pki-ca-10.5.18-19.el7_9> H HtxHFaݚe ?*}}\ zQNGAvMD~S BRm;d996007c71b48bf1cdffbc3f336e409eba21e10cgt29fswsfFaݚe ?*}}}88t?dd   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H9:IG0iHiIxiXY\i]i^ǁbdhemfplrtˌiu0iv wixݼi`Cpki-ca10.5.1819.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.as`sl7.fnal.gov%'Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEGl]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤as=^2as5as$as$aras$as$^2^2^2^2ar^2^2arar^2^2^2^2^2^2^2^2^2^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2as$^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2as$as$^2^2^2^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ararar^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2ararar^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2^2^2^2ar^2^2^2as$^2as$as$as$^2^2as$^2^2^2as$as$as$as$as$as$as$as$as$^2^2as&^2as$^2^2^2^2^2^2^2as&^2^2as$^2^2^2^2^2^2^2as$^2^2^2^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ar^2^2^2^2^2as$^2^2^2^2^2^2^2as$^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2as$^2^2^2^2as$^2^2^2^2^2^2^2ar^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ecb205508d65178180edc404e3e22c868599218569da061d52228b013c6081dc38cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb643811c199c1d988747ba4d5689f9167fd42a8ed07039e28dbccc4b744f4cccd469e8f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-19.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-19.el7_93.0.4-14.6.0-14.0-15.2-14.11.3a*@as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-19Dogtag Team 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 11): - ########################################################################## - Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu) - Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail in FIPS Mode (cfu) - Bugzilla Bug 2018608 - Invalid certificates with creation of subCA (pkispawn single step) [rhel-7.9.0.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-19.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*J*1/zLJ1M7?DJ` +-"j ap)pH7^#;~DuEg 7!lyhygDh>@(a<Ķ&f GoUW鮽h:>.W$jBg6_3ì?s(2?]Ƙw_+[P! ~l~|/gaJC>4fqIPٻIݤ68X?M?,>NvGY+-])$nmS񎵍M*~kAl?Cn1{<Ώ[s u݂Iepq.AOxdlfw{{/ 댶kז})+4\M 7@n#k>\utrLS垒6}Yg`a@tN E8wb\GZCŔf |fxo\^g%zvIF/~Ok‘PALpv%dq7%=S zX G^S, HyHBoؿ,joW[IʋW&$:nL=[W·-ԪPp:vdhfB=Sɋ?I]~5N1Q+>| pX+.W\xsJ2 p.dԦ-/{͊'G/4CNWppȡb)b{A=JQZH+WG&|vX@H!shte5i;IˏA[|_j>+QsK[XU͓+-_ d muV iZLp5\4FkZE3k1^=à :c E %hz*ɀVߍMrmͲ3nk\@4W!E:oIU dbiO‡x)RWL4S.*<ܑwǷ4G;EϧaI=\PQ'ܰKGbtX>\Og=j7~ ;jݝ*nwR8C:KT im5,vaQ%b ;F 2^V= leOkjYcݰ%Q^:aPp7=H&&&uil R]!N9=*LMyH`X/VgPp+ @B˴X*a[ʻZןJ=,9/bά A j"JTSanWoh;o>m%$(uM[a Je_W2n[+e. |(q2+Ǒl*%`5W:M|[)$HYWv=O0UXol3;-g-Nl T~+iX#4P0X8Z{}z tgyEOqa`Ĝp{d I2f8 NS.8!/u{ԁ4}_R"G0<1NM`rὫ W} (e,=(hiX?>!C5 NKF@nh`Rp@ʏ*H;ɛ"29I;_=@~=]#b'I["2he ͢ciU9^S|B>M[߇ >Lz h,ф~XL Ni:vAU9Iqx<~jF*Bİ__ϻ #MD@x`͔xLIUF"-hB9dr ]| :[{l+))["l-_Pױ"-Kۊ;;N48wgBYԁ̣]Bfk\Blyl=VLLJ@ϖ!6#!2^VP;~ȋj(w+_nlVgH\]Mñ{m rg9:{tKb*D|>֘j`U(10m{ rڠR. iΑ^m7 -%_o礪-8ՔExMPFoggICӿ-w#zw EyT,*TЅ KZ,dWF wS~|mW j33M UګlY9ZЊlŕU]vZ'ƲAfc3ܠx¶nqRx2;ZMR/N ǰ׾ۿ4Q1`jseN O8+ y8 ؒԹ\i.^c*Ր Y\pПA_enRHܛr+o)MNXTUlkf(Kֵؾ-gO:=9p;@Z GI٣/A(i ҺoӘ58N|(rF"ly.J S[,J% t`fw|fJ(iN5kuFZ($o?eȃ=&KEUdc;QcK}͠)KA@@t%9L K c(XR4|#<έdt 3~?JAX,8O'VQ6BEzmkAَ_;Hurӵ梛X7c1i㳃wa}\x %vZa.+YzL#wgRIw<gUh|8\aT鳬cy% AԵ 2PhC^#uL+U(qHۮ@z`s9s!VBʒPXZe /)_y)ּ+ Ȭ,`f;ȂAm3 [ḱ==iKxf^]( [;Ga Hv=$R__;pпÊ?[@F85ۦ+3P 츽=]͈?٢X*ͨJ3uJG)QwJE٣~+S#>3 dXy1fbPt%lnUV/O<$ҏJ;W o4B-+|~E?d s$Î!apߒ zɕWᐜ-Tý>6p0oc~}=z4GA5,Pk=HOyNQv7"vfdr2Ri=ke\nNOoZ[m~Yx:QFNCaPZ=|kڴjT1q% Uj~ʭGS̹lN<=PsCVy|`ý.8a%}kĢ[2abP /T')M0 ޝnr%/852!7;6Ki7<}9σ`٧*"br|\`1=E`¨=hx 7 8C21tXkh4V0~΢%USLz}D^03Zd$cGMC:Vf_xHUݻuPm(C$p?3JJ:B iЗ#dFϽIԜ9f2=* ȏeQNl7U?ۇݟz#w(I h&9 XO15 lBJGs N5Kb,>Gk$ aԚ,}fn$~qH1-(}bmϋ/o|"NU]ABxPu*W˪^S[dRo }BM_E.3[SADRm}2>l{D6B\K$qdR)N0x(:$Z"Wv/z#Tm,#i൉¨V̈́fo8v88s [ܮ!*6o~< r[&r81$Y#4Y+' U*Tatnl4 'DŽkl[혊xh*oehᦜ̦ j5H\}t.].,Iî/l=KG$xmctGApB?ڑ;@t\izo>1ށ*.R&-9 *T3H4,r!I '͛O2I$ĶhҜ9[¥|ȇc붜;km<)NPT7UWE *.@O>\21~'xkl 5$QS̄a2 aQ@xx}@"`䱉ϫMY3NCn&ܼ?w(E b ҩo5 Il><)?a";! ԮZO}x5/膅GjܥIuy& DE&k!Dw⓸ĚPx%y]pM޼-lLWnآ#3Փձw.B&8O7X\fb̩TTF0/O]=R&]+AZnW$8yrx(* Q+0]ݬ'^ G_Ƚh||j;J& f典 Fw}%hT79n-Lg%or@I=IG $ɟbRZD#Z"x@fTX֗igMw 3DK^^h<`IoX\_CXo iXp0.]|BhS)˻_Z,5j T񜳥5C_DTJtPK G,꘧*_&^?[+1V2'Bڠ(8&u䉯P8xTbC%jrwrÈGyQDS~S/-ʩْw_4 `>w>i+u+6ϒ|N =]S|C}׮0虦<׫>`79SDPL *B2 L)r,{;*l_h]-\8J&XuIQ>>KDI_y"~Ӻ"Ȧq/Iҿ8VOŰl] IEӌ1TXB(Gas[#_P%~P l`6aa9?̬d:hoPUAE=Dq@ܮj`i'].˳[:] -]M+RU #2Hzk>v4[ɟntg\ۿF˿7LDydv L*Weeš{3koynPHJxFP\(p;l'%N9PU3p51Sp|I' h۶A!M%6_l^CΓ­N#wcwT "xx'n}ݦ>Tn߀DXY՜4猪i^Z]UVգ\U6h&$;U@DL%G Oj3+cyTZzI1hg}ŰUrn@| l%2`` D%q&m>JDǞ#$7Jh AI{,㭾qR=/`/ nEC0D.`p5Pdfڽ=42O07-TEKlr[Oi0\WEGQ,am_wdzu+Ry-jC( U@G"> $r9H^jc,BWB*PpJgՖJ;u_JV2_#? JkɍBV'4hhbQWgϺgb/DmmI~9capgTg bm\|q&y;d>[Hֆ=[s΍:e>G qb3ä!EuZN\[F$^w\ L b6yЀrO]V?&pv|swaM󡊿 !(&|SG6''Lp)['d ğB%E?-–+vO [y2,=#є)~'Kߎy&N5eOF˩g({_gv2V>?]> AE; EMUN="wΡ; оpiܬlw2GWyB~M(+ B} < ":yAᰊ1Jnl'Aa5 Fj7Qy dVhfx/hPc9p l7e.?n 5/f_F$cv, )\l(ιt/JH[64_ N 7dtBݻY>Q'N4M>tn=ŗDQ0Ԥ%,bX%\t23V>Po7r)r8S"sJI4Džl9):20aժo\V1* aq2٠܈%f᫄c)=퐟+s:RE"mIGB%FmP1ٙ;O3_c#qlZ4L}n1t1d%ujzcqڂ L~SVp1*\XVK~nzGIdhs/}O&~WXw/n)`G>FZ7M+ QBo-KB": aprЄV~5>-oH+62]XRZo=unz~GN2.ݎ#"=$rnω?B0\S4iٶ襇@EJQ+S[g%_01a%}d`iwy3nN5F&>< `J݇I&7,:[hpKN=4޶IJ'<ΔVkS6@' xByN{D#/ }ZBb:|\b ѬNЦ0CtXtm^V{p;Ό`t&Zƪ>fokٔ*mDEƙ|_U8}qc>[ıH!ٓ. 8WI댵OJi$[bY?@g ǂ]_O%as086ȳmjdKM{K \zZI3h ,6lz*+y;\QL&,!8Jdb%`e {nc욅6LOGAb_"/Xb}pѸix6 U&[S#i̋ W7u|uP Ov[|?\yY|BXe.,O7ivw2isCA6Z{yqL& p| F7N5[展 xOpbM7T*jT%x\ ƟRi/",ļLoF$ c iE>eD,ॵQ%4 tE y. BH~j,MI!D^Z$t{Qw5OP; k:M>EPAnQ|v6l=R~'XmBdo<ĉlf=< [VRhʚP'O諐XuwE{tޫЁ5Mf!)LI]H?0[NqhO}g.>KFutųEt;CSwz%]8> [5q#X XIjKPi0Bd\ PV<'hj&tE9= ܩ[-yԽ*J*5=qNs˸a62+:i 'xʹ v`q8|:8vA[OF3 ~KlqTK8. ǶÆZۉNOqTT@k$- ,xtx߱-]T][:YOGFc%УSOXC"tTk\G:LKkTWT((Ldj̸Q;Aӥ2C'60ccz^T9a: _`zuV2v)2K$0?CIvo9h9:&1x=_"P K@GIݘ`O87գ2GYELْ[93/WRY:?Gm+)7%?B!40>tKk~=+6ޡ˜^+.婌-r/Tp77А:_ 8_bw'w7慔V,bi.cF̯ SvmGLaKn3&{S_+1W/XB[Z`82=RZ +Gnj[<%[V%T7U7HP }}&}_õ1v|L° t ʖP5a^RZ-u/rځgv῀$F?1#8|Q n4 =.ݢ)WȀg4@0Wg8h3eA/T_GP?>#J.eȱ@ĝ7ji)6(wFT"CO9ESARiS_US<9.e~kcNb30cDy,Tu-x<-9% 180$1cVPijXY`)ya=4<`'/5՞,MST#F+E7WaX?"Ό!! ~ݒMw,"Q LBqN%>#зA|~Qm}ޛJKB] ˜mʗ+EݾX[ǂ%x)O H5ʸfNu ?ѣx@'ijAN_FąϐL\O^캌*ߧҐW ~"Z+줷npE:BZݦ^1lT?P.l0a`enaN]zH(V}\#xsf'dӠ,+۰VDĶ<55XxQ>XzEs7Jesb=#g)3}T<*6] Ύc0r-~k]? {ǻʿ>MOzD<?dWG\ L<-w'q @› 04׽:y]ݖ.XI8{"(A_^y&IJ0eAKRt(50*'̚/~ HgDmK#w @rI |lϤJiIٔl46Y(>V)!Eq{ 'L}HSJOe,'fM=Rn~ cn8%z8| >lTM /p2;7߉(tȧ1Z)-" +ak"rq9x 9eCd%E;kA U fj}ˎiSbhλad|DЄLLTu#)Z̯橹Fsx'Ҏ1"xT'2PmX&ݖ+T s(\njx\Nv@W'yÉ\TFMvqWzf)cʿ8?s7OR*jxK)J0̱ FR7&\0iё27. q@5MST\Ycy~06*{z{Wi^|aF] ̬ж{t`*[3poW:'mp]9!ٙB>,9B,˭Dt̸poDd&LnR ނq( ,ZiS;1NIvM>[dȠ&@y~&&2f6H*1ᢒA}w?٩KEn1445i;]6 ', wvDIosdT oj<'є[`=)mDi fO;k\l +4pC& W+o'q{ +ih]F Fc\+׀fqӰT`dŷYCg(g+I\4v_CV_ ًnR+QiL;|ѭV5y 8A7K8|#*!P;rU I74 ¸3TiiD.iTAE4S3ʙ|p0t#'nq_[S7L =TV.~ a;d}4u<@܈o鎊1+F6>3dꓱ@R5~p2C ȮP|RfrkETv4T#ª6mchp"9hAJKp9{qf[_QW%"0ІRQ+9 Ccpd4}&; h( ]6R'ta 01s"*Nfcߚ;ΠIQk},Y7ʗGS)_zHJ8Dz^0(*( tO>ʟZVN&Lif 0 [XifxR)t@Ze>fg4<֣]R!@cߥo͕BjmS:ј)%7+tNb.KB:˧M~1ͭ L8a9Zph J>0_I|tXd$SS͠Y(n{ Dn`UEE֪!\۽5KP*T9/ވ?#Va\YgUߺJxx>'HdH;k6WrNHvm-'d ö=is-XsUsr*C)R׫6GeaB6,o8YdX'TFXH:+9ݩ9kG y_ fkPip =)PD[bCbȍMxYI6!d6agI[jj͈O} LeF3鶽:a3: `PUxDt3Y '(3~?<`+!e*tj(Kz&:q׏\x[[PY`Sc+h^ù7jZK Y}K0DdʏhŎ3kJoqk=<&Ą^Lm"[X28T+E{·NSo;JgN'92%ltKޒ pX "O,1,1|ڴKTV"XNmw\O K@jzO#|N@˲_'1_ "BҿɉllޔŮ Y4^.nĆ D?uO[h)dֲ:Omے5iE̓*ȓ;g>ȥ<쭚)Iud:8SE@\nvo MwJf #{~rQ= qrSx/탔,{PsOcF'}G 90' h?DS' zO@nR(,7 [u%CnTK TJ? fôIt(qk{n<ҵ^PC8c%ѓuӸ ]ݿt4/3貛5мZ,g%^!r}ipڶg .KS_]o? __οgm3iO #4pE\?v>r8E1ɔnUs}[ȘOl\΋J)L"?]}Gu^q|h R7Nx#8Rm&9Yw%Od?ݟ"~l 霖: \XGoI|˃J)!&7L[Gp9Pbo5RX nFaO~l9Dm;gRu@!aYJ*n҈Hm{NpeЫ߾{0JUgK3Mz8u-/>ʪ|[6*rK藹B:aԬDD<ԝ#RfٸMJrsFͿZL[_=i#Rj@pfV6 hv/<.~[1~g& se֘NTA$ )0O/&RgK~b_y+,NIg뽡 Ag~)r BVdbGJ؞g>Ej3j4%?4w#NH̲)2&'mیeM/k qKLC?=a(u\w$=L&_!sIczӄW5n(>oJ#}d!t앋Ks'wKh dgTηTs0IEj `wߍğǩH 1u9%RNgaDχ :<{?K.FӒ_+iRu^=Ʊg4>Vb`UAOxL}Z+ e>e<^(00{i76uޥwIgPkcJ?*Vd۴Z0*xLŅTb ~lVzvKXSAd6l_ z}A ]?_Wmeɮ-f,3IRۺvzS0w5ڍ@K0Axnb>ᳺڟ[d2TFj^Rb+N;.=TL]]g_UH,CTucx8Muy(B-spUBdžX2U>}L|v79.LQ7l&e-%%VOC6vPs_9\P>AG@'>0`ip`^x_+[#qҊ,\;!ΙPm-vB)ro}WxH2H8%GRX{_5RGi#˹& M*lk)/ǰvqtRힲR* rT.} ˾xq=`+ߣhbzcDT~>ccȟߊ\GMj.,+Z9m ܠ_~6%o̺|˓l?8 fŌ2CRNJ 2/l1a@WC2,p[w0xx"` }&{ZTu2o` m`H'D ?e4gZOA=K pln5,MDۏ"`y,CKnsFz ӗdz3y8\DgC<+])'XctZ~FT0?q d˫…KsD]ՠ^+U`Sw8 Qj[ :{ktX7F@z`mn򥦀9zDRǹz 6q۳'& ܦ傰p/_:֗ieKx$R,zUB%\U}u"IPz¯2hiv;^ ^Nb*(GaEr0<?xLP }^Ta9.oމTL+c\μ=0zj>f'|/ ݜq2eIJM*93 /M|Ò Kʘ OvX+]̙҂ QJ`[h>S44KAͭz'IEܥ})ޟNP}[(*IRN>.tRb-&&=V}{@*[BFA{?JNo8j|FQhκL{ʔDZ#| gSSW[BDˤZ_|0gܸ9=43t,옷QS}3?ƞJ3 /׵0Zg|B>*v;7*P1E؅KugfZ|g͑g/LyȞ1UuT2E '[?WvW8##ѱɺv+p"Wox8<Rc}$By>*l\_iOHD2_87W4wgJ،VĘbH *l,rsTutK2Ta2Pd^ M>2GnC~Q1. Bح0 ~5; /F]`HWXc5Q9\ُN тDbh;W^}5*DZΝ` 8A":*+oK[= p$prN#pu ~Y+y!#n$s{)Sl2.J"ڦ:Mz3tiA&Hbn0 2Y6m׬&NCN`೬g:-&"wdoSJ83wbH  k$y[7+9Aez/AN-,1w0"KRZgԭLēlz䊇1@٢C|AK9cn_ '^zi$QKpќZ*JWW uV oU^H=zo==3(ԽDLJĨ#'$jE/8aeRm<rCaI6oN`A'^ v8+qn3n",7:g|\|fJEαu9T^C`tѫMKd })UP'k7K`GUny󐙔f Bzi+/A&! س?hk|-KUށt5օeH9!w7Rl1ݙ} 8 mf3'd*O}8č!H|qTod4\.5)Z4ڄ;OpCK<˭ tH`/qd'S3+}#W ؘrT\LܔSFM6Gg )#l)(1&-7$7uV鲚ԧMT|`Ng eI|YXqיa#7) [ P/< d}/}+tE ?4>QN):kXTFNzkl?G6$OvSg9~Udv7n6=P "I=8QX%-KO}u-#j Z0D ],%DO_LAՆuBS5*Z Z6Srs96KyKW^M,ܒZc+Ժܟ7Vf?̘ ##7GA '}gظfw2j+>O_Ͱ[R&^Yl! XrkB?rC+ j_[ř9k_%Gdi@=qE *7o1_NbusN},v+ l<8`hVYid[G'Ch.q$f:- CB1'y&/ߝd׍nN_ ? e V4aN3q 3.$,ؕĴ1QߓC^Oo!CDžKI?\B{$#jnA>cF8lק7Yk+[|SG'.gƫ~!oY|d'2n+dM7@\UIQ(#A&{l֟oThcP#_QnT`*CqZ]m7ZݙVv`O/zt բ%Q6Cf|W>c:Gc+ |:t4C䦜B.gRĘ}vZ `  #[-* dx/|ҿinI#1"jG[Y='Lmxгz]|bͳIS,wSPl>!M$U$U)a` WHI+zJWwq%5ƯI`URS->p&`Y1.HNRCļh1.b:K7s<, Lij2cMwtR#l^E%8?ֻn)_9Z/ "VpW*^CB `Iy!P;1/c=uleFū`0rVzfHsc#R:`wWҕRA6CzǼOV,0:58HMH~> N#9X2Eb:<˫QԳ>s]S/~Y8L|rIzf,M%ND@#/~h EBgI~{vqАGvB3 ׳Y<13iwA _0MKoIA2 `3:x{P{ObxfH_Hcj.tm| r0z<'KH&UBڭE#Z EߐkUQ8'u3h)ru+c l5tߤ|Rw'ڴuF'{4:}fLs[EkeR]G~*i{qNΧ0FXm_&AYl{V4&EXS,Ґ GZg%iSSq/jH(oγ\\0'a2kfGDĕt`j VGePt8٢3÷ü&hsYXgF!͋:qd%P"Lxj~W2ȼ?Dtw⽿pNO&@@Hu41;gOW| ]NJ!uVDL͏Rƺ_$87w 5o8x )V)/"5wT$n6i'4?%(VߞeP|nj$C*Er;kjzIȟXuqӁ7gwVRzeL:И uJD@+$&p z#V.oN)LB;fRNP e)\&y^d1~1e֏wֻnBȏG c7z0+NЛw޷l!FY= 1b=W*%@]ZW6DhoIOLH:JUC;)uGfJ7sh~мQ0!T$A5-ۥkq.~09mfRPtL}UY4DR2FĚet[`@1: aZt@rF'*x=dIA7V s|g֡O(|%%Q忤&s[Knzc2Hxht 6ROH'+sO=S$ 1q1$PC,>=ea{ȑ2/jh)"^IC$nK?hgjP<>$ :mJ4zr{f# 33N&& .NnbLx4a{Jh9wif\.b[q8ka' %ѧ_v9ҙ~? GP^8i,e6.IlU=h W \Xm'LíwmNFEvib3<1 5QE^=9R 4ӁɅFэ'JM`qNIrݑ{`6 {"8 i%e7'?8^ { |ۣEhn^UB|X6ڳ8?gYwvqtF_\G2{e+ufawY =A|z,9Qc۳-+lHG.CvZ9MiR_zȃbݽ|ln_UP8Iel.|I-2:u*=fFBҚMMSҚ7u^ڊXFԶĻB%ZGg?Jmd?8O7ƙ -p<;+C:VVig.s{"~甶c}IƪY;1U T\FdsIIM6.USɁऀ[;o4<3`AEPG1BLea$Q;(w]Mǡ+L)nAd|MB`? īv J +$VIҘ0,K?`>2t^K V"+xEUثIa54eW$~$*Hj9eBZ LRg~aciN`F#\y'}g8}R[Nޔ$cOm&Pn +@"* 8}r.:ۢ uݥeOHpJ]cB91 CF4ѪisoFIq9dMp[w n~TP2%&nw.# Zgv!R_ޑle-`C< e^E vB7"rqLdZ;z{j{%X _b6>ClIGI=m(b>ԟ+ޔYWwj5Ÿɬ$zWN Q5ܩn)1CO,gN]5Q$n[&{b;4~簰`+G~Xue*_bep̱p{ʨX |)SH8fɿ܅ĦI.C$a% i1-c2} @HkN2W E91\:uාfbjh衠¯\fQ\re#7U2Kx9jF).~2%2ce Ql|ñ~YTWG__oh.Fkp' -U-ӊk;l.'3ekS @ :xO JE6oK7wMhÈDw3kVo  S1eJ}a2.3W.+k#kr=SkT6t|?sDYgL'WDJXiEXWeCD=THQʉ'\OzVjnmph:x#PoPab^Ы c{+ëP͸Y:;vpP*h_Æ Wj9/`.#Sjn1iW@D@W}#ȏ!4x9V~$x! r>P; ,ɸX5iM)D5t9֊Q>H"fl&v68 [+#&oe?t tk˾y0%?}fv悳`4B}L IՙE)dn|M+<4l4Dg9y9j|n1U4?4ΠC<*aD=I; ?r#\s`0``JtuR+Gb-ݼ$t4,ɯ9Q}ğn8=mZ^9V-tTLʠ4{dB$UQAug F2#=S/Cnqc-A!6DBe;\&u]qm;nWsZy’d7',n/;W!uogNܛɓ-G:vTz0C,ܺNL7i*];ްJVc jrm>OzYKSJЅ?g>Dqp0cze%AIT;m<ړf=fe9bS8[1උ áJ#[f2y2KO٣x@~Lf p,mB8IH%v>GXD%1DS-d$;AkZ!蜍3~"xJftn ce'y`\ua'I+VGV|;&o i\c|ࠐeVWٮzNz ˷V?έ%۾.~olR,Ype(raoUI987[TYY x*~!Xyu,@PȞnPS6"bdM-96ar0%kP] f@5r_V{%G=[lP:$8IJ{1JzuT !>MODK QnjМG|=p! \w<`Yydtjvc[L0m]rǫ>M]ަ]_w%7bJFhHGh8mP^$EMާфrЪ)7 kl:1'R?߁BƚwOO vXpwm?|No//D18JG` R1•H^hDK˾]cK$twpޞڦ Y@Rd$ahj \!#&!݊1s2k[Hat1`zAa˗i^G>kzu^cfJ) ZiԐ\ayO"7$Нʗ-Re&st m5G@0*&va I)\f vZا U C4ST2@Ks0$Il?BAuKr@|@噳 ljnRLZ:<*Wzޠ7BGywo,즮-هa- 3GMZPѡKm|4e$w Nz?n)Ff<4B~F~td@d913"W:Cy> K6s0qsQ9ved9Iw4\Y?`}(U`{K:=}ͅ( xIپ X4Lz=eSĒ87q \2~4@0#Hp*o@"ԟbΜNBl˩\qjU撳iJpy(5Lmw%cwC5h&!3 ,w -IyCG=λI!_2jQ7oYD9\l[zو ԧ>[z]ۑ%o ;lD^ى_JZ?әs-^GNLZYr+Rn U?5M-$a~ iZBr gsYlRIi鹂֡dC2"a~Va=w `Eh'S Nu0n~hZ^>8-9!"'*9<|n{#Wbǒ~Ա| ^AnѸ&?2YP,}h8**l@j^AJ0ƪy6xXL ܰRX υ ]qM69Gk&iI Iixy9ac03"c [f'C%{M?>;7/Ro8 - =vU_ե{2& 2a;kF6M @yy[ n- `[ڡ,VuG{R/YZ݀!y9f:J*>XN` 6d%8jmw.,FxI=sߍXfyl6^`MM'Y%CG|w/]*EQ4NiW8LnT rH / %eH6ц&*3og70F.:mRਢ  }g(܁ ~B' e7gfzjW6oB]Ciߌ}՟.G2=AX) kD䗝O\` 5Kփ.4ݾɝԍܟUB1|*$'I'+:W3.>l~ڮBnPǙlF,nbg9P^XeטddO\CQ zC\o+D$#0Wu/ Bh~Lk9c}[DNFG:3|]$' N,`f4RCd !BnUYJJa~JunlCc`NԻe75:9WL@ɰ3R7*+?$&*ܢ&mT?SU` 1>(t"Pb5XyI5T֖*-Ks:'?EvfH]r ެXSG05%>y1'2?]S }9CIa}(1&U`04~ ړW8GQ)"3,$=WOg`-ɘ<؃1(/X90&#cɘb7{`i3R:`G)p( &^&C-IW*{ i:]Ol3ZTA.B0ض5,  ľ:e09O_P`e ]WǰA Ssn;g@`,'GRgHo(>\Z+Ǧd .Br]#pm='+"-ہP⫻0LdkwK7@s7ZN$xu?Pz[L;i;V']qS7_InVЯpbyQCtNT8yA{cfR`;Ztz:6?.7\yY`.Σ0h3rGd+7|ӂd]El6D颚췝s&Y3jyV=]c'آV|:Qo[ap3[MV&=S0HֽLh Șe>wZ_qiĔ  ܜ $&pR \K~/*_1K6@v * K/a|zde:ʎE(u]nm$Lq7Sjc_5!hr:}Tؖ&5/Kf;Dz:[2P.lnĎ O6-kW\N >Q"kBBs8(%_knFFQ/:'Eە:M=`o4D3(/ /͑t7 v ,} ߐO}# Xm((΅ba6Y(i` c z% FMJ#5С-cDN ZPbws1Lv2惊Ns^Q2GeV4 >~fpSWY nIpR75ﰱ2HDEvR{fPG$]u޿/6*uY]1U,5m?M0seRG>wlڒGa TJ~ue2T߃@K@ThqiS F9)Q)n)pGam"~ZW׌YϷ_d5@{\UU̖dP\~dy[Agm5RO?drTv(FNBB:y *1>Ҵ\QYMJ!}.`38:n[qԸ V 7-@PXq뛧~S@^ŰF)뤈ӏ/"rmػ=/}Z( uJ`7`bOvFcsSo7`vj LC7+ Wkn5Xܘ-McԂ^2!)0 _0APfliKXE`ַ=2HkVvrPkѩ,T͚BUY:|kurTx=!*oV=t`m͖2McpÖszlK$L_'VYL$NAJ]Z`SդSWp͢T8BܢKh#WUE-:Ӹ jz9qIt &#nA@˿pKrnx-}{)8ԵAcfad&uGB&fH JhqrLnv? d|+C^ vO 04i;}R#Tcjzѣ[!GY]lxY^nըQ:$%DiRQ*Z P4؟`ԡ'Gwo>YpșO;xRt{CЅASJ@p;g0+2g+>-K]svoJC.(Uc$,AI߯nZBğ!ynܥM85/tzaZ,CZhi$t/E4f,|_SA)ǃ]\/A/YޞfR^'s}\d'k΅_G'3rlӁKp4cqOӆd!@#QHl&fdvCo5kviPKO

