pki-ca-10.5.18-12.el7_9> H HtxHF`P ?*}}Cjo޻} ^ iair|Y2ڼ>-t8922178eabd36a7865647b450f2242726476e668OjL%&^}F`P ?*}}ҋj׌s A=Md# F}bP7aK&>8h?Xd   E         $ B H Pii i i <i p%i rixPi]iji08 \  (A8H 9p : G$iHiIliXY\i]i^ubd\eafdlftiu$iv w ixǰiTCpki-ca10.5.1812.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.`P/sl7.fnal.gov%&,Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=msL+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~-d>Ed,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤`P^2`P`P]`P]`P`P]`P]^2^2^2^2`P^2^2`P`P^2^2^2^2^2^2^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P]^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P]`P]^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P`P^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2`P`P`P^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P^2^2^2`P]^2`P]`P]`P]^2^2`P]^2^2^2`P]`P]`P]`P]`P]`P]`P]`P]`P]^2^2`Pc^2`P]^2^2^2^2^2^2^2`Pc^2^2`P]^2^2^2^2^2^2^2`P]^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P^2^2^2^2^2`P]^2^2^2^2^2^2^2`P]^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P]^2^2^2^2`P]^2^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ef1d1a14e507e74adf0bd100525c45eff61ecce2468a24a900a3fb1800526b15b8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-12.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-12.el7_93.0.4-14.6.0-14.0-15.2-14.11.3`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-12.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL*GBC̬\?W6''ߦ1c">ӫyj@Y'./5u6fq;ۡ͝X]fAZw 8H9o%O@g1#NEy) JĤ+2*P I5pn.u0Xl\-kЕ5 N),+qXAr vrPך'C@V4>L;d˸L <}g ffX]1 K- gqjMuݎ!b.|yRr/mZ 7`ƈG$r>tbRV{ 9=e6YH׭dqG.si%7$fS*~.2_?2<~EŠ$ѷ/}=LiM1u7k;'}t'iB1B׳r4,䷸" vDxOٴa&g]4M$$cru:*4@햟5oJzsb0 Lz[~#9U=+x26SW,(?5nGPSO8&aKG}yӢ<|LBx[MXt@i6 G,K&-Dfv=j\Mi4EY`e P =:QI@+0Տٶ3\SP|D2 : nuA 5BU @W vìy]+Gs:v\ CZ-c2+@"$>o?aJ<4TAoC٥lL4hp8/OfKX#\>$ .3v:v䷭7P[,_p=*OP";?P|x85CVYfWjŐQ*Z5a ||6iQQ1Wǿ^ j2@ F.>+$Xz֎'Vo^J >.r1Y >ϤJ #.y x31{ F9DW닧x_ϭsZ=mB%8ǎz&z7-.;8CFi7hJ8ȟ񘿼GC=q~0d1BP4R&CRڂ[էR$noS,7˲c 57k20WҖ#- [wh{.*p_f.qPLZqZ\ qER*F0GC;Kkܭ1iAL5l#ˉywg5ò =x]>y&e< ^*0􈋅PyrT~ؔ&Ť_#Pv-Ȣ|(_KݼhČ,Y#i@Zl4:8ëO+ 939znY&!!XS#?t¾{ʇ x s޺Ed,>v0 3n$4qY7T)Ot~_ '0"lh1w@{NkPݎ̍omJŽm\g+bs(e5fp6:3VDC `ͤgp78ؘ~V"3X /8WX,& ;})[unpnw~}˛0scj~` 5<&IKg-)h?DOOSxb%Ě׈4W Itx x xs?/d6QYּ#q5.m7<Nif:7F( ٥z  eM5jp* #GI饍fRP0+?"QXlHǒ'W%̤$܌=b `CIl;8A-r/8Xu6-218ŵ)'GU[r)αbx9癄KE@% ~oxw _m-ǵY3x*׏aK )j%yսRKzݝO]r)na`iQ[¾ òiV`2)dpn͞OV_nW+HJM&~ˤ3Dޔ-bz0eNZ0 ׊. fR@$X4t Yho|rcB̸/BRGt;l椛GlkT xҊ]wT\$ޚ0 ^&)h2ߊ?-%P2P)wd3_R4'h\B2e2 &3QAͨyU/TEx!f2x+75>P_4G31pVLQ]?]nLZQC=Viw"/Ûs$SuX s=ɕ@'jŒ@ vS :5Eӊ jwz Q]՜J%zn0O},/#u[{FeMLMm[xp bC {2m o{^̶\^nqZ>:'#OLX,,6\ En4qbyō2MNtd0;uzCɎWUE[2z80L_leP!ʧkgnn]$Z <)c~ ݍLoj=S G-3+~x0ZൟϘħH 8&zl.|J(x"F &9hX`GZ&?bըTct@nRJٿ-!x7;7\:]>[L`~V`z3nmFv\P^ℷ }ɸiu r#Hʶt%[+uʄ <^L):3 Q0iɣI>.+J)ڥ [5@\):DӘΡ |lo{{ UIZCD~y\"k}] L a\hfU .eEѠ ^j(Ҟ%m5fr8[Q6s?4o1%~T~D;EpP .݇=>̜t)3ez0ꅌe0"g+R *k_ 8+^w+ݺg #ghz ,`w2$Ȁ;D0Zհ S2eIP6פ7gW 9JcvIg";n碁~ic:Paf!@O Y5X( Tn&1PRO wy5ډ{\;i"/$X .2r3 mEćRtCTVe~neJX8dj7P >Z,DNH4x֔=Jy3_%cO!_q+,+a5 "Ff}qXL^Qչ;&f:;nL1'a\V'?Ȧ+eϠlW3HkИR.#.Sbd`(-Pp^E UD6:: 1B:by?[~9Oa_hqXD՜1uLm:'uM&*W}Zc+}0`#N-fS7>{G@Hq?ŃI Er5|;]c'NĶBo!qA7`4nWMo\"mxnXrp7PA|i-A '&JèV5oί] YiQQ) Nd@yDIܷ;#өłeIgPAKh|̱4T;D]E:zsku1Cq6ceD(dkX!oA̯Tf}p GKzsZvij#ڃa_ Ӫ5ʢ\87~PxLjJI!gJ3^v0w7vv޴z[0m }\ڨ>_zA:5s0Wl~:%:,YolvxrTwsK3eL@N}U=wƾrsIOGF`d0oZJ <:R b+Q ꒱O@ﹸ9C\Xuozt'g2dWhʋ!?MA1Qy>e0M[͍z=-S["~ ^ .4Ibڹ{1,OD84) իA2II FtܮՁ,/;ua m!.؈.=>h*o`irO<_94 >##$ͯPQC3-A(o 5IIޯ(^8^Ub4OTBZ\>}V09CodF|-w6Jo%>X jJVMO,׌6Sƻƽ7:!669dI'G:Ie *Z‰ۓ M\=7O_r4#%J'y`e`79.\\z|#o\S *fp`<㗫 LRelV1ǬYxS6Ų`y9L̼_J_aei %J4 /qE3v\#֥بn:a*fKP(9#U*XW?A'K{Y-<ˉ`D\em"o:B#PWAԯJUYZ7[|}& (EنΩw TqZ0޸?$M$YN ˧ށKGa^f|J244c2_PgpBj"#m'I߼[f {SSMZًt2,gxϟ"=H!0>rp-`G/=!Z΃J6J3Ʌ ~b1o[pNl|aR{0 ]7i{1JƑօ1ǧO8{d7˘Otb| 0BL3VrqJTq*8H06{[96}ip9r{"̚/qt..I٧[2Xb}JӠĭZDJA?i[0(ޣ3҄j)=kXF.;T[}8J:]l0dlژٕrHk~Sk_GJXdȏs}J.*>Hv(0e99dv?V~1 N!# A\˗ h#=1ئQo%1خ˾H{D Uz^qlX`/^n{JLdX@`elX;x['L$?Zn2\7Ƥbvڢ!9B Ӌ(d{uEzr@_q0'_a'!&h;!Ԇ.tjkkK4?Ce`:p/Iok6J[2E%v c\@v527䇨 ~(<YWzBTp2_MNFÏ=0V9@n;g4y8&*~ )`˹L3SuKjA}h~_в4t4! #(Ek G![M&yd1#!["\-<ր;"X+Vz,^?G dSzQElj)Sk0rb8%ЂIvkhl!jzێfVΒMD1gZc1;t!Q>W59Xcj^Je8&˼i; Hg̯8=UL d<у|/ kTJu:60ɰ\Aw|q.wc$tғhҳw"2v QN1萘h!- %ȓ([D|/rnLEt!F<=2TkQ e'Тnә&V'tػ[RV!"X7+"eAMmd'jc5:8ҏe=a|#_P}vEXGDa &qf&dI5 dY**r#O^d#ַl \ªb. j|_SfvNEkYeTBKmӒ9Fqtf@EWGMǂb(8w6JҰ"bh$"@=q?Lϟyq~݃B<3ySHa1#:J>*T:шI17Dm/h nL8q-ɓ? =`@3[Ȧ;ZG vZF~P*AuL]HeNY3a'k}I܏'RCuUl/x `x{5=y6{VȝSjI.Z';k1 F¡Hi?ތ!v'U8tLn^%؋;~א=QݗhO`V?Ĩr`X&WmܑsR6HMSw `V%u.wwu{M ,* nQlzzHH4)UUB/[h6ӝX? /Fw!==5,b/e#jZS ?~ j?g3wv0t 5l5'`~ހD(0#Sy3#NahI >!/٭y?Kyٳ2ֈyJJ?<Ow(W:.wA?DN|@l;7/E`*-%o.@On"rRWC7tWW)jC&&*Wys;Nt VK;&RZ05?2j@5i`;4Q SP4*"-Q\ :RCo!X-o2f\ă9D^F/OR`,SeC,]'| (Յ>לžP;vGi>%yظ?e HP+vF$b !sY#nTDH,i۽;gKVb(^ce7dRJlj=" 0Dx8Дya L( IF@I5};B^]iiTj?sSK嫽\N\!2=?fn.y"eXʬ,*vܖ (`=T0$SBw)RlwU# 1Ǐ,spM-/_?""^ۛK&ˍXQ*RB25`QoC7թUEE{R$Z?*N1D l(.J1 _c 8\DUإ|4K SӔ{=fnoMʺXZZvǑ#a3jOQA8=60NIe17}_.'А% P\P" ͷl";#.jO6b B\KX}|Rc5 dE`Z朡*CO <́Fǝ]Pq^GI0{C v<bFҁnԈc?Ƞp% }*Ctip叮l ]r-{{|ډd $AF_0txQ) :e U!;!{ۉ]]x/I;[G0hɱ*3?dZh*G<&.$I%ԋy`%Rӱ7Y :ht-|dܤ-ELe"VШ=Ԃ5xk9[^pR ŗ3?tB>1%ebRc7 0&~vp,↎@?;?/p9x 7I|aVփvHݷ(uk|byL ^^ƛ39an[Regt83ό\AU^2Aa8^ʬk>p S(pl$uf|̴J+sb -*h؁xt*E(hᐻ^iYсXɱ?Z &mKv<(09vHTe#tN\ /QI-|rgݟjlj⼵6DkL5 Fxs'Cy*Lq\'&xfIX0fn(LE4#L`0~,,Fc<&Sm]9*'*a*`85 uoou5Onap.RJ"мɶXR΅Ǘ,k!G}:yP{bݠ׃T΍/%nG^_v$r[H6Fl9>>a|\E0;ʙ%F}% l~>CkvSIi80UB:C_\9&*W'Fd='? ;حH e_m̭ zT- ,(Q`u`9fr"5v$^ܽ#~J&Bk XtĆ~n$dtB,xRGYuc'( J#!-7ysu9y:"@%#n0XrLT -O{G/@ kpSPR>#3$᫊>eay˞+]g)dn݁Oq8odS4;CYMu=΋O A(F[wRO+-)H͢aE"e+ꮹvٓްݮmo*_-o惓0e@ͨFঙ9w1nG!43VlPg0Yr16~C#л pXSFOs _ TbD)츁ZɁ{cEذǀ*@Dσr U{~BִEaA \|k95JZ2 :n6O%QDdC_ЉA.΅+ęٻ8 #kj (c5ζAC?:γQoTđQGa ~Vԍh?hRUjߎ )4A,Y ص<@z[Jq^P)!!f p,0?'#x[lIp2U$AwfH%*ʡnrԶ*r13Vs3nJĝ9n7 !!fs`B D_s!sZ1eu  #&\p >jڃU\0EފV T޿Lj8Nm)ݧ9+szjW1#6KB5GFK+i:glIdiǫ&R=)XƶEgב:1 } pIuh9ϊ~bTڳ#DA:D+wm7^ǂ:>2 Tn^'n{R&&=,[גDi<(M :n2MbaۿD¸_mȝ Q e_$z::Hkk٫ݷyᶸ-䇇&EƨЬ&x D4%H7Zߒx.x1n OoR/N-_s㵰l$z0dA0Hoa-ʡAޑ.z @{396lnhUa++jt˽Wchw'RЙJBxizK-EO„!оOf W9\6^Z`(ؚmxRASvħ(bHʱ,H29Em"-&BqGv ]?:?a8wZۃC_L~DiH\U& GԂ"pR^Z`u "P t^>dYP9zη3'Q ()U-jPBf6du6gt{|h6ED.po%+[T,x '=Yҍ MuW1Re^a%r&hei}gw!5q`E6ߒMSDtelih̊VpNjO[.mYN?ҕd2K*a.[^aT^fe1XpAb=y ;K26KaAr{%`5{MřA,y]g?`D R0*߂HGS?YI}9|YKl8ZƂR&hCB8F3_ LPs뱎׈!t^]\ݓғ%Is823CD`r ;C>M 3[PYvwbj8JEf% Q|8ib9-_5Nf58]:J(jl8PF&cCUeџD3cAm=CD 0C9ݙ J/ bL{s4E 512?iW9& E?LpKPSh :폎ꬷC̖kb Wx%_}^o۫+.{]mzԫhu.pD*s@X[s?XW|Gӣt8 ~T)~~F&$]Ȑ~YݜfG@u0t[z ? 8mξ樰D㍬<=Tۖ#oG* ڹOvtbQ+A?/VjMs5VǧJnG1"b2?ӎa,&4BN_Zut˧yQe|"h,%qhY/鎌sm,ǂZWA'00#ЬedKѹ_y', '3. "lȖWTO@ QAnǡQE ~ ݈]JϩoNv/JALDwtV?p@?ñZ>3-kD>N#%|GVnuualĒZlgt:,-k[փtjKnH [Gpb)EB+-8wy\3 ެ~^oTw(ЪO!R;TÅsnuAr+ZqɎp U*+Tn&?;ćw=ӎV%y0ohx.k]l]7qҶN0 @g/ Uдc.U:zńtl@FѲoҔ{{,.M_=!J VxZ;:kߑrJ\}cBrd#2nF PIF;P͏A =^q>iRdqϾWTyj*"laECl/H5绷2>ɏuv4AEHx!ް=2Vef4H9۰;YZoʶ#5G 0+8ac I£iflp$(~3VMb 㯔~\.J?-VHt[B;Zڸ@2u U1b\b~> IꞾ!@vnuB_hD!+T~;&%A0:$͵/d:3@<ۃ-)CVk*6&-qy/lL~ɳjMZՋ= PLhK!Hs2yO";vޑZ"ȱ[#2 UJ=k2RFRJ/Zy%Y>!F/$]B*cϭ%22爻P2Ζ B4GyZMnC|2/4 penHTnvq3q js߲}xOI"R:9GCnϔ&a=s(uWٓ$WCnł!ajHVѨl^w{Li v0F i(xQx,{iq"Ş c͂ޤ\"\^giψ2c:ĨL[K5#xd<50cL6 "ֲ٠3塅 p KD~61ĨO%5 Ap6GGP?n+@Rp2@]tA(a= =yl#:trŘk~qҳS8|1tjc0rʺ%G~j*J v3aN8;U3 vX^mfW>_!!]m^ 3d`KN2N @"pE(WyT8шű KfmV):xպT\eI`}ͫXf&u嵢\fR̺Id_p]@4R!CT0vz%Tc}JA*(,^(8J\Ҋ/FP ~i슭e+?2}ϯ XׂlM%h=~=͘c!h 0ٴۚEZ*<.s˼/rKBHj6zJ4h#?'KSP:&6vfEį%y"*^ӫ}ыmC%\$' Mcn/+:uC`0Gk}^uHa/IO-kW2 f'v;2lCߑnIe˿#wܖ@J v+W6%9hbqihE8JEh6k:J|ʒΆ(ĉ}YgH5h!.37ף_kX&ZfԪz .mŋ'$객_k.C{`)uFaעص]ogNJ ~F|a[Z $N0Q|Vj(5 MK%xϨ \)>_ŨtN :48~@;ϩN@vjnot%vC )&6 xBrߍDT4z'H>{|ڵD8qQ+\}Ӡ/>1%B1M vb~A:H^yRHZb? ǴPw (,{zNgs;O5^T)`" \3'=1T{ `~kpZ @0T3fr`W'|Ñ^}cD[4lak,tYl&TZV Zm B&v@crKQ듷3.&&J`t<T LXt+udG3M&Kr OnC-`4-jҝaDaX=} &jIOgSsJx,%]o{H/#r)/:Cqh =Un^pEPgye9aU3^UQ8#\^q3;݉C!ư U!+%EW>' ǡi nat o()ÝG=)?R? O}Zt@lʥIǒʋ tf]UAjYdǹTlv' Q4^6g2%FުP]ik|f3dix, )%:Դs7/joO ?^]tDUeG o4Z+SG`ܹ@K^ ~~ޓ_w뾷yU94+Ano :mPȮl|4~/ʑ n|!16wGF);u=?o抢7{ 5In~ "õnP"D #M#p P~K+YL}>_c\9 pֶPhkO2u1G RD.6yJ4|0)d{>p #cl>YJ oWx־VڌRy`a0,&=Xfg~Qi+xwnN"3۶O"?gq*Hh.PmȆW%6;DC6Kz7{ŢRW +-bg^tR_dUoRf盹-7qqdEԸ Xf({\ B};O}J܆ i_&Ca9X@dM/a"8 cX ܸnXdl+s2P8;]"W~-S% 1"n]2 <3wwcmM|C]ݬL#ڼO6]%p"6Y3Oh${Ki15xA[ԏy aɢjPȐ|j e]Gv(g8޾~_#;K<ݟ_@4Ul?K^d 3S4&d4lBț@-_4xs " 7m,7пXIETpK"ɥ.NƉp6`}.MggF}#=ws0JvߠGgJ9ȍ"iQ≁0~p`i 8`e^/(xIΜ%LV8p4&*f_Jl m?JQ̱έ'%w tBu> ^4BWE`1]?Cb_h<omR]/_g=y"_Q+w3?6Dz 0QhHVO4_7``fm)Xw×w.uIb4ZgXR4~׏ByD]Q T#Z9X_e/PZ'5=;a3_QoLI_PDCbq"&ҬLWՒ lMzku P/-#-X7uo]5]V`#-flbِj;)nS:w,d8W֘ۨF] +Dv1Ɋ}o&7t&`ӏ# "'WQ(@بԘnHwχ5rKSUa-BTXhy:0vpkug'-{:`^ M}Sxs\MѾCcY\Z[*!2zK+'"دi%pϭLQHV2lrkF>v:BԄ ;8_e}@&| kPK3cnh3DJ B^nH IU/"/>y+\SSlJR$MxpxQ:sirV);ҷ)]m~~aL>Ƴnr/#9+k &N/GOajײʨϔؘ\كv_I[DZ-e'{[8_,&!Z4)~\tϡ606]|EQ" C8gcDo& 2v?d堛se!pVɶSU* ن:'=?J,UV7~TݱoGR@In5a۾øKd5YF̓M::#b@T3Uan=aA+FtoϲOxUC8  B Lf8;GƷ*_G^ ~"*vLN;.{3XynqDn~C< I)JPo'R?t}suC&">:_ŗCmi["҂L?J^B;"h5܄ Ru.me:k/與l~ʬ=tH=H0PwHp͡&JΩ_3|IsvoU~Ya9̰˓nr}&z!Mb;IUnnT`ipoC1TR)la5@/$ 8'ZFAb0qv"2^Y(g\gOҌxSBY9`)c%-Ғ1Nw̲c 4{uN9E}ܼj<0L%*l)x[liDRDEH,]:wdRFJpUV2GgMUbL)$tI^? )Grt @5A=h;ZylIgkn)vo(U})4swH8p_\35ql5ƌ(uZ"@77ΎYUr?!#lyj r-OV| TΘ/t#ʳ5f59Øw¹"`E=:pv`gĚoGM 礵}_4ez#.;(<?ksI҂uk5zZS" IdN TuvL x,@7:[kGBj`qmY-.iNgkXz(&zh[ ](oZ+G.90 |o;bPޡ,0ʾ(Q _s*@ϱ$EVGn|p"ԂzY FJFJ.#|6tЧ0 -UBC$k΍!g&C DO@4-rY |)6n p-ھo5Z1gϣc7vι2 ,JL].G]HS`d! M39wUOn3EC)a;2 /$3}%95TL{4X5nKo3^(}{KN08r#ox(ioxg%`/x_yyA<ZfVO۷OS}oҏа2ҳ*T~29u\!PH 7Zٺl d5YI#4*1:8,1-l>\4-}q ɟ huoWBtsZ3w­v/Ɉ]+7Mg4^Hl(D8?u:~>0 T*0m$ T*&C|ba_H C8*ql04/K(CI=kJdZ9i\A+|;fsi3ޖک6b+MW#CɭԵg.mskSLʛ* V_u֖()=+t\ff>[U؛J?{ffBhahf& 1^x m%(1[杨Ҭy4,M48x#D/BY8VuVjXC 437HZjVN)#WxfeJo45aXH&5#B08E$r\R#n3LUAif 6K 5tbAUYǡ=Y#Y]ciDh WnO<Ȝ]ٚwTe9uPtԝxq1im.i 2x7W VE LEˆX0 C{+oy gruВ#{5漢!Y'9Kl2 u<]Dxk flW>SJ_ PafR6@lk+z1D)lq?B~vDMj RȈzL(B<].0 Dv ٸ1 ɫ- @Svjǜ;ڰB|\&[75Dä"FV6GL?6cW(#7dx_gz! MY`kA #Z)cg J121RCy:[)~Ĉ먵9`'EJ#`tjgF~Db9uI#ށ#߭|/92$$}6Y+Iۑ!I׮7+'-4S"w2'a5*PpUNLeJ(]J.ۛ m1$ ϖe+{hAX[FDYoI@,{򷟯nֹ2_ wx%vܠ<`Mu0&l~?#Izkn/k!og~,%)?bڡ+FWE_5^wjS`M?A(Lfa|M|>iUͽң+bB1TC#4$sE.Z!:Xw(syG+an#Ã˶jQ|E6A2֨<`?*8 N'U ÃDi9qң>(~*,1kcپ6loN}S^Ъ`Uzw]bkͶ&y943Pɍ7fMkICs f`CMʘyAADN{7hU-P8Tʩq㦘^[,֒#gs)ⓩ>3e.ײmQ/Q*AW"Sw\AGKob߹L+;"X#Qopw@Hc':"%ydqg)צfX:sJq7B&di)BoeW/QE8w%!%!XRXfL *>=Bz"˞z5ji>2JA=3IW13Z0xN#j:nFЊLUPJ)siT`4>f8]ݍLOq7l4T|\c6V[lV7ob1IoR"xa¹`x~HUJрhA*uؕ|N0'Gp Twɢ2LqiCBq\(Eeq\mBz7 r2vMs K2f*rn2koY6w>"fM( ‘o`eTv3 @(Myι琈n(DS|*%jŲv @ĄeQN5+-j;@m)n R%9Z]Yx^'tDNbo&Sm+]]*](ǩ ڀ5{~=0F*#,AVZoKYYS}j=&u(tqaDVh-Mݥt]p[@6d^< g׫'S[d`ۚDUbϺx+wWЎK5uy/g_>\.[EV$P3>v9) 9lGTur{#8S#Bb?BPieAgo%h$8ob"'Fᴃ죯lgS+ ?`2GmVd.UM*tK:Tshe|.t8wUau\,-.Tg$=x.јjhRw o;]O8(f=kߞMPXv>i_ rQwm}N&^%wV#nFيsa¸9!sdkߐKiKXы8`I("6uMӣ9[rY•s4c}^Zy-lhg<\G&S<2R(y)9`Uތo|_)%OoJg@ȯci"Sȋ9L'ض/ K%fVr!bPuo+eĩ #Ib$C/*䩃])i+ݟrNbܚOMf10{퓕s%4cBiʀ7Y&@4d*1^F@i3[Tޕt>,6V<=쬞i l ݘS vD5tgٙd͍B#;z%2M hfȇ%9E}&Љqk~>K@ ǡbn"3FrM7k'E&ƄG=.J/C)u Sb¶eR T͹{NQ"Rb59$a"njs+ߓh`r(3JR'~^|yޞlލ6 P ZM8\}LI~r[[F]uh!uL#I=n,*0b)j5}o؎n5^=Q4xNDiJlT#5 q 1H<Q@Ld)S{y/ 7aRNL໔;V<Qi0@4n"y~ ܦ.Sb8D͵'1bS}"-çp)g8C}7&ևz0uׯwDBFkm,,T*jOS) ,ZP3_GIkA3Aez6T~XSrw/nȘ7j.2Yz; R6\hc}vTܔvhK{tzj/{SAK<'~..Na ٕ|K7ټG6 Evxh{5򚿎nz_b\fQrk)_ %c^e|䙖R$oui\$bPU@5cr=?X X+.gy|Hʡz]>1X"z]1>a;7ZCIVG⋙>h<ФΞǫ}/Se#E`0z=L=J$ž^1ZK\r5= UW ao-j!d !p^Ow&#m@gԢ#\!7~z| .|-k>ζ++_,N`3YClږ&iGD%xł9GMaCH7bN{9?1jO0'it)mvG ^-exGE*rھlHjEvG,< "kHt3}̭go#䖹…6RhjoIMAFe hatm:2#@*d~! N5X4.,!Xay<|}ecA\eL%[7567 Әd54 $k_z3_Rjꗊgdϥ[| Om+>P6RlYDžC-#YRq))tv@OG˨"d@v䇴mn+Bq2f\/}lTlY EqAlY Ɂo4n@DiA9Å`n[H۽TMewl 5"Ese:[.@QR/d[hn:ogafE@m%>hPW ,&!UbgP({hN *2|EMauD;Z뚫fJ~qM9 YD|c8E9h[lF;(*:̜RbY)-ylۦFѝg8v eQ^fƜp^ʹ V 1'z3RdR Yi*7[LoXu5%{ڊk4KQ~;[_]Lr R’0]aj4xYWƻ>K䎰DQ^>ӥHysxֱh*] M>H+ @LauCoK.m=09@nr[?I٩!