xca-2.3.0-150600.12.6.2<>,`h45Kp9|ESM 4?>O`wc6(RGNuBzf->>[l?[\d     9Zg }22 2 d2 ,2 2 P222 ,2 (89 :<FNRGNh2HO02IO2XP, YPT \P2]QL2^S6bTcU4dUeUfUlUuU2vV wX2xY2yZ| zZ[ [[[XCdexca2.3.0150600.12.6.2An RSA key and certificate management toolEin RSA-Schlüssel- und -Zertifikat-ManagementprogrammGraphical certification authority is an interface for managing RSA keys and certificates, and the creation and signing of PKCS#10 requests. It uses the OpenSSL library and a Berkeley DB for key and certificate storage. It supports importing and exporting keys and PEM/DER/PKCS8 certificates, signing and revoking of PEM/DER/PKCS12, and the selection of X509v3 extensions. A tree view of certificates is presented."Graphical certification authority" ist ein Interface zum Verwalten von RSA-Schlüsseln und -Zertifikaten, und dem Erzeugen und Signieren von PKCS#10-Requests. Es verwendet die OpenSSL-Biliothek und Berkley DB zum Speichern von Schlüsseln und Zerifkaten. Es unterstützt den Import und Export von Schlüsseln und PEM/DER/PKCS#8-Zertifikaten, das Signieren und Widerrufen von PEM/DER/PKCS12, und die Auswahl von X509v3-Erweiterungen. Die Zertifikate werden in einer Baumstruktur präsentiert.h45Kh01-ch2c5#SUSE Linux Enterprise 15SUSE LLC BSD-3-Clausehttps://www.suse.com/Productivity/Networking/Securityhttps://sourceforge.net/projects/xca/linuxx86_64#JpuSp^(<L"6 T#?Q$> Yx/jir[t3%ȁ큤A큤A큤A큤h45Kh45Kh45K^~^~^~h45Kh45Kh45Kh45K^~h45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45Kh45K469e0abe17c26dd43614699b548e33de7ab3c877c677e64e80ee282f90af78a4e4681f6c6253673a3e5463466241334f5b2a27cda1341ad3cfa8dfb93e56122acfe378ca8cf7be3a4aee58eec496f0a28a6ac1020882703105cd5a2856b9b07da42caf4a54bbbe27aa45b6efbc6356c5e299b19763e728b6cdb7201b02ebbe36c7758cb9fe2a9a7b6f16b2ecde665d83d09feba5f3daa54cafeb33a3175c5bcd93cfb5e2eafa90d961ab0f14c65cbff849e3670dbbee88911473805c7791380b9c86b8d65099e8274d5f877a77dfe47525c9a4c2876951b9630632ecf00874da8919e4d3594aaa8674127fa9c09c232b33b4ac3cd065286a0a747e1eca285eafe4aa46574e690f51fd2472ce1e04f34fb99cfbb16c0f8755c3adc335ecd5361fbfd7872cce6cee3f2017d26d6d6d35d3ade4fb79cf0e95561d8e6158cdd3121bc566ea113684b2a615b8387d16784b4b1db2c58d3693dd86f73c72624e798d1a859c525781acfc4d008cc4b3f46702300dec03b86e12b2b6c79283f2f253fe749bfa15b228bfff4b303cf8e6425a8b72308e772655edbf7fa387ee04780f9f1e0735492c9b14e6021d28706defbcf68af62519707aa2cf96a1261667f77a1b470bd67de20b72a33fe682c758c2f6724469d8a8c9a294be9261ee84ecec6997ff648cf60a0065fa9f931d699bac219dd23361952a196f404adb68a3aad951833444bd0aebd3544a59a0807bcec7482c2ef25ac6ae04134a1bf300916ad0201d70d804244398e952fd405b91134a1ce532f9a67da5508baab527d6b86d4540fe95ac34f4112b8d81897819cec0eaed83e04899f01f64b553497c49a1c83bd4604ca9ea5902f6154cf62a0bdbeaced561865c4fd848653ffe175a0e4362951445fb300dcbf40658127c4f7362bce156c7886d91eccfec7fba1b7226b971bfcfecfce6f4c09861dade6254a8fa1017228395d336b35f09dea945130049cd6918ac5ab110427ce1000caee21dd1b6b1651ebe206f83bc1fb1225dfaebab7380350481c6c37d098eb1bf55ca16dd81ba3e5a9a4a39f0554e3d0713eeb181551be5b148e128af8af706ee7c21cc4005b0214a1d06262d2cc3d1ad9572e75bae0b9b7fd2f7872a19c273ff56194800965000d0c9fa117320a7f7370a87eeb631c91930b1297f698a51b943dafc626bac8032317cef616fca42182689448e4a8373cc4898a2aaad100e76390911890ad642b21cde4481f30a09b1b55739f8ecdd30c43b858e710c910b5994277e9e41ddcbab8d8a4787f402e17ba0ad6219405a832c50b3f4e1a22054a30110bd67d8920fe643d48f6a3fc721772e6993de14d499164411c4eb7db3128c31eb427da68816697ab64c0357701f4240ad6a5f568f2940b91628641f92c3e2874b39d56b115d3209e9faaad70dcbc8416582af5e95e6cc415e7f9cf777