pki-ca-10.5.18-14.el7_9> H HtxHF` ?*}}cJwMڒ6{7&غ_1itB*[As7d9c037aac7c9cb9ee1af4ea24851f904c924873W'BMA(tF` ?*}}qcR'ߍhT?,w"۰VY^֜P&>8(?d   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H 9x :6 GiHiI,iXY\i]Ti^5bde!f$l&t@iuivLj wixpiCpki-ca10.5.1814.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.`tsl7.fnal.gov%'SScientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤`S^2`K`8`8``8`8^2^2^2^2`^2^2``^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`7^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`7`8^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2``^2^2^2`^2^2^2^2^2^2^2^2^2^2^2```^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2`8^2`8`8`8^2^2`8^2^2^2`8`8`8`8`8`8`8`8`8^2^2`;^2`8^2^2^2^2^2^2^2`;^2^2`8^2^2^2^2^2^2^2`8^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2`8^2^2^2^2^2^2^2`8^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`8^2^2^2^2`8^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e29fea2bd3e8e0d0012b78f9bf531febf01cea9a110048cebc6d702dbdd66a58d8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-14.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-14.el7_93.0.4-14.6.0-14.0-15.2-14.11.3``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-14.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*HW|X_LX^ ıъZ!L}0Y8l*ΘRf0BiIO`ro?#B,Ïs{b %Atg`0iJ mn⥂C -IY~@S4mNL_( {ј/}tBW@zq{>26fO9(PUPN`.` %E})T3GvbL|]o%rm{ltHXq ~NX@Fb.#}瑜OG G\\(gծdF%'~N41w9 LvtR[gZoߝbڗ ΧNJe͜c=OW'w[=r_!$&+%~Z[cF@礰H(omEK-*f'e+p?.OIPɗ D7fU*䎎2;`΄[/{ Ch"Rn( X de, [ ё,0䧗ݓR?Ѻ\ UрVC1N}S! cNyP[*UtF U \OŠ-TD,Sa 0X2wZpya~ OY'-u/@'YAEWdnjЦ:dSec~I&9e? UhN$&]\ȦWJK$9M{w@N``"㐇1e{/Pa.wl@End]DHGW-cnze 3xlKn9=vr/%.i@*<>9lx`Kо @8ajLNyn?lZ/x#ޝˮ fH2^ /V˯-WMb9*gf&b@}iL]--Tt3~̆k#DIS_6:ݪaSWM}?rjk+?4 c;:E h5$P,~Jr 4 *q&g`W P5{!$zVb8 H5ڤNQ$Z y1B֋.')LZ1"Uo}PQ/]< M{ѝor6beuٯxR;4MҶNd/.]uv7|BkN!iSL_ʮل"qvL<̷c!٢xG\?1Z@(}J&M\MIrzȇ%ƅ1FO MZ(0E?vc j.dd3$:eRiHڎ㮻|eKhgIRT la5fs>ͬE.ú?+\+q[Ϟ+ө4XmiQ=yo<>lplXO3+yB%V~= 2mZٱ"ZQ JK|iflaR*CS\Nm Z3{&b @Aw-Z?ۂdz3A-,7̷yBJKΓԘ\o1o6>'=-{t3;;Ym&NS$ץkЮu^k =Y %.-{iL!C\_rRK~& MFH H2RDL^ B&eipt{q~I`kUe6(Q\|80QsshB6~zLh&{<3l5''EE}v_ y(|yl W! 5+}6霄Nڟ#ap']:NX"I)*8J* H)%Eˤ-S,uޞ>;~w~ ^=ڔ6O4"a$6s$]yd= 6 3!~N.r0mZ^Pi3CfMtw<7S{;etZ/R ScԣI.zB^"Ԛ ~vVBbt^[Œus;A.(?\B}Ap&Fo@Oh؋l)N0{Ua&*'%[M^ɸ# S%R Ӹs.=9dLxÍ7 SA%:69Ѣ.FСKc $LK n=Շ2Ǥل*^9y7&?4wmֺ݇=KL^NDV~޺H?AG}1a3=\Ѷ%W;\r89'M"$2_@lkc%UG`ed5gH PC'1\cxo@^cLd~vS]8aAl Չ ^WG=_ʍ2dj-Fٕ0JCAl~1;*WXl>ycÀ+m5P/~i5_C.u0qدH0cJnB,W DWbJT.otIڵM!C U9@n5nDd"e&a|׏ߘb,Ŭ\b  FIH/v7@S)'C8!םls5e%qCu5ᕰ^l5_ic;yK;B>u9T졂j3+@0y&( ΁ы[MAKRcia]? i׬n}F kN&ϞA%? " ڠ_4nLimĜ. @aS"9%5(*9C/8&(kdؔjLprf&4ZV?xgN\|%> +vvÈ^Jrʇ/iƠzy,46Tc}EE[l8aKa P/,\o9(*09 b})fPIJ:fŚEx!.®P3s-y"?]€jqTH Źk˱A^R2'2tI|t $Rtvb!'P)e hiV;}[_uܝG߹x8cޠ# Q;l.^>mfE)zQ.\%E˓8pHD˕%wOZȻ)p=tNz~v Lfcs攪擄gB.j4vj{zܘW57V}sxY*'N)T"6IEq,HMHo #їmΕoh$kh] @ބgk]D3|W9Ye"]hԶ{Ʉ+&v;jTy$+Mb{!Q,]ZyH]5Cįo(n ݽn=/kìIƐlez|<[oC?,tY+y+.mwzfp.>IpO/>BSwcJ|A^tU=RA(%NaN&;RbHij^֪ό*P";UjL48Y")-b|QnۋIMb} ʧ&C_bX{n:ͤe)'n?,3UYD~]nhܸ/@Q$ ~0 8\^N)ɅEm#ˈdؗI+&VV"""_[*UIqR(;wLxm#Mmyj D`OrOm̲!lZ.f_]3PV}qf\\/]t񊆅FJWi8-MC ^a 1KzOneC lxR-ϑZ^ӖA饩ۘ@ͦI,vDQY/|1>\K#ME TWsC (x+I{qӠ'~ 7Paۼ֩։7ӕTD'xb ,wM ɂ#(Ңn%A&!4%Щ|h-}USZ|Y &2ߺP eV.~FFbt1J'LϠ)>p5}J7~s?^^iś#elG/A>l:]azǸD\/$7Br@L~K*GDXqL^W>͗U1$! ?&q_q*#Ux Yo{vfĈe2u{ %a'bby4Ӈ GDK8* gdC^,KF*HbQhB\H8[t+ کνƞd,_:?nRNl"E[S9:(B>jJp%?д%w?m&f2|r ](MtphaN!EIe ÃŧbpF9T N`pE\7$黿 *k^8^̎:*^f !?Zv9ηDY(ݷ]nĦs8qCxc-ovHczKC eѤyޒ| ydw?BM )Lk"o4 @?,|}'Njaɢ:D i&t]nAbT"Zw䦱B qi={q L bwfW"ƄTOՌ|<4`G֜,؈uVutB3B4+"3f9@,nƲ8+<H]{j{2qT:͕Jn(&4sٱD? *ɩ*BݦWsYGu Ѱ*A@*2h5tEmT(J匙8%9lKL $I a u ՉOEg#Ji &z g:Hc?q$^ɇ…K)D1wΔ/ {(CH0`F+`9OO> )EHziCxY4&m5N#Yb`FNMI0JbӴ/Q3Z!7hvz2*9O;bOy M8hE2"Gkt+>x0x^[HY} dotzԕdђ@eN3Sj:o*2C@`OilJM_U=fET߆WgfVD@^$ijWG>Vtʄ/{./㫭<1^s~ptWk'#1"\XZNFTޓ}Ry!(5| Z,غFL%AYs>RlF[uβQRY/X:4-ؚ)m1kC tjȨD2ğu+Á&wp$gyxएDFa jY`Rs9*š[FbUvqb^XY1~QE\7QD|sҶV4Dٵsʁ'Pڻ2,k0'J*ԢU _͠ujnB/l;` fZ%-{fDf,xBV %g_8"v2p> qrgʢmܜ**F^I"h9*CN2(>+Ff ʀmxpK#x ˉݜgRlǤc(r,#M{pfdYY{ Ik>hW~3zpo̞d hߊ}82 y N7Z@|%୛SuˎymR2RcUs+Yuҁ"Y6 dK /lte$W.=wT#(BK04dnBt7/ʯ+ رq~r\I;:* pA?kҹ:BSU0j3pPcɳP Kʾ#5$Y $i% RU_Cc~zu5s#QVݵL>7_t=H3u`4J`<,k?to:ud)7gTv#}4$̲GwaY*}ˆ8sfoCfGYS == sRJ/z}2xƃx t1C-אik\SPBG|>Ar:3i/EezX7_D* 39 1xrFNRkIL-czdԦ$o\E>354f6\hDbO]MA" j]xTSw, F`#,3|$HjO.u|%am;?'p˳֩AGU}a")vHi#3oWT݂=Na7R'HtE{&Y[.G_J_5MalV˼^{f[D4bمWq0|~߈t̼"-xlOHn-lcWڸ6v׽uŦX$ڂXF K I3Uq"֕JDԦEZ"a-=lo-5@v67`(3pn4gC,1%_,dgeӂEZ.UZUz`V Xl>k0Mvu%TPMZk؋܋'1K2#2xQ˗0-PdgԴljи &Ū ch΁ݡuwKK"˿oй]Nlϒ'pg=|ʘqmjrn] ĄeK|cn`-N qega܂r:@:KbH5 ImE, T$o >R9QSsEM/*aZâ8#Iؒc ?#fПvݍ,|܄s;;Ih*m(9"D LTpǿ.:i=9t?|)C'}ρ!*[;:1H:yj+AuϚdE=U* f^w#yΆIC/3(b %Dwi`ҿ5g}|˙˨ix*|G ь,FbTM3)~Twqq70T Eu~%=P^K㈑rT(X&0M(hmћT $`tBSv+M1 9\(Ӣg*>GV#i otfHk$i2FVY`7,2ALtӳ'(Y,Q|>cb -FKN!2%CL:x h5wˊĒE)2R~ q}9AZ\0& fMC'Q_xe&d8fju}(‚Q~~d qG6ӥu)MXXdzxJZ~Yb=|&[ KJ702/u=|rA_\V ߔW{BK(x#[Z(Լb?BV{4SPx ]XM6~|I{(K)h᪝nyn  5`,'086KmO (8 p~vϋ(Aܲ+ߵ ! `2؎@=@0@uًw'sr6ylU䯑;jsnj#gUO:(DiٛZlWb<ۏ'zDx_[Ȉޒ Raj5~0|2 ):z|/BGaWnM’TȐ0.> >l?Iq`P fIO5s7LTLO[㫊 )_|^TI.bqh*%8ĖsXSԧBͨC.rQ+!;En)aFM:o#LNs'W4=*P[S-j]~Kc{u͖XtGaEG3c:\!E&W/Vt'+f:{vEww 5 *ڀauDp"_DF@>K g@>%'\RIj`9ߥ}Ҽl0 XAyPԤ{yz}B~7e%crI4 W/fdOov4i8!P ޏK_Mh7[W((ŭYh$XY[c,0iˈ@81E g]`q֙GFIaٵ#= ˛2_N.@*2DbL1H !Ak^2j9% (,y#a2}n6^>U\v#Rv4DJ8{ 1DPs F7y~Kfr?̐RwQS H'ZeҎcTGy[)# b@DZ-4X}Gtb~ ay=VP3US>DD)RsGizUh"HBap>(=fzh"ȚhDWBR>ԐhZL% q;"01Lu#{H NF05?ǝɐ:GNu&4B/C+'x".xfb9lLRdf-'u c&}1NOr:/TY:x{9W#?H/;uE)b"O~$:M|ÌPo"k=R:"k=1^~|KP.Ny,.~z+݆lLj61ֽJ\s`2Elނ[cDՎ>UNO.3q|q{Ho.m+?nG~DFҬ–fF6F$7v8!C3BښF'!|(2Dj;[nټmzJy׽n$1ix:tʊ %5 -,+w 8ZafUS jD&ǫ0 ?`Ņ/3a?apDr z]B<63iS‰%o򼨀ن.3MW@312{ *v? 9LGb]/ί9z-XamU%Ɓ NA~Nx3m>VHOmv*-(Nv"3 S[`VpkZj2+ tsoJw)R?+#c:8vȕkˀA'4rˣ Y|=N|w8O6aQQ5+Դ{Zvq Ri W]v- `^Bǂ:z2Z@{5KwJլ_{g(9:傥$iˉYd4|6ߨ'PV'zשLP0GGM#Qf)fkW2:4&rCyuyǜ&١=dlBf [9U$㠈}AV)=($DN1}c NfMnl jvWUNؘ$-zbiuoU:t=adjb=,Ns݋Pܣ42;f7_B`ɴ}AIujHz~NudxPdXlgh)<ޯrwpD@+(EX3fv7o̚>$&n35N݂r~p2RA6s4p%&]:j{MUN'0ޗBoTvJ[4@ ݻ/KSGEE7Q#SYL4Y g66c#X^O?g3\~]OAۑ6Ӯ¸YNbVp,4_ITբƝQKw+ǕkFKYJG-Qn}ᡗ{fTتC^'qS*ʿH[bx`iWPiQ3sCBqfy9pu 9pi8PK~X:$jiJTXP% w틞`j&[\Dclnp5,0!~X㯲ʒ3l4 |6uaxdXI!mQ 46֝L|1~{`7Ń ҁB#Zl}'v"Mc/h!$|dh$ 1gLA̋j{8j66:<}=0K1 `>ְ=`GFY@8~I/Cs)܄Ph)wU謟*Gi(}0Tq;^`{1.8 ˕,5SCٞUg#U`T>xtҁ q`3l8y-Ag>!ISz2-u)"MO ٤eݏ\9t_J~8WH &yȝs[VI5=gt u@:=}\8||WXqLM}LPc+Pm< =XJaehݦFfxـ52N1s$2QdMPh\:>Jt< hf\WLCgԆQ?Ow\#0~|gVٶe8t{@\D$Yʉ6ݼYBsMh!EGJuleRɦ;XGnWt[2Cw-J"r|a 8L4W(v)de qN =@H|}z0QH]z3hkwVONMl1/@>›MgdC±{;b2 Ĭ`\z3~Qo66f?TBX"yե X/dQ{nsewAe:~0 o:[f,z AkiDB$]eq:^Zl' -Rl *B$ $#Y.^FIu['slwaIHVN\~R{q2䴽agu3S`] m3󞝚ka,8?Be!ל9y7K! ;`¾2y4*h?`nX4].@A!J'g. 'YmK0D$~dX DNxΛܶ?oYD8j-]WpsljB#m7OWL=v}heN (-q `WʾE*."oJt3=8a+1vg?LάH"nr2)%aH˚5u1o'.LoxWM5[M?rlaDsYRuͦ^v]gjciv/dkƛ}$'0,0du+ti|g8 n:O:Y_ pl6j6.q 7}[} Mẗ́ʸT[EL W_%h7T5{^٧u}^Q|>iadȱo`EȒl,{Dq9EI{89fP5T3v!Zc20ɱqPKU}t$v/̼D[D~mEM@n i+^í#D{pU$9.d@YQS(~9hG?>DGvp2J8 NEBiq΂2YNrxh|=/B1kWj^`;tYE֎V>EJ0J3DOVm=O2@eRdF`|AR%pN|7sz!M$r$>8Mp3IHaývzS׮ɠ#5El0/_]9X0,KZPYЉ^V> 8~VW4anC\/:xoƖ [u+gBSͱ}F+'csC\*؍@\S᠉[{1wf>V[k)C$ #!$& v?*g)%iKht^Q ]pYtcF * e(WU@X++Tar'PRww34 j݂t#lPU&8,4~ ,5֣wj\e?yf V ypˀpdpfRA\^&Ȓov'iE t|*(uPL0ydB0kC&IƢ^c|ʍzU/ϏTy?ǧ&*ߖD Ƚbl[qԥE&ib=_ʗ lOQ{3i5GN{pn(߳43tI xp{t'(Zmضdtd}9l^LΔu-Ԫ`P}!T{0c&™w&%$!ӻĢZc\1{ƴ.Ie ;끢Sm-$:g3Cߍ2^G1Z(Pz[D{اE9Sfgo=èTW۸RV1SOcSQtQVI/J'0׃cZ[h,=g_%3:GZtca/&+[,JF;9KSG@m{!fp7Uw[lheOzs_FQttW,w{)Ggv+C1n+&+y x RhuiWE OpmGv|W1p}eI_E_\BE2i%g~[ Eo\+\92[Te 7ǯAv3ŁH5n̎IU?*s69NhN )~, )|f!8@uGK%I/Nxqg>.fzG_p(j*Fe|+qK jsz)yDx–p`HQ,˹Y Hea*[}Xhd8{{{ʋ\.9d].PlwbT;(s+wP䭊ET#\4=+>Qgy(|vU#l 0ύq)Y`|Z"uXR|zٍem_Ր\oLB"Mo`3ֽ_^Pk(r])T8!=QƔb UQ#C'MaMOcd+#<ҳ.X$F^vz#l 3mj`K")}~Tp ŗ?c%yvq.fT EW ܴL7Nv>\nb#bcN|~ w~IzZ|s2dI)uzreLdZ l ϦXE4oO🧙_Ŵ]]k|09ʐx? l:tB0jךVV?n\4 p=T|2Γ At >RMDMS'a^<5[w=1DJҟG0\H."O b(LE:O9D_B3;Q//q$5oN \撏RC\ֈyshڞWOR, ,QnY#T~_FX3o!xC=WJ>\~go,ؘD*\iȉPA]JEp{?՚ϏIr6d轍Ŷ1eiU^9:Qȱty*4܋r!`;Qh ak!oZ|P<9[uWcfP pa'Gy.Y:6p6MH`7&J!A~9j*~Z(r/^w"=֓7caɁנxj ^2YߛlhtnYYt)I4=nM)? 7m&xY]?ΎVG_6Q3,:fh$!h5ek0LjFjIMJL KnRmS_ȟ%_fHBH}W߶Cw[V#|EhnHN\cDžI|3=Qpl&H|,] DhA=&*Ëso܃]r<&OHkPS&SWælZ& Í{XlV~EA zaK QX(PrXeGRPioX?~pk@Oɢm %L1^WN'ىٿl (] rf8 ۑg 990ALVBO?nC$Usv+ @H"S.l޳^R>tf.T$/U@걎O@"jek xʠ!dٓ,r%eVEY2HN]izX^jSeXn#s'qɡc#0p]푛7ҹU"C҉-,Vupy_0_TLnp%hϷZ0P3 QpN85l=@:vŌ]v(BhdL鹽qҭ/R#LCXܷZhaI@[M}E.S\۾irGVQbOf7GjVuKfy pG5󖨊|ղ37u/aeԆNUd־y|E|/ZP&كo,VpNUc^2 m~HińJ,^Xla cیxS)w(=ˎcydNb c(Trt8Q0t]OTy@q΀$K}D >eJ)ў%S7OR!ObzޅVTsei(ˌj -B;;p~We>HUZ ?a֯YIJEsG!}MV@kم_yݝ-) NÆ\o*8R|<}#G$ku 5"cm۞΅68L?PdTi8ǢE|yןXRBeab)oƙS3cƄٜc^M:@¾+&9%:7:x%؟MĿD/GlZ_k(t@`b;. Chd:>4av5z UfjF}ӊ1q5?5TK4k mC[1HMGy{-2)4ugձ5{ ylAbt.ݞ=]K]jĸ AJ4$;MMRf $K:gtI!2Jt4%O"ZVM_EZ_Ye Nߟ3؋Qo] X#ȎNB#tVSCOƮbI(NSs U*D_:1z'H"43!mũ [ʇ f +\4sW32(&_A/M<@X>rx}i8FgFFTQ`Ow_L%M=)hN5%9KJ8TH#>G5zͼxvdt?D1T&Tu3DltV㎰Ӽ]dleDAړfSo#lRM &L–O'tz+nYuXs\T+%`D,a;6zaJer 䴰55sa"}6`ufc w;ϡ!>irIӄ4bGD:PHR)}ӅX4aN:3 ]ee Oueb:iiogST)\!25p74ۀv !~xnays-[Ʉm'L]ORDun"dijHhXRu9oa;;u#iŇmd7D, 6@( 9wJ'?8:qF1Zs5>ݙZ5vp8K ,m-sD:9U`Syb9}gM؏SK07vOv6 W/|_~J3`YU `}=HfI1…BFۯd/}@\@H&8% e[4Ljpqu! 7OL}(2_ҤI %lHr@Ӛ1U'lD~3_G-J OO!yj#oVňn FC)k24/K ؚ#H1%!ЋL&Ƙl6:@5/eyh#@hŝ&ǢtUeJ >*@#O_DD)%Š1DtzюU3Ny! c[6 ݏwrEy v"[s73\M4k|2A>>(s8 3gBm$UCKsTA'P{OVB_d]؊;oX~\ fߦ\hüB*.tI "& c_AUQWf0Y헑Wڀ†2Pk'J"@:x8][})w@7߸;/@x*t{>֗9KH*%lɯ ~%ԨI+4[yf b _7g^H6 Y\ģ^a2J>uN]+Ҝ8ջҞ> ɏaW(_{X{[`7$m\/ Qov]-H|:V09W tOd2֮Et*ޒ7`٬#dG=SRÜGW+E. i=l&l3a+*^ ~!dK(Ҹ z5%q9MdZ+jE9 jJk#a@8<ֲt6ڭSbB| SHUUCIpGy$S R#E2Oz?Neb*Q Zp؜ßc"SFn~Nd>8*6XoJATްIIcּ,Qi*+6OƩCwW+Xۥ%Ȭބ ,b2U?r#+Qҁ4}4 Wm'f{j!Idh]5~'^@9;mŰ"@ 7H`-Jxon ~ U5YZCκ ӑ1%+Up* $[WMgƌ9s͖cՐeUX,Xt -iu!Ӳ<TkBZ(."kڠ b$e% c(]AaEJSfxbk}l<4"|ܰ70h edm`F@k$ZȜ4S4L f hnռ!OGs9MX .W]8]UbP=|2Q1yב)ަY^% [5K71 &QQ1`4*A'X7ki{|JVKi4];.F\Du~./Y$e=Ř26JÚlα+@j]H&״6`!f'͂"-xn&Hi~JQ i#ݞ:²#9&EEGlJ;zf~D5^c{!'rz@YqA5ŶzX١a)L"P|4/.\> [6m2p!o+9"M~4e_~ü@ImhJ[ESXIO]˹_S3f ՈS@oV ]Z[Mͳ51jy-)RlC }U vAU qм_SL fwzxdCHe~eї;&)2a٢w! Kk-E!S V/ vn6Ku _ ݏY<뼙n@?b?]{D\KsJ\ qoG| 'Kh@!d/L'y!mCq8eO܍wY; pUet $\MXOP\>H1$ SȈ*܊Aw$uO)"Ndװb(vxNʎ-1)鏵b[qR^d莩}|+)? #%V>vg F9vVz~tv$cP娋`G&3u3KL(d?Ȋkdhe\k]\oP?Z!7$ioYUYVH-м,(Tq᥎yo\_em,ҹF?N5Ao;J7?#` ͆:.IJ@Jxg͋T7Ct m)(g|֓xW+%Iy.$+!":D%GNqjI`V:= Š+M@>6l".H'O8F 9<*Ep0`Gc eA.O%I3Cd3v3r>@YXpHy+Zc & NLT@3ia7DžXRb 'Qӵ`֪GAQdtEu(p;vYl!hEOHmP! `;cPH Ppp5 *&Fqc_ε-eo -P(k&4_tʲJAqL(e6"q0*fU .EH4HeE|7:I{^r'<8::FA$v^ta`.qɢW= f>>^.rqzaadݳg4%X<.O$gEͽA;NVkpHS2H6J4Kz}7~DvV28?#ѯdv`_0|-/S.bF YQU9=j:㼁2#A@:'y]@ zHBو`oQ;c˟|˩KMxܙ2:=rr +?;횫h50?5±FE1?7jEĆ$۵~%åMSVtdL|ӀLdMh5ﻑ!tҥøu,\S<.5'̬x[z{Tfvk~濋shb\ GAW~3^06 M nY-ؑ~(=E,d $uddʝ ,SKF0mu氒urmzܑ{&ߖC`Q[hoQh=mi֊=Iޝ@챺eKɉ,M24\T7R ']7NYA(Tޓ݁Dc$&䨭 *C \:m.(q^+DBa,=gJh;X$Cp JG}qy¨  ı_٭<dE> 1Ы3]>P1Mέ5MT(ImZTrDG;ͱY}U GƌQ#vnq~'(~ԥQoD]G:!ȫi#x!sej `;g|I?`.v m{_ kTsI㯄;S,ϋ~,YN.[ ˤ8v/ *Hc:fU6W=p k,Ř_Em0RwJ:dϥ*k2}.(@TAC0aFFH-Piz 6oA@8 ѻf@{>%pj IEq˩0 +x0R.;:g(f"+<pSuAbح# G$]sXtï&ldɄ)&?~Uc^b>fU>ycd c1umOjmH"rh`G2 .a7QW'+;iwZ*<^5[>/~. =Rbk;Cg)AZe}OfTq/A_%}`*^VAAѬ׶/7`M&6d߄mVEe(<"G'Ý^@J7ta(ұE |N>჌B,0_Ohl˒:o{W09Ey ɚ&qQ}*)i>js_>F i_Iu 9;sBW׊Z}^СR>p%&|]qw1IH% I< L0%̧<gVM{-buلdGKS<4qKi2l^0nBzꈟ09H/e t[%fCM_XrKcv0'̟ iFKAf;a߁\@s;{ u-,y9%R.VS$C]#@Uܜ(D!bLR󭇬IIr%bLfhv';j-]&:ɫ4bv4t:js봰Xa/dA}iN1Ɋza/ut*񝺵z̲ Sd䅇{-+8-|w70/$ב@IҐ3+,Gȓcw~N޸ ´7pdħ:$?`7ͳ+͚͕|3 MeQVl?U-5;o%X~ۨ@$DcWS{VsT-{5G? Bk⏇~OΥ8 U*9@mnC3 f) c,؂#~ՎkSEu ݁:yz׃MG{K5dRs[~,<,~M_;2BaNQ*0!T;+u 8 Z!KU?boa4tC)3[W8݃j'@3 ͹i`&g$3ֶF&iϱ%ol A=iͮf-_ads/ w> +%sf1ZyYV-ٌ"rFI@񴴏^poe؂2/EfkiXz+nSxAz>iv_ u2ǽ 44(8iMv0Jbioe?[DWLt;BAsCJkmB)5 !pիBD4vCjw3LN@٠V#Mx6v^h|fPrۤ+Ss$_DzS%'aNFFHTx4)@.?:bhrH{jihBcVFWܓ$QL'3by:+V`y~' Meu OD~hxҏCn+kHשlŊNn&`vftᆫ <#55LN_Ts9+ԖGYLɂjY ̯ eٝE Ԁ%[7l7 LvcL7g(({wU$SszZQPagaV%hWœW0cE@jt9RFHkV<Wg' k%-&S(\Y<QAV𣜥%TjD!(&qy Dj2[ rGhA8Lߊ&LO0<)(9Ǧ :6m2O\ȍHJU˶93[cZ''{hN4V!$}\$C/yt Q(蔰}K,ÒdS6f(/WlziX[D?:Pavp8q`G/Q8= 95K;N[+) qh̯Ȍ4ŊP-)3Y6-9,%:M260#; ,mhJ~ǒ/pV9lɅ>{&}Blp?^#'\ú։ hĩ 泟Vv c.l[eeY & ՕGR ]j **~6}to"m1J 37p%ɞusf Bawueq[} 2X3wKFE]J[&(OY}=폂fq]0UM3Ho.,A`<,=ŢXÚb6qD Zx i1`QS'Ih1,c`H.@SilFqL5uhSluQtԡfKf 臅]S,d/oaW&uxO2ˣ&ju\V*M[Z(\45w#5z>\03;[`)p/?%]m*̉ٛ߰h0b܂+s$Q0q#^bQꠃHzyvǜQ.Q[G(?ʾ=AVxWKidԧq}ѵKpR@}X6AV2d|m Gb*VQЌKD n :m$1eteB iZUQG sA(bHɠ!