easy-rsa-3.2.2-bp156.2.6.1<>,ȉgdI%z Wh ZƴުsvE~荔 CIy(7HܩqwQqiҗS;Ng_"2"w6Z4,by^05(0!FqCv7.9:DqeXeEf _NqFrOzJF_ ɘP0 =466=u3.R ?꺲Rg.D(W ,_8[.e\ 4q+h RD1f (I\7~6Z G OFWyuǵC>ȈaqO(!XRl1jۓFP)i!nԕF$z"NҒ7t_a$U lk֡[tΛ2< 3,>N?Nd   F04@D]fw < r      x     4 L ( 8 9 \:FGfGG|HGIHTXHpYHx\H]I^JabKcKdLkeLpfLslLuuLvLwMPxMyN(zN,N<N@NFNCeasy-rsa3.2.2bp156.2.6.1CLI utility to build and manage a PKI CAeasy-rsa is a CLI utility to build and manage a Public Key Infrastructure (PKI). Once the Certificate Authority (CA) is created, you can request and sign certificates, including sub-CAs, and create Certificate Revokation Lists (CRL).gdi04-ch1cp:SUSE Linux Enterprise 15openSUSEGPL-2.0-or-laterhttp://bugs.opensuse.orgUnspecifiedhttps://github.com/OpenVPN/easy-rsalinuxnoarch#O M %#% ; FA큤A큤A큤A큤gdgdgdgdgdgdgdgdgdgdgdgdgdgdg /g /g /g /g /g /g /g /g /g /gdg /g /13ca05f031d58c5e2912652b33099ce9ac05f49595e5d5fe96367229e3ce070c2853dd3bfa0f0be3c508645ea42c958580fe783ed6187a2b5e2fc9488ecf914fa05c40e0f0f749cfd6d78c14777398e55a40b4a732e94ffb84fde2daa8ebd89e39f0342a69b6193bf232a5b8b7040ce216c58fc16482539f219c52df747e21f0892e9134f942c2e41b29476312e131255bdd8d3621e11d01f686ea8b8e12eef085561a14f61ab8371e40ed54818ba0e9dfe175577c3fb7b46b817f15bd5ef450f5ee6acae49875a044e8afb096e8513206cbabc53d4b956eea2377816cebcc29faf5e69682741855030322707cbb0771896f38ea8da00d6f4220b1c676c761e22655ff6ec11b8ef447bf2a92980759b8dbb196585f4078a884360555dc760736823067527e3a49eb34e9e52d06c3414897b7b208cdcd5138abf6f5aabdf1ff0eb4bb52f6b34a8537ec0bada102e809fd859a518b220233c214a7f64ecf3639d8c7fd76ac8fb73bc294203685208c6fff8c9721614b79777e41c2d33ab1ab23a9e6c35f275fb0a4356187e25ec5d24009e56a1c773996f0df2b6b6a74152f43bb05067a8c0a55471acd51203d68669dd80e75293ccb2fc9c37b99682606a03ce207f4975f5e34da714f2b2c62f712dd0046f5e40290055d5c5fda3d977c22e78132fdf02752f03066c38c0f6d3c290856a4c4f685cdf81995cba78b055f0eb47e5dfc4e5952e58b9b9ea7740134caf2844b7f92011800e5ff98b667bbec5ee5466862808ff286a20ce13909430596ac756c1a53ff6582a074697c98ca319df0842b7978a7b002442e4c05ef18eb0ae11b7c6a17a2932495f89ad407ab65cb85c73960f00e54397fa0869377eb83cf86d2d3de531812fbc8537fc96c7f5decd5cb89b6ed5751d80377b576dbc0ac033f9e17a4efe363edc4a00b615aa6bf4d6b757c4a4fc71745d93a87278801f1bca555562ca23f21e18293add64b9e6f6b7bf18177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrooteasy-rsa-3.2.2-bp156.2.6.1.src.rpmconfig(easy-rsa)easy-rsa@    /bin/shconfig(easy-rsa)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.2.2-bp156.2.6.13.0.4-14.6.0-14.0-15.2-14.14.3g gJ@e.w@dϋ@cƍci@c:@cb_G@\b@\&@Zm@YB@Y@Yn@Y{'@Yu@Ym@Y5GY)j@VU!#Richard Rahl Richard Rahl Paolo Stivanin Matthias Eliasson Paolo Stivanin Olav Reinert Dirk Müller Florian "spirit" Olav Reinert Olav Reinert Tuukka Pasanen chris@computersalat.deseroton10@gmail.comastieger@suse.