9C*Fě`}=: Sʛ ]ӄ\ܑdjZmZ%kx0Y.FaCFeWkY6G,륪WO6'd"#ÓfDˆa(]9]:TҖ-E} 'y歧YyNBZp(q=M8p1\dc1I`X 阵 DXX k|Z?gU:h'!/\+jGԭe,3@"@OK_po 7ORݥ Kjs49ć wLgQLþ׽b&lnхZ]e=Θ=oo*SO>~U8ȃ;9S1SjES`"nΛ" (|OGew.'}iZ@8FtԳ6ڑW0⮰ۂ (8 y$:@T./on v31$u[bLI4GglMa.GC^/lhfZwî": dxR6$Sx-Z} Ύ4hCh!d,ZՈx&70'9 ~avM$T_yȬKlI?28mO S\>S֋%$jwL̆]KBf .%lUS ! A mp36ғG5ӪYs룖 |ر E4 2>/9&u?,X seUy[6)oe!NM:M!'/IsۀY|wcSzc7Y veS<΃Ȅ.QNZV%]80A=1ևƄBu9ycƻq ˔)Kv_oߥ^rʾW"qKމ+- q?ޖ@2=(5,pK%^a_,mV.Qx6t 1aη,iqFZTM<Ɉe8Br/<,#U5EGZ(9Bڳ~MB)G氈 Rj(=.Ƕμ!- yh.|ih e˫K&'绨$i\¥pտ {# ڲai 4޲+}}eItHy~L_S˵aѧ>880N4X'nJMCZVo)֚^.*n'p|t| 5Nf86'Y#:TӵHUҿCLp S < U* UObi)F"ͪ?,0e5iK(B}k\=O0m@P/Vsd*dt)۽\j4ސtn{Qc AͪƂqTgX#SEC.OȰZT؞4VaF+U @ܥ\g_ؙ͆I<.@D:ynOػ+~S[\#p\HN^xƄ4z cTt~aHGCDZxAbPԨ|\=1C/}?)J2luƏ-~O3ڷ6?Spa.eqi j+^g#'z?:)k= w@h(+`j#b";[x^u¢#:􈹔 ^mT-w59 gLGր o,j32X#CB#U)d p(!|g}vs}_M LnҶS 8J"aC0[ 5\\UbA-ykj9'\8ZV.`+AůQq`(1k6~Ss~*+uU2f'ܫ7<=Ӑ`!,,XZ;Zb$VH JilXw`1uDxINxYe;~ϞJk]>-Pj9Vc6,h=_MЀzr#~[]~vAkX:!w4J|X>Z.ޗ~]͏dYp۳DCv+Z|R?M9ïlaWx:>t )>yjܙ'a~h_CFi fL OV ckyfVy7{bbfPZDjdKT"Ûx0T* Ii4 l]^2oR-[p:^77Eh?>gSH1T W(!^V́ 㒽1ph ˨_[_!b~ko\Hɹ*x#[%ޘj^iAV|TBv!;+n؁vO4xEV2qlR⿣r{/mnM|"=>%ԫj@RHa>X I7̩n "kW/L02ЊSV@)mV M?*-4><爫J7WۡEb0P@G{)SjkrmCŝ۰%5A!ŔeOIօ6R T>ځow*9>YD? n:3U \MkpS'A U5F03א +1m r8Busٔ ïfC[j 6yLa 6v!wT6qN,jXo\G@Q:&Zl;GlK1d^%0B}F@1SAJnl02>ёm9MH%5WWCKRfgY9MJ^iČ+wQl7=Y$`r[LZ['{+<˔Ƃ-V K-wvR+Rjݨcz~s#BYVhuGQ{}G*@F|RD:og'b֓ s 2r5NCLC4!%AhXҊեyr6z3K`c©X Yp1ܶZ ;9aJ]EUɥ}Ox(AL)QV{/XFm~G]Z=%2gjEJ]h9"_gNaFi<[X6VS{n]dkdB˺y-mk95-~^G9 czJU݌īYZn5ɝHVNc*9uf*5)Gϟ./uag{[/ճ|~jQvXOe.#qXUIoL(fذ|xT׳!?8=U^u^ FWhY4YQП| ޝ>I}sX.hћPŀv5OJCMKƦ^=cQmu{珣r(Mk fwrn9~#_[<0ozK%ˉ2Xj8Yߨ|W6 OA9j׋AF҃# N Cc7/[x/9>8X7ګ^F@ }s !1+}6UՓXHJvl2:M, hGr0o!,<8|2,Rc0:I<[JX2TukɋOpW F|wʿ H~B; @ (Q<3Z䰿z9TsO8xhN#׬֢;[6{h"{œm{H>(O?; ]%gE H[Mn\ޅTͻz]ތ2/+~q:s/V.0h5;(@dehyeSҋ*{`STjH+r ߩ;;P%[9hn93vnM/5EM[ڪDg\X176r$˖雐I55"\P]X47BlE.$>ܗeSaA,7>`#ue%+=>m4Iz:H7Y׎:tHpM}Lѡ-Q!MaNl`U2V8x>ĞkehS]' Æ[|$[6^[:A=ygԮ2Zv +H/0kM4Ӫ ߥ{]%^/酒a3-W\a9n$E킔oTr3RuxW$Y6JmcJ-np-V}u[DW݅z$?*kJ"`< cU=;yE-p~"M$K!@+όTA˃'HP۟ˇ(*DbqPWdXtu@o50iİVH;:aKK%X_A~R#J94Zq<7a!$H#FӅ{_^2+rKZ;~7-<sU5%6TxnjmqϮ?q,n'V&h 76@Hٸ܁zV}NA H| =p\+y9dlFTVgįs-2)rxFh D=(Ų~;n?i62r{S?c%Kh#kBjd#ULS J;RS0).!4"4S}ABq (O6`qNQ5`#8]#Wp텭]T# CEPAGS`AEAD4ZFBMB|A)wP9 _%l<,A̕%"]Nլ\t(!:ޗ1cz>Pu)+,A(kM5*`1tk3pAb%~qKFp'V= YD{Yeh۳h)4,% m ֱt V.#r*Q=:X"Y$ߕܗ\4$7=qjI8 "VDg0Jxc'Rc4SV>]3-o/GЉƽ9Q㷹&܅*=C@Ŕ?`>Ȱ5ä˸j2[C]*F[~̿ym4tv?!€8HRǏٚP(BVpUdEѝ~uRr P ɬzId(EzԬ^w_pݔO[gADQMk:AQHhO>h`NBNH79\̱{.@n~҂E"5\}MMFJ?}K_}JA^5 \cXm)IW\[^SL lje^@g =z"B$bWLIHM|f.._htZ&zk{PXhDWV.(',AubLЄF4TUfp^wɖof n5oͻaً Xm,\Y sڎIC{;$l?G^cCOɞdmp8FpvޟS>SObܪ:3kz`0l#LaqƝL b[v>ʇ4qgv COr䓾ro#V.KQ<;"G2QoF]YZtz E|ca jj)`nXzmE7${z 71d517/4sU%5s(N#NIJg8vzdc;FxUBbìO8HxMST+yG,N _b~8t5yϿ>4uxūAF4U~jWə3OjӬ{zEWh7E{Ê_9$4zyN=K20cgqCQW3=lX Mr=l`HΞ 2(v; &sSw`RVHZ>H7AI ttt_DƓc7 _w= 3J[ocU^!9RЋ!w\EfHЇ(6u#)=R&'|í(DhLzg1<"87 b,}bYjljU R,F<3(.:3gh9i$^FDؙ҃ᡁR"=*D썚 dIZOQs^AT߬\kfE`=kJ .5B!m)lPDz EG*>дz}Id5ȗ!=O 8dϋ&sORݧ eEc0}"4G5= m:-2G'D_*$3q hFfԟBmZŰ)YJ`h#SG`mKAO%S$kEK^/>]AbFXJG"t/ r,_8̣~mc'u6ӇK {*4, (3e7VʼnlX-7S/"쑯Qr)t\pSOJ9$7s #.#:Mqvm7N|j/MsΛZ貲jԇb'> uy9}g/#9$8[fv1JZt©I)] [MΛW!8mcf$Lϝd-e֐ݡ.DQvuBE ĥvI:8w, E&Ek0"Ynb/6Oݭ&:Mʺc#}oJ{&$z;2*đr,.Oedih t[W+28j9V8v\C-D@D+iT%f:NP=j"Z6ݘJ ??Sջgqi@2p6y4^,س.c Z9Cq{nsW]U75?Vt׮|\=P&[\p1W4*_Ǧ"vˊВY(}B*:wl<H5|seR~+;SSAOr=cLH 3>>r{@2nTU^") m)|6Iʈɬ+OQGdP[5_v!5c.彗)ŐCK`Ue{ tY zȢO0#)V8Xk\ok/ES2c,ʷb)KrJ C,]*(MȒOkxZ|ЅVA"G穄Ol;,䛜k 7>%sM 蒺v RUIhi|*+-^RT/SWj֫6겲hd@qFL@/]bv9@Jr+R̐UdraU Ud:8%Q^B3}^ϥ|ذ! H"1|DU5 /E-,W]"ε2SxҼ@W:T};&(]r}d@]Քgа}ܼ#1f{Wf7aSN'cFZ:ϕΝoӅh¸(>fR5?il-Ӯ Ԟͤ5xߟvF@&ﹿ">|8aS,k)N vdߋ7ĂA6>92lfAEX9yk) ưi]lC9JxVOԡVZ6%0&SN~|Z8gerjhnNp ;\ >.4)0D]eL6Hp $Rw79IJ%ʿ⟽01ú[lFS/,{:jGWgMh_D6 QۆҦmLCְP]CZ>AR*@ vk&BiRAw-"l2v iTnpI  aTA1nogg_KP^;&`HT8 @M;Oɡy"{qʕ MD@$ &5g!5VviAF؅=]~re6pU@ī6'(rwn}d2ehv<@F.u??fzȕm@Q[vqtIuRn9̄.IWl]-k۔XnE߭Ƈzؗ?MzL&L*ur El&f/k6snc=ds{r=^Zb נ{kҌ_2U߾D5kMU_EEEs1DR@hjX,PAg`"үEGW؄lc6ΟK|+-L*ӄ?b5MR*IlE}հ'!t#cWA؄2ۃ'olm3yͳa#w?Ue]z\*'*w*z|4s rL?ߥbbLMT-iճ*|D'2f]PT۬K۵).b3^ttC[&rx<|Gm*ZpMcW׎fjqpDS x*6{qz`vPf:Moڹù e uOomgsO{?`Ѥ1%GR}WOl-OT3/M S`e$|i#:^~gۘ%R *@B;?FT1j9nW%N36ڪn1 U4L ,ZT^.9 "U-?zVDGz11@3 E^Oٺ;>-IhUUJQuĩ̓۸*Q5n !i.o4۩mtxD|dݏ=0 T ѕ39 Ys>ey?y$ˎ/G ui)tJTZ]c CM)V9h B>Zcw,) 4.C@1W-Fh}`Rj^r JosRH;'۠6~z0!s.}3Eb1|^"zKm|uLdǎ>i6d e blgTbXH㚴K- U =Q>I=nb''P.T}O姹-y_bvQ-*89:]NȵNN=T~˪|JjpV켏ŝ*V+8i(31uC}u2f@؎mkXUpBTvc < /G1݆X''*ʿۢ7@J,LĖ =3#J2iCu"J+{PjySaofٶ\me]#g: ar$/rsTBʇ6}=Źan]9u,%Nc@  ~S'sn]-w]}j"d5M@sD;D#, < цֻK, .E?n19?RŃE?nePQQz|~.G3~88x0ޓ9jW}Gk$^9zs=Z˘L-~ vBvN̲A6_Qd:\ЈIV`<]$,e%8Vu!GǡIau%>4$&Gn3l1VvAE4ފszP(+:.N^iEm[Ɠ֞|V{.,FPtVT0krNqAlJm@x"1>Q@'wbP気mK<m& ]FYA#/-.G5!Y)N.d:$便̑>fte]EYgmK8 f@ܪL) #Dt]9pѺ[yc0qp&Gd\M0kq=,k܍KfйDƹ\] 1Q#u\W:sTtKnea'B4:yVTm',k™?$vnyK4_oe!D~ tyyC=YI_r9's\p?.Cʨ8ȍ˩L{^mԏ$ ~VgX.7D^l4_2k=8K04Cٜɢ..Ż yzbBU0K7-%>3œ%6lG$ȕh+ 6VsiE>[fWT@]pv4Z5.g"sɨIB>OUkz]Y~ɓ%;Pxeє"F$3As^sJ0ȟzR[i,y~_Djc+eX`B0E 5 5lzO[axw%?͌c&ЊmaPA ROtD,xU/r=\|P, нxVH蜱IO8?q&"N+Z`^6XXlJڡ|_ccS^ڬ. -#x y *L}NC^`B<"Ź>1&y4tF:(57TY2M1g)λÊN_n̼ ?AjC*idhKQ["$;'3[ <5^Q`a@cd]ьUIz\&N K<'w% 3J`"Ֆd~(K)U&qIÂ7_74{&J|%^}>1CaB/ uy:Wn-4f=V!W"npn1T@\($D<\bl>8 N8ɢUr4OB؃yKWY!X~Q>NaW_*90Ln8v ĥsfaF*8 2Wو WF vFȱr`S͋++=e*ɩNsy+.߬6Kfxjm 2[lw+/9ѼٷTAmZ_+›%gLT^[$b_z_˲0wu:^VCP:T||ԇ20B*> ~¤7׌}'Hӎ.Sᓍ$ hگ_-buSFkk.Y1h"Q- fQHG0ΫK@\Y)BzKGWԉcW 8'뗯-#h;:9+~{[ @=gwV԰PcWN\% _WdoOȳсGSn1ʡ`P+8 >ǥG0~3D7׈Y0PG0\rȿQX!QJ,|ZIO>z'ʱV|çx! 04M=e[;PYG? < :Uu3[\9LЖU;g(YlG_doi$7l M  B4{hT ŎM}:%怳l˖ ȱכle [C{R46'O]am-®jѮel mTղeؙv"8[n[m}3k~"hl, \y!GZ&gĵ+RBڷ#'ӘEY^ b #bCpzU}J 74?-dU*So k:Es%+=M(ֳ.zjFc0D*,*9`hgjϽ/Aډxa~0ӎU MEhj_(A"ɚn[tE&zW!LcepStYn: Z&sչcUtWִ8GmN UAa9Vɂ㇨A]RoaqXΠ{XItF*y`,0[!Qm^RMw8_4a;!߸k7*8'*  HMEŋe64TL9 U Dxn7' *pqr).P>SSSh:-Toդx+f/+yu@;9Kod6V-v´rs*}0s Q'2#\kCS_R>యubv7*"qD|5U+!c{,bŜ+?9D_[N@ Wg]qu[""J<ҵ^*xߠob8AΒp;=d]qTuR7[JXJ_4|if%Ǹ}ˬJ[i/-0X3K$!3թRnH^_ v5<:s"t/f^;p]9!O`˭'_~[}zq`$wSC,=Y* PKQFY82PE+s0筌]ͦ,g] NjD釹VseӀvElLX^7EwqT:M+GuMG$*4W&ZK]3 UuÞ.]lPd-: 6ht9`!G3,%PcfEq̧4 L$|Je;9F%Hg|\8}'/{$4@s(99ZXD*wx@)($}D/GD"VĠ,cE-ܼes6 ovL^:c@[4B^Ve~E_:{3bA@ƍ\V&!V`-$B X(PJ7B rVx"L4)|uS*2t˘ *=2 qb/?rN*IRODZݎvw h (EN#0=|pn9p޻-Ȁ&, hԿ5d09ӡ&JҟC$U:"uosXU,2PccLŬSCQIcH1k8s-)Z.g/d˲ EsVTmA~o JȣvN`,.Pj>>4|_=3Єf]Q} K[۳o1Flh>')-3L'ho%%zF~C͡[k[6VՁݨ iF&wȲ2 3U*6յW/m׎ڀTibU!|=lvDkN+w]Ofov||5_mc닻JգNM^)O br{U.4Sm9l{O:˟I BxlD7ĵ?P 2r@MU8yhdKSEp<́Tx ʥ-z=7Z 6 ڸ;"TP$-$8l/ݯU3'6s<\ (6l~EM-y~L@vnfnm6e&㦙͉;[IgJVp9WsQXkb}0%4&e?@b7g_1z ,-u[k4s8 8PXŒeqj~YE> WGhIocQ>کq-mY;pNc\ \uH(pY %8ylZ-'o=Xup#sP45}C)84n.M @AY&_rb ER>6LO6A):`PXdj'+lEiW^a޼[WC I3 : Tý!l yIjRl'\Ӻ%1Hǹ.󨣃$oy0PYQ6]Ө:hDD|j>blcM݀ gG {_S&Dg7tW4joUW{tkD&yDa')8r;tJbvRF+7x \}?b[jXRooxP^IK\ݞ44KY*;4RlCeOGn`$6+ K =Ngu0T b}_XЮ[ YW3z|e݁71!T% ~zE% ~_T̜ myh>THiokd;NHso}T3dT=Euπ=:9~@usQ+b0S5?(K&=FoMc4]*7@-h] SG}iu԰a-nOڰӆGՂlP5ĺ QB3 8g_e*oCBlXdU3q.+p&yIM RCXUJ;~J==6jO4ojr4&`6R~ -m/ #Xus=S(MxW߿;7 ^􃒵 #bRhIӒ*P FȪy2OЪ{yCvH<ԫ{@QGzs*2sQԌ0 4)}}{`2) {agc5<4]f~FQe6P+xkpi4$EUVPbjsvBU5yrE?A }tw8x?@\kDoGd9зl>Ԑ2ٵSP]b_bE5?DY-R!뗨'SGV24u`ۘ&9=m' *M^p^b'=/Q5fsbnvHX6ij1 *3S5~mC5%iuͱ ~zP5*e.h&@g2Pj:I ['`dxʑ$ 1^p9GP{=K7 [a';hKVpxeZ3"ԕ3?ݛ$u+}?)ڋJDXe *ʪ5H&F5RNmeI+fO7u&7S Q] [9޴LG U¼ A\_u3 D8LPOhkERj88k!9Me Gf6Ux A @:$"JR 9EL.`z('p !)]٪w א:҇/99geVX˹xK8,HEZ9 @K`yE~9:Bi; (\7L*E/Nd9|3i]'{6,wvR(@gldbu".B)8hzl!]'՛%g%tsO2V`+.^u_[Tj'`"Cms'ܣv<о {8} 9ֱl2IvP4b?b5=q;d=xUk!E@|&oY3WS+($4^46[ 9gd75cav$+[r:~ /!{wm`( _%?^* d|'٦hyIۜ2$!&>XGA8\C|Yw}sY#L2m OqfA^mi\Qx:aӁ loը,4q^礲F}clv] gxEw^/IP,]"JLv%|챦=bS&o8۝$ IT27OPNЙ6dsRwG *KLh\fCX)F`I'q:tvYRh%8 30+f1tAQV)=f酽9U;!qYV!Q._(dXݛ6 `>03yU0oHE+V棌&w|ٷy5*' $c"l C#NK`\ikJ},BφovSCǐj>kjo1^ITf>E1Ҫ𓨁9 yH8S:No: H6p0}0]Ho/J % l.o7=䅫xaΠvJd׿dpˁEh,\k,>ФLaSٮl=%ɡpF[t4EwOLjIhOP&IY?izrGz~(G5)ˆL;F +~pT^m}86r_a ;OWJ=w~u] db3-Pwzx}R>Hp75 f |c@$z(K|d^sZh:: z6>;^,3sݹ A@u~+!!ɄD)Rݟ@0ڿr+M;e~p+ȻJ)\AluMM@o_) iC_@Y۸1ԃO^+JNi WHFB|BD[O#X]08B,8>ZbQE`ltA0ځTv;wBw.|1è}A #w3ʬkmZeW-VTq'wG|=E椷bVQJ^$ bx1VhpOedaVzsv !FH7ð-AoQdo\Դ5e[M/tkc:'VhU#  4;z[SZD~-W>ijـO~%LaX[B#ki(1iϏW<[ XD4Q;j$tOyW&.n٪MQ"}TEpF<֨,=iu&HJpIW6l[hRSCG:ZfiێN>Wy QoUtԸ?;tQĠ ?AX \{Q6U4`8*/R}9=s- 4WPDlCڌPU*|3РKz=ZNa,qxغ~{;34C34C hLJ?x?ccs{P hz-k-fK:NEDOaqX )5!A,=G }7hl}0VN<[|V$d<,$SE;޼svOh99;g^9Y晋&R> ql7#%gԅDh|.8׭hB^'ps={5DUķs-4A]EƁb;7Ii ݃ pfxdaL9 t ]7MbR?3e6ż TDF1HDa&adjȧ/ %z>9Je{h43Vk.bb~ CN[ : V1l0?ELlNn %*^6;#iH]=bۂ6q;MTbx}&aI_Q˟m[W -_Pp<[ln]Y&"s!q> .jLx^HZوS2Q@K8W+gnTxeqQЅu-qI-ܴHّpC$2!ȴvpf|+ltDX|a98~*\9_k5|yGea b]yH2 CgWex\%BM ߣQѕ1 Q_5S$)P˧ ~O}g$G!8 $rk]I2ܝ҉&;(~L{:#g挪NMҪ[;Lsb0s20˄ei/[=.qaʌU&H0NEbM$ee-Ǘ*s"(IH_-æn Qsքܺ ]L~,m꥟V9S9 呂iEFa6+U _(*& 6K93IZ(B*>X>D#Y 1Ӓ=L'mQBRPnMS`ULO3\) MTߣw23Q҂/?ʷ66}8G&~BTޢ-I#b8\8PA@!5qpo-'e.l u J#*W}Z@ý`עfgoq,GeuH *yX*eZ6]2K=jbzb-q!cg|%aoμհY"r% ZmYssP%a64Y^l-# oի]nSU~0Δ 򡻆\c~`p.0tS5pxޛ0n2 vH9oLL1䜀Jerg c~1C=lKM6 ӛ;Tb_H̰38LZgCSQY؄N$lLWf0ѷB&: ]qK*A1R_$VL|`EP2$mǜ4Ċ3\w$tEJe^m<';bFF"4$BF?m 7_LV}ռ ~EwSaG=g6H N مZoVFoU)~NL3mS˳b{iB:sUlA J$z@…W?CsAV| }!a֙M  Xdh[E H J7t9j\Ev ) e{.E9kF {@crr8{z8-T !/lͯ VsoĺߊdD *) `l%&N}~d%D^]*:\giC8m|= M鹾6-n6X_Ca_Mp.H/tFf]QɥF!;W_x#1m|П ))NdvxkhsC6ȗ`+ 1$iD63Mj/ f!# A4 wyd2Kl9b`@EE7}1L,zlW T|jfpR(>Y~T3!3Fco1{ ݁Oa_J8~ǜKB2eǪEm@NYn,!*#qyK$06F-p囼me'gl?~,ʆsiԛFAN.|" |HfGAkļar:]mbͰ=5P RcVGk~AH?NkIR>&Ai'/&c?cFIE1lE~S>S$Gm5Ϥ 8x]T rw anedZivFJH)ڧδc8BRr Y3 % -i'|w~Ű(\Gvʐ p!)EBC@h/56=\@o9kl܎(C/Guؐ؞MB@hG3G4L|ö5n_(z]=;O%7 g@?bN,8 nd%2݁~H bIwLEgs,^z8-pkޟ\bפoðD1g-%^6Q]ZR֛l?1ՔQ-+;IwvSzl\bjLgE׉X>bFuZ8:}:< 3-1NRZꞃ79Gf(rHMsFYon,_n_@x#G(/ dX43a"&A4X2HSOnTڭ% BJ'e^%=) z=73vN6;fwAH%# _+g]ѸCtZ1xQa;74LjE*XoN5NUH:0|g7[3b:᥅IOO\x-u;:ށ欟+}brFך֬cU&lmɭ;N-hzYr14%hJUwsqjG*<ZCr);-N0Uf$d pT[ړWh,>$Mv3^L$7L_Ϯ~hP5|zWe8̤|YTpç]Uj<9IzHڎH4Lp*T(C޺{|mՓ|i8Ba[e IQK07uHgc2O|)+ȼ'} JJ D_N`o +~silf.o>L=to3evXhy-8iz7krg d'|o f2+NxSbb9.cP>ßGKeB}*+\z8x8reu34ܧg mR݈4#'e5dB 13#-Jwn!76-jGn>Rތʷz Yb:N{[PH h[Bk.XUo 5_OaTi pe;.$۳8Pjڋ~ɸq/?[2:ByřDzlH9Dw-0>VZ qH3^=+·n5k6y͒#D=wԻ#aXk1Vѱf7v<'aO1vfP 4&(*^`[A<2qd-r/`ss1LjGg)dGg+?{=C38F \`>*=?%?V]ΜŰ߼/sy%J3#d}Fx_(^,&p%H;TV'hFL 惱#ɷ @Sb2pB!zl#u <p0P3G!H-2 T\w "Fܻ$zl7xB@u+,  `檒UUfXss},/L  $wD෕5L;d::f+4: [\ʄ00eHFr0p^M4<@ d_f\u!5ۨT44Ot[h/ږ]AR|O+s&XѬQL}ߖ'f Ci 1m\JR T\}[tHX;U°H䀬xV30衿nZ3R5>,TH 8Fm",1ƈf|9u*46945],ו:7Gb{}v4:M[ͅZB S+@s^.aLe3l~6YOm6CAI5GԾuHF汁..B-r/^dѫRvkZ0sv^6e,feَ}SyCj1M 9tTKW?ڭuQR;iC6=a v%d +eWiI|0B1yFp_̠ Kע%XZQ؁uMI4bC2_"U=V'NM҇Qi-LFzOFGǎ_4U2|5d8 us0I7/tt%<-L7 hI=apU@ES^x!c|q`ܡ'Oc/X٣V#z&ɤZIR 5\8Y)}zdQ%tq! =SOWǥ=j=6ڧNI|`e,CRL)G; SAs1GB7TAœfeTv;jax!ЙR~vQDVR"K _tqHƥcZ8BHX8fD_M!=We$W9kB28W uad/oyd:QK7hmsa)ME6S^;`6@SkQgʑCkG9 |/P5)&j&(~ڟ%'bK=G4^LP 茌ʪ v=`k2F;SV*!\Ӧ͗BKR YՄn%P a X;MF;kCʝNAs,慔mjmJf&4]A~=Ϭ˳c)`fg!\㎡6[XdZCC%EK^H u"5?7x{%)2rlWs<|9G4/Hd|Hib{!O*J zjXs$|}ӳ˖A!ZrֵTftm&^P'EѧIȝ.B?T.A:,Y $7,TSqPtH:ou;X ?IR3Ohpg8DB]IY H 襦ǻTvL+m4Qȣ.3 Ru2! 7N⼿"NZ>s~NWrmuʔky8OÌX{AGA^eq+LA@}xd!h22kLtNHN7f6H6 C pr>3D[(Ѭw4ۿzf%A_as().$%5L=ƭjϠwU AG?"%dF}Heq8{e'i@)=|e4e_b=@ buj#Jc&EP)WD{y=.U|XiMyEW? J`ƉP=TǝvRwsZb_BO1Ht"N% @HB QWŦlAfC C t2v;^✝!i#9JѨR?x jWob{`|{^_2&XĜKبN5~t!fU0ɧnfk* ~?