@c-j¡#թ}^X t͈";utx (f3|y:zR%uV}mD37 "_?kB.ĬHkTهϳݨd}͗5F)o}˜qKO Ia v{H$)**>#ԑpcK=D],s׶knoPll5N;l'jVAhr'jvFgB1S>{UUǙ>K0)~ZܐקNJjrb3b"#'(_pI_O pov,-O=< ˁz=9[ 3^%a0c| # `af~ Yzm-/PQ'հB]p3OR;ÿwf*wq!<'3d,|qBOӿb@E@Gb3pz/"Y,o!wM򰰴aX/_L#H·xh7D$>GPEAD6g8v ~GBy5fпf5w+¥[c/fO 6b|uЫcpiM7aƃO'?$f~Ⱥ$C~x_it^UxH[הG內kak~EOh`δ`Dgy߁ICI@8!pQ,?q}ٝsjX!  lNC|-w/]NN_چ>]ͳ'L)/>MVޖ[JřQJckQd`m薔ԒJ:RO Ԧx-Ed_qO Vws[ 6#0_[vg>L?VDO\~194*ONPЦ ӜZgK=yVZ +>+?h܅4e˨"X=_"4Ir AU-B{%2r n۸N0hshÕ J8.;ʮշ}}Z]Phbb5x<n޹Ob &T9MA5ȥdPT§}7As`4GmE”F 6\m,?ZVx y IxǠUeNʪ}+\ O`Z'ߩO1Hz 1Y-`K+2շKl,XLNPK$f!՘.Z J0{D.4^_WE-)#B}ăt%uzA&s xT\@[& B(@Vds"(惼Zz5ZɒIS±hb%#[pvAcٛEˬ/ZEx5kv h&Sf;b"K6I𥪓i!CU$V4)1+rUO_qަ6.]8\LL1 niHy؉uwho@Yx̉2/ EH_iwSbb39$:m|z=vEK`+Spİ-<#-UȚP̧{JۋV5E>vi _/YP2HpʇZU]& \6@ga3 ^wuc`me{vH7N7Kh`urCisk8{2;W -52Aharo'<I)}}ύD_4UwPlRFU_a5bT|PNcNկv֖׌"\4S_n~x´#)#'/V3UբH GT k>|:slڅ-ul .1a*5 Ϗ|I'@.4"4]F#Y Y#͵;tH+B"CGH6WB4T=;-UT ߄;ޘΖtZb6s"t<- #TXPϦޘ~TAoO\*Dh˱h";7{oBpvWsC2"T'$Lϱ^!4ܮBY&bboda@(B1KVj?}aJu0-Ihq%G25G-!֠mVH0{?}EHtpFW3K ִxQO& 3 )`PFmPf7_0J$qTh$* lM5Ի .4\56AF0efmf{BMh 8_´Jx͘9EcG=_Oc,G}G]/LspGmί#(}"L:m]X#h7QĒMw f<ԩ A"jc?!]|4NY3c$ 7cqDiBsUQlyt&,=: k 8I'fىʶ{Z[ urh|0 TlkĔ/__`q^E1ŁM_W9>7ډ2NkuFQ\z1yh띮s#8pwSWH8E˰Evڀ|DcáxQ)mJV09$D̈́`6Ȯyⷥ4?NjrF[׌ `aT!@)_QVWoijH䎳V#'j*0BWRS9F1K~z"i%1Sʰ40|roh+M̲p} ,6!*N2tr}JrXXZd5vaz`( |}ʎDM!`SZ&<*EXv˂AI<7?f:uKʓ$29to6?12{]K̝Q=c U6 "?{!@(v$A>8 =[fc$qE6L*$# 3Mx YeaAДk!fB®}Qe5mTg*;.V|d>ii9Oo8-7Fu jO.3|σ ft"m&/T%æ(- Y#X,zÉ+Z#hr^fw%qؙ17'GVeZLͳUg]xMK/6-_D3Ed;}ǣ4> !`v{3v+\IILĪsIHʣrAHSB* BIk-49Dmy^6cû[^E ܠFdSUS?zâtLbb.cD~%,X:~똓$K@CPS!$"NJ @']'(&kCqOm T+55kH/v#Lar&t_R3Q4]8&X9)ߙ%AT"Q;Dc&L7 Y};+uoԕh>I7qsM #9*lߎC vVL0L-n*tg 4#.d1^WMBiT(x9(-u]>;HJ@[y;)T2ցGŒW'-f9Oygwlٮ!WԸ&mj?B=0mvmﬢ]iչ 01ʇ$3N!L W̔Mo0y"HXrT嵇&Sӱy#mgtT,kl£bbc7msD$N Ef*AF_RO3ٴP 1̆S ,6<qmoq 8{ ^|iSWҭ@j]lL"5_oL^ jFcpeX#=9FɡVSbsr_܌3V2`vzʐA q8$u0sSv˔D<4tN~H*uz`"AI|pAAPjT$ghj^jhޏͽ= !9K@'f:.,hazra^~4tCJ/k0#Ӑr jmEm__el"C [T|;6N) Jyal[)`EOxSQ.ֿ5co,S[gկ}EӕvRJ!&x4$ZE?DjS:FPV݄.2B8M:BUN cC)watyIτ_5;VӖeyq6WHa>nPu xU~yMYh8)ӀMv[(mOS[,vMbOL}Z7E: Z@V4c *NU%l&31iI@/cC7Fڄ9m8V>!+Dt9p҆1|EE e~~Uѭ_}Կ#]v-ؓxM1HD> ,ϸHö7f l—R.V#@ 4VEbsWH4ZYD#\<ҟc_|l_e@kʖ,@s4=^F*̈́6k-N?z>f>8FB6B=mv_g76oqٿ|H%#lj]ZC "|/n"h~yҴJ=JYdQ7@ `LmSz[V濎Z668Od DŁo Fd2[| R ?V|#!^, MSQuU, _4ΝKl(4˯ΛJE$G Б5$C{^ ev1D|8Nu)- q1`:߄|ʼcX5[G;$<ؔu mbFlHmxT^|GБcd=GC]1^"9.;zryr)>v:eK̝bfX|P̽ . m UC}j$!)<>h  0:Lf+m2!.4͙=Zxy6O=BiD)^qoIidL> ŧHOn/ wJbF┴G~M}.qtfмRHL2ܽҤ>1ݞ"mY_W"Mm@z4[17}\v)Ӫ#oA]4i`+4DabUUr+ %hꪒV"i]H" %xSgúz礔k9>+jZInNI.N}1٠-a8nsaDK+{1?/`}IJo?\|$&; $Mj rUS xkz WA1ӉiPnc}xsd3 -W3j,&a,h0^#D Vc'ESO¹f;"ŻS:azO©4U>sNKO^|ՠ6W|5XGo޹*ktsP.EV$^'OCJtmOGRa\*/S ?eTOa"(ZfŞjz-A?< DgCacy'G&Qt-6RruU1;yrڮ\DU~˶`T3sB^2`7?X' co@ a O>fe8A;av`QPdE^EdX$ (^! _B1)j`ݕ&D)ivf3j;Uʜ<+vnֺ ]sg5 blc]o\T*̪ yD77ܻlqVNRnt$(=mJe[q!$a<Ț؍eޭ9wݕ\a`aSPy\i(ڟ7+A7B&ѲR)Pv|nrҝ.>){YwQՆp ̯iyR$g24 yyaQH~:<&MZ[W"$!Γh=-T͜p5 aK"SAܨ?ö*,Xw@af3AuFcHԷ')oB8i ehN;ylwK'ЛQ"q$ewG7з|Nt/A >v#qm?:N 8i9BI:~H eODpF Q:P'+QiI4Ng1oR55 ZYte&,N,u8"ʨdhpZJ豫ߢ W3]/EW~x3-.-'3<6m>sL%89Y1`83uu>)ChM@3v*VI M$|Ǵ}{e"76hHX_h[ѳtf\=ݗ7p]ak7^ڄF\c[T^]pƟ;1Uԋ3[@>0PF qswlnV,:]@XڽHQ}~R$[! ~W ՟DB8oUƋ$Z`;_UN_a_[ UIU0zq̓)068t0}Sߙv"lrۦBwHz9/"^$L9%5 LՄLIIdnң}b m]@z8*yAZ!=!mCeWlmC>[t:IO'G;C槫`d^\PPAۅݏ8FPj萠 i 8[`VhλHɉnoad(G(,.# AN {g_-s~*5c#͑V=1_Lw78sN =uHupCJ)jUOwƏhs`m {N0QڑYq5d/+fZOyR\[d|öDԄqm2wo:2j> i+G>7z i!G%wlO/45LFD"DC"͇go*Q>-#(j 5Qf]e<{{J1ʅ)Bm5r}/GnIpD*1\"&KZ2=06O{1Hb4A6W M@]upMbS#|O߶tjCҧMBososjf% ..GQOCy6T $*nHܬjy;E f ;Q2n8: =E41*ͪ=u 3CAwolax|khkPv2,H*GM!?-MoN>6ZfkW{*oBD \w0wUCMP%Â"dG% .Ewin (in薤џ|+Mz8I&ȉpSZ%=3(j'ܭeuY?1vo|էz CY5Xw]+}@OeRAkûŢXj{yv÷IL ϡ1yx | 6v2ρ=Fy{[Sڂ/8)j$3V=MEf(v2I 'DS@BCGjB,@>A;bWQ19Ŝ^lXNthEu6Mj Μw2d#-99%5Z)"ג)# JD8<IV5phC6Icna{e8lTU gF/iB$a,;~-0-Bien4yI0_aGVjޜJY~~J>ne-ߴ]=w=9Q^B]BqUij+]-ĦQM64gJY'w`$?].o mJDC?SB/R-i )c(N~J|(_PR(<1>E/ q9)B}ε~S AKi4DZJՕ8gJfa 'De`iӥ)…}|^19IZ$+ ;ٿuƔ>KZ1UQ!I̔<>Su1iq(KoF Ӿ0RjВ%-+ h Ɖ4Ԛ$Ǹr*5qƠ*t k:J}%9@YHsyچ/ZXgen&,?bUwe׭=C(8&hr,8%hΛ/wU?j\|7Ţ* iԭCceߋArCB9|\Ԩ'0 3Λle).7!Pu撽ށ/G=ijboJ.w$Y'|SdW4CQ}s.IQ ]0C6-ZMhUG^-=*N 3Ǘ+7׀|'zǁ!H0P5 |/d*A1DD*d1 ;wKk҂"8PZV )WxLOE f yNY2qP\ ` zڬ*=6Kx_SY9'DO,98!VY$Y UkV0b/ +|wNf;CI_ Զ308C="+ ~t|/ieL3_]= Yһx”0r|1!*ZBB 3[}O\ <b'^&:ߎƍC>`\F~11@8/\x+LaC@VRQv/*=N@ڲ/SBۍўOdѓ< VPu([ qKD*ۂvbs{-i+L7=ު`m"tLCwЄa#d~N<OItoH<wϬ۾~q_\Wos!;­j΁WK9Xe#o^ $nS`UVZf/$#QbV+*<1\ ρC"I2@C}FsF-8c2*kדƣ,` 0SE!}JRl@>2> t}DF6꾫ʣǘy[_YeM#e\$;_u}DneRlՍ?ir6 D9Dp?vbJ)QǠ ~vv:=C˾7;{G0u)>aPYAhtO-u?CȪJ? g xjD^9.K%M&uNۼK wBݡ0=ly1 AU~!@IJ%_jmhJ{gVY<$7Z @^wۄٴ< *HxcHPy4N#0L]!Ё!{%v?eB03"}'c=h^rl)PΡDMH4!GbVC.S9QK>g >@ }}LBUF w$U>2} Y*ZgɌB'@|> c1=UTC޽ܟeUM!\:5S2'S L-,iA{E<+(I1Isz}+l V(F F~_ġ W0w.O7vN8-xdɐ410a /T90Hpi3-I3mW@7V 4f*)nQı ޙHMwAo2  XC1}0Zc15A9iH(F>s(SS>|JY˘"KI  xH€o`w̔܊w8!ܖMs7l]=ִb!{]Rquז7֐TwA@r2c↓^%ՌϧT=b)U*}(x0v!^%{4:dQ@DَáV% Dg'7cӽ Q1@'!.=}ViJo9H_q?DRNMd"% .> 7uX.BͳI貆d :Yυ 5[HE^J}UCM,eVdщ}m.MTNÊK4Al?z Zma.R;OYs1\]@ACtt53["T>C@lj̡o* ڤa&pT@E6(XNJnE=eyK~Ω=8|V[iџd40frJY3iʮ)T/I,>}3= ԰?*[cߟɊk-&4ٌE扱SoZ) 9yXbz kH57IGѺN,UAB" J 8C;H jXRE{F Juffiw~x,/P4.\y]f=5\FŀIVBV' .A7*''|zVn[[RyP]^OFgh ޜ#+ߦv[7VjEJrY_z a.w\>pH>KVnK'f66$.ÎxVs\`+oqJJ;"G= -%M}=\bCGoVKo6 8"LBx;:=k橡r?w_إ^i1xdԖG 9&DAѥ$MnjSCI稗ϲ!]аwZ]jN70Ģ# 4QLRp lUЊh?V dL(1!cvyagyގ :DWUu+(4 Z8I w-J30Cj>s`6,78'Ķ;+'7*c뙝JKnd ^jq?)S^ֹC~窴a  ~~u}BI˦=&+u7yt1 w m+'Oɿ e r"I k^VP4Nt(I ]8|ʳ.#R6Duf^9k[tJjClo?,Wǔi]JJA*0'(;ێ#CCp(%}Hj0 aY$MI6~5}Sm6=KHa4ϽCzKq6s byEaqҽ%3ߑpL}d? 0r l vsԂfOBʱmBJot[_5/]@bL}x%^ 2f>UE EfBћəEq6699'RZd@4k.  I"9zx1~V&34SpħrFD\fZ8k7 R-4re6t/_zrw4y<^QU&gVѽt~!1fƵ|+sk?mU8R]! ]Ifwk,<68+q2mHxz9HpTDQet1b\ZOy95TDֵ 06WVC=0h-cB*] y@mo @GūńaҲ_C 5>U8;~َ%԰wigv1z e~*: { K !E&b^`oxCeQCW,h4;,g4nq-@77Wy6YCn%{z,{GQA+.C=R*IQHgxhUՄ;ֺFͮ/VSXn|k<+ S{}v0ro0k{B fTI'1n{6H;"I̠{>xfzٗA2ll"Zv`-9&|E ƲmL@-@ HmOb"4xDPw" ߕʕlN@9@v˛#*_`Zf.7hi g^@@P$d  A.N&`sx Cq;*R`hVnXoՌ}N̝k4Z9An?!{r8J#JH[ P*3G.oS[΂ /fǦlLY>U,(i {vrQc?Z <8l8B_nIb0wSo*k'kʾd }=.E䆡;v+4g!92A(t4rlN`R(g< n1ܸL|J Ԇ-̝7>n8$YD*bTLrwhѶJ,1RO-]:w';w0\2 f-,7xד.G OGI, mV*"Wr1okB:+Bx+t@=ƙ2kg$>HBL5mr &\TgWguTjf/ {D{85MLY{THxW!֪h,%+B&Y]bd4obqa{5=bify% }3߽^e;j  aNvjmlu98Nj^鲠8噂Jd/>=d Cau' yJ/fP* &&=| 9SM.dF /VLpa 7g1=nisqۥvcQ8-`Xl@0VmcF4l7F) ݜ .)b+ ` DHRkj$4%wؚY^ߖs ?NLF]õ*bKTw{-?4R*Y? U)"nmBxݼTLZ;UԓѨACbًkmjG-2B&>.gZ*H4̹CqW/򙒴K)~G$S zHB NuM;X`Sj'bk%3Żb5+֠,U\yiǾ^ Rܰ˺>edmDg!<=*JӦs.unu Hc׿x"9 'd,Bet; J9)^fȀ9G<gb;J UkH >[`8c. 9'uiPoFw,K1*L43"PWvk%Qw8]zSnWd*R>1_h_EG;Ï&55 q#^RMŬ؃οs1'7!ʙuvݟ|n*W+4.S$:jڊ_ѭNfi/PY%.Ҧm{)bKmbY_GwAlbׂR80k\F'D-5}'RBv!2k6tf^j^(+ T,5&1 IKv$_ 542,dSNDN4-tKrకeb.P3PL]&O)-Y_g3?y|(.z8ZYq LjQ_ לA/vuX/Qo Ed eLJ&|7$p2'޵r?Γ8vM&j\:m<9uȕ?WwOjh7 B*fy1xtSgf^p}NIFJ]n N8nw|p:*OXj@9#w}nWiOv֒I$#紀,@oӂC.sDQVd^25%]ϫvsXӾ .qC6;/l K< Eqvid 6 >GԀi7n˦̈́H׹Z?.VKoWek&pg/6~ǭ)k%OnL]x9>\C5sӏ|if -%Z j(Bp SC!AųP¹ |Lecq$k]6L}I]5a\JԈe|؋J7 u0F~xo猖؈S?y_kVymn %R;uWN.u#~:_mJ>d39z4zN0+(aPdr6HG#6ӌ\Q+Jt6Xܝ:8Vtj yiIӑkz1P-o"(F žZ$v8xNdo`yֺ3Wnř? r{M޷!ULK!7lDϵs;Fϖ^I*3C*L?uvP鰂%Zs`!8vN;¢l%6b^HnUm9zQZ!`%R $}4EU2dGSjXTI{I"u>@J( 9~hblQP=YH<"Xrj;G); b&C6bNcN&dȤk ggQ6id3O}g-3+dм9;$7)xyN5{#+s$9`qJqI/ {>w'R;gZc TD7;gxAkU[- }/TJi6q( @Km\[vA%H&KK}E\nwY#l mA}%= F$E߸5dgc1coeG2V#f,YzcG梲|鴨NTL;[-2l*4wuL@J+6Tۻ$a"`|~N;hjr2frrD? qIP'Sb镌Un ~vg*ȏ֧'2WwhR9܈4i3Y)'d}Q5qEƻUM7Ip\ UFiJcDyR#Kz^%z @Ytgw89k$BNiG"sDoczЮ Z%;k/j' eڻ!y kܝT**_9R9mS;% P }܌\mQHz#2@}:kNw&&Ȅ[,IR {e  9^ D% | l-u;BjpF̒/8qV2{P5eTE`~:i63f{-]uAMA$7s6E=9w_xO]1p.f;NMXoC]P-wd{0QB5 5LW @MT{E[7{b-Z1W0-0+SiwoQ1Շ.ڝQWx(3!yjWΏ}Z!%N\?dWvs;(G!ֆrdkOc[leDAPq]/sOud9ƈl& 4wKCגI.gc#[ؑH SI|P5gX]snXX(io q˿:>ܜg;*&G9EIEd#w3J:oa^܂rn_{}e>ZMO^Q =Y^s=qJ1oR(f")K7(O+"^V;"0ss ?% حϼK$#^ uS9 v!\kD4VyY$詎pE z:ě`[5}p 9BX`$XGFFO{#+=2bγ[G j)%ğ@!Z"INe$ \#DKYÌQ_<[yf(EIUO{|F)ݝ@>#ڌj o%g3*ν:js>L(Q8(/<{[ѧ٠3gݔLi(kbƴ?(+3ޛR4ޚ~F^G:$9M顙Y嶾 SZ(\QtsJBMؾ]GdJX>+wx 8_+bj뼝~ZE I%mI*Xnm4mQ-%?շ{^Eh4;p5w$M2lؼL?+C5Z&s8\r9B^L NA4ϟ8 8O 1|BTjxhgOao}=ߐmjꁇg>1K(Ք}yN.'8 WUB^"4.ɌW.hݺS)2 D#3"Vŗd@֚, VW~X-߼Og{;6{S4*x1mAlY #/}YAŵҎ] J2aج N b2u E>!|\o+tk 昌huhcaf,~%Sβ;%@aώtnJ2P0Ec>"d _Q/K@B _~5`q?ssSv_tJ:81-EjSm8[ij@lDAZ W/GIV?Mߐw Bf~+ 6DZ4cox:,gʆz⢆<-O!=Q~/Rd ðI_qDmNxA 1 ]eq|&)W5LVTn"̔"(yDOMW85Nrs~?1 ð)&=/u^1żvȹ/J 5+ҫ+1yQ) B=Y2a&3#R8~}*W>Bn{4QQr%8. .mµkn~|# iAs Œ}\M?#$ݴ8Yj u3Axj]GcI/@BMDU2}MaѡU'.RЅ ^uxd@,}#Rb թ@X-7?\go`{6[W LJhD=5 z^{L]:dz16MvI6Kf+M:c4lW88!*TxǸ۰17K:Aʭ060x2?>-atl꼪!.8Cgri/۲sPZA!3kG]* WE3:`* !X R¦AF>D@Uf5qܽU+d~"dAbh ȥwH%S2ſ.š5=]Lg>GlzMot"t:=`wPBe͓p D \7TmKrֳ*V0t5b;`kr:=|HB9?KҶS욒&zmb'F@|rGiVh s{?|W(fZʔ>(1li -=2jߦ6NEOR@5{gbjN2Sb<=&ȍ lnZ; ǃFZ_Sq v *Ѵu_Bƒ>Q *hy?"zj;EYscՋ#a P!^zŽ}}GD5Nߌ2s]<{ԫ)o|8 q>V˃l2fZ לyK47_U NL]ܴ2'px'VT($&rǍ}.2 ٗ a-XW@e_ cɩVT#%9e6l8$vKWi-F5NJ+uK*ɫv|??dE_A [>\J)&Q$|¹T0r*:ҠraSq~;RĆƋXxT־kI`6t0+ѓ.x qװ EÜPW5[(ӹl抗W$f= 76eEVyvC\kl/ JB!8:Lk9-yBH^(vc\KG:w)ns@.C0Pc g@^okM,3-`'2&d8ka]XMs`q~GL[rrv2DvfcGf\A-/^6(4ťS`Pa@ Rղ,JyRT^4:;GD].؂Cb>rt[}%r_i5,8%q=/>"Mi֡oIBI\>I7Ȥi@gqW?agGRʎdo/ZpmSs)a\aR=f\w(K%b{s<D,{µ<&}]E2~ИK7tuE" =|~?\1B C+6po}K$ܥ{^?bfXA/lel3lZV&/]K XYMC¯KZbfm]л:ȗqd(4kdr(!zvcC ޗ͋m5wg[Mbti~qG3Ɔ?DDYx>cAaG"H,WnDM+%VY1'L2႞D}; oe@4T;qՓ խHW;T3&j,SA'Q\qF t%H;@IVQMȥǪ#MY]4qîeMa5z9qrjF Wؠ|? dj4ks'y߾S>]?Ds9lھ[@CQ ax!leP5v`{!j Qz.)] rf0,:c+F=>CrD~ ь{"G, ?)e?7On4_T[E\ .? U=c>$VmKu3qa!0( G+O& a%!Gs v;{MAlY lcgo4rb_S;]BjG(G/F"5J~2Wkr6s.Y)DT1P+*q)FXhjCS+c/679zL u*\_i3qwWO␅"Ig}vJ!~aoּLdu\7n<1B98T(B{'A;[Faq3(9Gsԝ_-RA%벽r 2x8++Iэc]u"߅}sY* e]0m]NjKtgmVYWu`<{ `Z0 XK0'NΨM!7G#? ,k)Ll$GY6xJ)$T>Po >!٫Û#٬쟄XlӝF5jLGb&K6LJ0kkTCԚ.k'Z}ߚc0ORta+3ߩ(]Z .U`\ "{5Nm<ľŅ[lfdPh\˻On Q!3{Q[A`VT߂Nv׍B$c0)|(l=j \,ğwZya7B&2fN}c[W ADGڝs EP# ͂.2(IgR\>lqD+ft:4-xv>{IP4A$_7ʅ9UJ~>">Q>>`uϋ*/p'lf#y{>8 $\4BiyE}]uv`7mtc:mᕮr(x_eQַ7P&䦷0=T.0\nU-徶J"ӥij?SY "TP ~W#;ٯ5;uEցh}ZFuilyJ#/`~-ՙn.I x48C61e!UӁyRe%5i־$AMcެ++Ca|9FL"2Ll+!Ugoɞ}EꌏY >CP*%kG8Xp;Hn9NT^uh-[d=?B"o{G1tdAdаu% +yTA0R$}؊.pbv`W훥~;jmHLH!"\&W||О ptFf蕣@^sH ŷeNF>ltH1wX%>Ŵ b'ƣSG NtNZ;jkSQ v@1eԁ R _}@rYK@ASTt[{~c]`|A!ӔAҡ FBCDA01¦;,Z*R? &Pg@A$,4FB %P BMeǙN,XҸ%u 8y0&Uz2Ā}t, tUAԹFK\j|ey"򶟮}Tc0j,,rGݱ;Ҩ|luvזv줵a br='^Y:hq2[ܓ҈E9zۥ `6&}s]T6g XaggUMb g<G$A+Yw95.tn^ė_0sun9ӄvoI[4[JQ$xDe`$G?vURMT>Bꀉ*'tCK:-d:*Js}]x<2 ZTD&b߷tbWPۢԔtը+N@p!hExi`, l9䕸sJ92)wXW.ɹwƽP]}|Dr"V[3oϵlzѰOk_rֽN i̟Ee$Y(MDp`cPnbѬ]cPZ(y{V_y]]m1,gǹK}5k G)cxR\Xn};Xf+So]~8%g G' D.8޺20ji׏7Cћd}Zzf-eFEu73l?t=*>eewٖ5Zr" '&O,*:ŜA zk/YXrT&M  |Z|"WeǺQXժ6R"nEYrKMSN{i|¬^i\׸i N|[J>%Lv&X7y@'b"ׅxʛWZn֠zp8 Pp-Qe*q1(٩1z0\oCzs|Fj>xx] IQo{hn_X°nf\OtXUAa/O7%<'t{JLPO]kȅn¦{@6w{<<ȿNj]<'Q9j#;pIeB^]&&+[` r.b}t@Tr%Eо$qXIG (A5;vS>&6Ql0h9/mRFYT11ehX#7'@aՎO>mgN} ^k<Wc$hjdJ늪I`XV`8C?Q2(dB9KL]Iu1 OWP=@a\rl-=HX|cp>~8*!jMnsU!;;7$^4-"5(TAdMVtOTm&WW3ADM8R=<9+T]Y0dߐY}(Q Mϵs#8ACE'|L92eҋQWľ TDm/Ꮪ?2 ).-Xc:ktE+/ar͔iҧ@yCDcA=,/f4,rv:h椅jkDNr}T"O8'o\QNf"M1$zL찝Me5vvS|0sVWuc! uVs ?" &> M<ŋs8 X|@&E^=˞A"PqR4|OurbcZr33> 3ˇ%FT;tS%_==5wEڙyH!x[]j-]PLv.=k FQ^И{<3ulB\-HuȰȘ<@+$&keN^qpE^ыE|H8뒦Sm+A~0S`Zt oNf'b 6k\)=q&݆R `v=nBߦP#\G2g2E&ɣ#?}tt?da"G 5ңxĜ9ٿ~GFmJ>:| gR ʰvU/ͥ>[cҢZ`CDKoFࠄL]rkx7`VM<,` H=.S NVӛT"ŋ/l[& c/:9n֨:B?P)bV)emY~p@pǩu7t7hNZ-P ?EaXNE[ Kw>P"e9}D@1c8x/!-FmAD/`ċiq+|pzwݬ=odԁ?3e֛0)Yk޻$@DeX螙\f?8f~O2 y4MpbMwxzhZ@h;OPS0UL#[IG~Ӱgϰt4I$wj}#8}4^lC:B/> lt9sLT;u?kLέяwEٚS651b)mw-m[p(hk nNe-z;DA_Dfz6*g1jjwi3~%r`{Q Q_ZssYjӼ=B*Q1kT%TRw(5h ^V5$͉T{:?Rٛ_ﳥN :|X=}2%'ar-DDIv098.0$K9 ,oJxyW+N†شw]!jiwӜz<+K+&*OvAEP?hzt]:dD|}zy폖c: Tn:e ~P? n!4ꬸQDn\6KqT->32zQ?UFdR1EOgR"n <+u%rM]JJNQUφ >͓=&\äAz5`)x<'W`D2&e5듖/r=\$x)8 b:ŐV(To,>Nuue້\ _Ntzd8ݗaOXqJ-0Uc+iߒܳm0*+}WƈpV! ds䩗3Y\mK-#|%2m&@p 3@ڕ>gT4,ء:M%^@Ӑ)L(&`o۬iI#S|uS~6g/(RF9{u)fYJG*"dSv=flMʹ\1ǞlQGwL1$x Y8i"̷W'id!{{S۹]놬=a)VV@ sj'ZSo8~;Ӽu]-x+n_`,HwIS5={</!;մ W^8@<9B(!wan*sđU4Ro, /y%YV}Йs1GVO Qlb dq ^9R&4~&¼>*-㣇t/S+zd>3''@7dp;Jt"aKE LDycӽ zew{SJ1(ۥ34 qPwǯ^Ҷ+d9BAH_D?x|܁e`̕lx^^i \{GܪzIiM{JY޺xL mqWhP1C8o`.L/x/k?c}c€pA }N\™V 9dT ܬKy:+g N"#>? pwj)>*hɞk1}Hm y[~U .WYCAr4]ضfogӣP\l_צuсj&Z ֵh)!/C\}%G+\yltXa^ssmi-QK &9qP \&pF(}%"魥R\leCaiH=b4Hߨ_*ؓZyfus@?E_Y߉ c )*MOn}fBxBEiVQ|םKsFqW& TIaq`Ȅ…ŷ~T-q8_1vf9:H%- 6qZZܛa:&{R.{FSt!ScZ&LS`7htSc:C'uhm! xMSDz@Z?T΄'oewhMDhWstWr\z)WWe~+?ד }:5-< @2w]܈2sDר-(U~bx#b^1n_Ex^d:79&8/Hh( 0/SC֘/FTUCe5Ha3eC<^KCRϢ]Ә?!m>+ִ>zרm!¼L\ \' C~CP6' s8D귺E`?Ѥ'QՊPѴE!e=|a0Ch[kr0y %[@OzZWSKu*HнKM=_<ϞSbFP[N* B e2/!fh8ڑiK_#)'+M~UL.