f33c576edf579f6a7b90db82ac8bc138f22c2ea882e6f0bba69ef1b33f51a267a9eaadaa850fe47872c258a135ebded1d061e710fee5bae2ff1efc9d85773d2a43e1c2e0ed52fd2ae616c0a4a1289b717af97cdb71a6c527959b582d55b4257ec31671cf591b4abcb819f39fb34c9ed49d36e341f08df6740351b8fb07cf3c7317ef76aa88e4f3a7ddce0a46eefcb2caa2cad8e43e13e93b25ea4f8d43c42dce01bd0e58a3811b7ed3fa4edbf41c54faa1477c3ac34ffa19ea0f1b87e6c823e3e78503f94cf97eb0c4f3f9fca9f2dd8e81c8fcd703e5f08e269201ab8fa0a702bf15b6d69c99312d7294d1b87b4d107a0739c30206352ee1ccc5db273edb88b2846d1ae6074dc59d0570f1ba54bfb5f96bb47a2e8325a1d308190cbe95f3ed9d1ecbe9dbdab7082199dcf928cc7e401fe452072dc781f283a97ab24e0a4741ebbce9ce0651a7675bbe4251ecac30176480693ad3f48587dcc575e7998d3a992071c16899a3157065ea939d1e63597e89f52cc02f9e6ab63ec596a031f38565681e3c9842fc6e1ae10014e932cd12b33ac189a0dc23c1b0818395065fe85164161c28a68b781acb1b6a37746d684d0478b7012418cbaa00c144a4e478a515493edb4b88b875e3fc778091440f5f81aae2a0c1d13f2a35c9824b96ee7frootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootxca-2.3.0-150600.12.6.2.src.rpmapplication()application(xca.desktop)mimehandler(application/pkcs10)mimehandler(application/x-pkcs12)mimehandler(application/x-pkcs7-certificates)mimehandler(application/x-x509-ca-cert)mimehandler(application/x-xca-database)mimehandler(application/x-xca-template)xcaxca(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@    libQt5Core.so.5()(64bit)libQt5Core.so.5(Qt_5)(64bit)libQt5Core.so.5(Qt_5.15)(64bit)libQt5Gui.so.5()(64bit)libQt5Gui.so.5(Qt_5)(64bit)libQt5Sql.so.5()(64bit)libQt5Sql.so.5(Qt_5)(64bit)libQt5Widgets.so.5()(64bit)libQt5Widgets.so.5(Qt_5)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcrypto.so.3()(64bit)libcrypto.so.3(OPENSSL_3.0.0)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libltdl.so.7()(64bit)libstdc++.so.6()(64bit)libstdc++.so.6(CXXABI_1.3)(64bit)libstdc++.so.6(CXXABI_1.3.1)(64bit)libstdc++.so.6(GLIBCXX_3.4)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3h/ge5@_p@^2@^1s^%@\X)@\G[ٙ@[GZ&@VT@V U@Tw@ali.abdallah@suse.comali.abdallah@suse.compmonreal@suse.comchris@computersalat.demardnh@gmx.demardnh@gmx.demardnh@gmx.deidonmez@suse.comliedke@rz.uni-mannheim.dejengelh@inai.dechris@computersalat.dero@suse.dechris@computersalat.deecsos@opensuse.orgecsos@opensuse.orgchris@computersalat.de- Keep serial number & revoke old certificate, otherwise the newly created certificate is immediately revoked [bsc#1240383] * Add xca-keep-serial-number-and-revoke-old-certificate.patch- Enable OpenSSL 3 legacy provider and simplify key checking algorithm [bsc#1234636] * Add xca-OpenSSL3-Simplify-key-checking-algorithm.patch * Add xca-OpenSSL3-enable-legacy-provider.patch- Add OpenSSL 3.2 compatibility: [bsc#1217722] * Fix based on upstream: github.com/chris2511/xca/commit/802a8787 * Add xca-OpenSSL3-compat.patch- xca 2.3.0 Wed Apr 29 2020 * Close #191 OID LN differs warning popups at startup * Close #189 Database compaction #189 * Improve PKCS11 library loading for portable app * Refactor native separators / and \ on windows. * Support TLS encrypted MariaDB and PostgreSQL connection * Close #182: UI not using Windows native theme in 2.2.1 portable * Close #70: cant open ics file in ical on macos mojave * Close #72: Add checkbox for OCSP staple feature * Use DESTDIR instead of destdir when installing. Follows autotools convention. * Close #172 #46: Multiple OCSP Responders * Close #170 xca-portable-2.2.1 cannot change language * Fix certificate assignment when importing a CA certificate * Close #163: Show key type/size on column of