&]Y˸p FwCszI~j7 (z<]VM7Kڇ]|u4X)wJ"ӫ9#Kꓘ~B2X4He+/@J+qVnƿWwS.u:(P߁!De#xÝ)mGZ"L#k? @5K<%ql @pXkinqj'uHXшwo1@^:ĩD3 1UĐ(+w4@cw8)DM?<'|2$ :%|sT0FybߌKW*u] 9?&"rv\E'rCحϡow*3b],Zt עhv&6xfnKg\3WUv;k{ ye}Ûe1[̂2|"Z?҉EUqE=׳bM^ ZKm@]b[w6D%I](Е o$"n-+`7o(78.Z0 n&Adr\X~l"\&BDT] H)NR4s0gպ+E5ϭTbꢂE6wJ##.WGǢ@b)H9.dh5 T .s C;9DZL1/n!]&BA^"gXQ2:Š;=yWL9~y}{X4"{%3hcia}s17C~|2:[]ͅㆧϻ1*5b(|N]V^?%0=$AHp ~w-Ŝ.0u~ |3:`(] ,im9GXkqT^H"t|P4Ԝa& `#B ZKA:'b9^%x5^ۂW ,^HD&Ӎ(2v z\}S^>IpKtuV F X3cIZ4J߹ x$qܖz#YV)y`e,LKmFW U%YSMY}GulRD?3"<(< PҊqq@1? 6xuoWB+~J4/dn]\Z=n`׮_xkj(1kiㄉLMQn%4|݊U{\t! F4ʫ@مk5hxIM gRbnI%!>ð I ӏG"D=_ TW՝K;0oȉm 5ߨDK嫸TT>1d`mV \roQN5UܳɆ/2e4FZLZ?'5EqM>r,Q=^[&֔jcDK p9!'=ʾ#5F07yT#0bq22}hDu`ĸC9i .}uCWG29 _3^O Zd_aGM3!JVr-]s~%(j7,[RM:T]4FE'?aĩܠz9C "}b:d0qQ/:(%tb4)(y8vbZV ԠGvŭ!FR8~ޯ񣈖5?ujM@-U>xeosEI֝ۢ s6Oת,F5;;cREmcc=PWQ]"wLJuz3ϲ}[hP")1m+KN܆PD;|bgTj)x?M-a3Q!*ߗl|6}c`P|o ? %+*prg6!rqEO$88 h_ש2e~!z{X]vx MlC+~!z? Uޱ70FdDwTHʉU2cwKRG$1*GD8G@$*b/SaܧFMT`/Rۧޛ/,[>Tk~[Iw|Ϧn-X)|EΜR< Gf_iop@Қͮ)(9zV2U_6sRC8n]K^p7MWy|D}(mמnōz#tz*YXdc@:0]6f `,D1`ތQJ%UI&NB?c)f_ʢObs\.B tu- h]`x2ɏQD3в)#{3 >v{.ʞ,;}i9qÚRoOu8h Su|LZy1j%:\`VW|MM%Ô!\rz;wMqtChePbu4)jٙEzE͡[XvEI fW"ӂrl n)ex/R{Hfۡ03/i [U1{Ctb H[ T:˜n||M8Z,?}Q8l~ ГX*KAA,#zW齍JJzr|Ԟ 7zH6K#{F|Rb erkNx 4mw '[Gat5^&Mq,iXm: Vn_~P*vpgH`~W$k)yE1=tjs3BE6F2|`=ʫ_н)ȊQʡ|U#=Bqj#*2dֱ"y{. ֔'DQdA䭖}CWфZ} &WU#C4O2=p#ScO;%bwWpC\S[J*M N$8m$pdRJss{E^{Ǖ/bp6j勛,\yV`{H1T" Won1ƧtmIFh& fƧC%G¾Nj@KRFDTK3^( %해y3Ul j/,M1'P "TcLD/+(*,/ bG>?!n ޭ nddgX,(٧=Zwi׏2[+[5.k #3 @C`dޣ'`х"^  r|`OpRبfGWYr:63JvPf&(||ްv'|эEyxEhT)f~[8pL6K<@/X;Oc |{Lեj 'д%Pɫž ϚA/0?+iucL=#eO73)t>|X{zUP0!0RIEgsфjD|@nm[}01)FgS)f"O\ <3cLR+t!֌ owH].K[ċ M25#~`nhakG#vH7)ZGSJh~w@~c}4bE^kazlv׃mQbɴmү-tT[oJzAF+:կDzgRlo)B+QN*BbK'G (J"'$9-"IÕyg21[Y{S7 PnWWsgo^J_@.-l-Mbּ3 r fe +W&n)k;IM2nPAF"GQ*nG$SH};ġ>*N'_m^D!*q71rLi`| nˊy 8tTaM?wUl0MBTEVHaTY#g&q,y]|WleT'7Oيv? M[wǺQ ؤv-ŪMP!Hy)J" GVG~<9f1 3&U(Ә;g$<6mix]?RJ8.L3P6^K(q 7g]4 :=-EĽ>sCUc,<dh6~7H(`igjgћm^}E v*V w/ژB0 K(ΐ&ʬ#!(/ GvCWfդNZ!S/[ Zr6 BQnҌt5q,ϣMtV9}К,oi<\+);՝ s'0%%zP[˕jTu0- ?})Y\:w4PB,KJ O3wUt!"lޑU0uN,4's㦱BcEpUt9I$yeD(ۺ)ET;zU=i;ť3Q*DzHcd2eM;hm E`Q|E7Nigz!;MQV~c&/Vqq]"<67 槊ttqcu? 9-6v]:A Sj§;.]C Qpyn=KV=>jxYϽPMj %(Fms+BJ^w_#_3K$V(T{H˦vNgj (4dliMWxl)/hM N#[-J62Έy,cJr~bԞd cu\wD*=,2ٿ dn3F(!9Jv^!H)?u :k1Z0oo⡗ħ!)KL:Z/f*=lݛ幁3PekԓdBT7/J41  N"VR Js.2j>矪/\b,Q0XxzȈQo]U#[[b7J09F$ԡC+\tEEYjyThߦ}8Z $fu!ː׉3l]ɘ6"O`ɩ?nUj3˕nŽYC-YƢ /͞kAobഠl<ڢ-F}lΤ qbM<@~M׶ެs)ޣdODe$5)WY=9AknD̨F JCIh+"uYU'5$:Yx:>sQhOߋ,z iqtrޭ.T4h@Z6 Wy]IB xQ6O.`ˑ$6*S$mR*^'[ѩON42~z8H;eQ6SE8 i>Lߢ\eUmC.Gp;@˯\"t1PRǝ@3QVp{MeF省y6[ FPbo ;>'$8Uқ Y]?lgN³5,?!;+t(POEl'e2`J?Q& xnފ|Ɗqg(bT&[W nM8b]h)$KW1٫!|QHv@뢈 kݝ΀3.io|+_CQYnYxyZKiD/2%S[2NA{Nl[?S:\ޝA9TqXd ϰ]{KI5z20W5 d *Xao;@̈́GJP:/ǰ]=m3ffP{pMV8)uE[ s; J(=yW=Q ]YhOO{ 5pS\!Q]1jeEKV0۠5jfXqY>/DDPyn{3 S?l4}K_{DY]?B赵@d-/S_-D%`^ %'CRVvu宏)q*iMײ`ߥlaOrشr/EPOPn:_Z4V#J_U.6u* KM%i0elr6 *<0S?aO'}x|SdgWKQu|n(WFr n:|Z|#r=y%;uD=TjlgY̠hI&Zڌ6n$/XCS{+ckNS ǟ#ہע5S@s%'KC.|1zŖya Λ~}%G"npЎANLA^tD>to/r{g#x{Ers i/Nw#2,;O96T86;I.7h OU(E>]eU`!sZ p(B-@d" 8ءQ&~ x#!ǟ3ޥ>L%md""[E?.3x FRNnNYnYLvxAlU1!%}0y!Cm%d$Aqvgr[@ Vjԗ!V;ӯ#+K*dRzUNI 2 mi>C>dɂp^%c>4.exA-=TZkP)72\!@h;hļ'TӠ ŗ/4cUM:&RA}b.ei 8MN&:"ͪx:_Ş|ZSI~YVT/.Eⷎ«VYq(`?+5NְehrR/rϔ#r88 RNKΆyts:L!%ȠԠ浉;>NZIP@2n1-7b[H̞Xގ_~PG۹lҡ4uܬ>ah4_TK`K8FՈ˷F.ad#.[h}i~'TFw# cZ^m&МDĮ7Ԡ&e 4Lz@fzX˻-6uyՌ ^E`YX5 9}Pc;E :/lw XqCh !}̦sJnc;L h@ VJx{MT܏A6a|ɪaiNKiE_8%IrW!|^#u8R59K͑NE'>u; ?DB -*47fd1Y2CDJ<1mL5-s.ʁK_hnbf;n-ϗǦ:ͺVG8,yFq UyTTu-oZG&{v}Nuk#sD_5$&Y /}=3ԴjBia=>å`t~ S)"@5â N 6gd?d( yOtuxANLsh%eC9ռx. 'f#NhPON1Jfnc{N䞦ԑ}O a=K:.^gE9.(X@z`$psp8UXgSH6jU0uNq @Ԕ}0ْ!DHQ0m\2%v;dۑdM=^2^@;`"ѐXnMMme A eEyX(;w gZ9+FF[mW66^w+m t4˯n|ͷ\U{4>;N4lue P4A^oՓ˽+k%)Q=۷@$ѥ<N^?V."*$rHD𲹿 A~{yX A!vϦL'Mm{FrZ6 ݲ{zΪz GpE  rX CFbTO2U@CqFx&IBGyXgue8q:-OPÂ^)'3.qq%&T03d˺ oL 9b鬑փS{U d+:T^#OORJ]O P&D`~j|V34v1zpVsu'^RAi|][{P7sڂ5yL,$n1H`+,C=~vT;LЁ:kSgsD9[o8ƷSv+& vѮHN̆WQK'Rt՟~1TtHSm4'XPdݦA%U/_9+4iLc(sސ0r7bXA< Q4لr#` b&5_>.@hcp@0Ecb(go̎^d- s4R h˻["A.Sr[D¿wkw[z%^o󥓼.mz"FO_b1sIkט9K#7T5!x^B7ulGbݎA1aN4sȕwžpծ&rO^&^: a{R~wL c/OİTL32GiWMJzQjQ%4|w+΄z,Rw: n0$ 2n*e5ƽe?7._ w_r Ry$/}U _,)pPPgb`NS'=&+Λb5=mWY6c^3!QyAeV <ԖKoe)ԓ0toWi+Bzfe9."b2|t?xX>a)M\5U eBl.2@Y4vY]30K#{MhwN(u=53Ul1ɒxƣxK}gY]l1}e҉Cu!DGdm-<4Cs򺍓 2Y~1%QIĢqNGx*kP9G=:49ꔋ5 s_ #.I;)\/&q c@a Släo׺Z=}si'^_[}Rjt=r]Xv:;{H>?~}ff@S4 D;aTXW鉨TUּ2iRX_EhbnHB#?l|-%2oA,>z@XNwpY3N kSүZ k(M;D*8YJD?SI5iǽs%*Xڸ_ ܋ T=/ vX.ɓs*u ktX{ ):8-i RphY(9{Ǝ^RsقZhBӋ鶬 >d.X:y;^h`nsB FKWسEqYj;CdS}X 0Qly2L3޲< H// h/]eE4 BYPZ+ ٦ڼ8b2L4%#fG__(.P:]T5]Xg̥$uPu2%.ueG݋i#3QS-40G\>1H⌉),t;dkKB0|D=pܵH/f {hh ڭޘ<+ܳ! gi̦绋V`KN/͐ _K0kR;2z\2M ҵo-ӸR}̃8ϳɎղq2qYsN&NO!(Mh@ zIzYp(nD|Ê}8+|tYde/6TD8,t2ʉ4-HWF˙ce|U|][SWv/JCNؓ녻ۧN4>^x7CX-g9F7azf~+G% S?>s aLKʘSy0jYk9+C-೗D[<C{Yyp>Ʉ|$"(b[ԅDx IF3"OOS^RM=-FԘP:bSeMr'CCZڮ{N_ϦTW kCch <[|چ9 ꫀF&L -JgSj9ρ׷te|lk52<9'Nr*YXW2r6ݡE~r~ţG0%GclY9Do$IY+?89%;Drr!A2K(OO{>DqxOI L( @ɀĜfm>UeE+n% kh~4w/śFe=>˥vR>_yOQxl̩Ez3,ALUH!#dx|HqK,xc:X1hKNym p.2~15|@LOU6 $df ٹ44Tn{>>|F-s/{ j^~%fRDԨPotMtdķw er~3 KyaʾtKfWN c_mYƸeg-RYKm}뢖wcW[[eY[Q_'Qu~G9{"\ ϭ/?T2;\#ߙ|e rWG5S=UNf:)2ħ ]V܌sк [k=Ǟ3^*#q>)hefE 7&]}]D{O?VϓT~'h1U[K?Br +"1v!>FMm$k 9| m7Ϟ$I@ΝH6 ܋*m8WyK>3{Sw6FS}JaFDU$2dt#~ + 8sN΍78-hPuXHY'ByytL"클FJJSL]]V+@3Bc%,B/~1mx@C/U,(#i0a=' w$eZœ{B1B%r}K?=Xh\&G먁<YWw؅:")B4 1ñ ߩJ?u,r{МeVl=uv PwQ ̥EV``6{~zLL8Cڴ1v&׋iHEDu!3 eJ]9dNU bIϾ@yG 9W]A(u-F-B&椦4-mmqUT) (ON1|[GDlmX㢾#ŷsaT&O-" k$2׼=3 %a'jti BM0_豁/\} ?;dX(Y̨Gm}ɜs ɟu  ak_ZJ-^ ӅZ(.2MU Z}=z6<0"K͘w~;4_$pz"R [K+*7SZN| $v,ygc0\ ,ʕ{@G]@(!Xkݖ*]`"P6:`a`zΪBjAxF WgigS43cS\a>"U]V%nanO·32#@5;-FCz&PC;DߠP$Ҏ|B`.qKkfV%T\tjueumGjj?2'DH [by2TEzdD3s&lgD'yԉ()h#D_^<g^)\וDO+i10]4mqx-uzڽr72 JkWn&3܏c{+uYf~m5l߷O&="o@ USI&{75]I=2Ex2 *||?Z(F-QRKu9@U# ֆz3̳? A(4hUF4`B{:[oSM"?Y+&=D`dlA+jzrq2dE#j#9xɣ<̊#ԕ#5>Fq.0.$0~|$ }ٲ!لXKY-偲{F/YS_Z,MrQ^CBfdB> `fo]0рKTyGYtaR; .pysBF[&W^)L7Rfֽ2# ,%D\B'hqׇJbҍ Cſ }k.3Z -1$ABeDqiĩhC"ޗF 3&״KAnx'a@WK*Yl|6x<.=6'Zj9BCB*SeoaUHs2&ZG'W[6NN0\=$LMv"Z*a OW.vy[#,`qV06dl -Rpu)J2_A H{y.^go<dNRCbotla #Dlǰ5:vnd9S\ov5 #;MPgDa\g( Ao3>.7iNifXtQ`$g##(L==U6HJcmل5~U|l^ͫ˼ l߬MAs4Ub|*Y k?qKTIZOn f R?*N>g-z͝ Xaqs*gƆ0T%wF@҃AUN7|)O}Crq+Ɣ{J!,i3͛.Ef"etI0KOBħPF4JyTwfϫc"pw'1:([B B^ZPG /Lja@#':ǘ>NdM@-|q=L==5t˜WI4r6nz [6@ a)鶖P[,5Q%-}m` ǯm-|2r#q Fe~$J';p;S^Ը ^e&e0fW!s~ 2N鶟%Hӿ.;Xmu"gw3c4^%"s1,GS3Sx)b4k@ ip>ڨ4hwdo Y4J"5?8.I:4.hR+?+ԆX5fPZ~;Ǣ؉?ڏ(ToǞsź.pH;CgY79Vg>W_t SU?un$6@jA5$}UH"hK#dl=`1&ŧ?F%"ݳa&g @xX =?SeyDTPIҐ5e0]qjVZsN3y9F<wڽi3@7GWIbK$HzDax{TV\ٚXq?!}8;ЌA )A$|(c7g9O.. b˳xDTe奫wlVs/&}v,ܬ!u#xvyһ?lf5lꆙ]Sb"CeI_skd{;ڻWo!k/m65%i&1[I(6fX3җX+G>P-`,:yo7/!|<HOG_emY hK!7F} VuMI+9oSO6^ c"4L׹Ű?]1l*XuH0sqyF*,V%jℜhKsj1ojg{Hsj֐)cJciea@rNȢ\p"o>D|ucn WZ2B*]t.:0_PS \.HJ""믞&m~%jcVyJóC( mڌ6UN bŢ-{ݹ1<< Fg[0 e:Qlq^e6z4(!-%L{M꾆Mev)<@2Vwّ^8FP:ʨ_!#w07E+FFysj5YFw}aD]A5뇂Y4vEeȽ*~E-#f֗e3m7P''`Ǭ l3AH kt3XkL;¹*݁W pma.Vl]I\|iY>E:g2ˌjjӱ s~31f&=Sk nE%9$%á2}@$I_mK׶AQ+"90]\**R©FZy ճq" r%h t*gy^(t}i>jVf)Nng,jwvZ)xxWIś(kzg{uAv{2MqumIg<Ը 9KDLI20C]EWdsS^#ݘ105.%0S+IiQ>o$` %3eF'ݔ+(# V/uioc@ ܫ>oF֊ ЃCCe^$ WYʲ,tmW$>].#Qh\`=?wʼnOAm K/O&SqĊx$^l2C)I' 8nbGYK1!%C} )4z9Xqn`fP VQi%hMuB~{kG5(J Y<^Zh2.SXq7J64Տ/J|;>Rt{9א[NO?,ى"8,QG1kS78# Au4WO0r>i =I zpPoĘq B?^Mh*w7ދ= %P Qj HR۪T^RPhȘ+9ϝһP;R=(\/A9 4T {HgT(' (2q n%Q^lSdau3Id67Q~f~#X~0{ :Ɋ/ւ s^h:8 8r8oNp^W. s[wqJpЪ^%&T*@GE s;dVY#IKi{7FUs#`)uGjHc\/.hꉿPvO'!NL2i뜞~0AU09_|3ȾrIe-En;[4JW1vrO}{H !]⊥AhIpݞL1m@ZTgYaQgjo'G"V`]`0Hyj9ľd=ԄX1qOGg Xгss+R$\*`r@^}ʰV*JHwx~͘J[ƚ O¼ڙQ\\qu/ƛ &8GRn/e^r7,RA*QsPgbB:Z.vah[, aD{Swzjr(SƨԋbB==NlQQu #³춏"*: */c/$rz[a~>pj7Gw v6$Z`]*ɯNȳ99mvSs(G>׀;XHx|a1CA zsZN7O(-GİGwGG7ץvhkOâq{}n u\. ԵK qqXzD/Yf%puب~r5Voש69R@K*YS[E~ u2?ZI6[ }c˼ʨ( lW 6) N*Opz ͟l%gB/vɨ(EH唹v:/+iV ;|o8\so\UknHb'\īR蝔,dF`:x//ttl2Hs]h^H:o!1+Ɍ=T$ԌkZvgpH7tn1?t (Kqj~cB֖>bH$/AӾٷT,a > c|ͅr<8G4=3`oeY'E+5zQr +S d5} O5'Mi걣UpA +5Qc8M0|2–#NLqbU鱑2mEAn6=鰉9byȖՀ!7Ky.yɓN&w ƺ+NoRKo]Q[)kF`j8d7ʠnzE#vW_:TaTLaPYA5!#Rb޷ۜ_7FR(Xu՞ɀO{8*e$%޽ͭhhiA@mK{S ToJ7Z0葮g٧w=,c ¿dtDhXdeMtsٗL{$hUhˀ1I3C#Pe>3aja@Ni#FHe'uUk F,=aؙ<_=cIz\_^l%GW da ̕"A 'cE t>c<4oV q}6 ˟U2p` ٳHe*soW%5t2"dxh9Wno8 -&r׻yh)$W8^Ɔ3|Җ4T) SSqs[Mk6vC2$"2pVv$uq ŔC=SW]oҟK/-:E8~ٓX޳OVf1cJK@Ƥn+ A7oáHwr1B֞ q&G,=~5f'rNG' pfv>ܫ~փ`V&B/t. Kv2h"8~/A^v`H `CIR݌<@Y-JMӜ jrPMl-ow(2sE sAEԊ.ЫNmZw:2a(D/+VECࢧ\Eڊ&{E[kV̀Kbʹ8n)n񾱊 _`" U?-U* 21:TIx[~<߷T8PuWE_kx("TZKѠq؈%;q; BIag?"xzp >5Ƹc=hk$*?3%R?:q)_!v-4/*f &z5ꐶVF_29ڵ#Y|z+Uv!9~`4RZyкj>%JAC`L%vbm}iq:D*Ux^ [2\q׉p2/!ՅFqPt{F:B&$WD(9 lVѭ6Kl<%L}^B6D3-yږ{xbo!u! Qx}z0ɵuW+*φM5jN,P4:[TбZ" {Eg>gF1dBqsտQS`%̇6>o4)4%ASQR]OV禤*Bz؁ ȳYӪ6NfApI_ }P>X-Sp]><>yM]l>VE+ LI fYP"_p!vk^"=aM1bsd&(JX^̓CWޡ [5sE\/oDuRXk-;a?fAXЖG|RP+UkX(אioD1R09eDF* ^0!&mh$HpAluF[ |+N,S2?פ dfaZw3-UoiSd!b{[;$.NZkbnץP-1J͂T.8ku:d>tG;N/Q3 vsb,=<̰>2F&n/An 50 gqt]G)JGpBWJ FJfrh]eϻW'Endm??IѮ|6늰dGf!a*9Ң["YO::>9R?[8@!k){̷H>X_ǂT2"o̝os d&xKrδDRY^|+ c {ƣc?kftTC ?q B~_:3YprlBӒ}͇kxX3߷#.'h4+}2 r72*QDgnN$Q WiE}JS",>|Q]kM )jQCI|WmqV ^ %mA7\հmڟZl̯ǂR/aD}.3Cfa-r @F_B+ڂgŀp 󯜞%rby>n>َ uyRNw{08nM?3④>B7h)6e!7+ȲYMrE2щe zRMqpqJ+#{iρ0[dq+ GH-T~x{do Wn͠6P޳o`!*Tց{cbvBoc>yo z w3f#PἙX]n`Ս#ׄ_bҞ1Rkpkע)+\A ǵͭőӿ͉iSU 7׊݂՘ r(-#8!0bԦ PMP廳V BgFud*죱O]v%Jۀu %!Ln(͈IZd׬49g\ Y׬O@֛eT~{[pJp}jo,g@ghfFr渻iho7v,>|ݹ76?FoX~I%Im 'Ս#0R&&/Mt h9Jm0qn3Bڭy{Z=N&Fl)s5)7NS`aN톹uL#I?_|D <ѫjS؃pV#֡vצ_).52qn\YCB: aA7ޏT _ 6d٠)7AV ~\* =L^\] 0e 6]++Е4 LsAoJ-G+ŀV8:4&@;C6bom#D\ V9FAd%rF?!+n4Rc+Fv(8{}sCd5ՋI墌?+}S1Al:lβ  %.蛃}^eA '5ȿ Q1▘_WQms*W2.N`R0^KDc>C+'Ȭ6N"7[o y77)tQԠ]-IDAj/s!v}eFScO d\⻆{د#V^ح[6s4R4ZKK:lDFPOd{ $rBjW N|"5a6|YQM~"|FP`>V)*w,ʴϗwtǺRhıRu}b| 鰔lh̾P[p3kA6bE(r "|iU*j@WqTB=f'Ktn;zǼ|o2ޞ!)EK;>/E ^.7Z,7ʆpNԟ-Ud?|W0z.?g[88N;CQG/p?whܿXHqrfEJS:Fk~U,Dn*í^JvmP缄HF I̛$㈊ Ѥ9 ?yFsYG4Am^Xu"WUp͹_; q(%J4ᑁwtD DXoڿ n1FI"wԂ楏 B liIxrr׀T\$%5y*;]AI' nX`gѷ JV6D+%#%\aXdo^0ixwj7#sX\9RۄFz|M~i)5Y`pvgA6XW3n{"fRJ>й~^a ∞@5ՙb8FB3<RwBw_0Y+?:eBg~#"N,M6EA9rBF[d<Ŝٝ(Ptєz1>.+PcADK#刧1''[p 8z3Lx4Q~>>UЯ}r]6?@Var@؟KNXOd >IJJ6e=3Db8r"u#C8vi dA߳U#;+L>BpbazeJDcvKҘY-Fj+gsEQ2"!B<$,HsY 8 }5bÄ mZ6?RVE꧆ְ&HB&<óFIe*s:*s* ,p1Uf[ϔ3:^)˪]QlқJĩ)PǖUӃ@u@sUjJtĿ$l !زGzq3ז M=r.}#]\L~  I…hfql/s{ub̬|J\-i[[W=f _r1 opIkey,E(hp7נf*ٜ3I/} jC鎂@'> aG{h5U̪MVҐAmێhi0< xࡾTFndK)uPX2ǤV E%-d`ȋf: R3B _?P3/T@^[" @?_wDF[xT噢mǸ "NQ*G.Qid>'*ǃ< :^[|Sb< xLfrVWAN qyhPSzn< "on9}6jf]u7}OojJ!x$q,ተ.}Cw p̍4^iP&A`yDՉ\2*J R Tw~.Yр0~K3}#G7{&DUa횦O8v֫5Q^}"ˏ{?idcV.#}pEM1 ;g|2j]Ci7v(ilgpi>ZIOXOkleX)|fMP8ckY<6M@ ^̍ mc*9A.@ܔˤ&akvz1;Fp-tX7t&4WwYV$E";B߻uB?aVF#L&8qJrfOЇ?lRǑkp&DR$xA t rP1JEP pliM܅FDhdns 7D {cf2J:q0SgM΀KIC}@bTa?B(ƣdݎZ˸8G~zn zpHxᶇ.b#}ac3|~i1@z9'㠷K z|'\놰OUn*6IytT@ڍƑ{c.F|%$2O} hpϵdi}X<(tg;j]g֎KXMt ѦD6O:9/GSDm2M'!p+\^|z="Gc:׆5 Ngϝg֐C(5?N/ eFc=!^Ud<*c,1X(P]Z\}<8\~m2% $c[au7ėTO.v gʧg;&*KO;y'䰘?pht"n^栊g {GX]:2۬H]G4 ~Yɥ>q#B 4k+\vN}g̊tSml$EݺyJ|=߆4രݜR~&XQٍw}36A"Q:Ԃ#dn+-h= 4$ZxHe)roNNT56^hD"pX<0-, ld}.4<|lf_I mvMCmįHDZGBACXedRMgwff#l:6K1AS]PFfP5#M7bnƝŲEMֹ|NT,ңo~ױk !!sETig_^r#Inײ\&fwݜb >QJ1lE͗R">I=R{Dyf7u*C3!xN\缘$`罭Z22+]Σ]9`QSWdt>:@:_|Ne'uL~=x*SC1a;̛"ШeO,H9>bwGoJMK;g:Im&&ܚv( 9o)T5E- uui7dFdʢN`sp_ O?\Ş)10 \ۗhߡ:~T[Eo=?' )Ukp| ,~!l4þ2b9EX:|8Kvwnn\U%lMq'#Fow׌S%]c8JK$b71/dKgCW *e@a$ST]%Mǵjq-*8L1DRs3, |_ղmsgVfre]S[2G<3 Gqmt,4uF.Y߾cjZDK 5BI<Ȇܣ~LhAEj'MF"!T̪Us>9A,Zak繋ή5P?bK<YB쑈Au|! JhDg~3)ٯ #IfR=ݙ6]Ȧ* $w~'I`N]GA ^<.?&"KAo6>IgɒrSJ쨌!'2 "C6)xvD3s+8 wt(/E #,Y z-gorGCm/τE,jQTRHʔuA8u a񊾸O*߃@(Hb;3ez3˴b@AO^ # okWcUҨݘr\WՔZ`!a krV] ?+݅n\m[2'0\iկYlC/g$_>d3nEF .>#ϱ:aލ2<ѣz-(;mu)4q;,J̎sVbSDcSo ls2ssHEM䝁rnw0pQ> כkMgsd OޯRWdR . NIude>"jvN͝jc$!h}/)af=#dHeYvI:m[a諳s"Tnutpsfֆu:W|oQn?bWU]Y,6PSbqnBȝncGne4KƷ1͒qbX+ df/7٠jqmxdNo3O(SF!Td< ȺVē@[cE$rs&|E2xmQ"?!1h~ZǢ$ki7Z>8)H\A*(5(7aK\#1! >iq,Xb.)7Hz8\^3f`T-ŶP8m>ߵ8_QVW7} za{:$N.#*8ԏ7] Y9yxl %Р}J#zTpſ<o.3RIU&g)lH>V#"{Qj[v3!{]eqiܘiC]WEjI0) fJ:Va bv06MgT"ć2hn3S?Wng#*jPsK"Y Ś9 -,kZ4ݲAA<.}æILN.