pki-ca-10.5.17-6.el7> H HtxHF^< ?*}}og>TYzc"b@+' ݁T 3e2229c85123ee4733892d9fe214640dc37e5e5b&'HS8L݈F^< ?*}}S 8?d   B          > D Ldd d ld d nd q dvd}ddHP t ( (V8`9X:G`dHf4dIkdXm(Ym,\m<d]rd^4bde f#l%t@dudv` wdx4dCpki-ca10.5.176.el7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.^$Scientific LinuxScientific LinuxGPLv2Scientific LinuxSystem Environment/Daemons{L)@1l[#t#1J6 ] S }F}F+ g%~~[G7(b)e%{xZ_,,zb+z 0foxJ76'P8bu}E% *S*L$,kI,A,:+A+3&u9 ;#%##"vSy "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q  dF r- ~-d>Ed,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤^]S ^^^^L^^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ^^^]S ]S ^]S ]S ]S ^^^^^^^^^]S ]S ^]S ^]S ]S ]S ]S ]S ]S ]S ^]S ]S ^]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ^]S ]S ]S ]S ^]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S ]S d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e10a6e5f84427dd59080c4531e9b593ec90a428b6dc9efe781e05da36c7be1c489341ad74a7e119b4577661ebb446d01817e3f85ca2f328d3104443a75f9adb720c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c82a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69ab635b3107b5f152b0d109c594d30b345a411367f6225df121e338c02536f4dfd9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b1dd2dc066f3dc6e0a46b42f17b9fa4c739b1cbf2c27cc9197f6900945a14f7207dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c208143ceadf7a4386c8b19a8dae483ad52f07039a7f985a5a012116a83883e9d4b788f7a808a87edef183779c0d3a4609363857aa1c21aacb86257582c018280d9d2cfc0e1f19c31633f0c71cca13eda286d22f389ce2bebcf1d29d022c94a9b98ccec6ab0adfb82d3929e5d571d2157ef9a4f77464b001ce8efc8319164394d24cc15bf06ff8deef0927b695d326de82058ba233500878642d560d2bc0bde3ebe95a1c60cc56866c750a59a70c6c134ea6459a77a973abc6953b85309f450a0225274f6866c00a09bc7b40baef850cc8c932dd5ec5b3666c1854665fc8314f568fe5c75ff340c4644dc3499e6b91f1321a1e4ce4f3dd892e93d10b3ca6cd22b741cde4e4825e5c30f60418a624f71213672f8040d0abce578035e96d3cfa8de606de27d407a3f3e9a4650c1c1b49be68239732577372cf2638f71daecd3d9292b015b7cfeac0813d63b114d76e67a8c22c532fb7f106404980376d572db56a38d141c99eb75104d02d3384b36b75f08d4d13f4cf24e42364783df0678c22541bf7e72fc1b0d55c2c7c01b8a0431a070a2410fca6f1c57e22fd46e46ca8d70c901d805f3129d3d149048bca7afff85777cf6f6b502dfc4253a442b2f7a9b00f0d5b1cb51d5103d982fe861db8608b9edb8e6a32969827fe15e870062c2098dcfbdfb0449d1ca26f2daaae39a9311c9fa0dd5b893f2d5129603101c157a5fb796c27d5f9419ea7524076f8a57670bc6f788415eb5690027ef28cc39ce90569d3380048f939487192af8665cda4b1b35b3dfea4a1c88a3fa4f052a3bc35163175399b6e65e4554f66f7d822b2a27361c9c86c7c9560a3c110f75fdbe0439a989bce076df1d2b34c197e900b7b4d2e0476aece85deb1df7d3f3e3740c40a7701995a24819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d4f27679bdb8f5e22e5f5623a74dbcda8215e1909aec6d2505892815dbd40c28931a3aa4dc5921c73ba193f68279daae894ef8af35f159e5ddada1e021aad9e9667a9c2f38efb90b6c24f51d41dbee3f3c346121658f5684e87d429c23a5bc49642b2003d3f805f392607559ed637c22974104ae7d4b5b88b111123db4809082d0f8ee5de3a92fef6b095b834c2dd5ec6c40df918fac07d177bbf434d2b510579dfe269c7f1960df6caedc2f3692eee7091fe359a17bd5559408927e255d762599d4b4655eecc878c1f117bff3640f17544c97364564e4b8e1131f647469468ac8b98bae2e037dcbef1de8eb0f38442e4c7dc024cc5da72898d19f68b8c50297d95b807591f098bd9a92be058f06cd18e076c431b88352201c21d594372d91c650c283fff6879a0b3247f04440a68d98a9deaad95fb463171008420832e7887c33a299c24ef69dd7310d4cb5f802827678c6d7ad7416ac1650da7ededdd1e91128e35e898cc31c4fed5f61bc2e2cb1ec2684aaab5f4a94b3cc5e84d42a84ba57d7d2d050b1ac4574a95547657812d919aa67d3cc17fad85c654e07bb16d8e5626a15b3831ae5fca439f780bc42ea11a05c5cdace1aee43a44102d7464f99f5f4a9f410e0c510402b3afee5025043ed21d22539fa3c0ee158306802cc6a503704a7b2e29c02f8f828bc173cde8a4c84b3b89b5ba563e2971d788f0457431e48b037a2ba523a398b6eef9396b5742d8aa7836133ecf70521ba6fb92bcbd6bf9ccc1abba3f9952ad3f8b9607d631b7c81eb29c8a67291ede8108d056535e598eb1bfe09e39d96c5dbad89b4150cde9f1a03f197b83ca2e4cc50edf44962834813f62a01fe68f324ff4944b30313f9a3e5c5653aae04dbfb1f6c6103de05fe49412fa73129b301e02d384032f942e8f6230fa47c38e2d46a139cf67edfea801e6e2cb9d4dc74c7f55a5fa8279332a8d9d9b14a2064536946e146ef6f13e47ea8882c61bdb1b53aa72d0876c47446ce5720c0254a1169c9715dd1ed7e38beb6d5989320ddcabe2e59a209706beacd214bd086484765ec380d412eca3e8e8d94168387f25227f78f8984070a35f6d12dbaa53b68db1f959601d93cd4116518abe99ab7dcc55fa24ef8f29cb36fc3efc8d31433c21da3cdc7d34b9419be658f77b1679883b53475e19ac1d885575ed8fd1f57b816fa4c39ad963db7af6201cef60c2212bcb9b1264e5b18901a9d6564d44486b891f48e7eab808db0b4657882b46208bb6ac06404bec58bc67603c82f5aa843f8d6a0932888960673ccaff71f3a56334c73021a9cd152d5f2f45cd84d76d5d9b2012793b7cf442bc9b59229542b1abe7c1c069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f68798e2619ed8cbabd811ee5c8d0ca7e626402ca55f2c3fa970f32ab7c316b2a8d5d4d69a75b878b4e1946387fa6a3706d02ea456fe19b71853b81a878b883dda336b0d4dd3d7f01030b858e33670175f53907a29f8274650e18882b6d66b764f3f75cf53c764ffbcb836b094b4e17ce7756752c89cfa1f737754e7a643f5e988ecc541a4aad51af047ec1e4d89e6d0b466a2b4b5c693aa295649d4c4bc3d716c9397ef5d9b0f4d416a8bdf8f4f0c2e8fcb6a2af6e77b23b916b1c96a1a203633f0bbd917d2bf9eb5a64b45b7deb287801a3468ce15c19c3abc1a8658a66b78ee0b0199ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018feecf3d85f33ab93a1a8eda5c558d6b58645d65a16f751ba49cd2f38d722f7f194a8f0e34e2bfc62b110b7684acbc69634cb1f3bcf794758933c1473a7c76ce5636f3c0e875934735735e2db4672ec26b0aecd71513a79bed49c7b7ea5c5cd37f8ee461c0b933bba0823e8cd935dce4511eaa3c9eadb61383dd9912cead9ff1ebea43bd42c72c877ce5b21fb4116fca2e25685173e25371b56d4164d378dd8784f0953d6e2c6c8829a2ce64212275c8ae0b5c8bf1c111a1f0aa4de5c57595fe23eaef3d7f0b60a6f59f1d19ed845bb8eb80999b8d5f95e01c28f8a027ed715ee2e70f196246ff270db8566b5229dcd8c978fbfdd8f45970bf5c940ee56ac2266819112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617daad735276d8f629cb6936827ba522b93d7c51e58390c8c1684fa41cfd7868114935a11ddd421f4f82e7bdef41b3a248dd3c2276ff47446295aa34a1effb6e8e67e6342a29b068d647a27a919928efd5f2b1d22b27fde5aea876d77b345912d7867773345a21b121518fe70a56bdc8c7683cd6883b74781267b6223503405827dfe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6abf19d91086ce880a7a6bd91c1a5bf27c0c3d01e4e646f7617136f75c6876ba7e9bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.17-6.el7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.17-6.el73.0.4-14.6.0-14.0-15.2-14.11.3]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru Koneru S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in ''.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by '' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by '' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by '' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. ( &  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd10.5.17-6.el7    pki-ca-10.5.17LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profiledb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.pro -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !X] crt:bLL'bRP60/)C%:Ť }:YSdSLprlq mZPyŃ&LRڧ 2*i̚ x(s$b2{S-`y$^?Fr<'Od:ދ`Yݥ+LQ EI7PS"(+Pۢ'ΝT$`}_ؿRgsڝBE`1jYęL[׼87 }>4fͷA^TrJMCD@mj 桰 !WE?fB\8iRW}P]o3yky;:MOYO l³d}Pl"?(q F9YP(޳EʗĈ ST`Dp?['>զ/պii/a5gƤxul"qʎ-BJzL?ChW8r_$a(A24'7ߺli\=c&ahGi_(Ж`EXtU;_)!–*v& Vۭ&V1N-?&Mwu+^;cvY}9H1l4lwз_T$^]ҳIN,~4Ў,R `;ցDCn@4z+dx|  Ÿ3aN, c}DLfبnr6nR=k:ᶴ@\)`Gjŭ4K 㮡̑#>2_(5iO7ȧ/h ,Ṳ`s{kgi,»"B7T6&h1ɝ">'4p%e&Y/\κCmΖ1kK>77#Ŭ+WI9t4 %^݈kDkmM>JWfΥ>Z^̱P.|*~%2"ńǩV {+Yڈ~dQ@ٍ٩gڽM)TiC.OK96 LBKED =)Byzt^""ѝY"~ יq]~1T7CZ\l=3&8ևI2U\ u^VʤUQδX?TpF<B ]$ĿWM4 Np-Ifo?799o>23S!:GP LɎp86{W@K'Ds& q8 =O|σɈm)SVQgBKA]D(8 k>eԱVqw8r[jr 'Q/_ߩ^~j/6R^VNf5WZ%e5:&XI;ji<\]nL,,J!48 On˧^.S/-뛄Pԟ$W`7CHf]>.ڈ :SYX"4zgӞ/Kkyأ"g鬝 m&yw/ fY.w>H % P08\}rysAfͮSG %F%J6R#fnA}/Q2P1j'.A:֋j~|KWx1?&:]Eݓ:6!1D4R,L3ZMaWajNtlW'MB,&siʽT*{s:=t_C#0z_*Q㓒?Pkw`BgH5 uvrzLx XC^QCn76&xKhځ\B>Vx{$o+IOB4~Jٝ;EW-$S6_-KG.7 ~.#~ר6L*N 'D/]#6%i>Gv؜6osqN|lՍ4H!`6WRY5fg:ʳ?<#rݺ3,7|<d2(:.}t41C|U"sn,YzޞpmݵA=&>J-IkF]w\-X2ץ)j]:%wo ̫gbR!եnA#yD ^b9mh)†dZd<HP (@VG`gycdp̸>CFC#?~r (C =d{x`LoIj5- >8[Pé{"]2g .I?%&<$E£8XW|ђ*|;TzTI/Ò!!oJҭd *TY*8_|{4uŅ96ef]v.>?AϯL.B {|fm{D1`mLگ\1~ڬ3k?~i;_p۾(/k'J^:YƉ~DX3S)xE&ZNN<9a7U(x.P"eoVPHjV<J]o\8F]DvK1,k)XNDܼ<(]d&ع`] De=fpL8S Sǖ/LN~o9b iX Ii1bGiNl+P~;vBT-J®6BLM; cy˺$xFm /lģ 5c&C H:8F~'-r%WpX3 2LR=qDsYWrnOV MA$ZGax/@#h6WP[BE9[kkaP=?5/~'nXmS*YgQf Y(3xWfP;LNiKm> d q YK?7IykɅ$MV7Wi vr? ae|D&F:7Xt O^+?K^z4 ~%QRGm6X@1Ý4*A%>;p܎FE;^XTM&:3GFݳYS(M;7kSANݍԬ$ +Š^ytbBZd,f;ߺ19ln :Bh{%kBzwj-SAזIތxKV69A<32*H#zz߿M]Γv?H,q X.~iG.3,vA3V4Ӕř('[E:)+Lt㍒ ;BHꂝȁJ6Z?EaǷQCgIq$,#U|+DvHgסV_ ka.*E6v ,3b=5ӱO1ʱ:rX:X`zҹ<34خQIH@~:VV}(x#v,'0tɑ=PaS>-s! gF(/. aq` F]Q_~c)iaeHJHu1RH2}%zP<[m禳x`r((zHK_B3]rH\NZ2vi˅GOJ#?v{Mx@OO3JO#w``$eg|sџ24#U]CvV)ܕIZR*44 Took$}Fz%@PP) z#p!Xȷ{_x-BK3pdm.op\Sj,fk`UɶEU_q@PbrW3`o%vQ%;8BW~Ő4 SVrEe"ޭwgfot O/@TfuFx/rL V'}_CFD)!o+G{*wkq{FO" mh2I<,J E5 #( k㊻c,kUWVU&]SY^F B(sw|>H~V8fd g eYt݁^-t1I/`\6:IZo0WRcjY+ʁ.l5o=7]v3w8 %Nr}٩l_uFkkT8?:1SZt\JTvr~q?I㴼dQx1z~~e#zEi]HRr4d)D+[:WB.s dc1?]pJqQ'Yh,qY.aW@i Έ s~V`%w:Fo^R| y 1BVN){q\"4rD n~@_i#ZCza &9;D 6{֚?3̯h&RC^(8C9O*MշYm/W$LFSp:2HDB(\csF_B3W>&}l,7n[8Qd*C )e}>cyÂnù5\z:_a{$HΊ}@,VYY׻39A)\^3ҏ[U 46zD1p ng]z,G%1.5n"xe{9ډf~c_klTç<+W20t A â7T3!u~_P1rW4=a][k/h6 Aڞ҃)ܠ9v1l- WԸEb_cḵ2,{Ty N^Bӏ] 9I]3|ayj,ެrz^UlO&A; i=[TT>zg*ǵw.p_΅!l. $kxL"]<{ =V>Ǻ="t8` a1*mË@;Ɲ \R0dGf%ҙ00:;@ 9!jzyW*isa׃0l8cxogp#h ҉>SlάKblMkGQD SPT݁y oK7-D-I`wG-LO7@H̪3m^Df%e:nc*YQW^L3Y7}q̸kG%4U_:eD}WF 嗂;,H]\<*a6o/ A>e+}Č+F*N#s(1_KE(|-xV_*3WF~Z_\ S24bQ~OW[P) ;xNזl|P(jp!D3KlQ$!6ٯF)& _< JlfȘ̉d4/W].eSyq.Xar 8gϚh2GK ih?%D r#:?Y݈LkkQ+\!u8LčԩP8pKPU* q{yG>0 cG5jvgsz: x$Bv1 Eq[Qf#Lɏ2mG9bBI ofjOnegW@K]ڜN2[#Y RLO%BQ]FB]-D֧NV!92reCRەpl76Y쩃`:;jvk 3D@!i7PtEm-&W1yJW9zX],W-1*uDV6j'թK H13GR3{aMJr;ru #W1:;eoIl QF(@5Ro(bE D6cw~`!>.J(P(l nDZ[t2SR,wfz*<xI/0w[LY"Ck+gj`(Q ̈́7GuC#Sn M+ɺgMz-;s{ Wn)1?]x5<(:6ֈoɈ:'c()NTO+d5+m.xKͧl~쇓y MLL+it(^1u|wC"M t9_z4~.2'dowH^rb'rݙW\|jX.xO!"M xh8 .-{L![ۓ鑛O9zȆB4Йo{dh@l`#ʈ]PiKVq`EΉlet}i:*~ ZM9A)i_J *~$w(r|A(#BYg(&;MzZQ(1{ lmsjx0:wd' ALB9ͬ%&_Py4ƾ4quZhǹbElzec0PUHh 1KHt8^RX6lk? kyݏ<-~j/T S3ɔX4`cIkoz,>GY!|WqL0e#u;mh`y}4G> fpu^,eB0[di| f=1; Civ/¢` ҉z0KCi C%CvJ zv+'-zB!s7"O{R(P{?|Nqξ=35G&jxёPI#231Jp l "TsX/ apqgvC]B"%d2֛ĕҵ Lqgn*S ݐ0)fZؖTߧd2\޼"*M켼P J$V7 v2bт{p\̯mՖ9̉͘PADXwS=cP+Qzi3)]:#l3@%Ė~m6ɸhZK'1@?rf6 &HM^Ԅm_iˌe--j; Xx @ڕRM bߓ&&k_hxAvތ}ۜ3@9xz*6m7Jst5^$Kz8!eGj8SJ>"B3[Fe랗 `b]D\ځc`nh3;Yu.U@xꉂz/zC4(z8Bi4>!f-[u\w=S:CfE2l&~uKCG?h#=V~S2EȔy~}u+ct8qilI6_.[?\"|dCr=Fꭱ?G M5 3|*w)E7\IK?շ̒js(!m-恼厛Zr=; qR Oeׯv<oro{_aFÖdy_ 0r & |d~ق Uhch6!\_δuP/b=$:uN5ٸ%~aVjg(,FaObݷфU[Xm$Ziڳ5.t 3;QWXQpݡx(](6hRcתDfۜ—qҮZVk%'ԅB оD,;qD!_4%a${9y8R]ty!(EUJDGÿBUϼ:w8θ@P+osrWL,<"u5*Ҏxoo`շ).tx:Fͯ.0-FZ@wK]*0'o=YuØͰzj5>mRI㵧5זdѨw%d +U_-@!㓣8x dž@̾Aa ށz(QO!ဗuIn J;N6_O1ܗZ"t4eC]ԃy剳Rn>y&8/4pEF:X`VghO5 m8"6JwzK;O 7,{W0ܝKM wQgڶ8]aQqnwb^q 6n v1bNCc1^-#}mC΄0Q0? ]?*KMVbR`9ޮ:e " 92WOV=At-1xèCSV{:mfGfB-+ FEB>mS)e6J֔65&$QSDza,wL6ïkɚ]3Xɳ fT6ĎHXpmaĭ/ lF*L ]"uBEPʼrDҒӡm:٧v ¨"%4M ccR;T x{V P@G9VC;kr2k .j>sZ )#0 08ʠDV.c13)6qֶ"V~u+Q˗A&}T \7tQ&/rW΁e'L[N E(O0OK|PX9߇[,'&_sw/spsqJw5Mu4G7"GY|kg7jT~/B"&'qlM&i@Z.~"&ہɏDygG<CpOÊ qM[]pguDI)ܝ3ˍݶJMdOmԼY m#ġɥY@qшUCd?&"] C=߈Qy#:w]Ys\Jw*{4\g%*= bSCH,Ø8ܥh C1 ՘Z<&Ū>"=2ǿT/bR <Ⱦm㓸  EQ&uZ+%)&v Y_}Wwn0^X@D#.G˼tXEbH V-E&1 PSaKb`M0cGjؿ6pX÷=6|L=^z#PuWA!0lttr0 ^֜4Quv42vn׃HkݟؽZP~& ؃Ofh2I7eájbb_f7 #mZlԫ8x7*q(Z5+)zbo阅Q7ߨkIw "&GIrgVT.2a*ٕ}'=GE/L_>bBGS֕8ȖC{BU%pY}CqQI+xFww3vMkTl(-Lc% 63 }ܶnbR>$vauA[j<4AvdZi3#NIc ҵMiZՄ7!h=P`^}B:`R$ɂSG Ԥz`=^U|)K$TUi\qe~ExdZ~1'gumƨJZ@%O`6sk .YANھ2#?Ⱦѭ|8ң||h8N?lP{È'᲍|Fz8*]#x4˨]{Ol;\S'Y=]HQ+[/ci@e+N ZB C{qv.q϶x)A}*۟f7PY-:aN! U9*ͯE]Fhtu\_ZD6oW}ZWQgFDm"3eSd?KV)&:׳bx5BSV][_ǠDv`'vI6j0-(_DQӥJ{/oyjrьmJ|ihi·/Ց~5g`qjn n0s&N{$!'[j@Kn}־k%FҤ>EXec曰91i̻qC7mTJ"F[KsqJZ2sb50: ^eWT}~) tEݐPLpLV}Y3PQ*rt]K.Yޮ D*>d'`?ѐMjiR$ڇLsK>J^LPyZwvX#o;x|UE3ba!CgA"Dk^biAߩ֟ZDZm?сt&w+Nf/ Lr*<`h,(x-`X^Y)t}KG5rs'w;Qbv*C1͈=pN[UxQVoXd=̮:TȞvPիu:N!o8yS.@>y+?osxGFfW(8-N)F9[NH!#q l!wKp6?[)YY#Rfr !8[ŠqǞv*BIwx~6rAn_v筕x5htuflUuZ3땧cg~HwVc/)'Bcai)YY}Fetˊ[ܳd(cx) *uXNU ,05\4槻^uFD|b@L/x0sv/~!Xޘ[<=Y4d/鑲 !