pki-ca-10.5.18-16.el7_9> H HtxHFa'% ?*}}(>VޮMIFF?é(-MeW*513261b3fc5369bf7de0f510277cad77dd8087ad]L5E=Jt.Q,Fa'% ?*}}.C(=F,W>뵔BTf~*"@a&l>8?d   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H9:GiH8iIiXHYL\`i]i^b5defltiuǔiv8 w|ix iCpki-ca10.5.1816.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.a%m}sl7.fnal.gov%'Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤a%m_^2a%mXa%mLa%mLa%la%mLa%mL^2^2^2^2a%l^2^2a%la%l^2^2^2^2^2^2^2^2^2^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%mK^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%mKa%mK^2^2^2^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%la%l^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2a%la%la%l^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%l^2^2^2a%mL^2a%mKa%mKa%mK^2^2a%mL^2^2^2a%mLa%mLa%mLa%mLa%mLa%mLa%mLa%mLa%mL^2^2a%mM^2a%mK^2^2^2^2^2^2^2a%mM^2^2a%mL^2^2^2^2^2^2^2a%mL^2^2^2^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%l^2^2^2^2^2a%mL^2^2^2^2^2^2^2a%mL^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a%mL^2^2^2^2a%mL^2^2^2^2^2^2^2a%l^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e5cec672fc60ab3856ec0c8eba6554bf46a71c2384ad1eb376a5868f02b57600a8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-16.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-16.el7_93.0.4-14.6.0-14.0-15.2-14.11.3a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-16.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*Iٿ`8f%.yԉyMu ,z8lΞWExy_ !s;r]5_f7QUwss'`DsGyErIP LA ,z2V.Uж"fsRAxXG:'f@&"#4@B X~^Wr~& ;6٭FƏ̭MKj,792LT=^7U 9X՛Cr걘i!POv/TQH7#'+-bʲLhS!pt7[ȯ,rҵŌq&D?VSC6 ĆSI3EN(;XB7$FEGH Gݶ0j5b}AJ'4̛FMĝm@1F=ڡq3`*H7 Ţʵᐬ0f;c^=zNyЮ`'F/RfH 3P\[8ܦam횆f.3]~HBXݸlu9kPG?1]LXEceϸ!CP=bI 6Du=#)Qo&| A# VPxݵDMmПPj2IUCÜ`{!7v#-K+R@+1SsziHǾV5E)bU'׸X7EV-xvW:fɊ2FOm.΋%_l˼k)֢ D~'"m3zC|.FvIW(ٷ}§L^ei; {ٌ >Q0L_Z i+td>wSDh77YG8*!QGz={C|E g!?b_ P9uG8Gn8n h\;;o^$-z+~{*Eژ&d&Gu(lYt?6)HU.I߶Z\zҪml7"uNQtFmeyeMw"*B\}6^[-Q;NnM؍ Byd{EAB m) tͲ,%kpA9ZE|5x~<Rygڷej[ɑ4 H  >@#wT7p|oI(0TдxQ]M)/7D^qZ[mеs\ knnFLHP$l>MʙD$,!H58yv &ll{^\Pos5t#i*䁡iE7=9Y5┸Sp-Q ̋{lHZ;VrCA/>`J|oTIK9_+u: O_Ŭ4+!T~ѻq\:q0vn ݝlv(  nfE|?09d3"bC`q 7,ޛA3{t0LFibxUSMHTғ{HNøQ@V6{%0r' ֛Qdr۳A!8_Ţmнb| q.P(z"k9ko-kTW$5=e=` )c$\`W1L6` ?If 6gNkN"Ȣ1[O4z'+2 RRI7.UZaIa{Z:ˤ .aڋU*6R]l7GkQZD.OـO-P{ײrqٚ襅^xLSգ9,~KImmŜ:2{ItUD2Cq啩}X`\Z/kĨ,'EA {u#1Ρ߱tΒ E6Vt5=t%bǫ؍kנÌ xHrz(׾$L l_IMYd*CzZ`X5 [Z(6 km;{FLId A yq0GNCnr%mVPSv[`lX $gy稩ʻu3I5T h!*1}q0hbf*+IE<%`0؄T\1HC@%M`_Ly&[57{ zGOw^]vvih*O!ٺR'Rfۃ% {\KWG s vO7,mqAd*Z(oz/ 1EMkr+e$ 2X$162LP'@rt&oPNuz^ʤuB}S#K4 ۇa$KK`_Q/\0]\+` oj,";ȖX&9|WJ_)7dDC(vДIoYȷ-i>ܳZ3fs/s=1F܏O\tNjs#`/m{_4k;i 펏տjiwY6 `Nt7A*aq[Mgՙ_=g}aӬx$8AS5XΊI27bSXSW qQ*JKnJz{dLC Ea`LFU`RnɆ,nr%T(D[ A8)a٢N?(Ru:̠y:: 3^SWX򿦓#:(OtBVOP8rUJljҼp{eNOH4ہ? KP9QUI .lgp V!$̋gW21Ts y7F,YWGYa(/3[})"5f ZOYzatw|C!JXA~~1O+Ƌ[H+hdo`A`l!@ND_bױA6% ]7{r)mx?q^x 4k;godk`l6 k/ƘM4 5F._\SG%)u4#q46!I&4PBZW/3b2^DvՎ7pX3MnŹ9\A-|fG7C@5zH6˃̍Y=@J*2O=(KB{HV́EjjJmLn!u;?f[ꖓ3r \nEhf$RaJgmWw>cOVvғ9#yvȊg6'LWT mN1C6˽7SI9:YqoWLd,h4n]dkJ? H[I%Z\N0K:ܝ1ZX >ɇlULHwQeDN; :<|2;cm_"v쀮)iM8@;px?M,o2r"((PmVɧ %>{&i'IRKr_+dN47JfU,H$A6 '33=.3GtozBSs.62fB &QZJhHvF)$̲`Ak5;t2"3=j$~ogL&M_u1F N$UBcBG$@z,pGtRfip맼/":o""J&o4ԔTbvՅ|M%YI?qcV)Yi*y=+Q;~ßǽ{ Qbu!/"JD4bD39>N|X2/uR/h]^JZ" ώ5JHm?wTOA_IzB&ws+0+8 }Fq ̶+TE>"VaܰׄÒ8B5(J|y4uuy0@TMpV]1^ܑsK\2UvyJON /x'`MuRRf Vꬠ %׏O<Ɩ2H~5~AG\<%_hˢwL?)C,'7 zR ^s82#']q]c``HczO:FO7T.),%.˥ 7:f+/UT\#7f(8ZQLd|1քMKħ4#<\u~[߀|g(.;۹4 MDdk8q|ZED6AHET~#^"ApxVmGD=q~qEEăT56UI'1M2k xWAseDȬK eG$'cNKS/G/lbk*(ਘ>Y:Q6 #@Q ntj">DRnR 'G):kF^`^h#@ Txbb$6؏  s)؟+!i[ViuG@EM4ЩJG{%;94R.6 \Pz1VD 5M{*-Zvf騽,LnE)iY4q-΀{,g ݟ+}8WA{b ܫna/&Q]t2aYIpWv՚/`>Tr- }Fq%fH9p{'AiPBc5$3}ipV}P8#&|סɌcGA X+(lKVLִnp&*blH Za+23ػ|z=M4&ģ]<[TC,he |lX2QΥЎM":{?6αk4/a"v5PYEzGq rXv;16at9x{mb6Q 8!F%!tOADVx)t^O@{ QԻF+=†B?DsC^xEj5K/%bgL8d]*ԙyg/Qw~E)-U K5['lqL\b@D WɧA>Fs{ġSwۓe [^?+9p"01qeπ5J˸x<9^TݗPM |7*5l?nFu0Y]xJo ٹ_H'h\ ZIAӛ4PD_ <v==9SɖUazF+h=7>lљ8U -IW[`N ]1ZSUM)XbxՇ h3ʐ,k]l['%R G ɧ(.i?QݍUڌ i\oQ`qiE-qo U !Mh}L̵Yo*$mΘnUE~.z[7Bg#a}%^;'F6ݠEQ^U xmdA h|-Fud翂}MFyMt4vfC^=Cہ]mϦdQV Q718Zakpx\杨ᖉOPN%B"IwQ_9 V .A& C4n"+c{žBύ^ mR ߶еeKiDR@;QY7r=@K#@v:6Ё-~ kؒ)~c0iB"/#H3]3Džh+Aۼȿ@.KPzWW1odԢk`.Fxܶq1 :Cֵ8Ot!TKUM@ϛ|4soy琏Wtxesv%@V>bm8#-y").$]QjެYݧ2< 21x9CZv%xL˒0%7%9F@ Bz>C&VmK[ц03:W7wf[p -v0d}z5[0.AɶS5HWWB՛^R\cbwEP ]3hZ>.J\P"S2T{}6y wͰb@{} x$N &Yߗ:9 т@Ҁ9sKrj WB>e#;N ݮG"slM-J;M|.CbLܣ$<݁/4krBTKpNP_˧3tivʥ\R(UtJ9~C&^奴Xtq H{687@tЇz*zz xĭrJ`U9RBGRf lẈZ= yU&)8;=`C\\bNϠ:dkO9<Ã5Y~F$C_ jz+OpWrɊ2AYtAK n;- YX⎛k )tmOH>wtBqo!`|J bdnZ֞͐E9M_̡c-FwJu)'޾ ?ukjQɼx=Pz# (Nyޚ]PE-"/c&Qye([?}6-0̮9w_^Ӿ؜lՆ$j9q{|SW]C={G{u׎u)6=Q'sA܄1 +w8)Å.G;/bZᚮ!bZUǤ84N/YG}";.Z0ûG3s%@81 1Czh< v܋ka{-O(pZbX+IGt1@]@S0^ЉZ@a\Yep*2\ |U8rمʵn~.x 87zq%3zH#ZsT7?~gU{gEMaH3 J!%f}@\ҿ-=Y oܫ*5ˌ<˼'5"cw [@zE ]rl \v|?  >W%$@$W2$rÙ~μny -Kd3}Iь5E*$cS+ʻv4 mB!=3g']C72Z dZukٳj\[OKi}.9xuW:F}jFY7Yz ˬ4S يKnGA} `#`; ^Հ؉T{*v x?:/ nrޞYw .ۤT3*vͣ [KGf>oSI1sS,b)46_4V''xhhd9YGEIO8e%S|9{Kb)d"_4C#5ͫdybr'6RKNZJÀ! z4.ELVB<~> 9>-v_F02Hk H$Bߴ0:~J|헸(/UNB.("?ݑf[q ޿ ~p,/Ao8dU.7;\p.r56gc nHZGVeJO&> ^bW[|þe*a{.~mOl1.& xk5!wiD_yTvUlȋ6dJ̜|-qQZO ڮ ~baG"ph44(~]5w :޸"􁠵a'-RI (0^#a8mPFܑa;ner0('KD t@D]/%u =Ԅ+>HÉJi[FG^p7ZwW=\9 K7 5b{]MA,Swf᳤a~8NQ~xQTޏcEVF4#X;$M ų0JGo_9'=:S*nnwߨX5-qr^.]N C&p 4=]"^C}dc;A`H) B}Ml;)[?^ȧsqyo>xo xMnI2@>|UV˪`٫ )حo*Sfôa{vL%$[E[&V{5"vR]Nt$};^)4jM|c.2Lsƀ$X}*4rQVB^-LJjr+,CӚ$Jl˥̷G5mA!>MZN:b4#+}k3Ʋ$P{q۟޻慕K Վٟ83HYJc8k?TIІ%4dNo,o>u/V9HȈuP/dՒGYWV~>Vբ''z+'}{ҵIP*Yu^AO!]:@JJ />wW4@ Bxv0dsiJK'T!G]b <\t1fo륵gW:E1AO=Sl=RsfGE:NL'Ɯ "\|玭LFn=TE, ޴i>) u[ CۃG]&7QYa $IJtkA7~Q}Q/ÕԫK, 0c.fSayv.NuOw jI ;D^W򥚃(ss$iX :̛)NŎу`hIrT2|Tn7_ ѡ~ݾRhIUօq Kh1=Ov fb{]*9w'jEz\C()Wa,k<>$jmhF*Z3'^P4 T.踄\J [PѾq!inQC*$1^dA1  RXbPlUf@!ұUSWX|@FuC==Oc^}{YBR|u19E>*v'jZF iL[javxo"lȑ 8sέǸĽS[eo NA CN%d<cAxq%zHѻoo/?P[@^ID,YRXjF}1L)"+-A6uα $U` F!y$@ 4q?>UY]9&'uN*d^N2 |+kpj@ =疳qyXENPG߉],BZLDIq:zk9<Iz.#Om.NS}:'M-a HzG`1ƻNl6>sji G+)|1T-aR0Xp%W Ps?& ~'>*oZӇ 'xLԵ8g, "bcS`VZ\9WJko!dBι, r9<OGb42o|AzP)ݻ& u|jcRUHGv+qj Z9VǨS\gR34f&2! .nVH?,&̤05MJOS2nF")NҷvrUG'K9~p̗= i~7Uo^hs~в3JSd~9|(ĠT\Z_MS rlr\+MλS9b*5Y0i,ГAxLV0TveE z~!9kH3zGP&D/Ɔ45;v`W%(Gi=K{k,=h99^ӮŸ.`AOY[aŨ7lRmִ$makNrZs:<-SQ!uM1AZǭ2pAn~;XT2q2մDKSyhr]Zm_F0Nc K30#, vV_A] g\N#Ֆ8F FvTћ45hǖw :O=b{d[4 5p)l3 Գ,BD~i@.p;a|q,]bW?sޗ\](;u9 !BtTSux̷sh59 T2*5yp T!tQKO+gn]![+3 ~%9Ȭ5ŗ/$|/_=+J4ȍM n&c|^nw z{⦽F7{1ZNAx6#h@u㙾7a[}JAs7$T!Ž :fxCTxR괖A3U:gD&Sh 1OdOJq.jI4E7!)ۆI[:?/rn{xC z; |{IJUD1ۣQWp~q#7+~x!~TX+e !I]]x :`p0uٿd"]kx*s|S85Dq<8OFXsc 騉{͕`j`-鶕ċejKS= CbCV mmE#א@JdNDFcR?5s&z< E̗:v37*0KFA|$'0<=KOQrO&^+#o.Q]I.OGJ@ [U'>\"$&~@~]aye\p{F^&rn+n[+"v'tӽErIˤz,>UvaUCݮhEQ'%}7B(צּiRmLM,w?Lx:!bfϭQoRU,}f*1% | A!gygڱa$Iw<@&ĸ] 7+q*{(HN5ڦnI6TJcF Wt\1bENmYU8MܕakO̔q@{4`B݇I#gaL^QshKIf ~qb暣d@yhdb@b8/qՈ=`<ʊY>R UUN[ۨ)=̲H01nnZ>pNO'ҹy]|:f{C.?tuiOQ7BD$'w*W9J~vMc*.3B^H=VACq~ٵBe^M23:yہ%5Ĕe2+!:JD>M+kdyXA&bk"=0*R/! ,HC4CS>z wޘ0.3Y[ &T@צ TC#,|$혶^h6V)4JɬQunDF̄Rz^˲<~wl*tfo1?k81|~yiJ'`a1Fz[e{uՆ%|T[*섖^@F:VNlIg7ڍ"|D 8 ;㜖/~JoTvW:y#0^?^:护BC'^] &Ԕ g-PݘSJ j[sEd4i[yB[J!$HPaMEHH6\W#4ɗY""X,F:%n<0|-v7Oo~tqPw(ͼ2UYp <\щDvwTidS=ZJ))/ :ƦNtz7+r_:^i.ɐ˵`Qr|ny3CˁJ9ҐDmz/H^D]Z)8/!Osep]6= '/a_FiԞ4 z~0X1`;G,pC2 }OrO8X2M >Pu,&RoءOƗ8D@We*OSc"8v}8^%[Rs35G@- EEb_MgӻmOm֕}iکj^U F'\]E}CWͳ3y N& %[AR`"p'@kexy$xb]j"JR]=u \JdJQK)]@};nXERGwKntiZťo 6S}ClBꁧljUfUO\|NsBZ׵0EO?4JKo@),9_Jt?cGѩ_?EyB5p8\ 4ĭ|F2r!0 *ku.)͸z`Z*Zau5ڽDɵѿ#џ>bpYaG)~ 5!%<@Pk E+?B[b|=Nq׈HgNK,?kZgMJ\$ De_E\qIV +K ͍^mzJ"0Pf⻭lF"܁xL*E?kpeb/ VB}lsQ',;K+`?f"=˲@[ǁeBjRYx2ݘi(+;|d豅jSaHUM->2Tn~C+m/pS:*!LaWxuJ&7(aJBC6m,Py&:wMM(y^#9^ƨ[09}3Ł/Xe: 6tzj4 F2F?T9R7ͺ| j4 IcExDg'F^lrs9n*l:Xd/衈f7E Ok-ƀiv2_vzv4#9Vf9BkcҤ@)_:ߢХ?*cI5=WF[-B1OԵӗOG8SHvš~>dqloѪ |Sc2:-׾DBA'%a=FU:l C_8%ǁ, 'ymDGFTw{iI#kn"ʊE2,2Fö$F > Oeޟ"DS#gyu Oğ0L=خg:hYQ9j/yFasf?`""Okw`}ιX>kɞ5 [BtaIk!>S3||ijpLC})9.6W:8.rv(0@VxppTD8n?CU@V2|5V`O7t LY $I|E># ~R2'PW`$ Ra}7;%APwҌPRS򇖳$K9Ž2^mSoap;30EIK==#5 پK>ǃo!Z9IKWٔJz%xy@|l/S+NL 6N|hjh[Wgt$3"8z^ڊW)%78MXsMHL|V;Pb~X4ao5 #_}dl?+(u|cdDkL{\5K=T#s {(.®\\H349#V;.ģ>dG-ԏ|{+t  ߹x6b2c!Q>S7G n2;anAzP9 a~Z mx5]Oc\3[[* \LX$9 3d_dF¾<|nSHlp2Uɸ$?Ľ Y=Y}P,97qG9 Pe6Pq/WGVy@Ճ [KpV*?]X62u9X&L#5Rn!f%?Ղ;]!bN$śROBvAA9v a04!vM36 ō5z^3ob6gtZ@%%NxOu2o'VdPJLɁO`G_cHNIOeRIOHS7)]n X5ErU./ŧ,=ĖTS@+ FFu/{_ \yxʶ \4 Uo G=l8Bv;7|"y`~2^Cgʦ}׿JL"!T*8;!r8~ |uxPd6t, AhB`Y~B`ܮU Qw m_SbC $xrj*8LQP` яYޞLF߲}I|ּ 2`&|0$P&3{q1 /4r٠Q LmMhVEa_CbKT֗tvWkC- ]cc~X8^u{Us!{9^ɰ썸t)Si]vo]Bo+ g"^p?a4=>`yNZg! y]4^OFR CM|iJƂ_+jtG'@U L:Bw&W䎭dYJV>.-[.eҬdɃsP<~ǣn:$kw +.Bǽqf7yC3(*ke3#XPK-];6w9YzΦq&:eݨ(웞B~"3_'I3 K܀_8VuA@'# ̛")Kf;O4a`qmm{n"FJ q~l4J_b+2NyLNTN !]:&:aqέ^Bk`BFo-jhޥv{86@:懇#E X6dd\ܔSuPr8rd2ˌ grw[70M2P ;/\ٵ{{1/'˭2f-l_+Tlwxr턽_#NrcE= %!HnC]-,X8g¥ŀdB nixwiP@_, |;ֵqy5EyCz|B*뙟%(I3 gK(.^HdYθ +U;`# ` .X,T$uwj ?W<=U#xC_| c_ZwpH9GO1ccq j~^I41ȧ?J0xNԣC D gYG+=L[MSNQc(6{W OI9 [*8NFW/KI0AԘ.? dYޕ;aX#qRYV4ݩv7 Om;!7O1p' )7%\'cg\vMi1a(eSDKqzT Zh}WT5 .1Ee?>~ҠCx~<%.LtяlW\/ zh3hČ:XeulZVPFi[?Ǫִ׈PCz2ow~9? fG/?uFS<\lt1p-u;V&s+PbЕ̽%%gy'EX t ?_0/+{+.~F'A~$u$U-c[q PTj## "ů)؁4Q` {^.__'Ũt۴Ёg}RsEoIq5l{e4@cP4z  s#NAShKCKnS~iWJbϱ",y1u2@-8@ tH%%9Z.NѭGv{hv˱0 2nIɀD^?mӄ mp잦(h۰DxM̦}oSl 3&15&o $OA՚oh'xВA37v2xcCNx0x;4Ntm\ 7Ԯ~FRcE葯 *kN=.i0T4BV񳜑Gcؿ'w);%yAEn7T  L4چ:I#) zJm-{}$(U~GBÊ 2حgQ ) ϶5rwWxV ) YI `) d Am*Yϯ%4.sj(p?~u' m@/|sKVq\9ler]|VOEN4TFS1 ݲ%wyXR$;R"1c3-dxeݑDB3oA7ebh9f'Jv+nۗo/$9տy =2p}H?IjxNHIן_>ks8&u`hj/f6A!Փ>\R/OoG :aWl&sU~(FѶ.(6zjJ3N=_{RmP+iW$CɠZqkՒΤ_(pVkJ_Kd$/Ho[wf#T[Vr7ɯ\I$m:HvXZކX+ժ3<ϝ=gUX~N؛!C뜙b! zs! C#*-Ч33S}`:^k %0Ng|CHUo.V^Q/҅d*CJ}( >n;Ue QfJ66gg&\hGlM#h!+ム5MĂT{Dz}ügۥ99Mgp02$~Y;)1%CJ跾L2?௟? 5]B)<[LE.#CSw# :T7cx5HRYhsY]gDzpE6`"ܝ0Uu7ĕ!4Q:>X'=2HN~Vz((OP3d'`X(8ȁ#R5zHT˹cViov慕]^} vHTE9tS;:C߸%oׄ+Ex|&A%򪂈 y*3(Q)ln?bJ[i^ "9Ȅw} J*h9ɜ ct/͐s} T2: 8qF[5KFU8 TTg4JaDHC)˫fTc,Sd$Pw[< ~p~ 5|c2;UVZeb(T$k ])Y װ5uܢ=7W]+:e6zg0H|bv`ʫHrd6‚3>_Afuk>m g0 շm>:;B<w_^ƽ\QE!{IWvOv-/N3)REeCy ,p;2 \14k֤k囄*kmz-ڗ8n%l ;(Hbe*#'b.Q"9 ۳(Qq@l'2?|)Q19H g@qԑhHH3TtRnAyLNc%7Xμ0..'hR4Jns+v<(b4{zY[a1=jA>` g-ls@s:8o~M񉗯̴|a#*v@;Rylu L΅kk)y_kxPJeB4YMG*; Q".  3a#杢0䮉6{dsYvZk< Dw~}]`y\(usy{3/3aiIA`; [A>*BDx"Kdb6uL_Kd0K/.5DEcjs3{Q?Fuؘ_,Azr?kJ)[AmC!_DGuk\Җ2SfܩfYIJRqok׍\H(Iq9ycrL@E~zg& $T|4;RPB95/sέ]|vi=-={- p\ś VXN\v'ݍ=OeҤ{Zd=֑[ڝꪅ( 5 _'l^K:WxH7{Ƀ%XPI@OV  5n -jٕn.^-W}x [o[?\CO%A/zeA!K}C':b7OAk-C:*;!s-Jִk`bѡ v&%Ӱ`gxb٫ `{FM* P::څtNN\+=hxO6" 8:9ΡA U<'Jz 1ir]R`#R75po>@(jhaK K"O@YE)S$~> JLN2 -{H\\d$`ׅ}O~39JT-#A H2`gR4>X\z+D(0vЌ=(+ &oyiJND򘵥sbF32cVmFtowK8Cؗy/W_W5,TB3geTއ7 H GkͰ+<*O:gC FCBA^OexMT!v͉))_p4-a[MeĘ80|޸ X,mL+e]H-Kى|&!#M_jM?0b`B\ᑢ.,G!r969OLKƝsٙLz/"ũ;P^Lrj)=5C̲CTqH_47iFp%Rߜ&6^VZxM_d ղxshQ$njXj'5OG&Li1$Vt'.ͣ`=ǮL(Jz#Kl6w@Y13Z7~R"E0.׾EeFJCϮ * H =nga,N೺fHڔPf_ .=.*!7)ߟ\22]S38;a.1 q~4Wct!n#m1" ]+ɕ`MS=HXJy:%/5`a~.$U1I7Ih"d()C&d21k9n 2:j]-wb]!alCirY]"V~$DIa7\*"/sNg66u-~H50_x fZ:a?9AwLEjz#Ad<VrO3!!oWrK;.?B6dr JeC61G,ݶsN6 !e~f.٘4 ,V/Ϣ1oc{$[KcfYBhNcG"0#?PN1U17*?MB=7=Z~O/z/^#/z?E^)pt1λY|8iVvAUJï.CvX0쪹 hLKm@HrM؏J`'VUϷ 7,ܡwd3)Fq]iKWZuϡ\ž: ?L6s-KP);d4!47i.~ u˿oqMD@[gP4 =1α`5)0*f~qq dnGk['~C ڌہkeC)]@I|OoHFo7:S97ℋj 2"og%tceGȑ $|堈71NL;vbK.Op#aM]a< psim)c}O2 F*>x-SG EvE\Cțl:ht`)t5el8lH*RB"Ngle^MָB`бG$td3e؝UJfhu@z1p%PdT*JI vn:b浗QY޿fAWzeOg9n04CBH‘=crޮ{9" 2nv2< ud9ƀ1ٻѿ䡂 R ix)WAQ[Za#BR1/DU,qqV9a2T*),DU8IYHA,ع&XbLoBϞqjrXM{ YEׁLXXFK#3X5f%"XԪۤc$iDlxl`aK|dJ''dm%"}pDYsr9ko2G SM#w?T)#74oe/Z1eᗺ}N[dێC};*ە++X2 ɱU,0~ ,g$P==Fnj6^,ngWIMXY n5hDT›>zqDh ]Mof5 sUXa"~粒K&_}sA45Y0_2S L~@㤡0s/^<wc&0e%F*tpd W8,U"-,&z/t*OKlQ/*JNe)x{s7Y.*0vړ"@nxQ!N4P}m 22L(8pB()L um/aҿ]4̣'S\~,ϝFEL褐ґ5X|e/9x$Jy-nchzlz݂ɪ!EV{b~WssiYq5ED"1OlU'ӂeR<Ҏ,p0Ձ#oŅx?dÃP7CAR30h-2{Zk L"J No'j{O5P^8VزI$x1Tǐr-^ݳ%5n='AzP `}PuT*Zą5\NA]8橺1DFxAAY OukˤI)m{TFkfеҨoa~* \!cv'q2uW~B8fjA)tͶ\L'd"B)ZI.wrirP~AL4U'B_7 |VVAѷڹ2ؖl<ֈӑ_x*[(}VY-==O%vJ5X }3Bڈ}ުaǔF+րbȀ[qm{UFBpW }tzEZ#BI| 0#R6nL ޛ`={Hn4KΛ8O1!h`)^e*Ie V ,9тO@o_^f%aJ- J82yf WE$Uႅ*gnwJNMi.0p-ZEe+x:?_Yrbtt+N2hBҟM9~ZbM$QfzyDwg侦.GnX/I $>eZM]IY!