pki-ca-10.5.16-5.el7_7> H HtxHF]8v ?*}}b9  !;=Kp~:T:ʻڜқ11f1e15e534ebbc6c3620bddaf5cfd8d8f32dd31 2J5&$WF]8v ?*}}Ov:1[RNMFp3hNK J|[yxu%>8?d   D          > D Ldd d ld d nd q dvd}ddLT x , (\8d9L:GUdH[XdI`dXbLYbP\b`d]gd^Xbd?eDfGlItddudv wdxXdCpki-ca10.5.165.el7_7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.]&Jsl7.fnal.gov$HScientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=mL)@1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~-d>Ed,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤]&'\4>]&]&]&]%]&]&\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]&\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]&]&\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]&\4>]&]&]&\4>\4>]&\4>\4>\4>]&]&]&]&]&]&]&]&]&\4>\4>]& \4>]&\4>\4>\4>\4>\4>\4>\4>]& \4>\4>]&\4>\4>\4>\4>\4>\4>\4>]&\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]&\4>\4>\4>\4>\4>\4>\4>]&\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>]&\4>\4>\4>\4>]&\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e24dcd884746336f7bdd7142ffb0e1a7b81a510512b14bf4595ca4f5dbe9d477702d78fd73c85cec42ec4c1823cac0c97fec0e80ca98ee88a49c90029c59e4fb20c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.16-5.el7_7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.16-5.el7_73.0.4-14.6.0-14.0-15.2-14.11.3]v>]Z@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.16-5Dogtag Team 10.5.16-4Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1750277 - CC: missing audit event for CS acting as TLS client [rhel-7.7.z] (cfu) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1743122 - RHCS-9 CA clone SSL server cert not issued with its custom SAN extension, RHEL-7.6 and HSM [rhel-7.7.z] (edewata) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.16 in RHCS 9.5- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.16-5.el7_7    pki-ca-10.5.16LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.16//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL'D~77Nrkl=XZ[2{eockW'p@dkGNKV*dXfhREldIʓ@(9,aY7]zU[UT}v~uߑa@^ȑGגh0&+i$&7:{ [C}f6TQQ_-=.+b k_tUs-04XjX-3, gaC l&lVv9vTZMSސmE- 488dGsr0퓏m~u#UNIu!,>2~ȵ8iÛ Gյf%?Z,J!)70iս""́$!?S/Ã*q =7o" p ݍlV C+RxDM9{ ZUٹڤLo;9FŬ x\kQѬ}ꄅӋBKͪtk9G*GL ^6V Z3=`Fk%MZif{sз_Shy1 󑁁8t"oAcagrCIL9-|,#/_3sd2Cۏ -ݮ`vYԪErؠu"f!9\" v씏}e%%6xfeOʎG'(c%2[jI%ʣe6`7T2[VA%!!("i%e !τ34щ=g*;nx;ϣg*)4.oxYq!C^Kiv(mg*unx{0QQ6[fe/G[Bf;bo]zR@~g Iܕw㎊bnq˚Lf)a88.-]qAjbAv:!iydUN 7h0v֔0+@5UɉMl0Jڦm>ٿHX%?'2>WM@TR9WωٛZɎ-FM2;B%ee*N采I={H?G~:ZtI|DE-i`-"$_(Oy89/;v]k_LMDEZ"">6fP=ޡ-XwQi6. rVle{;XWfbHJu-']#.헊 3a3]nʶyȖKw-HiNf1T]/BRSi'cvO[+)3paWڠp(E@<3~%#A}4%|-ݐ"_ЪhVIG?OejV2a2 ? * S  2[WwcHBA~X fN_2U[h^4kꧺصlA+n yRLG>1ؖ Ebۡ+]"ͪtE@ H6l%0DP&nU!ݬ13(!v) ,_^~]WF iT#!R^@ ?faHp86nݒgZ'Uxj(X?Ej%S.^4 gAHOCZPE݊hؾS4t9ix>j䰘,Аfn_^?*-[E?S'"SPlM# ʹ:/F̽X%qSL|^.2ͥn.24(G?Tr'J~tÉwۉM n,6m IYd|Ժbu ;f+sr9 Yhc";ʊ64H\حnp INV&VK3;ޭ 0Ak3uĵªYL7{Tj;'/&äF#Uk",K|Q-+ǎ%z>g N 4ϥX MZ ;^L]bݛ>Pݩx#?)okZ# uȩ;F9N3.nCGrDJLҮʑUjRyX A]y N`zJMa]wtuEvj:+qND,j`0%$>v"ʽ'|T% 9h|BڪJYEiPhD I8HF{zkwuHRO*Y[ . g馒ZuWT?yVt TYمV5,쎊h2}=bI*xc1Go }CUΘQĞBDnwON:nq+pJ^v2RjPXmBe~RfćYU9(ȋ5㳘-͵H[ @T^"*p,:}2]n=X7@m)]Aێ[`Ա.[3)^l[|"ȃ,/񉷸?EmH&<}ȇ6 tVvDd8V_ΐ*ղ}%3_[&s-%rI~ʮp}I+vܼFm&Ϡ}sbU8pXweX? RB<+ tkoPۉ#]iKV≂c?Bsm*<\ _/^&q ajSeڪv0Tx#QpEВl5d`Sʹ{vCݲRS,_>\ԕt΢L ST3=:7 7$ ;[>;W %0IڑY۽90vc>!+d'pI *\s]<{U&? &*4 0I&- Bjn H"i9%ܧ?z/ UEVmJWŧɲɽ|,cE[=gh?^҆;b{ZV|նQŝb:$?uZRWNH!?r SOPm.gw 50^$ )A7dk0$ jS܄؜b轝Mnz濊7J t!kw|CӒ+28 *2}Qh0/ s҂%4?r %a4TV rc_M$)͎^AidK92$%EDIlē?p$ԟ@.Xֵ?3q媄8G˗&0b#8v;䬊4+jR+;.g`)|Z ayD}kefL[v?1~EHp#=%Ve߰o%͝fx '}d!LXUKP ]YٛЛWE7vjW=N_»-?`D >Y7͖#ӏG=EUC3{$؝jR8+]PP~?,nmeN_\$SςXPj\$ %a3㱧 }l`¢I}!eEˆ+CHIٜ&7plkqKPW/ F7;h/׹ҡI~[LHH*mqqj|=Jk2:,]MGgWF!=qs)w8A }K*J2cVDI(R1}? po#tv&ϋw`C⋫,gpI.0޷oJ 4!9kCn%' &G)?2G9KgNA$?t@DXЮZe8!A<d}w3j$ٺfr|瑂&b7{ 6[&)&[IfRbv ob4|[uGg6T_:4`d 3`U{ز>QJ!tTHkuc1|_e M1pܟSSd{XNg ԅ0M4oWR6MrJ@pYy_xX/د yʽ](>#\>q? *f;eHC}+ĖU0%,eYf7-ziKh?;n5&TB(W@`)w6 :Vp ?GM=t \N>eqLW}Y Hu]Vy'` b̟/ݒ?6nu@~%)vqX4%g_fw+a0XE}Ns7d7'`mn"2.5-|LROP|tWou;4*ccqmVw]SeůK}LA!A%s3? 7NAc3A͈E &zN1Z9Qܠ&Mܝ V:W'inYIM r rrvQl=l-P[{EPcDL,͛`-=aLW+I!qc17A&b:YӾ;0E`k(3 [6׆#fԖ`\2'+R1awFk]87xKuql37f0⭶~2=N篰p@,kOkQ Rq[㗈x+$P6w4xM3 syTgx_~Km/ӼY`}?{VWBꈑ{P{dOc7#]k㥇']OYyOf*[`Gt8q.ij97];OpwYD`ׇ_C{l=X1FG VWy+O7߿ _n `kQ, ߬fzcEʈ&2 X"8b.XNl;M~Vdƍ V;Ja{qn(D)>L/jv<ůu:abqX ͚+ѷ Y4- }qh"BNJ\JUß2Yh/4VKe>FJn6P@TB[5_Ÿy0Yy?UE[ݛ&e:8 ֥%ݩ1fh2{ CI9\0X:ZTViz(#`V.鬈knwط+2!MLY,6@(Ei?dʅvpNS:+MX_[vJzi7 J`] #|QD6-ecj\t '­:m׼dv!;\8 % ק/a $49ؑԾ%oYN9||5z:G3yX dS/  ˳$=6RɨG<Md MTp8O-357oi  5D 1x٥B}q@a [OG^2@޸7wCz^a!n°xCOgM2QH5י[p:U1IgV:8]E! u6H5a@eFxحvmo/~O+I T쑕6vpl!e /NqQI'q`9c28C$%eQpCT,Z01pij[\@0gtvQ.:6!S92r Q'aՒ,h&iݶmCs=ӆ\7 G{ %APǏZXfD#$گ]a7 FvS &\S8? QDpH F{SxAi;"C񐦞hD~7:JͫnOQW"Y{א{,#|, Ix).3'". vRؓlJiM0(C,Q1j{kwe&c*Ve r.&;ֆ$Kx<9G ԕ:{Sָ=teOEc;8h}ק򇓽WvYo# ?{ݯI˛/K cxDv/A Uu(b(4?8s>5Di@?Ge&PeXUQ,՘'ՁV\>m3BX=kR뢱[;r/W+eI8~͙&!Wu:-7X(%:%d2}mz1)(rKj1foN+Օ.DY իz A }qd@i|BH< l }C{K刴h ;;--, ljz׍7fRVW??)X`^k«)7B_~MSۯ\OMrhhlTG'TȢ~T'[o@Bk8Ӑ:uʱR7$ lMGP:${n|:rTi>~;KObbQ}7zf.%VR>O臺EQnN@}g.[.k2 Z4gr^5Txgȇ>B# *K8B*h|8fGϖϔR%o.A /@\[`"{ VL;Ro!ezS1DVn^ 1#c<b!uU(-H^mb}>j'ռ)8}q_iRU}K͔h+YH~ާiu*M*aTݕ`_YoޮH[0dYPM{́lk$Qi1ѹ]J ]&z2-H3:=,faOR_ /xx,v]}d#_z,g1//AH{G S. Lۃԅah⻾NSL^{[WS~HOXVǼJ{A #F&lIGSrwIb,/n|x!`w2YS[(c $)-o+lدj\9~蜣2U4_@^S.Ra?6n!ꅯ6< ~ 9 EGOIfBZmE'nE(Í>`}Hk`'D#_4 1|\-&Sg*6ɑAp?czw*W GCQ(sX`_`RXE97D%bx"x\\)0b W}ϾOaX.=Dq+ҫc Jv*MEpUVbžMf^q@o3lj;Ѡ <1rSu3A(Gn.M!D5&3KPb,ݝQ&J-?Z $ 0^. Mkz]se$9k}f(ٯN%IwHK Մ x*a9 }pt51:++佡hǂimJEJBq4&nHJ5)@y~;#H./wI-1́`5PևCk-NS*'zWs-ɮ~%mc[Ik P)%($aױnC`?#D41DR!^I,@6={!3T1q( zIgbSz`Z1iq: 9kJjt0p\2"Ye=N5~Sb$5%e?Ւ;b D0]NĤvCƟ@!%EBPqfG(Ӷ=(N67?Yh$"EȒJᇷg;y&ESr=5GWO_/&;5?9ERv:.&e|^DGX#cX,fh.>k9͋gM>/D^O_̸_g}JYL[5 2h[CPJ_Y.<6fobSvڨp+т9uzѭjY|fy$V -2X̐NIZsE!*\Z.$DqǍŬk$ l/t+FvUޖEms !o7*0,0%:v6V}w8Ya֑)7R}`f;c.{o#KεduG0>x D2O~,s]zG BLdp3 xw37bG/B`1M4L3 T%ⵟ~ 'IIN-_ŧx%Uzj9>if1US>l/ŘFU`޻3h{VzaDUJ\׫[ Ac1%lY3,ȩtY/kElS~ sKeypFsjMS%HqxĻ(WWpwq)"ep Nl̡Ft 8r=^˒b <Ӵ1R{pw,Cτ;y6DLGg^'26 9=¥{ >7՘#a=$1jڷ-y_[aQb~S`mzW>xCqT=4T,0_Am /+VREK)D wG'%yOt,\JG R O˂ef_N wĥ9Z4th5Tj 2fe.hA6|i]ЌL~{" H_5!4uI,pcABϺHxWok1I7S|%ke[0/]݀XnPλB{jc y;Iԁ.T:O,e5bIm}2Ku' ^Y\a|175A7WGu>r?;5jw&uʪOr6bm}Ӝt0'á[Ӽ^r9"'6GT6/ݡ?g{/yaJMuRF=^rfħ`QF=/&e ]1|_( u:y)-:i(f@:j'6s}L])$ƲaK&"m|ݷEUT&EF0%2tϞ[%(){ەkuB呗If>91h:@KamNf8ְ>ж\y)*L`3^ٛ_΄UĔ& ,ĻIORXˮf+|ԕ6'U(V\}p4oLo f\4 KSGv*1,u"P8_~_PÑI7FG.F~5"kpl\K!&Fgy8.L~i@ŘpL3:eg&j1EjqP@t~Wun|e8 ?̃T3-3,&|k VU٠50p:ӡT'Zy7bWg'Laj2ܻXWgEzFAF'#? N11tE2;XO"hѕZc7_.EAۛ1s}~~!R.uS߷$^x Bd̈@jsvjix7 qix꩑䒑nYqF9]u??iVآ4Ya}EM]o4Q̀d ._o_2l1FNGs(UM'UGf\5DǦ qqem-W?`se}TBz[HA P'-# *jm*i,$K=m]ͺ'mgXBI[Y@+B,~"w(́6 10ʖtpvqm58 r7` C 7Z1HQ< ' B: |UO}02nC } 59YŲuzj$hzŸa|j\*5A(51wa5':MvSH;{ #FcrGSh*l *;IJ. ROk B8N'5_WyqG4wyeX3|澖Xgi- y|l,kQo\h,2m'ǂųQ 9wA6[9%-VN"|tVkv EH7c9)=aS@FHD*[oV~r  E$|$F|ʼ nh_)*OJn>ph1lIdF-2pnP(i2s䈅=F%S,Y jM|(*1KoD[V/QqX7?4\TM]eӦ$/il7)A6*b gEˢ{ m! Κw!yYF촁t;[yͫf= T21ej1v'4 #3lQJ*1o۴Lv\-d<;-1ܸQ΅ިa֚ gfy`S(.CuxK/m(]UIDU'|0?[Ӳ"Jox򮾷UZFg>C1|n' /{_DUٝ9VpRqmЗWFY  5+;9[zNmG;'ZV,$LDRq[nIY֭_/pUy= orhí雫֙bu!J&@GMƵҙf$g/qEyu1ULeb wgeųmͥsT?ǫ@qbﻩ eŌЋ̀Rt_C4ePn:@cޢF& sqy_?S]ǐQ̎E`Z9cSodC^)pS\ j>Z/>rH3g-Wi"P[ ?:USfJZY̏"QW?03oK :? ,osclQ!r{fx[433ȯ~: '͐~5?Sa lVh֠tӯ7kaޗ b l~(ͿSDFn$]SmMmku!5O8_ڨMQaը#¤CulkM5-ZGQCISz!P"Z[z+Oj`[gEx0eQ5Bc:$EGafF9seWWbf ǁe <`{V3nv,[j^OCȊAiqM3/5DƊ8q!6k~3Ǟ DID ?AܙJdHJ2 :hWF5H7kbpquW:#^'YڊP(>)Vܔ&@:)&5Qu_^+ OzHA-K;C N>` %@T|1,:1ute3>2aq M挚3XϵhS1y_9|O4lL]a7 n209{ VtN E_F<QGNk{ҡA!Yd^ڇ+ Ƅ %-2R,''ҎO 8qtoҖ.)[> g*_QɜFNdӉyh:ɣ*c KKpV}J1ƣ(3}6_t^N·jjC|6ŃL^`}LR淋+]Y5aIpvKwÅKU֠އ5qhI>tm~#kHa䧣+-|}% #9YOV\5/C$Y`1Kc8Qn k@W.=bM)q 6Q*fkoI~;1DF:j7q%XjP#ٲfVsYu֋Ғq=>ƻ] G-.-DSgMmh^b+gK8.K7)BL_lzN26m+Bp7/O;B0qiV2Wk-ʑ|!qP_H޺Qg 65Fﱮxus_X4quzM\EP2, >}#j1C{8!{r:+hcJ9Q.2K (k?%P>0sm LGvm9tvXh089+j6K7A㷟h'q Cip/;I}wN'Bf8=8[ga"+m=vX\Uct2tj̅ |g(XHC'$dR9vJAEJh(3y1M;YE:Im-/_Cac vBA᰽6%+au[ XS Ak^!bf|$q p JP\Mg|Y?&V2Q…Bq.(Xnho :)3W$>KݱF0p96AHBuuVt#F1WYea'ےԹ>3s~w2Ez7ASKYu?d7"hx@rm9n9:z ޽hkeFۼL,H]I8!/Sz6|FNqe)d(SizK]WlH2T}(,缆NN>PXZO`a3 hjªJPIݧCJ НoK"V5GZ/ 6J=fM-2Vܙu[Pɒ7(}iR`ت?2;6JMh)W[5Q^_NVd $k17dԅ 4I+bH#3{i!޽{!UyFAu `V*f>x<wɐ(w?Z}Mgz C8^ j[W,ޞ/p,CbVfq7(|V.w/aI I4o\|{A:Pdz%4j%͘8k&l{fwFb&Aߐ_ɸp-mE֕ŋ.a:qme&! HBjQ\+rmNn@'6J+dz^b\J-M饁Фٲ`]PMa2koeȅo |=y,w rRt \"PS.[S#Zo0jt d?5nAp]9H+&/ąDoُl@>҅ǭ.. iěL#&v$.x jMA~#9h@WaEHP$̽6-RwH~6˘͙7IjL&tN sP4˻^@=jqkp@ߟf2Ʋ,˖!8_z֞pZ`k]$KaN-`O/J(I{O /v#'}[{̓ r@_ϋ7[ ȐI/Կx/ _>*I5v*n p(_ j;Zj%j 2CfWL- S/DdZt"?f\Jͭ=ᴷ)[!l%|/#-m;aVeaw"RU祗>\ Yz~Hb)w~Ip5QJm#?eỲ'3~[p 5Q_Fld4uCErΆPZEA@_kLgsWzyԐ\   +AflqW]n~ mu形IiݿLCVɛ}MeҩӥSL!9-=%ͺ1^ƀW0c6rN·wXQk[iQHB4H6kѐyi ?K55*S8dr%Ј!U4<<[m5m]u-y,fhgTWtD2 .v/oY4V)5D h`KC-F^-}Z'Xd'ULޢw3fh!,'];]+WI] uKD!6-MRZ]pT(SR 0*^]KWߊBcm_*\8xlWsM-ADǎWY7)qg *U[kGf%N,? $ICI˵|%\& ֩ zf~djάݟ#"4ǯG~hw=u3t\/s"(*GTImtq@OEVX=-pMtp# 1ptNY,ϟӞnY.˒Mct cb>|!F`a>t=sά} Jp R)I1I25| Җ _%x9žP+cYy9>'%'F#f[KO%>!%UphT_B_Y4"tݚd.bJ;\UByVo.j9oܦ7u$|VSQ{s*$#R+F[nl򡓐7#7 "= ϕ8Vm-0܈e]{^QZDSY}vob HL;O# dpTf] *"݌9+WV&^_\ U+Z[iHqЋX}RKu-`a>M M Y "Д'0]}\rzT+þ3W(?<ߟ*@8.ϦϻGMZ Y023hD3/kTݠʃ">iwg!V]l?:bn9rGTw}桪 ҕ;3HZ+G-z:|5kdr(򡚋ȷxSҎ Ťffg~rtfDy|MX He*ФQer 'u0Le+w"$JzlځzߤZ5>e>]H^vd's4ڗ0!z+ZU]\N0up <9y?)  =G@EhUobgTndr܂Üb40IJ}EXAW˗zS8`%#+mc|EfҶ(amaQ8'u{~n^iCLF_5=dLȈ B$y„)`X ȷ\ [N=?ǚ ޼LY(1EE`nCrJ5k/ @Dˎ;% &4Yldj?OFwչa0oLʵ1. tF; O IC7|F\TXVȷպɟ(jtӮ6p7n%u~F&G4+JPH/ViTEM#僊@tCGGe=Uix˵şk5NS.c8m3ȶj]iO J/; Y M v<Ӝ-|pvbdho= 羸8,ljc p=KRj3c% l,A>fAݠAlLg00g~mhŸwn&'y͓+L'-Z𹽫Pe"4g{r 8.#c[IzG6g^ -#71+O:Ђ_Ix)efQ[>Ql^ m.},,P-t\bjBhMD4~p@!)-UkN 8cK1wn(ĈtK(xv,Į+d$pdFp7 +d$Wr"׃5$ =9'~?vm_^S [+e!-NpoXW&OǪMUGYzC'̃&gvQ7P\0*JgnMv N`A~Gl:UU2\ڕ+kቊ)b* 5piIW>JtFN3S~-Ò {Z:bqP_?y/92IIw]atqp^"{NXZ1'WJ"GU4$gwfeO%߉Ng]ʸ,+qz >#{E&Vp!gb6p09: _8PdA(ҁOv;3}(h{ŠρKCp}S/6)(0G'|<6VVlRr+U$nN3mr;@D n8Ks.wv b,`izui`G=|jO5~4; tD0R>ʹĶ6tue,V{@_lgnMo:5%)sgHuʇ#] ?逑 #܂f_*[E P=`/y%2^˷I' KW! {C!w eރȉik!SF8U(]?X[uîmiT_ G{l(q[P"W*m)UR3 P߱p5P%ikMЊVǽ2EfΡ_ƢAPtl ,Q +wo~J3R3Ӷ 4'x^]e̠×-t+j> i{L$Je4xs/-SquLV*d9!-ĥ$YhpѲ*evyoͫ/B[c>?[Lm^&*޲cM;ϐa[TcbIK!/ۃH #[ euE]~ 𭟜ŦRоjup U:|4'7g7rig=ECfߎi6Kꍘw_:饱~ BfV6YdhB>]6Ja (,kW*HfO ;3*_v M+~RyVoI[NZ'5wC T>D;PמzhrO1qEֲnhE夃I;eKuwd fpCzљXsf} , |vByI1΀t^Wƨe5>+2sɦin;ڈILVR#%z扈UkulC.]J!1CW0] }maυsKvUKS,MOs?dLc!~gўIy2;^xyuhl٘~FVq'L|#P&%dWATh?"]]BWn0gzWWuQv )ET{tIΞY0,Q39ܢ4A`;7~͉5a9pY6G O*y9RMvtBo`. CkKu a|Ug^7u۠nr"7 feW>+ˑߠC>_gĎT%+6L`kLlm{ox&z/ ݲ[9ؐDt6krdĆu xjuVSzOGτj6xy =zw>IdI,S|C[@DU/z!Q8~5]؄Ѝ K3V5habeMnasﯔzmz׎F? (}2elql z!>ifXִo fi8(Q~ܛsBPBY)!ӽ2$ҽ0]juui= 3%Lby_cB%@ѻcX'W. !1C*rbS!Z>Dpr~Tfj*YmFCK֩D9}1ldU^I ^%b,- 3o6q<'2Wi_9M(zMbBv`0IX*U KMxFhBriXmKwS*e[pmHmV6anS<"%pE^>ZkFûWKKa.}.6`6fa|bn٭c.D0,<\UY ˱4T8  G&i|_FG`*c_#@~]w0\6٪ؾ4s%졍e^ݮ$8`K^ܗSq0AG x }-9#(&'`e9W|کѣ36Q(asE A5z6jTVoArz7FBl>/GSdh eH 9Gʓ*8, W@dҝ>!9>-Q\t M9w@8pJ ݤXD!Bj|EuɑK . o.:NR2- 1CzFP[q'H% "[bgt *h>N=&9dU2f7S\GTj4)9NƽtM7l,Nkz</\j2HrKۇUǠ 㕫7XF v4 Ћ|?0DuߦugATܭwbpFqelj%8eFfayhղIm -r2Cl_5wmU`<6Ǡ!t^6C:Tj3YsnClq ʴ#[ ;Yjhڼh3ڛVӡ= /?g_bRbE Bů;b/'=I7`H-B0D A+&>NpI)nHzP|r!VY#5G7:1∁V=R(g8]j}Q߷ѤWi%n(-c xB4 Vۄ@ʂeZ_\pQqxJ,5:j+sg"tfW{[ Ey;@WɸѼܻWBCA-{ϭ ڃq1kB~PzV B*GFjR`bMm$XǰFi?> W"_T[)DK# "֊z wdl8B 'Qn\9w' Dp' |s䆍W8lgY@X8CAM4ZooC&֓4 mE1eA`ɹv;d0]!vɩ5s[)vb:8+IwF>iZl"o֭Lt`wNPDбYL e|3׃f͔4轱 őDHf҂9D* a5U8rCBv?#p?it&(nni%a5O̩zwI4!ZK$*Jin&m tʝA.>zK 3AT3^nkA)^$j^["i]̤Woae"!m|`mEچ խnY흾j;˺k,bOPM:%-X\ʰPQ1F>c/s.SׂtD!7] @Ii}Ni9T˴Hdqozworj uGOy5xt81XLSsE ǃD K!ޏXI"~/OjǸWiBn=daddY 汗E)p}?HceVx?ԃ :K;XBvkGTP37,p SH^D|$q[d.D;$ zA|9a0}g~ 5 ِ5|_^:<'[4h{, 4,tgjeH)9ٳ{W1q~;vSC #F5ßچݙ[8{6>f7UɊ1k#Y5\oじ?^ 4_%z_nU:h{/ A6B[Mc:0w)`N|)Ʀd97~(U0r+ፍWˊ(bLP;Ajx$Ja^\_ZѐmOeOO .a&o>=KC-`ncH儔&ɖ0ݶM qLHh)BHIߟ}߭f*D>V.SE9E_4v}h˛Ki]cqsp. .6w^ce(%-K w>#O1 <{C i*-f|eskSW#Y-ͶC4&p&((`hAGUSRi(2AŹv9V$eR0ˮ,%cWpݨpi>Vz_ ô&?< ;$K1 <deo GnZԟG&&!:\? FVPfp]a{|gȅqB!̞Γ=T@ Dl.XK WC=.Ϛn# 8u=eXn>: ]|ʯK\ͶZTM zdlC_n %~ARq^Whd[)_ PF0Į89O[9;:4Y] ǜNrρu f!