pki-ca-10.5.9-13.el7_6> H HtxHF\ ?*}}e]3bUXe`Z8ZRvq.V-4989c9adf466dee16f8fb5550ec5f388216359151\\{xF\ ?*}}[zQ~];Tʌt8?d   D         , J P Xdd d xd d nd q,dvd}ddX`  8 (h8p9D:GJldHOdIUdXVYV\Wd]\d^vbzJdzezfzlzt{dudv$ whdxdCpki-ca10.5.913.el7_6Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.\ sl7-kojislave01.fnal.gov$Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m)?1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~->E,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤\ e[!T\ P\ >\ >\\ >\ >[!T[!T[!T[!T[!T[!T[!T[!T\\\[!T[!T[!T[!T[!T[!T[!T[!T\\\\[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\ >[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\ >\ >\[!T\\\[!T[!T\\[!T\\[!T\\[!T\[!T\\\\[!T\\\[!T\\\\\\\[!T[!T\[!T\[!T\\[!T\\\\\\\[!T\\[!T[!T\\\\\\[!T[!T\[!T\\\[!T\[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\\\\ >[!T\ >\ >\ >[!T[!T\ >[!T[!T[!T\ >\ >\ >\ >\ >\ >\ >\ >\ >[!T\\ @[!T\ >[!T[!T[!T[!T[!T[!T[!T\ @[!T[!T\ >[!T[!T[!T[!T[!T[!T[!T\ >[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\ >[!T[!T[!T[!T[!T[!T[!T\ >[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T\ >[!T[!T[!T[!T\ >[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!T[!Td6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e6d0c624b08c77a769f0627a1301fd0a49aba07bc8d3dded3e56dd665cd4dc4061c0db21c1fc4acad6d16f5e0260cba0977a50fc158e19852e36dea21e4cdfd8e0c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.9-13.el7_6.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.9-13.el7_63.0.4-14.6.0-14.0-15.2-14.11.3\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.9-13.el7_6    pki-ca-10.5.9LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.9//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL'{T!}ll 0ю eqVZ8U$I3;&{K O`T:0,412-1;\*[AYH7zQv"-:Il 09=?Ro 7@:lʞS EkJǍ򷟛ڍKjF4f@Î=7HW[m3fH=pz aс̭*ndI S &vJV)tM)ڂR,>I;9x׆wW7mtq"O&S .:>D]3G ?ΑH鸾O#?jR >OF'qZDc>Udqd+g;BĚ:xQ G_{Y Ef%*@:b8S1%/b^Xi-CJ/0xpu2T@ N{9h r{RBPBis0"4>ݻ$^izzWF!\b0A1dKHWV|ʌv; F:\Z04/!l BjOkb7Q>3AQ=,bqY U[W>fʤ:gu{᳄CV@bBB>/t!Fn_ZrB C݉p5"75#~x?9cC|hy{3f`a!>4P:nL%xOUUI M<0%±>%SDZoaJ6N@{ ;p]@] c8b8 ?bQRZOtc f=(?_5:xpi/ 6tqUʡQc S!!YȨIl)VWAV]/p(.sqwե)Ëb)7a&-yӠ< 󉧠({Ȇj  Srnqp5=ar.d|aotEpʴ 47*CnyE^ 1տN wgch[_`AdVge:,\gu ^d8d?Fk.SZ^{Un%|Č:s5l (ije%DU@43ůc̝P W=y\㉁0eV,19?obՊ@3/_?Dj;MDC%:+,֌VEf5MWN 6?KN B7?%p`2r[6X GD6D[I mwk<JӨ sme%;?"C쐊Es"q,tPJRTnprGh63nhĽؠ`A3zU{⚢#"LTRu1::zی]ŔL|m"ǥP ۯ|/D>4$uX3N7I.! -`OSJ㷊?,=^ *|šGLP[i5=+Dz0 [$7:8{&vb~!kÎƍ)nqɶ;ȱOS/ sx $[nB4;mʛ3BDo_TC~)o['O nT,ǎ$1#Ro)(#/p'M{{+gMP@i$ov\Ahcs!'l;c,/ڡ_~?4C2OmNH]K!(,\*cU)/DьN<+ܜoH@G < [\PgՏn%Jݞqr9:^,;qNmV6 "ݳT}v65бk_ig1rԃU qxM!L/N  6aR?Ft뚡Hh:V=.,BL&SkՌM֝P(Qw_0:z 8ȋy N,DH`s&֘0 (mJʞ?־ŇZ=.N.C Gxd; {YY 'B9zP lpk`86?>'&\vz/ڠko9Qr&4.sN I"NE6zPE _EephkG"f])[yolCJqB_, ,pRCēufc asq:Y;uu|ҤV3"%t q9Y N_EߦʲEgTZnC%-nhn|@$>T&S*.1b~}[{ڥh&-$tQ-ϻR1hW4 cs -S7JEH\ӈ=yxIof)|.@|f_W-qU]+_ ǔ>6pD[ "ILV;Rw mQ&NSSZb/2Fo.\5BMc+RJ#Fxt*7W 4ɾ:g}Ba*:T}d8)@Fy0W[V>,c'̫pKQeo`˒"`O7\uyճ D,V -\+A$q{AJf7Y0ӳyvKnEtp}Iv_.#탁ARV+e>q(DÝͬb ulIA=U."[\ܶ}f|NdyM6Z D2jV8QZC֠TQ3 E>$XLNV~s*98徉;|ʝI ;`424e7ō7f龍 UG $ݢ;eWsVTW//Hĭ_tY|9 a )uPR%͐U?k+JDln=vOs:lT+LǡwH̢("/*4ڀ2zzW"Z2xU̴$ÿu/IYwcl'Օ68^-ګohd$q^oT,,hmHP1v |(N`c2+>wuUӬ%^JMtd C9<6'uz+F{'0{cͬ³E{cvLx4 VmzrY{:ΫoQ_KH 8Y/"*1@epk!5@ڤ;q>Rc˗23 |D//Rc*E0MP{$wFn|cL͊Wj8$nO9y%O& ,cn߈%V#/=.g w$.lYz<ƒ REɹE`o#r_=}.(Fp=^c̲g! 5%d r2z4Q@]GdX'5uZbL^شA,[ uǘaxnw$ص={Uir #Npcpr Ơ)]ueΪKGt`X?>ckUcaVB'}РIu5⹸c09Aw.tq%WO;Ky5X]l'Pd'zFKJeT5큹Xgc\Al{E ?&ed>p6JxX+f>># Yᕁ~\s|a"dtGc ݥG(φ!>w6[lH% 鍟5VmZ* 2(YveS2^ uzbҒbA'kTvAAhsM+B(~^ߩumIѽqdexifZ=Y$nx{ΘO|mW"f-1&(S6aR+{ U|zcwHUxbygu;E5yXؿ fϸf'1x9 `8A솄5ELiM N]4a1/KBc.@_Nͻ6'B9k;U!Ui `?j|> 7 MSbߴQ,Ê\41WCBY2elndb a?+l݌vXwSå1ƫ/&d1zTطH?X4bJD;FXrNֵ2NojË1 !X.VYh`MHz'\>F>|kv/`}z|3Q(VQa?Qۓ|h 5z9ȳE)e-_ 0p·}Q~w{GLAakZG"$uH-. "sӬiMNZU\oZ @!πp~thNHe80]"a Sq~!y5"%!79ORUӨ'DŽNzaDX&&kwƦ[{ƕ儩)7w9sHJvl9g4 [U+wD5z_ӊ/tG/G ӌ3wdx슛.HWڄ'=v(s'8 I|6.!"K%w tP _)ׂӿS) 8G \=v{uGwlpI ; OX ln]J ~dgPVY p 6pwXޙLY*ǂQs3m9eb@m!^]lS.^ibG1!CZ4$[1e߮fj~2̥?ui03⋄/P 8PIy=gF5ٱwN- x*ߧ=%[\K4N=EQ[) DY,jhiE #,\,_<W3KFl6Sޯ&svI& ng EˉNf}ޚ%֎,e0."!B x,=Iqi}ͪ&[hSwYZܝ  JJ,rR96#Y@PK-+V^tb^16fÎv(`.-)`iwgJG>ڒaϦ .*qV_YYnQ 6n%"RE6x<@"@hgb!-UKAapPG7>)2OE>PռrNA>}"ՁL)Ȩ 4[崍Uu4@O<~2ORRH(Hpn'ME U`?~[ TWhcF[>V_.d s:cǯ$c9n F{5zTF-|W4 W=;2\9e;zvKE~Y%uό}0 ei AWC(EIeSz3i!tרn8p+`OC#ͻ^*$ݷ.KN* ѺlƂ̹0z a}c)|~yX>nqO g8 VScN JHeQO wHbY*:S ~e;H"쩧1KZ-OzRӭPREf?@g`}ǺO,}ɲupnvŃ 0g^bW:Γ"1ՃLB'j^iP6j:~qʻ!-Š81Jtn/ar׵$A 7 y,LT*9~m\Kt7 $Huzӌ7߮lJő[ݸk2IKWgWc?m'dC(q=7_4_U>UIV%^M~YyVʵi~L B3jiYm=`'h6{O4;N#Ŀ ć#3ܳpf˞ Uڿ~7UkY iB=XRS!0N_`ƛ.g f[l!ݐ.˅{F+>>s_^#BC׿+`i*%C׋aIuv!4c N0x\i5- G+HM6Cm "K}|Nm<<Хֹ*i䏏$τdm*nȾ ׫<ҵN%"TUiߟw;0OG/RǵX~"Wpߏ“^hQܬH([U.jPz!`yRON]$q,H(IO…`p bKlGK\>)JyK.[{hh rܿBIziGNο: 4`(eEfL0wU@ x%L#lk!*L}0DWbmj/ $k*@Byi2.S*rIOg9!`ݷy߃^ ꊡf݊I'"q2 ҳfu6/ܟ&-y:!d\UynB S?z T#4^Ȯ*jxørљ6ua)Bz/{nJ8hx&傡J)6MN0q2C߅44eQ4l[-dmK<At`R `^֭5Kxj Yj\IhxwFhJ}4CNo\] \j~6\g1&d}6ҦRY?Rwz8f~LAҒy^g(Z¥UEJf&xN RQed,22fmRe i^ZR6lz%dWhc`*H"Q͇̎v3iVul7 C2bL`ZMחc :,C3_حlIev⨧8i絝h`3qQ0!#AL '0<2-ɬ^ck}a۶q%=Ź8@Jt7(Gp 0>i! WDϖr^5D<o+)2[B%cy&7h:sL Ayl-~!І]pyY~&1y**m 0 "~0j`5c !MlY-}hq x.Ş龖'oj@~6y&'݋Ŏ*1aH(A%1x"d[͖'"ow_::W׎ʨ#{i^!56H&m_3} mI $@ R3%Fzc$ bcR~A1Rc%L#1/U뾹LkwUQ1޷)ťߨ@0vVM˸(Br+,9]8L!4%)/@cޛʈ]i6^y L}5i6g@4YGzYS/Y1ZծwuyJPt`Q^9L#Dg金\^#M"m/2"~GqǴ6XqGys0;AHKhcZ|ᰔyro VSx]j) W[&G@[t4 6#&7Y\s%@ÇgFH]YWF^{1II];ؾl6Y!h`w)I o~.}N\1зФThَMF[Ym#Cg tQj69t"r V0&N"2k!o˪-nE7خm]܏bYJp U0㉔^".vCzQy#IN&0+6:(ͿBeoQ؀j/gݾd{R2vA@e+W5>S;2>jʆ`CbNw>˛yXлeqĽ sz$VQ!dzo@k2T =IU6< 9j|΁"pUwM|W`%c N[ O`0$VDz =a\NІ#7. [JA}Z_ضFώ˽z^[>M %T3 1ˡ-,% ԮBEz7@yh0XyI1;P&_;!["l8o! O_#'[ gދ0itMw&k5-ey$Ͱ2f01,y" H=QUqݕU<|'s]8Hf` x/Olz:Ym5|x`.:\?Jkdɒ-+{*Dʛ$BVR(}FXC:$VpGCYgMHص_[LБ44gŲ:UpR}0h6R`1P%YTkX!RdA9KL|P+Ur5Zzh?JGي_3?bF-8û6Gҹ-+$O? A,|_d W%L+8E1bIP éXr;rTuVG=ر$b}''Lu~W)1֟xB v%:J;(ԫt/o<)QnOa#j5x>7hE`8=el1Mdin|Y2UiOVP&Ͳe>nr7 '6)D68jBDMb|wdSG%שZխ m)*">u'20+^nA]dM3X"Z`6jM/Į4b8R9l a1ܖr 8zV嶚ÔR_E)"я)V.R<ڳ52%#TTD9ep HFgZfV?kpi*+n9zп8MP\3.Dscs, qH]+6aX^ϑ1L^L93tgBZHj|HmDW)7̄81 A FʫP2zUuE,A90FZ1\e#+SHM޸ΩOcD XYY\[JeS$j$ R&4UV[܏gSNR&zwإ(;ԣ%bTCQ]9Rx!/HhHB\%ɺ OͱZH 4L* BLx\Z#>8y7F<5;2paNI{g[0kPqHe46sIef]`iC} LPT_G`,X%̝z3R2˩u%~A,y0Sl`)`ot@}8~i-$#o dCwL2 XiTwT֍ZQ>3r lt^7zp)LLUfF-nWv A=%k20Y}`1}, oAy~,h\8<~YS+\Q+/{z>QSAGz?lk$ot릴\^<ѧ EZkK4w>oJV_WI'ϙm:m SA@ٶaf[ѻ>!ْҽ >t׈/щP|,nv? 8 UaQ,ځEM&@A%W<mJ)%ڧ7hJ"W7 ^$36FV1uqr,Ƚqwbk#F[|UHQeSW|guuF.Г~f#(;PL:X4F;O6 ȥ5ҾNa2)s֕#ucAS(( .,Sй_ju#9-RN/z q `5-JzSl "*)eP5jGY6}Cq(蜍y(iP#jjݽpi6Bp>bĞ-CL5%UR^%hdk#i9Vp?#F(EʴG{Rxw󄙮h*u8ḟ-"MO[1luc&(Nr{_9 Z:*nРLd|{L*ta<ԨMOǥj%ytڼfI{d0hfD4+N |HzAd`C؁Ġv``VEUGUd3D D&ΟgtlzOƾbVKm8[#=CWkC 3&P ซ?%D Hz#I R? ^bkIH72>Xk|*)|jZlk_fЮD U̔w3Ns]RA'f(@X٠K?rxZ~H&=MiWo7e|MBdďQZ,GƓIHUy7,zbuήJ T-ִ!SeU-g*󷸠lG  ` ˚0Mp.D\R~Xnyla9`9?]xf 4m Y٫~`4[-y_oqκbF pY$-'|29 //s-$sCj+i`>IDxiJA)Xgj+NܪwxQ~M3$ՊF)Iõlwem 7uMH`y A )jQJ(YjxKy JV_۟k%9e;NLv9Չ{ކ.KG>zD3i:;DJu2"<("/Y!QK=?۱̉v)o# kxv#/)kLMG2Ɯdo/ UL{+A…XU`;cF2w:-p1K:/RdǐUO9OډԪˀ&f g "<1]7_ !q̊^QFC/q2u;u:ė\|l $Cl9b4YaӍisnc"|$ g@Th x(4'r:)#܁7JxNyA?9( 0D"2ڐYnZcVNf~\ $Su8'Jg9 4@A`GTExf⭻(ad+l\|@ZԂEp& nP9DhPg)snC{3OQdͯy N[ف&}CSYL^ֿz QD6S^rX@4S@$篖Tuġt&k7X E)u'N^c$. /0$g~8lR1} !u۴@}mx1LؕJi543l_HO2IZfA_[MA%m%o0GF0~~;}LߊNR^(2;d*.xAҏ~2I5k\NKOUOϛ%}_KhXXȌuyl/O/78yh%5_r -~*R񑛶H4qhÇ6<#u#=C)+~aV&W,nd*sc,- DBoYTlph 0RQUA:#Hь NlR1sR[ n}ϦKVN2Qí%yYiV>$6$o3;?]U@ګh@Q(acN+h|RGk`uH^ '܈NCE(- æ"9uUWx\m"a^ᕑi^_vD6EY7_,6$9'^s#n$sd *nY)Ulxwٹ%Zœ̳iC)ز臭%.\轼=1uOz(DE,[_|7 PYLjl-^ChSg`$ڂ#-2Wnsw3hw~&8ݏ&vx$&C/waVVB9Zt1շߗl3*rzsʼkԟI\V w=!3na $U}WSFIۋv0"ƒC|Zg@pnY?^^2զXߘ?f -KK 7u82̘\&[6\V lkoyIua2:.peʔ#%8Dxb~n21`B"W&6*h:~NujУOLM|fv@ f$.[|SMHk_nĀN xeRbf;謁{[1 C'XxmqXԱ2y;$<;<Q`.llwEXj ]0*CWWSXҌUɾ9$v۫нr8~?=~l nyȤ {@QžaSE]kl O\ijBZ;hh=4vㇸLha("ݠVq ơtnIf#ʃV>p@含*mXŴ`.tav NBx.;'%:?V@s2-vKZ@*Qz)]#?u%JL &pn65o+!~7|(!jVFlL3+r-LDC2F,2jqUU"fvs$-ziGFj󠫗r ,zN >LYa2iMRϕ)t[@}ScaA@Q>ѱ$v3+IoԲk7vw^ ܢ:)E$T@7G_r3n &bQS D4 Hu{4+ȹzCWtOlQ_CΚ9vB:/:V#1hBB Km}=tXy 8kYR`\,Z<dox+QrGvq[*p/gM'Iک2nRtV|ҿĞ":ˀz)@[vb7A 4j}))R{,vcJ0TFk9ˈ\#8{}u"R}] >M$wd먾Wc^atwa#stp n[C:ndW}!.kh=3G yCI疇#1ӧ6h-ܛ @L+"ڷ|S ,"n4)ic۫ǎZ$z_I bQDt(9WDJ0aS 9ٿALJ <\._4L[Pے ig8賆f(WThcF)WF5?7{@7%S'}9Nm?%U^iTnbH:ANx 5ݬӸ=єCEh5+'ֺ7]di" KISdy)W+WŌ=5#\GBy|,p*,~{:EYw 椩^܋7={49emҦ+)rp)RPwlxT]f ,8pzTN} zo6k@sh=F݄BP=xߺc %|F:URN|}D "_l>i\ד8C4xᑙfz_ @w.5.ʲ:nJx!̟4ȗ}kX j!;clJjI?LNQӾΨ'm Xjњn)"0k,_s>e`onN3|'-JÛ, {NrZN q'h;N1T\ʐhq4{_( u jwd``;'}l)lUHx?3Zh\g+ZX2DrxR rH$*;?A$Rׂ<·h G,}_r UbV)2AThGt$nw[%]ʌV%@Yg'¶Ng 츛6+x܂ -ף (q7M ko [6o,uc6E-JkQSLc^w .9FƵ@ R _DyׯMtDpMedo tϕYJ/'maͷI7R ] HMa` ̹dfk{J:+)"?ƽtΞ*mviόN.jad>c=nwE"a w@jÇSTg KB0:m0\L(yA6M"?2ܳ21Y/ BB )Oxj;^wXFN)BeU<ǯ$^{&}v:ےF$VCG,s؃?(b#aHMg1%x -UJF 4Wo8(N&4;W.Fg|0eJIϒ$1] 9 PB}#\|܆!ލ5 ]83BjJ~)~r{f4,ܗ~lH p{PQM(dЩx{{B0Cl.nD,Hi R=KsY u,"c[*e#` SmpI֍9hxXM JV˄XCg%V c,oLޤxP右3 [A@4duwl`u=2u*t*6tr6pW.U+.^uloA@w/j,DZ>[L% Ѕx uܢSv~OsCu63_5&XkY[DLE4 c"/%TS$.p5{x8́Ciѭ@cb9QJ24XjkV{%d/|$@x(n 7H3p';0g@b A&A䜤Y#'ܬ1:_ܺW菐)*Xs\A"U杽'6`7@Q_X:!hw&uD<+77զD lM .[IUz:E ֒;uq-tI' |y &Q#f:yI,(icliV,^6$'HM>j:ag{*|eP51%Gn4Ж2Mr:NQa{:?=:қbHv)W59)Uv{PRȨ&ȝ |[K@Ѕ귦!}4Ϊě>p ;rc8AD "ؗi]{V'[,WMa#Ǹ4A.lb ^G1ܢN5緧*ʍ9r2wjYG*ygdNlC2ZGS" 5o v@x:kiT?¦LؼuLVڥm}&OyEd-Ln(ѤPk0Fy.٠wdk hV.:NF\% v>IcxƾFR ,0Oђ@Iɳ2A,DDU@aH{1Ut,9Dľft:6AVi H+^9RN|W2eEk1iFOxaT"l&]~ԜVu{<+1M TMRi%]jxry1P+TEˎpYls&>BrTU/_]R(H2ԇSvSS s~bѝHdyylUc8tT|MCs_za!^cQN" Eu*7AFh-E2EŦS;kn C2R͈I8e'\ǖn<^BQǓ4 A˺I?tcÔbC-MgCW {?6hx#MR]Jl-áGM`u^n/mB=lč=Mrf/bXk-7)W)|ġJ蠂?c}:(cZ%Rѹ}f+*FV/?BPДM{yȑ$8 aY LУUn!.{\Rq.kXQQO:'cvG;hL^@\Dk Ӎ!U%@Ɓm^Z[ao^-7= ox բ%+zBT1:'`d@m3E bpZChXԀn$/Tp=|Qe2]seBv0At.GEBVDA"{@+ΤnQ9vaP*p*Y@x%/ FL"C :x{ VUc4Ñ#~E3KeT(B9_syۭA}.M'PT!)Xoڠ0v:w^! aY8ՋR#-?uAJWٖ0t-^ qFu-^.O@XQ 2827F OBXTEMJy]ǀ_`63ӧU{QGue|6*./N$Q.펨D|mn=W\Co{sr<n(8Be!, .$BjzW6;(]"+TEPm-NrHʳJ.gojdfE8=6/ڦﯾ_='8oqjUQ& % V;f:Q鿚CPsb~Uil= ^Z7>347Eh2&3IJ= 8:x'ܱ:С4`x>ɸRMtո n?8gW"Re7qva K }}\Kȓr#C \ a)v20[LgDw p7Ƒ80.7 S|0h g{';-%)14>,+uUƩ1У-5'x[F1c̰\(;S@ݼ (+7o!bP㨞+Mf,s\qhW%`{Jt]8=K\pˇmFy9ȰeR1]Jw回@hMa[惁˯xU[ò:Lr4wcFR梦Fe{I FqMKiaԖBE'a\ Sꤙ͑CC֞zwb#W;q 9w#1H\&ZU*e]  +~H_zSh=cE,}J d}O۳_N'újNAVJ4*dZ@n)=1Ȱp&9JIsJ:E ^Ռ?^lâ_`x⺞=ـz ~^ݽ. e &[E:Ly&Kp˝}Yu2Kʞ  GiU@88aB \0İ3E 9"F=଩']4ti» sS-B*iBwQU3<o ʣ sh2M42a_@L&őC(ѷu+1 4q/SoِZZr Z: -<#(B3˷6]xRZR"&T@^ޡg/̟`7*)r /կ}_).1eDp&`H6"e~8 HoKzn.)AV4$@N_@ ү+6LU>9we*K ɧd|2俨;nWJWe8&IF;QvjTQ ##l5 fW8/6ADZAδa uN-Ϗ{ / JfxL@LQ iXzC`2b.3M4Ik^sMcs6`pF2w⹄6"+ȳ -sм3dY>8 üLѦ5iF dB1(zx˶EB1I!GBPi j<㧋 !gX%B+ἒҙC޾i۫;&ONg6> ٨!`wI#[C8"… g߳{־\ƔeEdl/ lGm"dxeMe[[dTgXC혀`ͷ Om }8럊MvQ [ 5L'j= W5wm|B]AӲkkvZ0&zW91~dzO3"y_53ggCU96)WY#D:XPxTep 67zYDC7{H]ː$ Pd5;t*6I!}@G{M:MbzE MeA/\B<ז, >9 `n;Zs`iҜ\͒j:(|(:'4UN:AbEu'rs0UܲA_YQw f."@C05 73ߖ?mdI$2Gv)eRmz(mo332~ ۰pċk,Ky{ jࡆZRst)I)n%"҆8xΤFwVR5-Ijm&~ЭYfhbFTat,(L/]:G . W{̘OKOnF""y-GPjU}#NJuTE2H9Cռf wYI5򢨖| z812דӣq0PsMwZ@;'0DeS1IcfqߝЕNϛ<`^ ie@jß[y lg+ he珁Rt9z~w&NTڅ͠Pts/\^rb.F1yǮuxjo-ϟLnyz4 (^!%``EHJ®{u.DaYƎXCi-{}H֢%uqPˆKu/j-siO@'Jf;7U-b63|T)a~ݭg;KaEzZ&}>VN լmԨ:[O%ZFu6z?PC^Ǹ{[C͹3V.ipTfĊLKiqo/q9셗!_^gxt:`VXl49"nh < _Ψ)ţGE<;#]sY\}WԝDEWpQL!_b7C-݃|SAΉY(7̮ZLW|dZ9}=O>bK!d/]VqfPI?qPf97cCP,{ : H)G%YHYAoް8$8L%韜?_8wzf; [Q ҽ0vM]7ස@' 4Y6r?亳ElmN:!yq!ATa&&Jk::JYWG1S&4\t.U6Q2V'Q_hؐoz/P0L-c<ay>C/&0bf95-(+Xܚ?aAptD%ᅯ)Gf(E;E Z#(s/+3Lt%s&tP:O;=PO/K"͍ _je=ԋq2CTJtC*5nKg&]\&ʔܢ!6a((Mk\pZǷq,56$~=^X )%^ .D,^(ˣnWdU65y)>wNbMLjDeS\2As WaܼE_d(}PҢH' &1lCwLpMn>Y,7,dj-v z旨Y5Go@C5`TpK?GDC  Cȭo4K-Fd` hIwc/04WƱȉQ&W 9 }ڇr;n%Wަ {0$SJ.+t5ڏd;+kVe훆G%kF=D^xOˏyȉǮzTÎOHd.Zv&;sP7?c&1ɩanU&e~?RV]`>lʪ|*h)mô5N OOvw{ZN0[:sa)BH&29[NG3ӥAt<ٟ1Z詝>y|1i]>*0vjZ[/V8{JQD#luJvz;r-#ȤzB*)?A5V}l PQu v{଼@{LT 5(mw2JRk<*pzThhN zUOPwfk,\14o*@=u_LރA]F-= =RΓF~(ITs c)̮sT0 -{wdM5pCPSS< LٹoĶ+ʳ ԟqF"V, !ol=vV~ S?P+L \cK\?oCTVv\m6D2sK[\|: |C"KѓǒruP MԖ@cJ1qxkMk`d +ɝ*Q3C%A#{CfX O}Y{oW{1hiߊl.