/Hv6)J# :MhTegdLG*d'VmJ/柀᥍j_p>MF>a'ʷZ S-HQs9oTo$Rnr-UOIl3-a6eC`RnjerXGp÷KS=83FFف3G`O\Anfvp3iVx_ " 8C1sZW#VGΐ|XrE.٢n{neԷXVE xu5]31T:B^*9♎}o3'[&P7 554 L(p8'}?ӴPY9 V,i@ ߊȅD%B f t~Ǣ} м\gb7zW /:d˧AROpFbcҏ8RMӬA-'7Od[9 cyU}\'.tæV~u{_/9}t=̾Jf_ wL߼szP7 ķ9`d~;׸aIsi LS3:?3:WD" K>0S-Z?"F'9,HE]UTYFD?uY6F~@~$w C\K {]ϯQPpyG/`^F?DU,E41D C%ۼ$(V zBG-~,\t@r/RY?SsḏX|`lrָ)9rrI~:fgrBj8&u[sy\"vd7&5 j^l/!?@(ԓ=d|KYc!_$ ,Poߋ ]TOKM'V\['}@ϚOnVdWLl\xsd~0QgS'dHU%s'[[?,Gk;"D/?ω&TS˱+KvPT,R.%(ʉ,+6UV-^PSk &\ˁ#3e>y4_"H(PbY㹿ap8>>ٱ+ 3r5.ų*6 e1Đ˹Į)tmYn.B K!߫rh_#N6o|!ƭ/ "JCo_dP|oܜ3–,ӡ9*k6!e5I/d>BP%}sz|?l%s!;RGz}~)%'g8읞]PDž^qEy~ST9Ho|cב7j4VU %d+rBt7{ww^6A| ^%:^z&.3fxrSo>`QJP.|ymsK\()2pw8 ^dzrTd̉Jޙnc_vQ"`/<$:"Q}>#6mMEyDe˖-8 +}pV^oT'^mozB:|xb5WΪ~ s>iVL,}gKf3r/rK|ȳe&mlh.(܂}2f'':[QE%ʽ'L1  )Jg]o)w<>UN2KgHZ:Xė< \]}!2M# >m߆}/?f%ct,8.+K{盟lA KmHAN .  R+y:զb՛"Jn{̿@ӫ<]2T ΂֕VjInS ϓ!jLe[*,צ/ !? e#gۭMkCd@+Q?|^&4{[ZZKO^SZގͭn ͽ0mZt`C1<5=n:ÀM7[[lEUQN+1R}ti^ <{k53jd&[8=jvA ٢d܆s)׸vx*QЭqb,9@/x ;BI3Jsl2TK]`n|:B}x`4]cDcԺT Qo\ Q63E/~ ybguR::a6?O|%^ܷ3(lg:J^2FJC Au}Bȑ 55H@WV4O<_G\~1Dp wU,Wk] n"9 q#ײVl +MPO/ 4b+MffjwGK"6(y6nqۤ,5H(c:/1hSI+ݔ^= 2јfww|;A$ZfYh3XǠ-/ѳ% ̝D.[t!O2zY  w|~-~͜whB Jd½{k'YehEsƃBɗGQZlV 9)qmE$ H ;;@j;SkFM!?4W|hbCع<"\pȘx9G38s^k_4u`B w";cЦ.^g؊)h#ʝmhhׯቒ7 ??  jU=FeF瑲wvy;R9VdP .yĪQ@D\lyHrɤi`έrivSkO '6D'FdŜ7_OD $j<;OXjOHkEyphż_ #iK=ZLUE&\'zД\[8+`ӳG_6&0lR_3ʷbpd;GĶ/O'P9n&0biƈrZ:82k7#"Hbrf1ñ;"Zj N[+Tw_>^Vַ], G=kBp暈 M}w6*UW}Az;yvoG*2Cdd bq3' xt+ 񦽚-T%bo===9!=Gq)4DN,@HGPWu5Vd c"(o[jE#tJwZ=d9X%jl+屖_Y i橝0QzCMX4A&ng̨¬+mB?n' [_Y(ۛaf(ȘB*5ShzN3XalxN #ү8*7L??ept8fΦRdUz G+c{"tfw* A X]̠띌xIZ/ 9('6" U6> ׀R_kJΫANd"ؚzc6v1^1J7ܘ|<Z !{;Γē-r2G* Jc4WM6m*P253hw[fZ@(6FB G屑 V?bߐZۘVAQusԺq]p~8bRm=l6K.K~Gu'FR_I D3&! tMU! 5n)w4C -p9uի~:6TJbec},L-H"(^SK3;/2nP3s3k ZjXxqy*Im EDSbsp$%PgsW ";L"}Q"fhaEE2l!Fkrz(G V嶑<¾# +4?nT ͮ7 |ll`1rWge!ٯ'|iv|ؾl -Ŷڮ|дV 5DqlX h7L+9m}uK$)=/{)^nTئZi)Ey}XU^*LWo2xfq3\Y3\]u NMr?#ӭ.cPq3#]IM8`\Ŕ+<#qtÒIwpO66'e'4wUF́8!-lLe${?PT`_̺MpiE)= u˶aYU]B\\E? s]c.X|K)UzBmw Uɰ64 ~Bhkh>]X\Ęlɜ'Sf0Jy]t,)8){I]<+zux\DdæFU$$3-)BJgSaWA$t 4#M3>tF༇Ǥ?tMAGض̀ĝ= $W\Jj0ATn8rhЩA*Du$VlwRZ'_)RQF%Ϭ Sͯkyb @VK̣6ɇŁ%dxD֜iX鴉o'Ɲ(x@Dz_A!ݵv s"gb*q˫ 뛖'j^GIёu`VmF?xxdok*׷\ܱ"`keT.j\ `eNۈy-:1 PaX BDR |@p(-j 7&aC J:1vJ 3>ȈTL-PiՂX Rl;/!,E 1bښG[ODZԼ|z9600*2l#aFFB9ɫ^˸ %k 70_Uf&Fz:|#C; BT ВO߫edhۜIbڴ5_Ώ ?%#ngSx+E,f793Hg._ vkēJN8$ˣ*EKOq4vʋW ;Ð.6:l>UP:9s(m3]yIA1$ĀͿd׃a+Wo؋p0(1w;ֱ9Vtǎףd9Tus&uw=:g{9ZAޤ'WʿE80ΒgE.$@C{{RD6h%U U ??!k"*ԗAlO.j1) /$3QG c8\]SAG9*>_.6{ͰLCcp_ǂĦǼ =ZtiB;'0. *vq'-c3zx4C0Kѹ$KQJ3ݕ|FhltABM=樘2sTqP`7܉S쯿> iza5'ǒQ9pǡ7,|@4[Wn]rIN/ӥ!qM&ysiHMܥ:uq)$>5e :Nq)*26 &2↽w 6M*=0 [;T{|A*FJ.~x=pnr:ߣJ(!͋LLR$r?P fm s 0G'}*^%Đ kg&%N*Jw~EW"ﱟVmWiWF~t|j<{^ʌn65@lLqIH:]Qb1M,՞%јJ*()ݢ$1M 9g5Ibxz4&} ->h LϨ #9.5u hrJ-Dpg<`$p :̡ꁧyYNi}M$kO[d=4fTFb+qWrGfZQmb _<Э i^i@h ج?/7ahC 9yB7țy 'Cp p{Kc.dG%[>s3Ce׎L{GfrHaiT+-u܌l읖Z:^3M"/xf͗K_ FX:~2JTtD~pό`rz!6l@|=rEBF: Q̮{ I̥ʤ$݄g= P a54)1|~/e{b8iFt,(eB'Xz0 ^VzZ>^ =M+NߢE0;,?I`#aB!1m$:SXF2T@ vҟ$Ufʥs7ìs;YwaGEə _<+wEuP&X=`F,$2 Y呓RGLڛ)TkwѐGg;鄒0u5ғpcYNeG`@*LqjHrs%&r]%7{wV2[F jhFVkVu:UsǴ MviĽ0gTRJ os'2{T~9ȸlO{*?,o'1.vRaIy]=+Pf>|j3^Pc:(U ʃj:bQ0rz6m]rDom K 'Tz _:Eiu*N-ŰAnl>tApD KlܜĠq ʸYg@nr16cJ]Ugǘ1)|n/& asKzPo29ެweAө juH*=6 n%;đ(e ϴ9SPC9`K)ԜKP=Q(yz5?&*-m԰x&δG'zyj_a V(v^7 <2)cs:]}H C.5U%٧䞃d-i52K$T 0HKr0OhF3c o 3pD{V.) xw`d~NH$$ 93G> (&] #EGq'/nUGY1DT 76KM3l7.0q(yt0:챁DvSdSZ+Ǹ]Z& rp84bjK3q0 ߵdeI>!Ҝ =<^? O%M#%6DVF>񻨷rgKp=7ьJ:)nM':vF$?X3 r3>>r )PPڞkv|dж Ɏ̤G4OU |0Cc &-8}x5`ђ4)a"vFvF%P$8ceIk 0mXg &wCgiZפ]5dlm+QQܽSnb-)F[YڻZڰE 2a*=ʥ\܍5M#$s >iѬOꉉTO?4xws*.~;O! c%֭P* 4zekJ&$iS_g?Z& =YݠzTb:-< c?\2J7^!4xxdnÎFxՋS&]ڞ='Wʢsw)ӳ9[y(t|2eS͋K>pEK@f&'Dp~`%}N]oA3GLuDTepv@r.Iy󥜱NbfcjHb%~^G8`4::9[Zx^9NpaKq@w{ULc'c18dFʆ<ۦT^KG餹8^RmHFX σv+1l6K ;֦{ùddHnQezES=':>1tf˴la! $gCfKWgR5V~bU񳃻1"=rn7CӫC'Juz"?? qXIJH V]6Nju тgjbm/e'𾏔ڗJu~\q_.G(z<]RjMG!D*B>g6@9MwO]Z<Ԕs6{"i'l`bsHPȦBqv.UYY0 SpQtrvȓ%^3SQ"=&ǻJ :EtEze5=Vל91ȎSɋ.e[} L._3.-y,3: ׊"c2zR _?:6:(֚l)}lRt3 L8UKXc"1'1o;K~ԑvAHlX/ v +eI͒~{+ۯ]}dIw#1-+}4V>./"r1"c:Sƥik0yvyHs*zFN^giB-$]n_S,ܒ:%P )u\Cc8Ob,0 zN5 871yj}Knsi:bf- y#v@,y)&lzj+PBk _{/6?{̺h I (Q$D_wqP YN.-I AaKN+&u\{3* ko1qW&ՎbQ̍vn#{x!0ƹeܱԊzA­]so LGdžV9V@JiaJp`(Wv&E^|3C|\_ix(dZ91[uؕ,'*@E'+#Vw'Mryg"J) czCۛ,>zL)&d28a3,q3ʔ٘$+^! [H|); T+SKOh$d$^Ӂs᫨Y7_ \ژk-) xe~{Y&m11JbW׏Gb/qr \~)2ƏO:92fT"gYj4S=O_c.i</S/>0<cء8`T[5)n^ppE^!/_AB">&qjSV޽۰낉]&$xq&6gm_+qt_]91]jƊbtɻMp!#uê.(gNErN#cÁp@AmmFVު&_jKwL~ rc5)d 35O4 <)ʫ]ɮ?2&ϻ gS*XbT)1]9ݭ"jkbI$CLn\aKhuL ;MVUߋ>$1i/jGkl@\=!P-./@g v1RGϕN`yKW}՞C!V5q5w |?>WKQcDp<ہ8x,(o1Dy% }M ӖΚA7WS[Pk`F5 -8TNHsre ~C7j+ߩJ?`4ֵIQ q9Fӟ+㮖h@5xɐ?0@Ā2"5*QUYßp>5T4ŲC[-D8p-$DΙ8xҊRBU^I~<}5p9i ~xs_sRАN'Oorb:4w#6-) طXc ޜo9(SQX#+sGstcӏMXNByE2rE};H*UwvWI S%.U˘$^&b1uhv[~sVlSaFGyߪv_h, MŠ|3㟦㤆2~dDŽ1"DŴ)`4N{r'ݥ0_ue>B[!#uX +Pֶ DF=rL{x& ѳЏZYJ ǯHґݧP@G M >EW`y<{y΃ qymй~)c+-m)F!J=70@=&CsYݷ Z2K&}sK26UrY{)VʐҠfH, ,BWIיdR{p͸ [wG t8rM$Aus.CT2V3i0MmFKI"vՉ r X>e1FMT wN9ˡ<)Ċ*h뿩B+/fNgG(0{hc5b֎}ZggFMW,j_p^o8Aomco>8Rao0/F N}؄˃wyY:Mϣj@bVE~Ng{5RjY&#)E*>`VtbY)KXU"'JpR@=R;}EBGy1X)#Ԫ\kri0->p%҂ƕ|k&-V=sot$'>ah5xJrh0x^"UY< W#!m-Շ.cY]w6>2<5$S\M?G]#]!#$Qi,;\w0g>=,2REb57erNIRH#qúx㈹a&V'5EƦŮq=;AڀէxKsI'MjhQx_$ ({+^f&5:v>H-kF'V~@I/:7:#y,wDrP`VDF-OE{hq'] \9cTD Q6b0s 0څ!½D3,tDQx&kRLZ)o;c\loɹC<ݡkB9>9Sј+K_,&Ȼ~xS~?#xxWJ"l8amۚνr3D,^oZ. leg>hESI a"шO9n(wARex^ikHjELxiHл&Qޛwqx>@nu#kZ/+d$(-2˔R8dTk6: 6m=Iv-$sKY4{LDEޟwڶϨ!#~SBCPf%!~ViCz1 4W$9$V @%mw4"z/Mf APqB0ctE%^}+V o6fCC:<HXpjuyxj GlϢY6h*T]lK߫%&";egiċʛKG}Fy˜?*;E3 T|}OclA6OC뺄_G%e`WxE¡OX{8Tf7 oM]8v6'' \D@s558\d@Ǣ賀y }\fʔ S! {É%wK"SYc uB}I2{ROL.O c ϥy2cUV#Jkx6bSo+G__{ѓ%85k9P2}sT3wscƠ c;U qMԀ6jű` o& Iϰ;MDG\x;SYNguey뿆DZcVb@R Pn8<"/ggH@ZX]DR RTd=Q3|?xh؞,d Y.vvZ4Q*Qœ 7~)L\I.3ˈqNȴ@CG22Slk!=bxXlԙ ,=AÙkVH.Эl}Ӓ;qbjnRHC0­zMHk&]~bnA+a,5>ȔkK`W0oXp9K6ԊߺhQ"/Ӑe[B>"ڰSH|E3"^E*]:7g}ʾ^oZ:#n (ZDJn>N* ҃2l^+:flzb8t ~ `e';ϓ,2ȹȔEyX!^]:,>U[_Re^n42?XWnl@۴L0T"E`Unɮ U4汴SFG9ll@䃩r>g|GYTsE Y. ߢQroѰD{/{]Vw@i"8 q8,t@Eu&m||º( 53Q!8,f!oX06)&³@|3)qÞ"z&]=DZ2P7 @RAo*R}/RALzmbkЖn`I%>`3 DC-"lWS\ߴ/,^B?%[0u%`CߙDC||YN,Ȟ#~^;VK/^ lt73-dH641ig?OAzl1ȝ={*FJd{Ƀfq́apLDVat?``tr֡4!҄xvi.=V/K M;S{{!jG7,3O^>>1XZ??׬_jy>D&m[^)~w9+yU?gflUGz:%c+١&.kVťiƭЪK_A>УX,. :6|(6Y#gKeƱea;L si%*\gN C`HSf^6]d 广$r<0KdUREzl҈^v$nD6LVSJ AD*G|@~vCz2"{ː"ONL1 o̪:exM&jf^bjɭu`K2!pȁ H|(UH9Yὰːǔ|R.|Bӆ-9`ۢ1=Uў17˃f| Ӈ/ ⅇ¯*Nfv$ N)=!,4m{N|H_*M[vh%[=f)Z5'Y[ǽmSpP_\)@֢)wn0*r.wzw[ƷStۻRُ(jmjJ}.| М|PSzI˺R\ql?d Q'f${{pYM_ě%Lux` (,`YZ+> `""VSߓCJy6XK=%kST4ZŁ0trcw$y  gǛk.U_!LK-%V2YtgsqdJ+[Iyەd o¥;֝i:Q#Ďr_:BLoyuae09UFcu[P\6 \ `$S6AZdʤ*7 A&nM*n֏E/8֮v iAayq DG$||h5#,XNPЏd3PJw#HNJTp T4ck'n '?V_{02vEmK$(ZNʼ"Gh9H20)sA&aQ#v#VfTi=ƌ8 $So 8f2Z~H%AnzcqKc (Y)99*.jD_遡7g!f~ʱx$i ^tn",| 8V\%)}' wMFzؕșTxm'aDc!CZnU.Ttjܯߤ8z"d-[-)?xIv'@=? ؞ quEXvs?{atO4@D1u4ԃ. ^/ ,KzYf]S [nמbΩ_h`HˆMG@)tXhô,U=^xժzύj WhԮOwCOWA{;`&D^o]P ؜Pw;M;tBȲs_NBR*n1yzҖ7l#*|☈9FYȗd K ׹m?X-ߞC"Z &S(ٖu.-!Tv[ǞwHa.?OV"SeNǷEar#4)~>i(Ə݇ NΣ2%[f0T8;|Vl.PYXD1BUXhpɖ*54Y͉`(ˊ;"_t/NlR7*]^}γy t=S2[ҿ ,ȹIlpq2Xf✈jOo\\1#mDAYNku!; Je( %C XmyNOP 4oG\jM#v\}ʍB9TآOƬ!&iAl: LjO3uzzSJMN=͇~!B^ C0xM{N2ԇnAMvE5nAtC+kOON) lEH_c*ZLգ2r3n4 :ύ"<[%KƧSʹ`)t'}&+ K&1՘g?R'#NQKۥ:Irs󲠔Ťlrɯh0> }s[!acVNO%viX 6Ih~~"ݒ`3aU1+]WVDi[rö&!&Qm &>7Uǻ#cR S*nD^"z/l$p{:1ϻdbnyf=d_YPI3H"{%b 7j[ Wfi>H_FxFRY~ ڊ[ @G_trx4e%"(?V)4ȑ0%:J&cf9:뭍LBźs~ Mi4ƊLà(6[!DODcٱp들"뻢Ā0ml":2ffIsD$J>w䑻o>󺶍a_նqvHD}Ave#+䈕Iv$#_Н/௺yUbb,kR{kG̲/%RV|p4HsGur,;[MzIs{W:/9x{_NQ#jF -_zYA`'" cb5L0L). #~[V8QzBi۫6#7~lQE"I(MHTVd sAY4!yk_ygt?Rҩv̤:eJ$a^mLj+K9`jɨ Z]B 2.!ya{"WCb==n>C4\CZZ+6&V6娮Dg(dwofjsP7HزIp1Llv@=q5#=ϵg9S7v3TFɃhzf;p@v2Z AXȝ2ЗZ41Z_dW #\En%4yl[8T$_Olb%vdQa ByIwn#nWx5įϔzffȲ9c%z1;R;U(N!tq?6ȱ`nLїF3*DAOub*I:j]W%N(՚R(=GcUdWKB}z'x2#4k \3h9rN?$ZUYĚEݱ~-0ZFe hLu ^<;#QNlex-I9/Ҵ4^l7Mff|F C-=ucꢛ׷}-#]DiamtQpAz&wkRs*85Y-=3$$STfќn}6Ãz _VpI=$zlầG8nObrN,ك} Sau" iDT-+Y/`(&†JJ w=?d쫯#0@{G<ĭ%d>@\@5Cù)ݗJP׈u犈ȾWğ܀- B\ 2Hux9 d`?G0Mz[м@zi G,yH=J2u&`/>5IgT ]O#Q.fDA-V̮.y- /Q^?G 4QAK7o%%/^r]XF{zZف_•ѬW7.8aqI%Tg Ufk~kcUx]J͹$"Tr 7җw'`I |_JCr1L5G@}W7J(9bE$.P9VK gŖ@i3v|S#ҩa x0V}jB|D}r`Q9>̱Ng2Xx{tsD{ŷ9T&0h)`m(qSFƷNyRI")l@j{%U AXe [avA!Wxs_ ^!s@aU72jĔ>F/ ާ9Z&yA ׷p{L1"kkӒd ̃e&<0Mt9emtT;B=8bO`*(jHuC-̫D֪e{eD> (ܼ(S*qbM %k;Z;# ^%XB2x@%$mPqlk #[UT<]TcùGO6Y[ӻnnU Le\ 4_~$ q}%{v@͑š!F19*ܴ~Rn^Z wBB+[83}ʟ6es>AL<9>ShR%RQ7[{~HfE+UMNl 9EG Sp_IIK1AuLcĄH~E90 7J"gU 7='cEƛZxK}+o2mSCPA/= Fί$,F1Ccdo(xVD/Cd[L@k;l6.Nȁ2 S~dulFws^܁tcz<"( ?j'14L5U/Q}gg}!:3·^R 749  wմ.,=& LI*qU\$̪9ThԸ`2xL8=C("Wki{m7ߌ$m+YK=n8)n"? x$X$m'YQd>M_R{Wa8[la_;8mo+!GG /¦WihDDM7r q{ Rn"ư 'c?kyBug4-!Dk*zdߺtWx]MW=i Q3ZHB Aٲn?@wv幛/vOn9`G둦k{МQ|H(SZ. R?d| [1WR0i`ȓY>߳ rs0rHN+p v Nzb~ג;d=h+Į8V6-ŏQ̩bCjì1sceĪDi4ܴPgH*,LQf5(*+TyQPŹ+0HBS.sۧ.T0ezhyH\tF?ddT.DE~{q1ckKrFmc_y ]3HC`2rJWLI9h]WǣvJC6&-x6Ԝk"UnX]_>Y_ʹ~ix_X BJ/,Xk#z}\;"IvGuCL hYa5ty0#!}q HqN>X|RWRƲ.SkQlrڸRUV|b/'\NfG4xBfQlnԛłG>8}|ϯߠk-@sM5Z| ;{?#O{W<ٓՉþi)ꡁAlK$-. <՟X4ѥRCϾH:ܯ`X͉E=Plz_EMޜW"g&ynr 뤧S\R&EN<=9* *ȽFB c)*Rpf(FmRBдc)$iiBKK!!I_͑Y@7.e8q񖜂R~1fE."xI"'0q 7#-r&nJb'[>OBy?#W5X}[[H$s+;ڌ2Ti3:Г.ǘ hohSg=k.j-7Z[[[8xo}@݂?S8~!+<8i\ |@0V_oZB2B;Mz`ݧ#:n(1cK#*sW*&|JicCyCSu3szi$OFcZv<ݝ SV`YPME qȈ+<g+^Pނy΅lCRB59.;blDP7vlMM2c6گRx~O$&r wv_&fT\LnJ{t Z7&A.l"'&gژT$}#u] ?A`Q7'֋a#peqR $Č~A0hFOnOp3gADI/Pd/sSޕ C 3c% ؋ =:lۇo N|0g-qC6K8;-qbmnO'".8xt1Ey6&McpE 8 'ICbFo7b/ldJ˞-A V@G>pg"Gޔ)69άMH`igDS:s\3ޮJЗMRᴞZ n[14ߜ ɕ \ St~^򁕷 4d#gp8"]F֛N)&*w"wOO[AfB,7r1g&{m96/*q:[i"Sܷ *]َ!^TMTgt`שђg\p)BL{9Fn9x) 7):mYzl|c[Z>tm9>sy@z -+J`@X 䦣:ۿ+9HNAbުl&YE`wXW1GNvD+TGSW0A -c.I0lԍ)m˨X_]3FrcDtftWV \M3jM h ^` T)Qp&-(:YF#ZOlnӋIؤ2?zC-+pF0Yt!vH*tZ[/kQӸ  'VEU&&8h(1&M_.1nX ^- YPHAU2wŠmYFW͚ 8&"vu%&dE@7ER%Ӂچ=jx"$nCƕsk=;EHU^Ģ&dHNgb9Y ^"٘qq7iTX3~sEo]r[!+(+!>rԌ$jPF<ݕu5;i )jհM؂rtʘA}Lhnmƴп"3'1Yj/ ap8# H#>=I"^:Sp gM:uF a$+&SP/\hPxtޗpmm{O]54J%ۮ:J_$&h{ދHb8((d'W+PLZEȅgf*J4/ĹvJx^~^a`Ȋ۔ny蹑jav-F> ^r}& M.=dByOAir"泛h<2#|be<JF|44!r8Ӛ@In6M[bTlT =5mJTΞ;dˁvZi@D:k*46 pr6񂌷CzAe)"QT9S  ,7h|d{HU e{һ0Ki,Mhn &´;MM<Ӑr)']F %iVD,/S ˏSQ3%KJ}d8? ώ΅..;GE0tKĜE_v Aius0pǝ9e3tsX6 q=&p}ZoZxG "l+ǸwҌP.M)9I#7$6W$ǖm;BU>K `:\ֵ>RhvbW)G.]Wxgr2l \ ['J# Ś}Xhe@h1PPƶlT,x8viι|`Ħ?7X$lJX*~fka5kΜ[0Zy5#o!DjXdWr + eUHO%9K8[;xr X_R5#%P|y+4P0zT%< 35Nx!QZ% d48"lH @HN$C V(M~UdKi'߷vFȜaS&WpA3=cOqYtu",Y"ycH|Kzp *t%ŶTpnW5njĬ?'֝/'u{1Q]ί3e:r; vYt|R[$x\,leEDݤⶇBZݓ^ #!?MϷhG-N/e`Dqc:'Cq!tLOLb!ޣe}1d$ܭqgmH>-?ZŚGhDlXcnmm6c5&ر{ p4C҂3 PL R@SNT%~AM,kbmjDžKuZ1; :7.rL-`Kw/@Q mSkYܸVϧZ *!ɺɲƳ$w%Pwt2>k$[Y,9|K^ _o]69Jf3%0< to>#]~$̰T^8?yCcNu9݄_a;p5ĦG9,}g!ˌkjc%Ka!UZDBՃTb' .c٘k$)Q=0C3.IMwzuʻ,.ZQ0X$%e(5i]KjcC42" ["l-A ag6čۍpiWT[ş$Yee?P-_5K3>zdNdx=d0% WUao19cQzE稹!6 LYHt(uV}>e0\Ox.*cp1FO@cgh㒙^jvCݚx̽Ab;qo=5 f]p#+GO,\;(fHFw҈ׯM_R=xHg$P}~>U4)^o|tޢz<x֥ڎAtnlApKbTC||w!ui/}*W~uˠ$@%aU'_[s򳠩?YI XPfs#nPESdK?p ZL(+~ZJnw31)F+D+ƣDܢ V0h׋ 'zF'Q͋4ªK Ӂ;Z̶=ш?O Aឳ&pdIrbЛ[kZXvO}~܊A힇|WgWnFcq"}ۃcȳ9,m$B*Ye8ܵ|wf \7O@5wNnrJNJmvdUzB,)sv58Ov>qSzA$7`pLڵHV7|lH7-K[z&K /Tm{ lq B@_M3-s|L5QP|xm0.ꏈLf  U/5?{TJ_Wį\վ6m|?mʲRjy*ZIuoyT$K"Ζp+˸O\/O~LĄDoPr,M! 9PpO ǵXM:5Dῴ47C]{ΆF]9uoӝJ}a>2Li9CmK;'2J9MI\Il ђK-^AFS@ Y1Ս ].nogO厛äV=](F9J,NZ"m@3Xh.1Jv몑w%:£u@~-"Zf<MRBHcXrr\~\ lufĕ峑s' PTƏ4ף^ BtISTfYCQ թ/4`m=iȬ|Ga(Q*Wi1|+|[EMbY?ݓ=&_]uxJ~puIB`0M ;`vTt}ـVIG%FۛEX痹Gް5*3`k(cOX2) _}`I|^1p&oa@]49vOnV鎰kܚ^$e {n(AAG۶ O۞8p=݆9b3,-4w휌} Ȇjt]RASGַ;<Fd!x`Q abaa-T&Q Hn6&s8ղ;HüXDL̊Ψ> Ih4oFps!pPwֿ Y=c3AP]; `b"Y 뿉Ҋ@`̡A!RmP,J";2x?u~h\w(u`13@wiut1 G!$::Zz/ JQ=BW'!mۃ/dMP91`U}y|2H9!w w~o/ á-tuP0's2n:$k A7q*+)W7A0`GgTd !.L)ktUZF4yfByܐ( n]f|ic{e[2d|n"2vz̛ rzJaCaKdz(~O:R!vo}";"dE/X|w`|Ƚ Dbzo}WJNhwc#kR6' vK-upVY+ʘ<-pd3CXdpLL`UrgN]a@ZXU~WΩö"<6l)u.+>V%ob#0Ŵ[>([,cVkK ơ\$ #_/r2")s=WE+͑GCI~(kcGZDJnS^zxp_Ҝ |P6v|ԭj7ƒI{̎Ϭ_ڇcL`k+YgXeWFƥ~cs s״N$rO0͟NuMV''pF3'a' *S;3(Rw/l7 9ri;=AE}Bx , ~g|/t˭>󪼣չ *m17Zx(}{ Okmר6h&F:%&ʣtJnl6jөCˣXiD'(x áM d9QOCXW[ &>8)xH6gÊ>7u E=Ժ&ߥ 3"Dv{Ԁ`eh TZುn-6BcXܐi/c!Ts z)Wh[Ȥ) p 4ʮaSK^M1Wk ZAXaZUEc?ݜyVU{/7;=O\ӷ^?