openCryptoki-devel-3.6.2-3.1>t  DH`pY1$︋/=„=Xp߸{CLM(W{N ǝ"kXS{4e,ф~1$N(B#$z 1t17EF~1Dz-ڝ/N8`N|W9]~Kx8e-8\1M3t FYPGیyo,8N(79I־a (E$ƴuFJ޳,H'"Qݹ}_vJƛ87":ll(28c262888de433664a2788c94eb5d6baf4016afadDY1$︋/=„юTSbߺcY M0+LQ۾NjbS߳y/˥.M)v dz/[3j4 %Amb$`=g h65Qc<% {qt4ɠ>c:l/$ |M}2Rwwp׻Dx3@'^wL25Gs U}ZR;>qIJ:Cz7#TgV~gjlN~VnqڋXcrQؐK0>9>l?>\d  lhlx| 0 < H `   @X1(K8T'9':q'F;G;H;I<X<Y<$\<8]w>x>4z>LCopenCryptoki-devel3.6.23.1An Implementation of PKCS#11 (Cryptoki) v2.01 for IBM Cryptographic HardwareThe PKCS#11 version 2.01 API implemented for the IBM cryptographic cards. This package includes support for the IBM 4758 cryptographic co-processor (with the PKCS#11 firmware loaded) and the IBM eServer Cryptographic Accelerator (FC 4960 on pSeries).Y1$cloud113KopenSUSE Leap 42.3openSUSEIPL-1.0http://bugs.opensuse.orgDevelopment/Languages/C and C++https://sourceforge.net/projects/opencryptoki/linuxx86_64Us<(4A큤AAY1$Y1$Y1$Y1$Y1$Y1$5155d50ee2e43e8cda3a95d496959b01799b2aae1f484226febc5c71e76e1e84f79ee22bc307f8ff29ea1a48a04a4601rootrootrootrootrootrootrootrootrootrootrootrootopenCryptoki-3.6.2-3.1.src.rpmopenCryptoki-developenCryptoki-devel(x86-64)   glibc-devellibopenssl-developenldap2-develrpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)trousers-develrpmlib(PayloadIsLzma)3.0.4-14.0-14.4.6-14.11.2X@X@X@X~@X2@W@WE@W@WW^@WEW@V<@VqU@U@U#U#U#Tp@T T TT@TT@TT@S@S @S[S[S[SSR@R@R@P+N&@N&@L@mpost@suse.commpost@suse.commpost@suse.commpost@suse.comjjolly@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.commpost@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comcrrodriguez@opensuse.orgcrrodriguez@opensuse.orgcrrodriguez@opensuse.orgp.drouand@gmail.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comsfalken@opensuse.orgjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comjjolly@suse.comro@suse.dejjolly@suse.comro@suse.dedvaleev@suse.commeissner@suse.comcoolo@suse.comcoolo@suse.commeissner@suse.de- Added libica-tools to the BuildRequires due to repackaging of libica.- Modified the spec file - Changed libca3-devel BuildRequires to just libica-devel - Check for systemd in the 32bit postun scriptlet.- Upgraded to version 3.6.2 (fate#321451) - Support OpenSSL-1.1. - Add Travis CI support. - Update autotools scripts and documentation. - Fix SegFault when a invalid session handle is passed in SC_EncryptUpdate and SC_DecryptUpdate. - Updated spec file to use libica3-devel instead of libica2-devel.