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.combruno@ioda-net.chprojects@localside.netprojects@localside.net- update to 3.2.2: * Remove redundant file: index.txt.attr * sign-req: Allow custom X509 Types * Add LibreSSL version 4 to supported SSL Libraries * Revoke remove private inline * Easyrsa disable inline * easyrsa-tools.lib: renew SAN, remove excess word 'Address' * easyrsa-tls.lib: renew, make sed regex for 'IP Address' greedy * Show expire allow zero days * easyrsa-tools.lib: New command 'renew ca' * Improve CRL expiration details * Tools move to easyrsa3 * vars.example: Remove $EASYRSA_PKI * Introduce new command revoke-issued * Bugfix renew ca and renew * Always use locate_support_files() after secure_session() * revoke: Make check for conflicting files less intrusive * Forbid a self-signed certificate from being expired/renewed/revoked * V321 minor final * op-test.sh: Disable download ossl3 and shellcheck binaries * Revert: Do not remove index.txt.attr * Fold easyrsa-tools.lib into easyrsa- update to 3.2.1: * inline: Add decimal value for cert. serial * Always exit with error for unknown command options * ntegrate Easy-RSA TLS-Key for use with 'init-pki soft' * easyrsa-tools.lib, show-expire: Add CA certificate to report * inline: OpenVPN TLS Keys inlining for TLS-AUTH, TLS-CRYPT-V1 * easyrsa-tools.lib: OpenVPN TLS Key gen. TLS-AUTH, TLS-CRYPT-V1 * easyrsa-tools.lib: expire_status_v2() (show-expire version 2) * sign-req: Require 128bit serial number * Move command 'verify-cert' to Tools-lib; drop 'verify' shortcut * Windows secure_session(): Ensure $secured_session dir is created * Switch to '-f' for file existence * inline: Move auto-inline from build_full() to sign_req() * gen-crl: Create additional CRL in DER format * self-sign: Allow Edwards Curve based keys * Re-enable command 'renew' (version 2): Requires EasyRSA Tools * bug-fix: revoke: Pass the correct certificate location * vars.example: Add flags for auto-SAN and X509 critical attribute * Global option --eku-crit: Mark X509 extendedKeyUsage as critical * sign-req: Add critical and pathlen details to confirmation * export-p12: Automatically generate inline file * Introduce global option --auto-san, use commonName as SAN * Introduce global option --san-crit, mark SAN critical * Introduce new global options: --ku-crit and --bc-crit * gen-req: Always check for existing request file * revoke/revoke-expired/-renewed: Keep duplicate certificate * revoke-expired/-renewed: Keep req/key files for resigning * revoke: Add abbreviations for optional 'reason' * build-ca: Allow use of --req-cn without batch mode * gen-req: Re-enable use of --req-cn * write: Change syntax, target as file, not directory - update to 3.2.0: * Revert ca76697: Restore escape_hazard() * New X509 Type: 'selfsign' Internal only * New commands: self-sign-server and self-sign-client * build-ca: Command 'req', remove SSL option '-keyout' * Remove escape_hazard(), obsolete * Remove command and function display_cn(), unused * docs: Update EasyRSA-Renew-and-Revoke.md * Remove all 'renew' code; replaced by 'expire' code * Introduce commands: 'expire' and 'revoke-expired' * Keep