pki-ca-10.5.18-15.el7_9> H HtxHF`E ?*}}"+69Cd k@V>hD zK&~x>0157ed2e7beda32a8adeb44dd3046f4f14628ac35ZL; [}QF`E ?*}}Fnpoxyf}Q(%?@iTL p&>8?ְd   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H 9| :m G|iH iIiX0Y4\Hi]i^bdefltiu|iv wdixi֬Cpki-ca10.5.1815.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.`Gsl7.fnal.gov%'SScientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤`$^2``````^2^2^2^2`^2^2``^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2``^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2``^2^2^2`^2^2^2^2^2^2^2^2^2^2^2```^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2`^2```^2^2`^2^2^2`````````^2^2`^2`^2^2^2^2^2^2^2`^2^2`^2^2^2^2^2^2^2`^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2`^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2`^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00edc31989ff618bb94fe5e2cdf6baa1bbc8923f301a7150f44939f5231f77a46278cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-15.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-15.el7_93.0.4-14.6.0-14.0-15.2-14.11.3`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-15.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*H˚U]w[эAvOsTM[r$&MփaiO[{ O@QZw0et$U|aSO.y:va==ʻYRؖ l3jN\$=:=m=BVJaԯxKq8 ,EBXr]00Y^' d~aRQHX%>&hEQD}"6npcq*dN݌R{K:'^D?zEiaImًw .RB]N_g4)`y~ f}5d#a/YxȻot{q)2~v'FM cO9-@GR:kr0R&*WlS^:{>h4lFHmG^CPUQm+0ÁsV8QR/~7}>;cH>e"xe_QL>,U BO.w !̅6 ;~ЌuC ˸f iVo{T13ɏl%DY1oPJVQ^KGMW@JyNv&A[_E_}.U{S>̍:+H'>x%$f- 왖駒pCAv S%L/H#T͊xe3P 63XP^p:.EG==N%읧zL }؄9!a-%\L,f&ߑ{tg7o齀roQZJwcX1׼;w}=؍0Gsg@Ԅ8 71?ե-RW9q?pC(=INQ@AE?gs)k1zV$\`aRg"Ll#  U\de4BHt:/pYm(Gs 0*IvԦELHj1K׎@ wg/@/=\/u(wl⷏:W^%E TuvuNnh< S")?b=%hbf{΋u(HxT"a\7SE$L%EiѬ u Q<7:t37hOe*HP (_ guWAw^@4+Adeִz{6j|lk|>ImQϩ&$|yB7\oAJpJHU*2a4d!ʬi+,^9'H0,`FJ頼? 夫*! ګn8ϓ,B!K:%?|RoZݖyGY5p5 :Fd߇bwu;"/rJ. O4Wqt<*(q/:A.T|_A@A2> _;S 3ƈV%עo<]9tVX.i1@Xv1S{7-nZ>M4K7(,t @Y8FrVnVѬi#]VEnmCM ȤMO' (3޶2g{EvDEf{Ok`nO).Ü&bJgNsrN9_c}L}\A8BHL}`P;uP)^wI9j+`7L 8,-D֮eN ǎOAE75敫bJ9:FhBp~| ޣ߼l=^;sҵ(pMʢՇ5i?qꋐň)ImpHT:嫬> 'L\imC C3v^4k( DŽ;E5MKsvvMp$\bYjyj|YWd 7mN /r1;bJ,FSgC_x1G^>@H2?7hKϯ NԜSnyR)ɺ(w `v ^߇6mu!BfR sU@jzQp@)|iv5rhl6waSw68!N(OrÞ,a^oE;ܐo*Ė1*-"ʼn(Iع# ~(5`iN ^I#.Lo1?|?*,>F`VC(ZUx `M3rzI~qd}ԈKcF_{TA?R^ ?V=8|fe|G~:\#IK65&>>(,{l|]*SA;)@c8zKj:}4ObutO*4:])]EI}ڼ>:V/{L@`.rFd;uu& M;XidNV@5d8 .E٠KB*s0_a>| OLK5Md)OBts\0x,Bt!YK[6ni=s4O<tx^&Z1D(aܱ 2!<zi3ƺ-y]Y٨Fݤd:Kpṓ)ݼU*MXЉbk?i$}3e);Ak7tumPqlC_'tꑖm$YӠoKm'W*u*]ӖnRV+oߛ#c Eh)sZt &O' |5)EYy#o}Z|]8ԃ-S/ji`fףtRQ- \wdtvjQ6QȺE(rj#| ʤn5Fr/,]|sE'J%e,1xCcY^Qc% ia5o?2z&'CI^lX:vt_I T L#fl#)k+FUibΤn3fTwcWҷ:ܥxgwb3HG wg+ z]<8}%S{^?g.#j!mr0M@|mۀIYDت :+$m BV4Fyqz^aǠS{@b[ (r9D@SQJF>8C)o&GԉR8l+mh$Z*S4EQ]Eyԯygldqi*Ux. $|ӍJN b?747$4-0~C|}^]x {*~/&k i}fAz" nBQ@6(QnaNGu8и{ s-Ƈ kymJ"o,B%4dv@ݽ'*w'DG}9d}pjl89,*8ʏ8T }bn(:H zu;urL'a XRV|K AHf[s`I]I ~YS]nl^24.U.Ri Y}~ڢPJgh=-׎ESkB16gFztE& ="vBGBT!NxF]~a6yf;Ϡ^ |fZo8*q1کz,X-vx 0@Xr-2yJ =ٸc%_΄k[oGr^ǿ#EC`ki9Zʀ4o6Ld!>%~.1f7Wk;Yp{bBflF yOi3R-=JlqdS@+Mc&HZ}NzPa ӳ[|'FHu@oک%hkA%]b! H⿩QX;X!?ioJ9cQUs'[PF`3n0KDփ %_Fmۺ'CgxZbS B 1iUٮ6Ѱa5z#L)/թ+j䔦meJѻߊL?V/.i#I/ ;'6[5=76*7izj;ʃV-8}~yk>52G {#t.VQjK=[a~"=ꝓJ(slK>wS>sc;&Ksk\}umuH'Jgs;OL1eIL"x[ SqQdpqN~RG " Y<玌&L NHP 4欅3ײ69D;\xIga重'"L^ ZX+ vH'BHbǜdXUfUH YWHN, &[qWK!B"eԬ(D1NjPY߫銋Ӧ' cR.&-,u\_UCC6kF# \*nl߰d 3H;LCP.WdA ?/-vXB&x8LË O| _z8ẇ\ n?Bʁ8zstBs|!#Va%:׺_`17j"fJS6 A1Gte" cj*Mvn Zclwo-ȱ޳ ZbMm&Q^XLϏGgU,ߢ-ղy*&ٻVtK{l=WL>Q  V2D*E'j/ՠ:.)* R5d`vq9 %t~٢Q-֩>(}~հ]n^+opX "o93{mKh^]5m[FYr4 ߪN?"Lt ڍ " KKL";#5ZKn45k_d+ڹxpT۫a\8CvUnЃ%.-\Y".;6 Z.~^q9&#!FL.'ʮ90?pDrVXѿh`tnH̎O /) DX^s!g<zqL=-+XW!⹶t'x eYm`^aI}̟:c3 gfY:AgPdm+49zIBNV}&P FkbO1?-KtǶ3fؙz$/n"jه;Kg2%ۀE%do`2_4 ]SQ ܭ?NeI -bSh蕢,'-e5F3{IF,U`eCG>0v ҕ=(a I#cv #bP=DK! O-Nrp "gxv%FQJy~̪BJ"vi9ϴ(Oh5i xxpJ>^AL h/׃慒 vAO馸01$\Ƅ0贑!-MbW VYog8w5Ti]!QԶ Ƌ@$`-#9agqaZA+5|,ԸFQvֽ#ii"03EJ/um1rTDGkZ&jl2yؤiQv'J!2lF*‡YC9@X!j1}!<7%d3~„@unՄ)Mb5(kiE26sQ=#`nMS@DB=cT5F(lٽUZQ5j>&g$PZ O/Ļ4tb^fu=/+swFBjDIЀse>3E;T +;EoF͢HH*E)\`>sW"4 }JPu8x{Tl"̎Z9V^UsQ$=/Y[n ;`36DoaH``Js3AZSHńD6ǞCq|Id$FƮN( //ZH.MXoSܝkc< 9典ݙraIb *?"_rAc.Uyw=_rP2('w֏ҁ'(PBﲐtCO ׯtM'fP2(sr[hEXy/^,hS~Q&n va)_d#-cL@s)pntd9Mܲ6izk /9G'}>YcM #ژ!WsH۵8XC|M (ziGPH5|3. apSBCk<*҅ЈXaq@h)?J-L;NQ}0g"û:r"ӿ]r'$@Bw &r$[(W0T6hf/8B}n +BKI (^b'vH~ZVI34IQ*V <]t ȹ>{zv L:{ w /1(%0W\!;PǕO i&^;ET; -*A?|W*f[Vns.ۦKZBW#e0#0dPC3 07>͕"*rӟ D-Qd3 ōoc۸2;tSG¶nV2ʴOulŞ[mFmpt}Ey2 `*!5;CѝG;l4N94kk,Hi϶yQbr_nXy׳2xe(єh/Mh1jU?sfD&tD۰nz#tN 4r bCtKY.+c+nR=1m:zU2܃vc2#P+ -)[iYgd:tQpwٵ@ɘkdX70/Hӎ%FЩ` Z眮D$ᡀ(,! %)RR[T/zZۥs4''>6s6]{(=D7=EXhH%n9vyou|k9A}(Ps'D_(D;VY S\%}ۈ /8h&s輶:az' Ի[;}vؠ{ 3/ۑ.xA"F4d'x0*&Ѥ,ҕkiMGd١ۏx.ɻ\4V"h-$S.͔a |AoM!KV`w$+&HBkFX#y~/cؔ tU#4 R"ڥwQmu7up4D >d>NcR\ݰΕ!62R.؟d,mRakNZxm@B~<#Yq^q\,Ҟ A冞eeKZGs= HJ9yQziqӎi@aUyc߿S!ZQ\i:j|Eд^Q@EH+ДWͥz2'oEn=6ͅs'†/v}@fu_=.N3j+ C~炲)8 >W2^Ih^bl8$j2/=m bj%>QHT oтoE;﹆)KB #/Fӱ~~DbƧ[JEBG6yarLjXK #@ &b: I`(G#3Ot Y52ij9f]Q3_MzdzJ|j"%*pc*H_X~nQKȪEPx̱Èqi 2=<6w8R&\I 5櫩o= =ޮm) {3I(mjjP 8^_x'FKf)f) )_W p؊0@sB_u~Z1pQE݋S05| j7,;تhusmvkvG fJd> {a|jlCD8P8o* ѤXa0rrLT̿/JT@NknOچ72哔3Pi=g¾OO@JtSu_g uH WRűfOe,ٳZkvձUm|>+`i'M?GMj 0TQW,ge3u5X$Yt?ʒ23O~gZ^0"_ QBR|o.(ں{Pf/̊DH~T_I2TJ pkn;m33?[S꫔d<'C3I*MBkk/oLOhSFVGW&F8mTmw`.@ӼsW2HiּZx3_ >!?3 $㹍,aУok}g6M$yj2XGuie!'{B,@QZR %`ԦdL!|EDFLqFM|ؐ>M‹3bh{ rYqv$&:n !ؠR{B7RQBvlhݤ=XhҪ\q*zeNㄛoEOӟIrY@ٲLL:Se2|ה55trf<Śz2vvl|"a^-+ד:vHj.BTj9q\EGniMq@b͒:N/HeI@r Ćt";.h|ew8rK?0f\s-DD i;swe9\"5 QTw;_?߭k*C:|7p= -QU iz;b}\sp4~NS~={=ܤ6xT6Cm:( Ʃ:n N7}4X*rzldWOW#ֆ@"m%KށŇjhƜ%303B|˾Vnlm7ߡl/[Tl.ȑ3pY7('b!Ɲ%- .Ȥib$oB:S6 x{l&W;4BY]ۄLxY:Y&(Zs*+o7S2ɳ3Z8ݭA-m<鰽BѦ !It6#4\==zB]nQmH%rv{Qx:x`HƜڗtD[BMEJK7#^N-A`\e8)QGNl┸*}pj$+.~͍d |,ח"TFOqJr0vR) Ӳ'Z#]$ 9rmOh[Vp.2?|_Y ɉj}%^YL ec O[ $ja0ZrSZohGhfJP=s2HR $55!PQ8Fbxv0$Yqi+zLΥ iM!iZyƻ:6ml\,`] ԙj@xY ]# _@a.}ϡ" 9KV,%O_k5ExQKMnaX}чDLCiv'A.Y7#$LVt81:25-p 9^H 23VQO tJ:cu0τae& `h6fҶKD2y%A UB1 ګP\_Ԗ/:iGrUDKov\y@ͪ;{:fZ%M 141(17ѫ6 &@W?<8q ]=ZnDDFy*Wf=(5y}x'[1ǭ Md($](Ǎx#ZV8z= s"Bv}J+uԕPx˗ֵ֋/>4b-,f"w\V A0{?oQEwZ:  VJ@ ϣ &H`«ZřFȥ(rs\ 35]鄂R8z$2(" qvQ!8^ݴ b<$0͋BG&:@jn$N,kNV%?&:<ʔg?W@+y{ yQ JcG`.'xsTh(Gzfof?<2g#/"ѯptb?&oyV!;Hɰw Ő(}o3}L@L!$STs̿LϠZyثdߙD9v+%Ή8|]kPo#,_ 3R26N0]b%)p5.;`IąHaŽwE*~z6aP}h%C _VlG#Uհ[2TJ [[uF5Q3zC9"W~5_lpgL=3exIYau|Y=g =iWY}偷@MҩkC1EG ʊaOݺ9R*Dtȣ27դG闩0Lo$o6TQ7E*0`c;Ciho\$,n;E%p0 o5":30[c[{̷Gs<٩迬xu ʫIDOdnwpc.ycP qWkZ1 ;8]/= t4Gc| lZn1u=b9OH-bďf."YOC-c UW#gmsliRgLmōp[bMP)sthڞ\+uRJ1eWa2 $AQBᨡy6)N@YEv e{I(Ca"]^:,(+FWRC{!K No([ېrUO /<;ſ9-9q3G\(bUg$Dk$Os$o0, sVIlSϨaW| SkR` ̩^[}h wqb!3Y4._0B5zF2ѹT 8!b{qޯ(cߖ: ʊrҦӇN"N"`Ҩq"c@8' /s%1 8XpELe2Eo_B@\"9݌Z">.39'GotxPPR 򕜩e1UZCRtNղR01 YCG p]I^))9X{"d,#L ^E J.*:K6ǚA=NaF힧ujP6xO%ef/@cj8^K \a_-!jkْC>.YZ8L m%lm(ns[V }RNҜy(Uȅ^!9jJ]׶8(^[<@]S[=veXF{<_s\RV|P !K\ ſ [Sp(@>t<ЍiH{w w.|@jXF"+lwƦ?=*nBN׎f?čś43HHl&vA`D dtvs+QL ?/-U&`"lxl>T64ZpYn|Kb[jY D̀N{ɐZQr=KϬX%k:U ">&| pTO&˝; PGtx_J |1!Z@?e;Տ` l CWʹe^t02' 9M@A3\c\n3GZN)Gi&Aԋ⏫"UK3 gN<[ݽETk:g(WXFNDC4];dQ'֯OUEw5}z p46mJoa#D);uNoz]L1 puV皺  \УR~-[hh>[eEeT+@XEFk|;)G_v bi0ʝ\:|M.iHٽ[? @oq0@O氩L@WuFòZq-3f9pPXȕcޔ/2 $.xOr#.m/MxKC[KMcrp;<PYKdy+VvPfL_fOA~i*>UhRJǩCS2oY-/VtVv ,nO t&B1(5:0H0/jt^ ّ7Ia{I7N^_uGYa$ ;W˯~"]̪XM)6 ER\ZEx!I>@)rLV8j;IrZfCtCDF'(학oX#>sې/W*\r9x]2;JyƛM:sҜy"0CW#/]ͶԕNVZ?geF2} QaoAF/~lhk5Ϟk* ֭>;+) l4M9y?zxz`hbc΂`.L!.8[d_YB)(ZB  Aj؎Mct4gy%tQ˓L` ׏w8@%2ƶ =m%-[sz䲬OqS&*XT"&H29r4j}*O}Dͧ5SjđCDWHJHh,_K܋0w +r?ChJ$e7wUW48H7S??nFQTAC(/ث?o-y|@j[G "zY 1ń`ϖ[-LL445ŧ$q xݹҗu wBW*7_suW}ZyB|ڊ(Jdo K/,o 3CEK-p?:Td"1u,Vdh˃0x D2 f͈hfSÞi$UrJ2H=ͥT8ꨈJE+h&]m/C}U0ǩ ߇+EBye |2Iˠ/*(^!=scDx/[p;sW) g&rS<Ž9Rz3z+q"%K`fxpf1|(C*E&dMq[LJ95,>Ӽ-Z]L6c#GQ׺U9HJ<@r}$m3׷@:$SߘR ۆ; Q}M\0*eGW _R'DtL3;/ Aw!h="W< }EspeM ;6#ݡ Y2z 4֜;l^kгM\Mw4}R >鐭G!!0/KAkRZOa wd !Mk nDk2jGeF:v_֚YoJ@Gybm٦ZG-?vuBiZv][ _VO|0沲<7>g4w%>y>$0>B>KUP(q0jj娄VRq}48=\c8+\Uuܬ&#I?ٟnv~2_[&Bgk7ԡ$!*^n)BW \>. oYa<3v}`}y`e(-QTH, ler Ù2 IߛbR6^@^)ZC{XφlP g(ìo`䓻Vkqt04G`4έ5? n4t8Q) P2qJӿ'Lsč`X9ϝK}?vHV:P[BIHAL%CVU=H[Y^m+FdYL-$JEL`GWLi>J$m@1lYMsAnöѿT@۰tAS|ˈc<u"*v4:9 MGʨj%9JUYDy[|@חcUk֔5N3aBL}ۙH]+6T*㷦7&Ml&:*a޿UD+/xr\%np}]n?L*g0K.~>K06iz2O$HEl}tV/Eci3cW+H[@Ax Dd_ɵ Det"G^)JJvߏ(t3NÔ|to: -bѭrd jM!6]T.W.ϊ.%sofVG'/ #Iւ?B@Y"Pa7=ɓϾnJӀ5]\M1/m~{¨Ue3}-w)I.!qD$|jCM%FLA/5BܮQk琮 d *}rxwⱄw(ר .߻` 0{*!2Z 1&9}!F?BO\U X}!RKE'v:,_Ҋ 9G?ХB_ytn~#'Ʋ+GZ4s=pg,B̕QaU0Ar5V.?nJ ㏔ M1Úªdehu"dZ-6J0"X>@Z`)=xQ's)a\q3lN\I^D 4.}RQg6 lsW=R/N[ɭIGֲRU5P=BBl8䯂si"p*qT"ېf PF=M 0W6.ޜN^Y3ES̀ U%Wp {Tsjq 4᝿pr\qLyhx=W[dlAF XT ٻQ|s'v2FK\SJ.LN ]=[|#Qƚ.O:[z=c$&sŸe*9GF%|ҙO7;"dWty X&?>PD 'nFZ^"L93@hR^|\(4iiBek$@0X䈙L{nksA\W3t[?;gd"AOEl25DDpdS!;~c ۚh"eO>ZN9?Bh]@WqwL;v~aT-}h#k)]¤鏆j4&%z2iӉQ?-590Z"z_%)}_4<Zm&˭ݓMݽ_E݁Aڀ\^%kS^;'vrY2KsBG/̳BtuW*ǓVXFXk= dD08Q7 ^! HXo0% Z.KDQV3x6hС]/|qgiӰ#8FXhK+p\^j3ᮨdK +/p3N}O,%v\>Hbjf]HmOw,H2n" @:iwFi:R_ݭ"Ufsns%O]= R. EVEm`qk*?Sf9Vqy7 X >/ Hd4 f#O{mK%aoz D ChwK8?nkhY%-^ղAiJ4iXA0wf86%鶔ѕͶ&U_D0S$kjAoJ(ݤ]<ѭLRX ơ6>$## }:g;\Rs&.C>SGEB#װ!yyBRI(rKV>VyU!3hNTG9k+-0 -Nm8:l=Wg!~qYjHVpԐʒ) mɭmI×[n!߳rg>ysD&yK9{ƻJTi(L~s*wsYјٖ&9w~]oPl),&[x8 ({,R8j4 dO2-ءuq):X˥ ' KmWH#츟vLEm򫹲&9FHqi`{l0 9%G"kphJӪL+"sHɬm;F>:bP57ͫX4{\"} a_}8iZ `ypΊb{ Hr)TKxRʀ-]`f&?IeD3RZkWVD~\жWZi9X紻ݢ5 [80JOםi&MocʓtˊKMjjZFs5w׬VRa4+5Ft1tT/莼^!9?TIʼ>K߹AKZD$҆{>+)~|0y& _X<w*%6911ɲLT_ _fkT Vѷ _ |u(B_㨁L 6$\{wRH6pUav@by86U4O2~VH`n"#*aBI$!g9\/YV/U1xF;- =)M*`f]k G̚$ _}8O'F*EM ,D\~,tjV &co|o/Vu^Epc}JȎ{b U8:iH`fP7G}h Z ^b>9DKOj¤' sC`jɻ+x)jzr[}۩)~o;C$^pͿ;rRo,'\:q/DFOI8N$P̺S.9 "@s谔32{)Sr%9/%>8<-h^"ooqPS}^H< bK(0 Of[Dp:J;Ew/ D( 8z1@%&agDlTCP8Td).cRt{bJUeI冧/ 'H`#X޹tBOBhn:ni̶q(Y_m݈ʷn(~=3^f;rnU\s 9 O*\ [|X Xn Q)7=f>Gh!0bs*k6VB|I+Z8' ǧ3.wLI!YL&nD %rN>tFz!bejʌʱt{y(ZD>hw ԭ>3l-YePK`<P{nju ?b"yuHDd mNu?rzNEpFSK0Lʼnp)p]OaM &Uݻ}[~$pңd`1rO.D(]Y\WG:_xRsGf嫰E:)N%~;ՠk1 xk޻G߫b%pO"9Y.PƩ)CK-S|D(Iov_% u#Y$G{-kg =rـu-U7Sܠ2d]M%e`E3+gqt/r޲ m{2z'lK0Ox"Xh@jOj7&jf!/ⵆ@C] I( B)V(D&,$UITy#<YոSk2LH\n萷0& oZ!t?0؊ z;$žߝdQ @p[P3\]jē F ZӫƗk:>E{ $ CPxL}v֭.^=~^Q.}sW M#tgc"'vV >KAf8Ylt!q9 exrM"X978,=! v&O"ٿP9-Cce@f3?Xxl*D9:o^~$q/$Wu9~]t7Я \T] :Zm@XoL ~S,)RnhPMͧڋ)v)BFKꋎ ٜ/;ׇؗ7-'1?[O{4b.:y0i >Gon+}o%)3mq*mmMʋ3>,5 Jzv'EK kz!<@YdcEq:T .l=]|sFَtQQ/?ASl(׀~|DYGߦSE)z1.RCPʺ &H4XյX}R o\ԛѫf"O3VF }T`.2rS&$ct %) uz/yIJg E68 /a|s6*_Db0dc2oWm!bdݸqqGcAӃ9~nS@O}O[9Hld\5 !F}I A+Mv",Cs(CbT%XmJlw`/~B-@#%i)YG ƷsRi>'4B`s*H7՞܌kaIq]ҁs ͯH`SBL"`c6`cĕpM(W;uutoN5€oV| ̖Ÿ;CpznΜ=aϣSF9o]:>mJovM븅x~+Fڋٻ2r=M7{ JnP"EA吰qpR vۖs(7@QR[ȪB?d1  |m|&zcvhYZ1u軘6X2i>yd(s`qYh^b:;zy +"8i3Np3Ըuj۩ej{-l /Zp"??Uvg Ƴ3ˣn06~'*9"k(}4"-23V| 2Kݔ 5ུ+#DlVOsnM1^4Oq PL:7>w Y')se6p?+»EV M]7_,$i2NNĜi&wMo׃=fxŒ vtͿ})W: hY'kf\.$v?4h FbCA,|>A_o("BxD󺂈@(+gz=EKJo_+H6&7v .G cr[ F7ebEk-vkH/6#OouyK eqtKU];Ջ,",}KZ  1v̰P Wy.Pn`5^(jY+yȵp}R'UM2-ż6701r/C#. = 8V׳KhkMui4B23v_Np%NbMXSZ*uLSs(3=4\$Lu*$/:i׃-elcpߵDcuv}jy#!FG\qtL*Úvo=y KCRM{P-b[V!B\_}7W~1SZ͊cNpK-EbDف^54 {,pXhZ.rB 'Emk;yc0%br4.gHr_IpXâDkϳs 8]|^aE1'~Q+uD6#0nP/M' y̮abyUnKiY@)u_R,Axy+F5lz*6p.ύ,Kgq2[G`S䮾G^* C68|^<@m PƷI~w,CB.گ"=El Ϳ5zou0Q4˚k)rG|%4c̸s鷨{VQ`mD@J]`rx's.̹'49m'+ҭx3RڏR|y~O5RhH2kn Wφ 9.Vi¡̕7Og1U d6}E%ʹqZeIz#AQ[|o폸~}rWGв2R#{PB` |`;.SG$3!Hq:F(9M='DM!x*6K%*cg?κo$T+6_¶fub_=}-QBm3vqAaIP4HtTcXap0 kDLB%HGnpEa:Ru偹w-NB'Ò7hDQW)T45% `nL9:UXxe#|g̋ל^T% !^3yT݇EFXx͉ȦќSt˶)km_ă*0lܣo E`ߋC܀wڧ4x_(8ޢdnSY"Vsqux{) ,Pju*F2]z[!:GT+ A<ߓ)Me$ul<]$04" DNX9Md`vnvzN=P)}I]xjYQ[`=&h>ssVxYv`d;\'xYB?$% - Z2>6szqūCm+3(k ;nU,+)߰IoӰEFx[^y' D?j;;Ua7oi nƹ"F>Yh3EQ\2<RiHalpO$7 *ypP &tYڜt!$8^+ NqppE[j(HhE\*GVɈ:rY#Mc t.[Į- FřX p|b Qq27D}zZ*`2(֨D8;#m) ء\&䖘!$PytS,JWZ l诳}Li6M%M* ea*(=^Kw Y-d<S;GiXR&UmsfOȗa#t/'.>߆.=E$N~VU?='ë{;y2>%Ԣuz=urʲPT}]jjr fk_B݄hvw&h+Tm|z|KfUs,BQ.KMWs&VSȞʇD+\VIHf{8K`Y$Bq)*#M,qj[S'C >}-ƞM3 A|F###p*K"(ҀDge%#"jw,/5u*Y<Q>q%qP7\Py?4iY*S('AF:d,Xdx~jirWd4gyi!8_Exq/̡% PQ|ؙ1X6t!C~"#/jxdJB`qYF[jLGo-&N>&n2Ld=O [JZ [s} ucL*q*DejnDF^Q:}dLa Ufh+I Kl^t+/l .