- Upgraded to version 3.6.1 (fate#321451) - opencryptoki 3.6.1 - Fix SOFT token implementation of digest functions. - Replace deprecated OpenSSL interfaces. - opencryptoki 3.6 - Replace deprecated libica interfaces. - Performance improvement for ICA. - Improvement in documentation on system resources. - Improvement in testcases. - Added support for rc=8, reasoncode=2028 in icsf token. - Fix for session handle not set in session issue. - Multiple fixes for lock and log directories. - Downgraded a syslog error to warning. - Multiple fixes based on coverity scan results. - Added pkcs11 mapping for icsf reason code 72 for return code 8. - opencryptoki 3.5.1 - Fix Illegal Intruction on pkcscca tool. - Removed the following obsolete patches: - ocki-3.5-sanity-checking.patch - ocki-3.5-icsf-reasoncode72-support.patch - ocki-3.5-downgrade-syslogerror.patch - ocki-3.5-icsf-sessionhandle-missing-fix.patch - ocki-3.5-icsf-reasoncode-2028-added.patch - ocki-3.5-added-NULLreturn-check.patch - ocki-3.5-create-missing-tpm-token-lock-directory.patch - ocki-3.5-fix-pkcscca-calls.patch- Removed reference to pkcs1_startup from pkcsslotd (bsc#1007081)- Added ocki-3.5-fix-pkcscca-calls.patch (bsc#996867).- Added %doc FAQ to the spec file (bsc#991168).- Added ocki-3.5-create-missing-tpm-token-lock-directory.patch (bsc#989602).- Added the following patches (bsc#986854) - ocki-3.5-icsf-reasoncode72-support.patch - ocki-3.5-icsf-coverity-memoryleakfix.patch - ocki-3.5-downgrade-syslogerror.patch - ocki-3.5-icsf-sessionhandle-missing-fix.patch - ocki-3.5-icsf-reasoncode-2028-added.patch - ocki-3.5-added-NULLreturn-check.patch- Added ocki-3.5-sanity-checking.patch (bsc#983496). - Added %dir entry for %{_localstatedir}/log/opencryptoki/ (bsc#983990)- Upgraded to openCryptoki 3.5 (bsc#978005). - Full Coverity scan fixes. - Fixes for compiler warnings. - Added support for C_GetObjectSize in icsf token. - Various bug fixes and memory leak fixes. - Removed global read permissions from token files - Added missing PKCS#11v2.2 constants. - Fix for symbol resolution issue seen in Fedora 22 and 23 for ep11 and cca tokens. - Improvements in socket read operation when a token comes up. - Replaced 32 bit CCA API declarations with latest header from version 5.0 libsculcca rpm.- Upgraded to openCryptoki v3.4.1 (Fate#319576, 319585, 319592, 319938). - Changed BuildRequires for libica_2_3_0-devel to libica2-devel. - Changed BuildRequires for openssl-devel to specify >= 1.0 Contrary to what the README says, version 0.9.7 isn't sufficient. - Removed the redundant DESTDIR= parameter from the %make_install - Removed the following obsolete patches opencryptoki-run-lock.patch (/var/lock and run/lock are actually the same place) Also reverted the changed to openCryptoki-tmp.conf to match. ocki-3.1_10_0001-ica-sha-update-empty-msg.patch ocki-3.1-fix-implicit-decl.patch ocki-3.1-fix-init_d-path.patch ocki-3.1-fix-libica-link.patch ocki-3.2_01_fix-return-type-error.patch ocki-3.2_02_ep11-token-incorrectly-copied-the-public-key-object-.patch ocki-3.2_03_ICSF-Token-C_SignUpdate-was-sometimes-segfaulting-an.patch