From 17c9a2e3c10ecc5552d06202eeaa02034fcbb52b Mon Sep 17 00:00:00 2001 From: Victor Lyuboslavsky Date: Wed, 16 Oct 2024 13:37:15 -0500 Subject: [PATCH 1/7] NDES SCEP proxy guide --- articles/ndes-scep-proxy.md | 145 ++++++++++++++++++ website/assets/images/articles/add-scep.png | Bin 0 -> 21651 bytes .../images/articles/ndes-scep-config.png | Bin 0 -> 77281 bytes .../articles/ndes-scep-failed-profile.png | Bin 0 -> 45691 bytes 4 files changed, 145 insertions(+) create mode 100644 articles/ndes-scep-proxy.md create mode 100644 website/assets/images/articles/add-scep.png create mode 100644 website/assets/images/articles/ndes-scep-config.png create mode 100644 website/assets/images/articles/ndes-scep-failed-profile.png diff --git a/articles/ndes-scep-proxy.md b/articles/ndes-scep-proxy.md new file mode 100644 index 000000000000..60f5e57aed23 --- /dev/null +++ b/articles/ndes-scep-proxy.md @@ -0,0 +1,145 @@ +# Configuring and using NDES SCEP proxy + +Fleet [v4.59.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.59.0) introduces support for NDES SCEP proxy. This guide will walk you through configuring and using NDES with Fleet acting as a SCEP proxy. + +NDES (Network Device Enrollment Service) is a Microsoft service that allows devices to receive certificates. SCEP (Simple Certificate Enrollment Protocol) is a protocol used by devices to request certificates from a Certificate Authority (CA). + +## Prerequisites + +* Fleet Premium with Admin permissions. +* Fleet [v4.59.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.59.0) or greater. +* Apple MDM enabled +* A Windows Server with AD CS (Active Directory Certificate Services) and NDES installed and configured, including the certificate templates for the certificates you want to enroll for. + * The default password cache size for NDES is five passwords. Increase this value to account for the number of devices you expect to enroll simultaneously, including devices that may be offline and need to enroll when they come online. + +## Step-by-step instructions + +### 1. Add SCEP in Fleet + +Go to the Fleet web interface, navigate to `Settings`, go to the `Integrations` tab, and click `Mobile device management (MDM)`. Scroll down to `Simple Certificate Enrollment Protocol (SCEP)` and click `Add SCEP`. + +![Add SCEP](../website/assets/images/articles/add-scep.png) + +### 2. Configure NDES SCEP settings + +Fill in the SCEP settings. You will need to provide the SCEP URL which accepts the SCEP protocol. In addition, you will need to give the Admin URL with the associated username and password to retrieve the one-time challenge passwords for SCEP enrollment. + +![Configure NDES SCEP settings](../website/assets/images/articles/ndes-scep-config.png) + +Note: +* The example paths end with `/certsrv/mscep/mscep.dll` and `/certsrv/mscep_admin/` respectively. These path suffixes are the default paths for NDES on Windows Server 2022 and should only be changed if you have customized the paths on your server. +* When saving the configuration, Fleet will attempt to connect to the SCEP server to verify the connection, including retrieving a one-time challenge password. This validation also occurs when adding a new SCEP configuration or updating an existing one via API and GitOps, including dry runs. Please make sure the NDES password cache size is large enough to accommodate this validation. + +### 3. Create a SCEP configuration profile + +Create a configuration profile in Fleet that includes the SCEP payload. In the profile, you will need to set `$FLEET_VAR_NDES_SCEP_CHALLENGE` as the `Challenge` and `$FLEET_VAR_NDES_SCEP_PROXY_URL` as the `URL`. You may also set `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` in the `Subject` if the hosts were enrolled into Fleet MDM using an IdP (Identity Provider). + +Example profile: + +```xml + + + + + PayloadContent + + + PayloadContent + + Challenge + $FLEET_VAR_NDES_SCEP_CHALLENGE + Key Type + RSA + Key Usage + 5 + Keysize + 2048 + Subject + + + + CN + WIFI $FLEET_VAR_HOST_END_USER_EMAIL_IDP + + + + + OU + FLEET DEVICE MANAGEMENT + + + + URL + $FLEET_VAR_NDES_SCEP_PROXY_URL + + PayloadDisplayName + WIFI SCEP + PayloadIdentifier + com.apple.security.scep.9DCC35A5-72F9-42B7-9A98-7AD9A9CCA3AC + PayloadType + com.apple.security.scep + PayloadUUID + 9DCC35A5-72F9-42B7-9A98-7AD9A9CCA3AC + PayloadVersion + 1 + + + PayloadDisplayName + SCEP proxy cert + PayloadIdentifier + Fleet.WiFi + PayloadType + Configuration + PayloadUUID + 4CD1BD65-1D2C-4E9E-9E18-9BCD400CDEDC + PayloadVersion + 1 + + +``` + +Upload the profile to Fleet in **Controls** > **OS Settings** > **Custom settings**. + +When sending the profile to hosts, Fleet will replace the `$FLEET_VAR_NDES_SCEP_CHALLENGE`, `$FLEET_VAR_NDES_SCEP_PROXY_URL`, and `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` variables with the proper values. Any errors will appear as a `Failed` status in the host's `OS settings`. + +![NDES SCEP failed profile](../website/assets/images/articles/ndes-scep-failed-profile.png) + +Note: If the uploaded profile is signed, Fleet will replace the variables and invalidate the signature. + +## How does it work? + +The SCEP proxy in Fleet acts as a middleman between the device and the NDES server. When a device requests a certificate, the SCEP proxy forwards the request to the NDES server, retrieves the certificate, and sends it back to the device. In addition, the SCEP proxy: + +- Retrieves the one-time challenge password from the NDES server. + - The NDES admin password is encrypted in Fleet's database by the [server private key](https://fleetdm.com/docs/configuration/fleet-server-configuration#server-private-key). This password cannot be retrieved via the API or the web interface. + - Retrieving passwords for many devices may cause a bottleneck. To avoid long wait times, we recommend a gradual rollout of SCEP profiles. + - Restarting the NDES service will clear the password cache and may cause outstanding SCEP profiles to fail. +- Resends the profile to the device if the one-time challenge password has expired. + - If the device has been offline and the one-time challenge password is more than 60 minutes old, the SCEP proxy assumes the password has expired and will resend the profile to the device with a new one-time challenge password. + +The issued certificate will appear in the System Keychain on macOS. During the profile installation, the OS generates a couple of temporary certificates needed for the SCEP protocol. These certificates may be briefly visible in the Keychain Access app on macOS. In order for the issued certificate to appear as trusted, the CA certificate must also be installed and marked as trusted on the device. The IT admin can send the CA certificate in a separate [CertificateRoot profile](https://developer.apple.com/documentation/devicemanagement/certificateroot?language=objc). + +## Use case: connecting to a corporate WiFi network + +A common use case for SCEP is connecting devices to a corporate WiFi network. Here's how you can use Fleet's SCEP proxy to achieve this: + +1. Send the root CA certificate to the device using a [CertificateRoot profile](https://developer.apple.com/documentation/devicemanagement/certificateroot?language=objc). +2. Create a profile with a SCEP payload and a [WiFi payload](https://developer.apple.com/documentation/devicemanagement/wifi?language=objc), and send it to the device. + - The `PayloadCertificateUUID` in the WiFi payload should reference the `PayloadUUID` of the SCEP payload. + + +## Assumptions and limitations +* NDES SCEP proxy is currently only supported for macOS devices via Apple config profiles. Support for DDM (Declarative Device Management) is coming soon. Support for iOS, iPadOS, Windows, and Linux is coming soon. +* Certificate renewal is coming soon. +* Fleet server assumes a one-time challenge password expiration time of 60 minutes. + +## Conclusion + +Fleet's NDES SCEP proxy feature allows your devices to receive certificates from your certificate authority's NDES service. This feature simplifies the process of managing certificates on your devices and enables a secure and efficient way to connect them to your corporate network. + + + + + + + diff --git a/website/assets/images/articles/add-scep.png b/website/assets/images/articles/add-scep.png new file mode 100644 index 0000000000000000000000000000000000000000..711ae17495cd067767cb9ca1817fd117104ca903 GIT binary patch literal 21651 zcmeFZXH--B*Dku%Em%NAKoAfVw}7Gd7KqXmrAY4}AOxgICsYg4i%4%ldItfeLsSeU z0U|^RHAqQ9k0gN*>J9Gyd+$5Wd%vC!XN$iYBb^rQ{`$+rN=NgaNwD2UK};*}{hU@=Wq&+_m{GVp$2Zt-dH$@Cjh63VCV2=txKi0?aRr{|F&dwT`e#%R@9Kd^tmZB>{b z^w#W%t?8^Wth%-O*uE&;=;56*`mU;HFOqip`ApXvsZwx8{;=!@s8I;Do0`yH7+fDb4>u>7rj^5v5BcF~2CDWp&qqJO zlN4rcySB$wXoALOLQr3aM%ws32MYGvx2O7tXAto5fx{cU1XMT;12^ya^t2H!zaKO% zx1j<{0LM0A7@+Ntd+E3~ygbsh6&e~5Vt_q^l=|n{$B>=&MhafRT_9I#v0&lR+^%io zKm!JV3@+F$Xg?fbjQ1PqtPcKNBqaE>MTn%bwa4SVonEF)TKu_z>~tNkW$9=chHoFD zD<1a$NpgT3OrEdx|QX5#kCm``ZI&Z{Cjpxtl2w&Qj zZ-{91GQctdK_GjNq=gT+3?xETe*P9v)tR>T>Xfkm`EYtO_(A(IUBnp;fB@<&3kT>B zz6u9Ly3B8O9UK(H<7+%jG~t_f1_ADTC{ouE zKs$2~=eeeA)IOnJ85*WE@Nyg^>33uMY=-#=#so@E0Irr|K1JK;N%S@GV- zL=v3JX;l>LwpU}jR-TK`gp@aJClN)_I`_xilVIx>wI4{C@YWs$Xiq71X1)6uzTlog zvo$?cEcA2`q$_f?2#U0}3E$YDt&$?z7y*W(emnCqks=tn{wG(13jH2dLF_!@0uYo+ zC!Ac%FkL*=GJ^p~f!EgQxKN1N(J_$Q5Y=ihs|}USb$kNqk6v z8iZFeU#h|DFgrn4ULIzl#EtNJ8TzV+@5cV|J2h-?~oRuHzN@T-23 zp;N#2NI&Y-(Q2f`PqO}C`$Dy~)dtdAEeYb|H9qHqIb*vo5He*6Tg{y&)SS5VowC$y z!kJ5IRpdqeY)e32gBocW?fmA2r#v={SigPF?}x<4&}vt&Y(ggy(uQVh{AR?%jsosG zVnW7}zjrl6f>(U=aOP9R?uSnS0M``NBafcyk`B8M#KUC+T#vcktnHmgrme)MHN)Y_ zR#gzF`PZgA6Y#sWOq93sVl5I8T3Yd3-~u^pFDDCMgP?BeDa;wmKWrLi;34LCOZR`8 z7YxlLxD3D#-a8D*XrxV02TD)~bBLb z^1&f`X`axke@1;#N>#BtGASu)N4iSTWKUw`udT4{QdcfxrJviLIJ8Gcczu0h1Z2HQugS-#*s#K*Gk8W&0%B_Sv@9x%SvAPLP`w)$5g0YRW{>X55 z5yhy7zBYn)?r|M`8lSE5s1wRhl5!w+k?mSA*;CnILARoyd5JZmmFTDSkB(F2p;<+J zrrl@t1nLy|o%-hTx6FDv?z5iyFj^jpt5FuP-2p8}Ndt4SjOu6jAxl+Z%|@vT)9cTl z)2JmWs&lS5%}yDW=|&0UgIkoHX<}eY&6L81 z>L7I({{2)R3avrjca{hAa!e93%vbx*8)362l0R4q0`|9w7?C8V^73b45!3rj4yVue z|MPd6`@)1!VW8pS-^!-keLw1 z1r2(r`5P$4hiFE>&oZ4qTNpEm=MbhpC10<3wUx{ef{-2-*u|hoO2596jci z&BIi+TJWpk2!W@0qzo3$Yd?vaJZEewTJ|?vFcvIfz}~80af|zv9rU$Y&Q$IrM0+T4 zD1}e^>EoZK>AjWp?IZdH#{`?;tpMkmqlYz~=;lkwYMc2>x=zK8@Qy_TAT015+gHRn zIn>XmPy^-dV&7uuL2#o%#+Oy0zUoHe&6tARhH7>;1n&XH_@PE>%op_M7c^vp$b?T; zZ%Crn67%TkQpV;d{X3Bd_Na-VSr1i`9)=wZW9KmgG6bDFcNuj%p$RtJF)Y6=ztK+GivbYHo5{S*A4R$7*k@jE?_h zUbWF9tKWP*iMJga?5EwH{2=aN_9WiwaU^{M_KOyqe6A5Zvr^F!?`yIdL21rFJ|wX= zM=r0#l?ugNkX%zcgu@X~*AT_!d*xKdGnX@1hejw__K!y7y`UwS7(S7ZPxfIeKYhEz z1ha7VyQ>ST(UpY|wbhBn3sM-(20kZP&h5Q-NU!BYmC~4!>eF@=#DfpYy50g-&Pf{x zCsz5O9f)}*1JjwH_49;4-7W0?_32LrOU%rtZ7!;+l%8_S=N21FMg_sYNh-_)gJ}w- zg--`X3TqQKs(18y_sQWJve0i9%1lI@Io76J1)|dcLRMWy*RawR!aufH+bkhLd}$|C z%;0z+mq9e~B$BcF{9;GjehL1`UxeC(^AzTM4f;QzfBkUTnfWd}t% z91XZ9cXF71I~ zZb~SwZew64^KaxMmHT@cvt+r%K0%2(T_uY)CTtYCWAn41_0%t?P zovJsQ4v+iWq4QvtyBOG{CeVAbT340RS8J+^`T8x{%je9?F<>)A(5l~KJleRJ=L0qr|8Lvn zg7t-!Px}Hc85PxEDNkDbKJfTwaSHA8lZc&1FaY^hI-Z$hsl3aB`{GOkNoh3v7D#G` z2%F=%H2il!ZN*pKVqXI;37J#oN%#Ko&kV2BG*4>x>@Y)s)};PwujFC_42Sf1V$G@` z1zD^ORGfbGy=QhV~GP^pS(sS5LjfK;|9`TKlJ_;XUz(reeKmgYUxy1p=+ zY~qqtZuUW{#zM_%yYrm^qlC8F3bqks(h2k2Ijn*N{i?NyF*c-iv zroy-7T5&bVc?DUE#-3;S&(PUmZZ8Xi5|L;i=csu06K>UP6A@DzkaPUn5J%zNe^6u8 zum7ctJ^)oF%I(J)W>ZRc~R&M%B<%d3+97iQ8tCTeG;R$gBG# zxVF;Mh{WC0IpSxwc!@|dwSeF6NuU9sE?|*i4S+CIS_n2R7qj}XGF)e5@@{$i0f)=Q zW^2<)EgO;PC(*{ekLe0gY|1}xu&Q}B%kx~CM@bt)$ZU)$<)cl&a2>5Wx%ge-PI4)v zS5rpsnRLb>ppb1=LA|7gTkJB2>So-9FuUY2?1G6b!<+f{{fg!=_auY*?`%1R66|S& z(Tg)?ufqsA^GsF6Gh?r^cB_LUwy<&iZAr$jOM zGQOEsEa{$DqbD~?IHR?9`Ly+Iyvq~S@|&1^c~mxHIY4mXrYU-#W7Ks}p0b3AD^m6_ z-acP0NajtwX)5zL#xYT}`)k#?moAW>-}5gUURg5do|hVJieJUv(~FMCG!LH@&>?R$r2@`ZuAD?RsBJ_{o-^P2UMA? zi;Kn`0!$4DtEx54<1TBqRFF(e-MBSn*)Nafrs(N%tmu?z2oL9#^IiUdGAWM8K*g;; zD$8~*$$b)S=g{Ziq$c$w0D~r4Rn<0o9ltghG7q@(_2D%FM!O0ksGH_P3s}lH5^gnR z5MtLBByPp|gN@1oQgK{skzE7Tv}*ByvD;Pb7}b5xOahUW9mSPF257O!F!NLi?uEU7 zPzW5>NE~)i?Y--pgaD$s?xySBRa8j}dE?f5gTS_-l~d^+rfKaR`M6zAO<#!v#nhJ+ z-3K(t9rEjPBF{@zEr+}Ca0eNQQOKqUoM!6BpOVfTrrob|zY%Zl--QhhsCTWoy_kly z_NuI~eZTxp0iQ$)5@3=XWuU3tzU>{WLxo#ZIHyMY;ZMg-_QgGSc-5>7Cz5wmfF$109+NRxOqV3+HJ^^rmclDZv{p&lc%)I6Ov^&62hQ{{ zQH?2&rT-ByG4Elp<;#tQ@Zo89^;UWnA>&S7C$hwR*?&D*TEp!+m42SvdZN6lUpC|! zS*rDrUPM@~j@{-kyy4LwDnshp=xL9>Q&V}Tp@toELC?OV^2+?WrU85@7<91m(0253 z$zH)-z3%?QALW=_DLn1NTN|b_M{5@Y^FOAEuY~Bs|JK;LRmdIPalywJ=Vd|8rvjFW z)scaT1s8wXvSqku$^@o-_$)X@Stvd?Un1mK>_gkH|cm7$(ygAwamSvHuLI%K}ch4vm|j=ZygV4pj{TZ)Et&YGL} z)Kv&c<}=1$Ulxis)6_5yi;hzg-_08+zbC6}sig<8y4qme`3i;S4<n$dTYYldCZWc^Rl^xIs40kglp>Y42nek7c%=s&8`)`f~xc`|*mcCvsV*gs4 zMeiGsg&g+2oRY&two$;h7fz+eaY@*6Ht`FjXKj!mVtYAY^)8*D2jHJ5IOd8XLocs- z*R-QRbG6Rtwg0@lQ1sak{4yCVxB8;ZZ85?TLi8+!thuAdVUPG_Z1u-EetgI0U>RH- z@hX*i7s&Z$<*R^idKsN`=fKvyjsKts=uCXQWc;A0!#)050d0gVtmUoRe>-2X(6H;F zk9T6$BM#N86m90>j;<;Q{cFSZEF&Pc_vSI`sp`-NW@khEExe0=Onh=igtacf@GBl$x*|nbJxxdr~YehR<#m{Rqc%Ye*s9Nxh)1<@!bD+PohkecI!6 zdF(&^Dkb<#K;qo_`YVD-gZ|mG?Hm7q=mz0;n9A7CYp+U{D*PVjeY?WV?B5Vk34tz? zU*?Wg(5)UNP)EmhXw_!9XnYQ7P+rsFhhBLLrpGDuswwqzX=?3a=(uU|R{VBYN8Q8p zy4cmhlrNzLIAp^|Eez?hcFyEFWM@&vqBq_2M>-}TUOS2opxm)HEf+ClsYQW(4YV{I zY(n{3lITc;RN^Tu-j@B@16?FvIv5uSco4%6(Z+NLj;38sT)|;JSv`{}TQB|QB#)3o znLKX~BC*N5yO4HmQ66nqx;!kPNAfQ5?bk|9 z*_|{8Uxx|Wh6pZNf2J40)|ieClH4-syXG+YUjwAuTEFA<=%QiWp>{mI@|1$+Y>9fxw z*{Rg9Ixh2%m=|Qc*UhPe4ZBfn&QY>@=u@mN*NMDi36FPdN_Gpl`u<{R_7+x~@0Tk_ zy+1M43|acUKayf}P6>_|-TzBKmPPUbjV03dOE*TR zmAY652=4Sa8bgzde*S+4zO#f5X2`my)U9CEk-kk+k1 zTe-A{qzKS9<&p9t(f9$U`Y-a$Gp5{ldd~KoheQ+5c7R@^4oi)w9n=XtI;697Ssvn_P9D z0D&4o3~}5iMFT!s_RsHmucp0`3e4X^zK$+Kp#*>hgV_4EYO2b_AEQjeTmE6P=(}g% zPlKU3Z?bceue~m(-{a5spGN6lo(TF6`*p7jV)pOhoigsy|9gBQm;dACAbW)j^uyOK zWSE25QLtUBt(l7r@v(olA&%c=yT)Ow!t|U6x;5Sjr)13uVc`7l64fQjmNjT~^tS04&Z>%Xq;`MYL!+|X5+ ztSj2yJ@W6_(i~qJ7Od|V6%EO}ZX_qLvHsa|0Kcs7-yClK&qKAkLbWviY~0_03IBd6 z`yO)j-;>?$lK*q-u@`vDf6psD^VvZ((&J@fzh7X;pDR@<#?TUfPD zptDq^;DW^H2)6?)o$jUchE_BF$Zj}UA~_?EU>{tjNPR`m$7Qe^lXic^^OW5c3Ua{j z^RrjvN9Z&nxTiTTigo#JCBQM_(Y zyL&;I;+QY*koqEOyT3~oVnDW42cf-sJF80LCivX7O<{5qzX5392o;g`gNfcS@B|s?@y+Hq^EU2qg31NR4_R0*6H&w!*X;KR72}P4LzQXv-&Yt!3CkFm`^hhsscrmZ8`Nf6L zhamBC&&TZU^*fD2y>DZdZbNbj%+VI5IxiuSilkYLOA2Q+_I>dbX z^{Tns12LmZYs!5Jde%UTVL{l-65S5+|VJv055zq7GIqNTg2wZu66G0sf3QB z#25zWhFh_)nX9jLOCN~N1t)}uj7jbGUdYQxN?-A*@7UQ{;F+^62V3v{AaIK5E7HE! zZ|vhZYuh(RaDjTLamPos#$BY!0R);3wqL2uWp=Tj8w)jO4Plqe7(ef~C1iUrk3} zl<4X4OQG~Uj+=37y@kM1E%b3aWh)Ka>nfru#E7Q^UbKBgiMuVd&%0Zuc^88cGxF-h zepKyfDWlRR33i)GN5VxfZ`TK`ZLn-wf>_5c9BJom+R8I5y}d-ETOQC8$~aIX=`?rr z#TV{yA8NSMBmQZo4-N|pocC2?*i5}&xH9R@B@SC1AKBhIz^xIkdXlqT-v(br_q`!Y zbhP-{Upx%UkQPf(+^comx{V=<9|JL>k)b2=qAk^x5mG zrV7YW3=lfaU_}Pzov`UmW114~&nCQJz?>kvX@6|B-{p(FuUwz(N%_En* z92t;s|D4yS*?aK83R|15oxW+DJd4`FQ_J>g$GkJ~7sWg3*A5y%8G2vOqZHRjj%i{$ zVmnH|cA?Pzjtk=5phVX4cWo<~`y4U+0cK7E5~}`&*Konq8L9;)MAzR$Sjny<*Y_5HM@jGpeJafM!=*8S%YeL+q2Ic+cfW1^4v*Xr~4W&=hc>!z5Q9-v*9&@cETOXJ0Yp%WOZQJv z{l=BdcV;wRG$wjVeW8T_C?a(&dW~NZ)*PXmDiPhH1UoW0oDdT!I;`Q*pZy>cZ9Ft_ z{|E)EO<+g}iyX(fB{~eXzH!o5Y*+(wrIx!NEJPla*9axp!7F7e-foU2a5#PNb6t9J zsELNvzp~e|>XX!2ft>RJzxp)MV&5T?Os#-fbQ7##2g7q&s>MEuK$bE02S~g81nnaG zqrifCr!g*niq93avlg{WtGK|4}*=KI-BsEf2=*DezXKRxL>U$^J_Rmwqo;SWO=;F=H3TP; zKR(Jr|7Pu1+ZaNI>^v$uB@{x9?4(4iuDz6ocg7HuH!H+pzI&?H?sc7hVB4t&EeD0I z!dX7Hklt5xUD$H50sDiWdb-%{^Oreo2aRLWfj}f;s zr{3FWTRg=kVA``L@iHU#CLDWuE&v*R)*FWE-#RUwgCAhkBLP`r2S_=UZY77>Hu22_ zolsZaC)ZtE=oI8iKEI6mo7S#+(WLnouMJj3oz|BO`=RK;!Wp1nl3S&4TH&bTUF>g# zaSy4?Ee<NocRX?GzVdf@qH!WNt=g^!iGR=EAo?