дKICILwty%#=gD]iB͸f+<ΣUbbw٘qѽgt+E?ˑ\ {"(*/#ul_m8WrV;˚ZC,_P .PB tZRAk=!8b"7Z H4qvq =:wԆK?e>˛YVTK5uFj/ amhwT'j&S Q22=ҽMrZL(=:ׇf^ٱY4byex;Fs'ᕠSkϸ*"([%g%KGK|nx7FŒRZ!2iGLѸO{ qJ TcS,jHe@H>z7 Z u9\ 3u*mfmx]!*{'/rIQ(ׇHj&7 Zfn5ڂa!T*"-ߖ;X*N4_'{ ?߼G~2f_$(˅ 4FMa@&Iܦ8*ludc|,e@DRbǏIbPc b"fcԘnTըډ[DNJd/w ]@]6Nhڍ-Ĵ7qtoi[bDFeڞxs+̣EF7r@Εp_bK%^?^icwg`l@<#zXy[($L<:RopxT])4r")Nec>!NH+D̆1H0:RZw?9Ɨ(/MrddDO'ex)1t Cg ; IG>/Kt\&VbD hPX mF2<-QbIeGg'| 'UQ^||nwq4LƁ) Mۋ˨mE+ُQV]LhmW(p<#8ٙ:7ɬ(񡻮4+υ}ffDބ5(T]9vSϔZ5}\&07EYG"}WA%,^!wDA W_ ufZ'*ʴfiCC/,]PՒ`f"_oQ 4P.]땷ST5rpF dn&l8UDk_"8Z9s_Ⱥ;//7!)ŒiqqbDlβ*hW #6lhA5~o]\!nE ~\Q*er6Eیjyi%HS^e91ߜ$ij@O- N۝%W}yH"b w7]3;kn@-~j|\RQj۠TVA!gD dz|6(GKʬ,$?*#3mѬɶ%M1+0JѭL|轶1C2VL6/MkɘKHMXgw'N^b*P)H;Ts|Gk7HL Ѹ:CXLj'raQH+htgk#(&_:.\'rKRLK9u11ۏΏF*thAю_@?s_PNrԭ [V+"lQ-s 4]Ver ?ÏZ:n?hiIҏ87R+#>pT!;++0+K"پoh0P㑯V{{0a7tnH+5m?eF4 !ٝ&PrO#qD*Y $gVRhW3˧RNEJF>SAYWtY&ڣʹd>"ڥ2|aio7=?c:PP8R _.e~=?m 'AASS s?Qbe>~ ]d<):0F?i C6uM=ߝ1єù#)O7 /}jhx0OMHO-ѽdK*E*kG>(z,2kH\}yx`<(z/TDQϘ}oXJ Y N}~`[ᜓ?_˶$ Mn3BZf7d ܕ2P[Q+_ ioЋ'Dl܌N)CN U=@]j%N$E6S-2:J]C5y=l*~ÿh;?Q=Eŗyʐ$_F5/eќ;56-q΄X8S <b[8mJ>k'Ԇj /FTCܼ?at%G BL녭\wLJ%TjvZtrt DMJH_V\,JDp70? kj~X&ea\6"fsC {=e1#_I Ѐi(΃[iaqYҞ _f ͒cY& ˊ 3nqY?yT(Wu&FSD<Ys{ ءE|& : .PreT&c@#B AӹEw?7b:7igvd4I2Zb^P`;H'9^_+1k=+KۂBL%bЋVO ש haP)dI+gGjO=(!-8 V#!hxxH׊r7GfnuU7&*F`seq6)3Dcs&ݯ\oGdIWܜeվɅ5ǻ/v=_MD˜| :WRMu)5Wi+ 152\m^`=qEGGjTX+EYɺ0s j?d0|{H8NGcUtHhLmSg^@bgr \:87qa1RC/![NꞜ B+[["#}Bϻfnh{bqӏAۜ/wQ;jJQ4*xY0?@f^"YnȦHyIV S>ᅘ4LMw3F%{8jj%3RE郹'B&=f lfq 5 P3"{G;b@OhE3nO_QviӐ_t#UOo˟»dUb.hSBaJv,@e&y]gA ]QWޖaGJo{VBJ"z5LU8fϵ`́dʾ'#}F, ȱjd0ȚΟBYԘ'T?rLߦ-Ui-1JQ^CN%? % <&=rqXxN]KӋ]6* |  0+W1dzl: Onp25ңn[xz̆a(w|Wp,1gS+P]Ȋo ٰ5.%t ^\TT`AI ![LOr%P2R?ͷ\+i^$91Q0Aq}˃bvBn4$y1i+g~YMNs9H:R@h+ԼODG~pJ28V7[,\D'?O[ ᖣ1`qcL8Igmʨ$6Aa2y][Cdǘo3wh_e7kT $ݝ&jK)\p+V9I3r5 :i}O*R{0z-;:~;[#nBc Q8LuզɣxPZ ;ӝД2Ŗ? C]%~y#?꣘Zd6]rRrc;}|U}wQKigYƺU0Z()ڥ:vIVTaKcC|j|NOnd8u :jv}g|P%=Z[{RTfKi$V-!uޡ5fْZ̶(h?R˥-%C"S݆ft7^D*(BaSen(@ 5S5oRvNnYuׇԎICU飵BZA Z)Dh :=6)K`9"Ȩ&BR& 1p#ƮP}.l374ON|V״&И5ԝE/(7A>XTHzjQqo俁He/%ވW]/g|RQȹ <Ċ-?: +EeaR>K`85H;ڟt0)r, u0&̎~SD ڴD=+,w"THQGm5sɌZ=Y:"Ӽ@!1wk)W#mcLL'Y.?Y?NwXCMz݋@.۫jA;b톛 4lvGW=HD}Jw. Wqgr Ӑ%a¦f*jєUB7)xKqM{'0]!kRn7f~ރ]Wx5ut,s| -H`H+c R%y@"G;7X,T\K#h)4# "c~"C\BM'P/(W4p%|o{BSg7H_ʠnQ3eSPj@0:+hP@OHGAW3~} nQ'S?Pvt@U>]*5R8.#=%G/<9Dw37>,JTiv\D]:TFx(?M*M" r=3?e3_ ύH{5tW:n.qrk"ur,q1JS@ݱWv 3ٳuט܉7%,tX<@-?JG=(i;T4r&f] e;ϩ[R͌ QSCR_]N#:0Fި[!wζ^s+of1ҡZŶ6ExsB6o|lEA1[<&B?Wg}bzO>/GQKXK9<^QMûWva'񏨸ߺy2F?p0Yrӣo l^\ xRG%AGcAiWpWO`ȷEJ$FW=blkIoZ`Ǧ@+"L /m(xy\263~'~T u6:}?n٦Vߖ6㟗~3Sgm.EzEVo$}벾͟c j`v1Ϡ1*ڵ̞y >t|Ui%j@IJ}>>d8eLE50eRĶDԚ2Pe#X`g⋓'o779/"k I e[^>\ְ0f;Y&9ȊJihv/ԀEVݟh3JI8=s3u;׽ɺk-jjXcM6m .G\lKQ2C2t;. , OS=ޫ8-4"L3mhGkG~*;5N߬g |>ۘWgmeh$8b iI2EFìoY+ ކ8 93N+X>1\x0E |En3|J_n@:yAD @l#J~*sg̗}sMK2"8kpRI%:)UqsRCԨ.pt;LF?Dba$ݶD'6k_yÙDD &C L=j7.4ayz mKI#u1`Nؐ޽pr`j(~RfMA//D=_2;):,΀;&a ;r u^HI{wȴnhbXps]AN Fw5NV TI=l9Gx--d(5O*qq!e|+^ލu殨5t+)(AO+6퀐 ȶȄ6^FA0Fcy ΠBzGXBXERXmB?,b4y2{3oMd=q ZyiJj76mx:Y~0D{p5< BHK1IJ4 N)XRy؋(*F8uNQfYe> 馽.bAX 69dKXG%YDw ]G M3!ġq"饵?e)޸,vZ[h62&C~gPɾ&9VVo#a|xiD]\Mc c>^Ӛsѹ8a]LT#X.9eg]1 l:>  %Ǹ2ygLo:3 S|D9a 9`/?A2 #ܩBaDͬ&K=)$=dJ6 {&&2&z1c?rLx.QbzNc@`u?NGO1scG\(Py鱣B{v?gխā78`|]H‘]4]/$M׊M#-zOPV'jg0C8p_E+7a NJtd2D]GCao>E?嶀Kpؠg$|U] rYij_JRpcm2LBQ7FV`ջsmxҢ7+#V\WX0b4]b^ӭZN(+ 퇡7.mm4~R*$F@?~bb*-"_$h*D] hF/(N< S> ~{HBNtSܾZ ._-G Vزi +Q|] ߉71ǝ@xșqOV%3w&*`Ţj&ïV\I[8\""b_PW\XQ 6Iԝ{Hud,~%g}H\/{Ə %* jSYL"sdHP0D bFHS $35knoB#;r$Q"@OCm\q9<҆hܬEDmi8=}>k`G\홱1n%c2{FajuQN*nm~1߷ɑHLseHe h@p3u0 \u83D?%3%˅85&IR*< $Y;>ʁiݖXS /&q곖1W")#'&x 8D[}m$FBb@lf %m\B-gKk@u2 Xva|~#)uMwߏCo_OӸX 8Dk@CT`QM<-{1nHH.!Jn6e_֔0׬ʀ= 5e>jMz}UBܛQF :tZMcYcB{4bH0#V-C0\&]LjNY@ c9h )NC,I?ٖŹQC#*OR}y4KqqNx_IR9 koFm?\Nl{+(HfOA"2 g4}Yk'SV $'7WJ>%`C:,D3tI*4|Q׽;]~;_Nj4b"Ěb_xz'-=n/x^ąIdI,ʬNkr}'wwLdi]y #)Ykh #@{ǘ9?3JLv=X]Y'(W=c wo&EpwRzkh*8\UIYςjU|`2@U {fP{5:S- ?,8E gjLzNi.p? QqԱ)S 򈼷KlQ" cY|V[P__0\ˉE=$]C{w+ > IQ[^F!cS[vw>j{JkwOE;j#h`@BOv_a'PNԍmqE_b2 3NLiU$W[aA q̴R6 G]d#=Vi/X9#xEKuNy葤Y$0RsKm2Bn@#5Ĝ(b=ϣC 0tLM:հ, gFZ<{s7\r/.@ 흧G/Vh_<—{7s9P"z;}Y.Aznf-t3 $0Pw"er]'^NR Ӊ}+5V^Aϧ.΢n٤ )/)Shxf Xizon+Ad,R~ 2nw<\IrjHhyPP;j+bLӹ9]HG~~ GG%i\Njg=z6[|PbM E &TOuٍST0Wu2Hr?d.r ~* :Z@{(5Y;h%w:׼@:dTa͔Ue>]"o8hN2W4UƟscLdOeNV&L uVʳeR45HƝ ɃH}!˧;VlO$RWD;E.D(>gy!-WhzL^l>GYBBmW*;IV[E<Ai^-Q8$vL_[ όzXo "UGrl::!3kk5Npe;]jWPܵ6f+ߦq_P\0V,QYO zw~›Ѓ_Y׏;/V<\0>BݠiSZOE\}7- <">ftF @}GP䕶| T$ M@ϿJ D}ڎg2AHmYKZ$z]dpC 7 j:S6 ;7L| ||J(`7*qmWpQ"?t#x3 b}"B[CTeE;@鬯lBCƧZY3Rka0w7dKN,8pYT- 8!cb/ܥ۾,O=2cjY!Fg.igoR0ìZL+.p} 3*i6FQG! XI.P"g$p s7h t/~leD=@mSKYf 0i3C+)=~㳭pp, ,fM5)8R9u jGcXco#8gᾭ20h4 +{v直Ī*ȹϝ'FED6ތ, I&PnJr m~cH^dwҠo;Bc8 ;WZifWV|iR5F!xr[p?7Ws"C7c^*;XS*?Ȏn\b u tnBHDA2hp0fC*?瞇v_mr=de$ ?C2q]Ɗd=l0|RSE&a(=k&a렵N/ wO_˧(6jwXs6ضc0h_G-aZn\FM^46\Fv7 aJhǷy[/zcO+h ҭ54m  [#c.e0??T*]pJ୦HJӏe[ʪw0rQSXaŸ|MaB[@N=OQs9*&-!͈458ؽ|OW`ȓ-݆IC9tYDا$_Y!jg:I-ƣW~2//ųE+\01sVy\[xr鑩PX,Wم(ibrvJ %}zd&|!*$(`҆vJtKJ 30I'ɏXEk;Z{yi T{Ɔ]DKA+c[/l" aNW"u'= z &mm52nxIFӸfezz䁨 `agVZISȫcmW3pcA9qw9 G{0g}p7^E x+zeX9,;u+g9)/4G U[bfRfgcFeSpLKdko\6~ڂkNNaQ77zHr ׼6",aL*'Q)n LvʰfʰXΜuDن{L@]a7jSտw4doo0aVf$W[Ym8[_XM.pߦ́}Eթ|*jN!L,y;TC#JT~)]rAK9~C vqIⰝd,ıA$2_W)XώU\A i*{L ѢI/yig6'/lxi-5犫³Z2AYMz`cDLQ1FjD 촇kTQ܀㖊=ccoP33`Y<S?GS!VUD zι unVb@ =(E5((l&%QKE*m]w\5*6p>S={9A5<ME­cGDk Rsfiルpb(o'ΑJk6q` ׂ]p )y%Jn dǻoQ&hjrf^xh˕"CPh=otDb.+H,oQ̳'&^r8TEyN,9fzZt}sBY3m6ɀ؜C bx~A +HlQ777|Cr8SVklJ#ۛ3#>AG/nFѭ gN#?L_sǓc D"f@bcsL/V/0& 2̯:E2HFJ[ŕT'~:C ,N!3'm#E\U96C"f݈ kٍi:Tctsb|Z4Znj*)m}prXB*N(0e7%AJ4{0-2Mh*HW{Œ'4y|x" cbduxGJ+pR_lf[|B@oO;;6pPř kGs+s'hgZ+Yݞ40lT H7FhYD_g7-F$:pޯ.0q}S9fŮHY(PE';C \PO-폗x iAUe$2(*BpYgH%΄}e z1oc=76QTOw꒬.;">LVYUow6"m2og:87z38x<@,^Cvr<ѡqvH%l;Ⱦ^#%= V5}$IPNTc8ہ'OPXSmUtЫ/s11}; Zv+%fQi\ GHwgdufbZg|7NaF/P/S\?P7&JP+=B/IdY zxV-.4e̿ZDجc?$EL݌4MEjoMvhkWX!xoߦnbl)|Bj#l+pF&߉ F!jXtW\giD3-i@I\Rjyn @cv K[Vt4/ߍ$ѵ &ؔUQB%ddq]Xa-&{a{ {nuˎرg)_2ʁ5%*t/ǑEqe/o {s#ա;(fb!smG%?(zҾ%ۆP |y;5p"' ͕=Wo70gp^ES=/K#1wJ$_S[4 2|K.> IK MgxrӵaCZzlC P1/۾)t%Gպ n*e3 Sjwy~)k4Q@ssHBʼn%A2'8`#ϘV>b ݛw8LxΪu[8ӯ5@ȥj۬K*9HmXoC3*kaR|Y4@kͺ'"iY ŎW\)U:|Zg/&&ǵjO+p 0?I&ruyA ݫteDC*R{V20 ٹRSEmxcb!̤80-,,~?sFFTjV K$NeMnqL@ӊ"5fXxE_4IyV߱Z=x (&y͢+J#sȽ~ZQs}VfXEeݢULK芪.?\o ~L=Ti}茮hdO>' ȝ1$̉>#4 uw]c|bȄMGR,1C$}Q~ A- 3C6Q-$Bvo+6Ȳ9p~V$f;U :T@643#{9<@Nx] \3M2u tΌ#< 1\89X.T8:d$}P^)B2FPk3 / / ʍ1=AwxҼƃ5Q0OaO}bWx$om$R>c{p#E<\# 724u[MX&U. d\= P3 f17"9nZ6Y@0\vqˬbY䉬,ol"I,_||;LӇH_'ɹ!^%뫰2pIyn M9gj41F*|׋@rbh~ɄV=ָr|8F@t-R߬g|1lG`isioi1`MbFe]XCtfςw)Zb]0鋷 .i}~UzeR%B8GkDxxN+EÄ2pfm soh~>ֿOBR"}fi9ϥ:02yV#M4(Q=K4څ^ |/j#Sc~~,9D߷/ 'q IV>/%~sy[Dֈ}͞϶?F W%E ))aP{|/F!]":XcK$ߒI T%1 ~e{9\![\74Mj=rDH_xgiʭV3Syu&:[UȺS /ԍGH '{&c߼ӌ'T[vžWH&c8+>^9EoHf͌o rN/i#z8lU1ӱzEbO4a =O; `ԣ@lP➻|R~GyZ&v BLej $ >XuaWGc,Yݲ:/dނ %Gg~`dLE)ۼ۬1p"~BIp#]4L*q.B΅wS˸vC`:@=bFNF.T\Ter=>K5+/Suɳ(V&"e3VˊJD#,^X,n5?;1/vhܯgM6/jִX23]o^U|81ՖP51 /hsIVcOc4}MQC0S%܇@R:=wmrVbXr&wK4_-_y/6<774+vRwOx3xKdF8LpyFR[۠D=s:]qcq-HL*T3v0wO1I0 ˈu6]Г\.aȸb!\}S:7֏WUpqخ$^2c k-'YRΐDhrfXk^ dЉ|hիkEbap[yV9"\VĢtub)GC6fO/7#J*6i5_U~]c,8of1'+S 8UKt4+)aDtvSGX(ϵh|AlVyԙ໼!ʭ۵Ұm˭zb,vK]n܌z<z孹F*Cy)[}1U#~(t#HI*Bh_k^v"OQ [6|s5%vBvEdt#QEb^6 %5 -.,*:u4dH۞wۢϣpW,aQoCȜ$Έ黫W#މ[t :u60P]{d!n=%ΣJst,M6*vDk׼EmH0ݛLpZ7,D~&R^j"8^\|S0|ʽ(;cnYr鏔 `'h~s =GG8 HkZRd;}`}j&Jc2>o϶^wo伲KS9H)`I/iɌ#"čqےJqww.`+`{}uNѽ~/Na:VFhΐ96tc޻ΓJ}!_-OlgՋA3@GsH`ȰMضk5:ȸ#ډvKo,+XOjK|b~1ҏC5UxF8tAͤxjNe&yu))ݓin|P.7 |o=|z$~+ezlz؆ ]c[̙:fI=J.*2bDzW+xNϪ \E bSٍy?+!6ng0UFk.Ro{=˜v |%O}h ^ZAdQťEVj8U _ >ao$ 2~/$(WlMW48RVR_'+scVf;_~@  .[ "K^2[Ѓ˹)78sF1c·q-{ے+.a2@`~ɳj4VCP0̀n`NYi#$y!'PC +E7UexMaCmfka2Tk8-B%)Ok>@0̱^ Ԓ4;Nz,yZsJ)'S#)?f\=*/iRm[GD,qkc vi~5NV a}y\szCF[K|R`_aia|R}Y9%^xF #wW :RH«~SoIĹB0؁i CÄ-OXKfqȇQ9*SUA-jf:5]ypE3J8#&%r dv^ckIۚvȷ&n"Ilzu+ 1gMcQKY /-Yv_(S浛QBcv SpQruQ4e9)rђE>HŚ.|APO˸&u%뇈r&X?Oz325R[x=Zy'/NRg'xpϪe^_/R¢@ H uح+=bnFk1h\"CY]´,ŞD<%; ڡ]FhIAհVmav[sBզ/tk்-%[nW(P!?AH^Ψ\ۂhԑg GrJGz`yP7p2pt!c_tI*!S PfR :yo—轤c;}"]|7UOΐTQc~hY"3c z4Ri ŲDYm*qh,7"F040#}8tCS)RvG'{#ls t_ 1Z=Cŧ3-*PmWm|$>Xnl't" !3~Qq;K* mtv\?$q.aV5)X!MMm߭:Eg}3s], gEw0)1=2SB:삩"%Frv*O݂.5apf5r@Ν0Sc濎"|׈#w)W۽+0J6{1$0{%VKd8Z-M];@)\Hŕ()}v,a}÷T7fL %+&/_ yIP].+MSc6SgJl%ĩtm65U9!lP/l9Fnbr,@c  y钂{A&R:Pj`e.@5ӟOYk„<OhkJ9a>cU݂9? Odv2d¾gҩfʵ2-7&ٯ Y UQU)vT/w|>?#ˆN@g+(Mg^7ffG܃ $/ש)-ijBW%C-HGۼ:8jatYin ܽ: ӏN6=-!i6k A5WdfC) DeexgC_YI/d}-:qDѫ#]+%aLM9b.DMX` mfֵmb:fH=rQp X".i3D5wa{U}ޗy) x^ewī_ׇ {_Hx{?9xdPNPs0)&VOoQa".b((FIc5Xn|?vu rAo \!a~ ?X\ЭߡBJFX,X B#Kn޻`Qj1^N@;r7ӷjIvY@82. I0Tfmg㮯Pw3 6"g9a,Y!; {[l,Tp 9r6NˆNeC ޾f)C1#n΅#qqI;NrݟϪuqI[F2 `؜+I`*U5 -q>/lG`1iǷad҄=K.)(.3:8}PTqwWO:jH;N}#˦\`*b!]. ,ԧq{QTb'GvM'9%L h,Q:IQZ*K*,2wש}@] Ā(#" ] RRX*"3ҭ%׆IIyY1nnn7a]'W$(DůvvSr$|Av( PxO@ǔs8uD\uEHXT+h|Ȇ7,hjDBu3* VR5D05= h;I&=o@8+Frd?-W1k&v] ^FbAd]H.vg/4E7,b+_8/so5hSMBR54ᎹփS!o7M+T\kQҶa jDSt6thA9bn$ԱG)Uxr li}t0 ~=396ֽ7"D~< c|']*MYo!PpwLh|YeW]P(f6Ud(Z`zE2;x6J]C_҈ePȏe8|L^0aKfVpEny?ŢV<P7!c}o`AcHҵjd7 _k٭Q}weXRhThk߰| +G/!Nk!Νdo*S/}(OoW'k-#q#ܻ8fReS]T~l{˪ &RrS|Z(^c HQ(XgPJ!kL Ä0 E Yh50=7I!Fى=RK1e/5s(a]}ȥ3ZII Yq#JSÉWS3Aay$;^fEa-蛾x|}}?'?m-0 K8[c' [ S:`' gdO")=5zJ 6Lݳ4ϝ Pj xBA5J'}奈\8!۞wjȸOq2UHTvMq %K|R z1E8#;_SK,S<ݜ?a9!o5DGjOKf3yGh)AgQhBf̅lD3WؿĪmB٣{T!6 ]>(EW"u'Q9RN,WM%Umpy⯽r{3~0z 衝J=:VIsgz僱ٿo1WݓAȽo T B_ȟDB-.bkɈhۥ<7_WhӋxuh,t }rsjL[  ۻT$+4bcs?\j܋\ڡ9R@4уF|iꆖKHx-/rJĽt+opJY" މ0dPqei"Z≹З%%y4؊R,k"7uys:D/2ߓb;{l/1%4e[jjy){{HǛY嫌l~B2ʝUQ5!Ý:!f&QwC4R ,(`(=f0y^KprٝTw#hA"$Lut!~1y=ZlL\mpS݁,U;KuHxWl.V YҥO% PClYCyI4p,]UӠmI] -ܠ䡱>&A!I6t~R "wT-#8̦5J[(S`a.Iաecigū֔L? 4L=ɔR'Ȫn@c_ NӓgH`d %U/t3E6~KIT#C: rWoT cO,C~WPN:50"; ȥ4*0pUr⮾LTיb ']+#ګѨ~a) BDN[E 2%;vK8ۅkH{d2iIcW\?mi:}e "OۓTVD |ZfdlK.r07^D3& OFp!@Nr$ M&BNkc9-:@9|cs'OB-VRF' j4sX#G!|v(A8);дNs0]w X㍌[^A*C>|/4첺Қ߁E6>Xa*  ݞ{zk$o$ᘮ$QW&QQ T2/ZZUƫG[1^OhO}ox>hkwqĵL⸫ TBg EK8l[={J 3ݥ_\)p Y%9=,7qH)QYwt? 8w~ Mag b__,&b{Fv~hnC_Պ Tp&ToAaPfyQgi mI^`5Fv'߁TIqd@e*وb#r6 ӨɎ&s*aSKKҾ[kG!ӈN- 9KgfTh,0ye8DS90gRr$t345h;P&uu/sI >mZ@|UsHkd 4Q j1'EIŭ^DtnZQa|h,m< k}.0l;3$Rݏ.Yb~=F4'5]Bκz^[ЛXdH:9D鑸+ ff,iZ}MUx?_Īy= ʻ&=R!IY^>1=4W vA)'xg~ RUtJ݀EC_dqi"ܮ ҄NjJ><ҞZUuҌ_/XKז?jO3[2^syd#<7c< Oφ1nxxNj ;j; ˔@rGKzHJ]2*. *C+-02|8(HB4,7c tlʂ1pT_1D;#͈B|e|aK0 XlJu]%ʅ2 kn>jtK}gAa٨Q5kLUd|YBߙg:H$U]Tkj+; %r(sl ɃHN'ڐY*Ĉ2'W{)j`D5O8Mҧt)[R]gnDk$wx9w%e'1Q̘.«nbn8Ӊ,HEoDT6tҼ񜃖ߏ y9EߡEp!@eoM(񂜉ar +#epO0vbTcospIKhh&3GY{PqTD/u`[aPh// 8.#m@c{x%Ywвtu O6mnL#IУ;헩dn2]KΕZ؄L)auo,wWLC޶.ѮɄmyL>سrMr ##RmGS vtֈKS:Mk]Sw'J¡h}5hz{/OOiTYʿY\OU1P(JS5G~1Т YTߕiC{Z[ZpaaOGƫu"=1gY?\V</c*O=$(M+uU d^"Lѐf4 V2%F.KԬM=<96x9#d mrЗCvaC-rGG'G st|DRQ Ѓ;OVHc, [7 .s,%qؠunI Sxc5қRGvilC]TR$3{dYWwʉ6bΕ*2>Gv b$vhʪ2䕫/Ov^|b,^)F. P4~RR"`#<ȑA$7k]EB؀pbW'B)J)O0ifaftJXmʗ{Í6Z:cҤǏx(v7a%i͢u{h߃/V?1wRoWR gf`QiĻ%p$S-R&!O*9>Ē_xN,\]hElc@Dy@0$wF`?QKfZZLp9Uiʋ$c+.ҾcHiϱGjR o? "6ϩ- 3Ӵq#|j`{L3uM8l lP&`g^*ȯI;`oa$9_f4b[ʱ=,ޖj ݾJMZE CC/p'p0ݪ՚~VUe}&go4Y[46;qXkF|MѮyPF,}@-Zbpl4#[c}uG^ms>Aƀ@Jghdaݢ=[OIBL@Gzph3>A!-DY,{ŋ+x/L:%! AI }eTf0XF)@l_fd 5SCONwML.TԈUčUR]{7U2LbP> 5^hJJAک=)|Dw;-I+6vH,p6^( QI rAHxGQ2R4Az% ^UuE`9sدz]X5_ѮS#E-Kod܄̊$t1wuYbQεW]0'#tN32=p淵*pu 3 ‡/ Sis=)^gI0a0_җ7.k5G^h?c}v;i5A?/p(I9Q!w^SgFҜ?[* !>xp:):u Twi_ rm)1rujF{9J[چ$^V[\6}ڧE47OZu&F6jɝfJ:a hÅ.>K ,P / 3 gȴ_Q,&K@x ]v5Nŭ4fGϓ8 ݭcpC-q#C` R7st5#.EPcjQԹ]7S,usi R_>$O2Te>7OC\;5tc{{MT8 " Kf%wG1E]Ӯ6_t:ԸpsI5b><ڠiMsu7`<3dA$o$(ilYbWVu\Y%΍1{% k+:nE8mڥtU[Jԛ͈&ٲD,jTt[|t"<A x) ΀+vU#|tww Pa|>-:!gw7u1>}o^dcBPq8TCdٟj;" 'aٰz`/[Y[~bxkʇM=@4D䳞M?U"\*H ܦ1:yj`٫Q⤋QK.XmOi( lqIsd ^WƜZ HO@/ZWTҡ:t/zFj\JAvtJxԧR0[f`C=7\;x5g7$b,B1^R"H>Z@e=\:򞭞݉DI3;mwTPoeo21PG-xN4Ӝ{]oQ75ak2Ȑ ZF]m,Hv)Asa_IEYz vd$$PFW +j>U1o.R4[i#L;q%nF=g%\4M~ߖ}=J!I-k?Q=a뗭&NZ!&V'Te/y6YI6'R w]gRrҽ?  '$Y?ƐEb!3J8 {E/^7Ԗ{YY pk/o N]ysSTBܵޑASHU9sՊ &ۀ=mDK1%ʐCyRk{QQLZT HW#:|B50OHE? fDݘ@S@ILB