ocki-3.2_04_CKA_EC_POINT-is-not-required-in-the-ECDSA-private-ke.patch ocki-3.2_05_icsf_ldap_handles.patch ocki-3.2_06_icsf_sign_verify.patch - renamed: ocki-3.1-remove-make-install-chgrp-chmod.patch to ocki-3.1-remove-make-install-chgrp.patch- Get a new ldap handle for each session opened in the icsf token, once the user has authenticated. (bsc#953347,LTC#130078) - ocki-3.2_05_icsf_ldap_handles.patch - ocki-3.2_06_icsf_sign_verify.patch- Added /var/lib/opencryptoki/lite/TOK_OBJ token directory (bsc#943070) - Added ocki-3.2_02_ep11-token-incorrectly-copied-the-public-key-object-.patch - Fixed two public key object inclusion in EP11 token (bsc#946808) - Added ocki-3.2_03_ICSF-Token-C_SignUpdate-was-sometimes-segfaulting-an.patch - Fixed GPF when calling C_SignUpdate using ICFS toekn (bsc#946172) - Added ocki-3.2_04_CKA_EC_POINT-is-not-required-in-the-ECDSA-private-ke.patch - Fixed failure to import ECDSA because of lack of attribute (bsc#948114)- Fixed BuildRequires: libica2-devel - Added ocki-3.2_01_fix-return-type-error.patch - Changing doc/README.ep11_stdll to unix-style EOL - Added BuildRequires: dos2unix - Removed globbing in %files and specified libraries to include (bsc#942162)- Updated to openCryptoki v3.2 (FATE#318240) - Removed unnecessary patches: - ocki-3.1_01_ep11_makefile.patch - ocki-3.1_02_ep11_m_init.patch - ocki-3.1_03_ock_obj_mgr.patch - ocki-3.1_04_ep11_opaque2blob_error_handl.patch - ocki-3.1_05_ep11_readme_update.patch - ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch - ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch - ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch - ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch - ocki-3.1_06_0005-Small-reworks.patch - ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch - ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch - ocki-3.1_07_0001-Man-page-corrections.patch - ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch - ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch - ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch- Also create parent directory /run/lock/opencryptoki in tmpfiles snippet if it does not exists.- spec: do not use -D__USE_BSD, a glibc-internal macro which no longer has any meaning.- spec: use %{_unitdir} %{_tmpfilesdir) - spec: call tmpfiles_create macro, if defined in %post - opencryptoki-run-lock.patch, openCryptoki-tmp.conf: use /run/lock instead of /var/lock.