%+MUJJy3_xQ Qk R@Ȉ7Dp.qe!7D}NAMQ ÿ=K sD) E1l_фsLCJkPEj kX ÇA()aq&k+vP_ K+c/YxrVsflD X10ZԢmCe5 ,jRF}D+їN='ֲTc)IbrLJTZ[z}7WogCoO^}KGxL3 "ԓnxmA VոHK꺖.M90'+=ʼnDcj/wPamU M>A;pǢH[/S? 3FGu(pG@,ҬMb 7wa:-gT–_"ǖAhuD&-mDq/UYmel\mW^W[Ho% [ATǪ߽A*ҲJ:vw?U9h9͞)h8_J[3hZ';A~QG՝!vMըs+!^# +X/h + ySm~Wew(O!G̇+8(2spl1ritIO_n͊"P̒ (Z5Bׇ5g̑Doދ!V i52![bkp)ʒH阉=M'zvTf?`:_}ۻlb8 ºRnPDg3SIM($uQ>^9[$(|W]qZwl6\KBWmkWɵbRm>J{~ə J~3no:>P+'5I*-J~yTHvv`o6@gΈ8ćD AyҽIݿܞh:z{r먞7bU72 d9Dbv$V2ioutD#iCQ֎ `ddY|ri&AU,|؍\4Jf Zg22$xADFӋC ώܗFqsd&eZၳJufRjcl3EeFōa͘΂C$!w.gs]lynnUmk )ܮlM cb1v^Ǒ[ovavprCi/>໔#" or3-"h,=xk掂,էl lkRyX(ۧ;t_J=Ar %|Ͱ0x@M1SJ_[2?798eH&]dx=c{/.dƠTA>mMj ˘/wC w< S10_9܄*^ < ěWwc,&G@FW@By E(S}ҧɡ1oދ͕w3tw䂀*u2Twv5%ܷ\*˜ T4Sx(_,#ЄE6[Q/ 95ۯXgSlK/ %o<-EɊP?è }AL'tu1PWx W*\X!?oŝ혧s*+^X7D^-yNTKAT5-2NZ~\@ǨD^Ish!dfM `"Pd(,dnЭoӎ%1,$RYySCav(&,)>q&IO617$Rbb}$dp|4E* v+>@˽zkZb_'D0Oc6XzǨ7 fW ֘-G tvy ~j>߾}fXT%}UwpF {ho3BcЫaѬ'1.)LpFՐlLWq7aHׯL'++޶K+B뒲pD5x{WJ+Y5X.j!BV'Q+ ֽf Kݢ΋:nAߜ#qʹIRmjp8h'D߅R!'0MqIs*JTone0;k3`0E.A[kIIo̧JLOƝdE7un&kX13O›=" !<-{'whϠsx1羝|34-_ـְ_Q"j*5_W%U/!2h-⢼ۚ6J߲_*=F;qTAgd>CD @ʄц?Ky:/6rUՠe==U1̢y#`(e gdBh 2&Q룓@{hA Go˜bƂ@{Og,AzE O5}!*?0FTS+]{*n]r>ϷA(k2ax=&-ratR .*j FKE-όoΊ^F`QђhJ 3WTL`ttpdC>3d+JkUǁ+)wzB^/6cFc)$/f:d8}5f ,#Ē'tېQR邷Ǜ 7sKvȽnSο'dIxghijd]cE9^NJaMpfA*|( ْY+hV@Cፎ,۶RvkuJbiJǩ6W"lDgTDw.U0 9,; A`r \Ia=~dK*Ƹm_ZG"Z4n<``|[Qu"M˨yU;ФR;KTJFȩP9CnZXMpOf7$?Y^]^71 vq8!wMϠxDRutꇁcOxƚ_OzWQ[E+@g?eK->K5핧(#.gj Sad"RDA"﹓cv%T:(VB'Y?N|l5dm^gmq)u4 l-/_Â"X:bdM-<']w[r4?(EFtP> XTw`f=}aA}Lʓ"r4⇕|$.^RP -JBq `tWGZF֢u{hG ;@ńmZ ({i##LIWߞJ Mc{)JmtҌ,8DvDz 9I=Dyۤ6z]OTV>y~AAb*4Q pm-M<=ѢMGj>Labd0,HGԆɞ'wXTv"jQ[AD%g"Nsa@^Y/O"V:u] H$'mͬ٫'$ m6e`.i:hYT 9&m1~]$79:hhºېuh'-[Fͦ j*2 2Ӹ3{Jᶾ1}iG>,Mi3DrVm X^Vt9reO(jtώ5U%zV2vzuȍy;ݗ֢ چsޒEJS5/m+su>&R++Zƈ2^j!%@”>D[0B)[Uk核K@Xl?~hZF r:E{2q$P0Y0zn|ₐ© ~T]us=dKMnV/~|u|"ij) E*EJ+ g@ ,H-Y5ޣR5=GjD(R R7ы]︇'q떡(+(@4J "J:al `Z2Z<CE90䩒އJck^WE~Ցەvc8M~t#w6R9`63Wx#BIG% Yׇ3I_q-Z=őtjW{va:N*\w}VHQ@Z^-*r\GIi52Z[B0;5։^z]u0ψ:atvт"J9s]xl1J$PaC3@uJ,<^~VFM9BBʎ!|H"1'U"ʾo{,b>겇i`IrU6ךL0\C+r)blف)fPz_1Wu^/51g^_HU:L3ctMga= \ 5G5 h~1?}2n k)z"d @M7%+Hqw?A؝^txy$Ax\HIleT{GgÓBқɇ.0fIymp Ԫ{Hw?'\N, O;FNL qc~W |,dvIwP+"vqش~Dd=^'[dbܹ%˱*c}XG=fQlCZz)?0<u^q<ܛOcشe 4>F}b2ڄeg̃$˃ 8?OIv+$'M8ux⃅7p@ˤ3;UxYBIqgRNi}s|$Xgy%z _V$a`os mg*"nQ9yw.9w݆@syM'[.*=t8_HF@tWyNyG^w.z4oG/aq,j>j*Xtc:NEbx]Z]6Q W{+Y2/y{ EF&[Hh\tg&!Ki>m>j:4- }~j`5Á%oCI`u$oY !?YkX X3R|'8z:8YVԄr#Z% oC'PC'tؒ?[]!Jv 29"&6+ŕPK4D#{ZiAvx?Hl\H4%t2i4E)/Ɔa<Ο\Hsa+$x _ܗ/o !|b}i|뭕h2fA)Xp>`dr!izDteH?8qM78m79;oX.MB-t?z5%1I c"w9;GA "o#M*xxND92:#ψJ_fYnJi+]ukrQfOsJ3]8䭉m܌d@W^R9e?A7^qkaHw-.~>TVfN?R?Z, ,!GŎIkavk:ҚuJn)Z|-c>X u$5 :)lz,ڦ8CѪw?ِȜ1e$j@ c#=s rٕeP.j\[[*{T !'ae8E+9>` ]w=_X EiS i\eB)vckEThqU5*-EvulZ dfF>'X׺;hֿ<_*6A ɥ$#{NcoL 8IZ tP#!H눫?D oIa_In^7ZgagH] {i X3f8\KSӵ_S+:뀛(.GvAڊ1,Ș~44gmg>O-*$4+ϒ/~6ԧFkNgh8EYcpehF-j:}gn[CL? cS֊HxfSofIv=agRV*7o48+$:NdM[fjA%A}s',%OPN|k!ԓŸfA$q{ڶq+W?^`5t-bxR :;عJJjs@k%DŽ=q!Gi+M!mШCF&GHA+]B!Gi}f\@#4, 'F,EIH5@Jkq&[RNNIRف1@J~XYkGN>HY=ܟX3Ml3D}Eu@ ,Θ7Xثwx%ky_h%ezҠЬ)_ 9%WCt-1B^1S5_YϐQGrb܋|t[b87upI9) un_<>CzR!>#Ysr>vt(3j~[J ELY՗sY"=+F@ɏ*Őmqnu7se9ظDtZ.{fW Pw,Y:/2U0Gkne&40} ѕ,q2r 23JcP_f`: 5mmO=Q<>>BAQ`lq9Hm_ 4BŠFu;)U\'Îl U4W7]d˹v?>:7-W!'mE5G=/WS[[}-h`Ͳq۶LG葨8?V݈59NKX+PA]zE N~:-c·V[ׅ1% N4$  |~5ӚI#cu7C .EKzlSdE,^FN)59$"")8k(4j٘N k#W"mnmLbk&Xd7U+{6y~E?OL&D)mZ5)FlOԄTp-(Jc!}$I絫ϦМ,ܤ[S\κIAT_{?hrq]s#`AŖcuEfK:,aKRd//O v.sV$CbыD駑At Kvn8mX|;9y#`ϮZxyhB&jOJ^z߫ڙe Q8]:14L IF\Lёw)' knX D/Dxͳ"l@2ho ,|9}a!T'yznmbb ^e\^88tWЪ07XPZ Y?rRjYD)O-l'>yeVQ;L'Ykl۠_DO+0'jXlpBHhc,NB8L2瀫~x|- 1H]&=Ȝ!{gh?ߵLgXU>ct1Tb(X0.4<(K8 |@FKv/tF`?|QnA~n@{7~5Mq2 87&iቭ ~qA8qV< \mo\H~uM|`}EKMԴFm:|7Vm.E}Z3ѽכI:Ƣ ?wշmSpF.yS- ΀'Ff_|Iv TDch,N^e}6qir֒q]Jgy, AT}Mqw%! *vьg#Tt {0}P̒v+ o" NTiphX#9"l,aȑ[gc"$@QmG@,8NCaVօ]+ ̴R N؏{~D^!e1YAU~ 04%GuB%IUɹ쐁]Xo,d C|hDF,_2?`͜" ^'4n+7WuW.\T<:@]z—fArPP})3zn✆ơ*(n_5'I}mQcT5dL[m煲sc\M,Sב $͞{nbdŒ|~YuZ' 04=_L\*#))ZFAZߣP 0V[nYB:|1{LAfwj /ynkG]!2( T1Mω M&= <30!@_ 0"ꁇݒUnSHj4; /^OţwUp{.\k]1d 0Ge6ynI҅ۆM?8m9K_t@aja`Gxg8X b>(FThi򦶢{{ٹ^"~or^f&EqUJ1gK$fNz(>$ܤE h'rE k !*j~R|30Mۈ] ;k6FOCRx~bfrF:lq XQd'Ĩ\Ft6Ng4hԑ-B Ovb0S[LSv7Mz()c VtU3W"}/o¼R[Pѝz.FM6gyE2វ}7v ݋X#&pB%*NF9f99j-TOw\:~1) F8gXJ;;>M03*"a*#ţ8[s GƔL;5'e‹Ҩ؄c }ϖ`d͠r(tu=Se+d e|\,0nOM_ 21v?6GB7*"_jZZL *YOA%})OϬ^Џ{x )N~nȼ4M'fVqɼBwHCrfDtl.- .%UvDvpC]صq&- sܮwK*0 T,K䉟 %ml='Fs3,c aXG"QۋoB(&tdNa<O~B Դ4eGxlƩ}*`{Ȏ^lU=(j2={P5Ȋu޸ l<цaWKp8E7[ͩ^<Aq=p[qiô$'W_T<b߽& }bG[~npuOi‡6Ҡ%_qkɷ[+qx-'[˘!PZZמ~@ē(,u(wQr:ş=*Rf]V@ }ǽ{w kV1)'3uPdN8iHe=*M(Bp'М 3ݱ'TxzOkL`8]tJV[H4/(.ܸa0q2w g@nj+eeϕ֪$B.yv6 *Fͯ3/agduLjTS O `8'09sˋ\ѣ˲rd<=4dt"αt. vLl|4&r^g::Bw# BrjGsh@(.Kd%Nт+$9>EGNѵ0)YѴG s49\K(@eߕ Mbxo[HOK,ˇ6+1Mⳣlke< j;``+Ajkm[g*U')Z'_-/fo$!@^ϠZ&MF &P1;OǒGX@[iFݚ \{,ܑE>mf,(Q3ή{`;oj{MmO0CG$;<O07;|{)^۠[EzԳ ؿUp AI,N5k!vE^cIa'hhY2w{X>EW<$: oWI3OvkIs+o,9K%7pvR+ !>߽ ]Wt#CJqYgSmu;*B[0%6%Ͳ^V_Mi{)6"Xܵ[2U@&/_ikNmx}%MtZt=NL+ݖW@,o ? b%OVkBM4 vȯ `PՋOְNfiL(KN8 sgP'z"?CsR-`xmR V紅tޓ Sݓ3 =D3cr`I8R77|O6vN '#-PFd'z;Y k2D*_a QM.ikuh˦y$54kn5zyI PFQ̅5d &!>#BFC'T ݻ\ʫki}(n;7ڼZBj I!Q"Y 3B{ ɍr×9P'0wث\ ' ֪9x@4hʃԬJWJ"JeJǶ(2a?(j,vOp`aZQlVS1Ѻ#\)#F!wh#TUn+*8j S :bFO;~@b*0AK!MQ : 2Q^hSPQ^r¿x4} :9TN٧iU%a|ϥ{?%"i4|tijw<$0t6Jx$>6:+jcU;"[_ 4Gf~zZ5+"X H֖?Vm=;M6^4T~ē47(dXvsr35nGEӚZ4d,x,У(fƈϿ1sF; 0d&Uh"4Jp'pԣm8P5tE mR b< p}WYOc{Lv?2hח4D XRGR)lS6Hnۮv"J00-==BazKGkANW;D%B*X.T[ bM/C;Kz;\oMp=ɳ2  ixIQQ$/ŝ2Xf;Cɝѱ?cKʫӅ!3nH۫Yj26 M0O+J*i [u3eY҄ZSaGN&\T_!7E*LZ߶ 6}p@U%zx5&Im&d$KB(;.r"xTUϐ 0m@O72l :D4 ^5*x ,GW֖,οQj=BUbﭑ9fFM-Xۥ5u_E }Uj ItYSڔ/G`F8qff3# K1HKm;q_I H<Ҫ9PXH mt2#A`)- U$%n:p w`Wi۩8G̸=X!sCj0.-f _AS{G&q_T"T;vSݨ/QIH`kruGk{0m! .^ڼxoCZ-[9CkWIV,#bG* L7pIom {}Ady\qK %@Jz?Th)˨d9FQu|*(A2H>Q'o5DG->4SUك0Q#bS@'Oᧁ<SO DPydk5u}NJ><*(G^x`T :TMl:'ntP$(7fP􆚞F(ݕgh%4ydh 5׋ĜVñz g`i {;QvӎT2zT.Jhmʈu`>x 8 ?):YKj[}:aΚTT#مƆ֓ :#EQS1aoՑ\ ߗK0[ a*#\nPq~ҟ&9kqWdދ^,G + W( B,+p9vOрLܕLK4f.;vf -=g`:(j<]HG(Ii+.;Dϕ^l- k6XvC0KWVx!zLu چk9Gxv+m tN!~]Ĉ{7?k*_5U\-~|j@FY ITx Ί"oD<&“yU]'%\JUHkwhrܵ33 n|"u4:1Q߾ iPvʊ1XIg`JxMLk#-Q~S$J۶4@ sD3}gO-'NcX(aDV,ŸS#_*nqXP^ r4!m`!M>V /NXD{Q? x(em0?cqc Y7-L|6KH%HTQF-LA\c>cL H  :NNa w36O?}dX Z"q,}|8#XT(W \~/2f~!#qKȌ`dl#~lbek-_,ܭ[Yg\䝻r<_ʚB޽]vNt'1 i{l%䔮ucTZP - V 0a ; CN2tGZq ֕-+*1=߼LRY#;䧓]XUu>?ʢ?g7呓y~=#Zf⧇ͻVn:Zjƙ7Opx)zXN!MlAj\a{ymrDj:n>;kVb%nc_OC.lL^s<=P8;3V$PfpOprISi*Vּ%A -#6*୙5A.O[] n6P*T&PJb۪a[4(%F0,l0iWuSTr~9C]sbj6j)w72Bua~VXӌpL9oq)~0J_H:E%:$GЍCFq]7fnU` 37ӳN˃vBʵMg?z=|i h`{btP(d@\Qmݍ G}nE3j/~8u:,rW!XTΤKZn&qq 8NfI.aMxpZd.ۏMGez]ߵMuh;`W+:h^W#[uS A!^C"G_kOoc|La~2Űg! "Pngz,=Úꓖ@](<¨gTh4F \5<-_FX`OMf]_{o:IKWcAXj1IS Ҫ`{i",#繲M\*#r Kc;3I~oɃ4 !wF{J=ln'M'6U{%,)^ D L L:@,S0E,'9mXʍ靿۞îG|I}DBE4?GC`³=OQlĐiNWV<nRtϡ23̼gX#j S  Q2+D<՞vuUND:.r ~i5 kZvAL$>u#PBS/±!41E r*ܵ:E8U/ zrMofH WoI$Eᇄl2)9iCn cZgw`l&r'-%v̜[TP]0L1307X!xFo_ 80.3sxJR/N^]AIO3ك{ٟJ&B`c<2MQ 7~hemۇnɣ(ÿM!)(d#{XVٟ\t:l\9E?0*(HL9Rv}O!0]agals똝%< -%;Rv :oSIK)t:`e'SUit}Z؟1С:3/cC\2+l\[IƠo<X|xm:*]M 1VҀy=Nqvk 蚠\f`oK`;[\?iQ'͘1_ÿގb&jm @1ujAsV.Czpy _}-0k\L\;_*EE'Mʏ| ˜7e26,HnJniC0Pz*m !;ԉJT f9Jn+ӑE+]ǘlo뿧ɡ> ӟ%F5"@Ӝ05d#h(V$L1`e`OFV6o3,/5N?^_I› KJMEJB6Cy \9ctաk=Ze' ?F2c 0޽¾9M2T^d],WFJF 8:Ӑؓ> YL(*~'D'kX;5|?ʚ$M2_>@k2D6_R٧uؗz+Y'X?u~eD84fcE$(> őşsv|wҴ> 'ܳn]LI!ǵ< P.(Eh(wB63x"rz ɮqF #"2Bt`ymZ1?ZX˜(48n? #>iRI 4t):M4ɩy:*u1zJwh0LH}{jv=9`.8 c00Hei '91#'5[~R-*Q#] ^ɄAV3\v3kR(^IΕ+VLYcLi/<$uL@ڶt#b D3(8)[ gX5oy X)-H ^~u#dUOX-b[OJ|GCYxXLoKco0u&ouΪ U ^S ziɷ ҇5LGOkm}͠٣[*Ԥ%PօxYV d1٩:8zQ2H-x4kԮS}sIFTjJʎWn`ASCX]-*n~K\**];yIoGHd哧< Z|SRz+0\%[}__o击"OAvfyp0P?2-[;;bx+ABP;a(,t9A$HᐟK!GYy]+ۖ_LU͜6IF:)Z@,^Q|"f EnLYF5 آa#ްݏ A1 95,jD/&5k=۳*WX;,><!ї}%L824A/9<;Rn-,[4c$l } q,|Y'bt$K$)DqJۨ 4^uߨύtx] #$}-NjQ~t+ƒDfWA>U*J8Xp8YH1m=-A)BU$R1XDdFHt_u{p\ʱNdy_9[SKs_qb6{/RxVàS= rݟcH쀑#`!\Qx}aZn1eXB7 u ?'P4vU 4V;%h2 >XPU8^`z}Yd5Nc)*0rzKN]. Hr^Xn%C0D'*H`\fK":aG.<4+ 'g՛"q"/DMpf?Y>2[#&;?rJ7$lWAt8ѣy,4topl yd}DNBCqqv3ed?[bV y(c}*+f;E\;A]T̡革å|qrxVS%moH T۹8e<SEbEyXy:4TyH W^9ObKB)Ԭɬ y X"3iB;Xl5|L]_)+7 镕WB}HYi,k ν9'3 k:{9 *_~HN;B}MIo]h:ϞWO;Ura]qEB[bT2:lZv LI?FqPp۷sD\VC> AA,,X09v`@/^xW58O9R{(oC% ϵMsYCg:$`i0ܿbkk"PJƳB_s̭`N@޻rp\\LI^Ax2/ظ3n-2,N$!*I[8a ”v6dT` gUP#kv+$%[ּ@KMNc8n4^%NQ܊_|ڜͳ@쥙pĠ;ь1 Q׌Ol\~p"uA ?Io2"zG*"GlpQқO1S+3J1zU:oME*wN48ųдApǥ(tlޑkԟCtW?4G;boCr/4U8NKH@QDg 37z(/jŒ~IqT">H4lʾ4FT2D!LlQ1剅?G/yĶSyAʊQDH d]q8'B| D[fzqnz&'!Y(S n@?W A(МME]=;GSR'UZ :U$'8u41FEuKYU\Ml[5a7^(}Rsd,˕5 \I{P&)$%brD l\gYj%£16*¾T[!+=7Vc|Rh{zM5HNh\@: *?(im/eA2*)Q4C+t[( D#ZV,(+bRj uͷ"I||A 5eC ؕ$SR'nuv.R_J3#0pE@(7f&{c ۙr#*} F;jwtI؃\8MdNQ:geO}7neJt@TrNlUTJO ,) 7>B9)!W ¿D4ɧyψ(lbGCZgmwշ-WPCvQ֘m 29; S:)Ip,~ ė8Fl#byxW>ίմsab,жSGJ{vؖI ]o./\EYdjӈŶqrXuc]Q73oq[(Y%HmA2gm!5@ȧebBDz@E&ޢhU%*'bh~.lV!!oDT|K_Y*,(C?wdMb8VM$3i uتp {BE+jlo6Uh Z*nSY㏔Zz,!]kϜI䔂#7~1FXQy}Xy jmU!t$MkζX5<01TqeȢ DŽ i4LوXgf̳4R >R_fnpX"T6(v+6QvEˆ\]lTT])a*zm DeG^Enb*3]oz8`K 5P;,R\`Fvw/+QȽ#4M`]DxYxFW>GY_{pb*]B]yJM]@2m%`|lb&E[:HrHsG%6IIFE<)}?D)%%a3 fsmp֡[$6ܦzBmaC9c@kCSzle(<|ɄeB ļR.78%M3vS2臻3ȃ*;C[-F޴45B[Fٮ/w> 9o5AףN4As; kid&Ѩ첛D'nJI$6ڻŜBPtz`dΔg,9&21&UY1ܸ 򷗷E[v. %hɚ~xbٷj$VNeО.L Dylb#"uGnCDU Ն߬eb>"nbd,`UI? s,:5_+U_ 0~º(H/dEPAg2Ű7x}dKG-&ukOㅯ$^C_?WxmOz=CpThiϚf Ozt~6n9xz37ks`PK4gNDǧdG]~ g]3?c-U|֙뜅t]UϤ(uCj#腬Ц&73(_MXuOk6VL\ߠA^ϝCk pa;3I uelx>zor槣v3/ wo)*NE\6)Q_tW`#z¹vGtӤ5 $IwRý|Ÿ e7GKD'c_FW* .5 QA qfW*=ZT}_XVtli@a9D<'$H:̶% Hu׋œ/)큸ϟ~h,vI KžØ*i?'?N@}_B[Ԡ -3ؗ a$uBF~C`G&ק% Wƫ`W[Z >Zs:,j獩*K14ۦj=Eé.fy|Ft3bTU/ԠӉoz&zswO$XǵeA84g`xrDjǓI'rwZ>rư=*[#;U[pCd6t#ħߘfP3o]ׁEI +_t-kXX s+8ĩ$IC_m!3cr Ο_dq`Dgf}ΑW:ldsn>6* l֚'8m'e\ȟ&r&O5kat*İ ęSXCD|}XX{Qs1)5c p+jT 5x n +{uw~_l:`>8 #a=`5J09^T0m}TAE'_T]}ĽqH鑌`灄Yn<aқ{H qS T rpes }~laH:)wIO[F q,-]yI*( X,={v'*e褘]M k-HË܇ ki}hwƏފW >kYGțAÆ^GV 5lj$ڞކkqjUPrc:Ydܲ)ɛO3eVB 0]#=}$ebFU |~eAJO˅u9ٓ4ODxQ\9!/s#HKI]JNwy{5g5xd6F8l$To_Bī3x,Am$$l>N7 sˡRES<{°q,}idr-K6k;gRjPxr~W4'!k65I*ܱy]/a-)`E4VvG(O!fޯJk,ۂbq[ġȺű&ʭkȶJfy߻7f[ݣJjcXZ1zKtB?7d9xZH lfϼяͨۇAye[+7h¨h୵kgͲ7 &N*r܀GnZ9)\eJ%煩M]j6,TIkn]Nj4P^ʕk#ѿ@KJ{()eDǹŰylLMvUhhHTut@N͑aRo.83˘ L j4GEP>8o,QWu; '_:3܁|#DPv\HX!4yIinn2>%,g(9\N˿+%+ a< t(/j^?"Y!S%"KG(_AߕɜЉ |+W \;k' 2 92UUkB6?]z3`XWNҝ@~L[7TΤ|.+˥TYzYC'M:K^_tmu!~nJQ}dsE! 9V}KRDv /Ce0Ͱ7[*"<;=H)0@NZ2# AG1x>N,Py2^-]~Jކ}xZcw6S/"T9A\+(d7'Es=l~zn7 a 5x9u7>z^L }"1K}@3fi:resl.htԅԦMjG&Nd*HaylWE .멄(V(? fL{(ү䚾߾X+)18(OQ\f@}0KN&kES zvS~ 4VPfߝ'6Y2Sxsw8; HZRэhM)4BhFd4VO%5ڰF%5z9U7xMN$_C8>R+X vo$)y2C G8RC~wVK<E5WX`[$)Fc{AP;}EEkJ oĮ0[E^T`'4@gg ? -`o~O9EnĢQ +p#yN&;Ty)7_hDD )7yÔ[ǁݒ;W)rJ ` _1t!\y2yQJY ':,o{8tDF!*mZ`s߶\jj$gꌸb򈠌nڈ'062 .fRT\W+v6'y1O~:wc&)_*̴{mI㘗*+9rnJ ?yЯV#@b4%!ci "#7*@}^NI)-YeV̄vLHHD$}~+3)*.wߚ9[Eec)q_ĩ=֢>fꂩRdU|{2TAu#AJ;Bx,TKCx +^if^1 -:QͅF2.kיxD)KeO|e9Z9KeS)=1Zwe (.9XiK0X{pƊ0y Fr6CaSx6k%$v~h5b! ?GgU:z~Kb/Pt2.8AGSd;0.AVy?( EŲ[Dss\¤f P0v?tŇ}qLA@0d`I˝B̅ڌw՝ .6xi,E~ ${G[fG-(/ǾB S?ڣ ,3CqH,tCu!5%uڇ>IB}p3^ pQ ] .>EFS#5!\ͩESLU۬~G, "Q 1 5r: VasF3&X L(f>@P ,4r϶'9l򤽊XGC 4?{-%P/q9o]+2*U'hS؏H0?v uNe2"zh!Q؆cϷnYW3XG2u6֞BDXRg瓻)-m1CP~S-2񦙝 }2@JujǃJb^cKDՀO?A9K>Q, %Lpa)8zG>q@KywR4ܽ]Ul nYUQ{.>qa@R]#zc7r 1jі_n%Aaͱ1wMtg_rcԢKf82S_*?-lt݆fz(鑛g@q/(0_ ϕ&.1 bꎍAٮYx 'g#}a[fz^{p >Ļj>Ǎ"AϻjUNҢWZ^!6|:,(tNMNv--3QU'\UyX@gxDqHҼTC#IP rٲ5KJse[ʒoZܨN~nfpow za 9N}nB|eAx sB^C.{F*"A +]K˓%L?V: .GXPu@}DDNg^l.Pۗ`;u# Kju~_x^H"Jb綡5h{OoPY^҉E%"=pNa}(|L4wny%Oj(Nh;Hbu .YMzbV _7+鱩:#$GN*cbݻc E==WDh4BGQ" %2#an)g?Ii5o \.PӁhmH]&moXx`20&g' rg)f`߬qp>FH\nb8,44w(Dƽm.4n!h78Q'ǎ=CjMS?iZOrkK(jEveu8x$7#Ldy4k@l꼺N/*:S/rV+vvt~If 38zt"OFF&ŋeDm qqw,}p t6!11x(̌e)d!a!_h& U^W390r=!)oV.g98bĚ5B쮷t.e|toDL~N=%1k 3* bsm!Ӕ,vŢ?0ҤfD(pɻrlhd|uPŸ?@d;Phm"7W]]^(us+8(GDH?І(lLHwimwH>5~ ^ekZ:0*8ۦL4l Q\\l^Oh#Ofk^|E#ܨ|wntOGzF?f/^f2is09%C6# C_6 Hi2[;Wm@x\?Ӿk9a^N`!A8$jL #*J4r'ۀ!9fREr?˭҇xaLfW;A9 i`j_TH?kʔsׯBAcv^m;G dw|p{ Iڪ-G2;F') jwu 9~?