'rXvĶ!>&9[St9]q  %;2t'Мg~0cl&ءR" Ac`G+w)e9޲PcnnIZ'C/gtWh DdrX5' wD0JDu1@4{o^l꼙sŽH:FY33-f6P;nkؽQÛ}@ Y%-;0^lEAPѓ" 84v;(n'b4Ao6TTV!&aGv`(ml7H5@LX7~Ok[A#;GB}L]h՚!"Ch*qs UC2J٤-CL}a\^gthп"zԏO .iWd_g9XBsxN&]l=vT0QHT=!1?T~dC ,yHH4\0>(.C$@ڢRc$q-`PT6/bЍ=v׍u^s-h5CCQ^kM=}{/9Kȩ9X &OcVUjhEisO lQe9a>%[} hCT,SNZ1nN ]5C,P^(? n0÷Z^iL0i>J<(X,'. pBE3̖˱Eb,OX&3&ohA"`(KH`S)p n'֩ "XJ&j~ Xhi[ ul/\ Ԩ ,fb-o6 Ix,j<Q-@2TP8m֢tpg&Z>o^A5{% Ԕ O, Œ Ke&TQJ]=>K0Cp(լc"; |(Si B"2488oqzԪghkҦn(5Dޖ Yx!G3yQ8Hpd0;h.^QDǩcOhg%:Ek%?=%hq5X )󸑗nrh6@Q\dP$`5C֬C+ 7Cz2&lAY}tk?ܲ1s扄{s5M+: i աkrckTа;ߐmqU^#^zg'B*:تz:D:kE(5'򞻴ힲXhO]0%$rZo>&_F"2C(PE$EJ›?S>TX^ԧc\4<^f5 <4k=pZk LEUX U)|廸27[ o_gBQ'W/2L >b[Ie,4X GVIc1lejU.Nͫ畑]E hWsBg K] iE[#q;/Q.n`ƒP)w$ڽo^ B e_4H'<2T>9) Yna֣eξ4F[~UN) zyNp0탴ӛE!Ĺ6V J*RUUcz\[dZ7)9(eZ\ݾ^/@U +`4kࣕ7a'Fi+ůtbǘ BMe|HCSzso>>62_^>ј1[d,/#3t4# ΞjiBcYڈ7o"Ӳ1=_e?Q5NŘa늑D :Xnb^VhQ[fd]m8]A궻 SB_Tt^8%o=)ugI^+#p[2m-*iG^nM=vq2䓋ђ ؜cZg5gfa*=xwB'mNTX'Iz%q@m>pT֛*ӥAjR]h:*>n F*kWu V\')}&m>V1>0^VS镚|_{H3VFOYt0j @h֠ :crPT5i!txӰ˘EzéMrղu.?: [ѱ 8.|+ mJYNeFC z/8S,O,}){#DO1KѻM:xxH[ڤuvU1&}LHHȳ9@{)GvT- KY*PNgߛ6Q|۟ '"_6O9'e %6Զo K? re?Lr 2(Fu 5w=9i 7v@ Tܼ2$S)`u05(w,ӹǭ)>CGjv%fI&-2""(A..M2vb&2Hl z埁̮Rg'xd\U۲fTbE]Ϙ%4Pi&'(ЪHp{x.Ul!! tϼچy'xUzq8;kwD[:`36`pĂ.7%MKfo}6bm^%8'p-l eA:Jִ j"cw5(p,j9r̎T w$Oz!TXUv)Dׅui_loRLU.X% Bx]IQCc*H8摇`{eS{ε'BbXiRUF*3Coě[E"dD1\k#Χ7xG|n=jPG5BJp7wP`Q>֘(iO('nkrF\sjK͂&;1o}9wC.4/#쵖O3a6+U CI/  av. CQdPOhCʑY6܇+qǏARB۞5cu>S|-_qiVP&R>)h\psj`C9؀Kο/A@|f k:.#kuTثFxF}zHz3ok vs_?>'*#c!$QtCxL/$AP{>󬿦#l3?.K;RtZ/RUAG Ft4G0'EkSMC`[^^`uhXl :Q3qHm\luKoz!Gv2FQ0Ub7 1>NMoq:> T\[T&x)F.mWoj2L8MU<&^vV69\mG!dڋ\{ wa&ECJPIVp@ω.Q`HJ XOWs5N`gDmXqΦɜ*KZLX]R6!Yt"v`_儩>  >j6t}:'|R!rkl.uKc[8S-/lg6bNkoң ;gqN*L-fNIP70̮*u]ckt;? ;dQ򈇰-4E)UIuėݚ Adl„6g$mN(BynZ[ҴX2Vao鱌̅1Kap8*$v*~^:ÈAztwj\%=6N=g TxZOLam! xaKtQb~FC{7jwaZ2it ̴'K%BǏd4oF3(UPrًлc8([G*cJ%b庒)*GP[WwuY(~ԹEx b~48vMo^[g8Q%{c1S2 }p_^%DSa*M l@`ϟFzYbhpt ~_ a*Oc8Ay,g?nhD^_*io ;کIw-U dQ^Mw `W J{'U1v[N#B6wIt[Տ-\Dދϑf!bd) Mxg {N F&:5;\yX"D"V2JiC\T@L}~ eeC [\`ތVZE+%B5M_:'("O z =˲|L,OI㔄+p1C$ueV")$*%3z xvİ*GRZv5>wƘaKLܿ^D,LX"ѓg=ſxx&em&v_sN?@7D G`#n׾p,2A|_a<Ҵ]/,} GpdjOu3SbzG~:f}~MKߚ[J#s;5o [EQ @쿸;T8f[__"v>fYWdj~f(/@\qύVMSr$+%Fk_`j+}>#Q(dKm:tB)з_|k8E~LD-"U5pWYw4}!Mؕs^ak|8ڀx@ib.Nô  \B8гtja![_R#!'*ӽ6'qvZGLhKA~]呉hl? Iͱ yMJw+V#&Ykc Pˠvl*dgdU(iӗ y(z8ϊĘygS{k|!z1ŽY%>Ib}~S?{• %N{OIX:G&0ܔ!Az2KgMI2WN*N@?RJ."}F.@ /Lǻu/KM1)(h# E #Pša>#v&=4)#g8}m#L"Z#BXBYfg).wyK?NG||sV<̺}ӪeQgSzr}"]փ}dD t(\.<!l:DMK^e{Dq%c6)_@0Z/e }(Y=},2^9ևѦ4WjxkVqQ!b<*hgAz(5P;k0njIHZN"UfT™bn+W2-(@^KpqI]izT*!";pW, UݹbHdgL$S^\_[nX%ɹ',.:n[ΙrFxz|#v|wHp4Zx㡑,u-k^uh&i](9ϛAg=PeV)ql-'X=&esg}u3*g;WdŽ6.X)jY(*KC|jn2*̹? 'NԒc^Ά8M">ҴRq0p"R!=S H|^ GKi-$buƷ<\jb &ꆫ"0,792r _9DK%X!Ð!$̳_O9Ty`ߏ%utdz~(x;f/_r6!b8-qUc$])0߳t̴ACElFn_ ctIxΝZvUyPi_Ovb qPx?R嫫8NAX,a\yhttUXmRL;UW'*[^È?> 5 < =R' dN t`2gDN!N2ـܷd=|Br`P.(lD \%n[iT?@լ)Q83wWc* sA.F&`},R?K*^.lCF8{JrS-ŜW$%ztڨFU٨RP7ҜצAMP4?'(,~V=)5ʯ`-db #MqB;LTuY=rʫK\tʴM d&bjs2|i *2W*'3s˂˜Yo/ҙ1 ݵt.!mjdGo)" LavTEg \br+a7Y\ guw]2{Un"T!$Qi:o7}"7f9"vߙHyHXo]V9T) *ՍX$/zBLq 7I9[вZE9dSJHl9ZNkXX@#h u+k#{(Sc# X,nɿ둙4~ o_Ch=JZ9).~>A2j>,Un*MؚCzmj8I4FxpR]f݃灖te {B$Z8ԑƉY C3vH k:_mh삿XTI[,") %hVh>eݴא,~foFh!<,`j/)\sI9zrc\w;!Iſ,BjdZEN.$f.pqM,m0F6XVXH# 'FC7^ݯp] y`fE@<Θ@sfJ{16S;=ak`Td;ݷ82רR_tO@œwrVH)ڤ4Ӹ  ekXVz #ȶƨL4l/9̛`] ?-٘@ŽNEv/2B.?N)Ƥ2X&#'H1D,Hߘ#9i<ׅ TYRqmIJ MDY?54MNP :M>/WVاT:_.?a=IJx(Nb2pT;!MDֳr4 }NKw pEM Ƌ)畆Z!cpY8C5_Ru'=J+fyv\k=P1F$T0*6Xے(Iڣ.ztgۇ~}m+Ǔt@rV$0f2y"\)eɾ᫥ҊS2.BjIhFsi*C;{~poH n[ *P7",]}!&]Y,)sxrh!?96(ae~>Ciqc+ӈ;?dʿSHV&љ /^ѯ1ə_Pzh'd{Jk`}S=xEebbWRrx%3l''@ueA8/nn꽸Py;Z⟯;?߲cEghܼNV@'$˖+T?8vW|P*\C W1@k :& pnsqi) Hw欿/Srfa6O͂XwJ*eZHU 'ݢ= M0E弦Y/rjH|1Ro?@Whmz(>m X> e6,l^ FZv>r|SB]Sw8a vU=0Y HC:KWR di1i8tfK o (vO+/g[NAcidB*p=g`z|I(mzV[A&ޗx>Hs5wz 8Z6!Ll^7Eܲ+ %ggvl!s0`~X{7?s5P^z Pe׬xJHZnA!bUA;lG]~K&/Cѯrٓ" tH[O ytABOeWSV9V ׋qsQ/Dts,;5WdNa`8aIo@q@{msdM7ykt{ACס*م͋jշA9-[ы:"^ܮ`+c =CP]Z86?C@f3"Wb2r/l%= <,0W聛x/7P_\ɠsu>I۵v8Gi{lz^ id0N5VrKw;j\}s83\G[{ihBy&hEDos'JL 7UtB-ajbW$L,)|4uH|C9}o$yȧ +T8oӲ#7 Y4+ױc)#(J|~]Tj$T 6'qNEUi~=%2κ&,''%U7]BM8>~g-1UCH/GE߭^lʾĘK)Emq i) 2~ (Eg  -# կ4B_^TM9fˋ¸pazW&c]7:pCWRӃwӎ}#@6>ד>:ymSߧȄo#O]iuԫ317B\|k4Aq祰' #x'1PXL֐~> HF_Zg)B2- +w1q\ȀLO?h:|ɱs~oʎ-梌a2vNƈVZI:U 5Mp_yWS"N=*WKxѓ?Ua<ԄrN.b3+Zը"^ҖZO8gD"|+L-b??+<$*=$HW1<8Lh? KM;1k-gqY2N| ܦC<70&!vj3>~BXG 61)8ٳ<2Ȫ;tz.UHڰD9:c4n-k1* RBK_xriceX۔<ݝFEQ,PYvww3SdJ UGf^N,*Kri'L3iy/ZQc{HaջM`4zX>DSAj1c ]+\;ޚJ@hfw=C<)57L^Km)wX(j}XğQc|ŹA$8`8;FLc;d"^D-q@)Z!0߿_Ql֭(2݂)=Es6;|jafJ+7Bnz(5'SW:A)W T x=eW1Q:.)h5~VI-ڸ5v*}Ѓ9LHs8EheG);9HȄVZۦSs3耨̉1IEP^8_z)┇] MYBƒx87'j({ը$` T#wA5{{\CGXX Lۼ[Uihl4)#qldX)/2iTz꺩ޯ}Zb4avavdSjUC?x~q k){*(>?I7W{n<LAzAR[0x4>Hv|nR $ChQFz5)VvUi} qDx-%YFFdll+Ծ.6_xv)V̔>ܥʾcb-$cSDž䓢oB){xkU ֒Ky!9EE#5en6 eFMKEW ;!וw3 z|E`SPAfwZZ8V&5 ]}(iu*]r7k!!ROeրdp.vZ?u([9udr0~w?dljԠ(\{7b?4 ӜV}{,P xfL̿Y.&)ŞTVo+N[2qTC&vkTS6|Lў_Lvb+Ëс9k?;?gnU sR:^rq,V5k G##,֋jHAי~zᕅ>_y]0G`B-n Aś[p9&cwH@s[n8MZ)O4ؙw}Ȁ;iu H"7mӱ;G6Lt #os-/u&+ҦQ|lb;޳/K2uXJC)&r/я[nSū !'_B$am3|vdbSo\b՚U@`z{=+b !RC%kwX&@^G}x*E zCf+n|w\9)OϱJ䡊L4 l'a6c#/PaFJ":oN_/.ЎVxry)aX] )yW3AtF.֯x \oya*0(ho&~;5ωOIIFF U]D"ItCxdEYKh„p4),@ EE';\e?s~>Խ.{:c$Ca1A~V V_F`(apCǚ9\~ HnSaD\mpη)Dɉ\Yڮ1.qqޮG$TV/}%:iw!| /֪zBaVzGȤZB/j?}-c D϶eeza,C .C -okO+R\5IM؇ Yv_E1L4K]`;6"ݐj(6p_:H5@E,0iOB.7EW8q F AfBs7(ss MCHQ熋Vʰw^嗤 H7e,07nJ';rcvĎKHhfMn~CdMT!E(U)$bZY.*[\7 V(O>_hNN#y" z :_COlOϒnMyL\A=YS܅~ ǧpW)JQh@eI<}y>2 SLtFMYxupH$ wY!Fkբ>cdrEӛ2ؚ6J܋f<$tDCAN^G%գ6-FaI#xC8gY`S`˘4ɨ-AKRF9KjPKnÕkiZ6f9" Vw}]S~>g=DC >Iv@AbFսcn7C!aG&Rqe7ßW@eb1 @:ݖW(c|!=T(+ȃ39>od FQ\T XDĚpzbI; g&f3RQWB~yt4yQ:SYa T.vq32]6D rr !y2YMPܱ'@+Jo81xV^cHel_F J7VyS}y;мi@tԠ(EwLF`GǍjⱴc7/O?^ _>i%o,!ktemi=j#-=*s@7*n 4Qke>w3dՏ ,bE@ux ;);^rz *eC hX*S>NUx:k5WF<-g&=Q~r) o@X4=UW:i#&9ߕ!Reiŏ8!c06uiBRڂ(ԹL"Iz3 J CD5ff[=}fἃ8]%Wi:kۨ+Ƭaka#4,YĬ>RE1Bb+:cn[YQ-!=fZ#aՠT[eU"GJ!Yn0c4Cq\fNz e&~f xe` ؼhw3 8vR|JgV7߶ْz6(Ӱߖr4boՠ W2?hL Sط_-?5e6h_cU1z&sa? m>wf*/Sw 7$hG'ꗣp yuy8 &.Ä:e|3}%d:L \)f=sی:v)Os:rҔ@N~zϜc"2>:E**g~ejoXONXҔ ձРe4:8McJGx _ua;"]Dg]VSa`k8r>T.?WBFUI 'Y1ho#3 C#),PULƩnDئ6NJxԒ_Ǥ𥞿j,9H""GgN ~Q䔹+FWlIv 0IG>Q %UkP٦iBz?6': Al{y_=6T qh\w p˞'uޝU>֎( .v"QFJ}7LbYV"=c")iսsTa+F%&w❜{$~%хrcYa\دa3 crV/ +OÇor&;NutiGGnr/Z;Z)$xrd)eT#Ŵ:rs_x³qF>pњpbshW\3.$rb-LHd51oєra2/ k3$fMݘb(B\@PPZpbjpI/_UKU h!,t0{#t՘1htz5KK v˳T/~{0o6ȦL]/<\`GO%3/lC:ZFGY%ܩ5Dϼσx:ܷT{_OQYVȏ;iQ'|a﫢{}` "ğ[W(rP= 7E?I+\#"]qxC#i% `GK>i.dv7өhLؔfD :'+U+/Q~¢:\!|K8.̮Hn;`+Go6Uar:{w,I^Ma.q,Oۖ }JcЎs'0j{ʦyV\VNTqn Gm5D3F%y l -ug̼n dc1UAo&\^\4OYSh9'+aKll`5% zTt!/^U:X+fMzx, }dWot0EJ9<4}7TK_"j |LeDE_Ipx6Jy.\ua9S X0˭}3UK|9gcՙ9#B[U=tZxn;{W!߃E(镴OS&Z %v˰4X~""*/E*D'ʵf^r ,h1L#lBI0i=yzi{l("͍AWOItsM7[Wj/),`9"g|R&gi(XǿY&o1RkM/M}7-O 5㪠/ ڦxM 4hi'a̺&RG/1"[Mu } !8_OT;\? d()ls&<-Vra# 'yrilִɊ,N 4N 3*mUuA^=<#!ׅkŞbCLC-;iٛݍ ?k/^ljPAmI&YO) `ENUQ -zE#hm`卦i}𽐞X.4&QZE:] - Lphe:iL<"ZY9/PxAwݧcWYeph:,Z1JMTYP8Je? 'ԍER4P[CI5J[BNP_@, ʘ7"rm媾ë(]i-ܔqUMAMqʕN/nզp؏~ LSr[V(KS33S e1U&ߛb8/r W2EnjB3N:ClNt|./Q 3(A}N]ʟO43@+,C"a(=R4OHEt‘l2V;y9OZHwG)>͟iV~sZQ6$OU`6qq "Է^~F(?QW,i%NORu+yQB0ͮЛRvtКxB?t{Nj]ӗA1ޙHb^{ekΙQ{wzg)kCB]ψMBO_J)eG ?%l~OƴP+FzyU} c[J";ˠBs&8ߘ$Qa@GMQ9'G&Ţ7.*9q-:Oz{MۡD^\u@Og&e9׹*mȦ-{~@D\_9{[ lXyUub zQNT@61lj{ULBqG  f + #/I1q.iN2w&U Jm1쾙o;[ 1 %ƏW}l؆ }fxy}8NQ8LC KSb[,FDe1|(YLa|1>\iUG/ U7 ]I`O{kHx0 ȟ2AJ+Ux/GQo[l^~p򶸲"ZDOt. ú|:'hy@qiI'T-5֙'_и2w80.KR& \ntg? S]eu\IIHD2^R ! KzOb|+gqOǎ.C_ fTq@TzerrȶzB.}cY]7㮖C"%4?re+OE|BH;.Hse۰[Ip0F- f|e0PG1qӖC7LH4'3bFb|k>GX4lL⩧˚+J{ @m{ho]ԑ@1ΟާVePiE&^hzGsn}O@aOd3ʥSS>4F3YǏ<;:A$U<ԉF>@M"vh 1ׅ''H1Ёq*-f$#9smz>Hմ!t8~sz ?-S[ ,,2B_34yM+22CozҤ|'l=KIW@7 #dLU|ZZrB8ʐ"!E Ɇ HR"_͇|XȁN[ T_k uP[cݱ4U25d^[/ΐ5i#\ NhzCT1Z) @,Br |Fz<DE/O6ƯK۲pRԑUґ4q;]`+D60ބV46eĦ/{&=I|NuˏཀnA*rH}=ndsP^U=|iiz)>Sáŏ{YpRJCl{,BZƔO~8hxNj9G9A'8*Q܌>b0vb;)j59˚ZSe ^ȗ4ٮ;!C.qH>F tX^S&p':o^>>vv)F -Rf1%^ !gomAOC6G5g bAr`x4YNkv,:9"oK0N F/o&Ur=SqY;9B\-Sq^컂uƦBdl? *6@!]GJ6=%by/V)vH3K;<1?C-,DOQZ !4y{qS6⧷ E8H8ѲWig?dͺ1Z "FzU(jA*x%fc>̦C}|~%M=uc:٩5NމIӻ rd_}*$8$v|5[.nlP"͑Ԋ{ݡ{Zٍj "qs*(D85k_ʙ\;c⼽AB"  3G"rtProaռ-tZS٨W̸N1_oͯŞb"c30|4?W?RЉb֕3=neVaVd+i_6IY2|Yt3?EpR)Wh/>̌Lu0;)Ͽt/ϝ,*E$ߣB&yҲ#U0L/ʳ]86~adsL~ 04̯=x'jm+ Vr4.]Ts:OdeNI0voGZZC*xцJf4ЦvJf/Tq" ? Fo]#9+UO"?XѡkEbB92t}9Ay֍V x-V4gE|pztS2N%Z6]WcB39Z`6U= {tTztnjM0 Nr\Xpp6De){{*~ͼ&Kw1sd pok\ PKH'q,Bt>uB@ʲsU3A?:Hܙ0t{0YVDʱ40i* Y%s x.;)u=thqn3 u_0޹09!hRBwLu2Vc:L$me f YBDDVS'ň y~_`䀛U$=P8; DZ4Ҝ&7v뭸 -2 !Qp8ma8›zqj=4pIvGR5Z GNFmr>͐dsdEN4+jι8ON4eV kXm3 Ö* #= ze.e-)%#$uB⚐U QJ_Z(Yop5=wA4疅U, Ù!S6PvK'!! ýz/brHs+&6 3mHKHJN;pUμ2k:dJRP^p5.چœ"qq4]_k5ǟ{  K"O]!A:d9>1}|$Τ_xx4<YTB%=};b0E@H}zSvN&?qҴ3ԁ tQ?A|U''xT+ȝ 7{KiI?U>"Y⠟"E{֘h $ocU܍ۜU `*aN2B83  [x)%mf&~^O:wbMFtknz;_k eF_%j9o=qjo C}\妚#Tf zGT6ZɃv|՝zM*:)pYDp|P:/+ikS%+WiO `F<>r?OQ9ha]O/ʮţerBuURƒ=Z_Nz/U q[!v<-ꑸMSجa*B+ˌzF8mQ{MkHY"r*x..$T3dҶ3,EEtWyaƀhʁ\Njmc`>g_4H_僁4&iWYf}Ax^JuHf5GU%녪Vf.q[`( ߿N)E`/CL>$#-GbA@]kaxNvRR:<1=E(r;˦T#T>^ _FDj{0+QYOn I#OpaM/ɉeqYv({0"Cw贃]k9-rj+;0AlqD>")IO#HԿ^b\6bsTjdoT̔JT˿%:׉k> I4vry@τvI, 6۳$nJfN=tvjjs+ R;čUz~Rbc,ב*zbeub. ZJ;R2B7 R#/.D-FЏ٢GK=Nu2&{ N@=(gp:Ȼ#OKەwk"_$A!vN[~PQ[D9d$u~ZOKb{/f!8-{.ZX( :{5kw`|JO恶#FZ͈p)Z`đ _'>yh+~(sSΏQH &!NѢu<ȯp\; \n,Utiިa|4C}yj cƨjvg"> ǨiUJ ť?{>۷[Ch"TbQLi -]ʩ\jU3#f/8vOhp}8:h [Vq]aOWnEg9@f7HZB*X ٭dao|*FPlZߦќT\|MЂ]=z|i5Q%NOY'C$(t5Z#nvZ>I;;hG!xR2LK+{$a ᡏp.hk٣.TyU p+$%nj<縔-Ygkቀ` .kfB)΍q딫3?jxhm+)FV됶JI؉R{.D%cd--آAoԄ9Ha>l`Av<*bסFbj! Is qyB֜7ئ r#j ,[%:0qšNoz""?~a$Tjтf;7&bY㳴cF` ykM ebaK&0C"Bh `SV2VxBƫeK5`;6E)gg ᖟ 2BQՋG p=!^WrM@,Йf't,Sp++"a ^`h}XNygR JQ23@[Tˌ+FPX|b}vYUzCqp`s<{̤ ya80>Te|[8bg -i^_51w,:]P@8g52m+ Up:NSgք\-b=bSz1Iih'A1't-^-4Phߏ@.]< _M|VfN MJ^D8F諄2 & 06/?%*` 幝A_D9[t݉ 4]f#7.`uj67@"~YtF/" V u9mQg #]}m8p%.Zcw&,,dFp:9uFri' D lZIlӑ,=4' ɢAkE#@SZ2J!".ɻ$SX^ᄺ͏T;VB.i̧_jLP(mE0U gnZƞz\0 irX۰yP@BL!E{nc{SpJ;,cCL]'(gvF6t//R6 `ؒϏX0@y׽\/^w!3%tVuEs :5z;4.5Su˔Gh@ߘ b>d)})Ňn &69R!eUu-l~mlՂW0L] pw8-?Xe!YY;I wi)d, j}ʿPvBd )r5 9>n ML_|7k>m"]p'aja 9zx)♲Q&BϷ=?4TDJTVy%8T#2@ßF oxO3m.+?F2Ul\CjGfH~9ffT3y\TljÀK^aZ{!;4@h<2YS)Q v{7"SpM8m3!5?~ޞmVtX3M?75v :=Os0!xWTW22ߗD=mm!OEU}N{ oC+"euW2zs-"J?Sh&{>/<4 N~ ]cr[ -X+Airp '$<5O/\5(9Z[](RH\A)Rjf c(4KY=:o(-T|{ p0VhMwjE|Ѩgwsu9V1Ӹ.iq39d~x;Ak)_zNQݲFjX:mVbfɒ1T82a{_;-^܊= =\_z$js8Pc&8n+i}N4U)^_7GHlj`6jG쳯.)A%H4}<:4 iM`!dlƭN4dI1$/ڂY'֜yo@^o<. Vhoƿ^^A; za`p zo6]v{ FPYL\?1)͘<A_Olpa +/euyԧ68zpOf(kwZ%Rqr>6wjL2 ~9"j g_[7/C+퍅o+5_'^7 [Z(B^8tmr]kh"NTwΌ)N( *ÚEol &'|S$f37x6-,,)ՖjCUź/ZJy*I sxݻ" '#s8!-y=c[vp My6Mkx #*U2cPBYNp8^Y8>M i,5/%¾,NO??m|"Ϋ* '^Ig}jUR.\('fq֙t ZnjܤĢ)"L % 4#yB LW+;81:wrHQSCl9LW3T=I̗ϑHz-bxBQx wu6b@ϻrm zq}:AlG9#!vgGM[GV" J<J7J a>yrjeRN>A(cn\+J@aI<$\['%ZwN+O24mGPF7ʹ%XOr*\˘㦍4|Π͜eEVd njPfwE<~mI9D7^0_ IZv Q@'ghYyb*hB2ST-B#Ia)Q5!{D[泅oY\B5 ްBv+zԏvSp񢐄⇎lt6|7ג}jf%Xng[es )g2&In毒T8+e_UX~Ԭ~ΉAY3ad͏eF}%Hxi'4Ȫzcz~,e ,9&{% bWiv'd݆ _,/5B-Aj]" o,X/nT,*`Ud?_#i]B9f\uKnD򰗳9I{Rk3D&qJ!%Q <>#%P;?''$K~b(4+&koN-h]p 4"5a #0]$_b kE`&Y?' D}to|}3#Z~6fIv dp~; SYb S 31h#1D9šmShېS̿pV] c*%am-xjY)oDd(!ZFCv}%ƫC]fTOEÊpVcWl=Ln!5IO=AFof䐊KI}NF_+nӼL ѯkm2FEk"ǒE4@PI\M=TV}26qM-% ;hw P<)p5 \{b?ﮏ;hUw/JsApfCa!4*7͜:D7א4%r`%9/?NڪE/V_r;M!APNeh>6g(~cAlVa0?nY᳑>Jx|Q( t@YG_ppsd"A%$rG`Wuh=5F20sLWnu~e>nxgo~#6ǎ:yJ)5àyY>^i]Go?oVJ}6>/[gе j4` <S5+_w`o1ӻW@*VjjCd9IvAbUUFۮۥ\4'Hg?3-n:W3m4@T+AgŠGLo2$L|IZ"|pGI7\1FYjfVR#eJ1nǵ N7$z<" yk#DivC]Rh.N&+NYyk\<ۆs@Q'}CƍVi:^LKXx9/ש,Acca(n$f+\wWYTWv5 P#q^b+U#Ydz8hMu彬F bqۀC5v@U0:$`'ZWB G/jٟy(ԓꇕjjoD͘܍aqlw+yޭlF#'Yh'>=>F0H™-3ҵ#*|B`TQHP-KJar&_ڶgN渃EW|%erk!{PdFO3+oGO2L+(0ycffmѲ(g#QZ+Z3oڭj1|O'h}$.tg&zxG>p&^0[SWQu`AëW U d ة5Q,.~WFW;b|-YAG(֚:Mc\ȳA'+eSLiœ`Y>r `R ~ ӵs E0hL.tČ6|-RmلNPʏv_ΉOt']T/cJƼ E˓woXLI0EƔװ'Ј+I҇+d`Q]+ 5$:C 1щZf 䠽=)c'ܩ4y/-Zԛ>1x ~q͉R-@J]U[+/b5ip[4vχFƂ(@|- gu9D33ڂs$L;r (X+;498N^ٵr3< LǺeI\JhMp<p(:}Pam!2]K>ӹs$ꝇfV~J*W+7}408y;}:@+JXPM<|$,[󁜺ʻpnd+fB?g> mlq8E4 1QEɖ ׿n3J:w pnj3m+9 (Mb:vQ!J ~#`1D_\7ᅌN0O(9(:q&7ܢ&($? NQ 1(>3sQ17T8м%0y>}rJŏ:s7}Tx jQj,*by#4DNZ(^#Z]gՁSe{ o_nalūmgvRԪ&* 5{ƙ2T^ay3[ 5J UeFz^9<%g\U:-y͉tzl>k>JL| tк e#zzvVAA.jzI KhqgP{x&AAm_}/VkQm);` Lex}gt4#*gB.c95s%Z@[`<ްSR?hzN$AqXҎ#𩪸\'ˑ/1Y+2{J:.#ث50'ːs$̷URKniC@D vA%ΉaT3 7M8kwd7̓hoz0E 4 KFvM at)K\8 F0Ld#ym&`&aKgYjTj ETj]IvqPz:P8!]wuW!xkޖCC5!Д6Ľ\N῍Y?_oQ >%exQ겛'ߖ'̡Q|ƭdqyb߱l׫b@(H={@Jd#،dRcy<#K\[&\^ L%.\@@`qoo.^&G~ӡ׭8ްKI.JCW<^8Ҫ Wf"L^{ϘXef:ndz&"P#,sMܤ ͭU==!=ɿ46=)rr'G,ƑyyN^D畊gH@Vu)D웁_xB8c>)6m\;nתsa&gs 0oڌqD4JYxٽ=:p_F%GлGꉗymvG6NjIFp<͡ ~\2U +4vt'| $S1O-J_aT'c1] p atT>Vgr=;2 !_3Gʫ׹<4xwMnQHAȣ g NrvZNtG(&c?JMa#8強pM6X5+#'sidʀ ǮGnMfd ѭl(m_m*;ӟ ݩiHZ<>]MA9*?Ʃ1ة FJt6MZKjZ&NE@ 6RXő6NVb.u9@4*^UkF"x{@A -0ߣ¿4 b| Cd}b5 nl Ds$FՉ[D xA0-)b1Uʉ%}PȬ'cpu^$oEaQgGUwv{S"5SȺS0NHô/Z2]+(R|NIi^0 ޹PC,$rۚBۜT?!Z{̫2 O/<\j}r1ϛR{z}WH_N,:d(^FBg}V޻9D7u,Z{d,o/6oHn/'_fwZ&0XRHFy~7=Ăb;>4*2RW~ϴQtaЌc!f:d9N2'Q^~zۃ873B!:m?YDs^x=5''V@ 4 awضm"# G+ܩQ]ڄJPˆq!