`J>5ovYNe>ie&" hXW5_R/9RxtxRt}f#H'1<-TFp0mWI+*G[y*J0oӛr)[垛{ΐDڒ ]$ILV 6=V+IoY<9b U[Yrw}qMmtBrH6̈SzI*Tp$0e'[ )2LoYHNƂ(+G+,RͷB:*miJǴbps~\I.Uysdu8. e`#ux6]̯zrYe zvfJ1 aDs"eF)!8Q[߃#*?dT{CO=\4*eK᭮$BcC mٗT鋣搹L,{ ھ^M.SeV'7J =(kiuՈcZi3%s0Ǡ<_2T+lQ9d *{JɎ  ^ 82p6rUaIc7xWs.Wpc ˃)(;ޫh'5Gr6Dz9.2⫊W2)@{wCN[AT#B91~db+ ̄=㏪ /q|LdHRٕ7R _IF F&_ZV m']-n\ÉŽ*NJ:b/[L,-@H-/r"`4!v<t5D_P*/^Ja=lI`PdAϧuD|R쐂tUCe:NE)K.>oeJ7* rO[Fdى䬴N٘g}FlQݹV*5XD ۤ0FdJ(HGI|?l y`>Qs84P:'&Ʊbh$ԎJ|:i߯FHPh]:|Zw.KŜ¢UY}Eqd 6!AsY景%~ .4%DW.BiR{#gV;=Y=Q[9:FQ#,0N${O9 HeǼ|!3Q|ឰ’l1K򜃭 tX:RTC "m?4;fqKy;C9_ :^kw%)>mb` `{GƃEv%敮7sxCǃaiJ+4DV J/#H=ϤfczKަ|*S.Ϻv)҉sɛ W8J=CjA'ږ  jr,cB uEP!2>w+2y#Ҕq0Í4~mv&^۬/]_=N|. %Mex>;\J$xGh<8zrt|҄7LpX0"`ŽELM#j8`9S7F`Yك¢˱~ÑYm(߽|usj-^U5X80BKk}_LPc$56cjHx&_ `et8*i 7?1͑%9*ƗI7^mU)6]$1xÌ[0?⛴9JT0btvl8U7nCxlCQ՝L2s6l?J?ULɜsXLKpU(L5wwPn6fzjxKW!L`aMY%b^u!cF -ҏ"K+Y̙*74N Pnf -PbjRJx[rjR5WJ eI2ަ;҃vI祭W)CO.̔#z-A::OZ6w&]Ճ[-(b B8Xj1'K^6.#T$ܤ -ܛ,f!Y5n4o: 1׌نN~ ̘SRz<'# C7kۜX/{kEo* f{RR5jic1]&ڤzf7 ^"MnL)G"#ɴQN*Rta]b|X{E2S]P35C*bdLK_8Ni&[[F$i(:Q]n$0*",z !cuPcDG -"tt]gF3Er`zG J!Yt_/i\検sP?r zMLQsiލLN߉$T0r\"FfmrI׉ܳ %7vzXk\(/ T!+L sJWB%;^B\, l*a ![ٓAS#r)cmįeںunjwY{h~O;M68Hr/FZ"U21 hxniU]ڵ||C}.(A&s7^Q*K$yw(L:[B ]^&8҅1NƵb%y/v o4yKL'`wD- \"@Lnż9V>`!1ܐ$rsm"-@DW(.4+@V %u8V?X&M2I%ם.@ 4-)o4qzGR]$@HO@ҥ:T _>Q~o-u  XsiJ/ ǚQ6uǩͥBHsEUEK Hspk m"NJ3]-57)9qרlL‡2Sb#!{‹ˑ_9Zu@"}I ,c; eϟmyJt ^aFD{A@Bp}e6pov{V6EV]P7`~ExuW* '# _;]D^g@5O4E1"`̊ރU5 c;{:exY`2sGDvM" h˹Y.6en 0\_ $?j۬T*{h`C蟡5-yd6ӆ0dlh 7R: .6f5HRᗹLosi'@ C?\^;HЙ:,3$8Vk_ Mv 6Ү$o w[rA'򕕍e%a;[ʟ@VO|S?PD rvg`SAENa FsS]7: 2p`vl|65gzA665.d,@ɩ0~(v*ZT4i; vc!.@K''OiBRrQ##<5}-\EwuQU}(xHDVc ,1>TzmZ|5HXSh܉xx ]F?qh\$Qy|'uz n @#eILb?𯎒\Q:B8iH`_ ^=EM#>\{}XWV??#p8,7`E%{'~ KC_' \N' Yt*)YrE;4]#/gtN=u{tw5lCME JZTrۇʐ|= P@E &.sY?>HSNn[։˗c#aءY[N&";_-u ^pmjGBjv9/xcPgd <0?.{_Г>zQ28\Cyuq"$eӷ7MhIGDB`]%US"G/y~,|}21ISg8LJmSmp }]|vY$_kҞ4|c$f<9'#H>]mEx߼ll}[F,A{p -heݧSbݣ{V8:Ƹ̃u>--=VGa&PUKbH6 nc2.)nLd1gӸ]%gQguHԜѩd(]CuTA5ảa밃&>\x ·$9Wk~$jN8_z/,1#"A`lޓce$9nLiM(H @{(X٫(7k̝ڔe  CPQrLm^p m瀣ٿ]V>ʹ$7 641}l[T#=|sOh;Dj۩sc+fyLz 0:~k7CMfJ#%Ӯ[/2$a]f<#VNT]X,}#ؿŶ# AݮeuXi:JAzm̭XKM ۪EC$9 -Z{Yl_d\G6\B.qv!(F\mp;jھ;{dE!>i0[ Y,#!<'ބ#,9*e^9>t"EƏ]pzьgP~lFHp/wpoAhA9bzz]N)c88 ݎ7Ws*sdSn>.,xp>| JuQ\k VW0~XŲ! ISGИr>@HkPcŶ[<IU߱Vٜ9.'-x_0DN]{ځ9Y Yz. +[3I؇wTrh5Cf?w͂^-Xp^ty{h OA;r}5|w * ȯNnN&+ >'BͧʁЂ2ܲqLFc"$Р>%it< h_1/(n 6|_2')]:21_b7G, EOq%$|>m>/˨tr4<3M%Q W9^*G-]Ӯz`YISrU: {EN FF>18&`lσUlHڎJ䘮Nd-q䛑LwI1PJI8yGAk?4Vv2 I_lBP_1Cr,cA|BQ'1jK\&S٩6@/lIr `=U/ijz 'ltkWWFtnU{kf6'1ߞ YӝX(9w%*ǏPw HPq۬9@Fx6nno&hϼ!v'p5w4.}֔U%ިZ#!pb?讆5<Ct@ 3XWV2YΧo=2"Y YG2Eڰ= ~-D1l-w(RW6E*.%z3? Ř\yAFxujuv;G8!XfK~qp-rMػnKnLb٢i!cZ&bՠc4⍲KfM@Elf\7+Wg5 +MO]3'?'Z/H$\XCOd40>kFW^La!/0C # ,59VG`,jn :Ō@V*^|| e5qN@;D^Q.Մ2)Ѭ ~;\c݉ ڀ'\ڝxé+Wn>3l"uJo m~<ݘ"$& lDW[k sbqrƵ ]Z, k'&A`[^=\A,TIG:fC\uPR5< H)mBu 2o-ÄIL~I/vY :zb!1Ogo@Ml8t=&$n7Fcrj0D;4r-(N vlF_$ <@wn`XPܠz0ִȚ$VR&vDDjX0{@buIp="F>h̨.zNZ]sc[bFL6ԟcZtd{Mbn;W~'| y zZ'z(p= Jٮ0"/[6SAuQdpfJp\eSRyv+ߏЩC('|3Br@1f8Z[ܑ#..,Jˌ)JG'\p$9IK)M;ղ9Xinrg`)I硢>G([KnΌRo.y42ͯE5Mq=܅&{2]^]틗[s )?U8\0lZm|Noxj{ ^.LW aw\AǟBANIBYo z\廚_wsfv˳|Ip4"w0 DOu_[nz/0DP%)%jb%'Z)՟ hFTd`j/ًٍ9 ^^|ER\|j^Ԡ\*f?#?vQ{ueǭEOnQb.*ctTnht@oVGpjFKmChܛR\Iz6;$;~]aPbyFB8w AAjHJSXS^ @B[P@VƧyT]۰Q}@nIʒc\3$b% śqas@7IIdžWY%]0 #t+0Psmx@)~[FiL[(ģ;C6L¦?/n} b5a)dDC4m5M0(`3?ھMRkt<5JgJ1O& )qP r98Ѓ֐( bT:h<4Bi62_6Di!Pr>4h@]@%LTX 7(]XicGf-kp/sMf̣8@^!]yD髅RwU{HcT4  ML4X@pW]iGv^'* CRЂ셥ߊwL)1!`✧V1~W3$< };Í0b061NtyV1C'G#EZb;5uO D( LY/ 58RhSmjG(#:1rSQ+Xok0䖮!wvgI?&U @*> b3\-\>CKɷ~q}Jhc0(GlVD 0 ݣO M|JnVX`x%ktIZXU?JרĴ1"nuXqWg05jhw~Gm»4FS@yJ4dk{(²aWpFiZ;7>Ghjo :.egU(=]o\?c5Y:P[/qSpvaÙrپj~6l{slcQ-1#=Z(+ʖ! տmٗ #q4u r$a!F)hE%':A^;lQ)QD g9 EPpQy XOFDz81Pv=o*z7 ٓl$;yf QhB[m(us!+~sU$JjĜr3H,'h'zt#t? 3^|p̆ %ۂeS(oj[QEId!Z'vru8`dƳ+ˤR:~L%߂4c<@x!3!EkDh0ukzsb,s'*{jjd&Ҭ:7+%O)^gyفetc3QI3~2(*s#öBXka-<lvl9KK)٨|j]tz(NKe{<1Rs=w-n@r#)w/%]PSر? ٪^ TVW]Š펷t;ʝ7W!d/}xKﬠÐ]z^/14fR\ 4AVK;P*XLߙ8T [4?Aղ)xn`@!ˁVKٯs4`DOݽV#4B`Ej3?t=y#]p>*"6Q@khVeE^ubzcn'yLr3sIa?wyBu=7 D y+n4*\w+'IyQϡr2W<X'Pq#h&EwOU%N kc$! ;ʻ: #L7*i=?- [<'FCkO(1ΈAfl8nF ē/ g;@KLyJW}ͯaF 3o K8A@E)9kG|yDO{`?-3CzV5xu Kפ*qW`Úi8愆zJmZ!̌[he ”PK$Y1O)g^Ls!pRrnH!8 /_jӞV+T>JsI:_Qӡ^KXx7<B5ZI(] Ǖu :.m9C) }wk9cy ocnCr}kwQ$kQOꦇQhfHŤ^f R6uuhs϶Sy`xb%(#k~K]@=ƛ|xKX3ag8mf6sg:~PUuߕ> .z.U5?ΡW_d,NXp G7y]`#dMCy%hEGtd/UrO.zx^_/u3wa2/"UFacvlAA3af~ ]_M4& 6 @C#ȬZ;g@'8Mɹ+ PNI+8z Ϸ F}qlo;*VL>"Dz58.YX ^)䈳WmYh}ĬgyB*yDȍvv)'-VTpW@6z0En%sjw(9[v4`oOQĹ7yVr]GӧgkH>6+ LqEAr"don|>R. 7:G` -TBе\=Ƕ)Ҿ3qJGf`b |8rnL]Z;xevN0jXϞ;B:>2sDm讲[P2(xֽPŝAZF{}n+_gjЍJ%iqLV֕rي/ny|h,6LE@Ptz.ܟk4ۻ!.ڮݝPF ^ϔKcEOCɼpPI-)jxwm BȪ^iUHsq{F&*4s}nu{S#.${[8ADh~}8TVDa8r-a >yn)Iigc~fVCV)_Nw\K2K"d1(ݾL1խvrz΁q[b$b.wrbE.Co3KsAKF =Mh46s?m=ג=cB?ECCDuAMq4 L7Ȯ1wյC`9z=b,! dat"\ un:SeU?} 8 tX} ޹nZvx*< V_KpH!TQMʢ(E˱q:G3XFJu@^CR . Jmȑ*XURP_Otfɣ: 6?(*ΐ_ms̔ ^V'řAP&Sjv9=TP к4}CҲv ( ϔ7tP4.DrBZK9 x %{KXUĭ6귝.X]|=s "wk £*rHouBseˀ @qclVffF KJE}TOD)ǩ [@zolWgg f­QSw"nl\7mÄH~;HUI,ONos2.9Q_{5+4#a^>:4m W^eRtj|gJY+OlUso,ʗbYB{3Vt0q *Y#oe*<X}T!L,['UniSf d#-+H,TqІeA&g, g!tև&TxuW\bE -Y!#AewT?rs0()c_:Ӷ~]\ XHڻג+@iǜ?g (*UsQO(ݫyx@ѽ)[]:u*Xt[JYCcd+O4>JRn6b6WJL?DNHJy`@؟"]y_[3{DǖW޸y s,15,"Y_dj`Pvt\b \M["Y\oJU)߾xTyn5upN5W78L8"y!~IO2^ЖTD4 "`pV甝]2*f&+ng6|:04h$zYI"?ߣI瓐8x|Z3V6SPioCLgė]_Yh~Ni;ά m"ޞYA(?ַ_C&OT_!Ӈj]X5:IeeVqXۋ'͓ ξŽ˾- ia ZV]` ڞeMrD!{}W'<鯬UʓEI!lrՑ~rp \$ aYNTH7qcs,8Jx! ߎUJ )H絿/@I -V01IȤ iۆVТl,$ CŁz_ pŇTsR¿SwVaNq;`) QXË(`%Ok4/ҧ%&N͐Q2:1ؽ۱9G{m /l] s#X֔{>q~]`Š~c]p6fiz^,6|VD$]Lr$FQYQhYFKf vs 7 ĵ2$CJ#Yd.X"lx7"WsKpԶ=mhl'c]DQt#;&%=w'P p m7.®Tv(} w5iߵ6>yegZ 0ߞAb".Pӳ'&ALnfrYgJG-%T*8m$74#[~ŘWk%+=l I2HRw6JlZsIgN"Nbi Jo-Hk-˭܁KSfNG,◎$"|porjGƉN41an4]U*~9,pm4B(\5B;.I\Ď Jden j $g3°C)m@ÿ`b)lUJyȦX]=YḺosa]QSw}7[ᝑٶdjlcePnh|ndYJzԐqC9{:){x "W8@o *- 9ͼ*i(Z=u3~ަ,)Rz9/*r$[zd>lUi,F\MOq#2`l:&΂$b3]RHJT-üBtA`BMd"R5-I8 S(DG61 $N^\Kf4AWW)+n 9tp2o6J$~:#C& 7q$IQId;)ZjN!C;}QoN;x(B@nKI+MLQ>ȸ) OGJk {{i//B? Ck4,^I2˪KWkҿtYh+Yo^nLgα;!)/ 7 , K7U.:w 2̽FrPn6vInj nTLJǬoYcMCVQ"-1r0,%nB7E83#UU1jŇO+]Iɥ"@$׹^o\Do%fc۩j%ˡI-L/0JtOKY`6"e!zq,TW@s$CXJN߂CԛKnrQvg߾aM8h|ohYt@upb>w5zРW"yȚntVo1(;%mizÿb9D$zמeM %yr1@쓙9fSK1&ҳ(Q gO[6w44n˄m6Mㆯ;/;2'/=n%m"fQy ic<~y]_F1WaÚ:a)ig7]~ X Z_ЕP^nQif3 ΒR,2[3֎ PQv=`EJ4 m?!@+Mj}}FzqvlN7F4QJnt%G~`6yΪQT&%&vݶ+DCi[m7[/:?e0"clk\4FLb]ð#NBk~:ECMYh0-YȺvRGIҕit-Ϳ~uƜo^$rc96rJa܆>+)oT^pZ"Ŏg~PlH&: Gh܉';- ݘEl9~`4)/H,iV/7x!oi}E{u$L)O[Ɖ 4W6S{ȁ=}CdȈMkRyBH/=df:@~5u,5]+U-КŘ̮!̛~F/ -⡮(E]!EkV@tyPDh".> [n&7ւ澋7~|oVܠSX,1uzcu4 $8$' +pt_N;d#s%йV참͜ G^m. sMx _oMOj-|Ԭ'Id'TBzߙR;'7(D H<6'43נ븷_=[G$h@f`n-"w[$~!m۲?XOg,Uى0zasoT`)VO>\~ l"9nP GXh|5eR$a:+ƿbt-r AFw.=OCɜXaL2|c*n$SmTh {Ȳ ‘Q'=Ot16yk'Ou4Ha޼5U.P>㍥1H=sGq\( zx[ 45^:o#^)j8^a>IH6FGk/Xںa ڂ4!PEi)AlR$0qBL5\Id^vS0@'!X8PˠjsI+e'XL}y'ERtDsSⅪ@ 3E3 K>" lk_ @] nRȎ^т!S6DY'Y&rUۻQ*0]T Wz#&]䩷1Y >M2-2T+|>F͓obE-`ѻ)O&jNİ;Pp #(9?L쿈f46Hx[M`. fc)0G2=C}܌0luaG2솋i <$ `NWMFp11]s䇵8U 61v)y:Ox<^E`Z-혹 km7pDAvX^ed M;Ã\jU2xt[T[QY)a$Q{C$}BU&_34X-04pFʟ2OC^Ls`R`&3bPyYhB1u=Xp͐ﵛ~CdmS@gGsWʡV{G$x]**֕SvT,lWg<~J8!@S~:g(&]-enkBObeAy{ @*?y;8o21 'stO{d?ebK  &KI8SL@T;[n@ڊl!I* fx;݅N22^\ouI;U?icr25A&2~;9P-joֈ1TejCνN,x{2u(QܧɺE"is"Q;T&B԰t;lNᓂ!fכehK*0̛FWV.P-m-fk$3D 7%idGzt"BU.è*,jv{ s5 /k5b d`(ޤM;]3]gj`*8BJۺVQ:4˝<ɋ#CQw9PUxg k[WAb{4CF=Ɩ<՚Y~PM?SWJ)%jc+&X9Mb5WK+Whtlch̖R/{vBН Oq<Ծ:ߣL׮q,ۿ=p ʨ83B=\G?~G1jv8E@o Sќ5I]Ec)%2ק`dBAn !,!x)Zδw0K^܏4OY7a/2(CW+˞g٭Xm%xKDǖ7E?γPٹęʧ+AxH"Gxp"PoiY#F#lljuqUMGDruc3u4 rW[V f^>L>Q㟶b.lgn% $ܙ$踟L\-F= g)AڝH= YT{,hQJ^8R5k6@"Urg޷lQ,߮;^&;ZS&s~'W3P DZ+C."3Uc,S `KNV='u^"~T}\\~ˏ7fDZA^E;B*륢6Q~u~.IM;徫 ݗ=bdkMxp9NRv:#KyIqt: φ&4FaEɢa3;p$k_bs+eV8fiCK")TqGBҵ-"N^ 4JqddsQR1UCSx%,hT CJ0K!Kzgͨw-yr..X/n <9- -dںsxa!7q??n^*[XxqpV(`y dXJpz kjl$ ɒrjs_ˤA n[덃;].BmqI7]N u@Q]<G߻Gz~; UNoCEVP-C`C?Vf㝘MtI` ?e]C{8{&Lm^R&d=5f8~`ȆfJ@_Hs"bnT ?;>lY ^ >PV|hmsܟ.O(j/k~E#bnYulBo\@f o淯7) R[q%Fܻ^}et圁VDGmG4snײZtֻ1x5{ʟE B%vN]nҕDjm ;`!o`G@1D_JoM3'5l\f< ݋?%XW;Kkv^i~x\j5D!۾}" Ry_jP53YN{Ve=C7#sPi&NG#|u*x_ 3.!uܷPch}\#n6rMe像0xZ = Z ;Mor ]^c#U|P(= ߼KXbwez& < _ϤG{IL懺* eRc_7P;Ҽo $b Zddh<~ׁ:Al+z0fHb/VR@g40 Q Ie֏ udfn"%E&/s3.^D2dd\gPT[!-د :G|mm3h530f WV(]84"=ψ9+D#- ,^iFR@VO#=ZW )y{Y߽Z*aYm/1* 6 ,^\ׅXE~A*Yg#Gk E#w6ai'@"aIAUqf-$BWt=Nwo'{/7ǺYljme9t' ֒Йʤ+\bLi[6t)F?^*S{OT͎=9G(&3#İDq}fQgap E~Ҧͫ2Fj:+{p#oTԊa|h 8.˚m|;tH3U5uB & 5*v6 t5:3GaP*S+cz(%]:THr^&DEMp=J`.{:ky ijz꦳ctC.wݕ/jlljhUp(ENÔKxz2^ϴsC%ŋN}t<ΌL&d!ẕF\ˍW2p#nGA}zrZnPR%ZCD"7o^E:v`'uեu$xĈ8-'n8jqKpj=[E?"Yvw;16u׎ֿ -fMK͡H8V%=#I$>Js(ûY- imEM%1`jpPk⇃[v<{#4Z9묤C/ 5?`X ?R4{Җx~Aז@A*?7--x} 2V&RQq>Rlrń_/Fi_%.$\: %a}X?n"M Kϯ.5}t19/WtY` UUm`dܓ 248϶wyVLvcVE=Ǫ#䜄+U2.[ͣ@mďegܷuQ w3nXOeJ`qc0z BAxCi?nu.t#N}>Bq4,s _>ҧ}G^()r @.حgdtᇇU"j\r̈}5!v嘃6ܗ(cwo9#iD& Vb((NvKe{ D e4"(di}ta nYBYœ _8ݺJ o^j?LzUZjz &~tbc8y<+*J- NSh{]Q2uq߳Ov^,ues>c҆=)W\ʚ}<^wyJZ ǝ4+xfe)[JPt>tF b@A쐥MbE$3Μ~‹ׅifW!m5LרCW3, qJXBR >)I&Zr >;Ѳ% ڐ^c( ]>u>dRfj:v,\zt3A{naOÜAiX{A6yrrbTNʛ9GXjmpG&uoTsYlO<{ބwK/6$}aʇyr_G1۱;n_ţEt7%fy4G1wSiˆm oi_'hJq8dW/lz28 pFy Pq%@}.'%}u?G5`tʥjDQV23o~.GS%* $a'wzyՇm^GYΉ3ּ&fP饃%¶R|/bVJU*VlyyDY.XчƾPdg0*a>q#)ǝ&c |oL\FG&4\7$k>+DWTj=]-g]|lE6 I*Pͷl5FPUQ 뎊nc#ccڌMi.a:){[sk^6o%axD#%!lL8e}2x Q5eH'$W8l|CN,*YW2YE4@&h0$0ò;O<D2"Sx?,fa0D\0q0ZS&I<оUʘ!wW:|)FZ.ċ!H@FNJ%TDJx'AM4Fi1,lrxdN*.0YUiΖ`9?g[:) DS:i:*9 Q8+bI|5B*h҇wcÝWPsLå5WE5.u__{95VmJ12rC2Or&`=,![D-X4~N*/٢h3'rd%3@Lx{M7 g=`9Q'3`c.D6jin]5)@? )R_R"7ecu a9Af[op_z.a+=(o:<'ko /kc} '4M_d,OenygU{ ~*pav7W zXE |Dd !|,jƑSu)N9TY 4 j#MkX)H#X[!b=_ U,aF_C SVD߾VH,~pxK: 'o*%U ^ ~G%9aO!*eF11/0$KzV>)te^LӲK_ZlDΠ)jgPo苋_Q8tD(V<<w2dVź𼗂GTL1FG#",֦ A'G"Āiq2$o^,߁f{2JO"ϒp(5U|pfQiaL#\ (gY.ƕ,v*7@c͏ry ܗFo]W4ͳ- -o8.ĽgB"t% Ery9MJ4TC<9cUyH15dVJ&e^n/ jݑݩE2qD+1>Jٳ(0qȿğ";F$HKBc5$Ú̿}nD&sb$VMHW[z`SC%ӣMmx3WZ\ˉ'6/ە=H7V48' J̆W!+* $So!b@g+krP-`H'~cĂ]);{@n <2zZ{NjMT,fR$FqMA|~^4;+{::Fs7I3:je9p a /#]5ni[n݅_ៜt4|djʏ3aSwYvA 8?l7rS{?|w~g+jg D-/Rh/: >oÖ](jERKCzodK&,t:Fvw!%^viw4M BnnbLB6(ξ#;Nt)EaSL !(?k`0Q}@*x/Kz Qދ#KrQ*2F j/"^&#rVo>wV>.'OqXLVZ_fp|#x28tqx3{ZڐXC Yߐ!=}}뒩P/Lwiƺ~4lVf*`Uă:QKwL,ץ[GU<κ&}x  ddvAcmÞ+ EϭET PdD^qMl+x>uAEI Ȱpg[\EmڲרǮcs?Y/BސHI||q| No@էoz ե;X^d^?(e-QC\]ޘ~bl6 OMF[\xᡩb~g2Rq kBхyZIXQPȊҝEنT"5ny/-|Cx6M3:e&ezZ'mf]4()E E tόs"Py) ֒w p\╓$i -pilHC JE/W\y&ݢvs?< $Lt%')ozy w=HFhm>|)ꮽ/KMʰ?Tצ`Ɠ6{MO,.ι6ƈnfGýLқS9# HF xqrDZF\BIĭV!ƒf(a/xTȤFe(Y]<;H'7U"I@}ԕN(+&t%MʸTGX%EY,cдSP(+:R0UoeԦTJOy!~ hzHE^*4(/_FƛrpD֥S J7h_[[9g$|ط|: &6#\5s@8]d=q8]/,'X@PT.r m|&]34Z~Z7$^/F跣ezb(&(k{Q!1%fP;nEU-g&s4 jj}*(8\Lv pe!E!b>EJl$d$߬2btWU=>4r&غP8nܓo#S솅9]YLBKDSQ.,.%[A)u>d- UnS#˦wU-UGsa[j4CQ/yuJGT<݉CiwtG֜v͆q,r-. :֗Л'pOɴ!q<^<%xkulgyDi0l<ω'͞wa4@~K&ydAyKg՝maqllRNu`Ҫӑm/a"]O?!Tw/Xr&BꉦEtfn--pj! Ëax=GnH6cNF]Ş'_yWP942WkNe5=K*TJWG4t!?jH`ëu[/oJ4z>ˆM٘'$yQ,]u;]5yC\:HG;e3=qS. I h$lzMPc,7W ^ņ`o׃'\2.2Հɐ#Qm$(EBnAYVqV]4y 0<\i62k?Wj~IOn zm:gcoj={Jl,IÐM"rzÊydBtImRya  Ck-F77z' vfI8W 1!@d^eV~EvCo茟Sftv&>V6  ə 0,jF^JsTTI_ ᷶dwd\YSa\I@{~w w ,.E\F d|uK%KjatXpBa~ʣ7nP[tc)W]Ds ƢrsڒZMywa!I3ejQ9@)5g$F3BnfJof=(Z }`u) ps07TQ*aݱL8C/PVS̡#AoQ { (K} G;}ɳ%P|F_'׵x:X:֠FZ6 :uPrִ>0L= /L?ɐ:(c}x:\Efj%l #!ӐIyDP3NR2ms>']aQn邶@bwU&dF^ h&Jɸ#a77Z1}Ԭ&O 2EPeD~o@X1Ce$~|iKrUU6IڧGba|sG7n,w˞FR-y>ϭ %1 'ҥ: ~C%iUDQB@ HuoS;`l,RЊU U_isTF"R"K^F9 1Z)}>Z8s[)ni7Tm<]b8~ّ%Q pvz`{N &(LAp(.آfK&h_qQHpZ wek J]'l)#" 4h;mdyycR(*QY2:&m[22Q-<˕lyun$EdVVzֿ̓eBۇMq}_%zzdGcT#,Lܑa KerPUuJ;oda(b-遅M^?4p=܅1ԗu$2EYȅ]`10 (4wiNtdjyPm{CYB<6ttة4ue"aFj|| M"x'0mJS`a)|!EWи`Y.f\ dyx=,R&DRɗtD{[$GsYVlè k  3&pd×}aM,opSlֺ **OiS|Tf|諙@)loLSjۊQ@mw˂ETB01G~?c =WXs?oo&اe?~c9s_aƭ[hu­$ҪwF;eCB'K:Z hc [ )#ׁ>-t$lz9S/qU!@ EskM#Hr,ɠ_`-Md e]@`s Ð(ËAFy ģ;o5^`a)gWO1^{{ ɑl=QWb[TwYhJKcGʓiyeـC$/1]:Bz c!'eyج0]x13ƿn6MV Xl#FޏlY*SoHE#e蕢KK#Zz e"ޭPz +RϝxhI92{5%eR]ND$QSo^mLɦo%rMO_Q4Fܽʴk ̳``wWGvgQ^ͧN 0!6S vn̷6Y9  P̔>z>q S#PuI{ 6Z8Ptq~NF U$PhCӠD'XW!bk4\M"flQY2Youv7{2DMme}\hdBu֣s,k[wڳv*k4WBLnoOއwEgkz1y+>fV(;9oB==A|yViVکҢ4սj1I^;O e:{Ͳ|fMeONM7b&RHzrQ|t%=n#V'CDJ!)DF 1! ̩>Ha3DΠyRsYsyԕgggiJ1S,i%Nf5}CJ퐡+s'+p?T62gr:l2d"khMJ^l=kB4%{|yk(oC/(H|~ ^OZ])K׾ LRE뚤{C>rץ}b\M#^Pd 왶*5殶_vc=,M_'5(TӷWMX [yդ=ڝRJ$gM2Wҏ`k20͓q4[\i'S(U1TqI!.Ղ_pִ1[L/;ʒj37#j7D;@>AYvI都}Ǟ G3#b~y"\p᱂Z۴GL,؂IƘMfPT߀B]?P4SRj,zZj/̀|s XAM%8> r!~/lc[2k8~:>F@ +PJ{"^~!