p11-kit-tools-0.23.22-150500.8.3.1<>,je:;p9|/G(HL7gvO6 6xoX+Ϳ*(`h<%^{Rc@I{5yMC&RH:ypѺ׉MĠl͒{[u=B锖xܴ}zt'#J_Lɱ>'uAJ<v ;8dY bu>.S60w| xCbpfУuL?7a{cP{OA>>5?5d % S1R_ u    U \p<(8 9, : F0G0 H04I0HX0PY0X\0]0^0b1c1d2Ce2Hf2Kl2Mu2`v2tw4x5y5z5d5t5x5~5Cp11-kit-tools0.23.22150500.8.3.1Library to work with PKCS#11 modules -- Toolsp11-kit provides a way to load and enumerate PKCS#11 modules, as well as a standard configuration setup for installing PKCS#11 modules in such a way that they're discoverable.e:;mourvedre-SUSE Linux Enterprise 15SUSE LLC BSD-3-Clausehttps://www.suse.com/Development/Libraries/C and C++https://p11-glue.freedesktop.org/p11-kit.htmllinuxppc64leP H  큤e:;je:;je:;je:;je:;jfd64b3d1329de02e2e5e8cb211bf1471da69c8c99e676ea1c29681fbaa975f4756346375a4f895a7314ed0a944bb3c5089cefb4f24f1efbb17c0b4c01f356a9f4afdd303b50c51ee2292d2a17cc45eee44667998f91be07943349e54d2a12caa990061f9c4a52c3bcff64808e66df4f6f1252c3c2a4e51cdcf4d59cf0587b0638ca25f352520a6103b86c59de016b13a7449e92358ec096a8e6a182e96788a11rootrootrootrootrootrootrootrootrootrootp11-kit-0.23.22-150500.8.3.1.src.rpmp11-kit-toolsp11-kit-tools(ppc-64)@@@@@@@@@@@    libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.26)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libp11-kit.so.0()(64bit)libp11-kit.so.0(LIBP11_KIT_1.0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libtasn1.so.6()(64bit)libtasn1.so.6(LIBTASN1_0_3)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3e7ca^@]Γ@ZX43@V@T9T;pmonreal@suse.comlnussel@suse.comscabrero@suse.delnussel@suse.delnussel@suse.dekukuk@suse.desbrabec@suse.commpluskal@suse.comp.drouand@gmail.comlnussel@suse.de- Ensure that programs using can be compiled with CRYPTOKI_GNU. Fixes GnuTLS builds. [jsc#PED-6705] * Add p11-kit-pkcs11-gnu-Enable-testing-with-p11-kit-pkcs11x.h.patch- Backport IBM specific mechanism and attributes (Jira#PED-584) 0001-Add-IBM-specific-mechanism-and-attributes.patch 0002-Add-support-for-serializing-CK_ECDH1_DERIVE_PARAMS-m.patch 0003-client-Allow-zero-part-length-at-C_SignUpdate.patch 0004-Fix-support-of-CKA_DERIVE_TEMPLATE.patch 0005-Add-other-SHA-variants-also-for-RSA-and-EC-signature.patch 0006-Add-support-for-missing-AES-and-DES-DES3-mechanisms.patch 0007-Add-support-for-MAC-and-HMAC-general-mechanisms.patch 0008-Add-support-for-CKM_DH_PKCS_DERIVE.patch 0009-rpc-Handle-special-cases-for-buffer-and-length.patch 0010-Add-support-for-CKM_AES_CTR.patch 