-K&{}70I$gYLRv~ zTz)mkplt2~=Vlm3?=&VaXH5`N`=J|3t#nQ6Wj_Wem`g`$Knb`fP2Yhi2DV2QZl(>a z47aZnXHX`0!|dWDe_2H9Bpzbyyt76~**eOzpn`UJ<~%jRK}}~%(gksjxn)xU6WN{H zQMsNLb_%IiWu^k_acS2w@*aqEuY8hzYsS~7=@Ip2!G>hXl9c3~YshmF&MsKlg&RqHv5h|h7F}a>j>~nDBx4&rt+dCa zaz;D#x%=O~?(nbZS4eJL6psnWwD+YY72r&@r6dTZ_?*a+*3DnN`Wx#!eX$Hll45gv zSc??g4Yw>igWO{`yVMliksQQSD_g2>SBB{n+mIhCMvJ@e_X`TQ6$AkN&mAR(%Q3~BJOzKxm6Aw#XmW;e*PCIft%b)gXJw7ie z6$@Tc>5f@Rgj4?MlUjCuYH8cS51~vJcp9G>*_~a6e@kzy1+b8svY;Z@vk-056AH|u zEUItgl%ju>@7^spRF^yJyENMppMP;T-G(O33h2+#c0&o`XfAiIiOtjOrqV7>A%M3OU~P;$g&pBJggeb?0YEl2YI_TlY0UqEEkjQPEJ zGb#ESSyxHGesO;r$mph_{S?{cXZLv!7&8E$X z&=QM2(FvNAado08B3~L+r8IBRIO~Uk8I`k2`j}1a!$rSIu?0Po&Kn|2u7D=-N_ttb zmtM%SgF>uoNbgs=2Ls?IWmrOU!9!^w#x2OQ12r`32qYM1gTLL5+MB5v6S)6M?on|MCMSWqnf z!w`VWn49qAs!N}!k#p5_u?awPIqn@UaFQn_D3{}3q zHmn$ssFY+mdh5DO6pJrCDIC6e9b(XAtM*7<#;L!3*M`eaOL9L#S>=G3d5!3LVgYDIs@GU$}eK_Bh-_0I*a>109dN)i&kws zhh;wM{VPSL07!-mfIQT;B|8IR5`3$@^7|A*8WmDo;o-QevrpkcEa{apAD6Rv;RuhA z3WVej2Y>9;G-}HwljyIM6tQB%sswazoe7M@sHM*xglB!NCAsz9SBqATk-~Z?u#&r$ zn$U=i!90qwy?}u9r$N08QLd#wD|qB-wntk^1@Bek(bpxVK zwjrRyBnT>+GrCq$Y?IOVIv4y|_+5p=+d+e`?@AOnxr_(DS(Wl+xP%al zUgzY3nJ#CLCAC=}vasnKw>v;zK0lDPb^U$A)~NUKe}``n?lz*BkBSXfVB)`0NAr^U2@O6^qH)4RFPzzb~Y{7 z2PEqvt0yf?56cPv6@)Ghli6=5&=Er8oNN=K3h2Ozu)jc--Z}*1wFWS8u>(H@6-=9+ zyv=$&NQZdN(t*fvL z{;Q8gCUjFg)ISpN=nnw5I;i)vaxxTE988(_xun{*JXxMREYCMb+;z&Mb}sHTdNy=4 z9k=j!Td-%@TCu07nz4I#+0lE@ZP^vDkJ+a^Oks2OEMoC_-s16uLXr5a3Ql-9^(s8B zpA$ai?(ZEm@MV^24VSl0E+BOIg<@2nM;h8dv_)heAUIPd-Xr4XpYdyqkMT@ z9`gI;PWfdSo{psj{GrPb*YwVy&}!>!Kt*x3oclpr)zJ~v&JQ*p!p|9mP4!l)&$0u= z>&bJ^5z^DhVj-W9$xhQ$74c%JCv`tVi4N@ly38M}b^xg3Rjoa!>>h5@1!|sdee$@% z^Rc&=F+K_sA-Cm~jYjL!-^5Eeo(05fy>qm$)rht4YpuAiOc_zp@*(Rvby2aqBq1o5 zLVFbizsqSmfh*TY1{R9!+Q~_WEa6wazlbK?ahBMV7!j6vE0K;D*iJK zz~7&Dj}6qSrY`e+us5^`|Cz0HTeqVSf_0c~bZ(usVy`GPV~@0Ko&LY2yt+qgdp>#__vU51Y>S@8xBVQ#u)>}A`+R(J z^7Ob|?jADWG`)iEAMaMZOY}xZIk+{1K7+Cph95HW%gXQ2K4JQ@?1S&^`?09gv!{#y z0rrQ|mdc-*NN#a_O?R}g)b{p|vPPfbop!X+a7&@wV@#Bwx5Mn@EFzPYo`qS5c&&tM z9}f9_=ndr0QvH&6M?bX99s=p&+#S8&pBYXu+_!8nChNK?_8aJcN`A^t%Xg3Hc4QVh z{ZBjo61|r4#*oSuogp>gkus^Zo)&$d`0=oO#yj@S#pmhwln|CA^4&A=CUM-{@0ySHGFLEUzh4hJU>Xn zg4MJ*l#eFnhy2tWCh`UUSGTw@W;bIS#CH*XY4^Z{@(^?!)-WHouvMHd>3)0|zkti? z&x(QI*-Tko^bEup0y^sw7QQSQTLj=CMAiOQh-XVoZ>)E#o?-6Oub(s+Z_BuYXiK}k zBVXD)TMUvU*s|Zy^oVDhdkB2p-&%4BagXQ(jWlQQegQQ!GwD^(T%Kvz@A>J|QFE40c_fuT>@)sZe*O1#L``eiQtT#&fLL(1BrU9X2iwP4)hdEB~mB~zD zoE?RdM{aGhP9;(+0lC`|hU*2COa(oz=$(lGkI-TAH#t-;fnXo@$-*I{j=TK?*xtDw zRa4*H4IHs14y{`%7>>`nQWxlhV=I>8B@T3Y;VOO5%@F0AYWM-|b)Q{jBP1B*`)kq; zlH{3?LyY|1y!jpmHS%a1w8I@!Repb4FfO$J*tUOOL&Xk&kw4#7sCPq0~N02!cw^*3moG~4HZS%htzV8jwFlk;yEdKjV0 zlj6aeAZO=uu`bP`Vq`PVJdX1ppi z5}Hw+)!ExGlXM0A=rsm2(ybyfG@Yz=K61oCd*iznXR>E+Me%MaN8uZFl&Z>f`leKm z?K3FN=BJ)QV&qzm_f7t`h99A;*wc?OVqOj#-9cqIDi9)?68#c2S~-BYA}Oh7L7C@mI11K4mU zOhN69C8V?L!O0v_-~{di6ek_|oT{3_e%!je3cr=2hHe&*;j?H_CFhHTjO(SV?x>aT zQaCw9LW9vb0}$DWR{z4982la#^A7i(9DA^JoFLv^WI-Pki6=lK%fOw=YWrpO94D}Q zJ=Oa8Iz7#r9?GZP+ammI6}zOeIs`p*-u%83PWfhx%5o-*A-z{E6(oF@M!}rNq{%l4 z$F!~ZGRxUuI!*=tC3C!mT#wf^$7JwT@rc$TZMX_?B@ z)DR}>YpuwsI>%Etw;3ks`MMEhsYl5-eskje7rP)MMYnVL(ddz`TJWr-E0mx*WoG7# zUFyptiWLrq5+l37wwF{Nd4w)W5h!%VNMXi52%=km%Qj;5T2>|!wB2sc&d3{Pgz4yq z2G`ptB*ygvz3JeOD$@BGdM8{KltaMG1$TyBlArP?*5hQr;TEDzyH;=o7&WHe&YnB3 zEhup#u@$>91&zKrzCq_=3UCfkwe(a z(BVukdZsc`FF6}{-}{`M7nB7^NnhyT*%Z|nUHO@Ng6`KGCZO%tCKU+TY$GDc`=yvW zZ}=)troWg}Qk*@b`9475d~_a(|P5o}WZpx#G%?1cW3_W~8HQg3f&)+`|_JIYW{eOC>S@A?zo# z7Ae>hP?JwsUJPO8z@+ntg-EPyECEaJQ1k2+WO3ofxv8Kf&J_)m1MGKSJ{X#3m-$n# zWuldd&YtIRhPKSBZMG8|7ryrzNa#)6ruUwrh1qGSmJ`4c!e4rOK5Hd#rTek`ISp*s z+948HbKwoW)z>E}+p*pUEk+edR^G|4cVF5)={BS3lJcK3Q+DzFFX>aHun9Vmf$+?t zq04bCTyy?;6@}qdx(fAiLHF~ZPe|u)b)ru72Z>cI7*yUVDx$=etqG&)7$rIYWeJ+f z1!IM>?B%fJaR#hsS15^k>UV_BoRlZRFg*pR{D&sZ0#OExRSAP%Ua&@V{tRTi+PUuY zG^ddEhf4MNqJ_yojfJ3hgn7iEkwq#j)0ry~Ga>tD;3J*otqYr?nt)>~KSue91w$RcN;@ z;+U}i1)eqg7>j((0-9`2?gB?fbNyCu+p3wXvp!e`iX!sKZ8`A{s`&+S>^yEr1YJMAfTOr=Ja7FO4EHP_3_aq zkG(q99Ke6CQ|P^9fX=7~SDv*~eDl(atP&NTuCrw{(5JT~Q6`cT1Qrnwv#?Dh43LHE zesu8O*l>?N11xT46R;+2lDM&hjqHN+`jUs{4knr;oO&m+p38m3tODFlf%0w4O*Bsf zH1c_jN9H`y@9QfH{GF9D&K)H~WdW!tm>6m869Qot5q_%gouA`hnbvOPh5d_lk2ei) zx0&;LUtA6`ctdbM?lx&>nQpYVV=WYAX-BPE4E=?{**%TX3EAT_05OYDf5j!EN75SgF$RT*4h$f#(wK zD>bj8K`p9>waC!%vt1foui%GdYUL1_KGbX3qd>;p$;Jo6NW8}55Lg96$A(J1IJ4Wp z3iV+01~>A75JCdyK?8Xk))R=bCf#%1NdqPV|6jS8KZ*jPn+)JPMKS%MDw1U;d#i#+ z=ZhD#-X!op$YeF^ixNC|qIEXsD!x#($;y&7{)0@2f!m?;@sGa=860%#_hWzBxGO-z zWTHBRbQ(Y(_ZV>P$mhEP068R1m*2B3>lp$1Z3N(Nzp)!Ufr6Zg7b5)(Ou`hkmDSP^ zXOWff(V-*KA%M!R+U74_1siQFfI_$1@9ehdlxf#YqzPVWQ>EZr3}OStX|_rat0%aE5eFCRM!O#)CnWR?C_|_BsvB)P@TcBkF z3_YcxZ&wE4gGJ7WM6ww5tRWs{K=8b>Pd?_{;VaRxEDFj94OtxCWWc@%TWZskSz22? zN7jW56}~xuRLY>zP4SoC`v}@+sVo2XN`XO8qp|u+TB7dz$u*C9%Lx+6kCci|MJ-3S z-A4cg3!pSb7uXzkYL(`HUz|sP#t!c>zkipEtWL)8--vil!rd|4>iGR`^XjItK0nVK zS9g&~)NY;`#a{)$bTCn-sts{|18eW=;@sThAp%lzQtF0^Dl*46cX<}IiHZ#AFh-r% z9S_3`AYL+di5EohS@HTk$#2^~I%?ovc~-ygbJg8npe#Q%nXG7Q&UA%TGDSoyNc&SS!0_4MzL@h4QC6EJsfuu||0=eHV z*qt-fZN1f%fg8Og`vB{gL|I*$cF-NOB;R*{>a@x-$=)!@23I^2*1XVs+HXd3fa%od z8SNuO)=RfI`jm_B-iRD&yOijxuZ#rsg9`y;H~DD$Wnx_tuCY2I+p^rGh&b4EW(j@Z zmSP2k1O^%WgHrB)gbaE1?lgC@q{3FvwDfGs0g&>yQGIXrC6e0S*4G-dk?7=6=V|%? zn2St7da|%EcFW;0=k?3@8hewdi&IkL_D z5K)8(^Yw#Ery-gpx3n`n7q8X7<^xB^FCkyw!}=VKy`5XACP*YbzgZZui_Qq)Hfd+v zygkgJK4+?&`OcVUv9ad4PMVP zH`~q2Ts)XLi1ob$xIyb+2k=v#N}f@Qlwo*#Sb5_&^@iJ9^VQeN-NZ-&1sz!VDgU}?-Nm}NK8hM`g==0)f+w%5UoOl z3i8&KVo&UuqPK3&-N}a8;4#k(xt6s_zRFr@sIom&1Cl7|n4GcmL~2tNfsyJjoJK2V zg1|loN^X`#i4K2TWTwe?ED^I>zFQ9}l@wjp7-?oF7T%-JwOV>RLEU11bx~XiYre6y zzpiT&`53PHrKIZgW}PH1kH;nR6SMkuuQc}dIAl)uq)2-IKkc0RKhu93$154h98*h@ z(5h8VljD#>$RXB9zBwP#a<+UkrwXBRjIo7LHqyZ%C5lmMV_PbY*Y&)Xb9i%#I%VJX$1=qP`cy|((youbw1Qet zbOGPj%kMT5Gi2TjwsTxk`-_Rm&)J?AUo2Td?uWT%V7VejrDXQ4U6X{~%6%FUW{C@5 zt&2B|2B)E8daZOvK5wVBd>has62v0stj%l*3j5hUVR_bs!)J>RJ@ChQIIHuTsNCPz zkr?|5Y+h5RrwVChZ6ECdc@{SY+)sK~LU=v-Csok$zJA_Q(Wwanj3Aw%e+PDFuZPV1 zR1Ry%J=STr^;T{0!s0oIfN2!rOg`XNssUS#$6XymC=USHED0;|xbovd*j^U!J2l4$ zPY;o1XdEtJY86u*<`7hdqK?xgvk9F`$@O=%rIzDj+7S<|x{9~Q^z_cHzUNyRtHukj zmGN4zZd#JuJ9T%v0TX7c$yeyTK>w42@s^sX3caZ%s~9SWQFwoA4aQ2gGhi%!+@z!y zj= zfDdRKHVQWA*(l#ZUPACU>`IhIs|9-Fd4P656Yt$(r!zN7ebU;CkjT88X+-xk%=1h6 zm>|EP@k6e21`xIEZS=o0H{=G&xqfzpaRE+iY46GbP>X}bzlTBXL=Y#4kE6nIVG?M;x)nge=% ziqn4p%t759pII)UsnWBVWI(}V4gyA$X>U~Oc*dgUngBV)w6ebT0c|Y zpV-~%uZq$;P_CtEaRGE-80lT>@GZOgNtVkiGR6wpjTn4#C6N0#fii#vRYjW06qV=s zOR26uG0sB3we&|x0$Goz+9xt-JloBB&OqyMcH61a#^tl7wgIn=iBGJ@9f}2Kr<*T~ zV_G7EiTY6y4EHtEv_a(xBO}>k6#WurL}gTWlk_LzEiCsP{NC8FXrDM{-&PwmH z=ylC0>QKB=?)Lcv4luT8N?(i9gZYXej`jJ}5=euu*Epscc}}+ttFHYC&7S;&zjPr- zlI-(*0)Z*l+Ai>xLOYL>lr623&0xA#OC4{{+T1mh-p3V@+6N@AH|+jKu;^Ss#LtiA z_v*2hi2K!xJJC(>{Mt3 z@KiqXU%g(cD57zck!cI+Ak-xL^72C!j7;daG@6mqxWAN*B7+g#BQWXO`3 z+`qny$2vhgAD1uG2b=Y`x(id~K=bii2t_WVRqynV|DKxp5zQ)LR(u9W-}17|`er1m zjj=DwG+w1)3?WfjcJm>Tje;EzpXPVx?sV>C5WJ#9W$wPvgHtpmTbjHP?z^p=`90qC z+W{YTsAw!+_RC6688xip_x@en9K)j6pE`7E;Mz*aD?29KE?Q|u>4wva^0tSlgG#Q*s2oWQFJr=Sx{DQOY3osYpBgG(uei>;Wmf`C_-xvPN_2!g z!l!1n{VcQ=^9^@*yvd_~lux}ML`ELjIe}iYll3|aGnmx#kQA)9budq)`Jh00y^Te6 z4!I-X-)S2L)KPX;1(mb=a!r;wFaGp}_ji6dMfkofR#+gEeN>a(-;q+RoM`8ri44%x zN^EyD=9f@qpx)1xKZmP6HY9^UKDDjfyOm@mfeb;EdQN=aOo)&h>m2dv6@#(FpFO)DMU=#WR~ao$VD~z-L7%(V z5F^Lf?9_d7 zoYH*eR3DA^uov)2_HJu}H*KXsc!9%{?Zecj~Rj%%kdEu zPJ9NZQ$#L(3d$QiT`iB7_I<C$9L5&oP5TvQCpk4)37}@inx(}I-}Ky z5H^|8!+aL2E*r~{$PS#tLxeq66!SdM4jdLlM;AK;$R;sgReW{?LO*>@B3*SPuQ0EP z0kq~ja_|~VUy2;3Bs%dZT3p?f7TLBrXQ45e$OyyE-7}j987?5}`Qg%f9DKLqmimkK zrO99QSn;HJiyYw7`xWJU%xPTCinhNWk<&iIAq6s#$Asd-21Ccf$_QFx!NK7-brFr( zkqhIjLlV0EXxHYPt1ckpadvop$oEVH>*w4NQNxA)e5E~EwCBd*ioag8+(4p3w+Q+@ z2zSznJMwVC&2tZ2)06+?Agx=&%Lr#jZFXI!`}tv`C9t@o^jGrCHSj8KN497Q)caNK zb8Xn|j|a&ytHl*H7}UI0$CtOXa=@P!)sk$JYah$dO#^WvzS+B`dYBeOW8mII8#h$X zJ{_M0>E5oaIn>{xw$%0@aG*rA<;xtr-vIJujG3cESEX7|PP6j?frQ*JqTNjs!lAe3 zo6kftjG<W>B z+lYY5E!Wg60;cfubJJhumN5MbXtVLe)uPK>tYr{H;L;!$croLV0k?N^sN#lq^D}SR zhM0p2i_9n49|xDn1`h+&b0EhtQ!hq@cef}KM!G!SNLZ}ejQ2&($O5auq)(+r!9k5O z)QlGR;*5^6qPIf-|0y7VX+j4$;eYhG?yXFA=O^kM{Re#t ziAwi>@hH#6mcaA!t3b937Vi=_Zu$p-B8*OYE#0eTyK}KW7DEDXSEKM3F;%l^#X}6E z#BWliBdWJXcbxQ7$n#S^@Qe0R{!M!sv7~pqd6_iL%2Iy;ScGkp&P%n`3$b#*q9RfPkcqfPnZN z9Ton>qo#Ti0pS_QN=iyaPD+Ya#o58!%GL}4;dPwb7YPMK)#stHX7Bhz0waSEbEJ_; zxG|dfqCe>;lW5L-q*6r6Fx+@shqXxj_U#2xkC=+RejQ{^;>$#dbmTXQwL(*1UZSom zP57Nt({=kD`ve`6TVHWB^taQg5O8zF|dfK2#%aE5hV~47~#()jK zkrozxCYEr4-gaLkss6sx{$(hv!Le`(CGj@+tW;6}AuX0_g)5}r+q7{k=X()}1%-ay zn}s#!c5^xsdT5-1wWeHL*7sG@$SkXMAA7xr)b3P6d7DV5EkA2~(0hiS4GAjlS4`yR z=nvBymDeFv7=Z>mKgCgX$PRF)2)@%PW`?2?Z=8HJyLsJNzYi6%_0p>pUkgz_6lky4 zSo`|))jnm}FFk|*B7|EZApccHKzIee!cFxx z3;_*(C4~Q}WF!7pEs}aR(tni^zyE0{p(Z6K2fwPBIGdT-yI4B7W?dnU!|g0$rLOI& zt@s{j;$X)PGIjW9#_nO~_=f~R*aHYJ+L^h6Xg%y~?OlK#BJ_W?0K&_E9&^ys{?)|Q zMuc8lQH55@!P$(KpPiGPlU@{)mX=o7+0-2P;jPTS$>Db*^p>u!jzA6$Fc{1Z=3#em zw&36r6cps(}De1IH(YB;#qIXV9C$Xu<={~yTy)clL=uW|j0o$#N| zfGSoVX0|$St?b}hg^MOCz{M^67n}c8^B+O~MXBLp<}Br42PbqD{f}AxP5k%De-i%1 zQu{wF-|+npmVc}H8|9xN0F|As;M_oebSTOt%<;dT{ky#|#~%g%P2vBt=3h_Y<`l&g z=J@ZaA&QB>6f%T>AdVpSRzlt5*+B+M8*xABU~IzUq2%rn`|i=#BUGl{Bm1}N6uU<< zOsc@d4_(<3(l6esd}(_+Pa9xs6ZWD?ArK3+i$gh-i-ibZBe)~1x8;p8s zLwZY1OSpA&x-mFo(N*MncLf+qVL;-u(H9{U4K-b056r&!RdMf`!SApj9UhaOFIH(- zwAA=m(75WA@vA>lArxyX_oMXLL?lPY8dofXSgK6Cn90z}?PNWzw#)-}rcK*WFR8gW6t#T(SN_ z4*~G$F{obe6^*dZJ71W;d}NZJgt56hL%4g+tLPF!=EYPuA%a!^y%{+siF@!)^LD1o<;VL0p04rlx6_sn zq)?SO$z#=_=Wo!h4Us#KMYjogYRgPshEU>oQY3&`H4cHb) z+a_G3XCZ}%rfV!Wp_WHCWP}kS3o9RGG&y{TwP%AE9%53Xkkr*$I`sZB^xb?3yKSmH zxtJceDAwK`XvmW?YIv8k% zGyCaky;nIs79@qtokl_C$~1C9ordC(ThSUl&k5zSL<^=ZolTiHlHI09S}tMV*?5}i zkaLNiwYtewB^#Sl0cMBz7C%(_ne1lyA0x9cb#D01mEHRVynEhV!e_(;!qhohEH2gq zF@N!W!y>GZ^FhLm!ksH5Phiy}T9>aNSpei zJyHn;=>23EwJKM#Irwe0iU&UvPn)nGB>d==Ri|#s^uva`PLN<)ug^mmy?mp%iH={SaA`Ha=7Qb>WivF(g2uE2*Uq{daGKhTy;& z>P#iqS*P!IqwCgzG+#D`hQv(&h8RXl#06c7<0*x$=K2|a+>1Djcv47u$Nf~KdZD_+ zus&KIUJ+4HHne)!aZZ1+groQ+ZGpmbW4>!w`PqlfB%|DOQon+DF=ra5Rc5|4q;WJ{ z>bymqmWdkatl~g-2E@qtBX*|nbEYy9jN~?q4`yJlT!IvPLFztb~+4)O4gVQbSBBH%4+ml%$e>CZaMMG9~LeN zUC2}uKa5&G61HD0vM9N(`keDIf8hv+1;2&Xj3Rj5oDcx+ue^0zA1O;d6ocLcdB&iRVa&Y3`o7-QFcNn8IALXuLN1@hj)FBV4UtL< zDNqe&-UFLHjVq-H`@(WhlM56`ILFGB&bCLDZiqpM&VRlmcOfk+kSHS$eim#3eR?b673)NiJ_8z&#Xh3*$<{x3 zQ{6T&-)f;y5M3KHFWZd+5KI~3-iE(}XPGE(43g)SLGGB6zZP6N2{X0yXXx>Jp@V_C z-DetfUJ&g70f)IAm7W9}ip`u13yX9x*z#=J2ib2NIL*)y_%%8igec9B#2vn+>UYa zaq_@IFrQQk4Ok3!m2FGsvL-8$bE_ar1^PuLHi-ugC!HH#4Dw z+Bi>Vo25Q%uQW(9`NH|(#HJCBKvA@t~n*H zqLGNqx+hiKuFmHE_iX})1HVIe&x7dDyVwdEvM|48^5rgUx!+ZCaVd0aQ4|L7CoxyaGBZ89V5~~}&zH{ZN zxyX4HA~KT|BH`)3`hed89~OZa$jR=Z7^*w_sQ}<{UYMIxsfBGKI|XADBD+q51cnn( zRNWYUA}lbpEq{3>Ms1XWg9E zVFu|Gx$}q8WuP)g%UrUkj(3>M7F2eu?yF|^c$1y)z6bW0Um296=c>&$xQUdgSBEU& zlCBmt=%NDl;Nv4C>574Q0CQ>!0P3oADiT_)#?>%bjni_U&D}|nLHE6&<)16O0_LPl+A7Sa_4429!hDE`usGTdV`WXEKiqjaVtaD{c@@hpK z8j>Zu-zZoEjy#~5<=DgkXAa|fQKR!cERVZ@368lY7Ff~!AG%>3##T`Dq$espfxf6YCoi< zGOqfKh!t+GHoDc|_9I9+fkJdqs!XTDTfh{bX!EChw&b?=Vwu@cUENh_ZEWBusvEQj zFLj1id&|u&(3p7V43Ewkw^AT&)W*+Xi5h!OvsnLY3-~r5wBMs5mS_*0eNMvsjE2LQ zQ+2*Ng}czH)PS%|lnQlZi(T8~x0g7Sf1r6KegLPG?4hguE(X$_cS6QnlO}eExBsKQ zH~VX1Z=ZNcg4|3t(a_>}XS&w#%d-2S`tNdG4vAvti^yatoUu3Iq=X}wyjH6$37nx9 zr>ebGL5BDdxMtHNzR@vdg0VY3y~j-v=c7q0nG7q|^-C^jPSNq4p$JWA1`DZ|KxbKx zh^03Nt2b8@PRu$TDHNVFSh1rZuHkUsub&gG$}U_+uYE*}`T-1w*^(bKH74iV0i~xq zgoW3qT2a@{Tv+~FRam5zMQ4e6%n}3j62W4w&Wr9;@|P5DeAtG`y?PnSk3L*(d;C3e z$u(!B0Qh_PEjja6Yl2_QXLS!}jKe#q31Zh~%A{#Diq@77IDt5U z#g@e~buQQ7Ej|13!*5#JGAue3DTD_Gp-gXMP{vC=hCjolMads?N&_WP;un(CE;g`W zVIzPPU#<#KnfqDK?!W!X-NpKTomyskvbYkOFXZRt+7031TnYycXe3L@d=bz_U{h_7 z%P&^rG${s_y$wImV=wwagorl-Nqsf~-QjOY z&NzcyTeV9OoqCa*%qrY+@ky_emCFm^z_GNVx`S07%6CDhXkd12-#29}Q;P~_!_RB@ z*0xh+NAU3|m*p-QvNv=26!afN_Mty*93wCC>kS$tr%$SafdV9NKC1s-^}p7UK1!%* z2}8x%RWD!orpcDJ#>;Fa0OFFjhHYa?Ia)LRIUm&W6Xt$NX%AgeA?-1OkQ7X4SL@ zr0kCs<`ug20CAy)F>op$<5gr6!Zs5S=Tzc6A5WzTxPGt%c1n*J52nrECg zyF)7D{2KbCqOAFZS(pa2iy$mi$*ht_n91Pcsj=-xH8Dm5I3_GO#c#3jNsrw3e0XiH z>i2N?d9Q9S^qlNOx7S*J>k@VA9xZRI$^DRnq_Cx!9Mjf0T>#8q5cJvMnRyK84F;~= z@*j2FTIAd&*aD>+9voAYP{u<48hM;I_>U{RhX`~vOboKlNN!! z2NF*9y|pfs)YlmTyTVvGESh%aHujw*Ff8*O=z7D-(1c3%d7jN~YJZkT79|fyT&GZ9oK@)-C zwb8?$m*oTvZmogT?cUy6=)%q;ybPiwD#8O=ZSPHbIrf*r&xDM>du;fnMwwBS0m+B( z*iS?ma1%Hl*c{O&e$ap)apqo28C&*;$^HTeOPTfspV@4l80^>8{4O)y?BAupDhqq^ z3Eh8#3lLp*HF`1*9FJpF#OUQ1`lxLHD^Czv57-GbWXrtsMNQ3 zn}hRbn5)7zmcn?YrNFWwtd3dH2Qj|;ocE4JLnbglD=wZJR8LSKNiQMTJtGY0G0?+A zJ)??~>MC%SJ3M@$Gn{e1j)n&mJUO%yvlJ`S=iHC_ZKVM8SYuYNxltNWPIdT=1I4S1 zL*K+B^(j_hWvFT*`{s;&6`@9==Bf0htO^NQzmNjuNbXGP3=0mWt0gUR;V(WE2b4pV z;oGQWe+0sflE+%#NfH}a1FbY(u)o0nriXcAlV-F0egBq>sOQsrw93sH9iEtXNfwtl z{>3~A7#d?p83HaV#+P;!DYZ_BkFX3Kku1T_#uw`&W&`z#+(n1uwl! z#Z|)i4t+^iRwr5U@hI@x%LqBjFp5lMb~bGuszN%mht4JnDb5_U?xSP~tLiJd zM(JsJDYCcEM-Yz|HD?{}W}i%q5k|@FQ^U20K~$2wS?#P%6GE;ma(;R{QXpUdW2mxY zu2Y$^WW41b7}Y_Y5>qs;pG{t?31Qs;lxcHk%9Av%w&pVL-%8bg5Q;iU0}Q?0Cvi&% z#Dgf-S*tF6#lc3$<{QnmW{KTu@(~%dyeuNxDlty3*Z(mdm;z!!+yA0nnZ44-gmnr3 z^!E`n1+^E4P)!tYwcp)!9yU!MM( z*9F2LBSR9s4aHtwClcP#dyzb>G z#O28xXI=p@6p``d5f2fAo}}0|`Y1}wu*CS(TPL<+v)+s|%V$-fwA}ahq-L_owl;%S zcom4|cE+){bj~DEoJ;OM&fV_Y-DR9n@3aX@9}VJJrY7I%C*xfGMqCLGPA$t+lx<0F z#%*ZzzRoNM8a5(ny1myve`7VIHte_SxzZ?$6 zD%Y(I1-b(y7S7exTIEbK@Mbw&VXrEjykx5~7>N63W_ryyaLD$Jp3?) z6sbIK{4Q9wLL=EwxXZX+dxeS)6^HhF?r~A0g{PBCibB)H!d5Zw>Gi1#f z;bv4f7V<_A+gN<9nxR(3?a(JgR9$1&uJ~ZbYz?I6e|HvRkeMrGVvTrG3?P59WG z($`YFPp&KWHRtP1;HN`{GteW(rT<|z{qYgyte+#cDUH(n?I%(wX_N%Y66mmG#f$pU zxUAnOye9f3k_t{(FwAFvtA0i1F3ifGnT$7hjfH&=A3a$dQ$*$idp%6wOHAxdzD5d4o?-Q!sslt=w z0*^Lx>B{p~*V7t0GChE|8d-NHsNY}{f9{nVuXj1z{ z=;fP5PfDMl1>M zAO#N++50k`_Oh{t%}Kr6CD^E;i30k_m$Y&eU77EsktZ-iyB!21<44vGJlEUs)52hA zn2$2q2*lug7yRqUbE0z6t@QQ|%XM|Rfacr2dEnmVyiqkkIveH)_6(D6HNIqUz3&!I z?d0=~aRX}$#r_B?sb8GV1`$QG)>&x`ZqN$B`daM7v-R4>H1uca@L48egK*K9)$en7 z!U%ZY9UIl6a2(tsqZLyRpt@HRmoX8c)kvV(XuJ~g^iGo%6^>3$*$~f*xc78bK3XEz zsO4s}BL)|~FODAWh$1oZr#zex*EyUoINmp*THQwvVi0{)NJ^LWtfx^PoNwkSG^mpK zI6590^EqRiJJxa6Ise>BH1#2+Qnt_~Y9b2=pnsQ*I1uz?EC^|O7}#_4dTLPAb0@zG zqaBrvrMXS4^P5k0>#5Q z-*01#J(C=o+f2Y0ey(Y#oFVFfZptaSA?G_xBSc+3m+PLWtmd?XgLw`u)u9 zmLGXMv!fN4mF%+UG&?|s-FR|UWzXOohQq4P%Wr-I7sY>KOdfW}ZFX)S z*@Y?=sWZ>MM9%KHX;ZnF`ChMP@JOXywQZ}xx?+dNM zhL#JLA_VY#-?*e&>Z#y)QPx$(3n=>;FLnf2tvHd;pA5f77Y zzNC(hf*vW+uI;6arTIfKlNN-)o^ktuFYz4%htfqxAjVSK^-KpUAG|5qbnioJFhdbh z5*xP4@20IA-dXT7TE#HrW}0kaFuS|!6RuvU2*tj#tuJC6QQE|~P#h}Md}K`c)#W(ZpVAAU}>FH^Ro;V?Y&H=lO@INrs;YPKswvlV-YOXe}m z{A+pq+ggL|ic~mWR(4jiOCX<8xAV;amn2SjU&c73~2%bOrlv=GEZmRC`!ph;f-OxshCfBghSBx$u) zgeQ{5yd%MBqi5fg-s7)S83F%JTYrPkoslG}aUjL#{15f}Um1N%77-IsA->(o;-5ohHag2?eDuy`UWcyKg#y;@LR zt|u2#=IL*^DMM0t5AE;W6tZL%^Jd8Nv1Oa)`jZs{D1_=>PUXwV?0U}iFHr~?VRqND z`v)pPi|sf0{2rUcw@0(un!@_sITu%2-1M?wzI99C!JLV3-@8dWT>}+*gZSokZ}Z!L zOBHF)G(s)XNWP4!4yux#o1-d`NP%(`7pkoVsdI1cySVf3agL-IKD?r`$wB{8fo1_^Xc(!GNuA}~_)FBaL>=JF@sKLfO z_F|E=a<^Be!TfP6av2i5&X!35qjigHct5Mug|dcd#%pYnCZ30Pm|v6aoHIg(-!9fC)6(904FvI&V?!at(7q?s=3d#XJJx19x z)jngU$T;`{N7I)SNq+6QGq3Jd?bmFF)}u#hOQ+PtGMp%2Gm zuqv|^AG~Z< zX&eRlDnMKA)0T`}TB(>pl%$9m0+e!#S09g(vXNqA+U74e8cgs`cgpd?{gC<7!qfOH z3KqG$S9GVokV!qoDz0NaFPHTfNilnJKHRp}d|fyG-D#7bvMyi?pGw`?7jP0orA+SY zLf#9N-Ns?J>RLP9!^0Bo-OFU)7@+T=aKi7k%IVT09Q;Wi<=&A@FCbw4Gg_pL>OIds zN2pYJ%sr@70G`intgrLyE{YJbFm?1#RMu=?lJ<^Gu<@z zLoMd%Ic7@@MQsPiXUvTHxdDtB(@V3&lb&YULPOk>`A!FI-QX^PbK*}7bKpEcpcL9_ z{D4Fi%rSA5!