pki-ca-10.5.18-21.el7_9> H HtxHFb ?*}}ʰsnKx깃.X.PjxG`d&n553d3c91b1d47990a857465525d38be72c62550fel SLfIǻ*Fb ?*}}HVF3nmt% ܘJ)~7&T>8?d   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H9:·GiH@iIiXPYT\hi] i^b=defltiu֜iv@ w݄ix(iCpki-ca10.5.1821.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.bsl7.fnal.gov%'Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEGl]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤b^2bbbb2bb^2^2^2^2b/^2^2b/b/^2^2^2^2^2^2^2^2^2^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2bb^2^2^2^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b/b/b/^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2b/b/b/^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2^2^2^2b/^2^2^2b^2bbb^2^2b^2^2^2bbbbbbbbb^2^2b^2b^2^2^2^2^2^2^2b^2^2b^2^2^2^2^2^2^2b^2^2^2^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b/^2^2^2^2^2b^2^2^2^2^2^2^2b^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b^2^2^2^2b^2^2^2^2^2^2^2b/^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e0ddb421d25ad7c59d927daf3361c8e93b2939b2f4241e15f2abaacc3638444438cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb643811c199c1d988747ba4d5689f9167fd42a8ed07039e28dbccc4b744f4cccd469e8f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-21.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-21.el7_93.0.4-14.6.0-14.0-15.2-14.11.3b@bf@a*@as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-21Dogtag Team 10.5.18-20Dogtag Team 10.5.18-19Dogtag Team 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 15): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - Bugzilla Bug #2082717 - SCEP manual approval failure (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 14): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 11): - ########################################################################## - Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu) - Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail in FIPS Mode (cfu) - Bugzilla Bug 2018608 - Invalid certificates with creation of subCA (pkispawn single step) [rhel-7.9.0.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-21.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*LFۡy(0,E5-򊱦X[ Qz(֝5~D\VfSB$Wl`V[+jv_FbGKF]-5Czs U6v+ ze.՘&vLj"V%u5yEAj>>[IS Gi2暧3ǣ@_j"‡^ps+ /> %T&͂0:O>Kh"3S*SA5kYJqbEp7v? cZhocE{-9)ʹjFbbv^}h2''aim̢Ȑֻט~Ov?>~u_,RcLaZ$+"i '—s S$t NP꼧a,qzIݽ h 8tɃهP&ܑZHʤG;>|QU~72 &5)O2!G8|n0خ^R~jCP-.* ҺWkK>ro.I<~Z] y2PD(BɈC[型x< 7'vEHzcuM3"q%wLq׽)Z7:>SG I* 3f}G*k^f* )TXZZ.M#coy۷\PVdЁ Pq 9u*R?Ql߿Kh9Q˿ :e4Ϋ۝z׬XǴ҄Yn=^ q(-/a4 216uA$7J3h#(DWF,/ j ޝb;6lJZ_>:; MO[\պufZ"e?MY71Ha8w?S6. >'|-/c}әc1TQ#F#,w2ӊ<N⪅< a5tscԃY.R3n0.iL{!NrX<(J, <}nPFQ=b KU 3- E?:*>$[~pF-JT0.xOM`F_f%ms*bۜҺSsxݖ ѺmoN ,h_ܓK[Xkn}p+H*L4 |i2HAKm9xJSFTRo#i]+ɘ!ȉh@K9"2WQ.i}uZ).7W'r)`v:@lDt7ȁeеI4{~Ts^ 4oVfلA V-SX!uwcmPBG'[8J؎WEx+.,Řka0*e͢+=oFSb4lbJ;iB`͑){_fsTlP6 Kι]J\ 2-ߜ-uxBbIO_n?,&Ύԛ 1>S^4ADT\ >I!X4%r*0%xFâqj[Ȁ: Av@|6J}!{(= ssյguʨGxo!p)] :voX]t#;9'0gOm I)vKXIsK߀1k'ɱ|M-s2!-@P!߱@݌ ~49~$9;bVK0XX.A2{yQ'AMPZu?_P q5]{?Qޙ꺄{pA]0/7~P5zÉ:XI-mJ>dB csk* 7s1s'vO┽ej[261C[M(#ijE,c8"jk,\_# qz7nUh;:+?իpQK?dg(6NUHʮЎ 3m^ZgIpkUJ?xoAMxZYϘ?ي'x?ӻitËhhWS)%mY#+7<׽,#dܙʿδPN6Uπ ILC r 3hӂ38hQCЦN )BVCi|e='JՆ|t2k)qVvqDv3}~9 >g ?S-W9TO[gEufcag'@ &%i47ロ2vaZ|hyԺ9P(e:k &џ29S%,n@=;XPe1.PsE֍۝cX>;sQA1ZSPJ ES 5^s|s-[DD0x?[ D<8f-?#ޤ!zo/zjl 8\cF2ńIpR`+oNkr%¸_'Oc$dj]RG=LyOvrQQA\}QA{xvOKi~jk!9dwNB=gT wJkT3ETOa9!VQBNFXmzvB|11v563q/=U1M_&9K4 =O\HB45bq| a: Cx *bDs/!q`#ߠvΰm1 7v,pG a~i|8b4VRH겇69DVSFi\Dp5nTX#Iv֨1?;׀| jԟkxT29iejSlt;F510%uq$7;CP:(bYz@&5 yI.eG AH[?2<$ɀNp[8wMɄ;7M7FWdBCE6(\ (ra@.fM3A2 GXd]Ub*ѥ,!ޣڙb",&IJ fl}'pX۪X[ :|sTr+]>1lSwfat]Su"XÉ{؈FGeohQxZu d6_,TٱTv\x%z'o|ڽ5t`ɘ;$ӉJ.>1VDI+[I# >(FvQvQfnka? &hcN=ZWWu ]ю(>:;J(%;Hv*cyI5f˓.p& L'/4qL?ܪK+?՞ A|c7<q3bavЃ3>Q Cn^MJP?o>y!ܙ9l+qcGr&ҋ2 kX8Q_[EH;]uȱ ^["#STfEV9K;`e5tL[E91lp%s(fڈˁ^;X>Sh:9Zˀ!z0 &=ąN5a0,3FcOeR.…P(gwOż?Rӊ.n#_GpS08،QKfv)\pBzN{v>Nx$-]Ƣpfk㊺R}OLȣe#G?V@XVoeJrзˣ%us K:xʹ!:Ne^tޫa_~@$`q; 6땥H:E_y{B; UCz t`9蒪GnL56 -4cGysYʊ{}'Pl.W6*3v,K$Er[̽ix{lNrL=ǖv=IdK*Ba)Xx,0r1xcnz,,*ⰉMQURȡTĄ3 s%oBo:{2M:y s.${k=C~z:z8{?  <6dSUU%ݨH9[~p6=S%|msbWʛj0layU d~ su#wӬE4E$ΰ sf,㛊{fXz`]Dzڈ,j̹ܠSd]ó'p<~hs`s1 ^~u`g["0}uKGp&ܬoHyk:hgI#}g 8n]NK}Q(7m%LܚQ=' e3jhY $:H6ٴULzC"~/fNT$H>I2EWP-t _":+T~6Ϳdmo+6+-sp)dȭ|ĸ9<4ZnSquQ\BhgNc*6Lh#} X? /nb dL|S*OE;o<2:7BO&xNj `6GP_oHv4aQjH `. zP#[t-Һm_^&=LtaM==1U譸,2u,^NºkUPŻ))MΥe)\9y7?IEJom=$m6n %C:]/C˚S`{2D+W 'nG.r)e7@ ׽ SR-;cQOZ+ *BRÙ` l}زX1N0b:b ќL%c87gpLdϑ n93oδO݋3.F^ʎÙ[_n)lt"c!P'rXbK@<]QaAusSVcT_$=fЃtrTT M2"`zbk?.ٝAg6,F|VQB$ᎢP~lz -J lRZ0 Cch,%& % 6o&S ΜiW]FI"m6\{5tٱkfHdl;yP>>s2ⴕa3 QU) a|QzxǍ9!.UJp;!EO1RryPv!Q!OBLsDB 's;Uagz q H] ߄*Jd`a6Ώf\-Jݑj 5A`O*O TهbvB_,$RK]-؊lXU[A:4[r۾(p Tj)t~hP;H_28ݰ|vKD5T$}w!Z醌%wN[7+?(W&g GyƧ;d$ڕKKK3v}^\cO4pyu35$ ԗ3i Jcmh$v M2g8i8<1,chA{{X <@/ P=:£bDq,]JmA5JN QaZgIpHbQ{58o%oCrrM~so™iP?D%x/h(E;S;'rrJ5I#W5LH6p>9FmfӉt,<~gp=݈cSeVS;T`T<[BS&8 '3ߋ1w]}& 2} wV|~ L6ujx﫡5v4m`} ܆׊2?084jw'}8( -1=U08g69S02Ț.:j"Wpj ȍPFcz 2,LlWpv7@.o!n:K }\%Ama_[p/DEp} u@1/쵘{?1xIs9'Wzx,xR_Zg]$S/Gd F_c8 1.[ SnkȚz޳ނ>}o_:d%paݝʓ+k*X恳D}Z 8a"nh@#t6hLѻM| kf۶AN6Q6(CǤc0Y!<6erI_a}ѯVpQÒsAE'(/&uDŽI7; f@knmΠfs$$YXy{ƈ#12Il?l'{zh#Li@J땜3q`bzz7Lqqv43W54P\DTYebOS',^`- EI?Oʫ?(.bvF&|g) 9x[$CfHdR Y8i*''35U%4'dxElelhZK4|uQbɰ&h8 U UnuFFσ,g=CWۣn8?nFš.`?sE"jDM}&Sbωz'PX%-L:hQ}S燔G'v6cPyGFFR=(rGk;garClb0^C[{^3?Zx%y_?Ez?76666PTQ0֒@CAdL_b?Ol@D32VNccKrwUnYvOoJQtX$II|@Vp.+#q?*ѬU|\[HÝ'm*J[OqmAN^g3<'&h  rZC{JG|4{[mf'E.Y+% Y :N.#;< Ӓ{2k*>˗~5=nH"kj.`]%3?) e5D:oD'(@5t,fo< om?,"~;$0ibg?SI iWis4K. aMOg0Ӷ0k8UJv; |xвI4(<!+S]ixzD@P>"5wn#%v^Ù[*ߟcT”!F} VDC#r&Bc~2YX Ex@.9X_ɐEB f,dad7򕚺ceM?&dtI 7rqގz~?GƯ9#S^\.K#l%hr0[n/9xv-V|?@NP^^#s~W>U-Rxܔa`ᯎʳf8swϊsXL^9jUb8z-xZ£!0=e=uFE c5$^AFX,*3+%Lmt0:;'p,-?GHc6JseWʮ2w퉖N 6*B$ъ;ǬPO)cu,D}!/f=/27`N̴tG"pkn`ާ[2a_^qd5??: 1`'Q>bSwMA*BJ@@M55$5ss}'H`ΰo;FF;49r+GᴶX.,3o3 QQEH;kn&OYX[ '9jM~OukfTp~_c`3D$g} Ïdh0٠ do&Y%*T#UaOPqˊQbn7b^ `=~p;Z>V|`_{y!㘦zFL P;U( UZP&TqUNʌ&9 Ơn^{аqr8 ~frW!^eg C)l_⾳|a1q.HoNR16Ja[:%ߺr3:hV{zo ׁoLDS>I 2@h}z~qM]4 !ֲľuH&pdkYQ9]b)Er02Jd'F%O#ZEP3sF c $ǭľH!ְ!cED?ҨbY@4R3 L/E{y6-' R cuEbQ4ay,%Ou-7<(b?c8ɺ߶?xBG~29be]\G-+Mܐ 4Xb vzA+}!yTbϭ8]Z~HdF0VvN}ۿDz>̿Ur9 z/kb3ߊfs ߌHBB 0l˷[Rk([)Mշʲjw՟gJ~ދvɆ]74_6( 8̔f ݽǛ2=N(,kNՍx kpGEjHS7k&k d]r>vFExz38Kݶ9:䒛 IS)U1?^y{ETjbHS 3}ζ{{h|hjݜfH{.**o&?D_]Q'vaD)RP":vMfX+З v]K Z!(~hFك|*<05D$)'*IF[_f1e+\NIʚ+Ldz39ϝLw=7A ʎn(Y1"0j BWj|kf?3Q^,pVdep]<~yo.8'xܝ!ik*1nfoFW[ZU Bը&f*q}9]Y\G~zrQϞ Ċg]mtWCDoB /+uRrB~Sk|4ћZU 7+ӷy6GG0nMѓ|.!*=oɞ"!ĥ9#&L޽o6Mokk6^ Cbn&ZwaB]V -s>RXd۸a)@mZwFNy~*Q0᪉ȁQ}}zʇтQxChHI-Gݼd檯06vyl -}3Äk9 #EW؁L٨'KҴQTqmqA 2fq=lOa7PI_G3]4@e"Pk8taƃIf?Y4bV:.b`VݢAsg.|%&ubXQUD4ABxW=,rPZf[Ctn6T=:?/ă4<ClA~L VRodq i;SyŽUPsz؄-% EQTLEXHmm<_XpPĦEAj8ph:|xv6}nd]hZXl gL|lxJO!ݍƷjKD2s`GZ8 pa`*CCr0)=,@m/8Û/S8ۼh[24XLbbh,=BsJcyN-9T}%as% Ɀ/2 QJ쪰b[^TX.#kC $MHb3ցOx& rȓAK,FDHHMA' 2]9hA4HXY0OFvhQB>N.wA `:xֈb.!2qaR9Óe=Ŀ_C|AX,? i _FXr4\[?͜TkVͨ\SʁQ7Yƽv9;܅\yKIĮAKPrfj7K=bݎׇ]Xg]4*vk_]8Xl}@_HIkЮ,9PІtbrrwp}{5 +)~e10.0~\%q:mA9tE&ǰ>Yi+LYa883n"Ҩf/d 65_faz3]C\3،8~lfs~}Y%RKw'Sй4sCb}[515p \XIbLL5̜8j(g 7e/rW[R??Ff Jl!$PF3qh%1D'Vi0XCI~ũc ,0[+Vf?gCG]84*MlBC3yT!|ztSNUSE-`GWG8],~'%KnLfp^xZT@}#{EX y lu5Rf9dpt [7, @@Bkt^ZX6(sA\$o\f iULUJ(PFKm5;'Jr /ÑvHXE /¿T$GYԛK*j-ԫ>0Q5CS;|FXv S}E$c5DP䱼+-_# ̹!7<+vn3Bo(&+[dˁ)77zlfuC=\g!取Â:c=@j Bُ!)r<$R(kIlKWLSE)?[xzüDyM *]<̿&yeW~έ%nt&!NY5&|5 hod:"8v^ H&t5n!U#ʹMRNZjdT6.f FZ[C  ]@>a9E4,q=GsHԔۙ!fnf\O23ȡf2Wz-)Ya&M'Q n4IB;hWե',rٕT8Ny8;M9x7-7Se /'\3شS8gI{,kodak|S@+EP+@ 14Wp7ڶDRMp#C'8?.1(AhR/1bg&ɲQBczjѫP׋G{;3 O"}0_4Bx6ϐg/> KzQ*,R ky6n,H0 1bNY*h)jsKf)H&!}g!&ƼJǚ- '5wi* ]\Cf9 '%aQ3!>߀0Hʽڡ1l ϛ 6@dv5]9@,Y؅ %3~`ZwT:5 Q[A#4Fw?S\ab Dpsճsl@Y)@ʀ%Qk6yǖP{1H6W|~'(v[12?iW9& E?LpK6h֤Ol*\tK'0x`vĽ~j.7"/Cx5ff ;- 8V?,>x2CswMrvs toOP;OF#ǾToc/Z@,VX1t gUroJ5]~dKD6`$]}ˮeLZ|2Z%Y|u2A:^J4n<= =(!` 86)xSo1T1M} J?[hgpKh_*>ÐC(H_K_ !BLtF|=#Px:IX'Nve: K F0g'` :=xI@Hd\`jLy$%4c  GӋ^7cw) v8nmn"]+7ڕv ~wPz `HjR$%JC+^&'yQ]^M ԤY}uH=}4L)Dc_FZ/Ϥļ 7p::3h1W^0 ty_Hb#chSRq qԑ0M+TjUA`Cł$\;nB{~lY'K0 "oLRhP[JG@Dm5HDiB[(ލ~&u"(zA,UGZ id&T7jѽ#Eӵa33~`$2-W}c~DZpSz ݏ2KE_4A^=L^?U=ku$[T?h&]ZP̜t:2n%K-D@3+PC }lY))qCGA,SUuer]΂gl._:3%!&(v=to`DѠRɟh!ɒČ."wwG}xI%kя8Oḍ Eʄ 5exdE7]QQfOה "3TrRy͟(M@i>#h7ԥ*bbܕ9yɬ}ȩւwcKh.awuJwYzhr>r8p&Gecw':['|G?H#UT -7+&w`8fc2q Vλ X V&ޮKHLaP%Y=rܼ?KUsu@%Χjm!nX%p5rP\\;>>}˥x+Vrf{{a~W%iEr2QIT_Y6@`bbRm*i}#z8QcوM $l{5,t?^n6625e) g,2ZLf~Bؤ v S5't"q$Chп~ĉx-$Ry&qwGq$|ig~?,BjH%g۫I#/E88Cq-1(ܒNO)9B'Cgi8[q?Zs}udލb|RCǁl̼oK%Ye@`^G"ሥ^k$Jʜ&u8PM,FPq $1vJ[bL_K-sO3ilQ6q]]Cs|E(T=D$ۅD n*ﳷA'vVD߳aF s(F*a`BDMc{"Ď"ƕglVA\kρkĦ s@QOe=dJ$``"+<+"eZSUz49vնD"\%Pf1rpvW#{G\+,FR ckzg WFBsmyįo ~T h.Nϼ1,^f6_WfG!le_%s8Dj8UN c)s+Z}b!|j" (;bZ~y~fU3#5P''%/ʺHyqz eԾcȫ˒gf%&lKUIJ+"#X**m >̜ޘ dʠ N晃/]oKx(*y| dհ=>Fc5SS uDB aͩoş5'l< HEj*A/p*JCTXkB,N:WKqDnk8ϱn 'CepmMoIj) /.KwѼ4TlהI'f,5 dc+޼6ievw ̊>Z.e5#cV.((c9B(Igv-J^V" ރ| t$Ņ7 :L0*B{W9VhH&ʼnX x.':NB /4m!VS>k|@B{9rP đ^9Њps ~kwѸHuN ֖U(Y*,ՠH `ܷA3&AY9wN5i ,N#^ l5';YZzY:v8zP~t{"uJϚ蹁xmr>+Nc;#;0 Lt)wᾔheD^'ƺt(sVhr6>=k*{d iSP&SXmj,멁JOјAٵ"fЫ 4n8f F7>IJ}֗U'7,A_3lp?}Ef{~D^J QF/T@!!O2&7+y*A!ۡD8P2lH" oM! w*[52؁k\ةm% p$ڠs#VfjksuRR zIӨ;FGW$ĬϤC${ߴ=nNhfXYl4Ҳԧ鶲o b̧RN/h Hl!@j% KTPZ؃&V9̭EHFLK)i{D 9`ahe^A8_յv(G-d97RtUښ" ȪIZS NI^bۚaIin3hWwޗoV{6 6:z;d=23> vG)=_]NRi ILǵ^U2ifM&e3?#DDpD)saa-DFzRhl!d}U?2ܜ⋭Yw^ ҄i'G9u )ʬ ~|7~bF\Cst#-Zy$9TyfB ~+1;VDv7ꡎl\y1Wu2<"tj:wO-}q/ CpڠeO=&+w\3 co*˗rfړ&̊*.৕S!d_߻?Y`dאԶ:Fs( 5em: q]F_N G#>ƣjbեe8kApR@(+#?eԜsʹ\UOof[ZKnzƗ;7s6Mʓ#lh a_[)6z\F[w$v]e! 6jb,B ^MhvF5(t)ݨ ̏Zf]HvQyNP ilqu=$б huGdTrјr{ d*HS&M#`ϼx::$VUʳDqj>w}VT_]Q9Q$B5!tQ_[]TĞWAO)}v8O~a+P8OS|Z2бW-(KIz3r{׎A|؇i?q ڰ@ng/}zpcHGcK|Mo3H.p7`~}bqDW2x˪TmU9F<\Mnl!QusQ,J!ߗ^JםV7Pi7$/z«vE9scS܊.J6h;b54d&Fl?2Lp Яta(e<MrЖŋ1 e:w)vpj6wȕ4Z4yT`ҧI=tt6nuy1.,h3SDo쟲+QQ,{50AhhJF/g 5yǼڊ4ݵ;g{m.? pv`("g5ioƽ/]i]\_֛F #X&:XkkhLnؓY>YCc}aK?  ;ezpӠb[J Z2'}T~J.ͣ%dd}j_{-S4L~`k4Σ~"uݺEmG],.4P1&|ʥ t"8!D`Vn 3d$1@ p7 ,@f3 @Ė^v`0Ydڣ{Zgάno 椼I8 HuD)uQ qλl-zaRtAS7H J<]cm!]ktQ`,Ɋ$.[-~ԯ'Ehy}'nז%ÄK~*ɮ"U)閟vz^UP~U yL!}"6Ox[reٴAćHeRdu ډK cIv ttD;\O3g+kei1L_=z tO$ nTl:⢨>}  ҵe mWM6V|Y&4\';#F_JP!0aE*aFz\#[H⢭ 碪[4D:-Nl_ttĥ&X/#R(4"Q|S3 =T0u4ٗ%J,36zח}urAX?dF?P J2ڎ^swct]-`&9+HSs.iAiYnzV;yh MO4CB*FAlGWMhQ?WAL N mGsz㭺"-o8D  +?pB`NUQ<aL l)t/u>1;8 2X!,HdmEwAO|(Luty?*}[A6 - >J),%3?ASKA+e.ݷ'Bc>kM{дTH>,jx`kUI`4Q|[*3MHdYv;a-L|7%TV( aMcOр kşJzH&8HG^rS}W#R Jd.43w:z& ;ĵ!^=(PR@0~*xZ=d iRD̲JK] -yX͐!ҽHF=hcr ܬ PtU\ǵ=1+l,'=EbEߡ"9Kߩ pknqؿ<.Aه򾪔v6ScXŇrDaT 5)/6,-{of?8cBfy"8te\{ JAFW&}C8EKقrRb7Mt՛g p!Gq`=gTDm1;6=b_Xo( XqLX_)`VN3aNo𰗰`KN]QB9P%Ņ5M{gO T dhGe#fZM]47Y{*>5Tpi.vZ^ވyѿʋlCB"=NPg ҺPRg *e+7Ý.Z#˔'3;EOa0SN _Y@HDZPd{\']f| Цҭyl۞־|M?AI_?yB}8`&׵pVAq3ʻRVy(6U8[]S%'%0~f>XKڧpUP`C.1ktKEEq&jz̵ri-*k+=4xC#VyO-CyzALƻp|t-Y4XT8Eu2`6Ǿuq7h-c:0XGKY$6Ͷ2P* vR5(J򣵑77#dwbI PUz|9+ar!9+I/ YQj2.O;](,KM^~^|&h75%Au.Pj[n/}o'?^O+NC`oӈbk߰D.ugBҐ)B~f RYcDlE9[y=#^гiI5 [[VjOM缺+ĜЭ R;/+X+PYeِzYщoE.:p<֪KT mk؟'x`gۿ'n NN|5G6ԔռܭLw=-6${!_M a:~vLD_#) '5r !ҥIʋb[q a `q;a8"5rO<IVZOߴZ#k?Bd#:w*YM|t3}6.m Ia6d1}ўS ֜w) {)֑yt£`XR}OOH*deÚҸTహ,L6&'{~ =P fD^ߒ8Wֺ/?#hMuÃM6ar u0yyiD ' 鏱o SB۽!J K'Tm@@8RP?Kݧ鳞zs|V~Cz[JjQo& ^$ΰWsUCbi 2ߪ rdG0Hc&iZgF0Q\*hgSipl8Z~1g]%0:XXd.ƃ 8($,` VM1÷ӯ@U/zu)/~vٍ=jEiWQ x(aQOI6W< 9`ug>R4\+a0a5EKr Yƪ}뿸`@W*%HHЬd^8{unK/-VJ%Bhi2htQvk5d@ᒫNk9m5Obp+$Eߩo346N$ln@Tܖ+dq:ոRxv9p$9_PiV- P<1lڇ;JҀR -|\uE2 ݴ҃1bYd=s|UyU|4֥3EndV?+uQAUFDH@?1PH 3V_QT1 @hgX|5ypDw"5s}jG' +iPFkޏ+Le㍨o$tW/M^ euowC*Exht~#,+?}"D2w_T$Kz}aQ3 j7H %qD `W̳mAFM<_axw#Xsny&[/w6Nff6:j'^&E7DjH,-tUCX`@ LDhon+vyxݝ/`-h3YXsX>7LO )$ii%IF[ l>*+!ZQ@-79~rB4:d{"I@ t`%Z>.w*˭9#&8.1eRK @SJ~PCjEң^.hF+aaW&Z]?ZMaVQj > =Dms'*I¡}-/v)R 6 /`$r8Nr{)SF54hp1a4F>GVp#C.SRO޸tu׆-DzzɾH#^jI摵௎w)^5Xƀ_Od1ylϰgRԟ7J $0kNW>ꭿ$C DuYwbH6Fǜ{~ڋTW(Nm#%6Rֹ KS7>a}*nlþ$8K$I.|)vSMvRYo8zzʹ"(0VhY+WR0"}@sf*=Y8ΰxu~=.()>3p"45bgh0C, JJZΆj3*BDds.zBaa"} F[Rj fm=Rnp}e؟