&A4EBh#?e0o sk|vY@~|&0sdKVݱ+ i^mzD+[%+#g|RBLtޞ-H( jϱe$-lz,DVc\n>6VX,'襷|bH9ߓYNzmn>g|8fZ0t%i({a[ dmKktJ:НׅizeR rqA^B5,}3e:I>a %u0_|V@fc"._GNȼ(sJʏ}[I+z>"eH^>Ah`L%D?L4K{)0 Ս>N- j;v>["YQf޹yXP^6ȝvK}6dGӼ!;FEƃCG2ccXn/k obde: 'q\-&na$FJ3r2=]oNGx BaWDJEZ0®eIJl!Qo&<{,yܻu}f}zź$fP1Q;߰bhLN*I`Tv҂nc.mG BݢA>x}u ,Ga݈IIdжŠK1W%L7P&XzFsHCW%Fe- rlPnWײfSrNX}z5M֖(28\,l&p]/7Gy~KBƚddӞW`mku5[ tX~ٞ(h2Dq76PB4T?L~}D.n9ozyL>CG:~#M0O*e9m:W/t(]nB*h:?Od#Iѵ-,VW*P p{ :Wy`nS[n9TH<޵ 29R]eȯn #o(SjrͮU?0C0RݠAoK+Fv@CX"3H 7-%rGS>/U=-j෉ _+gGlGNט+kMq?'d-'RJoKcj46zk66Yr?Υv©Bc슄Ry.1!LW>|Kj ('fZ2QX>:uu8,?SgNzh#ͩ^aI*oT݋rݳǿE-IE6&iD+y,QE(i U|Sl; C+'^C|Aum>\n[ #__=0/)iȑ$ú+h0H2) o»{$SxwM4 2ۜ-9ե7sxyݴzanvZD0HRs]*%/ K։I0VPvD R@u_0GX]!#d][i4*ַؑu|*B)'-o[U o(>>/J>b|%Pm RXhnjGdwЮjjl.Xlr(DN*|2r+1uO[BXC%?IWROC9흼AyFr:}+ӾM=:Vœq+h3A+g2juUܲg+%Ժu%7$. ^:eƒ_tyn/2!wtTk ΛٿČC;ٷ:~{$l}B0 E)H*Y(v>^-=+*̂0f`%s4~uE5vԵ]+Գ;g8uSAQUpﲒKunjŎbٽTlt%PIHrۜG-Ra: 9\F5 kB7Fj8"|[,duOՈ*~^o'Aբ_umtv.q? +LhA0bhi~]nF1G$1M}y_lM0Q!c!{l7S[ۢjjBpҞM|&ߏ7d9lů oe/+W]tUgvWقda&lO}Aр7d%/1}d ʋd= W`&4v0G Vq6Eԡe+[Q]vIm\_"d `if 2()QS bO:mԏMS\Bi@b8|i(N*,xޕLhL[M(v Y]MwLó㟜'%Uh=UdDDt2ig\mS/ҥ͉ H~7 p@ 첆CoXcHgjC(ˆp!/921)V/\aBI&i3.L)j_ZZcnA酈 q=I? ЉBH!oXgN$u`zGLB{du):Sx=ZthkC{ֆ` r*DZ9Mй ɡaԃ5{]>xq)Jp}g3+SִAÌ` Xlf6q &"n»6ccj,xXJk0tl ZkC5C"1:l0$ָ"ǝzwqBj. jA5~y90M"w*yx>Nl$ǣJI) ߋq5ЏlExV_wQ;ن]!Fxn 4dthBD~0],c ]#kZW2#R>uݞ0=YL75ٻ9A"^{R˓ms/Jv~32%qg)/}Tz!y`:$(Fܴe 4DFF(~=;%_)ZcKiӘHL_Y{W} ց 2́:Jt\ª[&=t?꺌dv~Oics/++lGs^g;a/+CC^e;FlApO&[Rgrb\ a6Q*Xv34TK,&gbXK^ؘU ?ɶBG+*#z>_@#g&A#tF3749a6'NC5:۹G'p8e.ufY@ETf+C jǹN^WHc] :% .8F,]`Awf`O?Zp; zc>JC5uH<<9v)CQ2x["Q fw}hҰ?qNp =b 4FqomdyY EѾ|,7r,],O\wy*:cBګߏ7 ~#m/;p",-Sbw˜"s);7cCثq+遜ͧ ύ>寗^J 3չW20`c `Alӕ/wk,gC5(Xغ@g*X*1!5?׍5op2*E8ĖCi57>kdr)\QƯI(?ٵO<2ϱ{wDW;᜵&aYkԕ67kg.#(|[[C>G&!?+I@n5GUn 5"3iǍz@fruui!l+N"d,Dg%"79?wُKI7긮>CLmLT!PbՕ T]vp>phz I@(܂p% fXH {۾ƽ /m=`f{1a80,-210ʼO#OH{~״9iEeܲY hlNeL]vŏFzmr:,Bo-H7dF1gVԭdsCyWTִlw(3û!`CEkEd{8XpBlb[0qbhJOxJ.N?y_Xe~cXH1GV8-D])Oh:IrH, [ß0`1g[&!(=e8C'PA%!ӢAd8b֌.KOj95cʞ֮˖2yہOOuJx2'xeI-ve\3V4:Ǡ`7kLW`>;o7qgEƘu-vlmp _dl@|PkCjxQg/܃[$N"]ܐ LИyC\n(h=bLEk`P ZDPvre N5(&\)f̎ $ 72>OF^VAb`"TLӄat7E^gܷPom0ꆅ;_Rh;gD1YnF_)K;f$J0|f+0#@)_&9`󃞝Y~ߍ#i~MBhK+@?8X2+L]IMVaQŒ[uy-3"V \މRZP[s%e2yKkf~xG%]?֊Y@˙h\T `ªWLyb2њ)q35ᑋCZ), ;o)q"Q),!b4ЗW۰Xs{‡A3uDumcqb+;;)NI~ҭ23 (,ʇ t-ME.co\M%Np8D6*gN9} XѱoB UEN8ʹtx.lVqᷓDMY\l4 's0t)sid6:z+FsˇEDP$}j ښ3S TBz~j@$(vcMiʫU .#@2ig lWOFHIRF9fzi[i젓~EY/=Hn3~D'YRN!n FP8QKJѠۄ>WkdXGM. CPoxu}7yfUi5H Q<*i-kVDRO`,avDbL8q1ږ H;bziKN{d7BV֌HoҾ.HWDpQO^:S\4-)Է!Y 3XSsg3$[Wcs/?lOCOQ'CAf}l=0b*eBŰR vyszMj W]Z<awvwQaϝ[|Xwp;Pe7G (ޕEc@ 7ll´˗yc-Z޷"HRf{N>MP3ǀ#H ;uNh!7Ah`xא.b`D  ]O@'f0@D amܢ(]f}S )5@9: T@^^Y'lryVX8`+a)cE&)4^\hDZLG%UhAC\x2Q 骥L< aP̑)޹x!37I'Ah^aeXQ%L5iziZEH'ĪWϺ;q/s !Vv{_mgkS(cۦvt1*T Yo0DUQu%$gjt0n!n$rsFL}˳"ZBWG&Y? ޖj){,ˇpL)Q^PwoQn11p%l35"4@ 4#|Zd.iC^RЩhC`\DVo.ܑ '3nrDջL9n6ڋw8wp}/8|g~UguD\C 9tU쳻V(m30HGd)8z2KW-TLϿzήr-r4#af[" i١V]1X3)i[dfOjQ&quI/oiV}hB6 64d,0^Dz엔 } Yx=3D6]_˄"y<-p ! {(ϱ'Y%"6>\nWU0u#=q^LDVSpXgzeJI 'o8/ArӫN!gͪS[33|$6w-sm&vC;N+\L&£ݕ}SK"ˆ2|`I'I_|SnhGށS7\#Y*W~9njAVjp8DԒtHv3 b}l$1>Q۪2.M RL48gu8i;]/^VmNq;31!'j_bZ85جJCȯq;SW!KWi̦ }^1+]Qn3,2"C'+Q+5y| F'M:>y޼Ia&m( :axdoPBj"Fa\]~( L? C_gK `N6e*3fnd5I] &2BCP& h)MncH_t®|x[(@βS^/ `:&?{K b=;5+س0.6ɜb=l'3pSNC\Ipw !}ԙ51sw%'ygW\9dmOwu0ipts\ ` e37-i,vC*ӟ $O*?^,ɯ)ٔ??F'#Ow+W\:%r\4,pgNi?~l~;ͽΔ}o49ss54T\ILWh-f,TKezQr`zGaL:YET Ny ͔H{ OOUԖ䁖]e_2hm$+}izP4ЕQ3LH1n"߸! O˱UzdA>BYvb8h#ɕ`?ck&:g4ӗF U(z;`SgLwy$ VK'!4F ӫoW v2[I':yIT¸D3lי3m}ܯt\s 6f(`MmhV?O2(J& %h5YExވ/ДZz񑊓|I7lxm;_۲gc+n Y0kPBٸSy ^khU(iF`^(p0-,<eGMmɆ"N(&ܛȄ) ,z+0 GNhϢpAq}avЏ#u`88>Ƅ|@8 7UrSJtpMoL5f)W=ObzoLLbKӝ4w4VoB¦~~ŵ2%9//q50'ĶW~㍱v3P!3M5zJÁd" Ϋ}6?bd̺:U%|q8p2QD^M^Ꝛc mPJ ׄGv|V#N,cb; w@ Y9$15[@ tXRLz:w- KD-'TDfvOE\. =n]3.lh3C]:Qw,_ oG?{FNB,I+*hAbuHHXiLt?\p!u}հ],9T.婩b AR:p,BŹsVȼi*(IʘmD`a#|A5G+īqY mUN Qh,dڐ~f?T,e1W@w,j)APYv+WVT6 hư cnǭFDFK֎,S.d}4|O_%%s3dɽ ;#Թ-( HiNw.C'3nEi8쓋4UՁH_q.9 Ǭ?^|/@%zl`2`CsEjMnQ[t+i.WNBE4=^?YM[[}>5^r^?hÚNiZ=cr~؏׶|xӉZ} =fMe#|@յC4_N~H?O(R15!irޡn 4x[s|ϾwUE~/tKeTCa1ʥ4f)25y M޵g0Rb-7`^O"Ob5CP Nt p&&NuÁ1Hcslj+4\4EЧIvÝ ЩG*J) EmI+f; Q_C#HR\W9پ?6q]el͏Q7~U ʡi{YvirNIipU%D<)y c7~^Fj.nGSPF6@W8M 8_,IKV|GU:^^0(>,}?3h $6-YgAM9-ڶ$b+wXڝ{~Y+/&3dJj y,WzG謸ָdG!5thbf;NY"ҌlRz򓖛s ΐɁnyuP*c)Bߛv4pAo2SX`K^D%PI%qVObdf^E.1TbAp#jGDK4B6H]A, 9Lmdcݦ/7Nelٗ`7I&8 3w#h!|~Pہ `x(Ty4z̬r3ϻ4%6kAHLռæN{T-GO;h*?`eT4$BH]ǜHq-P O{"z2ύ c35PqJf#wrˈҋ_jO@x w],(`e=? @^&iCLϑsY&:c6v%C%/oxq˜DR}l-nLԩ+}&Vk 9pG8֬f] Lv%Ѕ Ԩa7;x .<$T_Xuϗpq櫱=c`G/ ة kkULL^)5~-2bBfJ(4,6 XZ_S^eͣbA}w}F< uy,&Cc8 QPQ:j;Es ;#6bǵ#6wg _z+ufI`#'_߯ʛIbxjrWO L0bo!zd. 0b3xsP͇w*F`gW| U%#CYbw(rT ;$ ⫀x3$fDnj4|F IAdȣ@BA秸 ifwƴAZ(#sXUV.6l|-rbk@ix6 \6h*w0e1(c Uda2:#AΖNFDQ 5ӄUE$Xnϱv_U[<$A۲{ꊀa⹫6JŽly:ui_c\vB2<@WaQ'aawWKa_'GDŮߜMkd܉fJ.zzhP%l.+."QX sw)N5@:۟PJkF[|hq@PR$9A!aHh|*I>TA⨓[e𧋙pIr.{G~ ƔƼÔMg:j'`7 kl-mt @99(D#k>ݚD=Jf8ES Q΋)d,ꞻDBK٩MH3DQ›Ӄs\U~+xzǾCZh~#\h/PGU8eP_&dGb]JV_pQ6(Kh$ϽYJs[et*)tX7pY9eNPLbH)%v$ÿ~7wŖkY  R7)eyuKwtQoLf;C)xEXc|bKXh{k|q9~ e3/`) $0X`5rp[EuT bJ&ȬE@yWOp8.6L`EXKևj8TneUfwj+4M:zg<lc78g+{ eg]ؕc= ,}:ҋ ɴuz=eؑey]ߏ-ˁ=zB,O\{L!.aV>NqKi5 Uԉk(il}!y(V*A"uRstf Ik>m0Lm, {cU_-ǴCdcBr [o7X$6o" 1ۡ^0 M]0̩(໅ (;Q錾xMD;N{aCѿ&2\^+v*؅\sQcFKcZH d76KNom _ !`z}Et(C#['n-M9fcoyp2eG"+um~źY~=Yz$ɫeב܌U {.ڤь(ۄ]w}Kvf)T~ܔ) s5ll[1 ZP$$vkw,^;{?^3hZlǘIU(b)=Yk#8Iށ?sYϠ7c35TGͲEّ2eZZ5  S "ڈ`"j֝ nbn'*\vOd`¬^,v /0;[sm3n6uٸYΥÄ>jQ{5bk"pp/؀4^nRgB8ufZcl7d  !ZKc iOq8w֘}{=aqk ֞۹M3\`Fo~럗_׍&﫸İƪڄȶ| R+mqEzb8C:ucFn]Hu1W<&wsRhuxn_)#b(aڕ9!A},E^Ak1̗xJT }#6~WlF{ds>E"mS! 4Uc&dR6_+m4׹ pO"|EېRz-9YuzSֵSmW8\kCl6#4zW^3!(! -50KLgP] wdmGc?G_@ Z(Hs9=wC957Ń#Jpn\3tqeHmUq%XndOW5;'r!كeJ'b LTBCs|;q PYޟ5Jae$_橯akYl;m0فp*K֛X݇TG \;j5{wJt:rS9L_6~Kz;}iPHUz+ٲ6(4m'z(Vs8wop+Ӌcmy ̎zQNx/Y*fS1H~F` X))XDrtLpwfnVe;>l2Gֹ%cfsf; ӕ ~="*_9-M$Mw4ohnDLK LK2rӀx=^s:TR]ͤ@OH oneGvjנ>嫸@Z˒IZ|.[$pR<[A&f_j:\S ̎g58}M\c&(OzY>b9? aHO+#odCiQބl-jPݝyK*h8- GFB7vS 3QDkٝpcý3H8,זBaoNv}'>ՂP ,y]MH%mX`{5 'P%ILb3Xs3i KШUw7OUs;&978Ƃz7LjӮxZ\af7u,p|1VVc[+ $M#$% Kİz&&KTՓЯXn[| fqFp*Q?e#rj!D(( ֐Jl|j/|0H D,ᢎ'S9g ]lz ,A1))#hx[donm[%] L-+dK󨂗ΧsY9Iξ wۥaѠ"}ZACioZ-ڹLP5շ:XC&_d~(K$~p=c*Gw*B 8֏:ՓK( ~y4/]>:@)X0 RcI%j"qr)ys.]e&dhd>=B*f\d](HЛ{9W>JY=w:fܦ[k:#U4wgVll9]h*m'ykϒ YbDaVF y[Vnl P3GPc=zΌV~4LI`]Hpw: r=rPDas%+Rw#ij 9܂Ѱ\$URt[s-"fH!fZ-gsk&نR suW̟m16vk6nZBRb+$?Y!PxZ d f8{n]E#=C7 EQȃƮĜ>ct2yCRP{7 N) {|D||ܶ 8ɟ\>!K6 $oX z;{ӗ59@\h$Tx޺%Jˊ!}E$E4gk!v4sf 8T$%(e B10.6b- 8n CQ6'f/8BۣNЭ?#O.r\34hFvЇez0 3rU+cN˼X&O0d^7aˆ #:Y/CAq;3CLBRWCtҖe9>ޑ՞3 ZHfaf0"*rYW#r2JbE]]?n.׺( 0V9tGSO&fF-sDagDZD:J܄nkY89y^ :Js܀X_H!9Hk=5ub1.a>j] "<y? z0k j#|}w]ZU(yN~B%$&HDs$P|΍iq2(+Rm&\Nʙy}-^^9j/ZTsK?QuFBPt#T1ܢ\RA1,h=õi[wefϿNA̲zJq-u^X|f8L0 ;Vs}x)LM.s_ qjHR:P}:0JK٣P5Zjf3wqkK7 [FB" @fl+?$S# M_53}HUoZ:u G&^|;D@dsDF<ǂb8x)C;|%G2QhI "j(~F=mp^.x1Bi&)U'$=hn@Q]}8b{>3 к`_Fci?WalaɚPO7}q<щxxC!{i] #^_K7?$@t> HАLm6cmkThRxqI.ROMԍFWç0<@5-Zvjd N ~״b&/':|?55@Ԛ.-[K9nª1uSKn dZrhsJl)˱נeCf% %6"߉*VUeoc:mńD3L 49jfv\w,ޘ=l1'nQɆOhQeA' }'yϗLoxwiL?-3T(hez>EM&YOj_i)1{u9n12Ғ/V|[yb ^T쉹TlD*T/*dzbyky򌾓3j$26?#0jzgkh:+rj1`#k/ŗGu#: c@q먀4D*7ANT/.|ŝ4<ԺwghVw~+C \y%%%,f+lYJ@ OS':4ZTf +*FNy{ZVhv8ۓq\tqtTfl?%_6I^FL慯7]cAb3?! [F )3qlPIػE!Vz DhZ@"iߺ5- =9m/¼7ڭw5ZWt"vi{oXHas![Tъ!"J5\`\M +GRTGq4~W_hʖoeeGڛ27ܖ*-#?2_ DE7uI^}E/[K}9IV2g!cFiO#n_ @sQ`y\{%+T\-.MRCS %]d[1CNviEY_:08 bqFu /4]uz̷;uVDnQ?āxeW#`?MO(7Y!|c,Q|ip3ߊ0FY-LD-G9Ӓ` fhb :oלk-gtȴXz8,`ƨ'&rJ*W~:`C5Š4j|&hYx1 ٴA79Xrvh#ty/vGx4tEm CW 'T=0ruڮeHT^БAexMđ(l3Fm__1./]Lr/WONdE7GGl1MV1ĉ *KUDP=T|I ̴>E(6NVņ%bY` ̿޽wNFށAX΅=x0IK/*,9SĶYn^[ԾVKZGh%4rdv'_+6whBr[{ Ý|Cr8z.;x'5\$]lʩ7 }x% >BzIb}?km!rǔF$پ [twvM;[H%H?W 2%HB6-vuPr/i bUdcBT/M f63GDuޅoq; lb sȾ8y4W9޶[fxK +~ũJ$GMaկ[1`!\|漅-Xi!dq(TK$m@Ks:%}O|o2szڍ"吡[!vԾe_i˒40؟;hG͙G[O`K"߃5H.Z2:5 i~#9PS3t62~jSY/}YuȘf\xIjmkiVY;Rw|pI; `8dz`K}EoմXA1qD {V?/א,`3W#(N}ʙˊ`WybY 5Лh2voYÒLHECHZa)8ҳU5Gi??pmH1:a] .iت mgWONDq_@:BtFwY7l᪯yS&j-\vWr,:]--JmIN˺h9?hAk%sw54dW.fRÞkV->db$ߕ[C2D0Fiٰt1<5L~>Q䞵?=bi.@'(['b#&o$Ch5?TTy0{ma 3GnMsK.$_&7&v7 ɞhAoW[HΤw0 }M9)@ :F%q3IpDWs/1y o.W: 23~} PHS^&e>U>?\zR? ѻ8wAq= j䔄ԥ/kG~ߟ4qk8;]@ Q<ŋ m1oIBz ܃Rm6[Cci" s*$TLt]r&+7g7a,8(sHRuM n965Eᆐzm;g(_i <ֺb 9]z3*4q)>dRY<+X(B<=$|0§DHi.^l/ D4yDw rBksQشg+k6Ӆ$Jč\*e04'@SR5Xx,Hh ]^<ρhyVH5^_dۣ%5T lW-2I<#8+|!L*ܙʞWƸ珸ns_ Qc->tܠUސjɣ^xz+H}=+|+a[7l7U[->:Bt8qYu`vYf3&?зSme>m}F(m~G,}G,fn4 y%Tv:SlEh?[RByt.B3H}ҫJ n,^U)v,պ 0hDgdINzjd;:K'קSrS 2FqI5S/`$?Kw;Wٓ]jAY@cwƈ`>5OBGDOX39>; @w5gu`ɟGw֚LaNHǨ9~5݃#-߼4vRg86HIM 7#8n cY9],]v-12zaEn&D?kO`,Ft_ {j@>XydutT)\ZD+W"ukްtf>Fjx= t۵

vW3G7,Xz՘Y0(b&^[:fyu`{Zd]-->x |K9seh(xDCwd<1yZ҆iqyr>Ej:R$yG^྄C"EJ,f z>si9V{% <'*Y C6֤?Q"2M ,cloZ+w dY`O=TѝGClwk7M̀O:,&38>d1W?LVA]e-K_B-6#Oo~noՕ2\@P!`m{Ѻo}1a/Y٘yre"ܛQo'iu>+אZM6KbuKr]]`Ѷq0xf%A˪{(v:^Pw41Alƒ~T UijzE;l#,>#Az/ ˋ9 /i 1\}'5$p@ODмșRҮܪ)I PrV)pDf"ilWb:2C1xts@Kˈ) խM{ C~";n|뜼>B۳(-؆l'=! q]>%&VNƒ+&[*6م NɳSS$_GE%@fw1,n#%lZvH >HNscrxpN4"#2e"xselr8f"kzaMxw.CHvFa`2jVrNC ">c?J9.\e VO(K !I찇.W-ȭùA{=YSL Ql};$aDM9tMpʪi.Hu\=#DfQӁyQN**~hc)Fwj35ROPn,ٮEXuwP[q%K"?3fV/KsfUeFcz`<;!&%Uhc&w6 \O|P WJ Σ5ULF_6cfqNp<lJ,hJoㄱ 9Ó_~Rۆotm QՔr"\,[CՍegwܷ7#3tђse~p[Ḻ^ԟiOwl<1d\uO co%DHKJBx)A$i4uʎn ic>0Oܵv$Z'*AÛU Z 3PSMkBb^B[%JP@V}J9^8d  z)_U\/huĂ9dth&N aW )Ie~nLUg] ?]w aT)jݵal2oѠ AVv"!kR4r5\Љ>wAq]2'1=]!$$'o"cSmtnnHRnMSd{s%x%5刌{uSr`4-. q.%o[|hR|-)!| 8JUgLp& tN]̰{,[Ċ!Pʯ@#44 fg2Z;QzB]dM`D?'Y=F]2g0 '>"Y Lov8 `ѵg"XC\'YΒcBQy\_8jcttlrM_zal3ΩHȫ\J,¿Œ.9~# yoIW_M߾/FJ)5 *w`9`He/ ?,('|4, 8Jpmo%a .rTG91_Q$S<}p҇?,G~idD1s%7Άȁ !Rc"zǾbX)^#x0w6M$nsw2 !pcD2.Iu]+L 1-ޡ%1N4&7KU!<W0`sphv (q '4zLHwu|.+Pf'nmd3P=ȷbyHB(%hdchR܋“u@ :NB+h'-=e}Gव(Ye2)L4?kYZfh\8_~NWPH$+놨,L&͂O5R5 qɖ-mgCJ,~P\2->#c'3eEzU]$J3,QrRdȜ螚?r~%?8@ ,!V-vj◤8-g! 9eQ7D1:!t AFRʷN[=#-p,xX,m4ʑzIBfNgZ^-hQXIp&%ޜNj@,U>yI訲r)v^`1 U}`wy@#vN&``2=yXFj-m?(0?`#g2V7 c>r/);3v⾚ 8}#-Zyd+aR*!Wu.R0JD viNֆȟ݁@)lb+ځ%az(FyhY#}7ƐW²Tr,W~Ÿ&l,%RcFdD߭m*r1J40j^|%~I&t0~pQewcܫܚFcJe"02|f"AOy_|GߓK(Ew"\:e6 @yd衎( _ r~^칚K`~Yςm}TnsjA@b{i%[&@< ڃO=~ekvPw[&I+PXؕ?0$}/z'H뾊|kDZ*mmG ЁP-+]:`a_3ܐ NC~NZ!n'+'EZӍ=Z3Ǘ-"Цt wqO:k{(Ǐ~1#S]t 0NwBJ) _'ϛ;p)K!9:vtH~(y{cǭZ|ݳ(t noWþLKKjz `: +w8᧩2i7TMjœ?Ew/)OvoYf5]|dt DtzΦ0)"?d2uD@ZM8aVH}ϞLdmp cSFӞ?[R5?<" M}8[9a 9*8GYG.c,5 S-a /٨33$ tFő#sc^(q3M"Ҕ@i4t/?}P DT5m|j( pLarS$42OO];,6> r+ʦr]G* Tg2(ꎉtR3}ti9]gNI}2&ƙ7A?#+'nXd$xY\\37~-Ob;jbϣ35L˯̈ lwUiҺd#1m‸nRQ0nJoPx:{dc7unʊ n 遻 'xKHb@4փr{N }SZQxjs#ASK`,, QQP aQ\2 b S#}!/SV O[6T||-H%.MXz61a}lmnwP5v^YD و4V7LvDĖSzETi%iD ߓԨׇrTbᜢD+eREjXa;̎Y^g9gfX5c-.P˚ExK7 4Rq~Z&VjޘC` B^sԷ Ia‚ECJO20FCwy^{[g|!]H7rX{ +*Wn!D%90)xfBbH̽dgdbo z.%`LyxGE}۔g#ɜV̿!*'䑰?pD6 ٫OX6'ېY{UO8*TeqPlYtQiuu*h]$K|eS 'Dh$Q \, ye١j{-{,4H`ĂkǭlA9.0 )ʣ{FuCI@߅U^,RK۸ܐ~D@ KSA.${I#oȘ-*P#t)ގVٴk,ΰlzp4w덑_5+W~fUH2F6dzVZc~NG-LCM8L]"a Y.96ΎJhy#9JQP /p63~QEgSK~R#PԽԈ/AA=\gT8p ɱSmL)OE6 Wc6ϔYUX:/tֽI Jr5s7}Y .T0lY#<@69B̈(zmd8y졤^&YR59N"尨,*ۭXEɏȮ[oE4-`ɴUM5<y.1VPIt7]vNh3jClv1d{֟ lr},8Y NDt_mj{8yb?=EE2l4kz,`?EAu0^ƚmc<̀fC1aW}eX6_p^Z9nz;mRuNV<4*_ޭu6S8gE1ERͶrPƌ%>^߼l!4X(p0Lo!#V*%%xG{|w42LG-iP1'Qtd8knvR2\8]Kta,"6W-zOxA6ԋYݗ}pH۸jj#<7wXo7 %/Ǜ|X߯L43J͚A1üFH.'t5Z.qD9ܿ$նtm%LkXOE1s>* =ZbDcM]A_:;:8S7OV8b^)m: X CEZ˸ #KguUpi)3["lkh&{4 2<# вW62P]HѼS}d}@&&XdWw4]!6U}rWN'RCC"uf3_GKOA8示UʍaW#A˷dURB'\'ɈSRѣ1ݎڵqerx{:z)oj*#mw{3̋GBv܁g=~D< ުgFD>kS'9@~c׼cy˦TRy ]/W\s3,nPHVȗHb5N]%s޷48K0 ڈ[LY%0FJa* g?q'9~¼P,CH=F3aP~)G%J1O0* +qQOYg7A ^B&U8M.iX1H *d sؙ"K&6B炸{I5H2Wx3PNmqV~D)-eYQrN@:$CSe3]+56y:T.} 1NTf FI8\f^F/ܧ31!YŽ 5՛6}c1' 㚓VEn{a8(MxS FӜ % LMrWr89Mv21^ЂfGH}ƅ!^G >5{} 4n ̊5P<9@315^Uc^:r(SoȨ;~DoP^II@ո`3' 3"N_@W"oC}ڼT: fd~5:A-(\{wk1ß8NZJUP$A[!:iਜzق̢tuQ ;Elc9 ~~9)K~Qz7.Nُ%TgH# "p q*_U=gv5\vnAGT{ņ|`3Vo]☎}QGw"2=9'@OlojKñBp5C!Ned̙^E3ID(NU&qN{H(a;`Lźkb<ĉv]ѹ;%etL!b'ɿ}1!()m"%el%n4(y‚ZH(rɦ4 ՚[>|> iXSF ?3M[ srGQ,2-J.2#},͚)}'XdHo3U |l"֣Orذ]o?ܼ&0w L~ks'cU%za*6NLYr7.PNb48 =5GRe;O[ͦYwRߩ9ԧaFќ!E 2{xQcDKK O;>52IOȰVpOL~4zL!(dnlm_nT=ص1 נ{¸.bP}/fT{Ƽ5\.|e$~r~:ה8@eHq7G+4z()zu˳ݏN; BqB1/sN0ftr[S8rS c? 'R/^8LdECVq hN*ZN& qqعlG.}=+MkrEg>C g 5\ATt$.q 4:6f+cprYeƤY !>$s|9fw.j$3S%x|dXZW[ x-..tt6kC31TFYAaQR?Yo[ ɋ߀( )0Pi(iw>{J֬E,.dK[= 99fKI-I:z 5А͛[|Lu#rГY͉>W=:[skaSbCoL$h=`@;؄9kLEְ [;ˇn;<$_cz (N E8Fy4R=%ulaQ†`|=xnA1LA]II^EAeU['pGy*jyX^CEi{gr5 m"L[ƶeqE ZlT{/4n;.pvlشŦ ɺ{нb-g›x!