pki-ca-10.5.16-3.el7> H HtxHF]L! ?*}} /:qqk]Fߪ1~M>3lkl@ve7]oR20a504225a7c04dabba1e869efd40635cdc14dd9 %VBZ>F]L! ?*}}q7x-TƄhcƲc.m|>qbGEj/Q%>8d?Td   B          > D Ldd d ld d nd q dvd}ddHP t ( (V8`9@:uGQ0dHVdI\PdX]Y]\]d]cXd^}bdefltdu\dv w0dxdPCpki-ca10.5.163.el7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.]KZlsl7.fnal.gov$IScientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL)@1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~-d>Ed,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤]KZM\4>]KZE]KZ8]KZ8]KY]KZ8]KZ8\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]KZ8\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]KZ8]KZ8\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]KZ8\4>]KZ8]KZ8]KZ8\4>\4>]KZ8\4>\4>\4>]KZ8]KZ8]KZ8]KZ8]KZ8]KZ8]KZ8]KZ8]KZ8\4>\4>]KZ:\4>]KZ8\4>\4>\4>\4>\4>\4>\4>]KZ:\4>\4>]KZ8\4>\4>\4>\4>\4>\4>\4>]KZ8\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]KZ8\4>\4>\4>\4>\4>\4>\4>]KZ8\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]KZ8\4>\4>\4>\4>]KZ8\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e8c3af6c28b1cde9435fedc391fc73c63c3c15b9e3a41ce18c7eaced13799794a02d78fd73c85cec42ec4c1823cac0c97fec0e80ca98ee88a49c90029c59e4fb20c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.16-3.el7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.16-3.el73.0.4-14.6.0-14.0-15.2-14.11.3] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.16 in RHCS 9.5- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.16-3.el7    pki-ca-10.5.16LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.16//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL'@ OTǧ[@r!2u9S Yz)6-_(>&؞~Q` nm/KgPsI5o '*:r)zK)-f_ 6|z EQ$8^YYlG8iEUj07ځӓC=/&}BAm𷪶Qi8T)AT=xv_ucseiM>=ZLLG@S:׺[]|5v×臭kP[K\}r7jmefoC^ )u,*J1*ZC,E(*>;bV/ &Xs.ՉCsY=<0%~Wģ!+NIe-9LUwˆ1)cJ1\z/;ח$Aa{<pLM;I> KDA .Af %670˒7j+;1?sb7Ā#01 nWۣKuѹۣlWmtG *`(UZXR!{ []LkN%`d{}\nnVbACr)5`r>u+~S*sJIY&{{%h&KwqQZPxEvlcJ1+08vпxԦ9o"l4H[keou(Z_ǕUj, !#yE ns|̧K`؏6y5uhGR5!%cIF;M4s0˺I ˡj~p-z}1C,3M f}#$|mzZu_5f4X0ǚ' d|m賏We;Z\HD`gRIBQA%K-/;Mڷ(=?a@w[ȞE1qXHe+YlNba?̏B{;B5^|%48gruY7bD-=+7uhIїwři CydEy9*K\z7H¡VKiH mE;Y?f'K9s3Mb_6su]F|>>Ze;*/p"{%@dNZ?~ S_+ 2DBlXɩ _xJq%H~hQڙ435 gM&j*Uƣa*)үaaDyAO1j 1FY;#0,^;h\I4% ӯx;dvzgA~*Rdzv؊w$~ PE;Tq9ckz[\= %~TA]s۠S#HsvFvx0VMUe]4ngia+*v*gLAuܨ(1/=W~"2DSߪ ڌЧ4|ڟ!y(E\y5ב/|RZp~.%a%ֿ0e62&#z>*ud;t*.FUKo>" E6·ӫ<~Hglv˿ wH(ɒ/jo+|m~3h5bؗB%G<}!d')`iWa#HD3 hCYlѪ`i}&5+)m>WF^gˀ8rW/A4̯{aT7_ kw{,A/˲/_#ў;Y`Y[9Zzy0›TE$Mop, [区޳!VMdnsئmdJثmkY͚7@&;`7 >$l65kTDyWf_+$ F[e+)(Ѭ-0Mũ[ũNKm8$M;&Ϯc?C/w%`Yb JdTf#CXgܥMF{84f/j%sa [s_}*[]g SH-8*ԕDN#bFԟLu[1\b# m% GiCEܖ;>WESZmMZG/β3<Иq&TnVQ!ř$E~|sItLM['ك@O80X7&@[`i4&SL"^ٮ- 4+>]2m. 8;<54xpi{?ywÖr Ͻ1e})]}-nsf7?5既^o݅pBNrZ}%Nx]iX}mAt (CGUȞ?@o ҧ o8zu>iy PHEWZ'/vT8[.QX*?G%2l*0W.Uh0u",gYn(W%9q7:n|>ƤА0~Mu? "h_75I H&Q]eY&a'*ijjmH3ixu=>,I>)lBkošPNvWKe:x$q%Yto՟Bpl@2.y?ZO@':rm/x DOq`K. ^}dC8?t Ņog=zJѿ67O?\Y7g&zf-'&`_7 (xh`&>&:tPY4f0P|ǧhJ| cM9 LtllgrG  7}N/dÿBI۹O&dh3y?u_i-M<#FIߦ-q;{ <̵2΁v&qNtCw]*:nP7fkPQl-Wݜ#H+ZDtn7VnPya0)}#22yѓzUfK3>FzLC&O) uG-oƮ: ѥ?(d])QxaFc~mB) hrAg{#E[Qc6<!u%9) ɺSɂU񌸮mEUcŔgt me}@X,B0W+NF>YHDX?+BBd\EI9ZU]܍jz\|;>YuQÙDi+3C'D>$]`\o箐]\TSRw\8EDf]puRG V榦 )مR-K[qV8`-:'o dЩ|Q ;y*vE9@qCZ@!m#Yi5y >' 0Ew=6@[ ZSit?At7{="F^vIA !`FB{0Q=~;! M:LP9HB&+uU{s}E\%ϒHyH2S:an3yTgf0uqnaGJv,5ٌżlm&⃐2Dވ)+FFNh@m "TYgo"8~6*[ڮǔv) ۑӉ 9Ҽ9(%-O.u鿪 Iܧd_14A 8TjDCdr!v,ILquf **TPh/˱U%//D7vrLG;ˤMr9$Vv,(IEJ_uAn#'xfV% 8'HjN(:X@g kCi 0G=='ERDG[e_ +Ng+'0s 1nWuApy+ZP{hͲ f~̀:H!_HPw rra:K|\MOxŨLkߑ >c߬UvID/%g0X ^ޝ^Jd]6BFM05K$آO5 Gt OXKO1~UC*䥪 <8GԕhvEm4jM @W1`f,kg{*h[vUf0o娞 XYa.ns*{m\}t1NEG%aь𡴊dKmq!*WDЎv$gx5%iD\r7|CgH 2,`{i]IHtdȝdKjQrtpDˀ:hi 6-BIP@q֨:.X/ |e`P jcP͐ ^IJ'e:m ~d{NڴIz uxS,千T!Hl@#kVz1wRN?ΩbyR'3[q2hzR/%u*SX!> TDQ2:;EeےyZ|}'uVqaz\:s@cg}WurEdL6B5PTGO"ddIz.bdeÙEK ϖ:>:f{/5xT(ۢUK@2S4~K[fb%ײW>&nꘘvKJj u-fчxŢRlv)Zxۼ!eYe@J?ܺ/+vH{|?Sd.IZsO` pB&A5EpA:pT҃+qgp^f ~>I~Mwiuŀ*9i nmS BBQ.%G|vn}i/ؤ$vb1}4Ey-]*5։Z},GCD夶5-5]#!'];X$]eFeKөxtNs_@10 O:yFNxّƵAzVȁ0LZ[zkXSjX<{=- u^pu1~eo?V6Gxv<ʸ"p njrW?G vzF% bP,T˿J7qȏZq0qĎ:', =\~J֘>49WHgr&2w?CGi|'rek):]*bq(hsF M,&_5^ 7ƵAӮ)oQZoZ8BɂǨ=yT9.qLlxLsc˝|12 U|HPj ʱ]~Ӕ#'PpT`C*„W{*6/wÕhj*@ņX'J!$Z 5̎=E5@1*Mf)e*^M. AڒM&bK| NU(_#GGǰ6/&ְCNn2Uz r@|em{3S$$X ✻ ѩB /X=3>Xk!@r%shw{D;2^Ρxq3uX^`[8+Ow%;GWK ~bsq 0kŐ$?RO@ i1eLF )R KxX!. 5-ñF 6c|ۘ[ɆFh8 -2c\zӳ1rV\-@uEѰ֕9RY \06"BF/jB,gpIpUsv*]<+na] hfT9glmΩ?QEڷ)gw:Vs ѝW0*-Tܶuh6)gtFMJh&b&:~_9W1ڶr?8O3i҂=RDjᄈ >?!)z/~gsj4 Oc\vbfP|6TTKΉP8!m?gO (7Mýa cG.=. ?o W5y8uȡ Ҵ;9 ."]O;(FuxNB\*GJ0ݜ$P5jNoM{WX[g.جS!kA/j tkc̗LcFUؔYEC0m9zr$AJ#y:Wh`>!9# tӨo76&H',5!rsYa1G*Kw}gcZ.D)[ם,>GX2ttBZ>Jdab+u$ݱCЙf^LӢn?yU&r2*)@n s7bxro+E^Q VmI&#ov1`$LlVSsI{,m%HFm׊i 0[ QUoj# 8ϑf}$!DKkRQM4*'}16^) #h9&VQ-ToLhp͠!ӉT쑽4/$j)Z UРzApsTTQ?r Y qm`tjnPNPǕZϋqř} vcsZ.΂z?;nN^y.Pa>ܢ+=H7uMOBB67(+8E h7VTb&Fu{ĆiKP<[y/fAlUCROBt냤ݪw\^՟nDl^x=wUڻTA7& {F\LFBcr\dsޔƻR-"FxBe ˄P=(ߝN{x Egh \һc>, (]R @V*e$m%Xz;!iv';m&У$a^+= eѵi|P,-9“ꨘkE ]O#iK6)219#+բPۏuw#M I_*TUd)L+&yQҿL0fy(?Z /4t]j"ѕ7L v78o!R8b"V F!ݲbfa,f[Aϊ\xcfv[XWÃ/5z.#5iL9_*Mw.G ]9EbB-9@ed͐焈4^ڰ`nJC`FP?JAap.TW^[K󴦵JBG CJ2cqiKւ!-Je4dseQm|K=\ks}$ [m!;pSػb[_pv,~Bǘv<xs{r51Mq7Sk0N;ND;EֈCJ$+`O_T"hi:g^`zQT_Wv QuhORnt̺EHpr7S";k &., Gbקq*_9_|p`@7{" :8 m*`m'gւ`-ء@k@.[߂qmbJc{e3|,XQH+(9*L5}yиwH0mz⇆=ָR2!0=u_o~^)ݹMF)[L,o', ^<6n$Nu&&=wO ~ߜ,`[0K[^ᎯR˷$;~w-´s)v#fq*gP\@fJJ0_s h«[Z](^wP_p8Xiz^aV7n7WhA%phH#;{l$C v*fs4|쁖c-r: 2G3K n4DNW+=~kTvARQg)th0BL} UVW"$rLm{J_@"^?pۨ£hV2!t+v!>5XvQ'ܚKÄl"R[$P0DR="22/2Za#cT76 !Zwv.~ص*WlCھE6Ҵ[hqyۑuB$ wHRG &/z]җ"a1D]H,Ϡx;^N PYƊ<>rljDTG;Y #_OL\4YHy.F {! ݲt>s)RH:oʺ"!tv1j\kA'k׸e>6Hט˓V&J;x:1>nI/]kwfzHT+ I AGmy=X4 @$Voup:N{0 西AtfnhI1ZKX%\ $ă8yҗf՝d9Z5B\iDML R#Nv~t|vW|X:?-|u.KMԔgC?xIe+ùQX>4_hN y /,.IjՉ# 1uiP,1y2v\J!}௫ 3u#~r\ﶝRS؊GX(<㪭d#u,b("J8ǼVkh',RSFN[s! |Du 5Aׂ0DP}@f{5v92bk7i }wHsmOшbvD">v9$_.aW{u3{{FT6k7P\BhģW;hۘIl@ذW{nkeMKCMVfg콉v*P)xӃf{ WɌQ1K 1Р`%9yެ[zI/Hۼ=^So^d[t C)at~ԷZ/<@? }ɁY[jV;ܢ1/6BPWZK#~Ó)`d+_{9zJ|Ve2Bg5b"=l#qxf>tR")rbj[G%'{&{ J3-1ܧhA܊&6URk^U8.FLTB~:*i;t-}COJ n\nS^AKh%>~NwzK hQ%] p&(,Dw;ѥj ТdeUv&hGč)|y#Tr4Mu$seÅ3R ;0 c;5nGC&#>Y{[XPא\f@Kn9vK"X?Ȼqhc9$fua9YTyC&D`RR-qڮKnt ]9| >׃æ8ܡ*`܉؅dޫA}pgfO߹M}L <.@.C1}%>0Ϸb!xԋM9&ʻRvaXA9"rOFC%4wvu{imR8,'F\I`լp/WKLşOG(Ea1LP҆4tmjZ$oaVYu%լoS]Q}Աckczb=S ͰK'_+F“< 9Jq֨nxe%1@!m"JÂCu O_9y}qt|sgN9fSLgӥMI?YªftOqD.Ēӫ @Jpe iB7cMʐKOZfr% %kTTW̝+zLG䫔'&HIB)Eb{ZrQQwĉ5A 9r<557k 9Dqdq,"z/߯M3T?Yr8q/(*KHLj5IZ.7`5md RK5Jn1r7K>qdhLe"R^.'GYxMc El~ϕi*JY(?o߷"TcK2mOxajXF Hk(螋# \+-/gyET@IU+#8LOrs5H hrKt邝F N}:pP5{Rw#PutJC0 +5A)~L\_`D` ,)s0]^TvX Ǫ*N.")$Ė^uAo/$;$RGVSA%;u 2joZ1sp#B}^ 'vƞK#})C("4]K)LJl\pB )Aնf+?19(Z!2] ( 1/}[kfb&{V۟UB>x/ֲ͢vW؍egkH"fR7'W9j&0A jH}\aFPG1P&&ue#y5_9~ ի.G<(k&p=k\ \_ԟh M,X*N#Rf }6ٌ%Aa\\')J.}t .D0ݶ_ͫ mKOc$WE"/gMx 1%ǝDrYѷ 6`d< )d<H(y'6CíVvCFv|}Qʹ>Q[A0wGse,hߌThCVgC+UD>e e5sxܺ(2386`@Py0.TM[ݾ'#Y?m/}&Ajӗ}35+Tq>dX#뵎e oD[x5y}+.rXMw -V>.^o-*2N\f6p6 (걶DB EBva MN-:g atuGȉuZň*p<@mM5(yk"#06\ًܹ\G`7\ 6 1R& DnZ[qъIa,Vr=.k~fhiH#C!)dC"1l!}(cX!߿7澇40ATW ׶;z|0>Ԫb"Ҍm/Ux=GnȊm( vC '<us$*Z>9C^ Yp㰡0oȪNQ/]N"NVkH?';* WKb7/~ OO )}c ͈OC QB%Xͤf8c#"hi#qK&35*c;^@ڂm6<ܚ`j{s1$֜7сXRGQ0D s=1<_+sނf&jyݒ0kF*﹟e$vX _o^zoz[, d: (7b _u Z!KQ>a0&uh=k]E]3 CHaZ# 9U-jyn8P'>I\eܨDhxI"jQKD[clI(\t)whMC]zS&Wb`@5Xyڶbx}9^`I\{&=m٠3X (i(5jt :; i)ٳ90#6BD! <'_YA ?a:FX(gz|t=S"$=>7zP,ӯ(Y|'J%dV''qN#Co`h$r<">`yWRF`\x^kojPj)Szˉjo{@! Q9Zj4`x k$P覰Z!G iu]DD`fnr]$Q-]Ѹ7\JL]Ns(;>"wV44;ģwJQK h ZK}U4n`>1~/hN7&w  %k!:)8B2zEoqF)VFKݏ8vW͑@'XLYtdgu 6R`4+t*uX8y8Աy,JXO~jł}H_дWD"%LJnMYC{LQA)iX*Oft^ItAZ!؟PƐ5`>( LZIÍm'?p }T\~=}+#`0Bv I^L-kӁ"("7 i-6CLlNAc*;Jn:=R&7K=׋cyEE #zx*u?H,kZ8v1sy`~CLtofl}VUc *" vdpm@6|$:GbOS-'  ({, vxxS]E]BtrJ}C +$N{F*{T@١}f;ͨЃK|::5"_KnjY]ުRR#h 7H3AJPbv|,/ؘB@>Uz93<.?sJ]kBd1Y.@:^f94FE9AcO$=|sÄY)C(&F* ' B*@ǓL%9o!^lG1[WaUz2`gWLUs3RԞuEd5EQzN˴=BZk1RsanƛH#ij|N^-쾓U:4;Q(Ү'[ IYnnLf E)0S/£wSR0pU;P>e*֦&\Q 4XQ-4DU JVG2WagrfW :R vTr(lGAz'f:[#i[]{8ګWLj2>!RdńU`r##iݪZ]5:՚BY? ~|9Q,; }Z;L&e ~w;yl_Wf, њln$[˄pa͛{ds1Jj{ %aNˏ6 "ҩ壛ExoLj)Q_S% ؐ٬ N!9T=A2\2OoFZ of%*Cz<+L$/9DŽB C|fLDyjoN~b KĿ6b6WڝYlHLaX\5A|k[QO=3M<N*se>ijP8HowŐ"&*FUmeFNk%#^#P3C;/Q2i*ؠ.I~R[|Vf=kȪ[X#_>fSM27#ˬ1O}P|RDwω_v =Һq:⋱nM¬2šM~6G2>[%$^e~_KasKxš .%+%Y ,_hy4՝iV[m15uq|n.]ߜn:؎i7=R(.z8&@xZEt[+ ݴ!BF R?XUE8#M˩qrr{UxCbW/Q$+a|PsǢp 4$JGsv<ɦWP z.e;ϮL[?v0rdi dɧ(xe!w\!3[*L1co㶾okw6^t_F"Hu2#1?sݓW9_,*Z˜%AmX).3-<9NubÛw=tq=aK{0 i` OӜƠӳt1#J˺ݎYoːUDԥD2 Iff)@;¯>Exz#u|y4g`P[.:K!Ӻfwlj܈~eXcQvq+EvwI԰4NZ1,eT>'}k!eIadhCvCYxov6B3h8W] ( 3!#w+7!k$sN"+!R4j59NiR2T6}g4[b>"L)?fP_QEzG"[ + 1 _1oCF@~Ð6|O`:H.٨b'ׂAեN&$qjLxj[  i'f1dQkzƝ&NJ7խVl4rm]ʶ|**d0TTk8 T 0*X,@glF$>+<5 w"wPr"'羉 =ʠ;Lap/œW#"ol95I\cBg W5>09]nʢDp'^j$RÒ#Ν 'z3ij>{T{` h#~p2>en(i M&QmyD 9Dm%E0 yASAedgFvsچ!)Ǟ̪/"YrL 5H{i)00D|Zivgx'(v,~.pObiLd6o ܟry"XC/, {ۢ]kc6zਖ਼zUi:,)fO6bTU gUg4ZvLa}4#*(XdۇзLO0ǟ9Qn*SzIpZ}9 B2=l"51˼OQiմ gk䥛X$I_MMb<.5QK6@]W`H]~J"hQ ϣ:h|>41$DפˉDWiBӓ>5?GnpfS*0+u7ϵp4e8mb`uQV ]9Bk=Fp qȽU:X@['[mpf)K3L?omW3y1yrnDZW%Rvc8SwCڕ/H~^_3w.+ # =PB%U#3K hgUVbkڢ&2cqGَbQ`=Ieg../,=e @Ķsv> cRWJBP[IFXi'è`#bu1p[]*)2؞"mЀZܭG [^"קgI8Y1 q°`dz|,,7?5p]#Tc#SMlsb6ڳIMTpO$\o;l)/ %\x?!󋱏q@ ~qF"z[oH"fmg7\1-i!(:Uh "P,HP:?c[Nce˅`#邵 Lu\YC.83dhnB-a՗f+ZN4%,&Ÿ .CNcLb;g` r-2ܩ ftϓwc@71EܓX\:tvf%N_SYs9`<7Ǻwpܨg}0۽p))"[eՎFcQrz-A{(^^Aδ|E5ď))}ΉaYH;'H-+n51jp\GyB sBͩA [sg2Qy> ٕ10c?R7G#~_~0BƞPTb".9KCj#>F~ṬXkhKw4 Ǿ>]g&?[ W K2&3JwF@4ެ۫JV #,(0 56iו35 "ťMh WiQUPV2>,k;=3 w_cP g+-uD{8+߳Rv}\c$4H.W6"TG4dT< `1V7` [U 'bQ:Kϲ`ճ.bS7M8 tk=_L5Hvw YPI8gpim6-$A׺(^v4ƃG^$==[L|xǘD ٘c#dHJ{O1ԛ [`sm D<0Dφ) 09M٥n>NBIf]԰&Nt{bW w63҂nNΐ^Od5-C)e? B juֲNC3O:`̐Gڼmӗ-gC`.p(*9HwL /ɸR0iy 5nw~f)2VOGs}YQM5&1.0%[=^U#^25Qտ86U&g#"B\gyVϰdžjJNY"fxb4w?%g͟j@մg絑WHԡJek+h#fcT/ΒKɈggޥ!ϮNEqe6g3u%Š8pLc0ӕ}}Ek=4O !8RMo V`cQ. jBDfhZ?^5Ӻ)7aVԚ^|-ρSux /đT`w3mx܁u?q'b\Z`ENxWxE5/*Ir{K#zykNI,{sf)ت/HWG:IrλX75瀡T^ j4 ?/E["3;wV#9:O\;{zXSȝA& u OokJ/MӓΞ qQޅ0ԍǙF{nSöᒕ QwД Gd"rj#; K!C|rFUJlNz5sWTU.R,S]kސՀ%٫ 5+ dsNT _o uϤ˪)0Hr GWf2e"}b5{Hou#opЛUB% lU>kx e#vOZG]Q,ƗA g-Z$蜤96̎Ib,cH.+@Q=Q0\\`/S{0RtJ|f쎆"Ua 39구d/^-ƠHq]QbqzY7 6Qv !~=7A߹QIe)Xi?;xw'wtC̴pw%F_ Ln;7ӻPz0?2]y?7saЀy}qlC7kΗ'Od4tQ=GZ7#^Xd+} *]'$Z񠺱X磃ֳת5r,0*cZI+po m*Jo~-PMG8nL#iƣ} WbiL4p^v|7 Ϗ0#,h2_z0fV4qga8BGxӏa_ ˂iӣW#58}4]:[! 1pAW2,#Vp|N_FaH:+w ΀%Jz SLLpğ/AsE*yҦ:v!hUb<;0VT-t>S: nG,J?)N|>x5Mi GӝCHZF-tuNehvī17Gh: e i|ȗݺTTRC;>Z3lf^)`Mĕtd;إHBN _ 7MU&v{]k1h.mvo#;4vRȀ_1$ s@BXV"XYa$I4Ȭ\2cdU$KNe$?YZhhyx(My!-Ug5j؀ -ʒU`0<ۖp)Д 3U>l!'AVRX&a\2ǧ \J̸m}q51\.R?k2KcgU(P8S(D lRZQlfFU r 5򗽤 nɋ]ݣBjEM%wг#D^l~ ʵ*ow-))ƍ1nE-ʯgݼF eW׎]w@R9FҐ;%He;Ǒ)!=|EMpX, 6ϯ[I^NAFr1,P?I $" LB=4O3H~ѫf'5sR1M$eKf~ph=癥kpDeo ;<~B|$OSο;1l̒[KՅ7D*S޴P:XHXNRﳐJ{OCfQ91'y~'ڃ*^ɦO\mmhEdʁd=9?ŴϹ#ڠL=8) Bs/zCU N޼o}s bZL gДnxBA͠ MJ7_l2p3Ib@fH\#{lR.ʝ2KY\B65mcioW9ҝlaOcͼV~3WzY ?0÷wʀ#C/ysoe&}2h0fjhYYG+~b&ed˳`A7T5TIGS#Bރ螄7̨ ;.i=/`+V{\KFBYZr{cFRqu[_Z FI!c4w̥NYe;Ųcc>[1_^_E_y^}[ ÿ˄ӖM Sѵ= qeSBr&<gak_œGBpQ ^Ԃ`T &6R8kD$G2!_; =h߼P=W9çRL|jAsS~α8yYW>ҍlR|NNTǪ6_Q,ܥ]tDJΐ\[iVD;|s ) xͳ|Ww ^!QSJbJ?8S}c ^ Rjdܩx ԏE~}0S$؈bl$nD,Py6Pq3Q` ϫ/[]Poܪ-X *yZQݴb[R'ծ2Ϡty4cWПC:#AcNa :h:h:DPJ 5φx3sX;RXWY0`K&)m,LJ ' iwo|ڦ`+̷Y_pqZtX8cNRff]՝Og+!,1yp_4) ,m ご'Zl4c}AKn!o'JO~@.^&,t5E*z_v9R"Cm_q#VĜ[`WY%(>@S$v*c46:s'fdF.z-&l9 qCt?5't /*T_#^Hn$_w^#fMtK.e|" sva)B,Hmن9C,UNƞdvzD÷2N1&y'/vrZkಌr9U"OFO ޴v$;掾!x~s3XJn[M:xʤ;dNgE"gՓ<;p~&8݊8A}\Vawh9̺9--F-w{`$z*){9q\ } HfG|>Quהoϴ&"eIq`○w4Ju.*|>"kocE#КAqtMJextOg.s!T"3 ǠXAv.H~"+yԄP`B F}H`DSj7 "%XAXD&mz[/yi $kEOIobk|fT[vK20t]=# dNIqJB7 r+;A>lLM1a6ךb7{o[& ;zؒ7l! ?4oQhtARNCL:H)+镵`ML Ȝ3ݙ~Kci.;pg}fe ֗d:zЦ d~Wh6NZ`G0Q8xΑL DUe|6j\z#G[Ob`*">\x lR+VKѶK(Br٠ZYš&I PI[bpi')8%) A a?<"K+Aq L9Ihy!eyO8$H -hϦNpiꋿѝ*KW:}_Zu|gľ}%n /W{cy󙝇Ǻß#S+!f-lK7C>K76r&f"},=ShrD E~ZX 4>ABb˲u y-ͧܬBaw*Loa2NHg{_)i4nz"|uy<)KU9wROc>Kqu9;v?!?-35G,&*T<{ө y|rKe^{<4{9K}Af`B=H4"BE8C2Gfv|ȄqE"*}=$SSKIe.1| '^DBBw$6j~,PPkJe=" cʺTǯaH|W0&8ywnBǎ8oi^}tS$̸"15|,/ݿٮ1efv7\E3ޜ$Gt܈-}EKFB$m\h7"y\Y,w15Hr\޲-3tbXp!a".6Jt 1#|į8VugEN?s~FKP?uS^/9C7֔$wIf([7CA/(=,h{QY!z*WEHӕ5֧@iw/U3FN>0LM܎\YzmhP%9aG`mˌb&زsmLkC=yEʃ1طt 2#[{9x­.1d"Jlzދ*?"輱j,3sʨVF 9nq:7Ŕ)tQ ^FlХ&hG<#94it;R|C38?Bi8CYIRd_9?Es\xQD]_ݗi:.! 