request files [CSR] when revoking certificates * Restrict use of --req-cn to build-ca * Remove command 'display-san' (Code removed in 5a06f94) * Move Status Reports to 'easyrsa-tools.lib' * export-p12, OpenSSL v1.x: Upgrade PBE and MAC options * LibreSSL: Add fix for missing 'x509' option '-ext' * Variable heredoc expansion for SSL/Safe Config file * Always use here-doc version of openssl-easyrsa.cnf * export-p12: New command option 'legacy'. OpenSSL V3 Only * export-p12: Always set 'friendlyName' to file-name-base * As of Easy-RSA version 3.2.0-beta1, the configuration files vars.example, openssl-eayrsa.cnf and all files in x509-types directory are no longer required * Rename X509-type file code-signing to codeSigning * init-pki: Always write vars.example file to fresh PKI * New command 'write': Write 'legacy' files to stdout or files * Remove command 'make-safe-ssl': Replaced by command 'write safe-cnf' * New Command 'rand': Expose easyrsa_random() to the command line * Remove function 'set_pass_legacy()' * Remove command 'rewind-renew' * Remove command 'rebuild' * Remove command 'upgrade' * Remove EASYRSA_NO_VARS; Allow graceful use without a vars file * New diagnostic command 'display-cn' * Expand renewable certificate types to include code-signing - attach a source to keyring- Update to 3.1.7: * Completely Remove Upgrade Functionality * Expand help to include undocumented commands * Forbid "default vars in the default PKI" for all commands * show-expire: Calculate certificate expire seconds from Database date * Expand help to include undocumented commands * New command: make-vars - Print vars.example (here-doc) to stdout * gen-crl: preserve existing crl.pem ownership+mode by @Tabiskabis in #1020 * Improve vars auto load * Replace santize_path() and ignore Windows "security" warning * Improve select_vars() and source_vars() * sign-req: Allow the CSR DN-field order to be preserved * vars-file: Warn about EASYRSA_NO_VARS disabling vars-file use * Expand default status to include vars-file and CA status * verify_ssl_lib(): Minor style improvements * cleanup: Rename $easyrsa_error_exit to $easyrsa_exit_with_error- Update to 3.1.5: * Build Update: script now supports signing and verifying * Automate support-file creation (Free packaging) (#964) * build-ca: New command option 'raw-ca', abbrevation: 'raw' (#963) This 'raw' method, is the most reliable way to build a CA, with a password, without writing the CA password to a temp-file. This option completely replaces both methods below: build-ca: New option --ca-via-stdin, use SSL -pass* argument 'stdin' (#959) Option '--ca-via-stdin' offers no more security than standard method. Easy-RSA version 3.1.4 ONLY. build-ca: Replace password temp-files with file-descriptors (#955) Using file-descriptors does not work in Windows. Easy-RSA version 3.1.3 ONLY. - update and rebase suse-packaging.patch- Update to 3.1.2: * Command 'renew': Remove option 'nopass' * find_x509_types_dir(): Remove