`?P8c%jRR=iBYQC1vx|vstGL21B!6Nq3yU+jNyTC{3Wn?UU&FEZuC} zqTer5Xo=uahM?Pbwl6+)GEI{#jj@v`p2eIGiOocD>Jcw2M=cDuo0DtKXjZI#ykSwR z$#yzAMCK7NMruqH*pn{!HJXEDZ{hMm`81orZVFPejzVc|&44i=jmL#%`8VS|9+xw=74itZZ;@U{~cPd zn$svzDSRJ1*haTWanxpL^VxjGKy#!tF*xbAzj$dxxeA|u48IUE#LM-Bl!H6F_j*AH zmHx;4KrH#Ce$sl?3-Ew)xzL( zA~2u#Kedo>gMu?ez9npPbUIOBLL`-OIuS>tUTSEe$AisTZ&+%`D0LHj>vLfA(H;Il z#&>lV*e|F|c}Y)oqfxmMIAzA9d`SW3x!U9!B%gC>-{tP7@H@bG{;<5etnKnm_7=g+aNp#(2vf zo6qrFPH(a1H@WXc>vuWd&{E#DD6rJ%AFmdq#A%?nDms2260)3Xal|r!y!>^5s7Rk*Sa8!k zF(+oaj|?g%Thxtj-KUI;Q3y>#^b9mA|M((W9y8M#1Kz-VzpvG6q<0_mCbFr0f`{2F zzJ>;+hY|HaVwvZ&*54D?kqle}aCi zRax2*HHtH+Up0B8RoHq*-Ys0~kpaAZQ)&VX0KngHM>8iocu(}JX8FU=&7s#+@zOhu z>Rg}06>!L??4Zjf;TDv9s({!0ng5%|$R#lO7IF_6eui;-#0wzP?7nNZ?_I3!K!e@g zGYUTQ7N>FHuh&<44rFbdEo~kPNnv8=80P%4(J6&j;XFo-z;KxPR+Lqg9u`TZz?gw@ zwngQ<5-5JJCAy`>47)zz)u=ZUh$@HzJ2#olv}FKb;FrXq_g2TF_xxi%x!JSA%kpK$ zjV%Ze@tRXo7~=mOD8tejx2yZMglE|)65rPd%&UG?d zC+)D9R1@c^7~@*$S{4J_e$e{YJul%VVQ!V9sbGEYm~wX3t!Q6>)GQnAdC#)Fx4gi zBI>$W)=})=GvRQS4w0TJQZmS{^pNQ(Yh2FNQIsrrzCcy>jhH=I!A+%f&RQ0J_T3o8 z;=vywrV;e|>V7PEz)Of!-&kd9j7?nLA)@yuM4Ff#LQs!G307H{3QY**Kj5l%cp_L8 zzx`AlN3Z=+9pbal;|G%NJ)er?_>lE13!>_zy=4Q>7b~IST0-R;MZ=?>YIaFdmmM$r ziViq>c`oK;!(6Wtm>v=*IbtoDQE3-WS7*ALlptp0E}!%Y<)NQ)Rl*~Pw&)tZ+>Hl% z+fGZ3@V*CDzvDN`v_)2kR}m>zZ;!U-HS)Wa?x{G1XK0)WL~w@F^xzPLyvCLk?}Cg% zwL{OO(HZnO7rbtVG!}b;Nz*zPO(5UvZ?Z`?e`L%ujpFIe7Qo$_8uJt6L2J<|Qno=J z+hYcoN1ElgpR4BafD-;IZDu2mZ=_9Os%_fTCUzuqD)clz9dLL?rO@1XZ(mqL3!imv zmk<3S3dzUR&?V>yXHA)^*&OO~g!=un1aop`JLnbFgO%c7CrIN5!`L1Y z>}h~S{tLR$HE+NW68`J7C9icae#j7_#NNQz8{C!>A+*_f+Sx%4RPJ_!lXruLBlLGBE&CU}JrJ(c!DE`P+XS!I? zeKJ=34ngDnVVCdo<5Sa2jhSox*gHHbwMDLqd65U|Cpl=q6{B!Ls5eYxt=Tkeh_d`U z80rv+8H;_M96yMsvS;q~`$Dh6_;hA05v=oj|*K0KeZh$3pkb`+PG z+kAPX)_$u^yPAC}v~essNsM$CQIo>tIyVg&8h$se`HhQyEn=nu7l@=VvehvdX=V;K7XO zmr#7I`8rj;o&$Um8WTH0*R4|l&>13QWwL6zupceoQ&pB$V2N*9SRFhmEv%amJ^yWZ zB5jDnVjBlqNXn?uSUxtnCIEW@gP(MhnuaS^_AmE4 zl#i>jC#(0->t#p*M)#x1?eyx;lM^$ALD|*w89rApZPAftTgdWc)BQxm37jUi6=`4;b{1b;I6M|HydBC(=PkgJCR)O@yy9l zqEL2hj1Pe(C@9#gkZlKZjw3`vIF80vygNLuhmRv@lqqYSe;!XRd6{<-#&?Z}{PCd! z=XXW`%e7IkYbz-g9_Q@|of4gP*29I4Pw=c}i(;cgcH6hDxFRPS!>?3&VTsX9b}rOh zkw_Al83|xv-P)|Gbd#0&B%8t# za4G3U%K*|da?iIg_(VQ~2ZMz#Cb@{J{4SplE3&MkMUxNBwP>gX(Z8p|iJGv}6$>uW zU^jz2t;1q%bqJWz$EQGbt}8=7N7w^!Z;3?B;t$&z6K1aibQDLb?3TD= zKa>2hOR;zDNdC;0Akj52u%l^RxfZVDf^PV;k)65a(+7(t6Uw-KLa=9pH{kM4AkCa5 zny_>QgJ_Yo0`uih z1K;IV7FBEg_^CNlGld5k=3voK!L<#-d~lHW7p!3K7kDRED;o;%%)} zn%(iz`CSyvtbo)!&Fiym9o6R`dg84d8X@Y^NnS|yE}!XRpPc}!IYg;;Z|R(s_SFVA zRySSlo3e#o0hIQq{rg9*MRd^oG(wohDhP$pyq@c0gc43vk1;Q28SX96e;r&Pihe%l zenru3OR4_AITVfa{FK#We(|TY_BmljPmU-oP&UgcM4ICSOVgJ~wOJ+vzLL^D>BCo2 zEyp}a;v$@=^JMKE>rgrqP9@l9I%!SGueXQ!%O=fkmdJIfZfZci@y{CML$LNW2Bzt1 zy7=u4((QMcA+Z@9>9Hl24dzd`?xS8%1j1siSfxHAcAo^TtPsA2h5Z>xNqHt|&t0{{ z{5w61Mp_wqe+eQ8Jps~^j`ZelrR*9&gvay$U@64k;9EjH$;!3sbqeY%?mn70Kpfxc ze)W(^02Y=6UJgb+PrRi4n(>gr*cIp_`tU>d^V%mET|u z*j*C~#*P%f#Liau`gf)rh*gMGhTj5u_fzP-fIqkBd|RFqh@^e(L?FOt@fQu~v+PZ& zO;Sfs{v4X}(dloLe_>VL8X?lFNJGIK%IwJhz^`N>_q`6yLU`Hq9}vpFn!r;&(bXrf zSBB%Up8ZW{aG=W?<1+%tJ@V`B(EkaA!T;2O{5Jb@$FX6i{@=#^moQ>*%*!UDIL1Hu zi(kB?MbxPoZz*#F3fBp2<7@PwuqHxg2o*xyP+ZjHLgWJb#JOr3@eEErv?a zKSjp({e!vjg|-Vf|8tyva2pRP2N3>K=otfB;mPgt1IH_^ z%DCYSubmX~|NCts-p7E?Ql``5bIa^@#5H7dqDeCY$FZGzTyBr`&N*C7MlG;d&TaSZ z_LCYpZjTo2moMSuBHq@h!H<%@n2ec+1eVhv&dssJ&{WORRo zNpr-Q&?~X0<(vf`8I=R=vDu}fjqM4zZ^&}0>G5LnX9};=8KQ2hGq>6JH&JzAO;QT~ ziO8cBe`B}Ev&}Jiz>+|2nt+39rer;n|EevoH|(84r!$uavQM$M&naaa6&m{%98!{} z~zat6uRQRH9Px$&6m?!RH$Z+rwA5uOQAI`j}K>s-z%|wOv?}r~teb zbGf3w1iTsBO}&*}(cLUQyL&lPFiA6>%|MmqUj1<(|3$=xTFe1CL^tunbB3^}b!&cS z_z8j*o_OGLNWx%_?X^ETAKkgV(N_o%!gKDwk9ESi&hn>=G3xVsdiebLdOc6puipf> z4Gbj!x^3m&eoaUF($(=G+q~gL7r-U2P7u+x&cImw?nl_gImdRJITjD!NvrFvOr_tU z*C!$&l2L=IFis*hJE0cWU2qXhaXyfv{XQ4-YD(cLPhXH*Rq2t4^zq+%dsP0V_qp|oD!1miG24tq zK(z()oZkW zC|xuj+1Wd@7kxbTS4IPNT7Zte#}S2fCf&9M1cbg}(Q;6DdH|0%q7gy=Ot!#xl3kwY z^WpD1@5c13^R>{rU(bCj_l6i|To?Oge1_Ff!FRq-ACZq72ltZHwljbRN7Mv}#P^SG z=MG>)pAN&O32$DjJ$l%myxwH7Z~{L8F!TDy{?Bqd##`$;42QI9Mz`lcVx|N=1Fud= zuAZz)T&q~B#eTc0pVcPQJMJFhSgVdl?ru&w7yq1pxO&+MXj zi{p!j{{WIQeFsZ)3Swoivy+T4$+11)(4f(jPF)P+(~bUuRT14i%b9A=X^Mu96b~wr z+Ai}(xU(a{Wl9;K7yX)fD;HaT*OwWhzF82kj4oQusPdAFt^ZIvq=>W<{@lGzU zWgD;)_!XT~1ua7NJj~u@ebu0mSB1~5tLF)Y-=j_Nvo@I<>= ze=B;iMx(ub1+~XT6de z;{?cX7Jk~Qbf4ZBj4d_}OlLmc^69N@1RqC}ui}~0b*yj8b>+25H=SeGlM5Y9Rr*gf z9Nz7oOvXPKTNP4oH5Zis#+#$2B8(>E*my2*GMHG(iv2rZQuyor9t#Kg=>4vw`ll>Cq4V1Nhig0Pk)H}$75aJl&D^So6q}O8b3Z+=KT&%2eZOh| zpzYp=8ZjB9K37jdd*@0`%5nF#;aucRf^U?)fW3C;*H?1c6)8`>*a)aPYmWElQw53=$7ceO z=k^(Cbp2ZEBvv>(iRj$1Hz z0-FJe%9cvF)ioTq<$~s(1N+8>wEkna1>=|m(d9@#rC7e;>+^U%f)V?tK$AMBVI{w$ zc_#biMhIr9mqdnw(CDn*?d)TD%<9wx=&!eE>BgXV*H<%2h~LWR1a4_UUmZZs=a@IG z?$*{b(<;}?)%$vj!<*FB_OFM@dGg&cw<~OY_(2u0IoGtpeNdf|f|jj{+m$Rsi;Ka1 zs+!MDpcfvLRo!^B=lRj)?xehL8XmQ1pYo-zlo`Kg&0F5}T0f;tyi2B#!g77lZ4O=8 z3?W`kXbR@ew!g~VU}H;kr<(&J@lg4%yA`~I(0!v2#RN`62vv5)04*k}Ja?h8w41dS z=N^-X```&II;}2Q1F+IQ5BGXI-Yo_Fs+xo6#QmDQN;fYjsl#%!(Qqs|zPR32&?}?= z_5}YN`SbxfU2m9Hgo0v!5eKN2XD*@NnvLN$HOWOXE^x%*Z%@|)b}4r zX-w_-*_1J)WnT=8gwTqmamLCg+Q_Iloc&f2#G?kP?v|xJ`1Ue56BV((*!j}CU>2~Q z#%<>Wsi$D{2j*4SBx3Nco(R}&ahEJrvG{^_&|2K~X=ojW*a^Hv_2 zur&Xnk+KM;9_Sh4d+9;HqL>CwiLVxx%{(WrC^uJ}Xv!-iVP6fY@1Z@g5w~sh0pabj0iVMol}JzEU1Bwcg|W*0&~n_VbD$c7k!3 zB39ud%};C!paj?4`~l~b+4}M=)Roh%?Z>^U><)O%b@~D+SggfQ^r~06gk6IC4^C;C z_4gVm9%5bYt`GJZoTr&^*5oMFuCIq_y1J&8HlCF}v{E1D2Xc1Ih;-cWZ8Q4aH}QI} zGV4}Zw%^tOX&z2pgZ7%JFM0wn)%Cc}UE*dXC$AEIUm;ngWwh3CfxC72(6b+M{rc8W z7Dtpt)1Dn$lqFr}UZ!I69? zB+G%BocvJEa}obBsNX)02A&5TlgI2bCSSrX-Yl~c03>vacE6dMjG48Xkmd?r6Z+Db z_N##MoOWW`p$j18aC|95?KsmjlUrZ}xk3xNr194;kXtS!WuNRKdo7uHac$AaHaAWu z3*QfO$(~iDBmUAZ7$D$~lNb!@-B*CGT`yQQ(;W00YKMQ(1YiYS!>z0!3{&)$f-v_&|iBf?fRLkO} zC-0P7M+BJ#VR+P){=gGT&+V~rr)Z%7T#_*=X$3xKVXuqtO-EkNTO<8nwhimXb~X3i zkpK(MT5cyJ0WJ1Pfqtu<4i6j8X`1L`1?-pA=XG9x=!^p!>L2``-$Mh}0pQ7{Zs~&F zaw`Ko<#)d*iP1_yWD;xVo+HHxPnr0>OeL5ZpDm1qtr% z2_D?tEm#P_-QC?SKyasV_XZkoppmok?EUR`KhIa^?p&OUw`vvDHR+y9=2%n4_>bS* zy$kWNA;p+We6zgZYPZ)1q=u9prmVO^!U?Cu2{|3fSiZF7e!9>nT@&KojsAHc!_#t2 zVA5t~R|>>&D6DrKFf&k8-M@4X;0Rf~9T?)&iQH@QI1b5mOYVtf-O$aS)v9$N3b#E*ZbvRvw;t0S397rYRx8)j5 zllF6FJSaUzdq2h5kFKB$C4(DZbpAH@=JcKfh--g6?eqNQDHT^-78uOqs#F42DP**# zlvet6^Qc4`J9eFp1UP9O^=0z!9jK>c0XaC5YfIz@PO}RbmrV=Lr-XtakMTyEr!Bh& zF`~uhIp(_-!2pzwKCWXVu*~6au=Wi5`by7&N#1Zz|7fe~hX*n=Wx5U^?;VuL5W_G} zzdN9i!FF=NkTUJr+n7*kM>0UYWlHRG+5srS@`egJikdy>I~O}|&ABlQ4oMB}Q!aAG zg}w?&wbNg~X01sw@S>5Lai5cZceLBnMsi*k?6}29bs+#P$79stdEW_@vpWm$f4QMV zI#jcb=A@s2Z8|GOzgT`<{mhs!$ZRcMh%~9D&DJ><2~Uk+#;9V4v~%?9A?M+)p+AKx zhdGk_=`W>5C6FR?1iuT;y2+(zx@6W8vJNNjJy>l#YdTAs9cekh?iBqMqGtbX?Uk69 z=MCbhI|!l%HPZaxNGY#1(*4{hM2J+@;dDKL!g~(2-*a*;bEQFZPb(UjRDWcI7s<>H zD47Iw2Bk`DMUxgtoUsK_rISEv;pO|70V<5rDIMGPihJR`*4L$ZMss`jecy3tBe#vy zeU8Y>#)g!Jy#6WvTB8F_!yo#PiDo1`s)@vayyqEbO`QN<6oxb-)rq65 z-RElj<%00e*=^0WJcMukDg<6rrCuFne+#=unCdg-{JEFm8O<_PqIX*(ZVuD9h+IH4 zSZl|t1*YsJlcoe3lQwow*F(yw)WfPtgWa-Hp)OJAS2T7ouPMX3qbsi`rfc(KSArCEtnEoqZL3F{^cFGvP8zV?JPyPvxfoeail^yc(b2RyanShT2;;f^>-{^@(9eGXt^^zI|DgB7e|a2$8`q9(mvyj zD)dy3%gHOD<)jH^)Fg`?L@ zw*gaM7>EzC*yCJChE%TT@+~grR=#kpbfkc>XWkbpQ>iK44*!<-VL_|5Jl2pFz_CB4=6>P|?Y(*G2>R-B# zTAH{^T$d&>lut^Fm{ePgNzNgG(m9nCpFud;LjoNyW>`%J z^eC^aH(?)%F}O(FcApr=hs5$H;sUz~*~Mlo=o6z0qmPM*x`D(&QO=ThR@DQ03YGpD z)$}Euve|%;aF-K;xe}uXeWlR-`gq08U?4-{MJ`4_?_HHTqh)EbOC6u7*=$7;WcZKo zR4G-s%ut9F;icvlTcz`a#je@(j$*j*d)sf&>xwW^JHv7UkY-s|n z@e8TEz86s%>8fy|?(1moZs~YEspV& zg;)l4_(QipJ)3+yBBf7YmQaijB+?Fc5T9*9D5IXT^1zO%gsgtk3iODdxhqe*Eva>1 zo3dEvI7Q_OS0ihvFr32AvYJLuPR<+X%4FM~@a@xzW$ZaFlj)^CVK6A6VSXUwgIddVXz)ZLw!Gu@c{3$+~sJfUN>Z-OD zGmVi*hK-Jdky^AUn`Asd{xg{#!8HTtUEP6L2w$nU*z8NpV?xBz^<~yyi)u5I6%f3& z78@O(4Z#-xJtKQTz^jIIv`jw?rhfd5CoK)|@MG7bAn0Y?MU7_kwx1786Cy@k&QgOk z%YT;&<82LUQFsdw&+rEpcPeX#ykn=m>p3AT>X^1BPkEZ%p(a{ z)9*DOZlGg&`u9)jMLLxocc|^Z+130V_KS{|nm;BF_RA8@cif+U$T%ze9GL)voy2M+ zwFp*O6>BfmSX{`bj9E=r*%3#8s}m#mLX*Qkq6iQx-R!OLS$d~3L3W$6O0iCE5J$#z z+(AC=?ewh>()7)xHeZ#Tj~SWbgp|zo1@moWFLApGYxTE? zc^On73PvKsd%+vQvwyhh&4QmJ8r|a52G)W3vN_7V>{;k{n-c}eNchXaeGHhUs~e{y z1Ybq9s%v8?O?_ET{kstf+6gZPWlj9d_p_ocyAH_a5QTM|lR>)L7|SAAUeQnPj+P04 zJWWwDX$`D6z3KweBwpuAjchzrAy4P_#+7Q{`E>HffSOT$p}Jhx=hvdOX{wf{9&ps( z`CsQ&hVCRWSiskZy{2eWpWAQiYxW%9P}HyT!>3~klShpdWY z^xgQk-*t$_gO>}zFRvOx+Utuc3X`z?mQPXLVe`8v^Ib;$=jm5dUe z!v}HW$G!N%pIaJew|$s(4qxhf)7$e9Ba|*TFZ>b_dEz%g#;wo}an|usKnVC#Fy<9po&Bb_I_>Zi{K@tC$b?53=YS#oak{_(pyj_v5L9u4|nqqp8$5j|aSd z@dYT7WMI~+wn>DLOOv-3e%U%T$aP&fcG{zFlv2Y-0*#eC4Ac zvm2BD?taArX^Y6;!Dae1|KzN%vURV^GvM&ejI_}*0=v36nh>Lvo5D?WHt8W9M-~IM zJnkBHfpLv?DcCch>cw*=Bj+mk@Z=B3?Qfx>aW8SFCjnwc;9wx$*CTLPLmC|L1Tq#trky|hoz(ZEdg~M(Iurvw= zw~!9Wjd(ZPbM8~t=n*aI#8$#>%_rMp7=yWw75+@wkm0c1N^)^1NsGEzVb5huDr_cy zTuI-A<3p@LI)YDQiPWtnmkG^f@d1Y`fT#SFMrD7jlLsdfG53|VON3iH0PkJbKg8Hi?;xyUNd)RW1Ryb(wb_Nt#pp?(Y{~zMp(t_hK((J@emhGQwrOjONvA zt;{G21FvR9!CjVSGHUt6FvJEX4d){L781Wg%d!KK1lc+tb;GV3FQVWQbH z9eNLlcig6NM%fybPajv{{HqlGb#<8q$_>y?mEpL$UY2Bt5=yjNnSyC!G_AtVv)Ab7 z43pRBSBV*5B1P!8Cw(j#};M zGx#9T+RC4}ccMSx^yv2ZHQOSyMqM8V{@HNA|bToJVZ2A2L$k||3AhPOc#WiVu zD1i>DsG;2pOUT{|hKTYNq52D5e`x7u51GdwS<%L-k{iEIs9Y|)KJV_(S0pSofO?z! zXdz9#C;J^j3&4;tO1A8IXrD#nbB~RiQ99R2AtI!awvo^K%egdN4S)xs0<``8i8G z50zB~yS)wjydF}nOULPiu4xRRJU*PGtGr(96-K!Z7F`H`MIHU}vH`-MHAj*>Yv%mn ztJyj)d5|Z;Z@&V+PR!ccd5A@CLHZCj!r{lSLeD73C!S4KFoRTRz$~;_6tsZoB&5W# zdK78qP5B}GpXrhadIQJ(c6&&f`%RfPfG^wihC~B*zkHw!EEYD-_3u-v+sbV zLh|yhBBrU2;Icz{PO0xLBM@7mr0T->DEua7k!HGNal6PWk7Y6)pb_jKQAIiKmY=Lk zPtNKTtu3Ngmb!02Fv&FR&yb68LL>{`=(_VL=QEd|bZ=Y4r&yD);90p;6j)tBls*^G ztBm|6J4c<~==hM-F0Oe(qk~vG?5FngO*7hzs(m*ugKWR$#YTncw4U619jg27cO%rj zsto7IjvXxS=oizbdt+%lBTE#_rUNieo#N6 zVlKl4dC1x5hUW|JB;y9~X;c7pr2#q~f(Z`PO(7o$2iRloOgh2sv}tr!7tqfYwg^^t zfW7b_FWfn7g$%Ea5^=^)c&q9WhDZ;EeoFq-`*l3}m3L~ZJ{*(lKBqxcIO&ahDUagr z2&Qu|6aHy0i8c}zauJ8-cSZdbduPVZUANIamnlEre>-c81)l)!hDk{(w1C}!YfR}W z>!Is4s$n2hG24M2sdSUj#}1x-UC%Sxg;HKgHQsZTdJ^tpS>1HHydmE1+sNf}op1YY zv4W3PDhN`QwWYc=d?kTWXvLSa57PSYw`k>tA3Rg3(6*})yE1FsW@n}z} zpflx$`1QqxcA_yo)=v#P2_Hp$cU!tprqHk@Jsnf|L{L(R>&8j@Cal-xZBgoX`9G8i zIqgfADse>$B3EZte%VK_*u_( zx^kJdXq0A`85>f~clcC)f-*N*MKJ5!o~ZT#WCaj!r0zGKm(Cz}fW04 zaA8YYtE=mXo^#7b4mlKxkJe~1;$8z`F}$QyP;}D;)jid`0j^j0CT(T0Jox+x+<(VJBzu*>pd{B*Tr8`i4a6 z5h0lDj4p4`zqEDFHR}!|&t-0S$^jmEZI{iMNFSDniL6gpccvG*)bueGTI?K<-Q<*)$liRz_YwF7fATb&s8S4GdW zh9b3I6-l)?&dc6DK7=CFuKGKLL8mG;+!CH**)D?!Ep0LBENHm9zs9xibYFFNM9cWn zsOf9SWSMr(*TC0qcc*NCEQ}bhD%;#0fBZs8n}NUbR*>Y6NQbV|Vm4C)UB)kJ>=Ssk zj~|U+7xknFl|9kw*7$2rtktVbS4mK8{D}=wAxune5~Ah{BGk@pzGL!-D?1G1{O;Mv zj5a5AX{H1s!MFH?tI)ppG zij9PmZ)dW0*~=86UoNR|uF81M0>E>=lNG4tev9&#a_k)!pfJ06=t_D~_7K$9?LjE} ztA_yYHFRjkN0UaH;4OAL^7deQFgSu=H39k|LaIc463po4yQuor4vv_omj?dO?LQj4 zG5}MWiHFxr^)Ff7U-QjBp=dwsDiQJ!453Z&e`@7`|1$jf(F@#W%76ceJm(bwzt^|e zK7Vf^)jfwOns=-$`rp$4F&=h4O4yLWPoMU4yZ@^CFV!DHoL|xXi@1tkK)+yax4fXz$wv8#kAs3(px<5`I?HIhu={{~$nOt&15+)hXCty&M2K+_2K&W97 zNzO{KOp~>j7GEK5q56WH(|j=y@zO#JzyMucN_cSi66^}Wt` z3Snzxo*z@Wg`8S;?{Ys)f4~K@r0s<6Ps3bJ+&=p1x=aKjVS4PP6I|+NB&lWz%WfWu zHvi$o0-@+^i?~q5$F>E%T=W}=Z3Cpxf<19MvRLe3CsF^B{_)?sH=eZx^Xto4pT770 ze`$kHkZ(A}f+suS0tZw8V4wvbxBePHsA3{n0dfEpdrG<$GKCzfS zPyq}AHj(&DHLHf3H-*e_4tqng&1=J=00vv&R|O!G*^soYX8Yca?X@@RnNQHQY1Wy8>67UJvX#O>B+|*gh!}VE zQIP>nn$&KPWK4@>OvcBjpk<4bl62MeNq+_|)8 z8IoU~?2BRcj@$3~n4yB)^fGM6qdRd8ue6~+2oN0sexixx7gop=KObA7^+KnMr}51< z(pXi?%t}{7|vP(evl*}xCcQM)9Itj%7Z1@K-PL5o_SFtap4SXNe==3=% z?U}z*1B+zTFHVAeJ9i_3FJ6yt54*B>&pA{yj!#FIU(lL-qeN_XHt-TlD%Ps^K;yJf zooyl|r7l)^pI=W;6)dToJ(a{_0=Kh87~5pqNq9)gG?H=ar(75<0x*r73Vu&*#YKFI z>(838Fs`~Q3uJma$(k-Cn;uQYBoaCibcWpWn+)N4eB}@tXX%T;zq_-l49;uzU87iR zr~hc|k!aR_z852I@3y?PWJ@-=z#el@NJd7#0Z4-0t^@&G=qbt1W>c}bLdw@)4+Knr z1gr=WJ}$;IJ}S{2+8UGo#Ews2Jh=udv5|4%IuYn1AFmGQM4e~I6>q^=x$RctZ~uf2 z<$G{9qsWAqqDWQ(vqTY`E4j)uN*s)$5NDpd9^I=KC*acFXAt4Vkbn=iNO&CrI+m*f z@1VEexqRzGua5-soJz8DZrqLC-JyKrhI z`~RVfm+L)ol58$C!>~vd{k?ehA5i;5i<|cO0m0aJa&)6@QVi9Rq_<~L03P>v!7=G% z%~Mz`M4@1>X%swOLZ@zXR>O>P)|E{WDA8))ODDba5|q_<`+y~MQMS>@aH^jlaO)ACP9KxY+Ql?ttCg?096hpELr~qA4vV{ZD>&s5`QYN1sq43Gc zpItWoCi`>m;Th`sX(3bOGt2V?CP8P? zzf0e=qlkol=hqTtLW@5De253}8U{HY_4Gt%?<#?{c)@1hIosBo{wtE!j{Nj{P=wmc z$)sM9V+0WNL`eG6%YniiT?uwmDeIta6w?TswT|4O@hLoF)#N+#kFL~0yJQAm=f~1h z<7V0{X_l-cII=eU-?B-HHk#=qi-6u%ve6w*-;N{I z98D?ri31~H!^t1a#Y~Rkp|8h-`kPD~&En~u<{GQD$Bo8(@7*AZ!0rq`>2jha$pqS& zkEzQf9h)z%%YE5wFn4|@h!nr6{Ic<^c9$$_zu*TZ7`mHcn=bKEJslu)(m%LgA>z^h z2px8X<9yZX^1yw0oK3cm@!IdKom!e;oD=oDe^_2%|9}rUemxGYC`Q^|5YWfjsFi5y z&gMcoU=1pYd{+gn5V&!>^>x<6aLBOg0EPdb9V+fB0ZO<;dq7P*ApWHA)^lwxji{GY z0P;aUI|q3z52@)CX~ZO`H_q1UG``{RoO^yaF}XTo9TLe}B){^#1p()Nq*gC8vVCAD zzXo z{95nSTmkXxVuEn6t>taWD6m%nGyn8e((LuL@BbSo2LgTQ+9`#Uf^|>NW1jz zQh&418d8twi#FNf06Iav21`Klbl5Bw8aMkAot~$1$^%XzXB8&ORa>qjq z9n_pyH<2>S<_6ezqAscvtEjs`CNAJ`uGqYehu5doWXgumSZ%LDzcqfT-D;*qoFu+1 zz2zCHz?Iy0h|c{z0Dceg!R0~qH<#(kN4<{fO^Q9?^X%xu-6SSC2r4U3s`VfoUf-Xv z)`aoI9e>( z&3tkSy`~#JM%}iIgsQH1JMIc z37|CLEQdYvb-j-J!WNAB-%DlkpVhsI0Xba?hciyTLZT>&j`=ccF7$n^Cw0YD811`O zpDil6jGC|#4O;P}`iYa&Vw&T@NSbKV|XWP80Sud8gi$z|D?893X}# z_ngv6(p~U%+<$VTc^!@<4`-|?fh0;0?RbUJWR){SAcPNQKme{tD4+lBaW`z<_rtz~ z{b{Y;^V`EpD^znfNYdg~;Fr5#-Ydt)P21(c2MNw5?V{Bxi%<{D8+J6+X;X&WQjiS+ zJZn(sw=zuUm|;2z7ijIN(ARC;!%>n7Olx8yt>9Ci#~#}{fVq)BlYO*?=oCXwRy{xb6b@z+@ZI1&oGK2NMjUs#8xg1Ww*+&;K8)%g>PYUrcuo@6 zfcLzW&(|hWI(Ri~B+`l7Kf7Z)Jt#3_Z1bI~a&^ zPLx)5969NL%I|VkJf>Hmeja#N#E5Rv@xLo`cQ_?|r`L^M6|aP1%y2&VOxl?H56SCA zcCB{6Q7A>cn%TK=VIkNW6w$LCKao_;%JR$}(7UNSFjj0nueP`NE%QEosk;QKD zvfrJZPGl0`LMVAUYbmSF>@Xx$I|nu*Fb&#~n-=$?=L9>eTaz400Qt$}@YY+2Rudti zGo|L8hg?SziiCZBFF2U!)L`FBH0Z6r9X}nVBcGF$w7v9<$I-JkKFH-vZyKH=&I?sa>i6OAq<%8+gz9M~)IC8@NEJA%Y(k7Ta!czx%59pg?4fT0?Y9Qn@Up%?JY?D?e|C$>fv`&BjTqTt zCRXPfxFQPoTF1rSN4u>xH#q?WKSqON8r6+9G&}vGj!(YnC;r__Jhc)jP@X9jDe|?K z6J(o7VPl@s(~~DEL*Sf_#(a#94gaunMf~nMDn{l{)9ZL+?v{+wrE5*Di=P!9K?~50 z0fT(C3U`~uc+fqqoUhyHqk!jizViX=?=;(27255qd14t>b2c2UF-4hudcGcuM<5;< zE{nwnthVoSHQqwhE5L$ndZw>0ZWqH!SAZtwbp9W zQ8KD=g^(DG4^9Is3VHSBpm82<;} zo@>6I>sBBftS-)K=;Kli+vy@qc8RA{sgk2!K4qn3zF^kI&Sx=#xqZ(|l2~kM4l_f5 z6XO`?Do;AORzWXUmQXu{Rv**Hj!7tmwjJtJWgW!`lPqNw9c~AXDAC;8o48;5Q)MO4n zbSgIZ!RDz=YqkRl+)xX46sUWx$pY`CkEBmSB#)yn=Rz(M(}`y*E&lkM4zbe;u_Yy| zpSRIZJv(?Op4jep0!Z@^YBwg}ZL(Mm@6@$3bk^7S5 zp_<3}ME1Jlhr-Yia8K^eujU7Lc@r27wiZ(pTp$9p79cFapVv3Jq022P=2Es_!zh^^9Z^t-@(ilXL83nxYwlQi1~KS zyVlYc4y=*)tXNQ~8He1qH+n57B;S03S)bW^bH%=^y+4k{A9YN*m0Hh8)W0P!R{@ny zpZZiAHy25UuEe`s9LMBw+D>!J;jx&l{j_jI7vi_QZX`ld*tzX$whVV2s{fU3V=wnusjyi8ERNJa;=SLMzGC9W!M~T|x0YzP zNa>^T?v}*9)6sgvjoGzz-2*mzj~F~n-GkD7N7ZzVsaJt|W9^8#j)=0&4j+qQVN$z@ zf~GJ^q}I#y!iK^iCf)d5GpCK}I8UY8aKFRW_eVBq$zN>_59`AuG7`yb`2gBlLiTJg zVVLRUtut7ayLG*R^9JB6BM>9N=Vsce_zmaEAq~IK%{2`6i-!w{9h&@1l^o03l%(Yk zUdE?*ELEyXS<+*@or#XOe|5M9g{Kxu+QKy(Q@TwSV5J z?=}%$@gicx8>(x&jNeI+zFNVoron`e;%AkDciNRUT}Q>grMRkn1A{M}J0vjWbhv+%ra!D}V6svzqP z^1Ce~RT8!@c0vP0!LB6lGF!wPB!}pip;@&2kx!?qNtef-{ofv@=*gtV1-Yd!xDr#d z#LZu+_jubbUiyqbU#-=+hETksddgBdo7rO&>zIP7FU`rNL#tP8g?hdJye;!y?U`Wi zudJ=uS91#M-ge+)l)K1?yf@NujhsI+m$bKCqt`mvOcYvJkLK;!CW7S9z@Q@LXheY5 zVLw93bx~o{ELTZEp-f(;y5{XE`*=03dOIx;Dz_~}ZQqahE~uv$-Zy)@!!zVJ)^rGx z<~Xd#Q(%!}H59u^ua|zOg0BL@4zJH^%uwk=uD9TQ1>VWEop^)I!s))Ssx*uk;);1~ zWCP84VSwcJUbRBE8$npBp6+4wJ0>aijdy@fHlD2Bjl(v*!`9WqXocOo%O~pBx+4(bU$it9 zCuCf#%mnm~o-6-{jdh`vA#9k{_(CyVI$7IKu z^Ud#WM?STIHU(dgat-O^?YcVov`;CCt@QMvonYK-AXDuZ@t^-1-W|YvThCgFk)Ghs z>x=#pIceB zy7{bC!Sa-=d>b9yXB7bmo}}xqqoI61rAMX%rnqb$jh$oKg!XqrU`&`$LS%L9<#`s# z$+>icmh&C7-&x?7vK;LuG77)9KT+e6bYA+ve#FVsDVb%sD>v6zSk2JTyyve@#a`}V z)N8^0aZU8jd$Mw1hdYWU4A~dPq3ii$_u+(3lEWe(4RnN!Hkf~z~pT8Pz2 zC>8Twk%in0Ne&wY2OcC>X&6n5=+gFb^kQSQ*GE#**LDK?ek=xdjg?BdPpwJ}m* zJ(922=@TdaR`VU>*e9$xqg4!EV4tAJ438Hk^N$~!tl6g4aBP#aJIn@J$yMF?CE(Ab z$rWf-&1Oq!!