easy-rsa-3.2.6-bp157.2.3.1<>,jY I%z .8kEfȶ͐ '۟~* @&^M8?fpIָ$ "6!|f(]Kev\ V*pP)0ɶ>i&۔WO^#*_*FC  (eE 1~ 袭tAxa dG)ӯwsO);pWvPoJw4. 77@& +馶;bC* -8, 1y N 6ZW>ְ0ؖ:qx"<K=q ?*VO0$1 VOe,PM(E+K!>^?^|d   F04@D]fw < r      x     4 L ( 8 9 `:FWUGWlHWIXDXX`YXh\X]X^ZQbZc[d\Fe\Kf\Nl\Pu\dv\w]@x]y^z^^,^0^6^xCeasy-rsa3.2.6bp157.2.3.1CLI utility to build and manage a PKI CAeasy-rsa is a CLI utility to build and manage a Public Key Infrastructure (PKI). Once the Certificate Authority (CA) is created, you can request and sign certificates, including sub-CAs, and create Certificate Revokation Lists (CRL).jY i01-armsrv3.SUSE Linux Enterprise 15openSUSEGPL-2.0-or-laterhttp://bugs.opensuse.orgUnspecifiedhttps://github.com/OpenVPN/easy-rsalinuxnoarch#JAr# %#% ; FA큤A큤A큤A큤jY jY jY jY jY jY jY jY jY jY jY jY jY jY i5i5i5i5i5i5i5i5i5i5jY i5i513ca05f031d58c5e2912652b33099ce9ac05f49595e5d5fe96367229e3ce070cd4af4a03459abba93eecff5f3cb13104b1284ecabdb91128c76d60b3d79e3ceba05c40e0f0f749cfd6d78c14777398e55a40b4a732e94ffb84fde2daa8ebd89e9e7bd1b8ab1bc087b5045d9f5b4dbf83618ecf9c8540d247032c19d5ec59c0cc892e9134f942c2e41b29476312e131255bdd8d3621e11d01f686ea8b8e12eef085561a14f61ab8371e40ed54818ba0e9dfe175577c3fb7b46b817f15bd5ef450f5ee6acae49875a044e8afb096e8513206cbabc53d4b956eea2377816cebcc2967ad21f37d5dcf18cd9bc9d28053054185277b8a696f4fb9cc47cdc606dc30112655ff6ec11b8ef447bf2a92980759b8dbb196585f4078a884360555dc760736823067527e3a49eb34e9e52d06c3414897b7b208cdcd5138abf6f5aabdf1ff0e8bfa8ba28b62cb03d57c5505d3160401e15c79bd477ce0df82dbeffb9f661b39b1534072d3450abff7fa43d13cf2ea54411c3fe28582d5741c63572ddcabdd00d95f2c128607b17d61e4e27f71399ba297ca5086e1b61523591cfd916dc4289005067a8c0a55471acd51203d68669dd80e75293ccb2fc9c37b99682606a03ce207f4975f5e34da714f2b2c62f712dd0046f5e40290055d5c5fda3d977c22e78132fdf02752f03066c38c0f6d3c290856a4c4f685cdf81995cba78b055f0eb47e5dfc4e5952e58b9b9ea7740134caf2844b7f92011800e5ff98b667bbec5ee5466862808ff286a20ce13909430596ac756c1a53ff6582a074697c98ca319df0842b7978a7b002442e4c05ef18eb0ae11b7c6a17a2932495f89ad407ab65cb85c73960f00e54397fa0869377eb83cf86d2d3de531812fbc8537fc96c7f5decd5cb89b6ed5751d80377b576dbc0ac033f9e17a4efe363edc4a00b615aa6bf4d6b757c4a4fc71745d93a87278801f1bca555562ca23f21e18293add64b9e6f6b7bf18177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrooteasy-rsa-3.2.6-bp157.2.3.1.src.rpmconfig(easy-rsa)easy-rsa@    /bin/shconfig(easy-rsa)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.2.6-bp157.2.3.13.0.4-14.6.0-14.0-15.2-14.14.3i@g gJ@e.w@dϋ@cƍci@c:@cb_G@\b@\&@Zm@YB@Y@Yn@Y{'@Yu@Ym@Y5GY)j@VU!#ecsos Richard Rahl Richard Rahl Paolo Stivanin Matthias Eliasson Paolo Stivanin Olav Reinert Dirk Müller Florian "spirit" Olav Reinert Olav Reinert Tuukka Pasanen chris@computersalat.deseroton10@gmail.comastieger@suse.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.comseroton10@gmail.combruno@ioda-net.chprojects@localside.netprojects@localside.net- Update to 3.2.6: - CI: Enable shell switch errexit in #1417 - V325 326 minor touches in #1421 - Inline sub ca v1 in #1423 - X509-Type ca: Enable 'basicConstraints = critical' for CA/subCA certificates in #1428 - Import tls key v1 in #1429 - import_tls_key(): Use set_no_clobber() to preserve existing key file in #1430 - Changes from 3.2.5: - Replace local / global openssl-easyrsa.cnf in #1394 - init-pki: Introduce configurable cryptography in #1397 - Drop x509 type kdc built-in in #1399 - Always generate an openssl-easyrsa.cnf or x509-types tmp-file in #1401 - Libressl use $EASYRSA_FORCE_SAFE_SSL in #1402 - Update EasyRSA-Advanced.md in #1403 - source_vars(): Add grep regex for assign by equal = in #1405 - export_pkcs(), PKCS12 inline: Respect $EASYRSA_NO_INLINE in #1407 - Introduce peer-fingerprint inline lists in #1410 - help: Add '-b' alias for --batch and correct default 'vars' file in #1411 - New function ssl_cert_sig_digest(); Extract certificae digest name in #1414 - Upgrading OpenSSL for Windows to 3.6.0 in #1416 - Changes from 3.2.4: - export-p12: Move inline file to 'inline/private' folder in #1356 - Restructure help in #1363 - New global option: --no-lockfile = env-var: $EASYRSA_NO_LOCKFILE in #1364 - Restructure verify_working_env() in #1367 - Improve verbose in #1368 - Windows easyrsa-shell-init.sh: Replace 'read -p' in #1371 - mutual_exclusions(): Include basic checks for --startdate/--enddate in #1372 - easyrsa-shell-init.sh: Allow Easy-RSA to use '\User$HOME' directory in #1374 - Remove 'easyrsa_mkdir()', use only 'mkdir' in #1376 - revoke: Archive request and private key files and expand help in #1378 - set_no_clobber(): Add simple error detection in #1379 - random: Use verify_working_env() to configure EASYRSA_OPENSSL in #1381 - self_sign(): Force use of Easy-RSA X509-type file 'selfsign' in #1383 - Changes from 3.2.3: - Update OpenSSL to v3.5.0 - renew: Print 'unique_subject = no' to index.txt.attr in #1293 - check_serial_unique(): Check for duplicate Subject error in #1294 - Correctly define options names - Remove wild-card pattern in #1297 - Remove all references to file:easyrsa-tools.lib in #1298 - Reinstate old function as 'db_date_to_iso_8601()' [Renamed] in #1303 - expire_status_v2(): Refactor 'if' statement to capture error correctly in #1304 - source_vars() improvements in #1300 - add_critical_attrib(): Do not add 'critical' if 'critical' exists in #1308 - inline_file(): Include DH file or placeholder, for RSA Servers in #1310 - Fix shellcheck warnings in #1311 - Introduce command line options --umask|--no-umask, to set 'umask' in #1312 - Introduce "robust" lock-file mechanism in #1313 - New function set_no_clobber() in #1314 - Easyrsa mktemp v2 in #1315 - add_critical_attrib_v2(): Move file access to function in #1316 - Command 'write': Remove options 'overwrite' and 'filename' in #1318 - Introduce option --text: Create CSR files with human readable text in #1319 - will_cert_be_valid(): Remove SSL option -noout in #1321 - easyrsa_mktemp(): Remove secondary atomic operation in #1322 - easyrsa_mkdir(): Separate Windows from *nix in #1324 - Update Copyright 2025 in #1327 - inine_file(): Correct logic and add 'dh none' for DH params file in #1330 - show-expire: Move setting $pre_expire_window_s to status() in #1332 - Always export EASYRSA_SSL_CONF, when assigned (code standard) in #1334 - Unit-test: Drop old *nix test in #1335 - add_critical_attrib(): export temp-file name as input file in #1333 - Inline improvements in #1337 - Unit-test: Minimize Windows test in #1339 - PKI lock-file: Move possible creation to sub-function request_lock_file() in #1340 - forbid_selfsign(): Compare cert serial to signing cert serial in #1342 - inline_file(): Use ssl_cert_serial() in #1343 - Inline self sign improvements in #1345 - peer-fingerprint mode: Make CA mode mutually exclusive to PFP mode in #1347 - Remove init pki soft in #1351- update to 3.2.2: * Remove redundant file: index.txt.attr * sign-req: Allow custom X509 Types * Add LibreSSL version 4 to supported SSL Libraries * Revoke remove private inline * Easyrsa disable inline * easyrsa-tools.lib: renew SAN, remove excess word 'Address' * easyrsa-tls.lib: renew, make sed regex for 'IP Address' greedy * Show expire allow zero days * easyrsa-tools.lib: New command 'renew ca' * Improve CRL expiration details * Tools move to easyrsa3 * vars.example: Remove $EASYRSA_PKI * Introduce new command revoke-issued * Bugfix renew ca and renew * Always use locate_support_files() after secure_session() * revoke: Make check for conflicting files less intrusive * Forbid a self-signed certificate from being expired/renewed/revoked * V321 minor final * op-test.sh: Disable download ossl3 and shellcheck binaries * Revert: Do not remove index.txt.attr * Fold easyrsa-tools.lib into easyrsa- update to 3.2.1: * inline: Add decimal value for cert. serial * Always exit with error for unknown command options * ntegrate Easy-RSA TLS-Key for use with 'init-pki soft' * easyrsa-tools.lib, show-expire: Add CA certificate to report * inline: OpenVPN TLS Keys inlining for TLS-AUTH, TLS-CRYPT-V1 * easyrsa-tools.lib: OpenVPN TLS Key gen. TLS-AUTH, TLS-CRYPT-V1 * easyrsa-tools.lib: expire_status_v2() (show-expire version 2) * sign-req: Require 128bit serial number * Move command 'verify-cert' to Tools-lib; drop 'verify' shortcut * Windows secure_session(): Ensure $secured_session dir is created * Switch to '-f' for file existence * inline: Move auto-inline from build_full() to sign_req() * gen-crl: Create additional CRL in DER format * self-sign: Allow Edwards Curve based keys * Re-enable command 'renew' (version 2): Requires EasyRSA Tools * bug-fix: revoke: Pass the correct certificate location * vars.example: Add flags for auto-SAN and X509 critical attribute * Global option --eku-crit: Mark X509 extendedKeyUsage as critical * sign-req: Add critical and pathlen details to confirmation * export-p12: Automatically generate inline file * Introduce global option --auto-san, use commonName as SAN * Introduce global option --san-crit, mark SAN critical * Introduce new global options: --ku-crit and --bc-crit * gen-req: Always check for existing request file * revoke/revoke-expired/-renewed: Keep duplicate certificate * revoke-expired/-renewed: Keep req/key files for resigning * revoke: Add abbreviations for optional 'reason' * build-ca: Allow use of --req-cn without batch mode * gen-req: Re-enable use of --req-cn * write: Change syntax, target as file, not directory - update to 3.2.0: * Revert ca76697: Restore escape_hazard() * New X509 Type: 'selfsign' Internal only * New commands: self-sign-server and self-sign-client * build-ca: Command 'req', remove SSL option '-keyout' * Remove escape_hazard(), obsolete * Remove command and function display_cn(), unused * docs: Update EasyRSA-Renew-and-Revoke.md * Remove all 'renew' code; replaced by 'expire' code * Introduce commands: 'expire' and 'revoke-expired' * Keep request files [CSR] when revoking certificates * Restrict use of --req-cn to build-ca * Remove command 'display-san' (Code removed in 5a06f94) * Move Status Reports to 'easyrsa-tools.lib' * export-p12, OpenSSL v1.x: Upgrade PBE and MAC options * LibreSSL: Add fix for missing 'x509' option '-ext' * Variable heredoc expansion for SSL/Safe Config file * Always use here-doc version of openssl-easyrsa.cnf * export-p12: New command option 'legacy'. OpenSSL V3 Only * export-p12: Always set 'friendlyName' to file-name-base * As of Easy-RSA version 3.2.0-beta1, the configuration files vars.example, openssl-eayrsa.cnf and all files in x509-types directory are no longer required * Rename X509-type file code-signing to codeSigning * init-pki: Always write vars.example file to fresh PKI * New command 'write': Write 'legacy' files to stdout or files * Remove command 'make-safe-ssl': Replaced by command 'write safe-cnf' * New Command 'rand': Expose easyrsa_random() to the command line * Remove function 'set_pass_legacy()' * Remove command 'rewind-renew' * Remove command 'rebuild' * Remove command 