Ѻ@wx_,u:ck-Go Έ?69&T銆Oš0K?&v[hlFk*ʼs u_ n;tʏxOE;T\.nϘ;5HTh}p(ޟge"uϖ؈A!ݽ5ےĔXn*#$-|NŎUy묔ۇl1 v ڇQƹl`,} C^LGc0 ^UEú fW;Lz^ }=#la6O7Un3a㏳DTO}ah!5S]ۚ篡 pUd$]HiV-+4z*&p6?q+sؒh,vZqn5i׻,(^.VYA.0EeXR4%5rk"9L!IfV!Kigm|`d҉g2Zv`a ҞeyLH7KVc&y+Ѓ/xRӠCdPyP9~%s)xk{dV2Irnzrc֠2zq`M^(8D:n^kqq3?=[%,n&hW9)O18YVè/h9w9EN Z ڋ 6i!Fw*R+D%aH"2.Xda6855h4Rpo>RD-rG ,AAH+2!;O *C:OC~m<jN2|-鿹I';^ ޾eyG~?`O'*9)[ WzÊl#xs0C*I2{lP본. KfU!p*w ʔ5Jx;% ]=KkN+ژL8fg=]Ҽa %(7z_@-jLGavmc . ^ U 7z Z%ȫ`hq;4֥FhLhf;J:8^( @ F$Bi`féMYta"|7vKB 0Hi)bQR_nQ >2E?.@JM-xbub({kz&s[\aڵHA-۝׵9putNd|#5 {$ 5M0ca~8Uñ)ԽND3n .' ;E%Ye_-#mȂe7~P{Eyx7tZ)ղߒ4P [s`jmK `nJ:%L Am h-H#xk! A}0=.!ص wMO"yfbB<۞:,D@`ҥ[k/i6;ul:ke:1|szgSR#hkCs} D@XnW!]Dd~#Ⱥw9R :UUw Buf9AO B Enkvﻲ LQ/ߣ,.o΃*-?k[[ t -T;G3@;cT|J/0ϙ1(lY- S6 o8b!yztۮ({m,Sc{泉j+$J}KchՈw"N+D+ ZQCId-;3~3v ])棰Ga϶jm&6s嫞h5n ]Qpȃ22l8rdmk/5 Jwep" ZTk\`vb ðXIk\p ʮEKA~9o*uToy0)FU"cXPthgD\d{gʡQ3n(;qyʻDT 4luS9SPu$ R^6r4CĎ='y֍/((xm^{`ՁMWK Pxp{UQXd?0suӾ:--s& V&Mss}8vnu- 6W#פ5 pɔ8PvD=:ըSSfInݷ̀6=6$)O MLF:@Ӌ~f~A`#EFbd'3>G]DpV*{46ğDǿMhJ,;IS1wr<_]Vu\1sˉ_w{^`zs vZ*X"8-RL,wiqj)sAئ?Ζ@ e[j.Ęi%Z ' m(Ԣ1;Sz|P)"ǝf-i/T){6y'~Mb r{vv] m٧nQdf%bx t蝡_х^ ?KͤgBGt'Y'ziBJ[aY RM ̂ygi4V+Ɂ jf7R *ym/ ~R%Ob$T}Z#rͯk">}pC隒 =\ rJ1vYVѰ3oi6ѶB*[%IZ-6N |D4򪑿]XBF%w<8Z P|'_))04<̖w=gyot('QPd ~Ek0f뿿|C)G*ſ}uyF6I+Mi_4~nH$mo4a*=} ӷl0Hn"~jAX)R!Na^ҝR97* ۊ ,H_|G7,;[;oHlǎ5"L6s̥Rchg*Ʒ]%*Ĩ~vz_`8SMm72űQ!JJ-KJO-&dSj}z#/W{^Sޖ.+OlֽDY'19uz x :u8ѳI䔢%a",=*;S<|"->envRebDu0jTKeCDƏؙK̇|?p׼|Y)vS24GbbX( 4:{P$jUϗ pr)sFݳyto_]NN(bJɡq5{O1F([S_ dKn.O&x^IN$/! x#{eqRFe:hĹwcU2HNE]@/8bz]NҜ$u ]QˡuXI)_ GdŽ)2 D5>k5gIry5X;Ü'L fdF(6xљ'0|oEt\) @'C2uzz Nv=9D'o0 `̔iW!A MgWu\3STGۍK?d+TĿ6~y'tfQ"tIɓfJ`~1"bٴեKU尻\r2DD&A^ 3_L3L[ltU&QQ)ciq~}natĎb:Trޏ~#Or{rz$o:,-Ka9oX^ %zz1$K&r }<~Zǵ=#xaʤ-/hϤ^"ZߓӸ͕Wh2⯅~Pg:D'tdJX!,ʩ4`^nsYhB 3fNOÜfȫ3jQZ2 h;l95*yu@;tk Ξ肏rEEB v(p>.u^hkH6_T7DmwܻlwZKe2UnCخ|v=:gyx v $g kLMk-FMЍuϔky؁@ӇN>Msz>|`FRJZvYL,h' ,96/*M~?/*ŃHCmŠ=!yLa\V:1na~`ydH5DTW:ٻ5L/JR#9pOTQcJ:#/=ETZCQ!KZ@!4%=_Nb9H3l9VOĽE22cEXNw""^Yy 5MyBsho)ivw^ ]!8?2BQ=B: sN޳^ھ!ȐPt ݗ.W,PRNE͹=_*nE黽J̇Cŭg2ݯ_>'^CsU@b{ˀD Աpz 2fXA4RBtu{/!|&2p!V~X.UuL.^7O&a\b9iaˬq=泇@w=Bv7T/A pL;2oY'<2F $өo-=;j dfDrۘ.zj.T8d]YR%;p׻ ';\£*$@hqaqPYNgJHϰEƌ96SW~DaUբ/a_or6T? ͺ2cIxhN'S.i 76ѤUK#v|kQDp%G"Yy^uO^6di80%aO!cIN0;B&<d"%#Ҋa7F(3]>-kMO6h-܃Qb(aq㵤5ٴwadj]?4 RaB= ٪+ 0d;oB!$FJ:;2b]UE5bs'nr3 Y17UH{.yo-(&ɺ֣/Q:y-'Ơ_LHI3H^Hh@& Bk [9CU\`XYU4lS \ =⨪ӴneToȽڟ#pĕQϟ2E*(Ͷ8R[v󧨭QLY(`;:jypѿCc}#.Q675Ӱܢ(:`>J{VCr٪UJcIorU" h~qq)&N;c}\+".~b8!GID4W[d}$Vq=W3uקOkIA|M csb jnGک_ $Nekx!3z6C$>9\% sC d KW/X~:KO7mʔe3_1WZU"㩳'z,1JgeM?QI9Q$_x,ŋIٵقJT}N#42ʤ:#xo܃sz 腃Άο@g[\#SB=}>'кſOox6KŀRtySK'#ɽ{BE MuY=D, rUބ $"s ar5¥ʘ}D3T3u^Hg3ՙ])3Q=ɨܸ` F_;%\7fJD4uu?6mؙC?_E)B\ ({ao̴3C_xF S6ΰXϒ)yn(@jhĔ" aa.'@`oDd.$3x_L5u{7wUjOläK|DJGkZ5%3#t\֋NqG8 $rm#"v~}۰#KY@ԬkTz!zL ^/`WlhgXAL ͝1/P=oP*}-1,OI[z5Iԗb]EVW2E\:f:a@FmKgg뉎Y7#MS[Wq"Ll(PH~L8" Dʳ  e|+5!Աx.P̈́<ԯuR?W2fo{2ƈz1MA;bǠ=INi G$vWFD'Jsq4,H#z=6ހw|0*G9bjXssLҙ i.)x̴$\+ʝ3`k!Ő>'c+Η=($P8gzqL7O*maX~:o9 ]6a.W˹ݹoa6֭Gr?Fd%6Z~) k)_֯lY9'%}´=Tzm8>%##J\5|),]! a۸E􆂎K-ĨG2VMs_]j&ͧmayަɟA趞sIa8m^8'ǗQ!@ab\>l=J5 -}3+tW?smV +63tƬtD<$}+]966-D؁p[z/ۜ +\g ȎO*D"u}Y-[~Aɘ;F(/Dwc!-}I"crR,R.K^q]FJ] b+L @+>X쁞w=T o@6jcɧs;1d>w.idJck,D:7/5 +aC%YHA&ZTtcF|e5DDu|{ 僇^BuTz;)yIB'Q#U 90+(0aJuC;Ud HULȕ5K$ 'tH-0Җss&;Dt1!yFAJ3Һdymc~-%V :7@S?^p䊘1u,uga 3jB<Gk.녁*?-m[OG0qM]ΪݒW>je ~5 32ڿS+ڳShXdFFëGYzX=MzOkxiBħYJ2SL<݊)\ɩ!잮 q q>a O䚸fR6MwF ߨ؆hba%")r L>I7vYDpq;Ew£p 0oml叠3G;Dۈ9?|kgǻv]zvIJy =] -֋OP5[U*6;1UFy"ǏX@BG{)0JOhR" 8klm6v SC>yj<s`. $G(Q=:GBecPBqC_Hf+/\CI q(nKh]tE/c͝Gф'!lىkm3ګ|A$/V-\ϓl2xHi:rmcinL2**9@X߲x*nTބ=ٗU ;GyEVƇ\ld̯&ԫweTBњ%UTb/rI@XbchCYNFȫМ%p]WJsmVsG q&Ui`OL6Lf("*,bM"<X‡(=>@ +*z=8ιyG'j(R >ׁoPkaR;$l^;dOCfd}s&&gf}; #~>C`ȩ>PB.p硶ih+尬F};8#/p6]hT#-"Xv~kW( -D5GU jFML1z 0&i,BLBc@25^];kZ`Co/Kr׻A?ya+^6$ԦhT\jta~B2(R 8ɢaY'G56QJ5:Щ~ Q?T0[ ܥCICmz&+ul2)\qq>q Et"]m# B~"/[XlgJnM,5r;šM y{(o-QҤ:׹PbbߦG+qʏfD|B2d>J/ڽ_zz&*ZP R_c[py\,h#WC}~p9 j.|9Fh[jG=I=g<8| ]5Ov$o\T:}y1:VYKkn'%)j^@כ!ӜO v JN:VAo@i.7r0{u,]Ō=Qy񱯝Cf8'Y lmSvu"Z. M6EK.ylY-/Q^RFl e.9k#YW>s0|z3 xؠ[ŦHz-[F<ÃNce|A3dENra3-<n8R1Q5{cs#?&\z d縌G}YCPl GTe9dX4wi>wDrګ:B؏\6ǟ-C4pdi+]YJ v~`fVDWV7, Oӛ:*A]' zиˍ^;%С1OD.P>}1?_D0@"pϡH|sA kAfU{/T pצR*ėF,o3s v tJTZKrOOT/cڂ5 eS!s}55ͺO#6͖%g]M D|-j3N4\: 1.ZP uA^A1SJ؆} %솇}N/]Efj;AgE7߯h[!vٶȥEa-1@Iv.0S%:qj%Ÿ4nj):  ms,4.$Sg Ox2iI:V[>{tα&O-5X3 /jO%%~6W_l zi:ރȷNh޿\`r`TNZq t] #GLj8GdR%Tiyoؐ1xV 3w (HۭpB0-X!,eòܵE8N"9H+*]n}"@8`pQLsqC>_]pBI0F*Y^PSVbۜB}2TEsftu/NC%-!,MV猎8N oH<"3ACzWr~7rdf/#MN`?MϨ/n:UV?rɷ(o}PUMkEMFD.+U 8cOԝ;VaS_ȌtѨQnF٭rR]ΒR_F鍌?ɲ~+fݬny{ }9j^j+ݳVr`2$:󩓨Uzj>,VEn3L4K/I"+罷zgH]ȁlZmM;x T~eKWgsXpUjUq[[I 1)a;;;@rM 3{ˉx_4Oٚ.lABe`߈Y9~E$PlOWh{Ƒ.Mld.h󯲾-)c{^Ir uba7{^2cU.KX<4us.a,+I!vbmijV e9‚w -%\bKF#ښKPK ~_S\w[k@L~GQ/o8 Y/P UE,MVc#A:<8. ah|2a~;N3!L=rcOUARf@M@7%qD3$܈ƷIۡ4X{Jaשi-(1Hչ*e%}2"ع8?SlAM?!m_Qa,TG$XϧwZ;P̮g$mYb̻M-cVi ;i#H ?Em[Mw4UI:B=HfwN_xuA|?ڶ_[襩Ӳl w ~欇J#K L%E˴KIC*&&B_ ?DShv٘@@mѱo䰁wUg}XYu{(wVј GP8R-bB+7N{qG<\6 Ϲ&uU?X nZ14aϿ1%~ Q`Nbݑs:Hp=L%FyGx{0X)ZkoRGٖmb5rrD2xr,?]P+zm )v߆!/8?hwVDp~L^aVaW.U#5/?{?b"gdH R.r-N? qW WЮU6Y%?EҸ"7\tQթUVNU[)]kPR8PVL=!->G0aV )č(<~t+L01s/_'תSf>"Ţ *祤c5l 6[Mve 4SBuu3Bnss^8OxïH9ont5ݾ2Ckw0A*%5|/KE0IPK0{ Bu:&o%JS\-3਷JAJR4B[iP/=\`Yeg(W)'{3H%7HC;bGR_[t^C~FYTԔNGHM& ̐--{׳dTեՀ'&0j3* (aq_ǁ/IW冿w{%s~>b tVGف˥/N^6=d9 ݍ5 ]-xr)mzx6ocgWf9lFGJ MCP?K\Dkv61>VfA6ґ&Hh~ l}e}..oшCFcJv?;=V%w6 *fVɨTEPOTm[PupD'[{A2!LvUs)/'θOUhLLMQdfˁfW3)͉T%%ja<Ȍ'r0q?姍]%Ibo;:b`FJxk'CUFX1}Dž 1ycvIwd.*D:'`6VD-lP L5r5X?2Zp:^LDĖqP^Wtˑ6vk36aD!1R=KO쵟p~E@o&ѻcʄóa< e PFheܯ f1P>"Kח7.14 'w~49GEݾ:A^/#)lht xxĊ9%ky:7ADAQc``ERz+zf$i ;pv?$vX:~wsC܉= @OB=1Jgo0FW}# H">i_{ hSAj 쵙I sǤ>ʃ#d)'U,5o=._C $H"_R R ?Jt#+{l`ئ++ƹVO d]x ˺"d](d2$1Ch? D$b&Hf|jÉְH7~%$cɢIToBc1nhZ]tp“_xMj1gϵ"W;ǃz:?BDmը*|캦o삈zTh/ 0deNU#'3Q-RpH33qK6\6dm>*Q> pN7a;Pb3#X3A/yJFQ1.e @ZHGMky'棨@'[t@Z c;9.Cj3Jʼnf0C)`vb)oLUݜ-)zlсqJؿKp-[s ւ$s{P>8 \`3F;άHz񰸘B}|t8;)-"0˯ygd0()8>wXi ƊӇ*4=ZaS"ɗ$eԥVͶ/nۤ˖dHshŢP'|v"w"³z1{~Wxw& /[DZ<ާҸ,uIZq-dfdf$a˚uk|'h}qκijQӪ7YkA^ZCA2WK¯HAq kHҜ/K*-f}xyǜEA.ʾRju 3"ZX6+vpa3QGYQ$%wZ#׏C:Pcp?9J1]dak&Bk[JU%Kw{ńj]\7Yᵦԇ@ \2:; S-`- ZUq{į3I]a Bjo0(l֊\+;3k1ŽL _3LĦQSmcy"W):Njjsu\e&,bc}1|{v;{7M; Ze.I/2*Фݰ`S5|٣b~K}`=θG0l}>ZBPSު!@طgPM Ʌd1"AG!1tV )asp![W5ICHeP|YLF#38 jQL,a@rLablEs6%||jf7YaPf[7CʴO(Th>y( =)'XCخ ~ʻ#A-l\dxaٍ?2~qV#B:9m#  /a9f1'2lI2wi}saqdchm؍(QPHL͸Su,a %vJ"窜`镝q¨ ikS>앩l3@^;Zb`2cuFؤ9\qMɱ[)8u)9R|24 pדTc.?~4r&G'$$8dՅB qʦTHgsqk%LapqrŜb+Bl,ȣ83QC|hhS."NpO?s}rE3g}0zc>W4Y1.E-d"nksd1'8KlUӿHLo`6ma\w tVN4 I·c{.p؍;"9XC_ieV<3yo@O#HCZ )p[Xi"3_߃s|eDV0(!neCx+?F$y^4)ݫ6bE)R[zqV=F(LIت`g6W4g)C[jS@!)z\y/_4b̽!y&fqb*M4D6iq5 H6Rjk.қNUQڡpQVlQxڿ@S?PMP0EepGu|<Z/,UW~ 4si7%')@r1WEU{Ƙ]s<o{IgD~rejl ;!yUi_%Z-lc5䜁5z7KS}z~+VB^jr`S%mWo)V=2uS6wd4{A_~̻א8\|[fvG`d'\ \y`1Uyj8VcQ=vb(%=|7FwUNv ƼSą֖VL]FavΚI hHG 2 4( Aw3lGf*? $@D, Ǡf`VevR>rSh8m/PY350$2ļU(qCLyS ˜'9`&\X' |g)?٦ cq>JC7DlK+9m뾚Da{rJ"pl| 'rƚ\TݧҕW+./LGRQh#47T$FKe"L+t^ { xF:mɥ-fb?<w'3T:*p$ )u*;4!2k:nuh[۾tC7϶ݶ+zIo̵պ-hd} 4YlP2Ddf *=|[F81 #?g%)r6p"RFǞ9#,QDcɲ}a 6 J]Ptj~/`TVv*y*ʼ-WS 94*/ 4f;PgS+Bi]!`DvD׃Xk0"7JmM?u uY߰Yɒ% r\^j}8e">~\zi?<x\wS3U{\^g(;PmcZho{OKg 41h\K9OKh*`/@t~+@?+Q#@5jB~Z/8>r,ޏ 7.PHU|dDgk /f9*U!>@艄ϐNSzޝ q|uv[`^ M>F#ϑsz9T\.GcͰh"}z{gS{:&l~DajU#JGBrzw]C65ʉ^}(ωG(o|*^w|svq07̇( qג 2f nj?ӧZ۞8O (y6R䃣g9{4OV S_f`rbQxǡt^KgiO'rߕU<8Sm0Va9LW9]b7ـpg^ch6[-)l]TԿedp{nt9\ ,rHkR#aL?mCM斀^YD|Y_7~ԬWHL͜&Tp\R;DmijnnCy,0{=3i rV`}2imD ʌqGv%\.\t]^ ar5" - Otu<z#6̜_~zzW@[?xHGE6r!OvMw$:QBXP W&tT ׿tB$gGNsiIZ%_A-GZI?2j&WՒnG0!ƼWRq ٜA, (]bɓm)gw$vvw;;v. _vo igpgAs%^JΏ]oUˑKLHɹ9<~j.h 4̶Qd f88V ݩժ]ıf +Ŵ>K,c^Q ۔B&|+Ѡm' Ifo~ud2K$bls+snS3Oiuf2 i6ȋB!3I;,%yN iCNL }MC^ZR ^wN9gxpL }-d3@:'ѯlڵ֧UfK(Q٦ $ ul1|ݔHd^+€Iy~ps]*}u.s wd!=_Ջ \P4mJ szBllQ 1yJNJƾ~ݏ6FK^ 4NnYm:8(5k&;g3Pz'o<Z=j0@)}UVnSm]^I!8)q-I$: ث]hz?\U,&G9^[mVHƯ~ ĉDIPcp|==!L&X譇%P?$&eqPĔb(VZѯ!zp܆? G?TyQV"umҳDh>hSd0O8IUI_`ci7sg'51+rds~:Bl[lq?Sx9XPo c)5k5t~-?i-e!| Jz|32k'8!I0 e.\S|0/ϕÑz$l5j.5,w CGuj)yG\1 [FQ֜@KsAM)+ XKh' xIw?r[vU4BO]aSåAyQYHP!704wQ!/HΡ>z7DEl\U&k`0HB/&x]&]QG{L)kf;۹yD˵>ڜIǀ-rT-dtW- N_d=OdψCOJiqkYw]!s]Vt] @ w(]s}6Iۅj08fiEKP/ =BMorro+:\SO},985L(tHY}zLwZ.[`@ ^i2G%'SLk>`:o,HǠrDmڻ lJ5i O\NN_]kBOrhIˁ 3K NV$aB5Ll`lOs t["E7i}ó|u`FskܣLpIB ,ϊlV}zq*ЇV!ղpK3DY+]p$(褩= ܪ0~u|fI3EzahR5U qpemVP ,]$_w#Q';m:L-Xv;Wk#Whnꘟ訖rI`lJ/j%s}!9AA1MB@K>$1Pi0 zb榻yDkk4R69e=&s$ڹ#]0kԱn6 Kז EGհ(BCZ:e7ckbUl@J6F[ 'LA{* N'2j F;+2fh?}8&Q>O >EƘϿt&Vx.n hu0 P Q"Pł4-#A:<KPg#wH_c$k6g%쥸y .CRyCzִ ?.n &4;pO1 a@D["yX16F:km~1~ T\8/uvl@e`Fu 2.6o([A~گ;ɶ/s)0ϗKncuusEtUv' )<ygFJF@ZYw{'z2 -6B.hH1jI# 0lОȓL ʾuFEk|P}qPa3vѻ=W9>~!63oV0sDu|u 4o=ϐ |M_swGCS bOs*FA+N1龁&2%TjṾyDAWӠ|&RuK/fr'RR^Y1/+̀7/+,RnPW{<Ju?BNkɒyiOz_+XYc~0E% 3rVTrܿTjNh ?2l0ͱ+O54R6]OwnQVVK^\ ?P)HsZe]S) Ma:Y^Cgj@Ja~n#lꪋ#@8bwu֩s)@]S@y5b4l$ϵub^* Xދ%;Xjص 34EZiUR fG yؤy Mel6_ۻ0sU_?#ᤪRgE*wj^H <^. c ABBU:9;מDZT (+ 坚#BUl/5u?YeWB沉 )eU9gNeXՔ/\8h8v 2'fDߐHKq\~Z3tTDk~ԉB-7ƫπ1r|P&.}%Jv";;tބ94_WF<[gN&  , doXq1^t}lB$|AeʗC|27Π5>jNVCOCOTN(l'&aM8P }&%>SyHRs"Ϛm'J"VUGg !vȤ k\ >InY5*^l5,rΕ8qQa M@U&G8+[Eϒ*'X}/#($ N{]c'1ì!dNM~lo& :d5Jqrllš0ob7$;+\Ҽlkf|tf.Yp\?]RNr2/A=9ڕ0\Wr'85ӡZj;>F&jXEZdX?:>Gb`9s0k?(6 diz俙F)Ub0PEr\H߇eAW%!d[ b)7 +3?V_4vL5؈B:/MC~)9H~DfU"UطM5|[ֱj!?S䮯-YxӪO6 ޣLZ*Ű4ʞq3i(v,E-kFWwoo׽ZN;:br\[ǽ/tGfc_҉NF~͆1n'=b6͆Ieya.w)i|9Z#D_͆ LP kW2*oBWC.z&b [I ^ K`tzht YEN"yƊ hڜoѓA~pU"*§Ox 凳fDZT&))mLbigaޡ;`;w_QF;lrn ~xT ae3а13~\ !k6e qmmy" ",fCP\m~P mHhLG `uwpdkʟ`aGfvNCUFYTfώφ r|n1D 7u|$:e0]L4j%ϡJJ]>Stihы~k7nm$8*OZm9KlDQFzN[zZĄF28.DSA}jRh(u?5qk{VI'΋(@'QOq\7pT DER1jŋr#oU$`kN ŽeBƫ: [ryTJ#esd/@?`zIZ/u N|*x 稹av~)݌q:Bt m.X/'B*9|g~n'XgMO4%FPZ^ +92'wӡ^vA<(Q(5ožB .IYu1Y3cfvy)c-ăOc6/%_j}6{j,aHmӄ6uGۻ vʨXDǟ\$.).IDH2sf%"b\6F"۳QBU4P 0 jvSQy@)l).Wo[QFPo}ל.Ed^;ض*VI8k;hNЉho8n= 7y[EUMYRrt97@,@bB\Bl/P`pT}zK }%wz^Cw;ӺRԾz>J;(AK;u%ūömK9, uy;B,J SRHDyvf7hy5dudt3Jw Ct퐝Ny(x.Amˁ=ߝ0qߤք!\Iy)yDCBξSpJQ،-:x=:׵AU`ݭ3Pɻ.Jn}UI[/jȏѵs916vpziI3^X+oz'||F Ss\%2s(*fEr˲`y@% #oP%*S/ -rAP2r\k㩞:!oǒ5kX)z9ڵ;B]5ң_V_k^<ВC#1ܢ`;k'#Swf 5n^fpRT89k?BT U & Eh崪jTjk11y-jauDdKC+ fd]LJ3ӡLl$1nE(iĝE)x(Ut*J KdJi2s N.uT" 9QV;8o-dzch@v|Mvyrc !b!Ԇ3%ʸN]64H6hƾB<I|b[z=u I2Jd%'$UqdxcBB|dJ"ߧ#:pMG:0f%,c$aK1 y)KN/ch^hZьSz 0G: O=zlt#C1=U1Cz1*B梻Wâ6&1[^o)Z\7s>2zJvf' Tq ;ܗ~PQpn} +@NH] = t@z]R7صU!ĸ7JK(aev^>!NxMfXLJ/0y6[Dʼa1䥎i"j<<x2y`E'Y ='sq"QPTx-8r"!P2ݹy!:]ɢ?ϸp³CCMWkfSﱎ\B6ǯZMc#}'~iV-i7)s٘B@jy FikpUI |r%TjϛcjĹȏZmBRkfE+'bm4gF] gܼ)`s7r#L3^B}y&N\u7xFv[LJ Dц5b@.*= uO /IGof!3+`'Ԫ 3*o96rԸ)}@x߷eJIYmh 3,Xm/ D6n0L(vߜ-dZ1 #]-(I_7e 'rW.>GbgTTy8B\p-cpa_aQ[>zßMY<o|97<> E=[eW$ga>H |z G=f:oVQC `;,5˷nC+(' >OZ-x1 $^j?B?jP<ĤOfo<0TIK Sե% FH4 XSف<{Uж W\L0e3-)XSwgq6C8c֢kߌJreԡTb8[mKp5;I4س?qY!JS9J6ڕ-XNu9+kڞp`\y\X?s5v@O+3Ԃ0" g2&%CuG_B1C|P XJp}G c&]#|gLf$cwR~EJQOwF=rypgJwm/qM;;B!)&՟O1_W⡩RvKcP#kna^ҩ ES?>46kzB҅]'QxF_f6&޹@(qȐqك[a鸯;]zl^қUh&gLom] jo3([yO0ob_ /ap0Q'zm>-Е :YHJ'_;#q/Y^bz]&>U˒3d5TRbKwNr5Nvi-k2QX58AY.'xR'N#'h^%E %O{Q(9\>Q O[]kXG& B@A 4gcB,UWn/ ܅8\ o+]Pu*xVSB~ާA~\U^y(">wX>µɆ8xr /LQ5i1\Vj`^NoG9R|[_)fT#D}V>r*)tEpؠ "2*Z!"%)^/MX4@ȪGDDȉD'؂zk5|!ksD(rE(y6磻~$'kNZ;9 } k1>{5ukCA^][`#&Vx[>zfW4gP8$OG=EP)E@,PE8ZX.:n³ uі1T/B~I'RPEu؏B%q!vubWGO=?Kx6\zYVWl^Kd odq׋]8w#!]qѻr g$q:>^0fGy -PN|ts^˗q6w{ci`+`H/r*)7<ذEkk v7A#Nq)9C,< ~,?Org5|o_=@;{!p+m3-!璪cXB"M*?@Jg{5Š/%6eHm80eGx| 9'}Ձ]^<%og0Lzg'rx7{П* Ďǒ:G<֞p>t}c?FCڈ5LSI/n?#aҡSxHS-r(7H)ؽ`P7NT8>YyX{ \PIzaY+oy|V#p%%gPD4r^v mEAڋs@ bzh oAO#[/!QVu~2~=Աp6`Z[&D>NF#f`-W$RP8ts2I941 ߧ~YwF"\J1?{lx s}4d󯀹UN~?Ƀ2 Kf"NH}G,vc*zs,si/Ҳonh#dDv;Is5pheb~!V96rntV 0RCdC ʃ9?Y͓KJa"o]$ɡ ABl4i!9{?˸SQsT"TI!d+̣%1Mm%4Jm"ISomavI?T Μ*1DNʵ@('`c64`O{YVCNsRs M X8%ţ lax711_ },=lZ]%JP_k"ʇ\]"+924CJ nx`faKݡ:! o*nVŪ& :]arh_a%Ro OW51N#PJ`g(1R&bUR. gX73b{it~EJpQ! :X҃?S)Yv5tD7,aڮv z~Mp fT-)LZޚ#u)QCN.hA2E[n7 ogɍJs7r|#>KdcyI@oZ0W_fԡ4gPw髆25`sa"*mIW@'aٮ2v۫q5Eh&@CNjn(~fX5);bx+՗oBЗ@nB\YVǮv`tn?%ju8J Ek8C<լ'm ZjV6VÐͭ#ӝGg"v31^EˁCx C?