}ӡ1P4{C!J*]zF9|ċiPX'dAIT5)֫2C)NmQe2*DN 1?,'Αu]ÔYx88PA)"O^lֿV@3|}$vA&(US Y:&'y& L鳉,S[Y5ϯxy,-"{]=;;* 0aYY'!,/\ íhv>ni^#֓O^F(7Ʌ$ %Hy_nߝb%ZVadWvs4 Rge}5 CEU ?3xPUqG0A s']TęG.W3D<{:w@:z3ai{>5WEkD:;_EM0&LpóKbvASw "gH>\|N=&zG1FW,P^NFu/pWMљL4%/|#B\&18E|-!2/Q5:{a}8VA֍QIsԭ;#H.IIbӅ!X鵇ȗ^lO7bl~|4$õ4c#'qMq諲v w6':ʋwfŝeI-N{8[╪~ h)eɎXܣg2. -2.  NN[>^!8>*-2|1>h9ڗ-ޭQ_*E/lwOS,iP˓P ØEbu9:AZʑ:k$$a0LcrI˧RXMV [/:qc_9Y &]_S#r"|`}X J#풭K[EkOٖ`X:(!6!3jݶAv#V <,X'rөO~޷o n f'[?7FE"vuFLoa_Kb2G.V)3Qhn ye\D89 : x}6 #wވi{'PDuBį氙LHAG{#zC~qNA6 -.>?vM\u7F s^cضqe'O+&ʘa.}QU_-W-o$YՍZ4<[3f!mtu?LDG6rjVUE-E|'^;ƂFSYA.IvcY8xbNJEl0צn+Dq羌uxT:0H5z\ mCϘ,ľ+Y֕~;ӈ fy!YvLy e0f?K.{:.Z`uk$pPυO/'ۄVDϠpa}j$~"efzv," yf ؆Rs,Y$m?2 ;ٚD ::}@=`sbG&Q8N{)1XtE$0do_eF_RP6H.r󚩍y,9t@TtnN )f\Tp]BZ^26.Wfakyx\HxM.́4nm ~|h:A'5_&PkKMZVLRe-e҅ʔp<A8(<VKX7O0Iҟe~e: m,{GJy4ZB$g3詇~| 9m$Ug!b/X `q2憵SFA#ϓsUҝ8fLj,/bF.a$H+J/xKp2|9ŗ~Խt.h/w:PUnVM+ ?*/j'4 5u]L*xz+\aTd"%Q: Hm]BvxW]uA갆Bt\3kG@Zgn- ɍ%(-7Ĥ[ں{}ne1\%az{/&vTcwaXsN <@'Y]^DczfpvS;* _c%ı+\2[%E3G>)%-qg$ɐ(S1vȃ&yz8Dgd[u"IKa~uQ{cM MM- u !ȋ"r'K@l#bbϨ#Ҷ8<3C= 7cN\^;rD~#8W!-Qې~ ^^&>-ugZwؾin8WXLo-z,r^F[~#%IK wC?э62ݗJ/$7|` Jpbʣb/qjkz`لl= ҩ?-VY,ֵs1y؍;$jӓ3S޲rg#( %Kȴ5x:nq䬗2,^4Q؟jcܦ7g&26BGgbzK#k\?;kLgd[/d<=JJI wѵ+c8Yvi\HR'q+N}$$(&TBf_笫Rԝ TnjVےROA0sD@|400m+w"=8UlV$Ձ[5e['ϫa]Y!d1DV n:t( g|9-6XWFGe{OGVR,`\m!A39Rh`Nrw o/\+0xk&(Y:+VH!E pc\O1.7Q1O6OlݭЋ r]m y;cMM; _%lVtuwsdxjSr#(rࢵ毡ƕz 'F:J&9|]708 I%CIxQ!2!E3/0(O~?R!BW4},}׋TJ7OpLI]m6tDd?p}ڬ0|EWF𪿞Cx`ы4wB,0|CZ44 n57afiw{*L-QStSVxzLHLFor1CN$Tz};u`engsG1rVe"ō龜 Q"M(!⁧(G9Pf܀Q3*laVkS`;!A L{HWPb>Mu⯤冟P@4|wlwZVR%dl֬@]c3d`Jx~hwӐjBKl_EsVBam)FYaO*  %PtP"LN#"gzÐgX.7snn)s,:hZ&:RA8HJ5x%w?9ˏN*,;%o$LQaWn04Y Bdn(=̉Iq/ $b#nԼ6*Pr@ߤ)o1 ܕyK%i4ɦ[&e\ASRDkR dܱ;zVM놟(S7;mഏEpva\9 a|$e̛~t%Vc\bULWǥ@9H6Ƣ]rrPhiE.t1} 盙Zq:'N Loo FE"[XV!G;ϲ%v-Jƍ 2s4=YZ :zE⻖e5}ȊYJŷ̡c$+ 50԰172D ߏMβmq˴>p: p[Kk`7eɤtP_}aQP/VۢdmzD|e&9Xh]ӳ m캚u8+8@" b>^?kQ p#1 }yļ15rusIM@YV&i-xѩ嚻*AQ𾹲ף+k$GVTة]$`\RoQ}$+:e!5@@S{ɿ w^~/| l\%xz~L% lIͦ8qEc}ɷq2"E_;ۄ?{tqy:rK7DnߴN:Ö߹40`/E;eŰ]o+8)cĢkB)=ćg2Cy(:/XH?0ɏXJp A8>/ \T$pjؠn&BzA`NZZ;C[ {Z{/m{;aY8E# +e%hT[8r#]ݱyKv__.ˣ3H#}_ ojr"r.Rp'Z0TA3ut9FgԇO/ۇ-mZ"Y_M,ERj\ih,u)xKSwn[aEeȑk xꌔjwne7RM0mls ܌B 1kdR⬬euJnxQlhV{zGh Wdž $zVQD{3ap82d;@zHu:E0`yKO }wLwy'e:SCؚK]!(8`^ fO P7L0ZbiyzfJ!; pJ%;;MQh\O7YdC5fW78^'"FE$RDJ-&IKU7XTgD ݸء%2fj wz[&@$>c;#3txF^R7`rsH{&Ny IL(_eϻ;N;BH^ur[8#dD ơC?f> 6"]AR{vGh?3 (=w*^'O+sqNo`ߧ,k:L FG> ErAdV^/iջssz{Z]S8bGl8\$9l]&#.8C/ѿ b ]ŊLBTn'qyjQz`Arw:ׇ41mkÞp^}ڧ;":}YLEI;€Y_^6O(bț4x%4r>+uhbsվݤܒ/X;&onj4T!˚QU -4%?Y aHw4͑LoU"=O0%7:n[Iɥ Ka]6ۖk; yeu4e1]}՗_k}:|7'D6S-뇯 $flگ𧡴D :DbU3!VcK?"_bc3ZII9_P $-&z֚ƏM߂Fb,gIt=iu's.WgF*b$ݖ1{QSus:\ U'zy㶹hRw[ 0 u=MUvXՋ-iRVQ+7;;I(sIz`W=Prg/~jl<϶4ٖ#mϴYhcW)c `Q~),s>W{z4OO]!W_8e}G׆K#>:?UuϬAi,B (tTUCN.ec_uwHm\DkAOY\ÛT:v 40  `-߆XzdbQAF w?!`L#J%[%q) :]#rmZ߲w)g}To(on Z CP^qʓxT+s>(UrO1&\Ǟ' @̷Wɇ[sQ#j;ɿl ɗYG_UJgOzBDNƿ5 6Hإ5LZ*C cy|ڧ}X2Z1w^f 5Z">i0>s_4Q)Ж ؟]/S`} aF2]>f7֜ӎ`+T9⿤ch?e=di`*_!/~E-sR8_WM⯡#cn$'PFjaS[kh4`Ir⧴}2gkQ6f =bP>wN8~㜗P[8G8`[ml -Xu֭1aj9"v!6;_o K45\&`*3(ǰ9ڜgpq*Z(+u[rFIC7}td _phJ?éf^!C3CWCOm!~䐎Ӭ .Ͽ ]nz?tIA`9B$XW>(8#ÇZ`V ]|ëc>Q Y_SW\ }&,UaSQ˿GOHBxKh/lOdfEuqk;b;!xeCa&t#|)M/X僡${>{cX>*cy괎>xd*dΟ3z8p/7̆!{:M4~N4ԙwNs)ԞѦpx6'Zd?Xj] RzO&)٫~G{ ItwK>Go& I / E-46?F ~L1 0>*pK=L_YlItS r8H f+(}ӊv[bO-5vНaaOlv_!*-:ne=VɗuS+hD۪XvA`bW U@GDNSOxwH~n օbA}8koQ@Ǥ{HDChgY7m@)Ie[K_837C0'C~X(فL0' r^Z8ICQxfƀЉ~B1U:.g]>pXyMP'> }oOpe(Bp" (jfX5/lY%6L2xy wi7??\D޾ u,]I$4¾7ޓZgmk$xks<^ӵȽᬽb?ϪW c@/04DLw==NՕ(G yA8*J6#s~ۏ=50,W]UA%!{&eXUhSV]Pptt2r??2ՅNň(5&JRb'%Dv?rihvS37 MxGg;0Z^|/Ȥ7vh6y'K`=ݱM8I{wRp<‘6PuhWc} ʛ7 ,V en6E2Nl#чyt q GA͐LAu h,greIg,~ݴ|0夢6t>1]7*&{(h{%J{7 r֠Ԅna{ e2I`wAz|%K+kW!0lf2kqD0($DׯXg@c_cyy9g GfaːO-'^ "cg0(1D╶{v"0u&k-'׭$6{"zy?L.od{rCWSECYHUBgK)!L3S)p'Ty影r( X4>͋k.ba /z< !CIKn4R#_ 2.qi>?o\]#c~w̟Np֍D%h U/Z֢I ;⏩w`iαn>ʥų43AnaH[*(lba"V J[jJyj#>$ݬy3\}€f!-LNc鑒n򠞈OA.JyW QǐPfL(RWWȎzk&f~\K FRu3Vk ?s`֟IƧ9ቋCKط}]o<k DFSX>oZ҆O]`etnB"Aoɥ=La^o1ȷ9rlH`C%\8u?TQy"yc` e@4o1#deO25d @6#0.&|hfrGT4]/+kW/w(|=1׶Öuj=yRm"~ ȺRm | fG07ѩV @զޥnZhC_2f:?ͷ 8nʹBm7^F0A a~U}ʂHf-9!0qs,.3j `E[:}n2v2 m64uFgQq)IBJ=9ރ@>5rAפjX lF̍iPBnUb=#KQr)fM2c:Z+(64- _dOs1~/GIKN*N F;µ[gD` k\nX^̤b0J̌\$J\j[>6YήP rgaМ> Msd| ;޹Сdj[RT D_bBDL0P\h1d@+x0Ϋt]Z_S- c-qfKE"*Wp˺ hE_ tS&l@cUNNzh,pVIW:[X;4Ozʻ1\qgeW>7~,-H@g'sĠ?f-.sMB\S-nfB-]࡭d'Xe05͉% *v4$:uxdgvZ/ 1W`퀴@RQ+*u@A^PTC\`0LߥqB 4H$l08yZp!Ii<!Ý^$Vavߍ6aB!p+CX~?J^AS5+fP^ d Ĥb9[A9{J^mڲHI=ԜG7ڴ^B7j~77~@q{Qy:J{pcueQ5a0JfSO@l3ki;&%CUr۰+}dJ_KabaEbX2Cno5j\t4F3|i&AѦ Mû ] F>/[Ȇs=:Bo*h= _gPzG9;e1.PѾ\i:Z\wՠPki6x3t"z몦v=.O$R=14c7P:jm^ο8Ig)ITٺTeLÑC'!{n`)OK_JcEB6. rJwӅy# pN"#= LeLz J'mC971WEQsL4<>Zot^Ӑ(Tn򈓱f<VqyIsK|.,mSHRVwǥǞ@->ػt/ icQ`NYPq,ks1 6o@(`oPfq @m Z@גBHvz=yneE%LOacšuA_hq ld',eE)U->x%Pe6燗ҍ —y/\4c.a&ސڥ J%{,$K*E%i[Vz<'R]d.M'"ŏ2IVCCh,л5_ {L6jb(5`bD3.ٙa wf-6ۢ:\0|[m:;1!(BG_yGH0Y"sk@-@KϨv$*.}VҒU_|?aIJQr<[Z$bEqY\A倌vDP/l=C9ٌ?ޭ 'lį)r3/YԄâ'rn q6/(g?01' z#\EH=Y6͋_·>V9)X+II +xSoM fNvU0q2nML8Rҗװ?^Cʮ u?˃Oբh";o+ 9)n_d#o96{ܶu32P=Ç_p%3_9QG(&+NqkL"r\9Bl[^ݽxNA׉ ao[H,nH Bٴ?[.Le Ge* ‚lJ_MPkEb!=á-$y+EĀVD9Z $WSURRt8q|%Ġ~BD'\ \ ;]7J[nH㟫]رҋ%!'%*8yP%bcS1 #GjTH;m6JrPhK%oirϘ` BKydh1W>v`ɠ̨][UֽRjMT$q0c C t ()V1pezvg S6Zr2kSZYzV;#Ұ[4O!0굉Ǧ`xTxќZw}bsY^]7fZ^[IGHTaeG Yֆ5T 9W aMs Fe;%ZnX>ܔﺁBD9Gom^0+(`ȕu#1Yvo|]J*nd11=;$\rly5XǗŭ6k␣YNm{cw8L mJN&_HY|&ck TTd!J;%ˏ&&u2+XV~UĹ3aD5[@[{1BI4;z';~̙tuYdvZ0Pj (z,r4}Mb;`M P}Xce]=(0'eT)ڐzF+#7XG>ݑ%/IJNOwom,P) M,x\`ψB@cn c`& 20LH/^2-PsEA (;u[tل<4=>g*NeWP;z4Ϛfo14%Ъ!;LƎ.\~UtUGû 5mO~487WvFACZ!Ma?U{E6+iZ,W郠ꁲc _ﳝ^q~<0*a4:獒k* ~,Fgu<뱭I &m\ Gׂͦ3f#Ԧ˟Crj2ߔs `9 MbO-&}h$L$5\Iю֧o"sԏZ:o)A652^z{J'YzchKI6kT.҆]jIk4O:\l,% R,oZ 8)$`F8zNy*Zjk' E7]w[DmD yo ]tf+?6sϏ'Ldxwvժ_>^'cʜ'qY P ?dO:0J)M 2$_hYCn(xFXKgrf%*+}: l[8Kkq)IR!3ͦ*:< g d e=[F*wyLȽ3> 8)DTb+oyf UuUQ\l|`Dǚ%׼صu*~d(8!q*!V^B] #0n6='bg8 zsVqVx0h⏃~FsN~@zH1wi.׮}_M =>aZ/^JS,`s7_(`ݝumNQ$Y|dѡjWm%M l>+w,~%60j>"›X "^)a_0x$}Nଇ8A6`r'v,bzJ49d8OKx2'|`}i,uݳJm5@vLl1og: =~ (Dv* 7aE-o.JVīgGhcAFY論XR ֜A-mӯo"Ȇ){gOa of)C{* b< .Ȍ|d&| \zkXw<)(N!+6Ƒ6~dV!v#7 MC6p>x.P-N; )aWST 47iG )DxhQS2! jiSl358t40)͊sf&-Q/{+:\mF7UnHߑ]@Ŧzй7Jg% F[9F6sqy5AmB:n:H*0MNl[}R&ڥ؉TOzPܖq xgDm1$d/܇g0%"8Zggv&_R&nJld2`<R50+BSڅJjHfaAi)u/E5}n E٩r7 5#Єto>*| p)uN<~ˈ;UgMn^llipqYd_F`ooKsqᨸS9"$?wLINtU"+myoЅtn$.W~G R< 3y.5_;a #ЛZ%L5=|Kua")[ NHĿ)?un`4_5753Waug{5'$ËpNͣgSɨ6@fϣE'M+B?cn8qiDeqTv5zx. ^K[RzD2DAU <.~tG|F.+e>{!U5Z([Ұ7XP7Lz ZM.DvbWٿZ Kt"$d%2氲ԐEHOdvB 9Zxxx saI0MԒV%WB0hi[/kQ1g/53u'gL6CVSB% eW.`-jݚykgp~}S|rJ-H^ Ena8آոgA4jR`Q<T;!`?:Zh ? tJVj3rY2>CH&Y.Ya;e }Wlbr<ߎ k[u4l)2A9> %Zs梳vJ0320? FP[,dɲwDj[mЭHHǥr0'?gkV|^?:PGOf FV6|eO0$Dž@_G~:Ά|"i'Tu[uKc%":CHol) KC>ƁXpFuoБ^ T%&M/׌-t"TJNPh#M:Tol%+gw"9׾~*lR# X>n`4ɕK#3]ha?^0'DvG75Qe'mWBwߤ P% )!8FnZ>Z)gL8-]n+uqBпl0_:OgyN+DQ^XGMI5R<*Ns%8o}\[:m=f‚搛(뗲Hk&'Z¢q!^s,dƣ59R"y#64tR g>׿$UN>~([Wg6|gL7N1{wW(?|밺 O8 QfNƍOwdBWtVP%]-S4L#:JFL ?- jy?wvONzs5Ӣӫ FE=+޽Ȕmc;]`AR k !ɸ3T*lo;'"BKtNS)_6Jc (FZ>neIC&xfS% Vl >*q<Zbސ2{ H]V0qiKc~QԪMG" v#R"##Knt}/Ue?vC{ѫv8+1ګUʔ`Rm8YfygIAȞ5a~Welz<֎ 1$ .8aSX'L"}㼬^A|V]ocOD0X-SPbZbiKi 58:ͭ҃AF3GZ;$d]tlC6{a.зOzKvp#ԮbąeHfԍKۈv00?V5eu"30t0Lp{ۮ5&e.eGQՠ;h!F#mTN)('E!+pC(P2=hWk zo&.m?K"/w&tMI}TFKͅUqz* j @RbbZ3#11txު_\I`2Acݔ[VWr iO Raě+N30,V K%SZ *qMqMH1Y9%{۝O?+DxRUA QAtm#7` ]Ά‹ut]fn*f1WdY Ic'+G ocu.< 5(>T9BYvib0BE|T p7y-Homз&p@D`UNث?NRFFx]qO :* A_pK0lC&G "*fjU#Iٛ*^!ZFLVj4E\qRw!v@VB<O٬=dIk|5FY=A?/n:Zqk$ %_D qP&e8S8>Ov4a0=!,1ْMJp/{V7e g6P̳hBOeKܼDK?HW)ɑ`L@n־p[z_Ü 7j3\tkw 틃6m$uBBn}  + O̗wr*;j(Ft>h`_qۂj[P /wVgm aSJU3$^ "0EE ZvG2ju,iŷ 5]dzT&%D܏.2,QXm$N8 s+=N_~cjD {a}G6" g:8.kAهP5|RİG=09&W!j[E=U2]|:qQ'sk*~㮶JgNˎ~BD, o| n8@J>5$!Σ`—0ay#\ĎHq]<=ī%yĵXi +`~MCDGqyr_onEX['J\ .B%k0zBB4!:_망i ”8o,JC}=wq:fOSXniΐ b!)C'|5֩G/-P-CXoaom|s!;y;9-p׫'+UGlr.~^O 9ya0#Rhv2캂pF}f:*:\ylh/ZފqkT<ä:p2{pr'~4{Q|"Wt*-uMy16B_lPcSxHDLX苍a= fۗW&}(oL]?9ne\4͊]2.uD*fKiAdzJtzuq?x/>/*ѳ|r3EYȋ?l)f)q2z*+,>{+T,2f7ᇰf$Xc1p2acI^ysTgG. +Me(}ax1 r &QhQ;'tBmR7rgM[2iMNg}@~^|.nuHKl&m5%:GQ^p̭I&z`7HWsYu jBcF+n4)s/Jb893D$ӟZE[<7=" mڷ<8l}Wu ǧkc` ROŮ=N2Y?4d^bJJ\sMy tf]) 7| ,gh2/z` dQ}`n~e.dqO}ݗ.xdsnSuQ->$rV3F˓ m \}4܌Rjf-3[KR"TX^<ֵϐ 7m$gs<0JR4A$ U5foMkcFk+r{u.UуҠӈXaR ږH^M3HD`e%)Xx :϶EiY;L>3{VT.GweߑT+C_ҽn_5O[Keǚ{5] Inr}˅ȡ~[uM7]1k?FHMH/7:Čyz袐wަ a„2c ^-ʅENmThYlv)f h|"yw>Pbw<u]ڡSWlzZfG@.b-p/@k++>;1Dgm&!-uhonUg"@ Eh$>XV[76?c* $B[ W<`&Gfs.>(VCime9MgHmy<)S'Ӣa S)AX fIfA$庿uY@q{S8nL$y7oY_/?;}仫%ћ/0#4e`zB^~<$?N Zݽ;aU'ÌYahA q\BȦiigrfyBI)#i7)׼ hw"[ӇSaDԺMgl<~G+ƙb@t(>Gr&nZl0 } ?z 6x<fnu2,"Zܺ~-ǴvA!(<_v[˾&;OmcwËf]̔DıX{ʋ %k`_+r-"ymz<uZcdJeū\/s]mQ ͑0B͍9IhfpǙѐnn5r,՝ɵK̿\XOs,XW0 P*ٌ|H|'>nkjf 7RY<$lx@d_K_ c "Xy|< @8|9Nl@p`0IA$,~ޮynbՕj 1_G7YY,(*u%F/2a߷+P~Ϲ Gu `Z|@.5{Z ^AHH냲"D%e'2x>7GL ~ep^L6f%XiT~⭙V[FvѰd2_b~g  ?O50lfu$}# E2a[rx("tSz<w*Wwڎ]r%<Vno k׮kWmKm l'.Y:dX,d!GZ(/ْnhSȶ|./w?C Uj"n@av}$,%j>0ZlI_D[˳*v@/l2\gCNMZG߶,$'*X)+R tzY![ԁ% W/y?&NB>.lM.Ts4-k]ڇjjx^\.gX UBh4̃FĻkK{UO>W&azmC!Q紿r kVu0S,ޮ8g ا}nm<rnY6%B p}Mw2b0)5A8[%]4Ee/v iD"Q(wg˿D?@u&/Qqk)!k>+ &ñŕ.h*Ix=mf; 0uL15-|A>3%!leEIYzlqDw`)43pn~`t6+'(/ u'#ψbжtrk-X? 5$ _YqMZ%DgWQئ~i:XbS@0_e/9R-6Oh ?P*$Bv>gfy6hc+3:U}c BڮH\c$).`b@$`Ib`=y=. n*o\gGuGja Q/jF5R2!c}ݥtT%ya{A5ϰc REU-8JCXRI'&؞k0\}pPy䙾~$FZh?٫`WߣhY>q*I/g! ʾN7}X $ *D8soqcaщ]۔fIa\QVKgA%$ A<5 *#wofgOUdc]Ѐ 7]i`/h3O\?0{;:\-_2q wJ3oĖ$-sPy,VזQ5^Ibx3 QC$RGxxbxuDž&V b7ZlfOM-Էu F_Zr@ \{Z͇8T?"$}1ʂ!}5utF WuZw+oQ'Y,dH]0McoW8-UFW ;4=9ed l"åuZ eO4f"xs{-sf$wqgpvcZϑpBjz(9b,nZB:Jfh4vJx[v{V_~9毻:Z֛Tt9y(!9/Us<X&XD9_k} f u6Vl\@V&K3jCn<N8[vh$uu:W۵hHk+ܭ!`0E\&b?g`j5LH] /*`NȀezfV wZA`0;+v++2(j0 a([ret|XȶM4'?EI@.|㓵Å8s6AQ}\m?b߂Nl9B/mE:zmYZRx %֠^L_Tǯ}xȑ֖-T]sYS9Y _vNjla{cNU;":qz9iƷ)Ab$<]6SBwG;ڃjYsurojN^z6:qZZ ʞϷvfAV9VHu䧟cU{h‚D7pIzo&e2qvjl!C/8.XpCWaXcFӟL':rEzTB#'i;yEKEj[ X[g@uH2v}ʔ'u?fD R _Vb3|!73%. (n:tRx$I_fmV vb QɵيlѬӱ A |ʌ {F8b?"ۙ-c|B<2brX vkA,%_RYK+鈚b`]wIڽ(% lVA8 ,Qջ-]B~lX[r'Ccje1W=CfQE>̕ƒY,+1JQt2mmRkwn3x91@tsp|+u?vC01lpGhљ29 .%%i-I/RL* Y9Y#g$xBr` D -}  [e P"4$UK#j 4$Л%oZ%V?hUx 1vץK7ņ^p0[1})W|;ד\y}/^8(RNH9̲L2#yܾ>@R3Ams}H-An}9Ά=U7Bo[&kз#nj1wM|xЍ rx&A1>x eQ~\vw`qG4p+28A8XĽO\Ge{@SyFV̯5[ ž/{t4iZ5X=E豭EEc\CpI3gHjIעtpV=MZHԤ^kݏHd@߂SAa(a3R99ܳ@o5sxR pN.r[RnSN +x4g2zjմz}$kԯƽ/0oo2F)4(k0'YK&}適"آaKSK;dX)w"2W<ʎKe 5T~cUv}UmC0oћmPm)6V^0ٕcP/}@6A!@!|va?u9 [IFfEi'Y Z6~@l,FPU;6cѦfV|=Q y":: Jdlȧ]3"7NYUj@%b">LgCO~}\Ԡ)<0즟1GјD=o2ݲjl'pQOpћeF N^{6 D+(0R;ZC,R%+ yb־p_hI { q@T@# S;{ Atw5DR-Xc,͒@lݲYywM o EǓRÿejPdSFzv!ǫm)nw+>_,lE w7Ϗt!\CC*o0~HFc@8sgX^ϻ7uARDyKʕ8"FQ%#O(p_f}rPX0]h"oM >- PGJ> CZ4:{fe"tT89ZbiYI|g:g.hN` !30zȔ_7LWn Y-:ӝn|Ei6Yk%% fEv.0.& L{*Y=vz5k5qM\Ug{9+iݻs$ZؒG2~ޡ9 1 vNf$["k×3^"4d)a͋dXKF^K殱'()N f 輟v;&7#$ 5i%uq.Xa "t5MyP_tG\|B R}*brGtpuVu,P 9a'Gr jWL1jB; \= gF:!1:?1[pPاsUYN%dA!>Àљ!:ok4Z429=PԣW/‘ 1-­𻚞 ?2lj}NOa4%5:VW|}]z=y\P 3" +e8U M75@ %n f﯃HrQXl5rSp׬:^]BGDSYU{v]B|dg`PV~sޤ 1M[xWr+-E5 Ne ׋ :y^RNnωHc3j`Ohߥ.3RnEP$.(h3Fd9t.;& p 㷌"p@W4b8sbNRvO S4s??@N@AO29^mEN_(N*&9FgoR& 2bf!azg%$)l5>9s'vr#^dҗ%(}e[ڋhZ89*V P(1e[YTYnTHiݳH̓!o$>S(.a'>4"' +ShB,ϙXr6|Fvs*U^#r6y?KE֌Y. G֠ \Ɛ'[>9N3a~}?q@faLv#wߒ}b9ezgRz3brO w4,'gZ3%]}_]P)܂k7]y |NXDa2؉ҙgSs%;ٰ`9yy`W_#1B 54l=>-kث舔je-Rd{F1.21#zR!'#[џ |g x ݱȴ ppPdH4"Ȅ@$s:U9zӳ.To7.|H(!2 /s']'(߰ѠRdy!B?vFv 3fep/!M׼r5Ѿps[wz} ղzvnj*!@L1~T8s\PN\[ 2+V=!`DRI1/hly-Vc¨aUv-mg3'zwNI`G] sE/ ϩwVHș#<'yB7Qa9+72$QɪP WŔ4<n0:/5f}0TD.<9 *\glG V;lGN&\?`7iK-l}?Abha)\R܅Q=%M4X{UP)'y&*WŞI$v5}Cdw`gǏr%1Y!5O\/{>ٱ AAS_ 2fqOUʁur ey/9Hv=,o7Gc7J+L ";*Z/Kn94mǃb]y| *s1iIvp6N: [*`b98"4tN? 8|E~G`6YT^zCQ \Zc.eѭWPe#b5f#0=y2umi憴xU*du 08#Ө2O+mK뺇9XjɼF94͠Uy=):XGF[u렿ޱŜo,iE xnIs(g:DBsΡvsF|B/í6ZtCli@ڭG^X(LP5OJ"! Bsh"( *.;l3?oa60hs~K{Io1a +fҽV_U&)FIH"5<~{m^o`OZWK^aF.;/׎~i 6^fdХVeEW;=J/A_J.DN(o8Er3WQ z;d|:*[Ҋ%cU <܅P5izv/hUEq! Syf`ZgeF ^~C@ A7zUuh[͙!LyO,hg;HΟgK=xGRqZ7- 2>5Q^ґsL}r8m8&Fg?^CՕ)E(gܤlI}R%'prCh&@74Ď{SO  =ʪw] X4CraJ#,A|Hn?=_ӛe9> g8mK^,Q%)A*^z|O)@w|8R;G7 I.X\˭ f~ ڽG^Ss!p 9q֊QZER1F*5*%-\s1˭鑝*ၭϔ obJIi5QYg&'1W ^%ӗ% xBu軕Bϟol4w.