pki-ca-10.5.18-18.el7_9> H HtxHFa> ?*}}~^2 :&᜚:|d(-7n*7N575706e59f5130e2b823757e554128140f1aaadbd@H _K"(@:Fa> ?*}}qKUAX>Vp*3l11t*&|>8X?Hd   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H9:GiHiI\iXY\i]i^ebǵdLeQfTlVtpiuivӸ wixڠiDCpki-ca10.5.1818.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.aʩsl7.fnal.gov%'Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤aʉ^2aʁaqaqa aqaq^2^2^2^2a^2^2aa^2^2^2^2^2^2^2^2^2^2^2^2a^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aq^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aqaq^2^2^2^2^2^2a^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aa^2^2^2a^2^2^2^2^2^2^2^2^2^2^2aaa^2^2^2a^2^2^2^2^2^2^2^2^2^2^2^2^2^2a^2^2^2aq^2aqaqaq^2^2aq^2^2^2aqaqaqaqaqaqaqaqaq^2^2ar^2aq^2^2^2^2^2^2^2ar^2^2aq^2^2^2^2^2^2^2aq^2^2^2^2^2^2a^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a^2^2^2^2^2aq^2^2^2^2^2^2^2aq^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aq^2^2^2^2aq^2^2^2^2^2^2^2a^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e009a97873f1b5f7fea2e65e6c1c61c09072b0193a618b7fafee22f1208a943f38cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-18.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-18.el7_93.0.4-14.6.0-14.0-15.2-14.11.3as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-18.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*I@c,7`咙 )"v0G >q| F+\!0fB;&fwH}u^o.+zKz9y5^#'t<2tؚi"T{n@QxZ:}.yPK|.㩄O%<҉Cl7u"qo <{ ;Jd6~䌵oLrR<`Db. 5Cf[jű;لyc,.!VԸ{ӏ^bq:~;ljE+E&%FӒ 唃(טEI>:CO8hnɷf5;<=}Z0ktnahm.+GH6,8!Ef0~C^o"9]lTrhnE1tmcaah9DH?:M#NYXtukW$eEu֎@8)9([^OqةEFT*EtVń nR4 5x N$aMܵ{<) Q8a3#5;ǑiRepK3ͪaG0yZ9#輲R)Z XDW丝b&m>U{2fGIDS$29t4asT>jTo\Iw7}w֛v\ o?7.Ah-a"$mCҖ.'b=WO0 (rή"le?*UPPH$ mCV֢oo9 tG(4y9 ~RQTAr<^ɘ`>j5c ;Aԍzĺ:CNV~ b$D 1A~Nc}fh}y+QD=QZ@٤,]jwFIˋssJiamқ]OYQvYhZ?%u Eu8Ӗ71zi-q.ͥ:Am=f:$EW i pD\=_W( %<8amneQH:۝m@qRȾǢU䘧pn;Ԫ--3߭,S6ds=ȹH(,|As+}2Cbvr(p .cD`~GZBǃ&Ja ɀkվO @nQpL[l*t2Be~/CEՃSҤ ?L&:-jOБv%(&"zq En#bJet- N achdpx*Op[AH&h9 /'$\șKCօM"exͦU[mC~etl;Ø=3ʻ7T%WlkƾYrYNgBUCb%tʨFg xx~ oV bf֣ӣ.ĝb)բh2fsW-w*lٖ}>Y1p4Aځ#]7"D/j{v~A)1 @^Ĝ {$GSV'sYŁ  T/ -WYZAVXOŸ~g%΀5FfO{kCw#[)COP3"sawe 1"Fh͊ N+k͇_~=؊]_ 1o->&{j lKVbd:XOE\΀y畠c 9z5{Hmmw,ˎ㧆6#zEr*z5r%1ፃ O@SLX,mEqa`GsZEvWQ f6ep ~qͲМ20o*ov:?yN`7fS{o@Ff&6%Lw/u(pX8O0Ped^wp ,𞰺%R)CHHұ5nB/uHݦ]ԂGtR'CR$YE`+}iŗ|qOU!ųW]IJ bd#1j,#>u":|ZMQ37AMӎLYm3OSe+/z|ϜkK[dh4Ig0ˮTAͩ`q=fJ: yxcb=JH à&$Y]׻8Q`WM휕Tg䍔`Wun?,gEe + 8ΚP6o5xʕQ7r-;nL(D J<:]%Ҍ(Y}:Z@]^=&< x>5Ejx*ϪҀk[ȷL w޲/0p[W&>N4emi(8b<[-$0aoUvޅ^{w!̧4]vT.:y ܍"<PG%w VTgw,0*Kkϩg5 67Nj[sAM 0r92L-el'r,Az໯L 1_z;%_*Hg6W<ئ:^Hq)x}RN\GGwލZRtO2YTzl$5 /p #yt$1SP 0~Wl.+O wn8kx=65D7J:XK+} h7>M1Kob.mpcA[n&D)ltaaU ւz豗]kIdk4z.A ϤBU`:P/64O_chYЧ#,ʟ{j95l_D"|/}ig]#cya=Kr{*m- gR:D^쬿@ Rdϫ4S+r| "g]Ve{A7.'½:9χ׫+zޏajIh(*v'IoG /I5p\,lr/lM {L#s*#ZZ ~鈄^0Sj4)?~:G)TQ[=0קPfnꉌvgjmвgoat`o5]]nP/@x2 6bp2CB ׊:9jő8h:iW8ϻ9AJ_k^Kj 9ceJvNdJBKw Oif[MA]nZi#LR^,D\.!?e1rLCoH&$@U`h4ʝG7Z֖+Ьsԣ˹ơi(HQtdcOh `fJh©(-)`.80v("$2oXl=!^ ʳ.u(]6j3NHa^n`zu,!>h~T5ΫE46J+'|`%aQlj@G '?DŪI,.@z)w7 ܧ線Z,ixy3ɷH@jjsɘpȫnCֈOטΙ fhRȎኛE ~'UǖWC:\֢^Pxc&\]'6DP{=ƪ"Ԓw>DO|[ů GAij.4J's%/nΨ?`'TVE.jame%q(g*ʐqm)>|,'i5ߐy]МFgkj[Wy*.D`a4 %ǐ`ګtYMn޶HFiwTlN'IF*1*V`ATe;!)؇jqC TU?-B0ך]l!UG[.3K.ZpbX+:\5Ewf7tXԤ:+cwo=%5ZN/lud&W/DM XRgtRW' f!./n). 0cd0` /梔sydnZ@WU on𒹆uƐ1iGeԦd٘:4ǚ063 ZoTNVm ǿ3>l׫{K-6bz^seňSSllq]3]j+Ih'`[ǻbWJM S^wauȘ0RrXDNYm9Ŭi[DREUO]|\t4BV!q^T'J[z8]$P5>FB+Fp'lfCT֣lVPaeEyUA`"qC h+Snݬ]af9 A2;&/_ !e1;khl9-AdGnk(ogw&xj׻Y񠇂 X)9Qx:(ds@^LO6Sz܃߮`S% 4gɓY$yd<}E /ɇmv8=lIYѦ 貫es=h@Ezƃݚ#oNF/L֜X3.؈2z.v2^NhAb  ^[#)DߍuڠzfPw{cٌɣ`Ofjo~ފᐾ I;ȑ]?6ruVcˇ)*P5'L"&}~^u=~:K׸~w4K-h~4lKc"#t#`.ϔ&\wϒܟT,9#0_;=QFvm' _)O&(5#kˮ_o8.kќ)h}  }fSmg  /~<꾩8X\'Çr K4D4-`D툙Nr&LY1 ,ە1ؗz60nqQ򟬡(` <ƈPW< |}p6d9jdk3LH_nLἑz!QI5` rzĥ+X:|+v2#8ube4AE H hp{(v25(0O?<V$/YI>HǗ2tA&5 zWbuc c sd&Ch&{»dN]eK\8_}qd]cfQecҶ,Oaja fp@7luNWg2R$qqwBTJR:r+땋"n5BԟdA*KzwQ:'zYG4D4(oU~{hvġh$WIj_J1inFJQy'/´dnoSvuԒo70<ׇ"37ї ~i^՞ۯpx_ y#wyiؚSvs{23"f]s>uqX1+?"ΠZ$i4o05Ji;L|#5{N&gAL+Dҏ8".7Kl i\.4ހ?&9(,r>\ģzk?s'mt冰Oq ^aiF 5w6R#Zdv#VNw~O4IcxEo-8kGCY2h(דɩTR|P;ȰsmNy&KCW7՟Q}Go*2(l蠭}8@{GahbF?-L4?:S ce}OcC[mؙzo$.TQntiŤ0k^.|3r)e =M&ʎ(Ծغ7z~乌6kFwX|aQF~BeV/Y/t#ÙnKb;,nL]:ߕ6ϙv;w%Kz2l*ke>B.iy @, D+ȡ3ES]]Tg-4RuIL/Ү(3m 5ׄ XG~"JCEɆK)q[f;:STS# wS$Zѳ< 6$b+e1hC`xg> nř+#dA33jW_Whu/y֞`f YjӍ]TIGGMʹ^eWU`T4 %"R{B@a fv{WxL$&;[Z&A,>'xcvTBуN![t/SJ|zGA< Vӿ"1&h{|a1B UfМ]j~K}3[dorܖp>C_ 3R}peWt%GU¬J ϏYby^f,p7]wjx*H &,{C'1? z`k}cݡXAgfDvo(5> :f*䌜 )T fYjZv hE,YXy-ts-1 ㉞ ~@+љNl%[b79;U=Z 3k6zQh6-Fgv*sZ*Tl; -߅Cܓ :;ܺ8xZǵIջ6a J e u_H?A~uFb|\l7 `hq-8d4ܫFG`A(p$W ~|g.FߖC> W1;i INC,<hÀiReɟ\eHv WJ -v1qi*MkQlu R=WhR;D(]$kyP(/efaWGrA520$t3(GNjY. [fɜr3,mR7aQQiIh=WtHʯꐢ0U ;>rEbRiO8Pn\ϋVSPB 'O'bRe6b:?7kD22{'GG;0NQ_wC]W,'!F~ 7&,2 :TժJgx$!lCnaө\2W3ZO䖢\GD_j:,QSU4WE+N]TLoB2R B+2tG.F9FEv)\mf5hbnL4ɡ!EpDr)IT$QmWeN5j6LLŭy/AzS(J-,4Ykɛ^hN4}k<~F(7 -\y(Ơ|%=q "H8~Sٞڣo$ϫb;8X7؉3Sm"<(jMA}r4Wr\սWÌrxqg~N8t%GDP=ͫ14Led{jcٌnd"Vr0FT=tlp:[*_eɪu1U'ҙ, -ttzu̪P,܁%bzĈǓ,}-0o[sr_Q\^͉Re0Z>( av9Z.ڎklHM L{LYT^8XguӚ=S;ԨQ8[!R\1n`[.RdgHO$xrP#){ SEh4UBQ@WpMq'2,\fu=f +~A^aΘ]_1P ˦.A<aB6dv#nD?뿹DA|oA>czUIg^$#fޤ?7 .Ms xl(K")$kd棕,J%9XKxPZBN3 dJJ0-zW[pe;Mw K39-+!-|CaL1,8:e"nj^9-8S\ t=G%S1|t [OPtE5X1eGkRk}C܌b#o4m rcSdqrhkl(@܋Y1dN)"9upԵzXA\0ٴe ʬ;ԘJ,eA=oǞWk$?p?*}. c[ᠲ)ȆȘ*dʋ^9UL,۰;+K ѩx~HəF@UV[`ғm:Ξ`TyjiA2y\x_.YC^{rNQZL'Fsq~4D2Y+<ƅpq"󑳸޼llK";?\l،}lKL+@tpx8 $4m5&(Z! AU$\0[t%Fǔg鯺l-{CGxV Lpw31oNyC M q4!%/tw^ѧ~-\vekT`?14hP~,k$5یd&dk"(,#4:xzV# /³6"f aPXxh"^_/&fPR_5A#mP0ZsD@Z^u}=#Zœ.o-揳',}o)Dtp\HOCgϙdkSiBՋ ܌yG>$tl2yuT4d%:0I_(ʌR*VmƠ[MN'݉sUz 'n\kKٙN8lw;>igx*r)xϚ\l#eVCdّ#W:5%oou$գR!V:G4SSzH$0yBRCM]1+jd iBs5h9M;s$Y7}DP^nz/͝5 A*,zckol˶y@H'vhZEzﳗOg4v"UAM.fFRG$QZu]X1(RRk8;ZT :sFTs]aCl}rВ*ٜE(hFw{Cؼ6ip£K¾3n2삄!C$yGZ]^21~xyB(V^LD<-R{% {dU W<-yv Cj zs# FiP%q vN@|+BXkWNpW #=`>rlދ FF j=;&¼wgҴ?99tfE[akBP[oIov-hlT?&A֤L\չ`;lZN6D]K4SvŪ< }sƘ<<$$cSYS|D1]h]@JzN kcB-2F3=@ƃVH݈i#tpT%~@ NN?gOIibWOAh +wol$L3s{w!Q͒b⃐&7L< e{bf6I%7v]@&YkT\lw3jy!MJ-Ei;hWF-ʵ݈15 vKS>$.Z.WRFT24_MQfY j( BV!6?i1<;/܅Y0f [kjj=܊>kd旣zJ=V(==]$[whB9 [s[K IPꉺwߏmK&fLA!I_f 27 nwc!/f"71~AR@NgƪЄԠ%K ~ЃpW UVlm 10fKʐ!E\N't(\sp ￰`}xT/1\zՎ-8šD!4d0w"_* $Rrd\7 8 -zGja.~YgcLlKW k15$ Um6<󕈣I &LE,QJ$̭Acv4^GrL+EZ>D'~3ّ; @OiXg ,GY$O$%}b>\򽷏tS%M8|b8'V)mW` sd5$-k ::$w$S򻇀!4<5M?a3mWbiTB}fǟ8#z(b Q|m}CK](5?t4f`'ԌA^іν lG:fddn?h联 ~wԻZuX~llbJF$4|HW81p-/:YdxCCt,r![R+>ӢhXK9՗gp-=u5JA] Dap 2K7 >[Yͬ "T;MRg*\p0}cU? 5S`Oq\VLӚ>&/ڿe۩N]hşxwT +;Y$J2d Ryhcs,73v\oؽZ¶7:oce9ְ~vVp!ZG$$6:c@He,G1z#*BRhɾ3i}1[CA&~G{rj丸 g-HqB( ٨s%bbP"K+`WN&tj+DZc=vץ0U6ywb^5\e4FXp#~YR)Wv.uR*ԢLRޭᅟۙrs8+I$c/Wf| ?[↰e`jK0{L˥,G&r랙|㿣* hKxP|әDR:^\A*ieA ʐh{q?֫:nAh`s94I]HďrAP!w{(Ad *7GK[8Ȝ@ض7rT%]QALYa F=Y^CkB>)UnWާkdDolV_}o~i s:^[݂x^jEX!3v[Uu[]Kp$U17օ\ dsT ,9;+CIQ4њ!sz2Ʈ[Q5 qE=|0aFʣWH"T[{DNn@G W |}UھVpAZpk%۬ Ȧ@a(AhxQOԨEhhQn$Nng;?7ȉ 8~9S2Ćڬt}fб^MW@"<$f<"޿`}#DK; BzcH>`#DTU vӷ5bH!| G{ }R S-"[9X u*!Y?$I펓q 2] a9i{&yX,)|,bֵ" 0QQ rI-4ݟzTkF=H:#ﵗy3v0,U^Ayd~+!n"H1;XǛ%ʰ?V0^w!`onU?_-UM+qY-_~Fёn$f-{08J%vSImQr &DuKPDu%_Ĥ9cC&7嗆oQbšDͨDT T*G1gF6V(#+ȬבVbw]ct{o!B?T@IoɾVx)wq1uAul*pxށ{q эP3!)f >JOW`NFܵ.P5OAV73A@wľH!0"~M4u7`Q=C#f7U}c rlN$juT2fg^፿B^_՘dJ-J,.(rn/:ˣh){$` W6pp1jE^RUT[&s0D@0o#庎uA\K}PQNE h.j+4U؏h;.1q+I.^ (]::9 8QE9;"I^ qr823ˇ59=ҳkuus„;,]BM]#|i/r泤D>Tr]3JShנrC=/Y؃ysꢽjIgIb'_xRrvB(G$z$v*rpj!Ezw3, $-|JLb$v=)/ 6 MO&S\ /bƄp> c+O:u>@t"xnXKb9.wx[Q>gAHb|k%[M 5wT0Ο]5DjtB\fkiDk 833`ǽ=Jlvw@u;O%\" 6WC D/PjwⳲo]k6~VoEz"XTz xϺ42^|[NXP?.6̼DP6x?l8iv3 =2 ik(.aO‡ayxIY Cmn0Bϴ +ٳ2!zH1yImPmobըKVZ Yvhb)Ll;A,ﱶgiWrRaw ;IJV wB>F `o\-^J+~ʉ=>Ч(VP\gi-ȵ] ' s>`)uʢ-Ce [iIYb ]3ljq^Ijp;Iz(8480Sڻ*!܂ڡ%G8w*W{6ɵsp\S&qZ3㇆6@H,(r^U^yrGЃ>7X|pTݛtm(mcPHv38&}[k:`HA"Flߋ~7ߕ'U0 D~(5k'!NlK `Ҡ̛ za wiׅV-Ťb1s,/)Z-T u@v䎹JxFQ7e=;R`a.=kduD6Gt ~J݉cܠ$20I)E`lպC @Ѝ=rWoW\4WiDձ. LըЂt;ECof'[^͙'Cƾ*"3sw"eZewZa3ҁ#',)-i`;x6_gkR&7MVa1Iyb:$lW2S3eں;ĉd m t/9k q<79~i/=>ÔV LvZ(-(lEG+ȑ=qXl]zq`h + Xf"s @|d%m0NK0Z@iVmڢK٧1uGo(FO! Í:9 'N2rXz7ҩ:p,-#+:҃Ft jTi pSݝaHӺGIŋ8اuQm`!hbޚt~99~fuk@ kep;LP)-Sz:d:dKo5UӼeWt\*w拔&MAv U?zVeM v*%\ 6vW 1A%XH)O‹^na/ lTΞKy`SVܤ$ݛJsm#vnRP]Y-Y3Pt^EUl ӖekqQXNED2۞4:k)G HGz'eg+Y._\C7_ġ; UTb="ʘEh5Hlࡂ{ɏ*fr=y"z5at#==fBUZɛp/VH('PibE5yLH*L-Hp>qSrl L{bNK% /_Ƕs, zx^ψ}ШlD^yFMU=V CHCPHR+ůXa5w@Րkn0KOG{,Ll=,oXߏiD\gw~oCd E>˦[CL'8_`{`9"c6q*J21K鹚OmSJ2X@<)0#oa=L C`m.`Ntg-/ߍ9v>%*/A^'WM)/7Tef/Ad@;}PP8cV2$!^ xkuYU rnՋ E1~J{=T!*҃DF):{ 3}NR_٪JP/(:}GTcZ pDOpzv 2-ϫ9:^/wE2 AR䃨cCmYB * $Қ~s1ߛ`>,%C>]z/58{ 7ӤtF[xn^F, xe\ Ag'*Sj{7x~nΦ}^K <~ˉ8Q6x|*2EK -ln{E6ǀ2p5`巾MJ;*HD+|$A͌xMfgPcs}i/nzcRxk]gx߽tq|é $ [ۨ/=NXqɱV̘ z@c> ➙ n9Gm%iե,36|~ n)5$> ΒzeqKnS-!K S>_6sn. XV "`aӑT V8{CG^nKKmԣZz׋;3B2[d/.EƹwX`e z~M~i<6NT:nyVR̓j!mSv\@zJ$%@rI'8gg:xHmzt%[vGišdnؽ} qq .66uu*7p\6-HU|DfqlXk~w@[;eK,yXV_G~x6q^顒XOf RcwP71f,? `Ts^ƺOT+9dO:\Rvd6&Q ,kݽө)!A4ed03TC щ ި]wèLJVm XΊe|2 b!&}`0"]! y-]sT^^^_xI}Ykb\2hXD>wf~b?T]_1z עa9E2ڹprhSÓK>fou{uG^6gß@?< -\N6saE3CݕYO ٮ`7RER3!4IzJ3shà^MoDϳ^BvicY{Utq}XP3ԃ[4 5O"² L#|̛PՌb0G^YT|7վ5`L-3wm^%NCH !Bu ~oC4B pcJIġaU at]51>A3#,}L:I gv7ڣ[ai?Y- _nnCȸ`荲//PԜ"yf$/N&&>,Y̪ =VySjTaH1gv'f|Q|L Mkv&dQ]C[|ñ f#fwLG2fa<9܎EYwѸiۼ\C I^Sw?Dc#Be?QC,uAE5XB^; I>e3P-&(t Yoh`* `vTbCxÀ,AdSSRj珊!:>!rL~FhkɋK 3v$۳VfT34M? jNMq]4-B"zs:&gObg~TZ^Cⱗz-,ε$[7:Yv;|S#>1Z.}Gd_DWQ&VEN%5a!u2UI8u\Դpf5ţwT 5{Nϛu{2Bjo N9(C\1 b?S!tFTOÚxKÖPJtب~ ǀ [ک w߸~r48BWS <4y^W q-;Y9 OE1":h)p\8+GC6p?9%ÅeR^q|NWSLdn}2e #6Vç'Ou d#=+Vh\n@/U>&o]@.3II0١Nz/IYfDүЌ|WAS`e [/jоM;oz }|g%Q(9T = yғ׾e/OR$; t7SΜ6@Pݽ럀]ˎf؈z n9[~HS+SfٹYR }6.;Cՠx}qIщ_8 *q~ΌrVo9/.C |d Vb-j*}[`kixxҠlXV7=?7Cdm!Ȫ/&E?#X%*aΤ"^H=cI>M!,T Kކ>EZЙFk2_4KX15js, l0hEc7_}LԸ1۞K@,.UI&1j6KU\\`-!l͂v$tnCnl+*l" P.(TȲ!hz׌V=IUTBw*HtvTǻxCm"-WcwBۆnS޾ҚQX0w*BjD}S+Jc "x1w@FE6 ;?r8絚 Y[&\V뽳Qu6Zp'Ls Oٜ*̅T)9"MܥѼyV<{r+r.+:Tݚ;/T/U&o0C'^}`0 C7U>E@زjD6-pq5n`JZ uѨ-_8a8nJD^ެ.6|w! u: Zu5.E0@b=,Aɟs{1Rd|qPJ&FT,DZd^#Xy%)ZˌlqnљgؕKz |\/﷾*T:]^?F(xܝxp(F1+ ERҩj? GS8ßG6ЗŘP\^]03W7?glLI]i'E>.&1 G<A.IҀ3QRo\r]$qη,S>cOSr,PY8B.-xQ=J$@f찏7ERQg/7qU$kʢ^N32 Fu_%#WLj,/R2g <閨~B!-~ɝyH(?}W\ tѶMs>n6~03FJjJIG&}G[wQD?Pt$N;ܝ<! ;n)pW } Y8충\/>M+bNS APR#ǵON,fWfYyRyܸŌ?80SM6@A'4U'g*Mm0[ls~ьnv4C@O|o\sRgڪ5qRy$$(Kge(eLp,k$vE~M= &|eC0Zd:y\#el9QFg #sd\fR-?ILܧK _;e)ϗha M߷cPҺQmU^ #IO0꺀ルB`ؠ>) ˈXb YP=ʮN>{Ap향KhU˸юhׄyckZLׂFdSYFxi>>ݧxڷ[R= QXRߕ+:|J_3& o`F+oC4+z2ǭr5c&~K6 xi/QClm47}}EdІ=RZr@؅-bHc洬{ (CVK|kZ7-@6CۃĹb#驒724*٬'X8աXr\s^VNx3$IY6k_4hK^3U6Iq#đ <ٕQp`Y?gM>6zZSr``n#aԩȪv `-+QU+o%u7>va4]C. 2zЎ TZ\U* ӛMP/w2J|tXG>9i/K! Q]jY=l׍tyD A%\ <kؒ>(3;lo>Xzg*o>h|TLD"v?ag+B<dbA:5$My0T/CEO]w ۾'/ͣQV&ָs۴5Uj {Ni_{Gt FĹigtaW_gY}BݑK0׃{hIҬ%f}q#˓6~-ѺJɀ̖7Nc 9 +o-6_q̢Dx]'׃02R7#86YtNK_^I$0UZn1Or[[aΤG$G9 $ᬫ})Ki~&, G"ifo&CuV|!d)q]O(IEq11VYczDq hdQ OiW:͝G72$@p 6ye;t7] -TZڒͮvB>M!}&k-ocoC{΄廇}d~צt܍C/"Ҵ<Ƚ%ُgDEW +gu{re*|+/@q XEze|{P]ԨC}upP9Wd3ߟRSwg-PzJmB^WۉԉG+QCnjJC ͣ3aiX6u=J͸=:G೚Ϻ!0VK䋘#WKK/#7)a:t- [vw=`m۩ ,C#=hm8dz`O+29,kFʉY܁ze! PX>,If@8oGq0ϡ":8(p~f)j-pv!Bѽj![[ѦRӶĜp~q>;͔6 `&Lm=Jf51]P&9VEk]D5V[kTt,QDub C.|'|sOxcW;NF<n YXJk~އ~gͣHlZ8xL2ω ~ %EѫMN+tmy4!#[Y{Njϫ6n=F2H]2/>C:)P#WF,B]cB3hÜpa=oOO!JC4S!/Xmلhbs[lu*ooϡ, 2 ԡ]焍3*3.rͿ",.oy`EO}.(/t i?qy6!(s*ӨK1@`@&PҌW|{kƩ9ңVKGiCXQ>-o>˺,Y2d*50^C5P~\= 2@/D/#;1z'[(#4)nücShyp8R\0]Y"XnJW ̀B])ؐ6sAքnBn&,4gg0>l}Oz;pd ΈK M`"-tR{ BuuFivN`#K鋴n,k"D9d mjgحM,95\i5]5h]~84tVIǁ0JA/>!!})`R֦M}uU}QS~3V͗Non^cqԻzD+YFo٫(=c=G&d~GR Cufp].? U ]:Z@c75Y_ƁX?dӉ a7^}&y$bz1"Wqv" .!̐%n4x ;72&@HT1݄S[.)@7҆Ex`Bx{?=Ҋ5T:CѮ)?'4C5SXi#V`< S Rx"W;xPxI '-]'oKLJKR JhAmg9B90@D%Ǯ?*EҧX׽'ZƮ1Aa?dä'l}I+|Jf,NWMlzbH[fa,=Ji u]*4c7 $<{An cFups@V(UCRl4ȯ/gLr2;.w7u \ғd c:Nzj??jS  5~Q{9 f[42&CE^8ƻy^i<Ϲ$imBHW[}B?TVj;^#f jtQ\UMz̓KW+=S"J7Ra-keih2Amd!mHT^a_cό=fg[bdG싗 lPDS.;S#g&7:reB'.e~{n7AWץA߲!IԾ2ICѰb.8nin3yCy ռdpՕw Y b*c e )I?.'d(/G.w㛴l ~>xqa=Tw,ɁuFJx S5;UNbkf$uj$W/! Oxkeڔ7hȚ#zJ۴x{N[7l&~6܂+/l{Fl| #2M0E{wvR;X-ply9T1>`:iXUo6":jOW(/7Ci)@gaD߱ -oyfo(35(@& WDcc ~Li P,UE^IڙYh~bo&mPE6CG$\,1Zq'bc_dHjT~hL)geiP96q}Ht[6Y7,yȺat6^ CxX yN^4X=u^h$nÜrec݇ù1䈡˅PjZkf3Q(\_[Vr)k$!