pki-native-tools-9.0.20-1.fc15$>lgF;5Go>9=?-d ! C 'EKT             S   " " "( 8 #9 #:#GD Hp I XY\ ] ^abdTlYtt u vw` x y[$e(f+Cpki-native-tools9.0.201.fc15Certificate System - Native ToolsThese platform-dependent PKI executables are used to help make Certificate System into a more complete and robust PKI solution. This package is a part of the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains fundamental packages required by Certificate System, and consists of the following components: * pki-setup * pki-symkey * pki-native-tools * pki-util * pki-util-javadoc * pki-java-tools * pki-java-tools-javadoc * pki-common * pki-common-javadoc * pki-selinux * pki-ca * pki-silent which comprise the following PKI subsystems: * Certificate Authority (CA) For deployment purposes, Certificate System requires ONE AND ONLY ONE of the following "Mutually-Exclusive" PKI Theme packages: * ipa-pki-theme (IPA deployments) * dogtag-pki-theme (Dogtag Certificate System deployments) * redhat-pki-theme (Red Hat Certificate System deployments)O6x86-17.phx2.fedoraproject.org Fedora ProjectFedora ProjectGPLv2Fedora ProjectSystem Environment/Basehttp://pki.fedoraproject.org/linuxx86_64eML)=m  +A큤AA큤O6O6O6O6O6O6Op Op O6O6Op c813882cb317140deba0d73f2ffd1bceedf75b9179a907d8f35f15514ff05c1587e062f3c9c924b7501b211b83ddb2489487ce9d70f7933613c2c9ba280a0ac22010ea4d4a62f7389a86c08ed34de32c1e406442c95d1691ed749c5bc268574ceda3652002dbc9e20be472d12d424c79637ee17953f289ac7785b46d688f440a7a61b525b85d7c16bdc95c471e91943e731a8dfd45fc938b2e60a210cf952ecfd6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e6fd3d9e470d519ed851d562c377d0ca63ecb3362379e17e9da945d9c714398438bf0967960116753b05be985e009da6c32c03dfd7a99469987b0e5a438f652carootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-9.0.20-1.fc15.src.rpmpki-native-toolspki-native-tools(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnss3.so(NSS_3.10)(64bit)libnss3.so(NSS_3.2)(64bit)libnss3.so(NSS_3.3)(64bit)libnss3.so(NSS_3.4)(64bit)libnss3.so(NSS_3.5)(64bit)libnss3.so(NSS_3.6)(64bit)libnss3.so(NSS_3.7)(64bit)libnss3.so(NSS_3.9)(64bit)libnssutil3.so()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libsmime3.so()(64bit)libsmime3.so(NSS_3.2)(64bit)libsmime3.so(NSS_3.4)(64bit)libssl3.so()(64bit)libssl3.so(NSS_3.2)(64bit)nssnss-toolsopenldap-clientsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.9.1.3O@O@O O Oc+@OYOP@OLODON@N{#@NiNf @NS@NBrN)f@N@M@M@MM@M@M@MMMRMK@MJMIG@M8#M5M.@M.@L8Andrew Wnuk 9.0.20-1Ade Lee 9.0.19-4Ade Lee 9.0.19-3Christina Fu 9.0.19-2Ade Lee 9.0.19-1Matthew Harmsen 9.0.18-1Matthew Harmsen 9.0.17-4Ade Lee 9.0.17-3Matthew Harmsen 9.0.17-2Matthew Harmsen 9.0.17-1Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- New official build- Bugzilla Bug #819111 - non-existent container breaks replication- Bugzilla Bug #813075 - selinux denial for file size access- Bugzilla Bug #745278 - [RFE] ECC encryption keys cannot be archived- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Bugzilla Bug #796006 - Get DOGTAG_9_BRANCH GIT repository in-sync with DOGTAG_9_BRANCH SVN repository . . . - 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #784387 - Configuration wizard does not provide option to issue ECC credentials for admin during ECC CA configuration. - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #768138 - Make sure that paging works correctly in CA and DRM - Bugzilla Bug #771768 - "Agent-Authenticated File Signing" alters file digest for "logo_header.gif" - Bugzilla Bug #703608 - Enrollment Profile template Javascript code problem