&oOg>II1;d(tmu(?%^4{@i&1pAHQ7u3zL;d^8Bsy@+zOBC z6-C!GN}}EDp@>=5kv;G#*dtxxs?F>AKn8As3Y=#)(>G_`3SWlCrKFK=t0DYk@?P=V z(`Dk`s4j-AIb^;gxSH~=C@`HdE=N{ zZ=YPpD3@CdG@{O`8@2E+!~t zaFna6c&CZ-c%osVv!b`tjKBI_LGY$<3+4N)CwnOitjf^vJG?YMZb>z7XSGyp&lGg( zB2eF<39>1b0oU0xv1{1vf7MOQ(VI>>G}4oaHV8OT6UT-44ufc13sLIZH)7&Y)#B-r z*9fDoL6yCH)MmtbKC1=?N1NeuPfAVi>GNR(%_JyY6qnMK;Cw}^ z3B(gDUgZx9fx-10cIL(ft_0L*F~-(s-1$4$mR9 zi;nC`G}fuF<;>=wePqF>%gpCg8cQ&HUzg*lG0lc7r_`%W4jRAuFD=u}jj8+l47#;h z>xv=s z0Nv+EscBScC7R z=0S~LCFRSj2-xZ;uJlJMINtaRl5@L%Fg;Kna8#em0>SmrI1xl(BhT?Kj2xkECGmSzo#+x=bePi zaaY^ukVT*OSzJfP!X>zrd7JCKJ*yaKCF_J`zfQ#JlnZ&{3vj+ZO$Fnj<0?w|A=JbO zf3e*_u6$nL-KN_c4|c}HDEnl$B1%0&k0o?XcF|KqqD7;0(=G9ZwGy3-XRIxcRg#h~ zFQcWgOYYzzvRV0rtqPe`x0Bq?zbDhP8Z=twJFUc!SN(|lM6VkbaR_BB^R4{4wG{2NYMr#w^S#7KYt<;djN%u7W)6BoTXzuR&=fZ2;`O>O)whB}XGk+??y*-gSVrtS7HZ=Jq|*R)sK3Emy%; zY(06E2EL+#58FjbM^z6CQuVu~Y%hwn*sCJ^{5fb)=iX04TFzQyf=l^|Q+al~v_wdn z*Gh}9nwGtJ-<__6U1X%2jd0#NY?Q+k{_PFX~%-tj;)d2HZI#kkvd$C;y^5m!1guSiZGI`DeaHbpr z%U@X)cGjNmQ_mU&JE0h+#}t}n*dBFO-Cuok6Ft*FpS)oC^B&n|!Ugwv+x+qLvFh@5|41sB>^l1BS*&rwWGL@@_7%sZ^)pB%!~!)bVa_BN)o&6!rJY8yvW!HK)HX8 zv|={rHgx_jNA`3(*HuQ%8Nb@+j*A$OFK$r?GiauUutW7@&2M`-GE z`;S}gN}|EBnbOhcneEK`3>UuIUq38{Pv2Dgj|&~Xw#sT|WG1NZR9{)o@VWMtaPNv0{99gp$w7tFR9*%{AWwQ06A z*)buOZJuW*qM-yA#$#SK1*{cm|&LOXD)oq-hREzBwHxRt_4F=&-jDg~tPeAj#DYReVk!);HGt{yNthFg!99p`qPhK3%zz;LTyyha_`;T|W;PzI{{lywZ^5Ekc`LFcMf{V_<9~m}z;}w^wH~tGP;a?Ig^> zlomQh9g-aA@_$$W1m*YM?G4Fs39_~s*L;g}e71trSYVptT!nkkh~)DaAENk|>Gbrm zGl>ENFbl{+D;XNm76}eoc;ChA2yoa7W(W}E!ECe0oNy)0u+pqQd!yNX$JZ-#*H}x# zaUBXUtRkuTlR7{Z|(YCzB~uFEfEB2g+#s2s~>8zHzthF zXUpr2J4>INrCP2ooFzMJ`~6D5^P+04RE?e{MktmhSCWifgw}~+9661Q=#W?A0TDMA zvErUp5h>BME~0GPS+DX;LT?yT-3eK@rdp~wWC8QT)h1di5!AR0DXg0m8PUCh)UA5i zdyO5=;$jFN!TU~ZrJl_59PdIW8oD*HRGGj&>#Uu4ZpZX$l|9qzhS`1h7Gx4up%E@3 zcrR$AIL}lO@oS@D(9Rbyd2FU7J2|i2TccgQr~O{nlxLzoj-S)fFspIOY=2}y^)>gH zLN1Pie`kbBkuxFVPAI`9Y)@61|x=w+805$(Hx_`ni_buW1s?%A6HeUG6nevaK=m0fmTL$?wlk=+tYh<%+B(8P9evNVep4RKMz`)q-Q#hJ*fvA z>^eWWivS3!v&_-jHfz@TBx#qM$=y=Qsh|JVXFq@Si1boZyOM>X||S60`rD%1M^%)Egc|wfuD7rIa0vAB=`3c zT@RN$LA8V9OSknrZi(uTvKM~RFTAimUHtT?o+ac7(Rgcfh0e(8qI1d2NLE2mQtqoE z4De+upFS(f_hGMnT} za^O<_a{$)_lnWM{uTuR_<$q2je1xKy{Y^k+SL)A$_@Cpu0mH>$wNgZ8w)J)ex!J)PEAe8GqPvM z{ns7+buoensJJxb;o;(WU&1$)HzSP&X?vE`gyR$VbL)>5JcX4p$zs{^Wu&T&!vj+D z{<|gqdRS#B!Whz@KE=1g;_@{o5omP^R8_^d34>7+iXV_LrDunBiloHV;`zh>aZAeZ zie(L7ml*S9(sAPR>BdL015(KtRO+O~7ZH*&{_$mP_z9t`P+_ugiStO&U>+5_i`@U~ zLgZiik-~dZ5)HDW;>lXq$&0H5^N0Suo^@4ZVXSbjx{n!3Me;A6jlchUJCge^lLHOF zT~sUkUv>g~$G_=MIa5h2x5(e0-gn|Z4S?vJ@aga6*!X`MOq}za>c0&U`0Nk}81Hh{ z7~4NgWitRMZz_^lMfitF*kEUg#uLwI{nJKufpR?j+25)EW6*!y%x?^M)gp&L-r;|k zN*EeYzL`Vh{^}pL*en9P1vZLi$^R&~|5L83N?{xD_h(4X{pT&fIAr*zjWPk{-y$rx z<^It!+lath&@7T}@=qIm0hHS-MYW;)<6-}ABmAc+{y%I4|DI+gbA85({p!zb=e4#b zo7-e2$9Hnd46I6rfG-db9UAb~*`9bV3~Q9d<79eM$Rw2iuwHWcRIaU-ua|1-Ff6Ab zJ^0e>!=7xqpvI~P6m73{tzRhfsdT1HNnGFaLFLxyni=lXH!3PAV5jyx9nkeuz9ZQ0 z^9eIBPXC0Fx^*A5TyCDQ?H|f4hwgyHhj)VU*H~dT&1a|w3%R*BdOFzwFY>kPrKie1 zc{h8ki!0|z;ZSD+A;9;Z*QDP)oGpJlDy;1t?IHf{71`zn44ci8pY}HEl7vMyi@X^C z56!Y&rxu?VwpPZ4k~WQcOFhCC2hJghYl*p%F}yHP@jEW>elK@eyVCijC$m(ly4+}W zxsK~lWb#G2lMnIWVCcxn&M*i;j_+s`hb_y1`Hu%VU)Uc$xrXQGkHfU3CZl%Q0qD^R z0D(qqb|8BiYchn ztWJ|n=8~MNSfTM$vu{3_ll(Gu1I_z!;);g*PBXPlx!PC@!sNdGn3`|5A!@0m{dU@P zB(679Wt7wT>zXK{o})#ws$t-tlx1KK!!K;<6pCfkP)0N6De1xv? zeN?YpAg7Mb{QdxoJ33K${JK`rEW8nTWi{FoRhVX=PH4EQ3TqfOxerPPL_{bH)s8XA zTk*5*{PKV6?{9;F-a9ho1k_k)50?4F!_dyu@o8Pz)uwRHp+nm$#nKS5@xH^d{i0q6 z7%~e89*_ss<_{}MM}F> z0nY}QYCK)Oy;Fiw90(Jwq@PApPUmG;GN5 z_WKh?ugZ+q>!E`;)wZ92XpVFrDs`ab(Mse0L)%*bb@hJ#zK9?l(kb1IG}7JOEhXI` z-JQ}M(%s$NUD6?)(k*B6^%v^-pSkDG+&jZK%!BaRPp`G!ueG+0UBNp!UoTF*r1ugK zsna<&nW!W0TF&MIkMk~qJ1_)J8~X0v4Too-J;qZs6U=MTj&l$G*h}iLhWKsQ^R@v7 z)X+58Py!XvJVM*@Bf)LYaJk2)IsdNZq8pxj@tSJmW@g>o7G%0LrmEL!% z-`mpiE+VGv#}p{`7jrE-&I0jTR-hgctvhxlu1w>YKQtxcV*+q#?8(8$&&RU~;#vGZ z%^1l@(QIsisjsiLV0AqDrq4=3K+w5RhaJQlMDF>WY$Uq3y_6|y0Yb+vDVXWg^pC$U z#xyU_@(&r4-kY+y%IFt2J@3mooFXATSPwVr9b5B9Q|eRnOVyc_4T-gEoS#bHg7yy6 z5X~5#TsNmjah^KM_eG=}aHE`EhYjKlKjO6`y0zWR+1ajSw(-SL7-*N80u^U+eJFOD zPmQ7H=52?Kv)k<22-gEt5WRl@(kCPuW}mwN`-{i5YVi2yvL((0`;;XQ89oD!pf~k4 zYO_1C9e9H*rP%z%Vse2aq^Bhj2#bkZya`hrl}c1ry^dLl3ii)$gy`Ci#R0;22AZ$( z_cvQJ3i-jkQTOw(?^7&pJcB?WhvQVR(zM2*zMOEO4LYgz2z&fYYs~OaS0(%*+Qniv5q(4i5;{2j3H;J~C?`cuKss}Ua z+V1z+2h3Y+z;sa07J^2PZ|AXVU%r{&C1Jh_YA98#>(aYw+|HvqQn{O6nTOiJeq!52 z2aso9_IdUK?23~QPd%-htgHux#?QOb2j-qUC&!Wm-_m^Fnm?|sStb|`&toLC<_;?l z5=FM-ShMh#Be-4#d%1h)yt_XvB{jIO)bHP3Xm6+8bub|Uhe>BL-E5<4e2kFHkHEUq z*MqrN zMkmsaH_m918MBn_x9Rp(DpClHXFQL29*`1v^KFa$KKStQ;9?%EllUM*X}A$jb&mGP zJ>Bj7y#v`ty#knGjrxGqhhEabsqNzJ;d0Ud@iF~B@10Xf6j`UbOH>QHySaIbZ=4By(=Imw&|!P zB?bTZJHUe`0Z!M@h@b0UC%Py;HE{KGb@d4T(V3TfGzmC#MsNi>^jYcP#780j3V&l(J@ z4@)MIWBV}5v25A53frAMM*d+jZ^nXj=k=TPp4a`=wJtJ5i*NQ#kN)F{6o0t`qWE4w z=Rj~C{~T^$2sV%byPumX?=SNn-x~xNCQ$1iFuxs>|M-M{FW&EMNn-RL4+T65C~$v3 zcXZPIJ+6q{z~e6Y6i$?in7TkQReTDH zLis8|2EeuS%e4JheBwV(y&wW295yqPUFGRng(H_Oyug@SRbF8}lms2;<8KH(qDcKX zzY_HXHi01GiSu+mEma_E60SFfQu7h|&jIH>LFE1K|LAmznJb(w-9LBveS$ZGLGHij z>+7;nDxS?iJO4cc?Bc+TMQj@B{qf&PurhyB%_{^F74 zFK)H|HDg=kzznm8r1*dND{6oYw4W)aw4nbv_1-unz|4!-RMY>}{+SSHPdAOZ`D>X* zWxu$^e*utB}~0>vH(F&Q2-XMYmUBeg_) z*|k)=D(4o@i1wZw4o(OR>bxW^RDm$V9mwc!NhL~Pdev~@cjHn zX<}j`->h8w!A8o{e3^7wX)t^Xb2J!c*Y3MalICNhU$xWoPXpj_-1{xboPk|aJzi=c zbkV$RFaY;!=mU9ov@7j`uot8N>btjU^TwgAms+DzdFS~u<+O5n(OK3r%IRpCsMgH* z1V4}?USodP)-C~rqem!|R6K5I+wO*+QGBh%xp^e1Sroo#$yEC-H|tMkK42^w68>2} z_*O_j#3B63XYwvJ>U;nDabsxZlS0kudpHfrItMpu_^gNpGj^Lzzm>3kvJ;-@2k3Z~ zZyxQT;k~Urgps0U?9nwIH%F`J(%OeC=JD#x#kWm?i!EJ){dwWB^BdiT*E2!fL=?NX zXUMi&1Cv4LPGs=AjZnShGYn4bUzQaboC%*r&xP)-*OazE)xU@}m=g`h75>^iT?Ddh zse+QonBL&+)Nz2-#Wu=i$jtR-kMUbR-odoX)* zg|EbIJMVD84P6X3%Bi;UGZKbY-63*5pM5|u8Uaqzm zl&Te8BM&CQg$YA(Lt?wqG}|Rj%r)>Vm@0{Y|0waL%RkrVyGuYh!1{36)Reo(agL#a9A7xuiA*DsZ#M}MxiS^78vfXMUj$( zbSSc;zFQ}_Gu*JXTWM&2&lDM8JRfhz90}BE=h&}!RR`mtW;A8FTq7l(KuH1AagGB_ z8*%@0?<=;Qlznv(*R3Wq+AjchMP4us3Jy(~eK6EkJ?J!4<6PzVMCvUe*9&b}+v+gk zsKTBp>DFnptn4a7~RuNd_^MP zDdpA{T}~QjD;6S2w|(QKk4ie&gxn@p8ZK9_^_iJ9Mz}djdyOfU0$ne?Jg!ZAN~!6p zy%CLTai!Sc6|V7PEWOCiX})CT(<1olcv`K;a6HYibf3kqgV3B*c26wMoR+BM=*9#B z7PojAF;=T+YfxH&Y2HgZ5>v?^G|R4VVz4OB^Y*MqGrGI55O8~17@}3HwlMPq?2Y!L zZKbF0^YkMoACX-=_`eWV>5w62zy4O|pkP-bTsyR=Ce4&4KrS2%B?M+yk%`F6(HybA zEYNssu}^7YtxOX$w+i7yB$;v-C;!%|N@3rQ-8>Pt=PCahp&XmTEpzby&b3 zdgw<8NrEP>^ZMZN+!ypW7k~BJ&S_qwA%X2zqgzh!RkMs zqaM~srI`z`&^1)~=*uWIgftF$$v^D}SsC7(xC`_7Gu9c8zf#L{_C-fAruy=u>wSQu z|6y;7;8rM~Z}q_}%D3Q2G?`SZGTC-X>GrE!g5N2G(Olfo37sF#5ZV~GM zQQYpWg`I<$NzvD#DjDy~EQr`oFconMk?cTIal?1!~M5ax4lkMKR zo<%X$Y%=$SzWGyxJ`^!U(A>ydR zP(LTsfP<*heMBq=TUM0zV7k}-=aENPynr`fAS^T_m^c(Q%C>zE(j1=sIzj0S7QN}E z!Lgr}{dorh9SWCyM~hDcrbpD%jtn?wz!*vF$SN0S(z$v1v7(x9FUTBx*pUGJ5WFEm zC!4xyKjOR(o~L9{pL?H&c>vYoS*z<`B)*lwuiSx5A{- zN%|;Y^^C~YRUVz9j3uP=2u(BlTljDX=P9Q~7>01ld9sYxOPE!5yV~Ay-Ey~0LFy`K zNd-Rbk4>7Tl%rB;kRh)m5YO%FiOAnqKz=P6Exm$48& z_4pA-DQzaz-0~1noW`Q46z5ECuDg_{gq-4kC#cb*%a`9Tp&cW)B%w{EBur_TFji~C%5N4C)F0F0cq+6B3#M_QFtVp-&`y#J3yq4L zBMMlVOb$pV%|n`DKNHX!wgff8V?(#~dCuIj$Ii;k=JN_yEEaFbI6mo}qBn~o%Ks66aGGFdEXkP01?|gxXxV-h5zHo=HI2tgr0(2GIqA2BLw@MiOpA3g% zR)SX3f7>Z-m(h%BtW`0t2`MYIp)n{E9h1vrl-`>tOS)77pN{yT&l-!bs@o!trAedb?N>}53trA!XtPE{O@J7CXen?t z1C9iW&QzaSDqwR)xrPBJvbRHfaAFci;krtKo@R`)^;KwkCJYqWQ!QeV9iUfNO zvgg2U+*77{M*r*zuPz_y|ID2?mrp7ctEI&GSXxK;CItKmHw8tYzT=v90%3{`?r}}0 zyzdxei4>$&1Up}%{&{D=zC%y5x6P7(2q%(Sy+>%$^G3SN$MGA^fC#ME+>phjuB*?z zW5x^lWd_!-{W_Ro?QCCy3KM#B58yPKRGoz}BH8t^De_A~XCONQ4AEi1du z&RG|s@C-Y74RK(p3W8d+1mrrd=|VV4Cd(fx^g?(5%8344vfJzk{JJu<$~WMS+DgB2@WFM%~h zN}BWDtGGa;g#XnIVSPstq(p)e$PvQ~LeJ?v1H^$d@k*U2^@H}qP&2kyCO8un!j6Y`~|xsuMpQ+Z#@kRu=T`$$4=v-J z-mN2#qkG7#5ABnwE`rW^{Bo*!$6iEE{js(*z2nDz^+y!!SUG-?Dgp?m4&S&FET&f{ zDis)dZHQoLMyj-kp9rY@Wg)PJB$Mr+OoGgWXr{rJxReP~Mk zHR^g(t55JZRY6Q~N)%Q|YU{nNk7cnLw-l%z`~1h%=B*}~u)NXHzH|rX&K<|pvAXao z6iR+iV6TYqI}cXf;ZaOSW?|y%41zBi9UG`APA+5&u}?hKwTAUa1p{%$1LsXQRg|ee z-)&=?ug$7lPc|Bbj=1rR2=!d)!(;mRcYMVvQ!G)PYgnOCLFZ|><&QsLc>_bA(JNj7 zj3m!2>l}v|$$}Y)wodDt z%%QjL8kb}H6Ks4v*O<&N6Y(41#Gz`Wv&UnDzQ2Xqk>XuOKF}5O(ty-#1nS1=zF>Mh@8%xa_1XML!*F8X8KDNe<|kOxq_fBI=*VVdf3ej#15->y)=L^UC8Y!P znvI)557*8Y5fKCpqhajZxwgv{@-b|)LcisMF8vPXAy(rqjI%`Tyi@R)Ng=9%0oHD; zy-@7MjvR+TBdqex$t4Rp1R?%?@F)?^cHilv?1Qde2eGpgJ#mAi@-ErZZr8 z2f3g0R`_zUW}Sy$VjQf8{6tR_4G9u&lz;8dYtm!Ke0g0QHiaRU5>h8^u5qE=zSc}R zZawH-hXsXB$9bryi|G=%n_D~AGT--4&<8ORj4hC|-VBvnmyfuIV4)=BOGd{HUiP6Z zV+$xcp`Ug?nEOaZR}eEOj{(UZes`6ZT`STN28T{?G7mKg zj}p!#x$^A^svxItD4LI0N0$+&ONFK$qq8Fv3Rn9htBEnHkFzW=>;o~;OkWKk-(^vo zC^7Oc5PA7z=&p{nJ?&p4!Ftv%W)U5eVb`Yd4mmIPKTZi(A)Lg2@~vfNYF0T~W@tC- za^{>7nxyoqT;HZy^H3=t%mgK=XcHbh%GLvpxIGI^YIM5b5eMk9&;k*#{El-->uEo# zObs6{))S`6#eg{Ui_5Y-C+|veq9L4;pqDGL#sO*YpOI1xG^R$$7kl;t{uPE$_9 z7~hU9n`F81F5hK;hq(E0xTrs^AI+u-W|8j5!!3X-fMG1yccD$Ta|1hH>(z$ACARCH zn(FCG|05B`!CTl}z*+SI>O^H#7r|PEGv@+gd3RGCjaFTcqdbdaL=?R=b2<`n%kot_ z`+<1yeHFCtL&Hjdk4CO7cvAVHE{R!M|+c3w4a-GhOFWWsM!!F zUKk6lnIjLVr}x!waaZV8kuN)AxY`LFMq+dMJE1caG9iUlgB>C(`Cx!(Dv7M$#WaZbURX zt+K0RrDHp3Pg;6DJW)G;Kc)*~o=6L9C3{#F`DdpC0g#5VmM#*qMPShBMZJ0IXNuz5 zXtQpff^JxMWg5k7QeNUURT%*FRFz>ffkf~9jwb*zDO?vVjWZoK3C;{L!aYkbuaY~? zDGjm2{bGAQCbzWdTxm|4g)o%h0GZ<&lFSl3K6Qpj#9;2oUl@uHh0VTia>2JNK)N2) z{%0E|&vXMtCkdpFs1wGqec(#nJ}@;{BRrihg0iXW=YCaLlDcOK_M{cEdv*y&aGRW(4hrY@S6!T?3{9dTA^?NPRJ$1Hr@5O?Mx>)RPWO zJ~=lW>4wvgSE*bc?vF@7DN_@cxO1FqWZ&w#GlbphYs=k#tb!O##dR&y(OUoJHS9VR zm=O_&z=N4@nJQJY63cR^uJ=S^AMqA=y&##^YnZn{=F)339i@5y3VQN_}@p-fd+4*skg-7$!W-tY-25B&#jzu|T!VSZ5 zU^avAD{!RdWbZWUPvp_(ij3eW$f0E?It%@^k>^mldBF}q?9N*{iTUI7A~$eqM5q&& zj$1Ap6|Ys5$HS$ZC^Hgo{H2+@X1YHHKn7sfSXM~m5>hvttJNxjj#+c>*KZhpUF#zs;6mh!jg*kzUMemk{)=3K z%m7q^A8NfHNal<=+-`%^0wI%F%@#YLM7{7t8xr-(kcFSJtQ)(@iNvuWM&Lr4X`^ov1fKE}ZQm4HPi^IvQdAupWU~e zx1I-X-duDU?jY{C5J39sq%GQIKlxE%p7e9+45XohzQ0uRe>R4TrZ-%4Q@Htr4Efoo z;_h1=5)_@Qbb$<5Sc7Z=SYnX{)MGSr5M&uD?&PZ?L?Y|gXxqX|KDtu*5_BiYgH0$! zu&%HKk8kgBuD*L%+I*OKZ#d2~E92J-AwgagHc=a?U%==H+VtmdrY>=!)iL4rZ~b!Dd#$ntVJ5E!9s zjRTOo$1)e;i9<1@Y5S@77s)tRS~=gd`nkXEgtu=P&FV2i^;wb;SVU z#eyl`wSjuzcEd1(SBC1a>;49IdgWoX@(A*q_hHahqm7PJ&64Z^e8Dzoh=THI5OD7( zJ0R^hQ_|T58v<`v{^f9-lCSD{7&oh|lj{l$R|O?@-GBUlq$czj zg{^aE_AC@wa#nwsd@2Qx#2??GsKgpRlEp(voGRx<8MUh8ApTrjIvY7iWc5tVP+C~E ztGb65B93+)r);;5{H{GzOtoDI$z~iESWnxson;4}FlG&ALIm}UE1kZ|bm+jK6SVe7 zVWsXSvdg`Eh!B{dgX!@g>)F{Qj-7X~n3RTekTeuwt5@jPY|4fN*c&y{RW2&qhO`R{ z%GH}bE&{E7NEdE_ceIdk2$8=87{M1|!+!aERPBkDlcxZcbf(hnbr9>?|8VUe@rM3`pGYFap2)aW_jWmnx*P#iP1$mP_3|Q;PHU!@TXNrAGpnp zz8kw;HZbzx+S(lVcl{MZKj(fmmNmsObj+^!g$em~DnBO&%ZcKCNQD1nX6mDRjt|xu zO|0uqVO&SG7=9b%53OyTjQ{+42hutYrG!t$f-p$ic@3xm_G%_(bG8|{RL^Tbs{%5$ zig8e0VQ(RM`RcrAodCe?m%fjMUjM&Qih!>2g1WjkFsl60HU9mtw;L}o7Tg5}tAu~) zYS(}-5XYsNMDxc>XG$MnOCpS)Q0;Kk8^9K{A)JnfJZUzX$YJr~=>Xg_)(& zYU(j5l-yt`kZnwU&$Kx$N9DKz%KE!B2~3-96kt)=M{x00VLJFb-6z0uhZfDlN z#)VxJm@@b-Be}oY&xC+>w^_2&fWKw{;zh6I`$iq|S9{xwURi#>weq)KiT|QkLZ%4) ztyiMI=#@$tE!cnb7T+6(7+4b!de!8Awcoyod2I(VPJe<-#8JL48wuYWP3X4?0yJVo zofo}Q#r@p!WjX)$1&k4D5su&J*WVj~?>9q%_S+(vRk*)aDg2A5=360?TObswGH`?J z2}o-)sp2djexKl%EfW9+-A`ZMFn9ncP6O>a9&3#m8dgpGW2dW=cj>czD>qz3&5oxr z!p8G)Wbaz3inr9>tu>gWXwKX?zKC)yw~_6GnZ^IV(0bk%Y-x< zOwgj-kJVNNN37E$Z3#c`q7)0|`Tj$0?!Sq%Y(Y@#_BHls*&J&@=-E`~_MvzhPGV-}*}?CMEPymb zkSmc8o0DTusGPf5Xka+D(&UhD=UKn}St#!jU>Wytcw(bJM$qZB^)2jjZ5%uCB&2h3 z3_+Z>-~*BTSOJPcX`nj7p>xay=O5$R0|zXC^djITfCX+3PhnoI)5aqS0Lm98k8F(} z*cL1Ae~{3qBQAf=S18+N4j+frk_d6qt_F=xOAJu1UraE~NoCTAx>s>%Z(wn89tGe1 z@@D>pRC}|%bWb5mnXkjLp;9XKF&l@=Q4%nVyXPG&Mi+UuiWy?SEuCpnSflyowGRg6 z43@67&gVEYQl3;UPc34<*sMvvho16pZ4!NO93>&yt_aIulQ0@rBi|lQqhQsXm!VWC z(;c(Ph%`HxXloovX$OR-`$?SV!wjovLn`IrEsAQx(>7uNRSVag$v4Y844RGLv}{!m zL8mjVdaxKgojTl18NC*4eFvl;d>wK7eKATy0K4@=EtAm^N;O288Qq5m^z3zFybr|s zebQq&vYnK6OB4O!jD9iPc+A@CC%bV#9k8K8t8n^eKx(2XZ@I3N%d2=D0=y_(C*Fw% zgJex6aXa;XGGE{DJ|{Bgqkq*Vcl*cQD&Z{k$0c#HaUilj{Djbk4+z{lkCEJW>L*R# z)txUlIMW`h%(6{l?rnFHat+qnURNpYO3VHJprZIZZ*^mNR4ls1FQ0PkbMy2c&`2@5 z!GRz;O7$*nY+Ca*TcLtN}rwR5dnxEQw_{9>%w zOfnVulYD@bFXB{%#6M4}%>WP@#j>K*99la-jAe19ZL3JRfJ)%@qY6w}1)!|Nr}v(! zx}Y-a!*Q?g2dJK%dyd*GZk%nqX%JE@+Mmacm&F4-Z@;oL0hN>t<|289zYvLR1C>}v z(m3m)QK{y|Z?pwQ&T0=??hU_~;FS#uBR{tHYe&CiB$qke4KWK-jM#TkoHQKD$P{iW ziz@$YlU_gn1b*|cAm+c9>7$?*8l{SbXWGUI#PFoQ`&69oyOl+W%8&aO{zo>cRhBEH zyCWCPPS$nJ_Lf9K&=B(qSxjmsb2Z+8^HiFgd>nvf+WKiyusSW-WrqEoX|_zcU0U~U z+EU-bYQ8s9l|aQiG-?~=Bue?5pq9tY=fUlSv<%!{hF_tke_s*<)nGn1j~7QI#^e6D zq8xyjKFW}!Pb(imvP{{b3n9 zF=d-fcJnK0@sEv1zaBz0qnIdb#?c5s3d~)ryvQ-r=jZ3o`|jCx^F~aR+<;%pZC?wMnERgqG_K%v`~} zdiE1s>l2pAY*i%`hz-CK-`V%DPSuFLE>x)x_;B$^zuVH%^vbZpD4g=Vzps?>IltF- zB^+U>gNim*3oG3EcEBpt*#JNfvCq*gTiV)No>tL~XcwMWF=&0uTP24~2At~6=cCSe z=rj*j4eK=O4M0LAWgC2dySmnEfHO_J*nB+wiBZB=l2^U%6R{N5JnPcQb4498;iBG3 zZY_srk@iaR)blxv!OR{M@VYUU?AQ(qgwP+0^qVIa7mL>wDj89SR`)55PRr;&mwoQE zB0ty%x~k+I_w;}{uaC11XW-p7L%n_mY6A^a%dDVBSzacJ`S6sRtMMpE_l{1c;I+s6 zP9E_BNiM?~^3OZXCbmGOpYAo`n+xRt*XKl=n9&V%ozJpm*faA`gmPk9TR>W7P3)vY z(s@${Ka=Gpw$UryW-oe_R6z8MK7`Pr)p7rstoE9!_<`52``&n#agh7oAgn~AouXLb zbLwy709@4pysy&GW81LIY1gKj;52fjODP-OP$y9l49)Z3*cK=jrdGo%+Ou!3szD0M zm8gD=rM3}1(E^kBlV{W0rdv7KU=X&veq0uaIf%USk7)U2% zJU@ZZNvbWZxY)tIf8n9GkhLD2Mi;|LSJusF8A3rk8C`!Lr82;zWdpZihEi(e*`u?0Kz<#Ci{?wf} zy-inl)v^4?4dexO{uY>lyMij`;=iV#@`Ze>`;dhFhusmy%l%?W;wiCM{q0@Uy;zL# zWdCG6{^y}yAq|MUSeV&EJEebTLB#_WBq-=OP(5e!aS@Y#hpkfCKgD1H6SM@Au-Izh5U!n1_C80lL@4jtMW0Rm|9@v2&$a(rTeh(;zC!P4*I(@b1qwV-k<{v6$S!Zhi?5K~poa0+n)~n; z&~#*K2VMWLQh~K42bg-cD6BAlYy@Dzlf5`>g)DaK+VHsIUq&??2LOEieH_|>YF^Ls z7dl8F#H|68zK)_hVO~txvO}h6e6)L)k^QJJ-=YAlwCNb&0WoHm@UZKLfSPvOyi=VR z+lj2zNu1BDm}hsNDFA3U4+hqOT457Nuh^?!Gwdq?xA92GvO2Xsczd`0ouLY-NI3y@ zaVN*k+BgkzeY9e=x}Z^a61ESXgCiYRzxpIE?9NO6g+uw1B8 zm|zf>=0%h)Q2uu;0Fayp)TS*(5U6eWN=TzY8O*eC%K!aw;n zSU%VGZn-roYzheQ(%S9NM*AMrC9C+2OKBGdf722H_~os!r8h&Rtk*ZSTO#W6+O83V ztsZ$V#I*P0OLT-~j!}5mjz0o#{6hwXYGb~w)JqY)g}JjzHa`xd^6j2rWXJb;84b^( zCseA7x(`pZENC}Kp&tkvcSNV|SE^lg*qlq3D%1d6AE`f?RzxEmWwa|atIQUjSeq!`U^Dc7_uKZn)XuTcyhq&+KF1;p zxe{^ozEGWIuO9@`PPyq)cL&namwxR*c9~4;F?7sl653nCLh7Fuag{r%Ho^=hi(AzD zQ-yITw3-9Uk2w@}hK*x@d~1H(G4OjR496B`a^^UQ8y|jbLd|hE!#t&cfmQ?0Y zBU0A9gLLPy8R^48Bb%AYSX6eznc|i&nL=hZZ-vw#p;RKPyrcnP;S~3Js0SUV|Ebn$ zntB=t6*xidB$iIswF6j5EPHiMjp>4_dcC>9!K6EXLyO0p>!Zy{Ipb||C>*xxXT2xq zTkn+77U7X?4wuWsL6;um@41;xC3PmVsvHiV^saLc+{zbReoh&h5sR%j4pXHpG8c>Y zU+;lCT@-52m9tPKpP}=EDq9)4o_F8np_NXmO+{;R ziGAy4`CHvwm5@LZhkM&PCb?3TACuJ_FUQ{1(NY4jLf-g$iywQF*+n(VaoqRju~X75 z8i=q4c};BmCK9vf#mc4l4p$4^T&}ykfCArDihNUzKG+O|MLO%wxbMWYOgEGRSt2-0 z0qPMT%H&tROs`d6Yqrei9X!r4o3Ua!ehzd{eq%TsUniC-vlJm47@F`%3j`mKEBLTa zb5E6Ls5G4uXf_L|5EKMV33zXG3hlBI%AbZIfvVwHs(NMku z;U|VPS90`r8ZASQ%rA4$f6$jjk*b^<+Zk1cCA6hsw2Id{K>)l_vpZ24y!)_kKnYOE>fe?d@E-TD85plFik zCr)YzyBt}Ptq&V2Lsltr@W}^U#H46%!QQBS#l_XsIfLy5<>T*wNuzF1{TkyNfwD7Q z0#t4pv};+lqcHS6l$evgJz(}sUYdvY(+Fljm6J$5R zAcE_7lDMkZ&ut&Ujm0g^V!Gg$P zZ@p}$NvG5SdV8c4lK(Cx8=8hA^%n)2Ca0+*K!Zo?tc+&Db-YlmQ}+p_AGb&~ON)e} z{Yv(y;#-|2xA28N=WQj-J`a1gaTCWXxP_MWA?OG$r47m*%Gcso`9y6mu^LQpRNPrE zSNH+OQS6pXHjQ9EK!d8G(xlrVA=H7zN>wV)>yQqs`@AWbJjWN!$T6%sHi0%a;}l_$ z-+)fl*3_t;?3)!^1@S7)q^vS{&kEo zC#p{c-AF|Z%#(F*DyivpFS=9xcb+0&Va2waRC8MurDkclkbJY-lIs6Oe8_-BM=RJW zkp&6kQQ*j+Mxmb=RttwU?T(q@P)W$(&f@$ZS<;B2I$PRS`CeNe9{V|YMH_28JEZ+L zDAA$!