: use /run/lock instead of /var/lock.- Update to version 3.2 +New pkcscca tool. Currently it assists in migrating cca private token objects from opencryptoki version 2 to the clear key encryption method used in opencryptoki version 3. Includes a manpage for pkcscca tool. Changes to README.cca_stdll to assist in using the CCA token and migrating the private token objects. + Support for CKM_RSA_PKCS_OAEP and CKM_RSA_PKCS_PSS algorithms. + Various bugfixes. + New testcases for various crypto algorithms. - Only depend on insserv if builded with sysvinit support - Remove obsolete patches; merged on upstream release + ocki-3.1_01_ep11_makefile.patch + ocki-3.1_02_ep11_m_init.patch + ocki-3.1_03_ock_obj_mgr.patch + ocki-3.1_04_ep11_opaque2blob_error_handl.patch + ocki-3.1_05_ep11_readme_update.patch + ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch + ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch + ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch + ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch + ocki-3.1_06_0005-Small-reworks.patch + ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch + ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch + ocki-3.1_07_0001-Man-page-corrections.patch + ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch + ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch + ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch + ocki-3.1_10_0001-ica-sha-update-empty-msg.patch - Project is now hosted on sourceforge; fix the Url - Remove cvs related stuff; tarball is produced by upstream - Use %configure macro instead of manually defined options - Build with parallel support; use %{?_smp_mflags} macro- Fixed ica token's SHA update function when passing zero message size (bnc#892644) - Added patch ocki-3.1_10_0001-ica-sha-update-empty-msg.patch- Fixed README.ep11_stdll to have Unix-style EOL characters. - Added patch ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch- Added all files from %src/doc as rpm %doc (bnc#894780)- Added pkcscca utility and documentation to convert private token objects from v2 to v3. (bnc#893757) - Added patches: - ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch - ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch- Fixed pkcsslotd and opencryptoki.conf man pages (bnc#889183) - Added patch ocki-3.1_07_0001-Man-page-corrections.patch- Specfile Cleanup, Added directory macros in appropriate places- Several package changes as per bnc#880217 - Added openCryptoki-tmp.conf for lock directory management - Added 'lite' token support - Changed from init.d daemon to systemd service - Updated macros in %pre %post %preun and %postun sections - Added missing