҇V^KVw4}.|,2":m&9Wå5>t,UNmƄa7>GROϊڍXPFncVOr+K[SVe^^w/x÷,O"Y.ȇPQQWޒ˰B$>Alȧ(fbT9n˳X~̔:^g)A{rj%}B 7{,7/@Z)a #HY,4v_iaQ'؆{ { 6pa2R~~Tر֥iU(61Uu7ltH\Sz۰*|#xi*ҨUv# eiW駠mFx|xY]dLr8sr;*ëXz`DsC&S٫)㆏ٺ&Q~6!Fܠ NKX21Wڿur? Ś)?KpvH.^hswA +ٓ\CBt٩|I9WYߋ$?*d9.@k߅Hi3c U5\'Ÿ{| 4׸p1z6s13Q,E lz}P~&ܵp<Wvs+ n8ɿgE浉hCes2)p{E 9J@.XA,V?殒(AhMUhp;;]OwT3Zb_E{DIuï!|& G78[2C&y" Xo`10Iռ\&)ŠK}B$!&v߷\ߑ;CrlYEU6poC i[`Rp 9.,`@DuQU B[gg<߆ܘi JSilA[brPj]u4ESN:x4K$)yhZjP2lN=&5!oi-sQ4)+ .M4( .39)"D$h%OϞtqD*ȿP :wsŸ԰DLQA̮˝ )L#rv Ecq~ymEq,uDOum)'u(kРNņ렝hMdN!fXBHjM^mCX%ˎ}}59)wVCjs ȅ(kl`K*mv l^żNIx})LQ,:Tw}op4ذ`Do k +bW!Th5 iaa×;= I?>^N ;Ozh<ɷ1sQۈ! 7X1ElymCe9b"%k-c`vu%[m!/nKE~Köj$L1 7oix@J N[TsJωvyxp6NkdW5S7 憙11 ҉\D-!2焺UIXЧfAYazp.S=-N.DMJտh<1 i7~ވ%b'BșE L 8ٯ0mMCsqPqG!_8WfJnNea~? Blb-|1-Y?(H:aE;i,JTJ E0ys?yP(e'Q,TDaV:(Yň}: +%0(fd%Kjʨ}.z (Ǐ˩,u9}m K/*e'P;䀋vWEȸ~I!d{iB1' <oĥGEw; 8P^5Ml)ޙ;2)qYQVKOy1jJM=$2xhc5%nx.ZYݴ`T]wKGן;)l*g!%գ%dZcnx5%qK~ʅ v!!Eۼ0 bh*VAeٛa|Co:a1qKk.)ԝR.މK%g^x?f5V#%?K^^$]Pǐ, eDP75fv 7ը ırHRG73(Q`+2^m9#_KɷLx0VPrk*4F3wE՘a_'".Sn5_d98%H~5&7.+ctCp"sGk[' ]A2F=8T7׻~#5^r}GIw3ͨ|(f pJ-P_B#cErѼLzex)p7Au.xb55ndB'!}Bk2`7 {emkVNKW'4 b° VwF`׿oj!~BY 5 D;MFe>\J! !tg94BAڭU"׌U9A);CMTC35E8Xg@+yiIv.EP> a~|V2U_"%~k( WfD2r,3W"Q/'`acD`&!j~-騑;x;k?~PN +Z.~ΪNkiNI$ϥiUp~Wԓ 4r"|و{cZݧ1MxjȜtLQLmLXw臓53% ~t~ n n1FaKˈz/t0omavVҋu&ɤJx$Ѽ Ҹ9e(|cIh1lY хz8qeG]26t)D }W5ړ>Mo]e_**oxzĔΉC@ 2Sfqo5vDpQ1l^-sl;eta)(c tNL<[/&!tc+Y(Nz%{[&'v1Ug9(X#Zŭь:\*`-N(@' 㛋3'pR T1aY̗ 19+@kx9`_*t LWG3.[kMQU{QFꆛy_f+:k"T-Yҧ+F(,Uns;L ! ' CF}$¯dkF&n#?ݑ)VyΣ,q96Nʇڲh$ 0nX`B\Fa{3ʔL8_޾I 'r]Ca;.n$[vF ~Fwiof*2ȀBJz2LlNC kRi4jo-*">Go0#[-/\ΚMύ2s{hi]_*&XCևy6lA;U8t[ڋ;B=ӱ׸.lt ije}YL+w5ʫ=@QBb\/[5=5:>)0BhxwpA:_Eqֵon"\$;G?(hf=k}[p t<$v&="sEi ,]pV)wIEIo?J-+:.PCUA޿Y8ͬSkLQf=I9U~脲c_TU!5Ys?̈a'"GY~#V-Q_"o ؋)Ѡ%P`i3gEf,#Ž8 !Y8qj?PCDauEf}'9J,6՛ճQqluŠ%s,pT&=;fژ ȭ$W+"_]-1$=8:KJ9v%+uwŽe!͕<{yUmwr/9.bEO{ze,NVJ5;`M W5i Zo{'^hD‡Um)M Fg[Bdrc+h&X'W7k+L۟nc\SqRC:q_g.7sSB\t;{ Xp̀s ]ˋ$S%UD(>B=uޚ,k]W#eKH~҂N =k=tbfR_j0N>@w/7ؓ7 14B>kEl.CQem}T/.N: 3,UGMu ۬%qv `v^)^l 6bhJ:m,6!D 3EA^T[ǧ;G -;$ʽݦ&u!_7LQRVLҫ#$,RY+-xp\bʂvꇄ'wWIW}mx&CQtG 1zkzǸ$T^XiJI@,Ok_ %m{(}}o~L=*"&;;uJ͡y?[4i J%߶"QRl{("C650fI rұ1gK`˱t4ۘ|I>l[i ").'&bƫKU__{`߼)q۞ D潽(* 2]ɰUg8fP+j9(fC`(BN;4w$ b+Ry6#W>V`!堚KpLU*wpYP=ݟK1 FiC#-coL,g*2Xo>RMӤ$IB:-.oQdH_a~7TkNp~)>ᖏ=)NQ!(XaӘZm%v-1{sЛvNҹZP$\;D<R>y9>ʞ"}qμJXd,wL5 F15"G/+701fWۀE1u "7\k+Fs1Js!|ݜzU Ž\id^-˸Ì\{/.Ŧ"I=*( B}`$2  ax a[09eҘgݔϖ뱼r⭷)жPkSꬶTž&²իo.qZo,AԈtS4b_ fhk şC.V˾~>gOhpIŁXw|SĝfRQ5M:!{da"';$F#k^6TܺT#ryf8xmU?b=vxb% T͋LY,FG0TwO͗3w<)=SphrqHH6\Z $\jqԯ bTCGrPKч y14xې]L9*cԫE.+W5hWr ~3pi[ /BmډQ<'4;>YƉh]>_y ކr%LYE#,ݣ ش`e@Sb5u&ه]`PAG[Qf9*nS3/t# cӟ0[+QUB2͠Ê_Ly{\mpT=Xo]%]G5&$uS'3m_7@6PwRYzWx+S&EE>9]},8R34u"*_1Q)pQ+h;MM-{!+$dvM>zRО2'I=jb jHavp"a$XIQȈX#%[o%jk#wT9vsx3<#Pba|Mi{)8{GYN(`$dCsJ# +rzT֧'qAכRp8]Ņ{peTq\VGP{Em!*Y݄6`Wyڤ$Lz/͏ywNOQ]蝸q/l-)w_y wj4ۺg}I mAIUuDxO>W0w_a)f`|Q 2> Hs9@i{a^&DT|}H<)%K^A^3=} G[1kP4"d Zyb1{AZ0q55#h&zUN$U: r.Ԓ%"{_X^CEس"=qx/hEu}[X%\}ZaͰȠ҄a7UU4jFW[Ƴ>XI3\DP5 3nS 1(EE]VzW`FQ ́Ub"O \@"TozEV P%އܗa'.@y585#Pß\ :+jQF-&Z]~a Vt^'7:EP{_w!H :}2z!'h_j2(6pAo'эB5H;ec16Qk45&U܃үS Q0K"+6S }rΥ=ݷ??Ru_8 ZtSu%!ͷFGEҀīBV* rsEhj&3{ u"eT>X0$6U<ݴ9iH`'E8q9ɲoG|X',hrl|k'$6|mI7;E!K~Nx;-f R(DX,I])J8ƅ8IX#CVw}҆YuZ/6LKDž 4r2nPN=.7&(NDSR~T{HYL[]TU3 x)ͭ+T˴ |ZO#>/+FYSٌ̊ _5qT$78r\6>=!3$MotGRLRM`Ux\:6ϼ "@I0g|Ug"?o)Lw`D;`ًP  ߪfUi,?E^i;c&!?cHK9÷ѭwLg=e@UDJvh|,68Ͳ(*N6! )qrSgش/'/gs%s0_Xd02!sY탌|dAVUx ]`ŢVqX'4#9 g>uJ5oHY^*PҒpxX(-]q vDX~~Ϫpi/!ض|y&е} *~zD51@F_хduݾa٥J!buC+P7gC~_CTe޲W&tcc~tԭfo;s =UӉJm92˳ |gB:>Vύ T٣"XymQ3 WPsB,^4x8nz8ƛ…47Hpw5UiWN2*?pEBoUj2>`vV]=*0s?A~guoɌ~U4Ru' 7xŨٱLG&wf],ՁaU0'~c0*Ƚ2e};=alzjq{oJȫjN' K)/ܯi^ݹQj7x|)`;{ڝft ;uR P>m90ddXYij{v݋2TWC>ku Lr%lה܅ȼc2 4 '4 =W@r7`5NүKFtA#3z\p+['<[DzD~-lܢ F9:{(Ӧw*d2{e =ŭ&>s ]{s@?vu?Ĵ_?sufAh@$DC㜹 ranԅ0Zn&݄H%>zO$C8+4i1idK uDIf0]_HAP*hgغ4kaPT,uMߥq8j=[.Dv9D'EXU%!˳ *U//&I|i ]Uvsw3畠IwmBnmf>/A]jAY8%E4_VwRl=:cIzd{L1 |{8_a(wDL(f͘> ,'FUj孙9ʠS:[M_RdtVBﴡ +]+Xf+G׸ٓ*4rWЯnPlj \G67aKYڗ=GD&<#sYO@Uܳ;픤*F dR:sNx  @"SڀOjumT@XgиeIՋ]rxsL?ڄz*b ˲#+;(yH&oOxv n}\o"cWGr+:E+ 'LjQj|ݫBCxwpǔɉ@tcw:X7G|6oAFkcz2l⟁7$fdhWҴak~G+S E{*/ٗ~􎎳Ċד!|QIPkp"ƣȱMdZ_~5! Q!~ #Ib8ة^Rq&޼'=VQpS]]fl2E~If[Ԑ$ez[A77 7T*y#p+CJ p/,[Oκ U8zY Baq0,E_mZ!1j3^3wnkO::VqK" .M!`PY+N {tˆ`q&p!߽pҹ2KlZc"מ%r@z{JtP3=7l 'HI4SÞ%d (~7;Ț;Ō[mfuIMϰ n6PȄqEAқWGCvAmށs/z,z:/\8 !µV#nW@ 5zF . L{>+Nd`P[ϲ[".6 a&גC 3Q0g"Ow'sXPJ U }%&㞎g\#˴gf jHT7* QXlv¸l:' H5lo7Ci /( 6#ɀ4̭kT{mF\ZWS-(UF8ϪLr:+27IR k3!1Y!(:W Q~*ޅQ'|mq2a''_)7Nm@DEyHH@#ԙnK僇?§)@8JM\z,ERr/qKsn\b~h YY^يb;%σ 8E] yMYd"7~"*DeKdK6R/LXyu|\]7ZFO$Pda%*VN>^S$o GhdJ+ȫ&|[2+1c ܵ~8+] *:f̨ :%j;W/3%N\ |Dұ#$dDGj(6ּcXSHgcXHXr7Ztthj̐"^^ w 7uniqT.XҠ<_<B>Q?L\cy)}|u4grE&u^6}.Jg=ԮAz|3_I;C* mza%&( stؼX3]:62M9wUqɄy/rݓ)e(CM!LwnTǛ ig{AW%f"z9YtkApJ?2{%Z D=j9FŢd 7BCyWS m3iVUGК|ƛRT mg2*k,7}P~j*gJvG-٭ğ/\kаՐFaoQWxsMƻ_LQh7ai/MvFXCG 9c](>>;$.Hmn/\,Ӿ1U9WިiKwHCPՙ;Id3*奍frV-HFC3IԘA #Jyd{]^\ۻ}Kj @'5.n$ ߬?G=퍊P z۴*2 P@(˚ܮd6T(w?!OH5?1Te.yUGz}8Uzs4v>tӈt DZOb˽:`7[W#-q s]{ y&3)Mp#*k"!#hGJJ¿D*`.SLu8sA:C(5NQ "H tW]`g*DN28f.> 17bK8X^'Oc}6 UFeu@0b9Q/&JHE%4u0XλY:dnkjjxc16N9$p& b? IpA|eRU*W FYyw~|/;.VV)(5w!$ғ}XKrFv%d2C f]*ֹeB굠4ץZ,+UHSL_0\GG_ jC0Bҭ+/>drTR\Br iV!Եpgezu~l13cvf^( N7*1M'$>8;E4Xzڥp%%oIZ( Ǧ)T?֢^խ֜^MFc#Օ&}xO =gČtG.9g \,ޘ0U作<wkW /~e*])c IPgX80b(Nd\!}\-Pn.ne m (JO-DhE||70ߒrH;}{֥8I `ӏHxPu) )2 Z qLlTV)oӝf%J~;=zm*ѻ20SFR t"lqѐZq^|'>&"G R$:ȩ^W2P>Vc@0I,,} c!G4Ƌ=e@eje@-e3{qGqR.#B}( @ٸ1uG.J(XA:g 9#M\ @?w`z )Pqq7hV|Zo|lfa1#ݣ?[.P؝gFߺM)ѡ>V^ɭiÒ~ar)e_TV2r7%ĊH%Y5XPDB;̆x#]etقٳ0ql>q0:!Py|B513&a`_3f!t]T} d t?Dg'g2)%߉}τݨ<4lfBv:}]3gN3<~'COt曭slm)F%B`0K@C6F%DsΕ]ξrK?) gk[im{%y >)C'y:?Ι%fN<ՓNPRg? B)R*hmՐ䍦kWɢ?h;3~: &H _$}q #H0Ya3kᬨaD3369n|qآZzOK],IrHU= ᠶ7ո$'".yrr]K' 6[44BGt9m+}2pARp9P$?S[~j;Xn]wO]u{).*X7˞j.Ol- oY_7Ty]rkH#˷,Q8;PB[OaG*/0ZY 9/J.Ɲ3Z'M.AigdKeyv'RId \I}ci`Jvye t2]`*=g4h:{Un}PTd9*@X$_ב@w$K ibJӼO\~Wld{ ?bE NR8uqmΙg`@ j PO%Cu&BSS:&Rg t(j`#745C7iQ]f6H"VE0~ٞ ÝIkO2MUUNW?LqMtKKUJ|sw.V~lyVk|d& dk#^e7Dfj|X!7= O$b>ǖ4 vxF %=VSdf-9}~&'n0Z<q:~/5d &/uF>gmxyv@_6V ,|ԟY %,(gH]d3 cci`#n f̄mT`Zb(D- IwRtMPV^!5lZ]=Mx2l$x}*$&$͘0~u麨‡5̡3CqB "Cvd;SIjBT ӭ=80g7ivg$D`l Y P/߀SUuGi4 zYj9z>m&ʐK,M^GCZjK Lkj&)O, c ˗1$&3{EX ;H]1)F:{o[HL۴}AEysk!瘔ǖMD)ɰWDhZ tt:\]9N\Z>FJtcCRTJ;Ѻy,MxȨZJAft3߽8*K[65(PqaV ?sqdE;["$m8^-AI2jRUE~F#QF3?3r۷a#x&5eȫBo5yܕ:-s[C01 TR hB$1k$֛$OhODǖOJ?RnlɽIYbp A]܇&B9<`JA~f ܑ=? ~Gz$ǓhF~tFyȿ,i:1*j269AJ+gXz/W-@%q]-G)Ƙ%RzlB*_]lOqW6t]\k[l>'#!= *l/2XP>KBhcG!AbWX"2`,1i e@mxQc|ٵF?oOxVzF~(qUk{YXC>vz7.9WˁF°\<w̭Emv]K{ _5AU!tI&9dzS/\Θx+؏41inDaO!|tiQ]< 0=ңLUDFQAUr04)rz#[t9uejzͫ=iOCIs3rJNiP7‡J {)%45B9aFi;F3m让.0ݛ<3rB4Z^dm'_S.z@i6jhдP@ON"VBz{Q02w8C;kIG+H/?.Er'ɋJٮ4)ЧĀ~?ewg 5cL'+ɦhe[$(8]JLpv6̈tb>\6j6Sh/u$IW22}1YGg92T1*z='1 Bڒ%bNPv;x^ډX|FOvM{xqHo";X{sVƕaֶXvv5WF,\-:4GU1><|TQ̽]x2m|~~,ΎGǹ bewS\ڒIZIs}-wjt*>PÊ)"iLUoU[P$r! #+߭[&5S{N&M-9`d>ԴťӢ;Tb=`d 6D@oSh(6䑉7qWgВVʺU0wpȠvw8ɹe9rwFC& -iO<( j*_"ӫ-[ڻO9i5ɜwE"0%aQu? 2JZfʧDozdFZL m~m6t2Ȥݿ(Bjn@[qo<M`zUY\`ZqBW*r)QB2@}Fw қ+L{2dv̦yk}0XB{Z;_JT!ٟzp+s…x߬S29^3E*Ls{\">h K-66RڻXfb$2.) 9GkK| -ѮC !%d6Y{-d{  }G"tslK}" ]"Q`DY6YH%:â ȴ=s( ;w>iq'.7[u쩃99u@"!cilpSUG"H*9@#}NSrS#"&^z 8X*O|.b84aP6DsX1 UdTnku,yV!],0C3DB7uѤXG\Dd(K|w1vl V3Ψ g')uBf]JFA!ycG題ekIdyv^TeȽ\hMDTM`iԡ0AF`=sN'ԈC=Sܠ OwP9w=nP8gYF)v{b ]V5$9P%\XC#F b0=b4Y6*`l{+|b jhH?)k-r Fˊ]_h+j9c S='9>*W's}0hF]nV_tK5b .|jtf{#sBF>]"2@;q'aQ<`a >tujXNjaqD,17=P75^G0?QīoMIk>5cDjG!u4F(rg#)ǩ6Wtq~'ʑ Va'Fe_"夒q_u}vjtW/q=7b^*> JbDqRіym‰KK]Zch2wk_߬FTn[f~^ź2qöy좷 !Ƒ7S__t HExM2|MV;bòGq'IfsބJ} gc7oޡr9CT BǞ  %d5 ]ƳdߟK]lj&Qt[s d;/9nFmY8tAP9XF́$6vb $⌽ *M[h7*:'* Eࣿɕf p!JΑġv\R 3\C`9m+̗G_C{EcZk2|qqA6 wA ʌ؂zAB- [;ֶU2IHѧQPqA,.zVf5Tƺ/=)E+Z,0G? Uح=7 ~mGi",!:-G[A>3W;:9sY \gS3U8љއDZl' a$r9gOAT5&L.K~FtQkK[K' ɒkUD!Klqv6>oMdb#ZN9&LOL{0%( FQ3JoN<`Ja9.';1hP)}xUMt{R/rDbr׵aiYB 'qu!ZxqC$)e iPC_PfH(5DwzEl%ȇ^bhRkaS\/PdS4&&Yl]u3 PL-piab1AE_D4ej&qÛ6˷-BT,;xwD4}P}qȣ@d;-e?8#̌SG}ɩ,}*٦{4ۓ%fP=˜-B-@+Qg0,-p=t[ KUk9 a졌2 `E2'ɪ6z$X{.cBX=V<*Gsk?<݂xĞ{3]y츅uc=_J ?V;7w$dZX$~#W}ϿGg͍MZV",D=cZNqf6"ɒٔXpr8ɤ}|#|Aum=aV[1B|ٕذ.A2/9}L!i0ܭCQ'/SuM3_djw`bμN7KMH#!&yIR$Ut8CSU&͊(8ż#XeE 5+"OALcLPQ” BX[\hl;K`P%jAO/o%FҪK{ӪªbpvנwABB3՘eoeIbw >TQ}np(sE!d:(_rXW_ٵ|t`5S!^C.4v;0!8R2^0)6ED7>J +{fWkJd-_KZpeϋ(< mԏ K__]>ʥ,W Aݘd=8Z`k qE'Z@ԫחw#srB]:m=vԧ{{>;DiH5߭liDTrOT(!{qf3l#b,yc(4JR;hJ;r4IE:`R'($_goAp3y0`%Jh15Rx>ft^4WC@{K Y;AzDBXtg<|!՜0[?lN}1 ND 3W,.ǩ+z*F iOSs [w \D]ZjK* rRӖlFuSZ֛C _^Mns5@T 2Y*Ы2A.@ջFfA ZJU-ioA5D*˲pG.ⶇd.K:o.JKb B@١ukv QC0`G^魭 禃+,NyvŹ:ÝW` /5Az Z H΄=s ITG9fV \ EA7nR'm2tys4;>8\Ni>$hnY#'نxـoh2nz" )0\NR ZʫZNRCdYP=#{7 vf;ɨ}QEs ?0OVZ_9 #I‹1f m`H,oWѻgA~!j7cNE~Tc_`q]tw#Sl7)b`kQ:si >sCș:-}G҉(SP |ZcH2Vi&ka$;{۱qA%9eURW8sd丱FR'hNP-@]…h'6ak,x j, Bl.zo\5N M7~a,BFY%?'Z!֭ 3?V!tKRQ::"<* VdN7 <쁵/,wC<0-i4pCWu/"M}_1ϭ#ڑVLUyոOVh8'툂$! D dio{IGib[ѭY.-n[%f@ɇ_w#V9(_B-Oο쩯 P<+T,ױ9pI׆}ά'KO{렄#ʼn B$Y[M<ϱ卤>)atqh4̕3G|k5ỔvU.P 38ce .זl[`Q+V}U*s)mB|`D(QNQDEm}}<$tѫj(7IxAJ$>;]6)Ǖ2C6UCWҢm.Iܾ>V^Z\=mv3Llv;$gY+ᑶ8LMѫd9|5F :Q" ?dx=Ӎ2fK165!뾪A)|YH% ) qpM_%E6gܝ&CJtڂ,^orZ+DQCS;KS.򁶡v6rcȡ]Cnei))ڸi59d jv\*)ʫ`ɦcfJPN昛A x]zX/A/6CAס.9̜8*8): uEp$?$ӥM7'~86wpLLWLVheM9{h rQ5->Or #MKxpBhk\ye5xhd fq{6 ɛ(7&pcT^jZJקQ uu+<:t"?/d_=I扯x#b=Q7ME (@TVj33[@sn"Y(r}OlK9"B!Ӏ_7 W,xL.&ۓ;QGs2aIrqej:y)[ un5MoOОsbG9q (F?+,v~kπ-@rDK]o8PNQ> *d ŷڹG6~VoR w%N5+8Rɭ}g.9+Cژ>-2̄Q}iװ3Nλm(dNY18gxa+ޚQ0mT]uQS*98F\M7=zZKׅIXȗp^7۸{H0WF;:A!z':Eޙ juP#c9iDV4y;&2bl0Ւ 2cYw1\9 WԂ;Y,rgWQ^Db:ZZTv.femOצҝ-,5"(Ra:3PkjcۭGHc0*5 M[4A}o,2cq򯥊],?%)opgZ95PuD c!s\tmۋ5˳)3?kӁkW2Pm V!~mvvGvW'+pJJrѰz=`2 (E LJr7s\~N-+pY B~"N7;8/-i%yn-@v`.1[d6$LúMhk͚Q[iyQt29 [4IW<~3e ﹑NYq"VTn|,V:z(~[Z8,lR)^p|OGTc&¢h63!U_w6gg) drB#Jve Oۅ)Q p ({90w(yU0RcTڽ*oM p {2VwIğf#t~!8.d$ d'E>UboG4/GwYV簾 hkij  f?gC2{Yw#-aKlww`b_@OC( p 712ߧׯ4YJLg."J37e? ,*I=KS9#O >D+mzORˈ$)$>>I:F&tMAy/ɴ]ng8-fS 8Lṱ!vUZhWe~kƢ < g1ml:r9I#zvd1ȂRiiZ030GV=i#7'VGS\my'AZ"w} 0 ؜"TiFі5hmQ9."sk)!3UW o$q%s@GL ŹNJs׫RV$lsRم >c GŅ(9t n C6-ƧgTff+LwX"Rk P_[iؗtFszt/#`\}vJKƔ;c)V5 wiwK4hMҔZ*埴8yU-NbE/ܝ"[Em7N={jS&4cd[}‹1dӺQVt$7|([cKгqE'XH\Ew&>85dun'ܮS$k|m?Q/Ӈ{qY1V$ՎXU)Ε5 BCQ9BY)L5*pZto/`Ռxݛ4I#{IwU+<я/Q#*ZJ 5pO4:H]5Zs-8D[C)/4 ǜLFϧ(t>[%P} ߡqBbNz^"ˮH/ɏ`#H7@Z+s#` X> Ԭ}1,]>yYRQl !Z |bĨ _9-AYL Ʈ C(OZ<<dp%G{鬙 r_r!G[CPAyQNrgW"@+D휻~BP-!na|`xvJdyei_5Rn5,PRF-Ɓ}'+e٥S)i;m8 wNHAJ0yxG,Ky.0􈟧&~lT.Uii@#m{6Ivh~?gd仆D-PϦ]$XD²<0ϙoʹ-1yZ9'z8٫ŷYSĸeX`.}@"j[k\F.$G>,1UŖ"pK5ïQn b .ms2ad4ԼwkY̗kc >ӹ\2B-Bu,[DfLH13̧g9B;\i65"$X^,^TbDݽ\0+R-1`;%L{FS/}Jwmt*enhp NH{adRrLM(V +,!t9Y9""-t^!$+Ţ>2L9oM pPcj@KQB-/R_ -N7!LYdMפ XG٨}"^`%d֍U'5Fb8b6o߱K?;ڋgt+mb`[q*;a`AaMjXogׯy~ci4LC;/1YIDy,@#[h74աyv&oG$F?s$e' o<.vS|PIM.720rb6m33^#(dZX! P9'R'Wuŧ:ug8y'ߣ`L("7}ةL f,&qDLZVGYG}!0,H,}h~wdqH̗5'9MC'PnU]dT[5#O :Ie;MjJT)8Qc 21Cd:' Vcq0X ص?: t_txYo]-mZ`ʆv-O5<}wGjHYyV*hԼ& Qb+MP.͊ZB Yr=ҿH:/伸c7Z*%_g " H 6Y+͇kzFYѥWn%x4% vӴO8D|v;Z([T3~ڐDRZOKPDX`B ΡB潏Q ,NYuy 1PtfIJX/$zZu!RUfϢ'RGouWE 9>^p"UGv$Z"9q_xz\O =n}O 7"u2w}[q,Y=]*XGްO5O xRuc ޵*WgS}GV-I;6if`.f9HG790UTQ\mż3RE+> UJ l_`.֍0}Xⴜ8|H%@P]^qZ)^R*^aJq\OR#+PEaxzS|;h.w ߍfqo|`fLK' zMllDe%hAaq^H|6+T珯eJG"yKap.oAx,k;p➜.9T*0'$*9r0y%p6?yHpr72/\D8뎠f.xy GEJ ,E#ZB+OM:wYBjywo6ZxFjiQ3rM ZhR1~7I|" !X.-JB\4{>m;x$zubƶ1:F§̈rp-Hث%G''{EF5dwq=u!Ni8I(0쟋0N@D0fV,.wou\^Tr|hqy%WwK:l4K0 ҚCrLH1z>.2$ĩ]2:0堮~hjbaY&) H˪p m tV_v!cԩQyVP?sAKR\˄ZtB-h*Y6Rsp0ê򩑱iFiA4q*5NLgzY憝ECۇs=`s8Dn|i.(y3JSJX)9TСzy1?] x8`l9S]a:vU A 6}]&w@CM^la) Ku:^Հ錅NK cu?(4i5U8۟](#'Y'B+94[HV:zd6LQ>Ո&7+9>"mډN?1+Rf-ūbQK7WB-v},(T>L 9y?4!0a'̳^}L ùwmTARz|ƟE`-5e m ."g25{ MYAYl)ZG N4v«;vD^s ) .e )[Ō~$?'?ϰAu t( ^߀csķR8_>qke`QS4~?|2jH,m`^*^G[;a|RLi<1:.Yip=T;bnqh>2[[sU?I:+0F?7(jmV#槚tܛxZgCpy_4{ elR+jۉ2[GrT<2,s8_hA[Eū1@ <GJj-Q1278=Go]N8q5L ef\i.`:-C$Su;Ŷxft;m@A֍Wg-5|l zUfP v ,n)pk D9zPKZ$'ЀCo8k7FZhxǴ s9]G|SJ9/k"F$@S) Ql@N_钘fq uU7/~&L~f\g?