for handling non-dual ECC - Bugzilla Bug #223358 - new profile for ECC key generation - Bugzilla Bug #787806 - RSA should be default selection for transport key till "ECC phase 4" is implemented - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #703608 - Enrollment Profile template Javascript code problem for handling non-dual ECC - Bugzilla Bug #223358 - new profile for ECC key generation - Bugzilla Bug #787806 - RSA should be default selection for transport key till "ECC phase 4" is implemented - 'pki-silent' - Bugzilla Bug #801840 - pki_silent.template missing opening brace for ca_external variable- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #771357 - sslget does not work after FEDORA-2011-17400 update, breaking FreeIPA install - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #757848 - DRM re-key tool: introduces a blank line in the middle of an ldif entry. - 'pki-common' - Bugzilla Bug #747019 - Migrated policy requests from 7.1->8.1 displays issuedcerts and cert_Info params as base 64 blobs. - Bugzilla Bug #756133 - Some DRM components are not referring properly to DRM's request and key records. - Bugzilla Bug #758505 - DRM's request list breaks after migration of request records with big IDs. - Bugzilla Bug #768138 - Make sure that paging works correctly in CA and DRM - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)           jgjijjhjftttltMtN9.0.20-1.fc159.0.20-1.fc15p7toolrevokersetpinsslgettkstoolpki-native-tools-9.0.20LICENSEREADMEpkinative-toolssetpin.conf/usr/bin//usr/share/doc//usr/share/doc/pki-native-tools-9.0.20//usr/share//usr/share/pki//usr/share/pki/native-tools/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmx86_64-redhat-linux-gnuASCII textELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, strippeddirectory&6DRRRRRRRR R R R R RRRRRRRRRRRR RRRRRR R RRRRRRR RRRRRRRRR R RRRRRR RRRRRR R RRRRRRR RRRRRRRR R R R R RRRRRRRRRRR xz2?p7zXZ !PH6 ]"k%vzוϝDu݇=_ź)QAj7KXYIօ9:^+U.M}rf8C5j"N1[2wːMI6M &ʵBL艎me}BBR T"Jciһhѿh@ $oǯ7yNXӨ(r;nɢpU`s!*x|Tx~LRiGԎnɊL nd lW(N->齒"~-5MA6 qZ^2EnjWOSůz1ZӰ{ꀳvkV2;qXAd37 #˘ݬRt`cF'vL85kJ:CH$+TZQO4>VDiI%kP봋J,ɇ0C˜u1"çd+\U׊b)hjG+T=M&<ߺ0'vRojƩ;d {PHF9m e 8\Fnĭ^`_nNyތ E?60_[CerH'3ZHx=鶥9Ox kڋJ{b6JCOyozcXB%nM3 '.uDCl >0Bw)],Dԙi <:Y~`HeozdҢ% =dn'6ܥƐBM8M_TбHxت\&qv)ac=qf~__:Q+K;9Ww;3"|t3,~d K夆i3/cD}xsweZl'Cry ڎ)tIu{EnEߒEDP Hqp MM0+k\1¥whֵ$8%\ih/Ump^XXZ;J 0]ggUCĎ3zS =n5%QXp]= S#dN^a_D )[?CWz&etm%BXq煱X wUf@"~L M:SE j4Ou$Oss%e*f+YHV9ǫ G¡#)N J} ˢu5c_] < .NrM@dOHփMLlC[ 5x@QCpX ȸ3+2LWR߂o˘}p &™?X~s,K~;)hd5`1dX_0.>x=[RJ@뤄ެyu ѡy$݆Uܨ-p.L+^˭z S͙W:9ȗI^ԧYI\ib| ^(:B2<,}.?1ֶY SoȚ!Ai: /Er]TkVl6>|Kynp @Ǒ,8Q~Ck .0P5T"]/`@gg,L<"Mp}UcYu3ŗ̊ JˡӚ˧Ԛ_Ew+IQ"P? {qsv)Nz06l.,hKzka/ b&@_* x\NɕnMe+V L-s PRYOr _TRH-)ck*ڣN:Qen$X382Uߟz6)bG[~5I"'M*ncJ]*-~Q. &YNC}K mG PR_SqkxEj3#fM>h (":*zhDHE26XLa܉Ot 5$[ wLU>y*r9\CK* Ւٮ+N#$scwՒ¶j8 -ӟ&VQUFïKiךPTܭ|SdvtPk}x)rk_2^pUW:e"90駡ɴ4~^RKl_W*λG^(}k[;VǷN,-;"@(1s e@t'|f/z̍*c bFޱwIa_(|kzԍ5I f;eqg9, =^/Í̢q4V}$!(M$ j׃)y&Y]F^0'˃FUl2{ףz+aR[z6ҏ|//ly/cE M$ 21 w~TnYf1p9MMm]Lj(W,Kt3U{ S9?#f9MV060|"x,s! ]>yTi T3\6a8X{q;)~u◖ZK&A; r`"2Xl.*~WlUnYhvѽssԄOx"a`k ѻOck?MNl8 ˁT%٣L Qqg| u(ľ#R<gW\ْW,,֠j`>6a+'!{%:l/"nn>bpO||vGH8z}nӋ6ʘ 4BZbOaͰ{$u+hFlv`sώ~w 51?&k#1D}~3~'kYTWse~s hIHD-m_PӃ. :1r>{ !x2"FE a߀sVXSgB3-,<KE(e>=A8e:惷tA37(-dZW^^JD>&jjM_iVY ۴~NM\$}h_YO+-D]kSܔ{8ӝj%Nx~bj!¹Ny穪8!D<sY\ALܔ Bx0SumnK>*9:VF~ eˍj[&"_RpbYFsuS=j'V[C7{,NUC̈́X&k` W,AI=c^:~W _5=L8zpm!?&^.< D>UF$K:*P@YŅx F wv$*c:Aеv)֚r)t^m}` }_I`5 <YNG_u3qCVfUEppDIJ;<^0ObXjJ*13i-Dr*eVb7ah v.J+`e`D b\cgff/ePg۽Vrn,K3zz[W} *X-S?`Ģxu*7+χ_V&zXH/䲮K4JALY46C0{g(j 2C։~i*Ja]|hnw-!zA3/kRpWv?