excess checks * Remove function find_x509_types_dir() * For 'init-pki hard' only, always try to create a new pki/vars file * Introduce global option '--notext|--no-text' * Minor style change * Introduce command 'set-pass' * Fix shellcheck warning for command set-pass case statement * cleanup(): Exit correctly for SIGINT * Update help: Standardise output; Improve code; Reprioritise options * vars.example: Add EASYRSA_NO_PASS and wrap long lines * Use 'unset -v', consistently * build-ca: Improve passphrase input mechanism * Remove global options '--verbose' and '--quiet' as not required * Remove all prerequisite code to build a safe SSL config file * Rename temp files to reflect the purpose * easyrsa_openssl(): Always set OPENSSL_CONF to EasyRSA safe SSL config * Replace SSL calls for serial number with function ssl_cert_serial() * Introduce OpenSSL only mode: No Safe SSL Config File * ff_date_to_cert_date(): Correct the input format for busybox date * Re-order easyrsa_openssl() temp-file assignment * Stop EASYRSA_DEBUG interfering with SSL output from subshells * Status reports: Recognise Expired certificates * New function safe_set_var(): Safe wrapper for set_var() * Windows, build-ca: Add input password to re-open private key * Renewal: General code improvements * cleanup(): General improvements - Create KNOWN error exit * build-ca: Change FATAL error to warning for old openssl-easyrsa.cnf * Allow --fix-offset to create post-dated certificates * Default settings: Make default Edwards curve ED25519 * cleanup(): Exit with numeric error-code only * init-pki(): Introduce second warning before HARD removal * build-full: Always enable inline file creation * Global option '--passout' always take priority ONLY * Status Reports: Set 'LC_TIME=C.UTF-8', only used for reports * Option --fix-offset: Adjust off-by-one day - Drop fix-747.patch- fix for 3.1.1: * add patch fix-747.patch from upstream- update to 3.1.1: * Remove command 'renewable' (#715) * Expand 'show-renew', include 'renewed/certs_by_serial' (#700) * Resolve long-standing issue with --subca-len=N (#691) * ++ NOTICE: Add EasyRSA-Renew-and-Revoke.md (#690) * Require 'openssl-easyrsa.cnf' is up to date (#695} * Introduce 'renew' (version 3). Only renew cert (#688) * Always ensure X509-types files exist (#581 #696) * Expand alias '--days' to all suitable options with a period (#674) * Introduce --keep-tmp, keep temp files for debugging (#667) * Introduce Option -q|--quiet, disable information output (#703) * Add serialNumber (OID 2.5.4.5) to DN 'org' mode (#606) * Support ampersand and dollar-sign in vars file (#590) * Introduce 'rewind-renew' (#579) * Expand status reports to include checking a single cert (#577) * Introduce 'revoke-renewed' (#547) * update OpenSSL for Windows to 3.0.5- Update to 3.1.0 (2022-05-18) * Introduce basic support for OpenSSL version 3 (#492) * Update regex in grep to be POSIX compliant (#556) * Introduce status reporting tools (#555 & #557) * Display certificates using UTF8 (#551) * Allow certificates to be created with fixed date offset (#550) * Add 'verify' to verify certificate against CA (#549) * Add PKCS#12 alias 'friendlyName' (#544) * Disallow use of '--vars=FILE init-pki' (#566) * Support multiple IP-Addresses in SAN (#564) * Add option '--renew-days=NN', custom renew grace period (#557) * Add 'nopass' option to the 'export-pkcs' functions (#411) * Add support for 'busybox' (#543) * Add option '--tmp-dir=DIR' to declare Temp-dir (Commit f503a22)- Update to 3.0.9 (2022-05-04) * Upgrade OpenSSL from 1.1.0j to 1.1.1o (#405, #407) - We are buliding this ourselves now. * Fix --version so it uses EASYRSA_OPENSSL (#416) * Use openssl rand instead of non-POSIX mktemp (#478) * Fix paths with spaces (#443) * Correct OpenSSL version from Homebrew on macOs (#416) * Fix revoking a renewed certificate (Original PR #394) * Follow-up commit: ef22701 * Introduce 'show-crl' (d199389) * Support Windows-Git 'version of bash' (#533) * Disallow use of single quote (') in vars file, Warning (#530) * Creating a CA uses x509-types/ca and COMMON (#526) * Prefer 'PKI/vars' over all other locations (#528) * Introduce 'init-pki soft' option (#197) * Warnings are no longer silenced by --batch (#523) * Improve packaging options (#510)- update to 3.0.8 (2020-09-09) * Provide --version option (#372) * Version information now within generated certificates like on *nix * Fixed issue where gen-dh overwrote existing files without warning (#373) * Fixed issue with ED/EC certificates were still signed by RSA (#374) * Added support for export-p8 (#339) * Clarified error message (#384) * 2->3 upgrade now errors and prints message when vars isn't found (#377) * Update OpenSSL Windows binaries to 1.1.1g * Reverted OpenSSL back to 1.1.0j- update to 3.0.6 (2019-02-01) * Certifcates that are revoked now move to a revoked subdirectory (#63) * EasyRSA no longer clobbers non-EASYRSA environment variables (#277) * More sane string checking, allowingn for commas in CN (#267) * Support for reasonCode in CRL (#280) * Better handling for capturing passphrases (#230, others) * Improved LibreSSL/MacOS support * Adds support to renew certificates up to 30 days before expiration (#286) - This changes previous behavior allowing for certificate creation using duplicate CNs. - update and rebase suse-packaging.patch- update to 3.0.5 * Fix #17 & #58: use AES256 for CA key * Also, don't use read -s, use stty -echo * Fix broken "nopass" option * Add -r to read to stop errors reported by shellcheck (and to behave) * remove overzealous quotes around $pkcs_opts (more SC errors) - update and rebase suse-packaging.patch * fix: set_var EASYRSA in vars.example - fix License- Upgrade to version 3.0.4 * Remove use of egrep (#154) * Finally(?) fix the subjectAltName issues (really fixes #168) - Improve RPM description- update release tarball instead of git snapshot - add upstream signing keyring and verify source