From cefd60d7cfc9816f300090d7c7f72b34babc4782 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Wed, 18 Aug 2021 11:38:52 +0500 Subject: [PATCH 001/109] Update hello-hybrid-aadj-sso-cert.md --- .../hello-for-business/hello-hybrid-aadj-sso-cert.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md index b8ce7af3da..2a7ae63ab9 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md @@ -200,9 +200,10 @@ Sign-in to the issuing certificate authority or management workstations with _Do 5. On the **Subject** tab, select **Supply in the request**. 6. On the **Cryptography** tab, validate the **Minimum key size** is **2048**. 7. On the **Security** tab, click **Add**. -8. Type **NDES server** in the **Enter the object names to select** text box and click **OK**. -9. Select **NDES server** from the **Group or users names** list. In the **Permissions for** section, select the **Allow** check box for the **Enroll** permission. Clear the **Allow** check box for the **Enroll** and **Autoenroll** permissions for all other items in the **Group or users names** list if the check boxes are not already cleared. Click **OK**. -10. Click on the **Apply** to save changes and close the console. +8. Select **Object Types**, then, in the appeared window, choose **Computers** and click **OK** +9. Type **NDES server** in the **Enter the object names to select** text box and click **OK**. +10. Select **NDES server** from the **Group or users names** list. In the **Permissions for** section, select the **Allow** check box for the **Enroll** permission. Clear the **Allow** check box for the **Enroll** and **Autoenroll** permissions for all other items in the **Group or users names** list if the check boxes are not already cleared. Click **OK**. +11. Click on the **Apply** to save changes and close the console. ### Create an Azure AD joined Windows Hello for Business authentication certificate template During Windows Hello for Business provisioning, Windows 10 requests an authentication certificate from Microsoft Intune, which requests the authentication certificate on behalf of the user. This task configures the Windows Hello for Business authentication certificate template. You use the name of the certificate template when configuring the NDES Server. From 731d2d151e9bef92702af7f5a1d1eea84ce3e373 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Wed, 18 Aug 2021 15:11:18 +0500 Subject: [PATCH 002/109] Update windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-aadj-sso-cert.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md index 2a7ae63ab9..f40d2342c4 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md @@ -200,7 +200,7 @@ Sign-in to the issuing certificate authority or management workstations with _Do 5. On the **Subject** tab, select **Supply in the request**. 6. On the **Cryptography** tab, validate the **Minimum key size** is **2048**. 7. On the **Security** tab, click **Add**. -8. Select **Object Types**, then, in the appeared window, choose **Computers** and click **OK** +8. Select **Object Types**, then, in the window that appears, choose **Computers** and click **OK**. 9. Type **NDES server** in the **Enter the object names to select** text box and click **OK**. 10. Select **NDES server** from the **Group or users names** list. In the **Permissions for** section, select the **Allow** check box for the **Enroll** permission. Clear the **Allow** check box for the **Enroll** and **Autoenroll** permissions for all other items in the **Group or users names** list if the check boxes are not already cleared. Click **OK**. 11. Click on the **Apply** to save changes and close the console. From 6b2d7ef2092d81cd8debde881a5ba0491b7f7105 Mon Sep 17 00:00:00 2001 From: Nick White <104782157+nicholasswhite@users.noreply.github.com> Date: Fri, 17 Jun 2022 15:32:57 -0400 Subject: [PATCH 003/109] fix MicrosoftDocs/windows-itpro-docs#7147 --- .../access-control/local-accounts.md | 87 ++++++++++--------- 1 file changed, 44 insertions(+), 43 deletions(-) diff --git a/windows/security/identity-protection/access-control/local-accounts.md b/windows/security/identity-protection/access-control/local-accounts.md index 655ef0f5b4..bcbb8ba3a5 100644 --- a/windows/security/identity-protection/access-control/local-accounts.md +++ b/windows/security/identity-protection/access-control/local-accounts.md @@ -14,7 +14,7 @@ ms.collection: - highpri ms.topic: article ms.localizationpriority: medium -ms.date: 02/28/2019 +ms.date: 06/17/2022 --- # Local Accounts @@ -25,13 +25,13 @@ ms.date: 02/28/2019 - Windows Server 2019 - Windows Server 2016 -This reference topic for IT professionals describes the default local user accounts for servers, including how to manage these built-in accounts on a member or standalone server. +This reference article for IT professionals describes the default local user accounts for servers, including how to manage these built-in accounts on a member or standalone server. ## About local user accounts Local user accounts are stored locally on the server. These accounts can be assigned rights and permissions on a particular server, but on that server only. Local user accounts are security principals that are used to secure and manage access to the resources on a standalone or member server for services or users. -This topic describes the following: +This article describes the following: - [Default local user accounts](#sec-default-accounts) @@ -61,9 +61,9 @@ For information about security principals, see [Security Principals](security-pr The default local user accounts are built-in accounts that are created automatically when you install Windows. -After Windows is installed, the default local user accounts cannot be removed or deleted. In addition, default local user accounts do not provide access to network resources. +After Windows is installed, the default local user accounts can't be removed or deleted. In addition, default local user accounts don't provide access to network resources. -Default local user accounts are used to manage access to the local server’s resources based on the rights and permissions that are assigned to the account. The default local user accounts, and the local user accounts that you create, are located in the Users folder. The Users folder is located in the Local Users and Groups folder in the local Computer Management Microsoft Management Console (MMC). Computer Management is a collection of administrative tools that you can use to manage a single local or remote computer. For more information, see [How to manage local accounts](#sec-manage-accounts) later in this topic. +Default local user accounts are used to manage access to the local server’s resources based on the rights and permissions that are assigned to the account. The default local user accounts, and the local user accounts that you create, are located in the Users folder. The Users folder is located in the Local Users and Groups folder in the local Computer Management Microsoft Management Console (MMC). Computer Management is a collection of administrative tools that you can use to manage a single local or remote computer. For more information, see [How to manage local accounts](#sec-manage-accounts) later in this article. Default local user accounts are described in the following sections. @@ -73,23 +73,23 @@ The default local Administrator account is a user account for the system adminis The Administrator account has full control of the files, directories, services, and other resources on the local computer. The Administrator account can create other local users, assign user rights, and assign permissions. The Administrator account can take control of local resources at any time simply by changing the user rights and permissions. -The default Administrator account cannot be deleted or locked out, but it can be renamed or disabled. +The default Administrator account can't be deleted or locked out, but it can be renamed or disabled. From Windows 10, Windows 11 and Windows Server 2016, Windows setup disables the built-in Administrator account and creates another local account that is a member of the Administrators group. Members of the Administrators groups can run apps with elevated permissions without using the **Run as Administrator** option. Fast User Switching is more secure than using Runas or different-user elevation. **Account group membership** -By default, the Administrator account is installed as a member of the Administrators group on the server. It is a best practice to limit the number of users in the Administrators group because members of the Administrators group on a local server have Full Control permissions on that computer. +By default, the Administrator account is installed as a member of the Administrators group on the server. It's a best practice to limit the number of users in the Administrators group because members of the Administrators group on a local server have Full Control permissions on that computer. -The Administrator account cannot be deleted or removed from the Administrators group, but it can be renamed. +The Administrator account can't be deleted or removed from the Administrators group, but it can be renamed. **Security considerations** -Because the Administrator account is known to exist on many versions of the Windows operating system, it is a best practice to disable the Administrator account when possible to make it more difficult for malicious users to gain access to the server or client computer. +Because the Administrator account is known to exist on many versions of the Windows operating system, it's a best practice to disable the Administrator account when possible to make it more difficult for malicious users to gain access to the server or client computer. You can rename the Administrator account. However, a renamed Administrator account continues to use the same automatically assigned security identifier (SID), which can be discovered by malicious users. For more information about how to rename or disable a user account, see [Disable or activate a local user account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc732112(v=ws.11)) and [Rename a local user account](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc725595(v=ws.11)). -As a security best practice, use your local (non-Administrator) account to sign in and then use **Run as administrator** to accomplish tasks that require a higher level of rights than a standard user account. Do not use the Administrator account to sign in to your computer unless it is entirely necessary. For more information, see [Run a program with administrative credentials](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc732200(v=ws.11)). +As a security best practice, use your local (non-Administrator) account to sign in and then use **Run as administrator** to accomplish tasks that require a higher level of rights than a standard user account. Don't use the Administrator account to sign in to your computer unless it's entirely necessary. For more information, see [Run a program with administrative credentials](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc732200(v=ws.11)). In comparison, on the Windows client operating system, a user with a local user account that has Administrator rights is considered the system administrator of the client computer. The first local user account that is created during installation is placed in the local Administrators group. However, when multiple users run as local administrators, the IT staff has no control over these users or their client computers. @@ -103,7 +103,7 @@ In this case, Group Policy can be used to enable secure settings that can contro ### Guest account -The Guest account is disabled by default on installation. The Guest account lets occasional or one-time users, who do not have an account on the computer, temporarily sign in to the local server or client computer with limited user rights. By default, the Guest account has a blank password. Because the Guest account can provide anonymous access, it is a security risk. For this reason, it is a best practice to leave the Guest account disabled, unless its use is entirely necessary. +The Guest account is disabled by default on installation. The Guest account lets occasional or one-time users, who don't have an account on the computer, temporarily sign in to the local server or client computer with limited user rights. By default, the Guest account has a blank password. Because the Guest account can provide anonymous access, it's a security risk. For this reason, it's a best practice to leave the Guest account disabled, unless its use is entirely necessary. **Account group membership** @@ -111,26 +111,26 @@ By default, the Guest account is the only member of the default Guests group (SI **Security considerations** -When enabling the Guest account, only grant limited rights and permissions. For security reasons, the Guest account should not be used over the network and made accessible to other computers. +When enabling the Guest account, only grant limited rights and permissions. For security reasons, the Guest account shouldn't be used over the network and made accessible to other computers. -In addition, the guest user in the Guest account should not be able to view the event logs. After the Guest account is enabled, it is a best practice to monitor the Guest account frequently to ensure that other users cannot use services and other resources, such as resources that were unintentionally left available by a previous user. +In addition, the guest user in the Guest account shouldn't be able to view the event logs. After the Guest account is enabled, it's a best practice to monitor the Guest account frequently to ensure that other users can't use services and other resources. This includes resources that were unintentionally left available by a previous user. ## HelpAssistant account (installed with a Remote Assistance session) The HelpAssistant account is a default local account that is enabled when a Remote Assistance session is run. This account is automatically disabled when no Remote Assistance requests are pending. -HelpAssistant is the primary account that is used to establish a Remote Assistance session. The Remote Assistance session is used to connect to another computer running the Windows operating system, and it is initiated by invitation. For solicited remote assistance, a user sends an invitation from their computer, through e-mail or as a file, to a person who can provide assistance. After the user’s invitation for a Remote Assistance session is accepted, the default HelpAssistant account is automatically created to give the person who provides assistance limited access to the computer. The HelpAssistant account is managed by the Remote Desktop Help Session Manager service. +HelpAssistant is the primary account that is used to establish a Remote Assistance session. The Remote Assistance session is used to connect to another computer running the Windows operating system, and it's initiated by invitation. For solicited remote assistance, a user sends an invitation from their computer, through e-mail or as a file, to a person who can provide assistance. After the users invitation for a Remote Assistance session is accepted, the default HelpAssistant account is automatically created to give the person who provides assistance limited access to the computer. The HelpAssistant account is managed by the Remote Desktop Help Session Manager service. **Security considerations** The SIDs that pertain to the default HelpAssistant account include: -- SID: S-1-5-<domain>-13, display name Terminal Server User. This group includes all users who sign in to a server with Remote Desktop Services enabled. Note that, in Windows Server 2008, Remote Desktop Services are called Terminal Services. +- SID: S-1-5-<domain>-13, display name Terminal Server User. This group includes all users who sign in to a server with Remote Desktop Services enabled. Note: In Windows Server 2008, Remote Desktop Services are called Terminal Services. - SID: S-1-5-<domain>-14, display name Remote Interactive Logon. This group includes all users who connect to the computer by using a remote desktop connection. This group is a subset of the Interactive group. Access tokens that contain the Remote Interactive Logon SID also contain the Interactive SID. -For the Windows Server operating system, Remote Assistance is an optional component that is not installed by default. You must install Remote Assistance before it can be used. +For the Windows Server operating system, Remote Assistance is an optional component that isn't installed by default. You must install Remote Assistance before it can be used. For details about the HelpAssistant account attributes, see the following table. @@ -144,14 +144,14 @@ For details about the HelpAssistant account attributes, see the following table. |Default members|None| |Default member of|Domain Guests

Guests| |Protected by ADMINSDHOLDER?|No| -|Safe to move out of default container?|Can be moved out, but we do not recommend it.| +|Safe to move out of default container?|Can be moved out, but we don't recommend it.| |Safe to delegate management of this group to non-Service admins?|No| ### DefaultAccount The DefaultAccount, also known as the Default System Managed Account (DSMA), is a built-in account introduced in Windows 10 version 1607 and Windows Server 2016. The DSMA is a well-known user account type. -It is a user neutral account that can be used to run processes that are either multi-user aware or user-agnostic. +It's a user neutral account that can be used to run processes that are either multi-user aware or user-agnostic. The DSMA is disabled by default on the desktop SKUs (full windows SKUs) and WS 2016 with the Desktop. The DSMA has a well-known RID of 503. The security identifier (SID) of the DSMA will thus have a well-known SID in the following format: S-1-5-21-\-503 @@ -171,24 +171,24 @@ Today, Xbox automatically signs in as Guest account and all apps run in this con All the apps are multi-user-aware and respond to events fired by user manager. The apps run as the Guest account. -Similarly, Phone auto logs in as a “DefApps” account which is akin to the standard user account in Windows but with a few extra privileges. Brokers, some services and apps run as this account. +Similarly, Phone auto logs in as a “DefApps” account, which is akin to the standard user account in Windows but with a few extra privileges. Brokers, some services and apps run as this account. In the converged user model, the multi-user-aware apps and multi-user-aware brokers will need to run in a context different from that of the users. For this purpose, the system creates DSMA. #### How the DefaultAccount gets created on domain controllers -If the domain was created with domain controllers that run Windows Server 2016, the DefaultAccount will exist on all domain controllers in the domain. -If the domain was created with domain controllers that run an earlier version of Windows Server, the DefaultAccount will be created after the PDC Emulator role is transferred to a domain controller that runs Windows Server 2016. The DefaultAccount will then be replicated to all other domain controllers in the domain. +If the domain was created with domain controllers running Windows Server 2016, the DefaultAccount will exist on all domain controllers in the domain. +If the domain was created with domain controllers running an earlier version of Windows Server, the DefaultAccount will be created after the PDC Emulator role is transferred to a domain controller that runs Windows Server 2016. The DefaultAccount will then be replicated to all other domain controllers in the domain. #### Recommendations for managing the Default Account (DSMA) -Microsoft does not recommend changing the default configuration, where the account is disabled. There is no security risk with having the account in the disabled state. Changing the default configuration could hinder future scenarios that rely on this account. +Microsoft doesn't recommend changing the default configuration, where the account is disabled. There's no security risk with having the account in the disabled state. Changing the default configuration could hinder future scenarios that rely on this account. ## Default local system accounts ### SYSTEM -The SYSTEM account is used by the operating system and by services that run under Windows. There are many services and processes in the Windows operating system that need the capability to sign in internally, such as during a Windows installation. The SYSTEM account was designed for that purpose, and Windows manages the SYSTEM account’s user rights. It is an internal account that does not show up in User Manager, and it cannot be added to any groups. +The SYSTEM account is used by the operating system and by services running under Windows. There are many services and processes in the Windows operating system that need the capability to sign in internally, such as during a Windows installation. The SYSTEM account was designed for that purpose, and Windows manages the SYSTEM account’s user rights. It's an internal account that doesn't show up in User Manager, and it can't be added to any groups. On the other hand, the SYSTEM account does appear on an NTFS file system volume in File Manager in the **Permissions** portion of the **Security** menu. By default, the SYSTEM account is granted Full Control permissions to all files on an NTFS volume. Here the SYSTEM account has the same functional rights and permissions as the Administrator account. @@ -204,22 +204,22 @@ The LOCAL SERVICE account is a predefined local account used by the service cont ## How to manage local user accounts -The default local user accounts, and the local user accounts that you create, are located in the Users folder. The Users folder is located in Local Users and Groups. For more information about creating and managing local user accounts, see [Manage Local Users](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731899(v=ws.11)). +The default local user accounts, and the local user accounts you create, are located in the Users folder. The Users folder is located in Local Users and Groups. For more information about creating and managing local user accounts, see [Manage Local Users](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731899(v=ws.11)). -You can use Local Users and Groups to assign rights and permissions on the local server, and that server only, to limit the ability of local users and groups to perform certain actions. A right authorizes a user to perform certain actions on a server, such as backing up files and folders or shutting down a server. An access permission is a rule that is associated with an object, usually a file, folder, or printer. It regulates which users can have access to an object on the server and in what manner. +You can use Local Users and Groups to assign rights and permissions on only the local server to limit the ability of local users and groups to perform certain actions. A right authorizes a user to perform certain actions on a server, such as backing up files and folders or shutting down a server. An access permission is a rule that is associated with an object, usually a file, folder, or printer. It regulates which users can have access to an object on the server and in what manner. -You cannot use Local Users and Groups on a domain controller. However, you can use Local Users and Groups on a domain controller to target remote computers that are not domain controllers on the network. +You can't use Local Users and Groups on a domain controller. However, you can use Local Users and Groups on a domain controller to target remote computers that aren't domain controllers on the network. > [!NOTE] > You use Active Directory Users and Computers to manage users and groups in Active Directory. -You can also manage local users by using NET.EXE USER and manage local groups by using NET.EXE LOCALGROUP, or by using a variety of PowerShell cmdlets and other scripting technologies. +You can also manage local users by using NET.EXE USER and manage local groups by using NET.EXE LOCALGROUP, or by using various PowerShell cmdlets and other scripting technologies. ### Restrict and protect local accounts with administrative rights -An administrator can use a number of approaches to prevent malicious users from using stolen credentials, such as a stolen password or password hash, for a local account on one computer from being used to authenticate on another computer with administrative rights; this is also called "lateral movement". +An administrator can use many approaches to prevent malicious users from using stolen credentials such as a stolen password or password hash, for a local account on one computer from being used to authenticate on another computer with administrative rights. This is also called "lateral movement". -The simplest approach is to sign in to your computer with a standard user account, instead of using the Administrator account for tasks, for example, to browse the Internet, send email, or use a word processor. When you want to perform an administrative task, for example, to install a new program or to change a setting that affects other users, you don't have to switch to an Administrator account. You can use User Account Control (UAC) to prompt you for permission or an administrator password before performing the task, as described in the next section. +The simplest approach is to sign in to your computer with a standard user account, instead of using the Administrator account for tasks. For example, use a standard account to browse the Internet, send email, or use a word processor. When you want to perform administrative tasks such as installing a new program or changing a setting that affects other users, you don't have to switch to an Administrator account. You can use User Account Control (UAC) to prompt you for permission or an administrator password before performing the task, as described in the next section. The other approaches that can be used to restrict and protect user accounts with administrative rights include: @@ -244,7 +244,7 @@ UAC makes it possible for an account with administrative rights to be treated as In addition, UAC can require administrators to specifically approve applications that make system-wide changes before those applications are granted permission to run, even in the administrator's user session. -For example, a default feature of UAC is shown when a local account signs in from a remote computer by using Network logon (for example, by using NET.EXE USE). In this instance, it is issued a standard user token with no administrative rights, but without the ability to request or receive elevation. Consequently, local accounts that sign in by using Network logon cannot access administrative shares such as C$, or ADMIN$, or perform any remote administration. +For example, a default feature of UAC is shown when a local account signs in from a remote computer by using Network logon (for example, by using NET.EXE USE). In this instance, it's issued a standard user token with no administrative rights, but without the ability to request or receive elevation. Consequently, local accounts that sign in by using Network logon can't access administrative shares such as C$, or ADMIN$, or perform any remote administration. For more information about UAC, see [User Account Control](/windows/access-protection/user-account-control/user-account-control-overview). @@ -253,7 +253,8 @@ The following table shows the Group Policy and registry settings that are used t |No.|Setting|Detailed Description| |--- |--- |--- | ||Policy location|Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options| -|1|Policy name|[User Account Control: Run all administrators in Admin Approval Mode](/windows/device-security/security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode)| + +|1|Policy name|[User Account Control: Admin Approval Mode for the Built-in Administrator account](/windows/security/threat-protection/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account)| ||Policy setting|Enabled| |2|Policy location|Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options| ||Policy name|[User Account Control: Run all administrators in Admin Approval Mode](/windows/device-security/security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode)| @@ -285,7 +286,7 @@ The following table shows the Group Policy and registry settings that are used t ![local accounts 3.](images/localaccounts-proc1-sample3.png) -6. Ensure that UAC is enabled and that UAC restrictions apply to the default Administrator account by doing the following: +6. Ensure that UAC is enabled and that UAC restrictions apply to the default Administrator account by following these steps: 1. Navigate to the Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\, and > **Security Options**. @@ -293,7 +294,7 @@ The following table shows the Group Policy and registry settings that are used t 3. Double-click **User Account Control: Admin Approval Mode for the Built-in Administrator account** > **Enabled** > **OK**. -7. Ensure that the local account restrictions are applied to network interfaces by doing the following: +7. Ensure that the local account restrictions are applied to network interfaces by following these steps: 1. Navigate to Computer Configuration\\Preferences and Windows Settings, and > **Registry**. @@ -305,7 +306,7 @@ The following table shows the Group Policy and registry settings that are used t 4. Ensure that the **Hive** box is set to **HKEY\_LOCAL\_MACHINE**. - 5. Click (**…**), browse to the following location for **Key Path** > **Select** for: **SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System**. + 5. Select (**…**), browse to the following location for **Key Path** > **Select** for: **SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System**. 6. In the **Value name** area, type **LocalAccountTokenFilterPolicy**. @@ -325,7 +326,7 @@ The following table shows the Group Policy and registry settings that are used t ![local accounts 6.](images/localaccounts-proc1-sample6.png) - 3. Select the GPO that you just created, and > **OK**. + 3. Select the GPO that you created, and > **OK**. 9. Test the functionality of enterprise applications on the workstations in that first OU and resolve any issues caused by the new policy. @@ -335,7 +336,7 @@ The following table shows the Group Policy and registry settings that are used t ### Deny network logon to all local Administrator accounts -Denying local accounts the ability to perform network logons can help prevent a local account password hash from being reused in a malicious attack. This procedure helps to prevent lateral movement by ensuring that the credentials for local accounts that are stolen from a compromised operating system cannot be used to compromise additional computers that use the same credentials. +Denying local accounts the ability to perform network logons can help prevent a local account password hash from being reused in a malicious attack. This procedure helps to prevent lateral movement by ensuring that stolen credentials for local accounts from a compromised operating system can't be used to compromise other computers that use the same credentials. > [!NOTE] > To perform this procedure, you must first identify the name of the local, default Administrator account, which might not be the default user name "Administrator", and any other accounts that are members of the local Administrators group. @@ -361,7 +362,7 @@ The following table shows the Group Policy settings that are used to deny networ 3. In the console tree, right-click **Group Policy Objects**, and > **New**. -4. In the **New GPO** dialog box, type <**gpo\_name**>, and then > **OK** where *gpo\_name* is the name of the new GPO indicates that it is being used to restrict the local administrative accounts from interactively signing in to the computer. +4. In the **New GPO** dialog box, type <**gpo\_name**>, and then > **OK** where *gpo\_name* is the name of the new GPO indicates that it's being used to restrict the local administrative accounts from interactively signing in to the computer. ![local accounts 7.](images/localaccounts-proc2-sample1.png) @@ -375,15 +376,15 @@ The following table shows the Group Policy settings that are used to deny networ 2. Double-click **Deny access to this computer from the network**. - 3. Click **Add User or Group**, type **Local account and member of Administrators group**, and > **OK**. + 3. Select **Add User or Group**, type **Local account and member of Administrators group**, and > **OK**. 7. Configure the user rights to deny Remote Desktop (Remote Interactive) logons for administrative local accounts as follows: - 1. Navigate to Computer Configuration\\Policies\\Windows Settings and Local Policies, and then click **User Rights Assignment**. + 1. Navigate to Computer Configuration\\Policies\\Windows Settings and Local Policies, and then select **User Rights Assignment**. 2. Double-click **Deny log on through Remote Desktop Services**. - 3. Click **Add User or Group**, type **Local account and member of Administrators group**, and > **OK**. + 3. Select **Add User or Group**, type **Local account and member of Administrators group**, and > **OK**. 8. Link the GPO to the first **Workstations** OU as follows: @@ -391,7 +392,7 @@ The following table shows the Group Policy settings that are used to deny networ 2. Right-click the **Workstations** OU, and > **Link an existing GPO**. - 3. Select the GPO that you just created, and > **OK**. + 3. Select the GPO that you created, and > **OK**. 9. Test the functionality of enterprise applications on the workstations in that first OU and resolve any issues caused by the new policy. @@ -405,9 +406,9 @@ The following table shows the Group Policy settings that are used to deny networ ### Create unique passwords for local accounts with administrative rights -Passwords should be unique per individual account. While this is generally true for individual user accounts, many enterprises have identical passwords for common local accounts, such as the default Administrator account. This also occurs when the same passwords are used for local accounts during operating system deployments. +Passwords should be unique per individual account. While it's true for individual user accounts, many enterprises have identical passwords for common local accounts, such as the default Administrator account. This also occurs when the same passwords are used for local accounts during operating system deployments. -Passwords that are left unchanged or changed synchronously to keep them identical add a significant risk for organizations. Randomizing the passwords mitigates "pass-the-hash" attacks by using different passwords for local accounts, which hampers the ability of malicious users to use password hashes of those accounts to compromise other computers. +Passwords that are left unchanged or changed synchronously to keep them identical add a significant risk for organizations. Randomizing the passwords mitigates "pass-the-hash" attacks by using different passwords for local accounts, which hamper the ability of malicious users to use password hashes of those accounts to compromise other computers. Passwords can be randomized by: From 21dc3f138bbe7c1d7fd87beb029408a2d61436f2 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Mon, 20 Jun 2022 17:28:48 +0530 Subject: [PATCH 004/109] Acrolinx Enhancement Effort --- .../threat-protection/auditing/event-5070.md | 6 ++--- .../threat-protection/auditing/event-5136.md | 22 +++++++++---------- .../threat-protection/auditing/event-5137.md | 14 ++++++------ .../threat-protection/auditing/event-5138.md | 16 +++++++------- .../threat-protection/auditing/event-5139.md | 14 ++++++------ .../threat-protection/auditing/event-5140.md | 12 +++++----- .../threat-protection/auditing/event-5141.md | 14 ++++++------ .../threat-protection/auditing/event-5143.md | 20 ++++++++--------- 8 files changed, 59 insertions(+), 59 deletions(-) diff --git a/windows/security/threat-protection/auditing/event-5070.md b/windows/security/threat-protection/auditing/event-5070.md index 5763a4dba1..f21b182de2 100644 --- a/windows/security/threat-protection/auditing/event-5070.md +++ b/windows/security/threat-protection/auditing/event-5070.md @@ -17,7 +17,7 @@ ms.technology: windows-sec # 5070(S, F): A cryptographic function property modification was attempted. -This event generates in [BCryptSetContextFunctionProperty](/windows/win32/api/bcrypt/nf-bcrypt-bcryptsetcontextfunctionproperty)() function. This is a Cryptographic Next Generation (CNG) function. +This event generates in [BCryptSetContextFunctionProperty](/windows/win32/api/bcrypt/nf-bcrypt-bcryptsetcontextfunctionproperty)() function. This function is a Cryptographic Next Generation (CNG) function. This event generates when named property for a cryptographic function in an existing CNG context was updated. @@ -27,9 +27,9 @@ For more information about Cryptographic Next Generation (CNG) visit these pages - -This event is mainly used for Cryptographic Next Generation (CNG) troubleshooting. +This event is used for Cryptographic Next Generation (CNG) troubleshooting. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit Other Policy Change Events](audit-other-policy-change-events.md) diff --git a/windows/security/threat-protection/auditing/event-5136.md b/windows/security/threat-protection/auditing/event-5136.md index 2d8d45b93a..26b6d241f5 100644 --- a/windows/security/threat-protection/auditing/event-5136.md +++ b/windows/security/threat-protection/auditing/event-5136.md @@ -27,7 +27,7 @@ This event generates every time an Active Directory object is modified. To generate this event, the modified object must have an appropriate entry in [SACL](/windows/win32/secauthz/access-control-lists): the “**Write”** action auditing for specific attributes. -For a change operation you will typically see two 5136 events for one action, with different **Operation\\Type** fields: “Value Deleted” and then “Value Added”. “Value Deleted” event typically contains previous value and “Value Added” event contains new value. +For a change operation, you'll typically see two 5136 events for one action, with different **Operation\\Type** fields: “Value Deleted” and then “Value Added”. “Value Deleted” event typically contains previous value and “Value Added” event contains new value. > **Note**  For recommendations, see [Security Monitoring Recommendations](#security-monitoring-recommendations) for this event. @@ -82,13 +82,13 @@ For a change operation you will typically see two 5136 events for one action, wi **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested the “modify object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested the “modify object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested the “modify object” operation. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -142,13 +142,13 @@ For a change operation you will typically see two 5136 events for one action, wi - We have this GUID to search for: a6b34ab5-551b-4626-b8ee-2b36b3ee6672 - - Take first 3 sections a6b34ab5-551b-4626. + - Take first three sections a6b34ab5-551b-4626. - - For each of these 3 sections you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 + - For each of these three sections, you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 - - Add the last 2 sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 + - Add the last two sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 - - Delete - : b54ab3a61b552646b8ee2b36b3ee6672 + - Delete: b54ab3a61b552646b8ee2b36b3ee6672 - Divide bytes with backslashes: \\b5\\4a\\b3\\a6\\1b\\55\\26\\46\\b8\\ee\\2b\\36\\b3\\ee\\66\\72 @@ -180,7 +180,7 @@ For a change operation you will typically see two 5136 events for one action, wi > **Note**  [LDAP Display Name](/windows/win32/adschema/a-ldapdisplayname) is the name used by LDAP clients, such as the ADSI LDAP provider, to read and write the attribute by using the LDAP protocol. -- **Syntax (OID)** \[Type = UnicodeString\]**:** The syntax for an attribute defines the storage representation, byte ordering, and matching rules for comparisons of property types. Whether the attribute value must be a string, a number, or a unit of time is also defined. Every attribute of every object is associated with exactly one syntax. The syntaxes are not represented as objects in the schema, but they are programmed to be understood by Active Directory. The allowable syntaxes in Active Directory are predefined. +- **Syntax (OID)** \[Type = UnicodeString\]**:** The syntax for an attribute defines the storage representation, byte ordering, and matching rules for comparisons of property types. Whether the attribute value must be a string, a number, or a unit of time is also defined. Every attribute of every object is associated with exactly one syntax. The syntaxes aren't represented as objects in the schema, but they're programmed to be understood by Active Directory. The allowable syntaxes in Active Directory are predefined. | OID | Syntax Name | Description | |----------|--------------------------------------------|----------------------------------------------------------| @@ -189,7 +189,7 @@ For a change operation you will typically see two 5136 events for one action, wi | 2.5.5.2 | String(Object-Identifier) | The object identifier. | | 2.5.5.3 | Case-Sensitive String | General String. | | 2.5.5.4 | CaseIgnoreString(Teletex) | Differentiates uppercase and lowercase. | -| 2.5.5.5 | String(Printable), String(IA5) | Teletex. Does not differentiate uppercase and lowercase. | +| 2.5.5.5 | String(Printable), String(IA5) | Teletex. Doesn't differentiate uppercase and lowercase. | | 2.5.5.6 | String(Numeric) | Printable string or IA5-String. | | 2.5.5.7 | Object(DN-Binary) | Both character sets are case-sensitive. | | 2.5.5.8 | Boolean | A sequence of digits. | @@ -205,7 +205,7 @@ For a change operation you will typically see two 5136 events for one action, wi > Table 10. LDAP Attribute Syntax OIDs. -- **Value** \[Type = UnicodeString\]: the value which was added or deleted, depending on the **Operation\\Type** field. +- **Value** \[Type = UnicodeString\]: the value that was added or deleted, depending on the **Operation\\Type** field. **Operation:** @@ -235,4 +235,4 @@ For 5136(S): A directory service object was modified. - If you need to monitor modifications to specific Active Directory attributes, monitor for **LDAP Display Name** field with specific attribute name. -- It is better to monitor **Operation\\Type = Value Added** events, because you will see the new value of attribute. At the same time you can correlate to previous **Operation\\Type = Value Deleted** event with the same **Correlation ID** to see the previous value. \ No newline at end of file +- It's better to monitor **Operation\\Type = Value Added** events, because you'll see the new value of attribute. At the same time, you can correlate to previous **Operation\\Type = Value Deleted** event with the same **Correlation ID** to see the previous value. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5137.md b/windows/security/threat-protection/auditing/event-5137.md index f5b8f335af..0a90a9f3a9 100644 --- a/windows/security/threat-protection/auditing/event-5137.md +++ b/windows/security/threat-protection/auditing/event-5137.md @@ -76,13 +76,13 @@ This event only generates if the parent object has a particular entry in its [SA **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested the “create object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested the “create object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested the “create object” operation. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -136,13 +136,13 @@ This event only generates if the parent object has a particular entry in its [SA - We have this GUID to search for: a6b34ab5-551b-4626-b8ee-2b36b3ee6672 - - Take first 3 sections a6b34ab5-551b-4626. + - Take first three sections a6b34ab5-551b-4626. - - For each of these 3 sections you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 + - For each of these three sections, you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 - - Add the last 2 sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 + - Add the last two sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 - - Delete - : b54ab3a61b552646b8ee2b36b3ee6672 + - Delete: b54ab3a61b552646b8ee2b36b3ee6672 - Divide bytes with backslashes: \\b5\\4a\\b3\\a6\\1b\\55\\26\\46\\b8\\ee\\2b\\36\\b3\\ee\\66\\72 @@ -182,4 +182,4 @@ For 5137(S): A directory service object was created. - If you need to monitor creation of Active Directory objects with specific classes, monitor for **Class** field with specific class name. For example, we recommend that you monitor all new group policy objects creations: **groupPolicyContainer** class. -- You must set correct auditing access lists (SACLs) for specific classes within Active Directory container to get [5137](event-5137.md). There is no reason to audit all creation events for all types of Active Directory objects; find the most important locations (organizational units, folders, etc.) and monitor for creation of specific classes only (user, computer, group, etc.). \ No newline at end of file +- You must set correct auditing access lists (SACLs) for specific classes within Active Directory container to get [5137](event-5137.md). There's no reason to audit all creation events for all types of Active Directory objects; find the most important locations (organizational units, folders, etc.) and monitor for creation of specific classes only (user, computer, group, etc.). \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5138.md b/windows/security/threat-protection/auditing/event-5138.md index 93dac293aa..0757dcd92c 100644 --- a/windows/security/threat-protection/auditing/event-5138.md +++ b/windows/security/threat-protection/auditing/event-5138.md @@ -77,13 +77,13 @@ This event only generates if the container to which the Active Directory object **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested that the object be undeleted or restored. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested that the object be undeleted or restored. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** name of account that requested that the object be undeleted or restored. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -105,7 +105,7 @@ This event only generates if the container to which the Active Directory object **Object:** -- **Old DN** \[Type = UnicodeString\]: Old distinguished name of undeleted object. It will points to [Active Directory Recycle Bin](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd392261(v=ws.10)) folder, in case if it was restored from it. +- **Old DN** \[Type = UnicodeString\]: Old distinguished name of undeleted object. It will point to [Active Directory Recycle Bin](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd392261(v=ws.10)) folder, in case if it was restored from it. > **Note**  The LDAP API references an LDAP object by its **distinguished name (DN)**. A DN is a sequence of relative distinguished names (RDN) connected by commas. > @@ -139,13 +139,13 @@ This event only generates if the container to which the Active Directory object - We have this GUID to search for: a6b34ab5-551b-4626-b8ee-2b36b3ee6672 - - Take first 3 sections a6b34ab5-551b-4626. + - Take first three sections a6b34ab5-551b-4626. - - For each of these 3 sections you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 + - For each of these three sections, you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 - - Add the last 2 sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 + - Add the last two sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 - - Delete - : b54ab3a61b552646b8ee2b36b3ee6672 + - Delete: b54ab3a61b552646b8ee2b36b3ee6672 - Divide bytes with backslashes: \\b5\\4a\\b3\\a6\\1b\\55\\26\\46\\b8\\ee\\2b\\36\\b3\\ee\\66\\72 @@ -185,4 +185,4 @@ For 5138(S): A directory service object was undeleted. - If you need to monitor undelete operations (restoration) of Active Directory objects with specific classes, monitor for **Class** field with specific class name. -- It may be a good idea to monitor all undelete events, because the operation is not performed very often. Confirm that there is a reason for the object to be undeleted. \ No newline at end of file +- It may be a good idea to monitor all undelete events, because the operation isn't performed often. Confirm that there's a reason for the object to be undeleted. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5139.md b/windows/security/threat-protection/auditing/event-5139.md index 00145f3a61..eabd06efdf 100644 --- a/windows/security/threat-protection/auditing/event-5139.md +++ b/windows/security/threat-protection/auditing/event-5139.md @@ -77,13 +77,13 @@ This event only generates if the destination object has a particular entry in it **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested the “move object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested the “move object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested the “move object” operation. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -139,13 +139,13 @@ This event only generates if the destination object has a particular entry in it - We have this GUID to search for: a6b34ab5-551b-4626-b8ee-2b36b3ee6672 - - Take first 3 sections a6b34ab5-551b-4626. + - Take first three sections a6b34ab5-551b-4626. - - For each of these 3 sections you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 + - For each of these three sections, you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 - - Add the last 2 sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 + - Add the last two sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 - - Delete - : b54ab3a61b552646b8ee2b36b3ee6672 + - Delete: b54ab3a61b552646b8ee2b36b3ee6672 - Divide bytes with backslashes: \\b5\\4a\\b3\\a6\\1b\\55\\26\\46\\b8\\ee\\2b\\36\\b3\\ee\\66\\72 @@ -185,4 +185,4 @@ For 5139(S): A directory service object was moved. - If you need to monitor movement of Active Directory objects with specific classes, monitor for **Class** field with specific class name. -- You must set correct auditing access lists (SACLs) for specific classes within Active Directory container to get [5139](event-5139.md). There is no reason to audit all movement events for all types of Active Directory objects, you need to find the most important locations (organizational units, folders, etc.) and monitor for movement of specific classes only to these locations (user, computer, group, etc.). \ No newline at end of file +- You must set correct auditing access lists (SACLs) for specific classes within Active Directory container to get [5139](event-5139.md). There's no reason to audit all movement events for all types of Active Directory objects, you need to find the most important locations (organizational units, folders, etc.) and monitor for movement of specific classes only to these locations (user, computer, group, etc.). \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5140.md b/windows/security/threat-protection/auditing/event-5140.md index 067637aa9b..b5ae516ec7 100644 --- a/windows/security/threat-protection/auditing/event-5140.md +++ b/windows/security/threat-protection/auditing/event-5140.md @@ -78,13 +78,13 @@ This event generates once per session, when first access attempt was made. **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested access to network share object. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested access to network share object. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested access to network share object. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -120,7 +120,7 @@ This event generates once per session, when first access attempt was made. - ::1 or 127.0.0.1 means localhost. -- **Source Port** \[Type = UnicodeString\]: source TCP or UDP port which was used from remote or local machine to request the access. +- **Source Port** \[Type = UnicodeString\]: source TCP or UDP port that was used from remote or local machine to request the access. - 0 for local access attempts. @@ -134,7 +134,7 @@ This event generates once per session, when first access attempt was made. - **Access Mask** \[Type = HexInt32\]: the sum of hexadecimal values of requested access rights. See “Table 13. File access codes.” for different hexadecimal values for access rights. Has always “**0x1**” value for this event. -- **Accesses** \[Type = UnicodeString\]: the list of access rights which were requested by **Subject\\Security ID**. These access rights depend on **Object Type**. Has always “**ReadData (or ListDirectory)**” value for this event. +- **Accesses** \[Type = UnicodeString\]: the list of access rights that were requested by **Subject\\Security ID**. These access rights depend on **Object Type**. Has always “**ReadData (or ListDirectory)**” value for this event. ## Security Monitoring Recommendations @@ -144,9 +144,9 @@ For 5140(S, F): A network share object was accessed. - If you have high-value computers for which you need to monitor all access to all shares or specific shares (“**Share Name**”), monitor this event. For example, you could monitor share **C$** on domain controllers. -- Monitor this event if the **Network Information\\Source Address** is not from your internal IP range. +- Monitor this event if the **Network Information\\Source Address** isn't from your internal IP range. -- Monitor this event if the **Network Information\\Source Address** should not be able to connect with the specific computer (**Computer:**). +- Monitor this event if the **Network Information\\Source Address** shouldn't be able to connect with the specific computer (**Computer:**). - If you need to monitor access attempts to local shares from a specific IP address (“**Network Information\\Source Address”)**, use this event. diff --git a/windows/security/threat-protection/auditing/event-5141.md b/windows/security/threat-protection/auditing/event-5141.md index f69e095286..e63227b1ad 100644 --- a/windows/security/threat-protection/auditing/event-5141.md +++ b/windows/security/threat-protection/auditing/event-5141.md @@ -77,13 +77,13 @@ This event only generates if the deleted object has a particular entry in its [S **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested the “delete object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested the “delete object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested the “delete object” operation. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -137,13 +137,13 @@ This event only generates if the deleted object has a particular entry in its [S - We have this GUID to search for: a6b34ab5-551b-4626-b8ee-2b36b3ee6672 - - Take first 3 sections a6b34ab5-551b-4626. + - Take first three sections a6b34ab5-551b-4626. - - For each of these 3 sections you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 + - For each of these three sections, you need to change (Invert) the order of bytes, like this b54ab3a6-1b55-2646 - - Add the last 2 sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 + - Add the last two sections without transformation: b54ab3a6-1b55-2646-b8ee-2b36b3ee6672 - - Delete - : b54ab3a61b552646b8ee2b36b3ee6672 + - Delete: b54ab3a61b552646b8ee2b36b3ee6672 - Divide bytes with backslashes: \\b5\\4a\\b3\\a6\\1b\\55\\26\\46\\b8\\ee\\2b\\36\\b3\\ee\\66\\72 @@ -193,4 +193,4 @@ For 5141(S): A directory service object was deleted. - If you need to monitor deletion of Active Directory objects with specific classes, monitor for **Class** field with specific class name. For example, we recommend that you monitor for group policy objects deletions: **groupPolicyContainer** class. -- If you need to monitor deletion of specific Active Directory objects, monitor for **DN** field with specific object name. For example, if you have critical Active Directory objects which should not be deleted, monitor for their deletion. \ No newline at end of file +- If you need to monitor deletion of specific Active Directory objects, monitor for **DN** field with specific object name. For example, if you have critical Active Directory objects that shouldn't be deleted, monitor for their deletion. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5143.md b/windows/security/threat-protection/auditing/event-5143.md index 636a19a1bd..e533127f2a 100644 --- a/windows/security/threat-protection/auditing/event-5143.md +++ b/windows/security/threat-protection/auditing/event-5143.md @@ -78,13 +78,13 @@ This event generates every time network share object was modified. **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested the “modify network share object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested the “modify network share object” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested the “modify network share object” operation. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -120,9 +120,9 @@ This event generates every time network share object was modified. Advanced Sharing illustration -- **Old Remark** \[Type = UnicodeString\]: the old value of network share “**Comments:**” field. Has “**N/A**” value if it is not set. +- **Old Remark** \[Type = UnicodeString\]: the old value of network share “**Comments:**” field. Has “**N/A**” value if it isn't set. -- **New Remark** \[Type = UnicodeString\]: the new value of network share “**Comments:**” field. Has “**N/A**” value if it is not set. +- **New Remark** \[Type = UnicodeString\]: the new value of network share “**Comments:**” field. Has “**N/A**” value if it isn't set. - **Old MaxUsers** \[Type = HexInt32\]: old hexadecimal value of “**Limit the number of simultaneous user to:**” field. Has “**0xFFFFFFFF**” value if the number of connections is unlimited. @@ -155,7 +155,7 @@ This event generates every time network share object was modified. | "AU" | Authenticated users | "LG" | Local guest | | "BA" | Built-in administrators | "LS" | Local service account | | "BG" | Built-in guests | "SY" | Local system | -| "BO" | Backup operators | "NU" | Network logon user | +| "BO" | Backup operators | "NU" | Network sign-in user | | "BU" | Built-in users | "NO" | Network configuration operators | | "CA" | Certificate server administrators | "NS" | Network service account | | "CG" | Creator group | "PO" | Printer operators | @@ -167,7 +167,7 @@ This event generates every time network share object was modified. | "DU" | Domain users | "RC" | Restricted code | | "EA" | Enterprise administrators | "SA" | Schema administrators | | "ED" | Enterprise domain controllers | "SO" | Server operators | -| "WD" | Everyone | "SU" | Service logon user | +| "WD" | Everyone | "SU" | Service sign-in user | - *G*: = Primary Group. - *D*: = DACL Entries. @@ -187,7 +187,7 @@ Example: D:(A;;FA;;;WD) "P” - SDDL\_PROTECTED, Inheritance from containers that are higher in the folder hierarchy are blocked. -"AI" - SDDL\_AUTO\_INHERITED, Inheritance is allowed, assuming that "P" Is not also set. +"AI" - SDDL\_AUTO\_INHERITED, Inheritance is allowed, assuming that "P" Isn't also set. "AR" - SDDL\_AUTO\_INHERIT\_REQ, Child objects inherit permissions from this object. @@ -213,7 +213,7 @@ Example: D:(A;;FA;;;WD) "CI" - CONTAINER INHERIT: Child objects that are containers, such as directories, inherit the ACE as an explicit ACE. -"OI" - OBJECT INHERIT: Child objects that are not containers inherit the ACE as an explicit ACE. +"OI" - OBJECT INHERIT: Child objects that aren't containers inherit the ACE as an explicit ACE. "NP" - NO PROPAGATE: only immediate children inherit this ace. @@ -224,7 +224,7 @@ Example: D:(A;;FA;;;WD) "SA" - SUCCESSFUL ACCESS AUDIT "FA" - FAILED ACCESS AUDIT -- rights: A hexadecimal string which denotes the access mask or reserved value, for example: FA (File All Access), FX (File Execute), FW (File Write), etc. +- rights: A hexadecimal string that denotes the access mask or reserved value, for example: FA (File All Access), FX (File Execute), FW (File Write), etc. | Value | Description | Value | Description | |----------------------------|---------------------------------|----------------------|--------------------------| @@ -246,7 +246,7 @@ Example: D:(A;;FA;;;WD) - object\_guid: N/A - inherit\_object\_guid: N/A -- account\_sid: SID of specific security principal, or reserved value, for example: AN (Anonymous), WD (Everyone), SY (LOCAL\_SYSTEM), etc. See the table above for more details. +- account\_sid: SID of specific security principal, or reserved value, for example: AN (Anonymous), WD (Everyone), SY (LOCAL\_SYSTEM), etc. For more information, see the table above. For more information about SDDL syntax, see these articles: , . From 07b07c29209c39a2d82b64c73c0eb6600eadb7ad Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Mon, 20 Jun 2022 19:11:24 +0530 Subject: [PATCH 005/109] Acrolinx enhancement effort --- .../threat-protection/auditing/event-5145.md | 30 +++++++++---------- .../threat-protection/auditing/event-5148.md | 4 +-- 2 files changed, 17 insertions(+), 17 deletions(-) diff --git a/windows/security/threat-protection/auditing/event-5145.md b/windows/security/threat-protection/auditing/event-5145.md index 9c980ce0f3..1368fde95e 100644 --- a/windows/security/threat-protection/auditing/event-5145.md +++ b/windows/security/threat-protection/auditing/event-5145.md @@ -78,13 +78,13 @@ This event generates every time network share object (file or folder) was access **Subject:** -- **Security ID** \[Type = SID\]**:** SID of account that requested access to network share object. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. +- **Security ID** \[Type = SID\]**:** SID of account that requested access to network share object. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event. > **Note**  A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers). - **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested access to network share object. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -120,7 +120,7 @@ This event generates every time network share object (file or folder) was access - ::1 or 127.0.0.1 means localhost. -- **Source Port** \[Type = UnicodeString\]: source TCP or UDP port which was used from remote or local machine to request the access. +- **Source Port** \[Type = UnicodeString\]: source TCP or UDP port that was used from remote or local machine to request the access. - 0 for local access attempts. @@ -136,7 +136,7 @@ This event generates every time network share object (file or folder) was access - **Access Mask** \[Type = HexInt32\]: the sum of hexadecimal values of requested access rights. See “Table 13. File access codes.” for different hexadecimal values for access rights. -- **Accesses** \[Type = UnicodeString\]: the list of access rights which were requested by **Subject\\Security ID**. These access rights depend on **Object Type**. +- **Accesses** \[Type = UnicodeString\]: the list of access rights that were requested by **Subject\\Security ID**. These access rights depend on **Object Type**. ## Table of file access codes @@ -144,10 +144,10 @@ This event generates every time network share object (file or folder) was access |-----------------------------------------------------------|----------------------------|---------------| | ReadData (or ListDirectory) | 0x1,
%%4416 | **ReadData -** For a file object, the right to read the corresponding file data. For a directory object, the right to read the corresponding directory data.
**ListDirectory -** For a directory, the right to list the contents of the directory. | | WriteData (or AddFile) | 0x2,
%%4417 | **WriteData -** For a file object, the right to write data to the file. For a directory object, the right to create a file in the directory (**FILE\_ADD\_FILE**).
**AddFile -** For a directory, the right to create a file in the directory. | -| AppendData (or AddSubdirectory or CreatePipeInstance) | 0x4,
%%4418 | **AppendData -** For a file object, the right to append data to the file. (For local files, write operations will not overwrite existing data if this flag is specified without **FILE\_WRITE\_DATA**.) For a directory object, the right to create a subdirectory (**FILE\_ADD\_SUBDIRECTORY**).
**AddSubdirectory -** For a directory, the right to create a subdirectory.
**CreatePipeInstance -** For a named pipe, the right to create a pipe. | +| AppendData (or AddSubdirectory or CreatePipeInstance) | 0x4,
%%4418 | **AppendData -** For a file object, the right to append data to the file. (For local files, write operations won't overwrite existing data if this flag is specified without **FILE\_WRITE\_DATA**.) For a directory object, the right to create a subdirectory (**FILE\_ADD\_SUBDIRECTORY**).
**AddSubdirectory -** For a directory, the right to create a subdirectory.
**CreatePipeInstance -** For a named pipe, the right to create a pipe. | | ReadEA | 0x8,
%%4419 | The right to read extended file attributes. | | WriteEA | 0x10,
%%4420 | The right to write extended file attributes. | -| Execute/Traverse | 0x20,
%%4421 | **Execute** - For a native code file, the right to execute the file. This access right given to scripts may cause the script to be executable, depending on the script interpreter.
**Traverse -** For a directory, the right to traverse the directory. By default, users are assigned the **BYPASS\_TRAVERSE\_CHECKING**  [privilege](/windows/win32/secauthz/privileges), which ignores the **FILE\_TRAVERSE**  [access right](/windows/win32/secauthz/access-rights-and-access-masks). See the remarks in [File Security and Access Rights](/windows/win32/fileio/file-security-and-access-rights) for more information. | +| Execute/Traverse | 0x20,
%%4421 | **Execute** - For a native code file, the right to execute the file. This access right given to scripts may cause the script to be executable, depending on the script interpreter.
**Traverse -** For a directory, the right to traverse the directory. By default, users are assigned the **BYPASS\_TRAVERSE\_CHECKING**  [privilege](/windows/win32/secauthz/privileges), which ignores the **FILE\_TRAVERSE**  [access right](/windows/win32/secauthz/access-rights-and-access-masks). For more information, see the remarks in [File Security and Access Rights](/windows/win32/fileio/file-security-and-access-rights). | | DeleteChild | 0x40,
%%4422 | For a directory, the right to delete a directory and all the files it contains, including read-only files. | | ReadAttributes | 0x80,
%%4423 | The right to read file attributes. | | WriteAttributes | 0x100,
%%4424 | The right to write file attributes. | @@ -155,7 +155,7 @@ This event generates every time network share object (file or folder) was access | READ\_CONTROL | 0x20000,
%%1538 | The right to read the information in the object's security descriptor, not including the information in the system access control list (SACL). | | WRITE\_DAC | 0x40000,
%%1539 | The right to modify the discretionary access control list (DACL) in the object's security descriptor. | | WRITE\_OWNER | 0x80000,
%%1540 | The right to change the owner in the object's security descriptor | -| SYNCHRONIZE | 0x100000,
%%1541 | The right to use the object for synchronization. This enables a thread to wait until the object is in the signaled state. Some object types do not support this access right. | +| SYNCHRONIZE | 0x100000,
%%1541 | The right to use the object for synchronization. This right enables a thread to wait until the object is in the signaled state. Some object types don't support this access right. | | ACCESS\_SYS\_SEC | 0x1000000,
%%1542 | The ACCESS\_SYS\_SEC access right controls the ability to get or set the SACL in an object's security descriptor. | > Table 13. File access codes. @@ -193,7 +193,7 @@ REQUESTED\_ACCESS: RESULT ACE\_WHICH\_ ALLOWED\_OR\_DENIED\_ACCESS. | "AU" | Authenticated users | "LG" | Local guest | | "BA" | Built-in administrators | "LS" | Local service account | | "BG" | Built-in guests | "SY" | Local system | -| "BO" | Backup operators | "NU" | Network logon user | +| "BO" | Backup operators | "NU" | Network sign-in user | | "BU" | Built-in users | "NO" | Network configuration operators | | "CA" | Certificate server administrators | "NS" | Network service account | | "CG" | Creator group | "PO" | Printer operators | @@ -205,7 +205,7 @@ REQUESTED\_ACCESS: RESULT ACE\_WHICH\_ ALLOWED\_OR\_DENIED\_ACCESS. | "DU" | Domain users | "RC" | Restricted code | | "EA" | Enterprise administrators | "SA" | Schema administrators | | "ED" | Enterprise domain controllers | "SO" | Server operators | -| "WD" | Everyone | "SU" | Service logon user | +| "WD" | Everyone | "SU" | Service sign-in user | - *G*: = Primary Group. - *D*: = DACL Entries. @@ -225,7 +225,7 @@ Example: D:(A;;FA;;;WD) "P” - SDDL\_PROTECTED, Inheritance from containers that are higher in the folder hierarchy are blocked. -"AI" - SDDL\_AUTO\_INHERITED, Inheritance is allowed, assuming that "P" Is not also set. +"AI" - SDDL\_AUTO\_INHERITED, Inheritance is allowed, assuming that "P" Isn't also set. "AR" - SDDL\_AUTO\_INHERIT\_REQ, Child objects inherit permissions from this object. @@ -251,7 +251,7 @@ Example: D:(A;;FA;;;WD) "CI" - CONTAINER INHERIT: Child objects that are containers, such as directories, inherit the ACE as an explicit ACE. -"OI" - OBJECT INHERIT: Child objects that are not containers inherit the ACE as an explicit ACE. +"OI" - OBJECT INHERIT: Child objects that aren't containers inherit the ACE as an explicit ACE. "NP" - NO PROPAGATE: only immediate children inherit this ace. @@ -262,7 +262,7 @@ Example: D:(A;;FA;;;WD) "SA" - SUCCESSFUL ACCESS AUDIT "FA" - FAILED ACCESS AUDIT -- rights: A hexadecimal string which denotes the access mask or reserved value, for example: FA (File All Access), FX (File Execute), FW (File Write), etc. +- rights: A hexadecimal string that denotes the access mask or reserved value, for example: FA (File All Access), FX (File Execute), FW (File Write), etc. | Value | Description | Value | Description | |----------------------------|---------------------------------|----------------------|--------------------------| @@ -284,7 +284,7 @@ Example: D:(A;;FA;;;WD) - object\_guid: N/A - inherit\_object\_guid: N/A -- account\_sid: SID of specific security principal, or reserved value, for example: AN (Anonymous), WD (Everyone), SY (LOCAL\_SYSTEM), etc. See the table above for more details. +- account\_sid: SID of specific security principal, or reserved value, for example: AN (Anonymous), WD (Everyone), SY (LOCAL\_SYSTEM), etc. For more information, see the table above. For more information about SDDL syntax, see these articles: , . @@ -294,9 +294,9 @@ For 5145(S, F): A network share object was checked to see whether client can be > **Important**  For this event, also see [Appendix A: Security monitoring recommendations for many audit events](appendix-a-security-monitoring-recommendations-for-many-audit-events.md). -- Monitor this event if the **Network Information\\Source Address** is not from your internal IP range. +- Monitor this event if the **Network Information\\Source Address** isn't from your internal IP range. -- Monitor this event if the **Network Information\\Source Address** should not be able to connect with the specific computer (**Computer:**). +- Monitor this event if the **Network Information\\Source Address** shouldn't be able to connect with the specific computer (**Computer:**). - If you have critical files or folders on specific network shares, for which you need to monitor access attempts (Success and Failure), monitor for specific **Share Information\\Share Name** and **Share Information\\Relative Target Name**. diff --git a/windows/security/threat-protection/auditing/event-5148.md b/windows/security/threat-protection/auditing/event-5148.md index 094f91e5f3..d8739009b8 100644 --- a/windows/security/threat-protection/auditing/event-5148.md +++ b/windows/security/threat-protection/auditing/event-5148.md @@ -17,9 +17,9 @@ ms.technology: windows-sec # 5148(F): The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded. -In most circumstances, this event occurs very rarely. It is designed to be generated when an ICMP DoS attack starts or was detected. +In most circumstances, this event occurs rarely. It's designed to be generated when an ICMP DoS attack starts or was detected. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit Other Object Access Events](audit-other-object-access-events.md) From 2237c29387dd45d4cbcd77ba1c5afa44b1ec644e Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Tue, 21 Jun 2022 12:24:09 +0530 Subject: [PATCH 006/109] Acrolinx Enhancement Effort --- .../threat-protection/auditing/event-5149.md | 4 ++-- .../threat-protection/auditing/event-5152.md | 12 ++++++------ .../threat-protection/auditing/event-5154.md | 10 +++++----- .../threat-protection/auditing/event-5155.md | 10 +++++----- .../threat-protection/auditing/event-5156.md | 12 ++++++------ .../threat-protection/auditing/event-5157.md | 12 ++++++------ .../threat-protection/auditing/event-5158.md | 10 +++++----- .../threat-protection/auditing/event-5159.md | 6 +++--- .../threat-protection/auditing/event-5632.md | 12 ++++++------ .../threat-protection/auditing/event-6144.md | 4 ++-- .../threat-protection/auditing/event-6145.md | 6 +++--- .../threat-protection/auditing/event-6281.md | 12 ++++++------ .../threat-protection/auditing/event-6405.md | 4 ++-- .../threat-protection/auditing/event-6406.md | 4 ++-- .../threat-protection/auditing/event-6407.md | 6 +++--- .../threat-protection/auditing/event-6410.md | 8 ++++---- .../file-system-global-object-access-auditing.md | 4 ++-- ...tor-central-access-policy-and-rule-definitions.md | 2 +- .../auditing/monitor-claim-types.md | 8 ++++---- .../monitor-resource-attribute-definitions.md | 6 +++--- 20 files changed, 76 insertions(+), 76 deletions(-) diff --git a/windows/security/threat-protection/auditing/event-5149.md b/windows/security/threat-protection/auditing/event-5149.md index 3be32e2a0c..5cbafb7fe3 100644 --- a/windows/security/threat-protection/auditing/event-5149.md +++ b/windows/security/threat-protection/auditing/event-5149.md @@ -17,9 +17,9 @@ ms.technology: windows-sec # 5149(F): The DoS attack has subsided and normal processing is being resumed. -In most circumstances, this event occurs very rarely. It is designed to be generated when an ICMP DoS attack ended. +In most circumstances, this event occurs rarely. It's designed to be generated when an ICMP DoS attack ends. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit Other Object Access Events](audit-other-object-access-events.md) diff --git a/windows/security/threat-protection/auditing/event-5152.md b/windows/security/threat-protection/auditing/event-5152.md index 1e2cec8711..20bb33c8fc 100644 --- a/windows/security/threat-protection/auditing/event-5152.md +++ b/windows/security/threat-protection/auditing/event-5152.md @@ -109,7 +109,7 @@ This event is generated for every received network packet. - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]**:** port number on which application received the packet. @@ -123,7 +123,7 @@ This event is generated for every received network packet. - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Destination Port** \[Type = UnicodeString\]**:** port number that was used from remote machine to send the packet. @@ -167,20 +167,20 @@ For 5152(F): The Windows Filtering Platform blocked a packet. - If you have a pre-defined application that should be used to perform the operation that was reported by this event, monitor events with “**Application**” not equal to your defined application. -- You can monitor to see if “**Application**” is not in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). +- You can monitor to see if “**Application**” isn't in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). - If you have a pre-defined list of restricted substrings or words in application names (for example, “**mimikatz**” or “**cain.exe**”), check for these substrings in “**Application**.” - Check that **Source Address** is one of the addresses assigned to the computer. -- If the computer or device should not have access to the Internet, or contains only applications that don’t connect to the Internet, monitor for [5152](event-5152.md) events where **Destination Address** is an IP address from the Internet (not from private IP ranges). +- If the computer or device shouldn't have access to the Internet, or contains only applications that don’t connect to the Internet, monitor for [5152](event-5152.md) events where **Destination Address** is an IP address from the Internet (not from private IP ranges). - If you know that the computer should never contact or should never be contacted by certain network IP addresses, monitor for these addresses in **Destination Address**. -- If you have an allow list of IP addresses that the computer or device is expected to contact or to be contacted by, monitor for IP addresses in **“Destination Address”** that are not in the allow list. +- If you've an allowlist of IP addresses that the computer or device is expected to contact or to be contacted by, monitor for IP addresses in **“Destination Address”** that aren't in the allowlist. - If you need to monitor all inbound connections to a specific local port, monitor for [5152](event-5152.md) events with that “**Source Port**.**”** -- Monitor for all connections with a “**Protocol Number”** that is not typical for this device or computer, for example, anything other than 1, 6, or 17. +- Monitor for all connections with a “**Protocol Number”** that isn't typical for this device or computer, for example, anything other than 1, 6, or 17. - If the computer’s communication with “**Destination Address”** should always use a specific “**Destination Port**,**”** monitor for any other “**Destination Port**.” \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5154.md b/windows/security/threat-protection/auditing/event-5154.md index 4cd691deaf..4b45c0c9cd 100644 --- a/windows/security/threat-protection/auditing/event-5154.md +++ b/windows/security/threat-protection/auditing/event-5154.md @@ -95,10 +95,10 @@ This event generates every time [Windows Filtering Platform](/windows/win32/fwp/ - IPv6 Address - :: - all IP addresses in IPv6 format - +s - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]: source TCP\\UDP port number that was requested for listening by application. @@ -112,7 +112,7 @@ This event generates every time [Windows Filtering Platform](/windows/win32/fwp/ **Filter Information:** -- **Filter Run-Time ID** \[Type = UInt64\]: unique filter ID that allows application to listen on the specific port. By default Windows firewall won't prevent a port from being listened by an application and if this application doesn’t match any filters you will get value **0** in this field. +- **Filter Run-Time ID** \[Type = UInt64\]: unique filter ID that allows application to listen on the specific port. By default Windows firewall won't prevent a port from being listened by an application and if this application doesn’t match any filters you'll get value **0** in this field. To find a specific Windows Filtering Platform filter by ID, run the following command: **netsh wfp show filters**. As a result of this command, the **filters.xml** file will be generated. Open this file and find specific substring with required filter ID (**<filterId>**)**,** for example: @@ -128,7 +128,7 @@ This event generates every time [Windows Filtering Platform](/windows/win32/fwp/ For 5154(S): The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. -- If you have an “allow list” of applications that are associated with certain operating systems or server roles, and that are expected to listen on specific ports, monitor this event for **“Application Name”** and other relevant information. +- If you've an “allowlist” of applications that are associated with certain operating systems or server roles, and that are expected to listen on specific ports, monitor this event for **“Application Name”** and other relevant information. - If a certain application is allowed to listen only on specific port numbers, monitor this event for **“Application Name”** and **“Network Information\\Source Port**.**”** @@ -138,7 +138,7 @@ For 5154(S): The Windows Filtering Platform has permitted an application or serv - If you have a predefined application that should be used to perform the operation that was reported by this event, monitor events with “**Application**” not equal to your defined application. -- You can monitor to see if “**Application**” is not in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). +- You can monitor to see if “**Application**” isn't in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). - If you have a pre-defined list of restricted substrings or words in application names (for example, “**mimikatz**” or “**cain.exe**”), check for these substrings in “**Application**.” diff --git a/windows/security/threat-protection/auditing/event-5155.md b/windows/security/threat-protection/auditing/event-5155.md index b4626b59c1..06487ca949 100644 --- a/windows/security/threat-protection/auditing/event-5155.md +++ b/windows/security/threat-protection/auditing/event-5155.md @@ -17,7 +17,7 @@ ms.technology: windows-sec # 5155(F): The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. -By default Windows firewall won't prevent a port from being listened by an application. In the other word, Windows system will not generate Event 5155 by itself. +By default Windows firewall won't prevent a port from being listened by an application. In the other word, Windows system won't generate Event 5155 by itself. You can add your own filters using the WFP APIs to block listen to reproduce this event: . @@ -72,7 +72,7 @@ This event generates every time the [Windows Filtering Platform](/windows/win32/ **Application Information**: -- **Process ID** \[Type = Pointer\]: Hexadecimal Process ID (PID) of the process which was permitted to bind to the local port. The PID is a number used by the operating system to uniquely identify an active process. To see the PID for a specific process you can, for example, use Task Manager (Details tab, PID column): +- **Process ID** \[Type = Pointer\]: Hexadecimal Process ID (PID) of the process that was permitted to bind to the local port. The PID is a number used by the operating system to uniquely identify an active process. To see the PID for a specific process you can, for example, use Task Manager (Details tab, PID column): Task manager illustration @@ -100,7 +100,7 @@ This event generates every time the [Windows Filtering Platform](/windows/win32/ - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]**:** The port number used by the application. @@ -126,7 +126,7 @@ This event generates every time the [Windows Filtering Platform](/windows/win32/ **Filter Information:** -- **Filter Run-Time ID** \[Type = UInt64\]: A unique filter ID which blocks the application from binding to the port. By default, Windows firewall won't prevent a port from binding to an application, and if this application doesn’t match any filters, you will get a 0 value in this field. +- **Filter Run-Time ID** \[Type = UInt64\]: A unique filter ID that blocks the application from binding to the port. By default, Windows firewall won't prevent a port from binding to an application, and if this application doesn’t match any filters, you'll get a 0 value in this field. To find a specific Windows Filtering Platform filter by ID, you need to execute the following command: **netsh wfp show filters**. As a result of this command, a **filters.xml** file will be generated. You need to open this file and find the specific substring with the required filter ID (**<filterId>**), for example: @@ -134,7 +134,7 @@ This event generates every time the [Windows Filtering Platform](/windows/win32/ - **Layer Name** \[Type = UnicodeString\]: [Application Layer Enforcement](/windows/win32/fwp/application-layer-enforcement--ale-) layer name. -- **Layer Run-Time ID** \[Type = UInt64\]: Windows Filtering Platform layer identifier. To find a specific Windows Filtering Platform layer ID, you need to execute the following command: **netsh wfp show state**. As result of this command, a **wfpstate.xml** file will be generated. You need to open this file and find the specific substring with the required layer ID (**<layerId>**), for example: +- **Layer Run-Time ID** \[Type = UInt64\]: Windows Filtering Platform layer identifier. To find a specific Windows Filtering Platform layer ID, you need to execute the following command: **netsh wfp show state**. As a result of this command, a **wfpstate.xml** file will be generated. You need to open this file and find the specific substring with the required layer ID (**<layerId>**), for example: Wfpstate xml illustration diff --git a/windows/security/threat-protection/auditing/event-5156.md b/windows/security/threat-protection/auditing/event-5156.md index f19c968a01..4c668565fa 100644 --- a/windows/security/threat-protection/auditing/event-5156.md +++ b/windows/security/threat-protection/auditing/event-5156.md @@ -109,7 +109,7 @@ This event generates when [Windows Filtering Platform](/windows/win32/fwp/window - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]**:** port number from which the connection was initiated. @@ -123,7 +123,7 @@ This event generates when [Windows Filtering Platform](/windows/win32/fwp/window - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Destination Port** \[Type = UnicodeString\]**:** port number where the connection was received. @@ -167,20 +167,20 @@ For 5156(S): The Windows Filtering Platform has permitted a connection. - If you have a predefined application that should be used to perform the operation that was reported by this event, monitor events with “**Application**” not equal to your defined application. -- You can monitor to see if “**Application**” is not in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). +- You can monitor to see if “**Application**” isn't in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). - If you have a pre-defined list of restricted substrings or words in application names (for example, “**mimikatz**” or “**cain.exe**”), check for these substrings in “**Application**.” - Check that “**Source Address”** is one of the addresses assigned to the computer. -- If the computer or device should not have access to the Internet, or contains only applications that don’t connect to the Internet, monitor for [5156](event-5156.md) events where “**Destination Address”** is an IP address from the Internet (not from private IP ranges). +- If the computer or device shouldn't have access to the Internet, or contains only applications that don’t connect to the Internet, monitor for [5156](event-5156.md) events where “**Destination Address”** is an IP address from the Internet (not from private IP ranges). - If you know that the computer should never contact or should never be contacted by certain network IP addresses, monitor for these addresses in “**Destination Address**.**”** -- If you have an allow list of IP addresses that the computer or device is expected to contact or to be contacted by, monitor for IP addresses in “**Destination Address”** that are not in the allow list. +- If you've an allowlist of IP addresses that the computer or device is expected to contact or to be contacted by, monitor for IP addresses in “**Destination Address”** that aren't in the allowlist. - If you need to monitor all inbound connections to a specific local port, monitor for [5156](event-5156.md) events with that “**Source Port**.**”** -- Monitor for all connections with a “**Protocol Number”** that is not typical for this device or computer, for example, anything other than 1, 6, or 17. +- Monitor for all connections with a “**Protocol Number”** that isn't typical for this device or computer, for example, anything other than 1, 6, or 17. - If the computer’s communication with “**Destination Address”** should always use a specific “**Destination Port**,**”** monitor for any other “**Destination Port**.” \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5157.md b/windows/security/threat-protection/auditing/event-5157.md index e860f2729c..3569920d49 100644 --- a/windows/security/threat-protection/auditing/event-5157.md +++ b/windows/security/threat-protection/auditing/event-5157.md @@ -109,7 +109,7 @@ This event generates when [Windows Filtering Platform](/windows/win32/fwp/window - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]**:** port number on which application received the connection. @@ -123,7 +123,7 @@ This event generates when [Windows Filtering Platform](/windows/win32/fwp/window - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Destination Port** \[Type = UnicodeString\]**:** port number that was used from remote machine to initiate connection. @@ -167,20 +167,20 @@ For 5157(F): The Windows Filtering Platform has blocked a connection. - If you have a predefined application that should be used to perform the operation that was reported by this event, monitor events with “**Application**” not equal to your defined application. -- You can monitor to see if “**Application**” is not in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). +- You can monitor to see if “**Application**” isn't in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). - If you have a pre-defined list of restricted substrings or words in application names (for example, “**mimikatz**” or “**cain.exe**”), check for these substrings in “**Application**.” - Check that “**Source Address”** is one of the addresses assigned to the computer. -- If the\` computer or device should not have access to the Internet, or contains only applications that don’t connect to the Internet, monitor for [5157](event-5157.md) events where “**Destination Address”** is an IP address from the Internet (not from private IP ranges). +- If the\` computer or device shouldn't have access to the Internet, or contains only applications that don’t connect to the Internet, monitor for [5157](event-5157.md) events where “**Destination Address”** is an IP address from the Internet (not from private IP ranges). - If you know that the computer should never contact or should never be contacted by certain network IP addresses, monitor for these addresses in “**Destination Address**.**”** -- If you have an allow list of IP addresses that the computer or device is expected to contact or to be contacted by, monitor for IP addresses in “**Destination Address”** that are not in the allow list. +- If you've an allowlist of IP addresses that the computer or device is expected to contact or to be contacted by, monitor for IP addresses in “**Destination Address”** that aren't in the allowlist. - If you need to monitor all inbound connections to a specific local port, monitor for [5157](event-5157.md) events with that “**Source Port**.**”** -- Monitor for all connections with a “**Protocol Number”** that is not typical for this device or computer, for example, anything other than 1, 6, or 17. +- Monitor for all connections with a “**Protocol Number”** that isn't typical for this device or computer, for example, anything other than 1, 6, or 17. - If the computer’s communication with “**Destination Address”** should always use a specific “**Destination Port**,**”** monitor for any other “**Destination Port**.” \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5158.md b/windows/security/threat-protection/auditing/event-5158.md index f2a088807e..e2ecfbd040 100644 --- a/windows/security/threat-protection/auditing/event-5158.md +++ b/windows/security/threat-protection/auditing/event-5158.md @@ -90,7 +90,7 @@ This event generates every time [Windows Filtering Platform](/windows/win32/fwp/ **Network Information:** -- **Source Address** \[Type = UnicodeString\]**:** local IP address on which application was bind the port. +- **Source Address** \[Type = UnicodeString\]**:** local IP address on which application was bound the port. - IPv4 Address @@ -100,7 +100,7 @@ This event generates every time [Windows Filtering Platform](/windows/win32/fwp/ - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]**:** port number which application was bind. @@ -126,7 +126,7 @@ This event generates every time [Windows Filtering Platform](/windows/win32/fwp/ **Filter Information:** -- **Filter Run-Time ID** \[Type = UInt64\]: unique filter ID that allows the application to bind the port. By default, Windows firewall won't prevent a port from being bound by an application. If this application doesn’t match any filters, you will get value 0 in this field. +- **Filter Run-Time ID** \[Type = UInt64\]: unique filter ID that allows the application to bind the port. By default, Windows firewall won't prevent a port from being bound by an application. If this application doesn’t match any filters, you'll get value 0 in this field. To find a specific Windows Filtering Platform filter by ID, run the following command: **netsh wfp show filters**. As a result of this command, the **filters.xml** file will be generated. Open this file and find specific substring with required filter ID (**<filterId>**)**,** for example: @@ -144,7 +144,7 @@ For 5158(S): The Windows Filtering Platform has permitted a bind to a local port - If you have a predefined application that should be used to perform the operation that was reported by this event, monitor events with “**Application**” not equal to your defined application. -- You can monitor to see if “**Application**” is not in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). +- You can monitor to see if “**Application**” isn't in a standard folder (for example, not in **System32** or **Program Files**) or is in a restricted folder (for example, **Temporary Internet Files**). - If you have a pre-defined list of restricted substrings or words in application names (for example, “**mimikatz**” or “**cain.exe**”), check for these substrings in “**Application**.” @@ -152,6 +152,6 @@ For 5158(S): The Windows Filtering Platform has permitted a bind to a local port - If you need to monitor all actions with a specific local port, monitor for [5158](event-5158.md) events with that “**Source Port.”** -- Monitor for all connections with a “**Protocol Number”** that is not typical for this device or computer, for example, anything other than 6 or 17. +- Monitor for all connections with a “**Protocol Number”** that isn't typical for this device or computer, for example, anything other than 6 or 17. - If the computer’s communication with “**Destination Address”** should always use a specific “**Destination Port**,**”** monitor for any other “**Destination Port**.” \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5159.md b/windows/security/threat-protection/auditing/event-5159.md index c66d53025f..61393ef168 100644 --- a/windows/security/threat-protection/auditing/event-5159.md +++ b/windows/security/threat-protection/auditing/event-5159.md @@ -98,7 +98,7 @@ This event is logged if the Windows Filtering Platform has blocked a bind to a l - 0.0.0.0 - all IP addresses in IPv4 format - - 127.0.0.1 , ::1 - localhost + - 127.0.0.1, ::1 - localhost - **Source Port** \[Type = UnicodeString\]**:** the port number used by the application. @@ -124,7 +124,7 @@ This event is logged if the Windows Filtering Platform has blocked a bind to a l **Filter Information:** -- **Filter Run-Time ID** \[Type = UInt64\]: unique filter ID that blocks the application from binding to the port. By default, Windows firewall won't prevent a port from binding by an application, and if this application doesn’t match any filters, you will get value 0 in this field. +- **Filter Run-Time ID** \[Type = UInt64\]: unique filter ID that blocks the application from binding to the port. By default, Windows firewall won't prevent a port from binding by an application, and if this application doesn’t match any filters, you'll get value 0 in this field. To find a specific Windows Filtering Platform filter by ID, run the following command: **netsh wfp show filters**. As a result of this command, the **filters.xml** file will be generated. Open this file and find the specific substring with the required filter ID (**<filterId>**)**,** for example: @@ -138,4 +138,4 @@ This event is logged if the Windows Filtering Platform has blocked a bind to a l ## Security Monitoring Recommendations -- There is no recommendation for this event in this document. \ No newline at end of file +- There's no recommendation for this event in this document. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-5632.md b/windows/security/threat-protection/auditing/event-5632.md index 08210802e3..7b2b12b6e5 100644 --- a/windows/security/threat-protection/auditing/event-5632.md +++ b/windows/security/threat-protection/auditing/event-5632.md @@ -85,7 +85,7 @@ It typically generates when network adapter connects to new wireless network. - **Account Name** \[Type = UnicodeString\]**:** the name of the account for which 802.1x authentication request was made. -- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following: +- **Account Domain** \[Type = UnicodeString\]**:** subject’s domain or computer name. Formats vary, and include the following ones: - Domain NETBIOS name example: CONTOSO @@ -125,16 +125,16 @@ You can see interface’s GUID using the following commands: - **Reason Code** \[Type = UnicodeString\]**:** contains Reason Text (explanation of Reason Code) and Reason Code for wireless authentication results. See more information about reason codes for wireless authentication here: , . -- **Error Code** \[Type = HexInt32\]**:** there is no information about this field in this document. +- **Error Code** \[Type = HexInt32\]**:** there's no information about this field in this document. -- **EAP Reason Code** \[Type = HexInt32\]**:** there is no information about this field in this document. See additional information here: . +- **EAP Reason Code** \[Type = HexInt32\]**:** there's no information about this field in this document. See additional information here: . -- **EAP Root Cause String** \[Type = UnicodeString\]**:** there is no information about this field in this document. +- **EAP Root Cause String** \[Type = UnicodeString\]**:** there's no information about this field in this document. -- **EAP Error Code** \[Type = HexInt32\]**:** there is no information about this field in this document. +- **EAP Error Code** \[Type = HexInt32\]**:** there's no information about this field in this document. ## Security Monitoring Recommendations For 5632(S, F): A request was made to authenticate to a wireless network. -- There is no recommendation for this event in this document. \ No newline at end of file +- There's no recommendation for this event in this document. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-6144.md b/windows/security/threat-protection/auditing/event-6144.md index 045943bcdf..0cc09756be 100644 --- a/windows/security/threat-protection/auditing/event-6144.md +++ b/windows/security/threat-protection/auditing/event-6144.md @@ -25,7 +25,7 @@ ms.technology: windows-sec This event generates every time settings from the “Security Settings” section in the group policy object are applied successfully to a computer, without any errors. This event generates on the target computer itself. -It is a routine event which shows you the list of Group Policy Objects that include “Security Settings” policies, and that were applied to the computer. +It's a routine event that shows you the list of Group Policy Objects that include “Security Settings” policies, and that were applied to the computer. This event generates every time Group Policy is applied to the computer. @@ -82,7 +82,7 @@ You can find specific GROUP\_POLICY\_GUID using **Get-GPO** PowerShell cmdlet wi For 6144(S): Security policy in the group policy objects has been applied successfully. -- If you have a pre-defined list of Group Policy Objects which contain Security Settings and must be applied to specific computers, then you can compare the list from this event with your list and in case of any difference trigger an alert. +- If you have a pre-defined list of Group Policy Objects that contain Security Settings and must be applied to specific computers, then you can compare the list from this event with your list and if there's any difference, you must trigger an alert. - This event is mostly an informational event. diff --git a/windows/security/threat-protection/auditing/event-6145.md b/windows/security/threat-protection/auditing/event-6145.md index 17484bcaf1..3a84f0746a 100644 --- a/windows/security/threat-protection/auditing/event-6145.md +++ b/windows/security/threat-protection/auditing/event-6145.md @@ -25,7 +25,7 @@ ms.technology: windows-sec This event generates every time settings from the “Security Settings” section in the group policy object are applied to a computer with one or more errors. This event generates on the target computer itself. -This event generates, for example, if the [SID](/windows/win32/secauthz/security-identifiers) of a security principal which was included in one of the Group Policy settings cannot be resolved or translated to the real account name. +This event generates, for example, if the [SID](/windows/win32/secauthz/security-identifiers) of a security principal which was included in one of the Group Policy settings can't be resolved or translated to the real account name. > **Note**  For recommendations, see [Security Monitoring Recommendations](#security-monitoring-recommendations) for this event. @@ -66,7 +66,7 @@ This event generates, for example, if the [SID](/windows/win32/secauthz/security ***Field Descriptions:*** -**Error Code** \[Type = UInt32\]: specific error code which shows the error which happened during Group Policy processing. You can find the meaning of specific error code here: . For example, error code 1332 means that “no mapping between account names and security IDs was done”. +**Error Code** \[Type = UInt32\]: specific error code that shows the error that happened during Group Policy processing. You can find the meaning of specific error code here: . For example, error code 1332 means that “no mapping between account names and security IDs was done”. **GPO List** \[Type = UnicodeString\]: the list of Group Policy Objects that include “Security Settings” policies, and that were applied with errors to the computer. The format of the list item is: “GROUP\_POLICY\_GUID GROUP\_POLICY\_NAME”. @@ -80,7 +80,7 @@ You can find specific GROUP\_POLICY\_GUID using **Get-GPO** PowerShell cmdlet wi For 6145(F): One or more errors occurred while processing security policy in the group policy objects. -- This event indicates that Group Policy Objects which were applied to the computer or device had some errors during processing. If you see this event, we recommend checking settings in the GPOs from **GPO List** and resolving the cause of the errors. +- This event indicates that Group Policy Objects that were applied to the computer or device had some errors during processing. If you see this event, we recommend checking settings in the GPOs from **GPO List** and resolving the cause of the errors. - If you have a pre-defined list of Group Policy Objects that contain Security Settings and that must be applied to specific computers, check this event to see if errors occurred when the Security Settings were applied. If so, you can review the error codes and investigate the cause of the failure. diff --git a/windows/security/threat-protection/auditing/event-6281.md b/windows/security/threat-protection/auditing/event-6281.md index a4404d8d5d..08849399ff 100644 --- a/windows/security/threat-protection/auditing/event-6281.md +++ b/windows/security/threat-protection/auditing/event-6281.md @@ -1,6 +1,6 @@ --- -title: 6281(F) Code Integrity determined that the page hashes of an image file are not valid. (Windows 10) -description: Describes security event 6281(F) Code Integrity determined that the page hashes of an image file are not valid. +title: 6281(F) Code Integrity determined that the page hashes of an image file aren't valid. (Windows 10) +description: Describes security event 6281(F) Code Integrity determined that the page hashes of an image file aren't valid. ms.pagetype: security ms.prod: m365-security ms.mktglfcycl: deploy @@ -14,16 +14,16 @@ ms.author: dansimp ms.technology: windows-sec --- -# 6281(F): Code Integrity determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error. +# 6281(F): Code Integrity determined that the page hashes of an image file aren't valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error. -[Code Integrity](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd348642(v=ws.10)) is a feature that improves the security of the operating system by validating the integrity of a driver or system file each time it is loaded into memory. Code Integrity detects whether an unsigned driver or system file is being loaded into the kernel, or whether a system file has been modified by malicious software that is being run by a user account with administrative permissions. On x64-based versions of the operating system, kernel-mode drivers must be digitally signed. +[Code Integrity](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd348642(v=ws.10)) is a feature that improves the security of the operating system by validating the integrity of a driver or system file each time it's loaded into memory. Code Integrity detects whether an unsigned driver or system file is being loaded into the kernel, or whether a system file has been modified by malicious software that is being run by a user account with administrative permissions. On x64-based versions of the operating system, kernel-mode drivers must be digitally signed. -This event generates when [code Integrity](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd348642(v=ws.10)) determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. This event also generates when signing certificate was revoked. The invalid hashes could indicate a potential disk device error. +This event generates when [code Integrity](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd348642(v=ws.10)) determined that the page hashes of an image file aren't valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. This event also generates when signing certificate was revoked. The invalid hashes could indicate a potential disk device error. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit System Integrity](audit-system-integrity.md) diff --git a/windows/security/threat-protection/auditing/event-6405.md b/windows/security/threat-protection/auditing/event-6405.md index e8efbf0ec1..cd6d137b5a 100644 --- a/windows/security/threat-protection/auditing/event-6405.md +++ b/windows/security/threat-protection/auditing/event-6405.md @@ -19,7 +19,7 @@ ms.technology: windows-sec [BranchCache](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj127252(v=ws.11)) events are outside the scope of this document. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit Other System Events](audit-other-system-events.md) @@ -35,4 +35,4 @@ There is no example of this event in this document. ## Security Monitoring Recommendations -- There is no recommendation for this event in this document. \ No newline at end of file +- There's no recommendation for this event in this document. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-6406.md b/windows/security/threat-protection/auditing/event-6406.md index 5f556714d7..49d868e4de 100644 --- a/windows/security/threat-protection/auditing/event-6406.md +++ b/windows/security/threat-protection/auditing/event-6406.md @@ -19,7 +19,7 @@ ms.technology: windows-sec [BranchCache](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj127252(v=ws.11)) events are outside the scope of this document. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit Other System Events](audit-other-system-events.md) @@ -37,4 +37,4 @@ There is no example of this event in this document. ## Security Monitoring Recommendations -- There is no recommendation for this event in this document. \ No newline at end of file +- There's no recommendation for this event in this document. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-6407.md b/windows/security/threat-protection/auditing/event-6407.md index a5d377eb0e..791511b97c 100644 --- a/windows/security/threat-protection/auditing/event-6407.md +++ b/windows/security/threat-protection/auditing/event-6407.md @@ -1,6 +1,6 @@ --- title: 6407(-) 1%. (Windows 10) -description: Describes security event 6407(-) 1%. This is a BranchCache event, which is outside the scope of this document. +description: Describes security event 6407(-) 1%. This event is a BranchCache event, which is outside the scope of this document. ms.pagetype: security ms.prod: m365-security ms.mktglfcycl: deploy @@ -19,7 +19,7 @@ ms.technology: windows-sec [BranchCache](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj127252(v=ws.11)) events are outside the scope of this document. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit Other System Events](audit-other-system-events.md) @@ -35,4 +35,4 @@ There is no example of this event in this document. ## Security Monitoring Recommendations -- There is no recommendation for this event in this document. \ No newline at end of file +- There's no recommendation for this event in this document. \ No newline at end of file diff --git a/windows/security/threat-protection/auditing/event-6410.md b/windows/security/threat-protection/auditing/event-6410.md index bc2da0e57f..36e66234e1 100644 --- a/windows/security/threat-protection/auditing/event-6410.md +++ b/windows/security/threat-protection/auditing/event-6410.md @@ -1,6 +1,6 @@ --- -title: 6410(F) Code integrity determined that a file does not meet the security requirements to load into a process. (Windows 10) -description: Describes security event 6410(F) Code integrity determined that a file does not meet the security requirements to load into a process. +title: 6410(F) Code integrity determined that a file doesn't meet the security requirements to load into a process. (Windows 10) +description: Describes security event 6410(F) Code integrity determined that a file doesn't meet the security requirements to load into a process. ms.pagetype: security ms.prod: m365-security ms.mktglfcycl: deploy @@ -17,11 +17,11 @@ ms.technology: windows-sec # 6410(F): Code integrity determined that a file does not meet the security requirements to load into a process. -[Code Integrity](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd348642(v=ws.10)) is a feature that improves the security of the operating system by validating the integrity of a driver or system file each time it is loaded into memory. Code Integrity detects whether an unsigned driver or system file is being loaded into the kernel, or whether a system file has been modified by malicious software that is being run by a user account with administrative permissions. On x64-based versions of the operating system, kernel-mode drivers must be digitally signed. +[Code Integrity](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd348642(v=ws.10)) is a feature that improves the security of the operating system by validating the integrity of a driver or system file each time it's loaded into memory. Code Integrity detects whether an unsigned driver or system file is being loaded into the kernel, or whether a system file has been modified by malicious software that is being run by a user account with administrative permissions. On x64-based versions of the operating system, kernel-mode drivers must be digitally signed. This event generates due to writable [shared sections](/previous-versions/windows/desktop/cc307397(v=msdn.10)) being present in a file image. -There is no example of this event in this document. +There's no example of this event in this document. ***Subcategory:*** [Audit System Integrity](audit-system-integrity.md) diff --git a/windows/security/threat-protection/auditing/file-system-global-object-access-auditing.md b/windows/security/threat-protection/auditing/file-system-global-object-access-auditing.md index a5df9bf707..605274b0a5 100644 --- a/windows/security/threat-protection/auditing/file-system-global-object-access-auditing.md +++ b/windows/security/threat-protection/auditing/file-system-global-object-access-auditing.md @@ -23,9 +23,9 @@ ms.technology: windows-sec This topic for the IT professional describes the Advanced Security Audit policy setting, **File System (Global Object Access Auditing)**, which enables you to configure a global system access control list (SACL) on the file system for an entire computer. -If you select the **Configure security** check box on the policy’s property page, you can add a user or group to the global SACL. This enables you to define computer system access control lists (SACLs) per object type for the file system. The specified SACL is then automatically applied to every file system object type. +If you select the **Configure security** check box on the policy’s property page, you can add a user or group to the global SACL. This user/group addition enables you to define computer system access control lists (SACLs) per object type for the file system. The specified SACL is then automatically applied to every file system object type. -If both a file or folder SACL and a global SACL are configured on a computer, the effective SACL is derived by combining the file or folder SACL and the global SACL. This means that an audit event is generated if an activity matches either the file or folder SACL or the global SACL. +If both a file or folder SACL and a global SACL are configured on a computer, the effective SACL is derived by combining the file or folder SACL and the global SACL. This SACL (of such a constitution) means that an audit event is generated if an activity matches either the file or folder SACL or the global SACL. This policy setting must be used in combination with the **File System** security policy setting under Object Access. For more information, see [Audit File System](audit-file-system.md). ## Related topics diff --git a/windows/security/threat-protection/auditing/monitor-central-access-policy-and-rule-definitions.md b/windows/security/threat-protection/auditing/monitor-central-access-policy-and-rule-definitions.md index 3dc75d64ed..0d27bc3fda 100644 --- a/windows/security/threat-protection/auditing/monitor-central-access-policy-and-rule-definitions.md +++ b/windows/security/threat-protection/auditing/monitor-central-access-policy-and-rule-definitions.md @@ -23,7 +23,7 @@ ms.technology: windows-sec This article for IT professionals describes how to monitor changes to central access policy and central access rule definitions when you use advanced security auditing options to monitor dynamic access control objects. -Central access policies and rules determine access permissions for files on multiple file servers, so it's important to monitor changes to them. Like user claim and device claim definitions, central access policy and rule definitions reside in Active Directory Domain Services (AD DS). You can monitor them just like any other object in Active Directory. These policies and rules are critical elements in a Dynamic Access Control deployment. They are stored in AD DS, so they're less likely to be tampered with than other network objects. But it's important to monitor them for potential changes in security auditing and to verify that policies are being enforced. +Central access policies and rules determine access permissions for files on multiple file servers, so it's important to monitor changes to them. Like user claim and device claim definitions, central access policy and rule definitions reside in Active Directory Domain Services (AD DS). You can monitor them just like any other object in Active Directory. These policies and rules are critical elements in a Dynamic Access Control deployment. They're stored in AD DS, so they're less likely to be tampered with than other network objects. But it's important to monitor them for potential changes in security auditing and to verify that policies are being enforced. Follow the procedures in this article to configure settings to monitor changes to central access policy and central access rule definitions and to verify the changes. These procedures assume that you've configured and deployed Dynamic Access Control, including central access policies, claims, and other components, in your network. If you haven't yet deployed Dynamic Access Control in your network, see [Deploy a Central Access Policy (demonstration steps)](/windows-server/identity/solution-guides/deploy-a-central-access-policy--demonstration-steps-). diff --git a/windows/security/threat-protection/auditing/monitor-claim-types.md b/windows/security/threat-protection/auditing/monitor-claim-types.md index 643795c7e2..1a7fbfe2d2 100644 --- a/windows/security/threat-protection/auditing/monitor-claim-types.md +++ b/windows/security/threat-protection/auditing/monitor-claim-types.md @@ -1,6 +1,6 @@ --- title: Monitor claim types (Windows 10) -description: Learn how to monitor changes to claim types that are associated with dynamic access control when you are using advanced security auditing options. +description: Learn how to monitor changes to claim types that are associated with dynamic access control when you're using advanced security auditing options. ms.assetid: 426084da-4eef-44af-aeec-e7ab4d4e2439 ms.reviewer: ms.author: dansimp @@ -21,11 +21,11 @@ ms.technology: windows-sec # Monitor claim types -This topic for the IT professional describes how to monitor changes to claim types that are associated with dynamic access control when you are using advanced security auditing options. +This topic for the IT professional describes how to monitor changes to claim types that are associated with dynamic access control when you're using advanced security auditing options. Claim types are one of the basic building blocks of Dynamic Access Control. Claim types can include attributes such as the departments in an organization or the levels of security clearance that apply to classes of users. You can use security auditing to track whether claims are added, modified, enabled, disabled, or deleted. -Use the following procedures to configure settings to monitor changes to claim types in AD DS. These procedures assume that you have configured and deployed Dynamic Access Control, including central access policies, claims, and other components, in your network. If you have not yet deployed Dynamic +Use the following procedures to configure settings to monitor changes to claim types in AD DS. These procedures assume that you have configured and deployed Dynamic Access Control, including central access policies, claims, and other components, in your network. If you haven't yet deployed Dynamic Access Control in your network, see [Deploy a Central Access Policy (Demonstration Steps)](/windows-server/identity/solution-guides/deploy-a-central-access-policy--demonstration-steps-). >**Note:**  Your server might function differently based on the version and edition of the operating system that is installed, your account permissions, and your menu settings. @@ -36,7 +36,7 @@ Access Control in your network, see [Deploy a Central Access Policy (Demonstrati 2. In Server Manager, point to **Tools**, and then click **Group Policy Management**. 3. In the console tree, right-click the default domain controller Group Policy Object, and then click **Edit**. 4. Double-click **Computer Configuration**, click **Security Settings**, expand **Advanced Audit Policy Configuration**, expand **System Audit Policies**, click **DS Access**, and then double-click **Audit directory service changes**. -5. Select the **Configure the following audit events** check box, select the **Success** check box (andthe **Failure** check box, if desired), and then click **OK**. +5. Select the **Configure the following audit events** check box, select the **Success** check box (and the **Failure** check box, if desired), and then click **OK**. After you configure settings to monitor changes to claim types in AD DS, verify that the changes are being monitored. diff --git a/windows/security/threat-protection/auditing/monitor-resource-attribute-definitions.md b/windows/security/threat-protection/auditing/monitor-resource-attribute-definitions.md index 1be153db59..c9c75a970e 100644 --- a/windows/security/threat-protection/auditing/monitor-resource-attribute-definitions.md +++ b/windows/security/threat-protection/auditing/monitor-resource-attribute-definitions.md @@ -1,6 +1,6 @@ --- title: Monitor resource attribute definitions (Windows 10) -description: Learn how to monitor changes to resource attribute definitions when you are using advanced security auditing options to monitor dynamic access control objects. +description: Learn how to monitor changes to resource attribute definitions when you're using advanced security auditing options to monitor dynamic access control objects. ms.assetid: aace34b0-123a-4b83-9e09-f269220e79de ms.reviewer: ms.author: dansimp @@ -21,12 +21,12 @@ ms.technology: windows-sec # Monitor resource attribute definitions -This topic for the IT professional describes how to monitor changes to resource attribute definitions when you are using advanced security auditing options to monitor dynamic access control objects. +This topic for the IT professional describes how to monitor changes to resource attribute definitions when you're using advanced security auditing options to monitor dynamic access control objects. Resource attribute definitions define the basic properties of resource attributes, such as what it means for a resource to be defined as “high business value.” Resource attribute definitions are stored in AD DS under the Resource Properties container. Changes to these definitions could significantly change the protections that govern a resource, even if the resource attributes that apply to the resource remain unchanged. Changes can be monitored like any other AD DS object. For information about monitoring changes to the resource attributes that apply to files, see [Monitor the resource attributes on files and folders](monitor-the-resource-attributes-on-files-and-folders.md). -Use the following procedures to configure settings to monitor changes to resource attribute definitions in AD DS and to verify the changes. These procedures assume that you have configured and deployed Dynamic Access Control, including central access policies, claims, and other components, in your network. If you have not yet deployed Dynamic Access Control in your network, see [Deploy a Central Access Policy (Demonstration Steps)](/windows-server/identity/solution-guides/deploy-a-central-access-policy--demonstration-steps-). +Use the following procedures to configure settings to monitor changes to resource attribute definitions in AD DS and to verify the changes. These procedures assume that you have configured and deployed Dynamic Access Control, including central access policies, claims, and other components, in your network. If you haven't yet deployed Dynamic Access Control in your network, see [Deploy a Central Access Policy (Demonstration Steps)](/windows-server/identity/solution-guides/deploy-a-central-access-policy--demonstration-steps-). >**Note:**  Your server might function differently based on the version and edition of the operating system that is installed, your account permissions, and your menu settings. From efeb3b3aadad02a57c9dac045b6111eba21d2ffa Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Tue, 28 Jun 2022 12:27:56 +0530 Subject: [PATCH 007/109] Acrolinx Enhancement Effort --- ...connect-clients-when-logon-hours-expire.md | 20 ++++++++--------- ...server-spn-target-name-validation-level.md | 10 ++++----- .../minimum-password-age.md | 14 ++++++------ .../minimum-password-length.md | 6 ++--- .../modify-an-object-label.md | 12 +++++----- ...ess-allow-anonymous-sidname-translation.md | 6 ++--- ...-enumeration-of-sam-accounts-and-shares.md | 8 +++---- ...w-anonymous-enumeration-of-sam-accounts.md | 8 +++---- ...-credentials-for-network-authentication.md | 16 +++++++------- ...ne-permissions-apply-to-anonymous-users.md | 8 +++---- ...-pipes-that-can-be-accessed-anonymously.md | 8 +++---- ...-accessible-registry-paths-and-subpaths.md | 6 ++--- ...cess-remotely-accessible-registry-paths.md | 6 ++--- ...nymous-access-to-named-pipes-and-shares.md | 6 ++--- ...lients-allowed-to-make-remote-sam-calls.md | 22 +++++++++---------- ...shares-that-can-be-accessed-anonymously.md | 6 ++--- ...g-and-security-model-for-local-accounts.md | 10 ++++----- ...ystem-to-use-computer-identity-for-ntlm.md | 14 ++++++------ ...allow-localsystem-null-session-fallback.md | 12 +++++----- ...-this-computer-to-use-online-identities.md | 14 ++++++------ ...e-encryption-types-allowed-for-kerberos.md | 16 +++++++------- ...ager-hash-value-on-next-password-change.md | 10 ++++----- ...ty-force-logoff-when-logon-hours-expire.md | 18 +++++++-------- ...curity-lan-manager-authentication-level.md | 18 +++++++-------- ...curity-ldap-client-signing-requirements.md | 12 +++++----- ...-ssp-based-including-secure-rpc-servers.md | 10 ++++----- ...rver-exceptions-for-ntlm-authentication.md | 14 ++++++------ ...lm-add-server-exceptions-in-this-domain.md | 13 +++++------ ...strict-ntlm-audit-incoming-ntlm-traffic.md | 16 +++++++------- ...udit-ntlm-authentication-in-this-domain.md | 16 +++++++------- 30 files changed, 177 insertions(+), 178 deletions(-) diff --git a/windows/security/threat-protection/security-policy-settings/microsoft-network-server-disconnect-clients-when-logon-hours-expire.md b/windows/security/threat-protection/security-policy-settings/microsoft-network-server-disconnect-clients-when-logon-hours-expire.md index 5cf58f4daf..6b528db190 100644 --- a/windows/security/threat-protection/security-policy-settings/microsoft-network-server-disconnect-clients-when-logon-hours-expire.md +++ b/windows/security/threat-protection/security-policy-settings/microsoft-network-server-disconnect-clients-when-logon-hours-expire.md @@ -1,6 +1,6 @@ --- -title: Microsoft network server Disconnect clients when logon hours expire (Windows 10) -description: Best practices, location, values, and security considerations for the policy setting, Microsoft network server Disconnect clients when logon hours expire. +title: Microsoft network server Disconnect clients when sign-in hours expire (Windows 10) +description: Best practices, location, values, and security considerations for the policy setting, Microsoft network server Disconnect clients when sign-in hours expire. ms.assetid: 48b5c424-9ba8-416d-be7d-ccaabb3f49af ms.reviewer: ms.author: dansimp @@ -18,7 +18,7 @@ ms.date: 04/19/2017 ms.technology: windows-sec --- -# Microsoft network server: Disconnect clients when logon hours expire +# Microsoft network server: Disconnect clients when sign-in hours expire **Applies to** - Windows 10 @@ -27,17 +27,17 @@ Describes the best practices, location, values, and security considerations for ## Reference -This policy setting enables or disables the forced disconnection of users who are connected to the local device outside their user account's valid logon hours. It affects the SMB component. If you enable this policy setting, client computer sessions with the SMB service are forcibly disconnected when the client's logon hours expire. If you disable this policy setting, established client device sessions are maintained after the client device's logon hours expire. +This policy setting enables or disables the forced disconnection of users who are connected to the local device outside their user account's valid sign-in hours. It affects the SMB component. If you enable this policy setting, client computer sessions with the SMB service are forcibly disconnected when the client's sign-in hours expire. If you disable this policy setting, established client device sessions are maintained after the client device's sign-in hours expire. ### Possible values - Enabled - Client device sessions with the SMB service are forcibly disconnected when the client device's logon hours expire. If logon hours are not used in your organization, enabling this policy setting will have no impact. + Client device sessions with the SMB service are forcibly disconnected when the client device's sign-in hours expire. If sign-in hours aren't used in your organization, enabling this policy setting will have no impact. - Disabled - The system maintains an established client device session after the client device's logon hours have expired. + The system maintains an established client device session after the client device's sign-in hours have expired. - Not defined @@ -68,11 +68,11 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy -This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy is not contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. +This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy isn't contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. ## Security considerations @@ -80,7 +80,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -If your organization configures logon hours for users, it makes sense to enable this policy setting. Otherwise, users who should not have access to network resources outside of their logon hours can continue to use those resources with sessions that were established during allowed hours. +If your organization configures sign-in hours for users, it makes sense to enable this policy setting. Otherwise, users who shouldn't have access to network resources outside of their sign-in hours can continue to use those resources with sessions that were established during allowed hours. ### Countermeasure @@ -88,7 +88,7 @@ Enable the **Microsoft network server: Disconnect clients when logon hours expir ### Potential impact -If logon hours are not used in your organization, this policy setting has no impact. If logon hours are used, existing user sessions are forcibly terminated when their logon hours expire. +If sign-in hours aren't used in your organization, this policy setting has no impact. If sign-in hours are used, existing user sessions are forcibly terminated when their sign-in hours expire. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/microsoft-network-server-server-spn-target-name-validation-level.md b/windows/security/threat-protection/security-policy-settings/microsoft-network-server-server-spn-target-name-validation-level.md index 23c36d99fa..a403cf9029 100644 --- a/windows/security/threat-protection/security-policy-settings/microsoft-network-server-server-spn-target-name-validation-level.md +++ b/windows/security/threat-protection/security-policy-settings/microsoft-network-server-server-spn-target-name-validation-level.md @@ -37,15 +37,15 @@ The options for validation levels are: - **Off** - The SPN from a SMB client is not required or validated by the SMB server. + The SPN from an SMB client isn't required or validated by the SMB server. - **Accept if provided by client** - The SMB server will accept and validate the SPN provided by the SMB client and allow a session to be established if it matches the SMB server’s list of SPN’s. If the SPN does not match, the session request for that SMB client will be denied. + The SMB server will accept and validate the SPN provided by the SMB client and allow a session to be established if it matches the SMB server’s list of SPNs. If the SPN doesn't match, the session request for that SMB client will be denied. - **Required from client** - The SMB client must send a SPN name in session setup, and the SPN name provided must match the SMB server that is being requested to establish a connection. If no SPN is provided by the client device, or the SPN provided does not match, the session is denied. + The SMB client must send an SPN name in session setup, and the SPN name provided must match the SMB server that is being requested to establish a connection. If no SPN is provided by the client device, or the SPN provided doesn't match, the session is denied. The default setting is Off. @@ -78,7 +78,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Policy conflict considerations @@ -86,7 +86,7 @@ None. ### Group Policy -This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy is not contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. +This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy isn't contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. ## Security considerations diff --git a/windows/security/threat-protection/security-policy-settings/minimum-password-age.md b/windows/security/threat-protection/security-policy-settings/minimum-password-age.md index 960112af64..97ae441bb7 100644 --- a/windows/security/threat-protection/security-policy-settings/minimum-password-age.md +++ b/windows/security/threat-protection/security-policy-settings/minimum-password-age.md @@ -35,14 +35,14 @@ The **Minimum password age** policy setting determines the period of time (in da [Windows security baselines](../windows-security-baselines.md) recommend setting **Minimum password age** to one day. -Setting the number of days to 0 allows immediate password changes. This setting is not recommended. +Setting the number of days to 0 allows immediate password changes. This setting isn't recommended. Combining immediate password changes with password history allows someone to change a password repeatedly until the password history requirement is met and re-establish the original password again. For example, suppose a password is "Ra1ny day!" and the history requirement is 24. If the minimum password age is 0, the password can be changed 24 times in a row until finally changed back to "Ra1ny day!". The minimum password age of 1 day prevents that. If you set a password for a user and you want that user to change the administrator-defined password, you must select the **User must change password at next logon** check box. -Otherwise, the user will not be able to change the password until the number of days specified by **Minimum password age**. +Otherwise, the user won't be able to change the password until the number of days specified by **Minimum password age**. ### Location @@ -67,7 +67,7 @@ This section describes features, tools, and guidance to help you manage this pol ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -75,17 +75,17 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -Users may have favorite passwords that they like to use because they are easy to remember and they believe that their password choice is secure from compromise. Unfortunately, passwords can be compromised and if an attacker is targeting a specific individual user account, with knowledge of data about that user, reuse of old passwords can cause a security breach. +Users may have favorite passwords that they like to use because they're easy to remember and they believe that their password choice is secure from compromise. Unfortunately, passwords can be compromised and if an attacker is targeting a specific individual user account, with knowledge of data about that user, reuse of old passwords can cause a security breach. -To address password reuse, you must use a combination of security settings. Using this policy setting with the [Enforce password history](enforce-password-history.md) policy setting prevents the easy reuse of old passwords. For example, if you configure the Enforce password history policy setting to ensure that users cannot reuse any of their last 12 passwords, but you do not configure the **Minimum password age** policy setting to a number that is greater than 0, users could change their password 13 times in a few minutes and reuse their original password. Configure this policy setting to a number that is greater than 0 for the Enforce password history policy setting to be effective. +To address password reuse, you must use a combination of security settings. Using this policy setting with the [Enforce password history](enforce-password-history.md) policy setting prevents the easy reuse of old passwords. For example, if you configure the Enforce password history policy setting to ensure that users can't reuse any of their last 12 passwords, but you don't configure the **Minimum password age** policy setting to a number that is greater than 0, users could change their password 13 times in a few minutes and reuse their original password. Configure this policy setting to a number that is greater than 0 for the Enforce password history policy setting to be effective. ### Countermeasure -Configure the **Minimum password age** policy setting to a value of 1 day. Users should know about this limitation and contact the Help Desk to change a password sooner. If you configure the number of days to 0, immediate password changes would be allowed, which we do not recommend. +Configure the **Minimum password age** policy setting to a value of 1 day. Users should know about this limitation and contact the Help Desk to change a password sooner. If you configure the number of days to 0, immediate password changes would be allowed, which we don't recommend. ### Potential impact -If you set a password for a user but want that user to change the password when the user first logs on, the administrator must select the **User must change password at next logon** check box, or the user cannot change the password until the next day. +If you set a password for a user but want that user to change the password when the user first logs on, the administrator must select the **User must change password at next logon** check box, or the user can't change the password until the next day. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/minimum-password-length.md b/windows/security/threat-protection/security-policy-settings/minimum-password-length.md index d116884fca..79aad414c3 100644 --- a/windows/security/threat-protection/security-policy-settings/minimum-password-length.md +++ b/windows/security/threat-protection/security-policy-settings/minimum-password-length.md @@ -38,9 +38,9 @@ The **Minimum password length** policy setting determines the least number of ch Set Minimum password length to at least a value of 14. If the number of characters is set to 0, no password is required. In most environments, an eight-character password is recommended because it's long enough to provide adequate security and still short enough for users to easily remember. A minimum password length greater than 14 isn't supported at this time. This value will help provide adequate defense against a brute force attack. Adding complexity requirements will help reduce the possibility of a dictionary attack. For more info, see [Password must meet complexity requirements](password-must-meet-complexity-requirements.md). -Permitting short passwords reduces security because short passwords can be easily broken with tools that do dictionary or brute force attacks against the passwords. Requiring very long passwords can result in mistyped passwords that might cause account lockouts and might increase the volume of Help Desk calls. +Permitting short passwords reduces security because short passwords can be easily broken with tools that do dictionary or brute force attacks against the passwords. Requiring long passwords can result in mistyped passwords that might cause account lockouts and might increase the volume of Help Desk calls. -In addition, requiring extremely long passwords can actually decrease the security of an organization because users might be more likely to write down their passwords to avoid forgetting them. However, if users are taught that they can use passphrases (sentences such as "I want to drink a $5 milkshake"), they should be much more likely to remember. +In addition, requiring long passwords can actually decrease the security of an organization because users might be more likely to write down their passwords to avoid forgetting them. However, if users are taught that they can use passphrases (sentences such as "I want to drink a $5 milkshake"), they should be much more likely to remember. ### Location @@ -86,7 +86,7 @@ In most environments, we recommend an eight-character password because it's long ### Potential impact -Requirements for extremely long passwords can actually decrease the security of an organization because users might leave the information in an unsecured location or lose it. If very long passwords are required, mistyped passwords could cause account lockouts and increase the volume of Help Desk calls. If your organization has issues with forgotten passwords because of password length requirements, consider teaching your users about passphrases, which are often easier to remember and, because of the larger number of character combinations, much harder to discover. +Requirements for long passwords can actually decrease the security of an organization because users might leave the information in an unsecured location or lose it. If long passwords are required, mistyped passwords could cause account lockouts and increase the volume of Help Desk calls. If your organization has issues with forgotten passwords because of password length requirements, consider teaching your users about passphrases, which are often easier to remember and, because of the larger number of character combinations, much harder to discover. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/modify-an-object-label.md b/windows/security/threat-protection/security-policy-settings/modify-an-object-label.md index b320e305b8..373887c79e 100644 --- a/windows/security/threat-protection/security-policy-settings/modify-an-object-label.md +++ b/windows/security/threat-protection/security-policy-settings/modify-an-object-label.md @@ -34,10 +34,10 @@ similar to NTFS file and folder permissions, which are discretionary controls on - **Untrusted**   Default assignment for processes that are logged on anonymously. - **Low**   Default assignment for processes that interact with the Internet. -- **Medium**   Default assignment for standard user accounts and any object that is not explicitly designated with a lower or higher integrity level. +- **Medium**   Default assignment for standard user accounts and any object that isn't explicitly designated with a lower or higher integrity level. - **High**  Default assignment for administrator accounts and processes that request to run using administrative rights. - **System**   Default assignment for Windows kernel and core services. -- **Installer**   Used by setup programs to install software. It is important that only trusted software is installed on computers because objects that are assigned the Installer integrity level can install, modify, and uninstall all other objects. +- **Installer**   Used by setup programs to install software. It's important that only trusted software is installed on computers because objects that are assigned the Installer integrity level can install, modify, and uninstall all other objects. Constant: SeRelabelPrivilege @@ -48,7 +48,7 @@ Constant: SeRelabelPrivilege ### Best practices -- Do not give any group this user right. +- Don't give any group this user right. ### Location @@ -73,7 +73,7 @@ The following table lists the actual and effective default policy values for the This section describes features, tools, and guidance to help you manage this policy. -A restart of the computer is not required for this policy setting to be effective. +A restart of the computer isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. @@ -97,11 +97,11 @@ This section describes how an attacker might exploit a feature or its configurat Anyone with the **Modify an object label** user right can change the integrity level of a file or process so that it becomes elevated or decreased to a point where it can be deleted by lower integrity processes. Either of these states effectively circumvents the protection that is offered by Windows Integrity Controls and makes your system vulnerable to attacks by malicious software. -If malicious software is set with an elevated integrity level such as Trusted Installer or System, administrator accounts do not have sufficient integrity levels to delete the program from the system. In that case, use of the **Modify an object label** right is mandated so that the object can be relabeled. However, the relabeling must occur by using a process that is at the same or a higher level of integrity than the object that you are attempting to relabel. +If malicious software is set with an elevated integrity level such as Trusted Installer or System, administrator accounts don't have sufficient integrity levels to delete the program from the system. In that case, use of the **Modify an object label** right is mandated so that the object can be relabeled. However, the relabeling must occur by using a process that is at the same or a higher level of integrity than the object that you're attempting to relabel. ### Countermeasure -Do not give any group this right. If necessary, implement it for a constrained period of time to a trusted individual to respond to a specific organizational need. +Don't give any group this right. If necessary, implement it for a constrained period of time to a trusted individual to respond to a specific organizational need. ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/network-access-allow-anonymous-sidname-translation.md b/windows/security/threat-protection/security-policy-settings/network-access-allow-anonymous-sidname-translation.md index 82be9fa1ec..3749e86521 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-allow-anonymous-sidname-translation.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-allow-anonymous-sidname-translation.md @@ -37,7 +37,7 @@ Misuse of this policy setting is a common error that can cause data loss or prob - Enabled - An anonymous user can request the SID attribute for another user. An anonymous user with knowledge of an administrator's SID could contact a computer that has this policy enabled and use the SID to get the administrator's name. This setting affects the SID-to-name translation as well as the name-to-SID translation. + An anonymous user can request the SID attribute for another user. An anonymous user with knowledge of an administrator's SID could contact a computer that has this policy enabled and use the SID to get the administrator's name. This setting affects the SID-to-name translation and the name-to-SID translation. - Disabled @@ -47,7 +47,7 @@ Misuse of this policy setting is a common error that can cause data loss or prob ### Best practices -- Set this policy to Disabled. This is the default value on member computers; therefore, it will have no impact on them. The default value for domain controllers is Enabled. +- Set this policy to Disabled, which is the default value on member computers; therefore, it will have no impact on them. The default value for domain controllers is Enabled. ### Location @@ -79,7 +79,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy diff --git a/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts-and-shares.md b/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts-and-shares.md index aa56038e35..6bad2976ca 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts-and-shares.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts-and-shares.md @@ -27,7 +27,7 @@ Describes the best practices, location, values, and security considerations for ## Reference -This policy setting determines which additional permissions will be assigned for anonymous connections to the device. Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to give access to users in a trusted domain that does not maintain a reciprocal trust. However, even with this policy setting enabled, anonymous users will have access to resources with permissions that explicitly include the built-in group, ANONYMOUS LOGON. +This policy setting determines which other permissions will be assigned for anonymous connections to the device. Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This permission is convenient, for example, when an administrator wants to give access to users in a trusted domain that doesn't maintain a reciprocal trust. However, even with this policy setting enabled, anonymous users will have access to resources with permissions that explicitly include the built-in group, ANONYMOUS LOGON. This policy setting has no impact on domain controllers. Misuse of this policy setting is a common error that can cause data loss or problems with data access or security. @@ -38,7 +38,7 @@ Misuse of this policy setting is a common error that can cause data loss or prob - Disabled - No additional permissions can be assigned by the administrator for anonymous connections to the device. Anonymous connections will rely on default permissions. However, an unauthorized user could anonymously list account names and use the information to attempt to guess passwords or perform social-engineering attacks. + No other permissions can be assigned by the administrator for anonymous connections to the device. Anonymous connections will rely on default permissions. However, an unauthorized user could anonymously list account names and use the information to attempt to guess passwords or perform social-engineering attacks. - Not defined @@ -65,7 +65,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Policy conflicts @@ -89,7 +89,7 @@ Enable the **Network access: Do not allow anonymous enumeration of SAM accounts ### Potential impact -It is impossible to grant access to users of another domain across a one-way trust because administrators in the trusting domain are unable to enumerate lists of accounts in the other domain. Users who access file and print servers anonymously are unable to list the shared network resources on those servers; the users must be authenticated before they can view the lists of shared folders and printers. +It's impossible to grant access to users of another domain across a one-way trust because administrators in the trusting domain are unable to enumerate lists of accounts in the other domain. Users who access file and print servers anonymously are unable to list the shared network resources on those servers; the users must be authenticated before they can view the lists of shared folders and printers. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts.md b/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts.md index 1e144a682f..a6c761b102 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts.md @@ -27,7 +27,7 @@ Describes the best practices, location, values, and security considerations for ## Reference -This policy setting determines which additional permissions will be assigned for anonymous connections to the device. Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to give access to users in a trusted domain that does not maintain a reciprocal trust. +This policy setting determines which other permissions will be assigned for anonymous connections to the device. Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This permission is convenient, for example, when an administrator wants to give access to users in a trusted domain that doesn't maintain a reciprocal trust. This policy setting has no impact on domain controllers. @@ -39,7 +39,7 @@ Misuse of this policy setting is a common error that can cause data loss or prob - Disabled - No additional permissions can be assigned by the administrator for anonymous connections to the device. Anonymous connections will rely on default permissions. + No other permissions can be assigned by the administrator for anonymous connections to the device. Anonymous connections will rely on default permissions. - Not defined @@ -66,7 +66,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Policy conflicts @@ -90,7 +90,7 @@ Enable the **Network access: Do not allow anonymous enumeration of SAM accounts* ### Potential impact -It is impossible to grant access to users of another domain across a one-way trust because administrators in the trusting domain are unable to enumerate lists of accounts in the other domain. Users who access file and print servers anonymously are unable to list the shared network resources on those servers; the users must be authenticated before they can view the lists of shared folders and printers. +It's impossible to grant access to users of another domain across a one-way trust because administrators in the trusting domain are unable to enumerate lists of accounts in the other domain. Users who access file and print servers anonymously are unable to list the shared network resources on those servers; the users must be authenticated before they can view the lists of shared folders and printers. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-storage-of-passwords-and-credentials-for-network-authentication.md b/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-storage-of-passwords-and-credentials-for-network-authentication.md index 160dbb22e8..51152ae5b7 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-storage-of-passwords-and-credentials-for-network-authentication.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-storage-of-passwords-and-credentials-for-network-authentication.md @@ -33,7 +33,7 @@ This security setting determines whether Credential Manager saves passwords and - Enabled - Credential Manager does not store passwords and credentials on the device + Credential Manager doesn't store passwords and credentials on the device - Disabled @@ -43,7 +43,7 @@ This security setting determines whether Credential Manager saves passwords and ### Best practices -It is a recommended practice to disable the ability of the Windows operating system to cache credentials on any device where credentials are not needed. Evaluate your servers and workstations to determine the requirements. Cached credentials are designed primarily to be used on laptops that require domain credentials when disconnected from the domain. +It's a recommended practice to disable the ability of the Windows operating system to cache credentials on any device where credentials aren't needed. Evaluate your servers and workstations to determine the requirements. Cached credentials are designed primarily to be used on laptops that require domain credentials when disconnected from the domain. ### Location @@ -72,7 +72,7 @@ A restart of the device is required before this policy will be effective when ch ### Group Policy -This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy is not contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. +This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy isn't contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. ## Security considerations @@ -84,21 +84,21 @@ Passwords that are cached can be accessed by the user when logged on to the devi >**Note:**  The chances of success for this exploit and others that involve malicious software are reduced significantly for organizations that effectively implement and manage an enterprise antivirus solution combined with sensible software restriction policies. -Regardless of what encryption algorithm is used to encrypt the password verifier, a password verifier can be overwritten so that an attacker can authenticate as the user to whom the verifier belongs. Therefore, the administrator's password may be overwritten. This procedure requires physical access to the device. Utilities exist that can help overwrite the cached verifier. By using one of these utilities, an attacker can authenticate by using the overwritten value. +Regardless of what encryption algorithm is used to encrypt the password verifier, a password verifier can be overwritten so that an attacker can authenticate as the user to whom the verifier belongs. Therefore, the administrator's password may be overwritten. This procedure requires physical access to the device. Utilities exist that can help overwrite the cached verifier. With the help of one of these utilities, an attacker can authenticate by using the overwritten value. -Overwriting the administrator's password does not help the attacker access data that is encrypted by using that password. Also, overwriting the password does not help the attacker access any Encrypting File System (EFS) data that belongs to other users on that device. Overwriting the password does not help an attacker replace the verifier, because the base keying material is incorrect. Therefore, data that is encrypted by using Encrypting File System or by using the Data Protection API (DPAPI) will not decrypt. +Overwriting the administrator's password doesn't help the attacker access data that is encrypted by using that password. Also, overwriting the password doesn't help the attacker access any Encrypting File System (EFS) data that belongs to other users on that device. Overwriting the password doesn't help an attacker replace the verifier, because the base keying material is incorrect. Therefore, data that is encrypted by using Encrypting File System or by using the Data Protection API (DPAPI) won't decrypt. ### Countermeasure Enable the **Network access: Do not allow storage of passwords and credentials for network authentication** setting. -To limit the number of cached domain credentials that are stored on the computer, set the **cachedlogonscount** registry entry. By default, the operating system caches the verifier for each unique user's ten most recent valid logons. This value can be set to any value between 0 and 50. By default, all versions of the Windows operating system remember 10 cached logons, except Windows Server 2008 and later, which are set at 25. +To limit the number of cached domain credentials that are stored on the computer, set the **cachedlogonscount** registry entry. By default, the operating system caches the verifier for each unique user's 10 most recent valid logons. This value can be set to any value between 0 and 50. By default, all versions of the Windows operating system remember 10 cached logons, except Windows Server 2008 and later, which are set at 25. -When you try to log on to a domain from a Windows-based client device, and a domain controller is unavailable, you do not receive an error message. Therefore, you may not notice that you logged on with cached domain credentials. You can set a notification of logon that uses cached domain credentials with the ReportDC registry entry. +When you try to sign in to a domain from a Windows-based client device, and a domain controller is unavailable, you don't receive an error message. Therefore, you may not notice that you logged on with cached domain credentials. You can set a notification of a sign in that uses cached domain credentials with the ReportDC registry entry. ### Potential impact -Users are forced to type passwords whenever they log on to their Microsoft Account or other network resources that are not accessible to their domain account. This policy setting should have no impact on users who access network resources that are configured to allow access with their Active Directory–based domain account. +Users are forced to type passwords whenever they sign in to their Microsoft Account or other network resources that aren't accessible to their domain account. This policy setting should have no impact on users who access network resources that are configured to allow access with their Active Directory–based domain account. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-let-everyone-permissions-apply-to-anonymous-users.md b/windows/security/threat-protection/security-policy-settings/network-access-let-everyone-permissions-apply-to-anonymous-users.md index 542bd046ed..5984f7aa39 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-let-everyone-permissions-apply-to-anonymous-users.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-let-everyone-permissions-apply-to-anonymous-users.md @@ -27,9 +27,9 @@ Describes the best practices, location, values, policy management and security c ## Reference -This policy setting determines what additional permissions are granted for anonymous connections to the device. If you enable this policy setting, anonymous users can enumerate the names of domain accounts and shared folders and perform certain other activities. This capability is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust. +This policy setting determines what other permissions are granted for anonymous connections to the device. If you enable this policy setting, anonymous users can enumerate the names of domain accounts and shared folders and perform certain other activities. This capability is convenient, for example, when an administrator wants to grant access to users in a trusted domain that doesn't maintain a reciprocal trust. -By default, the token that is created for anonymous connections does not include the Everyone SID. Therefore, permissions that are assigned to the Everyone group do not apply to anonymous users. +By default, the token that is created for anonymous connections doesn't include the Everyone SID. Therefore, permissions that are assigned to the Everyone group don't apply to anonymous users. ### Possible values @@ -70,7 +70,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -86,7 +86,7 @@ Disable the **Network access: Let Everyone permissions apply to anonymous users* ### Potential impact -None. This is the default configuration. +None. This non-impact state is the default configuration. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-named-pipes-that-can-be-accessed-anonymously.md b/windows/security/threat-protection/security-policy-settings/network-access-named-pipes-that-can-be-accessed-anonymously.md index 78c22e2c43..ee23e0432c 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-named-pipes-that-can-be-accessed-anonymously.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-named-pipes-that-can-be-accessed-anonymously.md @@ -38,7 +38,7 @@ Restricting access over named pipes such as COMNAP and LOCATOR helps prevent una ### Best practices -- Set this policy to a null value; that is, enable the policy setting, but do not enter named pipes in the text box. This will disable null session access over named pipes, and applications that rely on this feature or on unauthenticated access to named pipes will no longer function. +- Set this policy to a null value; that is, enable the policy setting, but don't enter named pipes in the text box. This setting will disable null session access over named pipes, and applications that rely on this feature or on unauthenticated access to named pipes will no longer function. ### Location @@ -63,7 +63,7 @@ This section describes different features and tools available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -90,11 +90,11 @@ You can restrict access over named pipes such as COMNAP and LOCATOR to help prev ### Countermeasure -Configure the **Network access: Named Pipes that can be accessed anonymously** setting to a null value (enable the setting but do not specify named pipes in the text box). +Configure the **Network access: Named Pipes that can be accessed anonymously** setting to a null value (enable the setting but don't specify named pipes in the text box). ### Potential impact -This configuration disables null-session access over named pipes, and applications that rely on this feature or on unauthenticated access to named pipes no longer function. This may break trust between Windows Server 2003 domains in a mixed mode environment. +This configuration disables null-session access over named pipes, and applications that rely on this feature or on unauthenticated access to named pipes no longer function. This result may break trust between Windows Server 2003 domains in a mixed mode environment. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths-and-subpaths.md b/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths-and-subpaths.md index 1f5a821007..7a130c03eb 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths-and-subpaths.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths-and-subpaths.md @@ -41,7 +41,7 @@ To allow remote access, you must also enable the Remote Registry service. ### Best practices -- Set this policy to a null value; that is, enable the policy setting, but do not enter any paths in the text box. Remote management tools, such as the Microsoft Baseline Security Analyzer and Configuration Manager, require remote access to the registry. Removing the default registry paths from the list of accessible paths might cause these and other management tools to fail. +- Set this policy to a null value; that is, enable the policy setting, but don't enter any paths in the text box. Remote management tools, such as the Microsoft Baseline Security Analyzer and Configuration Manager, require remote access to the registry. Removing the default registry paths from the list of accessible paths might cause these and other management tools to fail. ### Location @@ -80,7 +80,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -92,7 +92,7 @@ The registry contains sensitive device configuration information that could be u ### Countermeasure -Configure the **Network access: Remotely accessible registry paths and sub-paths** setting to a null value (enable the setting but do not enter any paths in the text box). +Configure the **Network access: Remotely accessible registry paths and sub-paths** setting to a null value (enable the setting but don't enter any paths in the text box). ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths.md b/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths.md index fe4a3d425e..746ada8c10 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-remotely-accessible-registry-paths.md @@ -40,7 +40,7 @@ To allow remote access, you must also enable the Remote Registry service. ### Best practices -- Set this policy to a null value; that is, enable the policy setting but do not enter any paths in the text box. Remote management tools, such as the Microsoft Baseline Security Analyzer and Configuration Manager, require remote access to the registry. Removing the default registry paths from the list of accessible paths might cause these and other management tools to fail. +- Set this policy to a null value; that is, enable the policy setting but don't enter any paths in the text box. Remote management tools, such as the Microsoft Baseline Security Analyzer and Configuration Manager, require remote access to the registry. Removing the default registry paths from the list of accessible paths might cause these and other management tools to fail. ### Location @@ -71,7 +71,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -83,7 +83,7 @@ An attacker could use information in the registry to facilitate unauthorized act ### Countermeasure -Configure the **Network access: Remotely accessible registry paths** setting to a null value (enable the setting, but do not enter any paths in the text box). +Configure the **Network access: Remotely accessible registry paths** setting to a null value (enable the setting, but don't enter any paths in the text box). ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/network-access-restrict-anonymous-access-to-named-pipes-and-shares.md b/windows/security/threat-protection/security-policy-settings/network-access-restrict-anonymous-access-to-named-pipes-and-shares.md index 57dc9bbbb8..9bc2a12af5 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-restrict-anonymous-access-to-named-pipes-and-shares.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-restrict-anonymous-access-to-named-pipes-and-shares.md @@ -40,7 +40,7 @@ Null sessions are a weakness that can be exploited through the various shared fo ### Best practices -- Set this policy to Enabled. Enabling this policy setting restricts null session access to unauthenticated users to all server pipes and shared folders except those listed in the **NullSessionPipes** and **NullSessionShares** registry entries. +- Set this policy to Enabled. Enabling this policy setting restricts null session access to unauthenticated users to all server pipes and shared folders except those server pipes and shared folders listed in the **NullSessionPipes** and **NullSessionShares** registry entries. ### Location @@ -65,7 +65,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -81,7 +81,7 @@ Enable the **Network access: Restrict anonymous access to Named Pipes and Shares ### Potential impact -You can enable this policy setting to restrict null-session access for unauthenticated users to all server pipes and shared folders except those that are listed in the NullSessionPipes and NullSessionShares entries. +You can enable this policy setting to restrict null-session access for unauthenticated users to all server pipes and shared folders except those server pipes and shared folders that are listed in the NullSessionPipes and NullSessionShares entries. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md index 9ffa1041c1..3193b11f86 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md @@ -34,7 +34,7 @@ The setting was first supported by Windows 10 version 1607 and Windows Server 20 This topic describes the default values for this security policy setting in different versions of Windows. By default, computers beginning with Windows 10 version 1607 and Windows Server 2016 are more restrictive than earlier versions of Windows. -This means that if you have a mix of computers, such as member servers that run both Windows Server 2016 and Windows Server 2012 R2, the servers that run Windows Server 2016 may fail to enumerate accounts by default where the servers that run Windows Server 2012 R2 succeed. +This restrictive characteristic means that if you have a mix of computers, such as member servers that run both Windows Server 2016 and Windows Server 2012 R2, the servers that run Windows Server 2016 may fail to enumerate accounts by default where the servers that run Windows Server 2012 R2 succeed. This topic also covers related events, and how to enable audit mode before constraining the security principals that are allowed to remotely enumerate users and groups so that your environment remains secure without impacting application compatibility. @@ -50,14 +50,14 @@ This information can provide important context and serve as a starting point for To mitigate this risk, you can configure the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting to force the security accounts manager (SAM) to do an access check against remote calls. The access check allows or denies remote RPC connections to SAM and Active Directory for users and groups that you define. -By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting is not defined. +By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to the SAM. -If the policy setting is left blank after the policy is defined, the policy is not enforced. +If the policy setting is left blank after the policy is defined, the policy isn't enforced. The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers, and allows Everyone access on domain controllers. You can edit the default security descriptor to allow or deny other users and groups, including the built-in Administrators. -The default security descriptor on computers that run earlier versions of Windows does not restrict any remote calls to SAM, but an administrator can edit the security descriptor to enforce restrictions. +The default security descriptor on computers that run earlier versions of Windows doesn't restrict any remote calls to SAM, but an administrator can edit the security descriptor to enforce restrictions. This less restrictive default allows for testing the impact of enabling restrictions on existing applications. ## Policy and Registry Names @@ -72,7 +72,7 @@ This less restrictive default allows for testing the impact of enabling restrict | **Registry value** | A string that will contain the SDDL of the security descriptor to be deployed. | The Group Policy setting is only available on computers that run Windows Server 2016 or Windows 10, version 1607 and later. -This is the only option to configure this setting by using a user interface (UI). +These computers are the only option to configure this setting by using a user interface (UI). On computers that run earlier versions of Windows, you need to edit the registry setting directly or use Group Policy Preferences. To avoid setting it manually in this case, you can configure the GPO itself on a computer that runs Windows Server 2016 or Windows 10, version 1607 or later and have it apply to all computers within the scope of the GPO because the same registry key exists on every computer after the corresponding KB is installed. @@ -102,7 +102,7 @@ This section explains how to configure audit-only mode, how to analyze related e ### Audit only mode -Audit only mode configures the SAMRPC protocol to do the access check against the currently configured security descriptor but will not fail the call if the access check fails. Instead, the call will be allowed, but SAMRPC will log an event describing what would have happened if the feature had been enabled. This provides administrators a way to test their applications before enabling the policy in production. Audit only mode is not configured by default. To configure it, add the following registry setting. +Audit-only mode configures the SAMRPC protocol to do the access check against the currently configured security descriptor but won't fail the call if the access check fails. Instead, the call will be allowed, but SAMRPC will log an event describing what would have happened if the feature had been enabled. This mode provides administrators a way to test their applications before enabling the policy in production. Audit only mode isn't configured by default. To configure it, add the following registry setting. |Registry|Details| |---|---| @@ -110,7 +110,7 @@ Audit only mode configures the SAMRPC protocol to do the access check against th |Setting|RestrictRemoteSamAuditOnlyMode| |Data Type|REG_DWORD| |Value|1| -|Notes|This setting cannot be added or removed by using predefined Group Policy settings.
Administrators may create a custom policy to set the registry value if needed.
SAM responds dynamically to changes in this registry value without a reboot.
You can use the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script to parse the event logs, as explained in the next section.| +|Notes|This setting can't be added or removed by using predefined Group Policy settings.
Administrators may create a custom policy to set the registry value if needed.
SAM responds dynamically to changes in this registry value without a reboot.
You can use the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script to parse the event logs, as explained in the next section.| ### Related events @@ -130,7 +130,7 @@ There are corresponding events that indicate when remote calls to the SAM are re |16966|Audit Mode is enabled-

Message Text: "Audit only mode is now enabled for remote calls to the SAM database. SAM will log an event for clients who would have been denied access in normal mode. %n"|Emit event whenever training mode (see 16968) is enabled or disabled. |16967|Audit Mode is disabled-

Message Text: "Audit only mode is now disabled for remote calls to the SAM database.%n For more information"|Emit event whenever training mode (see 16968) is enabled or disabled. |16968| Message Text: "Audit only mode is currently enabled for remote calls to the SAM database.%n The following client would have been normally denied access:%nClient SID: %1 from network address: %2. %n"
%1- "Client SID:"
%2- "Client Network Address:"|Emit event when access would have been denied to a remote client, but was allowed through due to training mode being enabled. Event should include identity and network address of the client.| -|16969|Message Text: "%2 remote calls to the SAM database have been denied in the past %1 seconds throttling window.%n
"%1- "Throttle window:"
%2- "Suppressed Message Count:"| Throttling may be necessary for some events due to expected high volume on some servers causing the event log to wrap.

Note: There is no throttling of events when audit mode is enabled. Environments with a large number of low-privilege and anonymous querying of the remote database may see large numbers of events logged to the System log. For more info, see the [Event Throttling](#event-throttling) section. +|16969|Message Text: "%2 remote calls to the SAM database have been denied in the past %1-seconds throttling window.%n
"%1- "Throttle window:"
%2- "Suppressed Message Count:"| Throttling may be necessary for some events due to expected high volume on some servers causing the event log to wrap.