ý9cp9nY0 >ȡ8:$gyFI[V-Roz'욏6Ia$ o Ms1(i7I>E=`~{e1-GdؖnL{@pM/D`!,uͅȷ:Z4T & y!ݯFG蟢 a@RϵN䟲 ~hxE<~eˆ4#kJAQ_ix@mWR4-;݊^P8eq2/boAe: I~6@eR\:?=P"gd‰]K.K1JL꯳N/JOnzIM9TC矃׫QS_k}?t_h;S5W6oӊ Qb3.լ9v3۳CnJu_9k'" x$ɚ@_z Xp7,$[QX{ ԤtbS]c!rюDZ'j l!Q~Qoqb7&;]ChQ0PR[*m{'R#/ۊ< EMq)aR*a7̂!a_.otpl:ILj_&Λ%- ﶰAeҿd% ఏzrw=,n1!h|`0i z/gOGP3h|KD@F>1|-I?SV€>hYqLcy:Di s'tjw*rMKzG%Q0 W9%%e]?NAn:LZSlU2\%ϳ:$ BOzv7e엧XcH[P=CE+jNS>\={s;RMG(irJnc)X6UZ2ÉMcSgL<\T7fȔhn+x'BI\E^Ν~@ PWoÍÌ501袆CEF ^-Hׂ|vd=EHVNKGg uΡܽk o~T3oNTΆWׂc S^g"d4W-BΔ3;!Tw=\xύP GS6l7w׉!)(o|ǰ,jDޯGu7&[AWW³WĿ[VҾ=_uB]W˖P0/8Jդcc9%,DD@~{K*Q횗W47V3KtBH ve ҟg`ȶIͥGL|`2p&$W/Ž ϱ]` :*EӬD/S#]HG`Z޼+<)kGP?+c;?jM?yqR: Ŵ4vQi]IgS7XH1,ldă WmmjbãzHcUJV7poKΕ]-a2 E4ַs~ҙT:tJ>rVClū`\|"ŭNOɇvf.g3e8I1  ֤Ų=P)1R&KHpaڞ)G;yXLʴjTiJ$sTy:F%$ӌ$U< |3ƛ)rn>wuU>xcϜ ͪȦJ.]w"JO8=U2Jwz,čqҏj 0oXmƣ2#B:*~3(ysCּV^uu _ ^OaƗW.@!Am Nu6%YLW7#̙]<֦ߏ)WvZ _ S K)0AE?$t9')[,Iljrk.jɊ/pnw9\~|—[b-JvABVId3xEJ&|l6 H^wЬ֫X^@aڰa{uhm9ˤƚٿ;d }  PmEzG L:6A]2ȀU>T_7>O|i+p}x4k݁:ݮ>SX:qAx`]Ie/h-}⑳ݘ.u "۱fD߶~-6nCÀ}dU|^DĠ `=Be;|@#&ԷH^} |8!)&McQ&UV 8٩&{X; Tm YJek?vg 4cmTZ"QdJ[~$XkWj0D?|/9^$zIl+QlMv[; cMlI麣- DHbgE]i[*"A$GE}̺.BmECh%q5W؛?{z@[׮e#" 2\!mI `D n+u 9~G\IN5ZB #i&ug }._4oax}R8A~5/g+-Er6Pa Md5ZUF~।[SNGXn wGt0VS\YPT#qRWx/28"ɺ,3myp m&D(b3[ԚdNgTM4KDA=rA(_MTMDڧ4[K 1b4݋ZUĥ?qZ}r{NKK9ң[yc>} 5hr_( dҚAh:3oj!6Q"'&_aM<`n, y@{8/:L|<;_XXk1vziqA!cIw@B=,M=`p-RN<%S$F8ūbc2l>83@ 2H;3޿qI'=ĸ0pl%_ T'P  T48Isw [5ة%Ifr^VmG:O3di͝+`N*v"Gs\)(@0TCh 2D1[Z rwԛK'<^o -dgOIkwcZ2Kakg=m4yL;9gWoLS%-XkQ  Sc–94tz43@GkuӴAAiCnĸ}4WƴXLn捎S;pW@[[IL0]o^R dEF>/psGAƂe65)܀t0l HT\gq:3&Q n4 )1t8LP J=g'I"{ (0ܙ&Ё. tgk뱎Һzr=_})BS1jB54Lc |]C6zQ< J/M b9}fu܆ 4K/= y囆2 q!F9A WzÁROXa>ӍKm[΢)<(5V+ZQҴxjZg=$R{h%Xy0R]xa;ץfkCՔfCYӼnz&!_PW{yL^.ªCdd g{U,X6ϭń"lj*;zZcYIs ߩjr_h {V0Bȱr5o#nNq| nГcsYzIy +٠K0k9ė!Tj{sWG1UrЗd ש0,Kka. OCReMo)p|l3t<|Ж{6r⇶Ћ8m|4M\kg&͞-r޻+ "9QneY'GSt QiXGnn#VkDXRjYE4$ 2 T{"fV#ȸԉEF!_qsLM0Lȹi'.DX61[ vh,sU V J^&BF(vaɫ垧8v!vEsсg3p*R)%L[n̹o: ((d"4}H:Xsݷ'p0M6P"t[̾kbl?)_ tXc~/RBxiA?q7WLN,TI5#(M Z{ꢉedRwcpWBαS]t?hk6AXk,i{uYƬD+(^\-("2b"A7tZQ9o/ LM Nlʪތ*Aҫn07TP.B+Y_ҭ?'\K, 5H-YF}Y[} ܣ!PTGom/Di.9';ŮϽ3JN &؋Bٙb dU*mkة t1RuF ]>՚tHkAGB(W+1{{W{ fkgBW×Kl/?reV=;1Yf =,*`= 251#^rY-daVx=7 O6#Tȵ~;zfw7Nxik7Il;C, YhpMX-f^CⲠ9GX,g uE W~а6_jK\,ߋ =#LWQfFșlq(aM%^ߴ%A;ձcUe!jKݺX^g"mhE[‘@^Ͻ ՞B4w̼F]BvhH=ğ }NǢs[ξUyRN"{=],ET:AcP`Oy&%σcq:ʕg2ECÃ*Һϊ{@M3Lkz9cex,{g_]翉 #}DK|ǩvy31\Bc.Ԏ}TS]jU֡s&N 9q='J^)Hwr0?QdG2ӈq ?idk 5=H %0 'rҮI$^7wO=k^f)LSO ^S3СmeJ3WJJL;+ҘE|s\hױ /35 =pEv tmڴlLn{+R偅~A> hV0cC?+ _B uTIFRk!AC@[CDgٌ_hX2P =U[zb{yI)(5CDJMkYʊa 08ȧ)JI%Y/dD1ߥؙC %/XAӋ zn >_ `~BvC ߩ;cDdYni;+7YzFC-dƦhRxD"lءDva&1';¬B"#W#Ms!a(ȑYk r TnGKBS\Y KK/[m&ەf\_3onF4luEXcP2f8Szɉx}.{W5w]_DK2d:Y! ?'Uk5氙<+2)PU#WA}yiURߚdHw|xޣZ6$w`&|CռF\_m_ɒ!OoN$#pA4^,>lsk#89QTҍKy'ά$ SN}ι{/:dlWpvPV<s0OGd"ْe+ۗg*?MHJKz|yѢ Hv:;qwUnT$5()_0}mkS:IkZW&T9^p2y`Ao7vl kٮ}(Sڌ{L-X"Sn\Tí A%U1, fλ< ^ fT8o(kGq[pѕih؀1lPa710\x Xt!kiXr2 jv#ɓ \|b4>yKVnE:0ԆUv칣(HPo?`  ba[&Qk%I;-Ҳum a ni8{ZlI!.qѨDΉg+U"Mѧ5> [峝4~1{FZ.ݴ)GdqRψAy7 ,4 -wYח^$9DM!-֘A+gICV{4icPxQɶX-Hd5ةݖ*P-GJJ"= A܇yˡ CfCSc!/碑ʟk?3ϾB >+*s?yG;5Sl mU2a u!N",tBDTa’vﺃpٷ 5)VlHR\CJɘ]'0y.sA:؉\yo)C$Z] {Ǻ'78U=`98N}TE8p,@'Th@ c˺c]E.] SeM͐xe~0Z}Fn+ mG싴x9TÃRJDH;0mn!90_埾kH+v)YO{9| E$: ߛmRk3pfEtjz{6=C#camηo*-o̞ ﰔlpGW28F]ު5n.Vl V3I,/% I.2V|a} '0j|;u6v|sC[y;ϯ"JD3rrr :bYK(gX  '@?C6z=e!y#] ߡ]tE@T )IV>N,T[ 2A.s 1k4#Eھ:hvoI5qG&nB^Dc2VjFK,?Ʋ,7ii7i ͪ t'Ui~R]+0:فyI0 hW !ۧC]$6)-{nnX> VpژYQ5n!SkA?9nԨpP^ i9~Z\H'8i g43)Htpxf\P\ɟXTL ޤYdHKb@3L>;J 7Y=K"7r)-eObhHcrJ}c=X斱ox᫿`ee>T&VsZAjZᾑxAˡeD;@5h-טOȷa"i+y649p@o}uJk3w*ӉdwR]cڑ~ui}!ø>!!Hlqic]ƒAs߷qGR"&qNƌPb<֌HpD1Z `K <5q)gȞOSj7|PhĺL7Dp) Ň}kY9JS TŘ)9|`^/!]B]C68ڝc.?O]g+*l`6Po_ač6ٷһL3>Jϝ@$ |$('DSYctIƠe?B+a"KLiıKkn$7 @SgQ@sSF°xr.;#C> |¿m('WY3ѥp0J^el|P=K@TG䢕}櫌…F'30(^͔E %VAe]-^*>^]$a.