Certificates tab - rebase patches- Update to version 2.2.1 * This is a patch release, fixing Issue #159: "Opening existing database" which prevented the current version opening databases of XCA 2.1.2- Update to version 2.2.0 * Most notable improvements: + Support concurrent database access + Support ODBC database driver A detailled changelog can be found here: http://hohnstaedt.de/xca/index.php/software/changelog- Run spec-cleaner- Cleanup spec file - Use Qt5 - Refresh patches-Update to 2.1.2 * Close #40 macOS: Crash after xca v2.0.1 quit * Close #37: XCA 2: EVP_DecryptFinal_ex:bad decrypt * Close #74: Exiting XCA 2.1.1 corrupts database * Make PKCS11 libs, working dir and main-window size host-dependent * Support for XCA as portable App * Close #69 Library not loaded: @rpath/ contains local directory * Close #60: Fix MacOSX 2.1.1 binary * Add new maintained languages: Polish, Spanish, Portuguese -Update to 2.1.1 * Allow manual override of the CSR signed flag * Close #56: Duplicate Serials after Upgrade 2.1.0 * Close #57: SAN IP not working in 2.1.0 * Close #55: Calculate "CSR signed" information from legacy database * Close #55: Add Certificate counter column for CSR * Fix slovak translation * Close #50: Hang while importing 1.4.1 database into 2.1.0 -Update to 2.1.0 * Close #48: The SKI tickbox isn't generating an SKI extension for CSRs * Fix translation of dates * Add private key icon to the key name * Inspired by #42: display dates relative (seconds ago, yesterday, ...) while column ordering is still strict by age. The ToolTip shows date and time. * Related to #39: Dynamically adjust explicit DN entries * Close #39: Subject entries shuffled * Close #36: Support adding CN to X509v3 SAN automatically * Close #35: Configurable size of serial number. * Close #34: Improve Mac OSX installation * Close #27: Configurable certificate expiry warning threshold * Generate calender (.ics) files for certificate and CRL expiries -Update to 2.0.1 * Close #32: Version field contains "Created by Qt/QMake" on MacOSX * Review and update russian ltranslation * Close #31: Closing certificate details window toggles tree folding * Close #25: Certificates are no longer coloured * Close #24: Add LibreSSL support. Tested with LibreSSL 2.7.2 * Close #23: Improve limiting to pattern in certificate tree view * Close #20: Unable to chose remote database type (dropdown empty) * Close #19: Replace 3DES encryption by AES-256 during key export -Update to 2.0.0 * Open database before starting a transaction * Fix default hash during startup * Fix Importing PKCS#12 and PKCS#7 files * Improve automatic setting of the certificate internal name * Don't use remote DB descriptor as local database filename proposal * Usability: Preset remote database input values with previous ones * Add another missing windows postgres library * xca 2.0.0-pre04 Thu Mar 22 2018 * Accept drivers that don't support transactions * Install MySQL and PostgreSQL drivers on windows * Closes #10: Warn if certificate without any extension is created * Add table prefix to be prepended to each table for remote SQL DB * Update translations * xca 2.0.0-pre03 Thu Mar 15 2018 * Fix installation of sql plugins in the Windows installer * Fix opening, importing and dropping databases * xca 2.0.0-pre02 Tue Mar 13 2018 * Fix crash during PKCS#12 export * Update HTTPS_server template and add example SAN * Acceppt empty password for private key decryption * Fix legacy database-without-password import * xca 2.0.0-pre01 Sun Mar 11 2018 * Close GitHub Bug #5: Exporting a private key results in too-permissive permissions * Close GitHub Bug #4: Workaround QT bug of editing in QDateTimeEdit * Fix display of dates in the Certificate details (local time displayed a GMT) * The internal name is not neccessarily unique anymore and can be edited in the details dialog as well as the comment. * CSR signing is now statically stored in the database and the comment of the issued certificate. * Private keys in the database are PKCS#8 encrypted and can be exported and decrypted without XCA. * No more incrementing serials. Only unique random serial numbers. * "xca_db_stat" application removed. Use the SQLite3 browser "sqlitebrowser". * "xca extract" functionality removed. SQL views may be used instead. * Each item may be commented. XCA itself comments important events in the item. * Each item knows its time and origin of appearance. * Change database format to SQL(ite) and support MySQL and PostgreSQL.- Fix grammar in %description -l de. - Throw out old %__-type macro indirections and $RPM_ shell vars.- update to 1.4.1 * Replace links to XCA on Sourceforge in the software and * documentation by links to my Site. * SF Bug #122 isValid() tried to convert the serial to 64 bit * Beautify mandatory distinguished name entry errors * Support dragging certificates and other items as PEM text * Show User settings and installation path in the about dialog * Remove SPKAC support. Netscape is not of this world anymore. * SF bug #124 Wrong assumptions about slots returned by PKCS11 library * Cleanup and improve the OID text files, remove senseless aia.txt * Update HTML documentation * Refine and document Entropy gathering * Indicate development and release version by git commit hash * Fix dumping private keys during "Dump database" * Fix Null pointer exception when importing PKCS#12 with OpenSSL 1.1.0 * SF Bug #110 Exported private key from 4096 bit SSH key is wrong * SF Bug #109 Revoked.png isn't a valid image * SF Bug #121 CA serial number is ignored in hierarchical view * Improve speed of Bulk import. * Fix starting xca with a database as first arg - xca 1.4.0 * Update OpenSSL version for MacOSX and W32 to 1.1.0g * Change default hash to SHA-256 and * add a warning if the default hash algorithm is SHA1 or less * Switch to Qt5 for Windows build and installation * Do not apply the default template when creating a similar cert * Close SF #120 Crash when importing CA certificate * Close SF #116 db_x509.cpp:521: Mismatching allocation and deallocation * Add support for OpenSSL 1.1 (by Patrick Monnerat) * Support generating an OpenSSL "index.txt" (by Adam Dawidowski) * Thales nCipher key generation changes for EC and DSA keys * Add Slovak translation - remove obsolete * xca-1.3.2-openssl11.patch * xca-doc_Makefile.patch - add xca-configure.patch * fix sgml2html command - cleanup spec, fix deps- add xca-1.3.2-openssl11.patch to fix build on factory with openssl-1.1- fix Changelog - fix deps * openssl-devel >= 0.9.8 * openssl >= 0.9.8 - fix missing help files - fix rpmlint * spurious-executable-perm /usr/share/man/man1/xca.1.gz * spurious-executable-perm /usr/share/man/man1/xca.1.gz - add xca-doc_Makefile.patch- update to 1.3.2 * Gentoo Bug #562288 linking fails * Add OID resolver, move some Menu items to "Extra" * SF. Bug. #81 Make xca qt5 compatible * SF. Bug. #107 error:0D0680A8:asn1 encoding * Don't validate notBefore and notAfter if they are disabled. - xca 1.3.1 * Fix endless loop while searching for a signer of a CRL - xca 1.3.0 * Update to OpenSSL 1.0.2d for