`}[N̑3p(1>!/ϣTwV&ߋOU^C[V~?6Cf9~3&%3[=K)s_` bfR}Y%ḋoV:?_*X՞,5kx(3 - +:ih>kRD?[F-( *_2`'r/>6=js,߸U?/<*94Α|rw L0wiB>ʥ1o-f@nָkeInNr]MK ;C.z%]hi ?U<7?sCOӊ`g3Lۦs"^b&!VR@kx ]ĤN-J_ @O)8.^xzN 7o_iT*`@C"z^p;=fjȢa\-x*wb94|X<'jt)l lC |ד~ˆơ˂dN}LeߚiU=~ Htq=0SL `X\ 8OyrC9c?6}Go+8کf dqЇl1 7%Fv?8ڮtV=F"K/UdUHbnY-u^(TzaL0˂"c섎+' v$指G-5>\]CDœw[XEC<`H3pzf8}pO|pa5pT꺼}izg#9LTFؒY4Y}ŖXqb[w:qDw~[~Qgn)MטMJ5se)8}, OYĀ-̄}wLr.{f8gO,$wc@*3L-;&-txrWTDb( ]C6|/;Y:t`!>:c 39kL&Y(OɽqD7d+R_U raJt/m:pIwDzk4Ͽial&ю^~;֖&"[iS$^frLoຒFp.]j~^~ÒRCD$_[=)f@c4^AfmI;*c* Pxz;ՠHoS9T)lҜFdK;3qGAxn"\?F1 U*j ~WL@X]ՁNwj h$Met:&/ז/&eOغ$uJr!V]g.6qYF_)\mUΩ a;=2MD,8MP$/!4(: HC5&iRZ 4r3{uzܣ^(x0Y-+ ,ו+ R0pJ|Вe[H߾j*S$7[!~aK3ZgKOKȕ'H<}1#bTYR1+oeiYТpXr='"sp>Nj )"hnD 09 %3-)?xo<z$cyo[p?d^񶒑hb!PvTgpdsOBs+#uOD 6ٓe!Pk|z2Zr.*˻ 2$:?8t]!2#i6$صޜT,V}Uax`jT"YA5VIŮh~E-d<k"!f>Džt̅PX;b?0?Fgz- 쬥(cn+A%@q0FyzuJ@uRs8*xodu? N/_@p*m32?}wAǫm)U%de8,p `¨0 ]yX%ҭi"MCY)1{ kEtHQy7' X@W5$SL-4v69vF]W.D(JV.? Qظ,^^>h*L8դ_[O-RAyMFG47)?s?3@.㎏$dXe;vnk5f㼴Lɛ-ga}bN[޿xYSy-S3GmTŦ;MG񝼡xVR(5 >K/!%m̖9^s4k '`/r}VV*NxM 97EaiiDM4 -۾ +͙(t_9%"o`W!XmbkE&qbي52~v`BY86 |'U# 7 ͈FUWr;N.aJv=(_E䨖̩ :JHy¼,-eFt'WdX̶:W ?) @eÓ!j\iȻ)줣UXt.O*mso0T"Y؟VۓB3ƚ}aah/rd׳ׯk@ܽSV%[/`3iC͇6]} ۇR6l=ٟT-gC>;^nS*vԈ-✕tC*a#knڄQP=^i$RM Y]FwaLx'P}(@98Gi҃;Ѯc9)n5ŋz}Br06҉J^Puu!_kNHh]`Mre($$yx(Y8%;V}4 R-[Tz ,i8\d~ۊ"sh~1~j}sFo rߕu~/sDک/ ͉\IϘ"͝e76:V'HbYO!6e%m.$Y=K#y,mQI#GQMG&u8` Z7ؠG]I E#LuS\zv"QFk[R.H{jPٱzq\'$QnŗQ'Z0w [PV{d^nޜ`$Q'"yYfқqM*{qٻTQ|(b׫`=$΀_xDDža*Q;ϭ{r\F'^ ۺ!F,֓Zx춐,E|zbym_6CuDQ=rPcF7t)o fn.t '{1(DQ"M{:lt2m[#A[t%36?&uu:MҡKA.NpZ(/n3_I If{C®tll.*,&v<6y+"'o2 p<&-#lw d3\@ ] EY'sç-jp@n-4Ÿ JgQ^bIMog^ ݓJ@$²ZLYWHE?IDDb}]%eJҦ4.m2~3x9wr xv *z&q$ĖFJߐ캮"Ua706х/xN@"HFS=Tz=d|>o8*MnUL5&{7`/bY#,YJ֕Vm¨j(} RmھJ@\޿-,ճ4e;@Z&v9+Ne|%=NS jpϦ4 <${˸DNcLahCNP!B~1'EecŒ:hH)fu{L9UMrG#5D{eo4VUE|%&װ<㧸Zu\D.f`O;gS2٪r&%r3L2"OA}HZ'cxxa* h9z“f.,/_k#j6N|CߴӔKnyMOHpDZ0qoU1TZ$NrKvcd/Baۧ!Y*g v+w <\_ Y'Mc^oK}lnTws%f^{ Aג?܊;ieՑ3񹮶Ď`ds/p鵩C,/»oa%z\Q0gvP*N DSít|]m)8I:j:3\ϻ8~In/^MhA -&d28P }vEk:lJEg+?; =-W=)۽6mY-H'JDBY"VW-fu[{2 :SŦ~t ,;wPYnGr@;fIAC0~MezcnltenhXHy$ۘЏ݇s{ا_CRvg<`dMxB,8o뿥u;L% &Z %HOxCb !hѨnl( [Szd0f8ZǩDLCDMeȎs@}6#*Im4t?ȇzQ*}%Dl͢Wv\dR]aull U_ϣYߟNTg/8n{~p+OO<]#j2ZwZ"cwCoASJ[ &8~cfnŢrzRR;6{c#*o@8}Ѱ΍97.c;ׁ+t/ݵ!q`FnCmr< RKɑT]\ \8sږX-c{=[=l3NϜu0okd|N%uޅC1%x?dT$C32p9U#Irު޵gǘ"{gM~ Z{^ra ?:'/~6Pq,pڢUbq0')ceymN7W+zh ZkP{äuuku6ICDoj}yH axL)jQLBV_/E 38: xPXՂ`_^p*`xsyorNTq%k~ rKN4I0\q6ƁHf@M莋"Hcfc6Upyc(?h,xUs߃ a8sYYO\RHDRZ0h 116a7aN$y_){|a"yDHN 'Ke E-X} k'TBw%x :K:+r^avX+$XΌ$;qcM.eH2;m Pؐm-wtpaװ9d4Soqd | AkP_-kOWvOBPx$=ffz$4[މ8)pKJS3椤ճTq8ƈg##\^BdO \AkTs?TLր^qIf*(@wH7Ǫ7grBbJ#k$_LK1V"7sT3jv=uH{Ugjq j+Ңx#bP^reWr23k^tkJ >NEs7Iqn+lmm 1q>w;l=Hv_zm9uei*-`-]q,g:9ʱ{e6ADj[%1QnF!r|MLFij"g~\nƌgC%j\eMhFR," CUJߝ.p~_m2>CUd\wAޑֻR0H%ޣB$)ڴNu2 -'V.xRTF/Q9[׼YW+&}؃50w!j q`C_Ato= ~u;+=u-9M'h;%j߶x ܧA^^31T;wgEIJPp\UX}Gi9!Qp,f)y0jMzvdvDːxN6N~|{Bיs; XpR̢cl\2+~иNs7Σ '&#;S_K\N %D= 0Ur2 ]{ԌdMdކ¯j'OOZaGKqVo)I4;jD6wH;c֡~W6 05#[{-!+~S-OXծ%U4e6 4=1@%^ M, QC&U!ӞYN3MI1fm WC>L"W4dӾw2bU,]S#9=<7Pi~Tk;A0ұZTa?z̤ ky!+[Mg]hxExps=75rh10mOO:٠y5 1We,< #_`)zx)<511t`.E׿dke}d$k 1Iו.lQ;* ĹPys#u_?[M #yAG$B5/>w)#o:ݼAjo1Ypnj;SPh1iK4-+MNCϑdA{H4Ю ER(hAіpvflE.3t`́ t) )&Nzk:\zxX*D\e$P:!^SXC(wKџz$gzC%sr3RO+.YBodfȖ'z5UOQ)< l#BaMeF:ioY{~?-Mom,g .z :0VID$"Uvۓ"&XD6۰0ݭxWϜ[hW P] !2kP1EFPLlgby }.+q+d(dn!wX&g%:ep<0q9)Ht}W>43L QzL>eˮN++e"Y~j3+X>(L4 gaPH-Xcf[qOFJQW1 'LS=nGКǼmޜʣ+"vi?ݜ-uG1lcntYmkWLŸ7_w|df;E&bͳ-L=z"kvU.F;*Vr$Տ38/z-ii=EQFUS};emAL`;UNqSlZGUk敠RmZA5|B\=ܝ5  % ?My+CrU4iE(l K qZ:袖KƽC&_ O^(# 5F|̬i,.!Bv n§#~PGFVjd 1fS=x;S)lQS}h NfL]} Eqݻi7̲"DҶ 0L+UxJ*(T}k#!`Ao*;ADi[c ==&Ej ~m߶k%1\uy9n L 9~J+~.e-OO+VVRA#8s:KZ?X\巚C_K8 4mck^sWSW6rILˡo䱌?l\^~Xkك_@U+i.V޻妌x? anžIˈ763ᅵpra^N?$XM!~Ry_?H Uk/4G"h7 HX=\Äd9&OXџ#t Cֳ:7 ը\ƀ*O17˛!{^_ǜ! ňo5peD#}]GZ\՚ $?  _$Έ :ڼ^ٺ\)WS%8 h}B҈Dv3=M+MgrP턡6i]y>8 10+bE]ӂT.s_MN3cp>L4n~IԥT~ߏBڒmuko/xEdJ ߢ$H=;Si]?>!g˄yܠ Y,&N c}6@${Jèu1Bʽ kvV07ڗAȽbi A.0v;nun<45D/5&f_7y"Bk|1Z058Cd!(#Jkd<9S^VxN ]Jvu}RR="/Ủq4mmBkX5vcVA wjQ\J@z]ǓЇt}&cD5X#LDF$N}3ؤ qlf1:jȵG2kSt߂aPN] 5 m:pxOF{c'PvZx҈f t<P_ʹ;8JPLoR.}.WBf+~1rw "V pa@É< RPX񓾼rSnU )u/܅Y?K!Xtݒ+l%Q@BOAVdfnMv$ܳ0o|O<ظ)~xC`R7| =.n1 P8ԛUON`4B (.]3ٔ64J(D ԡxNh|b*K3Y95QB0%SMoghv,TK1\ɥKghrTGP!8J訕eR,>GVFݏ: [<+A{ V.3[(0gHKKy*u9@wtͲe÷z2v fOtҙvH[MR{No^;d?I]zCL ^"s@EN^ro+>?cXm^]FܜNlsuvW&pAXKU*%S+hƈ ?l|^ߗ|4f Yfku.O@ ;#;9Ե FYIAwؐgoMGp_8Z)˛\@Jɻ1/&aݐITrk$ryC*ŕ5!$FK:/Ƚ6vf|ÿAq^x7(+THl_EXJR+!=r~9F0:VwJʶtZZ!&n 1m{.Z6Q_2w3`m/Q8M:14\xS~`үm 1ZDa<#6({7AySaYlEJdqcr=4bWxdWu_FBX;nc/J_u2b*.Ί5 ^ͼibH* Y Oc|3kVRH_Ƭ0CHOcRּ_8^ZpRo'hŠJnENZe*&Crș><Ӏ9ڃ# -Qw!Qv zn97o(vȊRG2uVp-'WTTXTًqίdbLbgԻxdCeY0_o~ݕHdhҞc"JGNA&,EK*'8jFXW:KhTMLtHџ랼yݹ9G\o"uPjd H ↵_pRn67 Z`Ly߽ACH"]. ֙8R`2RzԢleO;Ĭ2>Q9ES."P`jL{PR4٧xݮ7?ڥhg8,]ѷΫvQ6—Qr!118Wuwݶ|R"qT*WdU }oևHZ^l挃8h *3T8q.zNI(ET.LS\THѧv݈"= 6Ɋ+J ϲ΃Jj੉*<0rVX4Ѽ:zO<̾ۉUkZwwSh d;RMFL/8³9pD?<} <HC@~Ie)pxYx_:D.iHfl&B!3x=6ɏPg0b d!Ou/f zK:9JU*H3Yg9Z+Vq͸ie@o$FlOK04Ҷx) n6$R?-6BRsU+ѝQ`MOTWz%vGN[y4cL= W“ kݓq1;'R2|PQ) Kȯ ;k!#ґm|v,RpDo9|#|ŘsqŸXkb1aPxno;R.wޝ+{6ǯ'Zr"rwp<ΎiaD"x}MD yic65P9 T=ld}J:[AGz\I8'Y T,w+"a@q4sWywy a{BkNk/eyP.f&U h~wU{Q]nQF``)ofX{ BҜ/qYFl/AM="{.ЇcOݜ@>c7'0*L]B%3x(zڰLؚiU @:>+;yw tFnj\4pc1f< IdӃ̡._MJO=%-"FA-%+K% XDmƧكX\7W]=x!2rX:HN6`uW>3 3hmO@ ᔭ{7-CdfB{\zl (,Li&.s˰IU?z,5 NS։Ći6FY}㙳7@3?)`뉔HI_ ֻxȅtpM&pl^~(,Jy<Á@SnUFet̩sǞsJ\@R,2HZLGUo0pd)1]a8 =T ]U=w_>\X+W֝gCF5ؿjIÈ(f %ޏ]č;]+Fi.vs;#TNJ #[G$%0#ˁYJ.%/-EkjETQދQ>6dZ[>2.'E2Cqf$p)lዬ*;7kmmaߘ`qBЧ2 uXobjt_d = T4ؚٴ W[$K$XM&'|q3Jd$X@"!fºN4 |9qduAX(iSʼn~|jJQW].7Gs_uS!{_X>OGHRDF_+:ǰjPtkR%X)ڸBm=3zqb,_[~* p^e̟G*]igo 3Nʷ^fM dS[,i}=3&0>o@zhUP8+ZW[Z:IFuqebXk 3CʰY9>#K&hAdԊ;eBX#zKFF Lr䅋+cAL S͕$b0C?^EoW_5Ke9pW>Ht6-ŌG Zp7w׃|Oс|0\2Ǟ&Cq] pҀW+&WF$,_$.ҭe(7C'AHpt-7tf#~EA@ࣄ2]ˉ_:.y-P\Ka/Eh_lޖ%e("ѩT;icN{N;?̫@DE[עɈ 5{ &ȇ(y;sƒ C^(e3ڭx.FySAs74n}㶕WcܩLfkMMkG$$-e#L+ASc;l3B?\@w)Jyi.fO s wa,cYB'}gڷo?r>)$i3J_~/0S)JMBh.:$sWVbYX$[I#8ք߹M0X `ʯwi{{[̂ꬹ*+&WU1}>61r'Gv.ͥN|Y`Η#RXcm2saɁ @!H3w|癬_ÿ+WRMSi[d>%W/\NG41[#o1dx%? źh`/qXflPIs ofhB(HZ+H:@"y5$]_^D/nx7ʹ|rز͞p9;Anjq'dSIZs KEg-c{kܟP[ O3M0իl=Cm>plfǭ#\@ܴ(zCop64:j Yqf=.|05D 쯽Ϛ:pҭ]B֠μ4\[Vvf)e6"sAd!7V{$2!AYI 1JimڝǾ醸[W!tGkIU οOS!v0b_ouN Ct"Q7+o԰-6l6b~(Fk /["v,:#HYSh<,C9ىƊi%mk_oc'viM[q4-I\rp⪬%$)u8)$񂪌&-<%*;˷`J>硶@<~I2* 1Ew9ހ.$"M hB{u'mp5 RV%]z[lGjabZ*Qٗw`9p׻ "8D!P<l{5b=#rn`xx^V ^5$J9?F?a߹`Ԝ8V=>*1:đӌ^oU9z9lYo3Y0R&&;,^]ΑҽSc_3JvH/l\bC{=Z-c3fE[&)Y3xLݗ!dnyM .ǟxFg<>F%etv# $Brr fCڠ+qIחD9#{ChХgGҘ hvELO -:NyyWo[N7 :@ŏ kyJڌnN&ЌC9_Bi)0N+" ~)EP87tݍjbbV|Bbe-xam.Y&apH ː Z+Iv+M$n(sfEY5¯. |l&5e@h ^H÷ gyyUÂBޠߺp7+{[|3ޘ@gkSއiـWpKWIf38`P7ѡJTUaOJE)o69$HaVIa@a3U$%أoC^6⇻;ic]\2j ?m#Zp36>V]ܹw+?=&w[2>%8fe!*z]/+_Zrk AEtCuvp)I`  Z/~WF!鹼*J^G<ɈR=fsJ3(ַ=rvcV@T/@h le*2%ؠWحVۻc;tQ٪|֜ԋڇwm@De6߲' D515 ?zVK.'G 5(3Dhe+Rk[=p㱘[R\u0.!!e#cNN.d&c4 #$|ё61`glAJHϪaNvwG1*]`>qKXi]mUcѾi%f #hn R}=xBtF VJ쮻W Řr&P:3@hAe rC\Jf/ :IT@ʴ1T{]#H?"5`H_Q Wj5<f{KdK<, S΀EL,pUMå[.f1iv] S}6هK*s̚9!k![FIo+bHC3 %qVyw Z9N+ b 1eC-xsGpfo]RQ 0l,LWl$F>~#_ɃF$Vw9#?P~6M2^}C] W&{&ZcjU#L@#ffnԷ{uP1 hW>Mp;AjG_dOfNqdQ-k2x3eb/s}ioeKIahl]+6ybsU,.,%}+gwרG1` Hs'n˲_yմ|9mS.[Jq(7CQqzU-r\BJ19e|cSZBBc߻|a9R$\<)>YFQUGg( ttBFŴaG?˳yOo\7֙сcilcۅZPPՅd6Ibm&¦Á ˹- e~* -T(cgbk?wkњ[mX!/8cfcʢ¸tDgFtkOڇS?\3ӄp6t80lEubfO1DFU|:rH$\$-EG?$?lvj{"c 48َ6GfCn\s=)@6mM&sZxYyDSsj%^-`$&x"aV0rZ밠!蚠)n-cAjlF޺BjT85la ^_| f{7Qh^G\3Q3+3!te754kFPѭVw ~ \FGS)W߱Tg˭U"H6~6.Z.J *YJTH =j$^Ipa`><o.B!t1d }#OvDßq{3D)h^B~ijpuZ|1Zh ֔XB[)2{-0UK"|=jA?ڕD]&H'L8l&11b<f?6fYIuy~Xݏ?i ՔS]#8=~N٠󧩋 |0.ExvJ'>b /uaPu R;9{?bp C#KsTMͱCvXíV`J.T?fB WP땺Xҹwry&V45Õ]$|zY)*||A^z= [A"`G&o;TEd<4E^trp&W:N4]N.RfO) F6o+p+M㶐y/3b08^2Zdx=ͥ H6m~lQeЕWFjQ}܉>@{p=StԳx5gT-~a\V6!S^?)4'Zcu.,)s?Z 9,χ_'`3ɢ@5e|zrS84(@$7W&fq Ig54$}[KG&qC9S 9MCmNPdNcVT]dョ2p ͑y%6d\ G~v~̌bKp[ N"|>Of;L=ff];j6saFqX2t`?.y+,8FJv G, >.dz@p e͸ 6%py߇//U j;MP ~t7\kSd^-*f!HGyYANku'Wc%K7ȭ ϰ F!k"z G6^Y^״yg%Ea7a+ɤfLjs;iXXfDU=|ȧו0"a+*_8̑,֑ Olk@yR@cm?FW& *7n/\U U"GI(_zNb|d}_uH@QHt=3_N9î>gE)J2Y\vq}8q_Kw9R㕢O_33;&L6oÃMA;AqE"Νkuuy9}dbu6m:a2 tx6ü]w{4rҴ UZbj ãEvBB'>ݕ|[nq G9T5p)kE~n^ͱWL$h|HK;Vx`DO>'Teq@xg-X 9g5DpjZ%Tʬ3&CEk?| Mp _/ʪ{[=;Dָwm1⣾ItQjSU{xVv&Ŗ+,!c\AebvdJQ }USowU׳ Ƿ]UhUqM 8@> <[ U֭qk,rtϞl)=ٸ`F,-Rj¤;f:Z܂[Z.~uFGSa~kMMMQQ%`}n\p3MDK.v Bn;>!fjd\ Q7?a,~!`~Q^} fLhzyٵ ^(hX^ gQݰ<K'r7zVq f GpnFgqgPKG&!/,*Eg/%LQQ>G7:ͮ{|l`% B+Ui bbOIRj"dc5P#2.,g 1djܟ>Ї o@c((R6%{:ahl(pC4`la쾌זakq%YxP k1Jkes$( SoFi`'.2̗AJ?뙡nWJ MNRTBd$bp0]xkl;9O|R#Ӫda[|{"eDt~=Dx@WRHvn-Xp(4Y[v\9,a&ln fV]ڻW(1-MW5,+ l^C G_e/cMP6x8Ij;eJhy߫ S*"Щ鎹 K= ѝЁZɅ"1ɏ`6G'dGiraaI^Ɇkd03Bw,Rs* vДOpqYڒ׭: FZ.y +$-Zr@QX sxrLFS[.dYfbc fy}qfWŮO0\q>Δ G2ԃ5FUš=\IJZ^O>\Ej荒k9p6 o/ݭ[;m.1 >U@~ OiZ[fx9#?C=xmum~6'a$֒-!Np[>}L`PR.W9)qO; ~bIGͪNT9ֽCTA) ނOj ivk[񦓂S.8cS/܊c><*JM*'Q)8<[\8, 5 uXp͕БGnZA~9>%vȒ61Ӧk0@ev)(i=}o Q,Tʞl:?-*ON(FUfM=q[iYw݌"eS1~#L£|6GŢ:al{. 6@tǯSyLzjdY  "ZSyg[&H k54Ԋ%7o{iGS0Yo$>88ʈ$d}JZ4[CmO +o7P-ҔQIog$)$(W G>è0-{Ҏ~ ivP@=~~L+ȪU*`Rf?#tպV~Ə!\RO=Y WX)ZCRfH`DnC(Z5$,=]rpf[;C;j c/1p֌FK-y! /9&iGb%-c[LMk3?~-;+Xi8XwPeH@XT@dAis.61Af,;fP75K }0gI`+j)ƱQyV4 n7vԲ! ƫ1o1SxѰֱPj冶CikŮl ~Eh*樵U'M@l 62MիGԫEoP[a1rZh %0_uTD~2oor;37htDY%mCnb Ƭ[g{ h'k<(ػZc(1Lxf!MR9xE pvh׺> =kCPt3p;n]u*Ԟ NL-/`5Q9a M[,2F|zmX!54Yb;it*m,UOۛe(긢;Ԗs? !^U<+֋֭a =-u9vX5Fئ8Ԩ&<|>iNHeWy? [_:tqQJM<"SGРv!`7Z3 W9}|mu K6z )_c.j@ ;--%x3u"# 4i77{}/wW >QmAOrO $`s *3ft:XՖ~s`~YpNI8k{``AaNkm` QU,FÃb3L**ӎpUB;' z77Xg`aϟLQ4⾵6iWJS;,&ʊD *y.i[h@CӏB2@^StUKW{__!ӕ4좥|[|rh[誻edg/Nle$R9}}g ܜ,OYrV ?5O“+&v:4=@~(-y0EܲPYܓC(YpeYsZzmVFZ!΂I3} 4< x*<'H=Eܹ,TV!ߢ _*HOXn'3B+xPQi8~u ' vFM o=T#6l7c]:EݾRdsqq^R]wW~Nd7@d)@+U]xŠXzl{ra>StTϼtt_ (V0b"A+wGJsӰ(B5m*9Bc?*Iӑ>a9}"@'jmG} PӖZ8Z0[4 s'JÐ@C] lg /*:2}WV \^pӴl]1T/:'ڋPމ2=-3(3*$i|B:f!~RcN܄m濱q8AmlDmW8tMy3xABZ g6>~y56{ewdp*=gBB4ą_mlUu.l&0vpzܫn AXlr17<;qM G^`{^:冾+5P)_\X)ѷn 4a@{(dKvM/+#vWlL*\31Ւ#ή,Wp0r|)A#zCH%IdSN6.U:tX[;Ё/[,ѹ$2ݿP&R7=Z㙠fFqb~n@:DA'LdIK!HjSf 9`"+knB(n?v7brw&~kL~_$]$Z&~Y31u(5%Q%3n(q4k^#[!~Az`ua]S- :q`X\wiD2^u);)o1 S)psuwEiR*|o*{&L(l2 )RG=fۅ{<(:ArY-ZӦ;qMZ<߁!_>(s4}O.+$[{g4~1"!pm|Usz4S4<='j@\IA\8U ,wGPtl< $[ l;tXpp,ysFrFR4P+Eb_i^2۱; !ҧZ b' 8O7,Z-4|%al씅LJX9x:X̬W CA"ǵ/TӪz->x[O):P _F^)ǟy2{'^$` %zPem\:əfJ>O{H<BO:V'ėס^vck"CP*xf1s3B:fxz+<Oia?gDEQnv67L1rlЛ ,Oø17VHwK""8ME!9U FYPQp>o~ӹjނċ[n;b̖2:0|E&bXJ\hmk05&`wm F:B/Fu9[:5T!A:KfNoВBgwNwm8kHl椺Zgor/0{s˛umI =#(N]*b루 e<_ \o0k^'j%$Z)ʈD$ƚ`}5(< u@hj+t{(ySDFir [C[=,Q 8I ^?ͬc~Q/[8\ ^ AWi˭Sb4xi+3 ❿"@S XGq`m4ɐϿ6f1.{ HkKOXYPCRwliqvjWnkY\J~Xe#sPO~b;.īZ>ݷ.c/ Q|dB-6\ r] S2`gT4{KEPm|%wT}Lٌ/[Yc?(x!W)c<7q.g;1N~#ha[rt{!&ӄ}uGW) j$+FutmxHF㯾9#8s53$SI,vZ?2iYvڣ5L~HDbXK }J ڎjb9w5ĕp{چCݦ{b]Cb^<]$xuf{=<*[䐩GP"'' #z>2.3m7Wx('\rA@m8З $bӢsXPH#J\yD}$BliC FOY&y 6t FU> Ws45Ew2`?+QV*'<|+#pTG TH&FLtsTkCD⤍0V qOl ?2b%s1֮i+~0fOdrpӟjYa.XRuݽ`=h @QzjDǙ^JAu\]6еzRȟvߑW |2D^s 8 }{e-lP:9ӊ'0+릡 As`?G^ߩ{.U,C-KSuÆd) 2>NJ`8qUa%q") h B7[Yܛ!WQ]৳(tꠛCb1p #{N>fa /mټ;MS;h{ǽ~z/w:05 ? ئ!w t)QMAy FN1hiYbK[_aGnBP.?.X'B sSi/lBۅu68D;brs"RE GF%ʹq3mXj{o9f4 nRr"/ҟ9'hzY S5? Ks8Ҕ:ÅCڊ;|CyR{Mn) 5D&5#>U mPw"`n&<;6' \=@=?o~mB{F/d5]ydU m2K +fm{yؾg7W4 ݞo}Hv3KPXg:0kQl QXUshK'^;TH ! uk`m$X"VDϱ<8+pVC#J.'iBC{rS| "*9o%<@Kd f؁ddR )8$%8+.51\`OQPFN\?K\n<)5B&nkgIq u6]ԿD9;hӤea:VZ'߁O/eO(XƯG^n!i"1]-iap}bX:!9rҙ)BtLq4+̵P*YYĕWZ,=*7:^CxsttԉϹknZqS4i.`P󐎂(f:-{vխgrbTN N+v+{SЂO Ld+i0>P("U4E-nB0`2xg ͏R_R|=8PݸP'Oʁ"G} nؕ; ɢ׉E○?d+_Irϔ&tpI0O+Q rf;+./4`4>ڌ[ĵnm@ZRA&:ѨZh54>ٍ3~ N@.Mxulj-IpB.Ƙi$ŬN|ә#vVJ{?a-yo5CLh3mWqAy55cg5I*S DvH`AhyQk'`n/Ga= p#N;Ff*È( ^/Apɡ%UR/lYJ\Tz ˮu &tTXlͰzRA2X<.Uѓ,}k2#&Ct+TL's0_rh.`q3xtt7ջ;_ລ p٨VCK!|d齃Z;Uh9 W-~S kiJ#+iH;=]1k6*ݽE:pHRExN&tUXX"uo7j8no? s!J̸YKX@36` N[=>QAqar[sZ8|k ͦ ԰k| x2!d\sN|6ˣ9uZ<$=L974IJDw@oy $65߁զ>3'R.MM y vSs҈pd<.#4$1(ըYpGLhfMEwK&[cYk'Oot…\o|^Qʼ xV9j.)lv=Ѯ|3ϣx`Kn+fH:>e/ѻe ~Jo͍Ju`h_…xCCS<4A]zƭumEYӛůYy@}."