ǾʖɌCӨlZ0,}b0XN4$/`âȴ相}P[99QܣGwc|>~1gl1IֹNh.(<;f~*ܖܦ k]ߋ* JcazjJABStC!߱e}8 Nb8V~q׆&D?`2P%`HjNҎYOo uLtʳ.L}O;0[kQdA J~eFH\2Av8sɚk_!Ȱi^a9U8x_)hng{om)"J،@/?gs"L7! !~~RFk oWE瀝 0W>?G6/i8t~F7V B;Rdp G\ '$V,a']0{] VI4}j]I6KY h`"eYa_ 䅺 ӌ@ڐTl3e!bE Aj}mH܌փs[;jY?S5]vwl%zFup^Ʉr) hǓ {Yf>}m_QBun|aOl.hH.&SjԢ*KjP4PN!# ˽}K1K:NF3iW+X"GԻhUcH_2}䪠 yhtBKQ( PnܧAs(.@ 8z=PG]ZZudX%ũ/}ƍ\'퟼t^A+d5CҼ3fAbbu|To53UlCdc=poiE}9K .ƥԮ[P/L EbwMxs2yǐœNY~ vxW(GTR/@NADp- n4i<^n~$퀮!֊],n2  Sf;]i$Jfx3XK/x "2dʁyzJvZ%fa&mLȷ$z ]3,-oF02ZMCA:Ʀ6A\@9P(+HJZ3?9e@n#Qkc@Td/67Fh `B7!-S@X4C$Rк|NKP&㑝4S^/,Sa͞"%&mq=]&d_A~"&#Ӡ8ŧsLJoHܵ{eEfG6 AX\5S>WpvhkzR wmߗB2M]},;M0,D Y3qDI:$n0<T!ޟ`-E)M4V ;lsa>OF=6<4IG/bؾ=%89G9Px6$alwj33S0 gCl5=w϶;4k-w|L&yWxfxh皤gqLeȸn!M|ȲhJWb t9\#XBLo0K04r=YpM |g{zUrgE $B ~MtVB kqލ~a Dd4Qe&~oGHV_ÌgbɁr@3M_匮F߯ceI4';fzp 8{vpn)piuyJKKp lд`k:OW2Bݡ~qh9in,|KJ\;|xv7STY~`6d.[*_e WvALaMڜ%i]mA @cIP xyҴea #-"a0C@@CS8iuv8Y*uey_.U -*:-G$ROGu}l_ΜУ:M?ƹj" -d ;' ZE+B ~GJmw!bZ,KtK& a iQ1^7xXhV/ ;lv5'֣fxQ5ZsX@nR[|(!`pl4+'YB k)$?*ƞ!(&Zn4~+M c"cIa_Fe`t0laY\10[QKQf4MBJh.^;Vd(=w/b,ORU]-߲Zlڛ$G_|:qlzdnNϜ?/Dt$ :>u׾Yb/E,;,y&~_2T g+A^.it-jq0ה$iS$!͜WS}"`0q!ءˁr<@TV}ȶqI`Z =VEyPNl"F!T9zIP|vkD ; @esNSK2]w_j1P/%i ӹ`+ ?z'*uq,%!b"z2#g]϶םKԓ=V;1}l}pw76nݏ)ӊ+*m=V5[apʒ0{ɕ/}>+3&=R4Q1t +|%ʞUR㾎 }vyIx @ӎzVF-i@3lC)H 5ӮULpG"oFyj&qĠ+L@D_f6jE9o3!Mѧ$ ps"xb!TդmC__ }, FhD2⿏"ݠVozd8p{@|[;Wz uvZ[9WU;p.d.C_O.JM5Yʞ#٧,C~@92I5GƏWle~r?@(C9J֚3g+1$5e"Bt ޘIe'lW;!۸e@)a=鸸"ۉڳ?Jt~@_ N9Y~kܿ._z3g{QЗr 7z~wԫ w4wI΃bވRD+ HTEWZxkgՍ#|]@a_x!Q21cEo03\6fMO1!Lq"TYSsn$EӐo+sSař{[Hܓwlj'_J0>?-b Fj-a).v{O/%J S(i7 XH0~@6y)Owx):v8+zeΒwҩu[8ǡILeFN4enHk;j`Xw+ fAN葐P̀~G]IEô!Hzʘ[J/XD{j⦞b^a:&+Gc ^5p 5On0yLH9jfELYPD c2ΛVEnuD FKrir"?q}8N%HF^a|N?S!FU433%"B/Ւ&UqջzE<#oqu#p ;p{2< .e8h7c'.iw CLl}xJ'IUc3Ua@|5col&EF!8.o԰R pel+өpRVzk'tŊ%H1Ւ"g6[dTx-@@) `-=!UH^|ɞ? d+-Z3j 8FAw89J:3)xY~= y&^9E3r W~ 9mp~Ze*_[Q ]spI(~A3;~n7Nܭ5XJ}lf[-6X.^\cB$Q)Vq@Ɂtr`|@yR27x68F#gbذ!&G珬Z@H; N(2D2>y% bʎƿ@3ʉm-;drj4etߧ_i)NP cuˍDr{`1rei$w}A.ȍш29Jj<²a(Y"P6|丷Gȣ?i֢'nF{$> F1ӎ`xFHƫD<VG"t:+3_7%Dk\D.8ýQt'{]Sb%/ Q/eX2^ʪ,ܾ'mЊ][UfQj2 y"H[(dihqT8ʋ2&ф}L2e:9.@|r&V6xՅ8VGڸOtrx`IJ J㧕-Ob$>0ՒgiWOvuʴ!qU˦u]_~DJL?{G#,s+1ﮄ? k::9qbdlץؚ'3J]xCJuB2l[M"52Zd͈%p>jǙŌ7lً{7"_DI]?h@j\-傄d8O~&- OX3XY~q.PbpdD:%UY+}oMN8l]{ʑSMc]@QJSIH2eR t:Ko;?ަyH-J xДÜ: 3u a<2@AcTɉf3]^x7x0>[l40'/YsS>};[P~VbNhQ=H ;*Bv Ċlb]Ugo]*rg*;9fť 2|Dz à!tW!܀ҧG̶óbc] RXb\PNbD{&*c%|)@qWj1k"8KWy:b%S>0<7=`WJmpSTK&NՠhTZ(GAS;tNXr0$$eU P PqO,*#?hOqPdZlQR/@y';. d\ WRو "c1~;SetWx24#X$CÞM?n2Z5EU\P,raABŅWReB(yiުam؍Q ,TdD2P9O%#TB2_/'w yhջ?@ Z@+R1 IAAbtqEMlu>(lշL}}мiކ\YΰvEjӎS[4X!ym.A집4Ve /BA ҴqrZU@\'s?b @ӽ\,q-(h`:M#%)9 ރ"'_O.2 =mqd9_,qW2f7ʨW`}Ouh$N 𿅞W`xXlJđYmӐ3Ѝ3GǪal: wGhB:m>NFb "[ *)G?K: Ω6еpٷl{FLvnfh Abs$%}ePcUVÇu5 U9{3ֿ_{ dڐCu 6ߧy (N,ww< 6f-GOȮ0Q $jcS#3TLEдզ_g,yښ)p BNÇH7)-,A#q7R?ybD'#VWUQ n|2ЬwxjaQoi8KG6#^OkaQ1뿾cFKT,B0B&DO>4|NhH&s*=F\h̖~KLWr53>F$ap)&!!ֿCUN7鬣د/- Fhfr }* A%0$43xcLǹ(c|}d%6;&cLh +)Zvo$00M0x: ~_b½6G*ʹksѬXUdj[}bxvD'j%9=CgU4`B%v8/Z=}EX CީZcR }L" >ҹDRGy\@.K-GRõE}JU9q2=vFDF~}{i[k]i%Xbc"xZgbb\7TBsm:º}K{"n#̃(G J}@̘6- *N-@r7te흡Ϳkx2> ]4qI]`$:6 fwߨI, 6E}(M;!ŕ`9srluL/m`B#6eDu{G + O\B_+l,ҟԳ=\C EkY98CŦ^DdRѾ񥶁G>fLgݵ>Z߇5hTEx-)-.RwӉW-ZNKU\keOw~P&\P RM.B*<%.Fo>emMWdtd BS 5>i6Z])'UtMKmL1<'[.Bs[ޙ3n :*:'ڴ,lYޢaD:{:7Qa+'lb,{+]x+r4к`0~jq#iA85R(/_6m}wT& @<_zMl,82I߄㿔)#^.EVoynCݓkj_hEmf(sbM‹݋&Ӻ9i;QTx?CF3_\pY @Q P`P?}42э-bx(lSq u&FqC#lw,t<6AGFǂ _ۦ7kl(v*E K:OC+tL4LZ#M(f=:d/'/au0>~o2@;z0"^mlCےRC"X[`d'惾k\x/j;. `4o\P"I65S۴'ݛw 8Ԗ.H^? XàQLghR{RPm?kL>R -rS^]6Gjc/D3կ{ct'2hWlPXWtoGݖL֠qNFd-[5ȶo1]a+|٬y'u xB5P7J&^ql݊;m%`Ͷiߛ1q޳\\t|{Ts)4~m_UD]B%mqhoalhG4!d=7?3ИdɿKVidklH%7Ah)bae 1L#LG/4XS$ލ^uZDH,6᱓j+Na?)o{K[: |l ͨLFaD҇ ž,2qFv^·nwCB~odH5~'Dn@CUP 5g-CQ0>iJKFpt1&mtNai=E)!@;vm~*⎧%I[u8F<ܓ687Zv=!K[z Cd`,Zu= N8aUphc06E.\ߨ$ ; /a-{ӳ.ĹMYA-ev2D/W6ЎP NUW[ ߪk }J0q 6m'x2}@~qQ.RuFJ>M@^.dS[fH33-n">:e;юml w&DlCP"OTfޥk^z9A:o͍-K\\cHۜ 3_W:viu]Wj&RGc(T9v\Y0{fW)4U,j;'&ǥf[SCۮ!L0 H2c7?Ґ~E/,wDR2J_ JmO^tY_w.0E:6M˕Mۍ)T8Ӝŏ.^\P[e!tDS=z/ ɔƎvp 8m4#d)o<&LW! }(l/8[P`9 NS]ߕgyT>4>3&H'mv lj Wj&q)8ɝBYB"#H{2Ya"NC 6czlF|>&]8+I<.g1meD#S "Nyr=ktK0l{cnS0?JWtDBEC8eon|\?$GB?U┖#-H>V+Ep( KS5ꃷhX8pA24V1g҆ᜃ-5kqvX,뿟 (8Rf^RBj#ٟ0:@sȢ a㲅tn@ S'ɞOAW|qo ;7lkfƩtp>'q tqXAͅ !j [vU׶ 5kwH)$*hc7Xfk|pEa6ɂ2:+2ћ6G-puvf Lr_Lܿz>a%{pWZ`qvcSEVEV.Zle úQ%u~E_.zބ1㣕<'$I}e'C̠]!5A qU _`5j]ʳ,-\E6Rd0uruH_N4ضʰ)$w  44TlBKy nL.)q7G'5¦z3oQQ7xnYc6"w93pVR4OAs [!Ң`U=QF_$*DaN M='?78K 5NngÁLƕ)Q?#h1۟ݶ@"-Hqn:f3#R15!DxU% "IT5JN$'?k"]gIs'f|TB7<(NʡG?L߳oMZ i[Q`=AYWiX'[vqi$]ϝ63ј#&'k9>>-licM8ޮ IF@hN\W6$gWmhC AM|G40 Q6e Akpji%]Hۦ j9׌:Gh;Q::ݒ3[b ;th{UG6`Ѷ9MnC^ .H;%xEbjO#x= @Or\*JOVhNX=~(-gFp[j}.P0!3W1vN=x8FOR:[^]PCo,D.ޛ-PlT実߅;eNNۂ-?iZRj=MrHwr8ЪtED!B`n{_Elvma (~`s| /_  . )e2v9>gخgev?eUize *G;wQռ>tv=5j^j޷7-ȃev2n1I^MX]Au}Φ?@KvZ%R>v#^Xb!$cK!#VKz)^Tzr^VGT4g[ËЭ,|B;nB0M@~lE(| Ε"Vc.8b(%&tVOK+֯#!rUeҩ2I}?eiL8L^.NYKMj]2^niY. /$4/|?aess*FBv>믡?=ݰfap^. x.?M#Q> _4 ;fMe+}{ ߬B_yϕ*C l0ԋbWWNLh{_\t WWUSqwIN :k B+X)jƪYzΐc[E;Oh'd3!я a{qQhDX~la}:L]ɯIu!mߠ<,kLBjj1!szc?zN4ڵp0y؊"%֖A"<2[G ]CX y rN++6Yw?y5H G?⡫!ة),Ш'2H1_-؞L@Cg+G@ߒR۴c^ݛ.v8;!@@WrevKAzOYU=z}e0IZjV+@:j$,i+p3QԢV})\GI]"c9-\GSֺCƁ؈ >5@Ψy#LP(K-.qj? (U u mФGj<Z â#Aw2lZ?GZRykP@Wz9|O,9Dz=ԖZJuXoOVLM 0 Χi%:WB/(;)SXibE6q;hClzZMO69:b|;T"i7WZyYW EcU0c]Y#HBYHK1h3‰bz@QAvTSXLr:4P4ޝ70r(1h}ue7}\e(Shb4U)ȑWf3"^H>u _$3WPߨcOpe)Y.\qS/ݟ9d}Mշm dzꒀ<>!^C{PLN/{Ao__(F:c9oFZ<&DU[.^v;i"yE`*6zu.dU)<g&s]ZЁ6 iq+66ٺ9B؁pR4C)ǯe^0*N}g!' vd9җhK])a0 vcxN4.#\T2 @Ttf/<+{ EEWKT3j̎wx£ 2Lt?@Eܕ'M˭"l7' `|D[/.pdWcoPt{h?|kfU-q>\zWЬy뿫<{.mKn]Wxh?qq MRϹ.:H4 |W89@![*+W>Ϸn%62Iqjeކ* ΍Bw[C ^EQR5#D @2vPP3Ź[#GR`x6w9mUmނ9!T'1t"a^m#V4Seus!(Q# T 5 , 1%}$6x%B7}4gjbW _%qKY5zB o9 2?)[ح #j-0?`F|6hFx>ˆQJ^F[ 嫽ϡ=JIq)vPH_!PVCeɂ!I;D#sq r9ӗ;?Re%0(X]XCJ)$A; [g33ܾI|>m5$-/2Y&΂)ߪLXHG"#4uZ۷Jug?pr=8./"M*:ҳIxT5f󩟦Ђlx/oiy) XaLW[6#ow+4$|e!ٌ s@'N2XczgYf}A>/ !ĺnx;V@In۔cz~y0‡Lf}d {譐kn=oA|qf;BI k#Z]|A/,J8a# GGOeزOAqp~A1X~ZԤ^?l#M[}E@i(uK9 il]m jzS 53:ʖC>~ k`I /D@רyp귺oM Dc籯8{xMNJ)AQ {,;9[VW[~fN.%*Pwےw>2ʬI$I'gb{.)7M͗G6n=8%g1W g^6L_;Y6Yz+oRI5lLz)8w;6ſQ+̀X-v7)4nҹ՟a/tam|zG_,^eĹjdQ #p”T$w7uku9YʾA'Oܿ/OS%e>e8V qF @iH) O| M?&Q԰ N5AnV4B@HˮA7Q.wI-ǝ S`g"ʚBygh_iaE(%Ral)Ϧ`>Fz[lacSy{ZEK-Ȅ*ݱnjuk\JsNq d0 ͊IFI@\#E|`P[qãv3gSLY~3IzН7aDqɠPnnI7 Hwa5ʸ (ɘ[3.? eS\j[i2[ I1'- MxQ9-\)7ƒφYj/G)^IX7JdsuʒeT6`J.e&`CleBbu;(}Q;'[1G%tU/% NegF%ޫ6 B-89.S;^[ 8qΌ˗}4DO\RϦ%2BIQ=["(B)0MDW&TQh i,[/Jvt>`%S h% $o'\ T6$*.Biʓ%4D&u4-Cv7E59>!o<#2$6H$EߋX#vpyXUwe!{qk\2"7š8?T01Sjui@\& AO UKyzK=o,Ưu;nhVEwVwg/W܅W5r+LzB+ȷzth2 FT5`8v֋1=/u9A@sB.YQӆNKU ֌pW#GA^ ^P?s$wYrI q4n\h7f"yuW_@'>BikKCVeӮ9V, "=xJ Zm ˙ٺ;`[7nx#C bZB1J%QlG;fHZ B$9Fn,VrPI: {_hXD c;OO ϯؒq&rѵJe[/bt_i(s?q.wbGgлTu1be-쾦'+TI/#۹"9yTC)@J[1mkـ?eaW'+z`&߆5K^)ĮeC?JV@DtJBmfk";ŀ }'I8ɛ ٠0u7im֭7|(}ɏeKwߝ|%svp&'Ӆ*GlQv31..o7 79,N\?]9Q.q4˨vR:GVb\gBH6r_M&geL)`fy8N#,\9N=z$ Ѷ RN3fN^WaHCxYY;*ęrjU6nNFKlS.iP2d_Y;R<1u Gjp$֖t]A[(LdcuxY"&&P<^s`$dG%hCKm IfiW'+dB#$eH*G]ѭ˒唱6%g |]8O&ɭ̢OZBI p{g$ |/Ov0;}_rs]H^1D&5"w-z29pzc>W `Bfݔ%T JSCߕ-5|B$Fk0C d37S?I',_oZI r@s֑r1eɾI!0/yn~PR;-7mM[R]o` : E4d|+7GnR BnD aXWvC{甲mCAy ,~pe~lÔ5 3+~2Ay8[|f )7^Kt _ڐ/bHռ;)ür*樌hiF nW8al)gjM2ش @$ml-k5%Seq@a9@z 2#f2$F6)Q I)pqVT%)xOv[B1+9KL> 8fb?~L[;y)Ù[$j wV3Ea\F3 ep^ZpN&J鰍"*y6O wOD-rfR<K0L6%X<5<ӵ9緍PUQԿ&'9q'/u(z,]"s`,)A!exC\ EpSԿ~ZodY<-8[upfssy'ȢQ0xw$<ժ}fGO$(kwUB'1_fl)`ˎ]$of,+օX^77^c&|.1#8IcQc-#!?QI<)\a&2 P" 2ȱ.@.ᬖ xtgE  4=!PbGZ=&t a+]?7^'еПr(ׂspxZl9ٕ06en䚻̏X=J>%rtf"S"}'cK0'0]2фXA TWT)$?ΗKa,N[{o&'n@P_$Md;UKa#3+`xYa7~j[Nc9^qdϽ Wac 4S|^,ah M $ %ow.jYe=ftV7vT3}ѦmYND0;d*"Ⱦ3jfm_/RXb843wȀ\ =ZJL ҕA~s^hFڠbGD<fPzZI82C .#VG@qU.15g!?3Y*Z(jQz*zc/i~JT3$dTu#_3˜:b {g\-ӆqVPl):K+})?}Vd_vxK1Z_AC*8ĉj+xmzٰZ=m01ߴe5Sc"'m{%@ek |EA"eR>X\-m40T{r?؏H֍Q:i\H՜snI!;Njj~?˰m43 R~ :^zN|vm9R0H57%RI^(1WP1\;oI3bWaG*oJ6 ]' l' jۙ Ů'ЩrdW5ĕ 4L.~:TPVW]9_$ٱɠC=6Ӟ 'Q}08إ";rK"l\TL0:ɻ!_!x-hW _kb"JTr 蓵ڂY0jpt?.VީV4Ν,V]u3KM,EY6!G8ԋjXCc|с~@}xǃޏ,L^!sƪt4^\WDi=C&c& u[p8@yD=;8"v 't͑ ԒBO02/xHN]8%T)r.;[Wd`MKs"Rwep[6P1V;"a{StuuY1|Ç+9T88Nd+؞;,LDc#|3X٠T0: vC:5[~QB-_ &ViQPLuh-29:0/F >n/įToS>cCtA{ݭX=5| .4n B>ֲ xh.ndC {V/;+ }ispEK츶m.s]/k҅>$"ƾXɏ f`h[L4۾Y\U3 @(ymR8R:4Jϯ2 or=W9 V Rd{"exʻhrt#爄^R > 9ֶbK&m2mjD h?،V9Hܢu*A}Xs>qcxq$뒩Y9'm ?B"/s a֘Lk:nAFL{,=7 &<΅̈nߍ-eޣVy̪4FAʕ3˶w1g ' j+͂U?CH@|T 41-ˉɾpU!E.q"^Q]ӔKcAM>P-̀sl̿[ئs)BA͉΀3t^rM5PWdijb2@om(N`Sn&7~ tWKO} t'|LgĭAuEtyR`%ulNYt8zbfrgJSzA1LUE]&x\94>2D:1v3Dz5Q'b=wϻk 3 G'Q3$`,O u^}QqPΙa*V4/v(e \0PԄnPŢ\|H㗝3n{NNfğ0x½ VB\h cO46~:",s4=f2bÍ)Va<*>(!Su^ TXJY\&U/ڟ4GLjŭ||`3?JS kVnʵOp 9(qJY25_Xz}ؒ&?l Mқ6=QRΣkX6n[N r )xPV,V~8Y5nFȹaWJ&#ea+N\s{ɛPF^2c5P4p|ٳ̱)zcwnv7.JML H"$ z]XK8wk fT}(] 3>ZrΡQRBjF8 ?Og*uH{foYYA-UN-wݛTxIL?IzGs.E,X 3 E㹌 TZ9-˰-i?BΑ|x#Rf"TXޚekֺ4hjz4ջlB}}O ü2)Sb[kh6⃜sPD=M&)~#֎x-h?/zU^]Jb?NjXBӜ"mc9#U{FyhJ.Ag3.`$n#Mgw|gli*f mO Ag$a_Q'/;ak4 ;^^xWh-fE:s)Fi%6I?D!Z.J,-#^NW22Ҕ7/,=+ƫRU@13}fW@s^ל 63g&"dD°gʐS珣7tUTX5,k\+b]{@;Tie\vP"GHkA Ƚj܅ƿ<Hp']'JWZ\}Hٻ<79䤜\wu(%:1MFʇ${M;֌&ty.ćٛfDG^O#g/2ĪKuYpHoѾ\@Z:o5-5 PYdnخޕKMqP> Pklg/Ud'G19K̷=9%臀=Pe3s^!; F\k_hk#-d4sd\oi46QML5'#{W3C rC5#bj[lþ3[;GqzBwbgIM HVVGݿzـ&Xn9U9i3UjzR~F:+8RR^jѹH"a9] [+K+(ʛ55g׃ZW-xܱ4"x-4ۤ6ʍ n4V`_Ci~[< :1HIP"p\kcJM~^[:E5/A[W%mDjF. 9tW,PQvoy$lⲂ&6E)IhՀۢi}Xwit*0=^$:H,n.ʟCM זF춑ռMAls{!u>2ORY9 n>&8`4Flt L슭p))lFYњ3Y3m0ȡ˫\`="cB㴐^U ŵ`XB:#R6NS޷.lfÊEBjP5 2I3%!yonZSogJ}{/ieҺ+i̘SO xIҵݵBk 㖁%߾i\IAԷP ӔT;( 3z'VҰ][*"Uf[=DG}!~hP`Jp(]Hzc5d$CbTXzMn繵 з07 ɠc\Bj|SC5sF1G~t^T- X5(-rwx{K}&Mzym*v'{Nfubۗ2}k5#x;&`0jF<4ZS v=gV̔M+R(_Ų"RӐ`SIo=_;ackt{_AdW!ue'g\秳h۴zƷ.g<)hk"eŹV#D Kh2={,lNp!97nA7[TYϞ@-afb׃*7 gvMr@z(0{"~J[|cZUZuTu_|IdQ aW-̋A F.t~}M'!&E rɕmzifGaȷﭳ/9ܬF߸%E!!,[+1~֑@SAybLO=vf6i 42i=q}"b\5!3Xpqda?ی }"bмmzxHq D5Nַz!aJ'~Ëe3 A0FHquhn>5Ha é|%O懚RfE|,C+H6pGτ^DY^p>,cH\nxR"gl܏1̥}a '(wjNه+WDqjޗ^Qh "FB׋.e\ 8r)2 * ^lbO2^`#E1B[#񘻸aLK35d8L;\TB^#nSuϱzCx]1sCTZG", e0XU2C/\ry5Av[T3V]ss`b"ҌnJ ++e v8qi$|-Bn"!QahBYC:ɢEh(R"W{H@L;lB&TR"Aڀюd:|R/30"֡Lұ,'s/4GToCJX7l~:,5]I YyQ})a]SИATx(Z$Zuuv_Yx!{*3GƤwM@߳Qh<$iUS|ahogWf^RIGD3 Ig kqK.ȃn(PZ3>W[7ZibۼTQeD\j{ L/ᾆs\g3yLarKo! &{ 261+[Ypװb+/zøLxr]tfb"p}1 +Pe vΣ %3[H-&DV_4vvLR*(I9*t1Л%%MLŇ:D:U?;xqBST( 3|z~np-gk:"Qc?x rk4-kK=$+c v`y[׊`[è*RQ,S簾4g8,_o iz9 쓕yߺX#V9?^[A?}-&_ 8ƹ×P^)ՠ׏:7Q`",{IT:g~s>@ԆJd܍TLw1 UYLM(1ԯgψwGg?n bpuZߺ05{5dzN^&``bŮ]vx5FhRwE)S{6HosAb+%Y=ZEݵߟ]SF2)rKBaP:XCZdvWcʼXOQmj+>$],W%#O89Fa_n[7j!UxNgPe&J Tj xk\&)BXIF= :',/zUgJ͍H u&xՒ::ኇ|srШ,78 y~^`4z&a[KtD0`h*+2|V&iA,j@j{Y5P1:s_%l$u qy}oE8CSYcvba7Fe/[Ro[ozS¼r_VDh*oVO:{8Tdcg}qKU^4J78}TqT+Ր\XJoRsbrI ]\p0dv?e cn;G{\fo9o eeh׭8Q(@;;ߑ={GZ0X!!%̓ft[A$nV;€BB6&o0J#V'5iG9 *1mCI :̶8ʶ&XO+;@Yk#_9Sp鿝c5F u=<ļkc z;nuc}0lu4ʎ+;H,vFCuɱƕV{qUkU$ D4l07[%S zf#nϭg`ez'#t^qldyIb 'tA yVYZu9hfK"*ěwi`ly, `A&cm¦?kŔq}VѨb+x] t>׌u-~LSOrADRWOFtwُk hIĕS+NT.B /`C eQ' #LE2 lkl"qQWk<“ҩ *C ̃a,P̤9Bo,鰖eO۝!R/#V-2c7|c wX-o<-Dƣ ʷ; !&h;&+wk*q5b jA C_8Nlz06Kָ2jX|C{y0-~Hu.&K~CP*I'9qv?,d1='Ċ@GPNj.qܯ+6wCnO.ܹA˘:'FC&F8VCБrj5f7KquGgI1aK(MQ;]S2j*,J)j)(;HRp'޻ظy 2#Z\&gѷ޼oTe 9~ ?zpYsQݮ|΁^Sp1UE6-Q`$bԹtus>3x<&π9iTt aL/[TsGYj U QQkY8C tS7 m Tm/uuM\p!u>%rb[uQvb/1H&Yaҁܬo^(*S2+:D7Fu8N dageE6vMas?u)fwd`7H"t?jxs+Ŀun-u`N_LK.\Bo9I>$m/H!;6;1JrOA[w$(='(02QcyͲds1/!UnvWڏ.1i-'g >c '}{ʤ4&s>޽^Y*]"!"y S|` D\-MB1Oi>~I7 ;<~O(״7:נ*~N_,!z$8hDĪ_GbhFB#U7pi.;} @h蟿҈/^1koɁU+5oqc!@%ؠ=\>/Z9f+7>pb,M9 g $Mo0EA1@P|SU,2=ݚzHY쐿-҈%$6'Zǫgq+o؂7RTGLai A[;2ޭނd}:d!G`V4g1;_{-⤶sHۚuTJR_jߕXY?V%[jTyk lJ& Y-J1/5^g_ߌ3g(]k -)q޻.m tuGOq Yfjy{|P/^f1$8DϾfWdv˞.*(7ED02"􅮄h6c[MX8@4ܤ2S62hJ=hz1&]s!h˱5 ~EqPwn?N"hPUS iփ! &N@q8Q_dubI"O.f+#`]Tny٧ ނB6gH|g.]#o7 5x,9-W/4i4 n܂CH6Rjl)]H/F-uFC)71{q1VaY+ZLڪy-d;ikRAk,TT x񥲾/~_Ɣm*ז"kF !l׭Qc0cZs+*QW Òڙ:ŕDA!^ ÀGYho#]=~w!PYC5dt u6(VlӇ#r&>].A{'] $~ ү- nDsbXn* iY^@v?Yr"-mod7;C؂Wn:!"VAbSof xoP0Su$t8Hנ1 &d7E cc#:M 3M/Gc/;gJ\GT/ǒ7-vRl@w+|M[UhioRIJr,|6)ʖ"wHBE~*mWbe{<C H`Ȋq|z(ԦGw,w\ {nEC*'4+{yWĭ$o|k\Os?0}Q\DUK;b͌!"6** Kw&}ECK]1lO;ͥ9>4EUjKW?v SVP}z5kd}GRޠX\9x2@D޶bKpq>.Y6NG!7I,&~>r#3gK( _7_}XzRk5@) =t-b5;~5n*@19kn"+;6 uK0T/Y/X{4~j(w&" Mr5ZH(]b=EZGR.3v/De -ωVcK̆~\hH֣ߴ"blM_)eC&$wo 8'"nk[- Hv=>kin7h} F1~wfT(3$Hn:c(cw*i(׫ d!iI`8h3F8Gdogxۑ|[X1ԉkwo C0 TWFzN3nep F!_kB *>]U2Y Q`R[A~5^lAjJ(QEz wv2OJaXG#PMÕ֝<1MܨyMr͵}.gie)˗~oM?