_6%t}&3M_{vbsO?;laT`bHUI;Y>Nat?tS4ub(tdK=CtaD!zZ$zCIdW#>A=+R*H^eC%R7 znYM87-Sm6t+OyJE@+sk!yLCBIoG#?j5pi4b!GBx7I-|p$qtTlg)o~7PruW>on-YOM zrC)P*eACW^77Ij*8msC5A2?ES_J47t9R&aP94UraAPJ;%)6&~mOjWQ+Wy{7&osJ-G z(iwCGm>t~LE=jIOg`;~b2yODcCZ#3`PHQ%`(*Z?Aj0pa4=1VoENY)FVLNTbx?RLZ@ z;7WKiJlQA7ZG6kxRK<(=U+M+;hCOb&W|CXm0H|4}9otvT5%M#5hRr6*xuH(*Tv*cW6djpR58tn$Ybq>~`VLDrrJkU}Is~@N*Zw9Op_|`bx zakvP94IqTqSVW&{5uFXMGkr5Kg6F{?j#)yY+*f4yc8GR|waXOJyDO~DabHL)+<*CK zM&#q>7JJ_&cql3gt|+jylR2OOwvCoF^jWty&;jGM@;q$I1T5k@N{hytJPiKOLD_hz z(&ibg7tAWe@gkFhtqAt5AnJo|mBW%WpGLi}RLtdFpDT(lBak5+5di#JP4qttqAP|I@pxM*ycJYFz6)qsah@;C9M?qmPmelhE?9T1F6bP^_?+=r~ zd(%`atuXul5AO=JFlBMawmp`_`F5;rfyY2%ip+xRY@`~tK_5jC_^1C1Wak7|> z5`B0su|D2!RH`5`BRPz=xBT}u5mkPC^7)m3gMCO&FxpR+d>Vn9n@VkZLhPAWD?%$= zrHqE-&0AkD!hAFpSF-RY&rM6`Pn7e_e`awXxAK3nhbh6VU!LGma3_F^Rc>%=0yod3 z=aci9G6T1O!ZrF~+l~#uQfvs~nM)tNU8}~^foe>}v`L6gTqv>YkY<0_F=AJ06&bG zWAO{*vKD=L4_8J{`l%BvE;G3VYVCXf!?TdIai1{+QfmSFqA+%L{XVG}84-{CPzb#D z*_W$!XSiv)_UY^VZ-h{B9XK<(c8jEW2Hx>b;EDIK3@=Tw z{)$vx+qySIabmF7t;+eJ2qr;fI+69eP`*kYf+GF8{faO0`PiCZ$jM@O+cP ztzTnK{x9%Va(G#mBBjz;ig926aFA!2B+wCcnwXOr2p2Cyij%- zzoH{6<}fYFa{Nkx@~G09hepH7h4W)tERLI;@$hR)<18?{2Ju3|BQi*gS5N@2X_qOh zU#4AALn4urP}yxLW|QGbxn!*XdaC};jFe;RGk1$Ja(mUs&SAPW-G{Qas>m^B4TGHr zJzBytJi7rzYB01}>s&x4>N~bZW?$el_>B%J%1ws?^=%=9R=Mi*d`ywaimErOHxoAhO|!KI8tAF{)Fp6vi~*T zD-H+qck3U0?Gpzg8~Gq1L117tL(HA&TJM7$Wz8)spFUuOIrlXQpWN}UMju~keYI0J z1;?!HXAi}OSDNSr`w_lEXLF*5 zbzOeKgwZ~EtXdS_#d^y)KHI3AV$VH`ZU^rf5o7~O=Vaqc)tu_1gJD*?rT(Ox}2cDhQ2rIZDIOHvjY5RAu`S#MJ* zczYxY_KS|?1!HS4=|Y{L=>#~@N)<+cl{zq@QxPh(W=dg zwXskpwqL6VBD`7LHKp|D_D(L_X`|;|aA+&-IN5PI?N%dg^p}9%mhnrpuJW4UA5fO# zwJbei_^`}GaKE5aJw6y6|5Ml1C?zEZl;=g79BEe)CrvCu5T~d8<9fQWmaDmoWO`s| z=IHcEzj1*+@%i4P;)&yJ#&u;mXp6h|0K<6OsQbE zFHNOpY0ZO2V)gR_j6R(GuHNY&_sy4@!cT|9%T93*9KIF_BdV*Q;#nHjJfCm)md8Cy z)%VSAoYx3G_k*YKY>%BN_6U(iLp!JiUWroVThRll z>P7AmWfupr^Hp+Uj0HoLl|fKSFdye8vZle9+(NZsddHYC=*&}f;&YZ`8$v-G)MVTG zkRNkh=79EOdH#Dk64lC}itGIWtMESx>f?YV4lPb*~j#|)7Fbbi>T}cbwgWGyN(~(#uSu_Z;5RU32 zH8?a=EU8lsUkcAMW+m?xxt7L}fEIRv;YD@r36f;%2FFI5e{D8UhI=?2`2d*@QkOls zBhM|MZY!tA`zPZv7`3ACZ#KN z@orxpXPnH)gHM+i{Z&OGfzQU9QtT3iK*&(bn-$>H`X@b$GWDTUsk+FdS``NR6eGn3d8+g{m6d)-s^4TKL7 z5w$XN3M^+{YpCkzpxc9 zR}t`4$`Ju#w#c4O#uxO*_cSH8z4&KC^vFt;)OOHzpg?qwv6NkF4Wz(Vj#AoFhm|q{ zHA?4OX_ zp*9K$#;Pz^joZJfM6;X_XmqfmFkxGuAd6hiaw^O-1IsXh@}zMuyN7ySJ-A5r$oKh< z{ZM3hW?0C3<-nRD(XKB(l#o7{(*j<|eWNIFkW=Pa?DIHtS=4Tfu4NtK8nAr$bHQv; zrTfcOz2Nr5a_t1oR=fG+hpPFt)Pr5E0|~NY&uAW)OIRfI<@M z;14q&m?p|awZM+*G|a#u7d0tbRF##P-5j-X1&Pi%_#W4N|e0A~}O(6p@^hWB~;Q2}g1qa)u%2VL(KXoQ5BZc`9WdKOZlP0BJ#sG<6)??6)I|t(oF+$qiUX% zmJ5R*eXXK!J(bQ-DXmj(NKw-f>Y`(#HxyqY&aj~_xwhv++wUoh;w?bTdRx#rjUI|- z0Rpyn*960K41O86tJ^AuUSVBfBVyUeo{=hD$cOpKY`JgiXX(YM^!&2D6*;w8_pFoC z*3d5?>T8@pS@5|`mCSw)!zF|{tX@3PbmisHce&x8mP~YoM09eJzD@f!hwznACCza< z<@*o^ywihRKZbf%QoaBd)OHEF>S%BMXsV1QK-pf3m!?o{(pJLMSV~WSU%BkZUGZ^` zNMO?|EWO2gJi5Q}F4_>h2wQjQKLSb!#q!)smZFD2{B`GB%CL}dy)4_iQ+db54nOT2 z*Fro*EQ?k>i^R){(-kT8N|lNRKsu<$g{zJ_ko2ZxqP%3ylPoam_vfWF?F5_Sl1B51 z^cEtfr{jaSqF0M6&3_(2Cx<@pAxMruQx0ts#5B_EJVd>jF2Xfc%j)puw?j|f_oalN zIu&ZCld6Ls$-OcKu@!za+$qhQOVZ#X^?JsxPjphM7%wy~bKxTKu+n>R?NuExw?0$f zr3^-PtWLJ2$e%RQ8JoaMMNRZRx6ga^%oRaQ$85)!t)+sqCV{Pj)k`>A=G z1bM!z>J3aiJ$)6wetj)~vtZ>2nrcrx%Bt7&#OCw+Zumb%q^EOja;lEXhszPpbj(+yz9=^LfIEoKTLy zaKGn)uEh-hGcrIcq^|*T{2x*%y96|BWP8{bFF%e*u3@%|YH6B`2sl!Rqm7G=osdhw zcRNb_DwjFTW;4=WboD2g*cSqOftguUg5lPZD!1s-n{0Gv_Nb>-RO+$&_TAdwr<2Ow z^C*>)U{u+olZdWhdwRX|M+u(}5)-R%J0}v zS64Sq5Mlrw38Ge~Xto5`mD#GtXZp5h_ zbuxh2*x@v-6$cO08GEANpc;PN^f{Ew3Ea_$fPHGy z*w=eK=&o0?CpE7*3w#9~XKtrFvB-ns+w#YtIDU`OE?IPR8?FO5E0UnkIcdO3zf-gy zRX1&cuRndoDTiPtE|njN=`jKzl|;q^+mp(yM*8nuj8p zLA{Pzv+n&QQWf+LFsDW|8}*cwBd#>fWp~Km^(fWUuV!@9XFF+Plf29yyXV;Ci|?v+ z;M+m4d2Nv3?D~yxaDf(D#8#$!dX4GX@z}(G_g(@F>6l>TmW*_3hwIetT_RX+s~oM- zu*+jBl@`3_ZKK<-g3&{y4mGH=W87Gl90ibD_VVaNMqvd744QlS>lcoyOQ_g1Wn&$E(Ji6K_1S0B4C>Rl4S7p(k+Nq0n8@z+hPFn>_w zXP-IEqbp9!&KCP56W2xyp{8c@V=0gd<3_jLz#-xBGq2DK>dU@|A4NBsT~#X`jGK=3 zlwF|K=u(t(sUv%8)NZ>p&vl+^=7=xf3 z4kuy+^pkjPw~#*drw)4-+5@9EmQ5@S7GyytOp!015*P_%KshqKtO{j&+%>>x(CC)S z_Uo{KnM%}ZP|{;`JJaJZiSy<9Sm{ZUaFl|AYg*YKlo5u84apfnoFuZB4$D^Thg)Q+ zSQ8&44qK8pM>2_PJNgZ$@=@-Ll(!!+hxtn9V)aHWecuSc9uJ+lkH5s(3~5S%dBon@ zI(N{t%vzGXB2SM!L^(pts(LyPz0^r5r^ZROkIU;_$Yy(!=q*MDmQAbu-hr14x&3w) zpW?fv2-jUPu~U^D8Ff=Kfq);bc4^t=&F&G^BVP*+lm z5&zG-*Hc6F2!PNR%#5&|8c3XpDjzGG%t)Wpi5#qDw^r4N7TQqRiz&k) zbqx(|iQA1*JvBy0>vYZhIcu!zgit%^q6 zkeXw8iUSlu`a%j1=c^#$sBZt%efmRkCyT{z`ku(bc9q?jyz9nx`{hYt2c70kq{qQB z)_av4Uv$e$F-63FXL+b{g()2qAd0eXk8EjG6+iW93GLh(CB_qv!wXd|KU;Xl(!E z`FB1mL(34#-g-5p+j5flE}Nv(aty zx}D-tk+=cNRNdY{reeJ;t%DKNJB^;M`jGdE$ecB8y5hh$&B=w_+1L-ip{{f+F%wf1 zjk;W6{7+s2fsqM?OUqv32{{o~a(4oJg5Mydix@!M$^{nPpMIBefvE4cv^4yFNh;m% zDRPnckqm(JXl;@n{RQCv1NWq>$hL3tbb6mg;KSz5&Zfc^J0{2W`5(TSA;5#t97H9% z2^{na4+(0P&X@z9jyp+2KKm^w;5Vkbtv8DUbcLB8vw6|LG0cL@i?O7f!nYdXe+iQ@ygTDZH7+uB4KmVZpyk|V>V zd@V`y0X)}Lf~fFqSANUncQ~!>|N>jbXyc@4?TB0sJ8i zqwA6HdD1qYb_WrPNr9d{Ly610ux1t;*( ztw`nn2ZhpD2Ub=-0-UondItM2H}S3~e@i{-ZgiT$$J`RYY0Pd7W%F}bAG0t2vpsa< zXijzJk^K)lAJ1cXk8XuKrD|KO65^tLK3L#n&j|_vwd$;Hv$f_bwel7}Z;>rIaf$y7 zqmThGpNBrAvg;6sh1X5xyDlM82N>%wWDffEz=kTT3=Q%l(WQXd@t8gH(TAiPYu#(& zj)@vbozx4D&wC?X?+(9pyi!Xnu<1^AdVO`aG`R|ut? z$X@$ENdOF4AE32V7xLxrB~fk+_|r`!Tet6T4{Zo+z{gP)z+6JDY>d|>poepVag%m_ zul@uMAD>`7ULirW+e^*WzZxqumieHRBCaom{XXY$lu7zBfuCihaS(_x)$nan1O}6$ z&F@6sG|DYuIuo^63mtn5qra#_f8#%15W6toW@=`z(h;EFAC3ADqeB3NyVtv{4zEB^h ze#`3`>gaPA9O)z*JUV|(b)esC$L>U*Kx_ ztXL4DTzI+VfcCe2XVa3Wb}fK@d((8V_O_G7wce472hSF;n=7%*6tHnMl(I7TGUcbV zJMXeDZyC~B)?Zk$HEhxq!PWv-q)wFIp_;lC09+doN1aFY#LQ7*=->&QuE2^6ZowE) zfdj7p1uh$;)G}#Th=3Jt_3yS{)+;ku50>wHbz{~0iqM+}FC3c>%KT1Njiex)Pdep5 zSE!%tmpGP~zB~IlR%xLW(3PiRX!k7#qwHR9J@S@qq98Jg)$2uEBh|QCID>wf|64>@ zoNbBWcz?@=3s^LuLSXAFB*9SCqZYkxqzz`8x}G!3T7MLzWjD>NWn|pz8fe{sZdBrw zILh!l8SFGeC7Y~kQGf2IU6AdEd`YnbQee&pBi|^E*DX5PBzoCy_jpk-AOQ6&8PLh< znh3KD+9Sc}oNUDfB>|D^QGgKqCY(W_%FYssa6lrYpV0ENF%Uxk-L&9TNACV%O0(_Fq0mA#F+m6l!R1#hWCVe1P?U&5Lk zBf)RO6987aJ;jNid*Zr^wm<4RzN|Q5anlhvn6Gi7T~+Lm%=_a<`MrJ7%w5AO+Q3Eg|E7E$e$M%TYLYFXc)B8@Y+VPW_p&O3k z;`AUnTBGcZ($6EMeoZ20*AI$%-P?!hoPbS#13Vx_n>WzoDG7f>%cWy%$mF<^-tiAj zA5pi`Vp}KD)pmVXyS}x9+QGih`nw0@2p@=KOJGrhEHk<2@dZ`N9R;l!3|70{DvpAc zK|uc%uTe%7s^v6T3(J}&&+0S8COT-3vK^R_EYQ4Uzd0?}B1129J9yV|vJ(C_;L*6L z9+;a;Gq|!#_%+J;;_@bcfkv@TmKE_FQhDD z>|@caTWebG?}qmWHhIkZr z_PJ1~b3LHi!dDbS4jj@Wmo|wDTMlS$GWwTxb$WwC>G``*mRl{lE1PX3Wzgfh%6$hjm=D6WxiK5WnGb+Y$vgkF(&C;Z>%x~ z@wATrVmQT2AT4#=aT^ql;_Z(RJ_C~cP7YgJxTMXV$g(DnFnG4dm^iENf)|V&9Arph zoFd{-fssm`4~@U8u+y?{ly68nUcQw#ODx&q+=g&mN`w>WQ8-*$iu8m^lZPTi+GifRc6q?q+6c`f|L-B`Fc_IcAx z9&TE6j{N25ovidL_YSxg>TE0+Q$4>96xS9GmCiaWk(PP3qG6U6?b={&KI7V9|96XC z74Nr&$7QoBd8Cip;+B6fHIlNHCm>I^ER`vHGn|X(QEu&+(O{oETEm?#DxbwBWNM7DC9Q*`ya5QbZW?orNXb2&3#9Zmh8mpp_#-w`a6N7snvP2Dh$ z+>uE<)Pr;Z#~q+4&hfjL#7xwtNTkf6ft9t>DcbB*3V+L#XUEQbk=> zrv6+LaK@XB;Gi4~+>c=+X62xPk#nLu&K4@WaopbLSGbe8+H(_$3uW`pkgAsSqAbg0 z$A6!Xs+K9Ue5v5RGa$iQ^*QG4)NC;306N^(@)&lu^Z{Q>4BiR*3#v;$CL4Vsevd^l zG00+YyEwjV{N4a1gn}uiJ5M(o*H3TxBZ%96_waoeF@Vp%ll; zAVWnaN&0=J70ZKJt^$4F=1Z}d+Epmih|M#esJUvGZL7^niZ^>uPOFvz$VAb=!8_G3 z@hKLUY5N51zs5CE&VAs()lkn7@7-iVe$Y$8y>eAkomq8FTtgss$&~vY#n;{J^hkv= zjCzC}Nn~<@;1r3$oKP!ClT8{oH2KlhHYIbDv z;CtUz>?|9J$l4Gk(YhHUNsobzQL*@s{5F1S195>=x@oQnki-65g_$B4I52ihypU53 z$}iLH0u@kXN@rGmd=})Y_Ju@iEo}%YK6qf(5tP(@$<1+%;==$Bghf(K3yK-{#Kt?G z98fbi!Xlj8{K}^+WcP{$9(;pNR_a7mYBmQ*jhh!}8$yrMj!6IV)dR`MHzxe9wmp5u z*Ta;R*C3E=>Wr5iXmIqxxJ2xw`&$|K>gzVL-k~H-UJeoL;1phn6B^)39d)82Rh}Ez zmz=&s=gZKGnA!*__!z_V&BkpNVIlm9PTOiGY`E4Q@vZ3?!&FJ9$~2QV+AtDHA;&d~ z(A8u@7(<;E!+b`AX~9B9ntPC-jtk_XcKhw8Q+2=%WNMuSSACmpXG2D!+b*4|cW&2u zl+~@xcblm$YBhMcgE&5y6}$4R>Z>qazMexHB{7Vl0WF2FbT3zHMIM5J+m_pkuf$o# zsku5;U#Sh5w>EUzG&6;6wiwoJM@g7;cJ=0z}=dlM%_PtR71Sm=?d;0 zgGQE__zNf2|DKdxV1)?`_K{Q0XlxiDKnBi*~v8rC8SHCH>+^|hA= zy2fc^%gF}Kxp@sQ8WVzMHJ9PgfS(`p>rH-QPET(2-O?PGn+-m6-@AheM|vJ#d!}Ie z;jSV{+@7%TU5GdlPn=R=<9g`c=wP$%KK$drcb~r_0*~~7u+tyzrn-|()TWB4AGTI0 zA+ml@w~uU^c~~KX>$jeW%0$#3I#^BX=SNYonJhv%LPXt%MK_{A*h<4E8G}^r?H{Vi zGlDKthH5%~S!xq<*VK;_s>|^-5>PoZXj=;+zy7U#TL{Jb(*JRD08Q72x@`i_jJ#VR2EwXs;UUyK+h4Zm2Wg)5VTRNN`b2@PaI@Y4r=9Km*Go2SA`twf zaS}r=SZ1VRa57BKn0!}n+`C}&NneHW0JT=@js1R+C8pB7J!Db1j?bI+o3m+ir+Z)ISyY@7rE6T|2-5aU zUz#XGQNwY+?)6+tH-Xx&VGEUpx5n0l*H4I8cW~=1!_L^{vS=ebCDPG%t_NJM~C|0q^9vMNM7OK(GcJLYpT0LpzQH&O_V?* z{l%?%oC1vO#XG#2gZj1)uN39#=(Uq$&D*J?O~t;v^;83$6kD`-$;9ATtHiwBf>%Xt z4^&u+Q5P3wFo`X9$vFAeTn0`Dj+(7~w3dZ^`DXrRT|{#OIcnRiWZiiq&|UKMGgMj> zRtGuCobkLF{K2FlI+#D7HT+kpA=;ktZec|!eckBxkl;HyGAo@1_SKi5gy#d(zy)lj zhKr?j*0G7KPmezvhP@m({6or3M69d=vUZ@EkwLm#v@FLv1)Qqa;+wXPv@Xk`AKBmF z6+WiA(G1?YrA`fI%KYe1me|dlW1Lp^HGR+h*|Lm3Rd{^$Sh)ga{>T$vcwjnX&d($7 z%^0F*2Tuxad4Do2x&6Z1YTMG`D4vK@xLSvke9g^)ud`H#A-KWPM$DEAymWh2rc%*{ z-BwPDPbiE2G)QMu+tWL8Vg&Dp3@Bq|z~2<`lp| z&ziJf6CM?Mq9!op4ulsP*;u{zNdl62VSXOpEJ~uU0wQ`rD zY|uXCdH==q6wCiqy`&82uXGjdTaRdlh+8^Pb)4r7k{PDbP4o!Pw>h-140T z51fZa!4$%7k*<^vL7n$fg^ZLh!kfyLpI?mps{3N(%~AIAD}QWF<$24k zKc(;HTXfUkkKpIh>f(nl;b?n}PbLegt<%9&da*~8wHj00Ai~ujO6;57Hzi@$D zTj80EcJs*$j$WzNwnp-lYK-B2$X=$Yb2;F}A`?pxp6_LW zoYE|>G@&bu<2a4}i7aJhW-AvupFje4P_5sb|s z^HD0@Y?|xR&gRq>qG?2O7g~92WO`yn-@83sp4V$DM*Uy(p#@~8@I#{W8QG13{Qw^k z)R}Yq>V-Q%-ouR6_;^63*bDLcwQN_fh-%GhC*)uiZRo5kNQ4`06qAcH>4eN|r|JqN zwW7X+(DMY$g}l^CgEj6IgvzyJ_tA|^LjYWm-#o*Nv}6|js7NP)Pvn^XK?&D<&+Kql zbg3CY@6_fV9<|gVwg8{kNGULxmFpxNY_g_y=MD&W-yb-+$0VEofQFcHr>AlJfGJ{9 z&7J<_Olau|lSsa$3fzJ#-JesW{#60Fkqr(sj=Dstud_WeVWL3!N{5C`GHQ+U#I-qa z?RkKC^_r>u9$(5M$PRY)KberV+vRUo*Z%R*`GpM!{A_H^I>2R(pSN~!tIKaLYqlN0 zeX<=ZV$w!mjH(wVe`O$5hs+d1)GC^c%!H>7=stj}Xm74F$8E}dXNuQ1)GXHmKQ2W3 z9vfYJHC}J>q4DN89j>e3VIluPxgb$thB753UGRLc9^ZY<@f_6W#%ZO;;4{`ychpoF zgk4G!PN!^b3Rh8ydQ1j}aPKim3T*w&g?nLno)RfTUg1tzYTQ@~c?1N;-bg*uaBZnJ zlUr70@g4XWg0+5l!7m11sx)9#`NKYBTT}U;q)H$Y5Nfw+oy%S!D@gct;;Onous0m6 za$33NkQfusA>hP|ru1+v7lIXO<$DZq(~19PwY~5HYL126e)N(paK>TP?KI)1^%ukY z*(KFNF@JFVH+#VzEp(p9(Qv&*{PoVDHih+F&N?HK|K<-r)k^=$9mz80_&14oM*;j8~2DXV<)W%bl~f^UOB=PB0CEZY#*-B<)$S_h5f%R^rq|I zd_PW-)bM}OgFuR^HIm3Cs@Ryd=9%=O&3ysU&aiN$EM3n9#@}rXtiG!L7c1``5s#iZ z5Z|o*mesefDTm&?2m77mvc8ou!~HweraQ=i+TGhbPt(;}^ym^57a%(b3T6LFM4mHx zrYm9eH$|{AJAQ7d+Y!k9lyG@g(K9$y3a^Ke6(v(7@BPljv8!`uh-)z|jkoy8+zsZY z4}Q<%Cc%3<^0oF&9wNtou_-?T)>-McNCE*P>cL@~As;WVEiSZ~AREda0nA(;UeE4PYP-o@oj;0? z9r3 z@t4W7(}4i*h8hQCH%xD)){eXOoLH#mk9z{MUmcF~z`(%!TT!4TGB&a`(t}p$_V7D^ zIQPUh4b^>lvnfAK@~ztj)6_B$SwHkz8O$s-_FqjpoS+q$BxUor322_P9IMTUu;-e# zGH3H?lS~sF_deKo3+zM)p}Iq$OQQb-&`OOq?vKuh?Tc|9DH4uy{X4 zEv_KWb}~-)YEe_%oNVa20DuJ5v=C-Gc|sCyjzeN*1SE$H55L^f)Z9v6{f1>~as%E#?3 z3G7~smpnq&NR`((L{922pLUT%_XM@0SMgt}E?zqB@LwY2?IzuA+gz0DMR%XMNf820jA(&b}`bmlTwmPOD)Me*nj;{i|OGB4ZbKKZy<3I zrRIlepAex`N`1Izj^F!&k=%vYPc0y3+b;PH#1e@Bk*}TO!$nKPADz?~9GBS1(1632 zMRBn?AkTAT23&EDIm9h3y}|ij1~xq8x42L0*Lol?`@l)e2pJQPGyo1^y@9~}DXV!- z<*HJC>7?0^JW}DT3wX8WXRux?fc0)* zqZ0L;(L1Z6Vwu8bJd+ug2|lcttb&z$peagn*9(W8pdCu_xYJ|I7P`#2V6kcL9gcE( zBp&k8o&{NA;w zs*^bLN=tipLWXu2Kid?+VJ@jPWrl-~u&?jP${1Q(Cs8v9z!sEYkRTX9gX)2em;d+! zBDLbv;eR-HX$1&$t*E4_Ujt{tal`G4^pfLsk#*kw&nyM8aJW0s11Ph zz5TY#CBNC6Ti%>tvEi-!xLvC2PkvByYHwF2P?Vq31}D7aBMVk?lUKd7MtkV@)&2HP zv`!?oW=>nj8d$RhmUW3;?#N#`KnPnZDu687Bd>3u*4g?-$cIzK_k!!rbY#f}BybB8 zwImer-)Gjv{K`fv%zc>MX5UX(HWPL%=C6*~laK=fJ~V_^Ra@dEJ^J-IU)E!m{vrtG zRW2*;WqNPTw4=unlBXrNo&Heuni1#3way<(u+(L=T3{E)P3?)?`%uWJf-4|ZrjR??kWZMp zV-ChFgP$y(PHaQ}Z09A)`<4}!`H{o{RZCJDyrGYAFn+xyO2^PKv##Rc;9)mMaoX%J zn`z>!sb(lYr-I_#e=BkW(1!v{vzfFp@H#B8dCoN?-C$ z2~_Y^iSGT1I^>?G+t7R8ns0c5;#=hKlWxVqM<*6YxW43RyZv#~O((|6a%O+Sym% zfwWH@DsM)F^2Qa-2SVyn#p9)Uqxqf#6P;Q>=w6HjWHD#|A2;FeNF^-*!`AeB3`%aj z-~>Mye(bpkkeM8vi;++!yF&mdEinSUtqnpy$WKyt+S@hdns@sC%_3e%V?UJ(NJ8*! ze`FswxoUm~`{7Iz7<97Y>VVzp5Lt;HQI?&TbiNq-H7F)qp4A3DML$tHtO@W<#yv*B zo0UK|4^BNv!B8zW#ix0d_|aq4;!_oG%e`G5XwhwwFPgXx%^%%R+ ziF1YRcN6=Z_IXaXht*-%ttui69nW&DJH91<4JtD|*&xSF3OMW*->{JhN1dEGp4~La zx!o+}tFk;N_+JHZ4ww}H73e*d7Ze(Ba!|LK*@VMd%0lNu(1o5WqWC>1OMgy-#`xKq zBAy*}P?n$oeQIH`=-&a$|8a&SeMsKV8n6I4%WO87R11tf({hZB7lo}KN@e zSj}%XxkrIs91UiY8km@rq4Z>iKMe-a9%E|_1JIBmfcq@TK1@V!;JiIhXJo$I)L`PS zFr{WO{FF}7Kz+Uubut(!W~XjUW%)1Ww<>!NNU-n;y`pfyoaQ>B$%p4nZok*ynjeY7 zpP}s0g{#tij>9zPw9SE_B7W=10~H6d%=kBYgCjQ;WcLl0ms8TU;Dgn6lZuQq9t9Qm zDM6y0gf`wTFyzM_V(p)0+-0GJNR^v&aPWPRSEICMWat%w4*;T|3b4}(zMq%+Z`kw< zfK9SI$*&2(_Iv3O3L14`D7PgcbusYD)md@vvMdN}$FySY?6iiy2aGyd4nV~7b@=0i z^-MPt$nXd$wp#afiql#){PxrJ!In~hC>wJo(=c^}bWB6*F0a3)esTibB2@o<%k$?) z^AdnOc6by6nXm*8U=V;JAZ9MtGxa&d)@=mqgR%DJsy8fxsU{F6e)g3r!1fA9iL;4U z9>AtUyOZxXMCQ<|{)iWtn?*oOWd~N!5tBV3pi&JQQ{tp>*0PIeV?1g89??zh#fGkOOK9<0>x=5U?4DjK8 za*1Ch(4J&(&f~XvaIwYT{;BkZKn_}f;`vBXm4FI+fhdVXS~|{JSk;Tr{mJ+V=&$52 zUug-OC7t&Njk<+Fgq8`xqN1^S6u7}5p~aM1U^V}i_x|*o4nw7q=H@4qiqEbRcHcO# zq~!kjez015LqnOAlhHmaO7S}xMc?(SJc8|KjO^?wc1yK7iL@5K5_~3|fh8XOtYKvI zdVQR6Qg^&?sL;G=sp+L)TGIROwjxW#HtmFdG+9pa>ht+(0%3ipD4@;ODK_fq>8a2u z7JaF)xzu%_{V=o}UKD~Yv zt)Pwf1z3?jKD$1L9SPz0MMV+kJGU;glzV>jtJw+Gcijl4mZ~Z>teZ?f^{kp}zYMVM zdp_U!j!1*o)KPwI zV-SH|OJjhL&#DjXHEP(_ULUL3qtf#}Cs{7zTR8Q)M!zC%sa&i45TN>w;J zD*xeM4IdesH1IqV{Be^O!O*N<>stfbJyHVpqb-SYvzZDQzd|+cUtz3YByPfvb1gL} zUOc+^dm;swT~NrhH!80 zrvCBxy18seIHV5G;pE9q1!bn_V~8a6*T|8bIa?C&s&}J9bahmu-v2|{Z{nJ& ztN2-4Hcvh(l{#*1&Z#K)K+gA*&u3kw?2{h)p;G(0gUJ@v()!qQs)Cf;*MyHelm4Qs zi_6J3dOia?>L1^5tI#Dm>$cBdzg~m6n4S>P?%*IMRs932Q|{xcx`S^!XUezFGrGM`pUR+#y>Flg9 zx)w=5&1a7mA&6a;*dxYtUsflX6cr$$gpo!*;!%m*!}_U34JBgjvLEDA3x@vw=>TYM zs|9eC8GTJtB0-_gG^GP$r%*Pb#h@||uTf2p(MQupSoCN`8vUX}?YD0#wQr5D%ILVt zxDuLC9ugr-#rBh_I)P7b9^}5JQUB;*DfeCDOPH+OEa3)*^WDX_0u;V4X%bG5XcGV# z0Gr8UFB8s>uRshe?wK9`$KT8Q0@3O{;GxNZg7v@b%V*&G|1I=?W%_&T5HO`CS9NX@ z#;>Jq$dps-`|_ZMHhar)`WhNG3*0&`8tP_ab*2=|-d0M?4{uN1QmA$X^LP?te{Y_W z&d{7K{%GNW^1CPE=x~DrPR7-GVx^me-zpVVLRa><*kNXdZa!h`Gt$#~X!kE$K+cue zh|PN)ROqc8M5LDVlRxb9d!DeG=jp$#u%@OoNbAa0aR9ta*+WB_SX-k+c=xwOi*_MO z7VLNc3(*VTcyk>{Qqb2h-66<2aC2vnaJ`72{gidGfvD46k?_%hY>jG%ibi=lbosG(!r6s72r{`%P4)5C%(`Qf6tNl9FFbs(;$ ze7gBQ&PFClB}vnUSv20zzhyFU#Km`$!B1x?^vY#@q$`9$72;NXxwWf=o8za6=x)5WpU+MkPeMzr8gA|t|FQUo3a_uU8XigISz z_l^DKB9YqxULKoX;fLtk-5+;qy88eN;YQ0*N_OrTSKFp zb<62|8>z0VDStAOYqAqKM$th;Rh9{pAW!=mN0UTzY-yD;RQq@r^DJ2VtdOx5;PdhPK9-KJN7s)BrK%V+#}h&U*hCH6|fX4hI}_%?V&_Z_K4 z?aEbTG6JwZACaHOf@-tcB6!A34GPXtj~HU&}|gRciRPUh*NLn;=|AjTHztwa2jJd$ps#ML#I?)}G+(ZXEG49&rubnXLfZa<;o*E{6U@o1@geVuFY z;pDO`m1&78#&>eRV!$NeGe}F%x1951PU0+=jS;6oAboWz8DL z5IpF^r<`e~sNk9r``DxCNFSs{o=B&Bu#sfp)37)=AH$F~_={FCAN=RMPh(hk-`oD_ zvk$XTmU_(tJ%ad>;+vvqMVWMlx_Ycy=|&xFV2|R}cd*2We_klhh)wG5?=aJ|=d(kh zN*kE*<)olw^QfLf{6|64wb$vK$ZvFtd((TF&m)Qwc@JQlH*|`1<8Wp+F+RXC(6i5u zULHJ0ucr&p-~TMR2OZ{ts&6Ut*JMZW3xdFFUj$t@-iZn*LCuq!a`*ce9^vhZx5Wi_ zP9x`RIC#|G{-gK+6s~Ue^XnsA`$5Oy%$H%F;#KZ)>_QCiLE(U8@rre_P~qqq4s7qw zm9Zpsu!;PZe(LzS?;YgV-qA1XozL6ke#v_Ds%y8-H6=5~rbBZzIU7DzDpas;?cV0I z=|S7{B3@@xlSix)kbf=lQa z4-4iAl|Z-+kJBV9v8>#s922RlfuXx8d;9S8rpz5O*|Va1i#Ksl7S3&T_b0=cr@yNds*^_f3zah4-jtKIfmYP??-0}> z7MK}Y`#tkdqQ8v%n_O2h0s&mR{_r;97%j8cnCTh(7qWZdZvVyFawhK4@kplZY5|1t9w=%2_D@f;{faO5>=Q)BITGtBCdgS%nBzIlE zNOBnl;~(Hqoqjtq!&igd>ng%B7zSKz=aR81EU{JrA^)BZYw*^rV5bLo= zAK&&aWYP@3`7iPd4iZe z*c!A6dYPM1T_;6Lk`Q?Vid&i8Vo5zWkz$gt%8SG{033S)b-*%uzn{#mJ;YPK)03>;n^1)={!0l&vgdNs+QtifkjiF}YX%09cb*Yyw;AuA zei3ecQ|@_S$TP;Y8~fR%4p+*CzA}wtH|TxLqr;R8nz&xdGIZwp^)$S{{5C|DV6E(>wT4b1=aM`wY2De^)213 zt)1PUfIZj)Yi=+wFe=;Kf9Ua0M_a)X>?C1f1%7NT;qBzISA{{zTY-M*WbI+W@9pI1 z?5^MqJolr70{wdLvE(`aA4NPIfaf0S+~HRTyIJ$gNnDb+bWZsQKR>^co0W~iz3Uo( zRj1zp&pq+*a8Zzygg_t?5NQdpo2}$!d3kxsOHz_jQsVRy;_g1q9v0r>&h7$#Hu85n z*R9!P?q5AQyZ<#U`UEBS-bh}SxFq=> zRr9d3`G2Xl_vX)PKj!skcS?JWDcrI1wsthSZs$a&Dt&0mGBTHyesuG1Z~isVKWjd4 zw{}wpJJBn8DF2Hse^vhZ6#j|gf3ow(Q#wDDk0?q0vo@5Eh}8mH85mR_n;eDov(W!SIBAX5F6`y`*CUXB~x!j^)_nR29 zN-YVOG>ubq$NLl8k;Dgh60LTrEneEzMwyHwP&?$^ZDNl`J%7%?c!>Y$&%a*WOTC$< zB&K_0-~JP-3_t(+%n+yu*#G;}BSj2>(6a&VS7m>Hb7*Ai=&x-b;=l8X`OpZXZ@!sFx@VgMCf1CPK)wAsUE|TBC$FpDl-fy5H{P(Hv|6h{-&qyvJ6G%yr zoj)%iAkYo5TC7?xwnq2goFBO>rcVi1NfrXvP}3ZTO6@dJ+W9QMP z@f;G-_cCwYS~L#6$*T`8nc!