}knr5!|]eU͊ƥɼjOBS)PվN1q2V.Ȫ ows˧@e u?MqK'Nlwx{` #C{g\..blTJbXׇSga埶>"˛-p?xQڂUeƈ]dӤn cg% ?['6GsG.;oH} _;Vm+ʹ2't51{ }2YTYt pJlvfwS0+L ?pM91= ?e@9|Cq.+ߨ>~ov#;=RS5L hD1F$Q@uT`G^vخ5X!|VsKw8 ia qu7-"9̩kd_.hW w#R[RiZj0.HԈDb^F#bglh(isWʊ}Ԙp79-̛,#ve1/ o|/ vT,ٱ> 'H,"z5d7Avx& ;\.,2+]|Ik7ApaN-4J}$FNp ⅟C+vjpKʂq:p%BHb3^;#zjp4w[K)ʀ?Ģ-uI^x !Yy*MЊs`ͻ<8"~󯱺_TitѥS\oo}r*6tq7'lsNybA|7WPԔ?bxe_~.Ո$M^ c}UrPqv(eoYQFhʇp&}֛C@'ګ;ϼQ ʹVEE=\ 8V<` wF"L|3bf/8>rzI7NfG;hjS91]> }ې },0jPb"Z*@2C qFrI"mi^QnEU" ?(j$f׎p gC/V $0`W/M;lO ƢBT/Ҧ,Kƅ2;\ø^aYC 6&Jk3n+%QGqe P L#k&dzƆXtGJEKdN.5@-$wYg/W,DSv( (ޗjB!_gjd;~'ੰQيJ4j$o߼U#_`QcwMln7@ ]X˅+ᢦ3*KWZ"bYrt[eX2i {J'HuUa&ݡ R @)-]bH£DA'Gz*鈴f6!naAo8 bw9La]UYl..eIԞ\XOK[_ݱBsՁ,r$6E^`n W&%3vn[]Zao%>A(806Oc+I1+غW]R1BippvPzKwSL &ZB3=%d1 Ojf^,AI4ek>VS4!*>UUgo97 "VJY|~`K}{c˺[;_|Dbqx_hQk閍+ɓ?QrbH}A[N[Gp= QOKĂ؊,i(:L 9VVߧz2rpaԃagFIZY,(xnH`>fտW! k\ BNKDܘ۪P?2w9tG$|¤lC\ġѤArKCppRm͈01pkS>xhY'mQ4^!w${8''dZn58sg#g1l9<ЦhtGo!AvJOq]{mMu30)߼ϞFҽ2FIW[cT ^HG?i0 !9䇀%0{t Ϲ `fW &q1pQ)5`(M1f -qc`g$[i >a x M'3PJD}f{-F΂7ALQm^Qu.o|&INܿryn\e %)DzϳM|4 t/o=_GSs~^v.u#u+-ufPWK VѤ2Г0 u4+c6/{gͯ[=lEC !?QQ]RvOLYGvg* ;OZWП:/WJ<>n#ƴ(;G+X]oL\1n=>qOj5t" i o.F F.WfUo";Lp74fF4ԣ~hxڠ߆*ݓ-?ΪrFSM"P!BOStdvO@lԲJ];pcVo3ס\;3ې#\QYYfL#HʨTPyhiˑl+30y4TA [q7ߦu*$.V:DfloċJ|UNA3氟Ubw3QO'ͮA]c_^IMD/5^\)y;vE3)FwwWX0n$U0P>sa49ԎnRw%;i)\a85uOuXC xIUxOc> CVtgG-ر {]ZKa«vGMSl6he2KBiFլ]ԲߡL ( ]&T.ش9MV(Q ڸ͓sgڂҬt4Nt:S,>NeՌs#Aɧ{\}M'пDgg S DZ*Y2|qX lPAw\e@F$mN.h;e;\r+}݀UZ4G܇o#BxZ!9 0V@&qkC;SM Az >4Oi1z6$e L.~"08N,ڕ߭spa?)m܆HAYq24qn!x;; ;6i?R+VLS*pӮySb)3?!0C|]2 m{k`emok`{*WH0 _}qI9zXب`7 ᒜU#;zPhj ܛ+lS^\k*s^ BSF2R-};T*yo+lm xS!tH!O"IXCzq@ժ1 I לz_vČpǎr-铆zKtu=s4r$V$YУ"gi E ǚi?Xc(٪+:C}ɽ0 /uvd 3!zQ\4*Ag# iڷ_?-煱C¬9xAT/1=Rʒռw [S[<#rhLzK4[B? Ŕ-$;(B᭽G^!P~ K)aP"kpkdbw| M`(6z)2?<0z'[g?i$c1҇ء?;tm&,`{ɶZe>uTW̮.ka\BCR_r yb^OF>zLƿ`((Q@拘`S]߶}l1 s>'A+(WH͟ݢf*АA>H}-~`wO:4ѪͱېP8$ N%G1=#?!t7}*{Gͻfs P3hdrFyF)@ѩu[19zd4{b3r2jk_UVPN'ЅZiKe2FDCY"p%%Ch( o[?kUs'I-X\C4-n tCeFraKצ3oۗ6ЂduC5K !ԓAV]+B)t-P'~g|u;)tcu6%F`LrJPeqEOԹӆ2 *mXųu'l7r<j:IxW~q@*d೹V_; :{X[1)/Ga?GH+ n$=/1AQ%L˓R 0p){ o)E9a+q{,\82J(qY ^X%mQ08o4(gCִf\LƖ\yL\mA$CAg0pg }ͮ?qh+aCU9XWdϻ-|̏ 1_~ѩ)@WAtA*UGO@MV%ɡz]==w14)(wBiT~}w^W5kTtmdYr-O${*~FNm:odzqCOd=[80s7|_Xazye%v [ò V^ї]Ơdt-ugpCCn4nmx:VM<֧wQ$[6X󮎐bX-ۙ^@chADv{N!ֺۄS0,{'Se0 gXp9Vfk?3ʹ>D*;鮮5͵J vveg0MM*/Ff7*+n TG32˪ d҆ '1 V,(ѩ?#ePp^PU[Dtrn[wV_ǂv^UQZj=v$84_>2gc]4@2>Ȓe35;uTZt=f5]ȂA;G(;8oj_OΐU6l1S+J! bV| yQ$eoX1Ъqbm :ZkeD[FE-_^kF T'e^b>b;bV1Ya-Z&3^V)ڼe_A%dHP> ęn 9x;%2f>Z 4h՗d|z M-ePCrYfް"!~t!t+(SG{"z&8 ]8V)Jy7  \@h9Vnwz0;h"VdSSM] =: DRQ\Dx)+O s^9d3xUЊC]4ȃm.a oe*5a ؖ*(S,WLwAnbmQ%~M;F" +11"_sAA0^\vVc F8nғ81tj|X;՗zX+IR?!{C9qJ{V\ARބ(AHJ9=ĿkmKovR-aHD4a,fO eʹ|k%}o.C TH-;! ܨoC0eUjzni`])!%mi+]-u>_eG!?\m' d=|.A0R5.2$cqD5\>1*j{g%pQ5D3= ָھLbb@@}CT#pH6]Q%kknD:1o~&𽦎߉(=Lt Ih#%3ȬC~xc#0U?MsNˏVRJ%esNDZ= Ffnm_ IHB)@+Ma)k OA:7)QӁ2(h jnƎ0u+01HB=5JgGJF<W[SΛxv,!6sB!밝 mZ|]3)6tek6(7 n.6|[o$5`ւrs]iKkѯyl,*hJbjz?7@7YlZ`-bv(aGq"Z 4 Cj~_R"w*G e =p ,ѲXEаB;sٔRTHӍmc0FFR>0l_X^TxQR,vgdr@-|G&=*LIUGπ!y3 3ShNǽ'd\.'co_ /7@Rۋ;馻&;Z\c6b\ޜ+*ue7%,W`zİΩ"9ܐeH@ 򶃂`6(h1TD`$Eg/Xs x2m֠[P VD~qk(+,z-»gp1L;5y Ӌ)Lۦ]Y2.1 ҈ >B<5rn 1}D1@Fwߋl\&/8y:34-l:.E%U`f?%Sy9u lBjOmR^Fn& ?"؛OzW~@sz(Bm3A%ɩ߉cMm*ewtR5WCsfU$ E{D8 M cBzHahRo\ 83S8UӊrQHvafU[[bWI7E"ī,Kȑ-iΘw4y 7A;o`0m`vDuPb|]5Cʑ!]"9kF.C^S&)簖]?){yemtS;0yOa+IgKnpD[_S3L݋4vq]Rpwx:d|Bki@P613=`=u W&^ 5pZK,l> !Q8bAdsA;]PweM`& 3xR=ꅚ23OƗ^v FļGƂ ({&B s6:"[ *w2p$'~w$cugMbݸr'CΌU~@G- <@ɪ3,SA:vJi'h =!G>V0;4](8a6 .570z 9F'Q>CbЦs8Bls9ATZ) Scֽ ѕbw(Ԧ½M2oro1\9zLAr:ރW'lm덒 V&wH E4?aN`+#dcq)s҄l ~ $D7rca1 pRTIpL};(C2,,U/5@3%ah=I2=ꩫN M}%9`A uEoH8Q댳6>F@Pp[O篞aͳL=ִ峬 &oC6d7$y:#޺:%77yQCwA d#jD@kNVz/4W*`)tuF&c_/$([pםnżz@9)'.< i!ﶬ @KX4hѹ‵EۜyqI0aW{KWLܽRX)b6Epgy% >$rD&zȈDRuVi}"?ju"fHt2hF^ExWXɢuTU7LS+ڛ1V(W Odk4B-"1GExUGx֞{H蟮583yY.#P'9,!RgAnR/^]a, =Hqol>&B|!9II$+@fHW;@OHApT OvgkϦA61Hf^cւ6 |}O0=nތM*'>`z"[!$HpCRߑD8*”&qP{va\%zƵ͹-o*]]jBnأR̻*7 Lj) v cFø >cpu.@Π :H[WjZ ᝗9@ x3%1 !/gh ɒIhlǔ>@3Ҟt vo%Utd}h8FAg!O x8=ȯh!{|)X%i -ZPS+3:$H5H~HcdpZ(Is뎛#Y{"鮗3񚹁UͰ@Mksv^[& kyy..ۆ%NQ@6 ]$Jp"Z/\gD^"&SdN))@%$=$Dnɋ$oDq_`JːNi i\}qZa9X"2j$WbPQOo-T^EGyKV$E0/t~.&T&9?"̮tTnۅo HZp FoAp2[a~x5pf&6x8E f(q8W=P3*pH T [ Wl%>[=3 S<˞lU/xa8 D¢ދ+ !uo s=Go2˲scm檎&&[AS }=%DeiNmyqy;`!|`=dIAxE |heL/G'3#Z*FֵTX\c]oV=]1~|e.6oD)WքWvBJŠbᆴjirnNA?Rux,%A&-obN)jt`ĵ;4#Lg5oQV6zKFpȹQt.yH@A!n7]DiL'.v>;&ʞUe0K`\-R )-C26e1( 8{ P dj`ҳ7xK(v|Vx"W2 E~E so\5XG_2,T7%ĄK?K ^C0>r)b o *.! ^vQR[|1H;d4c"\'Bu}v UKV=ݡw'͠HPCʐn:.\' :w$_g0:TNDՑ"g֭ ۭB+?Sd\{㛮f!IG`sXhk q%zGf?Kh/ZԐWV ܼd/[6pʭi%#2y_CLؼl˜HO(S`o.x4LW~ `͞+;JuXq}Kn#/ʺr~,t*\yW%N`KZ8mFDϨ7Zzг_ا6fgM నan(Tԛ>#r^z,9?CͱK Of( UwdkxԃI|azj vm%^0X_'Qk*IH䤣 ˹):zqp+R@>;)C4wuC \'GcXX%MiN-U ?9ۺ^4%HSo,f]mk>_kȭ,run?5>e7aͱ{Mk~BV4fZ ۃ15b 軬G.2ߵˠ; 6O] y_ʁSZKt0)-:9+{[L i+ߚ[f*Ոм[hFG'v((}?eO \#C~.t ?Ky8 )cW;\/y$${ELJMɏF\GpLT:M$j9F[ZM6Ĝybk!'K-)`LىkUI]`%9'sAJf׻.1tY6>M4ҝJ[_ĪʟM2` ^ύW2a;hId AƬu }jUi7wG+bO?4[s.˜1ۺ ." gbsB_r%FU¹ބ,sV̌IlM6j=A~}xg>\>+m!t|%`k&fqM :Ta'ҳ+ܬp9AE  l>VWT4f .opP<: z3%F5SH) ~9H`!J3H-Mi/HCi]!Փ[^"hu:F^7|<7tMb[a$x'=qah @M⟺Q"o׃BQ`C>,;sd$d)q!2e6ag8^/_z*x1]2ew}_ėgRKWBuC/t6`;n7ȮKi<i0jyv#kfw-O6m/)9)+~o w ^b|n)@PԺdg¿FbW˳#y^#D]$7WrA;,MoFa:M'umɄtK.%lWc3P͞LEo0kỤ E 7mQIg]_>d>dL 1LwOY᧻Ʌ"FJK^Y $<9۵nrßSM tA)pKכMc4*k=T%~k'h GAvtNuj&ߦ JgQMcߔ03!Ⱥ+ʞCT29{|F yD&5 ST)ͺXJی\㕦IOd#4@fd#O1wŸ X>,BhdQ}^vm5 lŒB:%y?tDϧ}gEgKos4:z3PP&b)= :Oxz#2)՗tAjlAyU?orXk dUZM%`[rPj? akK& `=tr<$P*UL2]ew>{HN%'ab{(?x>y+2J qG{͇Ď!h " נ؁)2<[#[Y{j"H uzH^.1ȥ#O'Vx $T A#2y!0 fiWwHhQ v>F\gMνVBM£1P+ bycxW%艪Kfr阘RI- JJ&ܑٔVMQY2F;S/ @W_Uo[RID@ ꐹ#MWcD`CZv0BǣsJ4 < U$W+{%%Zh2j6LU=ZC/c)51? 5#գtFp QuljVa "CE.RbÈL~Pd.,o?zW@!3EwCDHI>F7)t*o-/AkmCsϑ w#UlNVWՙ Y SrV#WbfWDCㅰ5~M(DʏqG+^r5?G9r.j?Ӓ_+0uy;bNMNʨ/5ۢidS}!^]lUϒ&;$T}J^C>aYFH=œL34gP ֝Ұh}B:~.`Hn_R; R-VE8 W4IlYA1Iۖ`YV2h|t2Eʊ'i 7νLfN}[X7$1d~gd$ĝ E|x=+{r{x0ͤYa9 ː)ewNWBҿBQ[~SVp8G ;Nx,ν#G/Q :,)E6i4ÁJf ZR:$]{l??f@ T<eΩd;D]rmQ!7Ps:iBeBx/ z3D|$jd#դ#8{4"so6F zmdˢ%d+]NO:] p熦b)# {E VyDz:fAsseCiY[*$j8D\Ox\NId_M19V2 | a:* L?kfV&~V0*Թ)joD0:+0,p=:yn# #F՟`LMtwǂ^d3pv!.14l<T{(֘s i3)%ykQ_$I*nd4|:sPBC>y6p(14P;p|bo%%?KT@cd [smB9& N%cVjKo#^*Ӗ ɲFJn(pĂvG;ħV$\%,_k3x (ml z]n :Q'21ӷ EkA q/~uҪX5:|yY݉1 f'6M:U](uSb*?NHjiZ"P#AJ.H 5 Ǿ'3إc-l 3Em' 1B`湅O(oAJ,;y/ -sU,GjZsS&raALrYBEf=n0ѭ"=9Eb1꣑4 r}A":pD@ί- ~?aMBcw:+wOq1nPX$pD />4͞TmX2Җ(# ڱžK z7<7R<xi\L-_Q2Kh$hOH-1KLn˝I}1۷g d$*z=_?R,+t5/ZQlӪ &o =dA7X%O !F i̹96+ ԣltQO' }@`5h;jӂjK k|%<[=߈5[~cfAcq'J?!M3payR$%<z1}ݭL÷ /-~7>\6 x~i.'j?Q'[# dc!3(A1 Lc<| i~ 8]:YvfPr5?Do$u\5zѮL0r˕5^_b1NQ /^! !sh^ڧؒ꽲qo(U?e ~Cm : 2(*g U@g]|4eԖ%"Yx )ų_VV]b&ٹr(n5nTfRp/5"ze\uKYoYD/i ɾQ@ʞ=7Pa7?13Nlu8O:$4!T`xcMlI "࢞|)Um%DM'nT4 GCAid8l<`;X=%]mdrȟ hyRh/Lҙ;\&/Ƹʨ p8bθt(Q8 R,cDJ|bƲ>fvnrXcDiuI=vc}%}1!M-h:9͊Ɵ)ɖto ':XZ^Ee\kW`FoݫV3-0PrґBt"61CA,b8gۤdQ~r$uW5qO(e~DE:Ƣ/y1E53^bDx`Q\7 Vfi}m5,Wrw=zmu]l--mCcǁʓ[:qIG*Bosn-;o[nۢEȭD Ai6F;_4l/3u|2܅]LS%_] 0/Fs4I.I4 $G8Z7I[в9@͖3s"Y81 /,瑘,$ח:䏣G{1cm(/iUv)cOK2kLHՕuE,ōHL-K"6%:Zöj5!⥣_q` CH=$#\=u1BXB],oQHBuDokt/{KQe~=M[ 9"z⮭ Sk0uZ;E^k&r'3e&:X>)'F PPȎH&w&}`UTUc4wAm!&̚- HۉaO/H5. wy9?hPs(ȉ*{Ҹt"@-\[J2HP"\g;#i \$+nGK>ڦ^qz$;C8֯[_ox dwa҉ޝD +ZXޗ&V{6FhuuKz( 7:aZ Sމ5c ^><:Z߃hFAkNBj(:d^G)UobY'"USWmV̔ҩW[1T¬wH-~HV)0x @!׹J:fCy?LMݒAaVLH{ O8kuurw輂kg ͊LCfFY,$yru` T99Y&߄8xZg3Cyj$2b"*Sʓ9 VZ5`fOQLzo  =j!5BԄpNcXGVd~b6Xgg> ߢ54oW4*q/9?Jc>b5N]Z] ԴRw/9X\ 0Ag2K .:!5!0A͔`oB4xTG~ |@Y}%۾b{8UI_ 'BttGoAlӵ BDݾ'{~H^=9%̈́_pm+_;mgGPw|HwΎzbvmѓ:[ '>tdv6H[Jh+>~20Mk?&2x`=<'vʷ@m<Œ Ei7Tz2#w+NPj8:)ߜ/7ւsf&8+]"Zls0)#sm5Xx@ dt'3=Z)lT+s'R[^k01Q`^bbyy0LdQT r2]2݊v;J"xR8Z#dARNVAM~ mt8C4pW^1BɓY7"^8/Ω='*yHKWJ!#×{ |VMyb#k^ΪMrL/_LnGBvD#0}Rd42:-.dΐ)JD\I뎖J n @vV8[| HWsM+ *_*[{jb(uG\*(º)d9ΐ9Bq+kRg vԟuHFg/#.4K#{|`zrƫ,%f䉞\Ғ+x!+UA8dSKN\"af/Sa 7Nȡ3.M ?d^f7/v8xM/daLaΔV!d/jXbZ5̷x5rT&)-8Q~9[c M`&~I{U4wO+IߙL \Ց>jCLG솶1L@53G_ ~ʊK.!=$:GIßY r_>%w >gmGgLxhh>ϖbK JB7 74e~L3MCI聛}a; أ30փbG#7bid0Iz{B3q-ts  7M \'?ga(|VYMoЯVӵmɓ>G1;lap1i~)@w_ zGemZ~-gfcG 35Uq\P_|m^TRj8}Kot߁o;F= d2t՞C&"D¤؆TnA<\P}萍Z HSQIZbWq**NE{j 5 L/,l[K15ݮdG P)yLpma51kzeƇ#(#\XdEqa$/H2~[u鴩\)h :OϞ@q6Ɠ>4okG81u=MMd W":k+̚h8.Syy&4 ]JäN٬{:z4v,g zßd}N1z v v2ԥ` Faf%Ы}S40vSfV569֏:kүBf'/ٝuu3{(nHqP'z2ʄ6TGb#7]@ؚzP>` $ݛva|K, pUp+N6čQTگm\'&3k5<ݞ6:5eY]~#1NwzT=RGss_‹3VګoN} ReBbF1ȗ64,WGl>Zn?dF jXA%t ;*:a*ޛ~0g˚4p1~>c יh0 l*JDYN שFc47s'dQHlu?2֗|oK-Qk8"lN+:usS*{-\݀G2uݹn 6sP-wFqq9س)Xh: hQ3Vh `;7elewNQ*(z'HѪi%3[mc .*/6m7xv, N-]xYr8.׮aM>=!edYg~pĿgt ) 3D*;bypӘ=Y1qS]~O @Hc9;/rlv6gm$NI&¦'#U'U}+4>::S_*_&cas lVD{Q+G +5ANMxI\/@Yv)dCgZ8?d}4`v9%ՇV' 5dǿ c9@v36u; g-^r痰57Xkۢ' ,&-) kPTI!ºqB2p1G CQECYdVU2lk? ~ N^S|)q{" <8Tg0t8=gqy dg)3LhkEc\}Eֿt[.L5 O\1; QgJ|<ϬJq2$L-I֚dtE3G7a/Ae(QFp zP0Em-ORÕv;" %CtQs*&x%)lLAɾxmZ~Ci40dʂdv37f7Y}؊JT ;-&;ts{ItcR؎)= npGYJ\rX1U-覩_ }9CHm[3uྫbx"ii1/Uq. MɋMB7a߉ )ڗ<ߎ0 * $!![9_X~^~+O$<15γe&JGKPk-G3Q`~:3[';vnheh9e+g b8"}jO8̒7h-ۂ?:xn>/*[8]g&eeƎFzM\2>$3t\Bk:f;FEY.q,r(,ފ4(ۨm?,!GgAF da%! ք)Fc(yQá-Ӹbl7ug̈^IШJ$-ƿU8ChGG0؞0Kyo+l/pƏ܁C$ƧAEAI$OXU,XF+$Jz 1Rͳ,/|2V=sN˖\*7<Wz>Kfd70ѳOԶ #gVa!{O Eq]CM7w _U踐N~T4c1Zv Ո屗T&8l5G66(#+? K@{O9̪JF/ $|9ſK0?s$ /ciIʍp;c8n猬J.D.6 >3>MP:FlROQ{^AH4Zͩc$&^HP6aMo"XTIZ;ůEWOwyƋ20Ȇ3z%Z_IaZY)=mU@vH}:F.VL[ç01fA۴u;}(;| 90 ph fo~gXDo2cySIN4zr{aݢ*GGj:?b(Ծ+,8btצo `Ǭ:XV E 7ߩ,'gŅ&YzUF5E VO*Y2O+<qGb8Y] u2P MT,8wϟHFK^Ë& EJZis=>٫y=>\FUAt0ڸ!7so^~lG 6x*[R:_JIӔ&j ےtӅ1N޿h OQ46KI1kH [QFd\EoF(ʑ`t0Bq{['2KXY~jSt0%&:/mw]C2t5ڣͅi{>N3YWV^ R48[@5UԛIj*s's¢p'ps*YPZ4d?*·>xC$fX$2-xͮ5ܲI&k yjS1M";=j+ҥvϨcvKk+q/U4_e paD|dwU`{J#< .GnjGƬgSfGm28ycNKSU JyQCrҤkӅLxgT=ejTB$lǟ1 MC>&8o a$E`BRE؟- sӅᬈVdtyl.rTEPH3G5!b: =50BϞ;e$;ZՖJm{wwwtX:P[uR?HW\~ p3aOV%;ցEN3Ve7I'۸#TA$ʇT :|Z \+O(e {뮶]}fdod z13YGN/8pe)9Kagin&~ʪU-++<7d'Fd @1yt+EVzz6y+Mfȵumį :c߲!)d!q)Z^i˔Y |f޲ґ}/UX֕{Pm!nKqW_pI-;%L QeMJ[wmwxBf#Wb< <Ή PK\kujg2DZL}L~/\e<Ppfz&:|SMRm4`)xԭ2i ;̉v(>OhKC.4wayXZ !Ƒ0q j+GgLoYj$Ȼ V?Uɡz\VPb\ M%4S* a3سhJJSU7 Kx;D$Di{ xssJs b [r$i ͏Og [7iΦg#B((xR!wsk73ZS=î 3>2Q.`:Ⱦ~BR'pNhAxkDʷdpGZ8Yq"Fjqg`ĨEkx!bը.JMHAs͏FjFf_j*TvßɓڈiK0_|S7nbLͭ >TR#yTUQD|1O&AkU3.(5e2`䤃/ٽ/LQ~)y@H8VPGbxai#^!&i,?o4iOL: b=J IJOOBnzexUtqgxp~>ߩrm"-*Eoӆm E2YS?H\`If=%.E.`9YTrJD?XA#4omIHL<kaUlh][Ÿ%QT@ĂYwٵNP}iF!hd}X-)ο2mձEb83$]@lgpu9Y]RJPG,#,q[fǒw%w5ΥkG 5a8uNDA]׹YzJZ AS (n)xe"`W`yǹI?֡3 8wTS o(ģy8Et S3.l+ |@1AV꧿1{ Qۃ́Ekp>|rTTFm*T-K`}D9<9Z.bS~H'k!O3Gf>Lx!~q9\P#Dp0k6If*o5!:I;ӂ>_+G %yGݏ/K0 {Zg2ҳ NDM [We85OB[P7,~T|onتvEҁ<):xޒб=gAw8ZAEQ^4Q ~U^Ta4|wbQ8OQ!> _֏!}7=9t\2G{>i w]|lvZ U:Hﴽ^Od8Z'\9+/= @ܙ%`n{J {NKFwzrN_- H@v㙜 ~B|Gii[쟮x ? d ͵W 9 O}#|7& "|yf]`1t\E0 n/G`yW]7JȁE9~4ه7j ;&~o0JN}Nʍ6eՎ,3=cfd'f:l:N$UV'I"'*BFgL칅uvf9ZizL-8$)׃߫e6. .r:}lap$ 4ѵ} cr3Ho"aӆL+0}JhEZ$ &)&lyl$߲+iz%B-9u: dx󰄀8U"~Bp:iZT%Cs(aq6{zB)E5&5T^܈2sSVG{)+Eecg YgNS*MFyYP,9:QAa#^cB;N2_% rG ^x)u `)@n^]}cn]<+mo3~Y Ob-OOWFaņ;@T(| ×'. bCCL~FN ;џ|?˕Hr@`(UusdM*MɑRơSq:}!Ut*beYO~YBӭG)տeS"?83wil(Rꗣ Fgٖ^B]8@`bTn7D.7ͩ/^EXm+9&ʳoBjH3]g8<*c[s|-]WH|x,Y> T }.]'4lq{/3f]C:Ӻ^򭑿՘Q]LL&pZġ5 eV\A3Pf <;qW&޿6$EVD%Vo}za<2.JnaޑYnA(=;:L~bw#;Y 5JsK!2 du|nr^Ů%N\5N>"CPcSTԮ`gUr4'^١u-u+\i!bDj6=DdY b+'@!~eRգ ~]wf\iJV3+H0Pۙ>p"0批h7-@$MKե$z!g q"d|,ؔNS[5.YW/?}$֗ d`j([fT%&pؕ@H-tpyz{_/¬Z8mQcMa|h8diaQc~WʠNYJ|kYV'u&Y/nwᨉXH$y?r% 0a<-C.;T1Z/G#+omO@e=b4"Tg|L^_ v&hL:,EdD U^F4Bo (cl ,ɽ t  ou6TxVvY`\öx5etbU\L  =ӱ7c ]/l6*%(4;)_1l5C^tsUu4/+b3&%'?J#|%݁Hr`+U _Xyۮk% kSzw s1Z ܎3c0\H*tt6z%ǨzZdm3?y ^;0b:3ra5m^jB @_Q&O8p1)lѸ(dtDdö '` ` #8 '?W.0wu撦vmAb&g0 ,hcN' Ѱ!MA@DK+nl*Ȁrf8e`#~%L!Iʅ-FG}sb8mĢ|R2!e51mG2A%eêuYk.Y ;u`w'Bh'?17mKeʾ>?Q܆Gfmx˒ 8=^ i*ogΔ/D:|?~1aHyTb6?~5rkzJUm̝ Ff%l3+j"ϻߖG a*ve"Os{ཹJq"NWsͬqvB^ꔲVs f:aM(i} @E8EYpTڰ&m?j! ,r&zx%Juh_;j<32G;C$ȗI*5Y)ymcfu˴EcaIGrJ_Ӛˑ=s-g-Jb0H!