<1ph5n !=AZ\ %<?MRsU"^M@PrCZgj>]y6) J0MG]t6>(J%A{v\'Mgƍ0dlOFZ@ >oi'AN . |u'&⊋Ԭ; xg= y],+Ď۳&(sbO E^:]ۦϠQ4ԉ ~w: ٙQ∍; Ȓ ֖$ف7?҈|K^bVU|o$=֛" wmb۾Rf'gWBܩc0a%pjBY7F,jiuQ}in)Wڋ X ,a_VO/~y<3zC Iu.σ\[pϋt GB%xp;u+İν}YqnDWƷh=!O&'e)WRUh|@7(|,BNezOyZbƄ Wn=w5x䁘@uͅ=1ÖUWlzupQ"!vy1՚+Rםxa' 9!%,ڈ@]He1P{X"C"+x|-(&\cH L~`M)4M}@i3J+']bZv08 #:$#\ul0NL!+--S < R ;3^];u'nzzQ87i8|ְK;[&m{! )2fSGdl%L@$"ڍco[.~a$P\ Qa?މ.GUկ1RJ<й7<{s7e@Y{'Xn잯CbRI}`ʷ1w̄5 o^ FxۛPNla<#M\V^":߉(05Bv铎i9RU! B'ɱ Heƀ\G ~u0=)v-у9ٝ)/.t8e,T2kwxar}wg$|PΤ5n@-fW%OUGd z[=턱@æZZԨ7p oI):gHK_ ֚re)H` cYJ/4o]nLn.I6Qj=[ً^%V:A_Lد^a|v~27#({i(9D %14s(kݭܩ͍?4iI=7oq9rb?g0 yF oYch1.MiP5>weH حMT|@{=^E1?OmXKZ=7-+qm5 VR}[V{S{H^THGmp9Yݽdt5nn8H"20ǵt,<\bkjPY 1K'ٸ¼K1 W:Mj!^@fTF^^6`95׹_YT@,5BvN!O wT;" eGtm,{1' N:8D^vW ٠cUAuG8K"l,kAUgKOgn뼁.Cb| oKJwx8KQsZx+?ӿwOFxTF8.$`LK:>R6wTqa>TcCHӍ;TӔ} BRyؔ`8AАIZƪAL{_Rn#]V!U0ז sN_"k",w' ~d}eZFut f-<B}~E[[uO:b*V- C;@H˨3$y6x{ D$T!H"ޭLX%M j;|(u,SaEjgSt6 ۫ guhl;bRzh˲fRGņ{̞-<-ޠΧem&ѓ7/0ㇼ/<?eb13Bէ\^_2)V6l';b_T&;Irxh;/)8w; D=|/.P#m#Nٟ.)=męC߸HN5X{ jĒaق鷹PJE_Ǵ/|pvYθQSI1*^D8!G$@R9n8h1|]p/x2&^ϻ\ !:~Gs`ttq ZSEryK+-X1~Ҕ!ENh]Sx$.EFSI*$ _5X%CB´;R8-Ԣ#6wyK'*ů ntW`/zՒ:hǼ=Gl.m#!81!Tm9:>?"mxhtCfy*&<#Lu6] 2B[7,"Uj>'[BoBSux‘:@$`A,J#FFG7h;IDT+t>t(~F4>;e\Te|>tonT܅s duᱺ愀!\KO%9A L:qES>Ɏ9p٫hfFP|Zs]& ڽ)^(58(y3F52R1n(R9o?u$ KQoo38pZ"W_g N"&}bq? 8gVIIP|ʃy~-zn::XkFaDmȝLiY-/eQ}.EGÃ#[okݵc^,qwʬ>aX},eLo+ʣR"|K]*X?sUHBfmQIt=+Ebk< %[" )pG P(l6g  OsY1!SLӟOFŋaSS`@dߔ @ +|!,/X]O| LxUm;'|"=FgM+<_Пla"k)^>53r,-nFGs2ȉJY?zm/pHPퟑx4_ 3icwV$$X]- &tEOK$hדcYeL 9>,qg=<aYzDr kiYN~..[FE`)Ѷ 2tB8eL-y@;S-w'C7)_>. U=.{TT* >/Av4MH1,(H%Hw}m5l>QO >]̢tƇƏt$Z߮H#.(Fw|Y EXRB3>ݽ~}R>jʷASC JHqH0Z?!E~lj`O3\gE!GgbVJ Y[E)JI.Qbllh)%`Y~Pn3rn=/+qĐxg'ӪV=u5(>"S? Zj@Ku WjIbr}e͐ =  .y*FIzfۈ(rNƺ2"4^q3e0hQ#{Q ,aW H\eghgq D# 5 <ۤ`L[ 4m-pFMmmX3h:,冊:TQhl/Ԕ*ğxi"[%7&,lȾ_hnMV9*2c`r]$FAVO",33?IwUtYʝsozE#~KA%`6PR!^CK5**ăB>V\Ub떗w9*`k\%DU.tMf+KO:Y0>w/`$[ٿ<{Lڶ/ZGq!KgI ℆?o 4-5ƃ:~Fxn6z*fbŢ0Z`+OK".YM&YGj$8iKcl@(.h7:~.kEJTZ/(JRS@ʷdCi*+dɮm)9 =OAc:7yUtv &K2hrI.^A}s_cr^% VIR29.A_0Lv˄K/0F<<.~ Wrr0Vr-`-%Lٔ(/͗LK(b U7 H4 D]4l@71={Q%q8a0hӍ)a|`mU%/":'9ͻǨbeZF^}9F r\r2| }ݗBkjA:vGI߹T( ^L7 (9 L:u߷|^Y%I Bmy˛sP5_@3m]'0;!4ͬ_Kg<@ggm`V; dUp$Fo;y_IHs&@g f=sWwZ_*kV8&|6OYW@ PhX/oOAzg0)'#Q$%A"A1Ŭmߊ ޔ[lػQN= ~HZ$,J8(؇k Tr]rڧ/k5~\P*B[}Y}D[C wWe-!{ h{gWUο}gypoLLV:K/'($ jշRa< UR YꜧܣD>ā(\nzh#t?ZwXQ2}onW|ie1ghT5Ͽ7ކhpe3!;A˶ReRV;%qCk!|;s|b*< vQPW"|:?)kd'fHB",Ձz*#:+7 yp@Sz#'P!U%(^' .EzQmڐa *}ACa+1naٔ-'svK!|.DE^un B]'z,i[čfhPK +dѩ1g @3Y`!u-DMK R\u\!s_ΔLKO@< zh It)VE({OyFغI^.vnb~Ԧ08NquF~]AE9 է.ȉ:e_uQ֝o~_ о7"-  Z }rgy|s&iIhN)7eOZ߇[eS)Ud741rDMDm8Zc 'o @ X ib -g4mi6"EMsK @! G#F z /U\ibl,l+ *~P!+ZV4mMϗHrBj4fH3=Ln&!mM cd)Ur$EcW2*Q!@et}pq{Umi7&V:z2] kE;e-N`5?ipbCNtdV`ڱ["t/')l3@$ ]&:*'iDhB*q=sYd"c2 { xE(l(;}W%:XUm!5i6hj"X#Ԧ+@`!!E!.VP7>I?VOΠ Hcc-KXP{,L[5BTT3OQ ?mO۰G4`dc)[BrJ'b*0Q Y٧,)UB]AS9%qde0Շ"ETAaȌHE۰Ja'bChͪH&8I3/yR 7"r?sdF2nQ^!@9FmۂB{-8?r/}-/ x̔s>p̥= m6 \jp raաR@u8jb;<!`O =2ӏM_Vsq6c$P3WB.䆫醌5#]Ih.aOʗ t ><ܦ/ndUW 6d6^=,],[Xȣ8~~us4ebNo\O3$A;dlv[|ˠCÉB 6[CU04JvV%oX&m\C3G02˫۶B=O2ʌ/Ş(f ZuRzȱO-`)lN"Ŕ6vW $vdS;y zU}>OTNF]?_52|8vq%|̾8:ajGX_ z̒LL"&[2 @]Cx%6tj,ҋv쬄SPAKiV>Ea Lk8K*ĵK @w3 QՍE*' (IzqSAܥWa%NEX+;xJ4IޯaH.%UBRބVjlQ֧{zq7T֝EN=alԶnZtήXsADCn̈́b & SUË1Ϟ=ݚA!vrs)B:s Κ)|ux9Bvjy@cxcl !O0̈z,+v-Z$t1?A >Li60-j;bopUJM Icqust76lqA \Cks]&L_/Z 6wzR(w`LXq.N S$[zcgĢ 8:{Z=DT\7;!R_^&>Y﹍`[U :A-t0X~f'V7>gW S[#r|'_&i{sw h{B]E5pKxe'\Ȱ_XYz8,Kp5 ZR>cEѿB51F8TC}fLz()gNǑ6_V lNAQ-hMwbVx5^PzB+NvǼt.W7[Y5>v$?FRG);uZ+tw 5\!( jHnI+|df0E^HpWR$f Ƣ44d6H7yˏ0ܚe̎e]C8ovIC6 wCT=K[di^:~@g$uI}CM Jf2j:iX󢬍o&90ܘ6r #`$G+Q#0` P嫆LNzӬ# &D7DI}71 . /.^p~;!.5Q=Jݒ2qi|slh WAe{+`:ՁY`´܋AV(k)9]LsC"*^B[RgΠk* .9xjiwyOBX[0[Y%>aP3[b]) 64ԡzB@^'_` w X~ FdER3la*Bjs 3 @65 7i$\٪jaeQ#2O 1nAE?hb^ = 4=B{*i$lxx%1oɲ'& ^PHTJ~a3tvjrlL '/wQu@gèB]`0&{Aaw|xg䬍=96݃0 fquwnU?)4L[Г(/́ z;^ _gzHLRQ @&zm 0; e j+쭕I朠Keˮ5~ؐII/*Xx>Nī0@ojB>>@&NZWٱQj g+96$XE$^jxG`s,z𤦻%ƺ?NʷPF3wK gM5<FHƯeښ 1V#ËFoOo08Q ;ņBqYU؞|2` ٺzDy6_L.`4#au>}XzGCCnh`<7hpWip@OhR@iF*c,g*уUϡΌ)HsҼ=}ze1v0|,l,ЌE+ܛ-v;s"i ߯&A@$;ĕک>< ޢO-&J!P(ܬu3)q ʉd,)GgPeN};K%Y Uj[Dʘ3wujE,{2!TهC9_@$>X5T>QBf mu嫍3һu[*X?%}N?:۟6NH8&hh%iaӤćA0'{6(1hӉ`Qꄩ]AkLf? O{,8rx{||ܾC:r[wmG9KEBCh34hk{u?5˴,܁iqU"a><&7G0-2$BP`FPCM fY+BqѰ|/Nj!AGbal[%;Ayih ): LR{bw]s8y9lLsA[W :3paΓcUf/q97Y_00JԪ!|>Lk)Y[1MVDe;|@2ԃ`@IȘdNpҧ|1!{;'uUfe) Sb`ANX ve6q~ZsZf%IuˋD $gk~XN}$AmQ'I0^,b%!ۮ5x{{ELC{IN8 v/Us[t,hߵ?3EMzo-@k 3tnۏ7>I?t|E #JEA4VҀDYk@"eTpS p[zU,Y->NȲ:y 9 +6.*Ne;5]nB^hW,-}P]7vkKD24)JE9vzÊ`jl3.~bPGW5'8YGnH8ڿ4/ڶ"rӱ |oǯhRQX(!= .ipyΟeKU(h0HD|(<넞 ~$H^Fȡas)AIf Y L#b[d 6Y84m9S(>zOg+06}hB{68Uy *NXӂ>}jxc9.9Xi :+y^^! as.WGG3;8e[s8ZWɊQFqm'qAUT/Cp%1fdEk$b^s4?IuX}|t&[d`zڠH~.#q)j8_gb l, *o($p#_ **)բ?q!P>s7ëX*0TTc?oo[ *'T83耧iNJ I 5;L'\;w 'H6@kTĤcJ/>coW=M%3L;*0\le5+kuRWd;D.0fxEHP4^R4&&0>E؛Jɩ x.Xf= ~KQ%x۵w?Ǜ)`z9- 1VF^ |$#p# G~J}y/dMcH85uϣ}>{0e$yGaEŮ B@y)qj%zGҥR C%P]̎2Sˤuȴ6@4nuVVhM G3*H s fN8{6,ݫR {pRa@xD37&c$O5ܕiE>Z,kbR!Wʬ߱y|Ʌ|eV'=kQB>M#H :ad&O]6EfCނvOYx%̥yC nѦ%ņz2SPNwp•NP_)0G4LӸ?t mo"TYN9 c:no r$ {>t[]*\UIsFL^n8׬:rRHFQFM~.^T-LnRigs`|=,Em R#d!߁匿lwᘫTv[B[Aj{\uʒK03i9lvApzJL'g-#hCjVْpejnQ+1'7ڎ|ץL6ͳ@I}t)4zԩKWY'mwkPnH`sh>2T=<7 d9{T-NGu N UV]<ƳaA+O9P,z5u&K w # ڑ6s2'&XnZ.5Qj,ߙ+\ІEJ |cJ":BqQAIJej1\)F`Ql4 ~򏰷5+R{2~ 3͞ʤU4KN]wM(z?Ǘ+㻎2DR/=x8NGr.,j4{1+=0_\jlvGF+oCZ|rl(8c#2ՍVWW՘B)g|xmY{jݐ\; VYO=+a\-\lhz][ҐanK|iy!6hM+]sk[Ǥ3Ea{JLq~&ʴnջ^Mxk8$Ȥ7dS8{9Xsls\"~+_ϐ8Xd?{3p/.rp֗$?4YkwjlkO4M&S==ծ؉i&WxӀ6s;wg{+w`LNcNn~lf'm1sѕp.xC$Թ˗G3RSUm| /ɅN*z(fsLlOUYRŢNVRob@>䊃JayjB4wix+YGnlRa:\V='V^9D3|qm8B䱅/-1=qs("-(r2 K!l*ƣIrfVܛ_Ov 5rhW#2&65{Jo(~'ECfO-- nliIKSE\}‘TvSi9{ՐdtAD)2[in~pyϋЄ8ݞDF, W6B=` $署aꥃ%Ƹ+Rqnxh@nu VX[  'j6kʍ/zxQ2 XiU0p^ q,;vԚmOrl 0 J cJ\Tw"7OF_MIJt dŝM#82pp,P,]V)bwÎj#Jg,ZN^{@FpG&~ꝕ_(iOsIFWTmpXU*6e֮ˉ2XDk6Vn?y^aF4 0h$j@d$]QmKSg4 RS[k$#5KE,4/( - \J bjhwaģ}֦F\ aso fT U|m~2%S.h$`aF~T& *.;!{m/$q*=j4E jS[*R$=!m,\VvMhqG~nɹ,b/ǒ@$]UJ* ~\刾i˄9 QTp4xA"z,P![h.kqaGoOkFk;x& !Y[ vjszx_ͻV밺Y?\3>zf$kaS4;#-T?b_a0S8)0!}hx::[Њ7ak6)ALП:T0Kn]r٘v Ա o`Gфm+JrDwx/?ro^ߧ溱=t8KL2νĔ}X J}@IEoj} [ʎsǔp?Yk^Ӯ|p*=[-ؾ`QT(srэydiz/rL9NjЍ &Zv5+ =JdVY"+ O&),=ɻec 1EOhDa{vπy7bZk bF"-˯Ve@[m!+RםF ,cN88{EnO:%{[EP!؇&w}x6dJL%:O#xk2,S YMb\#@52{"l#9GR&~Id<]DKJKsq K52*N(p#wy|f42 bp_/"[Gb` 4s*pY;b(+KnY"r| q6AQ64(t˜"AC\N̦'olJ7'uf\ۇyU`;rtj@3,'}œ}g(YF$@06W֞+ލ752g*"ӛz(\6,{ă>5b[ ${sEUXl<%ײ.LHh1*hqJO%kҧ]b-R9Y?;붥BeG28Al9gc+6Rc U.Tkulk8nn*L64@׺r>6 MSNu納 Ix#x[L**ށ&I.j"8ඥ0 8"JRgQcE5h'Eè,oLv3p࠭I($\|˧ X{Al3,Q{V@sԩJ׺[O~0Y?U1q*ث*(:qȲo:L?E;XCe =Y0/)u{%5 Fܮ +\0>֥!b6I- 󣷱t'kY>.'kƧCn֞(W(GuTfS\Y觴13m/J 򈖏yP5bg#y۬ L(w^/F;[^PEG(7<&)>W GOZwm"Ǝqh]βuZ*֓ݫ!ؒ.lu]ΝigZ3ys?7GV=@]ʈ6R`8Z'Mt}-(ł4?-M t^hvn|tTpG $APi}jG]C`JFzds4%9Wy@o =;H(5GS1Zt,6& [#!EPlשJ/[+Jۗ"x5t W޻VJ#FN9eh J–PBŒ? ;U%GD۟J fQH_;VwC6ܠ]9lj])hSj¢Xs6·i#qVUxg67e*e#׌tx; '\V@$σGb+h2?.0ӳ ~ LyjXCGX,Bpx:ZB/Pcs>3+-f4 #M$c$,x ˎ}bS JESӶI oF޻3as!ňG+6?ȱw{T}8s- @`;FI1>Xi6LѺ;g? @}~|/Mg>7cXk{Wx9ݷSR0»VIa9UemVGq+| ` +KhNзw 9"&`Ϋ@ ( t},|p"&} f\Q S$ 66NʕTYfDxcMF.SChOT)W/,Z,JCiK `L;kXvG[=[ @ iXѪE2ꦁTgݕ[:b,X0A"NE4yV:逛@ud#?J%_Q@\`ע׳0ճ@A*h¡e+sg{Д6<ެr{5*nE?xbWopƽ}Z1pG9IJ# Z$O796 ^@޿:k_/gd\dܵi/Aɵ;.8w[z![.aTA)~ d@f12v;p̻WD,~[JSfq(\Sf򣱢w><:ױ1ߣ0ƠaꖇK7]F.)/) 1#'دكb1eG;_qkeI#lS̕;6qysxrY&)6^l6l mϵt>^yktJ,_TXȦ^U#J&ȇ*xş=#Bṋ%7za`i1#B3BY.s6X0qlލ*%#+.tE߈ܨژ~xb2U}+#d9toa$gmvSw6"8??+3Yzھ-wF3JJڨ^~|@u'xrmpcp\ kt29hSºu(VrymSqyl9ib]N^{. ſ.Qն*&GxC$0# ܮl+XHw[l=`4ZlrTl 6~C96ۅFIitUF츻2f '[=׻uh}RjcXΦ'{^y(т$dS=eɑo i@tԲWa!/ґ!Xg =/1Ra9S8'vyߔ10laȠ}5ԩg{,ڡuÖ]P[z[_Hqef`LM\+EL j]."m- M bwVyU2s>zGWێc86͜>uءdts<_Iʪ!vsH}+MVZ-9?i(ֹܡlpuvr"L.fٌ^rrÿ趋ceX]ZJI+-H7Έ gO߀=`uo[۬"@Ч:*IRgc2_/u7p%DeCѺb.2Q`/<*ol=37Cnh;[U\O$V/J qMo$0"K7pdX;rC<$WX w]AA",1N<  ".U-־Q+jZcuyOU t)5I*$Z Do7b`{cJ˫,oB͵lg[9SRI[ ~v8**F&Z#cv>? 5P*a戕bK"r%ĉ{_牉)`}&4aQ7!$t+NXbhUcA Rnt(bUwjcHm-4)1fbcŧp'ʤ[ `ROIxwPjJ]q9`Z_а%n)=jȪRC2D(KzJ25~;CڔdT/R=1 a?<]?"xQqHVkptzE!1Vc k TWx܅,,+TVB-s@i2>\C~8$S]3ANĎF<:"^<ߙo:YLzF6&/BePJh a淚GHcԫ׽n6pXUPYV__qr:0n8I&$?&xCC6*In% n*e4 , i*<G. qr /;s +~pƍf|%^K05PmmD]TqPmVMնbtadb)։*yV[-#˥'y#^sL(/_(+!SMM: j?y⶘m,l4շvsTĉ9E4}65Gܪ񩨒zdC\d_eC,΂$TM?2ٮ@*ӫjdSvҙ, M9AW@ Hkt~^%RVTWgKJ- N}+aFߚ0 rB>HzCגryr2_MGf6RpQif)>LY7.[KpJU\vj-<]o]P_Gz|pwkG7'\al0^qAQ8>R] S>"X#q̶ؠ>aG(DP;sy7͉WjEQi~'yd^SSou'vuo,F+{.OG ӂ\?̡)!7j!|U`T:AN7J7;%IA1a B?X2~}qZRP=rmhr@4O?,B(kmRvdT{lU|/ث]:l][!Dx:t{dL뒅E`u0<$ ՙ+*款_%{l6AF]ƌĕ;Svѱnʩ~^]:Ч%"'(L,K&lb/EER+ĜN/` vNrGi#^5^&2-1!j3MgW<NS@I9߭KkbqYزf}jXsƥSi8F|&1ۖS 1|:*ט|sSJq``@,~*nwg8X%c#:5tBSᆡ }LcE}ly5S,ݍtf;k^'WmUyzH%! E],9Nأkcm'M`IpdBB_a_ "_D20+skGN q+jU--1~Q S0fاw|d9F1Ƥ0sXh:w Ti\5G^azkFڍ,/_hg2hx X!_BUU\T (/X_>O3ri . 9ڰ^Yԕtt$p݃_ |N( Z)#fa]7NBiޯzӝCU^t`yV\Y`Ŷ //Ocuv^DRvjؒ1T Dڂe#~c Ayk)pWq gq]{`nQhq4+3fJ>PT{ڮ!3ir-r|6b6n-M\̠C5)ÉP/"{$`$`E޶wATc| rשfKR R'| 滴< Rh]:S0쁟. ھ+%װM':KON,;%Fcy xBKqF0:qSF QK󹦵3b@ZOO g Js cf._keHDXO5FB,ڭ t-4Qf̊}XhmfZ2`B)>˻{2) /c.zW XX υ}/m*[/g|RZIkdƬUG Uokx'eþO@i"K v xiovPC5, [pd 12 DI+~!+™} *`77_K˯1XYgRckFK-~_[ZX2coħ݉&4?b]Ȃ^XvC- 5qGٱ}LՖ&oXbJU#ް,9KH`^m\zWdeKXLG*coTYu]mvwrZ Ȟ+Yg¯ p!O$$;e7U,O$`[z,We"w 3TbcI(t6͵A!(rŖ %9]7st{a{g+\ z9ݙ AwnoPċmL B@/dE(];v|"SoT#A!3t>@͒?fw S"Ζ>go!hst1KԦV79nke(g1 %[$ zn|1$>$xMi^M&\z6`.^L^Yߩ9 >-W=#r2O)8w=~N]d:3%` #IBisܸVp*$sZ\Z#. ̞|f|isUD<ꢡv CgKy:cON."IkyĆ!Ihʧbao,k6;%&$!!#+ÛXf.+l8,{KL7& BŦ(xyj*G "8{Y4kV HO$6*{ ^ Rj _6xml=3;-m""a ,$m #SJUX'D7H =AS: \D&X{ m;wiUs|/Iw4Li6p0st<"r3.soAʊp.vk) .G9Hp+^cyC,$6~3$Xo#z\p4[aD?`.̴-t%O 0WۃXDES 7k')TzLٔ9 4+19EnUk~L~Ma[BR d,bьUtyuр+;g0880^bi.dL<}p@gq)WI@?z(:XIMѢfc` iCr`"$3l@DZ)&\\(!.lyrRώy9hi#5Q,S߀4Fח>y)ţXah1ϰ^ߞԐ^ D)/~>gT:eQ *֏IX2, L,Oc_eG_d 9ofxzhv)&RQ;*J~˜(&Ԁ0y2)\m`F]4Ҥ]V?B W涂Pi 65c6dV&u"e%+m#5=A<{HsSsp\>?/;co:Š[w~|Z4UrY| [ cҫ;N<>~VB떀+VvQ=fXƆn5,lrdk`񿩠4OQ7."t^B@) Nb"sb ҕA@'l6\`a! O At($J]; Ox`|fI ?%*G6;kl8(R_-*Sw[yVG<(.݄Rmp#q^V" "c90⏳Y&s2y I,'JO*a/b $d$nТ\{HUIZџ<عIr.1Tk(C!z)Bw( kϔVr0]]}_d}@U:좩 pN3K>b9sPbK=k4wI| 0  {rGe|L f1B #ܦ:HFs$sJ#xV闲18i |hsnHWVuRD]PJd^>fK~4NZ3zwk_xTٱS~į7ȠsJe%##Vd.JΥ%]2hHqdq@;Là`Ⱥ8wk -OZ)=59lU 73n֔Du0F{OG~Cπ/ƺ?sŚΰx#X.Jg5_eX H PBՆEp+G ##'_A[Nd]]4WA9p#DgJ7)Xr࿲i`9}X}L<7'#w?V:C,~%"HoǏ$! #&OǸNْ!GbݼRF\]023y899G٠H)r*i\MPGX'Mxg58 `2"CܩY["ʚC}վ,;2[Q`kJ|=/Y!x fTQ.oK YzoK qQnXDTD&qo\V:uIJDI,&[n5j@~ Dp46spCsk'gsʱ}4_EQܸ͒ZY??7?\ٲm$.@^'|ODRtڱG*0Rdlp2ҚAiRhn7O ˊoG˛|"k~A}c95E/A.q`{ I)rt!]\&0{Pݳa]}w.Ax.MP]JPi-#J ^5ƱtW&cPG:P'm|ջWc(B+^<niPV:/PD:Ύ^`.t#|Z`=9e伻 =/%-z ݁aI3,9Cw7b`N ̍Dd_%ZYC"BxXÐ"erCi<_fչ 6l? XS#/*pluLZ+Ʈ:^|XA(\HW"[?cݨ![}@7t[ )@X C?Q50PP8syBVp35y@˄_ئaGap0Bpf,HƊ [ ]) 8m%pv!v$5AFq^EXط DHr>,k(*!@aN)6;K:8fawwPtl$G@+[j f=]/|LbS O㸴,vBoxO+P{a"Nkf~ 6'I#E)r4B}|#T*XX7u|ZtzL>uMD;ƛSJhe3Ҩ(+UT@-]1i&y { ={;"ucܸlOi 9r".QԖ7)q[ZcXDN91ZmƬӂcrЅ Jo~^[ؾu77s  C?!؇srTFx\~D!m:ѨYp{6[}M7)+CLGJ8zk|Jp iɘRRm6_MXQknFd1Nm&zqylQ)!OmORe@oƣTdW6)7hI[ޭеD)V,$(eH˱I=77"S`b L>9?-@yKe;G|B5`2懵s[Dj%K М9O)+ 2>2T ?aŏt$*3G-ϲ*&`!/\3`1x_v9@:3ʪK-8־ AZ:Im֭Xʼ妼\ZuU{E݋A.hXRn!xVlDg%Qɺum^8Jܡ( s~j)XqU.I4e;%!?I A7%_D4j!g<*mR'O\rڶ^K Zi#O=zusZR-9 Y{?P/rt19IM E+;ZW#f?hl|AJwfL+8%um/v4h?>,`}OԨSŝM­|E ےUF\q7z*vK){&ƪD.w=lc˓ 04#hC.IaK玓6V;TH5=ynGmn j)`kk+(HiRѨ^S P}}5-ŠFgcp{fk Ę:q4Ȝ<`jSWc%{s:h@ , Vwq쵚Y\UX֭]!Xnˆd-՜wp†4"wf++NHnU{*^4Ǿ(LH,}3jٵX{%xR.d~%f*NF>Np곟 W-]QQq |CjKp9̴V5e4 ŗ5'_Y-5}dMLDYQ?+XÌwfCnVtP&!'2_7H|ՄP>HϹ 7pTw 6HǜY3 :[}g $"N m]Ac9yZq, +԰6e2M{)$D4h٥o%.l\<dK0 ikpͺR&݅MwQ;{Ps+=+7Lf_OAub iwX urG@?YmVMԶE6jEFn؅xh{/*`f3w$pO2sҠ~\(κNdҲvy9 3azX7jG-+TԌ6 p3_x 0b**M^KE8&57ڰxjB[0 Ig0tv:<+ʇ !4Lm}oh&Z`r-o jCE 8td :[3"I:Lp|g:" @uQVG@շn.\y"q46H@۫Ʈd"LB~OOlOElokSNgxֲzI;V}֘ hZ؄+Cگf)$ Qo6.Qn% M$>q;KPĿbmi7m(Og`#S02HS=5;IXc%\}E]F^f; #^{]c((Gy?.g<. ɯ쑚 #ނI@#;ɁfD:zHIp& fvb"-ZȷowMymsDFSj f@F 2ر*]\A%ء} c2 h[,5bp7nu L O!Us2Jk7_9L[D1>Ol-Zn MC\x 3_% ]P|M]Mxn(S5@Rx"ȁHD6,o+F4JMX{ZEjB2M][*w<Lj]p0sudvle M}-Ǧz̀gI ilMPS. Ӄ9 b b ȓ߈d l&!GM W+x\e^X@OV){GphY] Z=D4=6D4 ɟ@r;1anz`3Z'lr23_PޱH1/M T݅f պZ-LjEGpZQcB' (/ X|h|X&t2SkY 8GLXn=lCK.clS/d욋$Y8TTwlEz`"KMȊ)SVp!Fh a[KV G[- &A1AgWIZ Aj[B|\9 yB64)(;m&0jw#ΡȰxF#qb<fYy6V:]EûnjcNER!SIEnނ+<ֺ᯾|/ Oe+ \t"pL3fP#K>(ǫH7WrMg0v^ߴ:/nʴ^;[s&GKwlϬbzk(`F!D{VcU.X)_s7R@??