^ 1;.p$LB08ҳvh :>geu4aS({ eX3w0 (r"0a2t͐ 0T#Q"՟K߀́X!Е/J 饗@p冈@ڮӧ7j"f;QgX- 8 *WCE_4T~D{D>? orzrNFyRxDa4xBЬ(LYZkDuU;X`l N96ޟ+$yc,PΦI0wƥs F> 0 Ou4d{@+˚ɱ{'EPй2r(YL('V:Z6m;ɰ'M KS Ԃ &B+}A>jwL$fnP'e:`7E_AϚ;w~¹^ 8qQ(y痏B%0#BDs|M ́:i|ӧW~t$yFMfQyձUcM+Ɯ;71rXx9ῄ9Y1v\2 uRBO+fi9i{~ ށ'epw!F,VBXp9]ZB60#~RSҭLhb.M$x"dbZ7W&#g3.}7MF3뽯qL1c =km H;3;JBFLV}uV5sA.e{~;3n;fj#.,oo?HEQO}AC ̑w矡:tNJth+Ł?9S1݂IM$3tó;^n}ypd<Ȇ33+Un #AȋJoDФ/ QǗoK5V𚊠z51O߿qXm&v] ʹ6ا6Z~Gz bbBD7BB[HX$Hu^l/]+>syE^=V.W❧P1|[[=QG{1#@?RQZFFwa٦*}àXOoa) M,8lJY);HBJs! Fv"D6A])O8IdbKcA7@݀HRuʭ[(3#d S/&9/g:փeCձ) 1ң{z]᧳i1Bjͽ:ޠ?qFVgg/$-gP’ॊf l"cs+_?!;M^ [fF9V~<cP3UWFX^=+QReAi?X%X(G*YFZy;r޾YR$Xc$ }>e.jW5Mb)d 6y& ݦ7h:#Hy %Szۿ s <}.;j-eEsv/ Uxy gJTK~~aW뇃e{iA={nU26|!W|A @8+0-Ⱥ.YsKTw}a{.2IAXI)է\F2-SN2\)0F~ZS~"929ދ1ו!r/'s}03Q| 6ZVוs~3أR ?/R3pqec`}}oYSg!*Vк8r;G&jpWCF#y.&IHOVƬeUa@Α⃕9埄DF^1&Q5"9S"HVsߪ5/iVN<^^b*o.sh",lW#cho4k;s#)? |k^,'QЄmNm${87=?UMQZyWKmѧr +bL_ٷRj8d= &0"Mʎ`q$S:dD9!e/3&`>kF\bQSaP[3"׺)_H!i(iR rS]5ZE-5RڿP*9XojVV/U^(6 eH?,N3KM5Bf NKOO"I ab.W=񱼬") Zr?8=] P<W@Lu{A0Rn`J 1Q-N#N;m'(Zb,I⼐;8'3zH&h}wĞbJ)vj3&c%0M [D_ݞF3XXF9%8>cN0cq ׬iR7A@%vBcR>_(׆-qᣛ\1H zu*{#cg.2>#ĺnW{jш5 b"6-. -o$+ 7aL/`IօqXEߑ?t.=uɚSD5.e伬G7.Xa\KeҀ*uBd Q.h.J"j SǢ(? ƼJz+]RXZ `q׉?1u"Wy ).~ G%1%L ֗f!:˹Lܞ#_&P?'4\KoCi7_r1E7G![ou?dmNݷN󬛍NVJ4:yCQI)^=a#30j]uh/{#֮`)gD F֕tЄR7xrdhmKHVjnCxsm)YTE5Y O WW5Y|0w:HpIidR4(*JP,Ԅ ) t„ ڳ(^c o\xuXf߰qW|=l|N{>mkEih>kЋ;SΡ)JK+)8"wi#XRy4.F;6;(Z,*&I9&qF\E"WB,a۟mN%#sOkv7*gXd߫Y>)=U:n +\l`v%2ocP-UC/\VkZF?z,f[HEU޳SW9Q~Xe(J'_ʐWኖE%on0V5pZ;qpJ>k,{35jCqS Tc)y|7Z` ,*qRݓ8# 6~!cZO`v[$ *>8S7;'h٤2BF6tV˟*l'T+]hN?p6?oވT&#ٽEzG/n9%ю &Iyg'p͜"A'\µ76o`2]u_i򚺍>:DBb7}/N7bA-z̝Fx-E`E`D jaRZ;ⳁen)X6̟5k _(MQEVO5@7q1AǤLM݂y'|qV@MpN-Sd)}gO{}bx$| Y`wLHj<"]NK/oPW$a]YS[܄ oB(z5e)OrCq#[Ɉ|+:;1:. @͇ſBeMCyyG :PQ-5P4]3jAӓ5xo(͏lsm1q"IOpwIMƝuߍ+ΨMaR$f:͢LHm5 50yS_ ~%j;t/%+Zz$ºOkuN(JKV[B@ӊh UKn}͓>|QK,{"yն%Z猾lq$/q!g~#wti2oN}z0 q!xޢtѪe哠]u ÖϹ̶KXw! mȶdkROUݳ<] ;qLc DDroE wt&zneq"@g?.4i<3`{}J+tu3z!& ]Hy%_?cLIUI)>6:vW7KmvNp(0w,XTlk8!)RforNUCNqI|ݿ]b d2ɺefB4@ USI~40hN[ڶkR?-yb{XK{ 2\ ̮x*XBU L/.0 t-2;oZ3vP:=Ql2̱W9{)d> juIΗb91쟯mH{fg*pv@cX0-"kAGAnDs645l?9ڬ Y-m`fT#D *nOE&v̈́KvM Z /a+AB0BZQ^P5=,$$Ulo 0 e2p"å@z."R.:=PL n -^`CQNf+bInJ8=#]dԨ4HOIOH?J!׼RmW~[{ ?KWb$6J>1:ܯ1m5p}^]:ڇlO 5.8^n(.7Gȶ:R8?V6 @1ܝr;{yuI4LeʐELK2y3[~]݇Ahp1S,ay]n}ڤʉƂű5ct. q 栘?4b=rlyɥPRBdV[riGc<69ՍՅ9@r~sg2&7(ZOQdFG8>C4rudJ179xE*ys_JĂg@t~ R{$O2];ԘϚNx' s{[2Z>&^yJx|*3QH謞[BP#ۛ{Iv*MLx*k0q'ʹX?NV`#yfkXG䁻~n}o% 9|\ka]x켯vTN`YHN 6g[dM}Қw&[ϻ VqhԳ:j "V|fF(7/Ϡ-@ S`rH|9(B cju >e%%a8JKy#7%Đ cB^/0:3.ϊnpY{qNA~=r*^/NBX 1x ɎJY*sޗ' ?௞`ɬ@4)1j$PV(MxM}߾:j5g7iyy'Du-B(J-2[W]Ff+*)se/"znNG&F3,Qc -%5ˮokb ,nyv E:'35[P iF$P@6$G4d:=4AkpD"Xb hP[[?#ٿxK͆]~*\.b@|g$n -ap|KMកKz!6E;C7 y$+,ekxr]ng>NQ$貕izsU鋝_^L ıחZv#{~)6q|1Gc :sг%+G}c'$U$LfFG" kw1ôZ+;wv.=&\Zu_SIcb= p|w&V#3D}zΞdFMם/^Zpz˂T~mi3 C*q#Z% UmwpgS%.x jDUX͆#Unlc} K$>YiB"&3iz7fcS{U܉'t~ݥ4utnչv\JkpISt`!^Sfjم|Ss>/NG.:OC'K䷐zK֥b@蝦IZX~=HW!d4nh{vɠ K#EE]'*f8$Ù.I?0|ħiA}r2TIQIBDAn{LCwwf?_-N3 hp!Kt٦Wb=3Ж)q6maEZ`@x4w TL-4b UAh͠ "S߅ƁWkN(/ij`~&w. %sꂘ>Hױ^+N>Ahw<'<- 5 dtt2j^Er,6m\JC87 WD@r5@DX_۹&@pݐ9w )#C$jf5#k-|>%?7C:[GɌ&*;|F YD;@w3IR +%+͋BHjÝ{O c|9Xޟi篳&/FÎ(#"XRO :z3wQdpulJ9xbb$[wЕ)K^,-Z$ 9qyxTOsՄ,13vR󤞫_Wk 5)Z6d[FFs5w9[VԜ9K4w)"='\沵Č\A A ̤*pC \]|w MG+:Ї^:6Mv&]^+Əuyw^#͍u 쇽Cc^Ra[Ra&UL[kв<,tFFfG0sFsP*ԛĀ&~.V2Tzg_~32C0B&բuةn"8)Z\R_qQ'HVˡ>ƹ;8pVEۀ&\$z+lɽ:fZ &;;NuF =`6r=x9v|$eR]GfuLf} hTRc8iv3!nf+5FkeF0a|W*TѡVXExKSD ym6^@ QTލ:":6˳ņbcYRѥgXbD.XWf:S<qK@%g1{˱eTWc=\6!+1%TV/;oze0ZrS]gٕ΀!]x1@2=AKz/0ʠ[BF€E~Lm>"c = -aDApM%^o~;UFQ6fE5~wyL9Im :g 0ECв#%'fx9QFv'VoPqL;hQ5og*kuK_͸ 3`Ь]+Ait%eb]`N#3"!rkgϲL/'.u6}Eֈ\o{n/>dYOP65^^fF:DòrKXhHCe6i*?eG~xV:8.iHL5³i͙F~adܒ~pXcaγpKy Ŧtɏ{@~~[.