`gez%vhSr\3"Ɓ#mG 7'|*>jTAȑ4.oɻ{1+A թ7mNM٠%0| mPA~U,R2g+QCpqԎRAȰ1nNLM啠Agm&9CzJZ mz6$y6joHrccMfk1vSYIhbVى@{od-ڂնk{n O;j9qqAz!7A1ڂJ~w;OYZcm^suR|<#1mq w I)" yA cl@Iˠ*()}U~w(yp>8RB%r u,2&i4'Ds|ԬaSfkbVGfp39"Գc)zل)/nu`=z$^ǮWk}a.۾  Z XkZ(#׊%>OHڽC,{6 @簜4¶Y'6_' 1WfOJ!XqQW8]8q?[ u֢j_XCS=ry+"f),88r.Ο\z:87;0vFUqZBMUKQn [ѩFlĈ'e'7qZ@LoV>kIcqlWW) naq$3^衟t#K}E1kԼ>n~'+el.%%单!O=)OL|9f{o5ȣr6-Guv`Up pT)sڛ[Eut}ܯ_Ӭ26ZE8xj(<}\Pϓ3=t~PS͕iMx0t+c7F?C!}|UnWdZK00ݡ%]; ӑO$֞w0)1r2'ҫ_:`ڧQz>Dźh%503㛆aTF)9Tg#U>kFs#QblAyXls|zѿ&Bâ(`7 8S+Y3ߣ yxV{PiJ/9u؞G1DO9t"zG I2&?2bǼ*ė$ZӒ8biWU$}X-(ʳfr<<;⨰QsjL[9&¿G&ǂ ^#U<5Tfy_}܃8_sS,ȈCg Hwk]TJUx*Ĥbpό{|q.uVӨNvxݵC*9ld6#I* rr=MQl'/ v*"tɚ zk A1<|f|'>tx H3υW^L~^*KWl?;>x֘T˽O.oSTk/vּ& !՚Qܓ5]>pY`v=4xm`J6N0[)2mQN0]uhbavԩ/ eJ1b#'i "TFFd@,hL k}g~v*:qt *[eM_aG$_6bEVssVbIV݇#dѪe!2ݥMxXAcۜ$.JM3;rcEYo)2;y g͟'ɅQsw^gB;^-[6d?Ri&4\r =.3Is1ڶOS8j,5&I-ʸ?3LV, ,Uo^A ns6ʁA- ()I/t=UWPVwt.к-S{DK9\lPs.)&k[k?WZZٴmA{CwF6XHfY7kUsTp*# ;޶Y@=F@4} ^aT}J8[=|T>dd]4(< F뚨( 7eg#X1Cpd:ef;j,JWҰJEQDCK; m%kThJwR aHQE5*+eU񯼪I/$S=IIlwq xXƹlWtPn6))TS1-&1ݗp;6Ȕwma^'},$Z1ICzVyN"Ò\g* ^F '@6qGDɹׄĪuC. a?Yu3 D])@_9`(ZxǗ#gIdH۹CQcK}n붌ެx"Kެ]j]k4dbv/9{SCx)oW.j Ϣ~HsWĠX*>u~&1P[^FSⳲ&]k phpUs?[ ѱ\WLL xI\egEl1ZU"@](5Ͳj1aچ:g(⌢GX\{7$ԕ,< oM_[dmDez Q'X8,ܪ^oa3:*nh-#hJ]H&ˆAL2̡w>+r`jK@hDP;Hcc.ærn K_w1k\ǼA=a"`Qϝ <JY?@{hm`WUj׏')VTA#.r^'%Ȫ:%4#g}]odwh?k"B4q6aܝ4et'zf+[hhϬe iL`m^m3N'A2Cԫ,=~÷- #Lٮ2)I8}\9H\6[ ?)" F($ URe]M 9? =@/mL  %PgT^2֙o'p!{<* 5Ǵ\jL*u[݊ )t5-:FsM` rQlatp0EVFIrʝ{Z(;ŘoXЙTY ǴN֮&9C.؉êsf13=Iы4Lgi~֜p2.)U:L |jS?ra]_R:=0;{68~w^GTـ8V򮲔Y vGU_Xĺ#\Eޢn Ol]g RUH}+\~DKVPih_ȹ J+ aruruI㱿 QY$)jD.w4#}qd ?ѼN{ߛӳ:^ۦ_}G=Vx˥"6⳽WjbcH9pbU {jG@bt<&k@^Ӈʋ<$3 j<:kxO,1W3$[6}NgWKir>Ly[cJwu/Aw4*kbJEG6(6LGށ$T2&z﨧>]K31;ϙCZxp}ЇH]\ʨ;ZeT7Kb]B3'[Hdqi ]M ܬB4a&/@dqjGh#Sw_+to|~M0ehyGj JuI}Sz$G'tGd) xot\ևIYG5P42#u]6IkuaԊbȶſq.-pb¼&3VХY1Ұ^Idr\jX/kO# d 9XPE;>#W³}\#_%c;M.%qzS.¼G#x֏k'w"wijnW|MMòsS[r\}Pr tLYw!9/0b[a^1ja'ӸY4rh~RH2>v\ԆiهYb!pN7{9 ]&FIhnGuR`AI^ݵQ}B#Z{Ga摩i;=*Y?[(Mj˦YaaSf:J$b~菂*Rxj_٠;?'DPNpUfjgY ;.`T?&.h5 O!BM]S],hkb'i!tO1*訇lo <H嫯99z] $M#Ʃ ue';jJ1 |:π1\CܜzZ<}DR)&|]ZT)fXz" tjlP2?`>xZ3LpZMŒk7g/`` .,4]{܈$EDZsQ.SRT&* }\s.?; ɚ J36Rk8I:[RY$ʡ/)؛"qjF!Wpe]@üW w_/n&(J\I%" dQ{L=%>uO>,|R!I bYlAR=3RLgBQIb3m;1B% R{ mCDKn~hƿ,5/^x3+tBPa t 9׏Axtqx `r!a)Fk|N#M UXrh44|bPzuw&%jf#ej/L!<1 sdZ;dN65B]3*QQ|,bԅ"t7̰TbWTFAy@zʼrIIB@U'_V{>,fPaVP:C!8ff}s{M3#";Y|Rz6f3w}] nѤ_ ߬ :3\!n& ܸp:upЄK,m/G=r{r <%G:Jndg̬ct5W.X%fL;ɻ㱭?\r *oʸohKE\meCf!og3.bCh9kWRTRb_5}XduJ&cS~(}%p{Jp=;7 <)~.S 5\ _?7ݺ yZDpʂC2;߆-}ku;ۛ`ߦ0I`"!HX_,!ȡ+q#QN! 0Q:1%,30VEBj7s^Xk]`QIg)ouR|~k"I q1 emÏAg`(3aZ'(F޻UU\!'VG<㺀){rN%K+`Y߿`tmC>#ŸYUDǓY!ޯ`j$C]/A :W-\ vhGפ)4Y/8˃ҳK0ƗOAgY0=bƦJ֣M_57f Sj~"J~ 6|&%C.\׉lp#ݞ aMے.DHt& M@" 7MĈ_^,,`鍂C#-]]!vmnᇂMJq{ze:/ot#/Rr~7?smk'kRQlv Yj&tB2˾?C >`ꫫtܸ QW!ȧL4~7tﰄ%,2>kF{X˷7agXaX%Uh׮W-6g@xx~,U^ $ Av7e>-^E>r:E#]"*^ K_bttz*aD]J:IU٥2iެ<\ +}i1 R !%<ᶰǑ?RZ3[XJ~M 1A"^KZ'@KNx/ȈbA_ >.lvH-0h19c N #'6jP(B_5y^؄<>e M@ʺi/I [0JuVc-za!'> QGӫsf PBoH2lsͯ '7?:-늈\=vj:X2sUF} ;HRO,h^hvUcnEF}6d'{]tAF7`?;!3U'X;ԶzX=#1+f(V4"idpʣ= \{^f)_lj©?tnK~'}"tTC f|߻wS~9),Nbn]KONPe&`\wG 4&< uК?gӥ JѢ{ x׬dp@)!k$M@*eʿ7rb t5_n`5V)xΠxk FDM-Ƕ`=υuƊb¾хzCm|Ή/3,s am#tseA1&c+L9=a6F6whL_hU04QZ"%"[ԝ>(AIkF_R2n-!I] NanzޢEw;+׾QfnMZ )4( K6 ^^0[OS c!fsْퟍ!=kd_}W%^ONXo*<\$G+_)oN!\{NR`n:/V[!?n,l脩aDU׺˰ dҞsC{ǀJZ6[pPƾ4y]DN`:CW!P4ω3k<|-q?Jل coUhS,.I]C+ϧfzZU`;s- #ßkMq6:^@Uj(I_uA_qXA#> .)j@0e_RN_;=ᔞi lu*8MWᒳQݯ5)Sbs/ . ]s\W~w(S ԑˡw_܈vB׭L@\7'*% 2byA#ꑓ>`>NMyol 6P#|Nv~5Ž$: mlF YNa E?KD԰ƂqAALvy^=ANء%Q<<4UhP@nl,~i4d_2YϮHL:t$n7C*$zU 1#A;%JI?:y)0rtrݛ;s. 6TY;U4 Tg!6gZܨe&#zHidEbńP>0v\רfNCŐ:DsoSY q1iG}E|azISxSBЪmaԩt-?1tBa5Du/Zg_j#*f,PJsx/`V Xl9&^V#M<v2}߈}"!N0}q np,F0\@9ETʏ0l3##cv a2JFz2u»:`%F+=x1`ky 4 pd 3WJ7ϱCGA}5ʊ57DfvY7a}rHo7kdk; =)4xڸ!^i!ĺTtLTd$+i.c*ZuTS Y|LrƸĚ4k(⊒R|ś=H[c1qMZX:kW {HR#,A`1 +Ym˯^ÌѝŒ*u1sԾ~{ !qcf*r{O+փWЋaWMR:vfWGu(/qE V-)͕b=!"zedjͮwkWQJі_^mlwc4#,.-,ceȴI'6Efvq-ȣP(+!%hU fidF!) @9YծqS=9y`l*уhs1ٌq; )`H}7<~' L_ vnCK}O}p4s}`Hѿ8/MrU8dQD({]m֜n;xޔ -Up̲&Hۇ~b03U7đ_肂["=í˖P0OpqB)2GVĝI{:7[TA) 1ؐ$Wp߻{a;خ(9@hpB<&],)VBUݖ q|eC12;>2XsH5Oa6{n Uy[|`=6&<*4#^(IY3l;zo~2`݆hti =_3m)U>F 4?cEH &auP#g 7'~.pɅBanLPRiv !;L1G~pf7,eZ[íȹᮾr30qVaNZ蘷6$KqHbc|VӒ@ٟ2FȌɪWe=-֒JW8. ^0'8v9Spy9%Ú9ߘ97=@̗zk2<5?H/,Ćt_+a~O}>r*_@xc#2rJm Vˉ Ԓ -jJ)#tObg_ ¿Ofak햴q=5**xodt7{!`’0Rq084FcW$6IlA@iz`n_9QY+Lc(0/vJw)&nHzisG4Ν|3dxUʗV2S 'f@P*X~KTǙ{̍ 1nXAleKOMO>'9=:Ҩ\6Ts$'vXNa I$3BsYmN6K8T}@W*`o.@w4٫>y Pl--38\Ag'+\=fpUM`;5@|_Y6kmϿC,SKj=O9=@7#}d Xcܬ3qjgć~t ᑿs&Ҿ>?zZ_8 Mm}mp_v^GiLXۭW$7WıKk jQEYRqo]ש8ZxTbyxwiEG( ѻbU,obϡ> AĕQN|Esa*#gmƼGjHgxPcJI jmFR&ޗtXzI@*<6ؤǧ@|8YIuY xY&3{w2cTf`{ a1 谁Q6j*nƝBM1 ~reE6 ab`*[-Vn^, ʄ+B$ᑐ:v~ dE7Wl %mCH-yMp4&wq<;j5 NF̦[Mv:`YMz&" .nE'i>vۍ67U?U! zQn y-0Zi]rG+֣,82>ws4Q>&6fưK?ݴ^6 ]W!JHpYzV`ꪷO z2_"`˺ %I'.WN:as =Rjڟ!$q0.MB{tH,S.ȧD.t+Kl 7Ɇߖļ"3߇AnL 7p"R&W[R>HooLT翴4  qwJD1P ʹT-2x=ҢXz,EU4(vWb0褦Cz˱:5z Q8ԍ;Sr'3Vg:ؓ%2խ߾'8t[};+CA s@9X >qo exuUaL( 혜V̚:Cqˍx7- ʸg[ s$#@.wBhg 12U/ ӈV_g$hk- |T*V/]կ_9<@3˰e17!mj?,\m} wĿ;qɈ6nr9$HRmcAY%렠|E :/ :"aT$Kr.WCbϸfjY1JNZst0s8:Nf@ [=\~scf"(m)9Ͽno/:S1IcGF>0["Ղ&jEI.r,ol4JD^9Y1jobz3k>D;p_eLx++KU/uPlAG^*Ѭo"*63hkru[»'kMq| Pm֔Y&Wd!tBPpMP_Sx ^dBB,csZ##7Kgd/z # _aua%'"<МKkARGw, 3T"qAk"ge$ߊNcc=4J''既b`D9' 2lö⎇@UBdJe$7N02ãDŒV ^Qp />1)rTwM̙`O{f+עS.8d//-3L$ 5ݻHx4/lHc% =ҫ@3e!M;:Ue.ڧ@nEKc$5h8KsЊ7IJ5-CdBΡ>]u #.bO'24}(pQD0t2<=Jq6X^҇6g긣-:b;)d3, J+!bYeƲ>U!6#DŃ f;KP]DNOS ۫wďl$ nϮGH@L&,f%?į#ͷ{ϐwtwYN*6<0% _MTMK0ᶪe{Yq"`T>PJ]Dvdٳef?8&?u,d8Cgp.P7d%J!ބ ֜x=f3|p:.tgo=͢lQA+ġ[ĩ WT C`m8U%R1Pz`fMIQE`\˩1^)!%%tO/ z!ƒ_p5{[m~+I y%"~m2"7#B[CBfL jZ"qO_%\ۑ3q"( eO`{oG SB Of٦-~6V~^Dי@`s8"SPBȁgcu݅ !s (/ܤɁ?)DVq| sjnGv-凔Iwo.+daiO'4'Z1~FS->>5ұDㅚ )YW9(->O ԟ=s5#Ҭzyk<(~s>ws~X;'zkJSLD8)Q0I兄7{fnc}qُ^TvZg"wku5>3UqKzyGX>rG͔em2|,d,EJ컅 laouu}!͞ԜBE\?CoΤA'3z66HVdV9zlQ[΁9D I:ehVRZlbUsUH ]f O ^m/=l6A8bV)v /;ɚ!1|{{gN~: Grz gN_Hҭ-y4M7JPfӎa*bX1FbTQtO^2/d` wA2=UduCOtmfBv 1cٱ%Xt3, TJi.N%CuúcE36(:=zşȵw<.-!:"L )협5B`77 ]im/'wrpS-QwPNw cB1)zh)0mgX DXIt%46ʂ܃*WV6H3H3ÒJC1/wynf8ynD1Ǯ'd퍒kϏ v[!} #ہHn^gŔ2 c9$ ۔z8xQJJVA\3T嗓.j Pk B}敕 zM֔ThEM@k%Ik~eNtΉ<ç e mPꬃ H2Aqb7GqQ™S/=.sPa+ #aɛ *+ z%B*ˬxW*{|+eA7Ks^O(BHZ{~4(YAOV!S^ԼRCϓ\VbKX Up4W#ϕb/`$ss?Uo\q~laY0S.UQX2!1ҩo*A#w2p2QjFa]ȫL^&<׌cx{`5"+?w$%tWnjaq^מ/xmg*+Ix5d:XGc uRR#gc7"MfEi&rҸFu$};oҨ]"F-.kv Ye,YijUNSe[Śt&{.LO]e!4Dݕ} Pָ\Nܴmߴ73=%KEO%د!:zCwXT(Tfcn{"譧~+8B: T^Xe ?o\YE&Jȯ|;qBpo Xo[Qٝ8 JU|pkj"&'B {(}y8F [!bPf+ Ҕ NׂO5h=N6D jlr!Ȝ=_&S0MrwFW'p2 nOb}xA 3:oI?P=a۔GXɿu+ je$CY;2W#G6YxQv,"|kخ3+$dZBWK/HӅ4ᔋ%&L ;@OϮu4ru6֢,WW/Ow> T@~ ~מc.){a)80r+$@>RӂRscV3ҊJԷ\cYejY?UI@I&Яl,X4뎯9ĐUߢ [#o[ᴿʭbAR[oCIe'jlL|8) W→Ni_ݵ~Vߌ$Mrmx ڂչ^?i-ER7'FKP1.^oBTBc|3wJj[Fpr7LP=ṯk; /FlcE: SL6`>AA Sl F3u \a& /^i]CR>]MrB8nYo_8z'] }2!k fKM]@RZEHE$I%8:hax(3m1._!Y3q,)"ϖ0߆i#ZMΫ`ih8b?X䕃Nŷo"Z$dM03αm҃E쌆ƕ:$YwȐM(JosrB =@N~ZxcG;;ki4䩨i9⩴S9@ɏ˖Gʝ Z]mN%(Junm$F%3ycxTC=zUm 6@t߀`.|y31\ K( (IYCJCƞsdy)waOx=oC6cU j]TZ#\>/o,ڟ/$caI^/pnpiBœ݈+#̈!ʌbA6 =FEN]Θ ,}5U 3^kF2 cܷ+`@ZPA>u7{W>qnFX iu[l{q ,u j:jS@ (9h*2 }@& +i4Ad9gC6 cCmv_}h6[(tu[. ް3L(8Gk <Fĥ6- 6^;?IGˍGP 咒ޯ!$īLȃ#kK}v˓<%V&)vr5Z؃/;ߺvp7̻w(a&>Ag8 n׾o~XphUezހ*w?c s M' 4}W,ɱQj]l%|8 * pqf;V{J5-#8]Kvwh2vKgɧLy\BK <;n*_%U,=MنG 6 S r~"4F-mٺ| yv0!CCx14='0ߓ)8aXx~uFՙdf6u ?Te83/^oȒG'.#Psܙ E_qN{Gw&2 I >bHDeY[w[ wW-NNd;&f݂Db>ysoQS*\&ZX`4R]')@Woݓϓ 4D"a~$‘ LyRbg^B'lLIbPJ= ?fw5er,#ntD. dԧQ*r׾D %u~Jb'{ܻ35AsQc 'ܗ`\e[ZRiC5KE^ܨ.~[n:<9!8ÐUӁ+鋴 n?mx1҄wk,qP}[ik&| ԜJ+_nD];}z_Zj;{|ԞbH7pT0•C 66g=VA5h(3n}`m*^/HEіZhzX2c# S q8D:FX ׬>B9iW\.භ8,/gh('<G?a w{/ir=F`7 ˗UjǾňϲEu2" (TgknOm2:#c a䘖K{oͬ9dpЉj݀;ϕKw3<|t("?.㉪ܫ3>3m/?hT78Pv?C"dX>։ei2"+-?21 K{VSzFX~{iGR3@ax,Ziu7g ȫĹddMH𬋹X۔*"` XPfS]Xjv~%j85/wݲ>Fܦ A6phy/kUh `,,ARWӷub 4pRzhPPJq7By}[:gs[h͵@!ֳߊ-$ k u1/? @8ا5jSsrJCK#Z( 7b2&@xVNqj?:x, YPxؙqr2$[rA(&lB٨PVr390 [Sc}t(6(E;1 'HQ<Q5dTlId ׺Uu7%cHzzg$#σqP`1Hc` mn{u/P 4~Rɷho/ý{ ixf޳)2R?8c&>y[%F#j9;"ְ8C͛5 ks >XӊS݋aAq"#Cv]MOĨjvQ0xg7%cg/~ XӹXxRjRxBO(nwE1}0ф2;WS5%(%mcӕĘJOJ/N-4|aMJ(9&?H]ܢ1ÁnU 7Sa^*hxku"=:MG׵MJkyEdw=wl42uP9;&ˇԖ3@֡2Kf4%H;hб}j'31R5%ҩ%)#M7srf =SwMޠh" Χ'.tS>OIhP ;(p(ș$Q`hO ;r+f~u 1ywc/㋈->D_I:|Js~hTkqMS--OH;ro%qd*`q*2~Ԕy|b۩0$:/{2?D/-*Po Tr*bH$Hʑn6*$17kXݨ/8C%l!YPfrBQFP :}2?vLɇ9Ms Ÿp0L]y ?nvT_R\ı75=ViR1x8q°nArh' I::v [іƃܾ!F`a~X~cF\*hȁ2WT"MzVN!rQȱ'{P8/[7\9E??\bsNJrLw 'gjhߞ\Ь|s[=戕x-fR:m.>͵05o |[;J &>1 & (+8o)օx/p,ސ7TWѡSI&[GTpMH3u Vuٸyӱp#7uu>5cː5j$-tJ8c<- bPmk C!$#(4j@&u^J͋J!'f j4r9k^%a aIjY:|:_AqR߷w2D`BM<k,L]a"rox5س٥KOɻG-'cKvDܸJk2 ^}U ~?~ש*wp#\^1CͰ#@w h фm7⯩LW"k3C>"Й+rvd [otcY/5w}ٸ{MXcm{sɳME96P"CdV_a.QZr jka<_h0L*XS ]Ut8%6o~:iqU(v&Q9d\ZKi餗^Oh꜍IK3jR9@i!hhr[']0 o~c8b ~ ف的ixUōB{tGwS;5HMyi\YJ9 K;r&A\[ig1/z-EnƎ'`cUwR~?تhtvƸ:i&g;a0,5F YR[p!%R}5EqI&YhxiTG/G$TSqV ]m@0({j!.Q5>]קRH4`O:oXQ l(M._-"(i&:"&*-!UtN~`*D*P#DW&$υuB3N|ɭ[v9X?06FK\p"J$toW,^|j|3`Q9Ɇ8n1ԃgUv \đnqe]|doqGBS1$;jq:3Ol" Pd[8l>W u ,EtA| IW1~iMJqפ^H'MTdš|\V4bLh(5e^uwK@ a!Y rKkPaԑqR9 [6dX;X(g7޵?]R:RZVL6*idYKΠMcz̩},C>`vXؠo[ Ǧ>w/ sV_{pg2B³9z \ֆB_mk!+EK/J뾞Rqy!جAl)`P{hgjBr%#n J(̻ o ۗЧV38 o5Ap$L‰ x)iF g5k[?,'h$Q!~UVX 8"Ъ,ԧ2j*(e SjNDy!=[~j10#;T;`Rc{pD0Ddi|:\5YwI@ZB yZڜ\!s| t_y+TF%O=>qͼ@(ҰJk23K9LW1s HZNgghsrƢiZy~]I'~GJD1u&dІT]|~< arkXyog;np,bj09ďjQ4_el-RY=,#x('|9V6Ǚj %TPGoU$:8zw;jA6Y+sVO @ cU^ZD!'yTsI3-l9qPEpdiv/Zђ|4f(쫜)rŶ^!tT;jHe~q ^XzcWʸHG%2ЅnS 钠2dn|y.VTAP<MڶE1LR4̱x SZJx.&6bЪ/0Ȇ8ae|+ZaǂYǚXxzYb)=>~ q9W50cURqxi 붷M<ztWlT"Ej'Y+.h~+?bcIA/C">F'ouSJDW\DuμŤsGtzBS5LՀ:c0;3 A{nv^=ӹe6 xXAx{pIegLd^UP %kK\%z@фͶ nH~R޿L$/l՛ jS8j;qpK\ůgE"ˊŲ0W-RMy ~,AN>>(f1=YbvƠ -un≸jv*'I#g*>۹C r^p2Q.I6p)R&t6|KG=SDGqٛ5A^AQtR.WzlDaF!715M1=ٯ8^G)uyڻp] ]xfB.)ECvĩxɳQ֝@֬Δʥ?>K)Bvdh]8Dg!5`YLʩ-flCON,V!; "/![OUY~M.ڰ柼 K?.>qqJʰL#׎T0.8XWmj`C@^vS4S69mi,i)̈+ N{;HqA'uVϼa }̥%KX/j[W`!)fۖi& 7˦]NBL%&frȦKZ*^<Fr ]?HcAk2HB Y T " _. s SFyC: -]!>6[k3!.f?I9)^e+NHAl+>A6diMIr(D9zIc(OHp p단K~'cc}um=z "j}nnS-/#lka MC՗{>Ӡf`1Pzس;y~6jj8xFekJ6 0 Tt'>7lU52"ou,W8^A`qyQl]szڗ'f/JYؠy ޛ>q1&e2pY֡. ng(S53ܞw0S30&'NsAhny^aKlK4xT/)#rZfzk@)m.oFfiH2#8> *F:pMmPFJe DRϟBa:͂*$OLFOҸԹVn5 dd#n692JJ M v+uVxFeEWn~H'S}f:RWI ]E@w5(o "iR=032F8W tGYvO̢\/~`^nRji?=$>(8Z_-PUc+(.b sGwݞoAnmi  3W^13oYo26gr*2j׭j? Fۼ.d0o/Rd@o.,,uP$ŏO-L^)^<뮗Tc# ǧ.4# 7pxHFq<>6NM7$\kvi*q9SR&òrӌN@hU{ >9g!;gJi/'Y;c"2yF#}9!M!sD!HLvPھW_U^zc:;p"KfPn>eӄuh6u& jz| ;+9. 4xˑj,q<=\9uds7 T݂FЁqt$mp|pv4VQI'b 6>CѥATkIwy*BK)#B$/9u'lBh>O^IDC/UJJǮ @ Epг!# Adf!ť/(zf31 y6]^,Ju医cVg4yS2LN2֖T"*:j+c݇2YP 8$1ή3 A9&%V5j# ۚ~_MmE ᒵ %䟄5ad`Vl94A85{=0sgGqc0&>/跴9[pKyӑ˞ޢRƓ7SV #쀪s T;'*| IizBޗo"YTx]zH̪ ˘{#8(J0qXW˹bGĐ3.k,d1ݨ`3|!XMv L/߄y_?P[>y"q-P F6'>*{k^RӤo܈#b}arA:f8@aUήgPhLn3SZݙ^O4HDVT@rRVG4B$jDv5?%"ҙ v)=ѤMsuW=K]ߒ_F[܏a2Q:wT-i8408oU@€bt #C5C,DĞJ㽋֜ԙu0눌pN%ֱ?(~(8 4D]3,ʿ>2H+?M23dI"jɎd*/싱g:fӌ|ڕnteƍbCO_=YHEgIf\+h? {6f߹tV?j)`3g3Ғ3@LD`$`/45W$[=Uw#LTmR>:CQ%a=B9CG l0d2QvMQZOik61]Jt8Wɥ!*CQEtL O;Q~ C8YV;v҅ CPѰ0XBK~U3N[ B i܀X¶=F_R^7\bǕLSfWO6h+h])%(pf_C‘ Юѡg==F@v+1yf '&Kꏢ$}ȥP \Ah aShtᛀ;19*WR[4֙Z$)LP'G@ . 5=>EUddX-D4 T5E!g@C䤋_P1DrepZ%ٜ8tdc6L6ܵNEbNx$]#gԕP4*$5!gSRվ؇T~1qbאBuk;>kd-|vqbTv hg5d7r1z hQ^;6 j-ix+nzKʣo؁0׽LracYܖG}pXggݽP,*^ u(py\8Q9 ;Ig{s%2cRAcbҪ (Vw\* ;ˆd׊TGǺK2[/I" 7: vI4d pmA)yn*k!:ݘ0zzҚ[;0s=L>h7M<0&\@4&=Qqtv9 z%J#FI@f g3@~ִ$FFV1vXDNȢ ln o8yKfX!)5s`Rg=B4WJ*l$XK!4;49>b6y3m'줕HX:טʱV1ڙfhǍgtTN.ގ}_TI>^R 6g$ lͿfEcXGG1&@uMom7/FX7{7@aYf`~.Dz݉6u6хIbY,5pdn#Yă$m1ᕐ]کjꗭ܋3RJ75+m^զ 蹒Ņ_'U2ަzz`3}74wD1pJ2 ]Q(]qiMNKE]_h s|-l3S:52 "R$Ur>SUFHa)0su`-z$|S{5f`]_זO)8U ))'~2X*F;y@^&z:nt t1gFLFMqIUQsiBwʗt)6J3/kZ/Z_2$00pg؊@eoQ> `덤XZI)cn%('\?w~2h *,2~m1p) |)"+ѕmG) \dlpQ{ Yh:O{n0$x궱Ա-Lv{Wh~ۤ\%Dy-דg& Gy~rI;@>Rsi6;4QEL?ݨ+|HoEiNu Vh3I5=P43dZ'M+k'N)`t(0D@;pi%ȭ+OFpl-7_2)No~lC$.輺|e vƃ6Nb4}'qКBFުTaLrn3O3(JQQ!&qT1NH !*u8H~vgZc3wlʆKW\ncnAգ>x~;iH߻enw$ "&{8ykW{fb]z0qp^uR~l ?JH,Q xv?qyIM┎3zBY Hiܢi[h+a|3qzkiXGQ)JU3d\)BuWAUlJ03ރ9o Iu@gEwx_:"H=h<`D[--y|CIDݾ\45B l cQ1zX Q b h[J^g{ tD/G`5bbes@*6l .2jFp9v Ҽg0-컧= Aq^vR >@ojLJ[U@,ps2wbO-H)'M'ǧ;i7;Bo {^c"T7j_1*329֯RFree/&쇒ީ]Q }n Z`ItRrMZ{<ïK4rVt|οiEN~ BA!W,3Ep|{Ƴh4 5 5"Y0f$ qx[Bgsҷ#6pd;-BێHr05Y$a00;>3I;0l0:tpzn| lׁ1\Axٸ&~2a6XwHDvvz0L4 \y!G´Njw6^ͮ N,AzA"{~`oPџ%p6ٜ2Cbn,` pd!