#E܆+@41"ZlY]LwܸؓXW$L< '7ܔ*J8Ie3;3S L/V2THmeu%?v%Oof}\m# _gf|H:7z9!}UtgR5,,@+z NL+a Jf%9"O40l*90 *2~m.eᙥUBD Oh7zSHU8>T 4&2yrf΁4SSZjkhdωg0'ʌ-i /VL  cÂ8.yFf pBNFllX%GE-%~_}7j@N @gsU cfRwR=zC"۾\=xw' ]/W~j&.s XIdYG _An1T6W5㹾Xkv.%bAoCRli]#1b<2}O7kƁ,&s7P'~JM kO݆+=!;PxiSBK+{Y4r$M}iXq#AjrA."_Wi;.o"FeHi.›է)w)O נXY^_DviaSۈk ʖ{8|P|SNC G^E:k eѬSQs8#`*v:1ԒIF\+OIE}C>o PJaY,֪.S᎝T]p`*Ƚ=>7@dZ͓2;sf sR/iVBf Tk/ApZeÀnԉv_tɋ8}lTǒl,`ml֙Z[ayPUet9'DXDm_ɂ8[6ivO1QCp1WţVz܌ KNf")b~:W`ǮL >;{qv\Nq%O}A | j96[߉wTTØNY?/֮$8Rgr!`U=ޚrLqt)rzv 1QuZnp"908 6LP_">kpg;c|en oͤ}K82u+%B~HU&dCU L}t4AN"qӹ7Q<&4C8Gu/'ujP8!O/-RrT 5q:V͹Rױ!۝6)+zE롪c:ݴ vpQZEie֝$Br z^1?sqn.@KaP Z`h1_] )`MOfm"wK1g`r~siɥѡ=>at!.l$jO*t'(L#f*ʿ}I/'Rx va*kH3ؐ^Sl?,0. [bv֙?P"RϼV9ݟzQ'?UѸM^;C9{1šg6l9}~3=!!& bfXT“ЪOh~hjO.ށ4,&9~yݹ#3p<<ĦRqG(ntj)#äVdF<u$.kR_ΰ9[@!F92c?>ۜ03 bQB;=i$z$W/(蓯Ҟ+E @pCce݌@͹ z:6l2 Q&Byv sK&B*ؤsDL0.3P) G9^|WfC˥0]N8%=mmtSwv2 $D-V_E[J!APMQvB{VGfRTw3}4)ս55?퍵l |45Sr$\ڑsV}}~*Bf3 ZV;(a7?$&O!1^iGhˎh +Ή(ȃ:SCAdG̊3m5uВ_\PP7YOaZa #g@ F)=)fT.\ A=F3kvʄP_|kg;`6hy+ .wki[P2Ooq+H2C?@X*r4nj~ݩ-ɱB#8Q5v&NiQ<"UIh8UDkw&RPLs"U`SW,=}^.q]\,6 c*{XF|VNYV!02M=a$ΜlW20JlJǷF.2uŋcp"X޲z/>^;Y78`f,%,gWgE0@ʳ ˍweC1QK F/δ3~]FL(qd-خaYUPQyh {Kj?r'{Fk6~|ˇ7bLtw] %dt^Wj,ru>ruU'>ۏ 8E| No]L} e~Rh+suJCDclJ$.Tā˱K|805'ܳ>$.i_Vv .I$jՂ_ԊLx1j~UIӁZ8U"zIwЬ\I`/(U;*dGj 'tb6*&>#ia 8{;2h?Bu]q5(0KL` D55"_Rȱt̡H6VTHwE jDeecWڠ_q} ^>2/%HZ6Φ T}[!ףei}-A 6'5?/į'w(RU Dm1%wFP?X!"\@-O &%_gSYuOYyW*$j[ذPn/8_Dx'>ZtUBBYQBb/~mh#v$=N \Nn`' (GF=֐ ڒC̎!4!j Xn4ƼR( +Ch:pmƣW+< F+aMnq JVQJ˔²׭ 5tͅ)'&y7&+PNٸ|-ӑW22W =UE©#++(!xe f!,>6 'p<^0ǾφMRWC:*WQU+lRBSuTPǪVZ ި!'<APQWRhTYWR+zR LP;( %YLic:'0JԃJ3 s*o&iˌQavh7Ykh 1[WOI|o)Бho K * qtM8M6ܯ}Ö`hxQt,}0Q73`Ҭ|+2v4?}o;$} =P]ιVCO|<6ݳӃ#Yt S;!D9p=$Wqk_6!tX°ۇ9iCHT}y*$fTIY:txz`Nk‚X@nE#Wv-Ņ= XD$RѾzo<!oc<M%nxdq*GW{ϰ(7 POe ה5eqy*<}x4f:miFj3NFW˻('0/8۶O0 Kh\@[S2umwҪMz¡vڀo[iNN?z>Jԕ<ы"M0`F dnxPwK'% D3ibtP)$eKl"!>R_ 6'ID%`/Aa(YGTS`%#dO񷕈wc?I$=W=N$ٯО,3vX(tfa\=LCǯYߚ]Cχ~ 'R)>lQ[  gҗ9RA}|IxL;G"]]Q"T>i-4n5 ")O'2X`3"g`0J^,:OG%6hvH"Oh#PE [Dn,[wJ;KAo*RUvWOc0̻h,O<n$Xԁ]QG4 )(3 lza~(IJd ǡ@^3ɺbLДAl v;H#/C*'Lq!;-] o* h{@ulӨLu~]0X9s)k*}I":xё" C tl}#pKaX]p]"=C`5 20RE!-˿o&lAIeO ʇ DZ\ o'WZ{12wHX̊ć@ʣRӑ@utV!nu~Db`QƱN*uk3' 5|Nݜͮ{b&Z}3N'4X;hE.b2\WJe7s2Y8]@aBC>DRfa,,t'9K81a3\?뮨q)Ó5gK"1lYӤH3nfVAKU/]m@f uot<*3;!ߜx^*i(cPSXf5C"6#TK׀ [-_Q!Tz aI}O~+57KJ9xօVoMCW\qx00LKЪʞɱ 1XqV;l*Bg`ty PCV2;Պ{įVT.校+@ϳ^U"~X&n~zA?m'?g@6fp3+dc'I;fdbfI254Ǯfk:ϜJ"Plx[HӸS<(cVny'XG\5/f4 2XJt)B"ʅp֔ v%{JG j+sc{ר=HUnO=Y$G:w ɦ ^(4S } 23_ s%PӭSuz' 61K<8?@z.L|˵bϛwDR^ÓZ}Og,s[&]FX^* yF f)5&~ĂsN!Ҟ[Xٔn8p}2RHt輧$r2[5KZh,ɩ/\6] jmT} J(snѮRf&8na[֤XW )6NK.8;m4mYW;];/4|zK F>/-aqIH۽@Lw;,oj 8+v̶7MUǸ^9??I/ ?K zuǃ۰& BRQ_l% D=wFSo`ᲝBP#2"v.C'|#ZSP" D\TK8;u0?+9zhm 2 T&R6@ k~noT&FrvxAJu8GCW "ߔ̊1څkh'oX4mEpg0"NF cUof:ezZm/9q:i I84pr#pMq(K/rzt䐆02nh`PIZҜ;/ w/ GY=u9ʤwÞoX7;+1,RBވ##ׅhv,)Ej~%c~R?)85%c64EB4A]s6xN'v|g=>)uNUC|;ܡ 6C jI% b3X8R`6\n^q'm:MYΞ]8[бU\\qGOD89_'FD64Hg*/_.˪PMxʵP LD{KcPODSP}ds ~;[YO(YmcykF$ Ub -7b5k]6 ꍤ+`|m!gdP򍒌PX +ÉUw[qvV[܈L#IjW52SK b(_0~b髪uviс3KRK/M#8[gfdԓ `d)Ɠr'>I (mi}_|HF!A,j )9 1-k\g-vFsʳV|>Dm'Bh&&x '`9tS#hb_gr4Թ- g% eK3Iג'G\DaO@.0I..잱zT?k`mLZ`v1$fa^f.wJ,>FO<ӦSdC#u,tYX K{VO(D&.Z.\WˆPHL;HCy{VΟ9A-p&S"po%dj^q D'(JDJiXV\=RmطQ~u` pobJB5אZCYf)B:-z)Ei TC!{xWUl:̅Bxq<3E+ᩭIjf@9]rA͛.|^gfxږ5\Lskd= nY66$/n:6,S( NYt{tOóZ$OG ѭM-t6/ŝ5 %?t0sMrNT_(`f~ Ia[LmC[|@'*c fbUWH |b{5`Pai:gp oCfF٘𝪽{Gy +g3=ir^e4;NPrﳔC Ek3N5ʻ3S6. 11)S&pNVd==?(}9TN\PH5<)zK)t;fˍX l;eJfR, u+H(6L #:'_`bm i^u87L[K8F[nfXٛԦ'l(}tJQJW]a>j4RuJC9P>_Yv/esQܜn@Yv%[y4Bb?~ڵqtVX~„eOAy (Kl򥲦KJ4{_IXC |Spވ5˽%NJɽ%]{$58v^7 쀁j!UjU5eKEL-o"}1mqqͶ>.-X\è@1ƞ@ʫ@PBF1ec){+:5ka3QxQdSVϱbHa9qP8 jہ(~!vq17g~5{sOLIغV}'|ޞx7b~EpdO  &~ VS³%Jpmq-s7.%#hbX;s#zk>q23߬CR-|POiX-x,A~odm(Fֳ>d{%8tOG$VQ݉wV{jͳ̱w^foQ|\߽WM⮹ /T߲aFĽG%R.%MqՍIm `N2oӸ_.{6 _N ?޸DSnHh<B3R]"* '/I |Vn#"zW6'En"0}vud;֏lwӌR9*MM[Q׃V`8Y7ƻj5 h;Ey]jNPW'JBP5,)ѯ]ɢtk/=lP$Z '3]w~ّ\M{W|?d$hVw嬊8ˮF!6+5ݷL-RkBn4fm;(\/U y<]6o<$@9k(e|;7̘I,T>C M`"-_=Br?63Fe61fξ"zN("fY^,-V;r28#֟Q} H)lTuC?9|㒟4P"bQb Wwi C4V;De~vQi}@pUuEf}8HyHp{JI O)C'iNþX.^yReÍ3%1H"س衐M#^> Rl k>%z7 Ήq-WxD Vss)/'x1obliO8UAYLZYOt xpoSFuxp}DwS?SzZn["~Lx;X@0W*Ar܂ Qi>և a΂DUu $Whk: ~ؕ.iA7xv!3~"0^Z㟲Ovt ֹA^Ejy<eTR~B蜌#l~TˏCt/ ^W~{^r碙 }:QY垆tgPS%3gOl|\<z@u[D!,k@/ؾs$EL`oRԐ5a_)<;OV m$p26iU/zIrg1f1?Ǡ)ϬF|.e-9Q3Gjv`(Aؼrjع0sg'=N.,pC]e_ :JX<8\(&z0n5/5۱<ӠX/(@.6YyUK@ wIp`~Mֳph# ۰uI\yυYLGcÅu&DZ̑!b_x͜ Q#HP\oGTa[N彽x$۝\mcLS@;!opkoxGĶ m9N*\ A{vэ&ԨAMoJ@{st@Kkli[Ȉ}Jj3HSՉ<9 0ټuz6k>L'휎,fZHxaزB_m1'nmw≯2D>sThDrE 5*eT&A2õVlZ 67fcZLaUwn3Q))4k o&f1}CpXEj<2hXPNM@h,r*PܷP𗥦0*>'roGQb4mcogEgړ]S/my,je-IiY~JYóM\l J OT7G i:]QR]l8\o0{se[N ʎU֚֡+>dNݔY@ldIg4wc;ePui|=(NLh S"Mҩ3C!C590S@o'(8j.:O}K+I%p{BtSj KG! Cg0vY !fs O.Yf:w5n3`$lx.}dx@zC-b!lsh"‡֫@V{mćјM>LmM{hw|!ŵR P(Q>Ac5 P')7~r}ՅH""q}&sQ-FS5Y:>Xm u<x;cTmZ2^ns&bOmckE%%I51O CsX Ğ|rt g=RT .@ yOGV}ZŻ~lo:5ӧ鿁{BVfGAB5n V lH*#)\@ /6oߵh%%\^KJXJCs<txDD<\+b̄(V ~Tpe#N{rgni2 ՓiS0M߸QE{DǺֻYK,!eD`lё,C(!@ri0Q3Px-چUOuoM.q_v3NP$ lTJ!-&0Ct'!`XJ+@a)\.ZKZj o5y\ؤOx$h&.<(NܢYAds@`,GrۻüH&ɺ < $OS#C at&*Nt{ XҲx#t:/BĝnYj`^+eZ@qկax7 ;0")uiw++mqHA>9.8 s6ƒR'G_>D9_ДXl#dFKߠ4N,F炥=jv/xEǫKR>i;,yO,*\@{\?{פ=m4}RڵIij,T~n/1 l@Nksn}bjL:E>B+Ǘ}U`>Ywp`h8HܳAD.mn+g[r+4,e#6%n1]ѻXP9`WM=%|ʱQRy = 7ZG}@ެIoRZE,PLS{rGT g$ fvɟ5S>qModg7.+= Y1~'^VDEOi&zdweCըVx?: H=XB#V.D=Htƚaw%_.ڌ2AR\{E:ˣĉ|U' c ۂl~`ug1&د - )*FA6نFyPIKX]E¤x!S+t  ^-B UVǼ*>u*Ԋ11_U LglrJcy7ډ3 )@ZOStg^aX5v-3sm<&yxQJ"ZkF'i:>; D3C˟!~[V ̷4}ϝH@z!tqgYy^1g$#}`ALct&q0,@~:ي;-ky|qUXnotMkNø'g:[PkrbO tG 3k +G~kU76_Eg}aVණ3|UeipN&zHm]S-8wٴj@_EHkLӟ"h9ۇPñ[a[{ ]TY( _HRU"59-'^C szwޡjM ~sAY8yUeAJy]ֽc/zJJ΃E>׏TA,1ȗPYdjŎEeVKNOreOIAha?Ew+Ӥ{BeTGmrOi%=$~h{++0K;vIW jw3Tx.1ϡ枥>ݧ%ژe%'jV*D6D ϕxvN̑L['< M>{-,pI}z`K| ք1aRV* x$i*S^J>d5~UAaw|HW\pR G"tY=\^nW€X `VE<{LٕRQ\ieE ǧkN6gΊ؈k/K1Ȓ:$S47 觺Y7wp:Mm@ z]Wh Y/-%@DV~X{ՍW =< E0Q.rp^`젣QGDAnHsQq/k Դֵ[4BWG)\UCڭ*9ŒUJ0(8sX{<8]v_M]*IF_{, =P,_O}(3$ut֚͘2 )gAr+h&KW7c1c]٘X 2C~ɕ:^}EbKf$寃{ п[ɘO7}.:RV~'. 6F>*gyfΙw \VW҄dE x<}3φlV)2@۟G4-NMP8QR ͤe=Yjݣ+b0Y_7e8-eb;\fӲȀV6cZ4rU~7InE#+3%05µAa]xa8SXUZȿXl%S- Y~5axR-5<62\:(M`vo}33 |nD%vYN` .&8jA4(WܩF{_ G18?3w*R1q5##@[]k;ΊG^ /kB*eˆ bdžIY\d^`+ʀtm+mt&&/ؘ`BΌOH_ N28$\D4F8L?"i"2-+& c?44,UbLxnJ`*FO48|MJoO=U\^h?t^܋KhY`9K[:`#s6ӊYf>~pZ* 5Nbw!~*4*oj 4" K`@f8~Xt{&[. n^:r[L~tLAfhۡ5 &(BiX^b-8]8"gјpoR5c @lUhQQ\V:i1ˏE .eoxE=Wy;bgّC#|Iڃ\E;sq蟬c.:5&mwf5eH 27PۑJ{D7 0Q5 ጰW56No,ҹÃMQd3Xx $L[t*r#ΣH}3l Rr::<#VKȔ€ȅwe (ң~rv"]/%K/Al1dY8dUxK][܄=6y̵]kkXR.Oʁ^/yB̑RdX+MżAr LQfȔthkog1!$-9ĂzTv֋C) Ќɿ4{ 'hO8hf[|G807,Y;`Ҙ~2eb/|Aga;_I-Ԛ ٙ&u4oB2u5cEgpŸ鳹9ghpoc]<qV%ӖrE;J|ꄡk6 ];!X/2۬ u)|R}F4'x9,6Ȳd4s@^`R\7{'E<}=`0}=izE`:ʗÿ;g0Uju Pb^> a^%NF=5GÎf&Ԣ*PյM+ΆjzŊO63ZR< In>7)ސ6z[.2fA FfV|Iy.\i%v h>rc= Ua YY2 :HfdzUhO AUTMhOBxG2@g=Nk%U%RE7ܘK %~'0Qht]_ixl$yמ~{+7L$jmѡ8bfvPa0kBל}vH|}/A6 "nQSK2\FOѲS: C`p;q|.o=1˦R)4 gQ !&02gCE}ӯԁk>tY},ds+fVouZri4KszZl dDQB=zؒK.E2Zo^I[9$;+D 04Lyb$OAOWU%F{A\ 2dED6w@G\yLcy.XL ̲~CYI'#8.>Eo`|5$gI"j$9A쩍GfAƒkJn3\ ϰ~;5ͯmװT${ %mD8l yvܫ-;n0v8ĚC ZD%OwZp5dhEo%m/JZ"ETw"%D UJƸ# oz@eS\x--fֲeK7\5MV)7#vm600tR>bu)pisPMS%iGSE_D8$MQGDIu%빊HwUq| /;nzɖ%܎,8$>fi gɨWH$.$h }{%퇐cVK T6f/0zutpY7R  RnKDKa ~iײs(,fc!E*4ܫ-^J֭#=)4W@=G J,PJSn(Zچ97M"I#b',?[ Ml1EU%=m1"Hd3cT>!9Ϫ*gciX{}< e:@Ob5x*8-{ .d(>Zo}_ny[%TO 3Flobed90Po;vZ Hl" ;ޡE,am'E[2%FcE${+8p8&.~Ƅsj.bBoOwh!1p`Q Sf˷d-7 ߉WbzBro{ h\Eg8 ~DM &@&wϒ=(@3 WpJ2P 2Rp#uPTyFWfʼ|$FHpj yVf1rJ(86l4ޣ" F“4Ϋ灛TQYHiF9@&.~E"_'‡>̭6xF I}EdcijwK3K# nj`'@*#P 'A`=XH8ʀlLCx1Cyu`rFL={w:\OX.-Wr{=Y!q|ןJ@ZMYq%^{ @Ve& VG9h9@-Ps4?gN>Jn4}2 1FXbpDU=Te[L9r߻R8kUEoU݅#[؛topr^b&ҽs+"$:bc|-ʌ ;giv~`e%lױp0Esg6-#Ϡ8@!ou(ϽSٴKb Rf⤍wDhVӹ/߼&24E&`l Z6Ӛ.Ѳ9( Cx k.aK1v+\%E\Qap-Lj{}RqJ!8>Z,n>sk~ }杏wBe/mWԢȢ 5˘㳨~mT{*60~)3VhS9jxg^ZؤOT|kh S造}9jD).LHӋi>| k`^t]9u9_:'FO;SCdܤ0&/m꩖<skuͺ_P5IyK33V:oZG{pf7Ƀ-2k<;d}Pí!㱑%3"ٻJ]7:$mo/d[%K};'%ӛ0 iMh>]X? 0Cl?v򀒴2 ÂdCRJQ[OBim :nfiڲm+5D>;{k7Kn646F8^(`ԾVX?{OV]HsXpn;i: 0(!d =1lTJ#9ŢQHg\'Irf`>,AHy` I._M^H]0eZAzRwQKFvs$x}eHB*D` ~uy?[ׄ-Eva2,N+Ь`˺phOV_{?ߊ΂*BO8Kn; 1jk 5kV+K? );M䞌7Ay&yT3b%%G g@{¯Ѿ57t+5.j[X}[K(t͗sT;ETJvTkDz'S$cd0y}+9=d[pۂk %}k^+t w)N!{!QPI 5}hCfmM%ֵZG4g\3wL[هC La&6$PmjV9Fgivd|gu>z6W~Umma˪rM %6pf,1F n)XVнR>>?h)S@+2ӱ T:[Hj* ~,SرmNA}ӆt(oMf5*5B(W$M_;Vj2v憤߃-?OYd-PRT%"U9Haًi^d^ c$L튬Ìğm""Y6us"ܩ pM5ߌhݛA*Hx}Ȍma7lnA Uwv}*^m ;N(Ѡ껂F-~+Lj/ 7i5!(-0tn9&t!.V~CsgNa oЧe9~1[O+b;0Jqcx堝N[2 ;&8fP7pl6 e5TِUY FB­|C,ίEΚ^ʏ_iXY:M@h3Py{'7~gzhߘsyf c[TO@9V[Zah k(bdH ^[mQa;">7)bi{@cmhU98"}1h.6~:%qvC0Yǒ>جO+ztcC?xHhɇ! "[deeI?V>bV8i!Ij{7Qr&! Q UҰ~G^9d0er' ya|ب=)Ycp1#%j"5OUZ?o-lj ׄ- :nW6A^YF\yrvmv2@M>U3=MTfGzI$ɀ6XgU?P87_Oe(}%aR~KuB?4z?9.0؇"sGdцy.&M#eS?u9"1+\2߱(62͋nۛ-Gw1\UįUxJQv ׾=Mo c[4--4͵r)1HM^yJk?tAwp5)<;]2ޠfJp01u'ĘoCaiyx>1N%1cTf8bNL3RO}J9.tЀubU&9v@>MV~Q; XyI_ O_iZ'w9G.F6D]хe5^/hUU/Ka3 :VEܷ!BfډbC(P)aj-nj!k|& T[3Dɶ\Vv9kSq+ٹKͅ=$ <=ǡ<L\,Ƞb%/qBg\ c: jijwҷt2dGՂFI 8{.Y.כ;M?Go|>VSf%hJ|ߩc1t>ޗbYtɅY]&;邵VL8~ V6T Xg\j5 +])y3W`&hlGP C ٢.1O ע>!x?! !Mj~s8]FA`ϝ)*3vϘ8ΠU7!_ۥPKSy%#U"^㼢6 7'MV24w\) ل㓷бĠr ꠭EҎ1&-O-s"=-憥+dfPH-pю7fEva|/_ U ^ X&VS_sFNeOY} 2 n\yuIq.fL\jʲe%k:>㶷;{leKN$D;68_L4?y.2_*ĝQ[J<%w~ =̓秪8.ukq"9{vχ7r./D ({EhCz¤mg#':uH8XƞNf'7J[&H8LN?;C-=2^9ZDlD 8qɻe$]kOsĀaB]|uSBz m HqW<ʔE { i)HAc XIDp uY{x20x0/i3'otduP],i!M)絕MMGN*v,8]^bK۬h 'K*i4O7\QCdR1؇;l`!@k\#+vk|f.}is~0 *r-4ѫj}L[s Œ!O2lnbF*׈XSU:Ww2GY'v+ƥwTw'&WؕsnA$Q U֔;?;:ӽX \|j/{LױԁH^aa uH];ڐnt32@&)/F i(i1_WMSO1 nFJDXNv(3m(ļ,lj9UҺFŨ^w@ e=CP5/O`ܞ [r7o1%v{o{<_+_ ![PdB,#K= 8{mp! JGD,l qh2kqSܕj{mViGG+Sw,ݺj# j]YKl~qZ4%[G=}xO5|rN4_(~C㥙FN.,-X s, s !xcɘ|,'xǘ}+ q' dHA; 4>W[ǔQE(b72PÂ",EiIʒI}jh!# k:[> dn$m%I8lYx~}@1b"f n@׽sjA@J]ބߍ}C(#~ 8l*䞤g4QuLy5$OdA C'4RQ@H44lݔCԷwGf"[G*^Y. j N|{|+Ms_31 ~pJ N\;!q, !kUV$Til* b_3)߳XpMAmத+J;n#4I(!iqM|*[obi_nKmgDuz~Ԋˎ,OR1+ %F,l:mzBꪷPBuRo3N4/^ Dr H$|;]gG?R{j?ڴἈCxKa$6VnQ b5٦5񛘟lէ蝊Q( Qk9udKiood\AJM+vBfMd) Ci0BkFv\/Nk 'ZLfIYЂk~ze!-#ڵְƈHKD}4ڃw'J):KCKc- lYK_baeN.ԅIe'to[rƙ/?5 eyGռvI@2~GwD -ҿn5r/ǥT+GŠ2`d: xt[\oںh;7B<_miQؔ.!euY״|؞ NoTdP>H.ĒdS# v+@cؿ9ٲCoX wV>kecJO:u`()σ4R"OLx?=[&+PK[\>&%;Kpu{}¹5ۯ{ޛH 뎳hLHaER~tSE9PvP2CQ·#2ӣ  :?B, &z^莣?AR$h?SD "ThWR$0_P=FK7[T _z㮇=7ff)tp kLʔDe@gd#l,F+VTMonlE>",RdR:nH_ys1?nؐ+1x,QT`#*~֧r:d QX{WCWגU~ډ|PM=Xk([k'xx)0XrήŅ3W,Ŕ D`0ȊU`Jvԣx N-]mr9a6B7Jt3K?)<5brK \tq+˨\\Xbۛ `/ p$L!I[/}#X-/U1OsN.{]`_{%Z܏{[bZ;1֮Y Smsj셧)=>>w3_ _z7ǣ?Kn$&X+mەehXQE-1s2D5׫G 5IM.+nĹIy7G7h7hE^zY!(C)pj&mdƥj@WIl";~s[}N~ $R6+CJ,쮕MxK7%\)\E$L~ۭtV<H / 37[E %?,c zW4l~4Ty43IY=14z5Mt>-ֽ Rq1ZJ 8 1%U&HUdwcKדKBmʕk=.FƙȊ)J>H :(7GvUgeV16)X)O`Q$ߖkm6M]pbp'乹b4x<(ufir{Ĕ} )ϲ$zY9:v,E;=>8mF-*ܻDjEv{!w@ԄI~*Zx0Bql>Ȗ='*@} N pNyó/f[%<%@ Th:_z`C,Gyy2 m b}Y{O<6-[%}ιsO!4_#9س([:mq3N:?b9mnwvN4BaY!xo7_a{i~Л %Q"8%&Xdx -lB+!YN)P*wNvz?{!ޖƋ\&ԋH!x PTI:χ=sr ո8&P} t Eء[fp< JgX7qrKn%Ȗxeol#eq]VIVW[t{ުf6հ0V06d1ћ,.Ru$F֯3ܱkdu8!0VwQ봈X n]ԧd9dePs/!o,1Psrs(Ų/U }hd6N*ơ'65kNʑ>e ۟jƜ312XЇXl0{ǐ5%g3 j!]'A:ݝCSY՘<}7k:mh u;(?&$1bA:]-X+u?f0F!z[e/rA9›L@~k`fhӗܘIiY,I/>~*Y/ۛxKIm!m2"^_a wó*J*"oХ]:n [֫ ysz{[[7~h/#QJǡW4d XJ/+oa2(pՓfA`G2xdEB=tzsNJftxءMR Tx T/pd"ƲF na5`0pk$t2p ~ӕJΨ'[EblhǴ'vj;JFݳY&9F SL fe/j2@Iu_$ [ǀs+gvX[^9*{K'4WP/[#;VéҰlӑ=> K![ ԭ`N@T &dW[dӇ̔x'8l(N$/@ s$kib|b\*J Y򨀎U4 'EӁU`2VlxsWΫ4-9RXo-l!B:Fj i~KQm]gb E7ߗOqݔt˔${/F%G!z:!( D za^>^VgTU,UUGΘ=>{ڏs).˂z}heAgC6"t&O [ygʀWw_KFdYycҿ恅u!yKþ i*>ǟFcr1SQcҫO5n\K+mA&?HjAOG(B8A40a r-]'=7q-rQ1s1%߀L9TEmԫ抆оNmf4v9 iJ#ɼ*Sq[4X鶵+'OBx_wQx 9,xDUisH1K?ӱyk>()|DU"1%!:vQ})%npySnfMjQ%E=;{jeB`2HS!V鴶ӗfx/i Z ?$\ PE*ErlcٟfZ\g4I}@%b2XB2/XE!q:O5sܪI;SuX?+*PpG`LܘGCC1R q;t HYdo1wYr|@.؏JȞGUv!uR~h# z9|ϻ ]ĚeC9KJ+rW1nTX%XEs: zsсanBVc#Uq>BR*>]ψq>XW䁊 9;y`()0ƃ18>:mS"s &{ًUGKhBbyxː7!~Gոc<;`JB/8^Wqwt*wX?OUu웽4VflOn4WBo#YʶW07=2_'Pxlk'q^,, Qn wL*\ ˎ@0PƒQ$PRVhQak"BٵjJ}?4La9Nui~ O*}XA ͵[V}|#{&J&>Geݞ :E؝_>Cm?XE\ʴ8 B US;{)74 F[lsUVzW=ʘ_ pCfA{IR yD ;ԅ? Q+G*st70{~qˬ2eGb܈шՆAH۫E;)]ҡ;uU~Yѧ*O@BjVok Ô*1Yr٘бVr۸6~RBmlբS6Oj—9=Zi%`rZ-C1dĠDwgXfu!ln=D E͸ 3lZtc>G/a OĊbCa.>Be9}2ΘkZM34Qnc!j-FR̟hn1.m㳵./)' J5Ga{>x3C/kR-l+2@jl\,g+|goy&@wNBvӀȰUKjꍲ,bi/mU'pF*+($kq%2sQ@,W_d&hΉI'5UzXZ|v=husҐj3H^M'c>s!+zA$[ |M.|6dRgy&HKO,z_[OJ-!GZsu_(ek-ut9dh zl,}^+bƕ<tL/*JapLUC n%84DE! G&Jg, 8^'Ǟnȟ5'}Tp+ W Jei{mUqV8,&:ǐ\mjqE_jc ?4a\Eқ%sgW;yg3*8}pf8w/` /P 1S~ GYhnkȍ@Rl6Jt4ToҐiEcF+QgLWG#s!!׮#tf*Hr&QDG*1^^{FTtW_:[]- t&dJ E06DׇA'uXt{ܘ]d|Hm$2Ys#q?'