+LvR@t/$ݔ~vڋ}F#O(Z~{pCZG3Yv5^=PR&чG3af^iPf7$z̍gnfY7Lw*؆pVsUOwfC`( 5veo,,sR~MRcl-K]cTM6n³@eTh2mf\^UFM") FqB@Ʊ@HGTF $&̲dLH8Rd<hbFW((B q;U2)Zn¶TnLWT{Hr/ ؘ0/O ħaz &'áX.|3O8vξ>WC,?TJyȁ)Fo8{e5{I%j>u0OYG;V#7$1#`7,sקa70: 3%brHW&<-/AT`Z=!~aX= <3}D>=CQK HoYc71I#`\I.gl_P[Q[QRTL1Uz4D=A&=!]p&Oy^ ">/QkFk?.G <ǧmrd_$Ј3 TA;/iH{m/z`mk1_{gghY|9߁Pix Ti&sW9HP{.w*+tc~m҆.$*eʷ^M<*2l۰1JYXz[椔>Ij̯RI6 Bˆ=Sv 7G#}L_XiHVN1ڕ;!S45֯LTg"=Dž<-;VZ&M [' P ɺl18CLD0H+ /9by<z'N.i?&KM uec0Z F-ajo.<<5=Rt-Խx\{XJH^oxjs 閣#تOtu㌀o!|M~"7Γa]w!ئSj% WߪrF.q^(56pI !XrwNI&Zc,=`I4/-<,8~})( JlD|(rSr%RdYi{ݞvD1^9?a{.rVfey?x_$|6bv"g8 kƯkK_WU9pzB;'29 2`nD 3o$smo2MI1UPa'<(P pxyol,Ѹ,9 !F۬dS҇NP@8g1JThKV &zҋAV8ߘmpB{ ߱Dw:"{z)}f\ Wjf`+R@2:e4֠l^R@q'J2iuS횄rQBN_hǾqE&~ R46l7x}jx*hǝ;iLW_? ⋧DU $?Y۰S VEͲL}pHu_h"fK{b8KaG{P f[C'š%t()MEVtj9%>Shh.XM<ȵ'=p Xp\̼@U%l5pmPR/`PA?Ў[ۙ(-qGzZ6\ށ2GI\=Bwgxɦt5NIIC!De8z&4]szK%7++mSIen(r L Z,Be,J q>~tz˧%j71(u\#1,,:nAMc=9YetoPr!$\)lk0Ҍ! f8ŲV!m 8:X__n#\֘wn%|cc<5aoD-=RT3Uy ͛T]󟯖jKW %(yq'&ZCz1!2xh҃Z~+| Yz $`2oy`4LcZO8"> 8)Z^" _O-4 yRhXy!s(§[_I\k`% nȉ%X]/#OY[8/Yyzd\za۩?: \.;^ S0zC(ɹ2R,UTJ8.+j3,ϗ]L:f *bQh @StRq-yߐp<%V8!jѫwa FlڀϤMp NJUN!977ԑZ ` o˅мMju (2WH|2(2$zN%ؗk ;3!U@>c6DHnM|oX݌(I|DLY`NpXQ8{w"qԏ{iA__sm;Oib?M_ZM%J ѲPj :-eůCcށE$e.LB{H@èI(f+uO |Fz{HpuBaZ b5q}c`{!K]O"SuڦۏF^x5\d$2ShʙJQ=R74^@X:u Ǚ{@@b\GhW+:sqYaҡP \̅PNu=3"|㨱g-F8:bw]kh1-Pi>cSʘ`䵄nt~po5zܢȩ/ =4oDovEQpGGf- edJxxjl QjJ"$YjwJw婗)ZPTPaGM"-]_ELr34S2LhLW w\vxjl0uG:9ZBոW^4ĦmFNC6`8_5ֺv!jLCQC,-?՘ϖ:Fg߭]W@$S}K'?yR61wPI3A b+AM@qخ{X]!U#E*7©^rA^y{ 3I kTSES~CrPE'HtG3EP3'4hu2ѣ:[*6U87Rޞہwy]; m=ٮ86qmw^*9< ,Q$=#S'Wԫrx?=J&;9{[IZQ!xI/mm.O-ϨK(S3- :PK+H&u}bDaT e"LmUWqSrdqJx%vF<&h;>a u7xDμ1L+@&0 w>#CЛ+I)e jGPK .uSI2/f  ~NxYWL7r> xE@dwO!(5pWgrThze:p4EljSIZfVg4^Pdj0gy*dC]zѧݝO2jF3zH{9Ph.R(֨9Vax!JW,}"X7MU6L]0 s%O `OvO=:7+27%e W"OIFD* o6bG` g`:G"4X HzUB ƃH]̄v p·I: +I) <1P|%f32_WZ j#Yӏӑ֯:Wm \cth 6>f-nʯ;,Cnm TXa II/. ̋tA2&Uc4uО[FF~v|ݹSn/,ʏv= J~(?dhQhm, 6T4=3"<3U ^L5^`%uD`ȉ8⯞,VcpYՆ fy<_ҩu@q8HIo1z5gE]eN 99&- f`d˶xU5'ҽY.!An [_CgKn<,{̲\a LJ 9Bz/JBjȎ0T.vt[^ S>^21j) 'z?$籓:'^Zf}GrFCU`Ta:>hv:|Rȥ{{hTt쪲vjvIit]_^_~E=׽`E 3㨟o1q|R Wx\<}i+qJrcK%1#Xںk/FOA&  \$VX1*; uV,=7Uc7q1թHININ=*_jw H쑙 76 v ޲q67΢ZpK Y RlI:E"96>SH""GDԔv*a7EEbEx+2$Q&+v VJA`ԊX#HuSdyCFq%ij&bhz@ӆQI>/|#/wwH vxG|UaL g T!C"b%RY3xDýq`3mߞ_ ҭ2Ko#/F!ٓ7DYKYt!" -~|}e>,PCgyj0gV POy=tVzb/g:몱EڻHҎ4|QX9}K{]5]PDA.Pk-E K 2Q[8^bs?Z`s[q!^:JU[*-_5@MDj[s-᭱ ܄RMduغI?ūbIL5B >>[݅qY&n\/H58u)5Lpi`N┵\Xbg]Sq08CԔJZG}!oFID[Š+Э[at qR,9fAr4mP`+,-V8V[G{C7H/xeD=gT\}vCIi80n]%ʴdꑏ u5p+cXf1q+ʹkub)cِ> CZ> owƍN>q.L砰oPWpEJ4`)mhݓCמkO ~̤ɫм -'LAn!L ]Mf:ІOJIJ}oo$_.ߪŝji v Z%")!Y1,"-rVF *|u6*m͗4HĖbXy%)VȢ秒L0jmP'[ )X% ݐEG??5~2Mq,3>S@%.*</khSZ;[ 'Ug$;= 1-Y')kM9nG[ &:~,3C' cxyЂ 9?ݮd#SY5hp#c1p]3W)HDaQM4ņE ^(BIL#nk,J%ֵIP  Z9e|Qmml`tNNO\i5h~/qF;v(ID*">m.,ڣ h[wDУҔmqJbE{b#Q2mYeBA2FޭjdR;rM$. !j8؈/B·ᔕUyesn0-g'P M7Naz>#\R`: e}JqkIEZRGw eX:EAV:KSK ˛s%h14ܓmq,?{oc9g3)WdfX Pңp;!/'H#%,zń#yBkd{n#B[h<*R7c&T\f,LN;EamF0ƒ+h7-k٥_5Vɻ"ȶ*ՁI_~xl*2n}g#PcPy9 P޺K9mH5G8q8`_ J(B&LoQSX`֋P4ϖ4s7Ð7wC.v)έUOZ.$=Aۢ  c3۽k&ֈP\*dԖÆf B0r*, 2gf-7jɠ7% *pJvm6LZ1hRzUk>3/,k|yА wV٨R7I |^s?`y?-O$ :ʡeɡ1,t~'h!]ʈf0SyjTtG/_$Fnl,h%CR" @-tgȕϐm8oK+db\ 7*aiݾK 0gDM<s9ư>ѡ/7U[Y>X(2ZK(iMC32+EH߄ >_XVToPjD̵5l/gvsU+ QHs;@c\geɓ5?6r5aՔlm# u%C p}WKLWHαs*62RXN4"+U4{ Lk9ƳVG|O3ܗṈ? [}mL/0ӿ_m_įJ?tP_0ǷC^:4@V4sRZv.#OĽb,X=z-jkqd1]m`f,vd]q[NHjj̥J-lW305:`_<4>MEغvDrft~"C~MG=BYD #zJB_r˽lvקTPWhbdK7`7 l5j t+DHȲZ],}ʊ$n=l Q'-i >1$.QxtDTm9t$TLT^;˝/vޘba}t06tE+#(P/n\4{=Tr g0ш1U[zz `{q3mho3Es7dW1 %4[ku<. mze_K{0ٸO[fvrco_# ?nx_z܃C~^ԦuC?jHBμeA3F%f d4p&m7\k[Hyp5j Il}$Ry%$g,c0KEƼ@5N7{d32ǒAԩ˫zK(K%L`'9G,9:Yh FGc|q;ۇvgm MZ 8F<20H ́2MvnGOfic2@JXV*S9DA: %|=(P ?