'upgrade' * Remove EASYRSA_NO_VARS; Allow graceful use without a vars file * New diagnostic command 'display-cn' * Expand renewable certificate types to include code-signing - attach a source to keyring- Update to 3.1.7: * Completely Remove Upgrade Functionality * Expand help to include undocumented commands * Forbid "default vars in the default PKI" for all commands * show-expire: Calculate certificate expire seconds from Database date * Expand help to include undocumented commands * New command: make-vars - Print vars.example (here-doc) to stdout * gen-crl: preserve existing crl.pem ownership+mode by @Tabiskabis in #1020 * Improve vars auto load * Replace santize_path() and ignore Windows "security" warning * Improve select_vars() and source_vars() * sign-req: Allow the CSR DN-field order to be preserved * vars-file: Warn about EASYRSA_NO_VARS disabling vars-file use * Expand default status to include vars-file and CA status * verify_ssl_lib(): Minor style improvements * cleanup: Rename $easyrsa_error_exit to $easyrsa_exit_with_error- Update to 3.1.5: * Build Update: script now supports signing and verifying * Automate support-file creation (Free packaging) (#964) * build-ca: New command option 'raw-ca', abbrevation: 'raw' (#963) This 'raw' method, is the most reliable way to build a CA, with a password, without writing the CA password to a temp-file. This option completely replaces both methods below: build-ca: New option --ca-via-stdin, use SSL -pass* argument 'stdin' (#959) Option '--ca-via-stdin' offers no more security than standard method. Easy-RSA version 3.1.4 ONLY. build-ca: Replace password temp-files with file-descriptors (#955) Using file-descriptors does not work in Windows. Easy-RSA version 3.1.3 ONLY. - update and rebase suse-packaging.patch- Update to 3.1.2: * Command 'renew': Remove option 'nopass' * find_x509_types_dir(): Remove excess checks * Remove function find_x509_types_dir() * For 'init-pki hard' only, always try to create a new pki/vars file * Introduce global option '--notext|--no-text' * Minor style change * Introduce command 'set-pass' * Fix shellcheck warning for command set-pass case statement * cleanup(): Exit correctly for SIGINT * Update help: Standardise output; Improve code; Reprioritise options * vars.example: Add EASYRSA_NO_PASS and wrap long lines * Use 'unset -v', consistently * build-ca: Improve passphrase input mechanism * Remove global options '--verbose' and '--quiet' as not required * Remove all prerequisite code to build a safe SSL config file * Rename temp files to reflect the purpose * easyrsa_openssl(): Always set OPENSSL_CONF to EasyRSA safe SSL config * Replace SSL calls for serial number with function ssl_cert_serial() * Introduce OpenSSL only mode: No Safe SSL Config File * ff_date_to_cert_date(): Correct the input format for busybox date * Re-order easyrsa_openssl() temp-file assignment * Stop EASYRSA_DEBUG interfering with SSL output from subshells * Status reports: Recognise Expired certificates * New function safe_set_var(): Safe wrapper for set_var() * Windows, build-ca: Add input password to re-open private key * Renewal: General code improvements * cleanup(): General improvements - Create KNOWN error exit * build-ca: Change FATAL error to warning for old openssl-easyrsa.cnf * Allow --fix-offset to create post-dated certificates * Default settings: Make default Edwards curve ED25519 * cleanup(): Exit with numeric error-code only * init-pki(): Introduce second warning before HARD removal * build-full: Always enable inline file creation * Global option '--passout' always take priority ONLY * Status Reports: Set 'LC_TIME=C.UTF-8', only