pki-ca-10.5.16-6.el7_7> H HtxHF^: ?*}}z7de99Q3d ?'"1bd7dc29ad73a3ed0070fd2d752bf275e53fa3e7@^A\6F^: ?*}}F691޷Tg!i&=͋l4;'ƴђm1WoO%>88?(d   D          > D Ldd d ld d nd q dvd}ddLT x , (\8d9P: GXdH]dIc$dXdYd\dd]j,d^bd{efltdu0dv wdxd$Cpki-ca10.5.166.el7_7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.^:nSsl7.fnal.gov$PScientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m L)@1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~-d>Ed,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤^:n2\4>^:n*^:n^:n^:m^:n^:n\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>^:n\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>^:n^:n\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>^:n\4>^:n^:n^:n\4>\4>^:n\4>\4>\4>^:n^:n^:n^:n^:n^:n^:n^:n^:n\4>\4>^:n\4>^:n\4>\4>\4>\4>\4>\4>\4>^:n\4>\4>^:n\4>\4>\4>\4>\4>\4>\4>^:n\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>^:n\4>\4>\4>\4>\4>\4>\4>^:n\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>^:n\4>\4>\4>\4>^:n\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>\4>d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ec1508470143629960235cbdc9b2cff0e0115b3c2b1f7ac4fc0de0eb6bcffdc7b02d78fd73c85cec42ec4c1823cac0c97fec0e80ca98ee88a49c90029c59e4fb20c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.16-6.el7_7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.16-6.el7_73.0.4-14.6.0-14.0-15.2-14.11.3]c@]v>]Z@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.16-6Dogtag Team 10.5.16-5Dogtag Team 10.5.16-4Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1754845 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1750277 - CC: missing audit event for CS acting as TLS client [rhel-7.7.z] (cfu) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1743122 - RHCS-9 CA clone SSL server cert not issued with its custom SAN extension, RHEL-7.6 and HSM [rhel-7.7.z] (edewata) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.16 in RHCS 9.5- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.16-6.el7_7    pki-ca-10.5.16LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.16//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL'ͳ% G;_@ Wg isdʓ`[R8yTQΓ[Џ3ohN5Vx5 Ȳuit0Y yU:ڡR}^-{&3 > }JYU =e}—)xNf8I,IHOD>{5x3Cͩ#K$Ҿ/(wцV g{TD2v:#>롳{8WkM8l]%T7vFJE2m,0|n&GG0!#_ bIXu-莂*h$S+l^JUr#K!{8;Zuf~iB6D*r,R];B"xwPYrS".Ro (7Cx q7 ;^a8ݍEv0h/"aċA=wdc5ZsJM4eA 8BCH%=_KuWԎ0zP-7zKFmضcClj:QC?WVDNcW-7b%_wtu" ,SSFw4yJpU鏸n68yPhit#ːԳ5g[|'ʿq/ 7*MM~e; Omw?>˼ 9xrAԓrw:ڑN4Љhs7f/7 Wav?^yc$ e4 eH)PMpo.7.)iN [1|V{0]MaBodQmg% BwN\#-k3PM'/u?TlMƞ|}o9v|BZ3̤- &\q @T9jXW SWyXwUs 5O(RL]p=|1zhɌ]L ۏE2 >cxg׀L\LʰH2Mh G 7h.vMg=@ms.5ׁ{ 5D5vW-7^0haT;AX/\4E9Xc LTtIs+u=ҊH_1vĔ~Vu б?Y=iUЦs}[c;l !0Ѩ7^ջ"vR+ fPb pݐ+ oCT]HD-s:1׼ZN"yوwL*z%()uu޳i$Q̅a_`\iYxЙ\r`;2vi,u%^blRr# wU( Y0K\jrND/$mqȯo ^BCƼIQ37D2Āvܤz/[i6\漣`F\C]G)!\px;|be5ΝI9)3a$pvՇr%/(0Pˎ&p/˜RY[nO>{R✷i0p&ڱ8a}R eyFSMOrC*,P[0ؠP[Zt5)g/C'pa=빙?DjTzx6EnE-TP!Pz;TuR|w t:%W|<,x*ՙR7zju T?-a|ښ;vj=}CO3g= K vacTX';'Sb.sA!cE /=*#nUf'è嘀|vkp$Vnk>މsÜ`[pjc$aТGJM8m JRߪBĤհ=ⷒ][4ٕE!`j~*\_vYJ>XX%裖UYW e6PҎ灞:*|m|۝k54q{سĂ-a#V9/uVkm&Mp-,j襓 9`^&Cn /F"IN].紌BD3rb{ixsؿ6$%D-i6z٭rx&_dΡ E<@Jˈaw>ﴪ. Z❞j .֎}0v8b2Dmb7fK~+o/yfSSkOp[O/yYҗt'N&AG ~cF}3YyQ@oH3G!.SF;-iтIxJ/Q {ߔZB ؜s6գ Xi!/cz-᝴lJ؊c-|1?tSm#&ijեVͣ21-\Vhŕ@ N#{꘎m,`2Y =ijWN)pҧԡҥP Fhb̖Ixjix4IL2x:NSюf<4tn@bɝ?˃őq$`xͮR,]c}]'OŶş1Vyv΀O&^l<6 1@9</ b_,Iq \Ode!TA8V+|U|΅bY[5 얯0wUu#/pwR ˿ ĊNEhCx1pvHsT#PbLa' lp) _ZS3Jә;h[2s/g0=flGFT3:|DĐ<}3aB1%?2c E]O$~3w&Of48C8mcSߖcګףEn;&8t X98i`&1é,!"j̋_ ar~ f<>u8ᔮPW6pD4=x]`E\rYעoseǺ,o)|mp݉J/?M15NY30>]c#ӗuC[҇*rKSoԋrT8%oK݁=%Ϣ_5b ^Ү=pYZp-) IL=\){&OS*jF,N{[ޞA"K h,W+0P_22@x_%Η%f:APGAc.˷Y?Fh \>1 7XDYY팩ha_IE:U0ҙX'Tcx7j Pԕt)ķд̸Z_C |VTR +6 1{DY,/?qny]sg=GK~ϹWC^NTe +{M)9F$~J 1UԗeG n~UdվM|/)?dk*9 pL}F 5>@vNZ]W%aᯰ ?hfzuq91>~q>yTD16D݂, l dV^]טkzeL(u1#CX@=F٧ X[ߒ뽄?:h]m8@Bc,&lsnJW)\8J͟XX 8K38{tUiB4(]V$4,,(Q³8OrsRC3n|pcSAzCi7ǹ6;F֘Wt#ϩ>]ihXJcZ}:o삚3TDZ)6Z 7-ɧI+e Sw;WwV#﹠>\#$}F[? q8@DdW쮝*H G { C˧ۢĸb(C♘]pgĘgQAF1G6 g1j o+Z,eJ3¤x&BS[ވ3ΪeNQDa{PmaZϽMB7E8D&>JLԨ?t "+ /OQ4U27h,*^F6L8քE7*ɳ2?Mà*Hoif۲![M #\0׼XvdB(xp* R,z׻cYl!MW1V+S {ρ9$c0rqX9֡gx]ͭ<յp͈  i~7s$Ɂ6!GO#܁k"08,TPmSdkzY -H"xoRz!LavYl\iaDztGLB@scXp¶ƝQIZΘ+7fD>ف.ݞ~scTDR.ݚyN&|Inꔲ8CO 9 5jcT|C<}pC%|\ %QZN6 _z}UU`q D-a=OF|zzjle0?|H {D/պ^?geLzj.٬ꄌݤ;*@a"{xIi  ?E=قbJVl.N7lL#ӲiH4I4ޣSM$-".ku%QՈc RJ l+|'7rC᪕J΄z!6(<#js`nf6-O 'ٹypu&myGw>nE77W]#P:dZ- 6=yOK&nzYJ깖0vV .lK1Wƈu$j- &nk 6>tͰ˥vu D>!RDPi`9AޕcZMǖH[TE3 X/MYg{i}1Ʉω^w 9S ,-Um' R(`$ΘroARδzԇ&B.2;YS|fZ%MwԫI 0T3[C:Bl=N!_$3 ^芌x 5^l(8ZRx{,*cbAy7KhIzdzZwUX Qݩ {akTw ]]Eq0VNLo<-΅r +".뀨NJbFE0Zid/ yl᮴gg-,*{ -i^ҚqN NsLrWNv\62PgYi{bl(e.{XAٛ4bqc+ڥ'Ga望dWn c`qr'q'iY1eqȱ~v+SS ^YIc d!Z($2L9DH0oY^/k*C" ;.6= 9ߥ$ #ݤnVh9a!K&_Tk+s=zeS%$HppMX C}Aw<۬C[KG$1H}~ @:OD^]lk2)uq%/a^vVª3H6ĻnսbC |?t#_O ȕוr`UIfrVG6JKz~ ft^Dݘ6.Ps.c3d<.Ҍ:W&~r<(l+ #RBZ,*. zǚMi}[T5&+h mW<٣8̻x #B:|79\C.2BߡYarBP}Usv%ؕKʿ ,nb5k*G9hXe1Z+b-H i-i@>7B`p4wE3uJwzC$/N乩)G62d>bi3>'+a^7pa[t yE=#6QMBf79@{ᦘUKlnx(==ML kVp`슌ㄅaE".) ɂ Tu7Ivߏi!mS>2q+?ͪg}d%lŃdXu} ޟbT [O/]'}k>CԪ\~~S) KI<]/~ƉoD' 0wɏ L|X5&v|KGh'E[膡ڱ \PCk-WǍu)]Ƿ.fxL*Kaۺ)\>8iyJ'NEٙ vdcx .rt(çCx tTmiۦ=@!%nItt,%dL&njob8 .c?Q29ݺC P>=p<_ GlKiP0EzAN?yo۞&uz%&m CYٙ%>̚xeUG5 [\Gܻ1Q`a/?PLl*M>Owsє~Wv@䭉:*&*l O.9 5˄ͯڛD|m~\(w gHKI v3lV`ع?z'Ң-q_C5ACK5]6R@@T2.# }#F[1~97Ȥ-E|@nb$4.TN Q|-d|k1_9B1u]H{6jՆ~+/}%1uNѣ;ݎ/Mi6np HOy]Anѳa53\h+^>qh T YBY5jWFlG/i<OzC,ЀDo28xDZV H ixT: lf uaD|c_ 4ƠN#|Y Ipj`Ќk4x6Z> N{.&*')^#^sHzⅷܴ: G7683Hew J$_dzuB l5z[F467VkdвdvԦr}OocC# hm !&߁bfI[t`CBqGW я}y%1cCI_HFa^؜<%EH܂c.2 N4e p,jNũN]e_JuSwnÏo c~ݒͅ"*>'MrE[(=VG*ˀ;30oԦa麇f?$󷉄?fa(fqg(WғT4|̾ l)KJ,˳5(\ª/"]TЬ),'6SR,}+|Dz:+ƃ-#Ķ;W઱ThXB~K+@CpOCXGqHp=rOp=1vȟBM؝v Ԗ!NhCɠt]'`\@ɚwu\=M}lB#ENocw&l "曗e!e5u'KULݶV?Q\ y%=HД~uH*)81I0m|6@*% D]V%eϽB;)/2Y?U5s%匕uH| KyBC2v/eOwL.N st!VfZZ/_V~6Fr& c$X'F2) Nq]DU,?`s]UK{$Fɷ_VelSԉ/X-Ƭrw 7 ,+(dNLkFy_$̳zEzttc{ʉh.ѡ+)6P ^('s%j-A Fr\FWYhuxZrˊ)mU*7z2`]\7&OpŢ ?f`wTM:ҩwX%E'pזĤI{ڝ$,@e]M8~h)֙,eb` $E;ߕgRX#*,WBw0hh,Bo,@ћKvi½W;-<;=B*R_-ێqH)/naUXЭ$O/k#4eŨG^h4cOx[^YH)`NrK@aTʮZ[?R!g3pxpL ދkU#%^1%F3$AuХ"z O:wv%l]]vZ'u"@]i`tO/]6v\b70‘C&[992͟Csf" CEnxߋ$߽ ۲=~ʚʍU㣱(<4\)m% DђAI#ͬ)jX|1 {~W4/]($kE gw{]SڛA{FA; X7K _@9`uj BNqLwg/مַJ3}z<0 E3PZ6,>Du6^P0{DmU4G˫|:oTB`?$Lx+O r^@dcY0 ̊_V6_Ge,Bɾ]ȈL..VF_H[+7yۥ5D#bCC3,@IeXc*+Rйyi@XP y{6ƍȃef?0& !~%@+ۿ@]iQHj5uh9B(zո'Q۲^8S'5k9WB$-!OO^7Nz8cQ_ mIQ+]PD~ oE閬tgz"rk%dT[?1 wHOZ9lVNjΎD3Pq5G߮d9WW.OL20ⶢ,7`؅J(Nn u-*Zip?cP~]Nk5P4irCm \ܝ&±KyDiL.m6QI@4CTh7w{daבhlDWx[7:=+?|1he Gw-xUhk%gğ;) kufET*Հ\)[,έl>uKs5>=t&$60º6W94=ʂyFڠ}(vBrlja {{3 [ W5;YTľ5ix qq%5ʘ"5z-.^]$E ggXRG %"uFI?)J6$V{NPYTm<`~JUE$kOVi+.cT#}ƒU'_Xclnh '8H!J?ylcbfb咂ݳ[ЦpcseL; x}h: s<[k6&f;YP-1#L-,xL_%#ĮiZy߱,$-GZV1X)#;A&!.f5gb *C%Ke{`m VzB76:*K98Ke>Tn$;{|b.lY*nSZjSEfş㘯]d&R>[gVQnFN0WД s{ߏ$ʦlFF'W{ z7|)-7uMI] YY)'Y(Uj=c6>_ ;a*w(?Ou`[h #LVJ PCdΊsfA*#J#<u2[?M0'7 =44;犎ePl~׆Yw^k1/vAaݎꦝ/mG:+ MLoBpߡ?2Xz!#k<Í@*;]eQse`,]%+ܞf3g4`,'9^ƾ,f6LCI.#ď.e"hpzoe"F]!:T쇎8M;YhBHk4?2 bDrlZ*觽d&Ams?qL $3CoOo&צg.yV|srM-\!j1A\&8EK /5Z%O9!KBOۡMzD|U9>H͢= '{#+(2Ok;֜ɳ8?jGim:C ` 6$/#ظʡ 0hMde` 5T}ϋ"'Q:y^Mpt=QYK!vX>eu&ތ+[鼪()cMvCHN9qp21VYTQSހ.m ԫ[xF eؠW3V \|Q >ߕ& D.Hn$0)4دcJ1v/h7*^kI!$Qq祣'8) 7t,grЂn|ƒdzdlBGy!q+ > !G \*? H补7Տ$S_T\L2m7q ڎf%~q400H/b Royi`{:f%jVIiF B,=׹obȟŸiɴ:FM)t4Ç _Dha{ ˾LJ< bg:';̼B0/B$X1 .ѣ t7ܜ;;n;~BX%wk_X;](?Ad+[(ޖ)0\?Zv]{fhK`IηSGIխdoh?Y`_2.VwpBu)+mAFbyY~i)2(qXE}_Fcj+P$Y;&왌 '胟^e<;Ui1=v]Ǿ-)ZgOS\bk4dE ~ 2"'&.[-e mVD}Z+Ϫ_d^O>]FG.d?5]%'U (˒ x *6AVVH k~sK йu4t ح ۬A/Zi=io-KW ܌&rf3ϓWґ+::8l*Kivړ\OUϤ")9#F\lR0rBC{pF<7) ȸHCjS,t=4b U5<EDTkd6 S%4A˩^rfcm,}ߴI'z:kgÐn3'y"0 ^z_kP@d ]&0vV 2fU=[W^ ;+ S]k.E#'+ɾ;xv}Uq'CU)Ҳ Nf>>*l] ꗵe3ȱ9*bMJwG;Jf>1gOV6Y>6z "UoV.x.yO .>wG}$>G aM Qdo/,9+qT(O@h;:0jW-nKtYTO%-В*ϯC߁x\}D[X T&2]GDdnݽ#bMҌ t' n֭+O5Q#^oHTH'ϝ`ݻ#XXe5X*fBtvUhE&>+iP҂ Oq,kK :s%'C2o 7蜒֊cJ a*6zjaƙd)9j^j dT@v*cCdbTs~A_G1Dk8Z44R:n}}$Ts)/rNK;55 :ǣNV/'בZ &%N<%AS$ܔf;4gMڗHsYJ!6ocSʷt_zYk~K=[|c;&{rV DnoH=[(JU$-QkG}DXv4^TCaeƿ}}v?D|aX|JW0zL'W?g?[ȕYVk,鼪:AZ䚈IlۨE(D~JpER!2 }~XɌ:EH`9mlF87S&'P%kOf3&[o\@#d7l䘙ŧoIBWi|896)GƧ1^!0w5&ҶڧV@J@p RTTFYzUa} &nb#"CI++Oθ$tNY" e;ث'. Kպ`6Љ-`@λ]mtD+ͺ? Eez$Qv_9U0hIG _z1xggc͉ྕsigP\_M?>bƏUxyB#ݬ/Zn->2 }|kjp#׈C(.YE "<^zʧ7kЮ=~,&3s z>ApFw;Rs=]j[_6H&ԚIǵh4@F ^׆8)3Ylڛ^#E3N%XdPC3t@$Sys&"<՝z9YBwk2~'G9GQcܾU٢/y)#QBO`G#+o 0#t*>x=܉X)gq%C=) UN"\\d[xǕqT Tx)S %` m%IOΖC]&<զtH۵bqKaUN{VܴL4jͯ !zO_ea兰PLVЌF)xnuWFrwc,0(c"g? sr NgNcT'*.@M;d%o2eCdFhNN{wWΙx7jacVd3{ŸЮz9 dpF?}wB>oZ|,3˼uDi69z\}\ RN6eǣ#}H/ޠlZR=v:1n(9s|ڗdo{g"rjR8qZtgWn|EX-oI~3N!~Upm̭ U\zc:U2z/f8äc}*R;'nbJBf^]ru`r-:W)5SD eȰ>P"Iv0T%(pa H%񭾟oX0)0ܪ X[?ZYǰ&%WbM5TÝ\"q_}%aTE8,ͤQ%V ۱'YQlHtX)w)D[ y梆BzA.lK Q匱`2a4*@Wj,q(Cyc02סFbf|r0·t2&남o ƣ+XuѦ_# Ƚoxʃf{} j+Lis*j Ekuc}G]Ɉ/YYk96YmNq7L!H۴Gm){ROSl`W* W'뽭1IDžDOç)'aF;K""wp(a_eGI[JG+u@ލDݛf [1/c> fED^hB?+ĉ/:{ѐjTN^g)J{0涜~syX>XG(WWz/p)4qДhB{|(b0쟓WuSN"G9'Z;2V1o MlA>iP*,p9J #铴:}y.Lj3ߗ;MriO@: D/d'%Bc|GSjc->Sp 98|JX36:MkI#Sf&KŘ/w >nbj4\seZ{Ƣ,3(laz _3Yl#hvPsШk!I d+$(D4N0%msYot IMN(\g]rZS" La ҫ`+z)ot'v9lpBeG]LtpϺK'ңx(RNm&afĜxaIPI*wg=Deeh%YB_L$:4uHjr Ig=.EƄ2JQ][c60"<e|vG#ʣ\6ıý|S1\_~ GAABVWx(Fقd6q˦5~5hpX$ۈx;Z,3X`ek*8-#FZ4iU41Ye@n eWD[/!<,-;}~t}%/$X|`$d1%Cj+=1/!yfd[U3wbHU$$C(T[ )+z1{y^ cl%]>'W'DQqz+5gobϨޛ}N^:mDdIf { xSWHӽm$HPd *O{w%&7I脩שAV ɴI*pا̘,Үc673MdXKT2ߢSDuZx$E CevV[QZP{[aQs0_8/,lՉ2\`&^OAa/cG=>H~_L<>ӋWzc)'{"$Sџj-7'ago67[60?ye^Ő YK|%'DFCIgD1>e4ʃ[)xWgmuyJnb۱*֙5hO\!_ےm _He eKAc:Zm lX Z-eHAUɱRN9v>,H+"1Z BG1ZϻGT zz@3s2{id :$rrsvk uPuY+E{ ;ZvO8BZzWAwA<ˠ{H6 B[4 5 5yЁ v5;h  5ˠAd HUΕW;PN8<"SqZ*bn{ʭGU?W7ұ a<+j7D偒V)AJ땊*JK#hotWkI"uNA}r=_SBx6Z54o@ J/D~?cpH3z(j>O%No?fvͥm|ᣀ:Mvq( g| sVk#9ZKYvz8ww`&/bpڑ}pĚt q~P]_d$,&^ }yM,oդ鵈2='cJ;H,{}MY "@<8 x6$꩗<ʻԬHjNԟ '({JpH8={ARdeV1x`?0$_#$YQ¸V~ 3Y1bZTK>_Dj(j#D%Z>J&8iZ$.شA`qcaTGvB ~Hq !;-KK6짗7;sm˿bs,g[SNxjJݢaH!tp`%(,AUV\=׽E ֍n0=V\$g8׳Rs'ooC\zvN>5SjLR$4#ԂaRT6 [z&\Ls*Cɐj[7sT0ǰ *;e[!ңiE~(傰,jU Z%KVҏ _[rh;Qfs(k Z|t^Pؕ#VƐnG083 <%FPaOdYƛ5-ݮ MH3tT~LKGS5}^Mm$rWF߹^{qT'{62th OJ克j;?"b.B" ^YӹjB$ VFܓW)p6%88/pl~zeT=`6.Pe=1ǥ0dA܈.bDCLO]1-(0GK/iN2xj՘^U'yuS%D,\0-@+|f9T$V;Ѕzɉ/1jƕ3? 8VJgݳ0g/ /Ik&x7!7L>^Co=[ʋd|u3"4QJPaYȱŶo BP|+C¿wE8r u9L.j-7LyFMR4#OhgV<ϪoKFDQ qOA/N1^GqM,䡚l`ĦwqEk[Ew &zېa Tߴ[UsDd7|Xa܌ׄb"Yv#G-a\:((I2XD4LN;&"BkxP";o8BPQ75MjÝ|c~">{ỉG^ bؕvr7i+?+7:,HY|wZENqHߔQyEe7feaXLfX=F`3Fa2,b(p!C/q z*>K 6ċ:']< ^])z;X/"BKq@AË]Cv3φ&/ǮGuBC1mCOa_w|"32,Sp,& ViO Ztԋڇ2[ȄbtKd{^ig,};m ꎰ˖ch-({P8R׏~J1TySښuz]nԋMsk]@T4E° ' <"-d~ZnGPWn-Dd,gZDZRox? ;фW2m m;ȨMƣqCRSayK[61x[11#֜>:DZ(kQ!RVP.7䧆O7#Ӊ!ɦNE g`Iׄ ``6g&|*`)+ p` ?iBbt[yHĈmtU=?„uG!5K0e1g h^iuz?qE#No_g^F)6B1Q6jK ۭq2E8u~(y.pW+YFy}d7^ň8>I_ HC )*Nƶg黴3PH#*e71'A$5a5kzV1A@Hcgd+2~僋|k0UFQαl(6\ev fTRo0첯nKDV;JX=힏*?5Iqs5bVTjҡ:;.I 6?*75c$>ڑ(&L*W~<hW؄⤖@Z.'zKl_9_c"E; |ezUJ>c)KBgؿ@]j.:}=萣jPj:m'/O|]*aC\6AS:6*p7=tU:U:v,lw :xak[W|7Ņ!j_4"Bnx@Y恝[oْ+-IV؃%l&sΌ͕~yEx?{V,l\qt9(TMPbQkw+ DVt_LĐ2 :%sS[ 2DrbD?i~]pU\z+~8ֲ@k:]" s'hUŞj(+I"mؕAw HPzehmo̔Z{!IlWoK>* n$Q>z&tss#6-iة5_U#hRX9ϼŹg Vk&`=4.yq>M2x_q1N2!u6Vvۡ-P]I|QeR™MHs}6W*tくa1VmէB3rmJg=<;fѸLio`j)mA'dtV7sɼjxVw=g='0M=vtf畴& ZT2E*[y))WU0p٣ zw˴HJݛki/vyƩdcl>-we{".%Jj`,Vq$DlHJ "l>\nPy5[X0 A4i)2v?z9ꮉ@$Cji"wDb ?U{3osx7~eJ\!tlqIyWT*b' ulWtVai=U$*OO$#|Q`XV#N ^#0`ݙnR`#G L?ohYV dI~@EL=hw0t!_Hi0GU|Lgd.٘T+tLI[ ޡ3{Tbw"uNNC% o:t^gOA.Eot aS"ƻ+$2́k({rߩx+wJk3> 5^x2F  Š `gx0U͗ޤPݤPV&q?+C/rh.:< /.Ej2[WAzt:r/MƺRq,7:`U.g?Ħ$LN]x|%)O!|^mtae@ ,0}H^4S\$'S;O=| xTeOaxx 5j7-g0Hak2Ly,?rS^JCʩ"@^7(pfotR%cB9PNf5Ĵ1| ǁ X$M3697@+}܊o:Lk0HrahtBD\ 7ø#[1jNÙUImL?O!Ǝ"%E23n@ji2e U-2ZY\6  *8,Q.&LehSlY |et^5Bl `>O|ёkt2)oC$hӨbƿSaajÀ^ñ(0 ym)Wž;Nߑ:y۱ZdvEGP&^g;3%Sew3k]8JL.