Windows and MAC * SF Bug #105 1.2.0 OS X Retina Display Support * Digitaly sign Windows and MAC binaries with a valid certificate * Refactor the context menu. Exporting many selected items to the clipboard or a PEM file now works. Certificate renewal and revocation may now be performed on a batch of certificates. * Feat. Reg. #83 Option to revoke old certificate when renewing * Refactor revocation handling. All revocation information is stored with the CA and may be modified. Revoked certificates may now be deleted from the database * Support nameConstraints, policyMappings, InhibitAnyPolicy, PolicyConstraint and (OSCP)noCheck when transforming certificates to templates or OpenSSL configs * Fix SF Bug #104 Export to template introduces spaces * Add option for disabling legacy Netscape extensions * Support exporting SSH2 public key to the clipboard * SF Bug #102 Weak entropy source used for key generation: Use /dev/random, mouse/kbd entropy, token RNG * SF Feat. Req. #80 Create new certificate, based on existing certificate, same for requests * Add Cert/Req Column for Signature Algorithm * SF Feat. Req. #81 Show key size in New Certificate dialog * Distinguish export from transform: - Export writes to an external file, - Transform generates another XCA item- update to 1.2.0 * Update to OpenSSL 1.0.2a for Windows and MAC drop brainpool extra builds * Use CTRL +/- to change the font size in the view * Add Row numbering for easy item counting * Support SSH2 public key format for import and export * Add support for SHA-224 * add "xca extract" to export items from the database on the commandline- update to 1.1.0 * SF#xca#79 Template export from WinXP cannot be imported in Linux and Mac OS X * Support for Brainpool windows and MacOSX binaries * SF Feat. Req. #70 ability to search certificates * SF Feat. Req. #75 show SHA-256 digest * RedHat Bug #1164340 - segfault when viewing a RHEL entitlement certificate * Database hardening * Delete invalid items (on demand) * Be more tolerant against database errors * Gracefully handle and repair corrupt databases * Add "xca_db_stat(.exe)" binary to all installations * Translation updates * Optionally allow hash algos not supported by the token * Select whether to translate established x509 terms * Finish Token EC and DSA support - generate, import, export, sign * SF Feat. Req. #57 More options for Distinguished Name * Switch to autoconf for the configure script * SF Feature Req. #76 Export private keys to clipboard * EC Keys: show Curve name in table * Support EC key generation on PKCS#11 token * PKCS#11: Make EC and RSA signatures work * PKCS#11: Fix reading EC keys from card * SF#xca#82 Certificate Creation out of Spec * SF#xca#95 XCA 1.0 only runs in French on a UK English Mac - xca 1.0.0 * SF#xca#89 Validating CRL distribution point results in error * SF Feature Req. #69 Create "Recent databases..." file menu item * SF#xca#75 authorityInfoAccess set error * SF#xca#88 Minor spelling error * SF#xca#87 Unable to set default key length The Key generation dialog now allows to remember the current settings * Do not interpret HTML tags in message boxes * Overwite extensions from the PKCS#10 request by local extensions This avoids duplication errors and allows to overwrite some extensions from the request * SF#xca#78 replace path separators in export filenames * SF Feature Req. #71 Add KDC Authentication OIDs to default files * SF#xca#82 Certificate Creation out of Spec * Add Croatian translation * SF#xca#83 Inappropriate gcc argument order in configure script - update dependencies * qt >= 4.6.0 - remove obsolete 0001-Fix-for-openssl-1.0.1i.patch - replace xca-configure.patch with xca-linuxdoc.patch - rebase xca-desktop.patchh01-ch2c 1748251979  !"