0011-Add-support-for-CKM_AES_GCM.patch 0012-common-pkcs11x.h-Support-CRYPTOKI_GNU-for-IBM-vendor.patch- Update to version 0.23.22 (bsc#1180064, bsc#1180065, bsc#1180066): * Fix memory-safety issues that affect the RPC protocol (CVE-2020-29361, CVE-2020-29362, and CVE-2020-29363), discovered and fixed by David Cook * anchor: Prefer persistent format when storing anchor [PR#329] * common: Fix infloop in p11_path_build [PR#326, PR#327] * proxy: C_CloseAllSessions: Make sure that calloc args are non-zero [PR#325] * common: Check for a NULL locale before freeing it [PR#321] * Build and test fixes [PR#313, PR#315, PR#317, PR#318, PR#319, PR#323, PR#330, PR#333, PR#334, PR#335, PR#338, PR#339] - Changes for version 0.23.21 * proxy: Do not assign duplicate slot IDs [PR#282] * common: Get program name based on executable path if possible [PR#307] * anchor: Exit with non-zero code, if any error occurs [PR#304] * Build and test fixes [PR#283, PR#290, PR#291, PR#292, PR#296, PR#299, PR#305, PR#306, PR#309, PR#311] - Changes for version 0.23.20: * Revert "Fix RPC when length-s are 0" changes [PR#276] - Changes for version 0.23.19: * common: add Russian PKCS#11 extensions to pkcs11x.h header [PR#255] * Add simple bash completion for provided commands [PR#258] * Unbreak list matching in enable-in and disable-in [PR#262] * Fix RPC when length-s are 0 [PR#259] * rpc: Add vsock transport support [PR#270] * trust: Support CKA_NSS_{SERVER,EMAIL}_DISTRUST_AFTER [PR#265] * Build fixes [PR#271, PR#272, PR#273, ...] - Changes for version 0.23.18: * rpc: Allow empty CK_DATE value [PR#253] * build: Meson fixes [PR#245] * build: Adjust feature parity between meson and autotools [PR#247] - Changes for version 0.23.17: * common: Fix uClibc-ng compilation [PR#237] * trust: do not allow daylight to invalidate date validation [PR#236] * build: Port to meson build system [PR#231, PR#234] * rpc: On UNIX wait on condition variable instead of FD if header is for a different thread [PR#232] * doc: Add 'server' command in help [PR#229] * Build and test fixes [PR#230] - Changes for version 0.23.16: * proxy: Support C_WaitForSlotEvent() if CKF_DONT_BLOCK is specified [PR#225] * conf: Ignore user configuration if the program is running as root [PR#226] * proxy: Refresh slot list on every C_GetSlotList call [PR#224] * modules: Fix index used in call to p11_dict_remove() [PR#219] * Fix Win32 p11_dl_error crash [PR#218] * modules: check gl.modules before iterates on it when freeing [PR#217] * trust: Ignore unreadable content in anchors [PR#215] * extract-jks: Prefer _p11_extract_jks_timestamp to SOURCE_DATE_EPOCH [PR#213] - Changes for version 0.23.15: * trust: Improve error handling if backed trust file is corrupted [PR#206] * url: Prefer upper-case letters in hex characters when encoding [PR#193] * trust/extract-jks.c: also honor SOURCE_DATE_EPOCH time [PR#202] * virtual: Prefer fixed closures to libffi closures [PR#196] * Fix issues spotted by coverity and cppcheck [PR#194, PR#204] * Build and test fixes [PR#164, PR#191, PR#199, PR#201] - Changes for version 0.23.14: * proxy: Avoid invalid memory access when unloading proxy module [PR#180] * Update pkcs11 header to allow SoftHSMv2 to compile [PR#181] * build: Restore libpthread dependency [PR#183] * Build fixes [PR#188] - Changes for version 0.23.13: * server: Enable socket activation through systemd [PR#173] * rpc-server: p11_kit_remote_serve_tokens: Allow exporting all modules [PR#174] * proxy: Fail early if there is no slot mapping [PR#175] * Remove hard dependency on libpthread [PR#177] * Build fixes [PR#170, PR#176] - Changes for version 0.23.12 * Fix compile error when PKCS#11 GNU calling convention is enabled [PR#160] * Fix getauxval() and secure_getenv() emulation on macOS and FreeBSD [PR#167] * Build and test fixes on macOS [PR#162, PR#168] - Changes for version 0.23.11 * trust: Add extractor for edk2/cacerts.bin [PR#139] * modules: Add option to control module visibility from proxy [PR#140] * trust: Prevent trust module being loaded by proxy module [PR#142] * library: Use dedicated locale object for printing error [PR#148] * Treat CKR_CRYPTOKI_ALREADY_INITIALIZED correctly [PR#134] * Improve const correctness for P11KitUri [PR#152] * PKCS#11 URI scheme comparison is now case insensitive [PR#156] * Build and test fixes [PR#151, PR#149, PR#141, PR#138, PR#135] - Changes for version 0.23.10 * filter: Respect "write-protected" vendor-specific attribute in PKCS#11 URI [PR#129] * server: Improve shell integration and documentation [PR#107, PR#108] * proxy: Reuse existing slot ID mapping in after fork() [PR#120] * trust: Forcibly mark "Default Trust" read-only [PR#123] * New function p11_kit_override_system_files() which can be used for testing [PR#110] * trust: Filter out duplicate extensions [PR#69] * Update translations [PR#128] * Bug fixes [PR#125, PR#126] - Changes for version 0.23.9 * Fix p11-kit server regressions [PR#103, PR#104] * trust: Respect anyExtendedKeyUsage in CA certificates [PR#99] * Build fixes related to reallocarray [PR#96, PR#98, PR#100] - Changes for version 0.23.8 * Improve vendor query attributes handling in PKCS#11 URI [PR#92] * Add OTP and GOST mechanisms to pkcs11.h [PR#90, PR#91] * New envvar P11_KIT_NO_USER_CONFIG to stop looking at user configurations [PR#87] * Build fixes for Solaris and 32-bit big-endian platforms [PR#81, PR#86] - Changes for version 0.23.7 * Fix memory issues with "p11-kit server" [PR#78] * Build fixes [PR#77 ...] - Changes for version 0.23.6 * Port "p11-kit server" to Windows and portability fixes of the RPC protocol [PR#67, PR#72, PR#74] * Recover the old behavior of "trust anchor --remove" [PR#70, PR#71] * Build fixes [PR#63 ...] - Changes for version 0.23.5 * Fix license notice of common/unix-peer.c [PR#58] * Remove systemd unit files for now [PR#60] * Build fixes for FreeBSD [PR#56] - Changes for version 0.23.4 * Recognize query attributes defined in PKCS#11 URI (RFC7512) [PR#31, PR#37, PR#52] * The trust policy module now recognizes CKA_NSS_MOZILLA_CA_POLICY attribute, used by Firefox [#99453, PR#46] * Add 'trust dump' command to dump all PKCS#11 objects in the persistence format [PR#44] * New experimental 'p11-kit server' command that allows PKCS#11 forwarding through a Unix domain socket. A client-side module p11-kit-client.so is also provided [PR#15] * Add systemd unit files for exporting the proxy module through a Unix domain socket [PR#35] * New P11KitIter API to iterate over slots, tokens, and modules in addition to objects [PR#28] * libffi dependency is now optional [PR#9] * Build fixes for FreeBSD, macOS, and Windows [PR#32, PR#39, PR#45] - Changes for version 0.23.3 * Install private executables in libexecdir [fdo#98817] * Fix link error of proxy module on macOS [fdo#98022] * Use new PKCS#11 URI specification for URIs [fdo#97245] * Support x-init-reserved argument of C_Initialize() in remote modules [fdo#80519] * Incorporate changes from PKCS#11 2.40 specification * Bump libtool library version * Documentation fixes * Build fixes [fdo#87192 ...] - Move RPM macros to %_rpmmacrodir. - New server subpackage - Change keyring to new maintainer Daiki Ueno - Avoid bareword to fix build failure - Remove obsolete patches: * p11-kit-biarch.patch * 