ݨ9͸;H.T^ O`zi|w> t2yqovUvDa:Ö;2&O..٨& ]Ӯ4[lvI$ ؈oDe73N;x3%`Q7qɍd S+01r k60m؃aK}VR!a=YhH0$kofN6 !a~}.aB {CQF*iw?5k5uw|d?~UxB <|0|v}Iu ycV,v:# *><>8˰%+"4_1Iw| B"4[8jT5fDg~&.32hs1~ǹdqˠSaB'!eKVIvK& yǻu_9H5k+ZJ}ЍYs@ ܝyH}Qvhv8Hm%QO&A\ػyjn(B!`zzU팴 qI ig"*fYm&z)?Uv)$&m-“GM$zŖeEr4fWWS*V‘ADA;t?mGGfk0DA?)_kLu)If;|- ^oaR^ ݟ}aT':A <Db|;z厀3@%N@|7L^p-o0V j:Um䊕Km#56ݼXJ%ՉbyN2XgX ϝE4zB zöҠrwޚULCSh'w5q&{ą8P*Yٗ>ZuLcd?kݕo3wQy9BZSݧ;@9;FTO&GО9W tHV;[ʾRǸoPo*pGzET'W3Gp}KSoorOY8n`]h\NBTMpwP_sXV8?`JFC \AnC@a=aն*N> `_kYXINH@ʄMcJM+Mpr(B<2_2k e"XEsZ6m_#jE H2$bMa̾(ة׽U~To_`zrXw`pU#\qtJPD%{|`\L͏/L!e>|[-c"^:9Oٌ&?#5PJ(;³"B\JM0'k#楫 `&c gÑ!C|т6{'.2,[.Ĉf,P2za@p: aBpc#w@2Ma~42۬Le {=#rYbIfCZ'hpj\^^xI9 $^w_vHT4pX@dOs qz ;9oVe+1)eIPyh'Bۺ&(U&ʀ:;PLr>ۥ+u=j6%g!Y̧GNo5zy uY&8Bd +IQ⠼*WD1OakveZAS0[UklWe^vjy;B7k6K{i.AFoͻw4VQpF]֗ѯ|P8 {t1lͬB^p  S ҥ1,Q?@?I׼;h]ߏ$ ;v7mI3x| DCG/2_#S۳Ձ..ze_.^ܖː{r%>#-nY{+d )_tycP1X {HA,P}3XHNpάօ~g,t-֊@k[.7:Dz@G@{^^dW*ak{gFi} *o5y|2~/09+''-l]`|Ξܪ {ܨjG7'2jJ& ׬Ɔnݽ.Dm FLGU &HH rPq`rEjSsk36noGrĢfTݙD}ڟ`ɡQ,G4n@׫/4$ȷ,e l,!H`dpD>;45-'2>%ev#?T#D^xމr敼j_+&_9B:G폲k704y!3|-58xu Q xS~1h/\v7L}[͜ gC4DNi+Klaa7~\/ޑЧWgvQ'FW]DkF}e5XdݻYȣ0Fz}{S%՞)߸Gֲ*4g 2QX)ţ1L7Y|o^l,'G-L5_±K[a7mLD.WV{㡜 Uc>~ӚA索=WG~AR%)H~O`YB텇1#PjE)#LHHjD!b$O$2< 4 c}F`f0M1C16Rħ;I ֧mUnd)zyZU}3S< ddtF3w4'C3ōqq!:iâOr5 DN`DC> 9;dr67,؂l>2 ~RN"A G z0Cv^%9= P ﴼgQk>^Pb%%u(\K?LPk ɘ׆g)|{}䞦KG.B`٭'0炔cf TAoʒ]X2S*]'Ar1R'ѽ=˕*WXV ط׫ت mS1ĬE(f(@DLطZij|iNn`592/k/!9ߺtb eʥ z/kۅaI\ŮM";>^@U~^iPBW,Mس %QFGJʉf^n6B6ҵ_ٸfTI6R/?׌V%1i/sJi+qB#N<}O-z'_#tj9z-+uIrUսϝ4=-pw:.mSZB+MlyNp`5 ;ێ>Nj4\U#lN`JVQ3^쮣Vב# bH-&Zی9H$<9@ 8w :. xlԳs@T 5NO}'8H4so픗'Yd̔+ϯ2v4^E9X) C*Bb ^FǮ E$r l[ 1WNVaWP OJ|",JG= Շq7Gc:x6Pw[Xo -{xs!kku?q0H@'wÅ [1[*vNi/սLL{" &OpQyҭWy7@ȡ[s y@;xQB^; %\;7ȱ4\AѿaJx--C!˫nL}@(QE&!om+Qe\y}ѷY6Ygʹ }> nrqlb˃AUzǼ9u3*,VrΨ6&'y(p *nj%)IJX4N{Fޠo 24XY-%""q-j'ٳ5r#KsASG= 3! 'Mڍ)w?5ۜLcMvBoXAyBXlD.%ĤicŲAvDؒ*E{ MXA[6^*2\luG=~Ҷ3ۂ !f愰ڠB $Z_tFnj31=Is.^'&a& dրKGH\h@'6+-x;jG[dD^,o[wG-wS0rUb= FI3v1p呖Nz|s>lڞucS}V{t.{*5 &aA(rLtQOđt2bN"sW8KngO uho߳5U8m%vTRY%,PLAZ-hRw8pI$(%L`t3r~3Q}jv+B ⮌qa_d(P4NKsW%K/jތ̃-[x3x`-vD |/q}"~Nn%1rG|p]No3T`"Z0ؐ$,m~<iw%֦#qI Gl$V܂\u#ݿ@8lm}8FX^ڷtfJNoth|z$v"]9i(`dM(d[ ]~Ͷ ɯwh??k|ֽbҹa-λ,bGmjY& Ύ$X&s%^µzFecMU1׸NKujdI&@7Gqp eg/ziāQү숡@pf@9 sct~r\ş,&8i[PS߱~nǛq Wss籛h7bEdR{ O fy'^eyhAIBAfXr*o?Ra*o>SOΞZ:ca۵t8+5OgIODZ4P2CtʕtIG5-~1ZB)Zr<^ҽ&v۽NTr(i4v弢bPc/1|\3:*bLyhN T,?Kn ã4"NՒ沖i@RZv]yRu-W.UEwfh@B e4.уt|U">sB<;3uQdݰ\-Y5{sѶvIp뤩 zNm+MG,^*^-n:\=L'gd&#UϦ7 *+4j4?2׬d?,B Ih!ƺNĿw?apL%5˛wVVXoTy; ~8) ndExvA0M-M6^.َi{HENuTV1P.z|VW&@!nM3P:9:tkyÿ"^(U`O > P ☍7P F@tJ}Ƽzz8 gH\riAK_LO'RG0(т,p@WAOf<8B Ju:^eBVBn/-B.ܜ^a{ /"ך>"Rzv Q{A3ogTᑈJbAc6$Ov,~J_WTޚ0Tx^e'L6!ˡL?45UT{7h|<-%gK(n׽KѮM Gf10EZoFnydvy6ٍ2L.6԰ՊӪy7m;Ham)&M:=׸1 {Y_ͱ*~tG[8/z"s&(mp4$){ۦiPE={'C+f~ˑC͏^'mthةGSV K'M)kKƍFθdF|BK&b1S,4_WϪnTڇPP, _ >[ˏX.T&_Iu851"C ~ZER8F2FΫ4~~@Gu"Z4%zeɜyzzm`OM< x4O!]`pR噒M It%P3WYr(ljݏD %;Ɍ;4uaӪ{mIFu`ayTJ jK& {:9?vݣ?|~'Hϴ:cHzus.#֜H7q߻iTGgbՉіQs _0ޒ3UɏS,fwXz@َ[*f7|T}*4v\E*{/AdfZ檸AB=,^P3+V *j(uUhsFXd ;,Js|uhāf$LNYRBYm.KmEr+Kfs|OSm~̓߿5a@ҶPZA,"9ȿbSJi%9<1mA[j`(DOEAl#_^_0y︘]$5G{ԶQjU/=jl,0'-'PȜ0/ah-`hYWO5IB[\.}7RK-kfOMA^!s\Gu|kR*dԭԩQswV(MQGd@'wMDElVuoWxb1#!0Ժ8Z.绻Y #p Ԉ[,so҄,g+Ek_B!Yk?-^UkGpx^gA*:vߞ#F~9nm.DleJ.*)rt [\?Z~]pN  ͝zc0b&+R@+{o% G4bE֨ iᵟW u{i@Ysh A zk)=Z/2֜rSz {I@ܺ.YTJr}#SI Fq5Cb:R (kd2rB_GђVcTcV8˻%+)6"Mե5*)ٹ_V3] t8Z*h  -KM>1q5Qt"HR8KEQ(XŎ.9Xdz͞yydӮ8˦&n1MW0JWvlL\j$jth5?F$/$VՀ3B%CO2R*֋:\. }ͮZi@FJ,=cRFY$o.7#^593Hi23DtF(Xb<V U7f.G0 E6xRX& 0붅0"%gRظsu5+Q5z\sDMqrޖ#ב=rvA@"١R9JWf P|[Q6ѵW5jmهy~}qwziϺ.Sv[v=ӬT+d dLn\$*.+:K'1:ӭCv*P^;ץ,:j'sGMv7IvCy9#ho(v;2Ộ\o>Ÿ@ ~%Z7/|&ż7=KSGP7ӄ/沒6 YSlcIJ R`;:?M= %*o+B!2JKj<.Eqm%y/p#NR ԓsߦ#3I$6s 0^9H]Kc} =Ab!S'˚҉2O/SSy,( ߒoCIU wԅvIՑ,G#1^'a0vZ@oe:%:ݣRI]0wiCI04ǘ!lZfxz!NanԶgց2N!1 Q$F"lͨفYN my+K!nDM3vŪQŒ'G35qm!MPEg GrxA=,G*¥r8`R8KPg(v=MhHQNQ}؜0\j\Xh1ߏL3j@}`=Ax(K](zݖ՛j,m>$I.ݰ5ŤS{ur,]VVP/tgMdBAŞ(_sl< /Pmܗh 2I9 qW -,G [K \ZljMΤ!g: ?AO 9G,ƤZ:B7F i%c"5/ܯJ 'νipErU}j%ay7;'$DFhujPׁGr"7owõ%U 1W4m4>@UPs'>`NNL8%7~V(OD~Fܳ*$Gc\P> U0z^CMt;(ruo+ݧ( ӛ@ rmUAǒ7ڹ%-F"#50,[ήpyo~m  $*dmEˎJRm=9a~%6l/; $8N/NAfs.va^hFTi 8$I kYmD/CDR,,뎌57x+l;A¡LD:[{1dHk|2F2l:mRG#Fd%\\W !.2gn(sꃟ㴳C5y"?l {4/T.#}pz.)2I_]t8l0_!䭼.ZE48~ ++Iq ķ EB>$V,x#0%*a. k|ĖʼntF;3{]aCii.TIcu7J7 a_b&{v#9ƃ_-@|N0]5?LT;KT417XI~ UxX L_h@.U#ac.qWvY3oqOAOB8ً͑#[@2$o|={@u[As*v<`'i>xO߫ƚ.x1^֏#>r`J=_ꬋV^pT-cSτ3YdWC{m¼ F<ĺ5^78 t\|r{.j+4OΛAa#fexoIk4 `9>nU:]C2q.p'ET?h|M5`8c^#  ATG_ d~[]i^ݎ2( $V)(=Ѫ;]M"4`XGoepFPgʺ%ZM/~NajB 8/VIEtKI6!le\CZ;oF-ֿjOvC!]>!w&t"+.tD2ݭu=0{):EѬPvʭnHS({|;QL*-uAsPnΕ.v%*=Bϋxќ)%ľWPcd$ ri[DÅҁO?8 84 UXJbEvE홶<& [Nf9DQ oC1eMV&)[%trR.a pűNY|V`wD !#]BZu2C9Z79RJxŒK }]Szdq F>_}Txw ((.zsH.UHe:zvfX8uNsRwaJҴi\! lT5tUooV3+`'*E2 ?P|Kdq=!r[V-ZzGWT\  m h60hMOAr"P,zN=p1s,T6[;*gW:O_p(clB&_>΢xf/ f(ЗM4'zqjPH !_f+TU/m9v H@^ ܭB<,h N0L4nwo0 U *A,$e\}FHpfoXvhnjl׌jDG(LkM4VËY.ED4,٭w̵?ӛ ZӀ?zM-LgR挹+%=Y{{!'|KkX$AƏE{U:ZEKH3-zӥ&3k, <@ [gYFg1|5S*~q=ފKH"18wyZ9j"+w'mC&5ﲞ( :Ҍˣ9O̟B` 0dJp.va ;xyscަo2Q 't}[R^^:]4éU}0'AKO|9vʮ`@qSaµ'>''NL/vrґմ.t"=vD'adXZs\JJ_I?/+״PUab3sR,sqkQ\uO5 PMފ _p_VhHc4bG Wcg .w&bóg$'hLBND8n2UG8rv1" e݇i='kiugihd@AwXѲUJE5^2YF@RߢH D Q0*)fmPnmZvg/kLJ0b {3.L$|&!Qd˓WmQvL@GN×g2w]JGi/Y7C B6Ԧ7k)Icݣd@K~|K8̶0Օ|4W\a : + 2G̢O³%vb6(a=n_6>Jk˙`T E]~H?o:wIh 1On|(Q_2!m&y{Xld}BtP⍠^T 6) SWk.5R nM:}0j~M'޿(xeHǍ'5[o`* ,1< o$CGZ .g&)T(:./Tere lǧĬ W&Z!&wKjf T*) j :E7hL䇜Кf̦J;!Z<>_3ۇCV RUPD8qY)+:0,u )Ɠu WR:q\i|jSN{Y_+'&]i_!SX*~JIѸI}O @p6Fl)݄HAy /LקI5qmϙUMz&*z \V~R$LtDr_ ~M [J`:ˀ"}{d4vD,Z*[\?ͼhٿ%Nd[eVmΓ;w#'gN?-Ɋ;Ҫ"1p_Y3݀I^|IF4=bp}TĕOxC|s g{a-}4IњZFbݛ!>XpE5֍5-)DF\̚ž%mpr|[4M vZ7r8(xH _S y/oWFq% CD)7G&f.i1"Ixacy'k"©ux{L@TQeL|=.zq;*9 _#0>!g6 L ᄟa3F1 lrO; x0QL6pR62(CWm]ܹ|Խ ]˫ɉiCp]{;n;Y;Os\Gk,'%u$26Hu9Jc&wYj'O|⵫4!a; p Xo6Гt0h E^}M? EbC3Nh% >%T`b̠k=jvRd|zѡ/ M06)m, {_+#dGQ-EM]5(9LL1D:!Cx$a^O@7ȁewYw5^s%Œa{XO":EՎnAT5+' a2Q ;e]18?gֲ[v& auX jEoQtߣU [$Dc}B1fQӿ̅}0wzԛ{2 fF*2f͔e55H7$zHG-3zi>ꛦ#eW`'bs9Wf7鋶#lpv?in:RYb6&9u ipv{ O7Wʼ̘8V)̇It@g"*.:َ;D3gRBs:m9`zvrQٳӪc1L3HHa>\YW~J9dLz/0p(ZRTΛS!O/nj{Vǿ<}=1 !X K؅HJbt`bSjWWOAvK1E~IcESwoX|T4;~ƋRSTR^IoHUV uOU.74ٺ~7w'E%aČң0_jݴYf^gw ^mž0+H7*J98KM>H(7Qia$YDCjr9lC1;,hS[ ˘T)On{O1}WP9,T5NA2t$`P(ؕ Ycu謋hLH@5H`>8slr7rP?`.HL٠?d'<5Wos,@}鱏oEv=T .,_SF9\j"b5fd5Vɟ: *I:]`uX]\a)xV_GQ{C G .,Gpi j0 F%sʇv-Z@ сiCW`IP3t+cɯk˅q8}ɅV»'PKբBf zE 4dnpہ޶7a &,cZ{C R:)XlbJ实*viQ+O_IYR%[:ap_yISY-%VL AM|?YLkvc-;)A)(Ϙ5@FޔnIr;y:fuF]M1Յ@ByTC!﫴y;S﷠%m)(|5cg!֓x(TR[?#(„ȰѽQ e S/E[aM(R`7DK$fՠ"6{ pvs VJnߜ,jۑDs^܂{LgWB^$y^ןfi\R BB OU 8$n~SZѼuY 軍C lbBXYnpӪt0FmTJj.Ne LKu Β$&rZrA:h0rN|b_ow܁nK_ysWWaN1bEH}pJG@Rss|>b/+2!W.0~fF,M@"hc~{ls䮂r)(%%&JCvc}cFbQj?Qa{rcbx*Y5#Jopl^) A,T`,4P/L* cy/[p ^X+֒7cv>!qRtN7@A*6d$[!b~ 4STOpehZFU_$mtZ;7 I]CŤ qCz R/,{9xhd981UKaQKku7,"ЀK|uH.@76lnTwM'j@S Ld9i5'scM&evDZhl=Wݦr-cZ` T7a 3>b~L{D2OnGj 5tSxR &t~$HINԇD:$DGwKVNh!}ΊnpM nH ZF%PkZ/>XHBGZv + XM62Q@duU \;dS=6C^I:ogYW!DsN(^M<{7p6IYW_abiruh`SL‘㾵T4JKQv'h&qM1_סGA"š,i LcB+$T1]@9\w%3 Z̋Xtcǝ Sv8 H@kg'[Z,n {~vX1d4 Yiy7p!qRU0 oDlE4'S햕ҋF*P)՚ m٠\(]L1@3 25h.A~yypN]kTh>OMȯc N04=<K0i%F;5GAz\Ϳ)&GԌ>}5ˋlf*ғ9Bz!J|7OFY=gLb7 |g5MJ{3xHccY~,:/:̟,sXRAsO9YVh"ŅynpV@] w{E+4CϿ*+5bm p*oͼF[x@d㮛U r -)ӏΒܭd& ɅLkZ5Qs9 wnGL. o$:3LDžS{+5OJCB)@ؗBwxƈD2/ސTvyRN%3UKosڤj=?!'h j un ]rWo44G>Б:f f1sVojޞ &{)(!V9``KD٪iaѓ乇\\ECd˾ 2BqcL5s2[E*`noIk]&7M<4hU`nqRrWA!;&%FX iJXznNN<3]pCE-q hhZtFQ[wYB\]G%Y4,G GWioHCFǁbD"޿q:dwhųX՞o[2N*6𤉜B#7*4wLb >!}S&>ܕk$qf\uQy;Ev߯Z~~ej!C>e+_c iJ|!^C&2UE74ieFlsBG+IjJy, b.!Z5x1X/]7琿>I.C{W6.ZMMP8+TL.Vb4 0`z#u,.iT@bgŦx u(8n_5L'#N ^@kUeKx|8Y@v T}onq 8lRh(cIFdĤ8!obCpW3C0n5vSq1њ8ֻ>ՋMB b?V@Sn[/3ٲfYQܐ %#0d?ʢ5Hd8d6o+3˪Qzd\:QL5byeIKMHI8W?o+%4/Jw0iFt b[' FzsU V:"ؔƊdy L!|X*hQ,Ȁ:Qghaρ•gڙ18ۓXD| 2~/acwmv[ZyOoLIA/,W}t̡GM2%w2#z%XCFڮ|"Gde {(TڿS67uܠpWqA(O 뉢bɾQEmo").BHD(s(g3]l9Ee* rMBڎgmbEr(ॶCj,i H־Bf\x'~E CҲ77ltKocƌ njpip/ch5yp*p>t9ڐZJDL9 '#WQ7(p;򄔽㫙!+[+WdAX8!ufNTv0?5uq|w'!NNca}kCz&/YWnv")u9!"5+]WHNHAsq"i_k$?Dugm>x͔r*hhiN{j r@D>*ᯖk5,4=UU>y9 ,BD'exouH&M}dz lLĈW]opB5""d7 V`j+ѱw-@8TqexFջKx rQt5[\Wczw?&ou¼'>g v䄕v 0yIwTmB5汒<7ls/HO\%5(Ъ:F4Ҵ?܊MR 3}.tǿBpXtӻ0O2&ߐ&wxjJ/?񬚥laۜfڧYX t EH*P ''-w̕PgsGk'6}&|ݲ!VqDMzG&4g- * V|; '>>zisZ F'=r # Avy^hb GekRm)r7aW^& -ֱTVhl].SvRD#Ҡ{L?yT/ƙe\ON)M3<%H`E+{G[=^i ~ᘱS'@Hg2}Nct]Z1xw-uO8  #mc{!pKg aqwصtlv:(SBs4YUM_:}sꑖ L`@a}^$=ǸqLrJVgSHq FgG c fe{ݺЄO2#J-~]eH=IZ0DD}'([wIdGl:6D-"T%4؎ 8#_N23o 8E.|eȕ4%C(+Ʉ$C4Tąd%[8S=BZP!c;jq pN:l%W_Hz >ػ2)$Q7ƍW2ɳU`M g#t:W\I^ԉ}5Fg->mJ?|)k͒9B8RQz!> ΰu[n,^_D%o3_@Ipl5ljeZ!Է޴ugyQ&\9Oof"xzmjtn];?:O z5{CHt x*;wܐ QT޻@ߧjǷFr%3s5.$.ͭ-A%$o-VYVїHyLCb>ٮ`!$_AbTF%6,blvsɳ/ 97M)7[ԭgtf\eĘ0 paN4-3^vR^ L/̦rW䖑SU9hn8ԅeG <>rSq(L<>/ E ueoe]=UC =ԣ΍6LS&s;\89X#z$pb쨶dcͥJoVLOcPr {bf=F< a7-ϫGN#/zTxpCW5{zUBos~T /(ѫԓӬ"w1m'MEfj4o-ŃW ʎ8`/^"K=,]OW-ܐ Tzc8Z! >[; 9 z`ea$k\dboni-ģr)6I*j19ESG Ag7μDpp];-9T`LeUfZ&bU}B`F[|#10T_-gmF~1oX2lڈQX8?- (aͿ,RtNLm e!, uLo+(4{.um >Ѷ=Yۤ' F3H\+LȜRU.h9]~6Vy4!L<$hv^6/[GAySnPDEl .\.V*bcQ]ʅ*u1@g^9'M0»Mu)[ҸkG9:oi}_y O!$np^/MZ" %zr>ꉵcbQBRT]$~~#Ms}vR>zg5.D#e'~Vx+O:|"ACZ 34^@]Xx?qD&ViԪ0U{1'4{Q ӧ*9SnosݦCD?Q*F/ UB4D;@rY\(k`mNgTH ˢ1%;io)dE_+.z QDz}?-szh7.GQ~Yinî}g-YF2ʆ#_R2 ZEMt_Y-s%a H77!hKK8gr9T ;H-c zgZdfQNL6&wT}MoN/HڭӒeŢ"T_d}q yЅN8I)@P:M;c35 7^u*Rn*M!3i:E=TtEv3p^ԩvF&jil/]oQC? gJ04 ]/O o=gGlBzT<5g5Y_>Ld_ٴHڙ@pIlk3Sxo6)1IWll,x};hcX2c9@˲;ynظuKD g<ϯhBʗy}һ?j^12 M$jgbN?vҽ$.5^5PόR[@CkqBVD) ^oWJO۸{&f[B||&IJHWuIj3W)3&=th٪ia9H4\ClI%oX׭:mKLܔ4liAaɁ#'EƗTg +E/ek] ^Ptn9u(,r/igd.إVW}ZC^LqéB05: W{*'1msbܡ){t*ITu'o`V@OJ?qlO_Y59SVvf]ӍygK>j_TQE߮"4^j=J#dQ`V3v,m\mE ;&2gPδ>(Ol AZב<4qLO&4Xzυle:dճ$ ZcѪln3iISW,2% eMS:v jA1K+)ţr_48 bk;k9њ`߃9y@!=:}Wy3 Lz\U't.LM /rJ?; NB[mvm P:qCV~@>H.lǶ1-7,瑢k9>ի.;#p]/t6ih>*%Ado`^1~ӈ233iB18&^0yBvsiON{ ?)VЗmD "X]j( u+BǥY* {I$4>NE+6F#[9]N獉ތcp8[kF-oVd"~5~'Њh]N87 Y Fj5=r(`E )|~s"@|~ ri5FX:kJMY>D̽c1qf^1OaE-kdȍ6`d21i>|2D6dyFϛb]$N/lr,SZog矣X[\z0cI9~c9(wN؅LKc&=e4 9.%(֥ѳ=fxn&3'' v i?>(+rc0ĒucCd@8o}53H ݡCnAe`r!Qz8Ws]c;?0tI|p2.|0!AybZc(B}Ad_/(FS_$%& Aۻ?nqʏY9Вa-Po{|o;%iEH^u_oEBW[#G4f靚:w$LUuD1O q̚<{u?[[P^5tJ DZhz]IoWoϠjp_CYP:kmu;szZ"[5N _3Ę֯2•ニUW<#8OW<PUɭS%nj9s*m ZB'|N-/cLڗ9J+SDi W D #H\_ Z X oPj`F@&yXV >pC}Ep{ ãB A`՛sI=e"֊Z x<)Ҫ1a ""vͰ\u=zk 0-=Z4) 8֯l4IھYŻT6G15xO;"쳪kRG /pY6c`w;s9F&(3FG*73?䷗a8$Axv}g3ᡛj≓M3YU; qyA2Yfpު6eY>u[ɻ%v;1 Ag*.e!p@ SʵFZaw4x'mԘVmBZ&*yg AR Uc6ʩg G4Y۶ۜ`uNȆzMZHOjnLOg@3YB§EwbbKW='FդemH԰vW'TMPh3aQ:5s7G9/d.DlێCPx ׀8`HgGVgDlU5YvrigSLuHERr3!N/h9x2w*syVo;c?_AYfL_D/Ҧ0J`ǖndV!!A}LN =WH&U *_AcnY$kn!  \o|}H|$fx~ZZ# ꨭ-YS|_La2h^Am /.Žh+⬣O=W ^iNүwΘS} yu] vmj»WسcN+@~Lo4L%+M.hZ;R퐫N/E ʾMcT ['?|ǰ}Ps;=d'EO6h,ixn8$݁=4|Y4f0xJ9gP4u?\F71(víے%3CVZ[Ass$?xhb(+-aK ~MTXqK+aѴ*cT2[ZM|N@ ?=ʟjgUN2(nirXI*9ץC8H(fE Rlrd9E'hS3[*W%{McY]4b൝vHTkW=44^~kϯ:`8Ėa@{,Nƞ r^tdZܩj*^Nź mx~;υC9؇C{C%ڠ_kiQ+4/=y(Ϙ 1*|&q)-3?lk fa&\xuwUCU7-N)ԗj'dh IH.4A8F^Za#X$IL?YNU(u y7hWs]JDjsŷB 65Hhqq+.t{Y0.x3~(Xم] /®j2Ei*̉+ZWHPKB-~N֙=cvK|V1#ji!E̎ok; 7=im]i3noCM-O6PC!ڰA,`jC e3%zE^ӭ)##kLH*YyREna!Px%b tyaM*TRmi>w[u8nڌ❿MhQZ_vmF3[Y4%GgTNQMS7ljD$<%O vMUghd.:·ىˈvEZ-oE,J,2Pq+sSM,\~wCX۠ެt_ >nۚCFV*?kX;.Rl!P4Juɘ/K6@Ut>:FR/cjty5!0U>oڴH08Fo,[ XjIND$cy)g'K3C< A6@&iXlj.z咇_[ 8$=J;!fg(P-54D5\g(5])nD'F1+M6O՟?JV}̪ҽZHq] Lӳ_0eih!ip%Lͤw Q,k;,?n[?_qHCۇ4QW9';iϲ<g6h2̥UDDZWzɌy3rm-DFv?Ou @6cYi2YJyqɡloLܙz&L#KX`Ł-q0#OVLYi ܺUK_1%훝ZdyJ OhSShO.?E0CB'NфQ^FJ&ӯi4CށE$WVd=7,w(c҉ZF^".LWST@2Qm*Eo`$IhMfõq3YM=NW=Rn ^}4 U/rILlR,TSbwBWKz{[A/wsfYFvRZn5KJĈ#\kstPJ1G1?(w@92]yUgxOsÕYe >aWU(hoLzH;-12{&LCޏԠGLIdםN dމYr6cJ)RTt{7 R0 EA$['+ci6&Yt^ \In2?*bC Ÿm !