#[@FWa6|l1 LBҕ\C]J$'"+SxA<@y7zRӖEl@QeM9b'~nYX( [}km%!UDg+> =UY WN+.)U[Ns7*%|'H@7pȀmKY}oHiĈhB9kwxXcqG{PkkmyZ,[.M"9TvnfOu !)ή0FZ3W{0tՂ 5ȿE,`Zp-ѻ!^16 7o^hĪI;M*,< Esl]y@)Ӯsb_ +0%%FP*]陾NQ \kVnz]锓DpO%MnJ ɼ>~|c,9"X8\ڒ?{5QfC둉H^`~w~mfuu]|g@K %R*+(z@ŏ8cZFcMjL$tBxͣUv}#œ1)qNԥyM%\c/;wח)PiZFPa^p_oic%KK34U\DDX^h-hA֭LIs[ Ovl!IG?5&7/4EAObP{lPV (|`ඃf/ɟ >JvB,n`vuKB`:?.vMqR !52eAp?cd~z2 xLwA#bC%-u0DBzͪmC'|dͣO0]FaJ5Fv6aN!@N]*dA۴JY|x(ytI 0Є.'ǻ6bزR'wDWHI?a`}? ;;hK1@c|R$ccLls\󺠛 Z0PQ9'0}N2D "ږ+$39>g6 ム%=YYέYGl!.08A\v"%; ɻyTpA+l>2Q6χ=(hpNyPy|Z)JC "Z}/^hٔ *׏UĔ,& .&VwbG}"<4oQպP-R@iL- ܤ&7 ~=m$@W*FU5j-@_~2Y=7_U6my 3q'-U7o/c߯P+갈fx7`Sx-4o,D*L [E.z|Ң|ߊh': /yQ2A1rl_쎠g.N]#gZ[Ypuc{’:EJ|b[!a͘3QdGi#A:kǠޞ&؍*?D8 e3ӱ6E;hEد,)~D`o_1n$H٥atm.G>T/B3;-m8x_S^HGZkN_@:Em%d\\F5 xyAA SPoFwܦĐ3%'r 5)F8ݷ|i$.Bo/.X6wHYnjL劼4-fޢNNDE cI ' qMռh;㿿xCzYV^DžT*g-i ;w+f;p! `dQ<n qx DP` }%ښY)( 0훖G ;Y=f7bK@W&SސJ,įv UpXvkC%ibxHtX' lY*,V,bȀ R1DRQUi?<'X\ = mR~8貼gPU9Ղ1*3h fVH%甭ee fozO?1Yf:Mg/.Jq7+Ɵ-6J~zvp@SBlg[ n`YN. "#H֊*Cr;^tgOs3?&-sD&*]Eu.5JMAvz[ XjB$W@,ksmWir@*{#FcH&D_3nb_->"S|ָ>յ;ݡFG~Z ȜaSMt R*|"^-Jc.AO=tU.Ϙ˗qP|ג­t=?n{l@x@1Mrr- Lo^Bcy] qdĤ%'}|3tHvGMNl ؑ["!*XO)[%f~:%u& QgIGW  MCnݞ(,8?zOEn U<-RI7w-﷍LȌ}NC$m0Ԩ)w+h%s4{Oٔy?$ijE86ǟfLRSd9-/ "X 4NBr<[=XՐ:uXod[T`̓-\"̭Ec}HQ#b %4?[{ň28vD::>BNF+^ K)9WJD!oPnbQCz]i -BZJiƑxeopFu%>-.N}tinro=4UU=!09c$BrIq}7`cmg[$DR4?M`:k D^fZ7Vm.\ "~>b/Uf.D$Ҽ!T~swacϪrD+U7.|$Cp1x/eї`ܷ%('F8)֗|~ MJd3WdL3. hxNk,uV& rȒt*ŷMCq[!к,[dgTx;#'OPSa[1..4]ϸ \zoLZOք%"> ~%"bBO iN&@AפR5KBz2}A)蘿n95/Gxq."BjXl"{ӭ_܉֎\c88އ[2xjO7O`ZSq~(fVH /,v6=N:,F0wH8cO4L|B{k8K|b^BĴaDWюU@K@({$: T7jT l+h[LԔwAp3o 9yJlSE ڛߊhˤ65z.R%bih,Zy,A+?)"?Yδ\ dM'ӐkY+wA CvSgiP IA >GYjX0FDl^.O>F_7%O,!COR‰ c 丟  1\eԛ.oR%Ш[n.x ,c#Kg Ɠ`/S6mbnQZ& XaBdaı0X/9?|2s\VBcX"/._A f*Ux-Uw)f_\NQy;VDKQ-s-ѝ dx뀓 .%#:Eғ[Csu>'p\woN9>Gd)Q:/`,55`OBT"LGD߇"RP/*5 [W1{2)rcm)c^l\z$ENk1W7zu8UЅu}2>aoRzHV}ϕ1eUлc܃NSur<|A8 GL⋣I7g *\yr<)CP hi \diلM£ɞ.Qqp'/hynG*Kv&z}Pw >nCCKクqqRLbQD ]LO_lKz#ʔXS̢₯k*aJFch@$l"*dۆj $6RUOg}_DŽLėЀlP̘!դRyM^8uMOwesr%E?@iyԪߖR̤5])GeK*,FL3rݖKJ".YO,C%*gc:{$(N!zg\wV47hHYп? NO{tug2+:$oQjsW1a-/j[8UWo˅]n89_=8I3 l!p]N8D*K~aa0!Zx RE`r[aKdzUdJ$j֌CD.vi&yǫ+.ROMYx!jNz{c&\ǹXX6{rwvk>>UYqR;29BABϕp\f9OGnĞͦ]$q.l*/Y˧zEzO"e~NJ' L+]9Z#4LUC V|5 caoAB,6ҡtH&?Vңm[b@U~B $ڝRι׽$ϒ ~1ZV21pʺ%JBۨf[2e|D?' } "|Rk+襔?&aY+qϥa0l]gL5p?uݻס<)Zuh[܅ xAKF6\'!MXbr(u&|aԾss{gM-?v_n (-rvZ"^_wFZ`+϶()wa?!EW{bH kv*u:'?Z)^kg]*qFȣpkHxk|hQ Tv"hʎ5p(o4(Rhy\@A)}IiÃ$hSE盲ɗ`EXID#QjO^C!kau"H@hVg;bTl7C; Np ʲ,JfQ2y4h|k^&uoi~Dd?Kc*Ix= /`1M6RXCr5[TkWɩ*|G:m/U8,6G!9!׌e*@%ԣLQ6~K0;QZYQJr G"]?ihAO+ѯ]a/x̭$\MӘDO*7(~$d A|< Ӂ(\$6D uDe_ӏ)!Ht8}]3Y+Us'\>!HuI!p"O yYPtäE׿ MgAkV>A=KEݥ qh~Wm &R~'N-j%D4^=@n yRs%h>@´R'Ll GS'*]b=9O @%̡[P3 m{`9p&ўc+? oɭEQ/#g +6%_ e~yCƷ~/\kU\) jM "yWD1A L/Vːz*js~W! M"@OtQcWbq` F.f&}K1ܽ2\ŒMX;6_RP_~d B@|{_B2iґ{H/W ׬[(~7/$FDÑf:k}2xW;xueI w=&L}c9P.v>߾0`n3O#8] qYRj,_1eDC?8IA͞g#EYtzYu^ AIFQvSb= I]|VEdd+fI*&qɨ1s'9HwSnvo:K\ !/%R &&ћ1 ݞ5vû:OYl MLZs1,(ƧR\ȢT`PL[,:OUi[O}$BXhz hV{,lr'K" @+T^$wkۊS\ubhe#}*~/X ɏtdV#Yp %mZ{mf+ 8jo-x&}clqW%סb0kc z5m r/ev犩eRl̄ҍ5(yTWՎ=Z2zf IZ@kͷ)U,H95 I@-XA3(I 3< KNʰtM2[ \*iaک} 7$Gu3LȢK7Dngeʺuyd]>nj(8{9mNo'0,Re\Fk#dOİAn3eh4p_g-/`)NoO^krwm]͜\oHl'8:16lN.5U'׹FfVWľ8}NO䒿dk+DNNU%׸XzAn>Vj*(_*lsq&p~XE~xOBiQf쯳D0\ &;Y9J75 wrub09G!HUJ4 q?9R<*1=}om{[,l]iL;0լ!,OZNlY cC`u9RA̹!_%U6<.cx}UE'n`&;TOChre5fRU`kl6s]?}XݡJ P2pm5ԔЯ:fY36{ʲibphlM,*'f)Ceޛ۾LB}:V/g#~ֺYO#vht(m[j1x6i HU)VeU81w;Q?۔BiMy [5~%\ O~i ;NioRL`;#y@טXc ~)艹 r7eBe]l"F <+G/t9y9l0aboXa~Qn~[&h}i{ f#|-Q4H̶U)+E1%,zL ԂeS;``rO qk)"P{zθ(mBNj1w 0r⎷߱\G^67Utػ )2yӞ7);؈mCCÐD=f/2;w'z-:W?Řd~ujziKrXn!'-a8qzORQ4fm$aMHqzq#2cCYEoLo~ YqL}N՚Z5Fև2''4=\$6ǒƹQ >d+G,DoR5siTqG0C,Ji>hR+ ڬꥌ JgYma0DsaoB_S Vr2CH!PaLQxBNt㸾o)L[وXJ~aFFK;/7"qb֫b>=~Kڒ:5Z!1Hߋb.gF5ieCHK)h 1w>o4VO t O\n9 T -UK0Jk$w6 5oa!nRQE,9\̜$eԦlP1YH!K U0{oD N;=u )4@hC܉kJ%iК˨#Zsz*gƼ_TV ?◭JO|þ/[pl|λ-܈(SvF22WeuaQ7a#KULHe>lZ@ E"8ؘs? 򾧧"C* E3?rqQ`Sz_qe6.(qf.^zzvZת/y\nR!o]AN 6nNwC>C[vE]ܺK,ɻ6 {!14]k&bV%)Uu>.c (#|`kzP{׮.OGBe_+ 7"ꩯ_"Hֱ~6f}؎7z8™CM_g q6clVa+z`0oG7籸ƛ4w=݋C`J ӈ{GOCS U. t4!Di"ʬ~"Yx.g> @nk<md͌ok] =9^I,nbƾ![>.v՜'5'|+]ְn_dң)nnGaǑR!Q5݉@9ZRwb6o;N ^1WiY#c~Pi iI]͕|_KoR^eWi3n<mN5O_XkyMBtQOLIUǯ5•='qi!8\tj` 6?- թ70dڢnR`%\'͗ⴤUu+D !zR|`{"zarM09MTZ_QOb ټs ~E\!X,9AE:h$+GZL돷-Jld  5Q=PcQD~~ U +L#5L={<y.fC9v*12B\H .Wbexn0~('A 5ȥvj?#2-8 #!#2.ѵwm~5=sӱ ' S6ꄌ~Б^o ?-'}uۄ4&CEk(vO:3=_]M‘v15 h?CXυc\4HV 7@[ - XyqyF[J/fWTe)q̈HL`lBeAC%6J1 wZS$e: JcRښsQ:,{)-8{`ZۨYv*9 a#LYzk{'߿NCif^Yn{Y^*%\hlG$CsWC8 vl[f瑴wy<#e1nz>#uG:*2[ѳy@4gf\5\d跐ލ Nj^rhajX?m{+,vG9;+4a:oј6w|0%V&\3&sj‘2ەY?; PQ8+\_3jc&$K,T%/YXy[YɧOa{aSUԥpTB K#ak¼iXTJ滪N0zhTjcN{)RAz_]r*(p 0kȟ `qAOCewD =?%~  < #녒h)Uy/1#/=35_rLO8H߻AZo ?\޲>GCMO3jE# pXo81J`c.cȚMz0G!13"db)Zt6%'YNQ\]eP=oi/"iR1ADžjS1E'J=fD0A1?y7jcnzz W* ä8RQ~?Q'su:pN'6ˀWQ6j-p5xNpOA֡%X|F {}tI\XI 'pb~hbPC@GuÐf8nyc sHB;sqnVT4_xvy*{p"i0jC/[̋RkYWԀ)ZTѦWUNghē_1g+y!.{OYsK Yz7E4Ki`1+cmЗ'|t|Tc ?~L&Ǐ@q/dtҲ;3&w/e_mcyLԙOc'x^^R{9vݒh?}yע=#݄fm3X~{UtHl jB^1:a&t0nqoNnٱpӁ?=n]ysP`7:xNDb໵—v!"ixQkvnbm9^?^3n_װRٴ"U>또 Tkyr#Ut)[wߦbc7=p41$?o "@x(`t~eUzf >@Æ;֟hX 8\kս]|?hxҬGt5<(WtWfTBp-{"C.ҁ3ϰFQ)/THkN#qݟ0a(Z^mIJ*ox[0y*o 8B_CMS j0i3h5gv̈}2O L`uoj0kԍp ׵=ʼn K!O9 W8,iuƶ`2kY|3UD4P(L=Ж=+H^zvsp,)X}?y&xcj-^5u Erm(L~PGȻ+Y!+Ҽء۶B{*u礏 ԮM~Wfa NI%1=$kDEM2 mPLR\!;NUUX#%W3A_'8SCPBp̥VOaAFsP^g$ 馆^J3AuCjm+.-. {(7KZ6<|)\\sS@z5T*Q%"fQiB_͢Q{֐0؃ [j,Ls^$eQRw`Y2(lxkI{*)jI)S? ,bUkKq|4qЫhAA\ݛ:Gj1fQG?%ERe1$fλ _ihR<ޱ݉e{}{IFKg[_QDjP$ /J<_!Wp`&C18}"KAÂ{]܎Zzo# `%s@+\۫2{ٻ}}OCMA[*y`)[$c*!Jm>.AB~V/=˂<Icu;5[i K~CWpmߏ*0P\mGt߰T1fh؟iAK>v= nH%$'9}`fcNęz QiDȗg@ؽW];G9'hfie934㊐#g2 !"Ղ#ԋ1F" \TKSm̗]g3v|C %Fiʍ_Ȩǖ%֨L ХVdh<+ZX&#ZUԤ5&}Ae@R _uD wu(jY+.[c&H~*g*v7#r08Ӂ$H-,8PXZAN}?U?!Ђ@G&Cڶ >! ^-t/M3@ɌuC[wh}ݼ̂^4k=`4Dx=s%ps}yKǂR#xձT1P6>|4*VWwS^1zU(ѧ8ѡ^ QY'kTm_Tf%YcҴfʬ}gG \cF /lNh}>L^0B'}b1#L.5fm| ,qkPMUʟ (HňttR%;,_>MQ)_.JۇHU^>S՘.#2@cb0$sLes3-[[7 $ 8{P0s3Wpɽc4HcvwzؒeN>x.(GzpNgvU*6r`O~;%}`W:N/ W&Gڋ0AzVظX<;L}ppjXoUa8SP[6ºWotEQD0|ZBJPꂀ,p"°܎Y߬PE>'o ?Ϲ‚G7|_4F:<v`AJڅ/_<-`w4rzŹ~;M".>?6A9r 5%>IN#<.J Wtj0,K| nIS Oĭ򾄻lQ' dUX2VEFTeDR05S}']<هŻN7o~fQ pyV 5|җV'Gƃd1aL3J 6#1*l^c/D i!`P]qK=<%&,Jί?K:8]C_4]kgڀ1%rbNPXjhg TB妲:[N%X2q?YTkG_ǼLEL"x&9Ό,lX-E_]t8h GH칲h{V˷2#D8cjA2܂%$O/3Pap gw<JA5%='E|̆=mȃ2h"{Vba 1CWy ,x-V@H ;2w|)л\@d n&ww/y`s zyH- N#pd^"4bea8]v2yN<L&b!M1|1FQh‡eJn@.Ev%-Qv5>c\ԃXjP*AD4A% eEGrP+hHBKS9HSIQu_rK 4R BS bHÊnʃ⍃ʰt}ҿL&P$5Qژm[_ɍo kb=Teݗ>TʴWP [U_GqqQEc>N\b|8\6PZZkêyP? ĜAQ쒂Q)dS=*QX4gڪgoKsv=tK9|:,"SlC .i e卋dan6 PYBkɍvwkJ-[H%gh{clڟFΰ#{Mւ?`g¢=ƾH4[)mL-sv{z y9Pec[ ,vf1q~Xe7N=D=ODa_؈邩) VKeDz&l4׍npu4΅YqوgAA{`jf%T;X+X7>#uYSx@NMHטilqi=0gi?.#5]d kUt-ʸyKE{LUW]sF2^h9}*d?4ɓvjd[0G+l$O ejk=v'u;1Rں;,zi* Jbi7"Y01D&TrR'ǔo`*B&pqz%}_$ 8fxgbu "?H./PH凁B"nFBtKOo׹)'!AFde,i;[_gG3"_%QUkWLTLUCԃf[ܛ2,kUwBد J> n RA.pvnWUW61ߨYW[f Ra3I$ў$bRF2{_=t9x?֢ ;J6p/eBգ<츻Lqc3t(uEAÇl|sswj'J!d]-\gpсȲlg,S_݀xS2?Z~.|ȃMfaUf?RpNS4K1I94K|;+9хp?TR{|Nxd|;DzY1|aL3n®Y, 60oPQV+CWD-/_#7aZS0%h,O3@x=DR? wrK.-KZѧ)AL.JӜo#t9d Fz/g82 `%ɤ}Vģwx?{HBʿ*e[$eRZ"d}Z6Ԛ!qVX"X|u9Y wyy!twrVs]E[ѽ/"$O~y\A2U.BM!&V6p ihZV 9 pwZSBR ĂRݐ4l4\ientnYψqeV]3-Wv]%Uf!UJeOr1=QihP8JK#y6S+BW({U۹@)nl*O}c2/g\ZD`?S¤S/ Dždrr7T#dÝYdTDQYbT" ɢ5b!rjLCFǶ©!)}~휭z_uiŽue~+TpvWCvVAuo U"¾qƉO| #S*"K<^0"( _*`ήݦOPlF]7D,c=h&H@-9evs757>=wc}@Sx?GO% ךl`0]XNQT9@)ɱzkJtwh4m%;<%ᐉrYp{ v%P60 ̄Gwȳ[G Gɼ@k yMMȒM$b頡ri9{׽NS0I,\/d!^l^Xe+sw3 ʯmzdBi*Ƙc)Pu>ռ}M!A{g\G;|6ˇVQ*VlaOfy=+g{Z69WѦD0#LZK&`3NӴ".KPfNQ^BU,#\8PYܯnhxb~Vc] BH VĶ^mCx޺r,>QND%112z'}K %`NL4+CO{ul}OOSBWvah82&[wWJ(u?+̉ C3g"ۡOYk4Uod2U^UBSM} ,Ve*%VYؾ\ox3[Nn`vKүw4@QEEV1F@ *C`$Dut5p|[zَ10"|ܷTM$띗ƭBgɉ5C] 14#<́7'^6܄*] .k:v+=Z+<Ч"!\*,>?Xbr}CD2oW5X%?\&pb^{ѕƷwsP+MB]P= 4UzGf=| Y4*Q.NS}]ُeb?kWΫN$͹v-91&KqM$Ei8.!fb5[{#((!m m\4LpCCM+WZy;/L|Sbk!6c0pYkx~  f> q˥Դ2iCim%VtK2(ιua|pdR;PF+| 'sJi%'$Հe]އ4Y4aQDz%k+I :3$Tg2$+.bakv= *)JtNfRm~UL^Ӯj)>qWš %$F½f%G|38 fS/7zW͎ݬ£~*l DuKGboj='%glĠF:T?y>!._|BP)D~f> Sm̤o,A.ueUzƠ{ft-JKlk ӆr3<iB-4M7hHɂr<\A*]BQj`$feרyPa2nFE –A|edxQ7*MFO<&~lt=P?d}DAzM,".)Wo]UL"Bǫb1zp !*D_-L I\iHjۖvt_2p_/uMralG xGf~[EtsQ*kK]CAl؟,P;n|W{HvwΎ|pLD}Ϥ/ܮ*T8R:o[=Rցu+\ M AMJX5<]nҠ#pnq7JM&&=yh逩4yWl49Qvã믯-iD'Aʢ>ne_faB.4F-lfDd;wj-`=}6g;]8{;O*)ߞ}zR^pj!x1PcңgЧ3/1yLi{nB>Q-N{I/ODkOG|ɳ[pMT`Y:3@LB/P`- fhͽ3TǬi𞌔cN.d *FeP5IS *3g麻f*UT)wB-34.3m{۲7 rd.t1iOZp#_Ղ7>c4֡Zܣ1ȔRKϣ+WC}DC"Xz5 Ț E0Z7ؼl{! sGP͍Gp# O86Цx~ eAlH,>L~O`_槉lPĪXlAuJ`k`_x= MH @my}0A5 $Ή)PMs+ تv[T B滨ոR6v4]m?>!z}n2l4g$ZbH/Ht V8]deq] ;nwl 暵ricMw>;ABA.9l3t2)N ,d{f0j!*qN耷(>!;={Sr {.N7&X*1RT 8T5'& ^h_kW&m4R_J3T/U _kSade8}Aȶ0 - Dd6JVDi^XKW " -#E1BSw9d8ggc.> s$/%~23 FSiڼӽ<g XL @s&Cɾ'_aj)+׫'HP-%x r@LįRdcCMgEOv+q Vf _o9dXLFʵF֒Xgr:mP倒J.+Em6Һ7iEa]:M)QE?he.Yw)n Ha!9 eI>B@o;3ye_ G!K5}RM&=4`s.1I~tYL~\yŶS&zM9^,\%q8q:Iqk#Ð˟a)[`eGi0atQܒhpd%Z $d{D~J |YQlA{,Tn(a+KIU k>nuZ*oÏ˙5yhKSyKsA_q5RTnjTm>2:nvq{r3tW޶6$op ʈضi5z';J ZZ/YZ4RӖM!>ޥnHhB5n8av&Ђ#P%&x?ƞfr3Bjtz;>z3 a݂dP?#Z`hrS;qJ_uẌ:iqMW6|scѦN.h5P4&z|msX. X"7eBFh z!߉/zC aFLf<8㿓j ӶШ5?&Ӽ.jL#Brs(4(?"[bakpQ ɎKi2ѰU% e /ֵf!q4]T8H#zgok*|_7+CuCů,,@3NPmcC 29оeٓ9rUnznjiaSd/5ְ -pIYoj$Pl]*s ˎe VaMHDŽ*M;,|PQ[+;⢺:d_j̓fKdU-2▻M殩k=q)ƲM26DX#+Tn%@B3vw&"osI:fN6]͜ @3k0[#O7Y9sxt_IN0qzV&5TY ,(m ^Yk,<幅u+ɢ󊯝Ќ/|8Q5mƟl"Vz˳Ta\2=Zrrm`Ϫ Q%w=!}u BlYbs!5v "F?)lm!wKzZ;.j4] A ӱE[Hs 7}=0`y4o J"",~FB~tv߃>`M>vs ߌ"f$ʷp^f-q[ lf^L@OHB2s6_`=N`e6'}3E[nʏLB7-d`e:c]N|U .O!ֳ*3z]{lOۂmJX{o%p(0a](㼂ËMTzR}`CٷuEd`UctAJ孚FgMG2'H)icjJ9'ztUyB \1~(Q@q@VfWTI-,!4x9Hx!`Y5q_`IhKxN gT83טoM6O_'&eCp x6^ر6ĜOdaQqlWR(i\Z۱1x 9%na[;A:H5ْ qA*)qbT,(D6O#J['x`: Eޒ՛u9,Zpٿ0kW]u)V ?@B}ާ@Yt]Vh6O_vI5U(y(iIM{V ޖi2h u/0Q ŘdccILJWf^~VF_Ζ=4mC\oڥ`}ZЈnT)?g}s$mxŨR٤AA;h)ͰIz%:BgӰ5/޺kLa`] yYQ&'f k@Ad3\o3TѐT Arkq3t EovVz+XH]=pR9nQJyߓ[ytduf9(=arX=*׎ze #@w?;OFNluB3]!MuX_!B>ӎni:rB (zuQ Ұ;_̎ [=x 6f&h%Ha~rkM0zl ⷹ"oZy&j<|RUePWpH"cv ~D: ;aJղ]L`>afD.sG_o ^wcBh$Vf6& {l,J"<􊦁4K: pLlܰ^!oc,1qu && ?PL!X*Ae$h.Ab"^Rsee^X2 bi Yeς4$Я|\ \z 3 n9M`Yqߝ1 3Iean'D:$[bNf15U-FkXwČ܏TF~yީ"e;=!x( O Ws֚0t 2vC[E@mE;ַq;r=PfK6I.2GΜ|p.ge0gۯuw1!&VtNy$Q{" Fv^;ۤ1y!cJ|>{D49EQ--myaH)%ƫm xplC/pMedSՌ*TypNLYH,}to4$3JJ2k2v]G \GT4IGfY|J7>(w7؍0%\޴FGl>zaI8P(U).qKWEir*J@@føy:!Z53 )x"%4k$sN wX8)l/rycBE`$wN-){f࿠/JtqJ,cFsdO"5[6^8_-5' J\-"K"E)$|nȝ>Yᦿbv,Z#_àQW'KMju黤^E9ӄUT _$+{HnȊ.w5(p[{mBO[ ؘ8"(x>w[z@E;B`wI9o} -RN*.lkEz@rBAEVuvCq{V<! ADI=!*5Ѡ"*MLPp=1Dbe~qr X+)%L^cx$/q2FfH͵O*hk$d3,Ϫ6/!%u2l(Iy9TZ^yL5?s[j uc""/-P^ g*#;? 4i JaȗX|bxCP_jʂ fL% ~NQLgAL߂RRq`E#|[+btB̅h5,ۡMP Q WRzR]40>-Onw-qؓQ3N_8̕=ou?ƿ㮲e"֏&简J}c0g82f 뇂<؈cНu`-X+e=fWe /(-;1h2]EթL8Y`!a.ӟI_%n&4w9AHx35te-6IĹʁd3쓳,LsgSV. `0Fg΍">ٻ볉DPߓ0G|3  .xg_Tgn*X6HY4w嚣.(zA4U ,d#~0V _[jUPMFk0*pY2 %Or; Բbp,}ZaI@yȔ#xW~hjVzVg`LٮTFvjjy>h; D% .=n^EObP'a Gii7l]Xf7?[[l[%tgy\v (дJܓav[)!MޭIJ0G:%r>,89D>DY2. DgSȃɫ\"o 4> KAU S4Rnkuo89'~QD,)YLs@YaC4Pu\6a \eY;Q[2UPMs88UTbL ۿrYOI㏸lӽtx <*P a L{t5& URj~ll&Xi_3_d;2 M?MKo(X*vJ#'ߌ+T9@/b矘!vL6h_9+X4O˱f}J9|5̀ ]o8ս'|ݽ G6\_`kz+Ea;%(H'lM7'`}SH4,K.Yt~ɩr+eZc4.KICH=n"%d>RZ Wk'nbnG)_Z`8qŊ;LI..=*yvؒ/WhD7!E~MN|[P|/@Kf?b(-g5l S7V +Tw)b˻L!xk) \v~q \d.4CRMC&Z t9WV6@4}YSM]H4h_AVԍ0v"lث!׷"eʫ5Ρ&R9i<3*duZ;@ڢ{K2T]+<Jދ/Qo){e=7 pszg_,|kQCL+z݇K Q&p:K0Hl ?N>tai5MT'p3!)J>4c eEEbʆJP#0=z}ZV\t @Co%ihtm vϨV-X{Ml8=F}26U;:Yj)NL[yjjs<uSgX-eq|EAw,QC3$H&g  '$5w- `B&Z+<;-kQ@9~ ̥b*a/0Ԧ3"*F]:%ˏ,e2o(u2~1~yV<'z0ࣜAk- ϱ#[sLʁnjtwuH5K C YU\Q=-yaE? `G,27ۂM N^HmWwq_O;UC[ $aBB⢪Ydx컻 'aȳ6VFZ ; e HЙYз_o|J)S}edӕY0VeaoQ?mj X4e'6f]#?ql&9p%l=<8ybc)dF|( %-pyzqY *u@!&\,~.QLrvn&lZY )5vUL TcŭpF byN YgӼ"̐%*zO1lTPl# }w[촑GB/PA0XNMPZ=Z:ν%QXaI42X1r*c7<%!ElIO⅜OsyƳp! 4Yk{u%֟_Zq i<`D*)<ݻo6ސK%yG.W3LT :<"uǡ%#  \݈]e+xt AxS3 yHg xGxSCvs]ldk_3'V vSZ&&qۃp糧*m#JRCPdX\䱰bH<|v%.(w8USƠo?F>C![ dE -H\* ʥHU-{C*ܟt`=iX,cxƃ$xl=+tl>>^ s fxJwJ Oȝ7֫L}4B Z" -kRA,?''y'Vh~:~#ơ ƿAJuJ Bo3IV32"B69fԋPZz"0"]6ce"~reo[r 8d"BI\COm^rC pθzRa%} /ߛA1yf&8&~=G՟_T 9{ەW-< AUJiRp:xM2ɜ8 ݰ7gbr..rBQ14Fq6KeyZMKի 1H+@+< mL?P] |A*E]4e3_K&wtB~3/cii}' ~*c@s"5<elJ3跮4qC"|1dvM(l L|bVy_bdm<ϩşgd *+5.TMLiXg>\¹-yLYԓrUSI4%دV%>3f{{BD-I;vK'5BXvK]G%AlZȶZPx/NFGL13%m|C,(rď@5Fqo:3G:0;f_ ?o6wTr7Dg{hB cXdTMe0pYKiEu}Cm$NdZ.Z<"@vC\Yb;g^ Wbɩc:txJ`z&m"-R);Y2`'uPȚIh GѓCCXB:V/[UL+HwG=@i^$Z>X*h`DǼn6яƸ-t]2Ul}0jV^cƺkգ$o˞hbQũ-@yNydWsbmofO8.1|궷 Rg5A/xebNx 'gB*pD045Z[xEjCD2jL7̨1\ckPZ?b;I E61.