~ҙ2PX WH-41~(; F)NQ!Le23ȡY+FڕM9QC&>p UV/a4S #/@2>H.n~ jYy"YXE6="Rƭar #;RkCUW=;3JniRsP T9\BڿW5a^neh'`l9=4ґaL1 S;0ÁãljQǷB>5Nn_9f ^HpV+-(`HkXBI3}FTt8|>;}`ۢbsrV3`?..Fjlal$)8Q3uVE*b_A&6B" yćMz{tՔe Fb⼸rb%9nϋDЖŽcW4m+mҸJ+q~dՎ9U-wϯJ‡~p4ԡ)4,'<;ι qmC380?U?yßu݋ćr/6_,%fX!oU}˓Nr%v˪Ii%i3v]s=U+q6P%l!OYF:zAZEmAϙSS$,Ч/ƅW)iKP ˨:~;ܤF%S2ր z>J}}!hA`\_'WtU = (oc)D>:>H9N 1sazc0/%G&ØA,!|(2~NҦʣx˚ 3E ȵ-l+NM (0z^Ftb܏ª@,է{y_޿&y0kd;2'O NIR6iǪ.S`9 8*d 7g2Ұh pp=aX7KM\`v*' r=o̖eZkt=Mp+EAyEqKZz1hkhcU^/D >*Ϣ٫ >7MXƱm$fjZq{, ÜK3WR@]=iaMH-@I{Mf `uhva\c`D2i{Cs}ܽ%+Y<?UEBPR*uNM(?KcWawt ꥢw/|IcûXxNYoCPFn'D8M?ۃOpRث4|-rU`4[' n 'NGafMp(.B?ń꿠:Y:'O&{ʠDS|"#P3  ͦ jUhƤ໥nn9 `'Y$7߭?*΅k b__DX["m=M?d_j%ToS`vr]VǺ\T5pkv} f=ʖ-aI(BGg _ECrY/?KR@'B9}t 7JOՓI Yٝ Վ)e|UǚMáfpt 8k#rW%:% _Q1c-IוsLqna*$hm-&ϙaR ~2p?OI)6֕ܖqr,n+1-RY Z4~StbscO;ǰͱ[G olV] uzCnJISh1?� U|x?(y47jCjksS{cѱ˰d^nNO&@T}]iL&f,ݗ(vF̰@{khaDil.Z8ԋ2*sqЛ.}E/ &{ $J@.~Дbиkb^-[r F>W_VI>Kg,`Y AReǏB K cs2q?h< {P% $˜Lncv&R@6.0Q1KqVpB;\n3 pw=2|&Q@(^ort蚩mY@A[lr3mřHufF{Yx 4Q:ŲƵq?+IBƁzCzתi e3. rug~jf}2ߠEE|EF+~== ^[2QN{.ّ+"%Z3|r.xxQ[tC1U0L]nos%wg+C}{5Qm13Pux]c)ȒdFWG0~zѓ)L}I)7R=(Xa3q.>zۃnBnlyIMqf̢F gB|2;;X5-wĖ. h?Oǩ?,\7ԛn[6iVuĬ!1C;* ^)cF1,_O"W>7H[a[9F=b+T72!%rayE+:G!&Ed~cx1o)ulz>U\Ӹ |^i&)\dygrt@l-tp8P'o ӊ ,1e+]$':SPM⍫cZ dWFc}ލt`u¼ǖ9D8=O6iHe3΅4L{YcS%Klm j͋ \ۧ[;R9⥼~j~FzK "w[\ 1rH#zoxٟƑTm/`NKKr5&7&*{E5q?[o߮(kępDd4eBiDߘDo2*HER>%/e6N)[G{7~D;{ZFRhwh6S^iYg7 R$ -Nn7Abm{[f)v%,[ϑSUZ\JßIRqLh-s8%H_&xNEfTpT*)Gg+DB7{ J51Uͨw vS*H`IOM…d%`;(3h:kcwYD+CSGz~HMyZ?lLS!c&஼W \EZ =$&kF׾SX̱&salN'@N 5̘Wj,`ڕ^0!gH. GC"Ot(Wy {4 ElɝޔJ9^ nLKɴ_oōH7-+yܗD='{ E+MXTkZ:[y4B27|ݾ :]iZM:o 0-0]q.νό_4iF\/F {>\"I@^|^eHm0BXMrFmZS/Ab+0CYd!v]&쒁zKoyǰd`=XwǴI6xda@<Kh?1>/'mR_xémߟ<}d%]J'-C'id5Cx 5<2HVm;P[Z{p?k4 J=19Vo2qjsb@"t V+=kp#uKBnk,L'%!E$`!j}b!iM~L~(w G>Hf)igVΥe6);HOJE9kvAJS6;(=:`^3A EȶX_!P*3*Ƭ`3|LQR|?(Wr&oCl7lΐoz8ͤ#y*T9FR`SycBNNO*,j&tgOw"Ye];v?lG"Q4}b"o*j~C[&q P |oF:3Zt"ʣҹfFIXkhS b7ɛ5T6߼0ЊTj>ߦ=$s'$ 6NZ{-,g bgﴴZf;BӉi}3!,bnGqѳ2] jxQIfʼ퇍1̭2V V WFrWV_q}Xykw=8#3^Dcڕ.biڲ۵/ :=>]#I]hx hT8YKܜk<=->367wTֱ|Ќ©! +z]YT6Z 7Lud] 8ݔV`W iMz~^N7SfGędnF@ c4/pBorw:@w!̓;s'S-L%CF36~bKԚ&zK.;E{ʹm$3կrK,x ]b'w)q1oSdphrX'x+4Lq _&6]6ef~Ekg =?󸶬ol8mzmkNC IerI稍9,_h $ae5g䁇?^кZ|SHc tmS(~T#OUDő'DYXv HB\.wݲ,|p\6(2SǷ_Qs=!˩87kfk,?o{>> 1en/뇁 zp``eMwu ;yJ_\#]=#"ģ]KZCaL3:\ƜɯLNNPi!W#d YJ!:df|\d?f)mnU jM'ZG%Ć# 7x:11߮я֜8v2ٶ!4L5IҘQL,#"I`Au-` my2[Ø ⚨ ^ߙUø/0G}#4D_81%lN.20t:ُt eq;MUDWH?#l(~Z?j23m@նa6 U-ђJ()̎:UҟjuG JZx 83{WڹF΀e~2 N0\moaTZLTw6`@ml[<>(FWbf` ׄ3u( Զ~r|O]Z-ĉa¾2X'ב7-*2ɧ9*k3n{XKE{/K/Eހ夾c-ky15r@͌ڼշ0p쪞W<m~AwΨ-B+E~6hZh `}J3YJL .} oYֱ')`-y : k8qގ-Ʋ4\/|mM;c(9#z%J$snFrvj2Px `JߣνՈBt#FW)p1L^jˡߞ5sxQɚ?Ut 9.MUHZ_IĂ]<(Bw"`4-0qw';4 t MUe0_`(ϗRE eqf/}#Araƚ݋8 +qH|Seo lN``4#yYWdWmo-Od4)eb؛ {OJp|0D5Te$'&~Enԃ8Tg7&p*l„V)#(^BN^8Q]Lzp EAXb!oWG]djz CJ'Ai,2m\oHGb@@1݇h"Q0]j9QwPyrڊL)O zP4PTQ{^C12OrԽrQOXT`*k5lbg7.xX~60 d8K?JmWarRܝ:3-Uk$QH*ck@czB$]r jko1?6B%!PggbzGG@BU.%F#R'fم%Ɯ*vFak{Rwqn[H1W6ս.FV8G{Zwꡆ) {{4et^?VA3*l5rz넟i',{/E g- Cu= ;#}D3xHIL{ÿ+h]LxX^9(5S*P9z xS[mf@GG}GqYn&?vQUur L (K0A V@c.w=GbgLQ9)~&%fiov'daڑ;)Tz J9VG$2jJ4f=GUl riNHdld-ڐo}b&F6 -i#WDi5 #G&@-3!<knx@u׵l;f*PIG7(roWF |׋&H)s:2=aC *yF I]>$|kF= V!UJq_IkAԆK؜\NE1q;8t"fAQlv^Y)O{<3#uRmWk y_g ?*Py)}Yz_g֥'B@/]B1ӊ'0o%٢)G {*Ɠ粁Y kKe~IEp:J?n\)*-y O*91M"5B| DOAzf֘W(_"\j>xòN9P*X}3)W=Bְ%:ʤ5ͱk{o yGO? #A+K':/{ڜn\Et]|5^Kv$H 3VSV8}W樤Jf DГ‰,wS {A7s~ZRxo"I"a>?dB(ܓk!Q :~_+"Ʌ7YCF$E-СACge8fy SdE+ct<ހ<8kBvbg @v2STK}qʻ׽xRj)Si>m ׷)D}oއAOVO6M d}o `.2O6`Wߏ@Mwn;Oe.k\LW.3f9 !o ’HsI®*FO,[m i8+d .)2 GQ,H_}i>̳|jleZ`P%W9-Ԃ3b䅎2u;ݐfBW䞧 F6洰TXˋ׶bt:~LH H2yk:>W۠r\ipnK֦ '΄=_e D8GjvA ?F{2RL33Y/bg!wʦ{SàU%WJF,Hv s5a4{ص9M*벿~Ox۵BN Q`=q8(IN}i~>oAADSZV_lY!H?(W>!ʓ_pG /P>?& NP멍UP3^ƲL7RwDb/Uʓ>0h9_)oH\РX0 s\-??_6}r!/jECh1 1%fL,D-vA9^MBM`1 AlI.5QAD%uG Sw0AIvaY`8p7>8 {J+intmqMvO0f=Iwb<9dM_t0!֚/ Wx@#]nDc2AY*aⷒ=$M:MIOznFă딖EȄum9X d 8=|OS)XG=Ti$JI:>(shʎ 뼣*,}CZ׍QqM :ySйޖe>̴"9*,FBJeP!1]֮VBĔ&e^6*yB߭OY_҂({{;BAsT{iŸwlz!5 ݦw"ߦ**,',x;Zo7/cVpf㔪*kSGUE3bAk5NoVo I+lk2?Wk풑q_j/]\B0R+ffLӢᔢ,eߕ?oC[p[[T_h M(kTn쩓YЪ^Dt_U3.U wV1ʷH 8/76ǩ4WY +1:|qD IrZjtdE>'I.ſ=`צ(!]҆p.^g.[hB|պR,|{-)9mUqoz\ ;{cz̤WSGJ#w<8C:3e,kzP g%\B Oy$ؿ1ptG,AmP qX Cvh4Q205azڬ[85@-a7v~:!Ï`Բ Ya'1RjނTުZ.yvٓAzJF_eW-LUZYgQP{n b/D[tE=SlmbeXmfDktGa ؖzIp?J)21 Xh]8X}Qw0.yAÔG[ȓ.W- _zS4bE uvI>$qZy 'K&#{ͭ9z eBo/* HwsV€jByP{e(DؒҵUTTzXƬGv1!LM V1.atT߿eM`T")myH (ƃ,=: "?q,h-;يw^&2}(qTmG6~ciEZ[OhŒe&Y#ggp5=){XG]|;ȒE-s x۹8,E"ϨB ="Iƿe81aׁt@z\WluT LE<%.=W0ەmX_Y6z`-wR<1,Tdvu9Je6f]V. :-&!Pl Vs1a)hvM4؆/?9~Mi="%=[r9-anDw1"zmQXF^\jN>7zBEnx5}gBO:(pE](x7͚wHar.DMd{8"YG{|[c\MRn8 L;]!eq]!XAbэ f $J%莰7 2~duhG76AMe]+{]f$ 2kk4-*?G%D@kw.T;acD_̰ |2gJJdžۏn>fH+{:H.O\8+5 46 a>]WڄAu*%yL}OM}jrJ8d_ג0f[B!bt&i0^{ܩlԫ4ZPVXoM'iaM>ʄ̙Î]FtrI95=fL`⪷tƕXe>BuHɨ_'GS@[ MӼf ?vϲY1Ѧ>"vUNp_҅*Z`Wa Ĭ5y`%F2+2ožqҊ];dS]c=Cn(3Caﲎ)m-gc1/`F5v/WLW!}n1E5Fd:ng2zS&8[u(ˋ`.IhK`N0 洛 udԦv>&*˃is2)>wnL?Pxu"1|9%3q:aNh%5)Zu ^ch!٭Q=u\u_C6{? `xA_7 UنM="bT{~{b*@dLwXD X>!c(+~KOmrX_1ύ_\(/p- ̣9DAr[<,V/FrW'/0"'I̍Ix`#p0߳Q`2.H0sC^~, 8 Is@uӫnO1x/n0u]f,ChL1ʍMi؇}8L5M(Kt8KyCu-IGOʼn#<%]*ͬٲ^s>G&4^yR;V*Fyf⢔+{$߮ ]#%qIZ0#]ԩA>Z7 '>$RGs_)h=I⭐?M   θ0.RY?ҋ#t$!N=@*\i»umT?QޝlY!@ui1`O& «2de/-Umw\h,$66DG.~QF[4AUM9|Phf)y4zEn!Z@іE:NnyN7WX_K4Jd?ɇQ%cޭgUU}M(b_wSpO|Q5$Sz5qJ[# ë#|y˿LZG@uHa &V" p!x~ S{5eI8yVe`;cؚ9,@u,ZxJ迯0=0u}#:"3l6Tz?ʸG7d#bI+Y*Y1^ΜΒD$YhHOvv Hۺ(I TlL ~Zf?բhLhc^kd=LrX@s@>OQ/Xe}w~čJX)TaW۝xK0<代$#yWa欕ˣPz?smg&yF/k&>Dnn+=@HU?2aKV>vzG\9`(pU󭤭( a UOU5B} OKIS~[q)Jpf>|duڢa.Pg4z004 :(:(y]4LmTuw x7qK/SR7+ص/UQR;]ik5W+䂯a<;XLH"U,/< ? ; 0f@xew>;-YʠE:֢]r7YGw , `CD|oHڡ^*XȴN0T:DWan9lkvx%V˩B2 [8 G9]HV;0:k,'©dUxx-}'U 9fhbQM%*$RjViSvl;;x}ZIF#/ږ-){IN[JAk 4M$ [\J䒕xND9q"0tT+vZa2$wc8N@\%/ lGbo!ISףԲp16' ϱDVRű>ئVb:VI6˫ /rdY}|UuFo.qԅ Ҡ r{ Y^` tr +gXۉJhTW4Vˣ`c3 R޸N;ҼGLt)&U=J[\%k]#^lSFZ$n!$舫K`KG0ԷZ 8/7nւtv`VN%hRsYf bJx v\ eM|=!" B5d MȂ+V"Z &[$#I9pR5 le.۹n:f 㓓KЭ~%#B;F`VM7]!ʼ7m+,  VLmS漦61#0dxte]!7ms"{T|&:-#_5 `,dVcO !,Rp"?rU~Yy*?AI7 RFh;Z1Q+=n=1TR0ZN3!:NC5x 'p]7rCb] (DLB/6vf>M>;O^_Iփ3nvwFo-Yld z9 f0}O!n Z$d` uL[e)wxdIAX1gb$=3W֖m#įKE|!d'rrߦfa?Ǎ[9}lvb4pu0Տ@Z&5sCX tK⮚īsilRȬ^0-X[Еi -8j\1w'Y!z|Y j VO` 3?}i/.u"~8k 3sޤABr:0\ʼikw5z(V>JNvUy7{MZg߇yaJ0HBçX*  "tL?=Vde>_Bnb GHR3b6~T ~ EmnnRQrT:To1+y_<:SleDӋ,!Z!9.v5TFJϲ'cj,_RRl_LBROd f߉ 61@D7PXUέes@FoŔ,y4{AK Yg*Zpw]bIXd hO]+R6:Zm'hA P8 CgRwوWgQsxN: Ut]Zݘ{:g$DEJ[r#nF/d7'j<=^(hǥN":!l/,e7U$Yh7K?{d,/]+g7p#L)a s`cZ9p̧A1>%F!4(1$De  ahc s4rJ+ /`q-Q4:X 9,VYeNhyx$c٣jOm3gW5u4V̈a:_`_I[Ծ xxW˰ɚРB5NZ MWZ7 :-l hVd\d r5^ @kcy,1/Z;+_ ~_ D*4U׆$ִ u:m\QbSI* `Ўq-yc"*M*]@`i6xIf_ 8FRl.$ rƫh)#?)&CFHSJ g&sgqC^_<0=^K|}L#;7|plZ⋉l1VAg'USqmk"ܷBGB2Qefą~1Hal'b}Z0|H =GNkH0SugC0)D@Lbc~Hmn\uE)ďYn3;=\o \IaʘagѬww~zCY|RmP)@>v.c(xJhd8euӻL~1Zu^PTP|BϬڑXƻB+QDw;Y( hUX3:̑fs~eA$F4R{\k`dw..7swwdW\*+*&_~5UoȽ:IHf|$ktc L=P( Ys4(ahfZ+)ؼTJ<"n|P?ѝ#v>2ACbpw $>|w=kB#a{Ʀߘ큶0o!n$i0 X#b tNI8B$03Ub;V)hT^;b16$7ԱxbM"Yϧ- vї` v<ȅ뼚;ύ.77s :Ќ5#`42(baHyP?]pÉ"LwLqM`0% }=4chg;'-Y1M~~mqvԁ, [j;-{vC%33_F I/A?IP,jz Qy<:ɳ.\ں9(xl gp')ws웬Il{2`W( kL]j$B2I{GZ`'nxT+2y"J^7i]>-C :ϝgHT5oZ*l+quKNӌv eTZrdH$abQrV(zl<<: B>Fs'5uoʰ[4f,bQ1$dַn $F;yq'*v/DM"V|/I>/LJ[*DCV }S?=qᛧ0!Y^F: /5Oʺ[~?T-*O0hЊuZºc{$&n.fG53ֆ&߆XK|;VrcRB2%tJgBv~NB0"⁜"ф?<m>MAЎ;xRJsȫZԁ;6@}.||n?ǟ->^YG~fs!Ux^d$:]'7Fe# ㇍zM1, =0+%'> [ \gbofl[͝vl6uN$|ggVX(dmtЧL}~v\6]]CaD:)jae!Wz(P, 0f`PWl5*nX|zCKTdh3&ܾjiU: -tlw1;}0[ PR[;+zCXg ǩn:|ic]H75/o֮#-5bm7UX0\_P߁mww`޷c|zkONa|:cR6(k}u/|/}km-u`k8TApդ% ՙ7>om~\/%(' NORPTԛoPoO[O%ܶv'r+*=0=H w=!#:h6)c Y UM u6 wWݾgaE{55e՝C '3P"lj<Vf}`^/b7 IxE,J)\cXRDB(2Hu1.ܙ2PQO Ӻ%yk/1[y~3v"D9aj$z!C`p(2$n Ϝ-[Akf0h-\ LQz݀}x; I tvd Vzتgy\ZO[c95 @:0E_b ]#d# Kbp&;bamjhqlHgOfJC|d)wz9rtԻF[JaxLH'CD>듁g&=Mtt/aX y&pw 0%6't&ÈUBTOzBu6Z'tMdf3GqDS $u\y-l^iW ѯ7 Qǚ\f.UyQMV!\ ƌ{l | U;y{fZQ7c aVؽ֗t5y8n:VfwCWM iOM *F:ٰ]7k;1TȊ$ilUnR(S˂g(jze~>KOSDZ[o4 ĉ ̾aЩ8ܳҒ߇|//&``z"Z? fa4W8?+ykGK8h Ըǰv5R=DԖ U7nK.0P^k{ S~J䮯ȣr _MKXCm%_~Lϳ 66vAK/AH>\ P9X!])?|p <*r#k#f4kE}svAEWT!;a`xͼ@Q 2 k-抵_OA5EcU9E*4I l;.NOjHN[7ZޟjABDiXʦ/{A&!"e#BGI\SHL|uj|]b7y>:k$ PLLl?:x[XXlBKS՜#C>tI?3\ď *$ssr*UCN^"CrC/ ">E;+$bޒw9bfd,OyxZd!J=qN0ؽBSK~p\%Y{UW<49"`+A5&֑6 /܂Ս!sŬx32Ǜ3>`i=@(">'Z% ku4`E+lnJDПX5G Xѹ`hU/1+JY4wh`p-^H@hRY7gkK*ףdۊkV^D4CQYjRa"@Nx5e/25So?EZ &` ;.TWFD;»REη=PMy.`ƙhN2Fj2-vc׀xl ҥf>%dW߁w۱jmg[uCT~jZxTǝf?ΏP,گI@^%}&q+99?M^;KJ8HT. $=@oXy 6A-cYW_$ߠ4yY' 9 `@Aج{,AH{ưW֝,ERA tJmCI:3F>=4YmilzA\^>%'֖- mL5ROЙd67IM_FX?qDp.Zv]YX^2oq8!6C!&tXx^F_ qޤ&1+]K˿gk9K=V7GF{$Z Ίd\o8sJҕ/bF8kTA,IsX7ū\ @tKLjaw8-qD_CQߥn {]b8 >6lTk;uN+*B̈]٣}zn%#rE]J+4-]̦V7!wd1-aԜK:jc@ 4wQԩ>!Y*a ŝr.|$yemFU8͒_jZ(U`*hA EP vn4UYS+$TA-P~e2kŽhߖO23/~j-Y:@ Qds.q ƘK[9kV#YO[r]x<еch>oߋzxNrWhԏg Zϴo8{V4^'L lit%IFй$b5fVb{i!\ښ7~M}D`n4`nX%҄/65 d |0|[Sbt{4A7]~N*йTzmlXxkT烯A_5NTx]|m̈7ti:$@H:#cR/Ʒ 1ϬI`-۸=H^eWx~ŧjEY ,x4.; 'JUrE!>nA}jQsTzb.ժuhԛ(H 'P8u>\aʅNGFeI{b6ͧYGY d"Cˬ +"HOGI ˳Zx#.7qjMajݍfy[@DA| MR?ev0&j:SA!܊R$ T}P.:#p-t@Wdp6(VΊ&vm~H2,?Dmo_d)OQ@Πn%vT4u Y7Q/B_GќArRQu\).z\-wC3q-'DcxN?/m3ŦCo[-~SK?#|gH'-r3QDL kPrb]O2OU)/)qȞQ"stmMRmYp6EfՁN(i} ?vTԪ̲d3B5r`Yw:֣v]ʳw>=({/KiVES-^_s Iw  MH;;q֢D&K'dXB$G,irEv33 U4碫1e)8a[JTQ@i}u2cWL S+ҖtwE#ewWmK+Q"LBG1iSTLFoVs~ _*9۩+6 y 4 @&OW*D*a5M6S73cל̩_QrLyfkJ/$yh|:F4&[y(֔I}qDJ,7Zd| zI_/M͘pR6m]d ADNk-;}N9„ob!.#(^Z`}5mHpkG6 ~y'W邔Au$EecvtA3u(V)<]h+t~u]ߖBfZu~qY3"'ek놲:*z5?dS*4e7(_[XW)ה]r-6Y$9.|rl,E9#D{~ЙM.o?Q!A(đ`Y1jo{jᄋzZ SW/~ȫې!|"VLm׿D ʅ ,?]^z%a]}YW"6sV27kh(m:@FNI)GhDbO1Ҙ_A(1@۵ӂߢGp\>:R-w1A^Rlb/5ĵ&`b{ANUGe6mw챏0,SnF$OS|= _,IKԥq؍?z 0`ՄBXA8|Yo%SN`r "gߋ%0 <(ƌTʼnd׶g'AXiv.XxmEHԲ?|WIs96w' 1B.=VdO)һ` L 1kLmH&^}Po URA~ X<.M-K Àqk' Dz/h'2H6tpWR)ui}uyU?yB.Ke>D#rk7#"(LQD,%ry^Լ%1D 7L[!Uv88ģ߀ ءk[h.Qc೘`"L竣.ɻA"|/# 91#Ve58 ѱ8DwYA4 >e^StHí^&%-ǥz}}Q "3$qkՆVU g#3vҶƈ"tHbU mnJ;|pVʖyaf_-7r&7(6F'ꎲA nħ8R[A0kE*j81(va"M)g4S>T\:'xk T{zFNVyxb\*Ո[;bӂ.ߵCҘzTjgY [)0ʣGLE0?och}8tFR. k+{Ǹ8Sg *7vE= 5L%PƴĠ$ya/|KW{Nm\ H>2i^AK Թls-uCN|_YZz't#_C=2羑̱&Jh{HJX+oG=mn7{DUbcqk,sG/ܴpOU *p)-P'HY@>F('OhTȫUeu`ӸF] Kyj_!PP g׈dKAdvn6^pk^9h!oT'B28}DmI(1_02A|}"zR[/#mi``n!'K 4l&x=~7r҂an7Yx>HkX8A8qyF?Es.]e\Y,񩾁L FQ 2 F.(«RK"H9SϹXjP0tWuq \V@YoͶb6J@u t4ol`jnziM9JtE@U~@UzrXX˪ N@R"ĦLgQ~*&m!58aN]Sɒ@K*:$mw5y:j/3Ltv[',d 0gpܾH+q5.,ҽ} EbKq2CуO9,$D}F̕;tDkm=sk#XW…}uy^ :kݱ&zug :~i DzA<̋d> uYeOjbI(kj=/B$s\yf:{8߿a3G-0|wMՇ;QC9oHފC+מϖB@0k5fդ4!Qד`\PWsK M8A A7Rcz\Y4:q ͮy6A9%2i㔯YfQ1P *d/Ds˶Vfb/#3nb°Ta?d~@kn:@ZkZۺ- $bdcjOrýؖԸR /$A/_)$`1VU: )9dP)'|¥Ib@aw+ v PVbC#6ߘa}{vI#01ΛF}CPw'1V;xOjHBM:=IzgH˄ S0DD RT UWov,?: c)XX|1g Wkxl"{ _XF=Dr@W?oFdH{pʶTYBK8gXƚcV8-L W |I6K.,~c`kw ^LyۆT4CӮo/GP-rSt1;9%4l[[>u=&xf4܂JW`b3OX:*KėXVYR+Ьߊdl1iV1c kO<˔&;赌xH\?6;'*ΤÖZ yJ{/vxwnkowFRi Oj`&ކU ^Z^rI"s^y7~*\ryE,9DIMHS8Yf@״EI*X%-!}a"qN N r:?JkM+lϫفX 4)J j4ipb*8c!!Atevl>yz67rLc:sϳ,}hKg7Uʹv1{GA8 sT?~mݺ!s7*La΂/"l %!\~(R bvTԄC8"ګebp=釴1*P3݊ә:{ މVR%<޴H7{6觇3өje.=U3+փ9= 8 %mX;ENJlL4l7ɿJ\mVQv+ׁ$uL܊fzHty(g&JtݜSo uRxE8vP䔔} sTn-ap4BqGBe#<В /m #n@RIlUk+n$agWDRM:߲FK.J$ík3Q.=l:xB=f/F *'{Jk-2aec*ukdߗ PQ7f!AkI!O%޻pb7>XCc,&0'CQ/]Y}+7~Q"wC0x|VK5dKuy H{Jk0m6}ӅO-)ܛM6[l` i0KT3uOA4WZFc{UVѼ[ϓ+F(89[\7+R'3RE`f/ t֦.H?PŠF'@]H ĆM?UUuDLww [' t;phSBE_[ByDFb :Wv?dS۝y͹ᅰ#;Z:iЩ LG\޵! ']q>1m-" ,XPأٖ8RO4anFh/G}Rg yk?~ˇ9#gh,1X2ZCbj6C(`p{hi28^عK6ȣswu rETxEOin-_tl9VxB !?+2GfqVFMT1n)Pk[w\+79uڗI9XB_ŋDp2Eg4N(~ }Bꬪ4.IkW`NS';H(vftQGnq=E} >tGhBE25%`FVA{[f-DM%_:I< bLc&_,r)Dvnr8+yd2@ r>5?:"Z$muY>ӧ {!Hz XvXHGv-…[Od<#sv#}O(,a"zR2Ki:c>*"uhDF٬N~n)"* B3 AyD vA"\e3/P3ʜ.:.6W+}7lkk8%g'R"kf& q^]"ؒ}p[8,޹[%R,5%XknŏF {F*w\YPY;Xi|uG)jAmFs~:&szo RBC;DW Z!$(6Ō-Ę}^A>Z~h{?DoN&1{~产h!fa2ZˤH: ",[c)4;. VkjQW~ײaL_հ-`p!&OΎ5\T~bVE2yѧI.PkuY 8%芥JK8=V:7 2-eư%(b ~:z l&: sIh>P ib9Y9ړf^6K1+ߴRV*=Wsb`(Hsc_}v-m}C2uM@Q9>tܐ :h)ȲoO^hKܖt˵N|'ف;/rMJU/條qN V=+-~^g4 ن5 ZPc`Hg>CAŗ˾R THסĴSp憘´@wlο9+9Nͮz3u.HilxVb͎_I_Gz"1ɪU, *7vމ1tG <_,۔*LѕvT셃M2OeboEm㻺"R$Χgh'%_$ˋYRHNͩg(2 Gp%!~m.I"ifZ4/gO`q5(tF?q;8C.YpPJ %Ÿ3϶yԁIMٻfӉK4hYQ 'm †K4+3O\#HUۅ Q?/Xw'pH=dcEIMdkvێ7?.іmϖnL8KZdMRwBr GG.fj ۉBoqkA¾؋kew,2֫7F:ؼx{v3*7?5Ia- :(r9I߯?Չ7KZia49 l7!