}9( 4*3츔Q -"fdTXRG6= ƚ-_SZ[6saԧ7A/txZ+0Mf;WyiGF7Zaf #zLOAmS8&!\OA&Zaǰ}UCFح,}߯bt ɜ(30a8s8HZ{J~kĢ.;ބo ghd~*%r+ߏ8E&TvP2<ػxAz vf+A`tNU9cR Pzh7S{GXuUЪMA{Gt]!?l'J_bC|jh ýZ&(frjBltC߸|{3SfÅfxp \(oOYZxTЗaw c$Tv1T~**)DAҠjGn⨉8dO<12lK %S8a")8`)߈N<>w`1o1%b@zy'(?+FjـyhX+AoI U 㬝$J y||Ph.l!I@8rA9XJt3NP/T=FE WՐFi磎4-0|eɖ9 ?+!ݭ ;&]p(աB޿zwR*UEԡ0;^?T1ZWQ|2z3 rZ=?wH*9\^mg{ 5R렅;TȆ $u@`lJ}ܽ( 18a&X }Je"g:J 2D5o̐; U@^gUT%v/(ak.6%O,Aj6p<<|.[R%PIqFƧ1` m!`UIZdC/(`c Egok#B헍fA6q(P 0{ppZrͯ-?*(#. 7~cI2x?3{>PXr,\4ZD/%}sl$A]}iB0ѓ@:c`L|॑?ˣ[v"hT=!]w69(w;5nsZ:EFųlA߇}B*)~TvkڇD l2S,qZ(u3Nnl٤-r!icpCgNjK$A9<1_/*\Αnlre0:HW @a]{:IH.5X~P+FB;D)::QpwcWv&MdɿLud$2lV,%r'^xx>-ZM+݇Y'SG"uveNa;=meg9q"I V{`FRu ߜ 4z*pˑy8;nk\xĸIsSw]B:P"!MnjOApO5 ﱶ-m)i5O}x@Q)s 2-{\4ٵKvy^`kob7F蛨c$mC\ٜ}j]6m5Thk1_ȶ t•ˉ{&9{/"]cr]!]DTPjԄZhDXSR""D1{UR'Q=%vV(,hPDԋzSE2qD.]3ca^'K"=㐬 H!0Q}qNv2(TD!P̴#+l_( 6iZNB6qG٬&/*l:sSU]rbFO MO㏼L5Y֔Xyޝi.ԁz}UU/0ZA]a3X0@Z'L;I)D@ЉfZxIq+O=Qc5/o9g$u+Ek5|NĂ٣C#Y}"3Ȑ/ı<ăeKdp)r-3#@i"k>p+C^^ oϮ{hr&bI[ed5)=v=k<=x؄9׎6F%8(P fmN2lui)ɬ rX24Xu nl~Axѵ@?@;QS /o@PgbqިOU?;!_Ne-㲱xw[c^rG]57YljuJ5aZ@jpsCNf~k߱fyr$:xcnTg mP4!,ҵVۂ !&&FxR;`ɠk&1.z‡sPb-X3MF7wĐ`y,DD2./&?-4ԪcHr fg( C.uQLO*3eȝp{aBn̑#yA*zX; yVC$L_̙V=!xp  dUN]mE2QQ6rB$sŀK }y%6'=[e;UsjЋ}'>dUׯ "̏W xd{sfp Gzĭ"Oyr<ԋYđCV]#\[ F<> . 4l_-ploȑdyή!H½ ޅ!M=ċYAs?alJGm#-в]>T>3,EDI'd$?Ġkd CwE $tkH#>i#i6 br){K3B]Αr7~A}z&e`Z85[U*{Lv*/et_tAZWS]:l܄rGPz2B'9`cTRF(lywP͔VJc)Lxf s9' !sYEp-,܂^uQv$wkwx3U"V ޡ `5,c.}ˠ:^mcPV2LhCXbnm@/+;< ߽m9FGI|Zzz %Uj6}$Eǥ8RFS^q!,di!߆oט„D35UpM2l )y¦08#]7$pIR݄}%Y^ʻM.'4|o/n-#$U68}_jgLOo{ͺrNoK=\#$9 ώu P.!$'xQژt8 0b,E@*Dz"&0+una @*U-Y*H%XN+}3kNAO01Q,V,&c|}.ƞqEYl3!eWY먫R8n._=( `l~ <$#mA~.Q(jĞ|n82 D}eccek?e T'^W &9h=7/Ó˓-IOVS@[qFIQ 'qx)nDwǪ*&gx0Ue?c-p-JvG6j>_1nلI[/Ό(P7:FZt<ͶEPšS1gk+I@m:DEpY! ޣxB8 +z5A*nYk6&kQ[rfEXB]w[eh(2 +Sԧ5ۡ]_V _nkW̝\f=Yi\LL(0z>^eKaIZ|t`Aֿ 6`LJ|8FX]ɌH9n-2}3iaQjԏ@Z6G m")0K@BAg+YݥYNו{+ &몛0n_{gݯIm"OcO uCù*iq;AXH:^" (톛mB# t+I񩸃9rzhMK!??CAIyae 씜((V&wW#dHbve=tCxqj~i'Uq^oӁ~&Fk x[F`w"26̝Bٞ&mͧQ6d#T/u8*I"H7>}4% 2GuX8(6t6+*N|k\Aev#X! YT~@oos,BSΗA+ wC J3zє|/ 8ȸEĴ\"8z>dIZ~=kY z )h&/eB DÔ<*~Hx5d5q* M>؊(SԹSD0smv`WV 'OJslWt5t P|_~VWCL> K: 9Af`ʿղZT@צ.a%/#Jc4x^&aK|Z.YLt&Db01>c-^H`R#}<;y*q$7z&.<lVƊ\%mAђ% =SF%K9*-01Y6. dMf-tkEJb <-b=oKo`.2ǐψC:LA᭤4GGءz/Eh2_[EW9 "6-=+7$KoV p|k{1R]5vCx˴~3PnV(g/x4(ߪԺꄩcD4v2--#ޕ`2$-@  UI}Qۈ`[-K.me$t=l;>EY 9oaDҪhl 0"ڨ}Lqx8rao-Ćr+S87rP ea@C;"92#oemR8jJ+wfe*W0v9{q^Ky=ONuytL` $E3>[ !_UD_)>+Rn#x&gOpc]|><: ۦsW LcB|[A5 7ݤY2ݻk5}O:t24Kw#<aPc-Yq#B3irRe7"ijV획QmYsMY)pW"۔98o&!x3 +VHsʱxj JH|sA n} ګRo>(\It7G[)%ls}uL~9(|U5ӲuşYӶcE>D0k`$k*1qßK{gL@#5{Jx?H|S߽VEwcZAs >qRo0J!ߕZWiͅ@h8SE˖qfR7i)8_,ϩdV 8ZN.,F+ϒ04{L'11le!HG&gDOm @<($L#*8oG`E^!wfmp=t%CeWIMDS RXI{w$3l`u}AJI"^?v9M}uBǥt=D?3+$'i(1bFC>&>ѧ$rɆ*|@0]ߔ;}D~m?Ɛ?Al|y&+-U@z:v")^@-Ӥҡ)-&3 ´˾'G2.,^zf^sKfK}ܛl Àὐh<%n_ Vs%\ٮ@[[&U{Iiv`~ܓ4͘~h5ku+FJ(bjVrZ«JH%LTXCbo@,B"!bgK"z1tEy!֑rgrtn!9-ث/FyI);iފ2Gqu_ @,f2nA.+iJLȋBǣk_'A:͚)J&&PF-;t2)k+>G}aJeB\4>7svl@[3̭p H1ҍSVqyuYj68khiNboEiSd+{Ħ{H1ǼЖh!4MF)GAS3_@^W¿H9W _KQ *b{M“䎆apgqvc.'ٟPyluUD6N|G cb nqBQߚ$z%%۷i2m;yاb?E0 #wi \ >M׳Oqvqv?ZbaECܖ ыW:tbWu|JӪ"vG-ڵ7Kmɘ +meb9lPxx AmKOk`M 4Px[*W<#~?U v"n0cl^Nf L]hl5IpсF 6[ 3˷1`_H Wno?f촨">(IÆ4b3"54=_v40՘[kgpі]$V",[ FKE;~B=x8&㬪ӫO9/?.F/TMWܘ7 T91YxUNIXfi֪.շp 'o] >?y#othNm*ֿ*}ʮf?_eĥN悲S>'3K']-1[.]jVk(;=iܖED`[bWhi S+B:nj[Wa㣘7L`}T$.qȝ0$6@q@bk*Q+kz3qlȨ.SeEPq׸|=0ɍ&׈hx1L ST^5I@0XO۲~{9ik@i`[Ut(h/Y+] $O *|uVgg ~AcAH'lT>LZ ,C::?tJ"֍ǪMfJ ?kRfJ)Ǎ!t3YBMYtU,,v^s\B9 "ŗ x&~͒jӞXv8(fu J6V? *!2;V[q y@_CːFCU}XS!U < ,YhJB"TDA%G~pwȎ|7~LBu|Bb5:WA"AΑ|oyo\]m)+:_t˟{$Il1%"yjַm3o7GA1"\G5kDl+j$%Yrn:oK6$-u"ag "=*٧4-<0 ͝E*ުgT k ?`)=b]b;, ׈1?ٔK9v2.huvb'zg"nRgH;5~&H a8Յ,Ub[l"o@h"t$/(Y=GCyBHY-a,o'#*y:#Y꼡͜o9 6Q`zʪV^T><`͂n0tB '"4>0ĞLN/z@o"a@5Rr(cʃ"!%!J;tRwD`("Mˉ=c?>sZ8טQ5z:U7|덾ہ|8OC_|gSe_(V+ :es⌄ sZSt[y9s]>_VG&TuwE >U[:͈!w{ 7j[85,& B}+!oGƍ)a(C+w"箄3J0aAk,kZ .ulcC}'Z0(l 0 ZV^ӱx,% fJ0 )`D'҆9Gs3#F p )%,tˍ;m@H%S} ?jػnpbɡ&jYU81u$3ֶiC^X***,D;U&\JnW d%qإ%2Xf1JU%DbLGK%o!@ӕ5-Z8S힃Bh P2.eGK$$%g*~mRϯwrbAPi3-yHoJ]{j"œOy JcdvjBQa- K#nI8Û ti(~dd_7s1P721_VDB-?/z˴k2+,4@cԏ+– sFD·cgdpl=z=fe: ؟1Oa/-mօ^UZVus!Kh>̯e/\0)R\O-W{ajfTem\fq@+u"5=5x*,k]-m > -mPᐪ&{lUU)jcz-pʍh (I_NwVdCr垑}_mKIUy983 c4 8.w\܁5w)qxZDr=.b:5(٨9rS%}3SOD"nseDYϝdH$L`@{Yi >Bk6I"c:'XlSkR6:nm(pvq5ݫ*d#BhoU$b Ffl1&nһ(էQ<eYN-gXT 6&+o Q9?cW[s]sX>!'*(ևG*t1O&)fp SRvC$VnQxH;άON:ej6pV{cců,J7XB̫AH+S{8WD6pPmiѡ ]Z1u0m?V0}^£[I 1l,1n͏4㽨_W8+fvGYx{m4 gѩzOO8UQ%LgyӤ#uHR-nr;,י*` $>Aj{n G)ֿa)ϼ}aÏ5NQ Rr&Rʇa FD9~$Arb !>X_t'~P%Tv&.W8Jy$)a^*ԗT"`}3gu(O~okziߓbCUo)D*^o0AfSr!'z@{Ֆ3LJib4\bYkv)Z{mO2n*@xCZw [+dd륖3ϔJYznϛup):!p뢷N2s&@(&x:WoJN4 F=m/=N~x&38s1bDMߩVf Ht֪Ηc l4^Vk_IH Cn=@Y-t6!+C>C+6qBHE5e 6-5f߸u3N?j>ZNu7b;wE|}%?1 =Jk=ޯ̔J:7^ca[6$(5Qe!#!o"#KU~%\P4ĆRT5H2#xkcz05^ ~e$@1܅|ۨJŐ]DE1Pe0# ̬K"p=7 %Uz>\EޔRnS\C 3=jL\[__W\MT@'؟y D=7TC/)){s[ONUQ   IF)3r=/n~&^U/;^KY~8]&uuh`ѭ䏋e讂I+uOoM3cٟ^6ZIxcti B%*FA*%1fn7FQO<[[r_KUerbDrgd%nX<(_2gz'Ye@@S[UKC dp7x>Ś]q3Vh[+;F\2x~ ġ1Y^E?U,<d=x-.;̋+rt)IT[0Ysan@3v9P` | lojcpo!ok hG؁~Muh`X[z%i Mzp?c.*NX._ѝQgjn&2_bt%\:bF9wKIwr K(5*w.>ckֹ+) phwX)wwaڦByRVk k3tQ;J3  =S0-cdž+hMLRlGݟ`O1@A$|WfBǓ*[:Z:IkrCZw/*SHSƠZw&\yӳEH6Ң<,PMd^z!3kGA\u'FTߛt% 2.˟o xORmdE}GDp'ʶ)2Q`Qqv0\hфx7?B]R~hSrݼ K6yvIZ=B5WĿ%Id")~e')"0ʼ4=t~T,U]οQhxU ^,J6y+zm=D9 PQRZ|rf@3OXPR;քyZ) W@蘭"jj15č vz/ں ;]xew]8gl?0<gjVW'wѪ=*,ox5rOumG9Pf( vʾ =TU@KZBQZm$% GQWH)iCuۯVIC C+5ѹ_PJ;!\=^6Bad(*}&JuTu$ȄT{Ld UzgǐmHPܐXV93"DrlEo k_=txҖϏ9NgM#6qN9U맛̧gb7EF$,۞@..ʜ^[x d[QX`gS/`lzGl~['OMU79Pubԙ'p0M S@/_EzoL2Bh?:fH‡nC% +lO7AW:۠N}%Ç۵qBn\=@CKdRM{R\ZQ 8 M[+pFps̷T;vP0cfB9SXLekx.Ǖ =k? `y Y+\3b]]R I, שcbaWAc @EE~RT{^"2 bٽ_?&"}W,Nrܷǫl%l ՘!1#Wre=vQnۯ 7>xcsOch9_.Tg2tjs7h/lACAW{-v[:gm@lp`8LmOfᾜg>֡SPb73!Quo 3jnZ2$lC}\gJKDWW$tl.S` 0C O3B4ۂb<㵝Fލt)+$%D'$bގg%| ԁ>Q;[Q&3WvĖ,LfMw/vBSG9/Fi2vpSYv?l@}>MOVZjc[],N9Բ"6(fj4]\gh*W=kTC[1a_w]$dJ.{4aAl]'=<0dqw/ WYٌ󸥾:ɝqRe=oz~7+:`'Y _>͸\lG&$6FDBf%Vl@żyC4c-?ϣaN|׆L>|s}W4`Y)Hw0+RpzpՔ>~4YpƋc4öL4QbLTbX}k|s,L U9’z25obDIY$5@QcϚ_"wzڷnoo8 EE;_/{.h@fu:a@ Yx+h$c)SAw]AR-K9&8sFg= eMNhPs]ĺ-ml8bp70ؽxj_)6<ogӄ_r>7<}nG"}_ɃzbuJ5 "~;7#]pZT(94a7=h Eڗg-t.7 $,mc9> ԆjRD<.;56JyF>'<3OVDSx<_3ufZ+Ah= T+k, d7e[O%N!N">`Vs߃x WOeAXZG#1ٽ.[f ]ô;AK@5~>E8*$ui؅HV~>Z|$"HP{y`9fx 4R׀ 8/DƊHG{!c9 ۠Y2ڳ^X#%z,,z{#>yM؟P.9q3'92,n/".s5,X# E4p9ߕG",l|j~'nG\$O z/0)8|pHc̴VrFi֐0kYR.rѳ-cSXTC&m3Ս/2r0JDeZڠ<,`Ռ8S\5gn4FXǭ H:{$AցlpHc{5rR( n^AB{U(b˩P)fd{}@>jPs \LIJݛ9!AGG1:ԁf{iѮtt$ԌT]C5;UkNZ6uw~,5 ?Cm|E^b n_埮l(gCPbT,O{Mlr)1 d 4Σyy5 DWQEn3cy$pw،ݚkO$9Kh }/VElC kMk.Mq.~cMw?H3W4%b⒜gj26r쐰C-*ci%A_˞QΌ^#9/x/'J$Cq)N&!¨ ںm:l F 1.s&`1()G<̟p34z<ܻi{ GJWE?ɑ bL2Ƃk;r'DWa JO5iW;`Be-,鵞r];mL]54sXmM;#.$S"43'@>0 "1 q~^Nuy-u{&o7k=[$rIoi̸MYx-az,.l\#1$i v!cRM$'bX?SЃFC|,CLd2({F)!*}v힚m. 5NsԵ+hh,gYV1`t5ޟ3J 1S^db*g/!UzٸIP%~`7&kŎ%_Üu5raG5 " =RL*A)\mޟ3lW5voZA;F򬋅EaNBj<JzfkrI0t;>Q*q?qMŜ[Y7•E^'K;bZܒ bǒҖFJ|l>p艶73nկU0f r+>, "3 8XBR_Y[s\T8x{iw^(w27$5a TxlFr%C6>K>HW>520תy'@=WW)TSceTs>xRI *UG-/vR/J`,f4(/Oy(nF>LZsBIosI\yAe'/dX%ҙ3y I3,9hdomS9}c@O}4m'G\Se^k?=9oANa yAl̓5?ٹ0•NJ55*eT^qDck.l#ԔR?GC@ȋVᗎ/2QF'dV k&kUmEDBZ-rToG)yjp^놶*mX.('WXt^!#tW&7KAO]syM95Q.8>9Z?+i<Pu]D  ⎐HPI6ÎpO@6wPqeR+ng=W_J`?N;a2) \tHpkW]vѲ`OAuTP8YeN|03 \)<(з4WW8 yT7WX.GX8"w6F*d'BYV2T}Of+@ Z@-j) 4x&MQBEH{ A>;@wdr؁.L[W)n h=9{c72|rqE$^8a\M_uigV6 31>X~ߖs]^z%xa1c iT!9`լ@H ~o 7$H``<'-jض[C gI]y[kXF~%O ,l4+߳w$u ::?Op|kp#n]p,&8s ,NjԱG]MⴹHЁL0-sq P_P8hi21[B3Bjm}ד0{ܲRq&Ul{zħ*;oG 8d~!n )E$Jz 7] H8vB%^|i?:^J03>Z󳌿Y-e`c>N"6D)s6=Nn* lӭ%ܾp 0kYVSu4YX`ѡj5G'+A$^Ò|WirqEuXV=XG6SO m-v#.!L6=W҅ne`N!3 Yސ _ȲK .Lؐ`2"oGcC.0^?oYURs\,m{gh~3 l0]-5Yz*C}.'94$XD!]~'UbnVR3}A7?[36W MKY,USؽ!S9wGc2ILbϤ'=xLZqv:e5E RV(:S"MhxLhle;\9Ʒۋ@:8g$> KݺǼXx}06bboƦy޲64 e )~6&-yH9b]\[5Ѳ?>Յ7 =>ӴS >ϚGY9.k:9= ; DT}iṛXdHBy8@6 JMV9<ऍ0qi^8G}wBAp9ni{C#;O fӑbi;'\}DlM}-gl+"mի{SuoH0MMxaE IF8n9˙1ulk +nBRO _ im̕Qхm8vepܝō' p<+dz& .ui(8#\M01cs֣`DݫVoE; byuY-6RK]Bms = 9x!]bLXUXHP|d⬀eI!x:!![ǧ 1k.r[#YBԚB #Mg̸#x:QOQc {^3i{6rސ@(?SGwQLjTkr#Y/O4GLKAs ,KܜѓnhQRݏZUs%Oet= ˧)XsX%mcr!6- ?vl1SQ:fX+"@,k+P]G&k7qPc"~K6 jn1M8hlaOPzd^$7}dm''j:G)Z/}zΚ6_ZB Sހr7J*vF^N.>N|vkplЇ*2KN*O\DʧJl]V+B]sӂfwaSk 3UrO'VЃ'TTUjbxӓ4CXh5 -OtdY)hXi$VT mKEaɾPnG쩅UJ݁vn)kj%]k']׸ oo6 |<Ei,ov;OAB i-_V,ſu$} l&2zx-/lcj)@%ؽ8Nc! icbb2?GW*X3i⧂D^N,=&]!(M0E^?$lq0CRw~c/A__Ah E'i0]4_Qp$?k+1G`89-@!Nfš}9UbXhVL| -zd#P|t; - tkYϠҮ ڀI26-Vx#3qܢ {+Zz뵟s9\jB[^ϛRQ@؊^D}Y@WG:uNYM|i5O:R k845 JH`@hlc#/[VTRuWU cdO}IԕVۨ nMӮ.6UDqn/u[ZT<Rb uZOӃu4~RUPbd+c=|mj}Y^ϼKG)1-gʫMf]:ղFO̐C{dQSAǏ bj^}O"@GC79G7&Ur3){`x-q#ޑ ީӖ۪| p"ɚ7Kw @B>#|Ea_nUVDZY6wWxPNm%:oG|V&m܊n ue.QoVêWyJ./IfI0)TXRY%i$ NDKV#2< r2wzHxO!DŽCOOUP/%9wj3Lu^;EU| dsx rcyňXwיΒu?a.bJtA;}uu<$@ɬg>ZDxH <\y /'<3Qj+uQB+aU}"JطyEE%"WgLKCdxTӉ:B&v?+22U-D(O 3n<`:0?|%+_~b>[~ˆ& K5RPO$Mrl]4.?BY|׹^tp7*aH6 F\p}JA4GeԦ9Oh.=t%|+ȡ"||/y8}r Ҩ]I" }Y6Ѱ!xKz}RaݭF$ paS}6n0opVD)o~hw>rs6Z`OWG~@1R!IRBuM. _"0ȢC&dfb60-IG*b-<@`rmG Rvd+(RRBT" Mt5yهHw䞇! Z F[ԩ`S03uAzy#*4qDǬ41qy?_:g -:9)-ڴr9>M9ctM,6p 1(bE\R"m_ws`Ƒ@p,~cs~XGu5+(8IS,m#fl3mI{Qh?r /DKt1Pxҗ:6FMciRyCv~ Kya+-' X1F ඦ(z͡of|эjPNM2-lVә#M͓ʺ.~9 K覐.Nuf,=2eIoǑ8~ leK'LܿaEFGt#KNy;SY1+<:굝c ;6NMװ_+Zh7 Y  z|UYm[wU$Hf#Z& ;/~M10ݚD 7ͷF[QMy-nB8τ7ԗ~%ja X+ 0F9vY|[>xkQDmdGJ]_F#;U\F8g9=5KŲ[n[(m&% &'.KD mhcia(4?~n ULJFZ^r-bS KR2[U{),M3 l!dVL(3a[OQ@ghLяI~_\]eEdpE&5]7rZ%>dU5+ B܏zr x 3 94i˛Y\,M4"S @.ef@,#ŤR bϓ_?J¤`Ā3;qԽ o;Hײ "kf$KO/6oIn\ZydEO|MƑS>'Yǐ mQdΤQ#|2X4``O7_n'g$biy宬w:_%݊;y+N1_Md Q-5KwOPWͅTzb 儨A;3h(iY_ivHZ8Ps"ELFEK,^c"(:Z8tGxV=uLi-;OLh4]c$4;ez{*YEuZ|--( yo|F7Sͱ+:%>i,/38-#Ag~WYڷWqng͕8N\c7/4LN~8:9DB$>?'5<<:?>_3?vh)FGyq98lb|IJqFզx*7s\9usԽ\f0Ni)ԏ4M&Jݞ&>R%<)1s/ywלج b򮤈%D!3+_$QI9| yYdY cfx3RF i>Z郴z Tw>i~K0ѻnHoxTx|S4LxL .Ŝ#dzx V9KI1?^Џ1π! :bϪ~'}>o- 7+.G|/G5߭ұޭ$W4?Y'|w58{[P8dt ˅{r'RdUOҹP.PoBkO3&py òݿ[$#O!T-ir E+D2H'SKCpX6 "V10`6 lE_NH լ#YH/X>Xsj͙h2$ h*xV6;zwA؈b.:_.!9i"-5:% r-6Q: ~>AuM! |F,4/MRFFO"ؗW4[]eHS |z x[hx/R F,CDP'dz]x,ݼB 29)!BX.t2:HX\I_tr-7'iWP0u. e >6\z~X| ,aϽLmS 2[W %hqil(tCMB]P$v5RCύ`U>GGt3W hOo00nswҝEXLU -@PJj,"L=ɲXlyQN!nSUjŪR癩}IItaN'DM=vfg٤)CIJi~*@wP6ە,tt]Cp>ņA7*vm1^h@EZȌ!- JV6e9Z' ]ч?W#Ay$b2"p(_9^$4<☽h}e@s>|Bn37]܎7kS'd$[(*D[ '*2r3jݩSž ?=šytǓO>_Zk *I\lj`%l:0$!J o *G&=f Y h`w OȆ&R݋SGEkoRA;n4 c R(An$| 6ѽ:C|7uU}Yߤz|0+1!59\.ӘdZe +%˄aM1G+W:}oh z@%qs,]ygxSC3&h!#'A2JAU*=AW7OGy֮}u…V׆*a)S4Z+|Xeȯ3ucKGw9eӁ pnTj2nbðD|ey!"+nKDp= ht./z8t]4{4%8\iXi70Blg خ4MnneG#B,bfv bQqãiS2Ͻ ]̍#y I&BA^a)*dN81JBj-:/^Lbl svG#'Z撍5,v4& (A0 ?K ǧ^eFp?Yj>jp<^&N;'\R$BIe<,^rJHl!52ԭ@`6xqN'NOBϦ%PA=2W,@fTנ|Dq+wVB̶mnlerj/ŀvcaBd!-2 fnOIw?vw Ғ{r H ZxjA?{nDWdV"AY'#6`ED?MXs̍ll& {F5fS0 8(06G?NKUs"Y p1r!Y, w54[z\ _?z YnTP#&1Q 6nO[R6l$8%o@9HN*A2Ԏ<D=VgE@G ڋn.UAB{ n[̏%05`}վbTB;Y{g.sq!}`p87%{ӶUsn 4гFv#wr.Dy0CvvU3O݈ t4g NbWz#5?G A.(3/O<|םh/IRS@yҔeNw3YstEӾ#_Sx1wZ_C k6@ #Rֳfb>{tՅB *q3vblVfH Y!d۳ɬD @?2n;YGx @W(9eJ`PUZάln!Xxʛjon2L"`N77Hލ}W:zR^HV.\]=w!x],,$3@T%y:~g_? 3QfDy,r˝ 0m)@ [/}6 KfVLYpa8 /] ~bpLip6pNP{4%ˠXZ^En+X1vX桩EB܃5%FRϝwLIi,5؆#]6e P1,ݲ$@¼W (>X3NJœ`8Py/U.Ε&/^#%s"!\d*wwE/ Fg2wo4 ܜE-G N %c|`tlJ,{O<4yr+.,k[ճ"e {䀥4A%f!Jm\KÖMel~r[",m 2r[o[]پ{r]3Y!d"mb,-Ōz7? TR#XnͩsoW .Knc?C/1 .6PSqpe+[{Gd탈+jV|7>F{]e g-RY.òY;њeD>?`+˱y<]%բb46[Gڕ<;-/Iߴv\'$ k>O/cZK:&`DbGj7@P6l-ŊhcR6 b3R?5-3>zavIks]e-[i[?Uۼ|ѣx2g#I'bʰ}()O>kX7V(X l,UE >wۣ8C,>PW6g^J"v|>-ĹL5E1?{f8\ESK%w ƟEsU/;>|ך 1+6x8Vw\Zʡ,EW|$.Y|ZG!sn\ȅ˺ZlK :\McW]{8.Ofo*} ,6|(hX߿P!Y*RԷNˠ[ q8ML>%湮ql5#*> HC4;~A#+H+3-IOU$[I-_8 sSr6Ęޓ rL20lI6߭d9}J/i;'2,$ЏXo-oHrvgn9p/]Gw לc:L8;NQP9x s̈W#taʒ]@Du2:> ; o0t½mwu{ +U߆_^ĻS&MakA hL~-BgAj o h,=} Rŵ!x.=B=BwYu5Qwt>_7M)_İE5Ok}\'kvkL~0y)(=p42?(3͚LGtvEh=P兵q A 0 ߋU)zBSkp:WmA*o+ QFQCk6O G)s-],K)!se~pw<+6ثl 7*:Y [e^(n;>nWc [  =CsEGK2Ye]q6[Jލn|qxyaqhFǖ`-vƾ V }>JH!]}0q^P%8C`X@2hh )ϱTBu!D+ؑ'v ' tޛUE!U6\ŪPb|^Յ N ?N;a+,LLi2kD1|2%)edOo gE@;~JkL$#h!