҇Coma9ߛ8"0ΦsL ++Fwud*BTf囟zGd>han&1\*I|<,BX2kS0_SM ڴ ('D @2A,HPƿB6bta>jo}kC!r3:fQv7ZK6F(֩rڎ__E; v}-$W UҾӌOc 25 ƿre:yQ^KRZ|!1WkCsU,8|Ъx ?\=OFl?BGVxRE.(Y/ya*{o+l KH`qelHEz҇ƒ"ӛy&=c}~{|F[ ݛz M1Vz|j`v<:|4s\tD9H =FgT']wLa'J-F;?qnu8qX , s۝E1x!#TA>,bR<<#5xd)p2ʪ{#m6q+6P҈*[  0Kvs)cW15v@RoFa1"aKQΚ~SB[k&NW>ģvsͅ])3m`y_ MR]6 yt%oX6&pSjGҟ 6m|v@_'xҜ,ygQBv^nbBg꽮a Saߠu$MpJ?Ʊ6S@mt-B'AIsGQˁhw:"&_~ϖSlQgc +, ]1EUsD_1N2d)0$P:q.ÐsCODQ sGwU) 4Մ_ɆM1;.Lf I.)C='Zt5"[iAY%93H&zb{oN08A;lϦx;/]ʋBj0SQcrtP^]Y48G$cuI$Pu=3ZL ATR,C1l 7,``l C$z;-qk)%j] xfZ MՈْ KN&|Z gqџY`~uY_Fbqځ 8t|P=Π^mqu o4@W!1d.wSU ݤXx_ý<$A&Q+?zsIn!=#i3- AFcs8=1mMV-Q*j0"m1dxfAWxoTj(w/]?Mҿˆa .휑Լ^Ju5{\1rl(޶|UE8(|r]r; rTRt8&?Ŏҏi5s$EޞSE.aKwܤ巚!k^{P1n=»-˕<\H4ݎS`wGϩGY 9!Ԓ :uu5^C6I+RHJן5Rr/u[>1L]kә^<Nj`MOΠ~&¶UhX3PGk f$Jtt!mNniJ8( bk,rg Oy:oV̘)YlpK]F}ue @N`tG,d^&4s̥xZMCGDQ+5PYֲ޳pĹGsF:,_JTB3nEZ#wm|Sg5׿*?2hJ$KT%foӦxS׿4`/֔zuyo01O+ 'ԦٵNW35.6(WwV PJ94ELh ):㆙}0I,e 7Sz^)ay(Pbr}Wј@. Nk0wm$3>f^CwmoJN?XK\.J,\a !1^/ݹ]$;@4Bo0<%*;o@dI`hXR~0a0cj̺1[KYVʯf]/!*i*"|E=+720}CTxM?V\-LhG5u!T&{,C<()HEK%QF J4dBwG\q聑BOѻI(5ET{P(KA^wcd:v\t1Ela0;Oaz dsI#哆8¨qo\&*OH(ymm8dR)OA$x ΋"y;Xy,:7~Ro9G5Gy0j1 3yC{,kϗy),Beᵢn4-JvKf2rn\?aY~_F2X=.%3\KIVN--*rC5tNHq_W?vSR|<]˟d%L9F gLP0i;-_aY4Q j-1hE򐴮}_q}RnJ%Dsr?xptROѠϓ~F^誦qqHW4aQ;I29mI+/,#$$L[eM!`+ynj*k}IhK|LNmnJ $µlw `r'1m! Ul5D38nOT` q̞V`z w/+^ $uTm*N gŠ{],qrMeF4EʸeS,%ڸ\VsӋĬۑNׂ|W->gW 4y,mcR =6ܛ$Gꨭ_\{> 4𕢈@&pDbwQ"q3ﮄ/oj8N!i6`V9;. m*R䤲†p `]M3<{p[Jo3̧RoadAĐ͓ D/[vPi!_ =OG`-~bMG)7HRL(n^bk< kԩ+:*&7ARt ٸEoF.)#=xC58ÊAq3pJNώ_0AHŤ:naeGt% An4Åm^}@&@Qke> 4ޯIa:nt@#bidЇDrwg$FkDVhϛiN;'3KXH@hTvBP4:Ԙtr0*?P,oߢ7./`&n-䢗x2ȕF܅BDWمVv-Bjk":Ex`-!aFDvТ 9`+Vw; v>0n\x#H*b/V D%=:P㽷n7a@ìr2 ;\i̯I,V9{ip% ȜT(WIhاg#[7_*+W˼6(AnŻ_FD1eBYӻlUT`(јL;|Ez6Y^5(ǧ25bz2t qڧMo#ĐQ_ ˭uC0%Eţ_oQ.ZDRu*l_sMq gG^".&)= ټ'1TM* U!w/|iOHmƜ3g޵[ .އBqqx;5Wa'fYcG~Ed*MdGy\7լI: Y[dBr,^^<.H amA} uvnV0\ <%1ؽ,4hm;+[G܉-τ-M~i2-*gA"#x#c8ue7R LsD-I h;ۆPc ]>%+ 67{p+tu{ؔ0Tޞdq7֦l5_T9OuNBDSȞu`vYئ( +T1g~ϼe|b]DFXuN3m_?UpTxOž1xb%{?hzDf<\ܸjhZtxtN#2f[h &P* hU$ hރA_֟+瘢ou0h0rϕ[,?{0- oimMt*Ӆe0R6R<aVިo9#bGjSތCW67T B&?}4h=o!JHO[wI o-5QfDY$&^J8mvLkCLv]5vy}]C4r554iljG )6ȼhc"M,1gWkv/:<u(r~ANDvax%=?5 ݨ[vN07[¡p<%DT~S,}qq`fg$k uIFzs=YtvMNh}+>M+أD!kSe,sLx;3fzԟrP)[-I]At< Vc9՚}\#_8cye/{)g9b8+"Xӭ-ʰD5bd{? :_6rSK P@x_DoJMY{2G`&}? #6!%6 bCʆ-g0I9#,`o;ėкfk>8nXy:鴍Tys@Z>~6X1O3j ^:3۝B1XR}蝥JߟۚS~|K-w%2LZ3dZZRkmJy s=eu__^ը%bg2iqB/]%v ̴ǎ3BlP3f8w!H`JYQӲ,%,bWYIw9/ّ Q;ݠ d^O٬$"kwMOڻVN|Z&JqUe7a&*L#m'-ρ)@SD;DYSPifFQb寶 8WO)KTpeH 9*Z#wGaR<efmV;|d8heᘡR;j_؀ONN  kO}iJ*J()OvA(Z+7A7 0*H $ц_ɹVi\WNdJ" dW2_n 'oGc RSZ`Kȣa1TNˊl渔{EL8{ZCb'0[hGTکiyJӚnzf^+:W'S]l@?=~$v1\qD@U a Ui ^HZ7ȉ =@A^uh,3%F^pFZ-- "Ű1⛈,r&ja*„rl KPɪɰrIϒ/𞵶C8pWq|4E  ̣]\5ɶm ;t>h'|Jڛb^ޝVyU,ř`XSzlGhUf( @_!`2R-J`0o̅Mʃwd=LD Be׮Te )d[-CrxNX_݇sXtp6?39ञjtЈSb)<?2kc#A`NomjKމoW3%>; MC(_3s=ch裏D^3-% !-/ P1+٪ % NA%B3>.0hƷ iyJ҆&0 zA&. XJX!{' culXo[n^Mf[XдL@ڗ;jRf䥄o%|ߓ:߈N2D1 I #faK][N&G޺RU_G 0L\x2^`U+׳nW^tuȣ; riXl;r8.OoR8:)HS-YxHtlat^9@C/|̨C{V!ܩX-?ZpG/76 b!E~3&& ydsS@z( X)u  zVTw{/|$Ԧ]/X-JAb` jOlf -Vv BHM]*U,A|s4Pց>غ'6ϖ&ټv{Rla7X %49P _uߕ{,6Bؗ!YZZL'Φ3D:`K;d!1Ke>BC׹v˼~m޷>+i8 MK:d#c_D됞})M>9ff'di)(]إ%ɞo?8jl-d| n6'X45Ǽd%G 06aW(rtd,N@^Vka6,}H-֘ZGW!b 'RK69a7ZqM\'0 Ѵ5 :$,&QAjFDzܵOx!z. U)u`ż*pvu:ݽD1_|P|!f]4H _>ϗ1{bt63Uْ:.S0~S y"~ZyZEo-Q\Q Z{2vGE 0H?h*f{ a[X[u!9Q1ٕc٤!ͣ{eVE Tk0 UW/#Eb-CdU5Ա man,MiBHq#8˸E֓ ;~[Jk~~vjnCsc$`E[[j$dȥ+`~}o`FvU-KjJEcTFjM#h P&=<[BUXa~e>#q'ѣߗ! 'rle߬#iƎ,n.Th1Mjq#Q*Ίpb} T&$9I՞ X\7w#f-T ق:j[Ӂ |nԛ J$<#q! ߛb#l%>ܖYQ(GIl"_ ꭰ|YuR?;L/9Є7}pv[NtEV}(ܳՕн7`iLus=*\c그X&iE3kɷzh]l/yJ^{AH*8 N_Y筮v*UT2(e~̦n=Rl'nf,r U"N"^ 4n^fhC>HQ^&";FwUϭuCwu)1nF dkgaF'T0iqu5Mb bSz8NNxyZ@uXmZU`IWkf aØKN]ԣU+J/կBp^fP[~y0}?zDZώ5~RR7 r*=ܖmU&tEp0TZfgP T-xBQ`hi5xsq$f( k?>tjO ;|'uWPcZ)EZrd Sf<-̽aO FAPI+w[P'$ '5Y|qM$DǒnSD[m2̧>aots#LNQj.1[Df==hR2+K@qCJ { Ş1ꬄ7nu6OH/UzM׷Ȅ}O Ep~@$Lc }vƖNlY'KľHݩZԔ5j:ި5R'ڝQ sf@6~Sl{Sz,Ir: fޕ~`4UxvB_W2q-y uYrH\42/Hɸuf$rGkwsQxu۳>:\d{Dgt_.[fZ-pw:PR[[/TslU½yz FG;5Vex kᵩLMp,#h1j/k=fYnxǷ"ӷT"t&au:9OMl|&"F3iфBKgGl!"A9eg$[26% V Hur#x5㖴RtuȑBmJ|}/pǜR])xmuu25"HN-3;>>&θ\c ߃ BT g.nDA_!+,MUہtvXv+94ծ\w6 9gPa +L?YQW0PL.Otiw^>"B0j|<+uc d?nl/ݓ9߳D0Lɬ~d1HNldJۮ]\ MT}Is-hu&ցWs@vI [(Ooh@" rz,*<7 T<[ }9JD]C7ؽO`xgyH#P"|ЌSwܶѥ6S)c3 ݚ!2ix\aL 'Ekr ;x0 @\mG-6)tPk: : t|]!ߥ ]_n9:Qzʩ-:: -x@vdO ÈrWkV|!xe& T랑6;O)"M1> /)}+}7(=Op-DRl'o /dH1ĵ<<򘛥~M=(8I&_6*dA;cwN\j$19uEkgOb686&j@9W39J_&"4qToT ˹ J"{(0@.7'?$UaLΙ,bU* PBtEI%O#&0Z^"Γ"ΊukC{+e2R( !c;cplm_N. ?_N]Φ+z`Xܳ _qd7[&-1Dʕeͣ#ILٯu@),il4tW#UI!@B+O n,q G1~)p\?SiQH"Pa} ![y'}2cѡ}2l5cMsUIG%V6c$Y2NU~pxi=lC5MdIwXve^kbzHo.O"Ye؞;3R-hܺ`[W &/p"IxPlEQSqHa'{ӂݾϕ(vACzx : W{ֲӈ6@!'"6mON+J^vaVwGXdo@a}z ! Dwer} hrҞ=?2&9Nj`r.br#f)C{o-6O'FBݼj>d.0tTkF8VoSdШ 8X"yAOʁ^,45e8s;y$grLIA7/KH王FtE $:X#Rt(Ϟ9e)qpx Kږ+;_.i>r%,Q5r 4qS0Z_Uݖ^1u]KRAD=ҷ<$bNSPׄuX%!^d"֜aY;UGAit)\} @LZpwyY՟rxF[ҽ-ʼ]Swb4Z^^\# ubI HdVVa*~)g=]T.SGA=vqv d=?xg"(.U ,ZϮ"c3scSd莝?,뚸IIJ7./^,O88W5%‚JӮf8F[@#1 |i1$g~ͧ`umv^X$P.nq4`JbFI˭2Cǘ9<7璞(kiQ1D>AJbjԗg!9{(^<{==>eFz\`JO+BY**Yng bakKOA /zUDᷝO$g\Bٜai&CGOs:Ӵ;[cevC`肵ҡKhp:l|QM㩾=o墿+ ^-Dsr18uwu(ƧկR}P#ꍺ{;,ּ`==bDWX7h0jx98#J B@qO>N>O1Nk$ޞ56eF.0bی] !#bBoF7XaƼʟ~2_'3=oIl%7h,^2O4}L2N)|8y{w. 't5nIԛzI6~ wL71tr >V=ףtxS(3T6qUMk2avk뎐m?>lr% i7_nYyCݪMu<ƬAk\Ug PKIqh}y{R,k<;Ep ʟ}H'|Kru~|tZN 'Dlh'U_QWkqAP_*Ћs d *P:I bzOxdx<e4r|ph M|H&'$“JYG_ J =zTnn4c i nTM3*U2^ơ'th%:J'iL_& ?#^t)C;5v/ ǦťOSYgY ɘ1B6{aלlNl]AQӍ"Tf1kͅ))x"uA}tZQQuU?ٚi|qׅP K. $x qC.4fMZ؝x?/SO,׻Hh# ]ĕ{kM@պ?h(e~ #{jGkvVaB6KKt֥IUz0!ŤqcQnkGyz/1fѫ' ` )Ses9~ !-aà6BkT kƦ~H=ZA6AzEtR(H;pF6g!>Zۥ^SP[no{*E4>=x @TC'(79@<|8ڷ+5} qA^Iz)2^2\N'ʠ^lR2gT@A.E@ܖ1 j~ 덈'Z8T}w < )o9N.O̍>rMZ mq)i E٪}?!Bɖ`̯'Eg3 ®՟%~Ἑ7wGḲUks&ʍ%Sk8MfNy5WrXZO wg2xWo_6&P@џYo4NӅT\.v=mOdQnӣUU4]4/=UXiڍ=wJ/~Z=<)Eۢc,a]@8$EQł5< roe԰ )iZl=DL#l'ss2cA=F;4R$8 3Y$@ǂ}@_=]AT7s$1LK'?߱G?q zAy.y+3u{9/b>u)r/^#v]9nP]c#Ӳ+J{VӞ6{ %;{B{9+1hW9o5~ޜ a?-<)_HaP|QD C*4A$jrc;}6!Y2mN7`seXéDcXuJ7֍`5{ *;\8[uy;w_yr)j=rq'^cYv)ڷz&X_;_o$LiزtZ<ݩPɱpwgpؿecB\LD$ S䧭ͣöV/뎒C& @"&v:yfH-uTE^ý&A3$&o.L{4̽+Dx6Y\ ;;Q~Tp, E.ΰ㿺] Lc\M_~ܵS)Z8gX(IGAZ/Ej)0O{:`6%k6 YϸJuDJ"+.dWKvDϿYE!a;*CFx,jokM7:$~Æ[v5\. ʫڷd&;CMx!т,XZ0ͨU{Kׂ:Cnt%(ܠ"T5#̪ؓ;}K_4 _LfȽ \ƽ'a'(Ôrdc{9 QL t`ՕK "4UY=avz 9u]&Z3Yڳ,%`0[wZ*Ys*a^3jOi,ՊĠO:a}AR\kpREI7<͜a9Pfؓ"/V[  2Nڟ cTYx5$3X33>1]D}v}/Nnk=F}={:YgY~ePgcE膋##'KV?YytLۋLJ|D^g .M$gw#OڏV<{泑QI;e*&G'%.rbȿO:'.H~&1~ Ub(Xl.&Ŕ $pO]at6j_*:{Jw[mެJ_ɥ.U1E!e&?}pn@۳U sruWM.#ޥ(RԞi":wX8QK[LgVPiV}=DuN!+NCI)+Kp^rDҰs9@UaDG`[U-&v\>N 3WWS%Y!X-WŲӼ,E"\hH0Bª5hf>Yή\dA= wP5*=؈#oJ&CI^`6{(nga~ӛnY~PH`N92M6'6r_ks,WĻάш &P<4C&=JBR۳¦Ŀj% Av\fUVeAravicseMl .Q>5rJxRר*  %קr`5I fx17ٖ~Y)U%L߽`/"`o:/ֹϘZXZijd5ӝֻ?>(v>Zd~A5-qO"]Jʅ#[)R[LT+K_^tdl:?d|q>¦}iW:Կ6gRK3;+4F#%=oU\I$Mzhb􆎥|&ۺ_q).kX۲ίo\ȪDgA$h$*Dn`((-/0*kת,8c62wWnTdm)-/QC_@ЧZ첻3ii_IÈ#mGXlMm蕿C@?|fNOGO،k*ͤ rBlUuH"'eo'a/(MpJ&m}ZAq\+qH\zdhl@u< 91`>'=@zn[/R,gm&G?hPsV" ^pnd ]R8džI%q}`E%L Wċe f jF+)1lpb8 DzMz46bj׮LKGNoXSBF—sRCaVkĈ :e FpEL}:ѭf8iֶ]L]:KFov<,]/q{#[sm&yxIL,x@Rs3ZWUO`1l&,JYb޲\Iy @QrщS:. C_b1t$Ǟ X(m<P%ECR.Xwٶ YZ, ј ~D+2EPJ)&dI/ҋ2ĸp90@^MIPAQ}K}6,+*yzP8!^שr%Q o!I/w#КG;t+(y"mj]дdžbNEfИ)м"e#/"Ih/uJá]9F>;\JOmf/5ǵ9Z |c\քpc ÓkhSn)F]%v`JIИ`ksAR-U`*[OD4LX̝S'8a4&:F|*M?fɄD>h:rgb,~`d)rjnf]0 L{"e'cζ pdc.s,t@n|'`'E-^ 'e<:6dPiGV2j$=.炍Ņ]QVhBuXo@D=wAXug< ! 6Y;SXKM¶}b>wZ@N (^I|6QėdKL3rlѣ5k[̖ZGFcxVI(g3k"uJaFrI˹DՔ8dn:PdGrQ5 iM}_\%(FD|G.yB%و4v\@츿Z< V0vʽEp=YҗMd\o=ѭ{f:,۽^[~lRj)<W(ilШVsFc,5;CJ9\kA Fۡ4s(g.g8k3ch=EOPcIXuѸ16u4Ap 9]*8Ve,]#eWr fG6fhEJw % (ѕt MHcD¹sє7tЍ!GWmqo_h|LoTQKp̈*Iu\oaK8U'3ve9B8xʦ(\pcETUQBl5s 4jFnF)Hw$-_W).,c+7O@(ɹym)Oɷ'֙{sHPJI6ҹw;] ЕIgHX%7 u\; BC(]տa6H%]W{ S-~sgL;ENimՠs6Sp}Iuvdm|׎D,$B+G,?''u}3gV 4wPC hۆ+ɒ)gy]fP)(0/vjDЛpv>N(baEKQ1^o|Qe#l#8,7!]j0[]1/x/au/I83Q8\U3Rskaa>A*Ox+xeb;[CfٹZP; 9uZnD(&2}lC(}Lv$[f0+IJ5+)vk)RQiʣ)W+7g?=;rF֗2ä>.F9 RQxy!#i׊tWʑT0EPG#W -B { nLAsJJXӨHi sG%D ϯY67$TP6ZjqI?) cMSy$ǎEcW0Hk*?`+ i߉M.3:=#mf"dwB ˵;hppUOC@W­= f9Z1FA-V^GXl1keGchtQ/L>vRWPݰ |6eyI~56E0Z&XC+FIew[^ӨSMtGFTB~cmgfjN5y9nz5ЍZ&2ر)3nf*ž$l"ʮ769r~҅n=hō^rA%\o|uK"2 >;~oYit!~L3Em,rL|.~^pT[E-Xۯzg (Tbm) 5(QV&;^o ~OVD~WǤ$2SOv4i+87O ^"L>oBlu!hRj'[2\q. _#? A׃ P^l*qc|LlG pqT^,gD13^*5k|IU3GJ y0bD?*P*ӟj5265wFRmYF gɚ䁋r'9`$I uR YFg&\MsImAɘ$JPB.!Kl.sh@hK5Uݓ6=@N-B^f(t֩6'aE'Eo+AY_,!&zhH{Gq-tYy2条touG Ʋf)21!~P Xʼ!?X3MT|i^8mm6dÿ<yX#H$oBڅZ]GoT62 ?B6nNXUxDžhJy>.J.#etT(96.!j;-Qp qTt%gyGN8{}{`2FA_/)_V>CƄU5jeK\d4KigNs `,1 aEs>BۗA|gFd׳,je˭sB=_la*LX{+~E]^ |6\@v]yw`gSl]TU&8iާ HOR ( |Bk'8A:8Į<_b(oreF!3b =NG@CcVO^5TrƱ{H!3/ޟ8ڕt\fR %IT|kWB) 41I/(z,:6.D2Kv] H܈{1$+-jM&=8*dD"sy5I6 1 $)lӟ-ZFY< fފT:S[V1U8#ٷ@-6b8>E욆fwg$yn;݇E9tZzp %:,襭sǥf<\$=Jft;ڍ|Db:2zt,c|m^[7nw%NJ6muv1'19]oYdHmQ&#>ڄ#j+Z~jWE؍g }&=⶝tshcMSM_'j /`-J VZ#˖j@(;Z8%<Pg?jZ @SCHUPhY7z;+Ϲɦ/0 b"6k|?'׭EK'k  | .6ֆkԪ}x*8pBGrED[JzOUd6Rl)Kf/kB1,gr)E5Xev i3-I /KqW9:%WqX"iCdzCUsfgC^ةd]([ 1\O2x?C2-aA5yMQ5`pTSy)q$ ";tNW8/\7|V-Bĉۀ Fqnz ϶(Nxk6x]b9.@~ Kzu.!B\`J$F-'E5ɠ'4+(,/EtT08dp8bV׉\~*mxtӱ(Шg\FoWE\УʝUV?vn-LE3Ҋ.q?$^>4I]>hv#'s|H ^ufl74~:8I{HVjE5‚*5`P=LMQ#d)Lh_)HQ,o]b֙Ml/ؠI~5zF_a M?lt?VEr Z3XeZK  iH_,k^)FwdS 6}.Ze !Wz _^/WɌh0a?h7NU=i*K6:`=,>aw>2[+~%"\+?{4L:ʚie Y Q0ym62l_jHse59+X.:;5L߫' ׈h c%!e `UwL(1o"9IU섞dS~4.~ڠE($/ 4FI'rKIy^x ?7(Kbۻ܊%*AK'y Ӳѕ$G3J?ӑT+;Cq`3z{ԏVa 7 b1 nL&sϤ.I&<Jҧ 73Sţ:pʗpޤ5OFrRc_fw/J=x`|Iɴ V0hk߆IB׈t Bg#U̕_ǿ_2TE΢%fmŻ9ӷl4 t {S=qi·86Nc/-"5' ~-#OQ-N`7FLkSW(hCr cEƔC$4\S&Kb*,]u!1n-iVWa/}ţWx[+Ub!yP = 0 &Eu• 1ztt*uO|SJGÌ*ʒ߫MP' 8s'C_R| z ;<4FYr/š{._v} S vq`rΈǖZr{Zn; OT:AJR\z_U E(EW;i)bw}hu\kSQb{ RDعY; 0$ciTQj5!puO벰^~{t8uA?Ŭts$`"MXmh⯆.zC\(E*B@vLg ^o | (ʹ!hhtX$Ķӌt 7I\:bNq;//$_eë(]3W(p9Dk5#Å q/ި zg2sɀڈT/:R?xzvyg42Gh[EX]td,ckHj}1¸p&׌v[$ykFBE@))mdC/ζ -1TYeW=ґ@f|6u!.x*}-lR|F*xPBGkˆwc;), U2tsZ2q%`l(i/$ܦmZMxIȦ{vlA2"/'ANjnO)g[ y5)H+#UƘNP|Q^12$ob"OwԺp#:Wzc3@WUތx8 w~<9IZ>|UcB+ H#f/u=fJInMc (m_NԼNQ+Z`ACa[,$e{ჷn@[tGoEBfkXtEFDL\ vkZ+)js+>Nh80oﺒT7†}*fZ*=bL23 یb-y2;Z ^c e|eFv\k~1~I T>Z2GGI\bon=C:=Z e5k*Y=6PF([ Q-+O^΂Z"ΚNỽ WVۚЁ,4J`\W52'}Б<1Ftm+6 {:=ihD\A׽zrsF x9uu2.#)V[ #dd~ƕ{0TLEܥ-AeR6źLU$xvxb!ۚ!"NGB\ 8M@5Pp(Η`쥄ReXw;:4<q*X 9uUF3%>R .g 򣋇X5o\ZSp% '@^R/8O9> $gfo]!Hq{_?@CAŕ{X46vG'QX#7c3{1v}Or.2>cn(x$ji|*pQ(OjX)q6D&˰‘}ZUv{|=<Wv\Cx۰I7CEZdz- 47zxrRCjIS

y';Lj2yoh᪤ &rcCꅎJ<2aD@R%emeody)'`\Sq+_vq@!1#tˈP>u?{ KO𝵢{wŜKQ1QϨ_ԈgShkTDR42uȭHƸa1 kŇ[ yGpC:U98h $ ʐI*C}5YòrTA}Lz(7qڗtgķo/zk 5ȪO]UPug[X<0;8X@YYM/߉}ؚU{*܎Y^)یᴀ%rXa"Hy8o2c W̯pkIL/}Ȓ>WJ;p61Tс+uU^>s2Iy0 c;Jb?cXo,%o\+lxK`ĭr9yKUɰ58dk @FQ |%ԕ 2nV@z̓NjU"ZI;S¶O91fK-=Y6tkw{yjwL|ӎOx92tb0XNhT@nVLΠSMpNl<Tߺlx܏gDH-Ϟóآ3R9cծi֞Z?Qz9~" uT3. ?]%cMKHEoS6 hvxI k7~yo~&ۖG 3m梫ع'4Z5~dгKE ABv]&5|'gn܁䬛ExYO*ZTmðوjO+ݥQSo7] n.Yɓε:5z.^k]#IYPH!7K+ʄ7B3@i'ϱT`6ҷR.iox%r >3yE훖26 L6&EVk+8c2_>xHrq)&H!/aGFkMGW\u~j3`+Aډd>J$:6_n&a,D(0MMu:鄌T޲3‚H$5GZ7,{XN[>ЭF2'=KXˉo zre|fQKE#܋lۢA/2<-I8 B  X[d$=M{I!}6aP >Yߪ4KٸzK`czˏ,FM$4׸IխR*n" 0EآGܶ*VCr'"pCɏa9-.Gx ~}q{ٌ@WOe8،t\3pK_ d <ŃJKzg 7!ܹ"V ]]mij+sPuD f'HȬ~m\ nE)CW(HKEcY{@dȊ蕇$V `CVɯȰ +ufZ9kYϔZ:{cZw3K9bq|@"=${PqlD~,==4]{ʅ En?D*gK0l\&F+0oNYoXYSg#P#t+wNjNlwa% Ves@(FTVsؐiJۥ-RapP'A'3/^NVD!Q117NL}.~9o:h,U|^_axH5N/AT BV_v-p,<6hFQHRW Wf-9ᾦR_`;,Zc ~"9PV䇡_} B0Z~qhg]b_GL>C(lcW& iHL6no+OaXh)!UMC !\&U289T/?+X_PCiwy^p]ZQP֒9W2]i{ծ=}C+ӵRc`'|1lu'뵥#2hk%!?4\!]c`ii:kfS謔$7 YHbz#ۭlK#jrA8UZ&>ϰwhC&c[J BdXJ|55KOqgpvEtp%2F@FjN4x8e%N:覰y1ڲ)\=SBͤy ӔB,@cjUԯKˊXGuC{ \*~/ph/b'b_wVO7C9|E} MEX\6Džqե6́u֍l1b2a B&D'CM'=}A#~ pሲ_8-1!`Se2] 1U{D>$"}R&b=,G',ƙkJ!W'fuMh)ȏPW:9`Uˍ b|[ e AwLGm!AԕP}*6wb /vd.q]qJ-R.ag$_ D="'6fb %}/)L%J"9fpQBWb2(6 |Pn=x>r6%}% +v6'ޖ~0"r>wv2 jo*lV0^uNJVh2{uwY"1_9EV$@ 7׆ޏ-a fE/&y l24x[Z풢3ޓ_*rkBI&WAp@0D v%Vslq YAjähWwz_Ff qιEkA sN4,$O6r@J47 jHx߂Dh; XAB !%)ba|ʼ+)re1PbcQSq?E,tK $j@k{x+p-E͒+oL;KSanr`Rd_E@B 4{-6}5$L#f?"ytuÞ]r(KԶ|ԕu9?z b H{^ַl*'pq0k>!IW ua02;2ɠ,׬ena]UN|6B{7 vx3<0`CJ~}?}Y,aDKjw,V|-}52 py}VAyg8pTљҌ~mJūYجczn^塨a9) bZEIi)P]Ӄkose g=rh[Ѳ > u7icd-qbגXJS#u]YRyYpJ8gڐN_7=f_]u 4r)KM`GZy@'aUo4iLü FF&eqUi ~6Nbe!d9 T<=4dފb$N%p۽s! <(㣧 w"j8@*F௭uE†I!)P8mvI(Y7$Y/:fݮ- B@VRDfnB??$i1vv[}8+K0-pݻHjY>c:!c@/24I)qs' ,_]ϛ>N[&c-AiiWaiF%v# &\=7@႔bAjřd"pf^'ԡ̮ɫ\tw1P`DMj>=lzl/epDPP$6W.