7"ӤܵRֶ+:Ex9Х6Ý#<-E6/J%uYV)󐆘FFD"g2æhgG*& HDqH@6{P65S,1a|r:9¯ܷ]4n>|&B 2љ/hK`$ą=Z<E-Ґ!WδV<H뚲IK8p<5 XR)r-b} 5珻b[I+㟀JȖPwNz4Q GR:10fBy=/E2 hvh]#"Ƞ#Y^p:(dCޢRrT2eαrz>7 ߮*an1f ROH_8P;V 6Hhal^cE-!O. h6N!ժ@eC C% B[[nԜ/2\s|ZA8 MsHt6[Q$CrwGYvHq%0 v kɢ8 RZh|D(ڑ؝76M=|bV 'ۀLl h)>vCF?Ρ&Ѡ5r#b?"X[h#Ers0DC?X/s~ Kh[Fu)}0"vt~D8 gfW?*WO*dySV]Lr_OHkEW䬑 $Mֵ{Ϯa"Fu4>9cDF@4=IhK"wEt5ռ,T dާ8џ:-1#51/^b1$u1u RW^,E ܟA!LN(Uټ,VR$ 夁 X`nfhK@^[nJhL,),3`/P^ rU5bsF JF&L#"=hrdQM@vvd&˥#Z,QXxpeTMdy;$6YK51O"K1Kfs8+[EAʠ c)KW č' `>ŁQb,6r:Qr']7C?91fUj'_R*w߸<ʼnS&hW$[Sy(I~nheTy^ӀU:atP`$}0c|jbHq̓/jTLLj2'lVI6mtg+Y?nڧZ۸?45I>^;ןVc4ljGȆRQ5Vocz (Mg4lD.KP/wJ\xk](kNSgͧI?%ȎUZdnr@/6 ~&ʊfjg܏≠Y7{T\#bҵ< J΋M\ߐԜ]yGrMb]Om"K EqP~h* Gra %:,g|<rэ} dUbn> f oS_;o8X2f_r%g]GvZzIL' C }&Edv[r$r^bn )}SV-*Eci@ fLDbW(6Xʩ: ꑌ:^U0Av*~a A5|όH_DpqF O醛HCPF Au}Q@ g{pg1T0TrR#b0>MxKF!~MMٌr2uǖNW`9w+| 6.Ax }f%XߌoN?` T;CmCiPj-SSbs,4)iC8NBcX{0pPeVxԩ¯t*^qb:$L.9>4[|;6%whk{`l>7IaA q4@^ ^Ixw;j`$K"%Ԃݏ2,`(b dǫr^#)c~ *c-Os&^/$Ub,2q}jNuH%V$$ jq7ۀP(HRI~%S.T]y|v0w;Gt{0-O `~v?ifw wmv<8abiҁ,ϗdrHDr> ie}]m ka~cK5@l:,!bp)kx G`]0KoR`&O92dA9b+sSQ'D !Qppp>btP1'2~I nXXN* Z+׶ чR!*A}=ǴNÞ߬G[28U!ѧ\/¨W 4+nUέU־hVS] ˄SEgM^H8ؒ?U:zBI{|plFc7Xb56ԑg_ydTۣb%riZ\S jncuȲLr$RVٸ-_SLn~I B`nka]g7xyb}nH JTO F/B]l G৞ۧ UkRZr(^=ﺎ Ǣ߲ƗJgЏMS{۞ O!c_>lO]DfBSvxʍh6o+EY/fFҰ e\QAfMm-!X&~"O7KKg0h®lhֶ{BqdP- qЪu OVdQb&14a (eV ̶N0WM8b<Әo?=e;ls⚞9 ^|4< JY%۾>;#׼@O7]G29_IOcEd$ ^SKSOhQ|nj<v'^kCgQ^<ͥ2? ʣ?D@/@TBXW "^S#!1j給 Hb$[ | .~ -V{:EU'Ur!CJq)+aV2?ڿ4'<%S.S ]MS׳q 2G]0lp1*3}PZA^MVm ldvLƇ$iw:)]ɐ"fZ<Td|du6 plngEu`G|lWƅ;-ȅȌ~Xg 6=~AbX~ Κi<0fr8hҬhNt+iҹ7s|iY'H$zPG i0Oc|鄷ۅ Q.A~{w뭛oF${S2QOFfiOC J6]rvJ/va|$kmr=##as2s[͉=l,ODz6;Oo|"Et`wtpUh ~jUt,MwcЍ0GzIEWey k,&h*lnܲw*925NeR OF4)| ^^ K-|AӤEpI9ÓؽLVwJ~[M,dp#::=El༒%i7lOk :e ͠le(浪<1iY-\_,̩J|Os:`˵#(11@ȱkL/ؒ*$W9866yC,rUxGP[*ARrWIPS$qdk{/}S#j2>k+ВygKzxRւ %yyc{y+~ '9V̼ĸ_i o;V8j(d%*aƂ82n>4`Ly$RI^}Mf(ߋzPŠ: ,? ˻M;ՌDƬ f`AflD5#Dː뻓o'!gѥ|ym)gG(XtR#'ObžҘT7EfCJBsZkLoTovm5`~r?\YAdFN~^R!9X$/Q8,EG;~CuB"zޞxA9.5K _K^ sHhhN6+\kp-'pX'Eőav1*Ilh̖j% :jz|&/N^'JzOaT DĨ{@IRFR_gSl`te^JZ2'B|g%,o&W򐬹 $C^ 3kPlItjح;z@ &ZYGIߒE~RVpY^ a#3MБ3THB3mAf..{ߗ\~H꼟]Fx> |F&z7mY_HM 1KN!v&[tcBL€`+0ǭ1 d,3&#:ϏǛ/; 7>j 7 xK ||N^ 7DK]^R ,dfPydJ$Wx/&D\D1dh~eL=u z?.rS.ZL ?W"QlƐrEl/U.nfǬLw&C|l)yo뒌y@3%X Q[I_hջQ\rx/dHLi%!ށ9d'y+گTG|7))T#A"7=m͟ O3mO3xҫ|`e93Y2zPB@xSFY4ᮑ!_Ly xL:YRnej-]¾sYpLlH k$(t0c)ǧ(f}ӰѧQ4[؆ͫX.U"ޚiU'~+PԷ_'JSR/'qp#vf2U=+#x Eʎiul۸|Fbˏ&VME)SZMobyU/N:JS@1ɔVIxˉ0.Љ})n\Iv̀}}bCkCf{ 2='PFT*㜓)n#eWe !mIiFob;x?a5`]Z [ 8 :M\f5N̓5#r-f*_b0mpnƨmA!Jav [1 O<Ƒ"t쾄7fAgtXnڹB~ ~7=x mo' P kaxU39*zx՝0K_7s85>(.&$_ibm~<ΛBrW}.2*j+$(5#v# aVRb%J*xk C]to*,K x*+&C4X0^PSjM&B_6բ~fl`L O$dǩMy*+ma? 3}f |3<jIx{fC k,Yל)8aZ8 j4wpa/L||w+:F9 a+g. 2AE:Q;*ы)!vvuWAAێv;ﲂ%EbTVoy;Fu^*/G8 %c=B<U*ږ}Մ3AP.=3%u _O)[~YUPbtTtQ7g_)WQ&gcg8ӴnE+qh&BuV+e G#y_ _gH e !$ooc.b.~-^uMy'ZP̜% xSwU:wI2t >=e~_b%|+uכ~4|5uy1<͝OLM íј .ZΏ+(s]Һ5PT)MX0A =C=`; % TIi2=w3.I, UҀZu}]UjWc{fk}#)RG!Z$ִL~ouX ~xN"h< bȃ̍6~0oN軮|-=@=+A3}M }̟'BsCy5!]z-u68nVvgp54|V0*Mq;d ? ;$fr 7HɌgE]{­($7YR0s.>L-QV{U#Z."?ue.O.mPpʘ+'U+{>&H7l!樜_I:/ <%MzooEc/ vm\CGu>'5 [Uрuș'|4rpU>'{ȄH^ڪ ٔB3#gJ]XB`S A=Ig7^hGt VK>4 Q:=uJ2LUZ|*]aͅ뱩jk{főE稰)VMo(%k2?6*}v}Mh,>2r;zQ`-ce"51 h  @BLX4U_&!?=P=r<ֲ>߈$r04%eLF<ϧNU -Yi@BMC SGŀ/[ʏ@*mvn[jk}EvM2o]x!LvZf J紤(#Br(Tש~l.&70օZE6nCqR `vY/X(X( չiiSa7!䃨Yk{zb}8Gk,/`{3_U iۜav:Ӛ |K=h djF x^ W[c:*w픏G#/}XIe];7`S/=POjPiWp5/SH9s٭ GqîV{]\+!f\ip ۯDB_OFs/:uADuFk] a?4ۺ\BtʼnQ|pFe,֦ aǚغE $l!^?zˡLٳ>/IBmuvXVN+vEH‡Yd`.&\EX<R5Am}EyW7I̟k;ߨ* ϶Al9!jSR6cP^̵ؘ \<$zԜmM&d2X/_lj oD^=VAMy7EfcpΌq|c+,WgzsɍzڣFձckA>D$_P%0t 1i콮o"!^`<\]5Fs CSip<V-boM4 p~ʋ1͊UKX6(.-Hci#pTjS122ФscQᣡrGofh˯hv52h7"3iѿq?=bI_@ Ĵ7._Ԡ]SAyKAy'Ѕ_a9$a`o%/VI5^@g;>ʃBtNmRxhg令,nJK 1bmgaq>n#S _%rOڍșt-ٛX\RKx"Wqu,9>=Y>Ggb8dn}Ć0A0P^dn7( )!w| @es~ikصRyjra G_,O [z,bfĉ arer4x-!˛BȌ[)8 Ɔ9?miYa5|u 7QSȷ%[ P&9v1qg]m3Rk@!_Ud궈2!^ 9.;֨YŨۮТDtmz,WA=UgNkAicf9@äGVi&jY #.9S&7~F*5bϺj@-Dn%͖؍Z{ Td~.p].k ;Wvf(3";KaF78Fb eY}QK/#{E /%R"Y"xidRETress[;^s#u+r^xZ5lxQ~ +nD1=Pރn*y+'FL8+1& [gwGk~(aECstfzuc IXU9 ,T++Acl`j+Ln#zb-5%u2Y< Wi8kVY/uL7P~x=Da(& ,ipZ1mwvPw_&VLY>A ۞#N0 a>Y6Y)FA**-+ B ,> t9$Ҽ8!UI*z $72M'}/~Lg!^CO|Y a{= ##Wdo+qZf5\)wjSMO#}DtoԐ+;w˹,6XEhZUGIPrw.j[Zvz",4Fl;G*xsqR.i]!25LGʕ ؞. 蹅h*h _RyMXaEӌeeY5?-Jd}sN@ _ntbBޕMQSWZ=l.w_M!+Vš"FdWw:1;Ng"b[dxE vtkTI7cT`;ނ+V5GRA1$i|E0+rk5_BfS-˧.AAgoQV{, B郫 9 )<=wbz Jnfy,=ZB7`ԦTBH1R ]BޢJ0"Jӟ1y ~|H!vQv||gNp] "vRe~ b_%R}1wQ;,\YάIf!G4o%X tb͵Gȑ>H(y+_6Q@,41NP~39"c IFcZe1FOLD|6AVX?c 1le03|/ BCE=2EvT?RźkZ5kmN 20.M#/nLD`=$C! RN4O|ZL:HM_'e!p txWV]h}OH@2rsщ`Yc&\,۔'dYYmm86zbaLJ0/D\*FI) !Pѡa8e_GKx알@F>4vi®f)ĕ2$Y&>yL < xь¥oF NJ Q4 'ԡju3phE ̋[V= |]Pҭ?h.Nw FmK?;! 7ֲQp5&G0#'<2G.çow2_KPuyjj2Fӱp ks׍ZWU9$2 Y#7h<5:G-ϫK%*sQ`qal!h^\kb,#ƻ2`V!8eH!#YXXr׼k20>Z*CXc>~D =&bd摳#` KFDE JZ׹=+F,鋽Of:_$:M&n2rk+! !gۆ8\haP9͕nH%maed6*SAR^&-pw>Ѯ̺ Nv?R& n~CJ#\\lF9=ލ$)NFD-%mbQ7^EY8/o>2B0jp;$h zK, GǗ>| XZ}F距Sm +XgbfVAНpd^|yA&SQle'KC߸F3~g$!WNj+ }oKёbcg_)UfnF]8@~ťp3˟yd%̾ۤM *_٣>c14kG9yi2 JQ3Ytć]Bel2ٚvlDoI3g(w[DhV Z!R9uJ1?4+!=1fjNQ$ȑHb5&jU[`AΆ}l,/pd˕@U+D|&u6=p0~]Rc|r X+i^?[QCRf᳑&Gbm52)Ge@k%FZ>25x!m$ \"!.4&R6J#U!/-e W5.mHtxͲkCdW x @lj%VXaL'G`]H|49cA-&і },tvvǥ{l(*8F1WnCaBo_nU#Y$Όbg^S!vzh 884LL ss/R!)+R8Ā1=0Eu )9m #9"y%܄MRu"YP5Ce8K.ܼطm3tͤ4E~ o~d !3ĭΣThZ"MNI>v RӢwlbOe8Q 4V`U9F\4[GxHܷ/1aPF5 i_~ݚp-TJ X*5Ѫ GJ])C I>ɄKil(t'EfZ槅0!2=]~YCҔG5,DN)ux= uU<.fѴf_Ӵ =8ދ㥿O"YZòӋ%99G%P)F02'Xq"K;({0(nU'fU %"ꩵd(r^5gHH'PWub~- Xͩ[Vi`br4y ZS :]T]:cYN0-W|4l#,6qXw i5\(M&XEn}8svAsyܱJ",&ˌ |5 8j'!d5;ӐG-Bâ6nl&Bt!`xJsn5}@-G 3{ SL4,#8>CcEr`|s2lrV.5PY`\.m4\L $ЯV'm0J覦o6B?yk\_;TB6baVH\yE afxQsk]BEq_ђ%ג.P!UC:.}2ˊ8RH}'uoPq^hZy+:lGJ_r/7 @kLwZ[GEkA12w= ah|Oo!&Ur7NpNҔe`_ta!2,Z1[qod:u79iXW^CLul_PtLnYcwIj;PE.(!d`Ol҅qdU#*eL*o"e6;FT:.p.\^z:8gS!`bb,U0}d-$j$߳=Ggqh)uTd(iJjϫJ{8Wo~{U&4@p%i֧T jr8AΗѝ^t@yp cfuAiˎR(ү~r{?op!2IX/h.naK jZIG"+`1P;U]бP^LOQOQɚ:lD#-,?ؘjGźvqUQ'V/@(ARԪC^*?Es =u$ʑP06nh(ipYFBPqfV{lFU1E;(N4"j ˜;ivʵq"P,>;eZ~+"On)#[p@Q]T\33,a$.gS&͉d%A xtLݳ6= %[.}WAkip8~=Qg8G86I wFf6漄wAZ?D^4 &mnߚh9'f;܄ mQ~7D!Ͱ0lN&#&OZ`ڔ-tt CNyc㯜|Y3Qň:cՑCE;`Ik]sn#͸sBҒtƞboWUV\&+ Gl[X-]0hVujļc89LQ/VJmƦ~q94b:_r^mtAPB2ZdU aäo:M`j7C W/rȎY4hFHu[w[=)'G\4]-ƣΧωۯfASI2I"?ZGe#{zKjۀӒh~Hi@GJse@V.bG4 'YZ- j({ wNwY|0 maհF/ U S ӿcy7r Sui0^4*'| &E@yB0SC>n/~ed !]m!a9L:UVw7h~缮#2q1JՔ<5QX+΁YeP! rKG~74: K[uXlNQ# "q@%ɟ# ǀ>J>@ƻ /[WͶ|)Fp2UHg=T`Oskt!~c[<-ň^V4 k&Xl Z[ =O=R<ɌPA_`:޶5*Ӣ#1&h1h>WL-z:83 ˲˰8tgj" ,fv{cNxRred1VUs@c=<:K~MuhM1 #Ҕh3m+],Ռ}vi7UɒF *Osh a7[L _$oKID/DW`yg$oTVFNqTJO/&w0UwR]ϤѩB(8GfegBEцV!}{;w&%J =ܱx E[+ǜ^Sx*yc,2?0,ɛnY,{?śs|`DnVFʢw ݵ9wdɀHLUD|Pe22zP;<*HT&EH5:Gkh*+]ȶm~r/}R:&z E@w|pYKy,/)=I9o3P6.A`:)'JK7=36o-NSڧB,A`J;7K!Qup- $9'PdaKP>{X 0A7E My{ٕ߳fCD`îE<=z@Ao?(wFfT PyBQǏ'l'ǚ(A@Cd~~LuTB0+>ˎ)@a89 x^SS2xlpvу6Gw:O۶-%GHM F>vQr[vXx嫛ӣbw۝WC}^HxDZ)n7Y&UpSy =4K soм,8A|T c |Aw^3_ s~9<Dp8pTR"Zц1.< c琙M T>0}9/ vHl`cuZS9y&`$| n3) 'i>5DHz`y1v֞ ǒjbh 'eLތkߣX Ya>;^A< % D#8hM)愿-%D>Ay$`^{U6T"ϔM8Orw?m$_Id)m|2Nd?KꆺO=Ro+i?x#Zpэ'=A6뚁pGQ Z5q:%.TYJ}W)A rmrU_$9*_sރLƣ`,֮AY !a#͙m{d_}tA>xZn,/(G9Q?(o)˂YwGՕMFIF:̤y$M1冃[fh\Mb((zl+3_Q@kk̺\wgIDɞ3)8(MHQ}B!!>1W!jPEcO(Y,.ĸ0XԵ9/'m36L L8G߯rEk\BDGr L3 ՘xMΑh0[ hyuo*}IUV .cQJ&}??q$($Jr>&ot#grH҆|X\=$qR%0̌I:Cjc^:NޔK {BI;Rc1dYH^89C>FVD˜Ӳr8’I{#4VFA͑Βy'f[C6a#Buoe}g߬鶵NŒ\{qVhJϹy F)( %6.ߦ0\OJIl )[_w9(6BETSq{oSb53~ę@U:)^4ݒ*]O(-et-ï[D&Zr-.sF`sU+veY*)_Y6`kKܘ.% ZPb댍ڻ<{M] :0 sT^m$&DE!?B~4-WLZd q--iQ ?7a!mP 4yv@w>mJ7gBwan>N LnGɔ}d¬"8 eqeԉb lbݘ<5"}N;wt,:Úր5p=teCƺކ\$w2m_Hh9: bZe7Г^|El4W6`7EH@X-*z۹>a"oeVA_*5=x:?G';hCQmUޯ;` uٚSN] d)EgPt !z?w 8BFl?۲Rcvq`?QDM[|% * կXr8X /AqF3xvsk[`܌ɴE#|2i|Zw׸A82bAҏWnꮙs#.U.c[s>4\OyX*8Ik}4(0L2 Y"M1rBxQ OC)v< =Y&$cpUޞjR(Iӏ'$ts^PjrExUA+/Qd$&7^ lQX?Mm(Ab,zɜ-, X6[3tiM?7A} &9Wmke/Ԗr|q_l2J0ȴFŊ0[>Y:T>L7]l_=Ş vpXJP7Ͻ9kHkLP|;{e-b@M`i5|*7ݜ""5Pأ`֏̠4yeugj\! c?3i (o3g|vxFUS?*VV d.}xM24>']&5Eq$ S׆KgUf)VMGx0LFh%0n{ԨxRω@`u]c-⁒'vO9? gC~%c' maxnh<ՆΝ&WB,`}TlqZj=ꎑ19Q5XO${E\Hj,dvT#yS7j$E. P5Aݸ?e9y6/ゆN,& j3р{GHZr#)qPS SjKb4R?SQ-P- ⫝̸#y[Dc~@`b^crM5߲VW5ɓRtMAfb)-R|EUG,yBWݰ}߫2ڡS୴+6 xM7[@X|ykX<&!i K2L`{&ƅIN*i|YSyl"ܔnhib03j{uE%3QQ`}}?e|:dYf UH<'t 'r |,b;~ !&BjBN=I~!zř BK3l$Ɗ? VȪǗ.ŒʊP ˿yN7Rz i\J󼖦O XꗺA `Һɡ >%!t'yHxy/wԋxg!%dC3nFӼ Sf4dl6YZbhx`/いZGSK~c`>*?]'m4ƤMs E:hA5gGNnʎOO gx<;;#xJ+CJX1a1)?? ZߞzX>ˆ=MHM"1'ß!=F7o CI0L5p nٽ.BljwK[s 6`FR)J}e[EROu'[e"Qդl>Dŋ{Y/ ٻ"z;#"o}4)€% daٌuO\9D}j}5\VfG,rr*P|xfqt{:\[5TjeߍrR}=PS fJI%. RVe /hF纁nә.x'JElmeBv/\ޠP&tE)DvV%PgN# >Ow>صWL?zBcw>LyNRydIΈ<YM$Qȅz=xhf%ltE2 Cݸ\,wkSv5^o(wn_BW%Np'# ^ S*݈g)˭A$D , ;!4=s3 O cq9"iYg>Sg49XE63 i ބ/ׯC1L^ P!ZNB/,TMsJiu&a9=KІ`"lq$(|ߌmFOy $N,q29S˅(PD۸WI#' 1"ziJc^GJ&!ӫh]lN4;qdBm83;aE4yRj}K(1ՑG;UF$URy rοf>{a^Vte2EޫZqAQ$Жֈ肢 ѤY!6^VҜ_5&.+ke_xzBRݿ׈@\;hHRPl~&&z?}FuJ2ba<o1XmỊF*vtQSvA' _texR&JoV#dS^&SDxI e9 <䦅ԾbÚb&。w J㵷Y|gkp{;Pܣ{QR=M&0BlԠmyG%ئۣ"K{L=BzB<|Id9x_4J,HoT.q荪sS[Mo(gV^hRϵc:Գ\B3&Eck>njnv%!W=q\/q,AI^ZxFsg7:1K{0BVL9 "+Ak}_QK 2ԗu\M䣪Խ8m=Ja.JOB'3뻣}+pҩ%+Qo?FqΞ:Gٺ]!m̾XX5ndu>l[? ;v|q/zHZ }ZO諚LʌD { %R~ ) _6m!}s~@+DMRp`ʶeam5( /؈eΦ2DHTÀ@׌q MR$;ya0 qxmQS .fHq*d /Y~Ob9`.RsݤN@gS9*.XLi˹]x\g†})?̠\[LjdW )ɸXDei#W6:+ֈVVt tJnҸ4{PCkQwa&vN?eP5V?֌.lOWe+|RlDA6*{HQ % DVQ2PPUYo$СٶrL9(p@dwD>σo:sU+ Κ}e3S*xqFO#Ȱ, YsOt# wΧ靊4g^&R3GE *p{IKWT^DX2VV3+ZP1CH Q. $g>Oo+;Nտ+b-.l~ вpG. v?*6>zSc1]fk$k,PFxʥ%oD 5d3YTBoQ{(8(l,/͊:Di - (]! {̵b܆!&< pÙ{Q.v)f~V]UCpN@#)>ٞh!U(PX5ϔ5&0Wr#<\Ъ/G_bJX(x5 zI1*??UZf~lvQ)`JxDT2vu}Z <.1(mt]үP媇 Kizj %諯a.X1K﴿"$虊GꛊL,$^R+LݢCuhv%{ybW?>XFMҫ+t㢃)2ir(8:7<뮶V3 CG}$T b&!JWW5n&9xcqg@9 ›6^N| ԡ]-0,=-̈́~O3͇#RKro_!9鉠Sv}ӫ+:éǞ= )  %D`φǧ@: k5r~tV,]a ,ll߄_" O}S{9v{EA99y)Mڥ$OsqbHz;Y~8!D4T`*e/#z#nGW$#Mx@[jTYW$ K罬| K[yrq,$Ml+&'/f0/,%oWot^\ N v$UV5R'ifop%$5/$:ƭgP,AECċlnP :" (_#NGD&ƐJTA/#Qid]ﹰȅ'#20h[V("Qt#|S, M-q؝y=nJ?sDVDxݐ?/Z(¬-v+ȣJ*8R5~FQΜ=H>mHę?-9 3>Sdhd|'΋UcO(+^Z}_(|"xIReKs$ 3#.̄=ˁk"BCfqԒVV8yEuJX"F$w78^f+:7v= R?ίHjDFٔ_x2k4l,u xT8oŨrm$D5Uw,b"(M!^9`$Pv& '/xk??;h:y? T/"j ҫ`LY%ho9޺~:ݖ e}^Z߼fW84L@X=<]˶AKs2%ë;IɜP~#{ޜc /?(n6U8Fb% Pn] ˅pX;‹ab\V[,~R);͹h Oٮ!gyf[khy?OTm;E  YQ"wU*/V?sI1zgzXB2?duA'9-%e4p^x:mp S5?.ҹe[AIמ9~(T^r1+V_ Eh"6!^!r]kw5`EFN _->??p%LYHo@ nJuOM']ҧ ^kɗm뒣.TmUn^:lr_*J$q29npƪuj+swb GENS٘Q!ЁdvYÙ?Xs˛萚SRg)T:]Lh ~`ĝ{A⦂ z" z&V}- ]>;CWX#F6ޛR|Mw8£Iק4Pȍ$ƇņB(5-c5}aF[󮁖')/q._Qe=׿L'"`) o]//G+4 锭;au;)Ob|s'i8jtNMERP([/t?8r?fRj64[kdJ$`[Xء} hqpm9m[F*B^mǂ36\c7]M|_l` ኽK猞K,UNUS&XG|q:_}Q1Eȿ۔٘#Mue;`9$am18oCd稏?Ho/=,/B,̡qZc;_%}]ѥ2\'t#0YxyI-:ouʉ2Ǻ Lc9;^CH1j-trU 潧 ֟*0pϚXA}~^B}b]=_)Ȼ?IŠɴљ4~C3A iP,&C3}?@TKx ?'iIs/=U : * SV%A:(ݭ6ߜ} *CX-d 'fK`%(G~ě ;ldLlAY8KL zly`lG"]Ĝ;<(S4+cFe^. g'PCv`V/ [~J GO7C1btثcf&[dnOHk&tR힭'DY8]`qhc? Nw|B yZSjm`TRxݗ02©syRs1QyR͕{(#L%5}zM2n_,/1?@Zkp .WfǂO[f2Q%eXn\fqU.TOS$M+Ye0ާZ˹]qc\ڗ "Ecuv.+7eoE T܇[l&Fq'Z=yl^G, O{u±71IiTuPND} ly&-hOP4Iߐ-::c- k9R{\P FPO_cꈑz/P2>{P6y :I?d*}FbĶ^a!R&0@dUot,;4.ƞ6a0Dp}#g)HY~StcT!=^%JZI/}F;hD=Ī\e,cvE_B׍v8ԋ])e@mx* 8KL,na#d #_'|d 6wk] NǔyMy#ȽI Ag~ѵO@:#|㊭ 4V>rUyDrB"rV3']km ְB-]2u*^3Rbkd чu S'Dj%5^MnAu6}*~ފ_ gkJu"?r s}\c-Ŕ9ꌘ6?N-QT+kp.6i4Cxt?sp؄&7.c;Nzh%MbZ؅ʜŸ$AABv yagP/1IIa خ/IU;[A-g#a|l̂ >sĄO<#TRT!/Ж/\3}@xldft$vY4$qviJ8ٙn݊^@G- Nle3i5e(]u0+J7tN:S>o}#b4p}0De3R' xvQhcP n3k WEw78Q \ ;(3!QDa/G̀'O!t@`BlsiV մ=:deKNN[3G_NŠpwB2 [H lϣq}Qt.5™E P#sͲZY2=ؖ hVܽyc^,{,2isܶb-ڥ'K?NeFjYNl'Ǟ}O"N8 wMDH1T2bmkqTJ1 _QRl*#puT}qV2FGAUeh*4j@p>ɔi!֥wp3&[q[6bg|!j0n FtS@XܭݥeUOoؚ VyS`Ԯ.S"}ͮ}<"#Al h&z39h]ԒV.MK\!K wя5.R"oy.PSP%Q()E?LjOy %/2[1詊?UjXW)5Ztm0n(1Kc{t..$a>yk;ٛ(J']ZtG#+U m0PoQmFВC,l-Q0Y}"Kuj7:U')aNĽ4wr7V)r_K>D>T^FAd}sP##FK"s*Iv+UUQ*TXL/MXϻI) BFP4 ba vCf$P>B;MB7 ]-RLoX\®>%!9jم5 ̫C vA.sz_\~R콈ZN^HiFOT]Ď6c91ڈ@Bb8 RA!i%.miJ4fC,DČI__G`cd+|@NE\\ LPa'NԾ|kٗ_.s'331KU*D8Ղ$|ԡ-W7^e^j m}B& ɯζE!.QmQ^HpL)wC y>M+0T,#F]rM?`]\'ascIG! I+*dWN"'PWOmP@Xnp||k6([,zƱX[Jn/H CuIĻJKou$nU j۸M@dM.kPָۜXO2>/|~A-W"C$ZQc/T*9.7áփdGH .6Pf 8U65?O{# My[ֱDpf q-T[(iU%ar`aGy̨eO?;Hps<VLLlo+_,rFԚ4t]}@9ַŎ/jۥpxnF{[.zs-d뱆#N[c{1i=*<9cNd fcwnK͋ϗ{uh6X8 ֎y "/%ݪl?=e ]Ujؐ"֑>7k r\E>O2e4Ib&ZTdni鋞+nWĥBq}kEc&_g1:/6HMsG# (0y &t#32t ^]hTN7&JR$M:&^}Sizɥԙrsctح7&ts꺴 va(|Ûڀ'VؼC ,$ K 9;2ܭl}>D%kJx懸8vm.Yf p-,0<_<)S )|&lbߜ0s!;J3Þ^k9 jNp ̿#![}P_("vg-3z\rC%^' - C3yy˨o;؀LX&k-3%C R5Ѿ>aBX &sƣcYLjDhBъ6- <ӐhtZv@BHG@}cF |n|TMAATsfTT&|-֏QA'"÷s[;;[ N"3v1*^֒NYi ^EGr~9И=zk$OvT`r f>#e;=X|=V/F>n89;jѱJPE z7S<Z^g 3nTRRП$Ŀ m''S5A*' //_M&ЬLV/%B& 'iˑ!