\@(P?yc |R^gGеhDsk%JP5F|3JAWuU7wƳ3 /yO2-נWg8U!uWWykO}RmZHhǖ%S#C>w,yU P< y>~BW!B}"Dz24, fP PPcq%hvXxž7Py(P553qN(u!5s+S?1")8;V p TP/zx&_M?j@.UFΊ~oazZB#ܕN|'TcM'X*6eX-;ʚqJt<>aIEA͋s+UiW8feoLS5ܪO& G}M"QDT:«JcS*B Ѵ-`€}}\k4lJYU[lt/czxz冏UpJ*1o jOy$>|P]\!5z)1N /DPZҟI&rҚ=~#F2ME<˺@B,`:v[G=vB`ɒq<Kn]%9Ռ▞rQ"P?Ta% lXv釵,ޒ@b|견NDL8|${/Sc?lÜM%Fky;Tbv1<EY5_s9 DS{Lش/ qRK&E>=W1R^C-bi0ןحҴr EGnAL-Q}&()+KE:khG?f_.U`m!; d4 z&k*)Y%>z/cbMxr{+ٴἨsJ8iO|^67vn{u!cf %첡i2)eg߀疙xǷ!p.mG:NOz+ʩyL[aX?IJXm7LC[l+P*-淙(Hh  9 $D(Q׭NpPH̃rܦ9w7]u >%?0J.uCȗ~Я&D'M_v.(ߚtVmīܚ\bK3&dd%9 s?ha}YاDo# Npe?,{h0d-YJ3w r*/tB먹 z%GK棤?u=CG{g0;3QYg`@ 3)Nqa oڢAd{_NGNy:-Zd6Zf{+vET1JٰE5# ұ\Bsˆ l۰ؗ[6'ٽ*=^|:0OZqn6)7*WKӚ9 ot': xE"߰'[µFDJd=J "k8dΡ_#}t 0BR)yˀyaj |uN|[!')!;kBCkx5nղgblgmfcǯxАrvt:Żs#Ƌ~ďUK93mraꏨP͠t:U 5m4δ4\[}%{(u/aen6CرKgԿ?wP&,!s~}t gHC,mNMQO"d+ ;Bpk x}$ъRuGi 3 3P*$RGb BQK FV}Gz8'9ez)GhSsN]tj:J^=O܎TP̊&֎Bw{ÉBK@MYg iYI ˒!O3CI֋dadLdz;T*-IG$`Ksv' z}0 RrO[iS ! xh o;e27\WXΆkb&.! 8ei#K o]H&Ϳw #d FCu[$t^9'0W?7AXz}(R%^& JxOa1\.2e&7} bo2i{zˀlo1O;\ $0`H.ފ4e ;Lx ڔ'95LT A[fȴTڐapjz3J|Cup̌0n-vrx{F;yzd ٟZfF9@5EZ*M!AtSDA :IRffQh KE[TDdFD cUMobD0y() An>g %\'d)覒JY{W#8p׳dJ]4FH}UeUQ#<7mCFdL= s?+˸T"e!83ޤn''Ug뼌-+:Zj}#Jijqx}dHx@tdffW["H\j:r cCWH# @3s9|YM_&ZUEo3h0c#'|?)yT6t0>;%PU*u?Zd{Arj+!/?7r͈qdݠBaJcRNq3?ET ( 2^^{yAS\ȮTxA+wTzƱIcd)0娝 ]0| u0T@yWM/oĄtTYI s\x`k?i%lrip W73* ~aet:=¢5?ޜ3Gu_1 zp^")_ MśW⑚:~`B}WM!J3t$`9LCRN ?>XrY":6DpOZ-;!2Ca6*{›@ mN(F< sϗ^6T3> ͍wx4ϓ>~a_EcHNf!nK"{{T >(+OΉ/ېSdĥV ,u?49siLZ \PMqRK+Ls? 蕋s>A F>NU{.&=o˾ #kʿ>x:gA' vSD\{F\~=c ;K{ %٫cfWBBT>H(^Eej` l{ m>B9 ?d T&Οnu*tIa˗K)QqHhij#w&9,s_,Wv"Dtip']Izs5/R`(TʒFONB3K^+ً_Jԯڢ!W뜸ܜN7ojVÍC[纕M=%mXru;m>=FVWEfѷi:Ɯ'SFۈy]G$ U;7 bnX\-pfP—$%+[WhfaNX#!WaL#9K $yw~: V:BV: 6wOD '%4Tjw"R[Dsrfjwh!l(rrWl(;%ǫQeMh+FXQ9PRh@[ zm8K, 2Z6:@P{Fejhq']s!5_,+Ѝ0)^tNTI,kR=Qd )**IONcٟ̏ $g|#k5/#`-2n:YB A N<P dvVf(fߎ_{nUt!jW9q_ "KZ,%6Su b9;]L8Bkҧ9L((1dF¹[-P8GΛ_dt߯n(/gEHvFr |f.:'ELCOU=cGNr 5?>%viι^|X A G7G%fݣ76\`0Y:HR{xl8S$ 9dSG޹R磧,Wey_Im~vp2DI.&6h5LB;Ƽ%87c~,R0g̔J|kv?瘀&?TʴLl v "!VtfYfΏLzy-uԑFs] /+Y>t&ی#뿘 ?84jr.Ayv_?e:aTcJ6c n{ @glnI ,0㨘m;-ΑLGŹY\$'S?&/$.E]Z0;F"{A4RajzL[6"9,Ow l 6~YxA":V'i޾#Hg(r4n-탕 DwY GcUIekuf$aGl:(҃2) ~p-l.4F9r“w՞J϶anP,<'﫟 ,4)tIB3od-]qJZ`쎏39-Oc;GOik׻1V $BmSTA׺TR;mc =\"Lw #UY:!E0!1m(j*]AiZ&@qrbar7ᰤ>j xHAIhEg5j L.S+w%pUgWI',1)^t'o#*)6>]HcJR Ey#1ddji(E SbI(j֯Glj;B4g{ڊ$գ<>㽦aPInU/srkl,Ec7'hwg W& {DgR:ԟW$O+\cSB0>}ACa3<wqÛ.ueRǯ)Рo,.׮Н4Z[A:*;D=# 6_XPp<%Cq53pO-,APU=!UZ|2<8LNb4#z[& ^9xpf^dIUTn?G]vWs4r*Q$,~b|bIY^?mgMUlӥp%{"WCM#eJ*&>N6Zh?cZ  m"nlT 9wb69ܗKWʟi2dY1^V)R0l}%y[OE'cEՊH_a#3!de*PNDs)4H沘 28]R'4W oqR^秊 B[#~F}!]~#vP3*&9F0F} HEnk9g=aOO, QjG2 &W\Ù)} V!eS fxگ_õx6|aEW, 9]cE>=4B*%΂P׏ո~'݂oYĘ)WWQaCՖΘa9n#>L ,pC:܌cvژKNWUje`㶂pB˻cFШƻz2} Ngว6rDzUNU&B "PO`A:p=kO][kG85'̆SĆ Mn@'u9KTէ>diOxqL V2wd Ǩ*Ku_ SLk8pH61tV 0sXۦύDlcj)f-DmoQ^x:~Brуl A:Ԟ81%e3,թ2%3fƺ NjWz?.WPUJ 0p@g^C'Uh*fjr4icY0*P9ҷe/Q{MJ R#Ս]=_uz_1}+%+ϴ'ǿK7w:TMtgx>ơJ_з$2l~@Uv+z5$sH[=Mp&bp# fv1ee1ݙzzK:5ُeGxa  @i3tg!)l:g= ەW4_BUfw'%TH\9[cƋllG |Z*W4.W¸%D p'!4\6(GȀ QuT/T_סHoVCZGEX魩cc]!GpJ̇xSTg~6Od ^πK5yg58<畲#T,IJ4{Gj͈\X)eZSI ?\IxQ5СPKzxczdZ br %AȠZ5A:NN l},6A-z16cc Hw%3Fo|b- u,xIq0:(ov8η'b!Oם!],ѹU645⒘UBon@,4,2CRŪ3=!YƜ%"0TX4zp@v8x?{i a͵==旵)/ai"]IE.)r2O<tޠkk=O$1)^K^m|RۂA&wo^&%V7nl DI6u7=/,Q %(|2IK܈:0XRu.J{2e)n}F~E,bi {UMAQiuwI>B煪rdgۿMl'}t/vH}-j8Scx4K~(}wG4tFFe0毊šM@,[adGNGT%nsF_ ub=A֗I?VGѠ\ЭƔ0_NuM"%-q{0?Ey9 #Ta aZ]u>7ôY1U TA5Ѿ|XI @$5bǘwzD^Ӡ3(C[b WUOjB)naU)ТIV\'Q-Zmo"m$X*72FIkQ9U~ܖfȌgYk|<-a7(rWUOԢYyˏY#5ǎB!& )(N3h `Ɯ{>{]0,;ʃ)n&vfgüˈ\۸?&K w\jH_>lټ75)K3L1r.MV~ж*)1i"T¹҈NE&n3qS=jPxƞVNTF;_LdBd/1*y)^{'K8AzA(/T1]m6F&iCֻBf`ju鴱voMhvW;Yu}>o\ NH PdI: -H[]+xmY 2i?={ͮv 3y{"Z$b̤|J>P,A"Bjt ?OB6e6MsXV]6{:rr>샢7"是J_d^?ngȪ[=߬-6RaH6{)S Z aCKmhq^o!24. TQă@L[ ,D5^Y bs_KD;0sh8vF2#dD a"H)NcBA/b#2n44CY*#S˪:L-sV"F pqu=XlZE˪"@t+"Vp +!N*e>꒪gy9ۀg7p$P5{ʌv^!D&-E~f2%h:8u pj)xێ=IvKI=G`J}m.c nM+}yR᛿̄ x4OrrK,]GSnYFrR3aH_ Vm>3HZSe ~gţ1ZA:CAc~QE2g5SǕ/m"7JSk]+0H”7+:U7eu>C Xp/ܣ%{}!joa_PB *Bch5DFA)aLcf"6d#I@/y޹XzDuOETr;3 }*fa V*QjsuD_qn,/E˔Vc+lms ,CK*A\,,@p|j9>9י St+j )y6kXܴixݓwO1wD`d^]dDCZ]ݬyk܉S#Yw٣UH+n ѽ\w̤jFv4rG~FE"xJ\Xy[?~ INŎp6}C~ye6F I3ysbdc~8E:sr8bm;x 3Ыd%}-6)3\v rZtu 5 9#>$P}*!O j0ӉEo.&".4D@nazp=]l֐BYmWr`YcDW As$W1)OU/4 z' l* &;SRE94 ,ǏG~5fOd>!1H{$0zcL-\ `3SByQPOI>nO_xKgҁwAbAN}"2S“mGÕ^" djWüɿI\g}Fj[FK:t `ߥw3NhH>Kh|*f N$ ?<"FK[Y[ig2$^w ;fj.g߭vMCOwja<ߴamvf: gF/9yJ83\aUDv݅⫽sBu#t+N\̠*%;;i1$_%"5t|A7l ؗ'7 ) tsHe]E7?^}LʜʒKhRP.;ec|(60ZײbgwwKƵlpBqߞ7C? /O mGA+(E EIɸKrU$Hn She_&ES)DsHO j#3 K*H0/IZ-ZqzZ،rlh mOA!dΛ!R۷GgS CU4Mٟ Q`Ψ|L}3gdANa}Y*U :g٦LAsk5fnJ}`az^ [S!D(Ցp_/Y=tԮo%Lmr+ qƴԯrؠJr(!cN526EN@"+*;$Oe8eY-ݞMؿ@ɕ;(Ln_[Ns8@4ۙ7+)iw;t$dڃaXb5A,)hmI&{վtŞ*f25)&inRY(Ϙ[pEe/DnLt<٤,pd{hJ0l^W XL~}%~݉u@{~]?{AkC K-ZDUHZe-VY0:LPXsAiWcK{TB\NJ՚ƶ/%0E7= -9f`hqmC.S)̯XZ~>Hee*7wE_ef&ڕ  2'i{-LXY[d1ה_;_(VKTG^VR)@ KdI%~IOlL\b^joOj\ʠ[g_Ӡ3I0 ҆"^r@G]qlGV](-sI٢w u\]co Ja0pR֡ofmTT߶G*^MTOd@Z^)]j$!fTٲ1XfC⯤pN繀huA<VҶY.{ux`r<".R)C/ 9_T 8މf||L #d_wtxzKlC!']Jf2WN]nh2-&a0!ؘ\)f[PStJ r#j|AayݧMb\¦~m Sq xsƌP)"Aw4G xX8: &Ѡ0ƃxB7S%) y3l&O*/%w~1iYCeg]P3L+c\ }$_ḩ_f",0~Dڒ#za´U9SqWEFظHӗ7{aQ3ݖ_tҀEƤM\/Ȧ y̰@ͣbܶx(y1hY,x-.t~*qlp-p``\ur9v;Pw {±:n1-TBc5"*OO:4,K}$4_K| @%n֚ٝBԮT6+[1Yq!t+{\bUZӃcL/9[SA&TB_Ԝ@=3k-,|h?{I.DSUUl{w`}W(5{l ъ]ުNH5%<+'|_n߂#j"þ\}M,p/$$7ݽ^4bSͩJb,(՞6n`ouVy]ƺidz>Jw˔g#d9Vއõl!V>huUl~=~67I= Ʃe޺jз@1{AozJOq֞tԅ;Z ; D_+fiOJ%ơiC{ ӏfȅ>->n}bSOsu]WL_Vj6SHG5іo.5'O{US_cEީ 3B:vVK_| nsfN95aJC v2q­684z@R'`nU!63geEOkwMҎ)M/0DX9jNx|0 1uU)1y%-8NMzw.H)f[B%/y]pbxТ _}1hJuR4)=ٌx͆'ϰ4߲Iޝ/%#-7氾8-azTϹ,Q2CwH]^pDHZbKk-a(&1=^Y(M櫌rR&T 55W>`PuE<5hKYn칂Q$`kzA4L٧GZ鍯үNO>= `c>fp<`Nm{?ziV,)a wZ`ݻ2oɎ#)RT/l'b:>DLԦL[ .Th@MKNE/7w'3+pI3ɮ}Č&i0Ӊ1\G$xF{'2uӔLQ( Q//,x\ >=.MA IXxҰ7ovt-6TԤkvJiL #gFն*'[]<;bjRct5gq4O *kJڃTƟLQ̽ϫ y39y:3..B_~:.\6>'QU9|aNLi-r3% !Sޝn8+DF.7c|Cv;N^mp)~hHE\Xcj sگQ}D聲_} =#ypq٩CL6xLB2755NՎdkŠݿ[[7:Ny (8ڥ4B  捸KrHmY:$fìEuڕIʋ/O/l3}Q, Hچ)|^xZ+u{͕uXPw=T?#;Ipe*-Ѣ9g0Cn|dlQ&sRQA|OUtM~pO56\AZF:~]svO7cpԭ2΄=tA}e1^Zo7e: rȅψ_$5Q"m3Wng f} < cm~G1}t9'| YzRYfhKQhl$NpvPp&>>  2zm/^X=PZWB'Ǡ:gSÙ/KJ'|_p옹}1 ,y9-H`cl\^33yΓg/|' &BfVsP]`+ND=jq* iGG%Z,1"Ē@)h ĪjVLg )Rg{Xl/)Wfk*U7Y$Uc7դ<˯~jur줬[Gp BEXp~N7%0 74](LX|pT^?L_Pstf60R.o[ARwVIRS$ vX5r)u;n[1Y[E_Ϡu?8,qLj.v xzA_>Gîԙ> 16 eEQ!9QZ=PCVٟQm v%ja-xV@HLBr'H$j imA7nZgg!miO. P@p{[&L\G5_TJT6 OH`"s(8G۹{+Phn*z(D챒c?e T(F}2pW;e.NjIX6n180JQq# ?Qk~,2:t>Cۈ#=F#wA.894iehWye@c> 46yF#L5&.G}B`)DwȢu >2]ncQ\6MqM$T i ?֐ 7me3X/A؈QB}lc- :.4(!pO~0@B}9چdt%kqǪ6Jt_#\6yQ?c8:08iδ60 9D]GN31?6 X^E5[T6ؠ1=t=8L B3h"./ecC7P{>]~(zִJ}xslb%88C+:A5~D7UjBU|&IͼFBllNRY; !Fܣ(8+CdwũGhE+qe刻KM7߉غ 7yćb,w\p;Xw ESI(ȋʟ$ӷ+Ql8 y]wܗ1%;DyqDATHXiKRZ۴ L,TN1UI]ӚP]UqfE|YJB|C -$|h?i(Wf*2S÷ܨ+v!ƓE~2{W/֩ ,A=-S`x n^Kpm:G3~I1MO?jZk;?:0rFDS? 0jӏcϾ] v.w\d7{tˠ4B0f"/C?ՠ@J7Ɏx=61m( b%zJqTIl 370x_sxjS0hg➌b *#9{FV p{+aSA6A_V5W)t^*Pfن^aE;A"[׋k@'QR{0Q# aviUwՑI`?^tկY&{ToD4uDbb))FAz&HR bGCw VAiGf׬ybn̎(W+33ݫ54itS!65!ѿT]j11 nvҚhpɝu=)GPRMy] )Ds~%dIH:=N0 I20N/{T̀`+7ԷZ$$jy$.Ihە «_ 8-B$Uaί^>RhG*xĹ9p3b\ ld+d6{9e2qc[VLND[ F$?0 FL◦؞PX =#d4B ztQ d E?}ġ(mGL,ī#Qoid3i§䨷Z|sxnm $ydH>JpNTrg l ysFG~=qx[ϴӀ5)ogk'V&a_]B[堎Zb "!#~7PoJ\*؎x\Xڶ®CPGH^x976 ?GY2dz0N r#L[VM(e͞M홽;T^'6 ۭ|8.2\@YNS?_j 9fRC/uIHZQVv6ВFWHX4afdPnO$YϷ'r&& (9Yɛ'z) 4c3,2[$#mDǏ4ф T8g4-@R;7A(Y%s{SJ5qn󯪼WKyM* T^'?Ln>;,XӐ5e@ Iz b,ޟV`3Ąᶰk%`Ujbj2.Ձ<M[^+xL8CpF ceR4]fג*q)C0yx1O wŪ<0l3.>xdˍSu>]kQn"L$V }([vȚ7MXMѥQi포 n?75~@8@{tXlkʠ˦֟YE?2QQ{silp6/ ӑ*% C r/wjQnoX|T_$}Ǹ`BDMAC(^Qcj)Vdϋ1(Y>θ% y`+W8ӥ+~&"UAI)H2x73O$u-0AAnaVyA?ø06Xrcq=#ǿR*yGx}wq<-rHAbթE,.߆k%:xHHllG_"V[`xmd+>4ai؄fMord FYȏ& ژmł[fpNXSsONah~>JNC _L~DT7|4|dGn@qSVt fEÎO6fUs\1)>q9C{)K;HP5=Bp !U%&89^gCGN" -d~cé"<<3R8'̕|jHxGZDn)F'R@ȋ{zʀ*_ !Blcs)aU ͮ,@#plLk47Zj6%_ {K2[JSFGoo;x^^-fyv'fh+-Cͦ(pGb2᎙Eu$ jωaP1ZoO=5Q2!avзQ ŜGR1G[q$7@ _ќb4X[ W%EVz]8Dp幒gvn!a:WKe24_ ǸH㴵(ZW/oIR=Ey[dA l(,%W;#/U:]ӎ,BYNqژ`_<="i~t^H#F;C)p'+'|CXaK#C~>N nm]9D%9+I84g\Ҫ=om!n}7P= *ljNU=xv}#T´f{!Xsm(`i%DЅ(0=s]@Cƚi2uR7}:|*ٶ<&g{GFr w?r;f8&6P׸29.wZSԊDl? wBeS >WW mx;OMT<:/Uf izUPBwq,nِ:ؠ ~ݰr0Ŀ]g}ȀE0\#'4EV}wNe[dlrWh8,~ե Vc^$=Tu2`K\ٕH'==R'q9En8ŮB1!0CԵ\gPfXGhpTicVfk~9!Mi6]=K[(P37Q-Hr2u"Uv#dkQ,=/uؽۑcCM ]L+v]PW7]jb>64k=9 jZɄaUsr[O\ 5+_oV%LzoQd :aϭݘ/BpڱصIzb `l2)ƽ ~yHGf +#&ҥuXʩ)n=%Lb@Ab ?)4K8ku*WRr]U|?7-h\Km ri68o%zre]GPnJ0&1ocBÒl6|(Ǯ|Qɳ+ yZ&lbyC-ܭ'1^Z頖[=ޥd0tc|J;Bl/m^a#-Ylej16{w;+voU>-{ L ž1{1kі}Az"EeXF%MD+y4Y0]*ҖVVhd,-:=k;q)$PucN%TV~#OK`ԌK;IX]ȘpE؃;~]Bש{,VOd I3K/y^,* /PDF 3Qvz`m- }|p..֕C|ao"8hÖ#* {:n2EW0sPx;7ru[M?iDJaW~aܤH9̭:/us8[X=bCB݆ME[ȸHJ߽]c^`W'.zJvEq^S&Boύ͏1CL(wR|hB)CCI#ڨ|jfŃZ f$]Vz|0PT,T Ɯ ՘c,8 Qp?HrBkx'|i_ qTfЉ* md(!yrMn$ e7ݩ6<,7H)Á>>l~ 5$_DhW:*8~"uZ7* OS%­1ƀ68N!KHR}"ӤHg% ɜqAn'mwrk9 dp6hVa8dŲy*L1VT)r%IOQ]9ݝnUNrW]`dCU=$cNm){‘zvP#] wcc@ؽD8|ȸ@YҋXǎ$!c#r"!ƣ TXQi8vœsw6LE)ُ#U[F0!`gf"(ҧ}82C VT*'(Up[ZXk ܣO~((x"~IV)|2J=xkT=6W]3Hz WadF)Jҳ̈́H-0H֡ 8[>d$% O2aJw5$N+=pifw46z d#M x^S7 -7:׸Q69ڀ/#N ADm\c#8Ցw)ƾXN`+ sV,G!j O4RkmUWKfoR~*?K1ՙi2멤4SNT̒pcK_ΝbP\K c=GLgZhMM<_#7"(4Omj34l!u U SaƠ,SnPˢ',00_m2)Gu)vQ=:^HqCْJz?a)NG圔19'yV!gIRQyr]|b~'lSpԟaYH z?{)+l NOxc!ya <}/EҨ sЗ.HM>DYxxLSKZ[q |ǛL&hUnq&q kk*a:<ɞܖxrϒxF5~fN*_mvzWNcFl85hS=}VvMaK!Pڻ6qO6.|"!l. -ug (d'fV%5z9G$@%a?NZ9fXco pk9dnwx$Čx VLpG$2k坉1פup.v~V&UX~|X-3.hD鸪Yj#E|Ǡ]̄ ٤1x_: vKZMg#k\qDB&r}<{ [s}A:= ˜-#-ٹoEG^2h[+RƼKMsɹL΁9tޓ4fQ΀_9qzjs=e}t}7>:2Tcjg!Q!v>u$x^7:gWFԭ9ђV^2,U|'"E}.ⷵGVl,lCO6?|408p.Zj%jCWd憆ǮRA^d;58+%aX=\@^%KvbmsI~y-,NW{|{8ʸ<#[4,㤖- q<~\\Вq(i)Xe߲h%Jo} sFY% z80 R72Fn1?SXL8?p׸Yxe5Xӻ"G?9Q?{ͬzc&, o% f6<.'vMy„zX8ϢQ-%@f8% Bj9(*#L/*V|y~YI ڨE9Ǩ` [9sƹg;j- ~z _%~s_qecKqdGR5f75@u[3GM G?1zFCg(QrhRcBB\g[u+Q/d)b+L0QjiGA^.U(wB9:(?-NJkDիlV`7c1`%\=5AՋajh}TaØ0C݌u Ttt?O6&U]N3~q ܺ &ia:/6 ފa-1H"=O)VnW<,~imv~@{yv Q4tQ bMߊK;Ĝ5ɤO~ H>СSZ>;Z26#tWKɄTusۈQcRLgkË)^QjygI߮:SSr.EޤO<7F*R} 3 "y>T}, -dZi(CI~'t}Ks<>Ʈcwv&/)l]vc3N.`pOGݣpXσ- @ heS5 h"3uP[c;×ҦZEZ6 ׾8nmg)cl]-zP- ļK2!z]`ĉzBhHɴL;ܻZ $@!P>έ)vNk8VyH@[%KL9Q[殅e} {ځqR*:]ȴxo%oӄY.h#8^D6@3& c'R#kc,~7修O&c{  ߙ-"x--,ALMMVvFNaw}8pvF5_ܞ?i~ ۻj@iY#>Mد<3 QX6]:EEgSJ4 Ct;YG9y|3v`mLnJ4s3>`M 2L+2]q1*\_34BG$X @(LXBl W&YaJXTH*Yl2NiXPy6\:yHx8ثOh;w6L1Nk5ٲldƹ~T9{盁)x(*"x.(Zf^Ww}+N"@ůo2ݾ+\s1HK؇!.YcBټ׳uR{HϜ䞙>> G=ejHp=dbh"YV_I_UeYNaf0޶%ל^S Dvm"3 $73 (fvQbob0P|-.vEpAv }wǡ2t;PX8}" jr4(o-NIn9`P@z8kYKcL-)=m6dí7g\:o<!ƒ^>ꘄ,4s#M$ DMJ]ŦXײN2EsQZ_FVD hrMat+% f-\Kْ*SOONصJPJ(h-[Hȶ}i>($tE3.+ٱT%_LRs@*W]E>qb! FQs5v!>VzHN)~r֤{QHaxJm ` O2[!OI,pRr?\LҊj#$ e >;49~`@HFs<E.ZĜҦNAfɌ@f/ =)[ޟu.|f7׌<>axHd?Np4*T9HyO%KSgd%{v]%y*$LeCR AɷTJ\.3ItY}/VҾ1$szuڿ"Jbh1AȫP1Nm/3~99_nhIwZLcτ4׼o5':dG37Rx7e_@VU{@q%WJz$Q oj5dI ,y\RH֣ X @VPO& ]Ylyeu 0˲d &E,+vpE {-LhFXy`\W|JH %K\8J[D YtZa5,^"51+|{/Ezᏹ ߼@eoԜ'fkͮ6ʺL]TXn "ndz86+t3Ek1 qAZ)|4J2lss_a6]`< /+{%P];VX7}4Vf.֧2 BȻYrS=@߱(dgчsfzbԓ=Vz%71Ti&!^w]TƸ5e SÛ[2avU^4kXonT,t1@`IEe \?~^L ="@7diS,(~tY^  A$nB!]& px7(_WK #Į(~V i6i`(:Uk=" W珆F0p tꈛ/fNr|-k kJ"yDUj&ߠyڲMꃴ'_/&[nBB=H$J!G{yӲ<1-BDeKb'(EC`Ey"5xԌ0=pe3eI&́CeGˇ&;s)(_ͣOqM\B]H &@,:)@x(?* 8hC(fbDPb.nW g=d > e J cyPQPKt!lrj 씫ҀTQa 6Zm splzxVu pp}[gvE_Rηe94KxZI'zt'@ZpMEFY\K?[ncշ B9h 99g-Ә<fп@j +@lNaх&6}c1N:( 3vp˽0mMhb*w2x9sSznCj(yNA7;sX~rޓ"c<[c7cu.ʣYf ~ɺ렋\O(񖟡=Tt hh5OafLM"(ӭ|}>;EKn`NeU/!U4rzC$ڽ,'bdX2J4?'J:֩^HUU7OI*{ GF `hӼyY$Zon <{lq~tŸ_&`a>͟{)efFjVLOYOQ Vz:`7[.+N7~pbQ!_eXnn_6UDh0Ѵ sKC"Lwԟ-WǴS6]2 ̄^Yr%*ZDIy~7s$Aִ0 [U~5lSGQ4h =6ʲ61V/dא~3WjkpOxs$cގUT;ZƂw[jl%v>IS Ob?g Hc@8L]aQ;uKWŵ=̻Νf_mU=#ŅW8mݔ5f2Z`PKU Oyf=CPa55;EV?$vc]$*ICrB[p-خN͸B..i\叿$RTXq1u\Z &a//S^}WcDO*)菁ohBMQٷãlӌ#!n{N5)R۬h=h{S 1zo^FY~rmʎ`+:V?|L'L;e!PՎ tJ ..]}$&88$^ ̅b|$IwKF^ 湴z:Cc]qO5으ItL1 z UO w< ghμ]F %7ỉY+@P'eR6*̍dyg:úlU,XRi2 ­BWaSBCw>1"bF4N6}lb\(Z|0K/dƘ3Aw&ŏyPH)Њ |tRJww?vs =y7Q{n @~e0JI: 5öCOuiv-çHhE4ʡqd6TQ^k̥3tR-cTJ3G꣭b7gWp\AER'}pjf!B?l.MX]]) MOou\A5 p&r~գ%i6M!;*#g4RŸ2¯B -Y-tuPtV6>;]qr7 =B;/# si65R=ɰP'Ӗu"SPs|݉y˟=a c{4Z\xWxQ"!gx \3}lC?r +/ 6 4Yĭ ^RŠ1 Sdȩ6ۃA˅8Ψ:΍N._.9 +dڝ^{P #ڋ,ԱxYk%ZXRH+6"`Ch\sCo d2AT{e?8XrWS^6'% _WB}|Wlв@GSz \UyRlrsTަ[&D4[f(ޠ%X_pVL05.