Note: There's no throttling of events when audit mode is enabled. Environments with a large number of low-privilege and anonymous querying of the remote database may see large numbers of events logged to the System log. For more info, see the [Event Throttling](#event-throttling) section. Compare the security context attempting to remotely enumerate accounts with the default security descriptor. Then edit the security descriptor to add accounts that require remote access. @@ -143,11 +143,11 @@ Setting |RestrictRemoteSamEventThrottlingWindow| Data Type |DWORD| |Value|seconds| |Reboot Required?|No| -|Notes|**Default** is 900 seconds – 15mins.
The throttling uses a suppressed events counter which starts at 0 and gets incremented during the throttling window.
For example, X events were suppressed in the last 15 minutes.
The counter is restarted after the event 16969 is logged. +|Notes|**Default** is 900 seconds – 15 mins.
The throttling uses a suppressed events counter that starts at 0 and gets incremented during the throttling window.
For example, X events were suppressed in the last 15 minutes.
The counter is restarted after the event 16969 is logged. ### Restart requirement -Restarts are not required to enable, disable or modify the **Network access: Restrict clients allowed to make remote calls to SAM security** policy setting, including audit only mode. Changes become effective without a device restart when they are saved locally or distributed through Group Policy. +Restarts aren't required to enable, disable or modify the **Network access: Restrict clients allowed to make remote calls to SAM security** policy setting, including audit only mode. Changes become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -158,7 +158,7 @@ The SAMRPC protocol has a default security posture that makes it possible for lo The following example illustrates how an attacker might exploit remote SAM enumeration: 1. A low-privileged attacker gains a foothold on a network. 2. The attacker then queries all machines on the network to determine which ones have a highly privileged domain user configured as a local administrator on that machine. -3. If the attacker can then find any other vulnerability on that machine that allows taking it over, the attacker can then squat on the machine waiting for the high-privileged user to logon and then steal or impersonate those credentials. +3. If the attacker can, then find any other vulnerability on that machine that allows taking it over, the attacker can then squat on the machine waiting for the high-privileged user to sign in and then steal or impersonate those credentials. ### Countermeasure You can mitigate this vulnerability by enabling the **Network access: Restrict clients allowed to make remote calls** to SAM security policy setting and configuring the SDDL for only those accounts that are explicitly allowed access. diff --git a/windows/security/threat-protection/security-policy-settings/network-access-shares-that-can-be-accessed-anonymously.md b/windows/security/threat-protection/security-policy-settings/network-access-shares-that-can-be-accessed-anonymously.md index 0e8c62d1a3..8886a5ba0a 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-shares-that-can-be-accessed-anonymously.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-shares-that-can-be-accessed-anonymously.md @@ -36,7 +36,7 @@ This policy setting determines which shared folders can be accessed by anonymous ### Best practices -- Set this policy to a null value. There should be little impact because this is the default value. All users will have to be authenticated before they can access shared resources on the server. +- Set this policy to a null value. There should be little impact because this null value is the default one. All users will have to be authenticated before they can access shared resources on the server. ### Location @@ -61,7 +61,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -77,7 +77,7 @@ Configure the **Network access: Shares that can be accessed anonymously** settin ### Potential impact -There should be little impact because this is the default configuration. Only authenticated users have access to shared resources on the server. +There should be little impact because this state is the default configuration. Only authenticated users have access to shared resources on the server. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-access-sharing-and-security-model-for-local-accounts.md b/windows/security/threat-protection/security-policy-settings/network-access-sharing-and-security-model-for-local-accounts.md index f4a400c044..c13b8ecea9 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-sharing-and-security-model-for-local-accounts.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-sharing-and-security-model-for-local-accounts.md @@ -32,7 +32,7 @@ This policy setting determines how network logons that use local accounts are au >**Note:**  This policy setting does not affect network logons that use domain accounts. Nor does this policy setting affect interactive logons that are performed remotely through services such as Telnet or Remote Desktop Services. When the device is not joined to a domain, this policy setting also tailors the **Sharing** and **Security** tabs in Windows Explorer to correspond to the sharing and security model that is being used. -When the value of this policy setting is **Guest only - local users authenticate as Guest**, any user who can access your device over the network does so with Guest user rights. This means that they will probably be unable to write to shared folders. Although this does increase security, it makes it impossible for authorized users to access shared resources on those systems. When the value is **Classic - local users authenticate as themselves**, local accounts must be password-protected; otherwise, anyone can use those user accounts to access shared system resources. +When the value of this policy setting is **Guest only - local users authenticate as Guest**, any user who can access your device over the network does so with Guest user rights. This privilege means that they'll probably be unable to write to shared folders. Although this restriction does increase security, it makes it impossible for authorized users to access shared resources on those systems. When the value is **Classic - local users authenticate as themselves**, local accounts must be password-protected; otherwise, anyone can use those user accounts to access shared system resources. ### Possible values @@ -68,11 +68,11 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy -This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy is not contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. +This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy isn't contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. ## Security considerations @@ -80,7 +80,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -With the Guest only model, any user who can authenticate to your device over the network does so with Guest privileges, which probably means that they do not have Write access to shared resources on that device. Although this restriction does increase security, it makes it more difficult for authorized users to access shared resources on those computers because ACLs on those resources must include access control entries (ACEs) for the Guest account. With the Classic model, local accounts should be password protected. Otherwise, if Guest access is enabled, anyone can use those user accounts to access shared system resources. +With the Guest only model, any user who can authenticate to your device over the network does so with Guest privileges, which probably means that they don't have Write access to shared resources on that device. Although this restriction does increase security, it makes it more difficult for authorized users to access shared resources on those computers because ACLs on those resources must include access control entries (ACEs) for the Guest account. With the Classic model, local accounts should be password protected. Otherwise, if Guest access is enabled, anyone can use those user accounts to access shared system resources. ### Countermeasure @@ -88,7 +88,7 @@ For network servers, configure the **Network access: Sharing and security model ### Potential impact -None. This is the default configuration. +None. This non-impact state is the default configuration. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-allow-local-system-to-use-computer-identity-for-ntlm.md b/windows/security/threat-protection/security-policy-settings/network-security-allow-local-system-to-use-computer-identity-for-ntlm.md index 261dd0a213..2b7a73365a 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-allow-local-system-to-use-computer-identity-for-ntlm.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-allow-local-system-to-use-computer-identity-for-ntlm.md @@ -35,9 +35,9 @@ When a service connects with the device identity, signing and encryption are sup | Setting | Windows Server 2008 and Windows Vista | At least Windows Server 2008 R2 and Windows 7 | | - | - | - | -| Enabled | Services running as Local System that use Negotiate will use the computer identity. This value might cause some authentication requests between Windows operating systems to fail and log an error.| Services running as Local System that use Negotiate will use the computer identity. This is the default behavior. | -| Disabled| Services running as Local System that use Negotiate when reverting to NTLM authentication will authenticate anonymously. This is the default behavior.| Services running as Local System that use Negotiate when reverting to NTLM authentication will authenticate anonymously.| -|Neither|Services running as Local System that use Negotiate when reverting to NTLM authentication will authenticate anonymously. | Services running as Local System that use Negotiate will use the computer identity. This might cause some authentication requests between Windows operating systems to fail and log an error.| +| Enabled | Services running as Local System that use Negotiate will use the computer identity. This value might cause some authentication requests between Windows operating systems to fail and log an error.| Services running as Local System that use Negotiate will use the computer identity. This behavior is the default behavior. | +| Disabled| Services running as Local System that uses Negotiate when reverting to NTLM authentication will authenticate anonymously. This behavior is the default behavior.| Services running as Local System that uses Negotiate when reverting to NTLM authentication will authenticate anonymously.| +|Neither|Services running as Local System that uses Negotiate when reverting to NTLM authentication will authenticate anonymously. | Services running as Local System that uses Negotiate will use the computer identity. This behavior might cause some authentication requests between Windows operating systems to fail and log an error.| ### Location @@ -61,17 +61,17 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Policy conflict considerations -The policy [Network security: Allow LocalSystem NULL session fallback](network-security-allow-localsystem-null-session-fallback.md), if enabled, will allow NTLM or Kerberos authentication to be used when a system service attempts authentication. This will increase the success of interoperability at the expense of security. +The policy [Network security: Allow LocalSystem NULL session fallback](network-security-allow-localsystem-null-session-fallback.md), if enabled, will allow NTLM or Kerberos authentication to be used when a system service attempts authentication. This privilege will increase the success of interoperability at the expense of security. The anonymous authentication behavior is different for Windows Server 2008 and Windows Vista than later versions of Windows. Configuring and applying this policy setting on those systems might not produce the same results. ### Group Policy -This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy is not contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. +This policy setting can be configured by using the Group Policy Management Console (GPMC) to be distributed through Group Policy Objects (GPOs). If this policy isn't contained in a distributed GPO, this policy can be configured on the local computer by using the Local Security Policy snap-in. ## Security considerations @@ -89,7 +89,7 @@ You can configure the **Network security: Allow Local System to use computer ide ### Potential impact -If you do not configure this policy setting on Windows Server 2008 and Windows Vista, services running as Local System that use the default credentials will use the NULL session and revert to NTLM authentication for Windows operating systems earlier than Windows Vista or Windows Server 2008. +If you don't configure this policy setting on Windows Server 2008 and Windows Vista, services running as Local System that uses the default credentials will use the NULL session and revert to NTLM authentication for Windows operating systems earlier than Windows Vista or Windows Server 2008. Beginning with Windows Server 2008 R2 and Windows 7, the system allows Local System services that use Negotiate to use the computer identity when reverting to NTLM authentication. ## Related articles diff --git a/windows/security/threat-protection/security-policy-settings/network-security-allow-localsystem-null-session-fallback.md b/windows/security/threat-protection/security-policy-settings/network-security-allow-localsystem-null-session-fallback.md index 401a588948..271d990f14 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-allow-localsystem-null-session-fallback.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-allow-localsystem-null-session-fallback.md @@ -28,7 +28,7 @@ Describes the best practices, location, values, and security considerations for ## Reference This policy affects session security during the authentication process between devices running Windows Server 2008 R2 and Windows 7 and later and those devices running earlier versions of the Windows operating system. For computers running Windows Server 2008 R2 and Windows 7 and later, services running as Local System require a service principal name (SPN) to generate the session key. However, if [Network security: Allow Local System to use computer identity for NTLM](network-security-allow-local-system-to-use-computer-identity-for-ntlm.md) is set to disabled, services running as Local -System will fall back to using NULL session authentication when they transmit data to servers running versions of Windows earlier than Windows Vista or Windows Server 2008. NULL session does not establish a unique session key for each authentication; and thus, it cannot provide integrity or confidentiality protection. The setting **Network security: Allow LocalSystem NULL session fallback** determines whether services that request the use of session security are allowed to perform signature or encryption functions with a well-known key for application compatibility. +System will fall back to using NULL session authentication when they transmit data to servers running versions of Windows earlier than Windows Vista or Windows Server 2008. NULL session doesn't establish a unique session key for each authentication; and thus, it can't provide integrity or confidentiality protection. The setting **Network security: Allow LocalSystem NULL session fallback** determines whether services that request the use of session security are allowed to perform signature or encryption functions with a well-known key for application compatibility. ### Possible values @@ -41,13 +41,13 @@ System will fall back to using NULL session authentication when they transmit da When a service running as Local System connects with a NULL session, session security will be unavailable. Calls seeking encryption or signing will fail. This setting is more secure, but at the risk of degrading application incompatibility. Calls that are using the device identity instead of a NULL session will still have full use of session security. -- Not defined. When this policy is not defined, the default takes effect. This is Enabled for versions of the Windows operating system earlier than Windows Server 2008 R2 and Windows 7, and it is Disabled otherwise. +- Not defined. When this policy isn't defined, the default takes effect. This policy is Enabled for versions of the Windows operating system earlier than Windows Server 2008 R2 and Windows 7, and it's Disabled otherwise. ### Best practices -When services connect with the device identity, signing and encryption are supported to provide data protection. When services connect with a NULL session, this level of data protection is not provided. However, you will need to evaluate your environment to determine the Windows operating system versions that you support. If this policy is enabled, some services may not be able to authenticate. +When services connect with the device identity, signing and encryption are supported to provide data protection. When services connect with a NULL session, this level of data protection isn't provided. However, you'll need to evaluate your environment to determine the Windows operating system versions that you support. If this policy is enabled, some services may not be able to authenticate. -This policy applies to Windows Server 2008 and Windows Vista (SP1 and later). When your environment no longer requires support for Windows NT 4, this policy should be disabled. By default, it is disabled in Windows 7 and Windows Server 2008 R2 and later. +This policy applies to Windows Server 2008 and Windows Vista (SP1 and later). When your environment no longer requires support for Windows NT 4, this policy should be disabled. By default, it's disabled in Windows 7 and Windows Server 2008 R2 and later. ### Location @@ -74,11 +74,11 @@ If this setting is Enabled, when a service connects with a NULL session, a syste ### Countermeasure -You can configure the computer to use the computer identity for Local System with the policy **Network security: Allow Local System to use computer identity for NTLM**. If that is not possible, this policy can be used to prevent data from being exposed in transit if it was protected with a well-known key. +You can configure the computer to use the computer identity for Local System with the policy **Network security: Allow Local System to use computer identity for NTLM**. If that isn't possible, this policy can be used to prevent data from being exposed in transit if it was protected with a well-known key. ### Potential impact -If you enable this policy, services that use NULL session with Local System could fail to authenticate because they will be prohibited from using signing and encryption. +If you enable this policy, services that use NULL session with Local System could fail to authenticate because they'll be prohibited from using signing and encryption. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-allow-pku2u-authentication-requests-to-this-computer-to-use-online-identities.md b/windows/security/threat-protection/security-policy-settings/network-security-allow-pku2u-authentication-requests-to-this-computer-to-use-online-identities.md index 1c229713a8..093d8db29f 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-allow-pku2u-authentication-requests-to-this-computer-to-use-online-identities.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-allow-pku2u-authentication-requests-to-this-computer-to-use-online-identities.md @@ -27,18 +27,18 @@ This article describes the best practices, location, and values for the **Networ ## Reference -Starting with Windows Server 2008 R2 and Windows 7, the Negotiate Security Support Provider (SSP) supports an extension SSP, Negoexts.dll. This extension SSP is treated as an authentication protocol by the Windows operating system. It supports SSPs from Microsoft, including PKU2U. You can also develop or add other SSPs. +From Windows Server 2008 R2 and Windows 7, the Negotiate Security Support Provider (SSP) supports an extension SSP, Negoexts.dll. This extension SSP is treated as an authentication protocol by the Windows operating system. It supports SSPs from Microsoft, including PKU2U. You can also develop or add other SSPs. -When devices are configured to accept authentication requests by using online IDs, Negoexts.dll calls the PKU2U SSP on the computer that's used to log on. The PKU2U SSP obtains a local certificate and exchanges the policy between the peer computers. When it's validated on the peer computer, the certificate within the metadata is sent to the logon peer for validation. It associates the user's certificate to a security token, and then the logon process completes. +When devices are configured to accept authentication requests by using online IDs, Negoexts.dll calls the PKU2U SSP on the computer that's used to sign in. The PKU2U SSP obtains a local certificate and exchanges the policy between the peer computers. When it's validated on the peer computer, the certificate within the metadata is sent to the sign-in peer for validation. It associates the user's certificate to a security token, and then the sign-in process completes. > [!NOTE] > Linking online IDs can be performed by anyone who has an account that has standard user’s credentials through Credential Manager. -This policy isn't configured by default on domain-joined devices. This would disallow the online identities to authenticate to domain-joined computers from Windows 7 up to Windows 10, Version 1607. This policy is enabled by default in Windows 10, Version 1607, and later. +This policy isn't configured by default on domain-joined devices. This disablement would disallow the online identities to authenticate to domain-joined computers from Windows 7 up to Windows 10, Version 1607. This policy is enabled by default in Windows 10, Version 1607, and later. ### Possible values -- **Enabled**: This setting allows authentication to successfully complete between the two (or more) computers that have established a peer relationship through the use of online IDs. The PKU2U SSP obtains a local certificate and exchanges the policy between the peer devices. When validated on the peer computer, the certificate within the metadata is sent to the logon peer for validation. It associates the user's certificate to a security token, and then the logon process completes. +- **Enabled**: This setting allows authentication to successfully complete between the two (or more) computers that have established a peer relationship by using online IDs. The PKU2U SSP obtains a local certificate and exchanges the policy between the peer devices. When validated on the peer computer, the certificate within the metadata is sent to the sign-in peer for validation. It associates the user's certificate to a security token, and then the sign-in process completes. > [!NOTE] > PKU2U is disabled by default on Windows Server. If PKU2U is disabled, Remote Desktop connections from a hybrid Azure AD-joined server to an Azure AD-joined Windows 10 device or a Hybrid Azure AD-joined domain member Windows 10 device fail. To resolve this, enable PKU2U on the server and the client. @@ -75,7 +75,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -Enabling this policy setting allows a user’s account on one computer to be associated with an online identity, such as Microsoft account or an Azure AD account. That account can then log on to a peer device (if the peer device is likewise configured) without the use of a Windows logon account (domain or local). This setup is not only beneficial, but required for Azure AD-joined devices, where they are signed in with an online identity and are issued certificates by Azure AD. This policy may not be relevant for an *on-premises only* environment and might circumvent established security policies. However, it does not pose any threats in a hybrid environment where Azure AD is used as it relies on the user's online identity and Azure AD to authenticate. +Enabling this policy setting allows a user’s account on one computer to be associated with an online identity, such as Microsoft account or an Azure AD account. That account can then sign in to a peer device (if the peer device is likewise configured) without the use of a Windows sign-in account (domain or local). This setup isn't only beneficial, but required for Azure AD-joined devices, where they're signed in with an online identity and are issued certificates by Azure AD. This policy may not be relevant for an *on-premises only* environment and might circumvent established security policies. However, it doesn't pose any threats in a hybrid environment where Azure AD is used as it relies on the user's online identity and Azure AD to authenticate. ### Countermeasure @@ -83,9 +83,9 @@ Set this policy to *Disabled* or don't configure this security policy for *on-pr ### Potential impact -If you don't set or you disable this policy, the PKU2U protocol won't be used to authenticate between peer devices, which forces users to follow domain-defined access control policies. This is a valid configuration in *on-premises only* environments. Please be aware that some roles/features (such as Failover Clustering) do not utilize a domain account for its PKU2U authentication and will cease to function properly when disabling this policy. +If you don't set or you disable this policy, the PKU2U protocol won't be used to authenticate between peer devices, which forces users to follow domain-defined access control policies. This disablement is a valid configuration in *on-premises only* environments. Some roles/features (such as Failover Clustering) don't utilize a domain account for its PKU2U authentication and will cease to function properly when disabling this policy. -If you enable this policy in a hybrid environment, you allow your users to authenticate by using certificates issued by Azure AD and their online identity between the corresponding devices. This configuration allows users to share resources between such devices. Without enabling this policy, remote connections to an Azure AD joined device will not work. +If you enable this policy in a hybrid environment, you allow your users to authenticate by using certificates issued by Azure AD and their online identity between the corresponding devices. This configuration allows users to share resources between such devices. If this policy isn't enabled, remote connections to an Azure AD joined device won't work. ### Fix/Remediation diff --git a/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos.md b/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos.md index bcaef6d811..afe9be35da 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos.md @@ -37,11 +37,11 @@ The following table lists and explains the allowed encryption types. | Encryption type | Description and version support | | - | - | | DES_CBC_CRC | Data Encryption Standard with Cipher Block Chaining using the Cyclic Redundancy Check function
Supported in Windows 2000 Server, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. The Windows 7, Windows 10, Windows Server 2008 R2, and later operating systems don't support DES by default. | -| DES_CBC_MD5| Data Encryption Standard with Cipher Block Chaining using the Message-Digest algorithm 5 checksum function
Supported in Windows 2000 Server, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. The Windows 7, Windows 10, Windows Server 2008 R2, and later operating systems do not support DES by default. | +| DES_CBC_MD5| Data Encryption Standard with Cipher Block Chaining using the Message-Digest algorithm 5 checksum function
Supported in Windows 2000 Server, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. The Windows 7, Windows 10, Windows Server 2008 R2, and later operating systems don't support DES by default. | | RC4_HMAC_MD5| Rivest Cipher 4 with Hashed Message Authentication Code using the Message-Digest algorithm 5 checksum function
Supported in Windows 2000 Server, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows 10, Windows Server 2008 R2, Windows Server 2012 and Windows Server 2012 R2.| | AES128_HMAC_SHA1| Advanced Encryption Standard in 128-bit cipher block with Hashed Message Authentication Code using the Secure Hash Algorithm (1).
Not supported in Windows 2000 Server, Windows XP, or Windows Server 2003. Supported in Windows Vista, Windows Server 2008, Windows 7, Windows 10, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2. | | AES256_HMAC_SHA1| Advanced Encryption Standard in 256-bit cipher block with Hashed Message Authentication Code using the Secure Hash Algorithm (1).
Not supported in Windows 2000 Server, Windows XP, or Windows Server 2003. Supported in Windows Vista, Windows Server 2008, Windows 7, Windows 10, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2. | -| Future encryption types| Reserved by Microsoft for additional encryption types that might be implemented.| +| Future encryption types| Reserved by Microsoft for other encryption types that might be implemented.| ### Possible values @@ -55,7 +55,7 @@ The encryption type options include: - AES256\_HMAC\_SHA1 - Future encryption types - As of the release of Windows 7 and Windows Server 2008 R2, this is reserved by Microsoft for additional encryption types that might be implemented. + As of the release of Windows 7 and Windows Server 2008 R2, these options are reserved by Microsoft for other encryption types that might be implemented. ### Best practices @@ -72,9 +72,9 @@ Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\Sec | Default domain policy| Not defined| | Default domain controller policy| Not defined| | Stand-alone server default settings | Not defined| -| Domain controller effective default settings | The default OS setting applies, DES suites are not supported by default.| -| Member server effective default settings | The default OS setting applies, DES suites are not supported by default.| -| Effective GPO default settings on client computers | The default OS setting applies, DES suites are not supported by default.| +| Domain controller effective default settings | The default OS setting applies, DES suites aren't supported by default.| +| Member server effective default settings | The default OS setting applies, DES suites aren't supported by default.| +| Effective GPO default settings on client computers | The default OS setting applies, DES suites aren't supported by default.| ## Security considerations @@ -87,14 +87,14 @@ Windows Server 2008 R2, Windows 7 and Windows 10. You can also disable DES fo ### Countermeasure -Do not configure this policy. This will force the computers running Windows Server 2008 R2, Windows 7, and Windows 10 to use the AES or RC4 cryptographic suites. +Don't configure this policy. This disablement will force the computers running Windows Server 2008 R2, Windows 7, and Windows 10 to use the AES or RC4 cryptographic suites. ### Potential impact If you don't select any of the encryption types, computers running Windows Server 2008 R2, Windows 7 and Windows 10, might have Kerberos authentication failures when connecting with computers running non-Windows versions of the Kerberos protocol. -If you do select any encryption type, you will lower the effectiveness of encryption for Kerberos authentication but you will improve interoperability with computers running older versions of Windows. +If you do select any encryption type, you'll lower the effectiveness of encryption for Kerberos authentication but you'll improve interoperability with computers running older versions of Windows. Contemporary non-Windows implementations of the Kerberos protocol support RC4 and AES 128-bit and AES 256-bit encryption. Most implementations, including the MIT Kerberos protocol and the Windows Kerberos protocol, are deprecating DES encryption. ## Related articles diff --git a/windows/security/threat-protection/security-policy-settings/network-security-do-not-store-lan-manager-hash-value-on-next-password-change.md b/windows/security/threat-protection/security-policy-settings/network-security-do-not-store-lan-manager-hash-value-on-next-password-change.md index ebf155ba56..e0ecaddc05 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-do-not-store-lan-manager-hash-value-on-next-password-change.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-do-not-store-lan-manager-hash-value-on-next-password-change.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management and security c This policy setting determines whether LAN Manager is prevented from storing hash values for the new password the next time the password is changed. Hash values are a representation of the password after the encryption algorithm is applied that corresponds to the format that is specified by the algorithm. To decrypt the hash value, the encryption algorithm must be determined and then reversed. The LAN Manager hash is relatively weak and prone to attack compared to the cryptographically stronger NTLM hash. Because the LM hash is stored on the local device in the security database, the passwords can be compromised if the security database, Security Accounts Manager (SAM), is attacked. -By attacking the SAM file, attackers can potentially gain access to user names and password hashes. Attackers can use a password-cracking tool to determine what the password is. After they have access to this information, they can use it to gain access to resources on your network by impersonating users. Enabling this policy setting will not prevent these types of attacks, but it will make them much more difficult. +When the attackers attack the SAM file, they can potentially gain access to user names and password hashes. Attackers can use a password-cracking tool to determine what the password is. After they have access to this information, they can use it to gain access to resources on your network by impersonating users. Enabling this policy setting won't prevent these types of attacks, but it will make them much more difficult. ### Possible values @@ -40,7 +40,7 @@ By attacking the SAM file, attackers can potentially gain access to user names a ### Best practices - Set **Network security: Do not store LAN Manager hash value on next password change** to **Enabled**. - - Require all users to set new passwords the next time they log on to the domain so that LAN Manager hashes are removed. + - Require all users to set new passwords the next time they sign in to the domain so that LAN Manager hashes are removed. ### Location @@ -65,7 +65,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -73,11 +73,11 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -The SAM file can be targeted by attackers who seek access to user names and password hashes. Such attacks use special tools to discover passwords, which can then be used to impersonate users and gain access to resources on your network. These types of attacks are not prevented by enabling this policy setting because LAN Manager hashes are much weaker than NTLM hashes, but it is much more difficult for these attacks to succeed. +The SAM file can be targeted by attackers who seek access to user names and password hashes. Such attacks use special tools to discover passwords, which can then be used to impersonate users and gain access to resources on your network. These types of attacks aren't prevented by enabling this policy setting because LAN Manager hashes are much weaker than NTLM hashes, but it's much more difficult for these attacks to succeed. ### Countermeasure -Enable the **Network security: Do not store LAN Manager hash value on next password change** setting. Require all users to set new passwords the next time they log on to the domain so that LAN Manager hashes are removed. +Enable the **Network security: Do not store LAN Manager hash value on next password change** setting. Require all users to set new passwords the next time they sign in to the domain so that LAN Manager hashes are removed. ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/network-security-force-logoff-when-logon-hours-expire.md b/windows/security/threat-protection/security-policy-settings/network-security-force-logoff-when-logon-hours-expire.md index daab389419..3bc3ec584c 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-force-logoff-when-logon-hours-expire.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-force-logoff-when-logon-hours-expire.md @@ -27,25 +27,25 @@ Describes the best practices, location, values, policy management, and security ## Reference -This security setting determines whether to disconnect users who are connected to the local device outside their user account's valid logon hours. This setting affects the Server Message Block (SMB) component. +This security setting determines whether to disconnect users who are connected to the local device outside their user account's valid sign-in hours. This setting affects the Server Message Block (SMB) component. -This policy setting does not apply to administrator accounts, but it behaves as an account policy. For domain accounts, there can be only one account policy. The account policy must be defined in the Default Domain Policy, and it is enforced by the domain controllers that make up the domain. A domain controller always pulls the account policy from the Default Domain Policy Group Policy Object (GPO), even if there is a different account policy that is applied to the organizational unit that contains the domain controller. By default, workstations and servers that are joined to a domain (for example, member devices) also receive the same account policy for their local accounts. However, local account policies for member devices can be different from the domain account policy by defining an account policy for the organizational unit that contains the member devices. Kerberos settings are not applied to member devices. +This policy setting doesn't apply to administrator accounts, but it behaves as an account policy. For domain accounts, there can be only one account policy. The account policy must be defined in the Default Domain Policy, and it's enforced by the domain controllers that make up the domain. A domain controller always pulls the account policy from the Default Domain Policy Group Policy Object (GPO), even if there's a different account policy that is applied to the organizational unit that contains the domain controller. By default, workstations and servers that are joined to a domain (for example, member devices) also receive the same account policy for their local accounts. However, local account policies for member devices can be different from the domain account policy by defining an account policy for the organizational unit that contains the member devices. Kerberos settings aren't applied to member devices. ### Possible values - Enabled - When enabled, this policy causes client sessions with the SMB server to be forcibly disconnected when the client's logon hours expire. + When enabled, this policy causes client sessions with the SMB server to be forcibly disconnected when the client's sign-in hours expire. - Disabled - When disabled, this policy allows for the continuation of an established client session after the client's logon hours have expired. + When disabled, this policy allows for the continuation of an established client session after the client's sign-in hours have expired. - Not defined ### Best practices -- Set **Network security: Force logoff when logon hours expire** to Enabled. SMB sessions will be terminated on member servers when a user's logon time expires, and the user will be unable to log on to the system until their next scheduled access time begins. +- Set **Network security: Force logoff when logon hours expire** to Enabled. SMB sessions will be terminated on member servers when a user's sign-in time expires, and the user will be unable to sign in to the system until their next scheduled access time begins. ### Location @@ -70,7 +70,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -78,15 +78,15 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -If you disable this policy setting, users can remain connected to the computer outside of their allotted logon hours. +If you disable this policy setting, users can remain connected to the computer outside of their allotted sign-in hours. ### Countermeasure -Enable the **Network security: Force logoff when logon hours expire** setting. This policy setting does not apply to administrator accounts. +Enable the **Network security: Force logoff when logon hours expire** setting. This policy setting doesn't apply to administrator accounts. ### Potential impact -When a user's logon time expires, SMB sessions terminate. The user cannot log on to the device until the next scheduled access time commences. +When a user's sign-in time expires, SMB sessions terminate. The user can't sign in to the device until the next scheduled access time commences. ## Related articles diff --git a/windows/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level.md b/windows/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level.md index fcd510671f..1841669403 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level.md @@ -27,15 +27,15 @@ Describes the best practices, location, values, policy management and security c ## Reference -This policy setting determines which challenge or response authentication protocol is used for network logons. LAN Manager (LM) includes client computer and server software from Microsoft that allows users to link personal devices together on a single network. Network capabilities include transparent file and print sharing, user security features, and network administration tools. In Active Directory domains, the Kerberos protocol is the default authentication protocol. However, if the Kerberos protocol is not negotiated for some reason, Active Directory uses LM, NTLM, or NTLM version 2 (NTLMv2). +This policy setting determines which challenge or response authentication protocol is used for network logons. LAN Manager (LM) includes client computer and server software from Microsoft that allows users to link personal devices together on a single network. Network capabilities include transparent file and print sharing, user security features, and network administration tools. In Active Directory domains, the Kerberos protocol is the default authentication protocol. However, if the Kerberos protocol isn't negotiated for some reason, Active Directory uses LM, NTLM, or NTLM version 2 (NTLMv2). -LAN Manager authentication includes the LM, NTLM, and NTLMv2 variants, and it is the protocol that is used to authenticate all client devices running the Windows operating system when they perform the following operations: +LAN Manager authentication includes the LM, NTLM, and NTLMv2 variants, and it's the protocol that is used to authenticate all client devices running the Windows operating system when they perform the following operations: - Join a domain - Authenticate between Active Directory forests - Authenticate to domains based on earlier versions of the Windows operating system -- Authenticate to computers that do not run Windows operating systems, beginning with Windows 2000 -- Authenticate to computers that are not in the domain +- Authenticate to computers that don't run Windows operating systems, beginning with Windows 2000 +- Authenticate to computers that aren't in the domain ### Possible values @@ -56,8 +56,8 @@ authentication level that servers accept. The following table identifies the pol | Send LM & NTLM – use NTLMv2 session security if negotiated | Client devices use LM and NTLM authentication, and they use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.| 1| | Send NTLM response only| Client devices use NTLMv1 authentication, and they use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.| 2| | Send NTLMv2 response only | Client devices use NTLMv2 authentication, and they use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.| 3| -| Send NTLMv2 response only. Refuse LM | Client devices use NTLMv2 authentication, and they use NTLMv2 session security if the server supports it. Domain controllers refuse to accept LM authentication, and they will accept only NTLM and NTLMv2 authentication.| 4| -| Send NTLMv2 response only. Refuse LM & NTLM | Client devices use NTLMv2 authentication, and they use NTLMv2 session security if the server supports it. Domain controllers refuse to accept LM and NTLM authentication, and they will accept only NTLMv2 authentication.| 5| +| Send NTLMv2 response only. Refuse LM | Client devices use NTLMv2 authentication, and they use NTLMv2 session security if the server supports it. Domain controllers refuse to accept LM authentication, and they'll accept only NTLM and NTLMv2 authentication.| 4| +| Send NTLMv2 response only. Refuse LM & NTLM | Client devices use NTLMv2 authentication, and they use NTLMv2 session security if the server supports it. Domain controllers refuse to accept LM and NTLM authentication, and they'll accept only NTLMv2 authentication.| 5| ### Best practices @@ -90,7 +90,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -106,11 +106,11 @@ In Windows 7 and Windows Vista, this setting is undefined. In Windows Server ### Countermeasure -Configure the **Network security: LAN Manager Authentication Level** setting to **Send NTLMv2 responses only**. Microsoft and a number of independent organizations strongly recommend this level of authentication when all client computers support NTLMv2. +Configure the **Network security: LAN Manager Authentication Level** setting to **Send NTLMv2 responses only**. Microsoft and many independent organizations strongly recommend this level of authentication when all client computers support NTLMv2. ### Potential impact -Client devices that do not support NTLMv2 authentication cannot authenticate in the domain and access domain resources by using LM and NTLM. +Client devices that don't support NTLMv2 authentication can't authenticate in the domain and access domain resources by using LM and NTLM. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-ldap-client-signing-requirements.md b/windows/security/threat-protection/security-policy-settings/network-security-ldap-client-signing-requirements.md index 006e925460..1f59bd9111 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-ldap-client-signing-requirements.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-ldap-client-signing-requirements.md @@ -30,8 +30,8 @@ This security policy reference topic for the IT professional describes the best This policy setting determines the level of data signing that is requested on behalf of client devices that issue LDAP BIND requests. The levels of data signing are described in the following list: - **None**. The LDAP BIND request is issued with the caller-specified options. -- **Negotiate signing**. If Transport Layer Security/Secure Sockets Layer (TLS/SSL) has not been started, the LDAP BIND request is initiated with the LDAP data signing option set in addition to the caller-specified options. If TLS/SSL has been started, the LDAP BIND request is initiated with the caller-specified options. -- **Require signing**. This level is the same as **Negotiate signing**. However, if the LDAP server's intermediate saslBindInProgress response does not indicate that LDAP traffic signing is required, the caller is returned a message that the LDAP BIND command request failed. +- **Negotiate signing**. If Transport Layer Security/Secure Sockets Layer (TLS/SSL) hasn't been started, the LDAP BIND request is initiated with the LDAP data signing option set in addition to the caller-specified options. If TLS/SSL has been started, the LDAP BIND request is initiated with the caller-specified options. +- **Require signing**. This level is the same as **Negotiate signing**. However, if the LDAP server's intermediate saslBindInProgress response doesn't indicate that LDAP traffic signing is required, the caller is returned a message that the LDAP BIND command request failed. Misuse of this policy setting is a common error that can cause data loss or problems with data access or security. @@ -44,7 +44,7 @@ Misuse of this policy setting is a common error that can cause data loss or prob ### Best practices -- Set both the **Network security: LDAP client signing requirements** and **Domain controller: LDAP server signing requirements** settings to **Require signing**. To avoid usage of unsigned traffic, set both client and server sides to require signing. Not setting one of the sides will prevent client computers from communicating with the server. This can cause many features to fail, including user authentication, Group Policy, and logon scripts. +- Set both the **Network security: LDAP client signing requirements** and **Domain controller: LDAP server signing requirements** settings to **Require signing**. To avoid usage of unsigned traffic, set both client and server sides to require signing. Not setting one of the sides will prevent client computers from communicating with the server. This prevention can cause many features to fail, including user authentication, Group Policy, and logon scripts. ### Location @@ -69,7 +69,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -81,7 +81,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -Unsigned network traffic is susceptible to man-in-the-middle attacks in which an intruder captures the packets between the client computer and server, modifies them, and then forwards them to the server. For an LDAP server, this susceptibility means that an attacker could cause a server to make decisions that are based on false or altered data from the LDAP queries. To lower this risk in your network, you can implement strong physical security measures to protect the network infrastructure. Also, you can make all types of man-in-the-middle attacks extremely difficult if you require digital signatures on all network packets by means of IPsec authentication headers. +Unsigned network traffic is susceptible to man-in-the-middle attacks in which an intruder captures the packets between the client computer and server, modifies them, and then forwards them to the server. For an LDAP server, this susceptibility means that an attacker could cause a server to make decisions that are based on false or altered data from the LDAP queries. To lower this risk in your network, you can implement strong physical security measures to protect the network infrastructure. Also, you can make all types of man-in-the-middle attacks difficult if you require digital signatures on all network packets throughs IPsec authentication headers. ### Countermeasure @@ -89,7 +89,7 @@ Configure the **Network security: LDAP client signing requirements** setting to ### Potential impact -If you configure the client to require LDAP signatures, it may fail to communicate with the LDAP servers that do not require requests to be signed. To avoid this issue, make sure that both the **Network security: LDAP client signing requirements** and **Domain controller: LDAP server signing requirements** settings are set to **Require signing**. +If you configure the client to require LDAP signatures, it may fail to communicate with the LDAP servers that don't require requests to be signed. To avoid this issue, make sure that both the **Network security: LDAP client signing requirements** and **Domain controller: LDAP server signing requirements** settings are set to **Require signing**. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers.md b/windows/security/threat-protection/security-policy-settings/network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers.md index d606dc935b..026f314358 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers.md @@ -33,13 +33,13 @@ Setting all of these values for this policy setting will help protect network tr ### Possible values -- Require 128-bit encryption. The connection fails if strong encryption (128-bit) is not negotiated. -- Require NTLMv2 session security. The connection fails if the NTLMv2 protocol is not negotiated. +- Require 128-bit encryption. The connection fails if strong encryption (128-bit) isn't negotiated. +- Require NTLMv2 session security. The connection fails if the NTLMv2 protocol isn't negotiated. - Not Defined. ### Best practices -- Enable all values that are available for this security policy. Legacy client devices that do not support these policy settings will be unable to communicate with the server. +- Enable all values that are available for this security policy. Legacy client devices that don't support these policy settings will be unable to communicate with the server. ### Location @@ -64,7 +64,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Policy dependencies @@ -84,7 +84,7 @@ Enable all options that are available for the **Network security: Minimum sessio ### Potential impact -Older client devices that do not support these security settings cannot communicate with the computer on which this policy is set. +Older client devices that don't support these security settings can't communicate with the computer on which this policy is set. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md index bf5804a540..828f91f36b 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md @@ -31,7 +31,7 @@ The **Network security: Restrict NTLM: Add remote server exceptions for NTLM aut If you configure this policy setting, you can define a list of remote servers to which client devices are allowed to use NTLM authentication. -If you do not configure this policy setting, no exceptions will be applied, and if [Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers](network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) is enabled, NTLM authentication attempts from the client devices will fail. +If you don't configure this policy setting, no exceptions will be applied, and if [Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers](network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) is enabled, NTLM authentication attempts from the client devices will fail. List the NetBIOS server names that are used by the applications as the naming format, one per line. To ensure exceptions, the names that are used by all applications need to be in the list. A single asterisk (\*) can be used anywhere in the string as a wildcard character. @@ -43,7 +43,7 @@ List the NetBIOS server names that are used by the applications as the naming fo - Not defined - If you do not configure this policy setting by defining a list of servers, the policy is undefined and no exceptions will be applied. + If you don't configure this policy setting by defining a list of servers, the policy is undefined and no exceptions will be applied. ### Best practices @@ -72,7 +72,7 @@ This section describes the features and tools that are available to help you man ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -90,7 +90,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -When it has been determined that the NTLM authentication protocol should not be used from a client device to any remote servers because you are required to use a more secure protocol such as Kerberos, there might be some client applications that still use NTLM. If so, and you set [Network Security: +When it has been determined that the NTLM authentication protocol shouldn't be used from a client device to any remote servers because you're required to use a more secure protocol such as Kerberos, there might be some client applications that still use NTLM. If so, and you set [Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers](network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) to any of the deny options, those applications will fail because the outbound NTLM authentication traffic from the client computer will be blocked. If you define an exception list of servers to which client devices are allowed to use NTLM authentication, then NTLM authentication traffic will continue to flow between those client applications and servers. The servers then are vulnerable to any malicious attack that takes advantage of security weaknesses in NTLM. @@ -98,13 +98,13 @@ If you define an exception list of servers to which client devices are allowed t ### Countermeasure When you use [Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers](network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) in audit-only mode, you can determine by reviewing which client applications are making NTLM authentication requests to the remote -servers in your environment. When assessed, you will have to determine on a case-by-case basis if NTLM authentication still minimally meets your security requirements. If not, the client application has to be upgraded to use something other than NTLM authentication. +servers in your environment. When assessed, you'll have to determine on a case-by-case basis if NTLM authentication still minimally meets your security requirements. If not, the client application has to be upgraded to use something other than NTLM authentication. ### Potential impact -Defining a list of servers for this policy setting will enable NTLM authentication traffic from the client application that uses those servers, and this might result in a security vulnerability. +Defining a list of servers for this policy setting will enable NTLM authentication traffic from the client application that uses those servers, and this traffic might result in a security vulnerability. -If this list is not defined and [Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers](network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) is enabled, then client applications that use NTLM will fail to authenticate to those servers that they have previously used. +If this list isn't defined and [Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers](network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) is enabled, then client applications that use NTLM will fail to authenticate to those servers that they've previously used. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-server-exceptions-in-this-domain.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-server-exceptions-in-this-domain.md index 5fb535995e..41ca2e0bee 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-server-exceptions-in-this-domain.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-add-server-exceptions-in-this-domain.md @@ -27,11 +27,11 @@ Describes the best practices, location, values, management aspects, and security ## Reference -The **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting allows you to create an exception list of servers in this domain to which client device are allowed to use NTLM pass-through authentication if any of the deny options are set in the [Network Security: Restrict NTLM: NTLM authentication in this domain](network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md) policy setting. +The **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting allows you to create an exception list of servers in this domain to which client devices are allowed to use NTLM pass-through authentication if any of the deny options are set in the [Network Security: Restrict NTLM: NTLM authentication in this domain](network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md) policy setting. If you configure this policy setting, you can define a list of servers in this domain to which client devices are allowed to use NTLM authentication. -If you do not configure this policy setting, no exceptions will be applied, and if **Network Security: Restrict NTLM: NTLM authentication in this domain** is enabled, all NTLM authentication attempts in the domain will fail. +If you don't configure this policy setting, no exceptions will be applied, and if **Network Security: Restrict NTLM: NTLM authentication in this domain** is enabled, all NTLM authentication attempts in the domain will fail. List the NetBIOS server names as the naming format, one per line. A single asterisk (\*) can be used anywhere in the string as a wildcard character. @@ -43,7 +43,7 @@ List the NetBIOS server names as the naming format, one per line. A single aster - Not defined - If you do not configure this policy setting by defining a list of servers, the policy is undefined and no exceptions will be applied. + If you don't configure this policy setting by defining a list of servers, the policy is undefined and no exceptions will be applied. ### Best practices @@ -89,7 +89,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -When it has been determined that the NTLM authentication protocol should not be used within a domain because you are required to use a more secure protocol such as Kerberos, there might be some NTLM authentication traffic that is still present in the domain. If so, and you set Network Security: +When it has been determined that the NTLM authentication protocol shouldn't be used within a domain because you're required to use a more secure protocol such as Kerberos, there might be some NTLM authentication traffic that is still present in the domain. If so, and you set Network Security: [Network Security: Restrict NTLM: NTLM authentication in this domain](network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md) to any of the deny options, any NTLM authentication request will fail because the pass-through member server will block the NTLM request. If you define an exception list of servers in this domain to which client computers are allowed to use NTLM pass-through authentication, then NTLM authentication traffic will continue to flow between those servers, which make them vulnerable to any malicious attack that takes advantage of security @@ -97,14 +97,13 @@ weaknesses in NTLM. ### Countermeasure -When you use **Network Security: Restrict NTLM: NTLM authentication in this domain** in audit-only mode, you can determine by reviewing which client applications are making NTLM authentication requests to the pass-through authentication servers. When assessed, you will have to determine on a -case-by-case basis if NTLM authentication still minimally meets your security requirements. +When you use **Network Security: Restrict NTLM: NTLM authentication in this domain** in audit-only mode, you can determine by reviewing which client applications are making NTLM authentication requests to the pass-through authentication servers. When assessed, you'll have to determine on a case-by-case basis if NTLM authentication still minimally meets your security requirements. ### Potential impact Defining a list of servers for this policy setting will enable NTLM authentication traffic between those servers might result in a security vulnerability. -If this list is not defined and **Network Security: Restrict NTLM: NTLM authentication in this domain** is enabled, then NTLM authentication will fail on those pass-through servers in the domain that they have previously used +If this list isn't defined and **Network Security: Restrict NTLM: NTLM authentication in this domain** is enabled, then NTLM authentication will fail on those pass-through servers in the domain that they've previously used ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-incoming-ntlm-traffic.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-incoming-ntlm-traffic.md index 47b963ab2a..d1310a007d 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-incoming-ntlm-traffic.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-incoming-ntlm-traffic.md @@ -29,18 +29,18 @@ Describes the best practices, location, values, management aspects, and security The **Network Security: Restrict NTLM: Audit incoming NTLM traffic** policy setting allows you to audit incoming NTLM traffic. -When this audit policy is enabled within Group Policy, it is enforced on any server where that Group Policy is distributed. The events will be recorded in the operational event log located in **Applications and Services Log\\Microsoft\\Windows\\NTLM**. Using an audit event collection system can help you collect the events for analysis more efficiently. +When this audit policy is enabled within Group Policy, it's enforced on any server where that Group Policy is distributed. The events will be recorded in the operational event log located in **Applications and Services Log\\Microsoft\\Windows\\NTLM**. Using an audit event collection system can help you collect the events for analysis more efficiently. When you enable this policy on a server, only authentication traffic to that server will be logged. -When you enable this audit policy, it functions in the same way as the [Network Security: Restrict NTLM: Incoming NTLM traffic](network-security-restrict-ntlm-incoming-ntlm-traffic.md) policy, but it does not actually block any traffic. Therefore, you can use it effectively to understand the -authentication traffic in your environment, and when you are ready to block that traffic, you can enable the Network Security: Restrict NTLM: Incoming NTLM traffic policy setting and select **Deny all accounts** or **Deny all domain accounts**. +When you enable this audit policy, it functions in the same way as the [Network Security: Restrict NTLM: Incoming NTLM traffic](network-security-restrict-ntlm-incoming-ntlm-traffic.md) policy, but it doesn't actually block any traffic. Therefore, you can use it effectively to understand the +authentication traffic in your environment, and when you're ready to block that traffic, you can enable the Network Security: Restrict NTLM: Incoming NTLM traffic policy setting and select **Deny all accounts** or **Deny all domain accounts**. ### Possible values - Disable - The server on which this policy is set will not log events for incoming NTLM traffic. + The server on which this policy is set won't log events for incoming NTLM traffic. - Enable auditing for domain accounts @@ -52,7 +52,7 @@ authentication traffic in your environment, and when you are ready to block that - Not defined - This is the same as **Disable**, and it results in no auditing of NTLM traffic. + This state of not being defined is the same as **Disable**, and it results in no auditing of NTLM traffic. ### Best practices @@ -95,11 +95,11 @@ There are no security audit event policies that can be configured to view output This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -NTLM and NTLMv2 authentication is vulnerable to a variety of malicious attacks, including SMB relay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. +NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB relay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. ### Vulnerability -Enabling this policy setting will reveal through logging which servers and client computers within your network or domain handle NTLM traffic. The identity of these devices can be used in malicious ways if NTLM authentication traffic is compromised. The policy setting does not prevent or mitigate any vulnerability because it is for audit purposes only. +Enabling this policy setting will reveal through logging which servers and client computers within your network or domain handle NTLM traffic. The identity of these devices can be used in malicious ways if NTLM authentication traffic is compromised. The policy setting doesn't prevent or mitigate any vulnerability because it is for audit purposes only. ### Countermeasure @@ -107,7 +107,7 @@ Restrict access to the log files when this policy setting is enabled in your pro ### Potential impact -If you do not enable or configure this policy setting, no NTLM authentication traffic information will be logged. If you do enable this policy setting, only auditing functions will occur; no security enhancements will be implemented. +If you don't enable or configure this policy setting, no NTLM authentication traffic information will be logged. If you do enable this policy setting, only auditing functions will occur; no security enhancements will be implemented. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-ntlm-authentication-in-this-domain.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-ntlm-authentication-in-this-domain.md index bdbf0e528d..e1cda4e95c 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-ntlm-authentication-in-this-domain.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-ntlm-authentication-in-this-domain.md @@ -31,25 +31,25 @@ The **Network Security: Restrict NTLM: Audit NTLM authentication in this domain* When you enable this policy setting on the domain controller, only authentication traffic to that domain controller will be logged. -When you enable this audit policy, it functions in the same way as the **Network Security: Restrict NTLM: NTLM authentication in this domain** policy setting, but it does not actually block any traffic. Therefore, you can use it effectively to understand the authentication traffic to your domain controllers and when you are ready to block that traffic, you can enable the **Network Security: Restrict NTLM: NTLM authentication in this domain** policy setting and select **Deny for domain accounts to domain servers**, **Deny for domain servers**, or **Deny for domain accounts**. +When you enable this audit policy, it functions in the same way as the **Network Security: Restrict NTLM: NTLM authentication in this domain** policy setting, but it doesn't actually block any traffic. Therefore, you can use it effectively to understand the authentication traffic to your domain controllers and when you're ready to block that traffic, you can enable the **Network Security: Restrict NTLM: NTLM authentication in this domain** policy setting and select **Deny for domain accounts to domain servers**, **Deny for domain servers**, or **Deny for domain accounts**. ### Possible values - **Disable** - The domain controller on which this policy is set will not log events for incoming NTLM traffic. + The domain controller on which this policy is set won't log events for incoming NTLM traffic. - **Enable for domain accounts to domain servers** - The domain controller on which this policy is set will log events for NTLM authentication logon attempts for accounts in the domain to domain servers when NTLM authentication would be denied because the **Network security: Restrict NTLM: NTLM authentication in this domain** policy setting is set to **Deny for domain accounts to domain servers**. + The domain controller on which this policy is set will log events for NTLM authentication sign-in attempts for accounts in the domain to domain servers when NTLM authentication would be denied because the **Network security: Restrict NTLM: NTLM authentication in this domain** policy setting is set to **Deny for domain accounts to domain servers**. - **Enable for domain accounts** - The domain controller will log events for NTLM authentication logon attempts that use domain accounts when NTLM authentication would be denied because the **Network security: Restrict NTLM: NTLM authentication in this domain** policy setting is set to **Deny for domain accounts**. + The domain controller will log events for NTLM authentication sign-in attempts that use domain accounts when NTLM authentication would be denied because the **Network security: Restrict NTLM: NTLM authentication in this domain** policy setting is set to **Deny for domain accounts**. - Not defined - This is the same as **Disable** and results in no auditing of NTLM traffic. + This state of not being defined is the same as **Disable** and results in no auditing of NTLM traffic. ### Best practices @@ -92,19 +92,19 @@ There are no security audit event policies that can be configured to view output This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -NTLM and NTLMv2 authentication is vulnerable to a variety of malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the +NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. ### Vulnerability -Enabling this policy setting will reveal through logging which devices within your network or domain handle NTLM traffic. The identity of these devices can be used in malicious ways if NTLM authentication traffic is compromised. The policy setting does not prevent or mitigate any vulnerability because it is for audit purposes only. +Enabling this policy setting will reveal through logging which devices within your network or domain handle NTLM traffic. The identity of these devices can be used in malicious ways if NTLM authentication traffic is compromised. The policy setting doesn't prevent or mitigate any vulnerability because it is for audit purposes only. ### Countermeasure Restrict access to the log files when this policy setting is enabled in your production environment. ### Potential impact -If you do not enable or configure this policy setting, no NTLM authentication traffic information will be logged. If you do enable this policy setting, only auditing functions will occur; no security enhancements will be implemented. +If you don't enable or configure this policy setting, no NTLM authentication traffic information will be logged. If you do enable this policy setting, only auditing functions will occur; no security enhancements will be implemented. ## Related topics From 5e97dffc00c36d1b5325c8bd664e6fdf4a48d71f Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Wed, 29 Jun 2022 14:09:34 +0530 Subject: [PATCH 008/109] Acrolinx Enhancement Effort --- ...ity-restrict-ntlm-incoming-ntlm-traffic.md | 12 ++-- ...ntlm-ntlm-authentication-in-this-domain.md | 14 ++-- ...outgoing-ntlm-traffic-to-remote-servers.md | 12 ++-- ...sword-must-meet-complexity-requirements.md | 12 ++-- .../perform-volume-maintenance-tasks.md | 2 +- .../profile-single-process.md | 6 +- .../profile-system-performance.md | 2 +- ...le-allow-automatic-administrative-logon.md | 12 ++-- ...py-and-access-to-all-drives-and-folders.md | 10 +-- .../remove-computer-from-docking-station.md | 12 ++-- .../reset-account-lockout-counter-after.md | 8 +-- .../security-policy-settings-reference.md | 2 +- .../security-policy-settings.md | 72 +++++++++---------- .../shut-down-the-system.md | 14 ++-- .../shutdown-clear-virtual-memory-pagefile.md | 10 +-- ...nt-digitally-sign-communications-always.md | 12 ++-- ...ly-sign-communications-if-server-agrees.md | 14 ++-- ...er-digitally-sign-communications-always.md | 16 ++--- ...ly-sign-communications-if-client-agrees.md | 14 ++-- ...e-passwords-using-reversible-encryption.md | 6 +- .../synchronize-directory-service-data.md | 6 +- ...on-for-user-keys-stored-on-the-computer.md | 10 +-- ...thms-for-encryption-hashing-and-signing.md | 12 ++-- ...nsensitivity-for-non-windows-subsystems.md | 10 +-- ...-permissions-of-internal-system-objects.md | 14 ++-- .../system-settings-optional-subsystems.md | 6 +- ...ables-for-software-restriction-policies.md | 2 +- ...ake-ownership-of-files-or-other-objects.md | 4 +- ...-for-the-built-in-administrator-account.md | 12 ++-- ...vation-without-using-the-secure-desktop.md | 8 +-- 30 files changed, 173 insertions(+), 173 deletions(-) diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-incoming-ntlm-traffic.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-incoming-ntlm-traffic.md index cbcc2e7d66..2bb128f669 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-incoming-ntlm-traffic.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-incoming-ntlm-traffic.md @@ -37,20 +37,20 @@ The **Network Security: Restrict NTLM: Incoming NTLM traffic** policy setting al - **Deny all domain accounts** - The server will deny NTLM authentication requests for domain logon, return an NTLM blocked error message to the client device, and log the error, but the server will allow local account logon. + The server will deny NTLM authentication requests for domain sign in, return an NTLM blocked error message to the client device, and log the error, but the server will allow local account sign in. - **Deny all accounts** - The server will deny NTLM authentication requests from all incoming traffic (whether domain account logon or local account logon), return an NTLM blocked error message to the client device, and log the error. + The server will deny NTLM authentication requests from all incoming traffic (whether domain account sign in or local account sign in), return an NTLM blocked error message to the client device, and log the error. - Not defined - This is the same as **Allow all**, and the server will allow all NTLM authentication requests. + This state of not being defined is the same as **Allow all**, and the server will allow all NTLM authentication requests. ### Best practices -If you select **Deny all domain accounts** or **Deny all accounts**, incoming NTLM traffic to the member server will be restricted. It is better to set the **Network Security: Restrict NTLM: Audit Incoming NTLM traffic** policy setting and then review the Operational log to understand what authentication attempts are made to the member servers, and subsequently what client applications are using NTLM. +If you select **Deny all domain accounts** or **Deny all accounts**, incoming NTLM traffic to the member server will be restricted. It's better to set the **Network Security: Restrict NTLM: Audit Incoming NTLM traffic** policy setting and then review the Operational log to understand what authentication attempts are made to the member servers, and then what client applications are using NTLM. ### Location @@ -89,7 +89,7 @@ There are no Security Audit Event policies that can be configured to view event This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -NTLM and NTLMv2 authentication is vulnerable to a variety of malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. +NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. ### Vulnerability @@ -97,7 +97,7 @@ Malicious attacks on NTLM authentication traffic that result in a compromised se ### Countermeasure -When it has been determined that the NTLM authentication protocol should not be used within a network because you are required to use a more secure protocol such as Kerberos, you can select one of several options that this security policy setting offers to restrict NTLM usage. +When it has been determined that the NTLM authentication protocol shouldn't be used within a network because you're required to use a more secure protocol such as Kerberos, you can select one of several options that this security policy setting offers to restrict NTLM usage. ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md index 0c1396e74f..2589d1f95d 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md @@ -26,7 +26,7 @@ Describes the best practices, location, values, management aspects, and security ## Reference -The **Network Security: Restrict NTLM: NTLM authentication in this domain** policy setting allows you to deny or allow NTLM authentication within a domain from this domain controller. This policy setting does not affect interactive logon to this domain controller. +The **Network Security: Restrict NTLM: NTLM authentication in this domain** policy setting allows you to deny or allow NTLM authentication within a domain from this domain controller. This policy setting doesn't affect interactive logon to this domain controller. ### Possible values @@ -36,17 +36,17 @@ The **Network Security: Restrict NTLM: NTLM authentication in this domain** poli - **Deny for domain accounts to domain servers** - The domain controller will deny all NTLM authentication logon attempts using accounts from this domain to all servers in the domain. The NTLM authentication attempts will be blocked and will return an NTLM blocked error unless the server name is on the exception list in the **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting. + The domain controller will deny all NTLM authentication sign-in attempts using accounts from this domain to all servers in the domain. The NTLM authentication attempts will be blocked and will return an NTLM blocked error unless the server name is on the exception list in the **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting. - NTLM can be used if the users are connecting to other domains. This depends on if any Restrict NTLM policies have been set on those domains. + NTLM can be used if the users are connecting to other domains, depending on whether any Restrict NTLM policies have been set on those domains. - **Deny for domain accounts** - Only the domain controller will deny all NTLM authentication logon attempts from domain accounts and will return an NTLM blocked error unless the server name is on the exception list in the **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting. + Only the domain controller will deny all NTLM authentication sign-in attempts from domain accounts and will return an NTLM blocked error unless the server name is on the exception list in the **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting. - **Deny for domain servers** - The domain controller will deny NTLM authentication requests to all servers in the domain and will return an NTLM blocked error unless the server name is on the exception list in the **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting. Servers that are not joined to the domain will not be affected if this policy setting is configured. + The domain controller will deny NTLM authentication requests to all servers in the domain and will return an NTLM blocked error unless the server name is on the exception list in the **Network security: Restrict NTLM: Add server exceptions in this domain** policy setting. Servers that aren't joined to the domain won't be affected if this policy setting is configured. - **Deny all** @@ -97,7 +97,7 @@ There are no security audit event policies that can be configured to view output This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -NTLM and NTLMv2 authentication is vulnerable to a variety of malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. +NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. ### Vulnerability @@ -105,7 +105,7 @@ Malicious attacks on NTLM authentication traffic resulting in a compromised serv ### Countermeasure -When it has been determined that the NTLM authentication protocol should not be used within a network because you are required to use a more secure protocol such as the Kerberos protocol, then you can select one of several options that this security policy setting offers to restrict NTLM usage +When it has been determined that the NTLM authentication protocol shouldn't be used within a network because you're required to use a more secure protocol such as the Kerberos protocol, then you can select one of several options that this security policy setting offers to restrict NTLM usage within the domain. ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md index f53a1e1665..9f98ea958e 100644 --- a/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md +++ b/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md @@ -39,19 +39,19 @@ The **Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers** - **Audit all** - The device that sends the NTLM authentication request to a remote server logs an event for each request. This allows you to identify those servers that receive NTLM authentication requests from the client device + The device that sends the NTLM authentication request to a remote server logs an event for each request. This event allows you to identify those servers that receive NTLM authentication requests from the client device. - **Deny all** - The device cannot authenticate any identities to a remote server by using NTLM authentication. You can use the [Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication](network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md) policy setting to define a list of remote servers to which client devices are allowed to use NTLM authentication while denying others. This setting will also log an event on the device that is making the authentication request. + The device can't authenticate any identities to a remote server by using NTLM authentication. You can use the [Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication](network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md) policy setting to define a list of remote servers to which client devices are allowed to use NTLM authentication while denying others. This setting will also log an event on the device that is making the authentication request. - Not defined - This is the same as **Allow all**, and the device will allow all NTLM authentication requests when the policy is deployed. + This state of being not defined is the same as **Allow all**, and the device will allow all NTLM authentication requests when the policy is deployed. ### Best practices -If you select **Deny all**, the client device cannot authenticate identities to a remote server by using NTLM authentication. First, select **Audit all** and then review the operational event log to understand which servers are involved in these authentication attempts. You can then add those server names to a server exception list by using the [Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication](network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md) policy setting. +If you select **Deny all**, the client device can't authenticate identities to a remote server by using NTLM authentication. First, select **Audit all** and then review the operational event log to understand which servers are involved in these authentication attempts. You can then add those server names to a server exception list by using the [Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication](network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md) policy setting. ### Location @@ -90,7 +90,7 @@ There are no security audit event policies that can be configured to view event This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -NTLM and NTLMv2 authentication is vulnerable to a variety of malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. +NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards. ### Vulnerability @@ -98,7 +98,7 @@ Malicious attacks on NTLM authentication traffic that result in a compromised se ### Countermeasure -When it has been determined that the NTLM authentication protocol should not be used within a network because you are required to use a more secure protocol such as Kerberos, then you can select from several options to restrict NTLM usage to servers. +When it has been determined that the NTLM authentication protocol shouldn't be used within a network because you're required to use a more secure protocol such as Kerberos, then you can select from several options to restrict NTLM usage to servers. ### Potential impact diff --git a/windows/security/threat-protection/security-policy-settings/password-must-meet-complexity-requirements.md b/windows/security/threat-protection/security-policy-settings/password-must-meet-complexity-requirements.md index 74efe115ae..5bcf16ede3 100644 --- a/windows/security/threat-protection/security-policy-settings/password-must-meet-complexity-requirements.md +++ b/windows/security/threat-protection/security-policy-settings/password-must-meet-complexity-requirements.md @@ -31,7 +31,7 @@ The **Passwords must meet complexity requirements** policy setting determines wh 1. Passwords may not contain the user's samAccountName (Account Name) value or entire displayName (Full Name value). Both checks aren't case-sensitive. The samAccountName is checked in its entirety only to determine whether it's part of the password. If the samAccountName is fewer than three characters long, this check is skipped. - The displayName is parsed for delimiters: commas, periods, dashes or hyphens, underscores, spaces, pound signs, and tabs. If any of these delimiters are found, the displayName is split and all parsed sections (tokens) are confirmed not to be included in the password. Tokens that are shorter than three characters are ignored, and substrings of the tokens aren't checked. For example, the name "Erin M. Hagens" is split into three tokens: "Erin", "M", and "Hagens". Because the second token is only one character long, it's ignored. So, this user could not have a password that included either "erin" or "hagens" as a substring anywhere in the password. + The displayName is parsed for delimiters: commas, periods, dashes or hyphens, underscores, spaces, pound signs, and tabs. If any of these delimiters are found, the displayName is split and all parsed sections (tokens) are confirmed not to be included in the password. Tokens that are shorter than three characters are ignored, and substrings of the tokens aren't checked. For example, the name "Erin M. Hagens" is split into three tokens: "Erin", "M", and "Hagens". Because the second token is only one character long, it's ignored. So, this user couldn't have a password that included either "erin" or "hagens" as a substring anywhere in the password. 2. The password contains characters from three of the following categories: @@ -45,11 +45,11 @@ The **Passwords must meet complexity requirements** policy setting determines wh Complexity requirements are enforced when passwords are changed or created. -The rules that are included in the Windows Server password complexity requirements are part of Passfilt.dll, and they cannot be directly modified. +The rules that are included in the Windows Server password complexity requirements are part of Passfilt.dll, and they can't be directly modified. When enabled, the default Passfilt.dll may cause some more Help Desk calls for locked-out accounts, because users are used to passwords that contain only characters that are in the alphabet. But this policy setting is liberal enough that all users should get used to it. -Additional settings that can be included in a custom Passfilt.dll are the use of non–upper-row characters. To type upper-row characters, you hold the SHIFT key and press one of any of the keys on the number row of the keyboard (from 1 through 9 and 0). +Other settings that can be included in a custom Passfilt.dll are the use of non–upper-row characters. To type upper-row characters, you hold the SHIFT key and press one of any of the keys on the number row of the keyboard (from 1 through 9 and 0). ### Possible values @@ -64,9 +64,9 @@ Additional settings that can be included in a custom Passfilt.dll are the use of Set **Passwords must meet complexity requirements** to Enabled. This policy setting, combined with a minimum password length of 8, ensures that there are at least 159,238,157,238,528 different possibilities for a single password. This setting makes a brute force attack difficult, but still not impossible. -The use of ALT key character combinations may greatly enhance the complexity of a password. However, requiring all users in an organization to adhere to such stringent password requirements might result in unhappy users and an over-worked Help Desk. Consider implementing a requirement in your organization to use ALT characters in the range from 0128 through 0159 as part of all administrator passwords. (ALT characters outside of that range can represent standard alphanumeric characters that do not add more complexity to the password.) +The use of ALT key character combinations may greatly enhance the complexity of a password. However, requiring all users in an organization to adhere to such stringent password requirements might result in unhappy users and an over-worked Help Desk. Consider implementing a requirement in your organization to use ALT characters in the range from 0128 through 0159 as part of all administrator passwords. (ALT characters outside of that range can represent standard alphanumeric characters that don't add more complexity to the password.) -Short passwords that contain only alphanumeric characters are easy to compromise by using publicly available tools. To prevent this, passwords should contain additional characters and/or meet complexity requirements. +Short passwords that contain only alphanumeric characters are easy to compromise by using publicly available tools. To prevent this vulnerability, passwords should contain other characters and/or meet complexity requirements. ### Location @@ -95,7 +95,7 @@ Passwords that contain only alphanumeric characters are easy to discover with se ### Countermeasure -Configure the **Passwords must meet complexity requirements** policy setting to _Enabled_ and advise users to use a variety of characters in their passwords. +Configure the **Passwords must meet complexity requirements** policy setting to _Enabled_ and advise users to use various characters in their passwords. When combined with a [Minimum password length](minimum-password-length.md) of 8, this policy setting ensures that the number of different possibilities for a single password is so great that it's difficult (but possible) for a brute force attack to succeed. (If the Minimum password length policy setting is increased, the average amount of time necessary for a successful attack also increases.) diff --git a/windows/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks.md b/windows/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks.md index 514e1a9ea7..fb0e337c6b 100644 --- a/windows/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks.md +++ b/windows/security/threat-protection/security-policy-settings/perform-volume-maintenance-tasks.md @@ -65,7 +65,7 @@ The following table lists the actual and effective default policy values. Defaul This section describes features, tools, and guidance to help you manage this policy. -A restart of the device is not required for this policy setting to be effective. +A restart of the device isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. diff --git a/windows/security/threat-protection/security-policy-settings/profile-single-process.md b/windows/security/threat-protection/security-policy-settings/profile-single-process.md index 599cb50810..c0fb47def4 100644 --- a/windows/security/threat-protection/security-policy-settings/profile-single-process.md +++ b/windows/security/threat-protection/security-policy-settings/profile-single-process.md @@ -64,7 +64,7 @@ The following table lists the actual and effective default policy values. Defaul This section describes features, tools, and guidance to help you manage this policy. -A restart of the device is not required for this policy setting to be effective. +A restart of the device isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. @@ -85,7 +85,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -The **Profile single process** user right presents a moderate vulnerability. Attackers with this user right could monitor a computer's performance to help identify critical processes that they might want to attack directly. Attackers may be able to determine what processes run on the computer so that they could identify countermeasures that they may need to avoid, such as anti-virus software or an intrusion-detection system. They could also identify other users who are logged on to a computer. +The **Profile single process** user right presents a moderate vulnerability. Attackers with this user right could monitor a computer's performance to help identify critical processes that they might want to attack directly. Attackers may be able to determine what processes run on the computer so that they could identify countermeasures that they may need to avoid, such as anti-virus software or an intrusion-detection system. They could also identify other users who are signed in to a computer. ### Countermeasure @@ -93,7 +93,7 @@ Ensure that only the local Administrators group is assigned the **Profile single ### Potential impact -If you remove the **Profile single process** user right from the Power Users group or other accounts, you could limit the abilities of users who are assigned to specific administrative roles in your environment. You should ensure that delegated tasks are not negatively affected. +If you remove the **Profile single process** user right from the Power Users group or other accounts, you could limit the abilities of users who are assigned to specific administrative roles in your environment. You should ensure that delegated tasks aren't negatively affected. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/profile-system-performance.md b/windows/security/threat-protection/security-policy-settings/profile-system-performance.md index 47f372d723..8eeabdcf30 100644 --- a/windows/security/threat-protection/security-policy-settings/profile-system-performance.md +++ b/windows/security/threat-protection/security-policy-settings/profile-system-performance.md @@ -64,7 +64,7 @@ The following table lists the actual and effective default policy values for the This section describes features, tools, and guidance to help you manage this policy. -A restart of the device is not required for this policy setting to be effective. +A restart of the device isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. diff --git a/windows/security/threat-protection/security-policy-settings/recovery-console-allow-automatic-administrative-logon.md b/windows/security/threat-protection/security-policy-settings/recovery-console-allow-automatic-administrative-logon.md index c188b74c08..ce9ada3153 100644 --- a/windows/security/threat-protection/security-policy-settings/recovery-console-allow-automatic-administrative-logon.md +++ b/windows/security/threat-protection/security-policy-settings/recovery-console-allow-automatic-administrative-logon.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management, and security This policy setting determines whether the built-in Administrator account password must be provided before access to the device is granted. If you enable this setting, the built-in Administrator account is automatically logged on to the computer at the Recovery Console; no password is required. -The Recovery Console can be useful when troubleshooting and repairing systems that cannot be restarted. However, enabling this policy setting so a user can automatically log on to the console is dangerous. Anyone can walk up to the server, shut it down by disconnecting the power, reboot it, select **Recovery Console** from the **Restart** menu, and then assume full control of the server. +The Recovery Console can be useful when troubleshooting and repairing systems that can't be restarted. However, enabling this policy setting so a user can automatically sign in to the console is dangerous. Anyone can walk up to the server, shut it down by disconnecting the power, reboot it, select **Recovery Console** from the **Restart** menu, and then assume full control of the server. ### Possible values @@ -39,15 +39,15 @@ The Recovery Console can be useful when troubleshooting and repairing systems th - Disabled - Automatic administrative logon is not allowed. + Automatic administrative logon isn't allowed. - Not defined - Automatic administrative logon is not allowed. + Automatic administrative logon isn't allowed. ### Best practices -- Set **Recovery Console: Allow automatic administrative logon** to **Disabled**. This requires a user to enter a user name and password to access the Recovery Console account. +- Set **Recovery Console: Allow automatic administrative logon** to **Disabled**. This setting requires a user to enter a user name and password to access the Recovery Console account. ### Location @@ -72,7 +72,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -88,7 +88,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -The Recovery Console can be very useful when you must troubleshoot and repair device that do not start. However, allowing automatic logon to the Recovery Console can make it possible for someone to assume full control of the server. +The Recovery Console can be useful when you must troubleshoot and repair devices that don't start. However, allowing automatic logon to the Recovery Console can make it possible for someone to assume full control of the server. ### Countermeasure diff --git a/windows/security/threat-protection/security-policy-settings/recovery-console-allow-floppy-copy-and-access-to-all-drives-and-folders.md b/windows/security/threat-protection/security-policy-settings/recovery-console-allow-floppy-copy-and-access-to-all-drives-and-folders.md index c06d6f180c..9c9c56c5db 100644 --- a/windows/security/threat-protection/security-policy-settings/recovery-console-allow-floppy-copy-and-access-to-all-drives-and-folders.md +++ b/windows/security/threat-protection/security-policy-settings/recovery-console-allow-floppy-copy-and-access-to-all-drives-and-folders.md @@ -34,7 +34,7 @@ This policy setting enables or disables the Recovery Console SET command, which - **AllowRemovableMedia**. Allows files to be copied to removable media, such as a floppy disk. - **NoCopyPrompt**. Suppresses the prompt that typically displays before an existing file is overwritten. -You might forget to remove removable media, such as CD or floppy disk, with sensitive data or applications that a malicious user could then steal. Or you could accidentally leave a startup disk in the computer after using the Recovery Console. If the device is restarted for any reason and the BIOS has been configured to boot from the removable media before the hard disk drive, the server will start from the removable disk. This causes the server's network services to be unavailable. +You might forget to remove removable media, such as CD or floppy disk, with sensitive data or applications that a malicious user could then steal. Or you could accidentally leave a startup disk in the computer after using the Recovery Console. If the device is restarted for any reason and the BIOS has been configured to boot from the removable media before the hard disk drive, the server will start from the removable disk. This boot causes the server's network services to be unavailable. ### Possible values @@ -44,7 +44,7 @@ You might forget to remove removable media, such as CD or floppy disk, with sens ### Best practices -- Set **Recovery Console: Allow floppy copy and access to drives and folders** to **Disabled**. Users who have started a server by using the Recovery Console and logged in with the built-in Administrator account will not be able to copy files and folders to a floppy disk. +- Set **Recovery Console: Allow floppy copy and access to drives and folders** to **Disabled**. Users who have started a server by using the Recovery Console and logged in with the built-in Administrator account won't be able to copy files and folders to a floppy disk. ### Location @@ -69,7 +69,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -86,7 +86,7 @@ Enabling this security option makes the Recovery Console SET command available, - AllowWildCards: Enable wildcard support for some commands (such as the DEL command). - AllowAllPaths: Allow access to all files and folders on the device. - AllowRemovableMedia: Allow files to be copied to removable media, such as a floppy disk. -- NoCopyPrompt: Do not prompt when overwriting an existing file. +- NoCopyPrompt: Don't prompt when overwriting an existing file. ## Security considerations @@ -102,7 +102,7 @@ Disable the **Recovery console: Allow floppy copy and access to drives and folde ### Potential impact -Users who have started a server through the Recovery Console and logged in with the built-in Administrator account cannot copy files and folders to a floppy disk. +Users who have started a server through the Recovery Console and logged in with the built-in Administrator account can't copy files and folders to a floppy disk. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/remove-computer-from-docking-station.md b/windows/security/threat-protection/security-policy-settings/remove-computer-from-docking-station.md index 4508560bdc..b42bad16dd 100644 --- a/windows/security/threat-protection/security-policy-settings/remove-computer-from-docking-station.md +++ b/windows/security/threat-protection/security-policy-settings/remove-computer-from-docking-station.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management, and security This security setting determines whether a user can undock a portable device from its docking station without logging on. This policy setting only affects scenarios that involve a portable computer and its docking station. -If this user right is assigned to the user’s account (or if the user is a member of the assigned group), the user must log on before removing the portable device from its docking station. Otherwise, as a security measure, the user will not be able to log on after the device is removed from the docking station. If this policy is not assigned, the user may remove the portable device from its docking station without logging on, and then have the ability to start and log on to the device afterwards in its undocked state. +If this user right is assigned to the user’s account (or if the user is a member of the assigned group), the user must sign in before removing the portable device from its docking station. Otherwise, as a security measure, the user won't be able to sign in after the device is removed from the docking station. If this policy isn't assigned, the user may remove the portable device from its docking station without signing in, and then have the ability to start and sign in to the device afterwards in its undocked state. Constant: SeUndockPrivilege @@ -48,7 +48,7 @@ Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\Use ### Default values -Although this portable device scenario does not normally apply to servers, by default this setting is Administrators on domain controllers and on stand-alone servers. +Although this portable device scenario doesn't normally apply to servers, by default this setting is Administrators on domain controllers and on stand-alone servers. The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page. @@ -65,7 +65,7 @@ The following table lists the actual and effective default policy values. Defaul This section describes features, tools, and guidance to help you manage this policy. -A restart of the device is not required for this policy setting to be effective. +A restart of the device isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. @@ -86,10 +86,10 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -Anyone who has the **Remove computer from docking station** user right can log on and then remove a portable device from its docking station. If this setting is not defined, it has the same effect as if everyone was granted this right. However, the value of implementing this countermeasure is reduced by the following factors: +Anyone who has the **Remove computer from docking station** user right can sign in and then remove a portable device from its docking station. If this setting isn't defined, it has the same effect as if everyone was granted this right. However, the value of implementing this countermeasure is reduced by the following factors: - If attackers can restart the device, they could remove it from the docking station after the BIOS starts but before the operating system starts. -- This setting does not affect servers because they typically are not installed in docking stations. +- This setting doesn't affect servers because they typically aren't installed in docking stations. - An attacker could steal the device and the docking station together. - Devices that can be mechanically undocked can be physically removed by the user whether or not they use the Windows undocking functionality. @@ -99,7 +99,7 @@ Ensure that only the local Administrators group and the user account to which th ### Potential impact -By default, only members of the local Administrators group are granted this right. Other user accounts must be explicitly granted this user right as necessary. If your organization's users are not members of the local Administrators groups on their portable devices, they cannot remove their portable devices from their docking stations if they do not first shut down the device. Therefore, you may want to assign the **Remove computer from docking station** privilege to the local Users group for portable devices. +By default, only members of the local Administrators group are granted this right. Other user accounts must be explicitly granted this user right as necessary. If your organization's users aren't members of the local Administrators groups on their portable devices, they can't remove their portable devices from their docking stations if they don't first shut down the device. Therefore, you may want to assign the **Remove computer from docking station** privilege to the local Users group for portable devices. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/reset-account-lockout-counter-after.md b/windows/security/threat-protection/security-policy-settings/reset-account-lockout-counter-after.md index 87951d31f4..51f96f1875 100644 --- a/windows/security/threat-protection/security-policy-settings/reset-account-lockout-counter-after.md +++ b/windows/security/threat-protection/security-policy-settings/reset-account-lockout-counter-after.md @@ -27,9 +27,9 @@ Describes the best practices, location, values, and security considerations for ## Reference -The **Reset account lockout counter after** policy setting determines the number of minutes that must elapse from the time a user fails to log on before the failed logon attempt counter is reset to 0. If [Account lockout threshold](account-lockout-threshold.md) is set to a number greater than zero, this reset time must be less than or equal to the value of [Account lockout duration](account-lockout-duration.md). +The **Reset account lockout counter after** policy setting determines the number of minutes that must elapse from the time a user fails to sign in before the failed sign-in attempt counter is reset to 0. If [Account lockout threshold](account-lockout-threshold.md) is set to a number greater than zero, this reset time must be less than or equal to the value of [Account lockout duration](account-lockout-duration.md). -The disadvantage of a high setting is that users lock themselves out for an inconveniently long period if they exceed the account lockout threshold through logon errors. Users may make excessive Help Desk calls. +The disadvantage of a high setting is that users lock themselves out for an inconveniently long period if they exceed the account lockout threshold through sign-in errors. Users may make excessive Help Desk calls. ### Possible values @@ -40,7 +40,7 @@ The disadvantage of a high setting is that users lock themselves out for an inco Determine the threat level for your organization and balance that against the cost of your Help Desk support for password resets. Each organization will have specific requirements. -[Windows security baselines](../windows-security-baselines.md) recommend configuring the **Reset account lockout counter after** policy setting to 15, but as with other account lockeout settings, this value is more of a guideline than a rule or best practice because there is no "one size fits all." For more information, see [Configuring Account Lockout](/archive/blogs/secguide/configuring-account-lockout). +[Windows security baselines](../windows-security-baselines.md) recommend configuring the **Reset account lockout counter after** policy setting to 15, but as with other account lockout settings, this value is more of a guideline than a rule or best practice because there's no "one size fits all." For more information, see [Configuring Account Lockout](/archive/blogs/secguide/configuring-account-lockout). ### Location @@ -73,7 +73,7 @@ Users can accidentally lock themselves out of their accounts if they mistype the ### Potential impact -If you do not configure this policy setting or if the value is configured to an interval that is too long, an attacker could attempt to log on to each user's account numerous times and lock out their accounts, a denial-of-service (DoS) attack might succeed, or administrators might have to manually unlock all locked-out accounts. If you configure this policy setting to a reasonable value, users can perform new attempts to log on after a failed logon within a reasonable time, without making brute force attacks feasible at high speeds. Be sure that you notify users of the values that are used for this policy setting so that they wait for the lockout timer to expire before they call the Help Desk. +If you don't configure this policy setting or if the value is configured to an interval that is too long, an attacker could attempt to sign in to each user's account numerous times and lock out their accounts, a denial-of-service (DoS) attack might succeed, or administrators might have to manually unlock all locked-out accounts. If you configure this policy setting to a reasonable value, users can perform new attempts to sign in after a failed sign in within a reasonable time, without making brute force attacks feasible at high speeds. Be sure that you notify users of the values that are used for this policy setting so that they wait for the lockout timer to expire before they call the Help Desk. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/security-policy-settings-reference.md b/windows/security/threat-protection/security-policy-settings/security-policy-settings-reference.md index a1d965558b..012a47736e 100644 --- a/windows/security/threat-protection/security-policy-settings/security-policy-settings-reference.md +++ b/windows/security/threat-protection/security-policy-settings/security-policy-settings-reference.md @@ -25,7 +25,7 @@ ms.technology: windows-sec This reference of security settings provides information about how to implement and manage security policies, including setting options and security considerations. -This reference focuses on those settings that are considered security settings. This reference examines only the settings and features in the Windows operating systems that can help organizations secure their enterprises against malicious software threats. Management features and those security features that you cannot configure are not described in this reference. +This reference focuses on those settings that are considered security settings. This reference examines only the settings and features in the Windows operating systems that can help organizations secure their enterprises against malicious software threats. Management features and those security features that you can't configure aren't described in this reference. Each policy setting described contains referential content such as a detailed explanation of the settings, best practices, default settings, differences between operating system versions, policy management considerations, and security considerations that include a discussion of vulnerability, countermeasures, and potential impact of those countermeasures. diff --git a/windows/security/threat-protection/security-policy-settings/security-policy-settings.md b/windows/security/threat-protection/security-policy-settings/security-policy-settings.md index a0a8270da7..48b90c0da2 100644 --- a/windows/security/threat-protection/security-policy-settings/security-policy-settings.md +++ b/windows/security/threat-protection/security-policy-settings/security-policy-settings.md @@ -26,7 +26,7 @@ ms.technology: windows-sec This reference topic describes the common scenarios, architecture, and processes for security settings. -Security policy settings are rules that administrators configure on a computer or multiple devices for the purpose of protecting resources on a device or network. The Security Settings extension of the Local Group Policy Editor snap-in allows you to define security configurations as part of a Group Policy Object (GPO). The GPOs are linked to Active Directory containers such as sites, domains, or organizational units, and they enable you to manage security settings for multiple devices from any device joined to the domain. Security settings policies are used as part of your overall security implementation to help secure domain controllers, servers, clients, and other resources in your organization. +Security policy settings are rules that administrators configure on a computer or multiple devices for protecting resources on a device or network. The Security Settings extension of the Local Group Policy Editor snap-in allows you to define security configurations as part of a Group Policy Object (GPO). The GPOs are linked to Active Directory containers such as sites, domains, or organizational units, and they enable you to manage security settings for multiple devices from any device joined to the domain. Security settings policies are used as part of your overall security implementation to help secure domain controllers, servers, clients, and other resources in your organization. Security settings can control: @@ -44,7 +44,7 @@ For more info about managing security configurations, see [Administer security p The Security Settings extension of the Local Group Policy Editor includes the following types of security policies: -- **Account Policies.** These polices are defined on devices; they affect how user accounts can interact with the computer or domain. Account policies include the following types of policies: +- **Account Policies.** These policies are defined on devices; they affect how user accounts can interact with the computer or domain. Account policies include the following types of policies: - **Password Policy.** These policies determine settings for passwords, such as enforcement and lifetimes. Password policies are used for domain accounts. - **Account Lockout Policy.** These policies determine the conditions and length of time that an account will be locked out of the system. Account lockout policies are used for domain or local user accounts. @@ -57,15 +57,15 @@ The Security Settings extension of the Local Group Policy Editor includes the fo > [!NOTE] > For devices running Windows 7 and later, we recommend to use the settings under Advanced Audit Policy Configuration rather than the Audit Policy settings under Local Policies. - - **User Rights Assignment.** Specify the users or groups that have logon rights or privileges on a device - - **Security Options.** Specify security settings for the computer, such as Administrator and Guest Account names; access to floppy disk drives and CD-ROM drives; installation of drivers; logon prompts; and so on. + - **User Rights Assignment.** Specify the users or groups that have sign-in rights or privileges on a device + - **Security Options.** Specify security settings for the computer, such as Administrator and Guest Account names; access to floppy disk drives and CD-ROM drives; installation of drivers; sign-in prompts; and so on. - **Windows Firewall with Advanced Security.** Specify settings to protect the device on your network by using a stateful firewall that allows you to determine which network traffic is permitted to pass between your device and the network. - **Network List Manager Policies.** Specify settings that you can use to configure different aspects of how networks are listed and displayed on one device or on many devices. - **Public Key Policies.** Specify settings to control Encrypting File System, Data Protection, and BitLocker Drive Encryption in addition to certain certificate paths and services settings. - **Software Restriction Policies.** Specify settings to identify software and to control its ability to run on your local device, organizational unit, domain, or site. - **Application Control Policies.** Specify settings to control which users or groups can run particular applications in your organization based on unique identities of files. -- **IP Security Policies on Local Computer.** Specify settings to ensure private, secure communications over IP networks through the use of cryptographic security services. IPsec establishes trust and security from a source IP address to a destination IP address. +- **IP Security Policies on Local Computer.** Specify settings to ensure private, secure communications over IP networks by using cryptographic security services. IPsec establishes trust and security from a source IP address to a destination IP address. - **Advanced Audit Policy Configuration.** Specify settings that control the logging of security events into the security log on the device. The settings under Advanced Audit Policy Configuration provide finer control over which activities to monitor as opposed to the Audit Policy settings under Local Policies. ## Policy-based security settings management @@ -87,7 +87,7 @@ Importing a security template to a GPO ensures that any accounts to which the GP > [!NOTE] > These refresh settings vary between versions of the operating system and can be configured. -By using Group Policy−based security configurations in conjunction with the delegation of administration, you can ensure that specific security settings, rights, and behavior are applied to all servers and computers within an OU. This approach makes it simple to update a number of servers with any additional changes required in the future. +By using Group Policy−based security configurations in conjunction with the delegation of administration, you can ensure that specific security settings, rights, and behavior are applied to all servers and computers within an OU. This approach makes it simple to update many servers with any other changes required in the future. ### Dependencies on other operating system technologies @@ -95,7 +95,7 @@ For devices that are members of a Windows Server 2008 or later domain, securit - **Active Directory Domain Services (AD DS)** - The Windows-based directory service, AD DS, stores information about objects on a network and makes this information available to administrators and users. By using AD DS, you can view and manage network objects on the network from a single location, and users can access permitted network resources by using a single logon. + The Windows-based directory service, AD DS, stores information about objects on a network and makes this information available to administrators and users. By using AD DS, you can view and manage network objects on the network from a single location, and users can access permitted network resources by using a single sign in. - **Group Policy** @@ -103,7 +103,7 @@ For devices that are members of a Windows Server 2008 or later domain, securit - **Domain Name System (DNS)** - A hierarchical naming system used for locating domain names on the Internet and on private TCP/IP networks. DNS provides a service for mapping DNS domain names to IP addresses, and IP addresses to domain names. This allows users, computers, and applications to query DNS to specify remote systems by fully qualified domain names rather than by IP addresses. + A hierarchical naming system used for locating domain names on the Internet and on private TCP/IP networks. DNS provides a service for mapping DNS domain names to IP addresses, and IP addresses to domain names. This service allows users, computers, and applications to query DNS to specify remote systems by fully qualified domain names rather than by IP addresses. - **Winlogon** @@ -115,11 +115,11 @@ For devices that are members of a Windows Server 2008 or later domain, securit - **Security Accounts Manager (SAM)** - A Windows service used during the logon process. SAM maintains user account information, including groups to which a user belongs. + A Windows service used during the sign-in process. SAM maintains user account information, including groups to which a user belongs. - **Local Security Authority (LSA)** - A protected subsystem that authenticates and logs users onto the local system. LSA also maintains information about all aspects of local security on a system, collectively known as the Local Security Policy of the system. + A protected subsystem that authenticates and signs in users to the local system. LSA also maintains information about all aspects of local security on a system, collectively known as the Local Security Policy of the system. - **Windows Management Instrumentation (WMI)** @@ -127,7 +127,7 @@ For devices that are members of a Windows Server 2008 or later domain, securit - **Resultant Set of Policy (RSoP)** - An enhanced Group Policy infrastructure that uses WMI in order to make it easier to plan and debug policy settings. RSoP provides public methods that expose what an extension to Group Policy would do in a what-if situation, and what the extension has done in an actual situation. This allows administrators to easily determine the combination of policy settings that apply to, or will apply to, a user or device. + An enhanced Group Policy infrastructure that uses WMI in order to make it easier to plan and debug policy settings. RSoP provides public methods that expose what an extension to Group Policy would do in a what-if situation, and what the extension has done in an actual situation. These public methods allow administrators to easily determine the combination of policy settings that apply to, or will apply to, a user or device. - **Service Control Manager (SCM)** @@ -189,11 +189,11 @@ The following list describes these primary features of the security configuratio - **scesrv.dll** - This .dll is hosted in services.exe and runs under local system context. scesrv.dll provides core Security Configuration Manager functionality, such as import, configure, analyze, and policy propagation. + This .dll file is hosted in services.exe and runs under local system context. scesrv.dll provides core Security Configuration Manager functionality, such as import, configure, analyze, and policy propagation. Scesrv.dll performs configuration and analysis of various security-related system parameters by calling corresponding system APIs, including LSA, SAM, and the registry. - Scesrv.dll exposes APIs such as import, export, configure, and analyze. It checks that the request is made over LRPC (Windows XP) and fails the call if it is not. + Scesrv.dll exposes APIs such as import, export, configure, and analyze. It checks that the request is made over LRPC (Windows XP) and fails the call if it isn't. Communication between parts of the Security Settings extension occurs by using the following methods: @@ -210,7 +210,7 @@ The following list describes these primary features of the security configuratio - **Scecli.dll** - This is the client-side interface or wrapper to scesrv.dll. scecli.dll is loaded into Wsecedit.dll to support MMC snap-ins. It is used by Setup to configure default system security and security of files, registry keys, and services installed by the Setup API .inf files. + This Scecli.dll is the client-side interface or wrapper to scesrv.dll. scecli.dll is loaded into Wsecedit.dll to support MMC snap-ins. It's used by Setup to configure default system security and security of files, registry keys, and services installed by the Setup API .inf files. The command-line version of the security configuration and analysis user interfaces, secedit.exe, uses scecli.dll. @@ -228,7 +228,7 @@ The following list describes these primary features of the security configuratio - **Secedit.sdb** - This is a permanent system database used for policy propagation including a table of persistent settings for rollback purposes. + This Secedit.sdb is a permanent system database used for policy propagation including a table of persistent settings for rollback purposes. - **User databases** @@ -236,7 +236,7 @@ The following list describes these primary features of the security configuratio - **.Inf Templates** - These are text files that contain declarative security settings. They are loaded into a database before configuration or analysis. Group Policy security policies are stored in .inf files on the SYSVOL folder of domain controllers, where they are downloaded (by using file copy) and merged into the system database during policy propagation. + These templates are text files that contain declarative security settings. They're loaded into a database before configuration or analysis. Group Policy security policies are stored in .inf files on the SYSVOL folder of domain controllers, where they're downloaded (by using file copy) and merged into the system database during policy propagation. ## Security settings policy processes and interactions @@ -244,27 +244,27 @@ For a domain-joined device, where Group Policy is administered, security setting ### Group Policy processing -When a computer starts and a user logs on, computer policy and user policy are applied according to the following sequence: +When a computer starts and a user signs in, computer policy and user policy are applied according to the following sequence: 1. The network starts. Remote Procedure Call System Service (RPCSS) and Multiple Universal Naming Convention Provider (MUP) start. 1. An ordered list of Group Policy Objects is obtained for the device. The list might depend on these factors: - Whether the device is part of a domain and, therefore, subject to Group Policy through Active Directory. - The location of the device in Active Directory. - - Whether the list of Group Policy Objects has changed. If the list of Group Policy Objects has not changed, no processing is done. + - Whether the list of Group Policy Objects has changed. If the list of Group Policy Objects hasn't changed, no processing is done. -1. Computer policy is applied. These are the settings under Computer Configuration from the gathered list. This is a synchronous process by default and occurs in the following order: local, site, domain, organizational unit, child organizational unit, and so on. No user interface appears while computer policies are processed. -1. Startup scripts run. This is hidden and synchronous by default; each script must complete or time out before the next one starts. The default time-out is 600 seconds. You can use several policy settings to modify this behavior. -1. The user presses CTRL+ALT+DEL to log on. -1. After the user is validated, the user profile loads; it is governed by the policy settings that are in effect. +1. Computer policy is applied. These settings are the ones under Computer Configuration from the gathered list. This process is a synchronous one by default and occurs in the following order: local, site, domain, organizational unit, child organizational unit, and so on. No user interface appears while computer policies are processed. +1. Startup scripts run. These scripts are hidden and synchronous by default; each script must complete or time out before the next one starts. The default time-out is 600 seconds. You can use several policy settings to modify this behavior. +1. The user presses CTRL+ALT+DEL to sign in. +1. After the user is validated, the user profile loads; it's governed by the policy settings that are in effect. 1. An ordered list of Group Policy Objects is obtained for the user. The list might depend on these factors: - Whether the user is part of a domain and, therefore, subject to Group Policy through Active Directory. - Whether loopback policy processing is enabled, and if so, the state (Merge or Replace) of the loopback policy setting. - The location of the user in Active Directory. - - Whether the list of Group Policy Objects has changed. If the list of Group Policy Objects has not changed, no processing is done. + - Whether the list of Group Policy Objects has changed. If the list of Group Policy Objects hasn't changed, no processing is done. -1. User policy is applied. These are the settings under User Configuration from the gathered list. This is synchronous by default and in the following order: local, site, domain, organizational unit, child organizational unit, and so on. No user interface appears while user policies are processed. +1. User policy is applied. These settings are the ones under User Configuration from the gathered list. These settings are synchronous by default and in the following order: local, site, domain, organizational unit, child organizational unit, and so on. No user interface appears while user policies are processed. 1. Logon scripts run. Group Policy−based logon scripts are hidden and asynchronous by default. The user object script runs last. 1. The operating system user interface that is prescribed by Group Policy appears. @@ -296,7 +296,7 @@ Group Policy settings are processed in the following order: 1. **Domain.** - Processing of multiple domain-linked Group Policy Objects is synchronous and in an order you speciy. + Processing of multiple domain-linked Group Policy Objects is synchronous and in an order you specify. 1. **Organizational units.** @@ -306,7 +306,7 @@ At the level of each organizational unit in the Active Directory hierarchy, one, This order means that the local Group Policy Object is processed first, and Group Policy Objects that are linked to the organizational unit of which the computer or user is a direct member are processed last, which overwrites the earlier Group Policy Objects. -This is the default processing order and administrators can specify exceptions to this order. A Group Policy Object that is linked to a site, domain, or organizational unit (not a local Group Policy Object) can be set to **Enforced** with respect to that site, domain, or organizational unit, so that none of its policy settings can be overridden. At any site, domain, or organizational unit, you can mark Group Policy inheritance selectively as **Block Inheritance**. Group Policy Object links that are set to **Enforced** are always applied, however, and they cannot be blocked. For more information see [Group Policy Basics – Part 2: Understanding Which GPOs to Apply](/archive/blogs/musings_of_a_technical_tam/group-policy-basics-part-2-understanding-which-gpos-to-apply). +This order is the default processing order and administrators can specify exceptions to this order. A Group Policy Object that is linked to a site, domain, or organizational unit (not a local Group Policy Object) can be set to **Enforced** with respect to that site, domain, or organizational unit, so that none of its policy settings can be overridden. At any site, domain, or organizational unit, you can mark Group Policy inheritance selectively as **Block Inheritance**. Group Policy Object links that are set to **Enforced** are always applied, however, and they can't be blocked. For more information, see [Group Policy Basics – Part 2: Understanding Which GPOs to Apply](/archive/blogs/musings_of_a_technical_tam/group-policy-basics-part-2-understanding-which-gpos-to-apply). ### Security settings policy processing @@ -333,9 +333,9 @@ The following figure illustrates the security settings policy processing. ### Merging of security policies on domain controllers -Password policies, Kerberos, and some security options are only merged from GPOs that are linked at the root level on the domain. This is done to keep those settings synchronized across all domain controllers in the domain. The following security options are merged: +Password policies, Kerberos, and some security options are only merged from GPOs that are linked at the root level on the domain. This merging is done to keep those settings synchronized across all domain controllers in the domain. The following security options are merged: -- Network Security: Force logoff when logon hours expire +- Network Security: Force sign out when sign-in hours expire - Accounts: Administrator account status - Accounts: Guest account status - Accounts: Rename administrator account @@ -349,11 +349,11 @@ If an application is installed on a primary domain controller (PDC) with operati ### When security settings are applied -After you have edited the security settings policies, the settings are refreshed on the computers in the organizational unit linked to your Group Policy Object in the following instances: +After you've edited the security settings policies, the settings are refreshed on the computers in the organizational unit linked to your Group Policy Object in the following instances: - When a device is restarted. - Every 90 minutes on a workstation or server and every 5 minutes on a domain controller. This refresh interval is configurable. -- By default, Security policy settings delivered by Group Policy are also applied every 16 hours (960 minutes) even if a GPO has not changed. +- By default, Security policy settings delivered by Group Policy are also applied every 16 hours (960 minutes) even if a GPO hasn't changed. ### Persistence of security settings policy @@ -361,11 +361,11 @@ Security settings can persist even if a setting is no longer defined in the poli Security settings might persist in the following cases: -- The setting has not been previously defined for the device. +- The setting hasn't been previously defined for the device. - The setting is for a registry security object. - The settings are for a file system security object. -All settings applied through local policy or through a Group Policy Object are stored in a local database on your computer. Whenever a security setting is modified, the computer saves the security setting value to the local database, which retains a history of all the settings that have been applied to the computer. If a policy first defines a security setting and then no longer defines that setting, then the setting takes on the previous value in the database. If a previous value does not exist in the database then the setting does not revert to anything and remains defined as is. +All settings applied through local policy or through a Group Policy Object are stored in a local database on your computer. Whenever a security setting is modified, the computer saves the security setting value to the local database, which retains a history of all the settings that have been applied to the computer. If a policy first defines a security setting and then no longer defines that setting, then the setting takes on the previous value in the database. If a previous value doesn't exist in the database, then the setting doesn't revert to anything and remains defined as is. This behavior is sometimes referred to as "tattooing". Registry and file security settings will maintain the values applied through Group Policy until that setting is set to other values. @@ -376,7 +376,7 @@ Both Apply Group Policy and Read permissions are required to have the settings f ### Filtering security policy -By default, all GPOs have Read and Apply Group Policy both Allowed for the Authenticated Users group. The Authenticated Users group includes both users and computers. Security settings policies are computer-based. To specify which client computers will or will not have a Group Policy Object applied to them, you can deny them either the Apply Group Policy or Read permission on that Group Policy Object. Changing these permissions allows you to limit the scope of the GPO to a specific set of computers within a site, domain, or OU. +By default, all GPOs have Read and Apply Group Policy both Allowed for the Authenticated Users group. The Authenticated Users group includes both users and computers. Security settings policies are computer-based. To specify which client computers will or won't have a Group Policy Object applied to them, you can deny them either the Apply Group Policy or Read permission on that Group Policy Object. Changing these permissions allows you to limit the scope of the GPO to a specific set of computers within a site, domain, or OU. > [!NOTE] > Do not use security policy filtering on a domain controller as this would prevent security policy from applying to it. @@ -385,9 +385,9 @@ By default, all GPOs have Read and Apply Group Policy both Allowed for the Authe In some situations, you might want to migrate GPOs from one domain environment to another environment. The two most common scenarios are test-to-production migration, and production-to-production migration. The GPO copying process has implications for some types of security settings. -Data for a single GPO is stored in multiple locations and in various formats; some data is contained in Active Directory and other data is stored on the SYSVOL share on the domain controllers. Certain policy data might be valid in one domain but might be invalid in the domain to which the GPO is being copied. For example, Security Identifiers (SIDs) stored in security policy settings are often domain-specific. So copying GPOs is not as simple as taking a folder and copying it from one device to another. +Data for a single GPO is stored in multiple locations and in various formats; some data is contained in Active Directory and other data is stored on the SYSVOL share on the domain controllers. Certain policy data might be valid in one domain but might be invalid in the domain to which the GPO is being copied. For example, Security Identifiers (SIDs) stored in security policy settings are often domain-specific. So copying GPOs isn't as simple as taking a folder and copying it from one device to another. -The following security policies can contain security principals and might require some additional work to successfully move them from one domain to another. +The following security policies can contain security principals and might require some more work to successfully move them from one domain to another. - User rights assignment - Restricted groups @@ -396,7 +396,7 @@ The following security policies can contain security principals and might requir - Registry - The GPO DACL, if you choose to preserve it during a copy operation -To ensure that data is copied correctly, you can use Group Policy Management Console (GPMC). When migrating a GPO from one domain to another, GPMC ensures that all relevant data is properly copied. GPMC also offers migration tables, which can be used to update domain-specific data to new values as part of the migration process. GPMC hides much of the complexity involved in the migrating GPO operations, and it provides simple and reliable mechanisms for performing operations such as copy and backup of GPOs. +To ensure that data is copied correctly, you can use Group Policy Management Console (GPMC). When there's a migration of a GPO from one domain to another, GPMC ensures that all relevant data is properly copied. GPMC also offers migration tables, which can be used to update domain-specific data to new values as part of the migration process. GPMC hides much of the complexity involved in the migrating GPO operations, and it provides simple and reliable mechanisms for performing operations such as copy and backup of GPOs. ## In this section diff --git a/windows/security/threat-protection/security-policy-settings/shut-down-the-system.md b/windows/security/threat-protection/security-policy-settings/shut-down-the-system.md index 57374f2aa8..597fe3f069 100644 --- a/windows/security/threat-protection/security-policy-settings/shut-down-the-system.md +++ b/windows/security/threat-protection/security-policy-settings/shut-down-the-system.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management, and security This security setting determines if a user who is logged on locally to a device can shut down Windows. -Shutting down domain controllers makes them unable to do things like process logon requests, process Group Policy settings, and answer Lightweight Directory Access Protocol (LDAP) queries. Shutting down domain controllers that have been assigned operations master roles, which are also known as flexible single master operations or FSMO roles, can disable key domain functionality. For example, processing logon requests for new passwords, which are done by the primary domain controller (PDC) emulator master. +Shutting down domain controllers makes them unable to do things like process sign-in requests, process Group Policy settings, and answer Lightweight Directory Access Protocol (LDAP) queries. Shutting down domain controllers that have been assigned operations master roles, which are also known as flexible single master operations or FSMO roles, can disable key domain functionality. For example, processing sign-in requests for new passwords, which are done by the primary domain controller (PDC) emulator master. The **Shut down the system** user right is required to enable hibernation support, to set the power management settings, and to cancel a shutdown. @@ -44,7 +44,7 @@ Constant: SeShutdownPrivilege ### Best practices 1. Ensure that only Administrators and Backup Operators have the **Shut down the system** user right on member servers. And that only Administrators have the user right on domain controllers. Removing these default groups might limit the abilities of users who are assigned to specific administrative roles in your environment. Ensure that their delegated tasks won't be negatively affected. -2. The ability to shut down domain controllers should be limited to a small number of trusted administrators. Even though a system shutdown requires the ability to log on to the server, you should be careful about the accounts and groups that you allow to shut down a domain controller. +2. The ability to shut down domain controllers should be limited to a few trusted administrators. Even though a system shutdown requires the ability to sign in to the server, you should be careful about the accounts and groups that you allow to shut down a domain controller. ### Location @@ -69,13 +69,13 @@ The following table lists the actual and effective default policy values for the This section describes features, tools, and guidance to help you manage this policy. -A restart of the computer is not required for this policy setting to be effective. +A restart of the computer isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. ### Group Policy -This user right does not have the same effect as **Force shutdown from a remote system**. For more information, see [Force shutdown from a remote system](force-shutdown-from-a-remote-system.md). +This user right doesn't have the same effect as **Force shutdown from a remote system**. For more information, see [Force shutdown from a remote system](force-shutdown-from-a-remote-system.md). Settings are applied in the following order through a Group Policy Object (GPO), which will overwrite settings on the local computer at the next Group Policy update: @@ -92,11 +92,11 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -The ability to shut down domain controllers should be limited to a very small number of trusted administrators. Although the **Shut down the system** user right requires the ability to log on to the server, you should be careful about which accounts and groups you allow to shut down a domain controller. +The ability to shut down domain controllers should be limited to a few trusted administrators. Although the **Shut down the system** user right requires the ability to sign in to the server, you should be careful about which accounts and groups you allow to shut down a domain controller. -When a domain controller is shut down, it can't process logon requests, process Group Policy settings, and answer Lightweight Directory Access Protocol (LDAP) queries. If you shut down domain controllers that have operations master roles, you can disable key domain functionality, such as processing logon requests for new passwords, which are performed by the PDC master. +When a domain controller is shut down, it can't process sign-in requests, process Group Policy settings, and answer Lightweight Directory Access Protocol (LDAP) queries. If you shut down domain controllers that have operations master roles, you can disable key domain functionality, such as processing sign-in requests for new passwords, which are performed by the PDC master. -For other server roles, especially roles where non-administrators have rights to log on to the server, such as RD Session Host servers, it's critical that this user right be removed from users who don't have a legitimate reason to restart the servers. +For other server roles, especially roles where non-administrators have rights to sign in to the server, such as RD Session Host servers, it's critical that this user right be removed from users who don't have a legitimate reason to restart the servers. ### Countermeasure diff --git a/windows/security/threat-protection/security-policy-settings/shutdown-clear-virtual-memory-pagefile.md b/windows/security/threat-protection/security-policy-settings/shutdown-clear-virtual-memory-pagefile.md index 4cada523db..185bbf975e 100644 --- a/windows/security/threat-protection/security-policy-settings/shutdown-clear-virtual-memory-pagefile.md +++ b/windows/security/threat-protection/security-policy-settings/shutdown-clear-virtual-memory-pagefile.md @@ -27,9 +27,9 @@ Describes the best practices, location, values, policy management and security c ## Reference -This policy setting determines whether the virtual memory paging file is cleared when the device is shut down. Virtual memory support uses a system paging file to swap pages of memory to disk when they are not used. On a running device, this paging file is opened exclusively by the operating system, and it is well protected. However, devices that are configured to allow other operating systems to start should verify that the system paging file is cleared as the device shuts down. This confirmation ensures that sensitive information from process memory that might be placed in the paging file is not available to an unauthorized user who manages to directly access the paging file after shutdown. +This policy setting determines whether the virtual memory paging file is cleared when the device is shut down. Virtual memory support uses a system paging file to swap pages of memory to disk when they aren't used. On a running device, this paging file is opened exclusively by the operating system, and it's well protected. However, devices that are configured to allow other operating systems to start should verify that the system paging file is cleared as the device shuts down. This confirmation ensures that sensitive information from process memory that might be placed in the paging file isn't available to an unauthorized user who manages to directly access the paging file after shutdown. -Important information that is kept in real memory might be written periodically to the paging file. This helps devices handle multitasking functions. A malicious user who has physical access to a server that has been shut down can view the contents of the paging file. The attacker can move the system volume into a different computer and then analyze the contents of the paging file. This is a time-consuming process, but it can expose data that is cached from RAM to the paging file. A malicious user who has physical access to the server can bypass this countermeasure by simply unplugging the server from its power source. +Important information that is kept in real memory might be written periodically to the paging file. This periodical write-operation helps devices handle multitasking functions. A malicious user who has physical access to a server that has been shut down can view the contents of the paging file. The attacker can move the system volume into a different computer and then analyze the contents of the paging file. This process is a time-consuming one, but it can expose data that is cached from RAM to the paging file. A malicious user who has physical access to the server can bypass this countermeasure by unplugging the server from its power source. ### Possible values @@ -42,7 +42,7 @@ Important information that is kept in real memory might be written periodically ### Best practices -- Set this policy to **Enabled**. This causes Windows to clear the paging file when the system is shut down. Depending on the size of the paging file, this process might take several minutes before the system completely shuts down. This delay in shutting down the server is especially noticeable on servers with large paging files. For a server with 2 gigabytes (GB) of RAM and a 2-GB paging file, this setting can add more than 30 minutes to the shutdown process. For some organizations, this downtime violates their internal service level agreements. Use caution when implementing this countermeasure in your environment. +- Set this policy to **Enabled**. This policy setting causes Windows to clear the paging file when the system is shut down. Depending on the size of the paging file, this process might take several minutes before the system completely shuts down. This delay in shutting down the server is especially noticeable on servers with large paging files. For a server with 2 gigabytes (GB) of RAM and a 2-GB paging file, this setting can add more than 30 minutes to the shutdown process. For some organizations, this downtime violates their internal service level agreements. Use caution when implementing this countermeasure in your environment. ### Location @@ -67,7 +67,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -85,7 +85,7 @@ Enable the **Shutdown: Clear virtual memory page file** setting. This configurat ### Potential impact -It takes longer to shut down and restart the device, especially on devices with large paging files. For a device with 2 gigabytes (GB) of RAM and a 2-GB paging file, this policy setting could increase the shutdown process by more than 30 minutes. For some organizations this downtime violates their internal service level agreements. Therefore, use caution before you implement this countermeasure in your environment. +It takes longer to shut down and restart the device, especially on devices with large paging files. For a device with 2 gigabytes (GB) of RAM and a 2-GB paging file, this policy setting could increase the shutdown process by more than 30 minutes. For some organizations, this downtime violates their internal service level agreements. Therefore, use caution before you implement this countermeasure in your environment. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-always.md b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-always.md index d5ebfdefe1..b720770fd9 100644 --- a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-always.md +++ b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-always.md @@ -23,7 +23,7 @@ ms.technology: windows-sec **Applies to** - Windows 10 -This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 is not secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMBv1 is not installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). +This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 isn't secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMBv1 isn't installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). The rest of this topic describes the best practices, location, values, policy management and security considerations for the **Microsoft network client: Digitally sign communications (always)** security policy setting only for SMBv1. The same policy setting can be applied to computers that run SMBv2. For more information, see [Microsoft network client: Digitally sign communications (always)](microsoft-network-client-digitally-sign-communications-always.md). @@ -34,7 +34,7 @@ This policy setting determines whether SMB packet signing must be negotiated bef Implementation of digital signatures in high-security networks helps prevent the impersonation of client computers and servers, which is known as "session hijacking." But misuse of these policy settings is a common error that can cause data loss or problems with data access or security. -If server-side SMB signing is required, a client device will not be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device will not be able to establish a session with servers that do not have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. +If server-side SMB signing is required, a client device won't be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device won't be able to establish a session with servers that don't have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. If server-side SMB signing is enabled, SMB packet signing will be negotiated with client computers that have SMB signing enabled. @@ -85,7 +85,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -95,7 +95,7 @@ This section describes how an attacker might exploit a feature or its configurat Session hijacking uses tools that allow attackers who have access to the same network as the client device or server to interrupt, end, or steal a session in progress. Attackers can potentially intercept and modify unsigned Server Message Block (SMB) packets and then modify the traffic and forward it so that the server might perform objectionable actions. Alternatively, the attacker could pose as the server or client computer after legitimate authentication, and gain unauthorized access to data. -SMB is the resource-sharing protocol that is supported by many Windows operating systems. It is the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission does not take place. +SMB is the resource-sharing protocol that is supported by many Windows operating systems. It's the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission doesn't take place. ### Countermeasure @@ -112,9 +112,9 @@ In highly secure environments, we recommend that you configure all of these sett ### Potential impact -Implementations of the SMB file and print-sharing protocol support mutual authentication. This prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. +Implementations of the SMB file and print-sharing protocol support mutual authentication. This mutual authentication prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. -Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure devices to ignore all unsigned SMB communications, older applications and operating systems cannot connect. However, if you completely disable all SMB signing, computers are vulnerable to session-hijacking attacks. +Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure devices to ignore all unsigned SMB communications, older applications and operating systems can't connect. However, if you completely disable all SMB signing, computers are vulnerable to session-hijacking attacks. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md index b1dc905ad5..b912861503 100644 --- a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md +++ b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md @@ -22,7 +22,7 @@ ms.technology: windows-sec **Applies to** - Windows 10 -This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 is not secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMBv1 is not installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). +This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 isn't secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMBv1 isn't installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). The rest of this topic describes the best practices, location, values, and security considerations for the **Microsoft network client: Digitally sign communications (if server agrees)** security policy setting only for SMBv1. The same policy setting can be applied to computers that run SMBv2. For more information, see [Microsoft network client: Digitally sign communications (if server agrees)](microsoft-network-client-digitally-sign-communications-always.md). @@ -32,7 +32,7 @@ The Server Message Block (SMB) protocol provides the basis for Microsoft file an Implementation of digital signatures in high-security networks helps to prevent the impersonation of client computers and servers, which is known as "session hijacking." But misuse of these policy settings is a common error that can cause data loss or problems with data access or security. -If server-side SMB signing is required, a client computer will not be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device will not be able to establish a session with servers that do not have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. +If server-side SMB signing is required, a client computer won't be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device won't be able to establish a session with servers that don't have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. If server-side SMB signing is enabled, SMB packet signing will be negotiated with client computers that have SMB signing enabled. @@ -84,7 +84,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -95,7 +95,7 @@ This section describes how an attacker might exploit a feature or its configurat Session hijacking uses tools that allow attackers who have access to the same network as the client or server to interrupt, end, or steal a session in progress. Attackers can potentially intercept and modify unsigned Server Message Block (SMB) packets and then modify the traffic and forward it so that the server might perform objectionable actions. Alternatively, the attacker could pose as the server or client device after legitimate authentication and gain unauthorized access to data. -SMB is the resource-sharing protocol that is supported by many Windows operating systems. It is the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission does not take place. +SMB is the resource-sharing protocol that is supported by many Windows operating systems. It's the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission doesn't take place. ### Countermeasure @@ -106,16 +106,16 @@ Configure the settings as follows: - Enable **Microsoft network client: Digitally sign communications (if server agrees)**. - Enable [Microsoft network server: Digitally sign communications (if client agrees)](smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md). -In highly secure environments we recommend that you configure all of these settings to Enabled. However, that configuration may cause slower performance on client devices and prevent communications with earlier SMB applications and operating systems. +In highly secure environments, we recommend that you configure all of these settings to Enabled. However, that configuration may cause slower performance on client devices and prevent communications with earlier SMB applications and operating systems. > [!NOTE] > An alternative countermeasure that could protect all network traffic is to implement digital signatures with IPsec. There are hardware-based accelerators for IPsec encryption and signing that could be used to minimize the performance impact on the servers' CPUs. No such accelerators are available for SMB signing. ### Potential impact -Implementations of the SMB file and print-sharing protocol support mutual authentication. This prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. +Implementations of the SMB file and print-sharing protocol support mutual authentication. This mutual authentication prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. -Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure devices to ignore all unsigned SMB communications, older applications and operating systems cannot connect. However, if you completely disable all SMB signing, devices are vulnerable to session-hijacking +Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure devices to ignore all unsigned SMB communications, older applications and operating systems can't connect. However, if you completely disable all SMB signing, devices are vulnerable to session-hijacking attacks. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-always.md b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-always.md index e091179e64..49782f3f58 100644 --- a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-always.md +++ b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-always.md @@ -23,7 +23,7 @@ ms.technology: windows-sec **Applies to** - Windows 10 -This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 is not secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMB v1 is not installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). +This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 isn't secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMB v1 isn't installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). The rest of this topic describes the best practices, location, values, policy management and security considerations for the **Microsoft network server: Digitally sign communications (always)** security policy setting only for SMBv1. The same policy setting can be applied to computers that run SMBv2. Fore more information, see [Microsoft network server: Digitally sign communications (always)](microsoft-network-server-digitally-sign-communications-always.md). @@ -34,9 +34,9 @@ This policy setting determines whether SMB packet signing must be negotiated bef Implementation of digital signatures in high-security networks helps to prevent the impersonation of client computers and servers, which is known as "session hijacking." But misuse of these policy settings is a common error that can cause data loss or problems with data access or security. -For this policy to take effect on computers running Windows 2000, client-side packet signing must also be enabled. To enable client-side SMB packet signing, set [Microsoft network client: Digitally sign communications (if server agrees)](smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md). Devices that have this policy set will not be able to communicate with devices that do not have server-side packet signing enabled. By default, server-side packet signing is enabled only on domain controllers. Server-side packet signing can be enabled on devices by setting [Microsoft network server: Digitally sign communications (if client agrees)](smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md). +For this policy to take effect on computers running Windows 2000, client-side packet signing must also be enabled. To enable client-side SMB packet signing, set [Microsoft network client: Digitally sign communications (if server agrees)](smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md). Devices that have this policy set won't be able to communicate with devices that don't have server-side packet signing enabled. By default, server-side packet signing is enabled only on domain controllers. Server-side packet signing can be enabled on devices by setting [Microsoft network server: Digitally sign communications (if client agrees)](smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md). -If server-side SMB signing is required, a client device will not be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device will not be able to establish a session with servers that do not have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. +If server-side SMB signing is required, a client device won't be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device won't be able to establish a session with servers that don't have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. If server-side SMB signing is enabled, SMB packet signing will be negotiated with client devices that have SMB signing enabled. @@ -88,7 +88,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -98,7 +98,7 @@ This section describes how an attacker might exploit a feature or its configurat Session hijacking uses tools that allow attackers who have access to the same network as the client device or server to interrupt, end, or steal a session in progress. Attackers can potentially intercept and modify unsigned Server Message Block (SMB) packets and then modify the traffic and forward it so that the server might perform objectionable actions. Alternatively, the attacker could pose as the server or client device after legitimate authentication and gain unauthorized access to data. -SMB is the resource-sharing protocol that is supported by many Windows operating systems. It is the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission does not take place. +SMB is the resource-sharing protocol that is supported by many Windows operating systems. It's the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission doesn't take place. ### Countermeasure @@ -109,15 +109,15 @@ Configure the settings as follows: - Enable [Microsoft network client: Digitally sign communications (if server agrees)](smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md). - Enable [Microsoft network server: Digitally sign communications (if client agrees)](smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md). -In highly secure environments we recommend that you configure all of these settings to Enabled. However, that configuration may cause slower performance on client devices and prevent communications with earlier SMB applications and operating systems. +In highly secure environments, we recommend that you configure all of these settings to Enabled. However, that configuration may cause slower performance on client devices and prevent communications with earlier SMB applications and operating systems. >**Note:**  An alternative countermeasure that could protect all network traffic is to implement digital signatures with IPsec. There are hardware-based accelerators for IPsec encryption and signing that could be used to minimize the performance impact on the servers' CPUs. No such accelerators are available for SMB signing. ### Potential impact -Implementations of the SMB file and print-sharing protocol support mutual authentication. This prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. +Implementations of the SMB file and print-sharing protocol support mutual authentication. This mutual authentication prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. -Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure computers to ignore all unsigned SMB communications, older applications and operating systems cannot connect. However, if you completely disable all SMB signing, devices are vulnerable to session-hijacking attacks. +Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure computers to ignore all unsigned SMB communications, older applications and operating systems can't connect. However, if you completely disable all SMB signing, devices are vulnerable to session-hijacking attacks. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md index 228cd2ec2b..75a325c3b4 100644 --- a/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md +++ b/windows/security/threat-protection/security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md @@ -23,7 +23,7 @@ ms.technology: windows-sec **Applies to** - Windows 10 -This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 is not secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMBv1 is not installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). +This topic is about the Server Message Block (SMB) v1 protocol. SMBv1 isn't secure and has been deprecated in Windows. Beginning with Windows 10 Fall Creators Update and Windows Server, version 1709, [SMBv1 isn't installed by default](/windows-server/storage/file-server/troubleshoot/smbv1-not-installed-by-default-in-windows). The rest of this topic describes the best practices, location, values, policy management and security considerations for the **Microsoft network server: Digitally sign communications (if client agrees)** security policy setting only for SMBv1. The same policy setting can be applied to computers that run SMBv2. For more information, see [Microsoft network server: Digitally sign communications (if client agrees)](microsoft-network-server-digitally-sign-communications-always.md). @@ -34,7 +34,7 @@ This policy setting determines whether SMB packet signing must be negotiated bef Implementation of digital signatures in high-security networks helps to prevent the impersonation of client computers and servers, which is known as "session hijacking." But misuse of these policy settings is a common error that can cause data loss or problems with data access or security. -If server-side SMB signing is required, a client device will not be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device will not be able to establish a session with servers that do not have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. +If server-side SMB signing is required, a client device won't be able to establish a session with that server, unless it has client-side SMB signing enabled. By default, client-side SMB signing is enabled on workstations, servers, and domain controllers. Similarly, if client-side SMB signing is required, that client device won't be able to establish a session with servers that don't have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers. If server-side SMB signing is enabled, SMB packet signing will be negotiated with client computers that have SMB signing enabled. @@ -87,7 +87,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -97,7 +97,7 @@ This section describes how an attacker might exploit a feature or its configurat Session hijacking uses tools that allow attackers who have access to the same network as the client device or server to interrupt, end, or steal a session in progress. Attackers can potentially intercept and modify unsigned Server Message Block (SMB) packets and then modify the traffic and forward it so that the server might perform objectionable actions. Alternatively, the attacker could pose as the server or client computer after legitimate authentication and gain unauthorized access to data. -SMB is the resource-sharing protocol that is supported by many Windows operating systems. It is the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission does not take place. +SMB is the resource-sharing protocol that is supported by many Windows operating systems. It's the basis of NetBIOS and many other protocols. SMB signatures authenticate users and the servers that host the data. If either side fails the authentication process, data transmission doesn't take place. ### Countermeasure @@ -108,15 +108,15 @@ Configure the settings as follows: - Enable [Microsoft network client: Digitally sign communications (if server agrees)](smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md). - Enable **Microsoft network server: Digitally sign communications (if client agrees)**. -In highly secure environments we recommend that you configure all of these settings to Enabled. However, that configuration may cause slower performance on client devices and prevent communications with earlier SMB applications and operating systems. +In highly secure environments, we recommend that you configure all of these settings to Enabled. However, that configuration may cause slower performance on client devices and prevent communications with earlier SMB applications and operating systems. >**Note:** An alternative countermeasure that could protect all network traffic is to implement digital signatures with IPsec. There are hardware-based accelerators for IPsec encryption and signing that could be used to minimize the performance impact on the servers' CPUs. No such accelerators are available for SMB signing. ### Potential impact -SMB file and print-sharing protocol support mutual authentication. This prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. +SMB file and print-sharing protocol support mutual authentication. This mutual authentication prevents session hijacking attacks and supports message authentication to prevent man-in-the-middle attacks. SMB signing provides this authentication by placing a digital signature into each SMB, which is then verified by the client and the server. -Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure computers to ignore all unsigned SMB communications, older applications and operating systems cannot connect. However, if you completely disable all SMB signing, computers are vulnerable to session-hijacking attacks. +Implementation of SMB signing may negatively affect performance because each packet must be signed and verified. If these settings are enabled on a server that is performing multiple roles, such as a small business server that is serving as a domain controller, file server, print server, and application server, performance may be substantially slowed. Additionally, if you configure computers to ignore all unsigned SMB communications, older applications and operating systems can't connect. However, if you completely disable all SMB signing, computers are vulnerable to session-hijacking attacks. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption.md b/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption.md index ea2f55d403..316d4868dd 100644 --- a/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption.md +++ b/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption.md @@ -27,7 +27,7 @@ Describes the best practices, location, values, and security considerations for ## Reference -The **Store password using reversible encryption** policy setting provides support for applications that use protocols that require the user's password for authentication. Storing encrypted passwords in a way that is reversible means that the encrypted passwords can be decrypted. A knowledgeable attacker who is able to break this encryption can then log on to network resources by using the compromised account. For this reason, never enable **Store password using reversible encryption** for all users in the domain unless application requirements outweigh the need to protect password information. +The **Store password using reversible encryption** policy setting provides support for applications that use protocols that require the user's password for authentication. Storing encrypted passwords in a way that is reversible means that the encrypted passwords can be decrypted. A knowledgeable attacker who is able to break this encryption can then sign in to network resources by using the compromised account. For this reason, never enable **Store password using reversible encryption** for all users in the domain unless application requirements outweigh the need to protect password information. If you use the Challenge Handshake Authentication Protocol (CHAP) through remote access or Internet Authentication Services (IAS), you must enable this policy setting. CHAP is an authentication protocol that is used by remote access and network connections. Digest Authentication in Internet Information Services (IIS) also requires that you enable this policy setting. @@ -39,7 +39,7 @@ Information Services (IIS) also requires that you enable this policy setting. ### Best practices -Set the value for **Store password using reversible encryption** to Disabled. If you use CHAP through remote access or IAS, or Digest Authentication in IIS, you must set this value to **Enabled**. This presents a security risk when you apply the setting by using Group Policy on a user-by-user basis because it requires opening the appropriate user account object in Active Directory Users and Computers. +Set the value for **Store password using reversible encryption** to Disabled. If you use CHAP through remote access or IAS, or Digest Authentication in IIS, you must set this value to **Enabled**. This setting presents a security risk when you apply the setting by using Group Policy on a user-by-user basis because it requires opening the appropriate user account object in Active Directory Users and Computers. >**Note:**  Do not enable this policy setting unless business requirements outweigh the need to protect password information. @@ -77,7 +77,7 @@ Disable the **Store password using reversible encryption** policy setting. ### Potential impact -If your organization uses CHAP through remote access or IAS, or Digest Authentication in IIS, you must configure this policy setting to Enabled. This presents a security risk when you apply the setting through Group Policy on a user-by-user basis because it requires the appropriate user account object to be opened in Active Directory Users and Computers. +If your organization uses CHAP through remote access or IAS, or Digest Authentication in IIS, you must configure this policy setting to Enabled. This setting presents a security risk when you apply the setting through Group Policy on a user-by-user basis because it requires the appropriate user account object to be opened in Active Directory Users and Computers. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/synchronize-directory-service-data.md b/windows/security/threat-protection/security-policy-settings/synchronize-directory-service-data.md index 88f07c4037..e6e95159e1 100644 --- a/windows/security/threat-protection/security-policy-settings/synchronize-directory-service-data.md +++ b/windows/security/threat-protection/security-policy-settings/synchronize-directory-service-data.md @@ -46,7 +46,7 @@ Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\Use ### Default values -By default this setting is not defined on domain controllers and on stand-alone servers. +By default this setting isn't defined on domain controllers and on stand-alone servers. The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page. @@ -63,7 +63,7 @@ The following table lists the actual and effective default policy values. Defaul This section describes features, tools, and guidance to help you manage this policy. -A restart of the device is not required for this policy setting to be effective. +A restart of the device isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. @@ -84,7 +84,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -The **Synchronize directory service data** user right affects domain controllers (only domain controllers should be able to synchronize directory service data). Domain controllers have this user right inherently because the synchronization process runs in the context of the **System** account on domain controllers. Attackers who have this user right can view all information that is stored within the directory. They could then use some of that information to facilitate additional attacks or expose sensitive data, such as direct telephone numbers or physical addresses. +The **Synchronize directory service data** user right affects domain controllers (only domain controllers should be able to synchronize directory service data). Domain controllers have this user right inherently because the synchronization process runs in the context of the **System** account on domain controllers. Attackers who have this user right can view all information that is stored within the directory. They could then use some of that information to facilitate more attacks or expose sensitive data, such as direct telephone numbers or physical addresses. ### Countermeasure diff --git a/windows/security/threat-protection/security-policy-settings/system-cryptography-force-strong-key-protection-for-user-keys-stored-on-the-computer.md b/windows/security/threat-protection/security-policy-settings/system-cryptography-force-strong-key-protection-for-user-keys-stored-on-the-computer.md index d5dd1f683e..7e0e17cc6d 100644 --- a/windows/security/threat-protection/security-policy-settings/system-cryptography-force-strong-key-protection-for-user-keys-stored-on-the-computer.md +++ b/windows/security/threat-protection/security-policy-settings/system-cryptography-force-strong-key-protection-for-user-keys-stored-on-the-computer.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management and security c This policy setting determines whether users can use private keys, such as their Secure/Multipurpose Internet Mail Extensions (S/MIME) key, without a password. -Configuring this policy setting so that users must provide a password every time they use a key (in addition to their domain password) makes it more difficult for a malicious user to access locally-stored user keys, even if the attacker takes control of the user's device and determines their logon password. +Configuring this policy setting so that users must provide a password every time they use a key (in addition to their domain password) makes it more difficult for a malicious user to access locally stored user keys, even if the attacker takes control of the user's device and determines their sign-in password. ### Possible values @@ -40,7 +40,7 @@ Configuring this policy setting so that users must provide a password every time ### Best practices -- Set this policy to **User must enter a password each time they use a key**. Users must enter their password every time they access a key that is stored on their computer. For example, if users use an S/MIME certificate to digitally sign their email, they will be forced to enter the password for that certificate every time they send a signed email message. For some organizations, the overhead that is caused by using this value might be too high, but they should set the value at a minimum to **User is prompted when the key is first used**. +- Set this policy to **User must enter a password each time they use a key**. Users must enter their password every time they access a key that is stored on their computer. For example, if users use an S/MIME certificate to digitally sign their email, they'll be forced to enter the password for that certificate every time they send a signed email message. For some organizations, the overhead that is caused by using this value might be too high, but they should set the value at a minimum to **User is prompted when the key is first used**. ### Location @@ -65,7 +65,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -77,11 +77,11 @@ If a user's account is compromised or the user's device is inadvertently left un ### Countermeasure -Configure the **System cryptography: Force strong key protection for user keys stored on the computer** setting to **User must enter a password each time they use a key** so that users must provide a password that is distinct from their domain password every time they use a key. This configuration makes it more difficult for an attacker to access locally stored user keys, even if the attacker takes control of the user's computer and determines the logon password. +Configure the **System cryptography: Force strong key protection for user keys stored on the computer** setting to **User must enter a password each time they use a key** so that users must provide a password that is distinct from their domain password every time they use a key. This configuration makes it more difficult for an attacker to access locally stored user keys, even if the attacker takes control of the user's computer and determines the sign-in password. ### Potential impact -Users must type their password every time they access a key that is stored on their device. For example, if users use an S/MIME certificate to digitally sign their email, they are forced to type the password for that certificate every time they send a signed email message. For some organizations, the overhead that is involved by using this configuration may be too high. At a minimum, this setting should be set to **User is prompted when the key is first used**. +Users must type their password every time they access a key that is stored on their device. For example, if users use an S/MIME certificate to digitally sign their email, they're forced to type the password for that certificate every time they send a signed email message. For some organizations, the overhead that is involved by using this configuration may be too high. At a minimum, this setting should be set to **User is prompted when the key is first used**. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/system-cryptography-use-fips-compliant-algorithms-for-encryption-hashing-and-signing.md b/windows/security/threat-protection/security-policy-settings/system-cryptography-use-fips-compliant-algorithms-for-encryption-hashing-and-signing.md index e98291ef6b..e38443c02b 100644 --- a/windows/security/threat-protection/security-policy-settings/system-cryptography-use-fips-compliant-algorithms-for-encryption-hashing-and-signing.md +++ b/windows/security/threat-protection/security-policy-settings/system-cryptography-use-fips-compliant-algorithms-for-encryption-hashing-and-signing.md @@ -57,7 +57,7 @@ Additionally, if a data drive is password-protected, it can be accessed by a FIP ### Best practices -We recommend that customers hoping to comply with FIPS 140-2 research the configuration settings of applications and protocols they may be using to ensure their solutions can be configured to utilize the FIPS 140-2 validated cryptography provided by Windows when it is operating in FIPS 140-2 approved mode. +We recommend that customers hoping to comply with FIPS 140-2 research the configuration settings of applications and protocols they may be using to ensure their solutions can be configured to utilize the FIPS 140-2 validated cryptography provided by Windows when it's operating in FIPS 140-2 approved mode. For a complete list of Microsoft-recommended configuration settings, see [Windows security baselines](../windows-security-baselines.md). For more information about Windows and FIPS 140-2, see [FIPS 140 Validation](../fips-140-validation.md). @@ -82,11 +82,11 @@ The following table lists the actual and effective default values for this polic When this setting is enabled, the Encrypting File System (EFS) service supports only the Triple DES encryption algorithm for encrypting file data. By default, the Windows Vista and the Windows Server 2003 implementation of EFS uses the Advanced Encryption Standard (AES) with a 256-bit key. The Windows XP implementation uses DESX. -When this setting is enabled, BitLocker generates recovery password or recovery keys applicable to versions listed in the following: +When this setting is enabled, BitLocker generates recovery password or recovery keys applicable to the following versions: | Operating systems | Applicability | | - | - | -| Windows 10, Windows 8.1, and Windows Server 2012 R2| When created on these operating systems, the recovery password cannot be used on other systems listed in this table.| +| Windows 10, Windows 8.1, and Windows Server 2012 R2| When created on these operating systems, the recovery password can't be used on other systems listed in this table.| | Windows Server 2012 and Windows 8 | When created on these operating systems, the recovery key can be used on other systems listed in this table as well.| | Windows Server 2008 R2 and Windows 7 | When created on these operating systems, the recovery key can be used on other systems listed in this table as well.| | Windows Server 2008 and Windows Vista | When created on these operating systems, the recovery key can be used on other systems listed in this table as well.| @@ -97,7 +97,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -117,8 +117,8 @@ Enable the **System cryptography: Use FIPS compliant algorithms for encryption, ### Potential impact -Client devices that have this policy setting enabled cannot communicate by means of digitally encrypted or signed protocols with servers that do not support these algorithms. Network clients that do not support these algorithms cannot use servers that require them for network communications. For example, many Apache-based Web servers are not configured to support TLS. If you enable this setting, you must also configure Internet Explorer® to use TLS. This policy setting also affects the encryption level that is used for the Remote Desktop Protocol (RDP). The Remote Desktop Connection tool -uses the RDP protocol to communicate with servers that run Terminal Services and client computers that are configured for remote control; RDP connections fail if both devices are not configured to use the same encryption algorithms. +Client devices that have this policy setting enabled can't communicate through digitally encrypted or signed protocols with servers that don't support these algorithms. Network clients that don't support these algorithms can't use servers that require them for network communications. For example, many Apache-based Web servers aren't configured to support TLS. If you enable this setting, you must also configure Internet Explorer® to use TLS. This policy setting also affects the encryption level that is used for the Remote Desktop Protocol (RDP). The Remote Desktop Connection tool +uses the RDP protocol to communicate with servers that run Terminal Services and client computers that are configured for remote control; RDP connections fail if both devices aren't configured to use the same encryption algorithms. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/system-objects-require-case-insensitivity-for-non-windows-subsystems.md b/windows/security/threat-protection/security-policy-settings/system-objects-require-case-insensitivity-for-non-windows-subsystems.md index 3a9ceb4840..9c7c2c4433 100644 --- a/windows/security/threat-protection/security-policy-settings/system-objects-require-case-insensitivity-for-non-windows-subsystems.md +++ b/windows/security/threat-protection/security-policy-settings/system-objects-require-case-insensitivity-for-non-windows-subsystems.md @@ -27,9 +27,9 @@ Describes the best practices, location, values, policy management, and security ## Reference -This policy setting determines whether case insensitivity is enforced for all subsystems. The Microsoft Win32 subsystem is not case sensitive; however, the kernel supports case sensitivity for other subsystems, such as Portable Operating System Interface for UNIX (POSIX). Enabling this policy setting enforces case insensitivity for all directory objects, symbolic links, and input/output (I/O) objects, including file objects. Disabling this policy setting does not allow the Win32 subsystem to become case sensitive. +This policy setting determines whether case insensitivity is enforced for all subsystems. The Microsoft Win32 subsystem isn't case sensitive; however, the kernel supports case sensitivity for other subsystems, such as Portable Operating System Interface for UNIX (POSIX). Enabling this policy setting enforces case insensitivity for all directory objects, symbolic links, and input/output (I/O) objects, including file objects. Disabling this policy setting doesn't allow the Win32 subsystem to become case sensitive. -Because Windows is case insensitive but the POSIX subsystem will support case sensitivity, if this policy setting is not enforced, it is possible for a user of that subsystem to create a file with the same name as another file but with a different mix of capital letters. That might confuse users when they try to access these files by using normal Win32 tools, because only one of the files will be available. +Because Windows is case insensitive but the POSIX subsystem will support case sensitivity, if this policy setting isn't enforced, it's possible for a user of that subsystem to create a file with the same name as another file but with a different mix of capital letters. That convention might confuse users when they try to access these files by using normal Win32 tools, because only one of the files will be available. ### Possible values @@ -39,13 +39,13 @@ Because Windows is case insensitive but the POSIX subsystem will support case se - Disabled - Will not allow the Win32 subsystem to become case sensitive. + Won't allow the Win32 subsystem to become case sensitive. - Not defined ### Best practices -- Set this policy to **Enabled**. All subsystems will be forced to observe case insensitivity. However, this might confuse users who are familiar with one of the UNIX-based operating systems and are used to a case sensitive operating system. +- Set this policy to **Enabled**. All subsystems will be forced to observe case insensitivity. However, this insensitivity might confuse users who are familiar with one of the UNIX-based operating systems and are used to a case sensitive operating system. ### Location @@ -70,7 +70,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations diff --git a/windows/security/threat-protection/security-policy-settings/system-objects-strengthen-default-permissions-of-internal-system-objects.md b/windows/security/threat-protection/security-policy-settings/system-objects-strengthen-default-permissions-of-internal-system-objects.md index abd9724c03..71e2fa8221 100644 --- a/windows/security/threat-protection/security-policy-settings/system-objects-strengthen-default-permissions-of-internal-system-objects.md +++ b/windows/security/threat-protection/security-policy-settings/system-objects-strengthen-default-permissions-of-internal-system-objects.md @@ -1,6 +1,6 @@ --- -title: System objects Strengthen default permissions of internal system objects (e.g., Symbolic Links) (Windows 10) -description: Best practices and more for the security policy setting, System objects Strengthen default permissions of internal system objects (e.g. Symbolic Links). +title: System objects Strengthen default permissions of internal system objects (for example, Symbolic Links) (Windows 10) +description: Best practices and more for the security policy setting, System objects Strengthen default permissions of internal system objects (for example, Symbolic Links). ms.assetid: 3a592097-9cf5-4fd0-a504-7cbfab050bb6 ms.reviewer: ms.author: dansimp @@ -27,7 +27,7 @@ Describes the best practices, location, values, policy management and security c ## Reference -This policy setting determines the strength of the default discretionary access control list (DACL) for objects. Windows maintains a global list of shared system resources such as MS-DOS device names, mutexes, and semaphores. By using this list, processes can locate and share objects. Each type of object is created with a default DACL that specifies who can access the objects with what permissions. Enabling this policy setting strengthens the default DACL and allows users who are not administrators to read, but not to modify, shared objects that they did not create. +This policy setting determines the strength of the default discretionary access control list (DACL) for objects. Windows maintains a global list of shared system resources such as MS-DOS device names, mutexes, and semaphores. The processes use this list to locate and share objects. Each type of object is created with a default DACL that specifies who can access the objects with what permissions. Enabling this policy setting strengthens the default DACL and allows users who aren't administrators to read, but not to modify, shared objects that they didn't create. ### Possible values @@ -37,7 +37,7 @@ This policy setting determines the strength of the default discretionary access ### Best practices -- It is advisable to set this policy to **Enabled**. +- It's advisable to set this policy to **Enabled**. ### Location @@ -62,7 +62,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -70,7 +70,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -This policy setting is enabled by default to protect against a known vulnerability that can be used with hard links or symbolic links. Hard links are actual directory entries in the file system. With hard links, the same data in a file system can be referred to by different file names. Symbolic links are text files that provide a pointer to the file that is interpreted and followed by the operating system as a path to another file or directory. Because symbolic links are a separate file, they can exist independently of the target location. If a symbolic link is deleted, its target location remains unaffected. When this setting is disabled, it is possible for a malicious user to destroy a data file by creating a link that looks like a temporary file that the system automatically creates, such as a sequentially named log file, but it points to the data file that the malicious user wants to eradicate. When the system writes the files with that name, the data is overwritten. Enabling **System objects: Strengthen default permissions of internal system objects (e.g., Symbolic Links)** prevents an attacker from exploiting programs that create files with predictable names by not allowing them to write to objects that they did not create. +This policy setting is enabled by default to protect against a known vulnerability that can be used with hard links or symbolic links. Hard links are actual directory entries in the file system. With hard links, the same data in a file system can be referred to by different file names. Symbolic links are text files that provide a pointer to the file that is interpreted and followed by the operating system as a path to another file or directory. Because symbolic links are a separate file, they can exist independently of the target location. If a symbolic link is deleted, its target location remains unaffected. When this setting is disabled, it's possible for a malicious user to destroy a data file by creating a link that looks like a temporary file that the system automatically creates, such as a sequentially named log file, but it points to the data file that the malicious user wants to eradicate. When the system writes the files with that name, the data is overwritten. Enabling **System objects: Strengthen default permissions of internal system objects (e.g., Symbolic Links)** prevents an attacker from exploiting programs that create files with predictable names by not allowing them to write to objects that they didn't create. ### Countermeasure @@ -78,7 +78,7 @@ Enable the **System objects: Strengthen default permissions of global system obj ### Potential impact -None. This is the default configuration. +None. This non-impact state is the default configuration. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/system-settings-optional-subsystems.md b/windows/security/threat-protection/security-policy-settings/system-settings-optional-subsystems.md index a271d9f87f..8db727008d 100644 --- a/windows/security/threat-protection/security-policy-settings/system-settings-optional-subsystems.md +++ b/windows/security/threat-protection/security-policy-settings/system-settings-optional-subsystems.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management, and security This policy setting determines which subsystems support your applications. You can use this security setting to specify as many subsystems as your environment demands. -The subsystem introduces a security risk that is related to processes that can potentially persist across logons. If a user starts a process and then logs out, the next user who logs on to the system might access the process that the previous user started. This is dangerous, because the process started by the first user can retain that user's system user rights; therefore, anything that the second user does using that process is performed with the user rights of the first user. This makes it difficult to trace who creates processes and objects, which is essential for post-security incident forensics. +The subsystem introduces a security risk that is related to processes that can potentially persist across logons. If a user starts a process and then signs out, the next user who signs in to the system might access the process that the previous user started. This pattern is dangerous, because the process started by the first user can retain that user's system user rights; therefore, anything that the second user does using that process is performed with the user rights of the first user. This privileges rollover makes it difficult to trace who creates processes and objects, which is essential for post-security incident forensics. ### Possible values @@ -63,7 +63,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -73,7 +73,7 @@ This section describes how an attacker might exploit a feature or its configurat The POSIX subsystem is an Institute of Electrical and Electronic Engineers (IEEE) standard that defines a set of operating system services. The POSIX subsystem is required if the server supports applications that use that subsystem. -The POSIX subsystem introduces a security risk that relates to processes that can potentially persist across logons. If a user starts a process and then logs out, there is a potential that the next user who logs on to the computer could access the previous user's process. This would allow the second user to take actions on the process by using the privileges of the first user. +The POSIX subsystem introduces a security risk that relates to processes that can potentially persist across sign-ins. If a user starts a process and then signs out, there's a potential that the next user who signs in to the computer could access the previous user's process. This accessibility would allow the second user to take actions on the process by using the privileges of the first user. ### Countermeasure diff --git a/windows/security/threat-protection/security-policy-settings/system-settings-use-certificate-rules-on-windows-executables-for-software-restriction-policies.md b/windows/security/threat-protection/security-policy-settings/system-settings-use-certificate-rules-on-windows-executables-for-software-restriction-policies.md index 9791d8a12d..e58a8d0925 100644 --- a/windows/security/threat-protection/security-policy-settings/system-settings-use-certificate-rules-on-windows-executables-for-software-restriction-policies.md +++ b/windows/security/threat-protection/security-policy-settings/system-settings-use-certificate-rules-on-windows-executables-for-software-restriction-policies.md @@ -63,7 +63,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations diff --git a/windows/security/threat-protection/security-policy-settings/take-ownership-of-files-or-other-objects.md b/windows/security/threat-protection/security-policy-settings/take-ownership-of-files-or-other-objects.md index c4781f258c..b3272708b2 100644 --- a/windows/security/threat-protection/security-policy-settings/take-ownership-of-files-or-other-objects.md +++ b/windows/security/threat-protection/security-policy-settings/take-ownership-of-files-or-other-objects.md @@ -31,7 +31,7 @@ This policy setting determines which users can take ownership of any securable o Every object has an owner, whether the object resides in an NTFS volume or Active Directory database. The owner controls how permissions are set on the object and to whom permissions are granted. -By default, the owner is the person who or the process which created the object. Owners can always change permissions to objects, even when they are denied all access to the object. +By default, the owner is the person who or the process that created the object. Owners can always change permissions to objects, even when they're denied all access to the object. Constant: SeTakeOwnershipPrivilege @@ -67,7 +67,7 @@ The following table lists the actual and effective default policy values. Defaul This section describes features, tools, and guidance to help you manage this policy. -A restart of the device is not required for this policy setting to be effective. +A restart of the device isn't required for this policy setting to be effective. Any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on. diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account.md b/windows/security/threat-protection/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account.md index 16e00a82f8..d6d32d8a08 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account.md @@ -27,7 +27,7 @@ Describes the best practices, location, values, policy management and security c ## Reference This policy setting determines the behavior of Admin Approval Mode for the built-in administrator account. -When the Admin Approval Mode is enabled, the local administrator account functions like a standard user account, but it has the ability to elevate privileges without logging on by using a different account. In this mode, any operation that requires elevation of privilege displays a prompt that allows the administrator to permit or deny the elevation of privilege. If Admin Approval Mode is not enabled, the built-in Administrator account runs all applications by default with full administrative privileges. By default, Admin Approval Mode is set to **Disabled**. +When the Admin Approval Mode is enabled, the local administrator account functions like a standard user account, but it has the ability to elevate privileges without logging on by using a different account. In this mode, any operation that requires elevation of privilege displays a prompt that allows the administrator to permit or deny the elevation of privilege. If Admin Approval Mode isn't enabled, the built-in Administrator account runs all applications by default with full administrative privileges. By default, Admin Approval Mode is set to **Disabled**. > [!NOTE] > If a computer is upgraded from a previous version of the Windows operating system, and the administrator account is the only account on the computer, the built-in administrator account remains enabled, and this setting is also enabled. @@ -40,11 +40,11 @@ When the Admin Approval Mode is enabled, the local administrator account functio - Disabled - If Admin Approval Mode is not enabled, the built-in Administrator account runs all applications by default with full administrative privileges + If Admin Approval Mode isn't enabled, the built-in Administrator account runs all applications by default with full administrative privileges ### Best practices -- It is recommended not to enable the built-in Administrator account on the client computer, but to use the standard user account and User Account Control (UAC) instead. If you want to enable the built-in Administrator account to carry out administrative tasks, for security reasons you should also enable Admin Approval Mode. See [UAC-Admin-Approval-Mode-for-the-Built-in-Administrator-account](/windows/device-security/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account) +- It's recommended not to enable the built-in Administrator account on the client computer, but to use the standard user account and User Account Control (UAC) instead. If you want to enable the built-in Administrator account to carry out administrative tasks, for security reasons you should also enable Admin Approval Mode. See [UAC-Admin-Approval-Mode-for-the-Built-in-Administrator-account](/windows/device-security/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account) To enable Admin Approval Mode, you must also configure the local security policy setting: [User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode](/windows/device-security/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode) to **Prompt for consent on the secure desktop** and then click OK. @@ -74,7 +74,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations @@ -82,7 +82,7 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -One of the risks that the UAC feature tries to mitigate is that of malicious software running under elevated credentials without the user or administrator being aware of its activity. An attack vector for malicious programs is to discover the password of the Administrator account because that user account was created for all installations of Windows. To address this risk, the built-in Administrator account is disabled in computers running at least Windows Vista. In computers running at least Windows Server 2008, the Administrator account is enabled, and the password must be changed the first time the administrator logs on. In a default installation of a computer running at least Windows Vista, if the computer is not joined to a domain, the first user account you create has the equivalent permissions of a local administrator. +One of the risks that the UAC feature tries to mitigate is that of malicious software running under elevated credentials without the user or administrator being aware of its activity. An attack vector for malicious programs is to discover the password of the Administrator account because that user account was created for all installations of Windows. To address this risk, the built-in Administrator account is disabled in computers running at least Windows Vista. In computers running at least Windows Server 2008, the Administrator account is enabled, and the password must be changed the first time the administrator logs on. In a default installation of a computer running at least Windows Vista, if the computer isn't joined to a domain, the first user account you create has the equivalent permissions of a local administrator. ### Countermeasure @@ -90,7 +90,7 @@ Enable the **User Account Control: Admin Approval Mode for the Built-in Administ ### Potential impact -Users who log on by using the local administrator account are prompted for consent whenever a program requests an elevation in privilege. +Users who sign in by using the local administrator account are prompted for consent whenever a program requests an elevation in privilege. ## Related topics - [Security Options](/windows/device-security/security-policy-settings/security-options) \ No newline at end of file diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-allow-uiaccess-applications-to-prompt-for-elevation-without-using-the-secure-desktop.md b/windows/security/threat-protection/security-policy-settings/user-account-control-allow-uiaccess-applications-to-prompt-for-elevation-without-using-the-secure-desktop.md index 8526a457ae..4ade31f9ed 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-allow-uiaccess-applications-to-prompt-for-elevation-without-using-the-secure-desktop.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-allow-uiaccess-applications-to-prompt-for-elevation-without-using-the-secure-desktop.md @@ -91,7 +91,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -99,7 +99,7 @@ All auditing capabilities are integrated in Group Policy. You can configure, dep ### Policy interactions -If you plan to enable this setting, you should also review the effect of the [User Account Control: Behavior of the elevation prompt for standard users](user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md) setting. If it is configured as **Automatically deny elevation requests**, elevation requests are not presented to the user. If you disable this setting, the secure desktop can only be disabled by the user of the interactive desktop or by disabling the [User Account Control: Switch to the secure desktop when prompting for elevation](user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md) setting, which by default is enabled. +If you plan to enable this setting, you should also review the effect of the [User Account Control: Behavior of the elevation prompt for standard users](user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md) setting. If it's configured as **Automatically deny elevation requests**, elevation requests aren't presented to the user. If you disable this setting, the secure desktop can only be disabled by the user of the interactive desktop or by disabling the [User Account Control: Switch to the secure desktop when prompting for elevation](user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md) setting, which by default is enabled. ## Security considerations @@ -107,13 +107,13 @@ This section describes how an attacker might exploit a feature or its configurat ### Vulnerability -UIA programs are designed to interact with Windows and application programs on behalf of a user. This setting allows UIA programs to bypass the secure desktop to increase usability in certain cases, but it allows elevation requests to appear on the regular interactive desktop instead of on the secure desktop. This increases the risk that a malicious program could intercept data that is being transferred between the UI and the application. Because UIA programs must be able to respond to prompts regarding security issues, such as the UAC elevation prompt, UIA programs must be highly trusted. To be considered trusted, a UIA program must be digitally signed. By default, UIA programs can be run only from the following protected paths: +UIA programs are designed to interact with Windows and application programs on behalf of a user. This setting allows UIA programs to bypass the secure desktop to increase usability in certain cases, but it allows elevation requests to appear on the regular interactive desktop instead of on the secure desktop. This requests-appearance increases the risk that a malicious program could intercept data that is being transferred between the UI and the application. Because UIA programs must be able to respond to prompts regarding security issues, such as the UAC elevation prompt, UIA programs must be highly trusted. To be considered trusted, a UIA program must be digitally signed. By default, UIA programs can be run only from the following protected paths: - ..\\Program Files\\ (and subfolders) - ..\\Program Files (x86)\\ (and subfolders, in 64-bit versions of Windows only) - ..\\Windows\\System32\\ -The requirement to be in a protected path can be disabled by the [User Account Control: Only elevate UIAccess applications that are installed in secure locations](user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md) setting. Although this setting applies to any UIA program, it is used primarily in certain Windows Remote Assistance scenarios. +The requirement to be in a protected path can be disabled by the [User Account Control: Only elevate UIAccess applications that are installed in secure locations](user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md) setting. Although this setting applies to any UIA program, it's used primarily in certain Windows Remote Assistance scenarios. ### Countermeasure From 639ed4ca6e577247ce458917360ce18dca836095 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Thu, 30 Jun 2022 17:57:54 +0530 Subject: [PATCH 009/109] Acrolinx Enhancement Effort --- ...r-administrators-in-admin-approval-mode.md | 16 +-- ...the-elevation-prompt-for-standard-users.md | 12 +- ...-installations-and-prompt-for-elevation.md | 4 +- ...ecutables-that-are-signed-and-validated.md | 12 +- ...-that-are-installed-in-secure-locations.md | 6 +- ...l-administrators-in-admin-approval-mode.md | 2 +- ...re-desktop-when-prompting-for-elevation.md | 6 +- ...ry-write-failures-to-per-user-locations.md | 8 +- ...arding-to-assist-in-intrusion-detection.md | 112 +++++++++--------- .../LOB-win32-apps-on-s.md | 16 +-- ...ows-defender-application-control-policy.md | 10 +- ...ged-apps-to-existing-applocker-rule-set.md | 2 +- .../applocker-architecture-and-components.md | 2 +- .../applocker/applocker-overview.md | 18 +-- .../applocker-policies-deployment-guide.md | 2 +- .../applocker-policies-design-guide.md | 8 +- .../applocker-policy-use-scenarios.md | 13 +- .../applocker-processes-and-interactions.md | 8 +- ...e-an-applocker-policy-for-enforce-rules.md | 2 +- ...onfigure-the-appLocker-reference-device.md | 8 +- 20 files changed, 133 insertions(+), 134 deletions(-) diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode.md b/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode.md index e653550846..06252b3d4a 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode.md @@ -33,9 +33,9 @@ This policy setting determines the behavior of the elevation prompt for accounts - **Elevate without prompting** - Assumes that the administrator will permit an operation that requires elevation, and additional consent or credentials are not required. + Assumes that the administrator will permit an operation that requires elevation, and more consent or credentials aren't required. - **Note**  Selecting **Elevate without prompting** minimizes the protection that is provided by UAC. We do not recommend selecting this value unless administrator accounts are tightly controlled and the operating environment is highly secure. + **Note**  Selecting **Elevate without prompting** minimizes the protection that is provided by UAC. We don't recommend selecting this value unless administrator accounts are tightly controlled and the operating environment is highly secure. - **Prompt for credentials on the secure desktop** @@ -55,18 +55,18 @@ This policy setting determines the behavior of the elevation prompt for accounts - **Prompt for consent for non-Windows binaries** - This is the default. When an operation for a non-Microsoft application requires elevation of privilege, the user is prompted on the secure desktop to select **Permit** or **Deny**. If the user selects **Permit**, the operation continues with the user's highest available privilege. + This prompt for consent is the default. When an operation for a non-Microsoft application requires elevation of privilege, the user is prompted on the secure desktop to select **Permit** or **Deny**. If the user selects **Permit**, the operation continues with the user's highest available privilege. -\*If you have enabled the built-in Administrator account and have configured Admin Approval Mode, you must also configure the option **Prompt for consent on the secure desktop**. You can also configure this option from User Account Control, by typing **UAC** in the search box. From the User Account Control Settings dialog box, set the slider control to **Notify me only when apps try to make changes to my computer (default)**. +\*If you've enabled the built-in Administrator account and have configured Admin Approval Mode, you must also configure the option **Prompt for consent on the secure desktop**. You can also configure this option from User Account Control, by typing **UAC** in the search box. From the User Account Control Settings dialog box, set the slider control to **Notify me only when apps try to make changes to my computer (default)**. > [!NOTE] > After enabling Admin Approval Mode, to activate the setting, you must first log in and out. Alternatively, You may perform **gpupdate /force** from an elevated command prompt. ### Best practices -- Selecting the option **Elevate without prompting** minimizes the protection that is provided by UAC. We do not recommend selecting this value unless administrator accounts are tightly controlled and the operating environment is highly secure. +- Selecting the option **Elevate without prompting** minimizes the protection that is provided by UAC. We don't recommend selecting this value unless administrator accounts are tightly controlled and the operating environment is highly secure. -- It is recommended not to enable the built-in Administrator account on the client computer, but to use the standard user account and User Account Control (UAC) instead. If you want to enable the built-in Administrator account to carry out administrative tasks, for security reasons you should also enable Admin Approval Mode. For further information, see [UAC-Admin-Approval-Mode-for-the-Built-in-Administrator-account](/windows/device-security/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account) +- It's recommended not to enable the built-in Administrator account on the client computer, but to use the standard user account and User Account Control (UAC) instead. If you want to enable the built-in Administrator account to carry out administrative tasks, for security reasons you should also enable Admin Approval Mode. For more information, see [UAC-Admin-Approval-Mode-for-the-Built-in-Administrator-account](/windows/device-security/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account) ### Location @@ -90,7 +90,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -110,7 +110,7 @@ Configure the **User Account Control: Behavior of the elevation prompt for admin ### Potential impact -Administrators should be made aware that they will be prompted for consent when all binaries attempt to run. +Administrators should be made aware that they'll be prompted for consent when all binaries attempt to run. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md b/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md index 48f2dfa8c7..dcc2829197 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md @@ -37,7 +37,7 @@ This policy setting determines the behavior of the elevation prompt for standard - **Prompt for credentials on the secure desktop** - This is the default. When an operation requires elevation of privilege, the user is prompted on the secure desktop to enter a different user name and password. If the user enters valid credentials, the operation continues with the applicable privilege. + This prompt for credentials is the default. When an operation requires elevation of privilege, the user is prompted on the secure desktop to enter a different user name and password. If the user enters valid credentials, the operation continues with the applicable privilege. - **Prompt for credentials** @@ -45,8 +45,8 @@ This policy setting determines the behavior of the elevation prompt for standard ### Best practices -1. Configure the **User Account Control: Behavior of the elevation prompt for standard users** to **Automatically deny elevation requests**. This setting requires the user to log on with an administrative account to run programs that require elevation of privilege. -2. As a security best practice, standard users should not have knowledge of administrative passwords. However, if your users have both standard and administrator-level accounts, set **Prompt for credentials on the secure desktop** so that the users do not choose to always log on with their administrator accounts, and they shift their behavior to use the standard user account. +1. Configure the **User Account Control: Behavior of the elevation prompt for standard users** to **Automatically deny elevation requests**. This setting requires the user to sign in with an administrative account to run programs that require elevation of privilege. +2. As a security best practice, standard users shouldn't have knowledge of administrative passwords. However, if your users have both standard and administrator-level accounts, set **Prompt for credentials on the secure desktop** so that the users don't choose to always sign in with their administrator accounts, and they shift their behavior to use the standard user account. ### Location @@ -71,7 +71,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -87,11 +87,11 @@ One of the risks that the UAC feature tries to mitigate is that of malicious pro ### Countermeasure -Configure the **User Account Control: Behavior of the elevation prompt for standard users** to **Automatically deny elevation requests**. This setting requires the user to log on with an administrative account to run programs that require elevation of privilege. As a security best practice, standard users should not have knowledge of administrative passwords. However, if your users have both standard and administrator-level accounts, we recommend setting **Prompt for credentials** so that the users do not choose to always log on with their administrator accounts, and they shift their behavior to use the standard user account. +Configure the **User Account Control: Behavior of the elevation prompt for standard users** to **Automatically deny elevation requests**. This setting requires the user to sign in with an administrative account to run programs that require elevation of privilege. As a security best practice, standard users shouldn't have knowledge of administrative passwords. However, if your users have both standard and administrator-level accounts, we recommend setting **Prompt for credentials** so that the users don't choose to always sign in with their administrator accounts, and they shift their behavior to use the standard user account. ### Potential impact -Users must provide administrative passwords to run programs with elevated privileges. This could cause an increased load on IT staff while the programs that are affected are identified and standard operating procedures are modified to support least privilege operations. +Users must provide administrative passwords to run programs with elevated privileges. This impact could cause an increased load on IT staff while the programs that are affected are identified and standard operating procedures are modified to support least privilege operations. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-detect-application-installations-and-prompt-for-elevation.md b/windows/security/threat-protection/security-policy-settings/user-account-control-detect-application-installations-and-prompt-for-elevation.md index 431ac04a15..53b87039e9 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-detect-application-installations-and-prompt-for-elevation.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-detect-application-installations-and-prompt-for-elevation.md @@ -38,7 +38,7 @@ Some software might attempt to install itself after being given permission to ru - **Disabled** - Application installation packages that require an elevation of privilege to install are not detected and the user is not prompted for administrative credentials. + Application installation packages that require an elevation of privilege to install aren't detected and the user isn't prompted for administrative credentials. ### Best practices @@ -68,7 +68,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ## Security considerations diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-executables-that-are-signed-and-validated.md b/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-executables-that-are-signed-and-validated.md index 242580312c..0f83be229f 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-executables-that-are-signed-and-validated.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-executables-that-are-signed-and-validated.md @@ -31,18 +31,18 @@ This policy setting enforces public key infrastructure (PKI) signature checks on A trusted publisher is a certificate issuer that the computer’s user has chosen to trust and that has certificate details that have been added to the store of trusted publishers. -Windows maintains certificates in certificate stores. These stores can be represented by containers in the file system or the registry, or they can be implemented as physical stores such as smart cards. Certificate stores are associated with the computer object or they are owned by a distinct user who has a security context and profile on that computer. In addition, services can have certificate stores. A certificate store will often contain numerous certificates, possibly issued from a number of different certification authorities (CAs). +Windows maintains certificates in certificate stores. These stores can be represented by containers in the file system or the registry, or they can be implemented as physical stores such as smart cards. Certificate stores are associated with the computer object or they're owned by a distinct user who has a security context and profile on that computer. In addition, services can have certificate stores. A certificate store will often contain numerous certificates, possibly issued from many different certification authorities (CAs). When certificate path discovery is initiated, Windows attempts to locate the issuing CA for the certificates, and it builds a certificate path to the trusted root certificate. Intermediate certificates are included as part of the application protocol or are picked up from Group Policy or through URLs that are specified in the Authority Information Access (AIA) extension. When the path is built, each certificate in the path is verified for validity with respect to various parameters, such as name, time, signature, revocation status, and other constraints. ### Possible values - **Enabled** - Enforces the PKI certificate chain validation of a given executable file before it is permitted to run. + Enforces the PKI certificate chain validation of a given executable file before it's permitted to run. - **Disabled** - Does not enforce PKI certificate chain validation before a given executable file is permitted to run. + Doesn't enforce PKI certificate chain validation before a given executable file is permitted to run. ### Best practices @@ -71,7 +71,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a computer restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a computer restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -91,8 +91,8 @@ Enable the **User Account Control: Only elevate executables that are signed and ### Potential impact -Enabling this setting requires that you have a PKI infrastructure and that your enterprise administrators have populated the Trusted Publishers store with the certificates for the allowed applications. Some older applications are not signed, and they cannot be used in an environment that is hardened with this setting. You should carefully test your applications in a preproduction environment before implementing this setting. -Control over the applications that are installed on the desktops and the hardware that joins your domain should provide similar protection from the vulnerability that is addressed by this setting. Additionally, the level of protection that is provided by this setting is not an assurance that all rogue applications will be found. +Enabling this setting requires that you have a PKI infrastructure and that your enterprise administrators have populated the Trusted Publishers store with the certificates for the allowed applications. Some older applications aren't signed, and they can't be used in an environment that is hardened with this setting. You should carefully test your applications in a preproduction environment before implementing this setting. +Control over the applications that are installed on the desktops and the hardware that joins your domain should provide similar protection from the vulnerability that is addressed by this setting. Additionally, the level of protection that is provided by this setting isn't an assurance that all rogue applications will be found. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md b/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md index 76a8bc97a2..2c36882505 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md @@ -59,7 +59,7 @@ If an application presents a UIAccess attribute when it requests privileges, the - **Disabled** - An application can start with UIAccess integrity even if it does not reside in a secure location in the file system. + An application can start with UIAccess integrity even if it doesn't reside in a secure location in the file system. ### Best practices @@ -103,7 +103,7 @@ This section describes: ### Vulnerability -UIAccess integrity allows an application to bypass User Interface Privilege Isolation (UIPI) restrictions when an application is elevated in privilege from a standard user to an administrator. When this setting is enabled, an application that has the UIAccess flag set to true in its manifest can interchange information with applications that are running at a higher privilege level, such as logon prompts and privilege elevation prompts. This ability is required to support accessibility features such as screen readers that transmit user interfaces to alternative forms. But it's not required by most applications. A process that's started with UIAccess rights has the following abilities: +UIAccess integrity allows an application to bypass User Interface Privilege Isolation (UIPI) restrictions when an application is elevated in privilege from a standard user to an administrator. When this setting is enabled, an application that has the UIAccess flag set to true in its manifest can interchange information with applications that are running at a higher privilege level, such as sign-in prompts and privilege elevation prompts. This ability is required to support accessibility features such as screen readers that transmit user interfaces to alternative forms. But it's not required by most applications. A process that's started with UIAccess rights has the following abilities: - Set the foreground window. - Drive any application window by using the SendInput function. @@ -117,7 +117,7 @@ Enable the **User Account Control: Only elevate UIAccess applications that are i ### Potential impact -If the application that requests UIAccess meets the UIAccess setting requirements, computers that run at least the Windows Vista operating system start the application with the ability to bypass most UIPI restrictions. If the application does not meet the security restrictions, the application is started without UIAccess rights, and it can interact only with applications at the same or lower privilege level. +If the application that requests UIAccess meets the UIAccess setting requirements, computers that run at least the Windows Vista operating system start the application with the ability to bypass most UIPI restrictions. If the application doesn't meet the security restrictions, the application is started without UIAccess rights, and it can interact only with applications at the same or lower privilege level. ## Related articles diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode.md b/windows/security/threat-protection/security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode.md index 6760e38f5a..3d53a0a2f4 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode.md @@ -27,7 +27,7 @@ This article describes the best practices, location, values, policy management a ## Reference -This policy setting determines the behavior of all User Account Control (UAC) policies for the entire system. This is the setting that turns UAC on or off. +This policy setting determines the behavior of all User Account Control (UAC) policies for the entire system. This setting is the one that turns on or off the UAC. ### Possible values diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md b/windows/security/threat-protection/security-policy-settings/user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md index 5eb4fbd4e9..15ef6860e1 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management and security c This policy setting determines whether the elevation request prompts on the interactive user desktop or on the secure desktop. -The secure desktop presents the logon UI and restricts functionality and access to the system until the logon requirements are satisfied. +The secure desktop presents the sign-in UI and restricts functionality and access to the system until the sign-in requirements are satisfied. The secure desktop’s primary difference from the user desktop is that only trusted processes running as SYSTEM are allowed to run here (that is, nothing is running at the user’s privilege level). The path to get to the secure desktop from the user desktop must also be trusted through the entire chain. @@ -71,7 +71,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -91,7 +91,7 @@ Enable the **User Account Control: Switch to the secure desktop when prompting f ### Potential impact -None. This is the default configuration. +None. This non-impact state is the default configuration. ## Related topics diff --git a/windows/security/threat-protection/security-policy-settings/user-account-control-virtualize-file-and-registry-write-failures-to-per-user-locations.md b/windows/security/threat-protection/security-policy-settings/user-account-control-virtualize-file-and-registry-write-failures-to-per-user-locations.md index dda6b18a18..97de8498ea 100644 --- a/windows/security/threat-protection/security-policy-settings/user-account-control-virtualize-file-and-registry-write-failures-to-per-user-locations.md +++ b/windows/security/threat-protection/security-policy-settings/user-account-control-virtualize-file-and-registry-write-failures-to-per-user-locations.md @@ -29,7 +29,7 @@ Describes the best practices, location, values, policy management and security c This policy setting enables or disables the redirection of the write failures of earlier applications to defined locations in the registry and the file system. This feature mitigates applications that historically ran as administrator and wrote runtime application data to %ProgramFiles%, %Windir%, %Windir%\\system32, or HKEY\_LOCAL\_MACHINE\\Software\\. -This feature can be disabled for applications on devices running at least Windows Vista because it is unnecessary. +This feature can be disabled for applications on devices running at least Windows Vista because it's unnecessary. ### Possible values @@ -43,7 +43,7 @@ This feature can be disabled for applications on devices running at least Window ### Best practices -1. If you run applications that are not Windows Vista-compliant, enable this security policy to prevent the possibility that these older applications could write data to unsecure locations. +1. If you run applications that aren't Windows Vista-compliant, enable this security policy to prevent the possibility that these older applications could write data to unsecure locations. 2. If you only run at least Windows Vista–compliant applications, this feature is unnecessary so you can disable this policy. ### Location @@ -69,7 +69,7 @@ This section describes features and tools that are available to help you manage ### Restart requirement -None. Changes to this policy become effective without a device restart when they are saved locally or distributed through Group Policy. +None. Changes to this policy become effective without a device restart when they're saved locally or distributed through Group Policy. ### Group Policy @@ -89,7 +89,7 @@ Enable the **User Account Control: Virtualize file and registry write failures t ### Potential impact -None. This is the default configuration. +None. This non-impact state is the default configuration. ## Related topics diff --git a/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md b/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md index 411b14fcba..8eabd03b34 100644 --- a/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md +++ b/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md @@ -23,7 +23,7 @@ Windows Event Forwarding (WEF) reads any operational or administrative event log To accomplish this functionality, there are two different subscriptions published to client devices - the Baseline subscription and the suspect subscription. The Baseline subscription enrolls all devices in your organization, and a Suspect subscription only includes devices that have been added by you. The Suspect subscription collects more events to help build context for system activity and can quickly be updated to accommodate new events and/or scenarios as needed without impacting baseline operations. -This implementation helps differentiate where events are ultimately stored. Baseline events can be sent to devices with online analytical capability, such as Security Event Manager (SEM), while also sending events to a MapReduce system, such as HDInsight or Hadoop, for long-term storage and deeper analysis. Events from the Suspect subscription are sent directly to a MapReduce system due to volume and lower signal/noise ratio, they are largely used for host forensic analysis. +This implementation helps differentiate where events are ultimately stored. Baseline events can be sent to devices with online analytical capability, such as Security Event Manager (SEM), while also sending events to a MapReduce system, such as HDInsight or Hadoop, for long-term storage and deeper analysis. Events from the Suspect subscription are sent directly to a MapReduce system due to volume and lower signal/noise ratio, they're largely used for host forensic analysis. An SEM’s strength lies in being able to inspect, correlate events, and generate alerts for known patterns manner and alert security staff at machine speed. @@ -37,7 +37,7 @@ Here's an approximate scaling guide for WEF events: | 5,000 - 50,000 | SEM | | 50,000+ | Hadoop/HDInsight/Data Lake | -Event generation on a device must be enabled either separately or as part of the GPO for the baseline WEF implementation, including enabling of disabled event logs and setting channel permissions. For more info, see [Appendix C - Event channel settings (enable and channel access) methods](#bkmk-appendixc). This condition is because WEF is a passive system regarding the event log. It cannot change the size of event log files, enable disabled event channels, change channel permissions, or adjust a security audit policy. WEF only queries event channels for existing events. Additionally, having event generation already occurring on a device allows for more complete event collection building a complete history of system activity. Otherwise, you'll be limited to the speed of GPO and WEF subscription refresh cycles to make changes to what is being generated on the device. On modern devices, enabling additional event channels and expanding the size of event log files hasn't resulted in noticeable performance differences. +Event generation on a device must be enabled either separately or as part of the GPO for the baseline WEF implementation, including enabling of disabled event logs and setting channel permissions. For more info, see [Appendix C - Event channel settings (enable and channel access) methods](#bkmk-appendixc). This condition is because WEF is a passive system regarding the event log. It can't change the size of event log files, enable disabled event channels, change channel permissions, or adjust a security audit policy. WEF only queries event channels for existing events. Additionally, having event generation already occurring on a device allows for more complete event collection building a complete history of system activity. Otherwise, you'll be limited to the speed of GPO and WEF subscription refresh cycles to make changes to what is being generated on the device. On modern devices, enabling more event channels and expanding the size of event log files hasn't resulted in noticeable performance differences. For the minimum recommended audit policy and registry system ACL settings, see [Appendix A - Minimum recommended minimum audit policy](#bkmk-appendixa) and [Appendix B - Recommended minimum registry system ACL policy](#bkmk-appendixb). @@ -50,7 +50,7 @@ This system of dual subscription means you would create two base subscriptions: - **Baseline WEF subscription**. Events collected from all hosts; these events include some role-specific events, which will only be emitted by those machines. - **Targeted WEF subscription**. Events collected from a limited set of hosts due to unusual activity and/or heightened awareness for those systems. -Each using the respective event query below. For the Targeted subscription enabling the “read existing events” option should be set to true to allow collection of existing events from systems. By default, WEF subscriptions will only forward events generated after the WEF subscription was received by the client. +Each using the respective event query below. For the Targeted subscription, enabling the “read existing events” option should be set to true to allow collection of existing events from systems. By default, WEF subscriptions will only forward events generated after the WEF subscription was received by the client. In [Appendix E – Annotated Baseline Subscription Event Query](#bkmk-appendixe) and [Appendix F – Annotated Suspect Subscription Event Query](#bkmk-appendixf), the event query XML is included when creating WEF subscriptions. These subscriptions are annotated for query purpose and clarity. Individual <Query> element can be removed or edited without affecting the rest of the query. @@ -62,11 +62,11 @@ This section addresses common questions from IT pros and customers. The short answer is: No. -The longer answer is: The **Eventlog-forwardingPlugin/Operational** event channel logs the success, warning, and error events related to WEF subscriptions present on the device. Unless the user opens Event Viewer and navigates to that channel, they won't notice WEF either through resource consumption or Graphical User Interface pop-ups. Even if there is an issue with the WEF subscription, there is no user interaction or performance degradation. All success, warning, and failure events are logged to this operational event channel. +The longer answer is: The **Eventlog-forwardingPlugin/Operational** event channel logs the success, warning, and error events related to WEF subscriptions present on the device. Unless the user opens Event Viewer and navigates to that channel, they won't notice WEF either through resource consumption or Graphical User Interface pop-ups. Even if there's an issue with the WEF subscription, there's no user interaction or performance degradation. All success, warning, and failure events are logged to this operational event channel. ### Is WEF Push or Pull? -A WEF subscription can be configured to be push or pull, but not both. The simplest, most flexible IT deployment with the greatest scalability can be achieved by using a push, or source initiated, subscription. WEF clients are configured by using a GPO and the built-in forwarding client is activated. For pull, collector initiated, the subscription on the WEC server is pre-configured with the names of the WEF Client devices from which events are to be selected. Those clients are to be configured ahead of time to allow the credentials used in the subscription to access their event logs remotely (normally by adding the credential to the **Event Log Readers** built-in local security group.) A useful scenario: closely monitoring a specific set of machines. +A WEF subscription can be configured to be pushed or pulled, but not both. The simplest, most flexible IT deployment with the greatest scalability can be achieved by using a push, or source initiated, subscription. WEF clients are configured by using a GPO and the built-in forwarding client is activated. For pull, collector initiated, the subscription on the WEC server is pre-configured with the names of the WEF Client devices from which events are to be selected. Those clients are to be configured ahead of time to allow the credentials used in the subscription to access their event logs remotely (normally by adding the credential to the **Event Log Readers** built-in local security group.) A useful scenario: closely monitoring a specific set of machines. ### Will WEF work over VPN or RAS? @@ -75,7 +75,7 @@ WEF handles VPN, RAS, and DirectAccess scenarios well and will reconnect and sen ### How is client progress tracked? The WEC server maintains in its registry the bookmark information and last heartbeat time for each event source for each WEF subscription. When an event source reconnects to a WEC server, the last bookmark position is sent to the device to use as a starting point to resume forwarding events. If a -WEF client has no events to send, the WEF client will connect periodically to send a Heartbeat to the WEC server to indicate it is active. This heartbeat value can be individually configured for each subscription. +WEF client has no events to send, the WEF client will connect periodically to send a Heartbeat to the WEC server to indicate it's active. This heartbeat value can be individually configured for each subscription. ### Will WEF work in an IPv4, IPv6, or mixed IPv4/IPv6 environment? @@ -93,12 +93,11 @@ The HTTPS option is available if certificate based authentication is used, in ca The WEF client machines local event log is the buffer for WEF for when the connection to the WEC server is lost. To increase the “buffer size”, increase the maximum file size of the specific event log file where events are being selected. For more info, see [Appendix C – Event Channel Settings (enable and Channel Access) methods](#bkmk-appendixc). -When the event log overwrites existing events (resulting in data loss if the device isn't connected to the Event Collector), there is no notification sent to the WEF collector that events are lost from the client. Neither is there an indicator that there was a gap encountered in the event stream. +When the event log overwrites existing events (resulting in data loss if the device isn't connected to the Event Collector), there's no notification sent to the WEF collector that events are lost from the client. Neither is there an indicator that there was a gap encountered in the event stream. ### What format is used for forwarded events? -WEF has two modes for forwarded events. The default is “Rendered Text” which includes the textual description of the event as you would see it in Event Viewer. This means that the event size is effectively doubled or tripled depending on the size of the rendered description. The alternative mode is -“Events” (also sometimes referred to as “Binary” format) – which is just the event XML itself sent in binary XML format (as it would be written to the evtx file.) This is very compact and can more than double the event volume a single WEC server can accommodate. +WEF has two modes for forwarded events. The default is “Rendered Text” that includes the textual description of the event as you would see it in Event Viewer. This description's inclusion means that the event size is effectively doubled or tripled depending on the size of the rendered description. The alternative mode is “Events” (also sometimes referred to as “Binary” format) – which is just the event XML itself sent in binary XML format (as it would be written to the evtx file.) This format is compact and can more than double the event volume a single WEC server can accommodate. A subscription “testSubscription” can be configured to use the Events format through the WECUTIL utility: @@ -109,19 +108,19 @@ Wecutil ss “testSubscription” /cf:Events ### How frequently are WEF events delivered? -Event delivery options are part of the WEF subscription configuration parameters – There are three built-in subscription delivery options: Normal, Minimize Bandwidth, and Minimize Latency. A fourth, catch-all called “Custom” is available but cannot be selected or configured through the WEF UI by using Event Viewer. The Custom delivery option must be selected and configured using the WECUTIL.EXE command-line application. All subscription options define a maximum event count and maximum event age, if either limit is exceeded then the accumulated events are sent to the event collector. +Event delivery options are part of the WEF subscription configuration parameters – There are three built-in subscription delivery options: Normal, Minimize Bandwidth, and Minimize Latency. A fourth, catch-all called “Custom” is available but can't be selected or configured through the WEF UI by using Event Viewer. The Custom delivery option must be selected and configured using the WECUTIL.EXE command-line application. All subscription options define a maximum event count and maximum event age, if either limit is exceeded then the accumulated events are sent to the event collector. This table outlines the built-in delivery options: | Event delivery optimization options | Description | | - | - | -| Normal | This option ensures reliable delivery of events and doesn't attempt to conserve bandwidth. It is the appropriate choice unless you need tighter control over bandwidth usage or need forwarded events delivered as quickly as possible. It uses pull delivery mode, batches 5 items at a time and sets a batch timeout of 15 minutes. | -| Minimize bandwidth | This option ensures that the use of network bandwidth for event delivery is strictly controlled. It is an appropriate choice if you want to limit the frequency of network connections made to deliver events. It uses push delivery mode and sets a batch timeout of 6 hours. In addition, it uses a heartbeat interval of 6 hours. | -| Minimize latency | This option ensures that events are delivered with minimal delay. It is an appropriate choice if you are collecting alerts or critical events. It uses push delivery mode and sets a batch timeout of 30 seconds. | +| Normal | This option ensures reliable delivery of events and doesn't attempt to conserve bandwidth. It's the appropriate choice unless you need tighter control over bandwidth usage or need forwarded events delivered as quickly as possible. It uses pull delivery mode, batches 5 items at a time and sets a batch timeout of 15 minutes. | +| Minimize bandwidth | This option ensures that the use of network bandwidth for event delivery is strictly controlled. It's an appropriate choice if you want to limit the frequency of network connections made to deliver events. It uses push delivery mode and sets a batch timeout of 6 hours. In addition, it uses a heartbeat interval of 6 hours. | +| Minimize latency | This option ensures that events are delivered with minimal delay. It's an appropriate choice if you're collecting alerts or critical events. It uses push delivery mode and sets a batch timeout of 30 seconds. | For more info about delivery options, see [Configure Advanced Subscription Settings](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc749167(v=ws.11)). -The primary difference is in the latency which events are sent from the client. If none of the built-in options meet your requirements you can set Custom event delivery options for a given subscription from an elevated command prompt: +The primary difference is in the latency which events are sent from the client. If none of the built-in options meet your requirements, you can set Custom event delivery options for a given subscription from an elevated command prompt: ``` syntax @rem required to set the DeliveryMaxItems or DeliveryMaxLatencyTime @@ -139,15 +138,15 @@ For collector initiated subscriptions: The subscription contains the list of mac ### Can a client communicate to multiple WEF Event Collectors? -Yes. If you desire a High-Availability environment, simply configure multiple WEC servers with the same subscription configuration and publish both WEC Server URIs to WEF clients. WEF Clients will forward events simultaneously to the configured subscriptions on the WEC servers, if they have the appropriate access. +Yes. If you desire a High-Availability environment, configure multiple WEC servers with the same subscription configuration and publish both WEC Server URIs to WEF clients. WEF Clients will forward events simultaneously to the configured subscriptions on the WEC servers, if they have the appropriate access. ### What are the WEC server’s limitations? There are three factors that limit the scalability of WEC servers. The general rule for a stable WEC server on commodity hardware is planning for a total of 3,000 events per second on average for all configured subscriptions. - **Disk I/O**. The WEC server doesn't process or validate the received event, but rather buffers the received event and then logs it to a local event log file (EVTX file). The speed of logging to the EVTX file is limited by the disk write speed. Isolating the EVTX file to its own array or using high speed disks can increase the number of events per second that a single WEC server can receive. -- **Network Connections**. While a WEF source doesn't maintain a permanent, persistent connection to the WEC server, it doesn't immediately disconnect after sending its events. This means that the number of WEF sources that can simultaneously connect to the WEC server is limited to the open TCP ports available on the WEC server. -- **Registry size**. For each unique device that connects to a WEF subscription, there is a registry key (corresponding to the FQDN of the WEF Client) created to store bookmark and source heartbeat information. If this isn't pruned to remove inactive clients this set of registry keys can grow to an unmanageable size over time. +- **Network Connections**. While a WEF source doesn't maintain a permanent, persistent connection to the WEC server, it doesn't immediately disconnect after sending its events. This leniency means that the number of WEF sources that can simultaneously connect to the WEC server is limited to the open TCP ports available on the WEC server. +- **Registry size**. For each unique device that connects to a WEF subscription, there's a registry key (corresponding to the FQDN of the WEF Client) created to store bookmark and source heartbeat information. If this information isn't pruned to remove inactive clients, this set of registry keys can grow to an unmanageable size over time. - When a subscription has >1000 WEF sources connect to it over its operational lifetime, also known as lifetime WEF sources, Event Viewer can become unresponsive for a few minutes when selecting the **Subscriptions** node in the left-navigation, but will function normally afterwards. - At >50,000 lifetime WEF sources, Event Viewer is no longer an option and wecutil.exe (included with Windows) must be used to configure and manage subscriptions. @@ -155,30 +154,30 @@ There are three factors that limit the scalability of WEC servers. The general r ## Subscription information -Below lists all of the items that each subscription collects, the actual subscription XML is available in an Appendix. These are separated out into Baseline and Targeted. The intent is to subscribe all hosts to Baseline, and then enroll (and remove) hosts on an as needed basis to the Targeted subscription. +Below lists all of the items that each subscription collects, the actual subscription XML is available in an Appendix. These items are separated out into Baseline and Targeted. The intent is to subscribe all hosts to Baseline, and then enroll (and remove) hosts on an as needed basis to the Targeted subscription. ### Baseline subscription -While this appears to be the largest subscription, it really is the lowest volume on a per-device basis. (Exceptions should be allowed for unusual devices – a device performing complex developer related tasks can be expected to create an unusually high volume of process create and AppLocker events.) This subscription doesn't require special configuration on client devices to enable event channels or modify channel permissions. +While this subscription appears to be the largest subscription, it really is the lowest volume on a per-device basis. (Exceptions should be allowed for unusual devices – a device performing complex developer related tasks can be expected to create an unusually high volume of process create and AppLocker events.) This subscription doesn't require special configuration on client devices to enable event channels or modify channel permissions. -The subscription is essentially a collection of query statements applied to the Event Log. This means that it is modular in nature and a given query statement can be removed or changed without impacting other query statement in the subscription. Additionally, suppress statements which filter out specific events, only apply within that query statement and aren't to the entire subscription. +The subscription is essentially a collection of query statements applied to the Event Log. This subscription means that it's modular in nature and a given query statement can be removed or changed without impacting other query statement in the subscription. Additionally, suppress statements that filter out specific events, only apply within that query statement and aren't to the entire subscription. ### Baseline subscription requirements -To gain the most value out of the baseline subscription we recommend to have the following requirements set on the device to ensure that the clients are already generating the required events to be forwarded off the system. +To gain the most value out of the baseline subscription, we recommend having the following requirements set on the device to ensure that the clients are already generating the required events to be forwarded off the system. -- Apply a security audit policy that is a super-set of the recommended minimum audit policy. For more info, see [Appendix A – Minimum Recommended minimum Audit Policy](#bkmk-appendixa). This ensures that the security event log is generating the required events. +- Apply a security audit policy that is a super-set of the recommended minimum audit policy. For more info, see [Appendix A – Minimum Recommended minimum Audit Policy](#bkmk-appendixa). This policy ensures that the security event log is generating the required events. - Apply at least an Audit-Only AppLocker policy to devices. - - If you are already allowing or restricting events by using AppLocker, then this requirement is met. - - AppLocker events contain extremely useful information, such as file hash and digital signature information for executables and scripts. + - If you're already allowing or restricting events by using AppLocker, then this requirement is met. + - AppLocker events contain useful information, such as file hash and digital signature information for executables and scripts. - Enable disabled event channels and set the minimum size for modern event files. -- Currently, there is no GPO template for enabling or setting the maximum size for the modern event files. This must be done by using a GPO. For more info, see [Appendix C – Event Channel Settings (enable and Channel Access) methods](#bkmk-appendixc). +- Currently, there's no GPO template for enabling or setting the maximum size for the modern event files. This threshold must be defined by using a GPO. For more info, see [Appendix C – Event Channel Settings (enable and Channel Access) methods](#bkmk-appendixc). The annotated event query can be found in the following. For more info, see [Appendix F – Annotated Suspect Subscription Event Query](#bkmk-appendixf). -- Anti-malware events from Microsoft Antimalware or Windows Defender. This can be configured for any given anti-malware product easily if it writes to the Windows event log. +- Anti-malware events from Microsoft Antimalware or Windows Defender. These events can be configured for any given anti-malware product easily if it writes to the Windows event log. - Security event log Process Create events. - AppLocker Process Create events (EXE, script, packaged App installation and execution). - Registry modification events. For more info, see [Appendix B – Recommended minimum Registry System ACL Policy](#bkmk-appendixb). @@ -192,7 +191,7 @@ The annotated event query can be found in the following. For more info, see [App - Certificate Authority audit events - - This is only applicable on systems with the Certificate Authority role installed. + - These events are only applicable on systems with the Certificate Authority role installed. - Logs certificate requests and responses. - User profile events @@ -211,28 +210,29 @@ The annotated event query can be found in the following. For more info, see [App - Find out what initiated the restart of a device. -- User initiated interactive logoff event +- User-initiated interactive sign-out event - Remote Desktop Services sessions connect, reconnect, or disconnect. - EMET events, if EMET is installed. - Event forwarding plugin events - - For monitoring WEF subscription operations, particularly Partial Success events. This is useful for diagnosing deployment issues. + - For monitoring WEF subscription operations, such as Partial Success events. This event is useful for diagnosing deployment issues. - Network share creation and deletion - Enables detection of unauthorized share creation. - >**Note:** All shares are re-created when the device starts. + > [!NOTE] + > All shares are re-created when the device starts. -- Logon sessions +- Sign-in sessions - - Logon success for interactive (local and Remote Interactive/Remote Desktop) - - Logon success for services for non-built-in accounts, such as LocalSystem, LocalNetwork, and so on. - - Logon success for batch sessions - - Logon session close, which is logoff events for non-network sessions. + - Sign-in success for interactive (local and Remote Interactive/Remote Desktop) + - Sign-in success for services for non-built-in accounts, such as LocalSystem, LocalNetwork, and so on. + - Sign-in success for batch sessions + - Sign-in session close, which is sign-out events for non-network sessions. - Windows Error Reporting (Application crash events only) - - This can help detect early signs of intruder not familiar with enterprise environment using targeted malware. + - This session can help detect early signs of intruder not familiar with enterprise environment using targeted malware. - Event log service events @@ -240,11 +240,11 @@ The annotated event query can be found in the following. For more info, see [App - Event log cleared (including the Security Event Log) - - This could indicate an intruder that is covering their tracks. + - This event could indicate an intruder that is covering their tracks. -- Special privileges assigned to new logon +- Special privileges assigned to new sign in - - This indicates that at the time of logon a user is either an Administrator or has the sufficient access to make themselves Administrator. + - This assignation indicates that at the time of signing in, a user is either an Administrator or has the sufficient access to make themselves Administrator. - Outbound Remote Desktop Services session attempts @@ -265,19 +265,19 @@ The annotated event query can be found in the following. For more info, see [App - Task Scheduler allows intruders to run code at specified times as LocalSystem. -- Logon with explicit credentials +- Sign-in with explicit credentials - Detect credential use changes by intruders to access more resources. - Smartcard card holder verification events - - This detects when a smartcard is being used. + - This event detects when a smartcard is being used. ### Suspect subscription -This adds some possible intruder-related activity to help analyst further refine their determinations about the state of the device. +This subscription adds some possible intruder-related activity to help analyst further refine their determinations about the state of the device. -- Logon session creation for network sessions +- Sign-in session creation for network sessions - Enables time-series analysis of network graphs. @@ -290,15 +290,15 @@ This adds some possible intruder-related activity to help analyst further refine - Detects known bad certificate, CA, or sub-CA - Detects unusual process use of CAPI -- Groups assigned to local logon +- Groups assigned to local sign in - - Gives visibility to groups which enable account-wide access + - Gives visibility to groups that enable account-wide access - Allows better planning for remediation efforts - Excludes well known, built-in system accounts. -- Logon session exit +- Sign-in session exit - - Specific for network logon sessions. + - Specific for network sign-in sessions. - Client DNS lookup events @@ -308,11 +308,11 @@ This adds some possible intruder-related activity to help analyst further refine - Enables checking for processes terminating unexpectedly. -- Local credential validation or logon with explicit credentials +- Local credential validation or signing in with explicit credentials - Generated when the local SAM is authoritative for the account credentials being authenticated. - Noisy on domain controllers - - On client devices this is only generated when local accounts log on. + - On client devices, it's only generated when local accounts sign in. - Registry modification audit events @@ -370,9 +370,9 @@ If your organizational audit policy enables more auditing to meet its needs, tha ## Appendix B - Recommended minimum registry system ACL policy -The Run and RunOnce keys are useful for intruders and malware persistence. It allows code to be run (or run only once then removed, respectively) when a user logs into the system. +The Run and RunOnce keys are useful for intruders and malware persistence. It allows code to be run (or run only once then removed, respectively) when a user signs in to the system. -This can easily be extended to other Auto-Execution Start Points keys in the registry. +This implication can easily be extended to other Auto-Execution Start Points keys in the registry. Use the following figures to see how you can configure those registry keys. @@ -384,16 +384,16 @@ Use the following figures to see how you can configure those registry keys. Some channels are disabled by default and have to be enabled. Others, such as Microsoft-Windows-CAPI2/Operational must have the channel access modified to allow the Event Log Readers built-in security group to read from it. -The recommended and most effective way to do this is configuring the baseline GPO to run a scheduled task to configure the event channels (enable, set maximum size, and adjust channel access.) This will take effect at the next GPO refresh cycle and has minimal impact on the client device. +The recommended and most effective way to do this customization is configuring the baseline GPO to run a scheduled task to configure the event channels (enable, set maximum size, and adjust channel access). This configuration will take effect at the next GPO refresh cycle and has minimal impact on the client device. -The following GPO snippet performs the following: +The following GPO snippet performs the following tasks: - Enables the **Microsoft-Windows-Capi2/Operational** event channel. - Sets the maximum file size for **Microsoft-Windows-Capi2/Operational** to 100MB. -- Sets the maximum file size for **Microsoft-Windows-AppLocker/EXE and DLL** to 100MB. +- Sets the maximum file size for **Microsoft-Windows-AppLocker/EXE and DLL** to 100 MB. - Sets the maximum channel access for **Microsoft-Windows-Capi2/Operational** to include the built-in Event Log Readers security group. - Enables the **Microsoft-Windows-DriverFrameworks-UserMode/Operational** event channel. -- Sets the maximum file size for **Microsoft-Windows-DriverFrameworks-UserMode/Operational** to 50MB. +- Sets the maximum file size for **Microsoft-Windows-DriverFrameworks-UserMode/Operational** to 50 MB. ![configure event channels.](images/capi-gpo.png) @@ -403,7 +403,7 @@ Here are the minimum steps for WEF to operate: 1. Configure the collector URI(s). 2. Start the WinRM service. -3. Add the Network Service account to the built-in Event Log Readers security group. This allows reading from secured event channel, such as the security event channel. +3. Add the Network Service account to the built-in Event Log Readers security group. This addition allows reading from secured event channel, such as the security event channel. ![configure the wef client.](images/wef-client-config.png) diff --git a/windows/security/threat-protection/windows-defender-application-control/LOB-win32-apps-on-s.md b/windows/security/threat-protection/windows-defender-application-control/LOB-win32-apps-on-s.md index e882f22e84..f85611c594 100644 --- a/windows/security/threat-protection/windows-defender-application-control/LOB-win32-apps-on-s.md +++ b/windows/security/threat-protection/windows-defender-application-control/LOB-win32-apps-on-s.md @@ -41,7 +41,7 @@ The general steps for expanding the S mode base policy on your Intune-managed de 1. Generate a supplemental policy with Windows Defender Application Control tooling - This policy will expand the S mode base policy to authorize additional applications. Anything authorized by either the S mode base policy or your supplemental policy will be allowed to run. Your supplemental policies can specify filepath rules, trusted publishers, and more. + This policy will expand the S mode base policy to authorize more applications. Anything authorized by either the S mode base policy or your supplemental policy will be allowed to run. Your supplemental policies can specify filepath rules, trusted publishers, and more. Refer to [Deploy multiple Windows Defender Application Control Policies](deploy-multiple-windows-defender-application-control-policies.md) for guidance on creating supplemental policies and [Deploy Windows Defender Application Control policy rules and file rules](select-types-of-rules-to-create.md) to choose the right type of rules to create for your policy. @@ -56,14 +56,14 @@ The general steps for expanding the S mode base policy on your Intune-managed de ```powershell Set-CIPolicyIdInfo -SupplementsBasePolicyID 5951A96A-E0B5-4D3D-8FB8-3E5B61030784 -FilePath "\SupplementalPolicy.xml" ``` - Policies which are supplementing the S mode base policy must use **-SupplementsBasePolicyID 5951A96A-E0B5-4D3D-8FB8-3E5B61030784**, as this is the S mode policy ID. + Policies that are supplementing the S mode base policy must use **-SupplementsBasePolicyID 5951A96A-E0B5-4D3D-8FB8-3E5B61030784**, as this ID is the S mode policy ID. - Put the policy in enforce mode using [Set-RuleOption](/powershell/module/configci/set-ruleoption?view=win10-ps&preserve-view=true) ```powershell Set-RuleOption -FilePath "\SupplementalPolicy.xml>" -Option 3 –Delete ``` - This deletes the 'audit mode' qualifier. - - Since you'll be signing your policy, you must authorize the signing certificate you will use to sign the policy and optionally one or more additional signers that can be used to sign updates to the policy in the future. For more information, refer to Section 2, Sign policy. Use Add-SignerRule to add the signing certificate to the Windows Defender Application Control policy: + This command deletes the 'audit mode' qualifier. + - Since you'll be signing your policy, you must authorize the signing certificate you'll use to sign the policy and optionally one or more extra signers that can be used to sign updates to the policy in the future. For more information, see Section 2, Sign policy. Use Add-SignerRule to add the signing certificate to the Windows Defender Application Control policy: ```powershell Add-SignerRule -FilePath -CertificatePath -User -Update @@ -82,7 +82,7 @@ The general steps for expanding the S mode base policy on your Intune-managed de 3. Deploy the signed supplemental policy using Microsoft Intune - Go to the Azure portal online and navigate to the Microsoft Intune page, then go to the Client apps blade and select 'S mode supplemental policies'. Upload the signed policy to Intune and assign it to user or device groups. Intune will generate tenant- and device- specific authorization tokens. Intune then deploys the corresponding authorization token and supplemental policy to each device in the assigned group. Together, these expand the S mode base policy on the device. + Go to the Azure portal online and navigate to the Microsoft Intune page, then go to the Client apps blade and select 'S mode supplemental policies'. Upload the signed policy to Intune and assign it to user or device groups. Intune will generate tenant- and device- specific authorization tokens. Intune then deploys the corresponding authorization token and supplemental policy to each device in the assigned group. Together, these tokens and policies expand the S mode base policy on the device. > [!Note] > When updating your supplemental policy, ensure that the new version number is strictly greater than the previous one. Using the same version number is not allowed by Intune. Refer to [Set-CIPolicyVersion](/powershell/module/configci/set-cipolicyversion?view=win10-ps&preserve-view=true) for information on setting the version number. @@ -95,9 +95,9 @@ Refer to [Intune Standalone - Win32 app management](/intune/apps-win32-app-manag ![Deploying Apps using Catalogs.](images/wdac-intune-app-catalogs.png) Your supplemental policy can be used to significantly relax the S mode base policy, but there are security trade-offs you must consider in doing so. For example, you can use a signer rule to trust an external signer, but that will authorize all apps signed by that certificate, which may include apps you don't want to allow as well. -Instead of authorizing signers external to your organization, Intune has added new functionality to make it easier to authorize existing applications (without requiring repackaging or access to the source code) through the use of signed catalogs. This works for apps which may be unsigned or even signed apps when you don't want to trust all apps that may share the same signing certificate. +Instead of authorizing signers external to your organization, Intune has added new functionality to make it easier to authorize existing applications (without requiring repackaging or access to the source code) by using signed catalogs. This functionality works for apps that may be unsigned or even signed apps when you don't want to trust all apps that may share the same signing certificate. -The basic process is to generate a catalog file for each app using Package Inspector, then sign the catalog files using the DGSS or a custom PKI. Use the Add-SignerRule PowerShell cmdlet as shown above to authorize the catalog signing certificate in the supplemental policy. After that, IT Pros can use the standard Intune app deployment process outlined above. Refer to [Deploy catalog files to support Windows Defender Application Control](deploy-catalog-files-to-support-windows-defender-application-control.md) for more in-depth guidance on generating catalogs. +The basic process is to generate a catalog file for each app using Package Inspector, then sign the catalog files using the DGSS or a custom PKI. Use the Add-SignerRule PowerShell cmdlet as shown above to authorize the catalog signing certificate in the supplemental policy. After that, IT Pros can use the standard Intune app deployment process outlined above. For more information on generating catalogs, see [Deploy catalog files to support Windows Defender Application Control](deploy-catalog-files-to-support-windows-defender-application-control.md). > [!Note] > Every time an app updates, you will need to deploy an updated catalog. Because of this, IT Pros should try to avoid using catalog files for applications that auto-update and direct users not to update applications on their own. @@ -186,7 +186,7 @@ Below is a sample policy that allows kernel debuggers, PowerShell ISE, and Regis ``` ## Policy removal -In order to revert users to an unmodified S mode policy, an IT Pro can remove a user or users from the targeted Intune group which received the policy, which will trigger a removal of both the policy and the authorization token from the device. +In order to revert users to an unmodified S mode policy, an IT Pro can remove a user or users from the targeted Intune group that received the policy, which will trigger a removal of both the policy and the authorization token from the device. IT Pros also have the choice of deleting a supplemental policy through Intune. diff --git a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md index 1b90bf0d1c..11e582e4d8 100644 --- a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md @@ -35,7 +35,7 @@ The [Microsoft Component Object Model (COM)](/windows/desktop/com/the-component- ### COM object configurability in WDAC policy -Prior to the Windows 10 1903 update, Windows Defender Application Control (WDAC) enforced a built-in allow list for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where additional COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. +Prior to the Windows 10 1903 update, Windows Defender Application Control (WDAC) enforced a built-in allowlist for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where more COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. > [!NOTE] > To add this functionality to other versions of Windows 10, you can install the following or later updates. @@ -56,7 +56,7 @@ Get GUID of application to allow in one of the following ways: Three elements: -- Provider: platform on which code is running (values are Powershell, WSH, IE, VBA, MSI, or a wildcard “AllHostIds”) +- Provider: platform on which code is running (values are PowerShell, WSH, IE, VBA, MSI, or a wildcard “AllHostIds”) - Key: GUID for the program you wish to run, in the format Key="{33333333-4444-4444-1616-161616161616}" - ValueName: needs to be set to "EnterpriseDefinedClsId" @@ -152,7 +152,7 @@ To add this CLSID to the existing policy, follow these steps: PS C:\WINDOWS\system32> Set-CIPolicySetting -FilePath \WDAC_policy.xml -Key "{f8d253d9-89a4-4daa-87b6-1168369f0b21}" -Provider WSH -Value true -ValueName EnterpriseDefinedClsId -ValueType Boolean ``` - Once the command has been run, you will find that the following section is added to the policy XML. + Once the command has been run, you'll find that the following section is added to the policy XML. ```XML @@ -162,9 +162,9 @@ To add this CLSID to the existing policy, follow these steps: ``` -### Default COM Object Allow List +### Default COM Object allowlist -The table below describes the list of COM objects that are inherently trusted in Windows Defender Application Control. Objects in this list do not need to be allowlisted in your WDAC policies. They can be denied by creating explicit deny rules in your WDAC policy. +The table below describes the list of COM objects that are inherently trusted in Windows Defender Application Control. Objects in this list don't need to be allowlisted in your WDAC policies. They can be denied by creating explicit deny rules in your WDAC policy. | File Name | CLSID | |--------|-----------| diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/add-rules-for-packaged-apps-to-existing-applocker-rule-set.md b/windows/security/threat-protection/windows-defender-application-control/applocker/add-rules-for-packaged-apps-to-existing-applocker-rule-set.md index d3d7b17207..5a985252e9 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/add-rules-for-packaged-apps-to-existing-applocker-rule-set.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/add-rules-for-packaged-apps-to-existing-applocker-rule-set.md @@ -33,6 +33,6 @@ This topic for IT professionals describes how to update your existing AppLocker You can create packaged app rules for the computers running Windows Server 2012 or Windows 8 and later in your domain by updating your existing AppLocker rule set. All you need is a computer running at least Windows 8. Download and install the Remote Server Administration Toolkit (RSAT) from the Microsoft Download Center. -RSAT comes with the Group Policy Management Console which allows you to edit the GPO or GPOs where your existing AppLocker policy are authored. RSAT has the necessary files required to author packaged app rules. Packaged app rules will be ignored on computers running Windows 7 and earlier but will be enforced on those computers in your domain running at least Windows Server 2012 and Windows 8. +RSAT comes with the Group Policy Management Console that allows you to edit the GPO or GPOs where your existing AppLocker policy is authored. RSAT has the necessary files required to author packaged app rules. Packaged app rules will be ignored on computers running Windows 7 and earlier but will be enforced on those computers in your domain running at least Windows Server 2012 and Windows 8.     diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-architecture-and-components.md b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-architecture-and-components.md index 206a7b287c..6dbbe7b0fe 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-architecture-and-components.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-architecture-and-components.md @@ -45,7 +45,7 @@ When a new DLL loads, a notification is sent to AppLocker to verify that the DLL **A script is run** -Before a script file is run, the script host (for example. for .ps1 files the script host is PowerShell) invokes AppLocker to verify the script. AppLocker invokes the Application Identity component in user-mode with the file name or file handle to calculate the file properties. The script file then is evaluated against the AppLocker policy to verify that it is allowed to run. In each case, the actions taken by AppLocker are written to the event log. +Before a script file is run, the script host (for example, for .ps1 files, the script host is PowerShell) invokes AppLocker to verify the script. AppLocker invokes the Application Identity component in user-mode with the file name or file handle to calculate the file properties. The script file then is evaluated against the AppLocker policy to verify that it's allowed to run. In each case, the actions taken by AppLocker are written to the event log. ## Related topics diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview.md b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview.md index af1cdbd2d8..4e4e13c016 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview.md @@ -51,7 +51,7 @@ AppLocker helps reduce administrative overhead and helps reduce the organization - **Protection against unwanted software** - AppLocker has the ability to deny apps from running when you exclude them from the list of allowed apps. When AppLocker rules are enforced in the production environment, any apps that are not included in the allowed rules are blocked from running. + AppLocker has the ability to deny apps from running when you exclude them from the list of allowed apps. When AppLocker rules are enforced in the production environment, any apps that aren't included in the allowed rules are blocked from running. - **Licensing conformance** @@ -59,11 +59,11 @@ AppLocker helps reduce administrative overhead and helps reduce the organization - **Software standardization** - AppLocker policies can be configured to allow only supported or approved apps to run on computers within a business group. This permits a more uniform app deployment. + AppLocker policies can be configured to allow only supported or approved apps to run on computers within a business group. This configuration permits a more uniform app deployment. - **Manageability improvement** - AppLocker includes a number of improvements in manageability as compared to its predecessor Software Restriction Policies. Importing and exporting policies, automatic generation of rules from multiple files, audit-only mode deployment, and Windows PowerShell cmdlets are a few of the improvements over Software Restriction Policies. + AppLocker includes many improvements in manageability as compared to its predecessor Software Restriction Policies. Importing and exporting policies, automatic generation of rules from multiple files, audit-only mode deployment, and Windows PowerShell cmdlets are a few of the improvements over Software Restriction Policies. ## When to use AppLocker @@ -71,7 +71,7 @@ AppLocker helps reduce administrative overhead and helps reduce the organization In many organizations, information is the most valuable asset, and ensuring that only approved users have access to that information is imperative. Access control technologies, such as Active Directory Rights Management Services (AD RMS) and access control lists (ACLs), help control what users are allowed to access. However, when a user runs a process, that process has the same level of access to data that the user has. As a result, sensitive information could easily be deleted or transmitted out of the organization if a user knowingly or unknowingly runs malicious software. AppLocker can help mitigate these types of security breaches by restricting the files that users or groups are allowed to run. -Software publishers are beginning to create more apps that can be installed by non-administrative users. This could jeopardize an organization's written security policy and circumvent traditional app control solutions that rely on the inability of users to install apps. By creating an allowed list of approved files and apps, AppLocker helps prevent such per-user apps from running. Because AppLocker can control DLLs, it is also useful to control who can install and run ActiveX controls. +Software publishers are beginning to create more apps that can be installed by non-administrative users. This privilege could jeopardize an organization's written security policy and circumvent traditional app control solutions that rely on the inability of users to install apps. AppLocker creates an allowed list of approved files and apps to help prevent such per-user apps from running. Because AppLocker can control DLLs, it's also useful to control who can install and run ActiveX controls. AppLocker is ideal for organizations that currently use Group Policy to manage their PCs. @@ -80,9 +80,9 @@ The following are examples of scenarios in which AppLocker can be used: - Your organization's security policy dictates the use of only licensed software, so you need to prevent users from running unlicensed software and also restrict the use of licensed software to authorized users. - An app is no longer supported by your organization, so you need to prevent it from being used by everyone. - The potential that unwanted software can be introduced in your environment is high, so you need to reduce this threat. -- The license to an app has been revoked or it is expired in your organization, so you need to prevent it from being used by everyone. +- The license to an app has been revoked or it's expired in your organization, so you need to prevent it from being used by everyone. - A new app or a new version of an app is deployed, and you need to prevent users from running the old version. -- Specific software tools are not allowed within the organization, or only specific users should have access to those tools. +- Specific software tools aren't allowed within the organization, or only specific users should have access to those tools. - A single user or small group of users needs to use a specific app that is denied for all others. - Some computers in your organization are shared by people who have different software usage needs, and you need to protect specific apps. - In addition to other measures, you need to control the access to sensitive data through app usage. @@ -101,7 +101,7 @@ AppLocker is included with enterprise-level editions of Windows. You can author ### Using AppLocker on Server Core -AppLocker on Server Core installations is not supported. +AppLocker on Server Core installations isn't supported. ### Virtualization considerations @@ -115,9 +115,9 @@ The variety of forms that malicious software can take make it difficult for user The countermeasure is to create a sound design for your application control policies on PCs in your organization, and then thoroughly test the policies in a lab environment before you deploy them in a production environment. AppLocker can be part of your app control strategy because you can control what software is allowed to run on your computers. -A flawed application control policy implementation can disable necessary applications or allow malicious or unintended software to run. Therefore, it is important that organizations dedicate sufficient resources to manage and troubleshoot the implementation of such policies. +A flawed application control policy implementation can disable necessary applications or allow malicious or unintended software to run. Therefore, it's important that organizations dedicate sufficient resources to manage and troubleshoot the implementation of such policies. -For additional information about specific security issues, see [Security considerations for AppLocker](security-considerations-for-applocker.md). +For more information about specific security issues, see [Security considerations for AppLocker](security-considerations-for-applocker.md). When you use AppLocker to create application control policies, you should be aware of the following security considerations: diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-deployment-guide.md b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-deployment-guide.md index 8b61cc5f7c..a7af9ef942 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-deployment-guide.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-deployment-guide.md @@ -32,7 +32,7 @@ ms.technology: windows-sec This topic for IT professionals introduces the concepts and describes the steps required to deploy AppLocker policies. -This guide provides steps based on your design and planning investigation for deploying application control policies by using AppLocker. It is intended for security architects, security administrators, and system administrators. Through a sequential and iterative deployment process, you can create application control policies, test and adjust the policies, and implement a method for maintaining those policies as the needs in your organization change. +This guide provides steps based on your design and planning investigation for deploying application control policies by using AppLocker. It's intended for security architects, security administrators, and system administrators. Through a sequential and iterative deployment process, you can create application control policies, test and adjust the policies, and implement a method for maintaining those policies as the needs in your organization change. This guide covers the use of Software Restriction Policies (SRP) in conjunction with AppLocker policies to control application usage. For a comparison of SRP and AppLocker, see [Using Software Restriction Policies and AppLocker policies](using-software-restriction-policies-and-applocker-policies.md) in this guide. To understand if AppLocker is the correct application control solution for you, see [Understand AppLocker policy design decisions](understand-applocker-policy-design-decisions.md). diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-design-guide.md b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-design-guide.md index 5175d57766..2c023e6bc0 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-design-guide.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-design-guide.md @@ -31,9 +31,9 @@ ms.technology: windows-sec This topic for the IT professional introduces the design and planning steps required to deploy application control policies by using AppLocker. -This guide provides important designing and planning information for deploying application control policies by using AppLocker. It is intended for security architects, security administrators, and system administrators. Through a sequential and iterative process, you can create an AppLocker policy deployment plan for your organization that will address your specific application control requirements by department, organizational unit, or business group. +This guide provides important designing and planning information for deploying application control policies by using AppLocker. It's intended for security architects, security administrators, and system administrators. Through a sequential and iterative process, you can create an AppLocker policy deployment plan for your organization that will address your specific application control requirements by department, organizational unit, or business group. -This guide does not cover the deployment of application control policies by using Software Restriction Policies (SRP). However, SRP is discussed as a deployment option in conjunction with AppLocker policies. For info about these options, see [Determine your application control objectives](determine-your-application-control-objectives.md). +This guide doesn't cover the deployment of application control policies by using Software Restriction Policies (SRP). However, SRP is discussed as a deployment option in conjunction with AppLocker policies. For info about these options, see [Determine your application control objectives](determine-your-application-control-objectives.md). To understand if AppLocker is the correct application control solution for your organization, see [Understand AppLocker policy design decisions](understand-applocker-policy-design-decisions.md). ## In this section @@ -44,8 +44,8 @@ To understand if AppLocker is the correct application control solution for your | [Determine your application control objectives](determine-your-application-control-objectives.md) | This topic helps you with the decisions you need to make to determine what applications to control and how to control them by comparing Software Restriction Policies (SRP) and AppLocker. | | [Create a list of apps deployed to each business group](create-list-of-applications-deployed-to-each-business-group.md) | This topic describes the process of gathering app usage requirements from each business group in order to implement application control policies by using AppLocker. | | [Select the types of rules to create](select-types-of-rules-to-create.md) | This topic lists resources you can use when selecting your application control policy rules by using AppLocker. | -| [Determine the Group Policy structure and rule enforcement](determine-group-policy-structure-and-rule-enforcement.md) | This overview topic describes the process to follow when you are planning to deploy AppLocker rules. | -| [Plan for AppLocker policy management](plan-for-applocker-policy-management.md) | This topic for describes the decisions you need to make to establish the processes for managing and maintaining AppLocker policies. | +| [Determine the Group Policy structure and rule enforcement](determine-group-policy-structure-and-rule-enforcement.md) | This overview topic describes the process to follow when you're planning to deploy AppLocker rules. | +| [Plan for AppLocker policy management](plan-for-applocker-policy-management.md) | This topic describes the decisions you need to make to establish the processes for managing and maintaining AppLocker policies. |   After careful design and detailed planning, the next step is to deploy AppLocker policies. [AppLocker Deployment Guide](applocker-policies-deployment-guide.md) covers the creation and testing of policies, deploying the enforcement setting, and managing and maintaining the policies. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policy-use-scenarios.md b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policy-use-scenarios.md index 32d003ef09..77d166aedc 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policy-use-scenarios.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policy-use-scenarios.md @@ -39,7 +39,7 @@ AppLocker can help you improve the management of application control and the mai 2. **Protection against unwanted software** - AppLocker has the ability to deny apps from running simply by excluding them from the list of allowed apps per business group or user. If an app is not identified by its publisher, installation path, or file hash, the attempt to run the application fails. + AppLocker has the ability to deny apps from running simply by excluding them from the list of allowed apps per business group or user. If an app isn't identified by its publisher, installation path, or file hash, the attempt to run the application fails. 3. **Licensing conformance** @@ -47,12 +47,11 @@ AppLocker can help you improve the management of application control and the mai 4. **Software standardization** - AppLocker policies can be configured to allow only supported or approved apps to run on computers within a business group. This permits a more uniform app deployment. + AppLocker policies can be configured to allow only supported or approved apps to run on computers within a business group. This configuration permits a more uniform app deployment. 5. **Manageability improvement** - AppLocker policies can be modified and deployed through your existing Group Policy infrastructure and can work in conjunction with policies created by using Software Restriction Policies. As you manage ongoing change in your support of a business group's apps, you can modify policies and use - the AppLocker cmdlets to test the policies for the expected results. You can also design application control policies for situations in which users share computers. + AppLocker policies can be modified and deployed through your existing Group Policy infrastructure and can work in conjunction with policies created by using Software Restriction Policies. As you manage ongoing change in your support of a business group's apps, you can modify policies and use the AppLocker cmdlets to test the policies for the expected results. You can also design application control policies for situations in which users share computers. ### Use scenarios @@ -60,13 +59,13 @@ The following are examples of scenarios in which AppLocker can be used: - Your organization implements a policy to standardize the applications used within each business group, so you need to determine the expected usage compared to the actual usage. - The security policy for application usage has changed, and you need to evaluate where and when those deployed apps are being accessed. -- Your organization's security policy dictates the use of only licensed software, so you need to determine which apps are not licensed or prevent unauthorized users from running licensed software. +- Your organization's security policy dictates the use of only licensed software, so you need to determine which apps aren't licensed or prevent unauthorized users from running licensed software. - An app is no longer supported by your organization, so you need to prevent it from being used by everyone. -- Your organization needs to restrict the use of Universal Windows apps to just those your organization approves of or develops. +- Your organization needs to restrict the use of Universal Windows apps to just those apps your organization approves of or develops. - The potential that unwanted software can be introduced in your environment is high, so you need to reduce this threat. - The license to an app has been revoked or is expired in your organization, so you need to prevent it from being used by everyone. - A new app or a new version of an app is deployed, and you need to allow certain groups to use it. -- Specific software tools are not allowed within the organization, or only specific users have access to those tools. +- Specific software tools aren't allowed within the organization, or only specific users have access to those tools. - A single user or small group of users needs to use a specific app that is denied for all others. - Some computers in your organization are shared by people who have different software usage needs. - In addition to other measures, you need to control the access to sensitive data through app usage. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-processes-and-interactions.md b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-processes-and-interactions.md index 8460667499..34ff057457 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-processes-and-interactions.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-processes-and-interactions.md @@ -35,7 +35,7 @@ This topic for the IT professional describes the process dependencies and intera AppLocker policies are collections of AppLocker rules that might contain any one of the enforcement settings configured. When applied, each rule is evaluated within the policy and the collection of rules is applied according to the enforcement setting and according to your Group Policy structure. -The AppLocker policy is enforced on a computer through the Application Identity service, which is the engine that evaluates the policies. If the service is not running, policies will not be enforced. The Application Identity service returns the information from the binary -even if product or binary names are empty- to the results pane of the Local Security Policy snap-in. +The AppLocker policy is enforced on a computer through the Application Identity service, which is the engine that evaluates the policies. If the service isn't running, policies won't be enforced. The Application Identity service returns the information from the binary -even if product or binary names are empty- to the results pane of the Local Security Policy snap-in. AppLocker policies are stored in a security descriptor format according to Application Identity service requirements. It uses file path, hash, or fully qualified binary name attributes to form allow or deny actions on a rule. Each rule is stored as an access control entry (ACE) in the security descriptor and contains the following information: @@ -49,7 +49,7 @@ An AppLocker policy for DLLs and executable files is read and cached by kernel m ### Understanding AppLocker rules -An AppLocker rule is a control placed on a file to govern whether or not it is allowed to run for a specific user or group. Rules apply to five different types, or collections, of files: +An AppLocker rule is a control placed on a file to govern whether or not it's allowed to run for a specific user or group. Rules apply to five different types, or collections, of files: - An executable rule controls whether a user or group can run an executable file. Executable files most often have the .exe or .com file name extensions and apply to applications. - A script rule controls whether a user or group can run scripts with a file name extension of .ps1, .bat, .cmd, .vbs, and .js. @@ -97,7 +97,7 @@ An AppLocker policy is a set of rule collections and their corresponding configu - [Understand AppLocker enforcement settings](understand-applocker-enforcement-settings.md) - Rule enforcement is applied only to collections of rules, not individual rules. AppLocker divides the rules into four collections: executable files, Windows Installer files, scripts, and DLL files. The options for rule enforcement are **Not configured**, **Enforce rules**, or **Audit only**. Together, all AppLocker rule collections compose the application control policy, or AppLocker policy. By default, if enforcement is not configured and rules are present in a rule collection, those rules are enforced. + Rule enforcement is applied only to collections of rules, not individual rules. AppLocker divides the rules into four collections: executable files, Windows Installer files, scripts, and DLL files. The options for rule enforcement are **Not configured**, **Enforce rules**, or **Audit only**. Together, all AppLocker rule collections compose the application control policy, or AppLocker policy. By default, if enforcement isn't configured and rules are present in a rule collection, those rules are enforced. ### Understanding AppLocker and Group Policy @@ -105,7 +105,7 @@ Group Policy can be used to create, modify, and distribute AppLocker policies in - [Understand AppLocker rules and enforcement setting inheritance in Group Policy](understand-applocker-rules-and-enforcement-setting-inheritance-in-group-policy.md) - When Group Policy is used to distribute AppLocker policies, rule collections that are not configured will be enforced. Group Policy does not overwrite or replace rules that are already present in a linked Group Policy Object (GPO) and applies the AppLocker rules in addition to existing rules. + When Group Policy is used to distribute AppLocker policies, rule collections that aren't configured will be enforced. Group Policy doesn't overwrite or replace rules that are already present in a linked Group Policy Object (GPO) and applies the AppLocker rules in addition to existing rules. AppLocker processes the explicit deny rule configuration before the allow rule configuration, and for rule enforcement, the last write to the GPO is applied. ## Related topics diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/configure-an-applocker-policy-for-enforce-rules.md b/windows/security/threat-protection/windows-defender-application-control/applocker/configure-an-applocker-policy-for-enforce-rules.md index 4ae757fa97..81a1e43bb4 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/configure-an-applocker-policy-for-enforce-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/configure-an-applocker-policy-for-enforce-rules.md @@ -40,7 +40,7 @@ You can perform this task by using the Group Policy Management Console for an Ap **To enable the Enforce rules enforcement setting** 1. From the AppLocker console, right-click **AppLocker**, and then click **Properties**. -2. On the **Enforcement** tab of the **AppLocker Properties** dialog box, select the **Configured** check box for the rule collection that you are editing, and then verify that **Enforce rules** is selected. +2. On the **Enforcement** tab of the **AppLocker Properties** dialog box, select the **Configured** check box for the rule collection that you're editing, and then verify that **Enforce rules** is selected. 3. Click **OK**. For info about viewing the events generated from rules enforcement, see [Monitor app usage with AppLocker](monitor-application-usage-with-applocker.md). diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-appLocker-reference-device.md b/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-appLocker-reference-device.md index 0675c5fa73..1f7b314f14 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-appLocker-reference-device.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-appLocker-reference-device.md @@ -36,15 +36,15 @@ An AppLocker reference device that is used for the development and deployment of - Maintain an application list for each business group. - Develop AppLocker policies by creating individual rules or by creating a policy by automatically generating rules. - Create the default rules to allow the Windows system files to run properly. -- Run tests and analyze the event logs to determine the affect of the policies that you intend to deploy. +- Run tests and analyze the event logs to determine the effect of the policies that you intend to deploy. -The reference device does not need to be joined to a domain, but it must be able to import and export AppLocker policies in XML format. The reference computer must be running one of the supported editions of Windows as listed in [Requirements to use AppLocker](requirements-to-use-applocker.md). +The reference device doesn't need to be joined to a domain, but it must be able to import and export AppLocker policies in XML format. The reference computer must be running one of the supported editions of Windows as listed in [Requirements to use AppLocker](requirements-to-use-applocker.md). >**Warning:**  Do not use operating system snapshots when creating AppLocker rules. If you take a snapshot of the operating system, install an app, create AppLocker rules, and then revert to a clean snapshot and repeat the process for another app, there is a chance that duplicate rule GUIDs can be created. If duplicate GUIDs are present, AppLocker policies will not work as expected. **To configure a reference device** -1. If the operating system is not already installed, install one of the supported editions of Windows on the device. +1. If the operating system isn't already installed, install one of the supported editions of Windows on the device. >**Note:**  If you have the Group Policy Management Console (GPMC) installed on another device to test your implementation of AppLocker policies, you can export the policies to that device @@ -58,7 +58,7 @@ The reference device does not need to be joined to a domain, but it must be able ### See also -- After you configure the reference computer, you can create the AppLocker rule collections. You can build, import, or automatically generate the rules. For procedures to do this, see [Working with AppLocker rules](working-with-applocker-rules.md). +- After you configure the reference computer, you can create the AppLocker rule collections. You can build, import, or automatically generate the rules. For procedures to do this task, see [Working with AppLocker rules](working-with-applocker-rules.md). - [Use a reference device to create and maintain AppLocker policies](use-a-reference-computer-to-create-and-maintain-applocker-policies.md) From 4e8cbb0dbd9780861e46c8dbbfacf5e9eaf35fb1 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Fri, 1 Jul 2022 11:38:41 +0530 Subject: [PATCH 010/109] Acrolinx Enhancement Effort --- .../applocker/create-a-rule-for-packaged-apps.md | 14 +++++++------- ...applications-deployed-to-each-business-group.md | 12 ++++++------ .../applocker/create-your-applocker-policies.md | 8 ++++---- .../applocker/create-your-applocker-rules.md | 6 +++--- .../applocker/delete-an-applocker-rule.md | 6 +++--- ...-policies-by-using-the-enforce-rules-setting.md | 10 +++++----- ...-group-policy-structure-and-rule-enforcement.md | 10 +++++----- ...are-digitally-signed-on-a-reference-computer.md | 4 ++-- ...etermine-your-application-control-objectives.md | 14 +++++++------- ...-when-users-try-to-run-a-blocked-application.md | 2 +- 10 files changed, 43 insertions(+), 43 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-for-packaged-apps.md b/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-for-packaged-apps.md index 1c676d9236..3bc3d41f7e 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-for-packaged-apps.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-for-packaged-apps.md @@ -31,7 +31,7 @@ ms.technology: windows-sec This article for IT professionals shows how to create an AppLocker rule for packaged apps with a publisher condition. -Packaged apps, also known as Universal Windows apps, are based on an app model that ensures that all the files within an app package share the same identity. Therefore, it is possible to control the entire app using a single AppLocker rule as opposed to the non-packaged apps where each file within the app could have a unique identity. Windows does not support unsigned packaged apps, which implies all packaged apps must be signed. AppLocker supports only publisher rules for packaged apps. A publisher rule for a packaged app is based on the following information: +Packaged apps, also known as Universal Windows apps, are based on an app model that ensures that all the files within an app package share the same identity. Therefore, it's possible to control the entire app using a single AppLocker rule as opposed to the non-packaged apps where each file within the app could have a unique identity. Windows doesn't support unsigned packaged apps, which implies all packaged apps must be signed. AppLocker supports only publisher rules for packaged apps. A publisher rule for a packaged app is based on the following information: - Publisher of the package - Package name @@ -53,19 +53,19 @@ You can perform this task by using the Group Policy Management Console for an Ap |Selection|Description|Example| |--- |--- |--- | - |**Use an installed packaged app as a reference**|If selected, AppLocker requires you to choose an app that is already installed on which to base your new rule. AppLocker uses the publisher, package name and package version to define the rule.|You want the Sales group only to use the app named Microsoft.BingMaps for its outside sales calls. The Microsoft.BingMaps app is already installed on the device where you are creating the rule, so you choose this option, and select the app from the list of apps installed on the computer and create the rule using this app as a reference.| + |**Use an installed packaged app as a reference**|If selected, AppLocker requires you to choose an app that is already installed on which to base your new rule. AppLocker uses the publisher, package name and package version to define the rule.|You want the Sales group only to use the app named Microsoft.BingMaps for its outside sales calls. The Microsoft.BingMaps app is already installed on the device where you're creating the rule, so you choose this option, and select the app from the list of apps installed on the computer and create the rule using this app as a reference.| |**Use a packaged app installer as a reference**|If selected, AppLocker requires you to choose an app installer on which to base your new rule. A packaged app installer has the .appx extension. AppLocker uses the publisher, package name, and package version of the installer to define the rule.|Your company has developed many internal line-of-business packaged apps. The app installers are stored on a common file share. Employees can install the required apps from that file share. You want to allow all your employees to install the Payroll app from this share. So you choose this option from the wizard, browse to the file share, and choose the installer for the Payroll app as a reference to create your rule.| The following table describes setting the scope for the packaged app rule. |Selection|Description|Example| |--- |--- |--- | - |Applies to **Any publisher**|This is the least restrictive scope condition for an **Allow** rule. It permits every packaged app to run or install.

Conversely, if this is a **Deny** rule, then this option is the most restrictive because it denies all apps from installing or running. | You want the Sales group to use any packaged app from any signed publisher. You set the permissions to allow the Sales group to be able to run any app.| - |Applies to a specific **Publisher** | This scopes the rule to all apps published by a particular publisher. | You want to allow all your users to install apps published by the publisher of Microsoft.BingMaps. You could select Microsoft.BingMaps as a reference and choose this rule scope. | - |Applies to a **Package name** | This scopes the rule to all packages that share the publisher name and package name as the reference file. | You want to allow your Sales group to install any version of the Microsoft.BingMaps app. You could select the Microsoft.BingMaps app as a reference and choose this rule scope. | - |Applies to a **Package version** | This scopes the rule to a particular version of the package. | You want to be very selective in what you allow. You do not want to implicitly trust all future updates of the Microsoft.BingMaps app. You can limit the scope of your rule to the version of the app currently installed on your reference computer. | + |Applies to **Any publisher**|This setting is the least restrictive scope condition for an **Allow** rule. It permits every packaged app to run or install.

Conversely, if this setting is a **Deny** rule, then this option is the most restrictive because it denies all apps from installing or running. | You want the Sales group to use any packaged app from any signed publisher. You set the permissions to allow the Sales group to be able to run any app.| + |Applies to a specific **Publisher** | This setting scopes the rule to all apps published by a particular publisher. | You want to allow all your users to install apps published by the publisher of Microsoft.BingMaps. You could select Microsoft.BingMaps as a reference and choose this rule scope. | + |Applies to a **Package name** | This setting scopes the rule to all packages that share the publisher name and package name as the reference file. | You want to allow your Sales group to install any version of the Microsoft.BingMaps app. You could select the Microsoft.BingMaps app as a reference and choose this rule scope. | + |Applies to a **Package version** | This setting scopes the rule to a particular version of the package. | You want to be selective in what you allow. You don't want to implicitly trust all future updates of the Microsoft.BingMaps app. You can limit the scope of your rule to the version of the app currently installed on your reference computer. | |Applying custom values to the rule | Selecting the **Use custom values** check box allows you to adjust the scope fields for your particular circumstance. | You want to allow users to install all *Microsoft.Bing* applications, which include Microsoft.BingMaps, Microsoft.BingWeather, Microsoft.BingMoney. You can choose the Microsoft.BingMaps as a reference, select the **Use custom values** check box and edit the package name field by adding “Microsoft.Bing*” as the Package name. | 6. Select **Next**. -7. (Optional) On the **Exceptions** page, specify conditions by which to exclude files from being affected by the rule. This allows you to add exceptions based on the same rule reference and rule scope as you set before. Select **Next**. +7. (Optional) On the **Exceptions** page, specify conditions by which to exclude files from being affected by the rule. These conditions allow you to add exceptions based on the same rule reference and rule scope as you set before. Select **Next**. 8. On the **Name** page, either accept the automatically generated rule name or type a new rule name, and then select **Create**. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/create-list-of-applications-deployed-to-each-business-group.md b/windows/security/threat-protection/windows-defender-application-control/applocker/create-list-of-applications-deployed-to-each-business-group.md index 7daf4320eb..4b22dedc36 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/create-list-of-applications-deployed-to-each-business-group.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/create-list-of-applications-deployed-to-each-business-group.md @@ -39,7 +39,7 @@ For each business group, determine the following information: - The full installation path of the app - The publisher and signed status of each app - The type of requirement the business groups set for each app, such as business critical, business productivity, optional, or personal. It might also be helpful during this effort to identify which apps are supported or unsupported by your IT department, or supported by others outside your control. -- A list of files or apps that require administrative credentials to install or run. If the file requires administrative credentials to install or run, users who cannot provide administrative credentials will be prevented from running the file even if the file is explicitly allowed by an AppLocker policy. Even with AppLocker policies enforced, only members of the Administrators group can install or run files that require administrative credentials. +- A list of files or apps that require administrative credentials to install or run. If the file requires administrative credentials to install or run, users who can't provide administrative credentials will be prevented from running the file even if the file is explicitly allowed by an AppLocker policy. Even with AppLocker policies enforced, only members of the Administrators group can install or run files that require administrative credentials. ### How to perform the app usage assessment @@ -48,9 +48,9 @@ Rules wizard and the **Audit only** enforcement configuration to assist you with **Application inventory methods** -Using the Automatically Generate Rules wizard quickly creates rules for the applications you specify. The wizard is designed specifically to build a rule collection. You can use the Local Security Policy snap-in to view and edit the rules. This method is useful when creating rules from a reference computer and when creating and evaluating AppLocker policies in a testing environment. However, it does require that the files be accessible on the reference computer or through a network drive. This might mean additional work in setting up the reference computer and determining a maintenance policy for that computer. +Using the Automatically Generate Rules wizard quickly creates rules for the applications you specify. The wizard is designed specifically to build a rule collection. You can use the Local Security Policy snap-in to view and edit the rules. This method is useful when creating rules from a reference computer and when creating and evaluating AppLocker policies in a testing environment. However, it does require that the files be accessible on the reference computer or through a network drive. This requirement might mean more work in setting up the reference computer and determining a maintenance policy for that computer. -Using the **Audit only** enforcement method permits you to view the logs because it collects information about every process on the computers receiving the Group Policy Object (GPO). Therefore, you can see what the enforcement will be on the computers in a business group. AppLocker includes Windows PowerShell cmdlets that you can use to analyze the events from the event log and cmdlets to create rules. However, when you use Group Policy to deploy to several computers, a means to collect events in a central location is very important for manageability. Because AppLocker logs information about files that users or other processes start on a computer, you could miss creating some rules initially. Therefore, you should continue your evaluation until you can verify that all required applications that are allowed to run are accessed successfully. +Using the **Audit only** enforcement method permits you to view the logs because it collects information about every process on the computers receiving the Group Policy Object (GPO). Therefore, you can see what the enforcement will be on the computers in a business group. AppLocker includes Windows PowerShell cmdlets that you can use to analyze the events from the event log and cmdlets to create rules. However, when you use Group Policy to deploy to several computers, a means to collect events in a central location is important for manageability. Because AppLocker logs information about files that users or other processes start on a computer, you could miss creating some rules initially. Therefore, you should continue your evaluation until you can verify that all required applications that are allowed to run are accessed successfully. > [!TIP] > If you run Application Verifier against a custom application with any AppLocker policies enabled, it might prevent the application from running. You should either disable Application Verifier or AppLocker. @@ -63,16 +63,16 @@ The following topics describe how to perform each method: ### Prerequisites to completing the inventory -Identify the business group and each organizational unit (OU) within that group to which you will apply application control policies. In addition, you should have identified whether or not AppLocker is the most appropriate solution for these policies. For info about these steps, see the following topics: +Identify the business group and each organizational unit (OU) within that group to which you'll apply application control policies. In addition, you should have identified whether or not AppLocker is the most appropriate solution for these policies. For info about these steps, see the following topics: - [Understand AppLocker policy design decisions](understand-applocker-policy-design-decisions.md) - [Determine your application control objectives](determine-your-application-control-objectives.md) ## Next steps -Identify and develop the list of apps. Record the name of the app, whether it is signed or not as indicated by the publisher's name, and whether or not it is a mission critical, business productivity, optional, or personal application. Record the installation path of the apps. For info about how to do this, see [Document your app list](document-your-application-list.md). +Identify and develop the list of apps. Record the name of the app, whether it's signed or not as indicated by the publisher's name, and whether or not it's a mission critical, business productivity, optional, or personal application. Record the installation path of the apps. For more information, see [Document your app list](document-your-application-list.md). -After you have created the list of apps, the next step is to identify the rule collections, which will become the policies. This information can be added to the table under columns labeled: +After you've created the list of apps, the next step is to identify the rule collections, which will become the policies. This information can be added to the table under columns labeled: - Use default rule or define new rule condition - Allow or deny diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-policies.md b/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-policies.md index 961dd4e3ff..8a5e46aee1 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-policies.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-policies.md @@ -35,7 +35,7 @@ Creating effective application control policies with AppLocker starts by creatin ## Step 1: Use your plan -You can develop an application control policy plan to guide you in making successful deployment decisions. For more info about how to do this and what you should consider, see the [AppLocker Design Guide](applocker-policies-design-guide.md). This guide is intended for security architects, security administrators, and system administrators. It contains the following topics to help you create an AppLocker policy deployment plan for your organization that will address your specific application control requirements by department, organizational unit, or business group: +You can develop an application control policy plan to guide you in making successful deployment decisions. For more information about how to develop this policy and what you should consider, see the [AppLocker Design Guide](applocker-policies-design-guide.md). This guide is intended for security architects, security administrators, and system administrators. It contains the following topics to help you create an AppLocker policy deployment plan for your organization that will address your specific application control requirements by department, organizational unit, or business group: 1. [Understand the AppLocker policy deployment process](understand-the-applocker-policy-deployment-process.md) 2. [Understand AppLocker policy design decisions](understand-applocker-policy-design-decisions.md) @@ -52,12 +52,12 @@ Each rule applies to one or more apps, and it imposes a specific rule condition ## Step 3: Configure the enforcement setting -An AppLocker policy is a set of rule collections that are configured with a rule enforcement setting. The enforcement setting can be **Enforce rules**, **Audit only**, or **Not configured**. If an AppLocker policy has at least one rule, and it is set to **Not configured**, all the rules in that +An AppLocker policy is a set of rule collections that are configured with a rule enforcement setting. The enforcement setting can be **Enforce rules**, **Audit only**, or **Not configured**. If an AppLocker policy has at least one rule, and it's set to **Not configured**, all the rules in that policy will be enforced. For info about configuring the rule enforcement setting, see [Configure an AppLocker policy for audit only](configure-an-applocker-policy-for-audit-only.md) and [Configure an AppLocker policy for enforce rules](configure-an-applocker-policy-for-enforce-rules.md). ## Step 4: Update the GPO -AppLocker policies can be defined locally on a device or applied through Group Policy. To use Group Policy to apply AppLocker policies, you must create a new Group Policy Object (GPO) or you must update an existing GPO. You can create or modify AppLocker policies by using the Group Policy Management Console (GPMC), or you can import an AppLocker policy into a GPO. For the procedure to do this, see [Import an AppLocker policy into a GPO](import-an-applocker-policy-into-a-gpo.md). +AppLocker policies can be defined locally on a device or applied through Group Policy. To use Group Policy to apply AppLocker policies, you must create a new Group Policy Object (GPO), or you must update an existing GPO. You can create or modify AppLocker policies by using the Group Policy Management Console (GPMC), or you can import an AppLocker policy into a GPO. For the procedure to import this policy into a GPO, see [Import an AppLocker policy into a GPO](import-an-applocker-policy-into-a-gpo.md). ## Step 5: Test the effect of the policy @@ -68,7 +68,7 @@ In a test environment or with the enforcement setting set at **Audit only**, ver Depending on your deployment method, import the AppLocker policy to the GPO in your production environment, or if the policy is already deployed, change the enforcement setting to your production environment value—**Enforce rules** or **Audit only**. ## Step 7: Test the effect of the policy and adjust -Validate the effect of the policy by analyzing the AppLocker logs for application usage, and then modify the policy as necessary. To do this, see [Monitor app usage with AppLocker](monitor-application-usage-with-applocker.md). +Validate the effect of the policy by analyzing the AppLocker logs for application usage, and then modify the policy as necessary. For information on how to do these tasks, see [Monitor app usage with AppLocker](monitor-application-usage-with-applocker.md). ## Next steps diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-rules.md b/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-rules.md index cdda7822da..8efbf0415b 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-rules.md @@ -33,7 +33,7 @@ This topic for the IT professional describes what you need to know about AppLock ## Creating AppLocker rules -AppLocker rules apply to the targeted app, and they are the components that make up the AppLocker policy. Depending on your IT environment and the business group that requires application control policies, setting these access rules for each application can be time-consuming and prone to error. With AppLocker, you can generate rules automatically or create rules individually. Creating rules that are derived from your planning document can help you avoid unintended results. For info about this planning document and other planning activities, see [AppLocker Design Guide](applocker-policies-design-guide.md). +AppLocker rules apply to the targeted app, and they're the components that make up the AppLocker policy. Depending on your IT environment and the business group that requires application control policies, setting these access rules for each application can be time-consuming and prone to error. With AppLocker, you can generate rules automatically or create rules individually. Creating rules that are derived from your planning document can help you avoid unintended results. For info about this planning document and other planning activities, see [AppLocker Design Guide](applocker-policies-design-guide.md). ### Automatically generate your rules @@ -47,7 +47,7 @@ You can use a reference device to automatically create a set of default rules fo ### Create your rules individually -You can create rules and set the mode to **Audit only** for each installed app, test and update each rule as necessary, and then deploy the policies. Creating rules individually might be best when you are targeting a small number of applications within a business group. +You can create rules and set the mode to **Audit only** for each installed app, test and update each rule as necessary, and then deploy the policies. Creating rules individually might be best when you're targeting a few applications within a business group. >**Note:**  AppLocker includes default rules for each rule collection. These rules are intended to help ensure that the files that are required for Windows to operate properly are allowed in an AppLocker rule collection. You can also edit the default rules. For information about creating the default rules for the Windows operating system, see [Create AppLocker default rules](create-applocker-default-rules.md). @@ -62,7 +62,7 @@ For information about performing this task, see: ## About selecting rules -AppLocker policies are composed of distinct rules for specific apps. These rules are grouped by collection, and they are implemented through an AppLocker policy definition. AppLocker policies are managed by using Group Policy or by using the Local Security Policy snap-in for a single computer. +AppLocker policies are composed of distinct rules for specific apps. These rules are grouped by collection, and they're implemented through an AppLocker policy definition. AppLocker policies are managed by using Group Policy or by using the Local Security Policy snap-in for a single computer. When you determine what types of rules to create for each of your business groups or organizational units (OUs), you should also determine what enforcement setting to use for each group. Certain rule types are more applicable for some apps, depending on how the apps are deployed in a specific business group. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule.md b/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule.md index 0add3ed41f..6247e45693 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule.md @@ -38,7 +38,7 @@ For info about testing an AppLocker policy to see what rules affect which files You can perform this task by using the Group Policy Management Console for an AppLocker policy in a Group Policy Object (GPO) or by using the Local Security Policy snap-in for an AppLocker policy on a local computer or in a security template. For info how to use these MMC snap-ins to administer AppLocker, see [Administer AppLocker](administer-applocker.md#bkmk-using-snapins). -These steps apply only for locally managed devices. If the device has AppLocker policies applied by using MDM or a GPO, the local policy will not override those settings. +These steps apply only for locally managed devices. If the device has AppLocker policies applied by using MDM or a GPO, the local policy won't override those settings. ## To delete a rule in an AppLocker policy @@ -72,13 +72,13 @@ To use the Set-AppLockerPolicy cmdlet, first import the AppLocker modules: PS C:\Users\Administrator> import-module AppLocker ``` -We will create a file (for example, clear.xml), place it in the same directory where we are executing our cmdlet, and add the preceding XML contents. Then run the following command: +We'll create a file (for example, clear.xml), place it in the same directory where we're executing our cmdlet, and add the preceding XML contents. Then run the following command: ```powershell C:\Users\Administrator> Set-AppLockerPolicy -XMLPolicy .\clear.xml ``` -This will remove all AppLocker Policies on a machine and could be potentially scripted to use on multiple machines using remote execution tools with accounts with proper access. +This command will remove all AppLocker Policies on a machine and could be potentially scripted to use on multiple machines using remote execution tools with accounts with proper access. The following PowerShell commands must also be run to stop the AppLocker services and the effects of the former AppLocker policy. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/deploy-applocker-policies-by-using-the-enforce-rules-setting.md b/windows/security/threat-protection/windows-defender-application-control/applocker/deploy-applocker-policies-by-using-the-enforce-rules-setting.md index 76c4ee127a..fc69f58037 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/deploy-applocker-policies-by-using-the-enforce-rules-setting.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/deploy-applocker-policies-by-using-the-enforce-rules-setting.md @@ -41,15 +41,15 @@ For info about how to plan an AppLocker policy deployment, see [AppLocker Design ## Step 1: Retrieve the AppLocker policy -Updating an AppLocker policy that is currently enforced in your production environment can have unintended results. Using Group Policy, you can export the policy from the Group Policy Object (GPO) and then update the rule or rules by using AppLocker on your AppLocker reference or test PC. For the procedure to do this, see [Export an AppLocker policy from a GPO](export-an-applocker-policy-from-a-gpo.md) and [Import an AppLocker policy into a GPO](import-an-applocker-policy-into-a-gpo.md). For local AppLocker policies, you can update the rule or rules by using the Local Security policy snap-in (secpol.msc) on your AppLocker reference or test PC. For the procedures to do this, see [Export an AppLocker policy to an XML file](export-an-applocker-policy-to-an-xml-file.md) and [Import an AppLocker policy from another computer](import-an-applocker-policy-from-another-computer.md). +Updating an AppLocker policy that is currently enforced in your production environment can have unintended results. Using Group Policy, you can export the policy from the Group Policy Object (GPO) and then update the rule or rules by using AppLocker on your AppLocker reference or test PC. For the procedure to do these tasks, see [Export an AppLocker policy from a GPO](export-an-applocker-policy-from-a-gpo.md) and [Import an AppLocker policy into a GPO](import-an-applocker-policy-into-a-gpo.md). For local AppLocker policies, you can update the rule or rules by using the Local Security policy snap-in (secpol.msc) on your AppLocker reference or test PC. For the procedures to do this task, see [Export an AppLocker policy to an XML file](export-an-applocker-policy-to-an-xml-file.md) and [Import an AppLocker policy from another computer](import-an-applocker-policy-from-another-computer.md). ## Step 2: Alter the enforcement setting -Rule enforcement is applied only to a collection of rules, not to individual rules. AppLocker divides the rules into collections: executable files, Windows Installer files, packaged apps, scripts, and DLL files. By default, if enforcement is not configured and rules are present in a rule collection, those rules are enforced. For information about the enforcement setting, see [Understand AppLocker Enforcement Settings](understand-applocker-enforcement-settings.md). For the procedure to alter the enforcement setting, see [Configure an AppLocker policy for audit only](configure-an-applocker-policy-for-audit-only.md). +Rule enforcement is applied only to a collection of rules, not to individual rules. AppLocker divides the rules into collections: executable files, Windows Installer files, packaged apps, scripts, and DLL files. By default, if enforcement isn't configured and rules are present in a rule collection, those rules are enforced. For information about the enforcement setting, see [Understand AppLocker Enforcement Settings](understand-applocker-enforcement-settings.md). For the procedure to alter the enforcement setting, see [Configure an AppLocker policy for audit only](configure-an-applocker-policy-for-audit-only.md). ## Step 3: Update the policy -You can edit an AppLocker policy by adding, changing, or removing rules. However, you cannot specify a version for the AppLocker policy by importing additional rules. To ensure version control when modifying an AppLocker policy, use Group Policy management software that allows you to create versions of GPOs. An example of this type of software is the [Advanced Group Policy Management](https://go.microsoft.com/fwlink/p/?LinkId=145013) feature from the +You can edit an AppLocker policy by adding, changing, or removing rules. However, you can't specify a version for the AppLocker policy by importing more rules. To ensure version control when modifying an AppLocker policy, use Group Policy management software that allows you to create versions of GPOs. An example of this type of software is the [Advanced Group Policy Management](https://go.microsoft.com/fwlink/p/?LinkId=145013) feature from the Microsoft Desktop Optimization Pack. >**Caution:**  You should not edit an AppLocker rule collection while it is being enforced in Group Policy. Because AppLocker controls what files are allowed to run, making changes to a live policy can create unexpected behavior. @@ -60,9 +60,9 @@ For the procedures to distribute policies for local PCs by using the Local Secur ## Step 4: Monitor the effect of the policy -When a policy is deployed, it is important to monitor the actual implementation of that policy. You can do this by monitoring your support organization's app access request activity and reviewing the AppLocker event logs. To monitor the effect of the policy, see [Monitor Application Usage with AppLocker](monitor-application-usage-with-applocker.md). +When a policy is deployed, it's important to monitor the actual implementation of that policy by monitoring your support organization's app access request activity and reviewing the AppLocker event logs. To monitor the effect of the policy, see [Monitor Application Usage with AppLocker](monitor-application-usage-with-applocker.md). -## Additional resources +## Other resources - For steps to perform other AppLocker policy tasks, see [Administer AppLocker](administer-applocker.md). diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-group-policy-structure-and-rule-enforcement.md b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-group-policy-structure-and-rule-enforcement.md index 2d9fdbe7c2..13836e63df 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-group-policy-structure-and-rule-enforcement.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-group-policy-structure-and-rule-enforcement.md @@ -1,6 +1,6 @@ --- title: Determine the Group Policy structure and rule enforcement (Windows) -description: This overview topic describes the process to follow when you are planning to deploy AppLocker rules. +description: This overview topic describes the process to follow when you're planning to deploy AppLocker rules. ms.assetid: f435fcbe-c7ac-4ef0-9702-729aab64163f ms.reviewer: ms.author: dansimp @@ -29,7 +29,7 @@ ms.technology: windows-sec >[!NOTE] >Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](/windows/security/threat-protection/windows-defender-application-control/feature-availability). -This overview topic describes the process to follow when you are planning to deploy AppLocker rules. +This overview topic describes the process to follow when you're planning to deploy AppLocker rules. ## In this section @@ -39,10 +39,10 @@ This overview topic describes the process to follow when you are planning to dep | [Understand AppLocker rules and enforcement setting inheritance in Group Policy](understand-applocker-rules-and-enforcement-setting-inheritance-in-group-policy.md) | This topic for the IT professional describes how application control policies configured in AppLocker are applied through Group Policy.| | [Document the Group Policy structure and AppLocker rule enforcement](document-group-policy-structure-and-applocker-rule-enforcement.md) | This planning topic describes what you need to investigate, determine, and record in your application control policies plan when you use AppLocker. | -When you are determining how many Group Policy Objects (GPOs) to create when you apply an AppLocker policy in your organization, you should consider the following: +When you're determining how many Group Policy Objects (GPOs) to create when you apply an AppLocker policy in your organization, you should consider the following points: -- Whether you are creating new GPOs or using existing GPOs -- Whether you are implementing Software Restriction Policies (SRP) policies and AppLocker policies in the same GPO +- Whether you're creating new GPOs or using existing GPOs +- Whether you're implementing Software Restriction Policies (SRP) policies and AppLocker policies in the same GPO - GPO naming conventions - GPO size limits diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-which-applications-are-digitally-signed-on-a-reference-computer.md b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-which-applications-are-digitally-signed-on-a-reference-computer.md index 656ab2805e..e8313de0e1 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-which-applications-are-digitally-signed-on-a-reference-computer.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-which-applications-are-digitally-signed-on-a-reference-computer.md @@ -31,14 +31,14 @@ ms.technology: windows-sec This topic for the IT professional describes how to use AppLocker logs and tools to determine which applications are digitally signed. -The Windows PowerShell cmdlet **Get-AppLockerFileInformation** can be used to determine which apps installed on your reference devices are digitally signed. Perform the following steps on each reference computer that you used to define the AppLocker policy. The device does not need to be joined to the domain. +The Windows PowerShell cmdlet **Get-AppLockerFileInformation** can be used to determine which apps installed on your reference devices are digitally signed. Perform the following steps on each reference computer that you used to define the AppLocker policy. The device doesn't need to be joined to the domain. Membership in the local **Administrators** group, or equivalent, is the minimum required to complete this procedure. **To determine which apps are digitally signed on a reference device** 1. Run **Get-AppLockerFileInformation** with the appropriate parameters. - The **Get-AppLockerFileInformation** cmdlet retrieves the AppLocker file information from a list of files or from an event log. File information that is retrieved can include publisher information, file hash information, and file path information. File information from an event log may not contain all of these fields. Files that are not signed do not have any publisher information. + The **Get-AppLockerFileInformation** cmdlet retrieves the AppLocker file information from a list of files or from an event log. File information that is retrieved can include publisher information, file hash information, and file path information. File information from an event log may not contain all of these fields. Files that aren't signed don't have any publisher information. 2. Analyze the publisher's name and digital signature status from the output of the command. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md index bb43e3b175..395698f788 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md @@ -43,17 +43,17 @@ Use the following table to develop your own objectives and determine which appli |Policy creation|SRP policies are maintained through Group Policy and only the administrator of the GPO can update the SRP policy. The administrator on the local computer can modify the SRP policies defined in the local GPO.|AppLocker policies are maintained through Group Policy and only the administrator of the GPO can update the policy. The administrator on the local computer can modify the AppLocker policies defined in the local GPO.