signature- Update to version 3.0.3 - Rename easy-rsa-packaging.patch to suse-packaging.patch - Remove obsolete upstream patches: * f174800.patch * 29d4dee.patch * b93d0a1.patch * fb4d8d8.patch * b75faa4.patch * 6436eaf.patch * e9e8e27.patch * 534f673.patch * d20d2b3.patch * 4eac410.patch * a138c0d.patch * 83a1a21.patch- Include upstream patches: + 4eac410.patch Fix string comprehension + a138c0d.patch Fix incorrect "openssl rand" usage + 83a1a21.patch Add --copy-ext option- Include upstream patches: + d20d2b3.patch Update docs and examples to fit changes in 534f673 - Adapted easy-rsa-packaging.patch to work with upstream patch- Include upstream patches: + 534f673.patch Make $PWD/pki the default PKI location - Adapted easy-rsa-packaging.patch to work with upstream patch - Treat /etc/easy-rsa as public default config, no default vars- Include upstream patches: + 6436eaf.patch Add CN as SAN (if none requested) on server certs by default + e9e8e27.patch Moved @ValdikSS's serial randomization to sign_req- Undo removal of .md suffix on markdown documentation- Add special %if for SLE11 as patch tool can't rename files. - Include upstream patches + f174800.patch Generate random serial number for all certificates + 29d4dee.patch Fixes #91 basename: invalid option -- 's' + b93d0a1.patch Spelling fixes and sentence structure improvements + fb4d8d8.patch Fix comment indicating the end of the function verify_file() + b75faa4.patch Convert README and COPYING into markdown files - Rename openSUSE specific patch easyrsa.packaging.patch to easy-rsa-packaging.patch - spec-cleaner -m (Add also SUSE copyrights)- update to version 3.0.1 * cab4a07 Fix typo: Hellman (ljani: Github) * 171834d Fix typo: Default (allo-: Github) * 8b42eea Make aes256 default, replacing 3des (keros: Github) * f2f4ac8 Make -utf8 default (roubert: Github)- initial upload: 3.0.0-rc2 (2014/07/27)i04-ch1c 1739547828 3.2.2-bp156.2.6.13.2.2-bp156.2.6.1easy-rsaopenssl-easyrsa.cnfvars.examplex509-typesCOMMONcaclientcode-signingemailkdcserverserverClienteasyrsaeasy-rsaChangeLogEasyRSA-Advanced.mdEasyRSA-Contributing.mdEasyRSA-Readme.mdEasyRSA-Renew-and-Revoke.mdEasyRSA-Upgrade-Notes.mdHacking.mdIntro-To-PKI.mdREADME.mdREADME.quickstart.mdeasy-rsaCOPYING.mdgpl-2.0.txt/etc//etc/easy-rsa//etc/easy-rsa/x509-types//usr/bin//usr/share/doc/packages//usr/share/doc/packages/easy-rsa//usr/share/licenses//usr/share/licenses/easy-rsa/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:18787/openSUSE_Backports_SLE-15-SP6_Update/dee2771e1fa6f459fcf83508476c8b4c-easy-rsa.openSUSE_Backports_SLE-15-SP6_Updatedrpmxz5noarch-suse-linuxdirectoryAlgol 68 source, ASCII textASCII textPOSIX shell script, ASCII text executableRvԇtk^ utf-87e77ae8bfe8cd565a8e1440f895ff1c939cb33e7c49ce024d085b71402274cf6? 7zXZ !t/ॎ4]"k%w HdXOXNjU{14RQjv8 \ʥHht"نrGZ.jKÆT:fALq82;iv?C0Cnf*17DdMm灈ԤHԘ <{2ǑS`e\9Y!j *F`+z⅑#+$ksX:@f1Z'x9M k۞h\aL-NU7+kl)z1_P7Xh|84DpXA8}_m;< ʶ !bYg7n<ȫC T[1kjNvY˶ǟW&,fv 1 צ w AK+(3@R:+ Qlp7 ;#M^wGK?5D-4ZZ%FBˌ=NӴ˩[+=Dv~"7O!7i :=)dsY/w[b6 r뺶˙z̵Y*qJu!A8Έox[8(h:."hKiPmq y7v=Y|@Y{ihmJu;aEBR4҈HG[$hwPد8WE#":k ^'+IKtMe5UFC]5nsD#oDIgQymAbX]lBl`.