>Aۉ'"}NY> r5.rT(I GF8QJ4HEOp+<(%эw~~>QEY W3o~:Av@Dq6ĥL3/e 9K ӿ K˜W6^KBX@HV݆ξ_gy]lJau9_裌AqJ2kw%гiVtAꐚ [HnقQ`͡N(<Ϋ/IGw]Аa9b u>^kۈ[Gm\=exXJDi`:=V޼권٫A)5j|B=k`ݗ*y4ąv,tBkm1kPI=d\W f,+D_cWp:N d-/TI 8&d4^b jɚf< &>!d \<\ m0?X|TxJmBq{iq~ K`j/~))fe !,|Akҡ#b#xQlAx7ՖL"< 8fz4i뉅+םg3(^D=`ʦMbW t.Pyw*|ԘKU?h)׆]Pp슛dok<”(YRD:P &Iqbx|O.ȥF_Fw=gˮQ;X>j W\7ddO:,k%`PELN2x+S y72MsmBZTeķ4f*O}BtP;.U?hP?+\&7P{vٓ)lWQuJ>#1P0^J%CN3_N 2[7Y? vcp`mkTNMP~Ktmf+E_?:y}ܩ*%V{]}xA`O:9Z֥`4ahX(4'py]kbN!'Ì=PPuUz/J /KQS8-U8,n?]_j|ĤѨAp8xL(T9rYdC[w&R:6s\_p/Vհ]Ӗ#_bETm_(_KkEU}(є\v061W0)i_q[xeƩ)2LhThP&s '6?IB4u|BNEv HMDք_*.kt>}݈3GС_K %)< ĊlBMr3&_BDG-wD'Đz>C-+?,Kd7)6,pwOD:Q.ݳE`NI>CWFKuXSV 'oz]roQ@'\X@ȆcV}Ÿ`>1;6N3XOS5lel5 |IucU9s+. Ektnh*MUl{GCL mNs,@jh rX=|dqBK.#/6ĄnG R|33q6q YB/;VP\k;iX9(FU`ZU@PI/p 7r*C*JFB_%*T2(ȓ@7[b[!,F:{c]8>tm0DSXRm{z0YƯ0-5 c,g>Sl82f!N ޻S/ Asi'P(ŀ uСmo)=7k^UmoD((z'& =Ez h1l7e$ oz`֦G=fn-CgC@JB-'~63tub^ɘ=*d{+?e(p1!VE3+BMG~"7",d&fòr7YI6]e$nBk]`A / [b(wSKKŔ9*o=4ܾ5f>,&QߒSOU3ԾKϡj{vk $kc]ڟ#< zkP-#42D Vgzy;NnRO)a|ˤ``~\X?Ep!S4gH2v_Bz;2WTZ>*=&Lc([@ ͜z+UW(vޢ_ӊ`-2˼[o1.QSID`ՄdC{qttl!*k|ATrwe0'Q ~X Lp`} I뒬ǡP} :j0pZЋHK~OeHhk%=EZ3oEB$]ɮxTؔh͙v_fCm"P- +"ih5O8Z4`" 鑶. t b~)0潡/Y5My J7gwĒy[3NسYϪ4ݽ[1g*^17ٶx_ ]4+Y'ES+,!&+_̦#2ݲzrL -E1DlH WIoon4 <5X3>ƗΒř:̵D/ҩ<`NƏF!myidL(VwC^;q/ Ip$ُN@3k=<*l7W|= rC XWA&b`*Q+y,"x8qћsHte} „XA*lD' 8UMaXlޑA2y;"L+bi9d$'fo JfCJ/3aKl^-;/C5nTW1EzrhӚ/w\P-X8>4r3)t)*3.mU k@V/^3:<tX ݈p980N]-*-\|#IuMėTXK8*]=iMb+tm]: ;C09ڻ#N5 X&MD`xBt82YmoM{!`H%Lh Pu]ކ8T&쟧0֢"' GQ+CI*7l`7lO(nG:1|\Os/CW+Ȏ}^v|oX:'/["G$bJ₏I_J`O1LP7n$oP˶q8Ss}T4O}$R8 #hek4u#O@ɇ5-RS{A)gf9T&S̈JξVh+|h;^ +P"G%+coyr?w?0ɉ&;Jdp>āT^E AWB}(O؄'P>;FELBР~B&6 )72-f)Wk(Y6Rݧ_ Z&yjb4NWHrȿðȇ`CMv EhQcڑGODр|lm2zvZ s+ZdkH{AV&u}l, 9]%OwxzﮍP lBfs]O{f8l!=,[3le@v7mw7[G#`Q0-] #قk3ɹosC1Tg~`,GLQaX֥3 jYo1v$u5V!=d.'jsQIp;emM . ڼ3JCǶ'>U=˄YZҠ@\z)n?ѪK;*XA7|f.'k1fA!]$hdmS#2ցk"ˆJyl" k0cur=QY1AAcƒBkg7Yb?Ɂw̯m[rTFN ~:GX? 4F(G_^tng{Ā ze~ EzZȸ3~ZoPg9wT[ v/r>YJ# BaVhaУ3oE 󶻿@n L'Χ4stk*0 j+ [R ;d.3@%ڲXVQ7@#5CKKw2ML>_t27c0$\m:Nmx vfJ&O ?SFkAYMtIS*( cS3saI%kD"X1ɘI6C|񊲖*B`(w\{ nBrl>N#䪝ւ(.5jRIYnp"Qt>p&˖F^#yM,L @ʡ^ZyuViQTq [ *aV+LV,esߝPq]CU%ςa:T'`gp~XSސ&=knHoktbeiXYGc*J9A`e uǎ˪A.ɣ:#vB$Թ2vz#z3)S0V^O K)9+l/@Y {c&J,<)osr9_R@jbg}~s?\: 'M#;UCx%ǯj-U o_t5Q #1n_ WWμ%׈+YN0Q(3 M{6O9`H;b$0!mpEٔƶ['yF+(,+ @Iw8{K94جJlAWN[\pOj@^ȿ94 *PQ>AhȀҔp[1b%+ix9bs Z:]iuZHK?e{t2pZ;2I&<[k{jd@f(~7 U?DX q6smn%xm8[Z;m v t7Gug9+ #pWˎ=`Z&I mOt~:ZwyeN:[a/>$S,wk'nzA`|ig3s}ɞm%igd ,ni7 AS0SZ  tG۰7<49WݒM.DLzKE䱞9ش7AܳVMݛ*6$m wj&HU0&;}0w'ųxޤC<ϺА\cG0t8>F8K $}#!ֽb׻kDxt^u* aȦi; IaHT= 4!'/3 uav4 cY-PW? O4PtxrF {͸>WFB9s$՜;n<r,u{~n1nّ'H :XDHn x$7"Hc 4G9b5e C x}u˅lPF`<?0:^Ba>x.fd=!<{7k54Rn6BbM\G+A{s(tg\/p E7qӨJ/6?}H7dz`8LM!Ҋ2]&-ږuIǃ=E-k2<_M@Oǁ2 @H0"-D:3j{?ϋ3C"<1Nt?#my 沕웺ST>YAkkOR~3W#ui~GoUY2>@̨JT^ 1Ш>ЧC C!CT:.'!HĤb=s$u^/nym">VN Ӑ,+||AM&aS3A(i Ks *Ř"5rQ֠yT^+(*_gӖcD>us|T\!  n3M]$X z? k(d`"h+x\23M8,wP'{E_{>Aa-,3 f/[N{6 Tf8M~R+k"JN`DOۚ8o唢L+o( Gmrϗ. 4Gy XO/rSx&&HI!Dด47Rؑ׿>{!],j_1;>فuWR"_ ڈ'V$NA7(*zعkaLH< zhIՊG\!hbqŭ0 BEӈzGZ-(w wE&\LY:d#ڶ Yh7`Ɋ"ɹ?X3&)g}pAδkDY6J̑}o$?һBDT ! bC#I2o ł4"LJ7M~: C2‘qtÒ#KYP ļ8ׄr# 1!i*0g@vH拪&Tp2Ew5+mZ9.s(S)1}}8*qzZo1êA.j0j2ۓzfymm&.l7Y/H"&W4g ?3#z5\z)zo` 8!!y}UsYP"+]Q&;Rޏ4((Bfy oDLtt:CxJOp\"r؋|WN{$yhG߂am* ?(k(gA)eCǞ(^hsfY ^?.f{0rj;`te#KjlގS}5~H#ek~-O{'2ٷ_㨁Q1'ﯠ(h"EqԵGHX q﨎Ed~ڥj~񲁆'"Nt-O0eM.9"> v2D_ol LOJZ8PJ:3͂JH۴/oLOjK5qqg@@UC ~BW ߈[ހ~Fɒ@p Ǜ}{-F$R8IRp d WrxOesv{Sho9:yiMW4ݗ9lc ֮e> `8]F3$3\]=PGGA'>[AŸG"a+: Wӕ9XV" g(H\$ Xd 5 R{')Ǥa;b$I0癥{/$ejM OI̔ [CL1:;hgĶHA-jZC;eXHPDc@EZSoG>19E_E#p=0rP gtαSLVr4ea<\?__rHG~]d2GKv/4!pQ!t}`Z#/ 2uIDS26RoM:t?L_kn#4^聆Ge߻RO!T% X^jME?v[Q7.|&,;1ncyfgц蚾lրҳCatO=5yβ6y23!i}Y/*]wUh\BGC'B f䇑 ̢lGA"'^cĜăxeo[g6t*CT#c&l "8}6-KTz<~t џDE`{Y٩FH4o:/Rټ/:v!Gr. É:a~>ᲜyRءq}}11A؊> ]dBOaۃt<V"L)H%vWFήO+BWqȩ27u3܊Oqi{XmWpyAZ#A Q%4tN]4Þ*M/}|6 pϓ*MlR={.? H4mzhJugs'ğ /[PS=*D_ŎmyJb{pPuF[V+w2.B\!]oaN3of +J#4c$lkSK?^Y)wKJh{F{L=?,=sSK(OL+ vܹ _N;Y yH^TeS;xȒW׎,l{' >]>.RI[ |S)vX?<)AZ*"g'X>PØo^`1}6 (-@uU{rk993d(Eմ\:ǴL},Rf<֤0I2 v4Kv[|1x_;Qwb |63 SvdFa~jXUol_,hJrTn=X-B g&oEH7-C]8z.疌H{N&IWQLt8pay/Xe GjwB@Ps:%#i۩h)Tiap̵EX8gzsl<;tek)UA-@ F9е;qN~~g䞀)1#PѸ6h 2f3h†$oMj _ x ;|/,͗Nz{څpvSH@K|YQJWb+:ׁ+[JJgt;UZl4{)| ,B$1os1a]ҔSJI & k<$>* V7td[BĜ/ykBǴ@ QzDZ8Hkm]/g*̴o5< xEw,SE[ol{nsiFNPg|H:Iw0~0J7Y85Ml-j؄?ĕsH-mrMݳ1Rs0Qɸ^_OU8je:ǖܞ-:_!diNVYp]fo~ssN*!}F~ +/u;C9tmFU`#H1[BZ~^+1m$Yȅ @3g%!:pzQ3?t@|ǵ϶AuR5^[; 3`14 &D^қhqօ} o tː5Vw4v9xL ]') ɱ7}f%NJI Fh *#͐xJJh,?3'1p%"7;)sٽ:^ch첍mw6rt]~k:= i$Q߮˜nֺ%dq+;4N^4'xKd)#G/eߗ džMnUj$~ $s1N'c0O`@ H)O)km8Cs?[y eDE?[0چ3IZ!:%Ya+g7< TsXE:;(Gu0sS8`tF CbfԱO3pjԘ9ByQлc y׋A%9~_:;|@uN ,{B*_k}uVr@yx/~+FR,LIҟ8OjǢLX R M=Gw0laҢtz* 23m> g|OË]zݽ%X.~w﹔\U.輀0/4yYoTػ^F>iAA'Uά%wTq[t ^>0kl  B!~4]UVxό~-' N\BSCQr]O~U (}i UG@kl xaNL{98f-.j9A%0} dfVus@lѻ 8z 1b)T}@mމLP?Nbar( ˬ neUnA|Yy<י:$'?I3"Nb莺 h-WԭD0Yd~ӥV H_P`+*ͩk IBtYOno&k-1AG-v ab"Y!`SVe;\hl !G>7CF\[~R!+DE}LD-н~u)u颰;72#Cc?.6.CAQ 6BIJ&˾ ]A(2ݏhX18iM!kN6缍n`M٬7ˏI_@ɤcܡm8bzPI>~8 ܹ'clo;x$04p OSR:ײ]\t\ùMQf !gJ Zw~k.U]gZ898(W+jirzG}{+PCᶁ85zl sr* i-ItOk y16.]q5WAzŮ LzN(SH&JN_3kZfg 3z34I^{%RyE."ދ,M1@0csxC:2#Rj|$ŝJk. 5m5oj͜SU¸dp(vXTg#]]\n}`#([,Q-`_׳9/؂GE0[!FWa)/tجqV]ɋ{R=1BCh7zR.e33;آ!۹=%H6nQv*gzʒ-W_YNE ɀ>2uO[XAqR[-}uJY?،̳{A~NP 6ry%jW)$Î&jO0+r4'.Gg4OZ?%^Lc&|KqS?\ieXD0dʔee3J\JN KgK(ee|N)/B=[+2.tu\MH,Mvze l]5i]ArǤ&$pŅV~['7ܴe*qpv{ &VJ#d(y8!6dいr'WLWXيԂhW3#bCZ`TYhMvi\7/k=/OV9 Ю⻴/_ '/c<\St/dVTn`;gd-W<+[H(xB'|tg9.h(ڸgOz31MI'Yaw_-?۹ݹaAWeё~$;S"r*T2 LkVj3 's~!#^7 zo} ;zZeSL9m}9/k %;Ř,fR} J/&{o3w&X.E1[ŕ[MNJ۴,HY("GL,u/%(m}rtCd#, o8]ܣ "uts;o"11gD6lcnOq h ۂ{ Xj XJ;.XNçQ=`k] Rlx`5 ˄p RC2Wg%ë> D(YO0ΊHjFH^kf}5 Ŕ],{(\Ľ@)[%[IK^8Xv;OOp@c]6񕟒M;6s@\oӤ^p,-KOk2ap64-]\<[jxsK\dds߀+5UJݣTAKw3|K.q[vW pB KIg( ֹM/C]0C53Ӗ~h(wkîFh( Y0#d6[nig' 7-JY9@ yK}6wual8Z.J\-z 2̨ߕՇ˰PW_QPZpe2L&tu >lDqGEUۖM%i @*a㗲Y 1O4Wlct3 Zw$'i.a_DQZ;bhl^пeI_w0"R>G*TH)P߬E"#-6BЋ6tl4l9y<7 o_WONٝտa%:38?\+~1,gVmhoT1W2#@]ǖW1pAUMc4w8^T{6&>|e 6g3Wu|+뒑GTxשHJu{|\9ISgfuhibF,+'n|TcΑaMr4Mf9`6PfpƆ3Ж"ldaJ#=Y(S~i& ([k)XR&]( +S9jxۑTo=3F`,TL IwyDuhΩ=9d^78VJ>E!)M`"¤ ^6<q Zɿl*z1h75{MAy{"'B4CCԨc )=΂NȜ iu V 2ʐ LI]Zau1 1ڨpL85ʄNNȡ\,hOrS~"ŴSeΈjS23w Fj%+`x#Ts-QK˃9.N_*#f+%zaA =ɜ 'Ki ʫO97 r, W׊:* 6DsC{9zɣWT)h!F+`ƍF,cnڤƞaٍ,*s~)2Y}|:Y äD3_ Z_ @66@*29N+A/iDڄg T elN+$lda.knÏ}h GRnT(ucZH/T4wBw)ȍڬ.pZR.pup&2bBXgAȽ^gCHfBHAvU#Y8qL*B*f#+qծ9n|x %*Hݡ{L3~ĠöMCAOXfa9:cSyE(u%+|>6h~`tf^NCv>jX)(/~Nw vHO;+"~|X|j0ClI6D|+U cEx>JX B_E*@e;iA^^响a[NW'qogT!νx2* f8u޸U_#r̙&[?rqoбFPa4Rda3|`A 脿x[㻝 jE?&4|x I {%1hOB2fC'8f CVɦy b J3UpEJ*3e McTNKq1"'?.U`N<޶qB)|kIѦK8MQF~iѿsX Qӭn=pG*W -O2 s->>f^BM"WDR7~UY@)A?;b.\yr [NW uʦ2YY aARؼY_avð^a_ict(P=Hk\ [ِ܂';s5HR:1Gsڻї_9k}Xi߫*zB*5#;c5mQ̹6i0[Z6ЩDCYt`RcwmY^'f,:|xtpGm]EY `DL "!o^q9yRMDoQ^9yhv(1(x?CcB=J_rzr(jjOuhtث&ؕoW*?Ɛ7?ݕk$ m2( 9R73+.ib2WL[JYyo¡ q1 ѿt4 BXƘ՚qbV=j'UH]Zt~3LTio3ҘԱ-:a)2w|hqZ}>ᐆ*n>ڿ.=4YgDd̢q[R^_~'Zsȼ_l|tDO7pW 4\\_992A萜WL}1h3 4"8m=&SV|(i . I0M8@5ZS;f񼤸OFY[Zs^RaU]u>4>Kr!!-s{b[ѮBI5{2xAɕ᦯J{v*F'ShsCGeɅdsHIͶЌ5#ox%w,Mݰ$iWa[qg aAjL$Sc).MI96w ]r*NWTG~xZX[4o{+T\7 DJH!pF}WrW1$Ln@*H .Vʊ>R%PmBl˿]::-dF,(GM%zRR#8EYO ]>V`0w(pn(n@1@_-;by$qk<M:?Y~P?s<^0oo}J}k"IE`YJ2_J#'o; 7dwQNy$ 팶V,~ Y=XX7<{վҼh_#mV[q:$p~9-ӠU2FsguH8 WX{:0; Ue{1J!gvԾ0fqj)o.ATCuj6A?Xe |a{T1Mȓ*jv? ě&  t²2$I*ilbgȣÚ?K_@ W2\9Y9\8-.׷&ڑ5k܅ݡayJ|}W̛Bf*Xív{=vvryFP@lyV ƹiEn:E0ji£Ӵ8uEZ3Q#-G BJ;&85[hko-6m>#r#e7ˎ)U~ق>0vC§}d| 쌯v04,`v$l\"͓7G>y}28d=g`Ob:%F߼+,'Х^g ^އ&rF~hPX_/C\؂cT' )o˿hܷ6cK2#%.AfZۄ Eq7Y!<'\ * tγAcOU>8]ևH]J7YhkȻ8bԼ zH(X|نW8kQIҹIDӿ$ ͯғ S|2P -#e[j֢1H]??!nM{O\E_l U"z~e#{@@H)`' ^  v!fY->1PP&ŷ„fVe0Gf8z$ mgySmfDBBChӣxϳCgzxHgpm0;ޖ6 S;<{J |!z=ʢ(X%M4=M|VSa *Abc2Z5`DJ z-"zJ$~u(jq nSu8 C+b]\ 7̟F>ιg;?ұ9UQfJ;X/TG{K] =YZ {0}[b}ߌ1nֱNf4n ^cT~n*,<#7#J,RH_ιt8rGu i>N[+e$Ww7 Ʋ$ӸaBFϸPx6OىZ`-v L#"{8T`~x81J!CA=t0yc*j!]6BSZw -\iFW=h"#05|-a9Yw_ns>F@ He<p:xaE8$,*zG ?Dw<4$(0,tW_j"=#C@&Q_4ƘЩD  g$SP!lĦl ,_,|qŃ$z9 ENms#O%[H2_(Y aw N'Zw ̩L8_܇'&PRX5Tɢs*-M곘!OfA&%Ů~"`QM4Z-  ,{l'd.Hf3LJޤHso/ý>\ Ӆd,:7s|@|w}FgQ9y^ \|hh!LX"f8&poA`~檞l7VaKbW/sn`ydJ&F |M_ >i1b~aMH◣rxUV.+~pRFE`=l)aҴ [Mo 1+͇5W| ƻ$=V\LU6[A{&vTi^f_\=(ӓsK7E678if4T42ez(8ܟ+q3i/=+d\-.jmB4||f2S 1*x4u)h>\ bGւnD8Γ 5HdSLG lȰFole~܁Al6QJEKJF_rjo*`2.'vp)?X$dG5ZZ$ הvCcVp-L%Uj=yTTOU胯t^ ֵ17Se)GI+W6&ޔH?5oNR~1M?Ct:E w%$:UB`8EL;oދ-ebAb*gDۖٝcZ!{&IɁnIc !Uf5Ϳz2Ԗ^KKڹ-85#^v- hhPDK=YF`Gsk?&jkJ,4'Fg CncAȺmC "[:Nd]QQk3ƾ/C+åeY(l9GD)6fUzT8cŀ}ۓBZ=l;V*Gk:JeFl)J5t2ΰlJⶬCԠ[QccJ أ}YHEwBBQuᇐy-48 X/gOy~-7ŗfs< gv!˺\[3˜nϰ Vd6R(*ON %{}pkĎt&\ʑ^(Em\7?~Q N5)2Ԡgkǃw3&|/!4fr u=_-ZcOa@o8h5G9u2=7pbmMTi'I[AF(%k3exQҝ1jƜE-qfպ"X5(P  SjϼYW F-O%.۩4t wܾnVJ8Xrg[+y #WXmT㝿Pzu Z~qD&;7kxc*)4e-4+ɴ]~~e#̭2r$aa,{W]@%jeJ _%Ly,f\˸uƊ=oAyة-٤FEЫPC53^െ%Q,*GL[HP\5J 'aғ|&&μk~XȏOж g+B?3mR&u4I tz0*`@qsLs(ڏ-8ee0&LҁZa :kg2 TxkcUMIMH‘XU[n', ]̪6 Eg?wbW'IƺFtD+tKѹ9!5J2B/Kz,C`W]6Zo0_IL,0XG g!܋I kd]{{[gavFX]XUό~(cg W~{S-TB`a"G4F {PJZ_ٌ쬿` -3' :(qidN8k@ARG]sڊSc쑜 =Ў~1|AlEwi`7,醸u_XuZI&b0SB&i z _~;luԇm$," \ ;>y;?֍-96=ߪϭFMp%V.xBa۔{Sat'gd+Vǩ2$W~ҳ-%Ba8L?Ĥ䌠;Gs_zy/ ޿9؊w$9AR$+u6N˖ &*KQE=˷81ݝVdMm, q4!AB{+چ:gk\/|>g wwF(u3kY*#>J U(zO_䲤o7YL7/KclM+ cv/^*q׆W眎l0 tgY&y$ha6[¢uOu:+q[ƁJddye[#ma|{h4He`%^@)Hos8?Kxp־q:fQ^'|΍'vG 3eM[od;nMC&-0RE400@2! =AV%?;7GXl'g?ݶp+Xmy3˂&d$olK(`k}΁Y^Vҋ{eÂ(Lxpx۔C1e0g7r$%f.9&]7O6^*wnnS{#M;&F7&-Qhf+=g9!RLH:#]7n}ZvXqC3&&7۽= PRfg{УN^Uc{rVS}xR>jmdnmgh ]+h 'jr$byj̼aWy:\b?1&LY}")G(KI["X1G̫e˵{W"T1GaK_Z*ks60o=c]x|Kj(z^vSVh6`TC6ѽ'f<[JIIt1c ylKߖw&]eV?8? <]sw Tלr28|up\'HC!ⷆ*W;3)CilRph5V~i)V`u0?ue|خ-2Y|#lXLGn`_4*SE\ vM^螦Ʉ3AYwuf{2t=&Abv%DDz!`3"ʉeiўX&瑹yO\wtAr78<',&xy$Li~=f =3xx_t!4出M!ۨ? +gFꎮ/6KeKCe8NxNoذv1%:s?xGݎ" + #d'*m=!@y[wl􆼌[-b4\n?b^cv<\|nTu2zf{ŭTE9BAإ hO;(`LKK< [3Mur<ѳX(Wϓ6 5DdEG !#>!R/-@OBH~k3aq'*nSrрRQƘl[k0{dXH5 &ƍKZ& QA\q0EMbKÞ?˪$Wr ` ܮꕜ@aYnǵdPo&Щ4$~<Lsp% tq.+ŋW}KMeCbEs=Dη wTRkNm"sƚc:st%"A9bM{*KdX?/=NIC-/.@:h8t c52ep`$0'E,Wz{08:&╦rB-["W/IRCWI]*`ѳ WMôMZHAhMM]nh L!hMlg%$y5K?P@ ;m(& ЪD335` dҊBsZrcO:61UU[-niXJiRZ G*y<|G'/nJ!JMO^{.OɆE 0G@:?R`y!փ+'Iv+s , ps\+Js$ØOMn~cYvr8ڥqs^ƭUMlDGL*"Рvd](@` [B-Y4*hSǦ_fC#ʺHƉ M1[0_Lo?(6@48(re_1DP.4gZ U~û)D"(iN|o@9p WK5tV/*D+Q4z?B[@ ߔA ռrF6d'-]2{7ƚb>^Lf>;W Bo`<7t\ \*UHYflh41V.9І~ و\kV w &/4p 1YLHEa 0G+H(&N'ejg[c"^s^g3sfȣ4%ֺ&Et9.jܳqHI?Uyt͌t(:$nkPN=jC)DKxL,If-H0g\W"}ܶLO Qbnp\p4ھg"L^UH_t )$׼b#̦ xr?OwSקڗw1Pϊ2H;k_lMI z;r"r`pO>S0 /]AyDCndIE#k(2ez)H\)Z 12lϐgL)?ecu,p?[ݲgɭ0b>"(HB,ζd`Yt*XRN?=:ѣn)R'?tꘫbłCZ6_JզI L!uh]G <%6.r/0C`G`RM0C͸/U; bYfn5wfuGe2h/6A4o{{:+ ܦ"`4oN'nT>RZy&6)i{t;PO7gЈޑT0v2~.uYn%@*^J4DPi~ն9-Jj2yJJ Cx(iBpmq٧UDY{gWxqݮp+ &zXD l=9zݏ|tBW@qޢBEhΚaevNB-Yy ciد,J_HJN  |7vW/iC?v5\ӳq3%!xOrE[ކRK܂Z[l &xKXRm$Z*ynKV*HBD42OpOXGX>aY\},,g8.㨹fi*9P~R䖇JV#N%*RT5Gv}$s2G%Aڕa~oB;7= 26_/ qtdFe; P֚ps5AeV \Amftz~dRIeAJݤ[MeVsG>`=!5|o~V"GoޥA/|r™;s'aӾԝ39H'\7]-peXեmcP8Zopt Zc٠IV#7cud`qM1ƓqoRՉN<@_O0%Q|UywucAӆf?u/ _0MVZ$H?~Y:NA/ RX$y) WMֆ%#4Gˑ$ҧ^h(J1q'I -:pFm}PJ0s/*K$Et[vpe)#xIu"Ix)ྑH=8m"A9.5#fj7lOvI 7RcrCӜ;{B346&7,2)6Fɞt8ӵ$[NγUR{Uʒ `)&mO1Gfzq +RYi%၈!D_ QH4>&(m)!@,jSP=hFޱYߗ3IseW+5oY@SmƎLYc:pa D#I{ /#}SQChՂ5Be^=0#ʻpQGyU@TJiwhw8\2%i;ٞBx}3e@k!*jL4'i4ш{FsQԸ1%]|%MF6^@Hr[)^XÓ9<.wc܇>*R..g 4K՗CIsrXTW&$ܮ6D8w@M~"O/ҿ/Q$א~yϬu]*Q1җjM'᭕rAuflٰ℆'2Ú"t~쟔^E'g p79tq "=N-q7 f9aq;,ު7>!<nW:ۉ@XBcaߥUIM_b5\R0.*׆jI5aˆ ܻ54G_1vsMWw"\}^ Bڈ qu 8hJ0(j?$2J%cpۂYc3"znI3,NSJM3cY>4r\cR^}q3&ṱoU8A;h긹wZ?v#*RY0F57ԒbeJ>4ɴ6W ,.%j]j|Y>rX);! B0*؃9Dig=l"UR奲@A~YoVF<ec5kVwrQeƝTT3x1C?f¸V,E0 ϪT6 8}b~[ _.%}I4!{v97z1Plkۘ1x?R7ģu[xnT~_Va8-6p=qAy}(oS[ |*BNUu?55uΞ Ȱ1֠gP ouz` Fr`CiSK->:|,Jw4~Pm"T2QלOΦ.l@RGn31ȑa(lH '-y&RYyST_[,ۋ5e2cynCu@8wbu< &ϞPb~b '~^Դ}A_eD\ޭqj#O7S(lBr٭ޫwCK+=E?XD_/HzL5Ny+ucfl4z*$Fo.!zV-bN yVLщwAݴSĦJjM'LCHXb?n^.-iAnM}ʮq  ptš($:OmS5 sTRr]5d?rc ¹=LoKdxjq1n>J>4H z,WxSqU+: n},sw=<[=<|%_%G) j*nS:bL!>KdC2@q4:C{Qh$X6T?EMyb˛BT!j-kC r)˱>HzѧAP:BvwExr,Jk=1kV`/M-Y6wt NQl|b:2#Fft`a#_C.HxDyBpǰ?1}/mU[P2}m+!1d?˸x-H>VhkIa!ogk6H+?O`ӃN[ZaL-P-g)6PYLV}t i]n&՘:y y>zh9$qn f"*+h܇;F)D/m@,:p(XO(Y1cl}ro}o'p{kE>S\$m͞ JN'&ip m4cT) ߕMˈlg/ s4*as9 >C{tҒ؜sPJmA "K+:Jl18dMwLJYmqJ#b9¢vYwE#BtC5FšJS=`MaOQiguEai|Ijsay?;m:d7SIR;\( P Z$:Q\ZϩE (`$owwbC3)HnB#" Nh. IwX,&)Sth'GO'/9) 8FD)&‰Ε>j`\6 Qdٸ)0ZQp0ZH8g,a%Yhv* 1#IfžUwFMD\X:IWUڞk5mEGՍ})lb@BB`#KS$|WOaW< ?>'P7 j[aktu +Fyd#MX J,y9w枑PeĹcTal}S;ԵmAjW"ػ:JniaDv%2jIDJ^"*\#L#1C2#BЯlF\+&$@[ }s@/riЈ=ewwA4P<#o{"M{}⩊EBa'P3-9?j[' R?d݀Q.Ww|[x:it2W٧@1 WP|le7CSۮ@#(H+z~m$j)WmpFM9ΜB-f9e9 ' Z~ó\_<{$aS^B d]JHwWԽKn+5ٞJ;*xSp+pӥ<'Vv~L}J/2b:1!)