#$%&'()*+,-./0122.3.0-150600.12.6.22.3.0-150600.12.6.2 xcaxca.desktopxcaAUTHORSVERSIONchangelogxca.pngxca.pngxca.pngxcaCOPYRIGHTxca.1.gzxca.xmlxca.xpmxcaCA.xcaTLS_client.xcaTLS_server.xcadn.txteku.txtoids.txtxca-1.htmlxca-10.htmlxca-11.htmlxca-12.htmlxca-13.htmlxca-14.htmlxca-15.htmlxca-2.htmlxca-3.htmlxca-4.htmlxca-5.htmlxca-6.htmlxca-7.htmlxca-8.htmlxca-9.htmlxca.htmlxca_de.qmxca_es.qmxca_fr.qmxca_hr.qmxca_it.qmxca_ja.qmxca_nl.qmxca_pl.qmxca_pt_BR.qmxca_ru.qmxca_sk.qmxca_tr.qmxca_zh_CN.qm/usr/bin//usr/share/applications//usr/share/doc/packages//usr/share/doc/packages/xca//usr/share/icons/hicolor/16x16/apps//usr/share/icons/hicolor/32x32/apps//usr/share/icons/hicolor/64x64/apps//usr/share/licenses//usr/share/licenses/xca//usr/share/man/man1//usr/share/mime/packages//usr/share/pixmaps//usr/share//usr/share/xca/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:38851/SUSE_SLE-15-SP6_Update/17ff962f14ce3729ebc3da990181c405-xca.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linux   ELF 64-bit LSB shared object, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=09cd159ab447f298852df77bb89fb699c8ea2c4a, strippedUTF-8 Unicode textdirectoryASCII textPNG image data, 16 x 16, 8-bit colormap, non-interlacedPNG image data, 32 x 32, 8-bit/color RGBA, non-interlacedPNG image data, 64 x 64, 8-bit/color RGBA, non-interlacedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)XML 1.0 document, ASCII textX pixmap image, ASCII textHTML document, ASCII textRRRRRRRRR R RR R RRRRRRRRRRR PPPPPPPP |5=utf-819f7d14ddf6a46082edf3d301dc0bec9eeb4decd2f034cf1e6acb080626c9915? 7zXZ !t/]"k%j+mQJZ&WGΟOw1%UU3uI+Lfl2 S>^'aݒ}v`p4 AZG+4..W>b(?B|\r7j帰ˀKOwκ fM\&hm۾& ʐpHj?+cǣ8O?]Zqc8(< |KkD6!z76Ə6Ugٺl t]m˦'rV4W҂Qnw:m}b;Z*93Ǿgpf4Tӿ^пez!֋"Jq?yJd(N2ԥ5pI5u\F7^FĚo~pRW/Vs9S7#F/.Ě`jޙȗG<(7K_9_{WTU$u}ʛpZtRr|#Ϝ6w2Jo!Tqj78jGuUo!cWMlk{y_>b}42F+D!Ek18`0"z它 jww%NFX{UϢcADN&n3"xt=v~.V\^5i|}C>''07y?faF6IFJR,&KBdҕef׫)V-GÒe)g(ѓx~,R뤂;+2sF:bA~:8$̽h;(NeHi!J%EKڎxE dNHzi̿/|˱ritNx$>$:gk $lЕ^;u UnCf X'A~0qUlum _^7]{(4zOD|3.9㥒:YUSRuvKTeaS5~i8u7-n@7? >&ǃQ{=1p/7+nc,g4!Toe?jFKLF $.+I^%q6!*+@5 ZBWKfZb(Vq '4{[KEþcK Y5u$µ0*jU\y g0J>6w64{~J:;dU _y?#)Q8S<٫hx"}8l&J:"閬$UIt aG@xxZ&J f p[T5^T {F'ʧ>o'O 0(<`U ~=Lmndg/u NdEN2%=^H~Eoؕ5mخK洖+A~VZ] vBLajsgpts4VZ_F ekty9^u]MSfZG]f~ 3XJ{B=Öa劕 jM4]%z &X [\ODuk{_|jrÂh'pf럜$8z@ԢIM,0X%C(d;Rr5 }G-9ܷ!7Zn1N'CH {;*Q}Xf-9)-I@6|AnW:h@) Z?kW_!E= 6^KnZ T}ŶTgMɮhpz.=g}*Dsu h]6dTw|zX@ܴr5ׯ8)пS} DF㠔{B̓kvVˈS#ZOZ1|ȿ5hM +`% \l 8Ga]. ԡr5Sf=-#5`r)!sx/mRI+i. ,t Jf˼<{]vP9f?R5!N֕/ O&}l^mU&zKkM{1\)4 G>:MxWHf)X80lsʽLγ>Nv^[0/m3Cz×j`DeIɓm-DWL`gńaL&}]enؑ2rbgKVyÏ2ݾ:LDU'!/xK,\93iaϴTyfq%p$T-(x5*ޞpʣy>w· H)S"Ȗi!M>iыSĮqt|!~`; N>9;&yTi潌OɝƄ 2%gU,` D"Րht~SI~X)42J=ѤZu vGpm&/7ax䷄U pm% >-ߔC}n~7 [P}MCR^m3uSOET>,>d0g7ER,] /6EKh|/mۚgz`"FC `n}s- !4{SČSqOˆ㟏4{UȺيҏB9C\ΐi.gl*Z< = ݱ˿>BHt'ZuVQ V T9dMR>k8a/R|qD,BuۅJpqrQq\}I#D$$os-6#Y 4T3mIh`Y ')4h]&E0tq(AwJו#N#y 9sf8Ē;<)CMDiHrͅ4} SIop2႑>z),Nwe砻@U u .Ќ8ƱKV-rdbџkܦivM ɞfrYf uWk|rZHZ|$^Ē@R  {0i$' >S8Oqz InB#hӒΥ8!|FEXz#zMPM xo\L 'gi~5Ix)uyTh֫GNЕfq)kM>J-(i_W2qs,G2f(:z98vyʫV`rz#+'LzP9$Mi!W4AGlK(ԝnN~_[Vف`('XI^1y&Cݟ5( ̴F.dlدM._5a߯ r/*7+D{XC!`~e$I}67v9{}5\ ƨ%K5x'RR9h6;M&M1]!ԓbAl0 }w"qHI !{W1C4>o]\$}޼Em mW\aZyR'd$~i̍ؖ+w4m\/2ҏG& /yxVn4N$'~;ovmR8 H v}vNmM(qVL7(ʨkFjѹM|KUo8H#JcsF?l]XrR0ǺjH^CA_ hTaFո!p9{d?