~HOMeIrďN80i\4H6WjåM_ 8'C8omZw6Y뮷Yf8wtY]ϥNz?sq7 x#VhP LhjY+ϐ T)ϳY;4lثH1z%5mzR6Tw];x@TvJm HO?Ԇ ( HEuR>uy^_c W8RS  <X`M0CE"_u30qbFqkbRhS\(zƚlD}-] rI ~>>ZbݭZj}✂`ukIR%)'jlF?Ͼn"`f 4!qrv4`vI6.D>oP3_xUH׶H'9BE8c7jS!6_r]ǪibO]bM?VU]T*|A|enPސjc*=d{Sj!L34)69gOJI^{'aޯb c3Q"!T19 [¡TUtsX͋_M\S<65SXRP'ޅ[v%=;KN @bogb>P 53_ ,!Svݳ=LJdXtL 7_S(Ǽv2* ;7yfo 55R\MzIy~DK&Gd)^F-,u$*AR7/sw_3td!:x+Mr+ nԻ 6dZ!MG*,j֜+;P2a,)TC:X}al]Ҥ78){iNs/0Mp:C?>w&U S 全 a>5 #$H]ӛHb7ս$eX@cHnkr>D6i)C8+Ի&0-1#[Y!*,+Zm"0al 81䨗~dLf UsXd}]nዟ(<GK}{D?5N|ȏŁUEa9҄LBe Oq&b3OQIbU|WnՈ}t5fV H*\H-te4 xntU~~!#h"@f7wV5lJzTԒnn=y~('`Fw \,3KEG|8+* G2H9"/[fzm~ $ri'h:xqě6N֘CϾ55eZ[(/> }d>1԰= HIC;Sla":˪gX ,L:Mx"۞g*).ۣ3bR HpiXA%!܅j՟MYamCCjhD nf":EL*Ǻ*2q:A/*O @c^Fjm{8{Ph$G>X@{hIHS[ `yk+#8у۔<k[LWG[@HÊD',VnPCAg?q+4*/CqA%}tOs b%Oo @J̡H(BзW9m0ЦCsǧfoK':{-kx| vHpXjά\`K5 _s48v(>کVwgŚhӲʹv qjc{Fͤ#2,j i\QLA^v:zhptyi~5qbJH{xgSTgbIk[}?ޙKWD.~ɑ*ː<Ԫ:< j#,)/N7wbee[DrX0 LŠ9n5x`*w9kImZIaG_iDڟ28]6WIS/v@Gq2n\VE+0./:PGF;󑗅0W\h󽇤=Oԛ\Tfr0'{Cu;MS-zCn K/rRv ZqlpCRd'zjsZ;CՕk>jf-"3VQmN3eO/gfε9"c"Kcũ;]D6:5BM1퍉g=1x."8TEaO 㐢WRn juR!|+mD1殙 @wrO; I)@ҕXʻSbd=k(Cʵs,wVIN@6MDWb΃$үNZjpO֔ qXFfCl d$Y2h1.]E+C-v]vFX ̄IJj|6|r.5x\$yCYus&:=GQ:9Nנ \cm;NV~Wlɥ W~eTaHLu]TT-J54n(•O鐌'!k$nWy\$6,~Kߐ`PR %E\t'~D^$ :5_jJLH({\Y>b5$Dx^;3JAA%OjA'm:Pdۯȫ/ݮd1(*|z.#&R5ʭ]oE%7IiՓBnDS.|q BI "\ޟ:<rW818w+! LPVP1gL]}"y0Թf5M Pb;r"NBy` 4\uN `q䧨6-#5+M?J7|˜POis6EA5Ս[6]ĎyEHvk ~*՗ՙACxzFm,PÜܝDUpӍRtIyTx`%;K<`WugDc_{TnB)1?Z}6޾D]_&+Z: nhѴʒlYӞ ϢB5z 4HG a6I2UX8d@wхc,u?W/R#V<؉׶3#xNRW}C>YӤ-"lD& P1O@)A簃K}7]G w6ln T(CzR]b_S!M~1٥ȡ:_.۩="KtE!Yc0ԋ RM/bu@E9C"݆m2!*LV&+#Oh4(?dkùMyGIӤud*Z`,7*g=:tl>WI-oy lirN {^"&0HiSQAR=&ZCSBPd<+$y?lFu kd[eP0jp!e _$.!F~ Ǐ:D~׸q+0ss6\.-Gq{Z0ܕ]?ÑwM1+?1]4:+`K;@JmXO42n-zrp<:~N._zԗ=2I' Yl0u~:Y)qA)bRnb~y!a+˪~=*9z>CMfFPۿQvVW.}7'qn_;rÚ@'c$dɸ] A\QdEu]-iytOPNME,rW>"u[{H݆jbutajxPEc8GdѤLyt :n^*21 >rxDbSExDo C-2{Qnrx+@{4@3n("Gf9cFAѤ#Oe~`.$w5DV|M-uex;ݳS.u|3D> i kamx԰NU9E3M] '6UE͙\`iݬl 6MkfF챸=>NzdaS^c'\jҬM ƪlCEA;QTCTg=}2} Xts$k'A|/ny8/fs(| PuM9q.SD%V,UjbaPn)^ WMK3\K? wqzG5uM%vOU82LZPEg-e?¿WD]bm}`xq|EˁJf D*[F{?Y:-VxJ8U~?\E0sKE5RE8C$^}) ߃GQ/QSuvYp}(L&>EC.hD̙Mշ6XO0E@R%9ghߺ S!-S!7tZ`F= /A> B&҈HY} NGHo(N@)]QOM Ū5Li۞H Ua5x`$8NZ!&CEwrlBR!Sh67uQ9Kp [ %5ܡAKmw%1 K_ 8NWQ[0)˅\|خܵUtكG%U7*LvUBY3j )`\Ь9yDv]tUF5{P*E8)Y~bۀoNL0ۡYn~i ſKG"*?VĤRu~ϠSCDf2*8o8cΪ-])l|IS r8w< @E:s+ԦHn+KB#måQZћC2ؔu'^ʟ|Iu۲B㭓H}띬tb&ϝM*~7{nW"ɛ#ڂ l-N 5D:]<"+¸ƷmDљ=mirȥ=؛2 ̿hSgT;PfMRSDsLNreWnUq'vR.ЮjE| ߡz#.n-Fo>峯P> ˇ8uodzn  =04FX+<pcP?*($g5&ՠrx:ĕ|Tt:"GW='sN6q:C&>%8C505Mv5iR.,8t; S~>ftē _4%O9iQQ!EDň(-<0paubԩ$x{kN[rs[pq=G*iAbU,_՘dqx`/ N%^.2Rk%4(vFm;9p0N"ߵk GX 'eyBc&mU}R޸(wL |> Xg?|Ly]0=TGP|c7W>LQy`*tuU׶CHR6d@b޽#mxiPS/FPׂF 2!D´f>>ka/.yGyrN#.cF.#Ox(iC)Web jPX*&l!$OH 5$L !ͷwjԗ.>Jj?眊!/>G_5-i_)UabqĭlKq04s"5t0WFim+^{HHx3FaTٛiJԳy6IaW@]%%'7s㭘P"o"J,& m" *XNM4wNMn1cl||J})ُ )8*Rܹ+IVIGY!'s@+hcFaP}p锓P2ŐPbg/!8T-Aj#CbX0I]ȵ˩d$t ^E\تW@MMҵL]fT(0Ÿ ʡZg'RCs+nV$GB ~|C߱JFRv-hbH8#Šuًmd䉅"0[Eg8#|[K!4pE?,^pMpsGCwu$Y 5`܅\|#ɬņk#KN bv\}󱌼`d禤ZUiGh%,ĆC>4Qy}Q08Xm`8(|sx_]݈uךnRO hNHG-a(klP\(͵.gwb\JuԶ@T'c_^r&ҵ߼x|'A(>YP9o J-o}d{^N%ē<\h(Tz/}9nȁ3w-UKNAWW9Qx׏{1D_7W%5ũ?H\YlѴ< 烍ɚ@U"D$DG[1vK0X,_:zQcȱʸ;.r i_M_?aQ9oDZ̞Y2J{TӮ>*މG9K,l_[4X{"O/Ba5U&D~f͐CROM w?r%>;3}dۂF]pDhw8>^3o{_6ٲ0%;}"n:7;N/U/a)&ϋr'<*BS1"pqBY^DLЄ76|=]Lh)71/ vt%,#u9PzgCd_3{6>-1yeMxYA -T2ı̸mS 'RW? qAm,e,nzẪۉ9H*Q#3pվϫt2 M0|4Fsgx er=By V2b ٵ>_9e(,R'"@h ̷RTf>;6s )|cDș,_լ"lT06fB?_B-MR>)4?R<ĕW7O+Ux!;AvSﻯSl}䚁֡y0`m0}Йw=(q$1 Ź>X-N :KFAY- 4v`2iuq |0T=`hՈ՟$vTP2P#~WĴj*BqeKj Jf@kϸ-6VZp$lE=qY`fxɈN:LXUA»O|o0bf R,1gaҿ%kh*:^Af#i? G _ [JykBPj'^?詔+ch#gp,M"Lg@+vuRJ6pA34īչ1tOlu5J}BI=?)a8 [y|!.pX;VSEryN3A{ao+VH=g x&bQYqQJV ]-F%i ᘏ%=.Љ`#;,][1\P4)p=Jt_*NX\9(B⭀FPnM[iE(4|>(HuT{ԓ1uo*=Գ#q0*1IyBU^^ o3<㞄^j\qunJB-G; ܛ32!XFh+e\U IсcȈfDG`ѫR1:Uhҥڲu$w q+: V~E9E잃a0~Q+F$\z')FHKH4$J龠/1>G0Su7 wW4p)Z*B#,7 F6=O(s\2IVCu4}ԡZ\/T(SdcFW\H3#8 ߈kY;b7-nx+x)Mӓ0oKׯ.land" A|,جz|IƠx s9|Z2Mso X.'GHf- #u5 BN6?H,T: w'mUvף`1:_{'Y| ''`A]|鴯ܬj<̛N r7`I,鑬m/qszdrqC(ETƣ?vBE3փA ,p O뒔.q<[e |ή!Zg:@#lNEA?}G5a —님9=T ԍv:{e|XMnKAK*hpc5Ӗ$2jf3[դS;fEG!z!x轭iougQҿ%̃0Y-1zT bV{*qY(<)`Ƀn=XEW0 !LktAJMĄ]ۨ C zj JH)Q@zjYdHdOշxnOhe1)D7t2MP7 BfU"\|64}z hNDX2QGg{`=7c"̇7La!KY 7[su @|z"!;Ih{iDD(!^4r~3a܆+)4>BIP-)G #ZF Ą%q0͢)5kfIFr[V K Zio|ߨq}`[paN+?";[0@m-fjhnL0SH遜?Xl ꌿpwfCZLk|Xȷq w"Q V+ Õ}AT!!)Cb8[:ƚ*g/VRŪ& \@+4du2%3˯KmV$RTnLsGvl>VLCi J0`wa op6٠r>< nMT:e4d:}#.^v,lA{+FT/h\+ œwݘU#ٺa]Bi Rz| 'Ksb@V(pDNҚU ꪄjgbq{oDm;.ݙ8p L<:'"Xcyk8,j{ȭօ+7t'e{ OcF"@) T?g-[Pd> .SPҝlPvA*+|2o56+=kʳXufb֨ :!@b JsG3ލ- I.@,{?6=ܳ'idCk)U|` YqBj3~!Vѝ|("o#o hh#p)ɅG/]vv^QY|ͩ_S*b0{[D + Q_@2ɵi].e& N!k=AP-{a6Y5D,뿅_D+J_>mo n1WgBnvnSc(lxF{sW(*޶Zc)JPdF݀Ii )=#-\<F69w-[b>:4QH/ "vC]S)H|Oޕ#Q5UOtߡo&#)yTQi?a9C1?FoZ^Za=&K:1EA 2ҥ I.T!g:3%w.vw:<.Z,D3P͠mAX>E["{>bfG{.hmX|t=D. >ݳ7\vq g;Krv6` EZyRIZ)fkou?Y5~1<3}!'}ڑB')$&*:f`G/N?~5+4Y Y< .ql /?i++ }He?k~KMiL.mf(Bن„1[ o)@fNqwf F:6іt |>#mo" ]*8?t2!| nL☳%ԑ9rIf}Z(₈/e_KmOOq귥9Ne?'\$A;o+zJW*X>"{/aՈa7*$VQ5GNᥧ؟C]xҪT,z@%N  &$ۻaVC\Ӥؗm嵪̕Aj&Mʨ˞gY~1H[%\A9Fqz\Iޖ7s+)Zw"P50X2F ;nZOLIE㆟KX,YyN@.S^Psq!(WMg"}$o*ZWAh}B=9L*qeD տ@jK~̀XjJF %Mi[-0JZaS/;nO cJQ6ȶ$hi<O E/fL>˖t]ߣ-$e}mxNUCU32e<4gE6C' Əw'w skC~Uht_Z9v신 <r"P=ԕkZ"=6N<]R,W`R-\ !Ф4䴍(1 '4Y4er֥WKLN/>O1v&r`a$OL*Z7?ZUȇB_NeE{\d40 ZǏ:7Ø舵M+JA0ФO8o ޒN吀B {Me[v n؃W 'ҞE'V6Igb> Y! > (_TO;$ʛ>An><], x4q a-+VU2: ."ڈDt(hoz:Qm8b<vEDqCHȯశ>e .!F$`tt5],],mh2~ JLr02eK.J]ϡ]6C$J m;I {QJRϱL1"8e`|ՍQymᗷiogCj:Ut Ưya1y6'<*lbC»=PD?slYdxLwJF | bl lts*9O2d>^昶 ?bUC(cj%uDLd((.aR4V1&#d^ ;+EQ6 SCޯ^RNo+S5@yӭX#l.G26Cix?.Y~W ;ؓIъHiak["$cl6ǖf,:~mO}{|#QWE{b T[ T- 8 ]@*|{B}c>Y`)~#0PԨj$;fISx`oaMMc%%w\lfbN Y7Y/9ks8Z`j4PBj>7D܊LIPeŤ/Œ]Z'9Yr/B{v@Sl+u( Z6ʓsC>k-%l^0]"ff1 O_[,Oa/ZNP+3*IʆU=AL;0|ٛ:~|]5'Ac٠X[\y IѭG`Os%_WܳUyoQWo>[" #*Y<pl)O+c֌.]Y1t"*n]ӽT W,'tJCojDنsر#zJGj#A /L Ӵ1fFj40Gi4g^G͇{XF<*8KFM?Rd "eGp̋"&WZ1vOK[8 O>[`B,&Vw> p|,ܝhߪ hav<@n{^Q` %2 s7 BhP=_`BqVFaq؞o+qnwBQ_9g"0@B%]Ü!)-oS~15}CXɺL03Q 6J^],PODZwP)jf'*)#:;WҪltPID.G{|{|=y~&ݿc֡IF~J֕6+ ^1|O}FqW_W`W گ(T42]EqI'ICݸ=o @_DIa 1+4PEn*/eRwL悼\ +sdy0<ԋ_:Agnv!Hj@ZЇb_RLN30cM,5G Fx@3.x%EbwO8{.ƽJΤB>xLc7B!YQ%57MC=xX\[SIG70Ny0ֺF_Ohq&(Uո_ޚZܴl3oȧWH@ݠEThyAZSI0IsWy!oH/OlZ @;NgPb tu ^Yh\P/bWfJbLC0` sgLPkOhuN[DW>+[ B&L0yKlze 9+tu_T̂|3\‰kK,TI2`|_鱘M*L]_xF!%zɜRI-loݎ(lبí+35+O43v꾂$4NՍ[.h'=$?[Վ 1uߐ#U0h/E.k]m5r†fD- :p*1*0tEp\MUU4x= Al$ `\"b@hYհLoNqJ,fr*Gn=#rBIlu̟djeMZQM]ň[hmn썴d;2ͶYӢ `s[o`5)\鉬ns"N_ESz+S)e`Ɣ/h&G)f&9o׏'nd'E'Z۞)biD AXAc5 `3/x;cZC$G^ݏ$b2R2q ?5Ulg]`@}y?hOs_>B7?ԌsoRTe ~omCcO ^AB܀ē&}[9/ҙz.&>-4 :s2s8SjKͅaHL=_A"EQU8&E{]}-7|&tN:cb,,U5je\64(˞99dI9wMAi"t]Sd<Jw}2;/QUgzNL7eݤǎ],Z/yy|^eF= ؓXOf^2h"P7oZ틂%4u}\e^!æ+8;NAϑ$`k#>5b&E+5Yqe зA}}kA[_ԣW&De]^ՙi/]ڑN0\ s$ h-Vt Had)eZfPNgٽ,UUiNIfQ,!!(REd!KüN0ٿ!I8t¼G.>"No9BE]<7.-qڪb)̥=hh mRz6I J(,4Xrr~g`et[_x,1@Ү[$t^܁A7v?ɺGMmgq50>xFٱF;)hrswM)[}{6m7F8.@9p #ihgDIi<깵-@(:;7aZ>g.VYLW˻Ux=1Pionџ"M*xtߺH?)؁YNЧ#b .ssbbu9w~%F!rE;zI=!XkV \QYk '(" nj麊@f)|ޗ#Q4M/ޛn]萦 e9c0) $oχ'j$ƏwhmN$Rܫ(;ظ[A<'ԇK+/Bˌ݈L~"ب>|KSB{Pۜ W3:J1_zA Wy2!f7Zˎyݑj :,l9@z]^ĆNQ 'LIO* p5JxHFa`0KO:`.?*gHD'ICt)t_OmE ޻lba!aOdDծc빷.QH&DqշdЊWH6͒cG"[g6CF+PY R>]x\M9^C&+n%M?B5)B45Lx aƫƃKn̄sUjn1RZd=bCgXQ}+?$ 7ɘg޼ }.gQ ~IvדT]d(~Z5Da+y7D7<,:d{[_z~ =9:?Q sҍ}1mP-gZW@Cu k% /M n |P|GJr/EIxHpBU $2QoېvPwУ$MfhhR@߈r'G0a ĽuԽb.P/YFff=);72P319s nYf/EqcE% OU? dˏ~M4?6ěJp[,߾f>^oӞEڲn90o%S5+p{anaଷvc]ᑲ`dX!$km_ra48]` lc-q uBiHcA qXΓ1 P!q |a^d}x%Jm4թPԕCA{C*k0 ɠ=F*$<=SC7V O-2sL&Xwo4\-+$λt!Ճ/v`hse~:>e9XlL7sh B]/DfԞ62:d ?Uzg&CC/ ~~Wj '.r\>MdַKM*~ݷ[ҳt,LR!wVgbP >{Vܤ C}!$0 r*P%;Ji2a;`d=VW9y#arbCns'T7dƫ_;*_vsEQKџ1oŕ1). x[W'ŧ4a5].1RQn@m.ƾQdmq_f(D{PIt}jIU5Ƙml{hɍB,rQ5N{1@gUǂ@`- [s:z_F[F=짆?$b&BuQmJ])51U5E'wkR8vȕm:^`g-__&2Vzg ]04q'y.=!%y%+)P1%ˣ8!i6aҏ|I%OLΞ:TJ]a(A# hvIp8Luk48Ў=F1,"6q~mҟZw}u&N(5r$}i[׹{pk6(gbLI2c/=xG_WO:.M|A룪ݽ?Ff7bTw"/,# 9s1=0&,2 -P\TŻL/ޢBCK̠]7GUAV`9R2˺$Η%Jܬp̛ͩ%dLF\9B/FѢfy.>:lghG>W4*w 7%,3CWd\vi2YcĴw5LVñMS@ZO[B:zV*u\& YTиqޱC5#JHu/J9su\yi .h\$_vɰmt"E T[D,9L?n43)|S:5TPY&NbO1L~yƘ4Q%o;f:ҥR]%_WyR+DcvۥWЯUVEaWX Կ?\V4g"Pb%p݀?!QF0Y;0!k%!t=z–6f>k*=ɷgM*3'P]D]#U9 #k~9iʿ[pऎ".|Uk8:WB˔&n%\1XR83َ9Z*PD39}D7U,}Y(3f%~y'S|+aѝr.]2)+#0JNK֡XGSG!{i4ճ%0OUcQ5azJDꪈ~8Yi+b:ox"P[FtG K?uc:,'o4~E0:~YKZ΂Ull7)^.F}Fsmj4ZHT64g ~ JzAGؽݏ:Yy"I_^`6{ Qrz**yC+kO | fE񔙮 dT+ssVsϾt@H꺴 d L&w1ne7,=k$pjmpk}*4XuK!3jI9֟z|z7A4qb]Mfιڣ$O%W[ }o`;pPѹZ`cgl2ĝ{{[>iNL[ |Շ9*)А<|f9 qWNW5Uyd XTYɯ+G oQsB\¯6gr`;Ij(8X mx+:VʹRZBE!WԖCwkT..?6oC9(N3;iFL@G;|")QIAeT#ѩ.N[ 1{h{mP!{ek'{P%4&洒;(tt"7Xg@*lcP:ՈNƼ 09!P02l|t4YD}M~\?K Q'Bi>\x:&6>;Ep:^+00I'^WOʕy.R ӰWX98$6X#S43tW*CO2?/zno"BD7w|} jK 7`aX ۋ5@ЇCA+Ƨ7mw՘lkMє Af7<&@R596qqE5h c,R-^}A4uoK<`,TKO^'{& sm-IJ\&RjZA;c5+Ar H-3-88"Tp{C3򖟆+46_?%2|Z\ŔGI0$:2lJ*hs~8h@k y&uO6 n4< ?x.OB!U2,F܉q6ev(TӪ{8_BROu`m '[{>@ž2H`;'/)#Ov_FA4XlZfe$~3Ry_)kdcBXx߶ 1(Ԥ aEw#$;<1hpC9JSeptSۧZ at=č_Oƹcc5'\_2Bflm8vAc'p"`]Ww Lć:Yx6sץbrp(vX(&w82w],ePM_jW)_ Jrb T ;^";`3Ղ}!_n(}]AF+>-Ch~'1hf֥FV]9'½d2y * %R4vgX8K;k TkIkf 3[)cBxlrZ!Y{ 7;fBQNY`$ERXGIVv4L_ૢoVE=5M8+1--{C)x%cj{oY(Ekwa@.ˉf"#9Ť+*8!9ـY{\|s \~H|[v*6KaA{D-CVy$ItYl-O>-[X{5g d'tM@V H"PVSVWХ-@ha9ՙp|`ZjrdRX6[~@yg/LX-Vk-Х1-Q7@BG擰",5P1Z.|*|hvtGeNz4(40ڱ[l۱2p=1DUdȡE 1ٗLҽY_ȚXk:.3.Sl',侏x<m8%0SF ?(.W;g-#)JN4*% _g+禽oByYOuq^}D#Ƅ~yåSӶ&G\yJC@qBCصtP]hX3iol>?Žާ"$ ݔK)1::~O(O>|F)qodꈑң]ԭy3SMQ^"Ny|d5ż49f}ĮiN8k/~{rdU1!ff)BTVNbAF:qTtb$AwqIOF[/lIĄC\ >UQeEO8YUO,;r5qQM\)2T<L6e-ΖR9~{5u՛~-ӛp.BofLڊU(þ0__ȲOT%JKźpb3bkh1+:9g~uE7eYx )ٞ /Un'p3˧&ЌeM5^_DJTщ]5u-KWﱍ)Ucı>.3σɀ}ݒ3z|?>3>rrpUVJc6a$4n5&^V[6Y |#זz5Ⱦ9P^adFp,rGvuucl$oiͥa9GySNE)}Q&]2pw.ujWi0$TJ} dB^JLH!h珯QGrV;fy`͡''t6hkDGru@aUɊ I~a_X7 ;bTnt=Q(:2h& 3ECEpa\˧#,ne#?mfi>q# g<l_1 Tr TCc u]C<~/ԥb+s4S<\uFBݧ/?/EZ#2Ѿ!EN:}V֚g/~^bj9N `;?m[5je6#pL=R`yvh1RHm )Q$|8}QQAQK3UW+(Ya85:eu~[|ޤdB@Kh3aD6v[|2ӑ6Wv\,^4"Z4RYϏ>u*v)A&dXm ;gFLn3$yWݼޠukXgƍ׽1pJ@N&'AZhH"d>w\0s{zhZj;򘄻'Vky̳%Qޤ!<*ì*~}~V> Hn`8V*86O2"2hp.zct})|CO򮼖0%kf{sNBzE e0Yqm*|dh_]6_+h/6Wݩ,fP0\ǧTj: u9z^>!1 R kk4ƎKF*\s#f G7b*|by3k1SΥVoh<ҢO2\"]]&aCaKZОf>w* A?XXuv4`@a- 7zL!.06 1ӈit7=y:׾jKʙ2h4 SUۦ3flD6Lnv cԫ@qj' P%Ј${vt@yMx.)L8.rn?eAcߙV}t\%ʔC"rs֛?0b8KzKg8g#x\F2|\6@>ew'x[h$5F+\ w/>p`3·_&_ZW m8 io]ꀗZ>0o$~8-?X2%g+}0UTj ݱ'Б؍\n]tN\E際 H9XG1O^O9F)'03D#~iECk]񽤕=mpڃJ#nlnM nPR6̘&>\lp}S<%!܋ޓ@~xU$2t4yJBKeRΪбX=սHv$KJojHZ_ۀckDqIar_"UV\`_ZNzdE?"k0Dڶt_"Ck[\]蒐J-91<C3J e':IA ?Y̻(Yu'fIҼ DP;? A^*RweW=j_-&p;ͻsAfSBvPXSU#󟄅l$)%A"t p凭y9>Îem CAA (T(m@a1-[pF;W.-뫃UDVC]H+ȋ7+~vVbys*ETg==KIq&쑚;Ouն{/?Hgމ op74EL@鄄x&H2Xr}!ՓCǎWy舀m>]5I*w YD˛2xKVdFhӒC.J7b2;itBFa u%;ɅeRvX PЯ]#]޼V+(y wH7]3ӜwL$$htÂȽZԣql@<"Rx^\oA#>ܾ=e?|M@g5{~w۲{MoB5_|}Jnn|fRQ9 Y Rz%0k- 7]xmr+_1> !oNxJ lB>Nn KG5",]Y|tX6d]^J{n5}>up%?cLTδ!K_p d‰Iv.Na@[F!(*[hBH:ӮY6T a9stRxjq/ IVĄ) M ^Kgs0cul( |ֆx 6bIC ?H2j)ȽG&dR^NB0R`R ag#6<@?v&CqA{%*{j覥sCRҥrw1w@s V$تSw݂iT==Y ~wCj*K]gI,O#0( =T3wO-%,[01j2L~+Q,>@?kDt<23LFFCLU>kO96zϷѿPŊ2 ~B r*O%*!{.Y|)$@S1Tj^sd8Y(GN @ܫ8*ЅñrmiOlcK\!R-QтEewYKr?'=Zeh#@VPB! $nq( Ϗ1qYOoyhDR+ecBb؉49f6('.ԘNJ$z#-F#{{ՂCʱf *;̐*DG@qu]ݮ>SXL@?ggBs9 ؟XB[t X;%AUfhN^&Cɥz @w$|Th;0N"׏ev:5rSC9Z6wMB0`7u܀ј<)_ѩ'^3C%1r9J:&@'JӟCWo\Ā{]U:id2-KpǨדѨ9!{ݘO^L {#E<7|f!2.CMg Nd +{F@wERa;~r7F:Q$tTĝ-~ ɐ qS"qM ,SIq8)*=c@Ѿf߾:/5A ۇ`sW!"v/lx,_=U^@[l\>w-('+EhJ~*X7iG@3=”Sa>Q4A]oy%؞/M)%"w`ʀ੨b8 BYsPÙ%hܨl %\+H3S쁋,VUJ*5e<942K% r^|z9yȁ k A[-NTհ4̫$ ԛ`_:]_½z&Mq4\ᣥkAf#SWc3Z};b>~Z4Vu*4Yek?0m;-Ҽ1vtFx_惱+>cf%'ĒN_Y/>Hbh>TF+Vjr%S#TǨwܑD:ed!r=4v#aˌ A տ nT, vqcgݙgTCBeE;f>oŖ.!j7yz1#QYa:Rt&c2 1vǃ}#`p aFP|!YXHLΑ|GJ碟ړw7Rrt+#bES"_x0)K}2|N8kӗ X>/#"8Xn &,楗 x~m4cb/<Rspo l=i&ȏJJ&}^۰𢚥 s,Bq~_ꩇ d+ZIp-\i'&㛣4X:/вwAFOy*A޷ch mPwEv\>b-tL/UT?pB> +V3"~_AtwmmLC.J곥B E:^;\ LM0ţsTDZ]ӓE޻A0if>~3I?P_%Pq&ۺ%7r1]zb$ geT ?Iu0d #J Ad|dlVXgWY8qt/V<E3zFgkT㗪ˬ%2C ɵi4c[Nab{U33qlAPf0@PC#\%ML'". P5}dC#boT;,ܴd$J)P 8 ů ]q}c0ٺ:WU{S3*Bu:^QE$\^_+> [>|9V'MYDF^5`asP.BFLPp#1bzKs:`h͵[vly:Nz Z``皞K,'9w\X$,g+m;@ Ѱ~-7*XTFZMphu: zԗʜSL׏2a 3ۃ>r8^ڙ|ESH8{̅^ϡs Y_%D΁AT"Q 6a[ؤ\ " KFo9y@dSXrHC%_nBjїHܔ12b/-pcl~˷%hތhmViy]7'{cs M?