= Yz `"AK @jbョ5O;2NhS:!\!P9 Db=A "'(v_gջoyUa3^{;rf`4F&07|i3z*rtSy}OэRI%G6l AHyf9A/"lgD"I( .&fclٚѲD]]pTnB'k$kx3?~]1)<>y8UPXMXzP6cp8C]u`yk".c1^e&īu)=ʗ]";QDEVBvS [qzR/'C5#.9Q$>]1oܪ[(_Z[3>pIbS!KK%癨qD?$+٭UMbXYJS^^*t%/PSJ>Nh8ǰPe ̫$W62*]kq{V""Mvr0r{YzI581E# WO^7v.@~ؕDjqCsҋԹY!Us*7 @mx+ ȻA؁n;DoSavJ IPӎes臂zj+9١,#ZhX&#;mp sXqkuHBlMR#0GkSG^I;B4gBLl1dkAq!%Xqd)Q'Ŗ4ui v~,1p ϫZa"zvGñ12mf{SְСEL0s|&CcvZdFe&k08pL'xbHDL?XǗ_+Lqg C!rs_t_hӒ=سN3L6b%sA $8:\6rpyl3v}WӼ#'+GCζH(nP!}>9;tse_~(^3eAORnpR]d}uOϘ=>g3Sen!1h g#lVfƼVo?ˣ?TDCqYfuww"/"KùƓ,($YSVLa( %QP+3^'ٻ [Yƈ!z-qrO%O8g,f 0PR)؞w!x1h&K>2CUnemޘ,cq_ysf\,{#TIi<4r&|1*l 969^7G˔ét8l@R׻ֈ0V髮8$1%WZ@Nn#joaܩ}FWTv s ϏO5ʍݟ MWsx`5 TW:X2E<6rGAouH2MJ֫S^AUWG֝P?pc\h1 hMd f>As@] 7V'~ \' u+rr.elš⒵QQϦG?pPk'@i ;6(0W;NW5gA'HITvܸO `k.hs{^ QzYf蕺 m w #%My~j9Rl|!P&؞HA\Xi -n*&ߒoG'eJYCcekjEy C;,qkA]ҕKt#Y6\^Hv ;W_}~H-g[$v#VQ9Ԉ7Hފ#-Z'qIt}ռ?Í7pKtuiR'rK]Ƅ3Ac߮S|&YRbS‘nk  X/y\q7zA7OB8H`:|;aMqAwbpM5:z|P]DS .A2vcLyh5o23fPS䎊]0yabFlU'wdzM<;)ڛ"b>2ޕG™orw4qnd.܁tPUnkSFl] iJFXT#ODx?0,8IjeVl]7m.C{ ڱE]U7; Nt1:t+Wl2-8-U9ZGzAlFӃ4MKPHp~jWrD'$aqƞ#YֽG"g]ѩkUxOڬEiCX[l!ܓdžlQ*uP0a9'vŇ n¡a]wrk7۪93 ‰ׁ+ޔ]ƣ3oŸM)ZWʡjH)+4 kգ2qUE8a!qġV g~2:2МƧ'>"7S#a!Ξ6 ,B7KZ`V21n}H+^Eɧ@{jyS$ReRJrM_YMR1ʜYtc-A[*NEK3]řF]|ViҊyD G#Ø[Ue<0*@Bۀ'<K"F \>&4Mu Սb1&T\pӀ@B_&;`^C7cσķ{vĒ 5IB\=Y8@fxE܎'uuuGvMW\Psu׸ 㲉>}-%W۷56>>qsy!SE~e fwʣ]ZH*D3E9%J@_ d=P TLJ_a owiXaxoPLox?0vʰGS sJІR)b==;M4~W[ L qz]w${r7]029 p>yYyLahtUQu;OJ0)d̿~.)^e K&e2(&Vu΂uKM3]]5ިP2#PlCgcb> Lzi׻ rvzNH̭P;g^7 =;$Q0f>q=6>* pZƾ}G-<]Yqr2֔p3dG\,#𜩜Q.$Ϣ0Pܭk=W@خA:;7Aw (|.W_ZNy[4c$h@"mj߇̲+K|I`D#V89T}w`酑D8Yz.BmpiUlƂVOcuFǡHgԅY#ֈ jQŗIDI< iO<ژ1qtE%/e9ͤ=\R /1ULrbNTs.en8 k+3R␔o-tm*xqWݭRZ:趟b%7Rq. ¢O_;M[;R˚9DD%!u1R |gO]pIZ='jqFwd|~e%kN0?1tl<teџr1Fjo{Kv{[?l634),xֆX_{gyUxۓnTQA_` >Jn \{f*xjM7/9+Q5noG%# #{h "`it>9]@֎~gj?ivj!jqd8D+h룆^dtlψihͶ6)ݩ[d6N7ߙP|{Y:wb]/9|:JfY<:K"6[^#/IrJ9w.?}X|bZp|&sGu7qUբ-VpEeQl`OOi N Ackld X\%VE5\VD; %ODDRְDm6Д'`bHz3Pc[YD͡izST' M[weˎm#o:G#6b$<(I0C1܄*WfkgХ:쪕T E<v`@I&]?讯~xa!b[}f*~47G>4ĬѸP%5atMfRmB* jhZcr[ge"lǪp7JkgS&>Gh0 1M KOeZ΅ޛ@A8<Ʈ՛[@KlJiRo7ւ_u)s85^D].*9Y6Sd(NKua$j@h8Ls;Nմ/As iI37 ?[]!< 4plC ˣg7eu6թvTZ#p9ѽJOSrF+p7 [aԂ7"ؿxcb>M!G.b#R^I'mSh"xc-hܶhWp "J6A '](iCш^ے#sG⑎qǖ 5Hr3Gˠ؂'AK @q^{rEqBz\dGkJucƜ/Ty}:|zj#)VF}.Xˢ?B=?j@7- XJ wo[hgCh,=a>gdls5^iP%{ WE m`SS?ʣc 2ʊ\k*E"^(\)`ǡ/iE>VeK Y?QK%lL=U7zRZcFr'MtZn{R + pcf0&0?M;̬U•?\Up- w}g sHJ1ppNOtǓO:͚aiTE{Od 4,eI/BR,,Gah/07Rhsh5τDNXJ֢kˎFt`4䀌Y{{B2v!]F~B Y-PT[pΫ+\3#::rFcnRCzxwL?ܭ jS{-ր#&[ ec&UQ1qVW5mslȆ |x7"X/QG?tWk3{ BoKkwHdBU^ trh㎫cy4iz8Ϋ~o_a8&bvI^@S%brKҕ>ECC~$>Zvz75V6z&aEGidJJh ˱Xfz"z~x]2ole}|ROkQ 4CS[W04A@KR i&Z/wц&p& ;юJyB ~"q Fdb>k;px_l@+(QWFI"25ʰ n{;x=ٽV 9jF&h pdRWxWML`E koS̖a(GCuYz(R1[Ja@1;v}]3c"ڇ!T`k v|_> LCKS`]חÿo=r.POa3F\E;eaI2RLn3L=λ J1v1 vj7SۅFgj sQj*xa蕇j[q< !>gIBШ76xM& $ X(O&8R3)Pc}&j,&Z:u#.Y6t ($іdr~p6ID瓭ѸʹRs0G#r9~s)5S0Kb(̉$(o6|vsM+Qⅾ2x,EH d.SkP\Q>Z_*֔*} d=rMiu:bXJ8R vǰjd\8VKd?*+;cnhNRފ`mj~ aOO(:!g3l3%j`q6x! 2ӭ`X݌EqR7ÐѨ)kќQ`$N)4QASyo>+$D4_CW(0t椯cK< 0֋0q1{ۙ}ln ˶{dhD0@zTR8|5CgK>ȇ*G>H:a2G6/̉(L mHRɉte\".;]9֛k8i:"|C), EP"B-MjI)1A|?&n}Evj[@s&ֻ.Qr~BwZ:ĜF`LN9V(B&1V*3`F? \?]@;0aetZM_ЌdXK dC73yU2„bzC\e%`,5ob/T(EnC66k ]-bN|ߛ#g:rtN5S}X^ށIdP {DpZm1\3XP2TU$32ױf+diqsR`+h&iyͰG^ 35z ic<>lyS5<OKt/T8L Ȯ[Q_ iȝM.Nů.%P\]z&Hm}&dPƂ"]Z<~~4MoZw5I/PFT%Ǖa|"4qw/mn 39BmwGa"\APG55?xb{cռFSA!ڏUf_bjf*Qd>a~YB V41ed*XW?\y|&<OY~]=7n%\=4z";[$Ć1W݂?A-VU5gLVfcBxU4q?!qKsy {{31qB ldmuXϰydMS彀 g7/oT/vr=on"y/G$2WT!ۗ.M"phhV:-O$I}xr#E]konv`>ڌLA'V%?O jݛS"Tx܁j(xi¨$[KN|/i}s,ߵ࣭>XBhagMy\V*Yه{0"-٢ױ߆ pIГfw_4"]D#uF/ ϻO "$`JgAf\b AL7/sB͕^;Q1bJhB)b=7.e ABǼ+^[m VcC[,T Cy:ۮFK>JkQ% lE)? ؤ2k V2k+3zEuf`pr"QNVSѫ ;Bkhߞ>Xw\wZ2fd(YcLg{XM>l$E J)J8/ě g)ib{w@/Nt[ 7{m &,޸Hzxaӥ5ɳQz})&֮+7}pqo CPvcSh$f)qDψS,ltPpknH`zxB(ݨyB?tC=/:eﳞ,ڏEU"0ԅ׽e]싛Y_B?yYQQ=5HGkHccwnemh:䃑`gLK7bHA(Vyf#e$ҩHǍ#b}I|>OEMM\6:;1NC$mmg$Vx6h+`=a![fjRPB8$SqsyNYAsN)zƃJ i S%D j; ,j@>hZm&ՍP*9Ji UAi 6n)j 3w@TW=Z#aE3Q˺B{+vh.Aj`| ._2:0>I;;co&\09я<&/e1騄݈q "yEQ&[c82[>{/0]@ys }6)MtE6u,Ddz&_GNW@- g*8nbP!'6mb!`$)ۺ>hqY@H|" RJwMeې#CJ{(^ Xw\*wcaqF'1n9^t|&h 3zv4յeķ.jwQh˯. WSzbkd $~&Ƨ0|:/GY}v \;UHpLQ՞4=.΋(am$; %Kyk)z!jDwADrހ*)\V>*a]L?gby&mvCPΰF0O":Q(mlHgœ\4GϜ0||7S: #VHϠ)vYFwI%kCd mv1janU/ie}";R``^[|b 1X@Ů ]5f D%x2,׭tugTMjv/pPؗL~gGexnIIɛ0],N3zt`%*¸5y EbTBbC2-pqQ(]&ΐ4릶ybYTo7Jera!3N.o݈4-oݷȫ1A,ۃt B]$3C9l2$7򁫅2Nf ʜ0n\k^(ش<]ix6 iC}^XfzW  *&Xh^ O(ƊOBD~BZ]i uղ|C3 J |25iC/R%)Xs\3CZԌ Um~tJELV]ʺkn!1j8gF"s}VgjB |l̫hu|d&PC#d sTQ&_IY8|&;PwnJu xQɐuh;=X9 ,a0jg:qv.%L?_QXQb4^RdmVdSzF)~4eapS 2\Xؒ Ja41WuVaOd%XSɇ >ᬟ@踃z#,,/޸`7MQ N:m6{·._EF1g"۵. #:Oјjg؄1Y 4e{teo+ڝl`=-B G[UI ƺHg?ׂM;uMjH`,qi +*MĀ6B"kQ}8݇vN_WbOsg}I_E-׋]&ɵUe pb݇ KQp2[d5?R`ϺH.pc ?<a= ĈX[8gK:َ{#=!+ iw.vLP5 b] PmnfXzb[1S(ýi^?C\sQE"2eчhq6%]BYWȚak;p\c35Vx9(୫AA혭Iק{.mZ0D)t{TD WR/Ղtܲ< [|V,XHt"nErpb񡄒 w߻pPdM[Nc[7b8s1ںj;3Nq1!t˵U D[%IQcI%i:r/wN>)~T}ޣ&0z;F6t]ZM娘gڍv0`~:2e1 `!Ew}(vI&z͜r&-&‡ \܍o(Ө)D; !_ng΋2Wen}ѨnT0c6D>Yrg!b?ܸ.~Er׭ǔZGgj{P_@|T_cvf3i1V ^k'p/*Я&H ,vXnbGy|eר;F~uJ?*1}R"nQlRW+ݸc);A ?aТP n<@~|5i>bKQخg0/0g^55MX%XR0j_s:+aJcRtT5oGS]bK<4'4OGv%=e5zPRjNm<+Ȼ-͌F_@)6HYfͨj, Y*F6,gF(j >ᆲA1gL9stK#Xyy\So&bYz.-ڗI/[CtE$Q/gl}ץߚ &\kI7 {V$z9 iؼ`ud Mfy(G Moq3J0?u-7M WKU׊h$0A!UlWa1 0(?!>c:RrI8PFvY~ƣL8C ׋`2p(;yPa(7V=QR`xQ?B/d΁L`NK,SHUDk>wyi-{~Wݝ6lx"PU  %-RF"7ЅYIDg/f:n}ZDuFv~yiѾ-mI |R%?K`b"B9a# ϗqzu>+)B1}H˙JSj4v12jf #th1St2R}] ; r˰VQr2AC4|kff{M+b<20hR*ezMԛOLrܚqA-.[k1y)h8?B mUKP\wVlݭ>|,_]:aDت (Eq9<,>=(_ Ĉd!l8I2\D]dUu76sAJZAU#+#s_Ӝk_lT ͯ_hOcx5s:%795[\4=0X=>c u7]݌:eHo7 *=fM3BH U0Eht5痢<[җκO6Jv(Y:'Y@=ZpC$h xWfF{qv ׅI*}_soUN`'<A˽7^t)N>Ewt_SFT ebz 0/utӭ"*;ӡDPu?Z֖kioEoeGkE7 UGJ y DgJ;^ɁWwSx!Ki_վPGCO?sFE܌]dڋ~bI{X8sU?NꢼKFLt PE :LdfTir[+65w=U'V4hY>#-q5 - řPe^z:XU"Ej?{:$˳z^㘌OM6v Pm޵q Q>)f+hdū 5'o CIN]a~aR}z93?X$d{(\Z5-2ދҕ~:, ^/{ dr {Zw9IZS&@a Y^xM$1V }HH{=*)drc|zPz~{?i^lUa"Щ}xr6#ci[]qh3@KǻznjdM"@O'돭ߕC5z-= pQi㬸Xb;]o,tbAߠmsZIx_;f휀ƙ}ǻ^H> UKUtJLd Vr8lPQ`<"H!yM+}F+p  BÝv"Q @Y m0:ˋTUPL&ծ7ɱ]&퉘 sqϫܩM(6#5B<\cpsq|1Avy&&GѰuՠ곢} [Bm?KORIi#q1nTuHF&iIr/u<-{tb$􏀉ב\:ˀeRFHl(7ʰH?,'(xY+&f}QgIe >GDSeB2x&Ο;+Ҷn'tzxo47mld݈Yk)ah[cK)m V}lAD &*s.T^d!qI6҆uKhuB^UQv}o=+!2ilvo чJMtk5-\DSE~q[a`Պ=ĆB? sU~Qh蟓#/Z5D9;-GgsB% 6=OP?,뵣ô"ӄb>-M |OUcS|u'ckшN;}*i{TX{A*3mO6I}8 AP2WL+o=u M&| <ȭ9B$&~q(۽$o#$0Rfc'>M._ } :z_RU Nӟ|ei9Q!j #}bl1Wfi9M[Qر lR<&WNR=%n*@|hUkk FP.QpT`!WY #WNS/&>b*_ù60ҦLn#b]dH9δ]uy#\VParMgO%8/ta.?xc(rmڀX HOP]vNPZ<=_Ok  Qw{d, %6?oRuM9Se igJb*{&VMɴuoZ2[DQE;5*LKy"YCB nl_G 4 h6D=:$C'Szw!.mdQCpsgp;_ ]}zSZ#6%р 4]n+>~ /\ĆynpX^5eɇ8)OW/^Ki{-"Kr|T @3%gPyz bQ2ǬKG0}T7wٳ[Ko`=L3"~dK=F=xsjpe&TwL Vė2 tPBANI(ڙVEv !„3B?.WːGvA>I`TpOtGiγ_6eU#[nseD/Aؙ ^~| R6mMY=Jw:G \SZ(ʣAW=3:+Fty`'۪f HԚK`, Sp%ƿjHD' YE &PX$=.QAh LOT<hnHԲq_~ &j2Eӷ; `ȩzOUtm^ =B"\b_/M l5ݷWLˋH1iLJdCl2(|u;eã: ՈȠa r}aG$s>9yaU̮Z2B_C-p7 _=4gkG<<ጜxT9p_rˠɐ_8l:3p)*yd!.N+49+˱ G`ܪGlߣ*'e E @b,it)SnRX>%5)>\ ]UI`" ]f޴8 lƺqC(Vr !:6TM~ iy): ƝGu3B˖G!Y&MuEg,h^V%(8Sy9sl  |bT15y)Y;x{^w/ۚ{|q[~T׉ +/uE:u".M.:P n$V-1tK%{,9NBhuQފAY^3qMr¤2Ͼb v=a;9x vI 'bM5lw`gɈ4B剶`vx?JKۓ΢|Ó:4M9+|VJ!H0\Z}{vgjAi<u(nzRN9m|サʯ](J̸Y;_ ^R@6C>Eޔˀ[n-6qU*}3x13{f =HSj\R Q52mv- MM݀l'?q0D\Y޾۪ .A2@ñbي?P%~ڿߓTMf]^X iI| :Fۼ6ȉqx(0u@`-[`E2peE/r~vjs')ԋTvX5 #|wgp -ٰr:,2GrK'QD|TF-BFX[=pv8YgeԵ6 M2QmJ5ɛR  z%Ȁ,p 39ٰ{.A͡-y)# 1n57,O &X$)$RuNXSKAaQ+pg,GCUC9. o&#93PTcLVWo ˲,E[G?QuQL æf:l5tImM>J^b1jvF|5N?́'ggE:-*o9[%ƾ<>MJ8>ZŲ"|3Pj:paǛ.mcL޸1WBv_@DDAy.՚5Y] :(;.rruT ״+re=͘>5)gGPzOs5ѿj$n/? Zկ:L?? rTh-++L!Uă[pu$K,$0Uص7\jtZET&L V;'cbp*CEF2 mR+Adc x^%}^1,g%_dy` Xchh xcc\bO@-ɟ%y"&(QtC.G+|ny鴣"ؼ \ʍr@J`j~ Da7ys Z/y qHN6=c 2#<aehe&sތ:4#(K Fy3g<^Y'r$V0\rЀ(+8Nთ]ɢDR&n#&,hpۻ]t~ .Z_3ηE|k~)!vP1Q SRGM=ҔZ!T8]tKyIKO@;&7gWO#<>ĕ>ObNWd'-$$ VRCnKoʂ?mX#NYKz<+.lV!V.LanCř~NhL[oo dM6 =ܲU= .&.=Js}܍3XZShq2O=%wԠsSS%E F[:mOHh8/sS'|/C9bвbL$/r+I4#/H,M8 =䪁A2N@) "LMIdFx#o(Pm), uj^Yuu8((*'yXD 6'|'ۛs= ?f\e1r)R,흾At:^nw{IjK`s>-: `iG8)$eD"5tdk<`8"pJ`Tx g*&(BwV 烁G~ @J T NbXe4RCt rbX HE 2as˥/2w8S&)ڐbWRTKd4Pa_0uZ:ޤictљnxdG}b($Ud|=tmS\I 2!بU >T9Qd&Qƾ4=xUco2ʬ}; )S[f%i~x3G=͵8(*FXDŽԢcT.ԉ*0RRRve$o=>SliRJyB$(lj|"϶(Yh$b]M^aVO$lÍjyʕf$=ɩMsOj{*'%j8M[sgP~I؉P=L*4s{ -J񕊼(@Q1DкNkP E`j0Eu ;Ln2$h{K )BXKd +f>n-rlS8a"1[ȯʈ#,kkI`"ƪdCeN܎+"Tƕ*-f96C{lv꡴mcKU Hr jjZ8j e&S{s72-gLb,K:-ۧtPz}MzU-' ]Of T@lGUb-أwjALtLNT;sD 0ʕ%/i|ܗ_ d% ?h.Ϣ0}qgL/1&LMdB9#Yc"85sweW}0" B*+ḍWGKZy+Kz4y..FuQbp3B4Sb4"F7ƑɢtQtEq\pDՙ"gQg#Ή nJ"p 8"MvL 4H:Kؙ6WBF $Q_%-(^(3%w1&]X^E`jqAt=1c{g0C1Xu[&qdwVt,'×MH WU'Wcsͭ4-bD3{, y+v-Pap^j u n!h. >ؠ{t2ԺW(槝]feefw9Ұ:ф[jkófx7 ;]ޝ:1Lgm12 8y@]}90p- yݼn*TDw>Ȯ;ZS 4v@d;*we{za֡OWD k6葄YhQB@y1}GKFy)NoH@%u0at5DQ9Kv_'~epp r,1Iï|'0ê:MTϻp4I GU=E+\8QIWZ\CvDTxMqo4զSk 0KJ nER;yo0@&NsHb4Ē0bMq!I;9ϯ`1ť ?u892IT={,@i-iXZb߬k.I~ sSWlnvx/]MdIEkxh~!W2%Zd_ՙ+UMf%mdnuxKf?T06ʲTLئư?cvu`#T-7XZوmtW<1} $GJ)sMj+Ddxm-g>cFB*.yAa ːjqb-sdXWi;8='B9[@H?:5+{%@''pI, قzs}<begz*iBGbk WPyE3Δ#E.ȒIgYIObqK"HqR?=*\SD8-w I24ywQ>mv&z%ebm(vG(fG,YYA8hDL&tT ^j=T)E(\=k [bVyADYDH?;)gہY>i]cY3d$?&jVdn`QYK8']Sr-m!1C$cdީNjo߰֒] 2LՒzJ(40{\=C$ٓ\ RX墜toX\"1Sk(٠sPcYP ]ۜ*k uiҐT$kVϬ53k:2?yJ,s%Gs1>]#[ACƱu8~ã,+Q` tm% ZlW(9$wJVpNCKu~#̄ENYnMΜ5 F1&,oy4Iۈ9޻x$P\)dyF}* D!9L<}<ŽMt1WQq OC'BQ V?-jO +Rwp&f)9f uiPb{kO{i7zθ?2}*nUtrs"pzw<HQ;aAO!~KN>2{U2qۘdD.v%I@h h8qaP^ &OgkA%[Qoo?#fJ/$vJ4o(w쐛}-(VcZw-D+kM֩_ïUc j~I:0HE7s@Jט誆utT*Yoꡡ\=#|͌] wLÙ.A(MٶlC(P'O'=" NGA׍7STz8i%+kaHF+`ظ :8bȨi.evwyEQ(ώ_ @+ 'Ebi~S=,IV"YOW8ttݙn'% A(K,ҹ=t#b#-(rŭ}i33(F\3y4$hY#ލZF3PjlL I^=bdBL ^$SHɍ~~ I?d- 2݀GO`㇟&lTEuL],à0=XSjW+'ųfWeEH@ė3m5>BEjQmnJde>& >' '/M:N WCI%rѯq.odkgxf/ʳìPhrS" 5E^%:nR6^u m %(Ih @/"o]3;-2)SGĨ. ۯ;(ȹ ubME*Hw=w_V?e:ϔю:3q^x'=:{P˽=[=J54#{|tU!Rs)+rh.乡cN(;W00y-< ^+PD:8hOVF4p?A3`KB |F"M[F_BnL49VZ:|6:fL,Gzټ ,EW1q!bCқ@;D&ՙ!=T4.?_(r]6CFp6 G4Dp]U= +RD"⻿(\hd ao3Fǫ`*1O8loeߦytU9b"T#Q/,zAaLG !>s(4`$Ŭz&3{z||fǮ8ms̼ZmݎMV Jy}ch<{j3yrAe*uCL63(9puub 0ŪЭ'VQXB؃] YU[Wm;f~R|̨dIxcDH%̖\W˫㬎^W.@ݢ%p77@EAN`VXXa—K:_[ g OS>y_6OVjf^ZT>K/!@NLq:_8lfKI9Ʋ !1*'*X6@ YI^,Sg)z[t E \2 c^hz]/rvIq&kfkb%7*dTxwF#F *d(N , *bW6--j wh=FP(4$#d]-%~a=<ߓ &jp!!82+dAޒK~n$kOy.ϧ/T)q^:0,$IB`|{4m|ROZ{t̳v"$WuE>^mT(E <s1nlʬ{8dF\ ʡb}HZ삱_Q/2U`@ |E".ZAiS=ۢ;2Fս@5JTB ȾZD*#BpĩѫR WK&l(?͖z["3z5Cpa-~,ַ Z z:S|!ltc;ߊ\BE~ itVsy@W>qQ .qԬ[nT Xkb;GIWԍ,wp2ޖK"[TRI5^BLyuS{d<>S{196.6,z,rWʜ)ʻS\F=vϓ5M~JTRd{{8Vn/;v4{EđOᬛTՑW 6S\j=*Q֙buKY8Y^%Y ݎ1!vIMTvsO44l|ҿc񽖅KJBK^ɧSh;;2)ɴƂln;jz~8~8Yb?׎IpfsJoO,K23J^Z޷xeq Q/k};Z7 j*C:;BDj##_2(2!9 :Cv 4;ۻlWd"y C8ҁ̈*c#UKe "%x)Tq:|8A\-v=6<'A{1rC᱃lanz e _~*~v#k.ys]P=3GD̲"Mbw0/|'f ("MF\`4= B0<ʚw} sovW^WJ\K Y7K{^zO\+B㦼nlU6VN-^pI9ߛf{]@Ij9{~LCm+?x.[Kh}|u)ٺApqP3F˻S8y;fl8yZ>3W]2ۅ{VR7''R">z(/rgU6N,ESZH?xر,Azq+T%Q`piMfCvWvLVH8ނc/tY6R:*E-2A-j8a9D+8BmQ̆хh*sL[} UHG|һj7 - ЊpXJiuG1!\"^)K1ۦ/`x W nH.ʄK1tg1aS:){}"m3;5L_V: ^R u֬a^4nhjkRL "C V!oBDWseC۩\`fZ5t/k2r4$6򰯶0y&1+MnY:c?~RUX5eNw 8և>Ͷt\; yy p -,+t.eK-8p a2}e+3JA(801l=d%oVDeMm4Syzm܀pgzwME,-f\eFZ` i+\ %l◄-\-RmKھ5Gp塑WL\S^T}s/cl5#*! f3hećyv3nq3|~k@ w  a#eȎJL`NYR ӱ@E\S0tc:'jgUFs¥bY?BvzEBZ) skg [̟ʶZHɺC 'D4e nF1V, F27Mo:i6Sbhh𪦶:\I|om1J ^.Nc" Ap)LÄhp`U iJTwAޓ;G&1; "inWֱk;؛y2%9Ǘ[)}n S4j+KxᅫWb {e4P,Ğ>wά'hHظ!J-5zhz}{I#kc5auIY6FFxȇuD4+˰K=*Itʒ>SA+g#՚ - Ť62b} I$p3WpFu]%t'm?alAYGo HGat9u zn ;ӞBwdY͍(R ?Dɜ룹5 K0G+LQ=V?o,~>0dT%v3Eq?cR. X Cݛ__yÜF \v`DQQz6($\Y77WE>'9mC@3$G/ +L ԇBykȡGF&?k mI 8)0b܊zSwZ'UΛBO^-;SF[̃)<"jB}a"M Ig7њ! f+o_2F&stkt>89UVT[좔z }(?2) Pa& |3 I{Ͱ_D2 B~gv- 0)D`Q#L撊ܺYU=KϗapA{iy?HPI}/[54Ջxwk3hCC_J;L1 8Tv,d:o+2Àkhs"% 5/CSF4bUS7-'Z!'Rl݇ 7dm%hd3 #s>֦/ҳnl!>I#p5D12=S#S0Q90@agBWr 5JmZ$BZ:WQZRf?d/ڧNZnYɅu(m"!ɖc"6?^yL/" fb4o[eϦ[kGYȞ"hR@%~Tca C+ 94)7Y2a=y8C!(PD"S-'Y($X!QS[L>ی }>ISfDaxzLUxb[tK.[E-؛q}%UAuG5y͵7W8'ɻFZM }ǯF{ -=ސӹ Ǥ2$m?;m[GGMt=K }]M>X/U Au_6+ mVQsfn^X{<_lNڕVq -|\+#yH2Hغ0`u.}u^d.R PuW|?̂zQL%g.&a Cg<硿&FLs p͹ |?8AUs]>b'PŎÚWM'H,!Tvd+*YSgt">W;^Z rC8oL~`P.PC.Դ<A,-j>5ibL$g0I^ &GxncʫdduUx,c_RG%1}YAjjo1ۈmreAbz Zޝg;m0&6r*yAzG~N!;q([9X;޷ H\~In_`H}K`>d P ׶//{1 }wfjqy}mikt tx6ꬰ1r~Fz#ښ3dpVb}[%l؇|js jҨ∵kH1C9 XEi{CaA)I]2 },0K; WHv!+0;.7j,)%o%ۿ;oA6AgK=~",{]'o^3|^׊s..gZy@W9H5G]jB|3`5:bsX*}kZ,4efÔl XW>t56;3bK6{b_xjuZ4TsIpbՕDf\J&R#Q9[>l<"ƞIAyZZ):1<])ۘQ)2ơtN,VpRLa=e0g)==;@Crv,}$W[CbJa#* Cqޤy|Xv:JWQ7T9Mz=KRM?