Ĵ@~"l“drˡ%zTm(h[ϳ?l`_d:"DCuV]U/9@d334>LJBEFtZ(Ǚ*ïÃĿ$Ecƺ3f`INٕ63baܹR6qaǰ(GYG # No|XэJL +˸3-ښU7isXBS+:V8.q/tfp!v;;Ŏ~ku\3yKims=k *]ĦGY` d4Dcw0Tܵͩt=(dy,>n:=Lo;2p ݪ|3taL.;AY p~,ɍDCN. _%W-nhx)0>>WU:wc"# $7O8I( mz}eҐJ2o3H¸J(k2:Ij-B4)ҹ4w ) ]|,|U_ 5<@voG4n].>Xdc[CoB;x6-ㅦ6zF cXxZFۊ?hHxKaM 5ik26 96xPrfDIM tK 0*n5q:W oj\I]{ClZu\:miakx@xz/t$FgHt#ÉH7_ LR P^6W%9`{MDNBb{0H~]t ̳}(u>_qRkWQv 䟽r(sX8`MrQ!u&v;$f[4 3 kIsjbMQhOA߆5lNr|< {=t5_-t{k_ߟk5Ci{3VY+k81'ȟ@}1ll~fFiLJiԩ7Z{磿IorҚ+v5!=+\U ѓj8r 1úKG$$ϯ`ܣz¡,ui-~EwfǯoEZvl"Һ2+6Y jp(]fϫVptNn/`Lcп_ _WXӖ1fw@>Ţ/s̝}n Edv/zQdYKP>81k?ݏX2}_ [*yR*,hp~"M)=ŭy‚꜇,|o ^,{ zʼ? fnI[wT) oA$"YV}_0A<ʢoɠkoee)rԋ5gyʙ]I?NU;(V%_ԇz.6vsc%NG p;1V2?InnqyRH*NؓkM,)lq695Uu b!tLS}\OjgwDܚж}[L܎R Yשhqc@Y?Ɇhȉ|-{bjDImos|`7$$1$u ]/߅uiMۼ m wKp1nOӫݾX0~Ć돞kگL8!M' ~oG&|&ڰ Jyr!/kEvDݦk 2]:jy[â;g`*!)#y(USC [3kЃnh%su \N>bG<׆G HG uPM)b!lC#k: TZ6Sxlh_i!İ MZ!+Vn8(2_@)w ܚ&/> ۯsVSljive H?:ycGM;Z~g-DF%܍35,J9^ !es 1BX2.2)Ȧ+fOlu8]4S'5#RpߝHCzJҫqF ӌٺyFvlApv.|PozɆLe|fC쫎\!ı>hz$:Brh8CEj,֖:6`SM gA[*Zރ-YU"axZDXYK` <jDRsJ.V;n23@qQo1.CkWб |C/ Da@"jOV.m˶:?kԃ;a-Bܻ\&rÃ>dP@ֽ qz ˝%k:fțC5+o-4nS؍7sbi/A-`Jk}ZlUr_Dzyz<{yqz6i0X5Vt* }k1W ?<UR `VݐN$3_! \Tp {K2N^Y+u=Dhj+kTUP|_@~rXi55=8u|xF.F<դCܦ;UF}~* .XEص1ΉL^5n /MD؍  ?b=(N: K6PAc^8%y:{3#Hf3qeko@k|g)RTn9v'2Z e0l6zEboR)F#/r|'tr4yBtUM/i[y\6l%1(-B]2F2?vj1#7S cތ?lfA0D }_N1|!7i~PȁPJ3KJz^C"qi_+,N)U2}%B3ӯ=Ćƥr!ܦj赹Cݱ{)>Zjkj7QZ$T`8e(+EbE/Z}g K. #"yeaئ}mkRBE~E뜨X!5;$5+KsոJըKz^uú0EN^[9.o=4lD* B SEAx0d9_h;-ҦzV]wUS/MꮲgÿwgZSWQU+˝5;j`Rմ(>W ZȹmG1ǽ=Υ7`Ziĝvm RQl{?*ȈM^4FEίuW4*g-/2 d4g $sE6g)㠒>|4 5ǹGc<~Y (GJQ9ՋO<#s" E/j)q^@,TqɆ5?U8/YָX7!;2A8FrX"Xa|6d'Cf""9ɇ-)2~[R rԙuΌXMV wǓ9O/f'Iy2";˃ƻG @QW悻!V))xnIXʁ.CUYPOA_4zYEے+)46䧾 SȐ0H ͏Z:u !Q́}vw4QخbԆT[i^IL2ڗG,z\ݕ]S@`iEᄐڱ/Q#h-cj-yDW3]X՞6Hƭ-ӥ@L[Y"=A Fm}񥝋W[?)%dmwCz[KpYmcߍr(^qʬu< Nj-Aa.1Bאַˇ2^!=\J̉iT9ͫ 4g_ ϷpriDklu".؀ S6wx"E_S&C4o 9n3% qt2D(9|QPAw1{ SB'ώr.2M\W)+iԍ+̤*7H$(U>yG_lÿJr[ee!}DvY/)Eh, nZy@ NܗWPx\u K 4Joy㬺c.oW)dt_G~Im5"=؆ҩIw`qUh H?jHLh-\f&"[w:ȣ҃YpUrkERI%eծq6/ԝ % c7@sG TK$g _ȚHIIDM$#*54c/%rΖ-μQʑp%ZԵu}BxP8 ǺY@T*pqk(eں5OPP['UUsA%mɦٍ7$@4ۗ7xֽzP)SqP;ƂNc-륜hxI-cD㪪 +qhѬ i?R4((V.2> VbD!fu.R%U6ϟ;. (] 1/gADŽWE3M"nyW^org6utDܨpM+Q۝Yͻ@L;oi"]rJL " 6LO%?`; 6Ve[C4SYR82EM>BlU;vSWfZ<Ɩ&|bmʸaC8Le-p*yoꌌkDlq$u]dmˋw@"2^ +#ҥISJ'prST*!mZo\>H%bg(yQ "&Q_#)v(,!/( rjDd)aYe4,)|{ԩs> n I>*ttDޅϲ z`uvk :ܾv~:=/8Au܁jޟ.mt*i3c{4vnȤW+CB6nߕ ,2DacI v b7si#T 2ysp%)WĔ'P[+лo#*@2ab6ReC6δط ڰI,Bh@Ajfk]|7? ZR}T+ yWSvAa?ukeLOhH1^/7\0cmO \l. _;Vg,tjZ hiNl얣Jeb<N# uՈou9 WV^ТW%xd{$\H7'K!- g[(vVbb?ґZY0I3gSN'"JD1WSbCZ_1`_ۍCOİT:8]p( MsҦj:Z) 2][N' wF2Ah`P6O%_IqjZT =,R-ߚI4%3MkV<1K:'kU@\JG00*RnjOхƱt{ nvXHdCg4 bl#i^~(h=fnS޸)0ؘ.DP!Tp7|c?PX| زE9}([pymaMܙ-B>&@:8MWCQX/zhQc<Ӝd1S_l:=^%u 81res0W!^;4dm ,7A(\cAkJ NlK \?n܅g- >m'*ۣV}dXW}?t5u`W[> Mfv2g4T i4ӇK?fsߖ_JL~q4F%}9g8j  ~ӦȬkfs0nQƓ_6ԃ , 袁V$xwp\ Q!К6J JCL4lXIZ~M@mx`Ne4]Fy5  + ,-Z0@Qwi8 Xw`\>+2/H98xMqPįr%]4,[DFQhkaŗ!Am;p؃8: - ڪ2#D:-sjMfžX:#^55,^iNߙFD5}6W!XX)ۺT0pl_bm *C^`H@|-BN>~dc;9ru%j~Ҏ]I_G &o'Ea!̢RAҘ_OœgF+U멓݀Z?}[찇> @Mh)¾4{ĨK桮I*KAiLӍ/.2oF|o Th6PXf('a8t0!PQG9Iޝ##鏗+i6mՑ4g_2 󓚌5,# 񏦘r v~UMQѡ 0ENDCP.U~&N!J.=_]=1i#2f>@Uz`#O4 UQjZh[,nKwUѺ֞2/ͺMܗ ?x47>mCS}W|jIg XrnN ! }BM?4z_aLZ/5 >i~/p_}XKfV =dD vq0HBŲ tg-ةMWFۨR"lzpA.HN[I9U &]s֒(m6:+7 }@8YYL۝b]q4(8e bCYyu z/Q#~fgl]J"@vsiR^0QP!.%oC=kȜN6/bxj=Ù[ v2Z͚'k bukkADk }ѓN`^ w#*, 븯)@dk" Ӝ JcB.\{>q_&lL)}ˬSGYZN> ªWN RVƩUE/;RIu|i=<嬞>T߸^rs$ꏕ\ 5q*:htNzM7U#xZ%J@H Q^lQ?7ωD, e9Oy?fi ܡ4|JUL m=6*ٿ#sHi}'YW9kʇwL2fcTaA^ Aa"E`G9“+0>s5Ҷ(NǤ6r`vKg) |zo ض6T*&pyz0`%Hk h- T)zYҞ$  =X^CuaDla`AQ KQc6l5nN"`®$SybWg=\ | ^e oG&r]r-rXs1ڵ|TaTT.SEʫNC'ȇOPGZg;{M[3#8kXnmtF_,ip{fR$R"H!Kp"v]@7TAѦM06PWc~F&3FTWw>"1.:V-\MIЌmgſAdMZ &5$^ssy.~FX 9r@o6Gz՞ ԍ&;wm1i5ۀ>5bMWXO g(XA؄U芿tL98;~VĘe1\"y.#nRŜSuiS՜v+?o*AU}+/UAsã1R;͂ ԥN)-j<cd6"uz`wV&Ĉ^މNM| !܋Ϥh_wԪrRaExT76v٘ v\aE]F&?&ZB:1c@/r`W3?H p%5BS[7*z'lڥgU'4 FxmSa87|jq9ZPla۶GOZq30{(͘ f[f#"\((ύe,q澡5ylv8xuPꝆC_i_w顽RN =!D|AiB+:ERDT(J hщ~{P8#=@ci#"rAfDƅT:*xJN wa9ܰ|8$IFD[(Aخ(+ )앁DN͵=ʁ#6pC#Hlv:0͞K~ ]eȴZ= /\R`h0lsaEc?' )yx.TG%E[ǁPTPZ* A8J@A |m"bG]N],|\fJmJ= ;bǠ]\D;{#uӐr-EV#tђ@gH$zCj QUƵRZڋݬK`}bĺb#|ŘyohL[/:+(l=ų873Q5"4#`^gAXuޖplpvh^+;[@"E},3z䐔{qF2VY 501!1hZ ʴZX[K:7LEvB)v [":B{3aK#ڮu_Dp5/)ȡ#OqaLf͙Ȭܸs\H15ku" p@xo~CbG2MDnjlfw^H;<.}{qu J~効Os 6Tאָ*D_nmHuŗ ڵ8q'yArڜGxk=u"@T'ٟuPb)=?9|_w - tv<O ԺxRbEw/޵yd.2XOXb-ێd{ZRyizqr@ԡB:^A걀԰#Rkulx}%^OSr,/`;L Kgkv \w~ h8٣Nn !ALCK-req6cC.)<'y|}'}C>}g/Q88aR"jJk0[m{Ilܺ08BZrus eM_LNjN=K)L+ P-VyÒ氷Xm`v!ES2}i9%=ƟAy®(<εxuXWz[V/{Z ޶K%X"Qa㖊}0.vayD|tiv e~!2"  bCU0QzQp_wB}DU:=49T[*l*bI7¡MqR8]0f`MnB60b t2B%xYD6$rܰ.A <Ʋ7o$! K͡o ZE ;r*ygڿȹPY1渽ZƶXb J<1+nA4h.ۦ ߬w`-fJhV_X3ȵ +wrK`𫬏YΪ~5J&љBC=gGc=w @60\*cT10LI ;#W-թDL<A~2("@шb(cwgWV~lu~?}c>V&Ud_-ݻ.I RD's$=Ue7! MOua ۄrR;=U_?f}W|'IFp{B{ j#KK/$QsX7䨖Jv YLm/E/^ȑAt?qF8/7[FI, ֣,@[+Hn iћjYNٔ[(R>fkZgj%Cv-Ip{ ABeZ(Thjb—e>M^G%IP&=֢ +t:蒻 _xn:3i'B+쪑ޫEا`WfoC~t/A{D- 3oBH؊ox{7>g뭥DF)&;ޞ_b&+q1Vh6~'-60s_B礆dxk=lWd_pvX6v7>'Gqx!GEK); f@|.1O-_ĴB\\@]m bXeF=Pb&}4AQEf3 9-iT RB ~JwJnUZ|7}䂕d pZ90!W܇RJ~{絞`ie4ؓk$y#&c`cUw,.47E؋bQ]! r_rf`dFB@7?Xg`VZgK4q\ -}@UF^ 2A%Qn1ݦr^R "2Ii\z]Gk qG.H 4Vº I''3auֻ\dLsx62i:9W|gg J}!uk$< SN/;|oǢJG5iβ.>J 2b.UWrsMY#zwhtb]gLT^C[X\'T6> DߒzrWU$$7\`J%[8|+o "kQݬ&ڃiE||"ZЃ1A0Z?Ϙ iYGo&aOSc4IV"`̳yf?*:YkFYպ>ToRхj}Ldfe@J[Pԙeڈcn4){d̽ꢀ}|Et'(X$8bamxg2F }  XejO+:`E9.er/JYGL^SO\w*N/DH@K /38 3Q"C~h S+G ^-Ά:0v.Gr9e?9;}VvJ(xrdf aW߿n@ 8tRpa_eo[xM tOG΅ -\+txJ g8#W?4BjJw.8Q]pp ꦻSn4|MO5Ab"R s8,D( )WlvC׎ 3_P؏'$Ý MoBl lJ3D1CqCB:_aS"ȐgqgRK:҅q #oۇd+~ZX6ngxCm`5? +R'yx\@4V[ČQ]mI\Kҽe)oc8CaakDŽb$Kc"EA/ȴFAbhQiweagl,G_0Ul]_%~@Wvm;RvnO 8]y&m=b)0HvrdcyAS%tzR=p&$1vKVK"{[M6W˓h` 'Tzp|Eg2|`q2$[O]ߒ0ՁWWơUx`Uԋ൦<16S_t4.[lTI fJ8.7 DwF~F }{kWksGEV ,*'WRjIbJsdGYF g;Uo1ֆ1J{K~=Us vq"Wb4P>9ࠗ8[_$n¡O@B= ǂs+I3WQ yh̸..8?V;lMkNDe9lӞ(|ӊw=IMtd1]/ӧ% @؛??]<8چ.LE 櫴ܜJT#g}.4|x*A /?0°" bpnn^IOٹ[orVDQ~CF#p;Pm;.O͸c-Ԍ틄f^}xǦ?- HYs+4`gȂ`V7s#dGlho 3c2hYZ@:Ctx7^ͣwTSI]zwL쵙g! YUJ?jd8'&, !}Η]W:waߴRr!)7J;_?b 蚢mt!/}-lJG}ݨ}&ptޤ:o-l<ɨ pq7LC+[@arF|89f7D:n4&R#d3K$0\srj_q5̴KVߝ"/hռ]IV%n =r\T,֙nEpiWIRG_r[*t>ojCHT'B~vzm5KrxA 3v+ް]L{d8Q, oG-&T84!gǞ9 hc҆3eC 1:{:t@)ˇHs@9Q?|fF'I;;^YٳJ]'#묋7HYx*!hD:C#Hm|U}UFY $$`ƣ+2eĈ9MG51έUD 8/I&ydרdž6c'?J^i ˜\Gŝv٘ߋ,;pA8uE1M%ƚZMdB 쫽/cN;>8_'̺x:EEIS!d!S =8 :1f *'yT|޲1Bה&vD-ql^/R_rg[{mF@l2Z3d ͤ'ڃ S<ìu`Zur#\s(t DL!wP|{4f%l$ J]Rp=)$%G8}uF _p*$4+YÂ>Qv)T]<7nb41vN_OI&|K<L^CbFo8R5K7wv[y'#⽋Xo^ﭹ25xg"P'PIEr;L! z`Psb5װ-L{ ^:j 2 "%M!+Ȇzg0lMD]pQ82V~ hEf`,B)@aCʹWOn#ϩ͊7ɶΣh[$.CwCΓNjK$He*#;/]AlB+@Kq_,CA4tI.ߕu]_'\r-;CO]/>q5^)M :aw:%m!ܘ~G1myL,` 0f\:>4caɚZ4ALJK [H] bזxU0>M< #- #P:[ne!oe 7W)Wz`\7pŻ IxJOIhR0 ki \:M崺-t2 JWmoM9fL[>6[u {:Z2 >eMhՄ2J+[ꃱ升FRzʟC7{ysN%w٤G0^n҄$p$"tOhb3o@Xl1 8uOz(?ȞPG5RMߙJ3==3 &1rX Mjضx[CWx* ",$I0eX;6,"tqmK0I?'$egshvdt29FwvfEl,kpDy#E~ten0:^^ d3U_ߦ;eڳ W$0ʮVE3Z OVn0N2lgKRƴ=F$nR w_ IgpjZS߹EgG嘩9 A+<0zTLB bXӷXHCUH>*;$:OzNw 5Ӿhy(1+sR.P*M3oyj^臰B8Jx&O[Gb2hxe>;UpuenPA(fDӰty7<4UU)Y޺ͦu[QNcTy( 6D*-:p3=k=Qzt򚌾LjK/1sЋX=CY SNn  (K͢B~of3 ➱uuި[4],'V cC`r`VtX+z'ܾE[g`βXڍ>\S%N'H]#Q&ahv2@#, ؐTTϐ-5q/`Pt9cؘ ]lwϖ(1 /e)ZyЪh /`ZK=, i0ՠbա0ds?ڙs_0Y`F fPmQ֣,\MmU2} KdV(fY>I7}8\&Hwx),nk{1Ep2By\(Do"3T$z0ٞ(Qzà6`2A@!{:0o133*ue^݁ L,947GT Z{EuFv;9axJ_@͊urm߷0S^~8Ȅtu˸ˤW/RZ.Ωs5&jCezLa&L|f)Q#^rǯsTM!Уm|;+ c,Iٚ0BXPF;LJNpl,;gO7 %5`8}Lu q)X|l|"RLY|(jmr=*ɩ#y8j0[Z=h|oOx)΋{/yRLR$!a9I22 h<zzjZlb 4T.'dz2hNR!8sv:YŐS±~J׾=JcK;40Z6k G/~ZI'\doP*f`u.ZrG;D,ݼGk rkhrMCބ*E:t@" Őԑ><u( /6O~Ӱ%u7'2F/,;]Pg%}nڶ8u wɳ͠FP`;WJ]#~,xFcZ }NYcߊרYÈ\|مLLa`ϔT {Ψ:Ӿ!_md7CT^m%q_qv ѷC3 ʒMvcbp _-G4Q1+[Ejs}i 4\HlDkDoTUP2 Z{eLZDJ~5}e|. 7Ff4~8XNe2I+ @v8Oxe|YQypbE ) ? L $IjU/ }fPi(2l^i`dyoeOC!$$ry8u(#RzKC c+i$-`ILy<գTe֦&mܭa@94O%SبmG7ŚwBS6Of T ɢ7o3MS&@_BcF=^kumTq<6ؙRP*QKOeRuQI4^>e^B4t{D"ΘMX*M>[+Tv bytp%8.9ڒԌ6B9TVO*}F߀6a `%c3s4v}U>s@pvMf$'5l`Z5XLBg^KnQe*ȐQ .P4BƷȒT7^ܵhX47 ɎRwp3&lfUO+ht4y[/WnBʬF/Q}qj73y󿟩*æho ^֘o/ ;Yt+G-IfmCvd40a2m 7!FUJw6\;E@AP@`-@hINzU'm u=:tz.޼Jy̫&p{5Q}=Z.nӅs l+_彺H]MnO cGoC9igH9ScY}GP}JWVZo;ETHiUAK%9TnJ++~~5dgj F}_g>U._Rw9lj@A"*N`Cdwf\k6"ʂdOXHSVDܩSf4/7ksTY,mIk4,-S`APʀ<-nkeF~i%0"5>% .0z-S8ѻ/'$lLިO&مX&:\&[ ϱDL@;F9`xeK^mq pU湭c4´'e6> S1pq;V"u3@?{Dn[D,orf[ӽ݋VȋP,Ԁ6ޥAtn9ΐO[K|_]hr]b2KhƷG hϹ )rUyi#֪Ƨ;L㩂Ӻŋ) $=nNsr{IIݟΝT/$v/0ԥywu=l GռzM 9%|^ _\,*R]k# Ph9g]]ӯ@,*zr.1 qF£A=zt}GoX0܆FfTjX4a1LȥK>Yd|j;'b)i 1ؐ5(ܠ@iTHNyjBDARt-qjŞ-\2˔voԛy;I)K'ҷVNTN<[-wj^ǷQS3u̍_aHLݦp[@mFYrmekBZ^NOܾ̒kq6jC= بӒ6YjyDMK%Zd(qe:K3SPQW}/cy*>SVaMa=PqGkTva'Kzq{xI8r/m@^ڷj=d#zSp:ngJopqZТ\}Y8u{`8LNLˮww|w۳>n ir)~DcM`+c:Iv0+8K"Ԯc%xVMn]}: 5ECO1$ U՟OS2'{ d+;.&zKoˇDD)~z7{W"aH.H;pK)'G#sQcqLZJL0-WN,.ve', wX]'ň WZ(a3$Zkm`zSC '1$yDw.n Ԟ,F9HwUԣ2yzW-qG{_ 46MLdUh9t#*f|AetkףX-1K݆ KSoRN*RJM6},aNN wݤq`sht;;G쥾')]I&؝H3SsD0X`'5%˦1b<^0(K". IVPS/>k%K!rF(V\?Su^'dm +\VJmY<|^IɽEourb=Z!5' 5X8|F%9ms zHNJXVnyh2G[5vA;hц +Oo&w. ]*12#ňk *+ejcKϨ0ihe,F+#ݰDpV08usmŞ_BCBʄYhvpCUA}` w^YW7Dit\ Gft)DEHkuK bo"C'0*7BtZeT'l@K~VPpN{řnC(oӹ7L*VGn(^WjǙX = r6ִE酞c #եd {OR@CO6W)Ⱥ$<Q݅kӶ = |C߸ɟ͓օ}x蝜 | LC3>3HnwKv-ZpR%hon"^'"_\0{O <{)o%$| <RJ$G3}o[LzgÍ'إp@\wxiBIGXlِ@H3sωBi(lnAρ}nTˈPWwW3Jyx#F(VB&o-:%XwR] ?h,-[}0FͲ񦰨:H^mbuIϙp6LLnơ5'Y@az p:ia$nՕMD0F[I>\}rgEb[.5 eYMsqx$W"6%ȉRdі)Gyv?w#4Rt(fOAM |:b3|ַ $ҲyuS^4d9EilӶ!cܑ\m϶SH" ř^TQJྼ`u%kxJB:rRӔF89bA vmIf&Pz{ }[]_W#MݝF vwf? []t g1k9d hRw "%ebU -rv/.uC>oE^ChdA$+9RQa#U?u,[F.i[< {PC6[ǿEIΤ0X7tcd2Oo귗mZī .S^T;IEBLHcƹYpE5Y6l7 XM̚Ճi,SJK9#vq]wDԺ|ϓ!>9ML^!{"*@^6^ ԰fϸ:%l2M")۬ {B?K`G+(O=^⦆tǒ ضcjk5I!jlJ[r[{mZ[bZ#-m)bffNAGt<;h*&Dd/F4_ZMdx">JSyCnAn~x_|LJWp΃+ѪgH4=x)gi\%7^.hV+Dp4*~zt_8~ >Y@(9 g0_ rf`2r@DJQL ltzaĤq䲓9Z7㯑ˈ·(]t88|Q3@+ފ>z 6]4N a`F.苋m6z%.aQ4_!;"tq[F$W`|l%|үH= egCwc꺌 vnx6M"qw̩ jp1tbW?d\[>VV;2&k~ ׅ R@O sU&`r[Us"sW-~^d@C)lх1I"ax%HbmFpVX$t<&wGrùa-*8}7m+KȌvy(xHڒT!?AE"̔9F^sSbkҐ0»^yxݳB enGUt9v0$?9˿Oc @É/|s>󗺱^?P[Ќ̰ fD: ܮr6)=nS{Z8gPn>aH,6M:7g#`,ar;;#[a^v,}l3sO2-fm ~J]M!ΒaT]c.c/"gT$sl~Ќ+3Th.a_4";4nO*gx>(*:ΘͬX_JHC܄A?^ Gp0[8Z)ˡqƄvf+$ɆRbJ:5GX;F'R>{B]/:WSoވu0I.*.7pCWZsFg 1>8 Tp)bG6O;LI tIČH.sw]K lt]BRKmMra?W䣶fRm2۔j VeUo٦(¢NnuQ\cjI ")X% ~\v%$.BճA'[e=lC⠐}$9y7U'Er҆ǃ更~jrh#sAgmD.gMFEm  V%5q%RF>OaQaJu :t!+г: oP >_L;s+º㽆>NЎ1e5XJ:8+upV&z~yq&4͢6 nlŹXNrF4:9E i0egL%<[$Of3;;F;R0Q!DKx>.0#rEogiLM _Rr7p ŘO?t'~99 5чl#^]T:pP&V])>` D!fف]}վtkG3 !3umjN(9>t[qȬѬp| ؐz85t=@Ik -KbtTave$c @eQ!U?Kaw"o/ 5G* Sƾ͹^Lsȣ0b(o }+1RJ"|vvh0"{R3w>" 2y#air[sQsREOQ+l&#|mwjȂh^lܳj*7o0'}! rݮ}ї09_2JD6p:7ԓ s3umw3 i!g Jջn:1P6ƼZ_^"LH(Vć0o91<CaiEjܘ@UK*nņªeTdvê5JjOWO5^?XyV$ jeP/?P+Gz ~Nw:}|Ė3 Con#6[ZBd-BA; N_x\_L S ׾ӗ6jռP\_iȳRYY@/C-}vjOlf!f0u.Rʾ%zT|XKPk9H# ŧ煣*vC3Å᥸ۆVIuOcp]kq,vekJuOFѾF!s`s%%<%38f,ܘ&sݭx3q&"jyg2kf;1fAt^!P8Ʀ|94g \b#*ewEsYBJ-.}EHPi=7o|=Zִ£ K38WN 8q@11liܗqllT%`a=b˺>|շ} n.oQ? c$zNv2pb󚏻-w?CT 7Xoyh+25Β#D-E׍x]X&qE$$ߝA^zf\XH1ٌmߛˈ- .DN ~_ $L\W25.wI 7~ꊧtϳWI,)"ft9TݡhǥG2Sed٨t-{qnnL=#\֑nl Bz)DsMDFIR5Q RdST:m&c1;&8_VS*f>u [h_99_υo^(Mg=7|t@q ް . ƨ0njV];-t.a K]ۓ™N_/ ( A+"1 )#yBmn 5 ?S._V倄y>(", 1`'jzDQOU@w L띛nї6Ǔ)ہ@_9scVzε7H;*p<^s @Kus1>3 wGO/.*𯰧t^}M k G1~ẅ́(~ib0<}cnD;0Q)fDtVyS#2,ɋ(5 P|tnIʴ=)O2Z_@mRBHTFq!Q/gIǤ ݃9E'_)X6tm<հdIxP🕏df+Ja.L{EβǗRmp ]U!FxGAL LT~ ֌/zAt,ZÛθ1 hGlfTW:@[HY?uCvMaì|HC눙2f)r|Bk;sõuH\Փ3y%ѿˁ?,d|W{Xþ'50Ω=&&Cw=] i"6_b>F T8ЧXQ֞U$|KwY"̧T 4BLOV l&|UABUc"E-7c% wHA2pRqh1/-_pH:C&W`Ҥ!iZm"ToKxe$-$XK&C}DZ`-)Ʈt6PZFCmȔ*i ̀feaB0Z-ϴZ#J'\cpƩ__qg/*Ft Խlr }L~^*LpE5D[H>"o] Tr'y2lFNW+//@ #Xu!٘ٷ]hBT M}40#t𕯾3@O۶Ǟ>g[[EE&- ZIkYSqwJGJOӹ%SS4&;M+x)ɃT:@(D_mj u}٥ K^zI!NGK;~,BU$)-=eCK82<GbÍn}lу6)8iРC-+ワr><_Eئ8P5C DvTtoXg<t'qtpv;PTh8WΫ #KwĤסYЀ yT E2IXl6mGj栌 ^ +wBcҺT=6!jHpښS\ +C.O`2$֙qTͣGSidlt]@N5*ſNhЏV*qR t![y dz%b4bDŽ*΄s>L,֗-|0GX>?