<}*R-MI <9ADT/~=K'/: gj\N&XrGdnA ~^Fj@oKt_l e 8qi:]i"_C6$s{QAVQ)IНmsІܷd|\` |TLQipAzn"^ xw~&ZݺФ\l5jatG,lrWct39]L1^L$5c-_Q\[SQUóU!3#(;1-D(;msD߳%ĭAԁ+bb2~-5o 5͎c㭞V;r~ká^%CQGRW"5"sJh'QVS4^5nNGagAقխ_v.l xZ)rC֛QK7D;8/Lںߣ`cx;#e/Rci`Y@5li rTwn<>Ps7MsS>t[ҥ 9bI~wG/3[a"lC"VK3cٍq;4 {YZ2ePj Ed|`ũzx#AXu-wlSe7S-:&EU+|/ee9eJkBHh}LFtƤD-7[VK3d/4A:\E5j#4s+eN|7Ht-V;/dj+sΌr?|ۧ@Q7WA8Z:Zmw; Rk=ee0,aq-0h^->(0T{R޷wRbfB9%*td{ZhOgBįÿ[ʧc.;>=$Rem5̀xg) qtZ*.4T"!gGbU_=6%e(b-*M,2'x[fZ+FU ^''a\|؂t7q+l TCA (aڦѹG%K$v'+r̮j2=QF {y5Y[D^g_pI7df5 2 ^1'F6+jŸ5ٹ^I2| 4?.G תN1-{k΀pk4M5x 0-IHbo0RsT*~BߎI[a]YrPǹGYLw:+<W\!PXq=#]/wPf.BdiFFvo̤Q`uy&EL0f (\>³".H+8֜r; !P"euQ w[d#^ʒHbc Af3AӔ(:;eo}pC]yؑtg?YoCԬҴ;"$Wx"{KldNAΕlQaOiF )9΢$doOiY}ܚf zxu x#y>nbCr/7T SN&c_A뷮_a<)T Ɵ6W،Ah`iDwjF,`CColuj5&xT|E9›8o >~zpLT=$Mh~W \dIkRlHd:Q\Bd|9; s;.ܺiv OQFL{i}ף14gU.*K&7pvy`USѨᤰ^wOOYBEp[QpG nWLm.Y\Ha^I;8o9{vϛ}룀UrP6!!{U.r$cUnY =*qc(^-R[ Z\8 %l?y' PkDT7.f9/8@v:_JgF2adCϩi^CO)odZ^|<mԛ3tXzp?& w^jNCe2Eʼn(8Ƕ<__1mcAv)? Zҳ>),Y4- ^kv0ڱLYpсLEIC}8ݗ+ TDjg+o>& >4@DF5gQVgΝԹw6MX܈'!AIu8"IjsCɒ4,-p2?3@sKqu\N ٲ[v G p:o-![C H t3l:sB֞$䋷3vE.DW'Nոdt:$\*HbO+Tas kǒlO'&$I n'[n_Ixp_:\ rEAw齊pfl%<)J5n~˧Q$IgХVi@̝I%hj[$o̗FPG*=67_ v i;|C8X4YqKywnr(iד[?g9_b2:zR\'OR W3Ò0Q6c38[߬=p\a{$&m.u8k W5)'nj 싵Y&OP~rvbq}wmEvIJ8xjA<sOG)'W񌒧ΓlG_-ttm"i!3~.ԑ4%lQS<?+B13+.7eNfZo2Ts2!ϟW+b>LsA 7…F0yv!CJ=&kh<ϔe̻SfXdw7"oz/OqQzF&ׯ.jf+]%8SX?H=yzEo?JO?\4+Kl_q%=vOEtXE[T_k"D?'#JP(n IVJoeWD]fA=|;Ieیnmygl|voׇ&g ';]g#O8?-bd)Ic|<*R$HXǒ5cr10Qٔj(z@7<^CfL 88uhiX0wXd&8# yvSSG<'qzD^ :ژ~f(a1X\H&\$DuauDDŒ-V/^y* kM. U} )Q~\T*2I>y`̎A)\7 A .76:9|0rv2c/kI4%ޑl0c{~o $Wy9#a2)"Q NL j?U N;Ar"T2Oi;5:Wqf畀k?uu F&XDk *jى@YwK I#~3=!~bk=ؽ^Es|]:zكo(KHqS)ONNR#"'1Äl!YS!)G?#TٷC C q驊߼dDsgT}Nj=~9.Ǩϳ4,:ܛ׏ζk3:RcbҎvyF`zoB 1&Z3Ɵ6w\9CHXƼ_'2XCi]D*(}6Uy̖Nҗ"zؙ)Yxp;7>2с;ÁA9۳! (ÉVLQWy^߲mDI`3z#g"A31:`GՆrӠ~vE=baK,nE藤k.vѕ+m)KQ ">>)7 gd~7_C,4§w \ϜճγG}sꩫ|!ANr&{X9VUH\HlR0m*k6e[ޱօ'{Oӳr w'Pr|n_ϸXk7jǏyB+'/So8,dW}-wrdT)fDcLDm܉e57 p׎ÆIGF,显[]}eRU%U /q7݋4jQlS0+:Hsj ` ]Ku%Ƀ jmo7JYA%@[Iuv{)c8ViCv5>.wSWKaTx/LbBN]\]J,F̺,UDi(Fֹk nJ% s*'n7 mj7#@u8yY5 (G-m m3Oܩ\*0 njb gqzV/sv)TsrH^nG_{*M?dG5!Ff5&2 nxChV=3kgeHf;D.u迭b ;OSXղ^E'Q? |Su%Aq<о7%(%ad3^HY-BsKY*IKHxzBFQZ갪N͊ST}QJEoa Ϛe(=(it0Qm栐Žu"QM29m̭w.49)^a,O5-kw 8C0躷 HssTvv:0l_^kZr8 JM%N4ϧP*-i:~bjb6yӾf@CoSЎ˟wOl#u? ş;7 A0:p h@m2@dKu+[[܁6{X yhŒ8gȏKG쥋 BⲚN?z ,_buT:b4JXSh}>d6Y>[`M17$-~y~]1gS˅]uS<|Z)b";J3a's,#N[)訮=ϝt=ĵmKi=T׎C؟n(V<ĈykxR2( v.Q LPiWmx6`BH9iv%iScy&lp,X®{>nLq(zh2DX <6ȱy\#b*lo VH@62h"o*@"ÔN0{;z7T_TϨ.H{O\]$͗j!wF*9)k!I[g@YTR8XQ9 +RiH#r&~JE>Uu~5ųY^:΍8[uǏQqgrPԇrƘU\~ ͧZokϏ.#[jBݪ&inpc)!%h@%ۑאnK.T/:dqLXG#&jkH;)=#0Wc3k;SghQ15rƽRxcU! y%+-oq1J zC\G_ 7ǕB_ȁQQ -w_nu;j, {QD◹&/9[0dj8 -F_ 0gLK4ig%f _D߅EyՖN<(ȔJHD(6fY2wKE .W{:,Sc}tkr<*F +1j`kTN4wb7XKDl*fDNӿ\}9+"$c2ŏ vI"QAñb5.< vEd]RA5 5G(1Zd=r<2 *nR\&!Urt#:-H"KNGu0yqY| ƭIGTf,?JX,2q/EDQt2Ta^7n2uivȸ->J1jӷ?ldZz~3ǔ Y1lzZ_|:q9ӄ&<̇&ם4d_;FdRz|{3l&mC:Vn4@mzypH UϑٝG8nf5!(=92f7JlQ%L lb<Ǣqc_ ؓ8ȲѬ8hXb5<p'' aߧDH߄< J7ڷC}9Dv<4'{g#9 VuP<7])u(? "NGˌ0UD8ځ\x~5qj%׀b>j{R-{i)-,,:j/zyj< n~\k/wO&G3_p8rEDM0n)d/MuxoZ&Ew][?#QagGjg)lJ5kM ս\dI 1!,|n֢]+D}Z9AkcD)6y jz_-~e)\4d zkCZ1ե.:)fgI)]͢.#{ >%$]J|:I7Cio2Yɇ:el rkR/.j%EiU71cNvp=B-4oאut' m.]aނWm=esƃ4xrrEi .0 7i9N~«Q$첚̻7*I"3i&l,b&E4`B(9\"[x4GgDNi+ؽu4Ͳ᧻e{"b(v \nCt*1&bsYE=ԊC"|g-.ekgxojm8@ris4]g雔},O~W:B4U>r{ԌuGF{|ڞ\K[srfYVz(R# HLvқd@;Mr/X6I7}M.:bRPN%|Ufk44ݞɗXhu7Q/2A獮*_M<cVglQZR s#yJ7{a(,dhw*&x]2xy<:F6#ܚ/'/'+iOKoa"Pk6!$VW\yϏ8A} 9*DF}HrHYa&%crlzPBg^P*V\ ouGJu 5}/ЪzW<9WC^vXenPB,E+a~j;a}jPi/a_Pp&Sqp'Æ38U7 _JG8;1gJ?.E kd%>N'ؤW5&~lȍFkQL XpkgٽIxw>i<2D6YST5c|#,v5`JR[zMi g#/AMƀ NiyYXB罬둵RXUI*9x>2; zY*@9\Rn cKWclTeD|d*zofOVd5>LZB=fi͓&H!9%%1j:iOD1)4cv$⊽gW_z&ZִwmAgIr;qt1PI[A=JX4!Ӧ;o*R? JjT޷Ȱ }?aN[ Ͳ'Zԝm48R3o%lJ/?vD33sSOuOCrP7)4_rgi+ ۉ) gϧ'3!S`%4z]ڑJ,b•-I>cQΌ$ZR3EOJq^?#dcR`kFȣ(E.[9obsTaS&N \'^yz|S2b(^Ytnii0kFɡfM+N]xb?9G qp݉{Y#&!!L{x.5!KQ;|bׄ Ct%O7UHH؂IbΞдIF[t BD@ZeWZD껼2d`ֽ-,S͎rMN;?]otNMSIWPb /x MWI.gB](a=۪Mȧo4>WIL]뗻f9Xt]]sfnq 14OߟX_ iQ ˆED|J4fs~wl L;V;9!FJ2:kRγWl{d/tN9C{OC=@rE~T㗐$^^Ώ;9$M=o}9?a+c͸hsm.E`)v˘^X.li 5TP1%Wh=rue;E ]: tQMo/GoyOzG@#gx-CDginP"Vch84Ws|bN0Ѯ ݷUjFic4'mHtrtՓ/SZBmœ.( [GQ|HXP+)uFfv|35ӷ fʰ`a!k 1* ;'PhD1 TzZ7l־(56 d I'S;Eb4W\8.xXUD0w?fdM`8;wb!em# 1DcgYq4m*"?r+>MScTRoRf jlc+hV;u"am}S=IJ:fR$QlX0h(WL@ؗyKwhsC xo~Xmq2plϒP#`$%~ 91t*mB bPɋ}Q~S1,v a(ٷ^!T/]@ނ)VӶn륭y)j3e!ss;燥c=tAJlsq/(BےĆrT)0ZU>~ldV8sCd44%E;H ] 5? ` ym`)\g ~54!\ z3#VtÔ F*7gIڄ|Q-klENj_԰@ɢ 9k d_Gsu7i81QQlgIJ:ѢRk}=# \(Z/W xosYV}zqW+ 68CnvyG٣+G,H6ʉQZMK$?4Wvh6B + UP4<:EM%e Y҄cMrR:cRu߫8+:$v P/xwsN/Wǂ014gϛt;KMiK 2nSnC)ᷢ9#x%+0 ۳vkJ盖͸V `)Xw)΢ӘM"K&ư>#ն/⨝s1 NK\:یNPeb$؈za"Ku@sro:M1GUYW;hD*Xn^GSqNȲF\Tu?ٙ~̖tB]{±/ .zVk3 #VCF}&&vYdq!w㦸;t s-aD#mfY=q-OiyiU.#i6'$1FK_Z+MF3Ӑz^=`[v:XJו w;T(^lݎ~&Q]lp=?'H_]TU [bRh}8F2= utiCa> Sh98>)OXc))@Zx uҝ4}vTkpǸtSX}J be:ag̕,0q_R l޲3ݐ`};7) [wy乭ToB}Ï:%L }/l,Rơ{r:l UւWqlmj&%JVgc:]cB3'dh4{rD:Ą"pV"p,U:c⦈FG!e!"z;Uzة{]͙X:ppN2f(K= :%nD2ty\,;L_ geT֦H˦ɺ[0*: KĴuJlKPHY-;^/JC7Q-8k7D'Tѡ-qlI klØ:cS"V _] D 5,=~Տی&?.X$hBZ^Zg$_<)^mssx8F]uǦNYA=P HϜ4w79o3ڸ7e$5o Y'TGP%#qHA|K<A_a OBns5--Qy+k_Qs c聱!!kxz+;{*8W2I^O[t>93OXaCv~) Yb%gƁۉG#ԚAd=<6|3K$qYJ0[ySr)we-8 jJQ>oRIu$ PJm|BHf6F\W(/ ZA?]kf>WvS ML+1lH' g1*(t) qI=U&f֚>O瘑q 60UQ/уs^c&GC@ Z^Ҳǥ]h{ᢓvdmJlۯi ף!UIȕ\}WCPJ2i/"q,⮚\U;Y &4g;!9'e!֣Wy4r|El2cJ?!Yf"N}rCZĄǶA,_@"搘x>[|gO^ |G)U $Ich !s hQ q }%xo] R=*g1UM+Lw q$8[Z^4j< @S1&Si"wX? .ܒNOoq^)K k6Iۗ6c3)z31(n,9Dmul΅.e.C"H"L} 2Ji i6pcd:Q4 ^j¥QQ[Me/o͈hyZkGl25aZ_S֊ь[2_+67کP]JZ'_g=O$KDz8nVA`cŏ_X!pmNT$;w: W 4`!6C0IC 퇄$ycI}.zѾ* 7Lqr*=Jx9BtD'7Oʼ5OMTrk[|wȰe5g8`&uS1 E TYS[CF?2~fFJ/v`2t 0t]*Wup~-\<ד!ٜ߹*ϜU Q%||gƆowz;3(OL(K [ۄځ}=:  鰪?P_Z6-lO# >op_7r3ۛa>]_v/ˀʱȑ2b2W99/5AفȂl'0,:DӴ\{6ӆ2r)&@rTY/rBJkmo!Vc6̀GUdS=h=Top~chҸ ?8W;(̯!5pMb-ľѮV+pCenzbœB*8d9/ř=2>XQM3荁ed$0"o8;2y}1jH#{Φ5Z@N` gXKآqsoa}!^d77PwlFx\Йml`ICgϽ;ڬ)!,M& Ƒq|De OB YUm`BLeSjћZjPW'ɼ{|feeg#2De9^ZX dJK#U6CKcT0OcV {=fC2a(޼t=,d ,"ix/#D.l:.$ EF(GI#^Y݄>w >+VZ!7S*u`Nj⡛3Wuh߾(0g]0Яkd@QyS(:vLgB'aT2ᐃS&t~aihe\ȁkC^3 >HOGoRj.*}t{2jj0'y'CU9}?Β[U|S(X/x)c-ņ2o0Pf6Y=ڱIWR?DVt/ْ0C8hn ?Ӏ=H)l)/2L\=U Tsտ8P/}[l*Nc#K[#hftjp#/c}Oڭ[TWxLMKu^ջ#yHG`yqKQ5hPBze O]a&M7;m> SJ:Jx^Pr0I^\^*3PSZJa ׋i]7dMUk&j!ɑ,x=$tUc뇃x5}ym^3-Rcʾz3S3[t6ggVpۛv]^uF/Z9%TT_cf1Dl"\,FHs,[ r]&Ka~pQÎё2,ym r~Gi#z#/ @1X/^{\EOƷiRC4NjߐpR*lbgF)m4*n |zWB%XTWPJ οڗ:͘}3p`W!oIݸ%z0,:]:Wz\?bfҾ/("1e,L~~)д'Vew ud)_Gv$SO,H DKE*ήRz䟏OSɂ)7Ff,L_݇(MگS6`l|-a嵤 n\V7@ &mE>Z%MʧxqemJ.hɌjQ[AKJMi[vjWycH @Ejϸ}\csfuÛLm\0jIbPő zvY[7*2CR.D\ngt\DM0#d:E7m ^*iMZҾo3P$']o1@ڹ,k`1\YpXڭ, V`a"@[c.>N<# i@,J7a4EwltCoF Zd*F}fbqf3D('O3HKů/+MR}vyjY;\IʼnO[fB* I{VX5 aʟ0DЗ(Kn.AN6ۨZ>qk'^7IpKǶ:^8/10)L)j/ <9dGbs|4k~5*s &2А嗃hEf\9:[r ,TDW 2³ l8Edٝd nƁvauaKt.U dvpyO$gS¦L|Bgl?uEcJL~:[ yL t~|^ Fz0~<( bޘ\5%գ>mlvLXX~cKZ] CP1g!12vQ_y ^Hbi"Pf:H h#j:[.Z7.M5 fQ9G2$窑ܸ< &cF[|TՐoSn{v/ꂵ6uܕvڼ JI`UY&`AyI9Z>meX`5)phpTؓv5kkc*m%t2%sӍfkO±N ulͤ@PW̛ Jv'<Z*I:"ݠZyFHi i onͶz"7y2QCiA܃hnUzU9Qc|+0#^7׍HVѸҍq1~$đqwuSVإQ.IKCs?w[7R'Rx0 %zf1.T[)b9Myn>J?3ǧ%_FQe;~L԰-6`q6ƜD*?&.u~Q-ʆ~aN=h7\#6q^fͯ~TB4H #eg W{샌"*㭯CYE^"\grڝw ӹ`nF(nnM j6ۂH mxK $;X^% "<%>$X-"pTv0TMͨstzb%[I|OyKY@#\3B/HAu$X@ɑx^Q0$Kg4ڵ}l.Ս(]iÁ <:~]f4I'ݷ8rJ+ɴ)>8_pt,rUȁL }}0_@j y(58z(}Fb1z2R7Ӛkُ}E=Kze .f~9) x1>>iPLlkKORTݳy=\)M#PXe< &1J}DVl /25 M [ HTld/957wfu8hkf[L4?"s`L,4CKFVyqgS]e3݀:L̨_ >~ h(MؽZg  e;>||l}K/crcl"Qd$~Rz+*QD/ u^y0TB#f-훆}yW7; iZ =,7ʬWJ +8bFɍbI %lPUoKkݭXo)*l撢Qͻ>tcIF hJ!ۿu)w.XD7Ru_B! ~I3}E),Oմ J '.i .R3ŭDuOǩKqho n;;d=Axl#R:ӥZV$`c%V{w[<:#}s^GaRF  - L|Q8TMEO@[tޥ1TQU(bEb*q NڠZ$6f^V\'1zph=?uE&ZHUYxTgRo>}cFzDs)|zuo趗к;"e2ΟvWp->=Pc=*}y*wowZ4E (чɃ R [C*{嫆1+R0~Р@w7w/ si # BD@ɻ?%o%Zdu 3LJ46G[}'JV$Cw0E7%rR=X+4 2n.L4vUg /w!gU .,#GK]$ r;V%_Gj%NAI!tԈͫ3x4U-O|X%D l#ǫL]/]8Ծg2&^FxK ڮu Ol!Ru4Tݹ|,d 38>MnAy[W{c#rk\b;T}8^9Z1(GCד(+^WWr aeXI1y) )֐ 4E!M4 #*9jOú8VXGڔC+:< xri ue:Iq`Aچt >ߪW>©GBW (}./K 'L_Y6\Tzn[x^͜ ywY8KFLBQڄWKHΫI35*W(2Ajڞ%kצ҉]ڄ<ψ\ <{Y]H[l 8d@J!|W5;C8X.Rjk."n;5 3`6X;Vcج5u94M؞y[HHTec||ʩc Ka7;Fv,c*{8i-2cȝÒ 7` IZ4nAY/Rjd3m]? {>8԰0Dhǧ$<%VɰS r̒ݘgTIsjQcz!w^=iHgu8YD@2/tLnP,h wOjl"-7W&3!llyg)};p%Aq~=hl~7mך6aV|ͷm6n/9u}oؾTIBZ O}u VT0IVD* &OsS&v.w) 4LzC t{Cԗތjۦc!+d`Uڪ{!B[}n.z@3iɢ}׸\ƀ %Q+ bu2q5'?QY7zYշۡ`oWXw{My.PPJ%(:7)p F2dѻ,1_th1K00 H F/ $ @"/ൔ-F}Vity8 /KUXbiU $DV9V߸>YI8nOm]^Bw'^I ,kVLp,,(SD#짭.Kۦ77kvx{t>X%=3u:WJRӟ Bhm]tA#?ӴTV>&v86 :X7@jbRsɱ~][VTef'Ɠ28XzTof|"St.]#OVƦw1*DW^*% t7ڙxܯQpG*V.. w%6'Ω,*;pyzn{#c&!cSq둖r E-,^ZVk؃ O Y&,0vIIǩDdžJMIDH,w-\$a$[5^1V H}FKy*QWeʳ' rf'E`d7)`5 w}ϚocF̤oCVɱ]ɲiFzsӼvVb^6I;6LI+ۣu'Y2SM/u}D$b:dҕH"hRS2)5C״Tμ œNI)y3h`%$}=oF >txOĪZ?TOb(\u4~t?um?S*qgn:<_DiGg {ћޭ@Kؑ`ה +wҙ0sM6 wagD~o˘QdgK"ɔ\yh*bdSuףV24ua0> `4Jv^$7g۝iN}>$v1A=5h+ 5g ,Օt%HbfԨ( @}A϶) DTN(!99r{woy!L(W oXINu,fb OX9e5_E ۙ0KΚ3Fd滁,8zk> vpz1N R8hI sg[ #jX pe|Ɏ`:~*ACd 7~&_߈:cK2Ƃ=@̜4$ٳ%IN^*|[$=dY=Po!7-ULfnLW3ϰCއXCE dB$\WER,؈{g,v_Yn5~5O d%2wP 8ѳTDG(CD%+tz,MPIbD;c] #G-Z%sg%js5/"MOZϖОYe#W-Fewp}qx~“*l>bl 3ϧhv".p mo{=L)DwCbO qXߝ3G$E8D %: @Hv[/,Mղ-z[ ^j_WL4 >5~z%fU^҃.(dN<63\O? OTU}Ed-%e*@ /wȣ= A5(?dkAq Eo\`w+6wK,<غP$5Cn,2gn`T]iX u7Йg@N:b rF]i^2V}V i|bCuF+}Kk x]4[]X S,},Α\K]bqN OR㟥n$+$*0\.997('}\L5ٙlmS7_Ÿ^t&.aj^4|n% *M)C_ 8j}T),u&_65 tb24BY0F'?BN #C#jXR#rM5PBI83n2Hd 3*+Ud𼛫,T\TO֮*Xer^~iHAdƓiU9Uo<siD*cUƞ( 5ww.Sa,<"E'kkh @}ENUgAIgn^|\2vVlxZH*m.UBLH~~B{p/t/08XĶOnYdtGx, 7ՑVy7VB8B OSMaΛ:,>Ue~숃ϻD飘 F3ھ_)qd$O^RWHUrSU }S^ .~qJ5p:"ϲ:}6|+ܖ{z_p"4X 1  `\+2PH}g!8>DF3* +'U($u?U4ɓj!+G22"rzK4 ƜQ뾣G'vM 1` _'@ۜW'?iO+7^{S8Z-ozh;}~&~d /3U[<<'zڛF/&} G qf<Xj7NUgQw5h$]S~Tj09;~N;ޭ6QqT޼O $oaQ --~Pao'rK gwc9(, dOJhcv#Sm8VLέ(A@?^tmN/4w g1򾀯Ō,gVQdr>$'m.^^K~ 䱚A=U?zd  ӱe}T'7?.$! b8ubjN~dģR0!)qkP<7I(!Vz+7k j- Q`R<+:?52ɢV5cߦ cx\;68 2tI"OgǚpҢQ~isW9}LMh>1ufqNS%dͱċ(>y7(xXK'nv\)jfW_a-1/S?gG/ XC} 78gI9G{G4;v(/%vēDjB罂eCD5rYBx$[CCdv"H{$Ĉ24GP H Y3IZ{)LSmAщ؄'TGג?#}>7>qUY#]b·nh{y% Ooz+l$W{ G[בgB57z0'؍ϬHW#fNKc#.:G")%@l/ $DvfÑܗO8_D$B? Í+!+lR<䇪}{AA$.U,eIIveoRdB_J^OC%͖~A!{T {mh#SZ2^u`5ȪlYY_fYQ1|M.!4<Fh7 b#Ts+Cb :˱tt-nAwu>G=g1%}Yj-ͯ IB"{By'_TMW'~"x eEM҃ ͔t5T*z>f {`QW ¹ʔ+D%qI7vYWq8C%= ۤ9uoa?gr,KiS|!CeF2iW⹆j%- M3;G&O{ eAGQƳ7e2yrg>%ԥ!ry"PDS Uԓ,;Ճy_.i0B/)uU^E'U 9 Ou bч?$zCS]9jʹѿ W[7LHߟ?ev5oah#*E(W)n4L@tmI6 M3vdJ(fߍwAhħFg\]froLsZ~P:&w7)aQˊ<0$]V1H-Zn w%AtU/).nKpoe*HRr֣ >!rȐ-Uu1Y;/ n6cҫKIgO% "{o7c?s%"<|CN譩)Z)VH)fg?T4ŋiim9Dς DoH` DsZa|C/(f^ss*bļu/[X^` As纻~{yrlº+[Ҳ }Cз<60Ո V3 9CV> ˰1dKJBSs' 6Dj5l l}Yi?c~ q׿k^ }p4HųkG] ZvõvK;Kg 6iD:zoj_̉e tN-)}A1#@ű6MwWoSW<c%7Xb8 ǡ] 6>?eDsxNaSe¾?<]GW]:k C(Lu'A* 2.3+rC5.K̛3d$ClkDUD5$?j~ +FOz Fi _QX QmkISQꪫ rL{+>(3rN,-5;5߯Hԫ2n^K"([}lJvu1'~ɪbe7:lí搜L{P2Ypȧ&YNv,'_m.kk~[3ɄzGQ>B@ ̓lOc)9gnIGw4!rHJT?t qsz@S>Z}1Aʶ{C!Қ+] $I'lgL8L줊^^ u?tu(LNpa+E2{_3B ϭ_@ȹ]mJgg\HON"K/yݖC'56?6v)|Z `-ҏzCM mWzS"+cZrUxt`mY͆GP"~%hjig`MM=VoUtatC:-7@8^a*477&<(۩źH9Z 8m^iuks \ oJs:SwnG=bICto+ dBsQm. y<'Lܲ'je5(QX3fiZ|0yAXN'aSs lwJL:a)}o4R6 :-=Pt٠ӂjiߓUj}̾|Ӣ5"c-W,LF6YwF-$U[eYىsM6UhKz}Le0׆P̊ɟө܆@ { :֡*,Y,4"k|"j-=r6<@M#,)*f"e%4u6˥]]Zr`5ѩzH~sWswz7BA7]V{X~>bIzFޥR},:ͥ1LRTWi] c4v{]l iA b 8%$jwgy}8/Yc+ZRT[ԘSLHI}c{ml$9/r%Ve DCCEjeqTkLIQ C43NZ%q`:\[K+sNϪׇ\'u@^d]!Le(OHx*VT?g4V(4я0סPӫ96Zbjlz 7* Z۴0bI&\FKmvRn%aAFFV&7@X!xi+·# i%w P Vdk75ws4`-4QFHtEҊB>M[Z!UpQ7&bGC|n֥κϪ_YkYs N1Gs)ÑAf q`"VLY39%Waiy";5c [ xiUs[z/-gpC36(^b +òl+Xz}@}&8O*UZ{."ҁzYS,{ăW16+xXG$gj% !?yZ%~ڦKo]A.u1q6TLN|SDyEf&ͱ荈_V  u Ǽ,'bK> [T(K#Tj4 8 Pۑ6:RVYex  qʦ+ת h!sl|\9ϲ1c`E@ѺLBxK"rͿmlЬ#7k3g2Od+E͓8w0ELiבR4G+*]DsK)V,XxqtH9:Rowaj`udOSq==kWj;YlF=L-9,*u_@$\M}.xLv . {'_nQ3$ ax D]y k] ueeI7M h|W8z^)N1Z{ mTOzo"lsR0wT]jːhdT_7kמ#ojl6a!)hXXȮ,urSCGY!3"C{/$9-2 ӟ7/S ^ԓg8TJR 2MzzdŊHrt}^3T7N+7RO*:v:]Fⷊ0G-Oȴ`C;æ\j4ƫUӼd,N~d tj4Z}oK0yGH. uPr:5"v]F؝z*L*i`b&cyj+iSa; :O:܅^!'T@i. +_*#}^|ښ54$yQvdyG/p=iZVi>ꚨPL:5_* Y5u7 ^Vش_<-^kH3A5.Z d4KaG`̬f3J78\YY}ZHq>Y YEqщIKFApF;U|%#XQhL+`9rG{cYU1 |w8MwGDD9կj;1qřDhRw KBZw^TW5۩wحJ@K1? iآy" ޟ٦]+,>uhX[eJEDduR4A$)ms^vqmUk-J8G@6Pt\T% }hj]φzՕ֚`5"6//yL,./.aNG4`Jn48f/mxy.Xv.x+qt+1ԑŤ*ًPhfGFPYђ'hi0tfrׅo)S$4C8L!)Ʌ6^kG]j#kפ6S$bsilFo49uĺ2/E*\]k+߼Bq^՞L0FqK! 1E2`jYcz/k_#t+nWn/ fmyKBd]K[ 5],T ",L˨se) *%h䵙-1,Ŕ1gD@0=]AC{&T+pU1Z`Ed98+UŬw$,R)S6w{ML̈w,MM/$5RbJEg G Pl)p +JH!R]5Bˢ4r%`^G&*N#@^( rٴ98Nj}sM w; 9 (NNx` z޼^(s6 = iP</TF\3%P{(jo [c+c?\~qz}5[`lj}XuϜ #u^ԗQ}׷l9AO%W 9;&'G3l{uD W2]/ [/HӬY!