|ۊ!EC~\'*ﮑO!p}` ja^qz~- ֚ay|$@ĕƙ4p3v1E.q$F-א$_,ŀV6!hy TV`N/EMhc5rb)4OR*.{E jzri Tru9';ۅ.O8nJD(D =fpkctߢ.Od_spطX]]8}͞MmW죀" ))G $.RqASBRIcx^1q, S~B1 %lfdCOQI?&P[j%Ǎ7 ];; O Ps{ ̉S[I'weq '^eS0t_;d*{H{ρ18? F eА@ zJPvϣoV>56:rHYm~@ZBmj>hHq3y #NOAo2B%$?bFAG?/'1B:p̳%񍐓 ==6 q;Hj%}-lCǞ3ـIƿ?\!0=\mYBHS$=0.E9ዞd?)un2"WKxP5{g44xRxk07&EIйqIwm`z!._0 .P11Nj]"}Sƅm݂]^s!FuHC$,er34LkC2K AQTTU!ѥ3uR^4GpC|E*kt?S{(4kac5qxlʫҀ2@ BB{u0#0-fc.%~zk-AIFl)D?` HDAi .ណn|wL6O-kI |!(Сq"Ѓie9?$N}~O^ԟE_Վ-J>r]X`kИ䃻SF"_A:NuGq<9.zM K#M .>S+哽;y04uʦYcU[`O=cZ3Ѥ?~fA` -mYrLƇ%/l: :zZt$)5g `lO 9hGhUMQ'E:Pj5Bƃ>|؝>pR%w_}/!vns%՞\EW-dW,wIJgw]Ŕ{Kz\;7k!z +8謸-W>Kb`; *wzrMҸcC{]A@ɶm8W_˲>5䊾m`;>ԋ+uB$M1`g}IFMaWRhz(b<Rn{?F'c CYBY:? Q^rF][]f Š@xkFу.C7\3:\G[ї̈(Bd n~K^Cw_5O"ϗ+*B&-닿Pj8b%sdɁ$ !)fX4~:p{Dpf/E^j[O5gSM&ﵕA4j&c3w"xLk[;]Lx뀀bs\~\g z~c| #F4r/'$ Gq]2Moh E%i=I K0NQH=}ҮZA!e}ŕB.̧!n~mBWAb ]@9`0 z"7G{xͫ3~WOw8PvVdIў@9lKȢY+iiYi8 fžw@(mUoR֭A;c7۳bL(!sW QO1]]fw,4̍dp[Yy*UG6Z/BC&7MXSO̖p#{X@iCrYyt29{{mFhL>FG0S^蓰mc Q&PH{NU MQNܖ\{gY'MM[_6v,@{xL78?LH|A-.=׻$=_0䛌s;CIUu$i"5wC~:VC+(Ľ1\<=-ެIu*@:d af/"AV` %Bͺ ,ܳ" X{]d5/bbB~<@ɍ>\VAcҸ(CY` SnIPzI1^E_ɞQ#:A7{o]N1`(]%WppYH>ްG:RSgP}k;vUH^=2(r{ B%aw,^:nc aHp֧"O#.i^@=|7+q"6v"\ho#I->E.Q֎RrE$kj -nj^CpH~V{vy[  +^LOʹ/kB[◛1*ROgv@(DM~hY_"O#$,+B]ON) Zm$m[z8:.H3sNs 4Ҧ7*;KW|'2T rpΉ:uC%a59k(a (}"!hYGݞʿ)ͱn9[[hTlĔ,-f ~أ";*/^lap @*kmehQݎOOTu'?<:M.X%gZsD96X#~d1Vq0Ā2M%OXJ54K9. cp8Nj +jr,re` gA|FQ2lnN/_t+uMxUXs2e 8q@~p*'YYZ/!3N+O`~/ a4Z#сO{L!&ML'xJ= 5v_7 jODD74B8+ q^f.Xw omei̓X?ƞe^8+rÒɱq+v?!0¸8onU fd9i@A^Ն#+Ãĥ Y=\/$T1{sʕY30J]y) I}*N'W8@K10-Np'?ӯ@ ڹ?g=4ǂJKowU|wà)]y_f+Moh4˃8究7 ZHtxo ae;7dW\Od)HN 3Y̖9% LNKh!SaÖ5IxB2N+cb=-ޝQZ2aO3kn9SK>Â|Ecn(G@Zve]#)%:{r>|!kc:8P->%O|7'Ts= S{&$1kP>x*tL ]GeV>o~'Ĭ|7˥hM猄Wk}΃ٙ&ֽ̅ܠN|x?ƅT.Ƕ< 3DQ.@7k53&e?/ Qq4s1S|E*" ݒj+9+`kkyijGedFj+s@3ןFsƞb{.׈S權2[eePd8 ʹ:9ߕr|sGXwwQY*^OugabԖ*Q.{E/΂􆣿|?ю$ ?w0mp .jեzd*~l`" ;M:L#$hs8Gi.xTBGËP8vbˣŒT?U`JNFQ9-Gy޶Q]a[Y\Ι>|k]Y ~k@ S}bV0aU5 ?vug[g%&M0X x(ώKU`nO*hV>;[`j'ߡ]Gt0uR:'k=uVu&ƈi-ֺG~DV |JI5,j Z"CC۳Nl=n`ۗ /i`K|$gB/-Ƹ?ϝ$W;J)w'qH}_({W&k1l:_*p;֞|2rP 42fGߧc"C\ؽ^@0uT4jqFJ4F|/l!ؐ"ΡIpѪ*B5捡1o,ivzc0zL&9_&#@CDO\yc :}S&.##,!@F7$-|SӬ^6^o045kpl(GE0B.dL΂=3rc6tȭ @9^dQ$ENBދW=E#Z3Ӡ{ab8jK:o,'($mCa%*6KCFL9f@wO6C ~i4ֈQ{zy! D;3 `*7ZXKgP@<@}Gmr x僧PFsBb7-Q/7y켭Zyy2CFvM/9u-_[ܗ X|cA&Yj ҳ%+Qy! oub(<ē-I6&iٟ@mN A!{ - ȮcjwYLK#D%֖㫲ppPC|f6 #_^Q:f:F✝uRhv86HT {&_ύ't {r(ѕ(a""[06ҭqܝ-u`eLꛩ'Kj;ӭ;LOrҺl ah[("n\0\AZ1g!XF2I\ Ĭ:JA'NʵkXdK8*EPUFzYPuf{ۂ @XRTl#S,%QLc)8_of܇\fS@-Ki]`_ ԁ+ ;:E,vN(G#'OQlR$^N%%ŵ.M".3I5CpPX\g<ax?J`V6{{$s&JϟR׿N n!@U\67q}Z6ث(dǹdh6,MYhbn IA٨wXPdFYsnܷ=:r6o-I_ldAqg|Xؽ BytS Ge FM9[c( E֩B!I\T@!i?湈bIVRf00L[sG||Yix9i7 NscdwaOJ%BYO|uӧT<&"_WJfIЂvc=JŴ*2=dw_OL4 7h,BH"'lX5~`af@LG7dXnX"oX0dͺ+N*!Ιu|RW Y1S[ ' 55U`5zEaN!*RԐ. I3zDdӠq4*^!9^Vqc2(1=f$MGs?UcX:Aq!rt(s<!֕̾jmٵ/A-\_>ƚp[aAL0\0١ڮvʒ*/~IY>lS>.<'F=nleA1!lBV )YY &fn^h:Y%Ɵ2p&FL(CJJcCkX+`n%yȹp<~đ[IlvK_@Z|Li/V, ^e*R=)KlM4<B%GwqA])>U*H xBǒiLviϪe٨ RS " C@+9Lk ,.SFLQ9ғކ&rqq؃4V0ZCez_>KuqՈ*֜Mڗ8 W>\(A} r=PeٛovvF(t(asT{"Y`FӔR=fvX S8Ywtgh(mVgJueMLI̲nz'#V~cDStP8\˞/Z;xLe~PlHѮ"cECR(Qrrnw-@ i/ZjxNRM-Tm22`&Sh'Akۆ- , V!؍1uvR^O:1QP%۫|T G pGw=;X`s ]pX 5di5+ȇ`5W9y Y![q `@n-d&S` ^"Ȁ13%>B`tV@bKu hOi?p,i;o(w>ҳ1-Wl.llXSo<&C}1 x,᥈jcr?wI[C&ұXv0R>‰Lh1 ~i V Q2s0g+rXkq s!VX=֌Ώ栔5'`ݪbnW%\R%x"T$ցCH1¸_Nvpr# ȕU+hXhO-?t`p׷);0SgdWe6hl5׹QtPoB2ƦQ,+85l[V2D^qԚr)+|6/1BY=Ӧ ~^Nc#lp1J›0x7gw^'_.]e ކ}~x̓ (WB˜ 4(OyTHeuؼ<F]6[eB/+n` AdT5|-UG.[FF4i2"ҷU0A|-Gג&Ubx24: 6Ux5p"q+,¤RXp#"06 m!`0q.:Ar|wl(ԹqU楟 ~d+os;ra)X#o,s.n`f\ ,¡A vZэrD3_`o㝜VtKr7 Jl]KGzU&EGq.V:_z*FVFahN]&` &m *=*TdnowHVfp" '^T?Yo ӽHulA M4 .d:CHeW2&ŶLne%}L~إ(z %{g.Y{_ 3ğ^!+E^RW@)DuyVJo$HlLDBf^xOzxrA~ņV?o?T_=Bi57xCfIM᧥7EZ.%=H!_YrH,'ȳ $)c WǨ!1>J#6ފƋEFS) up+@kHTRR _T<%(&"ftOnQ/ R u GB lML)1̸ ۮOV"(4iAo+ f`1(O\5CLi&߶xG4z%Mv4GзXnzxIaDr% Vsj@U]xzbLK@%}n7i h.P)fenJ!>MC/rUӘJ":b~չRMy&y[3.bE0/T'ە-64DY~M0X6SD]zu6!3UV;uRΦH> G4&ݿQ%E〨!s5Z\]C˃oIa㿐gr.|Fp H4~#ˆ)-N51)4t$m"˛jq&0 Aji#9`˖$⯒gSO/pnR۝Xs[ѰȤ埡Z+qsxFI A)spO8unY1a)bVw.?CLJ&/3D=AiIxN: Ga\L9?!Ђ(vcq lr (f,JA\%%_zڅ ]'+QY5YGdVQ+˜ԡ6=&RD_$;iEWa sQ=e @õ%e Wp%7LWe-8FA<(|dh  3EAA(&> YWYt(.x7a%,eճi›x|Z)Tky1ZaJ"|M r)m|j@ vY-E{ v?7'qpVOǍefNB-}=C](S'OQh^Fv#Nlhh)fכKe; k݌-yZ"QVf|h_4^X؟$&*XZ'-stqCafG80 k|^;|-,#?:.B̓[AMZODɨ"j{hZO[yal9 `A.}}8'`3ɾfE#! p=12.Lr6 Q9CEFU}UhjXr8Ž$kA|Xu`چxHZ<Bz>eJck!ؙoGi2dqZ~${s(oCB&,bdl`3_EĤFٽ:WӗR:T+\hxw!ҁDڷճ6$GsHb@KR W@H<7 F[Ka4tŬWFB (dkẽ3rsXdiċw?6$ CԪlՙ㹄aSbؑikLꝤB9s2aۉEr f2; v w 7upna7SΉLpE_-bJ_r6`A5SC齔测:Ł˹[0 Gw }1ZA}+>jX~g~ۃ7?6 ;W=Ie,ATHk'xaaRyw8S:n89 .JC#k,OU.6| OE'g FW0ޔe`/Z"D[ɟydocL?gi*c[(TXT0-Z?(fN9?]P1"BFC\˳,m\,$LFiy$ll}so6`\Â:pЫod|<Hw3Bl^fO3)3m&*z:KEٮO:B.FbMQܞ^2Lxj@2`ӄ>0-L¼G`KyN t =a&/X-ɍchFOEYt/udfK(HՕ6Z2*P_)un.Ø[ 1ؠоt "ta.̔S/?zhpWk~g$ ^j&mWs3 kܩSnpD"kMU6WF{ */nzr7 HQ$VNlj)t, M[MgޮfCM㬢nИV~ᒇ맿M'%]mES]W_"\. ښGQq p!ˡ҆QCwnݖV1t=E:zf Q} h6tkNL?0tZQfXi$BZ!1+H<)ongXGqD&9 ţoʨ >LFݢ8~NX5P7(LdvaZ9(ժ\X,hma (]"x N;U&D+wd|ET2}?uw'7̵Y )iH  V.eýKq?XsT3ERpcLRnAh-6*%2~u wF1_ BNèk<1"fj07l4RN+CSVwLﴕkt[z_72ޚNBf1],V*[9M4/cthoGvĿZ&⥊7e ?aR&LẗY2%9)Nśt] (o6GbyӬ=oJB Iy]\HKQPidt@xR:X6KZmx(31fůJ!ˉѡh^Sy -sR7KŭF4 533f̩O 5,{Fķy@s3浿nDA)l\gǣ1F1g)}Egm٤AqnFr~6 c@QHpp5z3Ρ.Upcs?.LXaxerQ Șn, udH?E. )׭s'ޝgy u\&5PynD%TŢǂkQ;e5AK}X?tfi >bM628P_U4%zIiWFtO7i>PQ^<2]L:i66to?B?k9[wm\߭@L[ -,97dF^li];/ ~huIXЉA|Bpb{44+y.M#Qb>,V(F8u9fFABd!zrZS8 F?S hbcWImVw)BD*]Apۚ 2d|Rh^zj&/XħbBhu~{̰ O="} n׏w4Gw)+\ևjXKK`a! /d|ר.o}[H}+xry_~O5X(YX(QlaFU|z.k&}Q= Q Ya7/!%"jr3JU.{l1BNOv*r,6TFA̸lJ:TXs@b7P6FMvyU.z2ЦW_^DwG6߮o4a tlAPн5cR` -ʺ\RyEkC'?<?n;qeۅUѨGW3p @SH^+(! tF1yO 8^- sBHSkҙߟ8AօT, O!j()zDuTEv{('zJnc&MRH>1<-!Q'=}JKD"Vc4ȤLs0X7#M U=ga1Xihaeti܄I=R:hڼlޘ=Abs3JϏu8 gvnmGx%Nc vvP>BL/Υo{fGBRk]Xnl.qۼ#I;e|[eU,Q{Wȇ+kbZ366udL0#\+iHrayT ;oVo@X \K䠊4Ds/VvT$x}Nw-> “pmxxpVbrzߔΠVef;m`9a18%߯|g|@"AL;uy8&4)6cj=DxhH^h@j > ڝM̆>Lgࢀ{eV<+'1k}W U|ϯLKJ64Oߢ'ѓMEZJGklYW8n`vWYYU:ˉz;So/Br>G@ᨀK|^Ž([`.9|Z P[r{b!?4mӻ'/ͧiAGQ]s11x*I Q/x;yf fF8C|y#ccbNkO'Y&$TL2 WB O jKgR1=U4Wv}uWx[f&_B\I Afy"uxpn E{Sپ'οgpWʓ٪Y2"5L4:6ip=Tq@A_8CZ ^x7 1}/#5yǷS{4y!x …_$B19f\Qj:^%@6]_ *r<=G_wMv$TB0^F ,{gL.,<fцC?"dU^Ejc{ Q~̖'yYxh+TlO4;hH?]862ѕfDmQi@r 8 ̵<}8ܲHh?dh\w oKiNf˰e!wDh/8EVgal f)d4y[,pZxEQB3춉eDbێRKtJL76&g3X,>F0Et /8D)q?X1Teq_W4po m{od)GqYXxƬ<FW-dT:"~)XYV=7@9٦ߖCk(15m3/?M?׵0O5\G. Y^7xk//f̅ʐ6: }:3z)سm+Y*z1PZԆϬ*w bˮw|nEL4s`qry#O񿕓^t;mLQ%^`7# KͩսhoXuÕ2LA:YBBB"G}ҨІM5E~""m 5  7W-,oͺ7d#{5ߛx4g/dX jHQeڸł? 9,Iy)WFQͣcw`yusr䜚5I5=%f9,zݶ o4 KL-*)NoJYn(z s3؝vX/v3E&}i'DNج#hzGxf[6'Kp3"b-pF%ssGB9Ïs]~':e!e୎*dFyWf% '3W:3X%gnj7#=+hۿdV$-`y~9CZ!T*1 Y~ODEo ,{[C? 㩣812}J\_`*=d U9b* ut'~''w^A6tn`+)ESCӪn`3ӗ[nCR'%_9%_إ WB">|>JNS<8=[x}up @ydQ||CŤ`dD4ϼH>7Q$!0n.,ndM"c:#uޖ~_p  l5UkVc (vH_ISrgĝٽ0K#^3_6ّ{x\)ɓE6{Ho]15ڡb9^[.ߤ,o~} \ۋR֤]Uof]]?6 ;gF&8%:}vGSm;]#bȇ&:hYJ3"~>-OlnNvCrZ?pXCSl9X&X!Ӥ>޽h5LCȟ=C>)t'E6fHF /{ ~zD^-ncFEB%x Z$fk3 2XЛ=-^hbK0EUN5Nn %":W `GY[@1,'{N6>FFd5c"ޤjυQ E/Spk*)nV Q_81+k;\cln$sgEXiռR@뫧ڤ x1ƴOSSe!=]h-~0)JYYG?vs3F 8xa0w,\Gٗ:ShK1ΐLCZ9rKE,A쟧l9bL+-JexWD>*!\{. )7 'G䈢$|y ȿvG9}^sh::Y]C9ӈ;.bqp{P3`iH(fNZ k7QSHrZ5;Y\ #MvA &Oؽ/h\ xK6Zv>MbD;۔ 'a&o ޶)$əE<|@f:Fm`fckj'f?EOA_ Zu ;H]}A#ٚvgnbf)@h؏{=gvZ@F_Գ,p#׏"e>VLLj9|q(k2^XqV@2Twe-Mm'E^56!" aFZ^HHtgIX[#ƏJzqYzrOns. (l`Tn8 ģ Y1Vc@1fI#]L]-mK $JH@sIz`Usb⚎K^>R|>-#nm~b#">?phgMO2= J#.OxznJB5}$dXh;s sk+(T)D\O/`_7 |V_(Y$}dԄ2tU 6]sͷ AMr~0AA؃SKM|w󡵳(rl@z '2 ܽ{bfz nҊXwQF=hjC[2LoL@KW4x ]馢te2ZمG2i 9ԂJTo/qxNϥOD bM'^=y_dKbkzOR+?_M ^XO)H*w*|4X9of:]t?t-S:(ahz!+R9[ b!#Aou* Sz{a+Z_^,M=!g0>ϋTi[gxM,oNlq"yEFnaQ/hP:"aNkh25'7ǾT^7I-{|q~+e*kKB3j_`S6eԌ`l*8fBvf}jMgҩܣ(v$elލH:XMˍhTP5 RgS٪)N\6CG9npdžS!%?KɘGqaҙĽz37a&%d[ז +C`moej$RLBB` iTOErƝ`ŋb1KIh:kI1ToSX|+tD?r͗D-ŔFfE)誫l"mG"C5!wVq8 A>%K"=O5ދ߮Tqd>]Pspx! )ɋcU`.L,Ayʀ;ʔmECB ~ŹErZLyk=/ ƻ |m>7L[ͷ9HG{M;,+`"m~%{<=)UZk2mxY %7 p O]i@{!cZ9Ql>܆q9#orD\nPW2#hv@E8 4ԧ/7YLC]yj#"5 9JI7@NX?ʼntXu~ Ap+5%d)BjsvF}quEvݬwhLK^ZiD@8i>f|QPwQ_Qj FEIQu@]+ j"+r,:oqz쏵 ezL`k|L,ߊiCKJp'j]i§J|oI `bm+9btL|q)RmH<NMrn9Hx+-V$,vbƜP1Qp D #3ȓ6aE?=&YxD> ֏F?Ԗ!܈:QJ2֯.B^/r!/~g-̴B bsA{ r0-hinH}/6-ʯNjhZͩ?_] lDS=fY;i5+ z`t;:Xxwm:wbAQvɐ=*'1DHX,/ `>qêoAR41bE!b-M-vj,GmQ- u@7g XIitEpjDѤB]'ُ2_?zdxùʇ!HNCXt83kဍ^o~g-f![b3=A_]{ 6Nv!mIFB.ɾ?M|GmxOsf&Y97e"+ʫj)D9KaQGz!<40"Nuȯ9oP0(`ޟgΤGG5dU sp)*ȧ]uII/_0Ē  }E>AgGG.*{g S/9HygF0W)ް!X֩k?vh7iOwJ͞=XYԐ;,t$ (x-qTޗB`ȷ[BѴ]S7ò%&VTM)8+Sfp,9{ߣ&K6ywWn  W&4qMIgW3A|AmÕ.`a&>>Ak0cљ͛hVk,'͕.ld'Kڗ7b\lx]MQDݧHޖv|0Ľ#.oBb,PמVY ۣĿQH+usZ>k)^n&W:NâdE#["bj'qCHb|WRSrppAId80W'Aԧ!Fv ڱWv c!C () aN쥼Z^?V`tz既B҃#J=~'lƊ]\z+/詻{hB%9@5'qQ-*n|U}=cB&DF_ŪKaj,DR?iWWy`C};{YGB!2/;ܩ=J"7B!QP|K^,hf&7XbPTabjf EXNQQ4b;0+%\7|*;DX3Ѐ[Y5&Ikњ'+vݖ|bgbxј5ljͽќ,݈ܧ)6OAD $ -^EGpy~>Chk~i 9ˏK$ ^1!F$KDLfa8F>_|M?gڝdAu EUA40^\߆$ySLhɩq7nl$MO|k$Lڙ^yWR&{ꚑu9f$!+)ȝŴ|Z}=;r3PVߠf{{U5o%Zh+z4 w `;gBI $tA9%%SsK]2r0̣7/I⨜Dz)|,J hϦ2E9=KCc(7}# d]I׏'ٯՂpg-FݛLB4>99(k"BMF7֨dIՋfs1ǫl!F)D@ܙe=)AXow101.ʼn)Nu}`_nUĶX_pfaG/[YC~Xv5%{mJh.-6ze_H&<*J\ºoɥd6} ~g~_lH>fe_p>tgUl*ERCjY0tprҪ*WI [ UՒTĆ;CT #Ɛɶ@kPNiW9FB;ob ônWMq5Q!U4#${ľ+IJB[ {MGa}X4{nnB f]厾 ̯أu\#-faJ$PӺ_ HIթ1"Q~[ E=Z!F8n.C~Բ) iŝ|`B䧭-Z6 JH  .֕ )xm.oݥҵC0Svq q7'š`8` ˥Go[H_cXAx? iO;ܿEѓ,zכ{Ae/iKڒ|~<`h%[j#Zę}% h;cQZ &w)V8[c2o@Q<'dmE8PCy4\7dxgIDYAM(eLC{Q (?˄+=% N!$7HPVeͻR젙,~7y+a(gelj=v~4S* DX֞{$fTcB869/u%>&+[AΦCT<l!f 0 $_2)Fg|-@N̿K=!_i`-"9#l'|{D >d sc/ӏ%t,,wɪB<=7kD eI3DI|5y:^e꜔Wz*k.QD_MT^~|p>zz!:ͪ>u&@Z 氼JfGDjj8e){{ct1GKp@ѹlԲf[8a kޒ FT#El5b4I\p̈1o#马rrL[LfH#U˖+=d.0!AR;Zf^uaSU˪>5򈱣:I/#*T/KƎ/Fe!N$ܐ90\N˛,8#=f=Zr[FzU+t~7~ǭDŽ, b+/儳 u3r8dw8(ƥ~v)xC9GU)TSG6ƧTѽˀt A_JO Q7tSI#gf&Mco\ǹ3h)HkAj)tޅcSH}/oB 鎓PpdcD#(.JUaBcW#n' f4D[.$&/ fc(;ZMV0ZA8ഠ=6'Al-4p XjOS`MBHYf&hP") ^;ED-zn5 % Λ';LpHn\I0G{]T%С`]wPQ& uGZ:Nlt.b'xؑeWǁ7a諄[R߂ڨ;ixSu/f2Boujm1,jZ WoK$˾G ~/?Ir+Obᶙ|%LUDz X|Jnjy+Z_x(p+w47| 5iQX1h"RUƘ0+Mp{Nr˼l;@Ȣ78l7:T1cG (EX2App/1gʐʫ\M8k fO&i?e#njnM3чeWR%oǹ/d=ԊZ9Tehwƞ9B5'&wTl<= 1 17t1b't6瀷H ç`[h<!ZVݱc{_Tb DV!ͦ+Yo5p'bY㸮C2vu@8X3)OX\p$JeTcjiBqLl'y$Gr;Jcd]9n5gxbuocJR:8/ tQ|Ⳃv/h?d[XvIK}5~6&₼/S0F:4Z_FSxu*r>8SˢN.lk7e!6>\Dtd ،/ P Š1EX 5HGGzrZA^֨%[]vrk+&zz󒤑U3 ka"Ew4opP'w 0o v8j(CۂɞJXugu$Wq"2/'qCZKdcR࣌72OЈRO{hN)QZF3=a#gc,RKHѧhNx91!'@D`c1nll+MUF:鑮"LӫwpCtƚ!%oﻇ_E CIJžVptT@ 7O\pHRb -1b0Plǰ<}WPp0KzÌֱA,'ۭy%L>e {W ɷMrte|=cM|vIyl.[Wĝ75jjmbq%pBX) VԹ GrNGIBcꚜ 1շnAg'$4Μ¬Y.;Fz3` rC Bc&& s%SH]h)/IaqLB$y4&/h'={^RT/sN4DY9,b',h? 6lR>s@i9'u}-]B0^hQ' B6! >WTB\z4zp#JT@ikCʼn_Zm-&0hHrcW]-3~I^h"b~ʞΗ*߱%Q92bSQѝbϖ>諊7.eP2!RDCEYJ)7 FO8$̟V(&Wa\߳I/oM%R{#rWj{ ƳH'3]=u'sAɉP ]#2<6QeMPg@,БMcΫMHo9, ֹPcq[IF_:h:`4oicdvOҖ=d}$O+{59utۂFftXaƅ]hmpe esmX~Kc'S0 ^̽zS(x^71߮$|Du*pRqWPg$YG_sjNlj9xع:H^Xh}[/m=K;WݙZaBUIeC@Z)4?j$Tjgtbz0 Cͳ4'qAz#*Shg+8R6S5WP1Z0:|Ck)s07}4 &vV| ^ $B?uz<Yë>\3ZS `CsgO>~½ Jb\,K ad2NQGlyHunxcRo/&͓A?mIM|^2(p@0si*_)oRZP…ݨPN+R: im% } ~onXTqQϽ#l1Xf7B%g^lvh?ܽk(﫰oBȥw&tG|8d(@Oc?GN?z4M!jP4B&} cm߱['@¥ ȉe)o_saDs ՙ}I@G6Ҁ>vi֋ :EYOwxNJńPK0n fszoY5јͽ3xV<;]Wq~ @|`JUJxyT+pb*ލ`&+؅2mv}{THZ g\'Yg^ͲdQN QG"%[@ޚ( <ͪ΁L_Dz?ۿ~@xVdTY J+TIn|*Z0J4))m;iAĮi0|!XYG5@I'%gg"6-)e 5o A~7(yecp{spS`sj[A`#C:B]?]q. 2g Z0uܒ]lvt-8_@TJPB͙2-{ 1=/ R }bR?CMa [Ĕ 0 | E"TAl?ۍF-Uu53B6 ĶNe|!иT&=DW9rl\ mQ`}j&WRCzvI68#e^-tS7Ƀk],l95sS w%vt ̎i9$ŝzUNe{cG2}jj&.I7m+{_a߮)" ,({sSU7_4NDd%3snAaW\Wk tcjx0 g*;O2@oA=R_CڂfA,S%c1:r"&XevG,jд fQzwm,0}e{ O4dULAMͺԩ}}d8%[xFwOjHf֭Md[;C\x-i0γs. `9tP/}&+cݭV`G_'@nKږd6% cXԲ\, v?/u:w~jkGCxڮO6][$}^|6$%P!)dr#_]ۗ%iJOCn )n׽$GV-p ,1`)W(\ߛĮ_K1R\ $w{W3 ZmJ'V+B [W`i~ ~jyn99ѿQ,d<ٹ,"owbUR%%9O6ӆiRj"'!zFFBoԬlQ1PYe>NFRMiMw0F T$ev;J]151~gw^{wM-ds! ^jM>پ7u 2=Vӽ5wҲTn}LȐAܜNAh~\??eLzϐ _uLtJ8VȘe#md2yp=[0/PVvc?_ͶomTm}+&G2av^.Iy^) oM O&P9pH5NP*tEl6"ح1>)C؅&5 0tKi>aڗBx\~MNh@j8R#29j*dgeu&9ᦍY #䈆tx0$#ھBV:LNW,+㍒RU~(՗{%__ 1?V9 v\0Vu?Ooirua xypPE: 1&ey_3]ޞ>ᡣ^@?HlwN [a$ϵD\TKe.ڄ멽gٷ?PChyZv8ff=3b{xg s.Qc ]W:jMpp@&wV1͝v.)K OnJn4O)7.lмQ= `qmѮ&]YhPx%Z9NgfF# Xbs}O56c+I&:|4 ξ'H4/rv~}[!A: O%DU.~r8F,65llsx"P~~Yڰ) Ph̡)ٚ6<=tK|!fe\ e?51H;'4?Al @^8ux kF5p|z2*֊JQE]Q?`Op>D{WS-E[_ى`)H]5O$L4I+D i #Lx>_AUk.