+i!$<=NZ  qF݂C"8,r݆pIOx#mRͰ& )J80 _}_9*o" G*rRP^8y;T0T./sN 1ʏpZv!f-ڿe  !^ecY˵Cِ^a(jlA![ٮ4Ru޺h4;[ &LYȗ)/2Op~ِr ٹqOx$ow5u9( MH-2'93};I ҥ#LW6z &1E!syaty3*,af0[?XNZ3+h,h.\SIA GSI4?zGd@ێq6dǟc^;O,th1os=2n(l*"Y][D2#uyL=mTvv \(E})++dnBQ85T^6R>Idw]&d8 (p~pz>_auB% | i*[m(vE5̓va<ʜ0,]:dhR1*!ÁH1dXn G>c3x Ad/ܷDH"kE#[!t+ UHn650T~`gؖfyZ°*Nh4 $q'"䆕ҦWS۰J~Pϑ͠kFH0r2 闡%mCe*sZbxW#ij.)jO8R0t"bA<>B(=c.FPf˯Rv]%&'x:%QXQ- 6, "o;B["G}hnzY!l۵P?-$P}wF41l&E57 baDZ)~]$r>Wv1^V(w <[TaZjV:7ug! o̔}0~GZaDYfrpC,1[2:%.Z0Ao f6ջRJu1^TZGjBKrfGcrTA=eQZvIJ6ipgE5S yH>^g? xu垖w+<Ze4 qJDGqaBMB!.ybӶS?=}H*B#aA:K)/{&M"&/+'^~sXZ_i艛adp;$v?ű~TU-RA@A1 tuƓo+BKTTe4P7=<,rپބƤ8{@xBƂWloA!dA*)<>r˓԰'oDطEtswFrQI=TWߕpLAlxCJWNUȄv!DW{6*"~R@ B˝]0ۼ"@W\< +V79hs2C5b9LSWG^ѝ]bJ ϠG:),pWh3Y[ͦ,W%6u&,c:{L_s7pI\JO`3oo7>c4]=ץVy^e44YGǁKu o&EypM3m>T0kvkBA}%-SŁ!~h:Yrtg#xWt}j%دXQo|J@l:d1{\OaV[ X4 )"ê.,3 P ^"d~2FB;bcX17y3U'W{MT(rK尟 84i@KeNygZV{;}~ '!EQGԚ$>.4 R6vRlsM,<7QoC"?G!hd:8F$lR!Kf؎-H(F>d\ tOL )|MZvR~‚Ֆ )_QJQdxph|4߷)(R=ſ9'M| .2(9PZcQ`K^DR%g@ N^taFq*;ir2lpJΪn"zD&L=5+0a|ňDTl^iGs$ =6s!.[ Yqf11*:dz)nAHP7 ]W^bk>2Puzl@;F < 1BD# Z}&?m4`:U! Ґ9/A5|6"H"f&/Q=PS盞UCmڻkyZ ()'|bFmY3ascV69V5=qv9A#iʹwNޑBiD:vĐ&-wXĈ5X`&JW8Tb",Wk}~[&SE柣G_2Ay1,'=2ю5svaֽI}sr[Q34#yJTM1x-K q8+_XFn[$"O꩞oiM0>Ql5],kO*),H**pLTAjjrJxb,q}̜Ɋ@ Pԓ-_ Lm٫Q$POKmu]{?e eؿs7}d;D϶~՗\ꗰ~{oF,<7wD2r/,2P{!JdžfH1`uI:u+?%Y>|G\֦`Pb FoeC#%g]oy]kЎ3CҋVD([k3D\kK$*..Pp+_4Fm'Kib3 qXIbԃ>ٍ8bAziAI-UNGFzPo 7R7Ͽ2TyɊ揔Pis '9[C͠)b[;s %5ȞkDWgIKw=9_>}Μidue"@3yA`+a~Fc`H%3Yv 6RZӀʒT=In12 8Nt8\c: ~"NѽxAq-YBR{c`x72 :gKoNSt4&t;t=E_<SDrE9Bsu\Œf`_|79V _/tѦkX&Cp[s.ASypv-GCW{tX_ 78tʣRvz1ySWXC' (!'VgOYׇXϳӆzR) Dx-tM_QZ``Ugְ"wCGp)>+%e5*ًww}!ܮn '{4=c/qٶ B^ibK Wz{45=i{_aUyB@`Xɇ}9X4v_*(RK.CKl xHXv&3OaPfIGqB%7@xѱNo ЩT@NU"<8',~&GDmQLv!sS`4_Ed SwMns rTDKM1mv#lxjErQ2~]׆D _ݟD k 5ue>SRG4 Rj`&$^YUE9ڬX6pQ(8S8c&Ts|%y\E[3:Y~zGNy[\8ZӨή4;O{QXŤ_*~y?_ruz7'$I ,8eJI /%PFq&/j[,"XTqaJSGwzh\>hЈorߜuUod.Po ӋܪI,l3ҥKRn哫" IX4,ʚcKNט-.v@Th;ş5 ևCr+gqOv  BMKLy p E%ֶ}Gr]eR=Kkar˴f0{ʣ~KR*-LW2;l hh@0]Yx@FUsFc%V˚ଖ%y82rC8tIIص0RM% .Ő1b_vjDP䙿ZS+#IV}KPsw9F,tXm3fU k.JI~̧VĄO,^$CVir&ki<mi024Й>H[g٩ΐvg=yp$}yuCp,:t?mƦu VG C0|Τ{3FFEwRLؖɁL.wNZTx=Ȅ>Xf"B8iS?Z_$b(UDv vva{ffj=Ed%hʯ͜xj}ʒk+d:5`w;%*.!xG"y "Rk{6%}5>\Ks!_$vAѰh{֤vj)c ױ$D#:bB,&<%cu S#&A;U y&^(AӼBJD^zyŴ)oU!.;p;STMoʰR`Tա\`|Q,*A;js+hv`\6K5 =zI }O@ֳuFZ9돆LCP;=ϧjkG͏/{!ב$ۜjs)REB Ҙf| `VM6FfƸk ]ʽVu{l{R|bt.ZKTӀB~LBĮp6heHY6|,]['l. l;2;nO)ofYdWxjeԃlGmTxMmDGZ~L8FGݟ;ZbW76>ʵˈUb?vǕVJhGb%%ڴTnYưks* I*$|:?6̆kğ-ҍmY+{3 糭,Ӹ[5}R {ȥ9F \S1%:bvvZU#mWZyrkVYypdpH8TYApA5 Se1G4.(3q[7v}CD;ɿ)eRJčr-{$ Ɂj} EbP%]MMW&"D"yƻ,x䒒Oٶ#Ui"2Son y~B:kp&z7KIؒFܡ']}wymOeg;qHKC5ټь 4zwײ,cԪѯ\Vh/KkJ&&,,OM B G80rj@DB$}~/Qw!׏2 l ω,J!7PuzW|G=w릃*eJŵj:(!-Ni5FI/Y/x`j)`iN!=8M{{(ceL@|pGBԧEăC`&mг~X=$&0v 6)xBr F/[Q}|qMĔ4'ɹ+-y6>QE贴DS_8v--*"GZԷ3κ`+u}gE7c >;k !K3pJ9ME$3B8Y=񢞉960`DSyOzV:_q ^`Y25\wp\?jICtNj}$ƫ1r (x0{[xxq,#/G{یQG(o 1r3M^>p qQ :$K;#Zj#$B"?/}] 2e:g^K[>`L.ke?VP u; & z$qA/V; \jװZ_?D:\ec|EghT{/ c,;Y2-yjC4 A>Ϝ1T gi!pNUN5THĔ nMHR޾ wUyE d+v>3~|K^,&}E(G1iM})KZӤ/+kPm](f[lSO@"Y;o|/!R1( yRb R1! WaVF([Xsd2;L [E.TczH@>ѧo@W(X@2JϤYK &4;E2Ӥ+f zK=JlO# Z횴l ܆|$ ^Iv`!$wHA=Ąhu]uajV ʈXr%x$Nyn%9K5ϣhJҺ1s vPZ](vΓFU(z s dSn;m a%a=z*_ @rSkBc >.r# :@,N "oRXtzTijqA#'ks?6uAVŽ*Mȃӈ-΅.#*MUlpN9M#a9ڦ>@~8#rGGz".U<-пd?}Jf5Rq8i%5Zktt=m'XrBME3MO/H <ߋLLk[nYj*c[HKYdtnƠQX7ن7Hbw)IʴW ]yB@?3:{ղd}fؘoU" WH}9d(sPBy°̣p`R5(L'fIfjQv:bn_|[4`̧vV,d\PD /l%A&ZLg.ȅhV9}Q㨾2%7lFlSj)fBi. 齩VX EGg"GRD.R`)M_43oz+81aa4 7oP# :rypIqgp݇8ڂTz`o \E (8Fvn#M5PJa4p7(CSvAE_ȍH7KÎ_>=0`AVf{p93ht>sBj9/kM0LcZ#H>hW짍sihP}=ɨDO2zaɕb)}F]NVwo!ʅN^/YSp~ sV#X Uq5p";2ĕnIťrSM Ƌd!RNKHss=Y2rk}^~B8Vz7djt.WWϪ;Ͷ۞ZĬ θn spFe ?*)-GZކ9E{X,5E07f=c3sa<ij OᡖzT%] 0) wwWE _8P֩Q4a{6,g^c:<[C8Vh, s>ë V 180wNayU fBعזq?3,JS7X\9LLgbZMhɿIƅNE: ɵ1J)DatZfPG,7su_M0,uYG T tu; K0O>׻:iU!e2QDq4}.uא|K# MəᆻuP6R_PLҞE#Ċ!T=[>Rj|!UsoEvûѷ_(&! NJ# @xY~8YRF`6R$m;>u=!ƾtKW[M?rQp1_9b-P&2A[N,K| JœkxRǔѵ/RkG7IoT 5Cc}VeN†f䆆#Fk9822?gMCgX)C;@Z<'j*{b^C^bǍly\4:8vU4t!,R wz0}N C{!d%uAqw:~pK @`]Yp`a&(=s,?X[~f<VJ3 \ҹÆAD{<{~KrPe۸=JmߒzPW'70Z98A+{:pH{C3r]`i`a'/rR3Mg8?#1l{5َr$ A%ciԖisLt:MY896}׎۝1|~OłWsUa'pXPquٙ KDX2e#O d]KG"@%I{Do waMx #>[IV&G {S˧[% lƩE"C߶~r6E$\kaO,jDZ̒-I>ÕRuYU4yK!BScInXb9^_ۼ_^a7>(W!!;A+y|484W CUhN{u y78(P8%6A/C ;V@w؀Or6"96"G㑛bf637oCSs,XkY+[ؑYM0>!3-M-ϑx ^Hͫz+ΜIbD˺&Ϣ!֭E_݌9uԺYMo7sgT@/c.ߴJ! DB; "ẈTaxfgl,ժ^! K/!=ږDB Cjl/ѪԡBγ[tk +b ;/0%i焌mz`;Sjs %'S\%xP~n?kfSu+<}^`Cu$ҙnߧ鉘t(&㸟;lCp!o"_(g21 [J Cu.8i>`iNb% G{ G_faq نg$Í/jah QxVW#y7 b,GQ@U`͊&p/Kh y[:aYʡL]N9U12m ;M{D?g-vTTl1Oa"<-C6*@RO>q頓:a-_ڢUzH%FhƬj:,U&m-Zyzgi 7L8}[?8'3^6/o=F0??r;Fц8gH5Ieu{r<$|@Svѧۚ0U?T[x& hd\Q9vFbQ Pq#ܽ=qaHeQ}QA$߷aWU!R`aߐtmԯtO6HJU3vvU*XUO%F(j踓ZR]Sa:qZ%='a nӒJsq]SLhG [ūKg<>>H&qy kQhVdUYbA.zY|`%nr= N0/#2S449v-V§;Xh16m/}Qsqb~.J9C¦ISMj6_u k[i{c jd2WNlSФYk?ww=튦BYxW&hQgxnj :v^"xS{L8!Gb7hl/Ȗ(8iL츕MfeC7ēAriW%JPCZH9JpdOc JJvHF *HgŴ <$3nȔ {J,BE5z[W|p࢞݊n(#Nߒ%D-'n0 T?%ϻr Wi/p?<5,z_; e=FYq@Ah]nezC!dHêAa)OؤwY,lsm? Z Cy^E[c=)KU*Q;,=fE: X0Hmb\~tHIMQF)NDw7H@J5j;aC/M"LF*6 Yf=6B|8u-4'; #2cY LMr99&c#CN15.6ztYj ni ASDVQ5]7sjoTqg4@f'ݗxftsHeS{Ѻ5KrYo+8:euwY@FIv\=?kgSҁzVdAĘA;ACwijW=,+,6OIz׆7r6= ~{HӍs 4vԐrt>O!9(#Bۇ[h1 J`9da Ef̋SRGԦ@RK/a*|=@mu}d(H ;S&mTO*`D&P'H&g[%qFtxdTԮv׉M sPDhl4] .'o?톌 M0%FP!^Nm )-?-$bzҩd nVgzҫ6ۊ6v՛ղ#CJ}46Ru&J2#1.N@!zȪ ~=_1 st#'kD;7ZptEM>'h(0F1zϊGQicg$vaD8W;D1.(r׽x4C'IRmCl[<;3 W JK]T=g*)mϖ̥/RxS`1XԦY)5X]ߥ/CLN.tZ403 (8Ǝ'$}KGE0>@!*1<|X+;)ke2-i@QGSJq(i k`X{ㇻW^: p^''k\c9K2cWY&_#y.dmY[^& /:0< YkjqpL'4yYj){MnV.#18<A J|fڛ;/4dg؆ꢜIIe$y1T}Vmr(_bO:VyJpت7EpU6%"Ɲ@g/[ b3^>-'!z-2TҡWRDvOxI`Ⱥ1*3#y(yŝڞ1/U!h?REUswrf݋;,8Wk`M'PY*k1b0Q'tU+bv禆fI2p;30e9Tν]}vsv[t|r.~\DI9(zʄ1|nB@gr,{ݡܾصTM,2ؑTkL?P!’$5z]A>R -jPjP^nCk Xl4vZd/Rv-ՏT~4uRk~RՄ(pѽyw/Zh h$P*=;|/o8]` Ug@3F <0ʁnR@;}˿u^5@pVTj:בּՑ\ 1Ő>?rrvAq"0 I:&R'֔~U]iL7VXbmʔfఓ~b)7Hp ^c4(Tu x$u5->5yn}e<l6zm;))w!Bxqont1uSPe$8"2`jz~ų=c]Uə\S ˷m<6ʁ" LwP~Ih_OqIöH'ɅL<}"6g#V9f"%Ka^xm~M5W +8O2::gO._NEQaTDHϗ4yكEt 3qN„A+G=N;{1#>>FqXyuԏjdXD; Z _1 hcPLV\uo?ْܷʉ;D_ˢAJ&hЎ02:y0rZUOhO>{VV1Y4Am!>)m&Kp6 =]<1L DМq&4bU w.Uk/Zv]Qom#pHT8E:)sgah9R_rЈ4d"njo'H 0Y!*׃&:8gÖUO`Lj3߽;;jbu1u5.U)ءX:lssU@vf?}_ϧgP]Ԓ_|5NIƘR q>1U#ǜn%0RZIYk(|ʰbrv?E檒(+Nt'뙝fKj701hϩZ}J;I(*yƷ}&nM:\gVsi5tMrsY!#vZs FY0'&NG/38j޺34+ "VHBMO- їT1<0DO}Yӳ_6tOVȬN{ˊ|6<@}g ǚ {CQj,\G?UDm8lxM!uį4bj{{}rwFWQJ?Q! /UTuQ`Dd&1ԿW9/)I0j8sF!QЙ|=L#pY[ K 啱;?K7^7/ ěWW(9! |LLZ&c g]?qӝ|ʮ$ b긄D(z439ZkwH]7!1.S/ KE=&B244KqZ|(е`1m0 zpw3mh mUm,|6y.o.Ѱ̊k\ f8؝Ò}rTӧZ99]6Ʒ6k.ƪ]);̻w:ê7{L0dӶ2[D@ :vcmg6!cU!o\}Tu೯.Nƥ.)"2%0'*!|<#}.V?n)n ,8ifFG nf2{A$ӆOOOE tåjc@r~ae3`O;Sl<t9O4*\JV *lےEv#^L{1G J{0}Xw{A:U%ڨZ''.< tOЋ `dK˧TV ?~vO6=eae⟏+S/Xmzce) KA0OSʦg#ܳ >J}U&#:/5pԤjDf;Wv=tEb&ChOo7_4@H[ #-q変$!6e^#ǷtM'āN&;"c)|Yk1=Հ%nqT_^Go: Ƥjq{2iY+i8gҳVʋ9:@bfx d YF 哼#cŘh?p]eRXb0!0JͳGKM% kX'M !9cX|s"<<*ƌ!Pqyn:abkh"_yc>l)* c sL/na6G=+,5PJ$ %K׭P}MRғe늖Ev]lui۟c4V|2Daxt)Ijck6;{S" 0,Ekd.փ-+&(zB6 ͗. =s\|{c7Y& 2+췓Ѻ zdMf&H֔ (h" -U|3^ /f5L܅<ݿ!#},K/[%\'T#PrWh XemzCC%҄ ],̚JA(/.&JIG+!4;@GوBu^pRgƾA kj8 Q}:ØNCL#Ȯ )RU&i!-1,mef=??E#`|_h Ei0m4m ƘZޡ"<̺f>|vuy'WX0𰒅[$]GɃuމ*P.BL~ͼ6b閖<|#x%wh1DF$p'iPKzgatGv$ Ӿ~5ОƢ863t#&˪'atYPȜhIJ(1?s &aqw>QruTw>αwqpC.}()љS_"\WЋ5C֌֎8+;ZT:I@7ׇf)(9P* &zkgRss6抒;%8Q `ToOr hm*O5z=M)iMQ}vnC`)zO.5LGBIR^ч@p2?5Ѡ T35ڟUd[2i#FH([)!zL6xwA8i,Uj*|rHlr1ɩoC&HGyk/宍*^ >/O1hNRrnc}SBٰ~RN'7+ꤑ4]&~O8o}=;Oh+ *qn5'bXJ llS e\4UQ`/Г9B<ܒ:l9X1%CDY f=lɇSɸ++ym2MG-㱌ܖNȘZh+?-hXFՐ^I?9@aa)RG3E'?/P&TIP %~oX9?0\DjNr{DF QgI OP&ߙBŒ2w!P YR4C6 Ev[6%<@c=~ ^)e#D79,MiysDj& Y4xƒpQ=+:X+p vV3iun'B/_?4-[$ .L*'0RC.cʔ/ pTҺҮ"N6흾HJi#X>lzWX8ZaX' `FyQ>0܇\yW%#/b5.tîSC8 [ WI9vyP>l"j($s͋C乱Ã@{W\>&dU`O7qtU;Pڠw6&LM`YiUR43z!`3N{ i&!;ANEpFG]"bbrc5U>6rvM!x6C 49?'xU鬔_0 }(!s $ʷ_!/K5oE}$AҼ; jiI;>XyL:c=n{,BxO@N)cǔ$\(v(i'bJczXS'i}h@:rM; R hX K'}VOCgcݨk߅ZnP;0T ud^deX X83𢡄uiEXJ z[M>XTBᓬK+_10vTn Mgb;W,*B»+.'gc"#xfU&Y>f @`Ƽ4+7".Jߪ%&Uʾ4QHM;8#uRY ]@Zq.y+*yq%ʿ'R][%HP4G N(WHeF;։#r"C.cgcޜԃ+Ud ǚl_~uT@;-Kw7-:Bɗoa+[հNsY.pqU_ jaK0j2:9X Irj MK.H7py|mk7*t`;P)o.E쭴V`=vϲzh{ܹwWɶ5aEFhU/^?@C~8&^F`'j.$ `_/C+[: M`%g(ӧIoUMgy"Y1S  X7Yq z\?q(IڝUGygu(سΖXiax"" KYPN]2ͱ\ }vZ0j:QJa, "хϿ//Iyb^sbΔ[,oeFśVchɶ^٥MZ :'2pvsTX1/B/9T>?9=oLUph٫kiT +"Ŷp)†3b7"ߔ+Dyr)[2ҩW8ET%džb$nLXY4lEӒ4OF*#Uk$s=lh,;7 gqĊM =H?d^{|O~I:Wt")%fcV :-K2z L [ZN7[F_:g)"4dq$O‡,6\m(QLss,47QgO`X0ӖSTrܶ4IAvLFvOV8DK.hjN+59{ (4qߍ_;6~ϮT#IR̀ci5TbA3)~S%Sԋ"FӫD z %&96u!#ko6:P$I+C"i-3/w0:9P"O KA tʋ8{:8&},e12zL2B=YW9dRŴ1bHgrnPzVKXݳ;3DW>>uD#(Hv5ȇOܴPk 1*zOls[ͽ@SMyvy ?9iq'PrU՟ #8:4'T=`}DL^9㑗go@ W&)=ͫ0FHjO$tU^FhI/ɚf4Q#67V[uN#PS {#zUKx?Ә<%l"?ɞ3̪hǞ^0:R8psug^96&Zϓ)˦*/dZiK5O q/dTs<߆X9 `OђfOauF OYC fٸ1οo{+SpA`+ϒldkRƍuS^j4;H*C,Ϗ,S O0TYhh{J6A76Λۊoy! x E!i& 3)Q]PB)p0`1o)3 QXQNoBeت :mVqH5 07ލ69xYA><)\bĹى7bTAd\4Rlwk 0]8_%]Gͪ!ƜĦFѶnZ3ځFؿ ǠvA0}B'DEܖ@58fiL?7WE搣ê~!90[MƵA<Fz "g᜾ߒ=Tg' ^1ೳ PWsmn!Lf/eksY7'_O^-f:fQL}xܕĎgShKB*O,G;GRfǠzCPSgQW8vM"<l َw!-[!7nc !+wr4dbMEK+/ҳ' 8gSJXW /')N8F}D@Ӿ#,^5cwhq8PX'_T,lŨRK4ϑ̅V5, `;(c凚.r<7,D)$^qvv:gw "eu!0"RevMatlLt^# ~&3e mS,ԮolfYE%\tdp{.h7**гw3Kw:7Izځ;_;{z 2VqZfvkyN@s/cxKqQEtV=pꍠ9+ȏ螛/M&HTИ1Z b:_a +OT1q|`+W3Q|u a>f@4gDf{"+UGdj窪i2NژV`fk| H+fNF8{ۮS`Ж/άO:V9Bh֝B\qbW°,nr\eQ3n$+C|BwmAٍuhshDJ,C!6:V#$(w${s[tw*[񍵋@{\4ii7ila;t7h5FdS#dxFM. +vm0j-8QAwxNjDhdʱ0k\~E'CSF3t?>Pc囍d3aU=Stc)$̕c11]#;SہZ ׎AêMV] HU2,p@ͣck_M`4xkILceDw*s!p]pOd&Eb~*sHxW_J<5d줖 ЏiKzSoc7f.ࣷͥqZe;Vth!0ً/ӆe0]V '!\Hp_=Xڥ&rGt RXJF_{,Eˌ/DH1$CkDF΋OYm fVsr- J`mÙS]ڮE2Ey k3'+l'a+y ,{w-Jm5u_86GMJ#-0ȟe 孢ƅ@ӥ(I|xaȊI,Aǥ;hr׋(_k誱R{ ?]h!_b9\ H9LFi!imuy^kuMzg ` Z:E"9ٛ ^vc3%߮dFZˤQRjzT&"\RnDR#2S/W!3e.4q{phUb1w|JTU Dt\4+:!&lfJVX \^T̕4y=[2#A!@&b9e5lsH^.h:zq^Rռ_ZܾENVB4=1CXlۊmIqp 6hw 84N& kqG#r;t֜M){g> ^G*~kpYmгGI 5f]hvK| DߚTPR1t>,9?M{A$ӹjd{_ t$6zOHA^Pke88kqJTOWL ~ kej>'Jr"TUWA ,pKѫ2-^/H+^Spm}^MmJVف$bPEmebk

`#FNMol%{KsX%p?:9R)3MNIeuC.A!̢+m&1d[A&V:8.d2H΁PPn[?"<P:0CqŌB讍?-ޮH"bxzeI"!(w1˱TIG~kj~-o/URp{wrc)?9Bio8a;[Yqz )/헀:a#XX}".WVl|\rﯙ"犤1 Z1 ogSv>WVT>C9؃J>@9 3* R_٭.s;c42HlvQ2gяa0vm` Odd^ U xzRB}U`e-Ɖ:&m='n%PͰ<ľBёϣ?ӇKy6V CRmlF=VEf4r gPyBFBvIt eLCOn8̼ +@WhβבߛH|TD.4B&$~>o\Br&vI 0iNSkEr17fk6ںB&9J<9-e&ZF&_PCo`r[YJ/f4c <']b4v+_NǂO>:,Yp foΜ?֭@ASہA\R( `Ysy_hp2/ԅ5 r9O|[dd^.+si:M1h] dA**tW$фhR8ނLtnv'nߝbO)ebr&-Ũah+]+OwUy hD9) 7vK6K#:;`R}.W@($WLnfz,_lӃ}bh' U/9H H-6ݗI>cڃ r2>fk%Dr"$󮗴PYh~\{/ݥʞ\lԧWĻqc9SaKVd%^Gϳ^TdSa*'5K؞:^AOzSGyP&]d|ܘ+oOj $:i#r!G\jkp=^ɕ s:ma`&NK9 ;z؃"Bod/K~,鮲F84J-jCs׺QDWųB= T4rpݲ@ A'*]>~@a0YYXYԸf%~ 8xjF z~HǠ4|]*2YALѩx0H!7$IAy[ NIM3lk?UD˗&e}"b뾀Ltpxt#svȾzkV'F~Aѕic O}C9omw?$C$bЌ|IZ_Q2hdzNiYV3')\xd+ K.EpiOrj͝JSBd7ik^JwNF]a[ntwhvfVd&ʮmz M[b(j+X3V4=e5 |>.dS7. R&S#}SN`I>FNp.Ԩ(. WQ)![G~JǮ<$r`X!)DqH)h(O_v\B$!|lh+"-h䙌_-2K(g y Q!m(9`9T tgvdk'ςiWI(5bLl/N)d*R?Caf/Ʌ<`Vf@kã㊖K]䄾n٨ 3LɁ{E9[9Qi[nީ~fXH|"~J 4[ :4͔+Z:yn^M?Gy{d "U7UߧG(96l^~4ulwbV8Z[Q~fmu:6n{{8Uw ֎jXb49r=~<v,@/sÿy3siyRAu`k3Bᬐf>qCX0ö/ ]7}_f 0e!Q\5,c-H/XIOj<|12TZLWN=}uYMeS戔P:'&n"&+=#,n/Ȓr]u++4ăUN5UP(RFW.D&H=ǠfLSFA*ut!+q% Lё|&&x$Ej+Kq{)s|B2Qhh0z=Cb}щ/='*&Ĵ C0igAK_HUîi~kԏyβ&9#dL7sW);R0BR@k KDfIe3fА21YJ]]ll)xU7-E}B^ ׯe "s-clfwrB i76g$ q{AFsOYֻZ#d`A*j[ 9ȕ]/6kykMqO,iy5x"gLlcb!dB/A2Ҹ0d'%/H S}~k$|Qslb@O;5S,y#?Ka'(t?2p`xb/BBz~@F"@];6w_#$њ < ddr8s gl7jWl%D :NӼs?t/φ=yUIf*ĭow^k04ER\D^TI -0/.c@~.Us^kE9d}-|@<}G_z&2UEΘE:ͤ(N9w.qMi ŋ 2 3pKKLܬ2FgvH3W٬yŋH#MhRWa u `G*Ul z!մ'U K!'0DC[7`nlE:2>6,PƝ5Ed#Dqb=*SYx4s[ڞ;-uׅmj&DusغJkȸ@1ӶT~{WosglSVER5O |z7j&T'tj_G*MNALSP! $`<^;Ģ5I :|crע=T+#?dBds!u2ɐt(u0u<$z6}Y/uI;@fm4I}lI&݁Mo C-C*fdJA(iAQ(UZx\B~o.ҳF0g LT x=*Ntu r]B \TމdJa鳰.फ़#Ʃ#Ztδ1ޑaaMӟi.zFysQ$f.ix#Z 7b%>*i 0_a|$L]]Thdi "[rK0nh7Üy0#{U""uA웟!GEuQtIS_wpj>7]F7t@},Іs҂"8np;|dq#w◜XHwx䰥jm]ڛL5umW ~0gؾvKM:!1oL*4Ԩ.Ӓ<<&XRg+|V~uJ5#;TTUMzqް X5M;s__U7 KCKJ֘ E0$0MB~pMECkV0KE䧓IzGGY.ڞȵ^|7q^CW{sL!3k *Wح{w`!KQ]CA‹6H06G_Wa5et :wqT `0$mrE{P8Ǔ (\i=XU"TZL{TցٮʄR!wB-8!oeiYM.lMhؖf(6Ul $M2\< k?|k~g\˕Op_zl}P`DĎ !.sݞ3z'{ʅmu݊:czCNct<w-^bIΒ_$>sE,ѐyE:ka.yL`}}` smA0/#D1_rځB@M>?H:*B.i{R8vVׂ-GP0@Oը3!LlᑙI •x $X`Qm ERPv.'rK;!sFiX*!U'{;;qڙ7\49|UJRVlUG <^5yE>8 6><:D`VI'A&KStʟFJ,wm<{NuڪUko*oΆ;U4{ٓPBCh_2>wNENgjD?@ VX xZ["Aڼ(%/zp1cDyj0i-6*B[~MQXx0 |Qjuu:>(Z&qm 9m-pd.[D/eX OS2MGDj9ô=6Ś/t.O.Z"v& ~+p3{IoHӰ߼jIų%HWR1pPJπ:-Ԭ= "SmE&Y&R?qnL3y;:BTiϓjRut.