*HԃPZ+VӨ0 Xq+Yۓ$z̲(MHH#Up[;'@r9]Е֚Z>;mΐ,usBdѭb9~XF%؎(yȤuڨIn/#%Vyǵ J(QY;Q+,Vge5{/bE%+_F = N*"3!m}h|u76 :,Yg76ѿ4ܵda$/kˬuTD:,d޺.W_>JAXWjyjZb#&) }oç3m ]PR^4<|D i2yV%jJNDu߬` 5Ŕ4!rzb!d{Ls Mͨϩ1" fX-Ka`e'S Vݦ dsD c]fd*th5_щ nR}Љe  J꾎YF7ʣlڎfӕx.vLu dy@9'c! BdY<2MA'Кr ~L+-xI.vjwa4NHLG_ EXrhU0Ħ 60boI5 c,Hbp sjH='tF_W|}=וtʻ}44W1R5rL H"tv(r+ŀF66bj@6,,9CL #=I0B?zOs=)[9qm-ٳ_ V:ČC;nGS-vw0#$Ҕ_^y)Y}% =Q:GAcȀfQ}0r06U#IrOU[lԻ\%IST_U~ \k|U 9>_|rqJ)::@7p ''bKF[D0?Sx:tuDM/1o'zQ沏 )%oM~Gڏ?HDABƽI_Tca-E7/Gdx刿hZ$Յ:ua5]szםt$0#86yb꙼Ec_GLB+@Hwmpc;7C3:¼i@G' 0980{kYkezn򾍵&+-Rr܇UFW1H&aSC'A/mH(s vﻷkb>I(na`EALbR47Pj醅@42# {DFT|M~L>/ tp(Դs٢J\ciT2XTRKu?.SWpNNVѻ3O=Yէe`0;2%@gõk=̱J]~d%m^Xڢ{䕜L+rƖbŰuЧpJζWzZ%Yӆ" oAq\aL3i)bj>;?`ٞnsZl' (qa4e/֭f˼Cm2q&M9@ p@l!O)`sd%X^=Cm5R e,5y՝Y\X̧=i;{#&^kZ5Hg4q 3Ag(rj{H^A #*)o~W!8(n@wO 5Xďk&S EMQU tF$cζ.05*P +#g_F/K|53aY0.Rd\|dXr;6q|~bhYpPԾz{j~PgtiB-,Z$/XFcd)֪-g)$Z0x Uisi+n`G0"_ksk{"DR?UAkMe -ww0PI)>[M6r  Q~㼷q?}0^k`3P) 2 g"M;"vl,?'wu$/J=Z<j ؈0%oeek[߻OAWҎU\4^G0 dF"|f:I)[*rj nΝ5?'``s9|zF`8dž;Qx|n!&9Fs3=Ѩ=AFP{?*X#)"cL蚩n".)PƑ@L |墴tKʩ!ĞwUoj`%9?FYO5}৽~D𧸧`xd1ŏ7[*{p15XCo̙)u缽yX{v= p[>-+.9z<]Qá0Cd 3oR]/R|QCЪGvjA߿y`d av}Ѕ,]8k='lyO3 ӤJEР^dБ !kgn.-ۍ_\LO7n SC a@?t5rv\cU0|YSsUʿƩ'qpI8'?]~/#DCDPMՊ^?gKL9Wy b~ECPz-1Ҷl"ۑ`6/`ěW~: Q)k̇#m|BнG*&!)d?[D@]*;GLR^Yu 2fPn(A)d—<1nCZ~RGF0Am1f y/M~í#V@߁YHTgդLV"d/ajħAIj7(xgc1.fJf#VKvǩ%Tw) *Qz~H8:9LOl\<&,'-Ea1lvWL΢IIz:wc +n+6]TiQLBlL~yR>Ҭ JyI7}e`6et8C SKD5FSV;ba. gPSJ#,m P ~(va '])ָ'YĽjp؟oZ'L(a Y$内r1=iC'FOv TM0HÌu+mm 6yt8gKrhS e9t%@vqEnBNH3¾JUnÕy׈/UE,LSqvYT \dASڵXʻp <}M"Ԓ)YMse#DQ+)?0bB@xADD]g.sJ؇7ƀf !MO>o_\yОju Iwl?9YN&0M+V+b@ԦhxfzzVQv<Ʈх"nJYuFeJBm2,TQolǴ 4^M)Y/g)\4MDԿÑ0OI uu .@0} J%޷|77 moj} `fZjS5 58_ٕbMAh4B$Tʼn7@B\GQ m(ޏd*ULjMǧsqyBf1_|4:vJMBt<;}uB!^>3!ױwFJpUvG/lgG HPH!j2< Uկ TM{O&'( G@nHSY-[#"*)[|lU z'%;GīЦdP*` !7Ǧ|cqp:qnڄa,I9WUg_?Clu}M095}'x:+= $C\,>ԛ{zƑtD\o{x9,G|HMNH9!@oC퇝<ن5Nj# ;*vPW}TkˍcL$EDwPj?:+k/bn%FE_ӱVtwW௛aXA"f =!Q,P8[f;j΁ۆst+k( vNWV^ /vA/6xVԎ*P\䰰馎O,=u4tm>w|~(Nl$/b[oO^yOJ?䐚|;yPI광 /ictf<" bw^e141[bDm٭uIH_jLZ^ M+xi㔕:M/1ox]І+աǫs6/Wu7@ ?7bk8R3ѩ#\$-`_0MgW?ГX4-d\kOXN]ڹ ?@K]D(X (z'S|b 7Q^|k?Zb@!(rP|eUiEPEX1]Ÿ1}d3cp^S72LF(;Y?U+hu ls lmLKo@);}`NbMXQp Yz}P~lY+m, Kk ,dCv>IJMGe? J𧻓mn,7~SN`MOq>o, ~yygwN1 Iw#XQ# &H8[bĈ>kb[ųy6Eb̂ eH@0K^=A6K @5ʽ7?Hs{Q-~gسǔ }qct"O.:gi.&%^'뿮kM/hm125×(D wiloWí` > Iq|H:mtC.~C!˳vUC_6sچ<[1"p8 /RoD ⯙} |[RɣӅщ i+LЭ2ъ3A9^a#%hr-Z)&O@-O]}G/•<.yAhM5"x"b"P7Y;/tUWaQ)lW&u&0dBuMk'TٹoKG^z?;SE;!Pwyvu6ό-sRET O=7ŊFhqVqCv-ճ60z;/awkM%}jKs=#/evghƎ/m\HPAK1 !^ʴdbb7v~^[r8PϫP2̐U{ _:k<=rMW YAѰçE]a+L-·Nx\aOmG,rb;yo_3x5x,N ĵG܉V+@OKQQqroS-T?S" B|9g.+-%DZy I _36E'3SD#G]En8W[My? Oq?=w]/V\ޠ_)t\TrhdȆmf"Kyk\$~x'|'@\/P8":Ǿ2cR^; ːl,]'略~JFߍ/sHlNs%tjzz?Pނ 2-3^i[gdYq0avTwm*9_ceM"t}?ny&spҦw_E|2J<|HPSW vRt~IĖP~EAy*TL.t(AJBT_ KtV6ŘIk|"jG:z؟rHfLŭq$8rSZl"qǧ ?nlF<ʀiF+&y>MnOr_h+U[$o61FWH1&.k-zNqdk5B#;F3COf$hsTfwYv d`uo-Mk|㱪sEڕ%|(9a=M͑O2 g o+*cn~ѐCi6k0Ibt֓"l%4bu U1qߤSq!p FIU9To{S{S_Fcxʇr)#<}È۝G!S:GLxxZ JC:(?$;x&ך_abl%W"0T|<'aT\Ԍ = 9\B3:xIb?<5g落α)<2^xmmP{ٛ0!so̲S}o2C UD-lrBM{ xj2q6y:Gx(  v*$!ĹՒ›Ay+W;_æːrP4Wfln!Y.(S<ŀZ~ZUak`nƍҒNw|q3Dɣ sMq9!Q+IC_EwRBߺvq=]<æ",gOJ+' # ꤺ ^6CuٲbWP]qzhO.2Md(Y=6>A{pF r@u k\ cX%}?ELRm\=!^lBgo-6exeIijNLu/U\ՁK!ݻ3^iM1kv.[ݾK) < !$9a,V_Z" y#e])+lΝ#Fň(zE@2oM7`^ @B)f4h8Tx*l3X\#q92,:Po?OnƤVwcemuR,=ݣR-IgQ u{6</06$+9rD11$JFšk Q&SJ. VE߭M2Ŗj@*\u0$]ZK-\ O4ap92pI|d%VrQb;3/=2wPK@WKz.]5ZG&ڤ]Il &S0#q1`ZDh-ӝVMHE,Bߏ'2߽b2!J+_Eٔv`M Aj<| zk'- \J= OdzD\LQ?!'( G̨ݴGaD@yӤ62=':*l \ kp>sRU{gʬg"r` P$#*K'jvB[pd۫[EGKkjlZjh.A9;R1 SFtO%*u%.-%xGZI sbAm'blѐ ]ф7fJAו 11v?,mA&f$rW B91'o݊i)L8-0d𚈡q"qǕsMjͳC{+0K-*"^e.wk]\jQi,"ŞGRhFBR6Q9Z6ۨQmZR7h~ xk1 ϫYS{K4ۣ>YVcgShɧDNt/={j>#5LJ@IUúLV܅|lN˜yX{;J[I #r1l)8z%4(\?C8FeD%z5㈷9 *Y]kk9Tqno._F6D希W+W<~S "docry=-ܞɚx/.ֱUOre_䘃ay =D SGMUIJqrq$85K{1m,ړYNd.itPGЦ=E!$8pFO2zZc&ccRP6𦋗y6 Hߍ])€+,k$ǪfTԤ3͢w8jx!ڥNXLrC85`,S䡏:Oub{uZ> z!ЧAXH2>7v.t_oSN$漌5tڦ{~p}KּsϋLpe61 D63⛶Hjrɚl3M%R!5>2j&? kEO3"l27|h)Lx5T!Wp]oq"{3ԅ$>yqT2DD ZIqfh'vᔵ0K=$o_ %^0G@9GGeQ oo^K>r oCY6sHC 2ůpc1kF[@Zx`)ùFWEm=-w#ѳ[U<+ݤwBfXh]su~S:ʭF gfEIxi .E6ܔPp @0x5ɃTy:g[koj=LBI?w//77d1܂ [OZC{ =یhl5j=q.ZjݽؒbH$x^XnLBٌ껇n+7$1p(^)*8-]f=C'G&.!լH溤BͼEK=ۅf@XM&S])!|˚VRpH0}}nާ7}_5 0lh٥)4}yrSGwޕyHYbdz*5&az:w=i%>V >mtDm~"EaOy@&{۲f|޻8y0"(ȑAem4 Ȑ[ԩ1+k&yDeleb{8z`k%&n+X>8unc}+Yf^-ERA+5<6e;A@I@cOLfMc>bPAđWDdvNwE!Lnpe'` (į9=\,ʍP-~+ !oa&ߨ!<$Äx sSjJBo#@#5!GS͚%ŽFpL՞6՛.":RRohgJ;D0*sp.DQT(Xߎ* p@e2" tivf5iHj" z:&֪:Aq*ji$S“۫z]iڜy)m` x|ˉTp4~4H+O23 }<8mk;lj^ ~'#j Yn4"~ŒS$.:}M}GQ2+|M!!/}pH+Qn;ԟّ8A(. &O`ZϛXs2LNi#CLMp^@B8΀fIWi nӍiC\r^@H9 ec)r:2`?!rI]/,ګ ֲu\~ _;rڐ6]&mmHk1#l2n(]ô2JQqh6<|Z-RwǣgWƓo2՗lāu~[Rӓ۠ڼ TC} 4eK~70l&emcvpEDHCm|p\Sn5Wm^sZ}HC3 CU}xxXpG׮f'Zo3*ݗpTCNH%E "0Т,/(x} *쑬 !q9 S_^&? BD A#+R_ގv8Ts~f!WeR 'Lyid?n3S}B &8kj%> b͵\wW{ oȓ8+3Hmnin8!ٯ'nF")!W/ߩ<@1Vn"VwNnFlsG6ֵ,0 G!hk?Voz fג;g<_/(xI%?&bVvLY f!qS(n) THH!vMVo\ݖ|`4ԝx>D+๊ovj ϜǍytj 2}%7z]}<{S`fkJ[+77;nHH`?= %VN[Pt\@:9pgs39L.dY?DyׇxiH%^}yT**#j<J. 5p͋Ç=5p]n׷,_xCϬzoK W-*"hD 1CcD);M7/ƈO_q"Qwe :S iZ6?(XX^# ٟMf6b I-6B&,s "DJQ++yفnqrbʂbkuk /MUpR /Yxb G&bIn$ͻgմNcJ4̉T*;ULh=cGG! nzѽD:*~OZo< dX`+[u_ihi.4BĐBȜq aг!͝=sy!>0R;r7- #Ixa^>2b؅z6Τ_ ;Ue)UsޜC6U,Lk9V!G,QN䶯yHzja1[(dx){!k'lg[+Tr9x 짫#Rs@ڨ|`UV} g^* +`?'ڧ >dz)G;E%lSA+ǎ?? BB8~і1NjBc\3TomD&6Dɤ\frOM4UҼ"dɉ&_w[H }~ot( #,: *;W{Y1rdnEKu(C Oڱ9Eݎ[>=˅S|M.8׉%B_a#{)<`RdhlZ >nI^OPsț;b0\3V#+MИ>n<PkF$Gܴ@B 3pA%DSt!MɕS{cI[N5'n(ևf4F [6YǐO*rQ0[2yHaDO]3"j %敍2Ej~_CyI3o1 7{1@ o`hlE@E`ULި~hބ2z#d ŭCdl`J1ܦqKHgʏPYJ{Z3[Iiםֹ!zb]n<@q% N1R_+Wgw,.j;}ђ ; LhJH:fD0r> "2g`,?su\=,(C,yh{ :",ڨb(cCy !b* m[s5'e$L MN7x!?}I .];cdF9 *S*Ξ="d+K/Hay3¯O3(̮0F+Aa"_O35X="$2(+K!j%>|͇"NZ qAUP{t& 9x\5V]TpiQV@3o^Y4M)r}iƸ@q/30@<{!v.c 'at-bZ_\YES1@㭮a`0v*J| ;!YyrlhpӫX%I=GJޯ`)OʻMF3]3DƗw]]*YR$ƭ Bǘ_ȑu\S߳+cA!VJP7bI2y/(8NqaI)Cr{Z !E;4ߚ)kwXج4뢢ry]}B@!m}DtHќhϞt*g10r->1QoVn–jϓCQdO*:D"wSsP -+!eI 7B.割9wB0%2[s$&ԑ,jSKwZ-JWR _Zmop<V-*Z)ae0̆&`Ɩ *pjF aD-p$a)'/ceĈ$cPbS:}O7*m,CӰ.@ mO[9ǘSԄL 3ΛL-Es&o]]:t LsCj׻ "`V"B:i+n 1L,3Kރ~W@}PٺW0FV4֏D#LuK(]00_+PD@JSL /_ýX^`JNy3zVz_W0M hZ0Ved$C/AØ7g Ϛ[lt3&1p32/w6:{w6HWVwFNKk[x P^Ѥ\&z s5nPVasZ<z1yE\)qHG/E-& Cs0^xd}rSs4ߛ!c jc&90Pk@P S$e''9YS0SyvJG`ꃒ_0 3{"k1BGlU~9 pl:|;-kLHN?,4ݚMkΝ%\M3\XCaic\Yç<猒 8"#t}FL>*xyQk` w=׭k4hp@Z{Ib-P5N LPЭ9.U zuXgRSHco7Q$hM/Q ȈwyXqGRp( jD ;ar%KmsbLL1x `ޑb|`FrUb|.)'|~;9SEJǵN գlװ*ͤ܃Рή3».fF3)vA+OVVis~Nˆ[~p5КPSL݂ouTyv!1  10 oa_ `5Jܠr^®T9YgWJ<B|⇞9 Fs޳$*_ÓL&I 4x$"_BK;ma3v`> KGȍÓlCܱ]{<[dI-)IA$. dn0,jGk>K<gLtH+1N<{L\н+/Lbr~n˯~wj>3HQR䠩|n:j+.sR=e"6˲=))=|LQ ?{X:9Q+g̓ 4r/Z|IP%\4v-1d"xi`l:z3mo1tDryd94=VK馮QfyG]tS'>.HZ!^&GeUe)b>1G¦cs~o\ Lu#*ݗg8wַ:GGG(ۜKDZ?rsC$!{rucc] ^7J{!QbgJh'yoDUf$n h3:${< nEh|?lLhTL>a"0'p?7W 4ֽiK/̴sLa9p7AdɐJ}155 8GZzhtu0VGv!y3PrAt=,+c!nOXݡt+:h PN%*9}/~JlctW";O&.B5&80@!]N[;a='>8 _WuJ:\4U3Ui.7 .mR†ƒ%M*7^>Ta4&nnd? RuJ?sG6!< BHꢮ<'M|g)gyjt8zj!ȼI=3::R{$i(d慭|'Qyml }D"ΒmviQn.Ltb8DZ*dgU!Y=\+ ީ#.gٗZ5nxs%"̍arsrMK?gG#M,܁S@;[\ۘ"Jqp\个Gmv -R=GPW %S^|E*(4߮bD•հQ`ڮQ]^T'}v^p8{@B4G0X0<òI.?"|Va<%$^>nruv>,NRe)hƤŰ~g1H{a&ڻzdmupE(({Pgu<3Ry&sRb*aZ_~GGW=?4=T?[I2oHΐ['9q. EGu z2`ԟL7ς]өA3r~L_لyVPs}dlfy{<-77>?Ε87e Da"6kO, :Lf/fumvv˪ $fD*{ܫ=MR "B3KТTje;@A}HT  &,hWoABm"Kg(M,wo]_Ǜ^@AR$OM|kOVEԕۯb7 oeƖ')4UKQ˅4CW"!w82qp#/\1& o Ns=UDtS2!:XyqQ6_;c TH 1P'qNaqjl۷%Zf6~rfjLO!CpKBgrSz . NA2W[I&*|>lfB%Сʩq썾I(Nf#Z#1lf5D'Wқ t(Z*Lu /1}MjST\b~I 5=5|}ъs-ΐIU{Q-YZ3Xo1$ӎo2{35I̾iO۵~PRE!H%,ҫ'jԤqm0M9<m1&4jqA<])Jއ0|OaZI1:z=r1EҚ~Mq>*k_=S]7J2+$b';ޓ,y7|O$>(M@xN%DO@\xɣl*@3rI46ղڪiJtzF`Tk9o*f'9Ks$VșRvDR&1T" E3ZZ9;º.'.U>~8, @Dt:? pc /ؘr},#,̐ 3ZP*\ uBQ"Xia5bZZ7zfKMXG`od(8_L<;-MǤ},#dYI%3:k\dmm1T'7\ĔKEJFc;2OJ(ހѩ:3s0 X[Ǝ'3l e$tz@8 O> jV{^bIE% KUl-)~V\BBJ2R \1TӢE0 /rSE8Opn'3Q|dX~*)Oأ(uA-x4edn h"o\ֶ9]VL|C&,egpP]u>sD2qrs>g'}LF,¡ʸ/K[1zV7 p\]`+Bs.CB|;1k>;J?q1՝mGZɍhU]#N gcq4̌}qP jΎ@b0v4BihI3fa6<9Ll(!%O/ooRȷe}_nW>ʒ62 m~?͝-x?Y}.dĤI'n X6B_mC8;KuwkMq˓mJqY6n:P|jPlC}oCM+!B93&9k8ژ%YWUL8T3q9OE?L{eLEyĔP#v:Gz,#EfI"bD8 e(|l-E۹ OMao1T/ ÇᏨk,<LJ8a>_q" |]#Ħ뒜Dg<6unF ulYۉg`hwd ? 涧L6ZgGɣ۬gCK@CU^eq&)c[hvzْ[tyQ<{G)cEɞkYW\r5.J%!iIy{OE$P2]~ݬc*/Nb'!V`>Ut>3`H%5o%cXv.hY$+RrU."Z7 =jZIM 쌝"4ݰ#n^#0k@K Tg i\e?­$F^1{3qA7@'p7>1av֝h ouKz4ec5ʺ6W߼p-"ba8V@hLӅ0Ez h(\>xȏ>^{J2N=ŁT[pfͧ/L3T\ٱY6o@oO}T!m&DLV;~ .{؆9Q"4!Nj`3u@IwTوTeOVF:F%_ͧONMYI~gbM8h,;604Ji#{o L.r1s-1wᐖ}dn|V0_ Omj0$ xYlI+h%ZR\@ 8.o/6 7lSKGTxo*BmM谳r{bK\f_V0Oi^ݿI@yVQO;̊ %^AtOa+ZX(DJ֪ues󇬥e߸o"(ygiM(p!~}!a՗'MT:қWxA|gQ:ʜ4>bHQg81nqG;pBԩ<Z<q fwoa_\nZL ).)Nɑɔ *gM~V#rXbTݥrqrW]+#w'4T@FX+0"AƾCj9>YUShN(Hi.]w͂w > `\ZP#9) c*ۡ7Y]]z"^w-l@ B.n&42S?Ѣ SQiAMO)*#|I Gm[|fhÐv{5P-r)6!\'PEBz_IQ(]03C+ fncHHTtn~~HIј+a)QwTQx񨣏r) w%FQJ7#QboXei *f[P*} &W#KzrQK+(sH +e>zo=&nC/V6XQҫvȫK\ W.z+rVHAk8YB%^`q=+eY G ۻ¹ r0N:!p)-<~z յ$zc1 r=Bwk0yYVXĿ~JMg@EK(* .z3 ;[ z8X+ź3y ,e!P#R1xsp}*GgSYbKF(tILRIE&-UΩf eytՂ 2MKKI5C{CD(ӏ׌y(|/Mzn K(*VⅻW _j:dMR= ޫ*]"/w&U -|<J C@m{#k|uB}P#^l-7H>52iYYhijiNd~Ry ®{KS\-m\rdRސB>m7dI0irI+# @71[8h: 4|Ya]$ +]yU0B3O4 ]]#> ω'%^uE|x1DW)S +:qC2Da(>i&K! f nQr/e=8xc `(=ؽLK1{WFO?DfAB|OV0 ^40@R8h8C[Z{Z;W6`iC%ysSbuQS@vn'Yc!qq"Rw뗆Cx+4G.~;".#öӾhH!-iN, u-; Jt`ӔdP^|]\gnl!d3. '[c[}-5lF5o iDʃ’2@0Msn9n'"IsiS][Fm߮LOJ+׋$W ^pQl)E)!u7\~bZU~2Ex((?"ۘOBE"'(?o)4]A,QN0M$˄0ѡ_=,'\?Ao Hd0<)/Weic\ Wk(oRueT=39 Dd5TgFe4؈,H-3%kNŐXKSK pH#@~j[EmNbЉN=` ׅ,/}KNqMe,X yJ*g>1TO*ا야h|ĦgFTU" ×AsA[ &ESb-IXSF*aUPFLԵ1.y^,4?1X0۬LY{7}QlsJͺ׆DFjQR{/^ֳh6P#͘/I?.$w6sGk.a@4I͈W+Q6s..d/ⰉyEꖒp}CPg ?/yCren5Cc r{PLr$Ε9?75?9]jk\j%W'ؚ*G}FShj+tP[jK]|W',"Eߜ}V/`s igo;=j8 '}בln 8Ksźy,-U἟f;2?褄\-(VbvT;*˜A̗ؓױ 0hwv1%'ZʓGHWC ]L_B ?%9aDQf.j3LlMF8 +?w1CoHDɓ(u=Ƥn\IW V_wSDg6:XNGH}t8Yw)P?է9$n-S^y¡f(L9޳F4қTɟNGzc49Y}NxqD_Pcm"3v(.I!9(^.|o5y" ͢8<BgKG[+ו̉#>e7ZVR 2^ _:4/}G\ Y[NsoDB]h*SV 1ܡՆ[&fWysvkSy%O*JA7py}{ 3 ߙ!l9i su}?;S2T 6MbwjM Ftvp{0gР:VMZ{v' BXo.s+ mЄn_[6yR#GN8x|]&+FG TcXU["w o(,~o!ɴLWŸ&ފ7^k>Ň7 ePofV %CnXE^c٠8 OH?$- :rQw  j})8Cڏ)?Q[^ΊU^ӤP_\.MH  QdQ.ۺغW,M\`dz9,#oTQQdNbά 0Knuj'AJ=Pȕzm.Nd|U01x_+^*{U[tZyѵFc" LI-]hB3~HFD0ρ"g{j Zz $Lsn(Q߫"[ժ$B3͕#!FBA 㛪Tk{q3G|dzY߀* 'W˿6nׂYq*xE/jz0[vԋ+[TY|Ppv`#b݃l[GïD|Xxcӹ-f3l.-@o\utRQB/];G(3f'\v.p7; fs#i:HFs" 2Fyid f/\|A>O hW~tJD얃{qeƨolW ?s6Nя }k;Ub|6Y jtAbQL6|wF%$ " 56Bb@e8V%Me^8hkw>K@pc9"˳w1.J2Y|7W$>iU` DgXî%&qfT1`bE ;B咱Y|bi(/fQqPb9|fRa/6<ԋC*'hr+fq*s%Gvr{/vfh"6пV˷vŚӨX~.j5,_P!GI'e{B]^rW3bSXvՈ>vjYBPekB=LY)Nr`κĉ**bnbiѐ߈i)Јn}mn1l@dqG:\.Kܮۦ%q3Jp\MX_a3@W9ޘv/%꡻@b @H6xcLps=ҷ҉z >ԥ2bȝ_I&Yf)n|wžSԎEc9uSRΎ ^g$;%M``n}Q6yQk)ƯY%?ԵH?aӪ %?yAG]H4ez`tcNJwJU/SHd “\<j|>jQoNE*XP5?q񍞆e{s1I8T,W}b}+) n̢^7 !i-.jSy=2܌\>䜊 $cFשpJh, MK{G/0qelQ.kǷp.qH=auosaUDTO+&?1, $"o Ȋ,ہGhoE$?M7E'cdHtUzJ:5.4WF`X8c3J22e=A D F]BgpO; ۡCN3I/Qg9{fvC'@ }p3궖U/vߨv!g'5>*F32Ǩz(45+c# MJ5-O>wGHG^.YI/:';EQZ2g\DLi cJ-h`9iAQ؋EGmg@xe XW#/b°emf]*K\fr{A?u"0'.1 h@[}!x 6`.Wēv0i.T itW5uʭ3ne$/~-<R7;:lmU#W]3~ k4eD.BNR.vXMAmk)GesNj^'ͯ}+s1nJF"zG%NähO#QUzxf6 'hΟfkaP/U׵8k}odFbEGq,vLZS[)O|uyDc֧ivմGnF~C,i5&m CyEY 0t :GB|Qa&ƀ%@eK{:crsT&Ҫ]g(]Ms2h.9H#zHw_qQTKѡF=-8Q }*pARr=)Y/kͲL`ꗠlq#ҧ1ٌ Lשeh樱0\ަ< Ye}%iHD^yKYY8\'A jE[`C9UKddk58h:<%g8j^8 [!瀙 te?c4VYUlFI{ 'uW"/>(,zĘTwx],;BiG`Ҩdr-n6F@ Cw^Us˳Mwoy ^/<}jeof?Q).{wX`Bqs-Y< =NX_Ĺ5# qRzDNw˜E>>sګ˻%OZEY'o9XQUϡjE '04_65s*j r>]g֟,W~ZqڎJL%=(s\p=癋USq@sq>O äB/ C31[-#$oTO:D,|$y7F1h|՞F7^!Zψ 6=w"r էC&yO0Jםjx ul K;$4f91Pޠ t! 1zXCh۠(ү*|VD{_xvs=tlKrSމhF ƨA,$i:baq5[jFv/`*4VOм] 9uzM>)/0->V'9_\3n0YZu `wv pBZ8!a3EubTF=~DZsf('C TI}!u2&EhdR|Ml9?uΘ9; !h0^_RvЌrͻ`t[s'lyxD uPlW'5-6ĺYQ "X]@<4OX4K,0:D`Uj^=2 d|;^%h< z? ;eBcW6u =(9^(9}u踏[5wϕ=?Հ4yrCKº?<%ؼvE"#F "F$`KƯeN/5pW:twvpE?2' (1PqWaJz+EA :18f/~\@_tx ݻs¿E&%\$7 Pyu7oq@9%pz +%feaoܚR)h´L <`ֈ$ՒB Z!$ q +S{{obqm_8?]ё #Ķ5)ѫ>S&6ۍ+ѐ?xD_D;_.ǔ~{hף2Xɋ^_c!O\iΪ}seI!KuQC YUrwKRc;Վ/aAV_4'K]Ͱ7_qisZYTrF#7$omc=Y\xQyMCkb 8 }Ҭ"r]O8Z[kp! QFɗnhFRa@٪<}hbǢ9N`Te*U@;zB= zMx&h7\&ߡ ImR6+vY<:6w~ɒ&"D]}ZճDQ ɨɤM9Xo/8A=Rh&BQxE)6lu)!G Eu[\? Z7Wu%~.W%Rܸ$ ̓}4$L, a4é$>xf3aBF!vmm޽zzHH7E@זD d v,v Y@IT3զLWQZ937$~Tq*ҐwaQISY V<39VPQk2jG$yCBAYz p87(05!>?L5OThc"xGZ#veE$9Ij嚧*\"f+ԜQ$q?*@~Shb 5FaCк2Dwݕsܤ~H뮨=[,TI,v/E Op8Sr0Rg Z7=Ny{F$z 9 x&+iF>p;f'Xα˜bq>L6Xp_XYe\Ň`)@orr`~UAnz69~e[{bԟ 转G!_^Ӌh4܌5 2fV P{>>%ϥ|q@ۀ/Opz}3PەvPc%I>YMg@3Oޝ(C*(w+b[m4*7)VV܈au{\dGU =ALSdž_>6Ifg;^UTʎp%  |ov.15 FhקWIi> aR4+={Ub$]o-a]+gk$wreLnS.E {OCzUZRX`>[:[~V R 8g =^YdVGaƮk\ n`.x:OpVrd{=vޅ*# e} o {{sÀ'dˠKRI<<Wuqa%(INES mysR<1}kT/ ~c2K;ғ֨dc~ND{VhڊU2*fV:g,uC#!bnpΤJC쿲-)r7V-PҞVʑR61vmڹC ^CQ͎XpuʜŶGwhOO0i^DG3mv~jJbIvr/C\qeurEzfG_UG4#C,9Y]gF>kHi=!v$^grgq.zZ* AHy1%QFflmtY~2r>g4'nH{F0n̳@ť} =^uxv!nuD@\)2UaN'*pk \UzqmWx4uIoYB1]tÅ8o|u2C:>f g֎ULU~.eczevkn&<k5"g0qF6"ʚʅU 㱂>՝N yѧx\iɆHbaV4p %le`MyjJ\y`DqK17p!,Kqp0j28\vu a2ASS`3XESͰXIĖøckH!cOx,IP WO4332ZY"b%?,F$k@&n 4@tBc z1LR{ YLΐ4LIŹi>1d_|U պ"F޸e [iS9*QԹ5AKnmXQhv żA$q :=z nRl X8^x S^'Y-A" 0ʶh%'$;{o*EUAD†90VxP A8dLhlK477Wຐ_~+j-Ԅ@|Z`>^ 椶ߞtj5d{Ǟ7~c; O |EG@ﭯA y'i<Δ\iw2cc;8ǿ.Q4TGTP~h0pxmN sA-r\N?