#[(}됈@[Er l9CTF}:+C"*Z{ b9$$k80'[$V %g̏o+3-f>*㛉l*G5 )s Z_U2WX%6 =y[^#* H:u?EԀS{܅ݚj((٩FIn Q[o˧mmZnf jHc$8r;7Vl GCͼ-L"1+!h\34xIg2C8z¬whtKJƇ T֩*a /,~Ғլ뿹PilH34,hee,n&+HWvH/ʒG,LXe[ABJBz^%NpGg GR4r{rXܿ]"qFE)HZWIw$HLb{7/ tyfd4;*օ j-x:p*Ofpd!XāELoY:_z̨'t3^L6MOxpk'B%gDߙL`f*ި;^t&W񖤶Ru?M 7TZ)|C`߬ XX3h0\X):g0ωPlS;ҹa*xݦc+ -dSw6VcN+̚X ' ÞZT ߱qٜޞ|Ins4J@ďs GqWwtp6 (w (Tyx O]6lB/4DcWf{:G4#jx:HTOH~筜8 FU'\<:rW']XV;hoef|<:jh`t8N ;R>W(OZe^Wrʮ~ )<}9Dk1 /|PУW0 bHR4lC>gBR00]rn*uT˘Y@諘 ejn@ΔKex\xv'<  6ow,˞֔&H[m1E Qb':mc.g-uGpej+M3}JsLd[6^k Iw)/sEvQ7A~hIO|: .4gޔswmRu>Q=QxqD'PU> 5EȤʌ+3磌<_Ic8gDLl#F^lNU<L GvAPyet!Gjq͆Uf8b(2PuyYު.G'S<4Fw? R[rY[X20LMEr}Xl.h䝎!)RlTj+LA?}DRą;53&DCA >`76p/I@|Ə{J _n GC&b!hGcudeTu {Io/&q+P8P"|raRm@qԖCGCUײcemGVIW\y@S䝈Q<7P"KGMnRbؔ"</]:-p}ͧ%vcixG+Q'3԰{yfH:So.>sP2adӞj?n(74~GTJ -d*K;򼐤qf-ot?EWpg|ic>  7蜸(nLLg4U+Q| W(>5αF#v@M "*dVv94fHu|V`9%)5)HcU>,RC~wCHf /#US{nV8B3GJvT!灳'vVEST{=_~31 E[7%튃a'sfhp5n79Jq$4 ?]"W b l&<7%-wri^ˣ8|P[/3h[eh_\2È甐k<<+sz۫}'Am:lxYenWٝ Rׁbdbj-':w0Xь]}Y=pU[{o,z\i@7E~^e4fbn1hnj^N\i|7s0_d+ZW-[bHF~%^?1:1k ٭;*ӣ'\w1mXΤC21*Ѿ08]h$40xW½c̐)KE.yI0ő ̎1-@"Z`.E%<'C]RJxL^CY*MڡMB?~F~{N㺞j+wt 57[35SH%wALk+_'M@mk4N$ gB&>C3yJlۺ~Uiz,5 ^ g0!P4ǚ~KQO {i?Du (FI7x6b+NJT_F°mNٕ_"JKYx%aM~2n ;b|ȝ[i {$$^D@z>NJy+I4({9Wy5 {,$_N~s]Gls }}Ɖ1Ձi6K:g\:? QePeTf{݄ck4Sֳ2{M%0u$aho/蝧c tA{C Ø-mZ=Ns_ƠG`txk|}Uq֯B@KP.Wc,Y m4*C>8W& XuϰYVϷ=0(8g%1A;.Yш;UmIcUh:ߺZ3 ~I PN;D_a\04$Rl<҂3.FY}iI‘ݭei.pp0gpM'N9)u4Ou0lTs7OEvcf4M@]h%J8'c'3P`ƥ]翳Co畁cHt'I~ÅJEs!d>_Dp~KJ;mƓ"^\^0B f<*/Gu@x[M #JPBO/^iYZ_ Rѕ.ɉ9bf,(#6Gj' TF_j n D)_0&)@1">VqYХj<?.8$2wmgF+Y(`sm9r@s5y}CHW/~MȈ/l:~g:#q &t 7d^tߝW E.eKn4 _Uzv]l_ #,B&Bn6 [8p-޼(q^D"M.-+x}o1ox]ՈFLF~q-}eChZk0DA6e]?a^uNaQGDI:5~v9ZqC?)8F¯Ah1 dTag^U܌eP}`P|q-]KvX̕yQ i-Br>YѪ/{`άLJͥ:u$Q*HұN1ޮ Q X%S:2Rq)B9U8hnMWzϬ26Yq/g ) ǭI%J w+s-9-5KnTݖkBJfl2{FOϛfhLLn0"ac#V@V.eǪ@^tr*фxܖ7.XH3W(_̴>uDBP E;'Uw] /S% ].m̍ |yri>suPt-!6}u/BtgUtZ"a$jf߶h_b/sTγgy|E373zJ%f P=#Ư=M@bËXʭ+浵TzPyy91Dx)"f?}=զ8 UI6arY90S<]lQ+F`MY~> u|bt-'.slJđVH1{*9{YY?LG^EkZdjW.oRv+m(x J,U4J4.*EJcLɾq3$[;.<;ƉnwhLGSS Z[X9 ]UG- UEUK φQ_ aa&;6w=7^PEAli$B`D=`>eHle61ST5? Zi9dЋ@,;5CJkI!śWYOZ|Y Vno:Wlg潅)(C=8=ZZEK;w '&)ܣ<}Y!UpɖֹfCpnh32X{E(c.a{(QA!$f b$Q uZz;Sƹ?'i 6lʋ{ܖ~k(lN,KXB@sJydǙ&b;(5پΎM7ij"!se Fg'B|U@4~9dHȎLA!{ARQHأcIzqv3iBo?|"8 G>'P,lXXsVaiV(Z|vtacn>~t6#% ;;5 g\jXH.\Bm'>/kyzHpSix>ufC=x,ɝ +{w](x.xX|LX®"fұCʤ$t1d2}=Ѐwmҽh gOȉC|zcu߮ctiy&?pe2{# !D1'D)XpN@<{Ns)<9.mkJHXxϜt[} ߶#Om,5 6U9E 'f3!8p.>Ur&7\Io,f~NP.Su*:u-T3|"lD 1ʙhIκ t;C} ) A#F#5aBSLOn"1oDB&{c[)]*hfF?Fnb1Pu_,e =T@-Ѵ D(C!Tk'Y9#FH,P:.5o!bFǘ$,Rz}Ub޹.k\i"ޥ]{Qx?ehJoMW1-B^-/+; D,9]mο,]=l[P*xD4t4^' wI2AyoqĴ&ơǔ{OrMdB[mZY%pS p"icKaw:`GC9[!ӛDR22jHDEm3C~ik Hܘ6+Xd'` F P/"Xq׮Xzo$Fgb{ @㮺L81<7Q"[EX'*s|CAm))tW(sfHk;qc1;{z"W1GPt:NERӴ2sQQRxl yZޠPدDv+2uE.;gfJzeSQ,H]V>LC$VI8>HDs-'(eAsB8Dfټ?"9%q{ VlQCDa@J݃@ӅXKY#Ef}oC1Vs}B'bP|ޤҀub~0,!yQF:#e{J6)$C:dyo MMW`6EjI_O/ k1`,Iƞth:ٓX ݉eW9Yc5w/뗕,NJFDf[mdWj $[&?yLW#.>iTR?j^6-MFxQNR=M)Ӂ~%$&ҾѠo^=ŻQ5 Tǩ -m c$MX`x@{$g{` $nSo,Iv"{yVxJ|\`pR&S?P7?AۙLA9-Ȧ:eRzjf4&0 Ԣ4<-aL&Qq vjs@ò&EƍaBjC=$&9TVhz&U>ZU+ 3 /"z3*9Lxst#Z@]D" }R-?>@2-\/m2VPJIK|ߊmQ7,d^Up=Vu۹6S :->*X=ah-*kEmLƾ 9;Ë%R9Z:x< ]u~V>MmZ89M%ۂ?/FhO)ܟnR5^xi % ى! 6c-pY$*Qm|U  l'1h3U LFK!0ZԴyPe9bYą\>82PzzyoV9ٺr(G=x g#ƾ{˔DnkwfH1;m'A(  VS)ωA0+CX![>j^cww3N@³u~ا/xCJ .Y [x T;*K2h0RkG~h0cc1Lޅ޷-y9=9*v/a~(BAAϱ SyN=BKjtaFT2tK=. ,䭽^d`^ MP>i$chncݥ lufk ovQƸ}ňD+5s~~jU-\k}مlfh`uP"`V_o/Aitj&7nSEcDc-7itC.3]/%vhߨl|]Fak6LC5?}l6B&^ GWᗄ== avEMLL{Xk*<1y6&-|,=tYiFN,Lft.^ H2^Oaդ}ŭ%yA(!B,I=#w) 3-{T U1BssH,4Т-22/uү' ֝uJ>E{?ɂnR܁";U@\hw˹FS*FGbpWSA ` ɳXPiOy U6oݖU4bbx$zDg`L=LfcI6\g1Ɋoz-)?* M;'Y('S{ZUI WA˚)=goׁ _4 qQmf0:NcӅm傽I/j{󦬋70'|FApZ~@w#C:MQMxpJ/Vzdr}T)c/%Ao@>"">-N*@#'xi9#,_S@}Ǡ)%z&5E]O)e~g g|XMPLbp/\o5?tJ5mNs祇5WVaĝiiͰdoSLt2[{[-Zf>$RMZvͫ.pyzp7u6eF*i XT4;h ߜ 9rHSq,%yy!Bn)WYթ``"2 vj}%+Ws:wTG-DmϤZ _=&qF5%$54XZ"x TјU@DSiz=˗=8ww?04*1•hKVKS)bVg&m8 jGb_`H̱T‹bJ.Kqـ'yoDt1 mJ[N @V$5ey2Aylc&;Hn-IYES~AygIESGJ">rеJe}v?z}% WL30XJ%q ـC4\ ?lA ;3Q˓ mdLhРDY*wCՁ>]Y_@DG91]VUUidӪ7_=J0o+ni4[SCQ6Yl/K"LS`GBa0TR.` x:; ~҄BIzOƮAeK! WjM(3|!'<V&!RG׬N0m!!,VK eposlP=Dw)& tGA,Oƃ+;5ؒ w+ ktq@s_ =2ܼIzT`_S=u—g*C329Dwl:9$DH6y `~nh+ 7]A$ KuDQnB\nZ Qe>=]f)u$-v$c˴ȸ .B) 豲meb6pPJg J.q sB}iW`O])gS~1.Z`椧Ct^ҼrI,?'g;Qb<#=%ۦJ0d5\_GrκʮbW4vi^J=Oj1]u)Y]2; ͕C&Er.~tuرKԃ2ju"wdϗ=:-5ykM[ EQׁ$u(_F{s|?Ue\zJ#Ѓwbva&dX[ΛI<\ ;Lwv.kw4(x,x(06c!eg8rĭX dŝ )`vyl[RWv`qΦZ$SX¸$.ǔwY5ЌCU<Fa_£G3Q\0O9,:*!ڬ /bEqg>88LIVڢx$@ E&1Q(/ɤc.(ɉvdoET7 kQ#Mlz)O!DZIY'cOUtZep/:?ݧ'jFiAO-K.=nJۀAFS+-os v۳!*3xEps+*TxPi:ƄqJv# vm{FLүb}1`u%JhjKE8C0Xf.SΥ/ؖٔtb{o10[tѻLv:y@ҍ[rc.C1 ۈ?!SDejeM>'G=җ%-Z Unϧ"ԩW\ajtt*X M"D O${>$R.%膏ߓCŸ4u[*8Ԝl3a{<Dwb9xl4uqem#!vdmDZƴlbȓybp4E1Ld4wKWZ WʅA#7@&F{>)  Nܯ JLj1hp~sԮlXT.iMw94(A\ dweǪ=9S -ř |ZÆӂ|AL9+[GpٹT;-ҋ89p¸sU% J}L众i0S*။އ$@4d~ e y(zU#+IaTNUV,LcSQsZCfi*Ӥ')r|mn"?9>ɜ$sЬd&мlu~:f k[࡚|Y3^8 (QvClodo ϳ$+ihΈmt)EHߤC@qfSVYz9Ն8)j=pt^/0*Yvp_ V2(a4~}DR;Ύo+N݅p`F~4͊NЧN!ss[ЛEa2L M􊲂aBә?b|w)" ܌/M\KڟM `5={!#.4kpMJo k( k.`%YX+A&gpũ.eaH\;OW<Y`O{Ȥe%pԋ{ UvJl+4rkz"-ld )@Q!8/r`X(dSe6yX.n\yBNg6'xOYVؚ]iJ";<@P"(d*!!! a9=^K~uGPL!kglqERoQO RqG=Z31TܶW3Q T 29/C3OLBEdwcS70hL\n{^IwNPdFWZ9z)QӚ1td \ 0s`U2%$,[mQeF[`o 2OO+} oPPdI {oH q@|S?6QΎIǪFg-O*٤Oyb'OSR{FR'Ӹ0F풕91ͣo?8sAcs5d)v։Óil,4\7ԝ5h|5cReI SuW'pZG$V!v-qȕ,0V\l|qWm.q3i_%Gþ]Z8S_ޕd?v66%OdAK^),s$܂1Vjc4\F˓B!; ~ \8\,\ zo.Z,1Fi# ( i{wY݈=-^0pEB̪MƮATuz嗐܇'TUT9 uL Ϊ.oy~Hzkd!U16J:WK7&%} )4qK0lաe|z| R CW_VaLaLǻ /K_G _NEl_=Yd{Xn>d.$g{=\!ss?ն?(l4rY([gt N:E4@ OVA"-8D%7 L,E 4T`e++;^KwsӾBbT®Y̩>^VSW/AS`y*@9!#!JfɌ2>@&pKAJqxH֬gK9EX· AǕfWd&Y۞&ȿ︗X dnhw?2rnmiIv'ֻԀӗSuc(t>l(zOEcV\|.=(;Ȕ?XB0oZ K4QŨ ,|3,~],U,]y(xvby |OD"iiY.\A;Q4Ç~yDޡ[%+ުA$_1npC,rd@csKb8BU7@һ m0!S E tb z=Vq4@D[sݷo_F1WAET/7߱Aau?g| )by/;j TQ• & ^_|))mdS(L)T+C|Y'jhHVdT%h>yqkxLCC6JKvW 4{|vdœ\>,,XPwA;q,A5d+6y"pӇ^W:̟X=7U?x洅_ ēUϟ [ )xDxuWXjH/ .DIQ2lou~Eu&J{*XϢ߇I$3B洡Y8hQ-='65D uCuHŏѐs%"R Wb [k 7$MҤ3C!bԾ#=,_UB vI8mڲ̶Y?C_A0ar'3w_F7,KV-e*&3v5"hIﲩ,[SiI9 Rgdw~KWߣm 3_/mixk_=ϭ)w帆!ҡHT rR)fKȾ&g]UE.3F(qEEGs'^},,ӳTsNhK'Wnn~j/Z,LҼeA1YF*:3Mg=\ax,D;Q%Pv Cɪ1 h3R_\"I1ع#og?3;x¯QUq, JVÒ!MzN-u hﲆUd9Yt &+"͟OWɌfqlW`%>g6)Bv8{ڻPy]e<)c1,u؏_Bl> VٝMFhuH#ojGi̭RGqž?*]:Qr8kt#E `S@&V93'DO> 0~i:Egq%ό5#ƃ_nk!p9oFKh]PJٝh#QqNh( x]Ep>C!7Iͥb5biTAhTwr"H [c%{84Яv|.#kAO i9ugRM!"vDűץ V==2vKp#Y Bv^)b`ġ.ٚ`*.^6 g&v̸++XB b%Kr7o0<{0R* ΓN!(?UOV,%Nfyw`La Kf96;p0j{)۲n>Ԅ#6ΞCE4 CklgM5c{&l#+'*n|9v5VϪMt5jl* H0J-OAXP|՛ɿ 2ENT;1E%T-E5 &Y=,DƓc|0 AMbT洪 f`tCEDvG.D Fh W ݿ ]Wp<"R **7T&"iuFS}8Hu@o%.;ʩ.F-e֭R)ri-W"Qp)iI a`s&w ӟY zA n[볓dPb%y00 hCSL3eVI=1mųb'}]xkęfL+̓~nkjmic7G ]64cML<^S^ZYx ]tU_cmٔn~J}Q`w3ゲ >klrOta~*FӧEǧv0*!=gZKufǞzH#F4mcMr Σ!0E膓qC+YkXw7&#|4  u9bX1Afi(ླྀKO,L65L{3{K'3іjp,xfNO//5^+2lt6҇vȨ˖% ǓK"7$Ԥk*RS߮0XU>͖M|6%GHډ4t-u"Z3uV},Jߤ*byK93z.b|#:M:pd+M/ 0g!Gb xU#7gs+Ń( y'疛"&Ck&w29RxN ni[FvX)r}tVƒ@Gx4$$Cs=̀sRMr+E1Y M 8)ѱI^9A )h~:dEU3*.Wv I|E-A` J=@#_@;(jXuolGTϤKhF)"爎i`#zynS̒kϸyJuf ͅJwQ~<nVgTE+;~swol tG)Ң%8v؉F:QAGŁ$e4 YzBmy.ty6Pv <9j@Pw)R"e"73DuH.bI8oxeo+-,'pq^Jr'x}Rb8xѷܐV2x+♅;"cOmfPԷgLJ bzai8Z@(lE:fa^͹I?6MΖ q 7.~Rd*(LJn=µJ'F @_ڍՎ'! Ϡ9XN:7؄.j{ UW/Hcf=y ]!Ac(BFfMWJ>sC]v FzݝZ]JFm솙E_{%/H%istn}iw-`B)!D> m+uo+7<w4z{)S *M +ߎ\AFކN3e'쯌PFLܰ@^d(6 m>pJl/:I *6V%ny?)fH CwE_ЀDk``cV,Y6Y[_}Bl*MM QSqbrWvwN qU5yb|x}o>!_oNoū<(G 9)հ[+X8=e>::|8?|֩M?X2WRҧ]{=2LJhټɀqUͅJMV+pN|3+F%[T;K+95d<_]W"+xn$dI 8P^T,U>'/#mKN[)v'mM_ZPSR\bUYaȅ ?o9RJIYlm$"P:8Sb[ܜm V a׍mz89гWtǒnfG"M_}D2Րr#=U=őAa- HԳ$F{ڋ&uMTd`}PEaώhCedgb d̼ U?drJ x@9e8;MmЖLf5M{^>>fBӿqw Tyhy=^͗)hu؃S]8ER!BhכfqOVՔYdTyp9fI7cPM)Ӎ@ٵc^Ffg|,*s? NQ`vv9 ֤>Jr FN{7XLG&矖^8X<֧<ҟLc LT,zeQ -pRW++$O%苾rrr93u넫YM. =~#q뺟{pw+{xdADm^ (vQQŗQ۞TCqMڸ4)T AnV:BC]Re.z^"belF6(EL/% y: &2 ˁ}*G8% gDE! K3 1dP_Qfͳi>]մն^q -x@e [wv#aa<\PVbSGK;xoT[v@uU593ՂtXeOҤH`xę0(Ymڣ9!^%сj&Bn{ =v("SؤהLڿ'5ؕmI_ ԑijO6tO剐|>cK$>,Tn-Th=,0&Qx7{1fM |VzZ)S 儚}Uo#*yy,ӵ:F1]6ozἘŪCfdi+*I/4 >}9&$R/R†ph'KF?'^=XZDC5 Y~/$UuOB㴴\1\juN;|xK5Iv]~^y@~TN"כ\'Cl0,˂nGpj5Hф;"Ѝ[i vuZXFG۩ *ڭ巰ؘ)MlGgW1TS,xq2"PԛOƭ|sUS"$mg~:%.AT*KQH{y>SǩZ\ jգ{ 'nT-ygcV+@m C ؊;bMϣ!rM@ :,|߷wJCO %费g4N-o-BC.Fv~~tĭH H$lpwyZ)%<(H ^ nџS+o0ǃ >xh .ekgӷ=N7`P.s;eH% _'Co{BS Wk|E}K}SjՠܓfLs:1@[o$.R7ZtqA&Eə/*rħHpWvT'ߩJ o0=D8 *7O< < Z0 lwLYmڃ2|kݦwd@H_i'z.*EvBEv|QV61_ץL슫hO}/dԭ;# g|5 g -ny^ A -T8# j +ZxĞnOe}(;AVrw:Yt;AǷi~u a,ɞ8Ӣ~4lۏ5p/eJ̔DRH|‚,LOhC98Y-i cƇk%8CP+NBsJ@ZbR㔢u3ERzCW7Bhp x0UJ*~1 Y"1Rkd*'܀m %Hk\U0!Oװ)'a!QOyfnYmlCܹ~+B/-}\u*<͛dMNH */z͐Ѹ#CϔE7 VJR ˬ9@۪`' scV_Ol8~G-ju*gkSN@(C/Ts^)pLJԧIyM=M: ֦|U m[XNǓ 7]钚wq%$f1X*r9dVwd5N9S_#{7X\mj Yc0(ۤȱIPYęRV.-1qyXSApPVi.->_.JiNͨF9 3t gxM \0㈞ctzsAxW V)VYU3wƓ ot(y qL' Ȫ_pck>b+nqDS$I>QE|z`1Jа5g}C{=H*:~4#E|N! 0&%taM/dR[MB,rw.ՙ.+'ү ?Ԧᆹ/Ē`{]pϨ_gAEG \F,YoK~4Byu^eL>H/̩lZKx(?ݨQyu+":1ڨ-uN%떘MKnq˟?jOZ?S"7]HZ$S4sفV1@P0"׍n$gs_ ߓ=$ Gq!P`$v 8\)¿臨b>,`@Nd*$[n$4Uɿ RKs; ҟ-m|!W@CTxOT\6UM4|rJKG4<(uG so_Ox9et}c& *ѷ97LzӺL~-m`\ k젼}"-d)[A^b{"8m猅Ap ƿ؂[BzWQ]ևB{߭gL Pj^Rp 3iSA\ZgȠ׵^' nX&789עTxK,?=:C[[ٵ!CMoQ-k+b!|&4tkۦ  ]3*tRD>d/ ܍9褔ܬ|ΠIZ֧v+u%a]mhVN<˒(fI\})LQxi|&]0Ta g.&|3?Snz<@֣$0 jrGAp |XK=.JZBw2rI9fyq)mlm`f] e)"Q}sIe"DQZ$UcB鍯'5R^7ɭUl~0S?}I?d_yjg`\UNg+wwBIj:AÑlce}CɥpW 9 W (OSA}|Iym'狕0' u :/51BQXb64mdό!Ưv&ʟټE7?Li1Ι d ;1L"Xt!*zd᫺!uH^a2dSh5+'eZ19l[Eg2? Au;jW!XpԅY#Ղʷ$Q4]r|P6,wSPn eu{>R&c&6zW5 P 7BsI;zl})UfZ}gwnWM2*;v"I bnCvK3 U1|RĐrӹ+C!Ew2nnH2@%v>__JeM0!C3!y~G;csjUlŪiL7{CxI!:4~*td%BVo%k.H){Q=RZed<揁#(0FPأ1SM m"fPuuz]d0BұAu'ao׾Kb<-{0tٻנlј]*,k#&. {OX&{ +w{t3[#uiS{=MpyK`]zEcP/9Nk8r.*qnr\hmjJ'ȥ ."/T̕#rpR`"y|]m&,(hF(n3|C\h%;'߳QCL=ЇM<{wΎDc\u/~<*/SˬA}ř w&ޑHSOxW4kpR`"qc*'r,?k zruo>W&Rb 2 SqFAN2ҁMK cr{}b/ڐ*Ь޴j_@Ez.`;0٩LbP?@j_N63ƾpHt3]s0}sdצ#cF~K#S䙜ՎH \)?n|p%{w4SYO췤 HG?DmQFV[P-W,%nDO&RS0_J uY; L&U!q aj>ƽz+C<ի۪)3gP.dwu"v+|w3΢H&Hwʭk.\c~gj48,ih&^RoCZnnFm7a+$\K<2j6!p8I'v\T'6Mj/ã^~5G 8k xK2aeP,p@`%t_" W=j>$4u%~H#r@dMポ[2ƛG[BX" gS[RMM*0 6(i'g3d&*#`[aUl%t #BR7/y!w&}eXCSmwwʭLT\/|%d{RXե;'\,?4jelcPYʆ}]`!3? BcחK50,K~~IJ9xA_kpTϣݏj544 uSv.9IJh-)fD$ 'mRO8O" x/~ [0˹ȰdKgɔZ.cɵ(|%[ _RD# ;p(hYtfOBAD4:Q\ռ@b o{h c}iKI_R/*0vkjifq56@Md5jl&\.: b2 Ik49 m7Qc`26Wz54!b3ȼ$ޔvҗ0[ɷU5|4_,XwǾ4}F8yDR|0{"xhd3?ਚPSR0|3徎''͵ GcdM؉hQ\ITByQbu+ 񯸱yjrO\dA|6כzp4$*n&9+PH1Tdw@f{XBTEy]jʪe~1iD^c#9$Kho x>WgA FgM&hUm5@hZ8>1SA4{lwdůnWvPE Mf?#& 'S1DTOA h4fpu[݉2SK$zvXhJ%;TEw+z 1ǑV["$QW#G>f7u`ZaMSI gt5=~Ib ִY{&+9I|Z՝!zg U@] D)?Sr: p֭Ý2%N}*3/$l^mWa(!|)B3l\> ׵E_RFYOrw8EfVX[p'c>數| 92p 6/.PR"X:jaIj֌^0#kR1# ] ˍxI+!y@ |V0ᰉ _{M )APYfag'Qba36\[q%LGWt67!YV~ lNᙘ6GkP5O/t$`1RM-}ǀO60&MyLO7y4xUjq82Dltu`F\:H 3jz2ޠk/O<Xhf?J[ i3>A80׿`:s Y_Di *5}U:FGum'HcV"f6jS|_r& - GdMK6ȲV~P @|~'(,ܡwqV̧u] svu YZ{2 Uqv3Q1r>5"mדW$"'sʟX&\ R:X ."+vv:‰ȉS!lWbhSb< @BTD![lL r#5Y~8rSs\%mpV_v(U"wOKM~Hx6e?︗R"{Y"l^#@&G7Ѹ(tA.pNvGB(L/R^-BUa^ECljv`_ӋϚs W<ewkg6؜NBTǐBw4;񷍋zѬ|sbTbx]` <BH#5C )OY-[p# S!qSC}’A*DڳԤ#dzЪӵhW2꧌Kgl " f B#H=(1[U8$` )R̋Vtj] }%>HT&u"؜5=VXPK QWNrDPht]q T+:|0%wi+gկxKHk z#m`FZ!`<Z3ŷnfq1hmv-kfII.t~_Q^:4Iz]X BIo1gDdrz4# l5|1c<믾6$ܙ34f9tM[>]X 0Pk.}?֖Bh6N"]AIUtJFv^4 dQ귾 ,ɄAVi>mdv~ 詡_${ iJC4Sl ˶eh j+.JőܐyruKӗ|d4ȼL#^4"1730]#TGU::Rþub~obΊ-ytK{k^OHA}lvlXBzg&<V;UR `ЌD)XQ0UdƤ r@V.6!ߗ״\$qqJf/V c>lьںm$S\D`ZbpRJl1\v1GoWJ0鋫&;f2wl:T=~O\旅mLIѢ vӀ}a(s(K ?kV57PzF&HQ8Br)aN׽AHJQPj6ڨk`~ k7IsvS)Eș%?6Ŧs.K&QwcbD|us++{ YVFqyڳ=YYLiT_[3:Dxr D1^'rh ^1{h$FE>'WR?%~ "g( y;3ʓINš+@;ۑO|Rߝn7;n&7TL* Ϭy4\ʲSM]i2t$v9/c/k-NyC~R&o[JdJKQ ʻ;gJ2̿} *wao<jhuHV >RMRW,[+ ꂑϑYw/cԆ_T >WFR0.`&NBiOxo(諗~ Uy=|7r)E^8nDQ~ v$d s ][E\$) rpڅo9,DK or{d%Ǩ$"Ak3jLI v XߴB̅e_:ZLQ||u"|T䬴J$&䵟ra7s<Ymۗw$BU*)_gNݡԚ +FȰ<&!4r"R/17gZ}&[$w@g$Re%юێp;Ob y?P K P c*?C-sepܰbمkY㽤!1B2n7ݎI<浭Kץ=#arT"z[oū&i$@Ž.Rހ)d<B E$ l–r1v"ڏ$QG5ˊKi1SgfR$X90؆rHU7he.3$*߰|H;+DY ry,X. nE/Jemu/g"117{r|pE,&KO;nLJ=G7|zmq 4"OT 8o+q_ۛWXű$[`AI<~3o1'<h"7̚y5z;W"m(_hU I.ݒ smL"stO/ DTO'Wvass,ؘ#Q'ݢɣJѠ]yGteuP} Z`ۯ?eךGH:Ӽ::mI s-]7~. D/Rϓ >Y,Z$){$Oe>y:]&Q>/Nn|zp֎AT8]KWM * 2E]el\_}&%PA\ ,SC7ybEEM4F=[Rp*?8v.HENp/1qxu|]|;С<- H v< "e D]n#Q5Tr(tWߨSoW썡OE/]+|~DX9ԐJ]%*<8n(TOe"5Xf/HFdudsFf7 M͉f6OV5 <[;Oa9stkW>)zFcUeH2M1?F2Mj7ͤ,q w f&2ԴhbB{z".0jt[D,:)Rm\w/'AwmytɨR ϡ[wAhn$W;kgї$~23p=8 n}/9n>lzy_vIM_kėo]RWy./یbwf\;_٠*lw`ai&|aBCsz>a2>BGUи!>_l6Yr+yx[R|ѯh9jtY103P䩅isgMS ?]G4 [7UJZ4Y­xN^~BFfN-h-[/$˾D]಩ gD%3 .y\{?zS޻/PG׳纄}Lyq7Ӛ(_ YAKÛrB8^UITp컞Xjȝ>@)qa#)BjF2@ vȇ: &D֡%&Xo1={S4@.@R]&h.{>%D[c_+BX裳 w  vPSb!؞p:l/'!M4_Z&fXf[@}$@MM5>Eq9]%/whoz6HpQi-sr|꒴mxiã2ܸ\jG *jCU$k_@jѬڵb}t_~;wn$}geL9~$9Ô@^\~.웩֠(/^"_M1e)'wEn$n ٍ+Gv8 8TB PW}Q=NĀsY+SF"IH! TX54蘶i+*~RC@Yǿ]|=&DuC\)җL6xu=E.b)*Y2|_VW+\LSvs1 B*@ԭE+ikl6wԲ55T$c[us;`P1}\ë$ JO8[yfV6>ȧVQ/&]T͠}O^xDx5"h&Cs(Cf36T 5ruOMR!Xs9CH4 sАiK2^GR_/zs._.T!'TE5hO(u)kdRǐIaFgK~{ gF5Mmn\`UDarhw@i^ ~vV!b6]&Z,4#mL .{[k:pj&]4RMz]z;&SE#bl{WIJYF;ϲM4<DEYr9лYI(\{t" l8V5v$^a. ұ}gQ` f )CZTe@wV6^)'jD.1fx)3S [QڏzV "OIh3e# OQ'Pߓ+O?T9 7-2j3mE}p16}HB_ec$^@06l4'\CpUP"ǐT6Lq}'Rvf4M9Uߋ:dr7H!