0001-Support-loading-new-NSS-attribute-CKA_NSS_MOZILLA_CA.patch * 0001-Fix-a-typo-in-x-cetrificate-value-see-also-https-bug.patch- Also build documentation (boo#1013125)- support loading NSS attribute CKA_NSS_MOZILLA_CA_POLICY so Firefox detects built in certificates (boo#1154871, 0001-Fix-a-typo-in-x-cetrificate-value-see-also-https-bug.patch, 0001-Support-loading-new-NSS-attribute-CKA_NSS_MOZILLA_CA.patch)- Use %license instead of %doc [bsc#1082318]- 32-bit compatibility fixes: * Add PKCS11 module to p11-kit-32bit (bsc#996047#c39) * Add p11-kit-nss-trust-32bit NSS module * Fix potential bi-arch issue with private binaries (fdo#98817, p11-kit-biarch.patch)- Update to 0.23.2 * Fix forking issues with libffi * Fix various crashes in corner cases * Updated translations * Build fixes - Make building more verbose - Enable tests - Small spec file cleanup with spec-cleaner- Update to version 0.23.1 (stable) * Use new PKCS#11 URI draft fields for URIs [fdo#86474 fdo#87582] * Add pem-directory-hash extract format * Build fixes - Remove 0001-trust-allow-to-also-add-openssl-style-hashes-to-pem-d.diff; fixed on upstream release - Remove autoconf, automake and libtool require; unneeded dependencies - Add gtk-doc require; needed to build html documentation - Remove redundant %clean section- remove patches: * trust-Print-label-of-certificate-when-complaining-.patch * trust-Dont-use-invalid-public-keys-for-looking-up-.patch - new version 0.20.7 (stable) * New public pkcs11x.h header containing extensions [fdo#83495] * Export necessary defines to lookup attached extensions [fdo#83495] * Build fixes - new version 0.20.6 (stable) * Make the p11-kit-proxy.so module respect critical = no [fdo#83651] * Build fix for FreeBSD [fdo#75674] - new version 0.20.5 (stable) * Don't use invalid keys for looking up stapled extensions [fdo#82328] * Better error messages when invalid certificate extensions * Fix parsing of some odd OpenSSL TRUSTED CERTIFICATE files * Fix some leaks, and memory issues * Silence some clang scanner warnings - new version 0.20.4 (stable) * Don't complain about C_Finalize after a fork * Fix typomourvedre 16983152090.23.22-150500.8.3.10.23.22-150500.8.3.1p11-kittrusttrust.1.gzpkcs11.conf.5.gzp11-kit.8.gz/usr/bin//usr/share/man/man1//usr/share/man/man5//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:31290/SUSE_SLE-15-SP5_Update/d2461017bafa557a22e90431a0c28c1a-p11-kit.SUSE_SLE-15-SP5_Updatedrpmxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=27c908503b28c7c18975ea0b0207d11c8851ce81, for