-5=W2`K/W%is/hԙ snt,JEb(^w]Oaζv$;#?M2@)*[mh M"ݠueŌ}q݄06$xj=b)K<5]Cua_Q16',bItJ]\?Qb `HoGL Y}y"Չ8H'+GX#z<2*p~O{ &Bf휦0gl` 碗)1AZG F-{ox%Vq? ϷӶs1tbBY^Oqx`n8h) 󁪰1 amq&Fֽzf$'wB篕08=մGG~QYr(e5D;)=4鋷Ł&Ɠ)v:ܿXf 8K,NG}1LQP{*Ҧ)w OILNjA85 ~m ?OR3se6$Ĝ`곮ljNGF̸t(7b R%2ɤHO$zFLNB\:FaZNi ?Weqx:PZO809yJJ&9߉"ӄwwU^f&YEh@0zGgVT3JdX}^ )22f5e1pIO[J~tGE%֙9.yM9 z4•%h#d<=xj6-D^fE%~r^gos_ *X[evG_R +)~1 2}`qS05`Zza(g. h2qT_fOow=3610b8NR(Y +N՛5CooJA'%A0r[59Fo $'S)lUAΏLDPHBhdە]H&J_^zФkGr9@Xgmoʠ7Y.302rOu~4KM6c"ZȤX4Owʱ"1jǀvGQYe.*>DzكfʙaaiAh!w\x NS`rl`I$Gxmo<-PƮ44 굊)|WY18&6[`77*Hv{Ij }"n_i\{9]x;UI Q`pvqeXoxo"Dߦ;s:w5\,p#ÂB,OrUg΅iUO"( IJ>7JDP;\|nY4n<)=(n ZdXLqoJc?MA^YL8_jL77>b+WU,>gd>J }J9֝4%xrQQP-#>v|.Xr溄Jm˿GfJ׍灚 $nYE^75^%iuӜ0DC $c|rpEb蹔ezDvAc鲹,-z_js;4v`c=ZU ^.["&D4:!E]-Ap H&е^1#6籐^/탿f61ñ ^`#Dƽ[ӗq`U@dR\i>G.ߖ-r=7]$_fOwXP R%mլ9 `L/-k!N!?P%z,0K2?sT+An` tUQB]ĺW̝x c !} Y>diV@+j2^wMK奲˛{띺ǏΆ k+Pjl_>q!qǪn`ӱBpIW:Nsj+r_#O f:>ٕo?~/Uef%9QÜTBc0 Oe4\Q%2sAxZ2)9ek2 QA~xH'dfQ rT*)[qR!!k#[_[KEor9)MHNs+ߞqՙX0Mfk˳RJ iQ*xQEc+G:}jN(8GbNj݆ð~6P86gCc?61pcHǕ*A36HףJpO`k5X\dP5oqBn-z:f(H67}Ŀ‖ YG"B>cΝ<{{&CVX(pԏt,Wҫs D "5LfbIW LWCJ6*D^ߘg\ϊY0qH/,G҆e>duN_m}aO2&0uX١qlc\%#!nOf.8`,ՋBN&PzpP'O&_9!A *#;Pp}WO@EDn_xt#z(4JHO+ KѠ2Fe;''_9t Ļދ21q;qn)e UUe݈6+NL0@#@}d{ؘ޹גoR!,Is|SB _`t1@T0 #\Hűt}]4LYφMzPl;j~>厭@aW&OtڲZ8#D*~\:'Wp5B]v4e"Nx7ϢHmk̐H/MNc9ژ1髃"8/H=85)ypbuTHXIC J>,s`\o,bhtzcD Β UNEd6jW޿"E{J4ޒ=P5W7 2cF<+Nf\b 87Kca".69VH7<@G`ge\(,# k 1#Ewlm(A`J)^5<'7O,N@#YR8AYi{9ag-/Q9UBppUj.SAjV)v?!֏v ʄRsxwXk{Ey7o.4Hy/@mTϪZlS@Q% $ rd;@S sv?]FA!zk=82Zjٵ0J]g2ϿD $ck2h8{v ]E[qI) )m6 Fnp>u8v7Q#-/+~ܐ4&cP*T|%W8sMcwBZCIUP+O ;B0}o>7qAqJ^am]Z aCNg\lq.|YL8ەjyD eG9T_m/LiV<z ,I \V]`UNޚo mUؗkb;Ȇq <[ ] pRrAtߝ^Ǿ3Xaw j}w"p#q-t (8'vnz!dѨK2j[q9]ЗF2ÆtɅܴH>XzFO92 o(+(:ጉw@ԬHL=/Vc)V[uO^h5ID=DiR 2t뷱TJΏra|\Nͬֆ/@s^ ꉓ 4Y ۓ(Je@=Tԏ̑+CwgeдnH!l&uctIݐR ꠮%jb0WɫBBI 'M 60>;IeVdh쉺V>4hAR<ӱG i.^MRzpN %~^-R+fVc:8B ku+]Z&V!28rc*+ ŦT-˳Cנggmqrk,R6B)z>Pnjv3rJ`pdJd?,XRp.1`@:,Sܬ :8fNbu%"mn-O6>Q>>SVԹzW>L$L^tNduV4ݼ[!j:(L@D}=::E4c EMm43ۊVP84Y?ˤAVH[:؞KW:A,>g}7ǩvק@. ȿz'.6o{=D}BNA g_)6ʒașy!ceecPC>" ]]c=АxSj_F-fSkHL(Xc;D)M|C1u 9z|@0EW0تjūF1C71v{g)l~2̪xxqLiz:j\[E,o/+Vq rZ:-Lg>jDfƟbf}"gpA{;;GmLzXT+ @6*5"5*pޣf1GDHM_s %mZMQ ўQPpg""32fn":w=rH?!qRz#Աao Ź_ZB/f)_崩o } Ș#e`,cxbIx܈+|0RnC[xm41mqsS&+{(r'sz(gh)?G SX 絍n1Lۦ"taֆ}#NSdx]><9.&4[:]߀#4W%fm!NGEsZ4&Mo_6?zp39^zps1)V;%Pk:"%AY6~NC^XYֈ6(Qz#%<.AAߣef'/Y8pvj*ҍV2 @{nΓ\yəH Zyg Sua714k7TBfbCb lj6|uCV$6\2Lّø$-E.ulCOl~"=;{!O >)TkkS2wf/q)܄ыa%cJ2F eTԦ`qbdi[Έ0iOՃHr=sl?z 6h{On.$wI~އc]w]wuwozrvZWiD1roLJ4AbV;$ 1x ;֟0XLvaYR-gg$.ٮ{ *hU 40҆B)y$^ ?BaM*TCub?uގaV[(ZLa.".8☀>SU_kM̥oX}҄0g]P1>u+Lj)5~vWQ˶YPOo,6 Gbg]Iz^7Z {z:=C['(3k>t]Ѥ$sI^J2[_U~>BIw@i\ |Ϡjn?*aC m݁]2@Mto i'dTJԳ"why֜?n6>H,PMbZߎaoQ,*Ef  *w+0CU0?Q16!Xqe%Yl'Mc\νw szH[mQE Vo:g# ^hPMs-7Ҿ-%_fmSĚ<>St>EOm|L7u7(bq^nᣓ_RƇ9.Qꕄs5PlvC ]ٌ<@qiߥZ&l1߂՟bN^c^c`zsaoJruu7Yk%ّ+ʢ0Ћ7๝:jñRy_$ #P {= YZIed<0 +tqNڥ 8n'֚ c>^L!cP+r(> 6 Ϟt1pfjb4}QbYkior`s^8mVx20J-HHZ+iy`˫|3N7NJڛ=g.AaRcwt2\),_km\^BJ:|p1HzTz ܧ>OOu/d`(~N)enŸ 6_5ʵSۭ z! _e13, ol\>}b/0o ^b,)DcCb)?l/Lݺ+qZ7ȦNN+qRW+Qp[\4j8MFט1BYHmLZrТYw@-/k؝ !n@~o.ˎfI|D)F*TҪjOy,F#O`ޝG ;"θGt nLoc`.<=w{㤹,Oh }0 F2o2-=_+Ϭ`_m$֡GjuQv-R&蕁1ԋ;>FڥK6qi0xٽg,V~pa>IBCJ+A*h_FK +6*U (W(pw̅ 60Jr`w3HujyQ[F~-7sh_&ϻ7[U$*'׹gtB(KmEլXC@O ,;pW@GG0Vy 0Y$Op+<@CF>\Cqxk}3 %<$'=Kt m{[B;sW1 }^%0k휺/q ~3apĤW}dc+EAnI9l7>\?.I6}aE؛b+&=Rձ>9GBz>8 \ <_WՎGyAoL3kr) <90N(pϷں!`!;?$#CcSIf?nMU*$/2нLdG4Wp6zGPqԕȟV抨tR7)8u\ )Hqx}*dND琘}/19| 3V*:MqLFwT*/s!9Xg{N\˒&T%G6\" g,H|"0cS6 5˰3R{'pRJ CECmXz G'.#irQ#n*xjr '3׌?eEf@AȆW:'zz>YkC0A"7@/QU!Ӹ2cx;q[0f>Ќ8L%K|ç$s0: ?#1Dmf()f7b. V~W`b2 JoP*hnxia1"yFaLl_3^4%JO^2qCOxRP$GfcAŦ |Bi/hyv2c:xTCGk>#phYiŤ,mq+`i\Gj3RwΆʖ̻짪LB1QdPg@C`Z:^ܷJe՚vZ 3!p4+:9R&y(Y}/%b }ou [lQ0D"gfor)~͹+j8'Em V`Z(kJ-ͦ!qhw%<@xp`~@u;pn-( PSF\ 0wm m9 L%9֖ڕ ] @vc&Pgn1guᏓ[Z;^/ؚP֗55kOd`Ii!>X^G@Haml餟Pƒonl"sF/]A̺FNj1H%\Hp'r& bYF!I-bؘ6oUGMC%<\: ړ4VzfƬu`JlՍ9vULAz=z͍Nœlnֻ$ZB>cb@urӘ?f{@=uZlet Dq"8`!k(TV//v51 W0n=SsQҽ`?0 B|Ē8`?S̪`2\o16`xwuљz@a1[[}NYX'iOksKf>ޓ2`rXi≮qMN4g<:nPiؒu!3IųM\ W("aKCE YJX|9Ȭpno\U7HCF1Q!G&0jBmWU~zY@K[\Cs>d * *ҥ*QS{=geq=:o64, |v VfEٸaB!-?`V/A[(U>^ZL3 >o*Xb)@0˹t82tIӈ) ՒZOJ8#2"8(rI=NZd23Nw {MZtUZ_nԌ~_ҽThMxDAdQR#uQ{tm4Q|胥"&x&^{V8nCBx珋5`} "6}W `o|Pr#eTxƣЩ)Yy^ 09= 'СݘԤMDJxmp#%Sw3yR-U1~t4a|WtpWa|i|p%<i˙f$/ 1Z5O2GAgoP!P{|Y2'uެ?bEV'% p|X[+?}sh11[0kW1 %7`'ߓ&|7? VtBيyq1"NS[3(G=Pǯ $OMQ7L9u 7>M#9u;|*>y<>w4X!,6Ƒ#0_ Q6Hjr<* h0dh 8- &`=vGQmvgmثG^'J7ɵo ~*>/yVwI ˥P0FnHC=@c(Eqv7h@% BuOUH:h RB /׈Jj"F9T!Je4)j^Bփ|&@"(022XQn]W3ǚ&ƉNՋT9ӭȇ=`vj* _Xhx1m<Y[nJ* wRF¿9\muc[0-Qʊ4zpa* 1dFXL+)$ԕ >(1Q-2ʜN]jg`~]Qf I=֭t,ي09~?14d]&Ղ Ff;C*H[;0d1g:9!F ʯu o~\1# 'Mt W0)v; Aںw6NӺ3ZBd'Mm_eIAn6q\4$v@ܣbM}bo(`B  ;ZU*n\PNBAQ;nǂlg+9ż[[6M%' Vw/1ÛQ P:o;yӖu18@ ׄ\E>g-U UPUWkE7z h>DeJ8CL&-5`!sa3ˤud&)cKk FXZfU 1 |\q9H!e( GUOG.F©3@gA pQpÿ::И"'=YypE~ 6th(b#H%|o/YK;S` ^H`{s>gC7&~rGaU,Ԇ: UG`%bjuqJeY0r EMeo[4onFŅAq|TKiy E*IGJ0Oۏ94z8Ͷ pM qFepV6f~CQ'pY1s87i">FmD!/ 6Yo]Uu]e^pj= Q/),TKUld{tP.?𳵝\Rjߓ{ylGOn0S֋vd t̡ᮇ1jkay&,f4P\C {} =qy_PVb]). \4G&vFCt:)7<;4F74e-uZsE[<'oNJr;ꞎz0zKDh;kwb0}`KEƞ)%Ogu'Rgg{}< G$&]jW=9L vWkg !H0])4 pT\}Ѣy%0O3Atom5> eoqlCU;} ,wU34Ȑygst#xA&rO.w6$eD-+ Re0e\룫VYzZ "ބ!2qugrIYji_'^鄹,M-}V.3IM6## i_?tQ7]ޢ^9NjRuQ W7'}%hܞKCJ Lv"F)`x1=` .߂\*==4;։_",fp_h"&JxG2V5p6TşeJQo תx0B Gد:?Zz#uFa Zzpm[g"}ת|ⳛ4c:dJ㒁=o nhN ֘7lj۫s^}dV,fzf0/FvѩRǖQ|L'+6col1}a#bcRLhߕf%]B*?GWݾؓ]nd p)~ЌoL i^P)[5bx[=9~ |RɐV.aCZ 9$sRGJHRju|OkKEϞ'vYv-C xɇم Y>OBa*i/GGL,xBX-_=nywrx3(VA5}߳M>yih2.rMMҰMg9g.¬Naw^] (UXOyL/oa|CtxuOJHIgYqa,ޒII?V@oPa SEk>%,քe``9H#?}B-+wa{ R{( |TTҷWg3~QDe{L& )_.duR:]m7 ib0H %v+!ݵ3>yЧJ7mcZ2O-9hI3MUzGQ*nslnn: ;FܩIدJV.A#ۯs\(LE"ӮZ&n[t_lxST.]oY? \̥y %7oUf;KC"7?[ Y .z =8kSg|`x_ZO,qRΜxCRS:/G,V#(ȠFZM$!n_$ L{Ԕlߒ6W+D"XG|5d~"K#3Yh~X\֤@DMLR>1J܂R-gtm:c""]Kbjo@2rwP۶tמJmT~] S-ob&)$J^fCUo=L뛈7'4TUv*L8k{$$Ҋ{4~Zmu$E;Ľ=;bO?K& N8z?&sUjcwD+$=`.YWUh{\u HQÀq!a *23^E 'K&S,cڙg tC'WM訢{zۇGGȳ| k$rX<˘OhJ-pU1S0RŖ>Y$ DCl(^N\f˥rJ]`ہs|i%B6^74Xy>O)#>'G3^ȸǰۘyR[5;|`Jf(uBc&W2[~ǃ5z.6!yw8`>\UC0]P5ptل Ce.#Lj?3\' DPm-(\&zOFHe`]V^5'D=x|썼fnmu;Pfg-|RCJ9&sb?K1"5vTK@.O{ "GKxW"cY7Fyծ=sg]1d–[CmbS J1v2ʪ覙.> ~q H%[s+R50kגby8# p\gFe_s$t}R\,T9ota\)3\nVECfL;[biZ ]2u0X:ܷ7+_c>~^hH ww!J'^ VG_עgMFkOf<.jI߸p ΆR*aȀl_Ǥv3F# BFJEdy3Z_# IGgOژ_D%MAQ0'Gsaqd~'v b̈ nFGˈuqߏTk66 OrH-zZKT~A{#c0R }Qo ۄuUIBJl-AqE_@/h+(>!B/FZ]D3un]UcsY)jI[G|ǀ(Rܫ`/':DO IavR L:~{Ʉr.PAh5nȻ8?4m"tXv?yeP3c2bЊ/bQ!J\]kdm Bح+[Xއ|]fϬ+ع!6eDF$q^BD{f"t2i Y9$V3ai"=Oq||/'pf ڧc/bŹ#?]FnI;hi" Q^f*h HS?m&]|AW ,,SY`1[Zz 揮Ǩml7(}u~YCп"'M;︴z;SVy fzaW@ xWOXTU`*GN\M$2s RjCu}A ,&SM,Hqi&zס\!uUF'ppnΕ7Ipɛf$Ձ"Mh+YM Qhk254T,ɄZzL? CB)^~ƛuI4ӀDxTdktF,QK< @\͎z=UW =bمk9+*n7 ).&+VrtS 6 FzsJ]]|M|a=<"$0ڧ⏾p :˔pCZ7s'|x><D("GR/fğ|xADB3VIci@^)9}|[YB Y& $xk 72D}G$GWoSDrx4+YNɎ> I4I! No$׿nXO2*:6a7DDƻ }f*5 K[_%yIQ 0Ф-\(WW;UGBMc!؃}$CVst[\P}>}mb/΄ 4%_ nᦾ[<`kd/4W䶍9J)?P?' gICCy1/]U["V9~F玪+9Y46˜={w$Sr+n E"rh(xw(aP Z?\>2Rl>Ѱ Z=# iwytz6|u3 p]b1tSp%*Or捽9ivբ ނYm 9"UAJ_݄U\@y bW@IVy}Z ϳ5Q-09萐X`ZԢlý K\6k 9o牄0MY&]݄MD55@% ܟXxoADk @n*b wC)w9aŧz6 {c'2GmSuȃa,ͣoʳsƲX^Kx/:ڱf0_CK;[54j<}.aa s‹ L8i;bh^Z=:ӕXXubyt8p⪝I{X[{QpmIW!$ 6v)Oa"GA3V oa:2 \j zdM Y x=0"DK'0N}# &v0#>w)Df'6 @5$a1Q S&B;×M=".qN4В^tBC\z\fhBiDXU@/>$ե |ۼZ3{T)5"KQ6Pw(>-m5Kii epGL#ѡ8_Y:K> !${GCK+B,=HnEAyNإ(jwM?.4 i*Uqjz4ZrVdM#<&Hz>ѵV#p"^ȭFښ>؏ jr QMEbC4$[ ay*LAD|-oEF@gMm]UlF0 eEpN %} ]L{Wg-/~0wCG 37ckAd:V! a>bFmtLy5ET؎fnu<=.S r8UKW3yKEꭏ^1TujQ́XXMgF'e(CέdePuT 7 G̙Ԧ L93Ha8[cs[e5ʊ|V I@H\=_j,DM̬J'F 5KD4a516SK3Ѱ =T?H2)nY#WSJvBJ]X̽;!SW /xq m hAא^?-EdnXxV<[GQ ͦXWݺ8edcTq1pn0]b)U{s+vOnct?&/9qF Ā]=0M?\dP[zy ]²SvAJW3`˔-aD6=&d]4̤1.<2Q; A(ss EqglYb"Sꅑ_ [Ճ).GS@o(uDǘ(}"CP 'Er]2LޑOsn*gFDY`Wx,H fmIa0(^SFZ#osC(Xѕ1 wP瑹9eTsY {'x\lDOCf.;WE 酽0 il1@){ fZLHPpV6Ů,M… V1ǒb܈~߆nP{<.V3f:.WKҖ~]ZdgQG`ޕUAW0V4`?#K6ΛYLM[OʡZ [AҊ2BNFbMZ&&2nWVtY8p&`CgMg,P$@>.3 Xu+[e /&a馞lh)vU6QIa˦pdB- {$C-^9uPDbC>4D!dNbC_d.#2|`u ?#1u2s+B LW{e2)踋 su8Ɠm~WPU#KPµK{1"ckneq}-x,3_%'vLUV))X8q֊gmځ/*Wn'"WTg P 4 pIX]ew `hA^o5`)&C^h/efHN(E5㽠GCMgKթ,ѦdY Kt'X($ʺ0OCæ30S kL|]k=vo2sw=)e]TrPѦtv7RfFg2O+: ـ"`Za9P\8^٧h#E DVX.Z- %[[:̭eLSyvj[% YRVG:nNC/PGIMdv]>{bʗt'GSZ5Be<SPtQ9IFWsUjbexӲiޭ$ S'my|c ҆Ġ)?w^fg-`#^K/ &¸Ttv0{_h7ج.$[&Eub([l` eLG) 7Jv@"nB_(njUNQ =qq+Bb[ ;,\s69"l~JICX]2 ^TU\茖bXM&l#p)+m5My5z"F0qpg0Aն#F@b5l Zadx6[k5>H [.1= gD5(b6ZY2l-Z7K}ZiwLhfT<b@n[7jZE;0/`0AQaF0v$|D78CpոRc by*ǸqU^oZf9"/_~ؗur3[lDKzv|T86_+P Y . g6k>Âoް bQlNt/EM(fnEZΪ @AψػX/5dK+[#lWOF2ތ. y)_@^J`ra.@Ҋo)lhj$3"a}N.<Jrald} f6-_IJ>֭5RY$E**w9EMC6l=:Y.?yEC3SUGN8@OgS0 #]t"WD+@eoxd۰/c3\ B94GܴO0Fk db*ΐClI1قEo]F9u0\wpB%Ib>nryt2uÞ![Ʒ+rӒ%3$!"B.Z u ҽZy,XW[ce&mӠί>^U yC.J aRd3'3U/ŦK7I`Cq|yn.IUǬ-6k<e/_ c*yMqδ5 <2ƃa)ȴ!};1QHɓ91WhUs {% Lg|Tؑ C5l~#8jX-6_ioHq)Kbj!u\y!){ )'2U3QFWjPfӯKl Ëj Y8+J6Ɗ΁ TG-J!:J}ZGۧ/"ul%/0QEhƪ>r?F?[$Nk1=kUS]1Ls{s@&JJAYVDdQ*6f#/~Lՙqe7ze5qc3̝4#ށOXmLE!Ť5Q9lyolaڽss]qӉZ¸EЪcdmi˙nZJmv+L_5"h\E8>-o=U[ кf'%噛Qf~xoB?*xQiδ{6w%-#۾,0XRFJ0ކԐ$s ."Ǟ,-6kάUo[Cir28="^@}0|=:G#JmwZ$º0nFX+ӖKiM8bн+(.Q9ڇ(T`IOdT#ub.46:;V땆YvCCEqAK*sF5L 0<*2{IWz8w=d݃Ơt@]s8ۢ{ubͼ/3Ped}H;ߚ9jN6=1 [ydlCi?H=s.TG!a8vCl-_3K/@!"xfvT@g?ާX&83[QkiZ0( DR,dC?]j>h4!ʬf1Ԁ&~9КU ިr䤅2 l9};o,'av6͒68@!A#ĥw]j-[uii5@Κ! [S$ߤic@i|?cT(K8(74[!Z,gUBͰ1h] @I^C=/T'aL12zrQ`4Z*K_IfOX~V`X<Ą=5/u#oqXɺ[U\Nըb˘Ro~7$wt4nzߘi)s'Mz[+J1V1Si[Fz<LI#iY3RSб`F%_iuύ"=H7d a!_ {.5ww JO4$Q_'=~1}n~ȢkG3eQ^HQT'@sGS9A@,-W_".$͡ q K#'D7:_*|l!hmn~F^lߵq[W{?䏶V[ 51jA#1Qz>r޿=Mjql,`uγmm=xG4DBYD?]Q N"ZdW0( ,9R9\wT{,گgYD?$xd(ٙms]oa4"v̥+nZsN{0fڿk;mCیq+l\fy[/;_ە,s*u@>< ş mj0Y50]ˢ#T481?(0ۿ޶rB{.]..6kDQK),2Lw-A| qe-i96LSsOuF N|jϚ'[E@kTE /KH R$IlœnپcT^ez ojY 4%}Cb/=b=7VD'ͱoX mR"U'{eXLxO(Y"*NZS|&#ۈhfjߝ8>3fX9xy px$:==.> }4P5Ȅ [B/HH/e!(riQiq֯vF`$[8T_IȬr@d;CVoVQE*߽އI[ 4  ERٝ-J,uUd",Ť8I;շFL(? qŭf^NXl6'd,4CNi~ތ~̬gD*U>(}^ư+C]4?I!1uhc%[g|I-2Ӆ /&# t#W!L!Έgw®C9n /6j c!;Q{vEw@V"+ M9 Sȏzs}G2:&䫘rA5S*7W1yka>f 8&AȊvrvA @R k59?18@]ۗj_k6{6,1:]FSi`iy{\ZS.Z@6D }߈o0BS]J-2ɴr9Hlݐ9Iw;j$ko \b^vs86Ia pS0% ~BsquW/mwlCR@l/M},Ai[+4lYCFISg Y72jĨDbU兗@Kdy?=Do_,$jH&MޏmZnʭt6STQ@3j ᩶-h*~5h}7B2F[#R8Gzv*20I߷6.+=8[I;zEY5N]*@ aI TPoծ]ꐆܺE>N;"!#g=jIi4,uaHm򒐒H>E6x;'*|(ׯVr QqD{VRuuAoHƨ%CX${u{<߾ca56ho@E"ںSD! kn7@}lP4us9 uWW0ǿuO{/HzG/|2R|Al\(s2]Su4G$=77?RƇx}<}bH+D kAm@ ;8TbzFuk> цܝQ K$ 7  YҴxSLT0a#e~ 0wC]i=ᄢ&ǥc6%Am4"M/6*LOg2yb$} Y m2vJޗ78|?77<&|6n4S i! "B3 ZIvcyC NC|0ڀ&8R XZ+Z'tʃ -hZQ)180$ 26!3EAۊmG^֯7oʗG<0ՌA#˘5b%ZX*igRk) zEC@KN='1$TקskŋBTugH"qn7 Xt2,fPƵȽV"WavoQ3>Ϣuyb>FrB FfjgĎM'19 ŕbgÕ.k35n;=7t$/)D'BlsmP>?h&#VVO=АS_a>0QgQ\`YM;r~j{SYvJHuZ{P/[GLM4"bYS]4Q(;T us$yPU^Q`yq&OxF,<^gž}H p׀b[WgC_8r䒘Nlpa E{lM5 ,u$PnO9 M1awg qRiD@|dkJw>gI6{ bVV|fo(+gث~M;1HZk.<`Q&  vr;!wE|1Zh.)T7w^?HY KK!.8< dFϮ?@$ju~nj ^_@,`-T/èah*Qօ^,L.XuJI>!P$.ޒUn|@@6xջ.^֘[bIbX zWZFQvRk([Ќ#('[opbYA  /{~Y ]5Cgk@ENgL!Dpq>OߤE/ ۑ[^^z>R ѽ99#+Rjd9+Ztc88^.J biIJcXU Lv6Zm*D?.Sm&ϡrv$BDxP\nP nCDD$sIlޱu̵S8E%g Aiw༓{7KjI%`* ҹWIRȪ k]ZlUl/6u S@™]CTPޞv|pd@Tf5C-Oa4XҡmX_ = M~>j1shoBVa[?ЙKnI%q+Ijp=մblX&53e#4xQ m(V\YQ"Hd.3d  )_Ԛ0(iȰЎ,L]i;4]P>s>, :٦^w;"?;µC[ٗri+h\!v}1JHCٙ|GDI0+SdۺLJ(.a2SSmBP!Ƙ,(N:6H밟nȻ&$-˷f_Weo|!Y=nn vv[ MD<~^tV9$TZ-(Zϧ@]x[AfD2٩hC5n&4$ ]%+v]s/rա[𽲶#gX<9 v8$W|^*D8C ߏDm+^p4k!BKVfʯȃ7m;g֐Gp ҃Fabq":(Hih6N\o,rm]MY.J:"Vd@ͦ#1YC \^"v@" ]{h^Zk6 \&Bi.eoD"E6F e82ɜ#s{iT@- _JDg$tI>l%:WO/[ 1t{j:11 U}p߇`Mv+rDGA̸w_^زhtND?