&~#SPL8#32P$::VnO#1AXt3p1ߣNJLLYg^ޑ)z8O'< Ύ'Dž3aKbKΣ#v=/,w:`%Wϧ0K bϸ["R8w>=t5;gtkkⲡKM$\+= ,zX{t0GNY۔!2'2Y:'f)ɾ`d<(g>E!:t-ڣaWUclZQ O AM~S-j.7 iK^[@Z %'#=+-qd׶mF Aֆ?C]5eQ[cMQy<%t4n@k7yECvԤ9O"1zV':aӟ$*:Y+^+L>^HOr`Wﮠs2zOC8 I%żCJ ]=ďeԫcM;emPfݛ@'ӵ̟)$:YzL)ާ W~/4<p00V$k3ߵHcڻ5qHt'2x;JFQ? 382"`bj&ITBW֊UMe"y-yPۓHCWSQϸh=VGɘ۱-˪p7kv3>W=лrhh $<0r LKçŮošZe\FilvA0;) b_uт7f" ydM8V4G˫D'6|) o^\zRSzH+]~ٯAP@!FOѱ.Pd]Hau:~5].MQvC6@`ƌvT5u´Y$LEg &nB>́O$:Rw[y-~mXYߪ>C@D>3 `Ƭb RW'vIzĦmJ)Q 1V[%_ۀtr=BԤ!tjnCje"˽ \G [U𝪇3=a CEHv˫HV~l9 B|␉P OƶwL \Ic<jJnjōxFv 2VS:h4 2 LhB0JZ(]m'O*e~-^f[xtB#&o,_6d ѹ^_v3s؋拌/Iy A}:Η#׺㦑!µumNH[,~@o\FBKdy=c,RE$I6=Kŷ ?$z?4E_u,V7+#L([iiET\Lr\\b`H&LPx/epw2uH-Keb>;vM~gZ<3cYI[P׻Ɗ\ WJDVpB~TOD6| &,Uc%= Q=11+ڼ`a]͡Z{ʈC~*wݤ8d C6Desio嗪+ftJh1cdy<˪U`G/|x|QZVb[?wb"$8E$ |Wv[H]EpEi)`qaiu$H6=䄉FЪedռ3ZSx,@mkZ_ȹ>iř֎ZVT-i={;[R %o\du/6 E;xv5|$0y~2B-l7|RQox Ų6☉l|zJW ΐoXs.Wo @/B1h:uI |W_VMrgApuBJ IWBm7#o$!OS<<콡9 ܬn(C~U ԉP vFFjQmlvwdWg/Nwm @ñܥy ͬc ѦӫҘpwHid#XPDZ /J~ q3A|B !g":[Hɞ!774kiz#JNUs*BF:6MP:vc4:eGe%`H: QaIPUf@2ޘm@2^/͖/cX[N] HTSB/@\g ۫ O^JJWKZwb Ӣ*N5XWRT'~Cԟmg'<]畻b<ŅrB\unym}P7UU{`|Q:}oc`<w]XX̎K>r9SY81PG`9՛1BЋY"Ei .&`(|v~_ۓ !^<ϨR #b)0%'hfK|*ARuH1O؅H>ILi:dQPiDB/ލ#s(]֮+ cYE5ׁɑ]r_yQ4tA'x4V~.P-b$ػ&G-6dNqQa &y4>hkcj dCV 6]>s!Kc&[@+hz90+֠?MHy?!{BUf7KO0M}Ħ`0f(f)):מ7M/lY6NXhɦae%:G!xL)YVll'?Ml.#+_lq u@p+J#*K,}[ Ci$GY_.ڗ3uz؏h(HI޲5NU}P ̄>Xߚ:/.KMTl7[ 7nRSH:!2r?ͨ``=#{m-/Xj a C Cae< d lnx%l%+VlϑHjJ&eKv0]m|ݺ9QJ} E7!DNRWhN #s E$1wٴ"Qݚ[9+$*@[ۿ"W\k}bpT/y$]9(]a2) BF)n]*I=2:@L vk -KV̞B!;&## ;jYs&zM{9kӰ{9y;?l0sdhPoh l_IJhQO"Q"kN9AlXۖLVDH&Ru0Pk"ˡNBwVR魝:zH$Y-pPܵZ  j"ٺmc__+)h'&3f!kfe1cmLr<]kW,R1ޠ̺ OXHrL,>>42kdY垜ԴxUkQz܅Åu]ڡ ]ӰOh bӥ E[`fDVPU ڻmxgin˱.[,@gYNF;)Q^ϠY5 ܋P.̘7 lQ JmJ[s" u.{sf :Wu86C 8nv5Q՟:Nh(u@(MBK٬6H]Er*8߆&tVxV BS/{u!x|񖠯qW ֩㺮sTI`죲=wQ"A[kG6`CHvaĀ{RXs ĢlWR>bM`|iR*>v]vlQM`h}.Ԅ4necMSM#S'&%،ẽ/[Dat{7XyG;j_wS&}!iS vS](΂"{XYM$1וL'{ JZ\ÃfY6ьj7Z~ui6>ц*T[ՍQx!Ed3KXp;49zBuHCw`>v#~($SEäs} N;ŽGO Hs"6JEFMmϳ>$$ou3w.1 gxCKj lFr(d]J]^Z `pt&p5 oʮo<]}=myvFl Ysq/{Gxt&Xëps%N}qTL[oh|祢`]mB -qRS %vdpl~_?U.u;1N:F5Hݜ}4ajAGyuyFЋ0P +?(J>+Idsa'8r 1gy5-,e ZNSNә $Bz`w΁hiݰ/ oh-&Ne߆tXn0ơbI.WF9{n2!(b+Ϯ1!P&Gȵ'Xoŝ|.3ˑdqawH[ϩ!p'-`k_ꨑaU2fsىH[" HEhtObs bhӢ5RNH8Pl}Ьv߳-|sUt*zm&9я 0B,d}" 890QG#Arm_Q#j05CG>e>\~Çl[FxBHI&-&?= ԧiEG6ft[sM*og8u/Mb.iܠe,siQA|r{f#c0H8AE<>ȱ+VcKɃNqQei3q~{֪[NRF,rB'Ήwxn]N=ϔmI؉J#E 1ӛM[@@{9MM6TB΁\6اi M2P\j? hhM{90U nZr{y!wDbxzyqWIF0s8G1ĺr#π߅ t C_ -i*uv8TLT ִ5MnZ䧅ԁnw篌#9ƢEiwoB=),(> d4ۻ`xPEFBUvHAQ=W$.7dj{~s?J\dgʲcZ=>z eەRT}[!طL࡝O,ED?Tв|5d'<Դ!wi SLj9`]?@Y8̘dN:N`(y r`"KjSPրB &+pM"5eb$}&`%_L$Ii?42XAmE;EaRU/酇T7',C ˜ٷƃwEuuѯvw_ hh5ΡϠ85J+SvDo7LzxPfbfL(.HaEr_y&[ \T;=s'"ν,V<3DhL1|뫪J$I_GQsw3d \?$#elkPm.O6^*y7)fOXY熫=w.VJ:Kft+] "ĘjJ=m \.85cBq~dSm--j'Tn) a<$:,|OeUe񰫿YeES :;j<`3yP:iY654" Z?qtUm,j;ǼN7cېZum.a_-#FI,O5eW{=l̀j3ݬEC6$ð:nừLWA󫬎uJjU?INE3}.0MZz 3ZիE^[Rj%_//!irJi:%rWA %!gTJ@½wx D?e؍>|4k;0UiEk WggȖ!ɧNSq1 eHk&U'Kc%lKsO r9+ynuIA_-!̭/FS~;$-zi& rtLQWE1wTZ)dvzٰV=8s{6yȨf5Km q'`>3sMZHcW@HY/1<_E UE{ 8]cЁ8FVfQΞܥM fg}buV|̚u;Pzn|.=\@ `jgb|J`ctC;{i.m/,:x*x!AF{`^ϘZ~C7#q!:s^l]`G1 d]ee.oCf05=1yp^hCڄ̉OG V`Vphqȉ%5:k8pA{ E=,,5h`LUe 64۲Saa.*A]Tb>@K|%}Gڠ#.>x@:abĽ]&Ҿ!]92 hw=<5+7d =8U)嚈;7<ꜟ VeY#,Fp)lƫd긗Etc:AgӐ 44bUCH&H[D^T8eoFl|lg7%xe_N}hD)5cـ iT~gilt=LsW5ÄY=:Ϳ|vix?U&. K ) t/ | [D_N:Y1_rRvH=02-[e=IT-QJeKp+/=s^DO!T3g+ApJg4O Սm,  |z&wA,1=ϽrD:k~ $19y\l*ׂFu4%I3b5NՈ)KW5'*eM)Bmԁ Oz}vFlOҷJK"YM|C ڳF"TUd1|^^M>e;50|Z{Mc"Euy t<F@/a?PޕGPY0=/DW9ߠ,"wH [I>Y sa5/~)txjM3&x[f}zƭ}/LiL#Bje@8,~34*jiXxE|tK/DW9` X#']uOd3uF'%§'TOlp-$73 ]_Ѩ|.NvC˔) ٬H - i& H۬[B+ݏ.b)hxԝvWO=`ަsm*,^R+!*)+Dڤ?z* 4NW^od˙[g&bE_Pr8LQē,TUm  /h~`^UWE 4i"̲߬Q6&`#nI/`!-I0R+ < cԎ\t`AJVG WX툎+c5,xp9Ṿ_[_X;'?AfaHk.c3@ ?,Һ`HQ/ ;V>=DT`6|4òVMO-H 5(U~w\(4t . 2 ?֢ :MLU< TI2y1l>8v6%kMȗP͘-)?yW[sJvߩ/qJ`]ׇ3$TLc^D1xO G9nL"XeC0|ED;._\kj(8J%P0CbA3~(f** OhzP($?_['c AטU0]b.\)_mANӭk#!GK<+$xAa,f\[nXF $As};iJ◄1Bz5YET([\TS߃'̀óv5=Z9Q+(L%5܇9򒧫R7#三:!l崗e (j96JdW0ZhuԷuk"_1 ۀ):2k}Aгj3fl)i9ȤZ}roLoWKqB4~-Iz Rh\ @E s4u5ȵ1܉ LU16OQnDdx2v6|tAx#3J4N/Ї16S|oh*vnN7_Ed{"}nI扅VC KT௩*HG6L!Bz&2{F܋L;XN^,{**!LQY?\aҔl:2+lԇ^e;A˫{#o|cIlLԁIvKHq}.)h*`9Ѻj;N].yޣ;WA 1p̓'bu<:ۥT2,0bDV|J zq䋺 yLO )gY̓)@Se]=9Ȫ_ig9"Zg[ɑ3ilj'K5)gA {AT(U5 xRbagnrkUwChO`@fa7c*F[dQOЮT[ֆ;&SmA7wAm&Ix{gbM]c̫HB̎*J9KګlSOlaڭfFY\W`zї)fS4jޔ=2o6B.Wq0^q\[+/_6nY 㛯Ǝt@/]R-6 j\ -k9 *l8+WB] +0@h b7{Dp,KdC5~oTWf&&I1FٳOP %G+mw[ɞ\t[Cs\9V#T<%4ɭD=?pu_bvA,Q;F8VSDR|rׯ{|D w 쬂.'Z]sm/G{=q$Xe無8'j ek3vyvzJ^TXQLO{'[A"r7w!*Q:W/{EjD3t1d!Ԭ/ash b=&A&@\G!2l6M^7AXhMoSc+P"1ɄWJL~^{߸7ژqſkp 6J;X\d^Z}%Z2SlG `0ܪ hz& E_޵=H+=b546nM?1. `Q; VeV %%Sn ,p2)]6T@O ?[Ÿ0]f8·]fEUF[tXRwn8U+?aNh)e<7+g"@`zh rwtBb;ZWV8oE,Rݭ DL70~}q1 tK|1KhyȈKq ħIJ.o?\E ,V&BuǦç4^`rp'eA&)[ iE Qv0M)&}iKJي ҶH2bh@:J,>#Wfw85`-,Ԇ&Ff5)9'wf=+SQ[ouxTr!&l<6#7NF^?诼`rmd f@+kv(o0r7(ˑ2PcbGJmO:xKcZo*zPb{<83HajP; ~,fN$#ߤZ bORۅTwa[(겖Y/g *# aVI]C'JtQyx~e bmG{'C|ŽDvo9yK pO۽,Vlb>k"@';k?FJ)fdz.ĭ5Oh l>Ad'ˢژ9MCz*^\MT]e7n+ArʕM=g\G4h%.af#qe6z'^ +joY4n_ #:tIfrF!wf9մM5mjBP%'qvՃUd$e YÚvg9b`=pML.)Yn@okeB:u:'LEÈ哶a`Gz^'o+Ym<*܂B(A@4Q'*B5",E]>^pjEC/Z.jzBZs$YH t '=AyTG ݎ]Z)m^5fny;qTwړ_U|H^cUC!8Z(3TL9ƿW!T p d_:}Fm>Ե(B19CiѦYĶ啔.{jX Sbgnb(N,VyJ:+' jdɃpܻ\<8{,Ѳ)ծQA{9WhĽMB1'2 "8'VB}ΚhD<-d{ ?UKyUCtѾ}B.R@hJ xXh Z|#e?fJNg٪C~k i&?-Y]XAh kgz #wZF69w:܊y1f0ei'ъT>oc8v`CUG^ٷ.>`cGkR uFKɦa͹]tbRGzIJ!^0$yE&'{CS?9P%`xzD}ا .$0j҉!M105+p9\-G>ӹ4SV-}8Vx{w;i,b˄׎h52%ά `=UaGk?Ł>Q.{B9ap*n=OGB >B/k.]T~ˠ{2e44~34@޺N?螎7._"d-ÌfMJ{n;Kf/Sm&I8`::WV߈q`b |;N%4W) <14 Zנp^}GuI7!BvWkzOjvt&QE0%iIpPVR]iEmԼ }&ΏᏉe{&Eq0ri/)7q22/$O>Gg+&%B`9Z_ـ4lnfO&'O%pmS nO3n#"D@oȀ8mT?Ȅ17ٶRj{%L3g?́Uvx%E-ܩ$P' ɞ$cBHD߰D)"LcvRԋ20*S921|#*g0|mw:𔮐?Ŝ=%I hu$# -D~HĪ}JNjem5tzun mv@ -37n4'<ݵ6 6$Qruvʃ:w'I"D(ɸ́  V&Q8HxI[y0ΰM4nҼ7> ݘR&=R}sE1byQăNρ]Koi8|vpzp|{4594oޛ MKp[Bl=}^ ._U©,AG 10NPw쭀<)S t mSXMՆH[9j20tv'uT2mfA<0Y;b4?"(ZS1ҷ)67!D_+GޞңwԎ]>i^zAͦ|*$uS`+H!FUJ㔖Y)dB)PV|”!l,6+i/}Ўvh2gw@cvVݣfND<$OBU" DzfmYidWn5I 8Hs'sG̅5BK Z!@5%8k\V匔R %C6VdyJ;3hF%/<ث|册t{4*o'fƕ4j9+l6)ƦV?ڶ(ViW#] V  sEܻcv0|2 #wdl%W~@OZu UL0kdD؜=j|t]ܴx6:Dgr5=H;)ig'ݫ@?Pid4+]. Mj؝tCl:6醅~a 8- ^a1ޫB>KiUUZ4\wM@8}dc-GZ<5kW 8E6> VqԎ&6p\;,GL QASzonC0&rVuC/Yb2RnDqgkϕՓGpҽ KTzn`= cZQĪLbU_ZIѳ 6Hd0>2c~M6( Ӎ\ j ?^z` 6+V7OSvOF[eo>b2*o p,`ckxLxY\qS4M3grLwjćlV16O倧tlgfDC>dXM\keuA=x|AoӀ Q× ^^,̂c3CDEn6!e#LE/5AӤA)iAɕ,ʹ;K]W2Ӥ0dz/lKb6v4Iޝ?Oq YG8}*~6y ~8/:> LZ=+l; y`e^\, tm>) `ir>N<*ExqC:@ڰYPm9?50,0ڽל@{46SX7/ԯ\VoQ} ϑ/_aZC&COvZe+FĉyE0^>/ѕ if??lMGtS߻4ԟ& ǛdXDFhQ ^ cfA d 9c > ^^o*` SK8❠-e ,ಱXBh_RWޜ/Hxxh?AU&UC7[u`h/LMFkiØ#}``JG;fH P KBOujC!rx:C8 o`b̝9Lh!o* @ՃmȔ3^W '˞"7(۾œb"po?6?̈́FLy[NIkQ[`$$ԙ0d"~O|& 鈒}¿S ;/HBΈ2`SE3bz-AhwH&3kCH>M'"UT7[q"W2S ;Yoj~inV( Hab)3r(.M w5-1o6i-, .^zl[QagB٫in U Lc9y2$vmt`D[m5p^\a# kxh XVwV=O@bcvx<2LDSdQ"_t/`ĸ`+zap1 vHX(y2'x$f,yM8efg e]\N+K Cf/z6у69&0i3'FZGҍ)in b^4^LQ*`0Ia9Ȳq (xol7)`r:V*? e@OD@c!ϩ"1~^yH95*A Aos/ʹn lBGWvс?~_P@L7urp7oϤ=džNaOצD?s|jVFM# PuEfvƋbUw=3ͩzozsjo,HxL>K+btAhtF?;>~DBSa:FxSRą8%WT?$wzC})H6sjwcmMhdvdh(:0w|`%WW}ҷs_=9YM8~\6L،!qdzU!Ury+ ~^I!J~M"+ "5|J`iJαc+\ܧqx!x$NOc]S}LYiWQ1W1Q$5|F@|2x><8ߔOQ8y*HSm@rF! D3bv/ʶWZurɶ=BOxc/7O:YM<:V M6t425o8s[ԹNDej=tgm"3_DXt 4^טv vpƬW GX0;z5'${K,EV+lolá&e&q`rPhKCC~I -ҕ+u(f:+޻OK)Aj3gz12sUۦ.`Z"@B}p^ztd6Aor'* .jQcv[L;7 0޴bj{/}t$\ a3P'.*ImfSK>֢'z^^mYzÊ#Q#L6iN`@N )(+䔉K!Z c'EuIN]<*?9ˬTQ;h{"TN5 l8h'XS'ߥvcx?ZLNI\]ld^u5QݶiG?wʿ`SջmAfU]tA.uymY`\̋2V V \r2)д]AMִ|!.X_by2~xj3Mꕮ]1y2\1^LZ  ԝtߍr ^ЪrSH ThR,,Fq.btpB 4lBg,#).;g=zVa$ED* @5kQZ7:=^W }5Ϛie>~W@ u}nEQ/0zP.Dҟh$zfg21.3 <9Dp间i4jPm8򾁖v;†]Qɿ ;M8fM˥l*=r a<V=۝n7R*UmoH2@ Օ.׍U'symPCg8`FwgQ G,DN#E 2xJ-'y̿/rȐ$: Mk37C`&u OxEÎG=ﲺ=Swɶ(Ou= fc輯'_6K5 cFV|? }gl嬶<0&54FnBShð8Fwӂ}8qKur&JOF׺HM %޶3Q2x?"jN,iAs &쀕iՔSl,iiH9,IL/GDhtߚ&w vK JO-)@ADžqՙgp"to|; M#滆6j l؝_T)t." 0huy.و*D;_vyICkfGP"n8o)ef.$WJ]wAM24ryt pM封hx:O+lj!wl~_+*-h ah"evd@4q0X a'($dE2vg#JRM.RbٞӨwAr3^tb2%0xZ-jYB_~@/qVRH#ZIX{$aOCj8 '9 B|l~º;VisgG8glJE-7 qgK)\` rlzk̰!K ]i}_3x-ko.\-2 '1j_N{Q @$>#<` [=XJ, F .$?L] I DCPupc)gYdw,~kSg{wA3욋SU'rނi^Y yvT)菰tX3Lr:Juu3h$Ls-( cv\4nm44\0^H=Z:S.):/7.Dwڏ)oҌ V `4Q[%3Gヌ2*@,@d lϊNHKu7Y5|.3F6CC҄w7 'WiN lx"ly%gExJ.'􋊌+ΏuGA f8 [gȭI%I ;,KgwT-?R鴑͝*?nD "MBu0u&Yǫ[HNLeStLFcu48a ~y8;IY"$$UX^Ҫ3G6"+DbBE+ll|bk)-n"6SG +q5/3bH<¬ozoXLkR38t@=Z!j`:ZOHL$ %d7$4hE3\(+1(ewm>*7  ;I6mKi}s8Lw8N؍vՐTvA5ۑmS㥷+Vnw<⃤_˲8+%yd72sEblo, U)<}N=~Z/ٕ(>* -<#X2lq)P3=9F7^߈uֳ)G9P3<F==/(is>|@CyX}+3&YKOx*aC.UG'K%~Ev ľrn"mcs'(2 $\5M|) r28(fb~ܸYG#<܉0RԊ@^ 0#K簯\jܫL\? ]D30-hG9yC9ep Ð1I' G OunQʴCg5 9 F]w[H$8m1b"by9q 3Hvȗ|.Ch7* $ J~Hʆ2i9Yc;͠rS8 X { xSZ*^hLTf/s3L "`,oA2 FBmL#͸%ۄ F78b2V@9sZ 7uJ垆8Bʺ?FY6 -r\HG3⽸P/v+v_}"Rv'^Z&vdW\.ڣX7jB{M%\J/njLz% F߭{@bZ9շ3zAId\C7FDŽ8{ ;$pMC2vR7Pg7V_6<>uRKؙ:vJUc.oA^= f|!Zn/ 34G%cxGLru2> /9*~~.fOJ 1R緆"@YpHJ=Rnq+1xj QMסԺ6LoQ.*U˄_8IY&m334 nO`G\z %5@/'$2+->ԥdYv}s1$ԉJ%#$c &ZFemj6:>:<d"UxRU_nɶa@{uRU= f*ȵjnKv+UI8Y%K>'u0}vY)nC*"iN4ҹΕn5/m:Ӛe4xXs?VȖ goV̴%/vvK[wRi#|1J`%蚵r2fFΖY s5% U3q(m* Mgg e@jOjߺϔ $N ըq~Һ-Qg6P p%JIӻ&`6d8WޱH9!e6˔;M^`.}sVd=n٫cz=Thǚ4u+ Wu$ЋmVQo1@l,~PJ;lڗ,*œ. ?9*i"9]t}fj> IV;*lXYl)j1BSZ|b2k'.dܱJ+7'V3Ix$k^8pSxVZqn,ʯJ%'lB*')OuM&4c?(ZOTC:}mg5f.gFS}Qud s;%80 <"J>c‹[I"f̣ŧ mSJB.UGH؋,2zvkJF>+6.NUdwZ3?HstRkզ8Ph:{^E4nϛe666m{`qng-FC6 ؃UD)!Hf$d[JҨ,"l`^'!H`*ګO^Wײ#*0Q_Nԕ^$qCK[&o[{vD/ugUqM0}~8ɌsX7n{8شBd3V~囬!v16ehJ95k`#PmQGEz]v"!dTx /I3^RCo-j363֧[e!}PyHLWrv[zz_#x$l@2!Y#vx °[K#l&| R'3a$| uӿ}X^5cF.m㩺$#Am"{ ]ʠ脪 LyOa~<z%9☶@_v2m(KZ΍!W^]ޣp x?Tlрv9Ӓ_ؓFqXh1`chi)Jο aՠtڤZ&V+ڃe^b PV$bP}Od05F.5|C !y.RXp7tdon8h9n^NKj_7-)!gn';22`alQ)Vҏro;R|]:d_-q4'LxvqH /Q3+֎iGf*$mmO:2n w OI e~`me`l͵*nD#?Q$K[·u٠,vyY<ܴ+!_?ݯ_*X:بX ZjIX-Kܞ|M'l=wR&-ɣr;)ԏCzHo*4/Ҙqᦒt"e]͖a^?BӇn@#ٸ xcͨ[ӆ|{PETl /njɨpsc⺉g ?|630sĕBx&5Ta9:w!^h́~O"EsBzn5-`]+9o8}=!~sdL{e$lUo2hFiD `VyraÒo4eլ;MJ(i y$&e5 ?.zB;P$ -^Vtgig۫V 'YEѬ ېX^t6rSgt|FdX 8140:a*S<&$Ug@-l|S ƛa<٩5@#3!wipz;,W7+R Q{heFWr$]=^.atٶeJEMPfO]hKHHv`jډdO=C eVn ҤMdޯP'SS]zri|ӃC]#rŶ wW)-=4? Oyh rD?zѳX)HN#S+Sޙ`MIX c!I5Wä߈©SB:unZa1w^, ZU(Hu~ QRf(f[՘4_o3)YR֞SE=-h#hI˜<ǁaQcW-^XRHUN kdr@w&]x1.n:wƔ:ҳ؆~0C^i A#h.p~M _*T\ݟo-,W{Da{kx1?mgď! #g_]Kewkr=8L($[塹h%\rnMmi1!lÐ0^F- U||!{E p<4MC)~APhC4Z.FrI/!T|י G= va?Rt U?%^VSH/gR A6_ *w|+C7 Q'M]glLl!eqRX@:-`[$,ӔK0Wp#+=X0 Si1+ ~#U $^ҟci8_iThZVTvk21g. ֬i}?&F2SUk`DCe\I cQf R| Pm^*XD&60ͪ%,X"R>ΰ8rKX XE2 VZy+IsuNMdɫS&BJEŬ&djfs`M<.ou`K$Zb3 ':/2(C5Ôh)<{OGls, B[!֗L.26tFa IS' $vxB0yώhk~y#B%BIJ:u LZ=#SfoR'pm7[ځB/y󍵵X5+c<sq&@\Le4Ÿ̀>A_C(yS>O *Li}n!eX֗ mTH]ѭ 5h"T GOγP8N(jg j4LIdgUW {d`S]!\4t''I'{dTПuuuz# >T!FS%?s=#ЀտL4~c-vIGmb%;W-}7+: T w5~k7CŅ8zapnˤWi!-;H ĩD6\V !- .g>5x?qDitsPhaYOvW*b'q1*<';oLB%IG 5;GyZobAJZ `-LHp^ioW0všOΌuSq͊95Oh'6S 1Iku"U=ݰ~:)w}[u7!]Gia(9^) ΋@5E~fmvmns* \ nÃԋ¿gEU2, ehꅦ}bݣn?P /E:r2FB>H;Ւg\ȭeέ,} {D(;~a K".plU#jJ㉫Xb^-1DxQ _[P⭘wh8MN.g,_4eR>% 9V=Bm9>.l%Ý@)S3mLɇ"`yK$4}og$4p#Wh5uLuW)8NtPQ'<bM{/Xh\S1O0ɤ5l .7JplG)'s-kZqR%8̧WM[Isj<73h{п{|WkfݶjM`4zb, eVpK :I+79ב؋ lq.l:G-@+') l#9#I 4;oÜ3OCf[ekX |[;Z|Зx&gjסlZ6 P2y Xq1G lm/q2y$x벒QIPaŒzJJȧM ^`K饰ϙ5Bm ǼT`L>㝿C(%{Ax;TxNSΜTȃ۸BH<_epS c7Z>߫74RJ=Gd}SDEV.㕮7fNfRAq!4cH;-:8/q_D @Wt  -4RPb$#@reBx E||6+ē䔘:FJ"E}~SSMP;Y8VAFQ$P[ F!V2gDZެG}Wxޕʏ,FO-s3Hx^g6\> sx}ZHp! b,${<Ё)CnF:^D3~m;shZ -gD.2sS)d7S)r>gc.+˷*1t% M,OeUwiX棬c!6x[zm {W=ELJM<}:&ؾ9z'e\x|O*F5q64nu []vmL',X)$?b;ubh68 6 ͒ L²k 2b DUflOx{vHPY["F67b[#]Ӛk 9zH+:C"i?L]i4=Yȫ pԏHV'4’iI } VlEC uht("PI͉wT5=GјW%O4lYxw0YIJ'7osbFǘ쥄ycB;_jѰDUnt%CԯuS_$6y0v~r]$Z  UKVb>ܓ~5MPR5sB!l(Mc\4|w՛ 2&4_NP[H5Ad6TvC業1,[vL63B:_+=nW) IEB rtPO r3ARO4EHCP~bi~Ip<ܲugI"N"7'ؚӀ ML.Sn^;/ѕKhM.M3l"Y), >Ctf.sRDJ>KPTo;I1nt5ͤ Wα "42-͔mXo0Bp9-v2LFx3g'cm+G?cٙ1qg<*p"#/ER vN>ufe@5#X y壥xhKIp/>.M9/4 VvւVw $b:x'/5@!. ݥlu٬h#sh|/vB1Mr8 UW}$%ܞ  RQ-|bԸ:,acLHa+wPļTydjt)$ʤbp_q:oc+k&pY Ĉ֣ߴp1Rf,bKqo F/I+OEB͡@$e+ Li VJَv )EZĥ ݷuA }z?E-2w-1@{#BBeCyHw/9H9yd07L~tsc#På_m>bu6 zj]^L}oۜ2Hv|6pO^gRaDDO6!Lյ]Buj98$g%U6w:}"+d5&fXhRFx#^_ 58sCF%G?