\>+sg^5#H[oLpX׹*{L7^ ܖ4KpteVh d 11gUv31b]a{wMp6+;TV sтhHl[t6gOfszdFΎE1s>g)'}_YQVo+܉| N3j0 uÌ33' _aL3}K.!+]!|ZR-熀8xy8ɯ*H.tO|5R^L諹3jXEM+\pmzR;0 _p@FmpC H:aa%.t~/d] ߰y%WO8dumWo6%Ƅeaെ/_:gsG>iEdS_h@2S[If* Dler>R&GHⳙ*eɑgEFї J*M!2IC u{.|$HbJ*:]^)fΚY=FTW4G]50b<ao>5(*L~x;A .^Cyuț[1]tD<;vuSE M1"I%"5^oFTL([wFv c\}r rEP*Հ%3CzF+/tzvx%\2v1djc]@_#'WfbkVgMR W!5uɽs|jr٧_u }5sɂ Ӏmyq%(ũnFBuoea((ބc 9zZn =3>U6dQ;G1Y v<-t~jj|xkwqY0{z9a[.MIJC~pt9$@iX/@i3%JS~6Gٸ0|_w}5+q2Ҳ70f !ULWPo_$Yl\/M&Qg EZqRz:;~(hW{R\By.}6T;m|QɨI1L'J '/HpO}^П6\6p-a>#֭:pJZ;*\H8۔CBA2&5~#S my;}%P΃uۊ%:bDUs9&s%WA`.ٞ(mE?E19~%"kX E6O[-Duyí/3a !u> \?:, GE02w395H*[U>,YO@?9ʤ;kG/@Ik=#Ɗ8RfbOԐ %}K糌a*kgk/%]DOѭӁd/vb#bbXһy0Yez)E-Eaoaϒvf:Kڞhma4TPq0FfBG[>8ʜ_Z[>b^U.ޮ\i*yʱ;c~3(=P1 v⠭ o&Sě.v5\& ]%V}/Ӽ㘺Uuӵ G #K+^"7-t!E]n6uYF >%YHxy0I%׌Ӯn.mQ==*O:>\ݮcfyhDkFo= >#`et@Ԡ/ ͻeq1FkIJI/qz9SS<*7}]'/)e27IF,zHYbY,QXg[&oc_&ۭ{X{'c%poST[ͯ KIpnJ$ ?SL{>Ԓb u-t|ڋd߈2Rw*2oǿ@9IqK5rrya= q,=)m lj=jҝPY0bqxLȀymTߔ A/H5u=N%4>Z&y)^eb!+Ho^T$) W9gHc 7q`D1wz8F`r ep±(ʿ*O4򷏎(53qbۭԺw+_/1vO4fq{n^ޫGU/ 0oӞAXmPv?jw4DiMVS gjكqW$aqL=zd2;k\rpcmP3]*ֳ|FcWڼ狋d*BX)Hɰ$vjV$RykҼO[Y{)@ߺd!k>,cUNP']b5x9v@tJ5L07= 壺ukLJy4pV"jPSI48`x 8Vl5=ꭕ Q7E3r-y9Hlzl$j!0&[=iik-3ڔBobM J)!l\z\>F,9L~)5܊.GLG,Y5%u6%e7$>K'8:oЩ4x%ejís8=JQHS:D2*8"N!+ )р/sWR`C7O5\QPBXt@ Y*Rz3 sE<)z-:F [}( Ȓ6=ܲ2c1Q`w>D2vOA0yIW/4%hכYjJhL@ 쀳=A3HeڛȕArvܥ5,2p (Tހew%C^Rʨ@6Zmq#3Ug8!I0&G}#j6Rt gBYl"GJ»(bZ^np˞ )-ZpX Nu7&Q:Ny;X Qt<"/m13yav{}.|t ^Jw ݜ.YC5C8BiWxycH.RRicX:{ q$P qzYOr1$2y=(l>:[ '`P %d߹C4BY3QS͸ -.1[C0j8ONr0^WqA'-unB$zM^rQI+v .#'LC^P@+6rPI[ra4&1a&[fM3|s"m>N`s`LRAڡCGj$$A`hbZ%3 yy+4v `egzn".5<pm7ɲB?thLaOAb;1CeR5AgQ']N/>EF8pvN\P-j],6:m>U4{W1?5{unZ4,=|2] N@e 7΢2곱yyOƊ] b> 8bb<D#HGއ|{qIW&$?֧>M"K5P׫SrT9=tJGPt.@σvQv8Hq)tMioz( :>FUz | O˰?;YxA!\?]gexqy@.t$k@dAۀqr\eT6;]N9dg_wU>},;U v]=d NNi^&% iϓRЈO*O /qe%JqDsW GTgau?8K ll ך$iϔT$`Rahp=c<zuPCd05B^7ulEy#qT<-U1e"yGkvkMO !m x4T% 9^reˆ VoYI%he)Gi#8:Ψi)wQVDKńb|?@ִeS~K!t~ k܄ :i+b1.Zbz?-H`V6kzk蔕Q|RyFikFCNOk˓w^a ־\A'Od?8*^&(PTdT+$N꓇R\9^UOMEl /&[~|vg_"Z: 2ӗ@ܣ+TĔ0Ȱe9y gUF ̰1`6 SH&2kLr9/J#a"К+1?+Dp!w|= Y]@6j5 uHXnp G?ӣЈD( m7Mjz{ͷCt6 p](1^ rE|DXqlduUћ I]aE2Huxj{Q ǙHd/ f5K^VwCL~hmŢkEi3͸4Ѕ,`p烅e/N0noAG}VFΚgϿa+؄bV~W{ZHBK"=$x+7̅18JlGɒVضg, _ 4|/ z`cpr P7"µ6 }?G{Z76/S@ D3|6}PGjlVP#Y*\6ogpyTʝr|bJh-/,ҼǂuG?#IX6 _.P᧢q^Q$|].ТHԱHXbnKi9\?:;c@W˛G(_<^+ ,)(v1Z֓SҤy8}Q%g;witlz/!g-"-_nkʑ=Ƅ%Ƒ܃GG34iM`of_cT)Ug[ߋeC`x4M$Z9\"NUŢ3ɲM])fzcRU?ʥs*{W\!pԷ+DrΊV]y$(aX_Xŭ:>^7_mwˌEv_bG p~?||d7#o3`$Rf4i? $a:d!Cl>%`!EB.= t  ?1̔p1ac ‰_>s.ۯv-V3/ڽ<[r\ 4z?gwFG ^-uTe-/^ ff!MsrE@h6hd]s'c=y 30z, ΛNLl t@\)Z2~prf@ow&j`OӃ+8T-Fin6bTO"ۖxLWĎW|Z'՗т7"--1ӊLuaj>2'W8LR}%gZ {ǛÁJ0KM0TEG\Ct6Th9?r6OJ#Iǃ$_Hʜ]3W<$6-kW f{K7[FkA'i;yl@P]u,<%z}N {2lw[< yzYGx%D`X(bdpۛ:0誉o1qOgiW$=O/MSI!d˚`3囇iz`r) OA r# JrQC>Wxuͫhq̛*=#%B{ػ}"tt!!<5%Rՙ*dmݱlda8}-1;PRB8ڜ"@V!h*{Φ5}E7;v"F*&(M{(JKDF@1 <4l@1wJQ? H?Gw!6!|rEUc қ9S{#$JAwgga[. J. .^QzHpG&˄y~6sbs4hxk7J9?hj7<[cЗ9OD1T7p ؘ&tAWhHt#ͫ|yHe_Y _#8gTTߤ?|r؈f1N/ "6g[\%>m=TRw40|r[NqC&<)f`za0Lԟ鿿ˌHwɇWGP4/_~9${ pJt)aha=S=>Bо5O!Fa0TT(AN7Å#_5w@t{!1bjV߶r" ΕI9e|@ ҰT{⛖P n6$i *zvR #M6-YD(S!#(LzXUH<+L-X24dTE 5tB& ꖟ }H[J}1)^d{<; .8QYezGeGH܃S$ܹVǦm$(T\$>1~*ZzD+)g8 W88cw[e(fvy_S ^ZXYt?NWTiC4Ҫӛ"޵U{ŽpÄTKV%%T`o!խzPenfO$H|=EM({w.ՉK}|339X(1*$2x;zbBQPܯp9t3/M盋hJI: !n^wjCTkzZH+YZPM*vC:aX(2ƫreT&5L[\j2.VjM:94%bUqaOa/ Ň[F>UiyouI'oq0ZkY"3ɡbւ˰:˜ 8 9ԐK n~0@^#KVnrze~mCe7C*RKӦ9]NwbrYW!p+u;lsyw"]B(?X׀? lGfոN'1e&Ą*ΈNAXp 5_az-uUUQMS%X5}Rm]oVXȱOmO،6?cS]NSu t\~+y-vNICg#'";3FzkiQ~0Fw?@p A>g^MJ'ggA!2Rѕ+ݚ}cPvNd©~ ;ki|&P'U~Kp>^BlؘUR};4_uv4gr@|:9ߍ©qxC4ZQ\M`G ]dG1-S 2ET`1}NazT{0,}&rUGI_%^q(L%acCe7ƎO^-? t"wj~pf(x+ȔaD?-uA*]DKmlf+_/##nUE@z$H1Y;(c:#z6_5<>QC͟O\ځZJ U1M0 $k<0$[Z{Km,Lf]c)P9: 0ܞ8'[ae%4AX/0rVvat;7wY$ZK\`5 bߛ4'ʔF3:G7˙g.S1b|3KǍh[[<ݻ`xJy\"Vj\!/t:6ܷy\2vb mW.07yOVE`? N/v")!`E-=^ 04*G*9|-::xƳekh526h[QKb40xg2HW,1.)9! ND?TcstSV|w\y3*tkW`+]R}&M)Ѧf.ez}9f4C gyk`veBT1r'#3jFA(f7VU;VT{o*A8ZلLՊAK->\fTqZ"Ql(?mJ.lJFS؜? ɲ;ZQN\TX ٸVkC*6bDVro *^%gcO|ɋtbQaʹZ~ǽށ<NvpQh험%SE &w~r %S(Y=k/ղz1fm ă+Yw*1uמ45Vx9f~7) m߆gjk^ȸe7S>Ӆ?6֜^a}Wk'{C5&ê'Nzj`H`O^a!y~Gy; C,m5`?JQ)Zi϶ѸAl `d: JrLD`O)N%]IFMH졝H!1boVsHX8{1~3.b|Dcy7;lTHF!ʖF!:pV]ӌf?J|H6G=0Eq^U c3!sxґ mPx;oliOaL~˺/[5ן \So[%|79fMei 8%2Yk#UVcIfSڳZ?><:xm5Gtt;EBԺ}QN~w4\&~_$!PB2LJ>)1+OPuJ) D=4ɴu ߶ m;=5 uS[1os _wDzr: Ċ&R?rS _ԩXpa<S 2/C iWqrjQk$?m}U9X:ES5(Sce#4{ v9|rD0m%@|H6(3^,Z8ՍDi@wzW;^=XJAE*gig2Ӥ#`,c`<"GΨwy?.E,Ҫ,JMk7H*"Ɣ^բ+Jټe+ڃcsOzQ&("?AV[ f`lj.ϠnIOYSl{Zk1c-Ҡ!o<$U1Hd+f8o:>!/+z{di\U@[?AU4Y0N0eAM=rLw;$7r3ʧ8|EȬ2L,G6x_1Ev}/X(_%@j/;.əTt}M(|l՛>+` 0uØV)Ҹo,X*#ȋSZq4& d&+*̙֖(E Jiwrpj VJvQ7]f$I6E+V{$9Y0X1@hv0np1sOE(õ{t_,0տ$Ռ-_Q:K5!S<]"_ Pش9 z ŽoPwd_ "]/e ~WUC pU`_-X9sK|4 qÞA 2s%O34*Z.ތeƐCR P/*"m03XC0 LbQ#?B_U%_ugo"qbr½N#!8!r㩀Ko"`aqOΛc7!00rUAܞ5]${,W,JbX3!nmk /if6,7C˴KB#]E鮒~eHE9Trͻ96qT ַT-"*oUF>XndR!0I{l P@%]֏:/yϮ Ic2.NٹV*yetE ø7;GY0ʯmWUǹag©F~y_G??Vy0 *'R?VW|~903lJ)5„.Ju}IVx.}\stK#CX+ZtǫVj1_ioI)FJb̗n_qɬFW6׎s#FWM.t9qk~(bTC۩Mm#e$$˥O>@\ĔWhMiDnk{] l5FQVGro+^F{f 8fmgqd ݨM: N|q2Mf2 k%+P-yb 20qͭm4.`9;DJiqiY=LX),߅{zyR.Ea?L(]:"Q&PӍxz1KxgRKz?4} (*ݟ"0Rwx%sͿ%9QAPܿ#23~|ɯ7Zh)sF,yύ6+/WKi =YF5gNfy9]ҷf9boqy9j[>?pѾsop:f!_96JZ2*\Zq(l58>z{PIvҳpy^08pMCY =s>/zL쳤?–̨x ;^=OێBs9z0 G9.Ȇ$&!kH61Ky~@i&uҭݶ- ,ܻR/x׌Ep-P1>v6G ]vjrWŜ#@"p!p;({7!spucfͼQ5EEM|H<j8een)Ag {V!.w+׈ e ZY7ó57%7 2z}0y}I%}z ArxQGt?l Yt\&Dkȭt* UdtL.muGujO} Im!QM`kBLtT/X %OX@qj:5THw0 %>}> ƆQ{2 PDWyκÔmڕB*nl$X&Sj2ަh^h q%M눍?C1/qBu(>B])*kD2ɶ+vq/&pAڽy,zcwMPL7vyFH4-ě[m,WrG}KջtjXۨSY%B^딞8(˚mtd8>-£a}q(hÔ^'x (ZZN %[tL},]k;{ i3=zc&[vFs%`ǵ5HCӌQSCnKU˜{U_Ni,P> 1Z% |4K[ER" C3S"y_},(K&?Dgvx6[Õ 3p紒MW_4ˊ )q^>pě x`r<[7 gyIKZVxΏKpsP$&qª~3P*ѡOqɭr \+1C>՚SMb ;(>+ĺM{֑)BCj?HxKP妕b_3yĢf5czdm[m=ϒSw8~Y&v4g^EiNUO4~h#pՂҹO; Tb[+&\T{kgV68Sl[q$:Xj *|a$-n&c)熽hb|p:@9V23qzI!IV,܄?{ȷ? #IR)ǻ~aZm[w|5 qVX^tgUiGq,S윆N 2㯊{((v}ړΉ<Y;]qSv- Vu7ioB!K/Ƅ`mpL5bV'WE )%9zFuāx&'DU;{h :MYK!a8 O,T-/>/HpQ[$D%\3&,vf>KdWc17ռ` d %(3J~f+瑅yji},{(nqR",_k$&Ye/Su>=g_UYmd0SM<,Ic{'uϧz$[X3$^څevE,qbBR!RzqR !X4ls =N8mat|ZAg0ק&D޳+"q:u[{HMmDLgMpH C{F2t-?nQjnP$@Փiؓ':40bursM3ߧYrelň(\BulL`pkӁ4 .CgjF^t(ڱ:N;=&y;zI)=CCi"]) dEjN_453 Z# 0J/^~$bPxe%:}),/nl5H@h ;bG4%j8k{7rt9}_UBXMCd}n~u|Q![._r󳋗T6E).?1 CI326pӱ8bu5'=(P)6n24F>S{xD:qhg<΢9"PX*\YxKERJiZ6u|$pO7`sSCluzLf9_YceAua;Im KȜN:]IQw@NR O!pg tT0XHÀap+) Oلw Vw2sLng;U<7:pʌĭVv5x0;$Zj1xPojt<{)@aA2{niu&IWh:g>N, N9( % | EP8tDy2|kW;L.*BU9C-![ŠCab>wJDS=F(5>^`бV)}hU+_tVBgKI9h-i#il^4~S1{=0.h ( zH;7gHQl!9ciˉ/ZJ4 TȔa:MѮI+Ҫ mmĢY~jBlv_<\4Y%E!@t"[~ړC:\*]Ʒsܐ4_?4ThudEAY+hR\ɹ+5lq4dVS@w,p@=|- IhWL_/s|ܤ$Ś]I|,4a(Uy-2PĹk$ s^4gqeIy\հU\Z*Cfe?v!R3lƖ'gHgI\ә-J,]D9Vˢ`ׇ_i/~1DC= Ÿ3/h{ ^0Gpd+PT<@|g@A+"):$ ,o"d>qBkbEF P)EQm"Ȟb w x+Em2lj4'c`'lo!{ud̐.9h7P*uy1ȃwtJ**[5pyVmGrr:Cf_o/1[OS CV7 ;q(Ҍ,YUIŗјΔ&93-!H+`t򼧤~I Ys- G=1 è;ŗ#3:`%kr򓁥ӶBBp<߿feCjnU*p9L?b3Qw>вe4lFmX KDxFY*RR t^=g&qQ-,nt8U䈍ZGζ *spl,@mرزo3]6m ۇ)`⵫-oj6ٱ. ID)Q9T-*NVORVX fVLμ1хԫOh2Ti车A+$:B$!OE4K$TڸR|$~dg F8&&Nc7v骄rdnDANVJoA`<ȃ WaB7P=i FMf+ 6mϐh`\HKCg1HDWf, X9 rHz bnjAH&!zJ1};*A&$B=Ǝ#*H͌Sg]a#T0,Zg- `*̑[/{!zw"?kg3P㝌dX n 1/W @n59KXWhpy ; ]ޅ굩R0(;V])1/)STM۬~"2Hh:|3]@X}cg00`pE`\X]?_-Hhbׁ7n"* D`dqBmh@Wl8l9h ]V,gM7?bh  .X1ϧqHw׆ ahE|o]@cQ"[11U&r] >9˃a} ?IQikO@~ Tq&i*ek׋qf"~+(eqxMy1{yAnG1="@S'Lbg ".zҟsS-y6ۈK]kOѽC`ʧtHLcP]R\YӨ.&׿FDu_U O+יTI8yLX*"_}QeDh~zldkBRq.5`Wl\ќf\` -D+YʀFTLbJ]n"0LguyXT $ 䬣Ro?R7wѤRiXNв=XibY x8ԽQV[督6~o aPȏ.1_9u~gܹZ%66UcX;A+C. `V?$w{әVs%_L%H︁^? IQG ʿנpPGn̫O8Ud%FWh]2F.EnR9vLy:ÀyjTfAp4DJǥ!olY=ni9Α^'^rcJۚM?9K,xk۪= 2Wһ t(Bָi71xo-Ba1N|rWƑ ~OF@6TϦ.éY51l b$!a|(7 V 욁&F~>j_OV߼zWr(jp BiF,8QҌR)9ި FE:5TtGdK'+"Zq&~1aQ̡:!;,5)=YG$!6?:]5paCjFlE:AW[#Ӭ[үF1wv߹h|_mxt޵* 5Qqnɂ$E~ᮯr}CƄl<U"\c5"k >iz fPeH/&#<OP?ֳ,&em}d @vjl,+zNnCb EM%kpO0v)!|$㊒YUhfA("J-3N?r׬gێ+'{YL2%tU5LYľo͘bv@ZțdA$tt( ŠӧBg6J)r3b5N ԅO]FߢSv[BE'::Ѡ-|X)3LΈN9{<2uWz%Ut>uܴ^P`^AU X}vqr3Z}!;]-CԔZΗsgcW=NANα􇰞_d}V)H",#H/>y XWO1=s9ѬW==.*ۏᘏ j[kB sH`7Zq ʏ);!?HG3#]arg O&>7`c|%:&$©lmr ~%ϛjfIMF_wal?2.EJdbi{ICc?;&m(Okx5{w|9e(vJCQ)n =B2{ Wu;~TY :HLz+>7TɻYWyY.pΫ- bۃ 8gF3HRcʖ~5 !7"_˯Uu9IP(DZi d \RZl罎),4 !*aˈfTT >%| _Du[8]d +rUVP݈;6?stbJOaA3v۩(oqyN˚A~;["DE jzDN3#KV &3-NXᖵigͫ1a6?$yb8 v+[N27.R >f7,99:=FQ>7~CR 逑%C<5sZ?3iឈ 7m(xﶧ_ B 5QpVBD/6Y羕sE`$RnHu=azPeYCqs3fP<:õУKvJ]!щpLKvZZ Hn"V440ce0%y%=K"ͥ5 ??SWw<~~ @r;8U8oHo;(Y1k,A\ P'>iAp{E/:ܴ"4 6+^beb+k$FKcpZ7e,M7lrAby[ly퇑 1Wذg}BdJtx38c2\] :Lba_>ߡL@e~XW)g!P{Sd|kؖO`n*Ñ/un8(|K|ki!Fs~סXCZz~U[ {\YϾˊR1"sqkH]xkj_ ܥy(Ӣ֚~K=StŽGYۑy@ hLJbnarП[.t[}kdN QkXXWyqH4AbiPPí Ç#Ç]-s~(F8TT ~e\S:W?V"k[cI{9 g|bߕDZ?T{=>{c8 |v%/Q6tOj[ Nݛ;c=mwOfneܻ A^׃ա]\< P`t Txg`__ NBws6͓JQQA ВL9ޜ }x}tynBv˗;sq= -OɭBv ~a`zmt1Po W) t֓ 6"s漲-!CZV?TF~wȞ{|'̳e>.1B7)7%lSb2Җ.rYZS!D?cI_jC5٤/}z>ޔb ԫRA{ӜSN&`s[U Mz9tȃa^ Ɉ̾fqGUy )JOh?`72k _yM oBC*\m:CUNJ'6<_2󟝺 {FԴO\gL=,liĂ3&DVsc ;AOz-cWcSr*ǔf~ %m;>Nm;JL5Bjka;{k4s& $[Am :Wwf(refz-6nƌo˽7lJU=]Ӗ~#Ps7Rav8@dhw*!vO! :pa|nfŞo#\@5S8nU-[E?/bOS։|ZSxI"H/̡f`vφQŪ:.1Ⱳc2N~#ͯ(C7Qκ~5#  Cld)S,, $گGXzsq"A| }g݆튌ύPëS!2^5`Nz[d);h@-s <kДa5+Ќg ,`Vi7OjlsSY/v?̈9iYx|^+Q;<&o+AV a2z9BZL]hך VnƘOQ:/%oQpA@+|q/Cir #@LСW m6v q8=9r:,@ 04ˈ 'lՃ1qZ9ix1Sف_| pGxKYc  H쏏)Di> p#ӷRN>23+&-M]lt\U( ɱcf2aL: ![Eޝ/@]lg+١kAX|""rLڊƚ-mB$nA_T\rk$ubKis@}kVU|mL&,݆ĄmΡ[/c 雴.-?Y0'ycBN fk QN5tBC4Bc%C&Ciz nm|K2OA-5gUN OӝQ2xt(BZՎ4hjrac-%Bd[g5KO,lX'vJ6iJxf7-b uϯh޸8=4ćT1*9lAtナyhqtQN"՝R{$^b{usYlXj -i>N9ԬG(,'4dtJ `RDZ/'tI֝5C|Hdbٷ_uMnB<8uz^e$w{_d%`lhEhı7ƛFfnc>ʭw\R㋺Ů77c.5jJ[˰ daDI# xKk{ʟ36Hp$U7p|FZ:23OfY4(ƫ1 .2G,uH{߆NTORGun"gf61}Ч9UYenl61'$-JGCpgZ2f +lTMZ(l*d 1&ާVgP36&KW? ؞,~7ʥاV* EF=yzWޭLLT_EP<[ٖ~Xb/73o$S Ip8BjwEzGOEXzM1H)2>|[Ϋ:P\6blQ2"S HhC`I\p?w˺#N ]Jr9͕D146P ms`N?_"(nТ~?&J (ZЬYwl\"wFe밤b J t<ם) 'v)D@lIlfGKc'݅9Q&4)a&SF+Xi>̺C؁fcxQmX*nĈ/> 9Η/]mu,z sKd öKn< ^yN|[%EKx4,#氡KhTS_Ϗ-phq"뀠F?h]sxFřh{_$4S=U6FX  =Gi s_1b7>(,>Py`RUAT]cOŏy,̷~o6BXE8י/? w8Ygnl;#BOwWNKm{ՇCsjŜ >jll\BZ?lw Ea/;K}HkŪke_Sݔ9O ˟K\Qv'8LBXI ج`i8\\#1I*ֆټ_QIDp:u\a^ل(A 5/q̒RMaR)נSҋ!4rrr99ӦÕc\}wzA Mفcw xcF!mu(ZQ^'rBjL s>zuZ\Gp {TTJ@l]%\ƃMuPx _ #ӂ?G @b5kby ^e8%3$-ݨG9*SrЀү[͹ {}ʴ3ȗKI^LΏ6;1plC0ZpT׾rje7mlU"ߜ,S{)=Hy" *2 &+8ߋ2iϭl8w<ᪧl:D'dWbsۉ|N-& b7Dh cc9G6Jc+sƘejˬ{kKUuy[hv'WkHj"'X@"Cn?&t^j)Y;!]7Nt|P;d9>1źbmVLny8[R> z|,ӿGrxPcs+_hz@B з0S DQ%"N/ AYQ)A_oC%n'BR-eM}}8;^W2l=YG KF]|=|VVZT?p!OgiԳ>OWwSdzW̚&",R\dP|_^"6 4'o)ѫoGS񔏠e&BޱFQJnx&\r:(G]9B5P(H$KG(ܓ5 1jX 4 bTkEmCV,$vJz;YY:%r72r++BDE Bο.~:萻N5 ZN>*th"68,XjJS>`1\"e7^v!8 -&&CYCغWqUy/] @>PB3зq.wq1ÕOL@F[QwW|fiNpxl0+[jn# bMFz~1o! X; I蕨Iΰy\s@J|0 ќhs$>dѶ2 K+JU4ֽ^0Oljv* Ϻ"eWm^zwz-(.)E![Iw\$x?}2@n\EF(UNz6t]!.nF%6=IvY=$Y ʰќ#x&hrIYbY߳e!DD]fKyϞ]A-'&0{Q2m.cAX|BGm\gZaVQר)]39V'Ku!l-mO=!IQLpqa~{7޿[ԭbνم=&rC-ޒIVeuuBr;;mB9ؐli'V|$;"*1tqk`u 7g{51eUÊ&)lMgyWOC"1V;ǷF%K-SdpXvpns- +zY$lE]3=}v,C !l,jU#j 8e'K<8i:<T> ;ס(},1Bj]ecm&/ɤbYbUi'ΘD%ДPqSEz2QDZ!iTA^Dɸ]|]8 &@}U^w_M<^4ȟ>[ yRgݎ+rb|Kdzs,<aHJ>:F_E,49ˋv1:6C#SuUCqPA+ ;4b,XwɖX0BR6k y;h#N3\]7Hkݼ.6KwG`sBWl I@kcąf;8PM/{uRiKկ z/#NI66XF%bRΗ84nn82nu$EZcCnR '1u(B#ɔ+L:bMſ NnҔU:}տK0w?Ik:QCڗU25\G;ahut>&>숴S#+Ijϕ X,#/vQDo?N3wŦH#p:(hG}Rfj{(ʿԯ ȿjd`@肭̫@XeJm"͌9Z%ذ\}nXGqIm0\A֕`;+NzΤe9ľ iX Gq˥X^>G=Z%T^// ';0BRI63 Qav-W}s*~Eܾz%{T86b.w_= "^5qI '20bz#n=sȾ*I&?ky vh9qh.cmϋbC%b_P/qe2 et$x{FC-leж9D9ܽ2}bdAhBSU|:'2-e wV,\LYYD)s|(@cK-ft@ B鲒QjJ'}83;ᗘ ܑ ʎԔ`~]y7Tou^ǚ̹ WbpaR\>U1RV?5OVa;dp¬ʈMTݪHwusy .|Uvą{PP)2NБl-ojufƿ_S n'\n;&hP@O-ŕtC~EO㢧Hx_{c:`qYZ T5Uȧ'ƟoSoW3?n$`Rg(DBGis$pm:B|2ەa\OJGM2hw.Yʇ\EoӌHj ?NT\]/pQx7D0Zn+!u L085unsmZuOoh?ǢԠ^𢎙>r9hmnlRpU])=|Q=~r<U+rS]};QtkJ};d:D 1ұԷDy"Ζ iݠu\v1$@tghW1Q4İݐu 2X4\AH)ARD%GX F[ug7mm,x-=k*%V ݮy##Dq"l8R&+It YX sM'g C6+wP: t( .Kwe +f*'[]m%uI&VNdeQ6 Bn9,xM\+&BiIP7:Vw#O^*:F!暳,)nsE)(+I9]XVU~;QUޝ׈6''/@Ϝ)+[=nOuG 3FtND"CZًM)x9oѡ{7%z+uɐ֛_g-\Y~,$W+5`Ra:ͣE379$]e kXf,8Oee)#(^6 3r+F=qqcVƩO}g,"숮S÷Vj 2]";NVp3M /sJgy,r(!dO2D݊7vY_UfHj|On33.SłC,TY>*rEF9GO$ɌduP؍ޕa1ZY_i-)AI%T|o ZxÏ.-wJmhx~7=cj"0̱ДD[q*J# JMhG(@ v'I̻_r>}'lcύή-ȈF 龭 ϼ騡:U=!0vaoʶro`٧iBS;_fh[a5[hҥ,BRΝ9`'r\.JS!@cVtjPkberJ>ĠX+UkAJ5UA >y!xϫv9Z1!|> h[ο~ljC0bY ͧo02A/?ҟRf-dl>y`87ުWgkVa*G/`…pDm0x)@ekp! v,N( 4`K>7IS=&MOb\.2"֧=H&2;[(x=8(.0'K>p+O߮fHrU+r'tQkĭi$2#c%-#S?IZ} >b0 nA?+ghrV" ~W9 ^*KNE6]Ǥ9=p%AUpEs57/ђvi6`' 2i}Ӣ>F2%l! MR;Efg~|!