icsf and ep11tok directories to %files section ocki-3.1_01_ep11_makefile.patch ocki-3.1_02_ep11_m_init.patch - Patches added: ocki-3.1-fix-libica-link.patch ocki-3.1_03_ock_obj_mgr.patch ocki-3.1_04_ep11_opaque2blob_error_handl.patch ocki-3.1_05_ep11_readme_update.patch ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch ocki-3.1_06_0005-Small-reworks.patch ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch- Moved libpkcs11_icsf 32-bit out of s390-specific files- Made ep11tok.conf and pkcsep11_migrate specific to s390/s390x - Added libpkcs11_ep11.so and libpkcs11_icsf.so to 32-bit s390/s390x- EP11 token available in the opencryptoki V3.1 package (bnc#879303) - Specfile changed to include ep11tok.conf - Specfile changed to include pkcsep11_migrate and pkcsicsf tools - Specfile changed to BuildRequires openldap2-devel - ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch - print_mechanism() ignored bad returncodes from the called function token_specific_get_mechanism_list() - ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch - Fix failure when confname is not given, use default ep11tok.conf instead - ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch - Removed check for ep11 lib at configure - ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch - Move stdint.h before zcrypt.h to resolve dependencies - ocki-3.1_06_0005-Small-reworks.patch - testcase fixes and file permission changes - ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch - Fix for s390 31-bit build error - ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch - zcrypt library included in build by default- Patches applied (bnc#865549) - Fixed Makefile to complement common code dependencies - switched to official m_init() function based on library change - checking the global token object count - catch the return code from object_mgr_find_in_map1 - some README updates about usage and restrictions- fix build on x86 (add CCA and TPM to filelist) - fix libica detection on s390/s390x to get ICA module built- Updated to openCryptoki v3.1: See ChangeLog for complete details (FATE#315426) - opencryptoki-3.1 - New ep11 token to support IBM Crypto Express adpaters (starting with Crypto Express 4S adapters) configured with Enterprise PKCS#11(EP11) firmware. (FATE#315330) - opencryptoki-3.0 - New opencryptoki.conf file to replace pk_config_data and pkcs11_starup. The opencryptoki.conf contains slot entry information for tokens. - Removed pkcs_slot and pkcs11_startup shell scripts. - ICA token supports CKM_DES_OFB64, CKM_DES_CFB8, CKM_DES_CFB6 mechanisms using 3DES keys. (FATE#315323) - ICA token supports CKM_DES3_MAC and CKM_DES3_MAC_GENERAL mechanisms. (FATE#315323) - ICA