*-:R@6ʺo5,"$QͯTF؈rx q~-BM6L?=? 0gZBJ%H _ R_&W!];?-#Ƣ,r{A $o a:.kAEUUh7c ̞'ީ't=|| \GW#zHdrҞd4/" (Gj^Q+][+wMiUmȳc !X .򸲤 KU>3F$sM˺bwwFjj7"{ɕqELTR)ҙ$sY cGNIUyCżHqeހfa0 ؾJ < UnVR1Em"hv {9Α*p܉\ Ec:Aip e_M93c$gFw OZx 1t;;= .)qlֽe2=XMq5nJ7SmGPs_Ʌ@Ѕc=aNG$=,iM$^|Ge(6xa̳ WNnǍTO˨d H]y3<}V¨eLX@Vzf4ӃShyYM8<rA!;{ÎE9w}@2ˊ~`"zpEtϋ# 9Raw:v@Z+-e*aG$klaYVAɎVraLfMgnyb=!i4R|Jڽ߈=s3`Ц\ &ncoJpSYKLÂ^5rJ. 2%1X  V5^S}Ҹh!#6*h&r&@ uWgH c3!%'PuT=ky&#Zi< D2[\!lWچF]/Twc!b5\[ٸ* 'hBtyl,p5A@X5t&JjD?JR r~ke #+3!`@_X.\5uk P>g FΝ?>扠7zHYq>N'U<@TpZn@ <~ Qv+0畆 ȪΡ0V M܎SgXk7K$ 5) ,fպJeO[ ։/nQb; XaA^Ω4ڣ쑏]гIK8qi?o~&Ͻ)XS#QH nSg޾[>#VJ9QQ~lϑZT# 1G*-j09CYozK]XNhN:ei]'-D+?w.wtu`%0fC`5㮂} LQ3%DҖGNZX40񘹱 VXhV~]$Ww8x,,S#!g > 5ħLv9P+}=*Fju/7:<ēueqZǗ_[/a `_MRzuC`VlPl?:-{H80[i:&bFYSbhUu$qzТ]Uqp5OGAlPآr X&1>?lк0C]Ωڿ1lb:$T|OFKTe,(*j= -(9;;@1!{#__olNŲ/:جu&+u)"VZSeR/%<" <7fDH&~iFX>'X%)Vnt:Bm'MGg})'=s$yunH@R 7YIG˩/ʾTL%=]g{Ӑ\9e A@:s$*曇aP? $U4NxRyb%#W0=¹Εb|6 6lBGkOi+bSqd &*l#Oذi1 P;c_k+^`6RjjbRwJMׁ`Me5Լ,h$qx_]9WAY]9~O 26c[@NHHl6g/S*2WX=(getU7'Rnm?iCC0:%lmZIq=Ttvffؓ-u}Vݽ6O凣~9WD{o7F40+/|wecr%Y#&Q#MQ8NliG-XAHkݦ RfB9 mC)GE??A;ΡHѼ( &DK`K4-Z?yֶ/--ΥPz#!T:\"r0(c1(;Y芏 :IUg#t6b}QBPYga}>?MDͷ^mm^Œ'wW[aT9%bڵo*9h(L E .#8*7@g 9ǟ`?1lYx~idse"3KhLpݭH6 Loon)úulR6vނO@FfmWGsȶ}k412R;R^nSȳR~Zn%3bRtzBWV9w mtålVuWB#I7 vP4Qv!;׈ Z>0Cd,U;m 5aOBpKN,"f X%?O>{s"{/1|9k7E6Ghg Kym)7dQE\LKQ1pd6Ț֖-rKůlKNgxs鏁 Ni󆪩VT h9857(DķFs!|W %zh>E:.<-k9@Ԧݔf{>&_v(?KRZ K̆p3:s/GTA'Urtnz0-txy']?d 6L\> .2q& ptmb*KNDe kRJ?-/u4ynN* ڢHi˚FA8|.B0wgo6ޗa }y1'lѤv(BE:4BY~cfn;Nnɍ@SlNl%ӭn|$0͋S>dP!a.wfjpeor"v+y>9p$~D\c2-SbIÑ 4%R*I4] ݆ocbgF~b($9((K4SgOv4h=΍Pm|x7Ic)8G&UZ$t1?JD?3.֭YUp3]4/ %9iԐ3rTY}of41^mw]HV $t\onIX`k.s9W"diZOs3_B/ ySLi3dHE )hUU-z,ù/نr7m>H8Z#=ZiO5VǦw_~bCl!,%Pi\x2z;XC7[Ueۏ?_o>gX4ɹa4 y.믫|aaE|fm,Q}3χ?3G ]xf@yPDCemF+=jJ骑9Xx'~-yX朌*&>6;Hp%pF,e?h<#|]}jjCqQRIDj6H$@PrOO麱<Wȉ|NbN a*@#[CA,]FWQ *7k, 8f+eG,9&(> H^JJVy|ih[׏-/s旀S$`A_3:%krhu%QZk/AGP cffObRIhlw7{\WҘ{1*\"lB!'8[o`n_,}# +=;~r#06P1y ^Fm8ϤIΪ68V Ry_{dS3*0bv_X]Zܮ W- "Mo1ECdUYqVУkzz^3i wnvpCHl7&>=5:!iUMk)o}nL,Vz.͘g\ A:\ `G{fU* umW$IUKOz2oʶ8r(5_^\N>7eIj1$%5-i̿,뵘N?/I4+%lحnŊ @1[`kukl1l~lʼnFdñob݇<\ƱoS1alFJI~kʼ-sC;yUrSƢB*H^pؤ]fT%:$DfP*LG H/jb'a$Sfcǜ1$cThFQ[}N@L 2t;4,Oj5>PꇜI-|j]\skF:u a&鷜 Z,b٩NΞJ%BH{AkuEsꌪhgNJmM,6Z_PYf)h3=I`42~hޚc{"Ӟ*cicDrА^*׿yS:w Tă&efY>*)3Rs 56$kFyH{bd yjGrGhz[* 'WHuTa vuS0MikL S;")&Pz е- Lyn- r Q *ؐtNJUyJlhak FB&b|HCp)$ܑZ[̤7xUk;57 ~\䨀"4:Vݍ;TE`cvu2]O0W>HWALH~u7#^R(_DYw5͡Ȯ'%ܖZ}Vn1!vBo+ {]5o^ބeR5 +- 7V 6 7!4@ar2ο`;4<Ģ^N%.:F@朮o寥)96ʼn]|,~?e|Ce!? eTtP*ѥl qe$;Kv`3!ǞUK2,YakR8tLl^֤XLRy EV+Jˡaešz)Rd5 YsSUZ%6F5W[`Тoۀo[͊x\ݴ*^]0(eKA29Mq)uP`q|+ ' 9쀺 J{* (/EԬ%+PBa=@ >?~E 5dzRBN'LzQsp N&0lc?tGb~UDD˗b:AdG'f4p*hcb"RxMvm'q?\KtF^;wm0LuڕU;I#5ŞT}$W>/l ezDnA\J|qCd}c@cI1a^I VS[v4 5RiV - "TL3h[E0M=.6 XiSm6%y\ï'(;{QE1-{ 4mcoEk'nD Om[Aŷ˼To ]궩؊"OY )Ϝv|F\:EqS_O`q㶞]h}"qsP<EiΟ&3kA(1s8UFEJ o>vǧf]*R#0\^20DMuqGGBifJ84ܽ2mɑd)+T ]BszrKUҒ`Ub[*T-unv;U83:m6Ou"P,B̔w ~ OaCNIL:V [`NF}VGZUA"qnC9)˴n8=!ʹUUZ$`6pC:+?*|!:&NGUH|<ӢC(&aD ON~(Gc*OGOx&"btIq+[9l[E1m휶ѬT>tYհ'Lv4]1H~ȃQNsLaW lc*IV*dQA`ˆxw-LbAp-+tUF-̄J1O&|8D$c!HZ9+@ovg:(77>`<(H(ƒ-Npី$\U͠+r# Z,Zz膠,UCDG`''_YȔZ~:ڊKfp KU4j g9ATnshOtڜd|N;-vCg&fj/VzvK5IK<4\^^u2T&:X6sfUe[R~Ls}Ž p}U>`_6|I>) )E_&I+SE!zzGeSUo KF T ŌSM##mK:-mPG^ƎZ.6 Fgc0 q>q_^On17܋IO$R<a&n[WGVT^|5`/:% mvtI^_>b~=a2%r* i"& ?}Z#S l]WE\#\'W *~*{mbwko5J9HrW I " QnK7cJ# v+oga;xّ&M"6:yeBHԄɹbAЮkߏ4]r^w^[jGz2$`CZÎHpU Sz +A+yLH.ńKB>` TL;Bk0iƧ\uq1o?D68azFfgʉ?|40h,&]q{ȏ.w| .L5u'Y V_. oZW˱y; vG@g M0s׸dخ IW]d+*߶B^6TPFۼ8,_,]ik`JR,9b.??-ĥQP|Ow (iy;u1sP,PD!QѬ&?n=>o|kYwsHKiW 2{<:;?= hg=;Sވo@yĴ~3,U(v'N!$M`! { T Z1i}eEqXoZmRMpO|nYo9v T*b/ئ"q@A[#] 4(s!|MB#DqΤ7-,8OߡT\'zW觘u#,E)A#"A%R _á`(q^D^W, !A3=Qg$G:jtVi? @Q-1#,}%9Lvq *E~Ѳ[*/͈1g$'7$ mG[l~ۜ?tuK!!X⡦ub| j5V>@pu fq fBN{! GPDTTc2O0FHd&^-fc+€l b_t-Z*W'W&aIׯ>z.n3O6n)˴S [9;J Ed( M1Oe{u,6/|F+Q mw?&s\kϘLf֝\ν^KNB Zf}z)0e %{ gLWk LuT!i:El/ gO4pߕ~ª]Ե$c(Ya+@% `0YFy0?64,3a35smwũ#T.}V26҃UmHXOB<( *F(Pd 2_4uҤj7/sBU^mcxiڀ6hϑ[Ea8u3q|5%)RS K fˉRTg.vƄx/Jw>@ok<(h%I$V~%ilGgv)=؏wvH./2PPL0xic=E/`~TͧU@ށzp[8١*w6oA<ru-)z+[#l>u,6ӆS iKIu8Hnͅh :Iu0DLUjr`ǨJCҗ=$yYC؋6Gq wpq+C7v)x",u"@ Nb&,FzqS@ sbp(Ÿ|Y*! 7KX\WszrC/#u$\wK(_%h \P_$>׭pg%ދFV@*q_ǹsB]HF1bue1S)!}Aa">X'jxkj\CK R+*FGӫB[reSi1rBM?_%ǹL~V,hwQW f.!=,5b0*tI&Ù^]>p⟎4ă~ G=:JN̺+ I%?U7)$EuWb L,y ֜ˉaP>w@{FBnwĻiJmqeٴ8 N[Lʻ|R+ oV"n;ŜWoBT$.Q\zϟ7"2j(D4) dJ`S7ս5N:Ry4Ω}Rv8vl*ͭAmE'syV"%})X_=6'M2bM?gBF:1,xPגTDJlT&&6 y=Ȁ vj\Kb$*,#@wE1}eP"fQKxpx{Z_nD6 ~*-|4 ;Κ 3@9P\!h@JHB:G`y&~¤*c(B#+XT#[!L~=#=ާu2^V}-~f8!hK>"ъ8Zmս3-ԫSdv փzFy0 ?u(Y@ܶyI%b-̦/*46 g`KqDIG=Z̈lK'U~+%5*Pͣ.P)ЪE'$-qli?q5. (TISOZy#]ܾH>[^.,/۞-;{}+.KL}Tk+DgPak9ᛋOP:q^V/OZ0 Bi;^S#p9K ޯTiyߩ2Nȴ5؋=" 4):MkTfOzH IF R($%hG6`C<_YZ8Q_WҰ9rEF},$ 4/Ѧ r:sˇd$"Z#5v z@٪JĎMf:Is)H73Jz4&pҹ>?*PΩ;X{D ݩj5,'k-ۛC\#,F]fE#Vٵu mձEydZyh]Nl%$9=Q_] MĦ&*lq1]$.A BFɾ%2l75níqS-]CD]#[CN2q8Vt*0_OB_TV;VM&) Eδudne-S@L LaT%sbtxdaj׆&lm{З|zD%)g!^gͩl(:QdQA% 3L(@J?`-|nzMWm~oQZxG}WW{]8U'Fk 7̄-~ ,$ƾio3,^EbJ!={hvWz?c Kb G0e=2qt7V.%[`gǭ^+3 GJ JLfcܹ/r>W[z{)ɸDwW-ol]iލ%`҄kT<֕3DBoOc~\}[oٺ8jF7Y:7q' @zd 9aJ@d`c4.g@1$($RdʶWٝ8r,9AX ~y)ݑ%H_dCfvi㰽$6n"&wXjPsrqJӍA::#ըN?=v~UZ͗pmJ! oE3d蛹ei쇑PZFKWX-ą(fHFf+gxU1O1{騟5ُX]W>"˞OxHy}}cg)\/2#5ٸ˾M8ߟ~;#ϑ*.u=چ)beO$궋RFq n甂Jhd8ΔkךI)5`lS9 =H 99Q\q/v+ ~*71De~ N2Ko"}%"QФ߂Lܺ=28Yǹ{5G'hjky+XVL}o됮V*Z}= [٢.ū)/@;.K%Ϋ˿hMU;_dS4?R&-āFHij*gBw 3%ol"/.h|wmPGa@X_5zWPR=Q:c7$5h#|*BeVh0F`e<׳!Z {ιώU8VMAc! Q ;ݞ N7<.Z*:Is%uibp6у9I#S£<B{?;}FIm 6Nvj?)U ?5WixBKF]ZLp@K݅) q]Mf[;1g0bݨ0;oj=)8F&d~-=7xïYX`A;] wOIH۾I{=H231=}2VΧChKVEvi=e@WT=/ݎn~-Dw CU\ƞ»%/.Gv;Y3)1j]-g }Iҋ  =E{~^rB>P"T^?dϒ] ,-'9qJKd1o_}E]v^!{5ҨK(SA]? oz|Ӕ `ч2=Bm'ZXB)XQƂ v7lgn?VxyfI|Z|fyrqAno9?='SI%k^5䑸Ѯ7W-Țx%V} F7kGXX3?!ec`o传A\wk՜VD8◳k k~CB~fIۣzRxHV)w^ㆥkGh—6x6dAVC4JG ;},&X{<7{4 %xd4:H{Ot+/K;o5^ZO^@@Xu`y#jWV7Rm* c%:W}M%ky#p|J)uk Bg@ Β-w0C*C])CPa)]#[gnf4fN%8阊7Ȯ5e4nP[ $;CoBP:B=wɰ]B~({vD7ߪ)Y|#~q֠ݐiF |M sJqSn&@eKeICvjMt7߿U@^RkMӾl>i1Ovtc!kraaFGJVw~7Spқ_zrKH3Ƨp vtUBPh?N1Sůl*d-ɐlP}W6I- ŒD ܍qȱT"\Vѹ]LV ,kt6tLDD Ax*v#lzIs ~򓢺79Rgrvmܱgg(H )rQbthYl<˛)ஏk!x-6\6}MGg'5q(W4jJ\A-a*2Oi 0b{P^,BrC^ȕU[{Tؕ6 ;5T5!9!85x2#dȾsԊNY~y=(2!p> k+?g(22lWNzbg,t?ekI9 DŽ)Jhw U10b`-'0~(`v`;x[bʼnװm5=Fﶬw?9Ҝsy9I\õݓXSї7oXUdc . ηq_}FĪ'-8$QN^KfR "!-O[Sr.a ?߱w=YRՋBK_q+(CwQ!aT0'LG3kd1MF`:CtqyU,EfM%CQ!z INN_D x {2Pdg\lR=[DylWʾbvL@dj>~\~~`rKMvVw] 57J7Q(цVѯeB!<m+ biЇLT[b- *&=M^O)"U~XqEr)ZΩuQl/î^ R匩Y@n^&wb(߂[f{B˜e_a],i4InVTfՏ@=o'W6u!䢨1bLSy cdX-TXwh|%F4GiWǽdn2bzS5v_t/<2QS ;H~͑)4ޜWS2?iۍ{1KO >uhxo6L栣/z"j42aI<ב>G4DVŸF2(XIGb}R"%J zs)6inCQV ^/ GcOkc$\o!xWa c>Z)gݜ9kjKN~DݪS6ZosP{2Rٹ ۻH-Ƶҧk wg~P7_4e0wL`¯ߚ4S9p`bDдI;qwzccQ^>MD?AYwSXf񃜿a@5g?!pA,;%d-AZEmqZZ,w*"!+p6e.2n탺D75Fx2Z^_2h= (2JN'ceg9ib7lf5Aoł2wD+?&q*&fr׺{LV Bdvh|"@\ si{@gB-DrRrN> -DWHeTt^r-x4& yT#DuT-Dyu" sMV/rˌzzN3?8H:>(IW\b5,3C$eS3IH-&;}i@<,3/us} _ _ؿ*-gvSIBԆȋPI6p`>` ,R4stG&f=^1._e:Wz_E{l|آ/MRp@GjB)6[ :N2Ydc{>+dVf}⚙Zڌ,XV9jxo矒,XF(*jEK Sުd` ]yZ*Ü3/?ReQ,zAqF{82O_9˃/9^8 X=]E@O[W`J-3chvB=¿fXU7Cql^:ދQ& s9W( bb^{}¾XN;:PaNtr&70QlVYWB tHd%[Η!XWjj2-, Gh(R5.ɸVFUe>z6a)e`=0 w_ p?͟FbǑt.a[\6o+&[.QoBy)Ҩ[ip>4@U83JL'NN |a+ަ"rY!􎇌u*U1rGl ֯e2=}|@X_\% n?TgAɏ+Ik꡵1RK>iZ;1cXQ XLɚBѳpb\$;wOK PLJ1BlBxu~Du/MW9Ec9_MKiަQ?x3B<>Ͱu*K[B͔|Ƿn+2"+,?3 gOl~t"0xɾ:Q=|Iǘ)ê΂)ژ2&;a9yt:ٯ9; xnyJzbQüh%QI\Dt,IJ:|8ܕU.$`H(Lf\kZpmt'Iڅ׫-RyA&OZ9GP\nlɕל)=ZF?cS-JΏs$dQ^G48HkٛywqVi+T]+ى*XK8䝼U@7\  UBndF\fb%"V_FSN15YsƐաd̯WF5Id`MfS;:ĝPhp(w~TL`ˡB1l?x5+0Ԟ>Lzg 9_LWԘ9hÀN͠X$k;LwS`=YWe%={(JmM/i cORHqs6Ku i@,1)0`Qpcȁ,pkӅAq|.JןK[#Nej JYǥ1zҲl"0[D(ʭZ ϝŷͲRUw)#(0*MerN ϙ|FRzt'WO*R^}:uy<,y"7m;Ev NUݚUJt1u3,i"}"{kt-[~v9zuBk,>UOuM|RtTXg>4v.J~Oo;wd6C:zvfc#.!*O?ωF21uIzXچ#&%8-?مͭV dX`Į]7mġCÊgƸs"9dG!MG11F5 V?A^`|e?X6R9]s7;)푫^ wy"`qaP+a4-Zt)}^:ь6YJ||U&u9c;&#)MftB:zbUtMi9LⸯͶb3#O'(oIhq<B-Ħo2*;C[_%5]Du*Wtk,Aը^RжV:޶\)UDl3KXl9 RCùNXU}Wb.oؼ*G= [jnG_a6Ul͕z7lZ :UKz-h7tue٩Fc`Cy M`weǡsD׆3<\}#>YfGyʅ\:UNiU$ر?za ĥsG6pH*uN}T+gR=">.70 VN ePEj dwɣp0kʸx!Ql}^,돐1s.d-(4 i.u'/SbPP\FYcKQoYe W9e¼~VŲr_1:(anOfr}5̧ Plsn(H'*8S|TU }⳪h0aKkU&;bsNzȗ,i7L^9KUtNj!i0Tk\65Qtor$q{%}m JBtՕ̥-#q,dG Gy>Bmdy&ɺ~pzcBZ7l5!+C1[A1*M dߏ4j0SJY],~Bi=&!|#I QPˡh<[ 2ߚ)i-,M|G?\ v\:LGig{:7 >s&w!8L&Ec6_cg9>#upOu2}0O.PV1 q''Ύ1ّnη-kj.@I2+$8.멙0EJAQ\V Tr !a]GFfiE |5D4s(e>:Q8j7؜7lW`wɑ Symh݌bjݗA$#XU٥h2~ <';#^5WG(wfb3s~8ϐlJutb6[I 2D*jJ14Gu3 %bC5SB`ɰ$Ƕ=a!0]eqʌJQ=O_"ulb̾ VGh8," hı= JM(YƦfs8\&qmjL^bm샴h;5_b\''h~;'A\N)xo[9g+2=(tF?-v% B^zJMW:`U[ڬK{" ?YSCNWAoHZj+*Xv Tp¼w%|KAW~^9?Z>ךW|sLz>bVC/G^WwCB%Ebv2غ"Ӡ+D]9!ZðFsh^s!S_E*;^6SD$R: Y'78M^FVSK\p-kDgaӒz2D:dn$KCTj2*g*wz8O4JQ~)..>qsOkݍOs%,|"KκeV 4m.x/r:&-9a~w/i2]9o*uyd#ѩ2ב Ϲr2#.nOTǟ{>yӕm x/Zb>y{|@^SB~u:L2b{x`N_V>TN)fe:Hjm%Dz7Pøz S3@\F=Ujѹtof߶ ܦɨ;@I(hLI1"? \mV썂. kJ҃š*}R{i:Vu-sR`)LsɥDq}%N?m1fhЌ )~^~f=K,B;{TTͷ3?'{1 =zH8 EI@d8) 5xv WIwĐs$~{Q mC_%q?C`|Pyqqtom;;unSv`<9ђ^73HSᶘ,8V5v(Ȯē{OvL8}DGwF'G՞S~KLU\KC>zl1Bk2cnW{3a/wq'TZҕq,FG \2_^Qo$Z>5^p'̋&Ü k"Y6z%頱;8qPnȫf]%Wk_~&DJ@ϓ}}cIΫ^x;yyn1#F@`23ڹ}B"97YR ,vbň(WۂAZ&ϞS:!&U T>=SF@R^$1T>Ʃ#0CKQ+E,OaĬh`!IiV BO@5rGzL'{ ^SQS{3ڿk|bFgV ~$b Q ~s\ͤ0a~`m[pȢVL+(KUܼ†] q"/?4_+sY7M6AUU\6| \žPᶴ+8^ϫ-HS. aϧdgŹd/(4kEv5@.@Jrūz{"%XJ9\u^i#ulC+ y}dc}r ;PkUP*N PگAwnh3hg}$$`?HԜ0_$PCUUȤ5irU@aQ/zqʐ^L4l)}_f1|{9E86l4" 9: '"ptmC7qCDן(i>Q9Ad`H` ֛7]sunpJyyJd#KP&kDHч/W؇O`<(Yzۤ"ftGJ ocʟ/ J +|N% dH7务RTzP4ƒЕ2Yy6*ns^"/L8s`P#x)#gɾ{(k څ   3g-BQC7W>;Ct֠߁`$W#(=P+,| y݋F 'H yCdLmA@WUv>Z0(u>?خx~iRv7(9Xw-$:6 EUҫ')LV56"׷XZp.L ,qh-(N) "5]i@->y&cG:Z6ސVMX] >}J!Kםl{f%a2[QH]k3M#yv+ҮƂ d\7ꦐhǤŸk0ZVx]B #[wrաef[|q_HQ-87@w(q^3sұ-DD>w7|]cȄ=}k$ jx4 ZG;A_iO8e!xu!e#RH ^O\A=y$8 8_I}IQDX5 =u{|7u 4ی+u;C\AM?^+=C}7W3Zr5/͟}xb{6]D׵NӍF"؟ %!ͦ>m~ϭ5m.~'0`ɒ>" 'c=Wou]苚70 g3<7nXkR/*2XXF?a,UXh*ǁ%5Geme A6D[<:q󶴖1N~Sչ$5o*z,ՓL] vZah>n[yM6HnIs.u&6'tCx٬ A|5.׶qq0MCDnwGbWsMC8|K#l {GG‹|lj 3_ 1C}LSH*f[jH*QeI6@LoC'VRo:J~ګeP4:W#vzL3PA_dQs iC3LaPMh41$K/ԹIkL"VMD;ne\E@o^ɯ5J@ l`&U>izYeZ!cZa){u hڵlLoD8TlaC1$ų0Z;ʣ f⩫FmpEС _SҵԻ,%Pc :p|܊CBȐ]}`X} .zgEsىKqtESZ#LB8z~5tME2+Nz肴Oҥiۗʎsm['z#vDčp Le-avIґ0os,Jxzت:Vq6}f^b&ה_C;('9K\TZ06m9["o$st(]JBmBB ?4W^ͪ˩8Jt1ip6t*%] Q -:xkScļ;Qx='3Pwkn)R6IJ6,i~]aYL[g,?Arv$^mÿa|4T L36. joՃYh^4@f" n](m>U.]&!t E?kC,cFsM1PvYدe3Ң_C7[?vob0clٷ83cd˷qޭ^7mkeWO;iļoCH YmybC70ZRs0JXCVCkEDZ2;^n}hxByZ;UvE=s68L]CI(p)(1e"3ozcA!rc0 ܄vXyڶ 5d?אFjdm)3 $wYdP_(g*2.NaK.ՃGU p4{[g $=86e ;W0cv"1R u@Cu NW|2EhHho0dO'=F@8|.ۇ|A4SmUTpTU 1 mkrר}&]zsz;'C·/sΆ.oL֡ *r pQL\Ex-fi319g} m; ~9m8~]HyWV=t+K9Kd"z,ZJrpReȊp" PT*LIrۢV# |h`g\@G8=N33K$\iJi]#̛@>i) iom~ ؝z$GAgcdٳgʉ޶hi/n'[,+ww8ei/{?HtAM"~-80;tq@5ֲiQ|BX쉇4B'CY Ǘw 8 m?׊K&rJVVe YK*x9V 3W:-OD ciZyeݗ&9q]_BjI/KW,9Yv0'des`e,է_R-f1mJ.rѹeۈ5nОISƚo-zi7{S |q?Ahe~sA _ޟΓӁ[-O (!m!"%jv+^a:x) |.+gA.sLFߟo3cZJA3 z;hw+| MyvRf .Nʔ^ 2 &tH&af#RU!VPvmKr{&ߢFYaYDSzg"=[ 녝G@.M$\e;Ϯ'=_Gҏ+<4@[ot߽[2`*-Z:ئuND-C#@0,CAɑd 7I߱Z5\@FgK!vhm ;uM[\շVt%`P[@obfkAj? cHYVk_lUwH8zXɯ_ x6D{ K׉WN/ؑATIvD?,D8+Xe=QNͬas\U^==S$FCrcz&GNXZHrɝZN2 _΂M{Ja]~W2E pJ+mя,5S! ͿpqW>Q0ϴq6 ,%(͓E--5! ;3*FPdNI^[8IS$&4?Aa6?kDԫCa1x1^å 6W߳QC n\;Tg9Q\Eѝ5)PEdr7iK>yMmADkA0޺΢Ipϣ]&y'k Yovҹ1j\\KT* +b8<-zd+ag>ULwL?3Sܵ"O"o ^fJ8lځ/e5m;tʑlF3mK4Or-1;n2X Vܜ.1Lye|Y"c\^&[h"g& 9PT[h7J\ c< pMa}Ό!?э޶JuKOR0ճcUQ'0S,"QQ!)qu?LMX33vトg?O]lRB:K(j~f1CUt92 0@E9o;[p_jf\Z풙0_}Z'Gb`ުermy-}"ԨYtrOy&0 C8KSn}pw.d;KڬiS o b{y:&勄_@ds-i%#M?4_4: { FgL*'7GPlMb?wLkP(8Vlq4ZY7;&iEq3gk*JnÄ g&)UY(d[6Zv^ +ًqXZc Twdw;nD L&yDjC]Gp4z9JL3ktP8M~ԍr,juhԞSsTd#k.9* pYP Kԙ5/U?1 -i )jZ,Ixم: F.&eOeÜǨ;Ag`C4OVV PRJ#H8P>#YHes JG&u2xEt*bEknn>O"$cp֡q.<6t0?@='u}03]vmI_9ؓQm?-Nbƒb(?=ג{\ݲkߺmϒ,9fS9l*U-lssRns]$4󲛗i20BjOR%eT%`2! $+ihepщ;Üpb/,Քґ=i&.I{vDeVJC0VXiBТ֖ʟ^>iԇ$8V a9t+lBZ5`ŨEkE 33*< EOϞ!䜚4@m-6 5~򞾞lb/%&2Uw6zٛ8Pd5'c>f XJ~߷"x*ӡAі . cfnìs9>\'!ї9+Co{.