( LtF" J2׌W{f~Lsx04VѨR{uS˘Y5;|Tɘ")Z% 90f$Tm"r|B:RgZ@z>>tW9P=kehnwÓ>XORNZ5ktoaeկ(T7J 584`>!]sZN­@VZeE/X{Uى*KrELĕ4s @mFY_W"CǙP AحxAgƽ-v lJY q u3T:;&DI胺s~e斳89mWr>ybc:~b@'ُ9.T,)FCICCkAp tf἖u_Z%M@(QWӠò}ш5|IA7B ,^dc)[MEѼKyHlͼ]w ޶r=Iqc~ %]G{ф@"j=NK>y:B;KhWDRNƶaјŌ٦zl?b{9*g o>8''ܽZ#-I%Bsdj|iڊմ,OT mkld}Fv *Z7&veBo>5Y繙4ߙGsF ekas`k'1[׃(HY)HEm{]Q>3&)[X{Z{F,f O)\yo+ Sh[jmΝ*K C,%b{ױdF ?h?a\!<ՁV"[:GX.Ymvz?)Qxhy޿86?8?jxRq{/:H l5P=L+4YOp S|F`W<9&  n QyFW'/ Oj Zva$3.G 3|MF܏Yy(c~ӭqٷҠuik6hA糷-IiLx6:)f3f8qBmS.ykg<%}5ł/ֱ&ig^v'p믦> D} q=Mۤl^\s/kQY& -ҷwx'l~V,ssmQ}hfl{X_@鋚NuL5t`I|1L9kDKVA\w?] .=fu(ZDm%dh7 ĉ}dmۧSW`7gضaٞXQtR^M;Pa8xVXA8A~Q[RF'f:#7."ּ|Fւ!أMww1ÝMLe߻485T^"`e(az/+G E [P_US,5^a-i^6ROYI&`N,Dz\*Ui6js)ɄsaV~3m: ,h~$anB^zd;]ô6\D&J:3Rs"!ѵFʓ]9<JSWb |ʔx<>V5|[7C4ie56/:EzN"2& ':44RrVpM4H ;~DXk`h4DWwA; әOxl`ʼ+?ԙ e qƎ\&0.ӄȻf[Rye/̕42C"h/.ܛ㪗l >=`{GnڵxUcbF'Tv?~udUtC?ʌ]qDeG"&l h=)ƥޡ&=AŚu е ,I[Rtu'=_oۤD o{  hg"Miu\bʶVF$M E.'7C &7b󳗐0Hǹ$#ˉ;C1g;N?onF#udlB  =.f]S^Ƀ=/aoy]TN=` يuh~~ƽD)vX˂=xޚ6=ޤ}NJj(y8q{/.Q3;FU >h >HHC I~ܰ Ag_ @@5 ;/( ]YxGQ΀>'g,fIӨMFRܞO>gQ _bpX]%mqSA`/7 2] γ >vIf Jw%)q.v" ޮtÛ"_e}_PZ5&v\K5XޚהL\*{^Nm)a6MX3.ZeC1;(k@N_Wo?5Ga -)PUr1rؙ:e^bFǘ‹׵pab~w_Xl~d"%fɲ5|OgC<-]oi_ xiMH9H`XHTLØnN(  R|o̊BVu0f6ˣِZ ?o^"m)(5*z>>*+y K".gAި숀!4D0Mfr 'd]v]ρp>`= il̦J*2xnM}Oڇ3H+1/ 2̓w",Lg!M)O]tL-K/?QE@]<@Ӂ\*xRc'|z ~eNЎdxzs @+a`1rN _m(T3C(zbu%@o }@m~OLe_'`TwmkU4TЗaa0oÖ Ok=7ް*N3'jʶӉ o9zހ[s~n,p #͚U7oQa ߇yMeB+5UB? :̑$ߨo>ֺÎZIKEveMtM83Bk~}H鍠^e>n\x/%ϮJ'N7tyj~agV?̣}7s4aʝY+ȚEGQv)B䶠29Nvv*VܺUJ͋Ut _8]cnOs/q%RKtQ\uoQǗ;WAn4ȾY7czreRYcDQ Z?o;F-$8oЧXQιccpHiju!5K?u`g(gveA+vջpn[bh.[NgpGnL1tz<>5>Qy7 8ٳh˨b@P,+~57-0_af{Lwy/ 4R.13a=K9;/+ZX+"ye% U (J d0+@v hd^ {{x LT}Q.a h=i0E^j7n 2g:T ! >ngxurBvc^﯀`IOkShiU4 @osCLv~ZY@[3T-{Um~"EE*m)J-V1L>$O*e6ƦRUxIs [4 U7Ghw>ő.[*3yPuK6!PzJWEgنd0E-ฤaŔڷ4B^#-7OͥM*@ZjjCVh,u:hJ7 X.!8],J>[22AH%6AQrB{nHjci3`lYY"4@mr'-@D@y/]8Ii֝0oǺT+ʎnPZ|d]ru&@;~dFSθmiiFmoX>h`Z+%4k-Sdr $}yl`R]v2Re/ vW?!֑T*n="AU;$+K[Wڙފl{TE&?}W~ﳺIMe)sۛNy7mЮrMP[@}oq4s| !Švjsr^%iDBM"#r7/}6Ɏ#iR.L8e}"KYh"8IyR 8˫h?㔺^&*FX;R1&V0JkڍWxL 7jd$^s'Q< _@;nqZrպ YGCYn[B,4FUV%{vrQ Rڣ Cbyp3'뽑*Cc.9ǩUG{PU1 -EPӔJˌ%&E{XԤڀYSk̊se7Rɘ  D=BWmOLX2W0͏tJ65hHnJԮvj`S+5.hXLƀ,=ZNĝ4 +fN~6j;ut„ U*ug7LiQHzwhnX[ig_RHj1e\8OZwnNʙp5"֋[xRC0 )|]Hݚ- 'Q ^gP;| q ?1ENs^HStw* gZ&"D;HU+FRB! rmrF.3UrH#+և/nK7uXN*ݽ N(ۓ bFjBBp\iCe2ЧS:¿!{/SSZ"N: %$:D#2U7Lpz)1l5%!0d%7EJI_JEBx4ɉZK>V:w,{b?o6H@捲w[lVRzu64IǗ(E2!0Wo#ׅbVߘo؎pOgm =9"Y2$9Rë*[8 cj4:Dʉ`?%Ɂ Qzk5+MCJ[U e~M2UXq{yOyqk %wf8zeM$/](#>~QK%t6&3#w.kd2gOCOh`%Dv8o B"7-sAK0%s:hadh8ZJ1X $Tv7d A+\wN7MF֫h}%mm0z n熵KY:Z0HX%:T5y3VdsI#y_- B0af ۶Ч`3'58 de%2J/+p|g&σv;R%c ZCddF'pH `?mViPh Ϙ78RJ؂)2 Q:WЯ'LRθLk >JKUU8Ҡ ݰƼe0yzyh$"Z6 ET y94QnBn"bٯ* %[gXj ,1L"4{ }[ a"[ ,ArrAֲ&+X3ç͑_lUB [T xH n]`t/&zA7*zg{` uKF|r50ަqfD[LcT4{>=mӚf0y&J; Ϳ;q` |l>LqM&,zl=_#C?t#C-0~iŢ \dn|ME8ģِŁL~N8wUWPN-'CcŻ{veϲۅ4d/i6JUtǺY^+F,b:֫B=n{4g6m-/$ 01EϜw=lG&8*wug[G퓵n Ҡ-ꐜ=G6Tp^z)8i9^%DЇǒDY( y0%/Ɍ:rkVS^?VU+ T8@(֓B2uz:I|oն"veE@yfg| D0>YK]$fl Eh}j ^hNa6KV8+HUaŽFE~;Nƴ~oҕtb3ģzU]d\ c( Y \- 0b="r"7[uFX7~rg b(ͳ|e8JrԫvS 3mqLo_)%|@Ī`w{4(h+4G|oMMt~ZɱLK' gp+v A!:eOҫw9w\Rt=k=`hJ\TADn9h~L`AU ԦLsFu9 im)ܴT@ㆃN%i ݞj /F|.=+1FۨR[}@hY3TV#$Zd"mws³_F^6LNQ20PTnl}gf`Ѫl#&l7:Nmvy91  2X$lazkWweac"]T~"Ck5']kLt~/|?Z%X9@ofn0,Y*u~S-X j4<d׆Pְ.ֱ0Ɗ{7{MٸSP۵IWBNŰ cwxrD-, xd:ؽs_ʬ6a`t}lp':"1!Es ǜ\Lz0g,gq Za"&`WDhZ$|'3 XXH>rn0CY2*"+&o3' ? VHr=J幩dIbIu}Z^"tcĞYG@4+=QZyVmz1,T BVt y8 n.b7aj% W8p2+YQa"L!diy'xǦiYP 8󶽠>*5 O H^MB&{ntߌi(z̲O<0v978dK6et^_F) &EIPsMo r?ZNiΙDQв3L AP#|4Pw7aezRÞY@L^YжN;{Rh,kc!qu+aW)+5Pb]Uu)3鿽ॆK o)0@<PUrh$dAn0o(#W؎dQw $UM)\Yڀujr3XE2,QS>^2V?iY8M$KFqШDa,$C]WѠ"nAlʹRL5nyJ8NM25eBQL1 7|ıE#Z/)80bݳ%BLrG2@ߟzǮBSPxW>gu dyS <0E^VD73x₃훪͵ɱ06@tq4]iXD5*Vc%͟=&O;|=c a/S}X_nQڎY͵!iEE[Z?(ݳܐg`7>& 7)IR?%g1ٵ?Cp_V,<˶#9H4*iGE^a5h'w:RZڤSWzEv}e=\뛱V6kI?h=7vKO:Ft㱈vJS3b{gaθnpp@˚!"U+l+d_`|!&J0«cRֈ3B; Ԏ5?[S b鐧خ P*Rm^bpa;vl_Mw@.0m@ h,h^wI~=#a@(Ez;(~%!1I,FN>Te b.q3L 3u6O2DTRJ/z5D[緮2ivj {t0DI-NBrdI~HC≵Fe_} [H՗ȹ'SAlN9o>w}:eɢB{?A3P'ҺC,c^~MG){ƌ$Jj1Ǖ3l2+Rl0\6UCY(*O07scbޣM7vKU1Y[~*Q2[V|-HUJ!&βKShi]*kQ.~w%LvFJG`8ٯvgZ3QT` ~y"HDzkkkUhiǶC.>Ҽim*6̡{ZIi*|)bӐ&i\2r59_ZzzlcU,tyͦIYFwcLtQU0=s/Lf7}6s˽si.>”s.hI*,H44PϗzqXfe'\yߕ̡{ƹq.#s/3*%g۸l?+ܿ{%u=wzql;R>7ح,HAcDoB/v/$Qi GOfJ-7qq: wM~A}4#y'⫿B)E_Y-'Adi֬u"ƍlʒ˓z{yӮClm1OHNgj>;% 5CΙ'pD́FU\;׉̛hPQ#Kжv-Ėj:{tFv3wҖv&mLbB^3y\ز\u>oE7siUkK ʕf(#~#5>Kӌ+G9R RLt[+q͹D?XNxg"SLP ?, (^t ޕ6ģ3i+bjOW<33^b7ÒK+o] 䥞M-ڻ5w~GAwF\v0e$!wYx;":SD|?F "SF]^|*;1pA;-l Z.r{g"Ƒe9e&Ubq%30X51׊ᒵQW8٦=7+HJZp"0cIϲ;ks*zrYJ߭7Dj4i~tVŌ9>gHX!%R3Fճ}#ާDJ fI`Sb¤&SO޵L" ^߷P0K.jdηv{Vbt<4"ꅻ=A Я5j|%*IumUYVbVsVԱQa,ƀ廞]w>{Mdu6Xj{y.K@" %1:h!9 dTξL5+8]!>kHhF}NH~Dy?6[և4V1""~sOU;zs*kf1/F 7Ѵڻ[C)9JP\5Bt4tO@52FPMR;iH._hR(G Z?DVtQΚ"BӢ(rrORM p k c\Y -PXMsb3h'C#p zkedW#_~ouD)r1.ԎܓIt#~ sB7AeŔq0 !h!!fP1Hk>ܕCb8btxvbeAlA \\Z ]d qTvmamUޯ"q inpcb `j I/o,8-9Λ4^O|/7}s1Ƣx\;D멮V KfE{s] |i84;E 3ϼ.PJ^;b'6891W75nek0-Y> Phf>N"ÌGE"Aylke$V:պRS$m7hO7V&dg\4G/kY* Hfc+Y>*4ʱ.GS[|uȒ(c S]I)쵈Ձծ_}:AKAG>BoX|(ᯠt:{S]am nH%ɕsZoI\QڲTUx~F"ea$?5SxVBq=+\Wr(R>b:Jw.clWd*TؓOڱ /1%WqƻSG.h촧z9H䢫y%=58UtetWȕ; `*]gen 2媻z6{W{Z>W"+9/su>:@9H\+B4xI3s-[8!ʥ5' L^;X.5P&`Ȧ?Jv{P83Lh'ZzxŸ ̝,\sUcpDْȯ颛V1GllQd /3][+a_;x v#*G%" Z>;aRM)ʰ)Jv2/%'98!@{+.{kDP/4l^SۃȄN!;Ac*ӸG2C:G˽ij"vEx.Kԫ-|^%P.gqݮaxVadg&3\b-J2Y|3MIb_\˴0&TGvϠqt雩rX70[ βCZ ~ =[+81.2PF>^cR[yo"V̘n{1V)m~=YzaCSI3^WR;? ^V9N BCdhY} Xdق8P\ Imٛ˚f Bakt NhJz1gsG"W8yg6ǘ $NN8gRrӳ2(}Imq1`Tw-/̳9Zt.ëH] }hzm}&XΛW$o57$=(U栦_52%&%l?God9Ѕۅ.'M y?r4I!nбl9&![oWF|;;w`{2~`^:ll]Ο fߘ(nu c<;{EW`[G{ʯIo'EcZEĎ' }P,-wYy٣x/YX8[% ѾxSY*Q2qTMAp} L2K$T_u䢩yYD^Lfݜr`4ghD~|Aρ+X6i&Od旿ϠtA!) [|f?RCIqH>ٕ sh]Z*xXU}H1e}̊פšEKF}{qb/P7.- H ц=4 u6'pulZ55_ GbJ]ؒ 2-IMNj|Sg8OeִNQZHUc/EFϮz B}mG]Y.N ڂcao-ehn^_jl>;4<~3sR0j+Rze(DZ|- &+mLւ(X; :kf? a0*@?u}4kEnsJկ[J+<8f!YV4 `M)LT)͞egXRLUMD^0r@*@Zփ6F^󒗵%/ѱNj혛)hT-P0Hd*OŻT STϔ*#D̈́n_Al?ND@%H)t^!TBBI+˛xd4zRLz2 U{00ԣ:c%j KIU6Z"_ah8#tOpˋ6FhQd /%[|{ ,V΁jS{j}+xs!MW+H-Q\:w,"m" DO*5  л ƷcLPPBgAm;bգ\WI E>hD{Eq
ȓR X+ɳ-%J6 zN{jo,ԦXAXРloBCIVvf!nC߅ܿauD^v]r&u]6 N2i5Dj<@!Z6S0Q!7F[#06o0+rXoV6{5lLrXр&T˻F k%C"o8O୽jV7Qgo@ JECb"aõ'ٴ8keeB$ïWAc_<6I4!KI#2h 7o!4&GYF5V bAրWӡl ~HQyB9lPγ KCODq~AS~w ͨV#dbʮyiY<1ȍ`)[=]"i{M Zevk=7Rgb٪ʫpS"Br3Y2NB èbgKMcn2@ xFoprX[7]K/dOr[g)n_}Ѩ l Z>Fjb}YWbH&dEvp615kOF\7CGWi(8~v%WT+Y :&RQ p}=zɵ9n}n䕗{t=*7VG[DTo줬Ciq"0(xvT*k_:?1@ 1pr74$1w?grRG펮[~;yְEQq[C)w&4¢N}.`!B5'5[_na;ެL.Z꽉B5B*D<ᜅq-{5x}Y/vN uHEH29;Mٔdhm=MȤFif[vI0K#b k9 .@!U5Ҍ̴qj_Wk,^>JF8<@]SΫ@NW1T?'ja\N17p^lJLOp/Ǎp4AG3W]v\DL>uF\c.Ŋ. ~.}`&ݾ*[X$@Rau/f>g%x}]yМ8ksSӀ((ћj"Vʔ p@`GD͋[HQ_ɢc9_ (@_ُλ=`UppYSiڭ.ʃLг ݈ƕ*ԷϫXJOdyR罘NZ|WU $.ȣڥ'B`^8^qc5UBbt4)l ynukc1F  ebˢgqI&`s0 }3|N<|n`FAnEoGxYdZ|laucZi/iVTI^DGm9>CAg6XFRpxO'_T0ɌTX,967y#G>V9h$rpVKd=UyW# -C3vur@il88D C kxu(N#6^fZ| ޟS|Rj|KZkL wL~BFa %Ok]EWX=.RZ•֛D&Z,.0[1^ 0B2+L,EߤLrNxsལ#zSmg ;r)$Fri)r^(y~SFS[B0Dp._" 5>\ś 9'_>Xd+aO>`C2A([ 899YuwK=F/&/cykQ:pgm\ G8"2ڍ y/*; %'fw?v`\!=კG@5͏N:rUE=noNAX XSMM_ H.x`mo 3*\˹d/9058F]/KX:+Vׂ'&A1Cw"TU'㹨3-6uZEƮ/~W P+2&"UHtZͶXfVqn\j8+A HTWtX{<#ww/HLJoF#= N]^{w% 78``M{Fj!ZpKV0a_Yx[ f˚ /7koi=9 3ܑ6NxhznUE٫ qMK%|'J9>›g5?dޘ;6̂Sj7z;ҳOA #S 6zmo#T/mHUC.89vJg:n.u1qK͊AZX3C5@r6Ft5$b}9œV#kݯND5?]? y4ыTV̼:<>znu^fF pґH\yfw*\:uDt 7u{^0 6y(6VIFK|sW+ P_FɑfL]dSQc0Z0mF0hUrTء}atI:I^b0\>X )CWD`C>Dΰ(>wR @rZSֆA,'X q@F#YJZEOS܍[/7yp6ڕBHTAukzI.G(Pc&~RGP^T/ϛe8&Y#eةX~uE\;E̍{iC0?)1?_E-vZ fVtpcs3%bi 9|RsS+ >Gp3՟ӖqK?IM`2xLDqP}~[[x⃀ % N( b&DF Mkϥ[ZN5w;j%bIr] ce 6^sdj%&[ԨF@yIQ(KN0:j/X;{q~vShHL…4^Bó(NhY<̡]hJFefS*HĹH/*rPmVXݯpuƗ.AU`gM卞~KyHF'yi(MG}J{JwQ>: a_gJ3/`1 vHOg>FaG{!gy}õ2vY}CN?v+jmBx 'm4S4aҥج5J6I&yߖ pېq5lI}qjn`dvpD8#-<1{ՒBԟ66iQa-m4QT.>nt@d["Xo|S7`RM 7F|RP'hQ%5؆zx!q ]5%tfYvqpOp./cA)I }Juݼr\$p(D~#77$P' |<%d(u c(n6TmC5 &BY->Ж$[S*,,W9슈0Aza6C3PNŚjk%7N|/[t7C5/Lvl@;mz#?ۖ\%N?YŬWBSglkIѨ]0V1hbX|ܛ5{ݗbg̝ 00gA;J-sKdSOCyZ0Ef+ ,F/>6#{0F^_ )brҬ4Cwn 7+(cE:<:p {eckMYFS V>xv>]%"P8Q@$gNXE0^~;7 8XyvȯmŪ\ܲ3 ʽ4?涊Fi]eqP{wP+'s{LcG{ \IX>Gvud>rnrFɏĬ_tk 9Kk=m{&?5K$$L'XYKܠd/{qR)cls= u eqE,„{V? zJ<6ƺ,_țudY=u'&>Å4#b3yiKJ֫ō~ɤI[i@̝I*voXBY@EH :'FYp4w'n }H5؏G$5Pq~T=PS4xfl{!<9ҙJoW$]ۋ)2U:V})_ys%W*-Ym6?Z|RE'ۗW뻧36}g@'PDJ+ȱw `O%_Dͅ4 YAl7U s*!ΡCu !R^BB !\3+q%ӃkXA_&?gg֧"|$`_Tnth^L% w"H@l`@t;rT/Uͅӗ B+[Q1vʀ ͷ9v<ϵNK9vD',,i}ɱqWֱ&iDt6ڐ |4]q!N`Q4(ShQ|մ_4}=&v0YrD8?=4޴DXFXftU,jg}gV7BF%8bCt۫yV̧Ԏevx sp|&evԀx ^ 9o_c|rʺx]ntk*h6/_ԀiѱitxWc>O5UNNO .*tWiAX_//4ܫ,0gAJy$N&l(_MOFi,oCa;5b7K ufZoP-,?}rljׄTBħ6%;t04On>^ꅳC{UEX7)jAE3:c\JUM$L.y׋w`M*8%nzkhP2;zk堠~l)5E9m!KZۇHBE W5{]qԹC"<ѯ"^a1Yvw eT;YkyS0k?rdbzAdE{. cKo?!~=?,?IWo}*~9b\4TW!*9"iGo ʹ\jAjr(TA3\B蹋53:f8dv0{<ԿtD|xC%B{l (B?VEKP\QSg=sIАuVYu?(5L tLNAGS}v ;n 29$z7kC-'č^tKx6\Ic,. *e? Z JV |>SmcOQ"z5t~UmEL%ثX؞s =u%<_>RVy+~Y5d#a.Vr^Y_m M jVWQw6>ivR>T26s,n +"C704F]Jn#~pH;tWbKv`3^g! ?HPo_(8 /t9Z-_j|˛dFzIRyx2`)_ȗ29$-P(V}1g9:g.lm$<۠뀛&oAI;c~RW(A=MmMߔ5eqDOAu"[#7Г>oݑ2kO@zK0!9y H4+{eK>Tcs;" X\ IoS팥1xR٬[Y&haP+SbݏI#3?(YZ$׈8z+#IP&DM*a.  /+6 /-$Bb|e)ї{{8}ѧW6Yw^/1\;κg(R"`)R\\\@a| Y#BO`3M]h.R!!y_'M)3bq܎f]6:6:~9Y_5|% m.mUƤ7nm.~lZv'w ÿi~S-qpC5;&InJ?k qg 7f('lurgfy:48;%"H2:lbݲ@s.9; oBJ]bS 0HxО||8 vvz׃?Tb`bĒ1ag*욆n5>G ;9mj)MA j2ăWzpbuUNq$c}yG=׬G(7UQO\B)sp'_k-ΛHqv͘U}{ߏE ,jtن.SrN\diCaBə7K{TV lVQ^hȒcoۀl:<3q ޮ [N wJ1CA5FI Rb"ٯ>?-Pu6=}AAJٓJyY{`_t "1!"2#)?zkGx(,zqMv!($:jD)uqx 7|/q!BVxߤk;ujaJp6CC"ln@>}0`ulEIJ6(v8jx,E)v5d=$t ϕ-_a7<7'L~m=b}vtУ \K-*n xTj4S 2E!KJ' %(_e!&U9I5+M7cکy4h-I=u+?ꙓSDJ_=p_eJ\ CV |8ݚᰲ FMͧ ݻj&1āL\!j=pj

(`>-fmGi~mv@Z}ba>fNo\qiԈ討TZ g[Awo`pÂN& B8qn2 'MM;޾T@%"͋4Yt|!mxq' یt'{oRD_\x\%^/D;?O]AW)?B \H b 0ȇĕ G10>|tR]T{.P,@X̧T !?Ý?pt:?Wq{3.-خdƚr{v1Jhz\,i QXdnJ хx*ӡYjS4y 1G1$@Mr ٖ+ l0]#ٗ {m*1GB孮_rUI,kzD| rI  >Ҵ?p}'.Eun%9sG,/nc9hY|<$T*6{;p{x)be@*7int%[teY9i ߶ϟUǟd, 8F.ͱ7jh 8ls|J vAm66jv!N݄2;Vuk@{}׶FTz|Y{HY 1Ú}Dkj$?}KP&cb|y7=l42ā UA#p u, 'lZ!*{P0 Qr#v XB"pXK-hTiE`0_~wZ߼%fd$H_NaݵIo; \'BZEWc%ʸx"Sk0,2avFd(:xʴFW_f2gi'JkE_[~ngK=F$B20XGS IDO[(թ}(Pr[45IbbSeʆJ/%WV+ \E%J; 0m|GTQK"FSa{mQ&[[BPZ.6*P'q-t#oo&ww^Q>~51_ HKpMLkɶA Ĝ-2mCKL;J'/[>-&0v'F$/=Pq^+N*m|Lj]D *3hlr^11FƛpX-ڃkwOM>ɅQа2K` #Ri9pᆠYsv0TbV8R@T:.pI=okTf7\s9^Բ*wnuvO!Zp9.=[Y}ZBML%(O(I~8ӛhh^؇И%uJ.Tmf-(Qa|rᡊP4ƪqP;G2ڎ۫P%""J>h7<@aK?7 ;Vh~Y %M`S?^ڴx^URy>̡뼪N;Ǜ%V5+U17㭉9*x"&P˯v V8Lr b ͒sJxm3YDV5X\R p۴fp]E6pZ\,P(nRmL(* N攃=0Cұ3}=AsZ|W@ CUUv " gGO!n~eMFcG[KAyu'//ckSjNbOwP9&O)jvm5yAE]q.$.M56]ټux|4p]&^-q=hZzO'e@7!@dvL|8@L{S̓žWMH~i]ӟ'O`˴~c4J% BEh , );&9!piӗȎ6HZD5 vQ 1D#\Ìyc?Nlx/=Wp"F[3Iy< qVF`Pv{q>e{rsj; Y~qQp[>kY@ XsD}?Hdu]#p{4KSo ,Xh77yY/7Y"WctԱ\cʇ0'7Tp0d[VuB8"m˫[1!.K߮5? jۉh}a5|>O'Jn!Ah-]+iUAfb]^CIid&y;)Æϸ$H.`b‰XsEa ?s9C(l|T:h Fw?wirsRG9ž16UӏG"tTSR'N)jDH14~0y!#Vc:(а@'#W.x2y hB8N4 Y3f+Q/85P&]D4K-{h>s={ϥ/;]&kA [hq tӡF(˱:(ym2Cdpn oN"'L[ "E棹#\yɽ]wZtgoN8$4.[msJWA_ q5 ƼL8 5$lfߍ(YqƠ&3?4,s}Aao<;r<3ZwjS~,lwb;3Zäo|+nY,B!?u/ǷMګDxAEjsȉk?i~lH`ۭf:` vRa r x㈡| m Dw-W+xڼ0L&0ϚDky=;D7=xgᴸhC9ϒ+Nl\ {Jc\W43=/ȣ̛e؎]x6uQUS<9RRd; a6MG} 9ƓR;c0F߷5=&/%$zLFIw);Ń [F"4^Ynx',j+"V; lJ)ȅ \bRxjx06.X7~?J6,"bFQ]ÓXվG504T8-ޱ$!d,r۸}[%LEͪoYb!~)^E|U 0VpSqZxEUbwF?(oU~wb2"_ۗޚŕ c8)t#>67"R^E$ Ҡv%F"*vۑa>hi)-rxR@'Y-0(e4&Kj7z=ewVIV퉉zՆ^GB.8[bR#GŔ)bzP/ntlPH2.V0J+/*cîɍ_rLƛQoRגtW9GZN F{S $QdƳ,:(XiH˜-"LYl8R9B $[("Ap2'iH!cF ayw4Zi^x./nD "Zej?-z!~-Gǭ'%t~`IJJ,gLX&Ih.%}Zࠄ04eD.K S1fȟ€%V(!9tNhc֖nx:]}$R )q}ükڳ/~;?Օj#"TFͶ՛C¨Wx`v}˒A Sn͙t ;Yq=s8I5*yV(6c$ 77LJgV"Qqn=8 o|vPQLJbž" `摒J|n,x6h]JFvۮl0>ZƿO[+$h"jMHmCO /aϛ?ކUbfט&FõK-]?Y>Y-egK]@{}^!b?:uʞ7(qMIJ_X캒tcH75V  (D GLLÄP :{q`*S{oY`덤X4ðB$S2$i]2-"V80E *~\IGtdJ\A;4(#tSKb:UTn eӥr H>;iCmQO/ooclE*=aE qGI^2G5|oF]?O8Fq? ŧ8s %zM.g`L"*/|o$ Nj B}q =dW1YU)~\,F\F+XqV9bOFà x@tU[{s]:f[qBp9e y"๜7ۖۇWh339%WxU0PLYr#C&d1Y*(hLDUstܽ05MN=D;%v)§Ƴ@:Gld];]'E˯LC<B@j ~ꤰz15𘕮%N6+uc]PM\Sg#0%=DV%PRxN wT|l< 4UycB썭 `a_?#.q$(jTGܻ~aFwpEc doZIa_4|(wT6eJ;1U ޴A9Bm S/T)(2Q4_܀Ɣ$*B/H=ouMf;!=YCVz]gdW \rgmUn]fZx;z>wkCrrOɓXQA!摙x\|*M<ړ/qҵ!JWc nϩ=ڭooo1\ϒrohS.0WSSK% w,ͩյ)x"ٞ%2#0`ܯ٠vx"dUY}8k帅,*DZ9bOHBWėK9]JqqhnEW:mA@,xuk;e&$3#$.3OQtox_v.