/y9{5DO גD5deҜiON@u)# @Js #_YgxCty%2 Ji?,x^Zo:@LM2i=֮96\iTRa$$+ C 6x~OPQSMLIFջ$o݊:ENOҁكo#2 GؔRu2jA2-ozKL TN$2Z ;N<,BDBucXlNi}Aj^J3r}Kfuo0^l:PcgA61־~Ի7O`/څ:̀yX%"|>7Bxnj3ְdq1*JRr$ҹa7@,7Xzf 3RJ*Do"|P4]E۳ɠ\Z|W #U 6yWAވ=w¾#$^2^8zh9w)yAD4.tv`>n{7o tgv t5n\%hAm0 R}U _'G02JQ , ɱ P2*3/*(r Ah֛jh=vPe +XbOE@lt5Jǝnj`\cl3-m`ꃗ\"AΕb Aʴqe\l57X-ﱥᗕTH|G?!4'D PRc { cEy@@naiN#oo9a?)6W99F}.j3WN薬p}ke ^11Hw ˙OJM7J–OrE<#rN|/ΡL<ÒކGQˈ E\b*2}sHrBMlXZ-447:e?sow2'Lăʗɴ9p'K('FФYy9L€X)]3'J~3V]p8o] fGƥ)z6ñ,dpEQ"amwx$V7sԻKQhk=ɩ9KhmsJD#2S6+ߊ> [bʹq?:+ONUL{]d|{4j .*D_ iy4tל7iCXK\{ohun4$ J6$6ABqGR)`,'3!A=Ñ#!Jl{u y=vF;v]<ၳ<5x5Z'k;CwΨu >CRM$4]n(MwVfmGBٔ)q$ }Ԡ,ZV+_d'k.Z#-#mq$gvl%xLw v|fT-DǬ)DŪ¬=R;Ύ2 PAfLʙxɁ_΅~I/msXЬmhPflTH;yg|d"0/{=[M~L/`<g>ӫc߯%5g?8QM[!A}ɸKRQH=ĹT&]-BOe^w;gwRd)/kDX/ 0^N݇}+%n 8'n/hg!EiwnKv02끓/\2ǿEO.E @|ɬEVPM cX77SNWdxI}jJ8w[uX^CevNR,m5ԑ%؂}N2L$ O}k+C^JP=y o!W}*Q;i8cT YAYyG%7E,AN|56idAijq=2eG[A6Mr̄hzHT<|;b mD x)+36[ûwlõX1huh݆Fd]ggTf{׏O;E8Kx!E7ʎ*2eɱ*46a{02":c 5ҬjEK*x99턠 @,h$nD*"B-A/{2>AV> X&x-,i-̎:wZhb.3WIsmp9F O_21F&ќ&̌Cnk4ߦxˆU[e%h!%iP"BYr_3cyOXBT!-l>P` ;FB__e9J ..ESP.;~!*qR6.h wl^ϭԽٿ*U/oA 쮗yaf;Fz! ,ATQa,1R`3M"FB40_؋,8PAA9IN3:#&> \}З}W'))G3:n}N}d=*6Ut_"m)BdoNQi3׉à kFCPoGy4q>Liv8҆5Re+{z0=7,k*sl|`j)7FK)xe1Pe!wWAtnkP8~BbB~T U4gE-W~4: Wuȃ@^!,Q4.@ePNtxyV%<ߌE4]`ӓLYpAou!4JPXi]=ǿ? -1w%3U)[W``'x+ȇ@£B ,ǭ 1ɔg"9#miWk ~pջ{ǖ*feC/$$}9 }d:VĮc,Xiؑ`F>ϯJ ! l&N(Lf0} cpGFd ΁ bi NtH?]Rcbak!wDWoFKc7s+U#FXfcxocVFDdq\!ːzvWAVDS>A]B핿6ȾX_:Y"+?a[_5nErĊx<uqG NpRhbE*-QgŽ fu14I$0 ^R, i?@;&ɕGLٮW'tF-gZfH&va]jb-Aمpa*[7kMXE#HdCe™a֫Hq\1c6))7e_E.αX-ԞNㅋ/fa`@6xU)V֯xW2b?GAI#c`C博$u&s(zY=%U*;361Rok_ՠL4C^Oޛ`&Z'A8|/2 ֚4յ`ވTQ5jx8m7zXH|ՐʞGHpEjY/HB􀡇"1tU }rY`_ՔP*zShl'lt8z"a?&J DR["a nplRַ~}>uAK%E1 򵮴ߦ,Z3 CԥCG®TLrp^=x;G)źF=eۉ3wd>UZ 3jy3R7Hp>)"C n9.q? c;O;4bY &8vWFUJguvmJYQ0s!Yg:o0$YuŖwo9z? yˆcd vqzSuح(!"F_=X=va<*'^4j|R`%=A $4-\W 9.WaЎlZroQ0e4ތإnɗ7>m0؎x\3 'tB 9FҞTA8E97 GׂۨHr7} ¿x xǩkꪄgfhWy<<«۷4oBm4Scz&W38!0s*=-rZ H^K*^E^6|Ouc8PCɅanDoS퍹z7 "\bҀbL_}}_!dsp>¾ݕH1\1/dZtL71S,}~Q͹5=1L`%} J~-<*!+$g~?۵m;K~i`̋QKᣚtpf+؏k{jnN.CvF&W}%:Y%7|t(%px]B,/6K(n(Ad?[vsйؘ2Pq@Nnaړ@FXv;eח0 AQ+eZk%B,gÍ7x{N)LOYu\ApF`I_J#؁Y?s3]۾ e<UPMu7b 0ϯQadԭmsCv&/Bu8 = 搡`qɄ,ұGa4# >[l8⊆=_Q鍜M4O3IB2_#Ssk'pl*66Q=ق c ~L,OJJlޒW;c=~AW^J#[>Q"5LBRӧfP/];CnBDx# l=/ޯy6UaUHK Bag>:l!^ u#B)I g,O!r$4{i+`?spgZ;݈GjW|ȜA|x:d~LJ\ rX{ksT1K1GsBy!&3"cLǚ0*)x7)$ 4?joDÒ^-ZYSR" 2uS,1b:W eNa܁5! ܑK&\ƀ,ּV ϶gq71u2iOt &icf(<5CbjHS} kѡˤF۝6^6 \I5-avGB+~b5= `Nv]c߫u_nyLS癒k.P|붫h.Q.PX_`:  yi䮸_uϪgtgn[ؠX۾.R3;e} V6%" -$+s-,G}Jx!'${a9sW6pS4r$d"I7^;ٔ+^˓֖&xϸ:TKu9"Vp.9ˉ )ax_V3&(4d]22o^6;Qkخ,צ `L>il~&]X2pEeTQ7I>mG032`9&_CY0չR1 )wҐ6u-8Xzq6/UE.Cc{ u B PRdLqY5gXtˀ:)GQ&>" -C\œB < $ a]z . ]$N$&ܧu{v^z7@tg;Ku.`Z^:kvW++:pZq*5QU|NBP%URX |mEjp}_pcDa:!\HsvyYi~FP[G<{0)+{NOբfJ J \j}_F-. !ߩY_nyiN)hN8u<|..C(Tz&u~Х::hQyoQ o⣎(JWl0,[:$=<tAum9~fs8{ap`b݅"c2B]y.;K;b6:/6؜A.<`\^6p N'ږ hcRJEM1yߦ^}܁5HDRa)Y D]hN@h n^\a#ꔤR& 7YD"} }$^Izb)Ek6tMXÖ8?=/mYOC(G~;,΋fKdQ[Y'ͽ6;JcX錦3[Yt1sNLjS΄$y>]xh) Klr:Q1HaE>^3%9`goʾ}&SmDz: *B&ʐA7D˥t OPM4 L(WbN!۠ #{*zeXݽs ֣8M UY () AKdalT؟龿,LZ^,7$qS-v|s70[ކ+(J^Dܬ]p%)$)[ ̐]x bH Q-\អ9ɐ ޣ$Hs_ u?¥kds9?LjdRJBИ_]RG=~;D-ƮRÓj-+ Q {e_\B@7\!JTgf}FdQ9a)L |PWM2UBA"uG(X>x?~at-шQ1W˓@;)Bbg\:Ģ׋ gVG$ftl|刼Ьa8=s̓uSQVdS1A=5XL;%"tc&hJb2if+wlo@,r) Hax Q_Z9|f ,P"+:T v5\/ZE'Z qʫ-_?ZMUDfٝJڅ(iMl;T/ 7/~,K$<x0qʟrxG)yrWv@dL![X4b"y-`ɤOXBNkwg,:8Γ(0VXpw?-W>i^ܺ]ㄭR.?TojF#% 0ƞPAS +]wp4퍒y:+PV~MF'sre׸tz>{*Eݘ,E& PKԤK,=ˬs5Nchm5κ ~8SZRE{\ (`NBdKF7?!KC[]Q"ʹH"8%o $VnAG8:Lx2NzV )Wl_TKP[^ŋF-R6?+߲ wQ'3q-sv!A5}o2"pzmc Ay2w ;bac= u".7_l`шNq}j,"auZbkcpwR{k&7prуa6G̙F@aSxzGs)sݱ[-ѱИBk fi{ů(C_@ cNYE0 URrV]5IƂ td9-xJy|1_"iξv*=T(E?(/-3b@C1ۙP\]mBO5^tN ԁ Ү.h(ؔmaB]ۻvfeEKZg 얫(XmÅ}7ǣVjKWcKh"4?H:.Q®ales!L6Rled֯'9fC(yΥxY\Ճgzyʴu~ݧi6`zJʔS1spVD M *!f8ԾS xQeSpէWRC+Ŗw(ߥ]1^_ŗ G.0 ^ĐW&Ȉ]:G4\r(+"}QǥfrD!U%dy9d*$pef;+\?.xk7Y6ƜiCHpϵZ|5ٮhנa7ȚY)8R*=ixyP2OIpmER 1VlJot d쨀 (rtTcW|Hht彪Q9A@w2c;jQ,a敀٠0#UC_|DNưdvC u QAlV^%ՇH+3xb6R5jUlX4cqz]@Dv ׈w$o8t1c?@~Z@nɇˉ!_A2Qa ˜ּ^+T%JGDiH1{/zT"+= jc*aZkrhI}M2 jz]l 倔,z$ķZ >{߿]o!/^;84ߗxB B-q$c$?+0lhOuxqSN$ܭ.w4͵AypqDEVFC%a)/:O-x2HVv7^>B.ιpCjː,0tn1Dlm2>xa4kr ѠAv{;5)“G(YUxim$P?#I%h 'ef$"\:!XRfRtU?Ϊ--8qGHwC ,4̅ ,㻈8Uv=BdfIzڥh6|{jm^$y?Khݯq3x;5ˢdJY*C,,_ N]|PwjuLܠ$ x>5swˠE)z>d6ʕi}ɅJׯ?jPز'Ep1HAWrAT+< 1!]_/,BXY 5)>ϛ6 !{M?}G7<>&Ts yP†t?:/<|TGN/6sG8YVdK a|:l7 {{ ߖ8z3a)亦C%yH"qpџ_6H{jɷ@4n*x84u@?!# %*k Pa/?hWlH` -_COj{]>k8 /%etY|;Ų Hw6A]a`9%Ru&sUsR=(=#Ŭll@X=쮗u΍BtWzDg+b)(yp]3a-{fH;SF}M yHRp 5r'HW)j1*E9T]U}KCzkh!S9v$<^I絃}efY?ZFAV^ q\IW wfEj<Lso>t'm=^1t#﫡Kb-$]y;[(a%n'eT(Zb 24m $ 2uhG&{ؾ>XWV81#LfT "7wOE"W5W$aoNɗHQÓU8S_(jV!O !f'jRuݙWh$5RuUޚԸ &F͠2^'<'h`!IJvf* MܥU5IfvP\ >3Yo#`T6;Cÿ`G; k>^O\KB"Cx%uWKAZkG#QBy,H] -vռ(=;Uμ-R+SOQ?Jt/q G6V׿}`J{;ei4co#ڜ]%`_xhr+|"27KdfJ&IIP~ ^\rX*o @c$>`E>I^t8"Z :dPWP6 0#Nc`t+kVA}ya5 . 2N:"(_: XMBd8ś2"EtZҍ/SzT9"olQSjYaC K[XDi˯+d6b"0`WMԜ&53wkiCvENBG5f} iV:l*n.XJIrh}52d>2}RSX&'J|޿[nW`O:DgT{C@CAZ/`CENZ "n~S30yz49ZSG;4`Z)_ԒR&bB^6c@R| ֤ymQmJd.JFԾ5v !FK#X2b]3Qaň%gneDYiJTm߳AnbBC[zlyd4=8|EQeYL®w-L41~JBAOTauÞjysGqa~ eҿp;aK6t J؏c챖c%f#хvWXnóC ty&+PJ3]P u rrLVn"ɅKA?7>0\r6HCWpEK;ݥ%!qkW'dtIMz~hiݮ8*? D+.RJM'Q*VŽ{Cdɰ dostsٯ ЮT^E9 ؖMon(juҭ('6:uAzhPaHh;3[вmyvjz7RH+NvYuV Hw@)) v٥E^Yf<a>,=Qp/2B$.woPW7J3mgc gUΪt/Q7S)w# wncUi^x=ɋN( |؅|[߶&ЪWPxn[%$,0Dܜt"Xlb{U[|q|Jrtz y - ^~S&0}(|Ń;i1 [F uge4i-uֲX`0X'} @l㊊"AU''ȀȄ@o<Ǯ%h{+"Sxw$3$S @td=7ՃoTY;0~d8C2l!\9Ewƍ ׆iX Ӈܰv83}Xe.oS5OĈnຫӄ2^Ҍe1`Yfg%V1{+PPo!#pI)Q9G#h`wH>HFd>+8)x=j) &Ms$!T*D&A" \o2Fxsr2uw:0S&ҕ`nS܅w~B{n*ig?˻d3GZ:*j_h0bǰ XtK&%{˼D]x5WK. G\2({PΘф(pbfnbpSUy0-cb\]y9i/Z}Um~3cg6˂7 0 aЁIA n-kX>5[ 9yC-u]Gv6Xŝ\gW*euxW9PYҪI2*;Az2)W۞k"i~vِ3~,Lb3{Yp6K7,&~lu,A(OH~ O@\}FO>nl+_@](lXoܾj@  $"F^:F0L9B yOpvNT'2$MM%=[!ڰZ!qDѤEZ5eFM|4JJl==sUSbzs 2eߖAdw [³q@)IIe1MQ,&럴!x[ +vM6=&xX69O' ˶fzI|wI _*r* w`a@ v")S\CyGNB>`ri5_2kÆ E<h{[ݫrl+fWu*9Q_tQ܋}Ld%8&{Ġ8BƈC\,ƑO}T'~x.E1EZX$ru ML:OVpOxfsQ_9߀e.J6K+W&0|Sp)z|6f{}spΤS &xM:+G8,6)̚r5>d4s*ucw-aDhFK!HŘ\P`·Γ䯱/b~&2uU:Pg%:# YAAÅRņߚﺶHYf?F.c^ßn|Ϳ]n|Q ݏfz*tO=m?#|L]E|*=Co98zT9~_n95&Z%+4pILp݇dME-/,e0 fYa`4z Mxnu+D7r|1qMsfGZC͉m%@hwo6 ZꐩJIb%v(UFI >3!Q;BruV`G- $Q#+| g_wD( ֪@Kz]p7riX;%oh==ha3w aX|z G*XHA*,]t+?֩ +t/\)^k"ү߭aco 6Zii%eJQw.DaHhR:O$LWϩ8?V{PX{׹q"VɁXr)p*)7XyL[UÎXaWA V%wHjPtHȲ|5ȢlDj gx}4dh6 < ӼRF^~\=RFL1*!HyaY*T^|NTki/Y;# qB h/ m,ħʢ  3wfXx f3&U4cF= |k/( r=|ۆ[`r@tMOq .0mET뮐%nilVi$`,'apˊ72?QK m1*H׈#/j.[w#mMڗpW:_U+:/,ү&aS%"F d?S1h9_c+b,'bafʘѻ+>p1J2? p5j3Gse@m ֬#T#/s~ \AnUDMAb}|֒'}mXEY\D po/bzP#!Z^f-GYSVR ܔ+WF5 3ZR V{+=2|PuN~=4J0M="'jS"hjY=E˗K @<#:^a/): dwR'T"& =/v~K۹,ss.A_͕fꙹdrXwnʫ>_H`?8Q fW h ilթNkݣËj+ܽPTе5( Z>᷼fӴe$Sb1ffXn='/#o`T"Lw,n-qi V.J:}vAVNV휼gkxKEDn8Oi{$M8:׆lt-޹el\h9 2v>C~0b8Qƨ_ob5xQVeZxIA57O|!8v("\>_Ig0ZXd8oR 2Ng1O˻ejmY[ i\,-EOpqh,bЎEP(q;1^b|^PI =uuܸ$<\ R}"$FN@1 B#7!Z:j2n&8K9:%#d)_<G_A*i*ה1x|[˽-Z,tW Mp󌫟ШCPūwf6)'p2$6YH*Xcb %7D{/%ٯ9ĬXH-tjW,-ra|J4̈>,NȗՃwslGx4V#'ڛ̐@`͝I|Aaq cj$>?5+>M/~Dx TpR}cyCx3 M¢qʽX.sOu/+r(7yIcPB?zvPʦ .; t oh_‘!οaG};4JZ ®\2\v+ ؟zxQ f!(2+}ch ~BZh7LBC{s(lƖoXaջ9l?<^W)80*Tbvs7rpMXb(n? ɮCo5(t(|6:W0kUܹ.2םų[r!?EyF_{79o[67V,_xH2CHA^B,=%:l5#fɡxYIeSlYM|B,T,w}/7pU e[:"?D`" F<}1 <o[wØ-j9kk]ԷOp+NuEDFNJ<'3* [IĀ_eMExp1A*R5a _hݗ}]xݧ}^<{b4r7-<-<}txq%w7Lb6DD! Xn}X'Py6jnQQId9dE(*B'A1N0߯ꥨ49Q&kjV^vGK_G~!xikU(Ҕgrԅbks4FiMZIzjE,C$E=͑=@rMoi!A[X&z̢լ= H2~%^FUʼ/DsF!, @zu乛2qnK:/sf" %qo -o:w'-vR*$ǒq? q K+Ah1ȾIO^! QmlW/@.£-[n=Dv:8;al1yd8h3e'RD% 3e#윏u?Btvbi /‹ {+2F*&v etTD$Q)I9v9-tEg{_rGR0W=Ltʢy6p] QEϔ&ԯm­Ҵ' r\9{*JkpF:fElﰻVsB8(KvŠ|rP^wSS c.!۶]eM@_yJNn@f5p^DjCzmMK&r$n0d5?k7#-zw|dotSZл # gY㵥$F=mo?A@dudڒ$%~ pxQFb7:_GA'tʮ D1+ pCD70]9QL{%!q?+9!OrX6Jfԅ5A)#õFfob<`$QVy5PJjHlOC ?<&2+$DhjpUo[URatM1&{P ㆍ 4>\.E~y"w t|ԨSW9 efMV!SfӈzӨQ%7з*?Ozg6l(x; cmH\ 3 SX?Ns3r:&}?¬2,HZQ/{[˛ {g#J"6)?Մ<쪖{7H|q=a\3U# [`_ P"cocd1[˙>5 Ee9,`IZ"H GJ)/sf٘DW2kt%Z,wا*ӎ+rvӸ/K\N'Ƴ4]g>1pbi(#?#W桖BU՚)5l7.c:;O%rRx&6v(5BŷKZS:{~CgaP ,w$Dl[?7:g,@j9cべO+14/QXp4AO!oKf6:Ѕ0ƿak GT( sa!ׇ~˲wGPĿKrh<ã+8m1# caKdG~|m'u{fWpr6$ʙ!;>}w&pHr L`NgN\Q[{\Sfx -{!цR)Xr,ZiXijƑ|ى<1Cђ1轄Uq%PJrqlƇrmGY+Y'c:NAUu14vU3KLŰݻ;j".].LZU:koҴLNan^կCBSπ7XhdJKQUn'+ tN|#>)?'re^cGi|ѽ{|[&*>mc`RK/E՟ϮH\Ք6\K%J S899AܖmFUo/,vn J\ᜤ87K[T/^Gk$,HIfZPmY7xW*8 [};dFF j:t q5\_nb iq?*::10uH OW;>)`)n;!Gx`H$l!QqSK]!<ޕʥ-`yDž5 G~J'Xw4H _Ky`2AS[#ky&2zFAhEr 4"+}ךzDONKIl6OD]2y<:+f R` k/RڪUxt5vt|;XAV-xQ?O.̑C}^0s xDjյP_0pǵi7 iV:DžY&*`Tbrɦ| 94i0Y`EݟqszD,3 >OE6Ŀ5Hrq"{ӡ<)4rFx@kb+4;)1%V~z;V.hUKM%p6\:3Bt8؆vM)XM 9 nҲEJĨ).<ݶH)附iLڞaxQEx0d$}B#[}73O6$0)B,.!u35n%;:\&]QS?OlgCk7F{AܰcQrJzDj<+n~k ٱK׉l>^Ǯӡ=G2UåQy+ah!xat>o-cuXݛ46r6ВN ҳK2kaT? &7 {IhZap?o{2*\zKޠDJ &Y9a1PMg7Rm1w/ 8v?$dQV>_ۥ8iB MUqa]~]wcVBw 1jol9Jy:Tz_?ȼwQ*Q1БVY90rFM?[4hdjИe d"rl>=;&05#򁥦Ob\(3ZդuKR3N'l,j)>4JcLU/Iz^ک8sh2U;Nt{+ǩ9HD=!gƥ-3VE4RfWat…ۢ&-V&:b|*ce( x}ңa+}d8ry[[qtYfSV.Oϵ$I[vQxa<ҹ%. Ԭ1lFd=K'e:AosbܖjV `lJV6A MWq^P65XGϹ#>>R r5v*'l7tkXyRӪ^j< }dUi.ppxv 1d{׌Z_[ 1e<ʄBXKg hvY&{sB='(ñ8GESviQ`fOꒈpd^*a~Bh=y%cZ7[0+uk Fhu{9FkJ9UD#../~0^'E,89KKs'禮L DiLIS.92 4k~ XT&]IԆC4d}=z9,d0]12XGCh|ܲCE^*v=."I$h|D[u9/B Na^Ng/,.Ao8r襸e"aF4 W(J{{F5;]1E,t4xTrm{1#/9`\ߓ"-ciP8B1\'iU"h:tsqX·O+֖. \ ~͙LϨҸ|EU[Pn |XY^ i{khu'nŠe)HuUa_kr$NpzYyj?ck{h2X} }Z-okY ] x'AÊf58A!T{3){ԗHQaZeohrM'N57WWMࡩP=.8grQZ.H=n 8b(X$ө&@4qsAsG.ڣ2[8ư`:;PD\%#pP0qGXXGǪk".[j\*<<Lh5u(8('} uXFF~8Qzlߍl`di7֑ߜ p4;w0+?I(gŇWjL˂G -Ћ^/G"w#C綕. ew -oCej@ AYS; P2w2%Xce4zk{]#DzVOv qbʽt+L})m1OnD\KZXH!``} o4>\9Q4>5lyD鰓ㆣ-߶G f x1"␪[l, R@ RSIW`T&TLzjb2 xTxd\rqA.yuX6(Bk=VO^ >{-h)t̬7n(@ ۰TZ1QfTSj܌ 8 B8++FE^ECL ?iq쯽'' &siڀ$Cs ԦUǑT Kԑ{;! A+Wm=E#FŤ`gr6 |mT\.60zK3|zn] 8ױcߒO D#3&}WnttW&qvkM œSY9c0;?YjH߅`nh4Fg5p,'tؼLJ!]b,iN.@uu ?^Cӽ^<,XŸqlڱ찦 tNԴ۬?'jme|QC=*9r`$g S_% V*>MR>a,gϡEgS~M h1jW]۷tL!\ag\p8,WNI&6bBbbbÏc@;X«[--q[zzyڒiF BSEA uӸ5v*"rÆLtFaf L {EHD./j9Y>[|9nP I`U2gIR9iFg9%X Ԍb`_BF+ˀ4)|}k~emEQ? ji>@b_ GX01C@׀E3&H='BL]-3*$h\ f_-Xü&yڀ K"-L]?Q= !yzS tII]d}RuJ,מCE5 .hE:KxxM_~ 6w?}]]zqqI0~H-fP4^[ZL[4\P#_vPcZNӿNSzh^is(?Sz0zŔݵ 5QE?c CU}% QM߂Ji3M[B``iKَ9~X~Dt\7 T0~mZ" # CrwlUoV K#ki$OKZ~zN򎎆Rb Av‰n-YLVX= D Uه#0Η %x1n^koAVBNj`| _h[dmWY .^#e1@ xAYLzwv3\ {!N3 vD=DXYƖx"S&^6RT5*^5繋+(-ؾTf є@,9pVJfοp52M_\̮rAF%X-){w塀k[dgK[.r=" شu7pSWK{W!xjt-ebqScNDk!KA-ݒ~`AtmbPˌӜe q2^IeĕST 6W7DfuK~,o|(=Wv"﷢.s}>k0k')} f=?8UA{#P ef.5y$)$~+Z޳V &d&7+TSCgb*Ǐ>Ʊ61:g5 /"Tq =7ߘx ^,k׎|~TCN Δ~r`7^|_-/*uR *h߱[g5fHl[Nk"Bth~3Lu%#oH!ITgz,Y3 :96c>4lNy+yq4dwץɳ9htBL0_c4b<ÄCC5<*c& z9pK$a^oS MUo;#F?OL1dx㢠ťDUF1l5 h('[/:EA{ϲi>hwNq Ӡv/:*L!vCC(S8(Qe*PE=q]0_)?vTtMWXKύ_i&\b3v#Ye׾3|1#ȹ[㙁(b!mq:T;W n=nϸ^3ʜ=Eo0FnYBw9 c5?'3[gˮ;.iO d"GoT?b_c壨׍"3IGEEv_+}RqdzO~_~x }Gi'W̷φs9d"]~.a`mNԍ\C5t/>{^l;1FεTOpi~S>]D!wvA+8\ @' 6{*q"g"cBU\WِL:p[.vAY`hziV_A4D =x;Kcϕge$B:kFHPV@Ium.URJ*Q6vMύ6b/@̄B RQ;^(KKd:1q-uh}`6Ub%vN"#)(KAhCGXْR$Gv'xJiQDK< !61Ya`2ΌYE=~6@U`V63) 4*Pxwb8U7ZV;.kgDŽ6d,õ H Lԧ.*BKi6փglM1=nQC*%?,i"רPmFZ *ꆆ0W-Y̜A5x>9^t ;2})nޭQSH=g0,'[-V9]_(&pGpP"3tC^c0=| 28s*@(Oo*p5Z.#,ON%:wD2WGΌC(xiC 1l<eHMyizy,]ؒ5Ch"a`$΂\v#"G4 %](w B{6:@?M'9I~9SaKqk hя X#sb7uv-d ^i˽ V &t%Ֆ?Gg| _nRgԾ9pypٌ %70s%)ӰԈT5(1gMAӴT0a7`?.(֔G-#aʰeEBE(ټ_kl-L#~u]e(o‘5|X{MkkCԐ€2" o5Բ:ɟ_z*1ȉ:jI 叺qfFc&˰20Hi !a݂~PlYA?q*.=V2;Pgg u5ڨǵ**5 e@ IUb t3L!16fc50X|Zk9C`;-`g6b!/?ئáo`6]A4<agqY1}t"H7nu:\tvϝuUЄyȂcoC{u-\u&hlQ6l`jpSo<ܷ屎{T=22a}|ouF,ۅp0ڪ]uEA 0#\o??f{ 뤒Jv2'@V\L~_涳u鍪4чp$ NLKǚqō@A%cD+*y4c4njd;wKcgV^|*/偛S$w~{,;;)`j.@i$ *T )6xuF!-tD.p|#:=ˍ! bM=y׏墉eŋςg*GХi*1J%SܳӝtdFѹ0g kFfFR;F= ÿPAscIO{%/R$"ՔQ7+JljM&x`sύߡB,#rN[ H߼ހ9m}Brɏ}:tokQٍްtPsG&L|l^Ij#6wkl`QQJ@ GSo߅]$hy&xk%UN82ݗaH4H@>20MoE;c( ^ 1C~^"DA)AI ߦa]mf{\K8g}_1>5&V>8 HicLO çY\t2Dž Z j{Lhxx3(&<9DhNHvtʚ'肤K?>a\剧 (gʼj2~yu]"1#?dMb3k/whH\V_I|W3kqf0wN)5@ 'Uw+p~Ʉי]r&,F[][`zvhނ5%*V[u @r߮Ydr+ׯ>q1#]~7_PvEͪ58m&7EluvyF}5#?il8"g;+Rt'R[Elḻڤ8T,Mf3<דD\bZeŀIJcmme)bxFlMi,Qe T8|K H9]$ l;9,za&dU=3yH2.*|E+([ o<Ar Ԫ??\|]:{_^Bؓ,[ C흿0M|Ba4ڒ(s:@QUgvDaXeָ7?LNЀMb&;A;H5Mz: F.cHĦ]ҠRh,^$3L'p6W|l۠Ϝvȼi%:g+gbMc؅|N(nb Bsgy #y*=w/V L}1${&wC@AI1u(n2JFw[H{)&uI s-ઓxtEadbspS>f7iw9́fC(G}I!TX"F1Z7sg λԯM`KڡpJJRT0rFfR1Wk֠5c1Ud'u>cgA]B~%YRoLU%gXb3r~?vGKe=oV]+B0&bWreѩJA'0GmyNޥC<0)t.];OꞠ+6ӼQOt.֖%E<^Xѓt&a[:YΤnVj:ƚw5*OokVP/YgdU)k@{`V•:C]#3$&8__eN$wf(<4z$7|Vu؝q ܶveZ+;S9 QPF\#.[A- cg%b^9@?W )kRJb˜,ќU)߅50>SB?.")o$?]Kz\[+pfn OEqU 9j->.=@$Gt*j {gE3,b_TPcǾ#d>=w0eEF+ɂi~D`Hޮ4_4W?#fM 55z,l"HVOJ֩b-{i_OnǤ 0q=V $dϕbWL0c7`al"QQFЖ }* St <%M(2}>-cU3/~/dhJ'}\̧5Л2Qgqbo=_?KҜ{OTP,lj)5e| ±fƙW= G/q.