-4gC4ȭf M%r4,:̽R_Aa6]`| GHfjpZOݢ<tq,>ta'.mG Yп^LR]zN^)*1 MNoN (ywR]ns9跶11 mzWHZ P4HDzNB 9-҇|{+Fcj  eȈe/ ˀ1N+ƶJiʐK} \#HW')j爙9~/\8].oeE:E>%5T|dsY8`@'ӋC1;5יE;lYd&|y ŪrH=#JG*H˦ߖPK/I7*/=mgN8Y9tC!PM8|Phg/ByJr7b64$LI ԦuT3bϤPץX΁_?\sleHRrd]A:mUEDSx=v%0]80y6z/k~mr7&A]}^Fݞ>'Cnɭ$&,i)f7U|OA_DHSr=*n!՘mE%ȎV^J "k#E&56ɀTm.4 1Y'~y>ہ47K  ^V[Escz'ErӜrԯp[t|bhZ԰.tv uSý?J݅ZҹGIdH3e8IbF#Zuón%=jDN#iɓAbn}p'lp}J9?>O8ɍj7&;G{ApȰ8(]R Pv&*O=`mqi eӐ)݂ CEEJ{`~ YyG\A;-dk8Ep2S Wn)@G`z׊_{Bvܠ+ՀTp77Dgn{O rb ;e*1?]?M;Dp$8*cB[I`W!"f<XpOA(z㕳:8!9 w{\ & K | ۹d]'~8(֬=-uT ^|pO0b=Ԫ!BR[1֜aᙛY8 Wp,P%-^%J, $`C'o|=#|l o}4PJ wm/SדL jmHS^O؃MKMp.'htY/jNfdjpn;s(v'e.~ɵnR!^dw.d\[pWv*2F4;?<۩m)CJy*~Ðd2Uׂ#Dj3Y~a_jXJե?2 {wI<&VY4|]ISiǺ?\ޯ|MJ#p&ɓP:('O Q_PƐz٠SR3/ɧH2lMpob9!Z6BU;IuuTGeBYˊ H9/Db]CwZ?=n/=1rS^~thK|K`@d:VA}* dZ=CvЇ]Utu.[V䛱)  @繥M.`G :(ǁk?M|>/(?t_VYcV)cy}( ǟ;">!#-y[#kiT*~{!]OldӔeW|W]o076Q٣Ema'\!(RZIJ4Z&נ33Ve"^8T͞P4P7{pF.w~q*L1 7IJPFШ/GF{nWEMmQnbK1%`iɯ3{; lEst;o\K@&9[B-1$_'$ qLüxLuap\Cb"݊w^)s0q;K[A%x}87>O<&2.9W%5J Mt+b_-{Z-/\K,C Na%u_g^%shkJٯ{>_Fj= Ϊ`g7h B>2 F/!$-ځ=4ɧYB WktIJy;PʙUNY+@lΡ]oARˆU+lR|HϗD @w\hAڒY d0@VbGx!&UT[T{-Q~bo{n0N6[ϭI|dBPiLyoݧ@yvK,WjGuu Kyc E5̿#14(Bqme{ r,Q#M12*<>-#I“3IE>!,Gude:ULI ź//rV24S2LzMXzKEqCq3-tdb䶒O&`I#I SP! Hwhzn.1FP*TAǖIrĘˤ+O!_N~ H^0/Nw5#0'=4C#JNjQ"W o !+ Z 3:B]џTx1U rHfY Hum푋wbn.܂0MnNH2>bjZ4}  9K\J$vϣ4s8?g3 `߰7H2@ĠʌD''γ(t 't#"[8Ϛ>aG!noym4vjʩ6<(ejQ J)@? aGk,ZH}djLvdcԈ.- i8#\$zݜCBf+_-5V9S?cЩ|̾20;aD񲒈;6!$*=7bHd%tDγ|?)]g ARh8VhUnR u[1a%8 a@\{RegA^ԡQ@Ij9s_s6|jE7/L44 00%TL[Z~3+UO\%m)v^L\.Eh3g^_ 䑜2ϐݗisJɷ[]kMм\-@(7q‚o3 /A?ia1DV;e>d4Y5peEy'b˺H>%!J`d)ż3.-n>0 P^K7m:$F\[`>g)?Oׯ6tYtKr;J?ڊC;'P.4z|& LE'H6 ㆒6}H`P:MIkwg&d&͉K]] THux%x>sv- ,j;詴 Z?aaj7wz(F{t="&Ci'NT*C2bQ!Lt m'9 j*4ߧn1 @7%!!6/?kP:[1D!^x n@rX/,A+9tZCSWe) i%O#APu3p{T(%æij2^6n~_hJ_A_CzX&ˏѼ )TGZs5q;5!s2T HeJh,j;S- OӺ3rP/ִ|Vf7%U$>28=_l Y,>|Tyw#Z >;*$BV|o<=JsXٗ qi ͼ"L:xd r+CJf,Djn]\he];!IJ`33oG vғ`^ u̮է?6VY䄊qH)f~~Qh!xѫݛSir3jUlبcZ $XrN8}d57 rhܦԒA.zlɅB.'HN:wJuy?{띿" Pu=8(XDPv72 fQBoJ,!*pIG"t{ 3w[| "DM/#jN!z\PȀ7Nt{@ހ.)z7ucSMvu4ߏPUhYqg:`GW/o ̉`ԡbE{-WwJO]Rjׄ߬ehT%"wokvSS~$EC\V^#aߧ"xot 9_5`$kFMiдtJo-##z02g.){sTPʤ˚fF$BF#-2Љ22.@~DYW$LΜ3W>}Ȩ , FTEްT㿂!5<6֗;Y9gv$4zRV&N5Bp=KOdtˀlc) |I~Mhl_yS<h}=KgONw,K;~Gyj Y9 i3 jj}4ڏxD^#5,:vi и =b:{+&6D4&W"1/ko"Üy5KNV.;[I|| U[ f"eR2\ ȰP}>q/װmEAC>Ԡ$|>x7/'Cmxʀ|7X́a޺ў͇ zlk!ϹJK" rw'3ovtO)ldwۛO ZOn[ >w)g1=Kd$5FV#a nZם%V*Tg0RuWsFm84tC&mhρ@՟ 1i'&67ΑD]Qɮ0Ӕ_|'A&]PfKJ@2 s.ҤTW&Όυ;c|̚qT{ATS%zv7䀹Y8rnv~8P[醮}oL :5"O1# M RVb\үE9=q=)x2ƁGuJnc˻ۡPgY8vf;k(6AWbe'4*Wzl}cO/ˠʭړwe]s] [wkܕɁDSf7ab.t(Vi͖C0Rw5GEDBN@W ~%<]V"e?Ӻ4~dZ5*b)2~p;yroZ{sVWWvYa%t5>>rSy=.P(jl:ꯥڸh|veިnl`Q35kz6߹ft6|FD]{{_?jU _J_ [vZ|xX*e;2> 7]`6G'Zv^Ҕ3aԻ =i]q+  _+ (ΪZ5j3`ɡsTmg}[4]"NzM Ad#i.g%l՟oqvRS IV=DU EH8ۆer_BX$|2MOaOhZ_Tg`9;pYmd>"Qw_YݬQ>ĉ|ʃyjίk2=@#윶!|3-?k[JM}J"h'+y몗vwCEpDݨz<:Y“: ^[[2I3tz}U念%>O"L6>Xܒ^85MØ@mepQ98Jђ]-b"*QMA);ӂA^vXc|e\{Fc5̆BbfV L$aUUּ^>flpv*YHߌ!=dO/?!ݚؠ&Po#'H9~ƣ[@@Lm%V7\ܳMY^\^۴Em쬸~*U7aga(VjӀΪ&V} X33)6Nurx=*8ڄI$l 5qY+ؖ h_ x:G¾QtI9%cQT+AMԕM"^g9UǸ'QUI]VDQ4 T6l FgwO >')ZlSHoO= eEmRQ'^T֖Gl0yW`&~!CތoS1!P-,+x74oNeVZdI=bMσȸ3$ ]RFF8+(ځnIGWby%/c V9Qk&T_^«YW0ŋSRz]/45V<&lxU>+ՉݪF<9)\ |Xߎ^6gM@pKzR(X g#l q thn~c8~w~yqp03>C"|CiXbtjGJyjR66WSwS>:?NG` 0smZZvs@Φn>"42`7i.LS ^ {-u^I(M 5/֛6JB|Qv%;foE'+wE_܄be÷,&۹|JV=p ><7O3쏎#u OVC]ObtQ3 c2r[}zc>iIY0Ѯuf+$ cjύHDz挓c?u&Nbؖud<`Ws2ZQ܈B7u>#NHm( ܳZI _p^8ΧH2| "'X'/)Zx^70|Pkwl\c{ta%\MH*$;`[{m ¯b*J?.-J!?ZG-'yUH#r~k[!T@tD5^MNn&FZ[=*Et'\oۉ9vcTy|}{"5߰.ϐEͬ(<ݵ egĚՐ]NM[ЅJ>G [GMhU }H`2lyk=0!5pO|'Nrv!>'GW* YeŻ@QScJ =j"PFP\_95z[yv`"|L ZtV'.ne)S[7;AFUtqpCVL9?̿8<65xlT ax{.}&?s1Rt'),NL'fG߼j.rE/c sBJ?gZl򓵺5Ga&uJ'1*Yҋd >F?S&c+B%3^uJ_*&l.h0*fȵEe~MTFl&qѾd ZGMJY;kp;؂K蔷P'sŁ=3i(/7US/8J >-T]?/t^Qzv9uq Ukwl`M" f׋#Վ]I>Z#,]E}x)DJ3Oo.,v(9A.=d ^hF%wę $i>"P QL*sS̫֜'g0u\xd%,EaήrCzACvCvj,d?"/.]s"vee¬~FcFgku2ힷ_#G-e,F2k`"$yq, 7w#rj9`@=5&eJgyGZl˾a𷸃g#kYCP,#'k+JF;ou33וmļ ;QW=Pse<IOp\{6=nZ_H)7fvG!7s[W[7=f7t|ו셋.'_tFZzNq< ^f D"U!C4p+C`hO2t"+ 7s>isLc5C3Kz{.b*.oπM?HT#Sf-Lf2}0=,=2hMVi~7ikPD>x]ï("Z" !WqLf]+FG"ܴ뭚޳ @6ZOHБ; #W!./$T:BۦXZ :g- nԇ՟Yt3\Q\TOx{dШ6*6`o?a E9 5gPţo8"ڼh2Mm>,bYG?ʋ2 ڙ߅EW d/Nj. Kv @XMfAN ]Ђ.f =2zPt}hxIW%%mJb3{f?i'fNS ^(֕g״ ӧGkM46~m]r#^@L=%HhzIY8i)(h]74-(>(Qp;xx<Ʌ7G_㋫4Ȅ D>Ys,xf4B]c-S=Z~ati[%)/;d:YmM_Bh~/lzE|N6-%oi7wu͡1Ƿ VY #[%S:V9QRu1:<14(EUPi{#A Aϗc){=1tTfzPI֬. Iѭ_fT^ݳ҇ɠ^en= z9όDCLz/oz,w@^i"#;nz&ZxhIRʄC:Ua@O66Zn >":1uiel g[$E;uJI5+?)qG'=-.{B'3_J'2N39ʝ7{$@fR7ԔxŖ,Nu޹:Jӭxۣ/CM=2JXAyv,PEB$e ɀy鷨@5Tp}  `lتoxf IstczǪے 8AĊ2)Քc.c #&@&LP`5K)7zwف@yhZ߲|R-jp5Z@܋$Y \,I8@7}XTG:Q|_[OhKz`9 HDzO~*[|󶻕I;p*܂,zHeBh3-lXloyS`f r٠p 1 4+xjT/To)qԡO)ÿ~[(~Ʒ5 ~ X;Ih7vE[$j3 .DD$QÏ* .Yc@a%*lZ*uzJeLZ ՁJ^W^hi/Ѧ-n&і6R4ߗƒR+GP:ȡg5vjUD`33y-eulP3\*L4|{;'%{9AlE-hkSKpsaX+T@Ѣft_qRt^8!X.MEM2& ao(O6EVeG0Du)DZlklPs |Mp}bGI4 ]6S95[4'\HʭQj+DFf[,= `v\!; R]MuP~^q+åȘ{~x PƁu4 a *ª>d>zty*"?6cث d\T ГjdN2Fqxn!I!l,{D+_.'xc$}g:U86oE;/`=$<,giv'$y䯋>C*} `Q#D:;&jy1HtixU.6m?}Z0Et,} xsU= X6_q.wM V]װ0xwҪ$E&R W.@rѷ*dov7A3/\p:A6}K,:mkrə| bϖ?\fyY? ,qU*YhO"Tu҄K+\F+?=g봉$|hQIoN,c`J]<`6q`>=2 T}YrM2熣9~NT ,WlEouKgars (DW2:*5ȷmњE _ j$ C8?Zl"QZƓ_T`ׂŝfΨ#`OtB:%(8lwuGR$ `s[ ۬=g[!u,Z/}jG@5)WB4K:YR)άobe( B0+W$ Z8`fؘML[ٛE o=_)#b2hgP>= (%=LstG^LJ<=m_PF^Q;I^ֵo0.A#p̎׈ =k#^xFH2w)HHܼ-iꍑ:hmHdS7aj89ᜌ/jacv9fLC5J2m꤬J}fxpf\l,g{P8@"a???Ԅ?\S?!kpVD ~u=r@U$жفA&a]6d>VGQq5Ж$ qgeJg?0Μ^{9B;b"@aen`HCzNBnoP*zzRhfIjetR KSn$25+٥iSxES=jڷ]>[.'}1F|2Qq:rT%[L14%hQLc8Bq\ʵ{.FȞsknʌs(bO+oZ4T?]`E#zǵ!p+i\NwA1ij`"pKB&6qzHxYUHSQ6fkߙp.[[:Z%tƈT[3n믨mOXMv @곪JڹSTZ"+5#lUסsVa^=冏|W} \ uFGiX1\ۗB`U1>i@,_#gAuNW@ugv^W+1b-G=f2xI:j891qEoSmrR>2jdw"Bnƌ49bZʼn<)v%~a+ 37uI\^g 8 hrIw2ss]P.xSPROaXYU{ IDcږg8G`;Q+8fo-]Y|Xü$ZtO'2ubh=H?<~Ξ#(Pm|kTrG=2@ʞjl7WoW2U~ailq{oVʦ_6~j-sB}mf/;~Y .;30  iq]^^k#M &h<뵕U)8H<Ù9%t}@!. xzD7h[pq\}JNVܩa)]l,LI?LѦmUdgE |@H03n|MĔe*AnEJ泪Yx5%V}` B #Ljt,93]Lmc=y&}ŝ!$`n(wb^iH9q!4tnFC:W-=8 /X37TL씓 MMcz9+4px~|ms?|I/7 u/U}ClM2W!#qܾBe4%RZ`1D̮N]oO~[/q d_w,~arC {lJ6&ܧr:{m̔d9rhsKΈKq0vSӰmHf 66N}V%^ 0#40{VB^ySplog "ya\/ XHFPt ݚzULBWdBo G6%!y[b2QE<]F'3\fa0쪕'ΉU.eR4h]{HZ= 56,L}svF"34*@ ;%+c5 s>SQd!:[.S %|٢gw[x=(c\qvB=0Agƚݻ%u7N€uCdD|8+!S"J;0<2gG|u-W-Hw-0B0oႚliRmY"%ߣm"{An(YV]T]cZ/RN:զZf `q%mYx35 {ooPA_|z6fw9Ó6`=JF }(*Z3mS\ԓ}[ I]W=4,F:ŧ& Nlυ⢻THW[ x:sgkZ\!tWk-xwpgS7o}j%0oR z!b|AeaeA_=ifr4kd 35[mrOo|qfwtL5 p(1Kh)w1yM܂a4:/q-NsfLt+W 9|82t^+|j9E_>%y;a'ˇFM=zVfu&ΤBy%OSԊ wκKj$^zb[\y=J:(t٠AY AvGoP9A'Uhd'8Hn+qU4}9@5B*Ԁ+H%g8Y]%]d^[Cp\aYn̺VVyz8²?y'7{>cJX:vC)Q(Q'z\2{7 Q$o ,ngy&o-V]&)b69>-TֺC{bUIx1A9״1,C_tϦ)McըXvXf8 e!!Y\=m% &UpNj4`-:'PrmƆ6?io nn{ClvNr",9DirξaAlutv; ÍVE(kM H+z?G%9je/]~u*mz1=6C8q:Y~ $K¸ĿsR吡G®CH>"m$R~H9"I5.kNS7sL.Qnctq6@n} :5b7u 77g]%4KbowTQ[}g2Vg4΀E`_0Xm-c*偀`%- ]cNxi4v%+J@S Y +0`aK/.cQ`ݎ0'34)8 !$ װT]&Vp#qd"ظe%]J w0 (c\n)X㕒+]Z=ovUtPEQzxv,,ЋWN⍱]!ZɆzHnKG#ǚ>}KDŽ-4%!00 t7gP!ĜU*qz,JF2<@&H f˾G]F1A ywf͂"y׃?QAf94" 44!}qv`T$t9z3Qa qn+ڞZN|j-{wXC"fas8ccNJFv+jB @F!~ 7:='}mlT)WQl<8?# mQu3ӂ{&wP?V`:FoFL{ڠOlct:Zz T[[!K0x9aJQax|&kL?a_wy{FUW6U,σ1T΀f^!j*[4cS3 lk#"MOa#[ilpk^tm .^ h1m* ^EvZVb;_ur+"[ݘRL 9i>g6Cĩ* ۏ>2Nda?1ct;@QQcMD4 A儎,äv$@+ KP r #8S`Q4Cb _{[~F qyyv6qvҎj/΢.yn ^Le= 'cՉbEDvn>=G C{:b.r&b6{t) I;5wj(}Yj݂^:q4V h*&4 <.zh[-˨K%IUL>0>\x],gxxmfC\P ?ѣb*vE p觪 e|}BupdL>цŘkpCуsg0hTݕdVoW#JFBom\!o]Z}\x^KKl] Ap#Ab(]lVD~%' 27FpVn@̦GAT7 uexi;5 V0]pYI? $De?Bep ("R.Fp @a~sd<ƹZs ghL[A_.s tq^R_)ngXBf4]@\^= \JPZrak 4\œf\}/  '|fYݮfJSl؉m+zt ?}¥Δx8ħu^JQޯ^ˢ50^z¯[N3¬\, !:M֑v$ns0=8z]IfEu'.O-N_/U4}(If\Zizɫ3z\Z 3UoCCCQ;&Giw Y P[\=C6د ԟ(l aOb]L|ȟh]e04Vǟyٟ[c/cUUvHN-=)s2q]=d j)ªt;(- 'ߖi9WڻH(Nn cqexkk3`2NQѥ~ԁII҆iL?-3ʍژmאٛ~t]BAa>&ӗv-R]A\J][df@tߋS.2&orW;ٱlu(B-Aٳ{ 7IDFޣnm/o1]p|@n#`KPȚD6#o?p^B҇-ԋƽjѬC¥g?kN^yz;YGH9B's ˕eV $o(2n 7uQdBTWxi"g١4fCܓ/DI^)ߨt>jS5)b 9YH$9gf /hgE{4YI-m' 9?Üx{cjo\)P c#<GwfQrn0^G,UvXV|柕iw,F즏2[dɘٖh~Di|K]/MjCpX=1lwLtݥp rI sި5aww L5dZ؋r5)m:Û\/596V^`$5O[rT(W'a^6?a QzǤD!޻{6(̝7()tITBIE 8ZnGIݑeu'dYKugJ󐥒2𼄞k{{bF_zDo- Y,}f`,eE+^`zɕozf#gx|MPX]p cF4w/ʏdvK6'KuY\>C:Yk?Ϛ&K9處1r^ղ])Rϭ;^/ɌN1Fz^uƶ׀LȲ:4_XM *Ok$HU,[ܽt(+k( 'ѿڰ]uM! L"Q4=ٝ=<Vƞp~l[)p`[5)[&*"!o0IV۟'W @WdTHp(z! pY_k*fV4ђwvrUhU6j6rrO39e#jX]WI/m~K2e&OY~K9{ȱ>@V2lF}?y}-jL\A"7z6(kq L N%ujw3R|X3j64<:? ʦxYhUʼnc6^QgŮw [2[ߪrkMzry9Iqsгfq-~!%FKhOKQGG ǷA?hB/eW IMX@E{`j((Ϊ .t`y.o#ՒbWO@@k$u"+56M[KJnFV<+[F$AhZ019jiMU2yz%iFn"9xRynb+Y}F{edxb!S}_&b x j0g4 y旊7v!.)u7z#826jSr[G6h)X }9p_?:VKWkfŹSˆhFӫR(؜cW |tɽ#̼0 pO3gK/atКK,xcV_Cۧ_ 1VҲ|"2}ewG` $FUIچUR^De-B 1ڭSY,U]#%VF SԂw{5$ :7F+Q3. S.^//L)PNI :iu(dL+@Oy/˥%sKBI#>X-| GXk_FtY TƔ9EΣdk $17>Ѩ꾜eK ;}Z3ny1ᔍn:y'vCPz˵<y=18*^E- kOxha]>0 @c>/iC2`b>l54U)Ře?brax+& 2 D9*.jMl j1 kq@,Tv'MQlTPKG̀́Ē0g{oD; l5DŬ du0b/|)3PU8[m {wP~LH q,3Iߝi 'Pf"hkp{*1?C0Z^Efe^)(uGeiB47KbJNt* S!K *tFWC<>|UεJ4e=A%VD= zFI<JŵO UQҰYtd?ճ }BG (^9>j;k( W?x;5w:U|&yR϶aG)/z8FBɔ b\ h@\LF1D>*Z^Sk*=-.P]"OѤj^쫺ذ>^rW]띔_GC'̓{`t%)cXP۵J֯Kq&G?)=F#`$󔹗S%Kh:рfSZ߱6[_$Z$wK΂B6O5EMG:?: r$FڋG ^F[X8_~z4{sQoix.P2vAEq8mȹnp0Yrd9V='F@ԒhI.ckG7 6EQbgh[@y\83FY7[pQV+܋*e#SggJ U/ܞoa gj҅D/xxg\oiҬ|iQOߡ+%PQV:|,[`(M:(bgVȣ]G0m'yLY QDgÁ 9ZûE`_9_q3rn>5@W=QQ<#l_;qJxSuztƅզfQzE3:)L*=#"`c'h H# Ig䋵,\1!̡%00Y/Õ$%[}eqA)nP!+}F2<ޞ*f8uns,xT)K𚯔= 貼g)-0eh%'}xTܢ}r8Vy紬l"`eI:l[U!>V $WVJm6U;#gs`}>ӉBi¶r{?r3DZ6.ָ/՝JVYto^i8;g ֱ}ٵ]sAg591wN30HΔjjWzYQ~ _OR!Bե]oWI)VM;aLj6) 0|㥑Q]JJۋiC¡)c %9qOiCo<=B= Oi('nOR;uz LY`ſ9 놈3]jS?pA_[+P+@lvF9;sP %y|Rf99` Q/ vGuH}N{&lm+ =T?0[c -1E y+qhȊM|fyI仕2T+Ì$?Y.bV BV)v{" .+2DlZ6(o21Pw~ Uc/>u\k=w|N\QN{a?xo?"ʘY*Rq'kfxtī7Wľ Vma=Pgdvp9&X(h;}"(if00 N7Ko{aY|(5sGL5XAR2OmTrf<-ԕidd*1ioPwk3(h] c<:O_\,vDU"u{YI׻қ&U2 (8:?ykզP9рu o)M Kfl*Iƛseql8+La 4, b WW: )j3"8-W rL<+2FœaXeWgy(;9%׫ǰunKFK)@*Qzb.سl#:6hi*=WDtwk+b6<U}mL2g=Z5N=@rËkO#)-o[:9} z-$xa'Yir}e(3PN'"A{'H ɝYJ7cmEc9S1 TH&?RwO`&j>Gc0c[DEyb;`mB"ל(v؛Y" i7AP\\FGwu?~3u*BC[ 8͘CK=sJL[0YJ\= ׆EX#щTWÑT9u~yq#i `S8 >4%nRVG.N Zt~Yc$\8`2jTalBy,DQ"3Nռ_S9cz@w̉HfaiQh#X9tnQVP0~xְDP47h+Z'y} 2: "7h{k!0跾N>^esݨ@d(ɐ)72(<ՋyߐBx%ڋ_4涩n`TTYN$)4+MْyKuK-%3Jj@Ҿב$OKkcSeԧGtyncܜi!Fs.2=2Mn%CY6fxڠHSɚ>0nU; !3&? O־˳N9x m !|*(zqX5}@S9-kQc|&tQdqIFk?1EV-m;pf7a"mS`8lom͔Om쮃L4$=CSw1Z؍z%՚Jߟ&<9sXjc~i5Ƴ&B-6;ԎMm쯞 `$"x/gVu_r͍ t%NQh>f#tݦ8t9OH,NnYE ?T.M7$Oo)ÎHEc\2EbAk5As o×<VOFLS4_X98_gH:-~GJcM˨ 5B ]pB?D5'eTh(vo?EOc!;]|ȟb&^fS+>!ێ *J8|p(2}zbzAt_4](,~,Gޔq這N&.\xul';g"Ew)cl~mdI B(h.c-uϽ.k6-*8ck7ꂐsh:~>j#Y;`2epssRg: ¾[PFN0lytbRc^cݩA4axe~.~.A'[~/NOBӯR ,TP 7gUUjdwJI R)pb@lNu|Mqaꝡϔ<AE[Z#3B%LS2=l`H vn CalpF゘}92a!Bzlz="zTK%Еbk豴<)EHW 8I^yDL]Zx(]8RR4ė@ 3x:pb.V{&dN^bl[?/ķc f8+ڍ7O}a4~(Bqnf><P6m˶I2)/[z0=;G~mOcv )z5Sw֌`C9_}v:3>F(463bzBC #7w %/g/JEřM%ףꍚ2 vXM;z"fg19f&GZgHWZ8j\>cʶBWXh.̙bzӔZi5}2HN9~Q+9rwm6 (&}YMg 59gh:,-j;*ӤYERg&#dot~0to]CTex%^Yq_cy"A6v*SNfV'}llUNt[nR`L@\N2!TvGS&pY ƒ 6e*U4}Y̷[2Msm9:f-!aQR|bBc׶pE#1ځU[<&Wpy).NxV)ap]tBc|1i/p^{t!,e/C9W~ȶf+5^&15ƤeRJ[K=);_`|@9 њuӼԪ2v(8^OU=֪KyP~ NnI{[ mŀV8VQHgG꧹y0ʾH]H/Yx=N y0ET]08uR4=R6 Mm`E8{r?a_3HmM_HW9|BEߩHfTg*Y7R z fZ\E}(]t!$iIc^'9W,jk>/|M#VV@M,k s`@ 69t掖Z(V:hD'i tsb$/M`R۩.dY{iv)M8Wk<||á`bm/x:u- /nQ&hIBWku:^*n>pC|"&6;9l;ß^PڮiI62 ^(D8ب0&m`*r.%KМNj}][\s6lll^{*֎B|xwFB[|  2ˢ⣈+9ڥ 8Y?gE3\mTV\cT}% QD|pVUջ %u0W3tQu!%A 2K/$/ #bg_anhꟚNVkq0xEed?/2O-8}1Zx0P(pYHT.$ {S%.rKQW4'X{&M Hk}=]|R>-h;qw=t<QgWT?)vW! [;Y76jQtNh;rd$pVoɨxx*/7T+z14=H cbcmo(PmR]'g6ꯥ6uy5]Lu-zUx˴B932α^`  %c&JrhXpʿp2֒9@ݵN09vt[[yiuJo/5Fnv)`ki-ϣiC9by|Mo@_Ќ 9S.O,Iy~JprB zl i#~Ԇp_8 e}"ϲ<gk>fFfY"[o6po:}!ve?c-^;Z3y-]c@D !6BjWT7e ˰{Xeh{$aX<'C[}7F<'bZPzTx8^!n/gP.ҽu'hxб]mz^UzIa`dj^`3)#^k(UWl_?uY~<bic7ڶxc-W-V*1ub8t*H]ZQҀ_8.oxy1@N/tړT7w&D+ِ{Zo'=`m:xx{jp%2q./נ槺eW;z #uQ`C`2iYU>EJ`yjrq:}zqLV,gUmj %ɧoUحol|H[ NM#B9 #O:5YG`u_ʱe#+BTi)a衄  &p9e#EXR8l#J=Ygmهa+7+bі\vDV'D{1ZbiJOa HjzJ2"FMU,a2y 9k,xD ; JS 2nJEgVl|u64f=mTkoY7,6whk6_?ǐ ׷Z~d f.`,qeNP8~T!jVt7Qb`"Jojܶ&XOP~VmQ>XMlW_lQ0,Dk{PmF5eE@R٥caGT["/qȬtwy0n70P>8牧DdTVybJ!t7TE:!hc,/[:Gi\.`uƨ_aʤ` ]2 i̥,Ѿ3y^>%]!'Rca}85VU7Rռ#9 ~MhsΈ$%>D>|> F2T(昱D%޼2emh͆1sAyW=h^+}ΩT\ 𢞬 ˉC_ֈ@J/L4V AI]}Z hI=]~]rԘb:E<A?ib{-v=ض|ɒqrhcϞ),tE J H1: FS4NF֢g6ٳ akjxMgdIU7ka{.GA)3e}/tNxsbC`x7F۸ŏgj9ns!ktTrBPc0^!r)V k&cR5\W1M\ʼnNM.I踯pnߠE?hEQtt th]u΀A܊좪VkMuX2km ҾEb.OlJj,Zpy lspbPS0EP@#]ч%a؈OQ/E,1Лt+$GQLx4^q2P@wyxy< G3QLT`* n^0V_9s z \XlJT0XŎCe[o~Φ]qeh]JuOjfH1HCx`]fW "@e\dbj,tgjP@ˑ2*(@+̛H>^Օb^&|A3۴)EE&1&r[7v_E V"W080xLgbO~ߋE&vN PC_S#f. ޹BO&kktZ5T$9$pǝzsû^F81L|;9t8 UTy.