`Wyˮg6  "w^6g@5Zm+=60jA@Z ?Gv8G*T 1ikZ5GwAB+\ kN6fR, {b/V2Ib{oڍP~ZS@;rc:f+-4:|$zN;]]3L2Rx[w4HڪiH{̢7b`9hdbãʨu=&'*o|v!Dpbi QEY0IgV wgfM|cDץa'xia̋F!fGr\QML)'17 tDP^mcE>kǏ@%Կº 8ZYTGejӡC/1f|NYL0|35"j8FچՔ>J -%?YRkXoʁ!k߳R{N%H˅D=K5܀N դ~h?}1ڛ![hzxIy@kߐ mդ at =踀_OvE/u>ݦS`$.jbE]秠Hm1*"Ⱦ+~g# GCFA͙҈b=G)sj%ςe?JroW0t[V 7l4K :A:&D|Rh#1aF0-_X慍yc J4y딠쮛!T9"k[}W;x?fO\$T:ac5H.ܪ7 k 7}C&twZ Mc)}ҕ}hx\]ȓTo/j2Ԟ"ʃ…H_JSڌ_ *?r8'mWGtO nou (=@MtV](\DT?ǢV7rhX_;fD.wG +O"sbB-M.Ձsְvh>o﨓Hu,ܸ|]M `bSi_c^Lu"A+竢@~hm_$-w׽`;;Ś.gj kMk#΄?&:A%?s K2 [d3y&ο͉s kqFh (T2^< b#j"&ۭP{HES*0k WLc+NeJA=[ب+W0YE'tJs4>Oe}7Γ= p6},iG‡({.El:#n;%6""3wˋr÷6S\q H`=#4h\[c- ‹(O8IY2a-;r} Y_]30T^"ϊφnFqgZts(ndU^NGKz ~L?ı@T fIm"!i^[y87q&[(A}o3ЉOݮ\asʥ,?^\!/Iʶ͎ g2h^͐DY[8uPymqh9sM^oVjJ`Bl>Qׁ8,Cd Qie9]C<`@P*G ښfjXл{P֞%I_Froз&J1bѿ%so:mZ$KS#hB_Q\-Bwi› `َE5N^r }VUj s|R@O`{ZϐX;8YnVd:j@/5(wF[=s9E:Z_ѝ&D?}(b4<˗;r,6 w^dMMbjozצ58ZK#rk#`'wMs =0X /fiGrJ"Iwq&炎W('DhsFunwweiVAI43bIMhh(=J&G_dU yi% 5'e|F$#x. Lt&H6| p+V$l~ƍqU*H/Qt+-B2  oV/W"Í3 M<6+Zƕ&91B/􁩀LI$Ex&UnE#+w||<dz &= "wm<4k\Dά[Pz>ɐ˹q81z/ ĭⵊ `7oSZ-S:9J ~ QuIAfic/b+]~ iI{Fko‰XQ[2uu鐾6;PAKJ4#K(ŋuHęwgbsɤANfjxxf&ͺ];3yV瓓{§ 8p/g_h|>KD5+_WGmWzVq|ޞ+Œ+Ɔz*m :N +S; ]z'!Z+c%tzsٶ(Ç7w?(>("w`%g,C)bRe4~t7U_h51ʹǭRy"΀nЁdʮgn+Pf-2?6S{g$SvwmÒ[e0JjtŀU"rb)b=VR:~'3_A|Df&ݍ&Ede-JU( F$A^Kd%Y{#^ ^G.6)-FksV#j}=,U72dZخ#q7R2bx}wZYN-L&lhC+*&Y -bs`cle3b#6 ff?i,$@T`m#i*W\c:t| I fѾ[םĜlK4Uo tӅPCԖuXn/koIg^`{\&Gț/9`>[aBF&G"ї4SƟӫWMu6>|j#3[2cSB=&gQ)"<_&Jȧ-aj+8q?_Q ^)H:G"כ~q6#ZR,;5hdG.n.8r-hONӗcBDC"!9Qhg'h:}GP0SCI #+7=Rhb $SMb'*[9eo1»a[yN͖+?iuF#DW')@Լ9,;O>5 }LѤV~Jyԝ3L3qdCj㬩g`#t}3_^2~Ig~@R LbngKl%bb;1IIQ76}[ d;6^aVaj<=E[#xkV ww?:0z{cn27i}%5?Szv.r/+t "Ο%#QŝgDVeײ^G5ϬS5ډD+I%@K\ab%vgv2ZW 5@ [:̧b"1 jaH5u1cb)}TPZ*'q[O8|a8ǁ!rSCP8`7a^Uc늨Q6! dO]@o6yI= 0⎴ ̑YDp!&Uh%uؔ %5+b 4) ~(!$-1k7u˭D ΍^< D̤&3:cx^ ң^dݮ:bcgӎs)-hDI'_V ڵq8fY!!ޭ~-м24|lWSpAXxZ VWt.UJ.8 |Fw `Y#9eꈎKorJYfDدŇO{* ̴$A-#RdPzd^^8](rmAhfoDY#A85v%8g&}4 OMśֈQ{Ժ/_7Rxq)Kܾn8"HpXg9E{ʅI}H{A[oܫ*xq9<ک72 m§>0(pe]Zз/a0*H^#{x&Q&%Êϛ_3G&a70{I0x|0~kGyO]%OQ2لuyqvf5N/ѓ{sY}Hx]5|Wc[r:>7|+'53 n4RvV`!\L|̃Ot\m4PA>V3ME#g\t@t Z֍3ٴ,V&B@MoƢ-wZWx%V`)ڂ+TᏃRAtPTsG-(Y".>#X[cqg[Q! kr<|j"xӻDoq59˺ =,^NƮ ~Cry䙲0 &ߦQClh"-l%yhx_d|^woag9ŌLݦ~$M}ޮ)̷ _TE=3 o)>,!ŝٖT3zѽC([-o -CX_uS>Yؿfxq8E}h{/JLZn)] =Q/7&mF ]6l6_pvwfyG <3K6E"&9xv2FgS_IM5#w}-J0<1:yz !]y|GKƭOb^#Y0IZ>c+q-:^}D('E[iF9{v,Q/a+}S>tAO2:NtT]mw"Hg$okvyxe%7n̻Y@m\׏[P+{,_hb-gqNf+?N@:ty0ځ8&Wox- ם[.aXJ[`b; y:oxl?ە F1+; kѽT9)वrUJ vYE`K&#aejZRV߅8O3 \>ɷ#^<}^,=#2N_ZcMdz;Mh 1ۉWhFu__-fTE?wvqu!iv"&ߎFd?<, xB˧ȘGX,|!uOʠ@Sj&PhB/x"b8Tp^y&lj( pX7>C 5ҮKzʹ?tH^ް^ɻ:PAG;Һa|'i<x|EΗ}jp.ȂX*7ΒS~Ҍ1vhl1fӵfWU/ocӍ=dLR;k:0k[u:SN.q<*w֊-䊭oM?,xrJ}WFzgbg=@߆'QNO\m{PФNmnH  Ob],Kj~Ϊͼ! ʓ[1gH* PÛ'G|/b?e4j]@nk0΋j [/{-=TQ) Ӥ{{ҷgwǙ/U{1W-P0 G̠cgG.Eu&F/ /Xg!v{+Y* dHMj ^͏\L Byq`XMd ,Ў4)-}>QM{ {Ykc꡶Gi>/nخ鞺4@F%aAp$묳3qbH8C6 :v;għDC'm^)k6R=` uMCY]q`T ݺP"x ~/K iR2`%57}w!4c<'ľdo_ yRwKIOpjEl{sg0]KA/’E:P &fBV)Mf*B9=S=VANaoY̹ho\<]t'G9sb!c/KA \69{}g}"%(:`9}ad^̵@r][\㟛||~N*|I΃NҢq.:o_ J D_֨AR.b J49ԫͅ0ϜJ-Y6HNT(~vһ6gXp-<޷7tvg[$4bew1KpFN=|֩s]6."Qdy{!=K*:xZ5owєjg=gQn9E_Jk z2ӛnKy eLy9D@Bz!NaY,̆٘L@ 4UЭJ䝖S=jIO AzΈ,`ڿʏ*:/-M~n4w:L:m Bpf}\1}3;sN\ (9Rr2jfhX"Xuwl%͖Dn&b[67] Șru U!B<.ӞlBG?-j"ryBf%'2uI^JvC#񆲏z~|H&PU)Mb O$vB88r0$/ve^e5Z1 s'y=6b#b[V4y!ip?/g"ܾt֝ ӇmrLD2<$(%i3h\`>]6OmyEaҵ)4J[&-@YgW-UƐzF@4th~Y)qg0δ> mc.)(E%b C^%䨥Cm2eߒKii(|sZ=tiѩӅ8kȨNZ軨I12?AX಺mdI_ FED%~{, -pǚ-omQ۞ȥ>#ir0r%o;O?zc4 q7!GJE0qݕOzl-~k^n?VFdUFE~ z%Z?~b;QunVr?SW|һH^ݧlvkuLN䭋PrH }R7=SJd1TI)" apƘB2|O~l7|n Ǭ dg$)Su636dҐ'x1Jޘ=˿3.ƺHP%#v/*qt6Xy9FmC_f.Aݗ 31?A',xΑF Bpyl,\%|i].UhP*]cbe_X$N*V֏^|ʥR"T#AnԻ)XH.Dqm@ITqO Qu+.AsLs%^OSQ4 A_MI֣bc[^Vkь!?ؤ=зN€=VïokCmI{m-dd7U6;ՌGi|E=~dp2P[!%-btώ1=gP8 z=R~1) SM?`^AI`, ĈHK7Hs*Yluiq}2?*l9s~V}1׺0Γ;?Ma0M zWɽyX xFRFsY38Xѕ=岐v~KzX}J7ҾYQv>Ne, ^*2o߲or%0N I4t]BEkG6b1f~iP8IQNՀvzPy%Lä4֖*@ޑO.,\X2{^>BubfAfz-i tDl(ё?xuOzbBو{8 rN0yjxj.jJwCIX # ;k چ UG7P_PQtdN-4lRaVB١(FS;#8!{OiL6h{ShߜX"כ6C%Dw@wA6%7xkDpׄn0lHC *DЮBrJ:8%i?bMOX.3u$N7tq6{|9.ɺUR3-JdL]e]&svBJ"춴}e*C"/ mΗ²nNМEYLk^DT!,Ԭ\sY\~7wCg(x%"ښ`KH_N2F+$˨eC+sܬ֪d09+\Gl,vx^MŴ6Ka9j?Y_Q-s47nQσ*؅B}<іL(feBJx{\>J W=DE÷;pH3HkeE$z_xrb`Zf NZh3r+"[_ԭ3ݑ(Ր@ܭ M-Nn?̫EYlܿIcTFxo9pZH>FQo=\+yjߍ[*`֕#r.͖4PB\$#%8,tY`:]mK8h n/fFig)c$y,2$%d?zZŒНo r$-@/3]&<ٲ Rz}DMv/絽ӊ UM,n ˠO, W@7"[pᭊa$5 7KR2yQB>uvS˜K`Ne;| ʭ1ArdQ$FT@O7z~8SKbUZzblgb+d'o-E3p+Su Woi%-\ 8$@BmV_MX@fdxht`e:pI %Ϣ8c\| A~obڝ@D^&V.,+Pׄ^휔 ĭ[oa>dspgttMLaiiH/l<,^M; yR u[Gz[<]\"DèkJeGh)suGh4$EP65Fb2Z8-]1: UBd 8m2jXt0ƓY. TBs {-.Wd'={\\8a flDഃ?(~,s#*4~7*>,t{} iGڌ0uP·|:[2 mmW\GّY=}_NsGEh!)fRl^f9z7MuLxn ߒA4@O 3u䃭{_~m&Glxk>.;Vp!V!_ݫv {=[T$/& KNPGcrmx {n1sM ړbYMN db etqUI$G[oTOLh(69_\Z1C5…W+1ړ:MEq#GιUj|}LJtCi3,R2a-ѬRꅾEFN(l P|(^5+Sѱ}yLٔDUC8ȝ9Doa;ܴ^msBg>"glflӫWNZ;Uur$24mi-QBLcxFvrT2eeDzt,ο}%, Om3#IkDQ@{|#8 a⿅ؘУڛQ;iAR,}_7^2; NT=º"i^|O'ɂN"M]M{Mm쟷&XQ*Dq#ڣ*l ef(Do]4E..n#:)72SbsI+AW mWms[y {H/FMerq I׈IUB_{ϙ<_g7)66?h <+Lgo7vo@='Ylv)CO y|1~H $|_G[*dt_Ab[:]zuL-clOX\[^+ݯ)Șc@ R_o ::Nsc!"'i$F< s)N%s؀h 8|C @ XwGvw+$zNv|!@@T8_.{\gc+Ϳ+>uL7Y^])uSIB$40@j>m< J_Ala=cCyH+d-G ;b9#7`VN,u)#(uI" ;/??lxDm:WGaK/vLGE+}\ ݳyҽuxW=J ;ߴ }ǥB&,y8]?-5!^ 53fip$(9!|L̈́Rc-b?Uܺfru>Gi9'Gp1Q BP^L7U w)H.]6{`݇ /Id!f-m#xJ.򸕶dtTm1 Kq2ͩ?2j|M"E |7X amr\"^2"PR^2e*߬ri|\vHo4a /翵b:;*+4I T`j-̷:VPQÿ',¤o~йN>j$FHk{i1p᧒q|~~?IΧxC4Fn$IWSJGFnb)yItuիB47ܟBJU& \\'coLܤ(9*YE!x~~I]Z?\+:ه?;i0CW?ChXJ^Q@ub JVp~Г*?1C~4j%e/z\ =alDSiΔ+Z-%Е:!\mIcht?0nŇxRU4o 5A ^Mpo,@GRѩ퓨U*JdĤ34h:}@uUJ{z (hK>y3W`2]òɪifl:UHf.dP)OISmd1ADLy7m*U(52[E͓`0Z7HKW)3}V4FPG8$^A%2e܍l'S\}ՖŔa̚[S}OPk#s?8J]Z$>o=3H0u p ج@-bo&*ґģo0T4uؘJENƭXEG}saIhFJfs vc N^L' 0fVxY:@<, RsTp}+C S竎%b ~G%r{'\.JF! hV $ꏭd -2n9<č2[[vokћ69XFݦkh7{2kؔm&Z9# |w<-I4֡_`lw,PI^lŇ.ٝk Zj䉥sXU_ m=+gKGN "X2d/_k(A!PɱGEup5ec'$}*y2^/7⅌]@.F߾9`˭{epHw~+.Qy2BP#ۅsAzޱ> |P{ 0Z"$MGacPkpbꆟ31z.#@!Xo菈8B)v0ݨ^)t+sBWS[Kx -)J8zt#PS.-IX>ގd2 ۶#d~q(={Q, QvgC Ѫ odyuR3a&9C&-5OIi5(WRu {hOK;CZU.JK{[ڹoakKJݺ)~62 b@ *Ac'5~~;Ƅy fU,Xis |f]GBRQu:9ʑ2aHk[hPƃFaB_zM yմ֊a)Qvm S=i򵊜Z|Ĭ,L@a!W D ~T6"|>G*wipgA*}7t’f[9PS߂5y{'&l{V>k@ϸH)vw66=bw[%/gPq"o.** =<9E(*j"$W{ WSN:p\5VyLh^,jBmb䬔h,'PJْs bVʜU!o-3^vпifDvK9ݢR18:xFu0AY2 @h@ZU.؆2)0(>=28+E`E%ǟij` yxE8. ȚSzNUL]rXX=Ĩ:-x/H),a:WsTF8fa3+zQP7kBWU{5Ǫ%ЉԵV#kӏ~fXОOwۋOԮ07{AGD FS7qZ L vdKY^Z/ ˽դEv@Vpt:IhnֲN<##a~ն-S~U6e:<ុt˿kO{<'oxm@Ayd]:+eh|tk{1s'F,R,_g||s*]U8ծ0.5~< (s.}h{\. ])6]Wח2џ-`sdF*z;]XJC*q5IT]r0)/HS{"$ILsYX!Ԝ.rev-޸-)as{®)3IKR⏚/ ՀInsCl(19h̻ Hsg SZ:YBeu5@KGq63'ʔvtrް> l d3:%ͱ[omðX3QBSƂ&M:DgndHUgQS9/_T &|"9c2۩&Gg6zv BGz Ss#֫kϏ`_6sh؀0K©C5/.FԬ g36xmZDΔl]Gኯ1j;m_P0p4(CRf%k2^6"Mz xv sQ֕=,kQ]Mdk;d*~g@f|Y;r᧔9…'*LovTؓJB4}]5@ȋ@ IX)I)d&RyLq` FW,ŦDu.s9ke7 *Q:F?QNU_-x(+clXs4%ɦP-Wf)x5aa xrHƬ~Alw= S1sJ 'T#3cBmBξ?=Gn<2u74^GzJ_kG)SJ@WjnT{~`Οx[ >>aߦS?#]X2gm3=!>rJד?ېe(8.NL6K_MW6A.+b{e2) "UWv>04>uGbi7nZrd1TӨ5#:N I2M0?ߔ͉q]W_Orp#Thu8 Nd 7yUe1OYP89"ᖀ I!>9"w C{+ $AEh1)6!E E'mL )ϸ#: -ej vNPm߀GtMm`$̱*`AϿ#V*d ݂q o7;0d腝CE?b>Xj&)l<",U@Q1b>F16kxy sFn(E6 8QvFZrdzߊ@d.Jɲ7J&k~W_ XH#g- h~tOy` V\/-韭Y%H)6AVU@-M$ 4^T}Lɖ ^ |3.+:838(lWƯݮV/&rҨ+Ӂ[zpc2bmd 2[h纖>3 $aXy p> KPRpLQ㴃m(=A >eٝ D" ̟ V暗c4Sxc'7IbQ] d?D#s:Qi|Gt$hLJ ^²N!V0 =!U+m'Z?}~ԯ;*.msAK,`b4\%?O2hZXr*X>/Н=dKPVIn=%M ljr\qǰkLڱ`Yy9P;/y[a>!lHRVctek_ L ,UyG[nGx{^dQ{_r?`Bwrw}{qe!F N .B|}G>3"WD `\cba[\(쪿ϠvO CHˆm~R+6Bl[tB!t4]&4q껳]%9}OgTAw}s)X&ֺ$ҼvQcHo8!.xi(fEA Y>w#uXUX4qϝNw[ux//^U0@` HN`/\xr ɪ<6r\nA9鋦0l,uac/խ~ W)q˳{Vե4g8PoQao!( jNy-[QBKNPw<]k9={|tk|.h@O%T34+PW3QSqhT 7-vy!j(Oooo{<!u2T7plnۢe MX%#r$.::Gg_߆/ͽ*dm\|qGiT@_mҎ$񚟛PȲF^sh3)ca^qw1Q9{cN1oC,ۺX%Z8=dHGM o6kݾV~a}&YAB<YI7/aJ #j\ܓU~ZsGҲ+J~UIC׮<,ꉻ]T6Q mFCR]6V}=TCP" kq˴ I?.6`s3>[SO}xwdaZtCG-$io8ױ(MUEIGO:xg_wUjt\Y0TN1>ѭ|KkI觡IGd@ʑN,NЛozV`޴JpgU¥zÙX?b{nBa_䬏|jzn5pB:a{}I*hn~xzoGN zi;4t v!ѡ 7E[]V8(f%ks$m=J@NUGFBʐRUl$buq.ťO =)iSaٞp$Yy1c5HCVyG ޱHǬW-F`+unRʤiQtM`vnox,jG{WalѢj.:[tY#!6j0o B0Mu(PwΨ#qX~0ZmcL6u Ƞ*GKT0gM|Ѻσ_@9^/Q BX. WV3 w[x >Р ! UyGQL0IYSwɲwT]r3рa))ikrԥ|@p/i[b:>׮1z6y}Ysv{ =+w>֡fSgA)Y4%3?$~U{FRE erS=64&7UD@h_x40ڥqFY[IQjx%FbGg_|8ƊRƫh.|eB ;̿At[sd+_PkeBQdHYU U: Mϡ;Fmsʻz=')aXgDp!A*3D&ՊrN&/l3 p[MͣCK~Pc9HVX}[Aj Onؑiq::x1kTġD>|+1Dh-xnv\*-g$dV%?i8VRxO^Sej˄E[ƙ-\6*`p#30]3B&Dd-# 2 ei6Xl [^>3rl*4%̐*:h<şwvu>\t' eZk ,_R|i*=j*@Iw88cUE i/B+<NJ i&!椆xS؊Bɇ!ZO2XN|(FF1> kkL3KXKPZ6Kơo3O!Ў؜ȥXt"h! &w(ɦԓ KG1IhUbN!0Zvh3c6`uj7 [i{,Jfu9/V@ݻNW(7n뾾2id*m1Ca p[ O`` bu~,r]mY%QP @Y7'j11yRi֐Wj]͎+!5T9rt;J)iէ5Qdw!0ףΔ jSEVOIۨNy-<ڦ340=y['m*B%`ˮo*1|cpw!FnLsG M󻏕Ԡƿ49U`8V߼sѕԝ>Y׺>88`oV2D@ Zn|S>*Q 1U9&DVaj_zw5m|c|,HOZrc w5՝ӍFs0m )[wӤ*Z]6p!R{9YO;đ-t'=Emǒ85(89#KOWjcU\o"Q/6n4Gљ?\%/ !mq:v5&c* .ðs=Q^HW1[w!0M %~{>f՝5~ \35k*fS5FυT"ߕI;c\0@ go v[WVc$^R g[Ecx $}WǞQhY=7K X6nB kLQ!B34Y"݄Vc1o*Ycʵmȏ#](2G1Yyԓ<w<1.dw\ÿX.#ׇֻ_ع ϛ!2ܥoVit[sK+c8haT%yPЄ'p@bI f^@ŸTMH p,o{rƄBpͻi7s-r0K@2cᶉEIKqfqmnv&S3KcKam_0Zf֩S@#LVqܮྏߞ4p(}K2*8tU4ɰ.;ǞgRՄՏȪD-Tun;Ht!;={t1q$+yPTqK6HɅ*ȧd#&8+C~7J }G!D!afG (g!T=u u) Jy_X"#kB闏5Jsms^4Z}SݤQs #{z6]K5T\> n=5 [zWo(Įe 4I<pU(PJV[A`0N~q8P/rHwePAx.5` Ep<CX8R&/'$Xy<3f5qp%J]+avR֪○{ªnR,s.8G;кH~JӥH8n9ǬR68%Yc NO*~Y:t `L(lQ1[㊃?kGZS:|8JT*F>$uz^86} AF ͕a [@{$/Shj^PoǚnF$)@/pn8⫭;'՘hD\ƣ*2W@AX⿀46`:ȐЎKtR9wQ5ib8=7 }o~dCʾIz`"Y BkZ^/ pB+k"bKit3T*Uu/^5p)(8+|)V~r] tEt 5a5!%7V@~$[玫cÔe/ۥK1ɱIgm|1fs"0%bX߁NB8#\ ):gQKk(l F!ҿ?:bmqƠmb"y\D1c /hMTuh^I,%TߦNfHzʊ5r!cl+Ւ>nm=@kFYTqk>uy|w&Eb9`cMTtj_vݱ4Iҫ_bt]ꊸl Kh*b׶GeToDsglH5j$:AM )F/ `!H ,}rޗe,":_*ݖIƧh11،!'@;]IJ{ͽ79E/ھw Fڵ2d|j,1#3XPTzZ,aNrb^o>uWP T`To`h!bXKf$҄9*/ dGBKn˹_9b?H;d``cP Vb\T!Q2sqߵZ= XViw4:<'#, *ƞ̈́nP"i?#f hu_cy nv 0 3Bnl\C)C-ː-;Y7Pb#IeSI^zGDSP;)|_2#>v=o 0&K[5. VbH<}>5(:_XKnz]O^>q!JPCǫR[ ?1lw9VxY͡v.+,m"]'USȠ.*>fAvc^˺$ZtC Ԙ*$hT;[,k{;&'*d)~:JdMjԖC lފfmFf-6l;Y "f~<'*y$Sȋq^ -:ûwzHoY0nڊo "7y,Ku,ZS~ɦbZ_V&E^Mmz=ӏ |{ _b!z{',nQnP\-:T Fy̔X(MFcAByZ%^.:Yb.cƏwV_O,@*|y-lc|~ %ҹ Tsx۝'ŵ)Ss>sHY7NP_Z-_…a2z&광c+ LrQ#5\Uhy+A/G|% 4Z\,-QVa"đx,➂[}lr1%C",nT݀~؝VX!r#::?qZrqӃvȉD[8= IL/M''rjiNG\QGfkje^ə' OJ4G֮BG!#a[J_i5W4'm k&X'./m`ǜ /&[ITތ妓ԩ2e?,)GV6_TJg z1^j֑xh7(o-3#Zm (Fɏsnmx8&_&yаPďU=eLo\Feu,~%].Fujv|y A7@:"/ﲟ$ t#U4 OL`PǤؐlU>. km?$`D<)&&%42V:yzGNon9d%0wWliڇ- Cz H GY8 I[Ӛ/2fH c3/D8b*_NEGg΀Y}FӧHbY1;9BvM!y^0#vqB̯| ID=5(ʌ*n֡LT=ѬoCAˏ̓{ @R R^J˰t-{O7:Mp} ;8\6\LA#;.eK\^Ytˉgfwtr_nxtΦkGJ;.Qm&^o[HBixJ:vkUyۏ% гFa3Aj9z@=sXׅ}TyU'Y*A݃@`)D ӷ3Y{^lMg ]}*ו}N;-CͽR_eÎŔS$A躉2:E] !xduD?ɨoL(˧w-;=*gEɎ#k5DePn G:eͿ./_@;i0 5>p(rգ`*r"[v`~cDWP* i"|ߒ8hIU$}3Ųva35K=E+Jom5tqC|3Us3Rj850}/˿1RaS3YFmhԨN!:*߀mݾy?t w O J^-(3ĐjhfO_:N CT|>bEPsQf-w'OIV6 \Qթ"tO(Y5c!6i#ZEUd{G"4r cq(YxG7Di|ʟd4`yv VQ}3Rm^ߝJ~UKtA/@''s,OZp)5j .h+Gȟ8~+F-k>l!+Lgg!!Njpx_ScFW7cCpLG~a9vx)49 kY߭t<ٶ-{ĬlPP½ME 7qFXu6@cKJsU[C# QIQ6l\}i$ȱD/c34Hۼ7҃GUWAٍWzɟ;ƈsѪW+J mX^G7Uy;wUHcZ h!W#T$PZUQ`-IζKʓeZ`92)i ӸP8#y|3Z[F$q\9f[iID<7?Rs!RZ4h/j`,Sae /0 냼bdKc&Ǭ`/\ e:c 㙜AmGp'{)h}A-R iҬbLc_OT]TT@jXv;B.KD{ kZ M Q?{[o8_ C/Q_՞([$wXVÅ3X门 T= c*vXPH"۰Z""N xn/7 Y{Mz1@T0b.zTY'Ѐܵj7:(a,˨~}u]-.i *@Ӎj Z⛷&!wxMa>{\\2-[TJi5KG^ l9u>jg1AW I(U(Cu5sbiv߲r@\Ẓ+R|*hD H=P"͌uG\=_ߚr2giNrra.69AVL|Q*z(;v 4kAZP"wMءT'VC/Y2b!7'igH4T5#W5 dOCGsb(9~rg}\d{!Zqr]Ӽ|V-^sn/Ȁ^5N ;TB@i^l4ttyUy$ +|RTThT 煣(&}⤵\~wI?mT!TD15mC~:"m3AXr|j2&CUĝ#E1#>q#阝;mdlJ˱jhvWV@8l"MSNjdʒpW(iO]Rolߚ39:Wby(}3Xu/jޮF #)=~pQMzi 3Պ!j'lvc=QAXTHCċ6Ʌ/1de\0y,c5:r!K`k9 d\<޹Z<5"yF87ޓѥ܍ϺXEnÞYV:,rȖU0=Db#^E) @,`A-x_ivC,v-MMܐixZlXՁ[N*+"'=N2[ %JU^z]g-1ffZzCU" ~CSǵ:=S9E3w"voG"?\N0I %xncj6xw]A%Ws#׍4`zIe6Sq ڥ.UVF(B݁ ԏ3B:U"`t:>ǫea%\o@ؤK2Fnu!J2WҌfv.[l+ oʼn $ (P9 7ʓ}ieySc%)'Ӡ^g ;_0%ӥ wPBo@kriîQw}Wt6ǟf >Si@k{+F͒­FR@4—|HVRSph ?oW<RΒ2"]X5M1߻92{r^0m´V=3M 㟘ry/e݈osKn;+Dr/ J0C<]ބo6 0ZT 7j?t4.FőL`aboᦳ1]l퐀~(Ս2B@,1?} ̃C[#-+9(ԫR O@TZZ$4BSLDڟxMEvNI :@b. |Ekߚ}A @@KtP#52 N %R]K7߻F&X-- )K;߉ ]儶>y=q,/%Si٧3.h"rS]㤋~Gm|5[WLlD~=,vӪG߃gMo $P&W1st3r`o>>P0RuyrmSCd0>AU!<^4d`k8[yc"DMlU}wK"/m(`w!Ш:*\YooR^|ŧڐ93+aP*E |.'c=q5=7ֽ^O@Į21 fNDTF*8 őEh'BS`p4'zrhSxX5h0n77s?^blJ1ho}'4йc< 0~NP~Hl`;wP~݅oٗFWR~[dJ~۰&ZŽ%Np$:~u_Q , G\"TdUXښ0n,>^jz>׫+k[K'5XaNyƂD#X&$Pk[#:eٷުV!D=$3E&p{!~96mVG^neL=y̘*$|Vzw d;3U'cͺ(ӫ/7O%sQs_\ؚ,])/-`-3U$j7l}SNQ,ሦٵB70"١6Y+Fh8;]-sGa=RZf"S͎*n`ה(0SҤJ1H*?=OqמAڡH[lW7QK/.cSi>91]:¢M+IIWՑоz (貧+rɽ8nc&^h&,ҧT>VX4>Rk^B{`)A^%[GWYֱ^i^bj5`yAWn`L?$u2G_EXIIC[/ۢ9~@Dy Psy877] Am#{>1Aڞ52pdDf\TU`?Q\V0_?Glp8g*d3b冐*x Je/ ?uVAQȷp;^iN;(bU>p&#{&PojU&O)x;kjS~90@J:+ YV!̣,tHkOCnX~.DLC\Hx$xtV&P1v'>T$ g7HރAI2~MƟJ/Tir) +ؖ} Kz9M JOiSt(eL>%H$XG=-Ê*Ze3ǒ Ʉ5cAx $VZ\ҪuUJ!DX8 #Bk,^eldV$0ͱ&-!\"ϓW7#+?<9YXa-kJ8ؕD1KUx!v#bqJ탓9@ƦG2p":_w\8"֦hR2tBnLU%`2)`NjA`2~gSK1O\ @HsbauЪ (4 u?!8+PeL1ط5;OKnKHI=p|Y@ "h46P#~ qV JԿR۵_{ҙKLHUYţz^Oxn.Ц+7hiz@gsVRXDJ E#B-Qg.d!ULb7`Nl-NFQm.