- Update to version 3.2 +New pkcscca tool. Currently it assists in migrating cca private token objects from opencryptoki version 2 to the clear key encryption method used in opencryptoki version 3. Includes a manpage for pkcscca tool. Changes to README.cca_stdll to assist in using the CCA token and migrating the private token objects. + Support for CKM_RSA_PKCS_OAEP and CKM_RSA_PKCS_PSS algorithms. + Various bugfixes. + New testcases for various crypto algorithms. - Only depend on insserv if builded with sysvinit support - Remove obsolete patches; merged on upstream release + ocki-3.1_01_ep11_makefile.patch + ocki-3.1_02_ep11_m_init.patch + ocki-3.1_03_ock_obj_mgr.patch + ocki-3.1_04_ep11_opaque2blob_error_handl.patch + ocki-3.1_05_ep11_readme_update.patch + ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch + ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch + ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch + ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch + ocki-3.1_06_0005-Small-reworks.patch + ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch + ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch + ocki-3.1_07_0001-Man-page-corrections.patch + ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch + ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch + ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch + ocki-3.1_10_0001-ica-sha-update-empty-msg.patch - Project is now hosted on sourceforge; fix the Url - Remove cvs related stuff; tarball is produced by upstream - Use %configure macro instead of manually defined options - Build with parallel support; use %{?_smp_mflags} macro- Fixed ica token's SHA update function when passing zero message size (bnc#892644) - Added patch ocki-3.1_10_0001-ica-sha-update-empty-msg.patch- Fixed README.ep11_stdll to have Unix-style EOL characters. - Added patch ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch- Added all files from %src/doc as rpm %doc (bnc#894780)- Added pkcscca utility and documentation to convert private token objects from v2 to v3. (bnc#893757) - Added patches: - ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch - ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch- Fixed pkcsslotd and opencryptoki.conf man pages (bnc#889183) - Added patch ocki-3.1_07_0001-Man-page-corrections.patch- Specfile Cleanup, Added directory macros in appropriate places- Several package changes as per bnc#880217 - Added openCryptoki-tmp.conf for lock directory management - Added 'lite' token support - Changed from init.d daemon to systemd service - Updated macros in %pre %post %preun and %postun sections - Added missing icsf and ep11tok directories to %files section ocki-3.1_01_ep11_makefile.patch ocki-3.1_02_ep11_m_init.patch - Patches added: ocki-3.1-fix-libica-link.patch ocki-3.1_03_ock_obj_mgr.patch ocki-3.1_04_ep11_opaque2blob_error_handl.patch ocki-3.1_05_ep11_readme_update.patch ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch ocki-3.1_06_0005-Small-reworks.patch ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch- Moved libpkcs11_icsf 32-bit out of s390-specific