<_#g _ -mJC/%kpH D %n9[-^.k|[G喏OhmwB:u|' e8Nf6⫌] =7}R"aAwǑk9ԋto[Q~Of˧[OKƂB˄"(rNl>EBgRLh.'T(rk64D V qi}ϰ$n ,)C $8ғe={bMYD 87j)slf+(Q`fYB+]HLJ@F7yN+4_ B<'M`Wl%ekk[HEBl~_D@*mG q}`+H!Ζ.w鱗dv{ k8BJ ?fݷ_>הL?sx_Dg22`r9XM nv6ye>B[T3w-LcYM-v$f2GwxfTwVH>\=|SQ,#;4h?S 친vTPS$7$dRbHw[WW]^&ю-bqqPej@)˰& Q%cG2>G޿şc^Hm#t|cVCt)h׸M@_*J4ܽJb.D~q{&Cݼ8hKmT5 qOdF40ҁ 4\d4)>2y09%X)yqu߽_Qw=({0%6־xxBx/Gs? IqBXtX~?Dyx `g!ez!IbUDO'=T4堉z̆'>]Q PB9Qf1 ,{Up˪%|k 괒`xf]{kEfVߗ(I!{#mBS=xtVᦺr4|VUd1IB9$4R5?*m*V` :ʪR$b  G(δ-mHn~:~.0O+MXe: PYHݩ3g>z+-`uuߺ3?/zbXfrR[LO8E+ifM6S $07*cRuQ5>fQ(*su"l|'0u\Ú|=%$ 0%yDd5'[`O8#SZ0wf'Q6܀(+\ u:ioPBr:ErQ'x&^4;?wPI>Y@)_2q{>#YT_!b:TrƳv?W$河w>{ Nm11g\C P0|8IOB;mBb{KL^R_=PCdx r'JIpm!gPyS}C.M)ǷNVGP(/[yMk)@!Pcv4AKth1(qQĮJYN8'U&NL7cL GZ#c8." B;iMN|DP@= [0-rr~rmLdGI!=5n6VKqf Eg &{HGk þQ`5c`CVwIFK+ $Os:8tI؉5nҼf GTd`+E)0G_>=Mc"N:Q8dc'EnL)=T80vCUbasvw+ );w$4ޫO9V5#KR*Ģ[@ҜbY8ֺ:@wPՙՒK2 ^YC`,w]%AtR9~t'V>LLj4$I^Vzz'˰~Qslټ0o1z7E`/! O6z\BlZ"Ǐ4_{Й>gW+(KQ,dsoQΟ!v5zuH1vIax[T܎W^hDwrϬB{TWPtĬ{ z ܗE_n?AmCIcS)c 7D$(zv""!$ hʊy/E1 YFbp{vDmcHNa.{S!&9?OZ[k-Gŀ@9q^%q'zhW  7Ơn9ULB+, cj@eFЅ\Ż󷋴~*q!l"+gbZN (ԑj ^u,ѮQop0ȃ$9rfVDd:"S.c6ぶў x@ WXAD̈{3l9MfLEH"AȼYa|!Ւ.K-`'J&V<K.0o 4 5mC([~^RqNtDV]dn~yjYkܿ;L'0j,-Nz"%ըO1.Jr(&4noug8.QUrwcw{,'ǫtIK(h~:C-3L{@ RQ'7Tw,R|Eb#g4r\'VSsrAO!;-]\жA-)GpõCmCCDN oytfjeX, c;]_ܽrt4aֆJPhyw~s 14VrKl?~gEVrH;+BM ڠTLِ-!0ZW ҌOtrw7&mp/.~UzRVd+6}_| P0qi(Pݚ(^o$[BeTjuqRAvJDZ(=a;°+|?*f {T@AkE[H!MS8R!zu "PaWTS\DarEPΙ{K\f=7?w#\h(f!Fھs\,ҠSKƟJXQ`Dj@ H%BgM2=q⻗g^ѐ9S ?hHzp_L[a y[:B ۝vQZmFo#峽O1I W$"MR/,oF .'Ơd [yj`y9)|?ҩHX?AceU˙^>ȟ}f;-Zv5KzTtQzѳ=:0#U)i)&8'|*֢mF"(z{kcp4Hvh8;*pvNVV>/q*j$+;Ozw++Is#ݽɈlE8pݟ{(piԧG(y@=:yBm-s"/فyI70gI?22:u">cSz(}?7g&k_Eү!lȲ#ߕ{O`7Ա\DZg%>tyKljʷϳEZog5{&CEG3%k9F$sYsORͲi]s*$0 r\BٕtRM8x"VC@Ky~$vZ-AZCK8jƁ ãԋ DHKO3@N0X`͆m% \1m!IJ&ʶ48[X`n8VC{hlMZ\.ѽ Phիk#T]IjW':_p1q. #ne=;yAwIcÕ۠Hst9H{Iy𒅆<`@X`,-w7PJ! jۖl/b nu?_EAdz.5ˢ|,lY@RY>϶8ٹ:G1+b;fmF-vA~SPEq2\ 'OSXw`nI}9t$^X1PV@ݨ<&Y|k6V7uڷpQ#ev9| cW~uMWeZiwW7-eQO\t#z{`2xw]7$/ l4肹m]4OQ#yC[І@W;t[FK:jO `v`($<&F:ȴ;հ"\<b i2o єI"LЧ]Hxɐ,>Yi;^ T5u ?1` 14̒Eë2ކ0*JwXb؇axfGΗI U?5Y ~ \Q[8u7H D( 8١=Pm){ƑU,h^?f[Z4{OS{Bx]aI&D9ʙ#s֟Ee)K* {?) WIze:_J~0#G4s)TgQҺP"Oh|x8c\[ǏVsGb^R$5wW(sU3M]Bf,$"g]G-ep+UH%ԍ}+;|Z8;X |3A 3a YAӖ7|er,]_u1_* FSʰۧy^]/(eqX4y dO Z0b@aM~Nډ52c"NUĔnYS1{[겉ЀR'X$-;-Y&D v*Hsc7iLh},TC=~.ް ;΄r7R 0E8M )a%|F92q&rXrLO(wn|\" <&E7UBeJO x>6I %4LQp :Uk0SvD1l)kܽ儼^N4e8e%{$#ՙɱЖbݨN87_!YӻZn5OG",*R8 LV=doT+R]9LAegJ%JC#miucQ.F7:롳A3MWT]~Bm!:xFw:}c6zCSG#`pC Twz {tcQ2iLN^ŦkfNgEyIp9WZptɭN«L9 MӋS7~Y Oeey: s:+)h{ %`D_8x/p.wNhJ؜LzXLW"f9O4 fB!t+s܄[49ҠW9s'3MQ_ܤ`Xc`CFZ&xnS~Tꌮ걿X:Ro62{f!{z6APt̖eܜ 5o cI9#),Uu#f- g6xWlUhW3]{V:TI9̄Ywl"7#Xuq8YOܭ1MDw}=oDe8 wS>&%]h6DW|yjt^.ri>/e2O޻<k9Nۇ1gX7'8VRDDR,`XY`W_p-K@f k^QXbOѶ8b"Q2B٠ȋ(" j>?Qv+g>68{X7+ПD/e94%߉sج5N$IHmV `yD܍:.܊JQcglE@g{^ȍ\zS{} %–DY{H!RgL];=Tv|~śŕ0神ٜM+6]v\ʥ "8:rU {(1(3N}[`'W6""2Fk*B>*2_:a0b3:Z0#zO۹^6BS)|!aʡNwv{rq̗Gm2i߫<yW zOO:%7AdM7k򞣖-I )y,V&|W_$t (_,]wNq|lQ#w1iˀ+ֆe2#x(Y`{> =fi i%2B<~_%$^RH<o'Bz5*@<}@!Zp\.f1fzlhKp[D]ȟPX4h:4Pvs5?`ӳ5oM!6:7K"^y$LlЙ;tɦ8#eHpJ]D vP"7܁>a|0{Qh _khA@$DIRiot4, ƛ.BjJްNy~0JAFqlIJ=)0&r,AEKY[akYec.^ aP|-ZF&"K s-Ɋ:ƶn&T'yʼ&x0Z% "g4BO!OCIS'ADX+hd8e-qT`}6b`=+sRGu;)I UPQ~,#9Д+n*F&$goa"Q#|g!I(@3N^o8?7bhTc87˒r qΤPm;dlvseU|)lb+#Ez|_/^6Up`FpѰyGP%v2w 9](A($G$Q)O9`nYq<Řշ_3T{::ϊ%=n@Hd_2w i<5-m8}3^V@A7f8D'Aa0 >^yHJSq^`7\`O{q{|voxZ.8*ty]v8Js|#Rrrk}(i/D#SV)]b ^<>uxb4,G~c-CAmF&2p&z8&r Uq+ĻeTn=AGy[cLe3i*>NO|,,l%ϱٶJ{N-VR}IzVv-dKlrk<'ofGqxEwx^ fGb!ph4m+KkiC{^H@'] (:ļ6+?j/ dܔBWZVTe- U@d"H\8cIW'2pp܈&xiSnB JRd'Z@ ap͖źߟ ΁ڰMyh2O!jOGB3ixbfWn)nSZ"Y!.LmnN ?^H9Ϊn] $zYEƏhNI,\A}_Zq*3=s=8/ zWT>I(]5Rĸ u^ w'D`EZi²G7RVQH7i]_ ˽֋CK ʪװ@hwBA\?0RULjz^i$С1Q5sQ#\9Ӵk%yžTt` >üy9gf>H ~Pc>ANdE%4C3{' $K(sn]tN֥?%'>~^7M&C"ni1tHs)|)ı  GAzG("!ŁncD^L|_Iq,3qH/]W!g*u Xb_./ 'UqP]U5Q*(n+*?±h^0))\?Сc@[ʘ*V '_XUfDɵ^YTKLU 0עh01/]qW$?+))~P/p*船z~HP >JuQ cG?؄w m2A@Wq>% \A03;6 ?ORR*9!= Ig'bc^ ]HX"),B݃7)̢3UbJe,25x,r>#|4&WwCǴ՞ ]Ԙ_;9fҵ tn]%3  ^vB3@xH 6-L ``Ry̜G~IN/Rޙ2=U-c0s=oG.N_<ۧPnI?Lk})E[mj C^YFY ƿ=&N6gOqAU<ɉvTB:A:i-ܨ=%:?W Qz.d.F2AR3Щek Q!%+j Dukm5Fg^8t7)Ĥ?&#tL[^8^.2/{[v60wF8d%B%D yp\P @˧R^7#氋# ]61%0,\Qr=v3x@ΌO2y/ݨfLC[ṭUebM9<ߠqjYÔ hcLϼ'rdowAq=XTeYxRĐhخp1x$aRr'HdSwg㬘$>z9^+HSyET(xn@VwT+/CqmuG լ7٢f׍PQ$8^?m TS ֭|u@ .>#lQޥCJes] ucJ_yd񋢂tf„⚜:c֐_TϚ.aΣEuMn !Emی"ag@Śtj}&^ǔ8)bvsU]^^Oɞu~RߞOpG$Ƈ=4]D0|CDIz!9 H;WEګ6ZUT Nv|R s :oz A16n\GcO&GXO&@l:-x]ɋ>&,؇d+3 &/=ycMѮ[cۼ~BqʙR &BX;XW,m7wnН~O6nLE[v;l-4tVW>; mЬ+v騽Y{Ty/Uӿ?*tDV}XaN륶W?b0W-G /=abGߔiqьwTG MFӞI-Tkdku.(CLNd\5iySL,RJH>7#RnNHj f/"3\8hY̳15|ǰ3Ɇy=`Pl:Q%;gwhyJS4!7$][YT!5\ FB&]pZNx*=5bW(]kLۈ|ڏ red\1)*T,pp~嚟b%Z1b')W-U Kh2G(Ӿ-0XX;v3=A ]߼FBu/0k*>mLcR2Q.D @B' &ۑ_û7$9\W^yFk" uQ=MF{B 5Yʠjo8 { s>qsVu@3 񊹙7Rb+ ٱegIχw]oiO7w\(MIpz+@M M+XO6Cq)^Z2ߣҷn y~K6,C_0CT< f.i/]h;489.xʜM SPI_3? b͚Us.ьI!;+XA ڨ=0>Ⱥ9LĒ e֫6D *zvq8*YGϱo/`8"C״nX[W@-Z aBJz`ss5DܿޘHN[oȋ܍(g3^ k7{*eyZ'hq9Ww f[57q"`x.:sB 7( s i KXty+D|E~hWT[Lǜ%@}S f@hVT10gW_PQT՞-ćoITc?rY{uǗDiSOr9 +w{iI Ȳ7.<֝6k'Z]Ad '}'v ak9Y K5o2ۤB}T6LL5P? Q,DtSK,=mN[ ɷOBꔌ^@mNO]SbqQh>tbniq20ΫS'ž Р qTmqXmFޥxK{iv웸33Pf5%TP،ZP䌁|Nv5Ce2wCkE^{O-+RPaN8?%'*U縁P? O`*<&Aܭ"%=0W"vض:C I-Fe(N}fğ^(`_;>DjhݐsL#FNCTwt ;BZ؏U6/*۷dntXKyͼQĂ:KJRyhPx_l|hF?ѧ;:UHko !᷂/he%qN#pMJҭn?W:W-/(f{ҟ)7/K_sܶ#y ㉣S/'ю4ioy/ĥJ{sicD!nOaկ~2v~| W,V҆ǥFfӒ{S eT ކ#@fB ُFֿ`Z6airTh7.[׊8|f/ZYhiA_gF q*:<+Δ?2DQጾ>ҊWQ5{r2 ^\":sЅc(T DrHF^ޚ|>+F>q TS1 =yE"Ny5~2&$tp6XD;.!7FasSWI*AEnDmalZX:ޮ#ߖ9 gٮJ3V})NN%gk,]CT5L9"&s t}w0~ȅw|ŌǃY}]Q 2ury0 A!RhT'8>pbyPWyϼTu~{* (_%A$G-Rml33D-Wq߬%lW\BS5ɋf~™BYUj,g@u7?uv.4'swa h9QfXtz(TYSԁn= px`3eNʘqz?JE֌vW:@c 70+=u :S1\M|μcT'*9Ѝ'a/ "9ԊK>Z. ?\Z'V +R{&*׭Q&vY1WN|" r ).u6F3Jԭ(sʶR2UqR1]j#_,?B_pܮ8~bRjԥ'dEޒ_ mYzޅVXu V/T+olD76BK5v|TE"F pty[ 85|xw sdf (D # A9Vfg %u8"2²BLa,M#&%9ʎcQ(zNX\nCkJ"> Nt@:9oW+(EOr+dk傰Ҭ\ a4b֮0obY$D!$Lr ÍYYzW~/(Tn=0e0[AqғNf$j7 Hg7l46nc:89Lm*)~ [wgAD!>j]u'6u 3[H`wfd6D[ѥ:d{d4EOj jhltY{+3vtKrBƤS7A;:b+!PeL$Z@쿃vb";B?Q@WFpvZɃ%Dew4OWe:%L5V#sp__o@6GFO ]Km: >ܰZq Uh;+:zɸh]݅AY7%\ib[:f/UkdkUroǼo{ɨ WMaRxʂVhX16Wcu$wP}5! ;,,W1X_?T~Gx+Zoզl%h TtDL`=Bx{K /ظr40Z[ ccFUd%iO7y?*eɟ^DQ,(ڨ1{F}*k3uu*+WrN**%9˚lh'ƋxGAJ)%Cr6uawk蹓Ȏi<A{J:DqUqek򗳴~` >e7p.rj)i.7P[\;6KJ70/l :!w B@f 2 Ay)='y?/H *zn)zhUR#XOܦ"/) Im %𺘶 MgnIPX%Uy Wzrr \ڻMkY]XbsaD?r5Ky$iCi~ڦx3q ;a+DAH "gj-_ Yrr?Ko̳s@qly&p 6DR@r'1/jqt J*364]O+JQO.4SGo3CN a-]įW띚ZOhv|N7=D[Ab0^YlzZl =)"g>1e 8e~3C\J|Op[/:=%XVH~M~&=2g$y$| }~N"5t9.ö մ 9ԓq2G (Q {ߩn dLD"Y},jê$ ԈT)Dؾb=Gj'~__ Zi"2ȚJn >0B.:xUH*rO$b;ϵ ;0I?ūck4dfD,'WRj:퉈dmPY4/Ō-J+yg =fM i,èFC[+'4^Ƹv r^EA'I]G^$ȅ3 A+w! OBF12Sih8no+=fCBNBsyܾ&m&r䂽1 eA'I@N C233CS5bwSc3ɉY> 4 !ds.׺r(ڄB[/-GpI'̩[]]R%!?c a\LKvV 7%T*Ԕj.9wV-؀Mo(Ũzc1$>ퟁIs}͙E +ҎF $@!B!NcF6sƵ5SSBf1Խ~`۷z.P¶<ȇw0 sn9 &J J>nkNAA : `aH6q7 %;2BnΌ]3?Mȫ&va FqSe$}cY'~8o KXDd{ί{5\x<BͶ\ 0&w7P ]4~uzp50[VZ;%ox|ΖBl/܇Qr>[ݾ?/cZX<+A -4B4ty`S1v00>fP (+C <C?:o)ݎ +Ļ< vG)>$n vX3W0.QhXh >[!e)0cwn]N_ };?0͙KH,yt+ j 0O;̨FP0qhvHln2mtxv .q6/wV dqIFR ==2g :8n;VoS!f͙b Q)>q%߸6Ia \c~%3%@2ĹXx͈ڣ8q42u}@o]hNL耄 ҡD"~0@07~ÄW(bdTMN6M;,W4~æ,Vq"|Ѧ=ћK.*뀬HzP;L)<,N3P]$DIp-$|kouޜq\{KܓMCCB 79>X ?:?ئ:O,*Yt#z ]A@-:?tʯIy|J+Gzۍo mtc~,VUfO~f՝s~ 90E^G" $z"ps @{=7Eܔ08Sg7;u2(P-Pև{.77] !aVzY| @+V k0IHW8L5_ӭ݉ҿ){AA1B{~wwֹS0jXA7q}ۥo nU`D^@p# ("ƕ~(|.N+@Ǻu,8y>8^Y0NI\g|ʾ. ;&\ ? -%Fmax¯џU6PX]eA`~a}fBɄE!'ĥ%՞0ͧňMieZdOuJ83OJ vLr {Ky-ҘYhsjC|O$Pi˥J+eF_FٽcOS+՚JQb]'L)x>Ij1])n-8Wjܲʒ4V>P'mlVs+fJ\v5*^YZ(:wi/`X(N94q2Tdvw-͗3Ol *p_&gDw*\,A:IȲL0MzY&D2'5P%S!'bq3ִ!gƕWeϲfJu] ж]gOj t[?n[qk@`(̈́W00q(*O`Œb!iїK#pYGu#]N#F5;UOK#4A; xGDm>c2b\՟j>h_E@DВN5bz[,:uNſ*IG~ 8Moc-h RS#F%w9> !4c ow"ޕez הD5"q+޾pRMnb\z3&++=*&ỉw"Q <.^Y;4a.ywo2Jݐ]!qy!CНa+;sARNE"9 ^2YB\:q2PNb[XMF 7n(&W[ >ҧ&tH,ݚ&׊Aj@\7N+zN]f'l/ZV$2*Xw yDQZJ7b rN mp_~ a  `L@ Pd>e-CaʀpGk^C1`Bs5g;Eh[<Ɖ80rh&p(ADQGDZLo<^~x,]@ZŻx,e/|ʂwP =+kg5Dgi(S>+bL6)WG5Lts~B1 @_cƊ4d:gF?л Y KC7A,<Ml ]͏X.AJmU~G˖Zkw F6!* W 0^~ydIl/)Iwga{c=X1MsWI|SVyЮ#qA &B[*Jf'k:3JvGxMÊ(͔5T%ȿG'̿E&]v$Aܒք y_nJWH%KRvՈMnO`R'&4A-P֐_p bt35a44!(hR~2L@[dB.oT[b$߄ T?;%F`%X#hqz|"I4*X`>vf}ã/2ȆI#fš*r fiGf_e,[viƭ$Ȳc*)a+jeϝzf YĮdBJ?fq\`<@,nv=#H>@u`OAhڠC׏>)i+RmqulCUL_s4> Crhd@KX=VOq8<*֨9*>` xSA_ pL$xꝈh'db%1, *aRCv;%I:l!Ȼ3`SIਆ#јUxnRQc8IAo`)! SA<ܒTڀv3'd=0 ʸԂ׃SrH2 uxwں`;S$F APJtUV>Em~>*}aǟ 2crsz^ `אK(5o2{A9ipFM@!!g J13Eq7$4@%tȴB=y5 > Prޭ.c!XL$YPV.8 7eTp5uL^D]+Eg*:FʦRy_ Rm`4ux;%!si>ҾK.}VJ t/r~ FZQ~@Y`X$pl` ZwDDL!wAGhEOTm/\ q$VhJ,nn]^2OׯCRzdZph,L"ߙ5I?,T{҅Uu>!*TyۋVm0 z [<>#J R4|5q0}/`Qy"q,ԎQW T8ϱV{nd;Uo#[ABKH2{*{#y#${>|'Cpt8N& ڼ8In_WxvȂHq*kΥmaoxSmilZqé9ZD#NZff.L`IkLA]o;t mQE:p ]W(nbRy`8#ҁ@JJ&B"].-5d2_^;EfL$}pjQP/Tl4~ֿ͈u*񖅚#gf%ƑW)i-e}Q3hk)wVHPLHd}q] d\jɱہ b-eQ5ygpi/]brZ5:iāT&qhb}@#_gEQp*bLv?hJZ?, Bu3=~x~Cz79J̤d^]rW~䡃eIzdEZֽ? 3p9^$S|-}gЅȱfC@7D B6C0=1.,+ff4S!LqrUJ _C ?10 [I^ PNxǖ9CҪ,~μ>MtTt &%P]J9|UkË6L!R˲=` I,M玎J}iOLN(9M2ZB*Bݡ7חhsg u˓~엑c% XC;94T/h3Z`GkB=<E\QC9Q{)㴨>5| s9hN~}*P*,]+0=.Ym^=LcڰX&yw ӴJ1w˺ώϑS0KEHk7IDBavfCZ>ZY}3d׼,(P 0.[oXW_mVsJ>Dd2,Lވ03ղ^(rŊkĔlA_ݰ hrĨx7+kVƂ,V"-›k6EJ T7f{Fߺ5fOQQ-ˬ*ԖFGvڕDE88tv?0}XϺ 1RSn"2u=z M J8£'<`'Df>u*})Ҵ\݀"BLv9),U*B^-|fbȑ!jdYv:dۦ`/LO_۷ROpYQJEE,t4E!\~,~j89Q)Zv[fo&5*ҘF7BK\"DOMm{]惻.o)-VN_; )Eva6Z0S‘H럡dz{9׀.c#*"8FCh&VMH5?N۬cOptX:֧`EN$7]+U3>a; #ҹ (l B-3rڸ0 ܨ 8_ߨU#wʗ_5wH ?I?N" 5+ςVx⫸ ^D37ǯ<^VVyYKz&J5{3#r_;.ehP5?=b ^U&WGɀ;oi)CFS9&lI}ΖUR@! il4+nV6`eNv+K?P'>,kt:Y Z=_uq53Fᶺf1 zb,zyM:#h)( xBYljUT0ʅ5L*;-[CC!{Y6ƀAsh؏,=4)[Z-j}7@)B6^tyU`y\ޞjP&4Q_%WN1t U՘jmkN'+l!@u@jӺDfr2,_tR,Ez76]<P}]Fd`3-QBmҠN܈BѦxq^aRxx+r$~ۺcW#Fw P kzCqst ;;rmS!piS1Xw k;hifߜ,Y};5qT`n#p}Qւv1-)[G׊\'^7UEA R{ riPQ*I'7+@$S} Is]V{khgvAnz b,O)C7^=Ƚ81 )<)XR?SR:E<8oZ HT^K'K|:9"@0MrtD LGh+~?;xWڀ TX:8] "Lgl@D/Id%\)*HlƘ<&EڎrFjj%RWZ~ ,XpL231`uG4KߐϹփL9u`M٘B@JC"v !h.s4*NNSF}Ks-j{OY$t9 H[.d\KY}ol~zxO R쐑[}KiCbXY#L-j?8ҮמL"m=L\Wܭ",2`l!@ <O̙VU JZ' -k>1 _W"WHfCfH\m4O +NvV^QEJ5j2ǟl^s's ==9YJx0jc|ig=8EJ7\Hck7 Q!XDD_ XB31s2}&6x!`C{K|v|rjXmMe}ѳ2)( !5#:}RďIT-/>5+QOjfq¦P_4VZ`4K{G@ TewN"1IdlއȺ?>ފXyב3ÅM!a^,HZRsxps~TSq:I]Zx*oϠA8Yhߋw]MT³G>t r,UŽԮgXtit ތOeůO}1$TZ ZHP`J!0OmU+ꃱ|4pR`|Yx*G: ̂7 W":<:zj..D (@1wrO0G3Tug0h0&+PQ_i;5ƍ2l%0Ɣ[*-XMt(9!*8E~}1Snv3H;E-&R*-1 f\"ݜ3P[ưY SjoΈ ,!+|^pQuF&uu9UC;ƜIg M YemV]e*xTAEKB ubƶL|>xk_AZi!в+8 m`5<ڹaO5{Q7ߊ`N9[ֿya+# h9 :֟@UX3^O_ӘW:-$9= VֻKA^DFŗЃdW\Yd!J%u$koHD,W'Q8@"X2Ct1=P_e-"u YCjNy/0띱: 'ZlMe:] LA=pr .M "vEgm |X|б) qr6θsr祩"W˲OeScÍt؇ڲQ ;?ATb\j!ZʪiR,4T529_RjݶcU(7\nWRQ!$+|O :#d15b}и;7ap+lsDHn8ÍZ,V[٩C~*Qf]1&-2r21zx+N;]%4룿#)0XKO6tݔ3+;4ԠC_n\mrÞS_YQâ!_56dkvj<^+tdΑ˿f~"KW0ĝ|P[a$Z~=j(&P>RhQ^o4κ+^}ÅP|RF*I'1epC 76֩cs+WEڨTae+!}L/ceϘ13_G c7Q2"M{BIHg6ȡۖeFe<.A])'2=qNOٌ8l42oLMB=*5`2 e>ꍇ#y$D/._ >ôt&dAj/#K:;d;n_䗀Qp;5I|{|sէa!C\)?P8S_R et+eD))Sx*[;1ľ1pBN2*vi{y)F٭;IU$~,Dds;FnVU2|ޒ( `YK2d›w¤ߐ-m Rb2".l" HSC KtH:xIVnЗp?t[r{T,=41'Vm8dc>&{ySywx|)V-Z)e?srcYP)9hǍ\q EV)@3TTogPc_R7<09%V丶7ϜI&(i}&3;2pG08w3g2nMk`(. 5WFAXɀ vg[Vϒ< kG]a?Z2s-JU9/U4lQ׆ %ƫxu^'b9#TH0֦J]YiJU+xD"%7M_^eכNm6}^tr FT90¸]4Db1?lU:9Wvh_?8{ry$[-9[4虈c,48n2hkI m_1g Į8 ^R0t]H+BwVjfVɿ_uY,O}SrjM%bx ̤C\.;2Zj6ebj^"MߍQ27|F/`MPtcviԎ:xN K}:3|n?` r,ɭTő3s1\o $9,qp220YsLa%D 77f!wz&ݍ ( w7"s4Ao5OnmY\ԜS;InzŽ l7]ޅhCÄ$,PYO$0>9Vdbeq]Tj8H뇤@HL !WH=pw]WW%>^S{s)YA8n7$}vnnz:[&Չ-7eMfcD] <QٖU,EI>>Quflt٪8x8Ҋz-ǛǿzYo] aUCQF`62R{w@o֥p2wj~dWQַ m7UȄUF^HvCƮfO *.8go>gG0`|`h& מ32P!>QrFpi4L7^QՆSsɑ6C{9dߙ-"d%fk-㛲*Yni݀U4OT+HV];3{aw%IytǖyAMk.lI*DLX4}2pzj?qWvX`lO4ޅJFY*"P>huŭ+n-R963\Vrǣ,BS/,%_t(}b Vкo &%X&gK=x[Bŷ a:dOJ$Ef*vq"jd1OMEhjblZ>)ƭ 0jOq$c]B4o(lk\㯙sԠˊC:@M{.ֽƊ'%A#; )25 ŲmoܻʔA<8l8`aLwmGesh jBԲPav2V%J6呡ںk}[Sjca1vw_]zzI.诔D}*7 Mݬ`D,'^=U1fNNw ~L8/#7c;A*pI.PeLZELߞ ^:÷pyF-Pm4ψ<8zm`lU&AE"S9L 0T} ύyFIvS+V!Sʙ2m]?BO>r(Xx*[).T 0YRhH ?{}))9')/ܓ/5ߦ<Qv,;oIKtǵ-95WjY2yDC OVRXDi9s͑Q^O{~WqAhCm*_ez.{cԙߞ">g+RJw Rr/YTBh߷oSywrDȜLd$`!SBfc>w2Bh1dm3s͗㽮z ̕/ms>>5~K,e197]ґZUF 6񴒮4-P +_aцx 1|S/oz;p/##ў?_WwkZ~) 3 !S+ kބAtA] q4/ָG3Y+t'VgA\w @<.V#`"SSAD&Luʄ\0vɭZsH I>MhuNTBZ2J>dZ[#V0zsP08 Q/H"5S u>+P FĠT{8eJ7ZKui#O$7i Aw~wDZ^CkلOo+bIMbf_ѥ̓7Ƅ~L\֭p8IO9Sff54̍ؔ3ܗn.?