AppLocker permits customization of error messages to direct users to a Web page for help.| |Policy maintenance|SRP policies must be updated by using the Local Security Policy snap-in (if the policies are created locally) or the Group Policy Management Console (GPMC).|AppLocker policies can be updated by using the Local Security Policy snap-in, if the policies are created locally, or the GPMC, or the Windows PowerShell AppLocker cmdlets.| |Policy application|SRP policies are distributed through Group Policy.|AppLocker policies are distributed through Group Policy.| -|Enforcement mode|SRP works in the “deny list mode” where administrators can create rules for files that they don't want to allow in this Enterprise, but the rest of the files are allowed to run by default.

SRP can also be configured in the “allow list mode” such that by default all files are blocked and administrators need to create allow rules for files that they want to allow.|By default, AppLocker works in allow list mode. Only those files are allowed to run for which there's a matching allow rule.| -|File types that can be controlled|SRP can control the following file types:
  • Executables
  • DLLs
  • Scripts
  • Windows Installers

    SRP cannot control each file type separately. All SRP rules are in a single rule collection.|AppLocker can control the following file types:
  • Executables
  • DLLs
  • Scripts
  • Windows Installers
  • Packaged apps and installers

    AppLocker maintains a separate rule collection for each of the five file types.| -|Designated file types|SRP supports an extensible list of file types that are considered executable. You can add extensions for files that should be considered executable.|AppLocker doesn't support this. AppLocker currently supports the following file extensions:
  • Executables (.exe, .com)
  • DLLs (.ocx, .dll)
  • Scripts (.vbs, .js, .ps1, .cmd, .bat)
  • Windows Installers (.msi, .mst, .msp)
  • Packaged app installers (.appx)| +|Enforcement mode|SRP works in the “blocklist mode” where administrators can create rules for files that they don't want to allow in this Enterprise, but the rest of the files are allowed to run by default.

    SRP can also be configured in the “allowlist mode” such that by default all files are blocked and administrators need to create allow rules for files that they want to allow.|By default, AppLocker works in allowlist mode. Only those files are allowed to run for which there's a matching allow rule.| +|File types that can be controlled|SRP can control the following file types:
  • Executables
  • DLLs
  • Scripts
  • Windows Installers

    SRP can't control each file type separately. All SRP rules are in a single rule collection.|AppLocker can control the following file types:
  • Executables
  • DLLs
  • Scripts
  • Windows Installers
  • Packaged apps and installers

    AppLocker maintains a separate rule collection for each of the five file types.| +|Designated file types|SRP supports an extensible list of file types that are considered executable. You can add extensions for files that should be considered executable.|AppLocker doesn't support this addition of extension. AppLocker currently supports the following file extensions:
  • Executables (.exe, .com)
  • DLLs (.ocx, .dll)
  • Scripts (.vbs, .js, .ps1, .cmd, .bat)
  • Windows Installers (.msi, .mst, .msp)
  • Packaged app installers (.appx)| |Rule types|SRP supports four types of rules:
  • Hash
  • Path
  • Signature

    Internet zone|AppLocker supports three types of rules:
  • Hash
  • Path
  • Publisher| |Editing the hash value|SRP allows you to select a file to hash.|AppLocker computes the hash value itself. Internally it uses the SHA2 Authenticode hash for Portable Executables (exe and DLL) and Windows Installers and an SHA2 flat file hash for the rest.| -|Support for different security levels|With SRP, you can specify the permissions with which an app can run. Then configure a rule such that Notepad always runs with restricted permissions and never with administrative privileges.

    SRP on Windows Vista and earlier supported multiple security levels. On Windows 7, that list was restricted to just two levels: Disallowed and Unrestricted (Basic User translates to Disallowed).|AppLocker does not support security levels.| +|Support for different security levels|With SRP, you can specify the permissions with which an app can run. Then configure a rule such that Notepad always runs with restricted permissions and never with administrative privileges.

    SRP on Windows Vista and earlier supported multiple security levels. On Windows 7, that list was restricted to just two levels: Disallowed and Unrestricted (Basic User translates to Disallowed).|AppLocker doesn't support security levels.| |Manage Packaged apps and Packaged app installers.|Unable|.appx is a valid file type which AppLocker can manage.| |Targeting a rule to a user or a group of users|SRP rules apply to all users on a particular computer.|AppLocker rules can be targeted to a specific user or a group of users.| -|Support for rule exceptions|SRP does not support rule exceptions|AppLocker rules can have exceptions that allow administrators to create rules such as “Allow everything from Windows except for Regedit.exe”.| -|Support for audit mode|SRP doesn't support audit mode. The only way to test SRP policies is to set up a test environment and run a few experiments.|AppLocker supports audit mode that allows administrators to test the effect of their policy in the real production environment without impacting the user experience. Once you are satisfied with the results, you can start enforcing the policy.| -|Support for exporting and importing policies|SRP does not support policy import/export.|AppLocker supports the importing and exporting of policies. This allows you to create AppLocker policy on a sample computer, test it out and then export that policy and import it back into the desired GPO.| +|Support for rule exceptions|SRP doesn't support rule exceptions|AppLocker rules can have exceptions that allow administrators to create rules such as “Allow everything from Windows except for Regedit.exe”.| +|Support for audit mode|SRP doesn't support audit mode. The only way to test SRP policies is to set up a test environment and run a few experiments.|AppLocker supports audit mode that allows administrators to test the effect of their policy in the real production environment without impacting the user experience. Once you're satisfied with the results, you can start enforcing the policy.| +|Support for exporting and importing policies|SRP doesn't support policy import/export.|AppLocker supports the importing and exporting of policies. This support by AppLocker allows you to create AppLocker policy on a sample computer, test it out and then export that policy and import it back into the desired GPO.| |Rule enforcement|Internally, SRP rules enforcement happens in user-mode, which is less secure.|Internally, AppLocker rules for exes and dlls are enforced in kernel-mode, which is more secure than enforcing them in the user-mode.| For more general info, see AppLocker. diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/display-a-custom-url-message-when-users-try-to-run-a-blocked-application.md b/windows/security/threat-protection/windows-defender-application-control/applocker/display-a-custom-url-message-when-users-try-to-run-a-blocked-application.md index 596ca4a50f..542a15ced2 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/display-a-custom-url-message-when-users-try-to-run-a-blocked-application.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/display-a-custom-url-message-when-users-try-to-run-a-blocked-application.md @@ -31,7 +31,7 @@ ms.technology: windows-sec This topic for IT professionals describes the steps for displaying a customized message to users when an AppLocker policy denies access to an app. -Using Group Policy, AppLocker can be configured to display a message with a custom URL. You can use this URL to redirect users to a support site that contains info about why the user received the error and which apps are allowed. If you do not display a custom message when an apps is blocked, the default access denied message is displayed. +With the help of Group Policy, AppLocker can be configured to display a message with a custom URL. You can use this URL to redirect users to a support site that contains info about why the user received the error and which apps are allowed. If you don't display a custom message when an app is blocked, the default access denied message is displayed. To complete this procedure, you must have the **Edit Setting** permission to edit a GPO. By default, members of the **Domain Admins** group, the **Enterprise Admins** group, and the **Group Policy Creator Owners** group have this permission. From ce56a2f15015e07bf35cd05ce3299340d16e759a Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Mon, 4 Jul 2022 17:49:31 +0530 Subject: [PATCH 011/109] Acrolinx Enhancement effort --- .../configure-wdac-managed-installer.md | 2 +- ...or-windows-defender-application-control.md | 10 ++--- .../create-initial-default-policy.md | 8 ++-- ...e-wdac-policy-for-fully-managed-devices.md | 18 ++++----- ...wdac-policy-for-lightly-managed-devices.md | 18 ++++----- ...rt-windows-defender-application-control.md | 38 +++++++++---------- ...s-defender-application-control-policies.md | 12 +++--- ...plication-control-policies-using-intune.md | 12 +++--- .../deploy-wdac-policies-with-memcm.md | 2 +- ...s-defender-application-control-policies.md | 8 ++-- .../event-id-explanations.md | 2 +- ...th-windows-defender-application-control.md | 16 ++++---- .../microsoft-recommended-block-rules.md | 8 ++-- ...icrosoft-recommended-driver-block-rules.md | 4 +- ...defender-application-control-management.md | 18 ++++----- .../select-types-of-rules-to-create.md | 18 ++++----- .../types-of-devices.md | 14 +++---- ...ication-control-policy-design-decisions.md | 14 +++---- ...ontrol-for-classic-windows-applications.md | 20 +++++----- ...r-application-control-against-tampering.md | 12 +++--- ...l-specific-plug-ins-add-ins-and-modules.md | 4 +- ...tion-control-with-dynamic-code-security.md | 6 +-- ...control-with-intelligent-security-graph.md | 12 +++--- .../wdac-and-applocker-overview.md | 12 +++--- .../wdac-wizard-create-base-policy.md | 22 +++++------ 25 files changed, 155 insertions(+), 155 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/configure-wdac-managed-installer.md b/windows/security/threat-protection/windows-defender-application-control/configure-wdac-managed-installer.md index 92f944b419..70a4c7cad7 100644 --- a/windows/security/threat-protection/windows-defender-application-control/configure-wdac-managed-installer.md +++ b/windows/security/threat-protection/windows-defender-application-control/configure-wdac-managed-installer.md @@ -31,7 +31,7 @@ ms.technology: windows-sec ## Using fsutil to query SmartLocker EA -Customers using Windows Defender Application Control (WDAC) with Managed Installer (MI) or Intelligent Security Graph enabled can use fsutil to determine whether a file was allowed to run by one of these features. This can be achieved by querying the EAs on a file using fsutil and looking for the KERNEL.SMARTLOCKER.ORIGINCLAIM EA. The presence of this EA indicates that either MI or ISG allowed the file to run. This can be used in conjunction with enabling the MI and ISG logging events. +Customers using Windows Defender Application Control (WDAC) with Managed Installer (MI) or Intelligent Security Graph enabled can use fsutil to determine whether a file was allowed to run by one of these features. This verification can be done by querying the EAs on a file using fsutil and looking for the KERNEL.SMARTLOCKER.ORIGINCLAIM EA. The presence of this EA indicates that either MI or ISG allowed the file to run. This EA's presence can be used in conjunction with enabling the MI and ISG logging events. **Example:** diff --git a/windows/security/threat-protection/windows-defender-application-control/create-code-signing-cert-for-windows-defender-application-control.md b/windows/security/threat-protection/windows-defender-application-control/create-code-signing-cert-for-windows-defender-application-control.md index 26a241db0e..f983d739b8 100644 --- a/windows/security/threat-protection/windows-defender-application-control/create-code-signing-cert-for-windows-defender-application-control.md +++ b/windows/security/threat-protection/windows-defender-application-control/create-code-signing-cert-for-windows-defender-application-control.md @@ -1,6 +1,6 @@ --- title: Create a code signing cert for Windows Defender Application Control (Windows) -description: Learn how to set up a publicly-issued code signing certificate, so you can sign catalog files or WDAC policies internally. +description: Learn how to set up a publicly issued code signing certificate, so you can sign catalog files or WDAC policies internally. keywords: security, malware ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb ms.prod: m365-security @@ -29,11 +29,11 @@ ms.technology: windows-sec >[!NOTE] >Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -As you deploy Windows Defender Application Control (WDAC), you might need to sign catalog files or WDAC policies internally. To do this, you will either need a publicly issued code signing certificate or an internal CA. If you have purchased a code signing certificate, you can skip this topic and instead follow other topics listed in the [Windows Defender Application Control Deployment Guide](windows-defender-application-control-deployment-guide.md). +As you deploy Windows Defender Application Control (WDAC), you might need to sign catalog files or WDAC policies internally. To do this signature, you'll either need a publicly issued code signing certificate or an internal CA. If you've purchased a code-signing certificate, you can skip this topic and instead follow other topics listed in the [Windows Defender Application Control Deployment Guide](windows-defender-application-control-deployment-guide.md). If you have an internal CA, complete these steps to create a code signing certificate. Only RSA algorithm is supported for the code signing certificate, and signatures must be PKCS 1.5 padded. -ECDSA is not supported. +ECDSA isn't supported. 1. Open the Certification Authority Microsoft Management Console (MMC) snap-in, and then select your issuing CA. @@ -75,7 +75,7 @@ When this certificate template has been created, you must publish it to the CA p Figure 3. Select the new certificate template to issue - A list of available templates to issue appears, including the template you just created. + A list of available templates to issue appears, including the template you created. 2. Select the WDAC Catalog signing certificate, and then click **OK**. @@ -100,7 +100,7 @@ Now that the template is available to be issued, you must request one from the c >[!NOTE] >If a certificate manager is required to approve any issued certificates and you selected to require management approval on the template, the request will need to be approved in the CA before it will be issued to the client. -This certificate must be installed in the user's personal store on the computer that will be signing the catalog files and code integrity policies. If the signing is going to be taking place on the computer on which you just requested the certificate, exporting the certificate to a .pfx file will not be required because it already exists in your personal store. If you are signing on another computer, you will need to export the .pfx certificate with the necessary keys and properties. To do so, complete the following steps: +This certificate must be installed in the user's personal store on the computer that will be signing the catalog files and code integrity policies. If the signing is going to be taking place on the computer on which you just requested the certificate, exporting the certificate to a .pfx file won't be required because it already exists in your personal store. If you're signing on another computer, you'll need to export the .pfx certificate with the necessary keys and properties. To do so, complete the following steps: 1. Right-click the certificate, point to **All Tasks**, and then click **Export**. diff --git a/windows/security/threat-protection/windows-defender-application-control/create-initial-default-policy.md b/windows/security/threat-protection/windows-defender-application-control/create-initial-default-policy.md index 3686f2ecb5..2d31e8f0f7 100644 --- a/windows/security/threat-protection/windows-defender-application-control/create-initial-default-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/create-initial-default-policy.md @@ -37,7 +37,7 @@ The policy file is converted to binary format when it gets created so that Windo ## Overview of the process of creating Windows Defender Application Control policies -A common system imaging practice in today’s IT organization is to establish a “golden” image as a reference for what an ideal system should look like, and then use that image to clone additional company assets. Windows Defender Application Control policies follow a similar methodology, that begins with the establishment of a golden computer. As with imaging, you can have multiple golden computers based on model, department, application set, and so on. Although the thought process around the creation of WDAC policies is similar to imaging, these policies should be maintained independently. Assess the necessity of additional WDAC policies based on what should be allowed to be installed and run and for whom. For more details on doing this assessment, see the [WDAC Design Guide](windows-defender-application-control-design-guide.md). +A common system imaging practice in today’s IT organization is to establish a “golden” image as a reference for what an ideal system should look like, and then use that image to clone more company assets. Windows Defender Application Control policies follow a similar methodology that begins with the establishment of a golden computer. As with imaging, you can have multiple golden computers based on model, department, application set, and so on. Although the thought process around the creation of WDAC policies is similar to imaging, these policies should be maintained independently. Assess the necessity of more WDAC policies based on what should be allowed to be installed and run and for whom. For more information on doing this assessment, see the [WDAC Design Guide](windows-defender-application-control-design-guide.md). Optionally, WDAC can align with your software catalog and any IT department–approved applications. One straightforward method to implement WDAC is to use existing images to create one master WDAC policy. You do so by creating a WDAC policy from each image, and then by merging the policies. This way, what is installed on all of those images will be allowed to run, if the applications are installed on a computer based on a different image. Alternatively, you may choose to create a base applications policy and add policies based on the computer’s role or department. Organizations have a choice of how their policies are created, merged, or serviced, and managed. @@ -48,12 +48,12 @@ If you plan to use an internal CA to sign catalog files or WDAC policies, see th Each installed software application should be validated as trustworthy before you create a policy. We recommend that you review the reference computer for software that can load arbitrary DLLs and run code or scripts that could render the PC more vulnerable. -Examples include software aimed at development or scripting such as msbuild.exe (part of Visual Studio and the .NET Framework) which can be removed if you do not want to run scripts. +Examples include software aimed at development or scripting such as msbuild.exe (part of Visual Studio and the .NET Framework) which can be removed if you don't want to run scripts. You can remove or disable such software on the reference computer. To create a Windows Defender Application Control policy, copy each of the following commands into an elevated Windows PowerShell session, in order: -1. Initialize variables that you will use. +1. Initialize variables that you'll use. ```powershell $PolicyPath=$env:userprofile+"\Desktop\" @@ -83,7 +83,7 @@ To create a Windows Defender Application Control policy, copy each of the follow ConvertFrom-CIPolicy $WDACPolicy $WDACPolicyBin ``` -After you complete these steps, the WDAC binary file ($WDACPolicyBin) and original .xml file ($WDACPolicy) will be available on your desktop. You can use the binary file as a WDAC policy or sign it for additional security. +After you complete these steps, the WDAC binary file ($WDACPolicyBin) and original .xml file ($WDACPolicy) will be available on your desktop. You can use the binary file as a WDAC policy or sign it for more security. > [!NOTE] > We recommend that you keep the original .xml file of the policy for use when you need to merge the WDAC policy with another policy or update its rule options. Alternatively, you would have to create a new policy from a new scan for servicing. For more information about how to merge WDAC policies, see [Merge Windows Defender Application Control policies](merge-windows-defender-application-control-policies.md). diff --git a/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-fully-managed-devices.md b/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-fully-managed-devices.md index c0296ea8e6..7cd08be428 100644 --- a/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-fully-managed-devices.md +++ b/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-fully-managed-devices.md @@ -30,16 +30,16 @@ ms.technology: windows-sec >[!NOTE] >Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -This section outlines the process to create a Windows Defender Application Control (WDAC) policy for **fully managed devices** within an organization. The key difference between this scenario and [lightly managed devices](create-wdac-policy-for-lightly-managed-devices.md) is that all software deployed to a fully managed device is managed by IT and users of the device cannot install arbitrary apps. Ideally, all apps are deployed using a software distribution solution, such as Microsoft Endpoint Manager. Additionally, users on fully managed devices should ideally run as standard user and only authorized IT pros have administrative access. +This section outlines the process to create a Windows Defender Application Control (WDAC) policy for **fully managed devices** within an organization. The key difference between this scenario and [lightly managed devices](create-wdac-policy-for-lightly-managed-devices.md) is that all software deployed to a fully managed device is managed by IT and users of the device can't install arbitrary apps. Ideally, all apps are deployed using a software distribution solution, such as Microsoft Endpoint Manager. Additionally, users on fully managed devices should ideally run as standard user and only authorized IT pros have administrative access. > [!NOTE] > Some of the Windows Defender Application Control options described in this topic are only available on Windows 10 version 1903 and above, or Windows 11. When using this topic to plan your own organization's WDAC policies, consider whether your managed clients can use all or some of these features and assess the impact for any features that may be unavailable on your clients. You may need to adapt this guidance to meet your specific organization's needs. -As described in [common Windows Defender Application Control deployment scenarios](types-of-devices.md), we will use the example of **Lamna Healthcare Company (Lamna)** to illustrate this scenario. Lamna is attempting to adopt stronger application policies, including the use of application control to prevent unwanted or unauthorized applications from running on their managed devices. +As described in [common Windows Defender Application Control deployment scenarios](types-of-devices.md), we'll use the example of **Lamna Healthcare Company (Lamna)** to illustrate this scenario. Lamna is attempting to adopt stronger application policies, including the use of application control to prevent unwanted or unauthorized applications from running on their managed devices. **Alice Pena** is the IT team lead tasked with the rollout of WDAC. -Alice previously created a policy for the organization's lightly managed devices. Some devices, however, are more tightly managed and can benefit from a more constrained policy. In particular, certain job functions such as administrative staff and firstline workers are not granted administrator level access to their devices. Similarly, shared kiosks are configured only with a managed set of apps and all users of the device except IT run as standard user. On these devices, all apps are deployed and installed by IT. +Alice previously created a policy for the organization's lightly managed devices. Some devices, however, are more tightly managed and can benefit from a more constrained policy. In particular, certain job functions such as administrative staff and firstline workers aren't granted administrator level access to their devices. Similarly, shared kiosks are configured only with a managed set of apps and all users of the device except IT run as standard user. On these devices, all apps are deployed and installed by IT. ## Define the "circle-of-trust" for fully managed devices @@ -51,26 +51,26 @@ Alice identifies the following key factors to arrive at the "circle-of-trust" fo - Sometimes, IT staff install apps directly to these devices without using Configuration Manager; - All users except IT are standard users on these devices. -Alice's team develops a simple console application, called *LamnaITInstaller.exe*, which will become the authorized way for IT staff to install apps directly to devices. *LamnaITInstaller.exe* allows the IT pro to launch another process, such as an app installer. Alice will configure *LamnaITInstaller.exe* as an additional managed installer for WDAC and allows her to remove the need for filepath rules. +Alice's team develops a simple console application, called *LamnaITInstaller.exe*, which will become the authorized way for IT staff to install apps directly to devices. *LamnaITInstaller.exe* allows the IT pro to launch another process, such as an app installer. Alice will configure *LamnaITInstaller.exe* as an extra managed installer for WDAC and allows her to remove the need for filepath rules. Based on the above, Alice defines the pseudo-rules for the policy: 1. **“Windows works”** rules that authorize: - Windows - - WHQL (3rd party kernel drivers) + - WHQL (third-party kernel drivers) - Windows Store signed apps 2. **"MEMCM works”** rules that include signer and hash rules for Configuration Manager components to properly function. 3. **Allow Managed Installer** (Configuration Manager and *LamnaITInstaller.exe* configured as a managed installer) -The critical differences between this set of pseudo-rules and those defined for Lamna's [lightly managed devices](create-wdac-policy-for-lightly-managed-devices.md#define-the-circle-of-trust-for-lightly-managed-devices) are: +The critical differences between this set of pseudo-rules and those pseudo-rules defined for Lamna's [lightly managed devices](create-wdac-policy-for-lightly-managed-devices.md#define-the-circle-of-trust-for-lightly-managed-devices) are: - Removal of the Intelligent Security Graph (ISG) option; and - Removal of filepath rules. ## Create a custom base policy using an example WDAC base policy -Having defined the "circle-of-trust", Alice is ready to generate the initial policy for Lamna's fully-managed devices. She decides to use Configuration Manager to create the initial base policy and then customize it to meet Lamna's needs. +Having defined the "circle-of-trust", Alice is ready to generate the initial policy for Lamna's fully managed devices and decides to use Configuration Manager to create the initial base policy and then customize it to meet Lamna's needs. Alice follows these steps to complete this task: @@ -113,7 +113,7 @@ Alice follows these steps to complete this task: Set-RuleOption -FilePath $LamnaPolicy -Option 19 # Dynamic Code Security ``` -6. If appropriate, add additional signer or file rules to further customize the policy for your organization. +6. If appropriate, add more signer or file rules to further customize the policy for your organization. 7. Use [ConvertFrom-CIPolicy](/powershell/module/configci/convertfrom-cipolicy) to convert the Windows Defender Application Control policy to a binary format: @@ -134,7 +134,7 @@ At this point, Alice now has an initial policy that is ready to deploy in audit Alice has defined a policy for Lamna's fully managed devices that makes some trade-offs between security and manageability for apps. Some of the trade-offs include: - **Users with administrative access**
    - Although applying to fewer users, Lamna still allows some IT staff to log in to its fully managed devices as administrator. This allows these admin users (or malware running with the user's privileges) to modify or remove altogether the WDAC policy applied on the device. Additionally, administrators can configure any app they wish to operate as a managed installer that would allow them to gain persistent app authorization for whatever apps or binaries they wish. + Although applying to fewer users, Lamna still allows some IT staff to sign in to its fully managed devices as administrator. This privilege allows these users (or malware running with the user's privileges) to modify or remove altogether the WDAC policy applied on the device. Additionally, administrators can configure any app they wish to operate as a managed installer that would allow them to gain persistent app authorization for whatever apps or binaries they wish. Possible mitigations: - Use signed WDAC policies and UEFI BIOS access protection to prevent tampering of WDAC policies. diff --git a/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-lightly-managed-devices.md b/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-lightly-managed-devices.md index d03bb18a75..9cb8de44f4 100644 --- a/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-lightly-managed-devices.md +++ b/windows/security/threat-protection/windows-defender-application-control/create-wdac-policy-for-lightly-managed-devices.md @@ -35,11 +35,11 @@ This section outlines the process to create a Windows Defender Application Contr > [!NOTE] > Some of the Windows Defender Application Control options described in this topic are only available on Windows 10 version 1903 and above, or Windows 11. When using this topic to plan your own organization's WDAC policies, consider whether your managed clients can use all or some of these features and assess the impact for any features that may be unavailable on your clients. You may need to adapt this guidance to meet your specific organization's needs. -As in the [previous topic](types-of-devices.md), we will use the example of **Lamna Healthcare Company (Lamna)** to illustrate this scenario. Lamna is attempting to adopt stronger application policies, including the use of application control to prevent unwanted or unauthorized applications from running on their managed devices. +As in the [previous topic](types-of-devices.md), we'll use the example of **Lamna Healthcare Company (Lamna)** to illustrate this scenario. Lamna is attempting to adopt stronger application policies, including the use of application control to prevent unwanted or unauthorized applications from running on their managed devices. -**Alice Pena** is the IT team lead tasked with the rollout of WDAC. Recognizing where Lamna is starting from, with loose application usage policies and a culture of maximum app flexibility for users, Alice knows that she will need to take an incremental approach to application control and use different policies for different workloads. +**Alice Pena** is the IT team lead tasked with the rollout of WDAC. Recognizing where Lamna is starting from, with loose application usage policies and a culture of maximum app flexibility for users, Alice knows that she'll need to take an incremental approach to application control and use different policies for different workloads. -For the majority of users and devices, Alice wants to create an initial policy that is as relaxed as possible in order to minimize user productivity impact, while still providing security value. +For most users and devices, Alice wants to create an initial policy that is as relaxed as possible in order to minimize user productivity impact, while still providing security value. ## Define the "circle-of-trust" for lightly managed devices @@ -49,16 +49,16 @@ Alice identifies the following key factors to arrive at the "circle-of-trust" fo - All clients are managed by Microsoft Endpoint Manager either with Configuration Manager or with Intune. - Some, but not all, apps are deployed using Configuration Manager; - Most users are local administrators on their devices; -- Some teams may need additional rules to authorize specific apps that don't apply generally to all other users. +- Some teams may need more rules to authorize specific apps that don't apply generally to all other users. Based on the above, Alice defines the pseudo-rules for the policy: 1. **“Windows works”** rules that authorize: - Windows - - WHQL (3rd party kernel drivers) + - WHQL (third-party kernel drivers) - Windows Store signed apps -2. **"MEMCM works”** rules which include signer and hash rules for Configuration Manager components to properly function. +2. **"MEMCM works”** rules that include signer and hash rules for Configuration Manager components to properly function. 3. **Allow Managed Installer** (Configuration Manager configured as a managed installer) 4. **Allow Intelligent Security Graph (ISG)** (reputation-based authorization) 5. **Admin-only path rules** for the following locations: @@ -68,7 +68,7 @@ Based on the above, Alice defines the pseudo-rules for the policy: ## Create a custom base policy using an example WDAC base policy -Having defined the "circle-of-trust", Alice is ready to generate the initial policy for Lamna's lightly managed devices. She decides to use Configuration Manager to create the initial base policy and then customize it to meet Lamna's needs. +Having defined the "circle-of-trust", Alice is ready to generate the initial policy for Lamna's lightly managed devices. Alice decides to use Configuration Manager to create the initial base policy and then customize it to meet Lamna's needs. Alice follows these steps to complete this task: @@ -121,7 +121,7 @@ Alice follows these steps to complete this task: Merge-CIPolicy -OutputFilePath $LamnaPolicy -PolicyPaths $LamnaPolicy -Rules $PathRules ``` -7. If appropriate, add additional signer or file rules to further customize the policy for your organization. +7. If appropriate, add more signer or file rules to further customize the policy for your organization. 8. Use [ConvertFrom-CIPolicy](/powershell/module/configci/convertfrom-cipolicy) to convert the WDAC policy to a binary format: @@ -142,7 +142,7 @@ At this point, Alice now has an initial policy that is ready to deploy in audit In order to minimize user productivity impact, Alice has defined a policy that makes several trade-offs between security and user app flexibility. Some of the trade-offs include: - **Users with administrative access**
    - By far the most impactful security trade-off, this allows the device user (or malware running with the user's privileges) to modify or remove altogether the WDAC policy applied on the device. Additionally, administrators can configure any app they wish to operate as a managed installer that would allow them to gain persistent app authorization for whatever apps or binaries they wish. + By far the most impactful security trade-off, this trade-off allows the device user (or malware running with the user's privileges) to modify or remove altogether the WDAC policy applied on the device. Additionally, administrators can configure any app they wish to operate as a managed installer that would allow them to gain persistent app authorization for whatever apps or binaries they wish. Possible mitigations: - Use signed WDAC policies and UEFI BIOS access protection to prevent tampering of WDAC policies. diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-catalog-files-to-support-windows-defender-application-control.md b/windows/security/threat-protection/windows-defender-application-control/deploy-catalog-files-to-support-windows-defender-application-control.md index 348fbacaf2..65565ec200 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deploy-catalog-files-to-support-windows-defender-application-control.md +++ b/windows/security/threat-protection/windows-defender-application-control/deploy-catalog-files-to-support-windows-defender-application-control.md @@ -40,9 +40,9 @@ To create a catalog file, you use a tool called **Package Inspector**. You must > [!NOTE] > When you establish a naming convention it makes it easier to detect deployed catalog files in the future. In this guide, *\*-Contoso.cat* is used as the example naming convention. -1. Be sure that a Windows Defender Application Control policy is currently deployed in audit mode on the computer on which you will run Package Inspector. +1. Be sure that a Windows Defender Application Control policy is currently deployed in audit mode on the computer on which you'll run Package Inspector. - Package Inspector does not always detect temporary installation files that are added and then removed from the computer during the installation process. To ensure that these binaries are also included in your catalog file, deploy a WDAC policy in audit mode. + Package Inspector doesn't always detect temporary installation files that are added and then removed from the computer during the installation process. To ensure that these binaries are also included in your catalog file, deploy a WDAC policy in audit mode. > [!NOTE] > This process should **not** be performed on a system with an enforced Windows Defender Application Control policy, only with a policy in audit mode. If a policy is currently being enforced, you will not be able to install and run the application unless the policy already allows it. @@ -58,7 +58,7 @@ To create a catalog file, you use a tool called **Package Inspector**. You must By copying the installation media to the local drive, you ensure that Package Inspector detects and catalogs the actual installer. If you skip this step, the future WDAC policy may allow the application to run but not to be installed. -4. Install the application. Install it to the same drive that the application installer is located on (the drive you are scanning). Also, while Package Inspector is running, do not run any installations or updates that you don't want to capture in the catalog. +4. Install the application. Install it to the same drive that the application installer is located on (the drive you're scanning). Also, while Package Inspector is running, don't run any installations or updates that you don't want to capture in the catalog. > [!IMPORTANT] > Every binary that is run while Package Inspector is running will be captured in the catalog. Ensure that only trusted applications are run during this time. @@ -71,9 +71,9 @@ To create a catalog file, you use a tool called **Package Inspector**. You must This step is necessary to ensure that the scan has captured all binaries. -8. As appropriate, with Package Inspector still running, repeat the process for another application that you want in the catalog. Copy the installation media to the local drive, install the application, ensure it is updated, and then close and reopen the application. +8. As appropriate, with Package Inspector still running, repeat the process for another application that you want in the catalog. Copy the installation media to the local drive, install the application, ensure it's updated, and then close and reopen the application. -9. When you have confirmed that the previous steps are complete, use the following commands to generate the catalog and definition files on your computer's desktop. The filenames used in these example commands are **LOBApp-Contoso.cat** (catalog file) and **LOBApp.cdf** (definition file)—substitute different filenames as appropriate. +9. When you've confirmed that the previous steps are complete, use the following commands to generate the catalog and definition files on your computer's desktop. The filenames used in these example commands are **LOBApp-Contoso.cat** (catalog file) and **LOBApp.cdf** (definition file)—substitute different filenames as appropriate. For the last command, which stops Package Inspector, be sure to type the drive letter of the drive you have been scanning, for example, C:. @@ -98,22 +98,22 @@ Packages can fail for the following reasons: - Package is too large for default USN Journal or Event Log sizes - To diagnose whether USN journal size is the issue, after running through Package Inspector, click Start > install app > PackageInspector stop - - Get the value of the reg key at HKEY\_CURRENT\_USER/PackageInspectorRegistryKey/c: (this was the most recent USN when you ran PackageInspector start) + - Get the value of the reg key at HKEY\_CURRENT\_USER/PackageInspectorRegistryKey/c: (this USN was the most recent one when you ran PackageInspector start) - `fsutil usn readjournal C: startusn=RegKeyValue > inspectedusn.txt` - ReadJournal command should throw an error if the older USNs don't exist anymore due to overflow - For USN Journal, log size can be expanded using: `fsutil usn createjournal` command with a new size and alloc delta. `Fsutil usn queryjournal` will give the current size and allocation delta, so using a multiple of that may help - To diagnose whether Eventlog size is the issue, look at the Microsoft/Windows/CodeIntegrity/Operational log under Applications and Services logs in Event Viewer and ensure that there are entries present from when you began Package Inspector (You can use write time as a justification; if you started the install 2 hours ago and there are only entries from 30 minutes prior, the log is definitely too small) - To increase Eventlog size, in Event Viewer you can right click the operational log, click properties, and then set new values (some multiple of what it was previously) - Package files that change hash each time the package is installed - - Package Inspector is completely incompatible if files in the package (temporary or otherwise) change hash each time the package is installed. You can diagnose this by looking at the hash field in the 3077 block events when the package is failing in enforcement. If each time you attempt to run the package you get a new block event with a different hash, the package will not work with Package Inspector + - Package Inspector is incompatible if files in the package (temporary or otherwise) change hash each time the package is installed. You can diagnose this hash-change by looking at the hash field in the 3077 block events when the package is failing in enforcement. If each time you attempt to run the package you get a new block event with a different hash, the package won't work with Package Inspector - Files with an invalid signature blob or otherwise "unhashable" files - This issue arises when a file that has been signed is modified post signing in a way that invalidates the PE header and renders the file unable to be hashed by the Authenticode Spec. - - Windows Defender Application Control uses Authenticode Hashes to validate files when they are running. If the file is unhashable via the authenticode SIP, there is no way to identify the file to allow it, regardless of if you attempt to add the file to the policy directly, or re-sign the file with a Package Inspector catalog (the signature is invalidated due to file being edited, file can't be allowed by hash due to authenticode hashing algorithm rejecting it) - - Recent versions of InstallShield packages that use custom actions can hit this. If the DLL input to the custom action was signed before being put through InstallShield, InstallShield adds tracking markers to the file (editing it post signature) which leaves the file in this "unhashable" state and renders the file unable to be allowed by Windows Defender (regardless of if you try to allow directly by policy or resign with Package Inspector) + - Windows Defender Application Control uses Authenticode Hashes to validate files when they're running. If the file is unhashable via the authenticode SIP, there's no way to identify the file to allow it, regardless of if you attempt to add the file to the policy directly, or re-sign the file with a Package Inspector catalog (the signature is invalidated due to file being edited, file can't be allowed by hash due to authenticode hashing algorithm rejecting it) + - Recent versions of InstallShield packages that use custom actions can hit this condition. If the DLL input to the custom action was signed before being put through InstallShield, InstallShield adds tracking markers to the file (editing it post signature) which leaves the file in this "unhashable" state and renders the file unable to be allowed by Windows Defender (regardless of if you try to allow directly by policy or resign with Package Inspector) ## Catalog signing with SignTool.exe -To sign a catalog file you generated by using PackageInspector.exe, you need the following: +To sign a catalog file you generated by using PackageInspector.exe, you need: - SignTool.exe, found in the Windows software development kit (SDK—Windows 7 or later) @@ -148,15 +148,15 @@ To sign the existing catalog file, copy each of the following commands into an e 5. Copy the catalog file to C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}. - For testing purposes, you can manually copy signed catalog files to their intended folder. For large-scale implementations, to copy the appropriate catalog files to all desired computers, we recommend that you use Group Policy File Preferences or an enterprise systems management product such as Microsoft Endpoint Configuration Manager. Doing this also simplifies the management of catalog versions. + For testing purposes, you can manually copy signed catalog files to their intended folder. For large-scale implementations, to copy the appropriate catalog files to all desired computers, we recommend that you use Group Policy File Preferences or an enterprise systems management product such as Microsoft Endpoint Configuration Manager, which also simplifies the management of catalog versions. ## Add a catalog signing certificate to a Windows Defender Application Control policy After the catalog file is signed, add the signing certificate to a WDAC policy, as described in the following steps. -1. If you have not already verified the catalog file digital signature, right-click the catalog file, and then click **Properties**. On the **Digital Signatures** tab, verify that your signing certificate exists with the algorithm you expect. +1. If you haven't already verified the catalog file digital signature, right-click the catalog file, and then click **Properties**. On the **Digital Signatures** tab, verify that your signing certificate exists with the algorithm you expect. -2. If you already have an XML policy file that you want to add the signing certificate to, skip to the next step. Otherwise, use [New-CIPolicy](/powershell/module/configci/new-cipolicy) to create a Windows Defender Application Control policy that you will later merge into another policy (not deploy as-is). This example creates a policy called **CatalogSignatureOnly.xml** in the location **C:\\PolicyFolder**: +2. If you already have an XML policy file that you want to add the signing certificate to, skip to the next step. Otherwise, use [New-CIPolicy](/powershell/module/configci/new-cipolicy) to create a Windows Defender Application Control policy that you'll later merge into another policy (not deploy as-is). This example creates a policy called **CatalogSignatureOnly.xml** in the location **C:\\PolicyFolder**: `New-CIPolicy -Level PcaCertificate -FilePath C:\PolicyFolder\CatalogSignatureOnly.xml –UserPEs` @@ -212,9 +212,9 @@ To simplify the management of catalog files, you can use Group Policy preference **C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\LOBApp-Contoso.cat** - For the catalog file name, use the name of the catalog you are deploying. + For the catalog file name, use the name of the catalog you're deploying. -10. On the **Common** tab of the **New File Properties** dialog box, select the **Remove this item when it is no longer applied** option. Doing this ensures that the catalog file is removed from every system, in case you ever need to stop trusting this application. +10. On the **Common** tab of the **New File Properties** dialog box, select the **Remove this item when it is no longer applied** option. Enabling this option ensures that the catalog file is removed from every system, in case you ever need to stop trusting this application. 11. Click **OK** to complete file creation. @@ -224,7 +224,7 @@ Before you begin testing the deployed catalog file, make sure that the catalog s ## Deploy catalog files with Microsoft Endpoint Configuration Manager -As an alternative to Group Policy, you can use Configuration Manager to deploy catalog files to the managed computers in your environment. This approach can simplify the deployment and management of multiple catalog files as well as provide reporting around which catalog each client or collection has deployed. In addition to the deployment of these files, Configuration Manager can also be used to inventory the currently deployed catalog files for reporting and compliance purposes. Complete the following steps to create a new deployment package for catalog files: +As an alternative to Group Policy, you can use Configuration Manager to deploy catalog files to the managed computers in your environment. This approach can simplify the deployment and management of multiple catalog files and provide reporting around which catalog each client or collection has deployed. In addition to the deployment of these files, Configuration Manager can also be used to inventory the currently deployed catalog files for reporting and compliance purposes. Complete the following steps to create a new deployment package for catalog files: >[!NOTE] >The following example uses a network share named \\\\Shares\\CatalogShare as a source for the catalog files. If you have collection specific catalog files, or prefer to deploy them individually, use whichever folder structure works best for your organization. @@ -263,7 +263,7 @@ As an alternative to Group Policy, you can use Configuration Manager to deploy c 7. Accept the defaults for the rest of the wizard, and then close the wizard. -After you create the deployment package, deploy it to a collection so that the clients will receive the catalog files. In this example, you deploy the package you just created to a test collection: +After you create the deployment package, deploy it to a collection so that the clients will receive the catalog files. In this example, you deploy the package you created to a test collection: 1. In the Software Library workspace, navigate to Overview\\Application Management\\Packages, right-click the catalog file package, and then click **Deploy**. @@ -335,9 +335,9 @@ When catalog files have been deployed to the computers within your environment, 8. Click **OK**. -9. Now that you have created the client settings policy, right-click the new policy, click **Deploy**, and then choose the collection on which you would like to inventory the catalog files. +9. Now that you've created the client settings policy, right-click the new policy, click **Deploy**, and then choose the collection on which you would like to inventory the catalog files. -At the time of the next software inventory cycle, when the targeted clients receive the new client settings policy, you will be able to view the inventoried files in the built-in Configuration Manager reports or Resource Explorer. To view the inventoried files on a client within Resource Explorer, complete the following steps: +At the time of the next software inventory cycle, when the targeted clients receive the new client settings policy, you'll be able to view the inventoried files in the built-in Configuration Manager reports or Resource Explorer. To view the inventoried files on a client within Resource Explorer, complete the following steps: 1. Open the Configuration Manager console, and select the Assets and Compliance workspace. diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md index 37126d5855..eef8622acd 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md +++ b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md @@ -29,7 +29,7 @@ ms.technology: windows-sec >[!NOTE] >Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -Prior to Windows 10 1903, Windows Defender Application Control only supported a single active policy on a system at any given time. This significantly limited customers in situations where multiple policies with different intents would be useful. Beginning with Windows 10 version 1903, WDAC supports up to 32 active policies on a device at once in order to enable the following scenarios: +Prior to Windows 10 1903, Windows Defender Application Control only supported a single active policy on a system at any given time. This limited customers in situations where multiple policies with different intents would be useful. Beginning with Windows 10 version 1903, WDAC supports up to 32 active policies on a device at once in order to enable the following scenarios: 1. Enforce and Audit Side-by-Side - To validate policy changes before deploying in enforcement mode, users can now deploy an audit-mode base policy side by side with an existing enforcement-mode base policy @@ -49,11 +49,11 @@ Prior to Windows 10 1903, Windows Defender Application Control only supported a - Multiple base policies: intersection - Only applications allowed by both policies run without generating block events - Base + supplemental policy: union - - Files that are allowed by either the base policy or the supplemental policy are not blocked + - Files that are allowed by either the base policy or the supplemental policy aren't blocked ## Creating WDAC policies in Multiple Policy Format -In order to allow multiple policies to exist and take effect on a single system, policies must be created using the new Multiple Policy Format. The "MultiplePolicyFormat" switch in [New-CIPolicy](/powershell/module/configci/new-cipolicy?preserve-view=true&view=win10-ps) results in 1) unique GUIDs being generated for the policy ID and 2) the policy type being specified as base. The below is an example of creating a new policy in the multiple policy format. +In order to allow multiple policies to exist and take effect on a single system, policies must be created using the new Multiple Policy Format. The "MultiplePolicyFormat" switch in [New-CIPolicy](/powershell/module/configci/new-cipolicy?preserve-view=true&view=win10-ps) results in 1) unique GUIDs being generated for the policy ID and 2) the policy type being specified as base. The below example describes the process of creating a new policy in the multiple policy format. ```powershell New-CIPolicy -MultiplePolicyFormat -ScanPath "" -UserPEs -FilePath ".\policy.xml" -Level Publisher -Fallback Hash @@ -87,7 +87,7 @@ Set-CIPolicyIdInfo [-FilePath] [-PolicyName ] [-SupplementsBase ### Merging policies -When merging, the policy type and ID of the leftmost/first policy specified is used. If the leftmost is a base policy with ID \, then regardless of what the GUIDs and types are for any subsequent policies, the merged policy will be a base policy with ID \. +When you're merging policies, the policy type and ID of the leftmost/first policy specified is used. If the leftmost is a base policy with ID \, then regardless of what the GUIDs and types are for any subsequent policies, the merged policy will be a base policy with ID \. ## Deploying multiple policies @@ -107,9 +107,9 @@ To deploy policies locally using the new multiple policy format, follow these st Multiple Windows Defender Application Control policies can be managed from an MDM server through ApplicationControl configuration service provider (CSP). The CSP also provides support for rebootless policy deployment.
    -However, when policies are un-enrolled from an MDM server, the CSP will attempt to remove every policy from devices, not just the policies added by the CSP. The reason for this is that the ApplicationControl CSP doesn't track enrollment sources for individual policies, even though it will query all policies on a device, regardless if they were deployed by the CSP. +However, when policies are unenrolled from an MDM server, the CSP will attempt to remove every policy from devices, not just the policies added by the CSP. The reason for this is that the ApplicationControl CSP doesn't track enrollment sources for individual policies, even though it will query all policies on a device, regardless if they were deployed by the CSP. -See [ApplicationControl CSP](/windows/client-management/mdm/applicationcontrol-csp) for more information on deploying multiple policies, optionally using Microsoft Endpoint Manager Intune's Custom OMA-URI capability. +For more information on deploying multiple policies, optionally using Microsoft Endpoint Manager Intune's Custom OMA-URI capability, see [ApplicationControl CSP](/windows/client-management/mdm/applicationcontrol-csp). > [!NOTE] > WMI and GP do not currently support multiple policies. Instead, customers who cannot directly access the MDM stack should use the [ApplicationControl CSP via the MDM Bridge WMI Provider](/windows/client-management/mdm/applicationcontrol-csp#powershell-and-wmi-bridge-usage-guidance) to manage Multiple Policy Format Windows Defender Application Control policies. diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md index 143fbdcc2e..5f1acbe65d 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md +++ b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md @@ -29,14 +29,14 @@ ms.technology: windows-sec >[!NOTE] >Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -You can use a Mobile Device Management (MDM) solution, like Microsoft Endpoint Manager Intune, to configure Windows Defender Application Control (WDAC) on client machines. Intune includes native support for WDAC which can be a helpful starting point, but customers may find the available circle-of-trust options too limiting. To deploy a custom policy through Intune and define your own circle of trust, you can configure a profile using Custom OMA-URI. If your organization uses another MDM solution, check with your solution provider for WDAC policy deployment steps. +You can use a Mobile Device Management (MDM) solution, like Microsoft Endpoint Manager Intune, to configure Windows Defender Application Control (WDAC) on client machines. Intune includes native support for WDAC, which can be a helpful starting point, but customers may find the available circle-of-trust options too limiting. To deploy a custom policy through Intune and define your own circle of trust, you can configure a profile using Custom OMA-URI. If your organization uses another MDM solution, check with your solution provider for WDAC policy deployment steps. ## Use Intune's built-in policies Intune's built-in Windows Defender Application Control support allows you to configure Windows client computers to only run: - Windows components -- 3rd party hardware and software kernel drivers +- Third-party hardware and software kernel drivers - Microsoft Store-signed apps - [Optional] Reputable apps as defined by the Intelligent Security Graph (ISG) @@ -68,7 +68,7 @@ The steps to use Intune's custom OMA-URI functionality are: 4. Specify a **Name** and **Description** and use the following values for the remaining custom OMA-URI settings: - **OMA-URI**: ./Vendor/MSFT/ApplicationControl/Policies/_Policy GUID_/Policy - **Data type**: Base64 - - **Certificate file**: upload your binary format policy file. You do not need to upload a Base64 file, as Intune will convert the uploaded .bin file to Base64 on your behalf. + - **Certificate file**: upload your binary format policy file. You don't need to upload a Base64 file, as Intune will convert the uploaded .bin file to Base64 on your behalf. > [!div class="mx-imgBorder"] > ![Configure custom WDAC.](images/wdac-intune-custom-oma-uri.png) @@ -78,13 +78,13 @@ The steps to use Intune's custom OMA-URI functionality are: ### Remove WDAC policies on Windows 10 1903+ -Upon deletion, policies deployed through Intune via the ApplicationControl CSP are removed from the system but stay in effect until the next reboot. In order to disable Windows Defender Application Control enforcement, first replace the existing policy with a new version of the policy that will "Allow *", like the rules in the example policy at %windir%\schemas\CodeIntegrity\ExamplePolicies\AllowAll.xml. Once the updated policy is deployed, you can then delete the policy from the Intune portal. This will prevent anything from being blocked and fully remove the WDAC policy on the next reboot. +Upon deletion, policies deployed through Intune via the ApplicationControl CSP are removed from the system but stay in effect until the next reboot. In order to disable Windows Defender Application Control enforcement, first replace the existing policy with a new version of the policy that will "Allow *", like the rules in the example policy at %windir%\schemas\CodeIntegrity\ExamplePolicies\AllowAll.xml. Once the updated policy is deployed, you can then delete the policy from the Intune portal. This deletion will prevent anything from being blocked and fully remove the WDAC policy on the next reboot. ### For pre-1903 systems #### Deploying policies -The steps to use Intune's Custom OMA-URI functionality to leverage the [AppLocker CSP](/windows/client-management/mdm/applocker-csp) and deploy a custom WDAC policy to pre-1903 systems are: +The steps to use Intune's Custom OMA-URI functionality to apply the [AppLocker CSP](/windows/client-management/mdm/applocker-csp) and deploy a custom WDAC policy to pre-1903 systems are: 1. Convert the policy XML to binary format using the ConvertFrom-CIPolicy cmdlet in order to be deployed. The binary policy may be signed or unsigned. @@ -100,4 +100,4 @@ The steps to use Intune's Custom OMA-URI functionality to leverage the [AppLocke #### Removing policies -Policies deployed through Intune via the AppLocker CSP cannot be deleted through the Intune console. In order to disable Windows Defender Application Control policy enforcement, either deploy an audit-mode policy or use a script to delete the existing policy. +Policies deployed through Intune via the AppLocker CSP can't be deleted through the Intune console. In order to disable Windows Defender Application Control policy enforcement, either deploy an audit-mode policy or use a script to delete the existing policy. diff --git a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md index b8f3362555..f4cd7e89bf 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md +++ b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md @@ -39,7 +39,7 @@ Microsoft Endpoint Configuration Manager includes native support for WDAC, which - [Optional] Reputable apps as defined by the Intelligent Security Graph (ISG) - [Optional] Apps and executables already installed in admin-definable folder locations that Configuration Manager will allow through a one-time scan during policy creation on managed endpoints. -Note that Configuration Manager does not remove policies once deployed. To stop enforcement, you should switch the policy to audit mode, which will produce the same effect. If you want to disable Windows Defender Application Control (WDAC) altogether (including audit mode), you can deploy a script to delete the policy file from disk, and either trigger a reboot or wait for the next reboot. +Configuration Manager doesn't remove policies once deployed. To stop enforcement, you should switch the policy to audit mode, which will produce the same effect. If you want to disable Windows Defender Application Control (WDAC) altogether (including audit mode), you can deploy a script to delete the policy file from disk and either trigger a reboot or wait for the next reboot. For more information on using Configuration Manager's native WDAC policies, see [Windows Defender Application Control management with Configuration Manager](/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager). diff --git a/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies.md b/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies.md index 7f04db97e1..0c7726f27d 100644 --- a/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies.md +++ b/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies.md @@ -33,7 +33,7 @@ This topic covers how to disable unsigned or signed WDAC policies. ## Disable unsigned Windows Defender Application Control policies -There may come a time when an administrator wants to disable a Windows Defender Application Control policy. For unsigned WDAC policies, this process is simple. The method used to deploy the policy (such as Group Policy) must first be disabled, then simply delete the SIPolicy.p7b policy file from the following locations, and the WDAC policy will be disabled on the next computer restart: +There may come a time when an administrator wants to disable a Windows Defender Application Control policy. For unsigned WDAC policies, this process is simple. The method used to deploy the policy (such as Group Policy) must first be disabled, then delete the SIPolicy.p7b policy file from the following locations, and the WDAC policy will be disabled on the next computer restart: - <EFI System Partition>\\Microsoft\\Boot\\ - <OS Volume>\\Windows\\System32\\CodeIntegrity\\ @@ -43,7 +43,7 @@ There may come a time when an administrator wants to disable a Windows Defender ## Disable signed Windows Defender Application Control policies within Windows -Signed policies protect Windows from administrative manipulation as well as malware that has gained administrative-level access to the system. For this reason, signed Windows Defender Application Control policies are intentionally more difficult to remove than unsigned policies. They inherently protect themselves from modification or removal and therefore are difficult even for administrators to remove successfully. If the signed WDAC policy is manually enabled and copied to the CodeIntegrity folder, to remove the policy, you must complete the following steps. +Signed policies protect Windows from administrative manipulation and malware that has gained administrative-level access to the system. For this reason, signed Windows Defender Application Control policies are intentionally more difficult to remove than unsigned policies. They inherently protect themselves from modification or removal and therefore are difficult even for administrators to remove successfully. If the signed WDAC policy is manually enabled and copied to the CodeIntegrity folder, to remove the policy, you must complete the following steps. > [!NOTE] > For reference, signed WDAC policies should be replaced and removed from the following locations: @@ -68,7 +68,7 @@ Signed policies protect Windows from administrative manipulation as well as malw 5. Restart the client computer. -If the signed Windows Defender Application Control policy has been deployed using by using Group Policy, you must complete the following steps: +If the signed Windows Defender Application Control policy has been deployed by using Group Policy, you must complete the following steps: 1. Replace the existing policy in the GPO with another signed policy that has the **6 Enabled: Unsigned System Integrity Policy** rule option enabled. @@ -90,7 +90,7 @@ If the signed Windows Defender Application Control policy has been deployed usin ## Disable signed Windows Defender Application Control policies within the BIOS -There may be a time when signed Windows Defender Application Control policies cause a boot failure. Because WDAC policies enforce kernel mode drivers, it is important that they be thoroughly tested on each software and hardware configuration before being enforced and signed. Signed WDAC policies are validated in the pre-boot sequence by using Secure Boot. When you disable the Secure Boot feature in the BIOS, and then delete the file from the following locations on the operating system disk, it allows the system to boot into Windows: +There may be a time when signed Windows Defender Application Control policies cause a boot failure. Because WDAC policies enforce kernel mode drivers, it's important that they be thoroughly tested on each software and hardware configuration before being enforced and signed. Signed WDAC policies are validated in the pre-boot sequence by using Secure Boot. When you disable the Secure Boot feature in the BIOS, and then delete the file from the following locations on the operating system disk, it allows the system to boot into Windows: - <EFI System Partition>\\Microsoft\\Boot\\ - <OS Volume>\\Windows\\System32\\CodeIntegrity\\ diff --git a/windows/security/threat-protection/windows-defender-application-control/event-id-explanations.md b/windows/security/threat-protection/windows-defender-application-control/event-id-explanations.md index e96c186076..4caa7844ea 100644 --- a/windows/security/threat-protection/windows-defender-application-control/event-id-explanations.md +++ b/windows/security/threat-protection/windows-defender-application-control/event-id-explanations.md @@ -91,7 +91,7 @@ reg add hklm\system\currentcontrolset\control\ci -v TestFlags -t REG_DWORD -d 0x ## Event ID 3099 Options -The Application Control policy rule-option values can be derived from the "Options" field in the Details section of the Code integrity 3099 event. To parse the values, first convert the hex value to binary. To derive and parse these values, follow the below workflow. +The Application Control policy rule option values can be derived from the "Options" field in the Details section of the Code integrity 3099 event. To parse the values, first convert the hex value to binary. To derive and parse these values, follow the below workflow. - Access Event Viewer. - Access the Code integrity 3099 event. diff --git a/windows/security/threat-protection/windows-defender-application-control/manage-packaged-apps-with-windows-defender-application-control.md b/windows/security/threat-protection/windows-defender-application-control/manage-packaged-apps-with-windows-defender-application-control.md index 71bcec1a37..c309371277 100644 --- a/windows/security/threat-protection/windows-defender-application-control/manage-packaged-apps-with-windows-defender-application-control.md +++ b/windows/security/threat-protection/windows-defender-application-control/manage-packaged-apps-with-windows-defender-application-control.md @@ -34,7 +34,7 @@ This topic for IT professionals describes concepts and lists procedures to help ## Understanding Packaged Apps and Packaged App Installers Packaged apps, also known as Universal Windows apps, are based on a model that ensures all the files within an app package share the same identity. With classic Windows apps, each file within the app could have a unique identity. -With packaged apps, it is possible to control the entire app by using a single Windows Defender Application Control rule. +With packaged apps, it's possible to control the entire app by using a single Windows Defender Application Control rule. Typically, an app consists of multiple components: the installer that is used to install the app, and one or more exes, dlls, or scripts. With classic Windows apps, these components don't always share common attributes such as the software’s publisher name, product name, and product version. Therefore, Windows Defender Application Control controls each of these components separately through different rule collections, such as exe, dll, script, and Windows Installer rules. In contrast, all the components of a packaged app share the same publisher name, package name, and package version attributes. Therefore, you can control an entire app with a single rule. @@ -43,8 +43,8 @@ Typically, an app consists of multiple components: the installer that is used to Windows Defender Application Control policies for packaged apps can only be applied to apps installed on computers running at least Windows Server 2012 or Windows 8, but classic Windows apps can be controlled on devices running at least Windows Server 2008 R2 or Windows 7. The rules for classic Windows apps and packaged apps can be enforced in tandem. The differences between packaged apps and classic Windows apps that you should consider include: -- **Installing the apps**   All packaged apps can be installed by a standard user, whereas a number of classic Windows apps require administrative privileges to install. In an environment where most of the users are standard users, you might not have numerous exe rules (because classic Windows apps require administrative privileges to install), but you might want to have more explicit policies for packaged apps. -- **Changing the system state**   Classic Windows apps can be written to change the system state if they are run with administrative privileges. Most packaged apps cannot change the system state because they run with limited privileges. When you design your Windows Defender Application Control policies, it is important to understand whether an app that you are allowing can make system-wide changes. +- **Installing the apps**   All packaged apps can be installed by a standard user, whereas many classic Windows apps require administrative privileges to install. In an environment where most of the users are standard users, you might not have numerous exe rules (because classic Windows apps require administrative privileges to install), but you might want to have more explicit policies for packaged apps. +- **Changing the system state**   Classic Windows apps can be written to change the system state if they're run with administrative privileges. Most packaged apps can't change the system state because they run with limited privileges. When you design your Windows Defender Application Control policies, it's important to understand whether an app that you're allowing can make system-wide changes. - **Acquiring the apps**   Packaged apps can be acquired through the Store, or by loading using Windows PowerShell cmdlets (which requires a special enterprise license). Classic Windows apps can be acquired through traditional means. Windows Defender Application Control uses different rule collections to control packaged apps and classic Windows apps. You have the choice to control one type, the other type, or both. @@ -57,7 +57,7 @@ Just as there are differences in managing each rule collection, you need to mana 2. Create WDAC rules for specific packaged apps based on your policy strategies. For more information, see [Deploy Windows Defender Application Control policy (WDAC) rules and file rules](select-types-of-rules-to-create.md). -3. Continue to update the WDAC policies as new package apps are introduced into your environment. To do this, see [Merge WDAC policies](merge-windows-defender-application-control-policies.md). +3. Continue to update the WDAC policies as new package apps are introduced into your environment. For information on how to do this update, see [Merge WDAC policies](merge-windows-defender-application-control-policies.md). ## Blocking Packaged Apps @@ -65,7 +65,7 @@ You can now use `New-CIPolicyRule -Package $Package -Deny` to block packaged app ### Blocking Packaged Apps Which Are Installed on the System -Below are the list of steps you can follow to block one or more packaged apps in the case that the apps are on the system you are using the WDAC PowerShell cmdlets on: +Below are the list of steps you can follow to block one or more packaged apps in the case that the apps are on the system you're using the WDAC PowerShell cmdlets on: 1. Get the app identifier for an installed package @@ -116,9 +116,9 @@ Below are the list of steps you can follow to block one or more packaged apps in ```powershell Invoke-CimMethod -Namespace root\Microsoft\Windows\CI -ClassName PS_UpdateAndCompareCIPolicy -MethodName Update -Arguments @{FilePath = "C:\compiledpolicy.bin"} ``` - ### Blocking Packaged Apps Which Are Not Installed on the System + ### Blocking Packaged Apps Which Aren't Installed on the System -If the app you intend to block is not installed on the system you are using the WDAC PowerShell cmdlets on, then follow the steps below: +If the app you intend to block isn't installed on the system you're using the WDAC PowerShell cmdlets on, then follow the steps below: 1. Create a dummy rule using Steps 1-5 in the Blocking Packaged Apps Which Are Installed on the System section above @@ -148,4 +148,4 @@ The method for allowing specific packaged apps is similar to the method outlined $Rule = New-CIPolicyRule -Package $package -allow ``` -Since a lot of system apps are packaged apps, it is generally advised that customers rely on the sample policies in `C:\Windows\schemas\CodeIntegrity\ExamplePolicies` to help allow all inbox apps by the Store signature already included in the policies and control apps with deny rules. +Since many system apps are packaged apps, it's recommended that customers rely on the sample policies in `C:\Windows\schemas\CodeIntegrity\ExamplePolicies` to help allow all inbox apps by the Store signature already included in the policies and control apps with deny rules. diff --git a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md index 0fbd505f00..dcc0b464fd 100644 --- a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md @@ -75,9 +75,9 @@ Unless your use scenarios explicitly require them, Microsoft recommends that you - wslconfig.exe - wslhost.exe -1 A vulnerability in bginfo.exe has been fixed in the latest version 4.22. If you use BGInfo, for security, make sure to download and run the latest version here [BGInfo 4.22](/sysinternals/downloads/bginfo). Note that BGInfo versions earlier than 4.22 are still vulnerable and should be blocked. +1 A vulnerability in bginfo.exe has been fixed in the latest version 4.22. If you use BGInfo, for security, make sure to download and run the latest version here [BGInfo 4.22](/sysinternals/downloads/bginfo). BGInfo versions earlier than 4.22 are still vulnerable and should be blocked. -2 If you are using your reference system in a development context and use msbuild.exe to build managed applications, we recommend that you allow msbuild.exe in your code integrity policies. However, if your reference system is an end-user device that is not being used in a development context, we recommend that you block msbuild.exe. +2 If you're using your reference system in a development context and use msbuild.exe to build managed applications, we recommend that you allow msbuild.exe in your code integrity policies. However, if your reference system is an end-user device that isn't being used in a development context, we recommend that you block msbuild.exe. * Microsoft recognizes the efforts of people in the security community who help us protect customers through responsible vulnerability disclosure, and extends thanks to the following people: @@ -107,9 +107,9 @@ Unless your use scenarios explicitly require them, Microsoft recommends that you Certain software applications may allow other code to run by design. Such applications should be blocked by your Windows Defender Application Control policy. In addition, when an application version is upgraded to fix a security vulnerability or potential Windows Defender Application Control bypass, you should add *deny* rules to your application control policies for that application’s previous, less secure versions. -Microsoft recommends that you install the latest security updates. The June 2017 Windows updates resolve several issues in PowerShell modules that allowed an attacker to bypass Windows Defender Application Control. These modules cannot be blocked by name or version, and therefore must be blocked by their corresponding hashes. +Microsoft recommends that you install the latest security updates. The June 2017 Windows updates resolve several issues in PowerShell modules that allowed an attacker to bypass Windows Defender Application Control. These modules can't be blocked by name or version, and therefore must be blocked by their corresponding hashes. -For October 2017, we are announcing an update to system.management.automation.dll in which we are revoking older versions by hash values, instead of version rules. +For October 2017, we're announcing an update to system.management.automation.dll in which we're revoking older versions by hash values, instead of version rules. Microsoft recommends that you block the following Microsoft-signed applications and PowerShell files by merging the following policy into your existing policy to add these deny rules using the Merge-CIPolicy cmdlet. Beginning with the March 2019 quality update, each version of Windows requires blocking a specific version of the following files: diff --git a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md index 1d88193ede..7c16581109 100644 --- a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md @@ -36,11 +36,11 @@ The vulnerable driver blocklist is designed to help harden systems against third - Known security vulnerabilities that can be exploited by attackers to elevate privileges in the Windows kernel - Malicious behaviors (malware) or certificates used to sign malware -- Behaviors that are not malicious but circumvent the Windows Security Model and can be exploited by attackers to elevate privileges in the Windows kernel +- Behaviors that aren't malicious but circumvent the Windows Security Model and can be exploited by attackers to elevate privileges in the Windows kernel Drivers can be submitted to Microsoft for security analysis at the [Microsoft Security Intelligence Driver Submission page](https://www.microsoft.com/en-us/wdsi/driversubmission). To report an issue or request a change to the vulnerable driver blocklist, including updating a block rule once a driver vulnerability has been patched, visit the [Microsoft Security Intelligence portal](https://www.microsoft.com/wdsi) or submit feedback on this article. -Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity) or S mode to protect your devices against security threats. If this isn't possible, Microsoft recommends blocking this list of drivers within your existing Windows Defender Application Control policy. Blocking kernel drivers without sufficient testing can result in devices or software to malfunction, and in rare cases, blue screen. It's recommended to first validate this policy in [audit mode](audit-windows-defender-application-control-policies.md) and review the audit block events. +Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity) or S mode to protect your devices against security threats. If this setting isn't possible, Microsoft recommends blocking this list of drivers within your existing Windows Defender Application Control policy. Blocking kernel drivers without sufficient testing can result in devices or software to malfunction, and in rare cases, blue screen. It's recommended to first validate this policy in [audit mode](audit-windows-defender-application-control-policies.md) and review the audit block events. ```xml diff --git a/windows/security/threat-protection/windows-defender-application-control/plan-windows-defender-application-control-management.md b/windows/security/threat-protection/windows-defender-application-control/plan-windows-defender-application-control-management.md index 7e7c459ff7..6691993b1b 100644 --- a/windows/security/threat-protection/windows-defender-application-control/plan-windows-defender-application-control-management.md +++ b/windows/security/threat-protection/windows-defender-application-control/plan-windows-defender-application-control-management.md @@ -37,11 +37,11 @@ The first step in implementing application control is to consider how your polic Most Windows Defender Application Control policies will evolve over time and proceed through a set of identifiable phases during their lifetime. Typically, these phases include: -1. [Define (or refine) the "circle-of-trust"](understand-windows-defender-application-control-policy-design-decisions.md) for the policy and build an audit mode version of the policy XML. In audit mode, block events are generated but files are not prevented from executing. +1. [Define (or refine) the "circle-of-trust"](understand-windows-defender-application-control-policy-design-decisions.md) for the policy and build an audit mode version of the policy XML. In audit mode, block events are generated but files aren't prevented from executing. 2. Deploy the audit mode policy to intended devices. 3. Monitor audit block events from the intended devices and add/edit/delete rules as needed to address unexpected/unwanted blocks. 4. Repeat steps 2-3 until the remaining block events meet expectations. -5. Generate the enforced mode version of the policy. In enforced mode, files that are not allowed by the policy are prevented from executing and corresponding block events are generated. +5. Generate the enforced mode version of the policy. In enforced mode, files that aren't allowed by the policy are prevented from executing and corresponding block events are generated. 6. Deploy the enforced mode policy to intended devices. We recommend using staged rollouts for enforced policies to detect and respond to issues before deploying the policy broadly. 7. Repeat steps 1-6 anytime the desired "circle-of-trust" changes. @@ -59,11 +59,11 @@ Use the [Set-CIPolicyIDInfo](/powershell/module/configci/set-cipolicyidinfo) cmd > PolicyID only applies to policies using the [multiple policy format](deploy-multiple-windows-defender-application-control-policies.md) on computers running Windows 10, version 1903 and above, or Windows 11. Running -ResetPolicyId on a policy created for pre-1903 computers will convert it to multiple policy format and prevent it from running on those earlier versions of Windows 10. > PolicyID should be set only once per policy and use different PolicyID's for the audit and enforced mode versions of each policy. -In addition, we recommend using the [Set-CIPolicyVersion](/powershell/module/configci/set-cipolicyversion) cmdlet to increment the policy's internal version number when you make changes to the policy. The version must be defined as a standard four-part version string (e.g. "1.0.0.0"). +In addition, we recommend using the [Set-CIPolicyVersion](/powershell/module/configci/set-cipolicyversion) cmdlet to increment the policy's internal version number when you make changes to the policy. The version must be defined as a standard four-part version string (for example, "1.0.0.0"). ### Policy rule updates -As new apps are deployed or existing apps are updated by the software publisher, you may need to make revisions to your rules to ensure that these apps run correctly. Whether policy rule updates are required will depend significantly on the types of rules your policy includes. Rules based on codesigning certificates provide the most resiliency against app changes while rules based on file attributes or hash are most likely to require updates when apps change. Alternatively, if you leverage WDAC [managed installer](configure-authorized-apps-deployed-with-a-managed-installer.md) functionality and consistently deploy all apps and their updates through your managed installer, then you are less likely to need policy updates. +As new apps are deployed or existing apps are updated by the software publisher, you may need to make revisions to your rules to ensure that these apps run correctly. Whether policy rule updates are required will depend significantly on the types of rules your policy includes. Rules based on codesigning certificates provide the most resiliency against app changes while rules based on file attributes or hash are most likely to require updates when apps change. Alternatively, if you use WDAC [managed installer](configure-authorized-apps-deployed-with-a-managed-installer.md) functionality and consistently deploy all apps and their updates through your managed installer, then you're less likely to need policy updates. ## WDAC event management @@ -84,16 +84,16 @@ Considerations include: ### Help desk support -If your organization has an established help desk support department in place, consider the following when deploying Windows Defender Application Control policies: +If your organization has an established help desk support department in place, consider the following points when deploying Windows Defender Application Control policies: - What documentation does your support department require for new policy deployments? - What are the critical processes in each business group both in work flow and timing that will be affected by application control policies and how could they affect your support department's workload? - Who are the contacts in the support department? -- How will the support department resolve application control issues between the end user and those who maintain the Windows Defender Application Control rules? +- How will the support department resolve application control issues between the end user and those resources who maintain the Windows Defender Application Control rules? ### End-user support -Because Windows Defender Application Control is preventing unapproved apps from running, it is important that your organization carefully plan how to provide end-user support. Considerations include: +Because Windows Defender Application Control is preventing unapproved apps from running, it's important that your organization carefully plan how to provide end-user support. Considerations include: - Do you want to use an intranet site as a first line of support for users who have tried to run a blocked app? - How do you want to support exceptions to the policy? Will you allow users to run a script to temporarily allow access to a blocked app? @@ -102,6 +102,6 @@ Because Windows Defender Application Control is preventing unapproved apps from After deciding how your organization will manage your Windows Defender Application Control policy, record your findings. -- **End-user support policy.** Document the process that you will use for handling calls from users who have attempted to run a blocked app, and ensure that support personnel have clear escalation steps so that the administrator can update the Windows Defender Application Control policy, if necessary. +- **End-user support policy.** Document the process that you'll use for handling calls from users who have attempted to run a blocked app, and ensure that support personnel have clear escalation steps so that the administrator can update the Windows Defender Application Control policy, if necessary. - **Event processing.** Document whether events will be collected in a central location called a store, how that store will be archived, and whether the events will be processed for analysis. -- **Policy management.** Detail what policies are planned, how they will be managed, and how rules will be maintained over time. +- **Policy management.** Detail what policies are planned, how they'll be managed, and how rules will be maintained over time. diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index 1b68313de8..474a39e5dd 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -88,13 +88,13 @@ Each file rule level has its benefit and disadvantage. Use Table 2 to select the | Rule level | Description | |----------- | ----------- | -| **Hash** | Specifies individual [Authenticode/PE image hash values](#more-information-about-hashes) for each discovered binary. This is the most specific level, and requires more effort to maintain the current product versions’ hash values. Each time a binary is updated, the hash value changes, therefore requiring a policy update. | +| **Hash** | Specifies individual [Authenticode/PE image hash values](#more-information-about-hashes) for each discovered binary. This level is the most specific level, and requires more effort to maintain the current product versions’ hash values. Each time a binary is updated, the hash value changes, therefore requiring a policy update. | | **FileName** | Specifies the original filename for each binary. Although the hash values for an application are modified when updated, the file names are typically not. This level offers less specific security than the hash level, but it doesn't typically require a policy update when any binary is modified. | | **FilePath** | Beginning with Windows 10 version 1903, this level allows binaries to run from specific file path locations. More information about FilePath level rules can be found below. | | **SignedVersion** | This level combines the publisher rule with a version number. It allows anything to run from the specified publisher with a version at or above the specified version number. | | **Publisher** | This level combines the PcaCertificate level (typically one certificate below the root) and the common name (CN) of the leaf certificate. You can use this rule level to trust a certificate issued by a particular CA and issued to a specific company you trust (such as Intel, for device drivers). | | **FilePublisher** | This level combines the “FileName” attribute of the signed file, plus “Publisher” (PCA certificate with CN of leaf), plus a minimum version number. This option trusts specific files from the specified publisher, with a version at or above the specified version number. | -| **LeafCertificate** | Adds trusted signers at the individual signing certificate level. The benefit of using this level versus the individual hash level is that new versions of the product will have different hash values but typically the same signing certificate. Using this level, no policy update would be needed to run the new version of the application. However, leaf certificates have much shorter validity periods than other certificate levels, so the Windows Defender Application Control policy must be updated whenever these certificates change. | +| **LeafCertificate** | Adds trusted signers at the individual signing certificate level. The benefit of using this level versus the individual hash level is that new versions of the product will have different hash values but typically the same signing certificate. When this level is used, no policy update would be needed to run the new version of the application. However, leaf certificates have much shorter validity periods than other certificate levels, so the Windows Defender Application Control policy must be updated whenever these certificates change. | | **PcaCertificate** | Adds the highest available certificate in the provided certificate chain to signers. This level is typically one certificate below the root certificate because the scan doesn't validate anything beyond the certificates included in the provided signature (it doesn't go online or check local root stores). | | **RootCertificate** | Currently unsupported. | | **WHQL** | Trusts binaries if they've been validated and signed by WHQL. This level is primarily for kernel binaries. | @@ -112,13 +112,13 @@ Each file rule level has its benefit and disadvantage. Use Table 2 to select the For example, consider an IT professional in a department that runs many servers. They only want to run software signed by the companies that provide their hardware, operating system, antivirus, and other important software. They know that their servers also run an internally written application that is unsigned but is rarely updated. They want to allow this application to run. -To create the Windows Defender Application Control policy, they build a reference server on their standard hardware, and install all of the software that their servers are known to run. Then they run [New-CIPolicy](/powershell/module/configci/new-cipolicy) with **-Level Publisher** (to allow software from their software providers, the "Publishers") and **-Fallback Hash** (to allow the internal, unsigned application). They deploy the policy in auditing mode to determine the potential impact from enforcing the policy. Using the audit data, they update their WDAC policies to include any additional software they want to run. Then they enable the WDAC policy in enforced mode for their servers. +To create the Windows Defender Application Control policy, they build a reference server on their standard hardware, and install all of the software that their servers are known to run. Then they run [New-CIPolicy](/powershell/module/configci/new-cipolicy) with **-Level Publisher** (to allow software from their software providers, the "Publishers") and **-Fallback Hash** (to allow the internal, unsigned application). They deploy the policy in auditing mode to determine the potential impact from enforcing the policy. With the help of the audit data, they update their WDAC policies to include any other software they want to run. Then they enable the WDAC policy in enforced mode for their servers. As part of normal operations, they'll eventually install software updates, or perhaps add software from the same software providers. Because the "Publisher" remains the same on those updates and software, they won't need to update their WDAC policy. If the unsigned, internal application is updated, they must also update the WDAC policy to allow the new version. ## File rule precedence order -Windows Defender Application Control has a built-in file rule conflict logic that translates to precedence order. It will first process all explicit deny rules it finds. Then, it will process all explicit allow rules. If no deny or allow rule exists, WDAC will check for [Managed Installer EA](deployment/deploy-wdac-policies-with-memcm.md). Lastly, if none of these exist, WDAC will fall back on [ISG](use-windows-defender-application-control-with-intelligent-security-graph.md). +Windows Defender Application Control has a built-in file rule conflict logic that translates to precedence order. It will first process all explicit deny rules it finds. Then, it will process all explicit allow rules. If no deny or allow rule exists, WDAC will check for [Managed Installer EA](deployment/deploy-wdac-policies-with-memcm.md). Lastly, if none of these sets exist, WDAC will fall back on [ISG](use-windows-defender-application-control-with-intelligent-security-graph.md). ## More information about filepath rules @@ -132,7 +132,7 @@ WDAC's list of well-known admin SIDs are: S-1-3-0; S-1-5-18; S-1-5-19; S-1-5-20; S-1-5-32-544; S-1-5-32-549; S-1-5-32-550; S-1-5-32-551; S-1-5-32-577; S-1-5-32-559; S-1-5-32-568; S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394; S-1-15-2-95739096-486727260-2033287795-3853587803-1685597119-444378811-2746676523. -When generating filepath rules using [New-CIPolicy](/powershell/module/configci/new-cipolicy), a unique, fully qualified path rule is generated for every file discovered in the scanned path(s). To create rules that instead allow all files under a specified folder path, use [New-CIPolicyRule](/powershell/module/configci/new-cipolicyrule) to define rules containing wildcards, using the [-FilePathRules](/powershell/module/configci/new-cipolicyrule#parameters) switch. +When filepath rules are being generated using [New-CIPolicy](/powershell/module/configci/new-cipolicy), a unique, fully qualified path rule is generated for every file discovered in the scanned path(s). To create rules that instead allow all files under a specified folder path, use [New-CIPolicyRule](/powershell/module/configci/new-cipolicyrule) to define rules containing wildcards, using the [-FilePathRules](/powershell/module/configci/new-cipolicyrule#parameters) switch. Wildcards can be used at the beginning or end of a path rule; only one wildcard is allowed per path rule. Wildcards placed at the end of a path authorize all files in that path and its subdirectories recursively (ex. `C:\*` would include `C:\foo\*` ). Wildcards placed at the beginning of a path will allow the exact specified filename under any path (ex. `*\bar.exe` would allow `C:\bar.exe` and `C:\foo\bar.exe`). Wildcards in the middle of a path aren't supported (ex. `C:\*\foo.exe`). Without a wildcard, the rule will allow only a specific file (ex. `C:\foo\bar.exe`). @@ -146,16 +146,16 @@ You can also use the following macros when the exact volume may vary: `%OSDRIVE% ## More information about hashes -WDAC uses the [Authenticode/PE image hash algorithm](https://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx) when calculating the hash of a file. Unlike the more popular, but less secure, [flat file hash](/powershell/module/microsoft.powershell.utility/get-filehash), the Authenticode hash calculation omits the file's checksum and the Certificate Table and the Attribute Certificate Table. Therefore, the Authenticode hash of a file does not change when the file is re-signed or timestamped, or the digital signature is removed from the file. By using the Authenticode hash, WDAC provides added security and less management overhead so customers do not need to revise the policy hash rules when the digital signature on the file is updated. +WDAC uses the [Authenticode/PE image hash algorithm](https://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx) when calculating the hash of a file. Unlike the more popular, but less secure, [flat file hash](/powershell/module/microsoft.powershell.utility/get-filehash), the Authenticode hash calculation omits the file's checksum and the Certificate Table and the Attribute Certificate Table. Therefore, the Authenticode hash of a file doesn't change when the file is re-signed or timestamped, or the digital signature is removed from the file. With the help of the Authenticode hash, WDAC provides added security and less management overhead so customers don't need to revise the policy hash rules when the digital signature on the file is updated. -The Authenticode/PE image hash can be calculated for digitally-signed and unsigned files. +The Authenticode/PE image hash can be calculated for digitally signed and unsigned files. ### Why does scan create four hash rules per XML file? The PowerShell cmdlet will produce an Authenticode Sha1 Hash, Sha256 Hash, Sha1 Page Hash, Sha256 Page Hash. -During validation CI will choose which hashes to calculate, depending on how the file is signed. For example, if the file is page-hash signed the entire file wouldn't get paged in to do a full sha256 authenticode, and we would just match using the first page hash. +During validation, CI will choose which hashes to calculate, depending on how the file is signed. For example, if the file is page-hash signed the entire file wouldn't get paged in to do a full sha256 authenticode, and we would just match using the first page hash. -In the cmdlets, rather than try to predict which hash CI will use, we pre-calculate and use the four hashes (sha1/sha2 authenticode, and sha1/sha2 of first page). This is also resilient, if the signing status of the file changes and necessary for deny rules to ensure that changing/stripping the signature doesn’t result in a different hash than what was in the policy being used by CI. +In the cmdlets, rather than try to predict which hash CI will use, we pre-calculate and use the four hashes (sha1/sha2 authenticode, and sha1/sha2 of first page). This method is also resilient, if the signing status of the file changes and necessary for deny rules to ensure that changing/stripping the signature doesn’t result in a different hash than what was in the policy being used by CI. ### Why does scan create eight hash rules for certain XML files? diff --git a/windows/security/threat-protection/windows-defender-application-control/types-of-devices.md b/windows/security/threat-protection/windows-defender-application-control/types-of-devices.md index 6ff71e34a5..287c4058d0 100644 --- a/windows/security/threat-protection/windows-defender-application-control/types-of-devices.md +++ b/windows/security/threat-protection/windows-defender-application-control/types-of-devices.md @@ -29,27 +29,27 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -Typically, deployment of Windows Defender Application Control (WDAC) happens best in phases, rather than being a feature that you simply “turn on.” The choice and sequence of phases depends on the way various computers and other devices are used in your organization, and to what degree IT manages those devices. The following table can help you begin to develop a plan for deploying WDAC in your organization. It is common for organizations to have device use cases across each of the categories described. +Typically, deployment of Windows Defender Application Control (WDAC) happens best in phases, rather than being a feature that you simply “turn on.” The choice and sequence of phases depends on the way various computers and other devices are used in your organization, and to what degree IT manages those devices. The following table can help you begin to develop a plan for deploying WDAC in your organization. It's common for organizations to have device use cases across each of the categories described. ## Types of devices | **Type of device** | **How WDAC relates to this type of device** | |------------------------------------|------------------------------------------------------| | **Lightly managed devices**: Company-owned, but users are free to install software.
    Devices are required to run organization's antivirus solution and client management tools. | Windows Defender Application Control can be used to help protect the kernel, and to monitor (audit) for problem applications rather than limiting the applications that can be run. | -| **Fully managed devices**: Allowed software is restricted by IT department.
    Users can request additional software, or install from a list of applications provided by IT department.
    Examples: locked-down, company-owned desktops and laptops. | An initial baseline Windows Defender Application Control policy can be established and enforced. Whenever the IT department approves additional applications, it will update the WDAC policy and (for unsigned LOB applications) the catalog.
    WDAC policies are supported by the HVCI service. | -| **Fixed-workload devices**: Perform same tasks every day.
    Lists of approved applications rarely change.
    Examples: kiosks, point-of-sale systems, call center computers. | Windows Defender Application Control can be deployed fully, and deployment and ongoing administration are relatively straightforward.
    After Windows Defender Application Control deployment, only approved applications can run. This is because of protections offered by WDAC. | -| **Bring Your Own Device**: Employees are allowed to bring their own devices, and also use those devices away from work. | In most cases, Windows Defender Application Control does not apply. Instead, you can explore other hardening and security features with MDM-based conditional access solutions, such as Microsoft Intune. However, you may choose to deploy an audit-mode policy to these devices or employ a blocklist only policy to prevent specific apps or binaries that are considered malicious or vulnerable by your organization. | +| **Fully managed devices**: Allowed software is restricted by IT department.
    Users can request for more software, or install from a list of applications provided by IT department.
    Examples: locked-down, company-owned desktops and laptops. | An initial baseline Windows Defender Application Control policy can be established and enforced. Whenever the IT department approves more applications, it will update the WDAC policy and (for unsigned LOB applications) the catalog.
    WDAC policies are supported by the HVCI service. | +| **Fixed-workload devices**: Perform same tasks every day.
    Lists of approved applications rarely change.
    Examples: kiosks, point-of-sale systems, call center computers. | Windows Defender Application Control can be deployed fully, and deployment and ongoing administration are relatively straightforward.
    After Windows Defender Application Control deployment, only approved applications can run. This rule is because of protections offered by WDAC. | +| **Bring Your Own Device**: Employees are allowed to bring their own devices, and also use those devices away from work. | In most cases, Windows Defender Application Control doesn't apply. Instead, you can explore other hardening and security features with MDM-based conditional access solutions, such as Microsoft Intune. However, you may choose to deploy an audit-mode policy to these devices or employ a blocklist only policy to prevent specific apps or binaries that are considered malicious or vulnerable by your organization. | ## An introduction to Lamna Healthcare Company -In the next set of topics, we will explore each of the above scenarios using a fictional organization called Lamna Healthcare Company. +In the next set of topics, we'll explore each of the above scenarios using a fictional organization called Lamna Healthcare Company. Lamna Healthcare Company (Lamna) is a large healthcare provider operating in the United States. Lamna employs thousands of people, from doctors and nurses to accountants, in-house lawyers, and IT technicians. Their device use cases are varied and include single-user workstations for their professional staff, shared kiosks used by doctors and nurses to access patient records, dedicated medical devices such as MRI scanners, and many others. Additionally, Lamna has a relaxed, bring-your-own-device policy for many of their professional staff. Lamna uses [Microsoft Endpoint Manager](https://www.microsoft.com/microsoft-365/microsoft-endpoint-manager) in hybrid mode with both Configuration Manager and Intune. Although they use Microsoft Endpoint Manager to deploy many applications, Lamna has always had relaxed application usage practices: individual teams and employees have been able to install and use any applications they deem necessary for their role on their own workstations. Lamna also recently started to use [Microsoft Defender for Endpoint](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp) for better endpoint detection and response. -Recently, Lamna experienced a ransomware event that required an expensive recovery process and may have included data exfiltration by the unknown attacker. Part of the attack included installing and running malicious binaries that evaded detection by Lamna's antivirus solution but would have been blocked by an application control policy. In response, Lamna's executive board has authorized a number of new security IT responses, including tightening policies for application use and introducing application control. +Recently, Lamna experienced a ransomware event that required an expensive recovery process and may have included data exfiltration by the unknown attacker. Part of the attack included installing and running malicious binaries that evaded detection by Lamna's antivirus solution but would have been blocked by an application control policy. In response, Lamna's executive board has authorized many new security IT responses, including tightening policies for application use and introducing application control. ## Up next -- [Create a Windows Defender Application Control policy for lightly-managed devices](create-wdac-policy-for-lightly-managed-devices.md) +- [Create a Windows Defender Application Control policy for lightly managed devices](create-wdac-policy-for-lightly-managed-devices.md) diff --git a/windows/security/threat-protection/windows-defender-application-control/understand-windows-defender-application-control-policy-design-decisions.md b/windows/security/threat-protection/windows-defender-application-control/understand-windows-defender-application-control-policy-design-decisions.md index 9729e7515d..406209261e 100644 --- a/windows/security/threat-protection/windows-defender-application-control/understand-windows-defender-application-control-policy-design-decisions.md +++ b/windows/security/threat-protection/windows-defender-application-control/understand-windows-defender-application-control-policy-design-decisions.md @@ -44,15 +44,15 @@ You should consider using Windows Defender Application Control as part of your o ## Decide what policies to create -Beginning with Windows 10, version 1903, Windows Defender Application Control allows [multiple simultaneous policies](deploy-multiple-windows-defender-application-control-policies.md) to be applied to each device. This opens up many new use cases for organizations, but your policy management can easily become unwieldy without a well-thought-out plan for the number and types of policies to create. +Beginning with Windows 10, version 1903, Windows Defender Application Control allows [multiple simultaneous policies](deploy-multiple-windows-defender-application-control-policies.md) to be applied to each device. This concurrent application opens up many new use cases for organizations, but your policy management can easily become unwieldy without a well-thought-out plan for the number and types of policies to create. The first step is to define the desired "circle-of-trust" for your WDAC policies. By "circle-of-trust," we mean a description of the business intent of the policy expressed in natural language. This "circle-of-trust" definition will guide you as you create the actual policy rules for your policy XML. For example, the DefaultWindows policy, which can be found under %OSDrive%\Windows\schemas\CodeIntegrity\ExamplePolicies, establishes a "circle-of-trust" that allows Windows, 3rd-party hardware and software kernel drivers, and applications from the Microsoft Store. -Configuration Manager uses the DefaultWindows policy as the basis for its policy but then modifies the policy rules to allow Configuration Manager and its dependencies, sets the managed installer policy rule, and additionally configures Configuration Manager as a managed installer. It also can optionally authorize apps with positive reputation and perform a one-time scan of folder paths specified by the Configuration Manager administrator, which adds rules for any apps found in the specified paths on the managed endpoint. This establishes the "circle-of-trust" for Configuration Manager's native WDAC integration. +Configuration Manager uses the DefaultWindows policy as the basis for its policy but then modifies the policy rules to allow Configuration Manager and its dependencies, sets the managed installer policy rule, and additionally configures Configuration Manager as a managed installer. It also can optionally authorize apps with positive reputation and perform a one-time scan of folder paths specified by the Configuration Manager administrator, which adds rules for any apps found in the specified paths on the managed endpoint. This process establishes the "circle-of-trust" for Configuration Manager's native WDAC integration. -The following questions can help you plan your Windows Defender Application Control deployment and determine the right "circle-of-trust" for your policies. They are not in priority or sequential order, and are not meant to be an exhaustive set of design considerations. +The following questions can help you plan your Windows Defender Application Control deployment and determine the right "circle-of-trust" for your policies. They aren't in priority or sequential order, and aren't meant to be an exhaustive set of design considerations. ## WDAC design considerations @@ -74,11 +74,11 @@ Traditional Win32 apps on Windows can run without being digitally signed. This p | Possible answers | Design considerations | | - | - | | All apps used in your organization must be signed. | Organizations that enforce [codesigning](use-code-signing-to-simplify-application-control-for-classic-windows-applications.md) for all executable code are best-positioned to protect their Windows computers from malicious code execution. Windows Defender Application Control rules can be created to authorize apps and binaries from the organization's internal development teams and from trusted independent software vendors (ISV). | -| Apps used in your organization do not need to meet any codesigning requirements. | Organizations can [use built-in Windows tools](deploy-catalog-files-to-support-windows-defender-application-control.md) to add organization-specific App Catalog signatures to existing apps as a part of the app deployment process, which can be used to authorize code execution. Solutions like Microsoft Endpoint Manager offer multiple ways to distribute signed App Catalogs. | +| Apps used in your organization don't need to meet any codesigning requirements. | Organizations can [use built-in Windows tools](deploy-catalog-files-to-support-windows-defender-application-control.md) to add organization-specific App Catalog signatures to existing apps as a part of the app deployment process, which can be used to authorize code execution. Solutions like Microsoft Endpoint Manager offer multiple ways to distribute signed App Catalogs. | ### Are there specific groups in your organization that need customized application control policies? -Most business teams or departments have specific security requirements that pertain to data access and the applications used to access that data. Consider the scope of the project for each group and the group’s priorities before you deploy application control policies for the entire organization. There is overhead in managing policies that might lead you to choose between broad, organization-wide policies and multiple team-specific policies. +Most business teams or departments have specific security requirements that pertain to data access and the applications used to access that data. Consider the scope of the project for each group and the group’s priorities before you deploy application control policies for the entire organization. There's overhead in managing policies that might lead you to choose between broad, organization-wide policies and multiple team-specific policies. | Possible answers | Design considerations | | - | - | @@ -91,12 +91,12 @@ The time and resources that are available to you to perform the research and ana | Possible answers | Design considerations | | - | - | -| Yes | Invest the time to analyze your organization's application control requirements, and plan a complete deployment that uses rules that are constructed as simply as possible.| +| Yes | Invest the time to analyze your organization's application control requirements, and plan a complete deployment that uses rules that are constructed as possible.| | No | Consider a focused and phased deployment for specific groups by using few rules. As you apply controls to applications in a specific group, learn from that deployment to plan your next deployment. Alternatively, you can create a policy with a broad trust profile to authorize as many apps as possible. | ### Does your organization have Help Desk support? -Preventing your users from accessing known, deployed, or personal applications will initially cause an increase in end-user support. It will be necessary to address the various support issues in your organization so security policies are followed and business workflow is not hampered. +Preventing your users from accessing known, deployed, or personal applications will initially cause an increase in end-user support. It will be necessary to address the various support issues in your organization so security policies are followed and business workflow isn't hampered. | Possible answers | Design considerations | | - | - | diff --git a/windows/security/threat-protection/windows-defender-application-control/use-code-signing-to-simplify-application-control-for-classic-windows-applications.md b/windows/security/threat-protection/windows-defender-application-control/use-code-signing-to-simplify-application-control-for-classic-windows-applications.md index fcb3a32077..b84336abab 100644 --- a/windows/security/threat-protection/windows-defender-application-control/use-code-signing-to-simplify-application-control-for-classic-windows-applications.md +++ b/windows/security/threat-protection/windows-defender-application-control/use-code-signing-to-simplify-application-control-for-classic-windows-applications.md @@ -1,6 +1,6 @@ --- title: Use code signing to simplify application control for classic Windows applications (Windows) -description: With embedded signing, your WDAC policies typically do not have to be updated when an app is updated. To set this up, you can choose from a variety of methods. +description: With embedded signing, your WDAC policies typically don't have to be updated when an app is updated. To set up this embedded signing, you can choose from various methods. keywords: security, malware ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb ms.prod: m365-security @@ -33,13 +33,13 @@ This topic covers guidelines for using code signing control classic Windows apps ## Reviewing your applications: application signing and catalog files -Typically, Windows Defender Application Control (WDAC) policies are configured to use the application's signing certificate as part or all of what identifies the application as trusted. This means that applications must either use embedded signing—where the signature is part of the binary—or catalog signing, where you generate a "catalog file" from the applications, sign it, and through the signed catalog file, configure the WDAC policy to recognize the applications as signed. +Typically, Windows Defender Application Control (WDAC) policies are configured to use the application's signing certificate as part or all of what identifies the application as trusted. This purpose means that applications must either use embedded signing—where the signature is part of the binary—or catalog signing, where you generate a "catalog file" from the applications, sign it, and through the signed catalog file, configure the WDAC policy to recognize the applications as signed. -Catalog files can be very useful for unsigned LOB applications that cannot easily be given an embedded signature. However, catalogs need to be updated each time an application is updated. In contrast, with embedded signing, your Windows Defender Application Control policies typically do not have to be updated when an application is updated. For this reason, if code-signing is or can be included in your in-house application development process, it can simplify the management of WDAC (compared to using catalog signing). +Catalog files can be useful for unsigned LOB applications that can't easily be given an embedded signature. However, catalogs need to be updated each time an application is updated. In contrast, with embedded signing, your Windows Defender Application Control policies typically don't have to be updated when an application is updated. For this reason, if code-signing is or can be included in your in-house application development process, it can simplify the management of WDAC (compared to using catalog signing). -To obtain signed applications or embed signatures in your in-house applications, you can choose from a variety of methods: +To obtain signed applications or embed signatures in your in-house applications, you can choose from various methods: -- Using the Microsoft Store publishing process. All apps that come out of the Microsoft Store are automatically signed with special signatures that can roll-up to our certificate authority (CA) or to your own. +- Using the Microsoft Store publishing process. All apps that come out of the Microsoft Store are automatically signed with special signatures that can roll up to our certificate authority (CA) or to your own. - Using your own digital certificate or public key infrastructure (PKI). ISV's and enterprises can sign their own Classic Windows applications themselves, adding themselves to the trusted list of signers. @@ -53,11 +53,11 @@ To use catalog signing, you can choose from the following options: ### Catalog files -Catalog files (which you can create in Windows 10 and Windows 11 with a tool called Package Inspector) contain information about all deployed and executed binary files associated with your trusted but unsigned applications. When you create catalog files, you can also include signed applications for which you do not want to trust the signer but rather the specific application. After creating a catalog, you must sign the catalog file itself by using enterprise public key infrastructure (PKI), or a purchased code signing certificate. Then you can distribute the catalog, so that your trusted applications can be handled by Windows Defender Application Control in the same way as any other signed application. +Catalog files (which you can create in Windows 10 and Windows 11 with a tool called Package Inspector) contain information about all deployed and executed binary files associated with your trusted but unsigned applications. When you create catalog files, you can also include signed applications for which you don't want to trust the signer but rather the specific application. After creating a catalog, you must sign the catalog file itself by using enterprise public key infrastructure (PKI), or a purchased code signing certificate. Then you can distribute the catalog, so that your trusted applications can be handled by Windows Defender Application Control in the same way as any other signed application. -Catalog files are simply Secure Hash Algorithm 2 (SHA2) hash lists of discovered binaries. These binaries' hash values are updated each time an application is updated, which requires the catalog file to be updated also. +Catalog files are Secure Hash Algorithm 2 (SHA2) hash lists of discovered binaries. These binaries' hash values are updated each time an application is updated, which requires the catalog file to be updated also. -After you have created and signed your catalog files, you can configure your WDAC policies to trust the signer or signing certificate of those files. +After you've created and signed your catalog files, you can configure your WDAC policies to trust the signer or signing certificate of those files. > [!NOTE] > Package Inspector only works on operating systems that support Windows Defender, such as Windows 10 and Windows 11 Enterprise, Windows 10 and Windows 11 Education, Windows 2016 Server, or Windows Enterprise IoT. @@ -66,8 +66,8 @@ For procedures for working with catalog files, see [Deploy catalog files to supp ## Windows Defender Application Control policy formats and signing -When you generate a Windows Defender Application Control policy, you are generating a binary-encoded XML document that includes configuration settings for both the User and Kernel-modes of Windows 10 and Windows 11 Enterprise, along with restrictions on Windows 10 and Windows 11 script hosts. You can view your original XML document in a text editor, for example if you want to check the rule options that are present in the **<Rules>** section of the file. +When you generate a Windows Defender Application Control policy, you're generating a binary-encoded XML document that includes configuration settings for both the User and Kernel-modes of Windows 10 and Windows 11 Enterprise, along with restrictions on Windows 10 and Windows 11 script hosts. You can view your original XML document in a text editor, for example if you want to check the rule options that are present in the **<Rules>** section of the file. We recommend that you keep the original XML file for use when you need to merge the WDAC policy with another policy or update its rule options. For deployment purposes, the file is converted to a binary format, which can be done using a simple Windows PowerShell command. -When the Windows Defender Application Control policy is deployed, it restricts the software that can run on a device. The XML document can be signed, helping to add additional protection against administrative users changing or removing the policy. +When the Windows Defender Application Control policy is deployed, it restricts the software that can run on a device. The XML document can be signed, helping to add more protection against administrative users changing or removing the policy. diff --git a/windows/security/threat-protection/windows-defender-application-control/use-signed-policies-to-protect-windows-defender-application-control-against-tampering.md b/windows/security/threat-protection/windows-defender-application-control/use-signed-policies-to-protect-windows-defender-application-control-against-tampering.md index 1b87884a5e..a8e73a9c67 100644 --- a/windows/security/threat-protection/windows-defender-application-control/use-signed-policies-to-protect-windows-defender-application-control-against-tampering.md +++ b/windows/security/threat-protection/windows-defender-application-control/use-signed-policies-to-protect-windows-defender-application-control-against-tampering.md @@ -29,20 +29,20 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -Signed Windows Defender Application Control (WDAC) policies give organizations the highest level of malware protection available in Windows—must be signed with [PKCS #7](https://datatracker.ietf.org/doc/html/rfc5652). In addition to their enforced policy rules, signed policies cannot be modified or deleted by a user or administrator on the computer. These policies are designed to prevent administrative tampering and kernel mode exploit access. With this in mind, it is much more difficult to remove signed WDAC policies. Note that SecureBoot must be enabled in order to restrict users from updating or removing signed WDAC policies. +Signed Windows Defender Application Control (WDAC) policies give organizations the highest level of malware protection available in Windows—must be signed with [PKCS #7](https://datatracker.ietf.org/doc/html/rfc5652). In addition to their enforced policy rules, signed policies can't be modified or deleted by a user or administrator on the computer. These policies are designed to prevent administrative tampering and kernel mode exploit access. With this idea of the policies in mind, it's much more difficult to remove signed WDAC policies. SecureBoot must be enabled in order to restrict users from updating or removing signed WDAC policies. Before you sign with PKCS #7 and deploy a signed WDAC policy, we recommend that you [audit the policy](audit-windows-defender-application-control-policies.md) to discover any blocked applications that should be allowed to run. Signing WDAC policies by using an on-premises CA-generated certificate or a purchased code signing certificate is straightforward. -If you do not currently have a code signing certificate exported in .pfx format (containing private keys, extensions, and root certificates), see [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md) to create one with your on-premises CA. +If you don't currently have a code signing certificate exported in .pfx format (containing private keys, extensions, and root certificates), see [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md) to create one with your on-premises CA. -Before PKCS #7-signing WDAC policies for the first time, be sure to enable rule options 9 (“Advanced Boot Options Menu”) and 10 (“Boot Audit on Failure”) to leave troubleshooting options available to administrators. To ensure that a rule option is enabled, you can run a command such as `Set-RuleOption -FilePath -Option 9`, even if you're not sure whether the option is already enabled. If so, the command has no effect. When validated and ready for enterprise deployment, you can remove these options. For more information about rule options, see [Windows Defender Application Control policy rules](select-types-of-rules-to-create.md). +Before PKCS #7-signing WDAC policies for the first time, ensure you enable rule options 9 (“Advanced Boot Options Menu”) and 10 (“Boot Audit on Failure”) to leave troubleshooting options available to administrators. To ensure that a rule option is enabled, you can run a command such as `Set-RuleOption -FilePath -Option 9`, even if you're not sure whether the option is already enabled. If so, the command has no effect. When validated and ready for enterprise deployment, you can remove these options. For more information about rule options, see [Windows Defender Application Control policy rules](select-types-of-rules-to-create.md). To sign a Windows Defender Application Control policy with SignTool.exe, you need the following components: - SignTool.exe, found in the [Windows SDK](https://developer.microsoft.com/windows/downloads/windows-10-sdk/) (Windows 7 or later) -- The binary format of the WDAC policy that you generated in [Create a Windows Defender Application Control policy from a reference computer](create-initial-default-policy.md) or another WDAC policy that you have created +- The binary format of the WDAC policy that you generated in [Create a Windows Defender Application Control policy from a reference computer](create-initial-default-policy.md) or another WDAC policy that you've created - An internal CA code signing certificate or a purchased code signing certificate @@ -52,7 +52,7 @@ To sign a Windows Defender Application Control policy with SignTool.exe, you nee >Certificate fields, like 'subject common name' and 'issuer common name,' cannot be UTF-8 encoded, otherwise, blue screens may occur. These strings must be encoded as PRINTABLE_STRING, IA5STRING or BMPSTRING. -If you do not have a code signing certificate, see [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md) for instructions on how to create one. If you use an alternate certificate or Windows Defender Application Control (WDAC) policy, be sure to update the following steps with the appropriate variables and certificate so that the commands will function properly. To sign the existing WDAC policy, copy each of the following commands into an elevated Windows PowerShell session: +If you don't have a code signing certificate, see [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md) for instructions on how to create one. If you use an alternate certificate or Windows Defender Application Control (WDAC) policy, ensure you update the following steps with the appropriate variables and certificate so that the commands will function properly. To sign the existing WDAC policy, copy each of the following commands into an elevated Windows PowerShell session: 1. Initialize the variables that will be used: @@ -64,7 +64,7 @@ If you do not have a code signing certificate, see [Optional: Create a code sign > [!NOTE] > This example uses the WDAC policy that you created in the [Create a Windows Defender Application Control policy from a reference computer](create-initial-default-policy.md) section. If you are signing another policy, be sure to update the **$CIPolicyPath** variable with the correct information. -2. Import the .pfx code signing certificate. Import the code signing certificate that you will use to sign the WDAC policy into the signing user’s personal store on the computer that will be doing the signing. In this example, you use the certificate that was created in [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md). +2. Import the .pfx code signing certificate. Import the code signing certificate that you'll use to sign the WDAC policy into the signing user’s personal store on the computer that will be doing the signing. In this example, you use the certificate that was created in [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md). 3. Export the .cer code signing certificate. After the code signing certificate has been imported, export the .cer version to your desktop. This version will be added to the policy so that it can be updated later. diff --git a/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-policy-to-control-specific-plug-ins-add-ins-and-modules.md b/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-policy-to-control-specific-plug-ins-add-ins-and-modules.md index 869d7f489a..b3e830a04b 100644 --- a/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-policy-to-control-specific-plug-ins-add-ins-and-modules.md +++ b/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-policy-to-control-specific-plug-ins-add-ins-and-modules.md @@ -29,7 +29,7 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -As of Windows 10, version 1703, you can use Windows Defender Application Control (WDAC) policies not only to control applications, but also to control whether specific plug-ins, add-ins, and modules can run from specific apps (such as a line-of-business application or a browser): +As of Windows 10, version 1703, you can use Windows Defender Application Control (WDAC) policies to control applications and also to control whether specific plug-ins, add-ins, and modules can run from specific apps (such as a line-of-business application or a browser): | Approach (as of Windows 10, version 1703) | Guideline | |---|---| @@ -38,7 +38,7 @@ As of Windows 10, version 1703, you can use Windows Defender Application Control To work with these options, the typical method is to create a policy that only affects plug-ins, add-ins, and modules, then merge it into your 'master' policy (merging is described in the next section). -For example, to create a Windows Defender Application Control policy allowing **addin1.dll** and **addin2.dll** to run in **ERP1.exe**, your organization's enterprise resource planning (ERP) application, run the following commands. Note that in the second command, **+=** is used to add a second rule to the **$rule** variable: +For example, to create a Windows Defender Application Control policy allowing **addin1.dll** and **addin2.dll** to run in **ERP1.exe**, your organization's enterprise resource planning (ERP) application, run the following commands. In the second command, **+=** is used to add a second rule to the **$rule** variable: ```powershell $rule = New-CIPolicyRule -DriverFilePath '.\temp\addin1.dll' -Level FileName -AppID '.\ERP1.exe' diff --git a/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-dynamic-code-security.md b/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-dynamic-code-security.md index 19f39c1525..337a1853f6 100644 --- a/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-dynamic-code-security.md +++ b/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-dynamic-code-security.md @@ -20,15 +20,15 @@ ms.technology: windows-sec # Windows Defender Application Control and .NET hardening -Historically, Windows Defender Application Control (WDAC) has restricted the set of applications, libraries, and scripts that are allowed to run to those approved by an organization. +Historically, Windows Defender Application Control (WDAC) has restricted the set of applications, libraries, and scripts that are allowed to run to those sets approved by an organization. Security researchers have found that some .NET applications may be used to circumvent those controls by using .NET’s capabilities to load libraries from external sources or generate new code on the fly. Beginning with Windows 10, version 1803, or Windows 11, Windows Defender Application Control features a new capability, called *Dynamic Code Security* to verify code loaded by .NET at runtime. When the Dynamic Code Security option is enabled, Windows Defender Application Control policy is applied to libraries that .NET loads from external sources. Additionally, it detects tampering in code generated to disk by .NET and blocks loading code that has been tampered with. -Dynamic Code Security is not enabled by default because existing policies may not account for externally loaded libraries. -Additionally, a few .NET loading features, including loading unsigned assemblies built with System.Reflection.Emit, are not currently supported with Dynamic Code Security enabled. +Dynamic Code Security isn't enabled by default because existing policies may not account for externally loaded libraries. +Additionally, a few .NET loading features, including loading unsigned assemblies built with System.Reflection.Emit, aren't currently supported with Dynamic Code Security enabled. Microsoft recommends testing Dynamic Code Security in audit mode before enforcing it to discover whether any new libraries should be included in the policy. Additionally, customers can precompile for deployment only to prevent an allowed executable from being terminated because it tries to load unsigned dynamically generated code. See the "Precompiling for Deployment Only" section in the [ASP.NET Precompilation Overview](/aspnet/web-forms/overview/older-versions-getting-started/deploying-web-site-projects/precompiling-your-website-cs) document for how to fix that. diff --git a/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-intelligent-security-graph.md b/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-intelligent-security-graph.md index 4e1abd6929..251e30f962 100644 --- a/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-intelligent-security-graph.md +++ b/windows/security/threat-protection/windows-defender-application-control/use-windows-defender-application-control-with-intelligent-security-graph.md @@ -36,7 +36,7 @@ Beginning with Windows 10, version 1709, you can set an option to automatically The ISG uses the same vast security intelligence and machine learning analytics that power Microsoft Defender SmartScreen and Microsoft Defender Antivirus to help classify applications as having "known good," "known bad," or "unknown" reputation. When a binary runs on a system, with Windows Defender Application Control (WDAC) enabled with the ISG option, WDAC checks the file's reputation, by sending its hash and signing information to the cloud. If the ISG reports that the file has a "known good" reputation, the $KERNEL.SMARTLOCKER.ORIGINCLAIM kernel Extended Attribute (EA) is written to the file. -If your WDAC policy does not have an explicit rule to allow or deny a binary to run, then WDAC will make a call to the cloud to determine whether the binary is familiar and safe. However, if your policy already authorizes or denies the binary, then WDAC will not make a call to the cloud. +If your WDAC policy doesn't have an explicit rule to allow or deny a binary to run, then WDAC will make a call to the cloud to determine whether the binary is familiar and safe. However, if your policy already authorizes or denies the binary, then WDAC won't make a call to the cloud. If the file with good reputation is an application installer, its reputation will pass along to any files that it writes to disk. This way, all the files needed to install and run an app inherit the positive reputation data from the installer. @@ -54,7 +54,7 @@ Setting up the ISG is easy using any management solution you wish. Configuring t ### Ensure that the Intelligent Security Graph option is enabled in the WDAC policy XML -To allow apps and binaries based on the Microsoft Intelligent Security Graph, the **Enabled:Intelligent Security Graph authorization** option must be specified in the Windows Defender Application Control policy. This step can be done with the Set-RuleOption cmdlet. You should also enable the **Enabled:Invalidate EAs on Reboot** option so that ISG results are verified again after each reboot. The ISG option is not recommended for devices that don't have regular access to the internet. The following example shows both options being set. +To allow apps and binaries based on the Microsoft Intelligent Security Graph, the **Enabled:Intelligent Security Graph authorization** option must be specified in the Windows Defender Application Control policy. This step can be done with the Set-RuleOption cmdlet. You should also enable the **Enabled:Invalidate EAs on Reboot** option so that ISG results are verified again after each reboot. The ISG option isn't recommended for devices that don't have regular access to the internet. The following example shows both options being set. ```xml @@ -84,7 +84,7 @@ To allow apps and binaries based on the Microsoft Intelligent Security Graph, th ### Enable the necessary services to allow WDAC to use the ISG correctly on the client -In order for the heuristics used by the ISG to function properly, a number of components in Windows must be enabled. You can configure these components by running the appidtel executable in `c:\windows\system32`. +In order for the heuristics used by the ISG to function properly, many components in Windows must be enabled. You can configure these components by running the appidtel executable in `c:\windows\system32`. ```console appidtel start @@ -99,7 +99,7 @@ Since the Microsoft Intelligent Security Graph is a heuristic-based mechanism, i Processes running with kernel privileges can circumvent WDAC by setting the ISG extended file attribute to make a binary appear to have known good reputation. Also, since the ISG option passes along reputation from application installers to the binaries they write to disk, it can over-authorize files in some cases where the installer launches the application upon completion. ## Using fsutil to query SmartLocker EA -Customers using Windows Defender Application Control (WDAC) with Managed Installer (MI) or Intelligent Security Graph enabled can use fsutil to determine whether a file was allowed to run by one of these features. This can be achieved by querying the EAs on a file using fsutil and looking for the KERNEL.SMARTLOCKER.ORIGINCLAIM EA. The presence of this EA indicates that either MI or ISG allowed the file to run. This can be used in conjunction with enabling the MI and ISG logging events. +Customers using Windows Defender Application Control (WDAC) with Managed Installer (MI) or Intelligent Security Graph enabled can use fsutil to determine whether a file was allowed to run by one of these features. This verification can be done by querying the EAs on a file using fsutil and looking for the KERNEL.SMARTLOCKER.ORIGINCLAIM EA. The presence of this EA indicates that either MI or ISG allowed the file to run. This EA's presence can be used in conjunction with enabling the MI and ISG logging events. #### Example @@ -123,9 +123,9 @@ Ea Value Length: 7e ## Known limitations with using the Intelligent Security Graph -Since the ISG only allows binaries that are known good, there are cases where legitimate software may be unknown to the ISG and will be blocked by Windows Defender Application Control (WDAC). In this case, you need to allow the software with a rule in your WDAC policy, deploy a catalog signed by a certificate trusted in the WDAC policy, or install the software from a WDAC managed installer. Installers or applications that dynamically create binaries at runtime, as well as self-updating applications, may exhibit this symptom. +Since the ISG only allows binaries that are known good, there are cases where legitimate software may be unknown to the ISG and will be blocked by Windows Defender Application Control (WDAC). In this case, you need to allow the software with a rule in your WDAC policy, deploy a catalog signed by a certificate trusted in the WDAC policy, or install the software from a WDAC managed installer. Installers or applications that dynamically create binaries at runtime, and self-updating applications, may exhibit this symptom. -Packaged apps are not supported with the Microsoft Intelligent Security Graph heuristics and will need to be separately authorized in your WDAC policy. Since packaged apps have a strong app identity and must be signed, it is straightforward to authorize these apps with your WDAC policy. +Packaged apps aren't supported with the Microsoft Intelligent Security Graph heuristics and will need to be separately authorized in your WDAC policy. Since packaged apps have a strong app identity and must be signed, it's straightforward to authorize these apps with your WDAC policy. The ISG doesn't authorize kernel mode drivers. The WDAC policy must have rules that allow the necessary drivers to run. diff --git a/windows/security/threat-protection/windows-defender-application-control/wdac-and-applocker-overview.md b/windows/security/threat-protection/windows-defender-application-control/wdac-and-applocker-overview.md index 6737ed1fd8..696ab59fea 100644 --- a/windows/security/threat-protection/windows-defender-application-control/wdac-and-applocker-overview.md +++ b/windows/security/threat-protection/windows-defender-application-control/wdac-and-applocker-overview.md @@ -45,19 +45,19 @@ Windows Defender Application Control policies apply to the managed computer as a - The [path from which the app or file is launched](select-types-of-rules-to-create.md#more-information-about-filepath-rules) (beginning with Windows 10 version 1903) - The process that launched the app or binary -Note that prior to Windows 10 version 1709, Windows Defender Application Control was known as configurable code integrity (CCI). WDAC was also one of the features that comprised the now-defunct term "Device Guard." +Prior to Windows 10 version 1709, Windows Defender Application Control was known as configurable code integrity (CCI). WDAC was also one of the features that comprised the now-defunct term "Device Guard." ### WDAC System Requirements Windows Defender Application Control (WDAC) policies can be created on any client edition of Windows 10 build 1903+, or Windows 11, or on Windows Server 2016 and above. -WDAC policies can be applied to devices running any edition of Windows 10, Windows 11, or Windows Server 2016 and above, via a Mobile Device Management (MDM) solution, for example, Intune; a management interface such as Configuration Manager; or a script host such as PowerShell. Group Policy can also be used to deploy WDAC policies to Windows 10 and Windows 11 Enterprise edition, or Windows Server 2016 and above, but cannot deploy policies to devices running non-Enterprise SKUs of Windows 10. +WDAC policies can be applied to devices running any edition of Windows 10, Windows 11, or Windows Server 2016 and above, via a Mobile Device Management (MDM) solution, for example, Intune; a management interface such as Configuration Manager; or a script host such as PowerShell. Group Policy can also be used to deploy WDAC policies to Windows 10 and Windows 11 Enterprise edition, or Windows Server 2016 and above, but can't deploy policies to devices running non-Enterprise SKUs of Windows 10. For more information on which individual WDAC features are available on specific WDAC builds, see [WDAC feature availability](feature-availability.md). ## AppLocker -AppLocker was introduced with Windows 7, and allows organizations to control which applications are allowed to run on their Windows clients. AppLocker helps to prevent end-users from running unapproved software on their computers but does not meet the servicing criteria for being a security feature. +AppLocker was introduced with Windows 7, and allows organizations to control which applications are allowed to run on their Windows clients. AppLocker helps to prevent end-users from running unapproved software on their computers but doesn't meet the servicing criteria for being a security feature. AppLocker policies can apply to all users on a computer, or to individual users and groups. AppLocker rules can be defined based on: @@ -72,13 +72,13 @@ AppLocker policies can be deployed using Group Policy or MDM. ## Choose when to use WDAC or AppLocker -Generally, it is recommended that customers, who are able to implement application control using Windows Defender Application Control rather than AppLocker, do so. WDAC is undergoing continual improvements, and will be getting added support from Microsoft management platforms. Although AppLocker will continue to receive security fixes, it will not undergo new feature improvements. +Generally, it's recommended that customers, who are able to implement application control using Windows Defender Application Control rather than AppLocker, do so. WDAC is undergoing continual improvements, and will be getting added support from Microsoft management platforms. Although AppLocker will continue to receive security fixes, it will not undergo new feature improvements. However, in some cases, AppLocker may be the more appropriate technology for your organization. AppLocker is best when: - You have a mixed Windows operating system (OS) environment and need to apply the same policy controls to Windows 10 and earlier versions of the OS. - You need to apply different policies for different users or groups on shared computers. -- You do not want to enforce application control on application files such as DLLs or drivers. +- You don't want to enforce application control on application files such as DLLs or drivers. -AppLocker can also be deployed as a complement to Windows Defender Application Control (WDAC) to add user or group-specific rules for shared device scenarios, where it is important to prevent some users from running specific apps. +AppLocker can also be deployed as a complement to Windows Defender Application Control (WDAC) to add user or group-specific rules for shared device scenarios, where it's important to prevent some users from running specific apps. As a best practice, you should enforce WDAC at the most restrictive level possible for your organization, and then you can use AppLocker to further fine-tune the restrictions. diff --git a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-base-policy.md b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-base-policy.md index 9d8ec5a0c7..e1353dfcf7 100644 --- a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-base-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-base-policy.md @@ -30,12 +30,12 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -When creating policies for use with Windows Defender Application Control (WDAC), it is recommended to start with a template policy and then add or remove rules to suit your application control scenario. For this reason, the WDAC Wizard offers three template policies to start from and customize during the base policy creation workflow. Prerequisite information about application control can be accessed through the [WDAC design guide](windows-defender-application-control-design-guide.md). This page outlines the steps to create a new application control policy from a template, configure the policy options, and the signer and file rules. +When creating policies for use with Windows Defender Application Control (WDAC), it's recommended to start with a template policy, and then add or remove rules to suit your application control scenario. For this reason, the WDAC Wizard offers three template policies to start from and customize during the base policy creation workflow. Prerequisite information about application control can be accessed through the [WDAC design guide](windows-defender-application-control-design-guide.md). This page outlines the steps to create a new application control policy from a template, configure the policy options, and the signer and file rules. ## Template Base Policies -Each of the template policies has a unique set of policy allow list rules that will affect the circle-of-trust and security model of the policy. The following table lists the policies in increasing order of trust and freedom. For instance, the Default Windows mode policy trusts fewer application publishers and signers than the Signed and Reputable mode policy. The Default Windows policy will have a smaller circle-of-trust with better security than the Signed and Reputable policy, but at the expense of compatibility. +Each of the template policies has a unique set of policy allowlist rules that will affect the circle-of-trust and security model of the policy. The following table lists the policies in increasing order of trust and freedom. For instance, the Default Windows mode policy trusts fewer application publishers and signers than the Signed and Reputable mode policy. The Default Windows policy will have a smaller circle-of-trust with better security than the Signed and Reputable policy, but at the expense of compatibility. | Template Base Policy | Description | @@ -64,11 +64,11 @@ A description of each policy rule, beginning with the left-most column, is provi |------------ | ----------- | | **Advanced Boot Options Menu** | The F8 preboot menu is disabled by default for all Windows Defender Application Control policies. Setting this rule option allows the F8 menu to appear to physically present users. | | **Allow Supplemental Policies** | Use this option on a base policy to allow supplemental policies to expand it. | -| **Disable Script Enforcement** | This option disables script enforcement options. Unsigned PowerShell scripts and interactive PowerShell are no longer restricted to [Constrained Language Mode](/powershell/module/microsoft.powershell.core/about/about_language_modes). NOTE: This option is required to run HTA files, and is only supported with the Windows 10 May 2019 Update (1903) and higher. Using it on earlier versions of Windows 10 is not supported and may have unintended results. | +| **Disable Script Enforcement** | This option disables script enforcement options. Unsigned PowerShell scripts and interactive PowerShell are no longer restricted to [Constrained Language Mode](/powershell/module/microsoft.powershell.core/about/about_language_modes). NOTE: This option is required to run HTA files, and is only supported with the Windows 10 May 2019 Update (1903) and higher. Using it on earlier versions of Windows 10 isn't supported and may have unintended results. | |**[Hypervisor-protected code integrity (HVCI)](../device-guard/enable-virtualization-based-protection-of-code-integrity.md)**| When enabled, policy enforcement uses virtualization-based security to run the code integrity service inside a secure environment. HVCI provides stronger protections against kernel malware.| | **Intelligent Security Graph Authorization** | Use this option to automatically allow applications with "known good" reputation as defined by the Microsoft Intelligent Security Graph (ISG). | | **Managed Installer** | Use this option to automatically allow applications installed by a software distribution solution, such as Microsoft Endpoint Configuration Manager, that has been defined as a managed installer. | -| **Require WHQL** | By default, legacy drivers that are not Windows Hardware Quality Labs (WHQL) signed are allowed to execute. Enabling this rule requires that every executed driver is WHQL signed and removes legacy driver support. Going forward, every new Windows–compatible driver must be WHQL certified. | +| **Require WHQL** | By default, legacy drivers that aren't Windows Hardware Quality Labs (WHQL) signed are allowed to execute. Enabling this rule requires that every executed driver is WHQL signed and removes legacy driver support. Henceforth, every new Windows–compatible driver must be WHQL certified. | | **Update Policy without Rebooting** | Use this option to allow future Windows Defender Application Control policy updates to apply without requiring a system reboot. | | **Unsigned System Integrity Policy** | Allows the policy to remain unsigned. When this option is removed, the policy must be signed and have UpdatePolicySigners added to the policy to enable future policy modifications. | | **User Mode Code Integrity** | Windows Defender Application Control policies restrict both kernel-mode and user-mode binaries. By default, only kernel-mode binaries are restricted. Enabling this rule option validates user mode executables and scripts. | @@ -83,7 +83,7 @@ Selecting the **+ Advanced Options** label will show another column of policy ru | Rule option | Description | |------------ | ----------- | | **Boot Audit on Failure** | Used when the Windows Defender Application Control (WDAC) policy is in enforcement mode. When a driver fails during startup, the WDAC policy will be placed in audit mode so that Windows will load. Administrators can validate the reason for the failure in the CodeIntegrity event log. | -| **Disable Flight Signing** | If enabled, WDAC policies will not trust flightroot-signed binaries. This would be used in the scenario in which organizations only want to run released binaries, not flight/preview-signed builds. | +| **Disable Flight Signing** | If enabled, WDAC policies won't trust flightroot-signed binaries. This option would be used in the scenario in which organizations only want to run released binaries, not flight/preview-signed builds. | | **Disable Runtime FilePath Rule Protection** | Disable default FilePath rule protection (apps and executables allowed based on file path rules must come from a file path that's only writable by an administrator) for any FileRule that allows a file based on FilePath. | | **Dynamic Code Security** | Enables policy enforcement for .NET applications and dynamically loaded libraries (DLLs). | | **Invalidate EAs on Reboot** | When the Intelligent Security Graph option (14) is used, WDAC sets an extended file attribute that indicates that the file was authorized to run. This option will cause WDAC to periodically revalidate the reputation for files that were authorized by the ISG.| @@ -104,17 +104,17 @@ The Publisher file rule type uses properties in the code signing certificate cha | Rule Condition | WDAC Rule Level | Description | |------------ | ----------- | ----------- | -| **Issuing CA** | PCACertificate | Highest available certificate is added to the signers. This is typically the PCA certificate, one level below the root certificate. Any file signed by this certificate will be affected. | -| **Publisher** | Publisher | This rule is a combination of the PCACertificate rule and the common name (CN) of the leaf certificate. Any file signed by a major CA but with a leaf from a specific company, for example a device driver corp, is affected. | +| **Issuing CA** | PCACertificate | Highest available certificate is added to the signers. This certificate is typically the PCA certificate, one level below the root certificate. Any file signed by this certificate will be affected. | +| **Publisher** | Publisher | This rule is a combination of the PCACertificate rule and the common name (CN) of the leaf certificate. Any file signed by a major CA but with a leaf from a specific company, for example, a device driver corp, is affected. | | **File version** | SignedVersion | This rule is a combination of PCACertificate, publisher, and a version number. Anything from the specified publisher with a version at or above the one specified is affected. | -| **File name** | FilePublisher | Most specific. Combination of the file name, publisher, and PCA certificate as well as a minimum version number. Files from the publisher with the specified name and greater or equal to the specified version are affected. | +| **File name** | FilePublisher | Most specific. Combination of the file name, publisher, and PCA certificate and a minimum version number. Files from the publisher with the specified name and greater or equal to the specified version are affected. | ![Custom filepublisher file rule creation.](images/wdac-wizard-custom-publisher-rule.png) ### Filepath Rules -Filepath rules do not provide the same security guarantees that explicit signer rules do, as they are based on mutable access permissions. To create a filepath rule, select the file using the *Browse* button. +Filepath rules don't provide the same security guarantees that explicit signer rules do, as they're based on mutable access permissions. To create a filepath rule, select the file using the *Browse* button. ### File Attribute Rules @@ -132,11 +132,11 @@ The Wizard supports the creation of [file name rules](select-types-of-rules-to-c ### File Hash Rules -Lastly, the Wizard supports creating file rules using the hash of the file. Although this level is specific, it can cause additional administrative overhead to maintain the current product version's hash values. Each time a binary is updated, the hash value changes, therefore requiring a policy update. By default, the Wizard will use file hash as the fallback in case a file rule cannot be created using the specified file rule level. +Lastly, the Wizard supports creating file rules using the hash of the file. Although this level is specific, it can cause extra administrative overhead to maintain the current product version's hash values. Each time a binary is updated, the hash value changes, therefore requiring a policy update. By default, the Wizard will use file hash as the fallback in case a file rule can't be created using the specified file rule level. #### Deleting Signing Rules -The policy signing rules list table on the left of the page will document the allow and deny rules in the template, as well as any custom rules you create. Template signing rules and custom rules can be deleted from the policy by selecting the rule from the rules list table. Once the rule is highlighted, press the delete button underneath the table. you will be prompted for additional confirmation. Select `Yes` to remove the rule from the policy and the rules table. +The policy signing rules list table on the left of the page will document the allow and deny rules in the template, and any custom rules you create. Template signing rules and custom rules can be deleted from the policy by selecting the rule from the rules list table. Once the rule is highlighted, press the delete button underneath the table. You'll be prompted for another confirmation. Select `Yes` to remove the rule from the policy and the rules table. ## Up next From fb92d632fe0231a24caafb01e3b2e793478aebbc Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 12:52:08 +1000 Subject: [PATCH 012/109] Add files via upload --- education/windows/change-home-to-edu.md | 221 ++++++++++++++++++++++++ 1 file changed, 221 insertions(+) create mode 100644 education/windows/change-home-to-edu.md diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md new file mode 100644 index 0000000000..a785c5737c --- /dev/null +++ b/education/windows/change-home-to-edu.md @@ -0,0 +1,221 @@ +--- +title: Upgrade Windows Home to Windows Education on personal devices using volume licensing +description: Learn how IT Pros can upgrade personal devices from Windows Home to Windows Education using Mobile Device Management and qualifying subscriptions. +keywords: upgrade, Windows Home to Windows Education, education customers, Windows 10 Home, Windows 11 Home, Windows 11 Education, Windows 10 Education, Intune, Mobile Device Management +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: edu +ms.localizationpriority: medium +author: scottbreenmsft +ms.author: scbree +ms.date: 07/05/2021 +ms.reviewer: aczechowski +manager: aczechowski +--- + +# Upgrade Windows Home to Windows Education on personal devices using volume licensing + +## Overview + +Customers with qualifying subscriptions can upgrade students personal (or institution-owned) devices from Windows Home to Windows Education, which is designed for both the classroom and remote learning. + +> [!NOTE] +> To be qualified for this process, customers must have a Windows Education subscription that includes the student use benefit and must have access to the Volume Licensing Service Center (VLSC) or the Microsoft 365 Admin Center. + +IT staff can upgrade student devices using a multiple activation key (MAK). Alternatively, student devices can be upgraded by contacting [Kivuto OnTheHub](http://onthehub.com) to obtain a product key for their device. The table below provides the recommended approach depending on the scenario. + +|Method|MAK source|Device ownership|Best for| +|-|-|-|-| +|Mobile Device Management|Volume License Service Center|Personal|IT admin initiated as part of enrolment into device management| +|Kivuto|Kivuto|Personal|Initiated on device by student, parent or guardian| +|Provisioning package|Volume license center|Personal or Corporate|IT admin initiated before performing Autopilot| + +Devices can be upgraded from Windows Professional or Windows Pro Edu to Windows Education or Windows Enterprise using [Windows 10/11 Subscription Activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation). + +## Why upgrade personal devices from Windows Home to Windows Education? + +Some configuration service providers (CSPs) are not available on Windows Home which can limit the management capabilities. Some key CSPs that can affect mobile device management are: + +- [EnterpriseDesktopAppManagement](/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications +- [DeliveryOptimization](/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization + +A full list is available at [Configuration service provider reference](/client-management/mdm/configuration-service-provider-reference). + +## Requirements for using a MAK to upgrade from Windows Home to Windows Education + +- Access to Volume Licensing Service Center (VLSC) or the Microsoft 365 Admin Center. +- A qualifying Windows subscription such as: + - Windows A3, or; + - Windows A5. +- A pre-installed and activated instance of Windows 10 Home or Windows 11 Home. + +You can find more information in the [Microsoft Product Terms](https://www.microsoft.com/licensing/terms/productoffering). + +## How the upgrade process works + +IT admins with access to the VLSC or the Microsoft 365 Admin Center, can find their MAK for Windows Education and trigger an upgrade via Mobile Device Management or manually on devices. + +> [!WARNING] +> The MAK key is highly sensitive and should always be protected. Only authorized staff should be given access to the key and it should never be distributed to students or broadly to your organization in documentation or emails. + +### Recommended methods for using a MAK + +It’s critical that MAKs are protected whenever they are used. The following processes provide the best protection for a MAK being applied to a device: + +- Provisioning package by institution approved staff; +- Manual entry by institution approved staff (do not distribute the key via email); +- Mobile Device Management (like Microsoft Intune) via [WindowsLicensing CSP](https://docs.microsoft.com/windows/client-management/mdm/windowslicensing-csp); + > [!IMPORTANT] + > If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key is not accessible by students. +- Operating System Deployment processes with tools such as Microsoft Deployment Toolkit or Microsoft Endpoint Configuration Manager. + + For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](https://docs.microsoft.com/windows/deployment/upgrade/windows-10-edition-upgrades). + +## Downgrading, resetting, reinstalling and graduation rights + +After upgrading from Windows Home to Windows Education there are some considerations for what happens during downgrade, reset or re-install of the operating system. + +The table below highlights the differences by upgrade product key type: + +|MAK Type|Downgrade|Reset|Student re-install| +|-|-|-|-| +|MAK from VLC|No|Yes|No| +|MAK from Kivuto|No|Yes|Yes| + +### Downgrade + +It is not possible to downgrade to Windows Home from Windows Education without reinstalling Windows. + +### Reset + +If the computer is reset, Windows Education will be retained. + +### Re-install + +If a device upgraded by VLSC MAK has Windows reinstalled by the student, it would need to be reinstalled with Windows Home or whatever edition was installed originally on the device to activate successfully using the key provided with the device at purchase. + +If students require a Windows Education key that can work on a new install of Windows, they should use [Kivuto OnTheHub](http://onthehub.com) to request a key prior to graduation. + +For details on product keys and reinstalling Windows, see [Find your Windows product key](https://support.microsoft.com/windows/find-your-windows-product-key-aaa2bf69-7b2b-9f13-f581-a806abf0a886). + +### Re-sale + +The license will remain installed on the device if resold and the same conditions above apply for downgrade (in-place) reset or reinstall. + +## User Notifications + +Users are not prompted or notified that their device has been or will be upgraded to Windows Education when using MDM. It is the responsibility of the institution to notify their users that enrolling in MDM will result in the device being upgraded to Windows Education and that this will give the institution extra capabilities such as installing applications. + +As always, device users can unenroll from within Settings to prevent further actions from being taken on their personal device. + +## Step by step process for customers to upgrade personal devices using Microsoft Intune + +These steps will configure a Windows edition upgrade policy and target all Windows Home devices that are managed by Microsoft Intune for the upgrade to Windows Education edition using your MAK. + +### Step 1: Create a Windows Home edition filter + +Filters allow you to target the all devices group but to a subset of devices using a filter. In this case the filter will be based on the operating system SKU. This will ensure we only upgrade devices that are running Windows Home edition and avoid upgrading devices that are running Windows Pro/Pro EDU edition which can upgrade using [Windows 10/11 Subscription Activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation). + +- Start in the **Microsoft Endpoint Manager admin console** +- Go to **Tenant Administration** > **Filters** +- Click **Create** + - Create a name for the filter (for example *Windows Home edition*) + - Select the **platform** as **Windows 10 and later** + - Click **Next** +- On the **Rules** screen, configure the following rules: + - **operatingSystemSKU** equals **Core (Windows 10/11 Home (101))** + - OR + - **operatingSystemSKU** equals **CoreN (Windows 10/11 Home N (98))** + - OR + - **operatingSystemSKU** equals **CoreSingleLanguage (Windows 10/11 Home single language (100))** + + > [!NOTE] + > Ensure you’ve selected OR as the operator in the right And/Or column + + :::image type="content" source="/images/change-home-to-edu/windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: + +- Optionally select scope tags as required +- Save the filter by clicking **Create** + +### Step 2: Create a Windows edition upgrade policy + +- Start in the **Microsoft Endpoint Manager admin console** +- Select **Devices** > **Configuration profiles** +- Select **Create profile** + - Select the **Platform** as **Windows 10 or later** + - Select the **Profile type** as **Templates** + - Select the **Template** as **Edition upgrade and mode switch** + - Click **Create** +- Create a name for the filter (for example *Windows Education edition upgrade*), click **Next** +- On the **Configuration settings** screen + - Expand **Edition Upgrade** + - Change **Edition to upgrade** to **Windows 10/11 Education** + - In the **Product Key**, enter your *Windows 10/11 Education MAK* + - Click **Next** +- Optionally select scope tags as required and click **Next** +- On the **assignments** screen; + - Select **Add all devices** + - Next to **All devices**, select **Edit filter** + - Select to **Include filtered devices in assignment** + - Select the *Windows Home edition* filter you created earlier + - Click **Select** to save the filter selection + - Click **Next** to progress to the next screen + + :::image type="content" source="/images/change-home-to-edu/windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: +- Do not configure any applicability rules and click **next** +- Review your settings and click **Create** + +The edition upgrade policy will now apply to all existing and new Windows Home edition devices in your tenant. You can verify they’ve upgraded by checking the Operating System SKU field on the device > hardware screen. + +### Step 3: Report on device edition + +- Start in the **Microsoft Endpoint Manager admin console** +- Select **Devices** > **Windows** +- Select the **Columns** button +- Select **Sku Family** +- Click **Export** +- Select **Only include the selected columns in the exported file** and click **Yes** +- Open the file in Excel and filter on the Sku Family column to identify which devices are running the Home SKU + +## Frequently asked questions (FAQ) + +### My MAK key has run out of activations, how do I request a new one? + +- Increases to MAK Activation quantity can be requested via Web Form and may be granted by exception. +- To do this you must have VLSC Administrator, Key Administrator, or Key Viewer permissions and provide the following information: + - Agreement/Enrollment Number or License ID and Authorization. + - Product Name (includes version and edition). + - Last 5 characters of the product key. + - The number of host activations required. + - Business Justification or Reason for Deployment. + +### What is a firmware-embedded activation key? +A firmware-embedded activation key is a Windows product key that is installed into the firmware of your device to allow for easy activation of Windows. To determine if the computer has a firmware-embedded activation key, type the following command at an elevated Windows PowerShell prompt: + +```powershell +(Get-CimInstance -query ‘select * from SoftwareLicensingService’).OA3xOriginalProductKey +``` + +If the device has a firmware-embedded activation key, it will be displayed in the output. If the output is blank, the device does not have a firmware embedded activation key. Most OEM-provided devices designed to run Windows 8 or later will have a firmware-embedded key. + +A firmware embedded key is only required to upgrade using Subscription Activation, a MAK upgrade does not require the firmware embedded key. + +### What is a multiple activation key and how does it differ from using KMS, Active Directory based activation or Subscription Activation? + +A multiple activation key activates either individual computers or a group of computers by connecting directly to servers over the internet or by telephone. KMS, Active Directory based activation and subscription activation are bulk activation methods that work based on network proximity or joining to Active Directory or Azure Active Directory. The table below shows which methods can be used for each scenario. + +| Scenario | Ownership | MAK | KMS | AD based activation | Subscription Activation | +|-|-|-|-|-|-| +| Workplace join (add work or school account) | Personal | X | | | | +Azure Active Directory Join | Organization | X | X | | X | +Hybrid Azure AD Join | Organization | X | X | X | X | + + +## Related links + +- [Windows 10 edition upgrade (Windows 10)](https://docs.microsoft.com/windows/deployment/upgrade/windows-10-edition-upgrades) +- [Windows 10/11 Subscription Activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation) +- [Equip Your Students with Windows 11 Education – Kivuto](https://kivuto.com/windows-11-student-use-benefit/) +- [Upgrade Windows Home to Windows Pro (microsoft.com)](https://support.microsoft.com/windows/upgrade-windows-home-to-windows-pro-ef34d520-e73f-3198-c525-d1a218cc2818) +- [Partner Center: Upgrade Education customers from Windows 10 Home to Windows 10 Education](https://docs.microsoft.com/partner-center/upgrade-windows-to-education) From cf0ea5ae8133b125ea8c0d6ea3d59c4294006990 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 12:53:07 +1000 Subject: [PATCH 013/109] Add files via upload --- .../images/windows-edition-upgrade-policy.png | Bin 0 -> 45890 bytes .../windows-home-edition-intune-filter.png | Bin 0 -> 40112 bytes 2 files changed, 0 insertions(+), 0 deletions(-) create mode 100644 education/windows/images/windows-edition-upgrade-policy.png create mode 100644 education/windows/images/windows-home-edition-intune-filter.png diff --git a/education/windows/images/windows-edition-upgrade-policy.png b/education/windows/images/windows-edition-upgrade-policy.png new file mode 100644 index 0000000000000000000000000000000000000000..f9c4fc3a128310e500be82ccfaa19de52549b613 GIT binary patch literal 45890 zcmbTdby!r<*DpSbf})5>w}424bc0GtcZbq2bT^73-QC^I3|&fh49&pM-9yK~@A!S+ zd!PGz|GCd|&-1{Ub9S74&R%=1&-$#jgOwDdurNt5K_C#;7in=75D1M11bQs<>@jes zN*D_YoE|x;NPPxXjF9aB7f;MT$$tWYsv}?AeR~RAKew0Gb^?K3b^iN%)N5B{0s_^{ zd=dYo=5DaR_~K)%`UA#sVCZ*h#+=8iSP*d^iEdrQKueq%gC8doq;GNvHUO=!k@K#F zUdor34NZn{v9NSD=dWUM+7%_$a|9ATk$56u`_txO$zx>h!rHnj9LwHUwA^FFW5j6= z5-8lB?v!CpF*i3C^KQpkpj<;&NhvBmK0YxqF*Q|JPfuQl*QyQfU@t%>^??e;q)Bl(Xz5KU=-QhFaC9@O<#jNImxCUG(5uBqSDb$i`o!9Zl0?x!f6~8{PHk>(dfr{Y?LK|_lv7rt z>@2~>;d}I)y5P~mt92$%;qB5FKJipSOa+fXf5_i+azZdAbc8Ax85v6qT0Jc+irU-T z>+9>2(Cu&OSy>C%*b~_dS?TGEG|EZ*SwPNOO5_z46@BacorAZ`BZa|94qIK8ta=Kv zmn!*;w!%$0@dUv4N5#Mm$U6j7JOTudIPF=&2Lq zD30n7vpurM{+&zmmjLu#qS^Jp^Zt5EFyVvMBz?*|M)e>m3Xk=nWKQbbj{#g?O!hU^ z50M|q5O2s)7|X00Wm;6g(sBE4*N(c_t85q1>)>7T#w8@A0~$6uZ7F03%`wmBFyq7C zMc3nY^HAv4Sr;3&x6xN=D<~*fTknsg3rZkj5UpOS=^T}`dEr@XD3b7ks;cA7;Z)S^ zB_Xc0QdzvgtznC^U;X!jZz*?=!wcPl3e8lE+3XhR-jw_<*R7u}Q6HR{nHd}$oS2wM z&`pBz^4|pE5Cg-~90)Y%_M;$KElFU}O&Ah*OGDH77a^wOu=9-|8xzkmSWbK2W(;Pf zjr!?lh+<#KO!rbCySz|fJd>t5Fhh!7vgmGLL-;Ug zSV)bBIC85UZ_fWTTKzb8jLc+}89b+_KW=du6k|GQ9SQ6{W;B&~I4Rymr#vLg_vAV+ zrkv2WdI+4780b^co-+2vQjlb8?|Q{VN5_WL(i?SiH6SDgL!a`7a0UGWXrJXlw#fD4&$ncPuGVukrqsDov}&vzAW%IO z&*p-F^7FL6C(?UWLs3;hGtL4CmxhOX6Ysaw1Xf;aJL4e&AS#K%*i_$|Jlid$Pekd!1vJQO34C z8=)#%5JdfSLx?N1ttKEbhaOTREjFc67e7r^2~%Q@(bQyYID24%9n~L zOS?YO4o;k%^q%@r3wAqPNREq3VAD)2Gi`}HfEW{ zc#Zgfmcuz<$g?wgW|%d9O2HJqYz89Zkqf2m3{=s_PO)95$w>dCd_g$z#gtBZVY%kp z9#O)PQ8cvJG#+agbdy9*%9h@LZ%P^Qahmu$F5Zqkw@ygL1Ix z2iiKnhrpH5+CojmP1zHIO1IaiV@95unO${JF)$|w=Epf$+bk!Ia|FKzzeR6IB-EAP zuAOmK9U=;bb0Q0>`gfXF^S5&a=Qt|&4cNGCnKj?Lc**JTHHifl7N9N{Gs53799$_9 zl8A8Sxg8;tm9wWdNSajqQpR3ehf|6o8oy14;4_KKwmyyzjeBg10)Y-o^qXC&)jyk< z%q+n(h%^>~xA(8(001q{=4AFW1z+E)-kmV%FFui{P}m9@_xL5>gJVYjqNsWW!wVBW@j$AT$@HR>@~|drW&gXrdsUiW6-jhk&%&PI02lbB$O*7gCspr z^IYHZ)%`DO!Cp;TsPOo3N=TR~9<|Rx7)GezhIIEX_(KGW?j}h}!-$wbd6G^=!Pq5w zx?bJZHQ!f(630sqG)V3G191!$A~Q|r}B2ZWX$o}TNawe9!G*$f(lvIdP< zG!+>2I}dB&xA$&Bf~cm%b!D|YhBg=QXn?=JQUB&EaT-^|rjNdfUz+w&wyAvTmzKiF zY>&L{TdZ>V>0ex6O16|Xm|Hi~&6ABoHtGb`i;Jp;5+6>FfLo6^6Ay|yNwMPOn8B(d zu$?il#Z4roZlwi|%|~lH_9&SQ;W{@>rch=ZU48=FgE-yp^~BUS^{P4f%lUv$ov1-u|c+KNBX1%bZi!fWK2PLB2no!((9DyD1b(wquO zsA?jGIJw$(5-YtdTvDjh74(xbj$E!vbcU4BJNZ~VvNZZ|Pv>6K%#E1QdSPo@yp`$2jdL9cWoIrdJIKbY?APronAmUWg9+&`#bGEu zzloAE`$kOQ;xlplneNNDtEA3*(m&{R{VeJUgxUjjyUqL?`tR8MKbHfBCrg4;rHEG8 z)9`~V>69fgZ7|Ns{pEsa*5Qibuw<96DbEwc2eTJ|RR_&>{54$LDQf@JM)gg3N0t8` zEY#iIZB;wpW4PvVTG-x>$lOqmQ!P6!TGPKnbsggRww{<5xSi{69o=iH_Crz<6-rM_ zg}KU(!&zM~an%_^s9Y~t4=M~yH9&NNuKQY!jx}?$%$N{r8X8&RZp%M@;l02Chm*GV zpn>cQ9qwk_w@p4S?Mw88NQ4rcA1>;eq-|w}-5p`;v&0CU(qX|`q>%Ty6`$N8KD>pYh1crnuL(>|i{f+f<#=v= zJyNKBA&6l)KQpw4r#B2Ay#Jx29+3?hnq5P;Efdmg0D(TLuYEnr#^oRL(uz@_n;T<6 zQyM4R7JdSl%oX>eZ|Xl!2?5Nd_R02*B`_A?N6zK7Z7DtdbRYipf@j~39#Va{JqY0_%$0Qho9w$F+U z0QAx>-0vEtQx;qS0RfGTjpaJEREg_vPHfTNY{|F7Yu@02efkmpcq%= zA)Sfsa=Ny3Cy_0^-Q6HQ!Se*U5gI4m>Yjmldg>@a%j+*a_#Wuf&l(s6iTAyr@~2Pt z@zBXs-WuqM4$bTGl^a?uUnBS*;ZUMQV%XMdr_R945!#ALm) z{XQilLm`%af6Ya&q^fFpGra81|FOWQJ*ZBll>zhuKp7~HyHT~d%znQ^M6KYO6}rS% zM|>M)u7jauH`e?Q;6L9V*}&`cTimPZOFjb4@^gDvODsDnJh!t2Tz1Ez z5B?Z(`^^MP=4J;3!5oQrZOOW|05>wO&HZF`q0wn)k391UXgLA+)H0)h(^9xKn8-FE zb)xUKD6z!JfCA>GUp;MSkga`xvKW^ZaCvyWuj~!Bi3EPSdw6&Z4EWJW+-yDo_)^J# zL<--jB5y3DqwG2E`B+- zWi}k}@nI49V^VBMXYS5@FM!zbPp*K6c` ziwd-eDDl!suDswVpm@zHNwV2A?bC()>A#qK_Z0Jx~3} z*<$I?9rD~7zCVjz_;v3cPucWtM(J1NE7hVu!U^=a#9wX>n~#7=7iU-c`t>b#M_N!$ zeOVcE2(&L4myVw0y;|M+x(TK&J&by9rjj?z+JPYidU3S$0JKU8(9W}*C^*~S9qt=! z-B?o%&)lK^l_R~E>GV)EW!0(w?Kv&|5F;~l-WR+Xl>`wqC#Tbv)|Q2@-@~1#St!g} z?~sFM1|d0^;!^!hE_?J}2|ZM)sHmn&HLY}y!XoM>Hp+> zusB}+i}xe`_C+BMixs@irsX8;Y=16Rof0vBdaH|NN}lFS9QB_`F0e055#8$pelZ?)EvayR+=! z{<6JA0=hc>SEjVi^<92p;lvVAZ*xA=AfSp!ad9Dim?`3v7&%t)uB&7H(`fkS&{Dcr zvS{cU23Z@nDk{^jET`p67~^&Xz0R#9QRs2}4)kKgnwoDk!#6Eo^LYCV04g(#%&T^th>5wR7w(a&% z@aC=0=`iosP_h`ErOx|I@n{0m;;8q^PfH}@uk$cJX6~MGPY=mv6I#Ok~zP3Vo{6 z!+ApKw9ZD?HTLTrFCFTyU{_F0aF3SPh=Ow0?a1aGmFL*(yY81gDyCa0)qe+8n`Y$} z5ed^G_*MuSa~1szlUeFco$wdtFDE3hJa(}ivmH!53AQ*17!&dh)B6iXynAWRifdu; z#juHRyuER@>bP{(9`O3hBW6J@go#w7_p!H|iii~+#-q#;Eo*;vijM=G1AMVLQS1sI zbkpXdrya7irQc#0p``|;wHSm3vKy8OxdiIz6t!>~t zqwh98hsyN3&qj(q+{F?Km`#knX_ zC9GT=9F!d#*z>hz<25wPb+|oM>2q?hsY3GIxn-0RFu{{We=9$(59?U*csW%69zJx& z6EZO;B^{!-nU40{pJk6`%mhT?EJMG+{;$1e0IZSz>k`CV5unw?3z+k}1nO&Jm&kX! zn$dL3t*;||#s-!&_GHVok0j+tr)!bcV1z@~kx@3}SJIb5@#VrGT!$soAVfevnrxj( z+%|)n>+u*vOKR6mYhRmJrsueQo#E{y*^aD6N}XdLe6j1ffwo}z95$XRQS0J?gb3R3 zi4-pmkJ3Awf!iq}olh3QS3l$Q2=_n>yt*Vc9P)?JxaUuN&Y|&dUf8)_OpglmR-L22 z*KJW*+J{~g<9QU+AJ#Sn_zmq`VCV{d@d_R7O~_~CY?F?aPrnd>zqaJjrC`zfQN9&O z*FAKbF-fQm=jUma>=qn+Mc@kU>m7lVOW3J~xz8y2UZ!`wAA7{{cC9&v?i@F;%j8;X zJsYPR!wK6BFI@wT&6@q}nt`sWn|LiQ#s_vzNi=(tmyJ<9DFVh6I3xWMI)!0OtjpTh zE7k9>yNd^)0wO@XspXY~_ z*3Hx#0x*Nl!(Jf!mm`$GbOHuT;k8p3&FP~$GfgFsH7Aa)_csz$iC!9dxNLv$xtKFo zXp9^9hGz+|iwY*|W;`2wlpFlf1OG^04uza?ywkp5*nX^(5svy=Pq+t!Ab&%L`qKm{ zucfuLs{g2#npzhl|5T0XAT>2L`b(le5Ike$Dh1l#v!NF+yLkrmx2pchNRN{99pI{j zL^Y^Y?6s)=&d<-X!XpfkGZl2&48z4RtM%3J7OE%a%ku3Bc*(DiE+D%tIx(mB`>6J2 zjuiS02QU3`7$u6<6EmJ%$Zy}rKvicU_Z>C(e%1FPi6i4PN+eZRk?uOR%89dD#a#9mBRMoL^w-;`~ahBY0|xNTNNYu63F(b6UyEw!F93}alMKZH`0VDS zmvUlUZWIqj%v11K=yZq^&sz9u`6q$b#?=QSG(v94;~&Rn<=p5MB6KQHlWnFvuI#Gf zZ(5zrIt%JbN=ju6W-EybntFPAT3YS^)KYCw)l(Y+BOCQXq#P?W5YnNqa@9*UuqZ{+ zI>eOKR<=LXRD+XC;#;nAYKBsIk9sNn@RDVE+hzvnt2{M~%(Z0oU+!OJXTd3>ubRK)fowSCYjaZkOpY|fv~;zb`w@3AyDGDoRnx1ez1ZQk1Urb; zqRVR2tn4Z+B-EZqaD20znX7XuYnR**95e#^s7|jxI^QrOU@{(Nd8KMZu16*T<_JM& z# z)(n9-xHH_63+D4bw4z&DS|w!OXOe5}PhA*3?7p7Lc0HH}{5e3Cm#P-NGS#iO%pbRS zhi$A&D1|RR;IZw)54axy%pZWrr}E@?{*-x%6=gn>cD)uU`f_b|pz}G+D!djf1;6Pb zwNulmGQDMo`l38bm^tDP&Swn$R)gup3t-iXy296Tw=3%rfma1@Or{z znQTh&PKC&&U`2ST;HtQDzTJkA&ld+r;py-BLaoVe#|v<;x^J%mf86?bvOb4rFL{k& zgwKCFl7A7Afg;$uGg{OS*%-w2)WzN?Gp6aVLCDceoEJVEiv>$)!9RPttZr1j{UUj5 zRqpVXw7L4{naL4{$kt1^jle0TXw_J`o?!1?x@mP3+2@INS{=bKv3!LtA5H4zY*5eZ zpfMv4e{$K7IUc)l41TP6=Q!pt2F7Y(OdEk(k;eS9*^d-!Hbh7lm)=*W7q}3TyMVsR z`mPnWODz&!<$Kxc`J_#8W`fB}P|a{G?sRo)4$-<9)AZey{_i%YxQ(tvrf$Pls*NDO z`)fMGHnHNqK>%>DHn|A0@PGKAWMXlOA8syGvMj?>(nyk?ErXEDHuA)N9^iQRD_glh!l4lT5|O3N`d2LUv%|ErsEUG{#O}Z zOGaYN+VCp5vp8)Wq)AKlMJP(o|=ExwI=3OTrOi|GuY& zXHPhgLx+*HX@rpfvP!My`9R)pp@g({gBOAA{dJI)TLM9q;rnT_Z#6;a*h1jh=mByw z`Bb9rJqFaSm?fzi_^ldzqm#pQzo`A=Jju2#IS z`i+kHSy>-ha>YGw@EP;IsQoB8xdGT!Zm@cGbA({enkbtvvS(q6TGJN#^B<)EXg&2i zK>_cp;}?Xi0N0+su15T zu4p&zo06u+;EmYd5;>ZE?nbq4k9dqV$MaiErLsU9Dy!+`Ch9g`S!8CT8UJVpbvB1D zZzb>nHi+HlT}Vr;iK(g2^+qCe7LZ?afLW{rD4HCJ(3hX^1GMqx+x>~APNg-q( z^>F+uK9s~0>cy}Ngz0w{@|}L7W6>+?m02#F)je=iL=J}*UQq0;Lj<4hkE&fA)NV(v zpe~mR)kSajA!h->e$fKHcYNe?nE(U>2qppxqx#_s|J8rPkJq)R`?yPGp0Dxx;uM1ZUk3Vs4_eH(rjb>B5reUG@%55_rM{wT$ zfEpcZP-p0gAcvP}a|%#}v~-kdLt88qC3bUGjV?F^p_&XsCEA>C%apYW z74)0Vx4%re`|w7^#H>~Wq!0#$`$xR*v}Hc3w$nM=@Z+^C5Xhdc!C?*EZsK#^hMt6k zghyi|AgS_O(ZYXh07m!ck z$;Y5w;22tcZ5cm&Y%V!!RhvTi7zlXhj(T@)i7J9-UqmOAZ`%z`Oh6hM_;`5}Gp?%u zZrxt=?77_)wD+SsJzdyDO}vm+==iRm`gcNPF$lCw;jY)6QiX@M@;npsYa+Rz>swe& zJQb8f7Kk6Dvj5T;_$Bo8k4O-7-|QJAP8;Zr^mi5}J3$;JH46sSpT{73ub}FzJMlbq zWZ?9_7(`YYAUN82=f{WdbAU?_D9vQThfrwg{ye1bU-@@c4;dmyAc6r}ek_naa{4pS zU*gq&>S106{Y$^G#~0W6cU|HCAHw<%E&73F$bbD*2Lux+X}|=g88|dQ<^4;BT4wwo zQIEHn(zziUu6tYa{$aXI5ev(aN27Q_FiaJe zDuGr`3Tkt8ROSPDv}kSEcZQZP`mtj?MFyEl(JjUS8kaeXdvuQYB|~UHy3Ilu#E4Sf z^#>lJ3}F#Xdk;yumf`Q-p=SCb#meKiC4L^sMi=BQfxIY{99R7dvttv!Slk$8xVKnV z?QMoC6};V=o+xEK>HW3Xm;?3CbIWw?FxD8*i>@uuDgDTH(Ns3bIwt*t`@I{UHmtDS zkExhXSjyx`PL&|z%>CARNj$n-+LXc_czZJ;9@_;z3q{pvr#@f`!YT}t>_?gvofZo+ zM_vjrC%Rgv@RXVP${2iwkiZ(x{&XkDOdhZA|Ir}UrZ{DVV19CG_p7<@#A@ABsw$k? zmlay{f#^|jy2YA@2ciipkc*7p&}HKMBpKOVr(~@cHCgJr^>y0)Wn8Ar*rLCEi3WBn zJ&@S(Us%wFs2~c}a+{X0!5^S)3+@_a{4VcLcQ%NnJb4C5)(rz$zW0kH#!i07ip>6$ z`_^sX64J+_E)psLfgU zZ~fueO@Qo@h@d3qyohjKWSk&xKlrTGcRzlUpkmf_Wk>W%uU3>~{;M-5Wg7;JZ6WDS zbsn=$fjzP1n|I-2TI$-RBPXS&KJ>0oR1t1+pEFdSa8BWRChWq>3vKlKn>?7kWY(Ym zgS3#xTPwYOv|W<7+S~H1s@bge1nb1O@WH=qVRWWYj$h&n(_TJ<8}ICu#iGb3q{6h7 z0(rB5#gq%aZo_C0Rk-NUx@NB~fi6xju$hTz=KunpnThmmN@qJzuNxLEGNd4v3&btIoD4qu#57wFQtwFfqE5z3 zSAOztyD@6q?Yc&@aH?1#kH^sAXZug@2kED~ztAjwc$YX@e0~qp_cfg#!cLtyHylsV z6h%6kuL5tY(u-yKGphK~T{)IYXv{-8jxI`bSsj8NgZ>=+RKOX@mKjh?Y`JwV8HMD+ zZvvzPo)3$xjWv8Mc@sLe!1V{W^Lp17yxOs0MG!iFr5d|M)cR8W`u#Ec^m6ZY- zUX3({II9_V53RMx*{tH5CG2weuwm@+?bLHYyONfc&JF&0Q9=RgS4iCbQqhY~_;sE-mNFm)4`JaC}C6H&07+;Z#~79l;hpyPZnQqX|JA zy<3`YCM>&6r}Y^>A-PUwBS0GF;lB5|so*yeivsFz$9W#^bnM++4nx*Fc61^&Y<`+0 zW6|Oi+P{;B_?5o!re9t?%1Yc->-l8}xxm-hb26Nj6g$n1e3-E2 zw6$)^IeAgW4<@oP{nU>ZNxAYv`;4QKwKeO74FxnVLhEm-n5yMYNxSfCAojj6l15