^"2x SȻfpKSCۦ`gDG t׾yeU=l{)2-wΈ.V1'I1(C%̾E:c h~kmGy}o- m;iZgE g!/<]m> {zњAy4,@2iMw-;gTBܻYc3cZܰQ+(շ*@H?r1΅2Wh"=@3cG\Au,Rk,;DŽ!yBP29{K|SbcRHɩcdË+M7&N5 )}]֜nSR$JT23c!0HM^kμ$r'b'+0=Y}Ȁ)Ԑ`n Z&-uC%5 >ty"^ݸN"b &q5{\P0[QTT4:u6T%y\(u P\*܋(Ž.@;|Y8YԳ郫wyeT)* V KNrP-2X1TCw^a9CF?::06dA}@7WFH9uPxv)]sМ}XR Pss,̓?_ rzӘp".8~rQڰ<8-!)2_?Q1?pQfQ1B£v;ɟ_4DH5^_k <𡗙0̬"=w 8.М9BjxDI3eq]A3t /9jlѲ)(@$*j+ɻX2/K һocL7#҉6_L*q*iՊ"947epcԯg_+>h<0|Jk9:A]vX ]Th92nωN5?jM iM:K.25 pҕ7cz%߄%{<ŬWHia%,[$F!=P _K -ƇX#6k9r%ȯ%:)I|j/z%BX"K(IG^\OUz^ b Ζ0Q|"v] .4U,$7'>t\J/ȉ(`s\6m @Ŝ**!Pv7K!d5c͓P#;UUOPHO0*MMR.Yx qkzNym)|rsz-ؐM̸U~uPz?*•{=lF{AMKqL$˵"^/C+ a;T[D0WʿMtleZJAo|ae<֙]vA~ŬS RpoxEWN[(Bm~MyEMYiMێV-LvuDc\eJb>Nəx3_N3 X'O4,7g9t1t[cg⏎Eeф`KN_dhAa{xKi沑\jg{}dȬ͋λkd Z kXXÐNH_sfbL81Q}ҒjM_ vQD50M<9f¼Ҟ$HOo6cxn4]`RX{A5Yʖ+No8鮄RjK+g,se3x}VH5tjv^b0L+{F|vPt b0ts9!CӌFJ躷en?C۠[5O}^RUW@M)&0e!$M}v@ .lF0twݫj)&纼2#6쌔V@@>V$4{Faj.ks:o_r SmM t1sBK=h6/Xh^B]$gIDZ6}=؍WfE,@}*tw6fwome_%" Qf gN^~zie,.ٚɲ5VtաtA8%8gI2.ß"ĿT¢zc(8-#O/,3RKtFPCj|)JCeQ}!$uN4z?{eVyu)tl~ _.~zQhAهt,TTkz'nHFֽ=S Xe{A't!CP %8+$Y ׻$Y9%$IA @mGiX#DDW i3^̪p0C[ 'k*?\I2+`*>g_(-%Ɖ̞RCe`R"w*l C躲i$0s JH/+oT`|~$\;fA\KL!KSCRfXt!O3Y x<<ޣW"4K)QHI>h!vSXVI4 q\Fes/˫ÓD2fӆ!2AQǵy+ -2gI<SPhk155GT;o菦?=cM,)>vY#tOzU?d5 CgZbh-MR Tid#< + *_8%IrlRkFWd '_'jmc QF,󞒛ĥ Te A*nٲ6_272K֞:GuKWΣ}tֳ 82ia^åD tDѭX+ܻ)Z߽{GEUO 8֕2\U0.g`gS\moA=+*ʎKGx~;)1LQEƭ8ٲ>&+P3'zEmnc3@uh,\ITÑV;j@ą H;pc(gwG`1ղ~)doڸ mWHܵ[hAzڵ3rj#(WN6y S]BhXDŽa$y c 5[|gO } r#(55pm{q;=4?Ṛj(0'C>byb1 xF@Eo Be"Jsjd@g;IFE;IAъfVE{̑=`MxРi {nZxmsO;_٪N5tgO  ;>H~cG6{k$>خ`{eK]d Q>.*ҠߛmyYJ|!,.SesP/9$pG5a>GE_߻i js4:FWgi7 d;o]\bG`3rMnCPR w| >_!,4gFEDCcW eI,wY|Kch쩐 A2r҉paF[p/@ar"_G( UtW2K 8J_g3=!Z9:HrO^EIp{|#`5jϕ_,&Wcn-hzMtVkY. *ч/]d8O_8Q/Ẍ5ZwK2h,ӧ\yta1eGaZ\ xyn7U^y0FJ@`{h k8fFQ_$=eh~pPٕsy,%شtqppk=f5OA٢,H%c#~uKha3 XƸ/zSHk%P,\"\vNat2RoWO}|eƓT#j֬Ex3Ϩ̸|J ƿ.99`2NX++bɣutv8qd. (f@mU١jZqx`Rԟj(J,YDtw?uA˖ժ#-/ vTصqUGCKKaJ4:+p x'Fóq SaqKgTvY\ơ;/h?0bЌ.@=wG;b-9tS*&Ĝ,ΨQ ,0a)˸ճW;e{:H#PM9x`"0KIf΃6|P4 h1A -Z-]YnY+L6pS%Gb@Mu;x 4Dr"!Z=NFUMeXv NHA3vTJ*c8"]+SހW-"& <>Y7p²)ʧ /e7}JMɣ;*%㓟A4zWsK8Yke=vvf )d܁ ʥ|Շ rWǡ;8w}pШIVk#ɽVhua[+7v5$u 9y#AȚݼ^oOf&;VXRwy˂$jewל`& Ik^aeCbLđ%DDi7-_lNqmGU  \꿆yFFJg55 j_뮨Y.x zL)x,[a+`/kv;ĭ0Z=;PeJ#V|'wy%տ]|p>Wʯk ɾw hM{< nkղM\P) 4w: 0_27BܻNnCϳ%7|(=HxeU iaCo&!`dK^JwL3 a =o$HhT D "N[@dA1XMeτ.zԏl7}dSKtכ,yjõI [%׿-+[@on>xS-m[Z"e4M N~ypU -eN h1 C=BHlCk-Ac8R3S})!A\EG>"0jvײcP_}D&3КJulٷ~wz:QDrz^~.ߘҧ턆 A0(-2vɚg*f+Dr"3D+:/Odqw y fɂJ3jF qD9MM ?AU70E2b1(^tm`vxpjz̕ ޯwtrX ܤq+;n\&z; ߬ &'%q'Su:}*ꀣkrzEv[bx\W l r!yXHNA"rs J,'%Եd=pNp,y^b 1(wGvߧ(+e#^kąFDcZ;䡆݅.P[pfB`/P9f<'_n)mD;Fm f7%72ۈ<sayA|i)*LPcQp*v5\ CI2E>tN[<&RXmO31 fq >5xOu\;K–t_$$í/}FT4݀g۔0Ĕ¿sJ/qKxkat!m8%͇Dkry rOL/C`  %`dVFqKh%R~@4: :ْ0WeztM%/+^&,^RxQx)FåߖaJW?}Ȧ L.:"Y`L1 TWD¹WmrP ָFx%O2nզO57>Q3\l^pZtTS!|#ųpRZfҶ~OS,%O_ܖYI'_"k>#<ښCMdBGie5.p{^?ښM0Ǻ&q)=j,#aT<8.5Pj&EܣN{#JN*[ێN>;_nRA-c?<~l+lVQlrUg<`m݇eYْd<, - PNbJ'N @8]37gkabU{`5hpHl߽iA?,ou oa;tWd,mm$Ԡf/%iy1Nƿ6aY ]U_N tȥRIC*Ee0I@"Df"/=H0tȱIcYh*&=sT$KW8@TB IQ>OڟH vN|ѓ9uhgvT$٨lE%}aL$UJۉҌipྂV}g2c=׽ZIc^1>6Ęy!$JL[Eyډ TWe]ԋNj[S 0%bY϶>' ċ-47#B@ӨY!6; dd}**I"ȃ=nr3(2io-s@'E1#KJ>J9;$/-֮Q7=e;ԑjX!u~JA=p :K`/hO*0Ht^_9qQMPUKہ %Gl$@me' ceNdn(k(ӿu~ 07748 *`il F^l7'ULͩOa6-C:X܈hXݑ^U"Ҝ8wb-ݏh |4+Yjl 5k]dj߽T%[J̽;:N؆]Z-F`t1ʀs\#.D8f:kF̾ 6 Hp *yTjt@x\|!+߂Ϥ>h*SN` wc'yɷ&_FaP j ~e5 T9op66"0J }!ʝR;T>!Y\ɣ|QHjx@?5p{ܵԋ_{}Cƽث&B}-MTMlO Wuٰ fj4cW(~ Ԉ|wwZ>U]q腫%}Ro%r"@' 4TT:1gr&d3I=e9*Lav#\`a(0&n{`_v`_LN'ny(fW*< j*%)zTGE[PI!hgvc.bEIfK>撛˩%2H?S/^\h sm]+5VrXѱNx1~K,KsC)M Sס" E8\~/ zE&[%gѳ_՝wN6fO_| ¹N$s<x}O\R+wXp;I"rL`dŠ9hunI2J!t9Pe7š0w&ˈNKBǮJ8n@d_fF: Su{Mhɪv Japi7/7B8oT'o]:A[Fĝ鸉=`,3Q\*]zPR잉@RE;iw,)C!(=ؖjߓxx/4zmKuW1c抹4`#҅ G–M9p{K_mb.#aprBӶ F[\Jqf =0c=^F=>+z6_tJuT),\+p9ke9oCQ?*WQzC,ީIgSKs?^~0e"+)aݸ惣NQ ytJˏ-!58> Ykl%;}٤t4PHsrgrú]=DRƩs%~ƺsmǣJp<8R^c ^{BXفkԭW:^ĄЮ"%)]+NGIf\m_NgCͶ^SdS2.,1F N+k6aYxBgniH!j\t+vaCF6 [UG ][ZfiXV| /0:"j9t5E"*0[/8>Í<؏>w3/ebfN,7=; Mx +`c&<+^F'?K$yHbаnr\)ahLq~OQsCA}ܧDȇ/?i:l@nqcdɲbw}8 Kp RYMNN (tܻz!nyg]r#j8`<tZ̏^4[qvYStrJ2)^JS*FwټR5)J7 `A^h*s챔J+:k3YN,4+sdi?bk 84{ڬItX,*ط.Į;)rWD) :<'uIAJHASI@=rOlʓXl] )(W }^pRpQ6q}6:Fs+46VWo.F ekq#c:D5u\';3lS>N ]/1%y5uvW֠q?;!ДU:?%L3jfĦh!Ó=w"o3cf^]@ &iJ-0"SwPD= [eSg_boxƐ($s8h0SX  Zd׊~ԗUpqxA#.FJA{9U,EK9e7lNdygG/1X$FMu|vbS^g9[1Pŷr4RfB&N_B+ogd w῞ cpN'w2r\J-d1eE%gB2xv`V;h;Z.@7:S)6-bPKVk4As}IN1ѩm"4[]?_"+X*mdutV߿f1V:T b`,mIpg[mjOҬP-@5&wpCLƞ$>i:ŰⳂ\RG0yK bBZɁf g$\1uBwrJ'xkRל*:tեsblnp{l&6;@޿2efvN㰛_廩Ofa#j qS”R0z5?4|S}96+*陬7IUynpr5۬:W$3)Zֽ~1<ב&9t=$\|8K(zQʜ' >S8+ d^|9[vHnh2[IEaEg߮ bb<ףP 8UmňEV@o:e>9hң{\!9LVIW @xC 9( Kљ=RV3zi"Al_yMLݮ泽(.,'o;OF9Do!}g A8lg} qf| AGVlrFJNs.YBc?aL0[ΊDp/)ZRa@ G*k<9U C3$[!*iWn}Fbziӄ?VVhvopo`u!n>c[oU~\T x$|hacJ3)(<.I۹OY&|y޽At ,H?יVգLH+ai8"vdlZtxUT{ߧE\cXM.mmZr1=Ba=y> YF,Y+צe,tu#\W1 s8u@ѳ8cRLq':CSw|@(+_"PWWkNm'`=㈡?k>}kRA[ $ӕ:#It-:@tCv10z xd ;`>AZPC1͢)tvu; <%:'IIq#g/lPZ".1ZLe$oz{Ѿsź˜0@avK*J#jy#+5uaLc,:iE<1 ԄIF E2?c>nۈSbmڊ3*z۶VXc`_5|LH_#o{exݶ+_A@ ਚiE:ْC@jx- [Cr;i}Qٷj@,vn/d[0>df`т. Β+m˻-v5S gū^$ %atY"qiV72G)?^3i>][_Nh' :? 0_,$־8U˟o^("z]őPTp՟ _|z0Au"+s jȉ'<4M8vNSI A{^dA ytYu,mUsw=׷ɢ"uQrk3¬kǦߍuR'1';qX<@%KKtc3Pr#z&u\0kj`a>h7'r{mNJaҹCL!ໝϡ?+At.)ыp@ YՍ- CL35+> 34J.T?q+Uχ!Il~Ѝtc^sc$d}+{b3Vt~gSew]Gɑ)F6F9ϧ(el;V54FR UbGKXh- -Y&!k:!FvY^)DGr]Er)GQok]P%l [Ɲ.A3yk|n|·G3(c"4r*S +RQIB4j?PzY[k#4>P#w*{!6W٠3c{goNöƿS:ςش7Jf6+OŲh Ƃ ^{CwM<\z^YX:fEbjRSJv"G=QTGin`/4XL,ْ65~Z3餬xU`;:kR@Ů t8ۤmw&0:S5<~IQLE _bvvaƫ$E@Je1<#M':RG<"С wފr<&Ϩbl ~ITX_t1P>"H0QXB=PXr^|^n; ѣbbkj/ S6znkzvh$N6oX梚^MA`'Cj)$4F=:;D3Wa~s!̒_C*yK$4ivE1̌<<-WT(c=LNJ@c|vk@*_"Bӂ7c>6z01Ed ԉFG)9fr\1{ae ]omX (D̓_V+x]/Diay J1V^fBXc;tAno=҆(IQd:ʉ_ ˡ&kN͍edf2+ƧօU<<0_@ Q*7CHU9lʳt?#sǎ|qКE7 mzhz( Y&Tװ*H70nԠP5B;ijRCv4 MzZOf!r?}cF=݊}\Ow˷~Eք()MtKh֎7bbb_peq#II}>U9K=sO=1og,ѝo?_7:q7e6Ŷ Vp)>сw)_cS2x)lp9k'xҔ֎,P Y.c@F{Sj$j֫$j0.c  㤉lk3xI:f,.82cn 1~ӝ6zu>ܭV!KyK{%zrJU^2>EeuUM9Wӿ\pl~%h+a9ˋ;AW3>]A#2fԍab_^6q+ <|:v,Q/|JwbCߕ|{@B]1}oa 1=ȳp,k@H% U2 b> Q-N%3'D2y4^ƝrC60~ZHOJB|NOPX&Qy /Rܮ0pTCj?S8  z 0]!fGHǠKgk/=q(#RE+[6wHy&92Vux**Xc(8v3Lj F(#$+mQX#ԕiQ ֏ۺ1{@|Ρ#; ٿ;Ў'XHG.Q6}DMPh*j)\3W=9M|%Mxܛq a6E"0Yzqc *D 68|^/wZkRYéTp$otcH NxX3/x*P4=cAc0pZv 'A95-.HF*-E?io=5’1h`M9W|D(jG?Ĝ j/+=wk/c'@WP#\4,+dP :o&OM3nT,k mˌ& pVNhu Ymq[eoږ7M)nf~/ʓK@9COY1X}W0nҩIҀ !)y{# HZmQv!@~Yh7dA }y"z?,Ro*a\tF:[CN&Zj辫q؁W>>aRFp\Ϙ ya+861%_t$ V/ʺ ,ԃv~&<$/\ OMS^Y։xdLK]>ӥڕo:䅯ͱgSlpܭ&zZ-s pVKJF~eMqyHXConxjg~I|SOȣ0 ;@UR`6֚xɹm䬍tUI'ĒkJ8fYɮ/8 Q$N&ҶIϒ[ޓk|יEFzvӜk\D/ 3~,*W4t#M/[T[_+^־R!_\ulW༭;j6!E?fZ _$bl# ,/9CY2)co}ec9Q8tѹ)xq`{FeɝU_uݻ %JV1mA{:%z?k"9Kuo7"]bЀ3+Kt؅`6m9"6͗?Wjq$+dd@)?+3r }"s8?PMD)5QҨ53/Q = *틞ڽg!%Н냽{ݡ]'C-~5T:t^ioaptF#'%|cҩZ@\9r[3,&-Яl-f~00O->=9 ~:T;G.GOm o#_ez[yyhc$-[lM8W=Mb)d?[H[.;uS~e;,I˻1a ə qUe03rѪL4SI~*@eC$pԃssb&ss.W|^MAlZ3F0Tc>i I, ? oh e6chγ5,]ʗ>H5\+ Ƚ($=O\ $&) m|TuS+/ ;r}0 ViS7 U c)d7vE0r\\jZwI}i斚9 (nLM\8:`ȸ! w2*kIZtpTtV 2_?,һOPԜ^9"*ڇ14Kjstf9{>i@*TRge8ThclhA"Cmg2";:L>~ *[:/&ȸ+R?'-lG+x@Mp ZgF\>Albjn<6!Zv9Tu-7Z"5 7J9b`{}F*8k};[P]?<*"Jem{* |ysKZQ TdROTIWC]XH9t_ql^KC7nzqe{L9jn uY\vQp'&#cSL|VQpA 7tAK%klXE+$f٤`*LCY|ؔV*ì^X.0 Oz_m' /1KkJqhE89B,P̍ȁwShaG8N[UxzІ>fjdwaW_֔1 Gpڏ,->:&;ˣ l99#_60b`uT4,uuN>;ؖpg5p ܡuû^H tn/s~lܯCa[ȒkG$WG".&UJkxq!A!.`[M*\=ޒ\t~Ǥ²ixzzcc`!U)V.KA[bL-GH留ijt.FY)AaܯRUvC:eӺN̫%|N[pd-AyޭݪSQGL@ NFmXEQ-\,$ءȸf٫6 9{H#ؼ_S U[e`h2ix)mm`I۠ RpciS?yK΁1Jj$ UɎ[_o)BJ;ɕS9wQLqR\_C*7b/HUc~ $xmx8@to/L7m76jnV<'_$KelfNeeH|O?ͻ#|!{65!3:ƺPsK8 -?kzip#a Ec?Kp]?Ԝ$G~uh0E_<Shj↔K쓑01lthp8Y$PeζÖ0>WTD79>q9LKrnP-1sP-lzv|iFjm6ynz;L*q0ur(Boo`H( ђ_ǁ=CؚzLhbI&\SBc@kWkT/n.7|N *r1h_1)6˧$ |Н;l`U;u&Iv{%Q۰4)50[?#zbaTOg5;'b%U6'iШ. 0'qԨω%|hǃ$|I9(뚈{Jc ѳA E|tQ}{:gCǴ0Ȉ c{0K|'Iȥ&OP ?ZxbDr˸*.6'<:skR&!vC t~^ S.k,P,fGE1~/fCEkoLFz&|h)jW>cmۆM%djќl]D>zzmW8.b_#q6`|S.`Mq"kʴLlFAPIf_R%ҧ0}$Sf_oKݟ+ULb\sp+FS9ڲ-~[qqd%C:P9f'4]9iR;͛ ,֘E"4•x O=#P Uը~{YMahOEHsK~&Bbh " p>"fnm1=ؒP+IJʼnп@x#*^1 Hws +HX[GkS#8 Pش10fHizR92%hREZqKH5$b߯ew,9-THwW1 ~$s7񃍅/*Zz%QP~BDֿHYԄ_v!?06#͎% ba:1tAJmYN!Pam}|X^AMיSIx,Ryd Un&+AZy E;)ʵckpT]U?a 1xB&I` Ѽ:)G|gH)g$Ae]=3GO{eДؽ*Wu2QR$[R}6c¦$SʓOR*{}DmGcK iPLĂ0u[Wߨ$6X')4_w+vs꣉oZ#, 4+}K۠"}!,czS*FkNbmVKdb$CFo]VȡYwsk^}%pReoUSِթ( J9Si4yC j<<dJLMDdXcذ|[dh5ץ&gtl1SBȕW?]1lkWʔ}ԅ ZY|-;48)ms{'U>68 ]x}:mDhN)yZs\9\/Ӗ>ݮH*yx(g lOnE  ~)v/3< eөkJP/\V%C,Po{*T*Un(oF.|c*aV{qS'SN:V]m _}+4퀶ǎIY%BohF-CH4sPL}3,j>cIhxhdEel#7rGvq// B*e^Nܗs]r|_h><7㴊BRXU+X+0Gs&#dbDWPC\ݨS#i_|51p𼨕?,YLIňqȡ@q)b?8T(eH+Ë=\ rNjMTh2BVXiכ$A{[xw1'W^ #*)eF> (&m W-@^;O2ɮ= ͈Z)>,K` _ŒոqŬVd ES|8<oTdcR}Zh3&Fܘ[.ɷqM1/!,9`n30(CښB~ >;M^+VYYO̐ ޳nO_h+@8N~&6G5#BfPK/= @ϭuBt^jm`CP-?!8<*" {e|cjڃR?;0O<œ=?if7.a1]ƕ 3e:v~ux$颔T\wE+(1-ߒ3xh5i y(,^\ <tSh͗9-, 0ڄ {s 8WP/B8恻XBsE&G dU.N"~ Gz&ۀ;dP1s/Tw0/IpWpjtsj8<|(.9_0o=+Ytۺp_ٱ<f`uP̎C49ZCM&*`$ˇN$nz*0NsC dB2Hr-ӛ%cP~)2C*8 ׀x#."d qKhQ1-Ez?F{:PTs !1ԛ-A̦,a E= Uc2'P7bf=(fJI`4?c ˁj DVH@?D?[5pd(m( [8~{$hʵQe|+qa״EO:C.^YRJ9m+ٓ:p 5ĈgFZEG30B Ѳ T:;x@k0:G>ʣ 5 ۴jT &ݨ@Ȩ#j 4cJ͝y5DZ0&.dZQһ|ʚ 7ݏ/n6[a-xr(pF{t6 L]Oq>Hw~~=G6Խ,.Mxb1'iB @!axO,y9T3ӄ_^=Y q&fnWb$]5"(D\ TF8~Z!.{&B;"K~>Y:3): Bϭ! 5,րg karrtV5uHcx&#G45<'L(ê)q85ڦ8oC"9[ 0A+5) qfU0PjhHִZYЁMkũEsdMe;x | g-Ã-L- rSɄBtK Rw!2Xb{9E!+vپ첉1|ԉexF@.bSK:Zmr&P!Rj]z1u51:8ؒbˀ0?!]0^VsSםـNo՛5ֱ{arPM[ߐ6gݎd69ekRo*Uw:V5Ј.yrB|]tg |nCBZכޮft|Qk~t9Drͫz!h|mP[Tja>8yU-H͞= [tG:gt 'γ68R"%FOkv''J5.U+{5P߶ZzGQGy?;.U Nh?9 d Zi_Ed1fEF?p֔?t`hPl`|gbW%\uP4~b,cγ]pfd'/n0RCM"nL X 6KiEDsuB@-pҷ>ϡwqd sB~МmEҝzG/&S\e؇X>oKmP {on*i_!`b4?>):~$gPq@&P{oNY Xo,2j⾀Da1B<fieBPWQ-f`Ht{Lk@HL{w QN3+6D4#MW;tl@c J<%u<~Q&Hik2_aR6'sGKIC\yT5.>76 \ "ri %M~&Ҕ{U4a寖&i-CWI":` !;Jo8 L_ˇ^8NǙ<aZ1 ֑>m1V=E!9ehE\79oNgWj)T6}jxPH)@:u4`@%O5cnBX6Ol#0 Ȼ|-i-24%,,>gh+.7bw8/|mL5cJs(UDBy -1%CGW9ge+] Btv{p̧&dD0ӹ3 tIPx5[,zL,#O4H4+׬8P|l݇s+;HZ'Jl'y 㜶/g So.ά/Eq&fQ8Y38&|p7ywY8bq |pa[SY"JN^+ĜMӭ :;n12Xl@(c;h`E:>A>*rŋi 1@AnM^rimE_ f|vNT f1T4X=o 7= ׅ{"5ț\\b!I8t+(,pc6pPZ9u|\dJ،⃰>MȾx  e@?#A;ipNU_k4IGG$\#(u4,uUUw:z35:jD(v(ٮNbWЍsuL! !|`U޶chxRT,K劲6MQ]YH^k|B46 *DbT`%l*.^H.XWi/l1/K* m&5ZlET#hb*Qi$Ju"ÄA>`p= `,M2 .bMˁi."&Y~q + w~?ͫ4[37@.hMh]-`_*czIX~DĻ*iM2+Yy4K5kV.չiTς,)?'bw}? pὅH)}e"7(8r(7n* v\JU d0mCE,zvL2`^M8_(Ҙ7o?LUʹJ2T 62$+>,śE,V%ﵹK3* ߸\n^wy&!p׌0.ɁF?-BՕspdO-! ?z?HcY\fV c؂[Cr Ed}4"!,-/$ޛ gJ%fIiQ[/4󷠛VUz7xf~H7)WkHy{Ъ_܄Q_ F7c+_@"yيdcYҥeKWD>Go+,gUF#pgo5j{l(Vlκ $6SMWs u5#)s*_^QQ{He 3|О+DF}½"¦^&#3eW q6mz%7lX~VL]tşDƆ%]l}ϲAĥwL?`= >BSҴ '. P30)e3D {k onᎇTZIs,[^?y] /dMCKK:Drx&[=⺇dتr$pDbX:'`yEE^f@]*ڸ9 Nj 3nw/fBf{H̄cȜb!`-tjͷk(G6\!W`b^#;orCNV%>bi:Fo.#zܰ̚!S7*'59t-iXG%mИe?| gdZ Km#a訖L2b">I~F@dc~uxޙ\`7Kdx¤PMʞH͵=zRcJe9whIZt"*vϪl^g;KC=;j "rnCfж| G~O[5yikr.wX%m'סCVbm)`pʛ~ᮚ`jY!<0"$qyS$f x3Ƒfj: =u-:sn{ YQ}]!1D.W$#Rϭ}GKFUNMC̠¤q/tn'τ}:2Y#K gDᐫ>QV x_ߝ@H6H O{LnDĿ)#Yb \kIE|>uBp'qD-+]#PlLP>QTpai}g8C@pDŽ..Bfص-a ],}-d%^WxӮzq$ 2XzPPڴ_b$x4E\;2B ˇ)azYߣDA,DW[Ի6M=14RX@בd i8ZCi\V2HԆP+2`y' Lž* aC p/0 '9X29&¦Yh]=^ 9p £Md.hCd ϷD%OQi?c8d\k̨f 鿏כD nL)OtSFào絀\ ~,[bRDoDɫ' 2<].2N*Cu 7a%~瞫v)Jtcb@P2$ Ԅٴ*e"md3^ꆪeQmp-Nw"u'<[ Cwpi :~w>Rŗ'r763O, ċw.ݨ{GJ 0(6}[ 5?7*dXsV 7\N$KA=S +޵-#( 32N$Mq+@V&үi"`mD*˜.:*cozm S+%-v&|RwP 1E/Y:F1mC'*y+U& ylNʇ!̷a`q27 oV~⿪ :awL UǞogDŠ(i58[սqFba_4y9486WJ_97 31!{Wg|h2!n)lӾzNs z`o+xzmLYB%3CQ)(1@JVbAܥ3 ܹ11 Mq}ZQ22zYn> ܊ ci'1pO,;OH^gg~3Fҥ\c@=۴z)g!^h~}`۫c/mHiĂRi.&l}$o譨c,|zHK- .QWڐ8j9(g躅+?;{5Ԝyp@[MVZ _{V<Z(o!B&'k> hu=0Xu %CUpn',< gS\ٜ:GuPȾVu0a7%Y@vNa0je:-g@& ;X dT 5"s}ߠZ2 Oarw!aO$Wo?|>@] fGF?+i&*7PRo;H %JiϣR6З)\(CKN|5CFE˙蹦&Vl#|Rڸ$ޠP!^l\bB&ՅdKrMC։DJP{{'JW0lPo5KDc,aKyjPT`OYwߟsxm{Wr8 nݭ&×O y&Elb=1$ox@Vvc'd[6d>|ebu Nifq`߳eZ];xgQ렗gi̚Be>PbͬQ QEe/ة|6Y`|=6j #&.TCtڔkd(ACVF`ǭZXm-إ4Cû\I<8%]ql}- R~YTBkF:J h B~?[7XV*9X`n*؎hSx2«!ӖIb jEfضw'2w7uY 2.