ԀѼ6˅f+{ ۛ!c,ZK *t,wvd4T;EPg|_摞h+XAMXZ!5m]'@ z˝FE6 tB8;afmpl=-4AU6Rܲv&m٢jc, l|<:04B7*gnUV3 S. o_!]82L߷{۷ " H͞ZK>]$pvKX:lZh~1F"%*<mx$w (;~y n <Ўf۶n%ًY%1Ħ,0KOMjEkeҨWiB @Rbb?b`^嘷.d㹥Ő`74,MS`(6 ,.cF%V a\u kSH6"A\&?u.}~QoMuWA-:JA|_P z H7DϹrA^%fBY_0JACr"+(1F!8#g}&\y\il F~>^yHv'?g0B@ UwMw$ӋeؒLx8؅(Jq3E'UN$d-oL֘$ D>~ $2lT2~Bb}z((F6'Nwr@qjZQTfjZ' ߉)boN؆Z .gMůnsZ.{{6Azhӯ}uXU֮(*8}KMFH 95G+ZJƟ4>x.7 qbBғNKCڣL}UAzc 3Gm!kifWyw:4E>?[yBS#5iq c~dfP2H,EW@pJQZlOI0!= #Xd N(RُH&O: G.v!^G ޳hEn^}TS*œSC8*Ґ`p9yL?'sWͥh;XIvAR0{2J\#Wey|}y E{U-?]i36-Qia #\ XGzh4]^SzWjiE} w tfG']8Vwz7Da_IV&tXS|}U-mWв*20$Ityg!nwtT 0oܥ'rH=KØa;"ίVKPC+W>+\ 74 W왹7\d-ð;Ru&,Yv^Zk[gUL8nB.?uPw8_⻘ōk=W$?>QWW >aYZ8~]u#vUh!f^1%RCu~o*w9SHt0N+ܬ)%'*Zr|iPýlSO1MmdϬ^ Km[ӫ ,0\js4MiR-N6sZwի!k%~.މ ލZRzK!J8w~i~yRg9 gš,b:Io݇i1d%ڨReSwdL}Bvٖb1_df"Vq8G?B(;2BwzBFn5zPJ WAwK!|ȒEѻŧ;+o|Ҵ昜Z~jB7 G' y!A 4&Ԑ6IurLo7C_#e|=`>}2`jg҇GK'Mtz< ٘vj3Ѷ( d:k}ђyn-;v[4t|H_9@ѧ r6"_сY|d{± s53`4 :OPeoU]+#:~ i=PÆՀ7_Ui7̗l,l - M}+bL 0ҕZNk D 7ASuBID(Þty)\e/gp3:4'}xlObo8VqUUIn -H\7mgE/¾_{vΉ}2&$SKUt`<UPդƽ^P0j صSr0gGVrI.Q/`8YʵwØPƐ=)&܂Lzy~?ʵ/aU{|/T\$;:PɈ;Dhfnf]eϼp7m#JD==# ϣ0}[fH91#bꭄ iԓF$n{֨G`ph/,3cϥOƬi(-|X9?~1W7ɒ$Ѿ_Iou ley=~Dy@}/Of|h[B -?^,z)9ns.P.r}5^3憽V%韆׬~fQj/#ݸܓcIիE K lGb,UZ)9atʩkg?i@Zc1$ _{(( !d&63Wcו;cEB_, 9ڄ>?1vS@6^ZʹGHS& {%Mk'ip+MhH!מI~I|kL+7^ tnBϳ|Uј}ƙ!O4<),k5@3.-HcF`!`& IE5r8,ڛ8b+@"4ғ\=YrNCH^b)nb[Ldî5 mt(OeA,CɩD:36 韓O NWUX1JEEc9X.&ȥLiz@/Y+2VGI4(u:.K?[k0n8 }R u91@ #zVng=[0FiCੇ)S'OڨLtr $ l 5ۚw$&I44rezEL9X#+@@(.ZpP4FUN)(#"ߢvmlvMj_&dÞ1^Q?p7b\v:48q9ȂP &Q AVWpO]k n -J}鼫Fze`MKR9ay30HxO U5cAm[FvDSP˃K^JN ^qg\q-܇GqԘ#H[NzX6~'iDxONW nk(-<EdkSxcGVwq#ޘ'ˤ9pM(Pq'dѫY8x틧 I+ D%(H"{k*raa_FKM:^s&&qDܟ+ݩ8/!0?W`⺄H-dO` ǵQL?ł%ܪ/8|ֶCd#x*ER%z&%EjQ:,IR9 b'H|-`B^D6.ٝAT䮐6a8BPO&_hJK[Yl0B9>ԕڈHm8^"? gS¸_zNd0,-:X(lx,l\ 3 R(?0lQC8ZBnSwM|Q5 OUlfgO}+ J5WN_lNs{!btl ]"SCI,_lBa,h=xu2os/N'6qrh(~Sv (ɝFɓrCH ~Dcvۣ/%Î^:5^KyVFKbJSkY*Lr.Y 4s5,o%|'n4<(9Gx'X.]"򿿏k ΰЗTahx^e]fgȵh;!&ͧe$H S-EME@{+ @reF$i 6L1/rUʞ[,dfrO@0ɯmF86ql?|-7by^` V\}8E;+[Cj]IeT*hyw"O*= ^(Zs($7 5x|i*@DeWyAR>= U|]IGFXA?~=B%EW2?ts^c@&%/QThu5']f) yaKZ܁j+*Ctz"н4zC[#R]RCD5C L;=rEɷ_I  ]z ]!^V^ ;-&$JaX+)NF`Leī4Y,# S4-3 {(~,U=P--N\2 7'R^ߙxj) ,bb= &6㪮m5J_9ty}n0 ^#AT}?`w.Sg.m;YVVO_g691V=&\$Y!5 7S/"4n;X¼d>BXc9!qy|p'shFl:aC$_AߋOZmǘrٟ5rmaM@nq\]!RޏY\Jv|HEZ?@[E5 Cfe\3߽S/^u4cc_߈> O'6vyk约GmەN.4-Dz!271\ݮWcq]FMy`F$A% `A^̆\}:>eSWuvk`qHҢ ZvK) @* ++9OI VvFŔ)& D|=uE"}&-®o`=پ茐/l<*~Fq! [ *yE7m|'U@#"^3cy~g װv}wA3ãכP\iM2QBʘ ̾&|jU9 A@h~~ngW24@(y{rWmRj R:Z?h}Jؗn 7*}Frf=H{ƫ knVD +h1+~Xx/K~9dVq_5GCkL̪5Yw|g/OdM1 ;FR h&G=]-*=*T=g+cչd*Ԍ}J3*Eڟآ҂{-*V <;pf10oAg|] o'ZPݼ' KO,8)!Ȕ+Nt,/b/wu^rW!a)rX¤5o=|^'Al ETο$R&o>04~pr\Om+e>bM[n$g~?"bE U`ʤ>kw(,\B9)IR $4Db@VTIH_]0yf/3$li]6KUtma @Y4cz[Ӷp3!:dYsHv ꍤli(DS~X\8 إ"!5P;_pRb]LJ%+ cě[Hf?9 0%bS~rwI4 \',Ҡ .̷2?N0#Q蓻w\0?a[wÝ=Vlgi y>MC׃m@G/WzP,jGTv@lݤ1~tgb{0}T cJSPKx<:i񂊚b@"}ߖT⊄p- Kns"'Cܬw]*@EbDepȓpqT%J-a~%]ntySE_%Ko`9\۴)0WW!}J!prnTʺ5fgk7גaXVb:;,|=K|ڄ1՘`h6UJḾ+dKمiA{j%Z1wF=aOfz/$wurbPfcQSchB]IjBVSd "& w&'\qPkD+ʁ!yѾY\{Ŝ_\ "'XYyAIHs\_{dNw/ȂYQI'k ҚkTu/Tφ\}M^FE]x{6E?ꭾ*`o@&I k]D؈/Ť8[Ү(x$_],8'#ԆSԴLGPzB`5z"X@Bv ~u>΍(ha nX,>NɶP <\_v^.gJLB}=m𘮵f9^׈ r0kFP:4 /,X\Xsٌ6 K[}`a᎚?e֜5Lol001y=1tWp0 /l}5ph|VtX2е!^E M%l% /(VZFbTO٢Wz^G2W}޴J<ѩ0p&DܖXY巊m sR_gJݰ߉7Нo#gz |bK`2Y=+[ī%X(Bjf.\X:^5r=_+ eOQR[&aGQؖ iUϗHl,*D69QUeZsCļqd`&ڶ:Vq-~b_ /v, QqY_%K181Y˼[*@}F`'P8ŏdݫ2?,^6[+gP-(gZmmX@(L`hoʤ;?#kQЌ8W0H1Z9f9%,;4 -<4f ]RאkU/\ގ~gP~_^E7.o N3ˆ*Cuw6ϔm*Aji~{?ʝ0v=hU&[MXKQ3O7<寏|J=W1@ʕx24Ѵ(2 *rQl|+8XR:vS&iM̄~ѫFeh"^n.~jn0ln{uGJM$hftO[R^'}>H~jߛf?O'{CjrX 2A2^lV$۱11Zn 72u`v^"egv hI3wovdB/ܦΰTSUpFZD|yXRte9@9eEuS8l TvbL.z,Nr__;Oun5ƄqLʕЊGJ^2&жu(X:)0*  J2i\u%Z/.;d?[I@d(Ċ]h_byn xQ*dbghxaM v0QϘ֣̑؝,NJ` !Zp6ߘj-vG2@^kJz'4YD},^}&L&]Vs2CNRqO6vl}I'N t&-)GPfwf< Gc!ܿ3P&"3KUG]aBaX9ٻtRO,ȬRFXY'8_~3߆8WuN_*|[Gs" @[J_4r|büX-(]C]|Xw3a6#0WkM% P;j2s$CH62:f}=x2ڵ㻪 6d´CU ~6읳DnUN*EۨSYDtjl0"m{}w bLȜBօ!q2%~vnnRfM&w\ Μb9;RSR~/^+9K=&V#+8Lxjs&6fEsbÕ*:KAs+wY-[ ֥UQn1{~‰i|2 J[EݹQvIΙ]Y}9lvq1{/T'ma: yѭi>81Mv:I4ݡ?n6]ɼMi_b®4X1R'9D pp+@!G[Rln鬧d9\J`a9 x9l'0mđD0#0o!~W^ŜhKHs%1b a4f1;q9ί6˼+a=pgR$Ó |\`TV+aqNò[]ɒoLl@w\+vL%2Է JVx'ؠ)x WAep~I'yF <`uZG/<!RWII+xبG_3k et./'fc?S`lﻅȾLY< 7fe^%gQksoa.V D+pgEVۚ ;(n13HTWNBdd'@Ϻ7,Vf 5Ф٤Z)FaK>rNs00LXM ^F 0vZtzw=0>uS ŨņLFG&"N8.c~ *ttOKfo],iQ<^s@D胷^ϙA z>j~%EcUt:ZK v&D YRG´8f32}X}UثV+E$`)K0Byd"63,b=1޻lTXJd$h@@lPVO!f9:A.^ Vl `ғ/G({NHxAVQ50{^Κv`cm R*N&p_@7yM;S01vC2+pʗv:値>34[擢oYgD0<A.iEU]Z6Os'yZa`Q+Ouޢ~*C ސ-'!v}u~i¼$\[k|t{HʝspF[iEsGS#9oZ:կ9?;BOzjhBl&|xG&aS==KOS9zYٙzNYDv,㼀5ήqt̵s(&YTBIj5eOu1SQпJ˗.s^(5q ^ZV1Oi|$x KyY|$Q{z/y4bd=&C#Q9Sn+`ɞh*Yg(cJ{ׅ *NALEGjRtΓفhYpli'*&Ey%b9poTJb[>\OoVH=ta@-x$:6Q:Ɩ wjC%] b>y3@vk;cUtW_i+Ҫ*suvIBi/S;:~eE t)a%*3M %hIq g@9YS:D_L!Q6 e'.mUfk+ʌ;Q0QDreart+ ?d s /z`nsȄ=9{+mtl7t!ȘdF=XUh\Vre(B$Y.fz}XnS"HbvDG%FYǵ'Q];RԜ+MνۅPho LQگͨl] ? 3-Ow!.s@ T.W=DR[߱ MKGhy^ Iyq]つ?Al `ޫ(EhU_a@aK, 媡"EB@q81fg|vaK'R 3=a6Pd3>c0-ճZ2̥-06^%S]ORSvisAbZigBU%xF>(CmYNP ſ X |M:?k퐁e5+ +3)԰V[(k| gn;e#a]덷I1Dn["yQ Rrt1k,Ux& jfZϱ8a19D\AiJtc7C5UqNy6q[uf.]N7ts )Y{!roeucLZlGjVJ,N!RSx5Jl\4hB\犻Djya KK8=.Ş4?FcZ&K1$z$yM|NJl^N/CcGZKܭt)5Ξzw9e"~q`)GݽךC&m!{q9-#h/<pAi\ JneF(So֑`t#\?IW:3 +(87&*.n7Ŵm~>2[r˨GӼw#-nP 6hS0чtϾ7*g:څ] !Npm \y?œ.Wm1k9;R,=IƲŦ:l;`Cx]b/paA]A3M4QǫpFܚz w ecqgD#G)G?oUG͘qiF%h7j\{6PDV#4P^?bKG_(ܙiA0ky킈iX^IcH MTQ#ۦ [51ٸUp'9a &K(ۥƾÓ,SD,x"A8Wx@'߁dWn.}#Z@W6C=L^k${W7v>ݹИy 7DitmPpS:䡸thhuHօn䠪004u{߹TwfX2e aqW4֟Z+n5ӟIDz{]d4/ 赣p.wYMxZnS(gQ-IcAT+7$-ڍZ{L>=έo`:LSҲU& _2TLda1+ä/0#X-$U,pHe E1?Ԩ]ߟ+^C_EL0(EYcAiL`lr*,gL=)IVg 5?m4/4 ;%r,4]Aq1zr62|ӛu98׉KkHaIם+ 6^-o4U\(( sMs; f䕑/5D1E."&p-r66Ph^%iN&߇[ԺmF$)N^F|4?lt*RªASHR{֠9vP^4>7)WJ;3WȾR@a3vY>N9]1w-sKM˰lM6<̩7*P)`=sSSu"IQ cfY'+{p"_c ^vc^&i͆SV52#GsPFxY 9)?۫BmLW3J@dni58JM/`V`HRV'=<ٕN-bٱy؀Mv{W~)cZ" Ёbx wh' 虇x;t^-吱DJƿG7Tx7ի;Wz p7[kL&u C.a'w<$swn3j,Sa6yGؠGomi>cP v;u3:q@CS?nlׂ}ѝfM%J`g8w;Qrm [LwZ_WNBnG ~y U;O瓝BXn@ b@/ϡm%2cVo<Jq=z7f z!l?=.r\l2(Gq2m`kӿuL^fl7U\L|7؁ln;p0ߡtR'Xkɷ̶YȘ.dP dB"+` EDHGU{(eoRR n=G{}۝h[eS`}9n߆4?^)J83QhJs~?*E,"576/1 ;m2OF"ScZ(uGK~0U'ph*Wގ-P^Œ)y+~z{V/jζS̹YkoV@pNQ6קʖOx_{$GJwO#'&ץʝ[j,:@# ƒ/:u;.P ~>5'WN2VI.~{ A7J& 1DJX vQdJ}7ŝͣ5dF9pW7d'oEDڃUH9Rf֢a7W?/ 6 G{ }ŽavCI<eИ!߯ɗW_ Y* hb|;aIx aS#HPhY~ fη=zC:Re82e]Y)LJ*8̭䩑t2nDXŏՓ07:^jq:\0T)Kc&k*V0&9r{I| |BjowN9aQr"7:v<sra@}}=GuMKjJ94v:YOǏ=#Ԝ4$ֈP'q 'zmn{L9Cqw)mB `o"HZ#XlyY&tHG\ A [wG]+ =t &*Urw]jztNK^3*Jm0X>qVUf F}[C/rJ5(~Gz3)(:籌Ab u9^i&k}~[x|ȮRU}:䂩L jF4qY=,)Ȳid-M@fN+G*[s#Wϭ ^=!׾Q[I7+SgaB67,H4Fsm㊁oAtϐRy-Hᭃe_G^4rTkw:][d̽ Vk"6\3j_f`v\yhb{"{3}dyeZI X"žF)o=ED"c%o*E'U 9a7ǨOu (!\8 [_п;GH8ꁄ-ߵ2{>Pw;-ᜆ ]^Vffd7!j9ճcCj0AmSxSEK@;'23xhI]S%~Hm>K[.6OͣYY3˖ч`="Fg䙱FdvuEzRMnf/bh9_"G}dV0ܯ"KMyۦf07l.sY ,("λ{/CU̦Xj;dSO7 )-!"P?k0q2M(Ι"$9wm SpISv8Y2'|v*,?-BOyCgQ 8)KȒMeW%U'(w/2%d2cۖԴA8(17e`pƉgSu;2߸5WKK@G1G%\P[^CJSy0!9Tbu53%@F7TŃ#9 ccDžē7Up 4/ D4Wd .IڐHܼѻ8g'rNY! Xj{T$Oy[8q(ylsZ{&kDfaT]%D䭋<eZ:gJ$/ZGˢ:,N M\ݥx##)!:,gPg0QRUg12͸T6U=&Iy'M1Q Ӎ#0Ҍ  R,Xؚc읚]9W' !D@gq΍cf'B%`sC~F +Ya}6[nX7R+g=Uy`J'IBW6%A;9k\x_{DHx7$awD+-ǎ@JCg<in | Gn7-s$qk&~0"Y^9+8B"`J218RR+Ws-qҸ`giYcqd=m! Ww$`Rm{ %HMLE\*ՎxXky.W_fXF$?Jβr-=-^$;& )'e@o MLlq%))+&nn⹓7R]ތx8~|3qZN {.9)`;M  guM-Uvh NR1{.ܗnb-St,d%7ED! U "'k=.{ZwnO{ 2{$n+!&p(F2;T4-hӞ̗XbV&-c0\WŽ@b{W8妫lvtw9am-8UF70g׻nmAK m9itGܜqr@f_jŲKo;ȭпOȑqժw[eE0*. 7bQbDw;:Q5͌=axB-0prg$ZpGpJB :{A[9`Yĉn#k"+-Ehy̹) ZхZ/f?"d7|c@pXUͺx鍅>CI$ɑ%Kp .k)F[eĮR3r{랣Ecoss ]A⋜Mgq =͇{ΦϓN1uZG_Xe4XzC)X6ݖр1I^R6Q,Ī#mS_ @ D/I|W~.Xs;N ,WhmJbVi;H ]OǝYc2}'P"ڑNȹfU'xf_o\ڇxyfP-ET"c擮KkgH"sQЌ\6M%πBD u_[X+&].N:j\curcfJ{ W KUղW (E W!F܍aWf7Jg9q> 8M‡ N[ s8!:9 ў9ˣ\ ֳKxahQVgE 6?N&̸ ٔD3 L2-UUfT2IԂ$O+96?s5l Q*ix<0/X1COSqz#4qT0gu7WKF16OOhKģH#cgCxU-y v'S]C3@uQKiMR1-6?84U#e{)Oܡ3Uwhz sbSo8%Pq[-0p VFrQy,@F'd|QiL?egŸf(YȧH[N-xYpjRةr7>$ZM1b[$85Gomdt<\6FgC$p~KGxE}75/!v ~/>%>tBDZC1=I9~srXl Зwk} bNV6t"[Rsr]ƣڕA6Z"E vYX*(QXbyD9`fh6-*+8.`@,ݯ[8:clyAؤ/=cJ&MsjjH;؆_Yj<@3d@Ky "PsKJ8kOG&LUן c'K g% 9gsH<q$\;>#m{{6Z[I jlQqN6n ˖M0]"EũQ"e]DMx!W=fѠ,DWU4oy đNs6VPi1~]>κy+ 8 sKC 5㭱 YCbL _n$?y_"89֎N lϛiK?-y5&i%}0'sqʫS~;DSǾyF=9r᭘-|SfG $~sɬM\ 4Xp"/ *l\s g`C^WÏ +uf d"aCCboFJcZ@kc-|ςav{5jXg770%uU.~fO|>P[;d{/R9qWirdrcAiXb{t@Y["jkhiϨ+2UVc+ cB2#dU"ƫNwp6@O) 7ʮȗ*Ay=2弬a!vi-pRmuRD$YyXE=f3=ddKN5x} J9eGVK87`::+fnIz~6׆/ ea g]~BE0I>xۜn@慂ߔM-PmPԖPмL uf1%U:k3u;H:CXI%{+~iaH>+h~83R7s߼S[1p"  qW$Xn1^,bPlVB΢'StS?ܒ@q ATq~!u{^hQVM'1&\eQOkƀZ5}MZ^|]]_wFY0sE<Ψqt3CES-%`|B"Y͗ijKH^Vi1@ GK 7ntP+w,!SU<̨O.:7D@M?kwb TxoU tf{+=2e g5 ]jL̫m~{}jU>)|ZHQ,ǥRqʛóhݝּ NN#r( ;gPB%Ů"r7/`j#x6f+*O_ڒ\@ -ڜ۳?޽cി(Gn_.d&1{!@ʕakE+PJB)Y%dB1PXqeJlјF7nJsms;AloP'x݁Λyn&qC0)68ܟacV{õMTRkGmkbUv+\ZZ1"#[RR;&L΋:Ζ]_VKK}v` V~KNHr)TqRPE_k-Ss2r_TXB1Osk<{wjqVv;dFqUϣf" J4x#Mk̅Er\U,8# SF{pA _OUd 0w*E̴A)#/ehݩLަ|H qML=;<]ڤSgM'ؼp HV=#l+9 h0!\uDcHw`֒^cC_QLX|~ 0r'~IiЏDi:@Yi}u1 -=-K?Z y:"7\H!._fcR^c [(Bޛ؇o W)%PUOrI)~OI\"ycr;vEP~1^zE%N&|tէuv]7)!iHݕQbPvUj+ $A͇_o/Y_A.+82B2c*wBs6Aԫ⤑#ejW*L ޴POl!{G6si/&'<{$^83'؜aY!pm 끰K#zK*V7_]$%0]0F&2, @vû<54$"ԗ;DWkME r 2{MK|}99m8E_IHux~ EgGo-i.`OlṭZlUb%;+YRp AUXW5e:aC䒐lfkm^D(^L#\4{Ɋϣ=3dSv}qа3g y+CҖt]( 'q$wUm`Xaif? s3i49h<^ڱΙ6hp2bk \"[(C>JXq1h ZM%馌K@gd -4kQ3wx]HNF2p<NAc#劓Y ĮvnE=hr {\̘0\$&Lk[ߑ"/γ@lGReyE}E0HU&-\~՗TDx%-cls`Ɲ3 *CqiWx[CK (^y]xLh\ 7Ji3 "af4{g|?rfrJBgK" tLU 8?*ﮯ{Α^ZcM) ~w~躚G[ uy \iз8 W5Y2@%@ B듓R f|NxvٔhrJuR)ߜ;K 7fL,"*0]%ֆkepY]V[aW0EG1A2հ>`rA-sTֽx%Ô.~F;z8}$!>A3.0ekx9 O*(Ǖ N~,T󠦟bDMɰ!7U¬GWwhKBlѬt$?\"Ɠ?+qe{k N k)쿼u[a<`8tPu~# jغ.v}N[5kƳv/ˍ,')a!?Y+u5]馱`g)w Mu|ʏI?B$Ms282tT%ر2tx^W:e7,MދUe++ 5;~֮){WK,_Ti,o4/{?, =dm\8[H #jhd==K֩b`{`]SMƫz'm%Q>4 V,IqΠ$%$JeM+@`޴bލ72/~r9AKa0p+uCԹIXRf,ۿ!XǡJ)ioPaiyb{2:% ef6F6KO(CcA8ql"ŀ'ם.6̤+ k{$(\0K8VNh BPIb=`v藍rUbqO+zbO5jAd:un$ZٶlbT) ؂fS|dF9[~Ř:(ed)@CH8*<qL>$mW^M%T_CbHBsߑ Z[aԡ OtN*zEPX}Bhs Ss-Wd95lp҃(?= g8K5QYW(ⵠX u1u| g* f8Ih{dZafʇLJnנ-2T~4 [ѵ2'Ǿ6N8wDpP@Eҋ w :ٯXR+f]fU$uэ^LH_.WzrY5vv w0Agմ4vu6qFUcPvD, &oHgNedS`r#YzO]k.MOH~$!]pC>Ӡ;`QzmZX=% >Qd@( Tu@^@ûڈF#kq/'NMZ6ba%*Jn/ŘB.2Y!Z d Hv`G3!y\x`7rsAab[1a/wAJ"ӏ 1W? Vԇ[skA %!Ņ-f )V[Ҧ}FJOH6JqE:Mѣ' ygO# \ƫg0+woxLG %N;jǹi`5s%'e;`ݻ%$3 `+ʼ֥e5ޚ Ur#8dV ꡰ'M49#ɳS:\]*o$aag%ކ;\7\M/t=l5uPN64%ył߳ z$VD2'pۦ1F!d:n֍<C}Q+1:: M YtK|e(RSޕ )l!iebī WtM;R&mDEc \":\5C.h[hEM=B}t|H;η(32'+TÿCiD, QpbxW/5_%¢Ağ>a\l10)"@Mx.TER׉lW+|>?zѡ;tsvQᵎ;}娞PfUh^t0 "ݡ9%JEiS]-^emVPkI҂-3ZE#S,bF-R1$IgBv+^;aX'eB%5fg\;6T+`RYNnLYA1YeJ[$/v_'Ͳ0B!v[ ."ƪѵ8]OiCb7zK)2n8wW)=ǭн]:iiJ;NqɽM}OiV Q7N7=E|Xј>DήA">;|?t<-JYmqq^bJDџYz =ЎB2S r!z4 f;MI聴n1zkd>\`[ZXРs$W ʌ{ W?YjZ]GY_5*JIwH.0#?:^>c,<5wj[wr(^;b{0֫s/gTg]~) tfh$T/Tzf0 üD#hQf0Tl:A hʂK])6ލpB>r'Dt*[; n}ԩ]0?W%4Rk(_XLJjySF,8idۦu~#%3x1',G"=.2Wʡ}* * @s4hpOR<@UdJ!aOQ/G1y9\Pu Ew,KԒO 0dβoa RH5@ާٲ1$6aںZIW3-$Q8g|8TX@y{ęM2c{ ~)MhOly@IV(%Htc#s=5?_vA`Zߞ?J^?1(T$ܗ=8H~(q|5 edn-dD>l;fgMS}+|sgc_O 7=D0d ]9pDf9-(SYzvwLX@죵*S[{pyЩ% 88.?BT-ۥ^7R NyW D|3Oْ7TB#u`P4igD m{3KįOAZ|83+ِcP+<5>Ch`fh }OF^.~xY !mgp6Z©HD9{}9@1-oWQ31 q 1H[yy(_@ҍ~ek|%`n_Y+5y}lC%LJY0`>,%؀( W|.W1۴sV+Z7=SSE+/e ({JЋp~WuU?I3cli(lā~ &daOORx(I(eR3˹/zF3qHOOI#q)'8 BWbyjaaZN 1H[Q_";=D4 'ӎ J+쳿MG