-iEx!u[X,:ZW"Z$ƀ{&%͟cH1P@JֱDpq ]Y뽫HPk721d. Gܠ֬A󱋧#+/#) HݽdiRYF2 (upXh_awٷv^NNMNe@Ğh$aEKp6SLf"[V\7%u%◩^M8=$r5EؾG&6:Y͚B#jAp*Q2gyZ6<3by&lz@ B'6_">N[v?ygjQٍĭ\0_- Mf8DR/}V@j% /݁5>X+B`njC2>^㬬:/ۇb=J`!֥6`WNbDJ:xjCaRcn?,@(ڂm_j+ob8 Q&(++g7uv# yG 0!N2LL#oaؽ/w{>><̦qDy$O+4 4N( *XO& Uy@v"{]R9淛>>{nFۥV*RUs!rG/" uUW^-kرH_D8"gbgœ9N!-e&4JFyj-X^=aŶl B@KW*A2NMgZ۾KfOJV(m%hD?X6=ޝA%iMU`'Oy?{ v #; k/q᪜o~u8sCTOcNPa~tʬ 4ǀո~ԅ<#к$5[gM -~QбקfD 5kҘQQa `Y3MhNV"iF= ?IJf['9|#<TzqYмs(r-Ayb# #"&5 0U';p)m ^W9LFVJf=tyu DB3uNNǏP 3e{~pSyk׍bҟV*hBszW8W.ccd)3ݨDpiY~qQRkUu*l\dF[sZz"e.XJCWࢵm*ar?SK51Z[> ^3/[yh`Fo=@](gC8x{!%6p3^~U"M[6Fk=B u\5ඛbE GJ=Obӗ $H%'z!sb>J jƋ,YWH}H7b~y@Wu&s勗 x^]&G=Xݝ<.X]Ky<״ƅ{@G< Ѝ3GSUIiު; _D |M!iRČ[M-0۠D-2 Gu٫AXkTc:[IN:dQW ?+1dW# WFG'V2\&U\M~>{b^*?h^cQN?'[mu^qBkiս lϔbY͉)0.Ӑ 9G-nO 3幮$H[e#CQN/7ԸW=*k<;$C=hLQ-+Xl =~DP `\ŵE) nNt3wrUCHE4$YgVx"-ds }DŌ~c$؄N `!MUayN=@1 ,Cy+e 4"Q0:o [|̶T4E`'/^޸ƺON:; z+IJY-qCAov# Zs+i1#[Dž)kk$=KGy*bͅ\A~;&ӥG°2oDMc nzS;#$ =u6 y@j87Y`}9'C" |X&dr"pAm{4&Pkqf%9m̑M=0y= n]3uWBRX( q T=smv] pyW %={xO4v?& +:k풏*/6t W_DK7CmtYst"&8 b61K$ր0>aJ.gIVR+7dnQ2oYBzuCv<.)Հqim߆|G캂=sqm<`m*&dK`[ҭ|H 0!TmȨYż*tX:7 J6KHȥ5ZֱBiIHKgʬ("Sf߀քX|SG(ҊOLn-No Js~1NZQ vC^Jw-+Ɍ(bWHRJ' peXӕ&VdcZM2_3xHo.~,gCܨB*\z< {麝Յ)%mKBԒA^s ݄n1)V*҅3׮dsxsN%e㭧OM7;ޔ{ ‚$=ۓT,J*[!his*]CGIUэgwr@U4$|4oC8p ڠ_H{_!`,2=0ux |;͑j-FqوX)SpưobLgʉ1|9q0:>Ux`!]KtF7YM4T8n{r,te5Z74Nwi}J\<x#H eO^ԸQ`=%ģў(~Oڇ@­7+I,(^֕UI(BTIZᆿ%ژ]"J\]-LOv$U@̈́&p!ҐQh9D.]6ŇX4=!$Rao譄O=bb,t|*9ZjEo:^RU *Ȅt lȕ C7=NL`Q :zۃӂ"2隔=L(ڶұ6\{{1:+] Tɂq&ftm<hZCvK\ ޘul7wR Ѭg0ʁjQj: ޾7}7yQIU`E% |aZꃧ/IIieN-_#|-YIv:/(i FmF~j|s}ƞZt>d|K1 r-2lN[̶UOB;sπUkVVol}7rd|#dmLݟh~ n{*Lԧ 9-lbz-!$:T\w5˚U=8$\}KAq΢v 9#U7mnzC P1Z>ߺZZÎ|R KpQD&fΧM.P7cMdYq xqZsSW͢΄?CJ:Î074yrEixkm$V"%7hR6Eې;*J׆;~=7.N(U!d0DB Hyx,\ 'ϴRY/C i%lR]rUe ㉸[`O$c ޗըp{t`B+)t>Mݭ7Ņ)+"%'1} :#=q% jywiQub셐20x>rC?j+ӈMj2X]G GRlv X729ڟH+tr~u$i(1wI{;КM7h;yM*G][NbYE{i; n(h+ kP_/fuFuQaD74ɤ 8*gXڳ2vVB"5< Q,RajxGt YTN9-!ѡ]1e^$4xhSĺ P 4M?w̰r#7ҭ9VٮmۻwlWX k QrSБ<`e-^@ķe}/#CW-z| ^ j[zϢHҿ9 AJ˔b.^xv"lRz8=B8)zF\Qa3mNŊ+ASjp7ڑ~1#("!0jEZu$sU3βJ)y^'`&՝,|CT-7VGD7T9e~m6[9} qz]朗nuBNEq^@}v?ohJ|e % $aNߙ%'#lǹLk:2;ovz!^8w6^\0OEmjw}ME6.x6 2=T(jꁰ(]EytGYSZ/ d`68xWɁvNFlA8+9}: *S͍9e6։N7>׀y|1X βRT Hwz~HYF:C4Ei3E-GV#dOc;/ƍ;/XM&U}u.Pd(i9 &$b'DZc{19e<_HtdQn `AZMQу+%; M|&ڠ[m37)8،|#Kh?NQxZDmheݳԡDl (J'#%E"`}Kv-iye_];:S4pf6AncmFΎ%ЙW\Ŷ2>}"sZWwEpA#]^q*q)neG&qwB>#9tU3#P4XX\L+eHRFwTR&o4=\r^&^훛VMUbzP֭*F*jw/$/U=ID~n?OABZ_'M{E֙\txg)nSo$I37ؓĢC=@O'ϯ%6$"c~}uL&p+^&Ґ as FYX4pڵmyEjhkp=28 {̌pE9qGET4p\7^pÚ'pFB65ñ;DASIia+v.0b(itn6!.Rރpa*QDq&MR0~-SP[E,9!\ݓTֿm*;ͶdW7"VأiF%\h>' uYWBg$s &7D q,515L!<Âmn'Ɖ02:ӒG]a=g'\)9/IKf֊;; }{a4[±\͞JvqK8rymHIuD 跐)]b$£% a~/E`Rt臻 ݮV1 `gaW吏b[\sIE/&˝Hê>PPkүӟjR{J'iWɧ'"In2=QsB߫ۉЭ{%➳5\(Tg dx؉tekJ]Tiir G iV%|ɦUe30hgXe 'WB 3`X}I֚LKwH*Л1ܭij?s=PӰ!H#c0!(c6$?Ҧ`B%>pM j['qܙ4<{ӕWTc{"<ϒmbC%I3voAl8;n0cLq; >*<հa-*»ڣqS::OX@N]kل&0PWYd{]RDC'l}(#B &l%åF~a\[uv^=X+#v'1i.P~{HӘclț4]DI* yfQG9 xŕȷu$|Zs+(5tH֫C@[?XnHlۑ[ɯѻ~H~dž(c) g4S ,Qat.3TfdA Nw 0|Q1oA/ң8~%xn?e(UKeG#VBęQ"@kIuDE6R8ȡ፭B㇣֐/97\N!fVǒG Ez=swAʇlN?AL(@a|V/\i<9d_lF#LSLuQΊVXeJ-v:1'{G[Xè#؈ݴ"?+2?yݜh1k:RUzdzRȕc,HTD1eF%? T7Zz2:Ǘzi礖c=wZpO6U{;Za͆7788W@ԫpe$MCjGq+AkeGЧwrnְAF̜MWh*A#QJ(%6'!16dxd?ܼ#-?p'x>c!\9}JZbX>V&.ac kgfӼ`koK_l_HDlyW+?@݅sf$6'Ut]Oz kt )>1ȿ *`M f'[NR,}: FT.8%7a\vWn|^'\݌,`9B,+Rc7pxu>]@RTǏmup=]{.D`5gL%1Nf @OP]4.rɩ&q "| Zд9ƜLATjQxh5(f_S5W/e(ŷH7'G`8Ҳ "+ʼn, 5HNnN>}V;N<%t(dלwr Ίrb0#r 5,\ġAsD)'l//4 ! GY)KRbS/ d;b\}KV)5UkT!7,_Mpuf}1 )]Р9ֱ9u[!w "<' m)& W2B<r4 \4.DoRWJص&O*is.ly= V-OcYUES1Sy$;W!/xCfxeVaӕ}oPvfa@*zJ? ϝ1%c :8r!:.Bl =}yLvݵ~ݡb/IB Tm8X2?{+< S!l_JA UeI-rRR=Ίrt2Y5ފg'}T j.*aS~ukϡ\,&"HFyj:W/s''yT/:&M6;npaUċeL*3{i[̄GH h4SL/F)4e{$@ݕdc" yԁ} @wxSSӤE7 )87#8:-)=^ǹ9-Ͽ1;3cf90p o G: cGByuxE+_Ѕ,$LRƹ  M%]NU0iN?Z *\ r(M'00nAVqƭP,IzjXɑ50ǚK>Ew2$=zCGK?4GC_HKd"f 1!/Rjg1|(GRE5i nw9l{Ni 콈aV?!ov6iեۉG@jY}!R˽6@y8PV(hTq) k̖Ax#n;'Q6N9&nKO$@Y402ۤBV^DiҏM-X؎NH1p~l)1J3߰T\ vE0Q!q^% g+iϟ/}dPPWRFRbjTiq7rTAcd=>=$p&; \ur4*}(17>~U}dPaF`Ds}X!yyQm.$+kΗϞƳɹ܂n\NM2xc6C nʏ֕|D w>.]ޣ}*8pΖnDټEQF7 !ވujR|6l( @Vi2c, IoN 5N:E"m uC-ށ yrbWPE2Q'$#ZeSU>gQ,yd}:} )*ᛈԳï8I+_IH5Ra3Y{ ƹ5K+1ÝȰ}4}{߇,>!3 *tIJ_Q])7,՟rg )%GIɶ [e{?j'@_|`pW!c'zI[V?8 ̇ e0%ß<' ߎJ^VC&b?G&ͯLo_IH"/ҡ?gBfk96xj3EO\& H5q6&U홿Sbyz[Aໜ>j]\6WJjh2OQh"?TuroJ]60ߚյI8 gRsVe< $`].Ъǖ8ʮ*ݽm뤤F2P^r+CFM{a( ;<'yQD3ss6T!:}H!ӶA$%bLM63 Xf8[Jaa_sU(Z@I^"B5_0\72/ 3w>H_v%RGL|Y^lBx`'Vl #wBXW(5.ڈv,LMawlL<|޺ȋͮrWT]XӐ9{V|0x~frJH^TZC2Lifov+C$}D"@d8c4i ȶ-/qjgeS"Dqԯ3.+(Kd=-8ѽN6o$hbى~x0Py d{l 7!:A qE;SC sw[lVJFpg!*~;HT hSAe3=Ad"5 U %IW"ʈzz#*t%MY!bS×Z8ï+Et Rf 5t5.ALnϒv(]\SYϡFb@2w\m@6c1ga @$s *1uL9FA}Ѥ!)&ʀp$۔2I#ɭwvy4f!, wȡGѼBm~\"sǧ`p%RT:ØDa*Bu_^(oGIڝ@Ֆ3ndG:d6k0 kIY/ %psmoCֻsAćK@z2 9P<-?L/duG;r$CxA8р2S"Ŷ2=^1u]g5jZMfLzo*(nc|-ZJݻ PzC$_EQ$$z]~6J /^5n5FmeA̧8p!P:8mbZԒkk32$ΓƀT@%L%,v3/c0a6h9[ MlY)UxV<J)~?Ca>;Ӈ JDQPΥ7cs}Qܒ - 5ߕr<܆{"<֮8NA)5-%%@:Sг5+CeWDR`QG7zF:CߖL/-ս6=u?kZ?jR-;f_!7x YLT'f{5lE= tT;=b.>(%(HUF@asOB( 2X!3Z=?, ay?@Dbr!]Oov%tʹMh ءM\LzkH\^11Gɗ bVuÄOC\5,F vD$CpVz}]6hK'8"]TRju1')\t:0-q>?d#(7%85{ ftq_~ew3oIlisy^C7(ӟZ8餚)wk#yJHzP ؤgop9Ch䛠Dl%!BQr=Z;;R}>Su<^斪1Y)F)_x1|T/5"DMSfB66ͧzyk Ѯ6:#d:3Y^f n"~nc^9_́Jӭm!~*L\{a m_R`Jj^FX6PR 3pH NR4G; t Ɂ%9߶Trͳt7^IИsʽ"*VV/y l}"LeKH'pڰ4u/R:3`ꎈg OT)]KE 9ϒR(w?n=pYcI>HW9<18%Gt߳BӊvDkAo D) h&dR}-+:Fi,tCQeP5+ٗt՘61Ѱ=0-t%a);^)آcRT窲@+-07̯E /u7pe;qUU'JTf`30f# =Ӎ]5 rO۪Z CM7hq̹XPhK5/R v*"qF5yZ|+ulZ,t.2̋-nլp43d~OnA``iiY;@'#띈5\,WD89gRDBT.vgeldvL&=$3(Q]^mEHQ(V^C^Ӯ"[S1( zxeO=_K9bWga%^>o͖|ꐋH͖[`@~c|Ϟy#Yy4`'Fs"ڌ)@-.E07'hViք׏[xvqzw]s)lBmWs ̅ZJ1ݿcj'+]A#TL.r<ɑRG߬.6G>>K{uTL4m_V4Ef"=+;#5djd`fGkᴝ.!o??rsɩ1U7`^V ^`SUjDlʾ.ז|JdDdBrp轂+.~ke oB X9WHZ7]෕|g C䟵~LіB89#sacv78}wSR3,j;evN~C!d돧Aނ0nkw s:#9YczNC?vY=r͐A{uVv2@L3et&i1ep*Js@~x6L-\ij"=*tGB{-d`mh' "![8H˼8a$q;m<2e N}D='|Dc-nsVݴwt.E@Le;{«@`h%/Sr 9Ʒ:_=w崻sr99U91FP_g`y)xAK_XT qmlzBs d) /7ob~{B]Y xJ(WH5}^jk,2!U59X.l9~b*oBX#Ԁ\N ׏ T3l L~uKkQDGG%``/_UļF&~I0υ*hD#0N3ն /{O{`a@Dvw4ׯ YVjsɁ=ܝ&`e7oqffi W"G;? }odz Qw\3|̜ BtCSixivt`[`7 lVj[Rs1ǗHHc]~BGLf++nXeM2XfC.]R܈T7.2PK`eA/ 4kHdcwSv mqgYo $c=/WXt)A/3Pm+dMPWmvfcEozH!jGOڻx~0~>P{G Agw֋ rVuTHX8*0S49ҒĄϦΚ Ca(QO-$X|@;Icwg)ᢆ̵/΋ 7eQhq3#)/U,l*>$.={Ȥ*<K$v/R7o0E2uC[Uhw|*%`,0lgB`5^sYI"& UqAwmb*KP@ 8{(;~%%xb3W6Uvd.faד'@wm˩ILaFUgNAQ1X]EkfW+ZiU ^ީ5Oo8a@q..NqԿ|;9&Ɯڰ^M"z%Is l-D7֬0yXR " QErք9* 5!Gj2P4D׍S&C}qMtϘ"AI9; R ҡxoZYY F(i7<\R~|~N4GwPFS !N˻dM]2?3J/3J ŴFjlw1bR0]WM6Xl=B0Xe?ۙzsHoc xV;({e,( )`"&V??׽O ݒL15F1}{rDkqaY{L\_R]un@961.njOY=>2ʰ %B_njâI-&]M.[+ 53W"@KVR]l-֕!nI\hԆ=EiA*Yw\4Zn[`֫M,N;+xv+EГ&߿+48"7cIPcI~RhC)lhW<`b ?& ea=RoF!]:{P.^Im/.X)۹yRj@4x 8|b *synOEj||H&vECK-.6ScbRFFth-@@s^%H't/w#YG0}f''6,ʄO}f}ge YKb$07ӧ dő86SEGZks Y} ` !|A6S˰*w.m\:=̃MlʞWvtOol;7ֹ/zq?RI:A( Q [BGF!FIᧅ>!GYMy{^4K^!.JBoIqk7Ay/p3X^4 ,|o;%B/Rϕ xdrD3pW~W7H{K ƃ07]2?Anz 1q1gQ^̋82;'~ɮCp?HtA+6Ìmq㻩Ɣm˜r|ceܪg)(Bxdr&4HD4.40|2H-wa~~Qtwpqy@VvM3A4G 3,.v)t:SגzG+O=l )_tj%DXf`_ז+wp2_jgj6_M P~o)aTkպ!F4;8]dem |M8~v}@7 FH_Zq-.㰠WgIhpk{h2ʒw E sc5Zul4;7i2,Є|R%9,n7>IiofX 9 кa?Őa(*\)LgȺ$U+釯F@IIjd2`G+\&+J@=Pd]+=Mfd$!IOGJA ?ErrHiMV'_ʚҸ|۲ah"I ͒뺛4e}_dx^Џ{" ʝRQ~Rq,=(<cq#tL󁟦l`n'sLNC)KLajUqL S2!SUv%*.[~BQ|뻡R\^b!a|32lqQNgTEya;uR["2˜%4| P $E+T8҃G#dBpÚ kI(7<ī0qj9{sW4)K&7+s8j 5{ /2I6js3XZ@&㍭M[7궫}Qer[t{q&tQ&=AEĞ1a cp"m%$Wu $6s\ 8oЍeW`:~ySvEv.A?bf*ȣr0sx\$g 8b(!h :b󇢡Au%/U vԢ.f:ۻQw63)R'f5UdHin|-9!vk0gLU.Թ۷шT里u@]#8S 6j՚$28R?0xjX?whH}#u<Kl˵R)ɤL8dA'%1*ʠX(Eh(Jc*Hݺ`PZ Қ3xvK~˜/Y*G.}Ms{}|B ۆ4T5j%* 41RF±Ly$Ֆ1ǡ*5jUys .t+xVOTb D \/\|RD5SޠXxk)+3ͳ,2ArPk">M} $W 虫3?7Ito7񜴻9Zg̭u FHԺ1=̆ɒQҘؾя'Bخc#RiCw:At*X!Z/P.L3\ ͂J\[V 'c;fm v._A?LI!c• .,'w5:,|w.D~ josS!^;jG?wnB9򭡈7"$H_ )~I- Hl?,{#.RM lz2f#qzl5n$j E(Mye1lKCf"SU,?X !rYU7Y}` .uzLE] 2ȟ${R]:Bt<:ō8' 16M% <>ȧԢ=a]?-)ʝا^Ip>1_ ^ynMO{yo8rπ$ Acs*몱Dm^|\3C|G[sXs/!֕R%хф~/LRhTK2caDnoۓޠ0&i:PnJQw"ם)CrfO:t *!@)?qd`zO\h1!GJetժrJ#b8ɇGbe=|% !]d$/S`cP6;&Ǖl v3 |s`r0k; =EGm.i o6m`M#"4FII`k SHKfn3;xxMJ1 =Li'Y5 hB'LQJGvn?>shڀWk\e2Yv52f%ef#B+Cw`l)pX26 s*"TSOt.l"Zrk I %qP:͗ʙLI vLX;cEɞŏDH1d*JZCDe:ۋ Hpo׃ى0@HV_g3_4ys]IrO*Zui{mY bB0]ڳD&ad#*2y3)Xn~++oT=F7">Q0yٞwɛtanš=Gm$'!F>θl V ?aHcޭ7k R4&C=\m68P,?˻* G~%VTʰ4?s}`-&QvP{E-WLO/ 6Hz7 r+kyϾM07cA*~k,DF`FL6~!Ae,<0lO=p3̟uoA-ZGJP>sL⹎nRrV_֕V͂#{Ғ0,wEJdUw8P,Y9Qc,Y\7~/O`'o; W׀K^{i!k}C2Zg[\)披s,tb멮lq/'ȉ1{XZOL#Q3)i0)x׺-4TUa"g 2n7)a>v 9=n.E4vt| UСJ龲ѨW>]N[\!6|v/sU%aQk%s@+<[K'w_°Aj +D) %FΙKm>K~ MXi8EpWd_1mXmN!B{:jSV[4b^Yl%Nz[ZO D1Ƹ|zzikG,OŸ |Nk]=(lkbǻ{}㈫Q#/ GAc/aJ‰"`x9昜290|Z^q晫wҵPs2fcBGRӮZ뙁ؠ@P`6;ͨm -do7Xc]mDvo$&WmBR u:=|0b7 QVq5rY#Yʬ*XU RaHr8́Px;9jwK6{GdGB2B94;dh`aWk`#ɹ×Q3;8?_ר\-dI:U =(ֵb6x8 "\j_k.?Na%ԇEicGCKq#9+L;+ o> wjXZ:Voc;F} ιu!}1.y-U Iv_Y<ËB 0oji`KWȯUBB AhF'%eafBe=P2SH$ڔ 7|BP.g2}b+6 $}fJ1(9@8ާQ:7pkF'Z* ~d ܨdrI;4햒^)7W-ҧ76̒oKqɭr(d%odmw;RPyP tLlwr^K ;m~np [w"=ռ7 ߻/Uۺp|e#"DpH\7 m@B ,@(AD0uΰa(u*Dy!592v̽%;Z>gRqO SNfuOޮ×fA {ka%^ߦ9;܀WN:|}1E;Ya''jmHsy r H&=/V,#N #e|{GlqMiJÅ"ʹ>|$Y˸B3LN˜ cd+="ӹ6^:_ ~3@S BM#f=K$YC=r2w!hU0|Ǒn")-O?a0Ү /m YQИ|E$orICFLJμ R˺eƲ Z:ZLfbSK4Ydq̀C!P Ss1:{cfuo~Qf0j /sŲQ`DЉMX8MR] b6moD"x!ٖ$okEfȆp}:WYϫ[-@ Z1Qf 88 KZ9t"Im'=4*,ޣnFX#xn|mͪa!1Bf7xޱ!,d[qIw/7%,TZP&;= Ԭ~Y~{u)M-CϦ&ieI`p#Xw^&QLtF4)cƃ=?aI~*.QrP!Ƴ$+n% nEoa\qz2QS[ʇr\nku~5dlb^UhO p9Hwmo/p"=c3ED?~VJp|ixszb7{k<:`.h݃l941di'#>yٜ:۹f\w ]VH2A|DEp 0S82j!!CH)gm(:/΋e0H>@i+D7#/L APFJ%Ԁw$T2no 5 B0=-ty{ 4 4"Hpa_W Pv[.=6Z:W,Ng잕\v7b܆ш+IЌ񠸸NyRNѢik4ǟ%z1-穬5jբeqk&rշfCzv:E8NI0_ַv>77=$y]ӗyt ;WU`]_IJb*7,Q m\'#֍=%6:@;ėzAr |k5;R "H6\V4¼9%m8O Beb04U//M%w4z;jQ$g܅3/&/&htvm’qM`:E;0?k lb!S` *2:Nedt+gY kߙ!HTN4JNݻ2n۶ȉTH" @&hVDA?7@ Y7ilѤ7!bmUL2~[],Z00kAb>9֌{k$D~U`Ō2&{qMwE@M'uÉ}j;|1R͕w:ǘDy!+P )&#JXcB.GtX}:hC'b wTF妝5PV=~;E#6W^!'OȒ7VJ}hzA[)^)&U^MIFWb ٛ,fG-~}L|븍[\3.<+/Dq/ftT|J_\.h E%ǥ#Z WE>w\K"+H k7j s-U$CB.m{o|mAI "*$xouA{ŸFc6ˣBS 3HpV K7uսD= 4yM#WIޕ܎b߽fz,,pw>|XE~@}!%^=A%Kk/yO0ʼz7-({٩5@pDꃺvt]DV *,YsB\p1W*L)%2pt5$?Lboի{>`aS 11ތZ!| nxƅhc-$@YT[=݄إHU,GCnUYB Ӌ"/m^'k(]/ =CZH>L Ʊ6 5cj`{ oa;[ԂqN<|JQȓ9}˿푕CFko1͟i$UN2#>NP7b⥧nf+>l`gBp q(q ]P6mho4q.S%7o ̼[4}2Ґd|k2͆.['DI?l6[ȀOU't9 H'V%JJ}1*A7[B(9Ɏ|ze1>Q\a3B#~@ChVdx JVfh\4[ cSM BJu 9c( @1VUPȞwDk\ҷyn퇤 Hc# Q_88ޞf5[&Pk3'H[콕$qcBLV\]T왬2= ~Y*Kjq9fu *eWZL|E@!ەdy0m\U]UDuض594F߳ { :{ \HAG:1%> ;Y7}١quKDB*,]s2 T`򆟘TI P a m_˾l1.F:D8/*nyL{~|۸v}-/ ޺U|3ᗜ=$\7vܹUS A&`rYݫK Z;l]^\?dX}Pr6R!TCt#gE"{Ϊ׬39gW~qx^Om+ˣo@E<7p'K@6<-j7 y{mX|dQ%α]@yݍ7MPg^܂ϲFe?vqO*ݚęA F Y??*'e 7CzL^XeM!?8!G |*4ƧCYG3Yj ݳƊȧ ,&n%{H\!%DP;7~ o3`u:&8J2f3ӕU\xF 턬C?5 HVi5[*G!LPG^GF ev6(.a.IdBr866 wmmm/ulE`¸?O1$( `r;;M5AKWR |tu\Z!_HV}/_ /C#4ÐkQtchLھB";5f:.9Qqy\#j,QMTI֛1)BNݍ)_\Ǚнm{]:$w0<ǗUt\&\X \O+%YT'$afQbVOPs9^NT1eÑnq G)#21ڰ2daXF4+۝ԯ/q!UQ1=)6rGu v& JEapឫH5*[jI uJ f{P>TM1+ܳKgp;|QD KxMjΒѹ uf+=sWuԊo:d;f~dG.2zYaGúa %"pT19qT#1 +bAbЄ`slE ։*r@/}<Me j\K)ѳF&?ty`c>,"3l~8#lX'nՑK!˯/H4Z@'D>`-kT!=0pT+@$dG|>)bad[csG%Ϙ P.B` GY~1NX6%Yv#Orv 5EGkdC30 9z lK+V Zz hkLsm\A]_c0DHalq 1ܗ} GƆP4QxLi^} Euo|7uajNC|bZ~Xek9b|kRcx3FW,+^nW S+-UBO'xp[9bq)./ZU<'_Ro?⟖.T-"¯YxU B9!>!zoئ$A$J6%!zjFS^ƨ0a~j?dpZDwJ#*F԰JXw@#hzN'軮/6(sNK̐D0q¸6Pk_-_y}okR5h.}ڦ8fRgެJȦk L?P(;3 eX]f"IQI"TmG>OMrxG\X'ӱ[z}zx`4ZCvFh@$g|Viz Ǣ 1eB'uv\uy-a^yC~S9Gbo9u iZ buB`ؿ^;|fc'l~- G~am觝8otiLoCk&j H+쏛;8UR$޼)D=ӷؐ(^~6%dK-N5 pHBN1@r_@{ImS0Ԗt~5).4o0i,TvKL#A*Ib79;6E1סCΣ#?p*f- Hs9?ZFWW)qdY-TčDH\gjÁ9r*(Sq5Jfh]9M\|z_=ϟ9B'@)u"h`[}nAj)xѯ&be&mYw 4*uNd6NVҍ)vi~膽2po;#+UuCjt2- :t'qF7#si\1zNL8LQ/-Ȍ`fgmRs6*zi5WX7]a(~oU \IS.-4.-@,}Gz-eX!?JU׵Z I 7>e㦮ho'{a&ġ_.y H^[ 4y<<-N2^W{k/XJCZ4$_eo"r.YF6A㐼Ւv V:|2߄jD)wj EȚ ?a]T_EҐ8Zg49( 5^NꍥG)+[nW̅nZ-^_6CJMpgP./ij&6m#0N˫ia2#.T,kXgTWO7"ouo \&ٖ5cv:tw[9PRQT̻_Ȩ=[i&,oijf6*0e͊h#*p`G!Zˠ,OӧFm?I'r(9ۼQ1b4 Alݠ;|ba}3/ zHRp]HC 3:ugN?P|8 GI+4L'S[U _V|hA=K0?;Plg˽ ܫ˶Ya^$>s<\(99&%S۩] Ywf}c.Etrr4g)6 XڐpV\x.i5M䧆c_Ѧww2i88D{~W~{-Ec~d/9g u dKNt3i1 }d¡=MN㠘{׹qn)gn]).^UqvaϬBRRÏl{yJ'l*p Ao'(u}7;=,KGDI@Jm6l'j.aPV#o?!{@ey4=F}.Œ<ȩk2*Tb*8Nǝ^PX>a2orisE^0-("F#RT賱oCP-48(U×R)柮 FEs睥0uj~loS$)q5 yHz(˴)Ss 2$ib{e_JwㆫNzh5bk 28snH#0AԖ/ĄX91'\GFKr MljerMH%˱ɛl*L|Ub;L j8!H־$9t\9زj0]FkpLE@R*xrnۘbB$D}݃HrYx`1ăs9#iF6*=! gwu;.^vAS'Y+`_"gI\lVTΙלԊ';VY9`1/ɏ]E6=xg!m9H8w2nf:J^0 7/?Bg]BF'I,orj [z0kXr:]E8+oN@"qw_fs<UYҦV euV T3BLO$UaŘrkD+\L)n=k|o5&7fp\%2m6STSF[wD>/^ָ$+5Bg \W.?l2KPmMsg==d[j}F|3]{Qw ځ}qEq*fzC#լ$%,?LIzf͝<b(\ K`rm ER&C]M3 2'Ƞ>dBflyWlPmDLniLŎϯ`h꿢 i\ކepbzrug|6R+`_Bsa 3iu, xȩ,3w~a;Iك٘:h 1&;"[y%۹O㵉}}Nn;ʅ;!4oAKɘȜ S4 ke+4:+ǧOO78WU&#p<=ϊ!{Lq :̷ .