+myz+%6H17eKEU?Lg,<|G*xbmI }!U'pqbUw7lep7xPl")X V-FĐm~@k7vb /<#lŶkccM!ͨm@^-2KԧDkJK"oۖyG9q.t` b/l܁m`tY3#CWQþ!5M$@ ӪF py+Tڪ+^ʼIF=W0k ݔk˨l h''Lʃg.{axLELQ5%] an&Os =vWm{A-"wu>rֺ'7{-luK[ $sR7m&7S`p uAOn/9WOzer;N4eE(XS+W]8Qbfm#}lM u残9LUN+z(8 +{c\d;]4BYy|ovz,*NyH O7V8 XY1jo T4{ZnM5TZA";́ ++Wsv";oH 0EEn*}d֭?`xI$nKdBCt9kg)? ejo!ज2ސ1Ox÷ _۵m-JGxh HXWofқA[/vq_1UuJ.X 4U; 9%ܶuT!OF5x57[L;ƎmQWѻߞaL|Do/#xr(XPC촭Hh;ȘUHGkQ+/maP.SyWBϒ~iTRlSN ) jE?81Ձ;6S˕ˌ& u|Lm h+,Npxl;ڋl^蛍g+#=QbP1LGeX0f!j4 Ǧ8a:G>Alw5B;".For*tzI5T=KXa&>ՙ9z/L0wy,o/;jV"k=H{&s= Ӫ޹i8%R.㼌߰g mJU--w j~),p(cӿ u.,팆A&%~yZʤ]>qHuT¾Je$Xq*9P]4z-h(k2#B%$ķ,7#çzQ&H>~kWope,P0'~+¯ek\VF nɣ :^+"7_N-Uv *@k5Q̊@ `gO'Us8vM@0drp jř EM-x-UOB*]0SC ~.St`7d,1N[JK//vjX"-xtOվھ{@19# C6rox?M/ѯqy (f,mx[&3Tڅ%Bi{rrL`o V׀9vs{dmo(Xsss! ?93Yv!D ?÷C4R.P7UTK}X(;nTG/:EB*;<)atA s*c W^ɑxþ0  5H.W44^E+`6w)w-Z$MYYҨZ |'k ?]E*NN+x~乿BZ'${}Šjhy'zKĆ)/Smzc=3YhƩW˽P!Rz@7ᜪ;ݿ"-Ks7kf +{* BÐuYT` 6@ FX>18d~. ZE D. N$ jP tUZM5[/F?ԲU][x6}iQU1L0瘡7ы9BLi\~+:cNb3j3DoD !eo0Hm*2ݼ5'cթ5 a^ry 郱2^9֯- JO6~Q='Џ}`yTgeu[cl淋wQV|)#6clY]EQc$L= l}zj*nH}6 $YܚX$RT$?6li܁޶Y ,xK9j0 6? *4G y ~R _Z8*4%qR <^Fف~  CQDs eT{(K0Xx9j4FxrIhLel3E%5òwLiJC C o;W?ht9֪d)ZEՋndx +pتA ܚNK<+nzI9jNal<Dz09 \A0M5cn:]MHB@kMFoچnjX{y}QF7@/(fBx:m- <\dw(}Dw,wc)sk?r6&Z$"6䘄Kyzn{˩)>$l+M x\DO f &0DZLHJBl%!݊!,Md8=8d6B'Ĕ['@GIξ<)ږe7!oqkX(Zaà~Ґ}9"mt}GZuKq0!ba2cG)BJ|^x, dyd’Sр tm}{Eٽ/Po/p j1:сB5kQA-Oe0 TĤRu_cmqDmLX'3#s/[k g(aB-Qh==`UO#pws;A(ZBz^aɬρN3c@=-uKEXU6ytt0R5av(՛^(Y¦Ÿ*V.~[F-b9((Pc04޿ho̠EdlZ* 3ׄ`w~Ct~0E -=h ˒@tY8[\ r,S([i3}WIS"A6е4B CJ~Cs-?pp· 8ųr&Mxͳ+Tnߑ@o*;0 9nnqa|˺55LN] LzaZ !eIhN?"r!(~ !=xb .Ƅׯs*s Haf0l(IK|75#~ fsj8.VU-E?=# d+ZmAR"q!ÖABADEMN|t"Hha8^ >U _C i}'O oSOFN0u(]籨Irܔ<|ZLJ6NrEz+1ek gx] ڤ|]k;Úמ[ݛ3G絻ȅfkI,ѩb[tKP2>Mˁ{VbhyMMƟtʨyxO)+S뻓vOVCRMxmBmՅjoX|Mm~!vO6ls1!P cQ6CtiFi Ptd 1sBA^v'UY"f5>cG}\dH):`#W?59RXBvrVGW?d|6$  7 t3zVniDd'J9ӶIquWUra֨ dI#ZGD;kٮ5,ăHV E Ty :`J>-bTZ5̲\, C`@br# 90&9Ge?1bC*`vjj[M!x2E _kǻs\.)?f<ZO+A#2ޭ'dX|痟1ҭ1Zg+|LkY~p3w+`χF˗ny[>v(07:w~YhӐ"[E+[[V^>}L(ȦQJ2Pي"r/,(2həshlJVJ=d# =&;:I ֕EZ}'gW"lgO qoCGR?xקhn1XQd[ N8BX@$c-6Pp$u}iX)v2yX[6ʩ+XkNzbEm/,=fcF~ e9"2LXÂ姱|_|P96D+C*O i7t8JBCrfE%;=?V@i~=4ʡ6"y-`[M f #0j: )ljH5CTĝu:8UVAs#¹A!{Ȝ iBɊ _~6]VŻQ8{{'km52%Ge+ǪlU ojn{O7f#px+2Jp-k!zW<>z`SQE_VV"2c(N\jh@G=_Txy}T5.C5:/ēr$SG9A>k뫂]{U+'Kkxq\ZXwD-*壆{ng2 =ǴF t8L>DZFl>6(=-CzlPaEzS i of6nj"4jvۘǑ|1}5k8Ha|(GV4& Wڕ@oM5p떩k>S<HVZVn;uCNn͎fLύ4I]^l=YYM > of@z)l>[LmY2 ] .m$~cH~DŽin}18҄[_]+ҭ5rzr(pWE)t ɽ+|@Ӛ2 Dt8Xrf#fޘO@o81U[eTB|mSz@4w}A^r@鶸k= { w}+w&'y2ԁEk'R2(\e_h>.ݝ9ՈMhN4;MkN H`8[|pX7<\'o@5r`z,I8|-#\F/ 0nq@#P9W(ºU*iLdVrhA0ĵٓ] Zhz]zI֑5p [$h+ Wq ;7Ε 4ȓold+#~j@@ۍcmN,~;c&J=I euҲkrCi`pYG>L/R;VQ>DJF,k!<xV/WXh;|Cds0(0PYݼ?\C$^ DpWOAV_V$̿ħЏe j(%Љ(fPf#}|>)Z`o1-LdXBOgL \']}}7|KZ dЙsis:aŒb#r#`d>ɘ89m>&Eg~Ct/ mk rQ̂]a,0qL((.X]A>jgPݗE %Z!B-+T$U)]]nφiiZC/gg0Ps:ޱ?NҼG[o5{3[pFryoVi.)$ *rBQramp|tҐ"o"H$bYHO 7NAH0j|Y,"LhUpi]qaT]#-6JeʛZKZ}q:$JZb!B!C Kw(njJMtRyZWEc4m~òe4g$nUn XVK͈@ÔI'3|a"f&TY>I0u@4gSMGN.3юyoZ>E2J)O XuhL UB8SQmw/y3bWIȺ8oL'Jo ],W lJv_{.8[TgM۵8."x%-AO##tdzpL6&~g V;Zy$FlggI('znV* feTD{1[5@!DrG+X7%t'igY8nEͷ"B˦dnK)fQ%JEm%C5ʷPp˅yRD"wgBc0.0y t蟉ytMAH.fpLmwWSD~/IH+76w[%-mG&j\KKj6a-?⡒(J`Nq=[Bqu|]{o_x-~ ZLbw}AVZS+OUK?=xmKg4T@ f{;c;4x3rcr4,kW?qx=o$ ƣdvJnj4PMJ3!ՊlBT&*+^{wRu {DµIADE1઩n*zЏb!":mԬ5]I.kP19R@^GߕJk)ԞR7@1s.\63%l] AxV (6mH72?]I+v<)e4+#21~2*ua|U"N[)ﺗmʗ'1/uΟR2YuU [xLKN3Rwu%A5ྸC(aj5&2 [6R}Y6hՈ~ PaKmb'Qf (q4WmH_ B!I{ I+43j#GՊ$SC'$`.SN`=r niOSJoU8}~+wq(gU V=aPԼ8ğz'+~q.Z=cqϙG#bL A~\ 1Q1.EBzapCoaBMr&N5< ;Uu.J:+r Oڨ'"]>u!lY]V|@gPeZ-6nPFϜcc)5%[u._!?o|?qc:w@F('e"h]9K܄10H=Kb$\L"GB8GV@;Yke՘񭻗jpC&;T0B35Sn0I>Lbtt0^})R] Bv2ܷEckDmPc׺ZlMBLCQ>C8 ? (Pו.Tf% `G6e\;M(a0੎DA,XնJi݆Bۨ]&Uxfn[8>Iotej ̱Ng1޼GhWs4pI5us%Z{^"ʼfM1vC@85vR;*iw(rX VB74#OJ(^#y%cϏTlRN#:`J{3]kF325cPLv۾6,:/7Xg| +d3wݠ)quWM;OGJ,% !Z^* 䣾ڷO)/˔%=fY<o-o*E`4\t b b";w4W wfcU%N'M4)ЄarOct!(ǃWK#[|toR]j<5}Ybi u (֝#nTO&s08/5gULI=^mn /ai;hk gwhCMhli7KV"1 =9"R(W݀E1ʡ RH{C#}䉵KU(N){W#(_ FdjxgF'CYǀN^P',Mm|ǑbxdRE}7^hV`PyV5%3dX i+*[NH2kՒ/ڹ5_C*Zpǚ1\l$SfTͯwY!m ^{ӇʴS&ùS(̲7DIzy'3"X鲷v((C*cpb,`9Vb@+I<\ *h~y:5 qHȿ3ǢfVʴۏ[d (UyD~>9*?_|㭚]V[(J5"8mϯjo'ǚz/"h3l̉ 8BʗZu g{7{ow'A͏8 E0y]&Ey+t.3'_[4}{ШfĘ)"o;>$$TH#6(KxL;d6gTGf|l@t§V[B%mP Ar%3Z7 Ԏ3P9x %s#%$枞E\=6! %0W'ziRZ17gC% `H<-lo Cn<(JyzҶYNp 2OON%p]"6HAqD`Ԁgʩ,PՉWH`h6d| }}z+Q㦒NSZm/ҶJB>IBɧܑ30N&e$٫ ں5 ~`Vy>T9No}G͜ "s=oshަKa¿R1IsPH< h6kfkjEP+(<]*ݦlBiq~;)Σw+=FUQ{ SB]@w*7܈ EGDe8nig׿ ~nE| dL-kuG™$ '1W&*bʩC?5W%!.ӟ@R]dw$B7`>³Qg=sűD£QH.27/q8D Hxa Ŏ5lO:όj&MIZ"v'kHm?P+ͺ9> oT PU-A.gd AS98nh] 54X2 È YFx\SfD /Yu2 W8T9|Y'jNXŞF8f\-Û\MS.k0?A-|2s6"XP>rT^E +S]DOSa'!V0TF?NozrJHj]~*&%QrCeCy&/g-Qb94ԑcJM)h2eM'S)~T;W!EΒr!-;30yz-X `ᤍ(S"mdowi22[yJdw~\pNщ.tCqUu,*[I/=@rc(5G?k Zx<M̥#m VsCUZ-s(p#q{ .f!AbZcW[}D^6g!H/We  XDA_Vx!Ij.&'Y0+8+~(2v Jdam3\pi1I[$ʃ `X*dp# Jw{Hʾ@Qf#eE2`r: aMY0Ic`.GCsɊspiϛ-0YԞC[6W ^7-+R1*-y,30Ƙ`K9(Ş/soh[W 5i4P@ӮɭKi0]j۬RWƟefe&wg\YwM^l{ ;\=&$Tg d^7(KaGTI" KG ڙeQ=*=n ekK u7<̈́xa.CS&:}VUo.閄#Z'kt-D@JKm0H8f䵧97QrK+m:R X|97^~H:ՒuC 8;2rolWUښo01i#jPEk}rOO,TXB:7`Rf}ONv{tdcu9]TI=Z}@au4bM}%"EצvwMKY^4NR\,Mr}0]^qYT+%uH˥_5eꂂq>h(P^/O_R黒(8`7 &(b 7J2 `6Lu~."]E_ҳ {˼i v|~>>%!.#_"0nL#G4(2ŘvQLtT2 XEz]k&ۀːAÖB3za Vf:nz}]b٢KyYb컁+Dx}pM0 G%?_$IÑsI jT"X1ae<؀؂촫Z0O3:x'V {m'05oCqprٌǃvU.u;u|FOQ}J/ьK:zL* D;+-Lp25s.]u<o(%IyleuV8OJ=#g,Wi۽" ?mD|c"=}˼1m+P;~eb=Q93qxb*׋) a#kRk`yth"p[´>^pSq0/xCRVv>Dg`ps,0|8 ǧ [2)et^.Aw懁06v H xB+`Y܄~GJ<B0׻3-$'0&c_Zr0kG30SǑ%>1OD>cnY, GlC s9V/n.*yv@6z?n/xC33;q4+]ZPkO5߫W9zѳjNַR2wx|F ##|d0a41ץfΝ;xnXXhmG#x2mxNcr[Ow̐j 4?f|1QVϫ?kQB@zDi}3$yXU63f"Z,!Plr&b:dCGj Btުzj:6}λՉ*+$A}ql93^&Q]җҮꧬ}XS>wjLiƍ:}ȘoMŲR3ӕd;p1_Fˈh5',uT/_݆t,)tS_Qxqb ,gGxd%)(:Ef- =AA r <_#b5p940Kgm`d!_l3U|'ؑ,A>4C.Y=m}&( sjF@˝D^[^;NFhE|W/9^t=D*UEZ8F,)0Y,B *&cVِn[԰E)8o!lRmBxP)38=@\3TW3Jjv_at暘tb3uli0o/@ bD񁷟`:p'cﲀÊ0]kSKNYF1ifu@Gb^9\q0|I#hE)k<ŴZ)]Ze[o>#^F^1i` 4Y2CK!0 9,9uQ]aph;KʖTz>hT$].r8MiąYdf,pv_g2_y/юQ~eM(R.Rʉ} zy!%Eğ1!b+>=Y0Z˺(DfuX&DA|ΘbjDɊ%\;\9}+x$B )ޑ5.BgjE֟1v,n +-f hf$pg͝IPS|`7x;|V@EQ ]?u-Jf~~#P7pnqqҟm~Kv*f |҉s/{.+k.t$eF0&؏ Zr [%9ju1OVLo3u/K<4UO:, f$=_YG]싩?XjiB`M'7?=T7 1]hP(;#zI{5uH@X/Њ70J93Jq4ʲY]k{@_&,C55.(\J(sZN$Q܋3 a} C|#R Q?UKۙ$eيa#ɲ*% PjRVkfP~){<=jet*fJev%v#fSkt@kf`o9ͦpjɧvN;.d-kTQ'K$IE#YF_0mB+,Ĉn#2 ?kh^)`m?*WeVf ݸ[G }`Ցr)ieR8:T~AY!U"1?"N_԰0A;IrWa29Cnۢw*vh+=t+* UcSK-|/&HrW6Arl@d4B4$!˛에0֣3m֦Ҳ2tv*I=I"LnPVlr;Vv(VVy8 +D ?AՄc+=̀8$DS#@H{@3pluW̫m݂xML!*7\;ףq"z_ߩǮ}=Sl_zOPo^ONNMjƒV"дΟ FGUw>(1SJtIe#Uj :Κyoll6cj.l6Y92|־ H81$ƓTu@iNdz_δiYq`wTۭG00[.`(hѓQeYiT+BGf;* z GoƖgO- \pPC.K`YzfFQߛ<@0 Qa.hH/)tPg`"hg:orL2,ˈ2>Q͜7FNd&d pp&j =QŴPHT:PQ+1oHGp[\VPM$nNr, N6aD`tmA!Zo3Cp20`wAE O^aR}.oPpyx6@l@_.~=g@I?{&ң-0^jUI0WySsEsAn-JueB9cx1_-'T9Y%Bu:>.H5$~;1SU^gx] ]r wCXSc 4c_9{e{ >-Ue> \IVj~8`t{6՟[sd!p,~F;Yg'3XӾ8ObB6ȴne጖ڲ<C!_H%"z5|K Ư`"%$r5_={j]) eR+/:/(anh*հQZm\ ww F vrH˨q,G)YGy -KT)ŕͽby4%0NwޏڽpւT[IPOc\0Ba!\.csեkHpcJG2RBAXf%TB5$l]/ 2 V a!5L!gq_8><=$V~_(fV\_m,YuXlBqAK'EN2 |H5.>ˁ܃0~Y :SHl=+Nȅ\3C4)7_Kps1k~b[UꞤW^,6|ҿ,1϶ Y!՛uT0)`.,Q:h𘴩fSތ ޅg^whT|8'H9Bvpw{!1XZ=3GYex8wh)<><9ߠJ!Ý~XPj(9D( 揨 E69fSl]B*!Np< {=c!8l-wtO3 DR ?ԣgѕ!8rVc;~Ufo9Nˤd 3|ʯo"ހdJV*tAz"CrE ,T Jl~>HT~wGaPdxuQߥ{Gf< e5~sF'B%>FC^}|0"&Z~(mr&֞T=}+#@vjG{jLӕDGBb*[+/Oqygnx ~EG6BO^#b.Y"V_&4*b`5SRaBNΆ;5 Ϙ?=Q:5p,&4lCc-4P}4UG/{s&0D ѪiZ(&vҸgP=-f8 U{`yHñӠ M,ZIr}˙:ߚ?k ޑAq Byf(:+[j;HmWvr|ҫh3ѩu|HޟZ{x !FW l7p!f ,Os渡-,@E f`p< ? Rʃn-p\R O©X@k("Q17˨4e[G׆6$(!Sci 뽺A7l`u-|@>2 UNx> q<5pVQ4+ݪ;~*̱͛o0R\*J c?ٔd/w+|x9`kS5-tóW7gh9}-4NrshG\Va*WCh ,BYO p^?% C<_QۊO | U$^TĀk$#6f;u?K; ~5i,2)H]:@]tSlʁHTOrv8} Aґ@.ˀ a:%%o҃&8\+Μ%Z,"i121"{rmseX0TlD~CW)J-qNI~=D$ q]?,al7bEr9H:Hݾt.EB"Q6C7zK܎nkd~Y+4-^%`Fb!*g`L՗/(%L:.߂MQMTSWMTGNNbwUJҥ7 A/]7ݻ cTުf9:t#=%07qz&>^5Y0ѫ;>W`&*.ҚM%΅B}8luv؞dJ^ђ8 WC'qzTJQSJj*1+ Qk!rJʐwQ;xcU'F\٧ PdQ/*Q $KVם-䳀;[# ,4cl ]:P,i)RO/"K [[/Mnay6:}k>D,܀cۖUtFIEc[}.if2=Dm{ -K8[|8%~(7IBio_/ןe;01Ɉ; 5W`ܵS="_Wj;EMD1XBhz fx?Sdޢq͙\.9⧂RnƏ~im`~Cmr1tJq V/C_-'Q/* 3*'0uao^?EB]1hFyg掲Uv~ɺ%GF8|x]k? DS[6ٌ ؈jJ3uvqj>6\l i (^yJS{O<֩uVy O{ 5sa^)s]\bZpK5C $NRLf~D;O+[QϐN #54  Fj IeR9 VrdK[}CܩuP"|z0w;-Js Hh: Mؙ^m\aaY'=|'ٕh%G6].J"njߩOۗpvtIO q~''‡a Bpmtc7v7IySһ`26ONK/-..C GH+yHoIKQB{|mzjttzĭeeEh2R[Ζ>a'𤤓Z}^&-YOx_vwcqG}^k|K%VKS)RLq;<$Rs,.o,[QP/f^O )͠0w 'ZVlX :gkK9EVBzA >L~)[q#do޽0нw :%"pzy#OlG|!Y+}aO/`/t޵ DӮ_{e@κcB^2 %c ? kW*jf^2ђ=QȻK0G ɠ`c)ўx";lݭS_bwT>|a?.'!Y|1ľ R-D։RaNRFD}v‘U荓{Dyp=n]P9bY*Cs~3wrM&jZ`*P/%ˤyvS/Lwe :f]TiE}XVi~alԠOfGݒOt3U|^j)xrN]J׮Cw@n0P9NXaw "Dv擐kP}breUc@&Ћd@!CkAՍ&؀Rn3F+e b}m#Y9FOGMliӼp ԛgw=Uv5]jq ``3I৔nQx ޑS>3-oOc#s2S{@uͮ㼿U1*i[]րx}m+Pi͘ ֈ; X;+%XݨW^d2蕖h焺L@T\A#+Cym#A|$Y  H 6Y ]R6)}6e/BH9QyQ/ik/MIi'pI70+c 7eizZeQ6[YMR@d\X t$SsexMs# k%qиr?#$\fiIiy_ lpt)xF:_Ī@Z^j7Iם %JY~ 4A0S,}z06+ػ)K?&f`uMW2 5/̡ڇSa5{:" {mޜ]~O3 \!6Z{_= 2͐fj]ܴېl=wʈ~8v0G`2lm =Zx7\վqGNoU|tH30JXr?!.Ŧ d(0PEs˵%Ь1[ c/j>z*|WpfHޤơZ$cμЫ0H(;i/eb.r!#u92F'_:y]u0}30fԓ4[B چoQ>C荧qTdvj14e.n` 5Ry&T(z;3qKb^ ~e8S&8%*0r?t-WE95EqD;LXW72 P˒oΦP:_bM=6滙G C|fFX$S5݃@yYw*#{kh]jټbrmd4 n-E6GSEaX Ү !3qDMS;Y:#0AzS@|1,{vM;p2Ѥƕgʰ8wsK7R4EfiQ/pL9=uFn7˞͹ѶLۂċ r+h@ {o4d7;naB ɬh;75\?5ш`sV S! ;fZ]rJM&wk]ÆT 390ǟNgAۥB9CB?Wͦ&AU:MI2ߙ!J_[:9ߕ(e6l#a>pPXpg #I`N"~Tp=i(S׈&&hԼ;  ;NIK߯~n|߶xܭ]$1nľE|1Z^Re@B4w:}G ࠘9 e81,_gz+hDqA+KASFG1m'U_ $, p2 =/tM&h4cx*x?2$soof M8{ 퀕ÀkYK$*gSe( (AXIjw/Jz5Mҟ3gOfM(v(n0ViF8QtUBP6[{TuE;byWJ '>8B4y{~ŏI;T' aVW6+1;x\VCm"Cr.wKhtl9RJ+-$#$ZAu_#}؝EQq4G p!L8z  ڧX"jC&w]i5TSn*"UZ^]羱ѯݧHv|ZtLöFD ,ܳލܤ"ozXYȌCBf10x}M9Nr-NSދd1RRS=RnEB)Xg>G ҮPnGoI}#vjUyO.Ta}iEB޵n`,EQ ƹ,*TE"1lql{hΓMA_$[Z5eYQѸW  HQ iFvw|BYɧhg_6T$ؽm"pb24JKk$8V>/FS , BPzNKEu :J%l /,px+DEw9e6cmUw] r3@pK.+N!zFwsȸDq\}х_Ǡ'YĘ]]AlCp~dδWo~dl!*%mH#fsC։B8EVPQn=UZ\ &gߚ֙7z^x-ͨ b&sd' Ę-/!~Ps>^DϤULu*xsXjj + v:yc;%ة9&Ӕ;I`84Z_R-Ј\S3m[MjΠ^*v^X9wtz>Iug`XZa<1T"^a+K5,OaAk"OR6`z"Ǯ!I$=NGgԟ3S&`?%ЮG) nE{<;@핛E?'r&a0jxj+^PS7agC#/ɔOQP'Voqf>Vy)Z$H>OACu8ʵnWDTNL])O-wPyp @vIygicb8I%73V1b&BEjr,ʟpuw=! Wɱ莡i6#$&|\gbyDv2["F^H64l᮷Y| <ϚΞj`()!^g*PQTSa~oM1"rA궗 i'\?i=Wf_Q>q ;l?}0%`(73˛w"tP P`fH]ac2}<6P9S"e$a9>!;rt0dG"\D^Bnav^r# ;zN'']z[B5W+Nq97L]XFU'w6ԔzfbC k"pԬ3yϤW-5 +{k7}|+Rq3$Iv`3j \1Zz *sN{'9:/O4eN-l<V 5ol@wra?i)TQE",L+H^ oV96Ҿ;$癴HFHo(H`]"*|u=wkn|=l/w9۸[R9O H|}Kj`t-@Ayltz㍎Tues>z@ èuItA8O 5% pA{ʗ03Y;mE?i`J1#NnΈ@38vL3R8w3֬4}i2A%V qZF2FafA)$= dq{}Sװvk/p(@^;H5WJT_2*xz-:9Eq_ʠC+BzAdm?/Rh_gflFR1yuX#:黯3h}&L?3yB EwӟߴgpmMUl g\[4(ʨ Y0Bw܅3od[@Ko13x_ej러=p֠]OQP=Z9T]z&  &;t fcm9b1,bڹAMdw`YpItΞIApbedUj@ܟ^^ e4LblUAU rMQRkx !Y˽nȑ6ziLR;YF4 v)Rkl܂b^y߉hYI:rѰqW~y6,:`_'gGEә_<6x roiϹrV _44a w{oWA3ϥ [) ɛvϑc\}Y!z4=1<mL%KI?2a 9Z@V fMJԔHࠐIͫ4OES@_*kFu؉ZV zr+,$JrΡh."qрbd#(uE@Kr:qwQV/*QW1i.Z<2qǕ{JT@P 1U|jIOKE7ޛ(zqgVs>K{.:kJ\9!tE:C,)Qža}nS_K'Fm󯓾]@~ϛыs؜Ub \Cs  %ǰyz6GHLE*rhirUZ"&'GO,}Z6 a6;@9T"<$4V1tJvlXӂs:6D5df 9U^duJBNM*)}Ag!әqI,~e!151zܥ Q8Tw_d^떩A'\x0MB\d (.U-Ѳ]Ǔ, Kvvghp`pB淘ë̀+ ȇ|qZW4{Rᇞ9g:IX? $_LӅ&/1vqtC|֮8e'@ZAHO |wş]2Jy&!LЌ.FEq+'*i,|v@ ؉ iiN3DA 4x7U<|B<2s>D*m9_1iJWFik`;oQ[gpZUYiS\6o_?pW#' 9U1VIadg?צJ6vSM—^wGc4>fԑ(~ni~UE/>SpE*#Ay)ZׄiL=6{?,}~R5c_3L+3Wأk6uqEY~B7A8.*vuhC"ƌl!+pruM#̞X_1`rcy _/-ܸߏϤJ47hoe$,& Ζm l(bR$$0/Ha}-SUB]Cs^ jK˔[ Yfsn︝Ywm×;}1cck8TV!ۣ-9cė^h/u)ﳅFHICCK Vy &.h:Gz$gPoG`bɫG^J\M?Sʒ,crЬπ3sfx9uBႹaˮx" ݀(m6dO_϶[Di.AəHr.3Eu*Dm=en r#i9X *qeYi{1 6p&{> lan\Cafia^jwԲ)3:Ê1ʷQ9 ~ )'G\-E}qqFOx}BIT~E?&pͫ>pVPn7`BOqa!I. @3=jpz* tp\(0FfeUWh {壤s^>4,݉߉&xCc2}k, lQɗ8UKUL’:;sёnsg|BViq6(@IWFp8qPN "^È6Y_8 cm 4JUҡk6݁́ Ƿ"Xŷj,aͷՖc=.p8J\=Oj >zkHOF4f =[]Edtϧ'BM0mATI=в SpX9gRGKvA7.bwj--])L>"}y9ӌK՜̙w P(I!'H4de_$8O#v{MAO &W4y l ^0/#G u$ҲbpYIҺ}}.pQ:C-"ȇ YK1D#GmTo+rkj! ĵ\GvJ :svϴ 'ɵ ,E^Sn6W#7L;+|g ]S&uΎ q x@kd71OsSuh<o%Ijcy5zxy% o;w|>ٿMLB)U`eI7BcЂJN۶* 2 _:.v 8xo>0]|TYjen|H=@{&VԚ {.FaxHIIkg̈פ%qO~q$.3~Ō *i؎,QArD' vunBZAsK>#4L}t͉֘ÙtGRo5,=I|c%8Z v:i;kj%p {_P Yr3ς,ĆR;^ɮ{z {|a4V ũV̒1_2|oڦ{L@=DQ[|+0 \+iEg:[7v R-*ǡV;jMgieqSfg6?o(Y<YD !2RI29xAXW2졖QJO瑻/xd$mTμ%~_*džCI4I߲%]]{Jr*R #K,JP.YK|AH$AsuJ3ɭg o"gd⼞IRe@;tv,:134CP+4ʛ_=\"!NذR+#u;<]@!L7O&qYiL=ȩC9z.1.42z貙bOhƍF^2[~BړM\m'v6{c!|8s?IuY̕wHX4>=?jӋSEgO~;h\`O.87!