GNU/Linux 3.10.0, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=e5a72d965218ad0a3b152096ce2eb782c8f88562, for GNU/Linux 3.10.0, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) RRRRRRRRRRR RRRRR RRR0d9ږ+utf-8550b689dc96f6c0afc58bd591021d4b567e7e1ad72c5c54a07ec630c754da239? 7zXZ !t/D0]"k%$P x3OS,פ_'X P\y M26\GPCsxq4Sj[L=`w::Wf/ͧ>5D0k7LU `:WF2ZJZ'oqg%IX);DQ[B`m#.bfOO嫌3nn~ܰЂIax{ L51 ♊b"K2W^5|1hqQݘa4I:sZn#1 -I! (E=-.Ce $݀zS06' 5(,aAb/-zaGǧcJV{Ad>.G,7]A ŅCyVܔ.I Xƪ&;3S!TLh<|ǎUT q0H5Z/A7KL#^pisusweWtee-|Z<[ r%{NMvBzmZᶧ,YL$}+gB-3ߗ*ZB<[Bz9UKQ}WnsAd;d҅17̖_lb|\ SM6IAE'O"R<ʬ{ǁx .(&c,tU")>%J|L#z.i 2\a<➚E6'Y. zH<3!yz~o`u:u'D-y:߀b uiX1vD+~B`Y8nw#+m,P+~Ay=]f(c髕<,{bB'bVfbzfŤr^[)fus0n;ؖ Y?}PIłm|/ _H-xO)ћ{Ix,Tn,@~F2,Dr0ڀUmhrUEƊ6T"t&-U\S(Rd,a]+;9+]T96 ^!btf ?( 35U1PN9JP1+qSͧ.HǨ39ABLtE/aD~: ~3Sx8J’&z*ontvL6E9X ALӪ+Cs^' !4Hx$ְ+u>zgXɐ/;@[(f)gu<(77Ǻ"H Y MrKh) *;KW*4{4AeG9!(Tn9*!gyϽjq o\Gz`nLiN re5roŌSmA-~`فn[|Wj^#O;Ok[d,b>s]cE7r$DPȅM(n!P5EqD0b B(.LYw`sɾ[n^#-UZ5J0AgTc=hA] ǯF֜یG>Cy.iZZ~aJ:v`(>\2A;j׎lls;jҗ/UH*62NGy"TR]ꆰ>`F;NG,@ߵ5ob'304iܬROR2HJvUB`DޑCc IcR^|8i70k7 Y2c@7<h5@IY.𨻓s%H\GڿSlH̚/r㝳[w?#'N}!Z gk<3BTB'^xk+yYgIkNE_7X{үBdMA+a;sxLjl;LP kO?}qyz) Uڭ8fJ _)gzTY/3f0 :庰a/=O{~Ɛ3ǝym !l+1l:esR^ r;gHXwZCCkѷؚF $*̥M6>V̂"))bpF}R;?y\|L":4V+6DuObߊϒ6?;FÅ94 l>]hvȔJi,]dB0BR8UzdWě1CkVЙqS] Ly4b% 6cAƧ?ģh|h3iLAVBsk4#&I[V:>&Ԕ؂K:6\Ά49`14C)9H76=qTbG69d#lԳxA)3Ҡw|آ\a5ҹ{I')AzMm :uK ';;!F-cW\]Tx/Z-{~Ά4>#  .TN<{ҪWty݄Rd>ը% 4ox~[7g-x{P]OF35y5/ 0YxߜsЭ|ص&:ܧJž/5]ɢVw7\ eN/ 9)Z̙wKdqb\5KD*+ VcBsn zl'?hV~7w<S(2>P5_S7Ǧ@ޱ! [Z}UBd]]ro3D]jwKs6 B{$ag)ݔ UC˟Wx9|slJ:L8 M z +X}S`_cb?TtͱUzz}a1IDVuQ[&KHs?Ԩ{q/+S_AHĵ*+Oٞ)I-#0 SV8J?qWTd2,4KЁPT$ljlA)/jw&13St`QOG[vt$Yo5Jy E aCiI z0LQR2Ѭd I}z3ϴT\_OivizEmb?,d+Z?<ݼGfvKM Wx"w@ӡ U%M n~Tpw,[/u((V#~@% :\Q,/U<BsGLM,֮sJLgI( U牧ؙ/{BАvu!n"J7ٻieQL}np J͒ BBL7|+v8x2ȌSy ǡA+NR<iyGO'l"So1_ݕ'^LT@!:㪡 1 (1E@q2x#dvQL$>GwoGs%OA E8{_(cQ2bj07Vj27WJݢU3=J_-9 |-bYpݯ@;bfg1r.ewdL3T:@¨[`eh[+G;XlYxz;=@"N@PUw?%SKܘv% qaTvyMδ3۵"_+N蟬i!BZCV81Mx y(kiku?C:$"lhcfV41-h*XƋu4' bpC\ b4˚4aǹ'/!ERP=oMv2-ŏR•UؿBÉ8V :$7wQ9)сY/Չ{k;Jaī Q8:(lII>@KumuKy6ZVTC$G6Kh]%"ņ&LjyL_B-p#1F1J_d}1]X̦SDx>HmV #nYKIzWwp`Ð..`1OJYfɩ[,uQn6u ;v=XQ8Ba;6vR{ , eH<8F !3=쏼̜'tkp㙺;Á 8f] ;~TLI=xe!xjD5Z'-)BqM8de4a ^Uuwtx A7Ǣen'Sgة=mWh;1Àq!7U?XL ^J|^-n_qDn37#ɖY3oۘPfV/[ Z7GC/0;~Q2_pFG&)0սQͼ4=Ii4 I,5&1 /ʿK߭xg*~D^hfd x0\DLQ(cl@tZ@Z}}0D%c 0tרdřLc;Jh!)@朜FzꎋiAE-Uާg*r@j9ĩo?