Ā;ao,ZgQic[ C& =+Э{SvG 4[=@Luf+⬶oo0̼v/EjhPIR}_E_#p|ۢ~NdM%QЃ>Ч>ͥPa4/c10^q[92ڹC%Vn A g`7oW9T7MA;u]DCULS%dG 4b^th(r G瘮 \z@o-8qSwFԞMՉ)M}{=Ψc3uE?=%# !{)h{9gf u6s_`H{8 #Uهk70<c\%H=JH / ڟ`0Ŭ`ָh/xiخ0G:tSМdB}&<4Uw ﭲG+xbfD(NAQ U1}˾(b>3v-2N;4.N P%|Iۣ@(Y?3ghn.@ՉOi`*=p7 "B9>Q`Ɩֶ 9G76lR httB)pcac̩$Tmִj Mݧߏ+d䱺=ONX/%x_&|.Ckv [F9ؠh4s9gR;{gD+GR?jw ꛓWUf7T2e}i 4F(R-* 6#F#3uEvX]nosՙZoKE@]yZ`\{ [qUhKDC0INg<ờ] ZZfqP*dPK^ԉm) i]]-1z3"yi50 6@ot~T'gigD @z%+dH,>ïu%&9D|6#M4ur]S`Ƶ/} m^N:GE~_Vqúv'EDބ\`|m* ߩ3wQ"4%4 }h>[6E/$SRC$jHy[醒st帓}wWHZ{I&@ {@F4ծ+`8_tOMNw%\DVT- _;nZJu0-f$%zǻQ=rijvѥzW52\;L]d ,웆=cu6eQa@6UOs&F0wI^jqpGMcg:0`l9tQ@7^6i| 5\o1Dge+v#T)g75~02.9τǨztc۲[jvb&"hB[)GQrLQy,4(OJX:_2=\ƿ]Zvv7f8 >IB <TK{ ,#Ƶ%~JH=٨݌ QY/A{fGVʴ cܗFD6N_|+|/K T{̥a6jfVvM4eP^qƘ+UlZ73xiGg[ e0 h(>0L̡rk/Tnx _T+xxOuWs wnQ H73Ql/Lh-%t _ېw^-|Q1y(; r)LmDHTJlDAj1X]=ȽMz_`a)un0n]2?Mސ-nYI0p~ 3br胿x4wV718gdzkĕ6Bewph-.ћ0 Kb! I8%Q%)n5B1+)=Rdk87s=HVj~!uq!Ha&. Z&$Q<Lד*SdZ_a y9Ť;1ug7w’Iժ~ R[0} ՛J [1lS4@T_)z 9u1"H3ŢG. ~n,ÅCk|-FGl|z2,9Pe5WrfC|&0VZ$( kx 1\ZZljrG#adc5錸!;W3ؿtMud+6^ؔ7=^.a0|{fT~ 7r_wIf ce:[v]cq,|WqyeҗÙgs<7gY8;N9bw">/mAh2HW@`yz4mu!)λg<|_n 3}kb }^/\IHys({ଛ\/SA/e|o"2Oh7 8­ştVN#גlH}h ;bRj]Z=Yn^?JUw& ObQ1#ߙЅi Pv~mq̼)%"M}pxH.<cb1XNա?Z>%2BSL]IIMt /)kaɼ=W%T^a᎓eY-߻z>J(͏z\3$WYl7+{*o!c(SşOE$;ז۠泝:xMp  p˅oXMWKTCK-y6}he4`MvA*F_+yM>=o%Y6p_,rC"դ b I dSY{%l ktiݝy.P;I0GQ\rC XTqϫWpۅXư&..CUxn=*uz6Ro޹,s?Lؕo6{(|}?ka0D?À*w.#%+`)EX`*ݜ@{*-:.W&ftz@bnFS} nw-4&#`k# "u! 58Cbu㳗̭#G.͸wm "F@Yș=**}F `KliYtQ- IWGWPOPHFU1.X;$ Q=QÝeG"{0;^)";FP04f|#q1mgs꫽Rm9S ^gºV$jL:ն!f6YDomi'pOdBueE(B0ca*)=A>=*Z_ n5A/;\ZqGi'}WVp_s@~}82b7P_/sY?C܈oގ`:ڑ" EpNg\ʤf,ΤEvnjO NaUΎ]_ M%ZL>`'2!{!qk 2Wz=ngAЗb[XzQMԐ^zrr(d;tk$Qn~ͤ ʆ̈́7#VRM`5˟Sho! |;Ή\r[ _)=u]TB7QQ.j<#Vg]"j` Eu4Zd?:3pa\Ĕ7m$;e8]siL@)'{K<m1n +[l0}™ceK>'z)g ]]0C+ZnR_BoK瑛TK XH2QU24gH-,m:IBScxb8KrEMuKx<Û?)V&#C\ -2e&~urb&9)x46:M][E5JPLFMq+Y3x̟}79 {Z[lrRBN^sbłj 71/2\v0$rc !v%p0¶DKrZNjY&>pmIn w =\%? j{DΈ8ݥY #n4y*ccp1-S^]n35R7[5A'꣤Yr%$h4$QB}dy򒟑 /1/8fjꭵy|L JSַv"Ƒ'BԠ54%L>^eɯ dv~o|x·Rix[ɹ)jN{3 MJs\" [ kHPJU3f|{0>( ׀>AtdX ^TL mV[0uVv]X[_|hYh p$|`jB`cFΞ (Q{ b9Or0' Uy\)5YTV4S@w3]L_DwU%G3mFc>a`!EŹ1hgH<˚B3"d´Vwt15N6? Wod CEQ4_U,^zOia" ;~dے47?YrqZi:Y_ %LΟdۙGSy 4;O NGvugu?<;2ǙyYe#30.շdXx <Ơdpj]@ ڱbم!׋zL"wpc_2( '4V£ πqBHsН &qs$,h&dBh $d1SK3&3W1G3tiLF!7o} &qGb@+\{}^LYZ-@a`?YH(4BдB#yI3G3ܡL<3$Yvd~G첂6=9x u˯3K)8v얘=s=igv0o{ :mYp\S=1d1k[buk{3q25H{wrLi#_&>}KoVN0L煇l?sKJ6uC2:H70GX5hmm#ܨC8 錗:M,^A' 5+ ;j^F{w5T<#@Ť)u4jh8rSDFe`;pi|B$i`OOtakKmMucݞti U -Y9Q?1R*HP#cjz7x3C52W S4jVn7h%?rArLja8Edrk&Ժb.$M:?%LjRVxgu Lho.F(֫gTkٚ&)$|N|%ecr˚{B鰥YVÙj,bn4Q6l|ld<[~e;XQ0Nqi\(/bqGMo2R2,9 +H\qc}!#," $D2g&[2)2{nH;|ˈuvSDIY`<V?SucѢ,"ȏ⛥ϓo|U_]&ީ\Tau]<9K_lnOȅDrot/7h}zbpS*<jRF.j #z;NV;BYKa[Ü>\mmT=\#b WƩTke淟~N q-^-qh4Hԫi|!rL\g jE$Ǵ nYu/+RnFwbQ8m>hTlok(ܙE|6+| H`JE\bObdlA70(g0ϸk]@ʽN'eGi[p3ͫiUɍRջؙ{!_{]X[8:ia`E}w 3r(W&Ry meIDz49kA?@"O1 6^i 3kcFjl$ 9iKr m)MPKqg~ghDŽ+jrH7+CH0Az/d$Bq`&OG4J!OE7WDҖ/4^WT6;`5]ڭ wWnjt#ՔA/vCJ*V+l6iZ1@>_>spYm]1cz`0cTح,%5$bAhBE]J(fK2~2e|ah{P v-OA[fȣ,xGԕ]vQ1%+P -C!YL`n 峂ؽjMN.AX=x6Ժ۴AƵ1<%ǯD!ٜN} X!>seF4lჴ2~!v1tdGH2x'qIzj0g1[AOQaK1dL^FCJ< YZ5ަƜ{ G٣yLnb~6Y#6LX #\`M/ TX\r|TsAP8zJ^c_L? h L=*VK|[CTa8DU {I[]'I%)'el& +7Q18wq}cMsӈA1#^\'shN>]d91ϲ:֓ NxE`?x\NQò) 6F)5K4Vw,QР5Ufe0 2hXN*w]EN\1zn!ÿ(j0QQ $k!}kL0p]YAG;rr@D񪎷QLD=TLG/DX58N3m3A>6uC[KMk捺 w$!S:G!Y 1D6ؿLjjG %*+*D@, cy_AWߑ`}#ôtEa54Uc7~H ^*FH+{?ٞl&?->.-quȓ6bPm+ "1R.O6tQ}DӘ_šU-5;Q'9=W=- Xk)lIZreeΐzk$DmN.d`tEJ? %&_?^5E$=u. /MOe'v3 s6k͠eL63F[ũ] A2qw u" ~$1Nq߷9|[zsщyc$u}ȗR2U%[#l0Gm5G'2%ԌWIdU:MG!؛)HLEh*k[YXY %E oyZ+Vyצ(D.1t嶧^JSӎ^{X":u'Q^K?+"s צcҫN3o!^͉զF)(7䆸cw7ؠ)s3?G.k/IҮ>?P+:GQ|$cdؚU"_ȫ:S1`*,)t[M݄j#;6oB8[1b2sCT eO/"6<҃G:h~|h-׬q$;DVotUĈ|6t&e%Gv[I*"iՉ7 K@D5Np>:Ζbm-f <U!w`IZTBfCUBr ŽF7O޻,8or 9K/[ՌgJ!WVQlX r}\) ;[EhV QƐklOP_MM6ph2/3@ &>ҪR04Xd !>xXNOF$eE #M^4/P4&m@MS/,ԨN|0oIvBAitf) ˆQLL#bn-YAI1,"aq0ZAջt@W.^~ -")ۘFZfo`~tMG$LH@΢Tc3/ QtPmX-f͙a4sB-o*>LJ0DO<e n+$tzBf]W'izҊ{xH=CIec_\k@r eeDU4^`E8d̍MeúeK!5掎Iq@&=f&KE,2 2H7*;k UZa~˂0d"x<˘o. RJI瑌A~/@q+ r.LCX#4xFx!T M%QYbC\HOf4NH^wNs_p?#$ojq#goGmiO292WU#%Ctר5i-]0f>" ;aR kA8fj;?`o``=v&޻ɂn/ttF3ϰ s ^EdX<ySӒ ]U*4iy3avΓ:2Ͻ&aYKXէմw˴=.c@ݓ:W]j̩{]BxFr]Y:>Y0w}rd[˰,֜WX.);kVI$ VMz# &6 ņط7t #N,jYC^E %=AѼށ|B)/zz¤Jŕ*ߞW*m! IL(}64홊FΐsrRaP1)\ْ#MQz_:}eǹnL2p4ՋҀ/]|-189\O1R}~RDI2l=$E۷#1;"5N! ?lEkh+b:@G 2a "e=  p,䲯f= Tl;Fif"2s2%pPqFa$/D cAeVTS[᧎]^A nT9Qw clhdzKK6> 2&1!Wi_sjhDR~-DwÒ{k#k"7RqMPwHz`BqIGaE @ ǹẉ2gM*'`+_ڽ|̘W%My rJ/;$BNzSZ5yYWյ1[P0MK9;AQ &JC~W,<hVP˕n TkSR$A jR3"m!W>2i 9Xrz<($>#ޠ#EbE x%8% miX& OH]0}BtiŌNhĝW]nA ll9z5;&9 rt6X٩̾)AL uħFc3uied ~cAT^}-*6B9ؿ(i% VZȤ;^|̫RveF_PlY`I- 9lrstT8;ȳ[ǗMj ^-9μ9}j]XwYw*ru٭iUY׊p))<=oo'99MUR(qQ#w-Eث7a,<FF)oS3#jc C?ZtM7O.<nU&h@v0r}`DY 2O<# ل(a[ z,6^%uԔ[Ld^+v*.㴈\䧂I$1nPG $<@^wa,U/= rpS2N>Kq\zM:QQERݪiVeqQ6.)ȏxK6Ι!W_1#y7E Ezcm/wA"~/O+> Ms1b¯KfŠNJt".ε6L"O_a5 V‰4mdЏCޅ2*rFZ]m3_k@KՋ+U:yۧj+ p`S ļ,1XbDX-m]qh9~򀐅(΢(mWQҐqrn7U3J]bXVǁ0[%^6N`溱+/-9Xdn( a(/?Xn,w%I/j` x!g.nfԪ7`zjEb;s[Wf1m1B{%[lcѓx{}Xrك7fq>ivuZk_vi3 zQJ+@ s3Q:kðXsϢĜڍCfpӯ)5^kK +9`1G[͐&u'uthzLM9d'#k^N:]RN )ڜzڬ@%w]$ڙWx .-)m}{;9s `amLi;ve&j^SY''m$QP r#3Ҏ⢉x: _qNN jÉd"Oخ&wL g?ÈK%[tsArxhޏLZ 'ʨ[N_h+f.ߦ3Mp1mVLL#i^oG ͤ(Z WLX8`uV.1黐|bh7CKA9t!1Hm~*fmRCA&Gr^i j~Lp2(pZwM˵1=gEbuԳ0]Fk]DQhL)"OBPS\T[`)kj~5].8U8Ue;Ď6=y#dKu.6FkIYPOj˗Ux"oD7#US^⧮{I,Uȕt!am׷l\s:ն6Tuf rZYf[cҩ(w]R/nf7\s!r8 : "P %{qQPC\V qIAnyUg)ZK5fHr0:"`B{鱽FHl |SI7N bQ& <6^!RPe8gG]bGY7?NuB8< ftQcATblK 2[d;./4D9:(JRp+1&Y~_~–1;Y_-׼Oӭ1ǸcӃ$Ht/zЂ̨03-2?ڿ+}l\(-{D+E@  Зa@ҍ!>6l\虼 G_{/߰kgzwCQ(YD|q?{ TlCjf!_`ip7׷7$/&j6̀}IU.٩@'J񀟙O@ZbfCrfExBg&Ӗ0*=mb402x gD,} 1moYz* ŊnW̊HY'6x?^GAKhf&VD+:LFL }WkoR#\'# 2J4گ|lB TӎQ,֒J6^S0U 0;ҹ@{wvkq4ÅEiT9W'6"p ̋aGk.1ZngɥnʻZƩh{I?ńhvc-9^rZyOtkP2^B¸/H:hlg9a50vk@4i߫/n˹>x?LQWDxVw;loBwv|t|sm#E`\cR:/r  =-m5NEvhJndž ԯ!gk_vW h 9=#| G^}|N1cQ&p콏)EX2Rofh:vj)O a(gtIi&UazL8FC2 7m +pqD@mXzbKΊzU<*̚P+M  `ՔN!_yyN3=Y;,ܪե;C#c_̐UiU ArKsmȠx3LiCvZP7'y&Q] ֬,l0X!Iê9;(}N?I+(jvXTw`o (eN>cO~@0`dF͝}~21s=0:k {PC0L`.IT9\ EVllx# 1ױӆ%A G02`qplr* PXm@AҝϏ_U1'HaԳ85LV9!/t*ljrJ J7 ҕ ѵkZ bt64§O0\n޾',I:AI9ix0lY!٘|"1<7`oP]/4Xvl^ciشRL8-L _]|APbjnUns˺-f; ɷ:p(}Fu?z+UhzKDH] Z~N)K]zf >[)UYU-3dms:0^z0FUWU-WY5<\0~DX1v$r &a4v1+(?^8*= ~dDT#o3S谍qK oudD-N4#r?50GJ|t#>Iộ;qyH2] b˚8Gדڴ00HYIKN E VSh'o| /'G_FM=-e>@H1q//-30tj|o";;GX&Pu tEe_X$F07&En@:蝀 ᲡYnTWDg&vsYӁ+3&(:RCʟJ|Z޿3:i9ºS*QRҿn4dXΛ6K-seQɞ\xEW6K9HY.e`Px㫦 n4,v\`p=uǧɊ?NPX*qd+eHf{61PP $4:N:͙S9 㞕Fͳ..z]U/z¢c U8FádHJ9R/W2 pTlE[nHR$TW%d0"#k_ :oJ6d9 =?t?M<uԮv>u:=?!Saaoy{sjLe7=8\Q]4Zʕp{\bU7Sey.1 ~QD>:p?V+].4N愡sXA*-T^mM;Ʒd Se0d5@[_jp7ZBՒ'/ZrP<[*#)ZQ8DGC-PAXNI7j!)FqrntyNW mݕWk4@y_kڋ[A HF`(P5N=YwDγ>ݔ=Cä#d濷*wLj{i{fwM~,5EcfZYtxK=6FZݚey|*gxCrGLd2Kýzgwa;[: v7^Z``CzߵKV>jyT^C`dBe l^}xh,lzN #& ho<s(-ȸ˗C$>cʣ 18&sӹDb=ͽS=ә}wplϏ7 @Ǣa Lm)f}ts{>b)ˆƸ; P\5찍?ﮂGl-;-٘鉨+f}3k42@M 9aPw\1pmD=/ JA)9ڔFUְEkɑ67@Cq#FLv{s](.^3{|{0d1+,7đ aO*`ūPN2cM1XWe,2١g! ?N '!r~"BO.u|cgl"?P pI(^{L`UqOKlЅ외TĈ$A))VHp=YgpӺ4mv%Ǯ9|Rl2tsO'{S @0۱KA2Aى?'Ŀ $K6X%nk|ucPc3~Qp^b"nc^Vr^6fvWHղ&o]`u׉/͕-3W9"yVoPuY'~N&{o|u-j~8˸/W'4J `4q4osIWzhBGI=2@vm-2ҩhҦ,6s'CX [=]b^(H7PiBA@}]YP7ܠԖ>l",m0 i re lR9HMb}4Lbˑ۷IdJ@?>W»O$ ˰rףSQt5_ϛ(c,p`(s%<4gG;{BdR C'j/2{ 194 R2 6*tn~YzKaP1$XS>ܫH|+u3jh䁰_DӺ ҫ l+B@g"~ OM@3wМc?`IN4VIԥ7hpԫ V#G;x9:7!{0^l (sﭤ~h+}H0bS_ٮl`ie*5NVߢ( *F*zri鯴$RVm孞 |xER 7Nr"\l>Ԙ|5$ɨQn\rtd ,uщIKkFpOqE^H''D12(r{} cV<bWR#Nc~LJ,A~xqQa~Bxb!k/ܮhapW֡mQأnW`Ƽ0>e}܆*({# eٱ(Bjx O q?cM"7q3^Qh`?R;ScS!W i&4^O|0ς3ﻀ@c̰;arDR3Ԕ1mTX4膊 l *g-ɸwx%n6Nz30NjN aUdl/m6d0m7YΠ%G+h-ƢkbҒ ~҈:X1#Pn^~0΃w6=G x LϖrE X`& ;P n:_hQS}%:`$lwcep& O`C I WFh6C1'0&K\ʈѫ t?6ZMWF-oNZl6~CE'Jd@1\cE0#s$6A]A#'0©{(0 Gc6q/~4j0&ʩlYB/7E y֔xnFuNiW\랩m_YJboęmTaه01x-x)ƟMmKLo$@v>Վ'&&*0iC|csGȝz3Z n?u-0~+xSBKj,_W' F+iɼT'%rz)eu1O#@ީ &FMba;҆U Ul9Mâ͹[Jm` <zPi# 0u )3!Ftft2u`[hDj$=o Xc皡eWn|b8Ca8_}M]e`v?Ęk,ǡbJ񃭖 kQ !h`җ4Rmou|Ͱ`#j0&NQ)*݈Kӭ\- Ynn~ybpD aYy[f!-L†yF[9;Ϳ%̣"1,Wps'KtT)+¥,J1j\0lBd},wU\{D1L0 צӔuLhۯ|s ?a5lFQZw_kC$&BF7إv4AivȚ*h$MMρ t>} Cr+kIilAD뚋?`쓒4׻'8 ٽ\0BKE IנjRW&SM|8gSzBm&AƞzɣB` \uJl47YT̲![L yjW !#Cr0v(j[h*;,7?tя!fFL2&,D4C-J~I#٦ꆸ4jpK>xE K?``g41c긖I6 @xӵw~xt]-aE ]C'9e; ؟ꌓ\Gv†r}6,R ӥIs8Yi>E[(iE # 梆M׏qmlF'Խ2F'ݘ%\su$٘bo)c1:dN&$6w\I{ϚŲl3O {2%9-j~k橎,.oFĠe't$8#$owz2',#[Glϝ1,!52tb3)L)K%]F KѸM Qb( H!O f &ˮd|L=E^,T0%NΝ(|)nf.B64;6ƱE@Ke6 ȝ5mj,XӓjyZu[DT>_.(ĵj1gb笶*D"^ gZcv8GC&Fw}nv '({-&, %f9)yzxiQ $*}g.*"5޶x2 e/]7VOڰ@4]2gQ 2fTKHx4'sͬմn^n7 מX]f7qW̸!1턾brf}RH9ꖅ1;fV 'p[) 3{/l7"~.\= K[{aÜuЈK@ `ݜϏ M+ꪖ|ԟrU!/ P؏9CٛF*Aƒlp(\50Y滕kt0R."[/XbHշA:ª?$0enkom;xl5L+mjxwi?b7f}z&f 3wHb 9:(~3uXpSEü x-Ʈ@;zI c[d*ֱUCRw).yfY H켓ZJM] FAXp;N۱,ܶ814>YZh~δ YP`|<_d-)>V\$S۠'kvyGŬ6r)*$ں˧6x(Ap]po3eV3)uv1)۞Η)x9lZJD@T0'R(OvZ"Bﮐa7>\ҟBc$d^[" ߔQ[m uKV`JV;-v~KH[n_?U+9 SZkr2иj:]cH;k#2aCz[,|]v@yʾa/LU\{d;|u%=0 Ba=ȩhEaӱZ ý7Ϙ;&=Ȇ`ؠ.FS5# rGlhwG+7؀7T-WB\ Y*YiUkiTV~mWቶ\rl9N#nf MF'Up %[@ut͝ߍ뼔U hFk ӦN &~xrFU1/ׁ?B?MkS KoepD҄ & "ɏ\KMp$_tKN!2p:x7C{q>m \h3xdݐc @ʻ.׮.E?nc~)L箞ǚ1%_a>g0giyn5vZe³Buq_KF-TD"4$$`jsop[筂낉- &OU\Lh Q< yUWT̥E-U'63ۋ pFA/H&;LvDO r1/y?(d "|9$ZgjTBuAdghR6}U(nQ&,,֌=c%E/ !wn8Y2p3pxt޷!9.ɦTCgQw=beG:x9#%){7 E 8%Fd 0*h>AIO6?'AYm'/t 6y45/b--,6_{MjivR&dS5?C-UF4S$_ݕM.4fΩDkE{Tf2Hhd <4sB>_ EŠ*1L2+P'!TO\nj8ܫU*qw-qe#H1dU5 *;0aVmj6Cb#Cإ/s~1# TwGp^;՟! Ghk"_G&ӸM%.m_W쐶?Uo"߅Z] i2("@ĺRMT9NqTYZ'WCmZyp&Y>EȤvm&-n)dHuEpfu~&>ytzNǩtd :%*DޖLfP:he-u ̩.)jfe<|rE_u Ŏ Jv]@ dGcnC/P6IΊH\,H9 Z7_-zE˄N6-?j2*(2AJQOX]x⣤cŠk*ܮJ8mi+IL'$CMn5bR|u#M sH#O}i D߉ȐO@O<݅ʃjq'BNvFᖓca5ڪQEb葨u=V Ru!:b4f\5onobf盓@]= _H9؞!{is$:ތJLF-C+,QI'[p+ #R5 a)+-ZPͻJ rQH8iZvr}ZKv2+$$yybn*K[O_i!ꑪÙ2#[4 㭗I)Xbm]]"`HԸ_p]E7$<Ul1]f*!]ԙ2#3ib7</i_!D~ZQ-3J4jJ3s}"QE`0te6&RCK(eX7u sڎ{3,9: vxw:T쪭[f\9:9A&&frmn`}CY:űD;,CE"RdW_ g֯FD᭨ ~tJaI^4: @TYRrLw`pMB0ustAluir1Oլ>g򃀣I+$qckkZ aQW=atʡLgml4=1dm+i}izfG,˦8*}iNѷfcI3xS:^[\O{, 3N`;6G-ȃħn:w鹏a泣呃#*%HMqf k;浍_ʣVU7! &t8nZ3J՞,K>z\E@;|\%'/tP_b*}nlYkVFI;3 (sgqJA83< 9S1*əzV/Wz>­}:<OMnsg<0xΙPM۰ڛ+Z<ܲy@PKI295gaS^K M"_EN廙SZM3W)7 roDozxEW ]OgoiK nq'(yJdR@7d_Fvw 3/C v$s9N F gUhg aXngͽb8Wjtk#85SE[$!͊6j!y c !ul'z]|&X'gdi~NoV8u,953UPN(lk qFP ,yD)lV ȏE-f4|J{cyiδMO:L”x.i|vq5]?\*151JT@p$o?#( ˂$40j{e?-0C>C0u2w~{>זO%o8>8ZqvZsT0SqqI='&1}R /_%Vm$Ny(Q$qVK-^4 D@57RZ_X=8ZKH&yv ]'g7I)#ZO ~\l3m랟 nKeN (Gz S層WLpس8V+Qo #qRXWqD^Z)S?,}@vt0|GIں|ȱlj0uH$zP ^.@X/T"'HyۡHxlw)t.'Qؚj*j{E>I ϥv*kjSwb߱LRY_K`Wb%-c],=Y0TioPx#9)%µC$ս`MN3I}D&V4YTTvJ0-gݻͪxE< ᜕t8jou=[%-ah>хX^2uR_Ec=IeAsCg NOISKeFcz@KA"ԟZUbsaLxeE?gVD!kė{ ?$k(L}lj[v9wO!>" D, RYL؉eG S8D|VdΚ9la\m[b Sʂ.ɨ?p99>W;U$ٱcl;'ս:꾵ݷRDRaj}k1V9qɶm* p%" `cyf'K$9C޹xacاҡl+zV.T[H=cb]9])":z `D~6w\ ]UƸI Ӗ2YV2XyT/2\G4HPIgu^ޚЉS6q$e*Ӹ̩:V#ֈB euPo RĂlZzPJJv-"]k_ m[ȐIڣxΚ"P۞⁀K[~3XZ:Q 0 (@bϱ0X#(HױҮCZ]~“gʄ+8H= zH @w \ !x:ndg㐦>Ϟqiu?p+,{@8ئ:9ޑ `XEDs\{Ē dZٛ|F5e|[׽ : >0E1co:s|I(ɸ ?ͩ֙ݪ>?S4>OViFrɏ I% ~K$3mPM依]qk pKTOG0o ˆrJRZ"AzN-5A ƑXikOg)e* D%͌RE x#y& Y~,o];r =CЭuȹl Wl77lyV =u4٧$:v(O8I)I>=ަXS71IbCn%M@E4ѹI`oĂʡ/|  Mlnr9L;mmďY+AˌIK^=Jڼ[.,̃%\8oIw-Xq c0! uoLo)#ӻܸШ;DU{ \cNk>RKC [ɦ/gOBd Nt'篮aq⊠{m6jԚ=B=3vZXEV^MBz=r~rb5X_\1e&#FL : Xon/m_דBt q;mIW*T~vjD\F/ # ">QABxS*cbHa@G'E*2}ݔaYujrce%T_zyb{f ]}bɁ5ެ ܰc&'}@L[j`}F(MpK\]ȷŲ'lz,B!YL7lXdm.$*G$c$cGdqE!$ y0hO<>9}Af,6+3yYdkGox=ƃ6J7Ơ:^s`S+{iE@uV>H|{-8FOKmP 'h*2 9ڄE^jghY= Pԏy}c{(_ @myH3 a|#>8D:> vrd(ڙZտ)?I3IX!W2X}̡*Fn/xܲiP* zFcx>?l&yL@Ԃ\(.6qz;+/=WUz~;s"f e/pYDϫpP}@l`N6޼w@ m`iTZj:k'apdϼ`㣑JRd*9!^mЃR-2~JkfqՊ6$i}ڕ":Lf>PqN:NRDEvs +=S? M@ET%oC.Rq_B2DO㥇f>G] 4f7W0ۈLhxҼ:R@., wskz{\,T<2b YH&[L ju *yP1[ Tfp2Qm:&2)ٙ齭z7?y)em0*;' :>-5:H- U2װLN5+ae{E{*Pk:hďM1bY!P&ͽRym6qr=dϗ`3bgX>SV>dkQo4ؖze18b~hS!=Z %(DuXS/҈%HLWėk@WY&O7(wwq-lR>p m;b1 t=_AYx"=+#nm\_S̞h GCoy$x0/q`yP^azPUg 6[?dА0. :K9%O, rf Llwݰ̖u\5JNA7?賆~JNkܶLAPukzS=MPTJ7cBp@MRfU}P;m-ݳkmH]"k>$|/5LrF.$S*deBnrDqv`r2*oPqۛ$NP1"+ܮF w?O;Hݟ`sAe0N)ǐF(g=<8 S]l@ͤN`'~wA0)yZ#Y!M];>6ԭ]2>aF ɽ’+oȥP&}nM5!;!;Jj*(&xo \AR+lUfȀY 8kJ+ _t&S26C#ĉd`G]6 GPS4!GJ"Qo~^ sזؘ)j ~; _H0sdVrp;$ !BUjcm ~^@*߈b#frF7?P% î4災0t=?