files- Made ep11tok.conf and pkcsep11_migrate specific to s390/s390x - Added libpkcs11_ep11.so and libpkcs11_icsf.so to 32-bit s390/s390x- EP11 token available in the opencryptoki V3.1 package (bnc#879303) - Specfile changed to include ep11tok.conf - Specfile changed to include pkcsep11_migrate and pkcsicsf tools - Specfile changed to BuildRequires openldap2-devel - ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch - print_mechanism() ignored bad returncodes from the called function token_specific_get_mechanism_list() - ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch - Fix failure when confname is not given, use default ep11tok.conf instead - ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch - Removed check for ep11 lib at configure - ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch - Move stdint.h before zcrypt.h to resolve dependencies - ocki-3.1_06_0005-Small-reworks.patch - testcase fixes and file permission changes - ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch - Fix for s390 31-bit build error - ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch - zcrypt library included in build by default- Patches applied (bnc#865549) - Fixed Makefile to complement common code dependencies - switched to official m_init() function based on library change - checking the global token object count - catch the return code from object_mgr_find_in_map1 - some README updates about usage and restrictions- fix build on x86 (add CCA and TPM to filelist) - fix libica detection on s390/s390x to get ICA module built- Updated to openCryptoki v3.1: See ChangeLog for complete details (FATE#315426) - opencryptoki-3.1 - New ep11 token to support IBM Crypto Express adpaters (starting with Crypto Express 4S adapters) configured with Enterprise PKCS#11(EP11) firmware. (FATE#315330) - opencryptoki-3.0 - New opencryptoki.conf file to replace pk_config_data and pkcs11_starup. The opencryptoki.conf contains slot entry information for tokens. - Removed pkcs_slot and pkcs11_startup shell scripts. - ICA token supports CKM_DES_OFB64, CKM_DES_CFB8, CKM_DES_CFB6 mechanisms using 3DES keys. (FATE#315323) - ICA token supports CKM_DES3_MAC and CKM_DES3_MAC_GENERAL mechanisms. (FATE#315323) - ICA token supports CKM_AES_OFB, CKM_AES_CFB8, CKM_AES_CFB64, CKM_AES_CFB128, CKM_AES_MAC, and CKM_AES_MAC_GENERAL mechanisms. (FATE#315323) - opencryptoki-2.4.1 (21 Feb 2012) - SHA256 support added for CCA token (FATE#315289) - Using insserv macros in %post, %preun and %postun sections - Cleaned up spec file - removed patches: - ocki-2.2.6-PIN-backspace.patch - added patches: - ocki-3.1-fix-implicit-decl.patch - ocki-3.1-remove-make-install-chgrp-chmod.patch - ocki-3.1-fix-init_d-path.patch- add aarch64 to 64bit archs- enable ppc64le- remove -o