׿P-!/v[3l}cQd 2pqA1C;<[>(SgVQa,?uy24 +aEv4 EI,& oW)'2drhNuBg WO=[Edeҩt!ϐӢ(%\OnvYAA+ ^̖,TvBrM;ۤP /?}x?djm~-2* ;XA$-QVüR 2YZT *@ȲhL3$RhP ʊՎr5ӄc|52nD+h9Lw⢍3гnO$˞˖bgN^*R% z2>x3[ÖRَTBYjJ봰NЊr*ѼUH*r}!Q%))h)tP?B]="3#y$dpVXM䭣 N;Rw2v4Y<0QK9#p`p(]FVY :դ 'baQ/{/L)T¸t?@ :.l&qN %_^\7B ۢcWR~!v`7> | Y`ng Y!b2~6M(9Ad&yap,VEkn 4"p|u3ׯbSNo z &pa4HnjSUpCIZV 11 ʜ5)J* A}3S0tPSfIb[5RVHi⾍\KuR@o’q-on4ϞW|+L-NZykJ$)O|T[ 6Lf[tMvgɭ9^&  N lXg:A"c J+#| eb㦩> &ȈNK%>̐]|`gC*tN^^2C ;^^jzI+hFEB:ɕ;QKR7TMGRDְɷW38@5 WV< V ֿ/$uU$8i2ݱe* rAߥ} 噾$7rd}@J.`_64Y~ ՚1Y=/Ҥs * ^YmďəGr.?N v:G/Q`LsHw# ?#;ɉU;*Vl|U~F 3bOni(P Mƞ[HgAA # %Eؼ#V V8^4ƊnƮ] ĺT5\ġ]Yc~C_lԬ}vmZ+D\$L?Ջ"7ÈZ2,گ.)AHb#[tD 0. 0sq>ҮTC's*;lWAGƎMW~ia-m' s@pORNIՔbmO]Ԭƒΰ0En4VxQWZ: k%EeoTLn-A M u'Fĭz<[۴MJ&1>A?Dz`?( N Puտnl _\K31d82ugƑ.X< kHlb@ ڤp&[ D}Nܷ`E0sHy0ε[rJ4OY뺖ten|QOzPpΏsи9@q%w>$6Q~M#Xv2p&/egޔFlD `NV1d%(ERү598h6ᔳxE2v(hzm@ .I]S/*BVEJِ)ԍrgƁ+Qs:s}5^y=%mtk3~6X9ˀ+[`oHQ]pLk6k0j[JeA`SJKO c{ .!Qۮ7\jA>Q́jO<^y4L^u'<ǭRN]ܵ[>p̈́!S+^lImp̹WS Pӥ̐ y@eMwߟb1lk9y(9sƣ1X&˝LRS7<~⃑& )z:hN7?^En-|Ae:/#P!cLԺ mG@pWWygG`p9ܴ#szK;s^+(o9_~s 5Ən8v9/6#p-jZI-7E>hg؄mccw#Y4Wme<J:*@d3~y:&ع ïS~(Jk˾^td;Dkmn\65ۅG/ͧ(Hѷ0ND%v~0s*2& 2Oua^u*Z˻4DO1gbpi~B+c3s%,X˶dsB{"O퓝jc#x"-#ke* aP# n"dB>;+ҩ(2}mb:.#-YCE.j4wyh:]tn1^nsXJf͆Xe@lt\hFU)y+ˤRBQ 8,W1;7t]UT&jf=6?mҲCeйUct$ϖ:aa⻬ᚿt U44j/bI NQbʕks|֜<)9A#&=ɒnqȭۊ ~ޚN(L8Y2'yVab즻Y ]y|!RufOTyܻRJtm\sMoADg"c*0;jFCE#qz*1> G "PL#t^n/kS`{bXU#Ú>8ak46dG`4Pv3DBiW\0ƀ-n VkFeCXGt[@Ž3\Ɋ!4W`+.o~keat_k*ѩu>;&+Lp-RVӑfFH|z)'mRV_4ٛZyKZ'V'.-jq Pxݍ1ۏsS `nB7`kw l̤ho }C:ysÌ]Bx6g4ܸqC^}~]-{Ax1>ndP%~!w.ޚ]WnٚN:^D#vtY;Q¾' mA]OiW}d4NNBG[}5?`DU=̜ū1e|ľ\~a~ytg\LjjN g 7Jx_V:TN7H Byyÿ(瀪4dfiJov' -wޜ@IcgZkٜVG3=7)dhcc% JUw,V&y*dLɻ$m}i~&mc ȁ2߇y*IcLXT~}ų0G\?T#̕O *tvNMk҉2UZ*$npn#CDa2c tmY7?NE֧8"M6 5U$@ #U+xQbvyY"N,d$҉[Pt@ž軨35_Ď(#_HI=-fA% S&1x(kv4y 2/v ףvZVC%vr >EQ(etd1z;~s7Neը8*T47eE*ItW !ͮlך'}Tvh*p&fC"x M"qtW M|9n%>Z> } Uo MM>FdyK~rJ-.8 93"DZ_%M"r4TOZ,PN6Z`ȽK$KO|q3'Gꁊro8 uI4fl/e)U?fn8DOpkql `,f# A) %jlRb|+!)"yOMIi,>*jLZbn3m{x1ci\+Gk~~ak<6я&a7l)*:rL9d KɄԺ KqA\ȵɂ١{٣l f<7/ϯǶ1Iu:yheQ Nqu[o%S=iOX_xnn}+F1U_'sxβ <;@RL #mgQqձ?a|Vpa a|kcO*eQz|U۲v ]Ѳ@ Ătŕv,Fk?Uw0\֌W$dYrac!YhQ3pJ ɍ./͖N,ÇDnLcd"q"Kڛ w`݈B^Gp+b[s]**zBr, ܹ(boaB]N}̑z vj/.9W`+ Yb5 l5/kVYaBkv۩&։KT(F;}&X`Reѻ4v #׷>(񶺌!?O :LyRkNP(B@^GƤWjus5_ {&\IQ$׽S Tqڵ{r 3jCjOߏ c /CN4mlH3PuGِ?qxޗV߀`J=MQ,Ux|w"^+ezi&]7]Vr@hDw9F)~cQHwM>H ϖ5`:iBU@8(@E䧲e1L+WT3Yw0=Y/]WG+*x;;uJx@:=5bՙ{Ftwh-U(ya[Բ"N`CtyDz~}X;b}^cw;F%qOM7 >P@Օ>tgVP# dr8JA `AH]FQ9%mf"”ב?W6Xry`\)3Nm l! ~ r߬'% )q R1%6MлZDa 2xm&I ߆Ax5 E-:}{9e[)$'?អ-W2*ğ[4w9,;ru%ufRv񅂢4lQ< C:MC8f<2)^O˜bh_ IŒع)$[=aٽ8OP 5YIb&[j-}% 4uyJkTu b!ei{4x`en9=f6 4?XQy Idpx&z%E ޡ`iy.h6A;6GBo[Srv/swNdXG\3u$.@WP\``Fgqs߯`g{Af||ey*3uh_MH~F*.SkJ0R?Ƙ'Eيwqxh8ϷA}}I2j?K3e<^eZh +cs0}˘j; wڢM^vH85 s_Pifd|PŔ :{xpЧmj<)`/`Q0 =s1[} T7-ЇO43dnF`9cCl!FQ|{>[H<+]f d.[  eru|g7r r>x:,p4fAL )fuoQ/PTܤ8K rZ# eͩd͞{t#]*Ղ6}9bđVE8izԹ[^i*XHI.AG:{V3Hu1.Qmirxy.\fe~fZY>/WN慴ߦOg"he(j=v%ALd ][c>(+l⡩Ur|ϘP;XӅ ĥ$/_6'aǼڵvŽt3J >=A0@gbP4S,HC9^l_B)CH:%SɌ@< #1<*C @6'wD06seYuPR>iH>/jVM4ta%m~L2yD`tcͼ/mBwodRw؋', g ۧ qum u}qK]Zv2#i(`B] ڰ4I.k֧OnBv3 %`qިt)lҗ+e?~3_LbPov4S ZoSL‘9yzXyH FZz ~gr._דۏYs[ǗN15ioo5d_/!BwAow4+ucNj5 ! j:z|q`{~ab 5F/]P^Ϡt6,3DjmZQ}ڢ #%N _|i"2aCy1XL R4V=p@ь|ƠfI@H:T`ngmK9Mv[yfTTGiϑy#뉠q(~^oqiQ4a̾QO9.Q=a_dP=`a֭ F!xĚ:kv+GYvŠ 0] * Q,/ۄXȥʤSKip,4D2L= `hYfR/e~t9:%!)݈5wR ʷN,v5 ]/'s~^LHF^g"ADmLέiC*AeP>Pl?"}^S UHFfzL1$5\Qg]=S ,r{Nse m@ 'h=Ew'(_.ºgs+AEktЩ&XGe|huoU0榠Q]e 5Mxɖ]/1#:p G005n4? ^u hU3} Tc[h*UZ:P6NvR~C -VW~mGZY _TtShV@t`-*_.LPT[~CӽBMB5A~!K;P}bcEZe!nPbRbҨ uƛtp1,poͩUZvJFy 4Ef9PkS)Ea CS;xFeqDbw=,ԠRV!.lw(ى͇1M(z 5vz{O=$KZWcSc;Mk%04E~,&E 摷=Mh`6vڑP^K;42FЉYqyEzY9?M~,{R{Ӡդ N kf>t͐E4,v^YF^W.Ξ!bJ~U%?زi!^00i݉0/a+@!Hme/应h)OBPdXgiyaQ+Gd#Vh,HwCs޹6GmN" P:4:c¼!XaAIDӵjmPK_̿ |5B 9: jSÚC;gp1࿆A!0tu?%ZY1w%goVxp56lUȶ`4NO۬9$MBߍ?@edcC;t5"#Qԃ7~8u𕳄%0JdZ,u'm0y$ۿ}<ᣲ4gʀZ;K#0"0 C0qGxXe)e=G=KK.=-Շ ֒R>xZܨ*9d.N}ġA@g8:QcOHK}[^E]$LrYApw\Fh*iӨPJ֮m~G||jIVx}00FPiw.;qF䧇eϫm9BrQQA4,둚)Z؂ߵ֤c8KmX+P)Y2܇ I*߈ׂ`kQSыqÓ⇙ BV|1/df4n@nX BWN cۡ(BS/ ^W/&R%)1Tݾu<)N}Vkc3XrYcJqR؁Yvι~%c$qÍ AT#r5}#O}{ T6[nB]GQKTfM!LǩAO7UJkc7FT9J`w ZeL[b\Ϧ#V6/m-E}*&])\N#Nu6~-\q4s"۪PH,i]o!ȈO?C=8J"%tCjwe-B¿a/u^0G?iXgp2GZ]Rjx3B>:;ѥOj8 2O!MѕdkrR+BvYK*֔ƧaSc g]li|wYaf5͑E)@iH+Ĭ(jnib Z+XXjaY!2|JtoW&+OXe8 P 4z[(z ]dX53٥?!͌A@IjZQʺ zb< $yN >ʘ ( DŽ)ߦ Ձ@qzd\ڮjKA2ciB4J"|1X.i9cC .>\,@]{[K zwL*5FhLoԼdgabsA;#PS52e^>t%RMZ|FvI DS SعUNCtoZ n}TNps}N8=T &>Oֺ!X[EU-QKr5CQf2 A~AK$@ɦ.:rF\?<\#tPM<0L+rm{PLF>upK#2#04WdtjpACTH\:+߫ANN9!8[jWzc.k_mA{7^K,hGR)Y[MV&ԙ{0;vս|wA糏j/MVNb$!(ƨj#\g]N2T6ׇ@0T].\h9F[rLg˫e.940dA%Ֆ?,Y/痫L*[|$Lq\:D_üީ8yblLv]h5to,?wi$Y(^T?5d0fgp0 YR:ߎ'{ WOco9D\h+W$k, TX)V)t tj@Ǭjc8s$Eg; %$?cb͚sqt?/{`=1ǘѭ}_Nׯ_~s3m+tJ 䒧DB3ǫ8ϔ-Pɋ~Է OWАKeVOܜ-!bS"'U0涨BPyWrE Eqj U]"?:'az$F};V S)ƙrAǯ], G'w*OJr0Y*Wd%\ `<z|MYDyɄ';k(J~*QbjP~YyOŝ2dBOlC11JR|+һظx4-CVQJ(\πc9$G>>saMe #NX|M; tH6t&qUsEvoqxA~rabث a$Ω5$Debs^mX-D0e pB+she&iݳPiw>QO?+?h! T0Wdӈ Qe' XMiu\h-e ݳIIqwNXY)K5׿8dS3l8XV}u %8H- tvD0DMocSZ yI&EVɥGu*6#.!4Y k;M 񞡬kXԀG 7h7졄\{lkt3C])zgl4 lDQK [ aNvl[k)Kϐh%H4ECl gS`4&ᾘӋ+qu~/yS7A䡷­\&>#byPɣ.>5Ðk'iKOPpGbK}fI#F%@j{KҜw1VB$ ,Nj[%%諹/tͯ~JMPoG]~q'iB9\N~Zn>5؅ rz\3ZJ]Esz92(vsOvKr3O>3 d[ۛJ|I+SŐ )oC[Nk]Pi!e;#)AK)iҞГW$l3\ӓYMp!-ۈQQ Moƍ]PpI/v|ƒ_9/^ejL raHVGJxFS%js[ $paF: (lPCH Y8y ooiAB`4r7&=2z#Q@sA$X~n}ۺk.SWv*I`ݘP|fXlC + v}#Z ׅVc}(JʪυXk QW, >1t=GKF#N$?l0a4N,zĮ?%UQr{wU"Pڅ4V=pQlj4cKtkMy%#P {f ye=#DM(@3ҾCx+f35•F\UP^VY1")=TApƏ4Cq@\H'zf84LuГ5{`.F+&L:WdG.tܾM`6Woo {8eLF\Cp6w: P'VAwftʀ*pj?'y_ :W"5(Bm%A#:|8agfgPB$cJEkz "2wkConб܂=⑱-OֈJ7 ZH,IK|E2-jG{^ Y ձ>NH!mi㧈x7/Ǚx`[%RmЩ'OФTU͟BxPVJ)ᙨ-|'½[b+$Ҕ {<3#u[w|Iz *:&~7e=Uu)ZrᦪVE S1 SeO!gƕ|)lA x ';hQ6{D%}o Y$H4&V `2Pȟ0g~5v.A]77}{( >_?Ľ!k`HvMÌX}ԂR?zIRɐiNHåg h,<Q:U,EH.N\~KRh^m%(߈<^S*naCý!4tmc1Y0($ᵟ#©z綤DmΆxbװ>T {S41y Góߦʸj٤y59Vi:_fV5 kk)tᵪ:01:Zj_y!)ߝeYp9Ԃ64a$]/N#L)kh fjg;BPT%^DQB49L>utZm; sDr@QlVbdLbO'`:㆘Uj܎cH;;d?S}?< nGИw{?Qz+N qP搙RppGh*/2lg9!: ' 4vnd"wW&\eǙ[hmU]jUN-.tbF+nk:Z۽ztTCcZ4k^? SKuUf~YS;GA)oQYd?6id; ^>ɧ2"exBȡ^f Z D[ܴ#G;RRu:+ ՙ3]ḯI$Nw%n+y9aF@fkDA*#P[ .'j#246-+͈O?l.'pOc뼕+f΂1ሞYg㚘1kWsbK.5qOMwƁ{ek ښmq38MlsyTתJȿk4yɩ{VugL5| a]L|s]V{"g PG Kc1)/PW2`+ki&3\x |z(o*A9zW]YW]sxq5CSԀ-s⋭uaZMoqb+l ꡙ&7"5`U5j;qJ?Ѹ}QyxqvCf Ѵ'"jФHF~NB{ȡZTP2x،m.ھ7m:XS,20.Od*׭s(xcNBVNq:agksrF¿X)d۔5ޢ=m 8༕4jS5RY  ,29=l޳ yBp3(ݹ{݃^'Hd..si aZ3T ~ShT os#EX M]3aˢ)Jۆ*a`Ɗ p$ߖ %8gƻfR*q ǙhG5g䯎t?ifQL0}y,*S' wPGGmъ45bir/ z.WqY/'[)we5?<׵ߔ'1d!/_ُ&-m+ >n =/%W†vIG 9ߢOTC#sf|jl-Nv9mZt(C:P=R#{ Ob1khS\֧`@tmRqJIxn3NV.%CB񑒔ʠ˚u%g~6VW@jE&9,Q}crdҾ^1Z=EX슼yxJ |D`T(|;gԣGoFs"`7YEKĶ0"T`XK .GV&Njuect_fLxBFw¼],ǹ/9olf ε6Mld/v~XTɜ uy:V9!Dzm9ݼn($`a]7xSx>-v惢Ң 9O.Sq^LY|/;9˲Ne?bEsnۖ=;g#ː{(+dFw7.yeyզpzFFȧ%Ԫ!$^9STHĮl"˵P_ zHQ\mcra&_K*[L=;^7g>-~呂p !lVsBg8L+֜K۴9F, ̧4}ڧj苘?m1¨,fshZ,GM&}xdOI vR6X!`ahAB;QCR0vޜ.ބ:`,$+&Ʒ\͑L(%G]o^^P85SYYuySz$ߨA:̐P` q" Ԝ ޏ#i7 /uJXZGܢ3E^,jiDz:]Y8|܍4T#`ٍKUwItRau!"`maCe6/,4WMBE;ZYxV^RiP<_U2tsix#~ï!Fa7fG|Xw gJP@ސ-sl꾝JXMH(&`ASy*BiE+ f&2[=O`{_x'̕{9$ۻG[9.Qq 59dp(vIsQ SȪmv|PZls歔1JG\1R3o/X(쵂uPc+y9]L٠/ΫYLUlo jzs#ǭʝs*kkB0&Fm϶uLP.$R_)JeoD񣏦\Nu0"2zNS@'sVuCT\Cd;] ze8i2dlB5żPav96t#rC`C ]nlMș8FYv-@ dˎnC0]5WLYɭ]ù7el&=5c$._=Wjt?^d ߗe7S,aNTOl904#I6E]n2°`s'd!pS>:*=oLk4DhCAWh;\DW d 4e,GFYuQDV|9%ODZhU/!^]BjhiNێ* ʆ"Ac57WL#ԣjs=|5eeHIe͇ WHL+)&{P✧/?vT"li2K'GˢXp \&g̃ͅ$V+zd2v;vݖT1M}ڣȫc1h4Cx0 1Ps&v^ֆkd +,Y9LwaLU/*W!. N3[Il rzgKdB.,nap < -kཛྷs\]+b#3R#@o'c2WM}=Nӑ9|ޚ)dޚ7|KhkCs3X0]z΅UV1ątڹ7rKx` 8^00jjps%T! b:Yo|z#<fħ##;E޵O&THxULdW%ok0 HtQsp}b#xZ)ܖk҅1@ }wn0!x˙m ݋M#P8t/YjyYʸ^`02ej tj璇{-TE5քTJeRAgƸnNN/jсSà-T/;!t#Rou{H8wa/3)vum.':B Ac mc5q (>L_CFYklJ[~&)4HACt/ac꿒 lZ?G[A_|[^ phg+K?gS˶{brQL [6DBV;r볗Ё7FƯ2G:m?(a r}e_5a|` z /'wOAJG}K-II^~QHtǵ@X5뽚@V@*Gk\&trGqnQ~'a^}u(7e*GCȈDf!*wA\e5:Ph::@q(krJ2 |"mŬtF:li\J砬Ybv^6czpaMZ G.l#@vfɦx|xE bx+"O@꫄1&_Fqa;C UbA х:*S}0Vu̷n]ǗX؈ ' ×S;j2Mii*8b1j&eBg^sSobqĎوT :LN4TRWXuAo6È1 fC.+8!x܈RzU,+c&9\5kI ӻ^iLqE Dy-5^(;|ʦW#,nqVQ?#d!kS>~f$Q%pĂR~..p F!umy If!;%79aXqQwrH7!hO$sڣ~4E'aNwp|( o9hҺ rdm$~)TQꎬMDug*🥫pؙSISI`Xp@6i6ew&ߝ^,i"2uM:õW{y@>)S#$"{ cbIҊPpo~UjB] . "{@RDq[5%F7agZ3B>Чp4cԒfOXѿRZ,e:zk~' .E"J+`!;aOy s)]dn3NQ `NHBtW9),Gmp|HqO#XcU%lg=5a˨a!i?֙$xG,$hg?ʭJEXoKr q P%}N$t7iK]jWw:k)j%l?F#cn\Aѳ;5 QsBC(vӻ*'߸”@9{aמH1TGӨ1XhH#3GW"@\Ț\Š™T&i ^C;>r50 ?aZ]M*ދT:χU+8I==-2kh #&p"P 9)4 `g(=i[0$zZбI%,|PPfͳhGppMqS`>JS9׈.xrVK<'A;KHj BeJ 8Ni@sC}2vh:n9Q]LE"%nMEȄg'~:*b##t(zTJ^ <)K]vx:]NF 9i4}S_)?%2j+yǰS<,t܃9Q=9l2m5b7ؾ!f],96NiB^: Z̀79t^iq2 !`ך6+Tao=JY}"5Yf]g_c-Z2j2o5,8XT4kBsyEe΋.ueB;xDHfҔFlEMor@{ *n3[ Dw'|cR\ nt Z>w2NX8\@3Kd5|%=(}$Sr:)I*e6+rY+쾺59seG&7 .~‘s qEXR^?M(j[7ClQtY|{ފ[.+ M`O xyH>"zތY*^d_/ɧqzKG=Fp?7"kC%9CZmLh}?견3.c/B@^8-3NҨ. WlH½>-]غEYUkΣ?&fp+q0@ 2WubS%;;pFAb129뚊ń|Ϗ;䵓}a2}Gdwg'8/eAHW^*P"tǔM֚}*X%h~+«Nzw.ƝM-Z[NU)-/[*0o}7o~6USgpZdxEl[۰]n<"j^4Qs[Δ`7$W{愈<  ?ᏽC4O˫zR yAZqq.aT0(M b(6i*2'aݯqגZ&QR,hQ? ?Ptt+n5+\* uNv+s17+B@Bm^ukގ*M{ü4kumZBCUO%5|41*KhK4_a h_a\G߈,ӤZ9olP_Xa q;a3 Ȩ:S!SÔpzoiYJʠTh,>3X9j2+Ls(Z2J3a6Rn%z=,HO; \҉-};W&NkjUhSK.nT ]bU@{f$+?s%f&K:*¤m]eǝo)01wLcPɳ)ψ|Tj-6cgsQFp2,V΢=61,Pz٧@~#D 8wHE9mT#&XOQ('Tzt6"5r۽ _~F{}f(a_\&; XkK@ qkDtfWR ;vlkE> 1r:>D7vtl~W*udE4\Pp)>w?"g%#ۡπv1onB6X0:Vy[ssWDze&$DN\A$ܥ о䚣e*s~.3ρ pRÛ@W54:/l;2w۽I(g/PwTS͉ϼ36-9 A/v]|@ s2G ;qaI%='%>{{VF8}y,5NN`z jl^^1jtďLXcd2W`P3 ~s7e'`WyB A,z wCwV{ -6]X*3kOqPjhYd?~ |KSQM[iydnvRR8}Ο"TRuf XP }gȢFRg\cWsIR= ZQ58#NVzpbl|AglmݝiudFaY*udɟQ7&SpUy-Eꂲݕk`mG7 h|~CDVOюQQsz["nLQZBL2E+4qY;q !:lX=9KyTsh$J ~* &bqG:G%_DB?g~+~Y2dBm[C)siLRJ$cDh|e 2Δ6!DtKf Pom;VYGdȱ0V`.F5=a( %WY]+|G"ҷ`67fq܎EMQen5 _bԢD(mlx5Ni#~GY!+0KY15.KT"yXlNߠWwa'.aZ+m?c8``/J/y^aԈa/`nna"6M4|*jt( 8w e- ^\x '}aR Ճpʢ.WPw COE^' 7UƥT+l&g`|Vg-@Yl%(#1^Z^<";1R$OB6솄A@t]/37E3Vս c XYBPJJ":GxuŒWd)^t a:c_C?ke\^msv/t!nTַ(BįMkm&]nBȶ>n,d[NlNO~d@d63qAGʶ@ֈ&tGY;x b. H F2H=R3(֏#Ob]gՃ͓e;Nvk9GpnK"B;?%ZZqPo ߅5qS.3be.,ydW*m2M5{RqVj2oYT A/@/ϓi>a1ȳ _voy6('%k~\* UX|ú e~H'XlA~+'*e5k+/ Q]НOGeՂGESsdwlRMW\]H=yČ0~6{Ŵ&U evт l\ @9ri V=m|Ȇtoe5X~M8YAC#UEun?=˜?P:A}CAr1U;S`Bx]{B"پu$e~'1 z,A&^A־;-Ңt'Td-,(8%$Sי[4Y]I(Id μw@ᚥ;LhEPl(ˉvuXA|da3Y-5>ߦ.1bVG3mEƧٿmggw|Nz06 lrH2>fLOlY%8XIޮ|QiE35`k5m碠L ?"zԣ[mv,Ty /|O\4PpaŽT9ͫ-KG!ܚ\B$8-Ow]nyӣB[: wÌc(L3K>"Vdb鳉Q?$t ^.Oh0,kQ[$] &oaǁNIľg{ȾW°I-:Cn bl&:x␐FҖ+_%ؕ蚰g#($@F~P9 bfLrZRyیEp6`**Kk.URyõq#{FQc\|\Q&hķoc=4P%RLϷAO0UYPg[3c$e#f,fKTN~MW|'*~oKgOpEw}?ET+\cgĔHXn,zEa|N.BXNݜ./B5:GZŋhK5\R71-3X;gT+^2NHl[CDb O\][*d-+af ڰڅ_R,b^֍go^*ahHmPOb*viE%%5ӵ]K{r!&jT CB~ IL*OkE@?;K ki ϛEP@,[c"ʲKJ^e1\-Hٌb1QZ7fy? 1rXӖ|f좾ۛv7j#.-G:+sRyKbz8H])A~KGK5_a} `oO?DÒL+(]+onK l u e {l7rQՊ7NӍ'V#; 8jS bj?Ft{TÑ FW̟!s#jUUS_7f7A9q(6>m~l6{c6nȗXzKk:TP2kb->n3)@G- ~d.a&XF\`y/! VZl .0KQ8 -()?]Q [[?-pvK:jd'oRT"(]:'?Nen߮=hP_bIdh߫‡Gߩqmo.B Ұ )οt'V HmJm5jP]hsy^]]#a`Z`C2IOj#7Zz<Վ)B^  7ֽRUkܴ^ziȶzj#\!rV ow2xM%^NUa=c6 ;IwxW;=Xȭy}"bR)uZvbyȗ͸G|A2μѰG1*l#Sv Z͖]YY΃Vtg:r"ҽIE?,_3{:@ӤjFޑg?dO >R=7E Dk~nEYa|2 ";[ע"~$gaKLz'-8,KˆE&1?Tk,!%u2 2E_$`C xMgғp|Ԫk ? 1h<=&\udfϲ'(n]o}ZycB_G¬kJ~׍3+DIR5HJ_(@^ %MĒZ@>F0%ej_n e6fQ"ɏьPjUJF5V|a sz#a.(~Ča-χGw~̀v 599 jK1Uk&hs4\W*ţ]fI({ȦU~׊V19 'fB?uWHȹ(4gJ樦L])zܠ2&]l# mD"o2Q󘒺тk]jl8ٔXW9f[( . 4_×C|V @I9" H;^8GűOD:~`zm!j/thMN=yɗA1\ۓ]]TN6yXH@CEyO@i_}BߗXz!ݺ&8ӘAy P=!/{o9fܗb3!v7T~/IĈG;L[6* r/'ÞK?mhGmU􀅬NtLq`zAD!"A 6DG 3%d!',xh}Z*=v[ +vx:4s ,+Go2`M~-)֜{3~,Zɚ1 lauS;*y`?,pjd͆nrAk͕K_*|m6c)n;z%~Kwg~{4(q_sA˙T{a. 6!r4"i)Ǒfwz`b uawD<+)1!6qΓw)d79hp?hE`H[}ygč*)pLG/UF^O) 471TPڗx$6A{=ɹF%4݃PDR 5R:jNI˨`c! puoSRjƱ-D {t.7U>I`fC9N|sUS{28k?U]aPJDޗ<1r7D5{V"r!2ȹ.ZQ3f~=U]1nٯRsAŪd%k̳d] 'gvC ]eYI5je+2~C۾S!)iZwFLU[L!w_(S};F^0K|QWXf+whlhn pb#YCϐw]^0Ǥy{Js)J|wҊ _7-UdTrtdWXX$UMF˜|ޞް1,Gs2̸p[X(8r|K.haS{>c S[R[ȖCѹxQI[-#Q|KK?t+XC,fMpus/]k/<|Jv:uYk/P{:iSOA_}MAQSIc_Άآ) `V KGa3,eE$zVVۛ hkI't041z}t`Sv{'{ ev>Z5eбz2qu1""V,XQ]ki+HiydӬܐ\Ԕ"rZ3/"%̠ZkBK"*=g=if~~ a})X QjC@Ka-̯r~Tq}7N:2ǪRc<=e[Mms|sǞ /c౺9_YnKWz]*@ Ij4aB?GwmQӝAMoErǺDPOgwoqNdxT#z j~md Jot(5^3~)D fT,GNQ cx&{NA;y?+ i3*_AzkP ձ/~S$.!!(>.U6sm7bAod,L]p᳉?nj.xȤ¦qV[N[xiύfpZ@l_κ=P^f%A`n (ոsCll(Mh5,WR'5WB(Rȝ(D5PLݫ]w&L+L?