ħ > cNpvi=n`#z)NBLahIq=zUL7zwQ#O7ڭA%; m x9ŕT>QP3#}ӲGȄA!U2vl0zʋ71.( ~T}U1 HT/x&83/kHyoZakٕ#AK @8d#KBM=J?.*BǘsK'2j'>}+xIPXes@8׿+:Wfm@X-rrC:vJ6C;fQԩ~ZT~ 0h<=Zd0urv"HK*^Ǭ%GУ)_:kJ:wf?0VS^kţ_i;5z]Do0?Ȁ۽fZC5R>$:/qh>R%=j RkQ-zTnzҀ}#E+ o*2=Oi j8s")2~}ui|GשHb[j} ~(cH 2&05}LZ ǐMd{WGO_!PuGVT[+d_oãt?dj~$ׄB~c, :#n>FR̳)_+A!(WzbYċy^0tN,8K=^gs.@< fr7^5fPP`HS9ggmS* kAh [Ee(I튥ʔ=&cc& J6K L s@5rlQӨ3= Í ૮TQ30Yrd!,Lc c/63ӓI%7XD;ۈRwdr9S{E.)(?F[#wƪ:OLɡ(*춧n{ {wYq*|Ap/UW:lrs7hєJYQE6o U h/YՏ#ǑpCz+e㑜׺.?3H01xIi*V䱑,>a8(B{*U9!仛!.cal}x  IAkr%UGs)+ۊR:bg j24C am/mW'r[2 q&:D'1:9̻vm \/06D7 Z.LjWQ."t}n{JwH,`z[?j(0-QNa}4xX^eGGmP(@p ?R]H}i/ S% Cط۹P/֩ jqgm8TQ(tS+Rw⽋TqxBzHfv~[" ?rP'!Jce'r +%lRN|#F tm+:d;g1@{Rlp27,lqM򇦄toYPZ*_a+EᆼU+봱 R>6&NT+fPKQ`91!iς-MD u=`:::M_ Qo=Wˠ=6f8CO@nΕypk[za.zu-w1N*ΗOU#en PFfm̫v>Ei{M(h˙e=pMG{[Uj/ &tg+ϐ̘ 3DMs3Eo+#lt%n!@Uio|#9WS)m6O-n'HYX+hE4i݀>Ibk~"Ppvč,\Tkg8 tpR#I0CaS߾^ߚ-/~'\_]C7BD9;^p&Nyl0fbzDCbIg ޚ;ŭaF^+P#A@5dž)h`r:-,E9ms\(G#z9)mKA~b$ PYSר$牽hF+!IweVou6Li[Ӑ}q`(i?â˸HrcVs"ЯuFK*$}DI2j ~\ <=\-c3H1^W&{?Wؒєs86, $%Z+pnp<<%C@_ϴY3,OaLtc6X'WSB 0Nɶ@'=;]ܜC pޫ_l_vxTl@)Y;7 [| D"kI[>t d;ٮʒ-3mLC/$v$_qޤ~ ^ʺHD;$q N̯z"r`m=l*"@?13`]|j.X Qb`D=ic%\E$oT|MgKrh8NAdac§z.}(X5B娱r/lV6[ߊN qvq"A 6Q:$Q9IBn{ǡ&J0|Tҋ)uCOv$5Jzmķye8zBXcnI]zRM5c4+ghJfn!oݚyk‹kLu_֦| nn@3,_=}h/Ϭ.(k{a_m'pQ{;6[&? JV`˴LV6Q̊[a>9Rn6<{ !_MCS]Ϲhz$rY_zJϖ>{LT\'ahe;\= "7LBP*?b\xra)I!N.A ?lFCk _tkfh"رǒ06>`|p΍H9Td41 s.}.QOE+/N_NZCĶD2&NF!갬T{h eщ}/b]lJ5Po~NMD8<.OabK.5q/)d-gFBǸ}tv<"{`c2-s)VoWH#7'&`$Cp#4-ylV#žVu e [.Am{z;V'6J8:zZ9aiHI^Gl{tyyI[/;b Z>b:؈2jl@JQ+~~yx{AU j8A,4[a޵m%bNq1)ږ4`ÔfޕޝrTO)gG" >q,oMGT{8bDr<_9MW*  fjՒ[K41h7ݏ!Uury˧.Ȝh$ HyF(hPba#Pٷ_IF8Lաk%ݏ혵#1I?bw^R- kz-`xGaO4Tډ0m^%*Jrѝ !QFt+hd :,aW/=\fZ.hb>A"pa^ՏIRd7̽' [Krj)[[so&HUNB;%S|Ev`\C "OR񢚃.ݹ?|ya %q x`LP_Sb0:C9hɨ*0?Ԍ]_M#,]ƅBdF3M)Z5}. ڽ/UDUδM*tD W4 3#3r.Zz/!l*KO(LHA٢dh'AG7nA'܆NIr_m|Ul^WώyT$XRRpK{$ַ GJhm|*f@._;FaI2m}_ZhmRȒOTlfi6Na OgC- 0ZOjΧiݩI~P_5=}*Čz;=e z7H tf~7Pgxf p`'D~zЈY< v2?׺+r @F P5MG!"J2?_bܢ@'t 57@2 N[ZGta;wF5{9ӣW -8 qQ.Qzq 鄠ah>D3n#?cIqy#\:0}X\4Hr nMA15$UIn?ENg^D4 gIW/|M(y,C@9OȎ#\ާ)~0}J/G!k+0e-T)1lK2OY/t f&q, jzUeV9~b:t@_E**koڙFu-i$ J``qs3pk˛_56d m81w?3% [r{NJ]:{|_67o={ De2dʏtՂ dfUi-cJ- -]ݡ+N5aN%tukBrt.I#6Z~iZ02ޡruU)dJ&cdҿғinϗ6?g ؼWn"ECc]7&؎A 8k JVgF&6UÃQt8mZbdNJBN%;x|xZǎDϬHDb̐#`HA޵&{1`p+ɘTm+W= q Q*B ,O ~U*2$#E@4*1|TAN&H6{}DQ Ȧvs |̎@(vJH;3 IyL Xn(jszy|t{xxmnkM)ҷ,$\kU"@ql &˨Ut1D5_`J;K3$'Y _fy+98\]Re#p2Iki xc4 a*GdNBJ6MOZNf|6ԑ 3cƉJTEӵ\"+f_5mIeu13v9 >BOB-Xmڥ^T=nK>\"ų [.jШв9!F^"mB4@` >Dd 8%8RIÊT_.ɖA*ǣae؀ `{CX({`|/}h^ȺmU_CkW6-"^Ht۵3Ecͅ%e)BL4jw \;uN?s 8+ 0YM9grJܯ&:{? ZȤ^,sS̉p/ׇ3o%> NDv(TұXReFxTy~_A  :L@Oǟ0IWBÂ˭>-^!*>3``n xS/nܤPGw,`[% t[MHn=sv8<3uFUSQ86ľ"Mo !ȱt)8?6ѺX$a[*CjsT) @6inPR rnýy cxL6V6( =//NR ;2ZVtDO^ٴ H̑ET9jK/7$  w sU {*rk|*JB|Wv?-N]6dtqT利 Y𖟘`q"b2e2F\TQ-ÇE.01j逈zI"pI㡝M!'yɩSS?ol /L;R#7$PNդ$1Π5#:5#ɮ-5PY?֭ƔʴΝyrtƐH(NJʓA G0]aEsr&'dK;yCMĦB{N5&cS.zN7~37W**TAw^ 벶`}߾lj2_ ǛЧϞ(J Y&q|pg䩭.44*e{ +hAH4y~.ludvqGzWE1N *͵ U='8b`IJ`-=@Vh-==2$[>$ܒp@hsأP*~cGsWt" S\K?''=ۻ=OYJ I(II f:e99nD'o?uX? ,ᐵÑ?Va[B&hLk<YU/Ҥ1C)mEAd 7v!̈́j3"U{4QVf%)i$y;*0a[w `ojMJr1QD(`~;pZ2Rqrh_R7jfg1,aA}"YoJ3(S<惒gp%#//~(QŊ|2q (L:n &R9iS )uSPJg]0'֤pU(ש_ $ GSSeG{v">a]N?Q*hۺW*PiU N}_6I 9 2F~ّGR/&Gyp&]b٨͜O/y!%&dJڔ,iȎC$c$@DI[%y:9kPn1ih'=vpl{$`[{!.2/^D#LQ[kiPMÐN@vvvI SR<4ۅ=RN3jSV GAk-n`{i-,J/kWY<7| ?nKM}Aݘ BzzXZCmp~1坱gtF2UO9HăuUfqEb6һ L,QeR@6 7NP, Z.+R`@٧$d`oMǙsm|Z;ؖP:[{rA*Q=NޓMY/ڷ%)J(nTqm K(ijDwyF@7->U @g)Qs濲Bjsgju wm ]eXoy4fA?Jpq`+ kk1i.v$7Q>} 6{M X'A\6dA;.MԊ0+[`Dh[7Y8GiOAo 6/YEK+&1Q=>wY}sO<h]YPTc^m, -iޓ=O/*,\DtTl]yReh&C/;Z7,, T'Mdj &hDr63)%V5 qo= vMVarr.K>֧"j\nt<ڄ5 GI v"lgr HA*q*'憋 H;TRQjgkBpX=𳣉7i ߩ#]՗SkqvvcV] 50-|fY|cSm`/ZbZZ&N+<9~~xL?5㮯'=plR5 [X 3g"S3dX@/81Yt!TvpÙ=xTu'>TaCK}J7U>"SÄʭ-vtn!YBvLOPٸPxRb6))! */r|R UBڠbǣl|Q>5U/%r 8>gyoҴ,7҅䃯 FV׷'w(y?tзrAb̤Jo2Zg+)- {B1ӷz!+. &%,6>,w7UZe k=vޗ*%+|JeAuUF,JJD9il"yf٥-9S1)=*Lhj(a!92_~7pchxlV(QKͼYr՟voA]c(qH >3=TRM8o8B$y+pј˄QEq5g=6]gzi!w]u6ʼ*,F8(ED?-boDq)ǾZ]91#H1{sQyJw{7&Dr¾pH9naQ7b~$d2a1}wyrJ`b*cpllC/2`#cVxB ๨q$Z7sO({7ؙ\_pۖIQG6.VE9qVpP"@6V&2C2n@efcXK$SCavOp,kQg.Az[ݟʶ*-Pm_B!+uqr4᩿eӞWkM+?`!)OH0!i`oK3$j#E$ >CYI MEb5*0͛YY޾wZ޶&N~yOv7S1#I+T̈UM^}M($t4o'x3?Ƙ:5H #{[ѰUtCFNaPuIN p<7Q^clр*EI6\tLI<'ͷ[C;7k4fW:A̪`+*[c|94F%2k3&Ç AY3l;n3p9o&}umVbqwn)qQ"Z |A N脐o [ALܻ%9&kcO' z-z͏ (!L%g L8Ǜ6ׁUS/3^lrrAz;Ҷ$Î f$(M'T+S3G)g%o9ɫfw{nuU#Y]v z_c84qK&tˑ~+L7Hn "+\#V0\ c ѩ`gSz̞>YE 7c1"vpKHe]Ldf2MFU4?Guy0*K7+H/X_rxq+>T*aKuI@;qHz<͕XȡK'! 4wy&(iD:?3NxY/,(Hd v0$O}OG۞f8H h #Ls@ǥ:xHIS54mRDT`ȥfq<9-]QT|jALKd0/4wn~(nhb/Gx~:Zca-l^-faNJ#T^L3êy5|7=S?Aa.ٲ[P9T/U*yz}Ϡ5{ܘsT]3{y*]/R}fȸjBy'U(-K\'+D{Ĭ\>p8|'ab |QƐ0~zvִJXff-:ʑ[40J"\hU(ŗck3^p9EЋ$ ԩi2@{חB'?t<~ST©íB{|P%KwKH8?.^}#L)z:bȸw6#U|K&+% #$2J[W'tжu%O_"&.-ztF(NeSV:̍FA4EY|H&NdQl<֣^zY0U޴kP:Qx9t)w# ػm4+7E+0UF2\li#w~{Y iRET-`z+͚1ەcX% 0ikː y4d)8n=6)ԯY@ղ#\h!k٢m9D~ulC= tE_$+(xt|])~qʞ,&ylìi#E,&xKP%|b gИ|+*gj! x`bCP VaZRൎo< ^)+S_!^#k5_ʡ;GY<) ඾D䳉п"6r|]Jlc rF_ǾBy&.mԴ2yP@93\}zp­@ 9XvU{xvF92~dXI$ߙ2VWeFBƼeyi_}14Q<(|-F^aY9VoG8kLm1j i&힙YAjӾyZ^'n?i/B DW`eĞφz4A Uᒷ?tQT9cI +m:+}pm˨ hrp%p8}ϕ٬ I!٦UK[RYL'2xUmcM3cLc(7mZ 9iTZy T͙"b+w S7bs{ma2`z 8!%CFQl>P -ISI4=KV'7ґ܍-B%!MF)<+[HKC{SJ;;WZg^EsBkU~kI)-/AXloUȘ7ɯ>Nt)N|}t/R"\CDdk{(-L\~,j zǘf Upp(.(PD@ [)*Kd:s=ő‰uFOQAIn?w-s՞YN_R I5hȞDes ;;14O8qW̆1hxXcxQd4 xUݒIr =)0kΈ T] Exi}з\ogK w-A ~.ZJepoQ?-e& ?ʊ l,>T94é6zTUV#f"wP8u+EpuXK*ȅhm@B.|bp }Ȋj_LϦQN("=ĨVuw[OÑ~B:(ٟj zdBԻ5g4 "o[5]LrjA'zٖgqE:Wq՟x M)]=L bY[Dah%=sv^#ӸpszDKŽ}84_ WOZr窛i-4%]ʇlx^ hg'sE/eOYId< y0r7g5SsLw Z14P* i?U,@z*Xj%s7]+yyҼ)8tБp/n%-DHfжE~ ]vD P(ٴF=\DI&-dUWVшPנpt|0Jl{h1oo Fy+ |@QZ ^7 dk&mDΌS9czbdA=B1zW%jDԠ4>11៱Znt/'8٨1'<Gg ' 3𕄨~Y/Ꮴis30ܪW|>aX)hsq1+[;]DDk|#w % sO,@v D2$m.Y~,7uكA ki׹1Nm}Pᄏlux5Z:LuY&nw˿ tte;D~^_Y ~9p&}[_F;%dPS?ܸ2$P[4L[u'yŕYP㲦v*I9"3^! ') waSQq܍鄄E*GUk'Evnc+Vxumw{ߜBQFzJ]H4 fUo=,"7,g)<3d3 IDGfj]: )4>R{FG xWwdN iɫ翱e4SrQE=L)p1|i"ldX@ D/% ~`b_=Ztt>:3sTa@l?IIzN aG\8;&Alm%_V|vn2"!W;S4.Ʈzo9}߷E {0xKlΕy~#ýs3$(&D BTN,80-!D`PZVWz' TR) "@JzZ m5iX} P\'zjKYRCrj\#SA+*ÞR]?1*FO]v1lj-TsSŜ3Pg2:j1ZEqHY/:lG mCzɲ߱9|8c.̸|OGHr"o'pp Ua(",N8 IAVWC,@OcTEkNgcj =L9qfxl ]l#Tq4@!-4˙}Pyw;a]~UdJjMG>8FX| 'G㿇 .)2NL[2{?Tc:K)'UpۜR̈́͟b~pO>eMNs?#-`&"^]ds$hTJX(%BmdE!VEuπCSONqj(m̽JLl$(%&ɟ'c6(˴{$#H^韶^(`"N툠6_RWG~E"hNMH ֺx-k㵠T I&%Vhkdg".}iNUt}{ `Wۭpoݗ jθ/LC$t_@\nԔ•/+=ltȠʏ8l?GF Sj\g.mM5+[`AjɝxI7X gF?x1[O C%K<[]K>xuG#$sr (5WC\Y4 W|kvj;%TķPdS_v|vg=)7YV {ON7 G~}0Z,X6./" "fNA |?`'-xs:aZΚJ2\m K F h u s;Ztb4RٲyM x0ᴾў{bL󨓪ZeA))ĽfT0D^ 5,RUGP$y5Y·֚!7%211^tɹx&Y0ڱ%?QS&ؗ =ؾ*@w8Ai$`jUOX|qi&\Ew4en:B DibaO:ކn~`ϥxC#Hs OC,.luT# ta€}i#٢ bG^ y3C:vi ޱ`Md,;0N'w|({6JE#1%Ѧ,xCՔ&1r0r*ËׁF)rP4MK`kNi d:: &OټT\tb[JHIxLC$T 4-EiPtziӶq>I b ̹"lnS_j?wr׎?!`]p ޵ qm .)7 Uۿc ׉4É$;lXg!gnzHj[i|/ZJJk jo5uFϊ,y,6_Y9vnuSwF9fٚssr-`g]BH%|hyc)ᆭ#X' 3RC|"e諲׸ \O]i@yH͓'O)ϊGl[~y7WK|UdS4b(ȹ=ǥ‘xJ=׳wuO눛bp7#2^`4Kȟj;uJ m_## @fyQĻ ܎AŹe7 7̒[r8 o4o2Oaq̸hh Z]+hw. xR1hH6.F#7807",9!dUPa0ěΌ{,]8T?N{̎Vr ޼0}tomUĊx,s|0B$^^LDs). bſediyOy2~v' .i|RY7~}bE;*xll=Ix߬/"&BS+NuULɵЗX?S S nr8A/^Bx,R&2w(, kY­G*AdGCRqfWu8z<1JS)]3lGS$;Y2ܶ{;4=FƙE R_i ͈8mS Vlz/|hzmzj+~?*jKwOT ðːطT|Ɩ0Xo>R`QW޻HROV叿X?2Y oF¡ߍ_ {(ã%DBZTWӦ문McFr[^I/%m/Uf4j%G0D˂!d{SP \FKY^ڲbel !C]wR3;P E,xߧ `n1 0֬2))!eUϿJ{jhrd؆:8"Lli^9TMx@k X$lH~MFH482(INrU[BAT`O#k Nh>@4艨؋ 3GR!&K%:sMK䠰{+%ˤ@m/GmPrX^}ޯu r_2ƌ}7Gi݁G+y$C\цZ2uQ(| km}a!d*꟝M <bsr^_TcLE?-zO7XD4ԡj!cjd~+Z`soX>d_e b@U?B*ϗ7D|cx4E/;xݛf:zɛ4ʠ8yhآIk4[]:mS90==1NZe̫|x?[x̠!v2o:i0ڱNHd ǹdp-3}|^c^rW=ۚ47PM @d\C: ЦSqO *ec|d=|ҋgOog'Im`A %m]C3aMl߼3L^>xuIMhKmɹq}xfZP&b^xuk"5(3T`96Z.(FYZI[-`aqZ U-%`>F)t@hPD7,_½%lVڙ;RYV/}ˏ "p$ZЫ| jO>Fos_ c^(N, ^yK +̀A5:°j~H̓3@n0&UVM%3)fVSL6~bκ1!cCa|4KIY|r6O2i3G\ܟ8YuSM4O`{k NE#GxSO+4>g0 94m\M P =Lg{"t` #Yskw)8tf"۳۱L*'Hg/36CM&L E3M^ /`2dEh!@G16 :t2\qA~F(d%vW,`O.nXr,+: g(YVFsVޝe!k.ѶM~$ U,G.YJԕC''kDY䳫[xZxj%*N )wpaH嘝#0Po@Swbnpu!ۑ_nw[5يἌyo Um ~+RA "!<]:=L$+Oi9Du[&`Of,PH>V|Arus2Nv{(ͪGؔЦob;ps{ [)jDzzH8R~˝p<Gl0ʹV89{OV<пƤ#;VG$:|EGbJ!!^`>c͆t}?0jpW-u$cvtͲ:3햞=8 <)}nELf=)j겫K7%`m a2i]lH4y'aH1hdI>OD2;PcKcciˠ ^ab*!h'<j!k t^/:Oktm?HJ6S@f3 * xpra9?l ux?d|4CB.x=YL3 \v)T}i~TI]~=r ?dec۶jZF1NDs86fL4rmB/ᦈmN< =g!Z.S߰Y, fg,ZN|z^{0 98D$֗y*b|=jMWpbv$\Om'X7DLv-qW!%"p)M}.7 "mAg57j-[^*t󰣍mvqW>BPO O3/pR oyiCC0<Uh|T5YUP '}#'N\gܜed QG{ >rv owMPIGS)6.j]DM2Mr( ImI]'mG0굼n).̭(>JT%W~% QifRCBwoN:Z^ N*gj@*- 0;ؘsj: ǩIi~_~H1ajd)ڍVat'v@"M̱xL^y Y?josuj@F- rlNL^+Pߒ)E싆~=MlkVGDw!YI+4yz0LyF{p[qJ:w̳C`Ik`]-tu@L|Y]PiV݀ElpA|g@J" ;J˒;\IG9^ꩲ/-[ `X6Y$!%Ͷ-tI`wsϹ"loC3R.D+Cil<:1JN Fq-5MrWLIqhQn3|F۪B@ s\]wGim/-LGAc{(~&9ߕe-Di:@`z;nIF+$x#0 !T4uUU;!=;7z6/Xht&,ؗU(4)-!zn1ӌh,(ػџlG@{VjǟXsIK1HЮCB0 f&lӪ:K2ft (ɞ2{#}I*Hx:YzrSWS'Rmxvٿ-y/4`kL+?֮Op_ *+:GqХ/K%\e߇g<οjs '߁{Mx$W?ȥTP(BA[I `]s-D32 u:gDgR9t7sψݺ~) __#,?fblb.ƛ)0,&@9@0FTB%o!+ơ^с=VMg<5QC-l$Pݭz:yu9 w/L!;Fɗq? )]lsßsX~,}yH mrRǪT}ob||kD;RM p)LMQEquV5^f:']""M;#n0V:Yyռv5HjWJ0mS  'EuLA$:2l<}ke=69*zJ p~-6lŴ,фf2r`!)| T( aR[|o@K\jCqHFËh*8|p@46u9ɯmA&C̡ U̿6۫NI0):3B­U+8+-Oj ԌB >ahlq.vC/UlBdw\پcj I`:;Jߥ~tis'+gm^tf rIk5)V*e9G`N{8$A$_ŝ#%}93rcUz*u!3l^nm1)WhB=o=nIzL5U,< .Kc7 LPIz:;cv}JkIJH)32S¶-s%6f_'v`Mϖ_ģSWQEN`b4\,I xKYnS.jWACG Wq~c>'{IîV J~$Ԍ.VX{ۖ/^SZy@te.m[4 !&,)o0q]SZRfI:)̟MeIXtDzAX)`BDf`쏀AmvF>=2͖o4\o-X E6(sbS- *Viw/|Ef-uxVDZfiK?rvnP!7(D|̊)23!P)y[cq˩Ld+nR#Ve!I]e%w"Qj0A#j-Z`;H8(yѺR3YLvuȚ'auffvt#.sX ,c3+xZ\o&wwIv{׀4.N)^\˳5R gp@C2Wn}r[-=.< + lBh3n<.S؆vC *I& Nz~FpF߈ްt_MúBL´ͬNZJmꠘnu3[[muM?ݜE3Q7Veer=hSAZFS0](@[Op ~2>q GEA)VnD^4̶)#Z Z=_>^YN*‘j9.kEjS cr|p$زwwV*v dx&#b۩*fٶ/qg&@ti}081.Q 4N}<0z"ޥ=Wfʰ{SF8 bFRϗ5T֨B'3-‘?|-;2oc\1O#R_>%* x`Up)nKaSA}"MrچBM}:̽BZR%c W^R:Q%:h=MH'9rFGBk[~ njԈ RnKW,Bw9!*4weKEJ=ĽxWr4/?X vhtuJ6 9o)!ŝx#|'Eults8V x=%cFNPi-򳚖C)_ܬNQƑ~7$#$"$k8{61v ӫT_۴Pm6 |N91ֆT0:0& @ZKIWˮU#}p6S@Kxl1Y4lo)VaAaH')]"NF 0`yk849ZEwlSO.QoTħNW4N1儲'|<-g8%r+VO']i仐9 <-MX@xG oEj4A cKu6=5v>hgW?4dk6_NK_ٗ^$"pe A YL3a]@0A3?bˠ2qk`6, m|o7'ՊP׾xqӑw ?r a5%7'O! !buhOu'Kؖv?WX/h雖 )ZQ/I45ozqdO/I9\Ҵ33//(e4ؑCzIʉ,6x-%_;#HWUJ@maKhS7O|gM?h{-<"~Vm-O5}[]Dz`'hVȲ韦MQ%xdMFb\]b:ًrZ q ~R 䟎 O$orb1aT_u \)םCƸ| nl%`-q:yޫzx&6CL0>,V?49l ;-&_y @t_A?sb0<Sjѡu&MEU2&9AltvݗoBᙚ3Eu?.k~*):}\^5H}4\QfDE*C}vU3d\Tx{Ir)xnw}^1LT3/ǏG~vY[cT6HBQ}UfPA\)C=\Cc >"2͔  r.GuՄ/b c]rFkCQHi_Z1|%"X8#z.Ueb "Ov䁡^l&q H)E{ *;ϿHD7/oSkm[f 2OMM8!We#|KÜѓ3(59q2LK Wi\&Iɥu*;=gLޥsYd!LV{I5Tv&'Q!7-`jejrK1rPW1Em>>Yu2Q CM,T Z yϕ/6Ck#@7_689^r} 4]4,*Ns_L|;l.݃V6+"fZ#Տ4 ! Xr9 &!4z`fU)=:ʣ 1kDhG!9:c47WvH8#Y #j #m饞êٿf&Zvb*:X})2A ~kKK((O~2E9{Rt>ó $ld'k .ڀaKKxnC vtMzS\6 5?ErG&.B> 4Sx3_HCc!(#<6FW.#|@A6pYS&p}1 #qa_e G'V|h&<& BoQOtaO1 Dt?o7f#_mXXxv<$<찤jFĔ'?Iv'oY"L]$qw WI~/ᇪˀva%kQv3QW̄ix?{;u2m6201 2`x pOY|!uyM6d\~¿ |e V9wěziJ =(e\q4=7^v4OY*R,lDžFAa>zC[1$oM.Yu!~CP sx6-{?h4[J)wxN&;^R⨡^jݗFѴ- %KKw)1*L] E[7FXYo2͘%;c ˰6L: Ѳ~d4 Ln\I e*gχ|͵ u eB^WuAXϒc՘GX){NkV=>⌓?CrTX5 U_I>v \®RD\eRRH" ];AeBH2ɺ%m.ϾH?қ^:Öy%ƙCC"2T.rQD}`H~yWyE덭h jnM^}LPdTe {`+; M#Rz0-{ƈ1gXGW{&6UyYئSٶzB{,t=?$֣[[dr HӉ , jl&hQ#2v46Ri"VZ&^AV]6DecΩ,sl}d [|Rwҏcv˦>Otfa6,h{JTUov,Wׯz jY!(>'a'zN4{@gu:N`buN9gMH 鍷bK¼eݱ}x;etwqLvM2]{4ӝѵ[b\^қ(Kifg+%\eԇSiXa}"%$`.%?:RrF!M krj(r!/MLI |Q1Zw=3P9 3dVE|8U۵YyЅm?o^l^c@UdG"l0MhGzW૩RxMRWTcevB@ɹ (QԈ,\m SicP1!: ;i ܊F]=puv=r]I`_z8 [XhC`gI% ((&wq"=;XYyP*7wXUt!L%$hh|\un { X+쭷3_,XǮ#&e =QEBv@m${8pTH<=)v4ΑK<PDhFXVv&3꾘D O$q\%O0EzM nˆٵӮD xFkq+(%$ML_<&;yF&AͬTCbXs?%&tbt"$!Y~veϫ88o-sdt4Xlp8A԰#^2{Qrҕ*CF+\x9]%=A vS"[{&O^*W=ߖFi.Ε0%,2k:&Z@"J 6`w- VX:uk}ԑ;3&XAQ(vȴ&QHc\pT/,r1Ip9rbLy}?  Dg{?,t?Ձuac0 o[Zy8DU$l9 ``Oiw_OnWtQoe)Q]zו6Q))#<Ŋm YT2EASr u):Gq xzP!D%mfͤQ،DkLȍU⽂L2mrȽQq&Lb  7U3;{ 58~La pB\n7č_hAM`cgl05(7*(o@[#o+qM<:Phezp xM=U%8xZgFNTY8F@A '^ݬw=RR[Ycmu^\Z r^NNU>[$_<~24+wN+W nS @λmWa}NW$(9c;#(Q}{^}( ޓyD;3-YF6K`Խn9%)۝H3%µwr8MEk\5l|.8Jsg,)6>\衞eF>JʉdyxO~y@z2Nd\Rk~<cjcZJvR!޵ LJ*$87!è X"j֪YӢMT$?1&j;0_If$ 0<|qxbR'v-u>@ÂN`nV'}RB;աѾdqv>J f !Ԧ,[ —ZT#^V}g#Jq\ͯm^j&_=^ioU bΑL;i'0OBݪzJWRCq2S8WPnҸH_Hь+ڋN(pm!gw$li'fCD0٠pBo6IKRDbᤁ1&H)({ۛqi] _ሮ(! !ü+Tf7$\ +R&:Za5c,̡җDf[:Ǧ,>6159Ekz& nz I0ךT1[,|Y vj6vк-":YjHZ/rjiOR"@hj%VkiETZ\ni&*xzϚ5'nI5X4bz Pef/bXnc‹ sjHYlT+O^G+P뱊d|zbj%G,SuW꾌DG L!<%vԹk(JxTcĊ#A"xE, -X-D\Q* 8p|S 4{JR\wL}f2 3Yg TB%N4@̗ (eIPotq#)vo%-,d /  ´i%R{}JsM)#i8>v /77 {' Zh &2*4wwA^ !5$*3\_F>L&y&g gf䕩0-Z<i|vcjG&AݞҴ v^F~2S!sjD9L8BIʏf_@.k.z k/$C4tԕ>,Mf6&{Fp4+ (vG N[i՚$/ktDgֽCQ#kuUo <`2MU"*e3LV1wC={GoQ>ǔ<$qO_k'Q#\EqɂSl'!ϋM4 59H%۸Pac&>.\(OL]TZY4#n_S*Wp:W*skLH 7PS6jgh4j) _ 06 L ȔrBa#Ǔ.1isWb~қ.sk-ۻp6$Rp綵uZx^sdf"C=VI&v0FF$ C@G̴Sɠj_qɱ H=? #m3XC#H|^V7bQN^&=1i8v^iz* i]DK37jwZxN(oNW_FKۉ#Ļ Uqr1Ns(1:~ H|_kO3w,Mhw n= iFVOaWa:4wʼmc pmPJvjWcG]'ћ"@Y+XTBS1 ɉ B<`1߫mIU>A")p)%#8 .hnTwsЉN<F,P#C$ !