(O?zYU[ . bQnӓC ߰e8'%HpIDoLoN,}+6_htj?1y{#m']~LdSエ?;>>jeC[xXeډW%[~-/(E;kAѡ&ҧA2R|Pp.2-gVp e" NyxkҿRCn/%'8V?Gz}ò6 Hq[_NѕoMð ,#CDW7z` m!Ye[HG[) KmVq1*ֺ$U BɊ0:zv.ANQFx #sf_ԸpYxqdZs.i1z< +A~MQ8OL5BÝpI/ LRŢImW|*'ǔVi.V`p8A9EoMyAD}O\]K[8?7+@)t&LBY rA( ƒe3yJqJ^{Қa':,-E-<9y G]+?ԫQ NoZ싑 a)Z菷@=Oz-\,3sv5azLG4 ,GWo_ #i^1)șe.52Aq-<9x`gp}$Vq$4xQEEӪ yCZAnrG0NU(IK]P] db)KcE0,[uQ&TeBR,XTDi+k}A 7%&%@Z JɘKT]yY t.@ (CX H0x'{WrwwE,#^:ai$.2ϼC=51< PgV=j&*Bآ)&AkUMA'A/Z!4гmٵ5.nh0QqV&e0L +/ˬWទrۜJ} i~sygpZqdh͚5` 6ĶP^ '6܌B0Z (6e]9_1Htսl/n{M<#(3əı9M2y4@m7XhV]tBI*7ףcdaw ~Ums ~TnzmnVM^y_7%YXڈ@Bc0 V - y{n.1(rHvڗ.GC"dMiN cL䎫膴Mh$nƻ,. ?>HT?<d'LK 1ta"OMm! '$ZymJEi d@kK@>S@XJxۇ9kll[Jdĺ?5QĢbU<:3YMFM'tL1XW]8(V C:$9[j )feJ:cOk/}OUϙ4ya>cG 0aYV|C3*߉'{T!`#!uM1Nм sɏ-MmL` Ú|f)!Czu&w;F5|<UxuT"ey3Oˈu ?FkƩT<3P_yůU\?{Z'K;HD? pA5$emX7FYQP'9"G!)|=jTWƿ m> n`#\ x9^TV2\k'Ch=Wbr*fT;{M"gcCpH]\*U-)? t](Z7ErKR$wjYw`Y[:wF2ƕz]Bu"6ʔH:᩟n 3BLIMotW_(#υX%5`zb~ȠGHx#KN֕Bo[^ڍT>QG׿wԽseg{+OKe._U-2q%Fom@u'ld 42s"V+WX9 > k|c؞Ĭb 01]:Wlj{oFTD^$ei%TrV/}&P2"dvjd\1У ;:D`&@7&պө =}z%]Qn'{CJ p2H/0w31W\C=U&o;&!xn.\סPuVkk^{r9xe)u=&;[oyssPj].gp71LMK$ θY$U-XChRICZ #ͩ1MzkQ6L +>־Tq-UHQ7(mJGN9 u#[@pxr:mB褴W,ŇOv B7͔LHUM&@$PƯV5T',w XNEE1ڧjDjO1Z7GEƘbC4w Tg1^ @{]Vo37;8.A;7A qaPuKro~!n#_g5E JN 2KѥvI^ jmiE satsp[]w6hj y\`p|Υ@$Aopxk03zvZvqr)´ЋinBnz^90hz |\ȉ(4kW5#?3aЭAJ8nt^FyGJImB,Dž2@r0k@׳W`8=_^ Nb`tPO> 鈪@J,/\noTB`M=BUJu͉6qJV3\caYt`rj{ڒn\ЯX00t;?1Yi`iYK;ţa,A!|Wz8ŗgl5 jN,{c>ZP+=@en۫M>N$5ڹ"ts$yys5]5B|m-+0EWU90m6cxi"3{Ui/4ru2S]JsR$8Iw^WpfG3yjBlE5*Tm@qQq-hѩ`&ʆ&l7#S:=3"% d);9~QZۧ]s:{'ɈOI 1$BmEY./5iW^ c!1!~ etkY 16{tBW,"KWpϳf5ZI+~AѰF|0TN~2T,AaX%Vl"ļc,GrBGOKyyű<"7-[4tmu77EW>D Ax!}:(-x.qf1]q礎DzjD#wj9IQ[I s=nQ)@ M^@wX1ʭcdڒJ/K1G SkD8f f6ڔK:2-z 9IaBs(ⲓn4$ԝ#ٿ1QVL Gbu~@Rz ~ԅԼtL%E1=ߒ+QRDvRo״( Yk-P`]AA (1P"JaZ ?y,Ɣo'5 f45dy|ñhh w%`I#ɏu gftTHx)9GP6 U^''ΗP_s`keDsQ=0$tYGc[馡 vw&**&-^Cq|mM_._G҃Jd=%{^tZp^\0$z+JDF;eUGt2ו n_Xl8ة9?-C+4NNe ӣ|4L ,0M8T:A?qESɮ'4#]DL u:^+us7c:Lt^I6/03<6sS"0opݦ׾FB%S%Q|'4w0Z;[n#,UF Twhj-ۛ^ 祮@=z~EuN9lz%62s ɣE})7?B`s1outGf'h8Vt6t~}vߵn[ 6g~5q[B(ٺ!"AD)xypSR&唿I0{diGk㫗7^i$~NQWeʾZ=zR24HL[ fߨf3,f 3C]S 9I.·RSAͲ<Ӑ?i1t/)x"RQۉO#P[A#oQpI̠ZY *o9`ĬX~BRx'JLtuCժ5c8/C7^Tly^W"j3缠.$I nx"|=XUzaګrdV{E LqȑnƲW>8\ [ktOQ_:w|nZ 9Xf~t1{õHUX?k1Gj 3l}^T3|#V^pqh1;!"լʩi4$0R  Mr0_+3-X3䕙h.N}+ T C䢔 ?>fڋa}:AswlwO߫<>LI84χ\@9+TltSwiw]BnpL,;c+1 d+GpBiJUˀڔU9T@A̷H픚Z}1h|`zl# [Y~j~S}C!ۏ D2A#b<|Z1ra.=o"BpN&rEܿރkh?{,Cv&jh994ieFa3ï[}vs5f7L#^v]5b^וgWP KaJ! =w ن,C$Zo,Ƶ ¢VSVqb(GAj"a](za|A^[䭫ZEf;uS Otb1[A~%Uag-|ko'{UG<4 h3-[<_bɈ|nd-'߱xH5w⇻i/hO[x䮳uVC<-Բ}9L|e )9::H(eG2XcmM1U3_Jsqj@ғ֘u*Y^/>'|2a.cbo5,tΓj/lֱ\,əag5Gn9_UN|h ԓ0=/_{ <#,L$&O7"?/NbqA؊FWc6>RnN)3Ք? Lc~BDVUȫL}C<yP_o KS`fqH=k9ݧFŘՀa{lW[ <׏!L(R z[8dH'I[> gIҙ jbt'kg8@$v>n°>ON9^ OLEg4 ,eוʈA`߲YwA_B"bsPI珛j r Awp{kݴH>靖`'DN%;!{܃oAl~1bIrK1til0ni~hFfJylN/E(2Ǐ1r|"qxv @A^BV.*On^ @dUj.@ !l0Tݣ@[Do:kasKڢ%Z)'7%;az\s3I@2 B"XW&#͜n;tH=9jL )ѷvM`@\{1Ty&+Ȓm3O[o`.]I6}&/'~=O^Vi\GًcOC>eMNS5"5B[ Q_,L\򾱲)։zb/%cO -"i}֥,q8^)O wyh-H萟3w?Nh^*DWUn~9l2dPBs­UE!X(Dd$Z6pA2U@шPLVѻ8x/nNJυ7,-5q:dGG m9 FoYJFPks+Mb7G>:CK.ō H ñZJ/zX1@& #n:nl4r:xo{ _f/П[m@?F6`b/ٯ;iI~!}Џ ^ v;Ϟ,}k[FLu#Â_u<=s<'fo:nWy*Xc&;4`ܚT>jrvY1Vנ0ou Zߴ<琹_?k\GK4` R+%⽫DQ_O4~coCO,EHV)77a8?q:!GZNFQm#f\.FrGfQ`?!~`E#/;г>kIXP}wwxWV: 髪|9xb} lAjz,хe˦ܷ.e&eB'4TJu\g2~~K1_Xh9-WLs&3e,i^ K?c"{ t9e?}XPayhhHʶ܏tGPݘ+Y~}H@'Q2m[N!Fĕk~QPF/pUo=\n3(҈ agGۻ"Uk`6c))iP¼0柔}p*`b C*;>ԧcyO?8e)U P%"~rq< ে;~Kſ$ LH:Uf sbH]An\#IK{ӧT=upQ,M"#L:pb9LM/b=ZU\r?z#cZEx)W"nAOj٪|BʠdYi8D)-}0Ƒ;/:Q1āb$ Fwq~lNUQw |Qk@_P+O_D\qM8QoJ1ħ),G281"}HgL69Lv=iG#JGj3SGiu!7=&)0l &TE5G8+cj3:wXopMzG?}6kAU^ m=R!*` Fk0 dR&/G /oA\ K\-o֛Q-Y#w ѨQ\9Olƭijcȩi3JMg,ڸfi:TZN Ss@+eT¥({qn̰u9U*>Al*򝡞0GYh@)uM0Y8CsaE?\u_HlW*ø4, ́oYH%X/48EQSUgpFsKzGOWMG%p?{#q兒`r3И\&q TŲWPB7};n]]xQJa'jGA /vTT%c;Q_ \RI. "Q@9VTijލ X)vHXԕ t%pC|fut!$kNbVj!J%nl!!\LoqyJjpuexTyMOQ-cR[,6AegHm^۵]~ٚ/,VX2xěqʣcn PIM^<0/X橷&Z@zf"Ah%^uPg1kds0]7}&xWϡ]n1%[HTsdRfkc(z}MM \ [?8{G&-3}gi$D+O ݫA!D|w_N6R[0/2 ̺Gx1^@cѝyS9p,% t,UӫXԺMXX`j`f ʡ5OqɌ-J#:^k-xb6HT3#I+ԅΗq9|3o ? Mj6rB4K_ =+huD-Q4N$. lv LN.V֘afszG2Rq[m$<+$@Ƹ10r_ :~b%MalRvݤ yUeʝsJia0R 9-J~oN]j+KeƯ&-h|QFv%i)IJl](@SqR,Y]+Q8Ÿ jpL |KKv ;))vX8eFi/\It!(Rs֓z4V\VpJj:INcCz0EQgRc5tX8 ~ţrn&*js;'J^i=m%sPZfE92gf{u1 JcR>> )1EW=dUf CPm' JkYWWF(>PyS'9$ POيQQtp1 yz™pl`|J{&|Ͻ pbQxED}7Sb@n}0O~7SAf>$FihDefwDgӌOM_PZ5` 2CY;\UhdPQDdVgppWXTS ]섁Th}ƘoZz !ɚ]wc#з8؝t`8.qCEKK>&WdV}^lcPGMvlӕKL7% +|xRX~| 쇬|Hr)Բ A%=#7h_61Y۰ kZI)Dٛ <Ŀr9р- 9;C G%پwAQ1 r,iɐym5ۃL<.g.ZēWN#M1( » H y"/vQRoÃMU)mˉqQ&b86Dr2rCjzn@ϛ~]6} i$nlp{iijXx?دv@`n~]tw0F H$IIQ3'{X vhT= '-V a,0=chlqO_{/ 駭WeGc[Z礦^VhEP8z3Wl |K溮X]Gi7RR[˞义]=`f3B筸Y=Pֶ _7ʣ5a:KhEI  9aYl7 ۳[x5yUk¦|^I"h]:8@ώ@^+GYu0J'` hϕWW'k0`YҭF.8@G:U*t䢦"` kq3 GO|;VEMПNK䲤-{Hr")@dܡTSgA4rD/h `@ E)SI]2MuԔ=" v탗=%H; d4mIX̩IsW'0݄gOy}\Si (È>]cX~**|(2j7Kq+Hn\íSo'lg;Í"m'~#=ZgH$4HR(ʞb+p d44>s/U3wi5EOmL>gkˍ_Ehx# 3h0^'e!T*#~Ҕq`V@(~ m/UhS\ޫvݬ_^Ցݼ&lV7l <6akO"U9[G$bk?4\kn,R) 3%2г" QK7W t>*d[ifd[4G( 8r_4bTЏ@ WzyϸQ]ϟ|"~:25n/pA@ydELOڴlYG 'ef!ý=tOk[mTDŽO'l{_\z $cr(w?L.>gP&h]}HjKgrIO3^h]Î}Ii5!S-pI%O>Vޣ=ðh>n7*KWnV80S)}xٶ?u* ZNCn\?^2%I:7;FXNMLGv&0i7ܞwKfjRP/lר,6Ȗoxs1>EnT 1 QE~6Rne@APfp8CItlǦ,B@\p"mdJFsQ,|N_XQj)Y _%sJ4սukߌ7{0&޸=VVb igVJyvXXT(kVɢ[2F$/@¹c' 2hkzqf2hD; :b/];IW,"iU] I\7څȔ78Tz!+XiFMO~E{ڸEn[xh˜  UP̿6qt@NS $•f oP" c],m:dLxtQ!E#W."4IjZq]Ii3'#I ČSfz,%q~r|*NtpMxuy}F){j&Pc=A̳t_aIƑcMfUϕy.m/bmƎy̹c):,mxḰ//܃ޖ47Y,ܙ80! v+kE#`&{GFm=+P`տ/JQi BјDCVQA%IQ PgqX8@wU|C"( D(Yz."⏳e%riG'f]s:+v?.hfĕ~ْP}"W8X組,b\ru ;{;!#NQ᪄'p?vLTGi ~gOAH H?1x0kAy"0 -YU=vM{g_j֓#v)]][DPd**P j%+.uJ9h)_K;x*4OEֺa:."-a{E]̀9 &tY;svּx=T嚦wmKV J@F;)=ʘKHCVzL-兪jrJspI=V()^M|5*6w-Q.vEp%ۨC11vkO}9Ԛ~Z;%q[xAH!4=?zP76V42 ]\.!:d}zr;1 qzU0z˫0k5E0Fxl. 0]kyk[Te]ՐzѵJH[q*f@>1_(d=.v$o 5^-{vihO?+ թ6mVL4! } To \PVƅ4115C[ <kg:#px(4ZIߍ -ni)r >֫|t.;=3]l#Q.Q'Sq|%' ˸Z Ju`B'w6Cz)hZ.:(mI V'2x oT4Xp!PE/A\I|6h񌍟xl&bQJHuUlCl&١r!VOe&wh ^R@kcy[:vՊ[O<,̥/x~y:[ֳ)r( ) u+m;! d2.L*9yA1m>? Hn#6$v`(:Q"&vus`e~eZ(et9f6DOŪem:yzD߇O |w%x^fێj6[:8:@D*CrNݭk)5FϬ, dDsBH>e@]z6mOTU+8Dn1?e ?A#:p+PԿIY[,mKЏ[#tB7Lh (dd\_Fc6S"8 I턹ôqOO)w\;gPl1Z#WKH9TUӑnw>Zk>]-ȺO+k@{A'! qI_pL=P.{# J^rAVg Kzǹ )T}un !:Ps*KHx=wf5.zaI,:{H6@qߛٍ?z0*Z#r$2jvw !^M7zAPmVJe%Wa", flakt5>d)}@ZIhvTPmCբw{jE d9I3= 2"EX6z~eIPE}Qh3'7 e$?v9(rQq!5k:vE]6]J2(<-g7ͪ#yF;ps<#g) %Ge7o4;^۩><9QA˾F@^-d~͕[xWSa~uV(_ו؞ MR[D7B8,ע?1<59Ow懸}y" 3}svMgHQ)r x=lfˉy}bI*qawBNaEj1絸7~Pi:U!v&+ ^$= v*Ÿ)9mlTˠi\6qb⩯̚V>>n +]'~3 D&_.<|퀳RHȥ}x6}eXrYERT ? .SDLi(r+؝75~3zQ.4n#r7Iު/YzJnCg{8E&Ce Oh\BO0s Dh"2#?c+B21r#] )ǂniCҜe 9 zgi[e&ȒFv~ɬ]~3.m5.i~c6N } 7dH ޭ`y(S:D} ?)`^UI0+mZr XYs7S 1 wͺ"y#sA˅<wh ]n9SmOe^U,Ὦ XZﱨ?ޮxuu4f~V:Gvx~O4W?g0\dKMR5Q䒂nhNDP1(cf?&bh4UEp?Q4z0pIHM_PyY6Q*tK(ygLܘz{B/D|[K7"$ &?On$`*G і>H/f(*7d~@4pxRk0ZOAt$̮xbn:y~JY¼3C,JuYPh|0K rCp wJ|H/'Qi l7A%-݆"az@Ff =np⦮vIr MjFdx 초,gKX z=[!3]C=#o倘Tt8\^[Qο{ci&}B%OոQ,&"9|D8:s7#TsRC)8Tǘ'1ўH^lPVBʚ5k c{ Z`J8BXOadƟWsCwzyi:to |y5U2} 7kTCٚ)C_tQxJJ 'j61ImEEK͉[ Ck3\^̤KA`;+>_`bJy #?*h "fnVbB"Qi X.| BL>@Δ"*K HZ.KKP"H^ RP&w v #Ût% i g[FH4_*5?G̦hdkռij~{эw!8`;EJt^PTA)sԩGCz8PJՠqj =y?Ѻ(,1ySO!9>?sr!աoی'0vi=%|7ig췑i-v+`5)QE{&I(:= >Q~iQPC䟸;`yU12uHG"32i2N8QVlLUí]z33+С5>'ƶU5Q*$FV yuא(V!ɃM[wst-c+'k տJ&Ec1»gy-*@[ԇ4ׇz;m8vOh,`uǙmmX38+ҜD׋7#iNfS\aε)0>~!MVqLrꪰ(ˤ͵k|]7o41cNC7*A(v C-F>pw7ƈF@݅ra~4ff# ^n.w0?akw;aNgk  k3oq=>dF__"JlB:!CbҴHP϶,3w/F bldmi5^ ] 5Hyן%v]=ݬ6|2ND}]ҁ%˨u¥w]5 QOFSBa.}E9/r2XM]@v&+vMW@ # c~45P2ʼnڱx,0&ӱ8"J4\I<*xrAm~q~_Pk--[u*VZZH#wt4Aת(V ,}ǬvbNl '7(1VϰŠY96qe}qfv`PO kqI|{ CpH\vH{OFmc]qߌV[t2W3Ƽ&\$} 9:I3Ra8 ߨ&y!yiʽ͍?oc0—w5we"sLO᯹p5G4~W.4Zg XnZO*#d>HX7U<:ms3M d~j (ͰFWϠQw ${\ .djXbyĞx=CɱS[ٞCP mbSd-!s {UtX$ SN  dLEyA+sUV96Wu ^M~zwmv"轝Wi?s.f/${NA\UU83m*3eiN4$;1[_E)=dq=4EYA~MyÒ׃` 6A7K'V' o#3}d1<~?FB|9R7ᑪ&OrYFל|9o6s~}G{; w~|1N})Kb̌SۿȘhLJ_^č<{b0ߚc;9/İ:DCUO'F2PcQj|/ j*KԵʹż4}+_4Dx}dz.hĮb.%[8sgyhbB{dO-D#])w%W!Ei/q~(epd}M[4}.Ս@&xvFKMw|E`Kv_͛!ppT Eʬ26ѻE6AtG7@UA휂VbޫawŇ!"׭9.#s+QQ7h2 %fѵKuݐBUJ@rwo2D<)uhC,\ rtO,gf _pV)YfayBwYk?FzSa Tqv‰Xl%Znk5 F RFY1C.9PVz<ŀ8yb +9uQl;:zec,Y>ȵ%M5!p3qAUP";8jL*pM7h]zPң[0f؞KGߺ6%TfwwfLw]vA@}Qi=JjQxq\N-ξ|?w(d跓b!-!m#vPk0yG;uZ .7PlY[ *rW_q-j3l7~LMO>%!+Ż3)&\m2P q8Hb6n:hW|î":?!qz;ou{{>[S#o273!z|ϙxO~n&]Pm fqJj0K]mG֖M!z'I9s?T5lԕ/ԇ/; çלm2JBiQW!!A2AWm޻vRu7>gBj}ljY =gir'cUaLi*. #, ``+;d*XBcNe`"3f1 W=A+5?HᎳT@IH_p`/fSY)\|5dd4kcZa oQ\3,pekthA-L8Q܍@xJ|rOݐv3 4Ju0Q~Qʥ{ ֔-A`[:{WiYEVmTL2"m\ KbRe}u.ik|Vsmv,p9Ag\}l7WMEFE;,«] x!9f$e`!e't,~>!~jyuen0'1|4 w zrY]b0Q /^AJ#gHQM?ӊMHkɔg)&!FBO#Glp{>{[ s{|L'\'9nw3-|JkТ7YF8~1{*,v"I@i9ѠLd}gVΩ$C 88S5Cط?/2r:G2iiTUCKm#u]g#nMT*^cDgoe$ "H#v-5CzUl!>{T9[sSถ}!XSq+>*8{[MA֨ i0pgdwS2ESO"ZVc!HM x4%?FtFgl,*37%ՉUJM[;}A!i࠰J L:?etρ8kM#1VyWMm7ǁp0=]|8 ;? q:Aw}q#c|Y!r_jtNiaEZ2([߭}Hhۊg $r9W|2^ '6_gu"*͏CJCxA"#pps#5L%I̪K0"%;㨍oWnh]B ǰ96*TDZ/!!ۃh.砬@S(k"\, P!&/!R#??mSZ~_u ظUzk9GrO 52 RL%CnT8Պ쾔C9=j}2 'K40A~4/Z$q;k:t03d~lpH\wӆӭZXdPAXUC )ЯnHL e& @NRLa#1#z˪A:.&^J%@@h(`Wt}y &"Yħ3% L}^lFPޛǵƖ27KnV3V߭/x(%AKd;L(Uav/b+ _]g1]l~@wd@}uhOm`=Lʫ}{\?Zu]T^ѐp;$zoϹ4s68g$÷oӨb[Q}&gD.pv.HXpG$嬶h&`&|1S@!Y[Tq=b82}MhAqPL ibVs{v^eqo@!)A(K~x΢c(w- BYBșٯt<4g~}k.^Q_l(mɏ@Jm3̓ԇqE 8nD$AN8ɘ: 24{1Wmr]]OlMqµToǪC [ot "8kTjh gV7x/GN77>/zQlm8 w^-1h|LA?K >c';8IpNҜ:[hϥi|uTvAQz#R5A2"*BH!'V&ޕLf' \ooVU/" 1O:mmaaodZbVh/UXFƇ$o:/BWfۓ ## ΃X%p6r .TZV2Qy=c ghOdҵDdQ8]'%B{_^#iE0:)iʑ?>oR:vPw $r1X:e[ j&^'uVwslDx2b+A ڂ.zxfc> DR'jW5VnЯ]3xO 1R*! `UPTY$!!wC;T!uNԼ=t¯rn%[:a@4|% GfԲh?ۆ]:(Vy`B /FE NqثU,n@VaOwA _hr?q|.q@Knͪl[pv,e@x_kƠ-ev1-ug߸cVEuXw Xjn _ZɱIRVy$v* aj2ۜd+^L}G P~ORcB 7L[RLf+,։GLH#NqWq.͏r- P !(ooX챎߁m e |y"#ze-,w918p>e٥G,GPw-9!zXy1>Ђ_Wɑ8E/L=_qP3.QW#=_hj^£O)*QȒ;Gؕz{ߚTrG5R)!idžiȹח`[kwC6}O#dl< c"iHFYA;j*_9K-4Z=͇қ'ZفV(q.gӤYR14S hL2$szOZ杘6\Qb$~e ˣ1 >E;g ˗әKDu $)Ų6%ӝYy#gw;殇bZ>ۨMPEf\1$%wU(P.4QɋnvivpQZw!oZt'[brq(%@V*|)eK璲X$ f;&!׫RAa{x8_tt!wS ;0uvȉn=l~zGOA_nhGgd4I*ן&xP~JVR%>TGXwNQ/m+䫓}"ӝ4aRJtU?;򕟲ac>g0'L=2=KEs_\ ]! lCQ5ъ-M4^?m2e^[% 5<PNmAuuƍl |{^2EQ iL>VdG0HS? SAkr.sىn<¥Y_ ?()OZT[BVvq| @651]M^l/ ,Ҍ7-Z2ѣKhEȘJ3FDmX1gǘң/"Q{҈Bͯ>p_z0c_jP.n#$na [ ch+t6kbƛwNDh&8]IJXg9UYArr5$M9Ә[z@P=! F0pPnJ5F@BOn.ԍoUYNeKj,^v*DǓ*-=e9M8S0A ]@>⤘uۄ0o+R 'ȝ- oǾj|.h ?YW` xg/axn=y&A=K@ iwXYCY )1-Ń.6r P]v)G HC\#d^4|0>M.#x^X.="fxԠh|ƎmB `"rU6vLNj+յt)3B ܦo968Φ2p_ 6Rxr áH nn%Y/O4'y_w}HkҀ;Hru'J삮SXӃ%naB~a{rX4!BmpV45V@tVn>+OpOl!ңSsYʎ~LlHѝkKyaV9 Ɂ.V^l^Tɂ3ФMeDz Hϣd#!k9щ * Ntٶ@1ZD)U "0{iC,3a\=N>#բ&pFƆkjXO3ia2FIY6hT?C %]cFfRSA,H5=L{#֏jC*P5 TGl9 DTr1ٷ}͐X7+5k~|^-Sf!0 "}WF%q/^fpγ;J^re\ 9i'`dW=ܹ)oUUǪv= cr>d6iY˰[kE^ @@cHXIcc6-S$~wHViU}.>1L9*.0,fă[B~R g+涒ڍ4i+21_ 1;s5U1.~*SvX>07 .k{`SMϙBݳ|BOLˑ˾5UCld/jpNWH!VOEv.bO7fW-uP̦Ί*@Vy~PFFoB<JxADW)fM[ '5p!w«to9ͳUҦMR1Z ~0Bח O^;X𤅔ֻO#fLJ&̕Q@)y|4 0hϖ@Y^IxMdfQ)ɝ`uV$*1w?~/6ّXka^+Z*@%9 ):HU-ͤ"UF3h`%K`B艶\lK `ҒI~ ;m?^_еA`n0k aJ$ZJAqTω3-&kdNݯ=~(螺;#3>9gͰ1⼍>5}V[iKBq\Mآj.iDrMF׵njvm WA>'+!;7imvur M~cP^D$=]uQj]40F,_v7 q9gnnJ,-$id<~;o(&R+ 5yU(Ŝb^σ;:0Y3Dk9}1 p7LvHW{&J1CL8"ԯ~n3$ο"`K3jĂ.?E8WSvD;=Lzt鯋MN|HMg ugQ" ?SYIap㕚$:{j( 0( g!/oњᄔt+V#:0"µpyT~ۙfI_ ȺQO7>H!o(&4 hsd.c(GٕI+DKp=|.@N=%x߁?ӤW! γpRi'P=^VUub6Yb[ઝ4ѹg/v}` _9Mq;p H&Í=AcVur X l>XdUjq ];ڊ=FR&iZ? R/Փ e-iy2UU]* ]Ga5fgQn#ZUxNoأ QSQ>M:+ k[AvgL2g~dvhoyzò߬!kf.g=[ZK|r.8-4+,bZ1訸X _P ȵ:Zɢa0z:=B]!:wJ顓$[& ?Bwb7"&5nNWqMy\ˌ`% i TMM~ÎY_|^Қ!%;n^(z_1\,Ed6h&'LMe QFv\Sa5㕇@OÌ7wy%C6E)8S8> zߦlqN9 =]M oqYRގwXS\UV*ӽrhd~[{SѽɐȌ'ggʿ&ioDyǐA*=R0̗Y!H劣&܀[?佞f%/KMOxǭҠ p|pXo֥XJk,YYezuhLx7`ܧI(*PF. L2grvȯ ]qٻ\}^6ze.9QݾK;?A_Qz b/htmvZK k)خ<]]t.\\J7(ߞ^%g$j'8q'!y{rA3СO-oW혵)\ļf?(\ɃaԞ%F*ޗ(sdaK#f6ժp6^"F41km<CI9[_]"2/xPd/YTg!mEN"\QR. _*^Q|N>qV<7xGgKy ¿veQoK7ܺꩤ6i |*?$Ss?#ì&Z!luzјa$w+iR")-7'4z kzO i V,[p(;vx1wGexE_:Va(!%ŭ&B8~l۶|a"m(NZP G%)N@7ǎ$)~JY4v2.q:%uJt<B ?.8RE6\'iUD>^جWhM}%'G{l. Rz!捅nOyfW璌nkμ^̬Ťy{zY8!;wsvZuà $\wKGո >_RcΛuQa`fc[%sϋ m[n80+_.*R\~ĐI32LC}a~K PRJvdZy[8,Y29 /_jQV:L(` weq[al7$tR4.ּ?gHW6tbQs"@L&W |/V_{`Eu7REW^^jT$vBf" }GZ,G}K5~(?E 䍥0uY 3ꭳFf6^h^Rk yn]8QC$&%;^ >|:lԭU pzK^0r eIѿT_ @`Iv *łnJe.^ab [طM~LA(r'H5iS(~?lŖjFGS#PXY&[ѭP_4D @uU2@=7Ï% 1\@+g7La%gF{&>$pm>p G7_] T,%#_KM,Q5D͈_4i,$.?#J {wVjhH[]B){%=mCCiwU9 2ZwY=aU ܭJWuoL2tip.S_&͉ ˑL]u@<>a37c& r{%`IJFϐ 2Ptmi{vPPZLS:؍yi ۬jN/ Fdg)!u.h#2lwtf1ek%& tktlߴV&y*({bYhN]P,}9YQC{7F`M7RzF|n$j>7K'xUvٯ 1Rmٰ;=^!d;nԴmM&py-׋VKŝHpҤtn,/-\h^+cKC_ЏQ|\Rr߹o45Uka@E`悢Æt0$G~( Pk?BQ(':W_ɲ" g:+4<~AcO ʡ<`ēa\ǷCwٍNb3U.*l;^G#hUYHU0g&R]7`"R茽Od6,45/pc X|tP.b$(uᵷG2? bevb,?e8dG"?T 01L!g 7 qc !{RD_EIHڹREC2BvQ8Cu=*ܡ}ޥ5C|}x((.a$3)F,zJř*N[^QJ< Qb1؆_D( ;RwO ɤe}~ƃzwΆ=ts@j~!{!.1 +ϑ3h+sGڜ cU._S5Z{nbλ\ze}NR3WQ.{φXr8HEIybs]ܚCzmL +~Dx-'#u_ZØJ-%NK&MK+a\ =WLue!yASuIdȌD1,7牄"惓`M )Y~jr.7\%HiG*l$2M*芐34ێIVys-5(F+ $)C5,%ic:` _V`Ԁv *A(Ѵ$N3DL)g֣l)M=8w4N"ؓQ@c0wYR)Vեz8|47<нL,7!ܱ{ag_7΄=J-`u-fFy'odu)IYFؤѨ訤H<^s1Sxo*e Nco,IэM!䏭]ԜE6cN P.aAeDޠ9C V{f| lAf3(+?$g7uAAJIV9Q ĕ/n6+e%xޤ<6Վ\{]֤YǗaR=+>WR@ٲNҺFp:z1CNG<1#|lCTi ._4 I!lR!~ZH ~W*,H=aXl'fv];Bt?ҩ7vWn '1d9 #6AGR8_`j_a683'oSv%x܂k6'm`9f{$6%S\UP1}("͆<} '*F3lYTS\MFECgVBF<;Ca#6Z?