>#UXswwli.C}r5es8HH01ژr.UɎ}_; *)`#eXӣKk\"A0Cߑ sµUu![T[::Ef]US٘ZWJB oD3dTZqK$@P8bBSFBf6H*GcT|'*QmΤIH[¤j_y;ihM ԅaiGĮwQ3,H]t,7 គY*Lhyۻ˒u6DQe~8v\]9peW+]Zyw>BO%]e '1fٺ:'_1._9b} kn&QlJoz\I'VPCy A)p{Gs#^ ;^;W8Ȍ U5 dePYu9)z{SZ=Tғ7ȕy e[dyzCbt+efCKZDB>V֖2PJ_>Gc_]'k# 4>hLQ;Yd!1&T(.:W΄>+FPW@8wf1/I3J~VzPV[r|WigR݁Ԍئ ZkTŝ=ځA]07mgAp(תb^pL˖Xf9D M/75%ՌܬD{k{(4v8X3;g7ާãTɸB@PK0CTG KTȅS:g*p(ps3M=u?ذD:xDH7Q/\)l"=)YV. Lry'SOAAq,8+x?|x P_zXlusjB4ofdjTq66zJ wEM/U#^KVi),*(1- GCnΉ1c$pPHL d5x6iaRbJ(}P373(Ŭ;5o5 8eN֐ZClkЁ9OyBR2HXbg7;M۬U rDű+b8{]ݝwhƚ52j~#VL]1Ԟm*ۏhTĮUA3Ƶ䮪sB%օl<0sJ`!ezm#N[4Q5R}:8'pvDOfៃ@Y*sj:НYxd;X~Լ5{iz) 68&gl.@DX7&g/𣽞L=ӥQT& |p lnGpl{8olP_Z'dԲ!aԦg#x\{ҴɢQ` ʈJn57&JZ(ɅRhCg6v >JK%H͞{b=؞kF X?r:Eŏ^if)#>/9SQx|k`lG!P~^̳J_> Vq&DX\۳aKCj1ziX]å{T:aa+Ģ=%0tJE,ܿЄV(Uot<F{(O+2v}( sLY43g ):Id<\^G@3Ħy4j.F}sl(p'nÐǃ{͞xqTG(WMa $vm3f,P{FjqX>n>ei?"2Ҷ;om;@˕}^hp܌d'^\>EkTɼRɜ9<:̪~~u3/j^ jWSqH9 ae 0A9-zg5[D9 lzkIK6E21 tA%5]UNgħuXi@J̌aP53+9eh6X6<\UpUF΄h}BšdI>X7j"Yw|q vawE=-HRW?}H}DPC,蹄̨{=+0xQw!XU'߻܄jP R#|MޥYLe Zoʙ`躁'rlyї2L˂5(7y~]'5eG 20+!a2sOQz[* n(d/r>9dUFbiVA^% c$;pMlmՐ\URh*1ʫFLߊrz5Z[p8$\f4c0D헹R:QTNlV>y(QbZ%є)+@{7y 5A_7]Ku=s:ܟ X lg5kںl K̽|dcFXMܬv.Al0Q1ݔ;/&porɖZvR=Ȁ3S9ޭǸ hLTܱru峡=r P:5UIߋyK) !Cuk~}m\_)O MMF?{Y}߯ {`?ipZ5}qwb 5Uԥ mp{8Q2JqX0xDAYf[5}HPI7K>Zn$U>s%qI5nhWjZm᲎Z*]w̧q/0ʼpOSQ ?nfZ jXBGhtțl!JKd0$DAMLjfܩsZ(>uWa#C{;S-#}7!7yMU/Cӂ{Y OMSG  -AURc\0Hﲧ@ ބ?EM/CIn(K 5'2/˛w1~t6o< X H#O8\V+a>@5EWRʱ Nq~ͫ&S;VUobA L/1yb&3whz!Iy# MtC$z].$KBLBB36IޕRX˿=-F, axY9Mpa&erI(U/9ɟu5SعUCK؈^`+l3Wl $;Be JUdz$78s3<aЋAmrERj,rGkwGbCz_ҥ1kUT_CX|1UcJ)14 K2Y#o863ܨ ,duX(7]8iϬg|ӔM]yPQ ۺqņZMj?u)!F0D~<QhZ(zG, Q+4{g[&u[5l UȄ(=MJ!6]Ei]^dF񪏿QҌlG^T8$Tr!6nYʂػ㱓D%N0FkF''!rW@gs3Jm9ܛ#yvrRbv5Ӧo/F| iȠJ~(Lt4S+=2rOӱ$h!WHisHU*v #j\5߰n}}"6z} fVkg]%RI`227%z8Uj[xFVߤ4*!q!`s0IPI$N]m5*d֌ ^_{MR keDg7Cީ',6 -ѹ) ǒ>N u?謈.n^ib4Djō78btwxskxd "Yzla'0piB37bx{n0H2O(|e~k./% 'b$*VEMJ-#1)$ḛFK3R* B7 k7|f; [$hkA 4C T*$ 93)真|&kXKppN 'wH!f/34TN2|)G<yZ݇jćR@ȡ~+Nz?속 _ By$AhsGp$&4e5@4ՄH_gMk* nl96CscӨr_;dɳtjeڗi8 c4%%L^0OrAH9)"Ӄss}=^0%<â"l"hz TK؝:5'A2Yńy. wZřPfc;Gd}Ԥd+1pDJF*|VKVݦqi.{iDEFtrGFDt+uClIYV^\_GV>D4 5-|P^L{ U)(T5u9&7쵻9˯ld|£G_0b73?椘|l&yKiy9׷~+IgxIn%Z0h)liuz$˘I-??񍤱1;jdY]ynYhtg:q'%TRxUCtLt#i~%vf#!4]v뀱= iA;]^ڔrDeH㛏ӈ36+KCUUv< Tsm{cc49{ t8QoDBkNӓCt巍Ifl;XzZ2w' X1be>#A?y&*&S{,꺁zHZ+ $@_50XSz/B|A4"SQA3ҟkVMYRjQ `yÝ0 l]ҿ vW`gc4+2__ nXc=H!tSz㸏HH-c"AF!ڎo#_y Zk5FhYīaK pʡ*h:2d zQ, ߝ ,~;7 7玗`4DCoaf@^E&Hz,=MvʝZXc/*k50;یb;8,NXC4d<2o@ reo#H>fDk5lUCCVr,T[sMr-x[|hpڛw|6pܝG|낻`O=WuSI/3SN8o_ .mc8 ꡞ;9i,$ijT&4E@$_ip/tAegzbhp߹P 2u/ԢkKQʄI|n&)tv;؋L\2撉a=OۣD@[J <e짾TzX*}ڐ&LLMVSZZr7vbޤch(!yE ns [u'ƽv?x $R]:Qc&oL jΒł>pu}{yr2ݬMzr</ub_ԎEFqrxB6$/ev4Po4hio4kk-[ YBRDƓ֢+/ 3)NjHiZhXD~RA%".r5}7Hhai|w ZOWHD\"٪#nRM~}ٷ甤1#Xx)ꚙr4oz㩂9Z73GC'/")Mdas D Ƹe5=t).m\^cs=#m :VRQhK:nHj3kz>H!Z/7ڛ<^Y7٭h^l%f;J5v32BX >D tO2UUe:ntfgwO1Lak\2:Q%,`5%z#V~\MQO{RHMNK`'GQmj#0.{AqIIT Vb,^7RRp Wfdﲲ!gJf3i~,TFO@9ӮH*;M!6i88lv"VDo#>r,ZD8dXft֑mmxez $NBʸZ8?F(-NR ]fyz44%`>#hĸ3k@`M}2#-P 1:^'bywݠ_%fGYf< 5^d9%S;0h7gxm&CF\ yD}b&tRmmPKM!rPIf9&#dP EW;*^(Q(={[89ڏ3F>x٢EEG~~Q=rp=b^ 8@ ;N7L)ϡ'nEYeq VwR>-4oq뙳װݎḄ9_ք@ r~hEgw2АKƇyv?o i xh3؎8'z_#p()bN A~Paψ #B{PN GO9kG0X|b@\.8ōRHi@f{ApJUa&@t N7HOo)& O#Xb]W%ApLhشcqKa iܫqmخ[ErYcs1IE_j8mV*:R:cosC;ň'JRW{)6;Yz@R`)YȩSad f$V gag8^4p\DIrqۋŖp-SR@w,Pç _~d$yAobJN6}mv8P|7)AM>a#57Jd!@8etvr*EH U (?'eNrPA3aS "z5,4fni脆B6 s7)~r Ja.U) uӡ'*|9r~XFQ$ָЖUuTs^l'p Ǽ-EcxQo { K4Ȃ 5/7d'AC^ f9#/O-c?ФЫ: (:k$ Up\ͩ!}IO>x21=tH?L>ZqƾBBH NxG̼WCEw)x>atc,~: Τ=e@;T3R11)_]ގ*䤶?l `dm@-ޥBb[@qHJ .I9Lё*uM 7gXekwwBNbQWHm ɞtMa.dJ1񳢇O{P]%$3WuBF]JuN# =9ngp} /E6Sm u{?>0hT/x9Yc` !d9G'.R?K%B/O?U{jU:@)s-[-{[?CK}?WF~ nHՐ}*vѡј-ٴX!U8dOJ M˔dxT\8=( Hb+'-/Lj3kCh;f3j*+_Hތ!ljIg>WTX|o~PIUk¼Ƨn~H(cwE@J-;5R:U޼$֠XM̱g$gB'uy7SҋA)I>hxDn@;!mq\Zf9 -p(Yy4dKɑJ p=8En2;Vv.:XmGsPw ŋխ}W!lrD|v1^kdjuț)b VE?|meZz鶿ps@TR9Z"A\-sg* BNa41'.7NZCZ7~໴G[`p KDC‰B,ZX߂(acdQ4K IhA޳$]otE! 66%ZrMP5:vte!'{㔂UZ ȮΐvGZVsx%fN;Yxmyn jtE4{BdY-2:hjbÔ Nu³8k}MvObCy2̠-$ȫϣB1ڔ}i`e3x[ؿgQǏT]_YfjVƘrQ[^.4uZqP04F &2]Yabc9Ig)JױG爹AH8 [C {tCrW}[EPm qcގIL gн蹰L߈IărLVXNxhԯ١pݸomsyT.]V)i+cg!Exh,LFФ (]\ UޓK*MZ-g }]#U̒2m*Ah0bhUQZXkCNdGhbٽ-&gkH r\Ptn}ڞQҧ"Rpo#^)uSeh Nuk[moC5^QI^z'@l.xlq@_@괔'GafYy[^~f*ʋCݧOstZ4AKuA=DP0Ɣ 冔2@rG!nUQGs?x*`#߅ _B~l|:"=6ؚ~q$l)+qJh7+n'o$n‚6pr}&8NkCςkS5-I~jR,f:zHʵg;ĄpRҪ 80t Twu`cCR(_Qi/׻{!N\ u "E2TVG]1Y:RZzߟ n ~{k0Ji^s8 {NĈ뢬:6F {6&}A߅,b|SO*Y^/Q:=S_zп?6nGzQWgiOX9+]qy|M(!1ij77-_l^T& #c4Pj*3?mSv(X7Mc-8u^KFg6H͘> ē}$9BGTg⇿:fJS,&#ύ2~d>Es9^R3/wا?[]OY*r^ڛqqJt} v*h+z$K5CHAi3/7,JO-bE7 5|h\^"D #_l.g#y5  d>bjlС ||,&?owNx"IR8|XET]?Fb@6pen.>({z[~S([ǥ|8[[L ywűvp~ 0y ,FÕlk[3gL9f :tS>L9cddy$sY/RmZ+*',4\RJB_ Sl.&'@;ǯuzٱY%cOȤi01'9Uf5._!P6dO ɆN:Tw%};f.ԫ$[VjY}jKvƍ/u^@ZgTZG D-|Kr8,pv|Eytpu!xGEfn,F`D$f}"52w;!) ܼ~6B7 lc^paG/@8Y7^2ñ-~Xo$/dGn~aF U[[ _b'P*U֟Y|9}O..lbL\# =ۣ8;Ƨ_KJs=uoݩ|Z8ð% |$S˴\&/av;/L tgH\Bzy ̟hZKuEn*uN/4|x9{qC Cn C캳Kl<XQSSXVnLouf i~އSm?3CX8MօK=0Ɇz~3\~\hGiKa0uqb0%+=cwU%=vU?j-#!g|rgu^QWbqY4[n !{o8o#uR߲v#184g0ܸ_9.0OE0j[cꚠ:}mHCg-75f[0|NI_sEzxJĨ.ã'X8;HdRnx?$[.kWt!Vt '"#|j}v_*[ OtnܲkE:|Zdw b8u:߳HZ>+_ U8Y?EYI3ܚRŁ>ж2&@XF?N5N4DQY&Z3T\ՐQ|a.9U9;8x]RX#u߳A$Zg;&hP>EZ5\'.ӡ'P+w0pnKI}%W<-IlڥP/YnQ/MМX*8NĎ!y,t ֝׮d`*锿ӷO+aEV֌xǬ6͙]AlrW%KSs  gƅɮmOnd8| [Yc"o3fu_['4x|e&4Ȗk6T8ic.)]^*sOĥ eWfPaqJ)HDp'͉`%s 0(7W װ4Ax*@ݮ] F+PH2а}ϮU 9LzRcϙor>|1丿*Z䴇1b=8RsY\5 @3'zD"" u?`S~Po]E%rdtc{{x? ."I9JbNƊmeI aJ`¨EGZ!ĖjY7{'~\;`x|Re1(9e,ngu ;JT엓:Oldn<{gsË(w0-ro| K"zDx)?,K#e!P ~Zg:satJ6_mx1_GP<$bHh`,xSqS:2XM1ߙ~Rbz*Z9ăy c.*{89*Ops "] $cC@r^q;!JΥcFjWf6#p[kZ(IxJO=:$OO68N.Y"*B [FQ?nÀ-I`9ۦES׳Ok&և;ن`Dn8&捅[@zUl6U_QX.ŖwA=x# h'ɵaIYg]$#Efe@@2DN%VDdu=o'= XJƪ0l&t,&+ʐhw0l*AR!+یJFWn$s\ي}A̯= 6#f_t&󲼺19(WQf&iH[å}Gϝ=$0K\f(يQ]o-.ysv e5cE%؛*B:#jI޽ޖ5G9\I ,' 2*גa]$!@8#=+BQW! ް Yb<s("1\ha!Ƿ|zn|G![Ca(PSu\Ŷ%ZpQw/¹]YyHFKZ&eДI3C YG-B?7nz_+K7#M).Ac^שKb ]la 4.gテZ)\b}b܁ՁM*Q?X#q+f3=psf+jf2BL:Pȡ5)[6+7}k TRCMEj8A譬M Eig*ȴY>o;_ۦsכriXzO,;:-jx>BDb7 ^x(y#= 7Ћ"绉.>`=+jzhVh/TuMlIJښwF߹R'g рJrbS~N|m$K^ϙKau'Z UPhVc a֭bxO[L9OpM5IUq[vä?F3R ?I.}_HA?.@K_IdDN9QdWLV<n8WҊf)Ef×]bﻂuӸŌEpjҗdQD#$4u+ q&>DvmmoJXq_rbAH66vnD_t`210"kfbĒ"kۢ$". JGk|׼9H:rPԧC?CWW(W`8:aϝnȤvy'?u~lHo!ǟ;^l7+R˧p'1h#.of+ D0Ә``gJqW䙐j/3!ר4>'VFսkUBGgWXE@RgdJ2F5}r_ 3Ê|G `>GnN"H; 7|7(^ݼcpDΘcݐ3 /wܿ!g^ mzIJgj=d:~oƄ7"4&D0/O*bU,I[I To\{ 4fX~M䛭/EaNPAz縧`d/nk79b}tF=j]Oc]VenJ I.w8Iy6 ZfOxŸhzH /ZUżCEQgK^LŤY("e..b)W&%/ďْlh9ލk-cu8FXZB_$*+4Cخ'` ̳ -1g4| &C88,1_9-;lo;-x:5&MO5OV!+-dřT<]I=;Ռo)ATyFgn &ƈ*c;M>Rɻʉ|ޞ~#L FgɡclCQ:^2?Wk,M?^a$Wҿ]swF29FMI;oB=uDfC #*=?4-Zl;8# aRFt;pG=g JE{y\|-U tl*O۹Dr:#jJPE%3?ĺ%O ΀3n3]NlG MEm:́|zO÷{(I0n ǻ{eLiд~x#-IM^,p 9;(ʑJpѻcasV@OP)Eau=J2水=w#=maZ?Ç6vIkc,v lNXТ>/+8fu8 _59Sb+BS휫 uQ?R(n6`@^i yǢBNd#Dqudx~,,eQxә|,sLϯzm= L9XauW*j4Bwa_ϯ$+#"> VL<ِn٣Oiǽl2O*X3ڒGB|u_ֻ(#ZT|K &()wIG:(yZ*v%s$_Qxg;"cCL2GxU+1,PS+'ocOK_l|lrPNNRݜtXRM[, /u& T BvJq/бqEo¨^U j^K3Q$fhn䷑f_I1,zSl$aǢךz>x6]מKB ,O W!c9B:4h-+0H.Itn8 >}=OEBYSix>@Qzn+0R)aڃI$nr%S<D=oP%4ON~BG5f6,qlLx(4G̔_Š2 WޑS c4g)LeD+ In92>1$Ӂ^XfF1 sT'Bcn'{iЈV$T7RTV P2`kh/y%eqi 5q]#a K\v+GՄAGng@P"kM~xgP@ TQ93h- / [}"yJeYN{^F&ye..>=˦9R߈qމ0POٲѭ~.jRUf* unCz,JH|)p lm\K+DŽO|\R u%"7,M4},ltT?%BCH+%+*5ځZK(=lc, !{hDbK&r0%=ЩbAsMF쇶u=0KɫC4 &/ZD Dzɾ]WB)ǡYm|92xj%'mU$JiEV2˸4e]"}РwJ]-/v8ъ8^ OS21֝B>ѽn>L_K֡:_ZKf?ۡkJ((K c$(<.<|j='o[(ֱz ){l JrqDkiO'7..8VHKm&4sbpX z@)G/b,!gd+΃p+ULaDn)j|=fd?=H:uM G=z&t5d:3fU[jKtPd3i7&1;ס SZ(`P2h߰%Tv=#IB-6St+s!|U<6EBF(~uم;sPPZMmnO{9G^,ٸY&o ff+yʔdo! o[+J[/L c᭨|ёymc!Ԇ^鼜ȿ-DYEAĬdlo9M6OMïae7xCdƦor#ɶcc;237yszQtO)T]0thӧ9 ?7̌VAB s<ћX֊{e۝%va׼ L{a ӟ8 aĬş?}P KR?1Á*~!!>V͘>[Z dUeqO:N''Y~Mޝ)oe[#*A2H T0j asqsZ,ۓZdw}@8/J2ZrkA;?B7) էxfLɟ`)hKS qT~~[C?w=Nd}$:DVHG"Iu%=`Té,ܠľj7ԿH؉ߚڄ0iӅ!*1bqK'V`Gj8 gZq}?ƃѺ$!S+ӖB!*xCaobu@*PT~Y" aXUO!  E9%m9hDAډkD/gιm*0\*ҁ㹻%!.6  6q^6$1;'D76a܎*q? 1*Xg|+P8.$n5v%ى[)!{=t0?*=kcYbӅ>eZ RYE% ۟;3b)Cb\Eb9|cHM0o4eѭX mf|(x qI` J;݃{W?%x#Eehx3G3) -&$jIdņ ¢IKOj6QR%0 U3/L7^_[ BTO[lWU-Ti9Ѓv o)RNa2Ss[ŊguÄ{o`rN >\5s FE&*dY;v`&XD TǚQ@TLݞ]a%Ġ{f8^V2ʢ`IokaYV9rm=̨=}cThg6o< ksU{%{ю x2//\l[ùWo9h+T=vsKf; *E#4 fjoV2! ;oqqt*TM˖PWUO APFsҩ~a`ׄĚ/]2|ɟETZ2haͩLI&NB %v^i!#V]m]R,26\0oY@8OL3-#rk!A{b_I)EcqIiK; 5:%*.\"ݙKJJp|f-]@ CRGy~FU)D3GZX)8#>}"XZCX-=B!ӵXy 03NGbLͮyXe1s@ 㷦i9G>*u# Ju-ݨk♜MW;-t{,msM4 ͸̫UHrbi忔x4Ё6Nbf`h iJX'w]t׫jP *O4 ,:Vy i`<6qR;+ЏXNR*+C-XxDlL#ۂuͪW>G6}+bBMtS|Q=P,7VCWl$z[l+Ymokm3w֩E o/xN6bpF{0iG_Yg0aˬ4"dH52!Lt,A@Wmch(*}} 3EZA?1 уt09Q #%,ۢ uD4p]aPuJH U30: `g*k?ڀ&Ayc IKѶhUF1XDzkYh7Zf ڮp?^p]#3Mg6)F$WOefkɴy&toH#eJ'.ֿ }VkVwxfՉwB5?|cPy8D浀gih{4|%\EFHc CE}NEpϷ L5+'{_3R @+k[Ux!R.mk9E3f]ohڿ?Д<ͼ[4Q`4 l:pG'uFzS<0a:k[0VF7', f`g t {%&g:KNu hQeoG)rOͫ'PD|_SVgkNV;p?1ӟ0FN2ZnF橧ORi^ JFB /[<(u˿a0DI~0e*>$Ȓާc4:z]b䃧r|^@w,`@ 7Q؋&hvwg4X6h!ʵE|Dܒ'R+ڊʞ 6F `FnDf7޺F>nS*+ ֐% ɖW0n& +Gc UAB4Oٹд?$J(.ͱ.RmKIo(^侨JDI~3DOe r cp'>DpK Rao|a6߅ZÐ b,s)𞮥MM}lٚ z4JxƤl^GbziV3Ӎ)c셽qRetC@E L ի6ƴ#O-fc TMNzZЋ0#__TDL pq%<칹 {,c\}\ýss D T4[Z4[5=Il *WG{ C=iN G 繁JWXEmO7b-q shL٨JDPQf(d_2^\-,]:ZkT^V -[1h'0 '?"s_k> ?xbg'Ac-;BHB}`k "È4,V2eѺڜyad)㣤l*QhJp ^qOiz*/i{kש`:QY)(ef Lm .`}`!J .3$St h=S)ty)܊Ɓ[ć;y8ѳJS;rnDG8n(Ży Vu- ꂱsMRw\ :~N&==w ;.AH/rz9s/fnUX¤I$Js3 rHzG~_ՄQ02{(JkO@k)'t}uLzAaAر}9tE8yDqv+#SUm/ބYMeHծY=r!Ittd(f:HCfK7.|C梕õ]P8!n\x;"֜kP3PK 5Lpcs%3E;CMwxNBWJ6>wöR[!N -4F _}aF~e â֖}5GO~JU@bd%duKy7Q`/DZzȫn"LA?]z':D8yaG+-m6vݬ6Pۜo-bBRX!uRwfrCR);3Bb% j I  =W[ϖ53 y Cw$e 6RK.8vqRBn@UNm5 yu aAuӜ?Ec"p˽=C H|>1IJ뤇N:wy P<s4]NCyz[At[I]@du#6o Z(PnRomb|,}pq"] cK0L^APLm$ٖOz\I(TR#t(Rc7͢PXDΨMQEwNNE\Nvi9.&[wrCSRf T-u +tnok<rKT_SgVQ`gL < ofMO8)2K~ihs.aPw,0լ3j~nIP~(%ݪ12 ˥6t#x97ɘYRd>> -LX~[6;d+Gk٘Icax)ƥkwPD̤֝֏xg'?.5xY#8NeZ]qnp_SWЊd$U)lCٿAGta^-~& WN _Z} fgd}Q W9e/Ͻ]H5$]>$Ě$:Ӝs -<>5Q\[=Hz8BӉT }9 z^k/I q#md5|b?,__&mn 8<&71,o\Ml6BD[މ̢*+8(HKG~k6;ۅ15}lf-'tmrrbeQeş/tV{1\6/xo?w >O`I?[Ǫ|^fIii/8s$owg} Cޜ|?7:+Ljsp{]m^cWRžaJM,ݗeCr"[-S ~kvhqzHCr/ *d7n :|\k pE$Abu(6Au_ZzX*zO?) .Țfw`\9mg"o}* lF${'u>Vȗ< -ފ7+d[.1O|SS /ouZqs`UB+w]mvv:=Uev8M1{vŒ5Э~qF\{*Ʀ [I̟s79eEDYq ́vbphi.GT 2<-Zk e Hk*#d`U-?zq dQ^#RT±G@PKsN(&6q5.kf:a^DCTyM}ָhƇ''#Hm Dx0kzMCw㔑>#ܘ0Uz j GAV~P@S:QEEnѰ\ GmaY΃i5w7 1~Nv)JB/YxGGBy2H1Fq%^Hإjt1Dm(#dHKg>jJV-$ΨN_\%= hSydP:= +MoɡqBZUnd,aҠgloӘv?U;VoGce4!tN&,O;Cե yx)GV t ,bOΦe SdzS?jKgI )~r }J4xNo(R w+"2~ XuiܮAQљD{^$ok!>H2Nk .;k"*m`f>zI1k3*BѴmur$KQQ |=vo =|!kgCC ͯ}!MW_& PI;(7tI5 +S# Yԇb\<@T'5\(&t -+Ľ]>d >syYZD8fxʼkS/ȓsۛ1Jp] ̤9QnW-pVWd.-*@5GfbN[>/-*D6ZʈedƧ,CgBϖ2'{C`pwso'I!}zZ{5OxװGMU.0 k24'#8"y.ٕ+ZriJ'RnM9B׸"x>v&7$5+`%u+,Mep$n.9Գ쁇ǀd ߿k fC4#(}~oLsְvu0s_]G6L.lRY oA.BpSvXqdAer,);o J~xβahA6~̇gK^p2؝:{2k T;]5?zؚn2ix߇=m_Qh>2pì~: M/7k]D=dGݸ:<Օ}BNҸm6ʿW78ɸRuO[sTU4Q&wt`UvG uћA3(ozA*j>V)Xy=)S;۸7&[=xjVۢ%%A0fa  qJ(4%Ka 4f\U2b=s ]cTkHPDQ{J4.:G >HUkŞʛ "(̐<"J~`[S 6hB b"Lj6 m2(;R 816?]pOcmxX ëi=\T[sH+'oǬ+@{-OtϿ\fuߧ[g&| rNbɽPqfOiQJ"G K4&4rC.*3-a"lZ+ĭ%fo(9֗ J*4drO!P*5dA/c"\o*ӹk z"ɭ1.2=)Zv^O3g|Hy\vhH UYdUG=NOg;%j-sQ21,Y6捘w FM13NYh^9ux(.™*GF1]CfuI̪0r7~لѾQ"%HcP>֒.8Zx[)f%> d@ zqSqǤ$pd2'ig-i)dcs f35Hb5@$ m}ޛS.>F,D&G" Z&Py.FS9 o6 -MnrP!{~; 04iJ`e5oz:tKqrU" Y3;Ly/Uhve6"q(O$i_a' ɄF}`UFj\|tK &NW j(hp3;DPZm˘ a>)q\jHlO%Ѭ{s5J"JMKRI- 8bGڐEic,"T@HJ?r/*x|-Vt:}X!%cڑg6?*VьMO itP(6k&ה*O3~Ըf_p3e\q|de B*ulL~ 3#xٕПl24ߋ+ :X+5 igXk}n@Kpiiwd&xll˩M9FI"師t1XIe\ӆ>$ũ)/1a&}A6}MGB'G~ r6:M( V;?Q)E+of>G/`$l̛> b#)]/ȴz")t^3Zb^#@cUn!M}" r*j1F>ŏS(`wbh0̲βHqSmWw~'iNDSb~|/9M:PwΘqK@e3dqk,`MR VJxmla],&+gOzk\ H1v 'zJR2o>Z Y5J?nK?<;䬭/UHkd3o+K4EZOGdIBo|$~ -}}_cL$GݖK_ qb_%~Rin,p6[xL{߈=H Po8/cnwL%^.տln=mrM6Id#/VlZ9qTjK@ŗ|"崻!6V$>z â$l j ?0R;|>^UM(.#z`~'D)%\wr-Q h>e wco;!Na!e$>shĹ[U;zFHgc\fKJI(ʁOHT^7?V$l:j/ܸB!vU =sX':W\645L>/rgڂ @e:%[V/D;GIn$~| x0 H}*KmJS T*5-yEaMyZ[xio#ۖj;>f\9{le_'Ξp7|z@_hЗ3lE>eܥ_ltge+~m<@5cudnxphuhun\]IkjP|Bbl Z5[ϔ s|iqI@dx٨Oz@OV=W.=6M^ ]QCJT.#(&34 'Y*)ڃDkaAAJ)EMmA̖۩9/$~հ(]ǖ֟ ioEyO!roA)[F9ms߿X&jg⭮|9M+=,\uײ:) P ~L܁-jܝd?߅t 糶|,qFxPq뾏"f;^KmU04x%:t@a|`>!ΣbW@$irNȔ[p*obtFČaz)d[oߎ EM1boF}@$.R8 c&YW jͱcs)w3dQ ZcnkѝK,A L* >k_XCq#ny/hFE8QoL;]#cL”ۊ/:YJD+ T3[Ee}FغȞ{t+y߹)5jC$__5Q{#9IzNRڒ 5v/b3|E2t:mJgbŀ#W! UST YI_f"yņY;]un05FtxZ 1FL] i[.]FstQL.u ?=+\][Oeqss0HtG0iEM$ocl@uAx`Q,gқ #%^C 7H1&o+>fP1Y)96o5(s0&Z6?8ԧ21/GZ`fB5.k fP< ~[c&ٞPV$=\^YH@c½Wӹlp{*zsg|B B;ZrE/1"3{(\qr'H|Uz0]^!