ޡחAz'ZDц:o*" cv(al~xH]פpڙ #((!.PE6tRFnd+A0v 3eXs$Q;̫;AqS#.H@J흠״/By\S (i]<;+h$s1j5P3rz:D$L70m+0MΖ+Qy?ՙ&]rs-Vqo*:2a`"V} Գ%AG{:D"22@e/.} `a 6%@u?AƝΓ6UĀlD p y/gI>DlbWjtn!H*U&~ )_LYxp%i6}ьFғ}~~VHzleަr 2?TZ< GA#C+ahH8&T)j"F^3 TIkfl}PE a{\F'j2l{cE,磱Y1a]{Y* Ïpm(? zJRCnY  Hoƾ|LP/ ^̥l˥˱FH1(X*DpT$A!Ut+R ʕr~øKPߦ A2fKKZk@b Ypx߉HIҴ 2`.vj\EvdDCr]YC~ܽ+ţ|4h-QuIlEf ièל,Q:rGlB V :67(=_3qqvHeCjvvE`rPר@$8̘ICX[ *DV :FXH}̈# yL{!w^8!V6 r4`Ъ̡Bn9qa Cq]}=WS곚T~U_$nlm/[Ըq$IY!@/8|~N=WJB?X(8EN<朋_фOwƖ ɣjJ|xɚini%62y=)'U)^&"0o=})(n4n_~ʱ*qBobut֠kmqHv}R>,]Obv_pe@'>u7 3kyg(e%bOMoki Az7xqX' qD[gm/[~25H}LH}mM݃r SiOQ\ &[R;aJd FjӠ¥3N!ɠ͵kЪeCmZ%}>\Fڴ˷1]9nbli`H6 6 L J$]7'mMu9hLRdVCj28&K$?r:X5;|Ueg5ݙiĖ3 \6](Pk[5T|@Z*;g!T94}ESs2ͬwN@zo;\d/ꃉ^H|Ͻ5Ȋ RR'Ep.#h*|SHYö[svE \hUXGL=7gX)H`*(ѥXfߤ J]s!Yj0V8kv*w:rEXUi^Dt*0"Ѥj:ʝ`:O{F+"=6%*Q!)3f8Qv>aڂ lȵ4cL/-:U䚼dn`3\`z7ī6B/J'v.J?j`ˡx抻qPRTSCJ{<%Aw?x=Z{BTT~IjZ۔w:t`i#IWpGoF -\qh%R$Y++29E6A"Nm{ptԳ``ҁ)C'$r&8f*V::Oo>QK]aVhA4JR߻S~ءK**dM&S ek)Q3I ,gA ȳ ft$e#i;Φ$|~ݷ8Qt%]5G ~3cUdp[씞`l D| =,%#a)HaEc u0 21P_O~hs~c2`BLanȠφX1F 1`U+L>Xwd{~qo~ Dke:<`!y-0Q 1S0.jkWf{>^AK0~kңlٓKxυ^s.DksIkRL9b:^nWvof39YqM<8ֱ~*v3Fqh=g| -.1\Ij ;= *Zi:+/킒W1?rUU2F_"]V olzʆ ^*tbX9s3k|) Ixw@BZ'`7]asOMsk袋% =>Lڹq\n>U&=BYy3\HܔV(7p,@ls" W3v[XKw$*\AX9lx-l9 DQ7kkS! 7ޖilBRE$TR[wRuSC^JʔY1n\4غRShwb\y:OJKnO/!PlpE}ʿv< W~2g)OamcνM%CpJŸNPzי8ߘ-:992t-);ѨU*\ OI]T FJ'!Ft%)+𷹓`EC n2))%9QWB,x{ @*x71_ zwfV_ >yV駚1$ 5[ťbb'F/N;mi?q9Ǝku5/;WĤUYGje(siCr?-O(H#F9 {M:jyB]Q}w-תE7xI߶)?tMt'Ea*ˍ&+s^YpemAsy*z4s P/NN $MuyLw*,R-ll{:SQ_oR(T㡆Rgf lf~)嘊VNln=VƩ Iv ϠV'6ћ ! w . g:<1Lj] F/T}~QW"4r :(.6)'_U 5Ldm1dql#=`)&{OT=&s :rnԓ\٧>֦W!)}:ե5ʔtn$Sˀ}򹛋I\B P\Srs,4lQ4Dq+](Ԉgp2IǛ5ʺx q1_,I+m@.:f͒,۾\z ҅ d\52\qHd |x'& |2$lj-k qaz_FbRz}Yw6ĢS=׺ۼ//!kWg`(֪4&DH6G Ŷ4{A3PB]2$(]L-H_Dv9z|>sV,Ecv:m:SE]< H{&+ΡSBw=U8U<+ H:`|;.Lv @څқX)>ڕ pu4_DYU]4yvY 򺺻0gCAd F ʓl^C %yi͂.qNAt>aQK5/`C|'Іl] mo)% nMLADJ#QpIp_/M/~?mƢk{+%'V#$`fgN/q>=q&TnrW:v/ح*orD![Bt!*B֞g6;{5gFe&ޡMZY Y;*J̗Ѕݏ_"CN:KՓi-^Z`mtTl/ Gp}gFmiϖbiLqel6eϨǛ j Ĺ&"["^pڛ/i~ti\أ/% Z`Kq\ݿ2އT^oCMS7ףvO usNŠ Տ^ZeqVpND %qL2ޤzHgB ƊWܢ ;IʻkVr#H\p^ 8T~坬 kƨzyCL߮ hlWl'cOMd ЩȦ3VPe* `v*1F=f&Gof5!FKr_#w>DwsA8v?6)όgZq#elI+(j[@P  3#> dŦNALށ|W0zlY'B7cD+ٌ#ъRCAI@ٖmQ^c wF;RIyqR2 \>,x~M43۔.H%ɈYxp᪻N^!Ɖ4l*x/ZŃHkGu7꩝:8Z_FෂVB@יCTf0h3SzvݯƝxnBN8gҊػJ+FAyN }V8T0L=0}\} QyU,# < K$41SsINUvV"z&h[ ?7^A+AO62ژ\P;[UuifBL'.Hemhq[^C_)dF1;B r\KGL;zY13V~$޿2܈6E2-oŢ^IYLw`mf,YOI FjG@p6 BqOgw6~={ސYA?rlqjCܿ%PK!3FKJ_|Z9QgS\R mf":].ߵ ==eL>]9[J!#gЉgj_%\2Hɇ]`&?LW}IB[m)}$Pdv$ǯaxp;Dt%ír鼢%/אjQgJPP){܍J_"Em ,9۽4[q{.nړXc~ )[<1 {q#̾<~ q[ IgzD Rƾ JA55H.p ~4!f GYH(ϱ0κ?Ӹ~\ZFEcAe/^мWCA= xkny /%Vs^MK]AE$G%H:jz;Яn9?tL(6} ҇m_F7W;3խFa07bxvk1ŧLޫj9E #BMyx Fש?^Y86`/}45(6KҼI`/qEOc0S&?䕗T87=Qp- ⑎K$cDFd*; $Pk3_&j_d Vv)w ZUITT@uFdEgfOC+;*%:8LGzUvtϖeVzو'Z0HǙ{;.nQ`ӕJ@"% 3vIi!aA4{T+%*N|AS¿Qê} q@K)c˟ۃZX&6pl ]@W'CzW,0=]i4S{H5hyaOHӝ{W;oX ="Q7YrC_'0C_Pus,>'=2(N;3sd[h8/y}*)!RB<+ ̱r98M}_@.1&>/{8oGi? A* y,(e0 D0-WZ&{8dr%bjS#*B娥>+Gc@m_ZOu-<0t.̈n_@X= {]a­0{GNt\!Y}⠅х/֍dmW❵[גּUa bL%ғ$W]"Qn[o nT*_c?ofC<9*)I8Ӣ̙S ,T;PDkAS]9#.pß{|fs)Tⵕ@cZLeKbcYu9HɞGˁH\YE>}\-[ r&q\S%2|$ ?C9cgv?)ތ_< Ny?f>  "-KiT!~cR! X榹w8i,cnA i5} mdP*Z4u$rDYF.$ :Gwb;A Z^LV;S{0Cjv+g>C~w3SHs93G#FM Lb M|gK~xY1laCA0>?jHе7"'4K## Үb"ӻM~ĿaH*~a 㸊&scD^r:wV,] luŧ:fiO?^b uAk; ;U}+ T tc/0 #a`~ՒF|ƶ!&0lw2fڋ0Z4L6Xo .ӎu|@Y-"BF@?Len1g@ʝi ?HX&z馛k?|vlɣ) ^iEIQ܆zT.\H+r1߄wK!u lx3-#wԈL l= 3 J ;퍧:g.?+Y_tKhIĒ)-R~dXapFIkz,Zq兰PjB{X$wwQ3WpU0_ "I%MٰGz}nF!W7#Kc6gNjY"3|TgN|hKM%/=fǙ$D ),qer?_t̡oGȴMڕk]"q&ffp d免{-:}*jכ NC?|yΫG3~Gy̚5ΑAÕsz] Ѡi*(^au-EиT ˏfoئц<F€אdz值S8 ڹyeq*p2YOgp7:TcBi7CUX5<2Dr \I\߅":\ƻ~b@E9zj䅳'c%0`0PMͪJ[ZIװfedG_#^:k~\B䤭/ZݍEhJi|/~&grcI׎GlhF? ӟъ Jׂ` {Ӝĸہm&-8i(wd@Mjw9ҩ^ BChCwT9צ ss]XF:0>j՛TaYcSzdpqxA͋I%ݽ߫Whvfr࿸B5xp߫u|mvI.Rxeay:N\ߗsWr  Sܾ,c1K(jo݉mM SrG"^-B.HSPݨ&>#4{ecZ(bìX=u$ qRRKMeWq)HWmڠQeAwh@{[y-a7\#"s |+wgi2r)^ΰJ1 $ pk@դQt7 >ݤvB[z06YKiPKLe%xҳ"֚])&~魢@!dg2)sxyDGJk M?,gWe ^ t}t.ˢo*i(< ZSS\Q`;+ FŊ`Lxڠߢgضt.a]Zw+܅/l-TM]:^$6 Yx{;k[i("Re#QI/l ĐIQT=CPI`jڷ8HTFH"ܡ2oO]ZqA5W2!ghDIzk"r= z3EŸ,i+@bK%<@;J1&>>JUu}YlE.OV!֤}!o"'#fgzR|$8{J$Oc,8EO ƣ}0Z9У43f?\'m}J&?6TL 4xj++`b`еU\ N:+ޔA<ӄO#jJ=ip_US(|*kͪA@K 7y/sU-<}]Va\Aq d1kU63ru9.Vp`J#0vG%p˚ y)s 7Yx`tʴݓw@E|GauങΣ9פHVӤcTg"F~o𬤘C}Mw$0pܟBj`oq' LG*$BB:7zo@]ԦZ[,wI[gSg錝O1&&_Xkpd 8 PGMڍ%k}4@3WN(C1`zymtUrõKJpv &FIM>8q gqUG&kNf g}ᓱ{4̊բ$j( G<~v%9x+u+r C!| Jg} Db8:[KMCiJi>^bH1sN/1Ude)Y0Eɝ ['=׮Wd'3Ԅ)NE*ו]]5`W2W a<;vQFYQ0P'Jn[os@z[0tUy; WHUɔ&5r4qe1w\ʍQJ 8L9xC᫮ Kxb6uY<6(Pyk=^4xŭ9@vŠ8U)J(\Sܾܟ;(mFc/3?Q0/D5[.+>xJ=vW=㦛{a3gw`@$I]xGIzSawZr'#CJ6隙ܪ^>,=\ ٱ2f3EN=ҀODz#O_pN&; W /2b20rB`S,i{ۨ6joES&_~,/oΒWv s]~ֱ~OdBEILJZլYQQbiN4ꊯ,h%̩hyp6$A-p;tܗM$qŔN&3A1a|0gSVB%*CzDLedGZdDcNAZJ?~k$;/#5JUt!#!Wh'2ZD jd ;DjYlx.- <69p ^]ez+ޠ'=y{`)MS0Of-`]r*b:[<wuIADv!@lYT:9G/lN4 AK/Npt}2wpWWj]z;mmI*󖖢l@"6də5svuFY`8_rOHcYԔj=֫lF=x؅?!1Sw&u4t^xvTSA @xw}u$v9~Guy~y~7-M^2Dyv;10/8Ski0 52S%Xcj[^FN>LBoW"GZ_vgȟ>:z:hGiJZdSw n,!$ uZe1NGC%$Pav:SyZ} rxΙv%2s0sLq?QLtFY"qz,IU|HKD)VI%ylG¦RMF^/}.9>Ռ{iY5XhTTj!dP >djO 鼎/qIIo}FDwAoVè%cM`xȥ.qUM|x ^|n*VIg*8޲ËaFN}6%hQ cYzYtnIWEz!4B}R|{FmM&F@pEżF,ʐ@F؟@ T <ʑa|ov%l+jSˀb%yIC-邿9oXݭϠS'Y8ɹTxIArYқRC=S;oX]'mB(-V޾a@:=uQz~C3ث!,/O8>X,x߶xu0{.24*Bkn~lyʍk_2Ѽ^S(G㱆*p'rSWcf<R21'KĨM#H^Z^Xa$d}<"ty{`wܙ'fM'gj,*#x)N8XPNb |Dɞٲ1'gZoEPƀh)Z+ZH<_1LJ@ χ3xnN<ūchi:I g8XdU%&*DhG=?\Eƹ S'6m^9*V%/b?K= BiN]n6 v{LY*Uc_sr7!$k}p;U:6M%$.H*3I[TA7c}Ǘ)R}MRm5$tޕ3oED**A M~1LR)K#jD&郼^> e;$UKx NkF>l!.s"tMl4v +9HX}^HOZ crt3~+.9`esEUʺs:?9 4Kwio a5љRm6\lڮ$ܳöimm':4IŞ])BHT+/nL6 m$Y웽|*ҳɼwA;SU3 vN >-oCL bSտ{ 4nКmѵPǂwH3XUE^=D C`L3[9d ٸ힥))[W=j43|J \&BdI!rXnԒKZ"m.cүXA?c0iI`MS"{B::PN,g>^W rlx9싞?+57&-7OT^( pZ[?T}@;go0]X:O1Wt2'L&6?aո%8`úgB[aM|cO~NDz9f#nFҲYW{fHuMZO ?qy+g7K0T&ݺv՚8]yeaB;v 46;ۊu_MYe=Fn9;A؏>hLDIem]p9#ƾ\sY[fpDTobD~U6;FKi=]qu͟|T0١3+ǖ(x U{7:Nyg҄'y\].rU"Sf&!w\: Lu%lSVqą_85'$i7C{֟7!=NkSS['}2vx4=7q'-JG tݑ}}B0ݑVnB][vZz!%&0ņp2hq AÁ[j=Jf~[)\g=aZqGI]!49u&` NCn>JoF Ա+2-? [R"'24_TS??24A.>Q;9FFx7w`JvP竕3J/b?I j93xn316da-9"!St3o~ Wx Pt`20W9 ʳe:m)_M;IaI ɿaݛxۡE1KՆNv>݌_|?;MU`26%` bm35="">݊ &8:xt1_QODO25m*C'yO(:bi/>q]3F׏FBX)2@|,#ݦ GM@&YU iSw6Z&D ` Z sEEs^)ERWL ɪLJ dQeu*7/s^X# X,":"qAӶ|4pD |z5oL0ί/is@W†~"`%厥:K;W<52`m('v@%GzXho_c`/|ѸfUj^Nޢ Tu^Zz6*sC6%Ɉý.Ƭ2tL)0]Y"DbD'35kaތnA% 0u)Ht+4j# 'fi|~(0d9f@+Vʸ*2kXA mKVMhws!RH='eT&<:hxj=9G{![7cXECjC {\f8 3r5>pĪ6}v<Ҳԁ%qj!Tr3z%~5ߥ@(X6H#*S(03>@nB+Qè1>K^QkMCgڂ|d%H eX g\M1t2l6t 4ډ#ʭ}=;qUiZa-=LHRRX@wBJd ĂNh14kJd6/DuaHp3X?[ A 4#$q1])fOkw|0٤fq{*4CGZSVxDț$ے?Ѳ}a3RϾ [Y"=U8wi>G _`2Qw!Ra=G,7 LJ|l2gVҬ%@8R022v8WCs7y^ 8_Of_v[b&p)Z:nc;iĥn8T)f u Xk*1'/܏ĖLl&~lkRLի ?GSkR%MQnyZP, Jr߰p5QrҐxʘÌ5Houx<{,/צ|/t dp66E2]\w6ы-IJVP؎9^u6amC2Ĺk']ZC끑dBx _}2ec(3sLxpVηɣW+'ǛxPb73xae@2*o6e]85,Qq$v#Α'!bbCwbwSJM鮴9 Ւq9j]DrUo`Tk?JWװٍtKGt0p]nYހB(B#jm3CڍpYOH2 WYi囊ULF[|60qm]|a4rz6'Mp ^]f۟Nc][("¢uwض3Ay4)@wUwL=rd'[E&gm>OJ֪)SIٞ1[(‹RxVZqvsIL{yzhK(C|[{c*; =8xP}3Qwmr]Ono'b,Ҵw2%]&pFu8}\ f~w,s"QP<5$>ǿ?w5>[_&=x|eDCq6T'f )@A2Ho!b< YfHz 8w!s=O xس M9+|!byYfˈ].ZbskC)yCo]P]Hs\9iI'W,PT{Kٹ.cȚ 8V_uAPS.:NU,!H{NR(xl6u# ji:f=E@=l+i[<J=֣IL:Ա"(Oɨ]4(0VS Cv=tֻX(wID^qY\g]YkgvlF@hFAFe >WUXO+̒O/.x cp @WPCg\O5V[ꭱТfdax{&7Jݩv*Y!S4-w/$P7l俌c^wFN5ch%j,5C@gmG]qۺ@Ո v J’Y6Y+6{ǨWz=|e#OW@s^8&y]O 1۠5ẃ" ai)^=TlRE 8n\գy 袪[xM{Ⱥ^wvZ{[D xfu_pB.¿ ?*L<38T;wn)1B co; g/L)69zu˳TOxc; p?|SƅRB$摣E;.Bt%:O TAq zqĊ63椚y`#@Π'e]eܗ$}N}m>j޼_%<AnEs1v*-z=aCe/%:zv?DTu $fAo78[E0pDF O.I b8?icՊq`ƮY u' ,@D4*9{(t c: zjJr_HpGd BS|8`-MĻZpt 7 ES(ǝ ͵8*lB85Ӂ7"񉎬D#ZiQAmK+s&%7{rAZֱ!ݢ0n Zs;Iq1pqqN|=̵FK6G+\RsX Q\ Տ`@@}~A_@o-X ;0ǭWzΐH:}y+ '`+6ب{= A92<s+X= $%CiI,3ΆKhLYRv$9%ˆ.3=N;$H)[ |ӚnEM<\="e; JHT ړ:ɓVD/t<oN13_\YEg?dhdrmCYqA0.CِxX^$~ V0͆Qdrჩbkok<of9a/7oCZkq "Noc#\zGNe8mO^YH- N8Kg s6a Oi}\P} 3)a]+)~9&Zһh9raˣu!8vU9l _n#N !T9+iҰE1#˽NY+۹xÂ"w$Mh1HhR&96E0;UO|8ʇJ \]\5` [l:U-C d8YRnܐI[1x!ߊZdJxbpx8-G)R޴_dO 0~OD̵*?Uh;ZS~ =f"íjSBLCg9ÝK2bI@''IMӕBHIL->of#j7WtT"K|~nix (\˷0 Ԉ TA.{5* g 4ˌY᫴'e|<CE(DD/-Pʖt*b:Y 櫘rnlʬ{l"-OwrԺLcNX#Z!D."%C%8&WSFۦ (G>؈3F,RjH fy01ͱ?!i!Dv?^a<8q&F#fF P-(q?o<H[S(‰: 9!~ךּz<{kzL22,?q]ҴUY$*5aXZdM5Q)T:]]6)(XtEajlxqdEi*s}Wg|)_=%g"JV mQB1]UVF{,F3Ag8>Oq!(큂tqTP'Y̆ą=<<67p+!ez`0]|wS{&N!U[qJ| h$z"5pchd256zI!'zKNf'ceuIx.o ್׵@`/dg!-n:qj L-=vfaq.eu 7+!OQWXJp'cNLkmD!J*9pHJH߄vYlwJҥEP._+YPG7n ˉ Eyۛ_c:{ex^(] -•FU&aVLiaw6 xڌAi٬h'oUti?@W"E@ۤ3Hԩ" dQ)Y-Cb1 z;T#RdvU'MpILRŹĶ*YIÉauX\ďw|Ξ/cG/+ 8Y|?du}GҎ0brAA_8LR=8ӏVKM 5yL7Xii?ײɓIG_Ȱj◝)ͧHa+lњd]L4Zz+d4iCXMކo.< M'e1Xe.r&|p: ܣ"0alL7%W6ѬvlT wwz$knP$yҳRkò`k=]_2Ź3{gnAs؝گChn3SSt&PFvjpf:LuDVty(.~xT#:fp49Usbp4 3\Ԫ=L*en+a @L߀딟@lfrqfwnd22g`OC͒]11_F1"fmT EXMTsf&"->9 ]=sѵTa:ݞ+vID]7q`os(@&p`ٽ#{rS)b>g 0bcpύz 5sq׬]R )Ƿ"X?%:.Ialj(eТc GfDYCGa7۹c]+RHFtҍ4ȶ>VpR-ـ|=RQFdDUUu TlC8!y&U\'d?xyv"?OޱTI<(*UN]g7F 4XӱؗTsB4\ˍ7_eRdK^a]˨Ylo ԣXds>l!c7nZ= 2lۄS-/Z1*+,~fᢋ0Ntbm`y0Lm'l L8wqpoAV \옲cnlXGD*rb¾62XqEL-koW7Jb\ϺHx;P1ȝ!A:|K~< H'꥾"ɕkD.{>)w@xu LkBQz.<&3&VY:J}4Rwx#b 4?oTqfy; }N&+HȃR vMCǒJ +2.&O<֧Q&6^ƱHx O2 &LjMl'deRu!ˆ"ޢ{9âbq&eh[Ǩo~z4+W Y(:^KdժM'ZBR3\p4uvc`jh'%ޚ Dz]1W@IʃC6/>RZ3v1 #$K$vYH(SG%,:\lRrU@fYd;Q6|(GHS<Ȉ݋D횧^?*u'ZOqg,1J`ΈFڸv݋kа\qnZۖ=K]4~8J.fR|-!$l˿HRڴ3)([gnt_ rOfSmrhH5b x7f?! 97:@Qe(9{]}{55x5F:ihz{N8YʼU5wuD6sq&RX ;M;HG@÷d+;9vPE3' 05]QrD, i%=Lg9G~(뀑;{H(SFYOdʹJwa1K1t$~NA[ 3 O+]3oJc]wj&ڞӽ.L 4qb"R{-*Qk M| O)I~jNxczFK=c_58ln27!Y_զPe'\^B)>k^,Zk{$d.{S &aٲk4{Utzf4v -mufXL~ L`4g4D[24ZÍ4* +6ORw8Qx"ctL^"r# 󓲓q9&omGfXyC~D&&߾]M.vi *c~Ea]a:iph8ZTg71O̒bX{ l}x0wZU|c3p]iGm97TEWЉ|3$і  UJ"0- [К<$Ŭۀѫ բ tJE"rU6/w)ͺYeZfɝ.Ã55_ltuHYrV#TgȌfEvx쨢%P+tf.b4aLy[`k;@ڝlzf׃ yZDS!ii,*JWBR+`܁`t7Y.f&]z$^.:])Ef^yɾm׿̽ixyO&ϸ/Zj_UzjͅR6MX]5s@ۄ.o+o sTOثʨӾs.PxIРdZWG|R'a)Mrh6xD<am]O7ShɴAA-к]14g!M$_19\7H&_ō$GTj KfI|(0t/~" ,g$ϚrFhK ]E$ dDZё![["~A(˖^+h}a3ɫ >T73 oW~_m`OL6|t2DՅޠPOCZ 9Ρ.J"ϧhaV a&Zwt6[y`1ԍ/QUg_tAmմysԨ/$TG2M`9B4&tCQ-}o[  s6flR'W#H2ᖶ Mf͔z&ed^Z0C 1FfK53o ܭE1]yCthLyU3ۢ.0l8&1ԯY;@0!ŞBPϷfu!,yijFJWzMS| K_E6pn|dfRy<=(V*/&vflgy60 v{Id7cPpp&i?_&;o"@Rwy}oA^s)B瀇be1Q2S3Ҧ?sB+6=#B nVNHNdh@{}iXXA)滴YE?jG.q$2e >H$9tFZk&oٯ^ʬp&;%{KK=b^ 8 sNmec8c\ΦCq嗙ё l0sx?sK!CN'e+ΏQ Ԣ Ub11L^.f%$sLs Mq)a92Qj_e]DPS 'OF?̧q[hɧT6,XM2Px͛RL$tVF8A!׮u|n!"si~ fBrpʥC4۱aaWL?LNS&E.:uR{ja>qP@{ky](dc, 5LG|#EY?~BwbGFBB{A/hfj (z.-Sgѥ2ʄavePQRtnz7WB&݂Ƣ9>(`Be*%**iB1kc@a!RY𕐗M`=u#S~:|Z/6zJLfU8M"`Ia|Y^%`ajOb$V~KvBe0,>m(PJ#+CV⾚`q옱L 炘`3i5uƗ=W=O0aۡd͈}{}FCMO(ݴЖja."ҸW:ߠSƵ9gQouELC^q߭ycg"aYp9ĭ4fgr5Ϸm2 D#3CiC:~{eXm8LzskǀF`GԌLHMQz!;f;_upi;(Z$kz?'XqZ(dkNƏoJȞ4$I,aG&/ɩ0+5C0IQ䱇<{3G) ̋c(Z)PY7-J|[=_@ C4쉺qet1:l(+ԯ,_V1HrYZ q0/<c2 \́8{8EiȓыiY6ItRp+و( )C;\,@ b@TW3Y.ӗ#^p/4uTc m>S:08NCj~fH-'w*]rߚ5TN#PQ'3`(vjFrgM3-BJKщѝz3Q Pw2,c}ij m[e|s)_&f',! ¡{Ci <|YXW]R_b4)w|u,ЀQ꒓ N.ДAq\O U"I ?Q j("_)3 ~%ӊ&ےjwK ,?7:{*(/Kt g8;0\"?+^Ҟ'/2҇~D̙qå49Y5QA¿AD+oh "ھvCx>o 8N=dGds-oϼ r-믏*]{ RU!ÎI}㏨^y,ocx0H; \K""sY^16OXC+B+\@Ǿ~)yTc\?,@+C]j Ĉh9*%g43ڗ R+S%QgKM-|/ɵfFv렂n楠dv cY Y@CSXlVUb% uU3xUw2pQ_E,=)64DZf9{8d&^]N.ֆE9yv/%Jb,j bm%E5xiL^@0y S,.-|ÿjPKv0/0BFa%HVhz?Rը}F<+i4/ bR,7@XIC A2~d-L^aW>j/)_AO5B+F EgM#`h+P"{>@Z'h/vzATCUʶPc [8Ur.$(XU@+f@kUD?UkqÄ%ӓK~;Stp p":YX :&v-R+5w,`bO5n}^_cT \tG\'vu ivj ;it8bLK@Fz)$ND>=@Xz+=&To5O{+0O'$EݲFtf6G+5ZwشLZ8*rCr%Ywc^1߶)`,QM % Fu5r^`soO!b "?$s>҆݄JO%)bؿ^ϖ0&}Pڽ|"K}C^U\mΛdFYSkcͷĊ5|F6%{UwQzGIa@HP9&b />t{`u5;KTS5gT}|\{ע,F kDע{kZԶnO{8T6`ۤ!UdDŕՑTޮ;L=B4M).É·-L{4詤{PȊ0SǛԦSF KjIjQdp5NsGnz};mup&ZG݈Ɨ6 FqOߒ?Tqs1)t[="FR5Y'YrZQPm#O9D2ße~ɲ"Y:#ɐO5lk"WK(ce>ȱJU-!u1ٍj(|z0}rK3Em Q=>ψ 'De)(\4@e݀+-MHf jḧ?{^Q u$ u+ݺ6-9`B3\H9ZP×vF/棊/%n"&UH$aBˆeexD,2Cg?fA-bcC.:^wԪLIG'V9䡰-_feZHCT9G| X2&PTg{ GooBpZ@ \0Zpah䋤.Em7u9ITb͵fC,TMNz7x"vvq&1&_l^ C"V қe}$o6=Cb9t~"R`CZ\pDE*,i0>mPf6I`5Eh:0sj3hWXWp./;LN:!#G/+xHt@H.U,7w|]}#>9]= ?Z\Luo] )6pF7 %}2/p2?7n0Pq1q>ʯ 3(3".Z~ici %}׷8$ 3jnt&D[drR @(rY]4Y$ͳ4YڏXDFBUah`Z=IOvJ"d(:-]oXl۞ MUwNGՎ'?;-1ZtA 1n4y]YW+WZ䩡p?TZS?#$[/Q|X(P<3U $X7E,B!mf#],K8 zfZDD}-"ۻ{urM-qk=f 08#M91JE>'(ՋO60e1HW)> S2Q.GH*wDB(-W}]@& uu3[z 瞨g:B~ZE3xR!̾JdXV0?g9hYɠ =v?ZayK#$i3Om[8=^+nwJ~d-eEbW Z|C -{hд_P-SןħU/t~I'G OeO{z:ݏWi Ͻ\V Vz~Ό񣖑Mf" F*s‰z9PѠ(״J?1U OAEK,0i'*7h#&(ʆU,} e8EWd5 MI!^,i>F,JN%#z>-_jqIVh^ww',n8O/i?b@$>!