||5$20ZSAfKPm8@QS=`oMPfR-LCnxOrG;2|T4Boc$sykJTq8)#egPT#R#!O_-`71XOihMDy6L>_dVd;~TIY#MKvlazs%i3}`sxUiC z!rag2FF|zrKJkjErz{AT+4DWd2JLc6Z5JxW zKsI>z9k8Eckx-9P0YIcdtH!SyC$RKTM%nOI4doy*6?N?ebuvfT_g4B#O(D}6a~M_p z%BXK`^%b8tZOO+eYT(Cg^~#{=$4*t=)F$HVY(qaGC%S)&j! zf%WC8zT-0PMUqWXG+YAqu~K5V&*zjU3LlM3)bkEa)geIN?K7etPZ9u9H+%h z9<;^OeUby?&cXe6L)+pJci6>^ZIlg>xBD&}Y!(&f<-U4NpzxH`&s=*H%-+ec^R6kS z4C_7LzLW#7t&yOwj3jk~19@|}915BldXAe14E{S1h;bF%0 zWS-ieCt2NcU~p(2H=oaKxgmb{LxmX)JA%&-59mo*x0+p`C7<7pie0P!Y@SK*XPP2O z*64iHAQsgwM3!V`%j-F19J-|d7-I_pMFdk+1h~8#v)K}4Bb9;Rax$5MXqPFO!n=_C zcP}aeo~jVj$thO?p$}TLjPmZ-j*;g$l{56Njp3#?4lY_fLqKNvqgg+RI7t%igEr!# zE{lol%IosY4a?e1ypX#v;x^2*Bt2fB4u*Jp%}|Ry=M5mr;A%OMOD@>#QzNvo9x3qd zIoKI5A0mnzfn1sqQTTH9@XuP&%X#0i8dTjV^cV|{ss^>V%Mx}`Kv{9|!AAEw7PKIq zwKg;vx9$9)6cDf}YXKiJit3+r*~$(My*0q+`4Z=j-~Nzj+6l_i7NxwZJh1LCtij}e zV7t(^skz)a=)+v5$m3N25N_U_dnHPsD(%9JS^{DyCm=nBeE^5Oa#a1nEQb)~j++crxLrC>7 z^CBg7ShGWkx<4nt#oA;Vqe6@6Fr&2IPRF@X3V)GG#q6gWaSnROSQ&3tt^)u->AW)Y z=&&=!2yieKKbxPzB-IM=Fx8k+*KNB5%#l|%%{JK{pw7!&RkSddrubtrhN|m`RIzxZiyw+EL}>66N%lqmUI$f z7K_ar9&;)#5HRO~-(4?^a*BW1RNgUAYUkeO15yh=r(}V{X+x1W~mi^(iJ`V=4%(ap&AF-RJ zNb0hH9;TE0;#ZS1?k+~6qjU2v7WLjS(J(6&)YCn&n>cITcR$ljuxp$suhZ8CL?^7J z*b^_if_Sab?_<=$@lMbbS@4W>dZuo@`{ZiwQUpPx#@RNL+&aDf0C0uej!+r0&qr-v zgQ_60J)h%|(c%J30HppLk55IZJWXaW^X5XCJ($WOX|3CdU5^pVB>E#>Z46L)1UcY> z;bfvk33~#x9PjN=408{ZoEM<-Rn>-+DiC_(+`Gm}>Idz_-$ONSIo$5-wl1Vxa0!N)Qs4>gpIOzfKU?{|BUYja>s9(Bh*1{piuwl%6u9yP%l zD&D3l3QU$SQ5U|sb3K}maH4i)kaZAB>sKo`ztUdl?%1%{kT7_M{x`>8VArs7Wr3NV z-6#l-hpS?-OE{&Zeq!C%xq3IUPAVZsy=FZj%b$u;B7fa{&M)uLB;(kbHe=zwe@0-6 zZrVH<)nWDfIykc*lHhUfixn2X@tyWsSK}ilhV>R~XC)SW917s#dtjoRw3Z~+#Q2Ma zoXQANT^gNVLisA>XoCpRI#>r|-;wqcPoO}-wr@_AS_vE7?7c{YEx!sxUod zZIVQ8yAPppV}^q6l_7tF&c17UX$w`UHjFX+l{3uWp*Udl*FQ?E~jsAKjATZ*S( z&8DR0{E-YF5@L~{qs(p)u6!?VIL~khkUX{!6khWlBIIxLtTCq?L0NnaK(ED@Oyw2n zX}vf?dGUZPp#T#@^lhs5dbuu*sWb@t=>L&ds-Wbw+(+}<)mjtZ#X9Recb^H$LG$C8 z&1~Q6#ZHaK|XI4iRbW(Ku& zQVKn8uD7}^4GNH!Kd^!V{NWe`H0#%dqvYmR?tgkM zn(pZ|RBg1hDBX;+&6A#<$5`6@QQh$-AL9y!cE!7WKdjlbK&E^ZbdIAcP7kipO&8;0 zj~7o0jsLjkJT1~m+F%72+_$4SN@m`BF+gZ;A}%)vA>wUoV^2!Q!~Ip1cdb6ngbO9x z(b{?v(Pv`I-f;SyG(R~1v%6R5e&idzXGzq%ei}8t1`1HC%@TAeaAt()47pc34&D+q zSGEO?ZXdd=le5-4^lTsP$qAL26==rIcjs1zDzv1g(6g%~Ns`-{fik)sodoS~`G6u5 zwYTqQ`ICZnsAS_V&F*;4!NqW871N;Gz?7`VHk*jpIc%=z6j^UH)vCn|Wri5WQa8}m z4XTo=dBwMLOGMKJxIH4P!?333C)!aYfZtB^Ox~ewz8R4h1aogQ5GS>KZOJF9)B)<{ z6>O>av-m8WXIxQ3UNK7MD1{ch5cS5h>r781PS)a0g-v?Kr*pFQj3NDOe{cxE>q+!| z2#YwjV=c~MEPu9X(B17!#eB^W1;6ouHV7cyWZ0U*Zb|vJU1z%##*yqpjqYMwxU?-M zp{N&fTd>FF&WG!+il(N*aOBclh~sX@YIp~0YE*Zg5faokF;t9NcoFiL_>Og04SwIH zCp2~lz?(wbvxf!=O)VyD%BB6I#DM#yY1e}>Q9nDqj|l9Cjto)vRqf4S*NIs)Hl}4Z zOqvXU2KMySYYb9G^-(i8fA}fV0tAY23l@`nHK@Z>m*|Yb@4n@wf!fON8@%}j%omUL zf7Uv)?CO+Mkqgy~-&r~Yft6uZQz=g{$Sbaia(^tm&GGGbp|t=4&JGQ{yXYS&`_8Ob zYGv5tR6X5LXx3+fwx+Y6hdb=rK@j|-0?0%oEQ4;iEnasW+&6Q_2U~J2FWG1W1 zcB^i6jM>w9AV$f^3|F4?etqNhYS~ndj+5t*OB&JX;kNyp_LgHS!XnYS{v~XIx%0BFk3m%bhNS%wGBGOrof6>ykIUUJ;nOdT^Li_h%MMzXl&@_ObApQ8y` zD`4Fi11IOB{%>OsH2VX%&hh3W(J}aT?Q8vuF=C6wG(hsvrGfPM!OxjOHv`sIPL@M( z=8d(VF`igLki#dN6ww0dPQv+PJUh>l0yg^G91sVsdvn>CAbn|LwKhP+?knS>`jYkf zyL3BG@%`=wUwB2!+;_3=RBGhL=;ZsJf(Ud$>wS3pJ$h2|%^p)`u}B@&};Ks_vy)b8gwI-MU8*kEh^rPXN|S zhp~kBlIAtH{z3DpkSN2J`rQvk1(Fy!Y8ZJb=ZQNLR!5+>*(j zf_5qa8J{-r7|>qctNk*Y48#u;w0gdN2=sqB6EVk;;xEz^HTgjKW26t?POeuRnZvw2 z0_Y_v23;shMB)AECYIcZMT?~zP{jHG!bA}f%M}b*=op52ZP~(M0$eV-GC*Q9>t_*Y zf!?5Xhm!4d2$Kgi3dfEOFsf@5!!XT z;qljXnIOq+L~hcq_U`iSS(Qi6kNVCDQux*@7LB(=9AY*@hLS9%4-Lq%p>)@>fg1{6 zAAj0v`v}LW7rey#(@NfQQu1YcyLh*~t3VK(2z0S5m?mSS@e{NWn0#}rj!8=Kgsg_0 z`|j)@s8V^!1U8feGrl!dl6NVb+3T`;Q54=Wsfpc1j{`Y_yJcxL zSg(pZOO+&FSd3YJ*M5cT6R*_-EMIOobmmBZfNFsyD`>b5HzTBb_2)S3o_m^OYbwgZ zAs*5KUtK{T{sO&VEj#AqYBQY?SRcIhuE&@MpbuV8$R5gOH0`S?8?m*qXT81c=XBWPBokFJKU0`!)Zy>9~fPGc2Mxxfb7i9YR}!u<3nXQ z147b;bdcZu1UdOuUX9=;XimqwU^I&W-;tw3W!goLZ!CV^w$uck^_=f5lx}yZ;V5-r z@NLy~=ve-@TTB!3q~TNhQDsj6ryfWN3sZ!qzm z)4TT5n%=kHYk%OilNH265vJ;Mj6>2(qeMV?EbZ#m)(KrT=LCLn#%j$T8dA?0_|?x0WC*0_E(>wQ z+}^PtBClq|%Lep)>RYWfz_vDXG=<8mnOl=J{^3cED`prkH{Y(N{^}Uw!*u0pk;@{8ID~NV7=Jq2FmWLyxvO|8}rvI|cqPiT*Yr z|92JrquBpH2-=$)=GNY!4p^s%b?)7FFxu#O6NK|I$!7My$@_QXJCoQcHa&Jg})SkU}uiE?apmnU7pWwH=VLxE{K>KCu z7mJ(ATd%0Po7nDU>ceV}7xzCs?11$;q3y0J*8<92g)fd{h?)T^LVn_=8vFcJ*d<%G zlZ{lHBxmLcn?{V)w4H!yatXyVqOcI?r_!cnJD}QI-T0!js>ZIzrbi3a<#mUMz@*&! zaDC-Dy6v_`4Qn(u)qi&N!M$>A(Lq}xQ0Mmb!yFm&uN_jCm{)KP-72k%x`U=}#gfbv zVOr*ER%Jg}B<Nn)U(bKgH6{9Uh#Fn|4SAZc!njyp@@V%3aZ zm36@mPTW3?_tLK^SM|<2vBaniM#d6QRZbUwwrBP{&pWU7(<{Sj8o&Hq^YSk8^vY-h z+*1-d&;k`dZ86-U`TKPF_j=r`bXS=XXwF35uWf!5Uf6E6X(IBhJSzBSmv(OlQ9DAX zj>Xp9BnM+Ah*RJ);@S-JCTXPH(RaFp56%%lT>v;+c13|3Ip7(LezlRS%T%q7AXa59 z=1pqk`(UD;8=v2@)`dD^Y=#n@pQMKXylrzso-6XjRMQ!BpZ$+kUx8mN6Dpks*V;%) zWJjFCP9)QKke<{&Wk8FEcbEj6m42~*)9-xGIQiheZbW%%Rs4wWLQEz)6fUadKg>7i z;i?EOSG6hwJ$J_RWfrmhzF~I#H5ndYULf=d%XNeK8#5as`R^5eXKHi0>cbJP7VtDQ&7r~j zGrF{AgIyOt!H#%2rRlm;dSGd=-5?Gwe){gCy9a+AY+c7+#nPg2b)#3<%sX2Mwk$U~ zSDJqdv#Rn7Gg`PhJPgpCJ1&;kUuR~*|J~&5j*oL9k<%woxMM?=J@$2Y`XSRg;fMz7 z?-L@79LtBTT;n&dzNusOV>B`qQVu)kvJd_r6uZn;;uPiTI$wSfc{&DQc+oKT&*{~i z`3fhLTlYv~+($}$3RZ3(f6l7>Cxb+JFn4vlURJ~CjH7M(EpOcvsv`)*AFox}yIJ-> zU^>E;ed?da)J^z{jU}%k2y@*7zXXZ)Hqad3*LlRkcNnEalzqdJe*AYO`+@yXh)Mlw`qcpXN~LN0sR_gB z{8DQYVEtW`llJt8#g=@I;%7%+CJ277?EC*l*`Fn##&(i9~TP7SZU42sLv({Trz>k65G7SsnRNzF5Fz0?R%TV z7FIsIm*rrKsOpfQ5#LU`(P7F;|9fVyK7`#5zadXw8vOSAXn1usPhwG%v)bU~4}<&p zp(i6;r>ix2G25(g`jBS6dt~{z6OfCq!>gJ`VQKZ6)k4`Ren~u|75OTO*85Kk9A{SW znwx#L;f_(h5%$U4#D*rL*@#lsl5^bAR2c0x$7-Qs5Fws6<2KVGQ;0&3o(Rae%m(!RO*y0R_{+#wnOX$9PDAP4muH$bxc{to$u|o&c9+r|Zs=d)s#4 zll=;yVS`(-7dRgduAYH47mgPUInfj+t`C;lMO7>B`sbJ+UM4}DSylq@vqU{A=la}! zeVdYzu0<|n_^t#GZQ5!$qN+>g1E1HE2l5l8Y#FAN{v#`UA=F)`49+X2kk@`YvodsK zFQ+?yQGSVBEY`Lc%(`=v*=v&zLg68QwpdXkss)tanOR|%1WBNLS>Fc(D#T}&<%qH7 z1aw0z?wpw6E~ox99b0mGno8T(Ei;SKv+kzA(P_c=-_bLIq6p@H*pk-a2;qS9W(wwK zIY8Y;yA*I#JIs1*c(vs4`6`@mv>5q28hn$C+(vqu{jvPbeOd)%dz%PKwp=w*V+g#s zujddUa|%t1=$i&XoJ4v&MrApM0bt6*9wwFVTSd4}PTD;O%G8hNJJM9OrzrW>k$q{y z{rP5+!pYv++GEO%GJot?)sVJ>b2%zhdchx^9=@`xma(PB%KEH&L&7WPU4(zkJ3=Gy zL9PKh!Xka)WC(|t4LAQfF;3iOGV;I@j;Of!%6qbCTne&uEyrL{mAe8HPePiGu1IXr zLvL}?dyw&JvpNDTDlA*Hg{LitC~CxaXI@7*DAd>qFhaz>s2t)i1RnZE6DK6Q@2z=% zo+Ox%GV%LP!PekJzyk_tF-;>pe#Y3B+O!da99@Z^2lH_btd-=H#K|udWNQsQDS&C2 zPpCNz7B$^ravqGL22z9ez@H)eEWee!V?*3Lp3h6KPF)o>mWkT3BLUQ%Q2iOe6$p+L zXVyPX;ra*-Wu%A7CBfC}fuoJ|@thF5Q}lhed+g(ooPKZ<0P4qGx%3h`xy515u^39u zrYC$|%qr3j?!^zH(r1C6>_ReE{W1B+X)BT9lG33^6}VJk!7}pYHA+`@&dvr5m)*;_ zd6IjK)!)XWcyw?tx9|G7OI9;tQZCCZmsQMRB=u{fdWmig?Gf8C;$c_PgDx~V!Y{2@ z8Wlb&;(?i}%V)U)2kjXt9cDy`8YM^g$~&=PM9e9{H$O6{62T~ZnChFHZ=aP`CU53E zOiQ9tY*k1I_B{nN0HWKLdz){*Sf2XSL=XtYAc^62ek5t2*c-XlW{Y(Pl$r@=Y}*fM zcg5g_tH@E?Y!1xZ>s838opl1fxHi5`H@Lt)VSNHzu4!gl1S+S}WvZp{H)VIovRdVOq&BO#64_lZZOAmPA%Dr<5_K;G0^ zIAqZd?7pJ2I@KG$;jN}V?=-bFHetrP&b`mCgtpt@_vpJp_t=%q*P!n8je}F^dRcFD zd9I8nhc9AAfd`xExpQLV^{PRf@4eBr&*nI1bDzz378~asctAP|rL}ctaB2u(5;8}OWv0gO%LHElbRs^l8%A-cAMD2d9icwC|7Habg5~G##)M9;ziPm9) z8R)uZYzpJR$RKv?>|ujG-K6}s+811Wo*6TERfTsm?gC9(Sd;Qlh2COuU8f672S=P} z2fEi6aj|%no!xPAIQ7E8-4X#m6+ez?sty5N9FhPx{{p336vT5o9CK5%(N$Ac0AG{N zs^>JeLRiuFhJ`!i9?Tqnt^w6L_+w%V16w4nBvTwi)ZOkqK4o0-BnO2b7271jXbn5} zx@oC)o%uOldFs`V@73;>zYMI>>@N&NI+v;w+Ffg9OU!NaX~K&`kTUc(=5f!Z)L8_c zeE?erW9(4O;u*HQddgr~i~n`Yz;VB|0IkKM{v`5J7*-Y4;aMMw!<&Cm0uejzbP&91nagw-{+==%%`oQmHdlx z?4l0fKJY-bf!y!siPP}1w*>*>9(NO^5zLDT^i-IV$EW@^gF4}t0v62h{gH7;F`C@` z+T9g>fF7G^n`tQeZf%yV3#(ILvwh&46pql)uf7WvbG%yVj8wW5DSI^}kbQNvYsi_x$Gqu4u$~0^|LEKDL4@pSA^FY}=u4Gz5&^@;_;h*C8Dy;2aNgTv zyVwH!qiIGXf;G|*9B?Z3%igwCn0#nI^P=zE7AGcaoezRd=cB!}Dtq+YIb0GR?8*Dp zbK&y3)3IG!Rfm@wrBF3wIU|fZ^>E93HN@>xr5>;~<4Z*ce?dz0^No{`govmeVI^Jkv zLZ1%n4*5vi1OP!AD49CljBNKuGr&~6;{lgzuI@$e>%7jUx(9mO&0+CAAvX7LJ|EPO zSpp>~ljCy5doGt_)1NNV=~%kWNOzD<84LgERcp9fSa^zLbvS>@t6Q;~Ep}ovnYFq| zSwLmaOlUWvQU;j-=E{=u+lNGS6sirOht`MIFJFi?>(bG6_NjcL$4}?dDQ1sXS+Uz| zypFyF_%gL(96|Zfm^)4==dOTz*pXz@7K-2}MCuISor0sZFrHkfu=eO+!d>}iM#`*vGPrsRM0pqqu1ywf zAX!vwJDKH|t6P<2FWz$xM{cm^%b|zvq|Sa4>mb9W(1-XV1XHE!5puwJ%f=c@rVW#- z4V}U+Eqnq`)Zo?f`Fz0zOYZgETgjV6Hpx9xnFPvh-5R2W=gh(~A%UX09)4ekdQiy$ zw#Mh@bhT3xk;Q;J$M$T2FZ;>8hxzV|e@BKFL<9rjMmzD8mHe98h5 z{~Dv~;}7@Wh^#?@Wus`yjznvf+`cj!jqS%v?<%$x73aD_MBzNl^uS4=--*r&Iiaj} zg_j(}>H4#RdB7#F^3L;yCp}iQ-Vp4fc8mOd(KeSo@8_6m@%d*2KY5g@ZdSWvpC#io z)Ts=Y$$GS3%ojjW1RsxLO9VIp5Ff|{cG=Ja+nZODE!MxXbi5i9xgS^;Cc3N&H(C7L z5PiW3`ZWlY6Bao;GV8`EQy2?9nm(;ERDh)B+cD(N63nM>>DCg}JfE1wmMdbFv(4uF z`Gk{~otwvS_nh%4&yw2;+Pj$qz&kkt{Opw2f^CrhG5QLOR6wGXgHrZb>sY|J4MD5> zBZo{FLK5&V6!gM(amejYazeF<+*_q65P%R$FShx^mG-06RGQ%$?x)CJ0XgR$!h>;$hNZf(ZaJLq6y9>DTrimh*jkb?sP_#QwvV=o#>Z2Q?00|s}L_&fz7 z4EOnO2L>Qm)Q28vprAO?r)T=PoBUQya9@!%+FRr>49-`PqHA+4@`^%w*>_Fp8WaYVmds5HcmnvnA8p1+e@fcP({7?%kiwm`3ocM?kvGBrAdltR#M;`Z$|Nd5p#`Dt~!;!;kTf zpV8*#B}Vp@!>TLR;}i9V9)1&MXo!6g&MNTeB%I;2IlHp*+kY>}#uijn(WjXaVzK4g z;8wQh`F^(kiX;O)p!pJ^$#ly7f=0YD_zRDkp?iWqFcz0<2u;__-az_V_!&l2<@*z3 zQR3@ZqN6N7RO8t;st72B%+>JXcT9?|dszNN19?>P0+Hpa=S#2sg>8QS`jP3EA<%jG z@o)Tw?iG(BV}T3bNF^`MEyPX!mWa+D@##;r%^ua#nt8w@g!1NjwlUH>ZQ*IotU%@!mj4nwVf-Zd5V{FzmIoQu$;W6iP` zRl2XyKu_FM(yL;?y(E}t9ZYyK{^;(9ueWpjUV zg|;8hjWI^$z>5-W0L_yXPxbgi(BGQw?w1&2`wxoQJT7;Vl5if4v5x(^I`L-8UiQZ# z{D!#p7a&a^wH#44pe1nmi*P&xJyf7@8FT5_#aHJ4X|sF1!{cfLO-JUQN^$(t@;~^n zsTr5z?~&CLd4Ey1>u<<;jBXZvzm@ZELZI{~rL;Rf-x|Dj@_?%Huj+t-G3U?W z=JY3iHvKnXQtAH(FqvHkpQs5r98&`2X2c`!OA+WX?OT^ye;VYTp~hcWfB1f$>Dfq! z3+!6rS{J(5)`t$PJqTv?p07&e)lJnosB}u=^|{2~6yA}0bs?50Y^wXpOZ2?Md)`4i z-U~#t>tC5ql?q2h{HFBoY|>rZp*`1@e~%$Q1!(>&CH5ynyy>z*6!={>GSv9b(k%-c zx^!f}@2^WHRA{cm{H{P%)eb*j{~S!m{!?a;jqC{-@!y3k;x8e~j{gbFH}PWqXbD{< z^8x%K57SZgEH={Hj=E=?%>O+h`nD4~^S%G-=fa(e$Cbu9^!!fo6DxTqc9js~i77tB zF4r`}w%s%tFQ&hBT@$cMs`Ny_&yRxfDt^lJAj}V47>ozp^;7oqtf-LH1^ya*p-aO5 zCBYY^Cg2;yzeRJ7+~WUiOP|vlk~Vm3De=E6RzJ}+l(7FL$~=B+b1X{xDMnK&InLJQ z0Q)z||9<@CQ#ghmB+FO*dk6UwcyDnCTsDu0&3;fdMGwF2X*)2(p0*nt_sc3s5|Caa zgja41d7%91$1&VSsmEh{r<(+Eu>V@K{;hx`KIs`O=ey>rWUbG6tbC3=IldS5Lsis; z++_$lQw99Wl68TO4Y}@@Q3YJ40K2f8YoA*XE!Fm80hNa*Eg3gAc_021aO7tWOieX| zpfTQZ^myB&&V0kTzON^%%+Pyg{62VHiHhzijwH%z5W8$4*>`*xt0epJX5h5bXw`$g z<5z;WPKV2f?;(h+B?0fKWW3>CPQTOUNW}_(9+n+8G56V{FyOPjvFz;;LV) z_SvS>jVV3x~uzTaCBxV#E`+%NE$3o4#?#i_&L z!NQMF&7L-2IL)Z&7mkDp)ucjXgi={AMATQyI`j{#+$_U-!ck=H&6Q_0$GEQyxxsdd z6oNHxqAEZpB~imI9}R`GYV;Fs9fvK++HKVyw^J~l3*PeD4)0%}`%DcB8EU%pgPD!{ z<-=LIM005%u?Y><_p|1q(e#6tl4r!0BA19LRR^h)YmLn*k^seiUl)h~ZW|L!JP8$(A>(7}3Lr8zzb@v31N zSbX~+SWU>E4YuW3vs1QBe5MpyXXy~s0Cs2J?=05bb}Z}5jrM8_BChgD1RI=vr{?=SJ<(* zsz1-Tm5%$MH?IhxWqF_9zTxxtw*ZE|_2v<`u=pK*@>+$mkU4i8&YvhvGTR=N;fjt5 zk+`aU0dT)7y36D$E@ioBh5%_BfK2sZYGTScXnJA5s+70>{*g1}<+)sm2rVK^!aPoc zNe3P$HN@a^pK2`kiab}5hkkJRn4z!a&L%<#&8o6%SUn>Sy40vj1OsjKwEKUh$FXp>Q?v6QC5xikvql!CJXjOlR1$_~TxdIk+ZSkmfXW zUMDOEOyid@DE*jtM-Owk)bz4`$9bxNDeVtzMuC{Yj;OGV!}%rvwr;wCmfi$~K3)cF z8hfpqJ4{YsvIhCS1Rej(FU*6#W8bG_Wg=^&Y)_$|vPNsdwWWcamZNN zK%42&!>g*bX{%cVd@GFR90{cyl>!EwgN$}{IpGav%LTm$-RfoF1@_mEL!=qsxYv$N$)sLUv=~?&&!kx+R z-8B!8)fdv;{#I?CYgJ3#c;~(giJbjXUCSSvAKI=v)r`r5+SSxR2Y9vSj~pFoU!Q*!+87%49;>a&3#bT} zMlIfWvv7`(;{HZ4I#vTE2pJhPFBRT-dW#Yg!@0ADF6S@1nX&Q)?W zYM~Tl>E{dDw=Oc?Xfr5C5UQR`>ElkuRV zgxEE53GZOcI%O2KwadJ-JV6?#X?&9)QO77>$O0RR_nOjLj#T+|o?zg4GcD_a&10+2~ zA{3(CV2Ni(R$#BN@~efNEOFLhoErygHa3!dI%HQ1;*;_~qg<;~hSC`j{1-P(L~dr! z`l8f)Th%TF;AfoTHz(LddF=Ud(ZN!m%J)w9Xw!;P|6=9FNR=FyS5;;>)sGcgg?KNnKO}cx4eC*G^pC6E zZR4({HkMI?>Gb0@?c^uP)mO$j=4FCCINUJ9ICGGA%`uE`d#>R3G$f{ua=~m2ihxy}qxss>0Gng20 zlaX8r=)4KS${8zlSBTBj=Do^H#oN0Dy3G$uyv*7#Ri4}EY+@{w;46;B_8hd+Nh zXu@53y3OnfY0b3#`Tg<{`bq6(SNTzMOvC<3XMEucf<{=0HKukZ>+Kma!^+1tjk9mF zgv;BnQWtWiweQTWmifJC)sYseCKaK39Qu`dEN4~?c2{g0UyDniuTHIrNwooXBxqj( z>ZOk7yS_2eEAOnljeo1|fM~mPj4OWt8kPOcbT~^VQ98^4Czq}>+`;L9%|lFSKTWoH zW?|CtR;17;g>rHo)4DlJsLWRekN03|i>7P?$WgJ@<^`3zDQ}~U%fnj~k?ZT6^oUPL z3u%sATac4fJFA1aI=#svz0K;~-sb8Z;buBK#jE~^e&SL3J8Z2M4SIvm znwKA3>Z=#qb3)TuHYbd!Q1O{2v2=Ej63>gw${nB>d>0CCitfZ zKviYhj5RFAq(8+N#ac>JM})-m+^2_a6}3Uo$};l$%lV-pzR~-wm2ccD_Kv+ZuC>N9 z7z9wA0=558`L>Y+?KAUjk)KY&$&%Z3Bk89?z$NQ^L(}bC^mBiRV}wx%9JO$9VB1@i z_i;XOMP5tcw4v~n!h9Rs;x|)VjWFE%ZT0plL(i~bs|||wg`+%nl@72E@~O68G^@%O zam?2YUanEt;Kj0h9QOEFjTOkB--^Bmq^(ZJ59%ui$Y-6&i>q8rYY^3$IxKxSWlL%Z zqdwp>y|!IHcUI-DYH&GJeUxf~vMqs<3!BKL__Y@O-S1xVANgQuqiy1X;(EZ2<4~g4 ze6&~8@j&t_s<<`|Ivf%=eBGBE3T(6?`FF{{zC14Y=nwqhwfQ75?wRQ48UJ;Kmgy2q zsE!B<5&s&eSg!1;raz%EJpFXptJB2k$OI1uZfoTY1EUYyCD_FTniuN*otCa?uT=JI znIc*q8olxSP0JqUP|Hr(+Q?Cg{#HDPWG+C<$A zHn&QMf9|-ub7Nz743n*mfV1$Xn0~n4Pu&4o;2m@e@CdOG`O}@Y#q?+yc@EZ_cz~d$ zhUClg4|NJPwg~PUUoA*HJh#?=f{L5H?~Sz;)`Z23^uMkOWHWedkX-+a9@N2-atP&v7pMhjo%TI1V_8v zutwYLDmTynM7+9+ep3Yf9PkD@O#H|8c$vfAcbGIUzl3YR=IPgOB>Bt_qUQYP6G~(4 zjb_^j&!Cir8WSV=p*3T=J0_&)djG=I4#s9E#CXN2_7iUDfNufwu5@!{l z3c!6r^-8~AS3*Yy zXRgC?GUzkUNrGBPrlV$0k$K3QV`c?sqfH)fVe5IkjMhtH1F9UTJ0S4#kTDpH&-{^8`TQi-~K&~Q|PRC+Mk z^e&j#Y1WDIjL!8a)^Dw`W9Q-F%Ow z_r*M67#H+k8~%edAaksnI@=J7kN7@aWVdUpU6%R8hxJOv+QRRk6YZ>4DV1P_Y%QV@YV)h~6o~XuYLVL4 z)M$6YAC$=5(AFkt25w1Gy{#$dQM<^c=#z4w7Z9)(z4IvL>?o}6&@6eTqBksA+Y7hyd`z%5*b6Y5~k>LEc(}GO#oM4_*@+A3Y8YF>7Li- z(vBP7*3$2%YSMC4^+lPKrt>d$v)s8-uZrB}pnVr0k5cWt*{YgGq(5?_(e9SO$Y(24l?csn_y; ze_rp;=X}54-}#;M`~K6JrswH!ZO`j^-0t`L60#J`hUZ<^7u;L&VJ11CNs!o{MQ z5z9~LtsETna+aZ#X%KJ(cb=9pDLuy*j=E#(4EUL;09%_pf&iuGt_o#7{<^6STP48xV*r?+1%C~yw?v9G6 zxSw~=-}({qqi~9o`Q(3m`A4O1t?@x^GRTn|+7*x=2vAx5at}uC=f2#Ns+kz0ZmiG!Fx?Q8WNA{)V;Zk}z|2#22z zd{v#)k1{vlC*lMr$BmYU>K6u7fFzw%uOqZbEa)N@1aohztJ(>22>k(s5V`t~NzLRC zul!s=Gvl;To9}|5B@1J)JD%&Z%ULMX;*^aAztS?7ZbP||%sEH?96K08xt0~LJfM0t zQ1EgQYS(jcX?G1ykpyt|+!Wm2YbYYTZrRUozxd9b!##ny3v(a#jFx#f9$f5K zU38T~1F8lU3Ty@MvkY4oW_)0YS~9b?7e(0;+Dnsdae)*MxCN`C9N&FNTDJ?aQwN`~ zQ7@NxHqU@&V?`LXCg(cXWwGa*;0T7HZ;D9R$D>{)%5@OcmJegw1ot_hyht8}`taTr zQmpWEt@t2f)Wf)8HDrhk?#fAXLmKh3kwAUSc4xnc}5)(Q%azd!@3MMSW zyI==vR8%_X7L*Od1+9OX6$iTy15#&bOcIe}Jfn7{jQt};cQp9Z9xF)#X6yGK4xe?3m#HV!rsi6|lAF z=I)#V(A#|>|6iK5hNJ(RM0z0N|9&F<|H>u9+j;aD40D6D_Ag{SaqNEw8UGEe4FwQ@ z2gx#|E$qLiYiZMI?XXCY$N9hdi@h^smec^aVtym)-Mxu_{UvOg5>8b1aCaVk9R8O- z>bD|bzx}Igq`m*EWgIXhnEgR^-(~=MfWJfr{EZ*=|K4Z(HK_eg{T3OJd~c#*#aBh{ z88_E5YR7`@{$8y9dhp1l6F(_m>i}nQ2xpJq+zjO7sswE0znxVYleE@xzwPPAmQf{~ zih$^aCbj0rJr~SY<4gCB`&W(kj}_qR-9LX;D8Qiq0BbbBN;C57pN^*VeUI9{__*WW z3BN2(YMnvi{qkS1>VKgY_-`Kj4jnBw`sSRtYUQU3o50$d+sO)Yua0PPRlWRQO9cMz z?>_|!q-%bFc;v~SHnw5d=%LOV`Han*Rm`U^a{g=4`~4~8#a{}K5unihN$mJzv74Vp zGOG0dDV>q5!jvp;No?SWCO0vqRy8fS!JN?52Vw&neS?N)L*lf9il7vi?mp(*$LR#Z>-(2R;8okR$y6 zyC7#K;(5?b`?eG@gwD3{-X5$_xd}txi+9t$U4KpqAu?9Ah6u<@bo%#^Zw=%AL)}v~ z{`8UIdndjSvHcDm-F6M{B9O02cz2BAvYM3--O?lekLXX2@+vCT|6T@@R?BRBTJnlU zj;9h^*NBBjM1YJ}wwUTf%*sHi`+hoCx7X~@r$B?eoaJVam5E@CCdG+B@&Hm(C^&+&1C<4SHHe>{yI{IYv0n;xjzNDKQvo>SpduV z)Q>>dE2w(cC0d;a3b@&R@W?3XvwtyE`IPtmvQN1mudHj?tT-e-_+W_@>1d9H2p_82 zbU&BnTlHbv{VdKQ7)tqtEZ5sw0PIw#!-!ULzqiqIPT7)0kpfy=pP8bs7wiMO8@Bg< z9jb$P-4QV!1p(<;m%|NFQ|qQzYZ-Xb;R&>~dFKHCftitKRx)mw(ZlP9SJ&?UTfXUx zq1yC7LV|4mi!alU>3+ZtvY{YXqOQ2K+){Yp?WX36=JV%tOC z@(jZ2R+pXAl5`d}AmcS&`7YzNjX{WAEfA19w|kwyJrqn2oGsGGA3kx1`KUmvn&R1gvDsg@1o6Q z^0gxjqM$iQO;FN>P2i-NRRBbS={k4!