}c9IG}wFP^ߐ 8Up@39ADi'`wKn( " R'DSȭNe 'y\I~|N '.KQ`ۈ 45d*-`CK$p N?Ƿ_k/4uYhKTL9֧LD}޽4Z(h(BN# ̎o-8+Sם1΀&{2Ri34֝wG@Ta%S/tR}|1SVZ-xfq{b90)JglyJ`M)zsEZA<+/"PR`lٲ_!1.E:]_AbDc#/X>i/MnЋ:9a εfzͣ8dpG?6SF$BtӬmzFo!3?"b E ;Ncb,,J3bj`+p`_W%E*Ӌ :1鉆3J#; ^ۋ(ݻytG bdVSf$Ba$EC4Seo+8 &X"_z`pi9bG50!qLP/?# e27ͳ6z9xOp(Lr.j/8~dPJ3A~>ޕV\oܧ@uyy uźtQ8,@Y]G%oY9mz쪕;2+RHhd$s*pXm]^z"3dg.Ȱ%R^ S<'?J{fڑ,A m j-\/+JO@MR&隂m_l{prPy0'' 3MtPW8M`lt\^fBZ0n>B 6WR- |!)m򶊢hL3FӼk/4E=߿Jtu"E-tԇ23n4GmFN#i xgR'J-'Kh ,CQd8tn `}giP+]^ӧmA.LeeJ4Â~ĂH$ E!K٩eRT c7Ab3աOvXy8.(Brg| Γ;aOW:pu ImvB͹FBa^ g[' **cT|q'N14 td)(W2֓6 K{,c'#+K)5{݂ռh~r=D kyaHGt!+fʊ MFB.2z?NÒi O ܰdG. ~kgn7wZ39uBK'L<6/=|SM]F TYC&STP{iL377?z~/~RX[;趁r]0e@ ? @k; pXt9H&N`#ռAQJ5;ԫz,R[jL13VksWVQ8g+m4:&>X'.(^!&V\&&ALG}M8/[@ҝws+ɲ~,MSG+q$Oп9򹦚<NAν7^hS Plݡ)NqEH{e#v,4!9 vWr%?:*PL&<==saɁwViǸa ߲)^hF.Hf%L^:!5@g":~)}IbPe}T%_'Unax{>[alu- ZxʖXؓxxK0lyD}Iwmp\q=Ě?G(ظƸǤWĵ%%ٱҬQ hՁ0)AA}mϗͯo U\y)e] 5Žۋ;^u47d{S2tvA圀J{T\ ;O;‘+oج)H!b }U !o>3^]rJ b 1`߻fq6'4]y2vΦr' D߹f8Ջr-\BFWg]<$UGMI=U ': HųWYYzaY(yb %*x@xT ZYxfUX:4q:xxD^41Q"I,ijkni#@uN/ح*Z!Al|GwzNԪCkPM1kp-39<'K%G6hA]?!~dkQ9K ;QRťKZ89,xΚW-;5ݸ{H`T19,BECpRb=S;.P8IV:? hԦ|rY=|c)k {z4jcͿF4i]`Pf@фٰE<9kse7$w;x-~3JZ$=,)_dLRv:N<[{EkЩ?TkXQ}T)ӒpoD_Pڗ%Tw5}g2g%}hG/z bNWwZЊ6!ZB8.4(~TUP;c碓.o Zo_JؐqJԂEәįtc+O-*'?/ yӳ X&4,j>NOQ{?SN7T6<0~nՕ~6t/q{W&]O U8Q2?}]K\/e-'봅"T-wUC>4j132QI^qF9Q0c,4ps*-hw&nb X̞% _} bn[-\"ށxr~qISCsMЙy"11o,c(U+ [H~BxZ*Kt9B֚<(ȭw*ԝ߷sT.M X8BT2W"Q7J?Hq!X]AڲM@ZSũ0OhLrҎZMS?_`X*O;;N%;)䮔j!b9,=h}Tyͣ^:^ ØyW.m̏M}pʱ$|FVRƃ!2mVW\`8EvL=5?\([M5&XBZH,C5HY>=ȣi׫ތ|1{@eقu ؑ Ftҭg}u4AIH 7b l)5ޅ-5Vq 2wӲTF{qr /tzh߲(9!>#trԁЙ_6'"F4A{:n? (؉ r" m:-h R a⧏Q&>E[*Ӣ3!뉆˪r t:;{$͹Ch;iIUN4hǛigA1A$:w=IӤ*%`2Pb]"GNϚp΄lndqQ $Koyhm=) |uG73]mn&#[᠛͖t,N|ٓ>ք&AXfkB)@=i& <3t&Vy$ԑ!ɷVо^Z;\ծ/m׹w<9C>#dÙ+d**$^#Oh~2h{A G;bhVtDn>naZZ2&ڮ>h^78lRӥw5:*)-ޠVSޘ7q9XB4wA[KHaSGAy'Ƕ[mV_.O؝3΂ wx6 MղΗ>3>hD'4sM!,pRĐ` lӰrB#7^qm"T-JqVR1B sDm#YF,Y"OVny}!vjάO_/ E󘍷CR2 kvr7dZO|ԑ5bpl^gȭAiW;/&( MܳIdIp]:gZ&H6n$\M&S[qKA|ۇ?ŒMU߼1 woScd1Kjg2'_2>ˆ6sD$g, D?L1 c`#.mID7=Pd;~nívMG2?Tϴi.m'ca֜}C@kϤ,N \&S?$<)LAoGM!AZUh"&%}uOW]?Je*E4\&23?O-x 4eB/BgLJBܴ ,o&7δC W}>hPAZ^ v,F5i!Ų,&,t>}M.Y"GhLJ:_:=e^%h~סT,Sv ч?.o¹Ţ ͼugi1Yn>-%) ,r6\;()Äx>:*3R>Ӂc7`&(P36]dZFh)o<µ.<01&|FjڹGh.cR}n%?A3o&/N !hq~·uVʽߛㄎomśhqj4L,>herکhB00yB[/~CVl22f*:Ґ~5dx,;t:f Uj`OKh^z*a]ӓ,X(8ΐ3AӢ`"~n>)Ҍ$BфlQ_p^aX[ N_ 7B1@#.`J@ca}b;R(DBXj8m80wX\b*y1zIpnm'IJj=$tNdN[#t9^`J&uؾ+e> 4`9Զt<p%8LzモͰ?1p<Sr0<-C:d޴(8jV{9s6xYS֜D b|E­K|d\pUv;xlpVyIχb[M U GؿR:G6񪀉2Y23:WJ`HU'7ń̂K-;gW`!a뒅MJCh;裱 *HN 4o8u83 !s@w:=,ܼ9 5[֢MoW ;]p7h;X\#&ͳpEu meZ{hc-Oԏ?`Nn;(Ļz]BZQfzvc.H b ”o|j7%Jx9H# > @LA7*7ȣFwKDi"*Y2H Cҁtam{(5]Bx1aC$S+mig~UQ.I QE25ҔWX-AgS\ګko:4R'EpN^cmٓq;޷iSew;}o} {aY~aC 1E4JY>t8T Jf RO֟ ҥr6^@/D#XvKѕoniz wliSVx jFۆj̫ƯʛtnnXjS{ž BD+#Hk=T\mБp(qJbЍ  n*h&yٌأqh]uMKYWd\x镚K(]4HM>X:jᇇcPG$DyNTfrUD1g]m,wޱ2Y߬$.|QRӂҵ`Ng2YJMJVwi^Wn!#qJdtNاV;v7gy_5* 破@dQ7]'r,1+V(یCj 1t~IUHu0[oUHR p V&DM䘄{Zܠ]PBp(_,e]O"&e1JQɅoNR ٲښ3" |Oaa8{H9 2,EMpHߍޚڸrg$Q6(uV#!UqcwQί}I=DdX-I)V^T3 *SL<mPi.\eUe-=Cr/I w_=W.AY?nj"3i8A 5(Nƀ)8&2H7]Jf)0K|/a"Uܑl BHuMKC/7+DZnByb W~MJOR-n*L!($)SB6g?tD#ʐ 66iXپhꂏCڟl/$ IW;ebWRFx n$q]?ħ#IXn,A'јq6em RQ ˼foqMolnX9R.ME`ܽ(|e!J狢V?Gdu>pIIA#EZZuG`pB2jCYZ-T;We ,QVD8pׅ y QyzWωCzm If(az Ӛ7ǿܓ_厐3?Ht$w]&lpww}n] DmJ2y˱ԹQS@{:M & Mho&HG @UF\e2P|9ُYv*T6qE.\ޫ P 6A 82&lMj?EbJ1ݥ\KhIyQo!['Hw'̡?D7Ա‰epEMu8k[hGbͲqr*}',5r"+1NB7 z$_E t6`8|"[q,.9GX3EDR%мWS5?+!Pޕ܄Y-C.zjqVO6kF1J c|ݑ@cblQ!7Fֆ@7ds`#Dp?mpWr ()F4~8XX8n~E. E&3kY n#%vF}[6AЅaV7$@wgC\*p߽յb2[HixY|Š< +WkJ!>m0#GB&E[Kqt07^q_6] y&C!W[hJ}s$5)=c%;Z4G}w0iQŪWg%_n g~ rWEc.OnBXBdcOC[tAHk6SFҢk%%jUc$ z4;bqQiA&^ԙلǮt+{HcYyGEdumI'*+st_i SKa.$ufk>Y1 $?O^ULW_8<]i*r2؅i\++i(tdQW)*|]\ds:թ0eǐd^Ͼx&>jS)Г0cQov2be 5Ch˳YE9 2P9{Xe c.V+Y~_Hy,ygB.;t" )r7>{ 6{쟘NYAE?=w}*H|5\n%4~`T [Fя0k RںoDT3rb3vb|t4fb*Bx3Qƅ ۖX,`b3h,0*({ S}p`eJ, Ϋb.AyGZ*gQFrNv( )AbbRyj=G93㼏$4y-AWiloN7vRÞ#?SݖpYy I:y@*e)԰H1z\r!aߛyN]ޞ'!o(T|>Epa0&y&aBuM' ʸNy2oc6=_m0 q+OCbU~WYc3K9@+L90uэ?U8}lS8s,u6FyNBq-NOiZo _JyQEǺ+ch|sNR\ {ųQ#R||ݔsy&MPJs):?DI^fDt}̌?^FLP*%4cnK,uk4x^kčj,%nxԘ"qG~L25qf֘NJɛSA^Pto ws"H4,~E)c<͆"71F2yz gp%8?Ì|CQX1E^RH:`@n Lf@qY !}ĵ, ZOp.J QG$^`+)c ôrS%µ3=8=a|M FgNas&vT 98 E H*>O d4=DG_uOPTW򣹠"6EWBڳR#@:૛=3TٰqiD+겾-4,.UK4J-#4!A²Tw'4,6RkJM_@KFo鱢H AAHk=}>o{Gi= gS顉AGE L80>}Q8/AXGlS :rbTtHנr-qgFW; M:fCa]Fbgv? y5 /6dA7ghB2+DB?3_Ʌ=-;!hA$o<WG͘dܼu(Ѧ;[ }ڡ0 cTQRCÔ6lίz,⇔f$Z&f?7t6޸k5KQ[ u2ynPD3)VI-G(]n9T'БY[[1 GvO#=mp~f%]k#7m'ه2|V`V0+ge#HnVhv(; 3gztWy*F*h t<7Ʋ 7?@*}2z&}WOn6xX1GqT?'>sC[%Mg,xÝDV<ė~o9&ޠe#`,OKU,u0ĺr{h1+G 4!edFLEYtϛHFi@8[t@iqhGYsϏ6j&b(p|w葪;tVR<'Zđ9gpAt$pF Nnc=Ui|v\ݢ*mo}SYxSR W|H"ӓ5wnyU%h>&0 ųXb W7^&ݣ)D}| 8`,]htr3?eo >*xKp 2 a5*f:} ;w_S20 LiM&Sd?WuڕtR,!Ufg!iff!iO?މZW|=/h .( >wFqG&N&\䧔g>+Ud uyٮfz2i^oҽA[?FRo .VԞiO_iB\7\]HB<]!+E`_۾?~nͬ>;X:{65Hp@a]_ ;W<׉]9~٧Njz ;ټPY{8oKJi4lJ^F.0VPr M ~}Kb4Ⴛԝeע~̚|Z /2~=heŸÚIjKaA+ k]L1e+/Ȝ=EfoJ  ?M(XmWl\e?4KTB@::` uQkܸN)P !8x H~J=wސM7-ķ~^b%9?Sh^bN.)-""zmyBP>xq8HTYI´F@V+ٰκo1S< AieDg!aL ̲J#<yG"֝A2T['`&HBGra,.ĘOwxŊP=Ψat$YaڦLcR %g /crǚA3x\>61_:-sZ-gP^|MY"NyyX )y`_pLƵ\ J5- tAiPX^{pun,_[OU%bbziQKR׫xRޢ􌥬-N=g;,R!PwQ,LD#jI,hQiZAO ) j >G()(01**<*a)¾˽ jh Ch˦׉83qz'y ׽:6}{NgfWґpFv#x1"q^@"ݬ/pʉ;z| i0@S|-@|O`U@S .mˆvbm>h&}_ @!&WjR,T$lo폼.H^bH_(]"Zqq@zRqI5/<MjAZMW\xjN_BNV w"ÃV=ڡ)j;F Y>% 񭉉睠[ Ȑ2o߾BJ$4"gJX& +6v815 P?cevlPzalkYo2+K 4a`I"?c*뒯ӾHxIu-6WF50~Bl, q^SpbO!`^S ڞ' M1i>Yrna]`efCh ȇ|<2۸Ȁ3s9j("[=ZWG&Llql5Ɍ v6 61a:$ϰgXHWN=Qw% ܫ1mӾT`^9MY!y',s)26Q>9.B¿NlVwi5V0޺xۀj@r$jDrc/8j!3eM[ޥ p qҩ Tj$Znu\:cڙ@M sMY8|NH/tM覇Bohp;ठ۳ീҳg *b|tzM8P0] 'Z:^k N,h`fȌ5aQJ@6;zd kYJʗTN ~/"sXQM{[:Շ&2 g?!PZDh*(l%LEjgd݆&Lv_{?[P eE*K%0Y#t|7f+H+ %r*Br52,9J(#gTdנr9buN\F RGLjXʇmS1m@{utY91!7_٭@dN ?շN+q}Azp -x H^SňN Q?ۨ=WV*7Z&2- {Iz~듦'/3Dܢqoū1@Rki|;8"|` qZKYuufKkpJ:ab䃑LgO+tK%̌#xoZ>+4h\'cYci{+ Y,5?Zc@E ÿ%+6yR6A}5x;x޺{ z@Lt = Pz`TӖUaY5Q ^v;bYm°܀C<){;mrtg'JsHR'J$*m.JLWO>strIAm6[J5z!6 ٟ6c㽽cEc50oz'@|0<qA($E•bD)o<ʭ]2{JMA?T*݈T1w\qDžO/'OXzX $Vs}oiBǘLA!+vQTs[8F]4}!.C/!H]ʵz%PI"2sW:P` ?udBBfDB- #I ȳ97݅;pR$A2~g'G[!.gkʃEQiϫ&ڐ~p7wQnm7V5+p64_=0`1Bjo݂j=)N jv}{ T( D[H)=btM|ՠD}%S@f7(EF%sdኳrq $,測(M!Guh'u91o8ȣ8 Iۂh^srL+uw.հ{R˾$ )/[?_c:S ?SJvᥓ-~i|U" ^e^ET5#20Ab8bQt6#<%/-aN&`>{`Ʃ(/ۙKݪSmM#}{LӍ3F]M fX1%waܱHvg`=j't,,Du\8硬p^4w i띋B$;W[w%g"[NLO!0bKw`Gs>[Gζg4D}t_{܍>4,p11˼Eac /Ɲ8›I3/{nx8[LA"sbiLgw '*o|h@0oLΏ9U"C?#~IFX\|[eKB?}>!?#EkV5򩳭xof*?խ7i 0Gu ^s@IJM)(s-3;5~pl5Ϝ`\2H)r;qk& Ј~T:Q.J6.^'#uY _FАC}.I9dշMa;{Oϓ2<m\}KVV:}ʋ龭{la%iJ}@J0}b(kkN涟N_bh`IU>ndFVG4]=hm=&!ܥv6*AM֏М 6W˃t";+ zC,?]Gp l.ǖLsqq%ja&4`UϜA{6N};#QP$J']eNOE#!)ٻf\2 ݽ5;8dݤr<7wU#Y=nA$pDx1ĬAԮLsO }p ΚB"֓_z%vNg6F>!j(wfZƥU UZɣV/x~K=<^QYc>rIRcutqpУK>ŕ &/M/j^!j;!{z:Ťs9'Uӌ4G[j)0u uI8WaY<Ϊ=<"|*~+ lA!=,;kCx9l 7H _cU75*s>͆O,޾2+0HHK_# ` b=1GM"RNB,đEʤڹ&6<6t &VHc 仙3Yv7]i{i~'$zn&VfcfΔ}tM=Ufp]=grX =)kPC0sP3,YP(*xpHF MmB+yC3V crZYC-rSJR+مS=eRhI=lґ^ j1A ۩TvCO<:'?džn{angd5^:ڦ0C]#\)T}r1RdzaԀʠYAB.eͪ.wTgpiN6D+Tuꛑ{"Z)A_do/㩅Bh"[gT3h_c (b4BLBoe_p$Ԟ/~ Nֻ-wPtMc>u;s“XG=xa2a,MJ1⿳N0Psv%B |f.HMz3o]bēŞV2f*C/>6 aɦ_vHE(kȢ9xrRQ+Ir|cwȞ {~)AJmre>%N.$X ɡGznX2l8AFzݡ ѯDG@Po3\2G0jeO (mLp'ipVzknhTN0Qjޘ܄LivB`$xtFe j9[4Wі4U:=J!4=3۫B rFcwxאLKEsx.k/2nwUXL1YOiD0˝vt&0O7:C5Ryil}@{sl?w*Fu9iθh> OStK8CPjg;ZNt'Q {Hܹ&lk%yTBt`Z. bQ2 룙nd;ʝ˅Z【~iۄݎO@IAI\GAݬ?)4J,`2;f1s#!J ̤&Ih>Z{F$ IAōg ¬{ ڐhUDE4PoO$A!JlIgΪB~b&90`l|S-)|ORcQE^@sLƚ?ma1nAb\@TY|Ix2z,͔t /8@iPѦtͲ؄-pP'kW`>9u fO 8tkjp%gn3Ѳ4U8 nKb) kyF.u3pG.'$Ŕ +(=m0oB2uO6NJS%*8:8q`\B-D 8b[vXV7ߑu amurWjSrjo{إcȱÕLaÉYu m]kia(cWIȖL y S_$ޠ$gS{D=-Cr>KcIW/CRu^+D0pa\tͨ驟vZU%ϩЇ%АXo Pqpy*\YAӀ3 0No׃rxg=`rBM>Ӆ^z8P'c:i VxbKh=|3T]:. G2 IZ思X4k!O`tfҪե? >WL*seg럜M"egNT5[Cy*QACvu&3|zBVYܼ$S! KĔR(X ࠛ)Ż}DQJ,vh)'y$ 5Af=s[ΥYK¬&؂}S$O=Ps BrJ5c#/g%U9i=hq3Kv8a&ܞ48^ѫqXx9;;?kUi3WYcGn8LejxhSfV6)$H./U1ql#w"PfeNc=y+'TԀ?AWI8[w} 5"|2tql 7TIi"*з^AmFei"oWˮ(#`5ZdiHmPGA}*l@"o)ӈTmރRkG3 zT 0Mt+Ebe` u/ؠhaIK'=/xv]0x+G?Sve[Y$NnuDvp5K360DFa{.g# *6H܎+<&ZE2vnR؉$/+6m;qrY\׬:Ul/T ѴL7 fﭫtGrU'4g5H&}H KM;RPLN1=r;f&criܘU~J{d_U 1.Y5R,MtR‚ܡ*Oo.ZtlJۙ^ k)" 5Og0*q{8nޏ6H$7E'iҰM +:K^04v5;V%![aݶ/ĕ":<10f;g9Oj}Y̢N:%ej+i5"(*.~WAD[00u]NF"XC4#dhTL9=qPmZ˿cd-B~}oͫl0v.# `]-r:}~?M)Fb#9ttZ}9r \F}sg=,{R-kGd9`VVK-O e)~0I܇ {D!pY[7u|0}r d dL/(\Xu /u _L34`إچ4L:N T*մj D9 +#S(FCmmA#y~4 /ݹ-Feb(=^5+dBARWtG er.2qx[hOg IX u1Ч,IDcF8Ro-]0~?AGdJCƦW)*]??VXNjll/Y K9hfI`lԭHN(ҚpӅS%|<' +*>RYK=t WFw,+: R'P6D6lMQq#<]Kr^[ک~?N"HqrۜZ?3'}ƪ^r2rܖqWc}ҫJiHd4k5oh "*cdhyA&v)}jT }m['oҵF`ʣ0y(m.F>ȓ|K{J}N^z\#8dK> R1>:iPM(isEtՐ# ۳+ xCH5禃^tiЂ.Z")LJ-8pW⿌}0g4’A&'Ӡ7O6]]s(AL {bpG}0N]ٕ}bvøx >^{s<#QzC<~vQ^@G75q؝l2k-Զz0C^+x#4 CLU3EB̀k\#Oܾ@ Q`MM*ٙT3hQs`Z|77ersV>X@ )Ӝ~'}W^N|0^MPG5D է&c^Z5V>Sg\1㒜^"ݽ/_itq?,jxkR5[wœ* ʭMK~Ǚ[´yAo+|&cW"Pq*NL\tȳ`>DZ<@8{[*>3-J" q͟@S Hӂ>$E3s#R0`۷W۶ 9Z,}s̘#@=ګن3O?y%=KR(ds]zv_+4+Vphz&iJ^ha`؆; 1|PR-".˺Vshē 4X2|;KD #΀6AbpR 0O:M 1:~ݍ8G!+A =01L60m!_ee0;-b*q9ḧ3u579ݙ k>~[0r OZJ eo\}@/,CV)-A8m"_M|&Y\*x%xLrB|miP.d=>U#Iú"vWpMbo6Gw޼_C|(c4ybcB# 5]3(Uj=P5`?$|EԓPo+b68l~\~jN8WOE9j$F.uBFˈ[ 5b1Ͳ?f^P6>S9. !łD[I)oVsvP?d:qH tF؀R=ϙ qd)xMekxӷ=̇ 㲱eD=$&a\9nYy/˭k`:[چRFD$Oay>gPn="Ȩz7念ubvJ(Bc ܭULj}Refg?:.pۚ[~}F7BÄWc#zuuFRXl YJ6'B&I9 נ0I׶x %l9AtzR :a*rO*T7M ?t&outWiJ|͂.FIB6MpP@k(`Z#:#[VVGJy \<n.)ȸ⚿ "Yfv)ڱ ϩz ٠Z| Q;2?0T+osRt7,z+z/I`/ C,|w b.ҷ~U#!' |)\s3ɃAF-tġ#,z裉ꧧޏc{ n5v`~M'`긮4s87L<̦c-|{F8ilw.F ghjmxV̢68 ,z:7]I,$F>ٶݍq夶ޱA0(ΩbZ`ddǮBrR+cjmz=Lk6 e?rp;@[vviz3H@z)E\6Xj[YiՒ|֌4&˱}L|mzs.<+ѹ6nh~juZKP1J_HŞ F=##jLMb9A2`#>A_6o2jp Q9ԡeJ#YΫo} $toi(z01sӭ̞I ^xܠjy)|-`UfG4;Z"hDrJC0 ]g+s8XbןJJv7}GZ3dkݵ `~p`P]-A|Va .J MBC@kkhNH55 e#7v2n'wQ(HnsHIKaQ."Rb Fd#-zue\f^ܹͮvfW  j ձlVz-Dt S 6(\k5F>N js/a-؎G'R[Jʫ=g_erH^ƛgUSn;ק!d@6hW u XTxW9Xl!@̶@zt0ZX>OS"";Pjy|UklT}~ۂwu>@轌—&k5Yus,xY\(E8\,KMqD֗lLHz)4t2!Vi[߈jIUFEZ26Q̀#覭IvܠG 'v1UTT٨[pܜ}[_|uf W$2!\f-L ;.D r ƥ (ci*W]MO) .u7T'&.^9JDg0 X~h[ g{P`οsG:~2O eOleZr4@=(-[z}8| l<%2߻yc8˔% W&t 1:y *v-MZn0Q趥5cѸ≞ a [q]\/&0:%1<å0?#p'PeǑ,/I v^4Ul1+c 5[rۣqfA):,lj YyXZꊐԞ/ ecmmkQ< "ƕaĆZu`|%b7w۽-CnxC5]/C7\`9Qnci6[Z7%isU۝8K 5 ? IQ_Px;BUeOꅭ"_sc#'( 6o# }fL]Wcjkkt$f 7ie`'o{PÏ`Hۀ35~k_\iVVX5F HapSBy>!}*rjvѬz9-0VEQNEes!%_hBԁ[׹$-&WEA9æj26O2sEfےmj]:;=T4n.tpql3RaA!p ~ԅv" &gK^!&a3o$lX`A۬5yЭ w()y3Xx5|,:HDf_5$hB6rq6He2pVle*trjU޾(L f |]b2 8X7H(Ъm0M"KehJrYޖH~'B}g%l޻_Z|!5 Y@6 <+ P :L7V7;SIZL+] um?6hͽCo_+:ϙg&6RREZݮi?*SXRnqwA iwSv1ɜuNNw9quiUyؒQXG6a}#y$pV0ګYqC(f{&ʾLk"uy'i9IL83?xmaˆ}U @.q)`X9I+?6DقY@HgNw.DY9E$؂7^pvXrPl)C7~M70Uvl:'b =%E͂0tA`k(Rx٫6%kk{B[v %D#UDpb2o2O9l oh2QڱKa_Y_M9''2e-LOaJ$ _QO_p W:ƃKzy}b[ܲ߂E\֊21֖{VF%@e잗þj@ހNX!yK9wxhr$ uܨkigJ#&;Y`Nǖ隘;.(!e]^E~ 3%k&[m) ]ЃW@-PzHtXk92T.PѿϳwPA,~QDrͧM3w;640&kh1v屌6MvRX@{l8Vee,QxmVJL . g5[\_Tɨ*JiXa[+j8||QTj\%M)2!ȴ _q~E2+oSOeVJA-JXìH3^3uB6qwe~a,r#8X兄1#WM;IWfG 0ޣx$2ҭC5ڴ*ǚCMS'{ "\æ`p2ju`!d{0aJl#A%W;f:k D#+? МYއ /; ;gOH@Y:q(]gGޠ{cXFeVmIB"K<5&n@FcFާc_UB8Ń+ ]S5 ţȀC&Ϥ×Ws$`53c֞ 7'F0JDنͷ@nQ xc7ATdQɞ]7RvBB#iu-nVק%!6+hQ7IDYqP +5m)-ןԁ%9Q0-FIW14~=QCgwUTB9:h.# eu-35ha"m%4O L Qln AjH3C7My!ĿqhA96DB64Jy&g* bT*bڨ tGj(J2BxNR,Hqg22 aq QY7uk fu:g'LߞfL[.Eo~sTG] mZ8vq[s (fͮqe%P1NPs(݌NZs U{U;PC~'4mI"+f\+_ ⎞R \#)w&R.fxc B.v~Ѫ? /u1*yGwܑ+[nBbbEZQO3+kd b*x.M;A!h?RmcnZeHmdmz|P T@ X,H>:Uk|Os`{ĺ #a@ Y“n~ ,;S\u%c GɩFﭤ|% h.9"DWP* :n_Z"*-7˥ L:R3Z<%_y^oD,^& J* ?C@X[24)o5H2B$:96oH X[lWUfN%SuWV{w1V/Uzm6-gL<:ӽ8*9UhG w7g JT֬7n[Z{1҃drKႾIvr:&NO348D% O8<ϮsJ Y dL0y@I % |p_i~1l*(7{ЈKI' `C|km!D &BAz)}`J8=@`ŕ6)!|Rdd!xkU˹ei#C0 z32zKjqDcƺؗk?8n~UI!% {FU\Ss@[3d&4'w{YXZJHX^l'qqk[jm\&V`.E^uiU6"6idGd{I* xBι tIeafyE>n(5п|@5u X߿7R RA#щARy[P ase>HIV_ 1u b{븋DQ5ޚT!iDj }s.^<8(gij $bc[HZ8l!dߤ`ӭ`,M,Jmn _?b8I:Fq3;|nmcvaYZy[OVj {R0) =H:-zc9gUߴ-,{a=jiRmӭ pN\stM]Nogօ,#@]ҍ騇!vqmbq[}8(TS\~R]2j: }/l/8|o'Ps,S\_b랎aM)~6fF"uwKG z'#R;p'ah5L|L *4t"ZVZ%~S6|[s|.