>CPY _)'rym6}\6!ķpxHl8=bra_ZnPjLR1ݨy-?`:)qa?F=Wmj"3į-,-…_Nn>9k/ sHn4Bxz /{sG`ԝl>U$m_,հ10&}_㆕?\6FGdz!U^"pz܎Zj/WOJ+deՕ8C./` 5plċ΄} #@ T=خ uk,_;IQTъDK?# !Ϣ=w<0$E ( ʃ.GÑ.4*qa=HK~[}17or\rXg v~̝-#;gk[e1)Ȧe۠ޏ ;_ R\g<؇܋ۉCya& z е8=sNyVMu-F/2JQ^dv{ )>j,EGf5ʂߓjJz{2^N)_N8YvGVáNY}6>ߤU$9pZ /-9X(=/,12`/e85D`* |0>ًk# uO3;'̸̘P EbOdTi{VU`eau/]a,N0n;l waO%uddrZ>BO8D װ{~@_,&ME<D^&k ۔q&i9zt_;{Y)K|HyŇhͽ̦3#؈*08B$[֫%J!0#S0= ZvgvZ}k>R^7IAW&bޯbв==gG9ð +˅'K'nʝ<8&L^w S.qavKEqw49DI;?.٩'^1}9szYyWX1Orp` E.~F^[z5Z5)8N$:s\"dgƳ,%5O sAFxo> eFFBLa;mr5DĦp]u<"006Q[X|:uc3(E79y[riCb~W @+zSùf&a"LAu]c$I{:WXP'rv\ub. TnoF<զ :' 5X x< jh._2ŷϙ(؁+TWxb՝ C ~pg +ƘCam9#(Y#Z(ktuj-LPtCaH7KH UX6CGu?F!0b8<2ȧhWLfK44VŕNsF&D@Sc%$2 _gu.?rf˜iX0Bه3?P984D#sv?$%{VFiUT5buU)WBL$ * ӑMb6Tݸ1:''s!pf FuJkIo$CF]ǢM@(H.GY,iULy+RnŀFʉ AҖm6EV! ݪ)7zKj/EjVZˬ.oCPOS+:n I-~]_BKj@gT9^RJ` ~<\HnE0tiHc)qUf/2\E: M~[jpI#&pO~];GBTJƌ@4 GT^Ոҁe|aChu!'=V(9CIL&`Si2ɪD/ Z)_gq[Z -Ӥtt!_.o\^|,Vj^LhJ=3 oqJZɞ\#v% BϧQv^fc[w5r3T<06%&vfv Լ#L'|`´SU8հx[5!kCNGLJz -ʀ扣E9ieuB0*4QQUE/! +h` }*Hoӛi0q:dWL<!@ ^pu9 )ҧ iL*KoI t@8י>b Rs)L+s9!Ia.xhfk]GXqgq Ǝq ,=9^I^Phl0" 1R`-:sr,c]&ͻL*oۆS~좫PYͲ)\ ? !.W~IA]4ܻ)xKct 'S\Lvt-h{{K5CROnsց>J &v c4CA;uzQ)g7Cm&gKɺj?1`nxЊɶQTAkSRq|x Fx8vSp{|qKdv*r5+')RNIo';]_ 13BSA4X >֡ aX%A$X:jwx)T Ccc)Һ-*ѿl4FpLP`}& Lhx7XU#``=phݳ6S뼇ftq<ˊ)&fa_| jeq l̻S#FeDu1oʵ")yY|fU4 OPM!@閍rJְ1o7=Hg1.3{'$Id;g~UoMw-|4zY(fv G>|R@<K4 E͉ZeUiLfK`q3ؠLb򛍀%RFU$gmeŝ-J aD/MiMe暰`'.|ΤfwZl6F@+.ʾ][l ǵl~-aDG95^ U8w鹄ߡD?a) o2Q6D$Ԭr7JRDof\ ]c/-'^]sp!|8eXjlp(qes}1woq(a3n!7~ǫDcԹYB>zS0iQ\zHޔ>7$%XBh"ǯuND?0#*5t-ÐS9yLRItm]\4RXX`2&r\a!vt`^0!r1`L@*4=赲ǯh1C,XCU)zGŋ)NlBQbg<6/F),/Y!C` 6~%uw PD%ƿiDcpY*0M#]Cu-;G2ukӻe cd, Tuv浽&j!}p0LxmWd[uIZc`w#U+LMкm a$|rDkfG %TISל|r.Vy$=د_/CfpWiul!{3άl(gjRة7: oqHC\/6-hwrwmvvÛeKY%9<[#|ںڢ7_kEцN/Tv5xSrF&¿Z/^BX1#+-{GhzI ?,5oz駇?Bw$ɋ%_~E Sv dvz1y ta? KPNӜ f$ `ELk[OOaQJI* ˺a^_׬~WV]faϚ449r ˞ڬ5B_XAb- TZwH%ʍ77q=T<u2͜Qr@̻Q;WXv8CYB>˃ے fdL6JNsUu Z?GUl!ESۧ3@OhT.@xN&ɣ_]2je+7yZGX)f]8?GMZHߣkNP}r+1wI;P=ZD"Pqy BA_%pjTT}\Zr. گu@BͶZlӤ/ p&?=i?.ds)2R7pzi> O#T$c$Dy eB~+DFz~ g+NF)tQf !4%3qr(#?̇@ZIhpETGXu14|*`Ý4l S%ƞ0$d/MyYsax_945JI(B/[W, X+#< S\gg_"e =p\+Seޅ:%wZIKgr ]}~ZHVoM*5PuB *䮐M<7F̘Y/R[7 Ww;f"ڊ *֠ndu~O>⁗b*"%o&"4TAybzjA~L SF8Q2FqOvC qP2;鸒|ۭ (^r)Xɯ6|?g {c,K!F8#ٗA0-+bz{3cǍQBy_c)TܘҊ[AʃGs&){b[.NNFrƁ,pgS,;hy7fxaXݰlTa7!vQhk~)Ub˘H-'Mه.L+ uB:eohyrI\m(fUiscӉÄY76yҌ6]CڱnA`e;DWyq! rj[aв ZhnU5{6ѝ̀ǒۏ EK9V0{ xZ.#U}K EtZ#{旇7eF6F4EʲTz;PxMӀڃ"xahR2`nwtc 9D-DXG1H[x[O/UvZUև(99rCZ~8TjPAL U !vn':FeOCϊbK0dOYuZ eF@#nOWLf|QQn%%S8kf,$Ԭtǥ\j8s5wj̊&ay #u!r@RkXLfEݖ/Th @R"SeXw`$45Ӑָr)GY5ԕBud3q' kU co?ԌnSTT.W+E%~11DݧS+T\;϶|KNR^raWK֡;,++I -^0"xRNXQmR6n KeoEcrXΔЖfߞ5-)^b-ߐ jy׆׶,9;P*J+#G˞e>*|MZ|D;e\!l8H D9]ǡʹhw1(=d0oGHO!gY8TmH؏(eߥů֖NP:ڟ&캵݀m}|ٞ}#!TGE qu?0[V&$ *ZgCN NOl.fWd R]c[ mk 85gu`TST<019)V.z㸶cfd';h8j,I_kib  KN[w_P܀|(ˡ]WSYGbE]BP:_@a͡{Ykn;%V| >U\-JV,Ϟ|,< ødvW/K,iDem{Y;.ЊCԽiR9`kfiFϰ]jczBPu2G&}eϝY,ʯh5w:pGgu'Kt–cy'ƐqI.5{7%;Nn mP$# TdDyݤjjQ4Zs OŽH@zhld—\%g(nj90".xt'"[dl}.<|9·ȏ d{Y/E.;Gh7͞^I# p4RF|,2kH.g0J*, |@/3zʉBf)f4`7+>0Nss6֣[XҩZ&a0rdU_ߥdG#]7ny Ƅ&Uj4!}N20z@[t{+MtխDķ/ް>e^(poбVv\*9)jlgt"ۇn A/ƴABཛ qz1S}G7ѡS3:HB0?6M1żg B V|޴L{MU=+JL%5-bWp8IO`xP]2G z$S*N 婡>cnO j8{/GR].MgxWl[s4D ʑ44;F#h!w:̘=߶QdO˚:9Q]`۞nmU&O:-B%NeVCHhS&'no1{CbbR0oů;(dTF\U#>%9}E2Qqt1qG&l{oNhy2^ H[Ѐk| &9"DÑȥ%\>ۢ[ԽXWHo^$ܘÕ\ .Pdڳj}OX4`D:om ޕnVT.DnCf4~P;+c~eWvI;0*"m1|F(Iauo=?yMuܦux󓯚VfH4)K'7TBͮA0vP6ZkF uV->۫U>vB=hYH䊸ת(=^[XcΙa􊣏o -zT8 v[` G{ ltt[xg}ng᏶Tc #ׂ)@;AsWꉘIVx3 D B:j+SJ\? @ӓ(FW"dʯ W^V a4е= !ԟA&T8ccMBb akg3b_N07v\U VY:.Vo:o25E}ǥkD<%Ail34;F11֙]1d7+meXM뒹! 57#V]5>m/8sKL޺\fdVl8FvքarRv`?U7K12Y?bg}K(\fH}v">.S{T 3%*jv¯lp Teku|.(X3x_-)AƟKpUcw &mylvf0Hb͢L Eh-Eg05 be I!"°Q:YG{wBׅ*UK+VNI&?l7֚=#3a)z]M*RhvvK!jхL1pv&3CQmIw{1eF? 6ۂ u$ue%|s14m D 8g 5"; 3-Ne턎+R:Vo}iuH M?\U8vL[ȷnx'Li@us1b)~q}z8XalS C\h)Џ+TABut,d#b)򿢍ʿ̤TB׿ {H=w 6! @Fˢ.U(h1Z"3#뚂^뻶~ dzv܈V4~X5ǃ ^&W83GOa7iQb|U[qi\l{c|lLКázFNLv^i^CLP[mn BMGCoEC3|~nA`VI)xvy{},EgFʡyE Id"wPiovƗxG|Q5VlK* њ}K4ŋ3dŘ%QN<: s+;ݤgC,Aۙ!V*;9ۂ ~pkvCn9`G+@pR W11kJF7:EBljJw5 bGu(T"wCHKmޒU}9!㘠F؎{ZaMKf2CA$~R?F2FqSjY"gF>%ҳ^xk$נzSee0M5ݔ %%%,SOA* E3O#(aJ mo9:+ #K*P9q u*. -@b>hN VVH9kw.wn—鏪H6G{:ʗv~O C%Spc?RoH`AUo9pE,=ۍv^ }m"Egf"%O=SKp-ND!3 A+^MEFW>8}iU - D]㾌X uBi(QezMRv~s{LKjQ@ˣ Ǫ~1pե5S_+4^〈4oN"OO5AXNﶓqAYe+ cK4'nt(AG94 ߠ+ViNxiq7{!H+Ս0}GC ):0gx Oq5xr;]%nc'pi,lqyV_;4iUEGq.ԷH bpR#˙.kʨ xwzSrë4#">^qJ/sg$ <JI| !t }7l+)Lẅ́qT#_= 9`=LG-=s ӿA31L6 c2Ugm8d W(P@⌼5k6'G]9/ ;$ٵvtfU\M{?LZXޫ#*s&]UhH&ŸȗQqd).:밙 }F2;3:7[ "AɣP?ts ~ T3Alk)Y9ٙ=SK*,:uWRbWE^RZ(vBL ^$+yoY'ئ|&Q4V%G9y}U5 yES˧IXVŶy_=Xg\q>Ct߈- ٹ͋#6N:xR&7>hW)ϸjLҒO.n#m1uWN)73D!-򑼏POnQ$)rMD.\Gd5noD;5MndaՑ\t]~TܺPiGӷWK=4nd8|3-0 M8>)#:-Kf@ _z$U P }~{skĄiz忝kՑ>%' w8n3v^\XE&'cJv7-q'C@kU> @tcqOjPD8 %j1[>>|~֥B*q<݀,gf |vuYkQTJbM;QBvKTl^;R:8epsqX#W4@@t0|RHZnZHg Kkv(2J^]:{6]! E!a~JV7ѱ!y0vWvYlÝH؍a-;wE{F* >6. sNY~ch㤙n06762y3.1=!NZ15 nֲ )\h^/=&NiÙ%el5m5WUך=  :o/%p,rj~mtj!ȗ7= Dh soJ*?'MΧn6jpy6)!AӁeǓ6o1"*yѐ쮏 h(3ar^Op=u wx$ Z6< xy/^[Īl\ jy2,_H|pݜ|Wd4R{Xa j  vXgcF` [D.fx`cu놂V49_f Lo B.%\#+*ݡ*`/d)ږOkf Τa:r$v8]e2B#pTx T5@޼>.<$5@,6k8F iV $ YsQaf_)Wc=5/zHhmaːi!'{G?E0._fpniJpW!tZ?{ʟy5 ]wSc)poyLfнK e;%C%jo{ PZzJenn.`< bb^W[>.J҆32%ɵ@=^ ]|3li[#)6+ZטW@@Eʁ 1̓})9EEm*uë^E4V6Nm&Aj7`fcA C Z6@4\rpL=+{4ѩ(Iڏ$O'w⨡70hg󺎃^Ui3odgPh,ͩQ>8?XdJ;xə#6imШh6w+gV;>qM,$¼:ä)+qTIWDeԴVf=JُTm[IqfASa<@V/U>MKLbť7*%00pA(>si,MW&:?Xo3@SĖQ>ěףZJ~{ٙ5ζI T]LfFVG }X%F@RIe`M>Ô杷#o:{ 8U)%)M;ۚ)2+};ڤ T&} Q_5F jI$1\ O"p`I 'q\F'ʴUa@7IBcPCh-b@W0`[BM|F$$1bdpܟ C`p%g?JQ؍DfPpۿ$HSoԅ&^g>}Y!p"*x[ֶҨ%Y+e![L%ϲXC5^gSC{OZh Dj#`C#BE;Ǯhʆ+ ^US1)1v$he+-'+m|Zp^Z[+YK@S;_=€?XE(Ql+ap )\; oQXf8ןqdIeGiV<(BmD2Շݴ$M?M@wg+ fˤEkh9H+&2&( UO+&xqᆣ?62ityV)! $ ]LtBߠ_eۨTZ0A7jB?E/ *DM5riuQ䘌e @Vsw.f2^(?M9uup1B%HW(R0 d[~x́d 'Y\j+͡*aQ|cgZ^bf 5A^FA6}|ζw޻(3 %gni$XI߶KLGerRR|}a~;lbRab{JTt7}dWpo*vLtF;_LGr u+Q~CYꤴ2 @FLըO;+n=GHH/TM>|3mP%y-_$F4Kk\.qs. _%֑J'Ő(]Hm2Zh$@UF@M#oon3#> 8Q"L߀ח̠-d(x~m#/:F(.ɤEW104Q7`!+@֖vuLJ0m*&᳣.gV(S$Gp'˞LuHgsOG ήPJh_m4ƫ@@XVŸGOK4| 9Lmo1cuYre'ȏo TVX_ ܫVPuU# FWs\3)*=vֹ):Smt<brO1 ƫcR`-4鿭=_YߑnceW9enp:PGKאȋ*1| ̙Ţ&rdL9۳:xA/]R Z:aOdݱ[Eq 9>myBx~̑YA_rTϭ1IPЉFWNg _uc\kyR][w02܇gU$J;YVa\?2U-ny9\$2*ls ͛U?DK Ϩ:yY y+,yЋt`k bI0r! _,6uh7޹K/dEU ŬM)mK=Nc9Ʀs!bgo*F2F&t~hI)= PL+)1qWjUX‹AWRý\h``jeRAU-* مcԤݩI;#* -x PwX2w2NTao{CW&[="/Z\2I*,q"ځMXab,or/wl& p1iyaSs!;n)}+1Gfŭ-Rܵ-9uuMLM*ڈA7+UdLjEF-5L{tȪ_/\O9sDZ>⥜s?ꥸ傭h͑e W!+V ,\eO4TaiسV{~ÝO*Н eM"kZmUHS\&4kƳT4DvP{UCAIJm*9Wm̻q2ý6^qXQ1|<ѻ om_ 6F[djpkب?fL ~_v3%}[ Q{wݩ~HqHfmQ5@N.P[n UfJR*tH%hZiR!*o*C$=a/Ͻm5˝cPRÚmh4y;(qc9&\Wە0,' iz̸ ~WBnH$[( 3&[A6F {\wi]cH*E$`yѰ}2^eMDR- +"*.Gټ<D肛Zôr??hnr4~S{zW|Z~3kÉl6t}{ǍXD8YJȂi3ǥԞ[&dC|}diC52O1?Ȣ8䑈%p*Z 0و/5/463jX E>;Ċ(T ƌ7+>>jx;YVW %%NM[2 ә6/.q9L\yePN1`qҾu|w$1+۵-+Ѹ{6 ׈ܳBx0Dj$ 2 $Yzzpvx/3-!]hi|BW#@1睵0xeAFULFvR5a&s7 XwOK;Yθ7IЎ~R+F֕ 1yg0u;)-fE܌O "JT`= é d*K}zO/;9ՓFۡ ҇ ŕVb>gkW5vbX?jX,fu ]\$!/f smtڸmxfvh.hY̦t_,F4wÈ ;`~{?oGgP "7"B{Ëhs 8 py+E剶LW`]~Yo}hQͳ!"OkyqYV^\ͱ=v1 *fvn#kh"--(\{*%AsFTׯ'.i@Ę#k)BzIp9"b3#mϳ9ӫ9f|s)y\RC&NƼb M` BǴG0d9yq~0ݒ5M톶B/ /vO[/J:E7E^\v c"G ]7 𒤝/=b_ShUL^CU:>wՖDnAGvӦFf{ :;B~RxSLP(F#yBMi?_kprA)ҁ k׿TGWVkJUC"X1D WzZD?x| W;@„ڱrgG*:ߏ:>5дq ;@q]2 _c\z'q!_GW(h'TVN( PP-s/Nc#ߐ%َ W4V3s\}E܇=fO7ŕ !#4*[䚴jϐpX+9!gS${οX ̴:>䞬~LyiQ?=\Qg*in44YxHî(t_G R]TrvǁS6~CX>棅+=AYlrl7K -};z~ Okv'ƣ`G% M)o{s\+ء\\jаy>3)Pb_+] TA ,Lԥ5*n qcޭu~ ٟO=Wٽ=`6(yhBw0BK>WO<>FҪ'ӇnvV[[d_ <$^7Z\;hEp 1hɅf[=x>H݆19vWO=U? ƈ-n"C$CL=-F^Z}P>5XQ~q E# g0IO HS\x4\}v{@t^r׃$"5ؤN!j[rNsZˆ  E:0c {Ȃ̹)B =h13gFk{ omN]X}^ ? ScrXvJu Uez h-BA>FQ׿HeWώSDG'v8/%7߳V 8&q0y r7Qd0ݧM&z. 16袆tgEs:OSM?.Gevj>opQddP9K섌X0s_ ;x$91+.ϯǖ( ['r 1 n'{G*ez:zb "T&-DUg<1 c6_P;Nx)qbQI&!d𱪧3frg,}=^܁h"F`U!Z`uf|aeU3O5L'>Y?kucZ,iK_5 $T|+p` EY;XL- |?ل )g 5wʭLnAf6XGi^Lp>vϮuiD4Ύ\M(H:&lgDaq% AM״̟p8vs{2 5xo*r,yKsw\.F&!Bt-1q y&o\>s}Ph08G(e{9prW|dӚJh!j#J-W f|( dv\{L y P2vDVl_ZgjG;pf!C*1 YndydCPŌMqw> ,ws<ƅO졷ܤץ)Bs;IlNks `Yt| '{5Hk| Fxw% V9ATZ|Rȕ }94S}f| L+n7<$O;ToyLJBN0DxF/>IRщhej{m_6%uZ*B'u_ѻ(XK'RQ%飂ytS Tg(^ 4LPTwb4wUY ,[JZ9iOl\q8GM.R @b|49k5Pӵ01ev|an{!qXoȦ&LX=Ł mC6/;] C'%!%AqhF:iɔ']GV8kSOqhw , 1 :j](rVrXH//&0jtZ }9,1;CH!Y@2 EeJ_{ƞTJ!`;q (bVAJvANjKHSW`ɳڍ*n7yǙμ/)v(+](B@hKv9Z6|w[pM4CHPO@y$w)qT#T=yUI#' 븖wqsoI,1#qϭ +bN=y/} L4)+P+RɇI@*iU7o!N$VM/}WaxZ؇ĄORB8X&øֵ;V=Z/U{˜ >huc/-vuO/BEJ3T0GPbEmi!Vz꓆_HKoCЇF~)0@lJ.|/ ^leRN_s ["IU-%jOz%Piߒy"a+ӛ]U?9v56xï1vyZӅh>ޥ,~,s:֦8d{Oj l8$`|Gw)pcNiq1nIXys F#GܝA`2$檭ȥ[^Iҡ}{Ga^JwZOAq^B|o~G TRќ  y,ᯞH~;Y#4457rvE냥 W/# Fq7-S@uZU}"`F.Jz2<^d h51?bŀ'vUlh`CR0\U2ZRow2O~v˸ɨܽskFN>N} w}։$|Spς1^<`C79 {w={VڡS8Zdkx6PbB:Bp̳}bq?0aMZfuRH2HrmR'k9Gk!X^_`w:; x!Uhe ;KQEbޞBMut+ƹd`&D׶ B"eBrRPDM_> 4~ \oRbͱ"鸋F˯wz5G  WiB]Q:GIqHxD8:+ ԽL>IVԔEJFM2Jw0txR*E&L.tTJ$ƿYSsFV W'vmȊ?Gt8*U{j?_ 9OW CQڔ0V{'۰"#p#%YdhoךdT-DDl5|pȟ(!~*+*O|=#cm5 8UR, _2s-[rIS ɓ|c RG< ﹛! # )6-VC]jU@|Iިَ'"i{[ ZKw./Jljۖk5LIBjAɻ |duu$bS&#`NH=* _&@'YsG\QJDV\G« P62POMoc"`٩&IJz7y1Z/oE9 u1G,5Jn]v!F8@SԴ͗>m"TmV+89> w.a" 6ƥwXs8H>>V;Yݥ!E; ݀IZLL^qkQiX~pR\t9T纕U/|`.Yͮ8Բ-|R~%tjέw,0 M{SL zP u}38@m`{x? ֑@ۦ G9nGdmBKG:UY&آ6_㟂\xf$_6R0< 2Mn{ W%_H;"W4;nuHx`;S sp|*Fl8e|BPt.SO&[ 2w^d65)v~],ya9a -^=+8 =oXKB[bLu 0&n(D¬Tړ%Y>Vkרv_bDFjE)zěg18N6PrMD ú/soJw3DrFmiRaCcM-?:su1ᖆ82L^Sfv=,|*=&5m$V$LJ[S֋T 253? `OM JNe 炫G Q[]|{8(x GzhoG@v26u#F'la0?)io"H]l\T.SwGbcqoDN-&h\*o(ƝvN¾_t\86Pϱ%{qT0SMk~SN/*+87At΅s.B}Ί;ʹ:~*qRppԟIbs T# `m*BTEl5茘Ds'6X+I~<;]FвRc`:jIi4d KRز@H }.fzz}~%wY=oeijxOpra5aaY}7U2X Mq|zjf)?1L]|,֋|GciX5D' ' _i,[AZ\TY AD#Glv^ԇ0Y_c c4K4BnRU EXb (W:駕׳*d0 [ w :IJcpWY9Y9$[<1zY=׺=jEKÑE:PF{,J#0(ֿ^vф/8^tSؿR"';#PNֳZ̤sw]V2VH@DkV ]2L" erY*Zydey#uJ6! ϼ8ȘHV.BMޟ{,@Χ ֞)2w5ѧAx(!WUb%ð%j~Zʼݕo]N`9KlMy[&FI3Ռ%#(FP+P:h2 лd?A`QiyaZ'/FӺ6 ): %6|]ek)mrsFi2y*q|Q8w`7n{PU4U|-Vz|樎2< ǾgR 4*ry& ^?a\m'ԫ}h{_Fq Š"nqKKԉt nFudv5 h ޑn׺ }@!j =W%;dnri QAiyp=_ygCnB2tt3Wgq߄>:rOn`y]S!f4f"30mYz;ء>>( TQT[c^jBm?@3M( JvXlQ xArW ݋;/s~N!+1C;hHHUp cv7@UFD?=s'34ݝW]ۃ&#*p-6j@2C*+*]̦9* U ?Sq Q0uY1+L~3,G OW`%YpZe*'i;iK]b;{g &LLDL>~9rVpx]H;.VW'5r3߬3T O(czGaePV}Y'܍"dh+e׆x-r+KX'U&C;@ƭ8!)C|TţĂ'Geqn9V0TnK6;JyƣŶA0CIe9.NqhCYʋ`|pGbϵNԐͤCQ}3fݕ3=9.ԉ7 FlP; l4'Drbᝯl^2u>fd2ZɕgD4ʼM>)k0x(|'% EMܜXI&8(9I%b#Mș#AjeQC( լ1Y5MER}_Nlk0)u13 9pvN4 j }з7+j,7d 7UƅE7;_˫wZn+&TyOQѣ_iw k&#VQj.!q%`'ch桫W >}p\ CP}riKz詗I avz|A/B ;<~M-QܚO1/"^@nfNeGho!% L iPfv[DX;$s W~BkP o>p#8*+߮~< N8G{$hhr:IF Yv(ÆjBOSAfˇ ORC\䑶֩zG="bՀGT]=;zaZIVDs(bɥM,vai3~Y{VJ{P+74$5+@[CKSQ6&!1@t"( 2 y$l+?N!4+mђ ,)oZ:U7n.X8Ε݋b9m9z}jmaEHĜ$~b#X`-'L#T<'Wx-ffQG7qSd%Yf PyY|\9q8@CH.*/DIt \Po峥LݤCu82> A]_F. DQ)Utr`x\;i<"-aQsV4rKG Ǖu*SJ-,91GQGr:$@.Va͹((vxpu9ɜֺnX%l}ѳ|фcuJG+`:d.I^%p׳h6qd8z; `g֤_@j!ɚ+@X aɺERW>q#Ii E*eoL%^QAvҸh љRy$#y^^'zt}]+&8XŧٌEaz[Ds {|SxK?8}6PPooK׫鏿qxY.ά z2Uh[6> [Bt;>-nN0Rg*5(pAi&x ^ @sD[۝HST3K eAF\L*6fsM4K)Dyr&S!Y5w=ۈk{JIڝnlE]9,5 bĢ!Sˎ'-"Gq@bWO^78C-) 헳EL"\$a|$OAxjˌ ָx"p@;=,Rtj߷Ȯo_b::{4BWh=NX{lDDej[aAꎫAB a-X#o;Yû?'' h#1v{ޛFm@Dy,EGKBbc.r? =Kz2^73Ӟ%]:"ۻ%Έo'#Z[%9hTEq6ѣD'-g6J"}plS=O8j8ЂHgJcX%t7yTX8'N(+p^:NØTy(UN 'P͆T$)e=T$;h,PGGBccaj8ujduN?ID:\GQ~ĉ < %3Wcho9$A .E(.({_(| 4Fo/ 7q+oV ,vik> [m@nV:_${0{9ۃ \yEO`یoT/JǎyZ:"?-^)Wσ;VHxջ7je5boͯ찕a`7/ܧ.λ+Z0M'4-x ]%B8.g[ɩV18G:򟍽]_Nٷ-ӼE ;` Dx6U44S~ޠvD~\|-Zd|fo$ /7xIOx`tz 6X-ybBj 5iLA*@2=;:,ҬlVWE3`&۱-2׾]OuŽo)z<`xV59 YtAJRCp};هFX=$=):1x{]Ej*>wUOo~J9@ɦ9ФԖb8j"r걿s䋪,%GHH7IKJ)95&@R_!vP4.K0bq#2enja/RF6Q4MpN5Z_$\a2-?/AV,BeFYZ:l6C<IC}-nH5M&{NM΃cII3T3!)\+>O哙}|6#byweFbX+uvk(̙P+3dm'+ѝ qYZxwS|(da!EXbd t.Ksl!Mqeyf3vǡD֧ө_e)('%{/fhzkÆ8Ós ~M_ϋKtΰBXϑ@NRiX L^Vq$3tt>pA] neEy3ţ+^MoIΆ#mHDδ$O.ãXZh9m9c=EVD#/l%ݪuKfva@ҎV fhLE@j,;Ne&ҌyGs]sBfi5^!"q%ԍ(/lbd # `X/w![CO(זΎݪz:h&]B C$9h^s\@>\8}0 +rUTxء"Ht}!`9~ Cw_{NyqBauh X^Ttx5W6ez/Zog:5{0kulS[UN" 11HFQϚ 8H0lxw!4ڄ6Tkcʜ =C0,b(4.S9%U% $^;!Dm<&^tDSb W;#:R&שR(),:j.bc:Lq }I69P,KŲUE_E#.XrbF!U0`ke%";{7EGPkr6.NjO~'C.z+ #DEBT$њn㥙0`QUUD=&sq({;cj!fUq~HװIΏu֢tUVauZ}~r@'ۉL/!