from groupadd - fixed sed script to not a grouplist with leading ,- don't package man pages twice- add libtool as buildrequire to avoid implicit dependency- enable TPM support (bnc#641919)cloud113 14963929273.6.2-3.13.6.2-3.1opencryptokiapiclient.hpkcs11.hpkcs11types.hopencryptokistdll/usr/include//usr/include/opencryptoki//usr/lib64//usr/lib64/opencryptoki/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Leap:42.3/standard/5d20a56feecd310f3d2a340c65a52e4d-openCryptokicpiolzma5x86_64-suse-linuxdirectoryASCII text!V^?p] crt:bLL',`"c!Ofkyb#$ioVO*V|aq_j/{%ANg'@2nw!N<\B,CK&,{Ȍmc ,]b\6PY%tyAP;9W+ZfAi)|`kJhI$r˒]l5H&PB&J ~J JHab=շ>'`wΞ?+M ֔Q;rrݨ;nmN;/bʼn!ޙ'Q|PH F&' `utyEmwtWh Y lwzHcT(%j?]'`znnwϱAFld2F` ms{-lPD6ۭwq82]&0ƥxvYˣ$0C[;ƓҲnT9i쌄G&_htxQIeC*]0'*PG^ W6*~\˰O \y=NTѰ ݝ) {ELӳ:!*3x8*={Zr0վ穕ЯЮ)̡Rٿ][B9Ӎhq]EU6<01ب7p{G9Alr\NUS:([{ҟ}_('L`w{uP_0,m"%l!h4LJńqёz2Sޣ/xpfP˜ɥ 毐?AیcG:@l𡝐7 e^YsDks*vpCtm92ց9N-;t.zzRjB})s)1h~XAMPsrP]6QK;vm#l@4 L48"8WcɊiHٟW ئyI}#e _d?] A 'b'< / zLJ͛'&,2HظVrE8?Mv5Lu]>!N]A3؝4}ozIK:F=qGP2bGンTD L3!NL$؆Ci%ԣ_eܕ۠.UJzK̬茿gIo&Vś~7򩦉YcdIplX[:*6d? ؓʃ|Ih!}kJae~ jW+f>+-4ҙ^""f] qɿtF|;,n骡7fz)tDhu9Zs`qX j-@K8*!EL¦~KBTݷu \{LYJ?(Q%\ &2ƛ:\оc8}*ڜN:fvƢ0Cܷ<.u& *mgVMV0>CasJ1ҍv]| tpD" \~4C[|yƵ7SbE[,9Y F'9GHw<|= 03mw=)=%iS?WSJ2Z_vIᡘ9wDiIC 砜v6e~Ѯ4L0U6;0bMFQvv6yBHgBU/cu 鬤XO2_hk_.vWK?l V[#wGw# B]@E /# 3ۨq:+:֯LQ q6$ `q|<*Ʒ0NҞm0/7!UT'OfDt2Resf?lrZB^R 5K0q <)^y$ZqIbIyR&@Vy$QRg&q$Y0=ώ46d:uaXK) "iB7OL3 G3,as"w@4gM*o+7b ݅&$VjKG'vkX'Ĵ\G3|J0(Ua,0c!i;u3upJ?I%V[<h~R .`BtіDx7Yz܂Oa6k6Y;'1 Z+(FE,uԚr4L`*K -3yׅU!( U73PU銺QiHO /|I0F C[ɖn Dj7>=USƸ)UNaOc]jYҪN5|oO?o<1+'e1'ԍ]]3tf8VM41ծKPxvjC).7?]SǗ)J," UvNo4AM1YR$3ֈ{9?:jsM2cNnr,KSV J4k68pԞy~ԗ2׆p KM6e% tvÒ&|Na)s.eEu^Ec{`7kӗ`u3^Kp(êW +yT76$hN]v9_QIm3[%\ ^>]Č@>MPr\4//h66V=ٖ!N^=ӆ4 ?g*Dd4 SeYEQHE]¹jN,8sR1nL&4:H  );8q~AY R.YR&๋X|x掠r9Vl3>n.^1I>6G!]˟[" -\M9?0.:ra@RAE,K~(g3S2V,.Q*nOsU֘h]4Ҩ}UQzKu_aR_LwEz"nl4v9:ZfLr ~Zz >__2 * @;DF-0`W1Yj9Q]a^aRuf/{yD:HbN{_N?% y`%?6( m0ʿKtAI~zF^dF/^mi@F5;҅>ޯt H~}t7n:e ˎ %7U`/e3q7K[˾sH?go!l<3 )P/2T#18Ns*?}e5A?ЧY[G oW&xa_Z83'XÒ/]g(; b3JlB}2/c]FcU/y 'SG'3[A nJ4MDxk+X|\rrkth)e3jW}5xs!+yj / +WuO%STY 1&cz$KO-8L},YX,)RG># /\v|+q55?Od:SƆU78rཋɿc*sH?ZRSzrU0!׍&fbI q71B0X8$6N=Ra[kYBm3 Pp@`W'y-V ; (.P`!\DDˣPMA߬xx75n/zG]VFc_{_MEYޟַd}fe$ɆW:96OtuvW'|7lf=Pnnv?uGqѷ='ek;fk\q*#hh"87Ei>q>_kkctx oe+T_aOw K']tC )kJb*E9t?w_ȵkv !Xۗ!PP%P ,꽣UCW9pdzB G&` W?[SmO4KG*՘ lU^ Ey> #v =`#1/[Yz#Nڐy֘5[-|89 ʍg ̱Y< F([y5#bHZ/hK݃!:nn+F-}jqǣewMMu0 Ϧs~zrVGiŧ+P%Ɇ[4hEIK9"`iq`4TpI/Y?2;) P,CK㽴"fn+@RƯt E,2jܸGFph ר@!o jhtU8wX,92=CG!dragmά%?91TIaFSOdKQ\q/ ήih(3a[,KsU)wuwR_1&|=-;"]0)ѾhB? u%2 "E޴:QjQ5Gkf[IR}0ܴpϺc2|$xH/M;܊d}xLܘljJ5ScDt/p~'=粬)wh0 A#+ Q9Q/ %',&ΰEAb(F V0A.K' }T<E8pTb=g+5_ ށx}"-ό G-AE&7hUn@xtc$EN6WWb/a4LAqtDIl4څ;`gr"Pq.418F@MdyCJ.