+4W!x!pKW>vpfaw 1*-}br7_H#W%moOb2'JNS;碢ŏ|q-"h0j"Um(,΃{)L,ʀl^F3EƳVۥ=>A1n"t$z86(cIɣb,--F鹬1&!oq(%rLC[d9L^',jO}f\\56Qz' FZnY .k^ppiI vaH2c@ #/>tƀP–mwLLYlaH4gpЍky1i HzCؒ.QڣWpw!GR љ³ Uм8`GvE$?@Mgbm%L[)[4.%zL`UV@1rw)|&N hJ;*^iS3>?B^٤bLT[Fy+:lj;bo1J\UDzi')VAF~tP\wh.L-mq09,شnT]˅k1JwivM^ Es h,X v.(FT×$6Qq"[Pwf% ڱ do۞jBWO0#9[Ng(;%_,yzowkj9g ˼GD|f@ztm!61g5˧mkיg}]@\W_3lnZ ΀VQ?P`.wvِ1nP(.auIׄԌA} q+JTKwz 7(t" 0uګ6^pM|a@ I-~tgZPyFW9i)Arvfsl텴&B>C2[ <]4N!HjvAt] M8&+ꢎ\s>#F\9@A?G;./D!!^L:I3u왟U gJ9Dޱ49fR!՟LRQV?)MT_E9@'B;Ux׍"S{L7$!p$B@X7-6AȮ@$_*D 0”Vq@ xL~VUfSg) m%zu*Meӣ5yf(˵#'$z1' C5iGgxN u웈cNQ7&޵3N^<0ѐOVڋr;\yϦ9z&& *sCJeZZ>FΑO(  u4Gz9j''Z(i97: ->}8m] WQBi,zw*We4HКKڶܪUfEHM ׹oz `@"ž-*9~d+jNFmʅ4)\"^3Y[ _Ȯqt@ JB%/ 6Nڦ |7'/~$BiG:ð1yL6ֿu¯ f*߯NcmcDY r9Rϳ*PЗeݼHu@F8|T^8-M:΃Mv[cr@p]xfQYIT`{AeONB\9cӁx|QVIO%K5W>ag؏쥒1 l1⊍sB9f1oq_+Kaޣx\lʐg6HՋƒ'MT֍uDzW;fowSdq&M`$la"{jUQoIf<&:/fgr棫,~v P *k=#q{g( \ҝS>hj%FkIm#Iڿ),$!%I ?_#X 8}Ua| #T[:&AvSqmhF ;d+"kw~7@dx3mBzI#Kmv nBkaL!{B[C˪Rmuv6TKb>j瞢!:H瘠/Yq3ջhQQ&T,Bf̵r#0Rq6j>"@iEM|>T>Mjjyf8tUN_2ďv;ȧp\sB$ K j,'BHk7,]K?Tɞk$>␛@4* W`/o~`u4Rz' 0edMMuL&! B %}KۂW/g-g5z 18 nӼ$t}?D~KtjM'dnWbsWY}UIiƺ+`SEMQ":,zM*VaDr^ωU7~fґcḍKn*jɩL  A+a{ld;o:odLz#-;i19eZ v6wXP= /;NO~n?ğdl{/) U-}Ztwa'з: TETF8\l9wx l;"6*~L"TXz9sUUF=̿O[~Yj-NIj }WM5Wu=D\YiPz-goԷ Bpo~\깈߷n?PH|> t$G  _KYHבIUd у9*BNb?Vhkk16.l0cgv\{&E`Omc.bZ'T)_ڡ !ݢ0ieGJKw&Oz [  I v{#tl#G%(V{1[®пTT CV_{Qd sTUolHӴ TwyÆ\r$e-:FBZQU4pZ8nj9=85g]_,GYE9X@sT13@JT$Vu f0REn//5b Kv nрVj7`Ro%rZ|iQmv^g N !-B~.LX$ ρ$#)qܕ*C B.m19Ͼ)| pj{8,RI𮧳hi$0]Hq+{[^8?o\0J2(bMv\N(, w"xƔIכaXԏ9gP{0^{3Dܹ5V+ fv |nl;^c=O+wYCr;$yq}c]>qf[.* k1 0PSte@&-.1JҴ5; 3k)L#9@d3jwm wSFI!TZ+*RmR?E?&.QQ+-7ոd [^%^׮}/2D4exmVKq+bl:x@.0 կd\d vWLcUR3χW)9:"o;p&pOQMg !u#esm6Cwu^fйcl]o,sZ}1n9o> TPCrf~Rl /A(Iڇ0"?!ꎭr `i,{y4/Fc:Q&q^|X䉿*"fBP_:{/](~^ 븞M;%9Dk,+rx@4 oVw Qv" I%SڹEÊSbhCu)26f&T :Dl~ &r1tX 5|[+<.Tm?`i>=vұrDTq ?%&#m<ð.i"ջk lEd8w. n5Ec6%AҶ,26 `򰋅lv nTclxoP.Gc[5u&p^3ka"@+;0W4X,FWq.~}W;a;?nJu Gjk1z3w̳tuGpDJ[T-N@uL%NEb| RW9P/cqg4f{)jƎݎ^G/Qri'H젵L9m%]lFTiuF&g2XC`CDKfbqΣKsjuX07(1Y7~][3,k/VҔ2ڠ.*$[  OxyFr|z 1O!K͵C{.hh5IPH=F!kcE>9jHI3 Uj|/4×W_%2z?!Լ5l1n&۽N(B{)ԳOZcc`Gufix`xGq? w M'mA.bX[j)9%v.x@EltsUr\(OJ S^VWI4ڀ%!@B5'l?`p;vٹߊ*T z5vb+jFe:+'\_Oz=6y$H\" lbt,8%EsL8AZf= uN0[Xc61=h[8 [qW!glz<훣"pvY㊭5mO=bٸ $ǮH&2N)ee O ˫Q>:Z ͈b{ruKw8m>8[EQ'zR95wz$gjҥQw 荪C+Ƨ_,#OǐyoJU`ɒ2c2(E>> 5wNRyUY tBV>eh!cR$u8NҥS/(J{źX oW\F(q6 c_,d07P}[4ɸ-Ր_ ը]@7s!7 CVfNJ׻+s2ɐw}~&'ĝvS?*}>^K,Oc;m cT$^wLThņ rygSΉ$KєYm.4c3SGjc0J!S"!էMG"9݋"tXNbMpI›GLثb ]NG;# Q O_ɗ{4e_]L+}Eƙ`gJuN7RSHPe ﬚!tsPGמ4SR0HnvjK*PQr!g~TS'Z/Xoě5`5ה% cH5|eNiD-x!]Oa_l8zu ..{y'`dߦܥ 2q*ɒ! ̐tYVwB53qy&F J?3-;51? `&غ l @'|&h6L& )Wf=hTģB!HN.v\kUH @ g "ScԄ- /KHgE71[cvdG0Gd9JYQH.~20Ґ r۟`_2gǫ G`N@k>~kӌ 6,q|ktӿ#ӦemVċ`m}ڀ]ng,7| [cLKB4U1fl,0rKf s&9w%hZ#t?.KD7!``OIs ;)N CN3 F/0/ttS@2ueݐմO\ ܚJH1t1N\mNx Άg`v6m{T# Le oLN 0dpe`PILG^ /l#kXzG{wNjb.Yv~a6 t@tp^U!#a@ҥn@Ӝ]Ԃ5p rA6FS&-,!,{{KS DlLbW$}Dά9U$M.f;F^Q-o:,,-G}m4XU«;˖(ebv)U\5`x5jRz.Nq/cթ}7rٜe|TPqaIT$?oȾ6+di4XbY8}8Ucv?z +)@Pn M(ZT"9~-b5]աzmN@ykOp<īP$UBj^7YN%?boMμ|) 9.2/_sZ;v,ONB5WS!;?P_ o $j0"{M:h:T23׍ݾ6|ɚuҥ# -fJ%=I;RgERٹ. M{U^XU-Uytv?ɀ9S R[ cޕ"4ڴЛ _xxLc!U}`FL,քSR py0ikiuh [+ ,&sU]dLO|H〕g#j} `$Hz;iTC8gqջ!}wOS?mxB*; DǨ!D'+[dV*|qWҥRe_;$JQq{qhˉ_R飚1FJXAy8FFb;#AΏlbzҗ\+|r3!MoF@C>UE"˃XQk9&"4'龜bjCsMU+U"$Y-LQIB$gmj9?3j'=npyQ[!`vB^Ʋ[AJb:S!TvZa]tV1Xؿ0KJp!>!9)l7#&whRv=ȇ}!Hrw#8Z?o1Nlf+i>AY"PI3^ǭ>>ߢmn!tMNb :-ޜ0 ٱD
N ~.3ni@5Bл'̏7izɣk@5PE4 φΘDu9zQlAMV8eEo%;(ƹ?J>9Iw(]ʓ+a.'+fYSDd*H ?7@[v[RQ˲",aꡂ: 6߁I_'|w{_-4kz}jEǚz.䐑-[:>v\3F` ~`B ^Aaӿmg*'m;hC4{u"&ǂ?ۀyfz Je 纮Y&6`+d?:8pbӜHmh3S5 Z/6[$%5\z$e#\@aA 7Nf, gΏ݋>]f&b@d^jU@%4 gou9$;iۨKi]Sap*nРFS Ψk7`y* ;_|\EUPwnx_A$oxѿk L! 7G$@MHTϳF= ԼEH@ֆ Kܯc# ;6rOu{`Y ;}W*GF i<p>g(bAǙ̦8~ĠCIObM?ZP`Iz{y|H {:(gJ }7JxQ[H'^ٯi%Lٹ:u#CYohΆKze >4z$z-\9 ʼn><sx7|DB2 w9n?Û@^Τҗ{8Ye?wO7lcs:4!$.¨cn9Nc&>\C dȾRSD'Uv%Mj%Ւ?ỳ90 bv~CZ '| :yTS2|A\HU-n$ٲ;'52[vB(4 Aυ [tw hhğ&w~y8H&tP-,dK QKGϺn.>5;")!]JQ-^8ʇPTOLKE;|Tc=KqlDŃ H`'uM I&\fjbgQtgm!Zat2cJwlR/Uml 'y;gB:!$&if{LKS7Jr?(UU`*͞,ם*n_HgeŽB8 Yu 3.oV$*c+( EIπ4tФp_޵q擓hodoyhb< 6C&I2`?h>A' l4#8ol jIY3dU+rtLۄmSLknFӫ4 '9$]jR]|Dʴ|f6^QuŴZ (C+ĩwi##~{^;Rs-ؠ#CB$ :۝-T͖.V0&~k87&;V9^;<a+S80R ,pyFmRvpMhhO8ep}V v~z_'祍ރ|ogSBoX[C{“uM 6yMVQTWw"7 ;'./lakΣ.=E=fH[ bh*)Ԏ'$Ѡ$1 w' cY=w܄V?v@hȶEX @:+#);9J:N htJ}:3#Al[`#]sl’fm|D@|/N;Ph+IVsJ}>YԺykyX%n3)V*=&iq^6 /="M3y6i՞ b^-ůxSi2Q)N(뒤\/;URG^u&&`]C|XL2ӽ i:+ڌh89#2d䡀XKB`A}2RmZvI4vFgFBU H]?GwF˘l3qZ@7 Gn<6QB@"NhW- H&/&KpZ'/8`*$rs l%'( ez6^iֹoEV6.QT8|Z%o^taιp1 lkQŸ>E1Znd1|tyȗB=O=\^Oko<iba#0{z{eZ@xLwa2beJ:M#:$L"ڭZPz砗rV#G/;Tlef9ΐUCʍKݱMw]iN8`ҽvU&0sȗM'qHAͬ+>ho{֍UIDD7 2yqH>{cNLv C=:mabٮ|qgW?<)8FfM` ΤڲYk*h &l.`/~a H\جO( =jn]@qNcpy&>!gLhf% /6uAd,ov>t [M-7\uʒQX1#MU2+q_(Ɣ_v{͠׹p cGy+]J@žk}s-W j/"eg<}ԄM_0ҪfjfffIEBKZFvHHp#oG:?L s58`$ hFoɞe)T7h˓GqoA #ɕ4xI|:m 2k']J{gwmIj=rӠ; TLmڑ"[7˲p"D8+|CSeG/2D R ZvF#w?y ^6 4N=XգjH݊0d1 3ww%=~?Oz;5gu=!w490Ѓ#{Ny .V(Y <4(e23F&(h5ϯt{R>Np.|∠Ϯ)s5V}7f/%xbF~>cv[2;'GuwEM4~NtCQg-V[.fZ]!-Ko@PpO ,|$jaQ##OBvY k)IEoM $yn{HBC.𒄐_`T0/ ŅB >f_ZqAUx?1-&H2еo@ I>Ӽ:u?MK"`=6,G'Ց2&^K@U*ׯz;*=rN1/"}4PyϑZn%U)|<ٛܕ[wEX%dҹ}xL!72\E!Qtv8o</:W%ZDOVw 33 zP)i9pH ٍn~s+5o?f~\$P(WweGU ^JtPxmigJ5} 2O6L/:b; xAnc)/5J‘6h ܷLݲ &cRFRrDvw xz |dpg|;$ec.ưh'HJH*/['7 rGmAAYtBAO[hBKTLWKQfEDy/vegVkFrTA #H&n{y -1r1$}HEkK{y [W%tYE{i?(CpՑ@@[2b#t6Nrl`ü%i3o]X!w=^Z%CB yXٴF;b&+ne!hwiP+,p[žZʅom!oWыD1j.bN#:K3MS!4ZM5zjXr w=ڗA~ DV`[uk]*A-$B"+ ;- '9DΥ]v(Ft(@Cg5_+%umc=ڌ9Nu@vx.Jɡ7e&睇JH$SXdSb!ktd (7N&SzdmEZ{Jr\f+yQ;H>IJ[ߣ@8Wj#Cm+tTLiPBROQ %7 MEq*+-]OzsPw<[?ZJڙZ|>^k®⭧_vBMIu`ߺzj=hP ܋k6c3Qx\zfOߵݢXC!-/b%%H5Imx6qWꦜn~A.+WPYdͩjGxV;ava>ỎoP )ZT}uW3I _Mb/[<\`vl<EJv'_S䞪%Do?{ʙwzT=,+',+ v&˥FvB9h{fRO'b&is9S: KC[U @sVa?ձw1`h"0)2ֳ}iu?S@G5lS/t2ي %FGz;iėz0t0tGW2BN7:f@wFOr!7]7ewoJT{= c(SNmp'OȔqNZNNxw2rʫDp͂dyaq -y?K~\,sG K*@qn{"=]AU{gˡdE4 (w/^,T#Y* M"=5q/kzLjiǘ>dȚqZ+mg!H29D BX"cFk!)ML!e`\` MUIM|^ǨԴɜ4MИ|*5Гڒ("){ !Uv2Mo' d:| SNE O$/pEeh,*ɭ cH L0KxzD]ϞbMT1^.Sw2Kjɸx>9#XUO 1E !7mz qX3V~TW M :.!ŨU =D':%`T#dij"Iq*/lƝB}* iǟ !v(>썓n m{F)[/N;X -  C%k"f> Q_LU3.ZU*yX 3Yʂx獠-U>nj;p39l!{Єxf%fJg8nE&aۉ;%Pʭ}Rjdi ͔y2Ӄ`f [)fΟyyE(Ϭ<ԈG b9<=m^mx')OD.JWX2j\cvAFuպ@:Y"0Ml&N_qb} K^F"l1å8X/pImK1Ȧ6{ebP9EAy͗M2ޘTGs5{ABEb_΁jR7M_y³]|Lʗ&rα&< \8bT~ݴ9]ELq:Bq4[$J9 !F3\n4$MaKRTq?˧-qc] DLK Vj^ь@lwٙҎoz1%Z"o(6(j(&m]&[=VQhRY/kC]!#*D+u3.M)zPf If?s00De.jgHI#fGzsjFe >ІIZ7*x_΢A+hcU"d y&WǥkoNq3ZԇHmAD&ѿj_О&k g3 AGa#̙͈l8Kq%$J De^fu[ԅL̑@Ew NNԼ\ u]>tJV D7MSx3}֧/ʄiL2땻Z \4u6~u,[.23-?rX ]KېJ)vI. ˌdth$@׀g@kwZD݄Z*T\? ,!?ؼa\S㓒{&׉zijw:+ptRt !\bv f;W& QV> 4^P))0vgcnuiY6xbksŞd=N{g2ҿ1#;.Ɯ `:Oz^pB/ ȕMx a-=զllqV$RfY{qfs^u"%ȁx+MIwH#"nۚ'uUAQ UڸGli>Eְ=){y63y~Bv|?%ZIN .I+ nnlӳ0lM2pdq\dd3Q܈x+,|U|ܝ1>ID& ]VOT}U|۩<1. 2ARX^+]֥ehn E0rcJ:ƥTvH~J)++yo[ozF>TN<* ̆<2YW[,mWRgOP6VBJR#@ 3AVކRR`ߴusd(V,&AjiOܖC0wtCfRNZ7k K7I5uc Qf^uIWGx,O8?Ɉw/_Ac!JU`i[.)E]not?nĵS*#vZd=)/ .7RѡA'av·PaVJI`mgkxީt f)Q<$Wd y9r36W&L\ww~ލ„Lζ yU뺉&]*h.SC6HkZk-oC5uCw MisgHޘqg v/ 2c฿y</5Mb.}C|r=5 7旆 [;DiXi )"]9AUH::Mb(mF{>?nߦꞗFǒY/s S]9١GGQ;J@rN]lpݾ w{}!V;3=:OJd^ ~ Kxk(ЇLz-ڽ?U/}&_n_[A>VvMswe_Pho e__XW ?9W;//ɘ֗U]F < s!iIok'SKOa]lo>A| ֑pC[x1Xr\L4/HDVuONB481J=a1\]nɘ~lըW ֬[r" #Jڻa5W ?yݿ_nQH[s x/Ebl|YځB=W ʇi&\J9bz0@n.bzX$54]c J*.@}X8=WՀ j0/VGP,IAۨi=٫KIqj!0NW|Rp r~#iwC.^)ÿ~~Sq^`mZ^.x+\ݡkm5^t@5sTg/@v#9 XfYVl^_Qd[)&36tZ/|`u'?(ֆ }@`2gU(R l&xW!1-[cǥy=}lMBߚ.K*D&6OZULO\ybڕ d:Œ bBEKC.cޏ$ VJu;1.HVW^ SClx$"c2M+!ʭʹ&/}3.=+uʹu~RP*2telfFyT;rհ9:4BUE8NLSm3 GdzNuc(p80Z =us&PoEi4#AO _XghSmޚ\KN^_cH{ze5/EiڟY95%=mfXqlrAƶy (d2 oC㐇0y%#6;UiQU:[!//th650LP0D Ӗ.Q)b5yg&l /7d :*g{k{cքb :Є:}2\]?vº_L;o5 )=m;=(C)qpՑgAy5~,z<(s}-QLjy«5̄%Rar-aQEmL 6"|J6?X똽zF0Ҥ-:.RAAn"Na/(.מmqb|]Y) [3Rxvb *A4g0RW㞞&#XNѲ3h#muEM@䝺"ti#KJՌ%KK 6; jt ǃ@@PCOq2k?\]G qLNK.b|I[ˣi#p`'afi+all39zΦ.d7ӟtfo0Fe""@1x$FFZv](M;Rj ]p8v5{}ˏ!Ip12sz՚]^HSD9=-zyS 217?d(ռipS2G>jGC*>s),ah3{j~ Xż֝J5 ,SE } \!vuK&7 l'IʟW;@(pEΐ~d YщZB9n 8n@N@ w1żExZ*=|Zjk\MDWjAL `oC刚uha724R`ӶgbNa#H)fdCjU<Tӣ۠|[{[v+0۟dxNx,zqy'T,yine-8Tc9EyWP7.uPNˣ TN&^L1cG8 :D07ēH׆6 LɊp7Xc&|-LjaZ-p\+]tO6qj{rκ\`6GP*EkoNEdBq}]Iz1谄)s)nFvFΤZBF$ۆ#}K^"q5-pq+A spIԏ۩ՙ 5g3ˬĞah1TZ2;, n%bpmvMk>t֑pjW5NZS+*;G|_ R߫|q$$7r 磛2bxk ?*q7܄غ?pyQ0p9YWaB"Uu"\244U[&,&ꩰ yc}$P_b1qytxb_" ÊSq8 = wcK{趝X&Ryxa yBA׈2$D˗HsЪ9 V(vcƕm3͵r]VbS^Yxq].{y{5RxsUr=b?\;Lme?}Fsh b5:9=}188Ts+`ZrjHvDZP ϥ/v=8vb%aCA6\JMV55ź&,IKKD$m/UL1WFrdIv#)5ZMo PyW M y/~jV\%G|DX'0`V#tj``v //GCSM)5x֘Y☁=$R6i&fB4ܞ$f&j7U * v\B2*}zݬPi\<ǧc9h|"1WED|sPF(2m7ŔB+oE)$G֎Y Z 0TЙ#"G\2P14J' TΊ3pv̓/ȧSxǻ>dF"P*B_~0;ƙ k7@"'!9s9_Rx#lG_À f\NތG{qW%샑w %!sm:ڞMD 5KW㼊ڦͧ0xh4jݶ햸؈4ŲڛJc i{DG\[rO/k%Xq/%DQ'ZhhA2TQegKܢ:S+XH 7 ZG=&///q}|aM9.\1W(KlI%L[=Δ;0p|y%|"GIhV'oe\ǹ|lָsU2<\ \*@%7GxD Be 4VD7Ն~K}Ja<߁s!EHcc#|105t~Ѐ:%qߘ?1F_8պt(CXG?Nw7d 9fuA-Vz GWF.PHz  e!/aMˤt:Lp%hrDD!uA(=@@;ՔʽuRB'I ;ExBŋJNX^&":Jʵ']/BϢ&qgx82kFM5s4:vrka]+>J eu{S4J\"l늠łL)FJ7& n$u2&͆+;hk=%MY[C"!fO $ߧ=cE5Q;nfnuѢr*FcQ4lc&Cz:'𧰊)M_~q"t19ܻ?p!# T]A4 l\x$ !ݬI;Nuў,824RU'!Eh`:k#]éˇӠU!Ea6Γ?D7 FG4Ң2:emV?'HTkBQk`&& XG6e?6L5/NM02P#TTDv5ʝ9z)ktcj=^LeU~ ~H%ok/r`g!حEs"h *85{ZPw(|@+-]}gO%~w>g2(1 H*3EܭWT'`Ǒ3Ki.C)gixr5Vtvp&-G  y@g) M%D+,V<-ϳ@%4Vo0@NGpvLU> J"] %RLNvB*, ?őhEr:581"o<$@,f j6--\u`LU1BdU|wקndњ8 oVhIrDLu߻ultqQEAa<4"*uxm U=swomfPN؋G"ll%Ѱ)bBRwYcX!N)(T3{ie^l:/|T3Y*Lʤ(V}{H|0㢘qhSeƌeec4Ms1б~Yc=8m%/VDe\3L6B)CSgtTi=I)4KdzhjQpdrP-9;0dyse.(pK8&%ss02L75Evn,#MMtS#g\~$CVv2wlcp ?FXD.w>|mƈmj 00]\o.ZD_"tq{: H0bC2{C?x_q..ogXEl72b|P˖;0*F*_O龏ٰˁ$Ӕ^3~B61UXn{xhY`Ȟ(M+6?v T8|oS>.+RhTmwn!n!&qhoX T\%&k P4 ],/3{r ߺ szj%sf9Z9UF LJ18 (1frdb9r4@` ǔc-nKE@h>&:* ^^-$~B&## XVX6CE ^jMZIWW,0 F rV0dchH?WlB!Msۦ0-"`~t=2zx*kr@N/`@܀PBu C%aF!Jb.*IO%p ?,lbދ~Z}^r雒KTGyk&S*TY9vr, "7{8bg$p3n&u+Z,.;J/kW LA0N"Zf}SrNI#x\V'M$Fȭ(kPicJSKK~;,oau;pj"}_RQ=#EsW%YB1bl]0sSJ}קּ{A٭k3gΨp'Jl^ 4 }~_ 5|wX":@4Vc3|0aBa{Fhaj@- S\ھW+} pPo`9tJ[kS|]AcfḤfqOO*A9׃٘Ozr#M-ZEѥs6YD~&"Bh:&*m>$-C@֦n~#N@){@jkC"Cp #5x*=3Ww݌tfuyb-1d&Y%Bt|csAӡǧ#o.n{sZl$[I䖦e[3 7DSm|TTJۄEVTQ`_p%k%4K-([a1N#r㹕JZ]v ONY侈+_~&\J*]9jC0W:q68ÏJ'0#+_0cߨ-]cG"eqDwzhdw!~otb@t-^چsu*{j Mה ܕL*m5Xږ ,fMo**zDם Ѽx$/Ị[0Ry8^cJ`[4 h\@r;{!f\Dl4yl{*@q1a R(Ptށ_ dz4d^kSAfۜ2i:ų:c{Fz!K{<7=VB/;ZV!gP,c̺}<@AUtep4M_w/6&ԷT$[c=2BAƴ4$I&xXKeﹿMkDpT|0d[v.)zO]K#^@4#ɝ'ƒ/5bgtjJ!Ph1zg̾  EE71Vcƈ-f0#rK muRo·V0L3ۜDYK ͪD&T'aΖඕDP9ygmɱ(d 6G2D|*>@mt44Lj h#A7s1BW Jݪc:^tj KeYn5LV^;%S ;r 5nd*Ă9r^ v Ɵ%C=:2ϴMʨtcqTi ̵\u̽ƝK*,W_ֳz za4g1YTb&xiwj4 >ԥ|l+i;}, tQ<c4A2]lk.LOnY::l$/7/Cl{H*r٤ݾX8M#X@j1_)./ >[$U1OԌn:pC!/pw\v QUo 0#aWx:«&ƌCAEubw;yVup:Gֿ)JeS#D0 7ogIH1X5Uhy۲d0ib'V>9 'Z/6jMi$ qbKHtĈp97:D3^CA7[(P2\6[n^QkcYdHg7g ز<1 }~ڌ֪`>e7m6&BP]얌 H=p(";tk복{4 &O6㷗ݡ⢳+O(UE0.X! Zn#PCOdwl,2x(i6gF@ =1(ԿSLG8Q3e>wi%Z1<A >lmCV\&d KNwwLtʪdێE1Lʎnۍ# ] -s*W033ʫXH $PC~2ehnY8B~]"@ueInipF \^C]5UUQc4af$6F@쳌!ݱ4,JS,9{^(pA*p'D~bIe=iD{^}j!?؃WϬ[C7 sL"I^loj0^eKDĵ݂"2 ԠT-QD7oS(5d-4&pqV"LgVGfKKds'8-.*_.VK&BșkǏm# 8)Q6hzͩz/do>MO@/v`7&+?)w4 mXwWt RO[M!! pŴ+xȚFBA Rj\B\bUM4&aw2o8B%=HBQ>;K=fInӇP#$K ,O6P%T@}E]}qˌ,;Tb.=gyj'T5j=E*10 ]Wfdq[V~/.+OM)R^\p`>/{@(m1X@1Cc/%yHkӿyp,n TPy[& =!xHɾFZn$5 12 m{|>{7IS!p6*lC0Yi&`(_E?{HZ^f;ԿjA9;fP.vZ-pY|]:;=0!Q^Y: @q5]+CsWܚ^cG*|}FG'bO'[aT_T%3y2'NՊr%q/ۅ{13mz t`d)2IlGs&-K= .I|$y9V-<0#LL$/uU0L6 D^\FSY.! $ %xn-"v2'f_̠v D!,0eȯQ.CAl 5aw`Ʊ eLet \z%oՍ_K?mx.}Y!* hʈe:^EF.T!@^uf/Hx<7Ԋ..M/^5!5"/,L!?/ND0l4/%evZKs '*&ClQ_ajku05U&|i~Dgh!g} }mPn5Z;Xpmh2؞.v*WQ {xg%xphD;>9cZa1(eɔi짩izzPqNHmA{.wG !o\7b"qQxml$Qja4#+=^*O3<9l/#}g L1օ;VbQ9 =mm"]T EF77o 1Tk? :eO yuaxZCL x؍32&w(Ґiܻi=y~ta }mI勺vۮ|׍ؾsn/Ъleq}5ŦR_kQ(%#K!9m=`ªA L!<?*T)/]Wx`e(tuo?ܼGVEOx"e]p6)ț3h9W7'_CXy6ASSYtPfvJZh;}Q^ڳPW~ ;eJ`m'2{5\ AIG&@W|nÂtb'zQ[%$$/)qbE0/txC8Ϝ:R\A 7em3% % 4I, VՕH绺jw^wnէsn\dbgjʲ́43W!UѰ6xc°s@ͽpڐi,*uSΌm糐Yfu|-*'\~]Cd 5dMZ09u7в蒫)f%4N97=OLV?gJ^6mk\\lOou}Et7s Уfh&U}IU3vn6?6Z#4(?3>p"Ԙ@$'UQTf?|33Nޗ!kcXƲ$RҐ"L?1\UX:ûNpAOjWOp0aL #(Rs{OX;IuA%Js!1EؐGt{J}^R>.>dD&e*XK_7a1A4_`<5&l\y@s5{3Uz"յP%|D=!,U=j}> !vʞ^69!na^O]"r}`=,*[hۙ>c̒^yZtfqM#A y徆JAygYFENo*C>+T'G_:\g"R9էC˞2) Yw1kc6Ϟ IvIo`'g\z9N ?"wdTk0ţ6KtyrC7'#fé`7b6!mL׉?t{EH-y0ӲyQ:XPDwFGV $H:( } Ӟh<S>1tMrxm^@⒨}Ct4p#d4PkiXV I@N001]@r W`*Z#dl.gw%%^:2 0"/ba)wC'(k]@CTA1RƁL;j[J43@Dxa94\&e[G3~[J |v/hގw|}͎M >jL+@+ye}Jl𩀁qu\K`=P_'PG8"[=9g( #rG:9'jI% m=99flĞqU'UVR FU;zRnGZ IiQ9LWJ̏=]jҘi:?:Ҽ] 6!9~#mgO .