#wDϖ$Z!x+F^sNGamK/Gdde%5Ѐ+Ͷhnz+rc |oޘiF.DSߩtG|EC6f4 5iKkQ&[@97Ğ{kK7̥KKOWTЮ~E :IGnM7n/#*0=¯;}л/Jts2k|% ]rkl|>ԠSyT@tX8.kKR箄l30C7͂@ynKcsJKF"ˈEm%R)z,>3$W[?+9٫,AښB_HAB[4C̈́y1Q~?w_{/jHRY=bOQ8PFR'rSnT J^h,f W;i;ŝdBHն )gJ/Тrl akj4e$C|e#:SZ2x/K1KB@jU&ET:]4V {c KbvR d(t.!Mg@|>٫6k~r> ;v`I4XP"q'O)qG+D2TC0od@lJC]n7<~oLBji=yfW[K#j2Hgxw kp8V"%$^zs̜ 3Sp{\"0&0*%&m1!ɀ1EGL-°``vF)z ~loEW\#Yg]w^n(<6% 43[XJ߲1rA~9+d/>mc^@U$aR]i+OǠ~Fw-/Uc,b$Y}x=rm/^?W=iMo'O=P<䀺-w'풩I8TZ/%43:.m/J f@S}\*q\/8!R/?Yvȳ _o~ 3%oZ%AJwG)f8!(tE;͡FgZdKˡF{Ϯh{<,xOp<%EQPNs4J)% fTV]0&ҸBjذA'~[^֍ W':o{S04ui/Aڱ GQ@iEGJ~5ݓ F(j n3{!@MZ Gؘ=6#f쌀YWJЌNІ:ӉQ 00sA5֏{%ajOZh 0 Av9nXsz*`KUpvN)6~xꍻs͂:purOyvS >H[&ʰ]+bAtHq[(֧-c39V! P&Ǹw:ׁNx>o2 lKRkڞˌxA~i8b=G4nYwϩC}K$[hrg<;(e`.[e[pOq/[ O [ 6^iOB7Ɯe9SNf i {Ѫ JxG,ͪd8&d AĿ!IΝ¯t7ewrc$126h71lح/s֘cbna 4^T+ŎVgGq?ޝ ꜀b ݸg%'$xu콒h|~F-lr`m~N E0Qnc뼃!/æ*1BEla\zUI:Cǰof1Q<=Ay-&l1>1e6vK $ʂ3**CxD<5#b+8)VvΏ QMY8 hvԈ~ 3\h Y-7I6WiKSAiM0;9!8`N=z(*=c Y,-ȿ2O>,QiZ 0GfkVUuPZZJu\S`Fe8}i Q^;xBYW{'4r8(gpxU͎KQ! !^k>ĩ0=3ϫ8:^C> Rl|S<7Aŷc+f|>i5*A|&٤`- ARl{ÞQg?+˗#+.Y![%m?vf*`1.'>+_~R[muPimג#t,(q̡Ez͵AkTNjMr V R(zs{u=4Ou9$ʵځ^ZRLEqaRdRCbmȄͱ.ϭ]aw7m̺qxй|_>Tmrk>⅕49Ǘ~S-`ԅM伋~+I",^{@drtlũ^ sn{iî|0-uޤY1 kg oE-ƊڇJY za|ylv~-؎ZP ]_!rpͪ /-W,m &zhPu#!k; }P4U)'K=s1,.75VDy$B1]R&sF`[f: /J$jq}{kհ~CsG3%?^qeoq%6?bqvpYP {G1i:C/+_-w[FݴANi(} _Syt.ۑ})~A5#5=HkmjQ|Mh; Ą> 2| J"eP3O)O؃>s.yhq8&;SFf !NCgK~}Woh,dm;8 Ϯ<#12z(g&Z0LןJ6+H7|ց0) bbkI[W\d:3v4Lq"61~%:IZK)Ȝn-7st_g*; t4;h^ViR7"iɃ2>m6ђ [j3{^G h~ DT=Ljv.[s|;Ps vMAq ĩ0tGal/Aov~14!#vobI6}Wv:e{e;sm .zuh!TQŷGeiH~gS݌ vMJ]ޕ,w7F,{Lgfw3bq`i(ê|~]#S[Á 3rup}HVP/Iik0l>kAK ~ё8E)ˀon OokbTmHӻԒF>>8NlO-Q㛔+@]*YȌAh|G:|ZZn&Xdln@6ZkUh^Rb'HRQơ{zV\a缿6L$\謦E<t3k—>n}-K@pKv5jJP`zƨA ?NWq='z:KIZ`9}0+jD|XTY BzŤHE\\jR&3MM :} m)ѾB#/Ld]"@<;/w)jO+Ә?>0N0.9p߹C+ n}4U PHfCW^Wf޴ÌS dt&HPNUD|͖ݮ?P)Q2pm[;F~ L^J)u[/46chNqP2zXJ[׊?U]3 ׉{U{ :|Nqe~!73 FP3~HY+GlCMpcǒda](,ѿ/=ɶiaXp氁8#Y}?Xzh7fWL_m`BEof -CudR/NYYRWւ`|Con08ęhx ͕w+<'h*Qlz̠:) pFƛ}D81;,nZ[6}|_?<" lF7'etԲt*g1 HݰSa ۋ:eF:h w%O Y2d^{=OxLl,p\;610`LeLI@?X1LTF/)D\4ᖩH)s!K7xk 'bRhӘ aDE4Cʪ^.]/T~+^>G+evKrt]UEm ; wݵ!K/hտprh/M@~`Z5]a (OWA0FN 6)ܵb;-pQCݿ{lÖ+ޗP3RoaWĖH+꘬,(9qbHib}O|o7qQnWJEn7 'BYP CƓ QQ@zʘql/ ?IPGY {Ӡ)2a79ޓ%v9e$;@YNI^aiL goіø9\}Y0:wT+']tS˂ *l]33w~Ef*,(lI J@zAPIGFrz>j^[7eIz|tDSaFz[8F!_Y,=l{ީR7RSC5_[R C4nC_\5wf7ە7Ӑ Cy MoA`\0^=LDrXSĥPʅDdͻ}DM"0jbOy< Y*rO ;r=z6zYQ4I)FKb\2l<73=)KrK^I̧bR$'$t /P=PP.:HT*eVD7 1hjÿu81q"='%G)$UaMn&0"+hb-0w[yU*"Y'eu|@Cn=D ?*Dz}SJYL6\6? ;ҿcy/(KZdrK/XBl6բ+ؕDZ4[І,Ugeφj>6ky5nPb/0+q&F7 GUA0-EB%h\~kD(ǽaZ|qE``1%Y.ÝbJ2BDz[z5]M銁 n28*Ϡۋs[tnUw [`ovsс~{d_ʵ?P| h*}A`n^V]*j;Vrtg.M]BQd_$e{VHQ;#fXgO*(dA~LKmGi#GzG;vs"' >l?|e P@u1BFihUA sF+0 "Ϛ >tΧO֝d wUd#e4@j^,Nym; BĺŹY^r$hFR8|/|GK`AA-\8"2p Hr(B@'8̳|qo|{7 jI]^)@C կaay>;Eo7vWB ̃91ws"*#G:m.@%9nH"Qe䳚n :xEYl{^OT_H-'fa`ȀsͰ+qTٙo#EjkbXsPVX?pFe uBynz7SՉ^ LNͶJ;πm[<ڿ9T#|6!4St^k|a|ҕROV(7WT`ހNcfB9tƳ*XqWJuha.뮾=c5"(MqbN#*92_f>3G ;AQ܆2LlVJoB2cogPNuLkIaǴ:Fe<t*MbDGdJ!duxz.ZmUNX_B $ãW_%{EHqt@qjRG}p hx 4|bXheg"yRn,lq v>ͅe-`^ib !IIq/fZ6pٮ3-4߳V/q94x{_ xnlJQUjxXW 7o -4kNn}fذ5xgfFc> ȗjzHvcXzs:yކYp].JP7Wd&I+k%J q[,jpZSv:!Cpj Aj?L?t~a4Kv:gOf ujBeXv;-wӣttqT0b.&ȸSoy0C w%+N-;#FRR0n[+V83Iq2*/~[Z<~ۧ3 G;fC~='lvgM) NKHCtJRs 4X~"k1D~uC,'V+ ,E:<QpaX~u0[H;NV<4$iOp@lA54,4wOaL#~Pv>F!i3[DIcN#F9ӣ`Ț1eZB R,K>S D m@2APa^+MQMDT_H t,n[IN&DX6pڣ0CYQʸLv͙(C^d';4'ӂD)y&I(NbPY2 e@Q= &{5sc҂v~Cˋr:| Fn;_afl;0晿'T PAI5ޅ XqE;>%Ldc<w{ԃIl[e[|g#^Qjx.`\ gDKи;\?'ݴLZee{'MܨVQ+!m4[@5Ύtbͳn.[~췤`pk-@-JxȚ;fR>1Q=-$ vijw`c4Y*Q O7Ǘ"Y]%P`M 2)YύyDM}Q.bR6_stIf,@fWMY~nuC$N{u0CN8K[J=a5)EQ5c 66d5NpLK p66z%7?6tll^c[GΠ_`BD5CTh=:I#+w6qʔ²O|܁ټèdMwesObWncX|˷ G/;ffRdhf3+1,hbw}J%CȝdE+M6/]91dBc }SBծK1/<eU^6[8jUgḪa䫎޽#l PXċ'.ӘOpgX]ϭԏe)Ti-k9٢u9v_Vi-B{KZqAmUZyPhAc3 oAzmI(B.|Қ21B>iڎk2|Faux^!{9$}(T? qo3rUk}5[d ]| IǼ@a|!JUN_p0@l9o)Aۜ0kx3JPNﶳђ :Oq XyN5qNՠA"5Gu~@Tu28'ģQ$ħ.$yHY]B֕ o`!vb'V'R@<C<זD_{d7|]4MM+OIQp%[@DpnlV=^sR}@d whص^Oѵu/Ͼ؜LLs*fܱ@u=%' h^o]W l3E:K_ 4 3V~L5;2 "zVl !u?$dl2]aG=u7|l9:'`^] pps&]=2"NM;Oy ANhOzuvR-jmp$gFwH\P:ɓ҇]{""f)=5(⊜AGnܷǞkvƌPR0>r:1LYTA>q}Xӿz+0 4Տm=hK[/ ɠNcSJ*>&8.&V X)C0# 6 \pQO12 *#F 8ŇK5Ztv2xƗp4$[V^1w^ȍ6,LwTaE ǜ7D)vB}RS!xLa,PL(4%!. i엂2) 420-ipA$rіW9FY-EX~x G!RLnė+@@ny6{f@ #};RG-V7_@ = t03?"3^l%sŪR ƙV5Eo"{?O_ۃJChNkj!ֆÎwC;+RfqIHWu~)J;l~AUϢRR6DQh棺G.vFdxXWtFa[fosjeUr o/m80{@2dr_xy@qy>l.էܶ*<ʔR%B[I]?ϧQXW+0}<7wԭ9vs% BvFʘ-H'6S;ӤHd-mw"nH8"69]xPǧ.mpVxG M&]pJIf_Fظg^v8$p#B']胘"!O(mdQ8FkR5MET; Q+g <&~G~>\~'bxΖҵph$S9E+aGLF?֫p= &D(LhZ0hm(Aw*^ZCO(UH`n,P J{*58@9+}̴N/ڈY =V%c^=uOOD5?b:ִ9Kdq3H Sx-nA0?n}JSnʪ'tzXJr~ M[q!E駅C\$VN&F Dp8$|#/J >Ou:q7%w[]LW(}F5 3$q6Ͷ{;i`p$ԛ2Tć@IXp^*)'t b&ѽ DbZNE 82ք~ hr9ÖrϸGJO4r9)DUx,'tiKy7Ѥ?x 3A 3 g11ģ#{7gu=4pn6Q>?/Hީ^+ӒZQ ˭Vsf~-n2T-?w 7fÂN/f=s:t7<Fag.b)gZt4և*0D[љ"t5T(Ofp(O7Rnuȏ(>HJoa! 78HZ3̫eJ $!MF;\ ?&"j!$S!Ky#v3o5?|SaV_??‡CX3O+a!€Tb0]5&ҏ߁wp01#61qY p,#*$#*~(bbQ[Pf;y[:PWvM6@&Qy]uXluGiIPi.,HZT{9EwYT&i twGa1}xQbfr^Uaq) 9 xxݸΫ_I a G -Au2V(9KYoIm+wa Z`U܍%ax9d7Lpk<)"X_dG/pUq Z~ ꆐe?ٽ~fX׳-c SRl jZ샇XTbnu[Z1mvJcAzT40,(񷍙[?8b ޚq-R2H8B*o'yIܣͮT7`Sn?BΆ"sdu>My\݄8;= 3JV ;2߱-A)nRk$ͣ%b6#K聑,[JogOlP}4t!ٸ %Z*O)lղ-CVUu#0LnNڍ%+h|^SZ_&-?O*0Rq\<ӆ?K3.S~-^N@<b1B ̀kDW ,@7{8c!50f<{B 90].W6ԏ>2w3 Y ɂRe~I_ w̧ .B1NkBcqZK6hߛ;Fs< g~+?G>8+; tL 3H i8t˪b1+/5>a렧EdRi9:z;QiH/1/1C (bH>Jӕ5͙ڬGGT*l=xx:cxcoq,g{Θ7W)&(|hBb@x8E*}8$p A<n x/8-$eieDTUߖH ,!ީ'@uז9Է|7 >A"FN)(JT?BK༩ %%]Jͅs+av̹5}iSS@Cav[n(:Yl[ 3T>{pf [D1TnG"KBΑ3HMFm)eN*HO3[辵CBnÖЖl:מD-J̞_i^Τiۧi;Uꥑ5$9(`"Lni*yz:G}SCxd綄RLIwR?ݲԖmqY&FQ``n oo]Yyj/N*b(#tVKjWeW2t?t я eo\BMi/QuoTUIͣQ#Q[mr%x1rBF< K$σ@M͌P4G>vB[erQ{o2~G6v=De9#y R.SuIHLD,\ͺ@Ks"9 NQ$MUc!>T.'KF+(t|d{B ~RWPmHwͳ0so8St||MB{ ar{ܲV8$q]+Biֵcn/bmc&fxO9x*4\ן/j-wJ7e( s2M軚yyݬd-%n( `jN!(e7 2QdF.IOO>c1vw%QIR65OdB&2p5%so>BiB(dHvBXxu'o,ﱋ)tY[ ,x{1Ŏ4MjZS{P Cm *{onu:_*oQzF"KC 3}歒Op?"ԏ1b(r`HBwyr3VZW)XpxfO65Fc(mrٌŗ@dXדEi%GaՎ anM ڋD)S4 i8S хHSZcfMA.$n:ў,acmħ)SAal!fẁB6o5M>,qDh:k-OTa; 9tm]Hjؓ󪋹>ȡ}BNf0||t2˟WM\R,ĆlPb[ᅇ]"8MjQAX0W}}Kyf Nwhyd)D@:f4q- Zcb؞#?&24+Sˊ2S`}rM o3N4XCJ}>oWKO'_B5 i+ri0wiR5]P,8 QD[&ξϗA`ߕUn\n74zV"ݣ@,M|5 f-;tr^HGLCSws<@-sIsjCYsMO RE]ףe)oBO @o OQkM`Z#\ė!jqݫ!R4p-!gk+7^ ͆aܽwARcE64]dmS{>˞nFvp*S m ԣKd;?Vı>Vz:Aő78 7T e$${~s&vh3@ ~2Qޱ&L8E0}s9pY$\!2c N X287q3_ "G5KO| :>|R|diij[ۺ(qP_I0Yצ|XgF3ƔH_MHN0"ίxČH`HQ /5$3L/\m&9GEԐXOrd7~O*}K=W" rjqzQCuTvbg(Jsxa(@ȝۛv P' \wraPO v"Q'fZ+*t1 RBOWnyloL7cZtC Dm&4EJˑsoYy"Kh|wP'X 2cxos28=2͛1l/L!a5Uq=#9E>g_u?$9i!ddZkeH4gѻ Z( Ky¦Gs%^$=4:ǐjaQeY jA :ݴWZC{h% x'4!QYCZ{׭Ǐn&kҌx~;c&9oB/|)v"B /YoNG8i2wDwLf:̵Ȗ_Oa5]&o 8@"<9~?~F1: X[)gst=׃{-pASRAtRaˁ>FB6Dk99.P+z.*jGHjr}OrZmuA!1k6Fy=:f7Q߲#nnI=|=w^h"i'&}QuV T |=ZJnmDaI9$;ogf%Razy (aN ~_܎I^7HOTb6ddSwKLo(:w 뿘O }/.Z w[n=)sSk-<ޢoS%\*[3 LcN%.Nt$]wI HnȦp$Oo#I&5ڱF_AU>H[Iᘬ9zVŦ uGbTBSf~!%!fkϥTHu-^$]0IJ\Ntqks^8N}D(,@gʏ- c*0sE#hF mz`DŽW[5db?+sehbB")9#aQǿ8e`'f`ۃD# lk4J`<2+{zc1])c> ԓP>=eNOr977YϖÌ)-"f|a]]ڑ^x2W]"}vJv{AJK|Zh레7`g"~_z˭C׈H ]ly y_b^;as<oT_#x5{a`;nG= !&8W5]8={m<ҫp0glAL]ԈN^1WJ2ݥ۱AΖ=0F"YZ=/O{ ^D,ѓd5ug/!OHK Ҽ㡋֓[U$@rwև?‡ĝ+4TzՎ]ಘWΏ%`-YRO~3g?REyMy޲5+[n8sJLvؑ\ftDGZ[Hdv|xko U. IτMh 1 +W[ݝ.kf`4"&'%;UNbì,4粏%|beHBKpZFuVZSz(_.`3dw$~/sXZҡ|$A-I'Ĕyy༠>mޙaHA']6GbNΗT~WGRk*h(9cmh ?:o2w3 6}CEA ,hNT26nYGe hH ,ki\86>F, N=Pr>0~ ݈[aicv"غE8]Dɗi ctbo<+qj Y8KmB`<[V ͋t"W[׵o|L|R[W^iֆGA09:c%E]ǛX1h)2>5>ШZ~ӕS._J V[j]fS=ZzYB| a`mnM~ }wU"l4s4xPQ]7@[g( :EZFA)c'>-5-1?IIP2~Irn @ Q̮L<ڍyP ?'uQ_?MrOf89f,X:{]?Mw$ ʛ~J̵:Y$qrP:yIdC&H1lHm2[kE]z&}e5shLzL:Y 5Gb6|‘ed$-9FfRwQ?<~D#t9醸{U]'2-SFzhw1a6-EKzx ,tpp䏲$IgdAr`0ʒgO 1\eNEdPh4Osi/K y3M[`*s + Vb+he,3[Zm^OlO}BsZkDS< فԲ# koS(aCi3]( ! ބ6e~|otDudbx7t-ƈB3 t4t#03֮lD]PzP]@Z >!.E RyȄ4u2Oř}ӚG7uvv;qv%VMMF =p#Z.lUtt%g$@kXdGq3H͒&ܗc$'Zv.yʍ$~]eKOLܦ9>M%81jEM:. d׫[X

)+4O,r6`#\Ҍݗ\#jZ1`n^d+`zaֽ_ND/uvD:w#JkyĒOjb*CR@HP\RǫKaX{a|nk_RPcJ|Qa<::yZR}̌^u쾪*ʹΞl>Rcl1G[F?4$^-q@ $5$O~wهj dg5r8Uƿw4*t>5N71' @xƮ 9"3Ty&b}E#fkhhܬ% 1:h' 3Ci[[Wt[@ɶ0oֆTa`֛ŊƧ[l}d9 cET.btËM,y}LD1v|!̈RxSvΛ"53o84"<-~1;(k9.%iQ{OePT^];>lwJqO _2Ha )k^ Pa1:sM;) xVAE./v4mnp;x@f-3Z8X`ivnQ[v)[o2ݍk=wpLO,kbϞ;O/nmV3rIOU?kSIWa 3栞ꜘ1_eX1~VRVJz lo~[b43^sۉl/ٳGU(O,7̩qZoz`4c0w Ƞ7%1fc5Yk+jصH>Ș\a`@EP Ybo 7OfI+Pa„P"\{zh1CYl9j Άl/(Ȩ䧋/njguҳnƾxOpC+eV~A˘s%'k$,8ܿDx'2IΓfZ$v 5!տ"BK>7c (^*-36BS6 E~H+4bTj3sDEjiT@?tiǵ^]_o9ü@ 1CsF6kvL LǁC=K$?[n`Nɜ ![7M/yʵZ,=JFXݙΥϜYxD͎Bq c'@&9"EKQ)M4c24MZw^lCX+J/Ls`xVIkR.c#g!oCE[I9m,3~-g{W%lús6%! tkRM v>L݉A:<:-3jBP[{w^u ~Mam}F^/ <O10R^IGۉ [6h=!Ö; Rn WN"!;YNaVEͺ޾$t,R&ag PՑ;~\1JX@)/=慥 ,qD t^dCetۑ9HDgKeq ?0gLpZreu|#r"LnfՅCo)Wx\+HeI?F̫O^Klr)cWv>M _?nό:p+2!!b7c$kGN M*P_"WflOA\]7>G-& ۙM"D|`Fwk4[ķ@k=7Ja 4l?#hIu|/3v Ԉ}(E S7#K%OcKK|t{+˝v ;}cN1ZvGow!%SL1϶Z%=Q$cP`[Ȼ7H&Q;ӥ<^k -3_mA"ﲜG6 mH\ܯh"_"z$e={e3JY7W#Is/t-n3].bu)|Ӆr>x26qO.DuIQ.ҨmPj-lX8}q όpfWa!% .aLRGq.;*qAt.4 x:L~.0;/.h`Fȵ@B4@0AKqH}4ۙ"Oq0}n wʰEC G2;AnLSAh,X=pGl &8_5>J97g1M>Br);܂XDP %ID;6Wg8C8o`Ob*g08Ijq̝SK{"6h<#aLv:k~;O ;ZP- oqu HUn Mںfw`9ZJK_TE="ڪn -:Xe ;~\# עeo/&)0.: QYs#sə ŧb(OqwƧatNrg6$v4ѐ3nj&@X4EVk2 "4s֙'G /q*c :B$IB\fhPX*Eɞ5,qN)2!\K "2З} xc`l MvEsKlq 0B:I1;*^z,KzHS{_XW 4y$,S@q4ׂ?b(.Atjk.V)ڇhrȩ K|Y /jgQB0,3;EZq(q:5I.}Knv oa-z `4=OVF?kN{Fj0N ?axO%| ڪ F9k6;qb"D+^ fe$\S' {/S2˲ΉG]a߃"XTũ.5w4{ƒ$w)o"Zupz QgK '_ks`9 NK!M{}sK/)N3+ }@IjzC(򷦃|)I%AB ff8&5L.ԞpFxBvh^ͭ%l1o9rMF% I[: VzkEC2sn+Ѿ f>zK `"{#tz?eK%;j Q@xÔ"^s QnѝpqU(^_X\MU3U%c+!.EE*Psz|}KW++Ie³qeUp5LW[_Qi6G-oe1Hal -$M)hz:e--+1R.ժ7'PW-EeqC׵` @1u;3rk,ͯHzg?'L 0E~5+9 r>{.Y-XA@`J),(V|y w3dh2Q/ɾ[3kCQUCߥ%8q"^7i)ė&NV9w'1%w6X~g_ʄ0,߮zHD"`Mհ9Q9̦&"4rS7u>SH>A*LUx$T/jq#Z_4;:}C<K3c SWU5' k=sHuXDi񴁴2T"h |"n?RP_֌qa{,'xL&'!NjΧ(+ $`gFOaKXd §Ff7]!.Fe?lCXi-..6'FPO+LJ91PEu AQwtfQ(tuӌ" Lx\b^D4ڗ7t뵺&|XhX2b>,lEHZ>-u?}t/ 4ahwt&Sk%9֜IodSM4ʉr(g$FJRɡ$a>)xkńꝧPAf3דD4mx\!?J!ؼޝ7u~^`u~7myZ(}z&.V(}8X>S7)AlbqHL{] ҔЊ ~VK+%$uxV H~UE8j [  7rߩX|CbwC+R ,ՉG!]&.gF,'~}վ9=ޒJ4K6{^[2RaY)*:|ơ[T: ~T`źߒ>$NF؂}7?(:Xq↊U''aċ.JVjuZҶZGT`<Nh։4no?AiwjRyw 0o;ѿV l| :X<0" gPmRSlo“ fڇ#%[hGOadSFiM`Kx ГXSEj}5;%;6!2&!.wV2M?)h8S|w*:DF-zG3m`m젱9^{{|(qb2lEȏK| a-}-Ьqy2o[P7DMv`ج}Zw/ߨ ef0{iB]eb\)ؘseʍ2{I!ő[Iؐ>,ܼfPD4ުQลfi(7wU=Q5r.@|KwqKMltEw2x$}hzKVeSѶvAt.pN؋+E=mlSF)wI U "Gz`߈{ӧRc R,`U?Љ{dO¥$ ,N_p z ȩW tvL[?f'nk+6;T;jL#iNANp#ʳ2{VgN`Sྒrn<DŽT$@+F7%a6ky:6vTR,qA+ȭc#{h~E&ϫ%W|WӗfQ-s)fdTz1VlL#)Pxh??l3&cmoSMյ>>SXOIP/R(YjA?c)6aױfJ|(1FrL* 1[-ɺ+)+Ufms: ˿Ȩ!|~#87 L Omn=5Vr|K.o9:4O;уO'~FyKͲ!c Q|UkC9^ɯ7Be䳉 Hk;r/]PaÍv6qV{hWs {1%^TN9S>cs{O,T,kҴpA BdQM7 aN7z-ЭԦf郻F ?V} *mm?_}61Iq%a%=؄W|띇0j+RLJ\ ΘUrΉ1yk˕eQ/JRFavŤtޮP]_H$ϵa 9n6P.e8OP:V u} ` u0ǻ*b>%%twƣ_tE˥LiV(T 8POk-Mh;OvISBHٍ G9Gv30>g чBb"P5GkGceX2p7Gp/"Ye3t `Äи+zdXd fJQ(`Z w׾GKd#˵`3.`?08JB ؅!Aq[_iN\FFTߦkXN6 Iu}R-p,isl{OOUz4R/vP*V8xKP: A*-vg1FLi }H(r&uéy/% ǽ+C=\Ȑ"*7ZFNhk[bxwM"U<>IE:3𗲂Z ԫGD$e^AB8D ?h_&< @6Vݔb R`[q>GܶLAC9-xkpmdA0Q;;A;F 82`ߧ3\xրiMf"'~l ,O.Er^|ze+4"o$'Ļ4f!d4 K<h+a?n?2`Ve=]8YxwB!/rh /^`U+y,± uСZ?D]ţ5SnDiǿ< }/YhPl㰴Mc\4r0(dACRL<#kI8s[bT[[OKcdEVjo?dTXÎO[/W;ˊK.5}+Ti~iWOaفia&cWԧr(y0KEtu̕MȄ#sC+Np⚅ pLJ7vArmlu>IO,ִVJKQs滙 =zzh%Q[]P; lm٭X.y#OlIF1t[h'`5(C #?xv0sD)Nڷ_M\5zplO*p-+lfd TOV肘l$[hOpGaiבM]`TwA؋SX@uoB1@suf鈂!\5}Y5*ϫEAojk)m!qP >\ײ.(O|=-Ml?]uKY!l#9b|G k 򴚊ɴ|j*VƖfv*J^J!{3o1"'6Ԃwdw قDeF(-tVzp~j:= wfuuaJP^kUL %ex/`PmpK 3BܰQvl7#(etRp笱LS6{懏(+N 7J%F^FhES{zU8EZ׍<߈bH4׫nIfkpiT194?:2P)V!T# j01w3(K̭n&8Fh q3چl35BoƎ?;t%L3k.HNNuA[tز&KY$6'Ì #/i `9fsJMT5j/w6ɳ36S7J ײGaQ7ÖsfzZTA+h WC6<3Ȝ?ʓ^&Q;1A]'| v_eʼno+cJ0uЫAFSw%'.ZihhBXpF}oH͠Wcn[e&"j˾D7}jN懚b!xZBK~*Ql=/j#-v )-|5^pܔrQ-6>ە6.]}%Vp}]$KhuW"@8@iAن+Š:04 *pFDCv msqTIMm, X@<=t &^ ZŚ/DEW"|%EfHyP)vɯ˵JdC+ ^\A粷w (nlH>rگa4dz-c Dm 悐KDYଋQ L[D"faymۄ48;^$>˼ T+BKBpjBif ұouPow*CtaW1$<2&3D?>n@E&_i"1)>D^eSR@۩]RʑsK5"(Wd Pc+wO3ZvZ$ѡ?%)<{MX*o>TvBC~%-ng{v;Y2{Ab#k"ÆJ+Sb6zs11_[b 3cLq{}U kl:tK]_yz2LNia_][%Ih3J,sì>KA"駟h9(X!})sNB,r2T7N:S/P@46E!  ,!~٧ĽU EY"C 䁦#(4ܨOz= e|JdIZQ/O?HKKӎ|ї]S F2dekְ) _%gzi0[Eݩe& '{fni-KAnȠa"GPMm,97)t&r`d P"Å?Yp~{ŤA_"CB?