{0$>DG<"_C7+61P vOFt0~ dz$x/Yz+g툺B:c/i:5qlDmpst|#0ϥӟ 8(؉{ݴ|.So^BReX U<.I@i3KR4t j!h,M (K|f}2<Ɛ{|t(Q_%ęiD hoĉدK@(Ռs Lmo3:%@szHlVo-'+y[HryQuZ҅4;cX)bK_e2ks "$=|X`j!U(,("BCXH9zsfqᥢ {Qlw`i<3D(-F]ڭR;T.<)N"qj3pj2j̭A\T 2l :F0d`sy"; Y'X֦J8b>3"N5D'1pu4d Q^yCm;@:jssh,:o[M>g>ʐp넄gI7Wg xԚ}Tܼzcl"7N66po$Ny4ǒTIME[R,-PMyTP<1͊Y2v/~R%[ғ}S%䧮XIjϐ{>ix:8lS7מkM=:Wo~)g]pTXGKs6),J0kV u? *l)yڅ߈Ao`&~D@%䬽_=>jb?D3ǐQ5_*ufu2(/5+zftɴN%iET/֤ErEJ%( !wGDYsR޺i gv*L S@LPI Ĥiy]s۞|_^5QT$3$JV'/s+7{*Ȧ%sN<彺J?9%o^1hJ&hwadMk'Z{]\g'WVAjប54 Q8U!= n@ceZ@1L#Q]B gGʜ(,$ U~.qɶ,4ȂߥS^4dl+e9m=Y~{u|mb~ )FLK[Qh}WO bQ;5&Pz69-XZ|U1;GvumTgO"tAAq Z3C:5?7e;/!&[v.Lœ!1C3w4VZ4ӰR*P<صpTk/G߫X K#$(4uїz䬃2Κ4R9}G9tiC]Vr*@\'^i~OlCbG,H <`w-&4,*-]A21\3n1b%q_ % +5Iʳ8ua~5nDzԩ! W#!i3 Oou6.I&n@S 7*k%NJ/5q ";6H(9TdZKKΛu? 1 Qdf\`@9T3X&P4L){$TawS3|M)qWd/( z$(kgSH{Dk8,a~*1G T]Ϧh?h0>;ȑPj7TY5`H `:YgT9fԃ5b)Cz_1_I9z' : , U7ifˋ&̹HYU2.Ep@ k,ܾt@O:Vi]VE*=kB#oZRܔBPƋMr?¶4#<+Ľy@m~ ?LOn"7  EMn7ŸxwGiBV\5&H.<OaoQPpZ?Z *Ƀ\_T.oq֩'6OK)e_rۇXGu.ALtLZR=TUG.OU]#,Y<^j3uHxvsLXN7u3Gl>ζzT-PkUW,!!ToS+?/gL}6wE~|[nѐA5%7JBuYyC1ɭABxΒg) q[4B\I+a.]ς ޷[$fQ v5,FQDndS oG6IVx#崻xkPQ!1FH]T}D U!ZJQ>XZ|ᇹm`ˢ=ô`/5l֩dypoW xt/:Z\ZdBCZ$)HT;ʮuk;(gs28h K>QGa_k%ۖ F5MG5̂o FbUxk;zxgi/Lya6"KR9ys弡$;%akoćL6wK);u{5o}ACۖmq4,F/0KzqD׿!Χy^ ݄=I %IR]٠\֓!s^7\ N p=甲ٻ;Qhd,U e㙓z֥4 נCUߥ[kԡl$^ c98 Ї$+Ɯ}*Am/DIcnP輪t)q/pXdDKd4Q&-:{ǸjdbA7x@esF(Pd9HFznco J2hӋ 2FY,d)iw)04A#Vg%,ڨqh<XƩڻ>HDosG[b $NUVaB( QTҴ(-;T̂\n;,ըݏ<%}%0ʮl ,l(:l HAGosUYl IezB> fS|~,gjyVN6՛0*hu"N/B ˭tGCT6"_fdS24?[;ocF9岠q?ʏk!5P:"7 cA]i6BJ5'&\LÞR֪ l0(;Ry<;p 5rS'܊&u\$Fb#%;'rk…AO%ˎ*V >CΩH:WWC[vsLgBO4YJ!oim@|7kN5F,+h1rqwgEE ,nB^3 * 4.LdM!_Ŕº>() dשdnqVȍߥ.~IBQ`ɫL}x`dc,X\SUlGl67 Q]c؀⃙ĝ!+)]uӍn* WJ:ZΡ1pzBc%$?2")O 9M2 MqoSkat@1.m E`u5J$O[g]Y47dUf0_7\ȏ<"Gqzv\H>~Q-|:32I㷽\K~I׺`R.I7M>yQ#5''fb9ZY4`zćoTxߴr_7q'L?z&!Ȼx}SU6x%Ct4IPS)~2ĆmP^h+ >H;/,ͼ~/-b8 7FhB^4e2. 0'˶g *.M&B.>Mg-|ĕC+PXQ[L.|hIV\j| {:yBih7z-M4$I =;vVL, 䫑ݵBRCP a|y9ubx&oQjYp- %(|2;ӞC}Pz歘h^_"|ɜ1{3L&mG$ t"u]-d/)6/%<0k e.qN"NVb'a{pN ;Mb:=%:KKx33f;OQl񾤾#q':DkK Ѹb!e:OAx?QZh#G,^]5˥ԩQ`~|6.((nI~65a&NrᑬM-1>&' mqX2ehk)Pe5 ,9pQ , j {NC@oN|~eΔS͛2glI Z BGZ-]ZGCF8v Fs{4,Ual*\FTaM-m~J_hL]mܓ1 '͉#=ѱm$`61RIuH1"@#vh˝#࠭OG‡irR+@MLaqAr!IeWcm۬ NjL]d>Y*gJG ".H\X='M$@0԰ؒ rqJ%H}~_N|%AJ4҄TC_"irϥ[̩tӱy^3R􈸏Tb6p ϽW6 EgR{^GFzy逪!Z )8XzTյA{?ۃ|-h3r !h?|^Fi)zl!s>k̵HI'[cHZV3c/Ys9Ra-f ;yS%4[ݤu+_ĖG AMw 2[Jưz8\RE`zݰ+ +#2 4| *o&3}lKa]&M5At5,K0\?mhpSY{ M6\<4ԉR<<8ӫ/R 48xEX:Af@"+t-\1(\Oq*\؉DjE'#ί ++JwwXeă 1{2tWě>M#6lk>*PT.Hz< Do#gb!lsN2/6I#w CӴ&\̀ލoyo0rJ%Ƒ 5 `ጏ -8_>Ox(G EJm/X6{V&h6vkMj b^ w@ )jH> O% ZAfK睗Q TnFy]VTժboXF @^"ZSds]Sr"WުU蝩KzWJjMB]3YЕ^Sٱ0DŽ#d3tDD)wnTL×ν ytXˏ{kv5n‘T`Ta6A6';td+&Lj ?m$/z6*dwA(AzX$gÓ38;ߋ-v4UOh1KPwS8{1P K@$e]f:Հiq-`0q (S͡kn Y&?5=.挳_ B1CdaT{29MtV[NX%(O0[G(Lcr[H6p8o}82sH[k+xt$.Rÿ?`ƨ݊AMUg w˿`nJ[<骔IdpO[vKOWJvzޔutGFB3ނd0`ڪGdߙ'HŨbk2fc殊W 6O༪7q;8xOt^=OʋQ%=L*D&bL$$d&m'r팓.op~<=w*娆2IVL&vh*Q,<'mlm o;i!;!X9gx'#@H $8rbGa:9ؾk<I۹0aXUQb : b}לMl6YBpktIt S!ޅo'M8Ho,8xZiBP^IۃtM {QGx]kKزQ{n;YJ7ǐ'w6H܈s_/uc/oӳ)י2|LP vwo}u%8)MXc-X@Cu9FϬ,RNNU/ǝҳ᪥Lm,[߽smǏ$8U"8ICJfH8D$%7Fut3-.؈ՍjuUC kCBo1&MN/p((\khIe7'ZD5 p1 Qr=e)O?3/tpfbsg^{j%lIE,c\^QlQã]{%6BL3Q8$6"} &DnK`eܜWQRoN0lTq=i `eAd7%TW9b$yiv ӂ&x~c/3gyDk`02^8gxƂJ+~P. !iQϹ<3|Ì?ߋ*8Gjδ/է?e$uf> "f3|"ѯVg/5+|1LlQhInhlTt^n7OƦ?A_~̉) eVS.cb;b/~ c%NT39WXZQ(1͍kMC.nM0樟+ "g$i!*uz+ŵqv#&[-FOɽaJXƯ%ȑpEt.,3 `sعIIUk'Һ:E< Z@#d+9YX_ ڔE" cnf3s5# S|Ac7Sd%•(P!%jN`ۨDPX*XB&g߶o㷟@MUTh:#`+Njq1Hn_+∀M03WYNb7#O M|^A#&fb)iZW:+XH$ /VeceNb$p~zP #[eYu# |I3pZx I|-%gU-Y!P,U[aB-X}l@Y2qlHLʷ)2Z)Q=lRƐ sNttc9 |7V+`zx"$+;%JVwHu<'k5pm'|QΊ9V-1FMXS5ugqf:?| gc)>n~O!8Id,~a<]n݃ ,B'Ds[ 8̪>TX5+Tcr^ eeɖGBA9^;)&!+R+M-pV}2 #6?, }(Uh%pﶗX< G g{ߜ}/>^&JA9C-XJed1# Qwxr0e5#}sry2NeyjŕLw] $2#Q">1f̸U(2hެd 9-:FeOķ:9K_OION͹n (zI lmoGl`#v*.> O'u}:nI DkT&n|5~n2+5pTDYY c`;^#S҉: %p8y3M쎟`~z #,˸DΖ>T$h4Lki!7T٫"c;4{/==F8AV")2sss}1: 9"bMkѫ Q%.Ll%ӟkS񾹊PKj~@ʩ txwlaMu6(DBP?zR0$ڀ03=ZTnC0эZdcB'p%!gn!e-U3:Ԑo@찃t1fTW~]F[վ=C*)$|=0L]J(/!  FAë2 v: y;ڂqC1] kqB<@f7J% k}P?5ETNP w؁qZ N7w}Um#4"8:<) 9 (? 9RϹ=#A~Y?4Y3  \46du|WԳ_GSb89 -jf",ob i - m %T.Z}#L<-&sJ 'v!{s ASq &F Ujte򋱻a!r.0*Ťęm1$؃a$Ҳ5\ͦ eDkO'E{3hqG F>˦W;+je4 TY"s42$b/uh, 4+ɤ 2Y``vrMSfk|.*Х$71!N>3`AJȓBb\|qU7Fl?[噷& sqdԤVe%p-``oꢞ6`%y[1uJH\ŎRrQuZl[I}!SPXK T'{hQQ}j byuvpɐwKb#fC58 'qb#PXI;P 9\cS2`K0";B2~ã0D" ?)] u271BSԢRy/ =gӜ\EaH\L)6qBL`jb|EowCP/rD-aKjQҼ'K.ͅ9^8/gXxGaǰaJ]yiӱcETXha5 /xu}KEmqILS1T|J8e(#Bаh+Vw Z=ͤ?^/U"^AAKlݏN^(̔OmA1&78 wc4.%r~J!N `\ 嗃NLY[.cEZ]?;b_']s'o2^NmN'O1ۛ6/b+I%x)io͐\h͖{)Rd7M i%OuO/\`y K#[(2"eY*MRm6)m}+~ )$2y" iUNUr}z?OՌl, GH#\;|'ܕxl-w8Lÿu}Jt}r/=ek6@7.5Z`UKw\o.jF`;uW|ǝxqԞ' wSNøNA ./Vg>NT?ۣ60 M_2Aw//z!8hݽk>-`r :)Z~`|Nkj 8a0M?)&:)p֮D´飗"L{?Ilop%lJ y僠mB/,UvnJu;~\]^Jt[mNQ/X j^v @|4OTe{M0;$6r:%s`\% sf@t6NLDyR(5ǝ"'!HI^ָh 6NxZS"8l;Qo=F7k욲ܵ-܌Ί e7m䀔lٗs .3+,lS%"E2+ }gnj򪔨üO~jXyFT#dJsדSrZm 3HnWL(8|HȞP#9?oQQbe8)>TaNM>naؐfվqYâ{Y gKvͽfI]|Z@!-@}&?Fg?ʙTHh$IX=K8aَPiuU&ڠJ.g?nsC oSmʈ%XVn+o=flw8ğ*_41;Y,  7FM^.ڕhq NZ:W 29\ ܖӟ8BUs[ڨ>l}"r չ}K.Y@J|Y$V7/yU]G6sZSX5 Wq?LT',wսIAx5/3zx.7=#u+8+!OBn"@R/O3Ȟ/"Tz`#[[ܣXZX¢8Dvu4bRB5uUb~e&߶Kzg"_IbQ}CEK)_fvfĠ+5T@=ǐ>efD @4nwQL2F&]MH=ia*Gȇ2+D#c@Qc`2X9 S[^M$7߆z|~͗UqF Qmqf>k҂An}F Νó"I\57ۋ1E($ݾxp]iܓz@kwɈ7PqiDp!;8w ,- :xlyh;$2+Fz"YEwc7ӄ3?ƈfL> m"i(*ݞv#;c-~2fpe>G$w|ԛĶĕN1R><_!;Hgۅh/ɨ/6>:/ۘ$t 2pWQ:X4vY&x:Ml7សKW2; DI|)E-k=q߃Ez-F@ب s x6ץAgѥ=q (yuxÙLj1vMԅ(҂wSN<3k nʅu֒.-S!HN[Π'4NjiAUFKMI_fl%r`͜8$ͺ.XaP)xBv!c4&)G:"&YO^y֕x3DT^%n ʲ ϕ(3ECtSgn=UPu]j Z5˕.!^F }*]0vsŸH6spe{Rt^DVö~~|9,nk," I2wzIUe{{2S1+=l4Tˈ4n'wVHUbM x&uaV DJ<{ΈSTMPpA kc">ҤONߢH9z~P Kowލ ` [Qmbr\NvuZ. VN/S |1)-{T:s,)>tQOxX`)aj;GW-'LB&|o#&OP-lQ[1k~p(5>ڹ5k2|Ok}0?.tΈ.Cmlc 4C٦U$#/@X|u͏Ri& DONW$!1BM8NcR&yC׳QV6mOߦH=Qd ]+y`a&׸g /$L'>4[1+qFG/Z!S1 Daٽ9^RǨΠL9xV:&WFrd7&tQf;mVyƞfX}b삀[\ 3ޫ-f<ŝ:j=c|˯N>X<{HW:EѪܠn90O-4k88e]^mhRD-a%/9 8Gr^W&q9@SJ({Pl> )6 `4hv,)?ym+t%DIJBe4X [(h'«x5/^&A +\)Z@X&EK5|Хk ѕ/Xo6y/1i.7G]`"Z{p Sf Ś$ɝh2 jrbzC~~2$~4xq,L0^dtG`óo1;5!ft.ׯ^QVXJY o= dM0ϑ ^I0~oڟ|e/A]#1C;^]kde_( [mZ4t]}؊eG|(ܿ 35Dٰ%"wpf^e 1%sRq}YxoE"Q7}4Mμ|u+iX<,[(u1*uzS,p 8. wV+j-0 =v_ܨij$t*)6A.>0 L!;HiJЕ<Ȟ4JPf -THF:dC@:J oO)=%-;-WY򕠗XRT )VW7$4NĐ:ˮ :Z'9eyr@3'5{o_szc' ;*WGEc)pA[B *b5iЮ WK4W|׃lدHZjT[$ #3G޵GR}jPxKҗϣADHMAXr+]bWr}*|8d{}1e PA4o/S;V %(lz7#3)ߵMRׄ8F6TaWO4뵱g @E`K#K&E|Goy=Tb\Z}.0^ !BflMDNjmT_UAQ˛-+@ *hs%{jk&j]gSÉgY~)v(oˇ%L3ΤpC㾋LdC}9WA6v:W2H_ީ2OkUk=듊l#l^0*e_̸1a.ț*pXYE}^6밺ZH aB.q)x-4<1wo 5;PºL$ DEҩ־є|x3$I@>ING*k_Zc{6ⅶm|ϻt_;X(&Cj_3աerSSmj@r< ~(cQ!hoPtTar9Kړ/c {Iy\%S (tXE^@ ct(/ig Vui`_ g])]QE pPoc]z7u'/EUA| =/6ǒJE(:y0ͱ8Z󩆾%/%EWd 1Qde6!_̲-'Ĵ#%͋>'fЀ5M+JA u< ̘[өO]Y4pV%]+:g}2&8Z-#THyT,`sj9j3=zL;jcû*-H#܋/mY1W='4 &ou+?0?JG&uq3frjHFWתE+%?@' 6hoڬs3H۵k=!9`}ODr%6z8|߆FSHFE>t5*C̵֟]^q`&1s'n|4Y,..͊ ##+,X?jѻܨ/ ϣvYޯ;Ddkin~Mer4yqM *`Bb?UzHš| y5fV[=`]bP&]|!CR;GU>eW;`"ן?O@7 y:Xfl(QQj5q, ~{䷵[x6N?v4 Gckc_RMعD?J8~C Z?-Sj 'b^e@A󩙽C&|s1[mtD}̄IϷ^V7'Cz]#RHCPrƉSi=zӲN=Ϋgj |c6Z=Eyoy cR*%AIyoq"nri~xZF1~27qx"b/A%\Ǖ)8!9qf]-aaq`ӻRuO\Drk'̐Fw8+ƒw;W\]+׽ŇO`d-ҁ.YHcuJˮ&őR6oQ}+aS.:B~Ume6׼כ+ o3cH$`uV/ j,Cޜ}L8}OϲQo )uzprN|y1"hJ"A GAD1f&!k)irQ[0\q"6LKGŹ=sm PfA6o*Yr3%tO@e-eaN)Łm.:1΍8!LDoQ؝%@&">Jx@\bGvR- ᬩ?$^jFADz$a^ѐUCM=r ^_4e&fX2Iu_]pr+3W56[egHC Ct_\7jV*M~)@5nEޛ񟻳ݎE' r=M2 d,o a~%rlo+a4=++m/p/t2*t~70Ǭ+zxqXS8PD~iԿ|7Sb YwT;tF xe\u{ǔYgο5mE k#~p9:_֓Z|&:G蟭Lp%XEX,,IoBaxlk+y1#@EHDL9raF; 2?lHN*rOR#DQ$ݯ`ޤ`i}91B*Z "APߟgo!cg!1:!yE$"H5em=N~3)op 0bH _ŜEc^~1[H}@sDoU41^~(vUal_=EsYPQQ-]w fM`d&m{;Z-# ot {j&B\i-.4ܭ:jY&͗.AZ9I P& WvsDzS᲻%m^a>+vp zRcp;CiFqܺJ)$$? gӎ6™%Kռhp̓t k*Mj@'kCh8ֳ\E  *M?Sr0E6!vP;Aaэ 5M?y1Av)D[8NS2<AEw.4XI6^}8ځa' 2 nS7kcRk!鵸_->9.F@eՈ@/|ŸyS( tV(5ٻrsbIv(P \n lu RbH|`NZG <#Q~ѲQ;9rz{ή3>*P>n \R.۫ s(T%л uD JOM l .iCw/K1Ka9_=ݸU5+4A~lBjG+s s$jA'B`y lZϩe[oIAw2Y8davKH3n;B,y ةg6F8'H0Ur!jBTņ D^_;vZT"O5N[H|>j lq,w~ {iƉ,,Q9Ž>GjStjpEq=y/dydZWZ;{= 5>7#E!捌HuS6PfU_ }# @L;(XO}_ɏ5/~S׌Nҏ/|5NZS(24(*ts'ɼP"8jL䷤j%48-"&υebJyf*bX$v'з%s regސQ./ 3z`5}<~n\"JpLø,v|ΏJ{h'rB "p͊-֜sL8ڳD=DHS\җ W9X?_y(lBe'GU6\{9s?㱅E f붵ikPo8[?A/3/ϔoI5,F(`/F|3)v ɶ65s9H t3e\l;8907 ha` Y`am%BAlzW'b17jv%55g K7Fbѩ)APx 6B0Wt s@]y4~̋HH54""5P2&1wDKϾB,g[8A`ܖaO/:7=lhAO>9c$wTx!ön}Jx&,9P\*EҚ*Ʊ޸]2AGHβ3S1럠,2`k-`!ޑ1'rbY9ϢH:M8Qi-32;SyS'>myA66i ), 'o3j0eި7 ԯ6qo7U~5Ʋφ!0pjv Ozd;%sĬ]yg̴qGBΕPڼm Gⰿ]oa+N`CӄEnJ }QsbWXVۨ1?hWWSJ$CvIP$R@ Aګ45"t_EGR({Rh✚aZO"5 ɲ=k(-^΃Vs j.*W`_ŧ-GH].|k.&%>[`!$a. Wy,=I ҏIogڋdϸnN?x %F)rpp% _*CcC~{ WTflkэȡ~`4p V<|:Φ.BEkK7KthjIQD `+>Z_ZV(, LJł'6zMsхGgn-ACƚԮaؕ=gr&, f?¸Z 5P7ݫ*IB3^% 噴c@~*Aԧ-CGQq*]NRq<*=yRoӛDQ燅q,R, 'W&WFZW/JIv2. :☣[Mb#u y sdV,%7O>]uw96p:Ho}Z/":P!Xح!j{EU\WSSغesmf@ mTꂗ %L +mt`=CWنli6.Bu09N'.s%޵ZX9k,BB Q G2e*"Tyx5G,xj΅a/ `6$a!I4N#޸ۀӟDY[?(b#V80P%ίG&e[ oEժLSTOKgYrZ(@EOz{@%N8~{CTse-w! Ƃя"@`ײAeyI\7 uJQi,`Hy'ELd n $W!`2dÜ]uo^e95;IG(I#tkaXӤZ%Eƿ]9-…2GM,%2!KFx&u΂۩m`ƎC[-xpßdtnn1SnگfVt.DSOC!XL_ofz~tbX!t@l@ F<~z&Keª9F.$FR;RqAՏ*jY,[S-I3dn W+F8)1hՎB bw,t-t G&l>i[HЮm/O ceJ]2.ַ xs[2>ko8>[1h:S9^]Wv|o<<6S8 4FϭjSb1`Lf?g V4O^!'( @Oswp dwcW(X.dPZ#J޻B\7 2黌mÉx5QgsNpt6>ʢXcˢDfH+k߫f9,IA n|ܬ#򝱡=%sK+K%ÈgI%0@ k~4vpjetHmql=+M$yOWEST,r uʏBbBSZ:݆Q"@!! F ibMcU6z>)$R%3iUB>e椕p-DhAt(*60 df s[z^ l=4![aNYMZlӷbRjDTM0jɁg8Рm]X̃?N IX%I^}qvY= ۴'+lzS<eKp酒n8\I.Sex"S+FELZz;˃13؞ ue0xm-\呹E*qЛI)UӃXgB8I8s)7 }μ0L҈ Qgz]֛;Z9ỚGi_b4؂ V6)0r!` B3%ct1;-k)LהFP;5?F]9./M(1NXqC 5R *Ûs)ԋWfb;LPbTQl'F7fy7@mH֫QV-!Re:6FoK$&?Նx:D@è [#]FphLBb۲%~Ž- :qλ\Y]}o07S3dM֡Ce ?놏Þ3͡!J(ae4 &L&kxҪo s<~mPodFk`{{07&•9m|VVћ?FC_[Қ T2|.?R)Wc3oT]Lt:++܋R<ʢzkv\;떃`!L`Ft`!`LrX=0 `6H{>ԺL Tas= {$b] F?j6*ΊHNy('j@|kP79q#>y8Cf%ov[;A|s ˵}<}.TRG ],/~kkI4zU*6ޤ!hkQ΁K[خ*aur20P!Qm BBтZ}T 6qvGTnd(2_|x.bc֢:nQ\q1dbb9$Rv0|23zB;:I"Z cH:opX$SqH#nWF|wMt30yBF0A/}E;yMAq yo\~W8> G{(VQ ec7xU"e$<Ϯq>9˹sĎ>v"^aj sJ IXL݈Oc[~{~| 's{iMzv<JfB:-5n)` 0WxD:Ԅ&ɤm0WH&lhl<_ǩTɃk`Li2 Z. "HyQ[nu.9:Ƨ{ tB`V\0G:'Cyc)}=vt~$* 7Bg Y S[tG ~x՜ӜY]yeFSa&%!71em#2O/_-t &%%ItW=Lc|:Juv&8"d¶ u9I22ʛ[zk W0ݪ/|_)tiMyH{`?I7od{[\eK†C'W7`Ie7M1ƺ&~C47@:Yh[yIJ{ke^#S y|TEpz0[UIvS~i +QH0yKa@3_a (X.r PI*9Il0oM**pmE/۾YI Mhy?JV%"DrX&tyxrȬd{@ 2旵@p4QUP:zxndrYZVBhUo\BZgj~PZ mF;SDeRsU6mN sϓgXK"u-p)ԼފI?Pw7S|ZWxN1̃΋iRg㓀F#(dGo ۼk>dm>eSyaU٤mܫO>z˲E>}9SMS/̍x^`C#BJB}T17auվtROys^=qljD&05X87GJ2FFvn)E6_:\m{TA10-Y ˨]~U} 2rSԡ QDMIW'[v153 s}x .q{3Ԡ~)=DAIv꙱Xi"3Eh)7o1# idMGǶSYv~CPo ;8m@yfOmp-%okQnuJim,v4̪=o*݆~?RKoOpc]1L 1paSCㆇND2wH6Ubv䰚 !2V1zĮR*+?#k(RiSOMuRi鋔9ʦh-+cӘNAEPfGQ6ؤkk ^'ӱ}W^wvS_v9OҩQTı܅\I~ )Rd3k+3=^8jGH:{z.UYej mM~3ȼn` ͚. Sa>9hQdN$k5 _n?,Ad44a1/>YznZhSlv/̱=| u/f^}hpDjTbǒ1IJT"wƠ-KwFi(BU98d!y[DH1 0 K޶ o_s J[i84Œ{BCG.6=|Ha:㍘{.xC$jlG1}E%-2m@Ĩk?)kMPC @a:L1/UF%{B}Mq,=7UKg(ha4A-Bqһ=]uA~1A z'BQF#P.jޚ}ȧxBJWPKkXTknI!Z}D&$J5S/mw$2~{{LZ$21XT_ #wOƘgv>e,:+p=-Pd-OsJ= p7bJ]7døO#Ӽ:0Y!j,*qz^d?n'Ψ%w8agMV+Dn@'+"z Řn gQJ+IULaW7Y=U;鸸,fߏP0*c݊4#G1ndE_A,%n֎u81/~+8M#MRa rZU;Ӝw9 +7f"R 0Ϊμv/eO)ֳJg)tЗ 8zo EV'A0Rwl"gT\;{%Tykm#ޘX W')DZf6nр^~^PrcGyy"!aj-#妡8l FX@*5A'L[ O&P&k ?0Ű@nim($ _ t#rnIX(=N ژݒϋאZ[{eox|8M ޼1~=梴%qFBﰦ2 $(<յW4UKvJd[ `?I\e0a pҰAN1bG!#K  U"Qg(LʊϜ>w+:?G X_UvME.*vN44ӲjVH@qMVYxZTI `̎<\6[/SwQaՏ򏸝^hPn IqԂoc}5`A }]m&J`4}$~"ea6U5h6R-T~,R |++m+V܍{`$Xqׅ);c &{1V>9CCR/HHx%n^tDk˫c}?KX -];Rʇƛ@E+je%:-b}52 w) x]UΎceUԃk'X5]Jpă,-x:52švՓg*whQ=. QTdWXKRt6r &K&g>-()=]zߒe`hJpRjUGhe6UVeQ)VSmjRZ#A>t%EԍB&n{|u7g$u. IQd^n הcp)U055+w) ؐL E%ؗ#n8NÈO=`~QhjS%CGPSP59@&DŽAٹjcM^:Rq^TUO5 )%I@^dJNoPB邩TTO p4SDغ^";L J%^8+%?os٠΃Tp齛e+%WNH7W~s?"~/,xH/]w(']u)f 3~__ZT9AcB9ǟ.lؼ"PQ5[5$|WSCJ],,'ND: }s1w>!~>};D ի7 =t 7Zq'a{Z8nkuXh!}{@<,/%Z|fZ[dg9m5b5bYSl.]LB Uu wh㨾9\u ``7-QiH'ېaHl,IO.nanrX8crPN'~8H.R=]C)7idhJC[V/.-j(#^I2ٜ>[+צݦGPv?Ck<9˕cD{:<>{~(w8?O+!v'= Є[k*ȭN,`>d+]qfN4Ύ<թ`zY{ |KΛiA1PM%^*upci&Qx*$zx)ZGjHz2{1҃DDWA0106 ǖҮR C$u }|C86q]Pc?sc#"SB{%Y>l[Q5H$K;sI]JΖ`,fc gX LWxsrױf@YT=' \8SihZ9T5H6ԙ`E?S2R 3yGfW)5Ah ˚,w*+b_Nhx;E5@"H14Zj>ÍC !FwJH2H;Xr4dl.PuOp.-ib/|UحP0+ 580=s9%@IS?]