#M-2DB-YnwLڎ|תR TNѹrceVXZƫ"!=w%61:W{RO} <-1jS#_$lHMqtf n n ݫC',kK88 gB~R'…}"YQwhԡ9xn/l\mlDJ4Tt}#߽fG&vԡeأV)XTR/m'ە-y*!U%d.l ^UϦ_ar[dmn3ӡ6sPRq)GW=+`: -C%Am@:=#ǣ‚30kQ$x f %bAyQCZbU$5#vH}jPФLqm0o1](E5^cq8RD$ zoTIif,p Y~*R nxkFsKn ɏyoN}_5ڤï?7C(%WyaXDLӠǤs,_ڹK? " \7\*<~='-Ajn*릉+8d2CΚ i1G#磁`)yo?:ʮFѻ_/R Z^ޝ"[.-3b %dO2}O>zEYT74/|ŰƜCZCϮ\4HGSפ|g#B;[Q49v|22}A^NkW,v S$u?;j1"0q1Rc5?m4=HO9mT㴶a6GXD(CǗ2ڜCx.&ҋx-ߣbcU-' B]ع䌘zWt F^HJc]5rk1"bYd$0>EI:ZM wtU p Mc6.7.ERURa (@wm.ce>W2/q+.lXܤuyÚ W5gcw2tD57Җl;EFLA U16WTsFy;OJ,KA7.amΚ^jZ #p*Jv45bm躪DS@ɪҿ?O6BAً5W`'WB |'WBZa5iFjAq j5޲&dqh.J7.&P[bpp.l= 0倫Oɂg}'gla  4HM> ,f:.3_*έbTAd.&}A%)u9uv. 9vl1w GmDsp.7^o(8i/.hX|=״0)P2" ?L&$!64}FW۰_8;\6}8ޙ0Ո3Ucpu>dyF6Es)O~'u~{נcB"F7.Ua%Y pCAn:k >l ?#b>V ߄嘚A?.|o],~XKN.7eIlO B^k^X3T`8zwCE s0A-x /9Q4&PL]L.XkA?׾>[(SiKh.h 40AbTGB"<=@,6D @Ѓ [lEc*JڟevDݴ3 v` $BiѢ  WʣZAɿ;at:D5\أN(3>EaJrZFBCKr8EU#h/*KFִO8pGAwBAN'\(vh?}Gc])^pi1b miLi%QQkQVn^xR{) < BeڒͫR)2XR8R0O|kOk;)PW"$W!߽xt,`4I]W1Peuu'{f}?w4/nIY"Widc$J^eOqI脈Vr] uS# ,[>ɰ!RWU.bOrG/l T3mg:SLst3:̂=#<sP?xt4E45!GmT--{۬#>MTF9D0C9\t'cv^~J(XV-%ɀ#o'Ԝjf܄fO҅XiI6ĸG!V3~.FҋIeTDQ?O[2j*^&PΑ'~O d 'n{f*WN޸;GE_6yyQ#L{]_:+4qSx a }{d6,GtRjuu}XvO*0K^ &PXnb_ Ƅa^TYc飬6o!]3ܿ*ܥ٤lg9LB!>8]$jT4\g1py['?ZW 8B&Y۲2N =XPD9@ :ft*MV' Jk>^a3gr142CHʃgRtKgwY̖8 HM#"ӱ]թαoIgq!BFtrhE]<z3`=ڽSY*N I w N$5<BE&8(brwhsu`[MF.CZVB"lϋݶ߇rdPtM}1Қ$c]:KdcHOc{5.!]y>K2pcV JѤztLf{e)X$J V3rlb0}R#}Ӱiiu봌.q0)7,& ^8ڲqYm_LsU._py+o3V9UHzS[vЁ({ Sz 1Ё WܶϵTid9吒.h+Q<͢Z|YSFO/m\z wwCxLTq [|a<j5QU4g!G4ey:MZ{1r^Y<%3(6rul9wխ*ŐD3ٻte†gAg;ho-T2^]n+QTA$;B9Pv98mu~kɪ啘"ZogN\}[??Ѿ> FO_ צ?m^ ^.DLZ X 8f6lz:G.zDRy7gۜsVm;99;\Ȣ26{|0b*`h0b^c׬j-nY{l<-RBDŽ>5*P9!:Rve# %d&TUGEVee p>/]pr+Ho^l$vg[u>ӑzª jsyU<dvҁYSRN\K>N}Eh-|dMCǃ ( %ٰP+?־̭{*hQ E,perzImI+7t+7JwjֻL?(^s6C.ƷwPK1(}H⯹E1<*{-ޡ'rO, E= n.P1J8*!gH,nK)}dj^J}Ht$g8(o5""dPVF$[ehYM'ɭ0 [maΨSWv{*AkB:цӇb#;^=XEi&ӊH4qe >ڇZtY 0zuhޅSlz [)%ݻfj&egNK+O鏙dž~k310ZF1ԱjjN6 92 'Dy' hI×zwqHw4LNp*(pԥ n$CP n]M8r4Qܦ:IliSuA7dkL}qa)K4kfd֮EzMAVI`mDiQCG6z˩Z@S]J?)C96CD [оa=gZ#ո"Tءo)wr^i}+ACVtKrĠDҳ{ R^ >5)`bu0ܗL!E@::ƅ"'V?7h‹8$-QwV2C&WHeU@+P K+ߵ.Q϶EL|=.f\ IFJJ<Ѱһ^(.++g,+w"]t. FQ7;'Ԗqri;R$V8⠴dj\@4K92!A2H,QWЪN0D*)zUnelݧոͨ%ЧU^q̱2]~ڼzL!5bzU8Pch_zS$@j=؅B^+#5G-V+TusHe#]lE;u좄C}5QX߳ukCuatfe՚EPO1s1~MdhDSxb>ɇQ"rMhl? 0q[ =yG4(ZSڶpc(;uVyp= ,RTѯvՠ; a%\Z{N{ P^e}yvPՁ92~Ǐ9kUd E]3j74Sz>R=40@s1Dz my{_pnѪw [p$*-Ub6kMʎnWaU!l2*`]H *9`p3 bmH_/~>\ةupS$t,y&^كd|,Fo7B kG! coZ?OAn8x0x6+I;p}&K._{BPSgz0Pagn3e{ۭm VCv4ޏZ#埘ٝM-vBcObҿ&^qz9ݘ ` 1I`Y\6 jd,,wf" *2+w s)[hM>*zLݮ ۼ /^}DCFdf U[PQZTs4xnTWC\|M{;R嶑˼՗s$Ug)Hz~G+&P񀂎[1, 98'F@128Oٺ0ηi1YDLemx^qFXعQhFD XG Gx@XEI5hjR;~~\n(1f@p_q;ݷxeOSf)6!P$ly;q".Ľ%- xp WiӎYo[A ^i{!\$AS\@ZQxXOڍ$]_t $ѭKe0Y,3g/L dWe .ίZs&N\D'fؚNr0-Rs {xEZjEx/XG&Ű糊O dWTns,vaƶdOd?E=lӳ`WYALm'78(<ֿu Kp!:/I[BjZ1=<>5􁤺U T -ʃAVof H %ܑ$՘6Żbܥ23a.jWvr~&&]G k7ĥ:m7柈'k (Dզ;E|m&4[.{V%pwܛDMsUkzy4ɐjF#cP"yʩ!wSe` 7m\T)z-K5|ɞ+&a~sF::w~,dEO03Mb1#i>M_C܌_(d^so ydu8l~]߃*YA: "lm!=Ilhf6*} >8ZXW50C+J|OFI$zVˊɈ⏕092:(&0HW4FBtŢHy7_vk]|b8( bWF˞: |Pf|G3o:{D[˓=3"amh`8 .dˊ)hM)/Ufﳥ =dvS1^cGtF"bJ|%L6<^S0.&xU\@ߐ(x$p֟*Dmjـ15BH;'C9U$!H1, *NdINy#ˁ?37irld]ӼMlNXy^ߖnb3݋GQRVbWPl#{0Z|:T>0-aV܍Ngagw:dG*)!v7מ\ 'Bc{j||KNEL{ulxPniESO!aA)@ʘؠ~NK+?>I6Q Kq3L4D|yJoy+u-"|nުYgZIAaGÀHY]هDw5niV&朞Rs5]8<׸'0z yf8= rE%HEj ]v{839 pݩmd&85x+(;,5Ve;ۖ&gý hݗ! sUlmH2P337Jc1ɘ[&a]2za0@#hjP+ŠebiZxs^_şb8qaKGv+ԺS8HuG8 &{ h ?2\|@eCZ+J\^C!f>^.p.N IMDVcՎ(ȵ9,fM)x%c]sܥ6d 0Gu1Uuh9@na՛_ocVX=SP]7wY RxJt;+J?J䑜`U*g7"I/ m=D0Qnÿ`[jK5\FxwY;ӋIkɌh' N,d XUM+wV-F)锠뮊g(PF -|7:5 NpI's߇0cs_#s,ɰ .V ( bϑZȯ́u!GYcf7P<γTv a3Nkp8&'ٴC]h+XޞTʋs)w!u8 ykGgi^'m:xss*+wl;=Zw<sΌۢR&A"ڛGZqnu8x}G|K9s+-՚P`eM:0&bR3J|' {k f$IasFoq划yV.fPz-@#=C>Mw@>aݱz] J\!6!īc@ɯEUJ./x)Lt H_?Sߔc)wUG6N,k3ʙ CrT}T:h9{;bW17gocޚ U?N58sWg.x>k z>t@(yAY b1z N(g2>4 T3 i}_Dr:4\W~T>pf])BAZi@ zrm^щ}jy#<}[tgKt`Lӂ}R"eOYx_Af2.>M g z81PrvYIPm.60/Zqvݯ6{ aVDGNV8V|(WO5#յ6IFI֑i!?l7 '̬}ѳ;z91@  DsjGld3A%}wQ(~7ȡ >]wqޠIҬ`>(Ј0%־Ipd $ĦKa)l擦 [R= T!ztƅ@E=Rt_m\ #T?v~5h?_*tQ c+P*UX^&# `*An+]'C:U|rSCSI rThm/ܳ.5Rnय8$2j;NLfV;h,d,ywCo ;WΪH4:fSw)>`|I<Hn ^>z8}}2N\.BB$B0] ʸ2dzTI퀛a^kl}jnvv`w;wJvP0~iy9&U"H <`<}/RO=xv)Cs0 Ԇ,uCs\K5>uF~NM$Y`ۉdf"BA->.{מ1ӹCXa O8lP9gޥ o"vӥd*{msX=fPA5]ל [n?vEǡF+\dy2MUEm'`^P; 59]RlտX B˚yMϚ(R3)3{=I׋E{ zEĒaoR$dбY*7(x'l̢w ec  wיe展Vme53guPr~Ј xP,8gy,;^|lA@?:i#C|mǚԳf}Nc {`|&"" Al%qlqO2iCC΍zk#BYV7CqcK2P9ʼsQp}4 [BTvD%~"Y [HН,&r)m{Su"<LX_Zn6<7bHSF9)`DCC u8k(9aPGK,Y_Ts;3;N37ÏFixZ0GR+ѡh{mZf/ l_WTYJqz~b ;>y;dG뽐):ul1cL@0! _ :ɧq@'柙hx1PZ$UR`^ kЪE6_E]ehU0S^|Ȑn\6,Fe%gmܐt*C0. NΩt'1M_o ̃y8Ju# riRK`ǙUңNOLF]yX䋔G?tjLh {GS:?;= [ᔜKP"_|QX!WtO\[N8"ỎxgBߑ>Hz}~Lxxm`9q.,,a 樰mk%XL/Q NNEo}8`jHQ8ǬKi'D&| ;$R%BB!tf5^phFbkVͺ jNqZ}P2`j ̜d(2Y'û-ψLSڢfZ;8c~K_QHa`6NJc!2v^ޣSt5/"NEE~eStvC/џ>}'fGduk$ naQ*,U칖;o˙ yyYR `4}p9ydpSIU/̥j|WSv嬾vOӓJhu;+\wNk]!o*nƋAK 0E ep1 7iGGk%0z$}_Q|@~znhG]VTl_ ) wd[8k@G*jhp؜g' D8N%Z5-V0RsjR'սiMKUL[- ׿=3q{D,hk3OB YQ!v81;mDW}:cDm2e=[ f1f:?>Z{{ϡF}8j }娡If`g)w f\LWN epzŸ<N_uEc9b2bIҥ dIf< M9NnӤ듵"nظivo:L\xWwq)kbdo,_uuV[wy;qln&Ʈ}7ң2鸙Xˬt.O7e^ct$,@E,t[ ևC ܶP- u۩g3FyW 33+"Ÿi VW6$0r@WXŜ-@() xSə~5xQTjڼ^u,~FIU*5ecbh 솟i' .pIh$q*|| l@t*"`Z7^n\(,f!99G`^S] $R3Sgw ڹGzr!ekdB>`EG+{0Hv\#JDY "Y>7+2A5U宔tj22qn]l:iׁE38VuG%ι)(_fVA(]u,H 0њಳYyx y8^tߨ8.I- y+%'"^4>–b wfvo +N9`I@|B%W{ 3_#5ӑmj=u,W|nJrʥM7~')#6ESdpO{ mѬ%%ρ*jߘUzZ2Q 9KU[(7/A+%i5h^'PP +4bDt|M1K< |b.ҞP,ED|0bz\8_ڑPֲ)! p~ `!jF:N+ϝŠq]/X^ 3$MɃ"<;%=ɪ˄9ڹA#W$ϧΒ25Da+k<$ oM[%Z?TW1*IѫЊAK7y}H{#Qv["TDۊZq' !)#{;P^Ӻm^>Y}7J^Oz]E+`"l)״ >Q¿kw*[Շ PKޠTS~ܗ@Fk4A@ WO(EI5 Y Ff@Vut{*Rd HcY@SCZ'·k})25fr<̬&s1|s݃Oq0fOVԳe\KmNGח8pq-5,6S=\;ojbew2q-A n~JnV%D)߻nB,9-;fA'sg"_+#j-thHɤ0_ȼ'N:)*^Dz2FtLͰ&MN@2M!xK`ltNC[,2Ukn(Zk`WU7"w@F6#nb"h8>U#(w(5/¬֧d q՚H0ီv?m*X4<F[ZSl=u7f3βClH#g/mPNN+sa2e)9e0M*Jn"FC۱@Uhؗt1F9 C $HuܿDl'8[;՘DlM:*MB)=Kq;E:Ӝ>z`-';$W͗X3V0(B$C/RE)Äm:ӦF嶓|(s7QA!$ >|G#'{H6>A یv;>+vZc; [ H2pYL&N * L4֘ Iߓ?AXn% uNi>rbG/,ߪ #f(U%},l%M6vp;ۄugWkn>H!iuBnKPڿZ[WqȘ_kW$OI\V_ Oy2 YizȱbVOj8z~Yk٧8{9Bj+ώa/M15JKw7חU-&';?M 1ǎÑ>HDy:ًXLmiFPL%᣸r.[v=?vz:ٓ1DP{L]NM|$؟g d7LyjL~ܿl8BGl,"&;}"\gFQJR*v 1셻8RUj2=+8y,5iPDf .rLO  ]541YSnw 2^t !~טD-,deefvuu`iSK0 Sv#+HG>7 * JqW\R"рZ-An,Vħ6S `α̧E'` Yv[%r}hVYȵ9.MwR4_V[} p%JW\҅Ps3^ d"jzi?dJS Ic /.@֪; T~F PW[.~wAOTz M@\1Vb˻u"4< 9_rzM60a,@WA)W9TБ#"32nDoLtzE2>LIS_:i?*=s+&oƲzUGH`JaO+-/(I' Bc|y}elze^?AӢbaOwJ{="M(l#S؏mSD FwgQ*ѧ sD.a:Le .9Z(BgFװo ki$f&mi(3m&a˝[`]%} W`гE5}c Pc{AqzN#mXqE/O;LK2tӎTѾolH==]0J$xCe(1Uz. NՖ On\$9E . |LK| Ga\33Bَ"61K1{Z!$طZ&Q@߼nҖǽ9H_d]Ndž*V Ծ?0<;!~\Y2P9lpQ $2!cU( %RlYFt\F2I$QFKQM;t>0 D9WI|BoXO[ d0j,Hp&?];ت:im+aI׽UOg+Uz?b`+CW򿱈J!,_$ɦco-),!܆R;ӊ8S{1{:6}1B(*O W lnj8&vȔ;jj|k\p}$ 3b fzoPăqosaqb~8[[8&i! aDC]ڑZ&09k31n@x02:XF%6/݆FXfJ_Dd`-so딛+; V}wB=BMx`%sM I_<]9,̙E5'0*iq,u=zdVVE56tV~2ߚ״Քݡ6(6wJ9uePcֹ~Vnp G&1OL+Qpc ʥ1t9[u3 @;E&űGYj1L$_ vyo *:#! ih~MUgD!\~L{cԣjV 7nD*_"V쀻"CfɁ IpX~/O-I\SA=mB4<+wخZK108o. X3CM&.gnF9lCq邠DZeM/Yҁwl&PO ?H'j6gﲄT YGZ= uo/705r^&3!'$~_?~ `;f%},͍a0mV/^e0MBK A%mSEbR3q{p"Pe˟R L_/f[j)2 s\]SۮZV`ΆsD.vF@(>A`hi6tz'jΝO?4n'Gzw{bE{0'd;wKQ) qk"tKBIќl5H;Z%?0Ně9B 2)ؿ?=?֥/ب!~ I`ׇ*c8k-+,VG332Э Рsٔ"yafhv `̤cMM$kI+0r7$<&O+ {8U~n7ElYIlbN}JvnN*I@r:|<EAߴ7!P,K +R%j怶&>h#ȜN9JY?.E8ƽ|oJQ0zχZ{b88%xb.l<-̋jzH{%0@:uųA7VhyrRzuxH|wq0LA 2U~Î%dM7#/4b͉Q$[r=Vt]AO5|h35E@?rqAiX<Þ5 ޺Qa>J4./ w*|>O 0X亚K=J{C#'aiOqR_]к7R4"b^`f(gIl{tܹx>eLڟsa~n'E4_#Q#E_.<Pk3F \h .-YKڬsqjQ%KƝGxr`"mGe:"?>M ;WtH;d&."_E%d:ˎ9`=-6)Bo[)T-vDꂚw)Z(Bl`^|0E{y bmϡ0*vIԉ@ސT v #oQOqy/HՒ(֌PhڿivU9 ػAYW|s&lqTZLeϯ.· Ty˪6ocfm(^Sw-5/(aԉ`䕠a[nY @ 'n:ntWYBF$4(}Dn?钖Eq t') - [⧏;{'[^1y|`*Ry1 PZ6-w=]N4# $m$r fpk89\1й?'6\MZ“"9o^Dш#pYT>Qv׳,'QL!(]M-;5'Gn`q'P1Oq&tL E\GGM?(s+,,~nAeq&V: ?nI;¦{J'Ȏ~GrBgΘ'ɩD[bcwIG'U9sbn[u%tza w#{n'EulWKDx-Ҩ);α\h_')f<иQ8{yyUXa?7HOtYɁj9 )sp2«;gV%KGg(ēGu噱p\ *W1:O&1#|:4캡վ u5 DɣXCh!Uq돂΢B!ލ %q2ϷĊGg}MʹGmU_\0m=1cTU;t,/) ϒ hvwX*jh4Zi>K#1`JcӬ46"Z|0ơL:>YN`"00zbf@cT7>P}$AݰVż:7Or2C!\D?|45 Hq.M)|iKXoiٲډ؏Rg24z̝L`X?{L(e방}?<}6 GsƦ_4ҀE;U_ '޵Kp7LI%h.36>t W! M˚7 <10nESTm{c6l chB•+"Ýͣǡ~$X2N]p8><4^:1 5UW>k]y/*:soP; Pb +W/wQi.NzaqŸ?i9br0if9FH_z.Xp7XeRCT= 0J4#w'PF hʩ> oW.IՔM,:2)kYL`NaB .\{p}yxJetԀ1uSoe=_`*R[)l.F>EkwӦn,[ C#p6.$kMSud)F73,cdff",˷ar +5N+OX33XǾѸ,p>a,w@-b)䤁tŅVB; 7畗( h}YP~7[ A'&ԫd 񤷖eʕ.i@a;/ZCۀ}.'G ߓ^? ?;}P\> nO:+=;DA˛04\P~cA$H<8Ap\atykY.KdN8"]Hwc V L]Ou, *F||aG6.|HJBw4)< {CY|5Et 7y>IM٩t)-zhbʟq۰7p^e댓4׭Me~D#8ɥ'˖MXWM84E,qX1𳠖~k3C30wP|DmuEF\9ܷ81zwx̋KA1k nEDިLOWV` ^TJ rI,(сŴx3.ai'^Ĝ ' ӈ\3@`t7_!8b%>w_ȡ뒹#|-hV.w%P]hMHF3Dl1Eb.px7~Yجu/`yù]k#nk9BQѓ56o5n'R,L<:0!]~NToB.Guh;h4BEfQ"ѭAy}+kԦK9т!iE7U7~h!b3ȑ*![9fIeӀui#nV =k{C?yVҗITB+qR`݇.2E [k<4r%wg!a6wSY0+LŅ,5Q 1M.<XXQZA$1xNL[0W ތZ.M!y#efFPI _AeB/6ģqb+S-&v'FA2;^~w_ KFd@|DAB0dѴ [q3̑b#@".-Ul;: MB߉i涖ڃDnF|0, q"sEsHC~n#'ex"D9X 5[ >ƕ2!“]P@y;hLEnnmw:`zR 1^ܫ93f**m#mR~O&7RRuwU72{PZoaJǚd\j&;%衒LiV8'RyEiomUƌ2k"1bKH=%vX%eBFq>y}f[pE P?0<.bs_W"rE(ĿJPhH ƈGC<Ήl'X_idDX(/A^bKg_r$ v|8_p 7aѨ 4@jkZ* g 3;^BmkWD"f+@:3 >i w+*k@/a*N?Fhb P&~Xd̸l.HU]Z{-NNN3-MROOTV4$.Y E$%p/C 9;ϿC]>ɡ]N=#֋/7bOa4yA &o(C_y3 Ei~ZԦfDPQ=2TPd,#L^<[BNpv$!ʇ*(KMp%uf$m%xI7B7 Ci~CBim8M#2P_DBE$B!4KGViVprZkC2 |q]j&oqzyI, N P[quZk'sٰHԹĄ0 LjlWH&bX(@\rd Ѡ/z|/T:&?N`Ξ!c{)iEF/rbxtCJQ _Ȭ^S2 Q [" xF] s y2Ű"Fyhg^Je8rT~‚X,,SrLb E'9I}H_|LuzDZ2%EÁs48oؚ,B $AO]\jqU)QxlJ9qe͒{1Z$q\xD"hƳer .3.&)'qi-HA䊔ԄVS;DU},*;Lg ac4LBO"KGvP=ļaq 8ы*nj2yAaEޒys >k^Oyِ9AV ! )"dJHIP0`f?<>Z.8l PD8n͗{OGRs?!I2s꜖8.dxD;V7CF ^Po-&YUؙNM$e%u~TO'5OC_\^Z!Y/i+A&şB70ˈ z2U`4~2F?m>~]#io K8I"_wN MF~ Sm!q^I5]6MQ -Oa#HFf/ N󗽒j!`_ ܀MxS`vǗ >tȫL%i)#?ȠdҸKj`$/::J絪4;y g$oeX/*MoϹMSBaa7AjX-N0́Hͧ!DKH˞%c z efe>_ڹk]4ۊ`--̪Az P0~=zg02lH#{#qSjj> B /0E"&[ݡ(v77١ ^ 2@::#ov%Wʓea .0{}R)H`]j D6I^%.q5Z:{\S۸(YۃǪVoGH&<[O)_*WD2A%rx1KՊw2Gb!3vaK! KbJ~F-m\^QAh[ЎT|@i]:>F9V=+?|3l1j]̠n}m)Ţdf ccҳkVvթÌ~ՔJ wa_9PtCpD8L;QzͣXEZEr)a&*AI½ZcZ%FLL  ʡpܛ9*Bb (gg6Sx! DM7* ?ƶ&*A eYP'8grC>]Єr %4W>eq"Pi0Gu}M*3J`󅊲FIbMAOtɳp)/DhHBnf,ps_$Ѭ?Z,]=gG0#^`ݍ AR-F|/uGXU*~y_z ;>cauabP$PQ8iskQ(k sh[c>=HgMfޡȊ]5%k% CFfIȜ?i$ MT_\R0hF6_\'/♿DA+FdE|" BwjKeo1i8&.>s?IXՈ.Ʉz}qM;БmA>ϲvs*jZTh7" Q6ߑSxh3ynbQ{s,!Y%SդYMcbɥJ;X?o 8;֚]QEv՗ (vi= h! JX 9UJj # #C-mi~VLx+*_tLT SJw^ڱCߏU)rx(QndzB9cniDž6 VaN!7v4g.6n Vѿb(N Iv q1oe/0_\|{H6fYs%@~?rtJCFQaIzES|^.tQ9AF Aޒ}A_1v%-% 0k\%[cW6䭞G'ծN2͂=P9xQ: Ơ){T˘|x&``B@aP|cNZM7Qqz)ѡE""J-a)0_Iٔh]"˘ Q6m9-Dz Ky ʼ#pDk\Et[efdLErIX@Nt#xQC>[LLrWwuY7aϻ=c73!B`xjiPȚ [GbQq *zuO<@њ)'R8UvMV)@*ryz5/k}\t3~;7K9F5<# 2e_#2S~)nPQfɵӲrT l q?X=r DC 4F̀m." =mc%Pz&Nbhe%'q@\`Ӗ-`Ck w-.!|΢A3E.@QfE+]dk:Ǝa7q_d{a it~& f:}aC2 .bvYal;(]16Bsh3xހ[NL%4HKdНi1(:u4/Xo;~ fp_Vu⹌ 6 /b۰ѧtІܕȟD28ʇ *5mE.kT$g$#ԎQK TІu5F̘f#BMcn-s7I uE6}ҳc(&~s{eWhl,Kl$fLgĤoF*m ̙|6 дնk YQSQ].-Ef [XBIYTB!DV@DyBȚ-b`Hs/#Hݠ%o|MZ$e7\Y"}- V[zQ㙟éal_̙-<˺Q},ck^@Rp*NJHc"TK?۲n{q+eaY OKK DSSi/sJ\_a.(7hX6Dg:o]D%:x- 7Ly)y=Ci0rgi&삙03M#˂|:vNxݬ1)NtS ^c$?R| lJ!=5LpÞN޽]߮xqQص*.逖κtbS27I3lh見ex'IҎ\r_%:`Fmn1pYekm06977 K:J֘]%gl|h-K`w -(c,Dމ / DgU*C- &; c zn 6/nkn[0{_Ě-oB\GsO{*LcxTB9wN?xV@bo` y64M?< 26YaUX |]^zLgCpp3|=%t'--U}q~&4z'qm[E &^poλ F<sUC"ꖱͫ4 { /uW'.-TV0+xȓԸuOi }mьS!/9WT>]THAPypb< v04.WS^+HS?̪:}]ƦV\i!pv4F?m!kC0e=4p`8IXBljT[qs{ {:M]CpE"Տd|w眏TCRt| . {&{M ch22`#+m2SKF Pr'`HgpanJ\ΓRj#Ԛdϊg.!S0x+qf\lb 5j407udnBKh`($hCus cZh/QkCnWPu'}9| -E"Ao7iSw7M3XVocfgo/w( :QۊLR?G/^'\hJ+SYՕ5k8I0e< 4Et:P Pc5]_ m!7Hi ~K&MQ8Lz[>5oK;oiRr"T|I}P?vԿ#mzi ?0Hj"輒@L[6\<ؕ @VDŽ>]n~Q8ls)(Ur'gψch7 (Yj'Ͱ VHTqibZuC'"L[1rcFuSuq}>~, bqW-I PIo]d>D|c>$$Z߬KCVn & 7 !#A3e-a ;&&s9l qy#GE` Z^< }-3p}fkdzd߿5rm1ӥɤ \x7I+Ng 2LjiZmIG/#)C^?)abӖۯr5XTs i?X w63Rl';ZNRnؤYu\AL!K0%"uq\s=M]t'iy fr)n0NZܐ=3Ux۵o5t4y|9\sK\9z-S9 !"Mcu=i|B>ei QE2GjՐ?8tO>BhG'Ow䟘XkV`!`4'95C&n(;\c0L1sĈ}v\yesf2¸yת HY7Qt.b`0`d7.DG,ISgKpS Ъv`Xݵ)s0uBW| b%Dg܏"N*'.>/z5VX߫Œӎ'Z{\nL=V؏ʟT8x]-h:nDulXPA%rU)ۼ~jI=Eh5lnVnwgYe= oUdB7&6(;Cw, _,1&G`_UHP9@?"&a(<9!mIP q o| :Zĝf!q:LY(3OV|Ky0A{4 qjMʲ ;^{ҿΘ W8ZC <շmWݗUDU>0H4 @͗S@M =H]J a78vw2FvFDf@/nA-!y$dZ WtppxLt~PԡΘ;kvSQI-6FUUZ#-e//G|:&P)> caMfzNR5VF:ˎ|~Nl,y(u@ZO(Ñ8Jpb*+]?2̥fC8ь..30;YlF=NMB3G'݆)pĝ|h F"` RB2QVAU zjrgKh)҄z1`.[!u]2B(a<ʣz3K +yEH\c[ՆݧS{G[ bŦ;q|z3:w&Rml;W:.