*yͮ(3O8Ot K0gHyCzNzS%x/G_(vO3l1M$Ivʥ씐+8۞zcZAu"oYŚ!(c !r`]0gM9utIt@78Ag9LREi'[x<1 G EћJ; _AIՑP׶6jܠ/Dǩ.miBQÎF p$ЛYXy!q|6* uK:W&ڇ1/MD U1y2R?gOE(kؓ>wݨת_0!!ft:q^K^cp?ʿC͟C4,hi>#khsW{Ϙpux"k3pT`[k^r|12ݣ>Pth(JBPWTsqUxG9z|T'`M$}hd;yu"xFvKSk8!^3 \CvmoYKqnJя%K֬e9K *Yx˞`K%fRص`nNԵp@G*H@"mRML3~ np{VE+ק"d/KŘEo:T&Y3&3Yʨڟ+} XH҃BgڼSGu(r+ S@FGxkXr X'IUof9'V⮑˾YЅ Ux Sz^tQ|^ETqةe:Uvb7-LܩT/HMɷc.iKoti7X[z+ /ZGCFִ6#z*|_dXQ 1sO`-~JY;44J۲(8Y86 ÖZM.b8GcܾEqg܉mM&yŪ詚ɇ,Zhy f(οS:4'q@u d~~up8X!kb5."Q5bϟ%D"^$:P` B;O)B>'/?Q6HkJ`8BrDGt -˩z"Ao %=P75_CLsf6fCMYyn(ۑOpn6)]kIn&N30jD|@R {x]x_E<&F ֤[5yŭqr|"vK%~ `jH7ђz.Mq1 ~1+t_I%*6O`9rLTrDcynޕ09agj0/u@4IFV5 U3rJҢ*E#4\FQ?9iQ<" g_ 49 濴qET6$Wȿw3ڗY1v:R_`ápCy6 i)̜ݭ;]4\ $(d3s $8MWgv;[}(;Ԅbf&_I†A1?73Z!1_JsRwh>wるn:w~{wl,vX2 @7yZތ/Fz;kʔ9n:j`0);L1KukCڌ,UGЪL-VaU1P_ @h lmqzp[}1*Bn6GN?L9rQ' L> KP \n3]G,=դme)  L݁FBS &{ }(.[ @c=(SŶ,QN6'X ;N7gSM=q4;8p%VEEx`ҽd"_zaw(j(=Yɐy,U<ƹ&S!Zl˕|XKlQgpZM!NGR*omB򪸋&^TSg|h0Ȩe*C5MkmV%pljXJ8)C h)h>goO֝W׃[yy&o^`ekZ-{t@#Gd4ɘлzh=hƴ6 MvEkO`Frhb_/q32:EiL1$oou]7GLl~w!# ]w굑XN- Eꕽ3O9 Hh}%Z"Uc!kzlS`%*J/mF<ŞcuK$MrZx|(鉶 й䂲<}P=҂czsECoF%/y ϸdjҌuu4͒MKGSuRwKr \EwAӭ.~#yb?%{E;/ UFa]"ҸHEKSW$|3b&N쥤cBb \ ^FxXC!;ϏEZǝ6L,ǥ~t/)ަ,0Oj26Ƽxܳg];LQʽ;q6 @* |!8P==*uDru͎X{>W;yeUKQf,g◗2';ǵ 1!mZ]2g5T%P3 TڴJaǫxn'%xhحNˈoVfN{*|UeJ;̘!F(\F]< x=NlI}oLLdK\Ѐ$t-Qfe$-;FUܕ\uT2mv#H+URl iϬe fפnH[%^T,\CnyccX-hcsG 9 4(Ntf&ffcy5ܮ. cfxhѾstP.6Q]L B*1G=rnZ]*.tQ@⦺7S[dʂxa mkoof@4-I\IuLt.]4XB|-aE[;q 30-uRod!2^Y,d-sBd~}Q'2^ A0OK,?m& |7k.4w29;LT[<[Nc'|2(Re eR{8lsŪ!~3v88m,[T~InՍ Zrz רB+\A"a_KMxZ< H zd"#Xb㍭וotE-%*)IdY =k2lL"&pPJ3suqPJȲO.kU)C2h; go[u67m0f OaCA O!XeRI\TH9=߮PMb+,P̾ך )I]s(&&B_ʽWȊTo/|5\R&mZ☯efG U Zo OqN*# RS9AUvdHmY{;hrkrW5!ty\ZLr0g7qӕX~-wݏH:8 " |'m39&{Y7:09)!7ewO_=@GAZ Abzw+^aZyQScU?ҷƁmo4g~"$ lx0U~p1B:ADca`*֯P7Ϋc|6@}Ӿ01I\O[_}"h9- q_3CuJNDL:¶Hk>Qڠo:l zALyݮ,GfQvrSt:d4(c !&sm!wglUyʭfսS wnEd6@EYJ nioFmh+O+v˶8\9 -9I&@b*y4@Z \Imf|Б;Mo':xiH}J|y%"+nYldVWqpxSxF$-;c cpdֹ/b1H'O^&ʷE@2Tlhǒ/ TBC>iŚ"ɔAI"v.E9w|o k7.k/`3xz9{&]lO9u ˶ XҀ_oboF0{l{i wb3M 6`u4XנEd}I\1vJTUo ͅ Dwkj#> /Gփxpw-}96?/K5 ~Fd@WLH _ RjT cYDAL=}(ڛt/RUT'$\ {LV(*L6.ۻ>XGĻF1WzZA-~G?CXۃixV-GV0W@P/2sm0N$ vNU0aA3˘~@!:bFGTAHA)*DGsH/A>q" `Ns@sGw~H:.nDʡVWH%MЕR`r(i gZ,cL51c E]5 ިJA-vc*KAL5 ~YdOE DlӗXidmQq2UHGƞ iwY*v>?@W׼BCL^vp -<\+24OJyXo3dD"݋%KTvRk T7mI/ԝ׳z&bo i.tIsq/8DB?_8JP6Jɛ`-x&S pY$A i&3܆1]Y*`{EEGZ"WͶBwwiTa\Ls=ָ:KJ!J qҶY. 0Eqc{G_o҄d{BQ8.ᡥs<+O'U](mB\hzj(# p#JWy`XYG,/I%|/D+!nX@lIH(3>=Xpe8"HW|ayy{7a"d *%p`OA|>r*m('JyV2-XfRluI9yoœ:斿r " @c-m1^J?KA 0?0Q%+bO슢 I:׷wm7uT9B0$yAM /D#TnǦ|=qjc-%m;-V3}| _~6r$$t5͹U{ $)x]E57eFk*iҮoEba6(!TJGN:\tڀl r9nVk+Y@*JN<&ķv>p-ۛ1U_3II^y5(B!% P<dsiv?k\9|V:˅QsG'eWd =ZoV`_- ? >f=f< E+ZL Z9s{"$Ysk(t+oÝUY_Uza#ؓS)T.tUiT8kCVE 8Ot!+.J'uDVN9 T+Mf|+m.|e "n ڵ\hʹph/59n;ʂw$i*Q!gQ.LYC@hϰóZ0%ziRXOtMX/>@ŏdXd=5U?5Z]443]g~4YZͱ)FLG~v?װ~uT 915;,$u-M>?HŨՐlb=:Z3] IGx.jP+; A4=% bƣ`o&G  ag>> I6McQ|Cnwҕ5 U1r{SS  Sǐ{*2A)8SAEݥ$8skvPLh[&)*Xfyf d bv?Ӑhmu*EnsrL_Ed0?:մɥM PI.oePI]3Ei챛xl2Jq5Q3KnټCV1i"lhh_f8nL! HHT+QOru/P{%FG'#OID9a0ڽ5k`=g.hAe3%bX wROOie_ub %E0zOҹ8Ȕj5hVPcd`AchZpDCOo!n|w?ז&?IZ"oi?bI-~%~ ǘW28 S/d^Vx73S"bFUèZh射rq]+JIp'KL&pnrҒ4tt>:w{Th L6r@~Z@rڝRe%;,DpoV{B&*m(Nz7")I)~װIz7^AB=̥.8TURih81/Va'wI=DV>~V- B*DPP\Hj)Du9 `KC ]ujWaZ3zfimWjSE|҂yhg&Y0Gxq\l#ORn]@U9LXҟH X]zv<1KJT!" @\ۏ4Ef5]jW`?0>9+-M+t 0eesہG 2 ?R :K6 5:ol?Gk-fmvK !Q U2:ľQY\.z'f*V"O#䁙n- N" (262EMj1 toLTÕ íRq7_pPQZml" #}85oq)Xva҆y/OZi}%ke܄T*ՏȖZ rE[n8Km 6E[|P bj܈UyX?~f称=2w;nj]08hf0Ӑc*,O*5MFWNBN?m8vXM[}/D @hNCDy?R숕7R@+Ð[ C?gRM5 ˅Y␖xMf>qN"Y=# (9W 8 v=Reh1r9~unIˎM9&kɰ}RI#}bD@&^ͭ` ­S"O֣X5)PEI#C ځD-dқ:5xlkw wˡ~qGq/C9uJ*=1%b6f؆lNѵ"_݊(|Z{b.{%T \xhr%JiI+̟C9㢽ЎV,yʃJeY|L͵ة_*;;%*Ow5ׁT5&nK{x3{`kSJ;UjW禓KXur{]~8<aM}%.#Z;*:3ݙhÙ^M/VSQipOGͭޖd\cp0RV 8??Dž#+WDy=w2oF!eR Xj y4!.;F~I办8{!̀ӹNu1~xtIV澑> Uϰ}Yhzne>0N7 .2A8y^? 6ʲ"4ﮙEVj'Ǟ$\rru%V:w&xiQ;Б!+Ƌ`\:׏`R?f&\2Y<( %j .>4+憟J+X;]#, '42-x"T;),rٻMgVcT=,U: D {U lfs5c$9"oq;)p~\DjLaBQmuV3觋~fH;G?6_cL zN=r-"&w`%dtѝVe."hed4:{̜>u 8v5|%(-o|U~FWɡS?TjʣZ7$`;9$zL&7Rź3*.i 6Ƌ" r *Pe0h/(%+UA*zZ?_&$O-~tzwVZ%HUCG\yO 3DG1<Օw߲* 3 JPk xV&Ɯ[L/1~Jקa̜9:`/P4xyCatKn^DwT4GQQ7Av޿gJv0 lDSl֐(fɈkQ3"` !T΢qX .r.@:{n9p+GU;Mޫ 25,)Rv-뎱wuCs$(*]DJ갽zg3h5@zEc%H_ܖIt*22ŜDF3=yJG7 3XI{ /dPJ ՊZt7-;$Ԭ&+3ccĞ*闱ZJMG_{|"E v#|QM^[N YsRb}@qvhxj8ukUjQI[@0;v4}5&je/;f?Sjw+P= &KeW:ʬ15M:jGjC?yl:$@~I]ɉC%V\ݜy(C 5. K-i f^uHfVD1%Y.k#f]0 kwOq%E*X_WVfDOxt/ۋ~&~m+] ̐,xC Dk𥳒U ~ji2 HGL@/m<;1q0](LfByM4њGv+r}FW}ͪ_"B !ʉ^8#aqeၘ?BRyS)CLpvF4 W~?W΂XjkB0 %2SAɹ= 0e2.Cd8>Kbrw eb{a9_!1y v8TQjfF@kym6r&>dcKqW".`q j>@\Y=W9<@3{rgv)(yDbMW@eYF6X;ݡfٔw 4V]fDDսεӗl]o )(V5C#}Q,ݒE^{e4lX{ wǿi#+ؘo#)!3kkR[10);*|Rz?,A\9܋m0Y'_&Ua#L@g) ߔ6dNh n=O',)툃 V<"?S k9Ϸm`X`Y}'@לmޏk+txFL9i=ک锂5I~ߧ OHA<ױ{錸bёUvk +78p{1WPO'$4ˢXd[:?=:rSp U}8܊|*91Hqʡ\1^UWkc[1P`Hظ7VXY7iB0vL7#U% `jC>2γ28-u 8+9HV5&7 KM_g_M,JpYü׷ N`Yv+jLT4* ',$%)?v_(1\/gؾtJW]rD5Bt(r^eRvs$0H 7: tIV0![&z XQJ9i!,@99դCɆ_{$\FjBPLw(;Ncu~) &E}vhhX ? w}-["UH| ]Dji5ԓDj^Y&|xZ{:& 26ЫcE~HonrCE4&,L^Rc@ǧNJ Aa>^G6`ާl 꺥'Im>׮= A;iv^{njCoYРnjtl)+Z'(J23sh^'&˅퇵~% fILxȧQC!'98XJe>1 ~WuU.ۜEۀ•{ 24Y؎kK-*9sP :`8E,NٍfǥT(88}Ta aJBȮ)xF^Ҋn>lRxeyziV`<) =;\NB,XmԈRm=%3;DY!]MdE6`?V精&*0KM`U텊+vr+Uc(c}'N?{ot(ڳ l0,Dž90Ձ-TB[~F`Kk= B7NN{gT4{[kOfl-+9{d.ʴ-mҢ( Qɛp_DAGƕU% 꼙_9߀P9SX,`DnoDrAw_nwL O!)n$նy" pNpj j"4JK~z,JZ%Y} [55xqCv]tܸGŋ#.G|C-w(מ.6o#FBA?_H?]JFt.H'yN?u]A.rKB*ˌLEu1~U?}đo 54KhJEj¼FB)aS)g4IZhp4tD@*~$+Ćj\P|% SXn'{i\ \.{ Nk=9 9iНDŽj̇A ÝoI"A # !~PPm}H04z׾z4Y]fLNe,ĥnvЃ#!^ź<8pvg@Mb؂VYblj=\ ݈"*9X uS+D`\i ᫐\1`=[Pא e -klsװ@g^"{*oV9jlD4oX q`|m*z>NG K08|@iڍ#$ƘTULBl)sZLjxKh( " l)r(>/zSey_SmxךS']'LW.@X5fGо"0;Y hj#ܕ:s9:f% Esu&0 r!VޕassbMfy(v\10ݕe {:l&d FU(uɣ֬t:܎jN>^yX /Kdū}{'=w߀X(7wAg*"Em} ξbϺ̲ǸW^`e=>i$ lY7.7DC)$mxKvrh?1s'dbƬ87L,kPM?D]ZOLR:j;ϙCmSgw)QFB݋9L !g+a(ؐ$3*gop[tȒS]*DK-IZCTd3*cZ c!"V\adnr]cI|G99F~=\?1lPVɐZCX&qg ] $ (HN$^ PC0d @=ÌNDÜthչ\?#nzo|MdjLeS9"X_*doke PgG@H4RIϠ8GdWwQQpnw=ꧭӳ}2fWrl:J$*);4a˃Qjޗ2DWC҉xqe "#BT:HQiby5v)i֧T, 6Dh4J"'ns{~d,'A&9t+a>JVdE\%=&;e=_ $iO"߱'ng9#z%[oJyD#ehO]SesEh3G1c*Ag4H3`D'2q3jY_r͟Gr8@T_I,I@d&RB6Ex:|Mtr'՚)JloZ mk?#b ;(- WsIW@ ~!Z=}MG8ۚHJY(\qpkVNš7 wZ27OH->~  MegVlY4'ASkE&/ @WNv-?2㺽M8MV6Mb(|}2]ӜCxOXib1A)%]Yc_=v+yu0n\SKϘ_E[\e{9Ґ-VZ{QvX'P{ Fjx-9TŷÃ+>R™ȴAǹ[ O_(&sC d;@sO^I;4=*p=??Sĕe%uPM8-g]e. ޚmx꼘V+ lQS%ekm9u=t|$+Lε[-Q7=9@Kmz1F *1zn},x\"c44]KIw~)*R;wr, kC.8oVġiEi&Ut?g=뤯KT[=24Cz^EVrS TYݭ2-5m5 |Rn|r_3EFٗX!]b =anr@[ʞWQCbΙ34־m8|rnw5v /6)A j ѨBjWhd ݙ_-c H>N; :;)2{KWXh~]lHՒ^4MGjWDo,CY}S`̧?*+S1qE9+ ډЇ@B1S1CK.@dgw(\7+ 0;(-aC|,%qS ,56[KffvDĩ:VN siހHa8&դ^ԡYq/8FDٗ˭~K3'&^"!׎ DIݲ̣ >.I3&GCrHi'\gΧ3RSrts *qII.4J*XX_Д̝[mlOJӚt;$, /?_@ D=ۑpnVp1́Yzs 5b:?+0 k"OqQqYW%Zs.|}k_tw,)_G,S,+LϊXGhϖe7ZYň.oB",A{ t*zҎL˗05Qpn0y ciuK(E۔{ll#!x6lu-'Eo?. ˷~T99p(7#urkqc}oQJh2Yun[rė ~2,U$>II7h'W=C58drXH(W,GP%1Rdn|,5/jx֊cs'Z^$`!')Rk_#$5sEwЃrcdS;e.SE a6v{#OrOq7<MlC"plm'@8;'Ag h\p "GjۦY :l 7 3ItZrHJ(;;t/[qcz9W$PPvԱZm  svɡn%)BKѾikC tpL ⴏµQ\kN5B *- /Z-L݄C 7b@aнP;2%`ws6Id;~"FaL ~i968!PF1Ru֧*ngsvBbEEʚ+G拋4X"KqjWS-'HBp||u;q0t:H|ƷvoS-x;go 7H2}Xe'"%Z+-|hB<åhM1-h6j^ꢝtDkfǵGVEFKL.?XkH<(.T12/!Fģ=0VF>ձBɷF!Vœexj$3o {uQ#I/ZwpmU(3n_1,Rg!`τmLzǽu5| J+Zr6/,"@eRׂ/)aL @)= )5~CKQ)VIdbsH:;qMj=&2^d_ 5su\4hm!`F5α:Ez\g!ÅPiLxj(#ԑ9G6A07t/;y!eABp1<?|Вj\3YNMBA}.ǁ௅'aZp PF`!2P]{&ث)|vyX}vc_>&%H :a#8GKid0YŦ$SEܻLg3?vBHKnKfP!nƘy 1lM>\p"_qm'ë&aLz`v݆z}Βq=Z%Rn{"{@gͺAuJD-pnjPƶYv(3u/hMƑ/[fR\P@a&(oS`tж$/p\#wN \/TH_)>׮ܨpH z BJ1h reh)o5w"pY,32ʖܳB|29L!kdZX@Vi98{Zn^j5_Qy9D0>ѹdc3 ×`&.(CEwa[h7G@ӓ^<R>|tЉ̌Vk^3з7w2VPS[#6 mr3  a&u9b2~Ē (i(rsb IsW?aZ$շWbBT_Ҭ ڗ-T*Am)0Ϊh[V~R9t,@y0sǕq?B:Pռ7 VEsb=t~gn3ĘS Oi#z Χ\.癑<8N,Jco0Joŧ?Gq (M"'@_i=/tf0h3y}}(m#Z)s>Ve^Wfu>]G pnrO5>JHc%U]5) Krv6oL;U4u4#Tڻ 3-$!bOV_-1u3!pJO.ldr:ba#;G>5*o[mxrKO *AI3|04kR&WXc (.aCVme+BȫNR x/օg/ Cx6?@WahpHԮ{0s|-h } DL!Ʌd\+aĺuRmbbxoTQG};LjskUy?Y;0:7)C]Ef:$Qeu} uU+xYesfΈOh9 RV' p]VZp?Oa-0N3yB:%twf tt]KU adUISdj=e%_K7@ I uĒ±8st9=?C\Rm.YSG{_6OγYe7t9ǵZo x.߁XCxbiǶcW {HWx#E?Gwq&bDO' ءI^(=`Y+E"zwe-t!Ub=Po)eE7?-^1ѥy}:.ԮwȅYwFсʙ[©l@e5 t\SΖycuCd޶`$c0Vm89N v Y׽|}>Mn %C5竪p^%}xF DT~WsQ8#kBS=U߷kGZۨŃGI莃҂vwL l\~,ݑ#_'LD RegM||x hO7Zq(B\F%OCto@ݕ]Jo7$7lxNj u;KKA 3,ܦ_zjk;5upK͓F%aEWJWg }G~=TЊ dE5U_[ xM~e'>撕zM r>XR*ˡEMZ ޕ{61FA@'N*s_N>o?"N bA 0D<{jfA- @q'2-@3>]>v/& owo| o u}+$(}۹P#.dKNС機C@k h-9JL߄־xnE3s] Ɂ'cʅ%ܜ 4KPr,S2Bϣ:Q yB"G@)*Ly $8ݫCa_X딏~*utbM\W?M: I #fb=PykUeH%,>7f.qR7-8NGkvñCEa$,Ο=+P~\Íͯ._[zәRuۼ qI""D mQ px2PI/)3yL"N[Gy`0dZ*} NJCPcFR3BMTQ#c\Dz[3Do!!kt;^ޤGoO}km f{^Myy~he H6ӭJ)?i ddc,dNsQ&K48豏MGj>B0r-(1dni1rjNxaA_WB A"^[ 7X,k&n:%*rbaPֳ5 ?.f`|H71m,2@Q&6bu_tۅ!!+x>x RmmfK~<{r4ZCG&\]x|73! ;,U]$b>+h_>u,̮pKE!r˯syT=-8SoD\E,+v⭯k1:DL@]1`׏XK>98\T0Z*fP/$n]f陎wF naPJmBUEVIf7BT ieGAiD;ɐμ "1C^n**܇w䞻ԾQ$OɁn;~~n zv0$_fw?(9KT&C&5GW8X%Y?)ISs%7oy gPy1ϓ"2Zܹoq|iBJCk~]!WWJDC79iD֋l;z\f5T-y1Lxrfh|Zd>tZvĭgRmV"mEK=a/CߏNdLsCBMpU/y蝸i7#! O͙5[|{_K&q]t2L "va&c0/tqH^SZ_4⊼4*++{Ĉ@2UO|<3sY4A%߀- Ȫa, %[N T.163ޮGUr0GIeԐɞEO6,]iЗ{.J+\?gL^R^hRm[σ-{=ӎS5o[# | ! -(G )UB ^ {) B)^[s{#%[W38U vڎ\pQUPd02ѪSu**Pef2E!Dp+7ᩐ^|3wv8qlBFzHIG1N Qz._+ L7*&z5kD'bdxoO-wNsg fk;sWblVl%'g' S<(筴b1ņUElN\tA` ;S5׍̀[ߑ[!tBu]b$mI<\LR.FSCՍ&\o_7F}!_:tu<(`$dkC(~\,6E=)O.+'S3Bo%k\U'LMDQ$MS@"=4BxbFv+c,޾ I )L4K;+`zx,a]: 6!uAho'̎o޳$CF0*#Iy}t.mӄ #+P/y-ZzvIX:b}%,fͫ yQelZmYUYgExI3:pZ*YЁy*ғkv*wbh\6 [~ Iv^OAaW;5y p&ҧ_yj9ǷF:}T\ƠÁ 5OP%X=}m0|@pcZxմEmZ6@Hq^glI/o@B-p(KHRfcIݫfjGX6."v)'Ob6:ٟO7[=1ӤL xţ,JZBܐ+3Hz҇1j DkhGv˕Cɔ0k*Ձ,zN_nGHM=Nu l 6!$Y#S0͵FCdj㏩s!vѩ+x_ +RVDM‡#x!#SΙlSu)Fg>:wuV M,sNʄ,㽦k:)"λB*_T <&+sp`O \F>ki[^m*c"-]Wz:)]dGly?_7G8.HM l3e'yAMY?{sz:Ϯx,HV[ށY"6lYG `Ap-1V4A.o ?֦zM#k{p4%QE,'hc;m/U56bkE޷I`ޢNs Й%zD6FC'oQÆ}9𹳄fөJ茬T]nVzEރ_sic3qGqe<@{áWv|4MqRaRN5Jy}kPʰۦ3wa*RW!/yfk]XuT|Wgj1He="2891#1e;?Mi0PD[8nwv'4w$\T')t\@Tkat̚\\NoS q_gÚ`8VB`?>s[k}^~&#UdԟEJ^ tLq4l.ЇL%nPkT'5,TGmFuM׃_SFb "є/b_;[8f{}n\P':>Wd7nd&Ndv'v衵XH,^朸fulT|fw +A@vwhj7?IѮoj~w5Jy{h`d_w8:}D@s$3˰-E2DbМ f Mc }fg2!xњs`?'jZ=NZ5e7%E+u $r'Rj *Y=㪹@yvewwɟPtǜ{AɈ#-p(H[=&  _)~ Oꇊ*E6ɿC|~w9I %.+jeʲ)نГZҁ#Ҫh99(n*7o;9(vh =Slkn8x8 I(pbQYᶾJa 6I{W{Fiv*NM%)Ĩon?f;p+(Ql {M<ĹtLG ޟ,)zlus8̃62Q6mwq3 [Nt6hK :3!_qdH` RgՏ)e0ɰ,L^ikӢV(Kr(,_%:jt{R_HS{ԋXWq#R94r ׭ϨPa>7V.ݭ@13qXZ 8"R0+YJ': @n!+HaZBw.Q}5@O*Pkv>@\,Of*FaiuA'#.ew7_:2wgOK^ U<͡kήTP:~6n@ 'GW考 v숯xF9Qc.p5LD] % ) 'Vh[ō{e^>ǑT6O`9N2 Hw4:a$J!(JHu},BlAdz_6xM76zw*j(i^I'4T4|66 y7YK`pЄ UP'p]%U6^l nPowš ,('>:yF sP 3aQ/ِ4G`Ҹȸ69[=߿  a,68]$myxh,neGZ+pT?8vJD!q mJP ʸ͒ g8NG.4 fVQ\p4%{"q܋u5~[ :'a4= %IZ?q(&]}rW{B#y|ʐ+eϬE{Ř<2s0:g^}Hυ(%b@t[L\g_ F9zB6Jj9wr**S@^0;g]M~5 OJ'J(CaG$Dk>AE|ܾTko ݸ7q[G_X([^җ4pg7;^ĕ7x٩d!D_.u]$a'WdRzMsk+ub mbv2&Bśŷ(I@-)My19fۙɂǐ& ^/ @1yqt6)LO6\|F:ԯsz[!E@9%5 q+^ O)=OL2a:ꕏS>*so r#mjGL7VyqN (dGͫGp׬upnʁXb͉u[x2ػv#Kz^.sS2fi'q\,c!hkGR#iv K cX) \H=3!<] t6= Qh[_5w PS_q}L{7!80;m-uykx0ӕepֳ@oؚ>9$;9q$@w@Eߛםgqz$x_z@R ;H b;Vs =E\`g5ݫxAĊ"k\h2,K󤲗4ܬ^H xE @?N곇A 3xH5ZW@9KyH. ۭlQLj_!g2KM 7/2Bs2^?~"nkCEԕ4HY{y舸~.}K~Qu=bRj.ofoϥ#om!1 p ku+} =mYmZ8'B?cm Wo>> R%D{֢xڿS}Ff"|ӟr)i:M:9Rk=}%US?W[.z+bx>Q6l!MP' 6B;w{޼ F7]Ѕ#eÉ:p1Ymnk?Xv! b^j4(HgqsOX;^O fGUbPt4IaCVo֙smS̯1c]a6`An_YAn{|rz+JSI_Pc41gq_w$g6ݞ'צ>:seݫீV LܨP] /Q(C^+A1 'dCju#ދU3^*v4v6&pkZV~|E"3E29Ph;Cߤ'O,l: ISa߻U=7r!yȑʼn&[.SQ-hfo&DەPQvY0g r¡xdL{m6NE^73W"A2ylVqY#Ʋ|OyfmR ^\!as+n-3 |.發0겙? m%^N&X(*Y d\ʩN0Y6N┊bщ''TJ#:B5AeA~0܍kL ӳ8'!xo'xVȄxv8Ś"|u:`bܹ{BoP|^a91i-DU7)2ej[xY'`|pMZ޶:!{j՘\}h6QQC11MRW>l63܇v@wzF>`-Xν*Ij)c0ǫ>ZӼW'qK4,9+jR$;goVd*Jeck(yqL+ ge}o i*,۝u^gIMl;ՙuJR}!MGI5$xB*G&Hu0ASQw[c|x^)A' K PןASȀY#&C5*7Ev*s`1Q@iϏwjb )#} oN\Zo*3C= Bh.xC!]