İPiJi8Ν/&Z GW|^]/{MF}G~nixY,xt0e SSDK]l36\欋scm)U"N^ Y “ƺ-L3-$n6<ٗsM9/e^eT|?,|Krǒ*p`Y I! 1aN1+C_S}gE>^sMyN=Pxloa1ޔ~t(QH.Z +hj!\t7TYiž$g̥<[ z(IZef @2bLRW-kUJ1T?J.ɽ7vn-isL4P{= s羲g<NwUK,e{WO?1\%~ؠ>jd8_Ǩ|3鷌&5=V}0**3*mP*`X }r/!n"7Di{ gcc$sGkQk5(KVy' 'j1|C4rݷtldU8^Q+^PM:5"sݟ3NXr食g(4XDKcKᘣBټOɸLzZp=H(y1:kpTjxz>?bA㛼ZQQ, ]~zеteӺJfYgrlP፨9eDݝ({ f݀&Hݦ p?nCŐ$1 c{oطӊVjgp ktGzł!gvX' <NniK8ƾVCYO6ke1"M&}L0O0 _: Ő;LAIܣ}]]s #LkMa.o#$) )Qń! H Jйݛ>zVKe9,qjEi?Fp`UBv=& S\ Ze" O)-o+t^n%I]gWHGAyy5xBDC.߫ QiFVi *}`Yq#QgDm ]=7ÊZҮ~Fq@E@p8(C=YDSXwYqp1!*}g1vPqFɿ>C'L&;~f3Mj 6I8{Ã?FX/Z@bn휊Je3AٶC2ŶyzJ*b%PRK:b@?2+7v&\?f ewFF4q~y$dFsO9u@FX\7|cI"3&cR.)? !9/a,(ݫĘ9{\ȘS订;+ yfL?ld fzM,"" - P9U1k~!zPy-D "o.8#% 83_fk lڃW#-!>rL#?Ud~ғ^Q[*T+J ̗N]r5Goʜ>HE&Rzj-?'6&6tesr/o徵IEW(;@Ƨl%c:R0HWn"scLƞҡ drڮ ̴@ض.1SLCa]TʕEaOy!PѝG6)"X2SYetzbP.^isEXp ƈe'L[`ciGA(PmEp(uDKAKwp{rVl'u}>PSO>$I&7X%Sp,ma0P[%rҔ0n}v[v{:!WA ˅0 ١,&GmTG#w3夙)+!> >)/'r6/'J:~O8k! /JHz>dQzg&T6~z(?]zrǚ ldU1: l!''7Һyv ]\~ 4.0aޙ|}xK,>2 AZE1&?xn盤qX㜳`Q񹣑O]9o2T^1h={Qw" &}_.ϖC'?bR^7FZ xk" lff!fi4$Ĝ<7!{9;ʅajНx鲫w'bPS&8,3I4UƖr ۙvB DE$t{mYN9Qyf{t{hΎ]uBէESfxF{kl_"h*#)yu&=(^,nB68_5^a$@0$[ K1;TWNI\]2 fbKhY{{Z,XhUkzs)=:ѿ@7Y.0Q?1aP²{mIeyyө<5ʹi4B|a('A'1J!7k-0 o['2YGk"]\4_܍iI&o$%dg9e(RޢyȢgYߨ/?ҿ$@#F$5y$`Ke mrSs{ y<%GFlW Y#3xî2U (klۭ%Zn1kXvXy-avK.)Kv)']DMK|J9qV3[FRv }8ոYLTŔ7fp,V0GU@sRi 5Wt Z([ Gw2E$=n־ljuwYc GT8TfAOMR}uDkڒ!Pk2Z//^('g+V' 1:v}O 41*9 ^8+-gʏYXUGϩꏐi66o*19~+2OjE#3")_D`mXm~f0D:@%"SͼĠVAQ$bHQ rzj#TCH}S"9h oyz ܻ9^kmhܺ?'NZs[F_?zbĊ*f{ߚm<ϐ?/։keO,nܳ5M=u#SNc%ܣfP҂FDYd3ͩBN˝rM픗Up+ŵ&^j*tpoZF=2nrPFd_vd\<2S5=M˰A?,1mgMhl&~:wz j-*F.Ew[jFT{-pqNHfMҰ8kB;`KǜVory$l*gx.-v(YR}F֔PyzU*:b-BݘEx5Y`}}dfZ$o:UEU_58j7PZlAnDz+6Ʒ ɜBR`?̧Ac*Hݼ:_)Wz X&җ#z.g(CAנ $sҚ==^ԢnD]T_$?ja8nd]ߋգ)K)-x5j a?RU5f;""~W1Y9lݞVb.d 5+{~AE[(_ctU% elIZ@h5v H߅C1)E7*sc~[L "L7-!=Qk3%Jbwvu[C0o~W 9d@UO5Mrs*D "!Z>yw>VzʉbJ<$'[W_1LՐ=2 x_i%2sޓ?X~ neTaZi58Xk~L2:,rH.L(3襂K6{SL%~+Px$pDK1ɱյգ~s.TF0yAI )b^cTUL+^}Ч`NYV"43L'`&AjXQ Fzn 4^Z9%gJܣϺ\~g=<į"fb d-y?Ž-MTanLBm3o7Uh6_ٍ"!?gY2W5

{8d`U6Ͽ #/K s7 ȋ 8HAJqmuĕ38\?`06~:EJAO~k}CFOh 6,9 oNA24]hDF,Ȱ~&3+pOI*D<ΫǵEkA)Z}_Q.*^`=7:jyЄtw, s[4e11 o2y;RοY5bHT#R9X zĥ`e/9*9G_U4)lG 瓎B7 | ",:l[!H iNk/8dҏU5)=V*:euW1u"| M'J2d2&S:[p=JB,K㏎b=HChϊÄo]Ԩ}/> 1I6ټIS)(䇐Pk +B -%PC?t\@ԏ* f\%Hz ⨳y1aƨF0:wnʓaGjejj*PU)H~6>x hxo_KwЃ#z+q0VHQ?7] emJxĖ[ 'wXƻA{>{U2qʼnt}e{|0oدtCB:]r cn]W?V6t-ʧ$truiUM (,h}=@NtOniR~C4ͺ"4 Wm9f}Zt ZZah\+gS['.|j}Wg--sVNkEfk Ey/{,r˽# :HyYYӪJ&qw5iö7Y!47=#"6OM[ 3$dX7!A?™ʌ%6E~>]X֫1+Mx=ft8몲$#VBg#0J[}].So< Η9 qFtztYr &eq @|5n g62OXq)aEa#) YZ