@mE?tU1a7i| XLj7B}yyLh| , g&6sTXdH]}o:&9P~,MOav!3\]|m͌3+ jީ!4S h]nJ0 }zDl8myu)(߈S LˑN]fAY1̚P`n$Lr7Y~:ZJ NpDaXiE_ƶ\}4A[@h5{wS|LB 0+V>7wJԊ̟3Ϧ#6v~ K}]S pg vgB!-;eoǒ*.&ܟS<#U ?]$\8݋?i`ϧՀ ^O.(a>W1Ս~Su z'c&8o̟u-Sq9C«T E+Adr@ YP̷t'9itWb~;3kݥhlH48 {?/۩W}7kB+Lio\YR|n.s'""w]T+AȞ}֕;HЧeӪR 8M==,܄%_LՈdpe/Q ՔWQ9/YRyҖLoq۵fiNzq"4 Xĭ1oo'cࢾeۜͭ}Q=z&mps֙iGTT_)vRu6|Iuֱܔs=[gѕ8'?xI5'n/h^aH+((h Lݱz=) vF;L01 BU!Sٗ5^{TitOIl ,|8V8)D]5[St2GeHP=uLiZG4Գ#U}D{|ϊ,kOUTݥţ<9#sI~OU88l@b.c|ALo[(!ks}Պ(Or¨ӡg!0&>B{(s*/Ɵ3F2pX&ek:_Z=PQ޺9re`.8D4͖ķ{zeaea}ĩ~vTR͚P?/!4Y,34ʁI3ZJ?Z1qZjZp EJ>B~ x588RR%`joSlvFI-΀˹zMg1F@E;;"aREQPs_Qd;eyue~|V3ĥoP9t~3JaFM.>.mZ`9ˣ!\4*kRCϿ/t}8%l ( -H֊61imlZAm!B_mouu(94N(M N/tzZFV=A>i 1bYo` RϖAZ8qMWds ЖKBTU|q_[c3 6зA'ϝ~Θ{jff#p+3wmH|BP-@/0gCS݋mK30| fv.lb`bj"t6DЖ7/oEPfN$iJ_;Ssذ^Ou/J0#"zaD1wڠV༛a//1FΝoY@<0Rh a)5kM*-ƶ^ 3լxt"D?dհ,d=7"ipn_R!!?s]W|Ч(9=<=>1{"d2;߈fO/R,QjD`Lr&QW1$Ip]56AgކH{/LAMmZo=$|]tnj˲O1H; +P`ۙ t<9GA@&TJC[wk26SI6D 9l@k(bn0ׂw3UV-8gy}6Wa@xICĴBԎw;S]mvňLTx{YAVHk&T>nԎblf:KSp|^V 3 AP F™EllTb}Dq걒u?a'c0 j͇B~͡.r\EY!Kz{EzcuJ&eQG_b}aru^Vkߧh%k&S _&j_Oќxp8o˱ =6I];2-"BN3T7NJ>h&L>#n_#G0fiy?+I'AW E>?4t[AkG \Ȃf𾺉zp޶uPλPU1*%+KuF$Əun}HQ1*Qi#o+=6c]az[xЯ0.򇱸eп/ZZVi50wk8O\gЂRM%U.mtUje`&_QpŴn]OgT_@oVh\_&s*gbJ!o"ܳjXXe1S0-IƼu4`n:‹GLrgUNp$w՗Y$~*Z\Pr^P ׭9 a_َUFC!T4Նr(-svV# OsʐRrYQ& An&WcBs^gPY`G_>55p=PC Ó3OaLP2^jLsLlF3EW|hmbCqp$ 7bLt'uδZVNY@C(lrĘ$݋u. y)8Qw"ы +y-#1-6sUØD3, r:ITKÕUvs|vJf|Â<5 i-.=ߐh+~l|n9wxX)Cwެ01uDϧMo xGW:K/c \0eеV4>'TϒI°/oݪ#Yn< %&YD=(vL1GZi{XE}/vjWp:r&>QFE_WO\·FWC\Y& &~xW8S-t^2K2!sIJ4H/KI 7ġI|0mn~xtNGDm7D7!u~R_m~o,vUۼTdʅRU0@7"Z\)1@;T[:\XkLsmv$~)D d]o 1}' Lށ`3nUx[[[޿'؂SHH/.Ǿj&0#30VV T? i*sgw4,rEΒsP{S(Rʾt(O$Fʒ>W`qpd 65ybNJsS QO'2iOďK){[U8\dRm/֪[-G,BzvۜH C5U( ^'@"0-lHABZ qtD ?{_τWp["咐Sagm2<.C_$ 1 U$`zo9);P UpOWb{sJ$L c;6nU&%㉆%9.`i(E]ej)m 09[0+Xs[HmԷ"wnf6Q^C 8-穴{4ێz(sw*51ƍ`$`]YKCZ#Y.L= |F.N X8Re곣-?F">o4BsmYh6F&  JKQ>HFt'NrP21 =r}Ν)j:I: !~^* WLʎ_Bt`U=#P+Lh͐E֬a=Ҩ_ Uږ,!ᐕ uN+Jƨ pYj7x0Twa[3 a'r>efG߶&yL(tH_ui)eFb~Tm}V{*A8;,5InlvΒX,Șmb/u+ M[AmTb+"6mmNwc KxK8 <B.*2bv37PC[jʋL}ʍ~In0pwÏT7om2s "؁~ G 08t/%0ʃx>|ōsQMrrZRvB~wA1B^4~PON"-u.Nsn@{S嚼/lˤ52][cBduNs>n`Cox WGU~FG٧ .RݸBڮiz,w*PrS&_P46>dOl7,\1fa79H,^ujk,JT`Y+CL3Cܑ!+y}/}+]\qv39q+_|}eb b?9%bpG'FrL t-6N#Oy`MTPdQl}4\'#2n`,ݣTt#u4x%co^,Vᦡg{aߪe R<3=*ÎUĄ&Z1bwIm-o: ٙzV$ED:6LoS1r0Z a[L7^O4L}#vqL(~I]3wRa#i4zZƪZPߋhX+bh*ͭDP+ɭbCyyl<7En)7d2NPjșIql<3\9VzJɺ6WZ-0x5n X°5P0bb~ 2k/kUO c5'Sk#ktOx^' :AL /f(4%!aoXX6PR([c7XӼSe@O3qIS">̱飪qr%$/!yc9ä'ab3m&!GxcWTz*zi_Ozpޤ4ҵ2Г% x8: [t{V;J38 uR7ˎjC3uOZt˂K4]l|\bo}Ca2 IOR+%t訴EX|([rT@=5e1}cΪ3dA??YGU iUVۥrkdڞF.2}ӈħ[HMܾ[@z~+uPx'Oe* ŝ兠O` YR6`T(2#sL>M=rI(4"C: Iy0.޳/| uaņYMшu¨0|4cc'C]PwM?j4G P9__RxnTKwj,[F}m:$' JZĥԶgHVG̶dyL8A~{^ΜkO -?[A`=#$1Q~`)fQCIulRF$끉~gwZzys.M,eXWr!__bf'5fZB7ǯŎ(|iN99!c;xIX-؇5:H_F'bn"OA,C[(Lc&>^$>$( (4߿. zHS(5:pZѦ\'1F%Վ J}]H9Z/Ҥl1*Y֑D20><ԮyT,H%n,~W`ϳ#Q}uR6 WB sdv$ej)І2(LMc ` }>gAGISl < OXn^a'X{h/b$^EGn:\"ޤrY3*-uRygia)$"3x90=.:ӕS{,R e[xs55FZu^҅ =/wqWL=}gR_!N*TDE/p{wZAvo3NATΔ`4N_rǓRͺW}/1ѹ"^TpN#9Ҥ3I7c k=#b2*}`t"ю=ؕtk'\jb1r)'g{kHZv>aB"_J',0T$xdY-N܎W%iD١>MH6!h4bqq_GV.4Q^$_,WQjk>37t:S꥛b=Rk2b:;&#SKn&(W63aӵx=Zp=laRGGVk5ZܿQPat%8XORs>oiO8}T Ʀ ZEH+N[5GݱmCq; X>8pPw>S-w2LE":5ĥ0>G}$Q4us A&/2"munuZ :k}@f{c<򱪹t;zF@,X_mBgP<Oj'~@'Ã͠C{ݶ37;AJ×iyN>_L6KՌ^֑W6[,nemq~+W|,wtidq_car1?ˁ^-HW0lՆ"%P*bgHnSPWS+něAġ쩞/Iq4JbUEkyC~*y̾Ay3a>pd5U|CK« d=AWy[R.ICG0|] Ro@nW [I\S3 j6SBhC8EU5Je$E3ے ]Y]e9tICؕDr[J^.LFK1w5֢Ꙧ;KވRx*L p~rqo3gu٨0!z>eX?[*kwaHDz%WJbSawљjZ7m QOxȠ'VG ?yˈ)aI4}ѿi^D0<(Uc7FEk+3jhI C%cOĭFn>_J*&Q7 O6i*KM.ۍ1qRb&IUl_CU]^ e GHjq?ȸ"Xpbӑ9Yb^Rխ a]A o;ہ!"W% kJiM1rQ.PG"U cVmc]m\ͦKRox+Ғ~όmq͟ۥ2:pktWY+o~Fzl"#R6j eۥfIQGǫI)*,nw_XtΪ(?IeZR6Z3Omq%I\z2{?UIU2LIdz;=8x+)czϓ~c@d՝gC(LOSeJbމc]e┄ ʤfhun9c` ʑ49i W̏\M3e+€ݔ:ثXf+: lRp{Lg>u鹰ovXzElJJfd rG7 5tx,a@h޾8v*nz^ Ϗ_ĵLїY-ޥ¬D{-~ZS mPy ֘tH.qwuZ3\퍪U xڛ%Ҫ30}D!zlkra =15T9gxuI#E'qAO9y,L0.!Npiܑrb{MK1V[>1EY34x7$;)>El3K:_ eٱ@c8}e )+U.̺#ܬ8B|\ӨYrZr0`re)yiA38B{'V"m;mٳ9mڈi~n t/Q Zv(\06͔`0ViEQOa61/&}1:1ϊh )PkX12)ɻ#v `O7PVlʋܱE 6mg;eBᘍ\` ]6g 40!r*C0^V{ d H,]'[ -+qQw+A_j=?d5N ~2QsX/v29xAJ?j*|=N\?C{$aНK[Nr9\w"ޭE$zj ,y\*as޼Z}MÏ3*wδ#/02ĝꍇ42f.Yȉ'\U"8]fņFX҅dͮ*xf5ҳiuqȅ"Ca=Yum ڴ$/Q~4ԺJ#*¨ #T^;J{!]/>GD$5sq+4"qw߈Ͳ,@?Y9*'fV3LF"K% )N ӺYvCB@W/WlE՝2m >`cSX΍FP\w@5aƙK`GU_Q89@[ǔ=A{mG<}3U@*0غ}Bڡk[n=]Ղ<[5DQ ;xUhiNYE# gh~np  Z!6/Z]M_}f %E;< VAjjWIJŸ=I Y"K,t[Nʤ3(:E cސcVuGh}qgɓ!h ?]O ß 9wr aHa}$s'Cv#b҇]N~i/#%`iA(hg=Wu1u#1 aڶH̍Y.Cp;"5"SOb'O}0|Z'D`݌gvX@O!TSc~Xf ӭ?-! G)ׇ%)ȣRW@aQ`Aj5wL_RzW9.|j޲gZ)=Xgx5Ha7ͣ+I0ȊMSY \ _KoxqKvqrUb_ Xjj˳uW ZZ?p'bAPs tr6J9ܟצdTU hFӱ!/Nce w~kkQM9Ce(a3;h!*Sw$CQvpEly!3oR6Oy d\4 2;n +~;ٛpZxʰ[Zp. \A=i zG#&.Žw$B vq;E ɟ4u}!m=X"($T+ʽk%<`f3u{Y{Jښ U4LjM)nީOb+LX]ME%&lb`7S{3wnM=Zڟw-RVP@k Q[Oyeu:3 WܔKHeѷ?tAB"$)c;>N6=9Qv}!ZO_&30Ǻ3.쪦Ql`XbIffADgEMF'>!TVmnc#(EvQ̓;l%?)y*8k2A\1$2{ߘX0ƚ.Ż?bKIu2Ə*/(O⻙m__yttI&3Ln梎inFWE(Y5]3аh٘#.ljaX7!PђwܘSBN.NЄ ~rxNg읲lk3C^tr6D6v$5 DFRЕŽY*9CjQ+e N,i*m=\$x08\SȘJg?[\1Nn!b).~>H&a_+IoGjNU}(vh)򋁚d֢H᳴!kKxwƔowL?PZw8<+ δ؃tGZ^$۽L]@ N8Ή8I9\D$-Ab"g[|kDPUK7k2ZA9_K `$QV~YA hRWV<xOG㛋BKC|֗a4ﵷ?NBMUVG7R3= )VG>NIu<9n*(H~ 1R{TDoM5'.Lz5ogCm|0ݙ̸/t!G[iUc\ʖq2xK7+`v|"&NNT'\bB*n(54>R1T g6ޠyMvVړ1} bƽYlt|/DTZB_#٪b|oQF~~ar SSȰB筩@KeI >"0lojЭ ;4kS.S Z@ITFM$"""W$yO1.L0F.Ttcp.־IpIB4J k#*;wsUTvݮGa krЇ,8ɱ,f\M 1C&*P@Xِ/'J¹~&"rHh<~!2^~&P}BPg'K"ra7LP_ κH"o hwfSsa)eVČ64s0pZmΓşe|N=ҁ\Y+E}% k?KSSDVtVt~5uE ;+K\wb q )~*wƤQ  Loc,{&3YO&q}9Mv%?i[ovIn!fU48r 6(E_˭kC'7m+&~FRk]OX uQ~ DCQ ,?:\@p3ǒ K׉Sa󍁸Wjd\?^-9W3*) (MD1{]03vlE%(:6"Gʼn(pCc". {GǑ)L\[V#.߂;#FQ26O$sr`˖? BP<39T:Xt]Ok (D-a e* 8 MIkhC2m}֞rX/rJKxiAdlٶY!R^fֽ}*|EMR{2uڥklk.,=L*vۗYNXէDH`<Y>zf)4F%]Ԁ mv#qE1ѠFM[$e5 XWYz -Y+noЛ.T)G0Ψyj][ᗋL`FZ^| ~)UAfI Pix\B"&z܈T37jP!^JjtFK[2sGT'D~61BE,xN᠂M):ob{^M1P)nOUWn([Dxj};-M?K8|{hx)ޟѐm,V`mN:FqYM*bYu~ɐ%Zx冰Lʓţ>N_HyInO-f>=)xinX^1e_jF$(6B$!đdƨ~Hۙ@lDp NwS%[tJ[QD5cXq"Eg\bj {;ͪ̈71*&ݾjǑA qdD=&P )W$=jkĸ$[ um_Y%YF,܋=: 4͓e]k2 X4,Vm㎥3&O`']vQФ_KQuܗwI?uE!G;55W H7avݏ,M*XD;-r×-;7FӍ9L!rV8G&hoxWH7ϠYԏT jhhQ!G$'؞#C{C?\tg1Jrw ?"g 6^3aIQ YJuMq2ac 6b0; q,:aɧL] I'Tq Tv8$m.PsIr~Cꊄm a pT\C~#kiLAA/&Z#L*4'HR..Ab9Rr~ky ,࡙!$WO+É4zղ挫[Z?:KL JwnV|R~z R|;/h9ȁsԇ܏i|3ȹ^v1+Ua?P,ۂ;>33ō/cS-!Y̘:fV4c -k{Aw+\*֮oJy}E-?a佄5S}<I.ԦZwG"Zf`+VDw&.e(c (ή%U3Հ0ZK_{alPvuG5T?De+=ܸ؉xo>5[f-` -d08bJfȰo6Ϡt"O6&ٸF^z FHz5|~;#/m1g/o,DžhȲPfYh,S4@i>%?kVj_}HCs3-8Ȍ 0a6ag,Bjy4~Pܶ3*QS,mZИUJaoGoRt7~(}q,f02R¤T) .suruKX|z,oVJ^s @sن9ŢAnnd= 14U42J>d%mTXdDiЯJ\E'sDt%˚76< %ѩ15g!c%l2-op_mt Խz7NpI^dg G"ۦī$|wCDf*6y+d#kmZ7S;xIHX'ꓗyQtohH ]$m_BԯDyeqn+i'/!sYCnt$^t:C2Ry[Di}3Xx-odTsC''vt1赏QniHYaQOQ} QÎ|Fs{]ΓΥcW N; eG'F{?s  c)`F}ƳIsY%킓k{%elt18;BryO~tGHסID@(}`c.on(ș|$ފp2JT۬qIӰţUJsa~3)"~[z"5+'wP߻rmƾ愲@Y/'O’swՑҸ%yDV!'xw{Hf[uIX訜6?K:uxL` x`K5`Wbp|K)˶A>9e`" 㔾.ǗH@r$ei8 Nt,'2d=w8#'Lc1ژi ߁kUlFOWa#68>E3?2CJ{79F& L8THI䃱5i.k*}f)/ דT(`Ufx-OȳNES͋bo9O8x@+O^u1si1"?ih1)?%FJ#䡺ܲ0qڟ]ȭ)JbЇǐp 2_AC)DO3^56gY .TzvS.{n!Gg7)_A&Dklw}XkSB L % ekDV&޹F^9/hlxoeMҜ=Ssy2eMz #"avCTb[$+u_Uf '䆜៼lV `.yΤ*v/Rk.0df$)] gὩ#oH&Yj&aG؛eu+Q+ q$U_B'ִwA'Gܧk8Q+r30$ckR7*$ȇ.`i2'|b1EP͠kZDs?Y?KZE@9졾g ppV& 퍓oO׵D7iDbu)>` |d-j$bSPۅ+ }/%P_ d1>'kƩ]"kbtS/EPjJƃ3_x?FR~˵:#d:!i|%=zb9"Sy*΢ԤDT0v}w[w"LyмmXMvR~!hd{2)n2֜+E`5AP[I?.!ŵ`tV%RxQ33&mT EcѫNxi0<-E"ER4Kd0΄ Ʒ0V41,+C[LQնѹSAE^8dϜVGyAke$[qoqEԀ~[b~m.BY6~mr20r:Ѱ[E}Vǔcs*G8YkF0yG(*`c+mR ĆkI7 Z*F&$Ҋċ=l ;Y&-\w,W=u OKoટƤ֞abຳMģ#ƓE XJ{+:^A#۬=QGM^#b)1wҚ̸Nv5me̦>VRǀq"ژLR")K' lhAl(y!rݏ1_3ɐ)EKc"Ow" ')rl`NIV:̘z;BBWV+yğ`De댫/x57_ htJMPn8z/Ӟ$PAϗWm׮3ٻKqiYڹ+E 9wid @{w65蔬CHN S?~C,1;Ŕ%^ BmB[6SA5FO+q$u~4Ŝ.:[Azf$qݑD4+2]S~%Dj|n\}]z(%T3|;4c_*`L.3^'Z1,ނ +KJ]&.!L? VZ<>J{-2\2v&%C) /&D4|Yɴ=0Lh0=|)h K@ -5΅Y1|`57e~&Q5p hGr_DP:h_\(!)[C-_Sh ~jl-q88h{ʏ"eiavvD=I(WcH:K;,$w&X7dFΒC&T5i6S,+iZJvIXrΕo7quvXF_xTdJL]k"mt"Ӽvx&ٲGy'Rی#mܔKؓ'C/$hDc}.b\XͿ7I,wn"g7̬Hvu35SXpd:#sbsp[,rŞMsmkr:l qW كќP^#Bt뤤6I>qRp'LVeAm0OH(eޘaevH;+T Zɀлj8BIOrY57hlh{eoMR6.89NU_0̙dU>aw]?@*t)tHLW q= CLӖ?lG%. V NbVU=VxYLRR.`RteZFխrbk=EY_+lK˕ 4("?t?"mY\q%q]g]O. RJbׇmu*mB5ZxL`zG2s#Yd!G76!~˟I[ )|20٪RϞkn#Zb6@Qs* mODB jShL|h?N'tFO~!KEEyOJ̦X_ZeՂ))zgwhZ6>ɏbpݎ }opm碒^}tm>vF8~$߮&s {ɒFH8ۑ4 A*`ӑH1#-([5shpkF1?|`k/pٷtFHˆ/`>VB));nM:+5,c1 ":V&.r+4Y(tYbNbMV^WnܳϷ]{ݰk/陳kuny ߓ<`myq-tsKl%or]F0&/bڊC[(5\/yٮaih-:X@͟W0“h/Wȕh^i< [b9pGNY+xŽh0<^, ǐzPu,Wq@~ĦTϞ뷩8=<ɗݿ-^ 䠆{_FSxv$Ys$kFz@ .,s|7L Y.rFW 'Bd@j9̍윿vIzoV`ol&3{ +2 eS$5xKCC9KzF9K^48O`{K8W'X(|XU+qP:cb8=*I?Ic|qoߐr @Tn8 b"Nܽ0YU\eӴ,cj^Fa &; %xl$f{UF. z5w}i*d %1ХiRA2Y<;ef$\z6x @}݃h IDp_ Fs! 0YU䫶o9~;2kط;}$dyeD0EBo3g2S. |MEr)Eٱ"k'|="K> '&\B>xuʩirj12$HB}aCΐi~:;A1%!?;VMd9St(Yp4ڥyM+3Dp$3Dv2x7q0CvMbV#]O~{R2Kw>p_$oxnW'Pzוrщsc~i%fgUy4߾H ;m/ PaJ!H)`X(+ڲmؼ8z`>]4,Non|s01;8<?7 bo߈;hD.kL_7 sZas9쯋WsCP"D@vp0A*.|a|ʑ:v(]C,W[E lJe࣠}md- D~ׄH1Ȥa̾a_tUBȹV1PBNh5=.Ӷ{;p#gsVћ(!jKJO,p y>h)TLI4G]L"hUۢeK&ZU=4>L/q3妗fy1 EѢ -myi |xEKgpjr'NZtw14Ni.fk,0 d6([Ð+c*#ŇF{ϒ"Kkֿ;W>Q'Ih.zPꇄ{77"'poFÀ+x+rRY5GCIL8+v`JGKϞȏ}͹=81XXu R{?! s$ 31T EL JlєIu~5CK^"?sAK+YBZU*EW"u:P '_͖BSU~F3Đb?٦F3 hkd'B٧o%7J;,j=Dk XTj0\7 폊Xe ;CUWk ɤ?c!3:ʝ$:X0~QWCMFH8pfgVT41ZID(pzQiU0 RMYyEMDŽ47r #]cRzh׶'s ]۵9ȬykSe7F*aQ nQ/bgږyTLLJ.@KEԡuFYF;dj;B:Q]juHq051inr)8ץragH'UJK|"@#qg~a[)@)H\s:܋X' /f6lq_'Q;MrɻEWɼB.?Υn>d/-r֝wqXd!2%fgd7i pSfRG)2S|y@oyX6gJ;4XmEـu}'Q.oI)81$[@MӪǐA@Q[A 4#n ~y]"Dh ֡~椉K_ۜ9߭ZI>Raj%/7 rhشeV\6큲{yÿm1,݌V-d7ˈ}hԖ;>j0lr\BppG{]}ok V.j+Ҹ>e #,>k#lc¬ai0+@gтnŦ,s?KvcSCjr?Qv]E'=XӪ?,dDZx-)CqsxxjeR[GU|lԕ`t{EӷUL bLr _=n\8rsGG͈2}QbXr-nΧV?gpV~ !Ixz?sM9v9v]G׌bT Wm0F"Se \QXFלJ _LKXH{CYwF4hQe̍`X\**Y]k5qSdq4r]Oy)/YeO`ZΡep~VoTY:i 29zOU?G\]4[3.٢ҿ I X`n Ó waekNhǃ:4}Mh55h =vuteb&2#ȳ֞ $&cm&*8 g`H":ppڲViTk=" Dض|9\^w O<{ nO3|9|ɔKɈyQX@OAk' GMk%9f_cشVBdЃ* (i[dCFcƯ.@&6nhW!  0%+qº0=%c ^#"3DG\u>/mI:1-%_m/L[/s#d v{$c6!pf\ZȎ? YU辟TfTн b4h -sr_CO14ӼQ7~WWƃ 8z"͒mz0MkAnb'*1 wBO+d+L CoBK+N|4ğZWjŽwZ'8>&;zpwp"}LL89_14cKxġP{0.Ldί ,wuiu`&qW$MƛqK!r4F铍\SF.>\BBk6a6I\Ì:n0O7f;~n&g~ٗyo{pA |wT;8ǚQyj}*3^ڻTŒG{lWZ?ɼыb ;h˔k{5F&KEpƏ6? }QLf{IDfs/Q{BUuiJ&#x\ʧ6'WreK|0HBVLPkYYDפw{^T^&iiJ% Yl{ :uNL [_E>1AĦE-*?ƨvoq>_R hKa?&=V^ ]⒏\R!b~vxG|ߚ#<?sւIԕ}[SmpOŵ @;Rg?@?NBݫe#p0@[n+ KT_N Jq9oj̘MhLG3yR]Ȥm1̐بd|3]Xgx7qSx$0k:yg Bz<9ˉˉ#iOCN?<>k0AH."eB@A }M:ɻ ,֜*9*C3([|Es8ؐ~[ˋ]y!6\DZa7ڬJp*bjP}Rvlzߤ9}{ EFɡO71?xO3/)Dm9#W6e2.s;,fIUMm啲qx.]񤮒,Nݺ7N\zXё%Ky޵by,|cOܐ"lޮ>b]5 *%H`nKB'#1Z2kbUC3H˭*>p̉.9W/f}Ia#7Yn1,f%;. zn =}5GOm]U@(MoʈU,hӹ𣀍 ptF~uoSXTkK*ࡏ;~).!X'Q~|gwÚ' +ف f EGHl_= ȑOiFqXyqE9}GPq֏M2]+/ -S/Bf RE| ,r_Kޅbߒ-3.}4k- ̽gjd52I0Jcjk7'RB}a6ILRܨ/#.FИgi:Ă_j!3b7LB杽fMh9h mQ)S{Y%ƋfZ!UbiS!E-"*':_xwBx_~_JgɄI"}^;vb I򬨛ĺ|Zf[]wUa=PUJ b/!ϞkkuΣڵ͌y8+IQ|@>:\_}}ݎ!&k. `I D#PHZ.S%ۮns=AM# jՆlXmjD,>.gS|yhv]Ko63`&y4?䘣'-d5D`X.h(=@TŘRI"s#lEQ|k@v ;.꘳ Q3DTg*'/8sQJ&7hT )26 똷 ͖` *c: zN[IN'RKǣ b#%y+cǝ%ܦ W='QL+ltM`γ" odGH"K&sCa$a>oMUww&:O?A sg %#O}>!2ʮ[aZk[">2RNeV</EI@ܦ̿Ph1u$J3D;-M] 9"*)ƞlHl?D: pXC4J}nbbl?8W5iR]ߓ.TSRE{Kz6otn3=ZfF!l7̲&a8uVT::h+H.y-"'L4n%-Z"DV;$%y ֈ !"=#yy->~u̸n^)_R[6g~"ߖ, dzFC/~sYh@-_/D/S)}j]a3X4i:į_-0*_k&nJ}^v*ƍ2ytWCsNFrucyfCѪxy{.u.)>QC#{h)h ca?< 5]O+s~;t/PajKN5?S}˲˶騺6Jd^z{>\IYuTG+C){`*Nܤ~(1 1=BB;6`S]%5d':Y[8IPCveeGf! 1fȶ=7Eqt[6_ĮSf9Ї"&_23'nO7CJY.5 0}WlWf.ޠsGD$NKL&s%F qnHg,6׹*ն(qҬ3iʣzXs̟i#dN/k8n10tiAz8jLGi:Wjp}#:?ƇnL0piwDe\tG![i2>~'Ki߻F6 DR6&9MRDg;=,ZS73!DF߇0ƏS6~WAtвw$9HRwgW`Jr1+`692 漺4e3Ao #rC (XfTo!L3tU R{|ShM1pnx]}qţrB[IOA3?:JpcJLr.,p~)×kX.'0U&ԃʉ5 3dYhsfWh' ief{bRFup,-Jߏ2#+K0Y&XoKaa U$| X.8pA4lـDfzK}; :6}sL|kQbB޺L JgkL H@|{ OeT2Haj驯v2l&&Q4AN}9M&Jۓ)IIk9 IuTKzC(zC|Xcd`eчYS<|яwߴLvTcw^{.c6Mj@Zm "u.o- ip]"Â+ ~2n-C<ݧR_ HO S$,'`4`_Oue|ؕT}> da]b/.0D34qš$G-crhʉ/'&h jA}Z- QX;%c)Bun-GQTCBƟAFeg"{\9ŽRP{r-^__h==hl#xN)GD|5eIXSKhrrLҋNeCJk WC+Da%U[0~ʈt?G8x H7!(n`DZWYmKh:fUENoֻH{ CGR PEXD!]G9n`iAQ6α"=$lD:ߺN!aE|3 wsK&TA q م|oGdK  M%X_U\JrbO>Cip5Lߣ2ҤXgfc8ӓaq1Y nry]#J=3G㹿s6f-OMsVx'hr:3k\~wԓ krs1Y]Ĩd|ʤ2 QVn"Wq ) #&gE[D|&hA9R#/XPN 'l?Ʒ8KКޔń9_Μ]TbrOy!SI%\7d: nC^h; ;RRAFަQ}=fn嘟fkȁR+uYviElbzI|q:cy[ k^Ԉv" F<@zE$ \%N#hl- cKà";t—ݺ/P\U.4_Vf,Z8P*ڗ0T\2ޏ&T*|F%“@{ (U [kݪ.O9k)]Ӽsw=pet&Nk1mHwP}3Y !(= |1 UM6&6O%)Kj䮓)<[p(jr6"7g[w5;%"˴$翾z\mǝ;'Lݒf"w @L r8)Dۡ(GUsMZ~I^t &ghd7|@ Vy U&0 ^w42pD7-D;,NV+A6u ͠Ypn1)f+;(.*`{KhrX>M˵* $,/4a`dO~'uޞQ1RIr}M9݄k噖6A2ʒo-P(DQEH<Ӈ`U3Z'µ<j2m2{=6텴#+n"9}t(BrY ڃ'i f"j,nJ^^pVKIƁ|*ob/BҪOmibOMB"RIIPBJHJc]7@ 6RcC I-8ˤp\c{'i[ňI H&IoN"8Φx={U;n)xjѧF'B$~=SI… J?