`*7׊4BЁWlzgKCt ]`DGEE=;Vwp0'> rSƴ'/SZX;d-KTmT Ħ jK1A؎ҩeiat[MXE\-/c<"N5TSm(I,yF4B ..yx%yBdjd,\qSsk%#⿄Em{\mJ]%dk >2fW38z7A_kMI,>g rf4sUM/a0MW'tD nCC Ol,@t7wz Lr_tu'nTVPry+%qrE`&ŝ 5隨VGƐsD &ks` &2Wߖ?LG\$;Gk\)/"]N}9)? w꤮- Jx&N>XHP?by Ա}Fx2mbnY _i<h @ 6ybMYg$yzƠ^fQTm"֗5O@TEx˪ -[`JUبTS_ GR|Ȗ$wh1:>Y4=DrQ" >_G^T]1/ChCB|%&߈LRPHFT"A rq뒔~᳅td V%ؒDO{lЄZՙ:߸wR0.J%] Yl =CɃr7CB&w 9 pIٲfCn &P6HY0W"W#ns[E]/yrNGmJʸF=?DMC^Ny+c(/1GxY@ls glvCG5ь%aϜxX .fY~=\hJСyjі9UP7hQaNYzAFPU~:YKPFL] (uwhv$9"woI uHIk rGŊ6=#1?P"V`)|z7 3b=dW uZ+ ߺ]V?TluZGaOAx'/m:05*p] h !>EY0 +tM8/cm2k}꭫/uWmƛznx[݇2TUeYZҘRfC `[^__udόbJZi& 5TՍOBr 7dIXj{SmRN&xE1W:ȉa%GqMUPfT3ޜFQȰ`W_;U#q5TjG SQ{5ugC<ɳV hY@ {`N듻׌0&'UF1ͬoD!H?Ǡ ˸nn,9=hU!DIO9+,W]߁fvqEt ѻRpk89AdԣG,tzMHxZ! v{c)+4`> 6_dfv1$C (ԉ+ L\1䫕Nx1𛣔gR1j[ &6<.`M!Ɩ˱δ}3 Ot]T8LF)xbeYmt fA;UU1* (r+&6=9pkS;=išxݤJDl6OH@o5lJNJހ#x$#v:~^R\h@8,Pg}QdAͮuZ,:Xqe"x3tUS>Ίę:7# 49pB \}IYqz'3G հ(wYN5)6^dURyEtǘa}Cj] CɖC`eriab&YBϭb짪(7L|H䡈3^Nbj~VvM.N2VXy1a;Liv:-ƠMH)0}$^uy:~X +}b[4i&LHWE+"\R;~^bx EBrv pɊFO_b9pl5+CEgA \Byk#0 ZFg؞u6O{4tLh :VclόL<^ƟvƄ5ȋpAؚiߞ:"E1_@xŒܚ;e.wزMR1<ᘾB:+v쌞L2mQ}"vX#,+ʹ-I)H_dY@S_y9Ft^S vE7ZHvx̍ NuK'J0ӂmP$<hpu= zoeu3Buo@.UǖsAY`VKj4l܆ISˆ:?{88_E{M=_'\W>`Q)0<#-SWSnp "ʦxkZ9X|`zZ"*}M5oIB$޼(g憎$ͭgItUcX4oE A/k8yOޭmS)INYJOBjX* ٿ_-@& >fȴuH6Ơ.98V0qH8ruχHV #ډ2cBrՒP7d0ktfMCСhg$w3`OZ+;spެp#ǾW+ xH'~R.m~q8P!~Ta۱QMp\vG]ŧNjhѧCBDÆ3ujifT/`ͬ 3+@MN83 t0!}դrHT A8?`"Y{3eN 'OI}'V|xNaZk?3Y^oE ;suth‚sf Nz{FmQۋѵ6*3@T_εT|C(y3#n{.*i, u XPq,a:j$ꀦ1f9ǙMB&sȧXn`tNPP$=3KU*5+ w323?XUp18*5%gGDДe̔BARBn2_'rhyA#yq0p8b "co_ McH\sDAIE_==Md+\Brd br'D~@JµNjPp QiSdp+ͅN!,׀&Pd=,/r{Ԫ%76 7r|awQ^y]ېX1(Sӯe|ׇʔ}L^t'Ԫ1-vc"KGO]kߌ~m-ϊ6"~(D)sV5b)D}@/; {HM,+S*[1@g3p4KbIMѡDz&g{{)jB}5Oeθ:4mf.:}mJ5mYN‚m2Iy/icJQkRXn0 _r8H4wvi?p~\_/vGʵ\nP9 /;{`_'FgFltR_1Ndwhc ΡF>0,~;F|gUi* bq6b2(o7^A*y4aвbyi8ybn P)1D[J g1$QoՎΤDKwM\gB<QHy~VPO ?x̏^\_^?,xWYՌ *Za6_Vdb_Ϭ!{W' wم>x+Rnb16JȷV &DMv%E Hzw ACO!/qi6ûvN D~nMƨL fzəsJu"[Wۖb$ʋG 5 Lr(0 #MPA|tei? ʚD2D BAtI-`SzqIZoz] $.`–D::Jp >l7szG*iwl#0P:]F`f_?^}!Jf"nGr30eHmo@|Ym }Sk~EDut>QsP>8Mu̅E0n/J6nH%5lM%T͙oxvhg =YBRQ~)ˊ4-Ϻ@ʴmmyٰbǯ>Y:Lᖟr:٘RoHQSk´\j#eU`NxЯzᅠɻ0KͫE Ke~;$\-,Mͮ }Zt߾I tS \/5F + (Uwu|&@I\C=HglX!^5_l5y$iJ(ْls&mwҦJ5ز-qnfҹŲ>v\tΡT;]1 Z:1#A+RRIlMΆ<Ŷ+sx}' gj6! *Eҭn澝 #K(UjWUfWf㒥I8/][xV`z~Tb~ժz׺Lvq"Ш Ye.N>#tB?t)B{?Dv ./!ᚩMe5]fl M(cwnwU dGf߷xyr=B&5p}@# nX%:]wۑ:JAX] 4`5nekkqц[Gabd_%@}/,zhYo% AEfܓ%l Y(4]&l2z!^Aw$@QQ -|>V6[h$0xOLw+Am=Ln>sj.=ƨi]-9⯛b<`΃]'- pgn6$^smwlJMA?x37AqԕzytR'ne;V5$Q;LpqhI/pfHxeTb193]oGc͌ t:[ q@s[Ÿ/.sx0QSLƩS UhcH ~@~ib)aVpbpu7}Dp|9Ҵ.;1c}>DPF [ٝ(dFfyw)S4Ԝ#" =?\sƶi{I9?ɧ&}#_gYy)8 MNDdَZ 9 ![f2君V #'1!*r !3Kİ~U|3WjH @-t6si:pPGĐN$ MC̀I-m@ >h%I@'ʯ\y15T j]N`/ayr1 [w0nEC߶ףe'd b".sXw+Ip9 HT82# @-tj%n=TG}nN"kÅX6A9o%bz:Ֆj۰ЋZpFI R)1X 7UQOkSܙ +tzaVH8a%*pYic[)JED8CQyuZAiYTѤ\i&Is@;Kz)ZFi-QJ,k@759ͩ]ef7{{d4#VMKTK,Y:r|#&VA$o1!l8]G[&?NƖNIpRT, $cR "PE # Bd 2"iK{;f\VJe#(VM?$AB߷z⹦Zǩ1WO#tDјxVapzc$kjvuGC P<|{\{*@4cza JZW[- s$}aЅOv%*Ud`2r7h8VV/s5[`Ź_0HU#LQmH]#1c ;n"F_y\-Bp⓸27QԗªB g }oh0 JHЄՖ>d*sVX+¤{ld_a$ ό4~ѡMTM'晰%嚥ʚ}'2O؎f^ bACq=pc۱h:ĹH,@3{[t-m(n'<) ޡG+ /b_R%M58 #v>NUg,j0B+㱧^`t#_({-o.s. oPmVvyże=gqŷdT o\{'%)4%oTI>myi_>dd_BZʆ<@²wŨ<|g9x™}T f+l)溷i;49V<?,A?'Qo`am@ePWDMkIXpa7{kWѮᓂ{B,z5g*KԇUK OL0kpۣ7"dH1v]bB!>]񆦰*sOH*ȭ]$rdV<%D7o-kθZKm.OrǯUw]6ߝ tQgw/h™Br|y U?b#.SH^c r'ç$ Lg/t3'YHl|S7n 1 8T6a>>KBnZ&OuёYp(Θ\Gո}@ wsƦpK8Ao:Ȝp>dQxGNZ/v3H/CH>LA5VÐ`B ` ?zewIT OCn!lg8~QbH-$k_S0S`Ǜ?j_c<B|)-ܵ": _IYJ;HɜgiܹTQږKI}UXRׅj@"aOE' ͮ?TH3TX^&`D{|b@uYD ygYgFŹ{-? 诹J9vD@#eގ {gnO?@bGr8*[715+QN6ղn4O%ӏ'{vUǰ#- C(lcZᯆ<<נc%1&JZM8ww \.^Ez~/TY>3'5- cVx~A 'wSڋW/SB]-3&f :%89~S3O |͇CԵ ZC7 Uib~.d+V+b"t8֨?{({a/zW[,JtgG]+ TO@8Қq$eZIߔAu"%[UGᏼ)j1[DMC"?̝.qv97;ptA"ڥ-" ,%GK_5 5JNH7׷5bn_$9eN3t/gw,<_^|yù k//m ZJ)%^E)dbkϼiOuER1.pla.@lحGN C)؎Sb"atI1J 5ѪMLK<&Y_Z'YfE^h9s\UxC޲0|j,Fs\>} Lwו@pQHvfAX2m]bcd}(e@N`u.kf&ujގدXi%a :q06uNu d 4Yud %R#@:( .v/}{ҥ5M׃er|o]#wȯv3NwzP6 Qg{u~#BwzBԠW9lΉՇ%h2iѓJJ k9`qޚ.hhl|ZZ7vdw.TQ&Z(n-occ$E>;_ܛ_ ݷVUUn.@kߡ5*`Lx6(=cF{Yn\bL/F: *WFE+6W Z* tM.Ze9y,1$ n߉P~'F O(鸎Tl}U0DhmWN"Lm!gܛŪܯn>j!@H}ʭ{5v^//w,òN)NX]1tƸCߑ"Q3. :8-6m0ʂm2 tјfb€yUF 'ƭo$1+D;~lY*Ȓf(Rd"_L5,N7ԅ9BzG]_?T_F݆rFđQӯHѪ41 >䑰>Z!ֽe.sGsǛKFrz6* <ʍFt 3TZ?^JnT-_j/&€ՅsCuef'A75Vn|Oآ/גB *D YR3o0 b'W`f\-jHZWFeZe՚rUHi(#|`bZX!i )G]K(U򰤑iԯʳccdcݗM/ Dm45%BЍ-_gݩMhxm' ?[{A֒Tك@]TJpRd~IW&to` 2 l]k2w !wH0?3 z,09f5l701jf~9vc+F#Yf΃'6?ٟN"z]$MbSuyU/OwԓnRv&Af&yMP[U>[y\^WO@]db.JFN|xBE%oIG $Y 𥢝 ,ufj^6FwVX'n}a" q oh:0,ƍ)k}C((xid51mi@;XzB2UBդ&G2\p߅i,ܩ\L2줱 ֱ^3<mGҩZF+FD'J̯DeL{Wm0` ,tle(DڎUʐؚv-`9ݘpi'";XmdQEtRJs-#6j]_\V_Ѻ^y_q<_|&iVt;p$z5:& T 2vVIY8M#A|0D\OKG.iC,)೻PpgnNXGy$a-)ןRyzU5|mIKϘas@@|B?t UknFl/IA{@[CؠiMZBXmmIeU}x=T 6PO ZG\sAlZwEB>dL΍<ľr8RZ 'Y'z)dŶ[Fz ^z& ekkk~iz\ fAM_pwt:}\,ٙ3[{IFk>Fu[,鏮'I)3v7PSSlw. }l^m~Im>a| 3OT/]g ׉R_ ^@])'ᨳxr ssjy:WZc.KP(PQφ.hd/XVyVtdϡq ݙVʥ*hfil-9W\w6[3ZI农q27  Gk+Ζ􈈁;FK:d%՘cTEY  aq(8/k{߾ge8Tq y'y-y^ӝ]z^i!bX"Kc3'=KJt 4=\L*@UU'NC:!]ryH!rqsuZ/ϓUoĨ3ȧ# nja!8t"P׻Id'5H;ҊCH]:MdmSv5a_ mf aŃQظ6Kdi/CkjHxhQI.4|EOQh=:ĺRC[;b%:0kڀHdsVs%^9;ors(h{Z) ίt䥴qYk.Nϱr?wMp4IVwI:fۼ#@)eVwXV6&;!xl$m>'A8{ִNB#MhEΤw/3bb+('.d@:': _[aNtNAI`l%5S8)R䆬Ƚ:YbdbK;!?## FNa*@2*#KfA0KSFԯ!0t; -wq6 D=(>;lPD3->蕠%M>ߤ1\nXH"ǒ&̢;bMVD,Pp#_y?#KCl968 +EpDOKG .(.Zϻ=EǷFؑl[jo=pܳ$G *Zb+*s.˶ٯ4HIt(UQn#ap}7w\iPgH8u.Kv;/9 I\ڭ"}uqS9-jHOW /,UVsDYrZkݩFDZ@A$ i7,z IMw,QN:qOfMDFFgH%&ڤ#ARWa:)?b[4;w#hH΀(IQK9LJ2ѯ/]AXxP'G%i(#h^,&m@o-z]OtBO*RQbUG=`'b+nƢ_m sw(DfN~ qמ'wi6i |R`dю wgyu>Xu!t Sk[((;\A:׈9v&Qٍ{ :(Y3sbO nR (X#LH[cPLMIg9jIN44`'Fle(b,V٪*̤BVYwxҸ^8 voH R/zZ*Ck;!x:f.ér}SŶPФCvnX1=N|$(Őpzu|;V/.;D-h?avZd7to¶RU5[UQc&NV炻* @%Akt5ڒ7,։z-G{h+]QVxwn|a<$$1V1' woxyN:2(I3'mdL9`00qn~~-ʫ-uzqRӛQHl?Hm@uMMAe,Ÿf%_uǍ:r"Čpӷ7GCM:2hij;'=cnQPbb5#W2#֮{Ŏʭ_Ƃ1r@y@r|`tҡu(]~Ze؝\]npi8[۬viYL6+iP<Å2<`&z97rwIu;0wX{Mú P" Q] Tq"-% > #5su;_ /@Z\҅V'xS#U,`#m晐&kVs*"{>Gegɂ[70d/9hn>a'~U{ppi427"0i}yBI弔 5e#LcΞMg:ʊ"sRSnYAh@u lAߙb"IDw`h1h~ \f,)3 ='k!ЉIPY8ECTPnWN &S,sx5&0xĥU~.i=$y_|)+|S'] v!^NQ.Z 枺*;8"Ӭ ǐ3e <|RG:lb耆 h 3Rfq(~y^dьv )u\;r ޷ vDc0'}pNzY=ùtu9&Wd!*yoľWr7]v\6Ѧ㵶XVfb"=2/Vˇf16]V`>0wW,r2wngo,:G6q쫆'Y<6I@>,AP/^#/ѓZoϤK>[of7C'DzP#+eD;L?-%Δjo%u <6B7~}?IKPkr<0j/B3A*BQT?@M؛g y,dߴsڒ5b2FEq?R3U)3^4Bb}纗Q 2K}UD߀nc4+ } /N?#*/(߼,9e "YWQigos.QcA7Puiwk. pu5rL| R,bkJ ]MHF1%ZS :u!}SSigͭ_CE'g3چ \0$Z3B$JLJ L9OEUO220.&YLz/X_`<*q$i9qY=ڼu_A8a:t3].C6 zIJ`+~Q[BoGӚOΘ ĞS}V 3ťӛ2.! lhp"  ":ظE%TQDdܨ/P옰/E~b2QKsw.MB "e?1Ք2v:8|2ʙHCQ=7MAȄT(L#NLsc"~#ܰ=^xe11_Rhe/jva@4Gk[4i^&s'#!Q:4`` Zd؝͛bJ&}C%hPN4죣iGP= Ćܿ3HSu+8͸wC ;N[1/pε#:PR>ɢ>ַ0N%>2F9߭=EbStG#M.2o-\`H#iF.(x}=EܱbVcx1d newr4$IC{3~Hh>js؆4Cjگl#&dgWRڧOnwO3@`eej|F5k8|hKvM.Q: \d9?j?"m9P."CI|Z%!4)U"~SML} ̊ %ICe7rP[qg\i{Ov]6Kl.$d- y[읒5 vQ!`Tx&̓qB'F"1x[t&.dYJTݛ.f)꧐nK3=e9^C}9Ӛ/XpEvX-f sEda끱ƙH?9 mܔ'/ [ig'ɮ"=/i>[ HPqI Ać>GsKY̸/yNAɃYU{hf],-<Ͼ2\(~9J_+Qnf mFE>࠽"0GͮEϑV&Ӏ53Du3N:e~ L ZH p]>QAl<`(יb^|krjP O1j~QdC_ܡ_I.-L%%'d"ԶhJ׬F2Gj["v{߻ǞzM[L Q \$MW[8yv_=(ADU"nZVc_ fA(':<di`2iR}k(tI kec-ڃ-nkj]Ynv˃ַWΎoHoVn젍VˆG$lޣfPw ~ERAlڦ}JEqt&Be`M-Z_|ZgeP5YfjG I  ޠ<7gb.ЅWnn0>^xѲ: :dV>(bzށJ#=JZ&p-Ǚ)qWYxZ>ǎvu%Z;6tI''PVמ7g:vl'PC4qU@a岁J3kUt旚L }zWFYن+ǔ6zױsayݩxE?kQmէ;͐w <PQ [CM2wʖe*(&ŒGtd+1F\il|ߟ[8Ixh>q[Ԍ`]̪|~g'tNE2~$LHٳڅ]W%c!{sadM|%+0Wp,T%ԾXlWk Z;{N\"2W59J]8~]1&|)ѽy_;-ݟSUQdyŐaX,5+ݲYY`P|+OEJl8vWJC176`S :0nTL]rroH[ 6FߚgGP8[i; ~D|&ދ@~`Z$L$_@N4sp?{vSqЪ8A9|pq$W?ʘk.A93}\ۓ #ΘfcS{1^6@{jBM{6,mJY0Hnd4orLj[oeA/T$nCzydRB^'z#5,1ug3aK" jh5%ه.Lzr?gڸsԡ}rآdNt35І5_Hod2)-#gUgs, n^OfOzlȟB\ޱ wpLnm9(XF]֛#K6Cn!zN _!9Dʂgzo<_9W00yc!㬴=p[J['C "l!%[(eEcU'uvݯ$X4n9g{Nj!"4Ewe7m&G?Mx1&_,~M-ѷs6 \}7Ď֐!,M}˅XYjuKقcH`K%ST9\T}N)d"b%H8KGKT&ZǁvとTqGJYD/f̯9 (Q;$[nXgݗ ˶ހ y C;Xrk$@kͽZ bc8Fx=_N^w]*̝̒̈CzAŽV=QMS T,EzS &l MXf3'}bbbJ` $.R+T@k~^(9AӻK jbY .d_9pN#{r KTYa"||*Zgv90 s5O{a@=7⏦>8wK((UFydnpGX!L(+o!{Mm%g8pklb8t{pXZʃъ.eC3K"޼NrtG~\x8喽 oe~@\wimR&ms)] 1V \.F`6`D~J^(@"> (_M)kN1kɤݫ[xFR,h 'Etw'ZO#@sܗEv;gMz `q(A }9ꡛ?\sk]onmg?݊ 4o[ΚGmxXhS3'taRPHrhCR+Z#=qzQrG9e(8Mhj-ч(nY'vŴ\ry/_ epZ̙qAii(x{Bd1[~]j]A&MFmh1_5|B:C}IR !Ecg-?VTzw}2%# ePBg|sy}Q\ X`QyBu@Y1)(K:SE@0#7AeCo5za$M~4ƕ+"ZaC89T:ҏ+> AttL] Zf]- .~^>j蒉X^6c~3!}ROEUҔf>x4¦Z%@6:tPT %ǸDcGԼ2g&ym2M DNNA<@ lĜW6d5ۦHŋ Rs wyoYy3 i/l 葊4V(+t٬>: iR@NӸ6d y~ –' j*!#&t!1#WYуՙJuC* гĞӼ+UgS-:k:eIޙOrhͺSz ŀG" V}@ssN{^`voYӐ 5,~s1TGRߍɮC㵎7oZ;]ɨ<[z&i_OoST -%~)w4:[Fy0Z1;4) -Y&qN6:'c Fow솔SԹdӼ (=q0% 7ftφ`4+6RKALb5b!#);hM</ c㋪Ò8^{EIG ͸&4>&f KT ,Qe, %I L?wlYGX$Zt,^J,ޝ]cG#AˆcIc _kO=O^V^;?TPiX{VwBJL uLh$dy+%rr}wnDSdQ/E9e\DdWW{*=IE-<̠3;U@rvg=ɠ4ꯔiT1g4i6 @ձHSޟMo16<{s-mV",m g?\R-,!~*HMKjeXel"F{aNDIzWW.B?ZkUj:kYgշ95h沬]ʅ$8Nn"u#lLNCmk 릇z[F>R|<2$b۴<<޷b!Ig2L:+=M5&?؎j=X26[X< "UyG,L#GGTVdtCAe -\ǂHPq쑿cfZoյai((\Ez讳v Yрr۲|"咱M;X`(֚'`U=-~7c.B`GkTF"9gTҍ@ MWݚ'>"^/)+ `2Ҥ)zXXĐkLdҝohj-9G]<ҖBd  #;N,. r-2y\=I7f!P0`T& &L)YLҿ` Tcp,z]1 GS=]}bR^nV7= eKK%zk36CPpU2.X`jowjCDz7F-l!jр׉yKE@!qrm$qyn.oS::'P61G|n>tڹ=)࿒o js޵x;#%j` mm-'8~M1.?eQ =o6N$a;0?xGPA^n6ًE~t q3ZK놱eR. [,= 8\cz ]l+B؁} }F}BcwPmrZ;30LbqByѦܕd@+pRKl9(4?Za Z/67ymӒ-q=19ʍ('#TVQ-lZ9ro\ݳ Ǒh ATu˯v͹!6ӝZ;#ĬR-iR55oI auJfHֶm|(tJT FɄ\LfҐ[$9dVT{+xֹDhqn5+7La Ft{}ҼLj;FSF/7Ez.=5!^<}oW]vxd2D1ȋ3L@.zؚxj($14!Vu{~g[;UU΅sΛw?G݆V|!; 1E}Mm=\L^ 6=\9 dGg݊:ߺ_>f:5!^1˯ mS{ 9(taZ;$P/l%^{Erzv~/ OD\f"vb"  #Y;xryEoWowL9i=Q#T(GmN\xహj73~u{e_c5bu: nH*ޜhWsHz*Lw]sg- ^nP[80 8]qo^֧J@A`KR8k\>"8UC{0x< EͰGae|K:(N&i'{0h`ԛiJiX6Ѝt(V7*:ǘe$ p?gТ5?zCԞ|~Ϥˑc%}2J7½'j]I-θp&zg YnsO@peD{ T&_Һ%JH>&zӽ4My?G,TIorg\StZu8g[3fF<\ѝ[<Xk;@x׏>@:A#l?(G3ٙNyÜr+LB|bDWv}wANZq\gQ%)wC% V_8Z^NbN//8Aa d^{: ys99ۃ+ ½7LS&%hJ-=rvPA!\h#+Yu1lΐy7,G_fQ}qcm.[*ĥgZKQ4Czw~Irk4ٕNĥ3c*>3X&YqzAz*a,a!I&Gp\򸘚 ӡZ96#ORԔag$#hYvC!祾t*AY'n-5QFkJl@B+zfjTZE@mڱA Z`c#1XуC_IJ˨ '~ڐdI^0src 069 enP:2 9ķL!rEĈQҥA|-;R|۽U"33e?4MWGbs; nמ8e~/.̃SC`L3em!G!WR.(v|_0׳SC;*4#:'Lkw+83۫A$$_h8dY,a䌽Eqڢ/ ]̴M; z1QJ% f\ z%ŢE76/;fRSQ ߰usDR)1X>w|_ K3ǟY>B:aE^BYy,IAUJoq2vCǥ;:"G'3޻Z>lT ѿ6&)srYx@Ցr^&bR x)_ >Z+AbufG{j|m4Y)*HN -TyJK_;/7<3v^9& ,o2*!}-uJ[Rw zH¡FDlX:"AVp'(׳೼ٰnr6{֯j}tcB\1mKب$Rw~/0oODб,,uDC !FNjuɂqm)Wwb4ȦmqQg CדYc`MPIgt$,xw7)]%Wu FPȄRD sQN')GqIۗ3D`v'_2awU=ݿc519[],+ˋcksoM,+VUEp$To7ĿBi7Md$̠.$lO~\}:Rcq{ yqUy+͓G/M'itB.P/O[{*07E8!>VF X1!By\-`?(Viqn٣rfKyu 3 w4:h^O9-ਐZ>2gX^0~t<.'a`f(dP ])i垀\:|u F5Fr+e_P(^@28x\<୉YǸ%r.iLT$cO-=ωjf+ uA}rI]FZw>VB@%] Rw fMS#$r&o-eB'Y)1iɋc4WjqYus:.GFJ-^>\V[JcEܖAa70fZ7[7uU2Ff"՝y F_-8@΂G$2 HTKnC4ĎX 3/-|D!@fY1@w;ck0|h$rdl,tkCY+ZZexvPG‘0/ s7{?Xl]-+fa‚izG_::xc h8T,,)!zޯ&~v6vsa}?G;4dqL "Ǯ*Tn,V 6LWҝC؜|&uWeЮc7~ۢIXP[,7_%6, պC'p;HL+pʙNd[մS‹VLhv@ ,/vm&lac6qAu)9$ ESTX̧UJq,sXJRfj_ZFo(V1>G4'U.%$L{:TxElb2N*@Di-@D綋k!dC(,)* H LDWyR0 |!Ob0e@f 7 >I'~];2{ ѫ$+ĩ^?/1w:sjvGk[{{X:OӬ8HK8:$J33lrןLi 4nءLJ g9QyH8_VX:n2 _VwLCqU=}4i!ym7XpP~ 4v2T}b 츏kq씣0hZqQMqE.׸#JebVŊY+Ø=Z(r(r/3KUyQT0}5L—ƚ];@&JU5S>˚ށtKl:Ey{_] VLڔ`,Dcnz*̋^DDwQVLtaX[ĭ&e ֪sxUڞ@%)qTV(c:`VB 8hB<c=Ķ@[7ƳSta/p'&'d8|JR'/dy[~AAl +Sleu)_ְw¡hIk w'#v , /Z lxzw(2<.dnt1i{!,lVbzmǂG?&$+e*7mBygK&4k0,>Cse4gM˟QD۩)0D0w} Mv|C=rSa Y**m vȟ+t/Y~<d^kY6!Ů*8r 8 ƉB=[o"5)*/<HLX*:yUvlWDI&_nIa02DsroOI  /|Ek/p;߾/T;>г6 6LXbŒ/>[lAהh2ToFbprLڍf w۽YS^5W7`cbc3O.E޽kJϝ,=ИqnJi; wAMΎ^{i헆0 brIEcãmáÛxfCөF<~n_e gҥu"]<gٛ}@Do OnЃvOhk_ TM:۲) zXW_o˕'VA+ y=w+eъ03>$bzp:שqWx& PxQ|Z4megȿD=\+OsBjԖ9(S{ >I,IK\`_TVO־݈P"yoѴdӌҝm ϼw75+҈ԣ# >W:Μ_'%Sdb')Z%x͎ }#DN&w-%5 Q>A_Vd=E EB Ra*FGWlxXFu 7|S2RuܨwsMR.}A!M wc92QOzIS@pM,f{(RҖ}d |L QϛᴠQ y0 Lܝ zuycY~wi73A[d~-kx{!/ޥ>]/P%*#y8w/jۑ2-qP,|V&/yiBfijT_E߆ 夐\ryڟה#UMQѬ"O~&ä8W6?kO2> V2͉">m h#2<ً? h{;Hh B-fTd9rèF/**R8]ߓξ7 _I@ns$21{zkl'1^쒸]VTPe4ĪG+=נfh/f1Eχ؃*" ts^N9-\5shcbꞟEe`l81BҜh⠀XS7c~c"zI+!: [:61K2<%9ҿn z6xD `usD1 +E|U]rknXk45ڑ1{Bb׎"hzL6%¸T0;Vj&͸(R':iEÒ[K~"}GsB$e@}*5FX}D `ȃ.իJ~EggJewpTKP6 p b>DhYpxw\ЈM[x{Ej #l0%Bnyʾ G}|?QDfR=h-碤̐fJg#F!?oU?PlBp/~q@ܞ\ܛDmm\<#Ai_[0ϔ[Tκ@<_€oӜw85I錡rtnWn7CYsI&<=((ɝb Et#SqR#Dd[G1]_r`\@HCÉ2w;͟>|~r)w{l iEcU,;|CA^zd-Z#e_O0x 4@#<"hqص޼R\סxmf&*oڃr8o#$Rĭ*gum3tۚ#xF~$*!9 S ^XW #2 d->3U IykN)TҲ%K f]`(섅5ˆxV[/tbKKn a ybo6KNq̝SѿlBEPLb/`V;sRW#5XNY-&#nO ڍA8<܋>x߻x&+0)Ӥ."5R/wN0TDucYo^VxRݡqͥ,z]O p =FeL$'Ѽl9'#7Kq8xחI-#(uIS-KIq!