token supports CKM_AES_OFB, CKM_AES_CFB8, CKM_AES_CFB64, CKM_AES_CFB128, CKM_AES_MAC, and CKM_AES_MAC_GENERAL mechanisms. (FATE#315323) - opencryptoki-2.4.1 (21 Feb 2012) - SHA256 support added for CCA token (FATE#315289) - Using insserv macros in %post, %preun and %postun sections - Cleaned up spec file - removed patches: - ocki-2.2.6-PIN-backspace.patch - added patches: - ocki-3.1-fix-implicit-decl.patch - ocki-3.1-remove-make-install-chgrp-chmod.patch - ocki-3.1-fix-init_d-path.patch- add aarch64 to 64bit archs- enable ppc64le- remove -o from groupadd - fixed sed script to not a grouplist with leading ,- don't package man pages twice- add libtool as buildrequire to avoid implicit dependency- enable TPM support (bnc#641919)cloud137 15241591493.8.2-lp150.3.13.8.2-lp150.3.1opencryptokiapiclient.hpkcs11.hpkcs11types.hopencryptokistdll/usr/include//usr/include/opencryptoki//usr/lib64//usr/lib64/opencryptoki/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.0/standard/7b32158887a67a916bf684ea9a7b775c-openCryptokicpioxz5x86_64-suse-linuxdirectoryC source, ASCII text8sW`s܂ lULutf-87570f51fbbc6e2f8233c1c3dd0dd6d90d0e9618896817df31feb2455ade755fc?P7zXZ !t/.S] crt:bLL ~ƪ䱄{V3pJwqCse=Ӕ|]1.iyd}s%rI"/123JB("%J{pzG\Ho4 4w&}MObJx`>塤PEL}?W;2fWOq1-cɌ]舦 B^w ]& !1wp:-Ŗ(GX67gTQT&)0>~KC9 q"N)=3CS#GvPd( M z\`w!yn[a2 HL7~e wIbaWFlsT':D;.p&/vG^܅.Fۋ]oGw zI,g#cN-vo]*89zm _zt,oVtRGMՇѴk vzNS4']/ ' 2s&̝؟3uh=5MPy1VL5׉\NW|tCHY۽111PF E"ĭtMn>rX-d4W0L`Y9aӸBKm+^N3ڰhu3ڳU/9R-IA tB=>{Ҟ:,Oc"XJY"˪wRt 7x蒇`ۊCD* ȶF"dզپϨ f<lYkh- ?jr2:bM'4 ,K2Q @:3byByyx46GGyy9LWXG9jsqTN;<h[6cX(knVO$*s ZePkO(,Q 0$b)Lz(^>Kea^Ro+=>/ 7:_7evF1h?Ʃ,c \hvO646~=-,Bwzq?|9ըU;FeZKaDQo1h EKFsZ(PţcͷYL['Eddf׍-)X+V MРLJN 4 v&-DHQ] yؤInT>z^>;CJCmnjV_-% t@j2U#z3標M6r?Є^͒bxg}|rP)t6Lq1 *:<& 79O:o9,{҉"sgE@ k uȯRDH<\~Y0?`{:8Sg.=kj-D{#}ߢ#rpӷ~fǚFA/3Gr6%X#f 'mDj":;0Vo? %t"|g9ԢX>_"ޮ5G_k{Tx!{l >\{]FF\LeTl_˧x/Vx{"Y6Nʆ|$Ñ$`OWnh*,BWY3`HկL/@"W]/kBsO3`'>W\)gp4KN2a/C*^VPg :d$ִJMƢ@b3c!xBp}J>yJ_>4Vثv\GM5QHôMBDa&=y8@wexz2 3!5[6&a{ಷWp,I'r ^FƤ:o] Gyop ZJWuG;@#5(UepuTm:j_$ `n6/}[W{[('ƑQ:2N[#ˠ9|h< TF["O}g*_ϡ!Pֱv3LYG(u*=~!GژBz;x\i~Ȑ PgL2RDě!o`m\|F]>nc;n(~m4mO0|E Ewޯ Z-e'S}vQNF]J-A7j'QLTxjyfΖn'H{$_K(րñ)U,Hx1FypB[q "[$.Ǧ6@aMK`?)tP3obqҦg-ϑ×("yNEUJQ䭈UPݤHz(~sWY9M*uЉ7B(dur%[E~X+xجh?C5hǣv|?[ ./MVrtѠu4BǬ,ZqVT0^kTK .T'}dh 3r#ݰYn|:.,zփn%*kA矉b/w4 g[\s pnj7IVsNEȞcedKZ)0C.O.hFIb65BDKaw fiq4ܬS_3cMjշPb1"Ϻm[eaCU# K s`]l]}iYOc6 Ub$|l{ir3C8djis7t3&gښiśR1Ljn[Җ\paB( v"?zңNƎscx =! ƌ鬨m20Suy-ah[!s ͋loZnړΰPҠD{-;m̺DW@^=XC߁Zd J}6 Z=a#Ʒ:Yjճ79C\U[n H2ʗ9%ȽmS O}}-Jj*_Z> 7,k(GuB3²bO^_@{LfyZ3yNow~q훼o!kjcF U1ͪoGiJG$6̋r?E+K_}e,ﮑլ/6 HĮ! mғ56LXSmNlH S|ң">HEmxed!Z@‰V%@"m~#'8B]8_1+qtQ_%EI?