(m<^RwA$^U%|KA˔ Y_y8ѓ '3hRVW@hئ{BП DoU`vD>3㞈2sWٙXg2^jj/rrMK 4s_9AڲHgQG7֕KƒGc@EbNuS襝No_z+ZM#,skw}oA5uW\pپ$| _џ h`;c,_SN6m7gdeZK0 |S} [#ܜcXv⯚W1 }ETt+ q,HդGLt@=HIUpqv|*f83^;n'HrP:54P|3jCySYi>KX{)$_Ғz@ ~8JGwV֠mnytv޷tQbvTkKa,"[+Z7ꉁ~wCy$Kjm{S4Tϼxh}=:xXF<}He| ;sWI bY4e&Yf2{`LtMu'MRd&a [ 9^Y5/W@T?XgdJa(=h[brxMju4LVwQ}k@3׏,J'-o{wIh^*)v;5L-N{*`;#q~~ \wAa L.mFy!S 1T(`Fu{Fk㾵7R&dX;ZO$yFU^`p6Lm:`$< anO•2f,; ,TK֌WO;Zzs1n_  i_5^,IHKКT'f[qW€c &ݖ##-/zN'@MҢ]_ E ̘`("yp1bqאX%*Ä>Oѹ$͹#ՇV'cײ'#j @䫚*/  su8 ; #ֹs& _ i!+H" C /_iqi{xD>o+AhYyΙ(aR }K8v 0Tu>=I^̒ 4Kl1gJ?ux1 S^;N)r.9̉8Ɋ@̷*g%!jT(>[:֨kXX|޼E"E˅4n[}̻vٖ clI9Nw"W7'8ؘYP;qQ <]q{S5d[[-koX REܕR ~~ l(A2KsNbK+%3^EY7 z s|L4:$t"FNcf[0cG,QWd1 zZbvkB(]`xj?husJ+v'!~ђ(ED$>az`?R$M[n&UHYKL$]ZOڲ?bfݏ2 R =PjA.RN}?LFv\"w8@$N29N!N(yFfoiON^9Z7] .t DY$L9ccς0 ]᱘4xpTchCat/ zkEeO.L/J-]1b+.oyNT1hOY1 PEQ4(1kGz$UMrAae$TNR:y*YL&jp !4~UqsC%[/Yr"/[n<<{x;LĺDE([;%-Aw^'W2+NOQ1[ T+t ļ+D;6,^lj.WG#AJNwѹ_toxnlwq`1T!~୳ꬼl/g9cv%(7׷Ap=(KrjCnm#g=lOl|YppJb+Jd,y, 7qn:#u/XuKװ>"g D Z`ǃT1jospN4`PU;oi XOno%mB{EZ퇍5pZI< 76c~ox{Kvumt`e#Jl[.N*hmul`*CjBK$0gc7u6#,Wi삇J뤪r5$N44 ?sܫA%D;!i6HM֠CExuA`~@]=<š ]P!TtރYLT]N]#1zƲLEmD C^qmoؔpҘM9 7ʊf={tmgFȚP?[8 Xg[mEYyuרbtd}(p5fci{CwUN&ye\@můaӐH~O+Q!d[vs:+HL?Y㭃K'6tC^1}#Hߔ3`AIuV.w@˓G4g 3$ a`DVs^4ƙ#8Qd0yn?HGHǣ]/nf{ sZwwV3 &lNٻIOnvD[u(ۋjy> aw}FKlOvI'tDv4",t)(f4Tuf5RЪh2k/W#v~3aW!62<Yi+ui ;mXMvvtP5m0Vnx;#=?ZxLFdE^ 1Wp 5xisX^ }ݙ[^!~ C(%;xkeV.wV@^bB! w\u{GEY)z@K r.FCˊ}0nߚU,0&|L3V;`oy ]`5Q]Odl#bsQyS_fe>˿PF<8aJlMF4YiC}##^4SN"c&)!ޙE[ՎX__;R+ &4p,M-r6 D 0^Cug~ V#R5Hy'9P1e"KS{cC8inm3o#%=k1 G{$Rdkmo/~Mx '!)VTs!Z!}6b(Vͨx?!} %9lr/5DCwS_NX%m`6SM\ _:_J[ha^.K۵GP*8&2Mr($R9hdп #nFR[!*#-dLékBool W,}=my,;%ta{ԉD Huo !k[nW"FJ1Je,ٙvL)uh鯑oC7Uېg߁c菆%o9gbP,ó$/t](1zlr&Jj=J: pFo\dG0rŠs/c*|_rX!ɭ%.g? aY]*jO aSi"629sۃ EwW3!?YZ1|=My3vKrS:ח(7+S&+2'ՒZ0`>sC4k*ΕII%3z+̽6zYN4j6;w\?\OoSSn9Iee-;\XݬU>g['pNhZu,Et# +Ⴏ|g+b)gb6ja'/*&q[o>" MLFJӔ!&a،X?4oC ч0.~]ʡ8]ߞ k0?8yg=/v9VOA~V1E~|_ߣ7Q&{` g%hl8P `f26Z,bϞ;s_Vh;+vE/bB!bK ?L6GI]g1n0@Plkx7he1n; yp'%)(tfޯ`D{ Yt bM+*q I xi8JFKP`OT Z!QIO7 站b'GsfEJ 鷖+G\XYWbW7*!Y鶛͏5ȜSp÷ttdk"ƩHl&|%xka!R^SJQ=ÁƔ8(Nw{6d=Rb]?mZޭHRI9v0Lûo'Z \q j/I";+<WF!qecHJ=4 Qv5M5„CP,=݂YRp^6$b>5} I⧹"8S LٜnY29iWa5gYS4T6m̬Rӗ6Lh 19vk^޲&hYJ[_ۊ 5!jR7]5?n$X{A:E_ompNjuFW._uu%BsMC~Vs*H$G[-  \x t- 6>iOeߢúL+K)D!!nI9s< /l]W`$kҝ'z.AϏ1&Bp]ςdeXfzK2м~} ݎNI$WiP2L dL} >|*3|8uļ ɃI.Bߖ'@5YH~U OƠy}6-PV1O语yDRU@ba8z`j PR]eVTuLa'scz>g"ˆ:&0uME`rߓy&&qnAqtoųOHud|4$NޡBcAkwÐq5Ldkeg.xiļꡂ.E~@])*Z**2C% j<:*bS3Zs-9bgl=~5jM%?vsΖ;erq,c`Eo AS A尖m 9s8aLgAFRƈVDХGy)|{r##j::.zfԦZ6X!Sz:z@xkB.iwYNj:(r9;%`Ynz𖹢ߜ6366MHu䑐DS.R_PxKUOW7hXDꠅJϴQ.}knaKK^=G\d\JL'ifE#rs7h鐶 PHwn3潳R UY3PĈrw +X dLleK*Ed VM-q&Wҹ gM IIk1Иz¶КJ%9wro󱽋^h8TLߘx|s-aڻe\Q ڪNZſ)xs0vZr\iKNj^+Gcr7rP2(Gx*-LW̤]Qh"U:X\{6}n,^#vk8>lNv@ }0>? =Vb?[;(Z p6>N^SSADvW=ɏ6Lq3DzA y\"i |'Lijj<<&`WϪj;-D?V1 Ovy:b,e1j!@؅x3Tq!r!Rc)[#&.oZ? "xn[/m4jXj;MRh_Re^Ġy$p-Ab*TxdǶOȯi%HC &b%CkC,W.z潮zIړ+x<,GXZ (Ypg+Q<^\,Z4,: Ne_[ {N&,Xr QC .%Kǟrx]Jې^&% ڷl!ʭ\zVAxcQ3 7G pcդ=[٭O݂kZ%r!<. C-^:(TV?oR<93;tHM[?DEii"wo6%>V/P79 1/:K*'(|.?Bl (*QPr*g݀{LJ=09@TH (s*M~xdJ5FI8_칄yj*~w,NLYvfOkK79&yBtYqE[C@JtpXBPvuZOJK$k拋|/%PT{^do蚯aH!ke 2ДEP7rj]2Vr%X|}RЫ"nZ{yGE-4kkYeYRVF ? 7وF:VNCX➒l\|"$84v8pU%Eom>DlYV)Z vRN))c Z2Z>!S.] PivdR1\Qo~GUt؀KszyƬ^Σ_oM2N4iZ/l84Ǡbo GQj+1^*lpÍN(01Yy>s' RMH`v#ۜ:ZȎ/!w6T :V *l~ԝZc5Uȧt PD'AIv'žD$c(XXѡ3l`Ch}KN%滋1?zyp=Ó~%XR%9Bڞr7zSOʵVU++9հ ir;^ +~aVNǑ>h{s<=8B\zYg+uIr02ĩ]axTK'ȹUw#@MݣB55 G@^ogϕ+γG>7 Qr :aj }vOѝaJ &!i9-hnZmX,p+_zl̠òv;W]<)§v>ajTMޒECeTP_8k!;2n,ljznĻ- |0'/r peM ٸŵNpy~7b %q$s fC•ܹa ve7Og*",H\c6$o1'Žę~sDK{g2sq͠*z_}xC# Qp3$,068a k+ThqUJF!`Bl˻s ?:oO(eTl\Ċ@HԝS7\{D??E?RMy߹ڠ48i_TҫAۋHJ(<Ri:!+:ea#gXS>&5:_Xچǂ=u&c x3HB%\g8&n i($Xj,nb/(qTzSyk儅,"l5K=2qRuq`Xc1‡;6AjM$lɱ($Wn1NJjH *?y3B&wL;sñ?U~{+S%F0ѶAGBʿepc6a  %ghM*c].X4=QjF{BR-E𣗂9M+{{LEtj=lB' X ږg^m%*軋nTho7>V9Ąx~,::*4\ ^3=]E)1Ozda^S"9=3H\3-Mp° e8SUm?b^5ٵA@>`߇a8YoBY:llMm)"ؑqک (d5 9hv7;Ɯ: =0*%l*HLTI࣌o+t3RͲ\='BrFz{l1ǿǷmׇvsŴ  P%3Âno]X0.MI@Gl|:`!'}oFJlnX/`nCMctGCTt~WW!== A@iQm ‰E:]}0SsLдZ?h ]L'6f#c񱚜Ԉi p#H/0mdy eo4TĔ>?}̩d<詳:N4H|Nq>AΖ&X'F(&yl[ |]04%Cw&+M- 5;Ꜷrk떋]?˶gZ [,!G⥗ro&51.[ $Xp~Nr?苄@Lhͽhdb^E$aқP*[9!$EvIm!91T:YW;{z-T:uܨ ioRx=R"Z3PT#4#4 ˼YVN{4 `&W퀅7 Z1SUn /%t/ݴsFP[j..H#1t{c[Nr"Jpy"$6Z(x+se+{nuzjm$3jRi[j4)HE 8 IL1v۽ MP#^n5xc8N* A/ N@@H݌}\Ҏtmচob`%+==cBCW1Q@WboZ X8 oH'`r_i7o |@C 4.uYR*˶o}NXkۊ3HNYYC !lX~18GtȊ"0hPt s!@R ޱ}8z糾ZξjbiePW#%"L~,D¬)N: (*ĵAMX[oDb4DyL2~u_vi \Nbtݞxꇱf`7/8E#Sa:`,ߏ$1\${5%kڱ%<+/ے;Տc?P6Ȩ(¬pPD/\E %;jf02-lvOdC:mkw(w$ۅIK# IV-X'Lso;Qkٵ%ݒں P==nMN,{[ +M.{ Ո")pG%1vd\f,1gk }|/i6RPrq&jr@߇EtpAp}>zlʊҼ36Pl`*F1PF_sl.bo޻H7?(gzӀv9/>@_<1%b^khs$Co:`V9(')a#i2$.{`ƶPD=o¼CIm`SZ? Q ix @Xa,Hqkg32| j[ux9mKkh0|ayB^q}sP#9dF*䮫:$3,!!8r;L8جRpOpBUHYʼ3~Ӛ㟳Iztjˢ3 jfˈ QPڟWw@B>|i9:l[Uq^U'?SwPGDUf91& i;YBEARϵYPE++AǸ(ֿ>K%SܳQ~RÓE Z'̼*,'C&n.2E.'s$TJo1g0Fk_l7L*wq*6-Nd1O6NtGwĥj#h P F#MsEE#*bs hh \z4[߳f:o.1$EXRe*7hshz8ˆج 6!7~) )w7s KފlvӋ T>ŦPv-G7_%4Gf*^m&7T&e*6lv4VxbNOӻU /MVs ӫD{i/Ch("QӭjH>=Ku%x.6%X4MP (Nb`R٠zIVT%@mr"Еz|o /s XWp*QVQ11,4H5NƦ~R.7'q쥚G=358 'b 烨h?OJ6#LRH]w;sjY8iK 1:jӂyUH:YFy4gL=b35 0*HhB=yW5w ~gt15+fgvpt=Ǻ?,-'7V ٫vNX*/N?1b SlI?x%缙fUa2P2DkYw]%zo~,-sގ}*7w&dq"bN@߯/I 3\ަE4R_o<^Ds "{$s2͵FDޣ~{C bSMT'1NoZaX'e O3J,\QE"SWd7{G,-$v~hZ[GDҐXAHݎCЙ0`0RfV 0fw|Mr$$fp& #:DRWF.8\eջ@{H⨗ N108?BCrӑu'2%VɞG{M +19d&z8dDLPE}2tH\'yo( !7I!г5G,tb TY[a7hpKt"褯o:}ʥS4[vI 00i !Ln±Z70 lC<-UldFE `ry*,}֛E>k7~D,@!ı}azb3|Ǹ#iHxdȔy"̿EaC4v<]]jq{'nkyif H&Pd]7h58[&lkH׏@DbV0K$?f9;Z ҽi#e < *2@3]-,:!HAEɂ,eg(xn1:J#}ҫMWfKPjHT>'D'3qWHRVyڄoT0h4L-2I.iOŚS$\[z#]ItcE#\ʾy" ,I,@kpp%=["!bG$ _8S6p,;o&`eb*p-{iٸ j'!Q3 21mjJ!LJ7[>@o;<]·Ϙ3-zRS`:S5LqpôR2*ٸ!aJ[ȭ@Y./P!xF77q=QM 8g/ ZExX[ + \`;.Ka`#1 '*԰Hby9ە_ߗcrMQ/׆d$ǣv5^CJϜw&vtꠕ*&#Ze" WW.P|lLT?oCEӝ$mϡ^GMDVá$Twn!:s(SO_ j `_ kg{gT&}^.|J_hMX72]?͏ wCNn߈+JR@=Tawl.el [B4[+ȋTM6ܳ)6bJ N7K 1rP+iC&&e<BƲ V'qg2p_LCfA|qFW3 ʎ?(I?Pq M*$郰!֎; 3R$oP\>(f92l{Y]1V)$bmU6? };k?i1A~Q&q:]22 S:^呮vT}OQ4D,( NZl"!37Td=UedK$7?HxGߥB-ĤCAc櫡ҷFV~s%ٖ }w7+Ms@ ׹UgOA25#ϧQF`1WI MY,Sy@By* G{EH)jl7)zy7f|X&T0~Iu#MXu7o N3J6_6ݎvhFQf/>RMX4@>I GYJ2<Wس~K9ǎ 6'=9NH7G▸:,#m O4Ej(mI7iUI=Ἴ {E8o5cݞJJrcYdgD܇1C~!zk l- y1:I ?B1QŒ0r~ [Zj<2(ts(x 򦕫]5g*p%iU,eĝ$u2\Ԡd코J()I CGi?"69Uc)XͶIQ5eo՛+U(sKtA+0^y7m>%K1q&cc-H#1~G4qt}:%V8E&P9o(oJmⲣ${z>zRIeK%] Fv gMKjn>Ѡ=A]!4ņ N`6 $Ϻ;=CtlW+u"Xx9_ZynifQ -R WתZ{kYj9C]Pxl–=*ؿONL8J-~m:+л8d# OV䷥WrJ "=DYYN6R0MA-[}-,aaNg}3U uON7dNho1ϕ\e~4ǦOw[*I&4$y'14.{5Θ$875ɌnRʹ WK[ Bէ{@djoJ|v ==~Oe f(mw(rRx؄sՄthxj7o}?D׆4uLpȺ` 5}HC\j6Rr$`]#z(K*C¯jBFmNNLȫfM7 k)W| o |uTnvZ1m&($t\\W*Q!+c mu~X.RDI !ʻdK+,`œH1~gd Gpkb_xBQ#}F0H m+Lw5//Jkf躛#bPF66يiZ^GSA,ZʡrT5CJq,K4zlS =VhMhna:K~[jYf"ه0TдPT̋{ᑀY^ AgHnIrS*S_3ȵy bwp-uv_(W:NѼ[No2(<1ߨ> t(l>1E | J$o8F)ʅ~˷ 8/fCˠIaf iQ%y.qP z ,3o;dXx֨]C ρ!V-O*YIb*|z,lc+fcKQ' +7 ]7pxai1-3DK׫*gBG9my-kBEUx\.|&"K4dsc1/tf<1* AN!äu@L$mFtZJv`5b)TcCQFOi2fU[AÜn"!Twm޲(::2822Ntg2줚x7qߩóGT @$X2)Z6~|X$= }M /xD@2=_r $4 R2EYSh ͪ,JEJ'L/AiGXb w-Oo%uB @V y\ު L[D{l3ՠ04wT 4v\IQ2biR5y;fCޢ noN`d _KOVڒ: b)DMm\` qxmrCNg@HLk|4~l z[:@Vݻv),W)Z;b/c_c `%ߑk˔<]cwW͵Un_8S޿F{Fɭ. {޹.JEEH dʠۨp-p>7#^+F|CZtZzGP|63/l?l0ЩZbHT L\P=twRA"X|A{-xW D":v'6#*df'V#՛9 mpi+":l; %T6ajŽ8s4al}L$.QuޒW❕Yj`pldtzGB(q Io8#͞iRwwbU1ce#f=WEt`!|4MS&$'Mfy##X o婻'"N ê԰b*YmL3H xwy&@}|K@2*? UFUc)s|Şk{r6L_!dk""$# f=˺[{a9@J>{Dn)]!Q 1ٹb%1#,c׺~g麂%l2S-Ex@ V*́̓yl AZW?I4#۬G^ $ԬQ7P\t1}H"pYE8 F,Б^JSۥ t./w7 V(g+t-*Qh_&(JjXRFz8pYH=f8LUOd007H*Ot&C;{=#XWwԮфө~ j0Q (Y!uXL5ꑙT"(= (,%N9LHY`}|(y#2>~yARJ*?/3>h Z}?w:y>0rƸ/׏iDhzwsKQxNykn~EBT9+2<h@ v-(PаiE#*L"JܥrTS`-H9;: CB}TS UB*"R}NAfȦw'!_Iό#執Nb&o%8C+ǣ# %Pn+WT+̉׶yB;RʑcZc-xsĪhl @ɓ:662/:)J@捩d<QѰ*by76|`~p`Z'm9H  =O[Bǎ{#Q`|-14-l78a$VLu#+Q kTS^'n"C,6:F9%p +=5n7A5Œ/Fg%#lG6'!|u3cϸ_0 X|@{CoH@!TAdFIB?/$e0m~(x4$YUYja9'|HHyPɼjPQqې%Pq??+؈\+wK!Og2v]>^4<ꪕO \<7.6,4l/|{}K3:4.X ;LF-cm-)A,TFjt( ^wyII#> IRpf>@FQJ +據$2NSS2ThY^]ؼPE8+17Hvj?X*E,Wh甹A|\?āt\sN Tf(E1UáMrڮ1t]"uN'T# (œh[1; 0$GvgNwDu5k.׍gGˆ;eG1Cb[ p(8AK'.6Lb=<] #q9vCOo+]~*"ko>|XLcWDn >EA5G~vߺ-1828#O?N.-;[|n{CԤ].(1C 6;f$˞IOhDXX{Ѳ?=pwIxRzS';KӗTԂ؛ lȼĸĵS!\=Ռv׮`% "S|7묱$McUWK`&N#z'؇wI;NA8)m 8Cr{]=`6OgbA+]#$кgn/](|+Np@ƒim~|vT_Uy:A\ NaΤrFQa} \rhó^LNW".6'0 2 N a-^ p@J8\y0ʺ Y/!Ӌ=J+:; |26 ާ+1q m6/BɹE<ܿ&`K!zBٗ6f 'qIbQjxca *Y4cJlG45K?g)oNH)\^`8/ufwh%n~,T@%\/rqcv}/FI|e/[( IõUTT* `گ@Y X!!/ : yOrhfq5ƌ<&~D.A'^„ۗGhv\Xo}h6ۗ)L4 hov07 v7P;_ۂh yh&ZTr^{ ^e3y)ciLE*Z>\\&ڐlB>i>Ay^ΥW?$3z`0{(`g/$G:Eӿ\g>Ud-!MmwY>:< HeQwnXk#GK\xYZd~@ 'Y UP%EOB3~*ftzٜ./(Ykz M.vDYF f?4ю N`~2*mU(D/^y( {3/̀kpQ4[1KK#_Pꪇ(ݵ༂|p&+d}Wp~ 9S/([Xí@B}W|2 Ϥ+825I }T *EvuZvTv;PlJNm _,QD2F-^bQԎ]M4ݖ6,:$rڧBYkrRJLf=|1gg!1u^~xX ?H/q[ T}Rq#T~ r q]e8ք|`_4mxJ1,{DKk :+-' \<&5lss@@P-_WG "2L74>^=uY?2bKvw`'\:=σl&+,„x>-us}'Q0FH:z8K@g?bTʫme^ ə7zE9HSֿ 5T(nC26+W1Lth~QۢTb -&+,312LU:i}QW񨌽2{;]#B{$|Jŏ˴\y$uY Djy@$M#D.N5JZ aOW Pl\!w*h e;1 g%Tcj[\lCBpY\e8-$49}2u-lDghy^X$s48APt{w((6vۈBw8opbhgT,Yygr f5#vUv2VyPq-97y1lziqxyIZ]z|N1*"2J [*v+63saz941٧wM-A >_.gL(/-?-򯸊 F9@Ιm:ʧEM>.Qw%zY9$xF}rwgǒ|ܩ0m [B \ PSg8w5wFG Eഭf2CbE1_Ya:=e3* %Dp;6(66zbHUvF O>ҩIuΐHO/pi(<qoBTyxw@W+FzG$k|!6l%*L`L OqqwF!6\ƽ6y½!u[~X;)G _06}>`G7&t/d,j}^'ilEwjLIgffp#ʊ:Z?)=1J.:W2-k2`V(%Ij6}dwJ/BW|ڻAȆF]; VN|Mt8eXL#RCuK?heci(U/휆N_hs_,mc;Ƿ_+3!ܿn' C_BȮ X$KTV%K; /'?FjOe MSquNx 7[_Mzg"XP\&Ze,ܒMN "7N9,3(}49]܊w&&^<IRCi'c4ݹ,Җqu]/%PCNDIO1ۼ"oo?> P\mF*ZXQwȴ)^|`;,_.)D_+nZ9|)­:%-0}49ԬWn3ة5%OkYnӐȢUD mspŸ=.yEcHHB2 m c~l&my}IQ*F`SRӕɖ"իbl`Lѱw*sa0a#RZ-ݱR'M RZA ggH(]NJF ӥȫixcGc[~qW(Zd3.Kz Zh.ҁ%YI"wg#SSdmjE;gM7f?,aqQW(Y!7⊜l.UAc0u︔ i8f^p'3֍tBxZ">87 Q"q7~at%O6rmnՇhEdMS^T"?D KSz䉺ovO^M qtFK f.\p^.}Q I4=6r+`‰ihu{ܕN$J ě6Mtte%\fź`#wjcVc+b^yyn-I°h_hl#|vZ2 !8DxamfTVyEAs϶pyu;7*؏{2/9eP襛KQ~`SẗRAۍ"Wc-rǂw!+4mnb\Ze㯔 Mn1|wFP6 F2"bo>d,=_#7tb^I"1gwj@ (TMRA\ uJԒי*-%ƙ1^#G+׌?z> >sNHU9SDȢ "}b()uf)49^xIEH3wV Q*{cBGl2\ʓ'H)"S b{\e_~]6NmS3Sgev`:-*IN4꿑 piꯒ#P{׍ܨa?>]|oD9 !O#T9roq EjHϞxXG*c!W߅~X³-C5 | a4+pF)Ws`@lIw9UN(!V7CQM XcI{<$.6^$ܲgsi'.F~4Cq1R?h3QrL)Yو-0S)a `2w@vZrLn|+D87a.L[yn2RdJYQ޹_6A&K_$׭s:tZy昣^@O'& e3,jbnFGpkFG(~:zv&3f"$*bF_)G Vj+.@ٹ!֢n*ڐKn[?砇(Y.ܤHQHKT9U$9(j({YYvU**&g|H;0m+wSr4k=O1BG̎@pb:a4kWɲQ`hM/!m\ v$f:W+ KK+hsjC-_|E{u sÁ|?%'nGQkFy#Zbz#-\O@Sny(bʺq\bnۈ)Yqԧ>8}舎iB#PQgD1M;P[@?{E!^$PT:OBnvl $nHR X'i89o/l5HJ0Um|gf'񷗪3& Ձ2}F,ITyq}+? wPhO{%ӥGo[ ]4|hً(CLvM𷶘Y6> ݶ(a&mI,8<Zc..gBPgiOП?, sy6`|X;K?7Mu/Z k|3YDq[4|Λ*uoW욜f?R WJES|OFcjDxv֫-y&)]c~OL@ te!ukGۇ|AHoǪS kzQoO `X,f*z$ #?Ҽln q%i᮳yzJ }_s`Ѱ,%m6 k9tcUxD1^5{quɿ:屮zH7ruPEJF TM@DRӝ}ExȾg9m/4>21;"jT' bP*P͘ZyND_|z8Fz>3hJH?i9v-vE/kI2.=jb /"cðm[[m3 C I'R.[#KN P-ECICT7c(s.X4l[y v8{CR&5ҤI6Τ )GZJ37D'ApK~ R)X\ߧ_ؒinAW^D%]ʺ^6QN𾆝mj~3{8e P۪g Go*yi}sG;:`1E%&Z)R4(Oph-}7'ew ','}t*C[-jpA;6@!8'4mv Q@E#Tn`?fƌz]GDế_'{!3ݳh:@WWe`y^E$x ɂbqBGՅV!j\(vM*C Mσq.l!z)Cx~{{}PWRAVc,>=lэK.īPgV >2G 5Pw!DNʯ93x: 5ea&em(Ӱ=Hv;yMTRgoz񸿮f8<;/'X//y>L4Aaka$%B6vN/(䙘Rx#E̐E ^!]"$4-TBX&+w捸2n pgxQ4ˏ붸5eM;`RI%cCc{G%gE8E8N'-3" 6&ftx/I$ގl/yƅV{. U%n #nߑxKT(ٌa)SQlg^R~Łgy¸csCͱe:Img MYW+E-˲"@TCSГ.`=6x_iD Ǎ{!5:BA߅FɽZ2@Z5liI'~2siB;RcjH1HEK*Eý,t!P4\{@{[AC'n-7v9b`4|<ʀH%c_? }vI!ʓښN'W-*;%PD.All[W'9 W1nK谘J<`9:&u~_AF#yaL7UEfZbAz EgPZQ@(P鷙9NQr<n>圙VtSP9YOs:QfDlR`nw5w>nzRe]  uV^[,!_d}b,h/3Fi>K8KxY#YG64ٿU&|3Yt}"#9q#B\>8W$A8Z ( Em =Q|jP\ip¹_QS$W|hEdepv⭏md)K`Duۭ}Mx 4t̩>C-l+uys K`==wf%fm*~S4Š8!³Gw?:8|1p9s <`F(^[~m_.y>oD΂W>]Qlφ$d!$wq* }Ӝ1MXE~Qo.*u&D8|A[Ixm<VjXbNŷ< ^*;5"+3rNh'[PH5q&NR y+BA4^'π|Y.AAЭM | נ/N@kZjV qת:}h3eSq9.!bMB&SϐbaʟFl,6hY4P3Z ރ'ћfgdo׶cEdVd,͙ð#3Y@c> Qj)<~kMWXVX껧*HҬ(4'ߔ/}RWܙ@Ѯy]Z7uYrEyK;I7hKOO}wm 0&Rdxiէ + ߠME絭}ɚkYP89[GQFBЩޅ+>>W g m3"A& b؝"Z1qP"Ji}g<- r8UҜs׽`~(`KO&1[Cw̎:LVېxUE<1tDl[ Grllu V¤ |0^Z!Sz鮁U@/}mիd=[?UY>94.)#{/C `V,A>3TY]?|"Dye92%9z!RKK=IS-۱*|q>YVi&-gϽ*Sa~d[T`' ʻ TQ;Jt0U䚃~=lȫ XcP^WV4wyzjtVQ@^/2| '5;jDFQvr:svf=T0h*,ݩaok]!La#9eOPh![)T ƠD,]~r0E5_KF]^kXV rhɜTN{2^8h~|@7|~][:O)4UNƪVcf6@qOζO׼rc$M^Қ%ls7?ާ G S;T[+ I@^:@nÑ~Sc]\]x*D5cjDXז?${M$:LC8zjoKi~Όz#H݈&O7.R┌^koyŤ`Ɲ;#WG*D Ds1^w Unk#IjPFMn.C?uǤDyjU;E{̂_ג1\YVD_4#o/hDh`,d*gQ\鋊ƘY3*ȩ!CZ {teCBXuj밾9&w_wu[,9 2LфKà`HL^qÆVYFU!9B@,6(:R!I7G1<i)H-q1+#؂Rb&9G;8C%0fejBcd1?3v`͸~c`U,k߻`}0:p+"ʤ;+ӚO$Xee4G+0}hK]&g 1<4 =Qtl%2: r4ViEԕ:,*9q SL x-w8]eP5mr~|}pxe&aLbxwllE^ƭ {wm AEC$ W~k" sDkRR֗Bƴ9xF^X(#dEe@wWF[M998B`#Af*Yjzg!e%Vpi(&Yf-Z@QQs;Z7HFf5FX)S\\Y1ЋZ|9WLh=Wz  /F FA^kyp[o凅T_YKluݶFN̉zf?eJWgTŶ6x5LLZ+Lt&ހz{%o\ Yh7-[0WBnn򷿣W{ו^RTrSy5OG~%꒓6Mݚ7ŭq]l;Df"iHAIsPA p1.?,dayAUyP]s- y_K a+EG/>ˮ9ն|4~5fĿYUCB8U % =DIX` {+ݫZ [?Ry6ܡ$.tm8ne ,È=7 OL< W֠ӌ><m wk&7vh ήV/>ҝqC3J7Eo{|4{H0[of(z^ḅ5vu3aNM}'c\پS^ju RGW2|}G*|v® PnRjO%rH4 9ެgؽ uVE/d.2 {%V7c)/u/UbdߦK.F@Zg}??OqdjE.z @I;<ʽt>h0rWT8,)= ap[+(jN8ƦH܍Y-xlJ!2J;{s,U,kZ*FJ1~wO/W".AzB6]躥P'r79ٻDȕ nL;pS-!'