    9VNP!P}=#`C)4;z{B8&NvCJIf1?jD4 zXY+EQt;sGafyX!-O>;N{%G@QKiA|MR;f=>m=;`u4O>S8qauA((clr8}H&-n!h&`zx z5^3&=S!CL zPi|h}t1_1-zANB*SkC;k$EmU3ayM&urqbHE@oYPt{y{+Hq~NN31LbtFgWFvecXA!} z-tt8Pt48>o2WoMHkZ0WC&Awd&E0y5Jjj?t2CbOMZvX`z(<+b+tY{_Z4-)L^~9nz^# zX&ApGl0GHTTL6k5KcwZZ8!zxn!SaySbkRG^puwBI?w&_AX6f%4r=|{D`_1*p;G$ol z{yO^P2Ur}I`=#7R${8pPy)Q4r*h4GE2VYvMfu9)q zze^Wza0prO2kdP<+m?im${|eFS*7x1HdjRDA%)!A`BovnKV61E&Q?o4hO0fZ!7BT6 zgw6w2nAE&T zUXs&5*yHC&iUAe19py&QmAs}n6^o%ua4*-cD!=pQ#c^&CTUYa|^pXkAZg9VxV$L}u zJ|1eMx%J%+N>0GRb259v!JT`)N;MIyd3*Xu8~U+Q;4ih^swCAODQ)mBm*+*@n!YSw zT4jt-6N-sT&+0=_w$$Hzvd;T;0cX1g)J8MJ3_9XxI9}hat!JlnpiR@M*oGf1ntR^( z>i6%`EPGGorvcAfj*<{%ai2XQCXdP=?|eM<^1zJLJEHiM9a9*Xy~oKi==}4H*)9po zOK``IKe{rvsNgM=UvXM$Dy@`n!ev^1z4{L8g;}vmMb(HZ+BNx0%Q+?Sbu?}Bip5a>nxVIszTc03yx6rD0+CwpUK0Q!M5_W?pV} zReZ{8i@%|v4L)JiJxq!m4ZlWB7we5`45NvX&KL!67*O>xNOlztZxjxx;9FqPNo4L$ zyIHxBvSgK&B+hmPvv*=n1AOQVq=QtD>Q$R9u7HYwaI6%S8!eVr^Mo}@T}$#61% z9DdL~{r0rL@wsAU{|Bxk08^9No8{4(7SQTt$9gVre`U~*XGsxb*6t)BYRS=w_swK% zWPe+9V}7H9&0DM?6;tC_G)X5^^mXUvv|N;re_OnI{Q%yYu4T4IaPy7z6PC_Q!n@j@ z&yZxN#j!E;0E|5hilc&R@$Gu@qQn8)n|hr6K9ad@}-=F1YKfkpJH1g78ZVB zK9ZAhtoUPnhgV=gaiCw{YF<+yC!7+jBk15dRsy|bbH8Hf(a=_|SFFMakf&s6;@h0r zoAP$Y`ihhbNswmWHK^Yl^OcfnY$9Br-kWi=x8kSi z5gAnWh^&P+Rd1&0mn$K0D7Gh1{tnNXBDR|Df}VoDW3Eq1%f=MkC2KD4tZZqgIqNNj zng?4+X?(6wEA+6RACzyWL~L(4xINgCk(osCUy6VGQMfdSt7A=u*uLG;@m`vi8W=`- zgDc)m!KDKtrzyt;ogJUOP@;ET0oE|Fr>)-FQ6TTVk98|B$Ev-Y%;?^ZbkUk>%{`)` z@Uhi!In-k-*ze$8vHXmodcb^}HM(#5JMvY&61$si z&O2IzTYfRRfN6Qp@Pi-WmE0sG^rq>}_Z3(N=AKB8`O%{toN(S(Mdv~8vv<-eMTu_Q?~A zw(+BGp8wwdQJuv907~5oDg=s}u<<$Yhn{SBW~@xwQ|Rr#ZZc z=CEzMwHeUkDJi6vUpuwGL|+nBtB-6qTcWfyrgt4@<809`$04_JIn75-eiB_=4dvkE zJ?X*0JSUkVneRhl72oYbuy7-Je!rk$86d;;LrGUiJu9!*ciEXde=?6I^RyAn>Lt2R zaWQ6w*!O?HC)`*Osqg8^uWV2o(mb<|a^CHlY70H@jI@s7=PiD#yEm0>Q(lyk(-#t! z$u|Dn0Cj6{daQY_db5?t<@@PAS8)1yyXS=WAWI(^WGzAFU@BW|d3zH!T1emY=8bRD z*&(sZ4{R?8MTP!ZqYwjAB8zhE$?CQ!5*F&yR9k-QcsY;FdnPT*Vk|$+TUOS3@aBe> zY0QtF9NW!8fo{+`2dGsu8g=C z9_lqKW^Jx}7~lY|)Gyq_!l%;=M`12fC&@x}*HXj6m$Yg72AlT6fTMY-{z#wA-kfNf zdT(i^EHlyNw@T7R_wN9zAwZD`l2WtS$LvWwohpU+B3{)}RxS((>j;}R0hv!Z=>NL6 z0Ryo^^&I)Z&Q7sB;09HCITvSCQk9MYPgyskVJ^<@vj!Izr%m~ z=Kq)T>bx`<2$1vh^8?hT%xOo=SiwJ6-L}6rTH^@Ox;2t6`%UBHN06y3x~_K=0nUH* z4zvn=T-F~;clvd2T#7RP4diPmHjMh;?h(+kq@IXE>Co3uzIu7^QV4D&?ZRtfZO;zN zNcoOSdVoRdH+P8hw zHg_#@2K=5ybmgN35sdEhrRT)!XeSOq!+%u7hm48{N8s25vZXwb>)*eF5Gmcdb$lW~ zK41%}$8q+fV6O|lH|djhH>dkq+Px4>lOX?+KPQR6h9LXG9Qwgp8=d?>?O#~qF~Qyv z4b?^&*_nq>s+1Msuv?8|q~FEKo5qwHHkeZ1UYu>$1Pyt(!si?4)Sb6pS$&txoUGE> zhg}HWz493aqd`I27_6tTolRz_Sx=U+cMzDK2C+sS*gTNfhz+4%&neSRGF?97Dd*N@ z+Y!UOc(z!AgR6Dtu(K2Oc3hFSW`5!n@6p7`&@b1ryUV(#i%TLWHF%6OC%TYxl1i~? zneFjiOJs{BDzphc_IJzP`3=Qt?R(+OHwhX#&5B-?Zjn1PzN_;SD#PP8;tD+mo1+J$ z)dz)%6B+p03s*i&9I-d2R^bItAXfQez}_LySHc-d9XuW7B#Gyqbp&QOh4q$L_~Sp_ z^Ug2d;BwUXjU3_l7BM7Wx# z!naPyB*ne$3pKJrl1fdoTE^s8(bv>@$9Kh^?mm@AhP*uS zJ7!X0MQjD}M*XXm)YLlX`%|*(Hqj3EG&rK#`j+*szGY}9;)l&PsOEl7;$KfRV_`4k zY3TL_iT~DE9-NBVyr?7d_|KzCfJZfifG0`}x2kWR_ME8G-S7A=R7UncD^!_0oG|e8 zO!na|(>XyQi;5yHx@oPy-j)|dyY-*Mp2ydnWV#4lqKuzH=9B9Ta8lwN_DoUFE`6SJ zHFs|;XjOlXt6CmHk7ywSERUcTpcoh{QiS%*cGv4|I=AL2mAGg_2R&m zz`QT2(e1;HbN}iVfdJLn(Ai_Do`pe4vaH|`oZ9+t$RQ4a;S>KTz@m?C^L+oP!tWuf z{m}{DY%G%N|DLfBH0bxO$r(xXzpkH3@DUaM7nk@y&+%lI{l-wD=>JfYH2aG%^=qCBe{&V8S(iR%7jL}6!CtFcL$hq0 zU>u?W=WD>hhvh9l2N$O#{l)x0Uf~_g=-afQZjJ4RYgmvq9$7)ObGHDwFnHZuhWFL; zP%Gju_(eL&e+fRN{>wCPplzmM;UAh$OHYNf)POtDzu{?CqqE!(Q93q#v)8)ptI%%5 zv$mYV9WJ8A;e4-LOJA+v0r!Jq;sKgn|w;?Q9I7}Zl+I;h$}DxZNR0D>ZuxEPe(3Y*?p9P=-&fN={r32?k11ZyzE}*t$Yq9^%}`5K+lulTh%^w z6jz5UUb>T7YJqo7ruQ2aT*%o9w>ZS;|4W)w^SxppftGoY9Swx#Pj!L4J($!-|5}rz zv$kugDwXxmSnR6JL|E^2Q$+74*R-TDS_}vn5Bytmm0wfRICVE$Pt@9Nt*h>QI^VPL zTR61bjeB^1L^18Hk2l<<)coMQ7{JYMAlgtXP2{%Zh@J7dACVRF8dMd$Aii0Jj@GC3 za1RD3}}iAep^gaMmsX4g{ni=hIvD@=9NvE zc~1YpX0%YYcD4k@NtN$<+0t%uw4N=Y4ZcbsTPo`pBDx$26+1F^@w^~4b?|!Ws9<+( zGVrYJMEEv5NvN`mwN^YfcOJDC7@JAb!^)7~+lnp1ZF)}-j~q~m)ugKo&^#1&9)O85 zzZ^(dDl4Se*VZ8qmD7mx_<9W`@}LTFOFQyz6T5lovliQ>7Oq!eGBHkT-0W7e=XS)g z(G!*=M7KiCVsk6lVsiLMS+(G1g+YVpyiaALcR88%Cw_n#2I;5>QEDGY4D`;!quOky zdF(`zbkvZ+OSPvJasv$r4U}KfgLDGA@FS2kx;2t&$T7S6jR2V2oIY+c+X)!HmGe^) z&uN0>9@V&w4Yf~T-Dm3jHaaPjEUFmcNlnZvas_vDDY^3}*P)T}cZYU_-Y^4%$mxl1 zu2G`(wHWP)+FZ#`(!`ciwFjIRu`CsATiY$lit_qxKW7Nxb=~(b=mwSU6z|sWX^i~j z+NhU;f7V%@hvA47SSuUIR(>&c*`HVDhl`ML9EL8IwFxL1IBsrgqW28xwOnWYn}<^a zG9%ALUjrl|4Myu#|K?AIeHX8FL&buF;N*JYP(_|>kw%lrKZS^3xbJT}Z-dQb@c)-+t>2X2ED-TL;43#ujEm_Q;)EwEk_)Wj${uwOuV1rUv$QxW3|z1okem%j z#(rdUS&NgJOLY-YrGV1y-r0}bysBB(yJHgT8D2_aX6rhRD2){j{U&ILpn^`kS$+R1 zwG7*UA0Ej%u_)^`blt4!<9V$$-+CHH>SWd%*=rGs)^xVZmbfpi;XQ9k0Uu=Bkr#ID zxvEi7Br_>39xrryVepmGQ_6GVe@)se>p34Clb13rje~`N9O)DHVuKc3Wzco;0gx34 zhvv0V%Nta`uMBd*3sE69_23uQMDmpb@uIl)5faJ}LDKZ#)TPx$73$Zbpk~`tvU#T7$5YrE>X8O3&yZ|}=r2g!k%q?; zW*Q!gGj`Q`#Q7bZp@vCRcE5|&Ro}m>^AfZrXYn{4;JwADs%hzBn~wKMecqhsjmk_W zL~px3N56P8-P6j?mlkhkmw7Vh+Q~B>klLF?Nve_XKsZpic74sl(@@n1V1i0fs`vl@ZYR)w^!F&4;LEi zQiSQcMrl?Jmw233pq4Q9kF`iI-*{0W1x4=r9UNfC*t146J}AdXk}|E<+f#S3BBS1M z(>5;&dCO#6H@n^Wxzk7(qqoX2;E`mp{cR-i0;m751*^p$4Co2d{bGQ5px=9+{ ze8@`3cp(pm(!*9a&h*Su3I1cqI*PEn{K}1j&Di{!uQn)#{U7f>dBVMS4O@-3tBYrf z>lh4V#F#w6H{SCB_s@L?F&Q7I@{Z__DEw*@Hq!LvuQPZ5P)as^A8aWrN;0C57N9F~ zJ)ZX|mSO+y#@{kh>i4+OPnzF~4{!fJ!p=G>%C>9!C@KO1N=hq;G)PMg(hbtxIdpfZ zNDbxCjdXXn5<_=McXu*B-dY%ZRky%hm+%P=8@nmqQDT`V&nUF!bO zlGOBA6O)WhFx3gjo$9%>F}=b%)Xfeot9t0ja;X!5lOt4?r$i9 z?nTF+hj@8iOTf)hA$zpG1*9L{ggTUW*8H^cE|$zyTW;bZU8RXiU3top8J;xEmnugF z#CoLx@moqECfmOkJ`Zf0RQehp8iu8gsdknN%cbH@0{Kfdltgbr#YK+oB&<}ZtEl?g zDY?w1tc`n@GE?3D(RyE;o|^#!|LI3#IWiFIQ5 z(=x6B%Scm#$PwBuuiMXLDdp^*`yE&1h)u*$IO(~sw+z0t*SBvL5<4NeST^wE5P!#o z*YNS6uMq=l)}U*Gn1p1S!~8N9O7}6SZdj@}LjK*k9JzMaw`Zq#6Ty3L#cjRwR>UXay>%1aHfFaAb;c8S5(VwV;~Q?DY%lS1b~cCIz* zyJt7nI(>A5kgxKX2~af-MLuKh*pql3wAHVc!Nm0AzIt`5Aby^BA+qaRF!_*rh1#N{ z*?5tT9-I?H3zKy9?f$m#aU|}@W<9mKyKdX>N{8*~HPXGbuPKy_D4N;a_1?j^9+Z0C z^bJM4#b<6sdUeMG6I}I#i`r)N>wbfxXy9P%KE^Mze z&rex*D>2KZR5~3;pi;{hW(DAS(q^ZwBPX}hzGPk9WyEfaam-!6lE3yzmOQi@r=;*0 z>;C!;FJH?nbZgA^&nb?XPlYiYhHNIMTR7Ffb5NqzI_}z5MupMdzw0jPLMoXvr5Tu=w3?^wKA92hhx!=!5{*nx; ztNv{9r&gzOj586Z)z!ob)meY# zDy&%oE0r_p2@;dx7CXBWB?OgeLmzPIlvs>?12WVV_Y7t#8?pIA1NW4HVaC_`>kZ%M zZ!pQGYu%5fNjugcSs(c9K{gMJXotc>j0fBN>674` zqQ33HeK5+GS@oW`M|k*F3ehS()|ys9u`+A)QlCV4LE7#USV=Mma?!5(V?>*}tE7_! zg|{QV?mezrvM9A{R4`x0(n9N@n!&3RvX>M#Us_l5RWma6mBaVmrgZk%9t zFvrpFmX=`EHIfR@N$=6z!Dd%>xXD^3PL_#j8ofSzjob0B-5~Hy(M6m-ippC*xo~s$ zs)D)}s(Kxr?8sUz)sV6(iC(R?2e$W(qqtHBWi@X}tf)OJLfA+3=<}Zc#yBo%)%x=H z#!U4s&s!FVsc#;WH}x3(X1osJ_G&ouO1^7cAI@pE`jO!CLDjA?wHRE9gIU5|=BL`* zfU8m7>@`!hN`UjutNLR-A2AlvL56XBr;2)+3Y7S@GS`_R^z1i(Uzld#P%=zFv-5>t21G%-`yzi=eu z+9dE?gw=^m;I%j86d9U*I~q|!$a`Th=fP zHoN{O?kco>VqwW`oB<23YUEcoeGNUxS&{14ysEeQA`S4n{1^+~oRln2u2#u0d2VLg zGbe&#Nmjhk9(li)Iiy?+_*88(nD_Sb{J?Q>X>-#G&1ZLPs#8?Y>4>9${Qy_gav`SMuCb_An4C# z%Yv}s#y#oXhFf82Uf0#sO)BD66uvI-(P>4|h58-s&wCVGOjh=ar=qQQj}{fUwKfS| zm7}(64rs7%k8mRTZs^v#)B>FL|J3jL3FneE`Ch*x^Cff>dd%xsBW@VX>)&!BvK-Ncu&c*G#OfbCxETbI3%bb9Wp?MOQtQGzzzJX$?) zsz=;=7&El61$A6&6g^AkOfP*NVjgiE-WHX+tz`_@bziJ|J&&UkrIKvH5-Dfu9DV9^ zKrf!4xU)m+w~gfEqZFXMz-s#Y{wifzv8FOC-Szu^6k*?xCTTYol1;y6eCM&gw6XRB zA>kp1;U#ME@yORwt%ZDyOB<8Y>l-CXQ-gW?+}4Kalz|4`@aBBX7+J&`!SKl5D~z+; zDr_%JzT?(vOOUs-{$}h7ned|lit7%Ud(+cIaBm}bwAR%sIxuC(ko!>Sg#GO9$}J7@ zY>r!2R#iM|A5&#cWDjaZTl^X8E$&n1aEF47cgaEHDDI4E`wJ)gX#4muOs|FK18aPz zR@L|Aa{AVU;llT6c}ru6bvyy$n!pR}*;L#2BAOmgL5yh;H`ePYnJCWb7*SYnXAnW4 zh}QG%#PaO`wbQaW{FIaPBW0-7FFzK7BWgWkS}~IU3t|`kqVs`N5phT!XWXm78bP5znLa2%0Iq4X4T!;8-F-yIPh{s=bzixzajcdLrdLA+ww+A?1r- z3@gugK*^=D>J+LnDj;jGZ8e1tRq{%l2hCq>>!S>T%vyYmJIwMU#~q1M#Qj9y0%^zB zMOw9k#a-a9=-Fhmon4&%fx*0XK!W!RcP&}&Q>Li;^;3A4M%!jj>b}$*8{nx$s^fJ_ z#{cu)u`k&bA9l!3tEbY%RK(kCa$MJyV-s7t9Gc9Y9P#@h*NaZaJvzD_%%?24GtL-d z*2JpVQV_1AemTyIj#Y;K(NZK-`-5$rFc&|N9jg=8PsWda`*RG(7G&L2B5N-=-7Cp& z#|XeVK7sA_A5Qg)beSa<8|&3Pf)3?j_5Md%bDJ#H(|bqn$0ru@uLNf3dbqsERq83> z!X;RphexA`22>m$2nl}^K72S#-B;(`$!Sus?A4tbw4%#wo*bL@smYgY8Opz&SFWXQ z{*~gee29(9P$Q`aJG#Dr8|P1j)8k^ElatXd{lA%P=GrV#BLcElU`eUjkFrqN#jAxs z{*n$Umz-I_ZKK0`ht@I#gqxC@A64t2R-PYC(%VNlo6IhDq#ocJpE}EUM@M_yD1Igm z@mKGhIFXXKzR|m|Eb+347r24ztEz~BLpqE%!^R*x*fCCDGH5kCMiEZ5j4I^DSvnHC z;~bEkP_5fEaUoHI&Pcz4J4I?J749>}Xc+T*w#=~>{jd7|8C#AsVj>2>w=u0;-Bs;e ztEA1tzoxzoqupO#R+#O&-1p;Ebf}2IQ0C-R&_A2W#R z;|BKhNC^urtaPq6LP#W~XP8B?ptW?ypPh2E?gq^#ACj7MZBR}|1c^rNZwzMx7X^~&AqWaHE6**Qspso>v6Gk&ZOAILpj+x0Lv(5*YkB0 zez;D&lX1HHP)dvO9)&0}&aOMIo2(I6c8gME*)zIwuxU)M zFcGY{CwEXp-s!k6uN;pOFvzfoh!(9gypy#FF~m^D?a#Ijk|#bPuRrm9mQXqZN{={N zXFv@7sB*hgFRZFQ9_=e)(1b+9O*Puj2;C7i>Z;QhXbcM;rXO~Wr6+PgwoOEYJIt7&Mb zI(}vEFr*V$qOi?CmT58iJn&bO1{!4PjG z_(yZ0PQ@pqe5bh@9I#RHxtt|kK?h?ujEq?Dr7XR?`-HmFNt_aae$9M@Ns5 zLRhn_!1jaIV=K#jh&#n8IfsvL14VAm{i>w8Gz%tSA?b4BE24)6<~ZQuaxO+6Mm+}_ z#>=*uJ8bl&j0Vn`Ry)~5^~_M6Wtv)_;3gBRw?&i@S+=19xDzUbi)AmRLRVOIKWkun zer+O#4sU2^Q4-_8T!m)R@2Kd?ZB)ytfRkK$2i!%VVge{@n)f5t@WRC#JEJI86)sn@ zS11o(VGIk9>gcCB64Vq~OY!q(2E!CI7y>>UOXIPc-~M1{vAO+(GvfK0bxQykeWyOP z<>=XQ9b5EheWRF?e4M}}WufkG@cPE{rg4Y&ya>(P*z1hS-QSAlk6TnMJ={X1h2dF)*0^Z2HT13U{yMP&N0N+Yw@o=4UHIpSeyX62ihs6jM z^qBb8;cE3cO1Jrk5teyTB z^XIj`-!F9%s;%Dsv)X=w#?G%+u`3GN*ynVAL>1Mf_^Tm{?b(dY*jXTIDy0*r!iY#X zPxq!PGpZN>VH=0`DOy>-X646!ZX~f?mMj3^q!wtr>W61WgUpfunAM59^vdu5JOV@4 zq{(3E)?8x}+u5s@_vf0y6ygeBI*H3)pki7-cyX4Vk$}f6#`11{Vy^a*o6@HL^$*QO z&O;}^j&lg4y15R)41M);7WodpN39owYoRaR7pfHioWw%#bB{iB83^g|_f4L7#S8eA8< z8}YZu86YJ7oDZVAol$sbkSz)B^7gU{;zI~dX4MC|hjnZYIuDI?-2N|nQRlxWt@u9! zBLCmu`yWO9*aIl226zS{C2hyRi=J?Ce!i}xLw63#r_3jgQshc*Xt>!acARMPvV>0% zj2%c2xjf2S3(h0h%T+COG=an6zyxwO-vdy4Wso<2`#h`LPX>9AC5)n% zvqYy@%`NQJz6BQK`4S$I6f`xpL@|G>NUzpro`}QZv!t%>!ujr0p-Le>Kt;pGZYvbz zHV{Cb%UM}nEfmQTjRwbwX-Z$T*6kmPQW#0LHg<(=UuSpMRYw@P5-ct!IL~^7DvPax_H9tOD*{ERh{V-+=dTH;JJY6ggvEms}AEY~6nz z>rFBw9OLjhg^mimhnYbfh^dAmc0Szabt}IMQ@xyS*`;Vdw~FOx3=8MiWOyYiraYZv zTAVzl1xjEwTxzzmJ=^12X$@B8eJ`Ec!&m3F;>Qmz9h4rF*1aCBgL{%{M^e)Hgk?+3 ze{}9xBUd4U7E=J+oN=J|lAN3z8kZG9z-$w}KV2zatQw+72uT0zA>CSn3T;x&DZH+b zQC_W{yZ+;5*&zz%N_zpvsz5H=1*;3WnBa{zE###yye7$$<$YQry^%ME9yaZilnA<}|IEo$ak5Zxx7}OCQ5X)HZ7wzL z6^N5l0(a-Z6JT6a-vkePE8kqn!{K$LmF82vHRjt@bvjUfsHDwIZEz5RjwL3e4xcSS zg>vV2MMmUTkZMJSDb~smb6MF}bgOg_$*#X+PPrZDB|b-qkW@`^Up^z8s7|KC2b&lh z$Ls7(0#%EEh0u9_hJ%^;us4Q2Lpg$Oi~$&}ii)E^9r*blqX>Q~bTqUIuIDsZnw}Fc z-bfvoF)=dAX350Vr`4aGo!#DgNolv*T!$4hG@DQ;O>e0@AmAp8D?o`z1%K~K=bnJ5 zR3r~qIN9RBAKeLtvb##sO{JCL&gvvN-+uI9huDfI=R1pzr8^f})_l4Zi$}T9Ex{CE zsJ})udx46rylmcSe_WDUivXyht69h6h0n$Spm_vZ)hKLk4r`5XehvDGL{96rlpE~p z#nW9*HBECm4nr>BgXaI>NbKcxwdw*JF_=W22a~jJ93{q44iIzfZOjRj0myJmg6E#@ z?kc6aI>u*ttOFFRv2#uCY#%@V8Fm{3Ub;vOZr3*3RdegT)AZ+#*aMX2Y_;67>Go8PTUsNs zH6$j7pRk85VfQ_e2Oh?qAEeFQ;Rbcri~WL(EX9md`h=Ro(zn%^&<0=K=B>twhXi?R zTN;6udQ!E<_tn;Zfdk&#MI0Wj24uC3-zJBAi>1WPKT_|+2Eqwg1_1v|22WGPd-p?X zmgYS)*4W|(`!$5F-#vh4T;D!Ut@JHj_>Eee&jT|?R5o2X@X zj_&waQmYHf5Yyp~t2n0o6S7PSxmIZc?li?E0O|p&rDpGiHEI%wGwr!t_RoTq2ld2Ab25*DJo(! zzm49Qc$k3z@TAh#uf7-^BX)v;zCMg|40AYu`;e5D&djfRNvFV+7WcAUNVQbg`}WFS z*b;E za_P;nhnQ1?w=T94mpoRSv{*_C6FzGLcj-Dq^{teT7>ae;f~nJ|gXr3!@K;pt83qia z-37B_d1_zO4nI!^@z~DQ4Kcf>-tNy>3wR&-j=~5jb8PTgpzla;_fCy;1g_i%P(~(j zHt%m5*&=bdT`nQMuFxzd+mg9v$D$zZ`sCtrO2gIcE`r-C_w_9N;J#LZb(1SZqY;*O zH8c28GcR{;!~_xR<>vSKT~K&QwdaCkNL025R%=?B{zny0hu?$W=b4ihe$Y72uf0;j zvE)A=kx%0CVrxmUSgy0zqarr^8cAFl9reL;oI00RezuIwp#A>(X6>_bTpWNes-sGz z#% z4B^mtj3(>yxXcj{c*tIRv)*hhx$9^gFXiPZmiD;%KR;FMoi7r&7$I`S9}1H#=f=HXzegUw2_q3i2wPK$Ag zHCbTRMm=OHqCdU3;B-1C<8jJ+z#Ix~RZo=;`7mZ02Y;<5Z5t5-Fo^k99`Q7R!wReyTlhbIj4x#Yx-c9KDw50r06@CK(QI_QQJY*>2xd(p zhvn$#7OB%Y@uS+5v0V9m*||yw{~q_1nQBX1Q-v~7RE2k$7J$=wn1SN(v1{+gVwiJi zoaEv4rj~HoME>zhsn78-ktQG>9qtg0YkN&`Sl)Fx=j-=0*AwOoaNO}~+lc1PGe)ce z$6K~y?<~nDZ%ts#I-DoFQ=$fTPVD4O*=a0!-dT=~6*JG`uF5kFzIxxH#SKa%(4TBD z^czO?f47axpOH)C@X_ys2`*nY-);l)L1XJ|D#iOLUyD)c%YdgG#2+1u3ARtlm8yI# zo{Sd?zDkOaPx*r6LT=^P-%QL^IGy1UfD$MQLR@5Zb$(}k;pQINlFw-VYd7-{9jgH6 zrOVTQvZ)t6PLG*Rh;my6Kr+>CV}jnl z3=LKpk1?L_@*&P2ooDrvhQ#HbrI6i-^y$xhiPIzcTxVjG(e$Wg@99+D5a+Khb}iPH z{o_4LKgw@J;^97tEA0baTQW`#H<7rD%lAH>Zk{vosm#q>`Pq3EOT@!wY|ap7i`v&rlzK1VgUJq7Y!YqHgBMh&B>FkX3q@Gk_MKc zCP-7HfLXY?o8f?vVvM!R-g{~2=C`G@#QRx84j^pM{#p?pHh+t&tU!wPDE|at5()cP z$w#$B=3!QDjtGX0=9<3~$XxuFO~uKG`~7v89=A`2!n93*cP zS1aw*P?ts<*m*- zLYCTvOv)*7?e~x0Ks5)z3z2yBrL@#G1fNkPpG<|*61O~PuoM{uGZX@uskJ3f;n@Bz zwP{O-8@2w~Pc9FDEK@K`0(+Z{O)zvS(~(i&aX3{{EK|$}vr`LEji_o5mgU}(xUhIWfURQtW)^~Jm2k&;0Fo<&q7hltVYooA`K#{*UQlG1)r^^>} zb4&_1pXn1!>0-LFo;tw8(ImZH^Jm5^XxBW8&iZ<2`=^;r@cwFP`J|TZDaX&N!=J}j zJxw{bELmV3G2bR@y|!LSMyx^d`}%Z_l3QSl932^%!G{jO@e(PJgwnrEqs9YXXG>CD zs;4L@ND_w9gLU5;ps{ z3S6cY#|pUQKkNrMB@hO%g?JxmQJ5fAwfW%C&xD)WkesN@)3Xu0P8B|bUnN@F2tM-j zele#`@)*{s0h|#PJ4a5dzG>47+au;#o+tT4D)@w!UJaoMgrqI5gG-22kaja1(DE-z zZf;Yili0FR28<@CEOw^#%kVd>wY#H;)F&kOD^HF+Bp+I8Jf|H*lVWW#Aj_EVa!DjO z>)Tz77dP7{1p482=Z_|0#@Ti^nkqkV+`%n1$K-?B z8Lhnnj(sa8Jp^E!$2(7FUz5#11}9zTou>d2u1L#6wgK2)+V*@!Mxo(c0Yjc`Rq0fk z%7T7u4W|n?-JWfaIa%aZf>Na1O+0d{-Y#_y4sP7ZD(?fxCIbV5s+R?6F)=1L`D)Xe z!f&5ry#aha61%Jn$wDluDwus&k@-H`%)=~li$iDF=7BWr1T&sh?T!u(Kr}N%Nez+R zt}iPaE)waP!KB6VXbgcs5VvC&^eti9cVd8jo)U`RDX*Clh%ksmfPI(S7EcIl2JTJt z5Dmz1Nr1g(c}sm~TwR~~P_uR@B|O_Q+dLgbp+pBPC89aX*RPIA{~%qcO@A)@`P)dm zm!M+AC_su_)t^%>IPnhq+Lo;`Om%qaX=`V}T1y)yDT+;;Q1;LF*o{}=F&z?ml_PV5 z>+9RccTr(PQ%tKAyovGAcjs6|MSN<;7tcqnJjD(fHVI4Xo9+vF!W8SDc z&qQVp@`q`&#mD5&FY#0@w*tq#URy(oj;e~QaoRb=g;Dd(9M@iJu17~nvJ-QoQK$H# z+@Y7jaovO8;dI>BMbd!pn+fsc`o>Ov`}>Ycg+$Y7R=88b+5Xw`qa@RCFRO92scRV% zqhZGE_P2Kd-d-CkUuVT_?gTCb=?rwmI z#B89&`(|Tv^VA_mN|Z`LK>?sTuE%V11JQHD(p!MCozA0-00{6(RU#buKVrv8kTMr`tDM=#si=RV&qf^yrZ(Rqs{*!vNC+6|djIPpf3Y zQRF9wIfungEV1a9!jNdNBJ_OVR6IPIYgS9V`)e&~nxDsJa-?0Bc}F7em}3!?V|NE+TsgaO6swbp6_EEu(v=sKV}2Bm z0S4a;Ls_VKk%PH%pHaYI>E&-*a$d)uwZxwfQ%Clz2QpU?Zarr_QUu&Sw{CKBn4;8F zhkJJWGeCQl>ySZz>si%~oMDXwRbUQfePaiOXcMS8UsQ_XwF)EIP#zy2>&k=R#vwNC}5rQAfA=XzJ+TUUb!0*Nnvv4VMb(bFfpgj9$gtsH2=F5jwC3zs623EtMtJ z3JTFtdi+{IO* zvkz5$R7s8&zCZPa?kG{E?bw9Pb@Tf;+F3VG&GOhKNUEP4WMX>%UImO!FTN2gubO<0 z{^G2!vCeT?YfMc$*ljh19iO-`fjoU8B)=bzX5H?le{sWUAMQ$165*N?Z7^b*s#v$$n|FaJzv=Dx95z z%PBVkykH?G=`J4gzOQn%PQ9A~wtJhKYCtfai07HzES;pXHDNv9Fmbdx0D#BWbfWM| zM=#mboL!!Onjj!2Ka|L-K3#7V&H1i}xt`M8M#-2GxRxGK6cP3LE>Hntyj&`UzFjCdB?&5P+h%>JKHbjaq zgu6H|-VzH?kC5o%DWR$*nsJ4bnqEu{llj#%6k)Lf1lwbVa`gWx6F#ulG^iZ#k)9H1 z-{H7roL4v5e1d-Ybn`C2&@T4zUmXb$!;D3|wh_%tYzkCN5(?LMD(IJ5Y5^L(?0@lK zcF36FLCm61Rkgg4Sg)WSRluVGe0v=gbuGBLX=7)w5*`^i{wuB1PR()swKR3gm8(+h z2Y=3DspaDuS%J)F2jX0fVL(0fCx3lwP282BWHwxd?zNtS*LniKGQ}$`Rt}Dp4gGJE z0zqCXJ0F0%2z)JVJHt1<_=oy$ zuFony21I|gwqJ|}fA7ne!jGe#A8kZkQZ=iDM8CV$qUB%ojd-O}-A}b#=bvSaZFlnR z98J9cB8Z%uLXRi#Fk5F2nxNVTgHSt>xCpTM*#m!TbDa_cw4agx9Uq zvj3i;3989`lVTnN@X*>GYN|`69E>R*#=gFQI7P9}rh{v0pUF@`lTjS{pjp0qVw}>& z*7{>^#<;wb4y)L|5`EzdNI9(eLoAsbMvZzc>7l%r$vn3L%oA1P@NE(go!kuZY$@fT z4KI)Uh-W&z459wD~E0v*jY4}WWiy~Sj*_=gQDUk`-i3oV(dF|hg($P%fnzP>~w9$si7g;2e|zFZR!cXQW*W4^--CV$R-4mlMp_GN9DzrYDm8eV(f zw~WP<1wU#NN^xSb2*3nNH!7%e1F6>X&Q9>Gc~7)qQu?hFP;P&D149B1cf+-C^4DbK zujFJbmN+%@VPg~y)~g5WRs07PKLftJw zB{9CM4%=Gdm<_dxr)uXND}kMPjyC-26%3AMz68G1(F)Y{V#O4Ir*otELC~iNY+4tA0>5tRT*wmh#5vq#>qR=rp&S7q@kXH#Cj=26w7wMHd&Vvegs5$gb2#5Ovv z5#*%!UlK#oVpM-I%czko+^Lz)nHq5b=l9v}2>4?Vik8S)I-OMN{cQ!=o#zAX1gVSw z2L3AAOPpPyA_q=6f(?6sq%xP62c1f-vxVJ7k~%M*bQnBU~3K9{Rg} zz6$+Y0&j=+?`I5f7yeyDvHzEI1nqzQELBfY3@lJ%lbd{J6EX4Y(}zWU=|%DS|6P>- zVKn2XMbAQ$nOg3>>wWg3^3=O9Ct58w&sjz~KJU(OxBps+_YfSZo2^4U4*Rj1h0S)9 z_p0du1R&y9fC8HuIjD5<;~mhvi#e@m0KGUJDdhe({O#}MDFAkf1S}0FmVEj3JDJ;D z^198yYa8vPDM=UW)T!743pb_v*FSS|wVj(r=DEiLt^6&lr(-bhpOae0JKpa1_&qec zN{u68of27e0d3OKd?xY19PtyaVd2UK`WUGWP};6)CAd4ltsiuLj^N^2qC+^I62a@$ zwTi0q6Ce-I=2h~(}tN*!Fv7$jejmvkO1Wfe*zzP)>`8=T=PHK0k_|Tu_AC1xV?4?&m(l{3Z@&b!}Lp&ffl?sS6AQt{Y6DYj`B@k zjKr|^QvjZ(f;S;)phc3w)Fu{w`o%VWy}2(Zkrsg01UUP<%jF*mq`RMIwgF#Gb6~UP zRaM@q8RrLSnJE6xr`Uj4{1ND?x;>U_yTA@UsCW*CXHge>4^0H8SUeh$0R5HLA zYA1imnJ<`TO0jC?QVWIx<0{j)#e;=6t>swZ$J$$W?WP#{b-{(Fl*san`$?oTXQ}BC zXAhYqQB5ENq0`_529n!pYQY;+8E>T@0VW-lADxHpWVUHP&F1$w9TGfQJG5SZMq4V0 zCO3&$%n_v!YTD#eX3opOYIRoqDpmy^cn)Y%;5d zXOU+}^J@iQ;-GwViwo3c^a7FMl8`JFPFkRIXzJEAmF3zFG(>-N*^6K1=Hv6~k7u!} zaIU*}2|W6_$kofS4E^2NE+JmdqHL%WNH>+A2nFG4S9m0bVUFFYp5}|-j;Qi7IU!N~ z_uY$Jh2n4j$(kw1^-HrR=4U5IupDL2_h;5VOtV+YXL%q(sm(?gWAl|rxIMm5Y zTk=u(A}FV!!qL)=&E+ZFfPdtd^>-l}le$kMem#qABkp{bw>WuLR_LHO0B&r6*S&U$&qKIW{Ap6y+E(Gc8`nfBfTuVuJ{WR?lDtJT;JxAiIDP)|hl0wH}|T$`d!;dT@=W=PLh7B{B* z4A`a)e%NaU9Cno!N#ltI9NwMnJ1&Jbk5(vHS>%92aCuRJN?Wg)C#@9H-c{NVsOqkG zR!)yT*ZQd*w2kVQsq&immw9;;MvoI?Zva*M`vK`3=i}nYT5esRu%aBpFc=|*KhA1c zYgw1)%-HTD%MtGVU%Vf}nnb9grzOZdG zd~rS*3isokhOpG~O zzeR4QuxwKoggrKhFCG=&LZqpKU#skKBF-;~C67CKm`rc(ijHd4!5a)?n9onMsfNfu zQr=o3NIkUDitj?x=1oRR{qgfWQhgB>vXLF5*Vei6j+rK?iVQLG7R)9G0#kv$miN~Q z>qDmzZZo0#8Am!`NvjOLke*Z)_pdKf?rUUs--cyP^yuAfdwtm1bJB$$O^wn_oi}~K z`R;$IUXwy@C0@%IvCXxOFpE8mjPR%T#J&KH)i(1<8rbd`ZtK7$f;2d#MDSv>YlDyl=c*554qdRppA`4bsv@2k`Uh)~C{!HXJ@tHe$D~6)nsER8|$3=?9S)HOtVe z|FO7j4>b+$mNYCPp51h4s~81gSRo`H^zmH-7#(=%w_qn6CQD}2#R%+eJDA7~+?m6}chlf~{e(wKw0Fk9 zXj|d~liozGrPJc;a;EwuRvHh%!od+a4oBwTkOf{IF$f- z5yCmTBcLuO&uZ(NZ&~QY2V&rQt{$$(t&GF_+H-fRIMWKCnmt*qq6=kx|KYAdn`eFV zjrZK8xy|lo`8P>ng_-(hPJgKlMHNH+Fo&ouVZAJw&+*kCwUeb+UaWqLN%{>FM~963 zKBF=E@`2ZNC*k7o6P^f=X7V0VSnw5x1CJ~F`(4i&tf#%l+Hk$B-0j^~9CIlXLvm@~ zux!sWqmf6n!9GW;4U<&uhuxg2a$pqPvj3jOqUY z(|n!V`Amqm1Rr-x%T3$ON}wf=YI#4(k%(gw%)a5m6MLZU{@HKS$`^(AsfQEx@%XiWh!ZOw%8Qo z89+wm;c_+$3*>9{=umeDpDx<@d&P8#X-h)z8S2e?!*6)ixvh%GQ1_BP8Gei)QxDP1 zcqjBy*wv-=J7QMq7FB%|;e1CIS{Wba@A~DobM*G~_qATvAE-Tx14rj#;t8|Ik_&D0 zMZmHWh3bURV$KA}G_j**am}`1PaYYGOYqTTKv)tTe?JA8z}?vxU`l-NfENO?ukz@1 z0vZvEVB{%hNN0>UN-3rgDi#$Vlg|y7aJ6V<89Os0WQYDIIBRUgzVBrK^Q?Fx)n?w( zR9g5|SsW^Uld2OfPofqy*qeDf(=vlf|!-+1c){E4K1jYY^w>BqFzT}pKA5idEnN)>- zw0BCfHFd~VXZ9xbmqn8Zco~CsSlXk)6by|GDh3j_pVt$-uYnj7wU->s4WjU|E@5ZY z@whRU>$^uxm}MUaR{8W9VO1PjiRq@xdZYa(BK3n#f~(K=WodI_t1Le?`;TDU-)>Ik zirbz@YL(!Xz)yRjr&GMz18$)15Q12_K*4k%kX;HV39Sk*%$@`($_wOwP1_97LB0{c zD(3ZBZxHj?9@@K)Itl!)oaQrjBjz(QsI(1WD*h)jeT70sZcRH z#55+{ADF{H8MK`SdLyYH2r{4(V>ADYyA07(c%!S1SlFPP@F(Zi@Sy5 zgBMM43sBq%1P|^S+;uONnfbom{b%>t=h?sRa|6je=bn4cJ@5PegvaF^{r6^jn99dh z?!lVOqd_CoAEjEKB_Z1HiNy$$%rxqPWaNU-Kd2XPr9<|pHr!KU+eR`EH5n_CLEo?h zhyB;z3x++|(5(Vc4~C6C{@2Nc$_04na%GJ70H~OHo*~U_O%2jwh})*sVybs@PFhSt z>e^KlL<2-t(*$a`;c&^CsY{39Z04wnI`yp{C#qR*6R~*EH|R~kre*vC(=OGvtTf7W zyXn}nQpk{oLl*Bx5}A_!2^!kEa9y|K-ka?&csN#?HB!NoHII%o$7EzR^JQ`q zmgioOz9t3CK)!gfc$~PGO-BOv#P^fWju;?krtAvFD2e9BJ=<276%_4qmaZhtRe zjBD)d?g0Ao->@Mft-8a!1^@}hx9~f$1D+$1{wrVxbO8%>%-eqwIe*j^-siqf&`^h8 zMKeOD(P=pg<8h^X_pY+3UkT<)bU#q16Hun@g(^iz+TNH`{jx{WpgzswOFr#@D$t}5|MsW;IA87De0gfRpXG9brFV^uW{ECiQq_2Uk30|>k zoE&@2q6nt7NrK`1!7t3*85J=i7V0Nfs05WQYXLu?C^6N14S(PJ_kD+ z>R_3dz{5&C%eqcz>#;DypV}PPHgIBt!3>X(TXps#)3|bMHqK5MAMSA5(nf<2(%l6^ zaaYVqr(Hx@J?*(}haL&<- z{r(o1i-aPkoNdg}tJDG>W4=UCUUbjiF~75i(%R%>J>^4@ZWfOr{-9Krpnkj3zn1$@ z>*|G|zkobDvWP9IlwKhSl`drIc^|8f$TPa73nbZ3#CT&^TxwG@0^nSiUu23~mkEeFOr%3jCcNh4`is_-9_2F!CVlROFJDZ=dr=ufM&? z8-4MNn~;{3;&ieFA1`~k2H!mIrBR>MP{0eV8z0A00oxrKJOzx9vGQDtG-ZHkK8rMn z4M`+?@rOqYqW4dBX*tU|b4hb@PzxWKXzfQ`3V_~rkI{pbdGg4`eOYcUZ60z8g0ysS zW)RG^I>`o@;?uvxtCI=zaJgsjWx-*z@}50i4v%rh)3G`>;QfSM=%~Me)sBG*)`NNe zegYD93a&-n0d{x;lOy)9?{Zv}67~JxNM{Tl@ym~UqAkxFVcx`laci9OElLUfBRu`Bdo0q-ik{AAq)YP(>c&#jo~H7T3Wss*^nLRbD5+bLmi?9;0oil1MZSuTK`|FsnY*13rJx;;6A2 z_@?Ze8%Q`C5Wmhot9E`wTflRkxg z^>&%Cx^OpChU}j;Cx>c!VPlO2>o3Dj4rW#N2l(tQe7qgvcRj}Z*>6der00Fcd94i= zvI(KKl2K4O1GhVS04!Ektdi_fZ13`ufJmn-v*U3P*&vTvtfE{rO+LXK3995>gb|*+ ztVPorxwpuDN(Tl;s7#6ZyL$p=W@_jZ?#TW7@gxnH$>&B$Gm}^qwY__cE3eE-v>*5Z zPfYDS-UL6@AP_Lm0tM?EX^daI8wgKl=C%F`JTw@Ba!dM=+IxbIVwFx6T^+yO(E3|q zbwYZ!>jP4gP3q*tPb8JIk48v7UB+ye$`sXpO%e6BU({la6O~w6Q$*X`bPmde;A>K| z2L|>ziL|i9s4W%90L2Gcox@j&UFTyN7d2hr7I%wV@8Y=vlUDk+6ZuxO<#E2UaJxRW ztbs^$N|=4wJ|iN-FkrK44jeW4 zM7G>IMSRT^ju;RIvBq^8 zDx`KCl_%ve)g1Pw+l_kt#(tF99CVwwUL$k_>Q1xJdVQ#tm_j(S`9N4xYuGTk095t( zS_eIAxAUyLTs0A<>A(grBN7!j*BbojQbi3-*31|gnw4V5K_UH`e&@+twh+Lv=1btj z>iUs(b`B8Yq}p*b`4$5W1VMUaOH~{jrb!Ga4rgDRPhe<#P=;3@+wlOc2bNLOsjBZY zy#Y6TXi_IG21Vj18a;(Io;=$1cC+J#cy*5#D&*b;#^Jy(u#eCxMi5_{kY)|3Q>!K+ zmgl6TD5IiPVR$sq=aM!%e-m+reE2P?l5Ns>y^1&-L1kDE7wSpmF=%dqBMmg?&u4H& zo9Ie91Qo=xwulhF0W z=qC=!-s0=r&!GmRp=X^nYujhA=!iq0k3<3aPk69JW`?w zM)R4H;4v)NPy3^6)q+VTrS?(Mac{}dA@H7`oW6MqYOt4r=R(WN9%RNBSiV(5YZk_{ zJvwG`{1}su$6=#hRD`&{K8ic!SP|{Ll@QMCR1uB8$d8jN1Yn+ptwx@O7xza~Pc(Wi z1l~R6Y`XrGiZ?%Wi*T2bCMdERe^jruYamBmZs2`KxR9uY&J-=j5Y_wYtC~c_V9gPq z@a1OXs15R%m;J*S1&nIy1La*DubKX?S<}QukCT-wyHay#w~FPRJEJsp?~?)-d=psD zu;340)R?X^+P+MW?I$477i2Gi`o`m~>u>#m%yG7h1vF(P?XOpgMEV`-fwH{crkvED zOttOR=fkpeswe?%4V;l&-Ea*(!o=~+X0nobQ}NWV1zD8cYG(a8OkQcC3bT9~SKBsv z2F-K_Pd!m+idmBiw`JkdF#R2_s-^bE3{udPxI4kEAfoU>{i z<_~cp>)par@N=UlZ$Y=7-vkwW^vTX*#yzjwwPC-l~?aTDD_ zl&wRaWf{0F0}{_^eG0W>|EdN}-6j;~eXvK>S9__uTXI60X)b}_f_6zd<+Z}tXL>)F~CR4s4i&u)Qh_eNmFennM~?nBKx5Oz2$?e>+p z%}>SZuL_o!$^-{eA{pgR>1j)frAT_d?3WAn?DJGr*}PG8eFL7xeuF970BWKl_%jT3 z1E=DFnqs_$#fPUNJkq&r=$yf`<8P(NpazI5MFl*UWm99ow61;2Lja-j-Sn-seeJ`k#P5S94Di41Rf1{lcy6#oE$J-{4enW(+Lx zeFu(QtfS<21I1VM3}`##;j3>qS?;drV5^R$$DC-<$cLp%5TYn2}vtr^nn2%Hg@?9d~v;|Ll2U zbh%*eTP4}a&&llNr}N2|I*u~{NG*U=_E$W0r3jtBVKtOLi*&~q-oXo4d6I=#%DpT; zUqy>+x3ApVrnd)Cw%zB7y7Png4hJ#-UNE6XhVc&ezn*pWW=i_M5lI^BSqzYkDB0iC zG3U>~pPaqI1^lQk12Mlv5|t8Po^p+hUP6qG^B(@5e;#(XSC|J7iXsDQfSW4A->zUS zKOQfjL9|sbUmx~@^(7^dJj|(OQ#1-|ym>Rb?ycY8`><@U@~qbPZr4{&-F8nhUi<_) z0aw`{Z4SMNt{cue@N|=QA4zK-Ki#NY+jzREdq@UjF&$@*p%Hhlg9%x^TM{T7D`-jX z`eRq?U(;lbb8s`;dZJC!a&Xn?7&EkQQI@yn`8ZH7;B)%mk@Ud0o5-d?eXZa{dpBEe z5I8X|g3kIk<@^5#HH=W2FA%MX2*qc#8x51A?Hi(X1o9nC-+1)oyX)T{X*-qT2?f$g zXATMq`-~$26OPd+o&WrLbJl|K6jLt|kpE80bZ=o2g&-^28FqtV21-h3`!G#!rx$c?F`o-conMn$8-AYNmK9w^Fn z%Ypd4({=@<96o!h&0E>gT@VKb+Wl6Rm^@OkK7agO?HwpQ05or8(T2_O=tF2HqQTe^ zT&nv4WI099hgv2hz(OsnIqWAS;+<^x3n#3he3)G}0JRVaC?h5Q^_Og)yCkX=G5(A> zWogR5JSTp_N7S*lSN^9+`(*Imatatib%s{BG(gDlcT0AyKq{*8GZl30lA~hVr8+4bL3;pri@ zf?(T#8_aWmK-{3NOeT_@u$^iDSn9)|@|Nt?OXOHKI#RX8B*H}FS+P@YDq%E5a6F?h zSCMa9W!n5EB*R>(=rhfimlZ_i3R7Vbm8O=EP^y5DwT`4uHK@Is?i+by()VuFb~>eK zesi2UN!Hj;WdVvY{l zB*MpSuZ9OxP(EO@-%eDXfIR<@~vBJ3h-!(~1gvqgC5n+XwA*+rttA1{jCrjM+W@QblTm01gQ`R_-fu z08!B8IG@*eY*bD%^>ApA4k0!w+4gjMUol9OzQY*g_}5F(xT3kP-WXFY@9kzV#KBG8 ziIamRmcts26i)Tys?9o)Y>%%})Q|IK~ww z1Oq7wGmV_L;QX?R3axw%5+b7crKP3C#l`t~fNLl&U+@;7-@EVl&#Vm<5WC#Ea>xF2 zzSC}f?%=_&em`X_InPXtC6eJh#-DPLs$cKaMC{Z>dj5VK#;}2X#SYA7TKuea(V=%Z zyfbYih&msUrWF!iv^ByZ`;hNFyL8?L27~L)ALVzVrO&IAZD@2dg;v?35{+? zHw8%rWN<*}?}5pfvnrdIf+C5=y58_1-!}IcF8EBebr1)ZmfTPu0PHSmOmUZJs%gco|DgD}O__^8&b2+Du05>;3&|nabPq+C&H$ zZ8r9)uWzLalNCCy;rs=86=mWS54XS4$e3qV2Pk}+fiZbn+cnyqAd~E{r^>gKjnfX! zr8XvNrL7$R-ii+qc^XA$B+^nlbY#SA@;dD;$xsieJ>DXC$_gqV2}qJSWd&YHRklLA zrXTY+uIj84s_0F#l7)wt+$_7cG*4Bn7R?O8>U2)92|XDd?<)r;bnoS9&%Wvce>E$hX2FKH~=$s*jon@F58L~ z-MS%OncUbwJO-dCh%mD=EQy**;3BA} z)_mzewo{7KH7dzKgL()zK>uq#YRJPXXSpkNcdZC3JsPVsSf{ynZueH|kNEV>xndUe z(sEPhFKy2ik<_jkv!#I}f!804(;JQEL4yV<8E)|r#>_s2 z5IrlU-IQuAz+tG2#Fw>-pmI|>>~RjOvsI>~3Q_=Iq_0%`jlP9EZy!-^)8Em8(E^yY z=qu5}E6AE{$Lm~oLr^1_X11&up`$ySKr(>zPBE82NZSwX^wW;heu7+s2T}V|^?S+* z*o|yyy(;4WG>gN#Le3}^a--?h^1L1sXsu*Znmke-ujFAnDgWe!;r$mk4_C!)Cj}&5 z)87_%JFsE5yb;yK>m$j{xsJk^tbJqB=D? zM*s>=crwCd`k5}R_@XHGgn1`Q>xPn5-i3TJsi>vTKpjb-sMd4HLs>)x$IZk)Gf26* zHYrk~gbX}q3GqnIHS9Dovvj5|dE(@0;G%)`o4OGc$-;<7-ati7U-TRD9o_5=7yd%7 zAX{R*>uR_<4>~b8bf8)m1B-`QkN8w?CJi|~PA+k<6~n9iBM@7TmD{7tj9pvw*Y=8! z*G+uQj3+qyUiP4+h4f%7;(1c)NC-sNZKL>G6)bp@r`k!1v^z}J4z+{!m+K)rVRjj| zceXFFxrU?m9B|?ex~;Q7Q2dbha|^_jbgku%Y0POMRfY%dc{!}3b>XJ8XO&CUs*64q zbMR1TKSY7icBas-F8YkYc98&2l)RB%xT18^208etnbhCs9xaP5#`5^!j-7PY1*Q=| z@_GcS`zLjL7^5Q}6C;{KKL@$JjG!(^9qGjUrbT?b8g2t#uAX$<=K>m1bz_tk6Vddx zP@h-C3L&C`Ye8Kn&np+Sw}1UqaF_*aEF5{xD@SJZFpEx7k+U{ykD-{A)lMa1yXFmZ zQLl%2;@J+qjX_)ACA%=^OSb0Oz@_Zj`$N z723QDV46X`HoQ&Yz^nc=TWadS3Gf-Lz@F{(D*>C$9wP4Nj+oJhBo|lqUJ$d#Xf^(`;S7-m2inM9wy|okyh2-`h%HntPmD>-zI;j&os6&C)n&_AJBqHk z^9w?#1qcazHEfjVc~c2q*|tAMzLZV9)Jh|2)~Pb(LH9!~0p_0z6oxroPkr+NP|B^9 z?o#!lNWuMC4_)GSSdIGb_BN8Io~uD^QkU#;(q1pK<{IvJ)XoAj*}mN09wH3i7jv)q zA||V$eB^nV+SD5Qsp(ywYHKKQT=)_fATw6*U1to3>7gW;;DBlGgRDlI;bD{mG+;=DTzRu--v8bZE2BYvO{xek$AF$ zxvSeV#T?3^(9&uZ?wH~sWQhNL*xsL}Fm%@Q=IiFat90!?r6J?FyS2N!_j|tjdAKJ} zHmTYAz93LgWyybkUs}I%ZJF6=Tg>torzBh^up!Spwkn#x%G2GVYXielVAJG#==11s zI~k@|{#Xa&!gd&06HDkGEyfdnOT*H@;^V(PqiDj1f(E=)wewoPPHSA$l3V0Uxp8Ot zq1B33EH)Av`Si!ada4Ojivnte6S|j*{I2ZZeuUSBf@lH9+~v1#3Iq@@JmxPQc>r&0 zG*^a;Vc$e8RP3yl6vSI&bDrstQ);8t@|e}@XUq(MGRe_)BS%i>b9O`dO_nZ~#&JX; zo?kZXDc70~EW>sdg)DgU|kR{#o_1#e2xk7(k43&529@^=aao)O`Tqd98L!gs_+ z)xKA8EU^_3h5`^tev*G;55O#tF0>EwGZqBSerbC}n5z5P{TPZ3->VV~02jvj8|(Xj zfcgFJ3H$5(3JXl4c56>7S&wChjz#3%Mp})hf6(8A5A7rdQ|kv)6v1oKxjKj7WCY{+iznc{^oWB=dT(u@F4c% zyO)x6m)P@n_U~BdXn)S=H)~C(eHnRyw40ll3PHG3oz{6-?sjC%{SyEK6b&5qP&!u2 z!Cv#yW-_QPho^``@!RpfT-3$a%b0LstGmU&|1*+6Pr`rq+?=W&Fd!zaU@F=W_Mj37 z*2wBR^N{P$)~xpQ9wB=}`operJmOtgUSt*rj# z>p3o>@032W3-}(dm0(h-6RVc9?1v`>++Pl`;r-MS1lR@2pZ9ySaHUbjLoCq3p{X&; zUAdZUp*$bdPEz+7Pjj4?81&DXRj!rG3mR{fionk$*p3z*hg{w2i(&~VEFshDwwSD| z-Fac0Cg85J_Kl4BWO5GCZ-zIxrv+QxQ8GpByafHLslXsghf0^?W@j*>hxQII0@+H{ zQXe2*c@BD)(S)VhDXc?8M7?tmje^gwasOjf2D4|1&x1XLH*@NsvUQHZ3Joj;3N>-L zzm*>jo3CuYE-vzny!|srA_Ne?_K)U51OHbRpup@U(05z@*F9GOUX=f65d&wSUwH{& zCkEgEu3nsU|C_1%YYP8=d;IqjCXlG16x&nlp)hc@kX1mjqRth-&e`O>$*b@3)4+$* zWu>nB7XQ`Re{m92=%m3rHUC>@z#j>-X{P_zN2*+neAlz>R>=a$wud+r_j@LA9nit3 zQW8CW&de+~ziIX1!v_TN1T$U#QF5~C3JX-k1`r#VcQ$e}Lzl8Xic34>(OhLH*@^++ z2;eIzVU;n+)W6_gaHvOz-p!ojr>83biGqmF zn*2Pw`ubq123-^Dn49+e)fgy#v<1K6oTGPKen=+@Sgr90>POQ*eV)2CKG_`jpl8u< zoicrqcx*Y7FP_DY*JY^^uC0oV2ljt|$pYXwxg=dc_35w*)xs~6dFfX1y06cp$w)0bvz7}VNtD9JP0nY52cTd^g z3}C*lW*Umk^s1!U94siMw49*{rKl=l$V3=3WIQT}e>31HP zl8nNXV9N?-LnC=VSwTrkE#w-lhOe96Tj7;~t7z%C z-u7*^yVrZ#;aJ=zG>6iGgWeVH6Htz*8twq0*X+L1op z2X~S*x4jrBWr4MI);3ffiV9RL#mI%$R%{=CWP&U3jg;)uvz_(_vnH3+mhrJTRF!`D@|GZ)i@HOze0`Ys`vt916H`xg1u=;GCMlXr9QW$wfub?`y0ftnTU-C(Hv|2xWS-wK+W8 z!Nz)z0@T1Kbbp{k2hVfs{GonN_JmulgRV}UYx{t3QwN~d6j&%+aFHl1K1g{D(Q5|} zgxMsGEpbi2mY~sm+OC4PnJySHRX#!|xM?XDfGW8#2RYw0oLzDUa7C7C0os7XQPq!d4%$Qb z-N6!r>Q_?PeVrM;d+2-~x}=l+p6U%xJEz0JsCiUXJ(mgV#S5@qcU+*GAAdIJNnWTr zd9`mYqVMur$_3}1nnQ>`5v$R7-EQ|EbARICK&XH=LDZT&_qOTtZG=nhP6E&le4S16 zXM-to^q7HG8@YK^a6vJ5_KKObn_MwN&1FyapK=7+akL@l)tWpo04E?6?f9etMtboM zfbYX>#V=4!loscma>tjLGTRvCO5$SIskPkmP%StNrth`7vZLVF{sN|uwW7Um>z20e zI51&ITx*MftCcOrZAIeXGzqMhur+`2E6=6NTY)deWIb|+>hzm_6hR;mu)_~Z!PeNZ z9>}(#-nnl!v1Dg(Qee@J=jT4X^6m`66~Ud;lN)^MM2i-XnQqdT4THS{Yn1CAr~4B* zcAe)^P`PALhCIjW+UW;tUUhF1EfY)F?7uidHNROZvW$J5uS|&AcL}_xI&P7D5-`Nh zQWUy*sP8dzqO6?encX1=&qTzI-)jeY`3~~^E9dWb^n0~ zG<+4MuWomsTJF4@BrjL7l-jjJiHOqCQ@3lQVNYOlHIX)f-?fA11;pXYO|a*=yq!oc zjd-;5DOsU7aZP{U!hB|qBt;swtqGk(3}!}l_BqbgPDhWic3 zPwdt339WKnygfp7N;d9KX*kEmEsj1u$xF z0YD%4y-doL9Pne6H~i)+(U9K;0sgWd&A?T3E+LB?H0P%XK?y7Y>v_QoMel@rgB8^A zy!86GeH;i6ZJclGaSN(c1C<1kk*Wy9Vw5kC_r%#6o$;03|J$Nb+h(!P{_nItI94p^dSz#3FNSQI|&U;LO{S^7354K4La>gc><; zUk^%4O92Io)oS0Tk&JY7CeF@BTQiNt6-61qVBkPvGIUFKm-Kz` z{r-G@-|s*7u66HP_YW4&^UOJCpR?nf*WPFEU}Z&VTr3JKG&D3^Ss4jcG_?D4XlUpP zkI;cH#r(oJz`uJRRi(wyN(QJlfR_j6?-bslp_NBqUwyy;-XGh`=zK&&!~1#ncdyef z&jbxESyEQwow}RBPSayAjn0&{Ue7e27`~J~`Xe)sxg_^e!JX7>!IW$pSw(#MHkWOA z#?Ve`W7qm7`Zg$&3lm|v@eGu=lk%Q*XIPMA8pQSe3G@q~47bx1~7ATG?Id2+t9NX77Gzba`4yL^|R8vz^ zQ7Jd>43D5I=lM8^v)Iarh9>iTxevq0SWdlbl&>mklZm^*Wrr5S`Rb2@s#jmC;?dB)Q?|Fao0^(tXI0zH8)#`s_k>)6!o!qVCn#MEzEz~yNOw0`1%5i^z`&JG@M66 zgFeF5r}!=%PLA?Etfr(S21pVR`^9=z#4OultapA+vK~^v^os$;O64Ls zhHueiWHXf^F-%Hu4uCqkjEZdBebx6U7=eFgMKEYwbWfrbDMRADr8^&8@%jO=UuO4% zj3L-qz4O*G`bt>yjbC7z&cS~8YA0o>!kf9X!g{|oMZL{0yXY+UaiJ6wS*noZZ5c8& zG?RND7@OJ#19|mHvifKRH?%NPUIRdGZ~thhlCRt}Qa zZjRkM%deZ+uIoWYuq5<)E0g+mArSjE?K#N|#AhSv^3ry8+OwDG=h5cm+og}e-Jn5k zP=oH6Yu{@@(|F%)udgIdXBCW&zj7ZPWa#;5g?s62&_?Q?owKs-Y=NvXY>$^9%tI{Nj+=xo)6)OIt*l3ByI!MFXhg4w>jx3AbZJtg{(Tz7;cir?c z%xal-tH#eQ&1z~A>~j+U^d?g>G`sVY7_*+o4|IUIj6xd)HP%xW8h;j!Rvwk?5LAVL z-T_KVg&9$ix^He>)Yc}#{K^GOo0La;Gu>4nG@7;?MDTJ~-7D61 zBJv);l3oJc2Ty-C+V;=lm>;Mwpa@yWbc<U+{%I9><_L&LXL_o8 zsNDDbP&`aJbl&TzAI9d&bB2TSV36;bpv!7sLh7?ae~CEFtZ1DFv7~5d{!D$@aevN# z<&+qa>24GtgHnGZN|$~26E5d3@$nlk_k0>RZxXg{PGt5bsK;+E>qGfU_s$KI-gq?a zSZo-H2bS(Qo{uemdR_n2NNU(v0O{|eq0em`&>!$wD1<${@7>_cq83A$7idzI81XTF zy4FHMorS^Hp{TqMyk6#ndBr8iE~j~Jk#N+@`cXr=Chxwv=G76Ifrtd2K2#yiz>8aS zU{|eycdWcD$P@>=l0+W+uNh>hl3*fyXK5OWoEkl)!1JQr#()rtfr4dY9kw}KdvRb2&Hm( z?5u@my~8VkZiwPBaZ;cUB6!WTL-aFKmR+Zi9*)fTI23IePZG<5`)!>|DQO(X-pp$3 zv;IgWOv`OWz1EXTt{DD=g8cZkhok-G&E62Bpe*NzPWR|XvcRookr?=k+Jyd7IG~;9DY0hQSr7r=3(=d zl=oa>C|{H7O-E+tu|a?9zV@UlV%tb0?5fQ%s@qCIwJ5OF6=XYR$sBfp*CP@uV#q59~rwRCFp*3 z&ojUuuL)FP0nt?Ye@D$4d_tk4eX?fM2X^P5Yd3>wc7K-AU{?oiJib>)5jPRg&d#f5 zXrEogm7&s3i@Qdr*1YX`Qq7?ENecF~V&%sJgWuS-q8xJ_ten3}dIOR{8$T|;5n$iPfP0c=*h#nnh1e4X=iMnGGh;;eu=>CdSG!b zXZYsxm3tfFtE`}_bN~vO;0&=9^K(HED?KYghR^Q5cq(ysk^$cnvXH=Lo({acNCF6d zH~hbQlzohFUjIdtfppoPDF5&ivrhD0B;l{f96wMjDXz1?I=~Z?huvC`V=WQT+m)4- z%hR39c)Gt><5dCFZTLlQM)+U2!kUdDa%9r^g+-jaDyg+5j)0A z5J4sExu~+ewS^79`7Q~IuViY%$D~1oK(BNYQepq5rY7NJ+q=;M;^&~LxswLLpgJP7 zm*8|{V`eY=MI(Sv_xJZ70aK9oH*-r|8%@S9$H>G4_p%*-3kCq-;kyTb%5D5g=4>O4 zB@M!31}Xiz&&Z4P@bnD)`gQr}A;A6N41qK=A8RYWJU`T-zcR$z+gn&z_;3M`UL^Ie zKBc3#v6?d(r#P6N4fSst-UxQTV=Hcq)DeZci!m3!fBER{l$^xuzv8|Xhqgxzd~g3~ zo=BlMM*Y?$w&<&G>Khd~KmC+@Pg&GHp$;Di>n}!Xy1LeQ9o{LyL++!cJk7@S-Cavt zYl}DDhw@KY3KJ7IdyF-tySh{iJ-?yL`ttDc96PyoKiI&Jg){wC5-UGc2pQRwE~VmF ziin0%eMnJt&ZdMu?qhZ?$4D)IKHlVX3+f#kE}g`sI1~hF5#_{?d~tCh8^bv3G^}9E zpLTn-)-C6^xM}|OQfGmj#6b&keSK}$a(!wXA$$thQskG$LqH-X4>_BTQJv3y*@bV) zoVUhmi3wd1Jl+?_PhXqKC>cTR>inX2%Y?sE18>cQM)z!bp78i%94@CH0 z8E+`DpP!%mo|^kgr9H%dMognyZJqH-!7sa}OYXj$e?&+vTk$x*`CuyU1N3D8PjUh~ zwac&3(Gvgxv+LDHGHO31)}o-GFmvdl`I5=d3=Y*~fJ8rX?0RvVUs{?Ai_%;h^f|4} zE?FH&k)z2j?^0OcicUK|c1i<8C03AAUvaU{SmS$zY9zbepLtzrE+WmlRcF3N z);HUf^=(o4L5P&lgaUJWj;h@<>*EL+)S@(O!NQGCS1xC_EK=dhNzm zC+wIWoz;H#6dUz3Plxm)#+2rjec$$d)ay6esOKdXG0pr-R;x7cO^Jdz;AO`}3mLZ* zO_Yv#LyyYvg3H{(ZPfjUt_G^!@1Pe>Gj9@*X(#vx8i`lyeO|!LiTX}@DJ)$p3yn%L zA*hQ3>E;k?H>O{i_a`#Us4Ht}#o0?sQ^81~)Cg;t>%16Hv)B}e{5$pMEro=&6GJm@ z;I5+0thABwXP&oBu4clw>>CAjAI(_kI5A4Re9wdHDawl_$0qDED=XE^VpH1`pizAn zGixH!KXfjhgetFOBeLhQ!py2I9ilxILpKGSH`P%ZCBG0oJ>aL#PX5VlHe^yY6kj`1 zmGnrX$YbGTczudr?SrwJ7`$vr1jkZ~br^*@e1jwPh3m^#c&bA>sr-d;3-O}ZF|ul; zvID>W6kntPZ%-tqHU_Kc(ih065Q^y&a+gMv7v$&DJe4pCYNQo%VJ>u?bC)KO;0kXn zUw+PsV3-@r4{*FV-Uyx?%M9TB5Lm7UwYBD-9ueJ?_3Dfinb+R$!LBrmt_Sejk1oMA z{6S8y9gU1~=BWc?=|SE!kzpsu-D0Jo3|eM{+}hr=a#^`-9AK-SSQh%~?9O}o9=mmG z+2+9dGHl2iOY8{Kt=SPOEDl|y;9k*EOCuP($~@n&PU#6GBXDZH1Kv4d=B@p?E*!*0 zT5qj`zAXFbc>2*KSG3IdV|*2(&dKA)EbyjYIu%L4vXn8OO6PZ#TaFe8d!7b;Ur$e# zRa9Bcrjo6R%2q>#P%R@w>m>-8DI`hbgor{>kR}hFd^QJ{0Al<)*g8#T7~dST%e@Cf zI~WrFSO`lQ{CTa*ZY3YuP^8$a6gzU`?3R|6=IT`m>dSWz%hfbA-2YT*tv0ZNu)MBE z<7ADag1d4RM^qt@ucj_g8LC*)$3<^1E8nUy{fhYks+n1|!dOHgp9LSoUmE!n1m#EP zDElSLz|yoee=d^mKQij5Vls+<92Nu*j=zGtCpeA~#mGl8SAB>5ycdmwuFoG|ZeFUK zD3*tP%EAeK+^2lKl9;cc*XyX%Rwl6)ryi!BZ?=l#tl#llOKbmoSwO-@pD2hki(hVY zEk~9tqrf=5o!b#-n4fT0CEY{wIXmNaBDv+NGY=7SF$Kmd8Y&Q$V6l6;bKzJDGkdCi zA+t0&zW+lK?TaB957!mM9Rm8}>;uE%y@EG5DVSqgx<3ujQ7v^-tAEt=mBLIoK+cp! zuAHp3uuuzpF{AdekNsGga?DG>Z1hUZH%=Pw5R2~s*ifS8Xg9=FPB2Ve91zXT2ELS1wpdZm6!o$t0YP-L3s`x6 zXKGaxkc)dbBIvl69e`4OEtF&%mOsK90AbX51)|hSP^ztxA+xmX`e0zhZ)Pg2R_#w& z$Y=Qb+;Wi2WnSwxHLR6T56EdE5Vt<3Ih^Oq2$ti@T!x@x_z*|jkD)Scnc%Z8Bl|6yMb7Sa` z;HRM;GPXbnV$$@iB!1j|NJ>xmqa3NnTs^0{o?>gw> z8D4*Rmd0CNJnA!u88GNgIdSG^NA|Ar78im^247pVSZBo=vCfU}@y2%=s zZ#eXkBbxjhGZt7IRi4xc7cXPEG(mre4>4C9yLB)jB(E(6<4LAd;m7MDTNqpZmPz^= z>R98$6X_OX0tuOg6ZI0m+3NOnzQ6`4`pA6L(APJA1XFQd?oIMj~G1fFEw-o4M)X4(m~QS5V%_j_kR6!-(iS1vrol@Qjv&`+k|Tx z1B=gVEXs`jWvD~<8}$qTHPJ$t~t{P(B z_Z!06>^S`!yH10Qy!jXE`wEuQ!Y?w`?~RKF@X`Daj~OCZH4DFlEF}gAKeWODeM-jJ zsG85R^7E&A_7n8dX$a1?4ESx6wa4sdYPGzdx9NK1bMTo+Wn0DdF_XY%;vJQv(hM(I ze?R&~#}XLM@QY9!`$cXQEnLtA6lvd9`N5#3W5f%NJw}lzayGKv!rLc9T6FGMq|-r7 zBw7KcDBoh$(rbtR(teY5tshJdBPEowX88L2_D`o}SdP04|AU35^5N;}EH)6As)|Wx zAse69@d9OO(;)zF07#?%XR45LJnq?B#?s9L7We8FVPbkMYsstNhZyZ6hFYF&ObA$} zCj^VsC@E&A5($cG{$`~u`KbZ@w?V=b2mQAoJim8j{_}l3iTSIQ1~1F}qoqwtVTi@r z$5d8$8CDkGjrRY*ogV1F{40Oz;NV}9y0nGLVoHnJzAT^4idJSbKE~%c^?V5a;6D|e zARej*zrx)<8M<25tDfys>YZxB!-TU_ztS#&6BmTTo%}UTucNIJC{~@VbdBLe4J&B-^huTabWiO1rIQ;~UxcFG#51&GEXowClXeBQJJYud^ zWUwy_6_7=uxNdh%3EL6a({WE#Oq@tn+UVloluD*4nNaG8JnYyA&@n6Tnap$7LSjfN zocIEx(x1Rohcli9G}N8NHLf1?v{Tb~DH*Q$K8T{aIKCJLTC5CZWsu7i@_<8xkyk~* zbZNt?Dhbl|2m$@2|!`;Szr&ND%)?&Ymb<+pla@w(wdy6|cQ)tTVN6!}#gM z){6q@^83_b6jnvsZym>okAFf#;ft}-gQ|srZ2xljyO7js5$0DWbxUV#!e3kLDBZnx z9(~)5X4`ndtj?qcf#`Ip1`*+Wb8g~;I`hA1OP#_Tbpcee1=qE8X!gv2g@#fE|9T_x zj)cHGI`0J`?W4UgY=tmfz)$i=(UP>!;cHS)HXdZvkhYxn$YC5|uSQ2L?J(G>riZ+U z9h+Po?hnJ|$~yK}*PMwZeFq6_8@uy4Hk4l6`3YyPzD&Y2=?QnsB+2L0Y@^3(ebl51)=?;xEIf3hW_g|=N7)WHB7 zOKge8fus`l8u?(sg8`l|<%qF6AP*(eS6F{meJzp**0B;+AN-k!_|_Kv%Dk4HjwgIS zk8M?W%9EGd%f6hN!Ef@`i{BxF%H*4AFVb|DO8cttBRre2gic{FwG2ndfR1qTnXDPh zeUR2u2u>w`F&BgcsVt0d1?P$`Ud1#MuA+ECn#O=#>ErPwK+&dysi>wPV;1XYU&wob zE`RpKTC@60nvp?1<#Znok?>y%vSiXTjQtC!!NIU#(Ty`vy;xFV7^>YhKKhVRg}7kc z|BlVuadJv W2DZYMWQ4W!Mdn?-ABDZ)o}WahW;o?h~~r~1M$^t1cb%OqC@pO{8PjF?d>j$&#sZr6QDS55tDB}AdzwmagPA&{ zjwgc_o~po=ulbzdex+GIN+bL;y8caLL$=R#PX0xx5hT*m2t>liQY7xH;6N+fIkY%{LhTjRDQ;0!ss`oswqurnx;pw#omJesN0kx zAN3I;_I~L3)m%%<%Ja832NB{aM+qX{9wWL$3mY4|jFV2w_U;QaWQNHnfj{avBTH1@ z<}k>+Z4gE5(@N&h$10meRsTUCqq|zaJd{-*vS9q62>8{ne7s*6fZ3|{ZRA+Z?!5US z(T^tu8im$|)+04l53;6y(Hdz%c6N3yYHp+D+}#DbS;{4*(!m!slccp1<(t=Mt5*x| zG?ijIP=Gn<7R2X^?RW|NDcz!om4^xWci|+#iGu6Yu{@W`2jy&_7yMp%My_Y?1k6UfZV*?$kzR=Hn zM6AFl-$z1dKVq({y))?VsvH5L1uN1*=(Q{8K>8m5t8|yL~*>kzR^)! z7yyY!h|%%!hyN>1LX9fjv9V#=-0JRnX8ZZDmpBf6;6js{f+8CK`CUvWaMdgE z9C{OoLLa(^SRwKF-lhU_>{`PIJpLTokGcN2lJRl5}&ZH0w$}BC7cqVoiYI@ke zZ&X0W6&lHQ4=w8f*lHw5Iy_a_&yD!5BaWj_UK39dMY^OCdp37E-W95~Qx)ZRS|WJNA6!8xvYp@5R_MNgDy7x} zRo|%cMdU@EoLM)%D`9u=_pGkQZHwPp%=IvMx3yog1L^ZZdJ%yyvx(41;u+TB|EeT zo+h)h%c&}^@hUi5v0r#|CY|sPQfp)|>=9`t3TwNigZKkIgHuMWmBkBk+Qgwhboxzj z%(Q6@wjY(+(0;+!@?Tn;&b+Jb@8jQb_9@gs6(T-+-K2)DXA8wLIYdiC7;%XR5hdEOSH%kDOL)vID07?62P zmoz-CQG`8KI04v-tD!Zc;(mv2S8FRSrKxF0pAFk?By2-uT*tcPT6Lj+n(xKlF$$K6 zuTk*vND;q))WT}h>wO8c+;~9dkOxanEoaZ|Lt@(&mOzeWaN#L;=$NMO+@rUHr>E%G zmprrQ`wM>6_r`v=iH;-O_k!YSdKh%4$}@giEN_WdNki-i7DjX)V%C=)*jpwK({J>J ztdzW-+PScI^&Bj1PdNnhrtVsqIP6%mNVL<|oPMU$k|?ZrGidYVXK+t(F4F?ClW4ZcjXOw(>GpTPkE|AUS@`!N2HjT$@Y2%ZH ziAo{eiPwZl2;*0P@9b4>EX53Z5L|A30zdrm;Y=sfZYlk$b#S4(>_gq#dO;47=Nl}x z6f=e&B+?NzIWU%N79Ll1y$@Ey-(k4Y9w8PfbZ1q5?$$%~Wob730O^MPE$XJK`yFDv zq`eCrIdhqGO_!e9H#Svko$NNc_SvQIMf?gcQfuoZuXOXbo(cSVy7OvI>HRmnuai-k zJ$loIHtJ?&X>5&V)t=I_Q@T%L3eY6&gdIc9jE{)-6mpOEHjlr)j@N-eCPjdGH zQS~A-Ii>^Q2IWbcxtM&mJqJE&%*8+TAl*cWt774zHN(nm@4Qo|!9M5W*IVu<5J7ip zu~@mdF+)onJnIS91;2iMY3(m^?%wzJtTu@&z13eIGE%Q^7*^Cdo8dOl@2NK~Hi~FB zmiS3lLV`jhEo}^xU!Bz28`6Ck*HWLI?~sTV0%zr%^txfSqc4`HHE-YI zb{L-?_vpjxm{`&%Ps@e+uaoMii}1c&zfKs>1a;z6r#_W(6$$?fOEDG3XvP=P3nMhH#SKvex~kJo(7B ztse{5x;ih|QmS&BcyNxiOQ3xFx+@J4^xwLmww5>PUu7xhPOfm8CnK09`RhbpM$9xu zE2?b0EH-)u(e-(qRg`xAjc+RR(lR04RRzK^+oL9{+b&qxOK$hW4L@-y47f@

    Lugmb)nuw_=+9Nia>b0E2teJZ`GTu3R45-*0Z7dSSR-s;^Tq z!Z7$Uq_h6FPQPjhlqSxkLGQOGFHH{*pWk-=@zsg?hbjMtsy>j}s+~0pb-H}}DjeQ2 z0Ws#}6U;5evRJDTgLyg{uua3QtTy#4vQF+b_jbvZ&*x95qGF|Q8#UIRy(~^>df~$T z8JfWg%-`lZk71;N%cLemJses6y~FZ4XJEE6Xe7Rvh24M*L9#yj(Jei1e( z>Rv4tAZxS9`I*ACpE{};URIHrU)2=3u^NQjHCV|W=Z#%_H8Z84BTx2lQ6E(G)l0>6 z^;WdlT9{N}L`bae9w?kYj47J$;KERCPqv+5?pp_&zz$m^N{0GGkM)=SJMR0)QZDq&6yCc#Y@CpPSc_ljo-dGB6+tuwZ4Oe|luBz-j5#;h znHKv;n^qqNQZp@b>Mt5DZ5ALzU6>mx*5lpIggp=ESd~rdD=EApJ_BQuD3r%%ryA^LPxWtrHLd4yj zPM+3?q9U&c0)+gtePYDq+V2?iau5I8^9YMV+)|{3O}m39m+#+qBG{&U-+odeZf zT*~$cuEZ&X`-S3a}`7#%(2{MsE0{<{g+s4FLW^ z*)KC)r^?Q@LE3#g$qCNCh!d`WiCD=sjX}NfLNpYnHLdX&e6?&bM7u+#+SL@X@HDsr z*vcyHLiQ|bOWbD7qpj5L&f;<4qnHScyH?~lt8wq3e;+WvoSP~`{(-OWeV)dW-jRO) zGT!k2Yts+%rvHb;2UTddZz0D54n96UF0MXsx!40^yMO;aa61Xy$^y5+hg^3cTl7r~ zE7;23o&bz}_xcp`^zKR>4eg5d9K3aLvNc|!|MM=n1h{g>-@eNiKtuZ@S-=eX=lR9a zd$85duehi<`?6f%?iTG6&R2EKXc+0h-=;6rWSdbx{_PG^SAk3n-{qQ$t}Zm7AT_r7 zFUjd2dPnO%VEs?$4p)RE`qoBn8mUoeEL_2QA^9KDmZsVV`r znQYwXOEB9w5L5UW|9SPn2x?MfPF7wny#6lj^;0Z8A($<;kJjr=F6@mbL~;-GJizD^ z3Pr9ze8&Km;5{(gw?5ivWbUY%divaO!d|rm6}a~&d8UzPD_=rB&YUxHf`9@U}& z)j4$96e9bFAWt(}@jm?rrBEokIN!^7c7om(Nr8>SAFC*P zDD-TtJ_|5Mr1&(wagJ<48N0#pYU*qQf{EB{HlCoIl-@~J=AdoHY&j1GN9aB4QZ2EVB4uHCpN7CxOAUSkegNub!FfO)F_sBJ9EoLl`lduW(%tvd5F_ zveY3SUXH!|kgsAL42saO%zu^P@)Sv~XRTv^e8uhn%;+{Ex*{Q2p2705)Q#{bM`uFT!`MMMG`qGle=V2M7Q8i7Q`jl=2XFE%XCeIE zv%hI&!2II>Fc+7;t%>0tGZd;z`9?MGW*gT?@c3Usm`@%ecy@IdD{ss?{2tD2($YP2 zm-X!K{m}Za<;TazYFeFD8K{uT03M)!_5%%l3O8&M5G(vgQ8f&f32JkM+lbLyw2kt~P((F6Bz{y)|?{%M5)& zYUt#%Dy$_-$P6L>AA_nu^vqz9A@x=13nhGlH{(gvt7~HY*JhnI7`VP|ZJM&o6H^Xn~n-i*qQHy3S=~8A;+kj$`-W8D-N5d$&hp9=_jXJ zy4{353Pa3X3{k*hdT!@QoW#^H7B4KWQRE~epOU8KZW(Wbq@a((kvKj_u%ntr$D1V1 zG$v{0vnWy}rbX|GVTvNdHx9{>Wb_ivd=68Mu5vCgEh^@Dq(`e&CF6XWy}JsJp*mv= zy$`r|qM1Thn?+pgcLB0&=sDXVv>w`JhN}7#8&HE5UaDa z$2J2a68oWqAbF+qcj-DkPg=Yin?;seNM+)fKOg@Q1qS#v$;LMz_|tkfVXx8Qv>mh- zZ)29WOtNt7zP|lQ{`XhIH6&*5T36iHi~N21zv;wi^v_VLt~b9gON`k15N@rpW55}P zu;Zo@dcEH+5auh88zth4EUMG^(ny>94ams0{e#RUnc+^@ib!rC9qmqksZJWy6$8Fc z=Xb~u;q9qsJ5W2Hut)mkgc3Wgc27{RKJ0SNTWMfk`*~~}y?ASf{zb-R`Fx$7;{xMR zTT@24wPyN2;gcx2av~0;>u`Er6;n4Gv($9+dHOtU-V>E`ScmTJ^~%V~Lv|1Olm^Zs zs;5F4T;{Z)?$fl_sQ}|X#eUaNVGuPV%&y2(hdfN=yq$cm_|dA?6ByO%(R{yd{$wfnNY3W&t_CGN|2J2aQ`PE?#> z9Ox3c7Sxo3p(+itmp`7V0OcuYFHBW7!2-(|Z-Wh>JGR@m$7;@LJ_V^Fdv00pLf8kW z?UIQWj%9~T(D|+eauK}N?4@gBM(fdy2bE`=FdjV5u%s$!Ey9jM*^fWj$?dx`uoBji zo6JiunA?kS?_VyVBTDn7rdRzmedU~QKOJqTs8o-Wjq}%59V|iroIbJ>zd6zpVDuI%Pwqy7X zK&xVfe(?Ay`1=2ljCg&lSILwU=&l!8C-P7r~?5^xI&!>1+c=qHxcBq#N{)eZSC| z7}5CArg;d1bGGC<>)lZDxGx>a(KhR0Wgtg%3irWc&1$_V#VK7}!&2&yXL64N@PU1W z5c#0~Z|?jHefv?3U_#x5x?G+gKI^T2RstRm#`60nuxe{nSSP6yWyETpbuhWt?iAI- zL}f)d+Yg01TSMGk-yAt#9-}#e!7S!0H>!G2heM+{2jGG`>95u zc5mn@Hkh@4hL^xgOT3nb8dqP!6Q0Tt^1Z8*eS9MhDN>(L-(#Z^x7U*r;ox;Sa>SBaOm#`vc@ zfJ0Ou=a)4T>ak@JgM8KcyGgpt8d)hSrgx?8*vqxn#1!s*vky0*|W(fw)Vm*D8r z>7Vq@Qu@agA@iHJdcIc%x~lxK;t6Dy$gcAH7hJvscxSk+eRf2>Wgt|s*S{1PFnxah z!I+w*IG4@E$?&PReNnQQi4og>fh2&ADs32EvD9AD5R`ncYX7spnH0JcrA2AkVS&A`d{#CayR+sjkl}#A#)~aKN{;y z|JO8~m#-$7<^OkU{?GqGq=3r(D?NDzjabruJmX0B|EZGpihn)Q1g!tM&Htm}OT@{L z^mAFmAO8^=xvGw=Cgfi>$updTvHw*%bpZDN>)a+h{O?e}?`wa(@yPuD()@qZP?{UO z<<=SQ%w&*G~*w zty;_hDgW!kV?GH(ZPt0c;{U}UT<-TDmI20-5;s_Nk`kRd@juB(R|P~AUmo^)`p%4u z9GBmX^FOu4=e#na@iMN3^@5e9n6C+_cM$rQ+xY+@wj9{e^)*>Y2(3arzyCkFkx2i? zxW2L!13A^QX?#7pAzEYd^RqxA?a&LrS_J<3N+vI}E2N5%np8d)T7@mgTcd`Sz;cKF zY5ptQr}6;%tkZWd_LavGE*lZ|{tbQHX<|F! ze|C}>VAJ{6UReL1Hl+#=r9womi}}y#_R+zZC?G*xteVToJ6_(S;xW+$_vRacNmQnT<|bQ0_hAJ4_|$9!9+884b((D7Rfz1Oue+O?-^xI zl#i@aufomqE>e~vynEB35^!9eC^tquK@TC=Oyfg)_LpSx_S7(IiO*b4-Vbu%qMR!# zW9z4(_eQLORvm?8Z{tthT*Z{bTBI6x2)pq6*z}ZpXfJ?34f-ka&84n2qz5Xf#CbV> zBG4lzYqI#wcyrYyDHF?>SckFqkwv!6T;t@DgLQ~h6ie{&{lUA=pSm)Ii-UlYt*zD2 zcvgB;wPrf~TPDu&va9G%IA<~%A8ZvrAdcyyfmz({Za_klA-?|UG_-j&8bT(Gy zo+=6s)BfFZth78*p556q$+Czn>qSLRWuciqO+~}RSWQX z=aLF27cl5DO5R~7C{{>A*%6edy|0@U4LDj5Yol0e6dY=xsQQp?d9g(cceKTu8x%85!@~T(>9Q8RT*eyw8ivFU=snCv$h& z5>@A(RKn6Uh%Dy@8eDlBiyLq2Mb=O+riTTbPQ^)Nq+}(g2-d+?fD4<(*8=uXO_~(s zobr$TKm#OoMFr0;faPXy0O(3rz+9aROCm;8nf8)WxB;cK;H{;Iw=O=C;k0T*8xCK_ zZs_p#011RmDC#2q=h(^r%dbnVa z$N5#=$c%IBj0ZOt;p+$WDBAoeLnA74qk>*Hm|2t&SJ@{yqEKbZeD*Sie89=h^5uN$ zryPicJN=T3s|hrT3b)jOX%6>Xe*BnYV>1lW6GZzYX-{4ALsPR0r9S| zfL2{Fjo;yO8{A4Q(9Ya}tRPk0y`E6FuplREOu0tsQE7>KGOk>L@}q#5q{TduQ8j@K z^#PxuA#9>^HHAEkE|BF`(c^akA+4f8>cnc!@JAUIv9L!f_i@l7Eq^_T4)cU;>eB=l zi<`ftm%bf+cFo@SlG78Silb9)kIry};5FI=uhUlt7(WW{VQoMearM?t8K{c+5gR=! z5;cYOyy2+bftJq}Mfu6a>@1*!cA!u@{La}k+iQXr0x@W?FsKCiRTq5JxuO_fS;#P9 zP_tQH?*4>SZR+<}zI&bPz~mg!wr##!(|ffmyp_PI;mif;t@(qcPQ?6+MFVUaO^>RZ z#}=dN*yj5B)L}LuIoY4I4Ff0$dJ7=zEQ$784*p3TQM!SSYM;L_b8_OxJbtHvB6EwP zk$h4WLO0-&Q;paRb_sV-l51gc&i$dV;G`kItjt45!yS{VXIfZtmwkgrLdfjT%3k3p z_E>{ca0r`LW>xi(yMCZw!Q;9OHU2zJC)b{0OBrR>5KdO9-IstzOi$=xU3r`gCjx2) z1^32Eu_*fmKpZTjb!)-d{6&wMjM)6FjZ5RD1Rce5*yL0 zbhBhA_&b;|+Qu3EJf9W6nNwaA%3V2W2-Fj+BCf+J0cUrQRi1{0)~bg&y&l*m?|VlECyw zVxB5N^=HbsatHY=%oN@(E-tDsybG2~lr=vs48it zp?wZBWI$Re`UIk}i;;R$sN?Z{3H z6{U2F5JTnjs@u?V2y96$5NFiaLssN%S!JqHpRm4>A0E;G+p-05Y02tY(e5hF5=)Yv zsGKnIwP*PMz(tcWT`v!lf>Li$99xt=Kg~v>j`$WqSh7vRBQ5@2O09C|rfp7y+GgCJ z(}uBPNy#@^+rqW1aoW%M7M&52HDwN{KgkWNu;I;CL-g>wuo3*ULxEHNy{@JU5KK6^ z@Gtc~$}Qb_L%oiNnRv?X>rEMe$qO0(2TL_iglaO@@RK}!3`VYhR}6HH*M{aw zqz)6coy-fHsCIj;nfi!F_Tt&btdd!*A-{>byUfv!Anh0(^$|_J>JE!?dbhLUg(!-r zP`y{LI9-2OjeemM2boqf&H=@7Y1*}}SwLlin+pH=-d>m&*jQxZm9&I5CvXam>H3iZdm=$KT)sZi7TWN&ZBrXSmvr z&tF9e87lb0_5^ZA27z)@M<9Lb%b@kjaAe|azPjS5sk$y`h+#1rxW{2)wCu%{{zOVp z_WL?AQo~nUTVGKMc(YHdy9MVZbUFG_B|dL2GBEUs#?C8tGz0(xwF?ET3|%DHj(^sN{yi@*_#}l{@;Z8lWk!I zNM2%dwYKZB*4<&-64ZZ1`{$3AD8Jx1}dQOXg;;kqko$cCSxO&F_{gIS#0UW&tetA7JNZLgPel z+mtb>ac4|5yXU_EBwF4(MZELNYwYZvzJF34x1g6_gD-yY^#k;HugS+ z2ob-I8ZQoDbiMFiV{D$hE}R$)5BoNSIB-}7+>`wI3GF__;BICVPs0Vcn%K>+8Ftwb zf7+ZpbG%wBBj9{Cd;H40RVD?vJaGi{k^?OQ`xNjJ=$i(_w2wA~fyQ(GjX(c`c>bHy z0LU|dnEne6Y5ql?A!bzoC0H92@?@!D}vAqd{?sYNNv(wxEH2yq6?!P93W?EvH2VepYYGyTjr@TesER zM2`8ukGkJSwclG%g0-+M&}8S=-@Q2DWQqF*dc-8RtV4$_#)kA*{5dem--}i-d4)($|7t7 z$bdB5Ully4eBTFw$mob|WpME9QgMZrN+e(=a*q%}lEA0ujIPN<{a0>?v#L9cah4>s zL9TF*nWV%juK#i2H-Fx2!?OgYxosA@E_;mw^rjfz!5 zhmhwaYJe@`9gme!CUV#cDrBK6gO7PT{z((Ucp;<1AbLAJVR0+7A&S;%ndVjbZK^iN zalT2_30oJZMU0}MhK4l0#+1U@AUWOc$jI=yIt?jpv?}8?en4LM>F#)VNf|}dE(b|X zl}}zWop$OIm2W&{V>UM9pn7U4X^e6L$7lRBAPs(!CaJ!eH@(B*;L15f`+O{NYXTZC z(>>Dx!yuw)dM>Tawo>0C^f9e8zD%Q&;}s;8oam?d1$JJh9;CE7J?QS@&f+tz)WSzJ zhJBV=K^SP*S>bp^puk2OJW^eO9^zAw)HA$5J57zb*mR?C_>Wm^+c=0$-yI>VmxqDk zRHmqLOa$+@8f~PMYr)9dqUyqEQHJfx?A9Z4M#!5qYGCt*WP|B}UNy7mZaXETDooG0 z0##ZZPkkN3u_JlSaSIlN$~TB5t3$N?B$}oSB(}-}i1BAzSVm04S*v1kftu0Cg?1UM z1D``h)m>Dj^mkOVVTvqLIGVZAkswnLWFit~p%-|1VxCXL)IgWmfSJ=3)`L%GCl~mO z)h{+`w81P%=R0*zq8@dya8ike^dPk-41Fz!E;Is-R!DPRE1KJTD}6A}U=XN(YtLzZ zo)?r?7<(upXe2|j@&gCOJ|ryDM>P>Q=O=9{J0q4}XC@~JTse!Y%qrGTW25SpWu!x2>}*a2SMw1|)3J8`z?;To@p8 zc!Jc{T6iW?eMV@OV18}En+a|)zJaA|MV6JYT?XB~DHa&sq|iPle-MR+5!b1DTz6d9fCUZ&A>Xd|HN%V7C028uX?TAW82_c;D&FI}Q~M8= zlS$^~1SP^n7Pw&~!@)HgIVqaf@SjkYX!z*bF?BAI)l^2Tuuq07)TxOBUieba`_oUz z0j(KJS$sjIM#5X#Ww5Ymsy|;t*)LPZ2#3k}k{1UJZc<9D%E&ZjP|m_yA!WII6w7M# ziPG$M^-yH6L;1@{lSa!%oTr*wxRqrmQn6<26<{u&j(NN5-GZ}X9K77sN*@>)rf8n` zt2k0MvBhPRnV3 zu#*n=8Tc?Lry@w1A|tObZZ^C*uLQa#b~X8FcN%^^Dw_RWKpTxELd9&@^Mu5gFTTN| z4nSLgxFL$KiKC>TK@R2Z-m)pr32I!wVES1FJcs{l)-boGaSGyzO3)J0+ey0qvmttq zg!uAoayd^!Rah2lT$F}nTp`=lrb&Mv(gZb&BC_5ZNQHJ;=XhqtsGi#N`Kb1m)YmCY zBLf;`ws`ZbXdPAIMtQ<1usMd5hKNg#C57AT488sD^#m?7C8s0R6R6_3; z^Dw2{v@EA!+i&X=RCH*+I+>GtmQ>~q$5y#BTXuyN`l!;95xP0 zcm=J@bdO4?^pmeFJN0g@M6QZvZkTTL?H)k4@c*d%?ZjIrQ542}e3_5mUr?~K2MFa_ zzOpB>uyy$l%g_n0TCHt=6_y%iq0_;_r5HD>y2N{{4{@M_>8W^=e@&Pv0 zqNO#P(9~N|_Mt7bY;x6^q-RVSx+5+*{t#NL8|Jx^q>PWMCR!uC_9ara)k7{YOX?#- zs)lgN?stSiJ3#A&&anuNq2g-~+T(Wlq`qd-XV=MeXs6*>@Y`XLTU4x9P$nM#42*lW zWcG@7{N?YXGAX6luw41DLK~|f_~?}vf;Xm`Sm) zX4CP&b3&_GzM4z&V1<``?fl#JIsAjbNFSeC4}d~aKfapajyValO7OJcs-G*%l|V9) ztjd3B&Sf0`zNT=iv?{c|c)|IZ+B;e`D2r5u2@duy$rCbg6ugr?2hX~haS9|pjH5)=n(58&S=yB=#k<;EuOrJfY;QO!IbTHn?3S_AA&n}EJDx?F zjfy@QhYwde6t5_7t+1Gzt!3<$$d!o%ZFSZfTf{r4y55fTA{Os$4GRMyv$LP{8u7t; z#kp(V5TfhuuPnJ&W`tp$Di$8y@n|dkeH6}%^i*t1^+UG)%C zJqM+O$mnYA1K19OLceiD*l2w+ti`eEgCE37QhV=e>Mw1oXs>%g9(5^1@+rSK*9cL) z$tCBLs8PaJlF3>ACy6n4v!slJCFiTPoS!&Ms<^iB8i6Ag^5bz%1Fn;w(Gc~#@pA2| zg+@WDiuG>ua|M#$FHJ41v&Rp98j>3F(nsSl zDV(t|b44^J7OSF$O+?LDz)PF?z#kfLjqqI#C|uE(CMJu~=+s*F0Usx~e(vNe)4=i3 zDrj!l8$s0+y9kRey*&zJvn!E4iVsH5gjwS~Z7v%iryXjY@!GOY? z?d7V=D#zSbjb9w29xA31l0PKXL07IW`JnD9t%YAS$2Q|Jexk)EvDc>e}zWJ6V?&-gQ z^=G-Q+Dn0W)hhtLj;s>|CZx=bznxu*0K!Hgsxko2{pEmL03^Tk{4Xuq0R}h{-XPT=)wX}e$mc!kbTSDh0#^}>f8wE+e#Ep!#~8Z8kj5(dvE7%Ms4sW zVWaY6)~K}BINw2%1xyoDePUO|^55cafNnM3vtR8OxLR#p8{*X#$CG-k1fF%jv^Z-& ztMj;akaF57%rZ3V0bnF>dw_ z>5qgznkmAj9W)y`4#++CZ{9KdPVu<={Qmx;A;^@)>%Z;k{cR5@X=`*7Ot^JA)5J0S z`V*k=A1+Wgij5>y1&DGKI+W|x28!&Ps4@3*RbQaji6egsT%&RCn*bhbyN;FK*qVl&(66!7G2!WcNB$_FqREd55a11 z*h@r7alS};j)-kGTVoBF8Qa_2vp}Ef4ncb4fi%gZM@0K1yg*OdLt@~XnCcIj2P~9R z04D7_R0&9rMsWSjpujL0TS-Asm5I+gZx9FXHu`-8ZrV2PLiml7v01hR205=^tARU+ z%%LX0El3?CCGX#2QK2_Y$s^%u5BK5!CF%$)U%$ER7q)9DHxb5ix7o(Buxxp-D@q_5 z(hF*2H_+YJ=Oj_D{!X0C0njlu@H79yV(jFLv*uz-43Mc-%Wy~EJf(J}@epCa`;?XW z5CagHCy0Ap$K*vkG02Ej=>2MQcTGu^jhaBdx+8aey$YD15 z9?x`Vx^fjCZA223G?J%lXRKo}SW&p$xK3rI0RD!>7}RKrcGqd>v7B`gvDe7wYeRU} z=syx21*cBx`3#k+$9Q1S?7EsLUIjME$avnjzh5h(L=<0#*7v3O8O?msX}M*{#~YWv zMmbC~Zgwih_N4MR**9jJ6xYbG0=(m#<@dr7&nGI!e@4q!#N z-m@b2wc7)(Wx_VR#Md=2XFa(Ro=L^p!&(HcH(q{ zp3~cPwOzjVa^s!k%?;!aDd}53dNVMkPw!XjS_cMZsH)Y-p3R{UZ@D~}*dAD4u`uV; zxNIP+mO02(*wR>jL{VhMRe$*QZTPbt@(3W&6j(hFC!xeOuss8A4<415nkw+GE;Y}) zUJXnxm1(EXrwq{e!qvGRW1?G+UqDqu>#&{p)J*bMglNm*`rezE1jeGTHLZXeie?eP zA}KzGr;?5nooZmHFR5{*Q9S4BC2cP4H#11;U^e6*MC_E7wu9}h3bUVgpn1_!;9j?46aeC-K@e!@TDKIIEqx5M@eJ9d2 z@F-sEpW^uqqmGA_Nib+*jMz5P-SI3>xu23{Bs|)G%Gmmix{y6zO-i>_GLDb_^lU^p zACj($jGR*WpvUE#EOR^6Ug{yj&DG`hBpb~GgoiG3d0n00DC`8rVS$FT{?guNYb9|+l=PIB0+^xt% zp6P#~&k6bM@dLHN)7M7hZ!P66Ytr4gXF^;qCiT@aZv;NW0_uK!D7kIC z29&w9FLu7^t&CQwMA5h0w*1h!4D=%+dyR**o1RFdp+c0oyArqm_$L7pzAl<QPL% z(PM>{LCe>Ss8jjE^WqFiOM;Nnb>~*#Wrc&AsUE0RN`O7~dk4JjK!pg|9;9?igAo3M zTn#q^@hyK5Dq+bOmrT(e2e3Ca2gxaayO-^b% zRC5g;)uRT+av5oEvtLzJFfy*9VaJ@3TIn6lR2Q4genj@sn(mud+S&HL)n3-ZDhqR$ zLE@=Cp2#bVrXm-x*$`};Ag^8{Tm33{N&UrBw1S!A%TaNn202%6QRGKEkB#Ga71P_x zKo&!AA_xhDQ*Eu>!?9j-+@gH?(HhDpm_$$WGU8Ta{HPwa6EL29?;Os^zEY`Yuf zF=W-wML*n-&VzI^TeH;EaDbTky3W?R@uVTxo~fcBKGt@kz?^>0<`HL9bYC*|LbMNH zA-Wwh52v=v&ePYZLp{p^_v}Y(HXG6Qx4MV)y9a#u&>{ttYiA+wlr*p#g;W(f^&vYMJQ_)vF3Q5r(C&XXby4?Sf%;hBD zWTL;@Y}PqSMAYtpLKLs2?|vrlcH-sW%c+@51YKJENaWnu;2r7UvYfTVcl=ue?rFrF z!@vy2Z{(`&c(-Cj@OISrB-hMS>7tn-$allykhF>=_$yghlEYl??XC45CcD#Nbc(#= z4-PC8)q!SK%T`vi03%&KcLyc*A*6>80}w5eTgwIB1PAUkCK~P>UO>`Jg#Qz=`$19(8ViVAILmo3hVA#LUy@>Cb8@@+X&k3EB83A9Uj91VOi&5n&&|L_rEk03sPwm&!a zY`VZ7NEKf5bQpee1UyU{;DPwO1LcU0SHhtNhK^{C{~`OVi5W+j^ev}1;J142gR=-k z$p=CLh$yh6bLv9DgYl1FPa}eU$lWWo5!wTRX~cdc3pg^K=ZDTv4o=y~zIfDp@2^aT z%Gmn!4?1|1-ty-v%$ zgK6-s(aCVF_;ka+%U=opgsCyU;)JzKEZKocPIodRs{*&Ho8$Zx^_@T^9pEFpxSvz; zS4+C#4U9`8j09Z#y#dC@azS!cu(evRNlGfD9flyT1b21#_AkKG1LlyKntl%$^z%Qu z(o9ldyNU$$ordg)R4C7naNBRL^qwuatnWZej#)O@H+iN4apCyzV9yKi^NXBMqAnN* zMZKTdiFPe&_vNJhwV`;+`?N@U!=qLG~1BIqf^BhbYv--oMZjT2TAY_o#wR7}{81$a} z4Qx%VP{d8Cd&HN}b5TG*uImfY6pN&I_z&SkfD%$3sB7JA@K21i8V{c zeaYI!Y_2Sh(A8<+ssG;8UmEtQKC$!ywD0Mg`}macfE$kn@o>%fmXX-t!eC3(5va)k zP%w5SG!TY2x1C7MS^uj)Zf&aED7t`N_1+bhyhk)fL_(zX)aK zJfX4j+UEzOjQ3&nk<_Q(N<-0DYUW$2BECZE`6i;uw}|hi;p8EEe3(`*P!`;7n66Wm#auw6J%_Vq3dMCI5bhy=dsE#l3U}&-P+Ttf$c>JVCBs@YsqDV8$Fm0 zUr#{@`G|x>p++T13>z;}!>A0wB5u^0`lGi4au<^hk#{*8PF z$+ZfJ^n&+}>Sm<;6Y$J$#dsfkB|(HeyWtM$n0-!$q30oViZD(Ev{)DS7P1rgHzBNV zq|%AQLisYQ5>=wkRip|F#!^xFJlJ!Blo#^`{3jxIb*rZ%$0dLwbCTNpF;!K{cXdIi zMQ!oM@t)@Kn)+GsB;}QP??AAUlzJ+y_G8T%r-u(WG|B*xJe#DKt_<)}?t4bRCeL0U z*H_XP*_C~($kB6%%K8pXkbcJ?QZBN*oL>f!s$JQ#O?-VFER{Vb;o*jzkLR~{eKi^c z*@V8e4kP8eW?$OYV1-iB>A8%{Kp@{cugD8vd32$k1=;dVK8$xSdRJ}_E zt!l7OBl4RaAW3BiH^D|T>w0NcuZq8urxW^GV$Di1PBX>u<0+GPpw2T7Cd0LUbFX|( zqgzi!MSCL+yD`O5)Yxi#R(|_@6-enjf7XuXe(~@=$B3Lv^a(K`N`&u*bpy&ip?Di6 zP2x3`1(D$&ze;bi7Rq}7s}OkApi!6;>MN%Uk5{Um{^kkYt8F2N(i$=Fww-s9$3 z^!>C2cuhIbsLZu%Qx^gCvMTk3B@*7I_d%28K0h(P zr&iMo>hw8ND1iFf(MRa>w?&U{gLh`23p0+yt;gCm7WNwi!7`r1Pstm$dlWs4VndJw z<Mq4A_UWQXZ4e_Po54ok0wPf z*BwwE7m)&gL83^xT~Soo+zuG9sYtQ(bHuzF90-C`P@eGAKWh|i^w^?b&{6}_%<6PL zMa$X~JNQ9EC-+jYv5knK9;QgpI}qM}ThgtNW`m7P--bF=Mw<3xAMeP=lX*S%Vk_mc zK@jV6qeF1vVJXI$#p+?V>p=D%EAC<7n}tXlCAGSleo!h|B&IsSz*+YIeJOcX-03az zF0g4$j(mlIurT!V)33jX$BAM$!eGY2AHQ;}%Lg-a)eVkfnrJqwJR?m64I4{`9hn#z zze;X~XDd>ijtMUNf>u=+B_*2A^^SdAcV7`)R&(md94S`HYZy81x|BG{j!J|uJ^8DrQk>-;&)Ng#fBrdNg)p~}qTUGI5lE%DfNj*IXX;rTYSF(u zL}v0}YJ+))a<7ZVY(rTOl5VdjW21XbyjxI_cRZR3W2q$Fi#buJc+BkU3x1S9{p36u zpB@5Fq3Mq0k7=bn_>AR>&sm*z@FwF*upJY*#;$TaJcRkK`zdMtoDW@oeOT{Xu&g{0 zJGbK4J4;CAe`Ea-vav^QYGaNw60~!L-{bBQiw?p#Z+)hQ!fc^gr&N7$Q%J)C2$OzZ#S z`m2!b4aQFHQo;bDm}qPh;!Gj_7<++3p(*Uz!X5O;Xh9gKzKRv9R zu2obcdVq;ui*Fk#IxX)}y?7i@zR~UL%Q>84H;=irtFHpiAU9i>sw$prisX)h&hPpc z=K6sGf9XqQmTiMeXX#+yamYT_ZKrggJp{<96|l*46|h&|vw`)W=pPlwjSbfCpF4Qw zut0G*5@%=IOclm5Q`Q}=*!0&^7_;eC~x0sjzjI|)7_Cr8;rqGz*zA=>~d7thg zb$}_(Pu3>GBZ_cUxkHZt>`#sJ^?pkg1^dZxlf3sOaT@tL_o4-riSNJl#5=kc}Oeo^zdWCEf zw(w0W?tCo*iv3I756dDo{FoX%xZ@3P)hUW#*Ey5&5}R&_3;>H3soDr z8<_5^j48G>*`ow(JE*O6W>SN2{zaes&BBwF@A6nvpP4Y7nJ`Wr2DeQ22^%2J6z`*A z-yToFi&vsM{i%W^4hGgfa7GVq_P2M0+cgKjL=P_HD(AWwwMnnCrwRF7on{QRE+2j-9o#RZKJ;PIk8-(J*f#P4k56PG`Cck?ja z2X_+%$^qDfO@6=leJ1Imhc`Y(bw2qvj?7Jh$H5N(fe@+NnZ~34#W)}+dp`dUk9YaQ z=a1=)7?ZbM>rT^Iuaj8cMkxW9WH^ub5B!L&i3s#KVkDgWuLuAHwRf3C&J% zZMB8|fkyFr{@+~-FkQ3ImS)GheGiwrk~29F2_PH(pSA4*zNN^ z*#z_jfPS^~i$71)ABcoVI2lCt2T&;o>Kch zBj^29b`-KEh%D+6bjQ8Vu$?nXiRbSY+y4+$)`$&pWtaghlT zl=RJ++AqFkMlfK!lgV|uAfKvI<@ujM6Da-2D;iK}!`7nj?) zd4)EUd!MM{yKNp!rKc7@SFToId^MF;;T-VtQ>Qd@L29jxk1_I}MD6I@h<-@iDZKTV ziaNC$u~_o?&N85zg)P6(hH}D|iL3l)jLnp6?MfCY)o}JAYyzmB8smia+o&jGo&(V^ z48y;KPm0#$`VRXmOp$EIa~0()*FjYbX6GoWS)z1rwVf&aT!vVriqyen>;Xjk^-Wtc zH>j`KVin*vbA+8wamHqq#!30&z5;OpU*Ud6`wk;kw- zMuiD)Y0z%klOE}-fz3G7JnG>SM0I95~jaq(Tfvklc?prNi_93>XGi=rE((Ix}rYe?^nR)^a3N?Nk)m2CLAuR1S zm9;M2_w@(?Rt6Nx*RRqDm;FNCq3yKG)JXpv?-@={R!JS6b47~GYc?I26?tYpZ*Y<0 zuU_zYTgHq0ozUu!;(+e8L(2~Yp`8^)Fj$E}L|HfQXLi&kM3T>;g^0=V%rcE^WDGW$ zzRhBZe5P5)UgTy&b=35Q!;a0}@YA3yc6&olBm+LfPPXZ(FsDXvM0GT=`)J#I}8k6>l@u!t>IS zRhdQo-m7T2-;yn6<vH>RRiRRO9W@R509h`t|fYu^3t@#Z?d#f>FT&%R7FxC zH}sw{2V$#zoG)dgiZ!&m+;ALiEe`baxd;Xsa45l|zen=n1O z^x>$gL6sOf^%wrVs^j9{;SR`Hj%WM1-yqO?8u_1ElOv7=Bq)PP0zX(pH`7oBpAQ!b z{hs`sw!PUEDt@^e3Fyw^s1jZ1uhhl-YQx0x`X)SqqE`b3(Q?mWjA&^c=mxU(VDAyR(qppZ6iFX^pKYqbZSB>4sVi>|33 z57{GH4*vVHi|~74kJ>(mVyU$Y-va7=LLy6&OaB@3uT`?apPFowa?PI#4?52VS()Fm z+g1hRa#>Dqek>+zIl}Sm9AmOA%0gNa)>``yR8z)RQea)t0o&#*e5~>p)NF9j8xR50 zD9nD3WP$|Z09!dODa|f~A#nkAXbBQJsB7_%cde<&pA z3I!^j2-cOk2DAGQ-cNNQ1TI$z80jFT96Vn{fRKAB67 z&s|FAZBW`yR|ezu#tr!w@OSnO%#zsr1Adx#i_$VIL{jwbF;6-{HSn~+wu!x_MtDq6 z%;dGBQF=I)qB{PKx4rD`+jy`@MyEm{*^?v0m*0VPns;t=^i=_E=V_mUcAK*}grHis zG{nkH*^j@HmOd;*syff}ZK?Q2;l6^P3*f+Bf^UkrC(Ll_IeUbg?8Y6qtWWC^Nt-^4 zmth9vTF|RP*}<)+N#<7pJ5sqy8k;-GlkovL74QsIA~bzPSbYN|bB=;6S$($}_&_q+ zO17^J16eWZHH8I-w|{Og%hUiPa~6{u$>+h*Pddvr^g}dQ1I}v|KweCwrdwC@q!I*P z)5V_BdCAIN-Z!fr&Ph`^ytMr!Er%aCtyBbytNRVevle~ksnh`Uj81}znYX0p$x{lJ z+-V1d)_cZ5wJIdMf}#nd`ef*5rXYZHVgRJGGxR&MqZ08q?n0RphGahFg+K?Z%eZui zKnB!r$Frj~PI~F;2L=48gEGl2i=?h%^&a~Do@xu8;s?Rv&t+$UsvEj1mEBk#z1;6| za;j!iLJ;zZbN&)y(eA@0U?VEY_NL_h?!VWb#0!NslOyG)x1082PC6cam6OB159OLr z=p@h{lD{a4Bdr+8ogbED4P7^%9GhK!h2tRYd1wUyk`v-$n{Y+Ndreh^4mp-4>ORgC zSf>>_ZieofruoNTjy;{fU&=b;1OLs{C#-Xm6val`ZMp*KlyhI2iG+5s8B+b^LKYk{{+1Mw4~Ggp|@c6V@&t$ zqJcmUqtnz=HU~;KIYa}p*qUVvTisY0BSa+Nq~*ttrhv@Ey^$0_gZtURhe67@cLck2 z8}jQiSdYuz^f4CIF_qNk-YudGE^sz4?m7&)TG1t%DFUUse~6Pu3iooH;)=mnNN)C) zTWV(&?)GO+WyRZ{E_w%Tb*HRPzpu^Tm1g#wn~%ru(Y-qR=JnU~!*w_b7iwec^k$zabV!}r1={2Dt5 zX`GpKI`X+>j2>mublDE<7;EPL>DuJ6UvJ4y8+X!J9nZtyt@JOmP;P*mYR|0rD%=(k zT;UF}Uj<_2eO*j~I@1~8eu6J`RmQH=o@YxK-3(VOADw*;=q~!J47&$LfII?_Oi3)5 zs86`b4^^G$I-6bWM{Mt@hP2Uq?h;cZ@5>i@YYHNvtF$JHFOEh z0w9g)L=jNn8uj9ZZLrBL=Bb&}u}1S_CzlTIWj8flfthTf-$x_1a??{i!}Br7chv2kl~w zqyYesb6La#Gy>>dr`O~UQl`U9!zV~z~PV$^r}5QomfT}?c$i#lw4a#3o4tpgeU(tk}( zYPN8Ki51%{#FX_v;GsOak{sGw*WlYd!e4_A4vI}W&aeh`A1SGw7MU1oya_<>sz-`qWydPyaNNvn3^4^H-;86Tt-Hlf@oda z;xWcbQLO|~V!Eb0Iu=iR6yLcBT0B)W)DI@nS)?hVsI2g+<8fCRZCAWFr{cP+8_TK? z`-Int*`r-pRmNRAZ0Kc0FwQ%IWHvI3&N_w}SE$mc5bkp`E4oOMwJ;6PlR(&1lF{x~ z%0@`fzw=4%xu1`Gh;@5cg5T#Qicw6X!A!FkiMr4=kTxF=g*^WY&{Ti7aQ{67Vllk% zOVp@Skjd>$D?yeJewm@o5(gKHi`3D>oj9 zOfCTejcRXkQ?_|VmM4|Tz%e}kCT)0FhWLd}T-p!bi(LEw`!>FKU~K+@KQRInRla@O zy0`Cp(Bm|b5zagff&);WPjyPC8Z`BL4bYJA7niJIODa=5D-I9%Q02pVM|F^^SqK!_ zNhWHvC6Uzzz4HgrSeujCh5uB~nvphy&kX~rKD{*iK-63m-I@F&F9CkM6>wb(OSZZi zk$C+rfe&5dGTYo04dv($zp^YN!exC#-48H0QzNm{{TGAwPsS+tTg{!ShWggnHl0AL z7AkVVT!pspUJ39OwrknwQz(l&ZV)#j{+7JEQ5u2zD*caa&i@zS{>(79L?Lu%_qdy%ioP|(0!yf?3eiwaz=s#+kUcy5c|c@w)^w_i zMX3Kfo1%7;h3Nw=hqZw)(N*V_Om(ZQPKbhvam=*f-1lxGD*9!046q8^mp&(?vWs>w z8L3YojH2hH$+&{4RiUd+Aj1+)ACnKUmp}ZBMn~Fl(Gk;mfVZHLs<21S%M~pb<1^TS zfwu~E#I%Y`ud3F}%ECxGgD-bsirl$HzV_+Q!_p&bvt98zymvew0 z$ZT+?F&3;+#?PxF4|bytBOUqd&}-VShF^XCk$88mcQx!HUT(pdWd-M56ZL9VkzI8h z;EhN{UBVr|7nY!@FD1>obMtW)h#O0?vD_oo3Ay~8w+lny{Ll_Un`^Dox*ndZs=sQq zuYkxLB!!_ey-iIiKJ&v$BYD6&eVsRtddzE`@yYl6c==E$tv!_b+d1mhwad+=y(0MX z-~7!3(qYpx_?$TYB~Rs~+ekI|)Gh(LETo;UBn?l?rTsPNt9mjE=#6`{DnTKr6f>Ke ze!?@8C-He)hD7>=2H!?n*7KcRI$J;7-EIM+rI|uir_8GO?Rd#wK#F}A(xc66zSldu z3VH+}@j-|;5xJ}D77EvQ_ti>%LgLTATTX8sF%)EH-%^;^GAzHQE!}#SH`H;7S#Uo^ zVNuark)H%rz6B8bma7`EJMG6C9@NIk~e_x~N;WY=|WQ*X@#4yElIgaP!qJTzY?;^4VY zI4YfSG@pY(1Vt=!3v(wzZ`jg_wQMdR63T#=a-*tly?8#zr99`y-xe>L ze<{La@iEb3!!j@1Lx8lunD;l2jvhebo5fl47Z$)d`Q6S5PmPk`u?K%5M~l^!H)&^^ zR_b_{fD;s8LZlwNi8s!($%yf9Ok?kZ8X09p3->LVII4W+J&e?s(J$zeq0dhx{Lf(2 zMKK|E5vM2-WQ(y67hO3OVp5Y$<>tDjZq)WPQjK#Mno4Lu5nM;KgyB@Beyv948%Bvv zyD5P{K>NME6=Yl2I+^p|4)(ZBG+E{Vb33 z^OZgo*pBk?XV=l8>Dfsl(JzbM^PDE|pvW6(W3 zI!%8nJ=@dKe1QWr13rht{tu-Q1=QZ!#Nen!H_y!CwBiXE$0zY0&28-2ISYWjW?4Ym>r^)_zt2x$=xtfoN z7vPhpFK2o?|NiU?Qbia**toUm{5f~5WH??K9k~?|MNrxjh0+~%`hCv0sWks$izlJE zDFZTl+Udb*rK+<$drHBRO)mXH<8Nus18qYAt-KOinBW*&Xh_>#dsXQ~L@;#o`@Bju zP@-;Q^#x$0@b+85f4~{iEL$+`H`0g%hPldm$aPj7j{`gZ*rHQdoF0Z>1-PzxLjEQP7}m#XBE@Eo4eFoVT2KY zsOUaOltjzP`}i_`CKEVV?$M)zKaxX&oqA_+@~iQ*5~4A?q~FaPrB#|J*S*&-(ADKU zTo;dQWgVSdVx3*U=B(MHH4th^Jn9GE#&gdHm=o_*W_z7nUPsS2Vv49CKS2&e{*w0> zlkOZay;T{tlKXA)$3-@J`9a4>IO(xwS)F)3Lr?k2)>;5;E!&AK6+Q?NRR#+&aTzE9 zM?@?|nFt=a%RoveYPsz6lHwtJt&1iz;mk z2Tpsx}Ze6IObPxSKQ_oePhJ;{A8dUJ8{_?b8F zm2Q69wCB~u#≠5CATB<6dM@(r&Ef(je~E=w<~t8L)SEZ$aVv{PG_Xh7$$_Pi9Sf zTHcP{xBLqvvM2~>K$j#yyAX}`@8P6A72&US5-I?HX1c>czYi8#%mp-{)jfGIg9bB# zs7@eQU(FnESm#{^d_F84EckHZ2O*&20lWhhcN3!{spAj2ImiuiFlNNUL|-FBrk1v_ zX@%8#uJorEo2r3}G_1|onH{o&5_ixd{k#A@>!U~a1E@D7+204!kfUckRJ7VmxE4je@sf@QCNvmb6mj&lMPqEm zgn|^xAgQ`ll_QR{2b*Ln;CaeyyW%iHF%p*(ScmFtp9s}94e>`X&w4D@t|2iLrygw7a z6mUH33*q~FxM7J`98fd{P}hG7(Xip}3(){CZIAVT9fXK(q!_FYd|Li!Th;NUd(mit z+bxy-^-NX-XmR&p&i7SCSMkR@>UO`6XB#O2eI8KXcK=|H6axU2q?O5elhXgy+j&Mc zm2Ghx1*0IS1ENpq1VNeA{qIOA9P~b$A=S z1NxgxTI@E)L`H1-gF-=t;Jrmh`ct4wB^yYatXfMbuvz6%&$gjH?@Ml`TGOR!d=tITOz8KXfl=E5MtRJrYrNZ0K=HyA=0)}OVR_@!o&`DV`dpe7)QuLt zH@LEFK~6Jwjo|CMsG3!3-nZ$hdnhZeD4f3Mbb>55E z)4ek;h16`blEJ?F-9&-qZp|X_c}d6H7A`*^2VGmVO02C{CEb|xB&jWrd(QAwP`Y>B zXxQ;Xn0>$Pr<^Gpi53i+(=a&=1zM^vxIurhhNJawHBd$+2N5C&X#i!gi{%mGG7{v7=c{2r!y z^1!TP_Mvm)^TEn%>pBz$8GKHVk!Xa?{u+VomL8X7edktb^$+^^UwaRo|3TK<$;%iZHJY@w0R=O(B56Wt(s|6CK?w_r3(VpLt`0casJ?Dpqh4(T zEiTbB_Ml#J?7jz_q{J9y65xvQiI1Vyw?<2}+>m0U23y}VQfn1xSao8B5qdsvUa!=d z2s&q+R6rM@xF;X@`TPT*`>9F?9g(HLa~DmmU`Tc~8`2UwIF%A)G5&KmCiOUeI2(Y< z@W77bc&l>IG5c+)=y`31GRgCX2g3N~1Fg7+@WXUJvfYB3^T)WTSO$)js1oabbK}|U z$BDRrQ$bze9=BfF84=hKNVzZUe!DHD5E{xNE<@e!tp{NW4=w{!jn1AmR;WBj7OxI> zv^W}g@3Jfdz`E)P%rz)}o~_c5NJvE<;%9$I86Ru6p^~7LW0ZsNsQa9|@)7`-Q+@DT za(RxryqJR_Ni6s$pKEjZDYayG&Wc2R?ge&O>CGwa%5h+$v(et+oS1U->g}6sbrUoU zhtS$m)lf?9pv2p7cRiVKSe}}^?#%lDoCVudsieQFE!6W?Y(qn-HPJD_ugB&IWTN`l z!uA<;Z|v2K)5Q^=_^zjWob-;0ZVhCHkq7k252;z2Asr=nD}S3`&Elboza?RUt`%bk zQ`CF}k;97ILrSvBE(7qw2*|g$t;9!V{>Fz*Wm=cl&0AO-W)te0ztt{QD;umPWjLaSsPZvB|t#RcwStJ?eYGBJ}eWq(=KGTQR&Siq(l`UA& zIxSfQ%rRX9;-vKwdOyGLDNORfW(1RReZI;3j3R2nA5?NN!pjcA`~D%^f7sib?g7P1 zlw|7+gqwXGSO$1$QxXn1a)znohLE zX$6-dN9pO&1T~iX6Jbp8Zw3&MP*?3rg0L=s!>K<2^~i? zD~dB~V>Cho6hj{p(h^o~nn)EtKjxn-cOqP?)6$=EA2ZAueg`LApkQX$u6|P8dj{s7 z_|RZ|<755Kl5D4=zWoaB4JQ~LzpvSgV<$s*k6lopi3hG))nAyP4R)-7RObuZI^*^~8PG39eDJkE)gR<-YO z9}ES#*OyxN>IA{zv<)K@)Z2oc+3>?zIvjYXu1$g1y%47v#iZ1CZNzF>xj(Qee zsB(^>#x=W)wWD&&tJl6gsu!4BRO)Q%t>?NPpPneB(xo-ar(}b!X?O5VcQdzWY6|$k z7zrRlNYgIGb;5kVk5DI#@5zV-)`LF+<4^^_`SI(lUlWW}>4{M}& z&1ibie<-LHGMy8WeCO!-n~l^*1wo@Z@O*B-Vf@ zp>m(UOL%|gAntMe=G3_ancXxV#O=YAD$Z;%D?L>gBLV+^-S7E>dh*12Rxv-ML73n%f zN=i%T;qkHd;k&jLX!w{HqVcDn*473But0;IF+}3P)`}D=a!GqN;&N}&lZ(-_0I3gX z^HkVQFpEHRS+0uV@+&;ahElHj=H@-I(2KoAwnkd)qz_CW2&btT4zIB~0qsQKN}Deu z5C}M2P$Mt^&>4gR=Nn2KTaZYk?&6z?Ag0v?r*3o19Z>-tbi^rM$vkk=xHbpy-de8f zXY%d^c1_8Xv_5iIsPIZjW=_s8E7Y;MFiL99m4quKLt#B0LL8@)356=oG8xTJ#1lW| z#P}GWi=hRep?wu5q6l(`aHvjZ%v1|kryedDUVzl$Kob&VaZh#4VoOD_=GN95bk;NU Xzln?+?*ZUx7M4pohUW{<+1>dE;=6U$ literal 0 HcmV?d00001 From 321c8f41273081ab4dbeb3d0358b2d2ca440b21e Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 12:54:50 +1000 Subject: [PATCH 014/109] Delete windows-edition-upgrade-policy.png --- .../images/windows-edition-upgrade-policy.png | Bin 45890 -> 0 bytes 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 education/windows/images/windows-edition-upgrade-policy.png diff --git a/education/windows/images/windows-edition-upgrade-policy.png b/education/windows/images/windows-edition-upgrade-policy.png deleted file mode 100644 index f9c4fc3a128310e500be82ccfaa19de52549b613..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 45890 zcmbTdby!r<*DpSbf})5>w}424bc0GtcZbq2bT^73-QC^I3|&fh49&pM-9yK~@A!S+ zd!PGz|GCd|&-1{Ub9S74&R%=1&-$#jgOwDdurNt5K_C#;7in=75D1M11bQs<>@jes zN*D_YoE|x;NPPxXjF9aB7f;MT$$tWYsv}?AeR~RAKew0Gb^?K3b^iN%)N5B{0s_^{ zd=dYo=5DaR_~K)%`UA#sVCZ*h#+=8iSP*d^iEdrQKueq%gC8doq;GNvHUO=!k@K#F zUdor34NZn{v9NSD=dWUM+7%_$a|9ATk$56u`_txO$zx>h!rHnj9LwHUwA^FFW5j6= z5-8lB?v!CpF*i3C^KQpkpj<;&NhvBmK0YxqF*Q|JPfuQl*QyQfU@t%>^??e;q)Bl(Xz5KU=-QhFaC9@O<#jNImxCUG(5uBqSDb$i`o!9Zl0?x!f6~8{PHk>(dfr{Y?LK|_lv7rt z>@2~>;d}I)y5P~mt92$%;qB5FKJipSOa+fXf5_i+azZdAbc8Ax85v6qT0Jc+irU-T z>+9>2(Cu&OSy>C%*b~_dS?TGEG|EZ*SwPNOO5_z46@BacorAZ`BZa|94qIK8ta=Kv zmn!*;w!%$0@dUv4N5#Mm$U6j7JOTudIPF=&2Lq zD30n7vpurM{+&zmmjLu#qS^Jp^Zt5EFyVvMBz?*|M)e>m3Xk=nWKQbbj{#g?O!hU^ z50M|q5O2s)7|X00Wm;6g(sBE4*N(c_t85q1>)>7T#w8@A0~$6uZ7F03%`wmBFyq7C zMc3nY^HAv4Sr;3&x6xN=D<~*fTknsg3rZkj5UpOS=^T}`dEr@XD3b7ks;cA7;Z)S^ zB_Xc0QdzvgtznC^U;X!jZz*?=!wcPl3e8lE+3XhR-jw_<*R7u}Q6HR{nHd}$oS2wM z&`pBz^4|pE5Cg-~90)Y%_M;$KElFU}O&Ah*OGDH77a^wOu=9-|8xzkmSWbK2W(;Pf zjr!?lh+<#KO!rbCySz|fJd>t5Fhh!7vgmGLL-;Ug zSV)bBIC85UZ_fWTTKzb8jLc+}89b+_KW=du6k|GQ9SQ6{W;B&~I4Rymr#vLg_vAV+ zrkv2WdI+4780b^co-+2vQjlb8?|Q{VN5_WL(i?SiH6SDgL!a`7a0UGWXrJXlw#fD4&$ncPuGVukrqsDov}&vzAW%IO z&*p-F^7FL6C(?UWLs3;hGtL4CmxhOX6Ysaw1Xf;aJL4e&AS#K%*i_$|Jlid$Pekd!1vJQO34C z8=)#%5JdfSLx?N1ttKEbhaOTREjFc67e7r^2~%Q@(bQyYID24%9n~L zOS?YO4o;k%^q%@r3wAqPNREq3VAD)2Gi`}HfEW{ zc#Zgfmcuz<$g?wgW|%d9O2HJqYz89Zkqf2m3{=s_PO)95$w>dCd_g$z#gtBZVY%kp z9#O)PQ8cvJG#+agbdy9*%9h@LZ%P^Qahmu$F5Zqkw@ygL1Ix z2iiKnhrpH5+CojmP1zHIO1IaiV@95unO${JF)$|w=Epf$+bk!Ia|FKzzeR6IB-EAP zuAOmK9U=;bb0Q0>`gfXF^S5&a=Qt|&4cNGCnKj?Lc**JTHHifl7N9N{Gs53799$_9 zl8A8Sxg8;tm9wWdNSajqQpR3ehf|6o8oy14;4_KKwmyyzjeBg10)Y-o^qXC&)jyk< z%q+n(h%^>~xA(8(001q{=4AFW1z+E)-kmV%FFui{P}m9@_xL5>gJVYjqNsWW!wVBW@j$AT$@HR>@~|drW&gXrdsUiW6-jhk&%&PI02lbB$O*7gCspr z^IYHZ)%`DO!Cp;TsPOo3N=TR~9<|Rx7)GezhIIEX_(KGW?j}h}!-$wbd6G^=!Pq5w zx?bJZHQ!f(630sqG)V3G191!$A~Q|r}B2ZWX$o}TNawe9!G*$f(lvIdP< zG!+>2I}dB&xA$&Bf~cm%b!D|YhBg=QXn?=JQUB&EaT-^|rjNdfUz+w&wyAvTmzKiF zY>&L{TdZ>V>0ex6O16|Xm|Hi~&6ABoHtGb`i;Jp;5+6>FfLo6^6Ay|yNwMPOn8B(d zu$?il#Z4roZlwi|%|~lH_9&SQ;W{@>rch=ZU48=FgE-yp^~BUS^{P4f%lUv$ov1-u|c+KNBX1%bZi!fWK2PLB2no!((9DyD1b(wquO zsA?jGIJw$(5-YtdTvDjh74(xbj$E!vbcU4BJNZ~VvNZZ|Pv>6K%#E1QdSPo@yp`$2jdL9cWoIrdJIKbY?APronAmUWg9+&`#bGEu zzloAE`$kOQ;xlplneNNDtEA3*(m&{R{VeJUgxUjjyUqL?`tR8MKbHfBCrg4;rHEG8 z)9`~V>69fgZ7|Ns{pEsa*5Qibuw<96DbEwc2eTJ|RR_&>{54$LDQf@JM)gg3N0t8` zEY#iIZB;wpW4PvVTG-x>$lOqmQ!P6!TGPKnbsggRww{<5xSi{69o=iH_Crz<6-rM_ zg}KU(!&zM~an%_^s9Y~t4=M~yH9&NNuKQY!jx}?$%$N{r8X8&RZp%M@;l02Chm*GV zpn>cQ9qwk_w@p4S?Mw88NQ4rcA1>;eq-|w}-5p`;v&0CU(qX|`q>%Ty6`$N8KD>pYh1crnuL(>|i{f+f<#=v= zJyNKBA&6l)KQpw4r#B2Ay#Jx29+3?hnq5P;Efdmg0D(TLuYEnr#^oRL(uz@_n;T<6 zQyM4R7JdSl%oX>eZ|Xl!2?5Nd_R02*B`_A?N6zK7Z7DtdbRYipf@j~39#Va{JqY0_%$0Qho9w$F+U z0QAx>-0vEtQx;qS0RfGTjpaJEREg_vPHfTNY{|F7Yu@02efkmpcq%= zA)Sfsa=Ny3Cy_0^-Q6HQ!Se*U5gI4m>Yjmldg>@a%j+*a_#Wuf&l(s6iTAyr@~2Pt z@zBXs-WuqM4$bTGl^a?uUnBS*;ZUMQV%XMdr_R945!#ALm) z{XQilLm`%af6Ya&q^fFpGra81|FOWQJ*ZBll>zhuKp7~HyHT~d%znQ^M6KYO6}rS% zM|>M)u7jauH`e?Q;6L9V*}&`cTimPZOFjb4@^gDvODsDnJh!t2Tz1Ez z5B?Z(`^^MP=4J;3!5oQrZOOW|05>wO&HZF`q0wn)k391UXgLA+)H0)h(^9xKn8-FE zb)xUKD6z!JfCA>GUp;MSkga`xvKW^ZaCvyWuj~!Bi3EPSdw6&Z4EWJW+-yDo_)^J# zL<--jB5y3DqwG2E`B+- zWi}k}@nI49V^VBMXYS5@FM!zbPp*K6c` ziwd-eDDl!suDswVpm@zHNwV2A?bC()>A#qK_Z0Jx~3} z*<$I?9rD~7zCVjz_;v3cPucWtM(J1NE7hVu!U^=a#9wX>n~#7=7iU-c`t>b#M_N!$ zeOVcE2(&L4myVw0y;|M+x(TK&J&by9rjj?z+JPYidU3S$0JKU8(9W}*C^*~S9qt=! z-B?o%&)lK^l_R~E>GV)EW!0(w?Kv&|5F;~l-WR+Xl>`wqC#Tbv)|Q2@-@~1#St!g} z?~sFM1|d0^;!^!hE_?J}2|ZM)sHmn&HLY}y!XoM>Hp+> zusB}+i}xe`_C+BMixs@irsX8;Y=16Rof0vBdaH|NN}lFS9QB_`F0e055#8$pelZ?)EvayR+=! z{<6JA0=hc>SEjVi^<92p;lvVAZ*xA=AfSp!ad9Dim?`3v7&%t)uB&7H(`fkS&{Dcr zvS{cU23Z@nDk{^jET`p67~^&Xz0R#9QRs2}4)kKgnwoDk!#6Eo^LYCV04g(#%&T^th>5wR7w(a&% z@aC=0=`iosP_h`ErOx|I@n{0m;;8q^PfH}@uk$cJX6~MGPY=mv6I#Ok~zP3Vo{6 z!+ApKw9ZD?HTLTrFCFTyU{_F0aF3SPh=Ow0?a1aGmFL*(yY81gDyCa0)qe+8n`Y$} z5ed^G_*MuSa~1szlUeFco$wdtFDE3hJa(}ivmH!53AQ*17!&dh)B6iXynAWRifdu; z#juHRyuER@>bP{(9`O3hBW6J@go#w7_p!H|iii~+#-q#;Eo*;vijM=G1AMVLQS1sI zbkpXdrya7irQc#0p``|;wHSm3vKy8OxdiIz6t!>~t zqwh98hsyN3&qj(q+{F?Km`#knX_ zC9GT=9F!d#*z>hz<25wPb+|oM>2q?hsY3GIxn-0RFu{{We=9$(59?U*csW%69zJx& z6EZO;B^{!-nU40{pJk6`%mhT?EJMG+{;$1e0IZSz>k`CV5unw?3z+k}1nO&Jm&kX! zn$dL3t*;||#s-!&_GHVok0j+tr)!bcV1z@~kx@3}SJIb5@#VrGT!$soAVfevnrxj( z+%|)n>+u*vOKR6mYhRmJrsueQo#E{y*^aD6N}XdLe6j1ffwo}z95$XRQS0J?gb3R3 zi4-pmkJ3Awf!iq}olh3QS3l$Q2=_n>yt*Vc9P)?JxaUuN&Y|&dUf8)_OpglmR-L22 z*KJW*+J{~g<9QU+AJ#Sn_zmq`VCV{d@d_R7O~_~CY?F?aPrnd>zqaJjrC`zfQN9&O z*FAKbF-fQm=jUma>=qn+Mc@kU>m7lVOW3J~xz8y2UZ!`wAA7{{cC9&v?i@F;%j8;X zJsYPR!wK6BFI@wT&6@q}nt`sWn|LiQ#s_vzNi=(tmyJ<9DFVh6I3xWMI)!0OtjpTh zE7k9>yNd^)0wO@XspXY~_ z*3Hx#0x*Nl!(Jf!mm`$GbOHuT;k8p3&FP~$GfgFsH7Aa)_csz$iC!9dxNLv$xtKFo zXp9^9hGz+|iwY*|W;`2wlpFlf1OG^04uza?ywkp5*nX^(5svy=Pq+t!Ab&%L`qKm{ zucfuLs{g2#npzhl|5T0XAT>2L`b(le5Ike$Dh1l#v!NF+yLkrmx2pchNRN{99pI{j zL^Y^Y?6s)=&d<-X!XpfkGZl2&48z4RtM%3J7OE%a%ku3Bc*(DiE+D%tIx(mB`>6J2 zjuiS02QU3`7$u6<6EmJ%$Zy}rKvicU_Z>C(e%1FPi6i4PN+eZRk?uOR%89dD#a#9mBRMoL^w-;`~ahBY0|xNTNNYu63F(b6UyEw!F93}alMKZH`0VDS zmvUlUZWIqj%v11K=yZq^&sz9u`6q$b#?=QSG(v94;~&Rn<=p5MB6KQHlWnFvuI#Gf zZ(5zrIt%JbN=ju6W-EybntFPAT3YS^)KYCw)l(Y+BOCQXq#P?W5YnNqa@9*UuqZ{+ zI>eOKR<=LXRD+XC;#;nAYKBsIk9sNn@RDVE+hzvnt2{M~%(Z0oU+!OJXTd3>ubRK)fowSCYjaZkOpY|fv~;zb`w@3AyDGDoRnx1ez1ZQk1Urb; zqRVR2tn4Z+B-EZqaD20znX7XuYnR**95e#^s7|jxI^QrOU@{(Nd8KMZu16*T<_JM& z# z)(n9-xHH_63+D4bw4z&DS|w!OXOe5}PhA*3?7p7Lc0HH}{5e3Cm#P-NGS#iO%pbRS zhi$A&D1|RR;IZw)54axy%pZWrr}E@?{*-x%6=gn>cD)uU`f_b|pz}G+D!djf1;6Pb zwNulmGQDMo`l38bm^tDP&Swn$R)gup3t-iXy296Tw=3%rfma1@Or{z znQTh&PKC&&U`2ST;HtQDzTJkA&ld+r;py-BLaoVe#|v<;x^J%mf86?bvOb4rFL{k& zgwKCFl7A7Afg;$uGg{OS*%-w2)WzN?Gp6aVLCDceoEJVEiv>$)!9RPttZr1j{UUj5 zRqpVXw7L4{naL4{$kt1^jle0TXw_J`o?!1?x@mP3+2@INS{=bKv3!LtA5H4zY*5eZ zpfMv4e{$K7IUc)l41TP6=Q!pt2F7Y(OdEk(k;eS9*^d-!Hbh7lm)=*W7q}3TyMVsR z`mPnWODz&!<$Kxc`J_#8W`fB}P|a{G?sRo)4$-<9)AZey{_i%YxQ(tvrf$Pls*NDO z`)fMGHnHNqK>%>DHn|A0@PGKAWMXlOA8syGvMj?>(nyk?ErXEDHuA)N9^iQRD_glh!l4lT5|O3N`d2LUv%|ErsEUG{#O}Z zOGaYN+VCp5vp8)Wq)AKlMJP(o|=ExwI=3OTrOi|GuY& zXHPhgLx+*HX@rpfvP!My`9R)pp@g({gBOAA{dJI)TLM9q;rnT_Z#6;a*h1jh=mByw z`Bb9rJqFaSm?fzi_^ldzqm#pQzo`A=Jju2#IS z`i+kHSy>-ha>YGw@EP;IsQoB8xdGT!Zm@cGbA({enkbtvvS(q6TGJN#^B<)EXg&2i zK>_cp;}?Xi0N0+su15T zu4p&zo06u+;EmYd5;>ZE?nbq4k9dqV$MaiErLsU9Dy!+`Ch9g`S!8CT8UJVpbvB1D zZzb>nHi+HlT}Vr;iK(g2^+qCe7LZ?afLW{rD4HCJ(3hX^1GMqx+x>~APNg-q( z^>F+uK9s~0>cy}Ngz0w{@|}L7W6>+?m02#F)je=iL=J}*UQq0;Lj<4hkE&fA)NV(v zpe~mR)kSajA!h->e$fKHcYNe?nE(U>2qppxqx#_s|J8rPkJq)R`?yPGp0Dxx;uM1ZUk3Vs4_eH(rjb>B5reUG@%55_rM{wT$ zfEpcZP-p0gAcvP}a|%#}v~-kdLt88qC3bUGjV?F^p_&XsCEA>C%apYW z74)0Vx4%re`|w7^#H>~Wq!0#$`$xR*v}Hc3w$nM=@Z+^C5Xhdc!C?*EZsK#^hMt6k zghyi|AgS_O(ZYXh07m!ck z$;Y5w;22tcZ5cm&Y%V!!RhvTi7zlXhj(T@)i7J9-UqmOAZ`%z`Oh6hM_;`5}Gp?%u zZrxt=?77_)wD+SsJzdyDO}vm+==iRm`gcNPF$lCw;jY)6QiX@M@;npsYa+Rz>swe& zJQb8f7Kk6Dvj5T;_$Bo8k4O-7-|QJAP8;Zr^mi5}J3$;JH46sSpT{73ub}FzJMlbq zWZ?9_7(`YYAUN82=f{WdbAU?_D9vQThfrwg{ye1bU-@@c4;dmyAc6r}ek_naa{4pS zU*gq&>S106{Y$^G#~0W6cU|HCAHw<%E&73F$bbD*2Lux+X}|=g88|dQ<^4;BT4wwo zQIEHn(zziUu6tYa{$aXI5ev(aN27Q_FiaJe zDuGr`3Tkt8ROSPDv}kSEcZQZP`mtj?MFyEl(JjUS8kaeXdvuQYB|~UHy3Ilu#E4Sf z^#>lJ3}F#Xdk;yumf`Q-p=SCb#meKiC4L^sMi=BQfxIY{99R7dvttv!Slk$8xVKnV z?QMoC6};V=o+xEK>HW3Xm;?3CbIWw?FxD8*i>@uuDgDTH(Ns3bIwt*t`@I{UHmtDS zkExhXSjyx`PL&|z%>CARNj$n-+LXc_czZJ;9@_;z3q{pvr#@f`!YT}t>_?gvofZo+ zM_vjrC%Rgv@RXVP${2iwkiZ(x{&XkDOdhZA|Ir}UrZ{DVV19CG_p7<@#A@ABsw$k? zmlay{f#^|jy2YA@2ciipkc*7p&}HKMBpKOVr(~@cHCgJr^>y0)Wn8Ar*rLCEi3WBn zJ&@S(Us%wFs2~c}a+{X0!5^S)3+@_a{4VcLcQ%NnJb4C5)(rz$zW0kH#!i07ip>6$ z`_^sX64J+_E)psLfgU zZ~fueO@Qo@h@d3qyohjKWSk&xKlrTGcRzlUpkmf_Wk>W%uU3>~{;M-5Wg7;JZ6WDS zbsn=$fjzP1n|I-2TI$-RBPXS&KJ>0oR1t1+pEFdSa8BWRChWq>3vKlKn>?7kWY(Ym zgS3#xTPwYOv|W<7+S~H1s@bge1nb1O@WH=qVRWWYj$h&n(_TJ<8}ICu#iGb3q{6h7 z0(rB5#gq%aZo_C0Rk-NUx@NB~fi6xju$hTz=KunpnThmmN@qJzuNxLEGNd4v3&btIoD4qu#57wFQtwFfqE5z3 zSAOztyD@6q?Yc&@aH?1#kH^sAXZug@2kED~ztAjwc$YX@e0~qp_cfg#!cLtyHylsV z6h%6kuL5tY(u-yKGphK~T{)IYXv{-8jxI`bSsj8NgZ>=+RKOX@mKjh?Y`JwV8HMD+ zZvvzPo)3$xjWv8Mc@sLe!1V{W^Lp17yxOs0MG!iFr5d|M)cR8W`u#Ec^m6ZY- zUX3({II9_V53RMx*{tH5CG2weuwm@+?bLHYyONfc&JF&0Q9=RgS4iCbQqhY~_;sE-mNFm)4`JaC}C6H&07+;Z#~79l;hpyPZnQqX|JA zy<3`YCM>&6r}Y^>A-PUwBS0GF;lB5|so*yeivsFz$9W#^bnM++4nx*Fc61^&Y<`+0 zW6|Oi+P{;B_?5o!re9t?%1Yc->-l8}xxm-hb26Nj6g$n1e3-E2 zw6$)^IeAgW4<@oP{nU>ZNxAYv`;4QKwKeO74FxnVLhEm-n5yMYNxSfCAojj6l15

    9VNP!P}=#`C)4;z{B8&NvCJIf1?jD4 zXY+EQt;sGafyX!-O>;N{%G@QKiA|MR;f=>m=;`u4O>S8qauA((clr8}H&-n!h&`zx z5^3&=S!CL zPi|h}t1_1-zANB*SkC;k$EmU3ayM&urqbHE@oYPt{y{+Hq~NN31LbtFgWFvecXA!} z-tt8Pt48>o2WoMHkZ0WC&Awd&E0y5Jjj?t2CbOMZvX`z(<+b+tY{_Z4-)L^~9nz^# zX&ApGl0GHTTL6k5KcwZZ8!zxn!SaySbkRG^puwBI?w&_AX6f%4r=|{D`_1*p;G$ol z{yO^P2Ur}I`=#7R${8pPy)Q4r*h4GE2VYvMfu9)q zze^Wza0prO2kdP<+m?im${|eFS*7x1HdjRDA%)!A`BovnKV61E&Q?o4hO0fZ!7BT6 zgw6w2nAE&T zUXs&5*yHC&iUAe19py&QmAs}n6^o%ua4*-cD!=pQ#c^&CTUYa|^pXkAZg9VxV$L}u zJ|1eMx%J%+N>0GRb259v!JT`)N;MIyd3*Xu8~U+Q;4ih^swCAODQ)mBm*+*@n!YSw zT4jt-6N-sT&+0=_w$$Hzvd;T;0cX1g)J8MJ3_9XxI9}hat!JlnpiR@M*oGf1ntR^( z>i6%`EPGGorvcAfj*<{%ai2XQCXdP=?|eM<^1zJLJEHiM9a9*Xy~oKi==}4H*)9po zOK``IKe{rvsNgM=UvXM$Dy@`n!ev^1z4{L8g;}vmMb(HZ+BNx0%Q+?Sbu?}Bip5a>nxVIszTc03yx6rD0+CwpUK0Q!M5_W?pV} zReZ{8i@%|v4L)JiJxq!m4ZlWB7we5`45NvX&KL!67*O>xNOlztZxjxx;9FqPNo4L$ zyIHxBvSgK&B+hmPvv*=n1AOQVq=QtD>Q$R9u7HYwaI6%S8!eVr^Mo}@T}$#61% z9DdL~{r0rL@wsAU{|Bxk08^9No8{4(7SQTt$9gVre`U~*XGsxb*6t)BYRS=w_swK% zWPe+9V}7H9&0DM?6;tC_G)X5^^mXUvv|N;re_OnI{Q%yYu4T4IaPy7z6PC_Q!n@j@ z&yZxN#j!E;0E|5hilc&R@$Gu@qQn8)n|hr6K9ad@}-=F1YKfkpJH1g78ZVB zK9ZAhtoUPnhgV=gaiCw{YF<+yC!7+jBk15dRsy|bbH8Hf(a=_|SFFMakf&s6;@h0r zoAP$Y`ihhbNswmWHK^Yl^OcfnY$9Br-kWi=x8kSi z5gAnWh^&P+Rd1&0mn$K0D7Gh1{tnNXBDR|Df}VoDW3Eq1%f=MkC2KD4tZZqgIqNNj zng?4+X?(6wEA+6RACzyWL~L(4xINgCk(osCUy6VGQMfdSt7A=u*uLG;@m`vi8W=`- zgDc)m!KDKtrzyt;ogJUOP@;ET0oE|Fr>)-FQ6TTVk98|B$Ev-Y%;?^ZbkUk>%{`)` z@Uhi!In-k-*ze$8vHXmodcb^}HM(#5JMvY&61$si z&O2IzTYfRRfN6Qp@Pi-WmE0sG^rq>}_Z3(N=AKB8`O%{toN(S(Mdv~8vv<-eMTu_Q?~A zw(+BGp8wwdQJuv907~5oDg=s}u<<$Yhn{SBW~@xwQ|Rr#ZZc z=CEzMwHeUkDJi6vUpuwGL|+nBtB-6qTcWfyrgt4@<809`$04_JIn75-eiB_=4dvkE zJ?X*0JSUkVneRhl72oYbuy7-Je!rk$86d;;LrGUiJu9!*ciEXde=?6I^RyAn>Lt2R zaWQ6w*!O?HC)`*Osqg8^uWV2o(mb<|a^CHlY70H@jI@s7=PiD#yEm0>Q(lyk(-#t! z$u|Dn0Cj6{daQY_db5?t<@@PAS8)1yyXS=WAWI(^WGzAFU@BW|d3zH!T1emY=8bRD z*&(sZ4{R?8MTP!ZqYwjAB8zhE$?CQ!5*F&yR9k-QcsY;FdnPT*Vk|$+TUOS3@aBe> zY0QtF9NW!8fo{+`2dGsu8g=C z9_lqKW^Jx}7~lY|)Gyq_!l%;=M`12fC&@x}*HXj6m$Yg72AlT6fTMY-{z#wA-kfNf zdT(i^EHlyNw@T7R_wN9zAwZD`l2WtS$LvWwohpU+B3{)}RxS((>j;}R0hv!Z=>NL6 z0Ryo^^&I)Z&Q7sB;09HCITvSCQk9MYPgyskVJ^<@vj!Izr%m~ z=Kq)T>bx`<2$1vh^8?hT%xOo=SiwJ6-L}6rTH^@Ox;2t6`%UBHN06y3x~_K=0nUH* z4zvn=T-F~;clvd2T#7RP4diPmHjMh;?h(+kq@IXE>Co3uzIu7^QV4D&?ZRtfZO;zN zNcoOSdVoRdH+P8hw zHg_#@2K=5ybmgN35sdEhrRT)!XeSOq!+%u7hm48{N8s25vZXwb>)*eF5Gmcdb$lW~ zK41%}$8q+fV6O|lH|djhH>dkq+Px4>lOX?+KPQR6h9LXG9Qwgp8=d?>?O#~qF~Qyv z4b?^&*_nq>s+1Msuv?8|q~FEKo5qwHHkeZ1UYu>$1Pyt(!si?4)Sb6pS$&txoUGE> zhg}HWz493aqd`I27_6tTolRz_Sx=U+cMzDK2C+sS*gTNfhz+4%&neSRGF?97Dd*N@ z+Y!UOc(z!AgR6Dtu(K2Oc3hFSW`5!n@6p7`&@b1ryUV(#i%TLWHF%6OC%TYxl1i~? zneFjiOJs{BDzphc_IJzP`3=Qt?R(+OHwhX#&5B-?Zjn1PzN_;SD#PP8;tD+mo1+J$ z)dz)%6B+p03s*i&9I-d2R^bItAXfQez}_LySHc-d9XuW7B#Gyqbp&QOh4q$L_~Sp_ z^Ug2d;BwUXjU3_l7BM7Wx# z!naPyB*ne$3pKJrl1fdoTE^s8(bv>@$9Kh^?mm@AhP*uS zJ7!X0MQjD}M*XXm)YLlX`%|*(Hqj3EG&rK#`j+*szGY}9;)l&PsOEl7;$KfRV_`4k zY3TL_iT~DE9-NBVyr?7d_|KzCfJZfifG0`}x2kWR_ME8G-S7A=R7UncD^!_0oG|e8 zO!na|(>XyQi;5yHx@oPy-j)|dyY-*Mp2ydnWV#4lqKuzH=9B9Ta8lwN_DoUFE`6SJ zHFs|;XjOlXt6CmHk7ywSERUcTpcoh{QiS%*cGv4|I=AL2mAGg_2R&m zz`QT2(e1;HbN}iVfdJLn(Ai_Do`pe4vaH|`oZ9+t$RQ4a;S>KTz@m?C^L+oP!tWuf z{m}{DY%G%N|DLfBH0bxO$r(xXzpkH3@DUaM7nk@y&+%lI{l-wD=>JfYH2aG%^=qCBe{&V8S(iR%7jL}6!CtFcL$hq0 zU>u?W=WD>hhvh9l2N$O#{l)x0Uf~_g=-afQZjJ4RYgmvq9$7)ObGHDwFnHZuhWFL; zP%Gju_(eL&e+fRN{>wCPplzmM;UAh$OHYNf)POtDzu{?CqqE!(Q93q#v)8)ptI%%5 zv$mYV9WJ8A;e4-LOJA+v0r!Jq;sKgn|w;?Q9I7}Zl+I;h$}DxZNR0D>ZuxEPe(3Y*?p9P=-&fN={r32?k11ZyzE}*t$Yq9^%}`5K+lulTh%^w z6jz5UUb>T7YJqo7ruQ2aT*%o9w>ZS;|4W)w^SxppftGoY9Swx#Pj!L4J($!-|5}rz zv$kugDwXxmSnR6JL|E^2Q$+74*R-TDS_}vn5Bytmm0wfRICVE$Pt@9Nt*h>QI^VPL zTR61bjeB^1L^18Hk2l<<)coMQ7{JYMAlgtXP2{%Zh@J7dACVRF8dMd$Aii0Jj@GC3 za1RD3}}iAep^gaMmsX4g{ni=hIvD@=9NvE zc~1YpX0%YYcD4k@NtN$<+0t%uw4N=Y4ZcbsTPo`pBDx$26+1F^@w^~4b?|!Ws9<+( zGVrYJMEEv5NvN`mwN^YfcOJDC7@JAb!^)7~+lnp1ZF)}-j~q~m)ugKo&^#1&9)O85 zzZ^(dDl4Se*VZ8qmD7mx_<9W`@}LTFOFQyz6T5lovliQ>7Oq!eGBHkT-0W7e=XS)g z(G!*=M7KiCVsk6lVsiLMS+(G1g+YVpyiaALcR88%Cw_n#2I;5>QEDGY4D`;!quOky zdF(`zbkvZ+OSPvJasv$r4U}KfgLDGA@FS2kx;2t&$T7S6jR2V2oIY+c+X)!HmGe^) z&uN0>9@V&w4Yf~T-Dm3jHaaPjEUFmcNlnZvas_vDDY^3}*P)T}cZYU_-Y^4%$mxl1 zu2G`(wHWP)+FZ#`(!`ciwFjIRu`CsATiY$lit_qxKW7Nxb=~(b=mwSU6z|sWX^i~j z+NhU;f7V%@hvA47SSuUIR(>&c*`HVDhl`ML9EL8IwFxL1IBsrgqW28xwOnWYn}<^a zG9%ALUjrl|4Myu#|K?AIeHX8FL&buF;N*JYP(_|>kw%lrKZS^3xbJT}Z-dQb@c)-+t>2X2ED-TL;43#ujEm_Q;)EwEk_)Wj${uwOuV1rUv$QxW3|z1okem%j z#(rdUS&NgJOLY-YrGV1y-r0}bysBB(yJHgT8D2_aX6rhRD2){j{U&ILpn^`kS$+R1 zwG7*UA0Ej%u_)^`blt4!<9V$$-+CHH>SWd%*=rGs)^xVZmbfpi;XQ9k0Uu=Bkr#ID zxvEi7Br_>39xrryVepmGQ_6GVe@)se>p34Clb13rje~`N9O)DHVuKc3Wzco;0gx34 zhvv0V%Nta`uMBd*3sE69_23uQMDmpb@uIl)5faJ}LDKZ#)TPx$73$Zbpk~`tvU#T7$5YrE>X8O3&yZ|}=r2g!k%q?; zW*Q!gGj`Q`#Q7bZp@vCRcE5|&Ro}m>^AfZrXYn{4;JwADs%hzBn~wKMecqhsjmk_W zL~px3N56P8-P6j?mlkhkmw7Vh+Q~B>klLF?Nve_XKsZpic74sl(@@n1V1i0fs`vl@ZYR)w^!F&4;LEi zQiSQcMrl?Jmw233pq4Q9kF`iI-*{0W1x4=r9UNfC*t146J}AdXk}|E<+f#S3BBS1M z(>5;&dCO#6H@n^Wxzk7(qqoX2;E`mp{cR-i0;m751*^p$4Co2d{bGQ5px=9+{ ze8@`3cp(pm(!*9a&h*Su3I1cqI*PEn{K}1j&Di{!uQn)#{U7f>dBVMS4O@-3tBYrf z>lh4V#F#w6H{SCB_s@L?F&Q7I@{Z__DEw*@Hq!LvuQPZ5P)as^A8aWrN;0C57N9F~ zJ)ZX|mSO+y#@{kh>i4+OPnzF~4{!fJ!p=G>%C>9!C@KO1N=hq;G)PMg(hbtxIdpfZ zNDbxCjdXXn5<_=McXu*B-dY%ZRky%hm+%P=8@nmqQDT`V&nUF!bO zlGOBA6O)WhFx3gjo$9%>F}=b%)Xfeot9t0ja;X!5lOt4?r$i9 z?nTF+hj@8iOTf)hA$zpG1*9L{ggTUW*8H^cE|$zyTW;bZU8RXiU3top8J;xEmnugF z#CoLx@moqECfmOkJ`Zf0RQehp8iu8gsdknN%cbH@0{Kfdltgbr#YK+oB&<}ZtEl?g zDY?w1tc`n@GE?3D(RyE;o|^#!|LI3#IWiFIQ5 z(=x6B%Scm#$PwBuuiMXLDdp^*`yE&1h)u*$IO(~sw+z0t*SBvL5<4NeST^wE5P!#o z*YNS6uMq=l)}U*Gn1p1S!~8N9O7}6SZdj@}LjK*k9JzMaw`Zq#6Ty3L#cjRwR>UXay>%1aHfFaAb;c8S5(VwV;~Q?DY%lS1b~cCIz* zyJt7nI(>A5kgxKX2~af-MLuKh*pql3wAHVc!Nm0AzIt`5Aby^BA+qaRF!_*rh1#N{ z*?5tT9-I?H3zKy9?f$m#aU|}@W<9mKyKdX>N{8*~HPXGbuPKy_D4N;a_1?j^9+Z0C z^bJM4#b<6sdUeMG6I}I#i`r)N>wbfxXy9P%KE^Mze z&rex*D>2KZR5~3;pi;{hW(DAS(q^ZwBPX}hzGPk9WyEfaam-!6lE3yzmOQi@r=;*0 z>;C!;FJH?nbZgA^&nb?XPlYiYhHNIMTR7Ffb5NqzI_}z5MupMdzw0jPLMoXvr5Tu=w3?^wKA92hhx!=!5{*nx; ztNv{9r&gzOj586Z)z!ob)meY# zDy&%oE0r_p2@;dx7CXBWB?OgeLmzPIlvs>?12WVV_Y7t#8?pIA1NW4HVaC_`>kZ%M zZ!pQGYu%5fNjugcSs(c9K{gMJXotc>j0fBN>674` zqQ33HeK5+GS@oW`M|k*F3ehS()|ys9u`+A)QlCV4LE7#USV=Mma?!5(V?>*}tE7_! zg|{QV?mezrvM9A{R4`x0(n9N@n!&3RvX>M#Us_l5RWma6mBaVmrgZk%9t zFvrpFmX=`EHIfR@N$=6z!Dd%>xXD^3PL_#j8ofSzjob0B-5~Hy(M6m-ippC*xo~s$ zs)D)}s(Kxr?8sUz)sV6(iC(R?2e$W(qqtHBWi@X}tf)OJLfA+3=<}Zc#yBo%)%x=H z#!U4s&s!FVsc#;WH}x3(X1osJ_G&ouO1^7cAI@pE`jO!CLDjA?wHRE9gIU5|=BL`* zfU8m7>@`!hN`UjutNLR-A2AlvL56XBr;2)+3Y7S@GS`_R^z1i(Uzld#P%=zFv-5>t21G%-`yzi=eu z+9dE?gw=^m;I%j86d9U*I~q|!$a`Th=fP zHoN{O?kco>VqwW`oB<23YUEcoeGNUxS&{14ysEeQA`S4n{1^+~oRln2u2#u0d2VLg zGbe&#Nmjhk9(li)Iiy?+_*88(nD_Sb{J?Q>X>-#G&1ZLPs#8?Y>4>9${Qy_gav`SMuCb_An4C# z%Yv}s#y#oXhFf82Uf0#sO)BD66uvI-(P>4|h58-s&wCVGOjh=ar=qQQj}{fUwKfS| zm7}(64rs7%k8mRTZs^v#)B>FL|J3jL3FneE`Ch*x^Cff>dd%xsBW@VX>)&!BvK-Ncu&c*G#OfbCxETbI3%bb9Wp?MOQtQGzzzJX$?) zsz=;=7&El61$A6&6g^AkOfP*NVjgiE-WHX+tz`_@bziJ|J&&UkrIKvH5-Dfu9DV9^ zKrf!4xU)m+w~gfEqZFXMz-s#Y{wifzv8FOC-Szu^6k*?xCTTYol1;y6eCM&gw6XRB zA>kp1;U#ME@yORwt%ZDyOB<8Y>l-CXQ-gW?+}4Kalz|4`@aBBX7+J&`!SKl5D~z+; zDr_%JzT?(vOOUs-{$}h7ned|lit7%Ud(+cIaBm}bwAR%sIxuC(ko!>Sg#GO9$}J7@ zY>r!2R#iM|A5&#cWDjaZTl^X8E$&n1aEF47cgaEHDDI4E`wJ)gX#4muOs|FK18aPz zR@L|Aa{AVU;llT6c}ru6bvyy$n!pR}*;L#2BAOmgL5yh;H`ePYnJCWb7*SYnXAnW4 zh}QG%#PaO`wbQaW{FIaPBW0-7FFzK7BWgWkS}~IU3t|`kqVs`N5phT!XWXm78bP5znLa2%0Iq4X4T!;8-F-yIPh{s=bzixzajcdLrdLA+ww+A?1r- z3@gugK*^=D>J+LnDj;jGZ8e1tRq{%l2hCq>>!S>T%vyYmJIwMU#~q1M#Qj9y0%^zB zMOw9k#a-a9=-Fhmon4&%fx*0XK!W!RcP&}&Q>Li;^;3A4M%!jj>b}$*8{nx$s^fJ_ z#{cu)u`k&bA9l!3tEbY%RK(kCa$MJyV-s7t9Gc9Y9P#@h*NaZaJvzD_%%?24GtL-d z*2JpVQV_1AemTyIj#Y;K(NZK-`-5$rFc&|N9jg=8PsWda`*RG(7G&L2B5N-=-7Cp& z#|XeVK7sA_A5Qg)beSa<8|&3Pf)3?j_5Md%bDJ#H(|bqn$0ru@uLNf3dbqsERq83> z!X;RphexA`22>m$2nl}^K72S#-B;(`$!Sus?A4tbw4%#wo*bL@smYgY8Opz&SFWXQ z{*~gee29(9P$Q`aJG#Dr8|P1j)8k^ElatXd{lA%P=GrV#BLcElU`eUjkFrqN#jAxs z{*n$Umz-I_ZKK0`ht@I#gqxC@A64t2R-PYC(%VNlo6IhDq#ocJpE}EUM@M_yD1Igm z@mKGhIFXXKzR|m|Eb+347r24ztEz~BLpqE%!^R*x*fCCDGH5kCMiEZ5j4I^DSvnHC z;~bEkP_5fEaUoHI&Pcz4J4I?J749>}Xc+T*w#=~>{jd7|8C#AsVj>2>w=u0;-Bs;e ztEA1tzoxzoqupO#R+#O&-1p;Ebf}2IQ0C-R&_A2W#R z;|BKhNC^urtaPq6LP#W~XP8B?ptW?ypPh2E?gq^#ACj7MZBR}|1c^rNZwzMx7X^~&AqWaHE6**Qspso>v6Gk&ZOAILpj+x0Lv(5*YkB0 zez;D&lX1HHP)dvO9)&0}&aOMIo2(I6c8gME*)zIwuxU)M zFcGY{CwEXp-s!k6uN;pOFvzfoh!(9gypy#FF~m^D?a#Ijk|#bPuRrm9mQXqZN{={N zXFv@7sB*hgFRZFQ9_=e)(1b+9O*Puj2;C7i>Z;QhXbcM;rXO~Wr6+PgwoOEYJIt7&Mb zI(}vEFr*V$qOi?CmT58iJn&bO1{!4PjG z_(yZ0PQ@pqe5bh@9I#RHxtt|kK?h?ujEq?Dr7XR?`-HmFNt_aae$9M@Ns5 zLRhn_!1jaIV=K#jh&#n8IfsvL14VAm{i>w8Gz%tSA?b4BE24)6<~ZQuaxO+6Mm+}_ z#>=*uJ8bl&j0Vn`Ry)~5^~_M6Wtv)_;3gBRw?&i@S+=19xDzUbi)AmRLRVOIKWkun zer+O#4sU2^Q4-_8T!m)R@2Kd?ZB)ytfRkK$2i!%VVge{@n)f5t@WRC#JEJI86)sn@ zS11o(VGIk9>gcCB64Vq~OY!q(2E!CI7y>>UOXIPc-~M1{vAO+(GvfK0bxQykeWyOP z<>=XQ9b5EheWRF?e4M}}WufkG@cPE{rg4Y&ya>(P*z1hS-QSAlk6TnMJ={X1h2dF)*0^Z2HT13U{yMP&N0N+Yw@o=4UHIpSeyX62ihs6jM z^qBb8;cE3cO1Jrk5teyTB z^XIj`-!F9%s;%Dsv)X=w#?G%+u`3GN*ynVAL>1Mf_^Tm{?b(dY*jXTIDy0*r!iY#X zPxq!PGpZN>VH=0`DOy>-X646!ZX~f?mMj3^q!wtr>W61WgUpfunAM59^vdu5JOV@4 zq{(3E)?8x}+u5s@_vf0y6ygeBI*H3)pki7-cyX4Vk$}f6#`11{Vy^a*o6@HL^$*QO z&O;}^j&lg4y15R)41M);7WodpN39owYoRaR7pfHioWw%#bB{iB83^g|_f4L7#S8eA8< z8}YZu86YJ7oDZVAol$sbkSz)B^7gU{;zI~dX4MC|hjnZYIuDI?-2N|nQRlxWt@u9! zBLCmu`yWO9*aIl226zS{C2hyRi=J?Ce!i}xLw63#r_3jgQshc*Xt>!acARMPvV>0% zj2%c2xjf2S3(h0h%T+COG=an6zyxwO-vdy4Wso<2`#h`LPX>9AC5)n% zvqYy@%`NQJz6BQK`4S$I6f`xpL@|G>NUzpro`}QZv!t%>!ujr0p-Le>Kt;pGZYvbz zHV{Cb%UM}nEfmQTjRwbwX-Z$T*6kmPQW#0LHg<(=UuSpMRYw@P5-ct!IL~^7DvPax_H9tOD*{ERh{V-+=dTH;JJY6ggvEms}AEY~6nz z>rFBw9OLjhg^mimhnYbfh^dAmc0Szabt}IMQ@xyS*`;Vdw~FOx3=8MiWOyYiraYZv zTAVzl1xjEwTxzzmJ=^12X$@B8eJ`Ec!&m3F;>Qmz9h4rF*1aCBgL{%{M^e)Hgk?+3 ze{}9xBUd4U7E=J+oN=J|lAN3z8kZG9z-$w}KV2zatQw+72uT0zA>CSn3T;x&DZH+b zQC_W{yZ+;5*&zz%N_zpvsz5H=1*;3WnBa{zE###yye7$$<$YQry^%ME9yaZilnA<}|IEo$ak5Zxx7}OCQ5X)HZ7wzL z6^N5l0(a-Z6JT6a-vkePE8kqn!{K$LmF82vHRjt@bvjUfsHDwIZEz5RjwL3e4xcSS zg>vV2MMmUTkZMJSDb~smb6MF}bgOg_$*#X+PPrZDB|b-qkW@`^Up^z8s7|KC2b&lh z$Ls7(0#%EEh0u9_hJ%^;us4Q2Lpg$Oi~$&}ii)E^9r*blqX>Q~bTqUIuIDsZnw}Fc z-bfvoF)=dAX350Vr`4aGo!#DgNolv*T!$4hG@DQ;O>e0@AmAp8D?o`z1%K~K=bnJ5 zR3r~qIN9RBAKeLtvb##sO{JCL&gvvN-+uI9huDfI=R1pzr8^f})_l4Zi$}T9Ex{CE zsJ})udx46rylmcSe_WDUivXyht69h6h0n$Spm_vZ)hKLk4r`5XehvDGL{96rlpE~p z#nW9*HBECm4nr>BgXaI>NbKcxwdw*JF_=W22a~jJ93{q44iIzfZOjRj0myJmg6E#@ z?kc6aI>u*ttOFFRv2#uCY#%@V8Fm{3Ub;vOZr3*3RdegT)AZ+#*aMX2Y_;67>Go8PTUsNs zH6$j7pRk85VfQ_e2Oh?qAEeFQ;Rbcri~WL(EX9md`h=Ro(zn%^&<0=K=B>twhXi?R zTN;6udQ!E<_tn;Zfdk&#MI0Wj24uC3-zJBAi>1WPKT_|+2Eqwg1_1v|22WGPd-p?X zmgYS)*4W|(`!$5F-#vh4T;D!Ut@JHj_>Eee&jT|?R5o2X@X zj_&waQmYHf5Yyp~t2n0o6S7PSxmIZc?li?E0O|p&rDpGiHEI%wGwr!t_RoTq2ld2Ab25*DJo(! zzm49Qc$k3z@TAh#uf7-^BX)v;zCMg|40AYu`;e5D&djfRNvFV+7WcAUNVQbg`}WFS z*b;E za_P;nhnQ1?w=T94mpoRSv{*_C6FzGLcj-Dq^{teT7>ae;f~nJ|gXr3!@K;pt83qia z-37B_d1_zO4nI!^@z~DQ4Kcf>-tNy>3wR&-j=~5jb8PTgpzla;_fCy;1g_i%P(~(j zHt%m5*&=bdT`nQMuFxzd+mg9v$D$zZ`sCtrO2gIcE`r-C_w_9N;J#LZb(1SZqY;*O zH8c28GcR{;!~_xR<>vSKT~K&QwdaCkNL025R%=?B{zny0hu?$W=b4ihe$Y72uf0;j zvE)A=kx%0CVrxmUSgy0zqarr^8cAFl9reL;oI00RezuIwp#A>(X6>_bTpWNes-sGz z#% z4B^mtj3(>yxXcj{c*tIRv)*hhx$9^gFXiPZmiD;%KR;FMoi7r&7$I`S9}1H#=f=HXzegUw2_q3i2wPK$Ag zHCbTRMm=OHqCdU3;B-1C<8jJ+z#Ix~RZo=;`7mZ02Y;<5Z5t5-Fo^k99`Q7R!wReyTlhbIj4x#Yx-c9KDw50r06@CK(QI_QQJY*>2xd(p zhvn$#7OB%Y@uS+5v0V9m*||yw{~q_1nQBX1Q-v~7RE2k$7J$=wn1SN(v1{+gVwiJi zoaEv4rj~HoME>zhsn78-ktQG>9qtg0YkN&`Sl)Fx=j-=0*AwOoaNO}~+lc1PGe)ce z$6K~y?<~nDZ%ts#I-DoFQ=$fTPVD4O*=a0!-dT=~6*JG`uF5kFzIxxH#SKa%(4TBD z^czO?f47axpOH)C@X_ys2`*nY-);l)L1XJ|D#iOLUyD)c%YdgG#2+1u3ARtlm8yI# zo{Sd?zDkOaPx*r6LT=^P-%QL^IGy1UfD$MQLR@5Zb$(}k;pQINlFw-VYd7-{9jgH6 zrOVTQvZ)t6PLG*Rh;my6Kr+>CV}jnl z3=LKpk1?L_@*&P2ooDrvhQ#HbrI6i-^y$xhiPIzcTxVjG(e$Wg@99+D5a+Khb}iPH z{o_4LKgw@J;^97tEA0baTQW`#H<7rD%lAH>Zk{vosm#q>`Pq3EOT@!wY|ap7i`v&rlzK1VgUJq7Y!YqHgBMh&B>FkX3q@Gk_MKc zCP-7HfLXY?o8f?vVvM!R-g{~2=C`G@#QRx84j^pM{#p?pHh+t&tU!wPDE|at5()cP z$w#$B=3!QDjtGX0=9<3~$XxuFO~uKG`~7v89=A`2!n93*cP zS1aw*P?ts<*m*- zLYCTvOv)*7?e~x0Ks5)z3z2yBrL@#G1fNkPpG<|*61O~PuoM{uGZX@uskJ3f;n@Bz zwP{O-8@2w~Pc9FDEK@K`0(+Z{O)zvS(~(i&aX3{{EK|$}vr`LEji_o5mgU}(xUhIWfURQtW)^~Jm2k&;0Fo<&q7hltVYooA`K#{*UQlG1)r^^>} zb4&_1pXn1!>0-LFo;tw8(ImZH^Jm5^XxBW8&iZ<2`=^;r@cwFP`J|TZDaX&N!=J}j zJxw{bELmV3G2bR@y|!LSMyx^d`}%Z_l3QSl932^%!G{jO@e(PJgwnrEqs9YXXG>CD zs;4L@ND_w9gLU5;ps{ z3S6cY#|pUQKkNrMB@hO%g?JxmQJ5fAwfW%C&xD)WkesN@)3Xu0P8B|bUnN@F2tM-j zele#`@)*{s0h|#PJ4a5dzG>47+au;#o+tT4D)@w!UJaoMgrqI5gG-22kaja1(DE-z zZf;Yili0FR28<@CEOw^#%kVd>wY#H;)F&kOD^HF+Bp+I8Jf|H*lVWW#Aj_EVa!DjO z>)Tz77dP7{1p482=Z_|0#@Ti^nkqkV+`%n1$K-?B z8Lhnnj(sa8Jp^E!$2(7FUz5#11}9zTou>d2u1L#6wgK2)+V*@!Mxo(c0Yjc`Rq0fk z%7T7u4W|n?-JWfaIa%aZf>Na1O+0d{-Y#_y4sP7ZD(?fxCIbV5s+R?6F)=1L`D)Xe z!f&5ry#aha61%Jn$wDluDwus&k@-H`%)=~li$iDF=7BWr1T&sh?T!u(Kr}N%Nez+R zt}iPaE)waP!KB6VXbgcs5VvC&^eti9cVd8jo)U`RDX*Clh%ksmfPI(S7EcIl2JTJt z5Dmz1Nr1g(c}sm~TwR~~P_uR@B|O_Q+dLgbp+pBPC89aX*RPIA{~%qcO@A)@`P)dm zm!M+AC_su_)t^%>IPnhq+Lo;`Om%qaX=`V}T1y)yDT+;;Q1;LF*o{}=F&z?ml_PV5 z>+9RccTr(PQ%tKAyovGAcjs6|MSN<;7tcqnJjD(fHVI4Xo9+vF!W8SDc z&qQVp@`q`&#mD5&FY#0@w*tq#URy(oj;e~QaoRb=g;Dd(9M@iJu17~nvJ-QoQK$H# z+@Y7jaovO8;dI>BMbd!pn+fsc`o>Ov`}>Ycg+$Y7R=88b+5Xw`qa@RCFRO92scRV% zqhZGE_P2Kd-d-CkUuVT_?gTCb=?rwmI z#B89&`(|Tv^VA_mN|Z`LK>?sTuE%V11JQHD(p!MCozA0-00{6(RU#buKVrv8kTMr`tDM=#si=RV&qf^yrZ(Rqs{*!vNC+6|djIPpf3Y zQRF9wIfungEV1a9!jNdNBJ_OVR6IPIYgS9V`)e&~nxDsJa-?0Bc}F7em}3!?V|NE+TsgaO6swbp6_EEu(v=sKV}2Bm z0S4a;Ls_VKk%PH%pHaYI>E&-*a$d)uwZxwfQ%Clz2QpU?Zarr_QUu&Sw{CKBn4;8F zhkJJWGeCQl>ySZz>si%~oMDXwRbUQfePaiOXcMS8UsQ_XwF)EIP#zy2>&k=R#vwNC}5rQAfA=XzJ+TUUb!0*Nnvv4VMb(bFfpgj9$gtsH2=F5jwC3zs623EtMtJ z3JTFtdi+{IO* zvkz5$R7s8&zCZPa?kG{E?bw9Pb@Tf;+F3VG&GOhKNUEP4WMX>%UImO!FTN2gubO<0 z{^G2!vCeT?YfMc$*ljh19iO-`fjoU8B)=bzX5H?le{sWUAMQ$165*N?Z7^b*s#v$$n|FaJzv=Dx95z z%PBVkykH?G=`J4gzOQn%PQ9A~wtJhKYCtfai07HzES;pXHDNv9Fmbdx0D#BWbfWM| zM=#mboL!!Onjj!2Ka|L-K3#7V&H1i}xt`M8M#-2GxRxGK6cP3LE>Hntyj&`UzFjCdB?&5P+h%>JKHbjaq zgu6H|-VzH?kC5o%DWR$*nsJ4bnqEu{llj#%6k)Lf1lwbVa`gWx6F#ulG^iZ#k)9H1 z-{H7roL4v5e1d-Ybn`C2&@T4zUmXb$!;D3|wh_%tYzkCN5(?LMD(IJ5Y5^L(?0@lK zcF36FLCm61Rkgg4Sg)WSRluVGe0v=gbuGBLX=7)w5*`^i{wuB1PR()swKR3gm8(+h z2Y=3DspaDuS%J)F2jX0fVL(0fCx3lwP282BWHwxd?zNtS*LniKGQ}$`Rt}Dp4gGJE z0zqCXJ0F0%2z)JVJHt1<_=oy$ zuFony21I|gwqJ|}fA7ne!jGe#A8kZkQZ=iDM8CV$qUB%ojd-O}-A}b#=bvSaZFlnR z98J9cB8Z%uLXRi#Fk5F2nxNVTgHSt>xCpTM*#m!TbDa_cw4agx9Uq zvj3i;3989`lVTnN@X*>GYN|`69E>R*#=gFQI7P9}rh{v0pUF@`lTjS{pjp0qVw}>& z*7{>^#<;wb4y)L|5`EzdNI9(eLoAsbMvZzc>7l%r$vn3L%oA1P@NE(go!kuZY$@fT z4KI)Uh-W&z459wD~E0v*jY4}WWiy~Sj*_=gQDUk`-i3oV(dF|hg($P%fnzP>~w9$si7g;2e|zFZR!cXQW*W4^--CV$R-4mlMp_GN9DzrYDm8eV(f zw~WP<1wU#NN^xSb2*3nNH!7%e1F6>X&Q9>Gc~7)qQu?hFP;P&D149B1cf+-C^4DbK zujFJbmN+%@VPg~y)~g5WRs07PKLftJw zB{9CM4%=Gdm<_dxr)uXND}kMPjyC-26%3AMz68G1(F)Y{V#O4Ir*otELC~iNY+4tA0>5tRT*wmh#5vq#>qR=rp&S7q@kXH#Cj=26w7wMHd&Vvegs5$gb2#5Ovv z5#*%!UlK#oVpM-I%czko+^Lz)nHq5b=l9v}2>4?Vik8S)I-OMN{cQ!=o#zAX1gVSw z2L3AAOPpPyA_q=6f(?6sq%xP62c1f-vxVJ7k~%M*bQnBU~3K9{Rg} zz6$+Y0&j=+?`I5f7yeyDvHzEI1nqzQELBfY3@lJ%lbd{J6EX4Y(}zWU=|%DS|6P>- zVKn2XMbAQ$nOg3>>wWg3^3=O9Ct58w&sjz~KJU(OxBps+_YfSZo2^4U4*Rj1h0S)9 z_p0du1R&y9fC8HuIjD5<;~mhvi#e@m0KGUJDdhe({O#}MDFAkf1S}0FmVEj3JDJ;D z^198yYa8vPDM=UW)T!743pb_v*FSS|wVj(r=DEiLt^6&lr(-bhpOae0JKpa1_&qec zN{u68of27e0d3OKd?xY19PtyaVd2UK`WUGWP};6)CAd4ltsiuLj^N^2qC+^I62a@$ zwTi0q6Ce-I=2h~(}tN*!Fv7$jejmvkO1Wfe*zzP)>`8=T=PHK0k_|Tu_AC1xV?4?&m(l{3Z@&b!}Lp&ffl?sS6AQt{Y6DYj`B@k zjKr|^QvjZ(f;S;)phc3w)Fu{w`o%VWy}2(Zkrsg01UUP<%jF*mq`RMIwgF#Gb6~UP zRaM@q8RrLSnJE6xr`Uj4{1ND?x;>U_yTA@UsCW*CXHge>4^0H8SUeh$0R5HLA zYA1imnJ<`TO0jC?QVWIx<0{j)#e;=6t>swZ$J$$W?WP#{b-{(Fl*san`$?oTXQ}BC zXAhYqQB5ENq0`_529n!pYQY;+8E>T@0VW-lADxHpWVUHP&F1$w9TGfQJG5SZMq4V0 zCO3&$%n_v!YTD#eX3opOYIRoqDpmy^cn)Y%;5d zXOU+}^J@iQ;-GwViwo3c^a7FMl8`JFPFkRIXzJEAmF3zFG(>-N*^6K1=Hv6~k7u!} zaIU*}2|W6_$kofS4E^2NE+JmdqHL%WNH>+A2nFG4S9m0bVUFFYp5}|-j;Qi7IU!N~ z_uY$Jh2n4j$(kw1^-HrR=4U5IupDL2_h;5VOtV+YXL%q(sm(?gWAl|rxIMm5Y zTk=u(A}FV!!qL)=&E+ZFfPdtd^>-l}le$kMem#qABkp{bw>WuLR_LHO0B&r6*S&U$&qKIW{Ap6y+E(Gc8`nfBfTuVuJ{WR?lDtJT;JxAiIDP)|hl0wH}|T$`d!;dT@=W=PLh7B{B* z4A`a)e%NaU9Cno!N#ltI9NwMnJ1&Jbk5(vHS>%92aCuRJN?Wg)C#@9H-c{NVsOqkG zR!)yT*ZQd*w2kVQsq&immw9;;MvoI?Zva*M`vK`3=i}nYT5esRu%aBpFc=|*KhA1c zYgw1)%-HTD%MtGVU%Vf}nnb9grzOZdG zd~rS*3isokhOpG~O zzeR4QuxwKoggrKhFCG=&LZqpKU#skKBF-;~C67CKm`rc(ijHd4!5a)?n9onMsfNfu zQr=o3NIkUDitj?x=1oRR{qgfWQhgB>vXLF5*Vei6j+rK?iVQLG7R)9G0#kv$miN~Q z>qDmzZZo0#8Am!`NvjOLke*Z)_pdKf?rUUs--cyP^yuAfdwtm1bJB$$O^wn_oi}~K z`R;$IUXwy@C0@%IvCXxOFpE8mjPR%T#J&KH)i(1<8rbd`ZtK7$f;2d#MDSv>YlDyl=c*554qdRppA`4bsv@2k`Uh)~C{!HXJ@tHe$D~6)nsER8|$3=?9S)HOtVe z|FO7j4>b+$mNYCPp51h4s~81gSRo`H^zmH-7#(=%w_qn6CQD}2#R%+eJDA7~+?m6}chlf~{e(wKw0Fk9 zXj|d~liozGrPJc;a;EwuRvHh%!od+a4oBwTkOf{IF$f- z5yCmTBcLuO&uZ(NZ&~QY2V&rQt{$$(t&GF_+H-fRIMWKCnmt*qq6=kx|KYAdn`eFV zjrZK8xy|lo`8P>ng_-(hPJgKlMHNH+Fo&ouVZAJw&+*kCwUeb+UaWqLN%{>FM~963 zKBF=E@`2ZNC*k7o6P^f=X7V0VSnw5x1CJ~F`(4i&tf#%l+Hk$B-0j^~9CIlXLvm@~ zux!sWqmf6n!9GW;4U<&uhuxg2a$pqPvj3jOqUY z(|n!V`Amqm1Rr-x%T3$ON}wf=YI#4(k%(gw%)a5m6MLZU{@HKS$`^(AsfQEx@%XiWh!ZOw%8Qo z89+wm;c_+$3*>9{=umeDpDx<@d&P8#X-h)z8S2e?!*6)ixvh%GQ1_BP8Gei)QxDP1 zcqjBy*wv-=J7QMq7FB%|;e1CIS{Wba@A~DobM*G~_qATvAE-Tx14rj#;t8|Ik_&D0 zMZmHWh3bURV$KA}G_j**am}`1PaYYGOYqTTKv)tTe?JA8z}?vxU`l-NfENO?ukz@1 z0vZvEVB{%hNN0>UN-3rgDi#$Vlg|y7aJ6V<89Os0WQYDIIBRUgzVBrK^Q?Fx)n?w( zR9g5|SsW^Uld2OfPofqy*qeDf(=vlf|!-+1c){E4K1jYY^w>BqFzT}pKA5idEnN)>- zw0BCfHFd~VXZ9xbmqn8Zco~CsSlXk)6by|GDh3j_pVt$-uYnj7wU->s4WjU|E@5ZY z@whRU>$^uxm}MUaR{8W9VO1PjiRq@xdZYa(BK3n#f~(K=WodI_t1Le?`;TDU-)>Ik zirbz@YL(!Xz)yRjr&GMz18$)15Q12_K*4k%kX;HV39Sk*%$@`($_wOwP1_97LB0{c zD(3ZBZxHj?9@@K)Itl!)oaQrjBjz(QsI(1WD*h)jeT70sZcRH z#55+{ADF{H8MK`SdLyYH2r{4(V>ADYyA07(c%!S1SlFPP@F(Zi@Sy5 zgBMM43sBq%1P|^S+;uONnfbom{b%>t=h?sRa|6je=bn4cJ@5PegvaF^{r6^jn99dh z?!lVOqd_CoAEjEKB_Z1HiNy$$%rxqPWaNU-Kd2XPr9<|pHr!KU+eR`EH5n_CLEo?h zhyB;z3x++|(5(Vc4~C6C{@2Nc$_04na%GJ70H~OHo*~U_O%2jwh})*sVybs@PFhSt z>e^KlL<2-t(*$a`;c&^CsY{39Z04wnI`yp{C#qR*6R~*EH|R~kre*vC(=OGvtTf7W zyXn}nQpk{oLl*Bx5}A_!2^!kEa9y|K-ka?&csN#?HB!NoHII%o$7EzR^JQ`q zmgioOz9t3CK)!gfc$~PGO-BOv#P^fWju;?krtAvFD2e9BJ=<276%_4qmaZhtRe zjBD)d?g0Ao->@Mft-8a!1^@}hx9~f$1D+$1{wrVxbO8%>%-eqwIe*j^-siqf&`^h8 zMKeOD(P=pg<8h^X_pY+3UkT<)bU#q16Hun@g(^iz+TNH`{jx{WpgzswOFr#@D$t}5|MsW;IA87De0gfRpXG9brFV^uW{ECiQq_2Uk30|>k zoE&@2q6nt7NrK`1!7t3*85J=i7V0Nfs05WQYXLu?C^6N14S(PJ_kD+ z>R_3dz{5&C%eqcz>#;DypV}PPHgIBt!3>X(TXps#)3|bMHqK5MAMSA5(nf<2(%l6^ zaaYVqr(Hx@J?*(}haL&<- z{r(o1i-aPkoNdg}tJDG>W4=UCUUbjiF~75i(%R%>J>^4@ZWfOr{-9Krpnkj3zn1$@ z>*|G|zkobDvWP9IlwKhSl`drIc^|8f$TPa73nbZ3#CT&^TxwG@0^nSiUu23~mkEeFOr%3jCcNh4`is_-9_2F!CVlROFJDZ=dr=ufM&? z8-4MNn~;{3;&ieFA1`~k2H!mIrBR>MP{0eV8z0A00oxrKJOzx9vGQDtG-ZHkK8rMn z4M`+?@rOqYqW4dBX*tU|b4hb@PzxWKXzfQ`3V_~rkI{pbdGg4`eOYcUZ60z8g0ysS zW)RG^I>`o@;?uvxtCI=zaJgsjWx-*z@}50i4v%rh)3G`>;QfSM=%~Me)sBG*)`NNe zegYD93a&-n0d{x;lOy)9?{Zv}67~JxNM{Tl@ym~UqAkxFVcx`laci9OElLUfBRu`Bdo0q-ik{AAq)YP(>c&#jo~H7T3Wss*^nLRbD5+bLmi?9;0oil1MZSuTK`|FsnY*13rJx;;6A2 z_@?Ze8%Q`C5Wmhot9E`wTflRkxg z^>&%Cx^OpChU}j;Cx>c!VPlO2>o3Dj4rW#N2l(tQe7qgvcRj}Z*>6der00Fcd94i= zvI(KKl2K4O1GhVS04!Ektdi_fZ13`ufJmn-v*U3P*&vTvtfE{rO+LXK3995>gb|*+ ztVPorxwpuDN(Tl;s7#6ZyL$p=W@_jZ?#TW7@gxnH$>&B$Gm}^qwY__cE3eE-v>*5Z zPfYDS-UL6@AP_Lm0tM?EX^daI8wgKl=C%F`JTw@Ba!dM=+IxbIVwFx6T^+yO(E3|q zbwYZ!>jP4gP3q*tPb8JIk48v7UB+ye$`sXpO%e6BU({la6O~w6Q$*X`bPmde;A>K| z2L|>ziL|i9s4W%90L2Gcox@j&UFTyN7d2hr7I%wV@8Y=vlUDk+6ZuxO<#E2UaJxRW ztbs^$N|=4wJ|iN-FkrK44jeW4 zM7G>IMSRT^ju;RIvBq^8 zDx`KCl_%ve)g1Pw+l_kt#(tF99CVwwUL$k_>Q1xJdVQ#tm_j(S`9N4xYuGTk095t( zS_eIAxAUyLTs0A<>A(grBN7!j*BbojQbi3-*31|gnw4V5K_UH`e&@+twh+Lv=1btj z>iUs(b`B8Yq}p*b`4$5W1VMUaOH~{jrb!Ga4rgDRPhe<#P=;3@+wlOc2bNLOsjBZY zy#Y6TXi_IG21Vj18a;(Io;=$1cC+J#cy*5#D&*b;#^Jy(u#eCxMi5_{kY)|3Q>!K+ zmgl6TD5IiPVR$sq=aM!%e-m+reE2P?l5Ns>y^1&-L1kDE7wSpmF=%dqBMmg?&u4H& zo9Ie91Qo=xwulhF0W z=qC=!-s0=r&!GmRp=X^nYujhA=!iq0k3<3aPk69JW`?w zM)R4H;4v)NPy3^6)q+VTrS?(Mac{}dA@H7`oW6MqYOt4r=R(WN9%RNBSiV(5YZk_{ zJvwG`{1}su$6=#hRD`&{K8ic!SP|{Ll@QMCR1uB8$d8jN1Yn+ptwx@O7xza~Pc(Wi z1l~R6Y`XrGiZ?%Wi*T2bCMdERe^jruYamBmZs2`KxR9uY&J-=j5Y_wYtC~c_V9gPq z@a1OXs15R%m;J*S1&nIy1La*DubKX?S<}QukCT-wyHay#w~FPRJEJsp?~?)-d=psD zu;340)R?X^+P+MW?I$477i2Gi`o`m~>u>#m%yG7h1vF(P?XOpgMEV`-fwH{crkvED zOttOR=fkpeswe?%4V;l&-Ea*(!o=~+X0nobQ}NWV1zD8cYG(a8OkQcC3bT9~SKBsv z2F-K_Pd!m+idmBiw`JkdF#R2_s-^bE3{udPxI4kEAfoU>{i z<_~cp>)par@N=UlZ$Y=7-vkwW^vTX*#yzjwwPC-l~?aTDD_ zl&wRaWf{0F0}{_^eG0W>|EdN}-6j;~eXvK>S9__uTXI60X)b}_f_6zd<+Z}tXL>)F~CR4s4i&u)Qh_eNmFennM~?nBKx5Oz2$?e>+p z%}>SZuL_o!$^-{eA{pgR>1j)frAT_d?3WAn?DJGr*}PG8eFL7xeuF970BWKl_%jT3 z1E=DFnqs_$#fPUNJkq&r=$yf`<8P(NpazI5MFl*UWm99ow61;2Lja-j-Sn-seeJ`k#P5S94Di41Rf1{lcy6#oE$J-{4enW(+Lx zeFu(QtfS<21I1VM3}`##;j3>qS?;drV5^R$$DC-<$cLp%5TYn2}vtr^nn2%Hg@?9d~v;|Ll2U zbh%*eTP4}a&&llNr}N2|I*u~{NG*U=_E$W0r3jtBVKtOLi*&~q-oXo4d6I=#%DpT; zUqy>+x3ApVrnd)Cw%zB7y7Png4hJ#-UNE6XhVc&ezn*pWW=i_M5lI^BSqzYkDB0iC zG3U>~pPaqI1^lQk12Mlv5|t8Po^p+hUP6qG^B(@5e;#(XSC|J7iXsDQfSW4A->zUS zKOQfjL9|sbUmx~@^(7^dJj|(OQ#1-|ym>Rb?ycY8`><@U@~qbPZr4{&-F8nhUi<_) z0aw`{Z4SMNt{cue@N|=QA4zK-Ki#NY+jzREdq@UjF&$@*p%Hhlg9%x^TM{T7D`-jX z`eRq?U(;lbb8s`;dZJC!a&Xn?7&EkQQI@yn`8ZH7;B)%mk@Ud0o5-d?eXZa{dpBEe z5I8X|g3kIk<@^5#HH=W2FA%MX2*qc#8x51A?Hi(X1o9nC-+1)oyX)T{X*-qT2?f$g zXATMq`-~$26OPd+o&WrLbJl|K6jLt|kpE80bZ=o2g&-^28FqtV21-h3`!G#!rx$c?F`o-conMn$8-AYNmK9w^Fn z%Ypd4({=@<96o!h&0E>gT@VKb+Wl6Rm^@OkK7agO?HwpQ05or8(T2_O=tF2HqQTe^ zT&nv4WI099hgv2hz(OsnIqWAS;+<^x3n#3he3)G}0JRVaC?h5Q^_Og)yCkX=G5(A> zWogR5JSTp_N7S*lSN^9+`(*Imatatib%s{BG(gDlcT0AyKq{*8GZl30lA~hVr8+4bL3;pri@ zf?(T#8_aWmK-{3NOeT_@u$^iDSn9)|@|Nt?OXOHKI#RX8B*H}FS+P@YDq%E5a6F?h zSCMa9W!n5EB*R>(=rhfimlZ_i3R7Vbm8O=EP^y5DwT`4uHK@Is?i+by()VuFb~>eK zesi2UN!Hj;WdVvY{l zB*MpSuZ9OxP(EO@-%eDXfIR<@~vBJ3h-!(~1gvqgC5n+XwA*+rttA1{jCrjM+W@QblTm01gQ`R_-fu z08!B8IG@*eY*bD%^>ApA4k0!w+4gjMUol9OzQY*g_}5F(xT3kP-WXFY@9kzV#KBG8 ziIamRmcts26i)Tys?9o)Y>%%})Q|IK~ww z1Oq7wGmV_L;QX?R3axw%5+b7crKP3C#l`t~fNLl&U+@;7-@EVl&#Vm<5WC#Ea>xF2 zzSC}f?%=_&em`X_InPXtC6eJh#-DPLs$cKaMC{Z>dj5VK#;}2X#SYA7TKuea(V=%Z zyfbYih&msUrWF!iv^ByZ`;hNFyL8?L27~L)ALVzVrO&IAZD@2dg;v?35{+? zHw8%rWN<*}?}5pfvnrdIf+C5=y58_1-!}IcF8EBebr1)ZmfTPu0PHSmOmUZJs%gco|DgD}O__^8&b2+Du05>;3&|nabPq+C&H$ zZ8r9)uWzLalNCCy;rs=86=mWS54XS4$e3qV2Pk}+fiZbn+cnyqAd~E{r^>gKjnfX! zr8XvNrL7$R-ii+qc^XA$B+^nlbY#SA@;dD;$xsieJ>DXC$_gqV2}qJSWd&YHRklLA zrXTY+uIj84s_0F#l7)wt+$_7cG*4Bn7R?O8>U2)92|XDd?<)r;bnoS9&%Wvce>E$hX2FKH~=$s*jon@F58L~ z-MS%OncUbwJO-dCh%mD=EQy**;3BA} z)_mzewo{7KH7dzKgL()zK>uq#YRJPXXSpkNcdZC3JsPVsSf{ynZueH|kNEV>xndUe z(sEPhFKy2ik<_jkv!#I}f!804(;JQEL4yV<8E)|r#>_s2 z5IrlU-IQuAz+tG2#Fw>-pmI|>>~RjOvsI>~3Q_=Iq_0%`jlP9EZy!-^)8Em8(E^yY z=qu5}E6AE{$Lm~oLr^1_X11&up`$ySKr(>zPBE82NZSwX^wW;heu7+s2T}V|^?S+* z*o|yyy(;4WG>gN#Le3}^a--?h^1L1sXsu*Znmke-ujFAnDgWe!;r$mk4_C!)Cj}&5 z)87_%JFsE5yb;yK>m$j{xsJk^tbJqB=D? zM*s>=crwCd`k5}R_@XHGgn1`Q>xPn5-i3TJsi>vTKpjb-sMd4HLs>)x$IZk)Gf26* zHYrk~gbX}q3GqnIHS9Dovvj5|dE(@0;G%)`o4OGc$-;<7-ati7U-TRD9o_5=7yd%7 zAX{R*>uR_<4>~b8bf8)m1B-`QkN8w?CJi|~PA+k<6~n9iBM@7TmD{7tj9pvw*Y=8! z*G+uQj3+qyUiP4+h4f%7;(1c)NC-sNZKL>G6)bp@r`k!1v^z}J4z+{!m+K)rVRjj| zceXFFxrU?m9B|?ex~;Q7Q2dbha|^_jbgku%Y0POMRfY%dc{!}3b>XJ8XO&CUs*64q zbMR1TKSY7icBas-F8YkYc98&2l)RB%xT18^208etnbhCs9xaP5#`5^!j-7PY1*Q=| z@_GcS`zLjL7^5Q}6C;{KKL@$JjG!(^9qGjUrbT?b8g2t#uAX$<=K>m1bz_tk6Vddx zP@h-C3L&C`Ye8Kn&np+Sw}1UqaF_*aEF5{xD@SJZFpEx7k+U{ykD-{A)lMa1yXFmZ zQLl%2;@J+qjX_)ACA%=^OSb0Oz@_Zj`$N z723QDV46X`HoQ&Yz^nc=TWadS3Gf-Lz@F{(D*>C$9wP4Nj+oJhBo|lqUJ$d#Xf^(`;S7-m2inM9wy|okyh2-`h%HntPmD>-zI;j&os6&C)n&_AJBqHk z^9w?#1qcazHEfjVc~c2q*|tAMzLZV9)Jh|2)~Pb(LH9!~0p_0z6oxroPkr+NP|B^9 z?o#!lNWuMC4_)GSSdIGb_BN8Io~uD^QkU#;(q1pK<{IvJ)XoAj*}mN09wH3i7jv)q zA||V$eB^nV+SD5Qsp(ywYHKKQT=)_fATw6*U1to3>7gW;;DBlGgRDlI;bD{mG+;=DTzRu--v8bZE2BYvO{xek$AF$ zxvSeV#T?3^(9&uZ?wH~sWQhNL*xsL}Fm%@Q=IiFat90!?r6J?FyS2N!_j|tjdAKJ} zHmTYAz93LgWyybkUs}I%ZJF6=Tg>torzBh^up!Spwkn#x%G2GVYXielVAJG#==11s zI~k@|{#Xa&!gd&06HDkGEyfdnOT*H@;^V(PqiDj1f(E=)wewoPPHSA$l3V0Uxp8Ot zq1B33EH)Av`Si!ada4Ojivnte6S|j*{I2ZZeuUSBf@lH9+~v1#3Iq@@JmxPQc>r&0 zG*^a;Vc$e8RP3yl6vSI&bDrstQ);8t@|e}@XUq(MGRe_)BS%i>b9O`dO_nZ~#&JX; zo?kZXDc70~EW>sdg)DgU|kR{#o_1#e2xk7(k43&529@^=aao)O`Tqd98L!gs_+ z)xKA8EU^_3h5`^tev*G;55O#tF0>EwGZqBSerbC}n5z5P{TPZ3->VV~02jvj8|(Xj zfcgFJ3H$5(3JXl4c56>7S&wChjz#3%Mp})hf6(8A5A7rdQ|kv)6v1oKxjKj7WCY{+iznc{^oWB=dT(u@F4c% zyO)x6m)P@n_U~BdXn)S=H)~C(eHnRyw40ll3PHG3oz{6-?sjC%{SyEK6b&5qP&!u2 z!Cv#yW-_QPho^``@!RpfT-3$a%b0LstGmU&|1*+6Pr`rq+?=W&Fd!zaU@F=W_Mj37 z*2wBR^N{P$)~xpQ9wB=}`operJmOtgUSt*rj# z>p3o>@032W3-}(dm0(h-6RVc9?1v`>++Pl`;r-MS1lR@2pZ9ySaHUbjLoCq3p{X&; zUAdZUp*$bdPEz+7Pjj4?81&DXRj!rG3mR{fionk$*p3z*hg{w2i(&~VEFshDwwSD| z-Fac0Cg85J_Kl4BWO5GCZ-zIxrv+QxQ8GpByafHLslXsghf0^?W@j*>hxQII0@+H{ zQXe2*c@BD)(S)VhDXc?8M7?tmje^gwasOjf2D4|1&x1XLH*@NsvUQHZ3Joj;3N>-L zzm*>jo3CuYE-vzny!|srA_Ne?_K)U51OHbRpup@U(05z@*F9GOUX=f65d&wSUwH{& zCkEgEu3nsU|C_1%YYP8=d;IqjCXlG16x&nlp)hc@kX1mjqRth-&e`O>$*b@3)4+$* zWu>nB7XQ`Re{m92=%m3rHUC>@z#j>-X{P_zN2*+neAlz>R>=a$wud+r_j@LA9nit3 zQW8CW&de+~ziIX1!v_TN1T$U#QF5~C3JX-k1`r#VcQ$e}Lzl8Xic34>(OhLH*@^++ z2;eIzVU;n+)W6_gaHvOz-p!ojr>83biGqmF zn*2Pw`ubq123-^Dn49+e)fgy#v<1K6oTGPKen=+@Sgr90>POQ*eV)2CKG_`jpl8u< zoicrqcx*Y7FP_DY*JY^^uC0oV2ljt|$pYXwxg=dc_35w*)xs~6dFfX1y06cp$w)0bvz7}VNtD9JP0nY52cTd^g z3}C*lW*Umk^s1!U94siMw49*{rKl=l$V3=3WIQT}e>31HP zl8nNXV9N?-LnC=VSwTrkE#w-lhOe96Tj7;~t7z%C z-u7*^yVrZ#;aJ=zG>6iGgWeVH6Htz*8twq0*X+L1op z2X~S*x4jrBWr4MI);3ffiV9RL#mI%$R%{=CWP&U3jg;)uvz_(_vnH3+mhrJTRF!`D@|GZ)i@HOze0`Ys`vt916H`xg1u=;GCMlXr9QW$wfub?`y0ftnTU-C(Hv|2xWS-wK+W8 z!Nz)z0@T1Kbbp{k2hVfs{GonN_JmulgRV}UYx{t3QwN~d6j&%+aFHl1K1g{D(Q5|} zgxMsGEpbi2mY~sm+OC4PnJySHRX#!|xM?XDfGW8#2RYw0oLzDUa7C7C0os7XQPq!d4%$Qb z-N6!r>Q_?PeVrM;d+2-~x}=l+p6U%xJEz0JsCiUXJ(mgV#S5@qcU+*GAAdIJNnWTr zd9`mYqVMur$_3}1nnQ>`5v$R7-EQ|EbARICK&XH=LDZT&_qOTtZG=nhP6E&le4S16 zXM-to^q7HG8@YK^a6vJ5_KKObn_MwN&1FyapK=7+akL@l)tWpo04E?6?f9etMtboM zfbYX>#V=4!loscma>tjLGTRvCO5$SIskPkmP%StNrth`7vZLVF{sN|uwW7Um>z20e zI51&ITx*MftCcOrZAIeXGzqMhur+`2E6=6NTY)deWIb|+>hzm_6hR;mu)_~Z!PeNZ z9>}(#-nnl!v1Dg(Qee@J=jT4X^6m`66~Ud;lN)^MM2i-XnQqdT4THS{Yn1CAr~4B* zcAe)^P`PALhCIjW+UW;tUUhF1EfY)F?7uidHNROZvW$J5uS|&AcL}_xI&P7D5-`Nh zQWUy*sP8dzqO6?encX1=&qTzI-)jeY`3~~^E9dWb^n0~ zG<+4MuWomsTJF4@BrjL7l-jjJiHOqCQ@3lQVNYOlHIX)f-?fA11;pXYO|a*=yq!oc zjd-;5DOsU7aZP{U!hB|qBt;swtqGk(3}!}l_BqbgPDhWic3 zPwdt339WKnygfp7N;d9KX*kEmEsj1u$xF z0YD%4y-doL9Pne6H~i)+(U9K;0sgWd&A?T3E+LB?H0P%XK?y7Y>v_QoMel@rgB8^A zy!86GeH;i6ZJclGaSN(c1C<1kk*Wy9Vw5kC_r%#6o$;03|J$Nb+h(!P{_nItI94p^dSz#3FNSQI|&U;LO{S^7354K4La>gc><; zUk^%4O92Io)oS0Tk&JY7CeF@BTQiNt6-61qVBkPv Date: Tue, 5 Jul 2022 12:56:21 +1000 Subject: [PATCH 015/109] Delete windows-home-edition-intune-filter.png --- .../windows-home-edition-intune-filter.png | Bin 40112 -> 0 bytes 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 education/windows/images/windows-home-edition-intune-filter.png diff --git a/education/windows/images/windows-home-edition-intune-filter.png b/education/windows/images/windows-home-edition-intune-filter.png deleted file mode 100644 index a033a481c390ecc9ce65ae9379d2dd94d1955074..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 40112 zcmce-bySq!_dkj#s5D4PsB{h}k`f}#&<#T=Jv2zCC`d^&LpMV=LzgI>GIUFKm-Kz` z{r-G@-|s*7u66HP_YW4&^UOJCpR?nf*WPFEU}Z&VTr3JKG&D3^Ss4jcG_?D4XlUpP zkI;cH#r(oJz`uJRRi(wyN(QJlfR_j6?-bslp_NBqUwyy;-XGh`=zK&&!~1#ncdyef z&jbxESyEQwow}RBPSayAjn0&{Ue7e27`~J~`Xe)sxg_^e!JX7>!IW$pSw(#MHkWOA z#?Ve`W7qm7`Zg$&3lm|v@eGu=lk%Q*XIPMA8pQSe3G@q~47bx1~7ATG?Id2+t9NX77Gzba`4yL^|R8vz^ zQ7Jd>43D5I=lM8^v)Iarh9>iTxevq0SWdlbl&>mklZm^*Wrr5S`Rb2@s#jmC;?dB)Q?|Fao0^(tXI0zH8)#`s_k>)6!o!qVCn#MEzEz~yNOw0`1%5i^z`&JG@M66 zgFeF5r}!=%PLA?Etfr(S21pVR`^9=z#4OultapA+vK~^v^os$;O64Ls zhHueiWHXf^F-%Hu4uCqkjEZdBebx6U7=eFgMKEYwbWfrbDMRADr8^&8@%jO=UuO4% zj3L-qz4O*G`bt>yjbC7z&cS~8YA0o>!kf9X!g{|oMZL{0yXY+UaiJ6wS*noZZ5c8& zG?RND7@OJ#19|mHvifKRH?%NPUIRdGZ~thhlCRt}Qa zZjRkM%deZ+uIoWYuq5<)E0g+mArSjE?K#N|#AhSv^3ry8+OwDG=h5cm+og}e-Jn5k zP=oH6Yu{@@(|F%)udgIdXBCW&zj7ZPWa#;5g?s62&_?Q?owKs-Y=NvXY>$^9%tI{Nj+=xo)6)OIt*l3ByI!MFXhg4w>jx3AbZJtg{(Tz7;cir?c z%xal-tH#eQ&1z~A>~j+U^d?g>G`sVY7_*+o4|IUIj6xd)HP%xW8h;j!Rvwk?5LAVL z-T_KVg&9$ix^He>)Yc}#{K^GOo0La;Gu>4nG@7;?MDTJ~-7D61 zBJv);l3oJc2Ty-C+V;=lm>;Mwpa@yWbc<U+{%I9><_L&LXL_o8 zsNDDbP&`aJbl&TzAI9d&bB2TSV36;bpv!7sLh7?ae~CEFtZ1DFv7~5d{!D$@aevN# z<&+qa>24GtgHnGZN|$~26E5d3@$nlk_k0>RZxXg{PGt5bsK;+E>qGfU_s$KI-gq?a zSZo-H2bS(Qo{uemdR_n2NNU(v0O{|eq0em`&>!$wD1<${@7>_cq83A$7idzI81XTF zy4FHMorS^Hp{TqMyk6#ndBr8iE~j~Jk#N+@`cXr=Chxwv=G76Ifrtd2K2#yiz>8aS zU{|eycdWcD$P@>=l0+W+uNh>hl3*fyXK5OWoEkl)!1JQr#()rtfr4dY9kw}KdvRb2&Hm( z?5u@my~8VkZiwPBaZ;cUB6!WTL-aFKmR+Zi9*)fTI23IePZG<5`)!>|DQO(X-pp$3 zv;IgWOv`OWz1EXTt{DD=g8cZkhok-G&E62Bpe*NzPWR|XvcRookr?=k+Jyd7IG~;9DY0hQSr7r=3(=d zl=oa>C|{H7O-E+tu|a?9zV@UlV%tb0?5fQ%s@qCIwJ5OF6=XYR$sBfp*CP@uV#q59~rwRCFp*3 z&ojUuuL)FP0nt?Ye@D$4d_tk4eX?fM2X^P5Yd3>wc7K-AU{?oiJib>)5jPRg&d#f5 zXrEogm7&s3i@Qdr*1YX`Qq7?ENecF~V&%sJgWuS-q8xJ_ten3}dIOR{8$T|;5n$iPfP0c=*h#nnh1e4X=iMnGGh;;eu=>CdSG!b zXZYsxm3tfFtE`}_bN~vO;0&=9^K(HED?KYghR^Q5cq(ysk^$cnvXH=Lo({acNCF6d zH~hbQlzohFUjIdtfppoPDF5&ivrhD0B;l{f96wMjDXz1?I=~Z?huvC`V=WQT+m)4- z%hR39c)Gt><5dCFZTLlQM)+U2!kUdDa%9r^g+-jaDyg+5j)0A z5J4sExu~+ewS^79`7Q~IuViY%$D~1oK(BNYQepq5rY7NJ+q=;M;^&~LxswLLpgJP7 zm*8|{V`eY=MI(Sv_xJZ70aK9oH*-r|8%@S9$H>G4_p%*-3kCq-;kyTb%5D5g=4>O4 zB@M!31}Xiz&&Z4P@bnD)`gQr}A;A6N41qK=A8RYWJU`T-zcR$z+gn&z_;3M`UL^Ie zKBc3#v6?d(r#P6N4fSst-UxQTV=Hcq)DeZci!m3!fBER{l$^xuzv8|Xhqgxzd~g3~ zo=BlMM*Y?$w&<&G>Khd~KmC+@Pg&GHp$;Di>n}!Xy1LeQ9o{LyL++!cJk7@S-Cavt zYl}DDhw@KY3KJ7IdyF-tySh{iJ-?yL`ttDc96PyoKiI&Jg){wC5-UGc2pQRwE~VmF ziin0%eMnJt&ZdMu?qhZ?$4D)IKHlVX3+f#kE}g`sI1~hF5#_{?d~tCh8^bv3G^}9E zpLTn-)-C6^xM}|OQfGmj#6b&keSK}$a(!wXA$$thQskG$LqH-X4>_BTQJv3y*@bV) zoVUhmi3wd1Jl+?_PhXqKC>cTR>inX2%Y?sE18>cQM)z!bp78i%94@CH0 z8E+`DpP!%mo|^kgr9H%dMognyZJqH-!7sa}OYXj$e?&+vTk$x*`CuyU1N3D8PjUh~ zwac&3(Gvgxv+LDHGHO31)}o-GFmvdl`I5=d3=Y*~fJ8rX?0RvVUs{?Ai_%;h^f|4} zE?FH&k)z2j?^0OcicUK|c1i<8C03AAUvaU{SmS$zY9zbepLtzrE+WmlRcF3N z);HUf^=(o4L5P&lgaUJWj;h@<>*EL+)S@(O!NQGCS1xC_EK=dhNzm zC+wIWoz;H#6dUz3Plxm)#+2rjec$$d)ay6esOKdXG0pr-R;x7cO^Jdz;AO`}3mLZ* zO_Yv#LyyYvg3H{(ZPfjUt_G^!@1Pe>Gj9@*X(#vx8i`lyeO|!LiTX}@DJ)$p3yn%L zA*hQ3>E;k?H>O{i_a`#Us4Ht}#o0?sQ^81~)Cg;t>%16Hv)B}e{5$pMEro=&6GJm@ z;I5+0thABwXP&oBu4clw>>CAjAI(_kI5A4Re9wdHDawl_$0qDED=XE^VpH1`pizAn zGixH!KXfjhgetFOBeLhQ!py2I9ilxILpKGSH`P%ZCBG0oJ>aL#PX5VlHe^yY6kj`1 zmGnrX$YbGTczudr?SrwJ7`$vr1jkZ~br^*@e1jwPh3m^#c&bA>sr-d;3-O}ZF|ul; zvID>W6kntPZ%-tqHU_Kc(ih065Q^y&a+gMv7v$&DJe4pCYNQo%VJ>u?bC)KO;0kXn zUw+PsV3-@r4{*FV-Uyx?%M9TB5Lm7UwYBD-9ueJ?_3Dfinb+R$!LBrmt_Sejk1oMA z{6S8y9gU1~=BWc?=|SE!kzpsu-D0Jo3|eM{+}hr=a#^`-9AK-SSQh%~?9O}o9=mmG z+2+9dGHl2iOY8{Kt=SPOEDl|y;9k*EOCuP($~@n&PU#6GBXDZH1Kv4d=B@p?E*!*0 zT5qj`zAXFbc>2*KSG3IdV|*2(&dKA)EbyjYIu%L4vXn8OO6PZ#TaFe8d!7b;Ur$e# zRa9Bcrjo6R%2q>#P%R@w>m>-8DI`hbgor{>kR}hFd^QJ{0Al<)*g8#T7~dST%e@Cf zI~WrFSO`lQ{CTa*ZY3YuP^8$a6gzU`?3R|6=IT`m>dSWz%hfbA-2YT*tv0ZNu)MBE z<7ADag1d4RM^qt@ucj_g8LC*)$3<^1E8nUy{fhYks+n1|!dOHgp9LSoUmE!n1m#EP zDElSLz|yoee=d^mKQij5Vls+<92Nu*j=zGtCpeA~#mGl8SAB>5ycdmwuFoG|ZeFUK zD3*tP%EAeK+^2lKl9;cc*XyX%Rwl6)ryi!BZ?=l#tl#llOKbmoSwO-@pD2hki(hVY zEk~9tqrf=5o!b#-n4fT0CEY{wIXmNaBDv+NGY=7SF$Kmd8Y&Q$V6l6;bKzJDGkdCi zA+t0&zW+lK?TaB957!mM9Rm8}>;uE%y@EG5DVSqgx<3ujQ7v^-tAEt=mBLIoK+cp! zuAHp3uuuzpF{AdekNsGga?DG>Z1hUZH%=Pw5R2~s*ifS8Xg9=FPB2Ve91zXT2ELS1wpdZm6!o$t0YP-L3s`x6 zXKGaxkc)dbBIvl69e`4OEtF&%mOsK90AbX51)|hSP^ztxA+xmX`e0zhZ)Pg2R_#w& z$Y=Qb+;Wi2WnSwxHLR6T56EdE5Vt<3Ih^Oq2$ti@T!x@x_z*|jkD)Scnc%Z8Bl|6yMb7Sa` z;HRM;GPXbnV$$@iB!1j|NJ>xmqa3NnTs^0{o?>gw> z8D4*Rmd0CNJnA!u88GNgIdSG^NA|Ar78im^247pVSZBo=vCfU}@y2%=s zZ#eXkBbxjhGZt7IRi4xc7cXPEG(mre4>4C9yLB)jB(E(6<4LAd;m7MDTNqpZmPz^= z>R98$6X_OX0tuOg6ZI0m+3NOnzQ6`4`pA6L(APJA1XFQd?oIMj~G1fFEw-o4M)X4(m~QS5V%_j_kR6!-(iS1vrol@Qjv&`+k|Tx z1B=gVEXs`jWvD~<8}$qTHPJ$t~t{P(B z_Z!06>^S`!yH10Qy!jXE`wEuQ!Y?w`?~RKF@X`Daj~OCZH4DFlEF}gAKeWODeM-jJ zsG85R^7E&A_7n8dX$a1?4ESx6wa4sdYPGzdx9NK1bMTo+Wn0DdF_XY%;vJQv(hM(I ze?R&~#}XLM@QY9!`$cXQEnLtA6lvd9`N5#3W5f%NJw}lzayGKv!rLc9T6FGMq|-r7 zBw7KcDBoh$(rbtR(teY5tshJdBPEowX88L2_D`o}SdP04|AU35^5N;}EH)6As)|Wx zAse69@d9OO(;)zF07#?%XR45LJnq?B#?s9L7We8FVPbkMYsstNhZyZ6hFYF&ObA$} zCj^VsC@E&A5($cG{$`~u`KbZ@w?V=b2mQAoJim8j{_}l3iTSIQ1~1F}qoqwtVTi@r z$5d8$8CDkGjrRY*ogV1F{40Oz;NV}9y0nGLVoHnJzAT^4idJSbKE~%c^?V5a;6D|e zARej*zrx)<8M<25tDfys>YZxB!-TU_ztS#&6BmTTo%}UTucNIJC{~@VbdBLe4J&B-^huTabWiO1rIQ;~UxcFG#51&GEXowClXeBQJJYud^ zWUwy_6_7=uxNdh%3EL6a({WE#Oq@tn+UVloluD*4nNaG8JnYyA&@n6Tnap$7LSjfN zocIEx(x1Rohcli9G}N8NHLf1?v{Tb~DH*Q$K8T{aIKCJLTC5CZWsu7i@_<8xkyk~* zbZNt?Dhbl|2m$@2|!`;Szr&ND%)?&Ymb<+pla@w(wdy6|cQ)tTVN6!}#gM z){6q@^83_b6jnvsZym>okAFf#;ft}-gQ|srZ2xljyO7js5$0DWbxUV#!e3kLDBZnx z9(~)5X4`ndtj?qcf#`Ip1`*+Wb8g~;I`hA1OP#_Tbpcee1=qE8X!gv2g@#fE|9T_x zj)cHGI`0J`?W4UgY=tmfz)$i=(UP>!;cHS)HXdZvkhYxn$YC5|uSQ2L?J(G>riZ+U z9h+Po?hnJ|$~yK}*PMwZeFq6_8@uy4Hk4l6`3YyPzD&Y2=?QnsB+2L0Y@^3(ebl51)=?;xEIf3hW_g|=N7)WHB7 zOKge8fus`l8u?(sg8`l|<%qF6AP*(eS6F{meJzp**0B;+AN-k!_|_Kv%Dk4HjwgIS zk8M?W%9EGd%f6hN!Ef@`i{BxF%H*4AFVb|DO8cttBRre2gic{FwG2ndfR1qTnXDPh zeUR2u2u>w`F&BgcsVt0d1?P$`Ud1#MuA+ECn#O=#>ErPwK+&dysi>wPV;1XYU&wob zE`RpKTC@60nvp?1<#Znok?>y%vSiXTjQtC!!NIU#(Ty`vy;xFV7^>YhKKhVRg}7kc z|BlVuadJv W2DZYMWQ4W!Mdn?-ABDZ)o}WahW;o?h~~r~1M$^t1cb%OqC@pO{8PjF?d>j$&#sZr6QDS55tDB}AdzwmagPA&{ zjwgc_o~po=ulbzdex+GIN+bL;y8caLL$=R#PX0xx5hT*m2t>liQY7xH;6N+fIkY%{LhTjRDQ;0!ss`oswqurnx;pw#omJesN0kx zAN3I;_I~L3)m%%<%Ja832NB{aM+qX{9wWL$3mY4|jFV2w_U;QaWQNHnfj{avBTH1@ z<}k>+Z4gE5(@N&h$10meRsTUCqq|zaJd{-*vS9q62>8{ne7s*6fZ3|{ZRA+Z?!5US z(T^tu8im$|)+04l53;6y(Hdz%c6N3yYHp+D+}#DbS;{4*(!m!slccp1<(t=Mt5*x| zG?ijIP=Gn<7R2X^?RW|NDcz!om4^xWci|+#iGu6Yu{@W`2jy&_7yMp%My_Y?1k6UfZV*?$kzR=Hn zM6AFl-$z1dKVq({y))?VsvH5L1uN1*=(Q{8K>8m5t8|yL~*>kzR^)! z7yyY!h|%%!hyN>1LX9fjv9V#=-0JRnX8ZZDmpBf6;6js{f+8CK`CUvWaMdgE z9C{OoLLa(^SRwKF-lhU_>{`PIJpLTokGcN2lJRl5}&ZH0w$}BC7cqVoiYI@ke zZ&X0W6&lHQ4=w8f*lHw5Iy_a_&yD!5BaWj_UK39dMY^OCdp37E-W95~Qx)ZRS|WJNA6!8xvYp@5R_MNgDy7x} zRo|%cMdU@EoLM)%D`9u=_pGkQZHwPp%=IvMx3yog1L^ZZdJ%yyvx(41;u+TB|EeT zo+h)h%c&}^@hUi5v0r#|CY|sPQfp)|>=9`t3TwNigZKkIgHuMWmBkBk+Qgwhboxzj z%(Q6@wjY(+(0;+!@?Tn;&b+Jb@8jQb_9@gs6(T-+-K2)DXA8wLIYdiC7;%XR5hdEOSH%kDOL)vID07?62P zmoz-CQG`8KI04v-tD!Zc;(mv2S8FRSrKxF0pAFk?By2-uT*tcPT6Lj+n(xKlF$$K6 zuTk*vND;q))WT}h>wO8c+;~9dkOxanEoaZ|Lt@(&mOzeWaN#L;=$NMO+@rUHr>E%G zmprrQ`wM>6_r`v=iH;-O_k!YSdKh%4$}@giEN_WdNki-i7DjX)V%C=)*jpwK({J>J ztdzW-+PScI^&Bj1PdNnhrtVsqIP6%mNVL<|oPMU$k|?ZrGidYVXK+t(F4F?ClW4ZcjXOw(>GpTPkE|AUS@`!N2HjT$@Y2%ZH ziAo{eiPwZl2;*0P@9b4>EX53Z5L|A30zdrm;Y=sfZYlk$b#S4(>_gq#dO;47=Nl}x z6f=e&B+?NzIWU%N79Ll1y$@Ey-(k4Y9w8PfbZ1q5?$$%~Wob730O^MPE$XJK`yFDv zq`eCrIdhqGO_!e9H#Svko$NNc_SvQIMf?gcQfuoZuXOXbo(cSVy7OvI>HRmnuai-k zJ$loIHtJ?&X>5&V)t=I_Q@T%L3eY6&gdIc9jE{)-6mpOEHjlr)j@N-eCPjdGH zQS~A-Ii>^Q2IWbcxtM&mJqJE&%*8+TAl*cWt774zHN(nm@4Qo|!9M5W*IVu<5J7ip zu~@mdF+)onJnIS91;2iMY3(m^?%wzJtTu@&z13eIGE%Q^7*^Cdo8dOl@2NK~Hi~FB zmiS3lLV`jhEo}^xU!Bz28`6Ck*HWLI?~sTV0%zr%^txfSqc4`HHE-YI zb{L-?_vpjxm{`&%Ps@e+uaoMii}1c&zfKs>1a;z6r#_W(6$$?fOEDG3XvP=P3nMhH#SKvex~kJo(7B ztse{5x;ih|QmS&BcyNxiOQ3xFx+@J4^xwLmww5>PUu7xhPOfm8CnK09`RhbpM$9xu zE2?b0EH-)u(e-(qRg`xAjc+RR(lR04RRzK^+oL9{+b&qxOK$hW4L@-y47f@