\5SJ) mQ8l3u`v"О"$}q %ݞhǚ Tc>#8@'MD>0&% F^ޥu[>Wp_=-Տ Ge HC' zÏPNqZkxGm"b.}wIW=17aTtH}GdFG N#S&t-^ u-`?:wTi쭶wŖȇLv <]xBhg֦SBAWHeƕhwzb1\ll/ 7PmIٲgiBy^Ej~j 9#IoAy-z3&}L^#(kjh،Qu5LG G({j:sx=s[lQwK\ÅLt_Bss\ +ePd7@S;x,Pij4irsA9\DmEL.,:z2Dܗ1{u~kdh\`ATఌ l'Z~[뎴ꛍ7|E$^$We8xqbtC}C*J3_"E9O/J!2oodv"qlR~b|4aF$/`)kأTVzfIϰй8ӷ=ݜ<">.0y*GdhB~" B{*obd#$Peu+zlBhZAq@*,;u u{j?iiqOOt1+p6~:<*YdƢYJo%fNsh^rFnKEwiyɺT, Ľ֢ {{͐VE>o6j ?^*խSlԾD( -3& 4(yiH$Zz:pXc,!t&?)mҀg<f*7">Ci~ž3(,o )lUW>j{MPb}y!Ѱ.9$kUcTWi3Pem*϶(*jE*Ǣ:0lAWBIktjKnA88v1VV54"ɫ Ο<:'azR܇ϭ2GOĂ TLs4tj QR:,CRcŽ@pn%AdFE;JVPl+˗`,XMpv\T;Y=<ʱLZX륫 k)ʙ-[ TѶ2F4 1O@~ &$!lozĠE"Q* ~ҼA a=\W$LOΠՏs em0#&@(xӌ @2䙡mv$gq=�apDe xҌLf`/ɃQʦa!Q.y/E63.Lݤ\GP8~-$s喺=&k0\cZPe_3k'bՉcDdxNCG2^JN["n*̈́%"gSųϸ n,Kp{W&Gl(>'t2|OԁanVT 2kƄu"@Wɱ~G>5Uy1qG ̟>ܒQ=a}=tXU`;D ^RΉIhV dnBͱ6?䡴-wCkcy#ٯ]XSg Í=<"z@]Ķ#7ת LLX8umE4X[dBVK4`)ۻˎlĞF$P.Bb@eqPOOi'B޾?n@߅qX0fz{Fk> Y \S^,WN^UjT$)jjHTJ7X $\ ݫ~EPa}fF99,MUwݡ)4BuTaI!a"d4tJ\CbyDU\~,A=-I`+n߃`nzx/GeOpgňdӪUͩA-Hf#LB'7+}>JD/n&ˡƓ/(“'A}v8ܝg7B<nEh0Srlbї:|"f3 ns?⼛'Y c§pPn]!5+сYL`ijvY89^PҒ`8ze# 6$ZKf%5 W~su: P:Ojg`ҙ5̄j^~Uv3H5;!t< MPG_~c!OVnŇū*IүcN;[_NtAĵa84^PSN uwȎZIc€ ׀ (yz9+4&i[QNQgB]:8*˟{m~Nb[Ԁ?e^I|Pk w)b(]Uv[-ڣ+0ˎ x$ '~$tPθYvf- ;M'/nd?ܚ9֩ړAf}S0֘ۈiCl|nmji *offoi<_H1RjmRP+%T&v@ d$Պ:* Y!qkuYT$ ͼf2HS`qDs Wo$EIAh7d^Sx.U z%yJ,2RK j;쨝VmձĤ͟\N5E~̳yi1xU+(È%]1CŔ8.>~~˱cg" ^:t+_5d^Ih!Z^Ăw ?#V I '~XdRwu<i bc\Auy[Tw߳HxD:m}/\b}U>AFosxB9o$xZqY W]QE/osdw234S,ެٷ>!otdoԗ?ʏU p7Á_<*]nW[6Q(,9NS40M(*X;״+!F@\5P@IM>Z\\!}M1r[(zM@P}ZTIB&L1 'MB^JGS7M$YDeqV2gdCWRa>l3Z@h;$7?h=ٓG蒭s\Abj-hX9Eқ.u007F5nrppʆlV^єn%e9zk/_o l7f`ԅiNkэ~:lЋ ЙV[sjjWЦ#~A讻Խ]ͰEF!F^vpQ͐܌S֔Yhڤ6Gk*|ͳQ2/vT9Il=@TVdmsp&F/dXO#}I` 8]rԵE ??ҟ][!\N~J.r^i$trWy.'.}Qd`d Z4?uLwlL DEXqj,dPQ5 9N,޺qOWJ aCѭNEb]yDp8qh:L!FRҗQM̊x݅ 3m:Qꢅ9u+AhI*ۣ!A^;2{yMeis,h)w jd8`+k0jfH`G)CΈL <4eS|w<>E7 if~O'3n Ze.j$&ݨVL{Юu[ƫ p-&U%C7_CZ6R޿ ʄdu MէCԕ [G-ofל?h/eY[UjV-M^UDRZ Z7*U5ظ EvC 1,뉼t[]dU F 評 qz50(>>:^j6/I%+a<%3]B7k~6$q_ݪОqJix{jDs~W.'&&/^@f8Tj1ȯHD i+.\$tbq;ޅgS|D _VoKOι' /3E%p¥!Ҽ? ~I9;Ȋ~'e2$e fq{n:޹raY_1+5)Nd.GU`p,a}ۮÊY~[Goi-RFН*66&sP,2>g ]ɦ:h]k@X%i.53^O/Q+@ZNƌ8SJ L7 [˽jوbS)ܯt/g`!?)P,^+D33p~S㯣E ^nnՌwc{Bk`4cA]H%i -x7 K6Ea'nL"Y:S\+ܦ= 0,M,Xwi-e9}B~RDSVL Kwtߋ힥΅eH"erF玠,(Bn›&U)#IT,W ;/C"s(&fj˲zğdN)"4IM諝po*qny KI;+sFrpABՐA>0;MTꤛJل.OCvfh%װYDQP켘C_jp޽C3 65$pcPta%zӔ7Z6+XmMw SG|w`6И,|s5uw$E!j sy! }pY-jL|LP ma_O%942}b]%JYğ\`;5*Uh9?esiA.!UptMHR{r`YV/SW)S2=iJ4|pKb i|. .)mz y 63i7a4ܒ/{4(7;M!0dxHğo8̴Qu'€I8Y)7RY؞yuhջv-oRPl7~6Pxok9ܮlo==Aj@˒P=Hq -{|eDϣ_b7qOv$PQwmfL BK\q3kqpt?r/Xd;BˬVt@i೘#ճ}࿕W列zI1cVTlWy!A?x?NܐOCO(Z#$̪uﹽ=ۆ8Vo%{lh{_[Jᚌd FK\b WnFc5H'ք‘eG]._yaต"?Fyɥ1i? ۱ԂHCy@zÉ׹s GsQpxy p rtԅlbRK"[79 z^sa_|-| z~vF)*ZVG_}7^)ϔ $ffn &Mq|?R IA[DdPU@\aq 5uq,E+J,j_VlqE{;^ӺGZʲ"NSwP`RVk!~d?1Os=^@^ ]#ӑ8alm^}Nt]9'A6/JbVCd`hncwaaYך.b4>`t"[]H"R39#ǸY2F1ܷ8'bKl⑷9_R>0w|uO6{VdTOdO&Mp6C,CU /FkclBb6W^=1D}SGv%Mȫ~Fia=!#_td!=]ϺP7kAgLkd>p:#lߙYmOR +فN0.`#X`y Jq.: D͏*`J!WaO4mMv8Ata&n!gE+&) jUrhmhSWHfGeY[.J@-\ R Yf෍8Lg֞`4>R4 2}wD̍C|)9g!R,q3CKA{tqsS.Tm|HzPPfK-\6E̊$ 60Lw$М={?dz7͙YON.u9l%mĥc;ZdRib%!` W!b`j[W}}!6M73rD%kd+)!I3nW f&'VǸ!)eU U O>zUL5+aT@͓j3J["@=G1C8DTRh&H \sq{觌+O0B8v fZJJ}ZSYm\zЙyA%{4+.@O^EvY++LF/Aro1iҋvuCMɰ{%߽)-OȄȨ֩jJ3seuP\$( ?5!KCw(<,Jõ[y,m$&&hJIoҮ&8ElB͍9M]VԫfJV; /Eۏ0|a|'R}u\}R@"DMEYA7!V?++o$i$ Oκq#%x+B77xm(tZ4|4>e:I͡UpQMO|}\A=蘮ue*Yorp}}_82먿ȈۅDl=ooS3Z Kaa8j0cG,+077=FJ)OF?75HCn))unn80_pY{kQi榘tDmîH/LGD+7e崚l!W5atyjP)-j0a^ASww9W#ݭPhL󴗫nb]~ k|1|3cZ˜ r^<-s : D1}\|rR]X%^s{@S2z5 bvyzbá0M9 ϕ_'2"\| z4heJXd9]kc %S-QfEj?jsT"bK˖EIY&xƏ|LE87mbdLF26V\3q>}g}!M-G9F$D}{^ggQ(r ߍ 3JM> >W\$oHL"[9WLj{(_8Y %EP0쭯̛1-)Mw|ό=M㥇߷t4K^xF_jFxh#S{]wI^~'ARbɡMI tjo@;?@6swBu hsҚf%4vSCiz%3DX<1Xuvy Pb2iT=yOWM?ZlLmv-5$: 7dc"8(uɾPA  y&}e)Dnʋddf!l  !