*̈4O ND 9J/#0 1{?F u񃯺%lֽ7W@pX‹ƺ{GiZ䮃<gm\MR-fTmjImԫ,;-'b|qC ;Op'duo^hW qH4hBtGh 3~c>CvPxl` qJ!ၓ/   4q =4\:J408 7 #i+*-nz'#L8c&״/2$CQbe _a.y4†TwȐo>%(>x]8gP.zOՋlE$%N\2w0G| dDa%zB vs,&4WpD&bC"`aQlm{z=g0tH&JxgkɏwwT $> ~;z l貸t*dE0 Q4EM܃ (r@0 <- Ui(4-3AWb@8.,7 JnUHR껸u |JξR>%E+'./f-gΈYX#[a "aEIooQQ>#1^i*e!3XK|'#Q  i.Rå>բ"4 2T 8>YG,c2D6fk} 1>}k,*?YЉ̾7SØZ7g/p;oyebz6a'fέ#y^oe+R0S PsH< l^$HdkY;2' j'׉̈́buOq_׏gEa?vP `HSe΀'8]om&Z{.q5Jgv/O1ˀ:pxPٛCP1c@q.+uTv )b2tzM?0.|*r@"|g'=F˖q4e59&x&wk'.5!dU<N{E&IIzCqHQ]2SON.>z#݉tJE6}D̅WÔ<duCX&6 s"ܛY6-+?7'+ݜKBF?GWZ[cFQ ZeqѨ]הjpz[ȁ [d.|1Drn"AyBɚP&&szfxݕyAP/ϐ>m9., ~GnM>nɆCY0vhMOu>(uA;bDX4)/ -Ais+DykbנT Xp[:<;jK]YAD2Ya)Q *9Z7 '@5" MtsES׍)q) piW2ޘZz5mS['-@g7|ppP$a*?'3C)]wJ1`7hioT@lsK A&<'gF}=S̼-:՜`,[?V@V,C$iQ9FKNݐLd!T8Y҈@gji(VnJV7r!J?1)G+' B~ @WݯxT20pg@ĭAI=et+' ƌ\Fྦྷ=6KQ`o˖U9Y(B{I% Y)=Q(r/TğёrOnYCz#qBЭ.SY3Gfa*>El;+!^Ukxk:O>&쭰P.TS4&5b [vikT$W8.V/U$$ Hj0HAT_| +|I] ),㌰tX2;G v8H!嚜ݍ`>md]J|䜟xJ F^RM@5Gb,q~qETdt1@=i9-tJ!!)=S5_< 0!9{±C@UwpIS+j#-S"T4X*aDJcNREIr,v _RY t9U۶tV/_8{o '<59"!c`P.T5HcWNu$їiւΓ}jdx#0*R#w5eN^pp9zKc2ޒFK-NM9TJN^SWOO%|uyIut 2pMu6,֝"Syb6~4J% rh[zk /e+mb(u 9`!Sy>H[&ѳFS{/b:{+9QC{:Ϣ` j?wԀwWx$A}d]rdqif)! uCu@nFIQI2lU$km#3Vڞ/h%0WaiVprcFe׷Pz*r0T4z`5̚HFyaLz5;YCԫ+lC`N'R9*kl_<5_Ք_T~RUf_YSqy>2 F pnY0~UȵKk… U=$i =,;u#~WeϓFWxV)}MG5kcjroo%M)5H.BDd3 3G?L3T!dLcNri 'sW`(S ѓS>Q(? 3ݦL- L&eoOhֆlQzn#d"ؙ4iӸ D0RB+cf"Ckka7w5W`Mh➈yrΉyg-tH rÄVW哈_ZQO z{0Ua1 JME`2fjbldоM Q ,'H:vRÎ1iXf\Pk[?@kgU`jH{YO{Q]O5EiUOEY?D;;~~=cz#  5Ubc*Ό~UjdjM&}pgΚ,1 *=v-LJy|P{dGkA%t1scwCo\~uu9svig9Ս[s pleLf\?#`~4 'mխ7+AT9HiM2IB q<'V&ҡܦC>./@(E s pd{Pc+|cx>@̮ϑ]f𚤏;"<9rfCPQNLh|XR\9UGɣfe7@k)vvwc]8P zg(4Nk*wDD_1GE;v~3Dʒ_gJjjA  *q腶NsU24>'(=<7,Mma|M;Uqty?28fGgbxXfEqrdL'eRV*!qܲv"/-ygeSGĵ_Ι&( Qf;N d!'7Ӌh|c3+5qxEW{͹78!Gx~7֊bZ^R^8-23x^gGF _{ޠ5XhbPg*sJp;}ι GZra *I3GNnP _ Z&$.+7ͬQ(˧5u{~3ro&T'}91Fp JÝm PoyUƚQ.'q%P47NY$0SL~xr* -]$݆66{Ǯ߼* YZ6*^$"M';iAqSօ'3C|ꚫؗFy\Qoe75iÕZ7}`rŮZRJhUeq||)a<8~1q;WD{P3qDi3F^ IY'1uQy~y\!)4)@G;@`B)No e١Bb,/\^?/R DYֆȘL<ݒևNj;ҫHS2 X;Or?|\uab^H IH5? O(\DsGY9 XLbYo=`qE_0 Ϻ[2ICpCz"=_hlH;y%Msz~ⶹa>DݏI<̝8OZRqIԁ $cXb0y=pKULfHH1P&]KUbWG;]h(=/sfڃ8RgBh8lx 'X&+ a9Ǻz@gOo4%_HwW[&& ;J4`gl'Zx"k =b7?-c /&6tYnsءQ@M}@yTP,wK)SF\&[q I`ը֠SZÝyJ1I+tl,FZa8O4$FEH84 8o@ѫ'FiJ~)э#YH,q3O8p'.|g!҃5Wh'WppK8sQ>$HNTK-?U uJ (meOywpnx?%8~vqYP?y?/Hf_pٮd8r>i]n16F4i q$@Aq}֌V< z¿2Q3ߑ lu$$Gk]C+&ژ0Z"| 1Ҳj5'mtC ǿysԙddi1OmvX TaDnt໅r@f)nZ?I6Va j0bOJN~)mmW}&:8\U_>0mG~+=@սoJu̡x "KktI7ARRqNG89,cEM$"|̨ [Lg[ʼn _8L#F 9j6X=PSݨDzIb6N8iGX9K/CXÔ x,Sc:Qd:Q4+ <"韚ʶ1AqAwڀa.j.k!5F@sl[bUfRm/U%F #  ڑ9T)A zz;No]gx>uׇq냃{3ͯ}v(VlY;6<'RRQ*.Dy. JNs159@N6Tf(<"`n⽷~Ѐf~Q]Ǥb%E Z~;C>;K 9=)&D:kA ?_܈AK=}jZᴒSDMj]~[pb-hLw:PFgj.9ѵPj@c¢:-b^͈D0x0Ėa}Kd@oI6dBl'ptwGSWߝi:3-riݶ9./ *րaPt斠(%7ge|1cqZYLhxQd=wTr)RF1صB19EtkTj)k v"黛*-8s")Vv/bBwϜ!I>BͿ48'r JH??o:"$TSG鱭LlhОRU |OjL1Ez:(<2 Sw-FP`kF5Zs#u:jo8+0Æ T.wޮB689U3O" @l[!Aqqf(CdHWux'7T7g)@z{}kD rОNsdޯpz a|cRIEZӵ)G[iבɮ{yzQB= ;ă)qْE^+ЃTWA/sWRkMl— ֯kkyO0=3{‰?8ves]9&I9LQmNw(_=TChZC㡃 8}Qhq4z;}Z4:;(>.s4+Qn-lChjcΈeME{$qМtd<r0(p!DMdՐ@@;i8:xΌ$\»oJxJU?G4U)@JV9UvL " B)Cì|8C}Û՝rc+XyX9+m'\XvPxm{&}KfMCDOrv,UG}ljYpg%r{yFC(QH># M,Hr6A+.<0-)t9VuwgUO{U.4&ƕ#quU1W_i63QKpݓ0tWxq%悙+B׶7AdiJ-d} 4"I6T}EXyAУ0$+l8`ӽTDp]aj91bA<'KK'yپev2D~ua1 ؀uDG滯)0hצ2>`;`w0oG u.:' |j@^j% "uŎS9ӏ~tUxgX)_%sYS1 v"6UE( l.< fR2^rb~U% j3ɕjIvIo CE>rd:# 3hK X9E03ښ?])4x qBC=HBLJǮ|چ$m'ЧTeB{ |l>ƫU9.2UD=2mgU p5r^4dx!H(+6 O(\[ᬁd! vWJ1V,hne%%UVImHpz ,w7i($}p j4FH`~,*T"($ԭb[MCEO+)0fPG/:飁4/oa g%zwʸ(}F!~7#T)U|R_7l G ܾvz$2Q2x26Mk&rh9Sj&^{wҊm=$rKՉwD7Ӆ8ڟD;~%}м%U S/(5CYe5T]pV.*DGCwq[MW3-Nzј R$̂E%`ɟePD7Zd]lt/A?EO|հnk(5t1n٘5a[,6{Z$/r>G$9n?2A=D^뒍e?ju ]wϷu/irgL+{+9:C_džs1uRmչ屙(Ϩq cxcɉRYpMPhz 'Fi*hn1g0)bXVP?v#shZy\Kǔ@ģ@Vn'}}".B( ώrrgHOxwHT4̅Qq᭠HWQ/2zFviC' 7fmP8VDPBtWZ?b! 9pES`]P|7ncjl0Y"5w a-ҫ r䷶0  pfS6U8*:̪+zmh(gK?{\bA ? Ya>L8}{@Un-G #i~Cyxo`lgN9+Z,ԐJk#H |x2q~\,GZLO3<y\(bWU Ds{Wեʧ[<>K{P&FX'-Hm%V0^ZݭWR :R2A<0zXp5݂|Q8OFǾBmeۍv[צ83,WGV~yi(Ú=WMza iIՂi`WLZ0SbZ] ӊ/cUS6d7Db6k !ҿIKא5_lpzYh{7j7sAOO2J=y[*pX ?4oK脊 -s2n> 1HQT%D߯9޻*ǰ'A)Ҁ"rOT:_[ ZS0Teܨ5풹) S/]?Ϸ*^+=6gԸ? ]qTcF-F V/h(Dގs>g!ݼvmwGDQ'>/~%SbF8mދL΄Qf"& ?!ps[Ms &jY1$Tr=R«AF&Ű\͉vTʀ1h^Hblt`wOC!`" \%l)sqh 8=P)bRy ݤ>өMNs;^Rf ]7w"48ue PIj/qw u8}2 愭Cc))tc+?̈!RFߝTA K>W!YU,&XsKA1t#ٛT7uS wln=$k5V[MeRfImȞxeTgAe>/3tN=rY-H+!j7#`?bF(Ebq (Y8y4LqWũ}BXFRpݬݫ5R{ifHHf֎_9xj؞|c1 _myeЭ#%d^MT \lTQYCcܑoRn{`uۊy{]@MbC5xSYTq}}{ip~3Gp|hd@\LGO:w~apefE߬Tս{0oPEs+^n*^ rv6~tlƶ?vAhh3 |~n2|d w*ߴ"Z%GU"aR)p@SpAud0NV1ftMӰ0iJ/wLYCML{ҧ=zQ+Quп^ U: 6w9 swlDӐoIw30AHb!iy]"٠R4 2.`zuZDU抰ݤa-6b {:. f2ƾrmj|M$j`fcA".V!{AA5/; aDKj3DԖ{l@EPx,kXɑm7w>?BOLJSLͮL`nal1eE[b0J~t lU+uG"Lx QD`!i1FlMz}^t\07#6nZݛ(TH`-mx&ef/wƪJ6ZF'gy" /腠g(߷Ҙ9]$ vCDxyoVJuRxCN^5UlB>J9+N^-$xiзȡ'ne}Hhć)|⏉0(Qd ^fUgEArl/ #OJ-PヸkS=M7$h=VdG ׸O/706w4Pd$~7zBpG*-Al3Ut8L#l0Th!4xk3il ')usڏ(dA[N%2q5*© mĽ덆˫•!Ýj'Ta3ljnբN ž5$O 0G#/tqC aΎn0x`kINb@wIf$R‡]+}Fb҂7PP4\05Gnoeo4ZR"C-:@2>T0~]U>#κBGxtQ\t~Y1KWXl8j&n%ly$5ѪBW _2kFq 4_P"F' xFh="Cp>d3A8yzpJ YC~Fb+CiH>N.D)ާShz7> T;|G +Ӱ!a QTew-1v3ծ9=r%Zǽ31U I>Y(_ ]&VOE3pU\m h %w4 C0I_B!.pW?C|ΜRn8(@9nQ v /|~Ym[݌ I JtYmn(G&l`(i? ݅@ L ١ӥE6ʼ7 \:_h'ONWfP`]H 7/ $>ǀfRG'T@3~Mx]?8{ߡ'F|;_H#rV:"x(/ d$<ӊ)zLk{yCG@=ImíɄF)^*; ;MUν{T4ڤIaB"Ir#hȄY~!u6RY0ssKCYREmf1YG vĆ*=vJÜ 'c /( <)Վt/ceh EX9*% 2ʍ$Vv}%~(W!6<~{Ҧ>ρ>BXFs;&픪tcn#!}ji Q%ͤ5?1҅v+1trGb- ok D~"un7iV r:='֣fUPl5/&fP"͵܋?;@ kLlK?[VgQ G }Hչ[nj6J@QH艆I~b;XFm1!w& #0h>/UŕB =NTVTC@ 9/v&^\|H&&QWFL7I`Z+鞲3iN,ٲ)BH )60(Z8ndjXyc⣀ta%Gk鬹ؔ聳< e .meuKAVnZ٣꫒!KBƽ>r*A2If $\L-$д8%MLՄfyO򻸠 XZ^tb};8`WjB9PP ?dbPnMoF?(CLh,}T#r*eVkn!%f*7*2itXOF( R]5y\ NJ(G8G#бov<#>g}U1q7؎kld=zr:)~V >D:[4v"y!qQ4S}|&J\` iz$ Dp%W]Ēɘ kdDĘU7@p4,`(ƁkQ!XDc-7ɼ)NC_ݫ nJƄ$ml=?izCFF$tE§k%Ҋw!+r£mR''2MU)`%ctؚTʳ$@R$ZfPцncpǀgFnQCmRœbm7az1K:G/P1 3hK=.RކKh3j(;k@XRmW- aǨ8mZcYah>: [xƅi\h cSNPǍ>ktO5|B  H}ײ*K >:G1P+(/~L>t̀yT:`}7v&џxxH7h"G&fL}aq;SW%>} m/ WLOzX!0DlO&si\ƾ;踕zYnt6ꁶ4 󖍭dι4FNWP1x?nR`~ e98vM;uX-&=ٳUe> Pl$-]iyWݠ )b=t9nKȀ9ƍ\VS{xoh|pc ;08l4[iNkZ1we0YCv7 nC9KD#sjU̔/=fC]f3:򯄀\C hnH-3y4K<FtâBeH}1+)BLN#-CA!z@ uHbbN+8B"#a>wFr/*A-̐$hNk*Xh͈4 smBM)x ?NYFg/7irV|qsM}Gi9|PąZGޛ S1[m be Sm{H>+N nꉷ)'.-"( ]v #;V;q/w%eufMtŞ hH>.r?9 O/jBM KM1@s~5H1Ir~M¬!geo:ii Tzr:_ =CpZUƂswc4\#hdgc\$r܁X~(d{Z`'C0/s@/~Ϡ˻ONa`@Y[J|E>{n$јA._|.z+CIGUm[^( 8D9]AR,3JmQSXbC5p2P J*_?,V6+Ӯf0O\PL*~63#dW)lӄ|D+O(Z ,[̀*.u[I /j6bzSaBx^Id1SWsrg"aK {j~4Icg]^yyXRҽȓ4:v-LJeӈ+y``_%9>4QV; l6=h>Ѧ42rW&[H?ܨtYlReQnA/gHiTtf<5_zy5@R:b'\#qIAΡ\3|pw5[ذģjC"JI[.^/,9t'U~nH]4U V AT=~[EfV!9GG˜{"5'v#e]H_dvZcX(`Xđ]b%)`~FҁbL]nY ٟ]& GiE _ך(V@;F!ah( X~x#(<7 ѹ|pq),~ɼ΂ްI&W F4p OZgCcd\m0pn<Xi1= ţfMy#x_x!Wixyt|a4~iK3T)VB8_&t>Wt:#D1s/_쫎r Tu|VW8rR.eoRf.oȓDcpn:Ts$2rF 2t^ERHvW5Q-dxW7 `jiMG۪mВKM GeS3nW0L" :Bu̠ȡǕ[v5)Y=1ԤVRz1+XpRd*f8Ѓ0-g'="rx* |&"l۬QOw8maDrl~}t⾑iH -cGK:>uV 0jpkWoNPCbvX4UٿCvvXMhc.fJ&,s$(#wq%,T@09)l̸K;Ɲ7*JDE c )L2U94].֏6kYpw@?') n('xo;Ja9~6xŻ2=lKC"jT˝JucOgA<8M_GTocm 瓎_;$d d88Q0$8Wt薹$U;=jgy /c#ֽn"(={+W D$V bԻ1Xe0 a[G1,q9vWdt7Y`ydU94 -D}n@6j $g%# &1QVSP6D`!ՙ[~VDx$(6N_v2GVum`Įi@Y' Ne-}8(][zGrrА <[剹\͐ U-{u '6t }+s)rsg׳4C6 ',qmݱ_Tx~ʀəd[@ iӡ{v7g~>eE' ZBIJfY#)r$jѯ쳅n`eJXXvPXK-Bik&xNoMBh?XlQuKTRĚo|C~}5]y3f"rI!H@GP0#+dh+vaCoP>iB͛A+h[qE {D-=q"pLD?L5~t5܈8@fNįӷlP>_Tp=-phiu~ I4ܓ"wR&߰QT0e.u\@?~\I aqIn ׯ3e)~X0^lRrUa[tՐdͰo3R;dϺTK:~|Ѥkޣj !Bg]~  xc]ebYӚfe;& ŵEǀEzrһն1+81 ָقbjz_j|9LM _6}]\Jױ*1[ 0G#A1ד tTR?bzGGNvDq8Rl՜.&˚n;z KgA AIf6Uil̉vZ֘Z'h= [1WfrQ<{2.2I~6ܪ9fv}5#?F,SM~X@u55cIgHϫK'?v|h^O`Vp2͖p,<=ka?g"xqgp+BkNcArdcDA qpye9Ñ8JUˢ9,-!Y=a?VFć*Wd+\#k%efϭ1o7ͼ!jupe ,A-[WOOZ %2l ؙ>4ry~E ,آsxT 'u?ZPʜ 82p)]ȷ Y Ù#'/r}xs4bL ͋]Lm(EtgC> &W c™;֦Qgy d_Th ]Sh bc4A-9MXI0^LԲ(j3B^4j ZD7w 9{3V˫rfY=sйq@ZŎo0VȽX갿lgd-;uL2,2O ~jѯs2も +>?6!(H u x p*wʅG3<>`^} m˫{:9&0 xyު RΰPshZjsV_T.nu5~l.ϴߣ@U὚=Wh2 8"ɊjX)ƳQ{}N>jI&uy[3wQ 7?K]h"x씶32)ğ`OI7? kA AA9<hXNSS[O"9& 4rs`l j /!+P7So/<~1e1xfX 0Gҋx^c}g5 uSnd3Lk2c^o]sGutنEo7<٠PN%UfS‚0 .F9!* ɹp'紛vJ,I|,#`^o4Sa!Rʻ}(61%ҙ?_XmfB>iDM i04'Yuc< F7fDR5Ҿݻ#>y`Iy`Α#ͤCBt8AUK/+M1*> ӞN" V s$9| ^sUćƻ<2Zoxh,ZHplÕ֮KZ A=9-Sk̎eU, uA6Ӧ9 DgfeBE"Dd+Ŵ( dr> %%p+m0yqqIbM72Ҁڍ]@jI7'׾yedP"ԇ&.H$(̳ i}/re*4Qx_r"q|o]~bmh9vn +CIBE ֶ2㬭´Is6Pszv |JL*VJmQ'cnRbS-^Iꇳ %2(JF0mcV|2$ʈ\R`PΦbket;}և!s&-fca]]5HBוZoᓕL;i:.>'EE(ö` ߟ9˓LزQN3P$T\$sgu%q~5)T{[: : !KX|ISR&}f#.D]+ѧ}=m%$@YsZSZ ѧLfvL aMEk bXyt:V6Y}~ c4Cm(a)X-N$ab:XgJ]bfٚ9 jdsjPe$e WJF0|7/5G$myx=DImᣧ@d- >ũ#lt|Y@g +r^#MXαSKmf9Ҧ#:_Ƥ'Tgy^M^Lس4̹I K(0)n6 N;:p" ;rB80XܓV𥩗IVv4 7G\>1-x 6R@edݰ]8_ͪ,>ܦeMNFx[JܞXK_:ez;Y;Px"nYvd82[̀o|pu+78at8lpq*Jvٟ`q'jsMNJ#4pBvi-a 5aWF En36|Cƙ }1i!/8&g+I n& (izXK8Yjh)!p%L`[hB,Ö)m2cQ:bw%H5Df>S1:sUhLUH['!@N ]䚇9=]Kd0.ps8 ~K20\pS^T~_Nd!>hIy:&L|qgQRqDWטd܅ݗm!<967sNҼKmN&??!xl!畲Cm [fqކaPCSh]Grd%|gl~Y6o 2ɧ14Dy~tKtp$S4Yax~,\U4~{+T:7"SYkX©Fvm@Ql0ڬr\Eyci-8`irQN}vT6N5=F}>@6 M:ڇd;ȇ\y]F֝ktnwJ/ Ju ݵޭ̘ZC*ރ۲<#H wo&eBZJ* i"6CEr=7UR8jǶd3XK3`o~i &{82 Ax<A~w~2tPa{+2;6)R/48D"Mkp̏S1JPNQ#xƺ~vRS q:m~e-.]%Iя%ٟU$Slurr Gݧ ߡT.+"Cas%KΈ~f BL{(m^O/AɗE4YSy`ME&?v}1[4V*DL`!(BU,`X֎|l;92eY9sȒ óv>)Dk(i[axC "2븣hH k7aoxQMo`Cπa #yt,߸܀ [.+Z nx0oe8g'?%&%1D!sӎulӇQ.DwxI$낾X@AͿ5՟9: Je?#>dVr ^?yc ƃ0,Rm,7/{z./mpW.(= ztbq`?r*EʓL";Kjgo9 'L4'^#D~4yпW!67&Y+RH0?p#OJ ^ q#L7,MءZ֛ފ.HljĎev;F r'oj 刏t!xvԲw] N{lLG7FRcҤ#1DfGh?܅J-9 ø>R$IcL_~7_2-C)P.p)7BDkb^9RYgi΋^`1%Y1@NkKU aCDEܻ`Z\(R'{Ҥ }fbus/L0CLgM;[ yuuUUv|GgmY { <^3S9z\N9cp`oe7=}UiG-qCi'À+-PG˒ꆄz}jLp8Hmr|YOs G1 Aqf'sk.=U+UB Xuz#|t 荓=虜d]rq)T<9o%Ųddq%IM>um#][Tz #yÑ R4ݗFEƒg[^luw~ oÎ!|RGNV@9 hFFt$=}iP/(j$l1  @X^׵/&..28^(OQzZx"nUNXOH$kU)eC%]QnmXU}5bôe\^fu 75bī yjVborTgT8Q}-kBd(Agb^&ѲjY3|hcr|g>Ⱦ]?@S9;/Jߏg8&e`mdN`㇗ P> \ypě283GɎ]`)Lp?.=H'DBf< ?>gɠʍq($g2 <8;pV=[ ouם h\'Cʬ Ƀ( K7WeF8:d#e%Ǯi각4pD$h`Fm19h~#RjA\JOB~)Ia#.UpWWcU6ֹoSw.KvN/l߫ΚH[ `~uՃvk=;ndzי@Cջksr$pF?̓;PDAG"=,o$4yΒBI/3-fעKnl]G1}kO m8hT&*Wв /j<4Nx{c]ŴAnP.W -`3o=>8Y%9UCSS!w^%X3۫) /֊ ޹<[1Z.,,yvm; x;j1ϪLdfmBSe)*?нPFA RG?׿Ec_?P.+ INÁ8|A$k`Ⳛ,N{kڗӊv()s\aY wE*s2v'-a ?.07KLW;VIrݙ^Ùw&\O4 x sC! ᮗI]$n[0<سnKHB~.3=VV]*W67f#%Nxph.2TneB5,G6k{`㠍ŀ MM?>^Y2ʹA@ȝdx9ʍ? cxXD.}T H4S5K07;7nڏQ 085Uks{' nx0-H, rGj:*0R49Ao;r=]{r3Ju3YoFWfS …B[yN(xJ،&)E]ʃɂ1ߘ(oe%17r?Z武|Ig9""!O=s/&/4\P $ XFgA#(p% :>9Lk=H^AxHo}dq_& 閲QW[DIF9RS'x ,0`a+cznFݓnH-*cCH|?Q"OztA@"X)'w@_Zͦ 3ڣy4L{oHPM ΂:'2m/-pWŏ9ǟ5i'8cU&^A5sCD PQ85Yy{6#h2(s M 3gx)1pd=ф%G|PX-׽t,O%?zgE}X1EhF&LhBk`׿ "p ^rL@^T53"RIvhsG8P2P sXmϬ ;=e!?j})ԟ@vfm{1=l7 4e3$GHI ]/q9Tx%c;hOՈj7|Z tfx UF~J40UAKKxޥU ӝʰ;seF&FyEhSC]Rϋ9\Κ#!pݺ@U?SF%cWfАVO))NY"uLq:m·=^2xAfP# ,L=*+|* G̉; &sn7qƮriQ`zZR Z\nN#46RVnɹݔ~Úf_HHCe#1f 4+e f1tb-tsVF%QbrsC6 s–!I‡*&A3P<҃]9otS|o52;)bvwa'jsTMi~>kj$b>u%\Q籐}TW͒тz*m)E4Es: 铖rWe<6_JخSG5 X%׉7g?mOZZM~k OX]͈;c‰ٚPvh3~ IWv h!bh+L//:tNא-)v%F )rhE*'BbKGcӒ6\ 3iĖhy>r#"K)硇WIWWZڸF#X+mI!aRYnp /%: ֠xCo4Δzt!A"|>Io,¸!!Mk@4@jYYU@6H 'ݝ0L U1VګChw XYzV)Tz%$lЙt;oq <232xZCQ}sަD.ꊧHUM>ҊwhӱUC{@}Bţ#lhnL3B$do:ZX,.m=RQ]\| s~Nm3WzrӦJBI{a1Vh]o;e@˖\M:ZAvP a7q!F]Z, ,Zgܾ<$1)o+/U+جe+L1,8(U7]`UiNoR3+eJ a$l0& 2:S];Ԩ)ž!ϥoG*|f9DcksKjwQlDG78]n$`ǚV{y3^Ȉ,/o*֙zFVziӆ y4]9[a.=N{U FKRfoA w/ o}%uO ?tḤTǰ&Fȴ;BjeEeA{v"oY-Ef썈r9n#)bs/pq]BM-L<4PKl5b.=@JP#maCMϬ#bPFx2ncH_X#j`G,65L4^{]zM io o̽"HTr>D٦,|> hl* V!IgMeڦ=Fm_FxR90t;3QVUr\.OnүM#+p]gfi5[HpReQ k N}ӣ,xdO!,T딽SD[`"$_7b MI|sbjX/( vT|1}6mSGC~Q j.^n{ZǶbIDr6v5V(Ә_v]tÚhdɋ83>v.:*DaJ$)N _ky_awaf KUsHdٝ:PX=[>ckPQ& &oI0͕L#xtE% \T˹C:2d8&]L9<=&=\/ \ ~NoNK}.bwz!7,;4lnfM9 זz^Mja+8kdƄ2fԵІia3V%;E+X7׫".(5<&\xgY=dײGWJ|뾸CȄ2!t9v+k'S!k͚MW")LIm,f@eD;)wۣ`ڷh_or0 "H@_k/HQKVx4Hʑ.LXք%=U.ی.4} gka_UTivxmAH?橽J e @(gR' 1o!Tp)% >̹@#=ҋYuQ$4YVV >)u:NK;*y~bsWmɟd"AyukؙN2v~`~Û/7%bd Wvp.wZ5u#4Q[?ܕRgl^$:lQ^ܻN/>&zDvVhŇj D"\pތŶcA e\v6,!#.V"%¦OVh(@UDF;4/Χ82WvRdwl jDR f{%"v˒%dbl.EZ|6cTMȮhpϬRcŲ铭Ғb  HՊ(H3uhk ;w Gh)j#ֱ(VD7ib~?&l/iߵV"ӲQcnٯ2Wci.ɽ: /YdLWI${0e J-dB\CNt4S\N=T\qFxO=.k)p@xхaP mUF?6 "LfdTĚϞD˃ؘdv"=f h|-r6j_saBgƇЁGN: b [WzqkYs^X$IێBޓd'-[M3iʧ WIzwQY ú:orV\b?i q`O_U McTo?WFO)`-`Y@䰎 /Ɩۣ: YZ