몥Ui^}DQc L5PY0=A=:rWCaSkDv nPr* ~-2e4י^vYW0weՁSYߌڣB=mssJcwfK[P!+`F5>.ֈΉ0_[]Xb.9m _1A~0kg:STJDXFT󧘪nZ'sV7d!9,6_4`_EX,qQtr>_'a!vK@*}VEډ sÅ`ɍ EkJT5nSHjjqiqlm]d!1Yxy\{~ kˮͻ!sx"CETK7P!l |ȼRdBDxzAe{95EBGRmcf.aO- Rj$dÞQDQF (؈[F~Tn`jWn+;Ef!)0,ѶTBE9ib>S]Tr:ieP3QY-I Aes*`t@UdǢ>;: A@CpϠ+>:vm|r='j'>g4wAaIem<۱Zs,Pdo~CaoUxVp,בjrWxlaa(ZeT4[9Xk"iҔ%M;e(D5ߐLG;M.{L_t-)2Nyre wF gafw=߹/ zO=ƐS"8mn,E|㏊0t]:zP;?i߶+/jIEҋy`XZM3eSh8K$x57ejQc5.0uM[;est%!ްrJIqwGthg8UkmT9@z]SST(_ɐ1y&w9Oӯhu"=$gaAK #h0J6/ʌV.Z+Zn.XbCjQIz0)٘˙_1o['*>eI!ދMt aTj3t>d*T.dfE2HWƞc8 .k$r k卡h1|s.}εB\J2ׂ~+|d N/d=u >O5D\0} s gR' ]"Z8q֡%T0$ŧ4+J7^h<l~y4?PHN5 oFYg8H^֣6'։76\T t+"~fP} 9wylȤQy0oOeDcVa oNƉ'(z\DU"P~7d{Ѡ {}h?\q3m\,TOJeJ o64gi{  pF;/%WPc>0z{4>c$g.g nIn݁$BJͦZ,c0Ѧ{DlAĂF3nQD}_ZpDqC t?tWst2/$m~_F;;=Y7N`ԀiXHAeA/WPjޕ/R>E@nu- UND ~%HUBʨuw{f6dqIjïŽDD$†N)>7;8V{00tg>?;ѷTCj8,d0鸀@%?}jF8CSjxkv*@*HV6?oGh854f)Z5> C+\,>?6KT٠g60I4%/4vP]=Cos% 5@=l:fL3ĠmflW7\YB~Zb-Ϧm8͈z(KH -bG~P~HP$jJA q{ToW0<'|gY|j!B2Q06+ 3I 6ܩ^fGR@ g l(A#^Q(qE#̐5q}G{b7YF9;ˍC=7gph,J=-+'2DnؠƠy/Ւ'0F</9 4vE[𖨐= +y.%F틒 b^R> Z9'tçw?Q2-YJ`pC^6IX4rRB&6#j Nd<1kY%ҝn%b$"tXfo& M>6¢XcŧҤĭƒo OO2rQcb4k8<ڛTo1t 5<+͍Z7q6![tT #x 5<5O >߇G9 (k Hefˁv ϗEZ'+ߠ!pΝpzaB8%1sVv2ѳi?>[x*N di;.}(W!rU15iGcl~MIh8yTm4t2X+uN(K v7F2b 4~|!2o`3wlbYvHԶyU9%J[nkgw+.yXգrpMDm7ȴ?fkDeב`Ս,'FZ<@x&nTh(3O* 2fW!}(wQPe$?wV!ؤPI!ꪔlZV^ܺg-ЌMXB sbYscj9<@vC Gw9:D ?[`iVw# CY_ZTaՅ{ߢYSwm:'Ck%üFet"s0]~\R5Q1wmiYi7s +i/Pc]a*=/Θo[UfB0^=So|ؖTl{ }/q[0#C?=p|X] Ìqth>BMÆŤTh,lپ~VSԸqw؁js}~\o>)Y7پFXzE0VC?i &3#Asm#쎚rI5U{.})Ad, !}:/^#4ݓrilf갿9 uV!zɡ8sĒo;ܻ&#H sйr8HcHE OdO͈q& D<'5~C7lkL7@BH[`$i(+bpn5ӫ/ޚ§?yvlcUz9}ΊXz"wJCQ`[tzJOs ` ctV aDs 9`J!Θ|L=`hQߑ@#= |CےbMꯌyKn]ȷXs%puL"yz'#n'EajCkhWt~Z ywn~xn35H楘A_x@è},)u7^_'=ޓ l I,ˁY{Mq$W2 +_k8c& խF ׷T Z, cQܒ -ȦIYf8BѷmU /eb qeCYGw5.?|ZeHk.IE߮!<͵} $ańq+" ·VJҽqp9Q3 LSٱ$ɀZ?e29POcemVdz;Uvr=Q%]H\Rヨ,sbm#2 ^ ©Jq6#pܒaaQUz|J/;P;ﯱ,l/1,L̕.7"P]~vˡLx1;l2*la볊ŸB+ aH[eOh5a2%]Ll"$BHuFI*k5>tlXNP 4e۠-f*]¨J[J h7uJspLdp=i@]kfg|"'^ J0!!kB89\X0 tq^/eU-(׎ȣ\E-PBkUs&\ %IDU.F4{³0(!z*6v} 2@۝{ݍ^ J ̐w1`̚BQ;T~ԫp\V̇"w3l?#>zQqܖud &8\z^-h1*o-{x0TJ : M̱Tkߺ y.;FU@%T)ʯ.(Z6 (YPi'I̢>=S'mj'!fI3lIU+*WT\5*{pQ8=Nt-Z<;M>9#zCEܯM'L.zԱqk];m.4WRˇ Zyҧ89śagH623ʼn*m U@j*4([v}T 8ZT;n".9JZ$ ~u?&?1z1uZȾZঐkr*W3jPප/E3M͓d>n.1`fDP_5Z"* wOrR!Xhy$.RnKʋQB}qD&_210SZ$[HI&<I]oMcRu~8V-]츮3G4iyxzr0=g[f Wƶ~Zp[*,b)ʏBX"c-h]i9ʋjQa'\_leo5O+]c@ed j*` UŜqFPܡZkM$EUh|> E[&]6Ë)XJwWNѐ#%]n̑f|3 "O^.ky W^&~"dcƇ3|Qr RF:9<)ůOz}"2vfv/21DĆMW5ʙ|~}|spN^ -إ~IhOB<[bȣ tRP^fHBpuնFmx"cuqrZ1P,o)ή6ϧ=XRxO JeIcwi1BeB"MRf'ՊGM% ,0qlZ*l7U>˝Uii .DmKbߚ,5D (U>;1"mMQY*#K(8腒 J Fu7ѵhE@Ǥ 1/n.̦i$`t ʊ)-΁B (&ϿȻ}Hjn6X-nl:]O=k vK|[zj'4eL+6`RW?ShtV:v5 07*W:"8~f!uh%tY;,$cz~ nhk# [6S^a:SOϛh&: #DnLXAŷ2{5 ÖX|pѨrQ8UY"I˯Bi+㌟3I)?=~Ԓݹe!Q ?mD)/\&cZF( %3ѹک&3(몪݀M\dV'*oܬ5MSڥzx>Za&-40{FL2 \mEE/џcϟa'G*͘qn#5z/%EޢτY=X&ai*`IgQ3|\(*XZtጋ4M*^D"_ 1p=I{PwovaO_0[ysx9{,vÞKܪZoJyыh|IGcyn6C3QZ\rM补>/]" Wc :}9ds/Yc]UzD!(ke(<5N_neݞ@y32^"Žo(k2Iv@Vӌtklb:gU;ҨQ ]k QR~]/B<OGƑ3[ˍ$Zwj?#Y6"~JN^Bh8bdU{h3f8J0%D=.vD,;<9hV~Sk#@N9RFXУyZRG21<zñL wܰ qU:b&5(6Y@vjKTzy:pS< ْٯnYWhmvs@rԔZv 8$F ƓŁ ï^jjkVw[ha(,-lE{}(rߕdLZOW]3+k,ƴ9Qɯ[2^cSua`;Ħ! LSo"N/灑C1]IT1/lywm{kfc\pt)"?K@-œ '[GD'kRԆ|b)Pz9]܄-y>:Xh(z*Ƴ L%OsZ /![BYjzK%N(UM}cT+~yh 4P4)~+TU=,Ԁό;u0(qM*ǭ=҉}XxqiK}*斷EtR&{YO_E~(Sw hc]͙/bu@2A x*x=E߇Z^@YrZ`o ^r]dAuE8ԲUB)iY+Pv7`w:Gpi@rh>JUG5: <&Ws+B([7|Ž]6a%!c9?w_[? JMBr7ߏ梯)֮Bt̘ݵHS f$-¯9",Ly \4ti.8q]R۲M֪P!$/g&d|}MK51y6hZNywtJCoƄ#jn[KYu!gM*F/ӡ`h(tI {k.*4"v5/_BxM# o>O*u:Ŋ\٩/ӊ!S7jd7㸤ofiGY(0v&- 'зٛQqMuBΙ \bP(Cj^iajѱ@V^r;P*U*1'>`ič9a% shSCQ`su^E3n@; pAnЛa_J pNtԎ6ڞS v[O܏|1fIԂd 3X ނ]eNDnoB:D;tz (~6c|xE&P K3jZ=df`;q噪4j>WBxJ ƱMhGZ2zoQk*G{*2%USO1^ L)0v8u nkNߐ*tVu*%H|i毵%'m@ ;:kX"'}:$ڃy{^5фNZ8T? ewRe_L`}W)鄒52A6_phgrs;BRn8c"fXr%7U\gV]3 M^y7ZѿIۘuC%sN+Qg|.4m3`f uw'[V8>nI{T~@K Qowfh7hCk?g*ߜƔWY3Ckn^{"3 s™fDozw$jmm[u*x\jg25)#yI׮`[HEvHRa9fnG 0r+at0zDuu2kyЛ\NG0ES'З#PS |Z)8Uuu#oq4U% @bC1yfʥVvHCBN5T5bqp/T&*c(Tta%itԦӞ yFN2wLgC/ L (saXżjya+ruĢXVsjr5;ʰx0%K#S U]M*^M n=4=kc{ w^PRHayVR\I.DDqqτٞP/v=#JwkGlHӜWiFgN>*|`Fc*9!J麌!Yn0;i/jp BApxZ, zD%D(l k`H ~'`s'"Iw1Ne(թZurqCP)+WveS4 i?|-{G}o<>y,M-F ױ>e!f# Kg8ªy, nܺK.Թ L0(O^͇&N&b OA4f|"BܚTvqYI'xbʜ-EdeXwb$l^{3H!юqUM+bOqp-4cjkp?N֓N@b" "Q'[0$RȖeCM lPFG.e. `)|1_w2_ ѰEL a8;"1I׎nDE(6U0CA猔80I\ٜhzXhܶs뙎κNtm- M̬WzE;~}w ,.m]pe\y$s)XQI[Guۑ7Lf2k(STmDOX*N6e:/bi56 6O8o:r73MXu!;𻮲8ħ!>VJA9Gτ3ԝv؈x ꠡF}1dtc> kVϾ}_\I|]tF7D7Q4oض<^~0snO#Z51pq'-u7-wϗXyqcb-K&d1Mg<XGeS-jU-h$!sUav@r3?~avhɆT3^k2lļLX+R3cQKY7.R@VXgafv{q} /^/rr`,`P}yEKc@.|\9Wyڿ6;R.ewz^E X}W5Q% ZڲڐMmg})H2!OXQZ4i[;R.ElRwGGV!eE (" hLzYG.(JvUͽ~<}@}k@F hZuKYƤX﵃|y#iNAR{EZ4Ȕ.cyp9)WA#S[*ω# L}O#hcj> ח2r3ٖO $d2˷EUU,LdO'> Uoҭ\,nYC0-MP}Яu}}tol.<44iTG2.\{S׉! l2-JB{"b 8z$@PoL.{];)|@?w&U7*m ^7ٲM֤o}Ķ(Q$uǪ%;Nΐc3tu}瑠1A*csT?AhN|q~(ksIȫt*Yd Zȁz@ɽS<Qiv'ۄtmmc#hKT.x0@oMz 7O48Ut}Oj)lcz!m?Y8C\@ԖSN-H dURLwkᅤP; L3 z;Y?1o،X*0сLwz`^{*YM$&6z9ER ?#i`o^h Z{W1p8TهB,z j{t n1Շ_`+xt Lܖ”.,@0"d/+|4"X[8@D}{0#Qқ9-5/SDRTS-AI}bۑ&Bq e74tG:ѓ/dwj'BSGhă}SHg1ZSRa.X T1q[!lǕ|lu0C9l?ŃbN}"pd1ɾ/N$KdXt\fBPb裧c!o#3R.!5⼿|zv{(=azͰ18$T t=rf g;2s:IK;unbzz@K׻iHZZD$z[Ӣ> iC!ZN@=8iYe>$U`a1a/eaܫx#@ V̔g(D):1*ew){Q<@qrxB3|oOWݘ憞t}"c\:0yEOEU*"S[gQ7Ȕⳋla> \֑)C0،00DXj kR[Q>1 8غK^B(o6y ẇ_}JX{|}wEY$74t/)m(mA7i ^a3nnWbNkZtlI';'5+g+jGwQf*p(K#moiơˠCQS7Ul3lۣ0" 6@OABtĆ,Us󡲲:@óU֞I˙yC|{K J% <~ !\}ݳ5lT=# ܲ(;`4}~^b)"q eS嵺1)ӍBJ3(Foܞhܞ(*ަ,kx 6BgC46l%9h#N5WK5RM;WݮBeɑ2Ԟ389W7DJ;6/B>MX~!?9y [uj:= g2=+g>yjk ( \7 }mN9@}ֲtUK1Yi:?`#9dlS=V8ϕطfwD$z{d+ JyUy}b2T^~zFl3 ^KlK(8HhBc9\ǪUisqnhlϮ V6ݙjgD $2qvȼ=h-UE,9`w󢯑JeIݴK[8 mz ˌ۔E;=9(Zhݻu*:% ౩h(^x=G>uo Y4(|&Qqokr$ µ'|haWÖ_8q ώsFQoS7x^ԕ\)S 5w%;d~OWN ]ԙk U aP-0r58`E~MΑrpL{ #ET8k!]y&4 tE /AB"I2`琋t3hE&pMKFEqGT nn#3գkD ҆؟o?rymOD N_IITR>1w:/#i<7yȥ1,<,@Ԓ8텾"vR : N>FKlq|\#4lX;LTrY&9bݵ#BU%Pu*#ze@+m9Iy1WUNsm? >bNB+ 8؛滐C}P Ims،6˩rAƢOg6rAaG`fl#}%BYRfޔ!Lbp0ҩ'nZzq/f&JIc`_pu_W'a Tsf8 Z ޿Q˗CɮDNauн>/'(DrIkuLQ#B=נa13Ƒ}H[c;i ι*%:Y+M؍/^ݱuil %5A[NǮ#u xnɞ#&6c`G|3 S*ݍ]։>ic(E_(@˓K{mCBTp4n`?݊r}YŗH+MĔk3т_:I@ojb:ڑGQsEm)l!?8`P/|ho.b8xיp[jKz5VpTٍe_WR QrV $[*7x$?vM=?u[4>lm{z* *Mj9I9??=jk[D`O/jckŲ+k֑(񜙩=R2#O8 K/=߼A5?ɄPD˧tLeDji|f,Po.>@)x(L-b=jμp.[GHHC+9,{IӅrU76PI B.&VIj=kUo6(ėB. # VTL~Ѯ@cr 2姓œ??a1R]+|L]vSyD=f 8od&gwSS(zA[Վl0EG5M v"%UT)lپ"܆g>UȟKH4 TG3rtϑRE l] >*bp6͏OMTHbF8r82Iɛ=tdz❩A6H_ 4kFO LbeG@%ca @.j._6D~@+xǫK9nIp:B¶TPYhfv[^_4/VD>.#e+ctyg{5c6#iJ ] P~K8eMVD\)^ cSeBWy1ݘ%CM`v\0hG'r10ӒFI\T#1 ^@삭u'YG 5{*J6Xb8ʗTbU7 usz[ݞwudOУ.U7ɪi Vʼn9ze[q2{fc?{9]G4bAvy ^d47T*jlNw~#jY<] h_8z!p9g~>=1D ](ĒwDb7%3%w;=Rؙ𛽵v-}rzE̿m̪fk&a"/Kv:̡~ |?@1Yx=~ܺCQ7rCBϣg 13Rh~7z G=Fz6뷰f=]#iTv{B# ǖX_zU<آ KYF2Ow Ss"%/6ݼQݣ{P~t q3Q Rx-$0Rik _fvQ *> 8zFAж1u>yv3Ua:(g4N/ݳf 'kb=/ߩќepy^&q&-U mOLbƷCٺ32$Ja@V/ 55HBN%sw :Ըdu]gv=R+K$ -C}![:ERA ,q gY8+EEJJY6O4vQ)gf L$:T֝iSUx;bSIכ җm55%CAȦpW]>w~֡S*G'FC No ~~:)\yHo^?便W -uVJ,6h.-MsJlhO[ Bk9 ;< mgOGEu؟m(yj(#aZ'+e~2cadS5F▜G-Tc IN[MHswXK][@*drppS1K)Tl*;T=gSZ.M IT{ކAⅆU^h>M#WhJ\5V@X!mlzV%Yj9,.AU@J+u_ rs b0?Xw?XF8Ƥ `8|>&U|^X=0^="Rd؝S%v~<ۣӡƣj7@%p2\~y`Z(ܡF' L4RxhHLt8K pߛCӳhMGCe,i\#L#3X=nndJ~7<핊0Kޟ?۠OHxűrkєA0~:Ù${*eNIzWZ!}(a9%A;ɾlՄ|\s[k-JG9 Kt~\kE d\XV#$_;S.x"Ci;G\oڛ#BeH4K6Wz8W.q @^4᫥瓨Lo#I5QFB0 w%yqButPE5=Im3}w&CR`n2 c 2AҸ #9h :zu dsZs5ŊN9ԁ`f[o%c琢pa<1Ya-bNS"Nh߱j}l+#5dMAS]hͭ0nV&2QwYB JKT[C['yd$7ιs~SX41,)<^';; P5/mdmҭxRDOe?L<bd/oA}HMd]nN9Y^ҎcV7_$f#=72i%#j#t{Ax =υ*v%pob* .*G 'eWW:@A(F,pfGQ난74P.Z?tLkVN'*s6נf0y-a6ۛ!)\44S:K9k0guhRCjzbw 3 `n UZۣsx>F%Op&c'ku)N?cn'#n\`c y=]TD4'UW*=s+aӨ>/,(ٗ10X\5v=,B|d'Hy꧓Qn>iAДvH{ΐt%OȽ=vIi/L5H֪M֎zKyxRՒb74y&SPϪ/`'X@/Ѷ>oDc2<ɴ>";?( M[={#<4R%g iZ?tÍU֒sioz"C/ $мY;~UmT[yd ia#Ntt^>w W;RO:ȯrSOH>ԁ$Gm`؁oEfu4^ƋPN7ZlCЫ\V2q1! y*$`xlH8H%=BFpճ yCxyCLHOIZ*d=VnH@-W{)AJh8{79\B <i[O/* ઃl~_ U&@OgMuLZsܑ2MS}\ ξ:kޕcN{2kɕ*d{K9ܪ&I`a8<1;ѣ/<@4•W'J,~< s_ K 8-7TmDw1qhy:ƽr|FPWTŦLцp4ʇœb&Kz4}=V&iFD=Ue5Un/Ulv#C4 neҳ%lo01ڄX\6>=-rJtF"SPaƯ)F34g*yLZ#3k߶I[Ѿ 򸈱ӗamb(,]6] eFQpL%KlObmU8^Ke=ٷ}d&oϥCrd= 3%vPuV\s7NYҾ !qa$3=*4xrtS\(C/%c%fs槳I_wN<}=(6bzEZ2L1/p.a$Ƒ&cSI 56B_di|HDlНL:ŧ2Y]#\8㳙'vS-^f C\AQr]g2*I%yyטIqAc4 ՙyY~[h=6Agi ߙEE$u杞Ln]0&)=؀ח I+YBc+BrMq_Um,X#<18Gg,:Qk!.W]͚'8+;3i("9,|G8 OQ~\Ù˴؛;Lޣ$z$9m?ՏShiJ?״jHHd^Z 1,poZnMOk4-+eg9אK5O2q- B\(0׋Ș^<杭QAٝ˺/ 麬#(Z~_ CZ;Sh'Wŏ;T; #-t,[02J˜qFf5M.{E1!]F?M%8\鵒4urڢS͘,@f>P-Ӥ<\5uuH̔N7;!,Ou޼dRIx$EL(oq îcܲşKJ_Tg/ te]~0^ d,`CZV ǘp/Cp<E6C~F;W)g"=ՐFhI%P9=>3:ZBs3YsęK6उ6"/2FwKmx~}{ѐm栢9]8&Sg?!^*Qm+f*q݋!Ike}l?.ծ3:.|; Hh SEW+[]R2ZΡ &^=\Mʦ߳[\Go]eU>]4ٻ-~Ǜ6k[:;}mj1ŅU6KR(X!kj~&wSQESmnr9.)ʭ홐7YB1$JE됶WR(VFc>|z1ap4ATc @)~"'$БpP0R}i yK*_:ztbr^ ,))\Ҹ RnB䑇} 9|=ez|гEE^l>]c&'JG%#rY ?dg? +oL JjmUᑃ{_N[,t ? Sp!JUXx)RqsGFBG4H#?qpB+v$ct_K@ekGobGf"޲5#KD@\C v yGĕD1/9gr)i-JjSENT;TN`}?X-w1jSLP! hFI dx[-K[qAYF}O2[a*xZ)2珐 ߮ڎsql7I\G00<>.<:V辘|GAl83N8+epɤPمFT>^Fʢr VI߻1N=WD'@K:yY+9u FRPQa}^{`OձA4\οhŜUC*uM0] ZTJcב[׋JW`~ѓl*tGzĖX.Cixg2 hKdӍH(*a֜{g,"B5ϛ`' K 9Va惺qyWw/fđk,M荔}v0Sq1b/ bl׋eG |ϭ}LF[y7#IOh=B/Q7*&f`9[KP`WC~Q&u*2weDB hu " Ga0AK4bgΖYhQ:A`_"sLQޣRfM@ΛXb`*2Zvr16U*cK5R:R갦ٝ] w>B}1"&` /({;#) k}J^0P:ICu<ړkb! {9HTfƲؖS3S*RtVwx +)O \,KHCPHU_jnvITʔ@_SqӯFz|%kwT`V-?yG^oy@kM4s`djŧ "ҋd2!X k]F.2k~Odl:97O]`y]?Rsl':zJzudDQr&롺%? /^i`T?ވI1%b@y #Lv\i^2QԄ3o}^  @j#E -AR<ӍF+a$Ӿ<[gJn$9]UjE|ʽH|ʸiP90':UN1f~{3&s! qJ!!& xr0M!]@[-">O 4/-{ ~`:}w07{ƳR$h!~gĜ -.uNu"-CP~$.xX a v*]8|\ѰHG P>ر(!"ʱx,U7E(-B!\0̤sg?5g!iz" 'iV \TZ_jbFY{BK [o@" srxӅ#VB\a o/͵t6vNwṰYDu'=s؆niz8k,Rdj_b 51cyԹw-{M ~KԚ!,s&3mtf> _trd_!-OfF{+BcT=C[T)INNnᒕʩqDSw.wޝV ixtk% W#12 &z Ӟ۠Zˇa+At}C{i&><_wә,m_9 VH|3K8_\fg,Acأ?v<i:PNߘ /=Uo}1> e} =$jGucj(j2Q(k#=W:nE`BgV-gsԻ2>[ ߜ^5`Kw)\blҽ}{~ T&hH׶G͏wV' (Gae ]{BOUߵ+;䍜E ^ͺҿbŮ 3Z6} v'iXz<6SK57i5ȴߏS5ؠ$MVrMpG! 4X[;SA7Am|daZHD3`ydⱀPʃ~4!跋4fC=SfƌZ^Q[Z]ŏKY#9i' @]?Eo/YK$|)Wy՗_`nmP_jY֍@R:rgl&9A =XV~7`z)C/{KȋI;PJ !avx$>;y]ًu #s~ tYe@Lh< cm_]Z 3,1HQRYr Y,1v-ui0 ''jg%Bci6; [x˔ |U,Umз%zb1R5K1h_sU%>C"HՉ_CWU!U #;`׋:;+HO=SUf^7gfQf:[0 /JB _+c3}3Lh V4!ILW4"$ Ҷ0vV9 j*ۈ<) T:|)=N"pK-)5Q .(㴣WW6Z+򠱩SEzaY#WJJ{wXFRc ({t(&鈸@^3uu#lD)D#n` G-ϕQJhRN*[R ϲL,~0$ȿ$6:Jk=Seǿ\PO?j0s?Ĭիhʥe k7.@vLC';[ci$%D I%XAcZ2%u@"_&-mv?'FoK)GZ"_ߗ)gq^#,wnf8 v†YcϱNۉÿuICB-UXx쩸*ŷ-ٛ?T~zkޯK, 5c\\q1$g8I}cCS%D'rq)%t&eH $S+} I3ASvg. 1Cgr,Skuu{ca#l[߀2}-3748 VI(I( 1lh=g>(כ(=ccz@xwJ;a P藳!,I"XgZw_fNvwZuiwv ^Lc>h$W$ߙTU} [$¥GׄfAo {!푨]ܣ%M]Cy2bgi%:Rqq \-28߃_<3f['@ҍJTb$76w@^Vw -IT-Xf^zzep,9b5+OI )+ 4\al|%Q9C3.Z2XIsa >vno4F/_x%מD^K^^6: <+TUe7#`P :76h-Jʗg0o<lpFo6K^+W?szܹص:WeZN@2t{D}~3iM>8!`#0tg> Jv;Euf Ɛ1  +&͖ھ|0F8*ok6_Г0 . +EHE:o}: [BoSOUIZq_ u1k$3τni=׶oOzE9> kA|5+m ć"P̜`M[~և;rSЁIhju%wTXӫEFݏ++'==m8.M~qSW? g?d::#FyZI[i W}mve:Ü=rfre1l_<]UR$=6 Xyq0"3Ғ? QKRmTزUW h yܼ+#rM&d.+|i/EYN4w?ºL`6Uz9.gl1F|\%Ns4<7AOx`;@ ,oa(J POZIg%uG_"3 4rTv~CNG)(pՑ i˕Xș,;.`ۮiu)e׾]vʻ"Crum<*%ȇ9#bْtvJd}PFLYށ0f' 퐆0zOC)3p?GeYup/"P1]FwUROV珀̼MĢ*ҽq[qgx@v*>I fbM<>ny*I/>.C9̑W"`)'L:k)}%r1I26  DaQ6TV̱b95I07($sN(e"v'e4Z#`mۄCsYNJuOyNzͺ\iW eh _+1N}Q ]֎Ţt=inlMk~HI:45/x^慠.|eiy3ֵ.ą%D1^Y3խ1i,b9r00q&G\Q"MA|Mzo(i #Rs~Q]=U#ڷѬ" kUen| ұ\j'mns?:}K`M4'_B.`S>HpD IݜܛSz-Z&0whl%_R*$LEK K>5 j iA=|7B͹Ƃ>s'c`` QCNҽ*2-/߄xJXbE b܃չ4_[Rlri8uz]*@!ZGֿwHBM&dg :D)XmV# v1D>SdOteyԥeLeo5ĂV>xu 4fsxޛ \\7h}oK X[2xui{-;h`҃XlS"[3Acu! HJxjn\u_7יEuA=Mݶ> 't* Q&3e:-GE╌7RDe˵MbH:sWw ?I1 ڠFO@![0X-5.|q<9:s5:D0\+anax;V:'b>6 Wan{aA5K<坱J3={+wǦM2%^Ktnk!p>v+Aq5^ _d/ˌ_6ddTTE;%sEs3ƔT< B mD3ɒP!'x/!tWm~HɴFUtQ"ہJ7]*B;…@~7  iRa[식g#/" !xdܼ0? ǖ&ZFX6\UXo+Qe'vU!i+[㍢OlB[ňp ^iC\EU͵!8XɯNT)j@-iPJK;韼wKJm^'.X.dF$E¦g{P&8_mi8*3e»t=*;XR ~ ,O\ ?'>>pl׎PM&'@ڭa𣲙6#x"TA>[(Po`b.K,X-v`&8i'%;f%dp >{H@e!Ͼ94nc4=Z;B[E(Ԟ. ˳fK~n6^W^@B4HP4is*ڄ~l p0x(Ãp 0+,./r˭7z_~IͺWΐn9,K7L(_D2̓CG]畟va!Ԫs2wm<&x WGb/Te oP'a>d7e?TEc Fd(ïKu+]h-xd$raP=#Fi+h _7[KP̊Y=2+L) ^H4M$"Q^wNN-ZCy{0ҿyQWRn?P|[R#0Rfl`!X $-8ǖi1x: YZ