#&Aly~sĜLN,%4I|"*Ώ]6~+CNuSǞђh)q,ןel&+4*$5 F5=rjROPVjq0uW9 3N'8x#6Rk>FA^Jhҳd5w$BpA"!R0Qv\.x/.놼P| FRtvm1{VGͳހGPUh>Vu$"0/[UM gN~ Mq]\7 zwUhI|KgLdr`йpFM'=.WHYNl){n*SE~K;6'#(P'bd*5/SP&J )"'kJlY¸𷑈MQuaW+d0U:; m eӎ!rVk%P<1@ֆO lUč^cFKn4w|ҡ^C,V4mzzCKCBr^?xF cnƪ[HGdb2S U%Ass)yҁ| |ny5>o[~?0i3}y'f#LECS Di?4UV;t+ ߆TM<^Pgi'P!B~"͉ˑ/"}s=MQo9< ~-Ou<]Rq ԯC/$B, }vpv(A6m 9Ԁ!@SL|WI\BL^m} E?ͯZPhopt_v'uw!u2>dEtx$}0TWɹ&ܵa8bH+Jb5eW;tj{.7mmȉ0|yJiMmM91W1[VKG: *(,.kgXl̏eiy4915.$6W>L'VkRÓb mܯesy]Kr;\\\πvTU ܎7%:C7(J=tYF gݏS (?*2z.'mGg۝V'xӌxmPd'ohIaM8KL#a7es<#P \ 26(6f8g4ý-@ }*&w厘 )<|cu3š-_PGP܈rAGk Z,9:}/+e|vroѿ։%I;Z[Pv~I%*D%08SHV 0᭟b_Co.N>wȔ?WYE8ph[R'yTٙn4AAʮH :e#Dv%~[[@1?ؖwoB7a;u&+? kDtp>Gq1Xu者bgOC(%}D3LGb%w!%U1YVA]SA6Al_[L*cu6@nW!Z!L9bB557;:> 廈'3 d` 6x/}~%I.ƽM½:&pI}p a4ab@)w%%&AӤk&bRqBg|* G3~Ӻ"w:ΗRm>3n's8 XijѲR=nXWDn/*MI73C }Ղ>kb\/b\_ungw-r cF5x #xոU+GPќ.3a&7G*G,Y&7Dlf97ys^1)C ՓY; {R9A:TImn[跶 tz> qZc#I< \ItحY A9Ӿ&oEXy\G'3lg 4D!-(uyH2C5Gno_jܡ 8wB;hoD8|bJAoJ)AF3']?uyV"<84h<-lzh03P*SnY=kVDr5.fďc蘛|e?NZ92ޓxDr:;X#$7 w/mw}=A^i[Xʯ:Q/į'b5M9Ֆ }g$E>p7l|#|sKBgXdoܾ-UB뱿].X9E6K%|5-Ti1=:)=R7{;MGHF4׏?'J8DԂr!?7Lܼ}9 MN Mi*)=ՏV!_( ] ÝfG CAƁO_;Κ xVhΓFuDʰʛƜ j_Wgȭ C_ۜS0TKڹD$ I eBa"9+_‚X>M_](U{a[Ehԡqƈh1F,sf&ۄcnC>23$Tsfu;{t|ZjfSlb-I=.=1iR) gRՓxQԀP,XxכMxf|2C!$ ϮdFl lj:CO[DiLIE7 _zxM ^B2^W(&B_k3R8]xő,T;ˀ Yhp fGo$$Gw5{/Ot+Ex `ŨiSsL>Jɝ({ڲU3!L+f$_g=IXs.WԘ_>rENu0SOf;춞ښǣւ$GC)dЂz7툾X'Gg0=}ӂd)U>[ `jϧ1=mOmHqMk ^"VI*["4aIRJy2=$k}T5Ӕ@)h\Mr ܴ%k$ faR.(ci!zΥ<<.w[:>8AltrS 􈬜ڮ2U .ZڤIueTvb8c"8c#2T81(3P!{}$41G$I15[1)-8e')];m3א߶"~I1{CVۻ7K"M-? ̳)In脑7ۣ <ʪKKDb\ؾJf'{hXjk-<*dG/ l) #!S=s H~aofp0#(1yIg*w¤^&t$^;/$~>oU+W2;3@ w6gL-F(@ 5P?>R$uj9i:L,ekɯp>h%1~V{p;D@搟Y X߃=NNa 줶iKOB2 OܦbWL ]AN\gZMy 4׬8`p3MlIj-^}U楼(7$UPl~&j*济-$Y˙jkgM2% v܁¥W7^fR'hVPɓɾ±ʸ|H]~tt({'>>U87Z x3f\qsk.P۬ U'ea,wdpp@p҉?~f7,|P2ٮ2O]-{DQzy8|P+9C[\/9{P"&fɴ(˙;&G:Fxb q yfA} ܶKAj32_Qw?_45v%7NI_N'ĨO@F7Bm~7LBuKބԺ"}Œ3+l$YJ=G[):4JM#/vF ܗ؝}zk]Ks ȷ4Fˋ6 edD!-Ϗ̥lRV-]X "*o0%I@"06| zthUҴꁗS%By'F蓓Wz;Am73jp)k̒`&*Jz34a!T+6A5z~?`#3mn=N<5_>U>4tVӡϓ:S%^y̅q* ld$MNܩp:ćcJMwo% պA3ט P^l%v &-=˙aL 8p ppA%:`ilA[!zM 5Gr炔Netz<uduWnX:.WkB>nK%:ljm9I 'SJ ő(aӸoC*^e*Q0h́`z& U::wlo βXa'=sO]~HzAs~ 4~?\AĦ||] mY8 \-(u`؉mk6c{ٰGsZM%UTdĊW>{׼U5(LXGr6ȝ8wóBBO5gĻa<#>nѿ S*qސӣpc*dO`J / ى]$>Vzzye30ZkWng2 *bTT"DBopO H(촊ɺ*}ݪWk \]:rȭrQ6soES /}< noFqfc5x? uWak=U-3\30v$HD%-d#CwAT:Z9vP}Va[I0&5MԤdxe)%fkXn@ͺPA">GqP`CZTŸR[Bnqŵ47c[CuYlG95$ut] GCqZ>U49c9VZTyrR_,W wKmV"g^6x) \zlDϏϱֵb"&vZfȸ5M7|wʴ N-C2>6.HyY#)sBGeڳ|%[{*Q&(m1]kl]bېkEEoRʓmr_H|Hd`LCҙhACR=/s5Pl1W@4ۋ+v#UwKd;nH"pl r(9R1{:դn{FGb_7:B&%pi(yIE 2d.b"ޅEV}aԀYhibP=d:#k;3~;cuγ_ +; yҏ*M{h99>vbUA![_j zT*S7S,Dl7ٟm?ke=ƀ{wɘi]+ C S^8yUdV{eM|Xsa碡65OVMJ-YvOK,"ql{t(7YМ@hS%Di"-_ ,k+BgT"%̓v>ڈF+o]5;t .N:f88|66,^J[ӫ 28 Gp$wJ]+%F`1/ݾ*|Aoa ?09ΓrjM]R+ $GQQSٞYe ~/RK{~9@9Qiɜr!%#]ݰ5 Ć󀹾9&}kgc Cr^6 &9.>;&e/Ƃ_ 1ֈKCX͗^w&&G>cn$ wGevkB}_c\;"ײp/ѭ! ,xer7T`a41BdoF(vǻiì2x1wEp5 *WpQ*1yLwXuNfFJ#sFƲwCbEF"8)x,AK@ e/B#e:xN OӦΘEI*s_Pj u/ӊE۱˂^?8+RKװ.fct.1V |Bl7KWJG(sz 7;2: )X4[[~M0sso++H3h EMEh-d1yGKKn_,BAUMtyN2DGgE竮{{4 2{hUXȜ94W<,,^Ɇ/ʝ~KP5r&|Oݮu mZTog61ڇPUW mVp̿V{<>̙Y֋(H8SA~^-]0~^K;l`X'D V!S3qo-΂&әs0m`BQMߢ[03`e'rͥ<opS䅭!al ]<]H>=0;A&69s1Ji zJC]]ڠ|++w+ GOk?h()ܲ#NeW( q|LN&p.dznAMK5|sJ%tgl 6l)We_X-J#JJŜI fsj\|Q?H4<+؉ xR$Ql$ qCp:@E@J7"6*lOMP;i@+Bv(OH³_%[l`J;V8̀&9\|EV4$Pd%;RN81I)'-aIiB#覝 k~NxHi#.U>2xˊ)VlPN5eᕡ*e}}uLSjn&>;5͘ mxiifڳC;ʑfy*Q }YJ`Br`[uM&wE $eT UI^*Vv2щю (Jʇ^y^Z!%նvoЁA#p!y>ΘmS S;V*rߦ[B'Du%,HArHq2`8G4PQ"lgĚ]_*$ȕ[Lòžڒc51_ įRYMYHmᕣ\@K "r-i,N/hc-=E(hH{#T' L cdyAWkl?I?@1{1=0]ۼA=\ c&AHaDjF)eQ2I3TZQ|b5c4umW~ 4CG5!a+ +Bsэճ򢜧vz.O뮂*(i9n_=]Ƽ m:lmL\?Jgiw\'jWѥY 7o)_zz#TF"=NL/\FU)dDq?Y `JmOn|n* i*b+j_VX5N*Qu1fP*OŪ)){_: ^*vE@JS*hR Rr FYU@?rЫs,kx^ˡ#곁pjκ9F F+KbAֵ'f}sĥ mr!9/fO&~Kڢ.YR -$2c[WeW>夥Evh(@зmnH NS&Ғj%b˿r˫Ay7eB(u Y)5K?