//iqsFMŒ{`\K Ǚ86#|iY hzg"Q7!N.c-|ȘV DB/d6 BNeR-[b!yvH~ş[y\jj% aM |ĔZ*njsĞa,KZ \@~V>Q_"[[IXGg=d;il]C c܅\ )ל ϾMZɏ2wIL~Y@}q"k#hm${i582ʮ b,@C$ ia[(>S'(\h:20e%aUte6BJ-.y"*+j\  06RV3<>1o&rLcs\1XjqFdP!Obbb[*Q-v3Y ':Ntl ҘT }k$7H2ηLdl %q/^> ƃF@"nϝ@9(]׌I2,B)b%AWS'N ZP\nz6s4"NĬx28X?&&I}d}ؽwsR=&h5WMhإ-H .wt/;x5+aM4lml 2pt_7Y;/,j2t?$b0&f `esV!O `Re+R?22 ,sנ)a#!p.VXm{%h,"0 ފ^9[j!"XYRfM橱@W2^UAX3K$iQu O07ʾu߾Q((\hJ&X0')K#VG~%$FLsMC/X_oOGzvgۿQ3}cTv[ZbʍGÅ{&qB흴\I~ `2%>}6b/EOf JZF%Y[_\G]N$FdMwiPQ9{y),C-'s{P1r%S?X t-޴o$ڂ92@[/YJp?/qS_p'w(Ui"Svd\Z(uE!V d͖GJC>B=ڪ WQN>}S cʤfIȇ|k[4N`!}]֮>Pa7._>4CFJAɽ<0%"j5^/02(k# QΉeT}آٜZk6%sY,D`nEWDd?!9GЃ `8!#AXwkǝʉz5Y+mEZCoG)ȜID;yP}wpu8U YArtRFḎEvcג9t+=iLwFK16GĜ ̪[>׬汪t@¿If6`˥8=r)#".NC^=qq_leVX~sJMJm>vkn#Xq6SacID"*AУ|=WB "oL1 n.֣&2,H"s5s4V ]KÂ2\3yDn,r(۽0e8CZ% x Z{S5r6wf ݯ0w/|CJOjKtr8>FҠ3q TOP@qR>]JCX PZ]-v̋=j{Z0 Vr(2G1Z:Cy.w52v*N_VrٞUTZ4,'=hFiD%h.< /'|X^ЧzO`E>@*m50fф:ψF ,!hb4sjD }8.|(D¼V0PEfcvf H[؉Epjwn7V_0+}>[_ob,y^ښ5]AJ&ABb~}!VqiXLoY/] c~OOs}g3XoU\|PCج{Ȍ.A fQǶRe5xTOzMqIQ$KExϊ,6w_֞5 VZW!9PL3Hf9iaEzUDBC|ZH<^]3F#>~f2B4L$;ٓPZxn5W׍IV1 A,')o i0fYdSf;[غ4W1wʉ҄_9d[oGGsj? 85TE0iC4.N)뽯wp@m|2N{\Yv:QG ĤvZVlD|`jha\4ӁJvu30Ldmib{D̊.NJ?SbXYvDY)mpK[sّS&h}_㓏9 =P AΰžW3 ML5J.ubIʽ_>εX&! Jl,7 #^,S G"_셅GդƢX~>+hՉsl> tEN.)*1[5y'n,o YޒY~O1^i8t^ՁC]^U_i:%O] mgj_j 8E?y#eFѧyL*=} ?G.o户s0d ٗbC18rZW3NZ9D!N_g#*+:&E@ED+YcTCT~ Kz[[_O@5's'Е2)^@6JqP^@|SQ|3]o)beS |,V}3gP=Cq:}tֿ+`H?* BYa{⢢03Be\ bh,]f_t % lܺh4c>+:HӴ1LZB:ڦ~ VfL{e)#?{~| cKP5,>b"-$rEAš5M^p7~K?`  I_ȨK{)"XQ5FeDR@̟2dM_7ߢ\z 9~iYf:~މ!W -"wKqU*(\>!i?x=ϵH\;Jvx:NP_{N$RV_1p/R^d7,oʝJc[jxF]O9Ede+Oy {t@?Hҧl"*/;tߣr5]gF uFu8lId'Vs߀>bĥJ8ÛHV9H&8wr9/$DYP1 T)w82lDH%\wṠxCI֝#Fpe]Gw41Zp1ٸ #4#D=UD3]2vTܚnl]תNC iG D>й M{TٕV+ӤUq(iX9I_o魩+'3jGɚ@F182:Yy?ʲ6+Hr*_?S]EXPG|&+tO ]n ܔ?izQ j^}0(ˆOYJ4OeH(`瞑__p_ǿ;dbAO#R_Τ (|<Tk룝j%dw>S"bwJ{=(SA.5/:pn}g|׀4swՀKiY^э_keF;:QϧPRE_#|H?#ftk mzɡ]ǼOaX$h pepx`F1&ƀ,1|>GG r~"g+]W*zgc{^f.$g:rpth k2HO[gؖ:Tt!p&LRrhʩzIC4 H9gd<8w:+x5 ҍ#jnI" 6=m޴Wյ͠1JW/0F/qLI:$@x /%8c߅5 *J1t\WT5V2(PDNRWV(x6^WӀ `jM듞dxPee4b@6W^V_0+ |N̰]  JNsgb1,ѸRBavCH2Jo;cEOw:"uď?:5=Wq)>|n);C͈ օ*]آ3¨̈9G7C q@zn$4f| ׇ]rpYtǑII 6V4r Eʐy\IŨa*,,y0qRnU2Q͢6 w'6;#g^cߨg./!)/1c} [쥵u\ Xj|.6fKC%G~hUz۷;Tzd\ٟ7ejS!5V+xS[:1K,E%E^pEL&`wjMA Q[oDfC7n=S^y~M66ת ;MϽvYDBXHB&!_bW7\6x'\E/EuVP;!QpTV[{-tG"pl_m%Q+ 9B!a.9$v ӄx%  حAഢb}Wv&>\FIi#,R`S2FF1gCȐo[RDF9b><5Xl?Rsv_<Ÿ"zZ)H\o5ʪ!V=iw\ $4.6ybD`P0ٍ^2qu"{ |_hac^GV :S<\xdf&]zfH݄í+R3^znx'{ `7ɬo GiºWxviEalP@n x F=2ނyIsp"1FRX<L8,or.CsvJ }9&KRR- 7 g œ$ՓR=RDN O…bvˤ P5l/]1D3eQVwhi+SS#`5Ŭ-ǦЈd/U(2: su&^:"*&.(}^PKN ]K:8F&͉@IӶ%1NvtF4}CSD\j#E65.d TM!ʁ1:CCYfO6#Pش.1wD8WhQFg ߆w jz颏oo+(x)u^<^9ٕl Z%Mf"^/'( })²7 ̈/י}g2р˓O1e;묷4˜b&,5H:)zKyӜ{EZa[NAQ!t>vȄh`H}/"m '9Ɯ\I":Gihź^0a*H~E=QfC݆3sgA><Joa@@BDMc7MUrnf?JA^5@|05AEmt@r|.[{|)^6y*91*N5n؛K󃬎\Z[dD3=RTpEfa(x{v;.d x'+Q`frY djStq3.)#H-)iGO"Ӣ铯caS eEIn򢭙/0T\9DҟS׹{9%W6 GR2W.`]岝2JDTm]pSjΔحF^`\fbF5\$!#.  0 2ڈyq21 ъo!/sW_ N6Km\}HpŰhRUuU7,NgH^Yn~10:~Tb34阴e[PQ|!g2ܽJHvZ\G%({}¦"fϢ` R8sKBc4~hiZַZK-HU)l;C mɷA-2$]yjt.$žKU!?{şfhi{4/d9|`C5#)1 6jU]%] R@/яpǮQ!<_؏Q>ص\B!DA|tCٌ [žD仱t).@ŋ"gRrFyP`_?>"n%b',|-}߂Eӻ{g& @tJu< c$ݲJ. X$cC$;ɳ`qմܙF漏TLΡ42,֩SډX.r8:@PC!K7jӠTT}a>XN&A{B4\eԙ^b'phe&]>3Є&x=*'"*΋ۙHc~JgtnF%ߞ:ϼ'D;jˉ N pNo-跙ѷ4eq %N8R9( M<&2ߍbGfd!1aHwPBjx̳R S^ҭҚm4VcI90oaM *On|  |Gք e"\Fᾲ&Wr -*U D]ig'b\_ՓXWj*Ga#ytq'>h7U^H;Px:LIU2Jql(y}.{>0GI  ^^#fЏ5 UxF}Y=i/lM+:^8# Q({^5: cdk@opA>=y))w5&,Ytj >eݕՔ kXtn'xmtb# ~35^2mF%*F hKfɓr =S7+s25#21XG7fQ =n%zC?=fmb/k)F=̬SY84y!-) `z9_#*`}bj 2"PuE .{$;+M4c u\\Lm$ݑ}VE&Cݑj_4 o~r#vr(@!r8'/p6uё vJYytmZ4q53WG9n4ӗnxFZ %P)*} 3"cwm \ '>G|H!l)ɜ`yc2?g wN2 RT ߙWi"5[Xl([k] L$>X~/ORM,sWFX.olW&3 Eu^y\d ĢYmחzN>k^j\&ޜ!bc2,0Iр([cTu/dzOS-Qe1qF%Q&QGCnGuTFeب.zꋈ (艿!̺3 B9xe{ၦhj&ĺ$~ݯy 6'f^D'aCe.:م'$@D.t|uw#vn?j[бIQXT)w*+;MZ.B@&F*%%= ka>=fk@Jl;Y'xO ذw?ӌuo%Zψ~e*K4m` +ɬ6ݙf'zt6lFh?QeO1rzma^zwNuī1. UQ}=?(Nj!df[5UHivP-scpjvm߻jgNrN"PmxfcR(fGd?c|}z)\#y':UWy]FB R-HU_O= .@ųLJ铛ņMw;m'#CxW6m1l&`%Z0]F 븼 Oc%$zEVJP0{FDY ֕w?CW\'3{$#XrlP顋ϖbIi4 Ktdwe n-w'D&siQF:-9WآS"5rۿ]r_KW5+V<`ҿΝ MmaM5U@FEstD{@}WprCSs|Jҿs%㡲WF#_PS3x:UBo+Ũzlkf̧/^y2)GSׅKȥ𖜜HPwR9UX:./(hIt4;o2A,<ώpxɂ%PNHVȲa3-,̄M%3iKq>\ib9L :9@{Z]0x1X?K̩*$(R FCU*z_ 0F ̲뤊rLzbi&R|g Z[="*MsfS\Jd wz>Rkd7eo)Jo$Xw˺c~BL{jS:X 7:-WcZ텨)ĥe铴w0˽<)QdÈI!Y $[;/v(ӎŜ*xuT +6D [_8 OxΧtJ䦤#lЮT2TT2*Ji1fܭnU=?1!U:ZƄbp((#p}TΎ;w6Ua^U()O@Y ,Ik } +*I/_w*Ѫ*ś v%QՅ5- 7Pۦծ%vY}sVTET -Ke[`6@w8`nG>yϙuLypHbk~mh$V{HӥH;Ou i@ضEqGffI C2rDc7O†P:2 IՌir; F팳0(Y> ᎜1E?5jDbvMty1zȲe1YeIҎ-g\%;m1f`xy3c~憨fw=PͰP~:[FJU+|)ώ)RJ>N)|32?()Af!dx!vs5V PVr4|6#z!1V"!@#6ߪ~rUk, MxeϽ҄ƕi.8UҖvq(G~ʷ6X.L+ / ̵Y7 +Zna]pZ #Oe ]~HP5M8ri -Q`\jkP ;IqؙX3CbI7uj8`H4jp#fkx2oNhZp%;;l$_˰t+z&爢c Sl<'{DFxnċS-~)hW;͸*LFiۓ]SM\AD+RxWsή\yF褧@iVvc(Kf8_ G vr]CM 78(X٭0&P-U=.6pA}'5:14N&mF+҄3 Q`2KVteu]%a*o1v'i;$-SwcJEUTQ$t0Fis;`̒׳LD^b.2Ezh+ /&};K-БTnY+2g71(~(0= D!CL E4 _ -~kxˈd֙0wع ܼh޳)x!W{ >iq@{iBP%Ͱ|oJcB乇"Ɇ[х[|H-u QGHņ뎘,C5%dlsc)#^CBz FNE:C|!|ޕZy~潃7Z3fEmbU0;X4 ybbKF"?GӊK5)ݞ;0x7ڠC=TRf>RUY$ig\[>8L F5l< B_Lla?GwN9ҁA-mT>룕)`U0D QoMD P^lوIyLiv$Cឞ-A0ׂݙpkyƄJT$0ؖזekJ^NG8oSLs,ճ@2 i+'"ejA1Xw5:LbkFa wͦK72;LPt^g^VQ7ҦwT3FxԠ/\%p A"$胃R2"LLpd_aOdS9"H)Q婶Nד9Q0>Q6Y=:o#]Et-q_jt7JZy &xW%sͭjxݓڂVy_V E0)!:Tyc"e dЫ=,Gݑb{ I!˔JVJ=r7SYai'J'`0>U@p긨3MFx~Hw[,Y>ɖH>Oڂ`T`j j뗷Չ޿A3Hc=+չI`b}ˬů;بy{/W3B{.Ej@þDQIZ!"vLcMDgb ru~BcpfˎlO *ALUZGwzjOy@ }u&9>ԁ?It{3쓐rZڮJX2vBnyq.,nI3x=Uya(ur&xL`֭k} ΆT c?Cwƒ|e5?W4;nJbIar uD2>V `d H4XLZ\VS qs.HW~;]V;@~ψ;0?El(ǫ6;CtR7K̃ƲpC4Ψ1>@X; od ~g"LmO:L<1͗9Nr7?6l$N9ڭ}^ܝY>^KU1[# !і)BIL 7̨nq_?ţyJό򄑱?@r,9gWX@FlR͚/8 sO++QEʑghAݯYI6$WB/ ;F~=wGIkOp;K6)3euuHU:36 %4iRz\>4Yx5=^),-禘)1-mpA(ʃ>]%! #w]@afSmչWp7N "$ ʒGÿsDQvyVњXLIfchF`W?=R#6g,73u[  L]ӼNrsKCsih@QI4鹪fUWHpf G1ro$)8lXvp> D> \^'M8.J{~(pT!OzVX>eF^.{,ǝ4J/ȗ+H1Yk)Aө@æ6}%2`˧̓|B:75,ZtF.ZמD7К`Xvz1MKɰ0< TWO$iHv)HW3ya|,Hy@˂]Wq*m׊F69 #&z8;wNq-r#rn Z(*7%`C@@(HfR)t=^ahkD+)}JEc<n߽ DzL`:)İhθ箖<&ZZЊ@"E f#Zw ǀ{a @I la܅ow)''78h(3M}ws1 iQ4mt}Rj;Fn N?9s'##ZgT[,MʝP* "=Tf/*[& F0e*U2f24?*3bT+\X j-(|_c o fzAed1 vLRY^4m;]W=,,4}#{OąW*Y.g~1>< |dBS%xѓcUX>AERo"0\pZ Hֵ\ p[v&bG?Dkd8.Y|VXuFI<=z<_ڄeV*cxoʋ},ԪQUȋ \P4+wMq MϺ&~(}:>eFhʡpPw>:"^ƺ꩘z*)C֞ U#h^&"P`gWG`STԦ+3W{ЍұJz}b2t_,8@̾y0͝I}2xa!BGs JDQtM4Eł:ă#x뽆C,lil>dsδʘ>tWMBJ I?Be q!q QΌuٙ(oL \d~dt<8.쾋.Ϥ3bZ @[\ZٜE* Wǧrm#ׂf NO^L{U|;VT,V]QcQ8Z晗'nnG-s|FdLJ=E% ҴoH39l;8|nBchiۿ>^7Z>j@b݋m}թSJ]F !~܀SDoG=|q ("޿`jNz%R9~4y^+!;{yb\ ͪ 9rzW6a4V.FA\r؆phzrɝ\8)sO$bs)~P2hJfV[pjqԾ e ixZzZs:L_zQ{X=ݨ`(J#Hg"N9׍"^tR#8Վ=D7g3pѢ *ow'm7E䩈~trƂB\6JI#8 l°k9Zj>}re3/k_?,mGt)8E)Ds 5A;ZYEt *GVJoT==?uwI=qף.|펺oQ}w-~ig:VߩB{ׁD}v.ltY^5T 95% 3B̹GĒO}wPخ+XqfmFuٞ0.Ño$3' VZy$c[+X0`!V*Ůq);rSunR+KQНl4Ɓ)9r1] _ g\yXx^rwX\ :ȮIzw|t %# 'c(eŚ[hJ;?ntNd0ɬN;DU3-2 ~z= ^4qR<Ƙ^xJop/y(3 %Xt {Z|`$\+]-Ҧt19\8 iH|=dsIƝ_sZewjގӫl ilJFyld^rWdD0b%oeNQOȬ(v5yϺ sW?40kN p2s&9bhV05s-h.s„iqr[,DeR ;79V ïq*]|'3ƜVHv/N&y_gmR]LB́ @:9[O %lyd6LvkƆsC 8{ŵI ܦXCa}K 5G5:hf8+2 # 4e|I0y§K~Wyn!l>6ꉋL] j!&F:HZmG\G!Ǣ8,%>yK;aZh ضKۭ sJ-L靂:O=k2+Sk5lsSS\)ڈӧG$O,LJ[lV,ygŽ2}d8݆ZKbm`e |ˇLTvnDE_VH(VP_~ ^k5C-~ ?)x:[ ݹm;7KDS_3kRZU7g_g$ ^˒D΀>'Xu`Ix7w@?jqZV},m2 6*,s::ռ D߂+_jJі^&raJ1U niކo? eU}F@K_J8&aj{}D?zo@yy.u N}R)#GG 5ZXl , fkQSjN*b -e70Q,,6%P`>nl]+_VY:︆Dd$!ruBȷP!!f\#;0ɞ6]#a!| D@܁f8V/+/Y-3OӜY =ON9PT@K1B;1+n(r>R*Z@I#4)_D0ˣ\QuOi.NW2R|Bq6dKm wC7&R/fF EX !Xh`Pw?v.UVHylp({E.a}l)l6oL0%=0uÖۯbVBQ2{ /RIĂ31JjAA~ }H[ x!P%)#\ό-&s(*il Rlcs\ p(P +ڲfF0, w r$m?ܧh_~3簼Goc;!I·]YB=sIxU{5QP.Hl_0yIBwP.֣kdqOН>amZLpLʥk9HڎKN9^*ReGz5l>AyѮ&$ NwjhS4=9)"PF#O/:5%U6ᏥIk܀F"V JUHǨǡR\mLf-q$p $#Nj:8Gh{X|PaY|ϿsN l~ ;t>~|xbSX G0Ȍoi۔d ~풾$ہbtfܤ|(r,pM4ī8VqUOSpmBmgΑd^F`Չy8o'~.l|> C5BKgk$T:E{w HXCH:W3 Qe.G{U~#?Bt]5~L IhE:5ԭNfoEg/Kt "&JʔxP~nǮ?o:cɿO_Ɲ6=ӤAqKj\ {ж!Dh7oAWT϶jj6SXRo6JVkHOK#V@輚ԱF ?b+.ܵL1[#p䴤6%cڔ"7Gt2XmSualŜFZ?co'>mI뗑ߕ@Fncsd89i+}z&j0y $j {禆WN +9Ly=B'aMtgxeU-,PoBcGoꈓ0Lǁz$',D@8CNz9T#Kovt O/~"J]:~ S|pxs*{жuhSDuj)7旿9ح6f*LH/3G`=u$X 3;'HFap؇3=Hgwqgtgߒ7- x`گ-jsr&)>Ti&~Ga/n$d 0hd + EN'Z3 bSFב,X0M`:6_ mמ V_\&8Ppi<:Z=Y9Pc-!Ʋ>I=W Se&m֐Q:{AJ5N0Jna P Q ikI/$h z\&A{g^ӷGvxSu{m̋fؗUZ?Bx ੐( ؂G;'z@HOBGLٙf)CatN&¢Y{x|[^t M썦B;ޟ(T/:2Ceg dOF@d:լyĎv6a`sM%98>3A<4rF%bRbX#r+01HOC+;OnK(B+xG+Ҵq ځ`<=_5ISΒuVDG$ئ -U_AQC;"+-$o{rƋЈ,z؉*M`Wh!x+2о*$͠0t%PWAx!?9RqԩӅQ7FO;g+roZУ=! 9cMmH\ L4"`Z8iJ"VY0SmCX$nQ#+c[u ~p8SYnL8ш$71I|R=t*t:-䶋O0b3R%!Gm:AUkOUN,{a-@2힮j|s&RBqM*u koD9w_-ɺI|?*9 ܺeSI1-Ď)L?/D7(|{%=Ϲ(>ϋ>!xx㽝%ac}{&Eq"JാZJ!h6 spakA&;xjiDt^OrN-@܊ϴ0|T=D/NLoA`ӊK}odra{ON3kp)ƅ=~ȟ@ rjN2!7θt?vLL:-2YM" t)xqucp q?x֏oC7qGCYvfdݔT\+RصY$ia; cV%)ŝSXFC #4ܼ,k{L:]ϺɓNᴀB -*QTwBGRRŐg?IV!ƒ߀ց˅lV[JANbwzƫ,5u"$$39D㴥G ~}b.@kii?GRm7JسDnNe'-v:DkVΈ t9F!#jrpdxV\/[c=s))"`nUl0@FL,栫PCo RTS[sd'\FD4a|fBq“ksHM݄,zpTߠSS{iYm]֒OWsTMr!FYXuΏ*26#xF!$by)s^7ROm) B +wFp@A>qo bB do}-3q?6#|q8l'yܵQ*hho v +aWJ#Y|?}Bev6!#Y\go!$`c.%~ͿuVxX6 vֈd2ʁQX4:=_ 'Y0q,;ږ +Es'Q=bq ',5\oGQɍadD(, z2)M9ɪL/+`Ub=eMHz~ef r0o]ݷUsjXŀLyw7k r@/Qh̹jB9(dƑupZrу`9~hS E?beLΤ&6I%!j>j|/C3ds۲O~ }QYeIpJMJ4!Wk'R/B*m:s^+" w@ T7})Vٿ(3t/mcMHTɋ𣅏9VE[l1)VNV9\X x"0!( [~ũ(Z|J6bVW)w-x(MȢIVQu&kD2~-j,w?+/-bP1#M6?2oZM)jvA!BS5aCfx޶k.avI_s/~LmɂuYWYD*4 ڠPw+7NJiZ_lXZ6(Rwy.y!/-[]`h1RlbU.7ߖJ2098鸞ryTB0襋@s2TkR}o%kIҗ 4K(t1d>i[Bqs! t(GĂ=\WQ9ajMSklֲy}iNYPxCn?v-yvvy`Ӱ `}bZyUrW3 K t_xq3fa@Osp׳mC&p@U'o-?Τl0Lz6QhaL]ݖ0w4,+@kWD@nc> p7𽟔9Wd #(TC.ڡݩ0JfkY1ZoL2rVbyf`i|^z hq] cM!gn"zwF6ǃUi 8y~kLժi/t֔6+sὰ=ҔW%Ҋ>_6D;C{.?#d1LǀÜ,c#o||5!-`R#raRVRЀ}m &T. l |䘧K{@KS0ҖZppAsgsw}31ua7z}t FPYa)n:9Fq$w Kםf>4\ O'5GeV˩$vrE?/}2Vxq駞_Dػ X:u:`\ox㨒PK6}[oGkO'hHfduG(7'ڙ85x@ y ƣ)#$Up1yewbQp#( TA_w`ar h(?%ᗔ85LDX>V?p'/I :|RM,-NhyE_j322Lu7!¨׀Nͩ"~Ԙ+T!Jx0 %K8?NG⟨ȃJDܮTa^ߧX<Ҷ*3JF~9nά$4#EGJBkX,Q|+|:̽m/}qS MN]K̴{/}\ FrԦROhVL!/\LwEN`9C)@!~[׭&P`4bg'¨N$SBW6(;Jq03y%#7U('M[?"z(09tݓZLo9J sDը$?> ,,Q<&iEˏx 7.%L}T$,O2q>k!e2E3[yҋ$ sJNs3\œqQ5zzќ!:"qBXl Nɀ$@$-P-4dVz͞LS0<, f/5Ө!^\ ^)#3J K)!Sɫ4x|kAI;`/=v9iNGkY(QrjQP,BAڡŒw͆Jo ˾xT $cH.3yjRȥs΢`#q BƦ{Jњ+GǵzBbfA 8<: gc`|RGlZyΟq䜗_tnpZ }1)>^ӎA1Qpe/ܿ0W h]쵾G^yԟE|1"E'*#q#mV/ʳN.gxe⑪3)kk; m="3㪺xb얮/8~7֎(ݜ>ݠwغDQь'׿L@0-l͡Q}CdL6鶡:N}K:lŘLh0t7{}5hN9FLGfQp9ΪWE;2#uC7w3YtJr4Y3bڥ pfYyާCO>YxGe *w ܘ{ YL5ܑѻh̓%:вgDi9ڴ o]؝l(G'>S'@} ,G5"+(Z֟hҊ߸:JiY N[KtU9h;8qm}>m$F}mq?OsKhBClhj\3/o"\] 0yEIU*c ).CvOϬ}f} hϬ,[$(`ytEKk΀H /E^4xuc vLХxO^ w ڃG sbXtQ~E9iOn@\̄zqT4§kƊz@ւxqtQ0oF]c.~Ycy0<#$R Y.(BDwTy@\]A+26ŴZM,* 1\f_T[!}R#޹V6gBq}]J *ca5j5fD_≫^Pe٤J[?2Bd=w|*G*pS1,8]NL:Sy$w} gYhÎPO>*g_8; QAA„?Fi$8c~xo 4|UÞXͮ6ZhIe=ap e8^*0$6~U^b' ,⦢pemY>DDe /t/AGײ{{dtkH|QeUPݗi!E.7&X4:֎)@3F,U#ے`8UK`" #e2Wb[xRq ` c؍>Q, Y~ SNG{~$sJ uVUM,Y' qvJ;PIzߙ%qݖ"oӧW v`Kȣp_D/ai_ڼҦSr -.B(YQWgv,D?NeѼ) Fh(f藄Y­g·pXwfxNѲBŻƢ"m+V$:}T#@}Iᬙ'n`qaL^KDM&vAlω66S]vmA 1y]qZ%u2-ia¬E#izvyΆ]jd@;odhL.fK`hחaadӳ}Jӷ@5Q?3@i[˝)>l_I6|@82''-]=a"3bw_8 /q?۫\UX0w}2-l8*ɚ}aבֿ/ȌB' / IûWS }B.,w0و`h#MVh|xoσbq=i ;20nh\UʟZX;>(vRQxĠN>S^^u(Ӥ^MPnTJۗn5jS[~ t_qVO%!#k/ w Y$x:O29"QeWυސX.{ 9X|Y|^1Ɖ+?t ޤN0T}< R<fTF4Kk68*q}}yy-Q~X/iD%9ȮɃDI/)dKV +.fyMv{dYP,}`T7힝@|E:Oͳ.'lX`F[BYf%.)3a#:g ݨ\NH3cj@P[ih"O£K}_c0vU&Hr_/'a5gl0 )K{91/O9 yk'1@ڻ~74$șm*C"e[b+ v+<<'SXmgSB+F2@zek67Ejj,ð}Muc]:Èru9 w/MЄQ^7YᯝPrr;78:|pň:SvbPw崑D~]+*cF3鷂;K5:xQBh3.^,xJ*0^AФ3MKKw\(c!]7ٖ TƲ1;a!W<ٴ0Ay / ;k-6E~V DFlx*^B="byI,.SƀFJ8#1C[)R,x#նeS`o;.݁g6hD +RŴ~}𿑾B.em iyͱaiU;I]-alS Cҙ*5J%q9!LsPyZ^<8 ~z{( 86I2[(Mt A+>$ɕ{\*5$ \Ͻ'$CnmK2udzaN,MEm`б*o_h!fy6D/G*6^+8MN{7~/yT %2@ oJ'ld^ o3 Nm@v~HtTdAK?~oA3Vi9TjOlzʸްZl4HYk6bBE3ŽUR7u]iə=3+b}cv`ml]><~@s˜` R^K#G131\7LEsKۯp7hB;M Y7&ɘu…HρB\hO0 Y[։[͈ FaDŰf O#7dI;nZ.Ϡ`S||]bB[KhU'He'A-qiE/ 3\8aN{+/gxZfsԑk @GP@~@/<(!7cio КF0VH'N3Kam&wX}6'ƍ0 \=2}my35@ tF"`VRm6I_EZ{|ݹ6?-9p2̍}0\i~-&I]Vy5 6oc2HM.u  Rؗ.mJqqުB]v Q\%B$tRczlqϯ h3z"qzS~0e?o(hl^/K.ìt{ " c|gaJQ&ɞ-4oq^*逎?B|e"UHezsN=.r7m,["> RI |)ZT$t^mِ+wHt!JG(-b̋ rVGp͖b_Vxp}s|B=kE\kJ$̈ :+]Ӎo~]3(]lD;AqثW4{T4!G~-0 ̟k* \.HsMNvC\( qorVoAuLu2LcQar Ղ)NCB% =Kۗ)|pK2LAXCޗ ZNmZ)<0Gw+piIX7Y]]TP*NڐbR ril{f3h8a_oI`WZx A{C6IMw^ןjĀRm뫐r]Mդh5I$3ІakR]5g.E͖:-Ҟ|"sCo8VtC m,+ )q'juEsbf{*`,`+pW5vQx=5EaqcD+!{m*N0rEe甸Y%S|3ˡ) 1P<=_Мn|i(fh^³* U0OL$h@0sR(Mtl v!Ȩ=_tjP{W}⚗$d!B!D^JVi&Ґڻ/5{$:3˜ 1+1Z' aQ+$kJP-v!ue}?8 \F 1T]u`2g/v-R`s:{JDw}8} U0` A /Dd<-܆ǎxGnၛ|GxBØEf5[GfKܞ?Læ ,= roa!e5 C{" k[KyK&O&LRX8lx6OBM2nr;h* (ϯ>nN_t5c' $"pDd֤i9e 䜗Gp셱qq23Ql%4 ;y%䬾Bxk&%[pmVHCmӺ(W™߿tI|P\D;2b^I}yJP?R:l %:eAHoYw7؉0,^$\Szn"av_Iqt <]`|? 