~yd@OZ%4]#;Y* Kfui&cDHTͼuQȳQvs-PyZA,'?R{H(nvݿ`e!U_fxC5x{`?UmT8֘\n E2/,-|m!-ټ~,Sde;d .mR0|c<۪qoM;H {!'t69'(}EeB?g`eyhW'&{;nsmӷ!mhu[: vNq6m:u4ua* K'yS}QxW9Ȅt0SEX΃1,˱jJD/:GʡiZD視S U څZˈ Nܑ' \toBu߲4vǔNlbRЈb4+9\'ʸP9g' "(jGA'(Xf{nR !wU`+,(T.n0!ٌ hb_e0b)c esם%וac)dΌD{z:A+WI|x|VsU|DRδ9utEUh9p^ rο0B u+fs"YzfuxHWn\*ooמ,&}CDb I8(AE!pk`G5rK&q ǝ6ޔOqh*uSE,{` >]F&F*& y:S uJ=vQ&4R%?ф;4ac8 *5w׉T`xU}bu#x&C k ۀ Z-ɋDue anu& h8ydBu*)w@(ѹi~vbɉJF{8^C_lƜ$4a(r1h;1g)vGBDU{jz}hgyz+@a""m kiujMbS7rW eh#C hiHǕ )؁r:X4VSF\64D~c풻"oh%-kC] ?&2J)"JWQ[畊%Zjf< ]g|(ͺ\?$PSfYc%pf4KyiǢCSݣAz\Qb?gzOJ#CE,]uضnG9qf:,{ڬsWPjl C,M ~HII+5_D9Z-t0:ꚈsLl9zdVE/EI'mk$G]nJAMelҶfIE1oq 2xi'\}쒘xg |74x>qGQ>?ב7^C03LԲ~ܝYF'ק("m#(|!meե|%p.e ,?M ;Q$LgZi =%"3}'0ցI <tQp_3C2ԣ';"ѡ*5y[M[[D =!@(x|+N8v2"5/RbǛ8jWWzȬ,s?p|mf_葈 Ρ2]G#?|D-嚴}#*`{sg1f=,)M+1v0.NNnB^Vt~Q9ʻWfR2d#39%zb`ȠxoB &3'M`uKE6SvT_ -C{o33k^(|qŁI󸥌>#G_Vl hdz|{._4oұ6 t +L6kiZje ɌbdqZjdȽȁ3稏əWgi+7u݆oVYd.黙U6 HS纏Bf55_(:NED4"{hL-fZ5]y8@Ion<0rvlb ZN8J**9X.(4sV>c<9Iz%|Tl~%([ɬb^dݺq#y" tKص@\;ph& K3N^X=+vɴ/魏)pX q}(g `vs\۰'> > e!?͔ŝaU[i XZ0h[4T⍛2t=~9㙕SɌx<O ׁHNXpJL4q(kPr>CA碣3o#&nO| Giʈؽ2 Oä!D?Fۚ$Ϳ[BpĽJ_7?2@B^Qcr j 6 Va7Iiգ@t hoi:H1 oev{7e6FWz5'Ʀ3ڹ,3l⮿H;y|l"؞̀yY26$tr,P$d ߎF--777d[G;d9||AZJ Џ?r^M` _Q +~A]lqZrҾAh]9>yC.xCQZ^Ž5&C*<q ViC'ȍmd;>=΂uxí%w8~?N)}虠U6c@Aښ(^6,DI'>Ph욐5pI1N<@vr@oh\҅U(Ļ%".3Y."bd;vZXUxԅl&]1{y>eiM2m%m\A(չ0Ks:^-n+VRU$/AͮNOAQ #sat(A| sl *Oqӂׯf|^l٫}r$w-Z㭝~~? KϘU\E=JR3xM^Aqչgt,[cQuލPsau3Os~8myLkЉY#5|F!XcxW43yϠ$,ep65@︥!޾ϑш!"Z|QTUS!afϛhWJOE,*}5{%f q[`PW1 E&ո7] W1z[øwH=!`N(zPDXJSDO,/::7٩{@~W {# {v>2z71Po{lQeYGJ'^^0;qHyxZ46h.b?hn#\!u]⩇ɮ櫖Aiwi8` ~liH{oP1͗Z)O BAh T b ѺP7 ~+R+7&!uHz_}5]V%ERA;W+?৓׊D֮k8!!BusfPrsH[oC@Ƅ w [dy<"|G ljÉޕ S=}z/WȒ煍+\w#Mw2^@j+MrS9)DI-]"˨U-G|AnrQIFUpu^¥ $@.DEb /XY7Me=O;'SgpbZ!7tk_D4 WHՄ qFLJ<3}:X}B|'} "Jȡn$FXCN(؂4V]~ߩ Xšx:l/á:OtFH`}$]&k#qP~\ =Eu`X|QҾJ5x}y>2|4fVHC rEЀP2Uj҉d<uӤA:Ph(.)C$ncǘ[VXѤٗK;)/I61;W#l*a}6ܫ?Uȶ6r3)ʲW&]koƉЁ1P + ;1DWe-ЋeY׆ao1C0ئ'!(߃F0h&s=QBx~'D6Fvk*v=#|)\b`]@.;Ί,b8΃&z'f` Gz@$WNњ7rE\Լ}s ?1.:\8F,if91E3b/1q)V^~򿐴߿=I`4i:/` 7R`~Jp"UeXlI};@RoEgtvS%.d&eGx8md* 4E}Z9_fD ip_@}GnwH扙pvS!6aŘ'1!o!dW$P/r oh'* OJ hbz3XNҊyU"QDZ@ߺbcmں}Ȥ v{~$ȁ.w;vY5AQA_T _M<[7vK;*`Ϋ= H7 *C(v4 u*ä9S_JՓ}g[kT!j]7UܜzfOXHeBk f$PǥhqGTUGXVM}: pP[׍eMm&@7&&-㣃#Oi,Pp9#.0yRqnDybLDp 傣V]=f 5.-Z [bU)$0m/P~|WR? ?j%Ԕ<3u(EXf ka+Լ8:kZ޿:,Z~۽) &'o!~ ƋҌ@eMnOorGflth,x%WY40O)1\y"L92nV]+%?vViLዎdmv X3O;)lZ#Q<\{mÐW'R`M\ !sNԨX^>k_`zMĒZqoĈ֫rlL>G0a`oC&+5&UqZ!؝& cج.;  tUISƻ5*1eTw7e*VdsTh([B<¤|\b {]چ?8AoOw{1Ykii6z\C<+a{R߻ X4xIUR?AKG >U̚[5kI:,|ByI>JY0D=,JGD!BA7to FSX;^9] eQ4cD.ڈijZO[Ƹ%sM# i{#`yY.om,e!6( gީnvQ&aBIWW7]@Vb%ZPGif~zfӑZL*CBF3VRKoWP/o fq[FGb6XJ6ȳ'UK_BY/C>O%3%NŏBnK [=U>wLrK:"áxCt"3#IKX~WP1("1E2;ŜVBI,(~:0s;(Ѹ5 $^9k6HxxhIR3_(ǝ1MQNաU^P8/byӡFr!ĭ5I?n(u||8R{,r?6沟QS`1˚2˾2Rc$՗ 9}`A Av:CHjw ke>MK-@M:{;1 }M 91%[^pzKa^Fab56i S= 5.8K7d}ޠ[s#+ͮV,o$ }6շtebE"K9Z TRsoIcbj_$ҸI`IJFHAIm_*=Ǿ;AqLF׈,Vx; Gꐆf{WD$zcYg邵k?*W1T[pƭjn n) 6ݓFc4O =48 $W%;vD ·y|ܼ-$~@`tƧtMh!N=XmGfa;acl0^ЉBfoc6:!:ՊL>B tA[^@X]TjHLa Dkj\qR6Ӧ)=t)0XF V;ţA]7J\h i(H=gXj;+@U"-}x9 : f>!)X{;Xm~\ь8Wqt_$<*\w<AT[ ޒrjlw-8lY"1$z,e(13OuфIk4y T%ak$J ;(@JLtHƘqʒGͣC B5UyMRIA  Pw2:vw!Bma;W[pÌu`݂~ Ls$# bN*\C>Bs8#mւQw"Y^7C)Cn~k>`>!W~` mZ)dA LY4|~rray>4a^72( Q|dc>ɫGrlzԢ'Xj_a-5P׸rHHf{dicƼHKL94] }Qg7%̵BIgx>fPp;t1v‚A݁)x3UWyg&geAnw ٳ$#ߏb4 Bh̟RzHy5ޱ*seSZ`y^JA+oS):~̗ pTޅX ?xW.rlzjSSVSN@4 L.NXr]?q]lWX+TGDKyc {5iňu'j? @z)}l-XߦRIߓlǬHnzrXФvgvaʍ`I͑hص%ψrq%jѪ,}q[todloŅC}*[|Q9|8xAP^Y6fg&1Ď" 5pZ| BzݓXջmF$w`#~ATdL=\Y #^\[c'L0 RΒyH$6a0oc&#WۏFTo=6JL{( 3 'n[R E_?YW4Ժ`fdc <&>U]_:jl@c]IUd_`Лܓ %3gniws竦KAJv.ݵ'[Hܪj0RG['35>ckTqƞV }Iv0"sN~Ϣ\V̀.8dzW1Y9x̔@GLn11_H>a_訞^":h?V4/?;q] P[Sܨ@!eUs5.y43GIܙvC 6Ä_[3LKA5ɠD-%ja0YJmj2c-~}ZD?h˲ԸyMK)PK HŶ5S)?MUoEjo :~$Twymx9 | hU#}ֶ]ئ !eJANIE7~OM{Ga&eRrs5O&y zb,uHd#ȵkMJ3= >^B r G1/aH;O oV>[ZhT'' D 9`Epq ^&fWE$'T{x]1۲RU;tV{e Iq/3ȶK]FL!2z')AJ< m>v#OO:d"7 nZd,Yܪ7@MG빃CڋEd!ҖlN ݍF~uU$WH-SmJKπakL nh|!'du}m[{IBC5C̉hHR&n \<;XJY,n+] o璹2«@_ .]}3D-`b\kU=&Lǹ2ڄqm6 E ZxOj烖a]dunѭ[pc'ڠ ]ynoYJ59tљch`3hv;AI"}g$'Ef>H}'xfLEL%gH s87ki`fU+͝Q\f5qS 0ਕn(nwW-hېgRO'b%2 ؄^ǶTæ~C^ 튑/4o 7+MT/v#*\Jw{Z16&/P %zN?s;>̏Ei[2u3udNG('5LkmC?W/xxLL}bT!Şc^5C< RP($ս,U> 9-ߞ A(R`z}o LGx=xM"Ȋŗ\yLgwM5:i(5sr:Aǥl@92Ͷ1[fNtj$\tǛW('sH(tU2hwWņHFw^dx0}rc1}DS<ǰR|U;~ejuحؒ`c1B!EWgKzTsR q̾uaL;p烯_31rf[2r[gL*P}`vD)C;!!eMM#Q+ a ?~$OXo rG/KVcլ%x sgEOjjlEWVq0+֏iGn< kr9YW#ihFG&GKE/: 8]&t v t䱪22\#×]=l&IZz}%bnxmG=t?ק9mL?raf0?]6CQLMs>qG0%98s6b,6(rnPA骱 ubʽ3 CZ@p}sܦYo!,~"k2xVZnJ@]W>RV>k( VE#Z3$̓"5^|8\S({n(2h$zs /~ \>TM7:kzPdUϺ 隖8F 5J*4Ӌϋ`gQq_M-W&/ Ҏ)=Dr]J>ͭF--/@EB52U 8] TuUOtۻV7"[P' -*sa}7m!bO cxo(8]̍v2`vՔ ]mmىd`(e\vX1+3C- G Mj8R*JG>O+LROHQ..pfG)r;.d/何'^'s6: '<kWuppB/tI.yȾ' 3T)/Qto&BEyba㉳,@?38!L-6P{M%Jg CB\{܀4! Cp~_굋{VV :Lہ=I& jlڦaL?l4͵We"ˁt" hRcq]Vߓ#e[gum0\ީN5,HAkԴPhOQ֯`S^V^nWc~g؈%y ׬%x4AbX,0Qi/OMA|PʃdH r@G[%GӁ.y5+r3I׏_G?AeDD#Qc.2{9-DR_!ZѾ6g0nhzGTtC5YΌ*.uZr9p­n?^@޺w9kօ*`uy@ZZJ_mw._wO >a^K\;ֶ[OWc^]n(jMC5`:gWcg!緶08۵󎄃{2 +w-MܥDžYm8l2]M=<4I?6]OI8G$fՙcrC.~)hNjyf,{V|,[^X"32O ο:.ye9}=\(ʐy==簛rZ{7c>INF@okh*^ fIyhuـԹJשr * (1E %h?H5I&ts#ܗُ73:]ھ9d,jcZ6riŎ*9iQe?knn+iK $-&һQ%q&W,":m$sθ~V4o;!C =b3~ʔGNQۮW8l ^ȅ2%CLf5Ȅ%3F;lz+;1-j)$8Ejd&=ƋO% }.n:TXIw#5>8lyF!TZ~aP۳\bFlYBO[,Ă֠H/0|\7ZbhrRO \lBi5]0HڊdV{vzaFIήi-t?7[I%B7 Ր3T=$JɎ@di9޶:1L(86ژ{p(_:bZ^6+P<K\NZ|GÃzȻdMr`c &E`NXkI@J;h ]$6t2Ux=+s^n^ǜ1FVҺJAihjӞ^pJ|]VΔZfQg!1-TY-Tԣt]P]n|νNbSJ`ȉG/^M J{{K`Z[icJ\&OSaF_e]@|u/I+// !/P%P m=-d7=M]<.){t]/PC9¬5*wxe##2vu}o,0Vk BF3P?F:zF¶yz+Lw ]^'=2@ *lj<*GKOs<ߗH@N_Nk{%s\'^vK0Eg7'r{Fzx95+Z*_:Yp2n@?679ƵAvʭ;:{;JUzA]koϦHߎx$yEoۅkp98[Z.1 xɛ>)‹ gG.y.h 0 -WiXΰvĎ5|+?. Jëy e[E^br tF_DNYb"mW@nPQZT6 |(CQc[;9{v)` bum]OB ~ZKNʾ }$ӡzaqr>g;ȼ2&XZw 9XmD˰ _ʣ, jdjK畑HL!eޣ™G3&)z@'Z [}fa c|^im w3g!ْR?$Wiл/!>xJl?K wd81!E^~oz[(\RE=s5p,X4R4V'O&t; N(8X L3O\ TD~$ /QY4;=8]ir zj]H=t$Y(ȺbRWx|dkF(q:Q4>iM8 2OqY&q/ɪ-.PRi'r;Ih6y/:T:kQB.2 $# gm}9sOSCj#\BY";⒢:)8o@6ch1D+ :NIt2z'FXaQ:D{R8!8dQҐf) c`v;:Nؔ8ThĒa(_Dv! ih| +ơD!a$i!hD켛6sRɐiz'b[C<ꬱ9rYr]L^>+]. A|[zϛW4 /Pmt:,[R`t\?}knqeen$31+3*|%u:UI#X,cM=:>rZ(_:Dr>wCMAEޡf6ȁ=۝ɤpCz zQF:8)l/N(mW]Z&U aTy,xY耓{5?2#] oC(irhb ڨ=4ΪejkԃȾCn<:%T ğy&~MC'28AW9v[E׸?NCͺ Өˬ ۖ;~qa5 Zq}{(UGqJq1SZ"Gf=$(Eqן䄅D3]˜;bGL3*c'-"wQɜ`Bzڜ 3&yP0LU?9M׫/*[ʌ95ue RMߞ-2Er:QIWeZd[ᷯpoAUS7eC圠0IpVHf xQ#"?qwUr%N |AfSȨfM2 -0>Rn5>ۢRMɖh]Gnʫv.ilEXo1EKI,.fm6> /mGlrf@Ͱ a|,*m 7qR>/ڣghO|$vetj#1d~Cμ&qۗs)Y. } O|)4qfL͚<$ ̘6_+{D4UN\5%Qq~XFwpSFfRo%@p.+X;r0L_A )*°ApX>dU*>K2|`\q'+ [jf߻ZtgрMZK ;6'Q̬;:T.aK׋b躂#eJ}D%;7[~R{ϛ+g̋% |.qMi/LXEbTj }T$Ze9=t$MwdbW4! L+7C ~u35(r1WTǭ//_U+OnKǛii~+YӵQ/"FJj1JDGĸ<{c}xo򳤐t-Νdȡ+ePW֪adJCPcmKumJӅ`i6OʌùH 6$}IA25G}'UڋL/q\xmkTv |Nw@sd݂JѠU7pKwᡰ XJr؂2#)4!c0w8`2@]kxmNN X[~ze0x<>zax[ {vphS[il_bF_l2Bo<S ^Oe9IRq ",Go7Z9+̦!X`BZ>|Lea>)O`wn2 cDRdT:jk#^2(h^8w5N,ZC:i_hl ]Y";Z n%}i3RxrbD@a?8>ph Az߾INŏ=S*'+L΂4.5?.:q5L#t2>mC` O0:ߎSذ +$\>_eqU*{Q f)exh%y2^!O^Br=7 p|:?ek = zP ) &ٓ@iJA$i17AgɿAᴟuhe9VKeԖNٗT+ceUԇv[NvȥrLk4oIH|+@4;1s~$p)_W98@wKwNOp3AQc@~ _5y hšUخי7xS:0\}&ɯn`֐cVm Srٌ`.1bˡRi |E/ A$?6 vP43qN%lnW)9qiLmɜBcYRSiJPy QЃ)C^YSKz%a~KqEee6F^ x8Ϯ o\ڜA0fkçɨE&z%w' z=Nݓn_yhmMZ@̀/ pya1+19MRP[1_g#7PCM.C%+ FNO$cR{4%C 'Sc~ Qonؒ@Wgr2ˑ%"l(;iAf:']V%9f'WH 9c^VRjXk0 t' ڥEh5@2ORkSڙ} œYN?DJoQN-Jw7EB)yapĺ{=5M~?HZY=:zlNU³ZO߃Yi2nF܆pr[ˋ{6VhlJ>md.}P&l7jz~T(cʁ6nҟs{iK~! LYrN!XV~ǔ7,rau9YaxCM{h^h7i蓨@=tu N&n>LҼX]06,H"> Jsz0wf?|&K5&L mX̭'.E}@+=Aq nWQ(aYCw^ 8'@tMmJgw](]~JԕXY#YŶ248D`$ri1û!D!/ }ba*A{%qpDst 3//y Y2 I ~?K g-ulT%qvNTZ,L\N*?y8Iʍm\Zw2Ku^.XzkDܵ3ɮik9Эvז`uL-3.#$F Pi1$tAL?Xwzn'9l̹Ii7x;NXi1c{Ӵ Ajֶ&9|7V-%jQW W oM!3l]aO`R]m"7mՐL0m,*Rw`(HQ5z z3> =? Pڧ`+oz ƭ_%iGx Nla-ms7Cۥk+ " WgL~GMc3Tx֩"`XɈ/;Ty4_S} l]Bsq"Rj8فk>rNFO)YCG)rg%?vz(?Ĺ_fB BQ;|sqt-p/9WFxSm_nL_}D; ݒ(Mus)dgAVOLX3iTvRoKԺE tUG8P42I&x&zYt盥i5l-}lBkӴwZZX \v@p}pI'P'"n6+viPGq jmjhe!RYz1<Ϣ=@5U]*p[ -fwہro8+wZ&Ubfp3]1l ^NA o~q>8q;KN˥Eg;?;.pUjvZf9^g=rH9P2[xK*< 藂k1F$=0UO1g@uwRSwR^"x}Xigz4\HkQJweR;;4SEK9GB_Nn`30 6m9|VdPض᝚Tintpӭs6̜rFnE—W"0߿gA~zu'6iß+7uȟ]nb( E#6v-쑆 93Rd [~Rщ i`f{l.L!dBY,>`EҠ1)_z8Tc4&yU'c@٘0Rmoϻ8w:[f #auma?m[4GPG24acRtWI qX]\I$UW;`RudĜD]ѳ)LO.Yy;5"DǢ#oKМ~JCK~"H"bA,>I(*M} KQf *Jv^h&ou&*lA.b4u]T]`?2雥p%3{./ s!>$!ypg@L3;ìF&ߘL앃qei%Yy7-Yؚ6' .r'YX稊ֱ$*F%H'(&VaWޝrJ)$S#+W<5BrX/bY.etBrHr6`ru1!/A*"Y6:!-xk;ZOp*9E2yw@ꟗn@E8M{7.MW20c L+0U vҚ#4.-KXgF4):7s@8˞X1( 3&ӓkMwi@J ۀާTBD-ڇ[Z8G0VqL2tk*11n;%Tu`X]!.eϪOŨ [ԋx˳ #^P\@vΩr?Svqn \cCfUZPB%vR."r$PImVgt͢2$|^OH̨L\VIh{/ɲhև>0Fwӆ{<6Pqq Ͷ۱ߑD"h@Vڌ^x\,յT/Rm o3 H{P}o}8 c=\ڹEnB&SND1Sy6z@K_Ӯ7JINhCVaڷrwP-^ , 40/Ž]Fcⳙ;-8`r|2q !;VFDv&bT 70`94Z"WWD+*IyYw[E2cMJOc^X _S'׭u|Eu_3&lvB-9~3)0؅LrH}Qݷknz w)gCoW(%!>W)3GY~bjΌ,SKAWb c~uvmQ*{zyV1z&VXc-habLH*i/)@G,//m%5쇇Qt@yg <ٮ9*k:QـȚ$8)d3- ʊ cB&@y(KAV=GxF[#1щRT@crq!"ܡQ-l#, ?4tzH8{FK0E!fP(/Q]V51Skk@;/ ?G;c(zvf[ԣz\P Ц8tkM&dO|W+g+^h'ϖgzZfLFPZc C}UIK4~&rvf~K:Hmi4 2'ƱaųdRR)A\ߤx CB*|NT%s!m91^kU}kk{Bܣ>žS/@AVRNa]%/dX$* yn\'ˢ{_#(g+tK-7e4HW CiE/]>2쿋ۯ]bP@ieսO RӪ^rZ-݋:EvGs%Z#rc9^OQӡt`}]vC<>Y]OYd?8<⫪!³1}G]| 2ҏ&BOϚ!C$/ʁN@sG@d*axi 3hle# y)ycAq)vE "FGhwr逩d4>چ^^̮``:Yzص!kj2+37?Lb߄ߣⓚdhjuUn໗m6 -a[䮢q$<<ë+/֠ytO wmeѬݭEuJ;Rp/n{Jќ7C? =׳{V|:p(Bo+ }Emh,:jA֋Ϥz/"3ZlWc_9=~1bă.R(e=!5S6pCM9jzVC}1 v(܆0*V.w,A: cM);.(HQZLxk?8XIA|m&TqzIVR/zLb l|ltin(4cdDżH;!AaL*2 맠D,ٜc@.vtJ+`vP\JW` D;O@ޚ0wA_ P Kis 4 [F,^V^0oNwLF̺͂WdH$_{^BCwfxN&QI㮝qxo~D}#!+)7uH (sC|X3߸W_ѯ}377^G;fSd1-U mH|Pa=|78ui(;dnvtt \<դjq{+|>D᫁ %!#σ'9 ~ uYMz;NK ǵۦ8 xCR i[aU,1h15t6%qj+!G{(ss\ d$| =@4KJhKYs<27ֹ>|4h_[X~;*;F0)4츧>Ua_!'@\TH$ "j>>=n'*ͨШR{mߔʠg$Pr;årIDa,-1Kd ?fpw)MeYH~xSlse|]cx!P | V[zy15芧WCƭgG_ {ZzLO%YB {ZӁʅ&Yf|kha*7em9>!Ka,HNce!!4>==""(S`F\}Z<]8 ~,# ufQES$,5+efn`ܑ9 @P: -M*'%8tA&VгT5}/'9Ӷ,x{$rT0I-Sf`OE|ޅ66T*#6ք j^Zd!  ~zmq1CU2#|~̴v"w )O{sū{!`̴n+>-R*Z:˚vzVctxYHT%b#x*Lxxˆr9nk)n ͐~J#o'F<(xJ25fgJM T !h*og/&&d , ha9c &W(k8=#& '!cvZlOiWFh+"PkVe:}3^k@PP0H3F ߢV=Y |{ľyrɡ#vlʇ: 81e7~<%Ze+G7`Je吴?u`nQǾ0gDu3Lv`!fƼ=1F7at=%#vy#`(xys/c#Q6k1 |NuЖ]O}ߩ<ڒnr0,yC\qm{_{K+:H? 0TR_bLF61`&LA)8DN:HNz ӧ7V /\ШQmU!xp@!r`cI:BήZ1~& ǏZ%.2"a Yo,BZZQgU orԏV)Y!~](;I0vɢVmDb`#N:/Y9q7* }nk$.$$kH'2kOj#) ng;v/ B2o_60?L u! /N&ީCf7 t<]3^=vP!{;+x̃ @5A z9aPR!;N K)cgiiqx^҈qXSɡd^WJd 0+Bu 7^~vVG3{/"I=U1q'R{4l^llcN?97dڨb4P8xN#΄C;YBڵp 5~ ` [@ؽ#ś` 12ߗkOٽD}\*PΟ'ckH14!5L_;V]üS2H/C9ZsITUzqZ^KBzN<ѲJJ3E.U^Ver{1f)(J=::rU (lZٌ-\ 8*l6ISt<:1| `-mp+iG*'>&+;ժ`gd Z_m# 23!Aٗ)4 ,5QAC,SU2'|D5[KL[<,oᘠ<++rp!:yn<`\CkzȚlH9x4rb^JȳP0GW  &k8I.×]hLrEC<_m~4 WQԜ,mK҆$L3SbK;A<Yݿ5|<|''"Ķ0[Y {XiBnYJV _3'}{9$chRS]Ve#WygD#eY[ w(r*LVG75&݄D-3Y5#Jx~K.E%},Q Mc/Gwo!NE#e Iak6KQ A~7-`p4( |Wog+(_mVIIМh|+wW~VReN',allܹRFYRTT V[I&ps0]f"o1i;bAɔ X/-%4v:0eB8PZwۜM\oחkt59.Y+mL}p{ ײy9#skPAfBkR^dW"A) z.3Ow0>z] CbLO6ZlnVK1EQs=~,6GZg E kiGGy(9RX4Lw vAcZ1`s-HuҔtm0 حw$ ̖jֲS J֨ Hh‚u?PRv&ڸ!ʨ6s-'YR'eXk+F`Fz$)X9kr]b :Y'Ԗ\ Fo2V'~̗u$g `2 $z3&sVuu/ĊJ-]":@$b+<"zY}~/&m[27gm~k>} 1gS}ĩ㸚0Oأw{>lsf5W4^HOL"ͶTu_]؊9@XV(HuO|hM(VW)(0w*GAT Tm-O~ { B"v{%*\?_Q`GBIHHIp<X( +9*-ϻ;r>T/e]qL&*LY^2*ganv›{@9އ$Z 6s.&c *iξÌTwhݔ68M ~&+oDԉn.;&JgYSCD뷉j}=ki{=(v;/4º$|ɧX qR:3R( 췩i!/w( e-Jb%j>W=3 hTrV &[+ȃo2)q,(bh,GQqn4%{-v ă Tj-fKY| qzGxC̆H \bR)r ×$mpk!گQHOomI=ADU#M%(t̙"2lUKNLtHZ!ulv^ͬ ӻ[!gr~b dQ//jka݄6joɛRp4} $NtSC\Q}c@Qu |qf R08g*5z9Fd>\''4Γsk]JAimEgYd5/0GB$քA*[jx&Y枳^jc^r (?!MȃPGKt š#zArkomtc%'Nn>~@ sU-xNKWժ_5,|!}Pv]L,icx`Bh&ko @j\R~. kB`)^d$Ü(KRW\o1҅*@Sfy܆$#h?RB+bLwcJ v3T M/kF f`hL{1^ԭdR8wBMug2'ln%?vG Sz;܃ID=a]գuH5C/%!gcdd'qQ :l+i 6JĮ^SmJ҂i-^u$ g; DR qc7?$#¸_5z-0rQ Q^QXre꛰,ȿgak5qU':T*ƚ5>MNXC ;&qQX(ArN)Er@rpfsނ# XF*âbls R$kgkU穢?q3vVtJY7<6s9y9pfh'DLK \" :H!* ,R!B]7sSؓt_H^y ?>D:uYyv+ۗ7MHm~X|KL0uWYd#%M'=}Hs\1ᖤ'F@x `u'xrΜ [)_. ŋ4A ۣ[z]ų`-nd6.bzc=tX& B[玄Zhqct3s0kroJqs=hqtvE!Mz{tϴ#~NQvT+2I-:~,үUBFC$1M6yXc(o޽ g-=:,RP[ݐyD<)&3 I+G.fcj *AB/.312;~ՖбXgM%ܲ/aS#]g'MoUVCwC{Sgm߯ox3 Cp n\'sl.]4L.5&|ɡFNba,Qb@9m!$URKt~G׈ua,QϢ8 {}Qjxr7*>Wpx<2k*sp)W|<]+uѵè.ɖ zрFq#nJcEfpiR\k T hAM}NZw։Ü:KPRJ%W9Xb%|QCs)QUr,j[Yq;%dA*-Y<d;Gυ5F2T}<5L G&=.5j7F')n<&12"ʴ.Ǜv0DFYg`TjΜ“m2n.o WA wY!:B TkS_m >bV=z%mC`Ȁk#\c\N\jVƅ4}]+3u?ﶊs5UW%D+v΋ӳ.Cb ydT]|dD5:epA&tˎ#ͬ}muHhJSS7P=#X6ۇp5&y(>mJs\~D1_LlPWαH1b=2G'# &ӳZ˔~7xxh@nT*l^ՑA>Ǟ.KR\Vԓ{x w!Zt\ Il NV@ZKѫ΋dW7!cm,7Nq