~kMeVdl>}gX 򤤒#Ww%siޕ=I4 vufڝWf{g]/+.rG#::; V(@D S j=$&^3P Ï3ݽøLBF>M TآqA`]W$Yt0ۆBD`Ifp)k)"pӨib]-Duj@{2x;SBE)aڣMya]k+} TZ[pA%%J ^D]Oo([AcDu3$ݔW{n^B`o/*#=j{FZѥYW?juv\E#  O6AӔ+F!ܑY& xǝmђ3ث755)Psčc-GCšxnyEvGLf%,<EJ"!JM}DēX7!ϱFy1TZޡj54=No=RQfE?,075,LmLzeskbcYgY2/qw{% +A'ԇz2:@3LF|'oWM*@Uz{o<1J=V%SQ @UJ&5> !SD KHxBÞ[MMx̟W)3C;>Zy=v!QzluƥIRU*'| TL5|I^ac><ծi.A v=+;_u3\KjVSP&mj{JJM~NLReuXfJݬF &ѣ n{[ڂfU{~1پk/c\慵'"ޝְ#H!<,9t)D`[ykv/:HM8>q")A1=瘅 ,~j:85? `kZ *Хv,b&JMZ_#*ЯjIz`B]:rӆ6n~6Sn+ift[gNXӽ W_\Y">Vd X_K!L)NhBs"/jqs(C|{f kE!u26뮍Όt# {ˌx%I<~M)_P%KgϰTHzy'C cXҨ "ԫT;i[ؾEJ(#N~xMV_ڠjڦmt4726'g[Mk9< q ~ky"W Il'ҕ3 #Q*{1:(SM&P%:3`f#Cg̷V|wZ9h/_z7X@+曒0w(@ i]Eg+UR`E#F{i^Vp_m+|JJt#]{}zo|"I`qT觟ǵD$ |e7ZF\zӛ3*e Oz ?3Eu! }\1>=3)j?D6{ ϕ, yuNйd@GJgp{zW Ag0J#fJ;?Q,mO=<\4BxCK-5(]SX„[K3+0z*Yh~|pǁbRľ5@Jv80#9C<}e|fRUʴ&qmG&2AQb"kk&lT/|#ANF&Y[ 8m=Q%6PCvxH}b)qv_}RA%8y>,%w:@_7M!!6m>ʝ> w穂hNL(y^-2evBRT)ݦ<瑊ABp ?m`ρZ55O\R|nӅGv+Ơko9@ԧrlke(tڒVED0-oFl0%Fkw!.H8Y !vYCAkIاKCrrJ\TZVXʠ>]lME(D+rb^wC(`p"ݺ-N|4B} $FNU_vD,_a7V_& ؔ v h`jdK& GNx`<@W#LP&F@:Q--vSg/7$%AȒ`?J4gl ȔjT$r#OdE{Z j-3K'se+ڻc{b?ݕ>jn('a8b Nw(\i)4:+y-gH"KO 9hd^`Kxx&̀OR\ۯwqYP[3sx*7 ?v՟bN ? e=Wky%sqRZ}+A1#5y Z'ω2Bi8^*;k:}Rdu8o-4R=rAJ̆-p+"{M.c|=Nb@BzL%bNMgOJ,JdgU]xjցƟ4ru{wj>jqGwjUP|ia&И)I} 8go+Xew(೥\xx 5m)ZR^o,6@D(~dH+ |;AGz]Hw=J5G |D}6`enK/gL2 5v']쒩J|@+chHLD؀M!`arzb!X vsH"2;e$OR1U 'QOKt"PBG}0!Ok6<Zt.^yE]#cNn &&;[%Gu`ʏ}r UaQ%p@,"B ©%JOxG jqEM|K>B]?onPP`3{=Ma^xӋE8Je^.rɆe8+yL.0]|FspC#Vf GcyづJe_H;V<ހl:*vi4wJ+\[g&vZ1F[ieu?X<:vcp9n]EBnCG'GKϿ>,R̥g( Y4F4|$wߤ1mruFxjp8c.uU-A~ %+ܣq*fBE KG.*kdvfdVpKJ/:>C'{($pk (3eon 4bV'CI #U8+CZ*X'TBc{C$FGvo7q>l+C4PEm#ф"P\<@s>6W dQo0f2??1)@|> CiSF`=pG}7:akd> ^Ti@u/GaΌ_ZFhfZmI8qInlaz5c$L>+ u!7扽,3d"f/DweCAx-ncqbYÉQ ^dHm[ hX͇ޒJDnU3gl$im&lxo[+[kM >Qd9D$)u_ ; j@:!qaY\=8nE$+ UT"wl%8bŞ )1JFNA׆鐄7kH=ܳATׇB& 4K/~ca >LVDPw<["L,sn/ZB) Gh Q˜(ޔ*T(ڪ[. (m7gJr>J.Ee9/j]A㭼t9Y0g7* YFj_ic1.TȐ#cPi"Kz:Bi-Pb+S4Eod&be0k!÷E^R?, W?wVKY9Ƥu[wQ)^<Z6f~IĮl^?|SviGyL®7.2qz쭑 mhSŸrrT]f| ^rC|hMf $.ߩ:p9RPvvP..@dK QO9 )(nݏw }H$FU^F;*ߑ@=tOm%V/\ Onoͩ) NoYE1ʟ b%#5*d˰^@ȇPD>]ԃ7@IV3fWo|FR$_;")>={>eӚx.ݎ7#Q 6L44~Td>Ґa}mKSfQʦFq8ڊNԿ𪃉FdJE>!<Bڞ뫳8jM)u @K13B }=BoQJ.l lWRdo}?%]e)qba9+DHf\}QR+fGZ|ʃF3{H&*yf0p!wΘ ;F|5p>[6-NS<ϪY'2[_a`yXl`2g:< p1->z b~>GQ952x3nze%o̶A ]+y\Kڥm&DžԔ,fpNIAlvl6Vց%[0JQ_9+i\+TXf} Eo|x~ *N gKig'*W1fṤHgn$ גMEJ!% Bx𠈵[%5\l&zX'~3IW!<ɽ5TgjLG;s LfB\}ȇL֎`Gt{1{hXIigA9Z4̘GMk[HQ+I<U+D)[Ϟϲ]j]r^h٪a:8̜k ;  ҁOukDشd]N{BkQE hObyս(5q*G0-c$Q)8/p?#{BYث1'KS9cKBSZh!QP.c D@jK]m1,0O=#܌T4E_€OL]-1-x {d vLՑzm< IS%%<4ALv`{měcy(/"yn W&uV rl>(crTٸ?xKUlk'},Ѻ(yx=LY O( TEB)_zvc3ಢ?Ȳ:c8(0]Ct  -ur!zs6O`Uo, n}K kQ*Rib3ԸT-VؗhD d\gt8nISE->'ŧʐ?ϬiYJas<UC]u?o]"&; +|ތޡWs28?uC\ltx8z:EFjeQL'G+2')FѲ"Mv6xV.:H& hR!A*]iNe)MdNNUS% CbQ K3`1.V/~6)xSmg AY pcC$T27b(3Sξ3 R%::Fa. pU_֗ao0%PŕLHdt$Ma@ ,t$v)Y<2̿}!3MnRڒ9s}>FU.;ȵ]dw4J.ht?>]s.c[KU+TGoWq{f^26~>lX/~H7ۅV^AZy/i$2_?2dyR#E;x'=\B3_<ߢkoA4U8e9h6(bU[xJ5db@ ,G 2N&'SSں q"̊]u'4{(=y*δo~=f>hR M0&מ&?EW0!u݃ ( v-GXQ΂SC.')ڧ8j(CJG[BLBmFdPʾ[#!>#b=aQɛß5hbM_uroQ,|(]͈&u(U3CXmC{X&}= mj@3zF37R@FSXIe6h:To4GO#hGr} 4 iZ6,'e _KX16l F 3-c ,krؚ$e#X^@ wԐrU %N-Nte ~X"|':,V&7k4IƱ`UEg̑䕣u4~ al,>+a6#_$_4"r,( mBxJ'*9v^ٜ.d!B\OF[=e_H4%f݉Wl=ٛ.Fh0.ޠ+GhۙI}\P`!_ v)uO:\<ÒBRВG2@D+g4>nJbBfZKD..,thh Sͼ?N%4!B  jeo\WfKӞWYƖRcٿ@ i h5)3i@Hs5V|nAI}FLp [%,80NOӉG]oH~m(mƝMmqisDAh2ژ6R}{2pʠ$qE7aB &,6EacAH<,4CUGnn+ r4@Aovt:e؋+WD"[qR{l,Җf@яz9z~ݗ,(UR ~q%-#Z.&BE+*wD^s9H9(Ӫ:_|~6[ϛ 7f6@Rƴ67Ah(y(14dON\|6jPB]U)jQ WL$plȼXPÅRD3\X''Qzs} e fs"ۜ)FϺClptQo|[|5t eQ&5~cdnG? CXR]B#{v2 рXSZJWvP`r6oEݯ' c|g;F:S &!==ɧ_-O1VOlc9՝j^ɹ{tJ]1Gr:}6ƧqI;'A8*HB]GK=U[" 68YB*Cf;!QZZ۾q6*CAe?Ci=TEy @ue)Kl9Nƅ~JPZ|<+K&\y,Y;uFzSW7v<# Z*o 0?24FoN!8M^}B,9$)co@=0IRPAc}Bt5(uUT6gtECWhj&AWr7{= ]s7guT`֫#:D1;MHRLJ@H`pԺ/;8 ]_,3D->ebdSFfw` /4(-Vĝi yKT&ZĦBb~0*^ yDb"U¼tuKG13yn&u=hln@˔=ף\!2Βq+8'bB<["d3#kJXC)·v&i:crF"`qw7 fVDZxi){ 6rŖ~הR*eQ3yeQ6b$:tEF`}yՁ`i8 Ǯ̀VZ:DTqs걌 \\Â1y<{ojKsVkO6fRZ`zr=ibzU4kMQi]eS}y)3@\] K"-fD 諾!ztk*[zWEw*,8glTމZb} 7;YO|abjweԱFlDe`+V8ie'1M|,p_twviD M7-1lU#& R"]D2T7Md+zqzOR&y޴?;YxHN,Pp&Ϛ ~WDrqfD*&'bbAWy^e4 OwxSgI>qa<@f߳fC@*1l\&%%_+>ZE̔%{가:jQcT QOe%7 S? Z &ŶقX 6쫼?gZGuK/ Med1h',А ZG&15%iHl/J{QemhIF^Lvl @}ƒ\!VA]a|Vɍup٨/~Amqi 5ī*2 61zIR騑FL3DY@o)9xjvyO_{;y@?-0Ns5~vE㧎Ոl_Ez)BGLۧs+cŋ$"|炋8YnX`Y9%STTߊw2Rܐ\3f~1,d2Z`y7nU秴8SUFyw =՗ UX=9xjޯ8"H r-lƯ?-[ I ey&fN[׹527s4h=JP `]ץBNJ(CW;WIO$pj6)N,$Y}}ᯁ0qzー:Ilܹ6xVMEK ʩJA vy1*dDjA3&ř^e?qOWqLTK2h^aJ5T3:?NM>qIAA8gIo`2p鵺X=ː%鸟ɿX IӒ@gu J~ݷg0O#1la}.]΁MZ1T>HzSaiCQPdK'jg7ŒS˖N `Gagcek.3]$6+M?78Li R4\&=>ob22&e![%6mXk.شR0pa  KÈ)W OGUb -kM)]d4ЗU*`0ɣ' #9g|?Ozov}*JFd bП'iuL,c:8LzC :NLo+ّLNG~564Ϸ |ɘEei% r6ois0l,@Y~ ?Hb[~ql2?1M:W@ضFQ XνƔ$p>w_~vV3Ng9n%kQbF8Z1RN I͔f??R2QbA^]~=X8w ͙_l6n+6X.+/v.&xh!1&L5}=X/ǎِ+` '؏C:v^ώ@Ï//=׿jZ01{T9 yo iCD#58 W0`Nǽ%nZIz{e!hN--a˶KYWT"·5P"*2OH'b#sz TEg`=`ĽG'­-8;76ۚt> Q-=0of wl͹=9/aU~:lJE' ֿn P#BF&v& /vf([{F+xҹR&]8D^̒^+NύvyLCDu38qcH^"'r4V K]pJ=t&W0)y`G㷤c7t{:V$R=/Qn$ gUt&X<ׇZF^,= D-e ]3N}ŊR"+<2 \#MkـJ: e8o`gi2ɑXdQS{o_9Go^$M׆&xm>XjeU#oP@j7GF+(Wd_E2)L Za4RD6 (!g+/ʒ$~C%]{dwt*j3[~OjCs>~8G1d?mo4RT0̮"a\7is9Wͱ/~M1}\|,3#/GhuZ*F. rڈ ˑOp` ' uE TjA?Ւ}m\qɎ4$xT:~Sˊ^g8Ox7Y1l9a R,URlWB10q]$d'(!eRc_Dk1k|GgǵZk1psKhN*}fHO΍(2W9g \#Dd!dy\YhjLFE~z7Aǁ짙㊀zaWnw!? wmH+*>,ѽJL*4=_4RD)g Up"i G~5D LG.ߋ^TNV:Iv1A_&-Z[}ޡpG@en$ vҴ=qN6h$f Es[Sӹ<%M? TwWXC.T:t& q\Xʂ6t4{ï:,kc1YQIt by LPi]aqsHd=9l"8b>U;,c7D_0p{Wo-״䔭$0kGt5OB9V?Sd^+P.vO}ق0wDr+Uxշ§LI]ѠG1༴i61)xn֟[ "]W="|t,)2nR'!}re]-,B[|qtւy]B_q9@/;{G+d(ڿ`ireHKr4@V_(b1X1dBB?9P8/'${T^؎trJnu˵xICIR܍r_láGƩ?VrF>Q_9ln,NjkMv Ϋ*{Xߌ|9({o֭O7p;qI~I WnnQWREgX亥7N=$K>`jnK𣋨OΛR, K[d ;l {T$E& FS=|1tk: !|^{'b PuŔqf~TzJՈ whyD8uF*;<ɫ:xqk/tܸ 0{u(q2xn[휡l>]1ƾZy Ȩ "gY x ݸRKa4O{;NsA; (zQ\}a59﹥1VJ#3Pv[*Es(;8L{5 okhr|Ј/biB°v@SkCj$ԕ#M#ᦝ]_#I`Rhcb&Wa8+ڤ|:E״YgMR3WɌpvpN(@tg~-ьn`ӡa%]d~sWc,pQjv.s5OA2!|e =sU^+ǣ}T/{ mMqmWm/#@0& C;+}!t"^57D\aOLhcoZZQAX=!]ۖXNƂl]#E' p筣>//JKֶu1A4$;ݷT tBp^^K[E&3T"Hg\7y(6I\aqӖoп-}'AL( #Ğ\a[ox+%hϫ$+Jdm U_=lJ 8-Q?t씤}7q5Iˆͺސ.2 SJ:X dqzvNL>LtD ?_>YJsTGfr,{rS2% x8» VTy\-DUj&KK wIw]D VA't%SVxݑUqx7|Nt(V.UWtq'LcƳ#X5F9:f*k1 7kw.͒)Tg^QQOE;Q1fb1ܡ)MZj-r$<)Zsҭg!H?\aǾfh=%3Y~ifJM7 m h{HUe+d.]>Oe7&L8<|KPbj`%w=7J(MR4XeB'Z׮}eo_\i6s2ޡ"NWu%@>2/ͷn [Pь2\LX2T@ G\g-?.AZNy3 T >: ~)_TOO[XNYGq{Tަ՝FM Μf rpP$Lie9]ĮѲX^pVdk?yf*"(yZI:ϼ,+tf Vfk0[ں& dNݗ)ʡ s My-8k~E-i֒l$B2P6ۢ'I "B 1_ߚ/ӝ3[*#%l8./Ptzzږ, U8$ɞ"ghpImg1U1CKtpCdE]_ՃM`_Xxuq"]ۃMw!Xf=&4@3G]ʧI pgu~΢͵v#SiRtl-Q5!ɬG۳`H0 -H^]Rţ,DM^gM[& ;^1)]vۮ] y\ >`>g%=n},8iFL]9P]@v?-ԑn0kdYd:CWI$Eɹ1^A# Nw#o|3)KAa^XM"e}0焿Q=3H])xM'2.`8WBXn<pQ0G&gwfh׎m`Zxn2?*oh~du3u56BF+\_GO3GZ)crz$(67zz]OXđ$&%?'_,SCK*$~!σ3 ]KugWnU؄aԺC]e˙?fp qFQ&ښùѠQ%nmb]94uwy#qd\XU'h",]+Y/QFDkJK~m:}J sy=Cl4&+< vq nj=ɤE)'7]*Dz["XAf)ea1\yJZ87;OP2|4ؑV>06$qp 4䛖<j$C~0"C1=/+}8 1?^5N&p bי;G=;Bh!y4r8DEhxgs킙zW2ϵ/{|O-hxQwհ&q''8 mbh= !⬘} WVjL銢o|? 'h?%s1rV.ԡdZz#-y#پCx^)_1Bu_,.|5nJ^w뺙kɻ|WD9_*͌ή᠕_(>9l~4wEӾq:W2<'ٟ'}WEb!S"!rO\x۽&Ok~\Ǐ%-3| mJ,a7[*?1,kp8{_uZo9 P%6熿ji(7zn03I8n_f@sve c:B,Yg䟑HjhAPHQ}0t(FKЊ{dR2bpUQ` `M0ܷfO1]vVNj,cK zҎ@ /3MտWn'ijzh05ўwtNxwBC5>A oȋ'D& 3U~r!47_qTmGԽJFHB;J^aH "!_:V)}wuFQeynx:5siX JZHV2P 'IڤW`QLh wF?u|m 讧qME̲ݡ: ]YZ/e6I,,/3g4y˛3.Yvq]VpM+]AbB ݸscnJŞNL `R_a-&FӖ?UO\)%i {ܺLk :Ljя9OCMHTp.JݼBr 2s+nޫ5*Tg{Za{>WSi *W!Yr?btE"/!!h8~c2k!OOcJBF;Z?(砵8`J>+* EUɇetdēc61 2__ZMbs8&_@TZ? 6!,E[ FL$pw*ah&jZesQetogGF?c_]H' C2h 3o0Mb)lZN,k357FZ9BM(mWy@MȼVAEKGl3Ne ǒ/D|}]KR@g;J 엲2;0;n˯r<^ҁ^y6}J?VebDx{Mmo^+ ;b[U٧NC 96E6D}#&t(xﱈD]v4yw3蛊 Ԅ9S]T]P3t` '1t9_:UԳmǒS+WLeyR5[oRxzZ/lzI@qfp?!i<H 8OWku;W7ږ49Qːä-$`ga1iQ6\eEu>PB/on9:V:M0@y7ϋOGBӧmI3s/!.^/ W)G&ʟ%#yZL (Sv#ƠX}= RuiTM y' .$dqqnVbʽiJb~GXW˙wI Y9ۂԩ\5 F2熹j!X|ŀgn\EE!tW"e7*ur%%5WߩˆSz`p!AUrL-tʽ i2 r)=U0!ZsNh7pjyaSbXyW8qDѣ$g_?Ow[n>l 8A~AL[O2276a@T 7=xQ ǩSqEs~8gl=Æc|~^eebrX](malВ-=vtPۨI[S}O fǂs߱ngRw!?BM[x y];!L.jHVe$1f(X>^ ox_ jD€u ֩J:SvdPHܒ]B%egM8ܾ\ d|2#,҄,$"#&Ge#uS7L8 N kG9^2ۯvTH:CIGCoxhr"fnJn7:F|=Ӱ%-NfJt,`}OS)HTf`]Y VQ>k/w< ΐ ve.aMa~$MЙ1ng pLvYI;=NFcH# L.y-7^ Ya/k6KWģ*so +Yh;U_F{Ie =*t=rMJ M93GkoOPY^H 6o} ^W1W"VGoզa1p=1?Esݧbsu_q Ėa(Bj/ʞYKWT{%U2 7U)&{ni%HB06|yRE۪Qg3GXb|^)Y;\=O!({؉yƑCa\FS-HE\vbQAg.)ÖGA8wTVnB Cu]ʕ D`L?7o~]UHMAU3?uClܖWݲ;iy%x?fpަ1nY#c)Xh$?=H+9g$Uo*zFeQ<{k7*q*v \ZYuLm!O%i?1/螎2 ic8[Y~UҪ3FBo::ߙwR|{۰PƬ]9I((ތe%B=׌pĺ tn^HRxJnyg9JuP.2UT}8)LC-[eM3B+ץBM4O=g⏱mĆ OSPVga!F\dky% h?nVEe|NTD! Ǖm~eFuCuq9nHaM4.7wiG8QehtCRzCNqjQICbZكH#t8[Z3ez I>m4؊Q1%*14-Rebe0SVax$bpLj=IJձ^Y}.mx!I-H7Q^~ԥǧ> L!*q~uk4t'sڑ0"$i BX)[jO,RJ`Qmo' KÔJj=r6j ŒYPϠdmpvX3˄hzTRrjipzRsEeI8a/3 4DT? l2)% xSNL4E:D2iH)älcJ ABԘC}s1q? tЪz}ԢdXbka*1d.rˠ qwN?oL7c,|onURw;hcu_fn Xͧ@Z<39)S$RȺbӈ)'HgdU+wc$LC1Ycc̙ߺ]foMf0a\WɵRTY4M(=F~Rz؍ՕEt_w&6*xw=.֒XXFn3NJˋIG~ >OF^7m=;X=_ܪY3(Du\UB}˭d挹O '|4:t,2Ș)x G4r)*AdN/d|!V7V_R@怉OhAߤU>p}Nkx2 $ m1)&$.p)v+ATފ/5~y(FlFhq]0Gg͉ u8EizVAeuZ춢VR&S]L@(`ٮ"`EQlm?|0G*c*&O퓌!5-PIlT`"q FKg^I}%.P09}~#-B>=\1J|'FS9ʮVp]z5$`Z/}W[=f mղTۮ*Q6Z8\R T:t&Ox# erG\ЖlǤ=Mt;)(<5CzfKFTxZ;O5KVR_u\Inm ԅKkO]^kGWJmmX-c5( GNU盃ՕxƘaRt ZTsZ⧉Op>9,뭴d}Laz.*YX}0/˂)hIu[j>Y%9-R.(ݝ1Z`"km'u3]@j<%yȟ_GUr>HCUz{ML"WŒH"*NXm`KKҳ0Zʭ7n kvmT˔J7yCKq=,.NEg5iw5??;EFu*rp0{vaJk[KqhDŝ`|RyM3`n;c&cLM?;06ir,靑+H!G5*SV-)Ğ`ݠNJuPq? 6[-׏ 1*aH"]0BaEyZ3?m] x)9ś ռ9,@k Em],ջw >thn8`g*d|L0T;+魫E}L;E uÆجx#Sl/k>JNtdH60fjj̘KZS^E=J l^e^JyҊǞp$=ύ =XQg= !546rmJ7IV&JC0 X9UtfsMb? ƥ$SSA)[qR=:NЍWyתyn iE+ehY2eTC|CTJK\ɊJ L 6~FZU0(՘[$`9G.!6SugE V nj0|/_^ʱ{%8G[J4mL'ɋl>u@%F>i0*G-oe҃QZxx|/nǘϮoB|[8CzjCߏmF$(SI.pg$.9}RmR躡^; >#mBgh}@/L!跶=>6v7=(ѵb'O:ǎ H!jɜpdXP :#F^.~V%ך`7B8Qn<˾dUś2T28jauӚ^ zvmXͬq8.]0I$QVab?A_i/ TO>~=.gf-nnʆ4ig-.XlJ Ŵ .p4zJ"̛d &'"rDyS-R1 9S*.30hqk%F=d/ݝc!xX_"lJT0KZ Wg b)ۛBf@0= ֫i)2tcnYL~٭0kN:rQ;u–/ywo" g8etNȶm,xL RM._Kړ F3n6v@$ʗ$SAu:0Ls;Y'q<>GQ%dlC#LsunsK18>G"$å|3BM3O)ZVa{lOEdI:D:^;[p2EÍv\7靴F?qI>exاj^! T 7>O*o@ Έݏ'ԪD3nN$'ݪOl$hwd| ݯxX aZT CRPnVg 'LZWL}@Pu:yRqzԔ2?+-O.^ǓA>>Ja. h<4b.bd*~*Q}5&u:2fAcSoU+vH=#1 Fy*;OZJ9 =MԴ5+\b0(^}7?mYVb|@`~) >Baf:?eh0ʥ|/sݩ1)*lxs-zc }#T6'V 4yzFT3_s%uZxخĺ<n%L O3Ꮨ`&gre l[ʁm‚PѳUߔ ÖҚ_q8aU-Yu;/ X'3N+wúZ+was"j>0b8#9a!XSP0pKew>Tӯ4%aR)cc:㉡=mO%^.Cйc^ 8 &JőX_W 04;һ9MfBΕ, c\5TNd76o'KM7eP1{@F)NSQR4O4(r++3UKR)"Ŀ8IO l#ܪ DդCYxtpTɽ[eM_m^0qu)ċS{ wkB-^;OWX^CP_ႆˇJs7@\Q E(O4`0һ~ի)T.%e )2ҭm R)MeE\mQ mZ+Ks4mQu<ۀRFw3c܅+3h`w9nnبGF]ٔ55 ? ʚ*aԎ}4q6z#Rc̡vvm5KN\ 0R<ݟu9 2][u#!thҷtĽ4o-~:uZ ew&#*6Q-rOo>g1Qz)5 2* if[%RsRvZKWKW(P'Zz?-hxȏǶb"o_GF:fAJHJFU`؞Gc}t]R('<-%%p 5_D}/t\䄆;yhԿsXsWXDlϦ.7զUnO!jn7u,ҲoTObY3]4׋ ʆEy}^LW1>WH| Uӝ%<%|< _qU5y/rKkVX Ew%t/aRg,܏;{T |(@_;J 7[q-ky/`p [Z2~T0妊B¹M||tpK+LiZ?c‰8Wteީ;fřYGNƒd] k`E4ctHYn( -"snrnM$y{ Ar-z8Ѻ?,>/oíJX$!+-h!WcA#~IL)x3W < kO'Lg1KԠ3ް##Ȉ 7 BHF_D Hlk'ƫvhTRX!dFc lr\y?dAk[W߁9("`bVL0 /b10qB+Pr*0O)Q>\C,&~nFqլE%lV 묷(QL%Yld.`آKeTvx~+wZ.)"]C3f7Vdt&kJ.c;{u-qwCIO!lV5\a&A_G iPM:u7vY' Hqް{qi]}^@=y&B..j66db-׃).lԨI'!*M](+>jd*w[MR, ~*ލH^eY!U?ė fΪo3i|s|(y8d'gih+%y7dbЎަ_"280>0c I %qs .; 另ʊՑWڧ2a"ZŞ5WVnr{04`|u_kn1F۔B1R@MБe +|@[FA)FyQ'ˠ'A^'+$-+vw@{y6MБ+aLG%if%YءevdC)a\S%dx;L+eTq [0$# N"Kr }@^![*O /`3̒aCh]HEĕe&4RRw|̸IsDu{j2y3pW:EeW-`pƦXoK,]> Q+{x0=ێ:F0w= B];J"Ԙc!%OliT?| {g@G&3F݅bٔ ԋ ӹD.?'%'2ץMJ,gJ8VQbBfsDB(jk\#/N!-M(@XX] @X ӫO}Cy)m 0_ǬB=ā>x>j>zl=Y-܌h>"+NT'>,Uz8&"8\u]rmp7'VNu5)wqb;f~ BQo)0IX:/hMhxQFXnUE[t{zYFİcf[LFk|Gm,79 v6Js:Q`23XGL7ICR8kuX"`MomPGQG+%r>Z2ZDHHWd/O M @8骱,c{W[ϻ={gғ.ZIc}Q'?Ҹl]Qɔbzp$_ ?nM0a)0ю6%Cy'Y<5/JJo3ີJL}S9n#*Y~l:aǮ6eN-jQ*R?k2OxalZG.c "F{ $ W~|༷NoM5KP?OAe3)Em$|K:o^q$n ow̐|V )-.gUdM%LEFJ4M\8-SV]^aMfትsֆXJ k,`Ý3\\c_U<ja͕*q=Lpu[4@4m/{](\4Q"ظHRK|^ܞWSI~= o$H c^mRsfѹtufj+6?#^34}1W)";7X]w, uiY]]}(.qIy*" hY!ß0sLpC:|;xF-AI:t7~\DŬcR.b[/nwvOy>2G M?K_vd4HwdN:I# T 0쏅NI7ET"@iC XԚ܈D%7;@fmP!Yd$q]EêL=Vn?S͓ rEAzV*RBPF@5EFRԤk:$oYaķ01Dׁl(~0.l$`@Wyb::"FsU!Ѧ ލ=Ϥǣ3p=z:E (#ZYdgHlET˦;-˿l:ZG1e Psq>HH:q0|pw*~A񷛣RI6>i?6K~(ۺ{ѴpZ%gD7Ԋ (/Rz%[ e|pAZbd/<;ZvzZW=et\ -6ќ {f8h `(HhaQG?Yήd*Ab%1"S N'b5+ive[Z졮$+@ ;Oae