    Lugmb)nuw_=+9Nia>b0E2teJZ`GTu3R45-*0Z7dSSR-s;^Tq z!Z7$Uq_h6FPQPjhlqSxkLGQOGFHH{*pWk-=@zsg?hbjMtsy>j}s+~0pb-H}}DjeQ2 z0Ws#}6U;5evRJDTgLyg{uua3QtTy#4vQF+b_jbvZ&*x95qGF|Q8#UIRy(~^>df~$T z8JfWg%-`lZk71;N%cLemJses6y~FZ4XJEE6Xe7Rvh24M*L9#yj(Jei1e( z>Rv4tAZxS9`I*ACpE{};URIHrU)2=3u^NQjHCV|W=Z#%_H8Z84BTx2lQ6E(G)l0>6 z^;WdlT9{N}L`bae9w?kYj47J$;KERCPqv+5?pp_&zz$m^N{0GGkM)=SJMR0)QZDq&6yCc#Y@CpPSc_ljo-dGB6+tuwZ4Oe|luBz-j5#;h znHKv;n^qqNQZp@b>Mt5DZ5ALzU6>mx*5lpIggp=ESd~rdD=EApJ_BQuD3r%%ryA^LPxWtrHLd4yj zPM+3?q9U&c0)+gtePYDq+V2?iau5I8^9YMV+)|{3O}m39m+#+qBG{&U-+odeZf zT*~$cuEZ&X`-S3a}`7#%(2{MsE0{<{g+s4FLW^ z*)KC)r^?Q@LE3#g$qCNCh!d`WiCD=sjX}NfLNpYnHLdX&e6?&bM7u+#+SL@X@HDsr z*vcyHLiQ|bOWbD7qpj5L&f;<4qnHScyH?~lt8wq3e;+WvoSP~`{(-OWeV)dW-jRO) zGT!k2Yts+%rvHb;2UTddZz0D54n96UF0MXsx!40^yMO;aa61Xy$^y5+hg^3cTl7r~ zE7;23o&bz}_xcp`^zKR>4eg5d9K3aLvNc|!|MM=n1h{g>-@eNiKtuZ@S-=eX=lR9a zd$85duehi<`?6f%?iTG6&R2EKXc+0h-=;6rWSdbx{_PG^SAk3n-{qQ$t}Zm7AT_r7 zFUjd2dPnO%VEs?$4p)RE`qoBn8mUoeEL_2QA^9KDmZsVV`r znQYwXOEB9w5L5UW|9SPn2x?MfPF7wny#6lj^;0Z8A($<;kJjr=F6@mbL~;-GJizD^ z3Pr9ze8&Km;5{(gw?5ivWbUY%divaO!d|rm6}a~&d8UzPD_=rB&YUxHf`9@U}& z)j4$96e9bFAWt(}@jm?rrBEokIN!^7c7om(Nr8>SAFC*P zDD-TtJ_|5Mr1&(wagJ<48N0#pYU*qQf{EB{HlCoIl-@~J=AdoHY&j1GN9aB4QZ2EVB4uHCpN7CxOAUSkegNub!FfO)F_sBJ9EoLl`lduW(%tvd5F_ zveY3SUXH!|kgsAL42saO%zu^P@)Sv~XRTv^e8uhn%;+{Ex*{Q2p2705)Q#{bM`uFT!`MMMG`qGle=V2M7Q8i7Q`jl=2XFE%XCeIE zv%hI&!2II>Fc+7;t%>0tGZd;z`9?MGW*gT?@c3Usm`@%ecy@IdD{ss?{2tD2($YP2 zm-X!K{m}Za<;TazYFeFD8K{uT03M)!_5%%l3O8&M5G(vgQ8f&f32JkM+lbLyw2kt~P((F6Bz{y)|?{%M5)& zYUt#%Dy$_-$P6L>AA_nu^vqz9A@x=13nhGlH{(gvt7~HY*JhnI7`VP|ZJM&o6H^Xn~n-i*qQHy3S=~8A;+kj$`-W8D-N5d$&hp9=_jXJ zy4{353Pa3X3{k*hdT!@QoW#^H7B4KWQRE~epOU8KZW(Wbq@a((kvKj_u%ntr$D1V1 zG$v{0vnWy}rbX|GVTvNdHx9{>Wb_ivd=68Mu5vCgEh^@Dq(`e&CF6XWy}JsJp*mv= zy$`r|qM1Thn?+pgcLB0&=sDXVv>w`JhN}7#8&HE5UaDa z$2J2a68oWqAbF+qcj-DkPg=Yin?;seNM+)fKOg@Q1qS#v$;LMz_|tkfVXx8Qv>mh- zZ)29WOtNt7zP|lQ{`XhIH6&*5T36iHi~N21zv;wi^v_VLt~b9gON`k15N@rpW55}P zu;Zo@dcEH+5auh88zth4EUMG^(ny>94ams0{e#RUnc+^@ib!rC9qmqksZJWy6$8Fc z=Xb~u;q9qsJ5W2Hut)mkgc3Wgc27{RKJ0SNTWMfk`*~~}y?ASf{zb-R`Fx$7;{xMR zTT@24wPyN2;gcx2av~0;>u`Er6;n4Gv($9+dHOtU-V>E`ScmTJ^~%V~Lv|1Olm^Zs zs;5F4T;{Z)?$fl_sQ}|X#eUaNVGuPV%&y2(hdfN=yq$cm_|dA?6ByO%(R{yd{$wfnNY3W&t_CGN|2J2aQ`PE?#> z9Ox3c7Sxo3p(+itmp`7V0OcuYFHBW7!2-(|Z-Wh>JGR@m$7;@LJ_V^Fdv00pLf8kW z?UIQWj%9~T(D|+eauK}N?4@gBM(fdy2bE`=FdjV5u%s$!Ey9jM*^fWj$?dx`uoBji zo6JiunA?kS?_VyVBTDn7rdRzmedU~QKOJqTs8o-Wjq}%59V|iroIbJ>zd6zpVDuI%Pwqy7X zK&xVfe(?Ay`1=2ljCg&lSILwU=&l!8C-P7r~?5^xI&!>1+c=qHxcBq#N{)eZSC| z7}5CArg;d1bGGC<>)lZDxGx>a(KhR0Wgtg%3irWc&1$_V#VK7}!&2&yXL64N@PU1W z5c#0~Z|?jHefv?3U_#x5x?G+gKI^T2RstRm#`60nuxe{nSSP6yWyETpbuhWt?iAI- zL}f)d+Yg01TSMGk-yAt#9-}#e!7S!0H>!G2heM+{2jGG`>95u zc5mn@Hkh@4hL^xgOT3nb8dqP!6Q0Tt^1Z8*eS9MhDN>(L-(#Z^x7U*r;ox;Sa>SBaOm#`vc@ zfJ0Ou=a)4T>ak@JgM8KcyGgpt8d)hSrgx?8*vqxn#1!s*vky0*|W(fw)Vm*D8r z>7Vq@Qu@agA@iHJdcIc%x~lxK;t6Dy$gcAH7hJvscxSk+eRf2>Wgt|s*S{1PFnxah z!I+w*IG4@E$?&PReNnQQi4og>fh2&ADs32EvD9AD5R`ncYX7spnH0JcrA2AkVS&A`d{#CayR+sjkl}#A#)~aKN{;y z|JO8~m#-$7<^OkU{?GqGq=3r(D?NDzjabruJmX0B|EZGpihn)Q1g!tM&Htm}OT@{L z^mAFmAO8^=xvGw=Cgfi>$updTvHw*%bpZDN>)a+h{O?e}?`wa(@yPuD()@qZP?{UO z<<=SQ%w&*G~*w zty;_hDgW!kV?GH(ZPt0c;{U}UT<-TDmI20-5;s_Nk`kRd@juB(R|P~AUmo^)`p%4u z9GBmX^FOu4=e#na@iMN3^@5e9n6C+_cM$rQ+xY+@wj9{e^)*>Y2(3arzyCkFkx2i? zxW2L!13A^QX?#7pAzEYd^RqxA?a&LrS_J<3N+vI}E2N5%np8d)T7@mgTcd`Sz;cKF zY5ptQr}6;%tkZWd_LavGE*lZ|{tbQHX<|F! ze|C}>VAJ{6UReL1Hl+#=r9womi}}y#_R+zZC?G*xteVToJ6_(S;xW+$_vRacNmQnT<|bQ0_hAJ4_|$9!9+884b((D7Rfz1Oue+O?-^xI zl#i@aufomqE>e~vynEB35^!9eC^tquK@TC=Oyfg)_LpSx_S7(IiO*b4-Vbu%qMR!# zW9z4(_eQLORvm?8Z{tthT*Z{bTBI6x2)pq6*z}ZpXfJ?34f-ka&84n2qz5Xf#CbV> zBG4lzYqI#wcyrYyDHF?>SckFqkwv!6T;t@DgLQ~h6ie{&{lUA=pSm)Ii-UlYt*zD2 zcvgB;wPrf~TPDu&va9G%IA<~%A8ZvrAdcyyfmz({Za_klA-?|UG_-j&8bT(Gy zo+=6s)BfFZth78*p556q$+Czn>qSLRWuciqO+~}RSWQX z=aLF27cl5DO5R~7C{{>A*%6edy|0@U4LDj5Yol0e6dY=xsQQp?d9g(cceKTu8x%85!@~T(>9Q8RT*eyw8ivFU=snCv$h& z5>@A(RKn6Uh%Dy@8eDlBiyLq2Mb=O+riTTbPQ^)Nq+}(g2-d+?fD4<(*8=uXO_~(s zobr$TKm#OoMFr0;faPXy0O(3rz+9aROCm;8nf8)WxB;cK;H{;Iw=O=C;k0T*8xCK_ zZs_p#011RmDC#2q=h(^r%dbnVa z$N5#=$c%IBj0ZOt;p+$WDBAoeLnA74qk>*Hm|2t&SJ@{yqEKbZeD*Sie89=h^5uN$ zryPicJN=T3s|hrT3b)jOX%6>Xe*BnYV>1lW6GZzYX-{4ALsPR0r9S| zfL2{Fjo;yO8{A4Q(9Ya}tRPk0y`E6FuplREOu0tsQE7>KGOk>L@}q#5q{TduQ8j@K z^#PxuA#9>^HHAEkE|BF`(c^akA+4f8>cnc!@JAUIv9L!f_i@l7Eq^_T4)cU;>eB=l zi<`ftm%bf+cFo@SlG78Silb9)kIry};5FI=uhUlt7(WW{VQoMearM?t8K{c+5gR=! z5;cYOyy2+bftJq}Mfu6a>@1*!cA!u@{La}k+iQXr0x@W?FsKCiRTq5JxuO_fS;#P9 zP_tQH?*4>SZR+<}zI&bPz~mg!wr##!(|ffmyp_PI;mif;t@(qcPQ?6+MFVUaO^>RZ z#}=dN*yj5B)L}LuIoY4I4Ff0$dJ7=zEQ$784*p3TQM!SSYM;L_b8_OxJbtHvB6EwP zk$h4WLO0-&Q;paRb_sV-l51gc&i$dV;G`kItjt45!yS{VXIfZtmwkgrLdfjT%3k3p z_E>{ca0r`LW>xi(yMCZw!Q;9OHU2zJC)b{0OBrR>5KdO9-IstzOi$=xU3r`gCjx2) z1^32Eu_*fmKpZTjb!)-d{6&wMjM)6FjZ5RD1Rce5*yL0 zbhBhA_&b;|+Qu3EJf9W6nNwaA%3V2W2-Fj+BCf+J0cUrQRi1{0)~bg&y&l*m?|VlECyw zVxB5N^=HbsatHY=%oN@(E-tDsybG2~lr=vs48it zp?wZBWI$Re`UIk}i;;R$sN?Z{3H z6{U2F5JTnjs@u?V2y96$5NFiaLssN%S!JqHpRm4>A0E;G+p-05Y02tY(e5hF5=)Yv zsGKnIwP*PMz(tcWT`v!lf>Li$99xt=Kg~v>j`$WqSh7vRBQ5@2O09C|rfp7y+GgCJ z(}uBPNy#@^+rqW1aoW%M7M&52HDwN{KgkWNu;I;CL-g>wuo3*ULxEHNy{@JU5KK6^ z@Gtc~$}Qb_L%oiNnRv?X>rEMe$qO0(2TL_iglaO@@RK}!3`VYhR}6HH*M{aw zqz)6coy-fHsCIj;nfi!F_Tt&btdd!*A-{>byUfv!Anh0(^$|_J>JE!?dbhLUg(!-r zP`y{LI9-2OjeemM2boqf&H=@7Y1*}}SwLlin+pH=-d>m&*jQxZm9&I5CvXam>H3iZdm=$KT)sZi7TWN&ZBrXSmvr z&tF9e87lb0_5^ZA27z)@M<9Lb%b@kjaAe|azPjS5sk$y`h+#1rxW{2)wCu%{{zOVp z_WL?AQo~nUTVGKMc(YHdy9MVZbUFG_B|dL2GBEUs#?C8tGz0(xwF?ET3|%DHj(^sN{yi@*_#}l{@;Z8lWk!I zNM2%dwYKZB*4<&-64ZZ1`{$3AD8Jx1}dQOXg;;kqko$cCSxO&F_{gIS#0UW&tetA7JNZLgPel z+mtb>ac4|5yXU_EBwF4(MZELNYwYZvzJF34x1g6_gD-yY^#k;HugS+ z2ob-I8ZQoDbiMFiV{D$hE}R$)5BoNSIB-}7+>`wI3GF__;BICVPs0Vcn%K>+8Ftwb zf7+ZpbG%wBBj9{Cd;H40RVD?vJaGi{k^?OQ`xNjJ=$i(_w2wA~fyQ(GjX(c`c>bHy z0LU|dnEne6Y5ql?A!bzoC0H92@?@!D}vAqd{?sYNNv(wxEH2yq6?!P93W?EvH2VepYYGyTjr@TesER zM2`8ukGkJSwclG%g0-+M&}8S=-@Q2DWQqF*dc-8RtV4$_#)kA*{5dem--}i-d4)($|7t7 z$bdB5Ully4eBTFw$mob|WpME9QgMZrN+e(=a*q%}lEA0ujIPN<{a0>?v#L9cah4>s zL9TF*nWV%juK#i2H-Fx2!?OgYxosA@E_;mw^rjfz!5 zhmhwaYJe@`9gme!CUV#cDrBK6gO7PT{z((Ucp;<1AbLAJVR0+7A&S;%ndVjbZK^iN zalT2_30oJZMU0}MhK4l0#+1U@AUWOc$jI=yIt?jpv?}8?en4LM>F#)VNf|}dE(b|X zl}}zWop$OIm2W&{V>UM9pn7U4X^e6L$7lRBAPs(!CaJ!eH@(B*;L15f`+O{NYXTZC z(>>Dx!yuw)dM>Tawo>0C^f9e8zD%Q&;}s;8oam?d1$JJh9;CE7J?QS@&f+tz)WSzJ zhJBV=K^SP*S>bp^puk2OJW^eO9^zAw)HA$5J57zb*mR?C_>Wm^+c=0$-yI>VmxqDk zRHmqLOa$+@8f~PMYr)9dqUyqEQHJfx?A9Z4M#!5qYGCt*WP|B}UNy7mZaXETDooG0 z0##ZZPkkN3u_JlSaSIlN$~TB5t3$N?B$}oSB(}-}i1BAzSVm04S*v1kftu0Cg?1UM z1D``h)m>Dj^mkOVVTvqLIGVZAkswnLWFit~p%-|1VxCXL)IgWmfSJ=3)`L%GCl~mO z)h{+`w81P%=R0*zq8@dya8ike^dPk-41Fz!E;Is-R!DPRE1KJTD}6A}U=XN(YtLzZ zo)?r?7<(upXe2|j@&gCOJ|ryDM>P>Q=O=9{J0q4}XC@~JTse!Y%qrGTW25SpWu!x2>}*a2SMw1|)3J8`z?;To@p8 zc!Jc{T6iW?eMV@OV18}En+a|)zJaA|MV6JYT?XB~DHa&sq|iPle-MR+5!b1DTz6d9fCUZ&A>Xd|HN%V7C028uX?TAW82_c;D&FI}Q~M8= zlS$^~1SP^n7Pw&~!@)HgIVqaf@SjkYX!z*bF?BAI)l^2Tuuq07)TxOBUieba`_oUz z0j(KJS$sjIM#5X#Ww5Ymsy|;t*)LPZ2#3k}k{1UJZc<9D%E&ZjP|m_yA!WII6w7M# ziPG$M^-yH6L;1@{lSa!%oTr*wxRqrmQn6<26<{u&j(NN5-GZ}X9K77sN*@>)rf8n` zt2k0MvBhPRnV3 zu#*n=8Tc?Lry@w1A|tObZZ^C*uLQa#b~X8FcN%^^Dw_RWKpTxELd9&@^Mu5gFTTN| z4nSLgxFL$KiKC>TK@R2Z-m)pr32I!wVES1FJcs{l)-boGaSGyzO3)J0+ey0qvmttq zg!uAoayd^!Rah2lT$F}nTp`=lrb&Mv(gZb&BC_5ZNQHJ;=XhqtsGi#N`Kb1m)YmCY zBLf;`ws`ZbXdPAIMtQ<1usMd5hKNg#C57AT488sD^#m?7C8s0R6R6_3; z^Dw2{v@EA!+i&X=RCH*+I+>GtmQ>~q$5y#BTXuyN`l!;95xP0 zcm=J@bdO4?^pmeFJN0g@M6QZvZkTTL?H)k4@c*d%?ZjIrQ542}e3_5mUr?~K2MFa_ zzOpB>uyy$l%g_n0TCHt=6_y%iq0_;_r5HD>y2N{{4{@M_>8W^=e@&Pv0 zqNO#P(9~N|_Mt7bY;x6^q-RVSx+5+*{t#NL8|Jx^q>PWMCR!uC_9ara)k7{YOX?#- zs)lgN?stSiJ3#A&&anuNq2g-~+T(Wlq`qd-XV=MeXs6*>@Y`XLTU4x9P$nM#42*lW zWcG@7{N?YXGAX6luw41DLK~|f_~?}vf;Xm`Sm) zX4CP&b3&_GzM4z&V1<``?fl#JIsAjbNFSeC4}d~aKfapajyValO7OJcs-G*%l|V9) ztjd3B&Sf0`zNT=iv?{c|c)|IZ+B;e`D2r5u2@duy$rCbg6ugr?2hX~haS9|pjH5)=n(58&S=yB=#k<;EuOrJfY;QO!IbTHn?3S_AA&n}EJDx?F zjfy@QhYwde6t5_7t+1Gzt!3<$$d!o%ZFSZfTf{r4y55fTA{Os$4GRMyv$LP{8u7t; z#kp(V5TfhuuPnJ&W`tp$Di$8y@n|dkeH6}%^i*t1^+UG)%C zJqM+O$mnYA1K19OLceiD*l2w+ti`eEgCE37QhV=e>Mw1oXs>%g9(5^1@+rSK*9cL) z$tCBLs8PaJlF3>ACy6n4v!slJCFiTPoS!&Ms<^iB8i6Ag^5bz%1Fn;w(Gc~#@pA2| zg+@WDiuG>ua|M#$FHJ41v&Rp98j>3F(nsSl zDV(t|b44^J7OSF$O+?LDz)PF?z#kfLjqqI#C|uE(CMJu~=+s*F0Usx~e(vNe)4=i3 zDrj!l8$s0+y9kRey*&zJvn!E4iVsH5gjwS~Z7v%iryXjY@!GOY? z?d7V=D#zSbjb9w29xA31l0PKXL07IW`JnD9t%YAS$2Q|Jexk)EvDc>e}zWJ6V?&-gQ z^=G-Q+Dn0W)hhtLj;s>|CZx=bznxu*0K!Hgsxko2{pEmL03^Tk{4Xuq0R}h{-XPT=)wX}e$mc!kbTSDh0#^}>f8wE+e#Ep!#~8Z8kj5(dvE7%Ms4sW zVWaY6)~K}BINw2%1xyoDePUO|^55cafNnM3vtR8OxLR#p8{*X#$CG-k1fF%jv^Z-& ztMj;akaF57%rZ3V0bnF>dw_ z>5qgznkmAj9W)y`4#++CZ{9KdPVu<={Qmx;A;^@)>%Z;k{cR5@X=`*7Ot^JA)5J0S z`V*k=A1+Wgij5>y1&DGKI+W|x28!&Ps4@3*RbQaji6egsT%&RCn*bhbyN;FK*qVl&(66!7G2!WcNB$_FqREd55a11 z*h@r7alS};j)-kGTVoBF8Qa_2vp}Ef4ncb4fi%gZM@0K1yg*OdLt@~XnCcIj2P~9R z04D7_R0&9rMsWSjpujL0TS-Asm5I+gZx9FXHu`-8ZrV2PLiml7v01hR205=^tARU+ z%%LX0El3?CCGX#2QK2_Y$s^%u5BK5!CF%$)U%$ER7q)9DHxb5ix7o(Buxxp-D@q_5 z(hF*2H_+YJ=Oj_D{!X0C0njlu@H79yV(jFLv*uz-43Mc-%Wy~EJf(J}@epCa`;?XW z5CagHCy0Ap$K*vkG02Ej=>2MQcTGu^jhaBdx+8aey$YD15 z9?x`Vx^fjCZA223G?J%lXRKo}SW&p$xK3rI0RD!>7}RKrcGqd>v7B`gvDe7wYeRU} z=syx21*cBx`3#k+$9Q1S?7EsLUIjME$avnjzh5h(L=<0#*7v3O8O?msX}M*{#~YWv zMmbC~Zgwih_N4MR**9jJ6xYbG0=(m#<@dr7&nGI!e@4q!#N z-m@b2wc7)(Wx_VR#Md=2XFa(Ro=L^p!&(HcH(q{ zp3~cPwOzjVa^s!k%?;!aDd}53dNVMkPw!XjS_cMZsH)Y-p3R{UZ@D~}*dAD4u`uV; zxNIP+mO02(*wR>jL{VhMRe$*QZTPbt@(3W&6j(hFC!xeOuss8A4<415nkw+GE;Y}) zUJXnxm1(EXrwq{e!qvGRW1?G+UqDqu>#&{p)J*bMglNm*`rezE1jeGTHLZXeie?eP zA}KzGr;?5nooZmHFR5{*Q9S4BC2cP4H#11;U^e6*MC_E7wu9}h3bUVgpn1_!;9j?46aeC-K@e!@TDKIIEqx5M@eJ9d2 z@F-sEpW^uqqmGA_Nib+*jMz5P-SI3>xu23{Bs|)G%Gmmix{y6zO-i>_GLDb_^lU^p zACj($jGR*WpvUE#EOR^6Ug{yj&DG`hBpb~GgoiG3d0n00DC`8rVS$FT{?guNYb9|+l=PIB0+^xt% zp6P#~&k6bM@dLHN)7M7hZ!P66Ytr4gXF^;qCiT@aZv;NW0_uK!D7kIC z29&w9FLu7^t&CQwMA5h0w*1h!4D=%+dyR**o1RFdp+c0oyArqm_$L7pzAl<QPL% z(PM>{LCe>Ss8jjE^WqFiOM;Nnb>~*#Wrc&AsUE0RN`O7~dk4JjK!pg|9;9?igAo3M zTn#q^@hyK5Dq+bOmrT(e2e3Ca2gxaayO-^b% zRC5g;)uRT+av5oEvtLzJFfy*9VaJ@3TIn6lR2Q4genj@sn(mud+S&HL)n3-ZDhqR$ zLE@=Cp2#bVrXm-x*$`};Ag^8{Tm33{N&UrBw1S!A%TaNn202%6QRGKEkB#Ga71P_x zKo&!AA_xhDQ*Eu>!?9j-+@gH?(HhDpm_$$WGU8Ta{HPwa6EL29?;Os^zEY`Yuf zF=W-wML*n-&VzI^TeH;EaDbTky3W?R@uVTxo~fcBKGt@kz?^>0<`HL9bYC*|LbMNH zA-Wwh52v=v&ePYZLp{p^_v}Y(HXG6Qx4MV)y9a#u&>{ttYiA+wlr*p#g;W(f^&vYMJQ_)vF3Q5r(C&XXby4?Sf%;hBD zWTL;@Y}PqSMAYtpLKLs2?|vrlcH-sW%c+@51YKJENaWnu;2r7UvYfTVcl=ue?rFrF z!@vy2Z{(`&c(-Cj@OISrB-hMS>7tn-$allykhF>=_$yghlEYl??XC45CcD#Nbc(#= z4-PC8)q!SK%T`vi03%&KcLyc*A*6>80}w5eTgwIB1PAUkCK~P>UO>`Jg#Qz=`$19(8ViVAILmo3hVA#LUy@>Cb8@@+X&k3EB83A9Uj91VOi&5n&&|L_rEk03sPwm&!a zY`VZ7NEKf5bQpee1UyU{;DPwO1LcU0SHhtNhK^{C{~`OVi5W+j^ev}1;J142gR=-k z$p=CLh$yh6bLv9DgYl1FPa}eU$lWWo5!wTRX~cdc3pg^K=ZDTv4o=y~zIfDp@2^aT z%Gmn!4?1|1-ty-v%$ zgK6-s(aCVF_;ka+%U=opgsCyU;)JzKEZKocPIodRs{*&Ho8$Zx^_@T^9pEFpxSvz; zS4+C#4U9`8j09Z#y#dC@azS!cu(evRNlGfD9flyT1b21#_AkKG1LlyKntl%$^z%Qu z(o9ldyNU$$ordg)R4C7naNBRL^qwuatnWZej#)O@H+iN4apCyzV9yKi^NXBMqAnN* zMZKTdiFPe&_vNJhwV`;+`?N@U!=qLG~1BIqf^BhbYv--oMZjT2TAY_o#wR7}{81$a} z4Qx%VP{d8Cd&HN}b5TG*uImfY6pN&I_z&SkfD%$3sB7JA@K21i8V{c zeaYI!Y_2Sh(A8<+ssG;8UmEtQKC$!ywD0Mg`}macfE$kn@o>%fmXX-t!eC3(5va)k zP%w5SG!TY2x1C7MS^uj)Zf&aED7t`N_1+bhyhk)fL_(zX)aK zJfX4j+UEzOjQ3&nk<_Q(N<-0DYUW$2BECZE`6i;uw}|hi;p8EEe3(`*P!`;7n66Wm#auw6J%_Vq3dMCI5bhy=dsE#l3U}&-P+Ttf$c>JVCBs@YsqDV8$Fm0 zUr#{@`G|x>p++T13>z;}!>A0wB5u^0`lGi4au<^hk#{*8PF z$+ZfJ^n&+}>Sm<;6Y$J$#dsfkB|(HeyWtM$n0-!$q30oViZD(Ev{)DS7P1rgHzBNV zq|%AQLisYQ5>=wkRip|F#!^xFJlJ!Blo#^`{3jxIb*rZ%$0dLwbCTNpF;!K{cXdIi zMQ!oM@t)@Kn)+GsB;}QP??AAUlzJ+y_G8T%r-u(WG|B*xJe#DKt_<)}?t4bRCeL0U z*H_XP*_C~($kB6%%K8pXkbcJ?QZBN*oL>f!s$JQ#O?-VFER{Vb;o*jzkLR~{eKi^c z*@V8e4kP8eW?$OYV1-iB>A8%{Kp@{cugD8vd32$k1=;dVK8$xSdRJ}_E zt!l7OBl4RaAW3BiH^D|T>w0NcuZq8urxW^GV$Di1PBX>u<0+GPpw2T7Cd0LUbFX|( zqgzi!MSCL+yD`O5)Yxi#R(|_@6-enjf7XuXe(~@=$B3Lv^a(K`N`&u*bpy&ip?Di6 zP2x3`1(D$&ze;bi7Rq}7s}OkApi!6;>MN%Uk5{Um{^kkYt8F2N(i$=Fww-s9$3 z^!>C2cuhIbsLZu%Qx^gCvMTk3B@*7I_d%28K0h(P zr&iMo>hw8ND1iFf(MRa>w?&U{gLh`23p0+yt;gCm7WNwi!7`r1Pstm$dlWs4VndJw z<Mq4A_UWQXZ4e_Po54ok0wPf z*BwwE7m)&gL83^xT~Soo+zuG9sYtQ(bHuzF90-C`P@eGAKWh|i^w^?b&{6}_%<6PL zMa$X~JNQ9EC-+jYv5knK9;QgpI}qM}ThgtNW`m7P--bF=Mw<3xAMeP=lX*S%Vk_mc zK@jV6qeF1vVJXI$#p+?V>p=D%EAC<7n}tXlCAGSleo!h|B&IsSz*+YIeJOcX-03az zF0g4$j(mlIurT!V)33jX$BAM$!eGY2AHQ;}%Lg-a)eVkfnrJqwJR?m64I4{`9hn#z zze;X~XDd>ijtMUNf>u=+B_*2A^^SdAcV7`)R&(md94S`HYZy81x|BG{j!J|uJ^8DrQk>-;&)Ng#fBrdNg)p~}qTUGI5lE%DfNj*IXX;rTYSF(u zL}v0}YJ+))a<7ZVY(rTOl5VdjW21XbyjxI_cRZR3W2q$Fi#buJc+BkU3x1S9{p36u zpB@5Fq3Mq0k7=bn_>AR>&sm*z@FwF*upJY*#;$TaJcRkK`zdMtoDW@oeOT{Xu&g{0 zJGbK4J4;CAe`Ea-vav^QYGaNw60~!L-{bBQiw?p#Z+)hQ!fc^gr&N7$Q%J)C2$OzZ#S z`m2!b4aQFHQo;bDm}qPh;!Gj_7<++3p(*Uz!X5O;Xh9gKzKRv9R zu2obcdVq;ui*Fk#IxX)}y?7i@zR~UL%Q>84H;=irtFHpiAU9i>sw$prisX)h&hPpc z=K6sGf9XqQmTiMeXX#+yamYT_ZKrggJp{<96|l*46|h&|vw`)W=pPlwjSbfCpF4Qw zut0G*5@%=IOclm5Q`Q}=*!0&^7_;eC~x0sjzjI|)7_Cr8;rqGz*zA=>~d7thg zb$}_(Pu3>GBZ_cUxkHZt>`#sJ^?pkg1^dZxlf3sOaT@tL_o4-riSNJl#5=kc}Oeo^zdWCEf zw(w0W?tCo*iv3I756dDo{FoX%xZ@3P)hUW#*Ey5&5}R&_3;>H3soDr z8<_5^j48G>*`ow(JE*O6W>SN2{zaes&BBwF@A6nvpP4Y7nJ`Wr2DeQ22^%2J6z`*A z-yToFi&vsM{i%W^4hGgfa7GVq_P2M0+cgKjL=P_HD(AWwwMnnCrwRF7on{QRE+2j-9o#RZKJ;PIk8-(J*f#P4k56PG`Cck?ja z2X_+%$^qDfO@6=leJ1Imhc`Y(bw2qvj?7Jh$H5N(fe@+NnZ~34#W)}+dp`dUk9YaQ z=a1=)7?ZbM>rT^Iuaj8cMkxW9WH^ub5B!L&i3s#KVkDgWuLuAHwRf3C&J% zZMB8|fkyFr{@+~-FkQ3ImS)GheGiwrk~29F2_PH(pSA4*zNN^ z*#z_jfPS^~i$71)ABcoVI2lCt2T&;o>Kch zBj^29b`-KEh%D+6bjQ8Vu$?nXiRbSY+y4+$)`$&pWtaghlT zl=RJ++AqFkMlfK!lgV|uAfKvI<@ujM6Da-2D;iK}!`7nj?) zd4)EUd!MM{yKNp!rKc7@SFToId^MF;;T-VtQ>Qd@L29jxk1_I}MD6I@h<-@iDZKTV ziaNC$u~_o?&N85zg)P6(hH}D|iL3l)jLnp6?MfCY)o}JAYyzmB8smia+o&jGo&(V^ z48y;KPm0#$`VRXmOp$EIa~0()*FjYbX6GoWS)z1rwVf&aT!vVriqyen>;Xjk^-Wtc zH>j`KVin*vbA+8wamHqq#!30&z5;OpU*Ud6`wk;kw- zMuiD)Y0z%klOE}-fz3G7JnG>SM0I95~jaq(Tfvklc?prNi_93>XGi=rE((Ix}rYe?^nR)^a3N?Nk)m2CLAuR1S zm9;M2_w@(?Rt6Nx*RRqDm;FNCq3yKG)JXpv?-@={R!JS6b47~GYc?I26?tYpZ*Y<0 zuU_zYTgHq0ozUu!;(+e8L(2~Yp`8^)Fj$E}L|HfQXLi&kM3T>;g^0=V%rcE^WDGW$ zzRhBZe5P5)UgTy&b=35Q!;a0}@YA3yc6&olBm+LfPPXZ(FsDXvM0GT=`)J#I}8k6>l@u!t>IS zRhdQo-m7T2-;yn6<vH>RRiRRO9W@R509h`t|fYu^3t@#Z?d#f>FT&%R7FxC zH}sw{2V$#zoG)dgiZ!&m+;ALiEe`baxd;Xsa45l|zen=n1O z^x>$gL6sOf^%wrVs^j9{;SR`Hj%WM1-yqO?8u_1ElOv7=Bq)PP0zX(pH`7oBpAQ!b z{hs`sw!PUEDt@^e3Fyw^s1jZ1uhhl-YQx0x`X)SqqE`b3(Q?mWjA&^c=mxU(VDAyR(qppZ6iFX^pKYqbZSB>4sVi>|33 z57{GH4*vVHi|~74kJ>(mVyU$Y-va7=LLy6&OaB@3uT`?apPFowa?PI#4?52VS()Fm z+g1hRa#>Dqek>+zIl}Sm9AmOA%0gNa)>``yR8z)RQea)t0o&#*e5~>p)NF9j8xR50 zD9nD3WP$|Z09!dODa|f~A#nkAXbBQJsB7_%cde<&pA z3I!^j2-cOk2DAGQ-cNNQ1TI$z80jFT96Vn{fRKAB67 z&s|FAZBW`yR|ezu#tr!w@OSnO%#zsr1Adx#i_$VIL{jwbF;6-{HSn~+wu!x_MtDq6 z%;dGBQF=I)qB{PKx4rD`+jy`@MyEm{*^?v0m*0VPns;t=^i=_E=V_mUcAK*}grHis zG{nkH*^j@HmOd;*syff}ZK?Q2;l6^P3*f+Bf^UkrC(Ll_IeUbg?8Y6qtWWC^Nt-^4 zmth9vTF|RP*}<)+N#<7pJ5sqy8k;-GlkovL74QsIA~bzPSbYN|bB=;6S$($}_&_q+ zO17^J16eWZHH8I-w|{Og%hUiPa~6{u$>+h*Pddvr^g}dQ1I}v|KweCwrdwC@q!I*P z)5V_BdCAIN-Z!fr&Ph`^ytMr!Er%aCtyBbytNRVevle~ksnh`Uj81}znYX0p$x{lJ z+-V1d)_cZ5wJIdMf}#nd`ef*5rXYZHVgRJGGxR&MqZ08q?n0RphGahFg+K?Z%eZui zKnB!r$Frj~PI~F;2L=48gEGl2i=?h%^&a~Do@xu8;s?Rv&t+$UsvEj1mEBk#z1;6| za;j!iLJ;zZbN&)y(eA@0U?VEY_NL_h?!VWb#0!NslOyG)x1082PC6cam6OB159OLr z=p@h{lD{a4Bdr+8ogbED4P7^%9GhK!h2tRYd1wUyk`v-$n{Y+Ndreh^4mp-4>ORgC zSf>>_ZieofruoNTjy;{fU&=b;1OLs{C#-Xm6val`ZMp*KlyhI2iG+5s8B+b^LKYk{{+1Mw4~Ggp|@c6V@&t$ zqJcmUqtnz=HU~;KIYa}p*qUVvTisY0BSa+Nq~*ttrhv@Ey^$0_gZtURhe67@cLck2 z8}jQiSdYuz^f4CIF_qNk-YudGE^sz4?m7&)TG1t%DFUUse~6Pu3iooH;)=mnNN)C) zTWV(&?)GO+WyRZ{E_w%Tb*HRPzpu^Tm1g#wn~%ru(Y-qR=JnU~!*w_b7iwec^k$zabV!}r1={2Dt5 zX`GpKI`X+>j2>mublDE<7;EPL>DuJ6UvJ4y8+X!J9nZtyt@JOmP;P*mYR|0rD%=(k zT;UF}Uj<_2eO*j~I@1~8eu6J`RmQH=o@YxK-3(VOADw*;=q~!J47&$LfII?_Oi3)5 zs86`b4^^G$I-6bWM{Mt@hP2Uq?h;cZ@5>i@YYHNvtF$JHFOEh z0w9g)L=jNn8uj9ZZLrBL=Bb&}u}1S_CzlTIWj8flfthTf-$x_1a??{i!}Br7chv2kl~w zqyYesb6La#Gy>>dr`O~UQl`U9!zV~z~PV$^r}5QomfT}?c$i#lw4a#3o4tpgeU(tk}( zYPN8Ki51%{#FX_v;GsOak{sGw*WlYd!e4_A4vI}W&aeh`A1SGw7MU1oya_<>sz-`qWydPyaNNvn3^4^H-;86Tt-Hlf@oda z;xWcbQLO|~V!Eb0Iu=iR6yLcBT0B)W)DI@nS)?hVsI2g+<8fCRZCAWFr{cP+8_TK? z`-Int*`r-pRmNRAZ0Kc0FwQ%IWHvI3&N_w}SE$mc5bkp`E4oOMwJ;6PlR(&1lF{x~ z%0@`fzw=4%xu1`Gh;@5cg5T#Qicw6X!A!FkiMr4=kTxF=g*^WY&{Ti7aQ{67Vllk% zOVp@Skjd>$D?yeJewm@o5(gKHi`3D>oj9 zOfCTejcRXkQ?_|VmM4|Tz%e}kCT)0FhWLd}T-p!bi(LEw`!>FKU~K+@KQRInRla@O zy0`Cp(Bm|b5zagff&);WPjyPC8Z`BL4bYJA7niJIODa=5D-I9%Q02pVM|F^^SqK!_ zNhWHvC6Uzzz4HgrSeujCh5uB~nvphy&kX~rKD{*iK-63m-I@F&F9CkM6>wb(OSZZi zk$C+rfe&5dGTYo04dv($zp^YN!exC#-48H0QzNm{{TGAwPsS+tTg{!ShWggnHl0AL z7AkVVT!pspUJ39OwrknwQz(l&ZV)#j{+7JEQ5u2zD*caa&i@zS{>(79L?Lu%_qdy%ioP|(0!yf?3eiwaz=s#+kUcy5c|c@w)^w_i zMX3Kfo1%7;h3Nw=hqZw)(N*V_Om(ZQPKbhvam=*f-1lxGD*9!046q8^mp&(?vWs>w z8L3YojH2hH$+&{4RiUd+Aj1+)ACnKUmp}ZBMn~Fl(Gk;mfVZHLs<21S%M~pb<1^TS zfwu~E#I%Y`ud3F}%ECxGgD-bsirl$HzV_+Q!_p&bvt98zymvew0 z$ZT+?F&3;+#?PxF4|bytBOUqd&}-VShF^XCk$88mcQx!HUT(pdWd-M56ZL9VkzI8h z;EhN{UBVr|7nY!@FD1>obMtW)h#O0?vD_oo3Ay~8w+lny{Ll_Un`^Dox*ndZs=sQq zuYkxLB!!_ey-iIiKJ&v$BYD6&eVsRtddzE`@yYl6c==E$tv!_b+d1mhwad+=y(0MX z-~7!3(qYpx_?$TYB~Rs~+ekI|)Gh(LETo;UBn?l?rTsPNt9mjE=#6`{DnTKr6f>Ke ze!?@8C-He)hD7>=2H!?n*7KcRI$J;7-EIM+rI|uir_8GO?Rd#wK#F}A(xc66zSldu z3VH+}@j-|;5xJ}D77EvQ_ti>%LgLTATTX8sF%)EH-%^;^GAzHQE!}#SH`H;7S#Uo^ zVNuark)H%rz6B8bma7`EJMG6C9@NIk~e_x~N;WY=|WQ*X@#4yElIgaP!qJTzY?;^4VY zI4YfSG@pY(1Vt=!3v(wzZ`jg_wQMdR63T#=a-*tly?8#zr99`y-xe>L ze<{La@iEb3!!j@1Lx8lunD;l2jvhebo5fl47Z$)d`Q6S5PmPk`u?K%5M~l^!H)&^^ zR_b_{fD;s8LZlwNi8s!($%yf9Ok?kZ8X09p3->LVII4W+J&e?s(J$zeq0dhx{Lf(2 zMKK|E5vM2-WQ(y67hO3OVp5Y$<>tDjZq)WPQjK#Mno4Lu5nM;KgyB@Beyv948%Bvv zyD5P{K>NME6=Yl2I+^p|4)(ZBG+E{Vb33 z^OZgo*pBk?XV=l8>Dfsl(JzbM^PDE|pvW6(W3 zI!%8nJ=@dKe1QWr13rht{tu-Q1=QZ!#Nen!H_y!CwBiXE$0zY0&28-2ISYWjW?4Ym>r^)_zt2x$=xtfoN z7vPhpFK2o?|NiU?Qbia**toUm{5f~5WH??K9k~?|MNrxjh0+~%`hCv0sWks$izlJE zDFZTl+Udb*rK+<$drHBRO)mXH<8Nus18qYAt-KOinBW*&Xh_>#dsXQ~L@;#o`@Bju zP@-;Q^#x$0@b+85f4~{iEL$+`H`0g%hPldm$aPj7j{`gZ*rHQdoF0Z>1-PzxLjEQP7}m#XBE@Eo4eFoVT2KY zsOUaOltjzP`}i_`CKEVV?$M)zKaxX&oqA_+@~iQ*5~4A?q~FaPrB#|J*S*&-(ADKU zTo;dQWgVSdVx3*U=B(MHH4th^Jn9GE#&gdHm=o_*W_z7nUPsS2Vv49CKS2&e{*w0> zlkOZay;T{tlKXA)$3-@J`9a4>IO(xwS)F)3Lr?k2)>;5;E!&AK6+Q?NRR#+&aTzE9 zM?@?|nFt=a%RoveYPsz6lHwtJt&1iz;mk z2Tpsx}Ze6IObPxSKQ_oePhJ;{A8dUJ8{_?b8F zm2Q69wCB~u#≠5CATB<6dM@(r&Ef(je~E=w<~t8L)SEZ$aVv{PG_Xh7$$_Pi9Sf zTHcP{xBLqvvM2~>K$j#yyAX}`@8P6A72&US5-I?HX1c>czYi8#%mp-{)jfGIg9bB# zs7@eQU(FnESm#{^d_F84EckHZ2O*&20lWhhcN3!{spAj2ImiuiFlNNUL|-FBrk1v_ zX@%8#uJorEo2r3}G_1|onH{o&5_ixd{k#A@>!U~a1E@D7+204!kfUckRJ7VmxE4je@sf@QCNvmb6mj&lMPqEm zgn|^xAgQ`ll_QR{2b*Ln;CaeyyW%iHF%p*(ScmFtp9s}94e>`X&w4D@t|2iLrygw7a z6mUH33*q~FxM7J`98fd{P}hG7(Xip}3(){CZIAVT9fXK(q!_FYd|Li!Th;NUd(mit z+bxy-^-NX-XmR&p&i7SCSMkR@>UO`6XB#O2eI8KXcK=|H6axU2q?O5elhXgy+j&Mc zm2Ghx1*0IS1ENpq1VNeA{qIOA9P~b$A=S z1NxgxTI@E)L`H1-gF-=t;Jrmh`ct4wB^yYatXfMbuvz6%&$gjH?@Ml`TGOR!d=tITOz8KXfl=E5MtRJrYrNZ0K=HyA=0)}OVR_@!o&`DV`dpe7)QuLt zH@LEFK~6Jwjo|CMsG3!3-nZ$hdnhZeD4f3Mbb>55E z)4ek;h16`blEJ?F-9&-qZp|X_c}d6H7A`*^2VGmVO02C{CEb|xB&jWrd(QAwP`Y>B zXxQ;Xn0>$Pr<^Gpi53i+(=a&=1zM^vxIurhhNJawHBd$+2N5C&X#i!gi{%mGG7{v7=c{2r!y z^1!TP_Mvm)^TEn%>pBz$8GKHVk!Xa?{u+VomL8X7edktb^$+^^UwaRo|3TK<$;%iZHJY@w0R=O(B56Wt(s|6CK?w_r3(VpLt`0casJ?Dpqh4(T zEiTbB_Ml#J?7jz_q{J9y65xvQiI1Vyw?<2}+>m0U23y}VQfn1xSao8B5qdsvUa!=d z2s&q+R6rM@xF;X@`TPT*`>9F?9g(HLa~DmmU`Tc~8`2UwIF%A)G5&KmCiOUeI2(Y< z@W77bc&l>IG5c+)=y`31GRgCX2g3N~1Fg7+@WXUJvfYB3^T)WTSO$)js1oabbK}|U z$BDRrQ$bze9=BfF84=hKNVzZUe!DHD5E{xNE<@e!tp{NW4=w{!jn1AmR;WBj7OxI> zv^W}g@3Jfdz`E)P%rz)}o~_c5NJvE<;%9$I86Ru6p^~7LW0ZsNsQa9|@)7`-Q+@DT za(RxryqJR_Ni6s$pKEjZDYayG&Wc2R?ge&O>CGwa%5h+$v(et+oS1U->g}6sbrUoU zhtS$m)lf?9pv2p7cRiVKSe}}^?#%lDoCVudsieQFE!6W?Y(qn-HPJD_ugB&IWTN`l z!uA<;Z|v2K)5Q^=_^zjWob-;0ZVhCHkq7k252;z2Asr=nD}S3`&Elboza?RUt`%bk zQ`CF}k;97ILrSvBE(7qw2*|g$t;9!V{>Fz*Wm=cl&0AO-W)te0ztt{QD;umPWjLaSsPZvB|t#RcwStJ?eYGBJ}eWq(=KGTQR&Siq(l`UA& zIxSfQ%rRX9;-vKwdOyGLDNORfW(1RReZI;3j3R2nA5?NN!pjcA`~D%^f7sib?g7P1 zlw|7+gqwXGSO$1$QxXn1a)znohLE zX$6-dN9pO&1T~iX6Jbp8Zw3&MP*?3rg0L=s!>K<2^~i? zD~dB~V>Cho6hj{p(h^o~nn)EtKjxn-cOqP?)6$=EA2ZAueg`LApkQX$u6|P8dj{s7 z_|RZ|<755Kl5D4=zWoaB4JQ~LzpvSgV<$s*k6lopi3hG))nAyP4R)-7RObuZI^*^~8PG39eDJkE)gR<-YO z9}ES#*OyxN>IA{zv<)K@)Z2oc+3>?zIvjYXu1$g1y%47v#iZ1CZNzF>xj(Qee zsB(^>#x=W)wWD&&tJl6gsu!4BRO)Q%t>?NPpPneB(xo-ar(}b!X?O5VcQdzWY6|$k z7zrRlNYgIGb;5kVk5DI#@5zV-)`LF+<4^^_`SI(lUlWW}>4{M}& z&1ibie<-LHGMy8WeCO!-n~l^*1wo@Z@O*B-Vf@ zp>m(UOL%|gAntMe=G3_ancXxV#O=YAD$Z;%D?L>gBLV+^-S7E>dh*12Rxv-ML73n%f zN=i%T;qkHd;k&jLX!w{HqVcDn*473But0;IF+}3P)`}D=a!GqN;&N}&lZ(-_0I3gX z^HkVQFpEHRS+0uV@+&;ahElHj=H@-I(2KoAwnkd)qz_CW2&btT4zIB~0qsQKN}Deu z5C}M2P$Mt^&>4gR=Nn2KTaZYk?&6z?Ag0v?r*3o19Z>-tbi^rM$vkk=xHbpy-de8f zXY%d^c1_8Xv_5iIsPIZjW=_s8E7Y;MFiL99m4quKLt#B0LL8@)356=oG8xTJ#1lW| z#P}GWi=hRep?wu5q6l(`aHvjZ%v1|kryedDUVzl$Kob&VaZh#4VoOD_=GN95bk;NU Xzln?+?*ZUx7M4pohUW{<+1>dE;=6U$ From fadf494b7de2ab0d48f2e160ac073deaf02de662 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 13:03:58 +1000 Subject: [PATCH 016/109] Add files via upload --- ...me-to-edu-windows-edition-upgrade-policy.png | Bin 0 -> 45890 bytes ...o-edu-windows-home-edition-intune-filter.png | Bin 0 -> 40112 bytes 2 files changed, 0 insertions(+), 0 deletions(-) create mode 100644 education/images/change-home-to-edu-windows-edition-upgrade-policy.png create mode 100644 education/images/change-home-to-edu-windows-home-edition-intune-filter.png diff --git a/education/images/change-home-to-edu-windows-edition-upgrade-policy.png b/education/images/change-home-to-edu-windows-edition-upgrade-policy.png new file mode 100644 index 0000000000000000000000000000000000000000..f9c4fc3a128310e500be82ccfaa19de52549b613 GIT binary patch literal 45890 zcmbTdby!r<*DpSbf})5>w}424bc0GtcZbq2bT^73-QC^I3|&fh49&pM-9yK~@A!S+ zd!PGz|GCd|&-1{Ub9S74&R%=1&-$#jgOwDdurNt5K_C#;7in=75D1M11bQs<>@jes zN*D_YoE|x;NPPxXjF9aB7f;MT$$tWYsv}?AeR~RAKew0Gb^?K3b^iN%)N5B{0s_^{ zd=dYo=5DaR_~K)%`UA#sVCZ*h#+=8iSP*d^iEdrQKueq%gC8doq;GNvHUO=!k@K#F zUdor34NZn{v9NSD=dWUM+7%_$a|9ATk$56u`_txO$zx>h!rHnj9LwHUwA^FFW5j6= z5-8lB?v!CpF*i3C^KQpkpj<;&NhvBmK0YxqF*Q|JPfuQl*QyQfU@t%>^??e;q)Bl(Xz5KU=-QhFaC9@O<#jNImxCUG(5uBqSDb$i`o!9Zl0?x!f6~8{PHk>(dfr{Y?LK|_lv7rt z>@2~>;d}I)y5P~mt92$%;qB5FKJipSOa+fXf5_i+azZdAbc8Ax85v6qT0Jc+irU-T z>+9>2(Cu&OSy>C%*b~_dS?TGEG|EZ*SwPNOO5_z46@BacorAZ`BZa|94qIK8ta=Kv zmn!*;w!%$0@dUv4N5#Mm$U6j7JOTudIPF=&2Lq zD30n7vpurM{+&zmmjLu#qS^Jp^Zt5EFyVvMBz?*|M)e>m3Xk=nWKQbbj{#g?O!hU^ z50M|q5O2s)7|X00Wm;6g(sBE4*N(c_t85q1>)>7T#w8@A0~$6uZ7F03%`wmBFyq7C zMc3nY^HAv4Sr;3&x6xN=D<~*fTknsg3rZkj5UpOS=^T}`dEr@XD3b7ks;cA7;Z)S^ zB_Xc0QdzvgtznC^U;X!jZz*?=!wcPl3e8lE+3XhR-jw_<*R7u}Q6HR{nHd}$oS2wM z&`pBz^4|pE5Cg-~90)Y%_M;$KElFU}O&Ah*OGDH77a^wOu=9-|8xzkmSWbK2W(;Pf zjr!?lh+<#KO!rbCySz|fJd>t5Fhh!7vgmGLL-;Ug zSV)bBIC85UZ_fWTTKzb8jLc+}89b+_KW=du6k|GQ9SQ6{W;B&~I4Rymr#vLg_vAV+ zrkv2WdI+4780b^co-+2vQjlb8?|Q{VN5_WL(i?SiH6SDgL!a`7a0UGWXrJXlw#fD4&$ncPuGVukrqsDov}&vzAW%IO z&*p-F^7FL6C(?UWLs3;hGtL4CmxhOX6Ysaw1Xf;aJL4e&AS#K%*i_$|Jlid$Pekd!1vJQO34C z8=)#%5JdfSLx?N1ttKEbhaOTREjFc67e7r^2~%Q@(bQyYID24%9n~L zOS?YO4o;k%^q%@r3wAqPNREq3VAD)2Gi`}HfEW{ zc#Zgfmcuz<$g?wgW|%d9O2HJqYz89Zkqf2m3{=s_PO)95$w>dCd_g$z#gtBZVY%kp z9#O)PQ8cvJG#+agbdy9*%9h@LZ%P^Qahmu$F5Zqkw@ygL1Ix z2iiKnhrpH5+CojmP1zHIO1IaiV@95unO${JF)$|w=Epf$+bk!Ia|FKzzeR6IB-EAP zuAOmK9U=;bb0Q0>`gfXF^S5&a=Qt|&4cNGCnKj?Lc**JTHHifl7N9N{Gs53799$_9 zl8A8Sxg8;tm9wWdNSajqQpR3ehf|6o8oy14;4_KKwmyyzjeBg10)Y-o^qXC&)jyk< z%q+n(h%^>~xA(8(001q{=4AFW1z+E)-kmV%FFui{P}m9@_xL5>gJVYjqNsWW!wVBW@j$AT$@HR>@~|drW&gXrdsUiW6-jhk&%&PI02lbB$O*7gCspr z^IYHZ)%`DO!Cp;TsPOo3N=TR~9<|Rx7)GezhIIEX_(KGW?j}h}!-$wbd6G^=!Pq5w zx?bJZHQ!f(630sqG)V3G191!$A~Q|r}B2ZWX$o}TNawe9!G*$f(lvIdP< zG!+>2I}dB&xA$&Bf~cm%b!D|YhBg=QXn?=JQUB&EaT-^|rjNdfUz+w&wyAvTmzKiF zY>&L{TdZ>V>0ex6O16|Xm|Hi~&6ABoHtGb`i;Jp;5+6>FfLo6^6Ay|yNwMPOn8B(d zu$?il#Z4roZlwi|%|~lH_9&SQ;W{@>rch=ZU48=FgE-yp^~BUS^{P4f%lUv$ov1-u|c+KNBX1%bZi!fWK2PLB2no!((9DyD1b(wquO zsA?jGIJw$(5-YtdTvDjh74(xbj$E!vbcU4BJNZ~VvNZZ|Pv>6K%#E1QdSPo@yp`$2jdL9cWoIrdJIKbY?APronAmUWg9+&`#bGEu zzloAE`$kOQ;xlplneNNDtEA3*(m&{R{VeJUgxUjjyUqL?`tR8MKbHfBCrg4;rHEG8 z)9`~V>69fgZ7|Ns{pEsa*5Qibuw<96DbEwc2eTJ|RR_&>{54$LDQf@JM)gg3N0t8` zEY#iIZB;wpW4PvVTG-x>$lOqmQ!P6!TGPKnbsggRww{<5xSi{69o=iH_Crz<6-rM_ zg}KU(!&zM~an%_^s9Y~t4=M~yH9&NNuKQY!jx}?$%$N{r8X8&RZp%M@;l02Chm*GV zpn>cQ9qwk_w@p4S?Mw88NQ4rcA1>;eq-|w}-5p`;v&0CU(qX|`q>%Ty6`$N8KD>pYh1crnuL(>|i{f+f<#=v= zJyNKBA&6l)KQpw4r#B2Ay#Jx29+3?hnq5P;Efdmg0D(TLuYEnr#^oRL(uz@_n;T<6 zQyM4R7JdSl%oX>eZ|Xl!2?5Nd_R02*B`_A?N6zK7Z7DtdbRYipf@j~39#Va{JqY0_%$0Qho9w$F+U z0QAx>-0vEtQx;qS0RfGTjpaJEREg_vPHfTNY{|F7Yu@02efkmpcq%= zA)Sfsa=Ny3Cy_0^-Q6HQ!Se*U5gI4m>Yjmldg>@a%j+*a_#Wuf&l(s6iTAyr@~2Pt z@zBXs-WuqM4$bTGl^a?uUnBS*;ZUMQV%XMdr_R945!#ALm) z{XQilLm`%af6Ya&q^fFpGra81|FOWQJ*ZBll>zhuKp7~HyHT~d%znQ^M6KYO6}rS% zM|>M)u7jauH`e?Q;6L9V*}&`cTimPZOFjb4@^gDvODsDnJh!t2Tz1Ez z5B?Z(`^^MP=4J;3!5oQrZOOW|05>wO&HZF`q0wn)k391UXgLA+)H0)h(^9xKn8-FE zb)xUKD6z!JfCA>GUp;MSkga`xvKW^ZaCvyWuj~!Bi3EPSdw6&Z4EWJW+-yDo_)^J# zL<--jB5y3DqwG2E`B+- zWi}k}@nI49V^VBMXYS5@FM!zbPp*K6c` ziwd-eDDl!suDswVpm@zHNwV2A?bC()>A#qK_Z0Jx~3} z*<$I?9rD~7zCVjz_;v3cPucWtM(J1NE7hVu!U^=a#9wX>n~#7=7iU-c`t>b#M_N!$ zeOVcE2(&L4myVw0y;|M+x(TK&J&by9rjj?z+JPYidU3S$0JKU8(9W}*C^*~S9qt=! z-B?o%&)lK^l_R~E>GV)EW!0(w?Kv&|5F;~l-WR+Xl>`wqC#Tbv)|Q2@-@~1#St!g} z?~sFM1|d0^;!^!hE_?J}2|ZM)sHmn&HLY}y!XoM>Hp+> zusB}+i}xe`_C+BMixs@irsX8;Y=16Rof0vBdaH|NN}lFS9QB_`F0e055#8$pelZ?)EvayR+=! z{<6JA0=hc>SEjVi^<92p;lvVAZ*xA=AfSp!ad9Dim?`3v7&%t)uB&7H(`fkS&{Dcr zvS{cU23Z@nDk{^jET`p67~^&Xz0R#9QRs2}4)kKgnwoDk!#6Eo^LYCV04g(#%&T^th>5wR7w(a&% z@aC=0=`iosP_h`ErOx|I@n{0m;;8q^PfH}@uk$cJX6~MGPY=mv6I#Ok~zP3Vo{6 z!+ApKw9ZD?HTLTrFCFTyU{_F0aF3SPh=Ow0?a1aGmFL*(yY81gDyCa0)qe+8n`Y$} z5ed^G_*MuSa~1szlUeFco$wdtFDE3hJa(}ivmH!53AQ*17!&dh)B6iXynAWRifdu; z#juHRyuER@>bP{(9`O3hBW6J@go#w7_p!H|iii~+#-q#;Eo*;vijM=G1AMVLQS1sI zbkpXdrya7irQc#0p``|;wHSm3vKy8OxdiIz6t!>~t zqwh98hsyN3&qj(q+{F?Km`#knX_ zC9GT=9F!d#*z>hz<25wPb+|oM>2q?hsY3GIxn-0RFu{{We=9$(59?U*csW%69zJx& z6EZO;B^{!-nU40{pJk6`%mhT?EJMG+{;$1e0IZSz>k`CV5unw?3z+k}1nO&Jm&kX! zn$dL3t*;||#s-!&_GHVok0j+tr)!bcV1z@~kx@3}SJIb5@#VrGT!$soAVfevnrxj( z+%|)n>+u*vOKR6mYhRmJrsueQo#E{y*^aD6N}XdLe6j1ffwo}z95$XRQS0J?gb3R3 zi4-pmkJ3Awf!iq}olh3QS3l$Q2=_n>yt*Vc9P)?JxaUuN&Y|&dUf8)_OpglmR-L22 z*KJW*+J{~g<9QU+AJ#Sn_zmq`VCV{d@d_R7O~_~CY?F?aPrnd>zqaJjrC`zfQN9&O z*FAKbF-fQm=jUma>=qn+Mc@kU>m7lVOW3J~xz8y2UZ!`wAA7{{cC9&v?i@F;%j8;X zJsYPR!wK6BFI@wT&6@q}nt`sWn|LiQ#s_vzNi=(tmyJ<9DFVh6I3xWMI)!0OtjpTh zE7k9>yNd^)0wO@XspXY~_ z*3Hx#0x*Nl!(Jf!mm`$GbOHuT;k8p3&FP~$GfgFsH7Aa)_csz$iC!9dxNLv$xtKFo zXp9^9hGz+|iwY*|W;`2wlpFlf1OG^04uza?ywkp5*nX^(5svy=Pq+t!Ab&%L`qKm{ zucfuLs{g2#npzhl|5T0XAT>2L`b(le5Ike$Dh1l#v!NF+yLkrmx2pchNRN{99pI{j zL^Y^Y?6s)=&d<-X!XpfkGZl2&48z4RtM%3J7OE%a%ku3Bc*(DiE+D%tIx(mB`>6J2 zjuiS02QU3`7$u6<6EmJ%$Zy}rKvicU_Z>C(e%1FPi6i4PN+eZRk?uOR%89dD#a#9mBRMoL^w-;`~ahBY0|xNTNNYu63F(b6UyEw!F93}alMKZH`0VDS zmvUlUZWIqj%v11K=yZq^&sz9u`6q$b#?=QSG(v94;~&Rn<=p5MB6KQHlWnFvuI#Gf zZ(5zrIt%JbN=ju6W-EybntFPAT3YS^)KYCw)l(Y+BOCQXq#P?W5YnNqa@9*UuqZ{+ zI>eOKR<=LXRD+XC;#;nAYKBsIk9sNn@RDVE+hzvnt2{M~%(Z0oU+!OJXTd3>ubRK)fowSCYjaZkOpY|fv~;zb`w@3AyDGDoRnx1ez1ZQk1Urb; zqRVR2tn4Z+B-EZqaD20znX7XuYnR**95e#^s7|jxI^QrOU@{(Nd8KMZu16*T<_JM& z# z)(n9-xHH_63+D4bw4z&DS|w!OXOe5}PhA*3?7p7Lc0HH}{5e3Cm#P-NGS#iO%pbRS zhi$A&D1|RR;IZw)54axy%pZWrr}E@?{*-x%6=gn>cD)uU`f_b|pz}G+D!djf1;6Pb zwNulmGQDMo`l38bm^tDP&Swn$R)gup3t-iXy296Tw=3%rfma1@Or{z znQTh&PKC&&U`2ST;HtQDzTJkA&ld+r;py-BLaoVe#|v<;x^J%mf86?bvOb4rFL{k& zgwKCFl7A7Afg;$uGg{OS*%-w2)WzN?Gp6aVLCDceoEJVEiv>$)!9RPttZr1j{UUj5 zRqpVXw7L4{naL4{$kt1^jle0TXw_J`o?!1?x@mP3+2@INS{=bKv3!LtA5H4zY*5eZ zpfMv4e{$K7IUc)l41TP6=Q!pt2F7Y(OdEk(k;eS9*^d-!Hbh7lm)=*W7q}3TyMVsR z`mPnWODz&!<$Kxc`J_#8W`fB}P|a{G?sRo)4$-<9)AZey{_i%YxQ(tvrf$Pls*NDO z`)fMGHnHNqK>%>DHn|A0@PGKAWMXlOA8syGvMj?>(nyk?ErXEDHuA)N9^iQRD_glh!l4lT5|O3N`d2LUv%|ErsEUG{#O}Z zOGaYN+VCp5vp8)Wq)AKlMJP(o|=ExwI=3OTrOi|GuY& zXHPhgLx+*HX@rpfvP!My`9R)pp@g({gBOAA{dJI)TLM9q;rnT_Z#6;a*h1jh=mByw z`Bb9rJqFaSm?fzi_^ldzqm#pQzo`A=Jju2#IS z`i+kHSy>-ha>YGw@EP;IsQoB8xdGT!Zm@cGbA({enkbtvvS(q6TGJN#^B<)EXg&2i zK>_cp;}?Xi0N0+su15T zu4p&zo06u+;EmYd5;>ZE?nbq4k9dqV$MaiErLsU9Dy!+`Ch9g`S!8CT8UJVpbvB1D zZzb>nHi+HlT}Vr;iK(g2^+qCe7LZ?afLW{rD4HCJ(3hX^1GMqx+x>~APNg-q( z^>F+uK9s~0>cy}Ngz0w{@|}L7W6>+?m02#F)je=iL=J}*UQq0;Lj<4hkE&fA)NV(v zpe~mR)kSajA!h->e$fKHcYNe?nE(U>2qppxqx#_s|J8rPkJq)R`?yPGp0Dxx;uM1ZUk3Vs4_eH(rjb>B5reUG@%55_rM{wT$ zfEpcZP-p0gAcvP}a|%#}v~-kdLt88qC3bUGjV?F^p_&XsCEA>C%apYW z74)0Vx4%re`|w7^#H>~Wq!0#$`$xR*v}Hc3w$nM=@Z+^C5Xhdc!C?*EZsK#^hMt6k zghyi|AgS_O(ZYXh07m!ck z$;Y5w;22tcZ5cm&Y%V!!RhvTi7zlXhj(T@)i7J9-UqmOAZ`%z`Oh6hM_;`5}Gp?%u zZrxt=?77_)wD+SsJzdyDO}vm+==iRm`gcNPF$lCw;jY)6QiX@M@;npsYa+Rz>swe& zJQb8f7Kk6Dvj5T;_$Bo8k4O-7-|QJAP8;Zr^mi5}J3$;JH46sSpT{73ub}FzJMlbq zWZ?9_7(`YYAUN82=f{WdbAU?_D9vQThfrwg{ye1bU-@@c4;dmyAc6r}ek_naa{4pS zU*gq&>S106{Y$^G#~0W6cU|HCAHw<%E&73F$bbD*2Lux+X}|=g88|dQ<^4;BT4wwo zQIEHn(zziUu6tYa{$aXI5ev(aN27Q_FiaJe zDuGr`3Tkt8ROSPDv}kSEcZQZP`mtj?MFyEl(JjUS8kaeXdvuQYB|~UHy3Ilu#E4Sf z^#>lJ3}F#Xdk;yumf`Q-p=SCb#meKiC4L^sMi=BQfxIY{99R7dvttv!Slk$8xVKnV z?QMoC6};V=o+xEK>HW3Xm;?3CbIWw?FxD8*i>@uuDgDTH(Ns3bIwt*t`@I{UHmtDS zkExhXSjyx`PL&|z%>CARNj$n-+LXc_czZJ;9@_;z3q{pvr#@f`!YT}t>_?gvofZo+ zM_vjrC%Rgv@RXVP${2iwkiZ(x{&XkDOdhZA|Ir}UrZ{DVV19CG_p7<@#A@ABsw$k? zmlay{f#^|jy2YA@2ciipkc*7p&}HKMBpKOVr(~@cHCgJr^>y0)Wn8Ar*rLCEi3WBn zJ&@S(Us%wFs2~c}a+{X0!5^S)3+@_a{4VcLcQ%NnJb4C5)(rz$zW0kH#!i07ip>6$ z`_^sX64J+_E)psLfgU zZ~fueO@Qo@h@d3qyohjKWSk&xKlrTGcRzlUpkmf_Wk>W%uU3>~{;M-5Wg7;JZ6WDS zbsn=$fjzP1n|I-2TI$-RBPXS&KJ>0oR1t1+pEFdSa8BWRChWq>3vKlKn>?7kWY(Ym zgS3#xTPwYOv|W<7+S~H1s@bge1nb1O@WH=qVRWWYj$h&n(_TJ<8}ICu#iGb3q{6h7 z0(rB5#gq%aZo_C0Rk-NUx@NB~fi6xju$hTz=KunpnThmmN@qJzuNxLEGNd4v3&btIoD4qu#57wFQtwFfqE5z3 zSAOztyD@6q?Yc&@aH?1#kH^sAXZug@2kED~ztAjwc$YX@e0~qp_cfg#!cLtyHylsV z6h%6kuL5tY(u-yKGphK~T{)IYXv{-8jxI`bSsj8NgZ>=+RKOX@mKjh?Y`JwV8HMD+ zZvvzPo)3$xjWv8Mc@sLe!1V{W^Lp17yxOs0MG!iFr5d|M)cR8W`u#Ec^m6ZY- zUX3({II9_V53RMx*{tH5CG2weuwm@+?bLHYyONfc&JF&0Q9=RgS4iCbQqhY~_;sE-mNFm)4`JaC}C6H&07+;Z#~79l;hpyPZnQqX|JA zy<3`YCM>&6r}Y^>A-PUwBS0GF;lB5|so*yeivsFz$9W#^bnM++4nx*Fc61^&Y<`+0 zW6|Oi+P{;B_?5o!re9t?%1Yc->-l8}xxm-hb26Nj6g$n1e3-E2 zw6$)^IeAgW4<@oP{nU>ZNxAYv`;4QKwKeO74FxnVLhEm-n5yMYNxSfCAojj6l15

    9VNP!P}=#`C)4;z{B8&NvCJIf1?jD4 zXY+EQt;sGafyX!-O>;N{%G@QKiA|MR;f=>m=;`u4O>S8qauA((clr8}H&-n!h&`zx z5^3&=S!CL zPi|h}t1_1-zANB*SkC;k$EmU3ayM&urqbHE@oYPt{y{+Hq~NN31LbtFgWFvecXA!} z-tt8Pt48>o2WoMHkZ0WC&Awd&E0y5Jjj?t2CbOMZvX`z(<+b+tY{_Z4-)L^~9nz^# zX&ApGl0GHTTL6k5KcwZZ8!zxn!SaySbkRG^puwBI?w&_AX6f%4r=|{D`_1*p;G$ol z{yO^P2Ur}I`=#7R${8pPy)Q4r*h4GE2VYvMfu9)q zze^Wza0prO2kdP<+m?im${|eFS*7x1HdjRDA%)!A`BovnKV61E&Q?o4hO0fZ!7BT6 zgw6w2nAE&T zUXs&5*yHC&iUAe19py&QmAs}n6^o%ua4*-cD!=pQ#c^&CTUYa|^pXkAZg9VxV$L}u zJ|1eMx%J%+N>0GRb259v!JT`)N;MIyd3*Xu8~U+Q;4ih^swCAODQ)mBm*+*@n!YSw zT4jt-6N-sT&+0=_w$$Hzvd;T;0cX1g)J8MJ3_9XxI9}hat!JlnpiR@M*oGf1ntR^( z>i6%`EPGGorvcAfj*<{%ai2XQCXdP=?|eM<^1zJLJEHiM9a9*Xy~oKi==}4H*)9po zOK``IKe{rvsNgM=UvXM$Dy@`n!ev^1z4{L8g;}vmMb(HZ+BNx0%Q+?Sbu?}Bip5a>nxVIszTc03yx6rD0+CwpUK0Q!M5_W?pV} zReZ{8i@%|v4L)JiJxq!m4ZlWB7we5`45NvX&KL!67*O>xNOlztZxjxx;9FqPNo4L$ zyIHxBvSgK&B+hmPvv*=n1AOQVq=QtD>Q$R9u7HYwaI6%S8!eVr^Mo}@T}$#61% z9DdL~{r0rL@wsAU{|Bxk08^9No8{4(7SQTt$9gVre`U~*XGsxb*6t)BYRS=w_swK% zWPe+9V}7H9&0DM?6;tC_G)X5^^mXUvv|N;re_OnI{Q%yYu4T4IaPy7z6PC_Q!n@j@ z&yZxN#j!E;0E|5hilc&R@$Gu@qQn8)n|hr6K9ad@}-=F1YKfkpJH1g78ZVB zK9ZAhtoUPnhgV=gaiCw{YF<+yC!7+jBk15dRsy|bbH8Hf(a=_|SFFMakf&s6;@h0r zoAP$Y`ihhbNswmWHK^Yl^OcfnY$9Br-kWi=x8kSi z5gAnWh^&P+Rd1&0mn$K0D7Gh1{tnNXBDR|Df}VoDW3Eq1%f=MkC2KD4tZZqgIqNNj zng?4+X?(6wEA+6RACzyWL~L(4xINgCk(osCUy6VGQMfdSt7A=u*uLG;@m`vi8W=`- zgDc)m!KDKtrzyt;ogJUOP@;ET0oE|Fr>)-FQ6TTVk98|B$Ev-Y%;?^ZbkUk>%{`)` z@Uhi!In-k-*ze$8vHXmodcb^}HM(#5JMvY&61$si z&O2IzTYfRRfN6Qp@Pi-WmE0sG^rq>}_Z3(N=AKB8`O%{toN(S(Mdv~8vv<-eMTu_Q?~A zw(+BGp8wwdQJuv907~5oDg=s}u<<$Yhn{SBW~@xwQ|Rr#ZZc z=CEzMwHeUkDJi6vUpuwGL|+nBtB-6qTcWfyrgt4@<809`$04_JIn75-eiB_=4dvkE zJ?X*0JSUkVneRhl72oYbuy7-Je!rk$86d;;LrGUiJu9!*ciEXde=?6I^RyAn>Lt2R zaWQ6w*!O?HC)`*Osqg8^uWV2o(mb<|a^CHlY70H@jI@s7=PiD#yEm0>Q(lyk(-#t! z$u|Dn0Cj6{daQY_db5?t<@@PAS8)1yyXS=WAWI(^WGzAFU@BW|d3zH!T1emY=8bRD z*&(sZ4{R?8MTP!ZqYwjAB8zhE$?CQ!5*F&yR9k-QcsY;FdnPT*Vk|$+TUOS3@aBe> zY0QtF9NW!8fo{+`2dGsu8g=C z9_lqKW^Jx}7~lY|)Gyq_!l%;=M`12fC&@x}*HXj6m$Yg72AlT6fTMY-{z#wA-kfNf zdT(i^EHlyNw@T7R_wN9zAwZD`l2WtS$LvWwohpU+B3{)}RxS((>j;}R0hv!Z=>NL6 z0Ryo^^&I)Z&Q7sB;09HCITvSCQk9MYPgyskVJ^<@vj!Izr%m~ z=Kq)T>bx`<2$1vh^8?hT%xOo=SiwJ6-L}6rTH^@Ox;2t6`%UBHN06y3x~_K=0nUH* z4zvn=T-F~;clvd2T#7RP4diPmHjMh;?h(+kq@IXE>Co3uzIu7^QV4D&?ZRtfZO;zN zNcoOSdVoRdH+P8hw zHg_#@2K=5ybmgN35sdEhrRT)!XeSOq!+%u7hm48{N8s25vZXwb>)*eF5Gmcdb$lW~ zK41%}$8q+fV6O|lH|djhH>dkq+Px4>lOX?+KPQR6h9LXG9Qwgp8=d?>?O#~qF~Qyv z4b?^&*_nq>s+1Msuv?8|q~FEKo5qwHHkeZ1UYu>$1Pyt(!si?4)Sb6pS$&txoUGE> zhg}HWz493aqd`I27_6tTolRz_Sx=U+cMzDK2C+sS*gTNfhz+4%&neSRGF?97Dd*N@ z+Y!UOc(z!AgR6Dtu(K2Oc3hFSW`5!n@6p7`&@b1ryUV(#i%TLWHF%6OC%TYxl1i~? zneFjiOJs{BDzphc_IJzP`3=Qt?R(+OHwhX#&5B-?Zjn1PzN_;SD#PP8;tD+mo1+J$ z)dz)%6B+p03s*i&9I-d2R^bItAXfQez}_LySHc-d9XuW7B#Gyqbp&QOh4q$L_~Sp_ z^Ug2d;BwUXjU3_l7BM7Wx# z!naPyB*ne$3pKJrl1fdoTE^s8(bv>@$9Kh^?mm@AhP*uS zJ7!X0MQjD}M*XXm)YLlX`%|*(Hqj3EG&rK#`j+*szGY}9;)l&PsOEl7;$KfRV_`4k zY3TL_iT~DE9-NBVyr?7d_|KzCfJZfifG0`}x2kWR_ME8G-S7A=R7UncD^!_0oG|e8 zO!na|(>XyQi;5yHx@oPy-j)|dyY-*Mp2ydnWV#4lqKuzH=9B9Ta8lwN_DoUFE`6SJ zHFs|;XjOlXt6CmHk7ywSERUcTpcoh{QiS%*cGv4|I=AL2mAGg_2R&m zz`QT2(e1;HbN}iVfdJLn(Ai_Do`pe4vaH|`oZ9+t$RQ4a;S>KTz@m?C^L+oP!tWuf z{m}{DY%G%N|DLfBH0bxO$r(xXzpkH3@DUaM7nk@y&+%lI{l-wD=>JfYH2aG%^=qCBe{&V8S(iR%7jL}6!CtFcL$hq0 zU>u?W=WD>hhvh9l2N$O#{l)x0Uf~_g=-afQZjJ4RYgmvq9$7)ObGHDwFnHZuhWFL; zP%Gju_(eL&e+fRN{>wCPplzmM;UAh$OHYNf)POtDzu{?CqqE!(Q93q#v)8)ptI%%5 zv$mYV9WJ8A;e4-LOJA+v0r!Jq;sKgn|w;?Q9I7}Zl+I;h$}DxZNR0D>ZuxEPe(3Y*?p9P=-&fN={r32?k11ZyzE}*t$Yq9^%}`5K+lulTh%^w z6jz5UUb>T7YJqo7ruQ2aT*%o9w>ZS;|4W)w^SxppftGoY9Swx#Pj!L4J($!-|5}rz zv$kugDwXxmSnR6JL|E^2Q$+74*R-TDS_}vn5Bytmm0wfRICVE$Pt@9Nt*h>QI^VPL zTR61bjeB^1L^18Hk2l<<)coMQ7{JYMAlgtXP2{%Zh@J7dACVRF8dMd$Aii0Jj@GC3 za1RD3}}iAep^gaMmsX4g{ni=hIvD@=9NvE zc~1YpX0%YYcD4k@NtN$<+0t%uw4N=Y4ZcbsTPo`pBDx$26+1F^@w^~4b?|!Ws9<+( zGVrYJMEEv5NvN`mwN^YfcOJDC7@JAb!^)7~+lnp1ZF)}-j~q~m)ugKo&^#1&9)O85 zzZ^(dDl4Se*VZ8qmD7mx_<9W`@}LTFOFQyz6T5lovliQ>7Oq!eGBHkT-0W7e=XS)g z(G!*=M7KiCVsk6lVsiLMS+(G1g+YVpyiaALcR88%Cw_n#2I;5>QEDGY4D`;!quOky zdF(`zbkvZ+OSPvJasv$r4U}KfgLDGA@FS2kx;2t&$T7S6jR2V2oIY+c+X)!HmGe^) z&uN0>9@V&w4Yf~T-Dm3jHaaPjEUFmcNlnZvas_vDDY^3}*P)T}cZYU_-Y^4%$mxl1 zu2G`(wHWP)+FZ#`(!`ciwFjIRu`CsATiY$lit_qxKW7Nxb=~(b=mwSU6z|sWX^i~j z+NhU;f7V%@hvA47SSuUIR(>&c*`HVDhl`ML9EL8IwFxL1IBsrgqW28xwOnWYn}<^a zG9%ALUjrl|4Myu#|K?AIeHX8FL&buF;N*JYP(_|>kw%lrKZS^3xbJT}Z-dQb@c)-+t>2X2ED-TL;43#ujEm_Q;)EwEk_)Wj${uwOuV1rUv$QxW3|z1okem%j z#(rdUS&NgJOLY-YrGV1y-r0}bysBB(yJHgT8D2_aX6rhRD2){j{U&ILpn^`kS$+R1 zwG7*UA0Ej%u_)^`blt4!<9V$$-+CHH>SWd%*=rGs)^xVZmbfpi;XQ9k0Uu=Bkr#ID zxvEi7Br_>39xrryVepmGQ_6GVe@)se>p34Clb13rje~`N9O)DHVuKc3Wzco;0gx34 zhvv0V%Nta`uMBd*3sE69_23uQMDmpb@uIl)5faJ}LDKZ#)TPx$73$Zbpk~`tvU#T7$5YrE>X8O3&yZ|}=r2g!k%q?; zW*Q!gGj`Q`#Q7bZp@vCRcE5|&Ro}m>^AfZrXYn{4;JwADs%hzBn~wKMecqhsjmk_W zL~px3N56P8-P6j?mlkhkmw7Vh+Q~B>klLF?Nve_XKsZpic74sl(@@n1V1i0fs`vl@ZYR)w^!F&4;LEi zQiSQcMrl?Jmw233pq4Q9kF`iI-*{0W1x4=r9UNfC*t146J}AdXk}|E<+f#S3BBS1M z(>5;&dCO#6H@n^Wxzk7(qqoX2;E`mp{cR-i0;m751*^p$4Co2d{bGQ5px=9+{ ze8@`3cp(pm(!*9a&h*Su3I1cqI*PEn{K}1j&Di{!uQn)#{U7f>dBVMS4O@-3tBYrf z>lh4V#F#w6H{SCB_s@L?F&Q7I@{Z__DEw*@Hq!LvuQPZ5P)as^A8aWrN;0C57N9F~ zJ)ZX|mSO+y#@{kh>i4+OPnzF~4{!fJ!p=G>%C>9!C@KO1N=hq;G)PMg(hbtxIdpfZ zNDbxCjdXXn5<_=McXu*B-dY%ZRky%hm+%P=8@nmqQDT`V&nUF!bO zlGOBA6O)WhFx3gjo$9%>F}=b%)Xfeot9t0ja;X!5lOt4?r$i9 z?nTF+hj@8iOTf)hA$zpG1*9L{ggTUW*8H^cE|$zyTW;bZU8RXiU3top8J;xEmnugF z#CoLx@moqECfmOkJ`Zf0RQehp8iu8gsdknN%cbH@0{Kfdltgbr#YK+oB&<}ZtEl?g zDY?w1tc`n@GE?3D(RyE;o|^#!|LI3#IWiFIQ5 z(=x6B%Scm#$PwBuuiMXLDdp^*`yE&1h)u*$IO(~sw+z0t*SBvL5<4NeST^wE5P!#o z*YNS6uMq=l)}U*Gn1p1S!~8N9O7}6SZdj@}LjK*k9JzMaw`Zq#6Ty3L#cjRwR>UXay>%1aHfFaAb;c8S5(VwV;~Q?DY%lS1b~cCIz* zyJt7nI(>A5kgxKX2~af-MLuKh*pql3wAHVc!Nm0AzIt`5Aby^BA+qaRF!_*rh1#N{ z*?5tT9-I?H3zKy9?f$m#aU|}@W<9mKyKdX>N{8*~HPXGbuPKy_D4N;a_1?j^9+Z0C z^bJM4#b<6sdUeMG6I}I#i`r)N>wbfxXy9P%KE^Mze z&rex*D>2KZR5~3;pi;{hW(DAS(q^ZwBPX}hzGPk9WyEfaam-!6lE3yzmOQi@r=;*0 z>;C!;FJH?nbZgA^&nb?XPlYiYhHNIMTR7Ffb5NqzI_}z5MupMdzw0jPLMoXvr5Tu=w3?^wKA92hhx!=!5{*nx; ztNv{9r&gzOj586Z)z!ob)meY# zDy&%oE0r_p2@;dx7CXBWB?OgeLmzPIlvs>?12WVV_Y7t#8?pIA1NW4HVaC_`>kZ%M zZ!pQGYu%5fNjugcSs(c9K{gMJXotc>j0fBN>674` zqQ33HeK5+GS@oW`M|k*F3ehS()|ys9u`+A)QlCV4LE7#USV=Mma?!5(V?>*}tE7_! zg|{QV?mezrvM9A{R4`x0(n9N@n!&3RvX>M#Us_l5RWma6mBaVmrgZk%9t zFvrpFmX=`EHIfR@N$=6z!Dd%>xXD^3PL_#j8ofSzjob0B-5~Hy(M6m-ippC*xo~s$ zs)D)}s(Kxr?8sUz)sV6(iC(R?2e$W(qqtHBWi@X}tf)OJLfA+3=<}Zc#yBo%)%x=H z#!U4s&s!FVsc#;WH}x3(X1osJ_G&ouO1^7cAI@pE`jO!CLDjA?wHRE9gIU5|=BL`* zfU8m7>@`!hN`UjutNLR-A2AlvL56XBr;2)+3Y7S@GS`_R^z1i(Uzld#P%=zFv-5>t21G%-`yzi=eu z+9dE?gw=^m;I%j86d9U*I~q|!$a`Th=fP zHoN{O?kco>VqwW`oB<23YUEcoeGNUxS&{14ysEeQA`S4n{1^+~oRln2u2#u0d2VLg zGbe&#Nmjhk9(li)Iiy?+_*88(nD_Sb{J?Q>X>-#G&1ZLPs#8?Y>4>9${Qy_gav`SMuCb_An4C# z%Yv}s#y#oXhFf82Uf0#sO)BD66uvI-(P>4|h58-s&wCVGOjh=ar=qQQj}{fUwKfS| zm7}(64rs7%k8mRTZs^v#)B>FL|J3jL3FneE`Ch*x^Cff>dd%xsBW@VX>)&!BvK-Ncu&c*G#OfbCxETbI3%bb9Wp?MOQtQGzzzJX$?) zsz=;=7&El61$A6&6g^AkOfP*NVjgiE-WHX+tz`_@bziJ|J&&UkrIKvH5-Dfu9DV9^ zKrf!4xU)m+w~gfEqZFXMz-s#Y{wifzv8FOC-Szu^6k*?xCTTYol1;y6eCM&gw6XRB zA>kp1;U#ME@yORwt%ZDyOB<8Y>l-CXQ-gW?+}4Kalz|4`@aBBX7+J&`!SKl5D~z+; zDr_%JzT?(vOOUs-{$}h7ned|lit7%Ud(+cIaBm}bwAR%sIxuC(ko!>Sg#GO9$}J7@ zY>r!2R#iM|A5&#cWDjaZTl^X8E$&n1aEF47cgaEHDDI4E`wJ)gX#4muOs|FK18aPz zR@L|Aa{AVU;llT6c}ru6bvyy$n!pR}*;L#2BAOmgL5yh;H`ePYnJCWb7*SYnXAnW4 zh}QG%#PaO`wbQaW{FIaPBW0-7FFzK7BWgWkS}~IU3t|`kqVs`N5phT!XWXm78bP5znLa2%0Iq4X4T!;8-F-yIPh{s=bzixzajcdLrdLA+ww+A?1r- z3@gugK*^=D>J+LnDj;jGZ8e1tRq{%l2hCq>>!S>T%vyYmJIwMU#~q1M#Qj9y0%^zB zMOw9k#a-a9=-Fhmon4&%fx*0XK!W!RcP&}&Q>Li;^;3A4M%!jj>b}$*8{nx$s^fJ_ z#{cu)u`k&bA9l!3tEbY%RK(kCa$MJyV-s7t9Gc9Y9P#@h*NaZaJvzD_%%?24GtL-d z*2JpVQV_1AemTyIj#Y;K(NZK-`-5$rFc&|N9jg=8PsWda`*RG(7G&L2B5N-=-7Cp& z#|XeVK7sA_A5Qg)beSa<8|&3Pf)3?j_5Md%bDJ#H(|bqn$0ru@uLNf3dbqsERq83> z!X;RphexA`22>m$2nl}^K72S#-B;(`$!Sus?A4tbw4%#wo*bL@smYgY8Opz&SFWXQ z{*~gee29(9P$Q`aJG#Dr8|P1j)8k^ElatXd{lA%P=GrV#BLcElU`eUjkFrqN#jAxs z{*n$Umz-I_ZKK0`ht@I#gqxC@A64t2R-PYC(%VNlo6IhDq#ocJpE}EUM@M_yD1Igm z@mKGhIFXXKzR|m|Eb+347r24ztEz~BLpqE%!^R*x*fCCDGH5kCMiEZ5j4I^DSvnHC z;~bEkP_5fEaUoHI&Pcz4J4I?J749>}Xc+T*w#=~>{jd7|8C#AsVj>2>w=u0;-Bs;e ztEA1tzoxzoqupO#R+#O&-1p;Ebf}2IQ0C-R&_A2W#R z;|BKhNC^urtaPq6LP#W~XP8B?ptW?ypPh2E?gq^#ACj7MZBR}|1c^rNZwzMx7X^~&AqWaHE6**Qspso>v6Gk&ZOAILpj+x0Lv(5*YkB0 zez;D&lX1HHP)dvO9)&0}&aOMIo2(I6c8gME*)zIwuxU)M zFcGY{CwEXp-s!k6uN;pOFvzfoh!(9gypy#FF~m^D?a#Ijk|#bPuRrm9mQXqZN{={N zXFv@7sB*hgFRZFQ9_=e)(1b+9O*Puj2;C7i>Z;QhXbcM;rXO~Wr6+PgwoOEYJIt7&Mb zI(}vEFr*V$qOi?CmT58iJn&bO1{!4PjG z_(yZ0PQ@pqe5bh@9I#RHxtt|kK?h?ujEq?Dr7XR?`-HmFNt_aae$9M@Ns5 zLRhn_!1jaIV=K#jh&#n8IfsvL14VAm{i>w8Gz%tSA?b4BE24)6<~ZQuaxO+6Mm+}_ z#>=*uJ8bl&j0Vn`Ry)~5^~_M6Wtv)_;3gBRw?&i@S+=19xDzUbi)AmRLRVOIKWkun zer+O#4sU2^Q4-_8T!m)R@2Kd?ZB)ytfRkK$2i!%VVge{@n)f5t@WRC#JEJI86)sn@ zS11o(VGIk9>gcCB64Vq~OY!q(2E!CI7y>>UOXIPc-~M1{vAO+(GvfK0bxQykeWyOP z<>=XQ9b5EheWRF?e4M}}WufkG@cPE{rg4Y&ya>(P*z1hS-QSAlk6TnMJ={X1h2dF)*0^Z2HT13U{yMP&N0N+Yw@o=4UHIpSeyX62ihs6jM z^qBb8;cE3cO1Jrk5teyTB z^XIj`-!F9%s;%Dsv)X=w#?G%+u`3GN*ynVAL>1Mf_^Tm{?b(dY*jXTIDy0*r!iY#X zPxq!PGpZN>VH=0`DOy>-X646!ZX~f?mMj3^q!wtr>W61WgUpfunAM59^vdu5JOV@4 zq{(3E)?8x}+u5s@_vf0y6ygeBI*H3)pki7-cyX4Vk$}f6#`11{Vy^a*o6@HL^$*QO z&O;}^j&lg4y15R)41M);7WodpN39owYoRaR7pfHioWw%#bB{iB83^g|_f4L7#S8eA8< z8}YZu86YJ7oDZVAol$sbkSz)B^7gU{;zI~dX4MC|hjnZYIuDI?-2N|nQRlxWt@u9! zBLCmu`yWO9*aIl226zS{C2hyRi=J?Ce!i}xLw63#r_3jgQshc*Xt>!acARMPvV>0% zj2%c2xjf2S3(h0h%T+COG=an6zyxwO-vdy4Wso<2`#h`LPX>9AC5)n% zvqYy@%`NQJz6BQK`4S$I6f`xpL@|G>NUzpro`}QZv!t%>!ujr0p-Le>Kt;pGZYvbz zHV{Cb%UM}nEfmQTjRwbwX-Z$T*6kmPQW#0LHg<(=UuSpMRYw@P5-ct!IL~^7DvPax_H9tOD*{ERh{V-+=dTH;JJY6ggvEms}AEY~6nz z>rFBw9OLjhg^mimhnYbfh^dAmc0Szabt}IMQ@xyS*`;Vdw~FOx3=8MiWOyYiraYZv zTAVzl1xjEwTxzzmJ=^12X$@B8eJ`Ec!&m3F;>Qmz9h4rF*1aCBgL{%{M^e)Hgk?+3 ze{}9xBUd4U7E=J+oN=J|lAN3z8kZG9z-$w}KV2zatQw+72uT0zA>CSn3T;x&DZH+b zQC_W{yZ+;5*&zz%N_zpvsz5H=1*;3WnBa{zE###yye7$$<$YQry^%ME9yaZilnA<}|IEo$ak5Zxx7}OCQ5X)HZ7wzL z6^N5l0(a-Z6JT6a-vkePE8kqn!{K$LmF82vHRjt@bvjUfsHDwIZEz5RjwL3e4xcSS zg>vV2MMmUTkZMJSDb~smb6MF}bgOg_$*#X+PPrZDB|b-qkW@`^Up^z8s7|KC2b&lh z$Ls7(0#%EEh0u9_hJ%^;us4Q2Lpg$Oi~$&}ii)E^9r*blqX>Q~bTqUIuIDsZnw}Fc z-bfvoF)=dAX350Vr`4aGo!#DgNolv*T!$4hG@DQ;O>e0@AmAp8D?o`z1%K~K=bnJ5 zR3r~qIN9RBAKeLtvb##sO{JCL&gvvN-+uI9huDfI=R1pzr8^f})_l4Zi$}T9Ex{CE zsJ})udx46rylmcSe_WDUivXyht69h6h0n$Spm_vZ)hKLk4r`5XehvDGL{96rlpE~p z#nW9*HBECm4nr>BgXaI>NbKcxwdw*JF_=W22a~jJ93{q44iIzfZOjRj0myJmg6E#@ z?kc6aI>u*ttOFFRv2#uCY#%@V8Fm{3Ub;vOZr3*3RdegT)AZ+#*aMX2Y_;67>Go8PTUsNs zH6$j7pRk85VfQ_e2Oh?qAEeFQ;Rbcri~WL(EX9md`h=Ro(zn%^&<0=K=B>twhXi?R zTN;6udQ!E<_tn;Zfdk&#MI0Wj24uC3-zJBAi>1WPKT_|+2Eqwg1_1v|22WGPd-p?X zmgYS)*4W|(`!$5F-#vh4T;D!Ut@JHj_>Eee&jT|?R5o2X@X zj_&waQmYHf5Yyp~t2n0o6S7PSxmIZc?li?E0O|p&rDpGiHEI%wGwr!t_RoTq2ld2Ab25*DJo(! zzm49Qc$k3z@TAh#uf7-^BX)v;zCMg|40AYu`;e5D&djfRNvFV+7WcAUNVQbg`}WFS z*b;E za_P;nhnQ1?w=T94mpoRSv{*_C6FzGLcj-Dq^{teT7>ae;f~nJ|gXr3!@K;pt83qia z-37B_d1_zO4nI!^@z~DQ4Kcf>-tNy>3wR&-j=~5jb8PTgpzla;_fCy;1g_i%P(~(j zHt%m5*&=bdT`nQMuFxzd+mg9v$D$zZ`sCtrO2gIcE`r-C_w_9N;J#LZb(1SZqY;*O zH8c28GcR{;!~_xR<>vSKT~K&QwdaCkNL025R%=?B{zny0hu?$W=b4ihe$Y72uf0;j zvE)A=kx%0CVrxmUSgy0zqarr^8cAFl9reL;oI00RezuIwp#A>(X6>_bTpWNes-sGz z#% z4B^mtj3(>yxXcj{c*tIRv)*hhx$9^gFXiPZmiD;%KR;FMoi7r&7$I`S9}1H#=f=HXzegUw2_q3i2wPK$Ag zHCbTRMm=OHqCdU3;B-1C<8jJ+z#Ix~RZo=;`7mZ02Y;<5Z5t5-Fo^k99`Q7R!wReyTlhbIj4x#Yx-c9KDw50r06@CK(QI_QQJY*>2xd(p zhvn$#7OB%Y@uS+5v0V9m*||yw{~q_1nQBX1Q-v~7RE2k$7J$=wn1SN(v1{+gVwiJi zoaEv4rj~HoME>zhsn78-ktQG>9qtg0YkN&`Sl)Fx=j-=0*AwOoaNO}~+lc1PGe)ce z$6K~y?<~nDZ%ts#I-DoFQ=$fTPVD4O*=a0!-dT=~6*JG`uF5kFzIxxH#SKa%(4TBD z^czO?f47axpOH)C@X_ys2`*nY-);l)L1XJ|D#iOLUyD)c%YdgG#2+1u3ARtlm8yI# zo{Sd?zDkOaPx*r6LT=^P-%QL^IGy1UfD$MQLR@5Zb$(}k;pQINlFw-VYd7-{9jgH6 zrOVTQvZ)t6PLG*Rh;my6Kr+>CV}jnl z3=LKpk1?L_@*&P2ooDrvhQ#HbrI6i-^y$xhiPIzcTxVjG(e$Wg@99+D5a+Khb}iPH z{o_4LKgw@J;^97tEA0baTQW`#H<7rD%lAH>Zk{vosm#q>`Pq3EOT@!wY|ap7i`v&rlzK1VgUJq7Y!YqHgBMh&B>FkX3q@Gk_MKc zCP-7HfLXY?o8f?vVvM!R-g{~2=C`G@#QRx84j^pM{#p?pHh+t&tU!wPDE|at5()cP z$w#$B=3!QDjtGX0=9<3~$XxuFO~uKG`~7v89=A`2!n93*cP zS1aw*P?ts<*m*- zLYCTvOv)*7?e~x0Ks5)z3z2yBrL@#G1fNkPpG<|*61O~PuoM{uGZX@uskJ3f;n@Bz zwP{O-8@2w~Pc9FDEK@K`0(+Z{O)zvS(~(i&aX3{{EK|$}vr`LEji_o5mgU}(xUhIWfURQtW)^~Jm2k&;0Fo<&q7hltVYooA`K#{*UQlG1)r^^>} zb4&_1pXn1!>0-LFo;tw8(ImZH^Jm5^XxBW8&iZ<2`=^;r@cwFP`J|TZDaX&N!=J}j zJxw{bELmV3G2bR@y|!LSMyx^d`}%Z_l3QSl932^%!G{jO@e(PJgwnrEqs9YXXG>CD zs;4L@ND_w9gLU5;ps{ z3S6cY#|pUQKkNrMB@hO%g?JxmQJ5fAwfW%C&xD)WkesN@)3Xu0P8B|bUnN@F2tM-j zele#`@)*{s0h|#PJ4a5dzG>47+au;#o+tT4D)@w!UJaoMgrqI5gG-22kaja1(DE-z zZf;Yili0FR28<@CEOw^#%kVd>wY#H;)F&kOD^HF+Bp+I8Jf|H*lVWW#Aj_EVa!DjO z>)Tz77dP7{1p482=Z_|0#@Ti^nkqkV+`%n1$K-?B z8Lhnnj(sa8Jp^E!$2(7FUz5#11}9zTou>d2u1L#6wgK2)+V*@!Mxo(c0Yjc`Rq0fk z%7T7u4W|n?-JWfaIa%aZf>Na1O+0d{-Y#_y4sP7ZD(?fxCIbV5s+R?6F)=1L`D)Xe z!f&5ry#aha61%Jn$wDluDwus&k@-H`%)=~li$iDF=7BWr1T&sh?T!u(Kr}N%Nez+R zt}iPaE)waP!KB6VXbgcs5VvC&^eti9cVd8jo)U`RDX*Clh%ksmfPI(S7EcIl2JTJt z5Dmz1Nr1g(c}sm~TwR~~P_uR@B|O_Q+dLgbp+pBPC89aX*RPIA{~%qcO@A)@`P)dm zm!M+AC_su_)t^%>IPnhq+Lo;`Om%qaX=`V}T1y)yDT+;;Q1;LF*o{}=F&z?ml_PV5 z>+9RccTr(PQ%tKAyovGAcjs6|MSN<;7tcqnJjD(fHVI4Xo9+vF!W8SDc z&qQVp@`q`&#mD5&FY#0@w*tq#URy(oj;e~QaoRb=g;Dd(9M@iJu17~nvJ-QoQK$H# z+@Y7jaovO8;dI>BMbd!pn+fsc`o>Ov`}>Ycg+$Y7R=88b+5Xw`qa@RCFRO92scRV% zqhZGE_P2Kd-d-CkUuVT_?gTCb=?rwmI z#B89&`(|Tv^VA_mN|Z`LK>?sTuE%V11JQHD(p!MCozA0-00{6(RU#buKVrv8kTMr`tDM=#si=RV&qf^yrZ(Rqs{*!vNC+6|djIPpf3Y zQRF9wIfungEV1a9!jNdNBJ_OVR6IPIYgS9V`)e&~nxDsJa-?0Bc}F7em}3!?V|NE+TsgaO6swbp6_EEu(v=sKV}2Bm z0S4a;Ls_VKk%PH%pHaYI>E&-*a$d)uwZxwfQ%Clz2QpU?Zarr_QUu&Sw{CKBn4;8F zhkJJWGeCQl>ySZz>si%~oMDXwRbUQfePaiOXcMS8UsQ_XwF)EIP#zy2>&k=R#vwNC}5rQAfA=XzJ+TUUb!0*Nnvv4VMb(bFfpgj9$gtsH2=F5jwC3zs623EtMtJ z3JTFtdi+{IO* zvkz5$R7s8&zCZPa?kG{E?bw9Pb@Tf;+F3VG&GOhKNUEP4WMX>%UImO!FTN2gubO<0 z{^G2!vCeT?YfMc$*ljh19iO-`fjoU8B)=bzX5H?le{sWUAMQ$165*N?Z7^b*s#v$$n|FaJzv=Dx95z z%PBVkykH?G=`J4gzOQn%PQ9A~wtJhKYCtfai07HzES;pXHDNv9Fmbdx0D#BWbfWM| zM=#mboL!!Onjj!2Ka|L-K3#7V&H1i}xt`M8M#-2GxRxGK6cP3LE>Hntyj&`UzFjCdB?&5P+h%>JKHbjaq zgu6H|-VzH?kC5o%DWR$*nsJ4bnqEu{llj#%6k)Lf1lwbVa`gWx6F#ulG^iZ#k)9H1 z-{H7roL4v5e1d-Ybn`C2&@T4zUmXb$!;D3|wh_%tYzkCN5(?LMD(IJ5Y5^L(?0@lK zcF36FLCm61Rkgg4Sg)WSRluVGe0v=gbuGBLX=7)w5*`^i{wuB1PR()swKR3gm8(+h z2Y=3DspaDuS%J)F2jX0fVL(0fCx3lwP282BWHwxd?zNtS*LniKGQ}$`Rt}Dp4gGJE z0zqCXJ0F0%2z)JVJHt1<_=oy$ zuFony21I|gwqJ|}fA7ne!jGe#A8kZkQZ=iDM8CV$qUB%ojd-O}-A}b#=bvSaZFlnR z98J9cB8Z%uLXRi#Fk5F2nxNVTgHSt>xCpTM*#m!TbDa_cw4agx9Uq zvj3i;3989`lVTnN@X*>GYN|`69E>R*#=gFQI7P9}rh{v0pUF@`lTjS{pjp0qVw}>& z*7{>^#<;wb4y)L|5`EzdNI9(eLoAsbMvZzc>7l%r$vn3L%oA1P@NE(go!kuZY$@fT z4KI)Uh-W&z459wD~E0v*jY4}WWiy~Sj*_=gQDUk`-i3oV(dF|hg($P%fnzP>~w9$si7g;2e|zFZR!cXQW*W4^--CV$R-4mlMp_GN9DzrYDm8eV(f zw~WP<1wU#NN^xSb2*3nNH!7%e1F6>X&Q9>Gc~7)qQu?hFP;P&D149B1cf+-C^4DbK zujFJbmN+%@VPg~y)~g5WRs07PKLftJw zB{9CM4%=Gdm<_dxr)uXND}kMPjyC-26%3AMz68G1(F)Y{V#O4Ir*otELC~iNY+4tA0>5tRT*wmh#5vq#>qR=rp&S7q@kXH#Cj=26w7wMHd&Vvegs5$gb2#5Ovv z5#*%!UlK#oVpM-I%czko+^Lz)nHq5b=l9v}2>4?Vik8S)I-OMN{cQ!=o#zAX1gVSw z2L3AAOPpPyA_q=6f(?6sq%xP62c1f-vxVJ7k~%M*bQnBU~3K9{Rg} zz6$+Y0&j=+?`I5f7yeyDvHzEI1nqzQELBfY3@lJ%lbd{J6EX4Y(}zWU=|%DS|6P>- zVKn2XMbAQ$nOg3>>wWg3^3=O9Ct58w&sjz~KJU(OxBps+_YfSZo2^4U4*Rj1h0S)9 z_p0du1R&y9fC8HuIjD5<;~mhvi#e@m0KGUJDdhe({O#}MDFAkf1S}0FmVEj3JDJ;D z^198yYa8vPDM=UW)T!743pb_v*FSS|wVj(r=DEiLt^6&lr(-bhpOae0JKpa1_&qec zN{u68of27e0d3OKd?xY19PtyaVd2UK`WUGWP};6)CAd4ltsiuLj^N^2qC+^I62a@$ zwTi0q6Ce-I=2h~(}tN*!Fv7$jejmvkO1Wfe*zzP)>`8=T=PHK0k_|Tu_AC1xV?4?&m(l{3Z@&b!}Lp&ffl?sS6AQt{Y6DYj`B@k zjKr|^QvjZ(f;S;)phc3w)Fu{w`o%VWy}2(Zkrsg01UUP<%jF*mq`RMIwgF#Gb6~UP zRaM@q8RrLSnJE6xr`Uj4{1ND?x;>U_yTA@UsCW*CXHge>4^0H8SUeh$0R5HLA zYA1imnJ<`TO0jC?QVWIx<0{j)#e;=6t>swZ$J$$W?WP#{b-{(Fl*san`$?oTXQ}BC zXAhYqQB5ENq0`_529n!pYQY;+8E>T@0VW-lADxHpWVUHP&F1$w9TGfQJG5SZMq4V0 zCO3&$%n_v!YTD#eX3opOYIRoqDpmy^cn)Y%;5d zXOU+}^J@iQ;-GwViwo3c^a7FMl8`JFPFkRIXzJEAmF3zFG(>-N*^6K1=Hv6~k7u!} zaIU*}2|W6_$kofS4E^2NE+JmdqHL%WNH>+A2nFG4S9m0bVUFFYp5}|-j;Qi7IU!N~ z_uY$Jh2n4j$(kw1^-HrR=4U5IupDL2_h;5VOtV+YXL%q(sm(?gWAl|rxIMm5Y zTk=u(A}FV!!qL)=&E+ZFfPdtd^>-l}le$kMem#qABkp{bw>WuLR_LHO0B&r6*S&U$&qKIW{Ap6y+E(Gc8`nfBfTuVuJ{WR?lDtJT;JxAiIDP)|hl0wH}|T$`d!;dT@=W=PLh7B{B* z4A`a)e%NaU9Cno!N#ltI9NwMnJ1&Jbk5(vHS>%92aCuRJN?Wg)C#@9H-c{NVsOqkG zR!)yT*ZQd*w2kVQsq&immw9;;MvoI?Zva*M`vK`3=i}nYT5esRu%aBpFc=|*KhA1c zYgw1)%-HTD%MtGVU%Vf}nnb9grzOZdG zd~rS*3isokhOpG~O zzeR4QuxwKoggrKhFCG=&LZqpKU#skKBF-;~C67CKm`rc(ijHd4!5a)?n9onMsfNfu zQr=o3NIkUDitj?x=1oRR{qgfWQhgB>vXLF5*Vei6j+rK?iVQLG7R)9G0#kv$miN~Q z>qDmzZZo0#8Am!`NvjOLke*Z)_pdKf?rUUs--cyP^yuAfdwtm1bJB$$O^wn_oi}~K z`R;$IUXwy@C0@%IvCXxOFpE8mjPR%T#J&KH)i(1<8rbd`ZtK7$f;2d#MDSv>YlDyl=c*554qdRppA`4bsv@2k`Uh)~C{!HXJ@tHe$D~6)nsER8|$3=?9S)HOtVe z|FO7j4>b+$mNYCPp51h4s~81gSRo`H^zmH-7#(=%w_qn6CQD}2#R%+eJDA7~+?m6}chlf~{e(wKw0Fk9 zXj|d~liozGrPJc;a;EwuRvHh%!od+a4oBwTkOf{IF$f- z5yCmTBcLuO&uZ(NZ&~QY2V&rQt{$$(t&GF_+H-fRIMWKCnmt*qq6=kx|KYAdn`eFV zjrZK8xy|lo`8P>ng_-(hPJgKlMHNH+Fo&ouVZAJw&+*kCwUeb+UaWqLN%{>FM~963 zKBF=E@`2ZNC*k7o6P^f=X7V0VSnw5x1CJ~F`(4i&tf#%l+Hk$B-0j^~9CIlXLvm@~ zux!sWqmf6n!9GW;4U<&uhuxg2a$pqPvj3jOqUY z(|n!V`Amqm1Rr-x%T3$ON}wf=YI#4(k%(gw%)a5m6MLZU{@HKS$`^(AsfQEx@%XiWh!ZOw%8Qo z89+wm;c_+$3*>9{=umeDpDx<@d&P8#X-h)z8S2e?!*6)ixvh%GQ1_BP8Gei)QxDP1 zcqjBy*wv-=J7QMq7FB%|;e1CIS{Wba@A~DobM*G~_qATvAE-Tx14rj#;t8|Ik_&D0 zMZmHWh3bURV$KA}G_j**am}`1PaYYGOYqTTKv)tTe?JA8z}?vxU`l-NfENO?ukz@1 z0vZvEVB{%hNN0>UN-3rgDi#$Vlg|y7aJ6V<89Os0WQYDIIBRUgzVBrK^Q?Fx)n?w( zR9g5|SsW^Uld2OfPofqy*qeDf(=vlf|!-+1c){E4K1jYY^w>BqFzT}pKA5idEnN)>- zw0BCfHFd~VXZ9xbmqn8Zco~CsSlXk)6by|GDh3j_pVt$-uYnj7wU->s4WjU|E@5ZY z@whRU>$^uxm}MUaR{8W9VO1PjiRq@xdZYa(BK3n#f~(K=WodI_t1Le?`;TDU-)>Ik zirbz@YL(!Xz)yRjr&GMz18$)15Q12_K*4k%kX;HV39Sk*%$@`($_wOwP1_97LB0{c zD(3ZBZxHj?9@@K)Itl!)oaQrjBjz(QsI(1WD*h)jeT70sZcRH z#55+{ADF{H8MK`SdLyYH2r{4(V>ADYyA07(c%!S1SlFPP@F(Zi@Sy5 zgBMM43sBq%1P|^S+;uONnfbom{b%>t=h?sRa|6je=bn4cJ@5PegvaF^{r6^jn99dh z?!lVOqd_CoAEjEKB_Z1HiNy$$%rxqPWaNU-Kd2XPr9<|pHr!KU+eR`EH5n_CLEo?h zhyB;z3x++|(5(Vc4~C6C{@2Nc$_04na%GJ70H~OHo*~U_O%2jwh})*sVybs@PFhSt z>e^KlL<2-t(*$a`;c&^CsY{39Z04wnI`yp{C#qR*6R~*EH|R~kre*vC(=OGvtTf7W zyXn}nQpk{oLl*Bx5}A_!2^!kEa9y|K-ka?&csN#?HB!NoHII%o$7EzR^JQ`q zmgioOz9t3CK)!gfc$~PGO-BOv#P^fWju;?krtAvFD2e9BJ=<276%_4qmaZhtRe zjBD)d?g0Ao->@Mft-8a!1^@}hx9~f$1D+$1{wrVxbO8%>%-eqwIe*j^-siqf&`^h8 zMKeOD(P=pg<8h^X_pY+3UkT<)bU#q16Hun@g(^iz+TNH`{jx{WpgzswOFr#@D$t}5|MsW;IA87De0gfRpXG9brFV^uW{ECiQq_2Uk30|>k zoE&@2q6nt7NrK`1!7t3*85J=i7V0Nfs05WQYXLu?C^6N14S(PJ_kD+ z>R_3dz{5&C%eqcz>#;DypV}PPHgIBt!3>X(TXps#)3|bMHqK5MAMSA5(nf<2(%l6^ zaaYVqr(Hx@J?*(}haL&<- z{r(o1i-aPkoNdg}tJDG>W4=UCUUbjiF~75i(%R%>J>^4@ZWfOr{-9Krpnkj3zn1$@ z>*|G|zkobDvWP9IlwKhSl`drIc^|8f$TPa73nbZ3#CT&^TxwG@0^nSiUu23~mkEeFOr%3jCcNh4`is_-9_2F!CVlROFJDZ=dr=ufM&? z8-4MNn~;{3;&ieFA1`~k2H!mIrBR>MP{0eV8z0A00oxrKJOzx9vGQDtG-ZHkK8rMn z4M`+?@rOqYqW4dBX*tU|b4hb@PzxWKXzfQ`3V_~rkI{pbdGg4`eOYcUZ60z8g0ysS zW)RG^I>`o@;?uvxtCI=zaJgsjWx-*z@}50i4v%rh)3G`>;QfSM=%~Me)sBG*)`NNe zegYD93a&-n0d{x;lOy)9?{Zv}67~JxNM{Tl@ym~UqAkxFVcx`laci9OElLUfBRu`Bdo0q-ik{AAq)YP(>c&#jo~H7T3Wss*^nLRbD5+bLmi?9;0oil1MZSuTK`|FsnY*13rJx;;6A2 z_@?Ze8%Q`C5Wmhot9E`wTflRkxg z^>&%Cx^OpChU}j;Cx>c!VPlO2>o3Dj4rW#N2l(tQe7qgvcRj}Z*>6der00Fcd94i= zvI(KKl2K4O1GhVS04!Ektdi_fZ13`ufJmn-v*U3P*&vTvtfE{rO+LXK3995>gb|*+ ztVPorxwpuDN(Tl;s7#6ZyL$p=W@_jZ?#TW7@gxnH$>&B$Gm}^qwY__cE3eE-v>*5Z zPfYDS-UL6@AP_Lm0tM?EX^daI8wgKl=C%F`JTw@Ba!dM=+IxbIVwFx6T^+yO(E3|q zbwYZ!>jP4gP3q*tPb8JIk48v7UB+ye$`sXpO%e6BU({la6O~w6Q$*X`bPmde;A>K| z2L|>ziL|i9s4W%90L2Gcox@j&UFTyN7d2hr7I%wV@8Y=vlUDk+6ZuxO<#E2UaJxRW ztbs^$N|=4wJ|iN-FkrK44jeW4 zM7G>IMSRT^ju;RIvBq^8 zDx`KCl_%ve)g1Pw+l_kt#(tF99CVwwUL$k_>Q1xJdVQ#tm_j(S`9N4xYuGTk095t( zS_eIAxAUyLTs0A<>A(grBN7!j*BbojQbi3-*31|gnw4V5K_UH`e&@+twh+Lv=1btj z>iUs(b`B8Yq}p*b`4$5W1VMUaOH~{jrb!Ga4rgDRPhe<#P=;3@+wlOc2bNLOsjBZY zy#Y6TXi_IG21Vj18a;(Io;=$1cC+J#cy*5#D&*b;#^Jy(u#eCxMi5_{kY)|3Q>!K+ zmgl6TD5IiPVR$sq=aM!%e-m+reE2P?l5Ns>y^1&-L1kDE7wSpmF=%dqBMmg?&u4H& zo9Ie91Qo=xwulhF0W z=qC=!-s0=r&!GmRp=X^nYujhA=!iq0k3<3aPk69JW`?w zM)R4H;4v)NPy3^6)q+VTrS?(Mac{}dA@H7`oW6MqYOt4r=R(WN9%RNBSiV(5YZk_{ zJvwG`{1}su$6=#hRD`&{K8ic!SP|{Ll@QMCR1uB8$d8jN1Yn+ptwx@O7xza~Pc(Wi z1l~R6Y`XrGiZ?%Wi*T2bCMdERe^jruYamBmZs2`KxR9uY&J-=j5Y_wYtC~c_V9gPq z@a1OXs15R%m;J*S1&nIy1La*DubKX?S<}QukCT-wyHay#w~FPRJEJsp?~?)-d=psD zu;340)R?X^+P+MW?I$477i2Gi`o`m~>u>#m%yG7h1vF(P?XOpgMEV`-fwH{crkvED zOttOR=fkpeswe?%4V;l&-Ea*(!o=~+X0nobQ}NWV1zD8cYG(a8OkQcC3bT9~SKBsv z2F-K_Pd!m+idmBiw`JkdF#R2_s-^bE3{udPxI4kEAfoU>{i z<_~cp>)par@N=UlZ$Y=7-vkwW^vTX*#yzjwwPC-l~?aTDD_ zl&wRaWf{0F0}{_^eG0W>|EdN}-6j;~eXvK>S9__uTXI60X)b}_f_6zd<+Z}tXL>)F~CR4s4i&u)Qh_eNmFennM~?nBKx5Oz2$?e>+p z%}>SZuL_o!$^-{eA{pgR>1j)frAT_d?3WAn?DJGr*}PG8eFL7xeuF970BWKl_%jT3 z1E=DFnqs_$#fPUNJkq&r=$yf`<8P(NpazI5MFl*UWm99ow61;2Lja-j-Sn-seeJ`k#P5S94Di41Rf1{lcy6#oE$J-{4enW(+Lx zeFu(QtfS<21I1VM3}`##;j3>qS?;drV5^R$$DC-<$cLp%5TYn2}vtr^nn2%Hg@?9d~v;|Ll2U zbh%*eTP4}a&&llNr}N2|I*u~{NG*U=_E$W0r3jtBVKtOLi*&~q-oXo4d6I=#%DpT; zUqy>+x3ApVrnd)Cw%zB7y7Png4hJ#-UNE6XhVc&ezn*pWW=i_M5lI^BSqzYkDB0iC zG3U>~pPaqI1^lQk12Mlv5|t8Po^p+hUP6qG^B(@5e;#(XSC|J7iXsDQfSW4A->zUS zKOQfjL9|sbUmx~@^(7^dJj|(OQ#1-|ym>Rb?ycY8`><@U@~qbPZr4{&-F8nhUi<_) z0aw`{Z4SMNt{cue@N|=QA4zK-Ki#NY+jzREdq@UjF&$@*p%Hhlg9%x^TM{T7D`-jX z`eRq?U(;lbb8s`;dZJC!a&Xn?7&EkQQI@yn`8ZH7;B)%mk@Ud0o5-d?eXZa{dpBEe z5I8X|g3kIk<@^5#HH=W2FA%MX2*qc#8x51A?Hi(X1o9nC-+1)oyX)T{X*-qT2?f$g zXATMq`-~$26OPd+o&WrLbJl|K6jLt|kpE80bZ=o2g&-^28FqtV21-h3`!G#!rx$c?F`o-conMn$8-AYNmK9w^Fn z%Ypd4({=@<96o!h&0E>gT@VKb+Wl6Rm^@OkK7agO?HwpQ05or8(T2_O=tF2HqQTe^ zT&nv4WI099hgv2hz(OsnIqWAS;+<^x3n#3he3)G}0JRVaC?h5Q^_Og)yCkX=G5(A> zWogR5JSTp_N7S*lSN^9+`(*Imatatib%s{BG(gDlcT0AyKq{*8GZl30lA~hVr8+4bL3;pri@ zf?(T#8_aWmK-{3NOeT_@u$^iDSn9)|@|Nt?OXOHKI#RX8B*H}FS+P@YDq%E5a6F?h zSCMa9W!n5EB*R>(=rhfimlZ_i3R7Vbm8O=EP^y5DwT`4uHK@Is?i+by()VuFb~>eK zesi2UN!Hj;WdVvY{l zB*MpSuZ9OxP(EO@-%eDXfIR<@~vBJ3h-!(~1gvqgC5n+XwA*+rttA1{jCrjM+W@QblTm01gQ`R_-fu z08!B8IG@*eY*bD%^>ApA4k0!w+4gjMUol9OzQY*g_}5F(xT3kP-WXFY@9kzV#KBG8 ziIamRmcts26i)Tys?9o)Y>%%})Q|IK~ww z1Oq7wGmV_L;QX?R3axw%5+b7crKP3C#l`t~fNLl&U+@;7-@EVl&#Vm<5WC#Ea>xF2 zzSC}f?%=_&em`X_InPXtC6eJh#-DPLs$cKaMC{Z>dj5VK#;}2X#SYA7TKuea(V=%Z zyfbYih&msUrWF!iv^ByZ`;hNFyL8?L27~L)ALVzVrO&IAZD@2dg;v?35{+? zHw8%rWN<*}?}5pfvnrdIf+C5=y58_1-!}IcF8EBebr1)ZmfTPu0PHSmOmUZJs%gco|DgD}O__^8&b2+Du05>;3&|nabPq+C&H$ zZ8r9)uWzLalNCCy;rs=86=mWS54XS4$e3qV2Pk}+fiZbn+cnyqAd~E{r^>gKjnfX! zr8XvNrL7$R-ii+qc^XA$B+^nlbY#SA@;dD;$xsieJ>DXC$_gqV2}qJSWd&YHRklLA zrXTY+uIj84s_0F#l7)wt+$_7cG*4Bn7R?O8>U2)92|XDd?<)r;bnoS9&%Wvce>E$hX2FKH~=$s*jon@F58L~ z-MS%OncUbwJO-dCh%mD=EQy**;3BA} z)_mzewo{7KH7dzKgL()zK>uq#YRJPXXSpkNcdZC3JsPVsSf{ynZueH|kNEV>xndUe z(sEPhFKy2ik<_jkv!#I}f!804(;JQEL4yV<8E)|r#>_s2 z5IrlU-IQuAz+tG2#Fw>-pmI|>>~RjOvsI>~3Q_=Iq_0%`jlP9EZy!-^)8Em8(E^yY z=qu5}E6AE{$Lm~oLr^1_X11&up`$ySKr(>zPBE82NZSwX^wW;heu7+s2T}V|^?S+* z*o|yyy(;4WG>gN#Le3}^a--?h^1L1sXsu*Znmke-ujFAnDgWe!;r$mk4_C!)Cj}&5 z)87_%JFsE5yb;yK>m$j{xsJk^tbJqB=D? zM*s>=crwCd`k5}R_@XHGgn1`Q>xPn5-i3TJsi>vTKpjb-sMd4HLs>)x$IZk)Gf26* zHYrk~gbX}q3GqnIHS9Dovvj5|dE(@0;G%)`o4OGc$-;<7-ati7U-TRD9o_5=7yd%7 zAX{R*>uR_<4>~b8bf8)m1B-`QkN8w?CJi|~PA+k<6~n9iBM@7TmD{7tj9pvw*Y=8! z*G+uQj3+qyUiP4+h4f%7;(1c)NC-sNZKL>G6)bp@r`k!1v^z}J4z+{!m+K)rVRjj| zceXFFxrU?m9B|?ex~;Q7Q2dbha|^_jbgku%Y0POMRfY%dc{!}3b>XJ8XO&CUs*64q zbMR1TKSY7icBas-F8YkYc98&2l)RB%xT18^208etnbhCs9xaP5#`5^!j-7PY1*Q=| z@_GcS`zLjL7^5Q}6C;{KKL@$JjG!(^9qGjUrbT?b8g2t#uAX$<=K>m1bz_tk6Vddx zP@h-C3L&C`Ye8Kn&np+Sw}1UqaF_*aEF5{xD@SJZFpEx7k+U{ykD-{A)lMa1yXFmZ zQLl%2;@J+qjX_)ACA%=^OSb0Oz@_Zj`$N z723QDV46X`HoQ&Yz^nc=TWadS3Gf-Lz@F{(D*>C$9wP4Nj+oJhBo|lqUJ$d#Xf^(`;S7-m2inM9wy|okyh2-`h%HntPmD>-zI;j&os6&C)n&_AJBqHk z^9w?#1qcazHEfjVc~c2q*|tAMzLZV9)Jh|2)~Pb(LH9!~0p_0z6oxroPkr+NP|B^9 z?o#!lNWuMC4_)GSSdIGb_BN8Io~uD^QkU#;(q1pK<{IvJ)XoAj*}mN09wH3i7jv)q zA||V$eB^nV+SD5Qsp(ywYHKKQT=)_fATw6*U1to3>7gW;;DBlGgRDlI;bD{mG+;=DTzRu--v8bZE2BYvO{xek$AF$ zxvSeV#T?3^(9&uZ?wH~sWQhNL*xsL}Fm%@Q=IiFat90!?r6J?FyS2N!_j|tjdAKJ} zHmTYAz93LgWyybkUs}I%ZJF6=Tg>torzBh^up!Spwkn#x%G2GVYXielVAJG#==11s zI~k@|{#Xa&!gd&06HDkGEyfdnOT*H@;^V(PqiDj1f(E=)wewoPPHSA$l3V0Uxp8Ot zq1B33EH)Av`Si!ada4Ojivnte6S|j*{I2ZZeuUSBf@lH9+~v1#3Iq@@JmxPQc>r&0 zG*^a;Vc$e8RP3yl6vSI&bDrstQ);8t@|e}@XUq(MGRe_)BS%i>b9O`dO_nZ~#&JX; zo?kZXDc70~EW>sdg)DgU|kR{#o_1#e2xk7(k43&529@^=aao)O`Tqd98L!gs_+ z)xKA8EU^_3h5`^tev*G;55O#tF0>EwGZqBSerbC}n5z5P{TPZ3->VV~02jvj8|(Xj zfcgFJ3H$5(3JXl4c56>7S&wChjz#3%Mp})hf6(8A5A7rdQ|kv)6v1oKxjKj7WCY{+iznc{^oWB=dT(u@F4c% zyO)x6m)P@n_U~BdXn)S=H)~C(eHnRyw40ll3PHG3oz{6-?sjC%{SyEK6b&5qP&!u2 z!Cv#yW-_QPho^``@!RpfT-3$a%b0LstGmU&|1*+6Pr`rq+?=W&Fd!zaU@F=W_Mj37 z*2wBR^N{P$)~xpQ9wB=}`operJmOtgUSt*rj# z>p3o>@032W3-}(dm0(h-6RVc9?1v`>++Pl`;r-MS1lR@2pZ9ySaHUbjLoCq3p{X&; zUAdZUp*$bdPEz+7Pjj4?81&DXRj!rG3mR{fionk$*p3z*hg{w2i(&~VEFshDwwSD| z-Fac0Cg85J_Kl4BWO5GCZ-zIxrv+QxQ8GpByafHLslXsghf0^?W@j*>hxQII0@+H{ zQXe2*c@BD)(S)VhDXc?8M7?tmje^gwasOjf2D4|1&x1XLH*@NsvUQHZ3Joj;3N>-L zzm*>jo3CuYE-vzny!|srA_Ne?_K)U51OHbRpup@U(05z@*F9GOUX=f65d&wSUwH{& zCkEgEu3nsU|C_1%YYP8=d;IqjCXlG16x&nlp)hc@kX1mjqRth-&e`O>$*b@3)4+$* zWu>nB7XQ`Re{m92=%m3rHUC>@z#j>-X{P_zN2*+neAlz>R>=a$wud+r_j@LA9nit3 zQW8CW&de+~ziIX1!v_TN1T$U#QF5~C3JX-k1`r#VcQ$e}Lzl8Xic34>(OhLH*@^++ z2;eIzVU;n+)W6_gaHvOz-p!ojr>83biGqmF zn*2Pw`ubq123-^Dn49+e)fgy#v<1K6oTGPKen=+@Sgr90>POQ*eV)2CKG_`jpl8u< zoicrqcx*Y7FP_DY*JY^^uC0oV2ljt|$pYXwxg=dc_35w*)xs~6dFfX1y06cp$w)0bvz7}VNtD9JP0nY52cTd^g z3}C*lW*Umk^s1!U94siMw49*{rKl=l$V3=3WIQT}e>31HP zl8nNXV9N?-LnC=VSwTrkE#w-lhOe96Tj7;~t7z%C z-u7*^yVrZ#;aJ=zG>6iGgWeVH6Htz*8twq0*X+L1op z2X~S*x4jrBWr4MI);3ffiV9RL#mI%$R%{=CWP&U3jg;)uvz_(_vnH3+mhrJTRF!`D@|GZ)i@HOze0`Ys`vt916H`xg1u=;GCMlXr9QW$wfub?`y0ftnTU-C(Hv|2xWS-wK+W8 z!Nz)z0@T1Kbbp{k2hVfs{GonN_JmulgRV}UYx{t3QwN~d6j&%+aFHl1K1g{D(Q5|} zgxMsGEpbi2mY~sm+OC4PnJySHRX#!|xM?XDfGW8#2RYw0oLzDUa7C7C0os7XQPq!d4%$Qb z-N6!r>Q_?PeVrM;d+2-~x}=l+p6U%xJEz0JsCiUXJ(mgV#S5@qcU+*GAAdIJNnWTr zd9`mYqVMur$_3}1nnQ>`5v$R7-EQ|EbARICK&XH=LDZT&_qOTtZG=nhP6E&le4S16 zXM-to^q7HG8@YK^a6vJ5_KKObn_MwN&1FyapK=7+akL@l)tWpo04E?6?f9etMtboM zfbYX>#V=4!loscma>tjLGTRvCO5$SIskPkmP%StNrth`7vZLVF{sN|uwW7Um>z20e zI51&ITx*MftCcOrZAIeXGzqMhur+`2E6=6NTY)deWIb|+>hzm_6hR;mu)_~Z!PeNZ z9>}(#-nnl!v1Dg(Qee@J=jT4X^6m`66~Ud;lN)^MM2i-XnQqdT4THS{Yn1CAr~4B* zcAe)^P`PALhCIjW+UW;tUUhF1EfY)F?7uidHNROZvW$J5uS|&AcL}_xI&P7D5-`Nh zQWUy*sP8dzqO6?encX1=&qTzI-)jeY`3~~^E9dWb^n0~ zG<+4MuWomsTJF4@BrjL7l-jjJiHOqCQ@3lQVNYOlHIX)f-?fA11;pXYO|a*=yq!oc zjd-;5DOsU7aZP{U!hB|qBt;swtqGk(3}!}l_BqbgPDhWic3 zPwdt339WKnygfp7N;d9KX*kEmEsj1u$xF z0YD%4y-doL9Pne6H~i)+(U9K;0sgWd&A?T3E+LB?H0P%XK?y7Y>v_QoMel@rgB8^A zy!86GeH;i6ZJclGaSN(c1C<1kk*Wy9Vw5kC_r%#6o$;03|J$Nb+h(!P{_nItI94p^dSz#3FNSQI|&U;LO{S^7354K4La>gc><; zUk^%4O92Io)oS0Tk&JY7CeF@BTQiNt6-61qVBkPvGIUFKm-Kz` z{r-G@-|s*7u66HP_YW4&^UOJCpR?nf*WPFEU}Z&VTr3JKG&D3^Ss4jcG_?D4XlUpP zkI;cH#r(oJz`uJRRi(wyN(QJlfR_j6?-bslp_NBqUwyy;-XGh`=zK&&!~1#ncdyef z&jbxESyEQwow}RBPSayAjn0&{Ue7e27`~J~`Xe)sxg_^e!JX7>!IW$pSw(#MHkWOA z#?Ve`W7qm7`Zg$&3lm|v@eGu=lk%Q*XIPMA8pQSe3G@q~47bx1~7ATG?Id2+t9NX77Gzba`4yL^|R8vz^ zQ7Jd>43D5I=lM8^v)Iarh9>iTxevq0SWdlbl&>mklZm^*Wrr5S`Rb2@s#jmC;?dB)Q?|Fao0^(tXI0zH8)#`s_k>)6!o!qVCn#MEzEz~yNOw0`1%5i^z`&JG@M66 zgFeF5r}!=%PLA?Etfr(S21pVR`^9=z#4OultapA+vK~^v^os$;O64Ls zhHueiWHXf^F-%Hu4uCqkjEZdBebx6U7=eFgMKEYwbWfrbDMRADr8^&8@%jO=UuO4% zj3L-qz4O*G`bt>yjbC7z&cS~8YA0o>!kf9X!g{|oMZL{0yXY+UaiJ6wS*noZZ5c8& zG?RND7@OJ#19|mHvifKRH?%NPUIRdGZ~thhlCRt}Qa zZjRkM%deZ+uIoWYuq5<)E0g+mArSjE?K#N|#AhSv^3ry8+OwDG=h5cm+og}e-Jn5k zP=oH6Yu{@@(|F%)udgIdXBCW&zj7ZPWa#;5g?s62&_?Q?owKs-Y=NvXY>$^9%tI{Nj+=xo)6)OIt*l3ByI!MFXhg4w>jx3AbZJtg{(Tz7;cir?c z%xal-tH#eQ&1z~A>~j+U^d?g>G`sVY7_*+o4|IUIj6xd)HP%xW8h;j!Rvwk?5LAVL z-T_KVg&9$ix^He>)Yc}#{K^GOo0La;Gu>4nG@7;?MDTJ~-7D61 zBJv);l3oJc2Ty-C+V;=lm>;Mwpa@yWbc<U+{%I9><_L&LXL_o8 zsNDDbP&`aJbl&TzAI9d&bB2TSV36;bpv!7sLh7?ae~CEFtZ1DFv7~5d{!D$@aevN# z<&+qa>24GtgHnGZN|$~26E5d3@$nlk_k0>RZxXg{PGt5bsK;+E>qGfU_s$KI-gq?a zSZo-H2bS(Qo{uemdR_n2NNU(v0O{|eq0em`&>!$wD1<${@7>_cq83A$7idzI81XTF zy4FHMorS^Hp{TqMyk6#ndBr8iE~j~Jk#N+@`cXr=Chxwv=G76Ifrtd2K2#yiz>8aS zU{|eycdWcD$P@>=l0+W+uNh>hl3*fyXK5OWoEkl)!1JQr#()rtfr4dY9kw}KdvRb2&Hm( z?5u@my~8VkZiwPBaZ;cUB6!WTL-aFKmR+Zi9*)fTI23IePZG<5`)!>|DQO(X-pp$3 zv;IgWOv`OWz1EXTt{DD=g8cZkhok-G&E62Bpe*NzPWR|XvcRookr?=k+Jyd7IG~;9DY0hQSr7r=3(=d zl=oa>C|{H7O-E+tu|a?9zV@UlV%tb0?5fQ%s@qCIwJ5OF6=XYR$sBfp*CP@uV#q59~rwRCFp*3 z&ojUuuL)FP0nt?Ye@D$4d_tk4eX?fM2X^P5Yd3>wc7K-AU{?oiJib>)5jPRg&d#f5 zXrEogm7&s3i@Qdr*1YX`Qq7?ENecF~V&%sJgWuS-q8xJ_ten3}dIOR{8$T|;5n$iPfP0c=*h#nnh1e4X=iMnGGh;;eu=>CdSG!b zXZYsxm3tfFtE`}_bN~vO;0&=9^K(HED?KYghR^Q5cq(ysk^$cnvXH=Lo({acNCF6d zH~hbQlzohFUjIdtfppoPDF5&ivrhD0B;l{f96wMjDXz1?I=~Z?huvC`V=WQT+m)4- z%hR39c)Gt><5dCFZTLlQM)+U2!kUdDa%9r^g+-jaDyg+5j)0A z5J4sExu~+ewS^79`7Q~IuViY%$D~1oK(BNYQepq5rY7NJ+q=;M;^&~LxswLLpgJP7 zm*8|{V`eY=MI(Sv_xJZ70aK9oH*-r|8%@S9$H>G4_p%*-3kCq-;kyTb%5D5g=4>O4 zB@M!31}Xiz&&Z4P@bnD)`gQr}A;A6N41qK=A8RYWJU`T-zcR$z+gn&z_;3M`UL^Ie zKBc3#v6?d(r#P6N4fSst-UxQTV=Hcq)DeZci!m3!fBER{l$^xuzv8|Xhqgxzd~g3~ zo=BlMM*Y?$w&<&G>Khd~KmC+@Pg&GHp$;Di>n}!Xy1LeQ9o{LyL++!cJk7@S-Cavt zYl}DDhw@KY3KJ7IdyF-tySh{iJ-?yL`ttDc96PyoKiI&Jg){wC5-UGc2pQRwE~VmF ziin0%eMnJt&ZdMu?qhZ?$4D)IKHlVX3+f#kE}g`sI1~hF5#_{?d~tCh8^bv3G^}9E zpLTn-)-C6^xM}|OQfGmj#6b&keSK}$a(!wXA$$thQskG$LqH-X4>_BTQJv3y*@bV) zoVUhmi3wd1Jl+?_PhXqKC>cTR>inX2%Y?sE18>cQM)z!bp78i%94@CH0 z8E+`DpP!%mo|^kgr9H%dMognyZJqH-!7sa}OYXj$e?&+vTk$x*`CuyU1N3D8PjUh~ zwac&3(Gvgxv+LDHGHO31)}o-GFmvdl`I5=d3=Y*~fJ8rX?0RvVUs{?Ai_%;h^f|4} zE?FH&k)z2j?^0OcicUK|c1i<8C03AAUvaU{SmS$zY9zbepLtzrE+WmlRcF3N z);HUf^=(o4L5P&lgaUJWj;h@<>*EL+)S@(O!NQGCS1xC_EK=dhNzm zC+wIWoz;H#6dUz3Plxm)#+2rjec$$d)ay6esOKdXG0pr-R;x7cO^Jdz;AO`}3mLZ* zO_Yv#LyyYvg3H{(ZPfjUt_G^!@1Pe>Gj9@*X(#vx8i`lyeO|!LiTX}@DJ)$p3yn%L zA*hQ3>E;k?H>O{i_a`#Us4Ht}#o0?sQ^81~)Cg;t>%16Hv)B}e{5$pMEro=&6GJm@ z;I5+0thABwXP&oBu4clw>>CAjAI(_kI5A4Re9wdHDawl_$0qDED=XE^VpH1`pizAn zGixH!KXfjhgetFOBeLhQ!py2I9ilxILpKGSH`P%ZCBG0oJ>aL#PX5VlHe^yY6kj`1 zmGnrX$YbGTczudr?SrwJ7`$vr1jkZ~br^*@e1jwPh3m^#c&bA>sr-d;3-O}ZF|ul; zvID>W6kntPZ%-tqHU_Kc(ih065Q^y&a+gMv7v$&DJe4pCYNQo%VJ>u?bC)KO;0kXn zUw+PsV3-@r4{*FV-Uyx?%M9TB5Lm7UwYBD-9ueJ?_3Dfinb+R$!LBrmt_Sejk1oMA z{6S8y9gU1~=BWc?=|SE!kzpsu-D0Jo3|eM{+}hr=a#^`-9AK-SSQh%~?9O}o9=mmG z+2+9dGHl2iOY8{Kt=SPOEDl|y;9k*EOCuP($~@n&PU#6GBXDZH1Kv4d=B@p?E*!*0 zT5qj`zAXFbc>2*KSG3IdV|*2(&dKA)EbyjYIu%L4vXn8OO6PZ#TaFe8d!7b;Ur$e# zRa9Bcrjo6R%2q>#P%R@w>m>-8DI`hbgor{>kR}hFd^QJ{0Al<)*g8#T7~dST%e@Cf zI~WrFSO`lQ{CTa*ZY3YuP^8$a6gzU`?3R|6=IT`m>dSWz%hfbA-2YT*tv0ZNu)MBE z<7ADag1d4RM^qt@ucj_g8LC*)$3<^1E8nUy{fhYks+n1|!dOHgp9LSoUmE!n1m#EP zDElSLz|yoee=d^mKQij5Vls+<92Nu*j=zGtCpeA~#mGl8SAB>5ycdmwuFoG|ZeFUK zD3*tP%EAeK+^2lKl9;cc*XyX%Rwl6)ryi!BZ?=l#tl#llOKbmoSwO-@pD2hki(hVY zEk~9tqrf=5o!b#-n4fT0CEY{wIXmNaBDv+NGY=7SF$Kmd8Y&Q$V6l6;bKzJDGkdCi zA+t0&zW+lK?TaB957!mM9Rm8}>;uE%y@EG5DVSqgx<3ujQ7v^-tAEt=mBLIoK+cp! zuAHp3uuuzpF{AdekNsGga?DG>Z1hUZH%=Pw5R2~s*ifS8Xg9=FPB2Ve91zXT2ELS1wpdZm6!o$t0YP-L3s`x6 zXKGaxkc)dbBIvl69e`4OEtF&%mOsK90AbX51)|hSP^ztxA+xmX`e0zhZ)Pg2R_#w& z$Y=Qb+;Wi2WnSwxHLR6T56EdE5Vt<3Ih^Oq2$ti@T!x@x_z*|jkD)Scnc%Z8Bl|6yMb7Sa` z;HRM;GPXbnV$$@iB!1j|NJ>xmqa3NnTs^0{o?>gw> z8D4*Rmd0CNJnA!u88GNgIdSG^NA|Ar78im^247pVSZBo=vCfU}@y2%=s zZ#eXkBbxjhGZt7IRi4xc7cXPEG(mre4>4C9yLB)jB(E(6<4LAd;m7MDTNqpZmPz^= z>R98$6X_OX0tuOg6ZI0m+3NOnzQ6`4`pA6L(APJA1XFQd?oIMj~G1fFEw-o4M)X4(m~QS5V%_j_kR6!-(iS1vrol@Qjv&`+k|Tx z1B=gVEXs`jWvD~<8}$qTHPJ$t~t{P(B z_Z!06>^S`!yH10Qy!jXE`wEuQ!Y?w`?~RKF@X`Daj~OCZH4DFlEF}gAKeWODeM-jJ zsG85R^7E&A_7n8dX$a1?4ESx6wa4sdYPGzdx9NK1bMTo+Wn0DdF_XY%;vJQv(hM(I ze?R&~#}XLM@QY9!`$cXQEnLtA6lvd9`N5#3W5f%NJw}lzayGKv!rLc9T6FGMq|-r7 zBw7KcDBoh$(rbtR(teY5tshJdBPEowX88L2_D`o}SdP04|AU35^5N;}EH)6As)|Wx zAse69@d9OO(;)zF07#?%XR45LJnq?B#?s9L7We8FVPbkMYsstNhZyZ6hFYF&ObA$} zCj^VsC@E&A5($cG{$`~u`KbZ@w?V=b2mQAoJim8j{_}l3iTSIQ1~1F}qoqwtVTi@r z$5d8$8CDkGjrRY*ogV1F{40Oz;NV}9y0nGLVoHnJzAT^4idJSbKE~%c^?V5a;6D|e zARej*zrx)<8M<25tDfys>YZxB!-TU_ztS#&6BmTTo%}UTucNIJC{~@VbdBLe4J&B-^huTabWiO1rIQ;~UxcFG#51&GEXowClXeBQJJYud^ zWUwy_6_7=uxNdh%3EL6a({WE#Oq@tn+UVloluD*4nNaG8JnYyA&@n6Tnap$7LSjfN zocIEx(x1Rohcli9G}N8NHLf1?v{Tb~DH*Q$K8T{aIKCJLTC5CZWsu7i@_<8xkyk~* zbZNt?Dhbl|2m$@2|!`;Szr&ND%)?&Ymb<+pla@w(wdy6|cQ)tTVN6!}#gM z){6q@^83_b6jnvsZym>okAFf#;ft}-gQ|srZ2xljyO7js5$0DWbxUV#!e3kLDBZnx z9(~)5X4`ndtj?qcf#`Ip1`*+Wb8g~;I`hA1OP#_Tbpcee1=qE8X!gv2g@#fE|9T_x zj)cHGI`0J`?W4UgY=tmfz)$i=(UP>!;cHS)HXdZvkhYxn$YC5|uSQ2L?J(G>riZ+U z9h+Po?hnJ|$~yK}*PMwZeFq6_8@uy4Hk4l6`3YyPzD&Y2=?QnsB+2L0Y@^3(ebl51)=?;xEIf3hW_g|=N7)WHB7 zOKge8fus`l8u?(sg8`l|<%qF6AP*(eS6F{meJzp**0B;+AN-k!_|_Kv%Dk4HjwgIS zk8M?W%9EGd%f6hN!Ef@`i{BxF%H*4AFVb|DO8cttBRre2gic{FwG2ndfR1qTnXDPh zeUR2u2u>w`F&BgcsVt0d1?P$`Ud1#MuA+ECn#O=#>ErPwK+&dysi>wPV;1XYU&wob zE`RpKTC@60nvp?1<#Znok?>y%vSiXTjQtC!!NIU#(Ty`vy;xFV7^>YhKKhVRg}7kc z|BlVuadJv W2DZYMWQ4W!Mdn?-ABDZ)o}WahW;o?h~~r~1M$^t1cb%OqC@pO{8PjF?d>j$&#sZr6QDS55tDB}AdzwmagPA&{ zjwgc_o~po=ulbzdex+GIN+bL;y8caLL$=R#PX0xx5hT*m2t>liQY7xH;6N+fIkY%{LhTjRDQ;0!ss`oswqurnx;pw#omJesN0kx zAN3I;_I~L3)m%%<%Ja832NB{aM+qX{9wWL$3mY4|jFV2w_U;QaWQNHnfj{avBTH1@ z<}k>+Z4gE5(@N&h$10meRsTUCqq|zaJd{-*vS9q62>8{ne7s*6fZ3|{ZRA+Z?!5US z(T^tu8im$|)+04l53;6y(Hdz%c6N3yYHp+D+}#DbS;{4*(!m!slccp1<(t=Mt5*x| zG?ijIP=Gn<7R2X^?RW|NDcz!om4^xWci|+#iGu6Yu{@W`2jy&_7yMp%My_Y?1k6UfZV*?$kzR=Hn zM6AFl-$z1dKVq({y))?VsvH5L1uN1*=(Q{8K>8m5t8|yL~*>kzR^)! z7yyY!h|%%!hyN>1LX9fjv9V#=-0JRnX8ZZDmpBf6;6js{f+8CK`CUvWaMdgE z9C{OoLLa(^SRwKF-lhU_>{`PIJpLTokGcN2lJRl5}&ZH0w$}BC7cqVoiYI@ke zZ&X0W6&lHQ4=w8f*lHw5Iy_a_&yD!5BaWj_UK39dMY^OCdp37E-W95~Qx)ZRS|WJNA6!8xvYp@5R_MNgDy7x} zRo|%cMdU@EoLM)%D`9u=_pGkQZHwPp%=IvMx3yog1L^ZZdJ%yyvx(41;u+TB|EeT zo+h)h%c&}^@hUi5v0r#|CY|sPQfp)|>=9`t3TwNigZKkIgHuMWmBkBk+Qgwhboxzj z%(Q6@wjY(+(0;+!@?Tn;&b+Jb@8jQb_9@gs6(T-+-K2)DXA8wLIYdiC7;%XR5hdEOSH%kDOL)vID07?62P zmoz-CQG`8KI04v-tD!Zc;(mv2S8FRSrKxF0pAFk?By2-uT*tcPT6Lj+n(xKlF$$K6 zuTk*vND;q))WT}h>wO8c+;~9dkOxanEoaZ|Lt@(&mOzeWaN#L;=$NMO+@rUHr>E%G zmprrQ`wM>6_r`v=iH;-O_k!YSdKh%4$}@giEN_WdNki-i7DjX)V%C=)*jpwK({J>J ztdzW-+PScI^&Bj1PdNnhrtVsqIP6%mNVL<|oPMU$k|?ZrGidYVXK+t(F4F?ClW4ZcjXOw(>GpTPkE|AUS@`!N2HjT$@Y2%ZH ziAo{eiPwZl2;*0P@9b4>EX53Z5L|A30zdrm;Y=sfZYlk$b#S4(>_gq#dO;47=Nl}x z6f=e&B+?NzIWU%N79Ll1y$@Ey-(k4Y9w8PfbZ1q5?$$%~Wob730O^MPE$XJK`yFDv zq`eCrIdhqGO_!e9H#Svko$NNc_SvQIMf?gcQfuoZuXOXbo(cSVy7OvI>HRmnuai-k zJ$loIHtJ?&X>5&V)t=I_Q@T%L3eY6&gdIc9jE{)-6mpOEHjlr)j@N-eCPjdGH zQS~A-Ii>^Q2IWbcxtM&mJqJE&%*8+TAl*cWt774zHN(nm@4Qo|!9M5W*IVu<5J7ip zu~@mdF+)onJnIS91;2iMY3(m^?%wzJtTu@&z13eIGE%Q^7*^Cdo8dOl@2NK~Hi~FB zmiS3lLV`jhEo}^xU!Bz28`6Ck*HWLI?~sTV0%zr%^txfSqc4`HHE-YI zb{L-?_vpjxm{`&%Ps@e+uaoMii}1c&zfKs>1a;z6r#_W(6$$?fOEDG3XvP=P3nMhH#SKvex~kJo(7B ztse{5x;ih|QmS&BcyNxiOQ3xFx+@J4^xwLmww5>PUu7xhPOfm8CnK09`RhbpM$9xu zE2?b0EH-)u(e-(qRg`xAjc+RR(lR04RRzK^+oL9{+b&qxOK$hW4L@-y47f@