-`u5tl k.'ĻQW+5zʥ:gq+dh-*cp7M #?_Kn 3t?/\+GrIL[ KgTg"o\TSj lK{!P'q]s: PnZ{_ N@ swվ Φ6,j7 ݊Xf|N<Bœ1/|R ɤC ˏBlTzRzaVvw `>6dbA\5O(s[IT1#MNʚګ3"3t5ei:حB JM=dr2NTKZdD>b,I9i <{:BϿX?*pp}0:yH2T%Ub9`$D[ #H> [B \=c~|p4I'/ t>8cqI'> '/9< !FzkY TYIS*@e 0}s&ev#d:!6Zx9[PqM5b>I ZH@h-=(= vɻFYг/A7W!^va(gX1AxrbCot8*r6%iGFSFT(~'t-\X*Y՛٥069C3:;KR_˽ZMT^`ꤨ틦T=m?wH`)Mo3݋~Y">tD"qL?>5ִ\Mh t~,Cq%fMO\+BQLTK1I[HwiCT%y]BZWI?"NޥpYQPZ .MbzOIp~b [cIIo#6V%}ؐeEn?(V"WN9R"(ןgx1T^ 3\P`Ox!/ ZXI xאl0_ׄV]-U:N0'D{l ޝ.;yğ5dRe},.̎~bO:xa [_ g([-R]:f<'5TW]J.Q شB'9/xbE]G8m&銈D!jr({5wNicAj_U,Eq7 Cjߊ΁G*ex Ra۩Qܕ9E?){|ӕ.({FnX6͸dUޮO߄9 KQN;nśRoϸ {/uHX5s@T TEo4Ku5~dˆF-ZeaN47U9Ed_nvvᰨC0l\<,C}jVZ}W$/3 Vы~uwW(Л+f?Ǜ.woIi(u)U5ǒ&L/!~3ռ8WIPƯVBTq$P9)n!VlnrK!vᕒN![+ 钘%{h#${)k:MrnPNNoU7%{=6uBf!)ǒP`!F 6j3ĉJSt,+tRiI@KhOv Q Ή.!!5ci}R.`.KTμ{xҸG-|;&#mINX`>+΢$qu()_/1_/z$*|šYP8 U깠\w1qe)ެi';1(& J9x, ;k=yvXd&> OyV7LnZ>k7ÿHZm֖n~͚lbKn\Z|`@21bovۓ3?(cz鰳"XCVM\yZzrqY{ PTIwRm ޫR .x  7+kP!q#; l)HH+N}kF?AZUY+uI{:ǼBTlZHsa]zg7"H"J]L9d 8-c4?7*yf3zdѰf!3QF5 FE#gqLxys|J.L)\-]d'n586K?OTZVB>2ؗQmhĚ8~qUwUTv \ۓRZ.3Əwj"P5w!tpҵFo8;9 tKf?#@9LJѫC~\Um+'M`^:M?E+\+_yX̧i6az0꨿N Uw!D'FXFk.eC%=:bOa^S66=YKH)o٘%u҅>ciqE E鐧5'0sKrsH})y[8L4D+kso}IYSE>j9W 0Bp6禲Z^H|{v]tF-d YVB^ڭ(~ Y3ZR0[OyX83b-V{qe*_0лHse| 4kpԨga)PL<f.} CFkm @ ح\؃dK'5-拒 V厙B~+M1hǶD s?AV Xf% SNngm]<Ө-od}e*@TB {W6zu蠃Vm#Y+X G=X}}Rs]S i^h->8H8eEGB\riځ}KS Xƪ*)k\M09aR,KHoӡs=TL᧖b}Y pgj(;O,D{`џs]g1F*a jA] K PȄ-8qVOLbVMx.:i K)>iR-p8 !cJ4/Bw(%~4y4~¼M0:I07Us_Z?~{ 0 Uѧ8=ꪲ (;nBANSۑ5 EYD+* ST`=Zo%ym@2l2+* ]y>U %:[9.#;Tx`]tӐ#gb ARaY.~͎|'z)vv%1jt5|_0oT; a[_8uɻeRbN^h^-$F-cM@McrBҵ1i'p_L/z9&dIVcx hJՎ !L @yk0 _=E*a~+7ԛ@: Ӡ^`;*yDZKe]^FAd 3@of(2ʍ ]۶!;kg凞򡡮BUӠ.NN{rn`=ӄ_M k|͠'3:%fThv&faG׏ESG3 %]g?8,1Umg[@m==6RXgh%?;L=Nm'u3;r14 }WƄ)D&`ǣ::ᕅ&!9P`fN]Uh۳a.f hrYn/َ6`G4B2Օ[m5يiBY{i+PkOD>yV lr.""8 : qr*֒TT4@*h0H\sP"" =j* ]Hӛbe|F&t`34`N @Z[{pd"`){˞ 0ׇe  *޶EqQH[LQ`Du EofJuE Y$ }hH9WbW\>0< Qb)L9)?&VN0W"VXcH0cv4ȵ6O]f;s@tyR6õξ}ȿh5<d3|4Ռf'f.-нi%wg#PhlgQnTTܱ$pN Ŝޖ6L'/ ʜhgDϒ-T1W{ vz$ [NT]|ۣa u1} BWd~O %TlZG`]S0gye?c"ϖXp/򭝤B3hK ~Z*Dk@RER 6nga ?; u\x2yAİvy4HPkdcT@]Zy;el:W3l}i̾>)e:7F)S /=~d4-}M;Ab Bˍ^_ѭX5z';֜9u`5۽k:ՔJ#L?n0 Ddj^C:d[Xu Ub$` #dǰkkg">`Ym6o,#銎;D.ɤ[ P{ 8JpPkZI T[l.;O G̛XsIŠ`Oo|ÝrKR*}#L2b[i2T|tbpY3t:7|W+4 hW}q4h!'XDBE?VG'W ӷEP cAј'/J֐բ!4DQV8FX;i [DS͇@c ܛg?^ˆ\ dݟQu  /sk[sq{sӰx!YBp_rp M_vF$ 9.e%VO+N;>b|wp2ݢ.<»$aN$Վ>O3e xM:m]GlŰHkZNۋp-h:;e},@u_Sux>@s K6X[`*卻b>u$ΐJN4#PMĊA7 >$j7Jڞ-\lw&Q?ʘ$UC84̍>X3Ov֜_,ZgPxE)͉k(Aߒ"ގeۓck -Iy& :F5l~[kUQ`$? DN:׮*\+)#mUDZ!i7gJ$bA7t*@ +al[KZ"^\`M 9SbH'|sQN.*fX=#4Eq fts$Ʋ۷6ժݑ߷T4`()fj2? fz/r,6r4b=w-Qײ X C 5#ZQC*v7uo%CTĶ\ʁ ]z5Lm^9coc\n^1籨.Ӏ}T 3!rT4\P*Tb#U|3__AfH`IjwO &W+\3%~/Ld]wbo77'ƃ̬Tڶquj_Ab1j>b:Y2ڴ}m,mlH2M0s10.wEA\~4r~Dޗ^4-nSƟ^|:t*1TI/wl_'pH};Uu\!A`0T^H %1_Zi8}I.bǃܑ$Qqޠpj' ` ;k +>U|Cz;>AX`a#dhV&vT"4&DC5d#YY0.>-'L^C+6jBtelx D1!Gդ!Ǝ1aǦlol)д\e{sć,4I/]1)? ̔.5[N-m{xX^X6)OI7^2+d1a6jYx ;S&rrN"ݞj0GvG4P[Mv2 (M[diS5LfH5j]j2U C [uI)iQE&o3|O^v^,dKwg L Qqi0bԏoBoCI͑-.3[,#n&.BPI 6 P%T=52 wF^hZ.b !kq9 x ?R Xś _(( Kx;KR/4+k0EI Gu ν>0Iĥ*Or.dnl@Dc:K]t&í:Ը62q.( PT5oE/6:?hoDɇGN(P@pYֻh2v髣ܪ):@B< ˱D.E3fk2frC||-2< 'y7㚘 L8d9T+V-0 @QWkP;1;wW]t=UMwi=o2l>K3FO=5WAilRn?HA&g)]f3։ΒSt&T8HH\~LfqzAID" ۔oL[^hZeoX rCIJh㽒*UDN1Rl.J!X<o1|#XLZ%aO E"Tl:x1L!ebQ,ϘP?VQ絠Ǜm>ϷH@ҖDWqqH.˷L`{ufKD"yQiw#ՅL|+];^# Q~a. P2f&/<#HyxMhʖo4C% u2B4(nZ/.u!Aj|8qn 5*V<+gd{]kQZNuH> SwIW:@&D{j^[Eh-WŝՑEA`ԎG")^-©:KG]bwsYgh ).+FAՒ0E o£v{Ѫ.l; 5Dy[^_X#)Tbϔ* ۉ:c]YEj1LDfi+{+R' ДO9aZMq%oGO#*H[pMx)DdrmD7-#=~YksFJ8j yrAl.sZOx$I+ oyݸ7ʾ!*1D-nwx=;3uan՗sݛ@ M0YЙ}mEP3bV!v`uA󉥙C Ti@/Gi㎲zKY.R^"Bu#PU [nA׫%ON3%`pP\7hO}'տ$@G5 2R%ۊ*Bx]Ī23)ӢX2g Q%E3Ą hhhT nG85k\]F'%t`K/4^3WG/[*gywOy4w2'3׈|Ei YZ