%Ɣoz+`%?sC {UC!4#GegB0v'&ɯ{M D⃏*g5mH[AcQ< QJH>VH @Fϵ+D}^ h5* 4d (s2*üհwx6XLw(bh*GV>rB,mG^PCTI@ .E%ݪ&:-mvgShvaav)Ws $k]5VO0[3]:YD [B%#=&_cLbGXtZ0H[E{쒝djrx$ ?FwNz# or5] 7k%8XMA6bmaIUJgЇzʉ<ԩ\}IRVMJ[&ڵL2|+ X(l\yܡ^UGo(xP{"X I8`{ek4vpl)~֊a_W! -i)j7K e7dh Nj n!`e>)jg9՞IyiܼsX\H#wdh|3Xɸqn@f!nCj 3>{v9r޴IO<5&x?z?UǨ=RJ.u mG譟= HYbL~dCSYaj0oD7fD ؔyX?~ ,MM&\?oMLME1ض!06r(yXhu#V{^JBt_ ZM `8R9ϙ˒h:h!A6>2:Xȣ6(a/*r,ԣÓ)R4m4oJ4PE,hϕM.dߋo!XA Rd*M>y>%xoÝyq+(qh]#Qۓ<%!O>Od(gؓ/JdG;^iнʍHцOoVy88#|H݆)cDafi:409wLKYI3fR8t#6zkM[p#*3ŪJrC1~$8ӄ9֋kd|yI@I h>`x*dWy< WÙrRmlg89s#%x[wȒF4ŠDY{}IRpt;h}I8q >vϼpj)lwu~.LY駸7}h !p=6тT^4?(~rٍ#.D(!Uclz* كpIE8}`hgjME)ct1_өEijqn_3~]km;lyi ,"$艒`DNe |&Dp2 %7érO7-Jݺv0NrpC*=e=Y>T:w/`cJ6ԭnB̫kJ?X7 L!Njbj2NؖD1qE:܍r^˴K ,&($\9)fr~˚m-+t${?+ 421e:Wc]g#nr?dV^9Eyhu(rfJMDyv{[0#\ c &CdA{ք R)ω\"<zI q@@&, (e=C&dyRv4$T [&0)Aʏwd]UN +W}Daü04q2Q5l ނ|v:'wNtPwfƊm@mjr%nUlzt^ct>}X9_'mD0o=cs VxeӲPMT C\ʂ޵\i~CPaSo$[H"T /H)@u')oǀ#g k|ĞwaK>/҈ykU[~!%}u[Qe&725\#t6BsT1 J|h ^+#[ zi?䕞JL؄#sm֏6}ߌ0yDŽ*u(h^8!1o2`3È=k{|#iG݅ cdi/י~]9;dc|r8( LuZT5;=w-W1C,K M"fu`[cQ s*ڷ4t ,| LSla&q-jq-eS3"Eb][0eYCʪkiu=䡘׶13PsUٹ݋ #3Vxqgk%-2bhyZ(i@W+Zߒ-9C83! u`eR:~tzKn,37!Q݆qu,UGCS*q狤ڑalҬRaE2('9ȏ8(R'e|U8ļP0$4bGuv${ f)"* )o IYŸ0Yf 29:H:Qi…9$ mKrNlHsoZ&[YF^ ;3ÓB9ɎhZ%[hToΆ ldl'wwB r~npPxue1'7^=YZF R+ҷ{hšШ5.3O݄nYeop:">4<<`ޙſCdt=zM$p^!\rcH5FwqH쨒S cj"xe4I r"/nw֝sf_KN <XI@yaq:iiVuы.?߫ |C[9%bMsMloHӍHd^ >Az~Ԁ+Nn"%U:9(_~ҠWoֻ(0DZ0L"^S w^lԚP~J4YC0 :J.ו&N妶X:-CzeZiA*!!*L-E/.M[MAa\セO5H4o[sh %F"{?m?`f@6^npƠzu oe|>];fCEWyع.;MNVBD8 !@~ 8|; q1U8{lf' &pAW Z Ǚ@OLB+[8(di rXrK$|dޟ(cc^Ԗ \zn ^|_+ 2:ֵr\xXu󆲲(A[A2>)PGJw-W!#8XJJ}hԋ-%% y2}76AV+ן tmSvP=DaQayהiV}Nk 4Sv35x]^$s;#O™j{ ']^& Wm {>6cZL9WD3y-ҰH}!2+c# Ύ9l eO&Zx1ㄲ&YD6+]Tc{ "kU#} cQ} H[|ȋ!G9=@p ! 7ܒ]~\} \3SJroպ66i' ?5u:B gHuxDeeOt֑BZK~1@f^BpisCۯU%cLX{ntZ$@QE 2qkg]nc;+Os2k-G_a.ё9pm-J=]6t*%TݿR'ƟU`rL;=cN%O<3ҵB ǔ{%a3F?BWzZVK JSjg5lj 5c߭ teB7Mֈʌg8O`z⮌)lLOۋ7(-Rf8F]R`ⲕp&5/yfOO(Vdx V9>~Cjoށ fS{cP1JY=.#7Ϊc6dZV)u&0MG"mC,jkXxqu2 ws;ѽ03>bQ.`cg7uH)t2gMv?)9s n2 99u߯`C1/ ">, >JE>C \2UވTB#C[Vo 8vJ" Wu{,=͒ 6Kiy%c30WմYlJ0J Q)/[ EX  nJ[dk%ĝK_zl_F9x5l U]rrh%LTD !=f\&F8!hF:F@|t498#I*~AET&ݍ"~ZFn V~K*%ޗ>a] 'X չS&Y,B'kfi*ur&zou_ 1=Eg־h-Kx6jGO#Cx0ڻ[I,;|(KS3E~R`!ȉ: Sb3B֕%BsB6¡[(Dv6}+⌢W<^oIw>R:/^d˺ؤ@8OH/*xt]tR9D^X€FbڔH$Ke(PB5$rB K8=Cv%عDhC D1$| sn3~2hJI16%%*|+wuF [2Yx`/Z=F648X}hA>hy6ݟ )^n̜ٔ)u֦C?MokZMw H:!qTazK9pZ@qo1=<6ţ~h1+?1 g )=zׁCgpe>ծ:p!t,S \3Υh AD#ڷ|5S)!eo3|<$1YOf^QL{Xw7W)a=H`\Ev.rY@3~Ѐ>-u}s~59\`gR@I[n'2BtG(-us2۽XlX֪Հ}*ͅIگ/Wd؝8ODѦC9FJDS~ PL:m)=>p~qbnDpEFƒ¢`[ϼ>2⍈)+7A{clQ' P18\p;nE?igcD\mGT&C2#_wxr}WbI[u^.g~{*0H˩B+i2jkMmQ2~rHD ȋY/z: UۜvdN@ TE'Roɟ7x\ò{-ΙI3`IQ)>һTZq~47 LOzٮ?rN*?ثL87~KK84m =&Þ$kDV`'!gѲ_ GdUѩJa֜U>{8 Xu], W@зu3?hԀ>`3W%@(W mk۟G85Hn ݍQULX%>QjHƸ򅨁2p,k+i7w4OB7ח5/uܻOyO;Y' @l†;8[=i+ոI' {FgUtM-q1ـXO:recA5Mdžg%l7r)k!;`)^`+o̦oiVtW?}PJ,5~(p)gz$%b=EҶQ8VeNGHL27O N^Yރ*;,t\ϋzB[E+77ǔ^4~XtdOb%$qE쎟^R.(8 s95QZY[rci[ҸixY leGX2\ZR.jh_]͋ga#}ٓOyvK̘+{,F`q:dLf+Qϋ[In<;BЖQ@-jx^n)-]~~)QiZ2BY'B2,S~'ͽC聪sT EO0nҗ|Am8`;Xc@T%ju6WkCW.r%LyL-,KU4 .O!W N97Nߤf'AY$#QNTN17{4w-#6gWpO3QAõ#R=0'\X](ɧ wjrc.} +HZog?S+UWGxfm6T[dKYҦp΄~#x)<{{ܒ:X_ ŵl!I 绉j9A"_UaɏU>'I2wW_!W2p覇#IX#7zs/@IeǨ!RP:@i9\S$QhyS_ML 1* Sq{nb+; +w!%2P|=@ƲiwsJgK40T;i},éLۦp_ l/gȭrZ THf%i8z=3_#棖i0) خF^eZ8o:h-,Dy;K"$cnh_tB9_3i {HHdP 5:O?gm:ckſ_ӜI M (BE>m7t)dH_yZ|o?wc NoaYP ,liݚdhovjVuEǠxE]xH8LpZVIErxhw+]tvh @KR(^6DPSAڨXi0["Ca儋|횳}oX[5EdѬU}ydP+ݵ2ZqEc";7#ip>#&uΫ1Nd\ʦ%C>kGXtYZY7Z|n WXb 96Ѻ2ϲ_pkHRLqx-w!@x,\!Ȇ\;DNu쎉N" ^(?,+;Ƣ,cƦҎ;_Gڞ<{exCEcE3;DdpOx$Wx.7CVF\"Qdinaгnh¼_K ً<-,zU?Gqۭ 9f!dΒ`Dw ,%&8 qIvU[>M.1 @adxI5P5 -VFӶ࿿j~n]ӹwK.][ٱ%XM@6Isj_*m];mu5 X3F'c1#*b5%yNqz*Tr01[䅉+X `'B+?;P@ۗV|LG#&o"ъAPaVm:v ;x [XӹЭLR^$js Ӳtc#,ZƜѫ)| \0^>sȁ>E0p^!D7~(\:Rc8"Ep#a6=5e^egOyd9otI̸W#4(RlY*l 7|G~OHr.-PiArDi~5DE |$n# PJh*ԊV Uw)S梧[ 5onK@F c8`9L(Hݠ~B)e΁R)z_Yz]P 'Py5 英aA`'jc}KDC\ĉO5܅N'ܠbsf l ,!.l1/$+/U<#zݚsHvDR:|+X1֨Ӳ_]ۯ&`= XT`S +@gXub`n*ǵ`c?_6[nE'c|0(J&<`vH]t@qDv6F6D%<+:JO+m M -ׁw5Xn*óIT7e4 =p8hj]ߦߦy9Ycff@O t5#ro3ϕ7 7f^>AVǍLqIf>I47"ul~MIvaZ9E4WDؖ[c!A1"!<5yi5(PCpT.%{QLca5Sَ2 i0SʀǒΆ,$Zv`r}񦁲q19CNs2Go`m*]d.Hd=*2NU,Pq&pY9AHy/HNK=aW\ra$ _:(Ni)?UٛD} 47dCV|c~^HҼKaJ H|+(x b+6&ə* ?OiLZ`xSXּjaL9"Xnz0!mO8=}"~6^} ap30hTtKWz@P-)J}ˡtNVExN uyDɭP&CI^}hG\f2Ġr*PDa4-`3}GT }sXVv:cHMDsG _U轈MR*l7;߂9[rP}Pu|FAQ+ф×:uŃ8!k:jl&k)fvDAX:ѭ~Xa`=e: FKvסQ_:$d dži& l,|C sZgv)A5*ǔ0o YW{bĶf+mr<%v.+I>y8vb)p RMvTpRfK3]Aˣ_>ONDHN[P"9 5*Zj#]O'O Y-q@O!$ǷgnQ΅ jx3^5#{8I3ҢeQ-g^wHL/ǭ3:VƑXS:jy\7. ddRPDIߢi(5gN惁Tņkd2Od`G=)Ҋo"9\ĥoW#HDzC (3F -<ѕ@*P~× '-}yyNɺ?Cic)K^IY|/4k ko⢇<FU|7~NLpDѐxhd/z}^ ᄆ!/mFFˬ%ki\Z{c 15Ͼhy7&i\pSup`d-̤`ÿ>a5<f:'_tnӷG[ 00I=^]rgߞtO}wx؏ Oq^%Quam >gչk TSw&i܅3W5ö o4>77̱@ƺuْh(똀:"&s9 ZRg6 E ؓX E5i)^^Q;)0x38% kmFГpwSgBE){/Yl)LZ$zs=U[i%yR#۫eaxx_4"?9V {QCy{KpD̅/ W\`)⦜ՠr)eF:eX~"gbSJ}~‰[mā Jk=E<{1-g5MGVO"6(nY"ہGuxu$PUF;N=2'7qk:7 E'X>feXCnҷ!_ ai""QFF/JY0=Rk/gOE`lwQuZҎ󇤭ƀes9X &7m!.cģ<<p6Dp"'H| ;-Tʔ v@l :eS`7R{*آ9G19)WX2r'߶IZl=WO.e_[%[iUM UFʭX<ߞ&@8CJ-k>Gק9YFfN6@29#>QCVԆD*z0CLH~ȤW☾Tgfsj;9טz<[e t׬n.NSkD \POyS466\txPuir GRLCwXN s>YVvk@z#ưNi2Pw%!&k[J 'ZQ&;¢)By/Gt˯7Dk{R{]myMaɮgkMwEwƙmy/Լ ^6%\F;g3_07@ą1vEej: *y>HBwz)_7$/!(E>ELmu֟ cb[Vh4#Qf'Aog*H(_ò2V Sy9T_" pLDWmy 501Ǘ} q,k}qF+i|P;n !yTJ|Us&H Cra)H7"RF~eVŊ־9>Z^d\̖n 7d8ː1;g ??f6GU[g߅*&=U,9MAj,!M ~2!#AvX(_3*7 B%b$ߨç6m:g9D+[co3,qeAWKtG ES 213Kz+S1BelQ<2)2G_t+I}f0(A=d{?^dn~0ޕld%>pӔ(x՜u$t|*h5Px/vYyBf+6b0AȸLz.T+%6dC@5]L0QN@b{17C`T2w{mha]-sSvzDCqω)\'G?Nڹ']qs#]͒hLItp7$kj‹Ƽm9ŋ9WT` -&ȥ2(i ݫ)21AJ~AR~ V56a}C]OPT@/>{=a0si smm{$Xӯ|t ޛ@?_g'2A.=(_P}AJo#Vl =?VigQ)@0f[ ᨊ-v>[v$`f"/S[B:(&q@J?7JmXV y0X+:ٹWNѡt0z5Nw uj bT̍B|}-{ 2ufh~$Ȅ^2m(iZ0LXJ]+[X%D[M@7>ƯߕE~2cU<*P8Րc\q5F/|w^mr0ԯhVHr ^U6puUTV뛄uU?`Oͦ3A7ǿ0'+h.ͰAq' Bw>[M̴t/S(WWh#9@x/R;[6,۹-0vSx$aRB}*vm`U͌w.g;n8W5/b)Qtq\GO-Hr,Uj,eGDSs#g[/@,Vyx5 pJ2㡭 vR2hO5pmX6wb%f,ۈfq<}L='Fl8 \[eF,6 m$4 b\yV;QAtuq:bgc!Lw +r4Ŝ)6\?ڑ ?\{M8x$ h}u©ϑ#a.m}%4'bɝ0D=R:Nr;mt!jJh9OYԢs27F:t^Ӄ6sw$&pРD`Iusg=ݯ%MYdY,u(FDg2"$!X'pO>< #Djr3b%dkV\4!s{<0MʵIAy?DIY V<)x3f(XCQҁe T<Y8pj7'ˋ%'~Peb 7n8L|u ;ϞO~uo_HhwWjYzwŰFe~Q˅+, n;? rZ6 -ϋ,aVOf^R}(:gJU^Hޝc[^9r'YMcn8;mQrp&jic.c{Op^V@~_[~#B$n8W*_D90"]XS߈q}(%E]Nyro h 0Qc:k##d9N85B痸! xa޹oJ9rjyҊD`4KS" *e bx_~JfOpM0btfoG,YɳPnvJ\|O"9mEZ2#cEš EMj].*~).yxt+g?cAo OaB޸mV̀G&n7kH(_qq3H8YU D1uBxꮿ_+-7J{U oVI~rfcq=7BǍ<(6 mU`Z#]~!q:=+fyBS;}aə7oXN<>{zX4/ójJ3gϫ04JLD_>0MO˻2bR9 M8oKS%\:b־[fV[^LxHϙ4NvȞddqgrwUh,]孢Jbkiނ QEWU"r]$!ѡuu_%@*=V[&[CPQpnS\W*閘.!nJ!*Tt`lMdnMZQ>Җ+W%(F MRbvۼE;,,ψ YOi&#WrW\ -t1X jHD5-ҩD4}B NJbvBxǤB(oEAC܋3rOg|K* O]4sWJ~b4¶!S~/Ԋ1?kNW AS3סgD&S*`R*'-zL$oǡ}v^d~΋\d$pvA~E &ulc徽aZ0r`bsWRj[{bɂzC A-!zMEVmA \'9gS\oĔEɕU٣Ǎm荋(320V}A1Lխ nn~|1޳J⭔n!'%H<n+]\T FRbLķI|wۥݵ.KZ3vZ;MԐˌ]%^ vW7Y,]ҽ2V=,?;N ;Chy~'qlx!-_i9Y6GMB/.{ԾY%7.2&D=xxH[ǽay6W? ͑!;Md t6!noqI0 p4dYgf 1%A\AgSee-?^:Z}2s6,0г'UoaAObh%"K~0̝umh%?y2-[ψm; ݸj훲-& lYiu ϋݡ3Uta"7ՋkI[tmwYdRy[XpUNRV%o/O_E^ώxѫC$<- 47IdA#GFl,3ƍb>Zk!A1Ei @JNnTDD{ɅUP)EBsS]x[{//be}g9tAd).XLzXlnAPΛDo%R\j)2EC$6E\y4L?ց0VFW?U^ZV}\3'FI3sY; 8-8բrdJA<ݩH!9ѧIj>k;¦q\P}퀽 C3<@~bFXIGv LˇZQ^QXEqQ@z4ˤ2ZePن:}K1hdESnW5tK\D%1![&rz:|"K ySqe 7EsX_`e}??W4aX_DXW6:{ZD 䛾Xoܷ#]?/ QWڥ:ꦆuEZ:`TOVDrC`l}y7XH0}2$@TLc86&w9VK͕8X >%7AO|;LO6 lA..l3㹩Mo+2EoP=CІwBmVk&Bϲ%2&oJQOUÞXm {Lr.i.=nRH;SR5 &p8ƂB+7sa /7u'EtrڇW_^. YFֈ?NiW@z!$UYyE8 q Z77'4!qZ<^bdlN*65ZWU9[n*HGTiuw 3ƻ|2(9V_uyY>FݪvE?eIHwK0_?YEQI^;xo`otXD ȌHUGoe2^jW޼l7秺ݢn5@\(b+F t#GV4JTsgGJXFjաP7+ 2rrkR-mn2u0nkoq۲8 !ʮ[yg:Va&g6xN#Өiv62I^W]uxc+ⱿdhJC[-prsc Kt:sT @BA 9SxG.Q{+'@5dH0pܬBR֋|R>~nbIS q•k獚Dtnh}*uYgںFL֜UT::O%,qX ,ao6]gUwa+]Q\@V9+k^OBrX HOR[>(#`!TlطJ@an|mۂtӔތSŅYvgl8Cy"F V9ϴMzaGK PZ~q_E r:1u4 so8 阡HJMa\Vda(Zw\34 su;Zj5sͽe߹r0jgۆLĺe˔禔UhҠ8c5h?z##~8rO>? b&Xqdm}]y!UJ)v{1G蓁4JOj|=f SvU4l2ʸobwqd(X5nxwCy+o`r!|M8q.a] >aOF/ɝaU^F>v.'l_+U S+= E, ݫkBs IV*Ď +0݋DJMٿ/_>ro'΀ Gj$J5T{0ҺnŢfC>qb9Vs]S/?߭cAdUIaبMtk(G2te9^uhP_s)4+ f?]] -&H' Ԓ"|*U2 ؞JPib_BH7;E¬?/+#L簁 C :OS_句O\֍N% )9wI/zK 7n=[_@h140 ?U3kbLA m/vj\ c\BUa`11j膂@>uͱ Gejڥ?AQ*gaYv eM4xÝE{eBTbyNJC: ǃxֻ#[VV#z|THM02 CMt>M$6LcIofD[ǚИP IZF[W Bf;~j,MrHB|(܋i3Vp8Z٩^qNhqudCsDm_J$MξCLWm̲mM;;DX>mEW.j a5d5Ɉ4:ؼm6!X:)BRC2jR\ wH+,dv _O3+^M{ġʠ¦98S$[%ҞbDңh30=fz pj*Ž[n;JB'}s @^̛H NEWHai#V&I^VwE);xM*'[rZ߫›&wɃve_4fڮI9hK -dCW6(a6;5>ǾJG^ZB"3_(uşrG?9Hĝ*Set#C2p @yk_Vdar:;9eV#fbnte5\e\jZϭ9 -D[20W p )M a` w/Z[uWWC?p\NXuawfwSҾ8h礫/hGJe+n쵔[Nqّ_lh*'N1+9o^"3!-sØ$V +UV?d aK~84fmYLee"<W̥Sye*7=@Őg/s`by7jzeAɾYp89o(̝#qm1|qCm4dq%L0- Հ1 Փ}2G]/J>[s~wA ޳Wɷ Jb`i)g#U1YR _̮ `_ڞPW(HcJv Y7|8¾p"5"7!g-8_MqMaxIAۓ@t+=X|W9Qk+(5V3 ^M⤄+enDϤ~UH(2qw*ƿd[£r6mw}@'!8v}Ҷ E@̫q3(iSKeDeRb ;4]v$$W3~8XRgon7=􊒾rn5^ҹEY}v?7W~*māM@~ئlc3cE0']j)& yZfm"nq ݼr܎7W)˃xki^DCiRGGv/)`#<9"aYi*OMB(l{2@)u$06/=ׂ,vQJ(b}@JN&!,J }wf ol}K4YkkEWK.-&(2.̻DדxI*GLXf#,p ȱQآ3xjRZkh0*8~yTDnjT\03!5"MB >D~Y5fE w  f%x΅c `ʈ|\Z2bcT9S' "2AЊ3ͥؐ(TPqEw"))sGvEm$wؗIj'0tvly.໌B{C1M0Ua% dYF(̃nIKm SIC</ŊtQ3MzDΐ5p}VtKM u Bz!azv q4d$4puU)PޙW8Uk3N#o_^_'AE' G!wTᜢVھ.vNBB enJ^i&I+z#5t(SmTD:Oj0m+ .BKY igYJjv\Gr^:D$DlgYG)`gJ$7?K(/ry!5o-lď&tYŎʉgv͏It4B ua8ۚ +,&dk΋ҟU9:'w[5D_2S),pH/Vs:'&8bW?E=gTc s̺/l :C%;.J9?BddC w薳LpAFI€y2#!*DtG4zBh $&YO9X:^BfUuI*o Lj% s/҆> 4OTP_$D 3X1<5K?D#r3v+8(9ZΪA`)Z'S>~6P[:|Vc+{K&-?(F3f;Ri?*'.GҜJjr+%od $|P*loc[9ԞAk]z$D蒇ڞX| UaŸK1=5V—5$Q\^̾2C;^ YgG0c&k׫1Jwzd*,Z~bTOl$ɡ$*u$Ry+kb})ߎܤF©*W S&WN dqkpI䑒 zeA@*pQkW |5 P [}SLL%?Ȋ/J^TȷL~@m [L R>"f]* G"*P3wɎO 3?-;NIS'4a~N92A΄4YC(أ6ݾ%/K' %%ҹ[XZG$+YJwZTޗnH( )?Vȯ rP~ZeB!%T6Vx;4rBIK!+Uza; \q U,!k Pxl@.?\oA+DL*J%QBMgx8|[3p^ Z ,K(D19e)6^("古͞2975xv4M?c,fp˕Eo[b\0HWb=%^[CF5 }"Bv*u[HQ͟ mz%NG 9(Sa{c4I cvuB.}]ghJ)ԝ}>?H%REdgfAD?uuPt} .~ϱ`wO N YTnr+]*el#n7-Y#@"")Q 톌B1!UO#Z~gvK3F+q]?lc[}`i>0K3h?]+ m3; zTX/})k 75`??Yg 3zfB,@Zdr߬3i%s?YrhCD7~/X""]æŗB:Nl'B)r)]fRC-.}eRt |0p;u&(5$1 ͺ(\Y*ѺM$$)9>u"ʰ_8dXMwp87alվSwF7q J=< KbCDk4LxL|P٧A"91`^ DKY06*(nӓpg7hո7% Q>rڄ%e%u/?ۤ'忖1M/20n[=2 )c=Trec|ۍK\쩬YR\S| LMIFnH&v/;eX%,RvP3%궺Ʌ/mAf}>5jMYj}?<.ZZ;e=o*oנSdĿJ)} ך [|9p*Xk*3.Bҡ4Iq,}h;'6RE~,xBH H`{:A2[nIǔүT56Ҁ@п ,fn3N`3HoNj,J;_ TNk n/չa38ϭ?VjAH #oG5%Hg ǽ_OZS},y1FJnZ<. YؐF6g\[< ҙD,ꢭs9fAC5~z-4ಱYT[%`³ӥH9Oq!ԍ)p$g<{4$I(u,uixIs]ä4O>[;~?\p e#0hI6< [xc,Jb[ڧB"P݇llYEec p3\z!d 3?І2H$ѯIs }VU)<oWH u6[#Tk鈄l}hĆӠ$U}&J5ZE"[aN/+Ҷ|pcZ?{@-3QN|sCR7 щN"z]<@ ]#7Rȳ7[\rh q=rx"#:T˪/=d$vwͳǝ30(KW`Ț5XY2ӽ\H!G(uAŞmn 1*[浳~ r?w!ܜ^S("1_P \_ *A;!;dֳeXlGI-u㇌ǧ|q7u#A6G괉!ܳ\͝X16{WĩuHM|pT{E9 +H}w]|䠳5 4ÿaEVa6Ol6 t$FG(a^?b*N/DhrViYH10-c/ ώlk xD~hY@ZH@pwnїߓ W^ҿy.8Њz怒A ѡm'ꙕְcL~<̣Y kH6t%|*hp}y>;p 3Mc`ɣ7c[z~`@8[((c#eGNxH?ɦ솆 anN@G5-v*Yoj=@,i{,nwf^f-znP5Ъ!nRiC(㚞5OOlˤwޕ$߇f1_^>ՒRwY,űYx0CuUBF^y *jC(Lzp ,(kGR˸9W^)A 19gMG255֥g<^ [/[30aofw ᔊԯ(|,XP||ٹ|Co@l~7OU? j(8.UFWNc!sΞ- 3PyZ=?rKcoEG9#L$O`؜CEa9 rEEʙYRĖobfҰL+Z?wT4;+w5KϸͣO`FU҃5Z/|=aez=}5!ʭPg0+SYXu8Y3YCrwUԥYZfu ?VLx@5xKG=J<+`Ө2b47c~CNF$d{q8.9,:*⇒(z~.𰱁ײK%CC3ރ[,n۶+0a`<'gX3QM4[7=my:(VrUf9jbnLxяln.y5AL4,7;rN [ F`Ƥ+3MHzi#tHEҁ>3lOxxьL 9g7CăF~BTp4u5値g M-DghIIP#ru"6fEx=)[s:$\C*ȐG>e#7ڝے5gra>9= J4}-: rW(6ո ɁS$0 i+AŭS?n b=@*u(>'eUޭ)pvF쩈fjj HxL )fu猁8K5z |Yl%W #~Dݢ v+jߡgG=ѕf-Y9m7%+H=ŶkLѪ?򝤿7 nq*dZS3 "|*G8 Fmlr\spW MYy1Dxi{_iG/}01Jk 6 ^^_Ka sIa{l)iSAS2!X京/.R-ҷ'3k]J]{ f`MxP/$"0Ӡytj-Q{Jnu`"y" }b5F^-0aǏR_D+=QXYV]5X$karͪT `] a<]< A WlcX!:luh2,XT\۰Erǧ9Cd0k唗¾6kO#n> {tFD/Z\u hʯ!eOÇRQUVJ?k%R@mc-K v?^Fc_@OrMjiG)G2?]%D,ڰDz4䑉:>"HͼECxSPX5\%"%ZY:)i*mL~7`d Y-j6o;Cl[:o[qS3o9&!ޡ#6Hp/{ iJinKt 4 R!Zo!r ~Fwe3Vg[o];ݺGaC{?Zu"s֑>OPV l<A_/}z&.eYC2`5*?b\JV1Ņ"p>=>宨yun_D]+(Zkd|`7- ^Y`8-%8Ԝ@ˏCzXY xOOh>? C> 25,-E(T26xhc9]THΑ8QVqˬ q54o?׏"fؓjǨ$8)= hOXHš[c0mLn6[?C=U-s?#6$QpµdՌj8 .qjG1Ú0?@hEWQL4Pԅ(K'3lpng`aY-n8N]t- h0$É[_Jlx? u9~Gz`hs8Z=_px1R_hsp{3zV3\zgb k΢ f MS`'y}V("< <0yf>IΘvOPnW*_#Z I#6b⎏f1˲k;Q}>(iz1~bŬ:m# X/l?OW!ZfʁP xGJa'Ba2iK6{:+;T,W싃 XEc, 0oHlf,g|6qLcLކ ,78F (*0o 4 K3 =f@_yg~( P)M kS}9Hé)R".