(H ]Wx0X{\jFpEZ :FjDh~y2Mte -@e[ [7\vPz_Ucfؑ +Sp ՜pSخ2ϥOtZ%ko_WbgՊJ-`jL&xJ$@}e%hdz?<|k6@2`)nz]p; 3d 9<@aogN$y#զz|}oEpN &ZнvJ2.+%6*ͫoՃU0]]:lGY|F}|TR/ 0K'#r>XQ`V#P<+>'֞&hbN ] F؃vT@ woe;ڹY@~Oؕq xMaE2Hc)VÆaq{$gi3|*!Veg .,Kۼ\D̶wdvB׀Lvs\3\,ɔA:&PHm8~9I ]ҐؘYPYo>p{傰! (+u+72I i22Lu"Qf?*2l~ P%p2L ;aD`i9QA" )%D˝&wm< re]Bvr;^fu#VGS{)8nC`u4ƾ}D}GG2;؏TMց']w`NԞUwr6f:.zKi_Zݯ]l+IH"+|ۭrUEwn8Wլڶ#tf) F!bj?{0ܠ;ueL6!Nն3XԐlҪe'̴Qim~u.~=UȖK~v̾,KDT?X{K3b L:lJ6Z&r n;':ҋ|ߪR3f5رf)=*t7Xɏ4ep.ɐ_ G(6*D3VًhЖ@|2 7y+K*|*YUo`fkQ;b:d$NK5HP ?iT"N~;#Y-y\_ӆY[ѬЬ{b# vw|kN7]o N:еAA_z;B~6iRnc7G 4 %Eh&3H[ج4BX WoT#P3)wTemV+'ɓMذeA_vJ$ܪ\_0 lH4VbY"n'~_<>d+6#DKF(׷RE+ AcDcþprGƂBVk*•[:!NkAid?; +B簯7>.;\K]ƀHw2Hڠ0f}R% I<7 yXhߋw'OG7EI"wƙ5Dɸs¢6%ȫ gujDlJ'zWSP4v5Qf]]4Cv9bZY2O{m W:2&$]/)َ!//@VGzUol2*+2yڄLq0ZeZIfos X~MuGX_ ,x;[o]'oB˿%LR!Z]Vp\O<~TfW3p4ٌrggj%(> D\9ɘ\q`RaGʿY i^r_iʋ?CH_J uzAg$ &bh;Mjx*zP?!m{-)T3~j"՚UyDWߒUt9>߽Mpo;NQA M/@I?}\Wql0fS+W5-O@6У{ .͍r4Arp}gۢV<ɤK1 A7 \w "S( jz.L*GL47b@&ft.v>2Lji[R{詴r>wՄy*5]$d,4ώ#6.0; 'q E,O_g ׽> +|sl0ZoSnkmg? ~6dWs!5Ơn~uʕ]B>@{n 00k.~(p='FɄ]l-Qm"a'(u棎88KmTȿ`J%fg5'[U>=[f̘DWP8T.[XSCr;Hd; RѴ@gNZN<^/>C)|KbGrZ)axyIȜ#֟H3Lؓ(9:4Mdhރmo.<`켠"=VPnd /~x 'M`HmU7Hh7Ԣ}x4us -}~Ȓ㶖{UPRr֒"#DB w+Z+ʪo?сj`B4R 9 i S$^-M+:FM::p31z |PUDJP&MFrG$y|d%'[1CHw/C<_Ǎʀ#@E,&i\iƒg[ympyȣ[p uҞ ,d^enXll@9H?f'Uȁ03?#J:%Q$h):4JQMѝGrW?4(.r|(ۦ' -Vtual"&+F H<0`%VWJ0Qjp?Ww[IԿ#l}ޅԍ++dn}_e7pC&:D\tH߅"#=1#)| 6U޻:l"GtD&oKAw#Tj%H L:ued=l=Ͽ(J@w/ܿCDZg& BDF"1b^Lj:BAPO "+,v6%#H07`-$SHu /TX0Wx3?>5 GiI؝SkftdY[-u L$P:QEm k`w(hB']b1x\Փb$t\Ikmgo U6\4gFPbUyF[XK/4zzݳp&r!y)XU,2ӴM[$I=of}֝j6Je 7:ȩN_8U5k".حa/!P5t/#3Nk(ΊMUw )5_cG!.JNb¤z+`F3]Iz+}dPO߈[3G  ѫ>#H 9,GnT5~8F(D-scVkDZcfTJ@ 2R6pKпp@5AgT/QF\_[1~Tǁ7}r#c1pav襦XAN6X5\d=F#]EP2G uߏXWU7NUnA!KDǵhŠOw0h$Z%+42 O#=/6F d?)C@ob|VCF,q1}rZK`5@[՞; %];3d?{c'cT"1E&=@YțKz(K4JMpc6$(uyQs"(͎o[,,8$28LD5W>KDs | ]QdܩdŎ 0oƖEkR6[CJ\Rxцch*FzW1[ӄ4GRfs:X 1j˫1ջ. dF:Aq} gvH) R̸zpb{iJ( P8Jڪ~1&96lcq)JRrjMi2.;sQ> 7ZRvΖX`6_00A`<4NIކM 7AdY \QDE#Mv}Op2+HbML %ž&TNAZ!׼ÃFX[{JFl B.,jׁ$fW26aO 7_s0GP#uQkZ63Ώ/|i =6lf`wr'?6jдT1aH 7C?ݤy"z[R&t!Ac$*7waf2%zĥ~?A \ ;ڳ%RvƁa.m(VfGCiƺ0a=Dzb9 KOw6źK>b:X(A٘dpkT²!/DndJoVǵ aĖ2DXz 7Ҵq%r>p=KejiR>\?na6fC\r13G[_x#(N'd "lW콄#OD ui&y3`lӃK k{0J7!q-8 k\AnOp0.=otDTI-tm]=S[r\WI-Nb6KGd2ywG1k~ b/wmk:2xG5n(gJs$z/"/.5k;X FL"E1".|΃7zII_!sU G_e iiQG2m`/ۜm6[*Su6P}V0ٓҕ85.|t|=p)(Iz愃* 5Mz" -?GJ MOU09 ?bL,?+GMx"ÃZ_$lS3)"Fx;`wf ӑtLd!6Tk0XaY1Aӕ; 36)DF/l8 `*l9q:ߊX7yX82C6,:xru]qϺ:~1?M"Xia;Xa*@d)k$ext"nHhkQTƁk#<^yd M^V=UW. Il,趨g~_ =MWF )(1e>e 0 >$^~bEH&)koCtv+c#ڃloiǗeأ©nJcI3<ʹiEk(|G!@b̏ՕB*_&hk+d-ۿzOre5$*cD88mYPs f'^{hu`W0uh1ٔ"I4`ݷNPl9MhV6Lգތ^zS[z>,7f`|EZ:ur801k{m@yo"ŲMA~*k~5KX&gX@ݹXR,d5m1a"nl!C}{PCuv&X9;SǁEjfISۡ'RT&{$,i&ͥa` rS#3]oi3Te5N1~6$ !Ozپ,-ʵ(=e4ɭ!O*|B5tDZ;![Z߷3l6YOL($gz.]9m:$xH )[U4:4`DK3p.YZBV/Y}"Xq,?_DPAa@>9b2QHؔie9Q'?Nq  ko4f|"8MY KӨB7FCZ7dcAҒ9-r] >lϡj6$ȼ"A PXC'!coFF2 l67&eEy*TG#G3% \XIvX5, P,5ɯhc-`1S"m~)c溄8,6°%EFyXPt=skl/+KY@oyt&]0, C.cjKx㧮:ZzvпCsC4 l ֍3"SQbR|aOrjI h:FXjBy|X+qY,hO#ڟń@Sa&5},p ̯@xC2_i!M)$TAEgɧRap(Yu ԴvQ` h+ҡ|{[4B$]1ȒdɗÛ Q>ӹȽ$%6.Oev̏8R[6"l[W!҄T)J^_XMdJlDZ'J>Oo)< C*CfuJa'iVl 긑1JK E˕ ^<XfL܇.Uk:aGP=# |ε)]J&w%|,L;U1-v9>>iBQ>xHz',啍oe*1.XӔcN|mfc`y#M&W{Dz?VBr%s{y`ھ^xe\l& ޖt1)e2;B@Z qD:\@fB!fmRn]rP_I7epKIb}%N:ĐE'/+&s\){R 91}p{0P 'v̜_-tEQf987|y:9zW{WlMTG>@ޔ>^&-n j@͡Vv\M'TU^byVo/f1 _cӕfV88E Bkwlrb ßVq]6?D/?,` t;N햔!io̐$*>.r{)D.r-s_n%czox̧1Tpm.k/H6HFS6ح}^Y_S-$MryL0!t\_h㗁ZX=3 E"=_V+5ՃrQ),HZ12 aّC!=-XŌUpfiy%=xx弮PՋw U O}FUZHΧxSY'AS(WS)AsA-t>CIȆRsd7*KM8SOޑF, >vGDl7֘:sCr1%9ßxHکWrDE~K>I.yupu;gɲtp-l <,t?>iHoGlбij*H$sJEQѦwaРFj̏R -d@ ߱hBMi=+g6;> .Ե-?W ,2Bt`mg^,8 "L<-K 1ȓ& wz[F qЋk߫G4xB]nK" 8-y 3N5\):=XnM'@A D[cWWYگ[!~>$>Q8'aeFN`7Mo,Kax2Z6Tν9vZN\`| CKu@ׂyMBLI^u 孜p6(J+ض"A9_:E76/٢&c4hn`՞^AsImw>u D^ N1Q-65ԘpmUۭ^f% I!  )w7g}}#yl,v0YEyd/~pQNQLWkzda4s<)koY_> jf_TԷ*!.f-dyq:N\ŝQmSzֶL[u>=u.OZU@iCR:(E.$haXOkZi[SDcA lP/xbܿ[RR \Bbc\xXy&YΦ>H_zVtTZXK(l A zЮH(ۦ7ߣ5G*=,(3c/wxQ ݏ^pm{Q9HN!#GPqx6 CU>ǫ~i֙ݎo*Z=w+;}Ȟ<Z37y4gkɰw+z~0HGnu9Lٕ6;f_ zTq%fnvN۴P13t[hQKKf6US1gk>[$ JY J1Z% dEe {WtZI՛ 6Ze0pnത y!z/@q# 4R^ԆdO0\f x HrT;\ߴ}7K]T`|*6u)ԛ EU]l 0iYmFyqHR<{!_djeEWZ~a&%WŬH~yب~Pʈm fޝo׸Jq꥔K{W{t5{{ZRH@dR{rTorXG4d/eGˏ;u} Nws<41:ްbAgON;X7xAf-*;z+e+phB.9e/tQk58;)~X $LI|xQ)55r}-<+}Պݸlxl5'#4qrJ)TI&laRZ]zna<ej76' t"(SX ͡`.,i]@^ iUS.:4\: kzd4!3Mz'EOw4qCp.y(Y??{j84A#&؞XD)ݬ0`\k#] żi,Ύ?)#[e. *6EFHAZpU`:Jo` ?BfI fkCƳrqYvOȖ+`kȑϯ*Má, g-UPnf=ImOe|Xo\[Ghlie2N>͔W]aO;~D>97Y2?]2M$yuq8^9zn,cDdznell8WU>z =s595"a%yi3&r>'ʏ_TAfh) 8]fh+h$]Nm fd+?K<?z"bӝxJWͽ* ;aEVh<(9f >5;ԏ9f H m2!\W xhp9.>VtjVDZ\6Ra+{.+!lw։V(%K3/܉Ĥ0}LRz_pU71ȯbIF |]9Ԥ6*?@4vRE2o}Є(LrA8oћTH}4PMGL{.T]v?*b)b+A׸^!!xC|)q j03D+ji:$E}wc],Er(pL)a,p09MHkQI+q,jf~YHp)w-[ݞ>ǥcV?lmt/QRP[ͳ:ԛAcثme)l#_C#O#"K4S[V$LmHG %A-ٰTc=ӳj0.@h?ENEA\oT=n+}Iw&W[9^>XRAL) $}GMF4ꉳ&gQO?C7˿inLڑϊ 8h plbIOJPT`璞@w x`DwoW,^^^ m.`u3lL6BY[t_4 ) НEYnѐ@ve\82]!Vuբ=xEI /xQ R|\&O9Z?.Zj`C E!>卹;BQ*h:޺^n?}הvY)U$dI:&/G؋}otrl4]H7j`F{,~1"9=M/~e<-J.*T(<8XJV<|A[>ǿ"b&IQL[$SƘS -~pw@}RxT2} 8 P%Y4)YNT8vwKFɯLyp˗p>8Y[{uS "U) &``%țo^UZ2f"yF*]L:$T!ä(|zhyA{}.8an\/ue34af00푦=u>MV3nsR&UIyFym@^f:agT-%p֡O>X'fz{ŸldpNWInp ]7դ} Hp᱇I ޠ_tE&HBw $"_'Wbs~0H[b*#z)!?IEk@t$`z#N'eBG%8 F턕-T&W[TL2{O5/2]*M a0\X09#Wh:*x$b´Y :5|`bWA"Eˣ9U?w)%n&x= *u *5[U'{\vS7,BSr:v7cc'DiπBDAvRPӳ,WD5ᒐ`1`ƽ.R;bRP"Lɓ"?Kaq|\"6,m:U };BZ"c7&KU鹣&okOwlQsH>j^Ec}˓w M,(ȨshWNK!a5Mr~ԑ7r;A0pxGX"x37j.X.I @8i[%~_!6Asgxe }LJɝF%=$y A%$BerΨeO>=Cr"J:rV]vߦi5U0UϚ:#/'Q/tXD GAI]Ɖ*0wɜ s/O3 N6 JHEALޛQ._+Ё_)ĊzVIV/U\ŠY ul̂?:;뺙 LcO f^',tS}{V}S lo+Sr~eF8&Ʀ{Ywx`e"/ "ߨH8@eDk5G%~"Xj(ͅ2jiEYאlu3ކfZz~_uJ,uSzMuSc,2 }CD)Y ')ML B3-؊n,[oEױ/7LRh<;S<\?пᑾyG-оnw>]9e4?:w|iy\}w4e D!(cTt6\W4'JS-=Y_Q_1Ӡ7ʖQkiA=~~uy誒LKf7OZhˆMП)]z5Ig-,%۬%PQ틖*d]L!̢V%,f~`A f@/nwy}E#ƵZ,Qn=1ģL)ZBS|NpQY[oL¤KC C#57 mt 11XMjD6$vbஈefhXzcj@CU !eGdvC_m~ ާ+~)})eS}(>%qZ7}zijɃ g)0 80,ݛ:Yִ6c`ˋO+DLxHZ{H 6r`чq+&$/q [0L3 Hسs pz=ْ` t.-t5s艟ߔ]0}~-wʟ/'l/)#cyJQI!WhN+|3zƄ( ݪ5w-,)`=}R||AAy`<e-$6Cku!A+i|oZ\C]7P#Vq1J^D9Z7 X#\߆9lz×دc]˯ʼɦ6?Od \ rCu K w3?(0&_Ա~BiJVԚ{)FwDmG[[e 6RIAm^mOG} *pILIΐpJQ zwS_$WչX@`NEZ󍛒!WwRKg=Fi:My k(RtٸWvcpdDf8&69]buЦ8r-oߓxLw})(tIZ6ar]˖.=;CKۏGІyw.#dy% "+GchmͻАz9+>=$Ks\S;בBꪨyi5ȶb-E2!.]DNsȀ⼕^=DK7'4ffܥd Z7 Ibz뼪#ըtry8U40чLj2;Re8;w6iI:*El ʰ&u&8pipC#P˾G+| eetZDK;&8)OQ~UjqH? J#4S[[Qѹq{ ױ^8<ګVbטh!' y4dJL܏2 .sc=4G_iCӜF+^^Ko+}lme4r.k1iOeJǣNR+bPyoEtW$x ^5@^_WIxTkv 2zT RO}z4TW0e(\cSMnc .1}([lz:' |}`-ķQj{8N _k,)ނnw2pFch *WTl/˩O8"R{;, $aaPߨP+[\} 8bN.(uتɚ+-X (J /$1 JDA)3EAL9 u]}U6- 9! =LILMY-1Y*f7D]N:E `Uw 8ʛ|jrRHZ"O Rn)3e Bι;WA2* wx!̓|ikx0=$EҭB0h3")M酢^'o̭"/^eTh&=-gg:34ճBI ?rO59I8"xS\i׺B 9 K~jS!wtbЏ]*ow}!f嶁}c^곜۽BP!ha}ai/i{q9}a^Avt ʏl3ِW*~)t]Ќs@JR=ă(0Z:$zo7$(gU'@RV!Jy NHX9 }iSU yF^7E=<8 \U/JXys \vǧNkG]H PD 7P )<}G\љ,[Uc8Og0* ,\w0`S$w$xC`~_ӜJwZzCBkeC`toìN.F_-B!`3no>O$yt3c` S?n};ˠ={VH]1 o|~ &0)m/eLPvb| iհp^P0D!=3//odcL^`mli`47ˣkERF[.8l[ӡ\8盋0m8K~>)v(ZY$3\A M~`)wYϭ˶Z!Y" l|$G"1jf>O)B5$ciD{zV˔*-.B:( AZ!̀ HIe岌tC94Q7y݃~yi=olx|Pv2I؅1q9]-ÈA=a]n *`H[=E 7uQ;.r= "ʀPe~ 3+px1+le37S47/Vam45a{A0UpgqCpf$IYŻ:<42dX'" [`ܰ߀4ZvgHGu]pӇgB,4)W59k~sHdN_ʉ10*ۇ'mtlݏR{-<1|nBZ>. Owg28DL6lȃP,HK%Q5&`eO ԵNg7@52JQ'QWHFvd+hoYTB~Lw% bnCoskD6HNEZ($ٟ/]-1INv|l<{N'XM + ,Ws)5M@RVn/$GZ7-ޙ7CcS 05? pkbi9&5nn`ō[DEx;&T˪OؑXԙ|pl/E8Աŭ\cxt:;_O5Y/qVxHNf{7e[@a$AmvH@I=w5-ݚpI[AՉػ1w@.WQ:jEWmU>hJG? O ]VںQ ! U&n@X&G<+>u\7Eg߈TwUf^RE|w wt3՜h'tB7iV)O~@܋V}1{鉫uX٧,@#+vX,0f ^T\3()g!z"R ~ifv:PdP6l# ]>@{4͊pݦSu9o"2/:ex ]VRc{6M\QVPm P]4 ZV ,rl(V,/vIL~c|8*<`T=4ٽ)&i>{zCPF^%ߙIhO28b[{Rf٠O 4Sz;|?MşOa4[UG̚)gc^F]Σ5Crom-}KsL2@ 醧@TimI ߪN>SNlAMwݴYS5'c5U#'b9_&mQO |R}x}Árd{mq]$ز-:a$4&O s`ۚtNescAı^Yժƍ׽]kU%I8j\|$t@? #D;.Pm. fv[w8]wˆ3`/'NN4-  4XStNg"%;@m]GU- ~\ut @\?JR õak̴%$ 8dF|(3%\oAZ5~Ei1Os`>S XȚx0UsWzת}-s:v ; R@ڹUȎyd5.d(ԚiPA sGVub9>F=ʄf`(AC0Y^ێQXJҫCVJ0x-׆vot_ E!BfpQN [GR!VD]yX&kt>^_`#CoZ\ p&}-j $M $WOz5}DQeKQQBTn?< Li^X#sr#i |4Ťi/ (-2m$<=u=#q_:l2kn"{+ F=젲$g9: F_jG#9+{԰ju7'ÇCˬP.*BF$LXA|5Œ]};3zhv=[++EL39>+zUo53 ]Wuuݥ]iip]Nux]5ittPu ^FpK2 ¬$E.ISmOq= "?y O8 4Y͢{IK:7K#y?T)Tr/-B'M\BnQjS$XfS4uapM K{,זDZQdq46`8/AXǶ QA,PV %ͧ܆ %5ﱫ_T_O^+q97E\߳Ԑ=z\!}<D_BzP:=i" q7nQ>$.wJ:te ih8z<'@`AҔ9X9R"62fOYFq &k]nnދ0.: MeUsRY̒종BQ800YiVwW; Cz(A,HSw~3+Yڥ4m?`è`k`-6}Gr $:̶;&zL0fXrjWu+.,ܭaDjؔ󥓧I*n!F;_k΄?mghg0%b .tvjk-O«/OG,e]@ql} TIR~.eA><;z?I=SL?vm%[48+پLE4Ɲp +_J *H<"-3Ï/wAzpݻ `zA0|g{Q4; eq<4*NʃZ+%<*^bO rK+=Ӟ wraD*UEҾI&jRb0!>E+&LA`i_dWzt)F۵kAmk_<He=(Ŕ+P&@U ZĚ3E+#N;豪918/opbՀ,?b#* kIösoocaGU0TA_aBAEŒe 罈,Fџs_jwi%!9aZ&wA[@o<_16^Rѷ&ѝx3y*;dXzBQT4?Tb&eC]>W~17S_J+YOJji#)½pZZ36l}9"AE|\&JNQxq䑀v%GRL= k^šu$q/_XZ:Æex߱&*A}T, ,M k0S-יcß/i<26?{,Ov"veI6PdYW-4Bz sٌ_\ UW[~f{\_tA{5 8*G$ư 8C Ik04͓ _$" 3YXC%')}t*zVJAT6(z'ep‚9AB9lβ gQ:K ЧnvZ`x-*"zK n;i7-#_bVo% AeF~2nk :^d~=@:dD) 3gh~_3o8*(qb@oz&.J͟Ԟs 몧w HHFz/Wu"`o1x=&DW,p ?ZpXjwn2>`C^(hA3lax.1ux?BMʹ[!d(Hdɷ?oC5 29x4 '37(q5(HۮI`_ϵAkL9a4(HAtao?c)hϩ~ Αf_gN./N~smMm,j5BYЋIn,gr~[b㸢@z;8u8Ti-^R- {M/cV+ ,MplRELކꟙ͔oTJRgkzĂ EXzݬ) ]T;VA>J:=%c]6YcbXr>oGXPxL Ds( 'j]M(k8v&՞>hN#dsBQiQ ='ї0=`B-$Ÿt匝RӚˏ{v?` rnӫHzp~]>~,> jɐÝϓ 3jZ  |%1;^_K/EWp;>D=i{ƒdžQD ҡt8.PhxׅQ%BaNC;H Tt''j]Zb_p ,Z {KK qEJA$6^=nX %hzע Ⳍ*knLUcW|g˜maNcR /7g3ч#ơLƝή iwZvrf/S =n{pyH I[,~94BWP|]|SuEa*pԷwM UVCu? Gs> 1LF1K^1k"9ʙҹ6GCƢ=ʞnQLyVPB]^Dg|xO; 4=$AHvЂAD;.y- 8l芿JQ;VErX7Ir‡or.pt'Tp s[ ˃ʛsU-:bis"ý|V.3R,k3d%v^AD-QשqyɊFF_{[rG0זּ92,[E!\3C`B4-9ԱaUM| B{S-.FKe+'8,HNkHJ=sU4m,_=+84 41!#,&C.| rnDqs1NK+q~,j2Qm+o5o lagAlu Tۣ|AnDq&>K{KX'-@|.l9 ]r,QBo 6K,6[7q{:/i!Wߜ'<zbxllL'q vT:Sx_*\cujbrgyՐ~a@|/FT2p6Mp_GX 8ۭe/[0Hқ _dBIիJiQSZ?T`cxm08mw =l0F-A^'[De6tYqAb*3GybwDKa"<(v(&8?*Ȏw՜x T– KAhDJ榮};S(&GPb=zL(uu̼O=VֲOb+>߹{HGU~MQl!clEliإvwNAFw $Y%zzZ$Q<-N־d(F1p!| ׍"F. XA_>y1MQ zvC48=?GloQ_^gZq5YU<&4 `ओЉ Aܨ٨cY6B6wU*RiUEi.HPPVp샛 FǜA\>oS6 Sga~TЁr;̋ӕ H!4$@}| VYjLpUM~1X!#3ż.u:lw1I=Τ|V)}*{':C瓚E0ŽX}"wRVBGdp! pvjW/B,0vp7b]~ 5 o12]$(Q5~D${oބt`%L~c_+X0 I$F>kE>>HsN,j"34DŔ,oOLm3PHʛi'ì,8Uk&-cbZ$eJF7N bH*pGGq]}˛༈m@q#Aw5oSf3 @^K@2G8Iٖ/'"s"ƈg&EFKЯ^J]Y 632JE@Yo漂d f%zATh| ܓB--$Ű$rj1'a( w^:LYVi&q`Cl/|ȳXa&ts夿$",z%uzat^:a}P:vb7 z)TtAp0I~"t3jJ4jc:j53GHDG,%GW*'E \%a3ɂ7RCсyom"+c9uL"+:%e{Nmnx/,$P:v" /LO rbT8)a+fĮ@Ѭ X;.V3jNJha&Ija{fv=CC a}ͅUQs_ 5{' ^#%Ͷ-]V^G18@.tO>׶V95 VYVAGDvS֌IKoChyaE!%7q;AꠌN;9*YcPupߵoWH!ݗ7kj7f(N.~"ct]M6lz/>bPnZ?xʯzi"u@ۘ"e1<֒܏ltJF QB yoq-j o@"YHy>Ζ`'b7 I$Z-ZBSj<5RM>vK1&|;_FAcN#0fݢB* |1T$ţ"/ȓm&#. VDSs!JG!Z|4_$k ԘRם@Ádyso"~D`NƮߥ4mΌCjII%ՊF}'XuETD}(WjKk)谞h3+ܶ^QT$w2(EY7!v)! |)fuG7"N;!H9~^ 9@) ^cevi1G#5H@,nYӞ7_|ϬYʩmN4q` y<M6`~J/>j!Ŧ(x`  jXg-4bG:ϔڻtnC/.AN,G`NkvCY"tgшTw|a 4NJk4Lќ`VӺ ([4 ;9^To:>AStUJ^C>3՞NCĴ`&RV>BrT]^.x62]#ٹ-4a/P'qDBHcod'=Lqb*n_L,6cѢ _Jܟb'/!GbKuc6kxe0<"} PQda^p;xsh@05qpC4LD!v oˑʋ` -EZڭAwҭy;ޢM]ćPiL:my%j"n|$sI&c^0c!Tpjp E"a+$ bSZǦ4]>6iڟXc~AfR=eY'{ zr5zbPO7Snޮ󡑍~F:LN޴^eQ _Uɇɩc_]ĉA6: l/߲}-fXDC|Jտ5R9 [nQ]eiϹt.Dϸv`Jrl6q _'3:@K2VՒ4vcоBmPU!_E:iNj$TNY6Fv Mg,2_i3#WBL#z~o%pTgXpuIMOX3Ch;KK7n4whNǏCuE8K?n S o'!2Ti?aR`M8? IًB6|&\8Q0|ajgJ=Q9c.U+H()4$_l$o68Íl*b"XFFP[U|mXߎ˯0;L=i&G74=},XW9U+ێA^I&0fLA <?3t~}O 0N`N5SQ#R5ʪAQP>>-ю 1"Ցcz\]8+b!қŦp5VwA90^slG`.[aAbR }t/Ky&:Y9o5+e 53foز4-A,M2ͮc%,1{nGES+'Ώ p^G V&K~xm4345], ɧOt>=~l;g{jxo 6ZU50.Ks|sjT9;Z]$ tl @𱶇%A_UtY!R})n 6f+U(Dz*E˶mme]48ť4R(lt:lߣPR+j>B[]B1τ > k@ %}ҳѼݝbSO6[^$!`濘kV})YIj|. #{TjC:9HM3Ř)Cj tTHI=bSɃY@B)G[5y?_e-& |߃ݘv hC 8H5]2IaBLo_r9+EӿOZ]T}FnWIs~&)][[dI:BqN25A[PxvZB4q(4{ˏhA$M7(rpe^,(`C%{?6f9n鳘q_:ԋ7{~P8ݗœkTs>\۟6|)Bs~p!#mD1IaKHwgq'bxڪ}iĴ{m&&IAdQ-+>s8}` O D]2ɰ_lVr# TZ|~e)TEx:G017Pth;Ucd;FE@|4AL NSMGle'KRnJh"EF- >Pxi3: 3Px-A[ 3\E+uLJHmL33Yݒ@Қb b3CI N[`trlT@oKoo-^\cP#(r~K&xg`ck XGP"0?;GM]Y(@i'#8( bi^g\BMd aiSKh+C.@2վq@)8p!ڢPp5XX1@qSeFb կVdiԮ¸М^i ! 5u(Ą'_A,kB]֝E)<)ٽkhzh٭s)W ;HuARH-5qI`+DiI`Y T!}NRHIIfB]]?kTw\Kn>T[{+#"l!>=ە;l@q 4{T iGlSXdHX$cLat6(\J[rr;L,t)#)|%`<&^=f\W|N 52Jσ̰Ҥf4 {M[\A12E"2w.oh1U<q.yrP/ɨQoPU?޵7F!K2 Hn@lDf2,]6Mr>KAUO7 o6x^嘸.1. ZyieŁڸ'{||Y#hz|X4e7bcA"ޱVIte ՜0p7z`1-Zǝ:Aٸy:Q~³FQg195ڛs\S2AoNT,Hݽॣxg^)2‚`ߧJ9޵9M~4m/dAdN=HهǨ[@. h=CԑE w6VJ+t[,7^v qwP%DFZ?2 Ѩ}F%T!{0a)Ȗ@gJUFyV%{s~O=sM{')1Ir=;b+9׶nq,B |a`ТY`w /sc٢:R9}_"C^}Ѧvrb>Yuclޕ̓폩5Lh@ .(,qb !RZ$9BEvZL3Tږ+TzU**ly8J$8J9LSP񝃰A*lHpj,fe`6<9LfԒisal7Q_, +'6R1NVZQzgzaAsv @&vM˧e\ᙍm>LPSϪ?fl'J$V*/k_Əc?NtC`NeEwVk[hY|zJckC<} ϮZ},f^[ }G66o{d?YZ" =yɈ`c$BJ&uщM]nڑ Zy53ˈ]sTE? /!TϿd*jN O$v]irQAVu&A3*7~Rƺ}༊ pho04GF'*Db)uMC+t{ d`_$Vx1醟(4*uT d_jqN?