@uTTBf-^v}FA&$7_iI0GMP0AXMeCA7^i&pR zZ^u0C%*N*wfGgy>`^qF2Hh%$CW&=^Ly8BVE(yt3*!dHk-D}lkuk+?qV`55h; zdd_0`e05cOVnxAe(;CmLV|;sgyY*etN~a{mDde-4jPecNdxJaKmBS5}n(9@4or8ob zcdkJaJKN<{e~!b5!rW=WH9)y2U0H7LjplhFbu|68RXXCDFR08n(X*QNqJH#4?y_8R1wbar^&?b zuik`_y}Q_7c*4_3zJvNTKqy>^ly?las6wT+yE88R{Tg0+#=zJ;oi^}mLHg@ENb0^p zdfy%z#MDz{39IQ)rZbV4cQw`t5YlX{Ue23w=s3AVe7&WKA5$-K+3EMoGw_}a^(o=KHe5AYrB0UXlDdun8pDDL}7XX{g0qBr1NZtS_kI{v|L zm2-gn(#t?LR~#ZZ5dshFaa=CUK!1@A2pTJXak_#utp}16noT38w_+!h9USUR$j{%- z+J18E^RxSLMnaU_zg4$3z)U75@q{yvDk4~Mnru-;Y>&|^X5W+rH^x=;0Qkl69*z?b zhScqSP-X^KDdYu-37fbQ2chez+10J#=&Z_9;PEo~(ztUgMAb4&JNmw>B;e^^W|@Dp zn*7_B&9umDadFp3b(T)JXk30j*s`#CSlM3DPk9kIf~}WbsZ7!74A4bPBQ>n?3l|T5)_9Cd+bRaEcCG*+NykjqR8)BOcyt0D z04ubCp5sLTyu|_;T^E4Bt1iX&yEkD`N`sID3m{ajdai>2u1|xY$(6s>x$-Tl6BrSl z3B|~(SGQ2CDmPZv~%SOM>5lE#v5yqpY%&L?TXg+BmZtm zRa>CO56zCl6dKP>Y4=L0LWc<@Ktkk5y6K@AW`VPIuq^GkVI$3B1kqut+)UylZ+W}9 zDz4=*e(Da)uB3*#JmXcf?Za7%=wGaDiJMpG^T^7BUL6wv6YWt><9f=$;A`EV)@xF(&Hm8U*({ZOI!MzW z-N1M5IU-X${9z+!_RBqq;cIolA64pcy5+Rfk^$9qU5o{ z1KK7aEAcV`o#J%pLzx&1Cns(;Cw#)ME$B-m^Qg`$|0Sob*-7md@ zO<6>=`2VW$JXfpwqgY^NuxP%o>zdpsF;laE!)}Gt+IrUFFFHE#=i~Jhl6_5gygG>9 zTUFzNwBF7)2jkhbuyU9CJ$@mbqvVap6vBlb+|Qz5V0AyA%;nBqC!rA!h!Yj*W1{(W zi&mXGda9jVGz}afgxoSu0CL4k8(vu%%!Z28=&ac~+p!(pgS9K{`{^yKmri?TzR*Q_ zjTG{od@BnX7-aX;8;pM11f;65UaR(NJ>8w=Q%3~B$a9^bXL#W)^+ovK5|ER< z&~*hLJ^cUzi@AvYSv{9BwGQIhj2m^g56*p-cHd1ci*~2=SkR8`S%obXto7{JtIxQ` zIjb{5fCaRy(#hene{v&`{}v*OX%WL-F^$@BBik1?lsx-d{R-EE;PuM# zd+LA5@4Qd`NelT08Gyit-0~tdOJ0nyi=t%1KRQ8!bTz{ z@8NAO>k7wIt~s97VLg4#TZ3L#!sF?%-m;6SqaN`2+(Nw>AbcM4^)ka z;%PP#$FK)oa>J>sG)Hi6M8teci8_+kuFz07akTVJ-&Pnw^IFdLIHG(e?q{mKEg zEX0q~W&}@$k|)wHi_Z^=m{vizJ~q5w-LbmaU;oN!ta((igK>pNLZf|ILWMqa-T|xa zIT)mEa`lr9aFDYe=h{+{K99t-Y@1ce?$keYn)eTWz`yT-%f5KM6I<0;=r>B(VKVF2 z9m}$YmMypPvyJw{4I5H|R^w_?tw3@nIyjkCi<{u0y(GIIU&2SfO!F+Y)@MU=uc*{oPXi93B%5>E*|37^@;ND(lM%7Dv3E*^^I4? z&ChYd`=4wb$(t^s3mFg5h39Pr{+{VwUHF;XNfbZ%;$})>`ch#Z1zzv;< z^1_|XdRj+j%4x7)v3_R13u)w*PkCGDfb(@~r%*(!QY zxfymu6*p{2CuL->nGA-wHp^CRtdG73Nvv3?c|T5>{Lt4ZSgVuUx@dx0n102MmV?AM za+}}u1*>L!J6%!!P#O%$3A^M5&s#kg;-{q+HiR8>vma*!JE9LQJ27{F=XYuk#qK)_ zqz{Iqyq)jb6v3GohnE;UE^vs16?eaD^@{QO*yAvf)V%v+B|ZU2=I&`1MJBI))#yyP zQ29<)&H@&q_$+tC(Z+IQ*c-VnNm0T()%J0Fef$_-*}NBiRtA3pnoyXC{yFffuztA3 z8@Vah_Bw`xG4wl^0-e;M&_SLH8q+BsAZ%nR~ct8>e2K1M4YcxAOSCoxUtJ#*1b- z-Bd1VW%@S)ep*k3lzb}CuyiXV^cDJGm9*~HGE_aZ{gn)(g|s7b`^mrpyLozX#d3K4 zLK8t#&ONkkGcCf~Pw2L0)N`ldz^)YmxfZfL_7zJu0$l<3?@-s!>$9*rr07&} zfbBu9-Fn^|3bfF<7qa}-4KwJ-jH@&d(lnrg<)k9wKWV=X<}26imVW1ss*9u5Keo-9 z9m`&PpOKlp(cL$2Iw9uw2=BsCkd`+>`(L3-B5CFYeO;TAHYM-&dxq;^pidJcarRxV z2v1eBWlATBnos+P;vN$||$C9r;l<#-YNHhOtyK#{63 zmGTisswg$pF-mdamZItoBl2uvRF<{Zd~~ZN$ZYeC(evDcNY^r%*_@%h;$mS>S{_@y zjcG9Sm#th61aPT>tS`IjJMqH0{Hs>`b5Lyi-poSz>W{-t(`@TSGaj2Z`0dKQB@&z z$f|;zp(pVjUbN!k_S(BJc>^GWl&!x zqXH(~7yKr1w!Uc9g9ehJDPw5joU3BhKb|sjSS@<<^tnooypvIIs!f7Bk2^#<@L8Iy zhLwtz)B7Ya6`}oN&SvEwjc}ZE$3kFvweydD%|fLBeG;iT z&9~uP5#1H3hc;{Y!rGeY(>z-zWR#xsXciG5ZQz?ZbY>6ok&NtrP<24u|JY_V&XFS6 z4kTLOvr!wULUDOHwzIa$4X(Ux;>8Ww)C3H;Cav1bO#qW9I&Tj9u57`b#xd?+m1(Tf z(DAPvIh_aR&o#e_SJt?h)?We-r|rB_l7;;2@EVg_nHrTWxx@U1K-jq@3_(4wGwnjg zU-MGzS8Ha(vlz;hz(#BI#qUw`w*!l--QH=f^)E!`dPLd$DE)ywDbH-O8v6*Uyw7W zpGCz1#@|8AHW@Y&IIG_4h_i&g@CN6)UzcV}*GxAt@ZVI#+RP#C6N@RfJ3r?5CF|^+ zQT-j~0w(xf*|&I^;hr|O4(ESnzzJa2D#uK*-8`{(HM>3hcB9jr7Ob2)7brcgkl`1l zQWmU;jgHrXf4log^=kT~Ngoie?s}BF@Myu$30g43l!}ZLTy+oZXi{=?VQ{LULlogV zSIn2@vU|+k8!M1!YZHQ9hoY65E{Rn&5%uPI_6Qnu()#LyKdkYhK$0>@gEj$D{tg!lO%853mG6p+KQBC zzf5If1a)+x$#&2))~juTSG?n_dJueU1bt;QbonM94_5tN7(4UO!kn(c=KE6}FE#!K znK~M3?#>p`Rvo?-pLJ$!Bs#pA)=5xHZmRIuMZ)SWuK$XOdN2HQM0w$ z=zrk%R_4odri|V`NaYZI&0S~i`$)bXI;oiu^DoiTb2W{_Q!l*vP$_FJwudOU44w_L zUUq=|90?CR;o#2@6fMuV0_BnAoO_iLrqXTHr3ms2nb~ zQBLR4z@wTW?<4#z`ToPe8vR*K-y-<~qDk9C+D-3T$j`WmOGv%x`|?bG@9Y26ezBdp z`_?>mop;N_mGYKpMI_{>XjoDCvP!3Fw)>NPV*jrm13rb6F}|M~$lR5-!h8-v-#@>8 z|AGq`-ARHwTAXSAhfi4TJUAq?N=8^U5{q(}NaK4cu~ysq_*Tr;=YoGenST5Clb9dh zPmdOqgur6Dj{r|TdKmKYuT#jMKkbnZ=c7+mUYU(|`}sN9P}X{@pQbQ?P7Y>dKgn4f5P0%DMIDt>F z<39>xO7H*Os74GY#KMjM9rm`bO$rW+0l@AP0PG51`by1+*6lc#UCcYh-Foub6z9Vq zfQ$Km`V>pzz53exPp{G?{CTwBUX3U0)+Z+9O6A(zdNDVcN6G>H1ZMRA5EGb!f?;sSwH9ysAJix`>W;U<9=DkD=Nn3wwtBJ-`V`VJp3i=tN3HV zYa#%{0B9>K;g^MAir=1OBQEV*zcyzS=#|dS48B1MaRjv(nUA_F=EtuPyg|= zb~ziAV4rnTihSbOpNN-|fKR^$zkL(9Q|>F-p*ZJYMF zP{6?tOrU!V0jjICuM~}*96>3)n}DX`=ql|O1-P&K5NxmzHhd)0;Vhj#8s>=?wvsRaw8((@vnn_2#q(+O-*0^ z&&T8?9gbJ}BbIFbt%GjF2v;3(!V|nMFa6sh^Lyl}B?9Aq7#R1uIiEvdPmkWNI4tBI z$Yav7pK9@6=7>Z3?U+wui_0P`MF+VTts?(yUk^g%d zf6h8SS!-?S{bBnD>$AX%k>(*Be@>fUZPVrsth+1=6V3m1`ZNF&;`c23xV?8|EcCo< zWQx(>ZHYYj+CljCO$k$zOuIC{(TGv!U6%dG*FR>T2mX5G*l~<$+<8vK^NZdG5&z?- z6r7s+D9-`g)9=>>lluvdcMeg0oP6!FaA#`A|G%;AMta=?vD~_W#qW)n~ zzg~Ixz0*MKdhgB7ILC9DGd8ErMiyCIKE-L}+y1VOc$7p|jD3)wWNi1HZ9qDlzbyW7 zaGlIkJ=*tshy+EV|6uL*05d)w6ePu4fXN;TLbtcqQ_9Mofs-Q^6$`+RF@9gGD;ELf(Kkb3g{6+CqZ00XKiXQNkuH&sp z@Jp^!r~+>F8cs}-G0CN>5B=LaAmq$JK)R&vUp@6W_0}Ed(P{Ax`48@f+rXYonwf9l zd+llu!H(1}dp#dj@%}7j@Ng+Ms5u!%48BN|J%*W9DIKwDu2Kumz057QzoUBx3wR+v z`5~fBSa~O5p_k4=-Ud8*ZCi6!l2rG$dao64efFc{5yAD=BXeo=N+2dMn`s1~Qlor6 z^w65*aqcV3^oE0`U*f+KAhnQTqGwg&2e$b|ujAf%W(OJPaU4}cH0owUP9*CDIPHBJ z0RcjJ{rin-JR;Gjuvcc~Ha5$Gf!~Hx`+SRZ-mac1?Ws6{B4J{nGM_Xaf^ADIZ9~Gm zWwSC#oM$=gXjKr8*RD=12m(l z4p^I9jsi=3rA<5f;9{AIWEHA8@FAxk<5;tg;!S%ZU~WoK$EHBi0#~?50Ju!L!)-Yz z<8_lhMQ9TNYy?O&Ua2?FRxGl@#BFcJKq3h+)_zU#zHcvu3n+v}Jw^!C45a1o+wRHC zh?9T=>m{ZYTo5I+dNMl(zp6oz1$r&wto+UsDHz$MbnTUMa$BWhp+Fi4k3i_6h2lV37qR6fR?}LMF1?Y~&ARp4a zO=n^-hK!W&x0=2MK7DMxU*XC7!eS*_pJ02ALH+d%P1UFD%D#G~PH3)BaM|iiuSDV- zRQ+;=^H|Lld&{j~po)>N+NfH`G(Oett5xH>5JGYkjQGr~>?io}`k0Su5>>#zrIxy) zW!Jzs=fil(Nq*8`5MN3UbmR~6tbN=n8=;a16`ISO7Gf3NE!- zQ{-WMx^lpqybu$S)3w|LCaB>Ytxa4J%&FqpFe}P5`jlzRExekZ#@p7!TL{k9r44V) z_jhh6E#DI{fhL2^YAL1bI0tvE?MK3V)I3!gTSCiKT!#o^0yv#doq$0W=wufOgR zT&?=>(`hs6Q^)4gNfIhj_j|Ri8ChT^g|)nV*}K4x@-`^YOail^AA#1W+v?%98!I@ANB@#j ze6OJ*X&2j9=6P^_hfugs!3*uYX%g)=S0vg#6(KRT4zP5=%EEf3@G;2&CJG?|u-o?* zQgL&=ZE1Yy>UuH@zg0yDDJvc~Z+1MzV`|csmvK$V8}sAzu{KHW6razn$?HRgP_xd~ z_O)jInfmCF3d@#bd_gFf%?^0<6&Vv`!Y*0p>}1gp(ix%Bks$f~obRBcX8WMr*fYzF zxD$(?({II~SE^dJp3@`cRIh9C!JST)@~(7|kVyap#GBpu|%*<#6bg=gk7pbVo?@#-kn;$Y60$KvL)F zrhN3L`cCp-Aaw##4gwW?l~P)Ple;0Dw2E#>h+a;B>wsyXZRsqYHxXI!`8Fo<{yjlW zm3a}tary)%d$~kADbgjZ$-Vj9vpCbI-L+%(?MYx)0e4Kkv@ekcU-qHi@TQixoe1}q zZWXKa>>zhLbD#Or_R&+(U!XsW@TL)h9oJ1eUmf|l(!iluc0QlAdn0l0Q37MI zJsTJ_r0|~VP8F$5aJmW2L#_%`-Sd6h8pX6V3Em7>lfh0VITV_34uXPcVnmQIHskqv zJ_^&CU(Jp|f{Y8PmV!uGO61v@J!M~Fq}}=qJ#o(jHzjwJUv+28fYkJ(7~fDVmz1jD zGMn^PV7NNxanQDHyC~<%4Z(1Z>(hwZu?+&WW?>}wb-p9EBQH!fqxlj3H1Bx=$J?H; zcnf=D)B3`NZrWXn1r~z_52KP+S7n^2KH!FigH$5ELVE{=l|S@u@2AT8S8FKI5}TOQ zG-l^2;2-wLgpupW)!eL?O{Ywukw$H;L!>~PslbZW32Q00uH_Yuz^yGO+ts$|?`^$s zHmRJn(V@bg=|p9?dn@;*%Fw7cX?DeTl4j}}z z5HyC~4$<$)sOfpfr~Gpl=h6D1OqqATj^W7S;5P0KSA_rqk;TF9c@NEP$N}jDnUDrX1eivg8n}JqZme{28(?n0 z2H(DPMq$R7SA^nRJfsEqSNn^diEOU2}3ifSTsbUyagih%O?XaLeU#!0=x@qXb?JidH&_{fKg z$D=~NjR?(#SLPBufcJAL7vasES=7n54RRJP&QPMy!6#VPx$5k}@koiF z%Zx}boiRO3+dN3Rj*i!`D{j0YGijD%=E9hHKUf#xs#4TI@bk7-*vwM3rjJ<$eWDxM zaJw4kcdww&6(g$GK!TABy>7AFD?$R3Nw28W3mi*Y6>d{8ROaM6E{;WdTIUA3-&M~^ zjuh;tkZhh zhdwj)_7%!_sfMoT5iap}XN4oS$B<4Q^tIre1jTUBS!t>z(7Y}WgI?x)2|$TAOMf*H z4ohUX9%fm;M*=R4Sgn3#k*lg}meG#cZ867pHzTA#Be$xu;>^B9rk)52-Vwi6=g*&N zqRmy$9;iABp{`);%;R@$gA<&Zjt1)8aYh7DmpP!=F?f~urA4{m!3(f(j_>;yKOGlM z7xzT3?E0AGoAIjw+JfsnjdgcY35Mct(+nUl5k%*vf?0S$?2yj5!ao%Hp;wm=p~U+yD;7e4)M_GX>U zKx$$EcC8Qfn69!t6O7Nbw<-ylj>QjhcKE1zQ$azmV3AoR?TbJ?lDTy7v+N-9I{{%$ z?Shaihl8+tnImPtj=9bu^5v`c!g^aoX$WVJ+2l>M*HLUGts)Wc?0xt7#BRl4z#)^T zg)f+8+Sh-{SLOXBj`$=~1p&xuv2xYgsGkIJm7^k2pmZn^<8DavR z`SksU%<3eV8|3l?+o_Tg53Rd^Se0$KK?tSjS)a7}@>Bp2uu5|&(w7c;77Tv1q;lVn znFe_-Y~r&oWVpyhdTZJ|1M1N2WUYlrtmW|s%nRruhovK4m)~gfbbe~>woeAO0Y6W7 z6%w3c`i^;i;Ol)lC>9v%E~8SZ`hY{_bIzm4{wutN(<*wfk;gX_mMgXKMP5quTId@K z0fHdImh>=@!$&B2mDUS69J%I!mp2*4T_d0|lQBL%YdHgYVw_q-u3&SpPxL}B7+CnRPQyCtPK;(qI!I$CxJ24_c7M{l%VTcG?5JhqHVA|6thHTEyCM$58QuRT?a z=q$6wG$R5U9NGj^=h&B>L%qT2$lyau)<5{@e(%ppE?$7X0QZ~3I&@<@NpQF+B?TYYC1?JHYzF>DSf&Cu?=l<1pVFnck3OTBcY z=;ueFB@_pGkFR(0KrcPdyv^tkq?A-mT-do?Sm9(BEh9rQR?UAQ>=Ce;I}DEBRg?BV zCWBI*f39pn4)Espp*8eataJ~TWvcS*9Gcdj-=zJd0HSBDjaiR0;37+t3Xr*MI{Pvz z@^s1eA_sC0$WhB7=!TSBRyoJ##6Q;3=0 zjb#b?g4x+I_qnzyru~4twMbHJ9Z;!O^N7o#WKKP9+M>3Q&$k~|;pmrzb!lkKoL+APkaGv}` z(kJza72_@Xt!Bz&|Gr~qc2e>PuXpY^9k|a{@#U6gmA94{REn>u+i_9na$FU2JREMYNwgdhY${5^8?QRNzRb#i7FzwQl6fH{@ahhpHzcvn~|J%_DJp zdU{^&g_!`;uNBNRyE&s?c{=eCqdR@6%(*Do_mI&8B@a5rCI623mn3D(>Q2h6LILRM zo5oS3$Okt4L;C|$PuS*6Vg1g1*N1j&#|jAjRP|ughE>=3_PS2_@!g#fVq^1lr!ldr zl=&BS){9l0y6O|i`w4+$)$Y0hV{?~hR)NcWy*W4?yZMRMQJ4GOv^x5E#%71 zdtR%ZL!GKmf`K~rpkaXFSL;|6jmZSr*yLZ7R!3FiGB|9sv6{7o;Sv%xXOtgoT!wqE z+80vMr+d#JOn4!@WG{Li{!m}Peb|Yx^t67POwH6`!RL2bgQ#KI!Hb<)3@>Wa>%N`< z2H<9Gd8{h!8)J84(wlrcP-y2?$l^C7F^gBF|EZkEpiovSg`aN9|(BbjCiU2XBeW79E<+V;t*SI$sp@QDXI76peE)GUuS3QD`kqT&v1B)G0{7iU|L> z@nt1S6j_v#FRV)c>^ufh?q6!U?1k=q?jOd&ZFsP>V>lnbglu^?FEd|_tp2c3!zZ97 zJe-&QA+TJhXRli_&{HMr-IL6r_sFG@)=ivAVNFlh6H3+TcP2yP%q+Kf6kf$BI?Q8$ zjo^2hPQdJTH-4ZY&?SUah#$=0a0@2Br3Ln-ht&u{?3$f>&S>(Cs2NI>{60n3>q; zX)YM2LjAE?yVvQYpHa5sB#PGBZ0}aHQ(iu$ZV~37;Z?J%xp8~N;SgEuaKr2h59v$(n|@yb z9tkbX1=&&SLTjJEVAryS;RcdEw*~71b2nZc5$Sp8TCV&M%lc*@Dl_iDj<|_!XErY? zdEs+Hsn=d?&5{7Hc8J@Y`DNLgXf;3qc^{^;MLOlkth!aXeX6%PGYk4CS!h=7*1l*S zo-Hccx!JH^fFr$QTQZ8s$~JJy%aF&JRJ51&Uy@C-DuI4(){)A_<3$>EM9WJIq8*Aj zvCOUf8^-4PdBQ!KkyUx~+F$&(FUTIj4DMZcv``Qx1=#812>GraL9jw9^Epj2Ea5OW05@7tRBb zSdKO8Kb=`P)%5G(C$rpNa#@DfDnRgz&q)lbrfQx!&M7vi)%(qw<+EK`e-~#e`}=)@ zr+-+yZr;#jB52()K7mTC|MbCfy<)A9gC-px6k5fgR~QjR%`kqAwG2$Fo+?Qb@9O_T z$+M_}EluOo9${^G$-uG)k$?G+1BsP%zTH z`Cd!!Dfd9}7RXqRJHzLNtyl@^X054i@G>znf0>x7FOs!b65NrXLcZ$S9XKgOemj(@z@4k)kd{ex9Egx6QBtGt$uZ#51x&lPj7rfUB?lPd{52mMafC(cL1-_N_LJ)=sx`Q21^wbo%(+d*@}5<;})H!U*b4iYCBL zf=|eEJBbbf0}Y)Nj#G9@ug>gbbA6`Ak*WXq0SY!-4m;l)%lqPC^q zE&r7-LfJ=}+tSU$r7K6c?G-yk3l-SsoO!lN^f|vXaNB{k(ES~KwB6Ss*S9spCOTG& zu!RM?dn0p;i_Q=zsge-n;Fj;s!G4q}w_Dn6=X0+#xc)b0TfY)46i? zofQVsoZ8kHZwYZ8$GQbZya&|*>TBMY95vaMU^dB?r8?Zv4%6WC;iGPEL{rJ;WI}Im zYCMx-_29ThYG-zG!L;UEws>~x@-)9p7zj`pNju%oVc^v{$}M-@YP5dF2%#34DxYqu zvrVbEo~OSMr6^F;d!`<&Ii_+xfoh5hr0Mt!ES&0-xqYux`xMUwE7jW{u8hdTH#6i? zfERN4s=>bXGvxL`u02cVIZvWzmoPH7hQou?=k?=HJdXXY$TLTuMR56Qa%AD2Eyg2* zm6uE}&oE4e0sbip zw3KUitLM~@o#dMxr%xZNwk;E#F%I@G-@W=FNe=SJq1-%2-3!b zwjRy*3s~q>K{W$7mecEVK)Q*?Tkct zLA-%yofSmddyyw@##?w4Tj$AOBAHftF>desGrT)Ct1?v#fCPf8jtc12J?da}#ikx@ zKDe@d&`a+##4{CT#sE}|ua4|)iOR(nXf|;OZ4$)1IoM0Ygf}v7hfchl1F;E&&o*6n zSgNTA`>dDaQIcpQv-EH=87bgn4z70Z2IB9e%{QCk8fA*WsfqVsP#m z3qT5i@T9`hKw~-2weqt*8)uv%&!j!QSyMkqdbK3L|NZI?udwT}4EwaeM#g3I;3L|8 zdD$!Z=h=zQw1TGV`X&azFu66U-*o+cjV5iZX6D<<3Ze$OsbK#+|A@Z2j&IUrCXIEL zFsw>jiWt=KTs9x1-nx};!Qifrw#q-ZR)Beh5BhWwUg2H$@GX;TSVbX0;p6p1_{;hq ztc=T((~GRvg&jB`CJVNKN1GUzv(mzmAdt6vJ6K!!6;4->B;jxW9 zWHLYQoO&Ob5gfg^eoN%h6$ey=sh4a1mDR?i1_@{8uicnixgVxa4dYO~91qxx`$j6} zyQ~v-e42)6mOktl9bveW&S#z@w4y#kouo7^!FgbQc_EWq00hNz4!^DqOK^wlxuHl+ z$pUA*`X6CAaX9J0XhwkfroVp9LhAR|!zpH6F>=_rS&G`mCllN5%pvp_UFApkfh(OoR`9`j2muza+3GWS<3`7-8>35AD zxBkBLZKw|ALF-Wz7?!Nbd!)nxe{xFYiR!Cv*`Pd2w0?aJmdDo@5KCI%f+IzU)Hy2c zyUiKL+Alz_tW$Ti7$rn}`6;Gg#&{9)zLE!FwRVJf|>Y!l!Y^NTtdGb0flc9Yw zqK>}AYt(%A!7%0_3m=HKDXv7k1ofjgxIWZg&Nh2Djpkd*PI;&N;M>~f_q(A>8}$z9 z)qy`~D`+<{^M{|Nov*MU$b*G-e7d8LB${B#DBd0Y#wzB(e3vlORPhM6qDx&_6ger4r2qxAX{N1nHz!gCNo!(qdh%=6p&RaX z?fg_vXlS<>gq0$L@3hgYwYKtI@Pg{1T-8;bET<1BI{5=t(L_F<<*DrCUO(rDkGNg{ zx2>I$3yL8Go$?P3M=9S-T=Hl8oHLEj>e}-oeCY1llw@u{`+Z(d@zo>hmgKv#{3e;5 z;nP*4GE+__Z~BSrX?B&$aBrOTm)1iNqMZ^qlYW@mey?lIdE|H z<^%PN&dbZ2+)GTHYYX0OA=&xMxGyRnl2}c2SU&oD5~uh#L1nDk`rL43ZwO>VulJI$ zg6V#gEMO;o$z|Mt&K0xQVF5B7qIz@HALUvp2qTbq@=eN^jZwd4x(`=bv z^_$-4mTqTff!&8cV7*dqVYs|Y9&vTmtq3VKTWQP!YOd8^Pv6Z$r#00)ibU!WP?fK$ zpWobn28q#Q_ok5Q{UqIV77?J)abrSwFosQrVxao*AP zs@JVZ`1S{^=wKa!af5d|m|Mq-{=nrMXlduMK($6p4(Y9)>~oV*o+w9JKhs)4=iRm9 z#K4BT+v@&W2&Gx=Qb2GN8quSDN215l;>*jt6z=5lkM02UPZ(jqsB9TNT}|_JWf>kB zEatlVTL1+GsYwkzNG2C|!) zj!Tf4rV--qchyp1=AZfN`@ZKH{^EIGc<(*;o_p@O_x;^-s*);e)7-5$#Xluon2WcP_Io1FJtXY=D#+3b0O#bRh{vP$=a%qPiehc4;YyNI>sn=h^2m3j&}!5 zK6%le=A(Ntg^*#tPs>{fnmoofjl9TZcgD{)*9{48YlZLD%sX|8KjnJFiNTY%q>M_( z$ji)}F5VA?Tl?Z)sb+cDUta!=z`XDiBpGYrz^4y=x|83s2A?FE7z1;h#(u|x+C!kd z#dN?;b#AsB4`%>pcTv}J0AAWkNO#1LL!ZhwPma9S?faqbO6#Hz$$RY5Uybtk1PJ`+ z8RTgvM3St(_3DwGTS|^7BsQ^H=>?E7f^(Ik+>MI0^I5Sj`3sSbAken5>M!z*xp33Y zhV=lv^G8#~xGGp$4vdB{d+vS|9fAjo)EV~g;xr5ftupJ8Z}Xky^blH2dtEqi%SGm` ztDl?8$@WidxL+n*1fmJ8o`C@$FohN$w50sKy0T`;qTqPge(N=*p(O>O?stpsyOavn zRh;`W@Es-$x*S{j$oYo-j}oos(xF3R%3P4SJPM@5R_KV-9)8Bx>!{$@4W(s-7@d3XR z8|iCbrX1<1CoxmO=JP2f_3LCPCFnuQI^|q)>0JEuZ}_G_39y4@!@owWEF;D<)M;C2 z#bI2YD_XwF37GDqGNfgR z1SdvE0wUB=n`PU--_C@9>v}ZVl&PeNBBfYCr24G3|0UnmVQFyP$xms=l%p;}hu)Hs zX^uPh=e!&m)3?*)!1YI*^?q_<1<2^gD$sN*exFUb@Le_)83h`=#FnEhR)E649Wk$q z{_O}6eS-Z@j))WMN!ns|BduF@w+T7{x5GbSxGS!Ko9D_iGK*9shm=5BHqU}sEG|B8 zYg4Z8k&e@XrmO}{{Kq_fl-M-I)Q30_n9#hIon_LW_zYvGk2{r%gH0dCJ9}h&G4j;) zBiG*Px+F4uFnTJ7t6RyRU2AhpI1`x*3)#-b?y{|w4w}`GG43G4`TW6*VaR0??jQ!1 z7$&A_R^F6puDr+CHa{@b0?ff5()RRzd~N4Ri`0CN3;My&-sN_uXf?5xFv&MJ-zsgm zri(#c7G9e>t2EtnSi8u^!Hd4mrn_aEYv>l5OTOEr>6%<{gnad}7Y4ipkBNY zsUY~Nr4z83PIgPDQcKSp7Ll+5V4%7$2N;QpBq4QF1(@;pxM*FI6 z6OxNYjmP9M0)c?bM=^g}xT@&ECmT+yW1kWGx=5Ql9_Kv!%uQ;##$L#?-rT@UX-qHA z%Gn!888ttVtm>NNL9iqFK-(V1Z*xJ`m1fa?3e#1U_PNSCM)|gF7C)67T?kffurH5*-`LhO#F=q&KM4 zXHHfwr?J~&%|sLwu;1GKy?KGmRnXtfN1N*j8Q6n)jRhI`ygnPZwxE0j_jVtN6)?Ch zWw3>up|(BbYG|jx23Gh*50~cJ6gKeEyGHOqy~f~~^|httyT|%%3@O}Hp zi$+Dv;g2+5YyMXULsm|cXP!JMyWqgVcyfVDsjR4e@w1EXTTxg{9InTO>a)J%7^j8g zVyp192pRqLRXOWo(rD2Z*WL z$?3geHRH{j9`e*MC_%G)m6V7rN+L?v{x%*d>9y!rz|Go3@GIiHyc*a!>E#iF&fNTi zslp#8y6ipkHcDHS3@rO!Q_{7y1xsP)i8~k&iX#7jA1V-9>Q~ttV zyxO_`z6k2OKYo6b*?%aRY8%bixG`tYwj=mMb*b582{fJk;q#ul^CMJYE53ImpPU;M zNGa^KAV)#!a)Qls%NKs7M!GS)18cDNJW-QBISn3vbl6?DynDV?1dV2d#JDFs=2KG< zy60}(7y7gb+V4Ghhn@(HRlD4?IM9)OjB14n3@kZ7Vi~xok+ogAhh-_u9yD8?$`{Dewl(TRFv{8@+Gl*K%;(*@Den!aV&svCa-C@=cr9BjrdE&J(1BOA*H^#pO;!bHhjL| z5>u|;si$qF1Hv(~JcOHKI8UZ&>1?N5bJ^x|o57~T{HLT10Ap{`ih6~cJBm5o5k?YV zc3AHhm%m@+_X{xPU^;0H`Mm1Tk+=7ly_h3@Wb+FPMHpAF8TB)Bw7xyvq)kcZfX! z-nU+i*E$*d#b(!X8gUb2V1Ba!hhly8`^;km&2Wl_+P-KzI6A<MSE$bF}K+#FvE_J*5ryX6X1+Iz&;k0~+rva3_4Tf@Aq} zQ4nVuTM;z2Z3i^)rbuHifM9{cLVw(9TBRYTF;-x`V{*NTc|csuV?bldFY|WzifPRH zH9%u@kcO(F^RRaHap19N^xWxuE~YWbSAfRE(O4&S#5CsrONio0$+S3hiw{pNV*&VB M9kAP Date: Wed, 16 Oct 2024 14:08:33 -0500 Subject: [PATCH 2/7] Updated endpoints guide. --- .../what-api-endpoints-to-expose-to-the-public-internet.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/articles/what-api-endpoints-to-expose-to-the-public-internet.md b/articles/what-api-endpoints-to-expose-to-the-public-internet.md index 0c24d923ae49..6d7e6214c783 100644 --- a/articles/what-api-endpoints-to-expose-to-the-public-internet.md +++ b/articles/what-api-endpoints-to-expose-to-the-public-internet.md @@ -57,6 +57,12 @@ If you would like to use Fleet's Windows MDM features, the following endpoints n - `/api/mdm/microsoft/auth`: If you use automatic enrollment, authenticates end users during out-of-the-box Windows setup. - See the [section 3.2 on the MS-MDE2 specification](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-mde2/27ed8c2c-0140-41ce-b2fa-c3d1a793ab4a) for more details. +### SCEP proxy + +If you would like to use Fleet as a SCEP proxy, the following endpoint needs to be exposed: + +- `/mdm/scep/proxy/*`: Allows hosts to obtain a SCEP certificate from a configured SCEP server. + ## Advanced The `/api/*/fleet/*` endpoints accessed by the fleetd agent can use mTLS with the certificate provided via the `--fleet-tls-client-certificate` flag in the `fleetctl package` command. From 01a7449fbc833c811f5bf8a5cb77d434cd7a012c Mon Sep 17 00:00:00 2001 From: JD Date: Thu, 17 Oct 2024 09:33:42 -0700 Subject: [PATCH 3/7] Update grammar and formatting --- articles/ndes-scep-proxy.md | 23 ++++++++++++----------- 1 file changed, 12 insertions(+), 11 deletions(-) diff --git a/articles/ndes-scep-proxy.md b/articles/ndes-scep-proxy.md index 60f5e57aed23..0f60b7aa3e5e 100644 --- a/articles/ndes-scep-proxy.md +++ b/articles/ndes-scep-proxy.md @@ -2,7 +2,7 @@ Fleet [v4.59.