ɳKC S^Ea8YOы0!EvEjX7t5 >8A`>gC[Jd\IјO9::!ъqQu:_grM֋Q3n'˒A GPYGXW:5N꠻'R!sw)KH KUVw,UL:s'FB)H5E})KqFo>|xk W)O2 ];k|>3j 5T 7ۚ@~ͺ 3QG8ĩ|f  9zCyAxV⬖LJas/b)kEK ǻφGgBGi:?xo2MV35wd֊,Bwc#\~&dЯ`lʪfuF,S=y(Ѭ9԰gH%5*ξGסrIJ0=c6hIIҿ CZQ<%Xzf!SrJkf@Ius5-7sےO'+;NŮ+Z5 68mr<.'ul""ɔuDM݅?{2oكI%7x]w In^?;.#b80W͍ bF`!E^ Mu/t"@*/KpjioP dj:1z8Y6|v!9&ف;!w=twxD\ikAܐU]A ;pdd]#ٳpS$B[6wubJuqoك"7U] ЏvcZb=Isk29SHXWk8qv/])P 0cG6lKE .cOVoޙV2Im SUx|RKn q_Dk5ělSDbz"L4 e Pk8汻=Q/'^lQEyV.T1̿ޓ|ٷWw)lO1AjG3D M&NEl7禶XtSӑ1H'HND&'sԩNL3 k uTz`Q=h>3mtldG<(jԡ D>N ,}ᥓ O(L m3fBcƩkܭ\32'-;굌( 878Nx'iǭ_OܓTa?f>`5QbsGEΊ"-NX LaPGУQK9!Q)RsVyODzzgQ Y݅-sxEmXݼ[޶ܥEibȜDdD{TK7,h=L-r`> nX[|FK70`Ю:F M}iE_˝G$hR8St}]1lC٨PASO_I@Df%JQ`gubeS 76aLCi&gw[)WaTZW_|r8@FFJHy n(NP}u3 !FOni>k42e=uHgJ &NsEoi7dIYh&0F{JX1)ſi@TEӏ]h)/ֽ <spoIf;vW_pK ,%;$f[ǒ TQ! IzЌVW?815kOW:s6*mѬ*Ed,{A~"d I=z&']"c'7&6J9TS:nS F,gG#0>nOz#4[ R25ԧ`Lqr(ԝ9vDX}9+߫[直 ןB>}"˅gFFl}˝R䯷ES[5*RߢexBT+ =XKi2P  N4∊i[ V<qwaۺtY@#NcDsOu4Œ(Y}СYp#/2 u?-Ǜ"|{g+vق T%jUDۄn TY+zj:b&ȿW+GBt90T!UDV ީQ^{kٞ7u ]CFX"Eۦ $)6R!2O7%+Nw2V&P9,J F)[zbH?DZPX:=X*9}73 Sx:I >WBBiq#^k/h|@ jMZ2VeTN#/vMD@AsV\)@=/zH8ǟB'/ ^hlRjsLiC0˾DRpם.hm2AY3-CWzp[vS2ē [Vf i'-kYGkTل0֤0')l `ФfpȣW>uC*)r\¨ (z ėpX19okdj<)sXCG,I'6Gf֝1Imfˎ9`D<7B@>Ւs5#/Rl@ejz{!η#s ,h ɎR8Oܭ].q~ B9߱*"rh亽 TUwWϱ:G/CQ31QȨt&997`|5 #ISkVu#+clS=f%$J7E-|6n;MZG,5xfA\m`XF$0Gᘒ8)r!DP6ä[&PjcfOHp%3MRZePߓ. B$J-͠=j/?Y=_7q{4I8~4r xg=N/{: N@WM +#@XfzrtyL񣶄NBS\'`gT6/!c=]&>U!rRKHR"jGYe7lgs n1O8= 5ȼ ǥou'B(=ݔt⢷ilu.Hgȿ0 / #u1Z$zﮪCGtXit]GA >k9_j='P!DӇZhM ? 8rC&)G9Y|܋_Gn{Fs(ז z W<;L1咡J#\j4*"cQYD^J|) 7!PP:ఴ8G~w =OQ2WڟVBݨo!cldl.$ "tv %ѬD@-{;{R (svuub`[ɯT4͆wWM\&YXӕ?iM^Qznf3avte -+Rɯm2xuʞ3XQhf~=ǹz_8m]Ӛ*VMM:c>7PX3uk`F-P(MbknI&3MkK#Of}A!7&>=x˶1}E"zگqoW{TDFќȵ4U{1vnDtǙ.Qj|Iv>4!~aHT$C4toC%ٖ8pBOg mnCL\nR\ʸdžW+ӴhgcAB{,N.ߛR1r*k7\E#ѝFXH@A_.G&rC~?Gu }Vo*][;_ݔZY!A뚈?i o@GIyy7k+!RzfRp2o'2"{וX݋v#ӕa.gm7uGDjAt J,·좂9+D[XK#8Gk3 1葮Hӳoթ~o 7|F? b6ZbA1[~k, _Qa1z (|87ڥ\#Ýz7VW5*e`^fہ'kW)7ס0YH ;E,/+,0dAK ~ÃZ̫ÝZ'^qy,1bhf6VW|XwNE-mد^x*geT9 :&C_T]ڏ:Lrԍ)Pgryfe|.C"~pSwG'JVZ'KŨT}w%qn Dh̢:RF3QY .};a' /!b$d( Q}gE~ 0Gxe.^>GP@a8K `-xAbe)7?to_8e">T>䛜 ~, p,gJA rLgYjՃ=R߂X* lq`7bI +auv/7N<+ɂEVz4as&kF":<ӫo`x0 &ź{XӎH(Sם<)}ȫN:F.9 6(+ >&#yJ^lj5ꀱF6P*"E;Ӹ,*C.WgB׀ rjk s96J:zpG0i$Ѐ1kP_Һ4c, JdƗAN ZBE RDHkg)ߗH2wȌ~:ѧwY3n]m3b$JH89U=@!%W B!mCT~CJ0S@wӳa?%VdA \c9YF|a͙Im܋$6(s,~LG(O^2LT}=]/ENQT*ܒQQҎ7O>sb'0~y1?̝iSXpsB)JCq" z87_elr-yX|Y91MURQI Tض}V';A"+LP_6)ԚH, +%Ʀ;6 ;vZNCje?&@VmJ8P{g6ȞuTV[YVjw|/,,@p$u"*"u݁^<0*TuLzMXH,䃰M?.`)<3>\9VM08:=ivyfZԍ[Â&ovA⑈HeeB0\!p ݹ + 4#ft@[qqYmrJ/XZa즾RgЬܕ?ivvp[VR([ M#X^z[N(Vc5ނ=>0GK&"}bDfaQE_r ;Vq~3SXiGst?v9yP[Xa0t ۢ~#0l ?bqߜ~)\Xca1:ٽ1BZ⢚)tN'i9/z#ub>V_}ڂpܙ*S[X$=ԄۅhNa">6l4Gc)0 P2j5Db(J;R4 PD}jdN/k:oOZ3r@kY4h8]+5BM.r _T-a[Z8gx6u]#rfs:H (DzÀoK$blk{dDZ$<\ӏssj-%8 X?]Rsc"UoleU{n_ 7!)P ?%|NAD]uE9zY -ʎCuI7TOnMWb>VWKX𰤐HUj~|n&@9sFO@?#Li9;z&p $%xɶ93e"t2x*2SiBp =] 8lGB}gND ԏ9e1ľ%؇*34 wҁD. ͸荗pRj 2YE~** Gҥ$ rPJ21^Q^؆4Zלqm#869TýX5BCIk\gҘ=as2|