6rՕƜʇcjfb$ ڒ` ' bmJF ;P#SpŰrj8i[.;R޵{Ŀ ; 5R;hs^z <| {Ue+`Mwi R̻kOhd0 Dwm {q;.H*@#7^_^%yyR2%Ki#}aqJՙ3KjZS{ xPҿfio3n|@xhA>@mMٹ/b¯Q<'$\k7I"l69RN089VJ_Crb +#ײs^[1Qm⩘nhz<*Uj7Dc~kXq|466;)#* w%5[+ j[Ѻa"lk˸MIYDXG0 ݕw4N H;ˁ DZ- .6u~1{ɿY?{3NdVA~]BBU\g U"P6"}6ZUچIdr~tҪ$W\Ҧ?@AZ?JSxdu J FvktRTϘMi4 |rTEK` :$uH/)һA!ΐ)7@IR;0?Qt:OZLSX _Ea죓4kbS*SrDG5_,Ξլ[Z[b %So1}w]1hf`Ep_z~@ Vt/ֈ712~6+)z@Dj*` d]n8eޠ6;cX6akfsu<.6Yφ2Q7dH7G2Fug,&ّ3Rdi_:7fAVr @ڽ3h^mvI'/]g}(k$Z* 7M3d` =̲ۤtܭyt*JE@܋j˫315m:FxHçlZ:1} wKЊO>I_;@Q|ťBt۝nM* ҵ:!8}{ ԏ :x/'#ȲZ6pH~˶"E7-[Z ~:c7BI0yy5N^-Vz[]1\~5GDetiPk'B~@PN[ n~>QZUz Ǵ"uI,~ 33>lZC' d`څ{eHl [Bb}Ӥ8 (`{;!̺I?rX}{wHWݳ|Qg8I[ûl Hfkgq|Px+ez 颙h( 3Jo E, |~͏4[ sfc9Kf4EDRO{Sf9[/h ParzY-.=Bcj>cR+QA 2,I*>J SČuaȹ02 /,`F!UWVpf]lK~{}Ґת>x·ql]PIZ+i馁acѺ2Kxv ߼Xd6%#=z͟_I4tdI="jf߇# f*}Z|0Mb\Pp36Daߔj_pfWZ<7*86xщx3xX.vzW\i(%`;ZjtS>[|2N8cMK`r&.'_z㳘g`\qjknnYqE?y8pZ=:3аBvJy0 1ci2E oMbWllU,6vcz̦>V%?nAN2F #.E*Eq5(VJso/vۻu1ڦZAXy+(E 'Gޒ& 9QZt_r_3bĎ0" 1X k8MC;px/nۿ~s00s{\~^iBg~uM7?{ʴı7웳՚wriRL'6 x?qu|(oHM=+n^HV$RH?GxibYK[t(G9.ol2=hT-ږ$m^V[ e\~b ^5\_7 XYF6EPw"gYao-DCھ_S( z-+c+'T4Q >vAQ__]ͨ$8UtGݎGFkQE*|'aZ:k$\UmuMmJdݜKx`j/pڧ83ތ!Rwh".YWISCV e=U:#{;~2߉"j;gfbuT91xqu|%>X>풚f4׺Q"N6e6b>?9+m k(\|:RO@>GgqQ+>gVaQRY2;i{6Kj/h.|}DMpWUem:ja¸8ns \Rx?,mV ]Q6fR/hXma-㕧$ͺ槨+_&LhA??C"aܨvV2,~pz RW-kb:ƞ|n[̼cvf MVoLV Jÿ4ῗq[ e8@b &: Yf*[IJt;YqAP $1Z:5DZ@pR,ōlK, څrZ .j{el |^`/dMy3~|0kcSggZ50 BԺľV"4+qj #D#;攚9lN-6 S-je1\ݓ)nƠs cg;HrH44JT35ǭȻf%`hC.fV2:Y<ٮ8ej+KTfxrl7 ^j'Ok̤k #`HA:,P(٠p݅r \G C}M쌕\C$ђ?p!d[t,$ !JFDGwދJsN0EE@`L4uPdc9}d2R@L hQU3|3^#Ķ= ɼG)'W[]tqA3hQl/{^:/;\*A|q!V3E/PAC~&4B^1&S3番)!uԑC KS_*6jH}I )Hy 6Ok={~X ym;>+jhሴ) |%wQٮJ j%e(6Z.=IEĕrC`wH }[ j.!BZPpT? 2:tch&t lxOGr{nEzΨ}`_p褷􃤟UO7Oր_Q-K ÓV1bєb\aRH+ÿRB97F͂璨}Ͻ݋pzZ,rWCή#D#x</ fEeVڥa`QZ2@ ٍ'3Ђ?99C',lAӨ DJMtcKhBX@y @݂kt XDer #Qp}?9Qvg (Sd{kɵfԄfܹc(>jL`kbd]1t+BcJaW_t{ `#QЁ%&~dDHLEdy6P( 289 ԣ" 2C( pbg'z!rf q1 s,J٥ >|-8ˡdo*IoiJ=(>cm(j9|;]K . 4PUZQ@IvU7FyX[WoDB)B. Y/14cB#V>Stۯ7[z5[9srՇ8PuD}-ęy$Y@]@ľM~F\݋&_l uJsۣ ң7ej~/i^qk&ONJkB>_yv9džrw$PXhW5#%(H; dS0Tf<~였Ntr:w=͒W>"Y/\74 ;~}q;zy5Bc*v[mVr$`p%'F͖ 6~Jo:]/`܇C6q{kd?c|ę#^ gxZ:Hp-PIN. 8T$`fO EqGEH_ 3*~?]z PE&;cH.é$,_a撫.8Bb!G*;g|HD #-؝fo>??L'v5hbp 31r('J6IҎ޿:ow%l޽,:Xm +5agD\8=5s $^T>M6V7)&^N=POr 01֮o]=8#G 칆ä9fRj%Hފ-!^SQhkjPtn_ׂUr}A䭔 _{Nӕ(ι90dV?@o#qQ$gVY/X\QИ&5!>^z6;V"2LgG?_^@+EvTwYAn0Cˎ6ĦyMO-H (mTyܹ:y5=QBb0eac'Ҳfa>feUSu)1OY獯*$~hp—a`%na2pIazOOaƘʟRD?IN~|L~*Fׇ9z>4¯7Qk>5ePb }l܀9Lj(:3˜Z[)N-`DL}.Y@JdDle&>NoXc-&sFT!3^-0q7$2W>܍eTVz2wS?9_Fy)}Q|/|nbia;3Yς!LHH1dk RGt q m%m9H]!Jه. TP`>/_ʠf:eYC D]Amj]1̧RH=ԪxPQ'|b4rQEKS`e';X g)(4r',*ݍX7+Wv8}Q.Žz|9Mz<<1qɃQ} ynrqr}QEFRխe{ 8]9 $<r`Ukg_!Vuߦ|}*TJV9B;Et!|NʚTv7 DITKS{'][ro`l" c/CܴlbB^oߍbl@CS;Jo%A,McBtH@J-%sbqO'i3ނR"s[eRbeJ30m  ֹ~nSJr)iEa}RY;5"[J:m옯aJ, R7L,eL'ꥥ#(mFN(7@0!@sWRW5E :Et hhK _acmc}Dg:Fnvk,7S(/Y@"OfӋw ڔj'@x ok cO6ƆMpqXYˣvWt|pXr)lƛqz/5jtGbap3SOF~IgjqTeU:/^2֋~] ) %\`ݕ:Wzd[9ZRs_b mfD6vIzLBʳ(`dIQkLhA. b2 <+bsbcJů*G"D-=rga|/CkTFJb%%؅T2Ŏϫ8^^.s0󫹻7}PĸYcy:nqnhq563?q$ ď-! yt1FSs=(Z~GcúFC2*2%U9Y S_6+ W8!1JQfqgl.7ތ^4l)X-FCd#3LxCE@L jC}v2A'Ci# 'h7$]ùY?׭sRr;ٓRꔪe,A%!0coP64e#1j%>&Ҧ7 ;-SXyi :bқz9PFK1N  >Jwd440Ԋ+P[ⷷ~t'5$֚fx{ʆh^ Xw{ypxyFQcuH'tp-˦4Ix("& 6%O{oks3Ԋq>N2}"pOj36 ގߴh'D '{J>^=?&[hgZI,p4B$QE: 73Qbk*5," tGX~QV:)5L4FC(v)l'|Wl d䪧S!tO3`e̽tG[ oof_iK7h c4V^c>DE t%}3ޱO W3Ah!YЌT{!K3t+-(UF]~C~\½5 %=2rmU2`m̅;SSl/^JCpV&̄8 u#DF? , 8 zP ʂg +8_D`)NNjiqY>ƗY&w;k$ 4z}%DC9K]CwY 4 @JU5i 2gDRcAbK>~v寮|y]]YFV 7P\xG'Ӟ. 2~+gb_?J1~FsIֳz ey;DfUk! Q|W(:TULEAل><6´FNp9 6CjQQTPZDIPv>>^tPx_Od׼BmԄwۢ)śDS< 3ܷ؅lM4oJ`ej&=6X8 Smej-FE=-O)'29N}g (u>Rs*Ze*51Bۮ{w@ 3qtu'?8}ߔ-D#i8Iʠv',]d͚+ fl.-*) NңFsu r_G>$}l<,P NO\(cQ<8[gg^UтZKH0ocgmALXEGex|t 0E̤(7kl[Q -80Oi.o{*R1Ɋ|[?>H)5/6tFzVU0+O(ipRo(1"Adr}QJs(r)?nHǕt5WzB6]^#DXɓL (# 7).e_5r>~O㣂v{# Egc$Lfv`xb9#4BVP$$&:6yEL{8<~O\0d6'R&ԗw+g s uM?\PM`=}JLpC"mT/sVz`>mJ/@Y(0$(*w MAE`S:t^3 sU~1bU39%R{93UOSrߒ& &5('gS9Pi,OxF&;2k&?7Cxy8Uziu N G{<*I:sӞHSaD.g4trҀo)2&9|m[QUupڹ rӔ]ppZb?պ`;n,QsLT؝Svۜ8Q Gc ֬G|{BjV//3+Z4g FfCXU*]I#zH5c|R}iF"b;wo[0%*뵧vUE {J7xz{o3#"wUok+xWBIPGEQ8X Ǘ+kwwUurK>b $w6.*DYZncU3DOiwz=KwL\ ?wj c| 1.Yy%Sѯ>I"0\vf?i=pWunQPpR&HUUb&'^OKhch?yBL0#:^; m{!kr!o/Y«eڳB|6lI7kMYf !-̠%}$y=edT&R$gfg__ӚsQ?ZarmK m8V-99RzʭM6reU:mM%ac%7šhK`/kv/!]4.oKwǯNI >=_wI[nzKۅ=^u0dT ]|dPO4ʣ]5NpU6 p){B=x$H:G98ZF:H.V=%` >3{hNXC=F z Y]m6Z4Kty$GLZprn*%F% 8`k[0;C3MaњG kI\Nzk{G,WMg/y֜ (Y7Kِ'%p;CMqn.gϪMDX;;ɶǓ%邝 ],67=ur:b7~nR7ȤX9يv N+~ <x6.hF09^ױ4zkq}:.Mn /)Ơ)y;8pca=F-ȇMo+¾ð2*W NLMm2  iELқuA>C>1%6ծ?_>eqF.;eSF:9ɧ\BveO\D~odƦ0,_#TN1U,뢦+Tti$C76*P)%BS5VaA y')k}wسyoK\!TYk[a_eDOh@Gb?uG$7L閊ۂD|0+ľ=X% A|@6 5>OI䁜*{b:z"/Վn@(II=4K ŭ?$B 6$ZV0"83Rz6dGgSЧFP_Z2ؠJBJ8l+a1p7ebgTw0b8"fAr_ER̳.>ѿ!GŠ -"!T_ p/|=)wEѼ6 %r. l ]8b@+>e%Iͣzt&fOFn#w&mOh{& ݱ3xCajF_YPH|KiU W\bXG({,(/>$`M;&J2bdd0'8TYe\mc߁M2tTԺ -=܏Q3Xobkm 1peμ\[Cqաn4>;ԤʑoSDDB@rV_&H/Ufۊvx!ruYrtػKN> gjWSW\:*Z,+"%pf]-ZϝgZ6+eEjr|dnnۣy-܂RUұf9)lẺD=ߛPM|嚨-l)|FU<.ptcKD62<*7D.UX+;ہ>?>c` _wzzB7dG̎`*6 @>6T.}7C2!k-5v/NI<+;Ȍs&ίb-4<'*$UQ=٧qZjۓ%3+#U3b{Q:Hv {_w7.(2F㎙e,~e̛εܐ=-9߰tvO)Vna~0-/q \,7EhWJ/,P2 5}tFC2.Kz#* 1X'8Sӯ-֡N ~#+Gʵ̄z :dI>h^[dtnОxWG 79MTQi%VIІ'*!hJ:zӣ8)y4QԄ O}3[jgg>"DG% fuf%sH%?7L2dE޺WfX4:DJS`R!SS Q0ĺ GF}עێNEh)4zK϶k`$DQƛSi.4(w/"Q@:u l&ϋkbU}ؐZmRp~JKG$t D؅q74^]X*Rqb: R+e=sx(+|.:_dIql\,-(rJ>} _ ?>NAkz |M+يジ9i B;iԪ1I" ė\q!g+8w+w2L<hF` t&Cۤf7 `AB=/W#XYx} :iu_Fb m.^Kj'ot(e)@~kKVSz pՐ>L>+, EIߟ]zkz A!DY4=+@5 Vv ;&w~GXbJHV|,CSv h8p I_RvK2XCZvPn<ѽkc/W/tˍ9<a&12#^vz$&jjqUxߎ4S#j ]OVP?6~s6j u`iN$ vP~"QL?_lvgH,gڻqyy2y2$( .u}> Ro`GdW׈thTo6,=ծigY4y= e빓S@x2 Jg@%)/Ù(ʏ6$j{+áI$XeOIl KYz FsڅeW$nmӍ ՚| a+O/㻔WjjlWi>!sJ^S#CJJO/?5#]/䪞 (z] *i ԝ 0p}H/ҎHSzآbxtT[> IgIP>uZG"A+*AF" QyQ[dufMZJ6Q0^KUOčj鬪W"D>TS.x)|w( JYڨܵ(p̴4`H$ry(aGe S]^ Onl՘d8 R)!7K;@{B%<j'9NQ9V+43qw?EnbUM:Xlv3 ZOpb!HLn ]@0H1q JF*,7KU3-U|KNL8ZhT.aZlze%|R|ݠ$ JM}"jk~Υ/YVnP~?a\{ W*)D{t-Pb:T|e8]E)Ep`m/]%FngWZ/h[ _?`TAߓ{tF:cvp ;^k 53jtj_bp;EބuyX~<4x03&LU9\ռ5IF \RNs%h\k SRƕh~\\lڰ rRϠ m2Ak&%2UDn<8Y|R?`K|+$ ⾠j?'\/yaDJ Gpz 缉 c~Jے׋dkA_ZQ]CB[c2nVm(ۗuyF:LJW/Q·sxmUW9&,hdPyGֹ+"̑pY2fN%Ecj{zaP@3C@o!y+r`% {2e@$Pݽ_٘':o ,jE ^z9+Oo.Uu 3uD{2>N` 3?} hl՗+qBw״V W^FUqtbEAo: z(W(N?MzD҇[x ѷ1gy113 QzAs-xa$` (؄ n=QA7^.+EPtP2ac*v#QB .3͉eliw V;YY| ,j1 -FY{bb'R+v"Լ\ʲXb߼QiR&0d 0l$Yj2 ƑC,y!"PVq}S%[KRYǩ'YqK],v6aס3.go (KD#K6G-Ϫ&mV6D1kLćUwr5j^Xu'j9%q[lxbwlmtDQ  p1+17v/i`ױ(b $W^)0m{Z":gCpU ؑ`ݤ:9oa%e1νusz0W]eZw/10!½ٺ6eueq4*` <6Z\ ݬ3fס:4+ȩp_ `U-H iԞքӳ[B. s~+T $=5)ƻ,Kϝ^5p1α&@'NTX+ g8jA՗J$m9(H<" 2\>Oh.;NLfީ;>8UI$~+VQcBľŋ#.~ cX.ě\REMf8` fѐFzL"a;% x9,e~tQ3p#ԉ`飔pH] ^{b1E3̇Ei M-nFwCp_ЋkjOMw +Es Q8n.{0cH61?^FPopJIjW 8Pc:]4OS!ƞbLb<>-f?/Ksۘm;Si;럞} p0KeMx<;-^K#* v?d/ˌgtc7y/iLJRÝA5'4lR6A @&SDޗps^rZVuL^pV~PXuЙYz9]VyXpgmiq{lcۻα;#(~ܑI4NAEə&yqyxlAwF;|L"Բ(#Ks_ rBoc ?*2f59lYO8g0@G~qǧ`nU0VQ:s` q ͦLZPALpV EE7>4ˤ4GR+tkͧD 4dweEpǀTƻR{?}ƕ)n6S 1o-$}m+0舳O&7r:#:A!)8at4jZ 8|tPux-k.}.3%KG-X8LCƞ6M[17MayeStߕvvR{%ldJ\EdʈӤSyְfǴ VDVUj#Abgl.׍5އawM2c˜FLA[@ӳg+ጀrdS:ȝiR#mScNrQ3TMs}@~䨚TC` rDޓ&ܡzp5-i^ќd0Wt@Y*:;>F5ܽޖY%wB H정u*3X:3m?iUbX0Te}|VGLͽDPq)wEu'LR o+AqJsCkꢞMdMHiz5eP*.rQ Y򾃹Uy :Ap2ql2s ;q% J8t4tBcQ(nH$818vqXX+߁/% |`dq 8fU"W^ބ;u3z BhvHABD;M$yapHaq锦$'4V7cnPqcaAo?{̹8ӵ)V`0שUԖ׎|Vtvcw..٠,TN8xl*ZW)0ֵ.|@2Zpߨ*A1|XQnKМ9,H [pk_XLZ_e~̶gme0owqD:RƢ$T_|G{J=P1NzDn_ur4yf=fZs|o4FG#msuv/*ޅ\$*MJ熲Tin_塆eֲ֭!j2(2)6 Mod†W4=;bXzB/Ӄ1M3ud4:,|nXrEm`={ n<ρujt'^Q1:6b=;+4WܱDJJ1eR9^pTGA|"&}zh[J}NZg2+$X{Oq^b@u5>wC^P=] -܋QY![M,(<Vg(XuPB0uxs K kX'&ニ"~ tb#jq2]EؚjX:J`Ll ZYJ_G`mdK?Omca"ߛy.[cTE>7PhkB{xLy-|UٗgҴ;p+)He:H ;+H1'9Hj .5r/($wĴn7Oy2\1O+2vϴ }uDv̿yNAZ~@k&)[OPNUfpw'xx>"u4AsAKDS,,ܭBq\CgsGFEDCK^E|\0<sp/\losQ(N1kSB#0wu?7S/̐6>jxŠS30eL#ٴ)kgBz~-j E"=W H E&N;5DOF*lH<-Ȑc. r})oO]=j#{]P]p +{á@<); R\3LN*WM"T$(OXlKv]G 3؛js C} Kƀ&_ hK2M;z<^:re|HR;C( @ϼȦ[,{H9 7W, -~iҗP=(EXe)ƿ F0MkpMel%/ںmnFbA1`fT!y9TMBƏN~䞒}M2ڤ":PADϡN9I88xe|sKTn",EXe\8H'8cE@06 fN!0SgCѬn ص{wLDp(twB?' B&P5whmN;' [+s<)+mq`IjME%)M$M=wZw|q|E[A m٫D c?~d#]Vgt2`=b Z=5.* >I"}1 ?Q7<;zKxA_Nx,)\2ݢPT#m{:v*^DNI,A[:;4)X|DfK5BݧԞ>%IWemD@ UAwBLJFC7h߀hmQjCgjW1*H5%_&e0o1!ӎ6O_|`X,j@)9(8EWinewk5ҫtgU@+O/V\!fJhYҶ0Sh)[lB˾g|sז[GT0E[BqH6  GUr! t{d:򌊰W V O=[Qށf RAHuAED3t3D>(5u`+kQgZ,H _uXۘW- -JwcA]`KۮϧEy4ᆧOXu]D ZBc\D:XZf͗'ӛXFoSO ,*]LO an^k+g[$V2nϯ% v K/F=uR)VgvFE4/5QMg@2i _S#*F'q"8־"!ȖQ5sdM:YJAvs]3e t\UX>4<^(Q Ɨ>CBB@5by՘eedx8/l1 ieɺ#&YVeXr w;!WpPPBhfVY!b"\ΎuVytn{_Κ ˝YѬ3ZBM6Լr ;*N/>&r a)(L6G8f0#)k[-?j/=U}7E V+ E'Q^\]v Uh9&Gc̪؎`eWɄXo$.T1 N"!G-8fX<+>-j*֡f%N-eyUBڏG;~cw&`ױ:'#dF>O)fj2x|^Z` W36/67BHpy>8vh.ſ0TWkpޠ[z-,f8E dE CٳvRy&2Y#,3/oCdsɭ|-V~r2ལE =ķ$8ls?bxjfiʭtX$2v gX#D9$I͏p+nݔMkihEVsل X笿 krXIzcpu[\ױ~N`)֌F'^2 B̲ɼLr-'C`3XШC>^%=B:?vxA5fޗF.qwt'C-Kr5&2zWXƽ|v=>5!/e(Oo UDK9#O Lb~>f@]Sos@]*TKIܐnmdw%Z%ꋷG(k  o?׃Ş!|;6wa!`x>Nf5 7 L# bwIlΐ6oˆ`N& I )ֱܜg2epOXBPl89PZA=@J(=, ;pD>iCFlyGf! {2RHw R 6;4Oj̻_hKs2[up:HGZk' WS?Ȉf[[ >ڿ} ];.0C,`}*^5r*xޜy8*gQA {܀WQz-u\!";yjjX@-~%rX?08L}&`B Mo>/Oy5(ۤ: xqgoJTT}d=<BFVtJ*B(ʅT pAOI) ɖ IP_|nH.hD_mm ?ːQH<#%?cTzyAsq?a6 oRho9)+#3H=GfPle?~%j]gvYgOufFwvŮ3mˬXV,hSQ;"4(u4b=E6[:Ai$LB~v=m zKSƃM^f89VzcP[D0{)9ԻB#,!iƢ**ZX6SOxZ=CY,4 Y&NT94s'I v>Dq786D&t0t i":p Jy崟d~'ˀ[u.lovc[܏S3=qDm`6)쓚X,u&Uջp]wHw\=,Tqeew}p/ܡϘ·RJԁw0vF 9VGDSxrpPv]5)߱@> ٥q&NtpFڏcB <=M#)d4@C:6j6ߒ:hzzU![.cf=ڀHW9fAkPmٽyt aQ9{v9f7?P^}@OCB+Ræ ƙ^}Oܫ"Yّ" VЦ ~V-2$UQUbDxBgO! a-T:/ޞ\P rV`3|Mgp'MmUc4wtK%y3vkSfQY8aug%hlz_o(]J7O[p图mceٿ}JE [RЩtrqSVw\4oF}V濟%,VPc;4ſ7wA'P11^)du280n Ȥ8+ҬDwXQ[0%5jS}lΜ~RvGIQDAD!:PY8J3: ,d8vNxwzqw[==nMdM =RIbEG:S[\.Y+'&-x)¯ |i^o,T.2V櫞 TfΚGRndʰة򜍤&==->ۉ?JQXݰXƭAdocS- Ј.x}) Fѕё":>+NXbf$,_繭-z@E*_XuUE5C3e nݭnʿF*2`]DEmڶwc(򂖺 >C:A]aR,F )LZ&WS Bb^u3 ;S 3jr8Khx&^a Ҥ5?_=bEm<$u!%S)iPDI'et~%*G`MIC(JVDdN۵ںS [S훢ʕ+ӑpjws㰈?osC7z"mf/J}& /{UC/jڎ 4:!!*Fgi.F ꭝ q%DX8y~b#Pg?W5V^9MB/0WthЉ&#{b?*T~qnI.Qo3h ؈P,2[sݠH y^&9㠖<+.ipz;De~sfY03ÚV(轛٪ VDH+nVh巿/ayBTAw9Aɿ8}ز^k~3`?;.3uGP$ ŜJ$LĻa~~E9pZJCfWobEz*tfn| ,Wv~fށJaE'z`#PcCGD-+1&oE'Q4T*fhzgDG"XI=cj6xH~9d@tߛOGZvl4yҙMzz.J$ <?7hm/"/w3*j+a6\@ 2 h$ 7W o\=)J{<y&B)N N&XUxҸNd"n'l/w`kVyX%/lg֋}-0d%˄q%}-&voI fNvYI}#Kc[`:~E@l$$ogncV6+B6YiJ۾ ZO3lmEd-sYU oy'cٽ=AI2/">\\EGy+8`[??~ U3)+*i,qZdԄ¼e̩,jΐ=Z.+?j = O?H ʭ{O<0ϫC'NV)+|]F2i\_@<0+R.)$'q<4ƴ$J=({Z6LЭ#sg\a"7`̙Bg<61)1WX&/E\u^BU.m)EXgnMa)6uoNSJ gTRBSO̮E$σs,5_o#'4'wPkЅ+P~oXp&zE77/l%׽GYv- n(Tfy:s r{%6;8 :eHr_B#qȘLo+yLMzru $l6λA<!57.6cnOcɻNpʺ|{^D&ޥ@BOvvBKpYۖ1gT&PEgU{?U.WVi}X.a |]*,g .o5*5,WJ|HtGQ,8Vz EFtuh*iu)@wXB&50G f˵F|e%<}P z'{ r'sO9E/fA]`X/3c=Z G\AN2RL@QGrc#|8=8`* ih,PEjō]pdx.fDy.ȝd^MfؕBXGyL-x'j!h,t~ܣ&hl5:㊻% Ǔ tyP&Y[gϓ)WZ4pG:oeý-!8tȠכko UdZcp>ZQodaR+)v'+G,@qn }rgO!Poh5,=3Mx3]g&J!F`gtkػb^BQxoRV8G/ kF({Hd#½x-iV;V2^?G2kIXPM$fYƓ.u)aSž a#WKc[!6Law:1bE\7/w?Yt@Bud(tp&և0ꢩP.]8k4#9Mȳ4?7K^2dCA. O5[Ca/' n@2{y.rXom2xnoS~Q pxg(A#ADwGc]܋DE=g?2G7)HL}v?O -ud]Zf0s%+.r 8SE2M)dq>fxcYa +k?Ť0"iPT~7r=yO[/=Gjɓ!0?)[Ѩl\W\Fɓܿ0,*~cM)i &ZURڅ4+$qNL`xrzfe]h3ͮ1ܝ?XK:݇jzO:= ~MArd}(A>`Py~iMƛ0c%{3A2+IW@jETTIw? 6q]\ \ B:< ܸ31C%8Qa`ĂBior\Tb[Dn[nf@2 yڂ?zVFjM^LA=uJ답 {|'O+:y.iŞ\  FVZ[j;{XU9lZHe|Ud+M$W*ˎDj MoYԯ-xczBh؍P(FtUdȌ:?Tf"^: " 8EA܋Y [ R@t( ^pCi$Y5rtƛU|;ط]9Zx`U9\-^㯻b퀚/DAx֒7(]KPcDiN%k%D^Ϙr}:GM eh LՇEךgw-uf%6pT@v"SgQq`=hEw۝; ˛[$N[;!96$&!u]'@W+"AJ; SSBÓW\c-C|?Gē >OEn#P{[/Zq|d"QkCAB{ x)jNYh=d&ml{x_W=& "[ Oˢ{'F# ߆yP++,)@ _O kvTriM"!qC^bO6ԮK2o&~]??$pui5+[P:dy0%k~ ֜~Ob<@6-XwYʒeaTN~a-&xt&!0`%1b##45ЮyJɵX|)KcR(/sp.9:H{[¬+vP[I# ;/Nv1h[$m9I Fj1ll m' Δ) s }6Rcz7_g͓0ls P@8frsu<8W*٫0\SW1m..hU,&Bq+u=r4;1qALJQӘ }<4MHVpCHs F}ϟj e"s;>)HS_6jjL责QNᖾ{Hhj_PpL*ix.>~K7T @UžjveX T $Q& iWO$K|d`?6Zf|[x2:6iFd!;ŏ:O?uNrןsՖhmwf8IʛyCԃ/IA/T}FDPxӓ;kP2rP7}&N9)Z6ɒ/T(}-a׊ƶ֤8:fo ΰ.F!C +"%-5/< ]m XmSt%Яxj(cQㄍ&`m9.Ds$^a{@|-V}D ad#^>6 ՄH] YJѱʿاA3TW-Tewύ㶡eE(-]1.gםŬ l8[)}%gj¸:X* 2P#RcC RMdm-U] PC˒?(E:3xCM=4_,_09\6GIXK%ی_@JASѸgeԚXT^lPk"$X&ů:wɭ>ҰMuW5 ȟ-~ K9`{]oAas:"fVz-2]ӽdnn_ߘ[-o!=z.̿aDiKqZߌ+h/w'q1tqF'FG̛6GU_vpS'Sf]PavTmf6қ h+6X\-qǢjn_doJHcScܙq <+cA5`]]^.e3~]냥YL>1Xb[xuEAܫ{dr-=Q{2D*c S$G)mavGj1U6揺╝!#IpX#IYҢ,6 -!XY~t}m 2F}+GatQ }t~!6Q=+f]KADr}]?_XBP:ӱWP}'.t+̢Y$Da~o4[E{,ᤀNyDd*8'jCVF껼%lc|L'iQMGk{H,BŒhI~Cr5V*Gմ/JY$9 [ F8;(uaЉU&|ᇌ^W_$S|dBf+nP,.