>Mq^ʒ/'by޿\lX~d=e[kfRO_sHm:Q_6̒+=p%cbd"?/'M+(/wc=·s]Rnȋ{#G^Z%R~@w1/DuE#;&uh`bBp).j0*j;ư&#S'K<\(F$3KOlZ1 %E@hSn?Y3&y,9F~eP)!N#m=IUN]kE,&yW22Ei)DNϱK}-`د7؄d_rG͔#ZWѐerBy!` DX*uM(Xb)Q*\̙&6yF(!RVc8A(+AYy:6EhϜ?= -vmLoo+9_Iv >>QîcW5AAjfy`}Y2r*K7ݲeqΤr/tis]l;"xQX: ua6˚{qY7&+G#v(+"{54/=zD**zǵA԰K;)_DUDQޒMNNRfSr\|ddzoi }؇ "hIp-l TfjI}'EX|-3~6΂>+ Oe= hJK0bld"OH@~LO*u`앛9$ޖ}܍^%{wڄq|GS4ŷ.ReNd]SZ(zGޟ_~L:EQ @ eQL1|߆^qȇI}6x*afb-́qVz38g6"hE $E҄5R=#=KZ6y^[Q.8S)h+ :pV:lpc({)P@ }%c_{~ߓB\Bb_|qN=:g"PzA _IjhD~)1Eepw/R&i>[r/AG$u#Y[Mep17ٽVܔF?|N%yFep[NS\*'CMN~Den05guiѦ| EeL`ѕ4QDhwthjmC/e J+a{N|]E+W4dQ v"'jF A 7Rvo{<]޹~p؇Onm=U#t3}o`oŅf zhi^AS.UL T(4rXr9g<@ڹ r.]KHLzZx.Fe& gz%F.;TsO5v0 VF 0,/t'@0]@%mBM;lkC,D/U9;L 륑 Ϙyd9 lP2O|a^v>5#2_,f<f?56J)sʊ raj9Q4EVjQWE=H=$uO]Mr*c\} H gz^ǃx3`zFp%p3/3%*T#"%SYg@Qi.'EHMN#T|z6(,'d67e?졹UѫHf_`MJ&%U>y]_<$y -#?mnz; NIZU7u~ih\6 2._UJ .͢c'w: 3ztn3}d~}Fͭ<B=YJzSYFB Ae󎾋{3b-NbU@w)eD} #xWH7]$ج-O@JJWJtk  KC(uNgmIxs7rWgKbjXؐQRd[7f0K3ZQ?i\C鯷˃?&x`y!Ba,\G0T^>n>pØۺN Wc /O v OD Img|X\.H,瑼RxrW0v_-\p[pj&Щȣؿ{hXڟ(@i xN-dUAXerRQ1.풇 ț ȣ +mCjh91g%b l&b< vg5vA;X_9SH6K Kf'|N=M Kg^ vǵh2X٢7"ҎQRvώ ¬i7{ sGn] qN1/u-fɟ3'-}GKS#[3Fof<w _Ө:ˍuNr_^Xr$_r[bCl$ ,dV`ݸ`L4omX%LiԨ4b"U/l6,x_NqY"w{pu #ejhA`9CgvZk9x|G7CD`7{sΤ@JL;T*t?Lvtu;"i@U00e,N=a|.nS?]MO3! jy2$1"~Ơ0s J>yя;\1-$ '9AUH{J8Ӫ[ о0>=^ 7F Ұx }g=mE+H" CcܙKh\>Sz:ڰ &p1Jq}Ot* DFv3%;Y6ᝂBM ,m|I'd4v@:C&fX R,fhkrTsd?+',K]1ZX T˃>TLij $bZroP7]I_LWwQ=)S[&Z`z>5΅teNtUTN[iIRGHndI⨮b轼X{~䆆 eYYHV'(I7: H)щ@Ă= L>V U$ nρ1~<~oLá`'T2G Q Sƽ$ ?Dc;f< 0&u{J<]!;P;-^Huۚ jqjtLնR*E^qt Ga2«T'3^PsRlp$  jMV%S NVOYddMD CoLxʚgǶ7"yUBj6߾Px@t(mhf 6GG\xTiVrj9vvK{7Xn%44%esHA9" Rzkot_qm^-*hv -XސζUCi~o_ϢűOON3kY$eˣc ;7ogQXFb]myp̊'tSi2O rvݘ֎bgeukPLBF^D)[U8/Dl_(J<_tϢ虓*v`vdc зb!h ehSnEX25z'bGJ$lnȡ~yO=:A,һp C"8Izg3jmaa-}縄BC9s$gPqa1P0 } ";pc%n;LԙoRa1 yp(D=ŋ*pUcX5)Z3S}pK8uSŸ+k۫gEοTw vW^XŨuz|y _ĕ>¼ZO[,8V:P,==Jz)N*%>r+jȺncA^9UJgʩRzp 2YCn%LFo&bc? k[o έ* O5ڷeڈwh1llBm!FS餝W6XAʽ_]8P)hG5?P(NNYl-MB` YdJC .*UA%O2gЂD?20nʆK"7A 4^S%*P2^bUuEۛ,ǀb<l_iR@3i"nR]οg1efɍWT'",Ѯl:49._Kj7@2=6fFpz)Y#AB].FTR G]kO&M[W}* !ޝYRlƈљӧ%W :tTWXRGrY+_F lݍ%ҙ}hӋ;%N+ RKy8XYfm氬6bCݓ̽m@n׏18ZuӔ@^BĴ92kf࠺9:, N~6O#[av uc(>>S#:r. st/PnAlh,>ȫAL'MG3&̋Vf}ɳ"JL"Bzٯf1+ЛgCtcY¨xRь*DLth_zwx k-K rb ;tGwWE CMnD1l4uᘿ`uz!{[hnwD\T,ިxz!bt1z'ؼd"SҶ~iY5@>tג #!]nb.FʹGLsu6?. dk.%0c3Cy7 SF8[EZ_zūϼ6Fݕ.d0pA†c}Lom 8KVd9ߣU܋O W勷C(6Tܪ@UxD پs 5`k?1Ǽ}}0~l *="MLEDzW_)\"Be U)@a`l`(2K+ 1;,ꐋۑ[́\/|VXp#2@l:AEǿ;!*EjQ02 xt1Jt~Cv2#~(AEF瑢B1FBak<|@MSnQYrה {4U'Z`5 .#@q+zPIͳ(q)m`RI9//جTΖA/uRW~/+MMo#5 03= vRO̅J:Kr:fSpm k{Gƀci6dEb"y"NŮSVnK%vOa{d{m}"'vYHkM* i& _.6ȐU*7SeޓU&ߣǙα)+TgjWǓ%޼}4xr:#gTad^*62Tp m9mg(DӔȨ#Ω:\^#Gk:+do-ՑIȳ٬u9y$%IiBݪ[O.H$Oҟv:!Hm:W"V0*C<#5f(%N`ǟ-%"1 z4Ŵ?imnuIqm mгdorz 0O "{@WLU1d.놓`V]xۥ0ߏ sULiGD"W79Rt+OkLȳi6[2At {c/&vj؀*tĮp!Bg?}OKPN{S[-.|jjY\݅39KMgR=s)`xSk 墓SSBj0ЃzuY'蜪FWF&GY[[e_zzLQ/P]Iqx."q=]ջQ8J#3n X b"'V"NE?-+d\S0gY<)J(gf&84 w%cJXatoa4TK `: 4gX4`8+/B^ Ru}*+޻Y"/69hID5?ghk:]7n4)(M.]#yy;,HʼnoϿUw# i2F}Pk_j pd / t=qb#TՅ s;N^2!Hsgp]?(S=Bll'7Y1dlO!Y+F\e|'1$!R9lhWՁt?H]]!T Zޮ82#H&;qyO\/!ϩIX /t?>g*Yp ڗ/mynA†gI(P~C@ſge ^1-t!N^(b;cl !~3y E#]bo"$e@dA8VK^%>C z'gs*.})&?Ϳ_Ii|$g[Qxo(w݂uZ;1> aP2Tnԑ:<ȧUEr$늓 E؋K2,r0Gy.ލ1o25}O},ꨯEb)X?BsٸP nO!8yϮ2MB͚=xS/_:c7ZPvlb\YA$ jddKS-iNX5d02aeQ}3tD[]N9yuaas ddF"wT&͋*O7"q37̣*'z҇|N`|cQc&94nNfԐ`0NFœ .ҸVTM| +ln` ;fߵ/_"e `fK,9*XTOה,9pDj/};7vw?Tqr(g>/{:wDuiwĞ,< pchoC9 S?#y_Lt?Q䘒T-!0~j/'8 LAuOo~Q#'yIA .qu` tb.Վ̻g 3\D_ʿ5A,O{Ksn9j9u^'GFlHؿ#ۖ=pr<XiA X۲F>VCԖ{܌O + yD >ɠoj#-}i%?$7z/*@ěKmD_zy)>"}|ӟaJze´! 5yeOF+ ( QvR|D|fϯ.[ pG5 wX . 0 HfrmQ=TW?j {(BT@zpaȎ*$ZpY}F"r!x75*/EF1>V[m4x2鶩ɥ% .ߓ×(VƯVP'TQ{y_HJO9kEWF~P؁ˊ7k= 7* ٜ( I(&^ɀ;˼ms~#,IqgVB[RZV2jy{iN5qGmR[Oj{`x"kĉz$ } Ux̰TEYg9)܅n̶{$x%O۰LX>W8<(HJ$q+ɩ,E[>vAߝl.%= PG rvsgmchokm! pKI؁k\$4w^B{j0n "+"3,;!-QX4 -߬Zng6c_[*4q-iaSzG2̛l cs1SfTISlwk ӮTOۑ@K[OۆEjBgǣnJ#AwO؛C!xK U)lpt%'@(4 r~lbp @(|UXb±esL?D+ΑR!Egf%7\_3mǸƖ-[n X ݬpLTQ]s-YI˷'Rlj#G0_qRi]d.5*fÏN^޾#ȧ>6HL|0X\Nƾo^)?;ȯODі]R^++豾Qŷ%{(#h18$3 Ҕbr aDukTƖ.Mg!xՔYI$ngKIRi8=5(L X <݂J+Zͧ#vˇVV$v5T!9j"0baVfm[!FjrT9g} {mcYTIlZܢ1\Ov/uŢbd ,MM&.kő92)о5d ?^wLMF-Pߺ "q$S]G*]uإ|DL .VЂVACM^n8QT+%"ng_t*z,=q̵!̇jW!!.G ''TKo1Mp#gCon6|f:i3L𛺮'}-3%n:qTFY_@2-`-MO;)FI{`Ar楾9#ewQJ|Ff)D',ru C3ȿ@Q az7.bXi_ۙ%TF>Ɉ~R&I`3݂4bKżYߓoZ"νyfh UM5BK33S// M D%^+٬L,ǚHJ}.GL}gjC*V]>xl2d-|YrE.>W2_EAC{jixE<[iȇEQRb+@(ٞ}=aZPب`7L3CQ3.uɊ(58mv՚(.g3kpZJE<6MxEyF4ذԈ ݮb5Z4GfnLÙΌҝ=^3GFzrr-T#-M/JAԠ dؔTi(P.|eµVj;_;S0+ZzBnʘU#P&H&`PzX6ីodS|쀰 &ZO0$ո ^wܪ$lo` ]qٺDq6XԪjO HDr."Rq%eYOH M*ҿ p) XXg#Av`r#' /.N&M:=`k2p)QHD&*UP|UЁm1xZjlBWt9Z;V>=Y+6wXw2i1gHǀaUޠyx܇G„g{']nT執.>݉ ,<-8KaV7.Xk`(XS'I@p38R' ˅1QO[G,CT"3R@nH a7gu9*"8 д4 Q@M Aדg܆?hl~GpSd;e;% eNr`Xbo$C 4ǖn|;c'bu2_- nZ1{~)T&z:?^ͅDsxAGi+9Zpo4l V#d3U {sSM pÅ#2egqx1k)\ѮU$U40?ه׌%[뮊ܲ,?4=Qe<.}WKRS*ћգ Qo{C"2T۝_LX!BGyhyW{c/7i_+227|o%s媘nj) ԭWת Eqbfhxr0,5߾Y[$%ߙtc?"B8NFZ\'ߩA)ͦc4w_{ Ĥ~hm,=JJ\QBN[Oc8; h4r<(C\c2'ql ELJmA0{~Y@ |jrht9VhnyK xퟥJEq׫'0$P"cN]=&r?OYo>f69f},@xr h6c6V`ܫlnc }8v)~&| s֔ 괤HɁ&{_6ejcφ~¦e/![Z&; />*55Fi& U'&Isr*IU*Drxɪ $eNdv#ZM㽍c7A8*Dc4=F\ hR6L#C*O֚06b]L4fbFauJiCg17-Q2~KO-c$R VٵVk{xZm0LRT$&D%S'C8"'TDpJ=a'Vn>'ﲺtŞ"TB8 ,񩢶40ﶊL@ۆ>ú2l 軿K6B_ i}/@P5:0cc|k{HlRDBlw3-ڔཱུ 4y%kc>)`}[m6Rީ"^rbwb f`Go6G},aXwwv eBNѶVnmuz ,rQ>V)/+րDڼ 7 :6 UYN !z+90,nzdžQ[;M8X‘^) [o3&75W !Q*i7Q<`bjCCg!|^OPSy Nj9<1B6e?c(㑕[$dTZ ~5w͂CZ`1<}[*q8!XO&;̝t_·ՆR?I}uElMW];0gI\ڻ*DFR~RI<[~x~hfbf=k4@ z5%kroWJRJuAfI{ a,cFDm'8Ul]0Se`{ ǭl3rH1 Qg#HU@Jo}9f*@\'BCFq :xJx\7T@_6$Cci!;<2 mVyTg;Tj$G~q%NF'aoӢ63R,/񐁩  GSϷ tUջY k:յ^CiI/!:P:vL]6<*P7:DtK3!zA-bC$}X^ !sHIrlLOKw5!K1ԩDLt+L^WO#ehn[1>ГgVfFg`VL2v.tE-a84Uɮ0 ): c^ ^p oaj PD.,QUDj3!r8\QR֪gAt]!zEii)BltM]UD׋>+2A3ӚA }ӼհjBcS1y_gmŸu8gp?sZqT$E8&>C\sR=l0ewQ;C{0[\ 0@JdsѨ[ZL\](zPz80h]R\KxI*[yچ2RP c& UT },ܥ̻ &]RW :'R d,P@'lJ(~dVU3biX0lqo˯v ٜ#]?.s9+2Y.]G oiX]נF/0N43CZm˽N( [3/laX3R0Jžrix<(4eCRv 1LK&5>b(א djSlTulBûCOŰ:[(8lEWdφ8:X]-5#"uIbsNT]rFw($,QQPjAg~,ʂVɫ8r(hccx\`#;5\肘/oXoj!<FW^B~&dN7V!QEܞ46/[\9ZYtnXyouM4'Y3C?Crgr{nIx67Y{?izAGkd#f9S/H>򤃅tfM:QvQ'E7I뱕tWz]֜QuNYd_s '-jJZC/R e;#"Ezo§֧~\}1~}("oP(iYhnv9^"ǟv>d_фy X%aP./!U93}TVn:R m:0y =氯4l+B{Rt'lO54TJKJ@ͧ|\5 , uH'A>E(TsVuV( r\n@Q2 $0d _J1H B#lS'81UF:]ry7Ҍ%#nCٝ~ǤkS"Jp7BѼJ_Sb:<cͩF M2j0~GI?|~x;0„=]$h}<缋?qZvعL* V'w&L? ȶ!G#,%1)'#x$_K!1מ(x?bcYһ]1Lp!$i>AuВr* `*2b*$QYu-8b:9]ϩ8\vɥzyӁ&ERc4qQ6Qo!6_gF<@qpQi&jHF,/*zfF1/ycy*Auh 3d`LZ M%m1JR>tk"^EC/"eS/.1m5̆5 "h@äҔjm&.pEܢS)60m<2pL U{t<=^%s1;:)]i %C/p^1:rRlA؆&QNqo߆R& U<OWjtO06RQhbҗZH|VPte;XEl5nUug|*qn簩75aoRj30^W2h[r4/J\0a 3얰^id}BR,oDxrE,n )מJN&(Qq*le t)?e#4׍e /ziYD! 4S*p _f-T̶<HKS31e%9gTro8nJk6#$KGr4~H5e{V4#K)G>!Is7YⵗfX >~{#b֘H371c&, n3xA ԟ:g2R QA_ɫ ݖY}yB6xzϪ"$RùcH<7hs+l) 4'yjו a UCiʷj/Z> Y5pQ!5~Ph|] qA(C si!N`0"waaаrk7m0tI$7yt74QU쓕5ȪuL>u": gkQJ^H$4_/{÷NŘ&Bhzc/n|zY"#o@ _=antR@Vr$& #̿&ŀQI!ѸZ2j`sic/"!lCc}*S ןHƻ}E޷3!aˠ0CɟR|T55HM4?280*Dj~&Ų]kA}!#򾾤frk?w,I 9 b#Ӣ8>Ÿp$gh_)\Øъ$d#=ЭS2olۋdC2\)N(#9Ppr6N~isN$xxGuUU8{/CwymK䲲<; lvHPlBBWYt lN:7xÍb)j>JRM`]*; &%3SW?a̶6lD/!1LIJM {U^C)󭨴]t;|F(cH: J{mng]}L6h)ɹKzlCoxP p$ ar;,TWI ?FT .kJ0*Y_$>!s`\%d/sOi 1I~8h 9bvո4H.{r.cvwɉ,HcPِEX4c fEP.-ڙm|l jnoȷ?7hZz6ܠ51tB:>n 6f\oOiz]4bFob ][4JT )ֹ^87$kRJh 5eOe`pa|=αw97{Jy*< 3N8wU4RK:VU^lFAn6ꅗNүM%c@0D{XEaKn_s,o@;[45(1%Cγȅt4ߧvb@M3n5g 3;~zS0+{z3[H2plX݌D ߀~?YEn>@O&^w@g8^`Zb%r$ >[E"h[Kw#IiչR˵8P ">CwrM[_ DQY.~me"}Ȁ:Av`L~Cp5XֽL-飡-H(+0'EobҲ8SMvXkx[ΡV2}:xKwzӤc1(c)jݣg\z9Ị{">[:,8u' $p:&^6>E:)U1ާ 2tmY1?= }…WXE1Dz-Ӆj聏~SfdJOd;jT4h~NgGq+@66kvkT_jL~0c#Km†hϲG?J#9% ϶M|AVvN0;i^1jU;^ 0]?-/qp]mfj:tI#"21(VKW9_jt$RiWC$A5VoTWIҦ0dWdҳD{ZH"܂joYq3׸T'S2$s$s%uL~ 4p J8tޙD1xϤ\֮ k & ٿ4pFᅦ=y;DPʓl kQ )oxqR94=^9n*g]`izC%Ȗɐw]Y#TK>}B=g`tJzFGY@^5g@); /܄%Tx_{v_'^w,@BK :˰VU7QZr+ڵfDK |<  u*Hz% ^Hs;*Rif"hGŸk0Ff.> 88|N񳕇X{Gn.jI[=xC~1X3Rt;0/G9Bz>ߍO#B$ R*-3n{+)2=6nUJ{D3Rf\mp\ib[W( ݋e \1D"'\_%-sܠ,~P tͦʄؑ=OtgkI;`-Te9S0Ǵ1,n{`vGbS 凚aFmwdo^y$bg+.iBP"gz)& w] 2g|ˏ*[ƷA&?fiݖ܏?[ߒ",;S: N^U1f.۱gu8o{ ~܍/'S/v-5w+:= 0 LQ_G Fw} H8 ȽÄx/kFV}am) 4o"tuX=.9>A3q7(xA@2̳!fs!*w4L90ҧڍ/OVhU[um*{B" ~hHhюᅫp-םsfr>r8x!k՗e)Uem`n@VU LҠ ic*~v~ -B'ܬj .WxVMwLZ:-<Z 4(Xm=d=1!*$ B|fKZbDRpNN/nQ(iR/ٟ4 >`h:+ xߪHs6n!#<...f(Go8<+jfLՑ0ai>f(΂= 3:~Tj}0}ƅa %:p;y5zS7XMkjU4TsxPfޟO\``yPPbzWF:x H;#3XM H&rp]b34ٹ^|+9 T~M14j`]) x *l%~aJw\,W8'T#ILW3`!No& xRG­b^I}${@+t̏nP%44Nni1ґwaH+>ZmQH`(Ϩ"Ѽ<#r캱 ,W;ἀox=B:X6d%yP#K]4 =@:Vtt]$'CQݯ#jJw;<=5EK8!>WmK7Uh$u'UJG2OD _,=\QՈIawo )kReeS%k ( 6_o? z`ݕfN桮U_ho$SC  b ZIE՝Nڴuۯ Py;1تmZc@#YHTr2`&,"kmz'WdX>+DNYL&o*yB4<{inoanM8D:_% ůdڏ0얫SA \ 3Q[hy0RiIѣe=/ J1]vNzG' Lboi+@¥}j㭨#_sR&Ag*y1 $sıJF&  83aEekSzSṵLbGGTu_ŔZkf"bL%MC.nSb)Xݮ T Yk9tDe:T(aw' -O75#Rՙo4?̎X1P@ͩ8˰Xt<Q#mf;}™z6Tg)hk`o\Rid`(D[.(X qe|3 M;P|kJBde8pp: EɘnIC(Tv}Fݴ-4;&㤤*%;YTQI&íu}6ũGPdf=_; tJm0 tt]!T0P>'뼪՛Hn3SL* tsضŞ\";55& OW3W v rչ7A ‡3Q%3L+"P곉 2!as"DdڃᣋlVySU>ujvL :1/W` …ѹp;ׁ^s0ĉk6xd``;1ָUwS0czn,(YNȏXM6j<^N9PK\ν-?xqSXpW. Vqkr'FǞ:^Gy8ٮt\YpVOՍ)$TՔSΤ<}0c&Lc(7Ǐly\4Y[(^ߍ mNsoiM:Ӏd䂏\aBH)s>-O 9F!H|P+D 0Z޽|]"0=Ҝ$Bl=L٪UgfaW'*)"'k+A]Nʥ y_w$AW] 7"l&|_%rZɢ Ӎ cB!/4懽]WH{O1E߄$HkJ奲5?^NqwpMO1EHi%Aij"C Ҁ'OѸl-\Ub&4-Sis"׋7ߤ~v:N|Zc@+!rPj\vcG_)(Opb;0@՗"Rmq1RWB)K ϣaʢV8uH{_O[@!%PM`VzGk?Cq`qǬhfP+F?edH7C7MA@kEo# ̲AaGUl0d^9Oq(m_(i:8cz%O\-b+s)A-ݏ|VFb$ƆoC+B5B^8j Ga3Dֺny[FzWŗ">>\ ޖU4th٢wRMů2Qw}|%rh\lݤ*c0UM<$,8x8%^&A1+0Z`<@WB:-{L%f Z&SH lP8<(><t.a)K]t"8(,tLLqoZHQHֻlr8rrV?ƧcUe옄` wq&ik3l@eLAbqRDŨ[}#YԆk`A#B Qkck|ZVSۻdfh=ܭfo`:~爏l9`3ߙ#L%<㘧}8A F܅x7Lǭbċ HI~+ ^ ::iq6r:E` wV;JpgdW"[g ]3xYkD5 n xo~>R; :îMox%?f@ъv6 fY* !,<9_!S;32ؕ*OG)>R("0 q%~+м4B0^ȉ7D6D Iь̼m0pTm$*iry,1l?gc%iFo4Nٍj}XYAҌz~FإE \%Q-rT!,DE'Mg:9MJ0fUD>`O ;я͋فƖiy$-\K@^b1w8$KtiR< DS@ezFC@WiPt@XK]%7=e=GϾ˴KםX($\amI+@L̜uS\e-O'@#_'Z lSed{u{qcj$Ncݦ\:xtyQ2CmiZ keztΠ۬MS4?_9p6#[PZQJ{Zoy:jƿB> r^ }li>o2S+FPmr0HZը&1&f/OVqf2?Jxb\3`{wPσ<6a%vXn3GK 6D" * cډ Y2ѧ d)eÅ %t=5$اR_C/-ݡj%9;:4䟸H'Auk!(4/%t]N YjFj8F?\mEv [P)rw➉c pvG  DqN-C#Oj'X0a|Є^:]< ];ql,ǽ^qOq/.Eit2OE}GE.X"V]NIXHFfhk^"v7?=dxF)En #A6qo~E{w$1k\z'y?OB姐~f&>JH֡ 9au$q>6Wz{hFrs QQƀ \6%s9T;M5E9HR"(hGr K+GFeAW[눌>C:#"˭r/kPkv8?}%У"rTneuGr'b@!FGYڋ̈EJ]4 FIX Ta6gAl4`ۑrRqOUp\QFCO4]KXՃcřc8,ƹm2) ?ׁ<{C&!Ԛ!ZpD 2_R4t FcEq?ofL$ĩŜ@|ڇ(i0E#9woe R>l'YbH5vђ@+^hڹji9#X Jdm>WgH}W~Ob [i i/GT>?dir3Jŏ:V~[" Mlƚ pa3oV$vǞ17g}V {5tMݼu/DM:![~ʳ$t:q/&Ə6A7l4|Q`ոh^~nՙ}fp#(lහNvm|jc40nx ԤpSӴvۤ@:':6i ҨE'}'Sڏv6ֹ |jY;46`{VUC{˯EʘXzIV8u7%="7m%JP7 QyxN?5 Oi_wUs$?bRyϽV8JGq矂q?m _ѓ4nN#> )8lUЃ/*i/5@Dm5i8/I8t9V<y03HR,Gi(*!a"K ʶ(}SH_?mNk!ąL#)[H?L[JvyJƩKf߈+ Z/2zzKmaȁK5a F"0@v~j>ԺnisXeZ0?Ȣ] ]uaуFN>>i&8ʛ*qi-g._N5BTʾ$񕴔2Hy[)EBeG*7hȎ)Jvlft b6k LL(iz2Q,MUcW2YUO:\Utlփ)7}qtmMբPΑm.h:oirAc7ŝ7<6)f(eD;D~~n1.@YIE.G8TH[P]VΞD`7=7SS%UzHxnHW I ƫ|Ujmmz5{`8xuf.g~dBe(̲<*5r??#zNz&rKAOSC<6Gt- ga]'vߍA(OMVa;czrzrߔVKiU(^'jdiLG&/$Oʃ`~*3 ]45(y4 LN @W i1KLHUgx#a ᛽yHgR"-%R-UKi*s^ "Mj=[MBYLJ.W% "T߿ ! #3N51UB$\ sg*:xb_1*G?u3GN3F{4^IA5󇵫hJ~l90BF+͛SւD:Ns[.l=2&;"Ry霼B;re_ӂg[ [YAm$Z\ 1+*s/Rk;}pْXWibA-/Zq_8 {*|ۇZ (DHl#UNojOT7ʟ7m!QS8H/rT!߽F*2e`V/템[U!͸9FhapVZ-(" tt-#phpٖ ?pS{Mp~zjxC_zG2NsR}B;tǥ`O]E+$^ e q? *C 藧RcR<ŋ-HZ,=4Ϝ|7D$ mD眦 wښ{*j\"i YVAc0|Z8 a q )a{٧יJW)g>R9sf Z#&Js2Zm6߯`u` i}9h]3c=;/=fF0\o^\(8>~)ٵ W^z ,,=˹mUzudV8M0=+oKڮ!&"()yH^bJ`zk4_G9|BUu\/oKar.< %qa3sE:iDP+93 ME8Cn3wWBcD*J|C3BԇޱvaqJ{^|z $Lbqr1 D[vWڹf>u`t"pg\i:T];ϊŠ*qYIdb)JJe'УR`C5L{i_IEf3g\f~M/sO ѿG:$zw+aX[*R1-'gƨx{,, lE]_*U3\Hb*z*d֐yH挧l:LkZH5 eކrZaHE*C -TѸJt@+z";^ov= `!!e'T]L"Yw^;\ Q+kj# n6FC-";WPM:Z|VtfDyP6fct_d%sy[݈=|\|pOXRx6 Dz<JYQh).Z8FyʳlEXIgۯ`^m_U&|Gps ; 筑kJ(bԻe%|trF1=0'+ acqq㴯)I3%3r?ΙH/[1m&ft~Y@\=?oH͔7<{2Kzg/W7Z{98{(Ab-ˍZ; MB:f;ŚŁK 2i*J)ɸ4v¶=bX?r+I~Ɯk`> IOck2O=?ok8wyu] a&\*n2 iܔmߥ,G+^aL'V=7 eUhm֦xBiIZ}6 `xM9iPҊؚ9:nߟ!%G&CZW8չ#,8^'QE6Ik{ &lD_xr-bw O!r4'Zpdp^cD߫ ђ԰d{=*bbԥ] J\,x IR㫅7by5k m/K nȖb$wfr:yױҔo\%Ea6xpnNC_Wj,Og<"sF?fu p߲'뻽ŋŤe< S).F-JxUh嚺N6];F҄U ¨VEmLo4\vNm-gBM&Nk7?2;6#FY?WWVtbE_r4n1TD 't|X3vjAȀ&#HJԸ4|^% l'rcino.200>fz!rע'K/FL6XE%?X5 $B) @Ƃ~$Jb_imuΞˍA2,!&cvũ%ncz^@5˛&xa(w0b*V\'! 