煷ӠB`-?N8:HȢ[YI苍z;6Κs',(9&L1s15cN!6f6AeZ]g3 geh6ik#UHhUfLe^POJ֠5YNHk:wEҌ|-0pr c:}('z)rSԢA5 '3郷V(E@NV}DeeVvDD]C!is|WxP 7n89UC0ez@sNja'g\KJ A Qtp2M{HPwְ&o&v]2e\BTo j`Pq,7P*چV5Qřy'3ȷUp#vF;*4Z HGm+2HaICcK%e6VzQɌD&dS2[GMٶ!J-g߉P70(}VC`=5jsMD Gҽcj8P:, =`#C7rn4Ke%R{9/ شoF eyS'YH[ ]+C,WL5*v!AټWw|vN0RڨDVyRH ;Ṕ} k5Z}RO@zBu H: e~eM0/{޿~N'liҰ{"0$[ᆀ nD/+O vl SuȹqS hhI@Uo\|MS ?+ۊ4i9r+etǴrG*ZN p8)W/YۙA'U-qZ~9Wis|HG.RjF5uQ -eE/QzhItQpFFsnzWٗWߪ:9$Y~NLRZD`ޔ\GxgU,"@]JYQxDc (C R$\g}I7_ڏn5`X N.^k) na`Q}[F|\pa?D֌fI[z$ppL镰56p2;-T#| a7Z v~G#7xGvU3A(ǦJԾ$U֦ x\_ HQ2[]:]]|fWŚGY{$͛ηN*jG~X2v#ӖMGD2مDu1sY!Q rnx fhJ4b7<u;ȄI犴l=p'.+0hZR` f:Վ/ $IFMޅd$ղ,:;g Wۺ["U_uKO"̋.n993J  1$o9 ( utWdR={;#SwQ2jAmrge+J.XkU!P<$8Woғ^\9u1 ,v G-}>piDr_o5J_z Q.T8RATc=Fr +xQO!%fU.6xyH_~gOے@9y7{7C+_ + ٝ =S]yݤ {mR%QsfkI2@ygC\\UԊ/0YEaECͮ6#]N]fq\SAf|R/FrB:!ږ{N^o?o*pGLC4dn#{M:]Ml$ϣ0,7]ʺiir]yW>ُKĢX\n<'E=I]نᗪAzI[BEZ>[( Guٔ4텶e [&π!n? H< Y+XfsƂs-t糑]jKd7ϸZ@qf.~xg,is'=#Oת!t,i_]>F桪6S=V6(4;L[FnX}RU7:Ƚ]ӿ,߼K_Y?cN8eoǐ6; (ɥ>p@(s:+-c1jgS{ lsס tiB5Ay[/'U?*?J>{ h z04.)ǠڪT杝"vH0MDIQ?0"':jz:t8LFYS3lA9Xԝ,lP*Or.N΄-p"0Ƽp5ZX\Ux)-\v{C=kvPQ an+M 7.z~ٌ\;7u`)3y9ĭ*:E}s# }ؿci/n;"!瑛R1(J W|+/!YX$f 8p{XnvvfULý&.ρ=ZtɤP2I ƏQkZQ/KÇd[I!vrP,SSI"Q(TciMrגX uJtLN~@PJ4/L܌XWIS6GTKQSRQ{U%'ϔSgwB|wz*鰢\@ƉUS%ɾPK$ W J)K4c8|n,XȡgUH F(Oo+|2zV"һ[Q*eKnQ[s v&IPtT|i Йi86̧\g\Sb\|{4m? H@_YAE LYˑȴn?ץ݉td嘝ҙygp1̸ldl4?|ͽi5mG9Yy "#{0gV&2a(Ω' y`9r!ڽ5s1Lts ;C9[J bi]57 e*0Bmu`P%˱nᑁG`n>N1$ݸDј^l/G6.zmۯR}wT{$<1[Cr]ف8 Z׋ 1/:(hyda8qA=H lh,p5nǬjJg࿖2 ft酄|=?xD5Tijtzk Rdb;޴BPy%u49#hC^xK7fgpP0&=.TϧG&q)uJtAOb{QU:@Q 9;#9(/~g8xX"2_;Sr ua+&3:[\%񂕱d睞?Rr K֛ NI/ɐvz>ˆU†47ABEWL {XRle:S/3~z >QQ~ E"PQb œo|[}ONmTXTSϼg7{?WFKіըtPtU28 ҂ȗpP 99a=c(cU n֕`):WEeUWsY)X՘0֋p3VCTxg(4zmk, )[7l#L!-9i{4$s1ŧqtb&J];Kw#xFϱxǶ7m{H|p[kR:SIjwz҂2KMP7@FmV~uvj7pƒ3 Rߣ]~!ehw>w9.ip- I2ڇM8r?ѾӰ[~\*Np M%{a2D0lqU_6m ~~SzhĽl) u44%.Jj -2)j8^t6xS;S\C̜>=[|@ |+y"%jcti'42!pjW UU&9hD   ٵO1ޖrд"FޯblYTog?-rN&?o;) Z)Ԡ/ 5vV'"t{l>Σ#UZvtȃ)W}BX jĎ4MCJ7^:y/;LT CeCY&WIzGP7"Z%!u/\o[ ղI}eY4s8Yɛ!>%@W%2 :_v=E$˫“~8s3kgpeiHK?*}%WՄ~OyhSDƪl௴?.K*)֦k̏ CA:P_wQNfDռ^4ʿV3,  }:qr4#ԝnJGj$@"ys扅СFVNϩin#Тv.k|϶{d\oi-歁`Xɻ4?ͯv0gn@1~AC_JY3JhrL<> ˿&1Vyvb.x#?1u l&u&*SB;]EVx'ij\ˍD7 pNQlJ T=Q- ?tM D*SDQp*^s tkʳ؞4[s2!t]36~)gfuլk.kRFϻan{iԚ=2O 2Z.Gfu } ط(Wɚʪ6pK F[[6z.C>I/R˓k ~~aa&'H-Onz)A4=!|%ʻY3 9ъ[l^w f׍Hvؿ5,԰BG$'N0_s5${j2bN.TM Ẅqը2]*(m&`zM Ơn["YnOі؋w}/}'] 5X旞?jpĶAEN4h )X<7uGPm>cUbEPMR֨ c![wsrsR76kq zN(+FDz>Xsr1u{ʦ@ӞHePc8:sj4)ybvo^H<7d;Yz Bɴ;3.+d/,+C)M;Vw!,L~u3LL{h!!>SWCz|1i{G#8:lL~N:~S^w'Y6"٣cߺz&c9uųlstxwĿ̆Ŭpfkϩi:ҸZu\hg!sljur!)EHr/ ]-DyDKV!݀L(j $3)ic .ᴰ_i7e\m* f5##NZ?Yx?ٽpY73UEX+&VdPg0hQBOa%i^i-=aM2I 9v 4Z*<1c7V)VRtsO2rְ@ |4r0rTb.^2$^~B&q>*EKoZcեYLaX*V#K qvrcRڙDWH> 勪4lJmڝeFw|3g,}[K8:8mTm|NVʠ>Ɋ+'Hk!6a-u=xԶ\8/@@S-Yo L tYGPbn_HywtFcnF_VV^K+!pTelMi1=\qGut{B(aʼn~\@ O}"J tMݮ< zܹ?7߸оf/v~NX_TSvZ*-ݽ<'|MT&} / 1;@y ül81Wtyc\:ǂ:=xq:2.&1grJ3rpIYn>iGpsy#5Cµg]ڒNseFLk}c@wG:G}8nh'6}7Qv diT%¤.Mřsim9@4*p܊,z8䐝lTπWu"*裨NjZ?ԻP0V3]Sa61PZ*!ܪG 8yaD_-X׻SSRX;i,34/}|i5f H%}| cWEK