ߪDQq%iKFDL5EGA"'3YV6*v01Vp4<% ؾogs,;q{\,4{Uϕ45c |;J6oʹ}QI"^ȵu#b}oQ(*c1LV^hbPk/o_BĿ'M§{#s:!r;#X7@bm_vJ !6eqG<ܼ\+ 1a d(;}Fq&[5 EXl ?sy|ʌ[?Rߴo 0 j/ie_|ˠ,5+D-'};Գ)c6Q2Y adJRmKa8&"L4~xo# dE6Ny Eh^7Ȝd%ude}vr2U0\ݸZUU80^IK4q3Yc%^4Y?o[=LB: 3%@,0$(迨Kq[K!]a㵊I%3c-ₗw^$-|n;R82z@9MWñ}+pޓd~yUa\# 2ǖ>0K2?@ " k}Wx9zcA"m쳕X Q12FRzFص#ٻU^$`W+Hun]tօhb_f7ȩ>{mHFk1GLp7ûW4L(䇠Ew5Ҩ˗V\ȫnʺ1dweU77S5:)PBhF8l]RԀGP[lj4Z=Ens !oi=X>+B/ "Ov1^u@2wz[B[HEVCHq"^)_. 1Ϧ⏇;Wi7ogWz!Aѷj/r$*ӭQ#n x:@_޶<6wH"sEA8XLHg0vs#/pyaq$4ԊLld>_?Cx]F YGU ͡E RsR^"Ͼ7~/Q;wR||4̐qzgoyFt1s {lj,=noymz+QDK|+D,LsmdA=_kKN_ =GGF]XĦw]4gƼ_O|X>k6Pl~Z߭vޭDŌ$L vk+_5"!+Q ȿVt%%0 7Q®)(8PyPt>L : k"Wi+2\C>BN;F7v3 jIÓl^l6: 6_܆SbNYVYC'#׬޻J*\-^|8='T3N[gי@Wyl93䥿s٭--rG왔Y!3Lyw*Ft@ޕ_/5tf vS) g hͨ}[rxc}O2Z â2Rm ie%&Ox]ҤCeC>e"z6Gat~?7 haf(yN''Yg@n/MK={;BjA n hV/]}5Gjraٔh~! cR eѬYM!q}v~Z CЦ3BoS D٣qkA:}OQ{Fb$JĤb{XOknr' ]漥&>Q9%OIn<_dyqg\+<-*̭)yk wx]C2ѧEyk t#ofCi'X@qƈiVRL=}eHR.T`+Ilc Υ؞_0X! ~*E?|vEX,/3ކ~ .N _,QϸcCכpz&vnpU" 0A9D^<Q$'G[lؾe$1uM Q?Ye>`e¢enr}4W ^oJj.\ݻo7*@:"$OA!τ䩐#]nڧI&W5'1&?>Bzc:ȘfO$&2n3Z*ؐ`9'k DַEc=BHfim+J&x췉 9nKfQiQڏ5bŧ2EaSmyRjhJE#[S3Bُ"`gQ0]҅6|Pc8LmF'12BML%D$pc;)7Y8iY$T 7 M8:Sbn-&|5< i08TD]Ô3"ic ','@e Y^ дH4ӓjuU#.]0Vˏ離,k1>ځK ޼$^iul'@xFt7E-J8ru U/Ԉh}vҖ}E ogEW`V)٦AKk4!O((Ʒ9=y8`)`x;zVN ;pQr'6Vd*BܛwPg}OiZHTυ8oY"W?) K);X߉ ;UI$]q\MG NtAᒊ,ӥ9kBK&5<樎8h~“b0_Sz9'2#g_V29dns@Cb`Is7v48%D&郮oﹽƿ2bȊi ɑCF[&'ףmWE .Tҝ8p#B(B}}d|ӗ/}Msʄ#Pq]3Jk0]Ɲ];d(<ܑ&KʼIo֖TYh 5Pnq/U)2`?fbzkҝF*k^v}0PNpv/8_ǒ$_3'C𛣰#oZIDYiM!~n?D [pN]:&P#C„5֡mCr}m 4+ ?g1kS)K^-w@Ic!~( 刎6ul9!2Yx%b룧sc{ÇLɪ{\Y-䡀q,@uB{{=En9 Ԋ^{l=M;(zqEl ~\jȱ̭hƻX]qisyI,CrMt$wah!? {>,gN"c9@sG#%" *jwh/ J>3LxP-\L9c/%xh<%_7&'#%.q @k B*J'EHNGTTJw}!e˝[dizyHI͇\_\k}|ȐGp.60ʼn4ueQ %rŐ؅0C[;նx'7EQ#[Ue }{9:OԿ(EF Mlh)NGiva3cY~0D+!l Ky^Vŵa؝؏ls7) /q+L4[K0aO*TY{W20Vs6Jnր2ƌrxyC,5_1tJuϡytG6>V-2uÀg,_,tb4r5f{ Ɂ hd$m> 5nyQ|8 毑j1zihqix( ؛aF!} KgiZ{[j8l9N#%!l[lI<.5Wև0D,~0Ñ kKKېcr.C4Yn/Bok3ֽi֫1&РPՁM%WitvkOԏ|Չe~ *&/<<[D2gM5FUmq rvK0fOXSM.zdK߱fJ>|ɩ7qetq:$NjҿA",~JZp8a 6CI@s.aϲ.r2#lI߄l MnEzy,s.~xM^EaVH ؈H4 P.މc"j6aA  qg(|yV6r,[UzW/}ሶ3vʢ=`]o՟QSL5V0#$ 3 Ym,0@\F\7!&q p+4pL,&κ69QR$ Ƨ:bmT)BM?|!tAc,+H'ڶU"T.%juKԡe 0WoQ^s7<7!OC[;<ٯAl C`REx`>ypí@/]~RX`5#GDbWJH?hT\y)t}%v)Ѿow%0[xYV>?EB-p v`b̔I0[_;ӎ'tv }d>ռn"e 6'J~.Q `"Ze'$cK *s"4 ՘'}9!N.=&P(waN66yƦ" _^ub3k?R:={Y k}`5gU1Oӄ뇵q'ۯp f~A:i@ A#jb{h$GwbcDba-*}hCn$,fB_ޕtbFԚ Δv3<~J"23}4=1b8̗{^3(v= *CC tG ~+ܔΩrU0.N1$1ea0[ʻ4Z}{jJ u?:}i4(𧻓=}B*wk54L2Npoߗ7x+۸-kHb?ezs:z5 ~c~_jv*M&{9!D  #_3Ŷ4?!SC7n{\hݦQF(lbGX9T~L=V>Ԓ64G3Zx}x~T6'KuIYen .D 0j3AXIU(ss5`G+%Q;@>A ,|@g]bVke nl-Qx'ؠwTqTy0FX.=#+6}6D,]3H@)hXng.MJM@%Q7-+( q(*ez3';?H\du0щ1M8(Z?[g N-S+fl>:R0*4uVr<ktuߜso0]uZy nKhשbF68c}Bv jVX6=sd9V ,At$WA8k& |,L긕 :}PҪ۩(nmf\z7zMˢ8Eoy2y!AWXwM M=H|V_%LyRz"hٹdhKp6cǎ">Rh`#ջUZ7V;jz<2d'^$tu,|>}(,:b?vL3LG ͘-ARhMꫫ?_9UN,G0@qX7 p͉aGkŕ d źg ' "50=.7ٌv[>.#kѨ5ܼ2վD!jP]*XCt6(VQy+sXEݗMڲKDWB٤0`e:MuԔQ2X0CUy{n͛+u&]ڒGom-T!4e%zbyq| ]nar YZ