3:K⾑`J-M}Y e֚RH9r` D3V\5gkEУݥwLR~}! 9t]wpK$mԹ$C]VEu{A#le9jT4w[乕עQܻt6b/w/cK74ޝT)_ɿL>M~)1e)$pqߏ|mZx1sÁKVOy)ѱ񧶀|Kd܉c>dߠ`NW@?z5wXWȇؿX>sfpc6 Q~\esL&Uu/}#9_9ɴly/N X 6,@{ex ђ9ݷq&Kpk$Ch?>) &h 6^}d#^`L f6+M]p3G]'!l6 euDtgH-8D.]˭`JB!A?od(R\|SzgVvg r\rx :1 3ꁊx##)l;YlRaOY}1SpD&i=#a[gt?}3"9BevFlzS6_ ty"0V f.EH[+BON6ڊyk-X6Z Uݡ5 ?|IęʬʈXo.d(v ɇ.hZx Rd+(T~(tBX=odFOLKv682]W/‡ l|UE`xz&?B)!A* >E 0\. |`V羚]"mԿ g6~NDsFFVC V,̭r #Cet@b-xJq@i,>lFBtfD@c8Α%"{$"Wănՙ>@YXle>`qDk>1E|H/z3B۷7:=Z[9)6*/-(wՋ]d>)%ȃraf{.#ʬ4KZ3N2QcEݿ_=dc~z: YX4*[ LJ} L(90pFed%f݊*Gsa-YRDJ L3KcpHo >^]4;8.5"Ы@"S4Bo!![b$q:$ W"R;vOFz*cɅ/̖R[|w_\~ (f+efQI9ɟ5HtG>~{gpX aCFdb(mmAZl0 >8) P2XZ*&/I)Gкg#Y.׀KM/Jw9۰E[kS=k ӫ=:CJoKHRp{,/CX!oίwwR<6˜W׸p5reCN+~BRcSiiT/ /Ơ[ѹo3\ !ap$޲*s ,` /9tXT՚M]dr]tG^8DӱƧTEǢc[f|N1FΨ;<-QF'S@j8fapH*=OsM^WiʼYBJ̶xJ ah;V;*0ȀZ94IF>!mEp?ʂV""VEՋb , rl~{a bVYdU ҿ(yK:JrcEڴCD?';:G1)YB6u#6\ưiMT>^ 3.mDV]ym ⣱Y0ԠzSJMcDޯ|&IKc|$I0w5T_uY+K`aYDŽ2K[Z:EUԌcRڐ@pG|}?zzF:;hD!M!{uyX@RgO`1oJV \bGCp4|8Zc.ŕ`MoJ-? iU[0T[Y~E_wܻmJACX)T:`_~$ͣ{Bp&_o2 ;a {Fw|w13b|JalKQzPn? 03 gIMIee`.iN1X;C}a* [SUDrl6nBM_ܡ"pe8B%^*SX~9;XDHi߅ frj:|κUU2AdXI hxlu-Dx#Ē?Jkì ZD 3ګ M.ױeۯ ͅ>F)Ӈǝ:q7Ety uJPDQK0^)x^C~l%Ț kVbF#\HB,:7.|hI`zGǴ1}q3T<_J}/c*d{%^E]e5$ (R mQ{|oW h=1ϱJE\QВPc'lj(Swe'TWcUmBw]sQhd@(ثJ>hİ7+^;Jbácߵfv=<ƠֲPx@rӎP2-?2|;h891J w9e47]B m}$smTXnբQ!M9'p0T5gr 4"$9ujm'x_Frs`%Y}pݷtDg-n:kЎ90YҷeW ?%=$޴ޜ$Kϔ > (Gٶ $!E=ro^DYv9-Wq(Dl+&.vWnjq!M6[؀gX۠520ƣb[lEۼ"2`OU`LQoQB2N2Ҷe _T9*W,N~bŅvӖ>uJޮZf${rZpeZ :+ފ?k)pOd鄢1!$Yf;Qj(8rwHǴQ vkTڿ@nd1 Ȥq5N88ᾲ#/\[W8; 8ThmpO}j)N>Zj4FynvGxfEԴw&SGD7,qhxQW'he}ߋ]UlԇaB|EE1#Áރם!IJX fdT{~_`ff![T><\r6C7;Yf3!Ι$~x娍@ tw{"(bIU*̯\eLV(Ct~&tr!R]~ 3Vb+y|R[iSԵ?]f0 6ʦx|~$re*d~ R#D9lȑF;eJ ;/t%;qJ h3v }y&5_sƕ%F.K2 ^Uk]]C?R.;Ed6_DZORvʘ4D,V#kjqT&_j= CHsy+?l/~`cbm}} [;EfrK:èZ Ϭy7b1S3 /G̃q.!1ü2قx/%\ǂglfBRgC q9tehviLmގhjˮ$NK+H6qE*#uJ 6(?dw==. 3Ȗ-7^J] ,^G0;g B&*i@r0}xoFܰF&֦v9-Mg&YbqGdӹZ[J(wugc#ԽD>+]lJŝV]_xŚ/`c )0Cwߊ!^h[.ŸuZ]Uy*=pFpzݬl3 mL ϖgR!tT2#~۽frkNm^\6gޑ!`-^ om3Q",HGNAڡJX fٲ.IIc 'O${n Nq[f32eWxEe (DOegU'=o:'$WEa|9Jr$q/^ӧP;@D>'yX+vrCIHc)U_:n̮Bg]?.AS?N\2F{5lByzb!T[]rJ#-b.k㸱K+C>y>>y_^߃wq\ /PxhWN=mOk2 |ڳw\1D lߠTy^e"2A>t⡂LRUhݎ ɚ[[N&6uX%D|S5p;g.gg+- (i'W}))*;\e݀SM ѝyu`׎"?cb0+Adr1N =4,GX1ZMzT3)dZ7:vˡE cM2nDӊ]*O#U+KGZMN/t_>M7|BYbu k`b?^I^dcyc:*7Hykdf#̏HR/t3VP=6P޴h63Qbw<{D_>V9\l/7MQz{ o("پƙmGxo r+*E-w7\NCS̟QRv*  Aj#{3Ȁؗ.!y =k9ͧߚg6GQZD(p0+3<H{T zO+prgXb.N ǸOb 庭8c3\B߄yzoBoJʜtҟ6{78``w4t;k* %rjtnW5YlAa.hJҨOCТ#N"Cq8MhU*j$W?_  J*ye.*36\WaԭSe"ԃ9*W(dw>aRw.f]L_a虮qXH$Sw.b>_ͬAAP]zʣ)V9P=`1K/4λ%bՙ[J:1snpieyƓ^J\.&aQn5_UUn'2%Tb)btOz4%䰗^cUIخU-prD䬀{z)ܠZKyp ꒡IƆʕ0cFͭ3D1D:512Geyަ3]7 TFxXBGv3 Bq#hĊքֺ,)%U+A_=#hanT)*VJ*^ۼi /;7a8 f4$ut:k4:}TѩUi'†Ee#%ñ-(̄rhr&,GByA"Hj/y`/%eD^+;{bw ^'^AB]#M ^n*lU G7Xrz^{(̈Zn#XkM <#~4Y%a&Bɟ TTd@^7A DήZᏕRĭ+'`~aTkSS<[>#^,U ;$߭׬\& ƟUB5B!7VXSgIgЬKox1{Ǣ8#PPHbϑ޺)Xz\ A~yGAZ_b.(厓/J~Ā$ {/&PTF`"fB N㰧 =$2ו\IFE,RWTb;[2" ׇ* ,KxQ\'ty\SӹRN[dAWg%sqq;MͼVz Ap 8 uQeBUy-o⟖=·֪B~p@($[Sj| >CIc6æΨzeJ 8<^7Ⱥ k9*t(3ծeOzN c""˳؇3n簾`wk\ĭK11#{k H[.O D٨Q7M,Zas!9oX6$hH+!1ctʃ74-D}NPs'IsICn7A\[*=~^Y1RG 'rhʈ.Ύ LLU+~2{iwg >$O gSTwp}:zU3DfGXTVz\g<]WRh\r}zw+-ٴ!vរ[S%zGJ󙊦DT-IMN2I8E׿7_ ‘`~YЉ5$z&]V2cNc2}[Pܯ2";5# S<ęz\0nZTDޤW Xlګi k4d^04Ϭsa| CڦXEYx[\v!|=f'i|W3*tի ϻoBt]> Ō"|&,;68rothHxBdѪmxv\cg2 !dk:㤞4Gx8Hm9O2btIF~W /\ Q5QJ j rk%[>nt*8EV p@@ZϨiz&L gZ>b;54@qۙ=_@_fs]bC y%v')_?>`$buUuts߀5*A!kĤw]QViڔL^p\hn-@A}ʆ{o7L@XId9pK6b@Bo-6t䍩xѦW0YN^)գLKi@.Z}dLi5@3`ҶJon4 R+싧i"[c/׆b2zoS"mrGQG85y_P<U8΢!] @ۉΫ8@O5i'V'P#ԐSsa۪kK&^8дV0}fiiq}Q<7[k7Kr(^V"7 H9 Љ{?AOg\Hi @wnbsuOAEc*w格-f7C?)=@x#<3IL^~M΄p uXVgv}!{K ~'=G7vWQ ۪+T"ɴ.W}ώ] 8g> };ٺ ~5l;#vX]1\06Ve誻t/΢V^bq?jJr a GTYm~$`tMP #:Kↆӊ㴾NÔui[JwՊyی3h"u&6MKUs1S^+b<'GLU:({x y,IT݀[pxBiV-P#զ 9?@'iNcq*\9g&]bT1%\$7.:O nI^kaN++ɭXBg LPD5u3濽,*oۮ?>G PFmҗȫ:@76(y:3܆'Ӄ5y%7i5?K&ۦHw}9#M#C9Ev8ia~%RQsŨ>eLB`;OE=6RYӡD ` IRAZIn1n'm>r G¨M/:2`&6:u P~! fʡ@!D,oOpڛΒ5ʚzB޲(o_?P5C OU++Hr~K +YNkvM6w9t큾:nA]NtLFUk]Ȏ̑ϻ`Zx b^;ё26,Ԑ3L**d\Rm#Ҥ "'q{mm[=.%Dm91[ڕH?-d]TO #O/w| Inʺy2Smy)=f3ږ7#1Fn}h޹tSl\Q\έp&#̥ ?LEL..$8x&VcHԨ Vkp]h ܳ"5Z])ZqC(ɻiŁs;i-a3gg5!=C8kXlhzTFF/O!PK!%y %T}WƝ@B(2UN-cnU uG,9'6eUW:Xa#)nv/7s])H̏}c &uđ:o:Ҍ76~؏j[-ەYЕĉ9.F9S->sO5 b#ܶG,6j7ba8ARV3u MM=+"RKvoAxo4͌po@ *111C7t}3.(_]Rs_ZH~X0hEhv3LAs M`i᦬ʆDc?](lyM5OqN=)Tf^%\~qh+ェ JL`c ɋcQ@ j͟MZ 2PW&U(?5o#׭\ KYEm}1X taFBN_4jZ n'u:u.gv/V%̒Όl;TcZږ /qօ㛂OS\*$k'`ʃk~' tn#;RW&=qDn.#5V=/vYPsDB%a[xIj24~cs- O\E  ?9('XWc2(qeǾ7󬝱lF@ \ /!U1M_"b2ws~P#,&|g 16/[ yġ-{DBpq.QhdU)etT R@ >/!`i0t= K'| m f_3M7k!-|Ӯ"?li撔.%|'EU#ȷ" E{lT{JjFSm6v߀{ep6;~{F+!X]nz:mʝ}̋5*.bDNxK%ݞ8-}u+skObwm]#m]3 ]_t* ]Ir\G4|OR9E()'yY>QE<]E 525*lH&K/Z30~%kJ_2vD.TwOwch~"&z$1 F!fGAFK"$G{%c8{YZ3Iz7^PidJе<18WtJJ7v$ZK n4ܡ 9B(١Jor5]ǤC^)j/-h)J_mk!RYصG6Y ySG*G#VUD~Gw_]믥0=Sˏ',56]Is# "xIYFk6X@]̓IjС{2!ĕR`u<[Em~7"%c׬_<Ѱ֑B%ZP_Ïan@e ύ4z&o=T0uTCzg jzG Us`ٜ\nSR0 !K\Li1)Y@KDj# H_u0d-<}"<kfPeLWp~/X-,@ХB@i[`kdgвȊ+g>6<ǩN5.2e׺m(rPoM>73}NQeb+7pkn_}ꃬejL߰4ґz5,P?1s!l"H$ \Gk |6Se^9C7 GzVBB^#TXy MDeh:>_12 YhfƵ*snm/F;Fn޶<;EJ- ?qHdT˃Y o}O;*xk.ċ,Eof )Zk"q0yJ#=nGFKE},$ʃD$9eXFcщ.t_jt-'idLy]1LjK0Nԅgje-¥HN}G$+rXgi4Tȭ*3&K0&d8<"{9~mSܰwJ8I!7g__u|(>x.A?_ݦlm[nZa@;z|-~I`Fh eVv:)Y3|Ѻ͘d~qD=Gd$xk%|uGf5@] al=Q򸳀[xM%_P\^"%*܄-KFWs<(S^ 1m"J6d>K$@^lz>,RVAi*:Ōf 0Y͊=d/Ibz.khdDs* 5 ?v+g zݞZyJg(e70;y>Jw^$z炊3#OA"ˌi9qi P}i+^}ST{!؍'_=K۟YگZ[[>Ӻ_%uHvw)lVEҤt"Dq򦝩bDȗ0=K  l5Hdqu42 T]VE"{fM<累^P4c(Yy%h:8g&UjPɔppZL?Y /+ݨa U\iu*JK0;&m۬,fe`SUpz8!Q0pϮawQ)>, @5LI/M9BZV1/N-H}vMÓX¼rsCQC GP(&_)Md}q^ |݁ƺ-v;r(7/Tn%hqWPR1qYZUӭ\=bA^nm" ٖ<{)B>ks؏@X'ub>r(k xt.]ϟ`*R~`lm2C]?M\VK]T`Xád &n FI((M}s1OrX)7줹7RajfHd^Rp eDZ^3\aꖄ'CYt>KxUk`94>UA!ww .,!04y\?ƅ>.!R?y od@ɜsyd̼eiTwHј(ϡpH=Ѭ M?v#I60RJL t t_Y\mn{UȑFT֑TT3v[j^9g4RClMbcڇD:pܖO(bHXb y"x$]`6b5,Hg]޷r\m*p-OB}=fv?k-KEǶΑ!RLE)(Aok#[UJD~)~&p~/N 0kXO z3h0 L8A];̤<4/|(% 0HjǁjǷ(̴&IP;TVvngQ]4%^,8m]~έ&c]' LYC4ՂH ?jWZ7vK.4rJ@gC}ၾ3Z`vtH-3!VlVr/wcclo ѢHvVBŸi%bYpbdG+՛j %%WY:H*e{R с'1Vd׷?1m5n1ѻ [cF몡'ׄS%Cޛ6X.\ _k @%X*j]åtW4^ǎ/II.{o:̖pcZ ª,CDpV?J4i?sݶ5TDԬ:QD^zH7!{""]s > Ge(Pjk5O٧. ^Ѝ k<o𣴮aG|.ѹÄ ={%wfnokm[* XAsUgY۬5QJ..$ H3|0*):C4t끮I-#`:ꨐW5l1X;%"U ^8b{ܒ)G @^>ȆIFP& 9|S1Nɩ8l R;yTOlsѵp%N纨fA65zQ&S"8<͜\r_'lO̬ zXd95Ag0S:FGzNnw žF=@ "uyU:foUMƲ0LYd-7#FЌ.ipcӄ]PfnXDzݎi'BpUxLC I$LN5|o]>f;MX}8knoٺٽ; Zd!wbrۭ*qZ(DJ*OPLMX 8CxD)UM'0{K.mGY+ʀLz9LR%x$x\ˈaɕѲ`9梚Jֿ77Y0h9pՠ=Ļvi% Ӳ5DOϹ7qPz-qKfi%Q{$p _}wkM:aob1n^ G,??{ 6MY;+pLvU ];Τ+qM炶5400?lYfg@z]{Yn?;Pc5 ll  v `#>F5b-TIK:3$:mFY)L;%A+]`epg6q kO{[aط#ULQQ&`0^Vg>36'¨P͗U )W ?B*&Tk jm(fY'Y Beo` Ro#jgb6Q<DFxTiYhH <#iP+v5R) z^"+`o^ڋ/'A.iZFAT+PVr7r u#+a* .)_BxD?tc[v(;"2n&G{ CwωZw[~\TB^e/7iݶ[U8HE ~gp[󫫥?_cvu|qKg`n,`o*OFY8 aA:!@JSK!2RHRd*S*uijK΢ŬR;Llui\n>FFƸGEP'B$1ݕ#k  /LqYi51 iɴI\QICrU9 LS_T?=Dv Jb_ĬnJdQkSرMi&uŹ6.pic*j#%TWux+wAo0 v"+oW n75 e W%genZԛT4pV6dmk{hB{_6Q3}g$TZ6K Kճ6R>KH>GJ8hHMآ`0`ICJ~EiJ 0'*Xq&͏_#ʳAJapF7a-1`U~cO %PNJU/%^-C'' !_Jk?[(1R 5 .q iK_,[v9^VMV`fF).kN/Q>m̑ G#.nE4kZ"dzg>-0xpb\wќ>'PoDeStkY}DkmDH ^4^4 KZPzKėХp w-{m_Sf=eoяWy QEei3t꼮hk?'ԳU<R)쭥)Hե~3On Q]1W.߉kGfI&I7^.޻5 F 6~<"A.uۘ(O1۝mĬDG9nƄf%Ҩ&Ȕ1I^1(6TyS](h8 S[nUhŖ%Ɯh~2e4m3`USI)a$3#ռcali<1btWoFdz;r =\~Yp9CAh*5P?Z< FogTHZ/bX]vA[43ݧZܑQѵK|EǹyIs4?‰Z`Z7N|MV $ Ol!,⋘s;KFFbN H ?pT{;Q>9_`rTs7C{iԓ?PM4[|viξK܃l m:%52[ }hd,,@sjIYeyT"bkEOvs8P$=;zoIk(\"8 HB]yiDDk#CGqNK>ՠغ&Z-fpF[s"9\DZeNHeb^Cůb"T}?va]_pHK/m3=# Cװ,n9c\$X{BxH }L%݌^v,3Tfx=X>uF5˒>CW\.P5[~awU/խqT0^n{1 ATVQf!;y $ݿ5};GEE}!r瀏 W= ,;BW2q?'C Z a8KZΝQ+ጨs͜^ΨPh%m43B[i QL9{[ʗIDQ$YՃ.Dؕ (DN 7V -ϊ /XE^kM8\7axsyW#XqۨbLH{\74k54Q9V ,,2a yCX+&*ujirv2(J7 .;LQH*$/Y9Al&@UTA޳qqfʆ㦨yf;x;43vNkJ,FMؐŷTNkGO?=7U*ܔ]umC:xd]F&22(#ilxօ­vU>>œ55mq,XXwdC2 ʌŠ=oJD!KU.u;l-%RZͬ1F=`=YY%۽mlh&M.l8_nDPƇkmlBQoG-ArP`K[V/jW=1^R$`ulB/Z<{jGƦGEe]3ĩ=ۀ6/1.R|u"lz½n(ft^1C `ԶJR"v+ g RYǢx~JN-60tsa6#ڒ4$*ۓ~' Pv :ƬLtmb#q0tOKnRRiBU!;agJS!Qk&` 75N,gF0'5c:Εʾ \0u[S_ҝ gӅwHj4yO-%1ZPc 1M9yN42Xɜ=3/6!Z0AP:Vsa6z/шu_u `T:av*Y>=yJRz{ ǁ9{WA!Of|)4l^ ;KQ6??\X^}Hl/_dG>RY <v֐ՌkloN~fSS-wc-ߞb;Cta4Ѵ F/'Xe!RಷE3i=DS r=&%II;%*{p"d U1A̽Dq6mP*Vt8`OεM&uQ2\iIBJ!nt/ [XQG;^n4n䇛_+:~"Nt9L-ѥL#Ί69XNXttL>GciUwGHQIH}M d,Vq %Cs9{Ui> U7=Y΅D1XٹT`%g=Hur? ~@kPK±b5e3q/w|Ƹ6"B31n- @Rr2/{m j f6 je8aVymOmzsSn2as .b7/RA iH@~S2@Aȭ4g1RR84ќoQ1J#c_t2[u}fp-eZ@I>0k}R7q^Q_?9ؗWФo1#teݭ.Y}[sV Cs{W¥ єJQW+Ԧ&XeӠٮ2.ʀw᭮Ѳ#la3܃0e94~!u,iB>6;^p-&H'9S^LJK/Z]=V`ac/cy# Z $ihw$*Y݅^7){=).pܷ-!=&} Rpz T&;#rX^ѻdΆ4^Tc "饫`NR@u=cwgn= )&3lJq?d.ǂimNcOʽ{L (f/ 3rOBݥ .Y7=A7;cQ9mqo2A/ct2~"] p15W^#oNÖ૝-s|+ j &]B2^ h6|9.L~eUg[5D+@<.IVyT33!rev,:$:F=T!ɈHi0}!'`܃q]Kcwio[ }Z[\}á'5o~0v)Zo㑗wI]zf fR|Y (KKU/<' j9|ldLIXO `4 4ܲƖ1lsbPXfXX淞O|h\z=s@u"ENE+J5&rA>.})_Z)0o.@͗)lCX#J׎l$G$$7KMsxoԨSe3#xٞk<ǽy4nxNY0 BL҇X)o_]_rg7Mgd֢ R8g'Ϟ{09%ݣ v0 L>fߝUNfP0|[7 4{lhy\79ӣǦ<ΈWq_ *_3b }9֚Ter[3~|c_(XmD>eJl(AK>E~=ؽTzdhjF}_;[0–ks~Cր_O΋Z>ZS89QKqe2*_ŜM6ZLN({\t+ԓe㜏4Ry4ʵƈ΂hzEI=+aZ"BjϞ:{_OEħ 2Yء¸=OЄ05v򻧝M"2Z#eqsH2<07COE9#мa>/k9#]@t(ewWU_0z] S<܇ D9ȥr2ڀ㻧.LDvˀ(T}fv,RX,@pVd56>4-J)5Y{=Kp ]:FJY&sjQ_0+CqZmw3d.ǀ'?Becd: [7vٻB_:ռޚoG}g0m~ŧKwYB^slL3Bb&o@p%Pg܁vdnt7䱺eh~tk_5lsa dy("s=f絜F&7z0(RUadz,-vFnoA'bjy#ǚMJ$l{#pe;/,E dAʠZJjG3]HL5 =ﶮ@Z^J~hMgMm^G-rbA\Gbt0qeE솔Cx(ELٚ}l0Ds8@J?۞ Qr3+%<<٤0VL2Z>`2;ޣ(k5 у*t; f"Pt9Ya˩p̾7 F ʕK&PiJ,+j%%4Vڊ9]ѭtWirBɦn2.Y6#,R, HSy]q T6Fje %h7?WԄx+#,gS rOdX_jˣTz`ʮܸ<;Q])[`Sfj+gI)!׼jL߼ɖ.;hd=n[ Xxn ` z36!QhO} C28)ZJ[u7Bu욎J[z|G77:Z K8wW]>dMrL8B-isTOꂃ~2sX;Y^tQĝVW6<xUwsXnojsU昷T:ƾQnK !4>gujCweR8*Pl3'~*֨cOκ^y(Uߧ7ě|pE3+\ E*\ !k\AT޵p9X)/C+MjV|UpG/u$1j8?oD;'޵Ot}ޔw޻jcPj_ϨGqܕ=&AJ {#*/1Q$d9`AP'B9i~䱍5>(A ==?k-8Re,$x W0Q'لJ`5g:uH@6ҔLđwHCU}!84e2E10qE_䩴vME5 8)ڎg$|c41?gZ  };.;dE{<[ ;1i cɐYdKhչJ㾀=9Lg?T =0Ee̩ܣ3;"[#@U&qqtq&N\ z< 5|s4yzƮjB^]9Eޟ@RwT4`LVekӀu6TNBM&nr^>/m[^f,RBRXު`/DzP107} ٺ '&+@Bəp:yA5]eBDFlDF@RR(*Pd?g=]D=%$aZXI_b2c%x@Z ysU29mV`*5RHțlTܴ?=O3!g:[V&6ξu_+үMTaX*#F@pv\:Ot*+ ##IđAݲh ņ~MPr+0 qt-zGDXV 32"+'լ>~f50ߛKQ@A0z:uէ諻qS= ;|[v Yc#>5B .3S)up?2FL#$(#s\Wϝ$wR| ^{#Dq8gsW-5A~3mnq(u0ԄAAX р>DnL rc]BZݙ~EǾ2;-s!'Q-yQuSFХKg8qM=݈rɟ7]ةꩪ9G|:w~ "Nn:;YTɊ`L}ԕ9,i2RsH>ɼ)XIKW=tdj%j &kTt:&IC]ΓK^gON%,b$҃ygϒ\D*DSv ̏Fg!S,.)G6)bbTCI; JF<@\*([ i]cU&~<7A *V˭@B\PP.2P_^rf֤޺5۳!aTV1}6PLGk'Epb^̈́O.$2s 6sʔ)e1IExESZ0w2L:13˰˓- kbs,DeNY4ѡUq}r߾w-N6J,&!(c~2,0lT!l=2o5$N> P MfXX F`xdm,F-,pBSTӵ;ū+7R+/5Ҁ.ѓĨ[SC %9ɂDlM^N 0Q=zq.c=Tu,0%Zۉ&goK?kk,ʕAA=N –LP!ON0V/s*ڪm q"j#ԃI|I 3I-"쫀A6&F!:&\ 9Jo]K^TD?b‹ *S+>J g&"jV G &F,PAjY:7mv Sl67<$Ic56sAO ) qT}gяXr?Btn@c*.5pW&U*=YT h& 56SlFΑϬ zO1GAB2+ S@&B{79aRxv~w3hH 7@}gTqL@F#/rWA.HmC^0a1,H*Ń E-3y.tNZ]т=cR!UӑCb^G$kہ)MޝA4g+W0쀖ֹ6;2O\- x@+~A\ja I pVs)lxiR02 [L{Љ!R#o=8yM>Z+WJ|HPY\7~T,{=pO!%W?#cIb lS Me )2#o " IOM&6 lZf:_~Dϊ:jOPeh )VNTce<|PxWYrS6p&z~j"z5!YkmV)3 ,rč%y <2ҹ$rjb*ՁɭH_$^hfdF&@H=F+E`n`3·h͈v T;ͯ<ߑZeBhw.S/s[G%0~z Z,߿+ Kqw #z%G4g d!%:v*2Y,gY2'U ~<݄]".vUROF*ɚGDvJ8$-3K̼r\_#ƪSUKۤoδZ)K'LxI4Qh4;j|Vn 6GC)$SQJ8UI6vDZ `gD.Ixտ~Hrw3bN_{h)=Jc$V>dfь䩠0޽U.seHN \Yx~W޴w[ '>o츯@|<$jl&Emnjm7kbx^舑wXƋUP:+6i8Z%%.ۄmZ(9 UUOmAg]s"1c񩲊dž۽XtgQN T&0">,BY g]{w3K-%=( L[#Tw5LaVWͼ.agR!Z #sڢ{ib3A)B$<NUj\ńVPȈ]u$yJC'<If/ٟ\rc¤ĸS""ș3XC;`)k_?vyC6 Ͼ A`Q"k{Eԍv_A Cz7y| ǚ6 雭0&PI)8re\3E1qh+IY\qtI9+tE=|4*Ϯx 2T?R`@*`aTбņqфҎozw,6ŐT,~lAFޠ*c%1E͸%/C'MkHpPWJ&^swmi)8p!;فmd*c+5$/ b`G5UqF0:/?J,xn;2c6dUh!8h/| g<]l Dܺ@z"XFEC\3)?3Kv%֤˶ɆQ@>O*"ɏXD_#Iy+zŝYegftcdS*<{~JnL/<" Xv=>>O!{l{90>sV3VPNG"Hҳ N?O0f@0. /wU^n\1Nb52V# a52Ay>MLosڠ0ѝıd_I;ّڶtqi^n4Ea&RK sw0s^cr:1Q(xH~p$ NɞFi1)A>FʎL|8nk E6*jz`̈́6\`\ |QlEz2לOz#OϴD ڲAPâL RHQc/n#qڄL)E7~9nDSFxCk=Cap) 5 2cMx[Эvٚ}2R}8b~=Э"kor;W"L z쬇P#{k NdBZ U5#0 ʀ"cFOX(bnxNs]hk(gkaKTW`H9@"tDz(Hcf5-U]k#?-ECnH듡ؕ;CHp:=v.AuI!nF<*>b<$1 ~Nm#h%ߨ'iWNekt}c!Ky={e6-9lVoI k"ā𬌒^1ƯGBN.7p[nT\xDl.SI0[1S՝Z8o'/B׃7 (=ZY/J\G.4˫_ Dz'A:A\& Mjf* 7IYP@]\aI|} +Dt00Zo^{--Rx.iu4o Y1L\) {hCNّ;v|苤@S6:p-yAG+Lea7C+}b'LG5_񟱘p~zҎTqcG[e$ZaÛHV1=A/̱(k'f_1i/+a^ pWHk |0\ DѠgd!5|u!W2cq_IJ2IiG|GaVjdnc0q75-(ɬ ?eqX/~:<FD٠aa$S9:x`+9"Gu@`H#Smz U]I7 ʵYVf^H&DD!Y)xkkeNA*i2ItE_]GBNWQb9:}dk H9j7fYykGTʒ?֒^F3!`D<1ri6GZT:3&YpI }n^&IW;kw~9J{ߘye<;1&N۴UЎв63IjXp1J<8_e>ڝIJÃ>63rAtӚgB6;^QFV2T~X8)oM2iѿn"n@ θ8h|{) sx)&zWEx끚Lu+笛}f,xeEpTJiH M4J 6[(\p>a#:L\M[ђU,Z9=ҕYPa$o:ٳc?8DH+Ю>S/%!pqƫn* ZK8#:w̦K'i`?|7R_Zhq 'RN<_ߌ!,iIs=HL 2@O Lo-5./ 3_=`D¦{t&f }=m +ʽ6i+8}.hJ5(U":g9=Ő~3k'uIΛ _F#+ԧp/.~Q[q<eUlMܚYy2,W\m_2YF0C0SEF97Zb/[Z7̾`a,^%a#JZifĢiʸ 7"j+!Kgb[Ȟ*upuB/FjvZ&s-_bkG⿋Ros.oAu: YZ