    Lugmb)nuw_=+9Nia>b0E2teJZ`GTu3R45-*0Z7dSSR-s;^Tq z!Z7$Uq_h6FPQPjhlqSxkLGQOGFHH{*pWk-=@zsg?hbjMtsy>j}s+~0pb-H}}DjeQ2 z0Ws#}6U;5evRJDTgLyg{uua3QtTy#4vQF+b_jbvZ&*x95qGF|Q8#UIRy(~^>df~$T z8JfWg%-`lZk71;N%cLemJses6y~FZ4XJEE6Xe7Rvh24M*L9#yj(Jei1e( z>Rv4tAZxS9`I*ACpE{};URIHrU)2=3u^NQjHCV|W=Z#%_H8Z84BTx2lQ6E(G)l0>6 z^;WdlT9{N}L`bae9w?kYj47J$;KERCPqv+5?pp_&zz$m^N{0GGkM)=SJMR0)QZDq&6yCc#Y@CpPSc_ljo-dGB6+tuwZ4Oe|luBz-j5#;h znHKv;n^qqNQZp@b>Mt5DZ5ALzU6>mx*5lpIggp=ESd~rdD=EApJ_BQuD3r%%ryA^LPxWtrHLd4yj zPM+3?q9U&c0)+gtePYDq+V2?iau5I8^9YMV+)|{3O}m39m+#+qBG{&U-+odeZf zT*~$cuEZ&X`-S3a}`7#%(2{MsE0{<{g+s4FLW^ z*)KC)r^?Q@LE3#g$qCNCh!d`WiCD=sjX}NfLNpYnHLdX&e6?&bM7u+#+SL@X@HDsr z*vcyHLiQ|bOWbD7qpj5L&f;<4qnHScyH?~lt8wq3e;+WvoSP~`{(-OWeV)dW-jRO) zGT!k2Yts+%rvHb;2UTddZz0D54n96UF0MXsx!40^yMO;aa61Xy$^y5+hg^3cTl7r~ zE7;23o&bz}_xcp`^zKR>4eg5d9K3aLvNc|!|MM=n1h{g>-@eNiKtuZ@S-=eX=lR9a zd$85duehi<`?6f%?iTG6&R2EKXc+0h-=;6rWSdbx{_PG^SAk3n-{qQ$t}Zm7AT_r7 zFUjd2dPnO%VEs?$4p)RE`qoBn8mUoeEL_2QA^9KDmZsVV`r znQYwXOEB9w5L5UW|9SPn2x?MfPF7wny#6lj^;0Z8A($<;kJjr=F6@mbL~;-GJizD^ z3Pr9ze8&Km;5{(gw?5ivWbUY%divaO!d|rm6}a~&d8UzPD_=rB&YUxHf`9@U}& z)j4$96e9bFAWt(}@jm?rrBEokIN!^7c7om(Nr8>SAFC*P zDD-TtJ_|5Mr1&(wagJ<48N0#pYU*qQf{EB{HlCoIl-@~J=AdoHY&j1GN9aB4QZ2EVB4uHCpN7CxOAUSkegNub!FfO)F_sBJ9EoLl`lduW(%tvd5F_ zveY3SUXH!|kgsAL42saO%zu^P@)Sv~XRTv^e8uhn%;+{Ex*{Q2p2705)Q#{bM`uFT!`MMMG`qGle=V2M7Q8i7Q`jl=2XFE%XCeIE zv%hI&!2II>Fc+7;t%>0tGZd;z`9?MGW*gT?@c3Usm`@%ecy@IdD{ss?{2tD2($YP2 zm-X!K{m}Za<;TazYFeFD8K{uT03M)!_5%%l3O8&M5G(vgQ8f&f32JkM+lbLyw2kt~P((F6Bz{y)|?{%M5)& zYUt#%Dy$_-$P6L>AA_nu^vqz9A@x=13nhGlH{(gvt7~HY*JhnI7`VP|ZJM&o6H^Xn~n-i*qQHy3S=~8A;+kj$`-W8D-N5d$&hp9=_jXJ zy4{353Pa3X3{k*hdT!@QoW#^H7B4KWQRE~epOU8KZW(Wbq@a((kvKj_u%ntr$D1V1 zG$v{0vnWy}rbX|GVTvNdHx9{>Wb_ivd=68Mu5vCgEh^@Dq(`e&CF6XWy}JsJp*mv= zy$`r|qM1Thn?+pgcLB0&=sDXVv>w`JhN}7#8&HE5UaDa z$2J2a68oWqAbF+qcj-DkPg=Yin?;seNM+)fKOg@Q1qS#v$;LMz_|tkfVXx8Qv>mh- zZ)29WOtNt7zP|lQ{`XhIH6&*5T36iHi~N21zv;wi^v_VLt~b9gON`k15N@rpW55}P zu;Zo@dcEH+5auh88zth4EUMG^(ny>94ams0{e#RUnc+^@ib!rC9qmqksZJWy6$8Fc z=Xb~u;q9qsJ5W2Hut)mkgc3Wgc27{RKJ0SNTWMfk`*~~}y?ASf{zb-R`Fx$7;{xMR zTT@24wPyN2;gcx2av~0;>u`Er6;n4Gv($9+dHOtU-V>E`ScmTJ^~%V~Lv|1Olm^Zs zs;5F4T;{Z)?$fl_sQ}|X#eUaNVGuPV%&y2(hdfN=yq$cm_|dA?6ByO%(R{yd{$wfnNY3W&t_CGN|2J2aQ`PE?#> z9Ox3c7Sxo3p(+itmp`7V0OcuYFHBW7!2-(|Z-Wh>JGR@m$7;@LJ_V^Fdv00pLf8kW z?UIQWj%9~T(D|+eauK}N?4@gBM(fdy2bE`=FdjV5u%s$!Ey9jM*^fWj$?dx`uoBji zo6JiunA?kS?_VyVBTDn7rdRzmedU~QKOJqTs8o-Wjq}%59V|iroIbJ>zd6zpVDuI%Pwqy7X zK&xVfe(?Ay`1=2ljCg&lSILwU=&l!8C-P7r~?5^xI&!>1+c=qHxcBq#N{)eZSC| z7}5CArg;d1bGGC<>)lZDxGx>a(KhR0Wgtg%3irWc&1$_V#VK7}!&2&yXL64N@PU1W z5c#0~Z|?jHefv?3U_#x5x?G+gKI^T2RstRm#`60nuxe{nSSP6yWyETpbuhWt?iAI- zL}f)d+Yg01TSMGk-yAt#9-}#e!7S!0H>!G2heM+{2jGG`>95u zc5mn@Hkh@4hL^xgOT3nb8dqP!6Q0Tt^1Z8*eS9MhDN>(L-(#Z^x7U*r;ox;Sa>SBaOm#`vc@ zfJ0Ou=a)4T>ak@JgM8KcyGgpt8d)hSrgx?8*vqxn#1!s*vky0*|W(fw)Vm*D8r z>7Vq@Qu@agA@iHJdcIc%x~lxK;t6Dy$gcAH7hJvscxSk+eRf2>Wgt|s*S{1PFnxah z!I+w*IG4@E$?&PReNnQQi4og>fh2&ADs32EvD9AD5R`ncYX7spnH0JcrA2AkVS&A`d{#CayR+sjkl}#A#)~aKN{;y z|JO8~m#-$7<^OkU{?GqGq=3r(D?NDzjabruJmX0B|EZGpihn)Q1g!tM&Htm}OT@{L z^mAFmAO8^=xvGw=Cgfi>$updTvHw*%bpZDN>)a+h{O?e}?`wa(@yPuD()@qZP?{UO z<<=SQ%w&*G~*w zty;_hDgW!kV?GH(ZPt0c;{U}UT<-TDmI20-5;s_Nk`kRd@juB(R|P~AUmo^)`p%4u z9GBmX^FOu4=e#na@iMN3^@5e9n6C+_cM$rQ+xY+@wj9{e^)*>Y2(3arzyCkFkx2i? zxW2L!13A^QX?#7pAzEYd^RqxA?a&LrS_J<3N+vI}E2N5%np8d)T7@mgTcd`Sz;cKF zY5ptQr}6;%tkZWd_LavGE*lZ|{tbQHX<|F! ze|C}>VAJ{6UReL1Hl+#=r9womi}}y#_R+zZC?G*xteVToJ6_(S;xW+$_vRacNmQnT<|bQ0_hAJ4_|$9!9+884b((D7Rfz1Oue+O?-^xI zl#i@aufomqE>e~vynEB35^!9eC^tquK@TC=Oyfg)_LpSx_S7(IiO*b4-Vbu%qMR!# zW9z4(_eQLORvm?8Z{tthT*Z{bTBI6x2)pq6*z}ZpXfJ?34f-ka&84n2qz5Xf#CbV> zBG4lzYqI#wcyrYyDHF?>SckFqkwv!6T;t@DgLQ~h6ie{&{lUA=pSm)Ii-UlYt*zD2 zcvgB;wPrf~TPDu&va9G%IA<~%A8ZvrAdcyyfmz({Za_klA-?|UG_-j&8bT(Gy zo+=6s)BfFZth78*p556q$+Czn>qSLRWuciqO+~}RSWQX z=aLF27cl5DO5R~7C{{>A*%6edy|0@U4LDj5Yol0e6dY=xsQQp?d9g(cceKTu8x%85!@~T(>9Q8RT*eyw8ivFU=snCv$h& z5>@A(RKn6Uh%Dy@8eDlBiyLq2Mb=O+riTTbPQ^)Nq+}(g2-d+?fD4<(*8=uXO_~(s zobr$TKm#OoMFr0;faPXy0O(3rz+9aROCm;8nf8)WxB;cK;H{;Iw=O=C;k0T*8xCK_ zZs_p#011RmDC#2q=h(^r%dbnVa z$N5#=$c%IBj0ZOt;p+$WDBAoeLnA74qk>*Hm|2t&SJ@{yqEKbZeD*Sie89=h^5uN$ zryPicJN=T3s|hrT3b)jOX%6>Xe*BnYV>1lW6GZzYX-{4ALsPR0r9S| zfL2{Fjo;yO8{A4Q(9Ya}tRPk0y`E6FuplREOu0tsQE7>KGOk>L@}q#5q{TduQ8j@K z^#PxuA#9>^HHAEkE|BF`(c^akA+4f8>cnc!@JAUIv9L!f_i@l7Eq^_T4)cU;>eB=l zi<`ftm%bf+cFo@SlG78Silb9)kIry};5FI=uhUlt7(WW{VQoMearM?t8K{c+5gR=! z5;cYOyy2+bftJq}Mfu6a>@1*!cA!u@{La}k+iQXr0x@W?FsKCiRTq5JxuO_fS;#P9 zP_tQH?*4>SZR+<}zI&bPz~mg!wr##!(|ffmyp_PI;mif;t@(qcPQ?6+MFVUaO^>RZ z#}=dN*yj5B)L}LuIoY4I4Ff0$dJ7=zEQ$784*p3TQM!SSYM;L_b8_OxJbtHvB6EwP zk$h4WLO0-&Q;paRb_sV-l51gc&i$dV;G`kItjt45!yS{VXIfZtmwkgrLdfjT%3k3p z_E>{ca0r`LW>xi(yMCZw!Q;9OHU2zJC)b{0OBrR>5KdO9-IstzOi$=xU3r`gCjx2) z1^32Eu_*fmKpZTjb!)-d{6&wMjM)6FjZ5RD1Rce5*yL0 zbhBhA_&b;|+Qu3EJf9W6nNwaA%3V2W2-Fj+BCf+J0cUrQRi1{0)~bg&y&l*m?|VlECyw zVxB5N^=HbsatHY=%oN@(E-tDsybG2~lr=vs48it zp?wZBWI$Re`UIk}i;;R$sN?Z{3H z6{U2F5JTnjs@u?V2y96$5NFiaLssN%S!JqHpRm4>A0E;G+p-05Y02tY(e5hF5=)Yv zsGKnIwP*PMz(tcWT`v!lf>Li$99xt=Kg~v>j`$WqSh7vRBQ5@2O09C|rfp7y+GgCJ z(}uBPNy#@^+rqW1aoW%M7M&52HDwN{KgkWNu;I;CL-g>wuo3*ULxEHNy{@JU5KK6^ z@Gtc~$}Qb_L%oiNnRv?X>rEMe$qO0(2TL_iglaO@@RK}!3`VYhR}6HH*M{aw zqz)6coy-fHsCIj;nfi!F_Tt&btdd!*A-{>byUfv!Anh0(^$|_J>JE!?dbhLUg(!-r zP`y{LI9-2OjeemM2boqf&H=@7Y1*}}SwLlin+pH=-d>m&*jQxZm9&I5CvXam>H3iZdm=$KT)sZi7TWN&ZBrXSmvr z&tF9e87lb0_5^ZA27z)@M<9Lb%b@kjaAe|azPjS5sk$y`h+#1rxW{2)wCu%{{zOVp z_WL?AQo~nUTVGKMc(YHdy9MVZbUFG_B|dL2GBEUs#?C8tGz0(xwF?ET3|%DHj(^sN{yi@*_#}l{@;Z8lWk!I zNM2%dwYKZB*4<&-64ZZ1`{$3AD8Jx1}dQOXg;;kqko$cCSxO&F_{gIS#0UW&tetA7JNZLgPel z+mtb>ac4|5yXU_EBwF4(MZELNYwYZvzJF34x1g6_gD-yY^#k;HugS+ z2ob-I8ZQoDbiMFiV{D$hE}R$)5BoNSIB-}7+>`wI3GF__;BICVPs0Vcn%K>+8Ftwb zf7+ZpbG%wBBj9{Cd;H40RVD?vJaGi{k^?OQ`xNjJ=$i(_w2wA~fyQ(GjX(c`c>bHy z0LU|dnEne6Y5ql?A!bzoC0H92@?@!D}vAqd{?sYNNv(wxEH2yq6?!P93W?EvH2VepYYGyTjr@TesER zM2`8ukGkJSwclG%g0-+M&}8S=-@Q2DWQqF*dc-8RtV4$_#)kA*{5dem--}i-d4)($|7t7 z$bdB5Ully4eBTFw$mob|WpME9QgMZrN+e(=a*q%}lEA0ujIPN<{a0>?v#L9cah4>s zL9TF*nWV%juK#i2H-Fx2!?OgYxosA@E_;mw^rjfz!5 zhmhwaYJe@`9gme!CUV#cDrBK6gO7PT{z((Ucp;<1AbLAJVR0+7A&S;%ndVjbZK^iN zalT2_30oJZMU0}MhK4l0#+1U@AUWOc$jI=yIt?jpv?}8?en4LM>F#)VNf|}dE(b|X zl}}zWop$OIm2W&{V>UM9pn7U4X^e6L$7lRBAPs(!CaJ!eH@(B*;L15f`+O{NYXTZC z(>>Dx!yuw)dM>Tawo>0C^f9e8zD%Q&;}s;8oam?d1$JJh9;CE7J?QS@&f+tz)WSzJ zhJBV=K^SP*S>bp^puk2OJW^eO9^zAw)HA$5J57zb*mR?C_>Wm^+c=0$-yI>VmxqDk zRHmqLOa$+@8f~PMYr)9dqUyqEQHJfx?A9Z4M#!5qYGCt*WP|B}UNy7mZaXETDooG0 z0##ZZPkkN3u_JlSaSIlN$~TB5t3$N?B$}oSB(}-}i1BAzSVm04S*v1kftu0Cg?1UM z1D``h)m>Dj^mkOVVTvqLIGVZAkswnLWFit~p%-|1VxCXL)IgWmfSJ=3)`L%GCl~mO z)h{+`w81P%=R0*zq8@dya8ike^dPk-41Fz!E;Is-R!DPRE1KJTD}6A}U=XN(YtLzZ zo)?r?7<(upXe2|j@&gCOJ|ryDM>P>Q=O=9{J0q4}XC@~JTse!Y%qrGTW25SpWu!x2>}*a2SMw1|)3J8`z?;To@p8 zc!Jc{T6iW?eMV@OV18}En+a|)zJaA|MV6JYT?XB~DHa&sq|iPle-MR+5!b1DTz6d9fCUZ&A>Xd|HN%V7C028uX?TAW82_c;D&FI}Q~M8= zlS$^~1SP^n7Pw&~!@)HgIVqaf@SjkYX!z*bF?BAI)l^2Tuuq07)TxOBUieba`_oUz z0j(KJS$sjIM#5X#Ww5Ymsy|;t*)LPZ2#3k}k{1UJZc<9D%E&ZjP|m_yA!WII6w7M# ziPG$M^-yH6L;1@{lSa!%oTr*wxRqrmQn6<26<{u&j(NN5-GZ}X9K77sN*@>)rf8n` zt2k0MvBhPRnV3 zu#*n=8Tc?Lry@w1A|tObZZ^C*uLQa#b~X8FcN%^^Dw_RWKpTxELd9&@^Mu5gFTTN| z4nSLgxFL$KiKC>TK@R2Z-m)pr32I!wVES1FJcs{l)-boGaSGyzO3)J0+ey0qvmttq zg!uAoayd^!Rah2lT$F}nTp`=lrb&Mv(gZb&BC_5ZNQHJ;=XhqtsGi#N`Kb1m)YmCY zBLf;`ws`ZbXdPAIMtQ<1usMd5hKNg#C57AT488sD^#m?7C8s0R6R6_3; z^Dw2{v@EA!+i&X=RCH*+I+>GtmQ>~q$5y#BTXuyN`l!;95xP0 zcm=J@bdO4?^pmeFJN0g@M6QZvZkTTL?H)k4@c*d%?ZjIrQ542}e3_5mUr?~K2MFa_ zzOpB>uyy$l%g_n0TCHt=6_y%iq0_;_r5HD>y2N{{4{@M_>8W^=e@&Pv0 zqNO#P(9~N|_Mt7bY;x6^q-RVSx+5+*{t#NL8|Jx^q>PWMCR!uC_9ara)k7{YOX?#- zs)lgN?stSiJ3#A&&anuNq2g-~+T(Wlq`qd-XV=MeXs6*>@Y`XLTU4x9P$nM#42*lW zWcG@7{N?YXGAX6luw41DLK~|f_~?}vf;Xm`Sm) zX4CP&b3&_GzM4z&V1<``?fl#JIsAjbNFSeC4}d~aKfapajyValO7OJcs-G*%l|V9) ztjd3B&Sf0`zNT=iv?{c|c)|IZ+B;e`D2r5u2@duy$rCbg6ugr?2hX~haS9|pjH5)=n(58&S=yB=#k<;EuOrJfY;QO!IbTHn?3S_AA&n}EJDx?F zjfy@QhYwde6t5_7t+1Gzt!3<$$d!o%ZFSZfTf{r4y55fTA{Os$4GRMyv$LP{8u7t; z#kp(V5TfhuuPnJ&W`tp$Di$8y@n|dkeH6}%^i*t1^+UG)%C zJqM+O$mnYA1K19OLceiD*l2w+ti`eEgCE37QhV=e>Mw1oXs>%g9(5^1@+rSK*9cL) z$tCBLs8PaJlF3>ACy6n4v!slJCFiTPoS!&Ms<^iB8i6Ag^5bz%1Fn;w(Gc~#@pA2| zg+@WDiuG>ua|M#$FHJ41v&Rp98j>3F(nsSl zDV(t|b44^J7OSF$O+?LDz)PF?z#kfLjqqI#C|uE(CMJu~=+s*F0Usx~e(vNe)4=i3 zDrj!l8$s0+y9kRey*&zJvn!E4iVsH5gjwS~Z7v%iryXjY@!GOY? z?d7V=D#zSbjb9w29xA31l0PKXL07IW`JnD9t%YAS$2Q|Jexk)EvDc>e}zWJ6V?&-gQ z^=G-Q+Dn0W)hhtLj;s>|CZx=bznxu*0K!Hgsxko2{pEmL03^Tk{4Xuq0R}h{-XPT=)wX}e$mc!kbTSDh0#^}>f8wE+e#Ep!#~8Z8kj5(dvE7%Ms4sW zVWaY6)~K}BINw2%1xyoDePUO|^55cafNnM3vtR8OxLR#p8{*X#$CG-k1fF%jv^Z-& ztMj;akaF57%rZ3V0bnF>dw_ z>5qgznkmAj9W)y`4#++CZ{9KdPVu<={Qmx;A;^@)>%Z;k{cR5@X=`*7Ot^JA)5J0S z`V*k=A1+Wgij5>y1&DGKI+W|x28!&Ps4@3*RbQaji6egsT%&RCn*bhbyN;FK*qVl&(66!7G2!WcNB$_FqREd55a11 z*h@r7alS};j)-kGTVoBF8Qa_2vp}Ef4ncb4fi%gZM@0K1yg*OdLt@~XnCcIj2P~9R z04D7_R0&9rMsWSjpujL0TS-Asm5I+gZx9FXHu`-8ZrV2PLiml7v01hR205=^tARU+ z%%LX0El3?CCGX#2QK2_Y$s^%u5BK5!CF%$)U%$ER7q)9DHxb5ix7o(Buxxp-D@q_5 z(hF*2H_+YJ=Oj_D{!X0C0njlu@H79yV(jFLv*uz-43Mc-%Wy~EJf(J}@epCa`;?XW z5CagHCy0Ap$K*vkG02Ej=>2MQcTGu^jhaBdx+8aey$YD15 z9?x`Vx^fjCZA223G?J%lXRKo}SW&p$xK3rI0RD!>7}RKrcGqd>v7B`gvDe7wYeRU} z=syx21*cBx`3#k+$9Q1S?7EsLUIjME$avnjzh5h(L=<0#*7v3O8O?msX}M*{#~YWv zMmbC~Zgwih_N4MR**9jJ6xYbG0=(m#<@dr7&nGI!e@4q!#N z-m@b2wc7)(Wx_VR#Md=2XFa(Ro=L^p!&(HcH(q{ zp3~cPwOzjVa^s!k%?;!aDd}53dNVMkPw!XjS_cMZsH)Y-p3R{UZ@D~}*dAD4u`uV; zxNIP+mO02(*wR>jL{VhMRe$*QZTPbt@(3W&6j(hFC!xeOuss8A4<415nkw+GE;Y}) zUJXnxm1(EXrwq{e!qvGRW1?G+UqDqu>#&{p)J*bMglNm*`rezE1jeGTHLZXeie?eP zA}KzGr;?5nooZmHFR5{*Q9S4BC2cP4H#11;U^e6*MC_E7wu9}h3bUVgpn1_!;9j?46aeC-K@e!@TDKIIEqx5M@eJ9d2 z@F-sEpW^uqqmGA_Nib+*jMz5P-SI3>xu23{Bs|)G%Gmmix{y6zO-i>_GLDb_^lU^p zACj($jGR*WpvUE#EOR^6Ug{yj&DG`hBpb~GgoiG3d0n00DC`8rVS$FT{?guNYb9|+l=PIB0+^xt% zp6P#~&k6bM@dLHN)7M7hZ!P66Ytr4gXF^;qCiT@aZv;NW0_uK!D7kIC z29&w9FLu7^t&CQwMA5h0w*1h!4D=%+dyR**o1RFdp+c0oyArqm_$L7pzAl<QPL% z(PM>{LCe>Ss8jjE^WqFiOM;Nnb>~*#Wrc&AsUE0RN`O7~dk4JjK!pg|9;9?igAo3M zTn#q^@hyK5Dq+bOmrT(e2e3Ca2gxaayO-^b% zRC5g;)uRT+av5oEvtLzJFfy*9VaJ@3TIn6lR2Q4genj@sn(mud+S&HL)n3-ZDhqR$ zLE@=Cp2#bVrXm-x*$`};Ag^8{Tm33{N&UrBw1S!A%TaNn202%6QRGKEkB#Ga71P_x zKo&!AA_xhDQ*Eu>!?9j-+@gH?(HhDpm_$$WGU8Ta{HPwa6EL29?;Os^zEY`Yuf zF=W-wML*n-&VzI^TeH;EaDbTky3W?R@uVTxo~fcBKGt@kz?^>0<`HL9bYC*|LbMNH zA-Wwh52v=v&ePYZLp{p^_v}Y(HXG6Qx4MV)y9a#u&>{ttYiA+wlr*p#g;W(f^&vYMJQ_)vF3Q5r(C&XXby4?Sf%;hBD zWTL;@Y}PqSMAYtpLKLs2?|vrlcH-sW%c+@51YKJENaWnu;2r7UvYfTVcl=ue?rFrF z!@vy2Z{(`&c(-Cj@OISrB-hMS>7tn-$allykhF>=_$yghlEYl??XC45CcD#Nbc(#= z4-PC8)q!SK%T`vi03%&KcLyc*A*6>80}w5eTgwIB1PAUkCK~P>UO>`Jg#Qz=`$19(8ViVAILmo3hVA#LUy@>Cb8@@+X&k3EB83A9Uj91VOi&5n&&|L_rEk03sPwm&!a zY`VZ7NEKf5bQpee1UyU{;DPwO1LcU0SHhtNhK^{C{~`OVi5W+j^ev}1;J142gR=-k z$p=CLh$yh6bLv9DgYl1FPa}eU$lWWo5!wTRX~cdc3pg^K=ZDTv4o=y~zIfDp@2^aT z%Gmn!4?1|1-ty-v%$ zgK6-s(aCVF_;ka+%U=opgsCyU;)JzKEZKocPIodRs{*&Ho8$Zx^_@T^9pEFpxSvz; zS4+C#4U9`8j09Z#y#dC@azS!cu(evRNlGfD9flyT1b21#_AkKG1LlyKntl%$^z%Qu z(o9ldyNU$$ordg)R4C7naNBRL^qwuatnWZej#)O@H+iN4apCyzV9yKi^NXBMqAnN* zMZKTdiFPe&_vNJhwV`;+`?N@U!=qLG~1BIqf^BhbYv--oMZjT2TAY_o#wR7}{81$a} z4Qx%VP{d8Cd&HN}b5TG*uImfY6pN&I_z&SkfD%$3sB7JA@K21i8V{c zeaYI!Y_2Sh(A8<+ssG;8UmEtQKC$!ywD0Mg`}macfE$kn@o>%fmXX-t!eC3(5va)k zP%w5SG!TY2x1C7MS^uj)Zf&aED7t`N_1+bhyhk)fL_(zX)aK zJfX4j+UEzOjQ3&nk<_Q(N<-0DYUW$2BECZE`6i;uw}|hi;p8EEe3(`*P!`;7n66Wm#auw6J%_Vq3dMCI5bhy=dsE#l3U}&-P+Ttf$c>JVCBs@YsqDV8$Fm0 zUr#{@`G|x>p++T13>z;}!>A0wB5u^0`lGi4au<^hk#{*8PF z$+ZfJ^n&+}>Sm<;6Y$J$#dsfkB|(HeyWtM$n0-!$q30oViZD(Ev{)DS7P1rgHzBNV zq|%AQLisYQ5>=wkRip|F#!^xFJlJ!Blo#^`{3jxIb*rZ%$0dLwbCTNpF;!K{cXdIi zMQ!oM@t)@Kn)+GsB;}QP??AAUlzJ+y_G8T%r-u(WG|B*xJe#DKt_<)}?t4bRCeL0U z*H_XP*_C~($kB6%%K8pXkbcJ?QZBN*oL>f!s$JQ#O?-VFER{Vb;o*jzkLR~{eKi^c z*@V8e4kP8eW?$OYV1-iB>A8%{Kp@{cugD8vd32$k1=;dVK8$xSdRJ}_E zt!l7OBl4RaAW3BiH^D|T>w0NcuZq8urxW^GV$Di1PBX>u<0+GPpw2T7Cd0LUbFX|( zqgzi!MSCL+yD`O5)Yxi#R(|_@6-enjf7XuXe(~@=$B3Lv^a(K`N`&u*bpy&ip?Di6 zP2x3`1(D$&ze;bi7Rq}7s}OkApi!6;>MN%Uk5{Um{^kkYt8F2N(i$=Fww-s9$3 z^!>C2cuhIbsLZu%Qx^gCvMTk3B@*7I_d%28K0h(P zr&iMo>hw8ND1iFf(MRa>w?&U{gLh`23p0+yt;gCm7WNwi!7`r1Pstm$dlWs4VndJw z<Mq4A_UWQXZ4e_Po54ok0wPf z*BwwE7m)&gL83^xT~Soo+zuG9sYtQ(bHuzF90-C`P@eGAKWh|i^w^?b&{6}_%<6PL zMa$X~JNQ9EC-+jYv5knK9;QgpI}qM}ThgtNW`m7P--bF=Mw<3xAMeP=lX*S%Vk_mc zK@jV6qeF1vVJXI$#p+?V>p=D%EAC<7n}tXlCAGSleo!h|B&IsSz*+YIeJOcX-03az zF0g4$j(mlIurT!V)33jX$BAM$!eGY2AHQ;}%Lg-a)eVkfnrJqwJR?m64I4{`9hn#z zze;X~XDd>ijtMUNf>u=+B_*2A^^SdAcV7`)R&(md94S`HYZy81x|BG{j!J|uJ^8DrQk>-;&)Ng#fBrdNg)p~}qTUGI5lE%DfNj*IXX;rTYSF(u zL}v0}YJ+))a<7ZVY(rTOl5VdjW21XbyjxI_cRZR3W2q$Fi#buJc+BkU3x1S9{p36u zpB@5Fq3Mq0k7=bn_>AR>&sm*z@FwF*upJY*#;$TaJcRkK`zdMtoDW@oeOT{Xu&g{0 zJGbK4J4;CAe`Ea-vav^QYGaNw60~!L-{bBQiw?p#Z+)hQ!fc^gr&N7$Q%J)C2$OzZ#S z`m2!b4aQFHQo;bDm}qPh;!Gj_7<++3p(*Uz!X5O;Xh9gKzKRv9R zu2obcdVq;ui*Fk#IxX)}y?7i@zR~UL%Q>84H;=irtFHpiAU9i>sw$prisX)h&hPpc z=K6sGf9XqQmTiMeXX#+yamYT_ZKrggJp{<96|l*46|h&|vw`)W=pPlwjSbfCpF4Qw zut0G*5@%=IOclm5Q`Q}=*!0&^7_;eC~x0sjzjI|)7_Cr8;rqGz*zA=>~d7thg zb$}_(Pu3>GBZ_cUxkHZt>`#sJ^?pkg1^dZxlf3sOaT@tL_o4-riSNJl#5=kc}Oeo^zdWCEf zw(w0W?tCo*iv3I756dDo{FoX%xZ@3P)hUW#*Ey5&5}R&_3;>H3soDr z8<_5^j48G>*`ow(JE*O6W>SN2{zaes&BBwF@A6nvpP4Y7nJ`Wr2DeQ22^%2J6z`*A z-yToFi&vsM{i%W^4hGgfa7GVq_P2M0+cgKjL=P_HD(AWwwMnnCrwRF7on{QRE+2j-9o#RZKJ;PIk8-(J*f#P4k56PG`Cck?ja z2X_+%$^qDfO@6=leJ1Imhc`Y(bw2qvj?7Jh$H5N(fe@+NnZ~34#W)}+dp`dUk9YaQ z=a1=)7?ZbM>rT^Iuaj8cMkxW9WH^ub5B!L&i3s#KVkDgWuLuAHwRf3C&J% zZMB8|fkyFr{@+~-FkQ3ImS)GheGiwrk~29F2_PH(pSA4*zNN^ z*#z_jfPS^~i$71)ABcoVI2lCt2T&;o>Kch zBj^29b`-KEh%D+6bjQ8Vu$?nXiRbSY+y4+$)`$&pWtaghlT zl=RJ++AqFkMlfK!lgV|uAfKvI<@ujM6Da-2D;iK}!`7nj?) zd4)EUd!MM{yKNp!rKc7@SFToId^MF;;T-VtQ>Qd@L29jxk1_I}MD6I@h<-@iDZKTV ziaNC$u~_o?&N85zg)P6(hH}D|iL3l)jLnp6?MfCY)o}JAYyzmB8smia+o&jGo&(V^ z48y;KPm0#$`VRXmOp$EIa~0()*FjYbX6GoWS)z1rwVf&aT!vVriqyen>;Xjk^-Wtc zH>j`KVin*vbA+8wamHqq#!30&z5;OpU*Ud6`wk;kw- zMuiD)Y0z%klOE}-fz3G7JnG>SM0I95~jaq(Tfvklc?prNi_93>XGi=rE((Ix}rYe?^nR)^a3N?Nk)m2CLAuR1S zm9;M2_w@(?Rt6Nx*RRqDm;FNCq3yKG)JXpv?-@={R!JS6b47~GYc?I26?tYpZ*Y<0 zuU_zYTgHq0ozUu!;(+e8L(2~Yp`8^)Fj$E}L|HfQXLi&kM3T>;g^0=V%rcE^WDGW$ zzRhBZe5P5)UgTy&b=35Q!;a0}@YA3yc6&olBm+LfPPXZ(FsDXvM0GT=`)J#I}8k6>l@u!t>IS zRhdQo-m7T2-;yn6<vH>RRiRRO9W@R509h`t|fYu^3t@#Z?d#f>FT&%R7FxC zH}sw{2V$#zoG)dgiZ!&m+;ALiEe`baxd;Xsa45l|zen=n1O z^x>$gL6sOf^%wrVs^j9{;SR`Hj%WM1-yqO?8u_1ElOv7=Bq)PP0zX(pH`7oBpAQ!b z{hs`sw!PUEDt@^e3Fyw^s1jZ1uhhl-YQx0x`X)SqqE`b3(Q?mWjA&^c=mxU(VDAyR(qppZ6iFX^pKYqbZSB>4sVi>|33 z57{GH4*vVHi|~74kJ>(mVyU$Y-va7=LLy6&OaB@3uT`?apPFowa?PI#4?52VS()Fm z+g1hRa#>Dqek>+zIl}Sm9AmOA%0gNa)>``yR8z)RQea)t0o&#*e5~>p)NF9j8xR50 zD9nD3WP$|Z09!dODa|f~A#nkAXbBQJsB7_%cde<&pA z3I!^j2-cOk2DAGQ-cNNQ1TI$z80jFT96Vn{fRKAB67 z&s|FAZBW`yR|ezu#tr!w@OSnO%#zsr1Adx#i_$VIL{jwbF;6-{HSn~+wu!x_MtDq6 z%;dGBQF=I)qB{PKx4rD`+jy`@MyEm{*^?v0m*0VPns;t=^i=_E=V_mUcAK*}grHis zG{nkH*^j@HmOd;*syff}ZK?Q2;l6^P3*f+Bf^UkrC(Ll_IeUbg?8Y6qtWWC^Nt-^4 zmth9vTF|RP*}<)+N#<7pJ5sqy8k;-GlkovL74QsIA~bzPSbYN|bB=;6S$($}_&_q+ zO17^J16eWZHH8I-w|{Og%hUiPa~6{u$>+h*Pddvr^g}dQ1I}v|KweCwrdwC@q!I*P z)5V_BdCAIN-Z!fr&Ph`^ytMr!Er%aCtyBbytNRVevle~ksnh`Uj81}znYX0p$x{lJ z+-V1d)_cZ5wJIdMf}#nd`ef*5rXYZHVgRJGGxR&MqZ08q?n0RphGahFg+K?Z%eZui zKnB!r$Frj~PI~F;2L=48gEGl2i=?h%^&a~Do@xu8;s?Rv&t+$UsvEj1mEBk#z1;6| za;j!iLJ;zZbN&)y(eA@0U?VEY_NL_h?!VWb#0!NslOyG)x1082PC6cam6OB159OLr z=p@h{lD{a4Bdr+8ogbED4P7^%9GhK!h2tRYd1wUyk`v-$n{Y+Ndreh^4mp-4>ORgC zSf>>_ZieofruoNTjy;{fU&=b;1OLs{C#-Xm6val`ZMp*KlyhI2iG+5s8B+b^LKYk{{+1Mw4~Ggp|@c6V@&t$ zqJcmUqtnz=HU~;KIYa}p*qUVvTisY0BSa+Nq~*ttrhv@Ey^$0_gZtURhe67@cLck2 z8}jQiSdYuz^f4CIF_qNk-YudGE^sz4?m7&)TG1t%DFUUse~6Pu3iooH;)=mnNN)C) zTWV(&?)GO+WyRZ{E_w%Tb*HRPzpu^Tm1g#wn~%ru(Y-qR=JnU~!*w_b7iwec^k$zabV!}r1={2Dt5 zX`GpKI`X+>j2>mublDE<7;EPL>DuJ6UvJ4y8+X!J9nZtyt@JOmP;P*mYR|0rD%=(k zT;UF}Uj<_2eO*j~I@1~8eu6J`RmQH=o@YxK-3(VOADw*;=q~!J47&$LfII?_Oi3)5 zs86`b4^^G$I-6bWM{Mt@hP2Uq?h;cZ@5>i@YYHNvtF$JHFOEh z0w9g)L=jNn8uj9ZZLrBL=Bb&}u}1S_CzlTIWj8flfthTf-$x_1a??{i!}Br7chv2kl~w zqyYesb6La#Gy>>dr`O~UQl`U9!zV~z~PV$^r}5QomfT}?c$i#lw4a#3o4tpgeU(tk}( zYPN8Ki51%{#FX_v;GsOak{sGw*WlYd!e4_A4vI}W&aeh`A1SGw7MU1oya_<>sz-`qWydPyaNNvn3^4^H-;86Tt-Hlf@oda z;xWcbQLO|~V!Eb0Iu=iR6yLcBT0B)W)DI@nS)?hVsI2g+<8fCRZCAWFr{cP+8_TK? z`-Int*`r-pRmNRAZ0Kc0FwQ%IWHvI3&N_w}SE$mc5bkp`E4oOMwJ;6PlR(&1lF{x~ z%0@`fzw=4%xu1`Gh;@5cg5T#Qicw6X!A!FkiMr4=kTxF=g*^WY&{Ti7aQ{67Vllk% zOVp@Skjd>$D?yeJewm@o5(gKHi`3D>oj9 zOfCTejcRXkQ?_|VmM4|Tz%e}kCT)0FhWLd}T-p!bi(LEw`!>FKU~K+@KQRInRla@O zy0`Cp(Bm|b5zagff&);WPjyPC8Z`BL4bYJA7niJIODa=5D-I9%Q02pVM|F^^SqK!_ zNhWHvC6Uzzz4HgrSeujCh5uB~nvphy&kX~rKD{*iK-63m-I@F&F9CkM6>wb(OSZZi zk$C+rfe&5dGTYo04dv($zp^YN!exC#-48H0QzNm{{TGAwPsS+tTg{!ShWggnHl0AL z7AkVVT!pspUJ39OwrknwQz(l&ZV)#j{+7JEQ5u2zD*caa&i@zS{>(79L?Lu%_qdy%ioP|(0!yf?3eiwaz=s#+kUcy5c|c@w)^w_i zMX3Kfo1%7;h3Nw=hqZw)(N*V_Om(ZQPKbhvam=*f-1lxGD*9!046q8^mp&(?vWs>w z8L3YojH2hH$+&{4RiUd+Aj1+)ACnKUmp}ZBMn~Fl(Gk;mfVZHLs<21S%M~pb<1^TS zfwu~E#I%Y`ud3F}%ECxGgD-bsirl$HzV_+Q!_p&bvt98zymvew0 z$ZT+?F&3;+#?PxF4|bytBOUqd&}-VShF^XCk$88mcQx!HUT(pdWd-M56ZL9VkzI8h z;EhN{UBVr|7nY!@FD1>obMtW)h#O0?vD_oo3Ay~8w+lny{Ll_Un`^Dox*ndZs=sQq zuYkxLB!!_ey-iIiKJ&v$BYD6&eVsRtddzE`@yYl6c==E$tv!_b+d1mhwad+=y(0MX z-~7!3(qYpx_?$TYB~Rs~+ekI|)Gh(LETo;UBn?l?rTsPNt9mjE=#6`{DnTKr6f>Ke ze!?@8C-He)hD7>=2H!?n*7KcRI$J;7-EIM+rI|uir_8GO?Rd#wK#F}A(xc66zSldu z3VH+}@j-|;5xJ}D77EvQ_ti>%LgLTATTX8sF%)EH-%^;^GAzHQE!}#SH`H;7S#Uo^ zVNuark)H%rz6B8bma7`EJMG6C9@NIk~e_x~N;WY=|WQ*X@#4yElIgaP!qJTzY?;^4VY zI4YfSG@pY(1Vt=!3v(wzZ`jg_wQMdR63T#=a-*tly?8#zr99`y-xe>L ze<{La@iEb3!!j@1Lx8lunD;l2jvhebo5fl47Z$)d`Q6S5PmPk`u?K%5M~l^!H)&^^ zR_b_{fD;s8LZlwNi8s!($%yf9Ok?kZ8X09p3->LVII4W+J&e?s(J$zeq0dhx{Lf(2 zMKK|E5vM2-WQ(y67hO3OVp5Y$<>tDjZq)WPQjK#Mno4Lu5nM;KgyB@Beyv948%Bvv zyD5P{K>NME6=Yl2I+^p|4)(ZBG+E{Vb33 z^OZgo*pBk?XV=l8>Dfsl(JzbM^PDE|pvW6(W3 zI!%8nJ=@dKe1QWr13rht{tu-Q1=QZ!#Nen!H_y!CwBiXE$0zY0&28-2ISYWjW?4Ym>r^)_zt2x$=xtfoN z7vPhpFK2o?|NiU?Qbia**toUm{5f~5WH??K9k~?|MNrxjh0+~%`hCv0sWks$izlJE zDFZTl+Udb*rK+<$drHBRO)mXH<8Nus18qYAt-KOinBW*&Xh_>#dsXQ~L@;#o`@Bju zP@-;Q^#x$0@b+85f4~{iEL$+`H`0g%hPldm$aPj7j{`gZ*rHQdoF0Z>1-PzxLjEQP7}m#XBE@Eo4eFoVT2KY zsOUaOltjzP`}i_`CKEVV?$M)zKaxX&oqA_+@~iQ*5~4A?q~FaPrB#|J*S*&-(ADKU zTo;dQWgVSdVx3*U=B(MHH4th^Jn9GE#&gdHm=o_*W_z7nUPsS2Vv49CKS2&e{*w0> zlkOZay;T{tlKXA)$3-@J`9a4>IO(xwS)F)3Lr?k2)>;5;E!&AK6+Q?NRR#+&aTzE9 zM?@?|nFt=a%RoveYPsz6lHwtJt&1iz;mk z2Tpsx}Ze6IObPxSKQ_oePhJ;{A8dUJ8{_?b8F zm2Q69wCB~u#≠5CATB<6dM@(r&Ef(je~E=w<~t8L)SEZ$aVv{PG_Xh7$$_Pi9Sf zTHcP{xBLqvvM2~>K$j#yyAX}`@8P6A72&US5-I?HX1c>czYi8#%mp-{)jfGIg9bB# zs7@eQU(FnESm#{^d_F84EckHZ2O*&20lWhhcN3!{spAj2ImiuiFlNNUL|-FBrk1v_ zX@%8#uJorEo2r3}G_1|onH{o&5_ixd{k#A@>!U~a1E@D7+204!kfUckRJ7VmxE4je@sf@QCNvmb6mj&lMPqEm zgn|^xAgQ`ll_QR{2b*Ln;CaeyyW%iHF%p*(ScmFtp9s}94e>`X&w4D@t|2iLrygw7a z6mUH33*q~FxM7J`98fd{P}hG7(Xip}3(){CZIAVT9fXK(q!_FYd|Li!Th;NUd(mit z+bxy-^-NX-XmR&p&i7SCSMkR@>UO`6XB#O2eI8KXcK=|H6axU2q?O5elhXgy+j&Mc zm2Ghx1*0IS1ENpq1VNeA{qIOA9P~b$A=S z1NxgxTI@E)L`H1-gF-=t;Jrmh`ct4wB^yYatXfMbuvz6%&$gjH?@Ml`TGOR!d=tITOz8KXfl=E5MtRJrYrNZ0K=HyA=0)}OVR_@!o&`DV`dpe7)QuLt zH@LEFK~6Jwjo|CMsG3!3-nZ$hdnhZeD4f3Mbb>55E z)4ek;h16`blEJ?F-9&-qZp|X_c}d6H7A`*^2VGmVO02C{CEb|xB&jWrd(QAwP`Y>B zXxQ;Xn0>$Pr<^Gpi53i+(=a&=1zM^vxIurhhNJawHBd$+2N5C&X#i!gi{%mGG7{v7=c{2r!y z^1!TP_Mvm)^TEn%>pBz$8GKHVk!Xa?{u+VomL8X7edktb^$+^^UwaRo|3TK<$;%iZHJY@w0R=O(B56Wt(s|6CK?w_r3(VpLt`0casJ?Dpqh4(T zEiTbB_Ml#J?7jz_q{J9y65xvQiI1Vyw?<2}+>m0U23y}VQfn1xSao8B5qdsvUa!=d z2s&q+R6rM@xF;X@`TPT*`>9F?9g(HLa~DmmU`Tc~8`2UwIF%A)G5&KmCiOUeI2(Y< z@W77bc&l>IG5c+)=y`31GRgCX2g3N~1Fg7+@WXUJvfYB3^T)WTSO$)js1oabbK}|U z$BDRrQ$bze9=BfF84=hKNVzZUe!DHD5E{xNE<@e!tp{NW4=w{!jn1AmR;WBj7OxI> zv^W}g@3Jfdz`E)P%rz)}o~_c5NJvE<;%9$I86Ru6p^~7LW0ZsNsQa9|@)7`-Q+@DT za(RxryqJR_Ni6s$pKEjZDYayG&Wc2R?ge&O>CGwa%5h+$v(et+oS1U->g}6sbrUoU zhtS$m)lf?9pv2p7cRiVKSe}}^?#%lDoCVudsieQFE!6W?Y(qn-HPJD_ugB&IWTN`l z!uA<;Z|v2K)5Q^=_^zjWob-;0ZVhCHkq7k252;z2Asr=nD}S3`&Elboza?RUt`%bk zQ`CF}k;97ILrSvBE(7qw2*|g$t;9!V{>Fz*Wm=cl&0AO-W)te0ztt{QD;umPWjLaSsPZvB|t#RcwStJ?eYGBJ}eWq(=KGTQR&Siq(l`UA& zIxSfQ%rRX9;-vKwdOyGLDNORfW(1RReZI;3j3R2nA5?NN!pjcA`~D%^f7sib?g7P1 zlw|7+gqwXGSO$1$QxXn1a)znohLE zX$6-dN9pO&1T~iX6Jbp8Zw3&MP*?3rg0L=s!>K<2^~i? zD~dB~V>Cho6hj{p(h^o~nn)EtKjxn-cOqP?)6$=EA2ZAueg`LApkQX$u6|P8dj{s7 z_|RZ|<755Kl5D4=zWoaB4JQ~LzpvSgV<$s*k6lopi3hG))nAyP4R)-7RObuZI^*^~8PG39eDJkE)gR<-YO z9}ES#*OyxN>IA{zv<)K@)Z2oc+3>?zIvjYXu1$g1y%47v#iZ1CZNzF>xj(Qee zsB(^>#x=W)wWD&&tJl6gsu!4BRO)Q%t>?NPpPneB(xo-ar(}b!X?O5VcQdzWY6|$k z7zrRlNYgIGb;5kVk5DI#@5zV-)`LF+<4^^_`SI(lUlWW}>4{M}& z&1ibie<-LHGMy8WeCO!-n~l^*1wo@Z@O*B-Vf@ zp>m(UOL%|gAntMe=G3_ancXxV#O=YAD$Z;%D?L>gBLV+^-S7E>dh*12Rxv-ML73n%f zN=i%T;qkHd;k&jLX!w{HqVcDn*473But0;IF+}3P)`}D=a!GqN;&N}&lZ(-_0I3gX z^HkVQFpEHRS+0uV@+&;ahElHj=H@-I(2KoAwnkd)qz_CW2&btT4zIB~0qsQKN}Deu z5C}M2P$Mt^&>4gR=Nn2KTaZYk?&6z?Ag0v?r*3o19Z>-tbi^rM$vkk=xHbpy-de8f zXY%d^c1_8Xv_5iIsPIZjW=_s8E7Y;MFiL99m4quKLt#B0LL8@)356=oG8xTJ#1lW| z#P}GWi=hRep?wu5q6l(`aHvjZ%v1|kryedDUVzl$Kob&VaZh#4VoOD_=GN95bk;NU Xzln?+?*ZUx7M4pohUW{<+1>dE;=6U$ literal 0 HcmV?d00001 From d2cb73d1fb7d6e793949a2a2867b66638543e37f Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 13:05:40 +1000 Subject: [PATCH 017/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 40 ++++++++++++------------- 1 file changed, 20 insertions(+), 20 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index a785c5737c..3e41adfbfe 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -11,7 +11,7 @@ author: scottbreenmsft ms.author: scbree ms.date: 07/05/2021 ms.reviewer: aczechowski -manager: aczechowski +manager: dansimp --- # Upgrade Windows Home to Windows Education on personal devices using volume licensing @@ -23,7 +23,7 @@ Customers with qualifying subscriptions can upgrade students personal (or instit > [!NOTE] > To be qualified for this process, customers must have a Windows Education subscription that includes the student use benefit and must have access to the Volume Licensing Service Center (VLSC) or the Microsoft 365 Admin Center. -IT staff can upgrade student devices using a multiple activation key (MAK). Alternatively, student devices can be upgraded by contacting [Kivuto OnTheHub](http://onthehub.com) to obtain a product key for their device. The table below provides the recommended approach depending on the scenario. +IT staff can upgrade student devices using a multiple activation key (MAK). Alternatively, student devices can be upgraded by contacting [Kivuto OnTheHub](http://onthehub.com) to obtain a product key for their device. The table below provides the recommended approach for personal devices depending on the scenario. |Method|MAK source|Device ownership|Best for| |-|-|-|-| @@ -31,16 +31,16 @@ IT staff can upgrade student devices using a multiple activation key (MAK). Alte |Kivuto|Kivuto|Personal|Initiated on device by student, parent or guardian| |Provisioning package|Volume license center|Personal or Corporate|IT admin initiated before performing Autopilot| -Devices can be upgraded from Windows Professional or Windows Pro Edu to Windows Education or Windows Enterprise using [Windows 10/11 Subscription Activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation). +Devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Windows Education* or *Windows Enterprise* using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). ## Why upgrade personal devices from Windows Home to Windows Education? Some configuration service providers (CSPs) are not available on Windows Home which can limit the management capabilities. Some key CSPs that can affect mobile device management are: -- [EnterpriseDesktopAppManagement](/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications -- [DeliveryOptimization](/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization +- [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications +- [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization -A full list is available at [Configuration service provider reference](/client-management/mdm/configuration-service-provider-reference). +A full list is available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). ## Requirements for using a MAK to upgrade from Windows Home to Windows Education @@ -65,12 +65,12 @@ It’s critical that MAKs are protected whenever they are used. The following pr - Provisioning package by institution approved staff; - Manual entry by institution approved staff (do not distribute the key via email); -- Mobile Device Management (like Microsoft Intune) via [WindowsLicensing CSP](https://docs.microsoft.com/windows/client-management/mdm/windowslicensing-csp); +- Mobile Device Management (like Microsoft Intune) via [WindowsLicensing CSP](/windows/client-management/mdm/windowslicensing-csp); > [!IMPORTANT] > If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key is not accessible by students. - Operating System Deployment processes with tools such as Microsoft Deployment Toolkit or Microsoft Endpoint Configuration Manager. - For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](https://docs.microsoft.com/windows/deployment/upgrade/windows-10-edition-upgrades). + For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](/windows/deployment/upgrade/windows-10-edition-upgrades). ## Downgrading, resetting, reinstalling and graduation rights @@ -80,7 +80,7 @@ The table below highlights the differences by upgrade product key type: |MAK Type|Downgrade|Reset|Student re-install| |-|-|-|-| -|MAK from VLC|No|Yes|No| +|MAK from VLSC|No|Yes|No| |MAK from Kivuto|No|Yes|Yes| ### Downgrade @@ -115,7 +115,7 @@ These steps will configure a Windows edition upgrade policy and target all Windo ### Step 1: Create a Windows Home edition filter -Filters allow you to target the all devices group but to a subset of devices using a filter. In this case the filter will be based on the operating system SKU. This will ensure we only upgrade devices that are running Windows Home edition and avoid upgrading devices that are running Windows Pro/Pro EDU edition which can upgrade using [Windows 10/11 Subscription Activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation). +Filters allow you to target the all devices group but to a subset of devices using a filter. In this case the filter will be based on the operating system SKU. This will ensure we only upgrade devices that are running Windows Home edition and avoid upgrading devices that are running Windows Pro/Pro EDU edition which can upgrade using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). - Start in the **Microsoft Endpoint Manager admin console** - Go to **Tenant Administration** > **Filters** @@ -133,7 +133,7 @@ Filters allow you to target the all devices group but to a subset of devices usi > [!NOTE] > Ensure you’ve selected OR as the operator in the right And/Or column - :::image type="content" source="/images/change-home-to-edu/windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: + :::image type="content" source="/images/change-home-to-edu-windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: - Optionally select scope tags as required - Save the filter by clicking **Create** @@ -162,7 +162,7 @@ Filters allow you to target the all devices group but to a subset of devices usi - Click **Select** to save the filter selection - Click **Next** to progress to the next screen - :::image type="content" source="/images/change-home-to-edu/windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: + :::image type="content" source="/images/change-home-to-edu-windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: - Do not configure any applicability rules and click **next** - Review your settings and click **Create** @@ -191,6 +191,7 @@ The edition upgrade policy will now apply to all existing and new Windows Home e - Business Justification or Reason for Deployment. ### What is a firmware-embedded activation key? + A firmware-embedded activation key is a Windows product key that is installed into the firmware of your device to allow for easy activation of Windows. To determine if the computer has a firmware-embedded activation key, type the following command at an elevated Windows PowerShell prompt: ```powershell @@ -206,16 +207,15 @@ A firmware embedded key is only required to upgrade using Subscription Activatio A multiple activation key activates either individual computers or a group of computers by connecting directly to servers over the internet or by telephone. KMS, Active Directory based activation and subscription activation are bulk activation methods that work based on network proximity or joining to Active Directory or Azure Active Directory. The table below shows which methods can be used for each scenario. | Scenario | Ownership | MAK | KMS | AD based activation | Subscription Activation | -|-|-|-|-|-|-| -| Workplace join (add work or school account) | Personal | X | | | | -Azure Active Directory Join | Organization | X | X | | X | -Hybrid Azure AD Join | Organization | X | X | X | X | - +|-|-|:-:|:-:|:-:|:-:| +| **Workplace join (add work or school account)** | Personal | X | | | | +| **Azure Active Directory Join** | Organization | X | X | | X | +| **Hybrid Azure AD Join** | Organization | X | X | X | X | ## Related links -- [Windows 10 edition upgrade (Windows 10)](https://docs.microsoft.com/windows/deployment/upgrade/windows-10-edition-upgrades) -- [Windows 10/11 Subscription Activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation) +- [Windows 10 edition upgrade (Windows 10)](/windows/deployment/upgrade/windows-10-edition-upgrades) +- [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation) - [Equip Your Students with Windows 11 Education – Kivuto](https://kivuto.com/windows-11-student-use-benefit/) - [Upgrade Windows Home to Windows Pro (microsoft.com)](https://support.microsoft.com/windows/upgrade-windows-home-to-windows-pro-ef34d520-e73f-3198-c525-d1a218cc2818) -- [Partner Center: Upgrade Education customers from Windows 10 Home to Windows 10 Education](https://docs.microsoft.com/partner-center/upgrade-windows-to-education) +- [Partner Center: Upgrade Education customers from Windows 10 Home to Windows 10 Education](/partner-center/upgrade-windows-to-education) From 6eb76af0a9006e5ad40fa64dfc413ba46e573d2b Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 13:17:44 +1000 Subject: [PATCH 018/109] Update change-home-to-edu.md Fixing missing hyperlink --- education/windows/change-home-to-edu.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 3e41adfbfe..597edfab14 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -182,7 +182,7 @@ The edition upgrade policy will now apply to all existing and new Windows Home e ### My MAK key has run out of activations, how do I request a new one? -- Increases to MAK Activation quantity can be requested via Web Form and may be granted by exception. +- Increases to MAK Activation quantity can be requested by contacting [VLSC support](/licensing/contact-us) and may be granted by exception. - To do this you must have VLSC Administrator, Key Administrator, or Key Viewer permissions and provide the following information: - Agreement/Enrollment Number or License ID and Authorization. - Product Name (includes version and edition). From 38dbaea485d0f55a82f754b3d2b6ff40c3adf44e Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 13:24:40 +1000 Subject: [PATCH 019/109] Update TOC.yml --- education/windows/TOC.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/education/windows/TOC.yml b/education/windows/TOC.yml index 717ae6c902..2f49cce168 100644 --- a/education/windows/TOC.yml +++ b/education/windows/TOC.yml @@ -65,6 +65,8 @@ href: s-mode-switch-to-edu.md - name: Change to Windows 10 Pro Education from Windows 10 Pro href: change-to-pro-education.md + - name: Upgrade Windows Home to Windows Education on personal devices using volume licensing + href: change-home-to-edu.md - name: Chromebook migration guide href: chromebook-migration-guide.md - name: Change history for Windows 10 for Education From 0ef9165d0a17052a57fa27de06d7b7b7a1cf920a Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Tue, 5 Jul 2022 08:55:31 +0530 Subject: [PATCH 020/109] Acrolinx Enhancement Effort --- .../wdac-wizard-create-supplemental-policy.md | 16 ++++++++-------- .../wdac-wizard-editing-policy.md | 4 ++-- .../wdac-wizard-merging-policies.md | 2 +- ...ender-application-control-deployment-guide.md | 2 +- ...-defender-application-control-design-guide.md | 8 ++++---- 5 files changed, 16 insertions(+), 16 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-supplemental-policy.md b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-supplemental-policy.md index 67405ee59b..65a4c8ef77 100644 --- a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-supplemental-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-supplemental-policy.md @@ -30,7 +30,7 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -Beginning in Windows 10 version 1903, Windows Defender Application Control (WDAC) supports the creation of multiple active policies on a device. One or more supplemental policies allow customers to expand a [WDAC base policy](wdac-wizard-create-base-policy.md) to increase the circle of trust of the policy. A supplemental policy can expand only one base policy, but multiple supplementals can expand the same base policy. When using supplemental policies, applications allowed by the base or its supplemental policy/policies will be allowed to execute. +Beginning in Windows 10 version 1903, Windows Defender Application Control (WDAC) supports the creation of multiple active policies on a device. One or more supplemental policies allow customers to expand a [WDAC base policy](wdac-wizard-create-base-policy.md) to increase the circle of trust of the policy. A supplemental policy can expand only one base policy, but multiple supplementals can expand the same base policy. When supplemental policies are being used, applications allowed by the base or its supplemental policy/policies will be allowed to execute. Prerequisite information about application control can be accessed through the [WDAC design guide](windows-defender-application-control-design-guide.md). This page outlines the steps to create a supplemental application control policy, configure the policy options, and the signer and file rules. @@ -40,17 +40,17 @@ Once the Supplemental Policy type is chosen on the New Policy page, policy name ![Base policy allows supplemental policies.](images/wdac-wizard-supplemental-expandable.png) -If the base policy is not configured for supplemental policies, the Wizard will attempt to convert the policy to one that can be supplemented. Once successful, the Wizard will show a dialog demonstrating that the addition of the Allow Supplemental Policy rule was completed. +If the base policy isn't configured for supplemental policies, the Wizard will attempt to convert the policy to one that can be supplemented. Once successful, the Wizard will show a dialog demonstrating that the addition of the Allow Supplemental Policy rule was completed. ![Wizard confirms modification of base policy.](images/wdac-wizard-confirm-base-policy-modification.png) -Policies that cannot be supplemented, for instance, a supplemental policy, will be detected by the Wizard and will show the following error. Only a base policy can be supplemented. More information on supplemental policies can be found on our [Multiple Policies article](deploy-multiple-windows-defender-application-control-policies.md). +Policies that can't be supplemented, for instance, a supplemental policy, will be detected by the Wizard and will show the following error. Only a base policy can be supplemented. More information on supplemental policies can be found on our [Multiple Policies article](deploy-multiple-windows-defender-application-control-policies.md). ![Wizard detects a bad base policy.](images/wdac-wizard-supplemental-not-base.png) ## Configuring Policy Rules -Upon page launch, policy rules will be automatically enabled/disabled depending on the chosen base policy from the previous page. Most of the supplemental policy rules must be inherited from the base policy. The Wizard will automatically parse the base policy and set the required supplemental policy rules to match the base policy rules. Inherited policy rules will be grayed out and will not be modifiable in the user interface. +Upon page launch, policy rules will be automatically enabled/disabled depending on the chosen base policy from the previous page. Most of the supplemental policy rules must be inherited from the base policy. The Wizard will automatically parse the base policy and set the required supplemental policy rules to match the base policy rules. Inherited policy rules will be grayed out and won't be modifiable in the user interface. A short description of the rule will be shown at the bottom of the page when the cursor is placed on the rule title. @@ -78,7 +78,7 @@ The Publisher file rule type uses properties in the code signing certificate cha | Rule Condition | WDAC Rule Level | Description | |------------ | ----------- | ----------- | | **Issuing CA** | PCACertificate | Highest available certificate is added to the signers. This certificate is typically the PCA certificate, one level below the root certificate. Any file signed by this certificate will be affected. | -| **Publisher** | Publisher | This rule is a combination of the PCACertificate rule and the common name (CN) of the leaf certificate. Any file signed by a major CA but with a leaf from a specific company, for example a device driver publisher, is affected. | +| **Publisher** | Publisher | This rule is a combination of the PCACertificate rule and the common name (CN) of the leaf certificate. Any file signed by a major CA but with a leaf from a specific company, for example, a device driver publisher, is affected. | | **File version** | SignedVersion | This rule is a combination of the PCACertificate and Publisher rule, and a version number. Anything from the specified publisher with a version at or above the one specified is affected. | | **File name** | FilePublisher | Most specific. Combination of the file name, publisher, and PCA certificate and a minimum version number. Files from the publisher with the specified name and greater or equal to the specified version are affected. | @@ -87,7 +87,7 @@ The Publisher file rule type uses properties in the code signing certificate cha ### Filepath Rules -Filepath rules do not provide the same security guarantees that explicit signer rules do, as they are based on mutable access permissions. To create a filepath rule, select the file using the *Browse* button. +Filepath rules don't provide the same security guarantees that explicit signer rules do, as they're based on mutable access permissions. To create a filepath rule, select the file using the *Browse* button. ### File Attribute Rules @@ -105,12 +105,12 @@ The Wizard supports the creation of [file name rules](select-types-of-rules-to-c ### File Hash Rules -Lastly, the Wizard supports creating file rules using the hash of the file. Although this level is specific, it can cause extra administrative overhead to maintain the current product versions’ hash values. Each time a binary is updated, the hash value changes, therefore requiring a policy update. By default, the Wizard will use file hash as the fallback in case a file rule cannot be created using the specified file rule level. +Lastly, the Wizard supports creating file rules using the hash of the file. Although this level is specific, it can cause extra administrative overhead to maintain the current product versions’ hash values. Each time a binary is updated, the hash value changes, therefore requiring a policy update. By default, the Wizard will use file hash as the fallback in case a file rule can't be created using the specified file rule level. #### Deleting Signing Rules -The table on the left of the page will document the allow and deny rules in the template, and any custom rules you create. Rules can be deleted from the policy by selecting the rule from the rules list table. Once the rule is highlighted, press the delete button underneath the table. you will be prompted for additional confirmation. Select `Yes` to remove the rule from the policy and the rules table. +The table on the left of the page will document the allow and deny rules in the template, and any custom rules you create. Rules can be deleted from the policy by selecting the rule from the rules list table. Once the rule is highlighted, press the delete button underneath the table. you'll be prompted for another confirmation. Select `Yes` to remove the rule from the policy and the rules table. ## Up next diff --git a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-editing-policy.md b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-editing-policy.md index e74fded92b..5a109b3b15 100644 --- a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-editing-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-editing-policy.md @@ -39,7 +39,7 @@ The Windows Defender Application Control Wizard makes editing and viewing WDAC p ## Configuring Policy Rules -The `Policy Rules` page will load with the in-edit policy rules configured per the set rules. Selecting the `+ Advanced Options` button will reveal the advanced policy rule options panel. This grouping of rules contains additional policy rule options that are less common to the majority of users. To edit any of the rules, flip the corresponding policy rule state. For instance, to disable Audit Mode and enable Enforcement Mode in the figure below, the button beside the `Audit Mode` label needs only to be pressed. Once the policy rules are configured, select the Next button to continue the next stage of editing: [Adding File Rules](#adding-file-rules). +The `Policy Rules` page will load with the in-edit policy rules configured per the set rules. Selecting the `+ Advanced Options` button will reveal the advanced policy rule options panel. This grouping of rules contains other policy rule options that are less common to most users. To edit any of the rules, flip the corresponding policy rule state. For instance, to disable Audit Mode and enable Enforcement Mode in the figure below, the button beside the `Audit Mode` label needs only to be pressed. Once the policy rules are configured, select the Next button to continue the next stage of editing: [Adding File Rules](#adding-file-rules). ![Configuring the policy rules.](images/wdac-wizard-edit-policy-rules.png) @@ -47,7 +47,7 @@ A description of the policy rule is shown at the bottom of the page when the cur ## Adding File Rules -The Windows Defender Application Control Wizard allows users to add rules to their existing policy seamlessly. Previously, this would have involved creating a new policy with the new rules and merging it with the existing policy. +The Windows Defender Application Control Wizard allows users to add rules to their existing policy seamlessly. Previously, this rule-adding task would have involved creating a new policy with the new rules and merging it with the existing policy. Selecting the `+ Custom Rules` button will open the Custom Rules panel. For more information on creating new policy file rules, see the guidelines provided in the [creating policy file rules section](wdac-wizard-create-base-policy.md#creating-custom-file-rules). diff --git a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-merging-policies.md b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-merging-policies.md index 5110ed45a0..172bcc1cf7 100644 --- a/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-merging-policies.md +++ b/windows/security/threat-protection/windows-defender-application-control/wdac-wizard-merging-policies.md @@ -21,7 +21,7 @@ ms.technology: windows-sec # Merging existing policies with the WDAC Wizard -Beginning in Windows 10 version 1903, Windows Defender Application Control (WDAC)supports multiple policies. Before version 1903, however, Windows 10 could only have one WDAC policy. Consequently, users were required to merge multiple WDAC policies into one. The WDAC Wizard has a simple to use user interface to allow users to merge multiple WDAC policies. The Wizard can support up to 15 policy files as input during the merge workflow. +Beginning in Windows 10 version 1903, Windows Defender Application Control (WDAC) supports multiple policies. Before version 1903, however, Windows 10 could only have one WDAC policy. So, users were required to merge multiple WDAC policies into one. The WDAC Wizard has a simple to use user interface to allow users to merge multiple WDAC policies. The Wizard can support up to 15 policy files as input during the merge workflow. Select the policies you wish to merge into one policy using the `+ Add Policy` button under the table. Once added, policies will be enumerated within the table. To remove a policy from the table, if accidentally added, highlight the policy row and select the `- Remove Policy` button. Confirmation will be required before the policy is withdrawn from the table. diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md index d87ee2f357..b2a21747f1 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md @@ -33,7 +33,7 @@ You should now have one or more Windows Defender Application Control (WDAC) poli ## Plan your deployment -As with any significant change to your environment, implementing application control can have unintended consequences. To ensure the best chance for success, you should follow safe deployment practices and plan your deployment carefully. Decide what devices you will manage with Windows Defender Application Control and split them into deployment rings so you can control the scale of the deployment and respond if anything goes wrong. Define the success criteria that will determine when it's safe to continue from one ring to the next. +As with any significant change to your environment, implementing application control can have unintended consequences. To ensure the best chance for success, you should follow safe deployment practices and plan your deployment carefully. Decide what devices you'll manage with Windows Defender Application Control and split them into deployment rings so you can control the scale of the deployment and respond if anything goes wrong. Define the success criteria that will determine when it's safe to continue from one ring to the next. All Windows Defender Application Control policy changes should be deployed in audit mode before proceeding to enforcement. Carefully monitor events from devices where the policy has been deployed to ensure the block events you observe match your expectation before broadening the deployment to other deployment rings. If your organization uses Microsoft Defender for Endpoint, you can use the Advanced Hunting feature to centrally monitor WDAC-related events. Otherwise, we recommend using an event log forwarding solution to collect relevant events from your managed endpoints. diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide.md index 9ae7311920..05fbd4e9b6 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide.md @@ -30,18 +30,18 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -This guide covers design and planning for Windows Defender Application Control (WDAC). It is intended to help security architects, security administrators, and system administrators create a plan that addresses specific application control requirements for different departments or business groups within an organization. +This guide covers design and planning for Windows Defender Application Control (WDAC). It's intended to help security architects, security administrators, and system administrators create a plan that addresses specific application control requirements for different departments or business groups within an organization. ## Plan for success -A common refrain you may hear about application control is that it is "too hard." While it is true that application control is not as simple as flipping a switch, organizations can be successful, if they're methodical when carefully planning their approach. In reality, the issues that lead to failure with application control often arise from business issues rather than technology challenges. Organizations that have successfully deployed application control have ensured the following before starting their planning: +A common refrain you may hear about application control is that it is "too hard." While it's true that application control isn't as simple as flipping a switch, organizations can be successful, if they're methodical when carefully planning their approach. In reality, the issues that lead to failure with application control often arise from business issues rather than technology challenges. Organizations that have successfully deployed application control have ensured the following before starting their planning: - Executive sponsorship and organizational buy-in is in place. -- There is a clear **business** objective for using application control, and it is not being planned as a purely technical problem from IT. +- There's a clear **business** objective for using application control, and it's not being planned as a purely technical problem from IT. - The organization has a plan to handle potential helpdesk support requests for users who are blocked from running some apps. - The organization has considered where application control can be most useful (for example, securing sensitive workloads or business functions) and also where it may be difficult to achieve (for example, developer workstations). -Once these business factors are in place, you are ready to begin planning your Windows Defender Application Control (WDAC) deployment. The following topics can help guide you through your planning process. +Once these business factors are in place, you're ready to begin planning your Windows Defender Application Control (WDAC) deployment. The following topics can help guide you through your planning process. ## In this section From e8549a9c2cddfd6858d72eb17f3be1c1daaf1238 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 13:39:26 +1000 Subject: [PATCH 021/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 597edfab14..1745071ff1 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -35,12 +35,12 @@ Devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Win ## Why upgrade personal devices from Windows Home to Windows Education? -Some configuration service providers (CSPs) are not available on Windows Home which can limit the management capabilities. Some key CSPs that can affect mobile device management are: +Some school institutions want to streamline student onboarding for personal devices using Mobile Device Management. This could include installing certificates, configuring WiFi profiles and offering applications that are required for learning. Some MDM configuration service providers (CSPs) are not available on Windows Home which can limit the management capabilities. Some key CSPs that can affect mobile device management for these scenarios are: -- [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications -- [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization +- [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications. +- [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization. -A full list is available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). +A full list is available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). For more information about enrolling devices into Microsoft Intune, see [Deployment guide: Enroll Windows devices in Microsoft Intune](/mem/intune/fundamentals/deployment-guide-enrollment-windows) ## Requirements for using a MAK to upgrade from Windows Home to Windows Education From ae9e98b994fd534cb81517d2b02959bcaebff016 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Tue, 5 Jul 2022 13:46:36 +1000 Subject: [PATCH 022/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 1745071ff1..b5159b32d1 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -40,7 +40,7 @@ Some school institutions want to streamline student onboarding for personal devi - [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications. - [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization. -A full list is available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). For more information about enrolling devices into Microsoft Intune, see [Deployment guide: Enroll Windows devices in Microsoft Intune](/mem/intune/fundamentals/deployment-guide-enrollment-windows) +A full list is available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). For more information about enrolling devices into Microsoft Intune, see [Deployment guide: Enroll Windows devices in Microsoft Intune](/mem/intune/fundamentals/deployment-guide-enrollment-windows). ## Requirements for using a MAK to upgrade from Windows Home to Windows Education @@ -117,7 +117,7 @@ These steps will configure a Windows edition upgrade policy and target all Windo Filters allow you to target the all devices group but to a subset of devices using a filter. In this case the filter will be based on the operating system SKU. This will ensure we only upgrade devices that are running Windows Home edition and avoid upgrading devices that are running Windows Pro/Pro EDU edition which can upgrade using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). -- Start in the **Microsoft Endpoint Manager admin console** +- Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) - Go to **Tenant Administration** > **Filters** - Click **Create** - Create a name for the filter (for example *Windows Home edition*) @@ -140,7 +140,7 @@ Filters allow you to target the all devices group but to a subset of devices usi ### Step 2: Create a Windows edition upgrade policy -- Start in the **Microsoft Endpoint Manager admin console** +- Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) - Select **Devices** > **Configuration profiles** - Select **Create profile** - Select the **Platform** as **Windows 10 or later** From c09bbeb03b4677e95df31c4ba86771c6ff6547ca Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Tue, 5 Jul 2022 13:26:09 +0530 Subject: [PATCH 023/109] Acrolinx Enhancement Effort --- .../change-rules-from-request-to-require-mode.md | 2 +- ...onfiguring-rules-for-an-isolated-server-zone.md | 12 ++++++------ ...servers-in-a-standalone-isolated-server-zone.md | 14 +++++++------- 3 files changed, 14 insertions(+), 14 deletions(-) diff --git a/windows/security/threat-protection/windows-firewall/change-rules-from-request-to-require-mode.md b/windows/security/threat-protection/windows-firewall/change-rules-from-request-to-require-mode.md index fe2aeb49e8..88550f7f67 100644 --- a/windows/security/threat-protection/windows-firewall/change-rules-from-request-to-require-mode.md +++ b/windows/security/threat-protection/windows-firewall/change-rules-from-request-to-require-mode.md @@ -25,7 +25,7 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -After you confirm that network traffic is being correctly protected by using IPsec, you can change the rules for the domain isolation and encryption zones to require, instead of request, authentication. Do not change the rules for the boundary zone; they must stay in request mode so that devices in the boundary zone can continue to accept connections from devices that are not part of the isolated domain. +After you confirm that network traffic is being correctly protected by using IPsec, you can change the rules for the domain isolation and encryption zones to require, instead of request, authentication. Don't change the rules for the boundary zone; they must stay in request mode so that devices in the boundary zone can continue to accept connections from devices that aren't part of the isolated domain. **Administrative credentials** diff --git a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-an-isolated-server-zone.md b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-an-isolated-server-zone.md index 296c1e7556..36fe34357d 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-an-isolated-server-zone.md +++ b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-an-isolated-server-zone.md @@ -25,29 +25,29 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -The following checklists include tasks for configuring connection security rules and IPsec settings in your GPOs for servers in an isolated server zone that are part of an isolated domain. For information about creating a standalone isolated server zone that is not part of an isolated domain, see [Checklist: Implementing a Standalone Server Isolation Policy Design](checklist-implementing-a-standalone-server-isolation-policy-design.md). +The following checklists include tasks for configuring connection security rules and IPsec settings in your GPOs for servers in an isolated server zone that are part of an isolated domain. For information about creating a standalone isolated server zone that isn't part of an isolated domain, see [Checklist: Implementing a Standalone Server Isolation Policy Design](checklist-implementing-a-standalone-server-isolation-policy-design.md). -In addition to requiring authentication and optionally encryption, servers in an isolated server zone can be accessed only by users or devices who are authenticated members of a network access group (NAG). If you include user accounts in the NAG, then the restrictions can still apply; they are just enforced at the application layer, rather than the IP layer. +In addition to requiring authentication and optionally encryption, servers in an isolated server zone can be accessed only by users or devices who are authenticated members of a network access group (NAG). If you include user accounts in the NAG, then the restrictions can still apply; they're enforced at the application layer, rather than the IP layer. Devices that are running at least Windows Vista and Windows Server 2008 can identify both devices and users in the NAG because IPsec in these versions of Windows supports AuthIP in addition to IKE. AuthIP adds support for user-based authentication. -The GPOs for an isolated server or group of servers are similar to those for the isolated domain itself or the encryption zone, if you require encryption to your isolated servers. This checklist refers you to procedures for creating rules as well as restrictions that allow only members of the NAG to connect to the server. +The GPOs for an isolated server or group of servers are similar to those GPOs for the isolated domain itself or the encryption zone, if you require encryption to your isolated servers. This checklist refers you to procedures for creating rules and restrictions that allow only members of the NAG to connect to the server. **Checklist: Configuring rules for isolated servers** | Task | Reference | | - | - | -| Create a GPO for the devices that need to have access restricted to the same set of client devices. If there are multiple servers and they run different versions of the Windows operating system, then start by creating the GPO for one version of Windows. After you have finished the tasks in this checklist and configured the GPO for that version of Windows, you can create a copy of it.
    Copy the GPO from the isolated domain or from the encryption zone to serve as a starting point. Where your copy already contains elements listed in the following checklist, review the relevant procedures and compare them to your copied GPO’s element to make sure it is constructed in a way that meets the needs of the server isolation zone. |[Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| +| Create a GPO for the devices that need to have access restricted to the same set of client devices. If there are multiple servers and they run different versions of the Windows operating system, then start by creating the GPO for one version of Windows. After you've finished the tasks in this checklist and configured the GPO for that version of Windows, you can create a copy of it.
    Copy the GPO from the isolated domain or from the encryption zone to serve as a starting point. Where your copy already contains elements listed in the following checklist, review the relevant procedures and compare them to your copied GPO’s element to make sure it's constructed in a way that meets the needs of the server isolation zone. |[Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| | Configure the security group filters and WMI filters on the GPO so that only members of the isolated server zone’s membership group that are running the specified version of Windows can read and apply it.| [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Configure IPsec to exempt all ICMP network traffic from IPsec protection. | [Exempt ICMP from Authentication](exempt-icmp-from-authentication.md)| | Configure the key exchange (main mode) security methods and algorithms to be used. | [Configure Key Exchange (Main Mode) Settings](configure-key-exchange-main-mode-settings.md)| | Configure the data protection (quick mode) algorithm combinations to be used. If you require encryption for the isolated server zone, then make sure that you choose only algorithm combinations that include encryption. | [Configure Data Protection (Quick Mode) Settings](configure-data-protection-quick-mode-settings.md)| | Configure the authentication methods to be used. | [Configure Authentication Methods](configure-authentication-methods.md)| | Create a rule that exempts all network traffic to and from devices on the exemption list from IPsec. | [Create an Authentication Exemption List Rule](create-an-authentication-exemption-list-rule.md)| -| Create a rule that requests authentication for all network traffic.
    **Important:** Just as in an isolated domain, do not set the rules to require authentication for inbound traffic until you have completed testing. That way, if the rules do not work as expected, communications are not affected by a failure to authenticate.| [Create an Authentication Request Rule](create-an-authentication-request-rule.md)| +| Create a rule that requests authentication for all network traffic.
    **Important:** As in an isolated domain, don't set the rules to require authentication for inbound traffic until you have completed testing. That way, if the rules don't work as expected, communications aren't affected by a failure to authenticate.| [Create an Authentication Request Rule](create-an-authentication-request-rule.md)| | Create the NAG to contain the device or user accounts that are allowed to access the servers in the isolated server zone. | [Create a Group Account in Active Directory](create-a-group-account-in-active-directory.md)| | Create a firewall rule that permits inbound network traffic only if authenticated as a member of the NAG. | [Restrict Server Access to Members of a Group Only](restrict-server-access-to-members-of-a-group-only.md)| | Link the GPO to the domain level of the Active Directory organizational unit hierarchy. | [Link the GPO to the Domain](link-the-gpo-to-the-domain.md)| | Add your test server to the membership group for the isolated server zone. Be sure to add at least one server for each operating system supported by a GPO in the group.| [Add Test Devices to the Membership Group for a Zone](add-test-devices-to-the-membership-group-for-a-zone.md) | -Do not change the rules for any of your zones to require authentication until all of the zones have been set up and are operating correctly. +Don't change the rules for any of your zones to require authentication until all of the zones have been set up and are operating correctly. diff --git a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-servers-in-a-standalone-isolated-server-zone.md b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-servers-in-a-standalone-isolated-server-zone.md index 4c9332aa61..db9e5235c2 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-servers-in-a-standalone-isolated-server-zone.md +++ b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-servers-in-a-standalone-isolated-server-zone.md @@ -25,26 +25,26 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -This checklist includes tasks for configuring connection security rules and IPsec settings in your GPOs for servers in a standalone isolated server zone that is not part of an isolated domain. In addition to requiring authentication and optionally encryption, servers in a server isolation zone are accessible only by users or devices that are authenticated as members of a network access group (NAG). The GPOs described here apply only to the isolated servers, not to the client devices that connect to them. For the GPOs for the client devices, see [Checklist: Creating Rules for Clients of a Standalone Isolated Server Zone](checklist-creating-rules-for-clients-of-a-standalone-isolated-server-zone.md). +This checklist includes tasks for configuring connection security rules and IPsec settings in your GPOs for servers in a standalone isolated server zone that isn't part of an isolated domain. In addition to requiring authentication and optionally encryption, servers in a server isolation zone are accessible only by users or devices that are authenticated as members of a network access group (NAG). The GPOs described here apply only to the isolated servers, not to the client devices that connect to them. For the GPOs for the client devices, see [Checklist: Creating Rules for Clients of a Standalone Isolated Server Zone](checklist-creating-rules-for-clients-of-a-standalone-isolated-server-zone.md). -The GPOs for isolated servers are similar to those for an isolated domain. This checklist refers you to those procedures for the creation of some of the rules. The other procedures in this checklist are for creating the restrictions that allow only members of the server access group to connect to the server. +The GPOs for isolated servers are similar to those GPOs for an isolated domain. This checklist refers you to those procedures for the creation of some of the rules. The other procedures in this checklist are for creating the restrictions that allow only members of the server access group to connect to the server. **Checklist: Configuring rules for isolated servers** | Task | Reference | | - | - | -| Create a GPO for the devices that need to have access restricted to the same set of client devices. If there are multiple servers running different versions of the Windows operating system, start by creating the GPO for one version of Windows. After you have finished the tasks in this checklist and configured the GPO for that version of Windows, you can create a copy of it. | [Checklist: Creating Group Policy Objects](checklist-creating-group-policy-objects.md)
    [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| -| If you are working on a copy of a GPO, modify the group memberships and WMI filters so that they are correct for the devices for which this GPO is intended. | [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | +| Create a GPO for the devices that need to have access restricted to the same set of client devices. If there are multiple servers running different versions of the Windows operating system, start by creating the GPO for one version of Windows. After you've finished the tasks in this checklist and configured the GPO for that version of Windows, you can create a copy of it. | [Checklist: Creating Group Policy Objects](checklist-creating-group-policy-objects.md)
    [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| +| If you're working on a copy of a GPO, modify the group memberships and WMI filters so that they're correct for the devices for which this GPO is intended. | [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Configure IPsec to exempt all ICMP network traffic from IPsec protection. | [Exempt ICMP from Authentication](exempt-icmp-from-authentication.md)| | Create a rule that exempts all network traffic to and from devices on the exemption list from IPsec. | [Create an Authentication Exemption List Rule](create-an-authentication-exemption-list-rule.md) | | Configure the key exchange (main mode) security methods and algorithms to be used. | [Configure Key Exchange (Main Mode) Settings](configure-key-exchange-main-mode-settings.md)| | Configure the data protection (quick mode) algorithm combinations to be used. | [Configure Data Protection (Quick Mode) Settings](configure-data-protection-quick-mode-settings.md)| | Configure the authentication methods to be used. This procedure sets the default settings for the device. If you want to set authentication on a per-rule basis, this procedure is optional.| [Configure Authentication Methods](configure-authentication-methods.md) | -| Create a rule that requests authentication for all inbound network traffic.

    **Important:** Just as in an isolated domain, do not set the rules to require authentication until your testing is complete. That way, if the rules do not work as expected, communications are not affected by a failure to authenticate.| [Create an Authentication Request Rule](create-an-authentication-request-rule.md)| +| Create a rule that requests authentication for all inbound network traffic.

    **Important:** As in an isolated domain, don't set the rules to require authentication until your testing is complete. That way, if the rules don't work as expected, communications aren't affected by a failure to authenticate.| [Create an Authentication Request Rule](create-an-authentication-request-rule.md)| | If your design requires encryption in addition to authentication for access to the isolated servers, then modify the rule to require it. | [Configure the Rules to Require Encryption](configure-the-rules-to-require-encryption.md)| | Create the NAG to contain the device or user accounts that are allowed to access the isolated servers. If you have multiple groups of isolated servers that are accessed by different client devices, then create a NAG for each set of servers.| [Create a Group Account in Active Directory](create-a-group-account-in-active-directory.md) | -| Create a firewall rule that allows inbound network traffic only if it is authenticated from a user or device that is a member of the zone’s NAG.| [Restrict Server Access to Members of a Group Only](restrict-server-access-to-members-of-a-group-only.md)| +| Create a firewall rule that allows inbound network traffic only if it's authenticated from a user or device that is a member of the zone’s NAG.| [Restrict Server Access to Members of a Group Only](restrict-server-access-to-members-of-a-group-only.md)| | Link the GPO to the domain level of the Active Directory organizational unit hierarchy. | [Link the GPO to the Domain](link-the-gpo-to-the-domain.md)| | Add your test server to the membership group for the isolated server zone. Be sure to add at least one for each operating system supported by a different GPO in the group.| [Add Test Devices to the Membership Group for a Zone](add-test-devices-to-the-membership-group-for-a-zone.md)| -Do not change the rules for any of your zones to require authentication until all zones have been set up and thoroughly tested. +Don't change the rules for any of your zones to require authentication until all zones have been set up and thoroughly tested. From 4e9aafea214f6178ee9888ba2bb357740410bd51 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Tue, 5 Jul 2022 14:01:14 +0530 Subject: [PATCH 024/109] Acrolinx Enhancement Effort --- ...r-application-control-operational-guide.md | 4 +- .../windows-defender-application-control.md | 2 +- .../wdsc-app-browser-control.md | 8 ++-- .../wdsc-device-performance-health.md | 10 ++--- .../wdsc-device-security.md | 10 ++--- .../wdsc-family-options.md | 12 +++--- .../wdsc-firewall-network-protection.md | 6 +-- .../wdsc-hide-notifications.md | 30 +++++++-------- .../wdsc-virus-threat-protection.md | 16 ++++---- ...ices-to-the-membership-group-for-a-zone.md | 8 ++-- ...ices-to-the-membership-group-for-a-zone.md | 10 ++--- .../basic-firewall-policy-design.md | 12 +++--- .../best-practices-configuring.md | 38 +++++++++---------- .../windows-firewall/boundary-zone-gpos.md | 4 +- .../windows-firewall/boundary-zone.md | 8 ++-- ...e-based-isolation-policy-design-example.md | 12 +++--- ...rtificate-based-isolation-policy-design.md | 6 +-- 17 files changed, 98 insertions(+), 98 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md index 3341806d89..9a160774c9 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md @@ -29,11 +29,11 @@ ms.technology: windows-sec > [!NOTE] > Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](feature-availability.md). -After designing and deploying your Windows Defender Application Control (WDAC) policies, this guide covers understanding the effects your policies are having and troubleshooting when they are not behaving as expected. It contains information on where to find events and what they mean, and also querying these events with Microsoft Defender for Endpoint Advanced Hunting feature. +After enabling you understand how to design and deploy your Windows Defender Application Control (WDAC) policies, this guide covers understanding the effects your policies are having and troubleshooting when they aren't behaving as expected. It contains information on where to find events and what they mean, and also querying these events with Microsoft Defender for Endpoint Advanced Hunting feature. ## WDAC Events Overview -Windows Defender Application Control generates and logs events when a policy is loaded as well as when a binary attempts to execute and is blocked. These events include information that identifies the policy and gives more details about the block. Generally, WDAC does not generate events when a binary is allowed; however, there is the option to enable events when Managed Installer and/or the Intelligent Security Graph (ISG) is configured. +Windows Defender Application Control generates and logs events when a policy is loaded as well as when a binary attempts to execute and is blocked. These events include information that identifies the policy and gives more details about the block. Generally, WDAC doesn't generate events when a binary is allowed; however, there's the option to enable events when Managed Installer and/or the Intelligent Security Graph (ISG) is configured. WDAC events are generated under two locations: diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md index 5e8737ae67..a552764722 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md @@ -36,7 +36,7 @@ In most organizations, information is the most valuable asset, and ensuring that Application control can help mitigate these types of security threats by restricting the applications that users are allowed to run and the code that runs in the System Core (kernel). Application control policies can also block unsigned scripts and MSIs, and restrict Windows PowerShell to run in [Constrained Language Mode](/powershell/module/microsoft.powershell.core/about/about_language_modes). -Application control is a crucial line of defense for protecting enterprises given today’s threat landscape, and it has an inherent advantage over traditional antivirus solutions. Specifically, application control moves away from an application trust model where all applications are assumed trustworthy to one where applications must earn trust in order to run. Many organizations, like the Australian Signals Directorate, understand this and frequently cite application control as one of the most effective means for addressing the threat of executable file-based malware (.exe, .dll, etc.). +Application control is a crucial line of defense for protecting enterprises given today’s threat landscape, and it has an inherent advantage over traditional antivirus solutions. Specifically, application control moves away from an application trust model where all applications are assumed trustworthy to one where applications must earn trust in order to run. Many organizations, like the Australian Signals Directorate, understand the significance of application control and frequently cite application control as one of the most effective means for addressing the threat of executable file-based malware (.exe, .dll, etc.). > [!NOTE] > Although application control can significantly harden your computers against malicious code, we recommend that you continue to maintain an enterprise antivirus solution for a well-rounded enterprise security portfolio. diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md index d9747dc21d..e3814dc5d2 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md @@ -28,11 +28,11 @@ The **App and browser control** section contains information and settings for Wi In Windows 10, version 1709 and later, the section also provides configuration options for Exploit protection. You can prevent users from modifying these specific options with Group Policy. IT administrators can get more information at [Exploit protection](/microsoft-365/security/defender-endpoint/exploit-protection). -You can also choose to hide the section from users of the machine. This can be useful if you don't want employees in your organization to see or have access to user-configured options for the features shown in the section. +You can also choose to hide the section from users of the machine. This option can be useful if you don't want employees in your organization to see or have access to user-configured options for the features shown in the section. ## Prevent users from making changes to the Exploit protection area in the App & browser control section -You can prevent users from modifying settings in the Exploit protection area. The settings will be either greyed out or not appear if you enable this setting. Users will still have access to other settings in the App & browser control section, such as those for Windows Defender SmartScreen, unless those options have been configured separately. +You can prevent users from modifying settings in the Exploit protection area. The settings will be either greyed out or not appear if you enable this setting. Users will still have access to other settings in the App & browser control section, such as those settings for Windows Defender SmartScreen, unless those options have been configured separately. You can only prevent users from modifying Exploit protection settings by using Group Policy. @@ -51,9 +51,9 @@ You can only prevent users from modifying Exploit protection settings by using G ## Hide the App & browser control section -You can choose to hide the entire section by using Group Policy. The section will not appear on the home page of the Windows Security app, and its icon will not be shown on the navigation bar on the side of the app. +You can choose to hide the entire section by using Group Policy. The section won't appear on the home page of the Windows Security app, and its icon won't be shown on the navigation bar on the side of the app. -This can only be done in Group Policy. +This section can be hidden only by using Group Policy. > [!IMPORTANT] > You must have Windows 10, version 1709 or later. The ADMX/ADML template files for earlier versions of Windows do not include these Group Policy settings. diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md index 3672d5c25a..a4136a591a 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md @@ -25,19 +25,19 @@ ms.technology: windows-sec - Windows 11 -The **Device performance & health** section contains information about hardware, devices, and drivers related to the machine. IT administrators and IT pros should reference the appropriate documentation library for the issues they are seeing, such as the [configure the Load and unload device drivers security policy setting](/windows/device-security/security-policy-settings/load-and-unload-device-drivers) and how to [deploy drivers during Windows 10 deployment using Microsoft Endpoint Configuration Manager](/windows/deployment/deploy-windows-cm/add-drivers-to-a-windows-10-deployment-with-windows-pe-using-configuration-manager). +The **Device performance & health** section contains information about hardware, devices, and drivers related to the machine. IT administrators and IT pros should reference the appropriate documentation library for the issues they're seeing, such as the [configure the Load and unload device drivers security policy setting](/windows/device-security/security-policy-settings/load-and-unload-device-drivers) and how to [deploy drivers during Windows 10 deployment using Microsoft Endpoint Configuration Manager](/windows/deployment/deploy-windows-cm/add-drivers-to-a-windows-10-deployment-with-windows-pe-using-configuration-manager). The [Windows 10 IT pro troubleshooting topic](/windows/client-management/windows-10-support-solutions), and the main [Windows 10 documentation library](/windows/windows-10/) can also be helpful for resolving issues. -In Windows 10, version 1709 and later, the section can be hidden from users of the machine. This can be useful if you don't want employees in your organization to see or have access to user-configured options for the features shown in the section. +In Windows 10, version 1709 and later, the section can be hidden from users of the machine. This option can be useful if you don't want employees in your organization to see or have access to user-configured options for the features shown in the section. ## Hide the Device performance & health section -You can choose to hide the entire section by using Group Policy. The section will not appear on the home page of the Windows Security app, and its icon will not be shown on the navigation bar on the side of the app. +You can choose to hide the entire section by using Group Policy. The section won't appear on the home page of the Windows Security app, and its icon won't be shown on the navigation bar on the side of the app. -This can only be done in Group Policy. +This section can be hidden only by using Group Policy. >[!IMPORTANT] >### Requirements @@ -46,7 +46,7 @@ This can only be done in Group Policy. 1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. 5. Expand the tree to **Windows components > Windows Security > Device performance and health**. diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md index 4a34381192..66b2b79227 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md @@ -25,18 +25,18 @@ ms.technology: windows-sec The **Device security** section contains information and settings for built-in device security. -You can choose to hide the section from users of the machine. This can be useful if you don't want employees in your organization to see or have access to user-configured options for the features shown in the section. +You can choose to hide the section from users of the machine. This option can be useful if you don't want employees in your organization to see or have access to user-configured options for the features shown in the section. ## Hide the Device security section -You can choose to hide the entire section by using Group Policy. The section will not appear on the home page of the Windows Security app, and its icon will not be shown on the navigation bar on the side of the app. You can hide the device security section by using Group Policy only. +You can choose to hide the entire section by using Group Policy. The section won't appear on the home page of the Windows Security app, and its icon won't be shown on the navigation bar on the side of the app. You can hide the device security section by using Group Policy only. > [!IMPORTANT] > You must have Windows 10, version 1803 or later. The ADMX/ADML template files for earlier versions of Windows do not include these Group Policy settings. 1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -2. In the **Group Policy Management Editor** go to **Computer configuration** and then select **Administrative templates**. +2. In **Group Policy Management Editor**, go to **Computer configuration** and then select **Administrative templates**. 3. Expand the tree to **Windows components** > **Windows Security** > **Device security**. @@ -57,7 +57,7 @@ If you don't want users to be able to click the **Clear TPM** button in the Wind 1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -2. In the **Group Policy Management Editor** go to **Computer configuration** and then select **Administrative templates**. +2. In **Group Policy Management Editor**, go to **Computer configuration** and then select **Administrative templates**. 3. Expand the tree to **Windows components** > **Windows Security** > **Device security**. @@ -70,7 +70,7 @@ If you don't want users to see the recommendation to update TPM firmware, you ca 1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -2. In the **Group Policy Management Editor** go to **Computer configuration** and then select **Administrative templates**. +2. In **Group Policy Management Editor**, go to **Computer configuration** and then select **Administrative templates**. 3. Expand the tree to **Windows components** > **Windows Security** > **Device security**. diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md index a9e4a148c5..8f9528db75 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md @@ -1,6 +1,6 @@ --- title: Family options in the Windows Security app -description: Learn how to hide the Family options section of Windows Security for enterprise environments. Family options are not intended for business environments. +description: Learn how to hide the Family options section of Windows Security for enterprise environments. Family options aren't intended for business environments. keywords: wdsc, family options, hide, suppress, remove, disable, uninstall, kids, parents, safety, parental, child, screen time search.product: eADQiWindows 10XVcnh ms.prod: m365-security @@ -24,18 +24,18 @@ ms.technology: windows-sec - Windows 10 - Windows 11 -The **Family options** section contains links to settings and further information for parents of a Windows 10 PC. It is not generally intended for enterprise or business environments. +The **Family options** section contains links to settings and further information for parents of a Windows 10 PC. It isn't intended for enterprise or business environments. Home users can learn more at the [Help protection your family online in Windows Security topic at support.microsoft.com](https://support.microsoft.com/help/4013209/windows-10-protect-your-family-online-in-windows-defender) -In Windows 10, version 1709, the section can be hidden from users of the machine. This can be useful if you don't want employees in your organization to see or have access to this section. +In Windows 10, version 1709, the section can be hidden from users of the machine. This option can be useful if you don't want employees in your organization to see or have access to this section. ## Hide the Family options section -You can choose to hide the entire section by using Group Policy. The section will not appear on the home page of the Windows Security app, and its icon will not be shown on the navigation bar on the side of the app. +You can choose to hide the entire section by using Group Policy. The section won't appear on the home page of the Windows Security app, and its icon won't be shown on the navigation bar on the side of the app. -This can only be done in Group Policy. +This section can be hidden only by using Group Policy. >[!IMPORTANT] >### Requirements @@ -44,7 +44,7 @@ This can only be done in Group Policy. 1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. 5. Expand the tree to **Windows components > Windows Security > Family options**. diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md index 924bcd1150..b0d7e2beea 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md @@ -30,9 +30,9 @@ In Windows 10, version 1709 and later, the section can be hidden from users of t ## Hide the Firewall & network protection section -You can choose to hide the entire section by using Group Policy. The section will not appear on the home page of the Windows Security app, and its icon will not be shown on the navigiation bar on the side of the app. +You can choose to hide the entire section by using Group Policy. The section won't appear on the home page of the Windows Security app, and its icon won't be shown on the navigation bar on the side of the app. -This can only be done in Group Policy. +This section can be hidden only by using Group Policy. >[!IMPORTANT] >### Requirements @@ -41,7 +41,7 @@ This can only be done in Group Policy. 1. On your Group Policy management machine, open the Group Policy Management Console, right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. 5. Expand the tree to **Windows components > Windows Security > Firewall and network protection**. diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md index 4b010e206c..c684f86a90 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md @@ -23,7 +23,7 @@ ms.technology: windows-sec - Windows 10 - Windows 11 -The Windows Security app is used by a number of Windows security features to provide notifications about the health and security of the machine. These include notifications about firewalls, antivirus products, Windows Defender SmartScreen, and others. +The Windows Security app is used by many Windows security features to provide notifications about the health and security of the machine. These include notifications about firewalls, antivirus products, Windows Defender SmartScreen, and others. In some cases, it may not be appropriate to show these notifications, for example, if you want to hide regular status updates, or if you want to hide all notifications to the employees in your organization. @@ -40,9 +40,9 @@ You can only use Group Policy to change these settings. ## Use Group Policy to hide non-critical notifications -You can hide notifications that describe regular events related to the health and security of the machine. These are notifications that do not require an action from the machine's user. It can be useful to hide these notifications if you find they are too numerous or you have other status reporting on a larger scale (such as Update Compliance or Microsoft Endpoint Configuration Manager reporting). +You can hide notifications that describe regular events related to the health and security of the machine. These notifications are the ones that don't require an action from the machine's user. It can be useful to hide these notifications if you find they're too numerous or you have other status reporting on a larger scale (such as Update Compliance or Microsoft Endpoint Configuration Manager reporting). -This can only be done in Group Policy. +These notifications can be hidden only by using Group Policy. >[!IMPORTANT] > @@ -52,9 +52,9 @@ This can only be done in Group Policy. 2. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. -5. Expand the tree to **Windows components > Windows Security > Notifications**. For Windows 10 version 1803 and below the path would be **Windows components > Windows Defender Security Center > Notifications** +5. Expand the tree to **Windows components > Windows Security > Notifications**. For Windows 10 version 1803 and below, the path would be **Windows components > Windows Defender Security Center > Notifications** 6. Open the **Hide non-critical notifications** setting and set it to **Enabled**. Click **OK**. @@ -63,9 +63,9 @@ This can only be done in Group Policy. ## Use Group Policy to hide all notifications -You can hide all notifications that are sourced from the Windows Security app. This may be useful if you don't want users of the machines from inadvertently modifying settings, running antivirus scans, or otherwise performing security-related actions without your input. +You can hide all notifications that are sourced from the Windows Security app. This option may be useful if you don't want users of the machines from inadvertently modifying settings, running antivirus scans, or otherwise performing security-related actions without your input. -This can only be done in Group Policy. +These notifications can be hidden only by using Group Policy. >[!IMPORTANT] > @@ -73,9 +73,9 @@ This can only be done in Group Policy. 1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. -5. Expand the tree to **Windows components > Windows Security > Notifications**. For Windows 10 version 1803 and below the path would be **Windows components > Windows Defender Security Center > Notifications**. +5. Expand the tree to **Windows components > Windows Security > Notifications**. For Windows 10 version 1803 and below, the path would be **Windows components > Windows Defender Security Center > Notifications**. > [!NOTE] > For Windows 10 version 2004 and above the path would be **Windows components > Windows Security > Notifications**. @@ -104,16 +104,16 @@ This can only be done in Group Policy. | HVCI, reboot needed to enable | The recent change to your protection settings requires a restart of your device. | HVCI_ENABLE_SUCCESS | Yes |Firewall and network protection notification| | Item skipped in scan, due to exclusion setting, or network scanning disabled by admin | The Microsoft Defender Antivirus scan skipped an item due to exclusion or network scanning settings. | ITEM_SKIPPED | Yes |Virus & threat protection notification| | Remediation failure | Microsoft Defender Antivirus couldn’t completely resolve potential threats. | CLEAN_FAILED | Yes |Virus & threat protection notification| -| Follow-up action (restart & scan) | Microsoft Defender Antivirus found _threat_ in _file name_. Please restart and scan your device. Restart and scan | MANUALSTEPS_REQUIRED | Yes |Virus & threat protection notification| -| Follow-up action (restart) | Microsoft Defender Antivirus found _threat_ in _file_. Please restart your device. | WDAV_REBOOT | Yes |Virus & threat protection notification| -| Follow-up action (Full scan) | Microsoft Defender Antivirus found _threat_ in _file_. Please run a full scan of your device. | FULLSCAN_REQUIRED | Yes |Virus & threat protection notification| +| Follow-up action (restart & scan) | Microsoft Defender Antivirus found _threat_ in _file name_. Restart and scan your device. Restart and scan | MANUALSTEPS_REQUIRED | Yes |Virus & threat protection notification| +| Follow-up action (restart) | Microsoft Defender Antivirus found _threat_ in _file_. Restart your device. | WDAV_REBOOT | Yes |Virus & threat protection notification| +| Follow-up action (Full scan) | Microsoft Defender Antivirus found _threat_ in _file_. Run a full scan of your device. | FULLSCAN_REQUIRED | Yes |Virus & threat protection notification| | Sample submission prompt | Review files that Windows Defender will send to Microsoft. Sending this information can improve how Microsoft Defender Antivirus helps protect your device. | SAMPLE_SUBMISSION_REQUIRED | Yes |Virus & threat protection notification| | OS support ending warning | Support for your version of Windows is ending. When this support ends, Microsoft Defender Antivirus won’t be supported, and your device might be at risk. | SUPPORT_ENDING | Yes |Virus & threat protection notification| | OS support ended, device at risk | Support for your version of Windows has ended. Microsoft Defender Antivirus is no longer supported, and your device might be at risk. | SUPPORT_ENDED _and_ SUPPORT_ENDED_NO_DEFENDER | Yes |Virus & threat protection notification| | Summary notification, items found | Microsoft Defender Antivirus successfully took action on _n_ threats since your last summary. Your device was scanned _n_ times. | RECAP_FOUND_THREATS_SCANNED | No |Virus & threat protection notification| | Summary notification, items found, no scan count | Microsoft Defender Antivirus successfully took action on _n_ threats since your last summary. | RECAP_FOUND_THREATS | No |Virus & threat protection notification| -| Summary notification, **no** items found, scans performed | Microsoft Defender Antivirus did not find any threats since your last summary. Your device was scanned _n_ times. | RECAP_NO THREATS_SCANNED | No |Virus & threat protection notification| -| Summary notification, **no** items found, no scans | Microsoft Defender Antivirus did not find any threats since your last summary. | RECAP_NO_THREATS | No |Virus & threat protection notification| +| Summary notification, **no** items found, scans performed | Microsoft Defender Antivirus didn't find any threats since your last summary. Your device was scanned _n_ times. | RECAP_NO THREATS_SCANNED | No |Virus & threat protection notification| +| Summary notification, **no** items found, no scans | Microsoft Defender Antivirus didn't find any threats since your last summary. | RECAP_NO_THREATS | No |Virus & threat protection notification| | Scan finished, manual, threats found | Microsoft Defender Antivirus scanned your device at _timestamp_ on _date_, and took action against threats. | RECENT_SCAN_FOUND_THREATS | No |Virus & threat protection notification| | Scan finished, manual, **no** threats found | Microsoft Defender Antivirus scanned your device at _timestamp_ on _date_. No threats were found. | RECENT_SCAN_NO_THREATS | No |Virus & threat protection notification| | Threat found | Microsoft Defender Antivirus found threats. Get details. | CRITICAL | No |Virus & threat protection notification| @@ -122,7 +122,7 @@ This can only be done in Group Policy. | Long running BaFS customized | _Company_ requires a security scan of this item. The scan could take up to _n_ seconds. | BAFS_DETECTED_CUSTOM (body) | No |Firewall and network protection notification| | Sense detection | This application was removed because it was blocked by your IT security settings | WDAV_SENSE_DETECTED | No |Firewall and network protection notification| | Sense detection customized | This application was removed because it was blocked by your IT security settings | WDAV_SENSE_DETECTED_CUSTOM (body) | No |Firewall and network protection notification| -| Ransomware specific detection | Microsoft Defender Antivirus has detected threats which may include ransomware. | WDAV_RANSOMWARE_DETECTED | No |Virus & threat protection notification| +| Ransomware specific detection | Microsoft Defender Antivirus has detected threats, which may include ransomware. | WDAV_RANSOMWARE_DETECTED | No |Virus & threat protection notification| | ASR (HIPS) block | Your IT administrator caused Windows Defender Security Center to block this action. Contact your IT help desk. | HIPS_ASR_BLOCKED | No |Firewall and network protection notification| | ASR (HIPS) block customized | _Company_ caused Windows Defender Security Center to block this action. Contact your IT help desk. | HIPS_ASR_BLOCKED_CUSTOM (body) | No |Firewall and network protection notification| | CFA (FolderGuard) block | Controlled folder access blocked _process_ from making changes to the folder _path_ | FOLDERGUARD_BLOCKED | No |Firewall and network protection notification| diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md index 2d43e965ba..cade645c59 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md @@ -24,7 +24,7 @@ ms.technology: windows-sec The **Virus & threat protection** section contains information and settings for antivirus protection from Microsoft Defender Antivirus and third-party AV products. -In Windows 10, version 1803, this section also contains information and settings for ransomware protection and recovery. This includes Controlled folder access settings to prevent unknown apps from changing files in protected folders, plus Microsoft OneDrive configuration to help you recover from a ransomware attack. This area also notifies users and provides recovery instructions in case of a ransomware attack. +In Windows 10, version 1803, this section also contains information and settings for ransomware protection and recovery. These settings include Controlled folder access settings to prevent unknown apps from changing files in protected folders, plus Microsoft OneDrive configuration to help you recover from a ransomware attack. This area also notifies users and provides recovery instructions if there's a ransomware attack. IT administrators and IT pros can get more configuration information from these articles: @@ -35,14 +35,14 @@ IT administrators and IT pros can get more configuration information from these - [Microsoft Defender for Office 365](/microsoft-365/security/office-365-security/defender-for-office-365) - [Ransomware detection and recovering your files](https://support.office.com/en-us/article/ransomware-detection-and-recovering-your-files-0d90ec50-6bfd-40f4-acc7-b8c12c73637f?ui=en-US&rs=en-US&ad=US) -You can hide the **Virus & threat protection** section or the **Ransomware protection** area from users of the machine. This can be useful if you don't want employees in your organization to see or have access to user-configured options for these features. +You can hide the **Virus & threat protection** section or the **Ransomware protection** area from users of the machine. This option can be useful if you don't want employees in your organization to see or have access to user-configured options for these features. ## Hide the Virus & threat protection section -You can choose to hide the entire section by using Group Policy. The section will not appear on the home page of the Windows Security app, and its icon will not be shown on the navigiation bar on the side of the app. +You can choose to hide the entire section by using Group Policy. The section won't appear on the home page of the Windows Security app, and its icon won't be shown on the navigation bar on the side of the app. -This can only be done in Group Policy. +This section can be hidden only by using Group Policy. >[!IMPORTANT] >### Requirements @@ -51,7 +51,7 @@ This can only be done in Group Policy. 1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. 5. Expand the tree to **Windows components > Windows Security > Virus and threat protection**. @@ -66,9 +66,9 @@ This can only be done in Group Policy. ## Hide the Ransomware protection area -You can choose to hide the **Ransomware protection** area by using Group Policy. The area will not appear on the **Virus & threat protection** section of the Windows Security app. +You can choose to hide the **Ransomware protection** area by using Group Policy. The area won't appear on the **Virus & threat protection** section of the Windows Security app. -This can only be done in Group Policy. +This area can be hidden only by using Group Policy. >[!IMPORTANT] >### Requirements @@ -77,7 +77,7 @@ This can only be done in Group Policy. 1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and click **Edit**. -3. In the **Group Policy Management Editor** go to **Computer configuration** and click **Administrative templates**. +3. In **Group Policy Management Editor**, go to **Computer configuration** and click **Administrative templates**. 5. Expand the tree to **Windows components > Windows Security > Virus and threat protection**. diff --git a/windows/security/threat-protection/windows-firewall/add-production-devices-to-the-membership-group-for-a-zone.md b/windows/security/threat-protection/windows-firewall/add-production-devices-to-the-membership-group-for-a-zone.md index 0ffe9699ca..669d4ede86 100644 --- a/windows/security/threat-protection/windows-firewall/add-production-devices-to-the-membership-group-for-a-zone.md +++ b/windows/security/threat-protection/windows-firewall/add-production-devices-to-the-membership-group-for-a-zone.md @@ -29,11 +29,11 @@ ms.technology: windows-sec After you test the GPOs for your design on a small set of devices, you can deploy them to the production devices. **Caution**   -For GPOs that contain connection security rules that prevent unauthenticated connections, be sure to set the rules to request, not require, authentication during testing. After you deploy the GPO and confirm that all of your devices are successfully communicating by using authenticated IPsec, then you can modify the GPO to require authentication. Do not change the boundary zone GPO to require mode. +For GPOs that contain connection security rules that prevent unauthenticated connections, ensure you set the rules to request, not require, authentication during testing. After you deploy the GPO and confirm that all of your devices are successfully communicating by using authenticated IPsec, then you can modify the GPO to require authentication. Don't change the boundary zone GPO to require mode. -The method discussed in this guide uses the **Domain Computers** built-in group. The advantage of this method is that all new devices that are joined to the domain automatically receive the isolated domain GPO. To do this successfully, you must make sure that the WMI filters and security group filters exclude devices that must not receive the GPOs. Use device groups that deny both read and apply Group Policy permissions to the GPOs, such as a group used in the CG\_DOMISO\_NOIPSEC example design. Devices that are members of some zones must also be excluded from applying the GPOs for the main isolated domain. For more information, see the "Prevent members of a group from applying a GPO" section in [Assign Security Group Filters to the GPO](assign-security-group-filters-to-the-gpo.md). +The method discussed in this guide uses the **Domain Computers** built-in group. The advantage of this method is that all new devices that are joined to the domain automatically receive the isolated domain GPO. To define this setting successfully, you must make sure that the WMI filters and security group filters exclude devices that must not receive the GPOs. Use device groups that deny both read and apply Group Policy permissions to the GPOs, such as a group used in the CG\_DOMISO\_NOIPSEC example design. Devices that are members of some zones must also be excluded from applying the GPOs for the main isolated domain. For more information, see the "Prevent members of a group from applying a GPO" section in [Assign Security Group Filters to the GPO](assign-security-group-filters-to-the-gpo.md). Without such a group (or groups), you must either add devices individually or use the groups containing device accounts that are available to you. @@ -67,7 +67,7 @@ After a computer is a member of the group, you can force a Group Policy refresh ## To refresh Group Policy on a device -From an elevated command prompt, type the following: +From an elevated command prompt, type the following command: ``` syntax gpupdate /target:computer /force @@ -77,7 +77,7 @@ After Group Policy is refreshed, you can see which GPOs are currently applied to ## To see which GPOs are applied to a device -From an elevated command prompt, type the following: +From an elevated command prompt, type the following command: ``` syntax gpresult /r /scope:computer diff --git a/windows/security/threat-protection/windows-firewall/add-test-devices-to-the-membership-group-for-a-zone.md b/windows/security/threat-protection/windows-firewall/add-test-devices-to-the-membership-group-for-a-zone.md index e3a45c598a..15f91730ba 100644 --- a/windows/security/threat-protection/windows-firewall/add-test-devices-to-the-membership-group-for-a-zone.md +++ b/windows/security/threat-protection/windows-firewall/add-test-devices-to-the-membership-group-for-a-zone.md @@ -25,9 +25,9 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -Before you deploy your rules to large numbers of devices, you must thoroughly test the rules to make sure that communications are working as expected. A misplaced WMI filter or an incorrectly typed IP address in a filter list can easily block communications between devices. Although we recommend that you set your rules to request mode until testing and deployment is complete, we also recommend that you initially deploy the rules to a small number of devices only to be sure that the correct GPOs are being processed by each device. +Before you deploy your rules to large numbers of devices, you must thoroughly test the rules to make sure that communications are working as expected. A misplaced WMI filter or an incorrectly typed IP address in a filter list can easily block communications between devices. Although we recommend that you set your rules to request mode until testing and deployment is complete. We also recommend that you initially deploy the rules to a few devices only to be sure that the correct GPOs are being processed by each device. -Add at least one device of each supported operating system type to each membership group. Make sure every GPO for a specific version of Windows and membership group has a device among the test group. After Group Policy has been refreshed on each test device, check the output of the **gpresult** command to confirm that each device is receiving only the GPOs it is supposed to receive. +Add at least one device of each supported operating system type to each membership group. Make sure every GPO for a specific version of Windows and membership group has a device among the test group. After Group Policy has been refreshed on each test device, check the output of the **gpresult** command to confirm that each device is receiving only the GPOs it's supposed to receive. **Administrative credentials** @@ -53,7 +53,7 @@ In this topic: 5. Type the name of the device in the text box, and then click **OK**. -6. Repeat steps 5 and 6 for each additional device account or group that you want to add. +6. Repeat steps 5 and 6 for each extra device account or group that you want to add. 7. Click **OK** to close the group properties dialog box. @@ -61,7 +61,7 @@ After a device is a member of the group, you can force a Group Policy refresh on ## To refresh Group Policy on a device -From a elevated command prompt, run the following: +From an elevated command prompt, run the following command: ``` syntax gpupdate /target:device /force @@ -71,7 +71,7 @@ After Group Policy is refreshed, you can see which GPOs are currently applied to ## To see which GPOs are applied to a device -From an elevated command prompt, run the following: +From an elevated command prompt, run the following command: ``` syntax gpresult /r /scope:computer diff --git a/windows/security/threat-protection/windows-firewall/basic-firewall-policy-design.md b/windows/security/threat-protection/windows-firewall/basic-firewall-policy-design.md index 2523d0ce01..b2dfe86d3b 100644 --- a/windows/security/threat-protection/windows-firewall/basic-firewall-policy-design.md +++ b/windows/security/threat-protection/windows-firewall/basic-firewall-policy-design.md @@ -24,13 +24,13 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -Many organizations have a network perimeter firewall that is designed to prevent the entry of malicious traffic in to the organization's network, but do not have a host-based firewall enabled on each device in the organization. +Many organizations have a network perimeter firewall that is designed to prevent the entry of malicious traffic in to the organization's network, but don't have a host-based firewall enabled on each device in the organization. -The Basic Firewall Policy Design helps you to protect the devices in your organization from unwanted network traffic that gets through the perimeter defenses, or that originates from inside your network. In this design, you deploy firewall rules to each device in your organization to allow traffic that is required by the programs that are used. Traffic that does not match the rules is dropped. +The Basic Firewall Policy Design helps you to protect the devices in your organization from unwanted network traffic that gets through the perimeter defenses, or that originates from inside your network. In this design, you deploy firewall rules to each device in your organization to allow traffic that is required by the programs that are used. Traffic that doesn't match the rules is dropped. Traffic can be blocked or permitted based on the characteristics of each network packet: its source or destination IP address, its source or destination port numbers, the program on the device that receives the inbound packet, and so on. This design can also be deployed together with one or more of the other designs that add IPsec protection to the network traffic permitted. -Many network administrators do not want to tackle the difficult task of determining all the appropriate rules for every program that is used by the organization, and then maintaining that list over time. In fact, most programs do not require specific firewall rules. The default behavior of Windows and most contemporary applications makes this task easy: +Many network administrators don't want to tackle the difficult task of determining all the appropriate rules for every program that is used by the organization, and then maintaining that list over time. In fact, most programs don't require specific firewall rules. The default behavior of Windows and most contemporary applications makes this task easy: - On client devices, the default firewall behavior already supports typical client programs. Programs create any required rules for you as part of the installation process. You only have to create a rule if the client program must be able to receive unsolicited inbound network traffic from another device. @@ -42,7 +42,7 @@ Many network administrators do not want to tackle the difficult task of determin For example, by using the predefined groups for Core Networking and File and Printer Sharing you can easily configure GPOs with rules for those frequently used networking protocols. -With few exceptions, the firewall can be enabled on all configurations. Therefore, we recommended that you enable the firewall on every device in your organization. This includes servers in your perimeter network, on mobile and remote clients that connect to the network, and on all servers and clients in your internal network. +With a few exceptions, the firewall can be enabled on all configurations. Therefore, we recommend that you enable the firewall on every device in your organization. The term "device" includes servers in your perimeter network, on mobile and remote clients that connect to the network, and on all servers and clients in your internal network. > [!CAUTION] > Stopping the service associated with Windows Defender Firewall with Advanced Security is not supported by Microsoft. @@ -51,11 +51,11 @@ By default, in new installations, Windows Defender Firewall with Advanced Securi If you turn off the Windows Defender Firewall service you lose other benefits provided by the service, such as the ability to use IPsec connection security rules, Windows Service Hardening, and network protection from forms of attacks that use network fingerprinting. -Compatible third-party firewall software can programmatically disable only the parts of Windows Defender Firewall that might need to be disabled for compatibility. This is the recommended approach for third-party firewalls to coexist with the Windows Defender Firewall; third-party party firewalls that comply with this recommendation have the certified logo from Microsoft.  +Compatible third-party firewall software can programmatically disable only the parts of Windows Defender Firewall that might need to be disabled for compatibility. This approach is the recommended one for third-party firewalls to coexist with the Windows Defender Firewall; third-party party firewalls that comply with this recommendation have the certified logo from Microsoft.  An organization typically uses this design as a first step toward a more comprehensive Windows Defender Firewall design that adds server isolation and domain isolation. -After implementing this design, you will have centralized management of the firewall rules applied to all devices that are running Windows in your organization. +After implementing this design, you'll have centralized management of the firewall rules applied to all devices that are running Windows in your organization. > [!IMPORTANT] > If you also intend to deploy the [Domain Isolation Policy Design](domain-isolation-policy-design.md), or the [Server Isolation Policy Design](server-isolation-policy-design.md), we recommend that you do the design work for all three designs together, and then deploy in layers that correspond with each design. diff --git a/windows/security/threat-protection/windows-firewall/best-practices-configuring.md b/windows/security/threat-protection/windows-firewall/best-practices-configuring.md index 20bc578f08..d71e89f983 100644 --- a/windows/security/threat-protection/windows-firewall/best-practices-configuring.md +++ b/windows/security/threat-protection/windows-firewall/best-practices-configuring.md @@ -43,7 +43,7 @@ When you open the Windows Defender Firewall for the first time, you can see the *Figure 1: Windows Defender Firewall* -1. **Domain profile**: Used for networks where there is a system of account authentication against a domain controller (DC), such as an Azure Active Directory DC +1. **Domain profile**: Used for networks where there's a system of account authentication against a domain controller (DC), such as an Azure Active Directory DC 2. **Private profile**: Designed for and best used in private networks such as a home network @@ -69,7 +69,7 @@ For more on configuring basic firewall settings, see [Turn on Windows Firewall a In many cases, a next step for administrators will be to customize these profiles using rules (sometimes called filters) so that they can work with user apps or other types of software. For example, an administrator or user may choose to add a rule to accommodate a program, open a port or protocol, or allow a predefined type of traffic. -This can be accomplished by right-clicking either **Inbound Rules** or **Outbound Rules**, and selecting **New Rule**. The interface for adding a new rule looks like this: +This rule-adding task can be accomplished by right-clicking either **Inbound Rules** or **Outbound Rules**, and selecting **New Rule**. The interface for adding a new rule looks like this: ![Rule creation wizard.](images/fw02-createrule.png) @@ -89,11 +89,11 @@ allowing these inbound exceptions. 2. Explicit block rules will take precedence over any conflicting allow rules. -3. More specific rules will take precedence over less specific rules, except in the case of explicit block rules as mentioned in 2. (For example, if the parameters of rule 1 includes an IP address range, while the parameters of rule 2 include a single IP host address, rule 2 will take precedence.) +3. More specific rules will take precedence over less specific rules, except if there are explicit block rules as mentioned in 2. (For example, if the parameters of rule 1 include an IP address range, while the parameters of rule 2 include a single IP host address, rule 2 will take precedence.) -Because of 1 and 2, it is important that, when designing a set of policies, you make sure that there are no other explicit block rules in place that could inadvertently overlap, thus preventing the traffic flow you wish to allow. +Because of 1 and 2, it's important that, when designing a set of policies, you make sure that there are no other explicit block rules in place that could inadvertently overlap, thus preventing the traffic flow you wish to allow. -A general security best practice when creating inbound rules is to be as specific as possible. However, when new rules must be made that use ports or IP addresses, consider using consecutive ranges or subnets instead of individual addresses or ports where possible. This avoids creation of multiple filters under the hood, reduces complexity, and helps to avoid performance degradation. +A general security best practice when creating inbound rules is to be as specific as possible. However, when new rules must be made that use ports or IP addresses, consider using consecutive ranges or subnets instead of individual addresses or ports where possible. This approach avoids creation of multiple filters under the hood, reduces complexity, and helps to avoid performance degradation. > [!NOTE] > Windows Defender Firewall does not support traditional weighted, administrator-assigned rule ordering. An effective policy set with expected behaviors can be created by keeping in mind the few, consistent, and logical rule behaviors described above. @@ -102,13 +102,13 @@ A general security best practice when creating inbound rules is to be as specifi ### Inbound allow rules -When first installed, networked applications and services issue a listen call specifying the protocol/port information required for them to function properly. As there is a default block action in Windows Defender Firewall, it is necessary to create inbound exception rules to allow this traffic. It is common for the app or the app installer itself to add this firewall rule. Otherwise, the user (or firewall admin on behalf of the user) needs to manually create a rule. +When first installed, networked applications and services issue a listen call specifying the protocol/port information required for them to function properly. As there's a default block action in Windows Defender Firewall, it's necessary to create inbound exception rules to allow this traffic. It's common for the app or the app installer itself to add this firewall rule. Otherwise, the user (or firewall admin on behalf of the user) needs to manually create a rule. -If there are no active application or administrator-defined allow rule(s), a dialog box will prompt the user to either allow or block an application's packets the first time the app is launched or tries to communicate in the network. +If there's no active application or administrator-defined allow rule(s), a dialog box will prompt the user to either allow or block an application's packets the first time the app is launched or tries to communicate in the network. -- If the user has admin permissions, they will be prompted. If they respond *No* or cancel the prompt, block rules will be created. Two rules are typically created, one each for TCP and UDP traffic. +- If the user has admin permissions, they'll be prompted. If they respond *No* or cancel the prompt, block rules will be created. Two rules are typically created, one each for TCP and UDP traffic. -- If the user is not a local admin, they will not be prompted. In most cases, block rules will be created. +- If the user isn't a local admin, they won't be prompted. In most cases, block rules will be created. In either of the scenarios above, once these rules are added they must be deleted in order to generate the prompt again. If not, the traffic will continue to be blocked. @@ -118,11 +118,11 @@ In either of the scenarios above, once these rules are added they must be delete ### Known issues with automatic rule creation -When designing a set of firewall policies for your network, it is a best practice to configure allow rules for any networked applications deployed on the host. Having these rules in place before the user first launches the application will help ensure a seamless experience. +When designing a set of firewall policies for your network, it's a best practice to configure allow rules for any networked applications deployed on the host. Having these rules in place before the user first launches the application will help ensure a seamless experience. -The absence of these staged rules does not necessarily mean that in the end an application will be unable to communicate on the network. However, the behaviors involved in the automatic creation of application rules at runtime require user interaction and administrative privilege. If the device is expected to be used by non-administrative users, you should follow best practices and provide these rules before the application's first launch to avoid unexpected networking issues. +The absence of these staged rules doesn't necessarily mean that in the end an application will be unable to communicate on the network. However, the behaviors involved in the automatic creation of application rules at runtime require user interaction and administrative privilege. If the device is expected to be used by non-administrative users, you should follow best practices and provide these rules before the application's first launch to avoid unexpected networking issues. -To determine why some applications are blocked from communicating in the network, check for the following: +To determine why some applications are blocked from communicating in the network, check for the following instances: 1. A user with sufficient privileges receives a query notification advising them that the application needs to make a change to the firewall policy. Not fully understanding the prompt, the user cancels or dismisses the prompt. @@ -148,7 +148,7 @@ Firewall rules can be deployed: Rule merging settings control how rules from different policy sources can be combined. Administrators can configure different merge behaviors for Domain, Private, and Public profiles. -The rule merging settings either allow or prevent local admins from creating their own firewall rules in addition to those obtained from Group Policy. +The rule-merging settings either allow or prevent local administrators from creating their own firewall rules in addition to those rules obtained from Group Policy. ![Customize settings.](images/fw05-rulemerge.png) @@ -160,12 +160,12 @@ equivalent setting is *AllowLocalPolicyMerge*. This setting can be found under e If merging of local policies is disabled, centralized deployment of rules is required for any app that needs inbound connectivity. -Admins may disable *LocalPolicyMerge* in high security environments to maintain tighter control over endpoints. This can impact some apps and services that automatically generate a local firewall policy upon installation as discussed above. For these types of apps and services to work, admins should push rules centrally via group policy (GP), Mobile Device +Administrators may disable *LocalPolicyMerge* in high-security environments to maintain tighter control over endpoints. This setting can impact some applications and services that automatically generate a local firewall policy upon installation as discussed above. For these types of apps and services to work, admins should push rules centrally via group policy (GP), Mobile Device Management (MDM), or both (for hybrid or co-management environments). [Firewall CSP](/windows/client-management/mdm/firewall-csp) and [Policy CSP](/windows/client-management/mdm/policy-configuration-service-provider) also have settings that can affect rule merging. -As a best practice, it is important to list and log such apps, including the network ports used for communications. Typically, you can find what ports must be open for a given service on the app's website. For more complex or customer application deployments, a more thorough analysis may be needed using network packet capture tools. +As a best practice, it's important to list and log such apps, including the network ports used for communications. Typically, you can find what ports must be open for a given service on the app's website. For more complex or customer application deployments, a more thorough analysis may be needed using network packet capture tools. In general, to maintain maximum security, admins should only push firewall exceptions for apps and services determined to serve legitimate purposes. @@ -177,7 +177,7 @@ supported in application rules. We currently only support rules created using th ## Know how to use "shields up" mode for active attacks -An important firewall feature you can use to mitigate damage during an active attack is the "shields up" mode. It is an informal term referring to an easy method a firewall administrator can use to temporarily increase security in the face of an active attack. +An important firewall feature you can use to mitigate damage during an active attack is the "shields up" mode. It's an informal term referring to an easy method a firewall administrator can use to temporarily increase security in the face of an active attack. Shields up can be achieved by checking **Block all incoming connections, including those in the list of allowed apps** setting found in either the Windows Settings app or the legacy file *firewall.cpl*. @@ -190,9 +190,9 @@ incoming connections, including those in the list of allowed apps** setting foun *Figure 7: Legacy firewall.cpl* -By default, the Windows Defender Firewall will block everything unless there is an exception rule created. This setting overrides the exceptions. +By default, the Windows Defender Firewall will block everything unless there's an exception rule created. This setting overrides the exceptions. -For example, the Remote Desktop feature automatically creates firewall rules when enabled. However, if there is an active exploit using multiple ports and services on a host, you can, instead of disabling individual rules, use the shields up mode to block all inbound connections, overriding previous exceptions, including the rules for Remote Desktop. The Remote Desktop rules remain intact but remote access will not work as long as shields up is activated. +For example, the Remote Desktop feature automatically creates firewall rules when enabled. However, if there's an active exploit using multiple ports and services on a host, you can, instead of disabling individual rules, use the shields up mode to block all inbound connections, overriding previous exceptions, including the rules for Remote Desktop. The Remote Desktop rules remain intact but remote access won't work as long as shields up is activated. Once the emergency is over, uncheck the setting to restore regular network traffic. @@ -203,7 +203,7 @@ What follows are a few general guidelines for configuring outbound rules. - The default configuration of Blocked for Outbound rules can be considered for certain highly secure environments. However, the Inbound rule configuration should never be changed in a way that Allows traffic by default. -- It is recommended to Allow Outbound by default for most deployments for the sake of simplification around app deployments, unless the enterprise prefers tight security controls over ease-of-use. +- It's recommended to Allow Outbound by default for most deployments for the sake of simplification around app deployments, unless the enterprise prefers tight security controls over ease-of-use. - In high security environments, an inventory of all enterprise-spanning apps must be taken and logged by the administrator or administrators. Records must include whether an app used requires network connectivity. Administrators will need to create new rules specific to each app that needs network connectivity and push those rules centrally, via group policy (GP), Mobile Device Management (MDM), or both (for hybrid or co-management environments). diff --git a/windows/security/threat-protection/windows-firewall/boundary-zone-gpos.md b/windows/security/threat-protection/windows-firewall/boundary-zone-gpos.md index e867dc86b4..10fa58f666 100644 --- a/windows/security/threat-protection/windows-firewall/boundary-zone-gpos.md +++ b/windows/security/threat-protection/windows-firewall/boundary-zone-gpos.md @@ -29,9 +29,9 @@ All the devices in the boundary zone are added to the group CG\_DOMISO\_Boundary >**Note:**  If you are designing GPOs for at least Windows Vista or Windows Server 2008, you can design your GPOs in nested groups. For example, you can make the boundary group a member of the isolated domain group, so that it receives the firewall and basic isolated domain settings through that nested membership, with only the changes supplied by the boundary zone GPO. For simplicity, this guide describes the techniques used to create the independent, non-layered policies. We recommend that you create and periodically run a script that compares the memberships of the groups that must be mutually exclusive and reports any devices that are incorrectly assigned to more than one group. -This means that you create a GPO for a boundary group for a specific operating system by copying and pasting the corresponding GPO for the isolated domain, and then modifying the new copy to provide the behavior required in the boundary zone. +This recommendation means that you create a GPO for a boundary group for a specific operating system by copying and pasting the corresponding GPO for the isolated domain, and then modifying the new copy to provide the behavior required in the boundary zone. -The boundary zone GPOs discussed in this guide are only for server versions of Windows because client devices are not expected to participate in the boundary zone. If the need for one occurs, either create a new GPO for that version of Windows, or expand the WMI filter attached to one of the existing boundary zone GPOs to make it apply to the client version of Windows. +The boundary zone GPOs discussed in this guide are only for server versions of Windows because client devices aren't expected to participate in the boundary zone. If the need for one occurs, either create a new GPO for that version of Windows or expand the WMI filter attached to one of the existing boundary zone GPOs to make it apply to the client version of Windows. In the Woodgrove Bank example, only the GPO settings for a Web service on at least Windows Server 2008 are discussed. diff --git a/windows/security/threat-protection/windows-firewall/boundary-zone.md b/windows/security/threat-protection/windows-firewall/boundary-zone.md index 11c757ec1c..11d52f96fe 100644 --- a/windows/security/threat-protection/windows-firewall/boundary-zone.md +++ b/windows/security/threat-protection/windows-firewall/boundary-zone.md @@ -31,20 +31,20 @@ Devices in the boundary zone are trusted devices that can accept communication r The GPOs you build for the boundary zone include IPsec or connection security rules that request authentication for both inbound and outbound network connections, but don't require it. -These boundary zone devices might receive unsolicited inbound communications from untrusted devices that use plaintext and must be carefully managed and secured in other ways. Mitigating this extra risk is an important part of deciding whether to add a device to the boundary zone. For example, completing a formal business justification process before adding each device to the boundary zone minimizes the additional risk. The following illustration shows a sample process that can help make such a decision. +These boundary zone devices might receive unsolicited inbound communications from untrusted devices that use plaintext and must be carefully managed and secured in other ways. Mitigating this extra risk is an important part of deciding whether to add a device to the boundary zone. For example, completing a formal business justification process before adding each device to the boundary zone minimizes the extra risk. The following illustration shows a sample process that can help make such a decision. ![design flowchart.](images/wfas-designflowchart1.gif) -The goal of this process is to determine whether the risk of adding a device to a boundary zone can be mitigated to a level that makes it acceptable to the organization. Ultimately, if the risk cannot be mitigated, membership must be denied. +The goal of this process is to determine whether the risk of adding a device to a boundary zone can be mitigated to a level that makes it acceptable to the organization. Ultimately, if the risk can't be mitigated, membership must be denied. -You must create a group in Active Directory to contain the members of the boundary zones. The settings and rules for the boundary zone are typically very similar to those for the isolated domain, and you can save time and effort by copying those GPOs to serve as a starting point. The primary difference is that the authentication connection security rule must be set to request authentication for both inbound and outbound traffic, instead of requiring inbound authentication and requesting outbound authentication as used by the isolated domain. +You must create a group in Active Directory to contain the members of the boundary zones. The settings and rules for the boundary zone are typically similar to those settings and rules for the isolated domain, and you can save time and effort by copying those GPOs to serve as a starting point. The primary difference is that the authentication connection security rule must be set to request authentication for both inbound and outbound traffic, instead of requiring inbound authentication and requesting outbound authentication as used by the isolated domain. [Planning Group Policy Deployment for Your Isolation Zones](planning-group-policy-deployment-for-your-isolation-zones.md) section discusses creation of the group and how to link it to the GPOs that apply the rules to members of the group. ## GPO settings for boundary zone servers running at least Windows Server 2008 -The boundary zone GPO for devices running at least Windows Server 2008 should include the following: +The boundary zone GPO for devices running at least Windows Server 2008 should include the following components: - IPsec default settings that specify the following options: diff --git a/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design-example.md b/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design-example.md index 2904f65cb4..17c7175cd6 100644 --- a/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design-example.md +++ b/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design-example.md @@ -27,13 +27,13 @@ ms.technology: windows-sec This design example continues to use the fictitious company Woodgrove Bank, as described in the sections [Firewall Policy Design Example](firewall-policy-design-example.md), [Domain Isolation Policy Design Example](domain-isolation-policy-design-example.md), and [Server Isolation Policy Design Example](server-isolation-policy-design-example.md). -One of the servers that must be included in the domain isolation environment is a device running UNIX that supplies other information to the WGBank dashboard program running on the client devices. This device sends updated information to the WGBank front-end servers as it becomes available, so it is considered unsolicited inbound traffic to the devices that receive this information. +One of the servers that must be included in the domain isolation environment is a device running UNIX that supplies other information to the WGBank dashboard program running on the client devices. This device sends updated information to the WGBank front-end servers as it becomes available, so it's considered unsolicited inbound traffic to the devices that receive this information. ## Design requirements -One possible solution to this is to include an authentication exemption rule in the GPO applied to the WGBank front-end servers. This rule would instruct the front-end servers to accept traffic from the non-Windows device even though it cannot authenticate. +One possible solution to this design example is to include an authentication exemption rule in the GPO applied to the WGBank front-end servers. This rule would instruct the front-end servers to accept traffic from the non-Windows device even though it can't authenticate. -A more secure solution, and the one selected by Woodgrove Bank, is to include the non-Windows device in the domain isolation design. Because it cannot join an Active Directory domain, Woodgrove Bank chose to use certificate-based authentication. Certificates are cryptographically-protected documents, encrypted in such a way that their origin can be positively confirmed. +A more secure solution, and the one selected by Woodgrove Bank, is to include the non-Windows device in the domain isolation design. Because it can't join an Active Directory domain, Woodgrove Bank chose to use certificate-based authentication. Certificates are cryptographically protected documents, encrypted in such a way that their origin can be positively confirmed. In this case, Woodgrove Bank used Active Directory Certificate Services to create the appropriate certificate. They might also have acquired and installed a certificate from a third-party commercial certification authority. They then used Group Policy to deploy the certificate to the front-end servers. The GPOs applied to the front-end servers also include updated connection security rules that permit certificate-based authentication in addition to Kerberos V5 authentication. They then manually installed the certificate on the UNIX server. @@ -51,11 +51,11 @@ The non-Windows device can be effectively made a member of the boundary zone or Woodgrove Bank uses Active Directory groups and GPOs to deploy the domain isolation settings and rules to the devices in their organization. -The inclusion of one or more non-Windows devices to the network requires only a simple addition to the GPOs for devices that must communicate with the non-Windows device. The addition is allowing certificate-based authentication in addition to the Active Directory–supported Kerberos V5 authentication. This does not require including new rules, just adding certificate-based authentication as an option to the existing rules. +The inclusion of one or more non-Windows devices to the network requires only a simple addition to the GPOs for devices that must communicate with the non-Windows device. The addition is allowing certificate-based authentication in addition to the Active Directory–supported Kerberos V5 authentication. This certificate-based authoring doesn't require including new rules, just adding certificate-based authentication as an option to the existing rules. -When multiple authentication methods are available, two negotiating devices agree on the first one in their lists that match. Because the majority of the devices in Woodgrove Bank's network run Windows, Kerberos V5 is listed as the first authentication method in the rules. Certificate-based authentication is added as an alternate authentication type. +When multiple authentication methods are available, two negotiating devices agree on the first one in their lists that match. Because most of the devices in Woodgrove Bank's network run Windows, Kerberos V5 is listed as the first authentication method in the rules. Certificate-based authentication is added as an alternate authentication type. -By using the Active Directory Users and Computers snap-in, Woodgrove Bank created a group named NAG\_COMPUTER\_WGBUNIX. They then added the device accounts to this group for Windows devices that need to communicate with the non-Windows devices. If all the devices in the isolated domain need to be able to access the non-Windows devices, then the **Domain Computers** group can be added to the group as a member. +With the help of the Active Directory Users and Computers snap-in, Woodgrove Bank created a group named NAG\_COMPUTER\_WGBUNIX. They then added the device accounts to this group for Windows devices that need to communicate with the non-Windows devices. If all the devices in the isolated domain need to be able to access the non-Windows devices, then the **Domain Computers** group can be added to the group as a member. Woodgrove Bank then created a GPO that contains the certificate, and then attached security group filters to the GPO that allow read and apply permissions to only members of the NAG\_COMPUTER\_WGBUNIX group. The GPO places the certificate in the **Local Computer / Personal / Certificates** certificate store. The certificate used must chain back to a certificate that is in the **Trusted Root Certification Authorities** store on the local device. diff --git a/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design.md b/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design.md index f134b8f1db..e61836e9ce 100644 --- a/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design.md +++ b/windows/security/threat-protection/windows-firewall/certificate-based-isolation-policy-design.md @@ -27,13 +27,13 @@ ms.technology: windows-sec In the certificate-based isolation policy design, you provide the same types of protections to your network traffic as described in the [Domain Isolation Policy Design](domain-isolation-policy-design.md) and [Server Isolation Policy Design](server-isolation-policy-design.md) sections. The only difference is the method used to share identification credentials during the authentication of your network traffic. -Domain isolation and server isolation help provide security for the devices on the network that run Windows and that can be joined to an Active Directory domain. However, in most corporate environments there are typically some devices that must run another operating system. These devices cannot join an Active Directory domain, without a third-party package being installed. Also, some devices that do run Windows cannot join a domain for a variety of reasons. To rely on Kerberos V5 as the authentication protocol, the device needs to be joined to the Active Directory and (for non-Windows devices) support Kerberos as an authentication protocol. +Domain isolation and server isolation help provide security for the devices on the network that run Windows and that can be joined to an Active Directory domain. However, in most corporate environments there are typically some devices that must run another operating system. These devices can't join an Active Directory domain, without a third-party package being installed. Also, some devices that do run Windows can't join a domain for various reasons. To rely on Kerberos V5 as the authentication protocol, the device needs to be joined to the Active Directory and (for non-Windows devices) support Kerberos as an authentication protocol. -To authenticate with non-domain member devices, IPsec supports using standards-based cryptographic certificates. Because this authentication method is also supported by many third-party operating systems, it can be used as a way to extend your isolated domain to devices that do not run Windows. +To authenticate with non-domain member devices, IPsec supports using standards-based cryptographic certificates. Because this authentication method is also supported by many third-party operating systems, it can be used as a way to extend your isolated domain to devices that don't run Windows. The same principles of the domain and server isolation designs apply to this design. Only devices that can authenticate (in this case, by providing a specified certificate) can communicate with the devices in your isolated domain. -For Windows devices that are part of an Active Directory domain, you can use Group Policy to deploy the certificates required to communicate with the devices that are trusted but are not part of the Active Directory domain. For other devices, you will have to either manually configure them with the required certificates, or use a third-party program to distribute the certificates in a secure manner. +For Windows devices that are part of an Active Directory domain, you can use Group Policy to deploy the certificates required to communicate with the devices that are trusted but aren't part of the Active Directory domain. For other devices, you'll have to either manually configure them with the required certificates, or use a third-party program to distribute the certificates in a secure manner. For more info about this design: From 532dd304aefd9fc7f029d820a3e32517655c9da8 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Tue, 5 Jul 2022 14:40:02 +0530 Subject: [PATCH 025/109] Acrolinx Enhancement Effort --- ...list-configuring-rules-for-the-boundary-zone.md | 8 ++++---- ...st-configuring-rules-for-the-encryption-zone.md | 6 +++--- ...st-configuring-rules-for-the-isolated-domain.md | 6 +++--- .../checklist-creating-group-policy-objects.md | 10 +++++----- ...clients-of-a-standalone-isolated-server-zone.md | 4 ++-- ...-a-certificate-based-isolation-policy-design.md | 2 +- ...-a-standalone-server-isolation-policy-design.md | 4 ++-- .../configure-authentication-methods.md | 14 +++++++------- .../configure-key-exchange-main-mode-settings.md | 12 ++++++------ .../configure-the-rules-to-require-encryption.md | 10 +++++----- 10 files changed, 38 insertions(+), 38 deletions(-) diff --git a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-boundary-zone.md b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-boundary-zone.md index 4fa942aac8..7e7fc7b158 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-boundary-zone.md +++ b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-boundary-zone.md @@ -27,16 +27,16 @@ ms.technology: windows-sec The following checklists include tasks for configuring connection security rules and IPsec settings in your GPOs to implement the boundary zone in an isolated domain. -Rules for the boundary zone are typically the same as those for the isolated domain, with the exception that the final rule is left to only request, not require, authentication. +Rules for the boundary zone are typically the same as those rules for the isolated domain, with the exception that the final rule is left to only request, not require, authentication. **Checklist: Configuring boundary zone rules** -This checklist assumes that you have already created the GPO for the isolated domain as described in [Checklist: Implementing a Domain Isolation Policy Design](checklist-implementing-a-domain-isolation-policy-design.md). After you create a copy for the boundary zone, make sure that you do not change the rule from request authentication to require authentication when you create the other GPOs. +This checklist assumes that you've already created the GPO for the isolated domain as described in [Checklist: Implementing a Domain Isolation Policy Design](checklist-implementing-a-domain-isolation-policy-design.md). After you create a copy for the boundary zone, make sure that you don't change the rule from request authentication to require authentication when you create the other GPOs. | Task | Reference | | - | - | -| Make a copy of the domain isolation GPO for this version of Windows to serve as a starting point for the GPO for the boundary zone. Unlike the GPO for the main isolated domain zone, this copy is not changed after deployment to require authentication.| [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md) | -| If you are working on a copy of a GPO, modify the group memberships and WMI filters so that they are correct for the boundary zone and version of Windows for which this GPO is intended.| [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | +| Make a copy of the domain isolation GPO for this version of Windows to serve as a starting point for the GPO for the boundary zone. Unlike the GPO for the main isolated domain zone, this copy isn't changed after deployment to require authentication.| [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md) | +| If you're working on a copy of a GPO, modify the group memberships and WMI filters so that they're correct for the boundary zone and version of Windows for which this GPO is intended.| [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Link the GPO to the domain level of the Active Directory organizational unit hierarchy.| [Link the GPO to the Domain](link-the-gpo-to-the-domain.md)| | Add your test computers to the membership group for the boundary zone. Be sure to add at least one for each operating system supported by a different GPO in the group.| [Add Test Computers to the Membership Group for a Zone](add-test-devices-to-the-membership-group-for-a-zone.md)| | Verify that the connection security configuration is protecting network traffic with authentication when it can, and that unauthenticated traffic is accepted. | [Verify That Network Traffic Is Authenticated](verify-that-network-traffic-is-authenticated.md)| diff --git a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-encryption-zone.md b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-encryption-zone.md index f543b9606f..1d42ae70b6 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-encryption-zone.md +++ b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-encryption-zone.md @@ -27,16 +27,16 @@ ms.technology: windows-sec This checklist includes tasks for configuring connection security rules and IPsec settings in your GPOs to implement the encryption zone in an isolated domain. -Rules for the encryption zone are typically the same as those for the isolated domain, with the exception that the main rule requires encryption in addition to authentication. +Rules for the encryption zone are typically the same as those rules for the isolated domain, with the exception that the main rule requires encryption in addition to authentication. **Checklist: Configuring encryption zone rules** -This checklist assumes that you have already created the GPO for the isolated domain as described in [Checklist: Implementing a Domain Isolation Policy Design](checklist-implementing-a-domain-isolation-policy-design.md). You can then copy those GPOs for use with the encryption zone. After you create the copies, modify the main rule to require encryption in addition to the authentication required by the rest of the isolated domain. +This checklist assumes that you've already created the GPO for the isolated domain as described in [Checklist: Implementing a Domain Isolation Policy Design](checklist-implementing-a-domain-isolation-policy-design.md). You can then copy those GPOs for use with the encryption zone. After you create the copies, modify the main rule to require encryption in addition to the authentication required by the rest of the isolated domain. | Task | Reference | | - | - | | Make a copy of the domain isolation GPOs to serve as a starting point for the GPOs for the encryption zone.| [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| -| Modify the group memberships and WMI filters so that they are correct for the encryption zone and the version of Windows for which this GPO is intended. | [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | +| Modify the group memberships and WMI filters so that they're correct for the encryption zone and the version of Windows for which this GPO is intended. | [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Add the encryption requirements for the zone. | [Configure the Rules to Require Encryption](configure-the-rules-to-require-encryption.md)| | Link the GPO to the domain level of the Active Directory organizational unit hierarchy. | [Link the GPO to the Domain](link-the-gpo-to-the-domain.md)| | Add your test computers to the membership group for the encryption zone. Be sure to add at least one for each operating system supported by a different GPO in the group.| [Add Test Computers to the Membership Group for a Zone](add-test-devices-to-the-membership-group-for-a-zone.md)| diff --git a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-isolated-domain.md b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-isolated-domain.md index e5e7186579..4f86220ff8 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-isolated-domain.md +++ b/windows/security/threat-protection/windows-firewall/checklist-configuring-rules-for-the-isolated-domain.md @@ -31,8 +31,8 @@ The following checklists include tasks for configuring connection security rules | Task | Reference | | - | - | -| Create a GPO for the computers in the isolated domain running one of the operating systems. After you have finished the tasks in this checklist and configured the GPO for that version of Windows, you can create a copy of it.| [Checklist: Creating Group Policy Objects](checklist-creating-group-policy-objects.md)
    [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| -| If you are working on a GPO that was copied from another GPO, modify the group memberships and WMI filters so that they are correct for the isolated domain zone and the version of Windows for which this GPO is intended. | [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | +| Create a GPO for the computers in the isolated domain running one of the operating systems. After you've finished the tasks in this checklist and configured the GPO for that version of Windows, you can create a copy of it.| [Checklist: Creating Group Policy Objects](checklist-creating-group-policy-objects.md)
    [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| +| If you're working on a GPO that was copied from another GPO, modify the group memberships and WMI filters so that they're correct for the isolated domain zone and the version of Windows for which this GPO is intended. | [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Configure IPsec to exempt all ICMP network traffic from IPsec protection. | [Exempt ICMP from Authentication](exempt-icmp-from-authentication.md)| | Create a rule that exempts all network traffic to and from computers on the exemption list from IPsec. | [Create an Authentication Exemption List Rule](create-an-authentication-exemption-list-rule.md)| | Configure the key exchange (main mode) security methods and algorithms to be used. | [Configure Key Exchange (Main Mode) Settings](configure-key-exchange-main-mode-settings.md)| @@ -44,4 +44,4 @@ The following checklists include tasks for configuring connection security rules | Verify that the connection security rules are protecting network traffic to and from the test computers. | [Verify That Network Traffic Is Authenticated](verify-that-network-traffic-is-authenticated.md)| -Do not change the rules for any of your zones to require authentication until all of the zones have been set up and are operating correctly. +Don't change the rules for any of your zones to require authentication until all of the zones have been set up and are operating correctly. diff --git a/windows/security/threat-protection/windows-firewall/checklist-creating-group-policy-objects.md b/windows/security/threat-protection/windows-firewall/checklist-creating-group-policy-objects.md index 1796cc336e..373174d887 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-creating-group-policy-objects.md +++ b/windows/security/threat-protection/windows-firewall/checklist-creating-group-policy-objects.md @@ -25,7 +25,7 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -To deploy firewall or IPsec settings or firewall or connection security rules, we recommend that you use Group Policy in AD DS. This section describes a tested, efficient method that requires some up-front work, but serves an administrator well in the long run by making GPO assignments as easy as dropping a device into a membership group. +To deploy firewall or IPsec settings or firewall or connection security rules, we recommend that you use Group Policy in AD DS. This section describes a tested, efficient method that requires some up-front work, but serves an administrator well in the end by making GPO assignments as easy as dropping a device into a membership group. The checklists for firewall, domain isolation, and server isolation include a link to this checklist. @@ -35,19 +35,19 @@ For most GPO deployment tasks, you must determine which devices must receive and ## About exclusion groups -A Windows Defender Firewall with Advanced Security design must often take into account domain-joined devices on the network that cannot or must not apply the rules and settings in the GPOs. Because these devices are typically fewer in number than the devices that must apply the GPO, it is easier to use the Domain Members group in the GPO membership group, and then place these exception devices into an exclusion group that is denied Apply Group Policy permissions on the GPO. Because deny permissions take precedence over allow permissions, a device that is a member of both the membership group and the exception group is prevented from applying the GPO. Devices typically found in a GPO exclusion group for domain isolation include the domain controllers, DHCP servers, and DNS servers. +A Windows Defender Firewall with Advanced Security design must often take into account domain-joined devices on the network that can't or must not apply the rules and settings in the GPOs. Because these devices are typically fewer in number than the devices that must apply the GPO, it's easier to use the Domain Members group in the GPO membership group, and then place these exception devices into an exclusion group that is denied Apply Group Policy permissions on the GPO. Because deny permissions take precedence over allow permissions, a device that is a member of both the membership group and the exception group is prevented from applying the GPO. Devices typically found in a GPO exclusion group for domain isolation include the domain controllers, DHCP servers, and DNS servers. -You can also use a membership group for one zone as an exclusion group for another zone. For example, devices in the boundary and encryption zones are technically in the main domain isolation zone, but must apply only the GPO for their assigned role. To do this, the GPOs for the main isolation zone deny Apply Group Policy permissions to members of the boundary and encryption zones. +You can also use a membership group for one zone as an exclusion group for another zone. For example, devices in the boundary and encryption zones are technically in the main domain isolation zone, but must apply only the GPO for their assigned role. To use the group as an exclusion group, the GPOs for the main isolation zone deny Apply Group Policy permissions to members of the boundary and encryption zones. **Checklist: Creating Group Policy objects** | Task | Reference | | - | - | | Review important concepts and examples for deploying GPOs in a way that best meets the needs of your organization.| [Identifying Your Windows Defender Firewall with Advanced Security Deployment Goals](identifying-your-windows-firewall-with-advanced-security-deployment-goals.md)
    [Planning Group Policy Deployment for Your Isolation Zones](planning-group-policy-deployment-for-your-isolation-zones.md)| -| Create the membership group in AD DS that will be used to contain device accounts that must receive the GPO.
    If some devices in the membership group are running an operating system that does not support WMI filters, such as Windows 2000, create an exclusion group to contain the device accounts for the devices that cannot be blocked by using a WMI filter.| [Create a Group Account in Active Directory](create-a-group-account-in-active-directory.md)| +| Create the membership group in AD DS that will be used to contain device accounts that must receive the GPO.
    If some devices in the membership group are running an operating system that doesn't support WMI filters, such as Windows 2000, create an exclusion group to contain the device accounts for the devices that can't be blocked by using a WMI filter.| [Create a Group Account in Active Directory](create-a-group-account-in-active-directory.md)| | Create a GPO for each version of Windows that has different implementation requirements.| [Create a Group Policy Object](create-a-group-policy-object.md) | | Create security group filters to limit the GPO to only devices that are members of the membership group and to exclude devices that are members of the exclusion group.|[Assign Security Group Filters to the GPO](assign-security-group-filters-to-the-gpo.md) | | Create WMI filters to limit each GPO to only the devices that match the criteria in the filter.| [Create WMI Filters for the GPO](create-wmi-filters-for-the-gpo.md) | -| If you are working on a GPO that was copied from another, modify the group memberships and WMI filters so that they are correct for the new zone or version of Windows for which this GPO is intended.|[Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | +| If you're working on a GPO that was copied from another, modify the group memberships and WMI filters so that they're correct for the new zone or version of Windows for which this GPO is intended.|[Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Link the GPO to the domain level of the Active Directory organizational unit hierarchy.| [Link the GPO to the Domain](link-the-gpo-to-the-domain.md) | | Before adding any rules or configuring the GPO, add a few test devices to the membership group, and make sure that the correct GPO is received and applied to each member of the group.| [Add Test Devices to the Membership Group for a Zone](add-test-devices-to-the-membership-group-for-a-zone.md) | diff --git a/windows/security/threat-protection/windows-firewall/checklist-creating-rules-for-clients-of-a-standalone-isolated-server-zone.md b/windows/security/threat-protection/windows-firewall/checklist-creating-rules-for-clients-of-a-standalone-isolated-server-zone.md index 62905bf49e..b6369d7c01 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-creating-rules-for-clients-of-a-standalone-isolated-server-zone.md +++ b/windows/security/threat-protection/windows-firewall/checklist-creating-rules-for-clients-of-a-standalone-isolated-server-zone.md @@ -31,13 +31,13 @@ This checklist includes tasks for configuring connection security rules and IPse | Task | Reference | | - | - | -| Create a GPO for the client devices that must connect to servers in the isolated server zone, and that are running one of the versions of Windows. After you have finished the tasks in this checklist, you can make a copy of it.| [Checklist: Creating Group Policy Objects](checklist-creating-group-policy-objects.md)
    [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| +| Create a GPO for the client devices that must connect to servers in the isolated server zone, and that are running one of the versions of Windows. After you've finished the tasks in this checklist, you can make a copy of it.| [Checklist: Creating Group Policy Objects](checklist-creating-group-policy-objects.md)
    [Copy a GPO to Create a New GPO](copy-a-gpo-to-create-a-new-gpo.md)| | To determine which devices receive the GPO, assign the NAG for the isolated servers to the security group filter for the GPO. Make sure that each GPO has the WMI filter for the correct version of Windows.| [Modify GPO Filters to Apply to a Different Zone or Version of Windows](modify-gpo-filters-to-apply-to-a-different-zone-or-version-of-windows.md) | | Configure IPsec to exempt all ICMP network traffic from IPsec protection. | [Exempt ICMP from Authentication](exempt-icmp-from-authentication.md)| | Create a rule that exempts all network traffic to and from devices on the exemption list from IPsec. | [Create an Authentication Exemption List Rule](create-an-authentication-exemption-list-rule.md)| | Configure the key exchange (main mode) security methods and algorithms to be used. | [Configure Key Exchange (Main Mode) Settings](configure-key-exchange-main-mode-settings.md)| | Configure the data protection (quick mode) algorithm combinations to be used. | [Configure Data Protection (Quick Mode) Settings](configure-data-protection-quick-mode-settings.md)| | Configure the authentication methods to be used. | [Configure Authentication Methods](configure-authentication-methods.md)| -| Create a rule that requests authentication for network traffic. Because fallback-to-clear behavior in Windows Vista and Windows Server 2008 has no delay when communicating with devices that cannot use IPsec, you can use the same any-to-any rule used in an isolated domain.| [Create an Authentication Request Rule](create-an-authentication-request-rule.md)| +| Create a rule that requests authentication for network traffic. Because fallback-to-clear behavior in Windows Vista and Windows Server 2008 has no delay when communicating with devices that can't use IPsec, you can use the same any-to-any rule used in an isolated domain.| [Create an Authentication Request Rule](create-an-authentication-request-rule.md)| | Link the GPO to the domain level of the Active Directory organizational unit hierarchy. | [Link the GPO to the Domain](link-the-gpo-to-the-domain.md)| | Add your test devices to the NAG for the isolated server zone. Be sure to add at least one for each operating system supported by a different GPO in the group.| [Add Test Devices to the Membership Group for a Zone](add-test-devices-to-the-membership-group-for-a-zone.md)| diff --git a/windows/security/threat-protection/windows-firewall/checklist-implementing-a-certificate-based-isolation-policy-design.md b/windows/security/threat-protection/windows-firewall/checklist-implementing-a-certificate-based-isolation-policy-design.md index a1183f3f52..5d59df9ccd 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-implementing-a-certificate-based-isolation-policy-design.md +++ b/windows/security/threat-protection/windows-firewall/checklist-implementing-a-certificate-based-isolation-policy-design.md @@ -35,7 +35,7 @@ This parent checklist includes cross-reference links to important concepts about | Task | Reference | | - | - | | Review important concepts and examples for certificate-based authentication to determine if this design meets your implementation goals and the needs of your organization.| [Identifying Your Windows Defender Firewall with Advanced Security Deployment Goals](identifying-your-windows-firewall-with-advanced-security-deployment-goals.md)
    [Certificate-based Isolation Policy Design](certificate-based-isolation-policy-design.md)
    [Certificate-based Isolation Policy Design Example](certificate-based-isolation-policy-design-example.md)
    [Planning Certificate-based Authentication](planning-certificate-based-authentication.md) | -| Install the Active Directory Certificate Services (AD CS) role as an enterprise root issuing certification authority (CA). This step is required only if you have not already deployed a CA on your network.| | +| Install the Active Directory Certificate Services (AD CS) role as an enterprise root issuing certification authority (CA). This step is required only if you haven't already deployed a CA on your network.| | | Configure the certificate template for workstation authentication certificates.| [Configure the Workstation Authentication Certificate Template](configure-the-workstation-authentication-certificate-template.md)| | Configure Group Policy to automatically deploy certificates based on your template to workstation devices. | [Configure Group Policy to Autoenroll and Deploy Certificates](configure-group-policy-to-autoenroll-and-deploy-certificates.md)| | On a test device, refresh Group Policy and confirm that the certificate is installed. | [Confirm That Certificates Are Deployed Correctly](confirm-that-certificates-are-deployed-correctly.md)| diff --git a/windows/security/threat-protection/windows-firewall/checklist-implementing-a-standalone-server-isolation-policy-design.md b/windows/security/threat-protection/windows-firewall/checklist-implementing-a-standalone-server-isolation-policy-design.md index 3090ba97d5..c484d2eec0 100644 --- a/windows/security/threat-protection/windows-firewall/checklist-implementing-a-standalone-server-isolation-policy-design.md +++ b/windows/security/threat-protection/windows-firewall/checklist-implementing-a-standalone-server-isolation-policy-design.md @@ -1,6 +1,6 @@ --- title: Checklist Implementing a Standalone Server Isolation Policy Design (Windows) -description: Use these tasks to create a server isolation policy design that is not part of an isolated domain. See references to concepts and links to other checklists. +description: Use these tasks to create a server isolation policy design that isn't part of an isolated domain. See references to concepts and links to other checklists. ms.assetid: 50a997d8-f079-408c-8ac6-ecd02078ade3 ms.reviewer: ms.author: dansimp @@ -25,7 +25,7 @@ ms.technology: windows-sec - Windows 11 - Windows Server 2016 and above -This checklist contains procedures for creating a server isolation policy design that is not part of an isolated domain. For the steps required to create an isolated server zone within an isolated domain, see [Checklist: Configuring Rules for an Isolated Server Zone](checklist-configuring-rules-for-an-isolated-server-zone.md). +This checklist contains procedures for creating a server isolation policy design that isn't part of an isolated domain. For information on the steps required to create an isolated server zone within an isolated domain, see [Checklist: Configuring Rules for an Isolated Server Zone](checklist-configuring-rules-for-an-isolated-server-zone.md). This parent checklist includes cross-reference links to important concepts about the domain isolation policy design. It also contains links to subordinate checklists that will help you complete the tasks that are required to implement this design. diff --git a/windows/security/threat-protection/windows-firewall/configure-authentication-methods.md b/windows/security/threat-protection/windows-firewall/configure-authentication-methods.md index 7522322a6f..b16b7adc8a 100644 --- a/windows/security/threat-protection/windows-firewall/configure-authentication-methods.md +++ b/windows/security/threat-protection/windows-firewall/configure-authentication-methods.md @@ -49,29 +49,29 @@ To complete these procedures, you must be a member of the Domain Administrators 3. **Computer (using Kerberos V5)**. Selecting this option tells the computer to use and require authentication of the computer by using its domain credentials. This option works with other computers that can use IKE v1, including earlier versions of Windows. - 4. **User (using Kerberos V5)**. Selecting this option tells the computer to use and require authentication of the currently logged-on user by using his or her domain credentials. + 4. **User (using Kerberos V5)**. Selecting this option tells the computer to use and require authentication of the currently signed-in user by using their domain credentials. 5. **Computer certificate from this certification authority**. Selecting this option and entering the identification of a certification authority (CA) tells the computer to use and require authentication by using a certificate that is issued by the selected CA. If you also select **Accept only health certificates**, then only certificates that include the system health authentication enhanced key usage (EKU) typically provided in a Network Access Protection (NAP) infrastructure can be used for this rule. 6. **Advanced**. Click **Customize** to specify a custom combination of authentication methods required for your scenario. You can specify both a **First authentication method** and a **Second authentication method**. - The first authentication method can be one of the following: + The first authentication method can be one of the following methods: - **Computer (Kerberos V5)**. Selecting this option tells the computer to use and require authentication of the computer by using its domain credentials. This option works with other computers that can use IKE v1, including earlier versions of Windows. - - **Computer (NTLMv2)**. Selecting this option tells the computer to use and require authentication of the computer by using its domain credentials. This option works only with other computers that can use AuthIP. User-based authentication using Kerberos V5 is not supported by IKE v1. + - **Computer (NTLMv2)**. Selecting this option tells the computer to use and require authentication of the computer by using its domain credentials. This option works only with other computers that can use AuthIP. User-based authentication using Kerberos V5 isn't supported by IKE v1. - **Computer certificate from this certification authority (CA)**. Selecting this option and entering the identification of a CA tells the computer to use and require authentication by using a certificate that is issued by that CA. If you also select **Accept only health certificates**, then only certificates issued by a NAP server can be used. - - **Preshared key (not recommended)**. Selecting this method and entering a preshared key tells the computer to authenticate by exchanging the preshared keys. If they match, then the authentication succeeds. This method is not recommended, and is included only for backward compatibility and testing purposes. + - **Preshared key (not recommended)**. Selecting this method and entering a preshared key tells the computer to authenticate by exchanging the preshared keys. If they match, then the authentication succeeds. This method isn't recommended, and is included only for backward compatibility and testing purposes. If you select **First authentication is optional**, then the connection can succeed even if the authentication attempt specified in this column fails. - The second authentication method can be one of the following: + The second authentication method can be one of the following methods: - - **User (Kerberos V5)**. Selecting this option tells the computer to use and require authentication of the currently logged-on user by using his or her domain credentials. This authentication method works only with other computers that can use AuthIP. User-based authentication using Kerberos V5 is not supported by IKE v1. + - **User (Kerberos V5)**. Selecting this option tells the computer to use and require authentication of the currently signed-in user by using their domain credentials. This authentication method works only with other computers that can use AuthIP. User-based authentication using Kerberos V5 isn't supported by IKE v1. - - **User (NTLMv2)**. Selecting this option tells the computer to use and require authentication of the currently logged-on user by using his or her domain credentials, and uses the NTLMv2 protocol instead of Kerberos V5. This authentication method works only with other computers that can use AuthIP. User-based authentication using Kerberos V5 is not supported by IKE v1. + - **User (NTLMv2)**. Selecting this option tells the computer to use and require authentication of the currently signed-in user by using their domain credentials, and uses the NTLMv2 protocol instead of Kerberos V5. This authentication method works only with other computers that can use AuthIP. User-based authentication using Kerberos V5 isn't supported by IKE v1. - **User health certificate from this certification authority (CA)**. Selecting this option and entering the identification of a CA tells the computer to use and require user-based authentication by using a certificate that is issued by the specified CA. If you also select **Enable certificate to account mapping**, then the certificate can be associated with a user in Active Directory for purposes of granting or denying access to specified users or user groups. diff --git a/windows/security/threat-protection/windows-firewall/configure-key-exchange-main-mode-settings.md b/windows/security/threat-protection/windows-firewall/configure-key-exchange-main-mode-settings.md index 6e18c1001c..d630831fe4 100644 --- a/windows/security/threat-protection/windows-firewall/configure-key-exchange-main-mode-settings.md +++ b/windows/security/threat-protection/windows-firewall/configure-key-exchange-main-mode-settings.md @@ -41,23 +41,23 @@ To complete these procedures, you must be a member of the Domain Administrators 4. In the **Key exchange (Main Mode)** section, click **Advanced**, and then click **Customize**. -5. Select the security methods to be used to help protect the main mode negotiations between the two devices. If the security methods displayed in the list are not what you want, then do the following: +5. Select the security methods to be used to help protect the main mode negotiations between the two devices. If the security methods displayed in the list aren't what you want, then do the following steps: **Important**   - In Windows Vista, Windows Server 2008, or later, you can specify only one key exchange algorithm. This means that if you want to communicate by using IPsec with another device running Windows 8 or Windows Server 2012, then you must select the same key exchange algorithm on both devices. + In Windows Vista, Windows Server 2008, or later, you can specify only one key exchange algorithm. This rule means that if you want to communicate by using IPsec with another device running Windows 8 or Windows Server 2012, then you must select the same key exchange algorithm on both devices. - Also, if you create a connection security rule that specifies an option that requires AuthIP instead of IKE, then only the one combination of the top integrity and encryption security method are used in the negotiation. Make sure that all of your devices that are running at least Windows Vista and Windows Server 2008 have the same methods at the top of the list and the same key exchange algorithm selected. + Also, if you create a connection security rule that specifies an option that requires AuthIP instead of IKE, then only the one combination of the top integrity and encryption security method is used in the negotiation. Ensure that all of your devices that are running at least Windows Vista and Windows Server 2008 have the same methods at the top of the list and the same key exchange algorithm selected. **Note**   - When AuthIP is used, no Diffie-Hellman key exchange protocol is used. Instead, when Kerberos V5 authentication is requested, the Kerberos V5 service ticket secret is used in place of a Diffie-Hellman value. When either certificate authentication or NTLM authentication is requested, a transport level security (TLS) session is established, and its secret is used in place of the Diffie-Hellman value. This happens no matter which Diffie-Hellman key exchange protocol you select. + When AuthIP is used, no Diffie-Hellman key exchange protocol is used. Instead, when Kerberos V5 authentication is requested, the Kerberos V5 service ticket secret is used in place of a Diffie-Hellman value. When either certificate authentication or NTLM authentication is requested, a transport level security (TLS) session is established, and its secret is used in place of the Diffie-Hellman value. This event happens no matter which Diffie-Hellman key exchange protocol you select. - 1. Remove any of the security methods that you do not want by selecting the method and then clicking **Remove**. + 1. Remove any of the security methods that you don't want by selecting the method and then clicking **Remove**. 2. Add any required security method combinations by clicking **Add**, selecting the appropriate encryption algorithm and integrity algorithm from the lists, and then clicking **OK**. >**Caution:**  We recommend that you do not include MD5 or DES in any combination. They are included for backward compatibility only. - 3. After the list contains only the combinations you want, use the up and down arrows to the right of the list to arrange them in the order of preference. The combination that appears first in the list is tried first, and so on. + 3. After the list contains only the combinations you want, use the "up" and "down" arrows to the right of the list to arrange them in the order of preference. The combination that appears first in the list is tried first, and so on. 6. From the list on the right, select the key exchange algorithm that you want to use. diff --git a/windows/security/threat-protection/windows-firewall/configure-the-rules-to-require-encryption.md b/windows/security/threat-protection/windows-firewall/configure-the-rules-to-require-encryption.md index c7c3f8fafc..00d5f4cd23 100644 --- a/windows/security/threat-protection/windows-firewall/configure-the-rules-to-require-encryption.md +++ b/windows/security/threat-protection/windows-firewall/configure-the-rules-to-require-encryption.md @@ -1,6 +1,6 @@ --- title: Configure the Rules to Require Encryption (Windows) -description: Learn how to configure rules to add encryption algorithms and delete the algorithm combinations that do not use encryption for zones that require encryption. +description: Learn how to configure rules to add encryption algorithms and delete the algorithm combinations that don't use encryption for zones that require encryption. ms.assetid: 07b7760f-3225-4b4b-b418-51787b0972a0 ms.reviewer: ms.author: dansimp @@ -20,7 +20,7 @@ ms.technology: windows-sec # Configure the Rules to Require Encryption -If you are creating a zone that requires encryption, you must configure the rules to add the encryption algorithms and delete the algorithm combinations that do not use encryption. +If you're creating a zone that requires encryption, you must configure the rules to add the encryption algorithms and delete the algorithm combinations that don't use encryption. **Administrative credentials** @@ -46,9 +46,9 @@ To complete this procedure, you must be a member of the Domain Administrators gr 9. Click **Require encryption for all connection security rules that use these settings**. - This disables the data integrity rules section. Make sure the **Data integrity and encryption** list contains all of the combinations that your client devices will use to connect to members of the encryption zone. The client devices receive their rules through the GPO for the zone to which they reside. You must make sure that those rules contain at least one of the data integrity and encryption algorithms that are configured in this rule, or the client devices in that zone will not be able to connect to devices in this zone. + This setting disables the data integrity rules section. Ensure the **Data integrity and encryption** list contains all of the combinations that your client devices will use to connect to members of the encryption zone. The client devices receive their rules through the GPO for the zone to which they reside. You must make sure that those rules contain at least one of the data integrity and encryption algorithms that are configured in this rule, or the client devices in that zone won't be able to connect to devices in this zone. -10. If you need to add an algorithm combination, click **Add**, and then select the combination of encryption and integrity algorithms. The options are described in [Configure Data Protection (Quick Mode) Settings](configure-data-protection-quick-mode-settings.md). +10. If you need to add an algorithm combination, click **Add** and then select the combination of encryption and integrity algorithms. The options are described in [Configure Data Protection (Quick Mode) Settings](configure-data-protection-quick-mode-settings.md). **Note**   Not all of the algorithms available in Windows 8 or Windows Server 2012 and later can be selected in the Windows Defender Firewall with Advanced Security user interface. To select them, you can use Windows PowerShell. @@ -57,6 +57,6 @@ To complete this procedure, you must be a member of the Domain Administrators gr For more info, see [Windows Defender Firewall with Advanced Security Administration with Windows PowerShell](windows-firewall-with-advanced-security-administration-with-windows-powershell.md) -11. During negotiation, algorithm combinations are proposed in the order shown in the list. Make sure that the more secure combinations are at the top of the list so that the negotiating devices select the most secure combination that they can jointly support. +11. During negotiation, algorithm combinations are proposed in the order shown in the list. Ensure that the more secure combinations are at the top of the list so that the negotiating devices select the most secure combination that they can jointly support. 12. Click **OK** three times to save your changes. From 0c4fea1c0ff80d6d785ff8aeb18b93d009c39632 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 08:14:39 +1000 Subject: [PATCH 026/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 116 ++++++++++++------------ 1 file changed, 60 insertions(+), 56 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index b5159b32d1..06c3bbd64f 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -1,17 +1,16 @@ --- title: Upgrade Windows Home to Windows Education on personal devices using volume licensing description: Learn how IT Pros can upgrade personal devices from Windows Home to Windows Education using Mobile Device Management and qualifying subscriptions. -keywords: upgrade, Windows Home to Windows Education, education customers, Windows 10 Home, Windows 11 Home, Windows 11 Education, Windows 10 Education, Intune, Mobile Device Management -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: edu +ms.date: 07/05/2021 +ms.prod: windows +ms.technology: windows +ms.topic: how-to ms.localizationpriority: medium author: scottbreenmsft ms.author: scbree -ms.date: 07/05/2021 -ms.reviewer: aczechowski -manager: dansimp +ms.reviewer: +manager: jeffbu +ms.collection: highpri --- # Upgrade Windows Home to Windows Education on personal devices using volume licensing @@ -25,22 +24,28 @@ Customers with qualifying subscriptions can upgrade students personal (or instit IT staff can upgrade student devices using a multiple activation key (MAK). Alternatively, student devices can be upgraded by contacting [Kivuto OnTheHub](http://onthehub.com) to obtain a product key for their device. The table below provides the recommended approach for personal devices depending on the scenario. -|Method|MAK source|Device ownership|Best for| +| Method | MAK source | Device ownership | Best for | |-|-|-|-| -|Mobile Device Management|Volume License Service Center|Personal|IT admin initiated as part of enrolment into device management| -|Kivuto|Kivuto|Personal|Initiated on device by student, parent or guardian| -|Provisioning package|Volume license center|Personal or Corporate|IT admin initiated before performing Autopilot| +| Mobile Device Management | VLSC | Personal | IT admin initiated via device management | +| Kivuto | Kivuto | Personal | Initiated on device by student, parent or guardian | +| Provisioning package | VLSC | Personal or Corporate | IT admin initiated at first boot | Devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Windows Education* or *Windows Enterprise* using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). +## User Notifications + +Users aren't notified their device has been or will be upgraded to Windows Education when using device management. It's the responsibility of the institution to notify their users. Instituions should notify their users that device management will initiate an upgrade to Windows Education and this will give the institution extra capabilities, such as installing applications. + +Device users can disconnect device management from Settings to prevent further actions from being taken on their personal device. For instructions on disconnecting from device management, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). + ## Why upgrade personal devices from Windows Home to Windows Education? -Some school institutions want to streamline student onboarding for personal devices using Mobile Device Management. This could include installing certificates, configuring WiFi profiles and offering applications that are required for learning. Some MDM configuration service providers (CSPs) are not available on Windows Home which can limit the management capabilities. Some key CSPs that can affect mobile device management for these scenarios are: +Some school institutions want to streamline student onboarding for personal devices using Mobile Device Management (MDM). Typical device management activities include installing certificates, configuring WiFi profiles and installing applications. On Windows, device management activities are performed using Configuration Service Providers (CSPs). Some CSPs aren't available on Windows Home, which can limit the management capabilities. Some of the CSPs not availble in Windows Home that can affect typical student onboarding are: - [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications. - [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization. -A full list is available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). For more information about enrolling devices into Microsoft Intune, see [Deployment guide: Enroll Windows devices in Microsoft Intune](/mem/intune/fundamentals/deployment-guide-enrollment-windows). +A full list of CSPs are available at [Configuration service provider reference](/windows/client-management/mdm/configuration-service-provider-reference). For more information about enrolling devices into Microsoft Intune, see [Deployment guide: Enroll Windows devices in Microsoft Intune](/mem/intune/fundamentals/deployment-guide-enrollment-windows). ## Requirements for using a MAK to upgrade from Windows Home to Windows Education @@ -61,13 +66,13 @@ IT admins with access to the VLSC or the Microsoft 365 Admin Center, can find th ### Recommended methods for using a MAK -It’s critical that MAKs are protected whenever they are used. The following processes provide the best protection for a MAK being applied to a device: +It’s critical that MAKs are protected whenever they're used. The following processes provide the best protection for a MAK being applied to a device: - Provisioning package by institution approved staff; -- Manual entry by institution approved staff (do not distribute the key via email); +- Manual entry by institution approved staff (don't distribute the key via email); - Mobile Device Management (like Microsoft Intune) via [WindowsLicensing CSP](/windows/client-management/mdm/windowslicensing-csp); > [!IMPORTANT] - > If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key is not accessible by students. + > If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key isn't accessible by students. - Operating System Deployment processes with tools such as Microsoft Deployment Toolkit or Microsoft Endpoint Configuration Manager. For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](/windows/deployment/upgrade/windows-10-edition-upgrades). @@ -91,38 +96,32 @@ It is not possible to downgrade to Windows Home from Windows Education without r If the computer is reset, Windows Education will be retained. -### Re-install +### Reinstall -If a device upgraded by VLSC MAK has Windows reinstalled by the student, it would need to be reinstalled with Windows Home or whatever edition was installed originally on the device to activate successfully using the key provided with the device at purchase. +The Education upgrade does not apply to reinstalling Windows. Use the original Windows edition when reinstalling Windows. The original product key or [firmware-embedded product key](#what-is-a-firmware-embedded-activation-key) will be used to activate Windows. -If students require a Windows Education key that can work on a new install of Windows, they should use [Kivuto OnTheHub](http://onthehub.com) to request a key prior to graduation. +If students require a *Windows Pro Education* key that can work on a new install of Windows, they should use [Kivuto OnTheHub](http://onthehub.com) to request a key prior to graduation. For details on product keys and reinstalling Windows, see [Find your Windows product key](https://support.microsoft.com/windows/find-your-windows-product-key-aaa2bf69-7b2b-9f13-f581-a806abf0a886). -### Re-sale +### Resale -The license will remain installed on the device if resold and the same conditions above apply for downgrade (in-place) reset or reinstall. - -## User Notifications - -Users are not prompted or notified that their device has been or will be upgraded to Windows Education when using MDM. It is the responsibility of the institution to notify their users that enrolling in MDM will result in the device being upgraded to Windows Education and that this will give the institution extra capabilities such as installing applications. - -As always, device users can unenroll from within Settings to prevent further actions from being taken on their personal device. +The license will remain installed on the device if resold and the same conditions above apply for downgrade, reset or reinstall. ## Step by step process for customers to upgrade personal devices using Microsoft Intune -These steps will configure a Windows edition upgrade policy and target all Windows Home devices that are managed by Microsoft Intune for the upgrade to Windows Education edition using your MAK. +These steps provide instructions on how to use Microsoft Intune to upgrade devices from Home to Education. ### Step 1: Create a Windows Home edition filter -Filters allow you to target the all devices group but to a subset of devices using a filter. In this case the filter will be based on the operating system SKU. This will ensure we only upgrade devices that are running Windows Home edition and avoid upgrading devices that are running Windows Pro/Pro EDU edition which can upgrade using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). +These steps configure a filter that will only apply to devices running the Windows Home SKU. This will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune]/mem/intune/fundamentals/filters). - Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) - Go to **Tenant Administration** > **Filters** -- Click **Create** +- Select **Create** - Create a name for the filter (for example *Windows Home edition*) - Select the **platform** as **Windows 10 and later** - - Click **Next** + - Select **Next** - On the **Rules** screen, configure the following rules: - **operatingSystemSKU** equals **Core (Windows 10/11 Home (101))** - OR @@ -133,74 +132,79 @@ Filters allow you to target the all devices group but to a subset of devices usi > [!NOTE] > Ensure you’ve selected OR as the operator in the right And/Or column - :::image type="content" source="/images/change-home-to-edu-windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: + :::image type="content" source="images/change-home-to-edu-windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: - Optionally select scope tags as required -- Save the filter by clicking **Create** +- Save the filter by selecting **Create** ### Step 2: Create a Windows edition upgrade policy +These steps create and assign a Windows edition upgrade policy. For more information, see [Windows 10/11 device settings to upgrade editions or enable S mode in Intune](/mem/intune/configuration/edition-upgrade-windows-settings). + - Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) - Select **Devices** > **Configuration profiles** - Select **Create profile** - Select the **Platform** as **Windows 10 or later** - Select the **Profile type** as **Templates** - Select the **Template** as **Edition upgrade and mode switch** - - Click **Create** -- Create a name for the filter (for example *Windows Education edition upgrade*), click **Next** + - Select **Create** +- Create a name for the filter (for example *Windows Education edition upgrade*), select **Next** - On the **Configuration settings** screen - Expand **Edition Upgrade** - Change **Edition to upgrade** to **Windows 10/11 Education** - In the **Product Key**, enter your *Windows 10/11 Education MAK* - - Click **Next** -- Optionally select scope tags as required and click **Next** + - Select **Next** +- Optionally select scope tags as required and select **Next** - On the **assignments** screen; - Select **Add all devices** - Next to **All devices**, select **Edit filter** + > [!NOTE] + > You can also target other security groups that contain a smaller scope of users or devices and apply the filter rather than All devices. - Select to **Include filtered devices in assignment** - Select the *Windows Home edition* filter you created earlier - - Click **Select** to save the filter selection - - Click **Next** to progress to the next screen + - Choose **Select** to save the filter selection + - Select **Next** to progress to the next screen - :::image type="content" source="/images/change-home-to-edu-windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: -- Do not configure any applicability rules and click **next** -- Review your settings and click **Create** + :::image type="content" source="images/change-home-to-edu-windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: +- Don't configure any applicability rules and select **next** +- Review your settings and select **Create** -The edition upgrade policy will now apply to all existing and new Windows Home edition devices in your tenant. You can verify they’ve upgraded by checking the Operating System SKU field on the device > hardware screen. +The edition upgrade policy will now apply to all existing and new Windows Home edition devices targeted. ### Step 3: Report on device edition +You can check the Windows versions of managed devices in the Microsoft Endpoint Manager admin console. + - Start in the **Microsoft Endpoint Manager admin console** - Select **Devices** > **Windows** - Select the **Columns** button - Select **Sku Family** -- Click **Export** -- Select **Only include the selected columns in the exported file** and click **Yes** +- Select **Export** +- Select **Only include the selected columns in the exported file** and select **Yes** - Open the file in Excel and filter on the Sku Family column to identify which devices are running the Home SKU ## Frequently asked questions (FAQ) ### My MAK key has run out of activations, how do I request a new one? -- Increases to MAK Activation quantity can be requested by contacting [VLSC support](/licensing/contact-us) and may be granted by exception. -- To do this you must have VLSC Administrator, Key Administrator, or Key Viewer permissions and provide the following information: - - Agreement/Enrollment Number or License ID and Authorization. - - Product Name (includes version and edition). - - Last 5 characters of the product key. - - The number of host activations required. - - Business Justification or Reason for Deployment. +Increases to MAK Activation quantity can be requested by contacting [VLSC support](/licensing/contact-us) and may be granted by exception. A request can be made by accounts with the VLSC Administrator, Key Administrator, or Key Viewer permissions. The request should include the following information: +- Agreement/Enrollment Number or License ID and Authorization. +- Product Name (includes version and edition). +- Last 5 characters of the product key. +- The number of host activations required. +- Business Justification or Reason for Deployment. ### What is a firmware-embedded activation key? A firmware-embedded activation key is a Windows product key that is installed into the firmware of your device to allow for easy activation of Windows. To determine if the computer has a firmware-embedded activation key, type the following command at an elevated Windows PowerShell prompt: ```powershell -(Get-CimInstance -query ‘select * from SoftwareLicensingService’).OA3xOriginalProductKey +(Get-CimInstance -query 'select * from SoftwareLicensingService').OA3xOriginalProductKey ``` -If the device has a firmware-embedded activation key, it will be displayed in the output. If the output is blank, the device does not have a firmware embedded activation key. Most OEM-provided devices designed to run Windows 8 or later will have a firmware-embedded key. +If the device has a firmware-embedded activation key, it will be displayed in the output. Otherwise, the device doesn't have a firmware embedded activation key. Most OEM-provided devices designed to run Windows 8 or later will have a firmware-embedded key. -A firmware embedded key is only required to upgrade using Subscription Activation, a MAK upgrade does not require the firmware embedded key. +A firmware embedded key is only required to upgrade using Subscription Activation, a MAK upgrade dosn't require the firmware embedded key. ### What is a multiple activation key and how does it differ from using KMS, Active Directory based activation or Subscription Activation? From b04c81902fb1a6e0edf32bb460cd676399492c23 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 08:21:51 +1000 Subject: [PATCH 027/109] Delete change-home-to-edu-windows-edition-upgrade-policy.png --- ...me-to-edu-windows-edition-upgrade-policy.png | Bin 45890 -> 0 bytes 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 education/images/change-home-to-edu-windows-edition-upgrade-policy.png diff --git a/education/images/change-home-to-edu-windows-edition-upgrade-policy.png b/education/images/change-home-to-edu-windows-edition-upgrade-policy.png deleted file mode 100644 index f9c4fc3a128310e500be82ccfaa19de52549b613..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 45890 zcmbTdby!r<*DpSbf})5>w}424bc0GtcZbq2bT^73-QC^I3|&fh49&pM-9yK~@A!S+ zd!PGz|GCd|&-1{Ub9S74&R%=1&-$#jgOwDdurNt5K_C#;7in=75D1M11bQs<>@jes zN*D_YoE|x;NPPxXjF9aB7f;MT$$tWYsv}?AeR~RAKew0Gb^?K3b^iN%)N5B{0s_^{ zd=dYo=5DaR_~K)%`UA#sVCZ*h#+=8iSP*d^iEdrQKueq%gC8doq;GNvHUO=!k@K#F zUdor34NZn{v9NSD=dWUM+7%_$a|9ATk$56u`_txO$zx>h!rHnj9LwHUwA^FFW5j6= z5-8lB?v!CpF*i3C^KQpkpj<;&NhvBmK0YxqF*Q|JPfuQl*QyQfU@t%>^??e;q)Bl(Xz5KU=-QhFaC9@O<#jNImxCUG(5uBqSDb$i`o!9Zl0?x!f6~8{PHk>(dfr{Y?LK|_lv7rt z>@2~>;d}I)y5P~mt92$%;qB5FKJipSOa+fXf5_i+azZdAbc8Ax85v6qT0Jc+irU-T z>+9>2(Cu&OSy>C%*b~_dS?TGEG|EZ*SwPNOO5_z46@BacorAZ`BZa|94qIK8ta=Kv zmn!*;w!%$0@dUv4N5#Mm$U6j7JOTudIPF=&2Lq zD30n7vpurM{+&zmmjLu#qS^Jp^Zt5EFyVvMBz?*|M)e>m3Xk=nWKQbbj{#g?O!hU^ z50M|q5O2s)7|X00Wm;6g(sBE4*N(c_t85q1>)>7T#w8@A0~$6uZ7F03%`wmBFyq7C zMc3nY^HAv4Sr;3&x6xN=D<~*fTknsg3rZkj5UpOS=^T}`dEr@XD3b7ks;cA7;Z)S^ zB_Xc0QdzvgtznC^U;X!jZz*?=!wcPl3e8lE+3XhR-jw_<*R7u}Q6HR{nHd}$oS2wM z&`pBz^4|pE5Cg-~90)Y%_M;$KElFU}O&Ah*OGDH77a^wOu=9-|8xzkmSWbK2W(;Pf zjr!?lh+<#KO!rbCySz|fJd>t5Fhh!7vgmGLL-;Ug zSV)bBIC85UZ_fWTTKzb8jLc+}89b+_KW=du6k|GQ9SQ6{W;B&~I4Rymr#vLg_vAV+ zrkv2WdI+4780b^co-+2vQjlb8?|Q{VN5_WL(i?SiH6SDgL!a`7a0UGWXrJXlw#fD4&$ncPuGVukrqsDov}&vzAW%IO z&*p-F^7FL6C(?UWLs3;hGtL4CmxhOX6Ysaw1Xf;aJL4e&AS#K%*i_$|Jlid$Pekd!1vJQO34C z8=)#%5JdfSLx?N1ttKEbhaOTREjFc67e7r^2~%Q@(bQyYID24%9n~L zOS?YO4o;k%^q%@r3wAqPNREq3VAD)2Gi`}HfEW{ zc#Zgfmcuz<$g?wgW|%d9O2HJqYz89Zkqf2m3{=s_PO)95$w>dCd_g$z#gtBZVY%kp z9#O)PQ8cvJG#+agbdy9*%9h@LZ%P^Qahmu$F5Zqkw@ygL1Ix z2iiKnhrpH5+CojmP1zHIO1IaiV@95unO${JF)$|w=Epf$+bk!Ia|FKzzeR6IB-EAP zuAOmK9U=;bb0Q0>`gfXF^S5&a=Qt|&4cNGCnKj?Lc**JTHHifl7N9N{Gs53799$_9 zl8A8Sxg8;tm9wWdNSajqQpR3ehf|6o8oy14;4_KKwmyyzjeBg10)Y-o^qXC&)jyk< z%q+n(h%^>~xA(8(001q{=4AFW1z+E)-kmV%FFui{P}m9@_xL5>gJVYjqNsWW!wVBW@j$AT$@HR>@~|drW&gXrdsUiW6-jhk&%&PI02lbB$O*7gCspr z^IYHZ)%`DO!Cp;TsPOo3N=TR~9<|Rx7)GezhIIEX_(KGW?j}h}!-$wbd6G^=!Pq5w zx?bJZHQ!f(630sqG)V3G191!$A~Q|r}B2ZWX$o}TNawe9!G*$f(lvIdP< zG!+>2I}dB&xA$&Bf~cm%b!D|YhBg=QXn?=JQUB&EaT-^|rjNdfUz+w&wyAvTmzKiF zY>&L{TdZ>V>0ex6O16|Xm|Hi~&6ABoHtGb`i;Jp;5+6>FfLo6^6Ay|yNwMPOn8B(d zu$?il#Z4roZlwi|%|~lH_9&SQ;W{@>rch=ZU48=FgE-yp^~BUS^{P4f%lUv$ov1-u|c+KNBX1%bZi!fWK2PLB2no!((9DyD1b(wquO zsA?jGIJw$(5-YtdTvDjh74(xbj$E!vbcU4BJNZ~VvNZZ|Pv>6K%#E1QdSPo@yp`$2jdL9cWoIrdJIKbY?APronAmUWg9+&`#bGEu zzloAE`$kOQ;xlplneNNDtEA3*(m&{R{VeJUgxUjjyUqL?`tR8MKbHfBCrg4;rHEG8 z)9`~V>69fgZ7|Ns{pEsa*5Qibuw<96DbEwc2eTJ|RR_&>{54$LDQf@JM)gg3N0t8` zEY#iIZB;wpW4PvVTG-x>$lOqmQ!P6!TGPKnbsggRww{<5xSi{69o=iH_Crz<6-rM_ zg}KU(!&zM~an%_^s9Y~t4=M~yH9&NNuKQY!jx}?$%$N{r8X8&RZp%M@;l02Chm*GV zpn>cQ9qwk_w@p4S?Mw88NQ4rcA1>;eq-|w}-5p`;v&0CU(qX|`q>%Ty6`$N8KD>pYh1crnuL(>|i{f+f<#=v= zJyNKBA&6l)KQpw4r#B2Ay#Jx29+3?hnq5P;Efdmg0D(TLuYEnr#^oRL(uz@_n;T<6 zQyM4R7JdSl%oX>eZ|Xl!2?5Nd_R02*B`_A?N6zK7Z7DtdbRYipf@j~39#Va{JqY0_%$0Qho9w$F+U z0QAx>-0vEtQx;qS0RfGTjpaJEREg_vPHfTNY{|F7Yu@02efkmpcq%= zA)Sfsa=Ny3Cy_0^-Q6HQ!Se*U5gI4m>Yjmldg>@a%j+*a_#Wuf&l(s6iTAyr@~2Pt z@zBXs-WuqM4$bTGl^a?uUnBS*;ZUMQV%XMdr_R945!#ALm) z{XQilLm`%af6Ya&q^fFpGra81|FOWQJ*ZBll>zhuKp7~HyHT~d%znQ^M6KYO6}rS% zM|>M)u7jauH`e?Q;6L9V*}&`cTimPZOFjb4@^gDvODsDnJh!t2Tz1Ez z5B?Z(`^^MP=4J;3!5oQrZOOW|05>wO&HZF`q0wn)k391UXgLA+)H0)h(^9xKn8-FE zb)xUKD6z!JfCA>GUp;MSkga`xvKW^ZaCvyWuj~!Bi3EPSdw6&Z4EWJW+-yDo_)^J# zL<--jB5y3DqwG2E`B+- zWi}k}@nI49V^VBMXYS5@FM!zbPp*K6c` ziwd-eDDl!suDswVpm@zHNwV2A?bC()>A#qK_Z0Jx~3} z*<$I?9rD~7zCVjz_;v3cPucWtM(J1NE7hVu!U^=a#9wX>n~#7=7iU-c`t>b#M_N!$ zeOVcE2(&L4myVw0y;|M+x(TK&J&by9rjj?z+JPYidU3S$0JKU8(9W}*C^*~S9qt=! z-B?o%&)lK^l_R~E>GV)EW!0(w?Kv&|5F;~l-WR+Xl>`wqC#Tbv)|Q2@-@~1#St!g} z?~sFM1|d0^;!^!hE_?J}2|ZM)sHmn&HLY}y!XoM>Hp+> zusB}+i}xe`_C+BMixs@irsX8;Y=16Rof0vBdaH|NN}lFS9QB_`F0e055#8$pelZ?)EvayR+=! z{<6JA0=hc>SEjVi^<92p;lvVAZ*xA=AfSp!ad9Dim?`3v7&%t)uB&7H(`fkS&{Dcr zvS{cU23Z@nDk{^jET`p67~^&Xz0R#9QRs2}4)kKgnwoDk!#6Eo^LYCV04g(#%&T^th>5wR7w(a&% z@aC=0=`iosP_h`ErOx|I@n{0m;;8q^PfH}@uk$cJX6~MGPY=mv6I#Ok~zP3Vo{6 z!+ApKw9ZD?HTLTrFCFTyU{_F0aF3SPh=Ow0?a1aGmFL*(yY81gDyCa0)qe+8n`Y$} z5ed^G_*MuSa~1szlUeFco$wdtFDE3hJa(}ivmH!53AQ*17!&dh)B6iXynAWRifdu; z#juHRyuER@>bP{(9`O3hBW6J@go#w7_p!H|iii~+#-q#;Eo*;vijM=G1AMVLQS1sI zbkpXdrya7irQc#0p``|;wHSm3vKy8OxdiIz6t!>~t zqwh98hsyN3&qj(q+{F?Km`#knX_ zC9GT=9F!d#*z>hz<25wPb+|oM>2q?hsY3GIxn-0RFu{{We=9$(59?U*csW%69zJx& z6EZO;B^{!-nU40{pJk6`%mhT?EJMG+{;$1e0IZSz>k`CV5unw?3z+k}1nO&Jm&kX! zn$dL3t*;||#s-!&_GHVok0j+tr)!bcV1z@~kx@3}SJIb5@#VrGT!$soAVfevnrxj( z+%|)n>+u*vOKR6mYhRmJrsueQo#E{y*^aD6N}XdLe6j1ffwo}z95$XRQS0J?gb3R3 zi4-pmkJ3Awf!iq}olh3QS3l$Q2=_n>yt*Vc9P)?JxaUuN&Y|&dUf8)_OpglmR-L22 z*KJW*+J{~g<9QU+AJ#Sn_zmq`VCV{d@d_R7O~_~CY?F?aPrnd>zqaJjrC`zfQN9&O z*FAKbF-fQm=jUma>=qn+Mc@kU>m7lVOW3J~xz8y2UZ!`wAA7{{cC9&v?i@F;%j8;X zJsYPR!wK6BFI@wT&6@q}nt`sWn|LiQ#s_vzNi=(tmyJ<9DFVh6I3xWMI)!0OtjpTh zE7k9>yNd^)0wO@XspXY~_ z*3Hx#0x*Nl!(Jf!mm`$GbOHuT;k8p3&FP~$GfgFsH7Aa)_csz$iC!9dxNLv$xtKFo zXp9^9hGz+|iwY*|W;`2wlpFlf1OG^04uza?ywkp5*nX^(5svy=Pq+t!Ab&%L`qKm{ zucfuLs{g2#npzhl|5T0XAT>2L`b(le5Ike$Dh1l#v!NF+yLkrmx2pchNRN{99pI{j zL^Y^Y?6s)=&d<-X!XpfkGZl2&48z4RtM%3J7OE%a%ku3Bc*(DiE+D%tIx(mB`>6J2 zjuiS02QU3`7$u6<6EmJ%$Zy}rKvicU_Z>C(e%1FPi6i4PN+eZRk?uOR%89dD#a#9mBRMoL^w-;`~ahBY0|xNTNNYu63F(b6UyEw!F93}alMKZH`0VDS zmvUlUZWIqj%v11K=yZq^&sz9u`6q$b#?=QSG(v94;~&Rn<=p5MB6KQHlWnFvuI#Gf zZ(5zrIt%JbN=ju6W-EybntFPAT3YS^)KYCw)l(Y+BOCQXq#P?W5YnNqa@9*UuqZ{+ zI>eOKR<=LXRD+XC;#;nAYKBsIk9sNn@RDVE+hzvnt2{M~%(Z0oU+!OJXTd3>ubRK)fowSCYjaZkOpY|fv~;zb`w@3AyDGDoRnx1ez1ZQk1Urb; zqRVR2tn4Z+B-EZqaD20znX7XuYnR**95e#^s7|jxI^QrOU@{(Nd8KMZu16*T<_JM& z# z)(n9-xHH_63+D4bw4z&DS|w!OXOe5}PhA*3?7p7Lc0HH}{5e3Cm#P-NGS#iO%pbRS zhi$A&D1|RR;IZw)54axy%pZWrr}E@?{*-x%6=gn>cD)uU`f_b|pz}G+D!djf1;6Pb zwNulmGQDMo`l38bm^tDP&Swn$R)gup3t-iXy296Tw=3%rfma1@Or{z znQTh&PKC&&U`2ST;HtQDzTJkA&ld+r;py-BLaoVe#|v<;x^J%mf86?bvOb4rFL{k& zgwKCFl7A7Afg;$uGg{OS*%-w2)WzN?Gp6aVLCDceoEJVEiv>$)!9RPttZr1j{UUj5 zRqpVXw7L4{naL4{$kt1^jle0TXw_J`o?!1?x@mP3+2@INS{=bKv3!LtA5H4zY*5eZ zpfMv4e{$K7IUc)l41TP6=Q!pt2F7Y(OdEk(k;eS9*^d-!Hbh7lm)=*W7q}3TyMVsR z`mPnWODz&!<$Kxc`J_#8W`fB}P|a{G?sRo)4$-<9)AZey{_i%YxQ(tvrf$Pls*NDO z`)fMGHnHNqK>%>DHn|A0@PGKAWMXlOA8syGvMj?>(nyk?ErXEDHuA)N9^iQRD_glh!l4lT5|O3N`d2LUv%|ErsEUG{#O}Z zOGaYN+VCp5vp8)Wq)AKlMJP(o|=ExwI=3OTrOi|GuY& zXHPhgLx+*HX@rpfvP!My`9R)pp@g({gBOAA{dJI)TLM9q;rnT_Z#6;a*h1jh=mByw z`Bb9rJqFaSm?fzi_^ldzqm#pQzo`A=Jju2#IS z`i+kHSy>-ha>YGw@EP;IsQoB8xdGT!Zm@cGbA({enkbtvvS(q6TGJN#^B<)EXg&2i zK>_cp;}?Xi0N0+su15T zu4p&zo06u+;EmYd5;>ZE?nbq4k9dqV$MaiErLsU9Dy!+`Ch9g`S!8CT8UJVpbvB1D zZzb>nHi+HlT}Vr;iK(g2^+qCe7LZ?afLW{rD4HCJ(3hX^1GMqx+x>~APNg-q( z^>F+uK9s~0>cy}Ngz0w{@|}L7W6>+?m02#F)je=iL=J}*UQq0;Lj<4hkE&fA)NV(v zpe~mR)kSajA!h->e$fKHcYNe?nE(U>2qppxqx#_s|J8rPkJq)R`?yPGp0Dxx;uM1ZUk3Vs4_eH(rjb>B5reUG@%55_rM{wT$ zfEpcZP-p0gAcvP}a|%#}v~-kdLt88qC3bUGjV?F^p_&XsCEA>C%apYW z74)0Vx4%re`|w7^#H>~Wq!0#$`$xR*v}Hc3w$nM=@Z+^C5Xhdc!C?*EZsK#^hMt6k zghyi|AgS_O(ZYXh07m!ck z$;Y5w;22tcZ5cm&Y%V!!RhvTi7zlXhj(T@)i7J9-UqmOAZ`%z`Oh6hM_;`5}Gp?%u zZrxt=?77_)wD+SsJzdyDO}vm+==iRm`gcNPF$lCw;jY)6QiX@M@;npsYa+Rz>swe& zJQb8f7Kk6Dvj5T;_$Bo8k4O-7-|QJAP8;Zr^mi5}J3$;JH46sSpT{73ub}FzJMlbq zWZ?9_7(`YYAUN82=f{WdbAU?_D9vQThfrwg{ye1bU-@@c4;dmyAc6r}ek_naa{4pS zU*gq&>S106{Y$^G#~0W6cU|HCAHw<%E&73F$bbD*2Lux+X}|=g88|dQ<^4;BT4wwo zQIEHn(zziUu6tYa{$aXI5ev(aN27Q_FiaJe zDuGr`3Tkt8ROSPDv}kSEcZQZP`mtj?MFyEl(JjUS8kaeXdvuQYB|~UHy3Ilu#E4Sf z^#>lJ3}F#Xdk;yumf`Q-p=SCb#meKiC4L^sMi=BQfxIY{99R7dvttv!Slk$8xVKnV z?QMoC6};V=o+xEK>HW3Xm;?3CbIWw?FxD8*i>@uuDgDTH(Ns3bIwt*t`@I{UHmtDS zkExhXSjyx`PL&|z%>CARNj$n-+LXc_czZJ;9@_;z3q{pvr#@f`!YT}t>_?gvofZo+ zM_vjrC%Rgv@RXVP${2iwkiZ(x{&XkDOdhZA|Ir}UrZ{DVV19CG_p7<@#A@ABsw$k? zmlay{f#^|jy2YA@2ciipkc*7p&}HKMBpKOVr(~@cHCgJr^>y0)Wn8Ar*rLCEi3WBn zJ&@S(Us%wFs2~c}a+{X0!5^S)3+@_a{4VcLcQ%NnJb4C5)(rz$zW0kH#!i07ip>6$ z`_^sX64J+_E)psLfgU zZ~fueO@Qo@h@d3qyohjKWSk&xKlrTGcRzlUpkmf_Wk>W%uU3>~{;M-5Wg7;JZ6WDS zbsn=$fjzP1n|I-2TI$-RBPXS&KJ>0oR1t1+pEFdSa8BWRChWq>3vKlKn>?7kWY(Ym zgS3#xTPwYOv|W<7+S~H1s@bge1nb1O@WH=qVRWWYj$h&n(_TJ<8}ICu#iGb3q{6h7 z0(rB5#gq%aZo_C0Rk-NUx@NB~fi6xju$hTz=KunpnThmmN@qJzuNxLEGNd4v3&btIoD4qu#57wFQtwFfqE5z3 zSAOztyD@6q?Yc&@aH?1#kH^sAXZug@2kED~ztAjwc$YX@e0~qp_cfg#!cLtyHylsV z6h%6kuL5tY(u-yKGphK~T{)IYXv{-8jxI`bSsj8NgZ>=+RKOX@mKjh?Y`JwV8HMD+ zZvvzPo)3$xjWv8Mc@sLe!1V{W^Lp17yxOs0MG!iFr5d|M)cR8W`u#Ec^m6ZY- zUX3({II9_V53RMx*{tH5CG2weuwm@+?bLHYyONfc&JF&0Q9=RgS4iCbQqhY~_;sE-mNFm)4`JaC}C6H&07+;Z#~79l;hpyPZnQqX|JA zy<3`YCM>&6r}Y^>A-PUwBS0GF;lB5|so*yeivsFz$9W#^bnM++4nx*Fc61^&Y<`+0 zW6|Oi+P{;B_?5o!re9t?%1Yc->-l8}xxm-hb26Nj6g$n1e3-E2 zw6$)^IeAgW4<@oP{nU>ZNxAYv`;4QKwKeO74FxnVLhEm-n5yMYNxSfCAojj6l15