мu@4SoZ|g7J*ՏرE^?Xr0}: $rN@CG~yߺ5L: PV;:bbRm+{eOZMnx8kZ TL& HGhaJis0IqYFKhJ_"qMOa~"֌w5f4~h1}yڬӱ2,S a)"x.q~Bclru/wX[׃hܪ|(n1wͮG>y^Ab [|j,=€*Kz[NȍKoC9ʟUKgI`nv5T؟5~CCw~@&; n{`b&X8Re5<04,nNpbB)nXILC!ҥ٨FdWyt[y_)bsJRvk Ϊ- Pҵf)p=rUxDD9`2UQ-D4?!:+ fI>?Pݷ(I R(f{Sz1!["05&xUjY]Vߘ(v_qD0,OL O4q!uMnѦ!e? kAVw~U d*&9ǩ\.Պz'NX>Jۈ0Fg.hx:8>$8v2R!M-?@kJo UC/ZTZ[eO閦DCVPf;sXKULf<]0>hpk*AOrd,-\[.Ƥzl'V4!] t4Xpu8!SkdoN'~=IݖQiUG .S@ҰrD}RpPB6}l/') /T(ޢFG6ధ?jN]gYSj]PA@BT<;( dƛ% rf鎦'xBLd^ҁ14\Sti]gן ',&1!ˑI7JS aҫrt֯%Uy YD|\EºA A"O n<JQ)oZע4nNy~AxQᭁ)H$l|wnF2^$3xKi(mPU&<ǀ<{l@LUqUd 6LV=O%xsj` 9禌]!\jYgA2iEb=lgzÌB_I N&//4|#~< Q (M\]EⴄKP4CiCs_s^<ǓL]k+ Nփ ;׭f=~G^ sD{¡mKSIR#pr?|B1&N(Bn_&SMDio6LMQrq|zWzT[M5";̻ c\ Hgd4̛0?KdPӳl8)>0cN_^}VbtH>{ю!_&/?qe~'TyE) |~raj&~LǩB ?=FA<+6s̫<vVȪ}^1xKbLk.zH7杈>;87ցq:%j1%yZ֯h4T ˽{䎇Y@e҅[f5`r?Zjd8h NͿ8 >=g  $+bS0@R$cn6;d !7cb%mc=kObd/Bm5 pFUdB/|zթX;0(3pc T.~el^?.vb ᛴ_pLg`iyϱyPI*B]bR7;pz oW&jӑn/𔔕*@R j3տ5qT@O5@ODb=m~;iai)N|eR@65,dV )oaO[t%mWAI_O>;{zSe 25P.'ַ1d(o>|!CD?F7C }?:6Rٸܴo%ޑzg="VvdZVX#6|,Xê /)6' $)=!mD\Ố ߒOg2>EFʗ1"]+VA[KG!Bk]|Xs(@nE| GW >ɉ`[g! PdD*sC#Z]\Es猬lae\B.O >㭜^%ܔe;B~#:F`x2dLsm.= +xAQdA?P%^&Oyvӏk6N+0$Aڭ9FHdY[܏DIaZy䖠DvHNe.Kf$T-:Cs8Y 7FAf>JF"5 z5%ٮA@w%{@FTq&CՉ3(Je"&3RwfJ͊?Ky]Qc/UV(݄Vj*qR-d3a\9Z=Ɵ R+4מݸ_^*㦹ŢۉE|qu+T=vn{ oABJl/kRBTS6tVW3A\|A6WI>Vf-ɾ\;t5vI m_z5 F@ϓmf7#!(`(;Bdp"L1IiT T \w % _А3$s,EF"(jöpr3Vgg5.ɧm9*7/]5fo|y Z>@GGMZڈwOC<Ł$U^a(04RXO|`Tq(ȉyF7(~\ ,y= 6&]ߋ3#f٧唥2Ϫ+?#>W jp#WK,tn מL\h<t,[]rzqȭ%m:vhbuZK:%\$$!OƟrWkрjT`fXKPe8{P&T\V#Wg$Ojd R6({M٩SVԗ9cy>ϤrfuA$xivEV))72?uXP?Og'"\PYb.'BR^R3͋:B1 Wsk?bO2@n Dbn/#nix(賝 |aN2rL,6$w[VN ub亂Ǥ̇0sOA{ADi s< _ک<_ozo3Uc8cB-[4mץ71l,Elt[JLXa_&½J>^f͗j\nkQ6DdΌ0 941&cpv8%I5y.!hX֦^,L{]q1CДd6$"tbr&0(_Bn4٥ȽSc'-@ ^/iUU)R1#81N6Kl"g6=1O'|ls;4p\U$r`M]zq=c_fO;-A훝˄؉ S25zug6DCDK,KyiɱGuaseh3x D_ZuCri&`HuO%ؚAJS<^4\@CH8oK\C9 T᜚MԞЂa.ēSSU]D})i3PBQ=ou"GnpN^=h:( Jfv W\^3-lX\9ȝX[!n7uvñbr-4H/)KmÙDK|Uq0[ e alUWfGN^͊D|rodkC~hK6)>)$wEw'd^[=)@WDylf%azE8pP_E&zOcQes pFh@ĩBq+E['ITV;N,/a-LMb5B{14l%:N ޵.X-hQWx;?0(O@cM.1hK5e[/ /z%Ylai .?e cJbAkRN,G^bbsKp4AK/7 s`i%g`xqRr${k1S,`IX!fgR)mL m~a^kK"I=G9t+dI\՘^; @=3K(hNnvVn- ؚ_LT]go4Dv20N*8Snp|Y8P?~?!Cp\otH{"0^5!:冮)`<%loόQEn(<œ޻`Rգ4y;e0m +])1~VevPY1h$NQ}%]W9N<8T7ugzV??K4l5#"֕W"__#;;*];^OM. LPtY–N$8Ϊ(vȱ`p7(3(6"LJ[$`NR#kCƷz.~J7_{b?BGm#b]:h|{O`o'9?=C{HMz<زmH]dӍܟCb*abF=Y blnsʲ::О,c!mي;c%ώJiEuRcB??gpîz4/ҡwfh;g%W"n_s%ߎ0桪Я<*#`I+N|*/*.Pb xZV5VGUq\b\-K3S9ŕT` n,Y \]RuXx7h&dBmk0oE. #, 6TucɡΗ ~BnۑslNܺ(+>+G`s?o谾Oe6Yum{@ fh:њ9vSt_ޞTTH7zϨ t.-|֬l`>9 D]$vA$ވ|Wx, J7`!y8͓d%{^\Jh縟C&-7WK"U}xDUb![kO.=[ I=7w͈xɻJ2%-D ϞҩN]lONJ!B2NռTN{<5$2-t#X(O}+l0^ؕ!ʿ~BSo } ".VqJjP&DdgԳnr4 Ry1?ffv!T&.*go"lK%/ 75:@BϙEvspfa-6[{o۵7[_(D &YZ",Njm>̉q!'ƻ2U\Zo? 6 lFwdl:Jϧ#UdGYZΤʜ0Ȥ I:2_;/,CIMD[vtse%V]ng~)ӹ`ģ([>^dWs.o \99:b ̑^6 x%R6&ْtY_0fZ|~9[V8yVsD,.H8 {T;#5kҢoCreߖ1'o[ZjӲ=Zrx[53|~.lj96z_jSAD_k\'Jxv݋.+~4:p⾍Ye~Q>qA1r>!3X6˜S_:nIX}#4εj!NmN-eT;+ģrqM5űq?0.cGzXpS 8n}GĞu#41@l5HzX#L\h?gU,n ҩͫP^ J \T!>X6$4#:-'y6ā;lWHNNUZdוFl!+r"+nuuabyoM >_t23pπ)7k}v.nJBKAVDs_JC"[=Cc92j ҾI2 :_ #J'$$}wETw@A_$g5vKnW?x|e̼5h/t8LVe߱FNa+<1#К>yN bKs0$kaU , ^!_cFdc-! _-sqTMQ#$78_; vm5Spiž(?zWyeYvƥT"$=3!| yŽq$q!o-фjKRZҦ6jaLiվpm dM'ڧ4L3lř.PF0YK> JہՏ l}ZT ?fᫎ.| >q,3{'jݤ}Z 04W<c~J䀨+9ԫcsӉe 3{쎋OZgCF(]y˭cL7$Cmx0~^^.vZNf; c0R hBBHuՈV2uI4]k"y+˚L&O!L2hxA)U)Xz̩ϳ0WYBé vK42sPI,+R%`Ȃ̟.yO91OrEE/h*Z6:9$z8.sDpdC3P74%e70i+r~g|)#3]acw\s`¸tdsjD0tRXɪ7Nhn;X1; -rq/F HqanvbÖz:B |B6q(OP$_-%GۧXJ;RX^VK%ځ(h $u&,yot'_q(CO ˵aԒ4W mjaA{n_3Hw}>w TyRB|$dMx ̴Y:j-Od lxtC~CrM`l\ AmB'oƄH䦺2G`wAZrD9]2f괴c{r9(}!AO2')nŶ\~f tF0z0\_&6.'D[3@$'D21CQVR^jbǁLI- A[S(tjS?01h% (!\Ϩ}D3W5F =2ُ$3i'AuCPyVglsR+ /c 4hy>UZHh)@@l8S xclﵸ"T[dpͱ9p)ܚ{B"a}u8 kR?8^JW욡r^ۘ'7"D!b 5<)Ҏs}H=OF\U HP :4%! f~N,KK k8*9 +27*+0 t9( -苖P>O)pD_#4HgUqP\}Yb< (|2ڇa0 YB*ςKZ7T9Y)\5U(RݧAb?qvh8j6o7Ϋ!̌V=Lyrӈp7 $ෛ_=@JCGM-웬PEE4`\ H12 gA*^zuf6l1)>,Nv=腕BD}G`n̫SuOXKAnׂ ɉ$j'>c=*Ste5M̤AE4AӂX}^JVU-YJ2,vzh_> %4+koO;+F4hdp!fA{i *cSU![ދqT=Vr3j<1{ \9Hr,-V>C$ #NU}B)y Ej̟mHp.USq{Dr^I Q7pM1&\%vՋIt^qNKk4t!hvnؼ‹a6- vhF ӬՔ_bWH9K }$V`ج,J>C%> }bhL출͕^Z p $K^(Uqw]׏/: Y Ž=9"Y8 Q]ET`CX5Q:áaFȂ3="\s}͓>)b9[刏cO::?4qy)c$ۃma%6Ή17V^A(cVi=v@.o¼.`] pVGReN9{L="g?3=Pb0OzI#%9㾛{D.-3_,&F_@ņt@ G dKf*|ރd𦟗ϏVہl}+:&4䌙Vz *$r)BYԉ2?iC\03kй L;Z@c'Ѷe>ƨk -qQ͵N-q pα MK>K3>Byҵ ˎJ6SɂZv`G /o_4Bf_f! v%at3t8Zv:g*N{$K%]߈*_E^o14PWaͦ 6Cd-5E3? ;k87L)!r v3n}+83-Jbx#]23M? ۏrş$E)SJʳBu,E D1uP:#.!_4uN"BcR\/[K~l5W:UJ/_B <6>_Zzc0P4*0l G]x osV[8BdkLNdrA۹<?B/hS˰ jg&nΌl p׳8g |Vn2 = :~o!Ms\X媢(G}7]SAR1 Oƞ4 dI۹Â) sZX_czya|h!ř۬6I3G^$YGʣȝ~R]/ҵ %uQBܳH+].q]u .u04[PPSZ\M:9Mڍ}PADBE Ssռ G{y8D3ޙ +l, ɫq`v+#&c؏]o4xPYvAVtuj!Re =@,KAx$4I*5 @dw2RJ:kXNFOWtH_ԖzEIk떒ZIJDѵZwha- t1:Br"jNiں:n:QT*f0EI,'OdXw=sud" {60M^ _.RgQ23jtNZQ=U@Jr5ciRYD$&c"m^ϡ0JC Kr{w{(G{_Z,=rE`ZdAV̻M'(%5Uji.Gcw>oWX,sX|CjJ*^7ډ.%μ Ac.j%ۓWO8bU\kJ;Y*!D`W7nA[T 6=owj0I.탿Gl2vd" %g5ƣЬok:]tSm01r& :+F{5gIkF~fP_xoFDgFtcYP䄝 `*e 'd[[uH#O|s/Sj?iōQtHTő|N`^ƨRWzGNR^Uzג 2=HTiG'‹&pZД۴M->6,,l{D9)Di2Š>Io6 h؅S NWJ3GyywEw|XxaAHi0]UTL2ғpݹL8˒G*Ge[ !Rg#`Ɠ,%5qC h +@oF^ IġCfDXc,̰#2~hI}r!G+d>nOV6n8:v^x=vW8(h~RdNKat8rE(2BgBƽ?aĪhq.Vt?T귑~ +@NROQFߗub MoyaF '8E't ̇e)7xZ7R •Ny loOE:{7PJc, 7jH,E(__9h ζev$ž'w}CJ+ ]SC*# Z"ton@Î1[Ο_Uwpb͙sB_ ؇%ɯ( eF_N Ω`@t/~7dfR}e],^K@,8 / wk=dT$'ʊ%șU: )ز +R\1ɌO(N[ٺ`$e X̉[%RVȾh?.r%5g _FfXo_Јa|['}BGyhkcV4)!f:>;|VWYߗ&_IEv0"\7MUN%9PѺjGĜ[)'qB%bxC )D!hi4F[Hc/[.@Kf:ea=@y K9gӂ߻ˢHL#qʿ1ѐNEu'7wic p l>7@F|U;, %5Bue 1tbuNΌx'4.d[2Q֚Q1ߑe5Kx *زEKW%W腤'D:ӏZTy@fdbYv@Ϡj«*ϣ_\-+6 ƧgRv ֍&27ٵgY) wI3ʹ?hB1 \DS[,3׌u\]ޭׁ "pN_.tlŋJJfl fRJľ{}dnj%Y[#村JfMkwXY~'3|9I[$/32x#xD3R4@nj쥂)5jT;{A_:P3~"+qAW攳\3ʟo?X̟%-YC<{m]~][_Ӑvyʫ2F;x1N `4Zxa_ޛ=nYyKMGrqȬɽ u9ӗ<a[5<;T-#ܝ?8y t""gΜր:@!5k?dh9|5{HUo.]ͷ;HAlkH]2,Xk:A8o?)z46=LR!`ǒQLHa b|YB|Ējbi7͔z;_qcX& NfmYR& @L>=GP/!(UJa9+xxWצv 4 Ϊ@`'(^b1L992ɛ~QY?s4c[}R@Pśwt s@GdjVs6C щJE5W㽫UY3be[+naS{RG RiF֖wJcO/M\C*f#[e#sNznج9&LrNS8Sj4- _.Olؓ&).`/=K kǕm@zY`Rb8CX v9 ,v 'I[(nLƭcX#g_m;臷 y[ֹM!5t'$9CٹSر2|GtfV*Op#9%Cm@״Om׋>%qtPo%w7s"d/AA_j6쏦 -'9V;RAqͥ;;-jQAEh)RЁES*S PVou^棣b8SJiʼhmE$FsEmYkTc">]ڞ\lHjCa ƞm\u /W$ %J̳鯚nx2 BvZM9RgBv䓉juLj]9P-m-vgQǔ . b=$:t?g)u#qy2D>k3uBܳdׁ1T|>SYeou QwAR:s4Fs`˱ߖ# Z߆YfKS{, /T7sEdz9T50._ ;Ȋ83J^`=H+?Y1qC%p!S8?o^LCS]UrT1 Niz`Xz!pF .0-Z4( FSIkA?'w3~j٫vPY"0D)~zAlIFjy/]FsH$IPD9~*Fze?ı"}8  K0ƚ!U9ԖQsOR1~^Njp_UX,\0%JUaxGJ>r S8-ч:X=pH)9٪_X,GʭJSfN3aX,^⫂"+eQ;75Sqe[ߚk$ ?W*\h0KOI{!#rw+D/G^˱<ڼ׼!Xm׫|>Q@û8y{jojbw`K(_EǻK}~kRnV18 ڮĬz{UB7a^p=P*8WA=B 9O0NDPeOqi}*1ʷ\d#1A$Skb#6hW5k'(sRLwx.1Tji>0s= Qɭ|K& D:p^q [֣.L_b50O.6oԚou}[˷Q4G)V$Ai`AL!GĽҁy}ѐC>3;A}Qų"AqpSn .?wʠq}E#v/zWVagxLJx>u_xKF&&UڂP>-t hL|3L A0=1Q 4Cpog {jHMB)L4{Pb _GXd6.fFK@ԞR7yY& ɶ?:M|[HVn־ũA)eu>/%qs^狚+WT҇_FF\'k\JWg$i?dJ׻v;colV gET 9JlD%* W¨ۭfGKV9+SZZҟLl~h Ne%Fҫc]Jdp^ τ*t`=zֱ ^ *Xh A䄷͐fۓ))Q'(/Q%zPuЎV `i"IQ?ޫG&N a9);y;t^R@VD]r8faD@%`,Z Uͤ|; /D#BWA ~P8W֌ [u[P> Gw>~>;"[p&P lObP\"6-@fgž2]0=Y:?"3pW1GHIN0;X!@D->peI-JG{«RP-R);μ8m^1Jq1}t/悬~i)%^(\jv! ?+f%_pxԒ'4/M'ڷ%!Y J @!1 "kAFL(:+5^h+k*_CKUǒXM (}牷کz5[,"p'B\x/'8Ivw]9]11=x}֭nձ^!1#AOy{2wc~$fT?(? TF8vyĩ23)Y@j 2̍Y(=.$\٭zx妢`LPכ*d_CO [(pOֱZ;uasn2TL}EmOŻ.Fd%b ƫ엇9@;cؘ)7'8WIz8[) ͼ kϵ! U >k+Jv>}/.hw5w1an*g?he?X>lf$S] +mɮ~!OLu[_xyBvnʋ?9() nP4N? 蜩/}è/SZt!9Q}^,Gnы2uMY7u!v>RѢ,Ovv`ʮ`0Rq)H'8~߂d8}5Ywq<~K00>nꃟFv^V}ݘǔʹT~oV uL9 ۭ/sh' m%&"e)P5pf[+e2Yu N%g'\Ԁ)bPeUG)N(W ڭ̬!WJ7+3G3r$DL;ìX0ΝB+1$"&+n޶jyo_+wZfx؆'OuZyezVg@C3dr^'/fxs1N?ytgBR4`P_e oX/1'dH\/vTJNW\}ݐ"EILBSe2et[ovʍ.(va !۳|yVNhӼsKWU6-d3`XowM8@}վI 0n'M`I$2!4݊ ~f'3J͉3 @87YeN$ۡ!OmCA: ~c&0ʨVH>(< ϘaBAآe? i1aÿ p®W; zA>LF)?Xm7MËs#we"A:WE V`nʙG[XO Q[n=fGW+5O22["Ri (;Zh ySQ>!ً[>Lr%7ihDҮ5룥\Faza%k Jobs%xr[w>Qa1#Y׍j'Pp[w(:|IHɉKvT)<_ViQ.a'$ȴ*uk㝱"L. k jet%US}c,}nĞ8`" ƁнE RL3G mk-.vx~c~<=ͮ-G٠6]I)J~]FqYt)qnR>Jpr0.')egBmo Q"EW_Ȓ 7.mqԾ=3y|<ƕBU,fldZ*sa W0-6o4,S]v;Y! Rl@; R] *%V%Vs;΋s4NյsWqmZgzݟ?tu @_I e^!?D@㨧}Z9PvT}bRT&sȊIx=<$kl>@/D;- I}64śQ 3Žb6ԺX EHF1hD2(yױ`:`nW[Pi鴓&WU;T^~jNv0;Sbtl ZLT96@ }n 'OrydT>n1[ d~Kvx aYLnh{A(Z@h͢ }&ȱ#AߒJ ӻ鴊tL-sCݔ'1Wvk3 y\dR9EHe׹6(fcB4Y%-Į($ bl4K]qt?d΂hcpM ^a=LK֩n¯$ L~ V,^$A(Xŏ9Гv:=pL ˘p.k KԵěC&[m[|X{b$+S#ВT0ĸ134OIح#BO"PlKlC p96T2R)'(od;B\q,o/C08p>kEBD RH4U_%:|6_yn>|֒#PKh~;zXiuiUa9x賲5IQ;'`tv*@Nj13zW6H5zJ^un6@5PV$%O.,mq4 qHm>xRlQoYF3," w讶3øACvYPyv)-d+䕶CT2*m"N+ؔ):+Z" 7!GA Ko\/cl^}wNR,; c:|^u>r0W=5k5sٳ7 ;7KR/\! (&r0|p-ne !nS|AdQN4k'J^g0ېVzPK6C ^\j"ejn=q8d"M:>A%{\B$qZuu|Eb:0ɾ$B-Wev*,@:^?}_6QV@K5Λ9OJ?#P] gJ͐.ә, ֮/3-wp!T:Gpؕ+7WGg4 UEaSjWj޸[.(iܸP!7'2%7(iRk7i_Gb!A6Dh!]|Yn*g.~DX?ZI3Q_eT|=V[1QOub\rv! O!3UFUVS#y"/kQ\;ڊm*i._ԕc?YP/]I^ ~%>qBCR= _HyfC7hX l08Ixe=p$TmR6pu+i1\!+2H-dbV i!X7T [g2*mr} H0KH}obG ӦR`Q 5KxAM5`Ҝ2'D8@/7":Z>[mh1~) X3F*flLļT.[IX;Ž_9}u^ #.z! w2 J?X 8j/t[U~6{kv9$=7h雯d4c-F#~Ǖ.=\R%'aCfA18q(9B= Յ~ BEE9jT@zJ`dM5)u)`c (K]Eqi+H0;4Eo]Vhގ>Iaا@r vu$6XzͧjKR 9BP:g 67n! cf u%Ǣ3hEsɨ @nEgՌZ9YrrQU"p)UBҘWNc[?D#զ>~s>;/ w wUB.{|+#5V< SR0UhiI=V91JV#MgvntEd (8 p>E_>6jfXGژu;zLR4?X|cbB]OQ1n5Wi[;Qy Z{(2:<*ᵾ4j 1ЌA!Ň$9pb Qۗ'n 39v*A(Y1\4MWr :Ƈ=矺ޣTN!x1D,S)TLT7&@=5.Q&;}li/RXdLe W욶˕QW:k\/fFFPC&>4G4^%J6|& /NGΎ5U-bٺb^j(+dxc*1UMnhpcpMQ,#tE?, $,񫞼Ʈ\ eaf󋾿6 (wP"XO XaUd5 @ _\-+H#mn0a) 4`6R;XEJu3= r|w#'%&ig cp"`69 0bU[4Gsqt}Ǜ$eT5/38+$iVO0?bsd1%TP_X,5DPM'?.>ZFy=$=FCR L۪_ бR_veܹ8bDp'KkװZf,{^aRpf]Ù9˳\JP{E7Åѩ6 l4IY"vYhp eO s%kFb$վ}!V̘ fj!#eTT[FȾ,]{em`n6dRl~L8Uܡc L%Wo.2j ^!9M'0- .F `fEILG|:tBʖ-/1{=^_ XRM,CnǮj0$Y}TvK ѫ9<,c;Qʟ}t^nC/Z_O[MFz$*@J~D`}x!c:#us9JƷ*@A7y=GўT!?ռxr6m9nT o,is%Ey#aBs6FuXΚ&h)7<Ha dO{;)1F %32[>N:`6wVBFɾg u~ MQ̧-9+.h8gϟɟ(} "`%a\)0!%΁t?9;]Aa,pӯ^)p 6RȌZ~kCfA)&P!ȱsTۘ =t`M~M+l+'tdkG{Mt^OO{W]3θ_؁bJ90Iа4'Cod}eY21g'ly*a󈻱‘8[Z7oZxswUӕvF Ddqmʀx#l8m"d10~ҫ*S +0韜sxk,2G7YH`}Qp؈I)񶔼9J;V'g7܀j NkZ-էm /|?uR],7X-!:8e13]LyՎXnaqG- ͲcױZ*S!go@`Q>Ŷl#%S]̕Wu 4w 5EA?ܢĂ-JK iP9GIqIn^-ŞH^6Ν\]³ `pu2YQowIt[co)k*QR,[dni#Aӄե_$ZŊU^X `M==+px E9k,52^0&oR#-t~Kb?@8.-.8-7`2?7_տ)_:Yo?biur(LxS86Q @SH@*3. <-,GȂDy|pfKϯiz*p6Q:3jGCIWm-S*\ا K o-d'ټ"SE%&@ ! ()L/۔LH#n2@g SnEbio!1hH-Z2EQI}>MlAlq8[՞]uYɓ?.ۅMHVk4GB׉?j°zs+̖ի{0N@Q0uha3^ZӰ0Ыy kqyk;{7@} ,/vA"3fc KsR9_e^ngБ ;yi`CV7SJsJ(1Fv )P$] {TZhCծUEq\U`~,cǩ^̂^׌y>YD.Z@* lrB:v]6crV`x>v)v i`7vjfiIWkZ."9^2]5Y8*shoкDm܄\ ⟅v|,Q^&MDZHx',עb\!(vk\@rg&(orI:Xtkl=Tj7s41 u=8_X'ewCYNO~/]-Κ VIҞ񒖨Pؚ| "KA(#HZI-Bnr{]x`Ύ=.\շh@+bwmԍN!u3RaȢ> 3Bn:]Ve+"_ZDm%7PB[ GH741:&wX,61Ϛx&=ozyARcֹaStc`EBUm``[F%\V 9Fd]f..|$>eljV'Y%d\QkBȊֲ|+d[)K8YzV׵H d>s,ރQRnI"0-Э@: Sg+u#ZWph!s*GJ%!:?_wh=i6& Ww'tTK5jhQ Ƅ')S[KtIW|QΟN'CW;&kgu`q)JFW4ę9]+5&_/T iSPO is2F+p뫔Ulڡg|/HAmqL~Naؠ:H%h93䐻Z 3o\o3㦏=?PMlHs_ɬ\`iQVUjI4U~zˤMԜwF ~UIJUõq@hlFQq3KQǶ%gcvW r+Ѽ[(}is^#EAh 1tIri鶳lO  lT0X73*M}ѹH&[qYvhjKM(0bυhW l^HnC5 ly0~\}zކlbQKê4+wDiuYvjTʌ^J4-u nGYT\ow)i(DW578J_6AD)9RSnwj3od?I 砝U9%N5xK Ō0OX1ϩ[%. k-$T^Kϐb3(G(Y|ӡvCrRa spbzs-IFAAO,u$$K 拷8d BOMZwKOҐ̇fD&?}+t" mpNf<-?NMP $0%Wg_jC6@DA6,J64W#@GRUVd:ߩu5UDw.!}D7BP u݌kl0_K;kܱqFu%h\~o!!t\Xj&ՀfFo^`.ren3Ocb K8-ؑF_egɖ.V&dNQ+0.퀱+cںxIJebAE|)#]oP |%..Za;PᠧrSmELh!_GI9UK"gX/Kds@1v|Xx,![B%V(lf}KfÕ.6\ɔ%"[Lq. 08͚{]eAݕX~[Pdmu|)xXiA*&f9 UK.k%D~B[uj&-hj"D F#{ųAgS*$rC䋹pA9L&V+U6r[YjN !R{?! ._153:hZڂdk_m{}}Ih NTf=~5cqC7E(%QmUpӳẏ)e$zf L$'atm_`O.>Sn6&*Vn"4e^0 ! %:}~3UlTWГg^S'rG8w.Hey?9|F{;@퓋ҋ,Km0MѲ)lnLΠfgNڻqTG`x.`jTÁ"&,K("wc=ݸvV֛HY':3CJ&3}uԱS7v-wQ ߫EJٛj65ɓkpyQl]kҚ [OAkp`ʓ dzPȐ_A"$8}]Q[_َBGQQxBܰ5-՛l?F,g8_YL\GfR,۠A m2Ȭ4MABSq $z:J)28cI8 JAg*':XFp_P:sƭλ" UGb}R9(<@M Jx>?aI$ctx79QH}JHC>*Q= p w"6|*^* o IT,R\f hL,q{MFwΤc%H 6וJ~גSW\]X%ɧ@}Qiz^<<;]p%S)ll7G{JXN]7e~Ϻkq$o /f׫ @Y#jL~[M|-xFb`Bid&Ac|(l6ǡliX bqB~7ˌh *rjW2U>2?w:X4#xe[bZS{6yj\P}6Ktz~T@^MI,ԗ~Ki֋0ivxru`^v+IPY JXez~@WХ-}ИŒKxҷTCqli+z0IQ#6Zx0O 5A_CB-@5#}l2)L/xTI0M:MZa~󠸜sI!jL&M%T$7jd2&_36=s2D9S⹍V~Fe2L \̄XN`\@xϱ!y=rMt4W4;\"/S+v-Zn1h +ОZ=(NZ*1J~ɖ܁7f!Ǽă8=jJd+p`8/r]UNzzB}{KG#DAeJk6뎲HVbJCW-'a;f.)Gd1ZmG;|݌52!=GG׬cߙC]-)mEM&D)IsUٕ Friù;FIINˀKޘ7q.]DޗQ0d2lKdz`WxB{<>ߘ|\WM(@G`E8]nC@ ֶ7HH/^MYU@3vw gjg'gQ^gE9yTV-Is׋ծ)HsmiF\P