used for reports * Option --fix-offset: Adjust off-by-one day - Drop fix-747.patch- fix for 3.1.1: * add patch fix-747.patch from upstream- update to 3.1.1: * Remove command 'renewable' (#715) * Expand 'show-renew', include 'renewed/certs_by_serial' (#700) * Resolve long-standing issue with --subca-len=N (#691) * ++ NOTICE: Add EasyRSA-Renew-and-Revoke.md (#690) * Require 'openssl-easyrsa.cnf' is up to date (#695} * Introduce 'renew' (version 3). Only renew cert (#688) * Always ensure X509-types files exist (#581 #696) * Expand alias '--days' to all suitable options with a period (#674) * Introduce --keep-tmp, keep temp files for debugging (#667) * Introduce Option -q|--quiet, disable information output (#703) * Add serialNumber (OID 2.5.4.5) to DN 'org' mode (#606) * Support ampersand and dollar-sign in vars file (#590) * Introduce 'rewind-renew' (#579) * Expand status reports to include checking a single cert (#577) * Introduce 'revoke-renewed' (#547) * update OpenSSL for Windows to 3.0.5- Update to 3.1.0 (2022-05-18) * Introduce basic support for OpenSSL version 3 (#492) * Update regex in grep to be POSIX compliant (#556) * Introduce status reporting tools (#555 & #557) * Display certificates using UTF8 (#551) * Allow certificates to be created with fixed date offset (#550) * Add 'verify' to verify certificate against CA (#549) * Add PKCS#12 alias 'friendlyName' (#544) * Disallow use of '--vars=FILE init-pki' (#566) * Support multiple IP-Addresses in SAN (#564) * Add option '--renew-days=NN', custom renew grace period (#557) * Add 'nopass' option to the 'export-pkcs' functions (#411) * Add support for 'busybox' (#543) * Add option '--tmp-dir=DIR' to declare Temp-dir (Commit f503a22)- Update to 3.0.9 (2022-05-04) * Upgrade OpenSSL from 1.1.0j to 1.1.1o (#405, #407) - We are buliding this ourselves now. * Fix --version so it uses EASYRSA_OPENSSL (#416) * Use openssl rand instead of non-POSIX mktemp (#478) * Fix paths with spaces (#443) * Correct OpenSSL version from Homebrew on macOs (#416) * Fix revoking a renewed certificate (Original PR #394) * Follow-up commit: ef22701 * Introduce 'show-crl' (d199389) * Support Windows-Git 'version of bash' (#533) * Disallow use of single quote (') in vars file, Warning (#530) * Creating a CA uses x509-types/ca and COMMON (#526) * Prefer 'PKI/vars' over all other locations (#528) * Introduce 'init-pki soft' option (#197) * Warnings are no longer silenced by --batch (#523) * Improve packaging options (#510)- update to 3.0.8 (2020-09-09) * Provide --version option (#372) * Version information now within generated certificates like on *nix * Fixed issue where gen-dh overwrote existing files without warning (#373) * Fixed issue with ED/EC certificates were still signed by RSA (#374) * Added support for export-p8 (#339) * Clarified error message (#384) * 2->3 upgrade now errors and prints message when vars isn't found (#377) * Update OpenSSL Windows binaries to 1.1.1g * Reverted OpenSSL back to 1.1.0j- update to 3.0.6 (2019-02-01) * Certifcates that are revoked now move to a revoked subdirectory (#63) * EasyRSA no longer clobbers non-EASYRSA environment variables (#277) * More sane string checking, allowingn for commas in CN (#267) * Support for reasonCode in CRL (#280) * Better handling for capturing passphrases (#230, others) * Improved LibreSSL/MacOS support * Adds support to renew certificates up to 30 days before expiration (#286) - This changes previous behavior allowing for certificate creation using duplicate CNs. - update and rebase suse-packaging.patch- update to 3.0.5 * Fix #17 & #58: use AES256 for CA key * Also, don't use read -s, use stty -echo * Fix broken "nopass" option * Add -r to read to stop errors reported by shellcheck (and to behave) * remove overzealous quotes around $pkcs_opts (more SC errors) - update and rebase suse-packaging.patch * fix: set_var EASYRSA in vars.example - fix License- Upgrade to version 3.0.4 * Remove use of egrep (#154) * Finally(?) fix the subjectAltName issues (really fixes #168) - Improve RPM description- update release tarball instead of git snapshot - add upstream signing keyring and verify source signature- Update to version 3.0.3 - Rename easy-rsa-packaging.patch to suse-packaging.patch - Remove obsolete upstream patches: * f174800.patch * 29d4dee.patch * b93d0a1.patch * fb4d8d8.patch * b75faa4.patch * 6436eaf.patch * e9e8e27.patch * 534f673.patch * d20d2b3.patch * 4eac410.patch * a138c0d.patch * 83a1a21.patch- Include upstream patches: + 4eac410.patch Fix string comprehension + a138c0d.patch Fix incorrect "openssl rand" usage + 83a1a21.patch Add --copy-ext option- Include upstream patches: + d20d2b3.patch Update docs and examples to fit changes in 534f673 - Adapted easy-rsa-packaging.patch to work with upstream patch- Include upstream patches: + 534f673.patch Make $PWD/pki the default PKI location - Adapted easy-rsa-packaging.patch to work with upstream patch - Treat /etc/easy-rsa as public default config, no default vars- Include upstream patches: + 6436eaf.patch Add CN as SAN (if none requested) on server certs by default + e9e8e27.patch Moved @ValdikSS's serial randomization to sign_req- Undo removal of .md suffix on markdown documentation- Add special %if for SLE11 as patch tool can't rename files. - Include upstream patches + f174800.patch Generate random serial number for all certificates + 29d4dee.patch Fixes #91 basename: invalid option -- 's' + b93d0a1.patch Spelling fixes and sentence structure improvements + fb4d8d8.patch Fix comment indicating the end of the function verify_file() + b75faa4.patch Convert README and COPYING into markdown files - Rename openSUSE specific patch easyrsa.packaging.patch to easy-rsa-packaging.patch - spec-cleaner -m (Add also SUSE copyrights)- update to version 3.0.1 * cab4a07 Fix typo: Hellman (ljani: Github) * 171834d Fix typo: Default (allo-: Github) * 8b42eea Make aes256 default, replacing 3des (keros: Github) * f2f4ac8 Make -utf8 default (roubert: Github)- initial upload: 3.0.0-rc2 (2014/07/27)i01-armsrv3 1784220324 3.2.6-bp157.2.3.13.2.6-bp157.2.3.1easy-rsaopenssl-easyrsa.cnfvars.examplex509-typesCOMMONcaclientcode-signingemailkdcserverserverClienteasyrsaeasy-rsaChangeLogEasyRSA-Advanced.mdEasyRSA-Contributing.mdEasyRSA-Readme.mdEasyRSA-Renew-and-Revoke.mdEasyRSA-Upgrade-Notes.mdHacking.mdIntro-To-PKI.mdREADME.mdREADME.quickstart.mdeasy-rsaCOPYING.mdgpl-2.0.txt/etc//etc/easy-rsa//etc/easy-rsa/x509-types//usr/bin//usr/share/doc/packages//usr/share/doc/packages/easy-rsa//usr/share/licenses//usr/share/licenses/easy-rsa/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:19585/openSUSE_Backports_SLE-15-SP7_Update/e23d96f96a4a00252b074a5a2b60a4af-easy-rsa.openSUSE_Backports_SLE-15-SP7_Updatedrpmxz5noarch-suse-linuxdirectoryAlgol 68 source, ASCII textASCII textPOSIX shell script, ASCII text executableUTF-8 Unicode textRްGPOl(euutf-8ed7183222db2b2350c061d50326b05fbe707e2c71422eaa05ddbee1fbaa56bf9? 7zXZ !t/)HZ]"k%nTHdXOXGd3k8;VڏNXSxдZ$l]8Ґ|e)GldsAoK) !zHISJقH c;dv[ 0n'J{ Kzc]tw [ / VOtgl,]O*>&[DK)*PAiԠVnk =/P{oQM'+ Kh;1^lŠ-ҋWz]5c2y^>uxFe+05k5K3*g>Tz һ|짃Y r1bf^ܩd*n3E}ߦUM`*, 5Oӂ WKف`W^2bmqhG H@$OJ?XFT^ KPvo=nE+!Cy L̃pR_>,TmTR~wmGu%l@tl=QG87R4q3_^',j-,tʊj%S`Q댵MN&5oGav3 o9 28RC1hX͊ ǔ0wUq^{9Gip=}-FS SFFR|-^Ƅ$;UOAnH 0F8#1Z ugXB+(OI0wP?x \ Vfb_X gCLM+Xk,9 o7"Uhǝ)v., 7=h@kB7m@@%hI1}ϓL٧G- 3ek@'.bƂΚnj&r3d4pچ)^j !d%b<;@+BۗqYy[hi8E ce 1YV^ME鰐AX{V G }z${oxL-Ӈn"0J%5dϧ@z{}=X/K)uɕAy/Ut`xԶEuQWF0N`;Nr!u щ fHWoLȞRy3!