|]K`pq9HO>'ȓ/ykNg B~Tqt;v[o1f]z":r[ ;z{/4WQԔ7Q0;DŧHr;,+x5G Z42YHE5u}5Rԁѳw2Cb!,43g8oHپqؤ ڮXJmnzl8o9;e$Ie`;!hj21M8M uG*;¼"V >>YXB>'@ed;K;k9X2 LI`BP(_ =xV&q'  j&SHu#)Bʙ)Edx9NaI˸Qvš^ei>}7RR/د8C\hwIT2dً᳅ M6FRgӰTM@ia0C"nǷ@qQRkLEݫ b[w9UG}Uj+kPV48quNZ%KTm|V|#ZwgP-qTZb[rr ?o̖fdbfP1EuK켪ROj wEX|Y(I$daz:Kޏ5Cԉ]J?_?9Cj6E3KyBdC\:'4D{&SC}.tXr ~m׏`B2wV>5 e+ ay1xS3@7I$5g47sdWx9 uP8Zwd̫$zDu6l Ft5מ/rI`7-˓br[ط$ChC  %]Arp#OmhUV֩*~  }\vw.O}Pqk*VZނ/COS#{pbSZgb1;" xU4-GBi>gBw@iְx ,ndWZ#<%sM|ԟq0^f ?Mdm}<{")AVKT"huFFou V ᒁcyGl:Z-;/ ܔTX*-c;oEZDr\kv"*+s#u;eg2'{ n=NrM=$YӇҼp 誮AXKH?D F i`hӯtJ98~ lq_MG }ɞSMs 36C0WxTHU+hďа {3P8mgRCơwҥ\Bͽy 6˒xBc\D}\H"-a㨉6Melu^QiϽ8'CAs~рJ6Qo9_r7$tؔ$[|HL2 8ֈ铗di, t}-j,1nEIR)nȮ*Ug#c : 2>OI&:؋tv@gշɦ7aa`P|d(l&5"qӞ{R۶%TRY!~ X0Jіt`D˒}*s(aű*\n|Na"nG Ѻl3ﵟܾ"!'z ȁ}oIKSOKd"ϵX_Ura6LGx%I]ߺKZ+qѮ\F@ Gc^Nn#p+/qsɱD:Bsc8[&H'<"H<{p@*̐Ϟә0lU(ZG̉%rB[9Eul4a\ܘXqzeP!f,Uod8t1DAY0Ǚ7CtW|Ӧvሗ9Ľ] [ |r^lCBh܂FϒA>?&iZHey×48e#O0DW*nRoQW$$;FD|)y H:qk0i>x"e/7hr;EWO{7^!MY|q{pjZ|Ka1  >kЉۂeuɆj]j^$ٴmp6x14"{jIM JRv>Yi8cVLQӺ[n0+U(7B\п Ao˝Z1>1A-Un/2IImT1P#4 ܀QvNgI NR9?ۉK l;3ʄFIA}UI:C-Wߓ\[%5 ixD+wwI75Wм47_xrw⸻SbFj2рڻn; .1vU^yx#MĘ|[HzQwf?W%cwwniinMkq#v5vi!Ғ!jϸV66 dcZd2# i@Gu`o@6h!:u$4;9 3r62~sA !k'-UU@.;= vs $ew2ˊ/> :cR#Ƽ# Ne`~F2=bmjN&T|ON=lpͥhiNnA}/vl?øD>{e޸R?l\=S=nS6f g>IN떺Kbd֐YE}=KJl`CF̫xE{gX"-{^~+L+`zJVɍF!=e^ѐmdՐ8`=->cg/D2?k={9>cO jٔ!x^{B~ZbKns)]`z^p0~ 8ٔχS*@l]dZm(I^J4f8]$#E7lqa8P%jNPZUܟS|0Úlǘ+#9K){O_pfz˥\Ϥe{z:^yS*LJT4)606peVQ&$(TʕҌ>en5ߞtɩtS$4 lByY1GU!AVF)Bnآ?M$!e3(e7s lcWՔ&[Ր *I8mb|F}"njRsٮM2:l{-[h[w yo8xڒzm_d㐢 >Cuqz;ɭ,zZV9cE!m-ߚIs"72 !RN^֕!7+0G?Nt>6JOM%qQV{Y9rvlTS?'~3*7 W9ܕ. D5Sqdd$?>b\]j U:4}^5HiU(gFAoC,Z2*rA ̣0(FOmt-[3׶O.b࣮^㙺oDիeyײ1"[i.<~T+mՒHX4ß!4eDuv\ZZ{G > ns`V +uB>K4gd8VJH1L6QX(Խivyk`x\.!Y&C95a֑I t{c)Wdj[كB x=0ΨO9SQ7x{Eҍq"yīY{,䙜eY:$n{ 5ޠKU`=KQ|&)ys9ʠ^J86΢K)tѮD<!/.UtPg'kT \zD( oԫ!w?qNB,WQbJmS^6t/>$AңΚM|9:* R<_E,_Oe}X5%f#f $`_—TCP~yg|T(؂Ŏϙ!'r?'whOi0L%w'rc }=#ebrW ɿ|0D,i}1찼b9@vwdj𶻛ifq X0LE++eNTJh) *~.csiAzP_\X̛}{*Z1sz :[zt9bU~@/J;W1usH7)H'saw7;hh\8i20K%ʑJk ѯ]%vH*gkO3˼;aja1蜧唰H5=|3[LO m6Q.9&\kr*]0.s:0Pze%*L"i_VYXCdnVU9$ݼ bɿ?\IDR"OzxpVq;C=k+hO6\[(@FҬ>DYbA>[t wEb>HNS9[ ڃ]G>ZXNq2}caX@Wԣ,V%vllkgEBi14lzj2.*c ^Amf47 9tv7[y<0]^G(Qy+I\0.8H%#  '")/gDXҌ,6a;E >2=! ד mr*q 9Rgf F;yN=4k{2BGj:[|;(tou6_Pg9Y 2X*em3Qm̓*ľu׻qu+`2d| 8ϲ;>$ͥ LcHGd .TXMen,G8z?ZV~ L͹ v*y ,ہs8w]*0 {j//wL8/'AI7LPKUtʚ ^:$Rou/ cxѽ^zf¶ Iq"h_MK5 .{N!t^\**HQqgzaAM[]%r2-0ɕ$pw3x\4뜂q,=?^-*(Il &;LIIC$E<; &=m|O5KT|ULH4R>TnV pkl>t)+݊M>m"ݘa({s jjSL0l*5f8podfS8۵ߨ4ygTD=")[zޏQ&4F"a"i{VpÇ+]HwU [tP2Q/a _GM]_BknmSIC V0_Rs(9>A͇QȒud-ܽ 6?4N0EQH!{ * ևyL9f"b)I(VLD#x nB Q ~OPVZ,۰^Kf s|y? NѮ X2%h3V' a@a]_/(m D\jvKŘUl_.,ļRkLtk1.w:{Bln!꿚X3EP3dt֏՘ ߉|ON tC65bc%IXsKkB>f@`-/2v='3 $2hՈi+@JO =^ &PlVD$11p WǝNd$`.%"ꈶLNӨ?}p٨П;3I%+V( bt>`<븗_3fXX_j5>7)`clޙ <UXt` eNQ !J_f{$R\̢Jo!JB DN)qs^ҪMIOS4q4奉Pfmp<3y`a,}?&W ZZ(|)ZܬAy˔gDh}RS_H۾ڬtwpR\69->0>LI"+Ո |34Jވ|2qUj֔sCwR00S0R㧭՚)1MZ?}]?Ds3{&K) r*]ҹ3xpoJ^D/br(趎gzG (MܥX Wʝ66~ .xpG8 ҁa`U>PpI*uFwеiMbS1QoH&Ziğ4 _ ԋf4!oӀXs,j*6΂*ZOd[m2LFGoKVj4[N9Al!" 5t?\X*~<]gD.ktTt]XÚۖŶf7Q)H@>¯P`c/Am<)(=J Ɓ3CW?\C1CD2؁:'clC%]a!I@7-jPŜ^1PayE _#> 7ժ+8ʒB[-!.1mUtzs# ^֒*Yn5}z8b~tH_hX2J{y@CN{q`x=}̌JCIfȫ抇)R*[ĎցP-x\t-%,`,. .%/?cN9ox3ӣdMNnƋ 4+$3eVh \wKO;-TZPNe( jCp"j9/EǩzțYWHMT=tVˮUQkp ,2LDZjҴQ4eᠹ:uR%ъ2囱`L+Ph*b'a5q-tT-UMpfC8 O B|K%o4)l{pJ~r^GTg7@hR*惝&U҃ e|7C>'򅈙QIb(ps 'j" ELW`I5 A,mRƳ9fDbUrm;w^펻}Qs)SrXC~3/ߐ jƈM8B\ok5/Ϯy]C@eZ8 Ȉb$df;[.2 \.(ρlN! y%̶ꯩrd3XAgEJR|&mP#.c߿[*wbc?FoDRYG5srOCTja_ցceI9Z-+@Lv6 BN Sg8V,ܺK @s`˝tNF{AJ>aVMx>Uov3k8]/A^މK|A>+ske-$:e5"my|mxS68VGi@yBԄvnc"EN^Չ~7KVO6 ?oNZ/a^OO%nRqz +m lraǚ³L^t}d4XM  i>č[ *]0}0 ,B=xkO EEJ KB%.y9oM0\Odvh |ؔ^:gA4oUțG2['q0݇mr]bTO.ĘARG|?U*\dWV۵O ?FK.3We*z^;Ooc0j*bybi1sDm@*Ø^*F11 8nޜVFv>C2&Z5~EA2wet $~DcDöG7,JA܏28AȔA.@Y)#7Qn+`܊.Ey6fWYvN$1Y9[|nd͉~ER;hU(KAם ^*pamZ,eF9wFT)?