̜-Lkc@&!i@i0|=`\a6 ;1X]*{7aRӼݍ\GzM\[usŨOGM=Mh6; ʷ8lypn91'?H;GRfֹ+W!>DgZuBɦ>3rrƧ߮5 UƮݘU"hj .X/o(\8q3!j"G J$jRvgb^K;geᐔ"|Ħ b~ ]i묗Ff# <1 ;-{}qOH+9w=Dž>o#egrMnN9_=n":mfs;S4@Y3ny~XYxv,6"XW|Kf&\!.?E1wYwn qc0?]Fg!.~d// B-02F,suWfOe&!R~ac.aXj3Y1K3B`0iIjv*W֔:))4!KVb-#;Cgs`r.y;| AgΛ*m(~G> bb 8eLT87/Lw[<k,-'snql?VH?zn1:PAo8O388"י_}sV1я\vnVn tqΨSn41ڔC"4˘Ֆ4?$0ԥ~+0. .M^ 3+pVhrm(k-4ŇW0faoW{c +` 'pL.E[L4 IcԆ-OX?l)OaXlh z1(|:e%eӉD^8q%1tJSxP!!oƹ Lvk ^ÍA}4H1m >j3E VU{(cQzh.(|}!;>v(jm1?æ3\r:}+^.?ֻGiFh""r\.\Ä2A^I3̱RϟEu\I0] ن7m]i Iz%`|6䏫J;PX"!ҳPyQ[.u{O͒=O*Jp-Q댾ܔ6{ P3gI&6E+%;QpxM`@Wq]zWc")ҍ0f3hUEN# 5]> v>=qjIkp0;p_.(:y *Lj,]i5禲[a. G6u@ʡtwfJ0 &X־n&z΍'H$?1`eIR!Ŝyyw#Hr GǞk&ÅA)+RɯJ,Xzozni íCmOFM@.X : H-=ֵ8.T7"%jyweX)QD]3jmh\ury+P(!5L.%?AÍu2}P贔!Z;W؄{&y (~Y97`*Ž𨓯l]C U/e(##Kx9PpPE2) ]y.(uAcntj;zTn`^wmtKg24x\/oJPWY *JA9턼m:궖=fCH3' 2x+6Uf"N$fNk-ɒaejHN,4nt8} 0MvUGM2Mkڇq,[^R| xnZp UIՏM1 }{YM+EThL] 5j ] xXdoǎFqQSBR) 'm1WOjC!}+ώD3tM \:_ 6NJZWnuꌲq})eXj_e\e'i8ݴC$*k3w,e" oxdʀܤPdˀ}AC_zɰ3D˯c1eo4K+xTMǝ*i`U%_?**4;>U W f8+ %r1w2ITwTLk\81ij=QwIOh_ {)l{bѝ v)7ba5]{܇y_BxO ;%ͬ#΍7ѿcl:>zCk r"n~/2+/ʺ=k`BQq9;T28A?^TO;#pm>&87 mOn MSvd?bySVIB0(0gU&H?> JBR[E7K2X^+۫d6g2ȍ%Ixݘ" Vͅ X3_̡˂wkޟ[C.cQC;\Rܵfud~qNP@d*D#*:!dwN GL7HRB EpchI@bj,@>>J-- FB:Y.?y%,P\;h&F>KGL|ȆFBv@%<07e;kzK\waKl-ds֤Li;XIРH4;i&b7wR<ƓM5׏K ǤhWZ"`T3ѕQ0 Yӎ0n$aSH{0XmqkKk6AFvH|#$D[wY%bzwlxtn}WN!ۍ̓yYN/~h%Jk䟿_TFlQTJvg ›6G3$G(y2t iV4q:ft{2嘺6dK_Oس"Ap)Ʊ1+9& K˳:ıStX4d߮$e9hLw?oOts )6 s#G?RKB~S2`fB"2Odl2g+ߣrx֏pڈј Bo Z!.4EjyABz3%I'Lvp{p4)䠽?W6 sb^r|DD!;VfX+'R}+> Ǝ, N8cg\yguI[IӥqyI6ϳb6QJDft41*'3f+nC-V5Nn%fbi7`p١^Å_EdJZdLpZx?#3`M] 9d r+=f7:>)G lt[蔏kmpgՃ|&|cqq/[5؋?%~_/nXwIۖEowv@M) f9Юn12@(ntC8m!vEG:s`]:;?;;/L{{}*@%_#wV铪KԒ2AÎ}z\->oÒ(Oc_5=[AD+ {oqٍ6fHլRSH#Q 2 iQ琒@PZq%M-sQԏDA5*϶"hrXЖ;={`Q=^cDoVjɎNY*AZPyjZrOPge*px3laN_y n,+S!nJ[@"O`Pڮ PcOa2G%wf/S+L\Blїခ9f>ԨЭ޸y٪#Lӗ^F[F'w902IYK-8 C#N6 x6"'5#?i; ?VN !D$F04H5eeʫTeA4< 6>г@􀶂TY }s>o߫W &6:6F2-e(&2'T)=HwBL!'|(vגK2z5י@tw1X'n[`*p)>a!oz)eÈRL᭞ETrre4كw*bRq[Vso$H;/ *JE=d8^T@|Ș FO4{-F>FZpu*Sp<#CE UB/ Q#}Yvq=MS#TԎ<k^ڿfݐPȁ9yZ8Bc@YdoʦD:K?z9> kτP ([X])8Y#6v7kt?dlp<ȝzɈ6EH*|YŴHrd[e'T&=ZPXX\P%5<ex%*-Qy6hF3@1`8?T*1_a'#LcSRm~0+kIU#Q%yަ,b¤E]w ErÃ'dȜFSMTL3ᥠ#@XMAtD UO`z[3A 5K΃EӇ4+>ɱݍ0$XU -qѕ- zq%-3 %T _}HgLgCKFp{ MϬf=PدoC%T lӖ쟇s%b]( 9:UG1.]E+Y=*נyEW2kLbJɯ捸zCb@gWMzm",.I*l7ڀݘjVֿ #3DňP`;Śexci*藤&J,~[UrPa+Tp߆tnq`B2u$v:8çUEd]f+ (oޯ|<ws3d[gq; /~Yw*ٚVfB"БSK wR5i b"8o[Þy>P:м3Q=jpC 6*^ Zbwm;9CX(1Ì_+@q##et"Ȅ˲Wȉv];V "/X,NE?3Iv;GmE*ԯmŧ5An+µnĊd%].gTXZ>EWĚcGw)UmxqH:aAbPf)Y7U (^c`9mLPjpsY!aO"+kbH"tN sIǡq6xoYZU0Q*#+?8ok{9!HAjd~l jrtGI;MuxJW8gW&4Key1F"U%Lw|(JB:WMUn8;slM8pcbuzՍ-b>+v穴tMnS!vmܕa.ǁef_f@-mTR'| [RuՄ5~X0C،4o%z?/}RPQZir&aHX(W8i +pը&Ҫ0XkMJM֗oCm]fh۹ʏH%xɐmZ6@6D-*޾xjmX0߈f2Vj#VlV.T* ~Ȳ̒u[*,d<8=0=.TKl եQkNؘ7;/[4'5&?6E !a g{ C%Ś+N>mQW;f ).rܱT2L|9 ~ f`Vw;lS^Id WeA<-aF -GnAb>DyJo>FfѠj'zKꚽ0$>LI@hx+ajݖo::Qԫ _΄JB6Ofz f%ԆO`wT)E|ԏ7UjP}3+t#Ô cwj1d"9cCz?z 1'tپWQcWOHlRv сa_q3#\H}lE }Pܳ״YzRƫɋn6A&;~XUqr]u"MěT'{Kـ$']T.!Dx0H=K?{K{1 QkyUb6>?MBz.}Okhȳh(L&SQd̋I0pYD_c2oՠi`O tB}@x-2rÑ8Ƙ[ 츺 7FڦXh)¿@O0b)b5XopLA)$&`b=EuhB<,rD31q`2<#E6ٴ9Cz Ԛ᧕ϑkS=^MŭW"*'AeԞ)C-ƅBR JaᑟM?&}?CA/a_m""As!"ܓ!zp]R%!b.4ᙅF#"heb?diŁj=^[D(>h%qV1FGֽ0.Cތy?.R5õ@6E% P$ANYB$97_| 8dm{duZaS/U-QƭEmװI2%&O2Wq RF;r:=m8Rc窚9b 폚tiw\|/&Wp~m9-fNdyqX u.}m04& \TcL+rUI2!6i:ZEVi?hbolrH~q]U}XIwZ,FD^WA`e[aNWC༈u=F4E:FoyY$TPbs|PD{7RW<{W5~c>p,|Eo*~. 7gtԦ㰥晭?Ju&VYoҤisIN X$@ޚUv906 ?bǦdoWI.EW|Vƈ2bx|ZQ׏HHTrR 6q7b[?N,? ;+F8dMp`=]młE1ߣ֍kxE YM v\gh-jI= Kylע.79eyrTDs?8<9u[ W{4좊Ef3zU"ZVdfs"xDA06colĩ3idl _TYJ'_lv|˝p6.! 9A"5˜W۬hL.lπ56?/662%/5r$8d_o_ "Df>m?/fqa1*QV(V[$zBIEQn4kȿ PexK[GE~BbLOeiKlph-W~M=D$TłR^ ܜI+a[0a7(E5J퍎O~m?SDa6{mguם%S쩯$Zj/d9r8uI"X0nbGizI\=fs*g +^h\{&ǽa;;4!9Zpq0!Ӓenz*e\0$]Яu,`<xf&e.62Ww[hQ5KitQ $T ,v7{jQ.\֎evj$) J`fn%ܯK@9 7M$AE;H?~0@!b9$5Eqf0 lsGq}9ƀtl= kSA'0#c Ljށ@s`;sq>+H}8()p !, e;;윦 ATq/?zs:ʶ/迣B$"1R ]pH-8 A G 8zV[-!s_[9G[m b޺t0wι,U/Cvo)!-ulyUE~e{ {Wsh$zO;VGLY^ȶ32`)\$Df]zw_괵p zD-_>}]_w oZ!W$@!_м{½QՏ0X0/:Ž#e#)'c%ʎh)§m)Xy:6|27nW3&=9P|ɟ'X६pj.J_j,B]OJQyoKUEѬ|Kͺ!6r `{=8RrcRJl;Tw(W+ C#zy-!o&=-h . ׿~+ۑ05f(hbDI os^jF~(㶡4}th2s@1 \ k;ʚ'fٶF0U+U`׼~]aFJkƌ5CGUP^evё5E* # R])5bY\s04``t~S_žoó<^eN"2}G ,N޺>baQ\xFc^R]p =ioII>jֹP]snh!3>I eL[)c2NDjb|՝ka?`HڄS1y@J[}Ш^Zi!z^eQgh|LX2T j:ߗeW%ÑnJz0ZpϘIvÈvN2 1 q1pӭ$M7uLZK MNqv~ l;CW,+@蛍UL5ldG#ƃ"MX؃b=ob|inAh 6f셊B>uX˗:l>* 0OoZs5> sT_4iꊑm¹s3Z-U>i ŧVH<K0}_dnG \1햝_U4{>9 Or26]'ܹ#!kœsxu;\ҤE2mkWzۃo *V9[a}RA&4ó(}U 0n ᇖE.rSªAn`(Y+ {ϻr=<B-d/3;2K f42-õÀWRToidC`_=ƥSζZIFߧE+dSV!&;+e9K48)xRu^nܘVC8m[1'1lS vhv[l/P1#V |V~0 EG|Uf˾j XBl-R*NA=, *·Je|mz=޽>WBl@k $bܹ\/oBBf[g1<:l76e4Bْa`boe 6 N׺g?^BճS}8Oh?:S)FBՌs#EQ$>$x2Q=I6jdB4{^b>Znq_bgHq|*U(9ң/,4$`>!Jabw^+vی=A@{7S)פN\*_ "`0W2GL,:qq'?.@T~-TWEA V$ZA4Ft/?}>dk><{[jl+l\N Qxщ -sLY}s :,_14vv7)CʥtrNK0%!~R")rx<@ $#&7lÙą]  Ƚ _@G$#"٥@0y"Ȓ 'h,Mh *mY =:5c~8AHrUyx/-TRÆ.+֖# n7fSUIP_im XHUH oZ.aj!^BA7aQoޫ, j&ZCt=K{D.#:>LDկ1pRKػ{EJDȄAZYtiH#'zw6Aw.H}( rٮ<Ipc#kٔ#]t:ebzCO bEWS@o:%M 7g8ㅐI>1fwKYuAVpZ^22]ZR/h]YjFi.ņ߬;oZ9f.bT"HeȆ@jXq& _yI,79d {r^.8<|- 2SԢU)_Hd@t4zGd=6*)2~Y?* 0dsv+ⶪfVu}1A*t{ *290bQa%6K$.L%ph}3;7{poD ϬvȠ fLpYGF0aS>E7Ds?1=Q* EKZYfk(ny7.@|Rݙ$3/PTҝP-Ia]2˾Q!&Y >-h dǠDJlr)L [ T$]~dߝV(,vE\4׹i,ncz$ٗI%<٧C[]ow߃}kflU뉸>)rFIS҆ IG>ɧ/t0x&tߜۈ29>[o_10YFob#ۣIHv?喿<#LQ"r.H"`&Wc{P {~adR^^2휙ݱ`OL(x5iߕm 㙓>'3s _Ya")pSf{ -R1aU.uÐKwS{|1OD;{ygv^3dSWIq ߒACz 7[!Nv5.%gjSԜV4OܶE-H]<'xK0c9?]ϸi͑):|tKn1l;qgsDyld`ef_]phl% QGͲ?8Tzc@+6⬵I+S=qB' s%R rKϱr:+MyVI[ 8H !B`L "F +@~/a76K:}N mfDV]q3RE}ʂ ,tG1[x"'-}iҾKl%oL MtE_$W5el6"qw;bG_+Bv'f\f4SЧ{ GA2!22!尴$R$Ѩ"Rq"͔v>_k`xMV`m˴kЯjib8Ho\bO!:l>#jhb(E `m:CǿIA[xNЮaٙObJ(v*z)~_ >V 'vYG bu QdO\nmN7:3R4- -VJD"Nk~ S*r^聮/u`pAyc;& ΝۮjxKQ ૅj{]ꩉn <_uU;]"g-by"s]br>l;XL Cnѕ(b|(W5KƏ|Bhx9Enpÿ֜XqT9Qj֝Mk Dd.9Ez-=N6Ut#ԟ\oMll[0tUP͓ Lo7b%vtXYUUqop|֙#P nX' DݩG8?FWZQ"cEaw{G-g} zT`=y4,vk8n}w5n|<yX`3|s~\fSabN]^=G0OFlbc=[ ~w2`Wf*BeEK'-J&#Ѐ#I۲MD@K`44g=%sM 6$) ckz`CaEW3ǩd7F Li`@ f׿Fɓ:a%H?xF .8E HIaq\ L`<׫̀v-oKXs{r=d /-N͜"f'Kg6)^WQEj%gcR-$M\THU& |AqLŖr{qhrY/5Tk` ;zAgYxQ%u[@aתs#ohqGL@O9t!>R>}y"[cvƨjfU;ӠDOrAm?O5]BŠ6l3_*w:*-<,xJÏҦ@@[Gf/2\:m[B\Y"QĥHi' Xİu%ovAOq3L'h爎h֌(5cE?IB -4~-eTyLzhrYCT1-J[ ic^~)I?~<<^Xʟ&"O~'u̖DyMT&ܚ+oA5[L>՘W d ּBUҀU}\'9lNaHw((7_=SaY~W9)ra wQ.&MowgÔFI7Q$u;]GJ@qp>#dEoYb {ŭӈAp.I {5x-%/6c^"kʖk}N*LvbrMJSrw58 +*)=C =Y|-!"ÛHPɭ _M;ơ@Fq)]؟mR,sת2 c,̆3|ᴲdF|'(8쪲Ll2r{Y'02K'=̥$ux9D٧ʣ%tsQN+XH n@(M&QvhLB*`̺#hl5FFjxfʠګx5 xsU}ww۞?F}o ) \>mu &I|P )pW~%& 9Zؾ"-AjblbԒ9i @lrBp_Kz'Bdi`fhS6륃` 4n2z{;)6GIhx ZAqyPz*D^ nbeiW 4,ApqnQVmyj#w:Ldnv7t-R`oWWVS%0X?t~Ǽa9Pc"kri ʜ bT|K IUPp].Hu?il8i> @6%6K&ڠpۃ3w&zĽ jm3Bp/)pV2d_5lЩ(c T y`x3:?ue@.ʦ'0, ZX@˳bXES$eSš'7OJ]OJNhFV.vS^6y\C [q#C6^\xtԙ*SƕJ#D2n {b1( )r":iV;BdĢ>R) m_E:kOˤ,6 \)cҒTz3 q S̺S&4^]Sg>'[^n|U`n\bD\SZ_8"}c-8?(Cw.-MBk "C! cw,`s@(*1R ǎ2--*i :lԉvsy`wT.9޿z\Q% l/ (ȊH9q1ާBN%Y礕@ Pyhe|nY8OyMZA:fZ$խo&RnveC֧:Ǯ_ :9|G3T]ϊC~xwn,om>Oa3e] UPcŨsT:#/vVZϗ9{eDaTLgCҷ< N@%% !ԳH(M̋`8\lb-ߣb\u 9IQOg~E#p7n 1rXy^kOJD vPdVcIM/}H3$]H?$dF(|?MNlpJ-#27\}RQg 82ju`G)bЄCP7$f>[S_c@\=3C߭FOr  F^%ϗDCT)_1Ej0/wC5k{T= >skF%>y19.,Z(wDT "jV n nfMKH s (jᰑj(m:v[JpO0CWޥG Ouv~XG=܆QI~a&m~lM"IْOAGZnc%kzA4Sr+hQkr=jNK?R[ t 5'U(t'[#hٓ|iat!zjKOp2EeenyZ` Hr0 #myf QoTAƅ4RFBP8.͠30 'v2xhIb)Ʀ%a:Yb_16xN-"b%`ZQO&ѲvB֒6!ei𺪡ZK4LsƦ qM[91][SѓM{NC#>Kz%J ɡ4 j1ޒH!~T9Ԉ$~5O5"NX3k.v M@;'R5Ph+ >,6O}zpy; ߲(Biu+ٍ[~I Hxd򺩐eNc,-=qW(I6 [c.v;-RxgBWnP]Y.ܺSfeџ7I'.~ W }0Lw]tt@2(|D6WB/Who,]w@[M!)+^idn-WgeZ@ί\:Vs͐:+ʢ@FQwG7 ^9-1pjZŁe7+sV* V\o}YuZF̬ lZgS.lJ\8& bN~>=UȄxmĭg] 7OMȄp|*ōnƙ# -t_ Hzrns67`dkcd !$fz@N6 q,-R$·%ua='3 cqzDioӋy'dvl:+bg848+εA^(JZӪl5kW+Im/bEV?G{t+V"7A $+?=OVJ`>3k/F.ԄPwIK R2nQTITnNcbMi?'Nmb9twX4{>?-ު ~ pG0 *㵩$?, <w:'k})y>4JLO3,.R6xYɀuL?`yÂzLYfj@!s )Q֌V Qpq^,VcRgkSI'-Ƌ|+oEb41V8*B^t)>T@ϳ;GJ>V] gYhohe2$5!sN[$Fi'F$*\ b_ΊtHL7>Iw첦V"-YJm d]C7eI"̝%:sp7ˌy)Fy[ԭKm^7is 4~N`bQO h*cq m%~=EJk&s^Yl!'5 1RgŸ7l2-&(Թ+,R8;ܚt7xRX/!Y8qL[Q9g>5) at]'o":F[ 28jݰYڦ&ƼP^eLoxV;GjE<~ Z ('+ȚW4fSd 8<?gXB}Q ,_e #KZ;ڥ5<Y \ _'}_Z))yڥXeQϚƋ0>G۝ Ϝ&{ۡ~Rw,9m BѲB/8 Un'ÁzhMÝEw.f\! {,7I掜p7v, ("@l]w= "\ Z:kz|a|}ae_ur+d[J;/[0^Ml?үި2!&Kd )xU+>bLT\'rE>+pK 8&Hd}Z)r?dgv9isnMDq-i}!K2hM$S酉DOײԛK594zK"˜Nq&yPL=m(>ns _L[_"5q_nT Xa0U%m/sT}=)~SPFCMcch,3 BD'> > "T<&mwJWܜUidJ, ;GQ'dU lfWmՒjh4_ [njTj*>Ai &"7g`Kl1B*e w'4cp\gLLDNwiӅ뾤 ivӨ٩jLB܍3lJ4KQ 2fo@4BioBO%*K'kp=H1}@VLTzh,Sj~I R蕹:`=huoeD /b4N"&%F5Z67 6DF }xVam)_8Bf!hqAS|T;!WvyU 1zӚEoE*& N{{'_Y-*KkbiV4E ^/ 6K{B?5BO] V5c-]cjqd~TIِ}:x…"FuNnR;yi`U(x%׫" ~Y; VTOǀrqZсD%SӐ1.UC.Qۋ4Rn9 .ҙ%9{"ir}0^s>땸SK7qPm/ ȄdF Ж %qf[7{L "+4rT*fQL>gTH&j{"]Uy{ *8ylO|~lG{Oe!S_ýpx'S5vtq6ĪID釳'Fڍ8ZnQOva { Ö=>)v]{e\Tg=B=CQM$͡4L6 sZʄGՆU&8Bp+"S.0<~}`x-gkN%lmq=Vg$*MKEK.㣐*U?2mTMY@vUxqAa'g9>]6؆ԜV./@bbS9*Ji[NLC.W\y]QUמF! &|5By\2JQ 6"L{Sn/{KWt>zeIdS 6ViX̚gWO쓟z9_c|- U+ _g3_%iG=RP|Z}.@|#uxB'H.mɎb}0M<)p룫Vi+ gu g(L#`As wX: r̩*HW>' !Ӻe6J4}k~ a>ۣ H|N,ݠX(U7݆2utNBvHp3CkEQF:]p"n/`M?sT/z~9Ŝklf&.blAp 1J,l_j{s{Imi&2`"`喇VS>lKɕC{O\֘ עzyv'@鸪9zV03AL2xY#-,We>`)BvSN$2FQh9fyI-󪳥f}xBVЛ'm<ɜ#ٮƌIi@&t,]*AH8ÄWq$ώlࠀ. E2 &r"5o]U\n]2mC 9LH=БU.axq)'G-(,"jqVRd%Ln] Df|3SuJpd54x̄U/Y)]U3 CAS#7.Sd{?)UΥQ>%( o1,@{'}";v^Grh?Bojgjb%Fqq *(aVfU䒂`!S$RD'+I: &_ikd2DK4sETmH`5 y\kղmq(שԵ݋%Ds̩yPZ7`Ea{$Gtm  V7#u EUna._YbBt ̙ÙFŷH3'naaRD@Q98:y`MAGQZt.Yؿ`(D!㤃,gOì?KR6C GxY1{cF2 6PL9c&R8rYn*Ǫq sv 6eT`|0F#{$ZD |o'r#ie+xᦇC06%N{@62)Xn)w޳ {ږMd (߈M/$f}T{'Tkz'zoSr"Y 0P\Z#?~k7uڳTPh ?DIث*ͦFT MnЅ&P|DI$|6Vƻ9 +yW%U @g%̸\:+F(~nޞ9 i% kS?c֫~UrW5']@'f%SٴxiOՠ^?[}j9ťB.Lcj籯.WE{W-+OP&e3E^,NCT76RTV|mW)a"9_*ɣ ~J]6Bg#)ITǕ2^ ~:82m1#Q;,pBl {ޢT\cPei{v=-T|ܓ1.ە%q}gx>7eJIUI9+b yLSԤڋY .:Xnu)2%D\+CpyvYAl.r \*ʛ+ $ ?CCEǍU`7I/jxyS@?f~7,z%`&Ӕ_UK2悞z{*dj&*9q aɗzf0 0A:Bwp[&Y<>*C/wI" o_X8 5,f˟G,Jfnf]sLq~q<1[Y LmF!r ܗYab_}oA}C"ȁmPc/.XYu(p5:^sx( ld{HE)@#DIXQ M/Hq@oNغ!*5[T΄?W)0ܼfd +^P{U 9tkٕ>-ynKgM\Z?ط>&5&6[D&p],)|w5;aV Cf|5O2z7d2]h䦭#/ŃP:Q,.d.Wq= +z8>_c:hŶ˺ēʲaҙ%^^'WpW"Io0pN`oȹN2 X=SMUwŐ,uQGM;شIW !L!܃xt螟6b8>}U86Tcq&#E莋 y L] EΡ`ߩ*-&n4Nraּ`n_%' TQxN<+XniAQ'T}G)* 8}nUy])$6,[ihcܛijטD_ÇJVu~~jHl!pz}̢z%:rtSo‚l1K8}: %zw J%c>ۗpP$t-r\+7YMg3 3#&o,!3:ʀ\aU nQIQ$Zo|N*D2-‘j!0YR#BB`Uj:P ^A ۑOx?2G:0Rc($)?PF.KBx 7Cq[)W*t<oG~04}L{/9 .l& ٔ4~م:jSț:߹z.oMfFQr`z.6MQ}C;ӏϊ36(N<6 +} s$9ƽz'ُvdrTJwt[7\(DukPvܶHbV:]aA,}ViS ^(k~8hH Zn@* 7,*}r_>,GVK얮RI4yOHO9]q!7Hl^Y]٧HRFQu So'c#ԴyLAr$|$'s=.ϕp݂dأ:v6=U{X~;CΩ  jR|ɊmI"M'g9FG/'{߈eAAGeSjpmqr0(3@20ܑCeϩY"ŖvWSU)81Wa?F_CIU,)"0ݚO8;!%ę+>!,s,4i]<eS5& [=CU"%_ v %#0bsONG()]EaS l̽@#ps L9M@g#ts+ٻ=9'sQmIC6#[޸JE,M0?AƲQCYqkaފb ͆4cُNSTZvr|=wߏ7G*ҶLp-[/Zl2 <IU`Jg a wWB q)@#7# O ׳:Z/uJzڌBOD^aԎQkE ӌDh ͙^n;ƦE^GcD-Jnv_IK{N&h vz;^Zݵ'HT_>%J"TӲ3nz~ |}EPt'p‰+V0mGcvi  cL\%Z/Uwwv]Y_6Qr4Y}4,h&5vފ0P^=ѡ 6J!i!9]RMSAz>oV:Wub((W0kgZ| &(q2w%΄s?MrE2Ud*#~^Ǚb[Hۚ.rwAMvT-N ]:Z [}ȬGR>u#ȱwU]%U 4`4Ă3'hlzsBcsG[hiNƆ8{чzg?:ƫ*?} 4f۬sj^ 3LZcŪ<_ǤzƽrQFhfLDp7Wuq ܿ R߳>%2.$|Eil )E{4qi4RnX,- L8oy*dpfr-SSedHC-gh:b5u@"qk*>W!0Hjοi#fV`"bcO;WZtkT 8?TK%+|S^΂G?qC(З^*UqvÝUdJ2`y8|F%xai- ~īl2(2HH^"*k=4;jI mQQ !C'=0kEyb` J]BYaU3͛L+t5fC;;#-INǤ"DAŠԳOL ]q&1jSZoCgN*G5X4G=0^Nt՛ |+|\V^i,e,Nr's=,4rFޣiN2Xh͹c_E|XcuxoõO#Ly12 N5kɔ d JNtԿk0`"sFJ%3D*گnGƴmS 2AwClQ|9/]`PUr)RA#mh*$j\kM@.*/}D &JG9ƝcLjdrq_&|j%%ك!K-;h{X7f57HI٬"? ,K7$CA ϓoj3+jcM'Dawk]Kގ 66 Z(~U4qYz!V iɮ{'b$(!O/.N׹}3kG)ƪFnJL*ȝ۔gQ%w3!%JUPI-ʑ׃ ʜ,B?^c\_i-iRZZࣈZ6`\/gq}[/F䋇ƲN AEFDC[}$O%uE=:lN2^XdnNdA/,Vz!y,o;t; @,W#MjpTۃb9BW ldnsI-$ N\D)s(v#]-rz?@Kpw%S`0z"U01 gj]f/qwڊpzCukRl TXߵ.>NHH~#pEKg|ȎxNDK&;Jy0[s0JJY*M(npҲbXfl ڥ=xl*ho@_oG2~u'$F0tq)RLnd5\N xS.1@0ܶ\jsddX1vfă=?Ю7w;H_΢K10!iYP@LF;yljޙ-_EV䙑?IIŘ"iq{.Mv2{U"'sgX}Zw OW`?dk܀JFc&Z|䥇$s?;~P;7osS;jfy428V 6vdΌ0B+oHaz.sjR!~0BiޛR"-I=@?Jp2v1W0Tq/F 3n8T yؘR Q`jc^KUA(o}&ǟwlcoW!X(Aax!(Xh,Q%7M+Wz/[W#.rsQw"n@qOc7Ja3q W貈>ϡWE zu_rE^FJWb`E @($i ۽HD;l=/ C:[οEۨSȊXecm㙃=Gq5.*@E*m1yrp<5B75#t-KVȸ@V縐PloENAE>%FEsxJ 7w}V[(H lf4Z$Qh΃꣝֐]ob*'P :<@/MlU(+Zav~Q쑶Ɩx4A~Uq !}L H2_\}cQ6j~۸%K4iq фg۫=UaXӮ_|y tP/툩N! ۷U`vc=nɭ.Y= &B8v(G,k OQeu 4Tmٝh[z,[){7N^e8D5+%,9ꔂSlSw1Bc@ܐГBM,ã&d<7cd81 89s@ >}b׺G.DOEQR$ XLCi7aef!+渨8 ƯxP%%73]WS|mdZ9h(53&LS_`#:9㧪"6ȾcbUim%, kD!3C浃ݡNѩ& 4%% L%p,#T-=KPNpyLӥNǜe7W;l^=F!`5] 9OuΐÃsU:L,|<`&E3é/ϩ@"^ $p\EA:4\79~+U H\7Ȓ4Bu¾qlSZ6=c^7cj!2[eau|Xfm1-t:Hx'c{ ͖8JҥKL\fC& ;j1eɘQR&Olt8ָEgp[`wP HȔ\kݹkὑ4;8' GsSv21bs5q_܎,6~ f,(ny8`8n!dP(Z헝2"UR6YriS?ۚzڈmK>D͇q)uf?4 3ƹk;s h5"?^xcٳt\"j>R%aT,] `ww_DTK5p ufdN xTCn !{"v$ QiVʋJXsQ2xp$]zXܨLn7MQ8l%ys0! 8#f%Y\y/o(g0%W=?