ۙ%?CaDy v|;vO|:Nt *yt`,Eu%X]iߎ l#b*rrqHˊQEؒeMGw\vIt|c\I5F27*H|ϲ|w)-Hk)=] Qx~3WqANu4ؑ _PnT7oTRKe9-+(iiM~%hZ\oqg?G[̀I3*/N pY惣k*n)KwqvǽL)]Ν7_Ny`48\H:Isv@S#vP)xԘHV]!l+)0J 48CtoE ,-}\ dt%W#?nEݏ_t{ldаՉp)?{βF$,.R!gNna$ yziڊ;DD j7o)q.2;(8H1*'ryYeM.DuY) r0 +C0s!dÖ۟5 RߖJrUm}N^s~d/&Jc%$BVs,5+#R'] Tw#;ڊ9p^ƥiMljҽ÷i2=[Q҄"7ɔTɞS%T1i+ZK= lguƷqF]'jTY ͸0A-UuyS{ر!9nU׬1U9 ||j96)թo Bf_RMNAd~* g@F 72}tTŢsj&"8,9C.f͸M k_kM+* R؉N7:g h`W^7p5HS,VD&]ogj7S*Cܝ9A4VbY ؀8zwײ/ Myl)!q)qodF-1$I T (y9k\s{ora <* ~f'B彳݆xԯC+dEb9 [QYqxDtޱ*jI3)Vأ۸J y9}^r׊)iqVfa<1i|ZciشS'VE@ ;TPG")t葩~Hrb}FH-=ҿ?V[4\_8 N{$ 谾bL. %^q<<`>7<Ҳ-Q@'-;f 0} ;6 ;tB0LQ/=^P$:\͋D8-!l9)*dHLLrj \}Dc'eo*yp؉Lo)Od׈|$zik)6?'9=ܠ4&($rMbʹ, Ρ,)̞vڍֹ:N ;l!la0'.;׽'m-DY`7aDydHt+ď3K1c GQ2'x.DCqr Tb1VqI0/Tz8qof5\|6Jw! C  Njl@7A1$ڤEiYfbUOAP2mER#aBNw,?Bsvֻ,w̚fnDG4?h\6B ~D5m>ژRyKn>sh%OˮGbEsQ]{ft$Я9mc]mx6-Ou1%486uUئ܏un$ D/ ݥI#PӫM+UX<X {u9̑v}8SS z@ %x./a؉uYݱa۞[6JP]V^{@MZg]06]eّ1F7tمה m,Y >3Px̦%Mт-Ko( ^va-О0$F86R4{8'q)ʧ!2lUϮkk5Upk_$iFtDUm! ^+'g.uv;]'sdƚ9ԡq0J.rbcE]Hk[6+Ŭ+ӏǝr b$Ǚ(\[M=u!y tkA<5Ԛr7J)#hyiJtz [f }VRXKw7RoQZGO4BlWtڍ2,_4/u$TS7JI^|!T(qҙ_}hO- xqox0"zźTtu)K /WWN: :|5^(}-' kV4/y[ dzec7d Oυb&tGU x#^lQS9~)riSxحoL2ߚ &֕J"^ )fdn fͪԐ' ݈łG4qHPIN2iJg$n`HFdzܠ&@ $};? =d1Roe^ Wkz>A)Y}$)N2jLX{Yn.Wfɧ '@xN en>bPC ϵS(M^ B/wAi"^n)0z'5fG-&b9PL *km>^s D4a4eD͈EvN*,=6tI }m=6q:ui^Oe(,> hO#;>")֗ d H9Ň<,D ,Vr! \ C@f־c{xf쀃MmT~so܇KtrC&Ipڔj= A‘S5W*鲥$DU-0:֛zq( Z" [l_Ygu})ՙѠ30yF U]-IyͶҞ>z+ E6)~)c>%$= }핾Wiy%"&wtvb>0{OOjjv&Z̓ʜbUJ_;“z9At[É>C'ál o(I/ #8N۞3^edNaۉU[MAgፍqOQFI/$1lˑX`A^Ѣ%ۆ!!@f,8NZ.U@:eD! Uc{VZWUr"ƈ۬ɹH1/UEWRxbPr(7r|\q4Ai{zO$Z57 G>K91CG@z;Idڌt_);Zw&'FƩٻo7'yKl/GapG=G߻7y b-d'^e$;.}7 86Õv=įM`\ <葘0BZ+魤yD񱁽w3B@C$t^h,Z='e_j8ìNӪ _ݚ͙[֕2x$w]/ 3L[¨`%% %$`'osK_2Jݩ%{o; ׯ$ );F7+L\yƥov9Fz]vJCiH(aVm / -2 \3d0L R-wMu G-LI4 ZA$h_(QPlO]eܣ4c?-)#m6.OOORFG NF%iR(f 6]!hA)CwGHh"_9LJKܔOX=;–"#$z}FM[qP"vVWǭ4|"ۜwTVKx?ZRҔǀ&*N V2]uȗYBllc‡W4oq~\už} <;=]0} (nVTHT,Z i;vS(d\NBa#UVۧLUGB\;DjogsmTΡ Q#/vh?P6"mIgHv]aY:s~Wy2H3q2+_*Fz6[F/g%?x@KT/-ğ!+pkus0cHEBVG1ybi+gWJҏENO}X+fr,̟!MVfh Uedjɖ;`qOx;M}7;k<)wEVi0YӺ˱s n{<2f񢥑F#PCOpx 84mqQPD $I>.BfױbcDr0.㼂HӫʣJd9T&3c IiQAhnǎ23S N>?SDksBV ?8ٕT.* 7 xNnkpY ]VY;2fyƾ}'#*^*TKilzYJtf-oe\i;*F~vX&GvAD,N` ?ak T|Oe6ʴ8Bef-Cs?U c]\w#WRpsyos:-v]X:b`kXқ}36ǻ_f,Ϝ^rQ]BI˙_ 7kc줢]vgtn@B1,`2^LI˖ϽEOvhLDp̟HojX/ՁQ"f,'7CІS2(Mk!֠O+nՙ\ryLzn &buUT?IRbG|@7&ޘ-[GJW&zWѲ(6ADIщӭX{.,IU+oȚ$)}9;k׵1>%ox<4$ݎL(g=\-# s2_Kk6$څ34Ԓ1wj!kmF{17-/euQ_>huKDhO`!%4APvwux;Ҫ|,0ng3N w- wJavsۄ)՚^$cfl֩-h3=Gk \˭Q <ㆆӠ'i(n^Ks$)z 2js5$oկX -6/rp,]"cyJxZsǾȴϬ2?u|OwwTX niJ)\&o;Ba2[ԈQ>}8d7,Z'Xuu԰0 rHH<2yh /Ssܟ/ъdDpɏ33cV!^[F.Ck1X lQHd~!0gPlRfVl==\3o)YoWQ(Us$h}L})!%ŕANݜJ]G|#/!Azڜ|g?T~P`?ŹCOҕӍ}d]IyJ ӿ/ۋH_OؒZ-ib;I+.w{g}oxRŴHݜ^pQ:}O0Rм]{! ]Y0dz>JaWUDxnj e$8BC=SWX\tb_VQ5mW'd"vm|q{*GdKnPF2+Z ;qڏ~P/1pZ'1t2|%/ Q:qm#U@ V[hMH=ۨ^^7C'8t/_t&݀҈pjZ%+$þ:&]-Rr jxZ*T]lŐtl!5[Evt֔/W#nJ%vYWU,?N)i^X}"6lzl7s( 5G@ qSa<&vT/<#ww PqPj\#Z`O%@9I™62&(G T%S6 zts"i-bYu6*y oO3gl'{v2=OQ]Jhմ>Ϙԃ uQ?i{zϓźUÑL Fhpb/M_R>0Oo>[>baw0spr,g {rkUѥd -׉1o(૩;lӋ6 F $i%$H"-Jxd/fXy$QOLf$zl|Өfx^2ͩHs*7F)q"8[F땶D<CHpXf'kxyWL7VkGi}Wx4P$3HS"DZGHC~Pq]- v -Djŷ7Г<5dv1]ECKF][V eZU,LFs6,c(L<ƍiW&OO;16(q.tޟ{OPQFD'lJlg=$99}])a ]Qx<##I÷ܟܵ5`/rQ+6)V@'[FQCpg-7Šђ/,jVUQ+5wYW~5B$ RLfPI=lFs>T/Wͭ&ɡ'fϧuJ}ZWߑ19hw*!m0P} $LR`6VfE4WrLDOQ}^P9)NGvjEç4)xNm /´t|q>jYRM]Ɩ1^&_$T@ vIJ GH x! faA .k1(5aEmkmxE=G 9ˆۀdg @HN6Iq<*'~%y& Ns&'; .M.H^ - }u\-S% &"u-A|'[D|RhBdDnlb*M}lGs "OC)?qu!qbX= ɰ.rbV8ړ?6W1 u_SCX.,R/4ϡcڼ ޼#*}zڧ-R)d&D@CHaҹ?K/J}{ۊF- n Y'xlhVdOEXeA(  2<ϱIgst1ѣW_coأ"ή"p43-2JoM+ɓ͔-@2IShʘw .y1ڿ'tg`?y_tTC 9'|2=nY> 2RoZFқseobUrbx!M( t{#!"QImQiy *Y jz' } YqjG_§o@$]ћ8,4CL_]%A׬Y0]L v!;%cǯKYgW.V&ҷ2ÝbN5BB|n[ɣJn;obJr\=)M.4j.03?d :Y}p[Tve-w"cOZTh~`֠w<ngoE)˶5)]b⡫s%if[@;D4D"u=8:3<Lꎴm$x|_\@>tf(~iy _nvJrzO.5gJ9{S"3Ģ?R؋ҩ&Jс7Ǡ湙 ;eh!3YLzuN.hOb] IF=N;{ٶD&iw 9WmM)xws(.Q,>™_ـWYh81ϩ<>yw8# hM<=iԬzqʚFPx&tO-vK(yiB<ÔFZAiy6WJ `5~a"a8*҇`wsa[z?B5`_e})VHsݣz;si05Dn|sk❺6n^/dgtBgG.