    9VNP!P}=#`C)4;z{B8&NvCJIf1?jD4 zXY+EQt;sGafyX!-O>;N{%G@QKiA|MR;f=>m=;`u4O>S8qauA((clr8}H&-n!h&`zx z5^3&=S!CL zPi|h}t1_1-zANB*SkC;k$EmU3ayM&urqbHE@oYPt{y{+Hq~NN31LbtFgWFvecXA!} z-tt8Pt48>o2WoMHkZ0WC&Awd&E0y5Jjj?t2CbOMZvX`z(<+b+tY{_Z4-)L^~9nz^# zX&ApGl0GHTTL6k5KcwZZ8!zxn!SaySbkRG^puwBI?w&_AX6f%4r=|{D`_1*p;G$ol z{yO^P2Ur}I`=#7R${8pPy)Q4r*h4GE2VYvMfu9)q zze^Wza0prO2kdP<+m?im${|eFS*7x1HdjRDA%)!A`BovnKV61E&Q?o4hO0fZ!7BT6 zgw6w2nAE&T zUXs&5*yHC&iUAe19py&QmAs}n6^o%ua4*-cD!=pQ#c^&CTUYa|^pXkAZg9VxV$L}u zJ|1eMx%J%+N>0GRb259v!JT`)N;MIyd3*Xu8~U+Q;4ih^swCAODQ)mBm*+*@n!YSw zT4jt-6N-sT&+0=_w$$Hzvd;T;0cX1g)J8MJ3_9XxI9}hat!JlnpiR@M*oGf1ntR^( z>i6%`EPGGorvcAfj*<{%ai2XQCXdP=?|eM<^1zJLJEHiM9a9*Xy~oKi==}4H*)9po zOK``IKe{rvsNgM=UvXM$Dy@`n!ev^1z4{L8g;}vmMb(HZ+BNx0%Q+?Sbu?}Bip5a>nxVIszTc03yx6rD0+CwpUK0Q!M5_W?pV} zReZ{8i@%|v4L)JiJxq!m4ZlWB7we5`45NvX&KL!67*O>xNOlztZxjxx;9FqPNo4L$ zyIHxBvSgK&B+hmPvv*=n1AOQVq=QtD>Q$R9u7HYwaI6%S8!eVr^Mo}@T}$#61% z9DdL~{r0rL@wsAU{|Bxk08^9No8{4(7SQTt$9gVre`U~*XGsxb*6t)BYRS=w_swK% zWPe+9V}7H9&0DM?6;tC_G)X5^^mXUvv|N;re_OnI{Q%yYu4T4IaPy7z6PC_Q!n@j@ z&yZxN#j!E;0E|5hilc&R@$Gu@qQn8)n|hr6K9ad@}-=F1YKfkpJH1g78ZVB zK9ZAhtoUPnhgV=gaiCw{YF<+yC!7+jBk15dRsy|bbH8Hf(a=_|SFFMakf&s6;@h0r zoAP$Y`ihhbNswmWHK^Yl^OcfnY$9Br-kWi=x8kSi z5gAnWh^&P+Rd1&0mn$K0D7Gh1{tnNXBDR|Df}VoDW3Eq1%f=MkC2KD4tZZqgIqNNj zng?4+X?(6wEA+6RACzyWL~L(4xINgCk(osCUy6VGQMfdSt7A=u*uLG;@m`vi8W=`- zgDc)m!KDKtrzyt;ogJUOP@;ET0oE|Fr>)-FQ6TTVk98|B$Ev-Y%;?^ZbkUk>%{`)` z@Uhi!In-k-*ze$8vHXmodcb^}HM(#5JMvY&61$si z&O2IzTYfRRfN6Qp@Pi-WmE0sG^rq>}_Z3(N=AKB8`O%{toN(S(Mdv~8vv<-eMTu_Q?~A zw(+BGp8wwdQJuv907~5oDg=s}u<<$Yhn{SBW~@xwQ|Rr#ZZc z=CEzMwHeUkDJi6vUpuwGL|+nBtB-6qTcWfyrgt4@<809`$04_JIn75-eiB_=4dvkE zJ?X*0JSUkVneRhl72oYbuy7-Je!rk$86d;;LrGUiJu9!*ciEXde=?6I^RyAn>Lt2R zaWQ6w*!O?HC)`*Osqg8^uWV2o(mb<|a^CHlY70H@jI@s7=PiD#yEm0>Q(lyk(-#t! z$u|Dn0Cj6{daQY_db5?t<@@PAS8)1yyXS=WAWI(^WGzAFU@BW|d3zH!T1emY=8bRD z*&(sZ4{R?8MTP!ZqYwjAB8zhE$?CQ!5*F&yR9k-QcsY;FdnPT*Vk|$+TUOS3@aBe> zY0QtF9NW!8fo{+`2dGsu8g=C z9_lqKW^Jx}7~lY|)Gyq_!l%;=M`12fC&@x}*HXj6m$Yg72AlT6fTMY-{z#wA-kfNf zdT(i^EHlyNw@T7R_wN9zAwZD`l2WtS$LvWwohpU+B3{)}RxS((>j;}R0hv!Z=>NL6 z0Ryo^^&I)Z&Q7sB;09HCITvSCQk9MYPgyskVJ^<@vj!Izr%m~ z=Kq)T>bx`<2$1vh^8?hT%xOo=SiwJ6-L}6rTH^@Ox;2t6`%UBHN06y3x~_K=0nUH* z4zvn=T-F~;clvd2T#7RP4diPmHjMh;?h(+kq@IXE>Co3uzIu7^QV4D&?ZRtfZO;zN zNcoOSdVoRdH+P8hw zHg_#@2K=5ybmgN35sdEhrRT)!XeSOq!+%u7hm48{N8s25vZXwb>)*eF5Gmcdb$lW~ zK41%}$8q+fV6O|lH|djhH>dkq+Px4>lOX?+KPQR6h9LXG9Qwgp8=d?>?O#~qF~Qyv z4b?^&*_nq>s+1Msuv?8|q~FEKo5qwHHkeZ1UYu>$1Pyt(!si?4)Sb6pS$&txoUGE> zhg}HWz493aqd`I27_6tTolRz_Sx=U+cMzDK2C+sS*gTNfhz+4%&neSRGF?97Dd*N@ z+Y!UOc(z!AgR6Dtu(K2Oc3hFSW`5!n@6p7`&@b1ryUV(#i%TLWHF%6OC%TYxl1i~? zneFjiOJs{BDzphc_IJzP`3=Qt?R(+OHwhX#&5B-?Zjn1PzN_;SD#PP8;tD+mo1+J$ z)dz)%6B+p03s*i&9I-d2R^bItAXfQez}_LySHc-d9XuW7B#Gyqbp&QOh4q$L_~Sp_ z^Ug2d;BwUXjU3_l7BM7Wx# z!naPyB*ne$3pKJrl1fdoTE^s8(bv>@$9Kh^?mm@AhP*uS zJ7!X0MQjD}M*XXm)YLlX`%|*(Hqj3EG&rK#`j+*szGY}9;)l&PsOEl7;$KfRV_`4k zY3TL_iT~DE9-NBVyr?7d_|KzCfJZfifG0`}x2kWR_ME8G-S7A=R7UncD^!_0oG|e8 zO!na|(>XyQi;5yHx@oPy-j)|dyY-*Mp2ydnWV#4lqKuzH=9B9Ta8lwN_DoUFE`6SJ zHFs|;XjOlXt6CmHk7ywSERUcTpcoh{QiS%*cGv4|I=AL2mAGg_2R&m zz`QT2(e1;HbN}iVfdJLn(Ai_Do`pe4vaH|`oZ9+t$RQ4a;S>KTz@m?C^L+oP!tWuf z{m}{DY%G%N|DLfBH0bxO$r(xXzpkH3@DUaM7nk@y&+%lI{l-wD=>JfYH2aG%^=qCBe{&V8S(iR%7jL}6!CtFcL$hq0 zU>u?W=WD>hhvh9l2N$O#{l)x0Uf~_g=-afQZjJ4RYgmvq9$7)ObGHDwFnHZuhWFL; zP%Gju_(eL&e+fRN{>wCPplzmM;UAh$OHYNf)POtDzu{?CqqE!(Q93q#v)8)ptI%%5 zv$mYV9WJ8A;e4-LOJA+v0r!Jq;sKgn|w;?Q9I7}Zl+I;h$}DxZNR0D>ZuxEPe(3Y*?p9P=-&fN={r32?k11ZyzE}*t$Yq9^%}`5K+lulTh%^w z6jz5UUb>T7YJqo7ruQ2aT*%o9w>ZS;|4W)w^SxppftGoY9Swx#Pj!L4J($!-|5}rz zv$kugDwXxmSnR6JL|E^2Q$+74*R-TDS_}vn5Bytmm0wfRICVE$Pt@9Nt*h>QI^VPL zTR61bjeB^1L^18Hk2l<<)coMQ7{JYMAlgtXP2{%Zh@J7dACVRF8dMd$Aii0Jj@GC3 za1RD3}}iAep^gaMmsX4g{ni=hIvD@=9NvE zc~1YpX0%YYcD4k@NtN$<+0t%uw4N=Y4ZcbsTPo`pBDx$26+1F^@w^~4b?|!Ws9<+( zGVrYJMEEv5NvN`mwN^YfcOJDC7@JAb!^)7~+lnp1ZF)}-j~q~m)ugKo&^#1&9)O85 zzZ^(dDl4Se*VZ8qmD7mx_<9W`@}LTFOFQyz6T5lovliQ>7Oq!eGBHkT-0W7e=XS)g z(G!*=M7KiCVsk6lVsiLMS+(G1g+YVpyiaALcR88%Cw_n#2I;5>QEDGY4D`;!quOky zdF(`zbkvZ+OSPvJasv$r4U}KfgLDGA@FS2kx;2t&$T7S6jR2V2oIY+c+X)!HmGe^) z&uN0>9@V&w4Yf~T-Dm3jHaaPjEUFmcNlnZvas_vDDY^3}*P)T}cZYU_-Y^4%$mxl1 zu2G`(wHWP)+FZ#`(!`ciwFjIRu`CsATiY$lit_qxKW7Nxb=~(b=mwSU6z|sWX^i~j z+NhU;f7V%@hvA47SSuUIR(>&c*`HVDhl`ML9EL8IwFxL1IBsrgqW28xwOnWYn}<^a zG9%ALUjrl|4Myu#|K?AIeHX8FL&buF;N*JYP(_|>kw%lrKZS^3xbJT}Z-dQb@c)-+t>2X2ED-TL;43#ujEm_Q;)EwEk_)Wj${uwOuV1rUv$QxW3|z1okem%j z#(rdUS&NgJOLY-YrGV1y-r0}bysBB(yJHgT8D2_aX6rhRD2){j{U&ILpn^`kS$+R1 zwG7*UA0Ej%u_)^`blt4!<9V$$-+CHH>SWd%*=rGs)^xVZmbfpi;XQ9k0Uu=Bkr#ID zxvEi7Br_>39xrryVepmGQ_6GVe@)se>p34Clb13rje~`N9O)DHVuKc3Wzco;0gx34 zhvv0V%Nta`uMBd*3sE69_23uQMDmpb@uIl)5faJ}LDKZ#)TPx$73$Zbpk~`tvU#T7$5YrE>X8O3&yZ|}=r2g!k%q?; zW*Q!gGj`Q`#Q7bZp@vCRcE5|&Ro}m>^AfZrXYn{4;JwADs%hzBn~wKMecqhsjmk_W zL~px3N56P8-P6j?mlkhkmw7Vh+Q~B>klLF?Nve_XKsZpic74sl(@@n1V1i0fs`vl@ZYR)w^!F&4;LEi zQiSQcMrl?Jmw233pq4Q9kF`iI-*{0W1x4=r9UNfC*t146J}AdXk}|E<+f#S3BBS1M z(>5;&dCO#6H@n^Wxzk7(qqoX2;E`mp{cR-i0;m751*^p$4Co2d{bGQ5px=9+{ ze8@`3cp(pm(!*9a&h*Su3I1cqI*PEn{K}1j&Di{!uQn)#{U7f>dBVMS4O@-3tBYrf z>lh4V#F#w6H{SCB_s@L?F&Q7I@{Z__DEw*@Hq!LvuQPZ5P)as^A8aWrN;0C57N9F~ zJ)ZX|mSO+y#@{kh>i4+OPnzF~4{!fJ!p=G>%C>9!C@KO1N=hq;G)PMg(hbtxIdpfZ zNDbxCjdXXn5<_=McXu*B-dY%ZRky%hm+%P=8@nmqQDT`V&nUF!bO zlGOBA6O)WhFx3gjo$9%>F}=b%)Xfeot9t0ja;X!5lOt4?r$i9 z?nTF+hj@8iOTf)hA$zpG1*9L{ggTUW*8H^cE|$zyTW;bZU8RXiU3top8J;xEmnugF z#CoLx@moqECfmOkJ`Zf0RQehp8iu8gsdknN%cbH@0{Kfdltgbr#YK+oB&<}ZtEl?g zDY?w1tc`n@GE?3D(RyE;o|^#!|LI3#IWiFIQ5 z(=x6B%Scm#$PwBuuiMXLDdp^*`yE&1h)u*$IO(~sw+z0t*SBvL5<4NeST^wE5P!#o z*YNS6uMq=l)}U*Gn1p1S!~8N9O7}6SZdj@}LjK*k9JzMaw`Zq#6Ty3L#cjRwR>UXay>%1aHfFaAb;c8S5(VwV;~Q?DY%lS1b~cCIz* zyJt7nI(>A5kgxKX2~af-MLuKh*pql3wAHVc!Nm0AzIt`5Aby^BA+qaRF!_*rh1#N{ z*?5tT9-I?H3zKy9?f$m#aU|}@W<9mKyKdX>N{8*~HPXGbuPKy_D4N;a_1?j^9+Z0C z^bJM4#b<6sdUeMG6I}I#i`r)N>wbfxXy9P%KE^Mze z&rex*D>2KZR5~3;pi;{hW(DAS(q^ZwBPX}hzGPk9WyEfaam-!6lE3yzmOQi@r=;*0 z>;C!;FJH?nbZgA^&nb?XPlYiYhHNIMTR7Ffb5NqzI_}z5MupMdzw0jPLMoXvr5Tu=w3?^wKA92hhx!=!5{*nx; ztNv{9r&gzOj586Z)z!ob)meY# zDy&%oE0r_p2@;dx7CXBWB?OgeLmzPIlvs>?12WVV_Y7t#8?pIA1NW4HVaC_`>kZ%M zZ!pQGYu%5fNjugcSs(c9K{gMJXotc>j0fBN>674` zqQ33HeK5+GS@oW`M|k*F3ehS()|ys9u`+A)QlCV4LE7#USV=Mma?!5(V?>*}tE7_! zg|{QV?mezrvM9A{R4`x0(n9N@n!&3RvX>M#Us_l5RWma6mBaVmrgZk%9t zFvrpFmX=`EHIfR@N$=6z!Dd%>xXD^3PL_#j8ofSzjob0B-5~Hy(M6m-ippC*xo~s$ zs)D)}s(Kxr?8sUz)sV6(iC(R?2e$W(qqtHBWi@X}tf)OJLfA+3=<}Zc#yBo%)%x=H z#!U4s&s!FVsc#;WH}x3(X1osJ_G&ouO1^7cAI@pE`jO!CLDjA?wHRE9gIU5|=BL`* zfU8m7>@`!hN`UjutNLR-A2AlvL56XBr;2)+3Y7S@GS`_R^z1i(Uzld#P%=zFv-5>t21G%-`yzi=eu z+9dE?gw=^m;I%j86d9U*I~q|!$a`Th=fP zHoN{O?kco>VqwW`oB<23YUEcoeGNUxS&{14ysEeQA`S4n{1^+~oRln2u2#u0d2VLg zGbe&#Nmjhk9(li)Iiy?+_*88(nD_Sb{J?Q>X>-#G&1ZLPs#8?Y>4>9${Qy_gav`SMuCb_An4C# z%Yv}s#y#oXhFf82Uf0#sO)BD66uvI-(P>4|h58-s&wCVGOjh=ar=qQQj}{fUwKfS| zm7}(64rs7%k8mRTZs^v#)B>FL|J3jL3FneE`Ch*x^Cff>dd%xsBW@VX>)&!BvK-Ncu&c*G#OfbCxETbI3%bb9Wp?MOQtQGzzzJX$?) zsz=;=7&El61$A6&6g^AkOfP*NVjgiE-WHX+tz`_@bziJ|J&&UkrIKvH5-Dfu9DV9^ zKrf!4xU)m+w~gfEqZFXMz-s#Y{wifzv8FOC-Szu^6k*?xCTTYol1;y6eCM&gw6XRB zA>kp1;U#ME@yORwt%ZDyOB<8Y>l-CXQ-gW?+}4Kalz|4`@aBBX7+J&`!SKl5D~z+; zDr_%JzT?(vOOUs-{$}h7ned|lit7%Ud(+cIaBm}bwAR%sIxuC(ko!>Sg#GO9$}J7@ zY>r!2R#iM|A5&#cWDjaZTl^X8E$&n1aEF47cgaEHDDI4E`wJ)gX#4muOs|FK18aPz zR@L|Aa{AVU;llT6c}ru6bvyy$n!pR}*;L#2BAOmgL5yh;H`ePYnJCWb7*SYnXAnW4 zh}QG%#PaO`wbQaW{FIaPBW0-7FFzK7BWgWkS}~IU3t|`kqVs`N5phT!XWXm78bP5znLa2%0Iq4X4T!;8-F-yIPh{s=bzixzajcdLrdLA+ww+A?1r- z3@gugK*^=D>J+LnDj;jGZ8e1tRq{%l2hCq>>!S>T%vyYmJIwMU#~q1M#Qj9y0%^zB zMOw9k#a-a9=-Fhmon4&%fx*0XK!W!RcP&}&Q>Li;^;3A4M%!jj>b}$*8{nx$s^fJ_ z#{cu)u`k&bA9l!3tEbY%RK(kCa$MJyV-s7t9Gc9Y9P#@h*NaZaJvzD_%%?24GtL-d z*2JpVQV_1AemTyIj#Y;K(NZK-`-5$rFc&|N9jg=8PsWda`*RG(7G&L2B5N-=-7Cp& z#|XeVK7sA_A5Qg)beSa<8|&3Pf)3?j_5Md%bDJ#H(|bqn$0ru@uLNf3dbqsERq83> z!X;RphexA`22>m$2nl}^K72S#-B;(`$!Sus?A4tbw4%#wo*bL@smYgY8Opz&SFWXQ z{*~gee29(9P$Q`aJG#Dr8|P1j)8k^ElatXd{lA%P=GrV#BLcElU`eUjkFrqN#jAxs z{*n$Umz-I_ZKK0`ht@I#gqxC@A64t2R-PYC(%VNlo6IhDq#ocJpE}EUM@M_yD1Igm z@mKGhIFXXKzR|m|Eb+347r24ztEz~BLpqE%!^R*x*fCCDGH5kCMiEZ5j4I^DSvnHC z;~bEkP_5fEaUoHI&Pcz4J4I?J749>}Xc+T*w#=~>{jd7|8C#AsVj>2>w=u0;-Bs;e ztEA1tzoxzoqupO#R+#O&-1p;Ebf}2IQ0C-R&_A2W#R z;|BKhNC^urtaPq6LP#W~XP8B?ptW?ypPh2E?gq^#ACj7MZBR}|1c^rNZwzMx7X^~&AqWaHE6**Qspso>v6Gk&ZOAILpj+x0Lv(5*YkB0 zez;D&lX1HHP)dvO9)&0}&aOMIo2(I6c8gME*)zIwuxU)M zFcGY{CwEXp-s!k6uN;pOFvzfoh!(9gypy#FF~m^D?a#Ijk|#bPuRrm9mQXqZN{={N zXFv@7sB*hgFRZFQ9_=e)(1b+9O*Puj2;C7i>Z;QhXbcM;rXO~Wr6+PgwoOEYJIt7&Mb zI(}vEFr*V$qOi?CmT58iJn&bO1{!4PjG z_(yZ0PQ@pqe5bh@9I#RHxtt|kK?h?ujEq?Dr7XR?`-HmFNt_aae$9M@Ns5 zLRhn_!1jaIV=K#jh&#n8IfsvL14VAm{i>w8Gz%tSA?b4BE24)6<~ZQuaxO+6Mm+}_ z#>=*uJ8bl&j0Vn`Ry)~5^~_M6Wtv)_;3gBRw?&i@S+=19xDzUbi)AmRLRVOIKWkun zer+O#4sU2^Q4-_8T!m)R@2Kd?ZB)ytfRkK$2i!%VVge{@n)f5t@WRC#JEJI86)sn@ zS11o(VGIk9>gcCB64Vq~OY!q(2E!CI7y>>UOXIPc-~M1{vAO+(GvfK0bxQykeWyOP z<>=XQ9b5EheWRF?e4M}}WufkG@cPE{rg4Y&ya>(P*z1hS-QSAlk6TnMJ={X1h2dF)*0^Z2HT13U{yMP&N0N+Yw@o=4UHIpSeyX62ihs6jM z^qBb8;cE3cO1Jrk5teyTB z^XIj`-!F9%s;%Dsv)X=w#?G%+u`3GN*ynVAL>1Mf_^Tm{?b(dY*jXTIDy0*r!iY#X zPxq!PGpZN>VH=0`DOy>-X646!ZX~f?mMj3^q!wtr>W61WgUpfunAM59^vdu5JOV@4 zq{(3E)?8x}+u5s@_vf0y6ygeBI*H3)pki7-cyX4Vk$}f6#`11{Vy^a*o6@HL^$*QO z&O;}^j&lg4y15R)41M);7WodpN39owYoRaR7pfHioWw%#bB{iB83^g|_f4L7#S8eA8< z8}YZu86YJ7oDZVAol$sbkSz)B^7gU{;zI~dX4MC|hjnZYIuDI?-2N|nQRlxWt@u9! zBLCmu`yWO9*aIl226zS{C2hyRi=J?Ce!i}xLw63#r_3jgQshc*Xt>!acARMPvV>0% zj2%c2xjf2S3(h0h%T+COG=an6zyxwO-vdy4Wso<2`#h`LPX>9AC5)n% zvqYy@%`NQJz6BQK`4S$I6f`xpL@|G>NUzpro`}QZv!t%>!ujr0p-Le>Kt;pGZYvbz zHV{Cb%UM}nEfmQTjRwbwX-Z$T*6kmPQW#0LHg<(=UuSpMRYw@P5-ct!IL~^7DvPax_H9tOD*{ERh{V-+=dTH;JJY6ggvEms}AEY~6nz z>rFBw9OLjhg^mimhnYbfh^dAmc0Szabt}IMQ@xyS*`;Vdw~FOx3=8MiWOyYiraYZv zTAVzl1xjEwTxzzmJ=^12X$@B8eJ`Ec!&m3F;>Qmz9h4rF*1aCBgL{%{M^e)Hgk?+3 ze{}9xBUd4U7E=J+oN=J|lAN3z8kZG9z-$w}KV2zatQw+72uT0zA>CSn3T;x&DZH+b zQC_W{yZ+;5*&zz%N_zpvsz5H=1*;3WnBa{zE###yye7$$<$YQry^%ME9yaZilnA<}|IEo$ak5Zxx7}OCQ5X)HZ7wzL z6^N5l0(a-Z6JT6a-vkePE8kqn!{K$LmF82vHRjt@bvjUfsHDwIZEz5RjwL3e4xcSS zg>vV2MMmUTkZMJSDb~smb6MF}bgOg_$*#X+PPrZDB|b-qkW@`^Up^z8s7|KC2b&lh z$Ls7(0#%EEh0u9_hJ%^;us4Q2Lpg$Oi~$&}ii)E^9r*blqX>Q~bTqUIuIDsZnw}Fc z-bfvoF)=dAX350Vr`4aGo!#DgNolv*T!$4hG@DQ;O>e0@AmAp8D?o`z1%K~K=bnJ5 zR3r~qIN9RBAKeLtvb##sO{JCL&gvvN-+uI9huDfI=R1pzr8^f})_l4Zi$}T9Ex{CE zsJ})udx46rylmcSe_WDUivXyht69h6h0n$Spm_vZ)hKLk4r`5XehvDGL{96rlpE~p z#nW9*HBECm4nr>BgXaI>NbKcxwdw*JF_=W22a~jJ93{q44iIzfZOjRj0myJmg6E#@ z?kc6aI>u*ttOFFRv2#uCY#%@V8Fm{3Ub;vOZr3*3RdegT)AZ+#*aMX2Y_;67>Go8PTUsNs zH6$j7pRk85VfQ_e2Oh?qAEeFQ;Rbcri~WL(EX9md`h=Ro(zn%^&<0=K=B>twhXi?R zTN;6udQ!E<_tn;Zfdk&#MI0Wj24uC3-zJBAi>1WPKT_|+2Eqwg1_1v|22WGPd-p?X zmgYS)*4W|(`!$5F-#vh4T;D!Ut@JHj_>Eee&jT|?R5o2X@X zj_&waQmYHf5Yyp~t2n0o6S7PSxmIZc?li?E0O|p&rDpGiHEI%wGwr!t_RoTq2ld2Ab25*DJo(! zzm49Qc$k3z@TAh#uf7-^BX)v;zCMg|40AYu`;e5D&djfRNvFV+7WcAUNVQbg`}WFS z*b;E za_P;nhnQ1?w=T94mpoRSv{*_C6FzGLcj-Dq^{teT7>ae;f~nJ|gXr3!@K;pt83qia z-37B_d1_zO4nI!^@z~DQ4Kcf>-tNy>3wR&-j=~5jb8PTgpzla;_fCy;1g_i%P(~(j zHt%m5*&=bdT`nQMuFxzd+mg9v$D$zZ`sCtrO2gIcE`r-C_w_9N;J#LZb(1SZqY;*O zH8c28GcR{;!~_xR<>vSKT~K&QwdaCkNL025R%=?B{zny0hu?$W=b4ihe$Y72uf0;j zvE)A=kx%0CVrxmUSgy0zqarr^8cAFl9reL;oI00RezuIwp#A>(X6>_bTpWNes-sGz z#% z4B^mtj3(>yxXcj{c*tIRv)*hhx$9^gFXiPZmiD;%KR;FMoi7r&7$I`S9}1H#=f=HXzegUw2_q3i2wPK$Ag zHCbTRMm=OHqCdU3;B-1C<8jJ+z#Ix~RZo=;`7mZ02Y;<5Z5t5-Fo^k99`Q7R!wReyTlhbIj4x#Yx-c9KDw50r06@CK(QI_QQJY*>2xd(p zhvn$#7OB%Y@uS+5v0V9m*||yw{~q_1nQBX1Q-v~7RE2k$7J$=wn1SN(v1{+gVwiJi zoaEv4rj~HoME>zhsn78-ktQG>9qtg0YkN&`Sl)Fx=j-=0*AwOoaNO}~+lc1PGe)ce z$6K~y?<~nDZ%ts#I-DoFQ=$fTPVD4O*=a0!-dT=~6*JG`uF5kFzIxxH#SKa%(4TBD z^czO?f47axpOH)C@X_ys2`*nY-);l)L1XJ|D#iOLUyD)c%YdgG#2+1u3ARtlm8yI# zo{Sd?zDkOaPx*r6LT=^P-%QL^IGy1UfD$MQLR@5Zb$(}k;pQINlFw-VYd7-{9jgH6 zrOVTQvZ)t6PLG*Rh;my6Kr+>CV}jnl z3=LKpk1?L_@*&P2ooDrvhQ#HbrI6i-^y$xhiPIzcTxVjG(e$Wg@99+D5a+Khb}iPH z{o_4LKgw@J;^97tEA0baTQW`#H<7rD%lAH>Zk{vosm#q>`Pq3EOT@!wY|ap7i`v&rlzK1VgUJq7Y!YqHgBMh&B>FkX3q@Gk_MKc zCP-7HfLXY?o8f?vVvM!R-g{~2=C`G@#QRx84j^pM{#p?pHh+t&tU!wPDE|at5()cP z$w#$B=3!QDjtGX0=9<3~$XxuFO~uKG`~7v89=A`2!n93*cP zS1aw*P?ts<*m*- zLYCTvOv)*7?e~x0Ks5)z3z2yBrL@#G1fNkPpG<|*61O~PuoM{uGZX@uskJ3f;n@Bz zwP{O-8@2w~Pc9FDEK@K`0(+Z{O)zvS(~(i&aX3{{EK|$}vr`LEji_o5mgU}(xUhIWfURQtW)^~Jm2k&;0Fo<&q7hltVYooA`K#{*UQlG1)r^^>} zb4&_1pXn1!>0-LFo;tw8(ImZH^Jm5^XxBW8&iZ<2`=^;r@cwFP`J|TZDaX&N!=J}j zJxw{bELmV3G2bR@y|!LSMyx^d`}%Z_l3QSl932^%!G{jO@e(PJgwnrEqs9YXXG>CD zs;4L@ND_w9gLU5;ps{ z3S6cY#|pUQKkNrMB@hO%g?JxmQJ5fAwfW%C&xD)WkesN@)3Xu0P8B|bUnN@F2tM-j zele#`@)*{s0h|#PJ4a5dzG>47+au;#o+tT4D)@w!UJaoMgrqI5gG-22kaja1(DE-z zZf;Yili0FR28<@CEOw^#%kVd>wY#H;)F&kOD^HF+Bp+I8Jf|H*lVWW#Aj_EVa!DjO z>)Tz77dP7{1p482=Z_|0#@Ti^nkqkV+`%n1$K-?B z8Lhnnj(sa8Jp^E!$2(7FUz5#11}9zTou>d2u1L#6wgK2)+V*@!Mxo(c0Yjc`Rq0fk z%7T7u4W|n?-JWfaIa%aZf>Na1O+0d{-Y#_y4sP7ZD(?fxCIbV5s+R?6F)=1L`D)Xe z!f&5ry#aha61%Jn$wDluDwus&k@-H`%)=~li$iDF=7BWr1T&sh?T!u(Kr}N%Nez+R zt}iPaE)waP!KB6VXbgcs5VvC&^eti9cVd8jo)U`RDX*Clh%ksmfPI(S7EcIl2JTJt z5Dmz1Nr1g(c}sm~TwR~~P_uR@B|O_Q+dLgbp+pBPC89aX*RPIA{~%qcO@A)@`P)dm zm!M+AC_su_)t^%>IPnhq+Lo;`Om%qaX=`V}T1y)yDT+;;Q1;LF*o{}=F&z?ml_PV5 z>+9RccTr(PQ%tKAyovGAcjs6|MSN<;7tcqnJjD(fHVI4Xo9+vF!W8SDc z&qQVp@`q`&#mD5&FY#0@w*tq#URy(oj;e~QaoRb=g;Dd(9M@iJu17~nvJ-QoQK$H# z+@Y7jaovO8;dI>BMbd!pn+fsc`o>Ov`}>Ycg+$Y7R=88b+5Xw`qa@RCFRO92scRV% zqhZGE_P2Kd-d-CkUuVT_?gTCb=?rwmI z#B89&`(|Tv^VA_mN|Z`LK>?sTuE%V11JQHD(p!MCozA0-00{6(RU#buKVrv8kTMr`tDM=#si=RV&qf^yrZ(Rqs{*!vNC+6|djIPpf3Y zQRF9wIfungEV1a9!jNdNBJ_OVR6IPIYgS9V`)e&~nxDsJa-?0Bc}F7em}3!?V|NE+TsgaO6swbp6_EEu(v=sKV}2Bm z0S4a;Ls_VKk%PH%pHaYI>E&-*a$d)uwZxwfQ%Clz2QpU?Zarr_QUu&Sw{CKBn4;8F zhkJJWGeCQl>ySZz>si%~oMDXwRbUQfePaiOXcMS8UsQ_XwF)EIP#zy2>&k=R#vwNC}5rQAfA=XzJ+TUUb!0*Nnvv4VMb(bFfpgj9$gtsH2=F5jwC3zs623EtMtJ z3JTFtdi+{IO* zvkz5$R7s8&zCZPa?kG{E?bw9Pb@Tf;+F3VG&GOhKNUEP4WMX>%UImO!FTN2gubO<0 z{^G2!vCeT?YfMc$*ljh19iO-`fjoU8B)=bzX5H?le{sWUAMQ$165*N?Z7^b*s#v$$n|FaJzv=Dx95z z%PBVkykH?G=`J4gzOQn%PQ9A~wtJhKYCtfai07HzES;pXHDNv9Fmbdx0D#BWbfWM| zM=#mboL!!Onjj!2Ka|L-K3#7V&H1i}xt`M8M#-2GxRxGK6cP3LE>Hntyj&`UzFjCdB?&5P+h%>JKHbjaq zgu6H|-VzH?kC5o%DWR$*nsJ4bnqEu{llj#%6k)Lf1lwbVa`gWx6F#ulG^iZ#k)9H1 z-{H7roL4v5e1d-Ybn`C2&@T4zUmXb$!;D3|wh_%tYzkCN5(?LMD(IJ5Y5^L(?0@lK zcF36FLCm61Rkgg4Sg)WSRluVGe0v=gbuGBLX=7)w5*`^i{wuB1PR()swKR3gm8(+h z2Y=3DspaDuS%J)F2jX0fVL(0fCx3lwP282BWHwxd?zNtS*LniKGQ}$`Rt}Dp4gGJE z0zqCXJ0F0%2z)JVJHt1<_=oy$ zuFony21I|gwqJ|}fA7ne!jGe#A8kZkQZ=iDM8CV$qUB%ojd-O}-A}b#=bvSaZFlnR z98J9cB8Z%uLXRi#Fk5F2nxNVTgHSt>xCpTM*#m!TbDa_cw4agx9Uq zvj3i;3989`lVTnN@X*>GYN|`69E>R*#=gFQI7P9}rh{v0pUF@`lTjS{pjp0qVw}>& z*7{>^#<;wb4y)L|5`EzdNI9(eLoAsbMvZzc>7l%r$vn3L%oA1P@NE(go!kuZY$@fT z4KI)Uh-W&z459wD~E0v*jY4}WWiy~Sj*_=gQDUk`-i3oV(dF|hg($P%fnzP>~w9$si7g;2e|zFZR!cXQW*W4^--CV$R-4mlMp_GN9DzrYDm8eV(f zw~WP<1wU#NN^xSb2*3nNH!7%e1F6>X&Q9>Gc~7)qQu?hFP;P&D149B1cf+-C^4DbK zujFJbmN+%@VPg~y)~g5WRs07PKLftJw zB{9CM4%=Gdm<_dxr)uXND}kMPjyC-26%3AMz68G1(F)Y{V#O4Ir*otELC~iNY+4tA0>5tRT*wmh#5vq#>qR=rp&S7q@kXH#Cj=26w7wMHd&Vvegs5$gb2#5Ovv z5#*%!UlK#oVpM-I%czko+^Lz)nHq5b=l9v}2>4?Vik8S)I-OMN{cQ!=o#zAX1gVSw z2L3AAOPpPyA_q=6f(?6sq%xP62c1f-vxVJ7k~%M*bQnBU~3K9{Rg} zz6$+Y0&j=+?`I5f7yeyDvHzEI1nqzQELBfY3@lJ%lbd{J6EX4Y(}zWU=|%DS|6P>- zVKn2XMbAQ$nOg3>>wWg3^3=O9Ct58w&sjz~KJU(OxBps+_YfSZo2^4U4*Rj1h0S)9 z_p0du1R&y9fC8HuIjD5<;~mhvi#e@m0KGUJDdhe({O#}MDFAkf1S}0FmVEj3JDJ;D z^198yYa8vPDM=UW)T!743pb_v*FSS|wVj(r=DEiLt^6&lr(-bhpOae0JKpa1_&qec zN{u68of27e0d3OKd?xY19PtyaVd2UK`WUGWP};6)CAd4ltsiuLj^N^2qC+^I62a@$ zwTi0q6Ce-I=2h~(}tN*!Fv7$jejmvkO1Wfe*zzP)>`8=T=PHK0k_|Tu_AC1xV?4?&m(l{3Z@&b!}Lp&ffl?sS6AQt{Y6DYj`B@k zjKr|^QvjZ(f;S;)phc3w)Fu{w`o%VWy}2(Zkrsg01UUP<%jF*mq`RMIwgF#Gb6~UP zRaM@q8RrLSnJE6xr`Uj4{1ND?x;>U_yTA@UsCW*CXHge>4^0H8SUeh$0R5HLA zYA1imnJ<`TO0jC?QVWIx<0{j)#e;=6t>swZ$J$$W?WP#{b-{(Fl*san`$?oTXQ}BC zXAhYqQB5ENq0`_529n!pYQY;+8E>T@0VW-lADxHpWVUHP&F1$w9TGfQJG5SZMq4V0 zCO3&$%n_v!YTD#eX3opOYIRoqDpmy^cn)Y%;5d zXOU+}^J@iQ;-GwViwo3c^a7FMl8`JFPFkRIXzJEAmF3zFG(>-N*^6K1=Hv6~k7u!} zaIU*}2|W6_$kofS4E^2NE+JmdqHL%WNH>+A2nFG4S9m0bVUFFYp5}|-j;Qi7IU!N~ z_uY$Jh2n4j$(kw1^-HrR=4U5IupDL2_h;5VOtV+YXL%q(sm(?gWAl|rxIMm5Y zTk=u(A}FV!!qL)=&E+ZFfPdtd^>-l}le$kMem#qABkp{bw>WuLR_LHO0B&r6*S&U$&qKIW{Ap6y+E(Gc8`nfBfTuVuJ{WR?lDtJT;JxAiIDP)|hl0wH}|T$`d!;dT@=W=PLh7B{B* z4A`a)e%NaU9Cno!N#ltI9NwMnJ1&Jbk5(vHS>%92aCuRJN?Wg)C#@9H-c{NVsOqkG zR!)yT*ZQd*w2kVQsq&immw9;;MvoI?Zva*M`vK`3=i}nYT5esRu%aBpFc=|*KhA1c zYgw1)%-HTD%MtGVU%Vf}nnb9grzOZdG zd~rS*3isokhOpG~O zzeR4QuxwKoggrKhFCG=&LZqpKU#skKBF-;~C67CKm`rc(ijHd4!5a)?n9onMsfNfu zQr=o3NIkUDitj?x=1oRR{qgfWQhgB>vXLF5*Vei6j+rK?iVQLG7R)9G0#kv$miN~Q z>qDmzZZo0#8Am!`NvjOLke*Z)_pdKf?rUUs--cyP^yuAfdwtm1bJB$$O^wn_oi}~K z`R;$IUXwy@C0@%IvCXxOFpE8mjPR%T#J&KH)i(1<8rbd`ZtK7$f;2d#MDSv>YlDyl=c*554qdRppA`4bsv@2k`Uh)~C{!HXJ@tHe$D~6)nsER8|$3=?9S)HOtVe z|FO7j4>b+$mNYCPp51h4s~81gSRo`H^zmH-7#(=%w_qn6CQD}2#R%+eJDA7~+?m6}chlf~{e(wKw0Fk9 zXj|d~liozGrPJc;a;EwuRvHh%!od+a4oBwTkOf{IF$f- z5yCmTBcLuO&uZ(NZ&~QY2V&rQt{$$(t&GF_+H-fRIMWKCnmt*qq6=kx|KYAdn`eFV zjrZK8xy|lo`8P>ng_-(hPJgKlMHNH+Fo&ouVZAJw&+*kCwUeb+UaWqLN%{>FM~963 zKBF=E@`2ZNC*k7o6P^f=X7V0VSnw5x1CJ~F`(4i&tf#%l+Hk$B-0j^~9CIlXLvm@~ zux!sWqmf6n!9GW;4U<&uhuxg2a$pqPvj3jOqUY z(|n!V`Amqm1Rr-x%T3$ON}wf=YI#4(k%(gw%)a5m6MLZU{@HKS$`^(AsfQEx@%XiWh!ZOw%8Qo z89+wm;c_+$3*>9{=umeDpDx<@d&P8#X-h)z8S2e?!*6)ixvh%GQ1_BP8Gei)QxDP1 zcqjBy*wv-=J7QMq7FB%|;e1CIS{Wba@A~DobM*G~_qATvAE-Tx14rj#;t8|Ik_&D0 zMZmHWh3bURV$KA}G_j**am}`1PaYYGOYqTTKv)tTe?JA8z}?vxU`l-NfENO?ukz@1 z0vZvEVB{%hNN0>UN-3rgDi#$Vlg|y7aJ6V<89Os0WQYDIIBRUgzVBrK^Q?Fx)n?w( zR9g5|SsW^Uld2OfPofqy*qeDf(=vlf|!-+1c){E4K1jYY^w>BqFzT}pKA5idEnN)>- zw0BCfHFd~VXZ9xbmqn8Zco~CsSlXk)6by|GDh3j_pVt$-uYnj7wU->s4WjU|E@5ZY z@whRU>$^uxm}MUaR{8W9VO1PjiRq@xdZYa(BK3n#f~(K=WodI_t1Le?`;TDU-)>Ik zirbz@YL(!Xz)yRjr&GMz18$)15Q12_K*4k%kX;HV39Sk*%$@`($_wOwP1_97LB0{c zD(3ZBZxHj?9@@K)Itl!)oaQrjBjz(QsI(1WD*h)jeT70sZcRH z#55+{ADF{H8MK`SdLyYH2r{4(V>ADYyA07(c%!S1SlFPP@F(Zi@Sy5 zgBMM43sBq%1P|^S+;uONnfbom{b%>t=h?sRa|6je=bn4cJ@5PegvaF^{r6^jn99dh z?!lVOqd_CoAEjEKB_Z1HiNy$$%rxqPWaNU-Kd2XPr9<|pHr!KU+eR`EH5n_CLEo?h zhyB;z3x++|(5(Vc4~C6C{@2Nc$_04na%GJ70H~OHo*~U_O%2jwh})*sVybs@PFhSt z>e^KlL<2-t(*$a`;c&^CsY{39Z04wnI`yp{C#qR*6R~*EH|R~kre*vC(=OGvtTf7W zyXn}nQpk{oLl*Bx5}A_!2^!kEa9y|K-ka?&csN#?HB!NoHII%o$7EzR^JQ`q zmgioOz9t3CK)!gfc$~PGO-BOv#P^fWju;?krtAvFD2e9BJ=<276%_4qmaZhtRe zjBD)d?g0Ao->@Mft-8a!1^@}hx9~f$1D+$1{wrVxbO8%>%-eqwIe*j^-siqf&`^h8 zMKeOD(P=pg<8h^X_pY+3UkT<)bU#q16Hun@g(^iz+TNH`{jx{WpgzswOFr#@D$t}5|MsW;IA87De0gfRpXG9brFV^uW{ECiQq_2Uk30|>k zoE&@2q6nt7NrK`1!7t3*85J=i7V0Nfs05WQYXLu?C^6N14S(PJ_kD+ z>R_3dz{5&C%eqcz>#;DypV}PPHgIBt!3>X(TXps#)3|bMHqK5MAMSA5(nf<2(%l6^ zaaYVqr(Hx@J?*(}haL&<- z{r(o1i-aPkoNdg}tJDG>W4=UCUUbjiF~75i(%R%>J>^4@ZWfOr{-9Krpnkj3zn1$@ z>*|G|zkobDvWP9IlwKhSl`drIc^|8f$TPa73nbZ3#CT&^TxwG@0^nSiUu23~mkEeFOr%3jCcNh4`is_-9_2F!CVlROFJDZ=dr=ufM&? z8-4MNn~;{3;&ieFA1`~k2H!mIrBR>MP{0eV8z0A00oxrKJOzx9vGQDtG-ZHkK8rMn z4M`+?@rOqYqW4dBX*tU|b4hb@PzxWKXzfQ`3V_~rkI{pbdGg4`eOYcUZ60z8g0ysS zW)RG^I>`o@;?uvxtCI=zaJgsjWx-*z@}50i4v%rh)3G`>;QfSM=%~Me)sBG*)`NNe zegYD93a&-n0d{x;lOy)9?{Zv}67~JxNM{Tl@ym~UqAkxFVcx`laci9OElLUfBRu`Bdo0q-ik{AAq)YP(>c&#jo~H7T3Wss*^nLRbD5+bLmi?9;0oil1MZSuTK`|FsnY*13rJx;;6A2 z_@?Ze8%Q`C5Wmhot9E`wTflRkxg z^>&%Cx^OpChU}j;Cx>c!VPlO2>o3Dj4rW#N2l(tQe7qgvcRj}Z*>6der00Fcd94i= zvI(KKl2K4O1GhVS04!Ektdi_fZ13`ufJmn-v*U3P*&vTvtfE{rO+LXK3995>gb|*+ ztVPorxwpuDN(Tl;s7#6ZyL$p=W@_jZ?#TW7@gxnH$>&B$Gm}^qwY__cE3eE-v>*5Z zPfYDS-UL6@AP_Lm0tM?EX^daI8wgKl=C%F`JTw@Ba!dM=+IxbIVwFx6T^+yO(E3|q zbwYZ!>jP4gP3q*tPb8JIk48v7UB+ye$`sXpO%e6BU({la6O~w6Q$*X`bPmde;A>K| z2L|>ziL|i9s4W%90L2Gcox@j&UFTyN7d2hr7I%wV@8Y=vlUDk+6ZuxO<#E2UaJxRW ztbs^$N|=4wJ|iN-FkrK44jeW4 zM7G>IMSRT^ju;RIvBq^8 zDx`KCl_%ve)g1Pw+l_kt#(tF99CVwwUL$k_>Q1xJdVQ#tm_j(S`9N4xYuGTk095t( zS_eIAxAUyLTs0A<>A(grBN7!j*BbojQbi3-*31|gnw4V5K_UH`e&@+twh+Lv=1btj z>iUs(b`B8Yq}p*b`4$5W1VMUaOH~{jrb!Ga4rgDRPhe<#P=;3@+wlOc2bNLOsjBZY zy#Y6TXi_IG21Vj18a;(Io;=$1cC+J#cy*5#D&*b;#^Jy(u#eCxMi5_{kY)|3Q>!K+ zmgl6TD5IiPVR$sq=aM!%e-m+reE2P?l5Ns>y^1&-L1kDE7wSpmF=%dqBMmg?&u4H& zo9Ie91Qo=xwulhF0W z=qC=!-s0=r&!GmRp=X^nYujhA=!iq0k3<3aPk69JW`?w zM)R4H;4v)NPy3^6)q+VTrS?(Mac{}dA@H7`oW6MqYOt4r=R(WN9%RNBSiV(5YZk_{ zJvwG`{1}su$6=#hRD`&{K8ic!SP|{Ll@QMCR1uB8$d8jN1Yn+ptwx@O7xza~Pc(Wi z1l~R6Y`XrGiZ?%Wi*T2bCMdERe^jruYamBmZs2`KxR9uY&J-=j5Y_wYtC~c_V9gPq z@a1OXs15R%m;J*S1&nIy1La*DubKX?S<}QukCT-wyHay#w~FPRJEJsp?~?)-d=psD zu;340)R?X^+P+MW?I$477i2Gi`o`m~>u>#m%yG7h1vF(P?XOpgMEV`-fwH{crkvED zOttOR=fkpeswe?%4V;l&-Ea*(!o=~+X0nobQ}NWV1zD8cYG(a8OkQcC3bT9~SKBsv z2F-K_Pd!m+idmBiw`JkdF#R2_s-^bE3{udPxI4kEAfoU>{i z<_~cp>)par@N=UlZ$Y=7-vkwW^vTX*#yzjwwPC-l~?aTDD_ zl&wRaWf{0F0}{_^eG0W>|EdN}-6j;~eXvK>S9__uTXI60X)b}_f_6zd<+Z}tXL>)F~CR4s4i&u)Qh_eNmFennM~?nBKx5Oz2$?e>+p z%}>SZuL_o!$^-{eA{pgR>1j)frAT_d?3WAn?DJGr*}PG8eFL7xeuF970BWKl_%jT3 z1E=DFnqs_$#fPUNJkq&r=$yf`<8P(NpazI5MFl*UWm99ow61;2Lja-j-Sn-seeJ`k#P5S94Di41Rf1{lcy6#oE$J-{4enW(+Lx zeFu(QtfS<21I1VM3}`##;j3>qS?;drV5^R$$DC-<$cLp%5TYn2}vtr^nn2%Hg@?9d~v;|Ll2U zbh%*eTP4}a&&llNr}N2|I*u~{NG*U=_E$W0r3jtBVKtOLi*&~q-oXo4d6I=#%DpT; zUqy>+x3ApVrnd)Cw%zB7y7Png4hJ#-UNE6XhVc&ezn*pWW=i_M5lI^BSqzYkDB0iC zG3U>~pPaqI1^lQk12Mlv5|t8Po^p+hUP6qG^B(@5e;#(XSC|J7iXsDQfSW4A->zUS zKOQfjL9|sbUmx~@^(7^dJj|(OQ#1-|ym>Rb?ycY8`><@U@~qbPZr4{&-F8nhUi<_) z0aw`{Z4SMNt{cue@N|=QA4zK-Ki#NY+jzREdq@UjF&$@*p%Hhlg9%x^TM{T7D`-jX z`eRq?U(;lbb8s`;dZJC!a&Xn?7&EkQQI@yn`8ZH7;B)%mk@Ud0o5-d?eXZa{dpBEe z5I8X|g3kIk<@^5#HH=W2FA%MX2*qc#8x51A?Hi(X1o9nC-+1)oyX)T{X*-qT2?f$g zXATMq`-~$26OPd+o&WrLbJl|K6jLt|kpE80bZ=o2g&-^28FqtV21-h3`!G#!rx$c?F`o-conMn$8-AYNmK9w^Fn z%Ypd4({=@<96o!h&0E>gT@VKb+Wl6Rm^@OkK7agO?HwpQ05or8(T2_O=tF2HqQTe^ zT&nv4WI099hgv2hz(OsnIqWAS;+<^x3n#3he3)G}0JRVaC?h5Q^_Og)yCkX=G5(A> zWogR5JSTp_N7S*lSN^9+`(*Imatatib%s{BG(gDlcT0AyKq{*8GZl30lA~hVr8+4bL3;pri@ zf?(T#8_aWmK-{3NOeT_@u$^iDSn9)|@|Nt?OXOHKI#RX8B*H}FS+P@YDq%E5a6F?h zSCMa9W!n5EB*R>(=rhfimlZ_i3R7Vbm8O=EP^y5DwT`4uHK@Is?i+by()VuFb~>eK zesi2UN!Hj;WdVvY{l zB*MpSuZ9OxP(EO@-%eDXfIR<@~vBJ3h-!(~1gvqgC5n+XwA*+rttA1{jCrjM+W@QblTm01gQ`R_-fu z08!B8IG@*eY*bD%^>ApA4k0!w+4gjMUol9OzQY*g_}5F(xT3kP-WXFY@9kzV#KBG8 ziIamRmcts26i)Tys?9o)Y>%%})Q|IK~ww z1Oq7wGmV_L;QX?R3axw%5+b7crKP3C#l`t~fNLl&U+@;7-@EVl&#Vm<5WC#Ea>xF2 zzSC}f?%=_&em`X_InPXtC6eJh#-DPLs$cKaMC{Z>dj5VK#;}2X#SYA7TKuea(V=%Z zyfbYih&msUrWF!iv^ByZ`;hNFyL8?L27~L)ALVzVrO&IAZD@2dg;v?35{+? zHw8%rWN<*}?}5pfvnrdIf+C5=y58_1-!}IcF8EBebr1)ZmfTPu0PHSmOmUZJs%gco|DgD}O__^8&b2+Du05>;3&|nabPq+C&H$ zZ8r9)uWzLalNCCy;rs=86=mWS54XS4$e3qV2Pk}+fiZbn+cnyqAd~E{r^>gKjnfX! zr8XvNrL7$R-ii+qc^XA$B+^nlbY#SA@;dD;$xsieJ>DXC$_gqV2}qJSWd&YHRklLA zrXTY+uIj84s_0F#l7)wt+$_7cG*4Bn7R?O8>U2)92|XDd?<)r;bnoS9&%Wvce>E$hX2FKH~=$s*jon@F58L~ z-MS%OncUbwJO-dCh%mD=EQy**;3BA} z)_mzewo{7KH7dzKgL()zK>uq#YRJPXXSpkNcdZC3JsPVsSf{ynZueH|kNEV>xndUe z(sEPhFKy2ik<_jkv!#I}f!804(;JQEL4yV<8E)|r#>_s2 z5IrlU-IQuAz+tG2#Fw>-pmI|>>~RjOvsI>~3Q_=Iq_0%`jlP9EZy!-^)8Em8(E^yY z=qu5}E6AE{$Lm~oLr^1_X11&up`$ySKr(>zPBE82NZSwX^wW;heu7+s2T}V|^?S+* z*o|yyy(;4WG>gN#Le3}^a--?h^1L1sXsu*Znmke-ujFAnDgWe!;r$mk4_C!)Cj}&5 z)87_%JFsE5yb;yK>m$j{xsJk^tbJqB=D? zM*s>=crwCd`k5}R_@XHGgn1`Q>xPn5-i3TJsi>vTKpjb-sMd4HLs>)x$IZk)Gf26* zHYrk~gbX}q3GqnIHS9Dovvj5|dE(@0;G%)`o4OGc$-;<7-ati7U-TRD9o_5=7yd%7 zAX{R*>uR_<4>~b8bf8)m1B-`QkN8w?CJi|~PA+k<6~n9iBM@7TmD{7tj9pvw*Y=8! z*G+uQj3+qyUiP4+h4f%7;(1c)NC-sNZKL>G6)bp@r`k!1v^z}J4z+{!m+K)rVRjj| zceXFFxrU?m9B|?ex~;Q7Q2dbha|^_jbgku%Y0POMRfY%dc{!}3b>XJ8XO&CUs*64q zbMR1TKSY7icBas-F8YkYc98&2l)RB%xT18^208etnbhCs9xaP5#`5^!j-7PY1*Q=| z@_GcS`zLjL7^5Q}6C;{KKL@$JjG!(^9qGjUrbT?b8g2t#uAX$<=K>m1bz_tk6Vddx zP@h-C3L&C`Ye8Kn&np+Sw}1UqaF_*aEF5{xD@SJZFpEx7k+U{ykD-{A)lMa1yXFmZ zQLl%2;@J+qjX_)ACA%=^OSb0Oz@_Zj`$N z723QDV46X`HoQ&Yz^nc=TWadS3Gf-Lz@F{(D*>C$9wP4Nj+oJhBo|lqUJ$d#Xf^(`;S7-m2inM9wy|okyh2-`h%HntPmD>-zI;j&os6&C)n&_AJBqHk z^9w?#1qcazHEfjVc~c2q*|tAMzLZV9)Jh|2)~Pb(LH9!~0p_0z6oxroPkr+NP|B^9 z?o#!lNWuMC4_)GSSdIGb_BN8Io~uD^QkU#;(q1pK<{IvJ)XoAj*}mN09wH3i7jv)q zA||V$eB^nV+SD5Qsp(ywYHKKQT=)_fATw6*U1to3>7gW;;DBlGgRDlI;bD{mG+;=DTzRu--v8bZE2BYvO{xek$AF$ zxvSeV#T?3^(9&uZ?wH~sWQhNL*xsL}Fm%@Q=IiFat90!?r6J?FyS2N!_j|tjdAKJ} zHmTYAz93LgWyybkUs}I%ZJF6=Tg>torzBh^up!Spwkn#x%G2GVYXielVAJG#==11s zI~k@|{#Xa&!gd&06HDkGEyfdnOT*H@;^V(PqiDj1f(E=)wewoPPHSA$l3V0Uxp8Ot zq1B33EH)Av`Si!ada4Ojivnte6S|j*{I2ZZeuUSBf@lH9+~v1#3Iq@@JmxPQc>r&0 zG*^a;Vc$e8RP3yl6vSI&bDrstQ);8t@|e}@XUq(MGRe_)BS%i>b9O`dO_nZ~#&JX; zo?kZXDc70~EW>sdg)DgU|kR{#o_1#e2xk7(k43&529@^=aao)O`Tqd98L!gs_+ z)xKA8EU^_3h5`^tev*G;55O#tF0>EwGZqBSerbC}n5z5P{TPZ3->VV~02jvj8|(Xj zfcgFJ3H$5(3JXl4c56>7S&wChjz#3%Mp})hf6(8A5A7rdQ|kv)6v1oKxjKj7WCY{+iznc{^oWB=dT(u@F4c% zyO)x6m)P@n_U~BdXn)S=H)~C(eHnRyw40ll3PHG3oz{6-?sjC%{SyEK6b&5qP&!u2 z!Cv#yW-_QPho^``@!RpfT-3$a%b0LstGmU&|1*+6Pr`rq+?=W&Fd!zaU@F=W_Mj37 z*2wBR^N{P$)~xpQ9wB=}`operJmOtgUSt*rj# z>p3o>@032W3-}(dm0(h-6RVc9?1v`>++Pl`;r-MS1lR@2pZ9ySaHUbjLoCq3p{X&; zUAdZUp*$bdPEz+7Pjj4?81&DXRj!rG3mR{fionk$*p3z*hg{w2i(&~VEFshDwwSD| z-Fac0Cg85J_Kl4BWO5GCZ-zIxrv+QxQ8GpByafHLslXsghf0^?W@j*>hxQII0@+H{ zQXe2*c@BD)(S)VhDXc?8M7?tmje^gwasOjf2D4|1&x1XLH*@NsvUQHZ3Joj;3N>-L zzm*>jo3CuYE-vzny!|srA_Ne?_K)U51OHbRpup@U(05z@*F9GOUX=f65d&wSUwH{& zCkEgEu3nsU|C_1%YYP8=d;IqjCXlG16x&nlp)hc@kX1mjqRth-&e`O>$*b@3)4+$* zWu>nB7XQ`Re{m92=%m3rHUC>@z#j>-X{P_zN2*+neAlz>R>=a$wud+r_j@LA9nit3 zQW8CW&de+~ziIX1!v_TN1T$U#QF5~C3JX-k1`r#VcQ$e}Lzl8Xic34>(OhLH*@^++ z2;eIzVU;n+)W6_gaHvOz-p!ojr>83biGqmF zn*2Pw`ubq123-^Dn49+e)fgy#v<1K6oTGPKen=+@Sgr90>POQ*eV)2CKG_`jpl8u< zoicrqcx*Y7FP_DY*JY^^uC0oV2ljt|$pYXwxg=dc_35w*)xs~6dFfX1y06cp$w)0bvz7}VNtD9JP0nY52cTd^g z3}C*lW*Umk^s1!U94siMw49*{rKl=l$V3=3WIQT}e>31HP zl8nNXV9N?-LnC=VSwTrkE#w-lhOe96Tj7;~t7z%C z-u7*^yVrZ#;aJ=zG>6iGgWeVH6Htz*8twq0*X+L1op z2X~S*x4jrBWr4MI);3ffiV9RL#mI%$R%{=CWP&U3jg;)uvz_(_vnH3+mhrJTRF!`D@|GZ)i@HOze0`Ys`vt916H`xg1u=;GCMlXr9QW$wfub?`y0ftnTU-C(Hv|2xWS-wK+W8 z!Nz)z0@T1Kbbp{k2hVfs{GonN_JmulgRV}UYx{t3QwN~d6j&%+aFHl1K1g{D(Q5|} zgxMsGEpbi2mY~sm+OC4PnJySHRX#!|xM?XDfGW8#2RYw0oLzDUa7C7C0os7XQPq!d4%$Qb z-N6!r>Q_?PeVrM;d+2-~x}=l+p6U%xJEz0JsCiUXJ(mgV#S5@qcU+*GAAdIJNnWTr zd9`mYqVMur$_3}1nnQ>`5v$R7-EQ|EbARICK&XH=LDZT&_qOTtZG=nhP6E&le4S16 zXM-to^q7HG8@YK^a6vJ5_KKObn_MwN&1FyapK=7+akL@l)tWpo04E?6?f9etMtboM zfbYX>#V=4!loscma>tjLGTRvCO5$SIskPkmP%StNrth`7vZLVF{sN|uwW7Um>z20e zI51&ITx*MftCcOrZAIeXGzqMhur+`2E6=6NTY)deWIb|+>hzm_6hR;mu)_~Z!PeNZ z9>}(#-nnl!v1Dg(Qee@J=jT4X^6m`66~Ud;lN)^MM2i-XnQqdT4THS{Yn1CAr~4B* zcAe)^P`PALhCIjW+UW;tUUhF1EfY)F?7uidHNROZvW$J5uS|&AcL}_xI&P7D5-`Nh zQWUy*sP8dzqO6?encX1=&qTzI-)jeY`3~~^E9dWb^n0~ zG<+4MuWomsTJF4@BrjL7l-jjJiHOqCQ@3lQVNYOlHIX)f-?fA11;pXYO|a*=yq!oc zjd-;5DOsU7aZP{U!hB|qBt;swtqGk(3}!}l_BqbgPDhWic3 zPwdt339WKnygfp7N;d9KX*kEmEsj1u$xF z0YD%4y-doL9Pne6H~i)+(U9K;0sgWd&A?T3E+LB?H0P%XK?y7Y>v_QoMel@rgB8^A zy!86GeH;i6ZJclGaSN(c1C<1kk*Wy9Vw5kC_r%#6o$;03|J$Nb+h(!P{_nItI94p^dSz#3FNSQI|&U;LO{S^7354K4La>gc><; zUk^%4O92Io)oS0Tk&JY7CeF@BTQiNt6-61qVBkPv Date: Wed, 6 Jul 2022 08:21:58 +1000 Subject: [PATCH 028/109] Delete change-home-to-edu-windows-home-edition-intune-filter.png --- ...o-edu-windows-home-edition-intune-filter.png | Bin 40112 -> 0 bytes 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 education/images/change-home-to-edu-windows-home-edition-intune-filter.png diff --git a/education/images/change-home-to-edu-windows-home-edition-intune-filter.png b/education/images/change-home-to-edu-windows-home-edition-intune-filter.png deleted file mode 100644 index a033a481c390ecc9ce65ae9379d2dd94d1955074..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 40112 zcmce-bySq!_dkj#s5D4PsB{h}k`f}#&<#T=Jv2zCC`d^&LpMV=LzgI>GIUFKm-Kz` z{r-G@-|s*7u66HP_YW4&^UOJCpR?nf*WPFEU}Z&VTr3JKG&D3^Ss4jcG_?D4XlUpP zkI;cH#r(oJz`uJRRi(wyN(QJlfR_j6?-bslp_NBqUwyy;-XGh`=zK&&!~1#ncdyef z&jbxESyEQwow}RBPSayAjn0&{Ue7e27`~J~`Xe)sxg_^e!JX7>!IW$pSw(#MHkWOA z#?Ve`W7qm7`Zg$&3lm|v@eGu=lk%Q*XIPMA8pQSe3G@q~47bx1~7ATG?Id2+t9NX77Gzba`4yL^|R8vz^ zQ7Jd>43D5I=lM8^v)Iarh9>iTxevq0SWdlbl&>mklZm^*Wrr5S`Rb2@s#jmC;?dB)Q?|Fao0^(tXI0zH8)#`s_k>)6!o!qVCn#MEzEz~yNOw0`1%5i^z`&JG@M66 zgFeF5r}!=%PLA?Etfr(S21pVR`^9=z#4OultapA+vK~^v^os$;O64Ls zhHueiWHXf^F-%Hu4uCqkjEZdBebx6U7=eFgMKEYwbWfrbDMRADr8^&8@%jO=UuO4% zj3L-qz4O*G`bt>yjbC7z&cS~8YA0o>!kf9X!g{|oMZL{0yXY+UaiJ6wS*noZZ5c8& zG?RND7@OJ#19|mHvifKRH?%NPUIRdGZ~thhlCRt}Qa zZjRkM%deZ+uIoWYuq5<)E0g+mArSjE?K#N|#AhSv^3ry8+OwDG=h5cm+og}e-Jn5k zP=oH6Yu{@@(|F%)udgIdXBCW&zj7ZPWa#;5g?s62&_?Q?owKs-Y=NvXY>$^9%tI{Nj+=xo)6)OIt*l3ByI!MFXhg4w>jx3AbZJtg{(Tz7;cir?c z%xal-tH#eQ&1z~A>~j+U^d?g>G`sVY7_*+o4|IUIj6xd)HP%xW8h;j!Rvwk?5LAVL z-T_KVg&9$ix^He>)Yc}#{K^GOo0La;Gu>4nG@7;?MDTJ~-7D61 zBJv);l3oJc2Ty-C+V;=lm>;Mwpa@yWbc<U+{%I9><_L&LXL_o8 zsNDDbP&`aJbl&TzAI9d&bB2TSV36;bpv!7sLh7?ae~CEFtZ1DFv7~5d{!D$@aevN# z<&+qa>24GtgHnGZN|$~26E5d3@$nlk_k0>RZxXg{PGt5bsK;+E>qGfU_s$KI-gq?a zSZo-H2bS(Qo{uemdR_n2NNU(v0O{|eq0em`&>!$wD1<${@7>_cq83A$7idzI81XTF zy4FHMorS^Hp{TqMyk6#ndBr8iE~j~Jk#N+@`cXr=Chxwv=G76Ifrtd2K2#yiz>8aS zU{|eycdWcD$P@>=l0+W+uNh>hl3*fyXK5OWoEkl)!1JQr#()rtfr4dY9kw}KdvRb2&Hm( z?5u@my~8VkZiwPBaZ;cUB6!WTL-aFKmR+Zi9*)fTI23IePZG<5`)!>|DQO(X-pp$3 zv;IgWOv`OWz1EXTt{DD=g8cZkhok-G&E62Bpe*NzPWR|XvcRookr?=k+Jyd7IG~;9DY0hQSr7r=3(=d zl=oa>C|{H7O-E+tu|a?9zV@UlV%tb0?5fQ%s@qCIwJ5OF6=XYR$sBfp*CP@uV#q59~rwRCFp*3 z&ojUuuL)FP0nt?Ye@D$4d_tk4eX?fM2X^P5Yd3>wc7K-AU{?oiJib>)5jPRg&d#f5 zXrEogm7&s3i@Qdr*1YX`Qq7?ENecF~V&%sJgWuS-q8xJ_ten3}dIOR{8$T|;5n$iPfP0c=*h#nnh1e4X=iMnGGh;;eu=>CdSG!b zXZYsxm3tfFtE`}_bN~vO;0&=9^K(HED?KYghR^Q5cq(ysk^$cnvXH=Lo({acNCF6d zH~hbQlzohFUjIdtfppoPDF5&ivrhD0B;l{f96wMjDXz1?I=~Z?huvC`V=WQT+m)4- z%hR39c)Gt><5dCFZTLlQM)+U2!kUdDa%9r^g+-jaDyg+5j)0A z5J4sExu~+ewS^79`7Q~IuViY%$D~1oK(BNYQepq5rY7NJ+q=;M;^&~LxswLLpgJP7 zm*8|{V`eY=MI(Sv_xJZ70aK9oH*-r|8%@S9$H>G4_p%*-3kCq-;kyTb%5D5g=4>O4 zB@M!31}Xiz&&Z4P@bnD)`gQr}A;A6N41qK=A8RYWJU`T-zcR$z+gn&z_;3M`UL^Ie zKBc3#v6?d(r#P6N4fSst-UxQTV=Hcq)DeZci!m3!fBER{l$^xuzv8|Xhqgxzd~g3~ zo=BlMM*Y?$w&<&G>Khd~KmC+@Pg&GHp$;Di>n}!Xy1LeQ9o{LyL++!cJk7@S-Cavt zYl}DDhw@KY3KJ7IdyF-tySh{iJ-?yL`ttDc96PyoKiI&Jg){wC5-UGc2pQRwE~VmF ziin0%eMnJt&ZdMu?qhZ?$4D)IKHlVX3+f#kE}g`sI1~hF5#_{?d~tCh8^bv3G^}9E zpLTn-)-C6^xM}|OQfGmj#6b&keSK}$a(!wXA$$thQskG$LqH-X4>_BTQJv3y*@bV) zoVUhmi3wd1Jl+?_PhXqKC>cTR>inX2%Y?sE18>cQM)z!bp78i%94@CH0 z8E+`DpP!%mo|^kgr9H%dMognyZJqH-!7sa}OYXj$e?&+vTk$x*`CuyU1N3D8PjUh~ zwac&3(Gvgxv+LDHGHO31)}o-GFmvdl`I5=d3=Y*~fJ8rX?0RvVUs{?Ai_%;h^f|4} zE?FH&k)z2j?^0OcicUK|c1i<8C03AAUvaU{SmS$zY9zbepLtzrE+WmlRcF3N z);HUf^=(o4L5P&lgaUJWj;h@<>*EL+)S@(O!NQGCS1xC_EK=dhNzm zC+wIWoz;H#6dUz3Plxm)#+2rjec$$d)ay6esOKdXG0pr-R;x7cO^Jdz;AO`}3mLZ* zO_Yv#LyyYvg3H{(ZPfjUt_G^!@1Pe>Gj9@*X(#vx8i`lyeO|!LiTX}@DJ)$p3yn%L zA*hQ3>E;k?H>O{i_a`#Us4Ht}#o0?sQ^81~)Cg;t>%16Hv)B}e{5$pMEro=&6GJm@ z;I5+0thABwXP&oBu4clw>>CAjAI(_kI5A4Re9wdHDawl_$0qDED=XE^VpH1`pizAn zGixH!KXfjhgetFOBeLhQ!py2I9ilxILpKGSH`P%ZCBG0oJ>aL#PX5VlHe^yY6kj`1 zmGnrX$YbGTczudr?SrwJ7`$vr1jkZ~br^*@e1jwPh3m^#c&bA>sr-d;3-O}ZF|ul; zvID>W6kntPZ%-tqHU_Kc(ih065Q^y&a+gMv7v$&DJe4pCYNQo%VJ>u?bC)KO;0kXn zUw+PsV3-@r4{*FV-Uyx?%M9TB5Lm7UwYBD-9ueJ?_3Dfinb+R$!LBrmt_Sejk1oMA z{6S8y9gU1~=BWc?=|SE!kzpsu-D0Jo3|eM{+}hr=a#^`-9AK-SSQh%~?9O}o9=mmG z+2+9dGHl2iOY8{Kt=SPOEDl|y;9k*EOCuP($~@n&PU#6GBXDZH1Kv4d=B@p?E*!*0 zT5qj`zAXFbc>2*KSG3IdV|*2(&dKA)EbyjYIu%L4vXn8OO6PZ#TaFe8d!7b;Ur$e# zRa9Bcrjo6R%2q>#P%R@w>m>-8DI`hbgor{>kR}hFd^QJ{0Al<)*g8#T7~dST%e@Cf zI~WrFSO`lQ{CTa*ZY3YuP^8$a6gzU`?3R|6=IT`m>dSWz%hfbA-2YT*tv0ZNu)MBE z<7ADag1d4RM^qt@ucj_g8LC*)$3<^1E8nUy{fhYks+n1|!dOHgp9LSoUmE!n1m#EP zDElSLz|yoee=d^mKQij5Vls+<92Nu*j=zGtCpeA~#mGl8SAB>5ycdmwuFoG|ZeFUK zD3*tP%EAeK+^2lKl9;cc*XyX%Rwl6)ryi!BZ?=l#tl#llOKbmoSwO-@pD2hki(hVY zEk~9tqrf=5o!b#-n4fT0CEY{wIXmNaBDv+NGY=7SF$Kmd8Y&Q$V6l6;bKzJDGkdCi zA+t0&zW+lK?TaB957!mM9Rm8}>;uE%y@EG5DVSqgx<3ujQ7v^-tAEt=mBLIoK+cp! zuAHp3uuuzpF{AdekNsGga?DG>Z1hUZH%=Pw5R2~s*ifS8Xg9=FPB2Ve91zXT2ELS1wpdZm6!o$t0YP-L3s`x6 zXKGaxkc)dbBIvl69e`4OEtF&%mOsK90AbX51)|hSP^ztxA+xmX`e0zhZ)Pg2R_#w& z$Y=Qb+;Wi2WnSwxHLR6T56EdE5Vt<3Ih^Oq2$ti@T!x@x_z*|jkD)Scnc%Z8Bl|6yMb7Sa` z;HRM;GPXbnV$$@iB!1j|NJ>xmqa3NnTs^0{o?>gw> z8D4*Rmd0CNJnA!u88GNgIdSG^NA|Ar78im^247pVSZBo=vCfU}@y2%=s zZ#eXkBbxjhGZt7IRi4xc7cXPEG(mre4>4C9yLB)jB(E(6<4LAd;m7MDTNqpZmPz^= z>R98$6X_OX0tuOg6ZI0m+3NOnzQ6`4`pA6L(APJA1XFQd?oIMj~G1fFEw-o4M)X4(m~QS5V%_j_kR6!-(iS1vrol@Qjv&`+k|Tx z1B=gVEXs`jWvD~<8}$qTHPJ$t~t{P(B z_Z!06>^S`!yH10Qy!jXE`wEuQ!Y?w`?~RKF@X`Daj~OCZH4DFlEF}gAKeWODeM-jJ zsG85R^7E&A_7n8dX$a1?4ESx6wa4sdYPGzdx9NK1bMTo+Wn0DdF_XY%;vJQv(hM(I ze?R&~#}XLM@QY9!`$cXQEnLtA6lvd9`N5#3W5f%NJw}lzayGKv!rLc9T6FGMq|-r7 zBw7KcDBoh$(rbtR(teY5tshJdBPEowX88L2_D`o}SdP04|AU35^5N;}EH)6As)|Wx zAse69@d9OO(;)zF07#?%XR45LJnq?B#?s9L7We8FVPbkMYsstNhZyZ6hFYF&ObA$} zCj^VsC@E&A5($cG{$`~u`KbZ@w?V=b2mQAoJim8j{_}l3iTSIQ1~1F}qoqwtVTi@r z$5d8$8CDkGjrRY*ogV1F{40Oz;NV}9y0nGLVoHnJzAT^4idJSbKE~%c^?V5a;6D|e zARej*zrx)<8M<25tDfys>YZxB!-TU_ztS#&6BmTTo%}UTucNIJC{~@VbdBLe4J&B-^huTabWiO1rIQ;~UxcFG#51&GEXowClXeBQJJYud^ zWUwy_6_7=uxNdh%3EL6a({WE#Oq@tn+UVloluD*4nNaG8JnYyA&@n6Tnap$7LSjfN zocIEx(x1Rohcli9G}N8NHLf1?v{Tb~DH*Q$K8T{aIKCJLTC5CZWsu7i@_<8xkyk~* zbZNt?Dhbl|2m$@2|!`;Szr&ND%)?&Ymb<+pla@w(wdy6|cQ)tTVN6!}#gM z){6q@^83_b6jnvsZym>okAFf#;ft}-gQ|srZ2xljyO7js5$0DWbxUV#!e3kLDBZnx z9(~)5X4`ndtj?qcf#`Ip1`*+Wb8g~;I`hA1OP#_Tbpcee1=qE8X!gv2g@#fE|9T_x zj)cHGI`0J`?W4UgY=tmfz)$i=(UP>!;cHS)HXdZvkhYxn$YC5|uSQ2L?J(G>riZ+U z9h+Po?hnJ|$~yK}*PMwZeFq6_8@uy4Hk4l6`3YyPzD&Y2=?QnsB+2L0Y@^3(ebl51)=?;xEIf3hW_g|=N7)WHB7 zOKge8fus`l8u?(sg8`l|<%qF6AP*(eS6F{meJzp**0B;+AN-k!_|_Kv%Dk4HjwgIS zk8M?W%9EGd%f6hN!Ef@`i{BxF%H*4AFVb|DO8cttBRre2gic{FwG2ndfR1qTnXDPh zeUR2u2u>w`F&BgcsVt0d1?P$`Ud1#MuA+ECn#O=#>ErPwK+&dysi>wPV;1XYU&wob zE`RpKTC@60nvp?1<#Znok?>y%vSiXTjQtC!!NIU#(Ty`vy;xFV7^>YhKKhVRg}7kc z|BlVuadJv W2DZYMWQ4W!Mdn?-ABDZ)o}WahW;o?h~~r~1M$^t1cb%OqC@pO{8PjF?d>j$&#sZr6QDS55tDB}AdzwmagPA&{ zjwgc_o~po=ulbzdex+GIN+bL;y8caLL$=R#PX0xx5hT*m2t>liQY7xH;6N+fIkY%{LhTjRDQ;0!ss`oswqurnx;pw#omJesN0kx zAN3I;_I~L3)m%%<%Ja832NB{aM+qX{9wWL$3mY4|jFV2w_U;QaWQNHnfj{avBTH1@ z<}k>+Z4gE5(@N&h$10meRsTUCqq|zaJd{-*vS9q62>8{ne7s*6fZ3|{ZRA+Z?!5US z(T^tu8im$|)+04l53;6y(Hdz%c6N3yYHp+D+}#DbS;{4*(!m!slccp1<(t=Mt5*x| zG?ijIP=Gn<7R2X^?RW|NDcz!om4^xWci|+#iGu6Yu{@W`2jy&_7yMp%My_Y?1k6UfZV*?$kzR=Hn zM6AFl-$z1dKVq({y))?VsvH5L1uN1*=(Q{8K>8m5t8|yL~*>kzR^)! z7yyY!h|%%!hyN>1LX9fjv9V#=-0JRnX8ZZDmpBf6;6js{f+8CK`CUvWaMdgE z9C{OoLLa(^SRwKF-lhU_>{`PIJpLTokGcN2lJRl5}&ZH0w$}BC7cqVoiYI@ke zZ&X0W6&lHQ4=w8f*lHw5Iy_a_&yD!5BaWj_UK39dMY^OCdp37E-W95~Qx)ZRS|WJNA6!8xvYp@5R_MNgDy7x} zRo|%cMdU@EoLM)%D`9u=_pGkQZHwPp%=IvMx3yog1L^ZZdJ%yyvx(41;u+TB|EeT zo+h)h%c&}^@hUi5v0r#|CY|sPQfp)|>=9`t3TwNigZKkIgHuMWmBkBk+Qgwhboxzj z%(Q6@wjY(+(0;+!@?Tn;&b+Jb@8jQb_9@gs6(T-+-K2)DXA8wLIYdiC7;%XR5hdEOSH%kDOL)vID07?62P zmoz-CQG`8KI04v-tD!Zc;(mv2S8FRSrKxF0pAFk?By2-uT*tcPT6Lj+n(xKlF$$K6 zuTk*vND;q))WT}h>wO8c+;~9dkOxanEoaZ|Lt@(&mOzeWaN#L;=$NMO+@rUHr>E%G zmprrQ`wM>6_r`v=iH;-O_k!YSdKh%4$}@giEN_WdNki-i7DjX)V%C=)*jpwK({J>J ztdzW-+PScI^&Bj1PdNnhrtVsqIP6%mNVL<|oPMU$k|?ZrGidYVXK+t(F4F?ClW4ZcjXOw(>GpTPkE|AUS@`!N2HjT$@Y2%ZH ziAo{eiPwZl2;*0P@9b4>EX53Z5L|A30zdrm;Y=sfZYlk$b#S4(>_gq#dO;47=Nl}x z6f=e&B+?NzIWU%N79Ll1y$@Ey-(k4Y9w8PfbZ1q5?$$%~Wob730O^MPE$XJK`yFDv zq`eCrIdhqGO_!e9H#Svko$NNc_SvQIMf?gcQfuoZuXOXbo(cSVy7OvI>HRmnuai-k zJ$loIHtJ?&X>5&V)t=I_Q@T%L3eY6&gdIc9jE{)-6mpOEHjlr)j@N-eCPjdGH zQS~A-Ii>^Q2IWbcxtM&mJqJE&%*8+TAl*cWt774zHN(nm@4Qo|!9M5W*IVu<5J7ip zu~@mdF+)onJnIS91;2iMY3(m^?%wzJtTu@&z13eIGE%Q^7*^Cdo8dOl@2NK~Hi~FB zmiS3lLV`jhEo}^xU!Bz28`6Ck*HWLI?~sTV0%zr%^txfSqc4`HHE-YI zb{L-?_vpjxm{`&%Ps@e+uaoMii}1c&zfKs>1a;z6r#_W(6$$?fOEDG3XvP=P3nMhH#SKvex~kJo(7B ztse{5x;ih|QmS&BcyNxiOQ3xFx+@J4^xwLmww5>PUu7xhPOfm8CnK09`RhbpM$9xu zE2?b0EH-)u(e-(qRg`xAjc+RR(lR04RRzK^+oL9{+b&qxOK$hW4L@-y47f@

    Lugmb)nuw_=+9Nia>b0E2teJZ`GTu3R45-*0Z7dSSR-s;^Tq z!Z7$Uq_h6FPQPjhlqSxkLGQOGFHH{*pWk-=@zsg?hbjMtsy>j}s+~0pb-H}}DjeQ2 z0Ws#}6U;5evRJDTgLyg{uua3QtTy#4vQF+b_jbvZ&*x95qGF|Q8#UIRy(~^>df~$T z8JfWg%-`lZk71;N%cLemJses6y~FZ4XJEE6Xe7Rvh24M*L9#yj(Jei1e( z>Rv4tAZxS9`I*ACpE{};URIHrU)2=3u^NQjHCV|W=Z#%_H8Z84BTx2lQ6E(G)l0>6 z^;WdlT9{N}L`bae9w?kYj47J$;KERCPqv+5?pp_&zz$m^N{0GGkM)=SJMR0)QZDq&6yCc#Y@CpPSc_ljo-dGB6+tuwZ4Oe|luBz-j5#;h znHKv;n^qqNQZp@b>Mt5DZ5ALzU6>mx*5lpIggp=ESd~rdD=EApJ_BQuD3r%%ryA^LPxWtrHLd4yj zPM+3?q9U&c0)+gtePYDq+V2?iau5I8^9YMV+)|{3O}m39m+#+qBG{&U-+odeZf zT*~$cuEZ&X`-S3a}`7#%(2{MsE0{<{g+s4FLW^ z*)KC)r^?Q@LE3#g$qCNCh!d`WiCD=sjX}NfLNpYnHLdX&e6?&bM7u+#+SL@X@HDsr z*vcyHLiQ|bOWbD7qpj5L&f;<4qnHScyH?~lt8wq3e;+WvoSP~`{(-OWeV)dW-jRO) zGT!k2Yts+%rvHb;2UTddZz0D54n96UF0MXsx!40^yMO;aa61Xy$^y5+hg^3cTl7r~ zE7;23o&bz}_xcp`^zKR>4eg5d9K3aLvNc|!|MM=n1h{g>-@eNiKtuZ@S-=eX=lR9a zd$85duehi<`?6f%?iTG6&R2EKXc+0h-=;6rWSdbx{_PG^SAk3n-{qQ$t}Zm7AT_r7 zFUjd2dPnO%VEs?$4p)RE`qoBn8mUoeEL_2QA^9KDmZsVV`r znQYwXOEB9w5L5UW|9SPn2x?MfPF7wny#6lj^;0Z8A($<;kJjr=F6@mbL~;-GJizD^ z3Pr9ze8&Km;5{(gw?5ivWbUY%divaO!d|rm6}a~&d8UzPD_=rB&YUxHf`9@U}& z)j4$96e9bFAWt(}@jm?rrBEokIN!^7c7om(Nr8>SAFC*P zDD-TtJ_|5Mr1&(wagJ<48N0#pYU*qQf{EB{HlCoIl-@~J=AdoHY&j1GN9aB4QZ2EVB4uHCpN7CxOAUSkegNub!FfO)F_sBJ9EoLl`lduW(%tvd5F_ zveY3SUXH!|kgsAL42saO%zu^P@)Sv~XRTv^e8uhn%;+{Ex*{Q2p2705)Q#{bM`uFT!`MMMG`qGle=V2M7Q8i7Q`jl=2XFE%XCeIE zv%hI&!2II>Fc+7;t%>0tGZd;z`9?MGW*gT?@c3Usm`@%ecy@IdD{ss?{2tD2($YP2 zm-X!K{m}Za<;TazYFeFD8K{uT03M)!_5%%l3O8&M5G(vgQ8f&f32JkM+lbLyw2kt~P((F6Bz{y)|?{%M5)& zYUt#%Dy$_-$P6L>AA_nu^vqz9A@x=13nhGlH{(gvt7~HY*JhnI7`VP|ZJM&o6H^Xn~n-i*qQHy3S=~8A;+kj$`-W8D-N5d$&hp9=_jXJ zy4{353Pa3X3{k*hdT!@QoW#^H7B4KWQRE~epOU8KZW(Wbq@a((kvKj_u%ntr$D1V1 zG$v{0vnWy}rbX|GVTvNdHx9{>Wb_ivd=68Mu5vCgEh^@Dq(`e&CF6XWy}JsJp*mv= zy$`r|qM1Thn?+pgcLB0&=sDXVv>w`JhN}7#8&HE5UaDa z$2J2a68oWqAbF+qcj-DkPg=Yin?;seNM+)fKOg@Q1qS#v$;LMz_|tkfVXx8Qv>mh- zZ)29WOtNt7zP|lQ{`XhIH6&*5T36iHi~N21zv;wi^v_VLt~b9gON`k15N@rpW55}P zu;Zo@dcEH+5auh88zth4EUMG^(ny>94ams0{e#RUnc+^@ib!rC9qmqksZJWy6$8Fc z=Xb~u;q9qsJ5W2Hut)mkgc3Wgc27{RKJ0SNTWMfk`*~~}y?ASf{zb-R`Fx$7;{xMR zTT@24wPyN2;gcx2av~0;>u`Er6;n4Gv($9+dHOtU-V>E`ScmTJ^~%V~Lv|1Olm^Zs zs;5F4T;{Z)?$fl_sQ}|X#eUaNVGuPV%&y2(hdfN=yq$cm_|dA?6ByO%(R{yd{$wfnNY3W&t_CGN|2J2aQ`PE?#> z9Ox3c7Sxo3p(+itmp`7V0OcuYFHBW7!2-(|Z-Wh>JGR@m$7;@LJ_V^Fdv00pLf8kW z?UIQWj%9~T(D|+eauK}N?4@gBM(fdy2bE`=FdjV5u%s$!Ey9jM*^fWj$?dx`uoBji zo6JiunA?kS?_VyVBTDn7rdRzmedU~QKOJqTs8o-Wjq}%59V|iroIbJ>zd6zpVDuI%Pwqy7X zK&xVfe(?Ay`1=2ljCg&lSILwU=&l!8C-P7r~?5^xI&!>1+c=qHxcBq#N{)eZSC| z7}5CArg;d1bGGC<>)lZDxGx>a(KhR0Wgtg%3irWc&1$_V#VK7}!&2&yXL64N@PU1W z5c#0~Z|?jHefv?3U_#x5x?G+gKI^T2RstRm#`60nuxe{nSSP6yWyETpbuhWt?iAI- zL}f)d+Yg01TSMGk-yAt#9-}#e!7S!0H>!G2heM+{2jGG`>95u zc5mn@Hkh@4hL^xgOT3nb8dqP!6Q0Tt^1Z8*eS9MhDN>(L-(#Z^x7U*r;ox;Sa>SBaOm#`vc@ zfJ0Ou=a)4T>ak@JgM8KcyGgpt8d)hSrgx?8*vqxn#1!s*vky0*|W(fw)Vm*D8r z>7Vq@Qu@agA@iHJdcIc%x~lxK;t6Dy$gcAH7hJvscxSk+eRf2>Wgt|s*S{1PFnxah z!I+w*IG4@E$?&PReNnQQi4og>fh2&ADs32EvD9AD5R`ncYX7spnH0JcrA2AkVS&A`d{#CayR+sjkl}#A#)~aKN{;y z|JO8~m#-$7<^OkU{?GqGq=3r(D?NDzjabruJmX0B|EZGpihn)Q1g!tM&Htm}OT@{L z^mAFmAO8^=xvGw=Cgfi>$updTvHw*%bpZDN>)a+h{O?e}?`wa(@yPuD()@qZP?{UO z<<=SQ%w&*G~*w zty;_hDgW!kV?GH(ZPt0c;{U}UT<-TDmI20-5;s_Nk`kRd@juB(R|P~AUmo^)`p%4u z9GBmX^FOu4=e#na@iMN3^@5e9n6C+_cM$rQ+xY+@wj9{e^)*>Y2(3arzyCkFkx2i? zxW2L!13A^QX?#7pAzEYd^RqxA?a&LrS_J<3N+vI}E2N5%np8d)T7@mgTcd`Sz;cKF zY5ptQr}6;%tkZWd_LavGE*lZ|{tbQHX<|F! ze|C}>VAJ{6UReL1Hl+#=r9womi}}y#_R+zZC?G*xteVToJ6_(S;xW+$_vRacNmQnT<|bQ0_hAJ4_|$9!9+884b((D7Rfz1Oue+O?-^xI zl#i@aufomqE>e~vynEB35^!9eC^tquK@TC=Oyfg)_LpSx_S7(IiO*b4-Vbu%qMR!# zW9z4(_eQLORvm?8Z{tthT*Z{bTBI6x2)pq6*z}ZpXfJ?34f-ka&84n2qz5Xf#CbV> zBG4lzYqI#wcyrYyDHF?>SckFqkwv!6T;t@DgLQ~h6ie{&{lUA=pSm)Ii-UlYt*zD2 zcvgB;wPrf~TPDu&va9G%IA<~%A8ZvrAdcyyfmz({Za_klA-?|UG_-j&8bT(Gy zo+=6s)BfFZth78*p556q$+Czn>qSLRWuciqO+~}RSWQX z=aLF27cl5DO5R~7C{{>A*%6edy|0@U4LDj5Yol0e6dY=xsQQp?d9g(cceKTu8x%85!@~T(>9Q8RT*eyw8ivFU=snCv$h& z5>@A(RKn6Uh%Dy@8eDlBiyLq2Mb=O+riTTbPQ^)Nq+}(g2-d+?fD4<(*8=uXO_~(s zobr$TKm#OoMFr0;faPXy0O(3rz+9aROCm;8nf8)WxB;cK;H{;Iw=O=C;k0T*8xCK_ zZs_p#011RmDC#2q=h(^r%dbnVa z$N5#=$c%IBj0ZOt;p+$WDBAoeLnA74qk>*Hm|2t&SJ@{yqEKbZeD*Sie89=h^5uN$ zryPicJN=T3s|hrT3b)jOX%6>Xe*BnYV>1lW6GZzYX-{4ALsPR0r9S| zfL2{Fjo;yO8{A4Q(9Ya}tRPk0y`E6FuplREOu0tsQE7>KGOk>L@}q#5q{TduQ8j@K z^#PxuA#9>^HHAEkE|BF`(c^akA+4f8>cnc!@JAUIv9L!f_i@l7Eq^_T4)cU;>eB=l zi<`ftm%bf+cFo@SlG78Silb9)kIry};5FI=uhUlt7(WW{VQoMearM?t8K{c+5gR=! z5;cYOyy2+bftJq}Mfu6a>@1*!cA!u@{La}k+iQXr0x@W?FsKCiRTq5JxuO_fS;#P9 zP_tQH?*4>SZR+<}zI&bPz~mg!wr##!(|ffmyp_PI;mif;t@(qcPQ?6+MFVUaO^>RZ z#}=dN*yj5B)L}LuIoY4I4Ff0$dJ7=zEQ$784*p3TQM!SSYM;L_b8_OxJbtHvB6EwP zk$h4WLO0-&Q;paRb_sV-l51gc&i$dV;G`kItjt45!yS{VXIfZtmwkgrLdfjT%3k3p z_E>{ca0r`LW>xi(yMCZw!Q;9OHU2zJC)b{0OBrR>5KdO9-IstzOi$=xU3r`gCjx2) z1^32Eu_*fmKpZTjb!)-d{6&wMjM)6FjZ5RD1Rce5*yL0 zbhBhA_&b;|+Qu3EJf9W6nNwaA%3V2W2-Fj+BCf+J0cUrQRi1{0)~bg&y&l*m?|VlECyw zVxB5N^=HbsatHY=%oN@(E-tDsybG2~lr=vs48it zp?wZBWI$Re`UIk}i;;R$sN?Z{3H z6{U2F5JTnjs@u?V2y96$5NFiaLssN%S!JqHpRm4>A0E;G+p-05Y02tY(e5hF5=)Yv zsGKnIwP*PMz(tcWT`v!lf>Li$99xt=Kg~v>j`$WqSh7vRBQ5@2O09C|rfp7y+GgCJ z(}uBPNy#@^+rqW1aoW%M7M&52HDwN{KgkWNu;I;CL-g>wuo3*ULxEHNy{@JU5KK6^ z@Gtc~$}Qb_L%oiNnRv?X>rEMe$qO0(2TL_iglaO@@RK}!3`VYhR}6HH*M{aw zqz)6coy-fHsCIj;nfi!F_Tt&btdd!*A-{>byUfv!Anh0(^$|_J>JE!?dbhLUg(!-r zP`y{LI9-2OjeemM2boqf&H=@7Y1*}}SwLlin+pH=-d>m&*jQxZm9&I5CvXam>H3iZdm=$KT)sZi7TWN&ZBrXSmvr z&tF9e87lb0_5^ZA27z)@M<9Lb%b@kjaAe|azPjS5sk$y`h+#1rxW{2)wCu%{{zOVp z_WL?AQo~nUTVGKMc(YHdy9MVZbUFG_B|dL2GBEUs#?C8tGz0(xwF?ET3|%DHj(^sN{yi@*_#}l{@;Z8lWk!I zNM2%dwYKZB*4<&-64ZZ1`{$3AD8Jx1}dQOXg;;kqko$cCSxO&F_{gIS#0UW&tetA7JNZLgPel z+mtb>ac4|5yXU_EBwF4(MZELNYwYZvzJF34x1g6_gD-yY^#k;HugS+ z2ob-I8ZQoDbiMFiV{D$hE}R$)5BoNSIB-}7+>`wI3GF__;BICVPs0Vcn%K>+8Ftwb zf7+ZpbG%wBBj9{Cd;H40RVD?vJaGi{k^?OQ`xNjJ=$i(_w2wA~fyQ(GjX(c`c>bHy z0LU|dnEne6Y5ql?A!bzoC0H92@?@!D}vAqd{?sYNNv(wxEH2yq6?!P93W?EvH2VepYYGyTjr@TesER zM2`8ukGkJSwclG%g0-+M&}8S=-@Q2DWQqF*dc-8RtV4$_#)kA*{5dem--}i-d4)($|7t7 z$bdB5Ully4eBTFw$mob|WpME9QgMZrN+e(=a*q%}lEA0ujIPN<{a0>?v#L9cah4>s zL9TF*nWV%juK#i2H-Fx2!?OgYxosA@E_;mw^rjfz!5 zhmhwaYJe@`9gme!CUV#cDrBK6gO7PT{z((Ucp;<1AbLAJVR0+7A&S;%ndVjbZK^iN zalT2_30oJZMU0}MhK4l0#+1U@AUWOc$jI=yIt?jpv?}8?en4LM>F#)VNf|}dE(b|X zl}}zWop$OIm2W&{V>UM9pn7U4X^e6L$7lRBAPs(!CaJ!eH@(B*;L15f`+O{NYXTZC z(>>Dx!yuw)dM>Tawo>0C^f9e8zD%Q&;}s;8oam?d1$JJh9;CE7J?QS@&f+tz)WSzJ zhJBV=K^SP*S>bp^puk2OJW^eO9^zAw)HA$5J57zb*mR?C_>Wm^+c=0$-yI>VmxqDk zRHmqLOa$+@8f~PMYr)9dqUyqEQHJfx?A9Z4M#!5qYGCt*WP|B}UNy7mZaXETDooG0 z0##ZZPkkN3u_JlSaSIlN$~TB5t3$N?B$}oSB(}-}i1BAzSVm04S*v1kftu0Cg?1UM z1D``h)m>Dj^mkOVVTvqLIGVZAkswnLWFit~p%-|1VxCXL)IgWmfSJ=3)`L%GCl~mO z)h{+`w81P%=R0*zq8@dya8ike^dPk-41Fz!E;Is-R!DPRE1KJTD}6A}U=XN(YtLzZ zo)?r?7<(upXe2|j@&gCOJ|ryDM>P>Q=O=9{J0q4}XC@~JTse!Y%qrGTW25SpWu!x2>}*a2SMw1|)3J8`z?;To@p8 zc!Jc{T6iW?eMV@OV18}En+a|)zJaA|MV6JYT?XB~DHa&sq|iPle-MR+5!b1DTz6d9fCUZ&A>Xd|HN%V7C028uX?TAW82_c;D&FI}Q~M8= zlS$^~1SP^n7Pw&~!@)HgIVqaf@SjkYX!z*bF?BAI)l^2Tuuq07)TxOBUieba`_oUz z0j(KJS$sjIM#5X#Ww5Ymsy|;t*)LPZ2#3k}k{1UJZc<9D%E&ZjP|m_yA!WII6w7M# ziPG$M^-yH6L;1@{lSa!%oTr*wxRqrmQn6<26<{u&j(NN5-GZ}X9K77sN*@>)rf8n` zt2k0MvBhPRnV3 zu#*n=8Tc?Lry@w1A|tObZZ^C*uLQa#b~X8FcN%^^Dw_RWKpTxELd9&@^Mu5gFTTN| z4nSLgxFL$KiKC>TK@R2Z-m)pr32I!wVES1FJcs{l)-boGaSGyzO3)J0+ey0qvmttq zg!uAoayd^!Rah2lT$F}nTp`=lrb&Mv(gZb&BC_5ZNQHJ;=XhqtsGi#N`Kb1m)YmCY zBLf;`ws`ZbXdPAIMtQ<1usMd5hKNg#C57AT488sD^#m?7C8s0R6R6_3; z^Dw2{v@EA!+i&X=RCH*+I+>GtmQ>~q$5y#BTXuyN`l!;95xP0 zcm=J@bdO4?^pmeFJN0g@M6QZvZkTTL?H)k4@c*d%?ZjIrQ542}e3_5mUr?~K2MFa_ zzOpB>uyy$l%g_n0TCHt=6_y%iq0_;_r5HD>y2N{{4{@M_>8W^=e@&Pv0 zqNO#P(9~N|_Mt7bY;x6^q-RVSx+5+*{t#NL8|Jx^q>PWMCR!uC_9ara)k7{YOX?#- zs)lgN?stSiJ3#A&&anuNq2g-~+T(Wlq`qd-XV=MeXs6*>@Y`XLTU4x9P$nM#42*lW zWcG@7{N?YXGAX6luw41DLK~|f_~?}vf;Xm`Sm) zX4CP&b3&_GzM4z&V1<``?fl#JIsAjbNFSeC4}d~aKfapajyValO7OJcs-G*%l|V9) ztjd3B&Sf0`zNT=iv?{c|c)|IZ+B;e`D2r5u2@duy$rCbg6ugr?2hX~haS9|pjH5)=n(58&S=yB=#k<;EuOrJfY;QO!IbTHn?3S_AA&n}EJDx?F zjfy@QhYwde6t5_7t+1Gzt!3<$$d!o%ZFSZfTf{r4y55fTA{Os$4GRMyv$LP{8u7t; z#kp(V5TfhuuPnJ&W`tp$Di$8y@n|dkeH6}%^i*t1^+UG)%C zJqM+O$mnYA1K19OLceiD*l2w+ti`eEgCE37QhV=e>Mw1oXs>%g9(5^1@+rSK*9cL) z$tCBLs8PaJlF3>ACy6n4v!slJCFiTPoS!&Ms<^iB8i6Ag^5bz%1Fn;w(Gc~#@pA2| zg+@WDiuG>ua|M#$FHJ41v&Rp98j>3F(nsSl zDV(t|b44^J7OSF$O+?LDz)PF?z#kfLjqqI#C|uE(CMJu~=+s*F0Usx~e(vNe)4=i3 zDrj!l8$s0+y9kRey*&zJvn!E4iVsH5gjwS~Z7v%iryXjY@!GOY? z?d7V=D#zSbjb9w29xA31l0PKXL07IW`JnD9t%YAS$2Q|Jexk)EvDc>e}zWJ6V?&-gQ z^=G-Q+Dn0W)hhtLj;s>|CZx=bznxu*0K!Hgsxko2{pEmL03^Tk{4Xuq0R}h{-XPT=)wX}e$mc!kbTSDh0#^}>f8wE+e#Ep!#~8Z8kj5(dvE7%Ms4sW zVWaY6)~K}BINw2%1xyoDePUO|^55cafNnM3vtR8OxLR#p8{*X#$CG-k1fF%jv^Z-& ztMj;akaF57%rZ3V0bnF>dw_ z>5qgznkmAj9W)y`4#++CZ{9KdPVu<={Qmx;A;^@)>%Z;k{cR5@X=`*7Ot^JA)5J0S z`V*k=A1+Wgij5>y1&DGKI+W|x28!&Ps4@3*RbQaji6egsT%&RCn*bhbyN;FK*qVl&(66!7G2!WcNB$_FqREd55a11 z*h@r7alS};j)-kGTVoBF8Qa_2vp}Ef4ncb4fi%gZM@0K1yg*OdLt@~XnCcIj2P~9R z04D7_R0&9rMsWSjpujL0TS-Asm5I+gZx9FXHu`-8ZrV2PLiml7v01hR205=^tARU+ z%%LX0El3?CCGX#2QK2_Y$s^%u5BK5!CF%$)U%$ER7q)9DHxb5ix7o(Buxxp-D@q_5 z(hF*2H_+YJ=Oj_D{!X0C0njlu@H79yV(jFLv*uz-43Mc-%Wy~EJf(J}@epCa`;?XW z5CagHCy0Ap$K*vkG02Ej=>2MQcTGu^jhaBdx+8aey$YD15 z9?x`Vx^fjCZA223G?J%lXRKo}SW&p$xK3rI0RD!>7}RKrcGqd>v7B`gvDe7wYeRU} z=syx21*cBx`3#k+$9Q1S?7EsLUIjME$avnjzh5h(L=<0#*7v3O8O?msX}M*{#~YWv zMmbC~Zgwih_N4MR**9jJ6xYbG0=(m#<@dr7&nGI!e@4q!#N z-m@b2wc7)(Wx_VR#Md=2XFa(Ro=L^p!&(HcH(q{ zp3~cPwOzjVa^s!k%?;!aDd}53dNVMkPw!XjS_cMZsH)Y-p3R{UZ@D~}*dAD4u`uV; zxNIP+mO02(*wR>jL{VhMRe$*QZTPbt@(3W&6j(hFC!xeOuss8A4<415nkw+GE;Y}) zUJXnxm1(EXrwq{e!qvGRW1?G+UqDqu>#&{p)J*bMglNm*`rezE1jeGTHLZXeie?eP zA}KzGr;?5nooZmHFR5{*Q9S4BC2cP4H#11;U^e6*MC_E7wu9}h3bUVgpn1_!;9j?46aeC-K@e!@TDKIIEqx5M@eJ9d2 z@F-sEpW^uqqmGA_Nib+*jMz5P-SI3>xu23{Bs|)G%Gmmix{y6zO-i>_GLDb_^lU^p zACj($jGR*WpvUE#EOR^6Ug{yj&DG`hBpb~GgoiG3d0n00DC`8rVS$FT{?guNYb9|+l=PIB0+^xt% zp6P#~&k6bM@dLHN)7M7hZ!P66Ytr4gXF^;qCiT@aZv;NW0_uK!D7kIC z29&w9FLu7^t&CQwMA5h0w*1h!4D=%+dyR**o1RFdp+c0oyArqm_$L7pzAl<QPL% z(PM>{LCe>Ss8jjE^WqFiOM;Nnb>~*#Wrc&AsUE0RN`O7~dk4JjK!pg|9;9?igAo3M zTn#q^@hyK5Dq+bOmrT(e2e3Ca2gxaayO-^b% zRC5g;)uRT+av5oEvtLzJFfy*9VaJ@3TIn6lR2Q4genj@sn(mud+S&HL)n3-ZDhqR$ zLE@=Cp2#bVrXm-x*$`};Ag^8{Tm33{N&UrBw1S!A%TaNn202%6QRGKEkB#Ga71P_x zKo&!AA_xhDQ*Eu>!?9j-+@gH?(HhDpm_$$WGU8Ta{HPwa6EL29?;Os^zEY`Yuf zF=W-wML*n-&VzI^TeH;EaDbTky3W?R@uVTxo~fcBKGt@kz?^>0<`HL9bYC*|LbMNH zA-Wwh52v=v&ePYZLp{p^_v}Y(HXG6Qx4MV)y9a#u&>{ttYiA+wlr*p#g;W(f^&vYMJQ_)vF3Q5r(C&XXby4?Sf%;hBD zWTL;@Y}PqSMAYtpLKLs2?|vrlcH-sW%c+@51YKJENaWnu;2r7UvYfTVcl=ue?rFrF z!@vy2Z{(`&c(-Cj@OISrB-hMS>7tn-$allykhF>=_$yghlEYl??XC45CcD#Nbc(#= z4-PC8)q!SK%T`vi03%&KcLyc*A*6>80}w5eTgwIB1PAUkCK~P>UO>`Jg#Qz=`$19(8ViVAILmo3hVA#LUy@>Cb8@@+X&k3EB83A9Uj91VOi&5n&&|L_rEk03sPwm&!a zY`VZ7NEKf5bQpee1UyU{;DPwO1LcU0SHhtNhK^{C{~`OVi5W+j^ev}1;J142gR=-k z$p=CLh$yh6bLv9DgYl1FPa}eU$lWWo5!wTRX~cdc3pg^K=ZDTv4o=y~zIfDp@2^aT z%Gmn!4?1|1-ty-v%$ zgK6-s(aCVF_;ka+%U=opgsCyU;)JzKEZKocPIodRs{*&Ho8$Zx^_@T^9pEFpxSvz; zS4+C#4U9`8j09Z#y#dC@azS!cu(evRNlGfD9flyT1b21#_AkKG1LlyKntl%$^z%Qu z(o9ldyNU$$ordg)R4C7naNBRL^qwuatnWZej#)O@H+iN4apCyzV9yKi^NXBMqAnN* zMZKTdiFPe&_vNJhwV`;+`?N@U!=qLG~1BIqf^BhbYv--oMZjT2TAY_o#wR7}{81$a} z4Qx%VP{d8Cd&HN}b5TG*uImfY6pN&I_z&SkfD%$3sB7JA@K21i8V{c zeaYI!Y_2Sh(A8<+ssG;8UmEtQKC$!ywD0Mg`}macfE$kn@o>%fmXX-t!eC3(5va)k zP%w5SG!TY2x1C7MS^uj)Zf&aED7t`N_1+bhyhk)fL_(zX)aK zJfX4j+UEzOjQ3&nk<_Q(N<-0DYUW$2BECZE`6i;uw}|hi;p8EEe3(`*P!`;7n66Wm#auw6J%_Vq3dMCI5bhy=dsE#l3U}&-P+Ttf$c>JVCBs@YsqDV8$Fm0 zUr#{@`G|x>p++T13>z;}!>A0wB5u^0`lGi4au<^hk#{*8PF z$+ZfJ^n&+}>Sm<;6Y$J$#dsfkB|(HeyWtM$n0-!$q30oViZD(Ev{)DS7P1rgHzBNV zq|%AQLisYQ5>=wkRip|F#!^xFJlJ!Blo#^`{3jxIb*rZ%$0dLwbCTNpF;!K{cXdIi zMQ!oM@t)@Kn)+GsB;}QP??AAUlzJ+y_G8T%r-u(WG|B*xJe#DKt_<)}?t4bRCeL0U z*H_XP*_C~($kB6%%K8pXkbcJ?QZBN*oL>f!s$JQ#O?-VFER{Vb;o*jzkLR~{eKi^c z*@V8e4kP8eW?$OYV1-iB>A8%{Kp@{cugD8vd32$k1=;dVK8$xSdRJ}_E zt!l7OBl4RaAW3BiH^D|T>w0NcuZq8urxW^GV$Di1PBX>u<0+GPpw2T7Cd0LUbFX|( zqgzi!MSCL+yD`O5)Yxi#R(|_@6-enjf7XuXe(~@=$B3Lv^a(K`N`&u*bpy&ip?Di6 zP2x3`1(D$&ze;bi7Rq}7s}OkApi!6;>MN%Uk5{Um{^kkYt8F2N(i$=Fww-s9$3 z^!>C2cuhIbsLZu%Qx^gCvMTk3B@*7I_d%28K0h(P zr&iMo>hw8ND1iFf(MRa>w?&U{gLh`23p0+yt;gCm7WNwi!7`r1Pstm$dlWs4VndJw z<Mq4A_UWQXZ4e_Po54ok0wPf z*BwwE7m)&gL83^xT~Soo+zuG9sYtQ(bHuzF90-C`P@eGAKWh|i^w^?b&{6}_%<6PL zMa$X~JNQ9EC-+jYv5knK9;QgpI}qM}ThgtNW`m7P--bF=Mw<3xAMeP=lX*S%Vk_mc zK@jV6qeF1vVJXI$#p+?V>p=D%EAC<7n}tXlCAGSleo!h|B&IsSz*+YIeJOcX-03az zF0g4$j(mlIurT!V)33jX$BAM$!eGY2AHQ;}%Lg-a)eVkfnrJqwJR?m64I4{`9hn#z zze;X~XDd>ijtMUNf>u=+B_*2A^^SdAcV7`)R&(md94S`HYZy81x|BG{j!J|uJ^8DrQk>-;&)Ng#fBrdNg)p~}qTUGI5lE%DfNj*IXX;rTYSF(u zL}v0}YJ+))a<7ZVY(rTOl5VdjW21XbyjxI_cRZR3W2q$Fi#buJc+BkU3x1S9{p36u zpB@5Fq3Mq0k7=bn_>AR>&sm*z@FwF*upJY*#;$TaJcRkK`zdMtoDW@oeOT{Xu&g{0 zJGbK4J4;CAe`Ea-vav^QYGaNw60~!L-{bBQiw?p#Z+)hQ!fc^gr&N7$Q%J)C2$OzZ#S z`m2!b4aQFHQo;bDm}qPh;!Gj_7<++3p(*Uz!X5O;Xh9gKzKRv9R zu2obcdVq;ui*Fk#IxX)}y?7i@zR~UL%Q>84H;=irtFHpiAU9i>sw$prisX)h&hPpc z=K6sGf9XqQmTiMeXX#+yamYT_ZKrggJp{<96|l*46|h&|vw`)W=pPlwjSbfCpF4Qw zut0G*5@%=IOclm5Q`Q}=*!0&^7_;eC~x0sjzjI|)7_Cr8;rqGz*zA=>~d7thg zb$}_(Pu3>GBZ_cUxkHZt>`#sJ^?pkg1^dZxlf3sOaT@tL_o4-riSNJl#5=kc}Oeo^zdWCEf zw(w0W?tCo*iv3I756dDo{FoX%xZ@3P)hUW#*Ey5&5}R&_3;>H3soDr z8<_5^j48G>*`ow(JE*O6W>SN2{zaes&BBwF@A6nvpP4Y7nJ`Wr2DeQ22^%2J6z`*A z-yToFi&vsM{i%W^4hGgfa7GVq_P2M0+cgKjL=P_HD(AWwwMnnCrwRF7on{QRE+2j-9o#RZKJ;PIk8-(J*f#P4k56PG`Cck?ja z2X_+%$^qDfO@6=leJ1Imhc`Y(bw2qvj?7Jh$H5N(fe@+NnZ~34#W)}+dp`dUk9YaQ z=a1=)7?ZbM>rT^Iuaj8cMkxW9WH^ub5B!L&i3s#KVkDgWuLuAHwRf3C&J% zZMB8|fkyFr{@+~-FkQ3ImS)GheGiwrk~29F2_PH(pSA4*zNN^ z*#z_jfPS^~i$71)ABcoVI2lCt2T&;o>Kch zBj^29b`-KEh%D+6bjQ8Vu$?nXiRbSY+y4+$)`$&pWtaghlT zl=RJ++AqFkMlfK!lgV|uAfKvI<@ujM6Da-2D;iK}!`7nj?) zd4)EUd!MM{yKNp!rKc7@SFToId^MF;;T-VtQ>Qd@L29jxk1_I}MD6I@h<-@iDZKTV ziaNC$u~_o?&N85zg)P6(hH}D|iL3l)jLnp6?MfCY)o}JAYyzmB8smia+o&jGo&(V^ z48y;KPm0#$`VRXmOp$EIa~0()*FjYbX6GoWS)z1rwVf&aT!vVriqyen>;Xjk^-Wtc zH>j`KVin*vbA+8wamHqq#!30&z5;OpU*Ud6`wk;kw- zMuiD)Y0z%klOE}-fz3G7JnG>SM0I95~jaq(Tfvklc?prNi_93>XGi=rE((Ix}rYe?^nR)^a3N?Nk)m2CLAuR1S zm9;M2_w@(?Rt6Nx*RRqDm;FNCq3yKG)JXpv?-@={R!JS6b47~GYc?I26?tYpZ*Y<0 zuU_zYTgHq0ozUu!;(+e8L(2~Yp`8^)Fj$E}L|HfQXLi&kM3T>;g^0=V%rcE^WDGW$ zzRhBZe5P5)UgTy&b=35Q!;a0}@YA3yc6&olBm+LfPPXZ(FsDXvM0GT=`)J#I}8k6>l@u!t>IS zRhdQo-m7T2-;yn6<vH>RRiRRO9W@R509h`t|fYu^3t@#Z?d#f>FT&%R7FxC zH}sw{2V$#zoG)dgiZ!&m+;ALiEe`baxd;Xsa45l|zen=n1O z^x>$gL6sOf^%wrVs^j9{;SR`Hj%WM1-yqO?8u_1ElOv7=Bq)PP0zX(pH`7oBpAQ!b z{hs`sw!PUEDt@^e3Fyw^s1jZ1uhhl-YQx0x`X)SqqE`b3(Q?mWjA&^c=mxU(VDAyR(qppZ6iFX^pKYqbZSB>4sVi>|33 z57{GH4*vVHi|~74kJ>(mVyU$Y-va7=LLy6&OaB@3uT`?apPFowa?PI#4?52VS()Fm z+g1hRa#>Dqek>+zIl}Sm9AmOA%0gNa)>``yR8z)RQea)t0o&#*e5~>p)NF9j8xR50 zD9nD3WP$|Z09!dODa|f~A#nkAXbBQJsB7_%cde<&pA z3I!^j2-cOk2DAGQ-cNNQ1TI$z80jFT96Vn{fRKAB67 z&s|FAZBW`yR|ezu#tr!w@OSnO%#zsr1Adx#i_$VIL{jwbF;6-{HSn~+wu!x_MtDq6 z%;dGBQF=I)qB{PKx4rD`+jy`@MyEm{*^?v0m*0VPns;t=^i=_E=V_mUcAK*}grHis zG{nkH*^j@HmOd;*syff}ZK?Q2;l6^P3*f+Bf^UkrC(Ll_IeUbg?8Y6qtWWC^Nt-^4 zmth9vTF|RP*}<)+N#<7pJ5sqy8k;-GlkovL74QsIA~bzPSbYN|bB=;6S$($}_&_q+ zO17^J16eWZHH8I-w|{Og%hUiPa~6{u$>+h*Pddvr^g}dQ1I}v|KweCwrdwC@q!I*P z)5V_BdCAIN-Z!fr&Ph`^ytMr!Er%aCtyBbytNRVevle~ksnh`Uj81}znYX0p$x{lJ z+-V1d)_cZ5wJIdMf}#nd`ef*5rXYZHVgRJGGxR&MqZ08q?n0RphGahFg+K?Z%eZui zKnB!r$Frj~PI~F;2L=48gEGl2i=?h%^&a~Do@xu8;s?Rv&t+$UsvEj1mEBk#z1;6| za;j!iLJ;zZbN&)y(eA@0U?VEY_NL_h?!VWb#0!NslOyG)x1082PC6cam6OB159OLr z=p@h{lD{a4Bdr+8ogbED4P7^%9GhK!h2tRYd1wUyk`v-$n{Y+Ndreh^4mp-4>ORgC zSf>>_ZieofruoNTjy;{fU&=b;1OLs{C#-Xm6val`ZMp*KlyhI2iG+5s8B+b^LKYk{{+1Mw4~Ggp|@c6V@&t$ zqJcmUqtnz=HU~;KIYa}p*qUVvTisY0BSa+Nq~*ttrhv@Ey^$0_gZtURhe67@cLck2 z8}jQiSdYuz^f4CIF_qNk-YudGE^sz4?m7&)TG1t%DFUUse~6Pu3iooH;)=mnNN)C) zTWV(&?)GO+WyRZ{E_w%Tb*HRPzpu^Tm1g#wn~%ru(Y-qR=JnU~!*w_b7iwec^k$zabV!}r1={2Dt5 zX`GpKI`X+>j2>mublDE<7;EPL>DuJ6UvJ4y8+X!J9nZtyt@JOmP;P*mYR|0rD%=(k zT;UF}Uj<_2eO*j~I@1~8eu6J`RmQH=o@YxK-3(VOADw*;=q~!J47&$LfII?_Oi3)5 zs86`b4^^G$I-6bWM{Mt@hP2Uq?h;cZ@5>i@YYHNvtF$JHFOEh z0w9g)L=jNn8uj9ZZLrBL=Bb&}u}1S_CzlTIWj8flfthTf-$x_1a??{i!}Br7chv2kl~w zqyYesb6La#Gy>>dr`O~UQl`U9!zV~z~PV$^r}5QomfT}?c$i#lw4a#3o4tpgeU(tk}( zYPN8Ki51%{#FX_v;GsOak{sGw*WlYd!e4_A4vI}W&aeh`A1SGw7MU1oya_<>sz-`qWydPyaNNvn3^4^H-;86Tt-Hlf@oda z;xWcbQLO|~V!Eb0Iu=iR6yLcBT0B)W)DI@nS)?hVsI2g+<8fCRZCAWFr{cP+8_TK? z`-Int*`r-pRmNRAZ0Kc0FwQ%IWHvI3&N_w}SE$mc5bkp`E4oOMwJ;6PlR(&1lF{x~ z%0@`fzw=4%xu1`Gh;@5cg5T#Qicw6X!A!FkiMr4=kTxF=g*^WY&{Ti7aQ{67Vllk% zOVp@Skjd>$D?yeJewm@o5(gKHi`3D>oj9 zOfCTejcRXkQ?_|VmM4|Tz%e}kCT)0FhWLd}T-p!bi(LEw`!>FKU~K+@KQRInRla@O zy0`Cp(Bm|b5zagff&);WPjyPC8Z`BL4bYJA7niJIODa=5D-I9%Q02pVM|F^^SqK!_ zNhWHvC6Uzzz4HgrSeujCh5uB~nvphy&kX~rKD{*iK-63m-I@F&F9CkM6>wb(OSZZi zk$C+rfe&5dGTYo04dv($zp^YN!exC#-48H0QzNm{{TGAwPsS+tTg{!ShWggnHl0AL z7AkVVT!pspUJ39OwrknwQz(l&ZV)#j{+7JEQ5u2zD*caa&i@zS{>(79L?Lu%_qdy%ioP|(0!yf?3eiwaz=s#+kUcy5c|c@w)^w_i zMX3Kfo1%7;h3Nw=hqZw)(N*V_Om(ZQPKbhvam=*f-1lxGD*9!046q8^mp&(?vWs>w z8L3YojH2hH$+&{4RiUd+Aj1+)ACnKUmp}ZBMn~Fl(Gk;mfVZHLs<21S%M~pb<1^TS zfwu~E#I%Y`ud3F}%ECxGgD-bsirl$HzV_+Q!_p&bvt98zymvew0 z$ZT+?F&3;+#?PxF4|bytBOUqd&}-VShF^XCk$88mcQx!HUT(pdWd-M56ZL9VkzI8h z;EhN{UBVr|7nY!@FD1>obMtW)h#O0?vD_oo3Ay~8w+lny{Ll_Un`^Dox*ndZs=sQq zuYkxLB!!_ey-iIiKJ&v$BYD6&eVsRtddzE`@yYl6c==E$tv!_b+d1mhwad+=y(0MX z-~7!3(qYpx_?$TYB~Rs~+ekI|)Gh(LETo;UBn?l?rTsPNt9mjE=#6`{DnTKr6f>Ke ze!?@8C-He)hD7>=2H!?n*7KcRI$J;7-EIM+rI|uir_8GO?Rd#wK#F}A(xc66zSldu z3VH+}@j-|;5xJ}D77EvQ_ti>%LgLTATTX8sF%)EH-%^;^GAzHQE!}#SH`H;7S#Uo^ zVNuark)H%rz6B8bma7`EJMG6C9@NIk~e_x~N;WY=|WQ*X@#4yElIgaP!qJTzY?;^4VY zI4YfSG@pY(1Vt=!3v(wzZ`jg_wQMdR63T#=a-*tly?8#zr99`y-xe>L ze<{La@iEb3!!j@1Lx8lunD;l2jvhebo5fl47Z$)d`Q6S5PmPk`u?K%5M~l^!H)&^^ zR_b_{fD;s8LZlwNi8s!($%yf9Ok?kZ8X09p3->LVII4W+J&e?s(J$zeq0dhx{Lf(2 zMKK|E5vM2-WQ(y67hO3OVp5Y$<>tDjZq)WPQjK#Mno4Lu5nM;KgyB@Beyv948%Bvv zyD5P{K>NME6=Yl2I+^p|4)(ZBG+E{Vb33 z^OZgo*pBk?XV=l8>Dfsl(JzbM^PDE|pvW6(W3 zI!%8nJ=@dKe1QWr13rht{tu-Q1=QZ!#Nen!H_y!CwBiXE$0zY0&28-2ISYWjW?4Ym>r^)_zt2x$=xtfoN z7vPhpFK2o?|NiU?Qbia**toUm{5f~5WH??K9k~?|MNrxjh0+~%`hCv0sWks$izlJE zDFZTl+Udb*rK+<$drHBRO)mXH<8Nus18qYAt-KOinBW*&Xh_>#dsXQ~L@;#o`@Bju zP@-;Q^#x$0@b+85f4~{iEL$+`H`0g%hPldm$aPj7j{`gZ*rHQdoF0Z>1-PzxLjEQP7}m#XBE@Eo4eFoVT2KY zsOUaOltjzP`}i_`CKEVV?$M)zKaxX&oqA_+@~iQ*5~4A?q~FaPrB#|J*S*&-(ADKU zTo;dQWgVSdVx3*U=B(MHH4th^Jn9GE#&gdHm=o_*W_z7nUPsS2Vv49CKS2&e{*w0> zlkOZay;T{tlKXA)$3-@J`9a4>IO(xwS)F)3Lr?k2)>;5;E!&AK6+Q?NRR#+&aTzE9 zM?@?|nFt=a%RoveYPsz6lHwtJt&1iz;mk z2Tpsx}Ze6IObPxSKQ_oePhJ;{A8dUJ8{_?b8F zm2Q69wCB~u#≠5CATB<6dM@(r&Ef(je~E=w<~t8L)SEZ$aVv{PG_Xh7$$_Pi9Sf zTHcP{xBLqvvM2~>K$j#yyAX}`@8P6A72&US5-I?HX1c>czYi8#%mp-{)jfGIg9bB# zs7@eQU(FnESm#{^d_F84EckHZ2O*&20lWhhcN3!{spAj2ImiuiFlNNUL|-FBrk1v_ zX@%8#uJorEo2r3}G_1|onH{o&5_ixd{k#A@>!U~a1E@D7+204!kfUckRJ7VmxE4je@sf@QCNvmb6mj&lMPqEm zgn|^xAgQ`ll_QR{2b*Ln;CaeyyW%iHF%p*(ScmFtp9s}94e>`X&w4D@t|2iLrygw7a z6mUH33*q~FxM7J`98fd{P}hG7(Xip}3(){CZIAVT9fXK(q!_FYd|Li!Th;NUd(mit z+bxy-^-NX-XmR&p&i7SCSMkR@>UO`6XB#O2eI8KXcK=|H6axU2q?O5elhXgy+j&Mc zm2Ghx1*0IS1ENpq1VNeA{qIOA9P~b$A=S z1NxgxTI@E)L`H1-gF-=t;Jrmh`ct4wB^yYatXfMbuvz6%&$gjH?@Ml`TGOR!d=tITOz8KXfl=E5MtRJrYrNZ0K=HyA=0)}OVR_@!o&`DV`dpe7)QuLt zH@LEFK~6Jwjo|CMsG3!3-nZ$hdnhZeD4f3Mbb>55E z)4ek;h16`blEJ?F-9&-qZp|X_c}d6H7A`*^2VGmVO02C{CEb|xB&jWrd(QAwP`Y>B zXxQ;Xn0>$Pr<^Gpi53i+(=a&=1zM^vxIurhhNJawHBd$+2N5C&X#i!gi{%mGG7{v7=c{2r!y z^1!TP_Mvm)^TEn%>pBz$8GKHVk!Xa?{u+VomL8X7edktb^$+^^UwaRo|3TK<$;%iZHJY@w0R=O(B56Wt(s|6CK?w_r3(VpLt`0casJ?Dpqh4(T zEiTbB_Ml#J?7jz_q{J9y65xvQiI1Vyw?<2}+>m0U23y}VQfn1xSao8B5qdsvUa!=d z2s&q+R6rM@xF;X@`TPT*`>9F?9g(HLa~DmmU`Tc~8`2UwIF%A)G5&KmCiOUeI2(Y< z@W77bc&l>IG5c+)=y`31GRgCX2g3N~1Fg7+@WXUJvfYB3^T)WTSO$)js1oabbK}|U z$BDRrQ$bze9=BfF84=hKNVzZUe!DHD5E{xNE<@e!tp{NW4=w{!jn1AmR;WBj7OxI> zv^W}g@3Jfdz`E)P%rz)}o~_c5NJvE<;%9$I86Ru6p^~7LW0ZsNsQa9|@)7`-Q+@DT za(RxryqJR_Ni6s$pKEjZDYayG&Wc2R?ge&O>CGwa%5h+$v(et+oS1U->g}6sbrUoU zhtS$m)lf?9pv2p7cRiVKSe}}^?#%lDoCVudsieQFE!6W?Y(qn-HPJD_ugB&IWTN`l z!uA<;Z|v2K)5Q^=_^zjWob-;0ZVhCHkq7k252;z2Asr=nD}S3`&Elboza?RUt`%bk zQ`CF}k;97ILrSvBE(7qw2*|g$t;9!V{>Fz*Wm=cl&0AO-W)te0ztt{QD;umPWjLaSsPZvB|t#RcwStJ?eYGBJ}eWq(=KGTQR&Siq(l`UA& zIxSfQ%rRX9;-vKwdOyGLDNORfW(1RReZI;3j3R2nA5?NN!pjcA`~D%^f7sib?g7P1 zlw|7+gqwXGSO$1$QxXn1a)znohLE zX$6-dN9pO&1T~iX6Jbp8Zw3&MP*?3rg0L=s!>K<2^~i? zD~dB~V>Cho6hj{p(h^o~nn)EtKjxn-cOqP?)6$=EA2ZAueg`LApkQX$u6|P8dj{s7 z_|RZ|<755Kl5D4=zWoaB4JQ~LzpvSgV<$s*k6lopi3hG))nAyP4R)-7RObuZI^*^~8PG39eDJkE)gR<-YO z9}ES#*OyxN>IA{zv<)K@)Z2oc+3>?zIvjYXu1$g1y%47v#iZ1CZNzF>xj(Qee zsB(^>#x=W)wWD&&tJl6gsu!4BRO)Q%t>?NPpPneB(xo-ar(}b!X?O5VcQdzWY6|$k z7zrRlNYgIGb;5kVk5DI#@5zV-)`LF+<4^^_`SI(lUlWW}>4{M}& z&1ibie<-LHGMy8WeCO!-n~l^*1wo@Z@O*B-Vf@ zp>m(UOL%|gAntMe=G3_ancXxV#O=YAD$Z;%D?L>gBLV+^-S7E>dh*12Rxv-ML73n%f zN=i%T;qkHd;k&jLX!w{HqVcDn*473But0;IF+}3P)`}D=a!GqN;&N}&lZ(-_0I3gX z^HkVQFpEHRS+0uV@+&;ahElHj=H@-I(2KoAwnkd)qz_CW2&btT4zIB~0qsQKN}Deu z5C}M2P$Mt^&>4gR=Nn2KTaZYk?&6z?Ag0v?r*3o19Z>-tbi^rM$vkk=xHbpy-de8f zXY%d^c1_8Xv_5iIsPIZjW=_s8E7Y;MFiL99m4quKLt#B0LL8@)356=oG8xTJ#1lW| z#P}GWi=hRep?wu5q6l(`aHvjZ%v1|kryedDUVzl$Kob&VaZh#4VoOD_=GN95bk;NU Xzln?+?*ZUx7M4pohUW{<+1>dE;=6U$ From bd41f2fc5a8e68482027dce8de732bb201096176 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 08:22:32 +1000 Subject: [PATCH 029/109] Add files via upload --- ...me-to-edu-windows-edition-upgrade-policy.png | Bin 0 -> 45890 bytes ...o-edu-windows-home-edition-intune-filter.png | Bin 0 -> 40112 bytes 2 files changed, 0 insertions(+), 0 deletions(-) create mode 100644 education/windows/images/change-home-to-edu-windows-edition-upgrade-policy.png create mode 100644 education/windows/images/change-home-to-edu-windows-home-edition-intune-filter.png diff --git a/education/windows/images/change-home-to-edu-windows-edition-upgrade-policy.png b/education/windows/images/change-home-to-edu-windows-edition-upgrade-policy.png new file mode 100644 index 0000000000000000000000000000000000000000..f9c4fc3a128310e500be82ccfaa19de52549b613 GIT binary patch literal 45890 zcmbTdby!r<*DpSbf})5>w}424bc0GtcZbq2bT^73-QC^I3|&fh49&pM-9yK~@A!S+ zd!PGz|GCd|&-1{Ub9S74&R%=1&-$#jgOwDdurNt5K_C#;7in=75D1M11bQs<>@jes zN*D_YoE|x;NPPxXjF9aB7f;MT$$tWYsv}?AeR~RAKew0Gb^?K3b^iN%)N5B{0s_^{ zd=dYo=5DaR_~K)%`UA#sVCZ*h#+=8iSP*d^iEdrQKueq%gC8doq;GNvHUO=!k@K#F zUdor34NZn{v9NSD=dWUM+7%_$a|9ATk$56u`_txO$zx>h!rHnj9LwHUwA^FFW5j6= z5-8lB?v!CpF*i3C^KQpkpj<;&NhvBmK0YxqF*Q|JPfuQl*QyQfU@t%>^??e;q)Bl(Xz5KU=-QhFaC9@O<#jNImxCUG(5uBqSDb$i`o!9Zl0?x!f6~8{PHk>(dfr{Y?LK|_lv7rt z>@2~>;d}I)y5P~mt92$%;qB5FKJipSOa+fXf5_i+azZdAbc8Ax85v6qT0Jc+irU-T z>+9>2(Cu&OSy>C%*b~_dS?TGEG|EZ*SwPNOO5_z46@BacorAZ`BZa|94qIK8ta=Kv zmn!*;w!%$0@dUv4N5#Mm$U6j7JOTudIPF=&2Lq zD30n7vpurM{+&zmmjLu#qS^Jp^Zt5EFyVvMBz?*|M)e>m3Xk=nWKQbbj{#g?O!hU^ z50M|q5O2s)7|X00Wm;6g(sBE4*N(c_t85q1>)>7T#w8@A0~$6uZ7F03%`wmBFyq7C zMc3nY^HAv4Sr;3&x6xN=D<~*fTknsg3rZkj5UpOS=^T}`dEr@XD3b7ks;cA7;Z)S^ zB_Xc0QdzvgtznC^U;X!jZz*?=!wcPl3e8lE+3XhR-jw_<*R7u}Q6HR{nHd}$oS2wM z&`pBz^4|pE5Cg-~90)Y%_M;$KElFU}O&Ah*OGDH77a^wOu=9-|8xzkmSWbK2W(;Pf zjr!?lh+<#KO!rbCySz|fJd>t5Fhh!7vgmGLL-;Ug zSV)bBIC85UZ_fWTTKzb8jLc+}89b+_KW=du6k|GQ9SQ6{W;B&~I4Rymr#vLg_vAV+ zrkv2WdI+4780b^co-+2vQjlb8?|Q{VN5_WL(i?SiH6SDgL!a`7a0UGWXrJXlw#fD4&$ncPuGVukrqsDov}&vzAW%IO z&*p-F^7FL6C(?UWLs3;hGtL4CmxhOX6Ysaw1Xf;aJL4e&AS#K%*i_$|Jlid$Pekd!1vJQO34C z8=)#%5JdfSLx?N1ttKEbhaOTREjFc67e7r^2~%Q@(bQyYID24%9n~L zOS?YO4o;k%^q%@r3wAqPNREq3VAD)2Gi`}HfEW{ zc#Zgfmcuz<$g?wgW|%d9O2HJqYz89Zkqf2m3{=s_PO)95$w>dCd_g$z#gtBZVY%kp z9#O)PQ8cvJG#+agbdy9*%9h@LZ%P^Qahmu$F5Zqkw@ygL1Ix z2iiKnhrpH5+CojmP1zHIO1IaiV@95unO${JF)$|w=Epf$+bk!Ia|FKzzeR6IB-EAP zuAOmK9U=;bb0Q0>`gfXF^S5&a=Qt|&4cNGCnKj?Lc**JTHHifl7N9N{Gs53799$_9 zl8A8Sxg8;tm9wWdNSajqQpR3ehf|6o8oy14;4_KKwmyyzjeBg10)Y-o^qXC&)jyk< z%q+n(h%^>~xA(8(001q{=4AFW1z+E)-kmV%FFui{P}m9@_xL5>gJVYjqNsWW!wVBW@j$AT$@HR>@~|drW&gXrdsUiW6-jhk&%&PI02lbB$O*7gCspr z^IYHZ)%`DO!Cp;TsPOo3N=TR~9<|Rx7)GezhIIEX_(KGW?j}h}!-$wbd6G^=!Pq5w zx?bJZHQ!f(630sqG)V3G191!$A~Q|r}B2ZWX$o}TNawe9!G*$f(lvIdP< zG!+>2I}dB&xA$&Bf~cm%b!D|YhBg=QXn?=JQUB&EaT-^|rjNdfUz+w&wyAvTmzKiF zY>&L{TdZ>V>0ex6O16|Xm|Hi~&6ABoHtGb`i;Jp;5+6>FfLo6^6Ay|yNwMPOn8B(d zu$?il#Z4roZlwi|%|~lH_9&SQ;W{@>rch=ZU48=FgE-yp^~BUS^{P4f%lUv$ov1-u|c+KNBX1%bZi!fWK2PLB2no!((9DyD1b(wquO zsA?jGIJw$(5-YtdTvDjh74(xbj$E!vbcU4BJNZ~VvNZZ|Pv>6K%#E1QdSPo@yp`$2jdL9cWoIrdJIKbY?APronAmUWg9+&`#bGEu zzloAE`$kOQ;xlplneNNDtEA3*(m&{R{VeJUgxUjjyUqL?`tR8MKbHfBCrg4;rHEG8 z)9`~V>69fgZ7|Ns{pEsa*5Qibuw<96DbEwc2eTJ|RR_&>{54$LDQf@JM)gg3N0t8` zEY#iIZB;wpW4PvVTG-x>$lOqmQ!P6!TGPKnbsggRww{<5xSi{69o=iH_Crz<6-rM_ zg}KU(!&zM~an%_^s9Y~t4=M~yH9&NNuKQY!jx}?$%$N{r8X8&RZp%M@;l02Chm*GV zpn>cQ9qwk_w@p4S?Mw88NQ4rcA1>;eq-|w}-5p`;v&0CU(qX|`q>%Ty6`$N8KD>pYh1crnuL(>|i{f+f<#=v= zJyNKBA&6l)KQpw4r#B2Ay#Jx29+3?hnq5P;Efdmg0D(TLuYEnr#^oRL(uz@_n;T<6 zQyM4R7JdSl%oX>eZ|Xl!2?5Nd_R02*B`_A?N6zK7Z7DtdbRYipf@j~39#Va{JqY0_%$0Qho9w$F+U z0QAx>-0vEtQx;qS0RfGTjpaJEREg_vPHfTNY{|F7Yu@02efkmpcq%= zA)Sfsa=Ny3Cy_0^-Q6HQ!Se*U5gI4m>Yjmldg>@a%j+*a_#Wuf&l(s6iTAyr@~2Pt z@zBXs-WuqM4$bTGl^a?uUnBS*;ZUMQV%XMdr_R945!#ALm) z{XQilLm`%af6Ya&q^fFpGra81|FOWQJ*ZBll>zhuKp7~HyHT~d%znQ^M6KYO6}rS% zM|>M)u7jauH`e?Q;6L9V*}&`cTimPZOFjb4@^gDvODsDnJh!t2Tz1Ez z5B?Z(`^^MP=4J;3!5oQrZOOW|05>wO&HZF`q0wn)k391UXgLA+)H0)h(^9xKn8-FE zb)xUKD6z!JfCA>GUp;MSkga`xvKW^ZaCvyWuj~!Bi3EPSdw6&Z4EWJW+-yDo_)^J# zL<--jB5y3DqwG2E`B+- zWi}k}@nI49V^VBMXYS5@FM!zbPp*K6c` ziwd-eDDl!suDswVpm@zHNwV2A?bC()>A#qK_Z0Jx~3} z*<$I?9rD~7zCVjz_;v3cPucWtM(J1NE7hVu!U^=a#9wX>n~#7=7iU-c`t>b#M_N!$ zeOVcE2(&L4myVw0y;|M+x(TK&J&by9rjj?z+JPYidU3S$0JKU8(9W}*C^*~S9qt=! z-B?o%&)lK^l_R~E>GV)EW!0(w?Kv&|5F;~l-WR+Xl>`wqC#Tbv)|Q2@-@~1#St!g} z?~sFM1|d0^;!^!hE_?J}2|ZM)sHmn&HLY}y!XoM>Hp+> zusB}+i}xe`_C+BMixs@irsX8;Y=16Rof0vBdaH|NN}lFS9QB_`F0e055#8$pelZ?)EvayR+=! z{<6JA0=hc>SEjVi^<92p;lvVAZ*xA=AfSp!ad9Dim?`3v7&%t)uB&7H(`fkS&{Dcr zvS{cU23Z@nDk{^jET`p67~^&Xz0R#9QRs2}4)kKgnwoDk!#6Eo^LYCV04g(#%&T^th>5wR7w(a&% z@aC=0=`iosP_h`ErOx|I@n{0m;;8q^PfH}@uk$cJX6~MGPY=mv6I#Ok~zP3Vo{6 z!+ApKw9ZD?HTLTrFCFTyU{_F0aF3SPh=Ow0?a1aGmFL*(yY81gDyCa0)qe+8n`Y$} z5ed^G_*MuSa~1szlUeFco$wdtFDE3hJa(}ivmH!53AQ*17!&dh)B6iXynAWRifdu; z#juHRyuER@>bP{(9`O3hBW6J@go#w7_p!H|iii~+#-q#;Eo*;vijM=G1AMVLQS1sI zbkpXdrya7irQc#0p``|;wHSm3vKy8OxdiIz6t!>~t zqwh98hsyN3&qj(q+{F?Km`#knX_ zC9GT=9F!d#*z>hz<25wPb+|oM>2q?hsY3GIxn-0RFu{{We=9$(59?U*csW%69zJx& z6EZO;B^{!-nU40{pJk6`%mhT?EJMG+{;$1e0IZSz>k`CV5unw?3z+k}1nO&Jm&kX! zn$dL3t*;||#s-!&_GHVok0j+tr)!bcV1z@~kx@3}SJIb5@#VrGT!$soAVfevnrxj( z+%|)n>+u*vOKR6mYhRmJrsueQo#E{y*^aD6N}XdLe6j1ffwo}z95$XRQS0J?gb3R3 zi4-pmkJ3Awf!iq}olh3QS3l$Q2=_n>yt*Vc9P)?JxaUuN&Y|&dUf8)_OpglmR-L22 z*KJW*+J{~g<9QU+AJ#Sn_zmq`VCV{d@d_R7O~_~CY?F?aPrnd>zqaJjrC`zfQN9&O z*FAKbF-fQm=jUma>=qn+Mc@kU>m7lVOW3J~xz8y2UZ!`wAA7{{cC9&v?i@F;%j8;X zJsYPR!wK6BFI@wT&6@q}nt`sWn|LiQ#s_vzNi=(tmyJ<9DFVh6I3xWMI)!0OtjpTh zE7k9>yNd^)0wO@XspXY~_ z*3Hx#0x*Nl!(Jf!mm`$GbOHuT;k8p3&FP~$GfgFsH7Aa)_csz$iC!9dxNLv$xtKFo zXp9^9hGz+|iwY*|W;`2wlpFlf1OG^04uza?ywkp5*nX^(5svy=Pq+t!Ab&%L`qKm{ zucfuLs{g2#npzhl|5T0XAT>2L`b(le5Ike$Dh1l#v!NF+yLkrmx2pchNRN{99pI{j zL^Y^Y?6s)=&d<-X!XpfkGZl2&48z4RtM%3J7OE%a%ku3Bc*(DiE+D%tIx(mB`>6J2 zjuiS02QU3`7$u6<6EmJ%$Zy}rKvicU_Z>C(e%1FPi6i4PN+eZRk?uOR%89dD#a#9mBRMoL^w-;`~ahBY0|xNTNNYu63F(b6UyEw!F93}alMKZH`0VDS zmvUlUZWIqj%v11K=yZq^&sz9u`6q$b#?=QSG(v94;~&Rn<=p5MB6KQHlWnFvuI#Gf zZ(5zrIt%JbN=ju6W-EybntFPAT3YS^)KYCw)l(Y+BOCQXq#P?W5YnNqa@9*UuqZ{+ zI>eOKR<=LXRD+XC;#;nAYKBsIk9sNn@RDVE+hzvnt2{M~%(Z0oU+!OJXTd3>ubRK)fowSCYjaZkOpY|fv~;zb`w@3AyDGDoRnx1ez1ZQk1Urb; zqRVR2tn4Z+B-EZqaD20znX7XuYnR**95e#^s7|jxI^QrOU@{(Nd8KMZu16*T<_JM& z# z)(n9-xHH_63+D4bw4z&DS|w!OXOe5}PhA*3?7p7Lc0HH}{5e3Cm#P-NGS#iO%pbRS zhi$A&D1|RR;IZw)54axy%pZWrr}E@?{*-x%6=gn>cD)uU`f_b|pz}G+D!djf1;6Pb zwNulmGQDMo`l38bm^tDP&Swn$R)gup3t-iXy296Tw=3%rfma1@Or{z znQTh&PKC&&U`2ST;HtQDzTJkA&ld+r;py-BLaoVe#|v<;x^J%mf86?bvOb4rFL{k& zgwKCFl7A7Afg;$uGg{OS*%-w2)WzN?Gp6aVLCDceoEJVEiv>$)!9RPttZr1j{UUj5 zRqpVXw7L4{naL4{$kt1^jle0TXw_J`o?!1?x@mP3+2@INS{=bKv3!LtA5H4zY*5eZ zpfMv4e{$K7IUc)l41TP6=Q!pt2F7Y(OdEk(k;eS9*^d-!Hbh7lm)=*W7q}3TyMVsR z`mPnWODz&!<$Kxc`J_#8W`fB}P|a{G?sRo)4$-<9)AZey{_i%YxQ(tvrf$Pls*NDO z`)fMGHnHNqK>%>DHn|A0@PGKAWMXlOA8syGvMj?>(nyk?ErXEDHuA)N9^iQRD_glh!l4lT5|O3N`d2LUv%|ErsEUG{#O}Z zOGaYN+VCp5vp8)Wq)AKlMJP(o|=ExwI=3OTrOi|GuY& zXHPhgLx+*HX@rpfvP!My`9R)pp@g({gBOAA{dJI)TLM9q;rnT_Z#6;a*h1jh=mByw z`Bb9rJqFaSm?fzi_^ldzqm#pQzo`A=Jju2#IS z`i+kHSy>-ha>YGw@EP;IsQoB8xdGT!Zm@cGbA({enkbtvvS(q6TGJN#^B<)EXg&2i zK>_cp;}?Xi0N0+su15T zu4p&zo06u+;EmYd5;>ZE?nbq4k9dqV$MaiErLsU9Dy!+`Ch9g`S!8CT8UJVpbvB1D zZzb>nHi+HlT}Vr;iK(g2^+qCe7LZ?afLW{rD4HCJ(3hX^1GMqx+x>~APNg-q( z^>F+uK9s~0>cy}Ngz0w{@|}L7W6>+?m02#F)je=iL=J}*UQq0;Lj<4hkE&fA)NV(v zpe~mR)kSajA!h->e$fKHcYNe?nE(U>2qppxqx#_s|J8rPkJq)R`?yPGp0Dxx;uM1ZUk3Vs4_eH(rjb>B5reUG@%55_rM{wT$ zfEpcZP-p0gAcvP}a|%#}v~-kdLt88qC3bUGjV?F^p_&XsCEA>C%apYW z74)0Vx4%re`|w7^#H>~Wq!0#$`$xR*v}Hc3w$nM=@Z+^C5Xhdc!C?*EZsK#^hMt6k zghyi|AgS_O(ZYXh07m!ck z$;Y5w;22tcZ5cm&Y%V!!RhvTi7zlXhj(T@)i7J9-UqmOAZ`%z`Oh6hM_;`5}Gp?%u zZrxt=?77_)wD+SsJzdyDO}vm+==iRm`gcNPF$lCw;jY)6QiX@M@;npsYa+Rz>swe& zJQb8f7Kk6Dvj5T;_$Bo8k4O-7-|QJAP8;Zr^mi5}J3$;JH46sSpT{73ub}FzJMlbq zWZ?9_7(`YYAUN82=f{WdbAU?_D9vQThfrwg{ye1bU-@@c4;dmyAc6r}ek_naa{4pS zU*gq&>S106{Y$^G#~0W6cU|HCAHw<%E&73F$bbD*2Lux+X}|=g88|dQ<^4;BT4wwo zQIEHn(zziUu6tYa{$aXI5ev(aN27Q_FiaJe zDuGr`3Tkt8ROSPDv}kSEcZQZP`mtj?MFyEl(JjUS8kaeXdvuQYB|~UHy3Ilu#E4Sf z^#>lJ3}F#Xdk;yumf`Q-p=SCb#meKiC4L^sMi=BQfxIY{99R7dvttv!Slk$8xVKnV z?QMoC6};V=o+xEK>HW3Xm;?3CbIWw?FxD8*i>@uuDgDTH(Ns3bIwt*t`@I{UHmtDS zkExhXSjyx`PL&|z%>CARNj$n-+LXc_czZJ;9@_;z3q{pvr#@f`!YT}t>_?gvofZo+ zM_vjrC%Rgv@RXVP${2iwkiZ(x{&XkDOdhZA|Ir}UrZ{DVV19CG_p7<@#A@ABsw$k? zmlay{f#^|jy2YA@2ciipkc*7p&}HKMBpKOVr(~@cHCgJr^>y0)Wn8Ar*rLCEi3WBn zJ&@S(Us%wFs2~c}a+{X0!5^S)3+@_a{4VcLcQ%NnJb4C5)(rz$zW0kH#!i07ip>6$ z`_^sX64J+_E)psLfgU zZ~fueO@Qo@h@d3qyohjKWSk&xKlrTGcRzlUpkmf_Wk>W%uU3>~{;M-5Wg7;JZ6WDS zbsn=$fjzP1n|I-2TI$-RBPXS&KJ>0oR1t1+pEFdSa8BWRChWq>3vKlKn>?7kWY(Ym zgS3#xTPwYOv|W<7+S~H1s@bge1nb1O@WH=qVRWWYj$h&n(_TJ<8}ICu#iGb3q{6h7 z0(rB5#gq%aZo_C0Rk-NUx@NB~fi6xju$hTz=KunpnThmmN@qJzuNxLEGNd4v3&btIoD4qu#57wFQtwFfqE5z3 zSAOztyD@6q?Yc&@aH?1#kH^sAXZug@2kED~ztAjwc$YX@e0~qp_cfg#!cLtyHylsV z6h%6kuL5tY(u-yKGphK~T{)IYXv{-8jxI`bSsj8NgZ>=+RKOX@mKjh?Y`JwV8HMD+ zZvvzPo)3$xjWv8Mc@sLe!1V{W^Lp17yxOs0MG!iFr5d|M)cR8W`u#Ec^m6ZY- zUX3({II9_V53RMx*{tH5CG2weuwm@+?bLHYyONfc&JF&0Q9=RgS4iCbQqhY~_;sE-mNFm)4`JaC}C6H&07+;Z#~79l;hpyPZnQqX|JA zy<3`YCM>&6r}Y^>A-PUwBS0GF;lB5|so*yeivsFz$9W#^bnM++4nx*Fc61^&Y<`+0 zW6|Oi+P{;B_?5o!re9t?%1Yc->-l8}xxm-hb26Nj6g$n1e3-E2 zw6$)^IeAgW4<@oP{nU>ZNxAYv`;4QKwKeO74FxnVLhEm-n5yMYNxSfCAojj6l15

    9VNP!P}=#`C)4;z{B8&NvCJIf1?jD4 zXY+EQt;sGafyX!-O>;N{%G@QKiA|MR;f=>m=;`u4O>S8qauA((clr8}H&-n!h&`zx z5^3&=S!CL zPi|h}t1_1-zANB*SkC;k$EmU3ayM&urqbHE@oYPt{y{+Hq~NN31LbtFgWFvecXA!} z-tt8Pt48>o2WoMHkZ0WC&Awd&E0y5Jjj?t2CbOMZvX`z(<+b+tY{_Z4-)L^~9nz^# zX&ApGl0GHTTL6k5KcwZZ8!zxn!SaySbkRG^puwBI?w&_AX6f%4r=|{D`_1*p;G$ol z{yO^P2Ur}I`=#7R${8pPy)Q4r*h4GE2VYvMfu9)q zze^Wza0prO2kdP<+m?im${|eFS*7x1HdjRDA%)!A`BovnKV61E&Q?o4hO0fZ!7BT6 zgw6w2nAE&T zUXs&5*yHC&iUAe19py&QmAs}n6^o%ua4*-cD!=pQ#c^&CTUYa|^pXkAZg9VxV$L}u zJ|1eMx%J%+N>0GRb259v!JT`)N;MIyd3*Xu8~U+Q;4ih^swCAODQ)mBm*+*@n!YSw zT4jt-6N-sT&+0=_w$$Hzvd;T;0cX1g)J8MJ3_9XxI9}hat!JlnpiR@M*oGf1ntR^( z>i6%`EPGGorvcAfj*<{%ai2XQCXdP=?|eM<^1zJLJEHiM9a9*Xy~oKi==}4H*)9po zOK``IKe{rvsNgM=UvXM$Dy@`n!ev^1z4{L8g;}vmMb(HZ+BNx0%Q+?Sbu?}Bip5a>nxVIszTc03yx6rD0+CwpUK0Q!M5_W?pV} zReZ{8i@%|v4L)JiJxq!m4ZlWB7we5`45NvX&KL!67*O>xNOlztZxjxx;9FqPNo4L$ zyIHxBvSgK&B+hmPvv*=n1AOQVq=QtD>Q$R9u7HYwaI6%S8!eVr^Mo}@T}$#61% z9DdL~{r0rL@wsAU{|Bxk08^9No8{4(7SQTt$9gVre`U~*XGsxb*6t)BYRS=w_swK% zWPe+9V}7H9&0DM?6;tC_G)X5^^mXUvv|N;re_OnI{Q%yYu4T4IaPy7z6PC_Q!n@j@ z&yZxN#j!E;0E|5hilc&R@$Gu@qQn8)n|hr6K9ad@}-=F1YKfkpJH1g78ZVB zK9ZAhtoUPnhgV=gaiCw{YF<+yC!7+jBk15dRsy|bbH8Hf(a=_|SFFMakf&s6;@h0r zoAP$Y`ihhbNswmWHK^Yl^OcfnY$9Br-kWi=x8kSi z5gAnWh^&P+Rd1&0mn$K0D7Gh1{tnNXBDR|Df}VoDW3Eq1%f=MkC2KD4tZZqgIqNNj zng?4+X?(6wEA+6RACzyWL~L(4xINgCk(osCUy6VGQMfdSt7A=u*uLG;@m`vi8W=`- zgDc)m!KDKtrzyt;ogJUOP@;ET0oE|Fr>)-FQ6TTVk98|B$Ev-Y%;?^ZbkUk>%{`)` z@Uhi!In-k-*ze$8vHXmodcb^}HM(#5JMvY&61$si z&O2IzTYfRRfN6Qp@Pi-WmE0sG^rq>}_Z3(N=AKB8`O%{toN(S(Mdv~8vv<-eMTu_Q?~A zw(+BGp8wwdQJuv907~5oDg=s}u<<$Yhn{SBW~@xwQ|Rr#ZZc z=CEzMwHeUkDJi6vUpuwGL|+nBtB-6qTcWfyrgt4@<809`$04_JIn75-eiB_=4dvkE zJ?X*0JSUkVneRhl72oYbuy7-Je!rk$86d;;LrGUiJu9!*ciEXde=?6I^RyAn>Lt2R zaWQ6w*!O?HC)`*Osqg8^uWV2o(mb<|a^CHlY70H@jI@s7=PiD#yEm0>Q(lyk(-#t! z$u|Dn0Cj6{daQY_db5?t<@@PAS8)1yyXS=WAWI(^WGzAFU@BW|d3zH!T1emY=8bRD z*&(sZ4{R?8MTP!ZqYwjAB8zhE$?CQ!5*F&yR9k-QcsY;FdnPT*Vk|$+TUOS3@aBe> zY0QtF9NW!8fo{+`2dGsu8g=C z9_lqKW^Jx}7~lY|)Gyq_!l%;=M`12fC&@x}*HXj6m$Yg72AlT6fTMY-{z#wA-kfNf zdT(i^EHlyNw@T7R_wN9zAwZD`l2WtS$LvWwohpU+B3{)}RxS((>j;}R0hv!Z=>NL6 z0Ryo^^&I)Z&Q7sB;09HCITvSCQk9MYPgyskVJ^<@vj!Izr%m~ z=Kq)T>bx`<2$1vh^8?hT%xOo=SiwJ6-L}6rTH^@Ox;2t6`%UBHN06y3x~_K=0nUH* z4zvn=T-F~;clvd2T#7RP4diPmHjMh;?h(+kq@IXE>Co3uzIu7^QV4D&?ZRtfZO;zN zNcoOSdVoRdH+P8hw zHg_#@2K=5ybmgN35sdEhrRT)!XeSOq!+%u7hm48{N8s25vZXwb>)*eF5Gmcdb$lW~ zK41%}$8q+fV6O|lH|djhH>dkq+Px4>lOX?+KPQR6h9LXG9Qwgp8=d?>?O#~qF~Qyv z4b?^&*_nq>s+1Msuv?8|q~FEKo5qwHHkeZ1UYu>$1Pyt(!si?4)Sb6pS$&txoUGE> zhg}HWz493aqd`I27_6tTolRz_Sx=U+cMzDK2C+sS*gTNfhz+4%&neSRGF?97Dd*N@ z+Y!UOc(z!AgR6Dtu(K2Oc3hFSW`5!n@6p7`&@b1ryUV(#i%TLWHF%6OC%TYxl1i~? zneFjiOJs{BDzphc_IJzP`3=Qt?R(+OHwhX#&5B-?Zjn1PzN_;SD#PP8;tD+mo1+J$ z)dz)%6B+p03s*i&9I-d2R^bItAXfQez}_LySHc-d9XuW7B#Gyqbp&QOh4q$L_~Sp_ z^Ug2d;BwUXjU3_l7BM7Wx# z!naPyB*ne$3pKJrl1fdoTE^s8(bv>@$9Kh^?mm@AhP*uS zJ7!X0MQjD}M*XXm)YLlX`%|*(Hqj3EG&rK#`j+*szGY}9;)l&PsOEl7;$KfRV_`4k zY3TL_iT~DE9-NBVyr?7d_|KzCfJZfifG0`}x2kWR_ME8G-S7A=R7UncD^!_0oG|e8 zO!na|(>XyQi;5yHx@oPy-j)|dyY-*Mp2ydnWV#4lqKuzH=9B9Ta8lwN_DoUFE`6SJ zHFs|;XjOlXt6CmHk7ywSERUcTpcoh{QiS%*cGv4|I=AL2mAGg_2R&m zz`QT2(e1;HbN}iVfdJLn(Ai_Do`pe4vaH|`oZ9+t$RQ4a;S>KTz@m?C^L+oP!tWuf z{m}{DY%G%N|DLfBH0bxO$r(xXzpkH3@DUaM7nk@y&+%lI{l-wD=>JfYH2aG%^=qCBe{&V8S(iR%7jL}6!CtFcL$hq0 zU>u?W=WD>hhvh9l2N$O#{l)x0Uf~_g=-afQZjJ4RYgmvq9$7)ObGHDwFnHZuhWFL; zP%Gju_(eL&e+fRN{>wCPplzmM;UAh$OHYNf)POtDzu{?CqqE!(Q93q#v)8)ptI%%5 zv$mYV9WJ8A;e4-LOJA+v0r!Jq;sKgn|w;?Q9I7}Zl+I;h$}DxZNR0D>ZuxEPe(3Y*?p9P=-&fN={r32?k11ZyzE}*t$Yq9^%}`5K+lulTh%^w z6jz5UUb>T7YJqo7ruQ2aT*%o9w>ZS;|4W)w^SxppftGoY9Swx#Pj!L4J($!-|5}rz zv$kugDwXxmSnR6JL|E^2Q$+74*R-TDS_}vn5Bytmm0wfRICVE$Pt@9Nt*h>QI^VPL zTR61bjeB^1L^18Hk2l<<)coMQ7{JYMAlgtXP2{%Zh@J7dACVRF8dMd$Aii0Jj@GC3 za1RD3}}iAep^gaMmsX4g{ni=hIvD@=9NvE zc~1YpX0%YYcD4k@NtN$<+0t%uw4N=Y4ZcbsTPo`pBDx$26+1F^@w^~4b?|!Ws9<+( zGVrYJMEEv5NvN`mwN^YfcOJDC7@JAb!^)7~+lnp1ZF)}-j~q~m)ugKo&^#1&9)O85 zzZ^(dDl4Se*VZ8qmD7mx_<9W`@}LTFOFQyz6T5lovliQ>7Oq!eGBHkT-0W7e=XS)g z(G!*=M7KiCVsk6lVsiLMS+(G1g+YVpyiaALcR88%Cw_n#2I;5>QEDGY4D`;!quOky zdF(`zbkvZ+OSPvJasv$r4U}KfgLDGA@FS2kx;2t&$T7S6jR2V2oIY+c+X)!HmGe^) z&uN0>9@V&w4Yf~T-Dm3jHaaPjEUFmcNlnZvas_vDDY^3}*P)T}cZYU_-Y^4%$mxl1 zu2G`(wHWP)+FZ#`(!`ciwFjIRu`CsATiY$lit_qxKW7Nxb=~(b=mwSU6z|sWX^i~j z+NhU;f7V%@hvA47SSuUIR(>&c*`HVDhl`ML9EL8IwFxL1IBsrgqW28xwOnWYn}<^a zG9%ALUjrl|4Myu#|K?AIeHX8FL&buF;N*JYP(_|>kw%lrKZS^3xbJT}Z-dQb@c)-+t>2X2ED-TL;43#ujEm_Q;)EwEk_)Wj${uwOuV1rUv$QxW3|z1okem%j z#(rdUS&NgJOLY-YrGV1y-r0}bysBB(yJHgT8D2_aX6rhRD2){j{U&ILpn^`kS$+R1 zwG7*UA0Ej%u_)^`blt4!<9V$$-+CHH>SWd%*=rGs)^xVZmbfpi;XQ9k0Uu=Bkr#ID zxvEi7Br_>39xrryVepmGQ_6GVe@)se>p34Clb13rje~`N9O)DHVuKc3Wzco;0gx34 zhvv0V%Nta`uMBd*3sE69_23uQMDmpb@uIl)5faJ}LDKZ#)TPx$73$Zbpk~`tvU#T7$5YrE>X8O3&yZ|}=r2g!k%q?; zW*Q!gGj`Q`#Q7bZp@vCRcE5|&Ro}m>^AfZrXYn{4;JwADs%hzBn~wKMecqhsjmk_W zL~px3N56P8-P6j?mlkhkmw7Vh+Q~B>klLF?Nve_XKsZpic74sl(@@n1V1i0fs`vl@ZYR)w^!F&4;LEi zQiSQcMrl?Jmw233pq4Q9kF`iI-*{0W1x4=r9UNfC*t146J}AdXk}|E<+f#S3BBS1M z(>5;&dCO#6H@n^Wxzk7(qqoX2;E`mp{cR-i0;m751*^p$4Co2d{bGQ5px=9+{ ze8@`3cp(pm(!*9a&h*Su3I1cqI*PEn{K}1j&Di{!uQn)#{U7f>dBVMS4O@-3tBYrf z>lh4V#F#w6H{SCB_s@L?F&Q7I@{Z__DEw*@Hq!LvuQPZ5P)as^A8aWrN;0C57N9F~ zJ)ZX|mSO+y#@{kh>i4+OPnzF~4{!fJ!p=G>%C>9!C@KO1N=hq;G)PMg(hbtxIdpfZ zNDbxCjdXXn5<_=McXu*B-dY%ZRky%hm+%P=8@nmqQDT`V&nUF!bO zlGOBA6O)WhFx3gjo$9%>F}=b%)Xfeot9t0ja;X!5lOt4?r$i9 z?nTF+hj@8iOTf)hA$zpG1*9L{ggTUW*8H^cE|$zyTW;bZU8RXiU3top8J;xEmnugF z#CoLx@moqECfmOkJ`Zf0RQehp8iu8gsdknN%cbH@0{Kfdltgbr#YK+oB&<}ZtEl?g zDY?w1tc`n@GE?3D(RyE;o|^#!|LI3#IWiFIQ5 z(=x6B%Scm#$PwBuuiMXLDdp^*`yE&1h)u*$IO(~sw+z0t*SBvL5<4NeST^wE5P!#o z*YNS6uMq=l)}U*Gn1p1S!~8N9O7}6SZdj@}LjK*k9JzMaw`Zq#6Ty3L#cjRwR>UXay>%1aHfFaAb;c8S5(VwV;~Q?DY%lS1b~cCIz* zyJt7nI(>A5kgxKX2~af-MLuKh*pql3wAHVc!Nm0AzIt`5Aby^BA+qaRF!_*rh1#N{ z*?5tT9-I?H3zKy9?f$m#aU|}@W<9mKyKdX>N{8*~HPXGbuPKy_D4N;a_1?j^9+Z0C z^bJM4#b<6sdUeMG6I}I#i`r)N>wbfxXy9P%KE^Mze z&rex*D>2KZR5~3;pi;{hW(DAS(q^ZwBPX}hzGPk9WyEfaam-!6lE3yzmOQi@r=;*0 z>;C!;FJH?nbZgA^&nb?XPlYiYhHNIMTR7Ffb5NqzI_}z5MupMdzw0jPLMoXvr5Tu=w3?^wKA92hhx!=!5{*nx; ztNv{9r&gzOj586Z)z!ob)meY# zDy&%oE0r_p2@;dx7CXBWB?OgeLmzPIlvs>?12WVV_Y7t#8?pIA1NW4HVaC_`>kZ%M zZ!pQGYu%5fNjugcSs(c9K{gMJXotc>j0fBN>674` zqQ33HeK5+GS@oW`M|k*F3ehS()|ys9u`+A)QlCV4LE7#USV=Mma?!5(V?>*}tE7_! zg|{QV?mezrvM9A{R4`x0(n9N@n!&3RvX>M#Us_l5RWma6mBaVmrgZk%9t zFvrpFmX=`EHIfR@N$=6z!Dd%>xXD^3PL_#j8ofSzjob0B-5~Hy(M6m-ippC*xo~s$ zs)D)}s(Kxr?8sUz)sV6(iC(R?2e$W(qqtHBWi@X}tf)OJLfA+3=<}Zc#yBo%)%x=H z#!U4s&s!FVsc#;WH}x3(X1osJ_G&ouO1^7cAI@pE`jO!CLDjA?wHRE9gIU5|=BL`* zfU8m7>@`!hN`UjutNLR-A2AlvL56XBr;2)+3Y7S@GS`_R^z1i(Uzld#P%=zFv-5>t21G%-`yzi=eu z+9dE?gw=^m;I%j86d9U*I~q|!$a`Th=fP zHoN{O?kco>VqwW`oB<23YUEcoeGNUxS&{14ysEeQA`S4n{1^+~oRln2u2#u0d2VLg zGbe&#Nmjhk9(li)Iiy?+_*88(nD_Sb{J?Q>X>-#G&1ZLPs#8?Y>4>9${Qy_gav`SMuCb_An4C# z%Yv}s#y#oXhFf82Uf0#sO)BD66uvI-(P>4|h58-s&wCVGOjh=ar=qQQj}{fUwKfS| zm7}(64rs7%k8mRTZs^v#)B>FL|J3jL3FneE`Ch*x^Cff>dd%xsBW@VX>)&!BvK-Ncu&c*G#OfbCxETbI3%bb9Wp?MOQtQGzzzJX$?) zsz=;=7&El61$A6&6g^AkOfP*NVjgiE-WHX+tz`_@bziJ|J&&UkrIKvH5-Dfu9DV9^ zKrf!4xU)m+w~gfEqZFXMz-s#Y{wifzv8FOC-Szu^6k*?xCTTYol1;y6eCM&gw6XRB zA>kp1;U#ME@yORwt%ZDyOB<8Y>l-CXQ-gW?+}4Kalz|4`@aBBX7+J&`!SKl5D~z+; zDr_%JzT?(vOOUs-{$}h7ned|lit7%Ud(+cIaBm}bwAR%sIxuC(ko!>Sg#GO9$}J7@ zY>r!2R#iM|A5&#cWDjaZTl^X8E$&n1aEF47cgaEHDDI4E`wJ)gX#4muOs|FK18aPz zR@L|Aa{AVU;llT6c}ru6bvyy$n!pR}*;L#2BAOmgL5yh;H`ePYnJCWb7*SYnXAnW4 zh}QG%#PaO`wbQaW{FIaPBW0-7FFzK7BWgWkS}~IU3t|`kqVs`N5phT!XWXm78bP5znLa2%0Iq4X4T!;8-F-yIPh{s=bzixzajcdLrdLA+ww+A?1r- z3@gugK*^=D>J+LnDj;jGZ8e1tRq{%l2hCq>>!S>T%vyYmJIwMU#~q1M#Qj9y0%^zB zMOw9k#a-a9=-Fhmon4&%fx*0XK!W!RcP&}&Q>Li;^;3A4M%!jj>b}$*8{nx$s^fJ_ z#{cu)u`k&bA9l!3tEbY%RK(kCa$MJyV-s7t9Gc9Y9P#@h*NaZaJvzD_%%?24GtL-d z*2JpVQV_1AemTyIj#Y;K(NZK-`-5$rFc&|N9jg=8PsWda`*RG(7G&L2B5N-=-7Cp& z#|XeVK7sA_A5Qg)beSa<8|&3Pf)3?j_5Md%bDJ#H(|bqn$0ru@uLNf3dbqsERq83> z!X;RphexA`22>m$2nl}^K72S#-B;(`$!Sus?A4tbw4%#wo*bL@smYgY8Opz&SFWXQ z{*~gee29(9P$Q`aJG#Dr8|P1j)8k^ElatXd{lA%P=GrV#BLcElU`eUjkFrqN#jAxs z{*n$Umz-I_ZKK0`ht@I#gqxC@A64t2R-PYC(%VNlo6IhDq#ocJpE}EUM@M_yD1Igm z@mKGhIFXXKzR|m|Eb+347r24ztEz~BLpqE%!^R*x*fCCDGH5kCMiEZ5j4I^DSvnHC z;~bEkP_5fEaUoHI&Pcz4J4I?J749>}Xc+T*w#=~>{jd7|8C#AsVj>2>w=u0;-Bs;e ztEA1tzoxzoqupO#R+#O&-1p;Ebf}2IQ0C-R&_A2W#R z;|BKhNC^urtaPq6LP#W~XP8B?ptW?ypPh2E?gq^#ACj7MZBR}|1c^rNZwzMx7X^~&AqWaHE6**Qspso>v6Gk&ZOAILpj+x0Lv(5*YkB0 zez;D&lX1HHP)dvO9)&0}&aOMIo2(I6c8gME*)zIwuxU)M zFcGY{CwEXp-s!k6uN;pOFvzfoh!(9gypy#FF~m^D?a#Ijk|#bPuRrm9mQXqZN{={N zXFv@7sB*hgFRZFQ9_=e)(1b+9O*Puj2;C7i>Z;QhXbcM;rXO~Wr6+PgwoOEYJIt7&Mb zI(}vEFr*V$qOi?CmT58iJn&bO1{!4PjG z_(yZ0PQ@pqe5bh@9I#RHxtt|kK?h?ujEq?Dr7XR?`-HmFNt_aae$9M@Ns5 zLRhn_!1jaIV=K#jh&#n8IfsvL14VAm{i>w8Gz%tSA?b4BE24)6<~ZQuaxO+6Mm+}_ z#>=*uJ8bl&j0Vn`Ry)~5^~_M6Wtv)_;3gBRw?&i@S+=19xDzUbi)AmRLRVOIKWkun zer+O#4sU2^Q4-_8T!m)R@2Kd?ZB)ytfRkK$2i!%VVge{@n)f5t@WRC#JEJI86)sn@ zS11o(VGIk9>gcCB64Vq~OY!q(2E!CI7y>>UOXIPc-~M1{vAO+(GvfK0bxQykeWyOP z<>=XQ9b5EheWRF?e4M}}WufkG@cPE{rg4Y&ya>(P*z1hS-QSAlk6TnMJ={X1h2dF)*0^Z2HT13U{yMP&N0N+Yw@o=4UHIpSeyX62ihs6jM z^qBb8;cE3cO1Jrk5teyTB z^XIj`-!F9%s;%Dsv)X=w#?G%+u`3GN*ynVAL>1Mf_^Tm{?b(dY*jXTIDy0*r!iY#X zPxq!PGpZN>VH=0`DOy>-X646!ZX~f?mMj3^q!wtr>W61WgUpfunAM59^vdu5JOV@4 zq{(3E)?8x}+u5s@_vf0y6ygeBI*H3)pki7-cyX4Vk$}f6#`11{Vy^a*o6@HL^$*QO z&O;}^j&lg4y15R)41M);7WodpN39owYoRaR7pfHioWw%#bB{iB83^g|_f4L7#S8eA8< z8}YZu86YJ7oDZVAol$sbkSz)B^7gU{;zI~dX4MC|hjnZYIuDI?-2N|nQRlxWt@u9! zBLCmu`yWO9*aIl226zS{C2hyRi=J?Ce!i}xLw63#r_3jgQshc*Xt>!acARMPvV>0% zj2%c2xjf2S3(h0h%T+COG=an6zyxwO-vdy4Wso<2`#h`LPX>9AC5)n% zvqYy@%`NQJz6BQK`4S$I6f`xpL@|G>NUzpro`}QZv!t%>!ujr0p-Le>Kt;pGZYvbz zHV{Cb%UM}nEfmQTjRwbwX-Z$T*6kmPQW#0LHg<(=UuSpMRYw@P5-ct!IL~^7DvPax_H9tOD*{ERh{V-+=dTH;JJY6ggvEms}AEY~6nz z>rFBw9OLjhg^mimhnYbfh^dAmc0Szabt}IMQ@xyS*`;Vdw~FOx3=8MiWOyYiraYZv zTAVzl1xjEwTxzzmJ=^12X$@B8eJ`Ec!&m3F;>Qmz9h4rF*1aCBgL{%{M^e)Hgk?+3 ze{}9xBUd4U7E=J+oN=J|lAN3z8kZG9z-$w}KV2zatQw+72uT0zA>CSn3T;x&DZH+b zQC_W{yZ+;5*&zz%N_zpvsz5H=1*;3WnBa{zE###yye7$$<$YQry^%ME9yaZilnA<}|IEo$ak5Zxx7}OCQ5X)HZ7wzL z6^N5l0(a-Z6JT6a-vkePE8kqn!{K$LmF82vHRjt@bvjUfsHDwIZEz5RjwL3e4xcSS zg>vV2MMmUTkZMJSDb~smb6MF}bgOg_$*#X+PPrZDB|b-qkW@`^Up^z8s7|KC2b&lh z$Ls7(0#%EEh0u9_hJ%^;us4Q2Lpg$Oi~$&}ii)E^9r*blqX>Q~bTqUIuIDsZnw}Fc z-bfvoF)=dAX350Vr`4aGo!#DgNolv*T!$4hG@DQ;O>e0@AmAp8D?o`z1%K~K=bnJ5 zR3r~qIN9RBAKeLtvb##sO{JCL&gvvN-+uI9huDfI=R1pzr8^f})_l4Zi$}T9Ex{CE zsJ})udx46rylmcSe_WDUivXyht69h6h0n$Spm_vZ)hKLk4r`5XehvDGL{96rlpE~p z#nW9*HBECm4nr>BgXaI>NbKcxwdw*JF_=W22a~jJ93{q44iIzfZOjRj0myJmg6E#@ z?kc6aI>u*ttOFFRv2#uCY#%@V8Fm{3Ub;vOZr3*3RdegT)AZ+#*aMX2Y_;67>Go8PTUsNs zH6$j7pRk85VfQ_e2Oh?qAEeFQ;Rbcri~WL(EX9md`h=Ro(zn%^&<0=K=B>twhXi?R zTN;6udQ!E<_tn;Zfdk&#MI0Wj24uC3-zJBAi>1WPKT_|+2Eqwg1_1v|22WGPd-p?X zmgYS)*4W|(`!$5F-#vh4T;D!Ut@JHj_>Eee&jT|?R5o2X@X zj_&waQmYHf5Yyp~t2n0o6S7PSxmIZc?li?E0O|p&rDpGiHEI%wGwr!t_RoTq2ld2Ab25*DJo(! zzm49Qc$k3z@TAh#uf7-^BX)v;zCMg|40AYu`;e5D&djfRNvFV+7WcAUNVQbg`}WFS z*b;E za_P;nhnQ1?w=T94mpoRSv{*_C6FzGLcj-Dq^{teT7>ae;f~nJ|gXr3!@K;pt83qia z-37B_d1_zO4nI!^@z~DQ4Kcf>-tNy>3wR&-j=~5jb8PTgpzla;_fCy;1g_i%P(~(j zHt%m5*&=bdT`nQMuFxzd+mg9v$D$zZ`sCtrO2gIcE`r-C_w_9N;J#LZb(1SZqY;*O zH8c28GcR{;!~_xR<>vSKT~K&QwdaCkNL025R%=?B{zny0hu?$W=b4ihe$Y72uf0;j zvE)A=kx%0CVrxmUSgy0zqarr^8cAFl9reL;oI00RezuIwp#A>(X6>_bTpWNes-sGz z#% z4B^mtj3(>yxXcj{c*tIRv)*hhx$9^gFXiPZmiD;%KR;FMoi7r&7$I`S9}1H#=f=HXzegUw2_q3i2wPK$Ag zHCbTRMm=OHqCdU3;B-1C<8jJ+z#Ix~RZo=;`7mZ02Y;<5Z5t5-Fo^k99`Q7R!wReyTlhbIj4x#Yx-c9KDw50r06@CK(QI_QQJY*>2xd(p zhvn$#7OB%Y@uS+5v0V9m*||yw{~q_1nQBX1Q-v~7RE2k$7J$=wn1SN(v1{+gVwiJi zoaEv4rj~HoME>zhsn78-ktQG>9qtg0YkN&`Sl)Fx=j-=0*AwOoaNO}~+lc1PGe)ce z$6K~y?<~nDZ%ts#I-DoFQ=$fTPVD4O*=a0!-dT=~6*JG`uF5kFzIxxH#SKa%(4TBD z^czO?f47axpOH)C@X_ys2`*nY-);l)L1XJ|D#iOLUyD)c%YdgG#2+1u3ARtlm8yI# zo{Sd?zDkOaPx*r6LT=^P-%QL^IGy1UfD$MQLR@5Zb$(}k;pQINlFw-VYd7-{9jgH6 zrOVTQvZ)t6PLG*Rh;my6Kr+>CV}jnl z3=LKpk1?L_@*&P2ooDrvhQ#HbrI6i-^y$xhiPIzcTxVjG(e$Wg@99+D5a+Khb}iPH z{o_4LKgw@J;^97tEA0baTQW`#H<7rD%lAH>Zk{vosm#q>`Pq3EOT@!wY|ap7i`v&rlzK1VgUJq7Y!YqHgBMh&B>FkX3q@Gk_MKc zCP-7HfLXY?o8f?vVvM!R-g{~2=C`G@#QRx84j^pM{#p?pHh+t&tU!wPDE|at5()cP z$w#$B=3!QDjtGX0=9<3~$XxuFO~uKG`~7v89=A`2!n93*cP zS1aw*P?ts<*m*- zLYCTvOv)*7?e~x0Ks5)z3z2yBrL@#G1fNkPpG<|*61O~PuoM{uGZX@uskJ3f;n@Bz zwP{O-8@2w~Pc9FDEK@K`0(+Z{O)zvS(~(i&aX3{{EK|$}vr`LEji_o5mgU}(xUhIWfURQtW)^~Jm2k&;0Fo<&q7hltVYooA`K#{*UQlG1)r^^>} zb4&_1pXn1!>0-LFo;tw8(ImZH^Jm5^XxBW8&iZ<2`=^;r@cwFP`J|TZDaX&N!=J}j zJxw{bELmV3G2bR@y|!LSMyx^d`}%Z_l3QSl932^%!G{jO@e(PJgwnrEqs9YXXG>CD zs;4L@ND_w9gLU5;ps{ z3S6cY#|pUQKkNrMB@hO%g?JxmQJ5fAwfW%C&xD)WkesN@)3Xu0P8B|bUnN@F2tM-j zele#`@)*{s0h|#PJ4a5dzG>47+au;#o+tT4D)@w!UJaoMgrqI5gG-22kaja1(DE-z zZf;Yili0FR28<@CEOw^#%kVd>wY#H;)F&kOD^HF+Bp+I8Jf|H*lVWW#Aj_EVa!DjO z>)Tz77dP7{1p482=Z_|0#@Ti^nkqkV+`%n1$K-?B z8Lhnnj(sa8Jp^E!$2(7FUz5#11}9zTou>d2u1L#6wgK2)+V*@!Mxo(c0Yjc`Rq0fk z%7T7u4W|n?-JWfaIa%aZf>Na1O+0d{-Y#_y4sP7ZD(?fxCIbV5s+R?6F)=1L`D)Xe z!f&5ry#aha61%Jn$wDluDwus&k@-H`%)=~li$iDF=7BWr1T&sh?T!u(Kr}N%Nez+R zt}iPaE)waP!KB6VXbgcs5VvC&^eti9cVd8jo)U`RDX*Clh%ksmfPI(S7EcIl2JTJt z5Dmz1Nr1g(c}sm~TwR~~P_uR@B|O_Q+dLgbp+pBPC89aX*RPIA{~%qcO@A)@`P)dm zm!M+AC_su_)t^%>IPnhq+Lo;`Om%qaX=`V}T1y)yDT+;;Q1;LF*o{}=F&z?ml_PV5 z>+9RccTr(PQ%tKAyovGAcjs6|MSN<;7tcqnJjD(fHVI4Xo9+vF!W8SDc z&qQVp@`q`&#mD5&FY#0@w*tq#URy(oj;e~QaoRb=g;Dd(9M@iJu17~nvJ-QoQK$H# z+@Y7jaovO8;dI>BMbd!pn+fsc`o>Ov`}>Ycg+$Y7R=88b+5Xw`qa@RCFRO92scRV% zqhZGE_P2Kd-d-CkUuVT_?gTCb=?rwmI z#B89&`(|Tv^VA_mN|Z`LK>?sTuE%V11JQHD(p!MCozA0-00{6(RU#buKVrv8kTMr`tDM=#si=RV&qf^yrZ(Rqs{*!vNC+6|djIPpf3Y zQRF9wIfungEV1a9!jNdNBJ_OVR6IPIYgS9V`)e&~nxDsJa-?0Bc}F7em}3!?V|NE+TsgaO6swbp6_EEu(v=sKV}2Bm z0S4a;Ls_VKk%PH%pHaYI>E&-*a$d)uwZxwfQ%Clz2QpU?Zarr_QUu&Sw{CKBn4;8F zhkJJWGeCQl>ySZz>si%~oMDXwRbUQfePaiOXcMS8UsQ_XwF)EIP#zy2>&k=R#vwNC}5rQAfA=XzJ+TUUb!0*Nnvv4VMb(bFfpgj9$gtsH2=F5jwC3zs623EtMtJ z3JTFtdi+{IO* zvkz5$R7s8&zCZPa?kG{E?bw9Pb@Tf;+F3VG&GOhKNUEP4WMX>%UImO!FTN2gubO<0 z{^G2!vCeT?YfMc$*ljh19iO-`fjoU8B)=bzX5H?le{sWUAMQ$165*N?Z7^b*s#v$$n|FaJzv=Dx95z z%PBVkykH?G=`J4gzOQn%PQ9A~wtJhKYCtfai07HzES;pXHDNv9Fmbdx0D#BWbfWM| zM=#mboL!!Onjj!2Ka|L-K3#7V&H1i}xt`M8M#-2GxRxGK6cP3LE>Hntyj&`UzFjCdB?&5P+h%>JKHbjaq zgu6H|-VzH?kC5o%DWR$*nsJ4bnqEu{llj#%6k)Lf1lwbVa`gWx6F#ulG^iZ#k)9H1 z-{H7roL4v5e1d-Ybn`C2&@T4zUmXb$!;D3|wh_%tYzkCN5(?LMD(IJ5Y5^L(?0@lK zcF36FLCm61Rkgg4Sg)WSRluVGe0v=gbuGBLX=7)w5*`^i{wuB1PR()swKR3gm8(+h z2Y=3DspaDuS%J)F2jX0fVL(0fCx3lwP282BWHwxd?zNtS*LniKGQ}$`Rt}Dp4gGJE z0zqCXJ0F0%2z)JVJHt1<_=oy$ zuFony21I|gwqJ|}fA7ne!jGe#A8kZkQZ=iDM8CV$qUB%ojd-O}-A}b#=bvSaZFlnR z98J9cB8Z%uLXRi#Fk5F2nxNVTgHSt>xCpTM*#m!TbDa_cw4agx9Uq zvj3i;3989`lVTnN@X*>GYN|`69E>R*#=gFQI7P9}rh{v0pUF@`lTjS{pjp0qVw}>& z*7{>^#<;wb4y)L|5`EzdNI9(eLoAsbMvZzc>7l%r$vn3L%oA1P@NE(go!kuZY$@fT z4KI)Uh-W&z459wD~E0v*jY4}WWiy~Sj*_=gQDUk`-i3oV(dF|hg($P%fnzP>~w9$si7g;2e|zFZR!cXQW*W4^--CV$R-4mlMp_GN9DzrYDm8eV(f zw~WP<1wU#NN^xSb2*3nNH!7%e1F6>X&Q9>Gc~7)qQu?hFP;P&D149B1cf+-C^4DbK zujFJbmN+%@VPg~y)~g5WRs07PKLftJw zB{9CM4%=Gdm<_dxr)uXND}kMPjyC-26%3AMz68G1(F)Y{V#O4Ir*otELC~iNY+4tA0>5tRT*wmh#5vq#>qR=rp&S7q@kXH#Cj=26w7wMHd&Vvegs5$gb2#5Ovv z5#*%!UlK#oVpM-I%czko+^Lz)nHq5b=l9v}2>4?Vik8S)I-OMN{cQ!=o#zAX1gVSw z2L3AAOPpPyA_q=6f(?6sq%xP62c1f-vxVJ7k~%M*bQnBU~3K9{Rg} zz6$+Y0&j=+?`I5f7yeyDvHzEI1nqzQELBfY3@lJ%lbd{J6EX4Y(}zWU=|%DS|6P>- zVKn2XMbAQ$nOg3>>wWg3^3=O9Ct58w&sjz~KJU(OxBps+_YfSZo2^4U4*Rj1h0S)9 z_p0du1R&y9fC8HuIjD5<;~mhvi#e@m0KGUJDdhe({O#}MDFAkf1S}0FmVEj3JDJ;D z^198yYa8vPDM=UW)T!743pb_v*FSS|wVj(r=DEiLt^6&lr(-bhpOae0JKpa1_&qec zN{u68of27e0d3OKd?xY19PtyaVd2UK`WUGWP};6)CAd4ltsiuLj^N^2qC+^I62a@$ zwTi0q6Ce-I=2h~(}tN*!Fv7$jejmvkO1Wfe*zzP)>`8=T=PHK0k_|Tu_AC1xV?4?&m(l{3Z@&b!}Lp&ffl?sS6AQt{Y6DYj`B@k zjKr|^QvjZ(f;S;)phc3w)Fu{w`o%VWy}2(Zkrsg01UUP<%jF*mq`RMIwgF#Gb6~UP zRaM@q8RrLSnJE6xr`Uj4{1ND?x;>U_yTA@UsCW*CXHge>4^0H8SUeh$0R5HLA zYA1imnJ<`TO0jC?QVWIx<0{j)#e;=6t>swZ$J$$W?WP#{b-{(Fl*san`$?oTXQ}BC zXAhYqQB5ENq0`_529n!pYQY;+8E>T@0VW-lADxHpWVUHP&F1$w9TGfQJG5SZMq4V0 zCO3&$%n_v!YTD#eX3opOYIRoqDpmy^cn)Y%;5d zXOU+}^J@iQ;-GwViwo3c^a7FMl8`JFPFkRIXzJEAmF3zFG(>-N*^6K1=Hv6~k7u!} zaIU*}2|W6_$kofS4E^2NE+JmdqHL%WNH>+A2nFG4S9m0bVUFFYp5}|-j;Qi7IU!N~ z_uY$Jh2n4j$(kw1^-HrR=4U5IupDL2_h;5VOtV+YXL%q(sm(?gWAl|rxIMm5Y zTk=u(A}FV!!qL)=&E+ZFfPdtd^>-l}le$kMem#qABkp{bw>WuLR_LHO0B&r6*S&U$&qKIW{Ap6y+E(Gc8`nfBfTuVuJ{WR?lDtJT;JxAiIDP)|hl0wH}|T$`d!;dT@=W=PLh7B{B* z4A`a)e%NaU9Cno!N#ltI9NwMnJ1&Jbk5(vHS>%92aCuRJN?Wg)C#@9H-c{NVsOqkG zR!)yT*ZQd*w2kVQsq&immw9;;MvoI?Zva*M`vK`3=i}nYT5esRu%aBpFc=|*KhA1c zYgw1)%-HTD%MtGVU%Vf}nnb9grzOZdG zd~rS*3isokhOpG~O zzeR4QuxwKoggrKhFCG=&LZqpKU#skKBF-;~C67CKm`rc(ijHd4!5a)?n9onMsfNfu zQr=o3NIkUDitj?x=1oRR{qgfWQhgB>vXLF5*Vei6j+rK?iVQLG7R)9G0#kv$miN~Q z>qDmzZZo0#8Am!`NvjOLke*Z)_pdKf?rUUs--cyP^yuAfdwtm1bJB$$O^wn_oi}~K z`R;$IUXwy@C0@%IvCXxOFpE8mjPR%T#J&KH)i(1<8rbd`ZtK7$f;2d#MDSv>YlDyl=c*554qdRppA`4bsv@2k`Uh)~C{!HXJ@tHe$D~6)nsER8|$3=?9S)HOtVe z|FO7j4>b+$mNYCPp51h4s~81gSRo`H^zmH-7#(=%w_qn6CQD}2#R%+eJDA7~+?m6}chlf~{e(wKw0Fk9 zXj|d~liozGrPJc;a;EwuRvHh%!od+a4oBwTkOf{IF$f- z5yCmTBcLuO&uZ(NZ&~QY2V&rQt{$$(t&GF_+H-fRIMWKCnmt*qq6=kx|KYAdn`eFV zjrZK8xy|lo`8P>ng_-(hPJgKlMHNH+Fo&ouVZAJw&+*kCwUeb+UaWqLN%{>FM~963 zKBF=E@`2ZNC*k7o6P^f=X7V0VSnw5x1CJ~F`(4i&tf#%l+Hk$B-0j^~9CIlXLvm@~ zux!sWqmf6n!9GW;4U<&uhuxg2a$pqPvj3jOqUY z(|n!V`Amqm1Rr-x%T3$ON}wf=YI#4(k%(gw%)a5m6MLZU{@HKS$`^(AsfQEx@%XiWh!ZOw%8Qo z89+wm;c_+$3*>9{=umeDpDx<@d&P8#X-h)z8S2e?!*6)ixvh%GQ1_BP8Gei)QxDP1 zcqjBy*wv-=J7QMq7FB%|;e1CIS{Wba@A~DobM*G~_qATvAE-Tx14rj#;t8|Ik_&D0 zMZmHWh3bURV$KA}G_j**am}`1PaYYGOYqTTKv)tTe?JA8z}?vxU`l-NfENO?ukz@1 z0vZvEVB{%hNN0>UN-3rgDi#$Vlg|y7aJ6V<89Os0WQYDIIBRUgzVBrK^Q?Fx)n?w( zR9g5|SsW^Uld2OfPofqy*qeDf(=vlf|!-+1c){E4K1jYY^w>BqFzT}pKA5idEnN)>- zw0BCfHFd~VXZ9xbmqn8Zco~CsSlXk)6by|GDh3j_pVt$-uYnj7wU->s4WjU|E@5ZY z@whRU>$^uxm}MUaR{8W9VO1PjiRq@xdZYa(BK3n#f~(K=WodI_t1Le?`;TDU-)>Ik zirbz@YL(!Xz)yRjr&GMz18$)15Q12_K*4k%kX;HV39Sk*%$@`($_wOwP1_97LB0{c zD(3ZBZxHj?9@@K)Itl!)oaQrjBjz(QsI(1WD*h)jeT70sZcRH z#55+{ADF{H8MK`SdLyYH2r{4(V>ADYyA07(c%!S1SlFPP@F(Zi@Sy5 zgBMM43sBq%1P|^S+;uONnfbom{b%>t=h?sRa|6je=bn4cJ@5PegvaF^{r6^jn99dh z?!lVOqd_CoAEjEKB_Z1HiNy$$%rxqPWaNU-Kd2XPr9<|pHr!KU+eR`EH5n_CLEo?h zhyB;z3x++|(5(Vc4~C6C{@2Nc$_04na%GJ70H~OHo*~U_O%2jwh})*sVybs@PFhSt z>e^KlL<2-t(*$a`;c&^CsY{39Z04wnI`yp{C#qR*6R~*EH|R~kre*vC(=OGvtTf7W zyXn}nQpk{oLl*Bx5}A_!2^!kEa9y|K-ka?&csN#?HB!NoHII%o$7EzR^JQ`q zmgioOz9t3CK)!gfc$~PGO-BOv#P^fWju;?krtAvFD2e9BJ=<276%_4qmaZhtRe zjBD)d?g0Ao->@Mft-8a!1^@}hx9~f$1D+$1{wrVxbO8%>%-eqwIe*j^-siqf&`^h8 zMKeOD(P=pg<8h^X_pY+3UkT<)bU#q16Hun@g(^iz+TNH`{jx{WpgzswOFr#@D$t}5|MsW;IA87De0gfRpXG9brFV^uW{ECiQq_2Uk30|>k zoE&@2q6nt7NrK`1!7t3*85J=i7V0Nfs05WQYXLu?C^6N14S(PJ_kD+ z>R_3dz{5&C%eqcz>#;DypV}PPHgIBt!3>X(TXps#)3|bMHqK5MAMSA5(nf<2(%l6^ zaaYVqr(Hx@J?*(}haL&<- z{r(o1i-aPkoNdg}tJDG>W4=UCUUbjiF~75i(%R%>J>^4@ZWfOr{-9Krpnkj3zn1$@ z>*|G|zkobDvWP9IlwKhSl`drIc^|8f$TPa73nbZ3#CT&^TxwG@0^nSiUu23~mkEeFOr%3jCcNh4`is_-9_2F!CVlROFJDZ=dr=ufM&? z8-4MNn~;{3;&ieFA1`~k2H!mIrBR>MP{0eV8z0A00oxrKJOzx9vGQDtG-ZHkK8rMn z4M`+?@rOqYqW4dBX*tU|b4hb@PzxWKXzfQ`3V_~rkI{pbdGg4`eOYcUZ60z8g0ysS zW)RG^I>`o@;?uvxtCI=zaJgsjWx-*z@}50i4v%rh)3G`>;QfSM=%~Me)sBG*)`NNe zegYD93a&-n0d{x;lOy)9?{Zv}67~JxNM{Tl@ym~UqAkxFVcx`laci9OElLUfBRu`Bdo0q-ik{AAq)YP(>c&#jo~H7T3Wss*^nLRbD5+bLmi?9;0oil1MZSuTK`|FsnY*13rJx;;6A2 z_@?Ze8%Q`C5Wmhot9E`wTflRkxg z^>&%Cx^OpChU}j;Cx>c!VPlO2>o3Dj4rW#N2l(tQe7qgvcRj}Z*>6der00Fcd94i= zvI(KKl2K4O1GhVS04!Ektdi_fZ13`ufJmn-v*U3P*&vTvtfE{rO+LXK3995>gb|*+ ztVPorxwpuDN(Tl;s7#6ZyL$p=W@_jZ?#TW7@gxnH$>&B$Gm}^qwY__cE3eE-v>*5Z zPfYDS-UL6@AP_Lm0tM?EX^daI8wgKl=C%F`JTw@Ba!dM=+IxbIVwFx6T^+yO(E3|q zbwYZ!>jP4gP3q*tPb8JIk48v7UB+ye$`sXpO%e6BU({la6O~w6Q$*X`bPmde;A>K| z2L|>ziL|i9s4W%90L2Gcox@j&UFTyN7d2hr7I%wV@8Y=vlUDk+6ZuxO<#E2UaJxRW ztbs^$N|=4wJ|iN-FkrK44jeW4 zM7G>IMSRT^ju;RIvBq^8 zDx`KCl_%ve)g1Pw+l_kt#(tF99CVwwUL$k_>Q1xJdVQ#tm_j(S`9N4xYuGTk095t( zS_eIAxAUyLTs0A<>A(grBN7!j*BbojQbi3-*31|gnw4V5K_UH`e&@+twh+Lv=1btj z>iUs(b`B8Yq}p*b`4$5W1VMUaOH~{jrb!Ga4rgDRPhe<#P=;3@+wlOc2bNLOsjBZY zy#Y6TXi_IG21Vj18a;(Io;=$1cC+J#cy*5#D&*b;#^Jy(u#eCxMi5_{kY)|3Q>!K+ zmgl6TD5IiPVR$sq=aM!%e-m+reE2P?l5Ns>y^1&-L1kDE7wSpmF=%dqBMmg?&u4H& zo9Ie91Qo=xwulhF0W z=qC=!-s0=r&!GmRp=X^nYujhA=!iq0k3<3aPk69JW`?w zM)R4H;4v)NPy3^6)q+VTrS?(Mac{}dA@H7`oW6MqYOt4r=R(WN9%RNBSiV(5YZk_{ zJvwG`{1}su$6=#hRD`&{K8ic!SP|{Ll@QMCR1uB8$d8jN1Yn+ptwx@O7xza~Pc(Wi z1l~R6Y`XrGiZ?%Wi*T2bCMdERe^jruYamBmZs2`KxR9uY&J-=j5Y_wYtC~c_V9gPq z@a1OXs15R%m;J*S1&nIy1La*DubKX?S<}QukCT-wyHay#w~FPRJEJsp?~?)-d=psD zu;340)R?X^+P+MW?I$477i2Gi`o`m~>u>#m%yG7h1vF(P?XOpgMEV`-fwH{crkvED zOttOR=fkpeswe?%4V;l&-Ea*(!o=~+X0nobQ}NWV1zD8cYG(a8OkQcC3bT9~SKBsv z2F-K_Pd!m+idmBiw`JkdF#R2_s-^bE3{udPxI4kEAfoU>{i z<_~cp>)par@N=UlZ$Y=7-vkwW^vTX*#yzjwwPC-l~?aTDD_ zl&wRaWf{0F0}{_^eG0W>|EdN}-6j;~eXvK>S9__uTXI60X)b}_f_6zd<+Z}tXL>)F~CR4s4i&u)Qh_eNmFennM~?nBKx5Oz2$?e>+p z%}>SZuL_o!$^-{eA{pgR>1j)frAT_d?3WAn?DJGr*}PG8eFL7xeuF970BWKl_%jT3 z1E=DFnqs_$#fPUNJkq&r=$yf`<8P(NpazI5MFl*UWm99ow61;2Lja-j-Sn-seeJ`k#P5S94Di41Rf1{lcy6#oE$J-{4enW(+Lx zeFu(QtfS<21I1VM3}`##;j3>qS?;drV5^R$$DC-<$cLp%5TYn2}vtr^nn2%Hg@?9d~v;|Ll2U zbh%*eTP4}a&&llNr}N2|I*u~{NG*U=_E$W0r3jtBVKtOLi*&~q-oXo4d6I=#%DpT; zUqy>+x3ApVrnd)Cw%zB7y7Png4hJ#-UNE6XhVc&ezn*pWW=i_M5lI^BSqzYkDB0iC zG3U>~pPaqI1^lQk12Mlv5|t8Po^p+hUP6qG^B(@5e;#(XSC|J7iXsDQfSW4A->zUS zKOQfjL9|sbUmx~@^(7^dJj|(OQ#1-|ym>Rb?ycY8`><@U@~qbPZr4{&-F8nhUi<_) z0aw`{Z4SMNt{cue@N|=QA4zK-Ki#NY+jzREdq@UjF&$@*p%Hhlg9%x^TM{T7D`-jX z`eRq?U(;lbb8s`;dZJC!a&Xn?7&EkQQI@yn`8ZH7;B)%mk@Ud0o5-d?eXZa{dpBEe z5I8X|g3kIk<@^5#HH=W2FA%MX2*qc#8x51A?Hi(X1o9nC-+1)oyX)T{X*-qT2?f$g zXATMq`-~$26OPd+o&WrLbJl|K6jLt|kpE80bZ=o2g&-^28FqtV21-h3`!G#!rx$c?F`o-conMn$8-AYNmK9w^Fn z%Ypd4({=@<96o!h&0E>gT@VKb+Wl6Rm^@OkK7agO?HwpQ05or8(T2_O=tF2HqQTe^ zT&nv4WI099hgv2hz(OsnIqWAS;+<^x3n#3he3)G}0JRVaC?h5Q^_Og)yCkX=G5(A> zWogR5JSTp_N7S*lSN^9+`(*Imatatib%s{BG(gDlcT0AyKq{*8GZl30lA~hVr8+4bL3;pri@ zf?(T#8_aWmK-{3NOeT_@u$^iDSn9)|@|Nt?OXOHKI#RX8B*H}FS+P@YDq%E5a6F?h zSCMa9W!n5EB*R>(=rhfimlZ_i3R7Vbm8O=EP^y5DwT`4uHK@Is?i+by()VuFb~>eK zesi2UN!Hj;WdVvY{l zB*MpSuZ9OxP(EO@-%eDXfIR<@~vBJ3h-!(~1gvqgC5n+XwA*+rttA1{jCrjM+W@QblTm01gQ`R_-fu z08!B8IG@*eY*bD%^>ApA4k0!w+4gjMUol9OzQY*g_}5F(xT3kP-WXFY@9kzV#KBG8 ziIamRmcts26i)Tys?9o)Y>%%})Q|IK~ww z1Oq7wGmV_L;QX?R3axw%5+b7crKP3C#l`t~fNLl&U+@;7-@EVl&#Vm<5WC#Ea>xF2 zzSC}f?%=_&em`X_InPXtC6eJh#-DPLs$cKaMC{Z>dj5VK#;}2X#SYA7TKuea(V=%Z zyfbYih&msUrWF!iv^ByZ`;hNFyL8?L27~L)ALVzVrO&IAZD@2dg;v?35{+? zHw8%rWN<*}?}5pfvnrdIf+C5=y58_1-!}IcF8EBebr1)ZmfTPu0PHSmOmUZJs%gco|DgD}O__^8&b2+Du05>;3&|nabPq+C&H$ zZ8r9)uWzLalNCCy;rs=86=mWS54XS4$e3qV2Pk}+fiZbn+cnyqAd~E{r^>gKjnfX! zr8XvNrL7$R-ii+qc^XA$B+^nlbY#SA@;dD;$xsieJ>DXC$_gqV2}qJSWd&YHRklLA zrXTY+uIj84s_0F#l7)wt+$_7cG*4Bn7R?O8>U2)92|XDd?<)r;bnoS9&%Wvce>E$hX2FKH~=$s*jon@F58L~ z-MS%OncUbwJO-dCh%mD=EQy**;3BA} z)_mzewo{7KH7dzKgL()zK>uq#YRJPXXSpkNcdZC3JsPVsSf{ynZueH|kNEV>xndUe z(sEPhFKy2ik<_jkv!#I}f!804(;JQEL4yV<8E)|r#>_s2 z5IrlU-IQuAz+tG2#Fw>-pmI|>>~RjOvsI>~3Q_=Iq_0%`jlP9EZy!-^)8Em8(E^yY z=qu5}E6AE{$Lm~oLr^1_X11&up`$ySKr(>zPBE82NZSwX^wW;heu7+s2T}V|^?S+* z*o|yyy(;4WG>gN#Le3}^a--?h^1L1sXsu*Znmke-ujFAnDgWe!;r$mk4_C!)Cj}&5 z)87_%JFsE5yb;yK>m$j{xsJk^tbJqB=D? zM*s>=crwCd`k5}R_@XHGgn1`Q>xPn5-i3TJsi>vTKpjb-sMd4HLs>)x$IZk)Gf26* zHYrk~gbX}q3GqnIHS9Dovvj5|dE(@0;G%)`o4OGc$-;<7-ati7U-TRD9o_5=7yd%7 zAX{R*>uR_<4>~b8bf8)m1B-`QkN8w?CJi|~PA+k<6~n9iBM@7TmD{7tj9pvw*Y=8! z*G+uQj3+qyUiP4+h4f%7;(1c)NC-sNZKL>G6)bp@r`k!1v^z}J4z+{!m+K)rVRjj| zceXFFxrU?m9B|?ex~;Q7Q2dbha|^_jbgku%Y0POMRfY%dc{!}3b>XJ8XO&CUs*64q zbMR1TKSY7icBas-F8YkYc98&2l)RB%xT18^208etnbhCs9xaP5#`5^!j-7PY1*Q=| z@_GcS`zLjL7^5Q}6C;{KKL@$JjG!(^9qGjUrbT?b8g2t#uAX$<=K>m1bz_tk6Vddx zP@h-C3L&C`Ye8Kn&np+Sw}1UqaF_*aEF5{xD@SJZFpEx7k+U{ykD-{A)lMa1yXFmZ zQLl%2;@J+qjX_)ACA%=^OSb0Oz@_Zj`$N z723QDV46X`HoQ&Yz^nc=TWadS3Gf-Lz@F{(D*>C$9wP4Nj+oJhBo|lqUJ$d#Xf^(`;S7-m2inM9wy|okyh2-`h%HntPmD>-zI;j&os6&C)n&_AJBqHk z^9w?#1qcazHEfjVc~c2q*|tAMzLZV9)Jh|2)~Pb(LH9!~0p_0z6oxroPkr+NP|B^9 z?o#!lNWuMC4_)GSSdIGb_BN8Io~uD^QkU#;(q1pK<{IvJ)XoAj*}mN09wH3i7jv)q zA||V$eB^nV+SD5Qsp(ywYHKKQT=)_fATw6*U1to3>7gW;;DBlGgRDlI;bD{mG+;=DTzRu--v8bZE2BYvO{xek$AF$ zxvSeV#T?3^(9&uZ?wH~sWQhNL*xsL}Fm%@Q=IiFat90!?r6J?FyS2N!_j|tjdAKJ} zHmTYAz93LgWyybkUs}I%ZJF6=Tg>torzBh^up!Spwkn#x%G2GVYXielVAJG#==11s zI~k@|{#Xa&!gd&06HDkGEyfdnOT*H@;^V(PqiDj1f(E=)wewoPPHSA$l3V0Uxp8Ot zq1B33EH)Av`Si!ada4Ojivnte6S|j*{I2ZZeuUSBf@lH9+~v1#3Iq@@JmxPQc>r&0 zG*^a;Vc$e8RP3yl6vSI&bDrstQ);8t@|e}@XUq(MGRe_)BS%i>b9O`dO_nZ~#&JX; zo?kZXDc70~EW>sdg)DgU|kR{#o_1#e2xk7(k43&529@^=aao)O`Tqd98L!gs_+ z)xKA8EU^_3h5`^tev*G;55O#tF0>EwGZqBSerbC}n5z5P{TPZ3->VV~02jvj8|(Xj zfcgFJ3H$5(3JXl4c56>7S&wChjz#3%Mp})hf6(8A5A7rdQ|kv)6v1oKxjKj7WCY{+iznc{^oWB=dT(u@F4c% zyO)x6m)P@n_U~BdXn)S=H)~C(eHnRyw40ll3PHG3oz{6-?sjC%{SyEK6b&5qP&!u2 z!Cv#yW-_QPho^``@!RpfT-3$a%b0LstGmU&|1*+6Pr`rq+?=W&Fd!zaU@F=W_Mj37 z*2wBR^N{P$)~xpQ9wB=}`operJmOtgUSt*rj# z>p3o>@032W3-}(dm0(h-6RVc9?1v`>++Pl`;r-MS1lR@2pZ9ySaHUbjLoCq3p{X&; zUAdZUp*$bdPEz+7Pjj4?81&DXRj!rG3mR{fionk$*p3z*hg{w2i(&~VEFshDwwSD| z-Fac0Cg85J_Kl4BWO5GCZ-zIxrv+QxQ8GpByafHLslXsghf0^?W@j*>hxQII0@+H{ zQXe2*c@BD)(S)VhDXc?8M7?tmje^gwasOjf2D4|1&x1XLH*@NsvUQHZ3Joj;3N>-L zzm*>jo3CuYE-vzny!|srA_Ne?_K)U51OHbRpup@U(05z@*F9GOUX=f65d&wSUwH{& zCkEgEu3nsU|C_1%YYP8=d;IqjCXlG16x&nlp)hc@kX1mjqRth-&e`O>$*b@3)4+$* zWu>nB7XQ`Re{m92=%m3rHUC>@z#j>-X{P_zN2*+neAlz>R>=a$wud+r_j@LA9nit3 zQW8CW&de+~ziIX1!v_TN1T$U#QF5~C3JX-k1`r#VcQ$e}Lzl8Xic34>(OhLH*@^++ z2;eIzVU;n+)W6_gaHvOz-p!ojr>83biGqmF zn*2Pw`ubq123-^Dn49+e)fgy#v<1K6oTGPKen=+@Sgr90>POQ*eV)2CKG_`jpl8u< zoicrqcx*Y7FP_DY*JY^^uC0oV2ljt|$pYXwxg=dc_35w*)xs~6dFfX1y06cp$w)0bvz7}VNtD9JP0nY52cTd^g z3}C*lW*Umk^s1!U94siMw49*{rKl=l$V3=3WIQT}e>31HP zl8nNXV9N?-LnC=VSwTrkE#w-lhOe96Tj7;~t7z%C z-u7*^yVrZ#;aJ=zG>6iGgWeVH6Htz*8twq0*X+L1op z2X~S*x4jrBWr4MI);3ffiV9RL#mI%$R%{=CWP&U3jg;)uvz_(_vnH3+mhrJTRF!`D@|GZ)i@HOze0`Ys`vt916H`xg1u=;GCMlXr9QW$wfub?`y0ftnTU-C(Hv|2xWS-wK+W8 z!Nz)z0@T1Kbbp{k2hVfs{GonN_JmulgRV}UYx{t3QwN~d6j&%+aFHl1K1g{D(Q5|} zgxMsGEpbi2mY~sm+OC4PnJySHRX#!|xM?XDfGW8#2RYw0oLzDUa7C7C0os7XQPq!d4%$Qb z-N6!r>Q_?PeVrM;d+2-~x}=l+p6U%xJEz0JsCiUXJ(mgV#S5@qcU+*GAAdIJNnWTr zd9`mYqVMur$_3}1nnQ>`5v$R7-EQ|EbARICK&XH=LDZT&_qOTtZG=nhP6E&le4S16 zXM-to^q7HG8@YK^a6vJ5_KKObn_MwN&1FyapK=7+akL@l)tWpo04E?6?f9etMtboM zfbYX>#V=4!loscma>tjLGTRvCO5$SIskPkmP%StNrth`7vZLVF{sN|uwW7Um>z20e zI51&ITx*MftCcOrZAIeXGzqMhur+`2E6=6NTY)deWIb|+>hzm_6hR;mu)_~Z!PeNZ z9>}(#-nnl!v1Dg(Qee@J=jT4X^6m`66~Ud;lN)^MM2i-XnQqdT4THS{Yn1CAr~4B* zcAe)^P`PALhCIjW+UW;tUUhF1EfY)F?7uidHNROZvW$J5uS|&AcL}_xI&P7D5-`Nh zQWUy*sP8dzqO6?encX1=&qTzI-)jeY`3~~^E9dWb^n0~ zG<+4MuWomsTJF4@BrjL7l-jjJiHOqCQ@3lQVNYOlHIX)f-?fA11;pXYO|a*=yq!oc zjd-;5DOsU7aZP{U!hB|qBt;swtqGk(3}!}l_BqbgPDhWic3 zPwdt339WKnygfp7N;d9KX*kEmEsj1u$xF z0YD%4y-doL9Pne6H~i)+(U9K;0sgWd&A?T3E+LB?H0P%XK?y7Y>v_QoMel@rgB8^A zy!86GeH;i6ZJclGaSN(c1C<1kk*Wy9Vw5kC_r%#6o$;03|J$Nb+h(!P{_nItI94p^dSz#3FNSQI|&U;LO{S^7354K4La>gc><; zUk^%4O92Io)oS0Tk&JY7CeF@BTQiNt6-61qVBkPvGIUFKm-Kz` z{r-G@-|s*7u66HP_YW4&^UOJCpR?nf*WPFEU}Z&VTr3JKG&D3^Ss4jcG_?D4XlUpP zkI;cH#r(oJz`uJRRi(wyN(QJlfR_j6?-bslp_NBqUwyy;-XGh`=zK&&!~1#ncdyef z&jbxESyEQwow}RBPSayAjn0&{Ue7e27`~J~`Xe)sxg_^e!JX7>!IW$pSw(#MHkWOA z#?Ve`W7qm7`Zg$&3lm|v@eGu=lk%Q*XIPMA8pQSe3G@q~47bx1~7ATG?Id2+t9NX77Gzba`4yL^|R8vz^ zQ7Jd>43D5I=lM8^v)Iarh9>iTxevq0SWdlbl&>mklZm^*Wrr5S`Rb2@s#jmC;?dB)Q?|Fao0^(tXI0zH8)#`s_k>)6!o!qVCn#MEzEz~yNOw0`1%5i^z`&JG@M66 zgFeF5r}!=%PLA?Etfr(S21pVR`^9=z#4OultapA+vK~^v^os$;O64Ls zhHueiWHXf^F-%Hu4uCqkjEZdBebx6U7=eFgMKEYwbWfrbDMRADr8^&8@%jO=UuO4% zj3L-qz4O*G`bt>yjbC7z&cS~8YA0o>!kf9X!g{|oMZL{0yXY+UaiJ6wS*noZZ5c8& zG?RND7@OJ#19|mHvifKRH?%NPUIRdGZ~thhlCRt}Qa zZjRkM%deZ+uIoWYuq5<)E0g+mArSjE?K#N|#AhSv^3ry8+OwDG=h5cm+og}e-Jn5k zP=oH6Yu{@@(|F%)udgIdXBCW&zj7ZPWa#;5g?s62&_?Q?owKs-Y=NvXY>$^9%tI{Nj+=xo)6)OIt*l3ByI!MFXhg4w>jx3AbZJtg{(Tz7;cir?c z%xal-tH#eQ&1z~A>~j+U^d?g>G`sVY7_*+o4|IUIj6xd)HP%xW8h;j!Rvwk?5LAVL z-T_KVg&9$ix^He>)Yc}#{K^GOo0La;Gu>4nG@7;?MDTJ~-7D61 zBJv);l3oJc2Ty-C+V;=lm>;Mwpa@yWbc<U+{%I9><_L&LXL_o8 zsNDDbP&`aJbl&TzAI9d&bB2TSV36;bpv!7sLh7?ae~CEFtZ1DFv7~5d{!D$@aevN# z<&+qa>24GtgHnGZN|$~26E5d3@$nlk_k0>RZxXg{PGt5bsK;+E>qGfU_s$KI-gq?a zSZo-H2bS(Qo{uemdR_n2NNU(v0O{|eq0em`&>!$wD1<${@7>_cq83A$7idzI81XTF zy4FHMorS^Hp{TqMyk6#ndBr8iE~j~Jk#N+@`cXr=Chxwv=G76Ifrtd2K2#yiz>8aS zU{|eycdWcD$P@>=l0+W+uNh>hl3*fyXK5OWoEkl)!1JQr#()rtfr4dY9kw}KdvRb2&Hm( z?5u@my~8VkZiwPBaZ;cUB6!WTL-aFKmR+Zi9*)fTI23IePZG<5`)!>|DQO(X-pp$3 zv;IgWOv`OWz1EXTt{DD=g8cZkhok-G&E62Bpe*NzPWR|XvcRookr?=k+Jyd7IG~;9DY0hQSr7r=3(=d zl=oa>C|{H7O-E+tu|a?9zV@UlV%tb0?5fQ%s@qCIwJ5OF6=XYR$sBfp*CP@uV#q59~rwRCFp*3 z&ojUuuL)FP0nt?Ye@D$4d_tk4eX?fM2X^P5Yd3>wc7K-AU{?oiJib>)5jPRg&d#f5 zXrEogm7&s3i@Qdr*1YX`Qq7?ENecF~V&%sJgWuS-q8xJ_ten3}dIOR{8$T|;5n$iPfP0c=*h#nnh1e4X=iMnGGh;;eu=>CdSG!b zXZYsxm3tfFtE`}_bN~vO;0&=9^K(HED?KYghR^Q5cq(ysk^$cnvXH=Lo({acNCF6d zH~hbQlzohFUjIdtfppoPDF5&ivrhD0B;l{f96wMjDXz1?I=~Z?huvC`V=WQT+m)4- z%hR39c)Gt><5dCFZTLlQM)+U2!kUdDa%9r^g+-jaDyg+5j)0A z5J4sExu~+ewS^79`7Q~IuViY%$D~1oK(BNYQepq5rY7NJ+q=;M;^&~LxswLLpgJP7 zm*8|{V`eY=MI(Sv_xJZ70aK9oH*-r|8%@S9$H>G4_p%*-3kCq-;kyTb%5D5g=4>O4 zB@M!31}Xiz&&Z4P@bnD)`gQr}A;A6N41qK=A8RYWJU`T-zcR$z+gn&z_;3M`UL^Ie zKBc3#v6?d(r#P6N4fSst-UxQTV=Hcq)DeZci!m3!fBER{l$^xuzv8|Xhqgxzd~g3~ zo=BlMM*Y?$w&<&G>Khd~KmC+@Pg&GHp$;Di>n}!Xy1LeQ9o{LyL++!cJk7@S-Cavt zYl}DDhw@KY3KJ7IdyF-tySh{iJ-?yL`ttDc96PyoKiI&Jg){wC5-UGc2pQRwE~VmF ziin0%eMnJt&ZdMu?qhZ?$4D)IKHlVX3+f#kE}g`sI1~hF5#_{?d~tCh8^bv3G^}9E zpLTn-)-C6^xM}|OQfGmj#6b&keSK}$a(!wXA$$thQskG$LqH-X4>_BTQJv3y*@bV) zoVUhmi3wd1Jl+?_PhXqKC>cTR>inX2%Y?sE18>cQM)z!bp78i%94@CH0 z8E+`DpP!%mo|^kgr9H%dMognyZJqH-!7sa}OYXj$e?&+vTk$x*`CuyU1N3D8PjUh~ zwac&3(Gvgxv+LDHGHO31)}o-GFmvdl`I5=d3=Y*~fJ8rX?0RvVUs{?Ai_%;h^f|4} zE?FH&k)z2j?^0OcicUK|c1i<8C03AAUvaU{SmS$zY9zbepLtzrE+WmlRcF3N z);HUf^=(o4L5P&lgaUJWj;h@<>*EL+)S@(O!NQGCS1xC_EK=dhNzm zC+wIWoz;H#6dUz3Plxm)#+2rjec$$d)ay6esOKdXG0pr-R;x7cO^Jdz;AO`}3mLZ* zO_Yv#LyyYvg3H{(ZPfjUt_G^!@1Pe>Gj9@*X(#vx8i`lyeO|!LiTX}@DJ)$p3yn%L zA*hQ3>E;k?H>O{i_a`#Us4Ht}#o0?sQ^81~)Cg;t>%16Hv)B}e{5$pMEro=&6GJm@ z;I5+0thABwXP&oBu4clw>>CAjAI(_kI5A4Re9wdHDawl_$0qDED=XE^VpH1`pizAn zGixH!KXfjhgetFOBeLhQ!py2I9ilxILpKGSH`P%ZCBG0oJ>aL#PX5VlHe^yY6kj`1 zmGnrX$YbGTczudr?SrwJ7`$vr1jkZ~br^*@e1jwPh3m^#c&bA>sr-d;3-O}ZF|ul; zvID>W6kntPZ%-tqHU_Kc(ih065Q^y&a+gMv7v$&DJe4pCYNQo%VJ>u?bC)KO;0kXn zUw+PsV3-@r4{*FV-Uyx?%M9TB5Lm7UwYBD-9ueJ?_3Dfinb+R$!LBrmt_Sejk1oMA z{6S8y9gU1~=BWc?=|SE!kzpsu-D0Jo3|eM{+}hr=a#^`-9AK-SSQh%~?9O}o9=mmG z+2+9dGHl2iOY8{Kt=SPOEDl|y;9k*EOCuP($~@n&PU#6GBXDZH1Kv4d=B@p?E*!*0 zT5qj`zAXFbc>2*KSG3IdV|*2(&dKA)EbyjYIu%L4vXn8OO6PZ#TaFe8d!7b;Ur$e# zRa9Bcrjo6R%2q>#P%R@w>m>-8DI`hbgor{>kR}hFd^QJ{0Al<)*g8#T7~dST%e@Cf zI~WrFSO`lQ{CTa*ZY3YuP^8$a6gzU`?3R|6=IT`m>dSWz%hfbA-2YT*tv0ZNu)MBE z<7ADag1d4RM^qt@ucj_g8LC*)$3<^1E8nUy{fhYks+n1|!dOHgp9LSoUmE!n1m#EP zDElSLz|yoee=d^mKQij5Vls+<92Nu*j=zGtCpeA~#mGl8SAB>5ycdmwuFoG|ZeFUK zD3*tP%EAeK+^2lKl9;cc*XyX%Rwl6)ryi!BZ?=l#tl#llOKbmoSwO-@pD2hki(hVY zEk~9tqrf=5o!b#-n4fT0CEY{wIXmNaBDv+NGY=7SF$Kmd8Y&Q$V6l6;bKzJDGkdCi zA+t0&zW+lK?TaB957!mM9Rm8}>;uE%y@EG5DVSqgx<3ujQ7v^-tAEt=mBLIoK+cp! zuAHp3uuuzpF{AdekNsGga?DG>Z1hUZH%=Pw5R2~s*ifS8Xg9=FPB2Ve91zXT2ELS1wpdZm6!o$t0YP-L3s`x6 zXKGaxkc)dbBIvl69e`4OEtF&%mOsK90AbX51)|hSP^ztxA+xmX`e0zhZ)Pg2R_#w& z$Y=Qb+;Wi2WnSwxHLR6T56EdE5Vt<3Ih^Oq2$ti@T!x@x_z*|jkD)Scnc%Z8Bl|6yMb7Sa` z;HRM;GPXbnV$$@iB!1j|NJ>xmqa3NnTs^0{o?>gw> z8D4*Rmd0CNJnA!u88GNgIdSG^NA|Ar78im^247pVSZBo=vCfU}@y2%=s zZ#eXkBbxjhGZt7IRi4xc7cXPEG(mre4>4C9yLB)jB(E(6<4LAd;m7MDTNqpZmPz^= z>R98$6X_OX0tuOg6ZI0m+3NOnzQ6`4`pA6L(APJA1XFQd?oIMj~G1fFEw-o4M)X4(m~QS5V%_j_kR6!-(iS1vrol@Qjv&`+k|Tx z1B=gVEXs`jWvD~<8}$qTHPJ$t~t{P(B z_Z!06>^S`!yH10Qy!jXE`wEuQ!Y?w`?~RKF@X`Daj~OCZH4DFlEF}gAKeWODeM-jJ zsG85R^7E&A_7n8dX$a1?4ESx6wa4sdYPGzdx9NK1bMTo+Wn0DdF_XY%;vJQv(hM(I ze?R&~#}XLM@QY9!`$cXQEnLtA6lvd9`N5#3W5f%NJw}lzayGKv!rLc9T6FGMq|-r7 zBw7KcDBoh$(rbtR(teY5tshJdBPEowX88L2_D`o}SdP04|AU35^5N;}EH)6As)|Wx zAse69@d9OO(;)zF07#?%XR45LJnq?B#?s9L7We8FVPbkMYsstNhZyZ6hFYF&ObA$} zCj^VsC@E&A5($cG{$`~u`KbZ@w?V=b2mQAoJim8j{_}l3iTSIQ1~1F}qoqwtVTi@r z$5d8$8CDkGjrRY*ogV1F{40Oz;NV}9y0nGLVoHnJzAT^4idJSbKE~%c^?V5a;6D|e zARej*zrx)<8M<25tDfys>YZxB!-TU_ztS#&6BmTTo%}UTucNIJC{~@VbdBLe4J&B-^huTabWiO1rIQ;~UxcFG#51&GEXowClXeBQJJYud^ zWUwy_6_7=uxNdh%3EL6a({WE#Oq@tn+UVloluD*4nNaG8JnYyA&@n6Tnap$7LSjfN zocIEx(x1Rohcli9G}N8NHLf1?v{Tb~DH*Q$K8T{aIKCJLTC5CZWsu7i@_<8xkyk~* zbZNt?Dhbl|2m$@2|!`;Szr&ND%)?&Ymb<+pla@w(wdy6|cQ)tTVN6!}#gM z){6q@^83_b6jnvsZym>okAFf#;ft}-gQ|srZ2xljyO7js5$0DWbxUV#!e3kLDBZnx z9(~)5X4`ndtj?qcf#`Ip1`*+Wb8g~;I`hA1OP#_Tbpcee1=qE8X!gv2g@#fE|9T_x zj)cHGI`0J`?W4UgY=tmfz)$i=(UP>!;cHS)HXdZvkhYxn$YC5|uSQ2L?J(G>riZ+U z9h+Po?hnJ|$~yK}*PMwZeFq6_8@uy4Hk4l6`3YyPzD&Y2=?QnsB+2L0Y@^3(ebl51)=?;xEIf3hW_g|=N7)WHB7 zOKge8fus`l8u?(sg8`l|<%qF6AP*(eS6F{meJzp**0B;+AN-k!_|_Kv%Dk4HjwgIS zk8M?W%9EGd%f6hN!Ef@`i{BxF%H*4AFVb|DO8cttBRre2gic{FwG2ndfR1qTnXDPh zeUR2u2u>w`F&BgcsVt0d1?P$`Ud1#MuA+ECn#O=#>ErPwK+&dysi>wPV;1XYU&wob zE`RpKTC@60nvp?1<#Znok?>y%vSiXTjQtC!!NIU#(Ty`vy;xFV7^>YhKKhVRg}7kc z|BlVuadJv W2DZYMWQ4W!Mdn?-ABDZ)o}WahW;o?h~~r~1M$^t1cb%OqC@pO{8PjF?d>j$&#sZr6QDS55tDB}AdzwmagPA&{ zjwgc_o~po=ulbzdex+GIN+bL;y8caLL$=R#PX0xx5hT*m2t>liQY7xH;6N+fIkY%{LhTjRDQ;0!ss`oswqurnx;pw#omJesN0kx zAN3I;_I~L3)m%%<%Ja832NB{aM+qX{9wWL$3mY4|jFV2w_U;QaWQNHnfj{avBTH1@ z<}k>+Z4gE5(@N&h$10meRsTUCqq|zaJd{-*vS9q62>8{ne7s*6fZ3|{ZRA+Z?!5US z(T^tu8im$|)+04l53;6y(Hdz%c6N3yYHp+D+}#DbS;{4*(!m!slccp1<(t=Mt5*x| zG?ijIP=Gn<7R2X^?RW|NDcz!om4^xWci|+#iGu6Yu{@W`2jy&_7yMp%My_Y?1k6UfZV*?$kzR=Hn zM6AFl-$z1dKVq({y))?VsvH5L1uN1*=(Q{8K>8m5t8|yL~*>kzR^)! z7yyY!h|%%!hyN>1LX9fjv9V#=-0JRnX8ZZDmpBf6;6js{f+8CK`CUvWaMdgE z9C{OoLLa(^SRwKF-lhU_>{`PIJpLTokGcN2lJRl5}&ZH0w$}BC7cqVoiYI@ke zZ&X0W6&lHQ4=w8f*lHw5Iy_a_&yD!5BaWj_UK39dMY^OCdp37E-W95~Qx)ZRS|WJNA6!8xvYp@5R_MNgDy7x} zRo|%cMdU@EoLM)%D`9u=_pGkQZHwPp%=IvMx3yog1L^ZZdJ%yyvx(41;u+TB|EeT zo+h)h%c&}^@hUi5v0r#|CY|sPQfp)|>=9`t3TwNigZKkIgHuMWmBkBk+Qgwhboxzj z%(Q6@wjY(+(0;+!@?Tn;&b+Jb@8jQb_9@gs6(T-+-K2)DXA8wLIYdiC7;%XR5hdEOSH%kDOL)vID07?62P zmoz-CQG`8KI04v-tD!Zc;(mv2S8FRSrKxF0pAFk?By2-uT*tcPT6Lj+n(xKlF$$K6 zuTk*vND;q))WT}h>wO8c+;~9dkOxanEoaZ|Lt@(&mOzeWaN#L;=$NMO+@rUHr>E%G zmprrQ`wM>6_r`v=iH;-O_k!YSdKh%4$}@giEN_WdNki-i7DjX)V%C=)*jpwK({J>J ztdzW-+PScI^&Bj1PdNnhrtVsqIP6%mNVL<|oPMU$k|?ZrGidYVXK+t(F4F?ClW4ZcjXOw(>GpTPkE|AUS@`!N2HjT$@Y2%ZH ziAo{eiPwZl2;*0P@9b4>EX53Z5L|A30zdrm;Y=sfZYlk$b#S4(>_gq#dO;47=Nl}x z6f=e&B+?NzIWU%N79Ll1y$@Ey-(k4Y9w8PfbZ1q5?$$%~Wob730O^MPE$XJK`yFDv zq`eCrIdhqGO_!e9H#Svko$NNc_SvQIMf?gcQfuoZuXOXbo(cSVy7OvI>HRmnuai-k zJ$loIHtJ?&X>5&V)t=I_Q@T%L3eY6&gdIc9jE{)-6mpOEHjlr)j@N-eCPjdGH zQS~A-Ii>^Q2IWbcxtM&mJqJE&%*8+TAl*cWt774zHN(nm@4Qo|!9M5W*IVu<5J7ip zu~@mdF+)onJnIS91;2iMY3(m^?%wzJtTu@&z13eIGE%Q^7*^Cdo8dOl@2NK~Hi~FB zmiS3lLV`jhEo}^xU!Bz28`6Ck*HWLI?~sTV0%zr%^txfSqc4`HHE-YI zb{L-?_vpjxm{`&%Ps@e+uaoMii}1c&zfKs>1a;z6r#_W(6$$?fOEDG3XvP=P3nMhH#SKvex~kJo(7B ztse{5x;ih|QmS&BcyNxiOQ3xFx+@J4^xwLmww5>PUu7xhPOfm8CnK09`RhbpM$9xu zE2?b0EH-)u(e-(qRg`xAjc+RR(lR04RRzK^+oL9{+b&qxOK$hW4L@-y47f@