[]T[0 rv!os:3@#l2RS>0%Ah;,y"#U9*r/gl8 -կXH"e=[@tbT|s\>F0$6ÀRXH3LL>L@ǎ{lC^d&%pP@|͑FhNUw霢2FlAt"QGںx`CKBӗAIH2VMbQ90̔.Ml)Prj?#"@-CSV )+[v1K]wOy$aF6FDMGdu-#.G\c%˝G0̯&O}ZF"4 Load:A]k(lWjk23?@xp* @B뚛٠pU!a, WQD wnn\$C<"Pc>Wh6oDm򮷜u =J`uܿ?ݔDJkF:"k)@ 5"$ =hW;eiHzhr!ˠ:U x;8v@r`qje6=gi" ھ)J>'Em Rԃ3F9jM葶S5 N^>!IQT_toL黦5F7I,?9UX$1ZHX;"%6NzhzxF9cŁq7ӲB֘vWu;Ղlj4V6 ֳ ЂxR܇ƶ3&78~4 =EO,߷9w#WxT%(9RNɃ?2 -2ߖaf/D$|vilPlD^7!$fT@MEʇ>you}TxhHG~HMD|/Ag{V7D Zl%s9C㵭bfΦbo)IlqdD>^dk~% ̦,WgH`'A;30>ujF G5˜wS0i[l)@GU _ؐ{cHC82 Ǡ%zs7T)oPk'ӕ''ɪ·{s([U۶Ujg0贈vnmT\ te`3e#K5pߵ˅'50D3pJ]da+Bm O?;ځơ 1H|byӿY~Cns'\>nj=k"B-6kU_OYnk=N~#!:CFۖ| Fǵ}6Sc#t.Zt`">lnEFm팒nhZMyȜ~7y(! cLհ_ӳMB@ N=cXETɡR!8idsjYovtf1Y+EK`=XޗN>oSf|cjq{Z~0󾑍n8Jk4 3 i!.BRޤCHjlm0bZ3r@Pr;+}M#Ƭ]3&?dGt4Js"Qiͱ2$ 7h@׼h []3run$9k8uTx{C&n:IBRF)$ y6xUytƇ 0a)0s#9QRŗ|~y߉QtсX5J~OMG~Rr،P^!ɂ;'k #\RFR;r=yE5M{7'|c*8 l`&PPdƾ0:o~c? c#;z^s)vEWMrBEIN*oޫw?I!zWl$+[44A,t7U*Ph˵oh2m~A 皉vrqg7+ތhU1C*X`f^LÎW5LA>9 ;)m^gǓx5)巗ms> Ӧ $4m;Yr~j-J:֫H˙E<7\gw8XW}̰;"+$q.}t?aiDP_;M$ O\8pqΊ}29&IڭZUovɏW!dsSd>}`#skH@*㨸%y(JdL7{$S8kOHzQa]-:6-unx{7@Fuic(|GŸPKՌ;Cq}i3/bvr?U,&[x#m"/)x0sB+Z[yz?WV~JUo?3w24͈dO^Bt {3_.xߢ'{: v(\ofbi{A.!4WbV,|%L[HJY\_bCdѓmM2qZ]Fk n -0JT>יxU~@3MbP<43} =g*ʛFb-0ńɐ E1-gKi)ߙbaGI$?&-Qֽcom牖-/c%NYh7D,31t{0kZY-FoR8c n*./rLv1ov´2$Ď7db-neRm__(gyrq T"0Wׅ?; -rN3OK!`-{RF:3DĒl/uwӥ5z$/ @9X7?g9 /GE~#a{ mLK|(pz=crʈ;n`d_?أ4X)(I{y30gZ &Yjuz3tg QnNj 2m-;EBK6MJ:o=eG!B/†xpjf+L6 7@5:]=gvm xIWzh̅@WƱa ywRpN:Zo[Q#%@27g`^'̡"Im nup^i^|& ;7Gh7뒠notXQ@jཌྷAf6*={ufה 5/;,AP.ksՊz)Vў/P1'ꭅwvC]j(#SbK28oh KC'd,N6@Àe 2My[E0|I?dϞ%vw۫6\, _ x?rw!U~iF|3u0xp2j5ۓ̗5l6N֐ᬺ2:ZBe.RA {?BM{XrS$14JLH+%LBoHܯ`ZL֠MkU8J=K0f-K_I1VL)4ijLzti  BFNW^8E oƲ#Υ},Qw B0jhbe\h̴/|o1fPY8N` &/P| ǝEPnaD=X#O@1IGGd.HpU//ѨIш7\)Q6ZdU= wfgѸ`ep]rX|YLbQR g4@')teRڦߵ%^kW;9jerS,;yt嘩K.Z'X cK` l~Ʉ_'4pXe>.#K$tA^T)4/*iSO!y[cFRL"~*)fs>4 _&t,K:ʗ)3Qkw2L;$8ǡDDz?O}| (DpP?cP#mpVg3䷲0XVZw^cG23| ɮ6'G܇f]y;zfO2=ҩCa!Ykȥl[~4[[|%G ,m9popgezݞC$}-P/q_"  5%L{n_la/zסpyBu@;7-#7Tug|qEt-/K]X,j~"*&k׉w@TM? В2Iſu?6TvlƵXBS̜c>2BiE dQ-yQ8^Ķ%4ZA;תX&[)@#okOLQ'>2l~ W5Fb~Y'9KXT~ܨNQV%jUh /S$Y銳[{ Jm~gvLs%NECK뫾&wS&{E{Q߀$XUVH6,h[,HPmT,2`Ll)eJ0o<ZSHgL~e!^ >-oP H !Fr ;uڱJ5:EXLi#[3:v)[ 4ݻ/S7z>VIIXOɍIߦds7^_$_x$q X9Мxo"U7jSg2V w=DD~QX{v$ Ytm/f{| 9sY'V˜JĚ@gub?tOd@ZK!T3c[0>s73I5lY7 QYZWUDq"7g=°S QjyG ѝ 96A倝h^h<ds{15ʣ=Ae1à6xp5کpSN섑FrG&Q,zyl%rlhXϖx`RjN(SAJ1ґT􎾬&C ^q2ΰ51`k$NhCb*ގnin['\q"MBDpFyz!uFp?}.G8 -Qt~pS]j&'ȱ mNIXgu)V{炟@n`CC;:fb& Ց^tGk-||099T0ub1z=6(ana4E Yfj➩2(PQg&xPBh䙢0Q(szfȠLmQ Bkuf X\S4 IU%̨e9X@R#n$c-ƻIŤ]F+#&;t,8:hߵF'U J?mCޤ:q`R▿O*UqZrD>R&*ow^jgexO8KFer&k[Z4N^cVgZ_7H=ѭsw5WAQ$ =+ V:Q8@ާw%`d0Dk3SOS4ZK__bxe]fUDuW88d_R[.CCPO,4~~rq [[á,$TU2XE]< :{C&Œ*ѠmEFk; Ss%Z ws= >*l|V]2z=n|O BՈYKְ W) bd.[a8 FW}^;:j-K~^趄EY/yo'3!/@lH98)ږiMK r; >g/3L-z,(M< 1͇.jΥVR3`!-l:߉D5!ӼAVqwZ/s"hkʓJn}@?6N$@9ciِ '釲>] /:+┇(\ Cۏ`I\)[́O>! W[L W-R'!u<:L tȂc>DƯ<ʄ7}빇d7z)Ÿ^1(dNP0=d cVRahH8~h%*o[L7ʙ ,^Ya:ʂHB&WZwym-o$djs)Q$ 1D 0beOy̗xP&T$ި\,ّF.Gy{<%2 2jsZ(C)bmlV8;²/Z۴hbwǞF(Řrgq>Ck$3ƖN /yθ@m/#Nm^TWA,KY Vfk#|V=I +G>rd*ʨb[hW  SFc8ymc6aǝJbc{1û+]Wsgs 踨vv̈q;/M=P_r*![E>;^Njc )Yq﷕z\arA:|OsA 6b-X"SkVpG7>򫡑$GJ|THKC'a̓(k!iO\"?X0sb;鬡Ȏbc[f]<T{3֔.l /{@2o&JL+=X 3M]jXem~'@cr[0[}{!Az i K̯:cw$&mXo_ҜVvB̢dE3MUVknw'Iꬿ"{|;T+_}.٧%-gjQZp,Sշ!=zK C<)I\)`fX@wЉ5Y@'CUhGs3bW(ϻB1!G7Ik K2ƉP*җa=݉# <( р]0M$>?-@ 9\ 8#AIرT2WT{cQiNv@ ޴aajq:tE rɲ]?E6vT^Y% )}Hx¥FD{~'cm+}.H>$ Z%=*~ω I uŸOev3r▴69zCB4p/Aڲ/ZFЌ3-&'$k|}],K,plN8AS4AI.xڃ`2\߼sԳ0A -V<]r^.2 dx83H1 `t`Q^c } `1 @~/qϣ}E^~o~J+4V<{4P.3iam F)$Qqn۬eljaԜܧIwVMY[L^&.C~Io^Ţl Ug~S ԕaCnF`W;x CPdqC&. 8 C?+s31 y-̽^ty׶ɶ9)uTsk_=R Ǡ}ɼ! ietH%y>+p؀Ln_Z iy%@c= -&S=0'V󔭏Lfj,[؀h+s*9mp S'DESlڴO=s6֋B"h28Drr0 LJ6(A+~3\F IW d;eK8mX= FH=Sq 8uns+ bU{w]T~DO,V~9\=jE&~ 7b@g'OW{F㾟n+ɧbWmΏǢ'k\:CD?7(qUL0x݋6b"'@D\{ Yj1Nh)3qjMGxJU!r'W\=#ݙDM75jt2ox܂n[Ers F_A`|tlV n>^˲'-e<<jw{?[ێ G7kdv?ucE2S~7 iyb"-=h(kڀ˜nz WWQ>b8lQlhg8v9 E/cA-TSab^Rgd (o*;D.ҕ/P_aȕ؟~򣶐jQ>" MuW7Rz#Yȼs3O'rzԊL8EXrGYC2bցFMJoGˣxp+ ܢX%c4vaZKm|s8=Die,9JԛfS<FIi`M.fD6L}{=V^gGMdpWMF6JČ"4^w(6I) JD%O_4i K|ζZȬnzhnHrq֥*LXltK zX':^(5Ɯݞñ.Z!U\e5{"K$ՁTuuG Pb?// +;-.?nTnb:hL5@?DE!˹XoDMfzFU KpP]E‘r~ϥu V61ı)UA>Vt)Kd=ʼYXy.¿F|%]NJmMW#o MVl-$v t#Da\Vf܄~﬿sސ16w%O7@I% ~hTW3"ϙB;DplӑQ !8I^kR.RjWIKRiU#qLFEj]ǿ%'v]ݲ-x~NIڶWx:GP{T"#I屌w// X2" *oZ+%l=Vvp*R" L0y`- e I6$PyZT  a?}#xx|Nge^ ༏dL|H85dB~cŸV7ʒQo@8ĺK7A) ezʋq_*ds#!F 6M&fQ`HG&kC! pHL JcboaƺkFM|F%ڛ5GjG.˽5uK Kaח"ؐQtt=.9ɘ~T2(3R͢U?$яfOѽQޙ]vw J;gT/.ΚO|oʯULJ {-P&1C4w kzq+^Rs|MkQewD18[Y\bPz>0074`?*Xiߵh yΨMܽ.WQ!p#O lR}8 =_Yk죂OR.B[Y{J^F5YbSKcީvV? M]O]d6d f4r5+!x= L*QQfE+΍z@i O,A.'RF:[4 W7"jO7>Kxx>΂thHn m09/Osf':v(Y tM`My {F6P 𒃮Pu ;[7cO~8r OJcG۳' 'wDn/4n{֘wԎ(P$ïT:Ju#NkG&w i4M<Ner5[ p4gV ƥZE}m_$ ި`gb9?pC{zN`նbrڐdvA0Jbla* ]Q~TElwٳf=GxzԾK0=*Ө쩴&KDb&%bP>G0dkltsnOٶ72 6zi46ZS2,/ {aqBw3 0fD/ˆ-("vHR`'kT) g0L(zz(@[nI[ &~U܃# %fTY Y֝FㅠJx"dթM}jXopYml&=veNIp"Z$^g:fp&.j 4qinJ]Dp}HgӴ;99!J҅1yYt.@J(kU@lod_ Ĩg,$rj4eb+&oBRCnRB7q^N^YU,ɕ7C(y^LtcSI#b&ܧi(H]z\,ÉN]V <y D:q7F:_X1NIқQ&-*݀(CߌBvʨ+eŅߕU(kZþYዹy?Y;Nf( r8w-%|˫)A˓2 dC[V=Bz5\0ƞ- _ǵ'>2IP!AΖͽ_1Rؾٯ;}VShVZ X߆ }' $aX_f?9w{Z{4/>2 (N=aj`{00ċxJ<{I-0v뇀^jAAk h'*'5ׇN?`6گ (Qp@Z}>^ Ɋn`͖Ep1fZ73W!'Fu~(}6P8R`+诡s8-vwU$*R ÛDr?1U p-=!E6%`F s/]Y 6(e}'n&TxiCS]Or('bi*pP_Iq H5ʦ=uhBK@DLIxI#M ;R%@\)/ĥ}N`) q WJ~sB;VUT5,LsPzUXOY(FwN>^y0b *0ޭ÷FT7'o+lli3hx8*W냵4͝u?P)N_eXl9MM54xm8'dzCh݃|XXbR5ζAi5EQ/@m)'J"0I%GFq9۽A t^%KuC1juǦUKۯx$BBHgdo9o@J$IN F̗ bNĒ3% pH@GMrL(bPh-@pvwH@>\ mZ ځ+T¤5=nrv7_'xCg`Ƀ&uvʔ?݂4yL)EtaI~1dXt*Pp?s_DPOE%Xu1 Ŋ]My:eF@8_H_o M_U6<sip<[G-F eʳ0:.~4 r! ١v^)2NJfR VfD-Ðލ[DКl%KSZϔc 9Z5m$ ˷!$CbS|KԤ/8IJ9<˶{OP * 0@^J~Y]$r6^x3ٚrF0HŽ-f2=*$ Ē`w;gT]F@9Y: l[ꛤW%JhQ=j˭H S6eǾ⼜g݁ux形e\G7A 9Gw>'Q 'ǗP>ݧ0)@t [5Ea!b*tL6ksJϽ0k/{/5W, o=/!0,h l~(*N'B?g=,qj@yf :WI+ܸB6poOb`rsQR1>4ln!K;.C/(qw.lM*iy?BM? 3(:׊>O&50tv2#P^4ٳVp÷+鹕#z}OP ބ bʑ愽um7oI2jS*; 06\Ž⥔O`RIKB`1ynrvk([»P秈#ޯTnpklݞk >:{b@#橷?Xaujm (9WZQ$_b,9~II݆G+הOc:WMV?RlqWYԤZ.Hp>rs{YFQɵ^ t*3qH1 $S": b~Gr&iTp:R>?=$ M(Ȯ\T,$W c%c]v ޹vq]vɚ2dwddH.XX4@,Chfi ^6lN ^5m/ ΌKto4<)P<}R-\- @_eL rIRɽ_SvLDOU/9B0.;jJnC> us8ψ(a4C{ʕx*7AIJiZeksV0c <~PBҡai w'ɯ^ݖr}7#C ̀yX r}N840#YDmE)(f7{TxGj^=|S .HdUa$SUsҰZ'xy [jΰ}SRu1M]|@l7| [Tq Oo4pЍhw| \F|RVlflR/a;3.b}hN6)( مq[Ⅸ&9sCt6)\Dv )vq5QDwKl0L1es4B,'n:C8D́_!ʙ, k?=/=Qgvˇ ows8F^aAP@6U$WT3mN!zsV9.A`d rKM2ǿ˴8bv6H뢦9'6(g GLr/2Jkߓ|Am2d315-pC;Roƿ-AoJ!i#sz5UʥdQiSconp6?b7e& 4pI-amhF7o:(+Bs<# U5+rAX&eE`Nl4նj*@؄[<Ѷ+1sa#ͬcVh:8X@X*0كLÁ/GCf?>*/U;;Z Ŧ: W]i:ueENP_h9㮻GmLYv{7dCVb-UU0Mm|"/\ Vy덢DL'OǓy Ep^6'f7; 1<paO>;bF'9A@QN-z7i6 UTO9A1GF7嘶hn2Q }O^| u|4tm?Sl$E~eH!$a 6T)l~G d8jC>*)jA:d#)tǓ%V\So66vi6w P]OtMaBУWKt/):B1mBQe%Ƴ9>:̕uvf }$,=Vྟ`cc8 fG@F}/}֤RF+ޥŮவ6~'*k2kŃ3|a0Ԣ@=Ad(0ݥrsL RF(6VK=~,"Sr^jMFWU?HЂ] R4?KXGhīMkz At͆gޑv0AcV _N-^ 6&qY²'7ϧ}LӹJp.pWDQ '׼X-UQHQgFtiг;e#܇?@XȒ%AbBhI$,J(,Km#Y$dLe"qtpO$xC}"Rpix15c_ Tx<JE Uq1>" (XzRp"( dut#Nh5 -ޔЃy%4"ޕN.I=~ܒ-(b9aJrۈZtHKqlLl:k+Ңji,Եv𚞝۰\`Y .oI5CERG8pzX82l.bZi̐]Eg>"ֿ}U}]`;)*tTMy σ;V6!^s:.8{Db*쥄_b{6C_"pIrw4AT8+4|6$4uXq+߭tdP]oI}^dg\9i*-֢ޭJ׮_.-lXiη)Ӳq<(#yyYUfD Y@ @='#`"`lcm'6ΏՇ6glL1@AP'AƉH_cApPE4VO]8!g{i-h`ҭ ڥ<1GRWXٍ(q~);i8mf\0ue\;Ukvtk*J梌)mp {h(IE y6/`.S@<6l@p$78ȶ+܂(Or}^0&^+Irk7g@c`'NaJY3v PPKlE aMyHTa,Vj׫R.P:jEhR6ixDJjm1IZ[1Nggzʺ K(_o|?Fa+lczvI$]}'_Tmc7s?M* -_eU|3kar0>&]S:q?3U%K7'S #l l?ƨ4t ʨnO9 h0@u&#y` k/@OD (v.~.!L[1꥞:mA|$ ane֦ؼ_0){rW^ }f@ӱ&SjVD6X^Be[쑏`Tlzz,X, %fÐ{yLw]YRo֢x$1? oE:o\{x?lX`:p'J~ $=)^]YZ/pσz|)7gIK#_֣ B@bx+G tI{t8ErXlj<HN i2=k8w+ ߤIQ|$p}WzO:eÊA"Ն͆76y\~qޟeH~uĴ8m|q݌ DZɜv; `aôD-r#?lɼ/IJ+լB )p< R=.Z=HG{GsVMFP6D aAܢ#bQ(!2c?b05gC/]_ݔ11|ip 'b䢕E=ZV[MhSEQlG!%~xG'kW/" 'Y効6 l(+rs/îyf=0Yi/iq頵tMawzI$IL}R^Ґ: Qڰh )~T1 Bfrv% |B"' Tw`xP&Oa9 S2 ׆*Sxb5'6Zg| {0y;;gc4 14Z61 hlQ><߳R9r I /e}I~#K[#tXѪݹTtT#WyoU>]#oz 'Ҁf( b_33nԼPO2پJRD7I0*i~!ͶM+AKzgQ9 } 1 Ǫa;uvКǩ63 T1'Ev\1\PK 4=*R*#dt絣^ 7ϒc3&j^=RQĭ(b/BVNs>û7y0v1-`ɘJ.6쬯};Ôǝ~>6,{Nv':م7 T&7T{jc*;$<o$[/o}+_6_# {q$0]6l|2%K^$$ò#$&;谌?,`,|+d\OS [m ɨ[Xv {g:/H!2;Y*E} Op{^ֿ.K*>'QvY^f&N$,,P>[Rޯ2C/N<8o@9-o,$[5^Ir;'ȨD#GRn=[5[Ř~zQ~2O8-%2I*'ӯllW xp:a<_b=}aw.NE۩ZC'Y1bfuz"5p%R^3*vNn{  >3=btM?v,yg/Oi  Z. 9}h;HOy(0j5N8Kk8>5QcNU)wFog,im̪S9"Uac#1sFդ&Nҋ G{G&T|"DG|^nf!dL<:<峎/փH(5VOx'3]R D%ZC0rѓ3Ƶgu`A5u>޻1%^ny݅/|DBR4L!/8ǃ6uVg<@HHO,mBЊ;8] }ʊ`9 M1L3.rQa)[?fi h~tja@ -U3蝢RCENlf Nl:W!Wfw4.5A@u7(mgQbfW4єueɴvXŽa?3,"A%Z80Tl^Mfls0,+ dÃ3=̡fn@p{^&`nEك$;N##/yɸYqn&bxXe~1aU ziF.A<\W_I¬3veI@9rPd@dugTR}KޝCM:k BY*'Qƿr)3;l(khZ1Ƭ ֒PFمfǎXglnSzGM]SU\#1A;[Jp* pXCm}8\=ħҕ\!Xw826{#pmwY÷2XFGy ?\#=τCY >lg,}o^ `O~QhoޡKlT5:8 7c%<ٰ>;Uek , 8^d#QpCX;}1?y3xE4em|aT=>#rwv/toz6!Vޭ78+VXF}N0}|*оSuo܇^Tf|=NG4b z1>bj0̩SJ3۪ !jSM~t&SJf1ys_-ZJZh^>*V·[`5"^&n&C4T/ ^.c#l &tl(ewUz4vl7e5s1q ӄr/ m{~76.쭤)K̶!/9 ͈ht:,z Y`B:ra,K#&y]E/F٥Q5\] T̃ +L׏oo6Hz^k|CLAEE}llq97@JrԎH2khQ'%/VIͦSA¤ eMC$~n$*b3].s"lM6e#? f&)}Q4R u;tpv^6XzDY^ڭE{jVNũgK5[&S[)*#MKkq>B+9z*}ﱸOJ*=4KW|lGvNVㄑʜC]"z)!)vJ^AR??vE0,M(Ctd%Oɿm5{ٲ^%J, ]|?]n v%DbC7" &&>{:* eQ'T~_l'q 5,v$(o2=Ksvw_b bddY14 ^u7t+SXECJuJi:(5&A$֭ɍ ސo!щg>RʠZ$L ?ȘI0?m<# Y , YK*u+|ٞ[)-sޱ{А4]ʖk`zj'N=c9k䶱_f+OҮ[ SRaCDu2NAͯ=Z~'!H%  (Uwl!??eȨGH>‘'"˖x[nȻh-ʝtYDG&CǼKY++ F3 V]zǵ??͡nn#'֘-&ohw "R4bԷpoXGK|2(0/398-A6G;kgOĘ= }f6R`CGB׍ᦝ_ ;F#goӘ#/];2XfѱpiB^0PDϽgSU]F+H'Q҈082*fTXM1/v,az҄Iǵc?Vx&;(^ hnaT+mЮ8)~C)n~gt6ţm_j5u*yK=t3$SK-~,؎l.j~t(0 ,V (r?Vz.r&|}Cy(g)is9Rɕ ~))j/ͼwu}v. lbR@",f^IZ\z,fdޕ+n/O{?#vUˍwybnx{6{nT,@/o?&NFzlWۺ!vDC/Xm[q H ZZpg܅}Ddî5sSxG-GeoXph`f |(ZLs=n!㐤*k"P0>xsBfxBY='tCdX}Y!OviV^3^ڰ!Ȱx~Lʧ6$}IlIO-Ӫ9Xǯ t% ~OiePF|$H KtCo>i>1=*`~N ӭsIDuB=s/7^*,.ǿ+6ΉNbeL, ӼXqO3CVz,[%ߘ`i P?cB~q`BRGHM{90 [t{SZ÷2BDs@qYh'.fYq OX1~U|&+,Za6gʘQ:pމ>x(`ljm搚9kۃsXf䤤ʚN?r_w≠ sgz恒` U-*S=˭E\J1gƙgʢN$<K*[~6:E9ߋFv :;V[EF^/61EqEխ儎2EKLߩ. +sa4H]15c3pvA"6D-DN+YDLM/EdNU_el~$=&߉$D0P@[9̃b΍Π81I#Y|fT} Ƙ;PtЧQGϹ `OLX1Ysq 3qx0@TvgHX+ Ak]|?ŋޅg yn4S{72XCJ?(`({%-]cLo{!YX{r&LQ3d6hzֶq1g)oCRb?!u_զ`t65{ 38NLP4Fa8)b>pT[F^5$Ļ9֧Mk%ݷ?-U" `j]sf+_s49Oaf=A=NpKSqr]AoV-*kDok0E+|(ȏm7/d.JT 3 il ujF|zZBQqW}jPܦWw@FfN+dEǙK6?H>TZw_d7zJoiײj0Bٔ_$ƣ|vE"CF)xwHi<PZRPD1Y4D4$v[zplF jy{EVΈ9"6A5LѰH  ^B>H>$Evi-/VÀ}mt |dX2k6pn*wz; qմӪV<ܖ'ɞK\LVػ mSƎ ό<И!uZ) /PX){ &훤`65v6_zx8(G!a2xHE1ZQ5*u %Lyfņ㚰[$/&r/F ,V[:D_ƞ3U?/U odG0>jofHc~US0(dL3"25J9jlag '2/<:V˟e*Cn $&SM:< _vDaoD'3ͣ2*_SNHxĄ dx%[Dhv6ThGһ>r bgHn.4NKj*^FASi P8:CIW꿺?VI`+Q ,s eŅNbxUs>̹(QR {={ɐʧ»HgGdf#xmpoi/~xqt<>7ލЧg6·{Vpi`6!P Jwpd50qx@;7eWy\ "i3\4}q yn1r?4ܹqJݝ&leFQܧޜx)mnek@uaو8*.Tp [5cdoq"Cd0Ze(aQ{q;ĵ. 99Ko,sm=?){']yTk==j(tBvP\5)E2zh>$u!Ca M:U9%W‹ L# Ia1CiGtcW')%a?(?E$3h՘Fϵ$ eqO}b3Jf&TȊƏEq8N-]~ǎՑ" :wU"Yw W0Aܣ`00[Odw]nr/N75O[/bSrtS yԷws_E[ 6`:M6 ӻ ՞^1_yg[z_vDxTuUu!8^ 10i~diK`]>DqpѬ*,Vv"`TU%|UZ`̉-{ Z X[m -˲1]0^q)p[gxX׹.w穡>`Kd9h5FAmC atS{ĆG9T[EVJ/#`RL3'c}ũ Y:'G#yU2>2aiu"B9dg<D"/>@cj-Uѝr[AJfڦS?E^zYr"^xZg#g?vÇj#/'G:pN@3%8a%v9n&Ep6NVzpՠ&ԄY|v&ßVa[OFI<~cS;(y'>oo.)$CZ<:}OLwP~u* !eI3vEٽ|Syvqv J 8Ssbg Zȋ8#V1&$&-׮piG}N"acPbm2ef)(0 XLyģ-Lw:-NhsRqӄF2 a>'){SށW6^jahȫ]&Ρe^:YZݠA֧ z;\5tt%q85ʄgvh^`cC1+w4/4{#B褔n?(ISԝذ+xf͉BLh%8Ap"WSy]XGlc-sn\߫LW&lV~aZJr&wqŝ"t8qw+obh1fof2vcwL2 A _24⸌KS/_0鸰"?fu&j=Ibc#g Oڹ7T5KᴅskZ+jǧK+حҁ`[ Hx!Osۉ'yP¨A™y4Clq*8#X-)eY|"S,3fu޼_^o-hpNp<(k+<2/Xd, 5X  [W&ٳ Q]wQ!BR%Y@t .<~t͙2KJ猁@/wBBAt 2Dov S=q:<+u,N]d6YI$W9L:v(eDDx#>O3 /0Uwhmg'VLUnTpRY\r@#j/vk#?b7;R$A`K)Bl%ka{"[(a)g_eD' XI h<1ŪԈl}{keK"6[ LY&/|+$7 Z&0.DCBAtcO\&9Q;$81rZW j4rCNu.FgHcl$2$ʐb>1\|\4sA#"`ZL.b'W7ΪVB⭤ªUXZE*0XCҺ%/oF9H/ Jꁡ"NN~ɼj9EMtuC?,3Kf cXmʽ+͙ yC^%!Bp*Bί#N(T3U~w;ޛ #̀ oWE່r Y1jꁝuVgf;u5bHxP!!ִZ80@~ʣ23F%kI^!}38CfpOodI89"xZҋƉbXC$-.Hw4D+oo28|IIu (_W B\i82&iN8P!n`R.P;h:} 5}U [HySWv͎8| 1 />#u {r,&qgjh:8 б= X$,48qC57f"6Ʊ]߽#a{n@sYȃ7.}VlvI ik嗖:9z{1Q9 h!U,*]ZPNc%sqIED/e43}K%'PS}6qḷAb~/ iM( vOBciv%I'KGN и0% T}PI"վk0Kn%eA^̴ľd{d.M AkY*&n4H11Ke|8 ~l g9f> WU2A#W=GJO{8r+`P+[e/ ag:pW߼=n; q6 ,nĿi {sY5u@pjCXY?Vt4#]aʬ[ bzιdCΪ:Ֆ,oLZTXN[os v|T*|,Z!!2| U㽅ZW1t'L¹w|Kڦuo9v)WwoJ# U>A, ?:t jRzC+Msa*6A t?*OVQR5[^u#%;v}Uj}]ND;'[Mm('Jp B^'SYgh E!EpMNΉKuOu[G@L ̺nô(`hdthxLʡ62xEvC{nDGc{ߐSZXG.XK9 Vϣf= x^IC.C,%R%!-5yz;ͦ0$. dJQ<4d m4/H ?:& YAUѩyt52j L+h_&YŶly)oa_S!m ǯ1R$ A+x4 QCMMrb0z k=~{߱",1^Gq=d<36*]]4)_cYg7IFXJM`BE2{/Bf[wj'عӔǖ=|: YZ