*ןF`-|b>9;*`RԦ6|7 k!޽ ~Ÿ?vyWGmiʼnZh)mM=qdEhT=MPzD(BӦ׮|]^/sٵk;:bigl.6tg^wR$&cqb f?X<;26!)\3=k{fO5ٓnV j\'T'r&i]U˦Lw |Js8N6YnZ)>+HP:6H?eP9bd;ñWaWlSA]S7/KV>'00jm?<]sa.)z_|n-_X'>v} frgqL_`{d6U9BOu[E* uɎJ{B>c`_+&|֩%!TeҳwF~K([ODVxM킊CrG{M"nJhԞw(lsS]\uuuAsH] q^i$h_t^? "1ҷhצ,S_WWNACa:k,| u6/&3617 yh64aF.e1㨩1,S|6J rQl>lQ拘76J`HhX0Ui_ж䷝h+V }~cM]l@¢GՐ-9*c# oe).Vp/,_^V 0Q>K ):E9CX>#b⼭[`w~5VDi4˴¾-l4O|m#*}u=>lLݿJي|H}V_IV.6pίC(ќjʎE>M o\)mv\_eYQt<bVН}* rJBl U>0R]cR=YmkɃi 6p:ߵ))"Nde_[eLģE/y%[X;"ojFq5t uzQZ"[T<5޵r,&D4Q'2x#+\RZ/;6?0X}o⋧,""f߃[HMA}UJ{(uzբ}1ʓm,YCնPw7Y,e:_9oFtn ">Sᱵ-4L"H0oeZ=A3W4mk>Eև.K^.Y?g7jwXQ5/N%)k֛cA<`y m(?͜ڬD=TORbꋃ{tbx~\2E>Tk)z)Կ+A+{ /%zYw,ACn*OQ?RhilGOKh?QWqlO=. țGpa2MO< |Ի;kbI‰&gX_/d—@):H,HQ쁞K7B9ĕ4_Kaqξ_i3/(Ԉ9{EdI%Ja:R14xùfMd*R#NR`Ylw u3o!0X /?@uϐ=bE7kח% ~AI^xkh9GL:V@8|Oϫs.hweNmT}X \mP),@hkEb=?} ىTv_髮vHBQgP+2t`({&a!4`"V>e8wi74_N3\uiN_/K Oޞ} `0q~yly`f$Üv~:C\BlG/~gsljS /Ov2 ?n"+:@eQ5>'s[)CkއrG251|LM :(,Nv;vp:ۓա)%tu?'s]P`JԩVH煚J$5Tِaf.ߑ_w#~.Knvteo> ߒS Tn2!uMלRi=ygCLY8:I`<#uۈ[ *^+:i%u؃Kl!+nv l;л*P>2*dj%F!E ႟~x | 1J Z ȬOo|l+ _6fA ]!=u)֏3)=^T͈5*] >nqB_9yڥ.;q8ßJcvYn'bڋj˪`:KN:Te (9 }0tHyj<]M ~Gcjai>>JeEQhVASj+>|,~/Aʷ_:}F?*K&`swz*ߐP "s!Hq#m)d5Yk nO4qR8.쩌$d݋-02P; j'VU}cO-eTT M fA^CuPg! F i/?_ދ`xԏnw~YV<ā̀"+ io.r>6.2SLK!wd^@ykA\zz ӟDiYx0(LY*N!\R1_奢zgŸ i'`hoiN/7ۼmԜOz34GޤXUڠq 7-$ vmx??|47(;jt}E*^yz,>^K\3fVcg8Ł00Qg n"њ;z@=ch Jta1{M๳<_3+߻M2HlG!YCN/oMUݶg~Ci:Ȇt<ɇcju#"ү41P5tI3ڨn7EF=ªFEY:oAάsu!ŧZoXz}, J\`&i)a^=ZO֯xe4,ރ@XBGG[N&pXUW2S+IёU9[QC Jv': aYj=}jiy[ʇْ鐳F0KoIx*AdřΣ})`QZ2h:"\a1"YڝG'ܦ7 '1UR;e{澛&iy-+K-&H}A9+~k{GVĹF'Y4) X\Q7t?H&Yg-F=@|IIiI7^9R(3 \@}VҰ,,/73r֜Zb[0jheM^Kd8#e}%@}} Py_A@a34fޛE7uG u.:Њkݲڐo:m81aKw_weS)UoO6#O4O,&m!]9~bۆvӥ*X@I{dqcZ;E#H?[Ƨ CS/n_My"n6qI9,(jC9 i8hհ _gwd0,ؐխX$2uU$nreM+/G(J3evHgң>}:F8Hg"9=a9hD0vRFu&hQ0gXP(E\" 6R|9wN/`S&AÎ\Y]au8lb,6N1TJb+P\kuO^KNo$B76쇞 ȯN -W39p?U(bY uO|+'&I7]wCp/^HW$rR#u={Y[hN_!x3q p݄K ;쭹yV,]0}ia'Y:6k>7nU.k V U8Չ(&LuKq5RӖb^ioyB+E,rݶa]"0ޟ޵C>: @iOzOv'Lk~G P2֮5*VAmO){ﹸ 0[n0.:|p4"͉f=ʶ΃;%}4[!lI..-Mwb{#%[;ׯf%]@9'niǺִYT_ݘ96y^n̜5LڦuV6B6s"U1V3.f.+ڢ5IPDgI)'Ag\O$_RiTn@#XEHu8t4 \WX6bNHG7jRinÚCGp+|H6)+(ҥ*J%%wmcʢϼg{)|Eg `UN<-3g,֨ѹdNP<}n2Bmnsz{vtSAt&%*3TڿdƵ CZK>AH5g?/2[E{!lSUfnEW2&<,,!4 /)VZm--;pzvʪԮ."Zz4BP~y")ªׯۤVt8:˓8VT*@ӽmk\Z]]8o @*SMZM`Ri/Ͻ<[,O &gy C̛r9GI:4(t1BnO}d/;EauIjh#?)D7Rc W4VrծV5UiQ$ Y(ԮUL 3JbjmPȴRy\=QUk1v° nJg> J BjEq11 MݰG$xI4m1ꌨPh28 }*.sy~?$ϭ7PƝJV^3U Nn_~ax9(\ &W*swb@Ʌ2ayKZIV#lLNC1D?L7POcn*)1sFLGu1渽'|'Rƌ"AO6,h^۟XmgPXc.2NC/Dݤfm]7Z2Y\$_¸+!!gfuŊ ̮w6 <"h/~^!ܶq90v%9 ǒ09Mu$=1b}NhvZӚ~{i|wcNs-f,C'ԺK[~&\?!uJUxC7!m@K:¹}FiU{N _X;HiO'UVCbUN+McfZTPȔVkF (5MRIꋨU*g?l3%: #M9ӰJgANɍ*LTΕaǢY_V(ěZMtny/? )'̋[mgVl:7G1gݻ:^g3- -3*K8A( OqXcIWV"ƛ^jU80F{$Í),ݐr|dsM4]fP[ % KݯޕF%@/mohX`]ѝS֩,F|V.K@ ?&N{yL>nhAx#{8S "Ru QZ"X:w /J]}~1I~#R4L(\#ȱ}yJ7ȿ^ rz=ÍTRS {C@FwR{8d%geȔNJ˭,f8~`yK ]/%>i6S8"mՌD9hʥ 3spYrʭEV6O+U<ꌳaS]s "( QO^)8hMkPƬӰ3 c1&ZC]"rȻhAV̝Gz4^O/2#agj턂N]01ZQ[G)6ۍa8Qd3/viPM1v?~[2#b R#0JeFҲ"-4,lI $<ٹncezt|E[@8ES-DS5V՜hۭ#;eޮSB3XdR9U"Ap1\/7k)Ӧy"D|CKKA%qh{({YWzm6H6z604 7aZWs/p O/79J'U٢&'PGI⮽ $,_9`z{E[ G5I'Y?F5Ʋ~Yl(_L ЛC{SG ,BdMrèsƸYi_+U:Qehx5H ̩`t:«kpX gUW2̘G!* XzRFVc<3+$ZDMhdG'+p<}6Z`ne%MQvO!T.̕B:mʱi1 2f_Qe MWr>*kI"a-<, |K}]5)vSntR0Sv9;R]%Put.Lkj(G`w Y %#sKAu0\Iwhz±ؤn/}G70 {}n ţwFZ_MХ-_y^.-B::I~X\q袷s}uh&0m]WδWZJ/MQ|,Y5RjRў7Y|^z"iA΁7hJ7A{4;D'hB,]c` Ā`yӫ+=z\Y>G}W w&i.RL>dF:(%B=](XᘊԬÔ8HHl4jM9ŀQ4hN!r1ߵ啍8k<1FE%{lmvDQ*9(‰=xu4E8LmdmY]}i=iױMSGA؍!45+j&cìRP=œxJ}7@mȗ.+ MwqaxBzy-- mDRaTӄ5QE,|ew?ߙ bB%ޠK:+[E;ހ Zd+=҇p z4} 3TᝓQ϶yv wUK.eXR3K!h/TNVilk Iᇯ;4Vy*spP*!G}*_9زz9j_Ql-NӋxOM,p{:tChU/v[GդlQ)=YYk|bwFk3&m˲Ϣ\u|Њڦ`Z<`o2_p˚N SxԲVKҞK g~݊JvpjŦ~5FocX9>FOA0k 6%D%uZ/Z8P Va8D79- =oȞң ϰ@%g,c!' ߇'@0",Á.Ϧ2LT~8kR=Qq1KT ABMrUVA8FL{[A]jv&9}1c6FLLt_PyТc5ǖ}=qb5/Z1Zѹ"L5I~rs}rwqϿB|;綞exMyV:}` ~B*hxsr< dABÙ $6w}ъ-leam'tzyL#n̈́>!{dvB=&PPo P atBj:ۏ|B`Q((; lGGD/ I$=1ʊ7cԅ̸&r!r >d7?p*yaØS%غ *f2L}S|I:NnJZ'q9?E-^3D'2M(ٿ(bԈs:@RmmTLs={w\Ppt]8Q;W [.m^Jy *:W!dl?0B6bדm@NJs wP5=^<>}([MÆ;#{wo,J2b&U/X0zlYdV}Z\v04, & rb&bzjtJGTlw;sMxCh3fdY0MhMF'}, ,`YR|z>֛ l;;)=HU8 ^ ~*Rz6*2 |_eJ)Ⱥ̶Qඊe-b1)bWؒ=FTD PM_1ݛ m1VۇQFNv1 e'y` #[`)v*"df D~B̃.pF\gqj3,uK.6igu΂"C%tNZbWiRP˸%AӊIy /~7({;Os˜II& <]=FV#k#҈ ,{J5{jhJUfZLB1h`|ÀtQ6q+ؕW=Ӥ笱IV.R>kX۪X3pLc:b\)94#GQ|7FM4I uEJB.qa'sztfPY2i<떋K# y\,P]|)\(뾠`lPYem>12vdZxfMC</E5szqJ^C*M虉hL 49 7= C˜NZ1M콽%L:bߪlx"$8rA,ѡ/Id$ G¯a=(B!u 7HC~14fK"Lߔ@䲳3 lGUrq^:`&rC(M\)j;cJݍ}[>ӾeyrY)+hvӋW][T ]کQ<=vhIQC*."n0~"9OR8ǦQq~R4, =-d$-F @Gc_C^hex'R1P>ODZwyԋ6 ypbqEx}F2*dQz''ڪP׳@м6EـTK\ i% :/٩ỳT%PQjHpݕRӅű0ojOqzI * KytxZ#N'v Pf{Ü҅x*4 _ 8rб; 8Jxܸ7GօjTA,v;#g:4f&o<`K[bIR33JWLHQ,r]+X IfHV ͨO@Gw71hmJQ2borde[vCp% Na?K]aYekR{2q`"Hy̫x3Y-|k`M靖rqg)7ehnStj}ӑU O!j֊S" ͢A=n$tBI^ay0@Pi(K+^ r_T='ғY?Z|.h,y|5jۊu o#,SH|J!݀>%Lu|qcղQ&r'MK}0ZMu oUp_ǟX%@֏Xg6b֥@0إxB ԣ 8\$)mix+OZ&঴E&kp3N(ev*7=o&{2wvca֓͏wc?p@~H1})$q4[]<܆GtqHg"x|8确aGS!)$d/}9o:N-RZR9,3>b&UӟmxAAQQ0yk;fbkMSsSsTurx(4:WI>ImL3K|+}- E K6|@`TҲA|bng|VL9Z!f-1+_S?>t?[BAr)|ٽlqשq/;ȏWg'<2+(_'lc[0\xo=˸tWK]"|XErCVaamm)~trI?clUwj75|9Vy?w0 }U= S[^aM M$ Dj(),0 !c'آ%M `>cV$NYգ7"E6NH_Dv`v5 lIQM^UvAi07U̝9Flv8^GZrDZrPG#\ڌJ,2efoK^sFhԙ^(Ytr ͞:}_5@pv{hl^WJϗQw4᪅7e>YWXQiiɱ;c ܣǥ/,|Xw~V VO hT xO+zMRԓ|% Z[͗4-т2݊{ 49޲8:=?[Os|f |HFE.)Nuq gA ls!؈ ;(i4@(B6: xBXDK b"wuv9&yĔƃ"s[}?$2x;yÒc腁8+y4# /[xF7pm nr ,KN#Ө>7{7,'5u{T8:RlR,ОGw'f|3 #^(a?!ʃtoఏd,t͛aKRP !%CvAeC^Q L%ǐN*3o jK(k [Xi/GrHv'{t I#=7N}8CP+_5"(X0Mvya&խpm| Qo>U'*t8,w lxEmqc6&FKDH=/0=' ^)dB+G(}:\R.?3MoUg[*.gxY6R&(UJ~v4ŸJ|Ys͂W] !ϓ:fMU^HRaP/pv+9Eb(T/(S\R޶/Vǂ&4\=^ 7ʞ8_gR@-Ube8.\W+XzoIQ"q7-:]zM*ZKuFܹjW q[# SmiIm%<8atoʸ2cѹF#D@A%e[~bhPMuZwӴK&B`(?zX@ODOϨoP3ya"XygQ"E*"4f~oj^bi}"~0:<G*rdo W<~A{LO=hNQzkwNDMP⦂si2hE4]DJȾ{f4t:Əux5经yMpG{fTx ݣ#]#Ƭ:k^նHQԟD͊5VQg@56b-!tCbrÞAg${EV4-^\zM|u['qpyWeˆnv˩pgQA7dRz-C;Pcrז'@i8S DnxNؙ]䨹`t0cfohU˕]OĸEB]aHߑ$vjҟʴPf`wvpc|ݨ#N!3SRQЀ ctډPQA 66E'|-pAR59S\oƏXA!hӴ6T:[0#U25Aa|6+K{EHś-jn#yѪumj%$VmڎEw&,Z xqЯ#D[GC_ X )5!ʴaޝ3p4Ž\:18q9kձ6tbBa(3-oH~ #>KӖ6F4<\u[$ | YCL'G6k ߼j.HE$RfYy}$\O6h*Zy %8byF6o\Ƈ6[ X9?-"3({AbrAx {bhׯEz|8[U4"eOg+2z)7]! tSC*CT9_KWcq[U A̍(ƮOQp1r {~m;3 WZҏ, wPgoܛ\,5L3򠫿vN{?F&f <؏V;Z&SX?}<_R| F$>=@9V/%<|VDDܨW?2,WZ1 vIWQs4+WC>ȸ'M8VB|*MA tmUw&Y~HiH- 均'bn_Ĺ0lJ k2'R|v}SQ:\4LZEشC] Cq6NU|z@}i DgHjH(L!io!nWYUI6=\̽Fē#,j?z1~w}Q/;26@OfR@9c{/34Cf3"3֛DxRC8xkťhpH[a!dR0-z8|@ȧc;H?!Æ4bXGn8u@3S-#`\V(p79K )+9@eƫ*Y=Q.r"ƊAHG\.Q/H&o4ΐu{DLuD̮~=K6':wPo,ܿVv ] Fȑ^nWu(NlR$l'f;\pRp*%pUH֧,9aF;C{]sy:{@$> 8aժ|N k,p+UoFOE@{ysEzÁy^b^ӣxhӀx,D<3"u+(2Ju͵ơScEirq^R֤Ě-L7`CI혡dqKxp0W?"ጢ$=~C)<&&zXG':MmEZ5kvg>@j;2PG:b!@$YDF0|Š[_vdZ꺏 {sDWMaaځ}KT>cW} ?N,nA8i9:*4 U͵v[LO%(#]&vQ:ph@'kԼ[Xɸ#a얟2'6\6!lW8vXFہ5!j刞u|Ӱ^t4PmrL$ {^2jʟjGj}|֦ )Ŧ2}[g"`3i*X}affpX':j/(M0j*VWJcQx~y/X2V>:VWXFRoXdwQB&5> Yʪ%Io!le~s_`N:0Dkʼb+Rl"d%ހlx֎Ob~ĥYT22o 67 *y󢵺*\<{gv#Dzv  J~8aRwE+p4[ Gz W2㎕ ?M$M+E6'/ fw2ܧu@ K;3 {>vPW+'ñexH$E\i}SeA句دø8ؒҖ +-ި'Z 9Y aϭ>ĩLpjP,Y8ytpŲs *x%H*jwmȣ*慖g4FilR&/Td9֮_ MZ܅jmUJv@p:W،/X*j$3x0k \i: ;[tUw^PR`'M1gBh`Цq^:ᗮet"_RXɨ8Y*4t"r} 5HSt?x:3 fL%Hjy܂O6 M!ui^A-Hj[++ߝt#ezQK_a 3x&H*xxҥGV. KWJ!hSV GrU[?5 mEȌBvH|)_d L%'}Ыbf8VuDOa8rq ܼThN1%zzD-:u{+d[0u]^̒ێ-6Tmu]m2KJ^嶸Jl?;rO2[MBEڎ˘=5žgZ ,7/Y& 1VUQjWNl nT^pg99kjd-ldɕZ/l~~Tt=DSP~: t0|?Ã7@і&-'=(= @ A0S٫#ˊ۩#g碜[/ލ)Wځx'4`=PL8Me4*Y^dQm_[j\9\Úp<9+ef7qiw}, 'X˔j0΂=y+Ҵ^ʡߚS(D8jPmK箴 y9s&2 py6B85՚’8oDZ}ԇfY&j8R1mվ}/^6Gx], ^N7xRL+ IqDU: t\C%ԓ3 p7o/^E' PAQ~c=x+WB4$8C:(`RwUb EC) nD9jӑL_'u,%T^ﱜyPp-̰meʦrv kSp)S;rg2UBش+3w΅$`V97̗e3hFl.EMEN3̍`X(FJx_XS>o؞5SJ;:3ĻPg8-;r wj/U1R(.m%Xf&_2q[ Ayt2*K0d3g3 d֝}F{"=9p"hn[F& ,cj(WR8-PTD(PzncQZܬL.#!8xj!!Ku(Tnn P7I|]1Qψ8Tm [rə *N!jb_6A79 )EnO2A312S:u)t.EǂflK!Pv)\ *RS櫻BA*|z$@=E焈YzfVk]:I-r$Cf!-ݶȏtIX9[y^~#yL "[g?t738!]RM8ʾ爂:HQ&&lځTp*iKm*1.>K8dD>ZPҩ B'kX]vW8z#^ymbͤvT'gC]\LyTL1m‘clZ ʒLtBi} e;pd=p-(\Svx[*t[Ds]Vm,]bbC J&˾W#pdE,ta$,(- w"YŕT"?,T_O7m蜾1dQŹ#:,>ʗeq=k}ڴ7x hOS;0[SXПH=Q{9+Oh˜uK1$9 `ē;qȯ9%,)VLŅ>Rr.Sߐ@v#3D`&ֱ5e*AmZmFA6a{:e Qb394"VگyM)LV16R)-öy:H[ ~zp&.~,D%(![B~A` g'v2 ." wEK:9J%sCM$<*աz6!k*P8Z5 AK$ * WSnsoH"+R& R4 $?q9"8-SwΟ .`=Av0n]ؽV/B<OŦWNb>R\L{S WL8DeFy-:ͥfq3Z0oP;mCQn d?Tcd2sPU:[IL:]Cq0.R#A YG 8L{,fzZ[y&;r!Wf$X Q+ e؅b]bEM5e2?Q=ifN(x9z +ݖn@dy̫-Bw+c89JIm c֓|ga Xi"P;\9-qCPEu ]Ы)1~H<(Ӂ;蝟(p/>eb:9 սZcuWMJ-ѲM A0ʥJ}U-;ER)7F֌ˆrAY\>ݻ$bYj[q(ɀ"}+ & Uz|ޠC }cB& %^%T? ?cn&FQ-lՖ9݌M[WLzDZQ94݁ s@>; ;4c(2ȅj>- #I߆p b\ _oL/v!n^[b'Cp>x瞃 ]!V/}߲\bql]kűl&4l k܋28iIBcXz^ 8*GR/jL~SqG\F@${P%NՏõOrȧ;"~纑)f\[j,Nj>|9%.Я3󾿂.e|`b^C 0`JЧ%3*/ A&pƲس̇6ʭ".ulYAbK;. '<ߜ dhF͵?wnT䔜va1%m~@gֲ ZΤ +ܹ evOM6xXn>Bz\ Λ 6وHŗce͖G@4^LJUg} :\7׫X%C9N+`$I`%m7:>xM ËC6 6|0?ޑleu>B6ֺOMGj=w{!,q2ESyK־j8r&$i d^—e46ω$OH c D, r˂)>^h]4NX{4I0+ ?+*fJL9;\04[RHZd$gUQQ;j5TR*K\Smz f53]pnCdCV;]$[ʪ,m Ѩ+ g}t48p'䫍 {: :~4y]5 8xzXmbp)7LW%gß#tɵmҥEZƠe)A2 To9H.}ix]K )?P1ߍk V!j# L9 MyC) BZa,gS1N軻@Y0D2#DҐI/>̑~ =-l.ǼR75 bF c@EiUv=ĸ%-hG|n[JL$L'J~*+gr{&5? `VZ;9JB$Z|HN%UטfBKae{OoftW Y.a1Pm r=TʝO-.,Qgb&DZ%j0n!XI\rN]:>O{DqF"hc$n0\XrIZKQA J"ZSF P\9)1EoC~5l+BK܉4ğ8'[ٷd1LİC+sU3џYFE1;@",G SvTZ_]7\׳OKV;lmFHmm |GGY޷$jw&nڀM~ğd( ڹ>1=Y,y i\2'=Q< cBGuV >w ?\RR!"^zk+KM6^ td3 6@Xϒ>™7x׷*Yv!6]R--QVr[cbHHC ap$6nq!F?&F'{:D\*2 *ЍAF2- :d^q= Zjtm@OgJ&s>5hSo'zq{@k꽩Hwtnhm+NcyqGB=!yN:Pm JWT Akrw'Bp`9Lz&m On]{@5-h& JɡtCxٟILtapσ`#X_>k& J:}ԛ9ևx|PGW+ &B/fRCʦ=:p.|HP;qQvˬ7u%а0ɄW6: 3ky)ԒPPA? ˀݭJD|HTUڑXtW*HgP&0_J m::Wy1,US :0äjxʤӌ Aq|q<1M{<t/ܱC'р3B_y4jwRcK37LŃ `y_P?,u2;HJvOKO<&.(!N |++b <XaE2j eLj3k)qI?Y-QTbjWfښ g}c ԛU)0ɲzb`@־yPNt%CXK~uScGkO{PxhM91+v:+^d_0CswUr}[YvxE6[Y 2enD&fzEG}`,_|{_8~D(U2,'Uf9ckAS͊IxGe#(AK?an‘~ P[HףC`#vxKBH.Y?.D\elmxg yB~8Nج;a {(y%@Nc`-d5exkIE;O2K G4=3=Ý)_d庿_seaL~V3Bqu7NEm"Kɽz3d|h֒̕f2t%Qwq%^Y980X kw\ XB{߀g 4n4 kICuh,8OjD|l(q Lq@薯qRPVf Ɓۃ`8'\f6hDƅx<(W޾?¤_?Q5Bي_ HwyN |ѧ9*Ƈ^Yn~ ٖdEEx0>_/qKo #ӔǗk( R3v.*AT^]K( ̛$U483\Qd9ŵ}O<[IEOlH-'I@t^g7bU]ؤW9R&<# xK}!9Z4(z ׊7p,SO٣ >JtZ1!eޫ!R¸2\s!6֞U~9-ir*JkHBrQ=MQHAI8;j z 8 ,frWh@VGA 䜘4#|}ųz` Hq{ r"lNqaHcO-=BrXzGM9ӊlYDٙ[W""ҍ<B=ťo4xq 83b 71Z!JʫܮoYhL Ն7 $TOtAGDchπָ{-'ӣe8z#&-NuO6Yާ{! +Y9zry \" do2lO@Au2-ҘVHf[D~S׌w#!c82[ ,`2C9'[GuU `P1{w_I'Alf,\6{<,rQaQ8EiA7G5a)"TπV*65+G"U-R}$oo8{hɉp+@YKu=U'.9:(ɾ~u vA꺻iJ ւOnK2dK@i}hPʰul;n/.oI~j%2Y 3?eC]$܏"ގ绠pND,uNn{4*漦Oe_[}ym` + iHW[{cedAtuW$ªP<5`dx#KlLP[':@{'0 \kVye=UHki" MeڠYakP <+eigk>߁yrC%U,ئV3 Zqo[^E,Y\0RRMY-7.lX]O;>/E Tm!Aj9Nm~}ytY~Dkv={tcMmYrn"'ZHP#*Ut"TlQUt Z08$+pVch,u]#wo1\+,/i5o<-fS3`7ic!@Lr^;Yf*C,PXljYaS/ǘ(Jҷ[X#&إP$}+`Fk~KE"v[d۽7Ż.#V H{ K̺بItXfDzrŎK^f~Bq}n?.;'z.ݧ^)YA}G 3ô[v'?pLj>șR'ތcb2no0,}ymxtJQ#g|4xKB8ZS x}/AEbm8%xn;nn4*1L5AV^u֕%H\As;_Iz͓(sӬ ([W I]Ju7U"PqaȤ( !A RRE8Pv{D[9X^]t$ԬI Le\z/,?4\ehHlYiϯ^Ha+(aϩ- 5Rb76,j.ʃ}?)v4/n藌y5Fo}Oy E!a0 谅^ƩrX잍`mVN7ZI{9lJ?!g:Z=f?"C7O$(!*9?Tθs@8'J}7*5Pv(q!)`nVpB $Qm/]~v[y2uԨ3+/M2yz<ߎ53>kKb*}A! ҙi_hau4\},Hu(cԈ ּ.$nlTL13,|3?jL7'f'iiS2F3Vl9;NAisb%f9T&@gY,ӫZNCb :-V~aR8aYu7kMo=%Z@6b, Dz3I-`ABr#)De<}&>|m* d:AVx?gziTqLbHG{nrIn+A|,nqw]RnO. Z{BL?Mئ]m[uR;2к1a%\yCO{.0+F<0v}!m2Gނz`:ܭ8huIsK쟲/ /u%94?I^w ä~c i  ȵ+[-ۦxǠv@Ff @pquʮDjwŽP Rʆ5V1l4G@i֪ɖjӖ_K5!q6Ê rK䅛;L>_R߉^m_hH% uaM)= TÕ3񵳞YUQ YQ R,ik*{FhހPyc`䱇>@3Φ.q!gVM"ƥ@!I{!aTUAyUXW m $FzsGٌhO A~a% z+sA{N0ȎPMtp<;p*v"mbTpw Zli<;ekroK(֏jBפV)1!{(cB-ʕ/k!:㭑s \ 6İ:o| "|)BAJ-(hH4>b.r[.@70H.-AX("LA~ Zm}5̞\#Pt(j(dU^-rboHKCj8L}(9>BJig]pv|#2@sҥ:SuA{+/zpS@y{w@hv܃ xH\ԑu#m]s`6 ?q5li~u7[_Ʈ.ڰ osj3 +љx_$hU0LH.e8*8\ġt$UmZ8.؇%"qmUxd9g8 1[az0 Ckjf(ə)WUa0S`=& ozY6nˢNbLnx;ʸ Z5È֕yb;]LhcL6M!M WO7&!FjrWl׌) A{h|,PۜoJ̯VOfaяn@ J5os+"W8[hKy!E٬`1Ls_6YJz# x(vhY85vegz'9?giS"BI>uD?{mLIBu]Ͳ$.'LƠLг0F2?j`i/Ʈfj8,Oz-BOSAR9]D7Ne"VVf8fYSfyRL Т2n9x:s c7`g^!POUĞy,d! c/^"CtnFX4O"",lWxBY2\Qj7#j(2|/@"4v@y\VDL3c$Zi% wo9Opx9:g穆xqjdZ %gyՍ]IAuD)IwIdPxeA_? -Y:~dBJ#1,Ɖh[9x`jӋd1fS0cr/TEM= QP8`b-uUC"Wl@^:NPA9L5xfS* O, s0 OM(vjfOʺbP)A&o_Sz>q5߼vzBY agC lF*Q&`T9Ù_3IX1DnM 44r{3/\҄;-EܒƀY원 Sꭋ?ݡyRҥRq$'PBM}hCfX mLc=$No 6: YZ