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.59.0) introduces support for NDES SCEP proxy. This guide will walk you through configuring and using NDES with Fleet acting as a SCEP proxy. -NDES (Network Device Enrollment Service) is a Microsoft service that allows devices to receive certificates. SCEP (Simple Certificate Enrollment Protocol) is a protocol used by devices to request certificates from a Certificate Authority (CA). +NDES (Network Device Enrollment Service) is a Microsoft service that allows devices to receive certificates. SCEP (Simple Certificate Enrollment Protocol) is a protocol devices use to request certificates from a Certificate Authority (CA). ## Prerequisites @@ -22,13 +22,13 @@ Go to the Fleet web interface, navigate to `Settings`, go to the `Integrations` ### 2. Configure NDES SCEP settings -Fill in the SCEP settings. You will need to provide the SCEP URL which accepts the SCEP protocol. In addition, you will need to give the Admin URL with the associated username and password to retrieve the one-time challenge passwords for SCEP enrollment. +You will need to provide the SCEP URL that accepts the SCEP protocol. You'll also need to give the Admin URL with the associated username and password to get the one-time challenge passwords for SCEP enrollment. ![Configure NDES SCEP settings](../website/assets/images/articles/ndes-scep-config.png) Note: * The example paths end with `/certsrv/mscep/mscep.dll` and `/certsrv/mscep_admin/` respectively. These path suffixes are the default paths for NDES on Windows Server 2022 and should only be changed if you have customized the paths on your server. -* When saving the configuration, Fleet will attempt to connect to the SCEP server to verify the connection, including retrieving a one-time challenge password. This validation also occurs when adding a new SCEP configuration or updating an existing one via API and GitOps, including dry runs. Please make sure the NDES password cache size is large enough to accommodate this validation. +* When saving the configuration, Fleet will attempt to connect to the SCEP server to verify the connection, including retrieving a one-time challenge password. This validation also occurs when adding a new SCEP configuration or updating an existing one via API and GitOps, including dry runs. Please ensure the NDES password cache size is large enough to accommodate this validation. ### 3. Create a SCEP configuration profile @@ -104,38 +104,39 @@ When sending the profile to hosts, Fleet will replace the `$FLEET_VAR_NDES_SCEP_ ![NDES SCEP failed profile](../website/assets/images/articles/ndes-scep-failed-profile.png) -Note: If the uploaded profile is signed, Fleet will replace the variables and invalidate the signature. +> Note: If the uploaded profile is signed, Fleet will replace the variables and invalidate the signature. ## How does it work? The SCEP proxy in Fleet acts as a middleman between the device and the NDES server. When a device requests a certificate, the SCEP proxy forwards the request to the NDES server, retrieves the certificate, and sends it back to the device. In addition, the SCEP proxy: - Retrieves the one-time challenge password from the NDES server. - - The NDES admin password is encrypted in Fleet's database by the [server private key](https://fleetdm.com/docs/configuration/fleet-server-configuration#server-private-key). This password cannot be retrieved via the API or the web interface. - - Retrieving passwords for many devices may cause a bottleneck. To avoid long wait times, we recommend a gradual rollout of SCEP profiles. + The NDES admin password is encrypted in Fleet's database by the [server private key](https://fleetdm.com/docs/configuration/fleet-server-configuration#server-private-key). It cannot be retrieved via the API or the web interface. + Retrieving passwords for many devices may cause a bottleneck. To avoid long wait times, we recommend a gradual rollout of SCEP profiles. - Restarting the NDES service will clear the password cache and may cause outstanding SCEP profiles to fail. -- Resends the profile to the device if the one-time challenge password has expired. +- Resend the profile to the device if the one-time challenge password has expired. - If the device has been offline and the one-time challenge password is more than 60 minutes old, the SCEP proxy assumes the password has expired and will resend the profile to the device with a new one-time challenge password. -The issued certificate will appear in the System Keychain on macOS. During the profile installation, the OS generates a couple of temporary certificates needed for the SCEP protocol. These certificates may be briefly visible in the Keychain Access app on macOS. In order for the issued certificate to appear as trusted, the CA certificate must also be installed and marked as trusted on the device. The IT admin can send the CA certificate in a separate [CertificateRoot profile](https://developer.apple.com/documentation/devicemanagement/certificateroot?language=objc). +The issued certificate will appear in the System Keychain on macOS. During the profile installation, the OS generates several temporary certificates needed for the SCEP protocol. These certificates may be briefly visible in the Keychain Access app on macOS. The CA certificate must also be installed and marked as trusted on the device for the issued certificate to appear as trusted. The IT admin can send the CA certificate in a separate [CertificateRoot profile](https://developer.apple.com/documentation/devicemanagement/certificateroot?language=objc). ## Use case: connecting to a corporate WiFi network -A common use case for SCEP is connecting devices to a corporate WiFi network. Here's how you can use Fleet's SCEP proxy to achieve this: +A common use case for SCEP is connecting devices to a corporate WiFi network. This involves creating a profile with SCEP and WiFi payloads and linking them together. Here's how you can use Fleet's SCEP proxy to achieve this: 1. Send the root CA certificate to the device using a [CertificateRoot profile](https://developer.apple.com/documentation/devicemanagement/certificateroot?language=objc). 2. Create a profile with a SCEP payload and a [WiFi payload](https://developer.apple.com/documentation/devicemanagement/wifi?language=objc), and send it to the device. - The `PayloadCertificateUUID` in the WiFi payload should reference the `PayloadUUID` of the SCEP payload. + ## Assumptions and limitations -* NDES SCEP proxy is currently only supported for macOS devices via Apple config profiles. Support for DDM (Declarative Device Management) is coming soon. Support for iOS, iPadOS, Windows, and Linux is coming soon. +* NDES SCEP proxy is currently only supported for macOS devices via Apple config profiles. Support for DDM (Declarative Device Management) is coming soon, as is support for iOS, iPadOS, Windows, and Linux. * Certificate renewal is coming soon. * Fleet server assumes a one-time challenge password expiration time of 60 minutes. ## Conclusion -Fleet's NDES SCEP proxy feature allows your devices to receive certificates from your certificate authority's NDES service. This feature simplifies the process of managing certificates on your devices and enables a secure and efficient way to connect them to your corporate network. +Fleet's NDES SCEP proxy feature allows your devices to receive certificates from your certificate authority's NDES service. This feature simplifies managing certificates on your devices and enables a secure and efficient way to connect them to your corporate network. From 7b5f9365e83fe6dd75b139821073ffabd99eb210 Mon Sep 17 00:00:00 2001 From: Victor Lyuboslavsky Date: Fri, 25 Oct 2024 09:36:49 -0500 Subject: [PATCH 4/7] Integrated review comments. --- articles/ndes-scep-proxy.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/articles/ndes-scep-proxy.md b/articles/ndes-scep-proxy.md index 0f60b7aa3e5e..d0a8fb05584f 100644 --- a/articles/ndes-scep-proxy.md +++ b/articles/ndes-scep-proxy.md @@ -1,8 +1,8 @@ -# Configuring and using NDES SCEP proxy +# Connect end users to Wi-Fi with Simple Certificate Enrollment Protocol (SCEP) -Fleet [v4.59.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.59.0) introduces support for NDES SCEP proxy. This guide will walk you through configuring and using NDES with Fleet acting as a SCEP proxy. +Fleet [v4.59.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.59.0) introduces support for helping your end users connect to Wi-Fi by adding your SCEP server. Fleet currently supports Microsoft's Network Device Enrollment Service (NDES) as a SCEP server. -NDES (Network Device Enrollment Service) is a Microsoft service that allows devices to receive certificates. SCEP (Simple Certificate Enrollment Protocol) is a protocol devices use to request certificates from a Certificate Authority (CA). +This guide will walk you through configuring and using NDES with Fleet acting as a SCEP proxy. ## Prerequisites From bee9552de96eb33af8ab6e1486df3bd8a11af602 Mon Sep 17 00:00:00 2001 From: Victor Lyuboslavsky Date: Fri, 25 Oct 2024 12:17:52 -0500 Subject: [PATCH 5/7] Added reference to Apple profile variables --- articles/ndes-scep-proxy.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/articles/ndes-scep-proxy.md b/articles/ndes-scep-proxy.md index d0a8fb05584f..42fe5169309a 100644 --- a/articles/ndes-scep-proxy.md +++ b/articles/ndes-scep-proxy.md @@ -32,7 +32,9 @@ Note: ### 3. Create a SCEP configuration profile -Create a configuration profile in Fleet that includes the SCEP payload. In the profile, you will need to set `$FLEET_VAR_NDES_SCEP_CHALLENGE` as the `Challenge` and `$FLEET_VAR_NDES_SCEP_PROXY_URL` as the `URL`. You may also set `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` in the `Subject` if the hosts were enrolled into Fleet MDM using an IdP (Identity Provider). +Create a configuration profile in Fleet that includes the SCEP payload. In the profile, you will need to set `$FLEET_VAR_NDES_SCEP_CHALLENGE` as the `Challenge` and `$FLEET_VAR_NDES_SCEP_PROXY_URL` as the `URL`. + +Adjust the `Subject `values according to your organization's needs. You may set `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` if the hosts were enrolled into Fleet MDM using an IdP (Identity Provider). You can also use any of the [Apple profile variables](https://support.apple.com/en-my/guide/deployment/dep04666af94/1/web/1.0) to uniquely identify your device. Example profile: @@ -59,7 +61,7 @@ Example profile: CN - WIFI $FLEET_VAR_HOST_END_USER_EMAIL_IDP + %SerialNumber% WIFI $FLEET_VAR_HOST_END_USER_EMAIL_IDP From 4978216399872c56eef076f5323216860939f664 Mon Sep 17 00:00:00 2001 From: Rachael Shaw Date: Fri, 25 Oct 2024 17:57:36 -0500 Subject: [PATCH 6/7] Minor formatting fixes --- articles/ndes-scep-proxy.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/articles/ndes-scep-proxy.md b/articles/ndes-scep-proxy.md index 42fe5169309a..7f547711c2df 100644 --- a/articles/ndes-scep-proxy.md +++ b/articles/ndes-scep-proxy.md @@ -6,9 +6,9 @@ This guide will walk you through configuring and using NDES with Fleet acting as ## Prerequisites -* Fleet Premium with Admin permissions. +* Fleet Premium with admin permissions. * Fleet [v4.59.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.59.0) or greater. -* Apple MDM enabled +* Apple MDM enabled. * A Windows Server with AD CS (Active Directory Certificate Services) and NDES installed and configured, including the certificate templates for the certificates you want to enroll for. * The default password cache size for NDES is five passwords. Increase this value to account for the number of devices you expect to enroll simultaneously, including devices that may be offline and need to enroll when they come online. @@ -22,7 +22,7 @@ Go to the Fleet web interface, navigate to `Settings`, go to the `Integrations` ### 2. Configure NDES SCEP settings -You will need to provide the SCEP URL that accepts the SCEP protocol. You'll also need to give the Admin URL with the associated username and password to get the one-time challenge passwords for SCEP enrollment. +You will need to provide the SCEP URL that accepts the SCEP protocol. You'll also need to give the admin URL with the associated username and password to get the one-time challenge passwords for SCEP enrollment. ![Configure NDES SCEP settings](../website/assets/images/articles/ndes-scep-config.png) @@ -34,7 +34,7 @@ Note: Create a configuration profile in Fleet that includes the SCEP payload. In the profile, you will need to set `$FLEET_VAR_NDES_SCEP_CHALLENGE` as the `Challenge` and `$FLEET_VAR_NDES_SCEP_PROXY_URL` as the `URL`. -Adjust the `Subject `values according to your organization's needs. You may set `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` if the hosts were enrolled into Fleet MDM using an IdP (Identity Provider). You can also use any of the [Apple profile variables](https://support.apple.com/en-my/guide/deployment/dep04666af94/1/web/1.0) to uniquely identify your device. +Adjust the `Subject` values according to your organization's needs. You may set `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` if the hosts were enrolled into Fleet MDM using an IdP (Identity Provider). You can also use any of the [Apple profile variables](https://support.apple.com/en-my/guide/deployment/dep04666af94/1/web/1.0) to uniquely identify your device. Example profile: @@ -132,7 +132,7 @@ A common use case for SCEP is connecting devices to a corporate WiFi network. Th ## Assumptions and limitations -* NDES SCEP proxy is currently only supported for macOS devices via Apple config profiles. Support for DDM (Declarative Device Management) is coming soon, as is support for iOS, iPadOS, Windows, and Linux. +* NDES SCEP proxy is currently supported for macOS devices via Apple config profiles. Support for DDM (Declarative Device Management) is coming soon, as is support for iOS, iPadOS, Windows, and Linux. * Certificate renewal is coming soon. * Fleet server assumes a one-time challenge password expiration time of 60 minutes. From 9b5e3c167a1a8093cdbee0dde4b096be52bdfda0 Mon Sep 17 00:00:00 2001 From: Victor Lyuboslavsky Date: Thu, 31 Oct 2024 10:24:54 -0500 Subject: [PATCH 7/7] Update articles/ndes-scep-proxy.md Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com> --- articles/ndes-scep-proxy.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/articles/ndes-scep-proxy.md b/articles/ndes-scep-proxy.md index 7f547711c2df..5e5f60d564d8 100644 --- a/articles/ndes-scep-proxy.md +++ b/articles/ndes-scep-proxy.md @@ -140,9 +140,9 @@ A common use case for SCEP is connecting devices to a corporate WiFi network. Th Fleet's NDES SCEP proxy feature allows your devices to receive certificates from your certificate authority's NDES service. This feature simplifies managing certificates on your devices and enables a secure and efficient way to connect them to your corporate network. - + - +