-r.3Mҹ# 6A *hXd;E4XE)M1~Zʌ֠CµCKRg65<0n4"6wM`.Azt:&tǡuOTJȌ 4*5s5>6נmY N07 >adVn]ufq3vd,h[-NS OzPSWۣg2} fsIP1dǙK{ɈT4G*#=<5}73ՉLo!iEit=cr/36)z4J1nQs 28s0~+*Nr䖿Od!@ eQ]#- ߓ?#*v֚s!x4慑Fh8M E4nD ^W7z%꼁- 06?gʶ*jhu` 4w3ɡfI;t%>fo7;k:FoZCrM*O)pdp$c4}6{X2Q3x39jԆ5.,`]@\ʻH+j?}ƅj?' r&3_mHyG"im+j ˷JS?nY(wyIҿ7`x'K 8~|V.a:(YyhE3\۝(3jF'Kq4?| 0o12/ ?JlNTŧJvڠ&uݧz[3pKcv,`0y"vIk!FUDRF >>PGWPOvr \l^qS=y:XϚLי~Ksk{ w. pQ!/#%KO29kG(et" e対ƌBr 6>{K&٣a'*gXmҧ*U}s/h]ܖ;24 x|`[ 6}ZC(]n؜koFg2,V .OYBnfnPHD]V~; MC47nq(Prs*oP"n،jfmO(p5 z2`,HV̔ed+"tZxNswF{⺢a )*_dgj\J1x_rVERZdpn'rm7]j#NGiY,mm3 np¶2 TT'(94v4";ĐQ}#--o$G{Xʛ(m*I7Ժ5y场!c% {۸GOTaMw!w+X!b?=[>#4uR~-mֆglAUvtԬiHj_mFAA> ~˼򘔽)G’4& vIynn.h?-*۱@ڝ>T09rnr#Q#p2PD|gdlѓĨys'lծ܍c%:Oo?ƲZӰ130rcGk3-3Zj2 P\V1 kT~HK^ x%0蜐O-.w8D_ _o ]53ف*uV~zrI^񞦳Z@QPYPU^84bz v;k eƧ"ͪh[D9 =#95uť5$=;5tscaOk N6WD@P@o'=fk&N\:ڀ7"~]=31eap gFE<0Usb3s9eFCZ|c:@Q0|4F[׽uנ M𧽑0R9@kwLpZ"ǂYS̴4]VOMVW jnس*ړ\V^qb_ Տa81H* }crÔfI77#oyn[Hb/>{§[S›eTY>9-WF1Y]cN..uUSyǤ_!*%sJIܥRRF}4a3=~VZ̪oԹ6`ILaZ78pQWeP"#j`9V3gO=jӇXՒX Z[Zc 2-;}q7SzMfI ›bZv;l?y - ڣ JڷfϮ+)@c{3(](㰐gc"TġL %GC1 ,]ߜ&Sǜo.-ך>0.%촿guڠ<VA!1f6Yc|_]K$ʥΒ3˞~+7ibߎU8od hdI?qYQ|;Ҧ#.^8Ć1D~$+'է; ұH];)b\Ϭ@e iIpbrџʑq,G:aI_qК;W4؍nSY$GN$@D>m@h̦$eZCLIuRh,S /r786)\ RIoa˷!J2AvN؈Eݶ9p1X2El,7"ߡ/QP/H*q(~ a!>Ii逑/ *l`L`.-DAs.z%[~͆@zqT^!j!b^u.;j0(z k6إv|AEwˇOGWLInge_JK:0hGE)#Ӊzx}+;GC<2G 2HU`HjV?#c0kö|8;@ ҦMn5@MtP'u4-ԇC .ɇcI:3ڴID"WbƻeFRcAá[?4KEh" ]z:v>fˀz?I[ qҪg<*$O9%pl)/vM/c[XȁpJv4ūL'f9w ȉqEgXE~nhJ˶k7'Y9Ru57GNXZh(_ȓA>AZZm Kn"9W(ˇCk>~p~.=A 8Zq⭆sjSY7~kO݁^#s\b\5xUid*ǼN"noSj쥟#trA$ba:vzXk*=0RGvEփqCNgNƑmؚ5H祯߯j4J`0 6e:G)]6^unİ@``>uEzœa0^ )L?WFydYMxU7?OHY\nd``Jp-h!1L&7[hK3Ċqy.~~kЈ'E0D`dԂojw󉫵ϐL-!z0uLɲAfQw'z$(kDn ߫3:+wz[\9{RQ1 PvvM{ܱUMAXoՓÆ[^G9[x6Ac lUgatpRz &hGдt,hs%S \†#jd u8%B/*f]%^zv0'dT @Hg /&rS}qw,Ec8o c3[Iũg_@78%B3 5,O)@W@O-.}ҖL'-0x}+0nrڑ[x@b2Xz;YIŪòrh)]2,DD`|ҟ؂Ul[pdERτvq"O{L.1BByxv.ovrn1oǜ @mfBI@T$M˗欱9)s>̔%'qz7B 2'biwlp1QcaY C!BM}pY1Iaƶ -8:g+2d(zCrB,gϹpPےN؛9V11$Kt 7/vx :d'fܵu%3`hѳܰWy'g= Ƿs7-GcYkAY~-sT˔r\SD#^mv4i.)7gQkk@Yg,<|7*J@r>9}zݰ(j~3΂E영@y]s<TBݭ,@R+sF#uxX@PhtR% WeɕJg??!%敕n38C1ৼwoXJ:NC3>)w`vu<>lcfn^dh3AY ZVhG8,Rr% qt>2)⒩T`Ý$/6$Da `q6qYў 3hAA0tΑh}4ENLoS1Ɖa@v"KQ0l[z-k dn̚L0+nI1?J~V͖ [wL=uxgZ,w5rE'y;wNW )ճ ngd*f`RaLtbBJHՑ tc|3;BzxlJH`#Mhv~NPJjMC̝73z!O G}l6 Bv0q(:*cjQZ y骀 sA5{Ї?8d<"sB]uE%Rsmoі_gڵ^PnYu{.V MX+ +Cew(xnd@QT R:Ww֦3c HW=p7 *eED*4%dϜՎ$+{Mϩx$1޶5BI17"CwrfZEI=Js.D2wA0k$*ITSJ(^+ +e?Taǣ> `CRL0=QH*bpox#Bq">U#u~x=Q$̬b=q~ ̾z3V/,Qdnذ!"@ Ǎg0=T8$ DP^zz&sK*y1ճ O& 8:ct>Ip])& S^ #aG$n<`t!6\uyof܌Iv0s쿇j#DFZ<7!՝NP۰BV'I]xYv/ZG_YI2H4HB/Hٻ/`ǀn%B%BN_w5KP8=t; Cy+FCH: XU`8vwB Dw9tȕ7i;"#"7 !Z&vMDt( k6}pg(F׳*k|>MHa-8- Ehg 򑐙2bEh:f_ J+^QĨXd9]t91[7}m;^w}ʄ4QeeMtQh?XC>R8E0. <NT ý|!pNaل V6)0,na}BvLW̕P)I39 _렴xZqk qk'Ucf'e>jHv&-3)l: =f{ܝL&zR j {kf*鹩z 3'xkC !N5w|ʷk"onUUȯfNQ90Ņz~]ɍDgY<'3tD f_ku4wqTg)/qf>DNizQAZJkG[']hlv$'͕t SfwܐʿcOPx}hr\,mb[ K;LHINf27x+m+„*$zEhm ނ[~+JhU^6zqwm" vBݳXK׫L|!C*#gDzf_^ Ay{͜5 IgϯӼP%@LP W c|9ǫ.ʎJb{}ϓ%Ј1cmTѡ=h5#7TWPRr3-pns#Pd\>v+: ܺ5 FxCLku/82uTD~k$F ϱp3҈ ه)_cȝR|h/H1-!b$3=e#MU:L iňOYp|z_2?r*#0W wQfϡK8;@@T8Dw^2", _J(Oj+dћ'xŪVtg/^> &ElFw:$LF;>$X ! 2h: -J鋸f }m6m<(Wo6iI:hr\œfTFF \,CtG ,}:zSvTK gsɘZʑ12|)[j8Z0?ulMy ]Ɋ'vu/ 0IN -TO`i??DimfhJJO/*-^6[fօ&"2b6P`u欑mN ${uKh#swo;m~QRg ?>BT;,HNQUQ%{pz+d"H VN1&/l;ƌ$Hn4e Շ]NTX/2/hT13X=Q o^>p\SdqP[)g(˖ơ )rp)·-/zOx.k*R:w,{ݚA[b"1O$< ȸmFc׊qWeR(c{!"8~3*bnN {(v" _jE LKL@#H)5忎99ɥEW8ʊCw; ʚ2ۘC!D30hYS;2;GRWQfVtMV-BnӍr/3F~PZq_]SNթaV~<;7oV#̢x4N\Pu_3kɟV/W)g b3Kq( dv? [ِ|ɒRh+96| #N)[ys$`V {W!q:VVJ~п&IvsC_n-+SOlp:1m7ήLez^hv*0L__@_Ҷ YZ