$ےQh-`&zXvCEB%(ХV>B|l9/JA>jg,hUƟ3Q8Qͮ_!"0_Yżҷj(OXt#Ŕ^JmP[#ȏM$2F] %|uJJh\nA>FyJ[jރ4mQUR'HD'*\Q|NJ@ \^o}-蟼4}z>Yi90ƈTgP vwOn<êZfpGgE@^xCluU˧ 6ϳ#"uhnSsw9T*=|u7Khu4 'gA8jN:^"2#*޸!1#O,+xC 4YS H"<z7-[˲ĭ9@Ř +S f$JccՇ,Ҋ=Sl0$7[r4[ $Po~zl )d^<0\=ڨL@O&{9ʼn$Q 2ǚ$l.mրx>gIşyJm,5QŀIVn'nxn{ WiMc!865dC&,v>0WzbI뻒Uؗ2'T ù-',I6y K [30/ID,wjPEP9֊ 8ʛ@]AѬy2[UcG!Wg[_H$+Ҭ}u<,N13TO81ȆOsa7.E83 lqtMkB# .dflo{pڍ &yPޥNݧp)k \R* Ur2$G}̊ŏ\x&DŽ4 f o=-Vׅa҈͕/^Q0&Ll(>WHx<䊐E($V_eѬ{"SzߑAWF J+fjd>^3=mtw}됵[ sLgгcɸRv;2HS|NB' 1߹h8) ;?kڞTF^"ƄjjyfL&7G.CU}5} v2Xd4 JV[ߍKhFgds7U#qn6XL-t| p'Nz`Lg-d},lUI"h#xEcE0c`B&y#f:$PNNN.B&Sz0tʼnkNՙ&!2S ts뜞._lD zާsy,HQq8C_dJI}<ƀ I!!w<>SZ Åb*2.aԂ/@}f|WdMB"4Zҳ'bBw(Mz2&&}g G]Um6m|UK%[G^UA:^[cRIL='Kcf\WI9Ϣ㗬+2/MHZ[>>?o>TܜCv3DʔQ*Ndh&,Y~aFң98_jJ]a~0u~{U42Ͳ5a=W} 6Hِe5m{Rm*dn̬)VW9h {:M X{N`eУFAk1^.cLW)\96)ʶ'1e%`9 +w.\z YΖUgp~8JýIn&)h3@xDP@^3%8iN&V~sڥ$M{yK(UbNx;ڄk_ܙ<</ACԵM~&5#oM@Hԣ;ĴDDFlƪ 4 9F'E=Y[1c^W)=S՚]P$P xߌN -D0qIԫZm=<&g6Hܖw>\RX^Q(eo.!Z XXG[/Ul1JΎʨ0|X*K{@lѿ٪*!v L7bK=;_hB$T> $JKa7ҵ#gf2Lq{lJW; [_] ²q5OV] ǀ'tOAkScEժ<+Ɍ>'MyK|1~Ka;-(ME}*~/"h%q= o\d0@d\/Gmrr5W ,189L%ueAu-MtpO.)tğ;CfTє;D"ج)HBiWs_> qҭrtLgMQ04w% T $Xm>Ϝt̨QhWHv~˴?Y 0le< p\,O#[rRLU'{bwVj>\.JjpAHI6лoehڢ*Yܩsˍ&]= mtd63t*K2cl-Θ{f,:s]B!Ί|Q٧cUmMK|4djv̘r> l9` ;qm<Ux.oMP(?؝O&syh$a^fӏXP[: w|9ÜKRQ.mRby%r ,RmQȻ>({E x?B. ĂcX@R'} Sr$׈7xA1W&~~@ĥx϶`Fʄ<MR6'8EQ[/+ƲPMe륃w%e ȝ^lۑJ17yuƄA?qBK?.Е]} !«Oq/Cz( $}ZEJ۞{l34.B2WA_3TG!nEǕ{3S#SyYuZ{}Uh"R(nȥ8C嗠Y })9R"4$diY:46;* (?WY= }b%ٲ|fv%qǤ@6I|hĠ^,x>]Emqᵟ5gU,jWp OYK"e v"7~kUvhg7\ T ]5@/vxȁ?sMMȲ;P-)ؙ֏M{@A ÈAU{qSjوuelPPmHW y+q7 J9_Q,? u^" ?SـN:iX33ٗc& j0/*9ˌp7Ǧı3q/HP dQNL}1*!~"8Ē6z<NtS'45'n\NR BƉw̫]ȷ=Ѷd^Z!| e{a񅙧o߹qwjG2|ouÔ[88E%5$3}Nf?DdpT`ޟ9š0VEN.ɣQ @@Sm6 fƸwħ6bK5{M8 A$Ðl ŐO,6FmO&1SӚ@zlZ*6ECd9괬o }o0Pqk2TE;+}q x{Vdĕo:BdU޹#tqIIp8|*ubN`nwn)y͵㱰 |2gA5n^I0bA@Q;E̟ /ܺo^S?QŖ*wI[dRE2W%޸kV 7&/ɍ2I (QHG]W± ;USQn&0Ӱ6y0`Өvɘ7BA {"RX|x*T|ux  U|ɮh]Pw8E+%L-7u˕@,|Uk:D$|_R7А CU]WF hkI>NsA.KhJClsԧȓs-Y;. wŞ"ŧ8DO{7" ʛ4-i}KUN +/1.GMGlTbX잷35gc/s#IdNy{J@Geg { "9Ё] 8b}ie[\3l )xY|2krǨW;4%A)&T\(p3P,s 1pL$*is_7Wc2Ki53,N14(|lE4 3&Bz˽! \[3U냁"\Z7q|V9۸*NMͦ^[G"uHT)k_z6OK2`%@7 $E%uWc 6# 60DW0z״&-C)ɘ^#a7YWS}:s,X[=:7ced_h`Ց iQ_$d -2Y/m]EcRy2Wb׊E躴_Дk6%1\v4zmыe3l ubg">D 4>;_( `Xe;JkM +}5R` xJ;/-fiȳ}έ/7ѐbгVcdeoֿB&!ʟI*zu)}J!r,. "S._1ӤyE'bC,M/s8X4E VֵUD5;& y>Z i}a{Of};qbR*uzEt;TwSҽ'4-JJ.z%̫Rt#Z %Ž7.DAT='%Ꝉ%~Aob#|Ӧe7ǐOg YxUQtbO}bEYm%;)9TA》w}>jݵ=qg 》 3֙yukγZ3Nu*Oa|s0laK47`"R1 (|O3R;ʗDIYُ?Q:9OG^2whdWJj8c&Fb}WN5bh^t+p(LKLr+nV"֪n5 /6QQp" p9>ϔsxU%;~ T!wczP/Udߴyn~=4{!טM 4XiC TV6φD?uHL b_2̥b8\|+zmq¡]b|աҜX ߿L5Q# {.dilƙ,SRnHH$\m01p%NȮslE{c=ge]' qH!&tD @"#Vqܲ wtdXU04S+h$` vU[|r\ J}4*0HF4lFwc@MbKdD[¥kC ]J3 309)Tt}ȸ9zCA7XS1>|W0Yf.|W?:ւ|J#nGr0oɏ_Vdw5]h>@\tAګ QmtTc@K>Z@mwNSڂ<]%$j};WF(hKhǝALٮ" qV$ڟѝG0ߧ`G]FBq$bX"d3j?^8{ݖzX> Z쀧$IV )p1j3I^W3DsW:|5tEE|׈Dfq)}]? m\vl {8&^L%? ǃEʫ ^_r)^Kܙa ppRW-KPS+p"CDQš~TZjB%w0dwuLYj4;-(ϑ$*?X,*0LSɯwzY5\￴)d9%To=_n9 7N8d zAϞ/G0ߓLGqǥq<zga hx]%-Bm݅Xq45{>p }xY ݽ^ii ,wuќkP=e$7t&!4 hZ K-!5n~E鑖5FR⊿YZe6&:α%ؚxi1_l]J F[q{& .ϓUD432&u wif EZ$ [xɺ W= o  3;+vH,zbHUwe E`s^\?:WBB_N ߳ YrQvE#>sb v\ve憆M"p5ѭCe%N}%>P_֕nC>\^r`siqܙ9O1^ 9w5k'aJ-tuFNF<#>j~cZ".r@ԏ6]< ȍ.UoL'hUl6%bg6}Y\m%ݩT%lw\v(HO@ENjrQ|flSWzBVgF"BlՌY=a` Y.Z)6!֡BoK|ʤɩyh?~sY 7CĹ_(T,:rE1"9k=}49aBnq:7 Сfl./Zx]Ǥ]ứ[p؛g#d;|Tsfw'pJ5v IKU8mowo@_ؓtJs[$]}20Q8ϒ&!>ׂWsk}lώZSt=5[2NȃԻΝےub1 L\;y+gWv( `nYg^-MDV!fM {k`ԝ\01nFg|WFu zh\ć~˵\ fzBmQul4]~YєqqWwXoQ hrzE<=Nz[鲌ð( g7Mkm#zq> < r[A /aa@Z/##Gq]T6eGٳ <49KVmBA\ȯ1d\6r.JU[gf!׽g,ܱN ǛF2=i.gRkO♐TZ@:ɓ ҾB;03~5=h,-һtnhK󵠀DL,>zAᐇRJ/kT,cʢV fa5}npwYaē`=PmB* ˍz2T&5FGKr{gLU߶ U'k>vǛߖmtbH iٛ\/اn|ְ7MեUl)9Ǘ‡ ]/4RΆSDk%}2IT!#g {zi{x;wĭ3hDAbrDê[$d|NNxiUx$HWCYGn:xٱʎGuŤU2tfN_/&msudPcսeWlgti-[1Fmֹ-049X?O."e_[TG[x | OxX*]<ەKz3Ś Z9㻤Xn,%.둭qm6'd>R8$KH_Dh2Nzm^hIS8b b u@WT:k I9ٝ)ڱT tCݻ4Lt#ؾ ~sN|;qkdГTɌ(5}+QJ 1:hSa6Y\lD\/j :9!ǕQ /ӻJ{,[?@nڤT iՓ3ljܺ0%: /sɝ"_# QνԱߝ3S:5^ԆA\85aBaIj-ވ΋">E@*G)*A,-.e9gj5ݸM>]Gb,>6ftWay I)pcCX61v|$r]D0eV&Sc!s-G`3^=*iz]gF=A9!;Ɯ?x9{&&f[$qJL4yÑi J.ۓpb ;1c7p51"d,`h SKK~K^Wc],;Q_㐕.p\j3JyfhZ utM-$ t2{?x06R`^t[ bENa/v)"R]&^*䗙௱/8@RrȪ:!*8Զpp[+̦<8 %SM{19X 94X Q: _"U+·+R퉗*2 %lɚLZpTA+;يd#EpZJe Qlͧ,RMP7]MΏ8|J y3KZfJ0=?f?ˊ ֱqlH.^O<I4nZ"?$I]U^Ns8'q=^暞F7j/Ȏq2i2XiT5 ĽGM0|q@i ǘut@800n/bz֧'GEAN%vA)4im: Td&sr-Dh6|s,7`ݳC3kwȉTw%<\p˰gV6[{ y3Hޟ`3T9;pZYj"v۸wl9pצz\ j.8:,E_*vgbP㡉zms &}̪򅨭X'?C^vԻd{G x=6k0be<VJ;/t[Q] Pەɔ6Ԇ9xv{gFnV)ɖtYWQssqqW#c\VʴA8'9FHoDa6+w:AR<<[x=\\:␍V\EiphKd0EsE"W,CVm 2ׁ,m[F::c6Rkt+h?<^'#,Uc?C|`drj͗7G&W[ o|T9],;g׵ q!&vE$ĕBs $йFnb;v|qr3>V=,~ֽ}k5RSu^[clP Fؚ}LHHcP][m#eK:> T낣&n-h n4F|05'YRd{eUE8c.^0.(yasd6 -*jm@q>#W@̘C`4{+h~έM*(SLNOǭBtk/!pIx" ř z ޾+Z|gE˪ʣ6Cý:H>.=Q8T3-:GB;1(vڼWc3_xBeFa*x/렂~@ݝ8Zp-@s}\Jr?soG棟۠^cR_eԆ!Nb۷ 6)pEڞ2RìZw%\>H-o p @ >H$\hn) 4M!N,8$ˡCw 9_ d\XQ>2 @uX@T'Kp@TU[;Z9BrÇz# VqpE.]1eb &^@DC=5!d%'=h\AWoQl_?A+'y}5.;ݮh1~mJ&ފ2lUo6I3LŖe7&4Ԩ'kcwrcUDQ,/bD7蘸ʙЦ5S˙n a?z $rqOk0b>WDž"d6 HuN7oQ(MhƜI·yS@Ɲw2_4JdP<,@z,0CoŒR4ݗJrM$kUVU17ڈGZ9Fb-C!jY[7[@$#W97N]f]}1K]0p CW)TV,[%fx³MxNEl$ < y;W[i YTx@Аz{sWITrPKp}`|_<,%KHGXZap'm p%s/z$~C0  ,-G_ڗi7Zn/fRd)=qpĔ1.^5ZfQa.q`K->dx.LeV<.ǁ/U^`u);b1uIΠ;AW^wA; !k}6NhhϝMtB >Sx@lqםlэhme,#1 :dUs""?M>(b*U}H=W8i@)G'N.jٵhTWID|Pj{*HZRȈ}7ej^恬+6+o^-YFf25*T}kFA"hhx1 ۂEV{S >N=c@'lG4e1R Ya*NypVBg>IGFqAk̨fm~+VA{[-w|duȉ"H3EzZ5<7Vl">XyD7U ;B҅6=ϲ7SK)ƭ.@^XIB/q`P9ik5P(lP(Qy ]⩄vܛH%fd~ӛNp<Qw5ƶT6vA8kVѝd,(z|4Vsf\rP76@2 Er ʀsʼY$k%sVs𜟹r6,7 cNό"y);MԘVqЁu*]h^aQP@Ft1 legc3Z3}<ʮURlÉb5,ǽY/VHHC+4(Iƀ;/iR;ej~j)Y8-Z]p,8%Xn.(]ȝH.;p.@Aj?lIK'ӄJֵqO_s檓)@ff=taz#f{3|udE%UJR尸jX袗%XEx%/᝶Wa23=yWUE[XcB>J\@߳9Ҙ}ϣiB6, 8*$"v)X3P5s}M!28ᝡq(_% GVkY A}yoRmi7O%0nŔ%=ֻs;y:#wV#'mn#z Se1Hlt5, hkyg!0P^6c;$;٬ԓ2u/8]VVauyw-qZ >裢R%W5#cqf\6y+&='/5͈ō;]@VsJ_/۔AC5?";;d~mυчoK#ȈaBv: <^O ,_ygi V9.;gL3"" Ӂ PRy^/&;P8=٦%GMe5#[l"u7_T65s4 R,W9476CCwkr~#_w!Pz|,׽B}}VE('w 2L<"@j)FG |k pp6׺c:@ؖiwVxVwÄqRD'k ?4d"TǽDVe F# 2P2S;q"73Fo,ROyY+W-abc+ݕQ0'+H<*/egi8"3MWwi$rk5;-O@5_VL֖h4ӿ=FBt՚`oǰ.UA*I;\rȜ}3gK b ;HsM hJ6,TĔ:<òUy}᳡ت0Sfn$tz(hɦ5\.!`F> +~N l%6؅ ={ *OmHa&jLۘiQOu23BYcL[л]P!¨taG/Xqv'5m^4h-;eh;?]vÛ!n6+tYWh rJYcALj&ҁ}q#~gV%G-2q%el4y?'TgW+- @LEU_옟RaQR1LZӯU!vH XeeE)\{/D,Gs͖قc.XW\Njzyk ǂ+xYµ[ '  T C% f.6Ը L,͕1ǡfpV1h˂ÚE#Ëj&Q&siXR|rIkɔD5FgCSqHk"Y]Etl6WEȿ_Ryq):`}Bِg aF5Ev5{V7{lL'K,F+_b!9 \Dkl,p ?}o;yNK@K Edx[+Z"Gcp]`t5EVt D9w̌|K7 A-$fK Ѕ ):m;`2s4q]؃=sʏ9. i'EgmW"V,PF" Eʡ9>)Ӓxb'`?LAF` 6:^b˒Pg KV*Kç=Yv Giba{~7iѪG}* ?ZKWv,Z{alwFe(5H1W: p,l{"LuaVFnj[td*Mۼ3F.i2rA'FPyUŷtkB 0  .:]o}%`ͬa, kZGQത%%YӔYu< 0f5;Fj0~yYIT|*Cd&z^Z nPGf*\͜K޼O6R78D@Am^cg =罶.N90?07IS+OVn t*OwF`v w-6f6N1Ys)&9  b# _<>;%oʭ5& \:y2x}(}LxΥ'>PK;}oֺ=WԤENi&o-!/dDfӴaӛkzd,M4m?rW"ßwZ 8u S=y҄]V"B!N-k~lIDԉ #z/ZIWVŽJﲛ[0ĸ+6ASj%O ̪fl ՝UKfɝ }Ee/ݧ.+qOKC(/%y02'Sw㰒t{NCkrmeIº]<[j%CtZm#qRՉJ|dYd81rޘۖfLԆ,:= S$gC.G {SsFAcHO=4*@OȪt`W5lzOY'BsP*1P36Xw[PMu 9h,rӟ>#&$:pm5PM1:RDdk+r+7Y<|D rxwE2. b"{Ŭ5,P4~RT&iyU}p~EHz߁ K%Bc&^ͯ];*+cuǦC´+PU k ǫ;%&n*2[xYX%` y 9]mjz~:8a["{:5M9S.D7eW@.qM|1 ˲ld_rUh̫>mBrXr49d-gZEnO>pYo.1dNFx;R 4)yrjPx`܇,\O;XĄR<3%2~Q;VD }AJ AǠI~[[wC=6IE[8dV5UWtǝ9?BBGܴ jQm;ADf=K7ms*myqd&;kH nLl PQzlB4MM%x.D\T*pxhfONR7s-a~Z@!TJMRZ) "qL&T1<,W[s %cYl`b l}F ,QDixxR@_LNX{l4~S@OX>`A ){*W;q{aTTQ|Mҩ,#^<., * J^(Sૣ<*%s80q(<)V6ŝi%eSH<~v6q5)Xt{OmꮇW)0U![ V~iA 5p7x1g3@JDz/dѴ7wgaݨ_MXQ-&kjO bKx/gub%#sqMA^Wq.b~HO4mKQe|Lx7V>7D 4Ηވq7=CBx]4?,V9f8Wc4Hk䡰-7rlmQsI-0*o9m_.1L.[&Ws;(Ft8i>b}B?IFu@1Ka#`K"ZÔͶOy\^wKKbzV6:9j*A|zl]/Y&(%ؐǶ0ڃn&E@h.?tE.LXF9H3yM!64։7!SS81[*ts{&)-M,wl #6T9v>}z#֋e^Շ`o) b?ˣ֝.M]᎒9r::-p*Ȓ}5Ⲓ$_*ۂ4+fuV?hFnb>MR-0.~X?B a Nm%.@n^@BJznyGomcSP@@D(l ~:4>.Z MO% 96$7$e«>o}b*3MNvZ#:[DBv wS I:JS,![/xwnU6hZ* a T LDu|2 hG䓙N>&2N2JQ(.zN`eEFD؞~/G FPʰqT?4rr8l4ߎ#H!aH`-d`QkAOEuE0Z Mx7ziG%NʨrbFg kPF7KfbB4kbPQ(<vlubFeuRcEI7 K+hܞ>}idI0`L)1"wֆxڗ4J۔gs0݌q/ihZRͺGlWY)/gf,|"wCʀ)~[ў]H.čsl-d$X z8֔8h,Ijޢx6$$tg0uu ~`Rl]RԛYr2!ȥƦ3q N/)+¾i»hrf~~VοQ_ےWYTekg()bx;ƛ?q${zCY0zZ.hD,}?=c{ߴ]4Y3D#,g '4Ӿ@c#I[=j'S>|d梣m~8ռ[%F8šc=g.{K()~0"M '!) wK@Z uSÚzMO96@)Tr.esL2@kf4@P uظ88h`СI{x%Ik֎s4fU8]KB<&Jy  6,?gVN2Sn]m#kO S+@>Gwon󭴙bƋ6}M'@"Uʓ-(4uO e6Nz?u~"t^YDF=Žl͋Nv˧=k֮;go=0^?iH*)+?sDxw_ʮ١UkhBuLǫї *"]K7FGrm"X$yVD*3 ;ɹC]ıu/sSbkdSwe3gձ㴘v..,nj JFsLJɯx0Fb Mv >KnjJ`DoơZ;6RMl9.屆Z ꧪU8@=wW/bvan&kp?V}) ޯc<lO%V[k([ E[Qƀ$[յI* | Ţi 083ekoj <O CC4W ^IgDLISN ϓʬFXGfA8ye~6^~,&tgkd1Z L:HNA:Ѩ#i6OmP}_3F_:-k .WAq%a_cUUEBd, r-O2 LmZĵit6/«t.5M\I{ܝjc[ZbxR. >< Ӊ/E4Fqyc6@ފA:<#!'o"ϡoIW |.oW$Tꍩ=5`˻QSPVk,hxQɧHiy&-Qx*8yYYGSfkaV 꼰,yIAҭc=iWحڢˑY[,7HeH^9祒:FȘC8GxbQuN%5u^D(T;QG2b`6g5 A0[;F߾,psBָ frM{({TuG](Qޛ>x'FUĀnIކ:)JE[а9h Q:Ҟudjy@])0BMqedɋ|8b5!Pe7|jo9(wǻBi$N?U e0F 5<ϖ7T\TZmT|ν[_o?Z" ::5eФf?dpLÜMqE*y:vlu#5^2&N7K9﹥(ힰ>xƼyX;7P#6!Df;*E {vF O{%3c;мs06,E65|…Py6Πs:u?Ā"K%^~#᪘7f $өаT+PCzʧm S 5~WӆQ8g\(IVNx[]=Ѡ!e;*cz:`Haz5Ω8U7?ʃq\cSo76{{\A)]=BzvoK #kQU?fEh"ǜ5_KA+8;RpygpVi)N\T0,~-h0`M2eW8zƪUZLMSuVר DY.pW$"# )|ٻ>8@7tnb%>ĭMCެՏa7n >'cX]wFdbkYYyIz3(LFQbf1W9!"r`[ͮ 싁U:#)ZvK)yΆV4"mU#8u>Nd U~>5q{nX13<@ &ۥ7= ]&58bRa  :X+W jrE!lcnx4|uR<9nEoǏOWn]ߋ'l8`oղRsUH ̹ɍbD%F:(1;V.'=Qs蕅B^{t< B@&>?I,PW?CFHo׹MX /pmQm`) -Ps?@##,[#IB"}mAY]N9ޥCԒ+Q\T'ͺf۔w/+/OZvbWt, !1 ]G%`hU4off3P- '0\iDusР L4WѼ>T<b+|PLߖ==گh+ܞ; $uf_*bu~g2@8ߒh!;3^J}~? ОVm?{_[C2TW?kB!CLt\d75Y0%dzQ&M9Ow/Y% E$1:K("PH_pm!>Aމaڡg=Q-fiơuic&(m"`QpKjV IQVϰ!5zH9B;S+qCSQf~E)21M e6|辩q9 W7@Տ++ T'$L^z܊.pCD§h1fN2oU0}E"=ˤJNm>ghc|f8xTJ3\B(Ȭ?U, dQ Q8* 5 NZO6"ʎ r04T^_kܳċ\H[A=8|MAejΥzD uxc7'A%njZwMPؤ0hw.f, SR}1}E@Z+k:)]dET\đv~NX/g\ fikHusJ$;`ߎD5<[dtfL@g19ۇ ߻,ٌDNqEH2+G`HE6-d Y0?t|eQt pyA&(myR(0:ga AOWr3,~AszLC@gHu/#ޫ}Yi[PfgL,ΤU3%*e: {JPuq&B pe^z&첈 }PdRp|15K@`ZR8׿Ǐ6dA^_6gPad#g=̕Fbn۪erT u-҄DθQ 3i`8%hYZMU*!^ ]z` 4vZXd~rnq)۽Gy9d\^xXjW};d1vW >ym Iw-Z2aᰍ+eh?sd">#_,漬D!Nܶbp[ BE_Am![`i(4OA>~VkYgՙ 0:Dp)&͢NZa@1",ʻ=]m5ҝGbq/0[J._&)ѱIxV18#f(>Y;,y#< ;VS;+ &~'](&N0 -W i(btؐ5v.ŧb2XRFœR ';)v?>U7"sشNܓ宫bK0;8ɤM)EvSw,Ae"o@J=uk pk,irQAɱ%Sci`n7Wmdbش9xꍋm}tŒ_N,psu^)+v M(aBx{e4Q]w^!wz_gh l(F@JZ]/%Òԋ1Ok'p?Qq3Bل{8܅¹JCy8ahD&pu!KU'՞kHb\Ψuh3JXfv2#ݛ]g P"Mw"{]]KZb3X?P!K-H nC5¸D,mXmot\\'4T1h*AUEζB*{6hèBZ Wkvq_C2y=ߊ L_^دdDz7O5P7҆ԗ2åOꉖS}L %bSp" ŸS$ePqP8&rx¹xcLt ҙr}h' z$DW4)دdsе" o`pXx~g'񶒩.ĄɫYw݆d1L-:l Vxr R;({[bgd&f~ۿ{a9?̱X!3/Ӊ&F{ ^gw]晿wH5]YTGn/R¹_MONP%z~kl~KE8"Tmu?NձBI0]BɗP}tkX҅qfEDLz7:<>8 Z;aIτNzy kt] k<0fxZ! 7E;}27G2޾ԩܚzUIN,H͙n-1&| 6^OP)fϢ(wD`>,ʧuEYrݕSq_nLIVDg$Lsw{#818hҙ9ղfZ'@N+`a^q# ѣT! 1ACZ@݉ /-.TCN(wK$mSF-qqNT` I^!K >YD6leA֋s^0OąJ348}*oouzw$yIp+#.;5279rCwJM:9>dSY4"3NuT6f!3o2NVWĭ§ݐqvHpӭ3=&6C\l$ȶo!~apqWY+]P$tA`*/)9nu> 2 `sI_^(?Nu_FxBދ8\(䈎A^vlşpuJyB};sbu9"Fo<+vFbT=75 -83̜A=lv͝JD{ܥ*؛.-1ʠelȊpZE 'aɤ֑5ϑVr>OLJDsTXʔ>g-9ZemC \opKt0qj){ayZ+ y 5ИIz9Zt8/WҒg-BC u8eKB~>#)T2j|Fks8Ri;9b$lK>&7 XFߑ-֗[ꨅZ|kRM?1TN D[pAX+ kKn(ڮ#|tmabYY 1r5H`xWM5iLC1q*>^gzӦE`,/ЋA1~26 TN_* nƑ,3|vwZ7Յ;U8d-zɎw jg&oS6P%ZzgNtZFl(Q$GTt|U+x[8;'YAj麶&kc0%Q(Ygv#e߳0 o.5[PH̽Icx,m ̸ޜoMX$FOXfFmdqM ktf#fYV9XIO؛g5Bu,LώBD=ց;;kdQ6_Y1r!)#59.‹ևYfp} lU!bhژ'Ee=bd.VIu"c5?}[߃ ƈDA y_u*Sk+rlFMw.kX_EC;JP 7BL*Q61(2vtU poYxdAJ3rkӛ˰).Tk<Ʒ sJ OIiwm#^#|K7338є$N^h,^n+dH1"W n>'wHJngDCR>{=_>|RJCXe1j'c *3/jiiSa!i' Ffwcamϓm ˱?0U ޵xi**Im xϑ`=՛_t>Վh{9u5:N<6E<_VP.t36tr;%(+zGJ47@!͈-?YyXz3v)mZ m2%YjY".!ENnDz.h*IJߑBNj2YP꜎Y,@VNP,A1F'%*Nt*R8C2n~ c^xr5Ixe]q%9£0f>~OS3xQ~n@ ,aWk$ T0Ƭ^uBP \6Ъ@8?? f@.K xz`.Iըψh;R/̤61CӃM2Z<ں{!]asԓ<ȫpGr{N/,"ϴPU`>^PơMͱP=w$׎ +*eiyFͯE@FxD̈́YxbAIgc3< @/0fP-,2Uv(%|>.𬐴4=\Q]r;k(RO%8 }RBF 8 /uzYf!9!">HRX,,*E-]$ZR?I2j'Rfu{c1;JݛkNTn8OxC ++pSwpޥdEu N+^ڮwQmk)Y70UjxZMwc}wA_č!VX/qχmׯѽ "5Q'T7Ӊ3 Zt G2m%Nii,!(J[\AfUßu!Ǻ6POgjMqy*-ۃ uSWZ8))4\ ov}uV~ڮk#RD5NKۯ 6]Ȓu.Ox.u m+ߝ_KjǨ翹(5⃡/Q7扖9e0`ß$`KV2 mázQw2dvmb'DNQ.[i .ϘJ,ҍG{ /N :l; 15@}W ;'~x 0ȻoPMo{!ֽƗ+1 -f Z2~DW #v%EzN> $ӜRSӧWh X/c9P. ⴆ.4?%k؜Aal$\πMseխڛmϠό_#יٸi{8@%ޏRTS(Bd{2n8[Tî885y`h(}m$w2] *wH2{y.v) x(, e1B՝)XyT/!s,_¯ ` ik/{|#ٓe9cf14%3M@t;9~Η OXQPKnՏ$~I1=[}0(I#4mt,Q$Y@*2|?٤:yxۙ~)vΜ-'xJNUˆ+tha3+akn'=_/ۯؒs$8. @E@p@=R\%':m֋kbQg.E%^4ӆsK% LI͆. rRݳlIALzteHclxnl;u@x1:.bQv܉KX|YAե!::Vbv~!)7_(Odst_rYp0ƈݘƏ<FZ˂Wrfɬ3+r`|Rsaq! k뱨b{YR+4qt*?ߕӇ?2=x2WlC DoКu3OC_Ѱjt3l1ZnCq+ech­@?b>n:]!ظn,!$Z;ՙ%7z6 -U'00x:.a'ya9U;c_D5|<$+G2qq;ͷ͕e&EQB4U<=%{l6`OwXnu&yF)O"hwykCo'^ed=kWLO,fo}IaLmqƜ5i$t$$\a{0jCοT쾙d{a$%9.Hn&H(y-!;9ףva:y-*Wߗ!Qf{؆k)u0nEG^ cHQR߾kċAbyҍQF~Rp졜%lkߠi$XjDbȥb@92,\DyvK'\KXwc fQ'TގU +,dy\$ӝݘ $;~x'M-0 Ur$cwAl-{׻&o#iDÒ޲5dTݼBDhBGƐňͺNi.%{,Wb\܆'4Z5탺NGT@\el;qڡIV#)+$u0tb5oXJd0NYܻQXg6YԫVj!lɪ,Kesi+Ǒ y>KW/ u U;VE vEʣ, Bg2ZT 7n:$M'InD7{J৷I*j{nڗRnhFI`,fqa3KwzEG,WXZk:.CƇSNa)VΜ& i`Ճ煌ct#-Ȋ| xx}|(UۘWO,S芨٤fjo<ƄhQs]@mOa7RNDz]LlvNy(ז `WC~B|* j]r ! IIrSXW\a %"k#lwiJqB$1GOiŖM놕t@@h4j |I7Oyv&SjB!