>%hjl<~%i!Hׇ楳 dl kA2h5g_]^[v<|9/Q}v$ % iTxqSQT۷"9Ú[6>Ji-bQTV={}V)<OI(v, =4,Fe#i׳s7P(zE@+˿]XɉF_7.MoЮ4+W9S4D+xl(Qt4KbU%}fe"`v3oh\D?kTv_vx\Μ=z^V.Os#LM4Z1be4eG7k%T)wռpYcUtdv4QL{h>Ro!IS![~CD%~Rf Sr /bDz4֙"XFIRTSYIuf^xCZ@/si% 08! T1 ѥAFN &N[N[+.,#.f(g6ێ!! i/,g%H+AKEs" VdU>\1Vf+)ZWMW*Q]BbV[>Ѥ;F$ѲYTܥ={ ggB-5'R%zO]{5G21e~8{ [%ڤH[IGo"LX"U7M1SynsXaԌ'fmc&4R%ȝI&'!.x˼%q,-csLB7d@L@w0 # .Nk `s&͐9a}xK WTTFhKO-?7ϸ?nh`'J -1}b}Ir0>ob7D~cg H 2&zJd411O#YW+lϐ$i/78A_GFieEciZ~]vfΏ§dُ,pFYxIKMdVfDCzas&q9ǷfTqF|_ 蔤t5em*x̀ i#U+lHe#ⶍT}\O`655SR<[+ے( O)|^J|5?q(RYM80RԕX[I{[Z&`Xv›vEɠ+ JكMoq*'C[gtVm|v:!3Šh|?Q$ 4i¤^DBG]mNlߗXJWQFoBf@ Gj#k3Xzd ™ a1)vRBfo"ʳP/z JvrcQ?w 2/͜#n!F]Q7 NsJb-\n>N0|P3JvsjA ^yy{'oبR6:"hQhD}+FE8)[]!P~!?嘉=c C tz*ԉǩi]UmdʐPɡgq4 OVMYDeIy?i)n<rO/*$jRd5MV<}T7 %S} X(Ur ЙѨS4iȵ]CEÎq3ED WA ` 9@Ӻ2U+GO (/o(o*fR'\^R=G^+֎uq7{CH83WneۥG_ΒIλxNwhTX]gt m_"&}% ;{&+< Y ~rݴBC1ԤɌp>go#!+H7A@gn覒Opb5[3l~ZS|6Z9HGy~ Q0VD]y46ya:ў d3||%[4 ;OL~/qId e-zme i[ZK#G8>9*5U<{x] 1У~7]7bKWEbnaسM\ am=@8b4Q!]AgȰ|DrH5q5]30R"@`: ]ºʼn톹 YqU g٩dlG1N՜@#fpFG*S4ڮ( R,蹍A٘h'p^$-D~Riw€ Hyj?F@R*WjEq{;beە!UąN1 qPnZ@v-AZX{Zmꗪ#h(>86}^INQA=0u;ZS])51z}iX+uL/kj$SK,c?ǎKAɦ/ DNX5YҩUgBDKHQ+ݕ0Gvإ+']w_T-ǂL+ܱ0GW.nhC,r2rԘ)"AfC@na7rc@yOu\ Gnᱛl,5r#bqQ ⩺t[j(= ֋"r9T._$ )ST[T9 [6Sr4]LRxT^MVA\5^M}J' O~_>ui߱H")*"lBUƟuhwI|HҠȒ,*MǁgҨ ¨_X- 2&),RaӑlXJ0% eFQEwPgј"gaG¥nf18S;/?hVO6_ `& jBt)7~čf',Xd9q>L+x)Phu}*+dMKm̍V|0o4JNykߴ<-,-4+tEV2|iސ J yw:a.B_V<8B҃;01GfTopUԐ =)o<@ay^d4K07 r }[|ܶ&w_ m+zM()UQsMF44EtW3>eQ,69$%F[l3yz`L~{us< -xg(i.^lGZ3u0GJuvqzᑩH~4Jo9tsg*Ү.aCxyR)c$=N\V}JTfH#(ԡ"ٚ+Sl RA}yU)MSqV6ďv§(kg@v+v(!bI ېmkԮif%V%\E6u*h+jFxx ɜy:Ѡg^iA3ƜHlx)F-N,-љcQ$.CKT>鹥aco!cF$ p&t#s,sB#!`@X 1ѫ+_6HnmLw{b"ݨ:EL'kEaR.C"j=+(cQ0V| NWܽ~_>3 wl?t8*v4EQ;Hq缗{xoZ /7۲1gl#3f6{UpNߙR cWyʐ-I A2Q$ b~XzJ)Zٶr{T2c&Md |kIO*?m2WP!)3!1ldO?Nnn zM*HRRN/Q*q;]+6 ^Cl%+d):mӐ/r*ݮWw=Cj?Ց[aF˽{;dln\@pJ/14M3 ěv!I$9?8NzTh8HFW }5?EDMuUG[;zg7tWtU; ׆ Z}˨л^ږ*TT[bCj|Dr1pjm\}V4'`B;:̲kN|p_ 0xִJ5$ƳyJ.Z3`Bh]kwiv mƵ&Th%+?`R@ eD?^EZetqϊE$<ߖ"ec0ݍ?N EЊS9_m|XHEQN+YP])e4%}Ps\+nZ[_^⁠)Όں*m^HtK{{楌|.%տ b@Q9<oW#}:?~gE`!zm}HpDY2& `hyY ;%M\׷E@bp4c~ƋO3?(6{<)o~4\Kvaj b`~0~nzpOftvNFW)3]۟ӝQOw@.]A!sZe ΐr#wBd"L:yF X;Sն$bl a*%VhgO~QV7lڱJA)Lo_eH٢!iЙRQC?Y3VL~#C-1)fu< 3~^9$"?woS:b/z&&% :uua ߵ>atE6Z]}/k {l1{b婹3lI8М+'h?9!Lk~<~ {?"fL&ヒ}#0]f/q٦,5@!`r!X$!q|`xb8)b}Ul91hR+U9yN|Φ0=ﱦ rqq|]9yNs|j dKpδ (:8igaHLJ8>:hA* LDpec,ϟwL9kܔxWQ+z9a#v{HK,K e)}GR%B{ -,ッMXL2'to֦$:3&28 XW`RXIbt[ų鬂DVfz8A-^{UŽ{KL#q74g'vA:OÎyAU,^>8 aƴG?cfF\NIȚ27 vFūX9 KyͶ o^ڜ9ݰu;i`gx ]c/1'h[Y>IB)Fu+ZpLƳܶ Bb~V\0UY_srPZL  _ꛍpw+|(p@SئMAaa3˪v"i!;Rn'!K:_03?׽i۷=РrXbckݞtn.A0\N-Poʡy3Q`$L:Yt:o)$ +{MxH-a AL٘^{̄ -h)j>Ckۗ}QrFUa=M>q{iBj_aJzC+'TJ.i͐c_ڪ  .WWn-\r+-UPj'S &fp,'&Ǫ{c8j ] /grPj?<_G';> ~{A̶3.ƠXѐ13'$^a"?,V<^ͱ0٪Bq7KP@4}M -+0 bv* J.z`lYjFԱffټzWŚ vMo$PǵAވ%דCL K!tX w\(M;LGZۃ^EUһT +XVw0d3+#1)fh\Hx[hd9&3D*V'9/Rf'|cdS 7@ncNEa: #)m x߾]%espD{$QXRuFf<4^Mgniͩ0 fFCk~5Z-0YN9dtF/ 8@ioM90P'MHf3-,)D?Wv`yW$99t]Agzϡ5EA(;H v5_yQ`OVgu=ʇwDM@a be9IlZ)U+$R+jxVg2HZqK /!9[o˱7R!vƠ<?`epMg~^>vSwnA)PK=*j]֐| u|8<\ϮI5ݚl_ZJb#>!`& _O5~ꀨy6VnrXlmkIXp9^Sb@% 4<6+'8V/C4>4a\D {zvQ #4| zY؟CaGc}я Y8 U>N nu>+e#+yc|kmޔ & $YyVwT9RND6H"Ehqf,mN6aO ,D%'tn]M cZkGha3f#*"0 ^ %'w*Tcyv:QI<*p%YY<Ґ ;R%H_+-!Nۑ@Rc- Zan|O.&HaZxp}dYARTIK@,EHqv]ee UX,J'Hyxa?{C|kG@}G^h68dQ=Zl\bUivӺV(E{F+5xl4$[ҿk$\.Qk+;sإ2t6WgENU cg`h%ֺH?$8VI'ۣWy/2::tqstuZWe"ZpӘD|j]c81M,Ya%6)o[R ng[6#D~ZFi_ҹnF I>5hV'{(*0{ߢ-,vQ֪--Z-wLЄ%ymm6]wlg: o6GMWgOCڰ&ڞZ5 "žh9&!旬j$7x~=1K`s|~.wv,/^)?!=;ޥ_*?_(ӮX ԎG  O6*$oEKTAu Pç,2fWpisWɆU0C* B@uЊq~Qmð'\\L_KFx6ٵ_<<']xɬq2_򙂞d<3=GAsg? jNgo+ѽW+@ Ph: f)?PQRLw& W,;d\h۷~Ξ")B1}fSڬG΋V΋8o/~$|բv-QQvr qG)02ZBK2_ix EE;tuxEBLZRَ5Vϭ,訾'A&_7 o?EdgK*9Q9*pRp($[61& 錥bUIKt] VMeջYi α߲QR  JU!<3XOJ6Ntw(v͌(JeQv9XJ+͵uR=Cl7-?^GeJ`\NR+M+eȜ~B8}żay.pxEfMn8"<=Ϟ#F}‹VRFؾRڂ͌'\CLMN8H, 6@6;c>"a 45a@J`GtCZXUC&Hz +Q!3Z??\ %`Qt}8Q^ ;Wv+t!G3TGBQD{N%<˾s"*0'uPGHMa +B$N{_k,k1 :@-|Z9 ߟD]ȥ#cƮ3] ٿ(fY}c&?G[Z-s 'yVׅ"f`r! p_ 9w\Z1線 v=2l< cO*~Br6#r LT`8U^ vq#M\MPۊ6T!%0ZzI: QQœ.x .IfqT֝x[Px-߰A ҕ"zYozZJ?_X@*&m!=U= |I@D6XRfLB&&O`W}Nqe|㲟0j7CZZN >"hov/׆\dl=)v- &bZZ^n02 B {:?uKciS.`kn+l2/Ig%8f#QxDys2*78g&e|`gޥ]fiy'JK>\kKfn["^ 0DM}^ph۫WbsykA"l{H l;E̵Vx 4n%C>Bbjw HY'EvE;93@%0f=V[tV6|`~3 HA,pX;n~i: Rvܧz=XPͶ>Ȁ~܃b:u9<gl,q71Qhƭ{&_6 7q|̎Ա821?m^gpdۈ៶[Ysr/H66dxfF~W2ؔZ\ |/^/]D}NO5oJo^?IZ6aCv0j{5ƪJ02CozW:l;KEPj 'SH,XB_eClEm0<+ jWdkx x88 UfXc)q _A6S׋;!g<)Ϫ)o(Kz{]f9<)OQ?azsG=#Ǐ趭x egZNfᑩփ*hnX9d ƈ2. n v K͓i m /LW@dYXDṟVbp y4cBdAMGDG®B)O>[¤AVs^f~qv64xʙ،h_@ l=}3ֹ9X~Ą-4[;'k 9,-2 PhÃ[ƽx5|8b.\08N'Os`ԉ@FR~Vk#A#R D8OܢNT2+fR+d Qdl>~*JS7 >b%/%Mtq*yejh21 $ Wo*0!..qIGHD ;oV=֒6/)C7y 14f aBMZO&~Gt^Bڃj(JqXhp=$AH{(~jY˝hRRtN^Xz=泧Zj!IF =i HVy!}ZR~|4Gddj$95XTwu$,?b(t?T@CO[qlGf:tio.|Ri^$ǔ }4)2`i>GwY{;;$b+OW,WӺkC IW:W>@棙W߼iLL t!XdڮnmWWѦ.yX<@*T(z!u:JgȚfB`^Pjo ! OaRtL8xrqP\YDxz6K*)o9wƧ5_w'q*yYzL"˱@vO\ge?4S$ th i-S'_/yƺ-9 j/BĨ2 窇~Mxq 24 LDld _IADYNdlĥ5隕HкOZT.s5}(!RDR9@f䋙ڰI9V.TN3&?m7qp:)xʛumXFhN>cxJ͉suȤ5SC]zL92ǥnb?xFcbH&^|塢UL~w,f9|#LΖ){?f1vƞay}lEz^VɌbJ #@N[̭__dWAO$Dab.9Yl7uNgG.if]IU7v=V6#\IG=<b9a@+ \ O2B8s&\ʕ|mIh#Hv aJ]FD3\~zѝ/wS"` KtO,<4AѷVy_BOX*R o|H   %, }dq/ʞH!iQ%Ùm;H:[:^TѦ"gάfWt[ݫǟ/$,`N }Cl*5yeS( z[ߌ)Oǣ%5 dw$zZ?A'E6k.y^4QdWlwmX(dn[ނç- G,01Zv)ZX9p[q!V>(%LkB,M}/<1Y#*SPG[M/$Q24 l TA<4'~"- _N 6! SD2VީbwĻP)J`܃ZFGz+6iZjffn ̕a06--@_$= mt)pBI4WoD,:nQwWh`Zi#mJ4ag&4?M:#oCH)B,hGt7^kR^#K,Xg1F\;NVm{g@[qn0 [9մ%@=i[ѿ.n$89cu{+ 4×U #1z,E9 @`яkWivSó^}7(rBwUGpG4cQ#(>}KrylYn@G'`1- 2NA8}XCm<0WJW+ EcK=q](LUmz'k!yoO@{}sB**YF`? #&QOwIc$~&WD ValS,#Nx*waO! l0C|,D}q.K` 5 MF<89<u&I3]*[*MbV&Q3²Ȓ]2[ hF8 [޷)na:wQvFe#w;aPj}v05 zYّY6:6UQObWh ;PЉ(N԰A_ MO@y+#^A(|,뽗NU[<ڞ,n12<σ` ~~ٞAE>.2 ^moFB{Oƃ"Oj߿|˖GdQ6~]W||m$eE K(Q|p| -|bk j4 $dׂ,&^.ܓ%K"z2c]+mJ:3~[tL+5\ t M̮p bƂZ`:'ouhTM[ǡ?sCeYpzq`QxC @ʮQjv:xBWTK6]}![ڦW6 u߆vE+@qeJd1+3&a=] PJ61 o|ٮ?BSS/#Yl1=Y nh7>B[lZ;jhe61Y*+?ߺc(@LdO] td7Oxk#6SI+Ⱥ,\Jѯ^nbz;+"CT~rmš,|#p:E:`;2O"Ո3 ]1 e3Y;9/sm. *LG2J>J(U[k_N e-,1CZR*s~ȭ\qN=m{E8 a&˄pPUH^=UvT߃-W+:FGOG`~KjNu65c0US,e}rl((ud{*Y5Svj:0RV@1`TPe0MP&Z $~e{kGm@(:tڕtX%7(D.a_!fkDxиb,3Y$k46ҪF hcΓD8<ơ$8P6ߋ-?9vo#M< BI..r%L{b52!*ڛŃy:n܈8O1/`y&_Dg{ KE[=|yzn<65|<˔$wj YHNFI#_ըf[gynX г5I$DY(i7"aMߘ *f2pGi|XU鬱R:`1#dEX.-*,Fե?ti'^ۭw=^T_rиY!8bI$M{i\(Qd8NQ%h WD8;2aF䲲sWQK{4˃j7|mbiΗl3پE0 [4`poܖeuEyrZ|y{6θ%%j„,<ƛ:K\7Q4;NOL\i'diDeg_$5Mʳ h k8Q=O٬}Ȧr? O<8q,yDƵ4>zQ5XUJ_v`sopN[iBs$.fs3r!#1TĸQ,v^Ӑ.n**FR| ʛ<<5n0žF߬n1Z[o<-/:0ȆQFK~~-3 FpkdiGΨo5dGIHg;l|n C0 CGF܅YZuIjBlFC7y^A-xۏFqw0t4>Y_!F}Bz`D"e=Gf"]ltW0W<{JU) -奈^ڊ]hR75BgXP[2rk¼Զ*B8~"|0},CKY˵?žhQ& t {oyp򟸜8R-+|T'הy&a1V>FZؑ˪%m|oѕ ^Sjǣ:rNu"t pn1uXsCHdBE{ۀnJ`ғuKYNَ![k?~"T'm)/՘Z,Uΰc~!7"$/΅Y0t|2${dMz6w`Nki0&kr)p&o0i@T+-fvw.Pڟk#VQ5RѰȿ~ $,тW!0ݽ*uQHv+@d8 7=зܟ U zxh0a(/ܡvȸٓMTw[̫tV[3w꧟çXTWx;i_8c r<J шպgkSn+ZRjz}[arQ%@v5Qw7>ѧc%-)8ڌQ6!Y̠noK^2AKmv~/4}yJE:L%p$]/95EBEMFSY,C0UoŧzQ2GvBd@5h7:T>QT&pi1݊.-5QLRZ 4D޸i{W/n]<_hղ\ǶyF2kQ~Up Hyd8>ylHbXD cb 2DoNE/؎{x2S (ghkO!dVqpQ2]Uqbwne:\2O!l]ȢH! +:W\Uz]]T)ίz8YTO/~5yMcS`?XSdf T@LYa\)ǂNL2{${­5)}Lv~ab(uBpGpd66Yrp 1^t)߷g!QPKnP\\HCfw1}`Yco^ P +M!g$*%ޒl6OaCϮ,DKr:Deee%.xfUGqWl0/h:$3^Fns?ԍ*p%Y9z|mҌ> ɋL>f^4E$$9.i~ާ@Gԩ!!lfs*Toi NXr痗~4l"ePzղrD EYwI,OqAu_lX5dl"osOTb8]uFjj87fg 5  MK|PḐWpЅdV)W60*nFi(׀gk-fĹÔa BR S$"A1MqvQpU Sm;$G8b%4v꿠$v!գzy7 N&~fe\}cFl @wz3,jaZ@wx|+^0.3x2Q@oy`W?,`\ >#KpRH[].䔪ϸwwLA!V?8rx<rSs&E^f9QG'ʯkBr?@ )G&d' !#4UXKMR@j*mS|bt68Z`_O9k:C<$P#gLǓxZ#uJ(P\يA>ܐ;G/d *By1lʽ!3|ڞa[{),R1ǣ:٢Y19Ǽn Zְ!E>äu]L˶ken*Ԁڨ-l3=E;Cʤ٧V+Ib%t%@Q9'|jkTpRB`SQyWG)G^Nyڄ$"dѬd6̿oSK̉5 ^^#x_)'+Kw wFGoIvtg-)T,]Ts/C PA+ M6%Gq>B^SЂERc^.9GOѺ4XJ8qfL omנkbhr(}HD,*Z~s(*F{1Li['E;ChJK,2!?Dvڰі, X*)j~^p=uzL)0,V>.e)XaDw*oDV{SI4L: g n#TeݣFq>> xlTU"-\ m ,-GJv[,-[-@Q>ߥz^&E~fڍ $rNø'yef3|=UV5-e|DK17rc @Bk7q:"Ldz4[1P\/@ŐڏtRߎE!l 8oycfD-&Ծw4l[B%lIr'C&@dhd]%uEkۨ F*Ra o$u3nlnU0p}}8a pҿ!-H$7Jd)EEpYj ]~44u86F sJG|J@rjiVe$HFGDB7ڒP) }թ72&s NZi)A<0Tf9nh뭘I橰4qڤoZ=Ia#~lIE8FIh0Jْ_g@~P0m<aY쁬ȘO"}RngҋypJifAk-])k{]*nyKB`IN oc,&L!'*~ccX<1$ 6_?ptNoXzk{cJHn`]CNzEz!ӳ~ۑ2g|{m\UC%>9/ڃ$z~VaЕNݐcq]ņSGeM4{Ѝ3'Eǯ>8 ]6ۇd*y}qv8(TYuWt ˆO*QP!4Pk!8 e Ws ѷ܅llUme5T* [W[U_SYH}: 'ՠO*yV`ϗ@}4YF3"aNUzgq׼Ԕ68m,#Dt'3 ̸q"[|^ϔlrw7a3u1#,6e,a P_5;rF*cG\Qo0<ie#\'✢:en-~;TN7't_LwtWjk0yZc2pmHR(v}mGD0„HY5Jwl )Xd"IZc!2S< AE$S%l[k&7`wI~2 0VCrJ/$U]IԘ0%5;YWO,Т_0Q&T%sJ+74t"Xe6͔ܱOOg*!Y(R)n,4^C? ;FJ IkgdNyqH_K&؟Q۝SυHKη;zXJx鵌z pl* Xc׎6{9-VR{uPI}@~hF|@1!i (~+KY"ˌix kzxمҜ0S 0ŋ8miPkm LgGP^lHp3f`$Tݳkݚo9=Q{L $:[^);$l}9FF  a z'~O4nQX3 1!k! i_}'~v"S7V4,e)d |WtBi=9&y|7S?+SAdAblNE[:aiٷ:0olwo *gfɂ\*{9L,[հi{͹ۼhr?Sb_LnҀK]Ɵ*E|\ptƢ_\Jb/9=,^~dϤ  Caj]:HA^}t,|uJx!o)Sfa 8̛JeO$R55Sб碠ns '.ܽj2~HaӞˁf@?ģdJFEqQ$H&5j,wC7{8V!rkM|!J9 }}8mWgTa۲O{gscƓD2RaNnFg ۴c)}$`{$ʭO0)y ,7҃eVv{"Q,ؕq=]󋖥{Hn?LMg k_ GWkdbm])r<( WǎC̔-^<#iLfo~1cۨjPZx#{?",kSSGhkmy߾>9ۗT\򝩭k"] vi.)aQPؕ8djA\7 ԟd;F!=M ξ`a3Cm2LpCmتGWw7vot^ձ`@zCq .%,B+-.#QX*lo>bKt0 Ƥ2ݯ0zo3#dzaPw KNe/8dAh>=x.1/)1 :Z"dfO `;:R2(C-]s1E U͟";*N5`W~~ͱcWXWZ (#&CNXf+|Dx |!騹HN,WXےbxdfuvd z+-aJƌbN5| ̨SγUVc m4K؉De'G0Y^NP M 郕+X KL$Ha -(a5%lnCStJi?&)2B3^2ɵzQ7,hp$fk}mNZ<1H@YQyH16}RT9h'Ja;u*Hb ;&#fYh6W BNw K$KQmHĉ~Z;)e{0D0#VP")PPg 44K\ZVIڸy>{kxha1!a줵Vfmvde*b 027ĤGr<\dHe"|mf??-Fuiqf_KFon(<ܨ:NJFGlְv!>5!B-5Kae 3^CQ"3O^ Z6q+)SG넥/tw9mE5$ɧ yi-gD^Ŭ"S3d,ߺ3͛(}M[=󏸞a/}wHĨyN2QX wB v_נW$=켬 |+fTz._Pg kml$; U|pNbEW5+@.k!O?"3īRH>y 6Y֜ff;HsN5`~V#B,>Y %C\jZ:5j޵FxѰG+WmQ`y1:*?J `fZFM$r BI cXI[m72҅{cAC5u,h'%*<[Ԙo_r\q7J[bT1/(-:]f@NƋEx At=욾Md9[TggYR,ž,>l#zd'/3sI 6c+cBÂ!54G\]4y&ֶ,4)a6d>W(dˠ}'PSe9\RZ>/p]e'ʦU5WIw g`NO=H )ɦU:,7ԕ팳KPNeQGM{pĐb|Ɓ7C> #WjaĂ6f.ybIp1$I/Ԉ-=4 e\Pk?w\8@Ǫy֮N|̿~)9*ժ#?\5YPL\tSPTEfwS^RB/E㠙,O w~8tD'Q槲%Td2s9J6 2ĞM#.APWUSEBp2MJ59!U}j+ˢ y~cM]lw-#}Ԇ6U"'\8c$sDEUa2jc;&SMNC!@Md5N# p!zP?)@jP$J"ĜE6|j:z0pn-WHBsDGr%_:!=ޝeJ /q+*+"3@8>v=O}Iox{䆷A^n ^ry>H{t_r.eS!2MMĭ~N4aOvD$-~Ke0#`oQZv}xoc7,sv`if[ݐN㔂oھ $b\$^DТ&W9noLX &Q q>!8Rv8Pj&Esxu@}HshB`i("j|MӃ"."vJZ5E.B ̽{O\ 'xڈXX2##%k,ޘcPgbnXW;Իo5,#fW&GkOC=x(>™XŃɃ>KR$r'lpj"auȣ*X#IitIsG^sBZLjU2P'swmhLXOX߯! &-/yBߩ>,Cw$20l^[CrF=."A#᪂zbO ZޛK 6IJi6.˜؋A m6 SpCLB!3HpC'cڰDP:] nr&[G3lG+]hV}M+㟙=.ʠb! DϻizqUȳtB^+Ore7%(6 ԙT8Rziw6v쨕,&:y] ={]M89YLG:X:sWf%,B^=բ;4"Xe0cNl,TM3Hqpn9CJт98j)fC Pʈ@cdK=j}ۀf7tgBf\ŏ?3*8\MD*$z# d3@ sY@ ^GB;'6xO HDc_tlH,t/[N:Z4\L]#;Qo[dv2uJxqgo;.;BT#ζng+N99SbcϦ{@/qG..e-_T] M}JQ@@fۮqК9WhJFǑfa &36gf2aEW'HUL0ޮVp=k'Ir1V5?E)6 ֠+p%Y{im@ff;<}=:['eI)b+ءOZyber6hvxSZ?'Q|פMVoL.$$kG@+H%]gȒ*֧U >gX:nY17aM}pd$t3'88 ׍_׫$"ۯU+IwО^Q7Z3GMhSx@E$iOg襙@B[RD"s]|5S %P>#5߰p13`/Dq.# 7u26[^P0!E8Dy[ ۳TDۡm$ʂKٓ !9jznoeb3 GɁ쵗 L a"g'$`"zUiѸŨZb5@Ĺ),Vr$ AeչoCר 2^S_Gaozc%عJQY^;`A1ŏKda+5}XȮ/KӻWC.Ejt%Ev_ǟ'}r@#$}I\nyn64T߅3=FFr;v$u3b `rfmǸ\)4#.Y߁j[16`/tb?ic;'& L ^@s:~U$ )s5~\;:2+G0 ƔCѭ}J 96f%1wٟŷ6bMxImEv#?N;eFT bJ$۲ x]>gqL5Ghm"6u͈OK “U+IJ D.iړ-L/j&1irs6#Х&]xPΏ"#/V_7~?WY]X\ /uZ\cj#_HЃ}! zt؂3?*pCӅSSamURq WJk$d#_tWߥ<AmaB+&%p: AH5v {Ͻngl .!--"x? u,U.I_f7{ehʺSp ╬j H)jϠ׾"-J7ihs- 5ȣ1a+Cjh7g[f2)5JG}"E  5 -c|qa2}ny_ Dȥu,1Mj{qy3o$1}d[kv[X*b"h؄UHWX/FKv4ؑmPCˇ[7_W*q=0+S2Dv*32/!y=l:Uw2mr[%ap@AO}JtD|'Lَ[;Hm :Ixnj7 =rsn) ,=D\A%q**;F{4=wgOFA ,CC&Evb3P%mf /p _ 3J`5$S ;W-ē7-߄#;, j#!0W+r2Vpb&iW6f\jk}cm^^,A4rL}ɬ$t*<9d)KZ}I,kk$L0+_A #T1j :6F1~eU> 8Lw6-Vm m&#U۳~ewX&ؾMH):l'8KNsh΁Xl||6#Ws"a6m[ ֘[aכSйVNۈ3* +. (k* [͊=*{ w7m_\3Pē2ۗUTڕ^WYz,s5_}hV{G"HV%$0.f玧ʞŸ&\c, }C+e.?LM5#T^;wgCWz~}C:W2aV@g {L d]2oQq$KX# ܏<.wa24d^ :c@`6ԌqCya% KP )@Lp&K‹&k4{< XׅC&79%fR[6hB&I}Ea5zWu  '. S49|oBJ${*~TA& 2'yu%jUÑsHbH:3 _%b L+r<:i sckƨɡK?h' *jjk\N(LT1 .RC60LڶPL!+ZRb-(&ftzlcQbZ!k 7/7 *Y0 v+1:2t8(d6Tmq|U>M=f@x1_ Րu:lEV^ ǒi|o˴qTދ4ӁC>nN6:Z%n[SfB]pcf{tf+K[J\"bƒ %6M ]}uDkvG.aP;M-K)U8KUx"#Ɏ3ίv/PPܣ-'-$q~b 1˽+'gmFɦDAG# [Q|;6w;?9Sw+tI:Ž i >1sKo_m@1AM(n!JgLtoᘂ5(AdmŒ{:'Ǜ'HE%M[ ˹IR\<9D rm,ج~Vc')g@s;Ib>)l4p TpHG8@"@P)UB'M5Bdm),nQݐB'F"kIzgV+v=enu.Z ȓ^CW.%!cH=.!GLa'5hKmy./ o`">35%kI$8T:$QӭNf$3fvxhB͈$֥-xS}Xfs?E%b(4C*ѓmXߥX''?}m\3>5$g!{DiJY5wʦ}o-FENgX S_ BYޛ5гx&So$P{wIP9@R>%Ɩu{alm#8{xT.R֏"`y1Pr9+~0 (ʕ6C&HZu5}N}28$LZ;Is@G.\Eˈ6;Ds|))k}4 d-ԩn$v%2w bטנsKu=d^0~vNMa+>L+%'=wb:dͯ 9}Uލ{D `8;CNb@N5# )n8b6ިz$z-w-P&.&ȅ?=38bQ/'Vi#,ZqFX,u1#`2{g<6cH=un= ݷb.CXp l yv>1/5%5Q߈z0[Ae)_~` Rv*}{+kx"}lbȯ.)[Z>GITڻ't{Fص՜p Fb*ZhQMO+bJ/?%;i3*5H5r>UB _"*a%xlPӾm|92\%|-zZ,*깕'P5L4O!8vW5L~349zyjKѵ3i/'VП[SYMT莇toK)7z ,8&<ݽ+xE}g2H.7V|)dxۤPȿɛA_Y 7;ϡ$[rՏi==9;K+҉5߀gA]!XSlNw Aej/cTt, |lfGa z`t878^7uV .姉3^I[.Da 6ҝh8źRjA2kж9_FcRm-8| TOmƆgY8R !oFx;b =Eps)SiyI2mfoN6Ө,KEt*d{a$[>i g 9enF`U6ٟ̿"zU>6 I 77 :QbTC?NʎDjV,Y;Dx(~(ʻ J&\I(\ 7HնfX0>f`dӮOxZI+cJ΍ zF#֤hCP(kZjQ,ҧD2o"tW#)kp^T(KUtM+O-3j a{4 N3.bndgǗau~.UΨ$w )6I<0q}Eߊ-_a;zwj\8jNI0p}jBcP8lh-~ݙq(O]s0IRr!8,PI3&ԛ1;}o, Up"u<r+: s!