[*AEn~S^Ç\|9ˤcyrNml" cLIiMa@L,w߉0`RC40 5t_^R^0L9HwI'-MF,wkzC@Hbݙ.P7LwhʥY_6{ջ"/ද,%.ψXv2"dT0͊[!KS, i1_ӎ* SzWef*TˌQ%uh~Jx''H]_i= dՈk8=t]׾& i9l m(̃<9Ǐ_5j\w^0}­_h*|""-NXYZi_80^vuJ/Y΢Tmm3wK]Wʅ0 KBQ <.B)%LPc9L'^x+k)Yݣ!Dv<WMj9 Vx :rR.qCNV,QZ#M1CzuLvWqwB5 !8,8:DLʮM%kwdR52mj"ѨX2ݜ+YJP*Awr~2L{/=nCTm0\ phx}˿~*fk}l&a҃XdGd_~Bl F8KWF9k"4m f.c܂.Z$E>|;ˢDb@U F(-A?:kP=w羵"d3:Ynp9z%aT,Tǚ^n%L&7 hr7 DžVwY,^K hC4b"fd]3%Nej >%V_w)(lc9Y]kER罹l`jl#x$thX #2btC/`8[!CmS0dA) 队0t36ZW"= ';oyDz+UM8z ws c$qlztb+5Qo VH`xyGzd>msCUæ A-mN VaMzdlw`5=aY_xy,&JxЊAKIQ%? CPue"Hg, QhpMf یYcȗOa*iK73s D F&z'}8t.Ib?+!i<_5yTX@n]my.f)}[[@k#Z }±0a d4t O N_3T (cV&nƀ0>; X}v Ah/ wL)r#e?8k:ُ @nOBmw)veW]W䳉n<2pUMݖpxJl$yA~񠾓09*).^)ۃߐe ˂o,x,GjSTe .P-*-鹫Ѭl_nT1 xUAG[8%*x鳪yYvqo/Oֻem)KtRIATੀ4]qaÝ{2avRNsAI|Re>w=|1cwfvVF tM!䱩}ѮK-;~k;j2{s2~k*Z@*xMZb@t\֨RGQ @)Uigqb֢.R^pOǩW_QJB8KCN-p %۔8SvsԖxo#f2qT&=踘_iAjJ? a^:.)Mb3Hۑ& 'rԵ2eyFL]q"5aR_w#z= P3ͥ*O =Aci&U:=|b{F Z+5NAL8 `v"AdGӰ90%𪁀LߠX!K RJ,jZQocHYYԝ%+!}/kqxQi¹GݽY1?<`eh%c@qp!}ă61GxQgo./-JwƤ wQF(Y}n?V;s4֬.-k͒qj| ʰAPAWmxgzn1& % [so}1|Dk:0jvRu;I\{xGJNV<`u}eW- YuBJ@ݪJ"̱hv #5jvCv/]cZ]Rݝ|DUi őQ_mcJ@@foݜʈj;49)Nقގ>*vԢ+Z\[!*|]3Q٠tsWAL@I:C9E`` W HtT SWI<2mfA}Xp_"P $ | N:A˪="Y[cx%Rݮҝ#-E=n9(V#)K++? US&z+@ 0z1M]QZ{c)J`E:YW D*Al: 9>VB&{öH%,c6z||3˪|u%u?b,X:DoюZq^dfDqthn0*],׀>ԅeDQ|/ٞ0(SdPLN~pp+Fv{3CA_~!E: sy^DCDN.h LRL I~UM@(]5YJr ϥ~4+D_DTczv6(0NϨBQ.AE vWXFe{HbrWǙO_Mk+CCoȠox۲f ASٵEsD%Yl+ ZǑ#k]>E̬^΍d7m t8PC{:~vIP 5og{}9!kw_ݘR5IEߒ3?D6p#m/_BܙPoq>O|ۄ7LK  ]md5h'w F:G@$QZOxK#/iPYrZcBK&/+8ZVL—Od#ieWu@'?嶒B&;{w@tURF8x#Ft}Jo v%{k9w8@ƠQUfV:B_ SÑ-~0hfЎЯ5ZAT=pdq?E|t=sm `(n8ޜᩅ}(jÌ GZjG~fJbRИ7m[sXL ۜ˪F{Z|_߽nr@[r2 d4pt  J1\n|e{Y9淟ST9uj3Sc+fgؚ1@Z/J{m4=]*8!7Xb}ƿd0>D#V^x>; 2-W"}P *ޅlSV훠dftNHyA%V5T-6/.1́I&F#l!Kn 3VHt{[R?sk'yW.n+4Cda Wۚiモ)"vgkf>+a-!5[P…E]?jysU+u#$iJF'.5VZz3"!Dle>W+Hԡ9W$q'gmVZ<$0DioQqNs4pS+% ʆD*Z?hK1ۼiW"L(!,[Q#h ]b ^ A6#:4XtG@'q5\,z_yp\0|F֙.V+svB i)-;d*p8,O?Ww̲L<Ƭ3##yj ݂ߍl 'lJg(fqf"DmO.k7t4 X`0nwSO)G5dpC՜;noQ l诧nv?D(I[,7覒}>4Q!Yϼ@#rRtz[s pC/P'/VBͯrRN25W>$hYWksOqȚƨaR|- 8~KbڭЧBh]p. $Ŭta󻾬:IL@Q: v!2zP$) }.3ٹdX'tAްwdbR qECEנSF=m&i>4 }fnPO=5~ zWԂLk%պ>oruJv(躃gz.gTŹHqIꦀ25ezOI*]q;dz;f4%grًv~HiWXܯNv JQFV3lC|p?2%G@CS=+R-2Fs74sFس7oi f/u$^tM‡ZIvic'{8잚<&(or }HC7ұcS8wZgAS_&W{q6t0CZd-EVJ]atS= m뵭iy6o4P!0)!@YL:$0-DU+wܢYPDCZO1jxnT̏xoЖe{.KAi[B/Jzxw"R)#ʚznDS#o޷+nSokx#Xw~*P>5vne3r(wV=~p&cN[|Җ?\d/*܂+9}a_{&GXwwEXMªzLej--Y׏8^Eo)/zb[ʷ|ˍZep(pJ_Lw\ޜn yOٿIx*!l!㊴ótI# ctzUH?9n}qlt\L|fV冴ãG(fd]_l7o;I!]L9 R,fVLn7qQd0xTZ ىM7 v S1ĊX-lH`hALp kzAD!VȟEҼ\.Hy&ؓHYȆEHiSƂ4'65XٮwxCAQAO`ʆ,;|q|ѹ JIs;_ Rw<gقnɧIX 0V+4C{+HCp{>_5Ŀkae9+H~bt@N@jAС<ǟUquXY~t.)nWut}*#q \FrSݝ\XKZj͚v!,>`D9}ϻiȮ3s?+ ;&m W @GW5~UJ9Eh#BVC1z?1d`X\$w/}z?Kv8md]}Qى^n}NVRiY3iLMӑw4ާ9'?3܂8K$\B}@[=  *-̬fvq5/&G(q3$iJ#_Ft”%4֣Xq:d9 ˴&Pt\vGPp٘FwAAf00}$ϑ6j )t9V?xXVPpjO˖E_N$?8Z@Y<6Ş0uwtW_~RN3`TEΑ?3^/5s kbZ@"sqN fK;w(bpӊc.7h,HEwjD6(b:bt&=?P ^L[mIcF ӆG78!>u"(KLcشBnH^h0ѓ/Iގ9|nP]_鐢ɵ^;>*RPFY25Ql[c V̖+Ziі5 3C1vKAv87= by0y;zȣq];s_7:(VV+ *Gp(b'ӤS!`A>3{J'y4GGk݈k Bm@H9UڑF$Y!j(,Vl#~?n{%TSoU^jrìR< FQB_ w;0힠-0.ΗaJ!dKOқs|F/c*hT5Gsכ!N0\]M<$v]Q<|1[tDh~݅W? p/GFSW~+0<`!OV2 '9YCr3vrmK]-blJ@a̰F2;1Ddw,SWQ%'P$- D_4F| o@\Iro9(&+бB*c-">6Q"䜵$[>l6 aKw =$1LzBѭd^9KyeI۝=u 'nٱs+]o47BS5)dXԘ~zև05oE9–4:wpv:cim!94 `Os>+1Vyi0zAl@ zP]ѣ !~: 4_NⱾbE\Ƴ9:~`6@}a_r `pt&eu w&APIY34-4D5t(cLɬcZ/ VK޼x9@Fn 8PZqt ˍ}.L %H0bμ[2k=@m>9D 6k-~p,s }Y( Pcu8q>Tۏ'B\֢nA$L[xnTCۺ{̒ʧv4Ҹ$TwKK[q[]x:dZ*kimtxj8,}4K0T4[IE^G[QfgTfN}p!)$݌_O^a^b8"{m9-q5dt̤TOϻO>.utJTb+wI4o&elgWr.$cFbdy*݅(0ЋD)`஖ b: _\9=0{\7G d_Y9Yz? Rp_H{K.y[?4:XBu'b290gk,!8m bj$' N{{WbWq9OGGElp*\lp=$;i/Sbb>53fMȓ>ח  {֗6&᫒7brG],laTbPɶژs/g?*'b̋2Yġ xmv"C+Cf Bbb4cȠ4XYS?"L}'+}{ 4 'HM`xIUFis&(fP @O mB71G<31QImg}I1q1`QA,\J94d=w0ʍMNHv<қ9anC8_ޘkt{I#*CsQX[qREpd}?mکM/Bg+UocNs*Gh]# ;]dAo;Pʾ$z;s{GhHht_kOKpJ̢#%]hT@p\RyQ.xɴ(Ks3|BKPSOiCϥšZ-<67)%65{%<10XST1ԜgN#a5O7:1 Vg^IO'X ~>W JN9<7Cdg0ڣAuGr"':0b4ICUlzafB.ىHf,9MׇQ**HL Gsf?ƳzA;."vt"6.z^(h_*GYB!$p{7Kqc54#n{r&)36uKR)L{^GĕALߚn6vnסH]1Z4Gjt!]bj<^q0=X_o*XF_"3a8|>)xSnD2VmNI{dQ[vU0ac>Yա,Ȑm@?w?,ڼdD+;T}KiNGj%f1}\{'LMb@OvC=bO h`&?1D\/>9!6o0znP/Z?H3TC-qpU Iv"L0A Н,H1ߊ/S jۛ *BS2n 7ۓoĸ4?X ]Oi%0sJBE [VHaFȥ~aUQj_:t@#^5׺["俻{LxW!D!nI_gУ64-S%֬K]oQ-"4lnl)kUĪ}2'BF {@NO3eY4D;GaE%~r/ QMT\t#L |˺H2SEHĖIF F[5qLbU|2Xc96=BN %`xB.WjY#ppSA,kq3Hߴ-TP}wi;-6줴n!Tw`&)dBYíP%A7&d u棘~{a'n=c9J9}iYGZhZ q;yf7%3m5,]@ئuȰD7͊q]-%³?FDMrSwɖ<0Պp 8ԴqS0 f5FIqRfUi&`<͚N3~\Q%[!}#d->KkKT ,LYcP"-$ʽCLsfBJV"Șl+JX=JUapV*(Y#pv(?^EPѺa* ^z^dGtw=P$r&-u xenpGh3pHȷ:amYM.!İ#I*vSG|㠎pqjE׵KwNK%n pɸ&XMnɜkL25 aFd#R/A}K+f*d^)h7VaZ%{ɰ#}*8~x\O%)J<^%fa(ap6 &D}FQ+k/oCkXJҋ+yL12)yQ S1cKOqG뵳Z!^BdsfŌ),(X׊H@0XhmWAc(*L[~ύϤڃf̢-|%1M}P#ZZa=(NEkhs6R**x \6huN:` p|r8p$_=׍&;\ PiKG<%,տvTF&w.rG ~EmpWDIvtC`r2SguO6;6a-# Α<j83=J4.4 0MQdA5 T!CkC|R\K1k,}o4z"YZ_\J.u'aм-ve'9/0SM$p(l4&4/gwʧE^'a ƸpZ!Spq[=\j+5:0@y-y Zz:e=D(d;RVxBTLls CJ@.Y˶!܉֨6L (qi_묏{Z1+ єͮD-'E) -D!&mjN?cNJk±;뉔J_Ya's=E!saZ~h u^Gc[;y% ^~:'mۓ0_v ڃR/EE/[j vv{bh ?@$˒R;/dho!csOL,Rr08ħ\'S)%V-!Jh Fm ﮝ #G m2k5?eZpGQޖwD?>S.lݵ'H겳` ?sJq De:w<>\Rr!l4vhS5 Kuv}RdchCèӪJjPY*5!Цݳ< ʣ0&Ԅpl$"^uA8爁c9!Ng?s3N{2(С+l% OtUYGy,nA=~=oOס4Hj|%ۥ݆,b~QTrq41[&Ȫ.YE餆2Ǯ,C27?SUV*~v0 Nэbnd!̽d,fI$/$F`G@ixcg.OY+fuvPTEwͅ%A浸 +'k.Xt:Wꢗ%~9;F\_m,s2fo}/v5Y4*@nʐ,LgSkc2PXxA]ZaKzA'agWzvDVuAjy UH!m%~>0(qkQi{SF_Z4sM@u{dߦjу^o8A*3;jT6H7H1ˋ`ؕ7JSTO"ּg4o5D%`aS@H..YkaB0"s^J"Ci;qʞe0֭r78S1?,iȃu}zsk=' 0]W ;,qiv|tҎBpS"Ҡiҟg>gB]$1$ęA jv *-A"%*$BSAKK .?\X6@|Kop*kLv?Ø8] _+s{&nս*\({Ǔg6e϶[G9*>m@wG\`qzvfju qc[͒3HZpGESKV'Kѱ[+ \ 9x~ز/+QL% /ؒHtYEZ^AQ(KK`eP(J@b)o%qqotu cSwP'eѧJELӠ`LyBJە*8NP\ _'(椭Rx 5 \Dto Ap㖙Q2 kO󤤆&G;a"JM JPD|zwن[-}cی,4k.LI/",QJG\ :TYu?v'\D:t4Qs1j)))8uhΉ_ۢ4B +cۢtpܸn1cp&=v$ !Jb! ׹#h_y xw @vc(1bc7sjBTC"*HN̮eI<p[yevpWG5|y$7n%Qmogf5 =Ry Ϛ_LYmjƼY+0 >1e Y!u>W2{vKunx>;֪a`Y490_lO3quCrQo`@\?u 69IIFrebM#ndgWTY Km6SݬLbhovE` RkVdf5:s3`ͼL}|{mzLr) a);8_ׅ(]bwYx_ˇ޶^|өۻ c蟚xCxwKw2jHK~rs"6z˺rYX(7д"ڗǜcGMMF [#j,6S?#ㅬm3n[G,3^ZUFAYh&49tP?icUD'gsM<;>#QMv˥m#9] ˇf#8 $rF*l{'s\t秣)aa`[?;:sc;MꐲL 91 2A Ѵ<3g2 0Hiڸ Dbt oRړOOpC.8⑦x|k ߥC+-y`Mb~azMteU}צćZ(jzHq7p_ݢ.)|k n玪bFrV?FIih:P%`Hö\gI/ZB׃yi[wٴ0ڇ;#gF[Xk$15M^w0fSrXFTR,C98F bX?ٟRNmfx}/iO6T!?/^]6}ʙMtj&D!Uh[ :?g/(dl+lH:<:ڳ3wZ|SenJQ*HQ#[(C l*^¹DOᣐo!V|٬<(Jm;8O65pS/ ]a$ p.;aK_OQRF\+Ft-YPU$$ŝKFd+ҹBv SV.GδWķi+ EǍ|3 {#b݈D3Um9m~@D?GXy<σL_C"6Vm 6?!=nyUeBeԒ.,| ǵ~IۃB+)1 RɺLM RP^_š瀖݋17%|>Hck \. ]O$ʙ:;-=Fm@iվzrwy`*I.:lfROaWn0pIвX+% F&nUZ4p0Ӎ BY1"@dNSFp |*I?缕 _(l& Mo[E6ȣٲW..u&@H }#Q%#k@Ji2Rϗr ŤQH6C5GTcI&ʗR ) OkGQISB|J˓G%1RdԖFb]0 \Һ2kVvݤÀtYĖ0eٓ`wgaȧu2ʝ(n.vBb{1SϏn"c{Ťf|n6cD>SXfk]OM atۙN׉InX!$8^PemF1EM9:M5lV3 ;j ;"iZW\^=ψB_Me퓬-{%)6LUU(n$$J5stfVw9;tQRvנKmGsRlQ|96+ŗFfJj/:;; 7 38P >uȊ!Xz2=#J3u?5x$FpeGBLLM(Z?@A&kC@~#ϕy@}{;fcZy[&.})-nk׀b?m9z/JVF Z݂2J%:LսO67B-h h0T潴'MKcv%RyEC(ACUW`c-o49{H9qX /FA %B~+movF*?&bXBtcF%Z7Ds~Y8!QhW2\qX!lZBAH!#GM~>ex}°'Qoͨ:@ )"3fA8[ XZB~̈t2-wA bH3fobG@N1uQuv7|T'VPU?I߯nVGDR?ɹр>NXztE)C>^*} [kFSTS2K J&y91Gb""^aHō:cY t4TXA;<6bb ]2IHDìmw3OjbWUbȎ.&bHnY9MȎ} 4vQ͛?4زc) 8+rͨ7AӰ>~p^˳Jsnj^#\ ~^yF &İwL4 \տXh3Lr\xYj!T.x >n=mSIiPSb:R$Ve\=b=ߟÝv'[xʰ[qdgr*笿J KaKmFWr0_8g@ԫcʎWL"J<E4^Z.4\vaDuHrgW wD "&-R2lD@ 4:UFsuT ;IHfu2:enj[MKJ{Vh Y$-w>oMxiZl11g({P? ":{a VDpT:'`o{90, \[`qi_H Su0D?x3wjd=?S_,Ep^LA~YUI}WO8gy'_d+vuvFDDE39pZ&-?;PkB7shX?H.ox*TD̀Y[q<(JS0jrtK]C#$LNCSނx|,GÉ4)8sߢe M76y%37M]n:VPPQ}UK)XQ`u;_eiFFơ#KU;jG:/j"BY0 ].YR,Br=\<gM@&t\C0lUPK\fhaojN, (3QE1غi}RqPHso=_U] J0zj9>;iLc_GaUu{)钦JA7);[0HXc/Ͻx[gG̔Y0#T&]\殛{Z\&&jd wet4_{5`CKPqX*D|&L}4@:hTᏽycMg]Vqu <'0pwl B;^yfKA3wDž ǥ]ë}C{4Rl@Tv q`&ipHljE΀:_ 7xp:K}B=$ܣGЊH\6dYl{xV.Kީ]}g'YA{0&IXcaց#%jCW M$3A*a *0᯻C::߲*܁A#j`Y2"֖ ZApsH})l3j_ %ivCVyXg 5L ?3BƘ?:G<:S>=cd7FVlk.?tzA?poU$+ad4ri7 c)(viQ&GVsӧB˒ USʛf Sy⤁:"(w:^7@ <04n],Eʷ8TgFӢ@R`I=mN0#6ob@-u{*U tA bZY=1rK6bg(U,4MEi3/{ Q լ6}_0MD'@;; S/ʷR/ Q=Bl2ML@5ciClnCԼT#YNp ױhy攽m#tI]FnvBk,Fk_N=dDqQP8b`A^5iX)B{-d<֧x*E,y-sL40)ZoX\TAd45T9nj'IG_ͦ]&a  ӕ'1\ m2ux2^0h>e Rv٨'w>'\d-B'+BvUorrKIҢ Lw6xuCEӨ)#Zƍm{(J"vN%'+x5?a0+x!%.,Ƹ0ަU/v 1_ ϑ`4I#ϰh+/G^<2?C~2hN$6~Go~2wil.Qodrz~ 9h@N.rU}<~2CyHG jA. h6Hef3\Յ0ф؜|iIEU/\.ba.7=XTbǾiǪ#|:,Qd=,[D{i?0r%b҆ba 9P)̼QK |/?482 p,hc+o_˓\xS#[I{ d,U mH?90%⏿.YWưrahΰJ6 `y=lcrS]~rJO赴B 2zR %* ύBzR^38D6oN5hw^5!9=c뒳(PeP.Um=\-]z>Fqɕ{5I)3y=⚎h}{4ٓrcv-1shJE%[R ˾ }v9\%tQ?)l}hG % ʬHأj˘fx/ (U=$aڥ} 'rI\:[Y,T)M;IB.zvr' YB kM2 Cҙ TF;@Ү}C+)Ӎ DnAsN3HY t J&Q#JTy^̆aOS֯=*c%gm` S)5s)pN$*klqSs?E X\4Yq7Pi'@Wx[ը{LMABKÏ"hu{_C:|-\mEf衻Y]$n+I-NyD>#NFbVq;PXggbPdžX2< »mUO˱4ve1\]ʔ0ZSA"'sZC5m~_P+3bf*9!!.uUƨgśs.oJ6Ԅ*;6MLX’+=_)f $vVױGWUȾ>0A ?B-Q嘶Cʴ ]a X3 t%ɟmh>en SiH$#!?vێM"C;SȸhA;eεN'ȴ20yAoJ޻aj궡!K^"gUnx;GT?B-qv>N-'Cحќ_xbԎٷEVCȏy)$+{̓'lT;: Idp;`]U49EayIut6سnڋ(dme, c8u{QjSM\ zz A{iW-- ``]͋{+ţH>ݦTs*xH@c- ?ʭH<*(8MG&XFHZ%|<} 54?9(s1,bsBks(@ȅƵ3Hx#dܙ]E<@W WRMvZ0<^1578 \X2$Itz(7`Lpip1jO smΒఠEC ժé_ś4 4ҝQǬRyD<72 f_֫@O鸿.G0C#u@|EĪ\k–="$}5V>oQf>hJ5FPQ_qBspȦ0J=&-tJ};Xa^nhq;HO `41J[DrF4G3u(]ffi)^To!bCq*( @m}׺ GRi. sUɓ-nGfR˱[]SxPcpFh(_[7rnlS\ckpuJHDCcLDqwHA*{aq*'Du߰|>y[ CAt5 !ˉm ۹e3Nm}q8TbPguL$[qe]{pwG oOBH>o,iQհK:xzDݑy,,V-(r1^gDLqq`t2#~1FC2;A`?nK2SqFs}E&;^q _tk飮[t1CW #%$41eՔ޷ Nq e кl?lH憇L)BrHSO" S wG)oe %軫 .X"3w)t|OdqN1GVsoϻ8+Y1#=v,wŘk] *_iAϼ뛍KsŇvzB D7H $sa'9ZdJ]wֺet АZ-Hd zgӇ ~p._iǛTHM8;t!@Ĺf02> y+ismaMWI/q\h6fuJ*wtjz ljA;&I1MWw4_!kU2zʉsj>7md9p ,HC!zH^G!|jڪM!{ZDb V2f$˘ 7ZQ03]dءnNkm@lmqkk[,H nNawG<0N%}g :.z ]mi,?? {$Xɉ|B62$Mj,^2DÓ] ɹ1& &>RIvluÛr( aOCmI34öֳxNO$=3 0'H*/n} V W?WG]jZ1+O #\2sdBuσAab~s:J G Kw;As;b7G 8/i]IW#wW|lN|Șdy9g9@ ؠʕM[Y@a `ºBQ0l? (۠|y<9"Lgvtڏ.[-0<Ʀ </zD#&"Hj[fiS/@߽ɣMTW!lD42[?)Qm@}3X8粭U3 J G{t.u~lĺ%eڽf}qQ;u)vB”E\d״0b cpw`to) 5rdw/>Q8%~ޑ3E4UŒ7B%Mg`} .$ 5T>Im 8O,|ۓ5['z ٯ/:8f۸): 'X\"hH -eC'X6$CZe7&K}m\jv[Ixwj{e/VYCRW mJ&;_EQb1>G1/n6~ji1hv$tS+c;5۸Vӕd<`<73c- 1|ɦ6 K+r\idP O%'zԗeBh ][v|d רĄPXmav{f#&S"Ia: $(@zcNGr|9TUw\ G7:4Bm b5xM_ykRl[>YUf[y=kGܒgw;t&c|k2 3ɱu-Dqi}_HlHH7k]l>V@q[Oٜ2y}Jn]d$+LByxr;ޭ6nY~Lg["p? "o$|cxPŌ@RHvTac9ir)L g0\b*A\\m)@{J/yqSSM>,gDK>o{x:VfLtB>=R[`z.UڰV  /.[$YX+;LVZl42 3=@Q{ڡ#ivyF x֭jj2Y mguګF+c8ܲGM1Ş -f7Nxq5gr^fѪ2wiZTPc/4r^>av0%+]9&\jAxlY?ʃ(ZTfyp)kFjcwZ;~b5ӳhw2q8qfqkTEއghS–_{sOBs*v쁋o» uSAu ԠM#q<6e"Q!z&D+ux,%W,"7o^gB2]m]_Dz O+O8-^t4wZQYqZ+B,/[ZѠ/7QljDc#Bu"*ƒYd d,`Pp)PЃO&˷[V %K)_EoxɌm^*Ϊ6]ulCC8=Լ`j>-8'N7` њLcn'8BCZQ[HxRg$ ] v|TGLI(^4k$?b^g D&!`4a+e) A5&[TF#13yʎf>ĝW9dRgZ [XF03f)Ɠ]/eg~BW%d΅Ypm3&Y2$Ou#Kcb (r/@AE&1b`݄B1:8?] &maT WJc%3SU؝sdW[lcyHKI<<$akЮ]j7+E@_1W3Nj[Ur~!L.|r}w(l`>Ǟ9kVW_M)$S2,죗9Ux`y$y*2zJ|<0~b37d% >F#@e$tE~ 53cLگ{Ӫgu)_˟(2C3Λ4kn4=^inݖPzR9D;onUw(ӌr!WV x@.zr2т("SI)# >+!K.o="Ԏt;K֦+|;U#o?Pqӡ( (a=e(#GW\Ȳؓj+"vvmd%7Tx]-j;`~!r;T 돭x=l@;GW>_\dǤ'#)̬XWEd S1L)䯵9bJ=,f*5-}*pʿ0w$$h 081 C)\A-ÐRʕŗ6YJBhnhvj)adLcvHs v ޤ:&5I7պ"|KͧBw)l21a-Lh8"R1xE*I1fF%(vYM蚀 UlǪ vNN B2SV!"l&nK0j1< ʜ*>]vvJ73i""8CacD,tvd ~s4soH vLdC/9*(.$Ka `hHWvR^&N֊.`p8HBHfGVilJ7ʩ(Bەj W9F5.0=MO oSQwJ2TSKby7i](vlrCuc{0N׷o}-dB8|ɬ@IW,i̱׆|aH[ "Be33v8_sPgJrnEZ?f84zQXA .{U`=6yZ5U/&<]Y}6%ݯs`֐q "Hn]oא-ǃއ:Fbψ\O6.q֞B~# Z !h27"nVmE} 46>n]T507.#M82:~"K9lאuDQdBtn=İH@79_M DT,FYk)}U܂KėǣC1dЀW6`{P{‹&^3%݃cv}lKk[k{h>(:ȷ[騂YUA )GKP=(Oܠ>3p0p|jrs&Pޤ{1rG=^Z;-/@\j<*U4XH k#Hn!ӯz[L&EL=3^@{&o =D'n捎QzZ 8IE:4*G…:VsQaOVf ؾ ܚU[5ic֩d~YbZ_@KA2‚P]n<}̫UȉJa N[9/A&%$}m?B缰ɦœoda;Ɩ}̡CӇ&(-_'vISz 2LmG&!iaPa'V$CYpҦl}yBdYs ޕho YV:ʤMCU,I|5vmki>n=Awi G~ GpBFxO#g7`3):@w"s^DlĜ.p%j{ߗM F֛FUB@!r;N݄|W1=Ec,`q[@vkq H/6́9O}ఌ+UJ1w]  Ok/P刐8p;o0o? af"qԖd fK7#)O~4!>>dv\6n5psk-puْr657Z&и7OR@GG~iۍ2 ,[ٔٮmxZD tKX$~=G|R*^eh>}a", " E'R+%mH}S 3S GG\&eDŽۘ-A6h[,&- \0+~PI* ^wJ_B|1J`^~wFU*ꑊ\TjTA>pǫ'`Nn7ܳ1C}ˍ~#a&%T!NAwT~6,k#_&f/CKA[eP6TjLQI=`=PmY*[ nŹaV!j!t8#E["~II,hU'b(%(5tک"&0.ZW3)\ՠ&.%P6K3izv4˨Gߝ1(ѵji } bsQ_ghTnqw3f}C1с{s %@n[F~CrFks bѼRIR FtZ?dM"E CSN,Q΂ψvܢ/K1k0H0j\SNjԙVvUGX$K24\%5pջ.Gو, `\3T5u jU&VFuQP O% LL% VA#nTSYmKwT kBo3߰TFM[evuݑZ̋(ЬD<̱akEY&: iͽ i{>(=KRr[iƚ_\(a1-]oԒZ͂ {w%;$Hp-&xb7@88CaGLVi!7iLy0\{(stG x }c,KӖ#~U,ԸR? 勏;w*i:2qON]*Ajoq]M{X@waDU99K|f,rlx wY0w D{ֺ% x s$:bX/\o@`# lGG*br| *zۿUOR6q0?W1 'вya 2l׶=KP+7qC63br74nVqRg6 _uy}vxJS7rcS!p)FUؕ48 kTn"wNѩƁDi롿jA7dr= Sf,<-wV9b DEZj71Fl?iⳌ \bX(WzaL.}htP9=K[Bn;;^3Ռ]P@_LLɟryV%8L*zCN݅S]Hi\~ڟSDZm S4ξZcGqڃdc')5MuJydc{2k._Z!ʀq-;Y7ɵeM6#O2]yJZtU^h~<4m9 /Z15ZUIZ]oM)^Z$xW& C;C$ǖxi: YZ