&\×J)[?ggyE\Ql͸Vz~('ppعα9ǸxgzASmK>%7q_m3GZm ?GhY+-=u~]yzo`14\A G *XDđx.Cl@=<$Y),J,h?/t nO@j?;s,Հp'HZ~ޜ(Z£%x2 |-'@?=XFB"S5!,l,osg?ǒT ,34 Ʃ0x?{>U@|؍/_AxN< yAo1MPqHH~*Io گa u*D6F^zPq1̇QVޣ)LdhMVثQ1[sO2HZߟQ?^-Liy%_xx]UPpfTj~㳏H |`KЌ5{}/Y ?xf`<WNl=49n;\IKƺC"vUxn] BNU;Ǎr)[КDTQIt ElY;q(4݁}-/z]EmFvQ 'Gv\(߇]nB(;6!VQfH(MAW*kB7 (/qFygy_f5ņk9Zܠեx8+࿥D~ڧ='aBE1ڴ"G,>7Ϯ\qtBUaL!bI^OhyDvϝ ȥ4؊,%ɍ QВ n^a^q<C0Ps +1ư7Z>X#^fQD.DO!r0yw6Dsu.)/TsDȪK֍CGҟ=݈btCXP %~ OiyӿOs&pDwoNLMBZ%ַsHFu9ґ Lc3 W3\Uqrޟ rjQ oeS(+: ",A•<[kIIdsp uXaU{+|/I)z壿wna'-2~>'g嬡-KtNJj]3)wK[8,ercOaf<JuM?V[=.zN{6a%RZMtV6)㳘|n7Ur׼#w ~9|OHMSwcJ Қ$RcQQnZnE=Tr]4PdP~# &qa}exPy+]8 IsU8 zrS!WT|<,w%cv:RHu9Q"7+|PMLVUp Ko ʽ?6l0m-Y)YjTe^ԡ[ aʛA¸UI)6S*S8kg}ڊH{! 5ou!)јWǛ Uw!CΤ3mk^NVKIb/ 8cD)uyjMubSNA$mzIC{. d aU/\ nj| .BLő(]o.[ڔ^h_dgv)콀n"궨H&e'OyDŽűN]dž:8SKCq^]jg HaAdGj MB_׹JS xk{O=FI,[[ʜyPEu@`<*K ^,[D&|7H'Y)5y[6]NfI!+1D<|3{Go(w~苇6{#mb"|ۓBZoD\pS.8&fdN'!f[wb#هwTﳐxC炋J({zc٭x@lfWrɰg[aYo+ arߨu<%kHk[V2gڞq][S?rtX}˟)"Yft Mi& +X[?6}7w'c+B " 4kef2SVK/JVo;uCeX>lt=x6{,2 ({aW]W:6ngo LvZ>hxfaߠ.GOzM2Uwߢ'=(27k&kjeuryѲS1~}I| ʃ%&|Do8]qv.=os ~Q[d^0x}1=@rMbf}!w{cn !?6 lmJu[3MAEay2LN{jLwp,*y,_`]&I O4us"K?[;\01?alMzno#ۓ=O-w1PFC0AyT} z[otcڑΜq:4BU$Y@]%aAr^b.73T `# Pŵr6ܶNTFwٖ֠lPSv vE8\;9 W ᷹ӻ,7$nHJhz ă:<-|0.Uɒ XP$3!Z ȿ֟3&&Rf rU .ݒ;rja c굪Araa8mquvZ^J 3xauͥ$xuq`x]-ͮ  x\{!̿6ڌs:0cKt~8Ig^Et q$\$d*~QY`K$tg[8ld*m!_!Rp_-́d^z&jW,ͶY3H5M?GILH?w[k2٠ѝGc~Hm̻ {TjXdo4؞RaP=&=z' nNn$iGcl fT, u !_/>~Y=>0J$nm4bwy9șZ.ڙ cRS=B~-G~ftuHhN͖}bq*؇o[)-ʂpϳn։P(bq}}ۺ#Sn DKV˲/]6gGYcdCJLjMe `PCoS^B8*d"]J=qd@Pl37&Wg`mԦ~lo^"R{ʾ@01uy\_7NZ.6i˅6GD/|vّ3ҿ` 1;W[*pY#rMzȬ׊$qg^%Dfq!o=Kmqaoj9"CxGogl#S[ ~cwTE,:`ޚ/Z2_Q,tϿ`?uUYVBĞ\`*k6;ܹo}1'*ZJM9`3Q<8S599ɇ: uy[/k0[{ӞM+v 9-7*;ᔵ-o8%NCT*\(]sbqAˆRJ^%*3<{/g1bLrc<`uͰ7=)>Be۫Y\&KoA4Z9o&IrAUڬS" "8ζzAzΘk`D`$d".twz+`/ ihYR6+B  Knޯ>- Fkcaݍv=^Y@ gOnJp}ҥbesU Z4l9u/\<IwT@FǺhu?%Y_+m&~чZ1#+sL1.-ayO>:b&ZnG©] {-_CcNb@R`^ʔ+Ώj Gx|1q 51M;t>Hb/[f z1.ϡqj!362qZ/U?HEo"gGoBIkhP L@NJ.ZdZL.f0IMk4d~]US+@ٸ87?D[翺Ɓ>jGGP `ZkY,wRa9*&%QJo >~ET&A2yA(:5o_N$ i:]-{OT Ӿx齭^5f`0}ZLjZ?mk8,ׯW p!BrǬj8SŻ%q_:^2;S}9.)H^I?}T`NL'-~>1d̜V6Đn1#!FaXqyyFҨ àFίY@S+Q#lPx+C:lQ*RGN[8Լ,zAvZrH%ƅ|wxzOiN=~u:'gɴXBEs~3Z{V b΋AiCݞhgAJT HdFFJ;;lϿ('Ք n;f>A N(&zDŏFV 6dVسb3GPJ6zD?\cn-OV!PdAWiD?ʙmd^$x6!j*Po~\6{ 84mZԺڨ(QxC^gZSAkr"*7Tuaġ[);*6X3Alښ\`jTƐwG7y6qY^ViA;5S~Īg[^qDq DiFk/S1iS z3oƐ3`,-uj/H% UfclrG,ujf5<,@['$X+ K܋CV ~쒯9U`9$B"m4牂_jZmn "w{&M_P*y>*lM1ϵwigٙZkr p'yS,*'Ko#ҺR(V(GzPIt0r̰mJý v&AZ||&MkW%rYKtl-@’Ne?u),c ܊G)+"qLhÁ@f[6~Ld.4oֶ@OġÉ5Q`C3)}8+^96f&NYFomao7#iWW3nЊ)X2s^~/ MEnzzȲ};ꤎp¦, fa׆w`/"]{L#y`{{3ӶX2F@ŒP֙ԹMRI7z<ʩw=)#U9慨UN[>dgIJ\N!yF?yY.EЇ h/x2hUsCHgow͢p^6k>&Tk, )|o|dDPQ)MkY gYZl"XQϧUlq{x[+#>E6k-:džߖTK@}X"̱S$js.Q.̨('kn48PQ.ERʗLjAE}*(I;=y2l:༤0Fqjn:7p.лqY-e9۵w|*|^N laT Pj?Dw)NoTr"8t#F!>X4f/y93vT6G&|LMH(ilJPBDN6qIB9>4j:θ@ R[IAIm OrDm!2#Y?HU-XP KX7叓<>1@^-GL$K0`ݡi?6чOPmh 6M ?׎1Bq6B?$jk 9]y@Iv``UnXUY\q( H @b&?5X{@^XuFŖu-MXVtrP`!&|fZ}p l&=~x^|sgilu=9>ƹ@hDF@\Y&Y*p rpEC=SB!G۫BOqϒ 9M@r${zY$4|)g ]&Y?ac}q/4 "OOτyˍ+\ vu_ I&?踄@oBk+f>a8 zA` BUfOq16ſn߭ G)sn?5f2hK>hQ,٦bKUT˕n"J_`2cB Q좇IC0hnmq{3NgT뭍Tހ눆7ulH]$ЯN6ɥ! ` k*:%~f]\EڶxTF z\ S~(Me>K$-q^bt+/K0oy2jsx`w~X R}c¼B/@pE-G_ǙH}$s{auU;#RB5?6A %]Ecj\{E䵦ce>KR%v:G]d'g~7F;bh.Rė嗘H*4rԫK!f$H>p i'QtW!,εs [ۨ]^CQ]>*o3ΉS gڃb5l41:wo㒏M)W,<^<4F"{d[y*Y6! 1/^"~ }OEpft^&CEj vi} 83Ya\3W N۸V0r-(s:{@-EkWVr{;h?Tk^9})Ed$W6BF (Gj2Ovq DplrR'@jC.5BݖKwƹ=v+L."/2m56yʚ}L@-?(5m/pHoԽ!*]sEwً>\~5+aBi~ An,ED{,:G*Ch˻A*:s>Da\?)L,u.nt`n>+pcL#LƇGYd3!1%ѪOEokﱓR>oqɕecL"k1r*Eo\1 &S aw`O~X> 2;W{{w>l&}%gʋK&{C#]He!BG]Bm o" 1oPW$m~~"j6oS2l$Zh '?Y,bwfRxjig@iaW0,zo;mD&&TdaBmē1Uv3pQsE!YzvWP ^ R_5~#2)_WŽ%Ϛt~kx5"/JZDa\t!ƴp_ˮDr \[hfXc!U׫ Mm:_)pofࣻܛCSʚ#S{7CM L`}%FE -&Xzn>FHpqK5/+_ אy`v!S?B\Gwa" 渊Ab{ p>j Ek~GN֣8u9/]x!y6JHkɠrnקJۗ B _*T.?DEGDt*F6.HSLj A}@%*%! K$ :ٱnJx16|4*50!f{!ߣi~p8%wZ.r:㓥 m2'fʸyDHAk X˄:;?G+ `}آz({dE6&EuƘ&m Rj|*v7υbRiuG`&iȪ/ncɬNŏ,z( ?^DSW`놞8|ЊŒ҄o`k-w&5GC8r'8pQ_&&;c6fjC1O+h%=v:\*lIXN$i^iLl1-aq c%%>^ʆx('톩ƴ<2X̐ s(>yG 'Q{PԜZӡ&DRtޓOJ!-eÏv}5jlq-yẎ?+,NJl)/*,TVSf0iE̽I]S"뜲U<3>uwN5-AȆ6'scط;.Z4>6vdGþ|?OZԁSJѩ\Oud0lO,|G?Qye5K^=?Y2wh ᶙdzaNlK/KG0ZZGx|GOe*YIi mz3⥢1z!xΫ>]Y|4̚3lIГ4d)mDsX'zb6 {nNzHIq4b<%: $W.}"G0waU\}g`vr͵ v0! l#uָz g8~AEiFFkO2cWDoKŗ/HE:jS_3IM3Mh#7o>x+lܒVD`Sn qJJ8[b8aTB QR꽶il2d؃u t;ЇK B=wolFp; **A (R y0.mybp2_OFi'u2 O%E1qjHƃFi7|Om:?(Y_C'9&)Ҧ V6Bm._jkd:qBfhQirF6l惵JABd3`1|O#CFD`jI@aor| f:5̜!#~`3-zȣm6\ǵ[ex) (~Nڱ ΒH]'1󾔓rXڬ*tvSZ9ٛIh x_qN||*&V{friȸユ-7AB[纩 bޭ2+SGhf}hCjQT~UG*p%VוݲKX7Mff\iHww*vFRC]F9}brC.'÷p9α?cˁL ~=4Gmu٧N@MïFxL3ы]%n:,PKgSRa"A 4PpxlØR;m3 ~qv _Jgtn4ox" Zlδ"lPw[B~Z9|y_l;R,1s< 10H~X: PeC!uee|q(ULׁÂ(B6~#\4E& 1L$:}JYݹSIY-cn1q7l#S -q?aXyXXo˼?'N^SėhzQa!yCI_dgmUǨqF~O튿qͻ('ؽuU8 ɻh@}ygˆC\xrF(^ \@l 0##|ݠCI)nF]f)`*OTa>hZBo2><9e{zX%m0>ann8̺%˓{Ӝ ?RFBf>✞Kn*Ofp@@Zp>=p]aC8?T鹒6pC'!hB223 =qFT{@~"ׂLCH !cK!68N xQPD\ĝ"UZ[ԏ ayu/Cٰu^+qt}# OKv:: WL щ!ңiPGEB XuS`.sU1=\LI=WI *}<@@f:@M !7F-@P{LkYkOq@?/7L"r=lQk[G¶Tmm8kr^]K+Oh{0ԑ:Ef|J ɰK,[DPMe֟)Ζ \.jQ ܹO+Cű$yP!$.Nw%Lc0vk; ԌK f;| 0p&[aϟ&##DS+%ڈDDb'3"E'WGۂ_f70]Ôwxt S"c<ؑu Ž:ޭ Ǥ#ZGTB7ȴ_V{e,>Z Qlp[Wn*E'g'D5V1y_!mUh1Ɛ ?(@@A3-݉t $rD9ޓT~` u96VXO&b$DgQLGE]H߈lf2AjAAfvE @ADSݑy @ҕ}g;JSd}T1-J>QXS.>GخbIi?@ o&7+0m\Mz;|#(yLf*D3J'g?ǼK *0Ddł2H%Į:ٌ9]_ظL@}Z`w s+tna3\e@,B-6ےfcɗm0(G4,?;ٱ=%sD zjv NB,qHae>! Ib]!}D>mX, YuѠc.O##MB@r5s^ԜwkHBBBPu4#Q&*q9˒"QHaGքzOOsdԈ+h2 b!KR6d>2mu*-_M"R_b͌r%@Up ^BvW\ׂj]d> F Dd=7yi/kǘDNU-c&UOgsdAʝd.߮Q$x(Jza"\b=wC͌Rgڝxna Щi ZK$C"-)Z{+PeN}KiKz'M /{nXQ7'.R O{rec xF< jIBq$-޾nL~o.k;W ;oI[OɘL6$wi,O*]cgoIEFPku4c !u*u3APN)]/r1+16?qƾZ ƌ=| eo HnL/0OׯLQn瓶* ݕ}%UtʔN .ÎB1rA1An;1|Ec#Vy_%F!Y;6czX $b0ǃ˘O%` uQhxojnprl G)dRv!Z'Zf R];[*)rl^Bt'0Z/_/.`8NJ^4-VzRL(s($lb-7Q:0].T],"!ѱDCB{`7܍p_Uboǫj-t<ԟpD0Ѽω`1<ӡi5Ok Lf|h97KU h+Ɓfو✤UE;x,=]d=Uݟ*#IItѐC *Ӽ魟dN͈&lrl :ćӗթ5]<NH}nӕXRh 4?":7+bȞߧgg,dȶeZu"%+=bv# A)ע0Z<n}Wn3q-Q1JB07@_~p#ra]M rZvr7 0M8xÇju̸9 DI%FsPi~oLAk Ѕʃ^_>*#eXқH8]UTB o@VUr\%,'|Ht`E$ N " .i橏7;% %5aqPX hp-:~%6G7ƒ!,!0y'ln++ =ELJVgPv)0Xvyϗ=7<7ꇐ.ll*S(?Mޡ+L6 M' .Av!?Z ]|kkk?kY>I69[#WVS&X, ͔,nDSE[a[/c0IZrP!f$0UB - wcfߚR# r^댻 WV෱3g P[ 5L)xnc_CcnAϙ5Ĩ{w LCt -8[6!_io匉wRQr/9.yD:9]^P!ft]mj :#7,m3 Z g>Zթ]O\5G?0(*GbdoތS~?bb x \0"o8c(.I)Sg~a5۹洄0.zOWqڳ%Hsd{LrlefØ6؊S!&?'c..Vݡx`@()"Yu14n.EjmY"9M\HdYZuʚDUX5s+-CD];Y#!YSlJ\@m !̗J @Ӎy@jϝP͇_7ʫ"X E$mѼkgW^;@N aXtSjL7FZchaR?'@&OH\ŊL2"ΧgQ:+WEB'\{q_\tE] .̾WQBi^͚Cr^8Ų_DEkL䂎YtB_E33q Rc$dٛ"I,[`K<,aiuYogBVxp|$aR)'Ӽ/da˚8=*T&C$Yn#vsځU^xǗ+d*:F%!m QuB{*,?kΊ- qם=]2OAx\U[[TjPp`Vdְ#U1@6rCx}@ "\lL߫0(ͪ!Uz^Dn9V+ҽǿ̮ZEeJSgFM|9h*IT`il{ߋ˷*ҭz+(O賂m,#a3vA^ ePA~kd >2鹯Za}1F-c{{UH@6vTH-:䂘kxL@L+qkŭPw*g'c?;4 = ?/-t's"|LN&(c[t9cK𹔾=nr_i@\Ӫ.Qb6D94H}:!}{0ߘr4XL(`5B)M9wڟ2?+K72f$俤s:THmXj٬'LOqڳTm>rn0Q= x7 fu1,uEhY&Lkɳ/G^R˧ Ƞ"-zJF4m`=0y8 k;H3gA3SD;{|?Sj]W?y^ZW3`vQhbf⿿fB*D/3@oT4:[.GȌ1`ET2໔(:D]wX^vPz\ {8Z̉ }Gķ5h(> \et]VA>`h",T@UGAIKO> 25{^jOb6!h[S|D?͂ x>P_eD%y8' *=-R6Qc2'4z\V%*,J?؞aفp|>NPv$8&~L K=~W<0s拄 _qHoJQ_8 yL +KVCu菢i(sӎAkmRվLUg#5~hCF&7y o%t K"IUS8gt)=T|F$G8VCG:dVмVpALkM:9۷`ޤA 2{26юy_Joݏ^ՋyQwĬ'w)ASeUNP%&>cj=p\Mwc.۳sgZaחeyZ"j+;0Us*5\js\<=Sl)BEFg5ɇR5Z(b[{{w#(k 43ZgMt*~ˆ+/V"vbwylW֖G֔I.#C۷@!o:ȈhnP7Lдv[-aoM3AP .Psfo bJAY{q3 >ťS:'݌\׏Bs=u ΕPl:`kS~0.MP "cHo iy 75pmN˵WW͸־}~TpJa3-_JcJT_TkVe3Z|q)i;w?KqKc?5I⼩ dO]UܢXE:9Ie/JFX؋&GPT?G)joh_*^3.HhD4]OZgxn߻ [TU`~-۶. 9H˸},4o8O\|Uqx!]gp?^WawG讉4Ę?Hz$ \A%&xY(ЮR׈2wcJR|{6Lw(^D3BTوЀVOZdB,Q6p$awZt([RST03;O'apPM6KpEڢS YxkW5hO2CUcKS>L[?wIcL 5^}PFWؐ̈jD-·L+0f4gI(;^(Frňuyv `nkYwؘnQ&Êd9zKCNb{S9Vۖm-Uՠ{*S|&3C[kYvU|G)T׉Y!5z+ ZJK$|^V@~>;(ЙO:V  CWCѷXO&Cxkx>*Ҋg:]XYvtJ|lLr nĀᦐKixŸwyO7@՘jݏ6e@ZK*LSe^d5 "'Zۈ>%Rv2=նj|5._$p |Xֹ~}aXr}WxR샔1i7/n{۠ n`za'['E]PlD̅5%s2mdvIkG,i'8C!1 ]87kT@chۋVͦPP;x:9Fvv=-ځ2pnXo12ʭ\\/Q~ƖtEe>׹Y$]O㣗c Ko*B:3yOIeÏ09t||mE%f O,ϣTѲYWк^'qAM[C) 3iDjJwu0^lZƻTгM윊:ҟJ42fb/`$=bռ|ӳ.Rt+,)^ksW6&YNCtf{*Y5sU @'pu!U<-xJ:U$#K5 0-b'(-NA5!%I~1͏j=?7)CAϬo#sޙ"C אP&Gemvs"!*0ϣڲw%&niz<3E#D*N]ZH)(SunW,DPpЃI:މT?&v$ܼA3+B%D8Ý$im&N$J x!>(5 >ȏw;Y(j2c,>C`C+2pRRu&ϒOG~FJx.~nlˊ(C@Qiq,u@!NߖC}#u:#,#%ͼ;r fn;YVގ:& qHvŤ*D=EE BNw/!8I?MF4Gڧ᪺X%=iyfvhI_VBBIBźuSKQYλP ІЁΘ;ɆGAߘavNrث$T!JF8Z Zt$W v 6oڂc1]?\1-'п=L!xjO70Ξ+ ٬9G}pȑw;ʚZ-u6"1#)a"&qCϨڣ8K:-œ^̹(XUA< ,kCa;BSuQX]ƃ DN483 2LȤμGKrq:ľG}h>4/c98ǔıӈ`h]xIha*+(Oh$ؙ#oGދ&o]Q볺92 y"w!`@aF94HF5CN nJ2P}Λe׻#uډIԓx3ve0jyH҄KB4XOX :XagV9Is}'i xq>pIbSV?b2`f)>I1D;a广.X!Ġ;"frX 떛TlS3yCE/m;25N3T9A4o()ft'3 k'`)F^5P-bCxbG _K@odE N~Aݟi\xfh g/u4?}s䵶bBE&/;QF-ƨs K'C {|̳pyOK(^[;^1+\-{!V'wO ==m6q1^#b%'ZXCY3^)4;w͢SyYƗjxr.ʛ\:2AX>6o ? 69io$M3eY "/a5904X2]I Ml.mx4er* d{-.Wf7V}v T]D7YtTQ-eߎ$Cѳ!ն]%풆]<w2f}=FILB1oMڶFu! oHxu[:D%88Dq4gjYR&,%sh &wr}]ݕ Hh:Hzk=bj+|5ze:@HUf9\g!1+f؏9n K&< 1,bǭ<< .^#L%E+^q +ꂾAS85Xn >1\\f ̢9CBDfz!g&K&@Ð;o3=CJΠ-µxFID3 +%ԚemfݑHtx$a>%D&EWMہè;#Ș=:!P9:}ęV0Ǻ=*E軤wGǠSMF@ yDC|Ul 6 >78l \o:ŝ[4gw`%3q_c}Pd*[/11.,0_YzV>5^P^}y(o-a~Ь'[f%}Y$WSm8|{ǥ3&ig{ذ{+6njd>!Wr?F3lNbAetOVQ݃1QҀN؞lv۲TRǿ ٛVB ~ {vhH"B%wV$[?JJ$q#bEnj_v1aJyx娧rM34K-T|$-hb_;Gn4viivԿ柙$]{h)iJ`ҋ~CA̵ѳ[NޗN6s֩+.-5h#)%ڣfTv/)N'uv"b[`=/ӧv*`ot,]9it@q 4Bg¶|MEJF2sE⡡dž-TC;*Zw+XA}fq&~㉀E_J9aWΝTM t%[bk{'x{BqH ɰm*I0{:Ii7܋>FF9'%oso>FGHwr e"k7jI0Bj*x-n5l LEfV_o?6!aE̫}ojCe+187jD.{Q366QJs<ҕ2H. -U(׮. ׉ʸ7P )\AGߢ948ÝlP4R" 0{ܯGv?e2Cn kKvӏ۟V5Rz8^2 %.|Η/WL0 V5YkND'&qhpW+1XSA廄=.X6E͕k:F)¤FgX".V]yvһu$} ƀ=? mSwne4,ͤ 9%y'/~LhoGgˢ \%) =;z&bI?#ȝ*BA82g,V z|3u_lVcӂg6,nE-dRoo3+x * ā.wRC?֑ (بݓeg\YȥQç8!Y|:%J/.V9$-&,I4 %1z;Pȍ@יYԫ3t?!uU`@~ *5rh%2pґ oa5}e&U@62n,;Y#]PY>0";<`@@s>/_V\ 5kj,d[~lPmIXq> 25RO`%8=;3ՋV1 A;gq9B52E*'~6Ol.QSYQIQ {-?ւ:d"80>b5@#@v`I&k$Ml61hp`#5x ~H0^`#fH,]u^hyp`rDpI$}A7=ogR.4͔jn*e~ę:fUp}]{-;0ƁgZ9F7ہNapR@IQ2=Ken:e%63**FU8Oya5dGzX`G@td-g1($y:RDEߟ^FE F< lip-XIx[do )7w )JJf;K8!m? NeUpe7xuǠ cH٣Xu9G4BII'₝=~YLC1r Ҿ2C=PF-a-##XԠ}R6}cUoΎ[cLl {/ z0=^.0^walp1^U .PPhWuD_6h(<$̓o{Ofk#0onܺ7 nh$2vĽF>z~6*m,kݘzȫɏ}&OI2$,(#M?k;/Y{D>}=#2h?$O4(:XE uNU:KnW[Z 8 ^J+eD#5|](/UXqk2'w/biLЙ?J Ѫ$NF:ԾoCkPxa5d:jfsKZ8ԑA2vlL_ͥ7cR MEA@, \T5ah5ğ%v84>~ӂiE%Ib>==5N]BS|GS^"!!:,x::VUPBw~LJk'\"onkULh *xW>jV7TdEHxlY7(K5ƾ>bcH,)m,l?2Ĵgw37Zt_ފGvӲޛ1EfC@#MI3ngTiuCp[=J_ ߹0ޫEGh,_`cgQ}GђY!{[sgG"ގ sc^NL[覥|5)cJ-\D LJ2? V1Nbw $ %Yh("qbډޒMɬTڤ7>-X&Q`?D HU 9*JnB U|z=j橚N]9`<yO׋t DUszyG!)K==l#fER^L[g/ӂs5cn.0|BkοhT{& XTM/N@8GKM U ۋ,8#$Q:jAcג:/p:U8N{@N0PNͰvqe  =(G\a~OzZp،rYZ~t][(N!w:0Ⱥי^fZ3 V$C<ӏՕ$4^&A&pavJU^7 8GPHy2㚧zP3Q][Fd<4,Ao6Ob?zءS }\pD΅!1U [bih`Dldw.}h4FK _L =>MQ5JKCT%NUL7`} k˻"*cfo/qs|uV\j N(Ip, Ϩ3ҩ7)|]IG x/Ⱦ0WPt#|`\5XTfbzE 705D^<}N,Z =^e/ahXTx43hԻEKAa&w[˚]&w65a. Mw 8ȵyae8yF,AN!$t"9~#ҘO B Ȥ۫OVtPĭQ [J,,2O_;af-pR\/"G ،Ǔ׬sԑתVcdR,O:i["K'N"otЧHТk'Fh{f⒫ < F}уI-@$vqs?A֧"lh1 d?!J(84.i~Xg sEIM!{~_̐w:xZ󡩔 .{ \+opaRuQ" NP3}0 Sr nXfl&/O=KArcjT2pwԕQ?h!KP|,6l8J≜2/+KiQc0߽糪MCEYmIEO!u࠵RTj_G@-U3(MW:bN#.蜍0|<ŀED$&Nso^}ū 6$zPܨԕk%:1kI#TUe*Τ_kb+LׁЯN_=&!XZ0zN+#$mm-:5+ . n23f!`GbD+FԐSfΚ+4Y<:Qn9ԔBy"fCًjxJCFtO a>309ʅ$‘h"7^J+ Gf_zJxɞ JQz`!-E<8M)anwu  - VrqZ '9R *~#ܐQHZb8񒞜17qm-DeG5=O-HLq#\ϑ_9HwtR~a&u֑U_^V:I\t'J`U&y`&Eess?OWH̄i׈>=$#;0*]zb+ߢ^E;+ު$tW_O'/Zp"_d 3wcII|.;8 "*B)L%88Q$,tMUe6n?,'^??dbO.zw;MѰ{}!bWRWwtmPI}˷0vݩertLՉ)hԒCAH$:dS N+t3.dӷEStQ"4{~#)!I˟D?O#$e!hpT'9wmLݿN"ݗ9xY/3;w#q67jKu܊-FCfN)2퇲O|ޕWV 7f+;NG:FS L Zeҋ>03kL=uF-AXpi'"Wi[{W\?FqB,籁D o᫟b̻nPp~/?u'KY8=m 47K4wqKOKDrl`ӘlXx YY:}4IΜ~|f Y3Ә=GYB[ȪWT_MVpױS~9 sLHI]!<.E7^ݖs+ Q'7b@L8V<晅MZu!] [,'QBn˄5C&WՀQյW%i$Z}Tӣl{ 1p̾ߑg"殡-:I޽w%5Z8K{&o3+N추`T,(9$)# h0rֹ/R&WVFSZ?( p0D%=Ho sIhزt>5SQ0$4;/?! U@%51צ#64Dj5>5Dp ժ_ŇIu<&{gǡ}$6ŠU"B{}$U+۲j"H_bՆ5|% H2-,Kx|q)ߙ:>*;_us$ޤkg!T]nLF)smmIC>dnb,\b= +)| E2/@kj]eEbWsRFTѮ4ԓ7 gI.0`isܬRu2 ӷ2ƫz7=ehXM\SH*gnP1ґF0P漏@E[*X5Ź *.sY/ 3DQ4di5e4Cl *0}=G؁ 9E>j؞`ј~돓ŪvM4-sBR[6fN!pV(I%fxkH%ɚlI0[\FnB9l~1[!`:,&W렒u~UvHO"ݷ)Xiwj4uvoa 0K#Sp߬.Cɑu>"89#wgmWPyIw3<'VBWL”\k&WSIJX ޡ:%1Ww [.(ZT%d& xcs~[*oLl ~(}Ϫv_V!&s6V[U!e Ȋi[pE;Yv*G$А0XI)!zABj+fz#Мƒv0QKg_o}fOcME$b-:=^~W>og4oG#cXcc$RNk.0: AU)X |125 EaQRA.mo|"ؿ} 0[-| +_q:D2Ҽ|a.O4oo> a=:rnIsUp.