䞈իWCUWkaDctpHRSS }EWS=b&_e(R}ֲsOUK>Ŵx$xS+E(=9`Y3r#tgnȌ̡ݬF C`ºps)c q4색!ܚ :馁6"WPudӾZ1N>Rs6>E02XR997 l3ok;%64 !m8F q|{15W<0AVi xQ/v `C˲Ϲ[ w}7zVovtHqg+yǚ v.|ƙ^p,0ͮG*8v5)i;mj]PrUk5Ͳ%s% VtiQ 5|]f[>䜔.$ p?psف6@zeX)Fwu5{~gI lW{5UcT,qzq+-8X73 WE{(3p\aUxazqJx߉GqAf̉;cM.wegk\(LKRj>?g&G ;IEC8t}B-2Yժ6s)-go, =;B6*~DXsxZEX8[-/QP{D~[g1,Ɠk+d^kR*Lw3O$9 Ӓ9:h"THM7k13yU_%kPU~GuLBNd ߋOv[]m|sߔ|2'Fg=^_DB&xQA1 mF޼Et!N*O;Y@8({XW^UE%)ᮃ7>_7J$1|o cU;.)]c˔</vQ_T-c@ lj@y%ۼQaq{|1#IVD{4\ŵdjB8@=a)q.GA·o.D]+En3ɪFRc"Gd78oZ.#߽.+O$uS#cHlډ[k:V7YYԜ4vd>Nc>!f#T]&$$/(QN']:IgTPu 5I0 ^s5=[Mj`a٘Bl7fɴQZ)Y"*q#<@-:Vc֏lqX4Iw"]>|.U0;dh)vl\/+'..1vҁ}ސ 3B(u3cSozHoy@\0h5Z0‚['?f \8&YCWE5 `,_?Jr6 `gg)8R.2E^]U' <_z'}h%QAg=a1Nͪ}ƙG ń[Np;t=Ek3<ՁP) jN;S%v VX;T䊤 :ۭj$cVb6)Ωgӈ3i"J8,r1/g,L``) eVa< PZ`k:@ R7&헽'CԚLؚ@mJV6b:"vlǕ&,zR9o-zаL>f38SYZDɉ2Ʌ?$A(mܻ83uƀqHӘ#g ҝs$_I8LDg^V( l׸Fp kRooӡU6{(ԫ4HH 88d~){,$ٚG5V O)-Ja.DH %:e~CHCA(8߬E T ,d YrFR{b6쳣:[960Qw!ARoOec|::j:@KMc+mmBխm3o=JS:ɫ'h+)M+Qdp rq%~L;b>r&!G"y5~gNt_ywIewѯ2"9gu{#`,4QfZtmo'ޠ$'cWk6_eNt܁+ο̕'!dhNTj:7 ZJ9?@X!;\LԒuה_6sfgxOm:ȰZ@PZ#}}+C CܟNb;xkMtfzgmѨ/4oΕ/ SOET(H z4/#A vw1dq3st=pkdLᔾq(J]ie1>UC,2d9pG5.%S.qSrI'Aؖ~*_*KEAʸOVx>&+Q~'gVՖ?I2*Oܽ2 +#&Jj;k+ia$?^-pԮ}g#j4aWep5]pL>*X"ۉ*;LH/zZvHA-oe*mtR֨H1v)0 +snZЮf@h]]mv?l\{1| }mc7uci_o-ģq U3SB<7XY4TOFcaH$? ƚUy[IJ%i?Z +!@d~ 1΂;DNԞ{ (kajVS\EotO/9+="CQIx7-;˄`K]vE>R7]IH=*(|4Wx3ܚQw;/KY]x[, #Zrm Y9D2$<(w`N/KL1n_;9P6yˈu+)^e>-7nydꤙ]U\=whPad@*%/`ΐ ,Ҝbka53cIN&!eIV~s]h=vp4=hb($mGA8.گG@ky,:z|GOw>&5h#g]x)Bā9IƉIz­)4v{ٝOFߙJ/2j-KPonJ.bt2~r5I$6=m)I@ M+wrOT$oTZ}M,V_X:ߙy޼n!9rÔNvF҄ O;  (9oN3Ee5J)zA95]Oqu׾tmc\-50QX%$.E ۅqJل)N1eVе9!>\ "~6QBNX{ƸG' Z**ٻTGȣvq(J!7'Y>ҖaA~jzQ-p>֟rDbhp;f4 ;5ui 63@ |-|>560Xʟ2>6jd<fL; Z2xޑB~\?KkJ%j7n/'Κ}f4A{]֫٣M~k1p9\mkWӈcWO/@BaǒSC9}Zަ Jr| 6Dkl#m:jJ+9v5>of#4}p#Oʒ:o{w;㲹]hf5:Dp֐T꒗Zn;e5LkE2 =SpveK//kzfVYO&B +nC:{Uc_4CvDp}|#OEE@CI]G(svDW!(<*&ٳ15Y9:ʵ-B13 %'J|}ؑ7_Pl4~VKX'g&lޣ,]Fs`9Pk20WjiRB0#U:,Fh$<}nªeЍb~G s6)ihZg,q{ ԠQM#f#d?*l4֐l7R.rPX%tqmo)l #>8EDNUߗ **/#%b;s 7`Jน@}SHpQ z5ev R5Jx3MI2w( [vҚ7^S,F7ko+tej[r}lTp5aB#ڈ[}ӷ!&2]yl§v_0ytE׵ y)CLoͼH"@}SWH BR#" ?緕8!YR;Zl?JؓLZP)W mƋ<- ԺxD6hljr*}ʼܩMۏSUFHT`bhs<w ɕɻk8,g0kjVdf|ʓ q0w7F&6|g@T9Kf_w1l3P02P_(WLz)݇E D\0LL";, 0> 8p[Jq{Tw34yb;:ö:='?ɺOγ*^bϏZyɻ(ə;gٕL^ dES"bpA=Yp\dMHH)7U0{vՉiS}S]9/;6aQ*)mӤU'Ә CE_?DT*~M=_8EgvN,ԓ}45"YҐ[#zvqF.Sr, jիSkAzHn'`bxh ) EakEJC$O3ߝSxu?@\elWT*(5OHo @:!kBK5$!>!i}v5PC*$kiʂ36z yTZC|Cxfֆ] 3Vu΂7K>(^٪EY$1JƸh±5+'K綜GQxAll1`?2ϠGNRU<ÚGۚx@j*'W-W Th?X4Ĕ"{%U6ӷ<7cVgi캱'QiH'@"Yv@:oĤv53&KV-v5C1JC-ɘߧ!#eNC"}Ư@Ȗ#~&2=ΐ }0k4y7t⭝ ~ϴ msFze37!,ss#+m RX8P$-881 \cR9x|ڟ% ہտ{U}Xu':)-{/W(#Z4óC [XRtWܫA i`"64O Cfwբ^3ό#KdE Nj4O~5R)1g2u*Vv H5'=6uE-3*iϕmYP!YNTi_?|3xWm12ڙgBdn)s4&FoW$AR Ww')J\3h^Y"Z uj>mo~h}i`\e @@~֣Mr{蜀ikt.n39߶XѠQȊW|'OnqC"^(!~2]t(_-|aȧ'V3jWh`pDz0==&@Qa/ͺI_ȡ1M\1?}Y|K:y%Q2N,jBQ& |F=Vh/ vN2>e&u]]r)Gq=b>?)oㅓp[}c1 9nx3+~$&ؠڮI"$j-ؖ^K1T3i)4LO}NWJ۷p0kV 0oɰ b8e;r,8sO{+75<4yD\M|ׯ0?/wTU/quE Q):->ONѤr.,sw0(򹖷d:Vlb9䂘eʵ?:g`SO q7/QtрCi^1 +RâlB'ε['!.Cfk(p,oq<΋h)Tř|H m]J]UFPu'01_YmkJ5ި"eYpMI[觧rpzs T΋vdPpi$UCדRoSAzl#1A ү`Qu -VW`z JsR?STJw _Aw]l}GMiea {T)T=Q"? STi?lYhX? `{cl įW̴Yz1 7mb]s!Pȴ< ÃYWD o`7Na)*ty\$vk>JoJL)}u@;zclT$07䰜΃W֟V7T1N;tDz!N׉XTmb-@qWR/ ݝy l]ma~JE!Aj&̃+>k ˟6{ANj14\&tïXQ:(E0CS!AGME&wE^宅ĚLb 8*=o@Ɇि= tN:9 |hZtkx_W+҄7 664@*SPI)Lm(+9r0#:;/p;E#W˭赁E< 8hHTW`%..G):0ZqӾ&x )yN9hEA@#sLN=oIף)C hfr0; Kt]H8-Z}O{flpJ"y|WoZ sGi-x}E=Vc֓H X(a(Hx[Ni9d6Rls9U1>kAm6 "ql%̺ЈG@X5tΧ#7,j͵!oWp!rfܘݥWBޘ#aC*lԈjֳ Kkj8އn|x0虃x֓/NkV^ۮ7z_(XM'28@榦?IC{]V߈.zIMmŧ&} Z\0@:SXes5#r z"/?9*Z n#ۊ϶Um곾 d!t"0u[g㧢&XO$ϖ{Q {=tt +/F$ ޡ řu#p0,ްXwۜv3)wȪ{$L6!h,Ph͵mKGj(UyNS,5GShBfٛSsR ;Ja62o8HvD{m+VC1^scӥ[rOkдTdX8e9uۿ%4J]?"!puտUlf T"낣LQxܓI3)@ hDKq~{JS81;Vᖤ28EX n_LG~+ QS?5\g%ޤ3a Hj쭻B~,竰^G H.zd9VxmSfɭ(:֪(7RT=^f8 EȊo|p66z)񣸮ϐظF*WbȺE!Gg øq|G̳CSt܏Zȥ G;NuΈ0?@NFހ8Đ{{6lH>TxԏՇ.kT[SlGyЊ]ᢴ熍#AL Bᝃ3S>z tqKY(`^f@..gih1߹ 8DȄj=}MZm@LfPҐj)'_0}b" GI(PbڢAʡY6ٗ4=i.#8*|LbhՃGز& Vh& t,]㰾?1u#t lbEQfB5NivP {$D\ȍ s;q۫ͥ_;YiEȭ3̥kp<͂pĶӾtZGd`|\ٗ?ȩWA$*cYA^`XH)1}A9/=VZ`/ikAxCa5x Uϲ7]Ykhkv ?ZJR=Wg,C<43YN$ۀҋ]湒sTӕ{Ló9LiJzb6Q1 OB4/ e($gBZa|`q6="C7s{|ߟ{jJ qsEQ. U2oiOz#N|b#pPEda@WI#$αZ1hT_B7:G#SR3{'Y iܙtxBbYвjqHZ): sf/1OzM-$=JX֜oO9;\-K#*_G^B~ 6S!K`%PLi!ˏʼM]IW6b[<(uh^>3kCգ½E*+x~V}S يd¯-K1N)ܽ)@IoJ,25n`J1nMưq Lu_+S}QGj.uzF-P0l6d$hUR^?-Qj)Gt01e$Gz FF.6?76 N"dƁa+P"+9 N&>3PZH斵s4`1oqQ*HOn /=8,H0 NP'gZ3 ~9`SJ;D`;\}.7~gM'i֌.Sb $TYAJcskMF]6\W:\nwTV?>h+R"Y ~գN o5=ڜmM+;n!{ Ť~hJjqt'd"c٢V df1I VENEFGsi̸#5W%hʃ$b>;`*ZpÉ_a`Դa*qR:D%izbj#l)9E=MrB԰7:^j I8o45 #V/:{r7hb/ ģ;#40eC('s2{\_ol1h4 z!"^",>Ma[VRmi#y=m?r{\H8g9]U g@.?n׈Ad]`{r-HC\M9-Qa8'޽ڄ RoiA Br\:[3XJ'HqMB>&0(6n'dsQb a'q(ΰx^S9h{spC!4\d@eF=Tl7 c45;쁿h3$ji 2Fr8.x^7XXʺ={TE^+af¥#IJoRJ27NDG?_2RKopKm vP Xm.Dܵ  ;)uV\ owZ'u#jSDq6k%9gɗf%eǟ8eG]]r9ae]$ sfmpSo s1TNBbU@s^"' C]WCye!eyY@FpOPDtLFAݍFbS/W;1R ɣ6a<G;'sQX Ǹ?*4ُܧ a8qbI` ܸھؔc 9|-|2Znɼf D=;Ӹ#¸E9;ʠ_Mk&UPk_.;܆/d7T%4-4I_wExv͇0SC(iro+'ykY~Tʧ1yIq3JoLW}?2mKQB+ mh8BPvCmaM{A?Kv]{ !:: T0P#D#ӰfkA(z?|;EAfZyn ǁ'P$qs  cͲhy.y>;/8ZB-q#GO &V.҇: ?  cdXߟQ~s{mȽxXҰg0~Rzz:&r=my) Jn756Gp'lhThr_s3p` 8 P-*ɻ_gZ]J^ҧ\̹BD3xeKtUÂ[Y,:vsz[znZަ lqQjl0xZ݀j  Nyr#Әc:c\x?! 2@CWzQjn{[Ãx8 ߑ]w +&|䂐7c˲J|T'%)W?Vf8'j $(fǑo6E!jE7`DӗxWU]y0._+ yi4D.N/E$_bJgOgF8[z|MK'd ,Qb>}$ȒkRT ixo#̠@ =ugKizYԉ2:9-GYeZ]mC24Oפ4i e.6C+HtٸcFl pK-CW܋h^{f_ç+2<$9/9<+KgL EՓ7' @H5|,*s~]Ovxlb᯽˃nXx^N2UZ9lr ?ڍn8q7[2"|& 'd '4 .[khcR&Lᖕ9aM)7:L `Ѵʡl<x#-mgi HĜ.GIˇMQmU^2χ^ ͖2펎i3wL.peuC.eZ>NSY#ȵ4=džQopUfr]03+,DxOPB0V{|}q"Uo|"4}i0J 3 n?PR9YDtB[<=MmI%9:iV b+& |b7>WC )d4:e-a )ԕkߪ!Cg* (;$e2;]HL|g=L͝T8}iZ˵"7ORAQw 9?BjI4LfNm8 F i߱vFXFe^ p>=<;F1SJN~zzזeXSBIeO^ʏLRƚmԀޚa~ht8-9iz,I4_2+ H\!z)4ܡP(eQS\4ӥnj3l Hf$WfZ7Œ&1A6q%kL$t}F#Of}?uCNdx趥Bk*r6Mg O;mmw#j= dO4/ܧbůf%;K94&1=YurmA|#TʁzJ]/#i9fJearJ^mV'~ ?/Qedb21)ja7/ 0-0 jyi;??T 搰j&*e0OvUcR~NĖAuxllڠFh61 ^mI:GDuvΌC-ZP2qIeN+ Nh4*Q1^=\E|F% {g46 nط# ]C `v-wƍz%bd2 }q 5؂҂k9+x׸&HIH7}ݣ%͆6bMQ(q;Yb5-u[gVhbCWcsMVC$\b 짦|谙)y/0 -Z ō7iQ[2ƊT/E, *(3B+E5o)  3zLq'ŶilP0m d_^Ty5I)(!0{EKrR p._e1J|3;&예0dgWw䵀 U' TW-S&TуVqAGM)L}<𩪵Fٍ7P`%[5见GܬÿoDXUGb|Ζy9GuafZBBgiƾǛP zI\B^@Ic!彚IaI G.CLmh%~MuYTaE(qFy=!Ky'N?8  xv*sg,(T\& J3el\޲g14Q?gxKisނ MxHlڠc1B;S%V0 'O,5(=bV(Qۈq|=D CAU\ %!Y-vjcŻMh :hg/ ˜{;Ѣ",_=9jcOHBVhDtqmAcݗ6.:"s6q{E=Nw}%ӷ˪\~?9ŜݘG(qp J `ea͕(tsP?,Nj&뤒ٌDyUzn7JrYuk#Jyk1X^ueFoR\! wz';x(?]2 j)o ˌ ǾھQzk*G?K`55&^Pº&%N^AaQvi[v&?8bh.%C@N@݀qQyoXUy.TnKJOta׷pB #Flˉ?~c?o:Ua ؆^!?&NoD[ ;De |}v1Ks.[t&&hmS{ QVfAkQˮ|/ݡeG%R-Xz JIVZwBi0Q|#שczLzpaP?¯Lyc{v1|2WJ9Bi ܾ[%;i=a!~ښ]:q5r5gówE|QI 켻ԏU=S ʝ2Ʋ&1rD; QV4*=S*\PXQv>`K]f KL HQGI`yxTJ4$ cuעǁB;۠\wlQ4]VRQ\0)@{W@K+Iؠ!}ր:t }֦yGO Iх==_MDtԍziC"]ӦbR2`1*$WB,x"ȟKR˽q_Z/o]*"2ᱜC3H=}foPr[]#Hv]>c\9KueűQ-@grE͕ggy&RjCXZ\D2j8M\GC;<2R_iw,8t{c9ʐM e P( 兛L8o1=3^Rjel˃Ƿafn0䔀K*j~ \[ǎ“F !FnjTg˪1gj~⻔JZf?1i Ʒѽzh8p+=5p#ٽ]DgXyb>X}9Xp*P]:^I8P.ڋuVP ,="xL v/;or%GDcmh <{9t>rT}Q&>dŷ5c$;z&EP#$APy_vcX< u a2*,B+(?.g518dj뷇\.d/yՊAMwt~D9~Ԡ.>n|rA ܩ>eSCD78~{̡;K|Mʈ%XcχQ{^zX OI@,l=cR| cN9s4rxTd9bH<&1P_ QyoE&ϸRv3vvŖ͏}sR߁WvKݏBC !+b]-zF<5s>15{0&>W]m3TbRL"iqO& [U3x0ҕ< 'fO-Rr6CMZGMBK<.nD/_o=ڨR_< Wu/fdk#o=mMD 4d/>T >d,c1Vr jepF橞}̌t&,Qc"3wdNAXlm$͹9hUzBW\ca-N y%II¤q,>,8Ҩ4 8 k@c&`y6>|_oh@6_K}Mj%95Ã{ D c1Y˱7w-yL#_̟n7ַy2¾:V]/y}&~l$ƅE V,T=I^!Tl wڛ ` <ͽpm-ʕLg\ㆺ8oNҰ˿#<.n=VݛtY9 q+~358?01R O E!^UQn+GLg+"C֠G )6CΧHsxa$<鬨*:W7C@Rh)kIhO)np@0)uGi̯E)kݱLPJ@̍+fTtNzzc9wmJh&B"`po|@Q*ijqXj%2O).^fVSA ?u}UK7H۷p͝jSsq i3;c)M ImmE<'X"ݮܰ( VgLQU /]@$ ͕mqFXBc@ 1l;ӚǜSU]HN"iAϛ}~RY$o87;K%^j⚲ !xEll"#VH$̙CoNj8ԼZucGt]A}3o`rrmNeϧ1Η7\4 }O;0F1? Rnbi/|)p*RȰh 7PL3/ 4kUlN j!Zr= +?ZTՎE39Qm2rKP挓F\ln'Vx#/-CiѺa:euä# X^ѽ<-9eT@?\N kaȄm%;11s--0e>5f%7z=NbOD,hH%vA~jD{wBщȧui~; h ;Cx8I'N6 l(Iq+y2a] 5cm`j~ Ӓ˜ܔaez| z$m(y+L Ohߢ"š;T - -YI9F(+ݞg bս'*82ϭt;@},2K*`L.cJSC$@bU51E`]v0w-[o |+!Pޗ/WՃ=WR:6\XâvV-T4[ΊTȏ%A@>aU٫~eif~8g~ˏ9.\/U2LE܍MNfXrX}۟4#urɌ!m@7Y/c_KEf"Z{6~/zOп8e%%V4`b}F{_WU[H_P(1Dy.^}(tl@Azm!4a;ݖ)Z}-S{ӫn2l 0KQ^y8@9$v'MP|}M9-dUJG&"ۚާ!^˒?Hy9[50lZ'OI{Tbep8NU^ L1[LhOr3EoK Xs$;̸2 n1b.·l jMY)1^ol0F87GӠ B#I&5Ur*)~flHf-IDC:`I© 9-,m_F*i]unHwV% j2*ݞ׌ E24wv!<7){;֍€?SŴRpdF!!}am9iD{G3|ZGF@YQWb]R1xPZ}y(ݫKP,&a2deV=dCVC4 .@]=V'\JO2ޕgg7煄8uµylVPx1{T!S!<[:)D<)`p#Qψ(FR#:`^SlojAbVߣ,e94 4Y ) s. e+;i$'QL*Z݌ih|`7b!G+,LK!W pV'P*iE%vG4kŮdKϒ v 8M$+:L1btlh`m#oB>j^8l9Oj"TYz7{CwpH4sx2pHQzO-@IN23).cNma>b|s[џ{jfJG N@|1~₯${!`<]<Dz(~`l_}ΘU\=sQ^zRdJ331]D6N{{ͩbqe}/M+zF!crE_,Αg4Bjgmk4SOS:$ # W~"\0vWH(F*IEumtHT :w񉶅nvl{2Goϓv~&~r;xQ|<.o -9]I4>]߬oKeca,+To b(OKyKU_d"O@G[تn]}m03yHUS]+ۗYTbhv7ʚV6-8 BTeI+T&TQ#9k h U(:Pa**?ޘs>^]D̜Ӏ9~lp~ueH97jne+G5 5'ٿhO#s'伯W;K#^ؑ\hF %W'S"ToLK`6XVS-ujl,W+ؓefigqF/cၾ&Jpv:^Z0v*ᯜYN\ZPF5,)PQ'ٛ3LaIb䎬n'&ZϋߡB"uQmF_ξ.e ؉'FS>+D⦋Ōv]n_3p(담gTt֛}0b#:-zM7Z}2Fk@/|D"/x,eۧbn'C)m,\Z4 Kp( 8N ?76IWt>}peNR)EC0YOK>4臘0f[&vE[3PUIu8aS,U G6M Od0Ɠ1.7+yۜi#}0Imfc΄[Gl;*&bƺxH/{#sÏqEG g~)IM<"G_CL#s-06Cv`XBhi/{8m>&8>%w,I]ߔAGnim&~]dc  zu(}?7-g%d\Js&*@}{E0% [B݉{'hd=Z ƴV]GvQlKw3!F,'y f66 ?gAgEP'4OFyѤ}ZP-sߓcf!46/$KJׅLn&ĜP0ǜ}*AP?Uњۤ ?k1{/>ʖP2! R·bSޯ;cLREFgA5&%-ƴ6B>u?9㝎 `P{x#϶*(aNkڡ||fnjN_Ʈ)D|MPG W,{&XNS][cWQC$(|v)s Pǚ\xD&{qPr$k;[R{Wo&e{{WiklD HYt߄j+99:FS!3Jo(H~mA h[| 4>wtU+#)H8I {ގ)J3[sСi=[6rSJ@14tzPo׫ELJO@ u-f3q>as髝^P29&*&,z3rt~5,PV1IfGM{H'Tiz 8sB T/)KSET~VF>wFrZ9&plAMɯͳkZIu;=S > x/yG-9H3;IJ$Eksy?e`lP茙b?M?!?L~zCs8by23SA۾bȿ:$ &2%[ jQ,bNj>xs,$ mY;G%-̳ƢL \TTw +D>M"ҴoByND. k5e ] $kx~R`Jy 0تr\}5%Ocٗ6;Q֥<LqqO/USoLe$]ɔSB9V*XuvwK1PbCUW3>*88rMMIzQO3Qsߍ/G!$&> Uv݀]t1[Xfi.'ed[1WlW5@IO aRb&|4o$<= Ι֐\s' S]=z!G`lmvSL0SEkuBGT;6++-cMXEx<;㞣HOD.%3Ũ33hZ'hPZ I'qq ]0ޱNa A Li1Ř&EH+߅K"=/Ư GTqbS#wpFJ$[BFz Q.gUILyˆE& (f.*,徻FYG~"S~>m].*Ȉz+I&-NSvu83jśh&WW_)'􎲘~.(DMEZM#t|-R^5o %XBɫH;7=-W u95((W )$({0X~'h]` ?tܯvI4 [WbT/*^xp9:*~hkl7 DžcqZ.ha.r2FdTp_Y5-ۉ̸ѽD6\N.`\&Q"$cO(zT~,^zw'oca]8`K( Gz%%~Zkw6[g?Ktd+g Է[ƛSAZ7ܑa'7Õ1"ɔ]t׬96tF.:Y21:~  E\R ԧo_E.ڦKo1%5q駙M_K)}z.hLIScA4vV!Ys$K 6X2x(pS< z6pGwƹjو2N{ڛInXC"څT#_1}*w_F$/EiqYqAގMymt-<61 [`㕅٤@a#Jb|kIX1P!XrP\}:&c3 ?z[&?`Q";v2'CaѻUrT]a ]FkeVch`NltF0ZaLrPӗAVm'.8Oafaex`2"kK}SZ _ܼqZ ##"{qZ:2r/O=f-EB5)%nM![ _UO?,6g?:6+z0S$޹+n &y稐d_[9VXэjQ4 :#6z]v.]c/g[BABH3&H$U]8XF腗l6B,'e]Sq|veLRo4IM3CG|$*Ȅ?"pB_4-ϗ)|a QslDL ~v+ AD͹ӟmAq̳NqxOs M.N :NغٵqXa,Oe#ݫiWV],opJJO"ZoZ?Y.6S)7nDj~P6t3Ϟ;ac5]+B]F9\FʟˇluAl!f<\6R| w +FQZșW+,1owSI*Ӝh m[@yL^M\yDN cNz8<be @2aIN,W .Y:oIS3(bsC;#nc]mEaAG=ZAFJDyV?^UC퀊3yo:@2p."y\^MLKU.Q{$&! endǘ 3in1S:po싨!Zz. / {>̴][ 7'0;t8yu 4Jm3g6vluF>S6EY<*1hԄC^z5M0ƱUr0 TuәM:NNȦ7VI_]0qO'W.+ JAH@;4'薠 ğݮm a/C({ _w? I]vW{4: ?q#pR)4ᗖ~(CJO}ąfM]SAڷUydv|zn.yeZ7AZA^xǽ-$y-&TD5OK ˱mU? (Q7 !G(`04*b tF~v6;M$JuiJ@PB4/6.,髛K Oќ#]N1P~zÜ9]ƕLdql[q&NqidYY4 c4q81* SUn,M7cǘ!cvk 5b=GQU9G~k?rtVcs)ۅveo oaXߗp(2D-XuAICSW)W']hlށY~5{2-ۉo]Мuƽm4d$7}$:a@[ ]6+ݡ!/^; ʆmO=Q8FUkGPAb-O6i) 3Zkw|j:<^2ECY)mĭfEHb(%`z*6-2 RDyF;홻^;I^E*_?H=rl 9T&mb˄en8E{vkJ%n8Vrj^DK|!iCnFKzR4qdzT"xH#k o y6G'_`Ie efTvMe;;-P=l\g%ᕑ2! >avMJe0ʍde\-OdqoFmț"R"QC 4`KR =9%LvC,jGE{*'/" =@rIw5ӵ2~'!U'vpm & +U1Z"(?+uPXEr>lLbEoXXSj9|Ia4?` ϡ)?5|!1:Iu;DY %ndr w夢qmP{+ 4#Ǜ-߯\l3m3{ }tqU#/Atą@=]ް-.ěb/՞x Z6w8c:SVU/τ-W4L U䎈C/_IѺaP}bRSiLJ6 %2Wjk1eO+S $ZI Q5x7ㄬıG80h}X$AJUt;m[ "K!_U |5] a@>M/ N4އlLh ?usCä )g9L$"+œ!!mLZ샕zU{7'Zr6_Z$T0ps:ѓ=(LQAU`'Z% OzPSmݖC`4tXdgkt"=8_B1kF*CjhpD[[=aqJӊ[Q_Hv xC:\V0G^͢{DB<(9ipZ#U>GNh8 kfyүZK!!7=IxeJ.HPr9T|PJDLRKC|a,JX&:j}\| =@S8!R$E^vms1[ߎ p{Ĕn>gdؗ}^{+mg}WЎܗY@+ ڈCYv^3lUŅ!1qGCF-xsVOQ(/:EA/g?oUDtHmVU#=nNz &>X|FgXW$ T5"$5Y`{N,I?381@,n>bC[9H@%gġ`c2lZVu{,-1P |cL-:g{a܊U[,QO-((WX>)T=T/%F_9z\v+5{u$7x?b }>SqenzDFԸ8 U!D1NՎU{䈰(I'ogQQ2O]zQQ/ޘ%f- Z;X_H.)Psw{0gXP ⇕Gil ռu{I~ KSc/ITʀ:l !c{ ] Sz& "pch=|OV-*9Ow$ b뀹6m f&[O߯09uft"lq-31J<_Z2 VY?uINS&bs$>jl]Ax4y/T-wZ*/ɉ2ZU|QYa D[$ ;(q V$P"o[:?QŴ I/!4jrR %inwN}gJLc1WSZ{Vl9*Ga~[ˡ*\%%jdT69r;!ӬCn8hD!\ܙK,7$d\Ѯ}Lt6F^\JU,j5d)X89 }aBX7}–3b㹓/RWaw60&B!ѻK} fQ`4>K C1.篏Ȓ׿\^WL;_jqr`iu#l8"1\=iӊmԲ!2Wv-ϻhR-hH5=Ms8) *1P*;{9z ~4QXvx-kr;upCmXEWPް R5`F&vèP[[+c+ܡ$:>`x _CT[ XBjuHx  T:$ᨎ7 \}bfegTyҞ:x D+; !b5YEJuS~s-[kTpy՜:UH:fu=xw-6:oZdAZJ;W%'+㯏-EY3ns𫂨~%bw[9bB5xPa3Bh~iOxCw($y@Zإǵc⍘qt+6!-p*;l7vp/H^AJ{y0ޭ!j0:{1 7z%{^СDLv!2 `@*%hF Qμ :&(EF~08)S3$఍MQ>f+j / 8( ;_ qV8 _c {l0v+Ls?q6 #)AD=\gE__U%} ZYZ"@U 1Yhu 9U-+tdˌ;"w?b}lnUY vBu^c$.Gx%JpSŠqνcJKMCJ m%.REvxA쾿oed۟:`]`];^ZRɫ5!}U%E;ыAbBIrM}<#_m b(nMW rN-)9,Nm(O ؖ@[UǢdR-@}0d{άA BHwK:/M Qtᘿ@;-SpN<_zc/dEPǶ;F>5 Y\޲+06Zxų@E͉( ધRT$>߅IeNyo__O\j7׶kCX*2D) R$"OҼJC-}ӎmƂYRt~kdIhFc̃ ðx-Al QXi')^I 7z0L4%)dڳ8Ъ[7ҘmhN,Uϯ꘳'؈l"PF-py;NW(\/ N-`tt+TX5¨!W