[2Q3T1D8_IkwBDBۂZߧ}ӱB@=FZ`0N*٣ABe%t{C+vf}t k}7K‘72C뢟 c4^ѫK 𧯩A!ebԶwašlz SWi]{ Ԭ89pJc{v@]wJ=E^+^%ַ匚=yYOR'ɣ7gD!'u[[Lq'weRF1-fI5v=*-;C1}HlD o,my'8'"[$<^ԩP5{Wqo\VċVjlQxۥ yc+qkHcnvfe4zEyD3J+*Z R(rn+ľG9ѯZP +7ѱqB7t9_rW:?A^);e ώ)LVrP忆_02 jfޘL%f2JWrlA?y@eh7 [bǴs `+Iof}X"MX4/O`U)>/! ?QaTMuuw;& jWSs8bbdMh| p5D^B+X φg2!I+'&>Au2X]AS*Y@/' L~*H˔8;1z)&z_œ)y,oQegMjҌcq ) m=u{-.: %Ieێ[Ep1/e#Ү3mXO͐Ɛbe pڕexpG-l ?5o>x >3Y*)``)i1.6=(SĖ^g`"i@Ѻ$bR89 m;UfGIu\K$}t{q kJkzJT8OR/>Z,i〃߆0./dHJC;b 7q6ZFl`{7[IȰ80v:l엁ޚFз3|,SU5n @`ګ*̳Mv }ӥ) #ݯB&Va{fG9D= Ad!{)Lԉa1VbďY߂:~[6Y@hAU!?cNy@9:^Jﲖ e+)MW g!X#%0\ߥ@.(@j +]j+ۊ5qt&X)MMqV3|ŢH1ψxQf\ŎBy?>Z.M)RW3wЊqGnH ΀!-RixM&+ܪɇwl^1.2v&1+WB "ncKm]I!P`hbIyk),S ;W &|RKĠlj?%egA`!s85Xc^o eЇ/T @$0e+`C6!0`68 X4UsUB^i祱2]zmg ۧ'E-c}xIgTJ[&[VsB?cBc(T4v yTZ)$&J|KbO?`ָ49.Z(sF:~6AjKE9\;l]HVN Qޗ \~!T-ѭ+~8Ǯ`qӡd_2슙&hpKRCSWSwna][h?`#&܅Q}<<ԉ'&L BY,ѦYC=0?-Ug)my- @]]uZ ;@!TAݡ|kH^?v@fCa;c-k zd46rHOQK7=OP1Kp@fi8_P`G4I. >fRZQRDXB#iO; b.*> ;$x8;m8jt f1^XJ@iEFlI\_ ;#J#Vfzx7jU8Z rL_0Gݺ78?ys@cFnyNܷbNJ¾M6&kcaORK!Bԡu&uO:}W-g,]*oat8.ƀOTZ}`xr%K\B)\ n"PKqwG!- MEN9o)Y\n>RXYnƬ|®/M WLAV)Q௃5D826ע|CR{[!+XD"ۀ6uᄂ.r㚜" eċ?͹m֘!P+,Iii0;;MȌ_d))4~|eE+]Q4wI419\@aXdsf"A kSia.XɄsQX|B@"XA{$mMTr;Jlȸ:&xG%'kpzTB'xZ!}ɾӲpO뱅eOHs#U69ʵ֚PCtnueXy7zlM"xC{;gl  Y7=b6Qq!KuRXc w*ݘC'xZ F!򉭓.LG7/h= Bܑ (n1ۃ+hl56Eӿx¥\%$l΀|ۂq7@cf`3|z1q1gi:s^*IۖN2j{g9H7.K#@ɭFk璄XY'*rT-̴" %=2hxWp&A]T⭺+2@t%v]AaN+-Cޭo @T m:m'gk}?_P̚\yqlKR%]P0i{I+AӒ,~F1"ʼ*h{;-iR^jE`;V-uKg Xmj\4yIh~ A"ף8fSy ۬K=4FqL[a wVkZk}g]7c/n)^3+OPGJ4 Z4W_}(gei?s\[a4dr x,\Q-]zE٠i/-S 4lKczp`SmmkloV2'H^3h;!e Ʌ'0,e \^Npz6K# Ai}lV5Ofdtex!~咒a2АC*V|W y"|O0`.4(."NVZj$3h5`vecgBB>s"oD퍰/m(8PF-Č`-D'0!XJD00*)VIlUdq嚃Q𹫔yJх_l>?hCt$#TӅgN0!N*udS6z:Ɲ(|Y9'WL PT0pnB%)k"O'˲g3)~{T},f_߃JsQ9VNo%g|Ais@`7ᄨ5wik ؎iҝN3g~fYhja^ٿ"Q0+iC~^5QY7 a@Y6USPeUOlruco*%mR?s|! 컔KQ)#f?:w+JR ͂%VsSZJB&"lN4x_qzミr{E*3ٝ& Y.iZiQ m(;62WbWXaJ޵ Z$9UM?ǧd6CۜNT['JlY͠rY~ݎͧdέfr1 ǔ ˍ`GFjmt"A{gްWx&lZuC2(ྤ|o+H5yL]Tr} n :QѤXGW "@ aHȇ1_W|"nI왼l,,  ?[ղYALF9QZfd|\#jx 693>0RJ*4M(FMZE7c%hiyfD|s6fKn[c.aQu ݞ~1~Lg :'1:wļ.8hb{g},$I:c` Kr\u&N&PPGv\i>V A I\y X1)t;=)I排?sz[e8=잢n$3;,F%ΫD ;/~W.6܂ayB/FI_>έ'ha`Z1jf3 c}%@2ڑRԫ7cU-ZߏMO;7N܏&oj׈mǒWYް45%sNK$ep7[ C; КNsd)>To "zݘ!Iu+)b쥩ᓲ04S-'x^ 60ź"WmI Q!i#`< f9ct#źJ)שA4oφ$)zoa߶v"ʀm(ɢplbs3WmԂhD:9'˙n?gVP_gCC˟We@0GzMftwnOV .R^ ԛ&-4hLg|+eRGgpJ5yt{;`q5lVAS# q [ޗnjpYNM0ʅ˽n1~Z S0gA \`\Wqٳ~9S(^o]_%`NDlA@_~6~ؙj7kTѵ9oAz!o󠌈Rq?;܌W# 2'¡jxsIe|:!g{єmKgF}Ր<6IH ĮUqoIbQDoFQPG|Me܃eV e.BzѶ'f_ǣIig]@~a0,GZ ͦۑ?6@ g.@]-)[i8kU /y5kDG&dXcKmP@g (д{;STTW+&vޕ8^*ҿ8ޠ(|x_`ͩZ%2,F>+Po/e9ӯm!"AZq,SmݠmcM{j7Uto+w",cJ}&YaZ L8 qr2d,yJɶ7fG"f\bcjϝUvrXش`D2aqu[7vx)ɜ.l|Ki; o qgnSꁡص>GAB0CԾQ ϝ=EMT'3k$BFˆBܙ~[]ZUMjߓ%|Oj <"֊TfDIVH׃A#0Ŕ @eLn"{NMQl֌r*L*1ϱՂpfIϚuJji}%&x6n2_ELTU+ylAlN@TFYj֮]?n# ZXNf il8_UcF;,GxTyELŊs}SԷ>vR?yq2SǘF fb1k~fl(.1CѶ +9gS&[Q3FdBgahP6|{W2\X9q I LkU~#JaWxX.7|(ԒӘ?.~/Ŕ5lzLݙ4p>f\&{ 5g:j |Ix+EF] 80 BOcQI=urxY.vsޤ)ҁJOpitP'^H} Ks)F;wɒǧ2*Z=I?R%qkfpOrs]t<P@[vCfcնMx'k^l5og#70FB-]N9Ӻ:*fX6#U(#}ė1K[)Z&7?D3rLgQG%fZQasBld= Y~"_xgr.NwOzM\dG 8H_",=}_ _QC^i=#XUH,d+h;7# bb\bh`xAR^UFb-zXmm="(&5 #ez̼n֒~}-D' #`h;Hrȣ[+$lUI6 OO94 aW`d"L%ڥn;QGm:lZ4^Ԣ ޮM?V$HMv;pdHJ@d৖jEJڦK I]}^iD}@+$ۊU ~9uISdשE^KЛU_53 UuوO9t:]sQI$6 ]w  ܎ɲ(8=y=$*ª.pX8_(v pa.V&Uq)g>" ,P@Z*26EAiX[-q:Sv,1$:'{ͳm1u;EO{ o:9 93aW^C.bnAf lF]hi4G}\ΈtxhIS[_*\^ewg:MxYͺ <1H , XBPG}6ߚneq :3H-CMMg}FPn#eX6&Ԣ1]niY(iܿOA𼢂Tj춒KJT.IyFL̡bG/opH.?,Iwxﵶ#ė3:JE0Q6pXه&Dh,s`;zi}W f TJZh 3o.-QHF5NxD)rQ&3/ Q`Å*JW2jdz]x>@rxHH.q啿q́;1#Qf&2ly"L <{bv9FֹB$e|۸oý/ϖ-.Iu;chW?"=G6D>ԫ$5O(xAA+7[*:+[ol%'ni^m v_?D SUB@Қ_!]yH-xu|^tC@X)6tUxs{R#F,йO:-S ?l9uG?Pe1ZCLX0_ d5(ޏ,_[ jZA $4m ySJib>?L#KATC>B"SMf-̓U1x$7taq2 q0M,&uL=ynB &} ,xFwnO g.93U.4T֠\A *&F{%Gq`)N(Z3s8z YZ