#%Pzb-sD8>V5i;)Q *k](9URkʂSPtO\E05m"c2qOG)YM ufh7|)l ՀxUkʮ?EUt?}M/I|3">v />81;@Mc@%0`TIh"pYۈWwv ~>K´ZЛ|̓&" `.+6HW` {_Ÿ%?r ikh y(D26߮}&j2 Cg:̈xN $D<%dY8Օ+D,'wqZ@&7M7,W{:u|fdY3=+>`WEwlXPrbUt BM [Է (Z3dk-jnQn $%S4.y8Yy9 UCU22jWF;nC {Nq8N psNa-_JxCihKkV4cǐK/Kf'*9V˖vOou%;1Y^9vDC/Ifh>BR0uFIA\ܸk ׊!D= !tn|_%:P yW!*^RB*<>hQ7 EZ.bmD=P^wDǼ CE`aTm F&4%&sOPWhܯh(XW%}}v|=ߦ R鞭DU'ΕCqnY&jn@ج<9&0^S.Єf&W4Z/W&NTo:Φ?,jcT6M}g-~´к_P8k%w ,?N8E+iEf@-w6c(д*Z:|B鸍DTZ5}E?(޽Y"u]1̙Y t90X6>jsլI{þLk{kя>\6[WMgSWj(xtxӳs_q_?DsAS {ɳ 1?.^!B8 L=Wfi .TnhAlp;GoQ svP--."~.ON5k9q؊GGտ]r6x ,#E~jCkcʢukD 4{̱9DxqΎK$k;Dcuc2u8 b)e (D ֻ2_ +F| 2dN/q C{_zֺhbIML_zkX 9=k,r{4u=N~)y돗S9$.ś*?*JdGJmb'on#Y)$g+pLzUraD2Dn=N-HNUQL_ @]:zX͟G($Kc)% wfN$$膊lρn؇ sma㪉Ls(s_݉UժWz(aX0•)Rne"C iǻ)s(x۠Ɛd`ẟi{>jLn"Sz )ue1.R1 Tt+)gUq}[ }uWK(]sKM&% E@)Ϡ^j]M]3pJ[tw!Jx֜$I_7o N Q9Q ~̹݁H H@,FnC@Y ^D/Rh9A=8R4M:B_Nk#q_صb`ۧ >+{wc9¥3=yc٫ j-=Nn>'cBlvׅ@;4\UMk7$Tӹ"n*C\P(eRʗ?,3g ?T1$'s 2>$zGv)zs >^} BfnCB;\ C[}^"feQG?xdK\#m~uBiw(]P[B_ɰ7-b0lH6,G,>|K"xH.*w\= R ~&'V(ygw.I}85Jb9 brtm Y>›”r9vR~՘\: ;MI MAۘmsJy4eRuFEuO(a4w6PUDZ4hYwTtssm?ik%}fC]GJL3ъ `d5 "&p<䘒߆kLXu2M Zl9 Laz3u՞kB؏]1|-VѮ:J~kg}MhnSUxx A{hK*S&Ϟt#?,'lb\g{Ub4!LȪ$n--1f#Mq'sm J3'(I9Dys$=LΊAI|]hZ;,qM;Z&q^OW4].p^M nYj%ʑ(iԺ^qbzCÛJ:J %{ m5 5hj`xrZXo?M$"[- HO᭘aBnd7)Pbz RzJ-"o ÉQaw,f0Bgq[jJrޙ4R*j"ӫ6Aޛ&/Y04֊͵!ݦ|d~- x}dQD6dsDeƛ#e kD1`~xR!p0fyApK]Q<ԣ)0vb_=@/1]r9W_FA,Ե{DO8nbpyR#M?bnIO$);Zv^1cMTv/ Iލ-ji@-.6dEf:{LTBEKEhW\G}{??׎ʇEX0|aJ~hK~^' ;G RJnBW Io"2Cw.јKjw\u@0S;@%-sg.Й|^*i´xyi,`M\EecYއÃlBRaqtJ,Iu_\M[~j}^:_*ȵ,3*p[{|Ϸcчm*v] [uqv:rp72Hۢ:~W*qW(4<<DFO2Hcl F)Hn:)_^=ĵx9X/F-.$iଅS(ԬLvU Ψhk~~d%u?6uZψGa?RB> TҽDi XAIe@0h3oQnWdVo&:,J\׀k!7l]^ 8R1{f( i'bBDZR)hN0`ja<`GNZ9K_ B6;LEw( ,U3*<-_%#&Y#;=r P)q#5<0TVLn{ ?''G's9p}9`{Ĕm@f ΦhxjY,I8b= mA?Y{EaDZoqrZjK3` sUG.T;FrաXٶ1tU96mҊ:3<^>|JY_9PcGw ƣ\Kymx*s>t gu6Ú~ KAM퍘p.'41?Nh@cqP &b Y[?_6 ^e\z|mr,D:4y}DAN S Gp =T $ޚdt'r9y$L,c[n%Gdɑ4'uSs#హ@ILNfE &[EzGjی|o{ vލEn @ ן"GQf|& H[e(ik~hi"p{T+%"DwPڬF`^gEք2~p L| m'RܛX@r(8^6#Yق}4F!b-`*yÓ#9Q y/קe雒sR)Y^;9= erpO[Eh+ɿsc`"GC#44mD9kEUTo,x1ǨYyʩ_|X=oA;]tzH1)`DJ48 JnuC/WgB Vx) kIJ hzTs$iy-|(J]>X<( {beIi!bH^lC!A?0sy(ZcuBG Q"óg꽦$X@b65iS~$y] Rдho/#Θ:ͦ6TXO`քw=WnWh檘-8pW {Ho_n{l)m:Lv ?,CE4&f&IZ{}׷kq-_~i\ ܢ" IO=XGZ^*es}~JDlOUU |)zg tFVjY Fۃb1F 2GN&rʈ3ɧTiPyQ^2V33wg`uXXg3YP%0Ŀy |.ڷ wKoSXWhWD1h#o}1e>W@1\cu _56XOZ vc8-@Xրa'ɶFП23…C]* BQ#8yв1mD*5@~ n y"q.rGŦqI@ȪVa'c0 ]S-@c[2 ه;y?'?WixhUܟu$xџ 0ʫI=p'Ip :vQ@쬐':>SODUЂUwn&{uD_qb: ;5#͞0kI-!sDqhKK8#s']'Y8߹(aVRPHܑ]?Dt0Tj'I#Dη#]jJQpw7O_ADµqsRrAUĵZH,G4!Tro~Q1Il5-.p`G0l yWչR0\鼣P~?-n_fS"_ NJp#G$+Ab>E,15\P_[ξGPĢa?BOS—XKߗwq 5N`\ճ$wV<9P".˼لX r=ZA)VX*\̀8wǺc wN!sJxfC^Z:]> &k>Y~\ld |B ?Tcn"bA<ҽIG'38CӀS F%aզuzTd ZAHs|Xο GXJoWK K$G[#~ofS~ջi!PCooȘeìB${lM8[t)#pOYe{t4a̙x:-wTXmhcG`^0tޢ9%e/ [Ln\~o!rnܡK*lYYr=cFbOLS5{PA6t;ލ{JfѢ,ldG1Fz"fHp|_E oweʤi`]̨|l@;H" qI Ϭ~Zyj1 cn)<Ёdj@.tE~쑺RW1ׅ]*mh&2_՝/WQ뷙ҥG4c 3߿F ki ݰ+>i/@.-g;0s $ CG#V HuU .YNPdrE)R584+Ù{cZհVy(jl(@f4'u`*8Ofa"}'ql[qeRG' b@vBfzKzV:gϘ6膘¹%Iaiú[:/!7[^".;ߥ/XOf &,z"w8LRp6a@lg\Ŏ!od6%v5&rv"YiDN92KwpTm;'b=r1xH3F,^8ӶׂE)"PyjFBwo/³C=j^Be5I}% ym^d$*tQ!Z:TL Qx#'bv6p|w5p"ӐJ-6m LlYɶ ֍v,`,1/!wiŻ7ˀ} je#^u+~3'FQ"{+$9,xPboJ{0t-S s?9 JȩI:ay nW@][$ ?j[w-^aUצW~`;{HtI *rU\#ۉle7ݎ~na))@=ZHx-*:ۻ綎g JB63:>){̅W0'm߽k%&tn{dFxIc>pcT 3EX"B)I@KО0S/J.~(3nr2;Vmn8)[nkOH~edvLBĠ +LD^^SȁӦEX1~7FPXZmG{**.DQ5E.W{3Q3{Lۑ>Z7pG1+ޓu>%:b* Z9 g} ~U7%c9fq^^[繸҄RVR>`d cPn[8etѶq1EmKiYLU2=&gjT'oşT^{D7-n`;+^Y#m־6*$ʉC*1?mֶk. ޲^[IzWPbe)á^F_u!d[]=潗w=wCc_Xxj\Z &]BWwSoR82nO'Rj7Vuh +'rZRl>evaNj&?g^!=RjGwQ9Y$jd}4J-9(i`b0ī?`Pc;!DXe?9Om;C -vܯj6eh{Uג!YgS{,–"]RNOu57۸9즀~Ҥ]F`@u\(Q)8<" ;IXEOW-iQ>-YtPN y{[hr&p&|~ j@]F'Ma!XUsªE *sf"zc#}& f 6SC xZq@hAic$Bɏ&ۡ]"rpIUEOVí x` r>be 7nZ1 \t{Dʈى߇r}>Tm^)ŰTl7ҽِ$d( JQe1/YQwl:S*gf> AGSe/@jӧ-fzLF^Y$)9hvJ3MP-a%9 d;|[HZVTY=c%~.Ŵ`QIc2(Y|BZRFroF#5*bre늡Y~HU`?iא>jrS*R(zHD"3Qm\+:g4r.|˳+':z512H9}-ao7hzS[OK6]F t>L,{gW)ei}Ŭ6Mb=ȄCPN5T) H(xgr-|(E;y4;*1iYNMkO,&o߬U& 63'S5"dA2kr:%n$ ds~SvmS].'1"x|%LUEV,qxsw XWClwo|F'Vo{];v 7Ks˭{eŁz&|z[/lچ(U6y^h(j`}hTum6ViByjKSA"_Z\a588_'oE -Sm'm}U\6zHE@dU6aBlzVNs4A>̭TĚb%`"Ȓ:Ӄ^'} Map¤ќIK%ݢLpud& n uKQebHU`8hey7vcHxI|rz6+:¡KEoICp8ɰ$?U<*>(GLmNTPقc=CF" \^"n'IA0.nBŗ?уa!ְ"!,9ÙFtu 6mxZ.SƸp7H)Vr%l^A<'K@l惢2wː}[s=]fW&C;8-5/.m: [=6a:J3f5Ԗ-J*oj\LXRG,B]2]]6komUOO-e^u V5ҽ  ۆj 7k *y+HV˓ ˄P EHXɠ6 4^fffdah%UxrP7l&'|LDZs#*qv']VJ0p"o@dJ3Sdȗ~ !kю+z8xROߛ%Kr"\5L P2eɚn-E(\ J6igF,[wVP5Hi";;2+Oi)5lP*ڹC=6'O"cT{X%K zǃ^|=UBG9އ!!k-c@YS &QO]ivA[&ڋX+vb;7\Y}]a0۩b"*o?N/f-zA.FPqGe@CsN|*lVS ;iJJXD$vbӍJS+aXaΘ6s֡u]-GŇZcr0:ݽE:k\lDج4rGf,.$ոpViQz'MUCfljGofbHL %0Pls53tզ]}_ouBJU.*tmƃT~R{'7pH{LJt6 B =S6PBٍ[N..,<7/Bp@j :h*@;m,j&bG}ؒsA^ /4aWA|0e~x[x7Xx|&+uĦo׷l<6Bd\28F=.ZJEnR{.; ͪC74KK_"z-kXc!HC'liLqF%/i"ncJÐ F۹mu9͎^7%}~8{@aϺ'G-}>-&^W̽r]4XsAX.[+QerH|wf{vgxXMm#8..g ͜iѣo*?ycbB\6U^}2G)fe,>{A:H˭>9^Dmf?D[zQJ͌p&xJuaƺ*Z/lGB{V hB\(d D ޞ:Hdz5cii-;SLSۇ,^^KgvFR+䲦 CɝO_h˾{@Z#ol7-|E1*ts,S@,dA䔒`R.wCL I*cHќ: lČ/>L~'Yq ȅr͓|E[۴,7B+DSBRFJb9,:=W޽9@ TlhZ×'z*-i\8-fcXLBm}ːF "7{wSB7H_k=XG]펮{CdHŵ&-}*~v^O1qHn(^ȫJF6\9ޫ!x X|g?WҎSccU,u -oSMuP1@t)K]XkԮiWYee@Em;/wYXa+]-*WղETqOvۥQ(!]7Yp 4=92˹SG'6_R*i`Q2}lb sJQ\λGs)_P订S11bU W 9E5RZߕ b Bgjқح| s4޺VӨ,f)%w M!!a'{Fw\!9 3^h|ӃIF 0tc*Qw2_,d K֓v4K\;b6>j gϞD<^ -~6 _MݧY$K]1"vs b==[hI@9+:@҅O!}ʈfCDNa&9gĕe~]҄mڣ{pw.qFzd<5RiN՘d ?&GƩZ_He&>FP&SYW 2ixw1Jʒ)SHֹbyLo.WF_⡻;Ot;ޯ1 v¤rEݬ0zv5ğzJd~~stJ]º_dJݴ7M  X5Vz}ǾαA=_\)kzdrdLG@%-]CsA><-bh]-fpFy!98St)mt_N51R2yG#&2͞:/"5bEIݣN >c7V[!B׊Ŵ1C5qUӿ<31 jջGv_23GWf9Il{췶Z*]%{߀^)FNvN3bJRP''LܱNG!lLJ稭<sgQUVU\U|g=8d8ۺZ 2 I&M/ŌGP6S$La6KU@'@x&ʲQLr6׾EogF~y9h1E ĴT[(Om!ECe>U ->dzu%E%dA) ӆ0 ̥6X+2iZ 2gJ $S6Q ,OwoJbQW[$w1_$F{ER wsH`ikT@X(gC3 qjRZx2jk=yrvD7Zut@lb zLf`1ޜ0"Cĥ+[ 5/cp}8=~" ~^"#tESƈ#Ii_<׏Y։'D0+K0Ͻ#Zm,qp "q^]d$>uu"49\}kb1Qcel,;iȕnI1:P/Hg ybSOSZKv$=j;B`_@LtB#s{- cqlAyĔ2W@'k&!&`уCcMq65" %# O=-BcM]=8R[d[jjv@lg:`Fá)yc69ƀSc0|<ĕ$&] ט?a@8QpR7H.RI۬˷v n:o$d;ܿkq$YL$\,LA%y;pnsQR}Z!b\kŶxg& ө0$2+Ns\@"[U }ejDR](|I@T$->FVX;+/;\t㜹RS;i(1ag%lkx5i2] TRsyj&Y^- qL0t@X~5T+x.1}K~2}))kw 79jV"Zycek2fiwb%[lX<%aA^ %q!Qk#`to*˫TCvsDYh=gE_9Bl]sz,60Ӽ7lv2e]2ߨAZ9dz͡lUDT\3eP1H@R+^zt n֓CT# lWnϘ|Im!]՟P{=XZICp$9ɝz]g%j:2ܾ~e䉐:`6l8sU欄Ih+~D~ex Weg$:h͉>ı= 8Rz?p{Ub֓U-la!2g,A85scM8Wu" Dv8(gE#o"3D)*V`<ʅx^&'Jȿ5w}HO+9&za/6úz(zItqyLW5NTPj:zknjt#:複T=BǕl]ᒘlK!HO W uYPʫV`!)p xA%41Q1 vǁݨ:ӧ9vPX9qܩQHܫ"꾄GXjP1P"skUi<%<J(7QU/YŽ+9”V\z ё{aT{^pݑf&t66 ez}YX}߄/j;B :H4_ݞ_wi ~`ׯ |zM .(i/t/1fʢCyуVT,UCvywA7qdQ`5ݼ"o\y*rH{z0}t*ȫn7̬C0$V@ qqTe 4GeF9sq8&oq8\dKY"4Mf֘z1Hx5z_UPKZ[!tjN<+Ynïg&6Q"AFRIϗQhpxVX˜!$OkYhh\Ok !.OH*Ȩ|}dV4hj՝毹Aʿ&qk8Lw6ÿ^dVﶇd5sJM *u,dUe⌓q6M$/~hhhjY;X%`En(WkѿbBB^dD)tϰ1|:o ‡vȂ\-lS5jԐ_>(XDEՀ~^2.@ߡn@^r~+^& _GM(;K"N@rݩY'87K1lOZ&.u.J~TMȹ_ @eǹ-"#zn9Yqt^$ E̓GDl씿L2y&p|܂9Bvc{P:{iJ.$sF+? hE{ϭь?EZz$}QԱ-7O/=|/K(4@=]/NnYi'^UK8~!$\E*˔t?u/7:k.%4Hٓ8'AD W_r)Qow%Z@Bi!vju@NO[_Q8f}1dič`RKE9bmW%€Y껟6:AP"Y 1eh` AŤʋ%‚?wuNph1H59IJnP/G+(KqJ`7p͏*=bge&*CgEJEc%Wkc H;(ThPWXOȲ?oC2ӄ,Atd dd{_nbA ;Fy3 ˕Q.σZ vjIjH< rJݠ Nb"gXw|뚼"JIJܙ}0.(3$Mc6쾚 cM%Y韕dr}ݸ̂ +<ǽt8Y䦱Xϴth. CHoY=zԼ`/ ʋ9tf&0YG6Dwq ǿ SDǮ_GA@ hN=H7˰[fv'bEV몯% 3ȧrvOnQvMpuPi;o|sp=;ؘ=1ӲQ%3'ak%5>pI]G?F]#$6f<_+•ĺ:.gkO6''( H򍣇px<2qN SqNf 3my&ŁV<`)>t/c؇c{˶xle|P |F 2Gl$XC= ,09gOm ̯. ^nt)<+1.L 6ZZ0?2_L`K yW;=( ~ i 8kr_cp"h~X7aDDnT"iw;hڈ~YBoZ!XTף=% +O:Ko$glw)9NɟE̽ :xeJ(|s_JZtFW& )Ίs*b,Q5%|&HRNj՘"6DlKUA"?C*m'Y /qg\Y/*LfȌ$ifpq ˗J0mÒ! yf@:{np[8!ױ٠0l;i玆\c{ $S$҉H䌄kp_A;!0==QS}F)]%n1Eٝ ڊ@|[N>W kӵp60v*6wLaB(˪{4o93^}uz64Na,4V^jӲ4dR9RY4I`e*Zl r),h#҅)d/d2a}%Pe嵆rt9%+e?WDv+Y H?E)}.Jb72Ydod"+uьF!X-CG<9ع"LDa('K veaL.GB <.Aoz}NvP q ̊&ߴzkWĊ}toyZ~M>CR4d9`n >yGAѤ% 'S}{VnT'F T;5o-"SW Y\sTEZLV-r|Ď;?x5R(XCǑo9CފO ?oG | Gܣ~iGǓt%kg cΤ8c֩EuH՞Y=Nk׍ fvΩ}ͅQRˣn>;<ܵgNJڢE E8 1soW𘦖8a̗S!Ԧ낳A#q:Yp?t Z :;;P$+T[{.ݺz%SXAI\'uNǧH2k:2+R`\݋,lF$~G@'O73?sU;D '/r_bD;LRNkUJ:&%'JϼCQʼm8ZOig ޑIj#¶K9`Nx3pJv~f2kwц,.K87ȯ,j:6}h8^O;d()3S2HZ3^8xK Ѫ3%.3M!i$vC9x<`ѓNU2 ([ЕçjDQQҟ,f2::i(/Nm-Ŋ-=l鴶lÐ9iHyp6+,xBcfXl\H(J3/fw0V#i|6kKPp՚BOCbS֭{̢Fa}[72W+nV\l4fm.: 'l當J`Nk,e}JitVe:?ꒄse3Gjt ]M#Lb<6,tǀ]MϛO"o(A:4uIK_phڽJ#8^xLyުU|9`$:7s]C,^) f5\YS@ұj,X<ԙ/A-lDumE5D&wFиcXn\DTRo#!b N8pky#"@и#͠l]&AOh xvz`)akIܢ1(!JR O:-43H`h)v:JW)67M& C[gg킴‘ZH!:̕⸫ IvJݛm `K{O6)X7]3ŧ SZ P<{Tۿ80̓vHW:; ںd~zܷk4jg2.k˾rn^cUk]q##ɧz`n S(_ Xk d]=mYm۔&?8L߸|n1!6Y̬áv8'R"-"HٌXmf3Կ__m>aN'5Oם} |G6,4 ΪH*뀙ǂ&"lØR]-ԍbp75K̂ibfjZ?5Gor!0cA2bv"lE6._cЃig:@`z;Y.+1)'P P >@tMwDnͅ~iPa߹FїP @/ߛf=*!觧F|o"q|!x~#jriȨ֓CY0_$ q7Tm}K92lU cr}ft:ep6j=ȥt m߳1/b=oR',SRȍr_pˠ9N%F݆A6ekaNzHIC@Jg;W]]A +Qf2 %%RmFK8BFŸ3cr_')%d!^=Vd!# (a}YaMq Nf˕Ԁ;vLzcIezΊ9EIࡊ_A7g̃:p$~47oꚆ3qpGU?WEȦa&K-&SL"<Ss+Y:/bV[,Ƞۮ4pXqjm1B:+HDqB&02ѕp˜ ú8&jB-*)~-#7 k#X~rO!P'aV&v 4k+{He^fIpd5}%s!<@;u?5RP4㛧_󎅐[nX `E>oJ#"KS Ͻu|ߏR~#ODKy2}b.]M+ ueu&Y#.LoU{MDj )4*IJcoEro!*օ]͖,:kcZ|u㾳?+w]:Ԍ`CS6çbt3RFo lzX z'&rC]٢$vj$А? L]#r<u >XKo%Ʃ^4{UB=$w~[#j^bRFm{%lY喥aٰ<{H/*_ҴK3) yñ/+w8JDL2˓ԓL/4T.X%ub7 Ӷ/ j]Ř/'Z2 ä~6͗$:$. 錃:ྕՏ|y ΉZ+)M~I-Bpz*O£{fai̾ζ6S/dF3HY6z3aJ̈_DJɋ&VSÆY_;NIVcs7o{2X^뒣EJer1,Y{h1V~2]\ ˨9 WE~ndj9mps-΂;;Nf.HtvVXS| u&7Db54Ci<7ޘhS7=8+"SiT*B`%aRC)@ s9~b{%*O[#8@.f·bvf9}}k]a)6ʇ=;U ۷Oʳ za9άW4Ai"mZݔɣ|3Q> <벴U*e08 NO"F^{궻yDjB oO3ȋY (jݫOkr}d DӷQd;H|1 hDr 5'e+|G4=k!G)zNOT+ؗjR 2QV {#X*m;iRjpY{sNt&*]$Ri$Y˧uqTsU=yr+1Sm;" ـU\6eb"-GM.A[F5ROΏSa_koŽ[?ޓ@1kfzT"I |&>5Q&ۨ$c%*+`R}MUbGa(Kyq} ֑TKX*sHHbnËF^yq^ 0]=,x| Ad}\4,#x͇ ,-cg~zƊLk` Q"PTFaPUBP 0B(|`>OeOE:#Uupap # Ro jvo`览 " *J4C,YDrq1YL49/!bRJoKa1D`r8gWmqhaB,Ԛ-Y#Gν\ei?ZqCHymbO{A̯dJ{0a˅ -P?^d==6pƄr5fuv>w[aBM z BiyW될?,n8QYX&2(Lۓ+t%>. q@M(;{k].*nѦz Ć'HAj%ܑghE2agutOA7F j[l,N:9oI(YS|E.)VV}Fv>TImyXW?)4wxNHI*20D>E2JsN%҂C1y:NJgSYcHxHq}@y ~lʱ/MVn\ʔ&D*>7wPO@A =vrA 9oZ*'n{f~#1;VhHK"'58m0}J{$2mKO6_z{a4$g5?߽,+-Е$?O!գX_Q=^SP-8 [PYTeo8hi%LzbCVߧhŔPՄ |'~Z`j3)^6QB~ԫ},>ą ^*5v|:I5'\E!@$Wԏ$ "^r3t«RI3LanX>–ņ$A91Eʒnmٳ6zX# '1VGt&D%*W?  E ,ۈtX77IOkqY5xXo%w|oI'3v)Go=9RP,/+/wq};NV!Q=[q2&mIDݽ1u<^L0UY)j QdK=?(x=R^"oP) Jt0Ej1˃{ly*Mz8{q+*vx7Jts':?,)˝sMdrQ`OÓ%{0,VgPXN.a|I>15 w. I;_ZPƿz o@KK[؁*. $^l.G v5!]Ӝe̮.4;LNgKDd _ %G37T @HQ%b߻RVzOQ:KUP%8Z֯| sG%Diy b61RmYAR3g qǓ7킣9g' ږ՞] pDӓ;~uX%=]֑2$1@ Q =6d{̪SϬ~VPgBPśD`})2ңo/6@3DP rsd-g5[K-9Q1ey,]dQP^YY Q I!M%5C *eÜF>lRl_OI"pSVH_4n[N ʶ wJ%|B+VOAgJx^8^/Gs%LO۾9y*T /7R Ƃ*^̛jnϔrtǒ_z(5IpLYIǷ](m%DeG,9,݂RR@1""dqU= 3W⤯8x30`0ig[t?m PG(C :Ҙ}2n+h?B]_/Sv=7.AͦZBD`לӹp4;Q589N nbyˋUPX Ka8{uE+{L?޾ņ2039G_0:e֮$:U; b'Xiwqwa6̪}J'qT>1sic> ؔ 42 g{)R7O|qߑ \sQ|%v]s? 2>K#&i߀Y]L&SzbꕲBEB2ohxYl%&l-zLs4qWcO|t_c|{( [`Ӊnո>$C9+(!q KZ~̃2{Z<0tW}m7JFVT#ǰ2 @ۢ[icSLecWv* U:6 ؃iƕ|h%ƘAU?:bH3 ^5)QD=}3) .gwTȊ./G0á0 oip-.Sd4$2!r<Vͻj /p8>T$S{s'Ułsͻg9d MLCnP'lPԕ.EV&D J\i/΢Qt>DbPb!.Z7F̃ZwPᇂ\ӝI X C/u8CJP<@BA ?2,z1&|)TYDd`>/ cG1ocp5EoV>WIf&A!f\l6f[{A,إȺN8^HwW.Ʈ <a#pGGjIy'봕i{)P>"D1zD ՛^ pH$bXM>FV}8^o!KޏxEŔeˣFIDW` 1r "]<+uàb$=X T#>vk<U2dobxXN*kz;x婿1J'2]KHeM+ӊXxKWo2^~3l~yf'~/7GI,*%R 2wV AG]dI}+VeuIqރxMmq4H:k(V xw汆(Qn 9[cUblplQ $1TkfD+[>R|&M?`i[帻 i Qz6\/nH6dU\V i[gWQS9xQMп}`-uN{E(SkbeGFS&r7$6{xjIPIbkTG+ R6uVmiv_{_ o%oX|B;`Vs=" 9|JҎg6T|dJƒzQ~s'rAs|(u|,eb'|噗]`dT`1_tet@c+Zufz^j{c= &`$%h\TfmCFTJ beoYRۺ؞>kAoN 6q4Nzۈh>;8 ~ZwG0O UuAo ցNd\5-JBHU ܊hE%Xo=C )̿ ݅*j\&rh6(luU|EB;0ɗ+7q&R^M˶<%COFagO; 7*rȼ&B87vSmR*%]X'kbq8@sl`1QQЗ;NV XV( Vh^p)/}tb3J6Zk ђgp|j+x^FF "pi1ha:iɖ)yj.ck{4&t+uađDYW:~΅1VCOsLÕs e8BґMN>ЁA&7:C>GrR?'2nZ&vlDݔ< ˕ƀvHgިǰBkl_H'#S K5wT٪y0c2wFZٻQV3טg>oA+]x0;=m?ꦝ6k`d|L[)39*qwG >tj14XOsǎ)'ҼltNX.?(zcR,V ͸* __ZA+gD 5#٢ aV5G\W&j4n*]^d!RCզد(gci39KhNގw 4ӛ+\*tbF!X#G.нz)VoY+J6v$ĕ7Za FR6<#gARFMaLNag{S4J~',z o2K)$CYa,1sEe˓w 5 N b 7اF:4~7oYD|xEЙzgi\ml~,cC▃!@73'!6%< Il=Q_QT4p@&0 bh0ʩ\wE\4=|&ӊojY9FzIAJ;ߧֿTѕ 7J=ڶa Іc8&o^ι̘v#;[@E5G™mC qa 7GERsMюu{۷v0[өXm(ȁp+FG8l-*̳s+ @[d(&tIX5 I+%Ntv'U`x}þ]7W/\ޯ:2z@_Gj٭5;ETؕBRkG4At,](A6ibu z/)dbOlhG1(cƭ)>P!LK5 q"=%kpƓZeخA{%RE~w3$cj'M{r>T;HX60}ѰExHEkM&Q_0*] 6G_й}񱈩j7 zd$Ϸ׺Ṳp@I(Kd9=B̯^6B4?Zb~ws~:UZWAe^6hI& 2C*тŗl.a,5oaI+bM;)!vg'%<^XROnJ2m>fJEǴ:heE8񾳫j~_"3+>};a tHc}$kmI {c!0sB*- Th*GUJEB3Sbv_/"CZd* K}JyƆ6+{4\ ^_|H2J X.XlܸS.)ۼS+OV9*(D9f،{<줘Q" : YZ