>Ε7<);PY`~qwkpǕYv0z UXD~KbN+KKj)1Hul\KW"aW߄7敻̌DĨ3/0J`.$ʔ ZIW*{GPh/y:4ʞ, ƿM'|ЛRKO!iDJ߽Up;T<$,ΘH+f0W)# )Dbnj1fkNgCC\]Lq>r1lzyN|;(뼏Uo ?V hQ~ ӼQWAS}[R&6ԏ>oJlA4!.&u_'5id 8or}PEn|ׯC[2au-LG1[voA0+ O}I*mmmǓ~:0?$s3zW+߮ Sv Gwf4l4L}X=#2PDd!sw/G?+uv݌F`]Лຶå?"'3aðǽ_,m57OнYxd{BF~\~ޯ#eȉYg⎛؇dHXElkRk;!nn=yl+$.A}:P.Åw['E30͟WlEr% W8  #1GBuA| _AB E=Vv @bdW .M>s|g#wBC}ɸDojT',YК%P; ߵB7ˊbdP'1,%'jlN{%ȀUЧYbIqwzPc] קyhy`;+sboK, c=}ǥ,*-//5$uXnES4Hc?HMr[PQ`' DHO>&#Yoc\+.QuW4H 1CV貕Vt:="m ç'/Éz,R1#)l=Z5 ܣTދ!ۿinOjɕSDy-l3Y1#s' %Mng~\xKJ萇itO@V4^ ꌐˎa AHzUDdz ~̖Q/*E4u7ީdtŃN8 </+W*aO$W3p/'Cb{/t ,Xo@X9iMٜq'nHm~\pt8-&2WJ _I}-uk M rUVqS͡ᇖ2c듋#g' 1$d'遝{;:(OO;4| #k⊭ԺEi l=bz5l+D,NyHA%՛_yzrtmeyF3qT@} UI2ց"_gis8l rQ$ae9%2P҇@J5Nj/oĺ_=ᩇ]ݞmɫq f<͸P16xNQ-L1P"? .M l )'ۑ~4:E#jVO` ’s1f\;Znݣ1n1h7 k̵U7ߤ\E#z耈(6bx F淑nqDc~J&>*° h }zee3Ta .5# LW tȹEH>Y~fx^z0JY=#I5.Qƌϒfg:J =Ʃ UQs /a3\`“a](-HWJqjR8 nOѳKNaq:{/M$jH@6;rF ooT{ɺ@[ܽ+&k_073v<bLتV4)I"8ktiCrA4d Ѽ>-42=}%C)*OH P GNѭZϴg@%Kl5ON]0>#g9k}nY gWj*T<0g/i9i @f>l * }QRj=(~XXB(tME rCB&/ltr[Źݵxﰆ@S!ݫ9."i7򮸚E_vZbϻMϺzYt&oZE,Gθ+ nGqjr&+좚d%@3ke'""r;^Ֆ6+7zN;ʍw┄[d+n;SfAl &WYŨ|^8hh-O zUV@.D m~SI|FCi5`mP4[>(0)\a&).+{6;\DEus\gf Z_kcqdTz?᪋B`94E2m3=eFr` b;,ڢ2T݆!K OjTvM8-InJ7p *] `5aªp%"Ou?Q`E246WTV-fq 4!z'/$m<,A4:c7%J8ay/Y, [4gđ n]䨰 {S`Pk`j18NЭ)i+W@Y-/K&o~8̋s(-TF;htԢT8S㗙f+ruAbxHS$5"_òw_+z'׆_M 9JTulO5qkghjؿՒ`X'jiCڨ0Rz]5jzo3BF( ,lF%K!=֧fK:Uf`f(lUU@r/4< cM$[7k0QFpcSΚ_O!u,¤gƆ([) fRN 'A {+,uY˜ZrgODD=#B ޡ$ \$Ւ1V$U&$ #Bc&`$UԲrf̒b!.0D2F凔Rc}Usk-T4֩e=`',["PDd>0V Z _yX[ #2Zy2̚N`Nu ҿ7&t$9_LS,? "p9>6Aq8f(._*t3IXdQnUXtIԖ<в_{LOCMRIܢ*Nr-@*Q@tۉ/&zOPʨU һ4ҝH'!5rY@~[a'Eӱ+!RRTLvc޻<WխqV{ߵèܓԳ"+R+|05-`=U(gd*E6̝kPzd['2ޟO2`f۱ANĸb@1m<̍s_5U'vQ`H r:"!:.C"ta[UO'i:ibK2JCW:(=9J !~=Db@UB'6rN)$̐y! 6qiJ#߮UMl`71'Fг>w: Qo2랽q2Jm!Jb(h>o(2aTuY|Rܿg{mg}?* =h Y[Tn4#GJ,g&R_JzV rtׅo}d+UiOv<'98!aI>'MPj#99NG2(WA :{;t{Qh?0nֶ|2wn<rI^MJd( (eˍ>snz~*#,4 |sPrUL%HP:Q`m2K&leWبǽ?vc3rEyպ%w/d>ݔq ިAV?ToJxhT' f}c3,0'AxZyك{_|JKhz !ZL's R&%z"չr ƥ5|R<.)eҎ}+e P2-#qB:DQx,Eg)qGJ,j)_Cpd_Sb934El"tGt9(BkO?(Y?6q~4')en ^Iݻ&AI7uuիv^tM`.B,܍Ux(*l;cz _8 mxt  tHij>>,G` ~zӂADbX^yDCQZkCoHbtV8S6ft kw>,7KQAbn/V#{O~)sS גg_iN I[ZNUCA0 &YJɯhfCj. h*c?n)QE92 `ňB6`6k)cа{t+P7bKhȞ&Ոnߙy/;1eGuszo5W= kFyKn~9hϴC@ TwsQQ>(m-(qz5VLR&_,Djq-_COj[Mt/\ʱhz俙^4&z2,I}N1k@.;g?Z eI!iLm4y&W,A5Ns} }10%u$VVgCH^-* KfRB#t#j9>PFJ-䙘ebˏh'Yf }|Uxrɛ/PM˷ k\*qa䗂YϥZfNl[p.-,VRfNF%VEwɷۚ&,{(g|J^ϝ ?v'r$E Z:)r*YLnsyb%.3z.V9VrVdǔ|W!?HWxO{X{$˷~h촟N!fD LFaյ^@iR2P0Ԥ^xiڻ fiIw>L\22U~ѨIJ nJj2b(!ts98 !H>=Z9Um {)F"$R=l -'6{E:Dm.#7rwVS峰on ikUʸT2080)=%i3p *'-{ʇע}֒g<̱,ebSĆmŹui+?BoVqx1sA޼[f5fP=`"d^y w_²3of'#$<ķG-Ot}i63-˨|řV+!YeN.^T$TVjd$.UwF40_Xv&QjT T.ЬoT?}̶:g`1ޠk&~h.V-0{4G6g#M{X8,+ʽۚ K61_q䗬M>^Q$l:hb[!a"3:vLI!BYrqc"+^c~K?&r?hUJ7$g/9davKr~y{[b+RToq;9, e$3Ô]X5˥ q-߸>^ C ь=8 A *\lo)j+񟠲{7j0 A/ק,DM%z^8YoӸ4)idd;ql;HI$U '5y{};W5Pub2@<.Yj'G`kM1dxƋJk$ Y(L`%y7dg$UP8Z3cZ\RGDstF [z&|WK~AAWs%3f1~t ?Q_8PSxUǣ}}xQPHf56#m(d\ϯDW91eN:}03!3p-&14+_T=>PkoEY<F VASLkFJ:-Q! (sm(I _Qbü֏̋X֧(wT5”l ֖=Ly}5ѡ+ƌ<]uQ%.d0xoIy( \Dwlv1p=7XrpŃeba|K'+9h5!?K:RGI[:0J7|1^t#/~T΀QM z>΋huԖ8|X%|fvz{<L[MrCBiou떃rL印+xCތ%F]TԾaګ ZϤ&eR6#"|@mhIhS`̟VCZǷA¿6nsj'q FуmnJ+Cﮌ}2'LÊQRv"ϱ=ZI&aKXcDE>o]L?W 3J||Vh|cO#:ڞT|e@D1NQ]K5/o@wA )R[A.ԔB lu?.Te\?ʝK^{emH0p\䮮E9Ԉg. ljN-<]3XIw>"+YeMW1/&%Z3u`*=_c^Ó66Hb* h1M{Aqɯ!a\ruT|bKDlc=$kfVJ,@˭_6(W#*8Ğ8B벻rNRiPb7S3J9OIf4"eIPx(txhw `LA\q3'+yTpSrM:*d8?~[,7Y*d5i"tpdjzLU]m$D(&/4dRd~-mR^mbK1 ٙEع p }jf&l|[˔Nzx95e O0.>MFyaЕgLp (J%]a Иp]S;ی&l~ՓDdBT&1h ZtKֹR%#/ҰQ~>;GsF"`stpv)  \. b*MmH>E; 1M\$טeFGPk9%2)eј4]i wo 2-ѩţHڰ t7^{ :B6f%c}Ko\olAl}k~ܪ⾙9R[3Q9X6ja`3SAiqH٢1O}- He]kkc'+]z ǷaI i̾c UÁ^`>D'`WMFoF&xg>]|wƎLoc%BU@B> kC"oT9gAVR.fmW[?xT)}vHTo}hs-jva>3uiEu'ŠLcvc))B |4@ϭ'ZY'xw!}v(> sGH ZL#*$/AGk  T)grO1@"r{YqXf\c dŝna2 >Mܶװ/ȞFD!1[Կ~ax~J ̘$4/e"xq) UTd`3ChA=kAP1g?b(~. rYp6.TQ˒^U~ w2]f{J/R b'6$4ڍT9"&7JfKmZPf4Ik fql K[7_NT|byl&Zl'O)r g{b>Zlx$)!PuQG.C-&]#S6ȷ6Ճ/~ޮ0_7LJ7k7~RI#ऒ%;wFվ)q];qKOĩ^!2H$зSƚc,z%)9i8K(Uv֦>M/yhB W)Px4vOx7ҵ~>@8[K~l\VF5M^#5w x]!zeL j$QU~SK:jL܃-t>R]bW]nK[۟+GY_(1zpq[q]_ Mv;j,sͺW6_AvƣP!=|̳Ga`H99YԾ+* gZt.B{چͲ<*~Jɣv$,+7\w{{A{dMy Gj3zh0E2> O 24z9Ar굉o~H_;d[<$SXOӗ\3.[Ǿ>7;:zr`cJUO8ѭ3[ t<IKM B‹D㤝ҧYsX,#U4EAZܟ]Iӽ|+BAi;HvYs[gTs!i.7(s|yڸh 5k ڰ?oө]&jp dPUr0Uچ.T;@QZe,\CB{*d'&vL_s^!`C1fK#ۚ{S2^]=nLzj0SBH34@kQ[1wyZ/BpJE HG%"n0L;t԰WGABX[;pm=El*S~+ SlIsTej轟iQf[R:PO({ZT^4X=yc|Z^6`J486jṮ҄cuSC^i]{~d]a#;a(\R[(~b/h聜3 Z͈MJc]v645ՎSv4ޛUƿ&6phkot>itdgi~}툟 `ϕ(.3)>G%nNMa$wg(hWQ"͇Y9W2}q蜩z/1/Z蘙VYO5sJfH[D@;mmC?axe0YC4~$9+S1|~R3]R1|ƻ1?9KY 0_ XOuZ$_Ni&*t"T˳syN<^ [ǛvG\ScSta5G˼Fi+kgl[SyehIJz ˲YXݫpc#gf%t٬[ϫS.lɶ?,G0Py-NG ƶ[P ` Ȍ]h!E%< .844ؠv/ǣT_X Zb t*:ptT@}i̡T|)vxywЬM{&="<[=5"hab̞q׏2"Ф{9?.tl^hK͚4,W: !mT]uϨWNK'|~ ^W rg} dJ/]]tOYh}j.Hvɾd6 FbV M'bh8tis 2|Srʠpغ=Y;8!&iXegd ʢHw/; "ѓ#UH8pZFWVM{U>\ƂwdŇD򦸻Y*gҤ)*j;njՉYz; %:bC'&YJj m͖ՠ>ni8kos e$IiK {hYIoJĺŔ od f!6aUBBnL>6cjFŇaHRm{ g γsF"{Dek ){~~']zx{~Iz'( 9g B'$o;5OAa*m &Mcn:p"gSAy4*sr*ءv|aWʙ}V!A۱ xZ⒠  oޤP:R֎&0@FQcoyN[oS)u1(@2F-s>S.Qa#^H-?Yq5(3W뵖''ƾpT%6 _7눽s8E6›Xz6Lh9x$q"\,S{4ػŸ> Mќ<3h]6h'krS^HEpRB|nۘ92*f+]xYYl7L#4r֮(n8n ݭ|P}\~K.&lFT﷿;lʹ:_>W( !JV=`<q=OQvsY76Q΅gbb|KQ&lN>;AJF66,kk gC8nץq-H2 WkoFӣTjhpX?5|q`\Ykz!Z\F.I9K:=(}<`\՟ST Ai1jZ[7_ u][2'hD ?#11?x,6_QȧQvEQ]ezM*"yIjGx{cL|ǽ@|M6RmYIèva}Q$TtZԴ_<{OGNu/_|7ζܴ:{f5ȡ 6)%U Og6c_XG, ]̏,M]Ēx7oûVzȒeyB` خe`~vm蚄q? /'È<3m!"s$>zƛrJ zұiRfm ~6VzxSԈ~F/a n,vrB*^%p3| ǠU֣:.meFitx.P2VMsb WOg--Gu\]db_)vcps-KwO0㑕e_ak"ٮS {Vodr&)ů{ SDzG+'"un+sb(Qj~ jV|v/iE{hkh: Մ-(bi }slEU 5VgNXmpi+8Dȇ=E/2n޺eRk 'a]M|Tax\nD¤V&b tI }"Σ*oըvm#D 8 ㉪Gm=4;o2I5HMkɓr=Lua^͝I,J6tjE;6O||7|mq;vsA0+{GbL](lܘ6͠{Ʉs`LĐH516 ./?|NDN9Ur\5_> C X^< 9"4ȡTصL{' 3:ǡf E3nWIܩU'T[9?i]IL@كXIjjfc 6Y1 )sT8me$Ơ_BZվLc0`Ӧ)O;*flYߢٰFVU:u^W8)hVD&`~+"lys{.[DiV@˱ӮJشR8M=bn1H|_B"@D̗rA&JqoĮDQF#@fTÞߓH NVMZEGکH]v8]"< Tj6@4uW93Hʣ§RQ zRSfސe]9x}G$ᕣv젵ǠSEfDj*=V@n;0S},<žDžKMfл Z+LÕwUC;ׇk6Zʍi2^!-ți(5$E6uBd =k$ \gEuNwb OzN~yWg Ҡ\6 L~yLnAͱ  ,\z+}-:(5yp- 홨O"ryNT6j¡dt0Vhvɢ Gn5/, Xu|bJU9dcFHyPRO0gJbҪ*ႁ M<7A9={)9g+)?YLI/Iw+OѲc-֙QddڙdVd|,<7ZiglU~O*1'籬ƃޯӤ$ake2&\Q1YpqӻlxĦjԃ,qϞ K& vrl! ,R~{a Nm\dSVNO8څZ]6ih6n\`??v 'ȕGSKä_’boXnM\PƘ^%{by\g:NVDÃʸ`Z}KЏ{9ɛaYniX%2cJM* 8sCO5AwTKJCƱo}r؉>3@.}4 >x %v,)I?R:o,)cS p *{eONYE]dکk< ks}9oP0p'- &c>Pw"ZD}a22GYek H,z&ͤ$e "[z}ڧ"$y(tijVTl}7'_jCV7z_3Jl8V֢_tD$}JX$3o}òGϺ-nb.f<,AEĕHÆqC#U.7{vZf(=n){p֛˘,vI3Z\To ?\g4VungmA0nw)L8I0Vvtn ;dz|9y;cYfJ%ҳ&HG>P/>%avw\CG%B@ U)@Owlb3I!XT Mӥ\#`;,$k-eOf02q4,@&'lܸ/df1qh:\ d'f"}<= 9jM`]L27!a ,ྱ` ,x8f#8X ˜۴ƦXۆK]{SM;-mbah @DFږoK ){1LUeq g:vHlm^vk;fJXE<%J}7Drd-'՗IZ"M9[#GN,MH&A<7 kKZ n5Om|Bv%~H&N 3`22(Wv9ŒU5zu Jk[EnF±wi%I*Z l{?8J!P.?duC琖z`]NW]@͚zFf2Rl 8zjv^!mï") %&. /],])aef}=|;Ɉ7U?iV^̡@T]*礖a 5=VBou*|zk*> ztbݾPbSckɓ:%n|MAV}JeXr/0µO/ŀ7Ѿ5eY]F.[^e9g/-lc]&[-hh}O;5CGe~2oU,ҏƸh]{sD$ٝc1%V.ۊ#_``P U pDC|کQ˞e*21 +Z|'4){-γ )f|\!>*WlM]\Q9&?ls(IzdckE*f;=FPVQ_4蠖h r![R֥4u[ nO)R 1+#^=,4~crbWZUErR:~(uưA(yz92"ZZy[w>h՝.hG~HF':zΌ| ~ˊ?|6szJw/"zCI yw59.M jndgjcf|%y`t9b2T6Bc#wt9Hݛ<5 l` 5GY#a]?e0idn(fnNf yzčg'Xj :{)raΞuS('ZZ6Jbc%a|]0Y<e++  @jeS$#}Kxe]F[ $ ~'.Ƣo%˥:&rfcha8h v& B"#9u=+\#)آ\ ijg8P^ā0ɨ@˾ʡi?]1yLK MWZ88闤?E &CN7 & g,?w\l޻YqtsR)j#*6^15}VH{. "~VAG%)[܅\4Q̯I#Z=:O@x\AYBɆ T43ʽq0ĸ8Z\mo6UyA6aq,Ԧ G'qm !k,sݯ7w=B %X!R]).؟>WJeb5/gV9a3tҰ/0 blYKapzndFW6UMu'@4h%t6:ⷂ-q%2~:1ޑ\Įq!$Q9L c[N c(%ԑFE}zN=ee#[u7R@E¾fSL;9PIf?W;`.%LʋaRR~3uP jrX1 8՚A8(&%2;RWj^#gz wEÅU>ydXba)j~'e^gPYD~ lZ1{i1yiv@c6|S d]l7 CvkLYb𣰃rdbHZeO“'z9^<y *.6~#Z~ye>D@ 8B-TƃN5̢~_ryk>^PVO>? zG\:\k1USQ!: z-ᢒ㢻]j7^| EbiɑjqJ#vc)fT o(]{0bNb Uf+7* IyIFp7l,cBb@[ ?, Ӵgi3$.ޑ 0qkʸȳ='{`0"(ʩo[Q/bTUM'p9.ǓSye^dk0U߮;Qlq)tQz\oC biCЗG8Zw:}y,H7=~ŗKDjfrrɿ~LAxmqi1J"?=0_=Kܥ?9Wym|J]H9EY p-Y߮dq٫l |ϳ#7A655zԺvc>Lo qfgVmc.Ii!AFިSZR<.*݊ܥ쀃LŽ/nFA>/sttU|yq*G*);/ Y1 d&V)p>  U$ikqy(0 Yk8ɥrT N98rKʭRe?'|6ra\c}q=,ik^[jäPM+FnAmSMB RoBH>w"_1d\)G{v?}!,w{?+*SNXHr>:.:(EAgn*c$ܞ7AXDH{-ƮD+5iRqڛ6"yc0#֥[`^3?@ )RۋVJZjoѷP B.FZ# ;ǃrySb9uh#nEza, XlǦfg_0UZ:(GT-eIywHYԩe1dHb% 4GN-?*ۼ-[<{sMSMMN> 6I<¨&g;JH2&\S¨^ɀ6X^D-س&0Rp"N1k|^ޣ˖0:NDW]V[1c$n\t\t^GcwPzgV^\KVb͡EYC{6sp5[O+Uʑ=7yPT<ܿ48@ߧu4gI{3Qq3Ad9xUgʬY`~cZ߃1b`3RX-3X!PE3*G^gsn.6eqb2Mn.[S0"@qj@x4SdHFW["^ &؈'l?cb2g+4Ms37G&>"w(lhkfu̓:yZ .Bs45 Y]7劶,՛aޥ|GY\*ۥ_@ECx7͐ xe'.p3N3H?[ OpGm`0F4Y{4>+?Op(jZz)ߣ1ZAD)vhMTcдY8Bʬn;=:1|<\# 95+26U3^q{Ɛӛ x~z UВ5Bx>9&er+T%h~Q;>A,,0= .ycZv\߬tIOmT;UgȋYdjJ2Jw{d`+6I ̀4 Uoc%`Hg5:xJdD8Wc hYT"2xW$vqE9kI T!b/Ap[h-uH~k[5bQu;dB`?Qrzj:^$-fkD//{Q+4j&`9huGE-$g0"w#:gw|zMtz1SgX#0вW햩ؤ~ vuqw.c~ÔW`k>mSh hYUQ=}*V%T\8&,\\Hžt.6ѲЎn4+wf|h~ѻy_(iC D3^@ϤM蓠շv5Lx[Ր$ |@Sf̔[k*U[2GrL,P"7`p7jL~jyP`lZb#_Iܼ϶6qEAss < yvUYa)9HKvZi]X{}>җ 䑒gJ{,a^!JLl AFy*(S+dz!F]:g/jyF}2gtl1X@*im|ݞk ZokPIgc~g'AZG(TG42PulX,ɍNc86|auOoqVaaEɦbV(-QΜ;L*h*9l;lf6 aԒ)/PI3G.",.669؀+Kr"߃sJ/2 *&4=?%y4l Ե'j~ko6"ڈ6]4 ,Lw5x_u~LɚS/ͼ|LЀ}hGӆh7U!f(c8hC# J@|\r2[u^1ty(ᾤ"LLFo"̜pxn/[ C9IM_3u`uXMw $WH~]ED;‹~v I 1d` LsRvڊ򿥨EyG-ql(0ͧxXBE \ݸ???֕'[甁#@5k+i!]6\ژ\ry~qH~7[` ;vHo3kа_QNH( sD¥c`Q[Z9|v5hbZY>ZTSaLoMַ}fԻNI\dEpI4>H6VC\K O/;(բAFEdtwv:VQB-(TpEŒ+;71ͅ!<_\a#|J@?>ܓRH283yuYKLʄ-WM5]ہŒ?\/c0+Y[VnU)l!2ygAدqZ~sAgIR$SnWI̺[ҜӀi]9-ڲL fӏU<7DS.|dy]֔T˪<|4.j/Ob9$2Djwb^hxt5zcb; ˂iUMc Syrt_!(nB  `]Ё13+?r I^DS}mYtBAT6J%nЃsrhgx`t5|bMn`*Xb7` M35-K! VZ+P4/)n`ҝCY'ϔftMICj"WrF&mde ƍڜi'rLRau{s@&XflB N=hU5^044CM6M9G{s3&IM4 FqKbA.{:IW-dxѲ3V.Q֘-ET\hK X A6+=R&fYNy+GF>TcE[X .4yC"bW`[v _~/XÍ)G)g%)P$>9@Xaߐi6۠r'PQ?k)Tת'`a ^/{rgm˃inQ'Q́$2cTB!a{<ZWhoIuc65'!t&=.ҍdu2޷Ījk']gqbm7)ZTɕ< J߸ܿ##7٫xT8In2r z5=fK׋ *d  ĞL0)@m7YZд,̊ȈCk%n$ՆMqtÓlz8h1(/ZLg\׳5 sFb-q, Ýa{;$KAC^4.EdO_w~% -֨N̴pI@ z{U>KU P=QibIk#%_4qukȑDaK[)fk셽ρ">H4K GUoC zO f3nqs2jAl<ɛ, tNz {:%Җ[Ep2#%tW3˨P0>@xڝ wJ+# sA2=JȲ+$v́0?ҝ=N6MBC.j\XYAg Y.etG`ХAg~͜NJTD+YQӤRe/5iN/m6s8˭7Pb;ajnB9n:2b0ppQ/Qt( n @Kz*34+dByqy&$Zc 3) h%/CsK.q2iUx6H%T* )0/Nu4$?é*I2VV W@?=ͣ :wg=05l{o7.IJ*@ 'ImZqn 5O BAޯД]t.gL?'nx^]}% Yd ; ZZ(e%+ Y_`B>%": zi#;[LG[҈Oس  1v|f-b(;MF`%{dۮgyxc.-SpC;WPKRJZA+@*LhJQ5FCh/4 =qBl2v{@:j6| p|vE,>ONlnCkpcF F^TFP5r1,| +9 ÚUHʈ|oHݺd QbB R=o $\F`n!ݤ[*c3on0m)~3!PP7GJYQ yC5!a}Zlֽs#~}lp1 q'@oޭ"?2oC W U ?eXWCqi)~C"1y6 jUS&* GDGo>n)*,I/Wf Km&>2$̖ 㒖~H~ƍA;('E)uJXGaaBeuf>8{WUr@T#^WAP-& uF8=/ X]m=]F{_q?#hٙ._oq@AԿ+ܖcnk0m-iٜ4J0 F8Ah1 oyyH2H폣ggZ&kf韪%ad6ALU Ѽ,@ hWس]ZK\ 4M3kWA$pZA؜ Jf۬V/U(9*ATxSv6<ؼ< Ü ZacV##^H.v{Gq= a" J*PB- gfW7vshmaEATE|'48o݃RHQPQyWe=OSm? Ia'8zf>7+֢NoAQ=̧RT ƨdvaa hE Ϭ nq eJ<~2cO[pY8L?:t8`9*/ Kae0JiocT|%.;ۯ#J5QKuNFGX&0w1lMB)IpnYS) 7?!^(xd|K{.yFwͺsw1OOk6ots*cPƝd_h </<+/rH ($$vFC}K` ^Vh񯂞8e ͱն>ljZ7fHng]YLul>R3 ) 4I@j$y9ӓ[qh$\&"C""˄ 'T߽6toofz+ \@ck/bJ'1>CR\qPqXwg]ГQ>P힄& ́VB{TXO.|FW{>gydM -><;(5܊3 Aҫ!-) BşLg֙uCg_BSGV?eĽF%=gZ!v <d|!{=)7=43^"'@xcJv=*agG  ж}$?0)_=EVɸ_yl>ٴn, MxY+@Å޶{zfc`Xv>/@H}t~s6q"sad *ˬN18?P 鎀Z#`j%J82_H/=sfe[r"ap`x5e"@6(9m n,Npjq=$̞L/G h!0Eڔ5%1LU z*bXdKȽ`~_ qCS' nEħW),=d%VL|4wdk0L儴(PWXJ-y)&!t]띕A-ٕ!fj=d~M_nqoT/(SL#>$&xXHƠ䀣WP?H =6A1w@/y(D GBWۇ _Er= R Ȫ;*gu{Vt)JBd۠i $jH_3GM{ÍoyKM;bnr24,+\ "SA$I -F" L9A`9𛒴WjK^3+:RZ)RxZAAZI#4uXZ͚v8"H4_"Ŀg<]k*GߍDXWq͖M84%ɜS1LvO}o{)Tb.F=6ٺTkdxmܙJ` F|C;tķ=dljQ1 =~nߧL8N%yjWpLxhPCABr6S 2f3)c8dcҠ)\-B*ct=L8s5`f(x!43m!%msA@o=[VaKpd1Ư,Y|quѹYb/4Lfc,Id$-Y)A(&"YD?z.rRKV(A0q-A{lXI1$jQd/c47vI/|C{q˹~05b6skѺY;!<\0[\IY{q'{`љ}8 `*]Te vǖ >@uRgD>ptxTZ  "ڝ0 6n'U dgnPF֕6~۾B0{!8BPT"]<}Efw/o.~ҎZb/Mga3 {ÇfKnUd?^Hi^:z"zOኔvv!$ڪQӔ+wE$b RdT\A+yWZ(0 @ =ں\U}wm2|D{_p iТ k\#:)ʃpFo#:wHwDM|| 8LdtJ!p7dk˯7X;KO jvfb֒߱0m}a (fW?raƖYf# [ QW߉Դr/ꕒ~,0]w$u`*93/{]7u3W%әih(~oTXS+.E"U|fi<,zP9%Y%4A%RT_?X@a+ű{oF@&2&-gEIIkVrw>^ o%sHvFcWv1w3j]/hOs67|:S^N>E4),xڳ =SEuIe.r ۋ`Z:f\썡p7x@[2~A9h4Hڝe ҸY~A*bYX /KGe5=(IݏHџdŘkxM_G ZĜJsmAc㣽 NX LkXo^6O^P2lH30F`JsDZ6G cjϟoBiRX:rYOi3n]Ub;(,z훪r;ARc˔cT@a~# Xcu5TQn4'[Ƽ[wqE0n;{Mlܙs;!Ӯ!*wuZ6i뻔K "S?%{nˀJե6^m]8Tw04NBgu۟Ơ`U{1g;pSYhtaϪ_;HZ^F"Q["Wy$b8B4QfVW)/@v(e)fO";nHHɔ~D i#%+gÉ8v Z'JYC&.ʘfEVgLaB6bgAR[kkP`qpulSP vu"<U9WTu7{@ET/RF 5&9{TϲՊ,Ї5h'yJ+ kpa8C0<$\)+ÝyċD0(`KA^0)֐25$d;(/5ʵ bi@"Ѕ)|5FxS$+0N՘n,y6+:AK{vnqM:(Bm TC8*_WktR#Z!_aC/Od^tŶRͶRN7cFZn.džc%a<W&hV5t!瑎g8 U)Iu-53#8%Բk5&֨lh_`MP) m>XMC_:cb)b߫R{ac=FJ$hLށMIV=6d'7UAn%ChGK\a}GÈցn24d44Ӆ P!њޏԣMGjQ)HNZ( Bf3h_+AVMi-莔DB^ %X59~8"SjUݖ-ݰ Ϙ ]{9sM{XZsA@L߹i=Bz=8ZD'+RW|/LEҡ×fyfR:*}BΌ1Jx3_D<@JCFwnD3iՀ(*g= U`s .,Ȟ2:`=Xg'6 YYp~l )n?rrKRhoJ&4۠IsP'8 H{X34 q~ "´kЀL\Zn fz>z.yY.zHLJTlK8Gխdq:!#4 Wu p*nOٛIYUEVҨ|W(m Y0z! >/er̍CMb0LUd cyC /a7.L^7