    Lugmb)nuw_=+9Nia>b0E2teJZ`GTu3R45-*0Z7dSSR-s;^Tq z!Z7$Uq_h6FPQPjhlqSxkLGQOGFHH{*pWk-=@zsg?hbjMtsy>j}s+~0pb-H}}DjeQ2 z0Ws#}6U;5evRJDTgLyg{uua3QtTy#4vQF+b_jbvZ&*x95qGF|Q8#UIRy(~^>df~$T z8JfWg%-`lZk71;N%cLemJses6y~FZ4XJEE6Xe7Rvh24M*L9#yj(Jei1e( z>Rv4tAZxS9`I*ACpE{};URIHrU)2=3u^NQjHCV|W=Z#%_H8Z84BTx2lQ6E(G)l0>6 z^;WdlT9{N}L`bae9w?kYj47J$;KERCPqv+5?pp_&zz$m^N{0GGkM)=SJMR0)QZDq&6yCc#Y@CpPSc_ljo-dGB6+tuwZ4Oe|luBz-j5#;h znHKv;n^qqNQZp@b>Mt5DZ5ALzU6>mx*5lpIggp=ESd~rdD=EApJ_BQuD3r%%ryA^LPxWtrHLd4yj zPM+3?q9U&c0)+gtePYDq+V2?iau5I8^9YMV+)|{3O}m39m+#+qBG{&U-+odeZf zT*~$cuEZ&X`-S3a}`7#%(2{MsE0{<{g+s4FLW^ z*)KC)r^?Q@LE3#g$qCNCh!d`WiCD=sjX}NfLNpYnHLdX&e6?&bM7u+#+SL@X@HDsr z*vcyHLiQ|bOWbD7qpj5L&f;<4qnHScyH?~lt8wq3e;+WvoSP~`{(-OWeV)dW-jRO) zGT!k2Yts+%rvHb;2UTddZz0D54n96UF0MXsx!40^yMO;aa61Xy$^y5+hg^3cTl7r~ zE7;23o&bz}_xcp`^zKR>4eg5d9K3aLvNc|!|MM=n1h{g>-@eNiKtuZ@S-=eX=lR9a zd$85duehi<`?6f%?iTG6&R2EKXc+0h-=;6rWSdbx{_PG^SAk3n-{qQ$t}Zm7AT_r7 zFUjd2dPnO%VEs?$4p)RE`qoBn8mUoeEL_2QA^9KDmZsVV`r znQYwXOEB9w5L5UW|9SPn2x?MfPF7wny#6lj^;0Z8A($<;kJjr=F6@mbL~;-GJizD^ z3Pr9ze8&Km;5{(gw?5ivWbUY%divaO!d|rm6}a~&d8UzPD_=rB&YUxHf`9@U}& z)j4$96e9bFAWt(}@jm?rrBEokIN!^7c7om(Nr8>SAFC*P zDD-TtJ_|5Mr1&(wagJ<48N0#pYU*qQf{EB{HlCoIl-@~J=AdoHY&j1GN9aB4QZ2EVB4uHCpN7CxOAUSkegNub!FfO)F_sBJ9EoLl`lduW(%tvd5F_ zveY3SUXH!|kgsAL42saO%zu^P@)Sv~XRTv^e8uhn%;+{Ex*{Q2p2705)Q#{bM`uFT!`MMMG`qGle=V2M7Q8i7Q`jl=2XFE%XCeIE zv%hI&!2II>Fc+7;t%>0tGZd;z`9?MGW*gT?@c3Usm`@%ecy@IdD{ss?{2tD2($YP2 zm-X!K{m}Za<;TazYFeFD8K{uT03M)!_5%%l3O8&M5G(vgQ8f&f32JkM+lbLyw2kt~P((F6Bz{y)|?{%M5)& zYUt#%Dy$_-$P6L>AA_nu^vqz9A@x=13nhGlH{(gvt7~HY*JhnI7`VP|ZJM&o6H^Xn~n-i*qQHy3S=~8A;+kj$`-W8D-N5d$&hp9=_jXJ zy4{353Pa3X3{k*hdT!@QoW#^H7B4KWQRE~epOU8KZW(Wbq@a((kvKj_u%ntr$D1V1 zG$v{0vnWy}rbX|GVTvNdHx9{>Wb_ivd=68Mu5vCgEh^@Dq(`e&CF6XWy}JsJp*mv= zy$`r|qM1Thn?+pgcLB0&=sDXVv>w`JhN}7#8&HE5UaDa z$2J2a68oWqAbF+qcj-DkPg=Yin?;seNM+)fKOg@Q1qS#v$;LMz_|tkfVXx8Qv>mh- zZ)29WOtNt7zP|lQ{`XhIH6&*5T36iHi~N21zv;wi^v_VLt~b9gON`k15N@rpW55}P zu;Zo@dcEH+5auh88zth4EUMG^(ny>94ams0{e#RUnc+^@ib!rC9qmqksZJWy6$8Fc z=Xb~u;q9qsJ5W2Hut)mkgc3Wgc27{RKJ0SNTWMfk`*~~}y?ASf{zb-R`Fx$7;{xMR zTT@24wPyN2;gcx2av~0;>u`Er6;n4Gv($9+dHOtU-V>E`ScmTJ^~%V~Lv|1Olm^Zs zs;5F4T;{Z)?$fl_sQ}|X#eUaNVGuPV%&y2(hdfN=yq$cm_|dA?6ByO%(R{yd{$wfnNY3W&t_CGN|2J2aQ`PE?#> z9Ox3c7Sxo3p(+itmp`7V0OcuYFHBW7!2-(|Z-Wh>JGR@m$7;@LJ_V^Fdv00pLf8kW z?UIQWj%9~T(D|+eauK}N?4@gBM(fdy2bE`=FdjV5u%s$!Ey9jM*^fWj$?dx`uoBji zo6JiunA?kS?_VyVBTDn7rdRzmedU~QKOJqTs8o-Wjq}%59V|iroIbJ>zd6zpVDuI%Pwqy7X zK&xVfe(?Ay`1=2ljCg&lSILwU=&l!8C-P7r~?5^xI&!>1+c=qHxcBq#N{)eZSC| z7}5CArg;d1bGGC<>)lZDxGx>a(KhR0Wgtg%3irWc&1$_V#VK7}!&2&yXL64N@PU1W z5c#0~Z|?jHefv?3U_#x5x?G+gKI^T2RstRm#`60nuxe{nSSP6yWyETpbuhWt?iAI- zL}f)d+Yg01TSMGk-yAt#9-}#e!7S!0H>!G2heM+{2jGG`>95u zc5mn@Hkh@4hL^xgOT3nb8dqP!6Q0Tt^1Z8*eS9MhDN>(L-(#Z^x7U*r;ox;Sa>SBaOm#`vc@ zfJ0Ou=a)4T>ak@JgM8KcyGgpt8d)hSrgx?8*vqxn#1!s*vky0*|W(fw)Vm*D8r z>7Vq@Qu@agA@iHJdcIc%x~lxK;t6Dy$gcAH7hJvscxSk+eRf2>Wgt|s*S{1PFnxah z!I+w*IG4@E$?&PReNnQQi4og>fh2&ADs32EvD9AD5R`ncYX7spnH0JcrA2AkVS&A`d{#CayR+sjkl}#A#)~aKN{;y z|JO8~m#-$7<^OkU{?GqGq=3r(D?NDzjabruJmX0B|EZGpihn)Q1g!tM&Htm}OT@{L z^mAFmAO8^=xvGw=Cgfi>$updTvHw*%bpZDN>)a+h{O?e}?`wa(@yPuD()@qZP?{UO z<<=SQ%w&*G~*w zty;_hDgW!kV?GH(ZPt0c;{U}UT<-TDmI20-5;s_Nk`kRd@juB(R|P~AUmo^)`p%4u z9GBmX^FOu4=e#na@iMN3^@5e9n6C+_cM$rQ+xY+@wj9{e^)*>Y2(3arzyCkFkx2i? zxW2L!13A^QX?#7pAzEYd^RqxA?a&LrS_J<3N+vI}E2N5%np8d)T7@mgTcd`Sz;cKF zY5ptQr}6;%tkZWd_LavGE*lZ|{tbQHX<|F! ze|C}>VAJ{6UReL1Hl+#=r9womi}}y#_R+zZC?G*xteVToJ6_(S;xW+$_vRacNmQnT<|bQ0_hAJ4_|$9!9+884b((D7Rfz1Oue+O?-^xI zl#i@aufomqE>e~vynEB35^!9eC^tquK@TC=Oyfg)_LpSx_S7(IiO*b4-Vbu%qMR!# zW9z4(_eQLORvm?8Z{tthT*Z{bTBI6x2)pq6*z}ZpXfJ?34f-ka&84n2qz5Xf#CbV> zBG4lzYqI#wcyrYyDHF?>SckFqkwv!6T;t@DgLQ~h6ie{&{lUA=pSm)Ii-UlYt*zD2 zcvgB;wPrf~TPDu&va9G%IA<~%A8ZvrAdcyyfmz({Za_klA-?|UG_-j&8bT(Gy zo+=6s)BfFZth78*p556q$+Czn>qSLRWuciqO+~}RSWQX z=aLF27cl5DO5R~7C{{>A*%6edy|0@U4LDj5Yol0e6dY=xsQQp?d9g(cceKTu8x%85!@~T(>9Q8RT*eyw8ivFU=snCv$h& z5>@A(RKn6Uh%Dy@8eDlBiyLq2Mb=O+riTTbPQ^)Nq+}(g2-d+?fD4<(*8=uXO_~(s zobr$TKm#OoMFr0;faPXy0O(3rz+9aROCm;8nf8)WxB;cK;H{;Iw=O=C;k0T*8xCK_ zZs_p#011RmDC#2q=h(^r%dbnVa z$N5#=$c%IBj0ZOt;p+$WDBAoeLnA74qk>*Hm|2t&SJ@{yqEKbZeD*Sie89=h^5uN$ zryPicJN=T3s|hrT3b)jOX%6>Xe*BnYV>1lW6GZzYX-{4ALsPR0r9S| zfL2{Fjo;yO8{A4Q(9Ya}tRPk0y`E6FuplREOu0tsQE7>KGOk>L@}q#5q{TduQ8j@K z^#PxuA#9>^HHAEkE|BF`(c^akA+4f8>cnc!@JAUIv9L!f_i@l7Eq^_T4)cU;>eB=l zi<`ftm%bf+cFo@SlG78Silb9)kIry};5FI=uhUlt7(WW{VQoMearM?t8K{c+5gR=! z5;cYOyy2+bftJq}Mfu6a>@1*!cA!u@{La}k+iQXr0x@W?FsKCiRTq5JxuO_fS;#P9 zP_tQH?*4>SZR+<}zI&bPz~mg!wr##!(|ffmyp_PI;mif;t@(qcPQ?6+MFVUaO^>RZ z#}=dN*yj5B)L}LuIoY4I4Ff0$dJ7=zEQ$784*p3TQM!SSYM;L_b8_OxJbtHvB6EwP zk$h4WLO0-&Q;paRb_sV-l51gc&i$dV;G`kItjt45!yS{VXIfZtmwkgrLdfjT%3k3p z_E>{ca0r`LW>xi(yMCZw!Q;9OHU2zJC)b{0OBrR>5KdO9-IstzOi$=xU3r`gCjx2) z1^32Eu_*fmKpZTjb!)-d{6&wMjM)6FjZ5RD1Rce5*yL0 zbhBhA_&b;|+Qu3EJf9W6nNwaA%3V2W2-Fj+BCf+J0cUrQRi1{0)~bg&y&l*m?|VlECyw zVxB5N^=HbsatHY=%oN@(E-tDsybG2~lr=vs48it zp?wZBWI$Re`UIk}i;;R$sN?Z{3H z6{U2F5JTnjs@u?V2y96$5NFiaLssN%S!JqHpRm4>A0E;G+p-05Y02tY(e5hF5=)Yv zsGKnIwP*PMz(tcWT`v!lf>Li$99xt=Kg~v>j`$WqSh7vRBQ5@2O09C|rfp7y+GgCJ z(}uBPNy#@^+rqW1aoW%M7M&52HDwN{KgkWNu;I;CL-g>wuo3*ULxEHNy{@JU5KK6^ z@Gtc~$}Qb_L%oiNnRv?X>rEMe$qO0(2TL_iglaO@@RK}!3`VYhR}6HH*M{aw zqz)6coy-fHsCIj;nfi!F_Tt&btdd!*A-{>byUfv!Anh0(^$|_J>JE!?dbhLUg(!-r zP`y{LI9-2OjeemM2boqf&H=@7Y1*}}SwLlin+pH=-d>m&*jQxZm9&I5CvXam>H3iZdm=$KT)sZi7TWN&ZBrXSmvr z&tF9e87lb0_5^ZA27z)@M<9Lb%b@kjaAe|azPjS5sk$y`h+#1rxW{2)wCu%{{zOVp z_WL?AQo~nUTVGKMc(YHdy9MVZbUFG_B|dL2GBEUs#?C8tGz0(xwF?ET3|%DHj(^sN{yi@*_#}l{@;Z8lWk!I zNM2%dwYKZB*4<&-64ZZ1`{$3AD8Jx1}dQOXg;;kqko$cCSxO&F_{gIS#0UW&tetA7JNZLgPel z+mtb>ac4|5yXU_EBwF4(MZELNYwYZvzJF34x1g6_gD-yY^#k;HugS+ z2ob-I8ZQoDbiMFiV{D$hE}R$)5BoNSIB-}7+>`wI3GF__;BICVPs0Vcn%K>+8Ftwb zf7+ZpbG%wBBj9{Cd;H40RVD?vJaGi{k^?OQ`xNjJ=$i(_w2wA~fyQ(GjX(c`c>bHy z0LU|dnEne6Y5ql?A!bzoC0H92@?@!D}vAqd{?sYNNv(wxEH2yq6?!P93W?EvH2VepYYGyTjr@TesER zM2`8ukGkJSwclG%g0-+M&}8S=-@Q2DWQqF*dc-8RtV4$_#)kA*{5dem--}i-d4)($|7t7 z$bdB5Ully4eBTFw$mob|WpME9QgMZrN+e(=a*q%}lEA0ujIPN<{a0>?v#L9cah4>s zL9TF*nWV%juK#i2H-Fx2!?OgYxosA@E_;mw^rjfz!5 zhmhwaYJe@`9gme!CUV#cDrBK6gO7PT{z((Ucp;<1AbLAJVR0+7A&S;%ndVjbZK^iN zalT2_30oJZMU0}MhK4l0#+1U@AUWOc$jI=yIt?jpv?}8?en4LM>F#)VNf|}dE(b|X zl}}zWop$OIm2W&{V>UM9pn7U4X^e6L$7lRBAPs(!CaJ!eH@(B*;L15f`+O{NYXTZC z(>>Dx!yuw)dM>Tawo>0C^f9e8zD%Q&;}s;8oam?d1$JJh9;CE7J?QS@&f+tz)WSzJ zhJBV=K^SP*S>bp^puk2OJW^eO9^zAw)HA$5J57zb*mR?C_>Wm^+c=0$-yI>VmxqDk zRHmqLOa$+@8f~PMYr)9dqUyqEQHJfx?A9Z4M#!5qYGCt*WP|B}UNy7mZaXETDooG0 z0##ZZPkkN3u_JlSaSIlN$~TB5t3$N?B$}oSB(}-}i1BAzSVm04S*v1kftu0Cg?1UM z1D``h)m>Dj^mkOVVTvqLIGVZAkswnLWFit~p%-|1VxCXL)IgWmfSJ=3)`L%GCl~mO z)h{+`w81P%=R0*zq8@dya8ike^dPk-41Fz!E;Is-R!DPRE1KJTD}6A}U=XN(YtLzZ zo)?r?7<(upXe2|j@&gCOJ|ryDM>P>Q=O=9{J0q4}XC@~JTse!Y%qrGTW25SpWu!x2>}*a2SMw1|)3J8`z?;To@p8 zc!Jc{T6iW?eMV@OV18}En+a|)zJaA|MV6JYT?XB~DHa&sq|iPle-MR+5!b1DTz6d9fCUZ&A>Xd|HN%V7C028uX?TAW82_c;D&FI}Q~M8= zlS$^~1SP^n7Pw&~!@)HgIVqaf@SjkYX!z*bF?BAI)l^2Tuuq07)TxOBUieba`_oUz z0j(KJS$sjIM#5X#Ww5Ymsy|;t*)LPZ2#3k}k{1UJZc<9D%E&ZjP|m_yA!WII6w7M# ziPG$M^-yH6L;1@{lSa!%oTr*wxRqrmQn6<26<{u&j(NN5-GZ}X9K77sN*@>)rf8n` zt2k0MvBhPRnV3 zu#*n=8Tc?Lry@w1A|tObZZ^C*uLQa#b~X8FcN%^^Dw_RWKpTxELd9&@^Mu5gFTTN| z4nSLgxFL$KiKC>TK@R2Z-m)pr32I!wVES1FJcs{l)-boGaSGyzO3)J0+ey0qvmttq zg!uAoayd^!Rah2lT$F}nTp`=lrb&Mv(gZb&BC_5ZNQHJ;=XhqtsGi#N`Kb1m)YmCY zBLf;`ws`ZbXdPAIMtQ<1usMd5hKNg#C57AT488sD^#m?7C8s0R6R6_3; z^Dw2{v@EA!+i&X=RCH*+I+>GtmQ>~q$5y#BTXuyN`l!;95xP0 zcm=J@bdO4?^pmeFJN0g@M6QZvZkTTL?H)k4@c*d%?ZjIrQ542}e3_5mUr?~K2MFa_ zzOpB>uyy$l%g_n0TCHt=6_y%iq0_;_r5HD>y2N{{4{@M_>8W^=e@&Pv0 zqNO#P(9~N|_Mt7bY;x6^q-RVSx+5+*{t#NL8|Jx^q>PWMCR!uC_9ara)k7{YOX?#- zs)lgN?stSiJ3#A&&anuNq2g-~+T(Wlq`qd-XV=MeXs6*>@Y`XLTU4x9P$nM#42*lW zWcG@7{N?YXGAX6luw41DLK~|f_~?}vf;Xm`Sm) zX4CP&b3&_GzM4z&V1<``?fl#JIsAjbNFSeC4}d~aKfapajyValO7OJcs-G*%l|V9) ztjd3B&Sf0`zNT=iv?{c|c)|IZ+B;e`D2r5u2@duy$rCbg6ugr?2hX~haS9|pjH5)=n(58&S=yB=#k<;EuOrJfY;QO!IbTHn?3S_AA&n}EJDx?F zjfy@QhYwde6t5_7t+1Gzt!3<$$d!o%ZFSZfTf{r4y55fTA{Os$4GRMyv$LP{8u7t; z#kp(V5TfhuuPnJ&W`tp$Di$8y@n|dkeH6}%^i*t1^+UG)%C zJqM+O$mnYA1K19OLceiD*l2w+ti`eEgCE37QhV=e>Mw1oXs>%g9(5^1@+rSK*9cL) z$tCBLs8PaJlF3>ACy6n4v!slJCFiTPoS!&Ms<^iB8i6Ag^5bz%1Fn;w(Gc~#@pA2| zg+@WDiuG>ua|M#$FHJ41v&Rp98j>3F(nsSl zDV(t|b44^J7OSF$O+?LDz)PF?z#kfLjqqI#C|uE(CMJu~=+s*F0Usx~e(vNe)4=i3 zDrj!l8$s0+y9kRey*&zJvn!E4iVsH5gjwS~Z7v%iryXjY@!GOY? z?d7V=D#zSbjb9w29xA31l0PKXL07IW`JnD9t%YAS$2Q|Jexk)EvDc>e}zWJ6V?&-gQ z^=G-Q+Dn0W)hhtLj;s>|CZx=bznxu*0K!Hgsxko2{pEmL03^Tk{4Xuq0R}h{-XPT=)wX}e$mc!kbTSDh0#^}>f8wE+e#Ep!#~8Z8kj5(dvE7%Ms4sW zVWaY6)~K}BINw2%1xyoDePUO|^55cafNnM3vtR8OxLR#p8{*X#$CG-k1fF%jv^Z-& ztMj;akaF57%rZ3V0bnF>dw_ z>5qgznkmAj9W)y`4#++CZ{9KdPVu<={Qmx;A;^@)>%Z;k{cR5@X=`*7Ot^JA)5J0S z`V*k=A1+Wgij5>y1&DGKI+W|x28!&Ps4@3*RbQaji6egsT%&RCn*bhbyN;FK*qVl&(66!7G2!WcNB$_FqREd55a11 z*h@r7alS};j)-kGTVoBF8Qa_2vp}Ef4ncb4fi%gZM@0K1yg*OdLt@~XnCcIj2P~9R z04D7_R0&9rMsWSjpujL0TS-Asm5I+gZx9FXHu`-8ZrV2PLiml7v01hR205=^tARU+ z%%LX0El3?CCGX#2QK2_Y$s^%u5BK5!CF%$)U%$ER7q)9DHxb5ix7o(Buxxp-D@q_5 z(hF*2H_+YJ=Oj_D{!X0C0njlu@H79yV(jFLv*uz-43Mc-%Wy~EJf(J}@epCa`;?XW z5CagHCy0Ap$K*vkG02Ej=>2MQcTGu^jhaBdx+8aey$YD15 z9?x`Vx^fjCZA223G?J%lXRKo}SW&p$xK3rI0RD!>7}RKrcGqd>v7B`gvDe7wYeRU} z=syx21*cBx`3#k+$9Q1S?7EsLUIjME$avnjzh5h(L=<0#*7v3O8O?msX}M*{#~YWv zMmbC~Zgwih_N4MR**9jJ6xYbG0=(m#<@dr7&nGI!e@4q!#N z-m@b2wc7)(Wx_VR#Md=2XFa(Ro=L^p!&(HcH(q{ zp3~cPwOzjVa^s!k%?;!aDd}53dNVMkPw!XjS_cMZsH)Y-p3R{UZ@D~}*dAD4u`uV; zxNIP+mO02(*wR>jL{VhMRe$*QZTPbt@(3W&6j(hFC!xeOuss8A4<415nkw+GE;Y}) zUJXnxm1(EXrwq{e!qvGRW1?G+UqDqu>#&{p)J*bMglNm*`rezE1jeGTHLZXeie?eP zA}KzGr;?5nooZmHFR5{*Q9S4BC2cP4H#11;U^e6*MC_E7wu9}h3bUVgpn1_!;9j?46aeC-K@e!@TDKIIEqx5M@eJ9d2 z@F-sEpW^uqqmGA_Nib+*jMz5P-SI3>xu23{Bs|)G%Gmmix{y6zO-i>_GLDb_^lU^p zACj($jGR*WpvUE#EOR^6Ug{yj&DG`hBpb~GgoiG3d0n00DC`8rVS$FT{?guNYb9|+l=PIB0+^xt% zp6P#~&k6bM@dLHN)7M7hZ!P66Ytr4gXF^;qCiT@aZv;NW0_uK!D7kIC z29&w9FLu7^t&CQwMA5h0w*1h!4D=%+dyR**o1RFdp+c0oyArqm_$L7pzAl<QPL% z(PM>{LCe>Ss8jjE^WqFiOM;Nnb>~*#Wrc&AsUE0RN`O7~dk4JjK!pg|9;9?igAo3M zTn#q^@hyK5Dq+bOmrT(e2e3Ca2gxaayO-^b% zRC5g;)uRT+av5oEvtLzJFfy*9VaJ@3TIn6lR2Q4genj@sn(mud+S&HL)n3-ZDhqR$ zLE@=Cp2#bVrXm-x*$`};Ag^8{Tm33{N&UrBw1S!A%TaNn202%6QRGKEkB#Ga71P_x zKo&!AA_xhDQ*Eu>!?9j-+@gH?(HhDpm_$$WGU8Ta{HPwa6EL29?;Os^zEY`Yuf zF=W-wML*n-&VzI^TeH;EaDbTky3W?R@uVTxo~fcBKGt@kz?^>0<`HL9bYC*|LbMNH zA-Wwh52v=v&ePYZLp{p^_v}Y(HXG6Qx4MV)y9a#u&>{ttYiA+wlr*p#g;W(f^&vYMJQ_)vF3Q5r(C&XXby4?Sf%;hBD zWTL;@Y}PqSMAYtpLKLs2?|vrlcH-sW%c+@51YKJENaWnu;2r7UvYfTVcl=ue?rFrF z!@vy2Z{(`&c(-Cj@OISrB-hMS>7tn-$allykhF>=_$yghlEYl??XC45CcD#Nbc(#= z4-PC8)q!SK%T`vi03%&KcLyc*A*6>80}w5eTgwIB1PAUkCK~P>UO>`Jg#Qz=`$19(8ViVAILmo3hVA#LUy@>Cb8@@+X&k3EB83A9Uj91VOi&5n&&|L_rEk03sPwm&!a zY`VZ7NEKf5bQpee1UyU{;DPwO1LcU0SHhtNhK^{C{~`OVi5W+j^ev}1;J142gR=-k z$p=CLh$yh6bLv9DgYl1FPa}eU$lWWo5!wTRX~cdc3pg^K=ZDTv4o=y~zIfDp@2^aT z%Gmn!4?1|1-ty-v%$ zgK6-s(aCVF_;ka+%U=opgsCyU;)JzKEZKocPIodRs{*&Ho8$Zx^_@T^9pEFpxSvz; zS4+C#4U9`8j09Z#y#dC@azS!cu(evRNlGfD9flyT1b21#_AkKG1LlyKntl%$^z%Qu z(o9ldyNU$$ordg)R4C7naNBRL^qwuatnWZej#)O@H+iN4apCyzV9yKi^NXBMqAnN* zMZKTdiFPe&_vNJhwV`;+`?N@U!=qLG~1BIqf^BhbYv--oMZjT2TAY_o#wR7}{81$a} z4Qx%VP{d8Cd&HN}b5TG*uImfY6pN&I_z&SkfD%$3sB7JA@K21i8V{c zeaYI!Y_2Sh(A8<+ssG;8UmEtQKC$!ywD0Mg`}macfE$kn@o>%fmXX-t!eC3(5va)k zP%w5SG!TY2x1C7MS^uj)Zf&aED7t`N_1+bhyhk)fL_(zX)aK zJfX4j+UEzOjQ3&nk<_Q(N<-0DYUW$2BECZE`6i;uw}|hi;p8EEe3(`*P!`;7n66Wm#auw6J%_Vq3dMCI5bhy=dsE#l3U}&-P+Ttf$c>JVCBs@YsqDV8$Fm0 zUr#{@`G|x>p++T13>z;}!>A0wB5u^0`lGi4au<^hk#{*8PF z$+ZfJ^n&+}>Sm<;6Y$J$#dsfkB|(HeyWtM$n0-!$q30oViZD(Ev{)DS7P1rgHzBNV zq|%AQLisYQ5>=wkRip|F#!^xFJlJ!Blo#^`{3jxIb*rZ%$0dLwbCTNpF;!K{cXdIi zMQ!oM@t)@Kn)+GsB;}QP??AAUlzJ+y_G8T%r-u(WG|B*xJe#DKt_<)}?t4bRCeL0U z*H_XP*_C~($kB6%%K8pXkbcJ?QZBN*oL>f!s$JQ#O?-VFER{Vb;o*jzkLR~{eKi^c z*@V8e4kP8eW?$OYV1-iB>A8%{Kp@{cugD8vd32$k1=;dVK8$xSdRJ}_E zt!l7OBl4RaAW3BiH^D|T>w0NcuZq8urxW^GV$Di1PBX>u<0+GPpw2T7Cd0LUbFX|( zqgzi!MSCL+yD`O5)Yxi#R(|_@6-enjf7XuXe(~@=$B3Lv^a(K`N`&u*bpy&ip?Di6 zP2x3`1(D$&ze;bi7Rq}7s}OkApi!6;>MN%Uk5{Um{^kkYt8F2N(i$=Fww-s9$3 z^!>C2cuhIbsLZu%Qx^gCvMTk3B@*7I_d%28K0h(P zr&iMo>hw8ND1iFf(MRa>w?&U{gLh`23p0+yt;gCm7WNwi!7`r1Pstm$dlWs4VndJw z<Mq4A_UWQXZ4e_Po54ok0wPf z*BwwE7m)&gL83^xT~Soo+zuG9sYtQ(bHuzF90-C`P@eGAKWh|i^w^?b&{6}_%<6PL zMa$X~JNQ9EC-+jYv5knK9;QgpI}qM}ThgtNW`m7P--bF=Mw<3xAMeP=lX*S%Vk_mc zK@jV6qeF1vVJXI$#p+?V>p=D%EAC<7n}tXlCAGSleo!h|B&IsSz*+YIeJOcX-03az zF0g4$j(mlIurT!V)33jX$BAM$!eGY2AHQ;}%Lg-a)eVkfnrJqwJR?m64I4{`9hn#z zze;X~XDd>ijtMUNf>u=+B_*2A^^SdAcV7`)R&(md94S`HYZy81x|BG{j!J|uJ^8DrQk>-;&)Ng#fBrdNg)p~}qTUGI5lE%DfNj*IXX;rTYSF(u zL}v0}YJ+))a<7ZVY(rTOl5VdjW21XbyjxI_cRZR3W2q$Fi#buJc+BkU3x1S9{p36u zpB@5Fq3Mq0k7=bn_>AR>&sm*z@FwF*upJY*#;$TaJcRkK`zdMtoDW@oeOT{Xu&g{0 zJGbK4J4;CAe`Ea-vav^QYGaNw60~!L-{bBQiw?p#Z+)hQ!fc^gr&N7$Q%J)C2$OzZ#S z`m2!b4aQFHQo;bDm}qPh;!Gj_7<++3p(*Uz!X5O;Xh9gKzKRv9R zu2obcdVq;ui*Fk#IxX)}y?7i@zR~UL%Q>84H;=irtFHpiAU9i>sw$prisX)h&hPpc z=K6sGf9XqQmTiMeXX#+yamYT_ZKrggJp{<96|l*46|h&|vw`)W=pPlwjSbfCpF4Qw zut0G*5@%=IOclm5Q`Q}=*!0&^7_;eC~x0sjzjI|)7_Cr8;rqGz*zA=>~d7thg zb$}_(Pu3>GBZ_cUxkHZt>`#sJ^?pkg1^dZxlf3sOaT@tL_o4-riSNJl#5=kc}Oeo^zdWCEf zw(w0W?tCo*iv3I756dDo{FoX%xZ@3P)hUW#*Ey5&5}R&_3;>H3soDr z8<_5^j48G>*`ow(JE*O6W>SN2{zaes&BBwF@A6nvpP4Y7nJ`Wr2DeQ22^%2J6z`*A z-yToFi&vsM{i%W^4hGgfa7GVq_P2M0+cgKjL=P_HD(AWwwMnnCrwRF7on{QRE+2j-9o#RZKJ;PIk8-(J*f#P4k56PG`Cck?ja z2X_+%$^qDfO@6=leJ1Imhc`Y(bw2qvj?7Jh$H5N(fe@+NnZ~34#W)}+dp`dUk9YaQ z=a1=)7?ZbM>rT^Iuaj8cMkxW9WH^ub5B!L&i3s#KVkDgWuLuAHwRf3C&J% zZMB8|fkyFr{@+~-FkQ3ImS)GheGiwrk~29F2_PH(pSA4*zNN^ z*#z_jfPS^~i$71)ABcoVI2lCt2T&;o>Kch zBj^29b`-KEh%D+6bjQ8Vu$?nXiRbSY+y4+$)`$&pWtaghlT zl=RJ++AqFkMlfK!lgV|uAfKvI<@ujM6Da-2D;iK}!`7nj?) zd4)EUd!MM{yKNp!rKc7@SFToId^MF;;T-VtQ>Qd@L29jxk1_I}MD6I@h<-@iDZKTV ziaNC$u~_o?&N85zg)P6(hH}D|iL3l)jLnp6?MfCY)o}JAYyzmB8smia+o&jGo&(V^ z48y;KPm0#$`VRXmOp$EIa~0()*FjYbX6GoWS)z1rwVf&aT!vVriqyen>;Xjk^-Wtc zH>j`KVin*vbA+8wamHqq#!30&z5;OpU*Ud6`wk;kw- zMuiD)Y0z%klOE}-fz3G7JnG>SM0I95~jaq(Tfvklc?prNi_93>XGi=rE((Ix}rYe?^nR)^a3N?Nk)m2CLAuR1S zm9;M2_w@(?Rt6Nx*RRqDm;FNCq3yKG)JXpv?-@={R!JS6b47~GYc?I26?tYpZ*Y<0 zuU_zYTgHq0ozUu!;(+e8L(2~Yp`8^)Fj$E}L|HfQXLi&kM3T>;g^0=V%rcE^WDGW$ zzRhBZe5P5)UgTy&b=35Q!;a0}@YA3yc6&olBm+LfPPXZ(FsDXvM0GT=`)J#I}8k6>l@u!t>IS zRhdQo-m7T2-;yn6<vH>RRiRRO9W@R509h`t|fYu^3t@#Z?d#f>FT&%R7FxC zH}sw{2V$#zoG)dgiZ!&m+;ALiEe`baxd;Xsa45l|zen=n1O z^x>$gL6sOf^%wrVs^j9{;SR`Hj%WM1-yqO?8u_1ElOv7=Bq)PP0zX(pH`7oBpAQ!b z{hs`sw!PUEDt@^e3Fyw^s1jZ1uhhl-YQx0x`X)SqqE`b3(Q?mWjA&^c=mxU(VDAyR(qppZ6iFX^pKYqbZSB>4sVi>|33 z57{GH4*vVHi|~74kJ>(mVyU$Y-va7=LLy6&OaB@3uT`?apPFowa?PI#4?52VS()Fm z+g1hRa#>Dqek>+zIl}Sm9AmOA%0gNa)>``yR8z)RQea)t0o&#*e5~>p)NF9j8xR50 zD9nD3WP$|Z09!dODa|f~A#nkAXbBQJsB7_%cde<&pA z3I!^j2-cOk2DAGQ-cNNQ1TI$z80jFT96Vn{fRKAB67 z&s|FAZBW`yR|ezu#tr!w@OSnO%#zsr1Adx#i_$VIL{jwbF;6-{HSn~+wu!x_MtDq6 z%;dGBQF=I)qB{PKx4rD`+jy`@MyEm{*^?v0m*0VPns;t=^i=_E=V_mUcAK*}grHis zG{nkH*^j@HmOd;*syff}ZK?Q2;l6^P3*f+Bf^UkrC(Ll_IeUbg?8Y6qtWWC^Nt-^4 zmth9vTF|RP*}<)+N#<7pJ5sqy8k;-GlkovL74QsIA~bzPSbYN|bB=;6S$($}_&_q+ zO17^J16eWZHH8I-w|{Og%hUiPa~6{u$>+h*Pddvr^g}dQ1I}v|KweCwrdwC@q!I*P z)5V_BdCAIN-Z!fr&Ph`^ytMr!Er%aCtyBbytNRVevle~ksnh`Uj81}znYX0p$x{lJ z+-V1d)_cZ5wJIdMf}#nd`ef*5rXYZHVgRJGGxR&MqZ08q?n0RphGahFg+K?Z%eZui zKnB!r$Frj~PI~F;2L=48gEGl2i=?h%^&a~Do@xu8;s?Rv&t+$UsvEj1mEBk#z1;6| za;j!iLJ;zZbN&)y(eA@0U?VEY_NL_h?!VWb#0!NslOyG)x1082PC6cam6OB159OLr z=p@h{lD{a4Bdr+8ogbED4P7^%9GhK!h2tRYd1wUyk`v-$n{Y+Ndreh^4mp-4>ORgC zSf>>_ZieofruoNTjy;{fU&=b;1OLs{C#-Xm6val`ZMp*KlyhI2iG+5s8B+b^LKYk{{+1Mw4~Ggp|@c6V@&t$ zqJcmUqtnz=HU~;KIYa}p*qUVvTisY0BSa+Nq~*ttrhv@Ey^$0_gZtURhe67@cLck2 z8}jQiSdYuz^f4CIF_qNk-YudGE^sz4?m7&)TG1t%DFUUse~6Pu3iooH;)=mnNN)C) zTWV(&?)GO+WyRZ{E_w%Tb*HRPzpu^Tm1g#wn~%ru(Y-qR=JnU~!*w_b7iwec^k$zabV!}r1={2Dt5 zX`GpKI`X+>j2>mublDE<7;EPL>DuJ6UvJ4y8+X!J9nZtyt@JOmP;P*mYR|0rD%=(k zT;UF}Uj<_2eO*j~I@1~8eu6J`RmQH=o@YxK-3(VOADw*;=q~!J47&$LfII?_Oi3)5 zs86`b4^^G$I-6bWM{Mt@hP2Uq?h;cZ@5>i@YYHNvtF$JHFOEh z0w9g)L=jNn8uj9ZZLrBL=Bb&}u}1S_CzlTIWj8flfthTf-$x_1a??{i!}Br7chv2kl~w zqyYesb6La#Gy>>dr`O~UQl`U9!zV~z~PV$^r}5QomfT}?c$i#lw4a#3o4tpgeU(tk}( zYPN8Ki51%{#FX_v;GsOak{sGw*WlYd!e4_A4vI}W&aeh`A1SGw7MU1oya_<>sz-`qWydPyaNNvn3^4^H-;86Tt-Hlf@oda z;xWcbQLO|~V!Eb0Iu=iR6yLcBT0B)W)DI@nS)?hVsI2g+<8fCRZCAWFr{cP+8_TK? z`-Int*`r-pRmNRAZ0Kc0FwQ%IWHvI3&N_w}SE$mc5bkp`E4oOMwJ;6PlR(&1lF{x~ z%0@`fzw=4%xu1`Gh;@5cg5T#Qicw6X!A!FkiMr4=kTxF=g*^WY&{Ti7aQ{67Vllk% zOVp@Skjd>$D?yeJewm@o5(gKHi`3D>oj9 zOfCTejcRXkQ?_|VmM4|Tz%e}kCT)0FhWLd}T-p!bi(LEw`!>FKU~K+@KQRInRla@O zy0`Cp(Bm|b5zagff&);WPjyPC8Z`BL4bYJA7niJIODa=5D-I9%Q02pVM|F^^SqK!_ zNhWHvC6Uzzz4HgrSeujCh5uB~nvphy&kX~rKD{*iK-63m-I@F&F9CkM6>wb(OSZZi zk$C+rfe&5dGTYo04dv($zp^YN!exC#-48H0QzNm{{TGAwPsS+tTg{!ShWggnHl0AL z7AkVVT!pspUJ39OwrknwQz(l&ZV)#j{+7JEQ5u2zD*caa&i@zS{>(79L?Lu%_qdy%ioP|(0!yf?3eiwaz=s#+kUcy5c|c@w)^w_i zMX3Kfo1%7;h3Nw=hqZw)(N*V_Om(ZQPKbhvam=*f-1lxGD*9!046q8^mp&(?vWs>w z8L3YojH2hH$+&{4RiUd+Aj1+)ACnKUmp}ZBMn~Fl(Gk;mfVZHLs<21S%M~pb<1^TS zfwu~E#I%Y`ud3F}%ECxGgD-bsirl$HzV_+Q!_p&bvt98zymvew0 z$ZT+?F&3;+#?PxF4|bytBOUqd&}-VShF^XCk$88mcQx!HUT(pdWd-M56ZL9VkzI8h z;EhN{UBVr|7nY!@FD1>obMtW)h#O0?vD_oo3Ay~8w+lny{Ll_Un`^Dox*ndZs=sQq zuYkxLB!!_ey-iIiKJ&v$BYD6&eVsRtddzE`@yYl6c==E$tv!_b+d1mhwad+=y(0MX z-~7!3(qYpx_?$TYB~Rs~+ekI|)Gh(LETo;UBn?l?rTsPNt9mjE=#6`{DnTKr6f>Ke ze!?@8C-He)hD7>=2H!?n*7KcRI$J;7-EIM+rI|uir_8GO?Rd#wK#F}A(xc66zSldu z3VH+}@j-|;5xJ}D77EvQ_ti>%LgLTATTX8sF%)EH-%^;^GAzHQE!}#SH`H;7S#Uo^ zVNuark)H%rz6B8bma7`EJMG6C9@NIk~e_x~N;WY=|WQ*X@#4yElIgaP!qJTzY?;^4VY zI4YfSG@pY(1Vt=!3v(wzZ`jg_wQMdR63T#=a-*tly?8#zr99`y-xe>L ze<{La@iEb3!!j@1Lx8lunD;l2jvhebo5fl47Z$)d`Q6S5PmPk`u?K%5M~l^!H)&^^ zR_b_{fD;s8LZlwNi8s!($%yf9Ok?kZ8X09p3->LVII4W+J&e?s(J$zeq0dhx{Lf(2 zMKK|E5vM2-WQ(y67hO3OVp5Y$<>tDjZq)WPQjK#Mno4Lu5nM;KgyB@Beyv948%Bvv zyD5P{K>NME6=Yl2I+^p|4)(ZBG+E{Vb33 z^OZgo*pBk?XV=l8>Dfsl(JzbM^PDE|pvW6(W3 zI!%8nJ=@dKe1QWr13rht{tu-Q1=QZ!#Nen!H_y!CwBiXE$0zY0&28-2ISYWjW?4Ym>r^)_zt2x$=xtfoN z7vPhpFK2o?|NiU?Qbia**toUm{5f~5WH??K9k~?|MNrxjh0+~%`hCv0sWks$izlJE zDFZTl+Udb*rK+<$drHBRO)mXH<8Nus18qYAt-KOinBW*&Xh_>#dsXQ~L@;#o`@Bju zP@-;Q^#x$0@b+85f4~{iEL$+`H`0g%hPldm$aPj7j{`gZ*rHQdoF0Z>1-PzxLjEQP7}m#XBE@Eo4eFoVT2KY zsOUaOltjzP`}i_`CKEVV?$M)zKaxX&oqA_+@~iQ*5~4A?q~FaPrB#|J*S*&-(ADKU zTo;dQWgVSdVx3*U=B(MHH4th^Jn9GE#&gdHm=o_*W_z7nUPsS2Vv49CKS2&e{*w0> zlkOZay;T{tlKXA)$3-@J`9a4>IO(xwS)F)3Lr?k2)>;5;E!&AK6+Q?NRR#+&aTzE9 zM?@?|nFt=a%RoveYPsz6lHwtJt&1iz;mk z2Tpsx}Ze6IObPxSKQ_oePhJ;{A8dUJ8{_?b8F zm2Q69wCB~u#≠5CATB<6dM@(r&Ef(je~E=w<~t8L)SEZ$aVv{PG_Xh7$$_Pi9Sf zTHcP{xBLqvvM2~>K$j#yyAX}`@8P6A72&US5-I?HX1c>czYi8#%mp-{)jfGIg9bB# zs7@eQU(FnESm#{^d_F84EckHZ2O*&20lWhhcN3!{spAj2ImiuiFlNNUL|-FBrk1v_ zX@%8#uJorEo2r3}G_1|onH{o&5_ixd{k#A@>!U~a1E@D7+204!kfUckRJ7VmxE4je@sf@QCNvmb6mj&lMPqEm zgn|^xAgQ`ll_QR{2b*Ln;CaeyyW%iHF%p*(ScmFtp9s}94e>`X&w4D@t|2iLrygw7a z6mUH33*q~FxM7J`98fd{P}hG7(Xip}3(){CZIAVT9fXK(q!_FYd|Li!Th;NUd(mit z+bxy-^-NX-XmR&p&i7SCSMkR@>UO`6XB#O2eI8KXcK=|H6axU2q?O5elhXgy+j&Mc zm2Ghx1*0IS1ENpq1VNeA{qIOA9P~b$A=S z1NxgxTI@E)L`H1-gF-=t;Jrmh`ct4wB^yYatXfMbuvz6%&$gjH?@Ml`TGOR!d=tITOz8KXfl=E5MtRJrYrNZ0K=HyA=0)}OVR_@!o&`DV`dpe7)QuLt zH@LEFK~6Jwjo|CMsG3!3-nZ$hdnhZeD4f3Mbb>55E z)4ek;h16`blEJ?F-9&-qZp|X_c}d6H7A`*^2VGmVO02C{CEb|xB&jWrd(QAwP`Y>B zXxQ;Xn0>$Pr<^Gpi53i+(=a&=1zM^vxIurhhNJawHBd$+2N5C&X#i!gi{%mGG7{v7=c{2r!y z^1!TP_Mvm)^TEn%>pBz$8GKHVk!Xa?{u+VomL8X7edktb^$+^^UwaRo|3TK<$;%iZHJY@w0R=O(B56Wt(s|6CK?w_r3(VpLt`0casJ?Dpqh4(T zEiTbB_Ml#J?7jz_q{J9y65xvQiI1Vyw?<2}+>m0U23y}VQfn1xSao8B5qdsvUa!=d z2s&q+R6rM@xF;X@`TPT*`>9F?9g(HLa~DmmU`Tc~8`2UwIF%A)G5&KmCiOUeI2(Y< z@W77bc&l>IG5c+)=y`31GRgCX2g3N~1Fg7+@WXUJvfYB3^T)WTSO$)js1oabbK}|U z$BDRrQ$bze9=BfF84=hKNVzZUe!DHD5E{xNE<@e!tp{NW4=w{!jn1AmR;WBj7OxI> zv^W}g@3Jfdz`E)P%rz)}o~_c5NJvE<;%9$I86Ru6p^~7LW0ZsNsQa9|@)7`-Q+@DT za(RxryqJR_Ni6s$pKEjZDYayG&Wc2R?ge&O>CGwa%5h+$v(et+oS1U->g}6sbrUoU zhtS$m)lf?9pv2p7cRiVKSe}}^?#%lDoCVudsieQFE!6W?Y(qn-HPJD_ugB&IWTN`l z!uA<;Z|v2K)5Q^=_^zjWob-;0ZVhCHkq7k252;z2Asr=nD}S3`&Elboza?RUt`%bk zQ`CF}k;97ILrSvBE(7qw2*|g$t;9!V{>Fz*Wm=cl&0AO-W)te0ztt{QD;umPWjLaSsPZvB|t#RcwStJ?eYGBJ}eWq(=KGTQR&Siq(l`UA& zIxSfQ%rRX9;-vKwdOyGLDNORfW(1RReZI;3j3R2nA5?NN!pjcA`~D%^f7sib?g7P1 zlw|7+gqwXGSO$1$QxXn1a)znohLE zX$6-dN9pO&1T~iX6Jbp8Zw3&MP*?3rg0L=s!>K<2^~i? zD~dB~V>Cho6hj{p(h^o~nn)EtKjxn-cOqP?)6$=EA2ZAueg`LApkQX$u6|P8dj{s7 z_|RZ|<755Kl5D4=zWoaB4JQ~LzpvSgV<$s*k6lopi3hG))nAyP4R)-7RObuZI^*^~8PG39eDJkE)gR<-YO z9}ES#*OyxN>IA{zv<)K@)Z2oc+3>?zIvjYXu1$g1y%47v#iZ1CZNzF>xj(Qee zsB(^>#x=W)wWD&&tJl6gsu!4BRO)Q%t>?NPpPneB(xo-ar(}b!X?O5VcQdzWY6|$k z7zrRlNYgIGb;5kVk5DI#@5zV-)`LF+<4^^_`SI(lUlWW}>4{M}& z&1ibie<-LHGMy8WeCO!-n~l^*1wo@Z@O*B-Vf@ zp>m(UOL%|gAntMe=G3_ancXxV#O=YAD$Z;%D?L>gBLV+^-S7E>dh*12Rxv-ML73n%f zN=i%T;qkHd;k&jLX!w{HqVcDn*473But0;IF+}3P)`}D=a!GqN;&N}&lZ(-_0I3gX z^HkVQFpEHRS+0uV@+&;ahElHj=H@-I(2KoAwnkd)qz_CW2&btT4zIB~0qsQKN}Deu z5C}M2P$Mt^&>4gR=Nn2KTaZYk?&6z?Ag0v?r*3o19Z>-tbi^rM$vkk=xHbpy-de8f zXY%d^c1_8Xv_5iIsPIZjW=_s8E7Y;MFiL99m4quKLt#B0LL8@)356=oG8xTJ#1lW| z#P}GWi=hRep?wu5q6l(`aHvjZ%v1|kryedDUVzl$Kob&VaZh#4VoOD_=GN95bk;NU Xzln?+?*ZUx7M4pohUW{<+1>dE;=6U$ literal 0 HcmV?d00001 From b087461838aa5bfaffaa514b17d96727b899dbd6 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 08:31:49 +1000 Subject: [PATCH 030/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 06c3bbd64f..db5755fbd9 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -131,7 +131,7 @@ These steps configure a filter that will only apply to devices running the Windo > [!NOTE] > Ensure you’ve selected OR as the operator in the right And/Or column - + :::image type="content" source="images/change-home-to-edu-windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: - Optionally select scope tags as required @@ -154,6 +154,9 @@ These steps create and assign a Windows edition upgrade policy. For more informa - Change **Edition to upgrade** to **Windows 10/11 Education** - In the **Product Key**, enter your *Windows 10/11 Education MAK* - Select **Next** + + :::image type="content" source="images/change-home-to-edu-windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: + - Optionally select scope tags as required and select **Next** - On the **assignments** screen; - Select **Add all devices** @@ -164,8 +167,6 @@ These steps create and assign a Windows edition upgrade policy. For more informa - Select the *Windows Home edition* filter you created earlier - Choose **Select** to save the filter selection - Select **Next** to progress to the next screen - - :::image type="content" source="images/change-home-to-edu-windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: - Don't configure any applicability rules and select **next** - Review your settings and select **Create** From 2db62d6aea3bfe3fb04e397804d594812884660f Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 08:32:24 +1000 Subject: [PATCH 031/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index db5755fbd9..cd47e31a47 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -161,8 +161,10 @@ These steps create and assign a Windows edition upgrade policy. For more informa - On the **assignments** screen; - Select **Add all devices** - Next to **All devices**, select **Edit filter** + > [!NOTE] > You can also target other security groups that contain a smaller scope of users or devices and apply the filter rather than All devices. + - Select to **Include filtered devices in assignment** - Select the *Windows Home edition* filter you created earlier - Choose **Select** to save the filter selection From 6d177d93845346d34fbfae5df94b26367bd56e91 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 09:02:19 +1000 Subject: [PATCH 032/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index cd47e31a47..2360d3e712 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -40,7 +40,7 @@ Device users can disconnect device management from Settings to prevent further a ## Why upgrade personal devices from Windows Home to Windows Education? -Some school institutions want to streamline student onboarding for personal devices using Mobile Device Management (MDM). Typical device management activities include installing certificates, configuring WiFi profiles and installing applications. On Windows, device management activities are performed using Configuration Service Providers (CSPs). Some CSPs aren't available on Windows Home, which can limit the management capabilities. Some of the CSPs not availble in Windows Home that can affect typical student onboarding are: +Some school institutions want to streamline student onboarding for personal devices using Mobile Device Management (MDM). Typical device management activities include installing certificates, configuring WiFi profiles and installing applications. On Windows, device management activities are performed using Configuration Service Providers (CSPs). Some CSPs aren't available on Windows Home, which can limit the management capabilities. Some of the CSPs not available in Windows Home that can affect typical student onboarding are: - [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications. - [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization. From 0a414e126491d175b03f3de3b095955a2113882a Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Wed, 6 Jul 2022 09:05:30 +1000 Subject: [PATCH 033/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 2360d3e712..926f372c58 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -59,10 +59,10 @@ You can find more information in the [Microsoft Product Terms](https://www.micro ## How the upgrade process works -IT admins with access to the VLSC or the Microsoft 365 Admin Center, can find their MAK for Windows Education and trigger an upgrade via Mobile Device Management or manually on devices. +IT admins with access to the VLSC or the Microsoft 365 Admin Center, can find their MAK for Windows Education and trigger an upgrade using Mobile Device Management or manually on devices. > [!WARNING] -> The MAK key is highly sensitive and should always be protected. Only authorized staff should be given access to the key and it should never be distributed to students or broadly to your organization in documentation or emails. +> The MAK is highly sensitive and should always be protected. Only authorized staff should be given access to the key and it should never be distributed to students or broadly to your organization in documentation or emails. ### Recommended methods for using a MAK @@ -79,7 +79,7 @@ It’s critical that MAKs are protected whenever they're used. The following pro ## Downgrading, resetting, reinstalling and graduation rights -After upgrading from Windows Home to Windows Education there are some considerations for what happens during downgrade, reset or re-install of the operating system. +After upgrading from *Windows Home* to *Windows Education* there are some considerations for what happens during downgrade, reset or re-install of the operating system. The table below highlights the differences by upgrade product key type: @@ -90,7 +90,7 @@ The table below highlights the differences by upgrade product key type: ### Downgrade -It is not possible to downgrade to Windows Home from Windows Education without reinstalling Windows. +It is not possible to downgrade to *Windows Home* from *Windows Education* without reinstalling Windows. ### Reset @@ -114,7 +114,7 @@ These steps provide instructions on how to use Microsoft Intune to upgrade devic ### Step 1: Create a Windows Home edition filter -These steps configure a filter that will only apply to devices running the Windows Home SKU. This will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune]/mem/intune/fundamentals/filters). +These steps configure a filter that will only apply to devices running the *Windows Home edition*. This will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune](/mem/intune/fundamentals/filters). - Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) - Go to **Tenant Administration** > **Filters** From fc46a1a12c9b618dec45e492b5094f2c4736247e Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Thu, 7 Jul 2022 10:59:32 +1000 Subject: [PATCH 034/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 36 ++++++++++++------------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 926f372c58..dc682baeb5 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -1,6 +1,6 @@ --- -title: Upgrade Windows Home to Windows Education on personal devices using volume licensing -description: Learn how IT Pros can upgrade personal devices from Windows Home to Windows Education using Mobile Device Management and qualifying subscriptions. +title: Upgrade Windows Home to Windows Education on student-owned devices +description: Learn how IT Pros can upgrade student-owned devices from Windows Home to Windows Education using Mobile Device Management or Kivuto OnTheHub with qualifying subscriptions. ms.date: 07/05/2021 ms.prod: windows ms.technology: windows @@ -13,24 +13,24 @@ manager: jeffbu ms.collection: highpri --- -# Upgrade Windows Home to Windows Education on personal devices using volume licensing +# Upgrade Windows Home to Windows Education on student-owned devices ## Overview -Customers with qualifying subscriptions can upgrade students personal (or institution-owned) devices from Windows Home to Windows Education, which is designed for both the classroom and remote learning. +Customers with qualifying subscriptions can upgrade both student-owned and institution-owned devices from *Windows Home* to *Windows Education*, which is designed for both the classroom and remote learning. > [!NOTE] > To be qualified for this process, customers must have a Windows Education subscription that includes the student use benefit and must have access to the Volume Licensing Service Center (VLSC) or the Microsoft 365 Admin Center. -IT staff can upgrade student devices using a multiple activation key (MAK). Alternatively, student devices can be upgraded by contacting [Kivuto OnTheHub](http://onthehub.com) to obtain a product key for their device. The table below provides the recommended approach for personal devices depending on the scenario. +IT admins can upgrade student devices using a multiple activation key (MAK) manually or through Mobile Device Management (MDM). Alternatively, IT admins can set up a portal through [Kivuto OnTheHub](http://onthehub.com) where students can request a *Windows Pro Education* upgrade product key. The table below provides the recommended approach depending on the scenario. -| Method | MAK source | Device ownership | Best for | +| Method | Product key source | Device ownership | Best for | |-|-|-|-| -| Mobile Device Management | VLSC | Personal | IT admin initiated via device management | -| Kivuto | Kivuto | Personal | Initiated on device by student, parent or guardian | -| Provisioning package | VLSC | Personal or Corporate | IT admin initiated at first boot | +| MDM | VLSC | Personal (student-owned) | IT admin initiated via MDM | +| Kivuto | Kivuto | Personal (student-owned) | Initiated on device by student, parent or guardian | +| Provisioning package | VLSC | Personal (student-owned) or Corporate (institution-owned) | IT admin initiated at first boot | -Devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Windows Education* or *Windows Enterprise* using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). +These methods apply to devices with *Windows Home* installed, institution-owned devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Windows Education* or *Windows Enterprise* using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). ## User Notifications @@ -38,9 +38,9 @@ Users aren't notified their device has been or will be upgraded to Windows Educa Device users can disconnect device management from Settings to prevent further actions from being taken on their personal device. For instructions on disconnecting from device management, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). -## Why upgrade personal devices from Windows Home to Windows Education? +## Why upgrade student-owned devices from Windows Home to Windows Education? -Some school institutions want to streamline student onboarding for personal devices using Mobile Device Management (MDM). Typical device management activities include installing certificates, configuring WiFi profiles and installing applications. On Windows, device management activities are performed using Configuration Service Providers (CSPs). Some CSPs aren't available on Windows Home, which can limit the management capabilities. Some of the CSPs not available in Windows Home that can affect typical student onboarding are: +Some school institutions want to streamline student onboarding for student-owned devices using MDM. Typical MDM requirements include installing certificates, configuring WiFi profiles and installing applications. On Windows, MDM users Configuration Service Providers (CSPs) to configure settings. Some CSPs aren't available on Windows Home, which can limit the capabilities. Some of the CSPs not available in Windows Home that can affect typical student onboarding are: - [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications. - [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization. @@ -75,7 +75,7 @@ It’s critical that MAKs are protected whenever they're used. The following pro > If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key isn't accessible by students. - Operating System Deployment processes with tools such as Microsoft Deployment Toolkit or Microsoft Endpoint Configuration Manager. - For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](/windows/deployment/upgrade/windows-10-edition-upgrades). +For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](/windows/deployment/upgrade/windows-10-edition-upgrades). ## Downgrading, resetting, reinstalling and graduation rights @@ -83,10 +83,10 @@ After upgrading from *Windows Home* to *Windows Education* there are some consid The table below highlights the differences by upgrade product key type: -|MAK Type|Downgrade|Reset|Student re-install| +| Product Key Type | Downgrade (in-place) | Reset | Student re-install | |-|-|-|-| -|MAK from VLSC|No|Yes|No| -|MAK from Kivuto|No|Yes|Yes| +| VLSC | No | Yes | No | +| Kivuto OnTheHub | No | Yes | Yes | ### Downgrade @@ -108,7 +108,7 @@ For details on product keys and reinstalling Windows, see [Find your Windows pro The license will remain installed on the device if resold and the same conditions above apply for downgrade, reset or reinstall. -## Step by step process for customers to upgrade personal devices using Microsoft Intune +## Step by step process for customers to upgrade student-owned devices using Microsoft Intune These steps provide instructions on how to use Microsoft Intune to upgrade devices from Home to Education. @@ -215,7 +215,7 @@ A multiple activation key activates either individual computers or a group of co | Scenario | Ownership | MAK | KMS | AD based activation | Subscription Activation | |-|-|:-:|:-:|:-:|:-:| -| **Workplace join (add work or school account)** | Personal | X | | | | +| **Workplace join (add work or school account)** | Personal (or student-owned) | X | | | | | **Azure Active Directory Join** | Organization | X | X | | X | | **Hybrid Azure AD Join** | Organization | X | X | X | X | From 1e3440c4cdc95153b571166c7069e45978cad077 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Thu, 7 Jul 2022 11:10:54 +1000 Subject: [PATCH 035/109] Update TOC.yml --- education/windows/TOC.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/TOC.yml b/education/windows/TOC.yml index 2f49cce168..f2d04a9792 100644 --- a/education/windows/TOC.yml +++ b/education/windows/TOC.yml @@ -65,7 +65,7 @@ href: s-mode-switch-to-edu.md - name: Change to Windows 10 Pro Education from Windows 10 Pro href: change-to-pro-education.md - - name: Upgrade Windows Home to Windows Education on personal devices using volume licensing + - name: Upgrade Windows Home to Windows Education on student-owned devices href: change-home-to-edu.md - name: Chromebook migration guide href: chromebook-migration-guide.md From 56bc7d37b09943e87a2d69a216da3017494d5079 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Thu, 7 Jul 2022 11:14:11 +1000 Subject: [PATCH 036/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index dc682baeb5..aa25b98b28 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -17,12 +17,12 @@ ms.collection: highpri ## Overview -Customers with qualifying subscriptions can upgrade both student-owned and institution-owned devices from *Windows Home* to *Windows Education*, which is designed for both the classroom and remote learning. +Customers with qualifying subscriptions can upgrade student-owned and institution-owned devices from *Windows Home* to *Windows Education*, which is designed for both the classroom and remote learning. > [!NOTE] > To be qualified for this process, customers must have a Windows Education subscription that includes the student use benefit and must have access to the Volume Licensing Service Center (VLSC) or the Microsoft 365 Admin Center. -IT admins can upgrade student devices using a multiple activation key (MAK) manually or through Mobile Device Management (MDM). Alternatively, IT admins can set up a portal through [Kivuto OnTheHub](http://onthehub.com) where students can request a *Windows Pro Education* upgrade product key. The table below provides the recommended approach depending on the scenario. +IT admins can upgrade student devices using a multiple activation key (MAK) manually or through Mobile Device Management (MDM). Alternatively, IT admins can set up a portal through [Kivuto OnTheHub](http://onthehub.com) where students can request a *Windows Pro Education* product key. The table below provides the recommended method depending on the scenario. | Method | Product key source | Device ownership | Best for | |-|-|-|-| @@ -34,9 +34,9 @@ These methods apply to devices with *Windows Home* installed, institution-owned ## User Notifications -Users aren't notified their device has been or will be upgraded to Windows Education when using device management. It's the responsibility of the institution to notify their users. Instituions should notify their users that device management will initiate an upgrade to Windows Education and this will give the institution extra capabilities, such as installing applications. +Users aren't notified their device has been or will be upgraded to Windows Education when using MDM. It's the responsibility of the institution to notify their users. Instituions should notify their users that MDM will initiate an upgrade to Windows Education and this will give the institution extra capabilities, such as installing applications. -Device users can disconnect device management from Settings to prevent further actions from being taken on their personal device. For instructions on disconnecting from device management, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). +Device users can disconnect MDM in the Settings app to prevent further actions from being taken on their personal device. For instructions on disconnecting from MDM, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). ## Why upgrade student-owned devices from Windows Home to Windows Education? From d9e00e51b53116b45cf29c707230167317b6bab6 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Thu, 7 Jul 2022 11:18:12 +1000 Subject: [PATCH 037/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index aa25b98b28..a3600773ff 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -34,7 +34,7 @@ These methods apply to devices with *Windows Home* installed, institution-owned ## User Notifications -Users aren't notified their device has been or will be upgraded to Windows Education when using MDM. It's the responsibility of the institution to notify their users. Instituions should notify their users that MDM will initiate an upgrade to Windows Education and this will give the institution extra capabilities, such as installing applications. +Users aren't notified their device has been or will be upgraded to Windows Education when using MDM. It's the responsibility of the institution to notify their users. Institutions should notify their users that MDM will initiate an upgrade to Windows Education and this upgrade will give the institution extra capabilities, such as installing applications. Device users can disconnect MDM in the Settings app to prevent further actions from being taken on their personal device. For instructions on disconnecting from MDM, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). @@ -79,18 +79,18 @@ For a full list of methods to perform a Windows edition upgrade and more details ## Downgrading, resetting, reinstalling and graduation rights -After upgrading from *Windows Home* to *Windows Education* there are some considerations for what happens during downgrade, reset or re-install of the operating system. +After upgrading from *Windows Home* to *Windows Education* there are some considerations for what happens during downgrade, reset or reinstall of the operating system. The table below highlights the differences by upgrade product key type: -| Product Key Type | Downgrade (in-place) | Reset | Student re-install | +| Product Key Type | Downgrade (in-place) | Reset | Student reinstall | |-|-|-|-| | VLSC | No | Yes | No | | Kivuto OnTheHub | No | Yes | Yes | ### Downgrade -It is not possible to downgrade to *Windows Home* from *Windows Education* without reinstalling Windows. +It isn't possible to downgrade to *Windows Home* from *Windows Education* without reinstalling Windows. ### Reset @@ -98,7 +98,7 @@ If the computer is reset, Windows Education will be retained. ### Reinstall -The Education upgrade does not apply to reinstalling Windows. Use the original Windows edition when reinstalling Windows. The original product key or [firmware-embedded product key](#what-is-a-firmware-embedded-activation-key) will be used to activate Windows. +The Education upgrade doesn't apply to reinstalling Windows. Use the original Windows edition when reinstalling Windows. The original product key or [firmware-embedded product key](#what-is-a-firmware-embedded-activation-key) will be used to activate Windows. If students require a *Windows Pro Education* key that can work on a new install of Windows, they should use [Kivuto OnTheHub](http://onthehub.com) to request a key prior to graduation. @@ -114,7 +114,7 @@ These steps provide instructions on how to use Microsoft Intune to upgrade devic ### Step 1: Create a Windows Home edition filter -These steps configure a filter that will only apply to devices running the *Windows Home edition*. This will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune](/mem/intune/fundamentals/filters). +These steps configure a filter that will only apply to devices running the *Windows Home edition*. This filter will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune](/mem/intune/fundamentals/filters). - Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) - Go to **Tenant Administration** > **Filters** @@ -193,13 +193,13 @@ You can check the Windows versions of managed devices in the Microsoft Endpoint Increases to MAK Activation quantity can be requested by contacting [VLSC support](/licensing/contact-us) and may be granted by exception. A request can be made by accounts with the VLSC Administrator, Key Administrator, or Key Viewer permissions. The request should include the following information: - Agreement/Enrollment Number or License ID and Authorization. - Product Name (includes version and edition). -- Last 5 characters of the product key. +- Last five characters of the product key. - The number of host activations required. - Business Justification or Reason for Deployment. ### What is a firmware-embedded activation key? -A firmware-embedded activation key is a Windows product key that is installed into the firmware of your device to allow for easy activation of Windows. To determine if the computer has a firmware-embedded activation key, type the following command at an elevated Windows PowerShell prompt: +A firmware-embedded activation key is a Windows product key that is installed into the firmware of your device. The embedded key makes it easier to install and activate Windows. To determine if the computer has a firmware-embedded activation key, type the following command at an elevated Windows PowerShell prompt: ```powershell (Get-CimInstance -query 'select * from SoftwareLicensingService').OA3xOriginalProductKey @@ -207,7 +207,7 @@ A firmware-embedded activation key is a Windows product key that is installed in If the device has a firmware-embedded activation key, it will be displayed in the output. Otherwise, the device doesn't have a firmware embedded activation key. Most OEM-provided devices designed to run Windows 8 or later will have a firmware-embedded key. -A firmware embedded key is only required to upgrade using Subscription Activation, a MAK upgrade dosn't require the firmware embedded key. +A firmware embedded key is only required to upgrade using Subscription Activation, a MAK upgrade doesn't require the firmware embedded key. ### What is a multiple activation key and how does it differ from using KMS, Active Directory based activation or Subscription Activation? From 213b1878184264f103516372088071dc302e6ced Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Fri, 8 Jul 2022 13:29:29 +0530 Subject: [PATCH 038/109] Acrolinx Enhancement Effort --- ...indows-sandbox-configure-using-wsb-file.md | 32 +++++----- .../windows-sandbox-overview.md | 2 +- .../get-support-for-security-baselines.md | 6 +- .../security-compliance-toolkit-10.md | 6 +- .../windows-security-baselines.md | 18 +++--- windows/security/trusted-boot.md | 2 +- .../zero-trust-windows-device-health.md | 16 ++--- .../ltsc/whats-new-windows-10-2015.md | 42 +++++++------- .../ltsc/whats-new-windows-10-2016.md | 24 ++++---- .../ltsc/whats-new-windows-10-2019.md | 4 +- .../ltsc/whats-new-windows-10-2021.md | 38 ++++++------ ...ts-new-windows-10-version-1507-and-1511.md | 58 +++++++++---------- .../whats-new-windows-10-version-1607.md | 24 ++++---- .../whats-new-windows-10-version-1703.md | 44 +++++++------- .../whats-new-windows-10-version-1709.md | 8 +-- .../whats-new-windows-10-version-1803.md | 30 +++++----- .../whats-new-windows-10-version-1809.md | 56 +++++++++--------- .../whats-new-windows-10-version-1903.md | 42 +++++++------- 18 files changed, 226 insertions(+), 226 deletions(-) diff --git a/windows/security/threat-protection/windows-sandbox/windows-sandbox-configure-using-wsb-file.md b/windows/security/threat-protection/windows-sandbox/windows-sandbox-configure-using-wsb-file.md index 94adc3d7c8..830b23c793 100644 --- a/windows/security/threat-protection/windows-sandbox/windows-sandbox-configure-using-wsb-file.md +++ b/windows/security/threat-protection/windows-sandbox/windows-sandbox-configure-using-wsb-file.md @@ -21,7 +21,7 @@ A configuration file enables the user to control the following aspects of Window - **vGPU (virtualized GPU)**: Enable or disable the virtualized GPU. If vGPU is disabled, the sandbox will use Windows Advanced Rasterization Platform (WARP). - **Networking**: Enable or disable network access within the sandbox. -- **Mapped folders**: Share folders from the host with *read* or *write* permissions. Note that exposing host directories may allow malicious software to affect the system or steal data. +- **Mapped folders**: Share folders from the host with *read* or *write* permissions. Exposing host directories may allow malicious software to affect the system or steal data. - **Logon command**: A command that's executed when Windows Sandbox starts. - **Audio input**: Shares the host's microphone input into the sandbox. - **Video input**: Shares the host's webcam input into the sandbox. @@ -32,9 +32,9 @@ A configuration file enables the user to control the following aspects of Window ## Creating a configuration file -To create a simple configuration file: +To create a configuration file: -1. Open a plain text editor or source code editor (e.g. Notepad, Visual Studio Code, etc.) +1. Open a plain text editor or source code editor (for example, Notepad, Visual Studio Code, etc.) 2. Insert the following lines: ```XML @@ -43,7 +43,7 @@ To create a simple configuration file: ``` 3. Add appropriate configuration text between the two lines. For details, see the correct syntax and the examples below. -4. Save the file with the desired name, but make sure its filename extension is `.wsb`. In Notepad, you should enclose the filename and the extension inside double quotation marks, e.g. `"My config file.wsb"`. +4. Save the file with the desired name, but make sure its filename extension is `.wsb`. In Notepad, you should enclose the filename and the extension inside double quotation marks, for example, `"My config file.wsb"`. ## Using a configuration file @@ -65,7 +65,7 @@ Supported values: - *Enable*: Enables vGPU support in the sandbox. - *Disable*: Disables vGPU support in the sandbox. If this value is set, the sandbox will use software rendering, which may be slower than virtualized GPU. -- *Default* This is the default value for vGPU support. Currently this means vGPU is disabled. +- *Default* This value is the default value for vGPU support. Currently, this default value denotes that vGPU is disabled. > [!NOTE] > Enabling virtualized GPU can potentially increase the attack surface of the sandbox. @@ -78,14 +78,14 @@ Enables or disables networking in the sandbox. You can disable network access to Supported values: - *Disable*: Disables networking in the sandbox. -- *Default*: This is the default value for networking support. This value enables networking by creating a virtual switch on the host and connects the sandbox to it via a virtual NIC. +- *Default*: This value is the default value for networking support. This value enables networking by creating a virtual switch on the host and connects the sandbox to it via a virtual NIC. > [!NOTE] > Enabling networking can expose untrusted applications to the internal network. ### Mapped folders -An array of folders, each representing a location on the host machine that will be shared into the sandbox at the specified path. At this time, relative paths are not supported. If no path is specified, the folder will be mapped to the container user's desktop. +An array of folders, each representing a location on the host machine that will be shared into the sandbox at the specified path. At this time, relative paths aren't supported. If no path is specified, the folder will be mapped to the container user's desktop. ```xml @@ -100,7 +100,7 @@ An array of folders, each representing a location on the host machine that will ``` -*HostFolder*: Specifies the folder on the host machine to share into the sandbox. Note that the folder must already exist on the host, or the container will fail to start. +*HostFolder*: Specifies the folder on the host machine to share into the sandbox. The folder must already exist on the host, or the container will fail to start. *SandboxFolder*: Specifies the destination in the sandbox to map the folder to. If the folder doesn't exist, it will be created. If no sandbox folder is specified, the folder will be mapped to the container desktop. @@ -120,7 +120,7 @@ Specifies a single command that will be invoked automatically after the sandbox ``` -*Command*: A path to an executable or script inside the container that will be executed after login. +*Command*: A path to an executable or script inside the container that will be executed after signing in. > [!NOTE] > Although very simple commands will work (such as launching an executable or script), more complicated scenarios involving multiple steps should be placed into a script file. This script file may be mapped into the container via a shared folder, and then executed via the *LogonCommand* directive. @@ -134,7 +134,7 @@ Enables or disables audio input to the sandbox. Supported values: - *Enable*: Enables audio input in the sandbox. If this value is set, the sandbox will be able to receive audio input from the user. Applications that use a microphone may require this capability. - *Disable*: Disables audio input in the sandbox. If this value is set, the sandbox can't receive audio input from the user. Applications that use a microphone may not function properly with this setting. -- *Default*: This is the default value for audio input support. Currently this means audio input is enabled. +- *Default*: This value is the default value for audio input support. Currently, this default value denotes that audio input is enabled. > [!NOTE] > There may be security implications of exposing host audio input to the container. @@ -148,21 +148,21 @@ Enables or disables video input to the sandbox. Supported values: - *Enable*: Enables video input in the sandbox. - *Disable*: Disables video input in the sandbox. Applications that use video input may not function properly in the sandbox. -- *Default*: This is the default value for video input support. Currently this means video input is disabled. Applications that use video input may not function properly in the sandbox. +- *Default*: This value is the default value for video input support. Currently, this default value denotes that video input is disabled. Applications that use video input may not function properly in the sandbox. > [!NOTE] > There may be security implications of exposing host video input to the container. ### Protected client -Applies additional security settings to the sandbox Remote Desktop client, decreasing its attack surface. +Applies more security settings to the sandbox Remote Desktop client, decreasing its attack surface. `value` Supported values: - *Enable*: Runs Windows sandbox in Protected Client mode. If this value is set, the sandbox runs with extra security mitigations enabled. - *Disable*: Runs the sandbox in standard mode without extra security mitigations. -- *Default*: This is the default value for Protected Client mode. Currently, this means the sandbox doesn't run in Protected Client mode. +- *Default*: This value is the default value for Protected Client mode. Currently, this default value denotes that the sandbox doesn't run in Protected Client mode. > [!NOTE] > This setting may restrict the user's ability to copy/paste files in and out of the sandbox. @@ -176,7 +176,7 @@ Enables or disables printer sharing from the host into the sandbox. Supported values: - *Enable*: Enables sharing of host printers into the sandbox. - *Disable*: Disables printer redirection in the sandbox. If this value is set, the sandbox can't view printers from the host. -- *Default*: This is the default value for printer redirection support. Currently this means printer redirection is disabled. +- *Default*: This value is the default value for printer redirection support. Currently, this default value denotes that printer redirection is disabled. ### Clipboard redirection @@ -186,7 +186,7 @@ Enables or disables sharing of the host clipboard with the sandbox. Supported values: - *Disable*: Disables clipboard redirection in the sandbox. If this value is set, copy/paste in and out of the sandbox will be restricted. -- *Default*: This is the default value for clipboard redirection. Currently copy/paste between the host and sandbox are permitted under *Default*. +- *Default*: This value is the default value for clipboard redirection. Currently, copy/paste between the host and sandbox are permitted under *Default*. ### Memory in MB @@ -197,7 +197,7 @@ Specifies the amount of memory that the sandbox can use in megabytes (MB). If the memory value specified is insufficient to boot a sandbox, it will be automatically increased to the required minimum amount. ## Example 1 -The following config file can be used to easily test downloaded files inside the sandbox. To achieve this, networking and vGPU are disabled, and the sandbox is allowed read-only access to the shared downloads folder. For convenience, the logon command opens the downloads folder inside the sandbox when it's started. +The following config file can be used to easily test the downloaded files inside the sandbox. To achieve this testing, networking and vGPU are disabled, and the sandbox is allowed read-only access to the shared downloads folder. For convenience, the logon command opens the downloads folder inside the sandbox when it's started. ### Downloads.wsb diff --git a/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md b/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md index ec43ba1f84..ec211848d1 100644 --- a/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md +++ b/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md @@ -60,7 +60,7 @@ The following video provides an overview of Windows Sandbox. 3. Use the search bar on the task bar and type **Turn Windows Features on or off** to access the Windows Optional Features tool. Select **Windows Sandbox** and then **OK**. Restart the computer if you're prompted. - If the **Windows Sandbox** option is unavailable, your computer doesn't meet the requirements to run Windows Sandbox. If you think this is incorrect, review the prerequisite list as well as steps 1 and 2. + If the **Windows Sandbox** option is unavailable, your computer doesn't meet the requirements to run Windows Sandbox. If you think this analysis is incorrect, review the prerequisite list and steps 1 and 2. > [!NOTE] > To enable Sandbox using PowerShell, open PowerShell as Administrator and run **Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online**. diff --git a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md index 42b2cb57a7..5e0c376121 100644 --- a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md +++ b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md @@ -17,7 +17,7 @@ ms.technology: windows-sec **What is the Microsoft Security Compliance Manager (SCM)?** -The Security Compliance Manager (SCM) is now retired and is no longer supported. The reason is that SCM was an incredibly complex and large program that needed to be updated for every Windows release. It has been replaced by the Security Compliance Toolkit (SCT). To provide a better service for our customers, we have moved to SCT with which we can publish baselines through the Microsoft Download Center in a lightweight .zip file that contains GPO Backups, GPO reports, Excel spreadsheets, WMI filters, and scripts to apply the settings to local policy. +The Security Compliance Manager (SCM) is now retired and is no longer supported. The reason is that SCM was an incredibly complex and large program that needed to be updated for every Windows release. It has been replaced by the Security Compliance Toolkit (SCT). To provide a better service for our customers, we've moved to SCT with which we can publish baselines through the Microsoft Download Center in a lightweight .zip file that contains GPO Backups, GPO reports, Excel spreadsheets, WMI filters, and scripts to apply the settings to local policy. More information about this change can be found on the [Microsoft Security Guidance blog](/archive/blogs/secguide/security-compliance-manager-scm-retired-new-tools-and-procedures). @@ -32,7 +32,7 @@ Any version of Windows baseline before Windows 10 1703 can still be downloaded u **What file formats are supported by the new SCT?** -The toolkit supports formats created by the Windows GPO backup feature (.pol, .inf, and .csv). Policy Analyzer saves its data in XML files with a .PolicyRules file extension. LGPO also supports its own LGPO text file format as a text-based analog for the binary registry.pol file format. See the LGPO documentation for more information. Keep in mind that SCM’s .cab files are no longer supported. +The toolkit supports formats created by the Windows GPO backup feature (.pol, .inf, and .csv). Policy Analyzer saves its data in XML files with a .PolicyRules file extension. LGPO also supports its own LGPO text file format as a text-based analog for the binary registry.pol file format. For more information, see the LGPO documentation. Keep in mind that SCMs' .cab files are no longer supported. **Does SCT support Desired State Configuration (DSC) file format?** @@ -44,7 +44,7 @@ No. A potential alternative is Desired State Configuration (DSC), a feature of t **Does SCT support the creation of Security Content Automation Protocol (SCAP)-format policies?** -No. SCM supported only SCAP 1.0, which was not updated as SCAP evolved. The new toolkit likewise does not include SCAP support. +No. SCM supported only SCAP 1.0, which wasn't updated as SCAP evolved. The new toolkit likewise doesn't include SCAP support.
    diff --git a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md index f1ca17ad61..1a2434ffeb 100644 --- a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md +++ b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md @@ -54,7 +54,7 @@ The Security Compliance Toolkit consists of: - GPO to Policy Rules -You can [download the tools](https://www.microsoft.com/download/details.aspx?id=55319) along with the baselines for the relevant Windows versions. For more details about security baseline recommendations, see the [Microsoft Security Guidance blog](/archive/blogs/secguide/). +You can [download the tools](https://www.microsoft.com/download/details.aspx?id=55319) along with the baselines for the relevant Windows versions. For more information about security baseline recommendations, see the [Microsoft Security Guidance blog](/archive/blogs/secguide/). ## What is the Policy Analyzer tool? @@ -64,7 +64,7 @@ The Policy Analyzer is a utility for analyzing and comparing sets of Group Polic - Compare GPOs against current local policy and local registry settings - Export results to a Microsoft Excel spreadsheet -Policy Analyzer lets you treat a set of GPOs as a single unit. This makes it easy to determine whether particular settings are duplicated across the GPOs or are set to conflicting values. Policy Analyzer also lets you capture a baseline and then compare it to a snapshot taken at a later time to identify changes anywhere across the set. +Policy Analyzer lets you treat a set of GPOs as a single unit. This treatment makes it easy to determine whether particular settings are duplicated across the GPOs or are set to conflicting values. Policy Analyzer also lets you capture a baseline and then compare it to a snapshot taken at a later time to identify changes anywhere across the set. More information on the Policy Analyzer tool can be found on the [Microsoft Security Guidance blog](/archive/blogs/secguide/new-tool-policy-analyzer) or by [downloading the tool](https://www.microsoft.com/download/details.aspx?id=55319). @@ -72,7 +72,7 @@ More information on the Policy Analyzer tool can be found on the [Microsoft Secu LGPO.exe is a command-line utility that is designed to help automate management of Local Group Policy. Using local policy gives administrators a simple way to verify the effects of Group Policy settings, and is also useful for managing non-domain-joined systems. -LGPO.exe can import and apply settings from Registry Policy (Registry.pol) files, security templates, Advanced Auditing backup files, as well as from formatted “LGPO text” files. +LGPO.exe can import and apply settings from Registry Policy (Registry.pol) files, security templates, Advanced Auditing backup files, and from formatted “LGPO text” files. It can export local policy to a GPO backup. It can export the contents of a Registry Policy file to the “LGPO text” format that can then be edited, and can build a Registry Policy file from an LGPO text file. diff --git a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md index 18cb5242f6..e37c61bea7 100644 --- a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md +++ b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md @@ -22,13 +22,13 @@ Microsoft is dedicated to providing its customers with secure operating systems, Even though Windows and Windows Server are designed to be secure out-of-the-box, many organizations still want more granular control over their security configurations. To navigate the large number of controls, organizations need guidance on configuring various security features. Microsoft provides this guidance in the form of security baselines. -We recommend that you implement an industry-standard configuration that is broadly known and well-tested, such as Microsoft security baselines, as opposed to creating a baseline yourself. This helps increase flexibility and reduce costs. +We recommend that you implement an industry-standard configuration that is broadly known and well-tested, such as Microsoft security baselines, as opposed to creating a baseline yourself. This industry-standard configuration helps increase flexibility and reduce costs. -Here is a good blog about [Sticking with Well-Known and Proven Solutions](/archive/blogs/fdcc/sticking-with-well-known-and-proven-solutions). +Here's a good blog about [Sticking with Well-Known and Proven Solutions](/archive/blogs/fdcc/sticking-with-well-known-and-proven-solutions). ## What are security baselines? -Every organization faces security threats. However, the types of security threats that are of most concern to one organization can be completely different from another organization. For example, an e-commerce company may focus on protecting its Internet-facing web apps, while a hospital may focus on protecting confidential patient information. The one thing that all organizations have in common is a need to keep their apps and devices secure. These devices must be compliant with the security standards (or security baselines) defined by the organization. +Every organization faces security threats. However, the types of security threats that are of most concern to one organization can be different from another organization. For example, an e-commerce company may focus on protecting its Internet-facing web apps, while a hospital may focus on protecting confidential patient information. The one thing that all organizations have in common is a need to keep their apps and devices secure. These devices must be compliant with the security standards (or security baselines) defined by the organization. A security baseline is a group of Microsoft-recommended configuration settings that explains their security impact. These settings are based on feedback from Microsoft security engineering teams, product groups, partners, and customers. @@ -36,17 +36,17 @@ A security baseline is a group of Microsoft-recommended configuration settings t Security baselines are an essential benefit to customers because they bring together expert knowledge from Microsoft, partners, and customers. -For example, there are over 3,000 Group Policy settings for Windows 10, which does not include over 1,800 Internet Explorer 11 settings. Of these 4,800 settings, only some are security-related. Although Microsoft provides extensive guidance on different security features, exploring each one can take a long time. You would have to determine the security impact of each setting on your own. Then, you would still need to determine the appropriate value for each setting. +For example, there are over 3,000 Group Policy settings for Windows 10, which doesn't include over 1,800 Internet Explorer 11 settings. Of these 4,800 settings, only some are security-related. Although Microsoft provides extensive guidance on different security features, exploring each one can take a long time. You would have to determine the security impact of each setting on your own. Then, you would still need to determine the appropriate value for each setting. In modern organizations, the security threat landscape is constantly evolving, and IT pros and policy-makers must keep up with security threats and make required changes to security settings to help mitigate these threats. To enable faster deployments and make managing Microsoft products easier, Microsoft provides customers with security baselines that are available in consumable formats, such as Group Policy Objects Backups. ## Baseline principles Our recommendations follow a streamlined and efficient approach to baseline definitions. The foundation of that approach is essentially: -- The baselines are designed for well-managed, security-conscious organizations in which standard end users do not have administrative rights. -- A baseline enforces a setting only if it mitigates a contemporary security threat and does not cause operational issues that are worse than the risks they mitigate. -- A baseline enforces a default only if it is otherwise likely to be set to an insecure state by an authorized user: +- The baselines are designed for well-managed, security-conscious organizations in which standard end users don't have administrative rights. +- A baseline enforces a setting only if it mitigates a contemporary security threat and doesn't cause operational issues that are worse than the risks they mitigate. +- A baseline enforces a default only if it's otherwise likely to be set to an insecure state by an authorized user: - If a non-administrator can set an insecure state, enforce the default. - - If setting an insecure state requires administrative rights, enforce the default only if it is likely that a misinformed administrator will otherwise choose poorly. + - If setting an insecure state requires administrative rights, enforce the default only if it's likely that a misinformed administrator will otherwise choose poorly. ## How can you use security baselines? @@ -60,7 +60,7 @@ There are several ways to get and use security baselines: 1. You can download the security baselines from the [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=55319). This download page is for the Security Compliance Toolkit (SCT), which comprises tools that can assist admins in managing baselines in addition to the security baselines. The security baselines are included in the [Security Compliance Toolkit (SCT)](security-compliance-toolkit-10.md), which can be downloaded from the Microsoft Download Center. The SCT also includes tools to help admins manage the security baselines. You can also [Get Support for the security baselines](get-support-for-security-baselines.md) -2. [MDM (Mobile Device Management) security baselines](/windows/client-management/mdm/#mdm-security-baseline) function like the Microsoft group policy-based security baselines and can easily integrate this into an existing MDM management tool. +2. [MDM (Mobile Device Management) security baselines](/windows/client-management/mdm/#mdm-security-baseline) function like the Microsoft group policy-based security baselines and can easily integrate these baselines into an existing MDM management tool. 3. MDM Security baselines can easily be configures in Microsoft Endpoint Manager on devices that run Windows 10 and 11. The following article provides the detail steps: [Windows MDM (Mobile Device Management) baselines](/mem/intune/protect/security-baseline-settings-mdm-all). diff --git a/windows/security/trusted-boot.md b/windows/security/trusted-boot.md index a0e24a1035..409613d466 100644 --- a/windows/security/trusted-boot.md +++ b/windows/security/trusted-boot.md @@ -25,7 +25,7 @@ Secure Boot and Trusted Boot help prevent malware and corrupted components from The first step in protecting the operating system is to ensure that it boots securely after the initial hardware and firmware boot sequences have safely finished their early boot sequences. Secure Boot makes a safe and trusted path from the Unified Extensible Firmware Interface (UEFI) through the Windows kernel's Trusted Boot sequence. Malware attacks on the Windows boot sequence are blocked by the signature-enforcement handshakes throughout the boot sequence between the UEFI, bootloader, kernel, and application environments. -As the PC begins the boot process, it will first verify that the firmware is digitally signed, reducing the risk of firmware rootkits. Secure Boot then checks all code that runs before the operating system and checks the OS bootloader’s digital signature to ensure that it is trusted by the Secure Boot policy and hasn’t been tampered with. +As the PC begins the boot process, it will first verify that the firmware is digitally signed, reducing the risk of firmware rootkits. Secure Boot then checks all code that runs before the operating system and checks the OS bootloader’s digital signature to ensure that it's trusted by the Secure Boot policy and hasn’t been tampered with. ## Trusted Boot diff --git a/windows/security/zero-trust-windows-device-health.md b/windows/security/zero-trust-windows-device-health.md index f042c1d12b..4cea2b5834 100644 --- a/windows/security/zero-trust-windows-device-health.md +++ b/windows/security/zero-trust-windows-device-health.md @@ -25,11 +25,11 @@ The [Zero Trust](https://www.microsoft.com/security/business/zero-trust) princip The Zero Trust concept of **verify explicitly** applies to the risks introduced by both devices and users. Windows enables **device health attestation** and **conditional access** capabilities, which are used to grant access to corporate resources. -[Conditional access](/azure/active-directory/conditional-access/overview) evaluates identity signals to confirm that users are who they say they are before they are granted access to corporate resources. +[Conditional access](/azure/active-directory/conditional-access/overview) evaluates identity signals to confirm that users are who they say they are before they're granted access to corporate resources. -Windows 11 supports device health attestation, helping to confirm that devices are in a good state and have not been tampered with. This capability helps users access corporate resources whether they’re in the office, at home, or when they’re traveling. +Windows 11 supports device health attestation, helping to confirm that devices are in a good state and haven't been tampered with. This capability helps users access corporate resources whether they’re in the office, at home, or when they’re traveling. -Attestation helps verify the identity and status of essential components and that the device, firmware, and boot process have not been altered. Information about the firmware, boot process, and software, is used to validate the security state of the device. This information is cryptographically stored in the security co-processor Trusted Platform Module (TPM). Once the device is attested, it can be granted access to resources. +Attestation helps verify the identity and status of essential components and that the device, firmware, and boot process haven't been altered. Information about the firmware, boot process, and software, is used to validate the security state of the device. This information is cryptographically stored in the security co-processor Trusted Platform Module (TPM). Once the device is attested, it can be granted access to resources. ## Device health attestation on Windows Many security risks can emerge during the boot process as this process can be the most privileged component of the whole system. The verification process uses remote attestation as the secure channel to determine and present the device’s health. Remote attestation determines: @@ -38,23 +38,23 @@ Attestation helps verify the identity and status of essential components and tha - If the operating system booted correctly - If the OS has the right set of security features enabled -These determinations are made with the help of a secure root of trust using the Trusted Platform Module (TPM). Devices can attest that the TPM is enabled, and that the device has not been tampered with. +These determinations are made with the help of a secure root of trust using the Trusted Platform Module (TPM). Devices can attest that the TPM is enabled, and that the device hasn't been tampered with. -Windows includes many security features to help protect users from malware and attacks. However, trusting the Windows security components can only be achieved if the platform boots as expected and was not tampered with. Windows relies on Unified Extensible Firmware Interface (UEFI) Secure Boot, Early-launch antimalware (ELAM), Dynamic Root of Trust for Measurement (DRTM), Trusted Boot, and other low-level hardware and firmware security features. When you power on your PC until your anti-malware starts, Windows is backed with the appropriate hardware configuration to help keep you safe. [Measured and Trusted boot](information-protection/secure-the-windows-10-boot-process.md), implemented by bootloaders and BIOS, verifies and cryptographically records each step of the boot in a chained manner. These events are bound to a security coprocessor (TPM) that acts as the Root of Trust. Remote Attestation is the mechanism by which these events are read and verified by a service to provide a verifiable, unbiased, and tamper resilient report. Remote attestation is the trusted auditor of your system's boot, allowing specific entities to trust the device. +Windows includes many security features to help protect users from malware and attacks. However, trusting the Windows security components can only be achieved if the platform boots as expected and wasn't tampered with. Windows relies on Unified Extensible Firmware Interface (UEFI) Secure Boot, Early-launch antimalware (ELAM), Dynamic Root of Trust for Measurement (DRTM), Trusted Boot, and other low-level hardware and firmware security features. When you power on your PC until your anti-malware starts, Windows is backed with the appropriate hardware configuration to help keep you safe. [Measured and Trusted boot](information-protection/secure-the-windows-10-boot-process.md), implemented by bootloaders and BIOS, verifies and cryptographically records each step of the boot in a chained manner. These events are bound to a security coprocessor (TPM) that acts as the Root of Trust. Remote Attestation is the mechanism by which these events are read and verified by a service to provide a verifiable, unbiased, and tamper resilient report. Remote attestation is the trusted auditor of your system's boot, allowing specific entities to trust the device. A summary of the steps involved in attestation and Zero Trust on the device side are as follows: 1. During each step of the boot process, such as a file load, update of special variables, and more, information such as file hashes and signature are measured in the TPM PCRs. The measurements are bound by a [Trusted Computing Group specification](https://trustedcomputinggroup.org/resource/pc-client-platform-tpm-profile-ptp-specification/) (TCG) that dictates what events can be recorded and the format of each event. -2. Once Windows has booted, the attestor/verifier requests the TPM to fetch the measurements stored in its Platform Configuration Register (PCR) alongside a TCG log. Both of these together form the attestation evidence that is then sent to the attestation service. +2. Once Windows has booted, the attestor/verifier requests the TPM to fetch the measurements stored in its Platform Configuration Register (PCR) alongside a TCG log. The measurements in both these components together form the attestation evidence that is then sent to the attestation service. 3. The TPM is verified by using the keys/cryptographic material available on the chipset with an [Azure Certificate Service](/windows-server/identity/ad-ds/manage/component-updates/tpm-key-attestation). 4. This information is then sent to the attestation service in the cloud to verify that the device is safe. Microsoft Endpoint Manger integrates with Microsoft Azure Attestation to review device health comprehensively and connect this information with Azure Active Directory conditional access. This integration is key for Zero Trust solutions that help bind trust to an untrusted device. -5. The attestation service does the following: +5. The attestation service does the following tasks: - - Verify the integrity of the evidence. This is done by validating the PCRs that match the values recomputed by replaying the TCG log. + - Verify the integrity of the evidence. This verification is done by validating the PCRs that match the values recomputed by replaying the TCG log. - Verify that the TPM has a valid Attestation Identity Key issued by the authenticated TPM. - Verify that the security features are in the expected states. diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2015.md b/windows/whats-new/ltsc/whats-new-windows-10-2015.md index 6e75a1fb9f..4f42bba988 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2015.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2015.md @@ -21,7 +21,7 @@ This article lists new and updated features and content that are of interest to ### Provisioning devices using Windows Imaging and Configuration Designer (ICD) -With Windows 10, you can create provisioning packages that let you quickly and efficiently configure a device without having to install a new image. Using Windows Provisioning, an IT administrator can easily specify the configuration and settings required to enroll devices into management using a wizard-driven user interface, and then apply this configuration to target devices in a matter of minutes. It is best suited for small- to medium-sized businesses with deployments that range from tens to a few hundred computers. +With Windows 10, you can create provisioning packages that let you quickly and efficiently configure a device without having to install a new image. An IT administrator who uses Windows Provisioning can easily specify the configuration and settings required to enroll devices into management using a wizard-driven user interface, and then apply this configuration to target devices in a matter of minutes. It's best suited for small- to medium-sized businesses with deployments that range from tens to a few hundred computers. [Learn more about provisioning in Windows 10](/windows/configuration/provisioning-packages/provisioning-packages) @@ -33,7 +33,7 @@ AppLocker was available for Windows 8.1, and is improved with Windows 10. See [R Enhancements to AppLocker in Windows 10 include: -- A new parameter was added to the [New-AppLockerPolicy](/powershell/module/applocker/new-applockerpolicy) Windows PowerShell cmdlet that lets you choose whether executable and DLL rule collections apply to non-interactive processes. To enable this, set the **ServiceEnforcement** to **Enabled**. +- A new parameter was added to the [New-AppLockerPolicy](/powershell/module/applocker/new-applockerpolicy) Windows PowerShell cmdlet that lets you choose whether executable and DLL rule collections apply to non-interactive processes. To enable this parameter, set the **ServiceEnforcement** to **Enabled**. - A new [AppLocker](/windows/client-management/mdm/applocker-csp) configuration service provider was added to allow you to enable AppLocker rules by using an MDM server. [Learn how to manage AppLocker within your organization](/windows/device-security/applocker/applocker-overview). @@ -42,9 +42,9 @@ Enhancements to AppLocker in Windows 10 include: Enhancements to AppLocker in Windows 10 include: -- **Encrypt and recover your device with Azure Active Directory**. In addition to using a Microsoft Account, automatic [Device Encryption](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#device-encryption) can now encrypt your devices that are joined to an Azure Active Directory domain. When the device is encrypted, the BitLocker recovery key is automatically escrowed to Azure Active Directory. This will make it easier to recover your BitLocker key online. +- **Encrypt and recover your device with Azure Active Directory**. In addition to using a Microsoft Account, automatic [Device Encryption](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#device-encryption) can now encrypt your devices that are joined to an Azure Active Directory domain. When the device is encrypted, the BitLocker recovery key is automatically escrowed to Azure Active Directory. This escrow will make it easier to recover your BitLocker key online. - **DMA port protection**. You can use the [DataProtection/AllowDirectMemoryAccess](/windows/client-management/mdm/policy-configuration-service-provider#dataprotection-allowdirectmemoryaccess) MDM policy to block DMA ports when the device is starting up. Also, when a device is locked, all unused DMA ports are turned off, but any devices that are already plugged into a DMA port will continue to work. When the device is unlocked, all DMA ports are turned back on. -- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings." +- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings". [Learn how to deploy and manage BitLocker within your organization](/windows/device-security/bitlocker/bitlocker-overview). @@ -67,10 +67,10 @@ In Windows 10, security auditing has added some improvements: ####
    New audit subcategories In Windows 10, two new audit subcategories were added to the Advanced Audit Policy Configuration to provide greater granularity in audit events: -- [Audit Group Membership](/windows/device-security/auditing/audit-group-membership) Found in the Logon/Logoff audit category, the Audit Group Membership subcategory allows you to audit the group membership information in a user's logon token. Events in this subcategory are generated when group memberships are enumerated or queried on the PC where the logon session was created. For an interactive logon, the security audit event is generated on the PC that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the PC hosting the resource. - When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information cannot fit in a single security audit event. +- [Audit Group Membership](/windows/device-security/auditing/audit-group-membership) Found in the Logon/Logoff audit category, the Audit Group Membership subcategory allows you to audit the group membership information in a user's logon token. Events in this subcategory are generated when group memberships are enumerated or queried on the PC where the sign-in session was created. For an interactive logon, the security audit event is generated on the PC that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the PC hosting the resource. + When this setting is configured, one or more security audit events are generated for each successful sign in. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information can't fit in a single security audit event. - [Audit PNP Activity](/windows/security/threat-protection/auditing/audit-pnp-activity) Found in the Detailed Tracking category, the Audit PNP Activity subcategory allows you to audit when plug and play detects an external device. - Only Success audits are recorded for this category. If you do not configure this policy setting, no audit event is generated when an external device is detected by plug and play. + Only Success audits are recorded for this category. If you don't configure this policy setting, no audit event is generated when an external device is detected by plug and play. A PnP audit event can be used to track down changes in system hardware and will be logged on the PC where the change took place. A list of hardware vendor IDs is included in the event. #### More info added to existing audit events @@ -86,20 +86,20 @@ With Windows 10, version 1507, we've added more info to existing audit events to #### Changed the kernel default audit policy -In previous releases, the kernel depended on the Local Security Authority (LSA) to retrieve info in some of its events. In Windows 10, the process creation events audit policy is automatically enabled until an actual audit policy is received from LSA. This results in better auditing of services that may start before LSA starts. +In previous releases, the kernel depended on the Local Security Authority (LSA) to retrieve information in some of its events. In Windows 10, the process creation events audit policy is automatically enabled until an actual audit policy is received from LSA. This setting results in better auditing of services that may start before LSA starts. #### Added a default process SACL to LSASS.exe -In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can enable this under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. -This can help identify attacks that steal credentials from the memory of a process. +In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can enable this process under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. +This process-when enabled-can help identify attacks that steal credentials from the memory of a process. -#### New fields in the logon event +#### New fields in the sign-in event -The logon event ID 4624 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4624: +The sign-in event ID 4624 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4624: 1. **MachineLogon** String: yes or no - If the account that logged into the PC is a computer account, this field will be yes. Otherwise, the field is no. + If the account that signed in to the PC is a computer account, this field will be yes. Otherwise, the field is no. 2. **ElevatedToken** String: yes or no - If the account that logged into the PC is an administrative logon, this field will be yes. Otherwise, the field is no. Additionally, if this is part of a split token, the linked login ID (LSAP\_LOGON\_SESSION) will also be shown. + If an account has signed in to the PC through the "administrative sign in" method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. 3. **TargetOutboundUserName** String **TargetOutboundUserDomain** String The username and domain of the identity that was created by the LogonUser method for outbound traffic. @@ -113,7 +113,7 @@ The logon event ID 4624 has been updated to include more verbose information to #### New fields in the process creation event -The logon event ID 4688 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4688: +The sign-in event ID 4688 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4688: 1. **TargetUserSid** String The SID of the target principal. 2. **TargetUserName** String @@ -121,7 +121,7 @@ The logon event ID 4688 has been updated to include more verbose information to 3. **TargetDomainName** String The domain of the target user. 4. **TargetLogonId** String - The logon ID of the target user. + The sign-in ID of the target user. 5. **ParentProcessName** String The name of the creator process. 6. **ParentProcessId** String @@ -187,7 +187,7 @@ Some things that you can check on the device are: User Account Control (UAC) helps prevent malware from damaging a computer and helps organizations deploy a better-managed desktop environment. -You should not turn off UAC because this is not a supported scenario for devices running Windows 10. If you do turn off UAC, all Universal Windows Platform apps stop working. You must always set the **HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA** registry value to 1. If you need to provide auto elevation for programmatic access or installation, you could set the **HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin** registry value to 0, which is the same as setting the UAC slider Never Notify. This is not recommended for devices running Windows 10. +You shouldn't turn off UAC because such a setting isn't supportive of devices running Windows 10. If you do turn off UAC, all Universal Windows Platform apps stop working. You must always set the **HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA** registry value to 1. If you need to provide auto elevation for programmatic access or installation, you could set the **HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin** registry value to 0, which is the same as setting the UAC slider Never Notify. This setting isn't recommended for devices running Windows 10. For more info about how to manage UAC, see [UAC Group Policy Settings and Registry Key Settings](/windows/access-protection/user-account-control/user-account-control-group-policy-and-registry-key-settings). @@ -267,15 +267,15 @@ Administrators can also use mobile device management (MDM) or Group Policy to di Windows Update for Business enables information technology administrators to keep the Windows 10-based devices in their organization always up to date with the latest security defenses and Windows features by directly connecting these systems to Microsoft’s Windows Update service. -By using [Group Policy Objects](/previous-versions/cc498727(v=msdn.10)), Windows Update for Business is an easily established and implemented system which enables organizations and administrators to exercise control on how their Windows 10-based devices are updated, by allowing: +By using [Group Policy Objects](/previous-versions/cc498727(v=msdn.10)), Windows Update for Business is an easily established and implemented system that enables organizations and administrators to exercise control on how their Windows 10-based devices are updated, by allowing: - **Deployment and validation groups**; where administrators can specify which devices go first in an update wave, and which devices will come later (to ensure any quality bars are met). -- **Peer-to-peer delivery**, which administrators can enable to make delivery of updates to branch offices and remote sites with limited bandwidth very efficient. +- **Peer-to-peer delivery**, which administrators can enable to make delivery of updates to branch offices and remote sites with limited bandwidth efficient. - **Use with existing tools** such as Microsoft Endpoint Manager and the [Enterprise Mobility Suite](/enterprise-mobility-security). -Together, these Windows Update for Business features help reduce device management costs, provide controls over update deployment, offer quicker access to security updates, as well as provide access to the latest innovations from Microsoft on an ongoing basis. Windows Update for Business is a free service for all Windows 10 Pro, Enterprise, and Education editions, and can be used independent of, or in conjunction with, existing device management solutions such as [Windows Server Update Services (WSUS)](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)) and [Microsoft Endpoint Configuration Manager](/configmgr). +Together, these Windows Update for Business features help reduce device management costs, provide controls over update deployment, offer quicker access to security updates, and provide access to the latest innovations from Microsoft on an ongoing basis. Windows Update for Business is a free service for all Windows 10 Pro, Enterprise, and Education editions, and can be used independent of, or in conjunction with, existing device management solutions such as [Windows Server Update Services (WSUS)](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)) and [Microsoft Endpoint Configuration Manager](/configmgr). Learn more about [Windows Update for Business](/windows/deployment/update/waas-manage-updates-wufb). @@ -284,7 +284,7 @@ For more information about updating Windows 10, see [Windows 10 servicing option ## Microsoft Edge -The new chromium-based Microsoft Edge is not included in the LTSC release of Windows 10. However, you can download and install it separately [here](https://www.microsoft.com/edge/business/download). +The new chromium-based Microsoft Edge isn't included in the LTSC release of Windows 10. However, you can download and install it separately [here](https://www.microsoft.com/edge/business/download). ## See Also diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2016.md b/windows/whats-new/ltsc/whats-new-windows-10-2016.md index 7ee18df927..74fe44632b 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2016.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2016.md @@ -24,7 +24,7 @@ This article lists new and updated features and content that are of interest to ### Windows Imaging and Configuration Designer (ICD) -In previous versions of the Windows 10 Assessment and Deployment Kit (ADK), you had to install additional features for Windows ICD to run. Starting in this version of Windows 10, you can install just the configuration designer component independent of the rest of the imaging components. [Install the ADK.](https://developer.microsoft.com/en-us/windows/hardware/windows-assessment-deployment-kit) +In previous versions of the Windows 10 Assessment and Deployment Kit (ADK), you had to install more features for Windows ICD to run. Starting in this version of Windows 10, you can install just the configuration designer component independent of the rest of the imaging components. [Install the ADK.](https://developer.microsoft.com/en-us/windows/hardware/windows-assessment-deployment-kit) Windows ICD now includes simplified workflows for creating provisioning packages: @@ -39,9 +39,9 @@ Windows ICD now includes simplified workflows for creating provisioning packages >[!IMPORTANT] >Upgrade Readiness will not allow you to assess an upgrade to an LTSC release (LTSC builds are not available as target versions). However, you can enroll devices running LTSC to plan for an upgrade to a General Availability Channel release. -Microsoft developed Upgrade Readiness in response to demand from enterprise customers looking for additional direction and details about upgrading to Windows 10. Upgrade Readiness was built taking into account multiple channels of customer feedback, testing, and Microsoft’s experience upgrading millions of devices to Windows 10. +Microsoft developed Upgrade Readiness in response to demand from enterprise customers looking for more direction and details about upgrading to Windows 10. Upgrade Readiness was built taking into account multiple channels of customer feedback, testing, and Microsoft’s experience upgrading millions of devices to Windows 10. -With Windows diagnostic data enabled, Upgrade Readiness collects system, application, and driver data for analysis. We then identify compatibility issues that can block an upgrade and suggest fixes when they are known to Microsoft. +With Windows diagnostic data enabled, Upgrade Readiness collects system, application, and driver data for analysis. We then identify compatibility issues that can block an upgrade and suggest fixes when they're known to Microsoft. Use Upgrade Readiness to get: @@ -65,9 +65,9 @@ Isolated User Mode is now included with Hyper-V so you don't have to install it ### Windows Hello for Business -When Windows 10 first shipped, it included Microsoft Passport and Windows Hello, which worked together to provide multifactor authentication. To simplify deployment and improve supportability, Microsoft has combined these technologies into a single solution under the Windows Hello name in this version of Windows 10. Customers who have already deployed Microsoft Passport for Work will not experience any change in functionality. Customers who have yet to evaluate Windows Hello will find it easier to deploy due to simplified policies, documentation, and semantics. +When Windows 10 was first shipped, it included Microsoft Passport and Windows Hello, which worked together to provide multifactor authentication. To simplify deployment and improve supportability, Microsoft has combined these technologies into a single solution under the Windows Hello name in this version of Windows 10. Customers who have already deployed Microsoft Passport for Work won't experience any change in functionality. Customers who have yet to evaluate Windows Hello will find it easier to deploy due to simplified policies, documentation, and semantics. -Additional changes for Windows Hello in Windows 10 Enterprise LTSC 2016: +Other changes for Windows Hello in Windows 10 Enterprise LTSC 2016: - Personal (Microsoft account) and corporate (Active Directory or Azure AD) accounts use a single container for keys. - Group Policy settings for managing Windows Hello for Business are now available for both **User Configuration** and **Computer Configuration**. @@ -79,7 +79,7 @@ Additional changes for Windows Hello in Windows 10 Enterprise LTSC 2016: #### New BitLocker features -- **XTS-AES encryption algorithm**. BitLocker now supports the XTS-AES encryption algorithm. XTS-AES provides additional protection from a class of attacks on encryption that rely on manipulating cipher text to cause predictable changes in plain text. BitLocker supports both 128-bit and 256-bit XTS-AES keys. +- **XTS-AES encryption algorithm**. BitLocker now supports the XTS-AES encryption algorithm. XTS-AES provides extra protection from a class of attacks on encryption that rely on manipulating cipher text to cause predictable changes in plain text. BitLocker supports both 128-bit and 256-bit XTS-AES keys. It provides the following benefits: - The algorithm is FIPS-compliant. - Easy to administer. You can use the BitLocker Wizard, manage-bde, Group Policy, MDM policy, Windows PowerShell, or WMI to manage it on devices in your organization. @@ -116,7 +116,7 @@ Several new features and management options have been added to Windows Defender - [Windows Defender Offline in Windows 10](/microsoft-365/security/defender-endpoint/microsoft-defender-offline) can be run directly from within Windows, without having to create bootable media. - [Use PowerShell cmdlets for Windows Defender](/microsoft-365/security/defender-endpoint/use-powershell-cmdlets-microsoft-defender-antivirus) to configure options and run scans. -- [Enable the Block at First Sight feature in Windows 10](/microsoft-365/security/defender-endpoint/configure-block-at-first-sight-microsoft-defender-antivirus) to leverage the Windows Defender cloud for near-instant protection against new malware. +- [Enable the Block at First Sight feature in Windows 10](/microsoft-365/security/defender-endpoint/configure-block-at-first-sight-microsoft-defender-antivirus) to use the Windows Defender cloud for near-instant protection against new malware. - [Configure enhanced notifications for Windows Defender in Windows 10](/microsoft-365/security/defender-endpoint/configure-notifications-microsoft-defender-antivirus) to see more information about threat detections and removal. - [Run a Windows Defender scan from the command line](/microsoft-365/security/defender-endpoint/command-line-arguments-microsoft-defender-antivirus). - [Detect and block Potentially Unwanted Applications with Windows Defender](/microsoft-365/security/defender-endpoint/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus) during download and install times. @@ -130,7 +130,7 @@ With the growing threat from more sophisticated targeted attacks, a new security ### VPN security - The VPN client can integrate with the Conditional Access Framework, a cloud-based policy engine built into Azure Active Directory, to provide a device compliance option for remote clients. -- The VPN client can integrate with Windows Information Protection (WIP) policy to provide additional security. [Learn more about Windows Information Protection](/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip), previously known as Enterprise Data Protection. +- The VPN client can integrate with Windows Information Protection (WIP) policy to provide extra security. [Learn more about Windows Information Protection](/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip), previously known as Enterprise Data Protection. - New VPNv2 configuration service provider (CSP) adds configuration settings. For details, see [What's new in MDM enrollment and management](/windows/client-management/mdm/new-in-windows-mdm-enrollment-management#whatsnew_1607) - Microsoft Intune: *VPN* profile template includes support for native VPN plug-ins. For more information, see [Create VPN profiles to connect to VPN servers in Intune](/mem/intune/configuration/vpn-settings-configure). @@ -156,7 +156,7 @@ This version of Windows 10, introduces shared PC mode, which optimizes Windows 1 Application Virtualization (App-V) enables organizations to deliver Win32 applications to users as virtual applications. Virtual applications are installed on centrally managed servers and delivered to users as a service – in real time and on as as-needed basis. Users launch virtual applications from familiar access points, including the Microsoft Store, and interact with them as if they were installed locally. -With the release of this version of Windows 10, App-V is included with the Windows 10 for Enterprise edition. If you are new to Windows 10 and App-V or if you're upgrading from a previous version of App-V, you’ll need to download, activate, and install server- and client-side components to start delivering virtual applications to users. +With the release of this version of Windows 10, App-V is included with the Windows 10 for Enterprise edition. If you're new to Windows 10 and App-V or if you're upgrading from a previous version of App-V, you’ll need to download, activate, and install server- and client-side components to start delivering virtual applications to users. [Learn how to deliver virtual applications with App-V.](/windows/application-management/app-v/appv-getting-started) @@ -164,15 +164,15 @@ With the release of this version of Windows 10, App-V is included with the Windo Many users customize their settings for Windows and for specific applications. Customizable Windows settings include Microsoft Store appearance, language, background picture, font size, and accent colors. Customizable application settings include language, appearance, behavior, and user interface options. -With User Experience Virtualization (UE-V), you can capture user-customized Windows and application settings and store them on a centrally managed network file share. When users log on, their personalized settings are applied to their work session, regardless of which device or virtual desktop infrastructure (VDI) sessions they log on to. +With User Experience Virtualization (UE-V), you can capture user-customized Windows and application settings and store them on a centrally managed network file share. When users sign in, their personalized settings are applied to their work session, regardless of which device or virtual desktop infrastructure (VDI) sessions they sign in to. -With the release of this version of Windows 10, UE-V is included with the Windows 10 for Enterprise edition. If you are new to Windows 10 and UE-V or upgrading from a previous version of UE-V, you’ll need to download, activate, and install server- and client-side components to start synchronizing user-customized settings across devices. +With the release of this version of Windows 10, UE-V is included with the Windows 10 for Enterprise edition. If you're new to Windows 10 and UE-V or upgrading from a previous version of UE-V, you’ll need to download, activate, and install server- and client-side components to start synchronizing user-customized settings across devices. [Learn how to synchronize user-customized settings with UE-V.](/windows/configuration/ue-v/uev-for-windows) ## Microsoft Edge -The new chromium-based Microsoft Edge is not included in the LTSC release of Windows 10. However, you can download and install it separately [here](https://www.microsoft.com/edge/business/download). +The new chromium-based Microsoft Edge isn't included in the LTSC release of Windows 10. However, you can download and install it separately [here](https://www.microsoft.com/edge/business/download). ## See Also diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2019.md b/windows/whats-new/ltsc/whats-new-windows-10-2019.md index a5e9788ba1..d71d316113 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2019.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2019.md @@ -71,7 +71,7 @@ But these protections can also be configured separately. And, unlike HVCI, code ### Endpoint detection and response -Endpoint detection and response is improved. Enterprise customers can now take advantage of the entire Windows security stack with Microsoft Defender Antivirus **detections** and Device Guard **blocks** being surfaced in the Microsoft Defender for Endpoint portal. +Endpoint detection and response are improved. Enterprise customers can now take advantage of the entire Windows security stack with Microsoft Defender Antivirus **detections** and Device Guard **blocks** being surfaced in the Microsoft Defender for Endpoint portal. Windows Defender is now called Microsoft Defender Antivirus and now shares detection status between Microsoft 365 services and interoperates with Microsoft Defender for Endpoint. Other policies have also been implemented to enhance cloud based protection, and new channels are available for emergency protection. For more information, see [Virus and threat protection](/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection) and [Use next-gen technologies in Microsoft Defender Antivirus through cloud-delivered protection](/microsoft-365/security/defender-endpoint/cloud-protection-microsoft-defender-antivirus). @@ -366,7 +366,7 @@ For more information about Update Compliance, see [Monitor Windows Updates with ### Privacy -In the Feedback and Settings page under Privacy Settings you can now delete the diagnostic data your device has sent to Microsoft. You can also view this diagnostic data using the [Diagnostic Data Viewer](/windows/privacy/diagnostic-data-viewer-overview) app. +In the Feedback and Settings page under Privacy Settings, you can now delete the diagnostic data your device has sent to Microsoft. You can also view this diagnostic data using the [Diagnostic Data Viewer](/windows/privacy/diagnostic-data-viewer-overview) app. ## Configuration diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2021.md b/windows/whats-new/ltsc/whats-new-windows-10-2021.md index e91667cc1a..e10132e61d 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2021.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2021.md @@ -36,7 +36,7 @@ For more information about the lifecycle for this release, see [The next Windows ### System Guard -[System Guard](/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows) has improved a feature in this version of Windows called **SMM Firmware Protection**. This feature is built on top of [System Guard Secure Launch](/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection) to reduce the firmware attack surface and ensure that the System Management Mode (SMM) firmware on the device is operating in a healthy manner - specifically, SMM code cannot access the OS memory and secrets. +[System Guard](/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows) has improved a feature in this version of Windows called **SMM Firmware Protection**. This feature is built on top of [System Guard Secure Launch](/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection) to reduce the firmware attack surface and ensure that the System Management Mode (SMM) firmware on the device is operating in a healthy manner - specifically, SMM code can't access the OS memory and secrets. In this release, [Windows Defender System Guard](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows) enables an even *higher* level of [System Management Mode](/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows#system-management-mode-smm-protection) (SMM) Firmware Protection that goes beyond checking the OS memory and secrets to other resources like registers and IO. @@ -64,17 +64,17 @@ Windows Defender Firewall now offers the following benefits: **Safeguard data**: With integrated Internet Protocol Security (IPsec), Windows Defender Firewall provides a simple way to enforce authenticated, end-to-end network communications. It provides scalable, tiered access to trusted network resources, helping to enforce integrity of the data, and optionally helping to protect the confidentiality of the data. -**Extend value**: Windows Defender Firewall is a host-based firewall that is included with the operating system, so there is no additional hardware or software required. Windows Defender Firewall is also designed to complement existing non-Microsoft network security solutions through a documented application programming interface (API). +**Extend value**: Windows Defender Firewall is a host-based firewall that is included with the operating system, so there's no other hardware or software required. Windows Defender Firewall is also designed to complement existing non-Microsoft network security solutions through a documented application programming interface (API). -The Windows Defender Firewall is also now easier to analyze and debug. IPsec behavior has been integrated with Packet Monitor (pktmon), an in-box cross-component network diagnostic tool for Windows. +The Windows Defender Firewall is also now easier to analyze and debug. IPsec behavior has been integrated with Packet Monitor (pktmon), an in-box cross-component network diagnostic tool for Windows. -Additionally, the Windows Defender Firewall event logs have been enhanced to ensure an audit can identify the specific filter that was responsible for any given event. This enables analysis of firewall behavior and rich packet capture without relying on other tools. +Additionally, the Windows Defender Firewall event logs have been enhanced to ensure an audit can identify the specific filter that was responsible for any given event. This enhancement enables analysis of firewall behavior and rich packet capture without relying on other tools. Windows Defender Firewall also now supports [Windows Subsystem for Linux (WSL)](/windows/wsl/); You can add rules for WSL process, just like for Windows processes. For more information, see [Windows Defender Firewall now supports Windows Subsystem for Linux (WSL)](https://blogs.windows.com/windowsexperience/2018/04/19/announcing-windows-10-insider-preview-build-17650-for-skip-ahead/#II14f7VlSBcZ0Gs4.97). ### Virus and threat protection -[Attack surface area reduction](/windows/security/threat-protection/windows-defender-atp/overview-attack-surface-reduction) – IT admins can configure devices with advanced web protection that enables them to define allow and deny lists for specific URL’s and IP addresses. +[Attack surface area reduction](/windows/security/threat-protection/windows-defender-atp/overview-attack-surface-reduction) – IT admins can configure devices with advanced web protection that enables them to define allowlists and blocklists for specific URL’s and IP addresses. [Next generation protection](/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-in-windows-10) – Controls have been extended to protection from ransomware, credential misuse, and attacks that are transmitted through removable storage. - Integrity enforcement capabilities – Enable remote runtime attestation of Windows 10 platform. - [Tamper-proofing](/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection) capabilities – Uses virtualization-based security to isolate critical Microsoft Defender for Endpoint security capabilities away from the OS and attackers. @@ -82,11 +82,11 @@ Windows Defender Firewall also now supports [Windows Subsystem for Linux (WSL)]( **Advanced machine learning**: Improved with advanced machine learning and AI models that enable it to protect against apex attackers using innovative vulnerability exploit techniques, tools and malware. -**Emergency outbreak protection**: Provides emergency outbreak protection which will automatically update devices with new intelligence when a new outbreak has been detected. +**Emergency outbreak protection**: Provides emergency outbreak protection that will automatically update devices with new intelligence when a new outbreak has been detected. **Certified ISO 27001 compliance**: Ensures that the cloud service has analyzed for threats, vulnerabilities and impacts, and that risk management and security controls are in place. -**Geolocation support**: Support geolocation and sovereignty of sample data as well as configurable retention policies. +**Geolocation support**: Support geolocation and sovereignty of sample data and configurable retention policies. **Improved support for non-ASCII file paths** for Microsoft Defender Advanced Threat Protection (ATP) Auto Incident Response (IR). @@ -103,19 +103,19 @@ Windows Defender Firewall also now supports [Windows Subsystem for Linux (WSL)]( [Microsoft Defender Application Guard](/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview) enhancements include: - Standalone users can install and configure their Windows Defender Application Guard settings without needing to change registry key settings. Enterprise users can check their settings to see what their administrators have configured for their machines to better understand the behavior. - - Application Guard is now an extension in Google Chrome and Mozilla Firefox. Many users are in a hybrid browser environment, and would like to extend Application Guard’s browser isolation technology beyond Microsoft Edge. In the latest release, users can install the Application Guard extension in their Chrome or Firefox browsers. This extension will redirect untrusted navigation to the Application Guard Edge browser. There is also a companion app to enable this feature in the Microsoft Store. Users can quickly launch Application Guard from their desktop using this app. This feature is also available in Windows 10, version 1803 or later with the latest updates. + - Application Guard is now an extension in Google Chrome and Mozilla Firefox. Many users are in a hybrid browser environment, and would like to extend Application Guard’s browser isolation technology beyond Microsoft Edge. In the latest release, users can install the Application Guard extension in their Chrome or Firefox browsers. This extension will redirect untrusted navigation to the Application Guard Edge browser. There's also a companion app to enable this feature in the Microsoft Store. Users can quickly launch Application Guard from their desktop using this app. This feature is also available in Windows 10, version 1803 or later with the latest updates. To try this extension: 1. Configure Application Guard policies on your device. 2. Go to the Chrome Web Store or Firefox Add-ons and search for Application Guard. Install the extension. - 3. Follow any additional configuration steps on the extension setup page. + 3. Follow any of the other configuration steps on the extension setup page. 4. Reboot the device. 5. Navigate to an untrusted site in Chrome and Firefox. **Dynamic navigation**: Application Guard now allows users to navigate back to their default host browser from the Application Guard Microsoft Edge. Previously, users browsing in Application Guard Edge would see an error page when they try to go to a trusted site within the container browser. With this new feature, users will automatically be redirected to their host default browser when they enter or click on a trusted site in Application Guard Edge. This feature is also available in Windows 10, version 1803 or later with the latest updates. Application Guard performance is improved with optimized document opening times: -- An issue is fixed that could cause a one minute or more delay when you open a Microsoft Defender Application Guard (Application Guard) Office document. This can occur when you try to open a file using a Universal Naming Convention (UNC) path or Server Message Block (SMB) share link. +- An issue is fixed that could cause a one-minute-or more delay when you open a Microsoft Defender Application Guard (Application Guard) Office document. This issue can occur when you try to open a file using a Universal Naming Convention (UNC) path or Server Message Block (SMB) share link. - A memory issue is fixed that could cause an Application Guard container to use almost 1 GB of working set memory when the container is idle. - The performance of Robocopy is improved when copying files over 400 MB in size. @@ -125,12 +125,12 @@ Application Guard performance is improved with optimized document opening times: ### Application Control -[Application Control for Windows](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control): In Windows 10, version 1903, Windows Defender Application Control (WDAC) added a number of new features that light up key scenarios and provide feature parity with AppLocker. +[Application Control for Windows](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control): In Windows 10, version 1903, Windows Defender Application Control (WDAC) added many new features that light up key scenarios and provide feature parity with AppLocker. - [Multiple Policies](/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies): Windows Defender Application Control now supports multiple simultaneous code integrity policies for one device in order to enable the following scenarios: 1) enforce and audit side by side, 2) simpler targeting for policies with different scope/intent, 3) expanding a policy using a new ‘supplemental’ policy. - - [Path-Based Rules](/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules): The path condition identifies an app by its location in the file system of the computer or on the network instead of a signer or hash identifier. Additionally, WDAC has an option that allows admins to enforce at runtime that only code from paths that are not user-writeable is executed. When code tries to execute at runtime, the directory is scanned and files will be checked for write permissions for non-known admins. If a file is found to be user writeable, the executable is blocked from running unless it is authorized by something other than a path rule like a signer or hash rule.
    - This brings Windows Defender Application Control (WDAC) to functionality parity with AppLocker in terms of support for file path rules. WDAC improves upon the security of policies based on file path rules with the availability of the user-writability permission checks at runtime time, which is a capability that is not available with AppLocker. - - [Allow COM Object Registration](/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy): Previously, Windows Defender Application Control (WDAC) enforced a built-in allow list for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where additional COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. + - [Path-Based Rules](/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules): The path condition identifies an app by its location in the file system of the computer or on the network instead of a signer or hash identifier. Additionally, WDAC has an option that allows admins to enforce at runtime that only code from paths that aren't user-writeable is executed. When code tries to execute at runtime, the directory is scanned and files will be checked for write permissions for unknown admins. If a file is found to be user writeable, the executable is blocked from running unless it's authorized by something other than a path rule like a signer or hash rule.
    + This functionality brings WDAC to parity with AppLocker in terms of support for file path rules. WDAC improves upon the security of policies based on file path rules with the availability of the user-writability permission checks at runtime time, which is a capability that isn't available with AppLocker. + - [Allow COM Object Registration](/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy): Previously, Windows Defender Application Control (WDAC) enforced a built-in allowlist for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where more COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. ## Identity and privacy @@ -143,7 +143,7 @@ Windows Hello enhancements include: - Windows Hello for Business now has Hybrid Azure Active Directory support and phone number sign-in (Microsoft account). FIDO2 security key support is expanded to Azure Active Directory hybrid environments, enabling enterprises with hybrid environments to take advantage of [passwordless authentication](/azure/active-directory/authentication/howto-authentication-passwordless-security-key-on-premises). For more information, see [Expanding Azure Active Directory support for FIDO2 preview to hybrid environments](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/expanding-azure-active-directory-support-for-fido2-preview-to/ba-p/981894). - With specialized hardware and software components available on devices shipping with Windows 10, version 20H2 configured out of factory, Windows Hello now offers added support for virtualization-based security with supporting fingerprint and face sensors. This feature isolates and secures a user's biometric authentication data. - Windows Hello multi-camera support is added, allowing users to choose an external camera priority when both external and internal Windows Hello-capable cameras are present. -- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less login for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. +- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less sign in for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. - [Streamlined Windows Hello PIN reset experience](/windows/security/identity-protection/hello-for-business/hello-videos#windows-hello-for-business-forgotten-pin-user-experience): Microsoft account users have a revamped Windows Hello PIN reset experience with the same look and feel as signing in on the web. - [Remote Desktop with Biometrics](/windows/security/identity-protection/hello-for-business/hello-feature-remote-desktop#remote-desktop-with-biometrics): Azure Active Directory and Active Directory users using Windows Hello for Business can use biometrics to authenticate to a remote desktop session. @@ -151,7 +151,7 @@ Windows Hello enhancements include: #### Windows Defender Credential Guard -[Windows Defender Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard) is now available for ARM64 devices, for additional protection against credential theft for enterprises deploying ARM64 devices in their organizations, such as Surface Pro X. +[Windows Defender Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard) is now available for ARM64 devices, for extra protection against credential theft for enterprises deploying ARM64 devices in their organizations, such as Surface Pro X. ### Privacy controls @@ -173,7 +173,7 @@ Microsoft Intune supports Windows 10 Enterprise LTSC 2021, except for [Windows U A new Intune remote action: **Collect diagnostics**, lets you collect the logs from corporate devices without interrupting or waiting for the end user. For more information, see [Collect diagnostics remote action](/mem/intune/fundamentals/whats-new#collect-diagnostics-remote-action). -Intune has also added capabilities to [Role-based access control](/mem/intune/fundamentals/whats-new#role-based-access-control) (RBAC) that can be used to further define profile settings for the Enrollment Status Page (ESP). For more information see [Create Enrollment Status Page profile and assign to a group](/mem/intune/enrollment/windows-enrollment-status#create-enrollment-status-page-profile-and-assign-to-a-group). +Intune has also added capabilities to [Role-based access control](/mem/intune/fundamentals/whats-new#role-based-access-control) (RBAC) that can be used to further define profile settings for the Enrollment Status Page (ESP). For more information, see [Create Enrollment Status Page profile and assign to a group](/mem/intune/enrollment/windows-enrollment-status#create-enrollment-status-page-profile-and-assign-to-a-group). For a full list of what's new in Microsoft Intune, see [What's new in Microsoft Intune](/mem/intune/fundamentals/whats-new). @@ -189,12 +189,12 @@ Windows Management Instrumentation (WMI) Group Policy Service (GPSVC) has a perf #### Key-rolling and Key-rotation This release also includes two new features called Key-rolling and Key-rotation enables secure rolling of Recovery passwords on MDM-managed Azure Active Directory devices on demand from Microsoft Intune/MDM tools or when a recovery password is used to unlock the BitLocker protected drive. This feature will help prevent accidental recovery password disclosure as part of manual BitLocker drive unlock by users. - +s ## Deployment ### SetupDiag -[SetupDiag](/windows/deployment/upgrade/setupdiag) is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When searching log files, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. +[SetupDiag](/windows/deployment/upgrade/setupdiag) is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When log files are being searched, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. ### Reserved storage diff --git a/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md b/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md index 8190b90e04..d1275f53bd 100644 --- a/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md +++ b/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md @@ -1,6 +1,6 @@ --- title: What's new in Windows 10, versions 1507 and 1511 (Windows 10) -description: What's new in Windows 10 for Windows 10 (versions 1507 and 1511). +description: What's new in Windows 10 for Windows 10 (versions 1507 and 1511)? ms.reviewer: ms.prod: w10 author: aczechowski @@ -23,7 +23,7 @@ Below is a list of some of the new and updated features included in the initial ### Provisioning devices using Windows Imaging and Configuration Designer (ICD) -With Windows 10, you can create provisioning packages that let you quickly and efficiently configure a device without having to install a new image. Windows provisioning makes it easy for IT administrators to configure end-user devices without imaging. Using Windows Provisioning, an IT administrator can easily specify desired configuration and settings required to enroll the devices into management (through a wizard-driven user interface) and then apply that configuration to target devices in a matter of minutes. It is best suited for small- to medium-sized businesses with deployments that range from tens to a few hundred computers. +With Windows 10, you can create provisioning packages that let you quickly and efficiently configure a device without having to install a new image. Windows provisioning makes it easy for IT administrators to configure end-user devices without imaging. An IT administrator using Windows Provisioning can easily specify desired configuration and settings required to enroll the devices into management (through a wizard-driven user interface) and then apply that configuration to target devices in a matter of minutes. It's best suited for small- to medium-sized businesses with deployments that range from tens to a few hundred computers. [Learn more about provisioning in Windows 10.](/windows/configuration/provisioning-packages/provisioning-packages) @@ -34,8 +34,8 @@ With Windows 10, you can create provisioning packages that let you quickly and e #### New AppLocker features in Windows 10, version 1507 -- A new parameter was added to the [New-AppLockerPolicy](/powershell/module/applocker/new-applockerpolicy) Windows PowerShell cmdlet that lets you choose whether executable and DLL rule collections apply to non-interactive processes. To enable this, set the **ServiceEnforcement** to **Enabled**. -- A new [AppLocker](/windows/client-management/mdm/applocker-csp) configuration service provider was add to allow you to enable AppLocker rules by using an MDM server. +- A new parameter was added to the [New-AppLockerPolicy](/powershell/module/applocker/new-applockerpolicy) Windows PowerShell cmdlet that lets you choose whether executable and DLL rule collections apply to non-interactive processes. To enable this parameter, set the **ServiceEnforcement** to **Enabled**. +- A new [AppLocker](/windows/client-management/mdm/applocker-csp) configuration service provider was added to allow you to enable AppLocker rules by using an MDM server. [Learn how to manage AppLocker within your organization](/windows/device-security/applocker/applocker-overview). @@ -43,7 +43,7 @@ With Windows 10, you can create provisioning packages that let you quickly and e #### New BitLocker features in Windows 10, version 1511 -- **XTS-AES encryption algorithm**. BitLocker now supports the XTS-AES encryption algorithm. XTS-AES provides additional protection from a class of attacks on encryption that rely on manipulating cipher text to cause predictable changes in plain text. BitLocker supports both 128-bit and 256-bit XTS-AES keys. +- **XTS-AES encryption algorithm**. BitLocker now supports the XTS-AES encryption algorithm. XTS-AES provides extra protection from a class of attacks on encryption that rely on manipulating cipher text to cause predictable changes in plain text. BitLocker supports both 128-bit and 256-bit XTS-AES keys. It provides the following benefits: - The algorithm is FIPS-compliant. - Easy to administer. You can use the BitLocker Wizard, manage-bde, Group Policy, MDM policy, Windows PowerShell, or WMI to manage it on devices in your organization. @@ -55,9 +55,9 @@ With Windows 10, you can create provisioning packages that let you quickly and e -- **Encrypt and recover your device with Azure Active Directory**. In addition to using a Microsoft Account, automatic [Device Encryption](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#device-encryption) can now encrypt your devices that are joined to an Azure Active Directory domain. When the device is encrypted, the BitLocker recovery key is automatically escrowed to Azure Active Directory. This will make it easier to recover your BitLocker key online. +- **Encrypt and recover your device with Azure Active Directory**. In addition to using a Microsoft Account, automatic [Device Encryption](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#device-encryption) can now encrypt your devices that are joined to an Azure Active Directory domain. When the device is encrypted, the BitLocker recovery key is automatically escrowed to Azure Active Directory. This escrow will make it easier to recover your BitLocker key online. - **DMA port protection**. You can use the [DataProtection/AllowDirectMemoryAccess](/windows/client-management/mdm/policy-configuration-service-provider#dataprotection-allowdirectmemoryaccess) MDM policy to block DMA ports when the device is starting up. Also, when a device is locked, all unused DMA ports are turned off, but any devices that are already plugged into a DMA port will continue to work. When the device is unlocked, all DMA ports are turned back on. -- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings." +- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings". [Learn how to deploy and manage BitLocker within your organization](/windows/device-security/bitlocker/bitlocker-overview). @@ -66,11 +66,11 @@ With Windows 10, you can create provisioning packages that let you quickly and e #### New Credential Guard features in Windows 10, version 1511 - **Credential Manager support**. Credentials that are stored with Credential Manager, including domain credentials, are protected with Credential Guard with the following considerations: - - Credentials that are saved by the Remote Desktop Protocol cannot be used. Employees in your organization can manually store credentials in Credential Manager as generic credentials. + - Credentials that are saved by the Remote Desktop Protocol can't be used. Employees in your organization can manually store credentials in Credential Manager as generic credentials. - Applications that extract derived domain credentials using undocumented APIs from Credential Manager will no longer be able to use those saved derived credentials. - - You cannot restore credentials using the Credential Manager control panel if the credentials were backed up from a PC that has Credential Guard turned on. If you need to back up your credentials, you must do this before you enable Credential Guard. Otherwise, you won't be able to restore those credentials. -- **Enable Credential Guard without UEFI lock**. You can enable Credential Guard by using the registry. This allows you to disable Credential Guard remotely. However, we recommend that Credential Guard is enabled with UEFI lock. You can configure this by using Group Policy. -- **CredSSP/TsPkg credential delegation**. CredSSP/TsPkg cannot delegate default credentials when Credential Guard is enabled. + - You can't restore credentials using the Credential Manager control panel if the credentials were backed up from a PC that has Credential Guard turned on. If you need to back up your credentials, you must do this backup before you enable Credential Guard. Otherwise, you won't be able to restore those credentials. +- **Enable Credential Guard without UEFI lock**. You can enable Credential Guard by using the registry. This setting allows you to disable Credential Guard remotely. However, we recommend that Credential Guard is enabled with UEFI lock. You can do this configuration by using Group Policy. +- **CredSSP/TsPkg credential delegation**. CredSSP/TsPkg can't delegate default credentials when Credential Guard is enabled. [Learn how to deploy and manage Credential Guard within your organization](/windows/access-protection/credential-guard/credential-guard). @@ -100,10 +100,10 @@ In Windows 10, security auditing has added some improvements: ##### New audit subcategories In Windows 10, two new audit subcategories were added to the Advanced Audit Policy Configuration to provide greater granularity in audit events: -- [Audit Group Membership](/windows/device-security/auditing/audit-group-membership) Found in the Logon/Logoff audit category, the Audit Group Membership subcategory allows you to audit the group membership information in a user's logon token. Events in this subcategory are generated when group memberships are enumerated or queried on the PC where the logon session was created. For an interactive logon, the security audit event is generated on the PC that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the PC hosting the resource. - When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information cannot fit in a single security audit event. +- [Audit Group Membership](/windows/device-security/auditing/audit-group-membership) Found in the Logon/Logoff audit category, the Audit Group Membership subcategory allows you to audit the group membership information in a user's sign-in token. Events in this subcategory are generated when group memberships are enumerated or queried on the PC where the sign-in session was created. For an interactive logon, the security audit event is generated on the PC that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the PC hosting the resource. + When this setting is configured, one or more security audit events are generated for each successful sign in. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information can't fit in a single security audit event. - [Audit PNP Activity](/windows/security/threat-protection/auditing/audit-pnp-activity) Found in the Detailed Tracking category, the Audit PNP Activity subcategory allows you to audit when plug and play detects an external device. - Only Success audits are recorded for this category. If you do not configure this policy setting, no audit event is generated when an external device is detected by plug and play. + Only Success audits are recorded for this category. If you don't configure this policy setting, no audit event is generated when an external device is detected by plug and play. A PnP audit event can be used to track down changes in system hardware and will be logged on the PC where the change took place. A list of hardware vendor IDs are included in the event. ##### More info added to existing audit events @@ -111,7 +111,7 @@ In Windows 10, two new audit subcategories were added to the Advanced Audit Poli With Windows 10, version 1507, we've added more info to existing audit events to make it easier for you to put together a full audit trail and come away with the information you need to protect your enterprise. Improvements were made to the following audit events: - [Changed the kernel default audit policy](#bkmk-kdal) - [Added a default process SACL to LSASS.exe](#bkmk-lsass) -- [Added new fields in the logon event](#bkmk-logon) +- [Added new fields in the sign-in event](#bkmk-logon) - [Added new fields in the process creation event](#bkmk-logon) - [Added new Security Account Manager events](#bkmk-sam) - [Added new BCD events](#bkmk-bcd) @@ -119,20 +119,20 @@ With Windows 10, version 1507, we've added more info to existing audit events to ##### Changed the kernel default audit policy -In previous releases, the kernel depended on the Local Security Authority (LSA) to retrieve info in some of its events. In Windows 10, the process creation events audit policy is automatically enabled until an actual audit policy is received from LSA. This results in better auditing of services that may start before LSA starts. +In previous releases, the kernel depended on the Local Security Authority (LSA) to retrieve info in some of its events. In Windows 10, the process creation events audit policy is automatically enabled until an actual audit policy is received from LSA. This setting results in better auditing of services that may start before LSA starts. ##### Added a default process SACL to LSASS.exe -In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can enable this under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. -This can help identify attacks that steal credentials from the memory of a process. +In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can enable this process under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. +This process can help identify attacks that steal credentials from the memory of a process. -##### New fields in the logon event +##### New fields in the sign-in event -The logon event ID 4624 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4624: +The sign-in event ID 4624 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4624: 1. **MachineLogon** String: yes or no If the account that logged into the PC is a computer account, this field will be yes. Otherwise, the field is no. 2. **ElevatedToken** String: yes or no - If the account that logged into the PC is an administrative logon, this field will be yes. Otherwise, the field is no. Additionally, if this is part of a split token, the linked login ID (LSAP\_LOGON\_SESSION) will also be shown. + If an account signed in to the PC through the "administrative sign in" method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. 3. **TargetOutboundUserName** String **TargetOutboundUserDomain** String The username and domain of the identity that was created by the LogonUser method for outbound traffic. @@ -146,7 +146,7 @@ The logon event ID 4624 has been updated to include more verbose information to ##### New fields in the process creation event -The logon event ID 4688 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4688: +The sign-in event ID 4688 has been updated to include more verbose information to make them easier to analyze. The following fields have been added to event 4688: 1. **TargetUserSid** String The SID of the target principal. 2. **TargetUserName** String @@ -154,7 +154,7 @@ The logon event ID 4688 has been updated to include more verbose information to 3. **TargetDomainName** String The domain of the target user.. 4. **TargetLogonId** String - The logon ID of the target user. + The sign-in ID of the target user. 5. **ParentProcessName** String The name of the creator process. 6. **ParentProcessId** String @@ -224,9 +224,9 @@ Some things that you can check on the device are: User Account Control (UAC) helps prevent malware from damaging a computer and helps organizations deploy a better-managed desktop environment. -You should not turn off UAC because this is not a supported scenario for devices running Windows 10. If you do turn off UAC, all Universal Windows Platform apps stop working. You must always set the **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA** registry value to 1. If you need to provide auto elevation for programmatic access or installation, you could set the **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin** registry value to 0, which is the same as setting the UAC slider Never Notify. This is not recommended for devices running Windows 10. +You shouldn't turn off UAC because this setting isn't supportive of devices running Windows 10. If you do turn off UAC, all Universal Windows Platform apps stop working. You must always set the **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA** registry value to 1. If you need to provide auto elevation for programmatic access or installation, you could set the **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin** registry value to 0, which is the same as setting the UAC slider Never Notify. This setting isn't recommended for devices running Windows 10. -For more info about how manage UAC, see [UAC Group Policy Settings and Registry Key Settings](/windows/access-protection/user-account-control/user-account-control-group-policy-and-registry-key-settings). +For more information about how to manage UAC, see [UAC Group Policy Settings and Registry Key Settings](/windows/access-protection/user-account-control/user-account-control-group-policy-and-registry-key-settings). In Windows 10, User Account Control has added some improvements. @@ -309,7 +309,7 @@ Administrators can also use mobile device management (MDM) or Group Policy to di ### Microsoft Store for Business **New in Windows 10, version 1511** -With the Microsoft Store for Business, organizations can make volume purchases of Windows apps. The Store for Business provides app purchases based on organizational identity, flexible distribution options, and the ability to reclaim or re-use licenses. Organizations can also use the Store for Business to create a private store for their employees that includes apps from the Store, as well private Line-of-Business (LOB) apps. +With the Microsoft Store for Business, organizations can make volume purchases of Windows apps. The Store for Business provides app purchases based on organizational identity, flexible distribution options, and the ability to reclaim or reuse licenses. Organizations can also use the Store for Business to create a private store for their employees that includes apps from the Store, as well private Line-of-Business (LOB) apps. For more information, see [Microsoft Store for Business overview](/microsoft-store/windows-store-for-business-overview). @@ -318,15 +318,15 @@ For more information, see [Microsoft Store for Business overview](/microsoft-sto Windows Update for Business enables information technology administrators to keep the Windows 10-based devices in their organization always up to date with the latest security defenses and Windows features by directly connecting these systems to Microsoft’s Windows Update service. -By using [Group Policy Objects](/previous-versions/cc498727(v=msdn.10)), Windows Update for Business is an easily established and implemented system which enables organizations and administrators to exercise control on how their Windows 10-based devices are updated, by allowing: +By using [Group Policy Objects](/previous-versions/cc498727(v=msdn.10)), Windows Update for Business is an easily established and implemented system that enables organizations and administrators to exercise control on how their Windows 10-based devices are updated, by allowing: - **Deployment and validation groups**; where administrators can specify which devices go first in an update wave, and which devices will come later (to ensure any quality bars are met). -- **Peer-to-peer delivery**, which administrators can enable to make delivery of updates to branch offices and remote sites with limited bandwidth very efficient. +- **Peer-to-peer delivery**, which administrators can enable to make delivery of updates to branch offices and remote sites with limited bandwidth efficient. - **Use with existing tools** such as Microsoft Endpoint Manager and the [Enterprise Mobility Suite](/enterprise-mobility-security). -Together, these Windows Update for Business features help reduce device management costs, provide controls over update deployment, offer quicker access to security updates, as well as provide access to the latest innovations from Microsoft on an ongoing basis. Windows Update for Business is a free service for all Windows 10 Pro, Enterprise, and Education editions, and can be used independent of, or in conjunction with, existing device management solutions such as [Windows Server Update Services (WSUS)](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)) and [Microsoft Endpoint Configuration Manager](/configmgr). +Together, these Windows Update for Business features help reduce device management costs, provide controls over update deployment, offer quicker access to security updates, and provide access to the latest innovations from Microsoft on an ongoing basis. Windows Update for Business is a free service for all Windows 10 Pro, Enterprise, and Education editions, and can be used independent of, or in conjunction with, existing device management solutions such as [Windows Server Update Services (WSUS)](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)) and [Microsoft Endpoint Configuration Manager](/configmgr). Learn more about [Windows Update for Business](/windows/deployment/update/waas-manage-updates-wufb). diff --git a/windows/whats-new/whats-new-windows-10-version-1607.md b/windows/whats-new/whats-new-windows-10-version-1607.md index 48342fd24c..981388e744 100644 --- a/windows/whats-new/whats-new-windows-10-version-1607.md +++ b/windows/whats-new/whats-new-windows-10-version-1607.md @@ -1,6 +1,6 @@ --- title: What's new in Windows 10, version 1607 (Windows 10) -description: What's new in Windows 10 for Windows 10 (version 1607). +description: What's new in Windows 10 for Windows 10 (version 1607)? ms.prod: w10 ms.localizationpriority: medium ms.reviewer: @@ -22,7 +22,7 @@ Below is a list of some of the new and updated features in Windows 10, version 1 ### Windows Imaging and Configuration Designer (ICD) -In previous versions of the Windows 10 Assessment and Deployment Kit (ADK), you had to install additional features for Windows ICD to run. Starting in version 1607, you can install just the configuration designer component independent of the rest of the imaging components. [Install the ADK.](https://developer.microsoft.com/en-us/windows/hardware/windows-assessment-deployment-kit) +In previous versions of the Windows 10 Assessment and Deployment Kit (ADK), you had to install more features for Windows ICD to run. Starting in version 1607, you can install just the configuration designer component independent of the rest of the imaging components. [Install the ADK.](https://developer.microsoft.com/en-us/windows/hardware/windows-assessment-deployment-kit) Windows ICD now includes simplified workflows for creating provisioning packages: @@ -34,9 +34,9 @@ Windows ICD now includes simplified workflows for creating provisioning packages ### Windows Upgrade Readiness -Microsoft developed Upgrade Readiness in response to demand from enterprise customers looking for additional direction and details about upgrading to Windows 10. Upgrade Readiness was built taking into account multiple channels of customer feedback, testing, and Microsoft’s experience upgrading millions of devices to Windows 10. +Microsoft developed Upgrade Readiness in response to demand from enterprise customers looking for more direction and details about upgrading to Windows 10. Upgrade Readiness was built taking into account multiple channels of customer feedback, testing, and Microsoft’s experience upgrading millions of devices to Windows 10. -With Windows diagnostic data enabled, Upgrade Readiness collects system, application, and driver data for analysis. We then identify compatibility issues that can block an upgrade and suggest fixes when they are known to Microsoft. +With Windows diagnostic data enabled, Upgrade Readiness collects system, application, and driver data for analysis. We then identify compatibility issues that can block an upgrade and suggest fixes when they're known to Microsoft. Use Upgrade Readiness to get: @@ -69,9 +69,9 @@ Isolated User Mode is now included with Hyper-V so you don't have to install it ### Windows Hello for Business -When Windows 10 first shipped, it included Microsoft Passport and Windows Hello, which worked together to provide multi-factor authentication. To simplify deployment and improve supportability, Microsoft has combined these technologies into a single solution under the Windows Hello name in Windows 10, version 1607. Customers who have already deployed Microsoft Passport for Work will not experience any change in functionality. Customers who have yet to evaluate Windows Hello will find it easier to deploy due to simplified policies, documentation, and semantics. +When Windows 10 was first shipped, it included Microsoft Passport and Windows Hello, which worked together to provide multi-factor authentication. To simplify deployment and improve supportability, Microsoft has combined these technologies into a single solution under the Windows Hello name in Windows 10, version 1607. Customers who have already deployed Microsoft Passport for Work won't experience any change in functionality. Customers who have yet to evaluate Windows Hello will find it easier to deploy due to simplified policies, documentation, and semantics. -Additional changes for Windows Hello in Windows 10, version 1607: +Other changes for Windows Hello in Windows 10, version 1607: - Personal (Microsoft account) and corporate (Active Directory or Azure AD) accounts use a single container for keys. - Group Policy settings for managing Windows Hello for Business are now available for both **User Configuration** and **Computer Configuration**. @@ -82,7 +82,7 @@ Additional changes for Windows Hello in Windows 10, version 1607: ### VPN - The VPN client can integrate with the Conditional Access Framework, a cloud-based policy engine built into Azure Active Directory, to provide a device compliance option for remote clients. -- The VPN client can integrate with Windows Information Protection (WIP) policy to provide additional security. [Learn more about Windows Information Protection](/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip), previously known as Enterprise Data Protection. +- The VPN client can integrate with Windows Information Protection (WIP) policy to provide extra security. [Learn more about Windows Information Protection](/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip), previously known as Enterprise Data Protection. - New VPNv2 configuration service provider (CSP) adds configuration settings. For details, see [What's new in MDM enrollment and management](/windows/client-management/mdm/new-in-windows-mdm-enrollment-management#whatsnew_1607) - Microsoft Intune: *VPN* profile template includes support for native VPN plug-ins. For more information, see [Create VPN profiles to connect to VPN servers in Intune](/mem/intune/configuration/vpn-settings-configure). @@ -102,7 +102,7 @@ Several new features and management options have been added to Windows Defender - [Windows Defender Offline in Windows 10](/microsoft-365/security/defender-endpoint/microsoft-defender-offline) can be run directly from within Windows, without having to create bootable media. - [Use PowerShell cmdlets for Windows Defender](/microsoft-365/security/defender-endpoint/use-powershell-cmdlets-microsoft-defender-antivirus) to configure options and run scans. -- [Enable the Block at First Sight feature in Windows 10](/microsoft-365/security/defender-endpoint/configure-block-at-first-sight-microsoft-defender-antivirus) to leverage the Windows Defender cloud for near-instant protection against new malware. +- [Enable the Block at First Sight feature in Windows 10](/microsoft-365/security/defender-endpoint/configure-block-at-first-sight-microsoft-defender-antivirus) to use the Windows Defender cloud for near-instant protection against new malware. - [Configure enhanced notifications for Windows Defender in Windows 10](/microsoft-365/security/defender-endpoint/configure-notifications-microsoft-defender-antivirus) to see more information about threat detections and removal. - [Run a Windows Defender scan from the command line](/microsoft-365/security/defender-endpoint/command-line-arguments-microsoft-defender-antivirus). - [Detect and block Potentially Unwanted Applications with Windows Defender](/microsoft-365/security/defender-endpoint/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus) during download and install times. @@ -136,17 +136,17 @@ Windows 10, Version 1607, introduces shared PC mode, which optimizes Windows 10 Application Virtualization (App-V) enables organizations to deliver Win32 applications to users as virtual applications. Virtual applications are installed on centrally managed servers and delivered to users as a service – in real time and on as as-needed basis. Users launch virtual applications from familiar access points, including the Microsoft Store, and interact with them as if they were installed locally. -With the release of Windows 10, version 1607, App-V is included with the Windows 10 for Enterprise edition. If you are new to Windows 10 and App-V or if you're upgrading from a previous version of App-V, you’ll need to download, activate, and install server- and client-side components to start delivering virtual applications to users. +With the release of Windows 10, version 1607, App-V is included with the Windows 10 for Enterprise edition. If you're new to Windows 10 and App-V or if you're upgrading from a previous version of App-V, you’ll need to download, activate, and install server- and client-side components to start delivering virtual applications to users. [Learn how to deliver virtual applications with App-V.](/windows/application-management/app-v/appv-getting-started) ### User Experience Virtualization (UE-V) for Windows 10 -Many users customize their settings for Windows and for specific applications. Customizable Windows settings include Microsoft Store appearance, language, background picture, font size, and accent colors. Customizable application settings include language, appearance, behavior, and user interface options. +Many users customize their settings for Windows and for specific applications. Customizable Windows settings include Microsoft Store appearance, language, background picture, font size, and accent colors. Customizable application settings include language, appearance, behavior, and user interface options. -With User Experience Virtualization (UE-V), you can capture user-customized Windows and application settings and store them on a centrally managed network file share. When users log on, their personalized settings are applied to their work session, regardless of which device or virtual desktop infrastructure (VDI) sessions they log on to. +With User Experience Virtualization (UE-V), you can capture user-customized Windows and application settings and store them on a centrally managed network file share. When users sign in, their personalized settings are applied to their work session, regardless of which device or virtual desktop infrastructure (VDI) sessions they sign in to. -With the release of Windows 10, version 1607, UE-V is included with the Windows 10 for Enterprise edition. If you are new to Windows 10 and UE-V or upgrading from a previous version of UE-V, you’ll need to download, activate, and install server- and client-side components to start synchronizing user-customized settings across devices. +With the release of Windows 10, version 1607, UE-V is included with the Windows 10 for Enterprise edition. If you're new to Windows 10 and UE-V or upgrading from a previous version of UE-V, you’ll need to download, activate, and install server- and client-side components to start synchronizing user-customized settings across devices. [Learn how to synchronize user-customized settings with UE-V.](/windows/configuration/ue-v/uev-for-windows) diff --git a/windows/whats-new/whats-new-windows-10-version-1703.md b/windows/whats-new/whats-new-windows-10-version-1703.md index 5a1f162a4f..48815f6698 100644 --- a/windows/whats-new/whats-new-windows-10-version-1703.md +++ b/windows/whats-new/whats-new-windows-10-version-1703.md @@ -59,18 +59,18 @@ Enterprises have been able to apply customized Start and taskbar layouts to devi Previously, the customized taskbar could only be deployed using Group Policy or provisioning packages. Windows 10, version 1703, adds support for customized taskbars to [MDM](/windows/configuration/customize-windows-10-start-screens-by-using-mobile-device-management). -[Additional MDM policy settings are available for Start and taskbar layout](/windows/configuration/windows-10-start-layout-options-and-policies). New MDM policy settings include: +[More MDM policy settings are available for Start and taskbar layout](/windows/configuration/windows-10-start-layout-options-and-policies). New MDM policy settings include: - Settings for the User tile: [**Start/HideUserTile**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideusertile), [**Start/HideSwitchAccount**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideswitchaccount), [**Start/HideSignOut**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidesignout), [**Start/HideLock**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidelock), and [**Start/HideChangeAccountSettings**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidechangeaccountsettings) - Settings for Power: [**Start/HidePowerButton**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidepowerbutton), [**Start/HideHibernate**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidehibernate), [**Start/HideRestart**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderestart), [**Start/HideShutDown**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideshutdown), and [**Start/HideSleep**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidesleep) -- Additional new settings: [**Start/HideFrequentlyUsedApps**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidefrequentlyusedapps), [**Start/HideRecentlyAddedApps**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderecentlyaddedapps), **AllowPinnedFolder**, **ImportEdgeAssets**, [**Start/HideRecentJumplists**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderecentjumplists), [**Start/NoPinningToTaskbar**](/windows/client-management/mdm/policy-configuration-service-provider#start-nopinningtotaskbar), [**Settings/PageVisibilityList**](/windows/client-management/mdm/policy-configuration-service-provider#settings-pagevisibilitylist), and [**Start/HideAppsList**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideapplist). +- Other new settings: [**Start/HideFrequentlyUsedApps**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidefrequentlyusedapps), [**Start/HideRecentlyAddedApps**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderecentlyaddedapps), **AllowPinnedFolder**, **ImportEdgeAssets**, [**Start/HideRecentJumplists**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderecentjumplists), [**Start/NoPinningToTaskbar**](/windows/client-management/mdm/policy-configuration-service-provider#start-nopinningtotaskbar), [**Settings/PageVisibilityList**](/windows/client-management/mdm/policy-configuration-service-provider#settings-pagevisibilitylist), and [**Start/HideAppsList**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideapplist). ### Cortana at work -Cortana is Microsoft’s personal digital assistant, who helps busy people get things done, even while at work. Cortana has powerful configuration options, specifically optimized for your business. By signing in with an Azure Active Directory (Azure AD) account, your employees can give Cortana access to their enterprise/work identity, while getting all the functionality Cortana provides to them outside of work. +Cortana is Microsoft’s personal digital assistant, who helps busy people get things done, even while at work. Cortana has powerful configuration options, optimized for your business. When your employees sign in with an Azure Active Directory (Azure AD) account, they can give Cortana access to their enterprise/work identity, while getting all the functionality Cortana provides to them outside of work. Using Azure AD also means that you can remove an employee’s profile (for example, when an employee leaves your organization) while respecting Windows Information Protection (WIP) policies and ignoring enterprise content, such as emails, calendar items, and people lists that are marked as enterprise data. @@ -83,9 +83,9 @@ For more info about Cortana at work, see [Cortana integration in your business o MBR2GPT.EXE is a new command-line tool available in Windows 10 version 1703 and later versions. MBR2GPT converts a disk from Master Boot Record (MBR) to GUID Partition Table (GPT) partition style without modifying or deleting data on the disk. The tool is designed to be run from a Windows Preinstallation Environment (Windows PE) command prompt, but can also be run from the full Windows 10 operating system (OS). -The GPT partition format is newer and enables the use of larger and more disk partitions. It also provides added data reliability, supports additional partition types, and enables faster boot and shutdown speeds. If you convert the system disk on a computer from MBR to GPT, you must also configure the computer to boot in UEFI mode, so make sure that your device supports UEFI before attempting to convert the system disk. +The GPT partition format is newer and enables the use of larger and more disk partitions. It also provides added data reliability, supports other partition types, and enables faster boot and shutdown speeds. If you convert the system disk on a computer from MBR to GPT, you must also configure the computer to boot in UEFI mode, so make sure that your device supports UEFI before attempting to convert the system disk. -Additional security features of Windows 10 that are enabled when you boot in UEFI mode include: Secure Boot, Early Launch Anti-malware (ELAM) driver, Windows Trusted Boot, Measured Boot, Device Guard, Credential Guard, and BitLocker Network Unlock. +Other security features of Windows 10 that are enabled when you boot in UEFI mode include: Secure Boot, Early Launch Anti-malware (ELAM) driver, Windows Trusted Boot, Measured Boot, Device Guard, Credential Guard, and BitLocker Network Unlock. For details, see [MBR2GPT.EXE](/windows/deployment/mbr-to-gpt). @@ -106,7 +106,7 @@ New features in Microsoft Defender for Endpoint for Windows 10, version 1703 inc - [Alert process tree](/windows/threat-protection/windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection#alert-process-tree) - Aggregates multiple detections and related events into a single view to reduce case resolution time. - [Pull alerts using REST API](/windows/threat-protection/windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection) - Use REST API to pull alerts from Microsoft Defender for Endpoint. -- **Response**: When detecting an attack, security response teams can now take immediate action to contain a breach: +- **Response**: When an attack is detected, security response teams can now take immediate action to contain a breach: - [Take response actions on a machine](/windows/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection) - Quickly respond to detected attacks by isolating machines or collecting an investigation package. - [Take response actions on a file](/windows/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection) - Quickly respond to detected attacks by stopping and quarantining files or blocking a file. @@ -145,7 +145,7 @@ You can read more about ransomware mitigations and detection capability in Micro ### Device Guard and Credential Guard -Additional security qualifications for Device Guard and Credential Guard help protect vulnerabilities in UEFI runtime. +More security qualifications for Device Guard and Credential Guard help protect vulnerabilities in UEFI runtime. For more information, see [Device Guard Requirements](/windows/device-security/device-guard/requirements-and-deployment-planning-guidelines-for-device-guard) and [Credential Guard Security Considerations](/windows/access-protection/credential-guard/credential-guard-requirements#security-considerations). ### Group Policy Security Options @@ -172,7 +172,7 @@ You can also now collect your audit event logs by using the Reporting configurat ### Windows Update for Business -The pause feature has been changed, and now requires a start date to set up. Users are now able to pause through **Settings > Update & security > Windows Update > Advanced options** in case a policy has not been configured. We have also increased the pause limit on quality updates to 35 days. You can find more information on pause in [Pause Feature Updates](/windows/deployment/update/waas-configure-wufb#pause-feature-updates) and [Pause Quality Updates](/windows/deployment/update/waas-configure-wufb#pause-quality-updates). +The pause feature has been changed, and now requires a start date to set up. Users are now able to pause through **Settings > Update & security > Windows Update > Advanced options** in case a policy hasn't been configured. We've also increased the pause limit on quality updates to 35 days. You can find more information on pause in [Pause Feature Updates](/windows/deployment/update/waas-configure-wufb#pause-feature-updates) and [Pause Quality Updates](/windows/deployment/update/waas-configure-wufb#pause-quality-updates). Windows Update for Business managed devices are now able to defer feature update installation by up to 365 days (it used to be 180 days). In settings, users are able to select their branch readiness level and update deferral periods. See [Configure devices for Current Branch (CB) or Current Branch for Business (CBB)](/windows/deployment/update/waas-configure-wufb#configure-devices-for-current-branch-or-current-branch-for-business), [Configure when devices receive Feature Updates](/windows/deployment/update/waas-configure-wufb#configure-when-devices-receive-feature-updates) and [Configure when devices receive Quality Updates](/windows/deployment/update/waas-configure-wufb#configure-when-devices-receive-quality-updates) for details. @@ -184,12 +184,12 @@ We recently added the option to download Windows 10 Insider Preview builds using ### Optimize update delivery -With changes delivered in Windows 10, version 1703, [express updates](/windows/deployment/do/waas-optimize-windows-10-updates#express-update-delivery) are now fully supported with Microsoft Endpoint Configuration Manager, starting with version 1702 of Configuration Manager, as well as with other third-party updating and management products that [implement this new functionality](/windows-server/administration/windows-server-update-services/deploy/express-update-delivery-isv-support). This is in addition to current Express support on Windows Update, Windows Update for Business and WSUS. +With changes delivered in Windows 10, version 1703, [express updates](/windows/deployment/do/waas-optimize-windows-10-updates#express-update-delivery) are now fully supported with Microsoft Endpoint Configuration Manager, starting with version 1702 of Configuration Manager, and with other third-party updating and management products that [implement this new functionality](/windows-server/administration/windows-server-update-services/deploy/express-update-delivery-isv-support). This support is in addition to current Express support on Windows Update, Windows Update for Business and WSUS. >[!NOTE] > The above changes can be made available to Windows 10, version 1607, by installing the April 2017 cumulative update. -Delivery Optimization policies now enable you to configure additional restrictions to have more control in various scenarios. +Delivery Optimization policies now enable you to configure more restrictions to have more control in various scenarios. Added policies include: - [Allow uploads while the device is on battery while under set Battery level](/windows/deployment/update/waas-delivery-optimization#allow-uploads-while-the-device-is-on-battery-while-under-set-battery-level) @@ -204,7 +204,7 @@ To check out all the details, see [Configure Delivery Optimization for Windows 1 Starting with Windows 10, version 1703, in-box apps that were uninstalled by the user won't automatically reinstall as part of the feature update installation process. -Additionally, apps de-provisioned by admins on Windows 10, version 1703 machines will stay de-provisioned after future feature update installations. This will not apply to the update from Windows 10, version 1607 (or earlier) to version 1703. +Additionally, apps de-provisioned by admins on Windows 10, version 1703 machines will stay de-provisioned after future feature update installations. This condition won't apply to the update from Windows 10, version 1607 (or earlier) to version 1703. ## Management @@ -214,7 +214,7 @@ Windows 10, version 1703 adds many new [configuration service providers (CSPs)]( Some of the other new CSPs are: -- The [DynamicManagement CSP](/windows/client-management/mdm/dynamicmanagement-csp) allows you to manage devices differently depending on location, network, or time. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country to avoid roaming charges, or the wireless network can be disabled when the device is not within the corporate building or campus. Once configured, these settings will be enforced even if the device can’t reach the management server when the location or network changes. The Dynamic Management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs. +- The [DynamicManagement CSP](/windows/client-management/mdm/dynamicmanagement-csp) allows you to manage devices differently depending on location, network, or time. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can’t reach the management server when the location or network changes. The Dynamic Management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs. - The [CleanPC CSP](/windows/client-management/mdm/cleanpc-csp) allows removal of user-installed and pre-installed applications, with the option to persist user data. @@ -237,7 +237,7 @@ For more info, see [Implement server-side support for mobile application managem ### MDM diagnostics -In Windows 10, version 1703, we continue our work to improve the diagnostic experience for modern management. By introducing auto-logging for mobile devices, Windows will automatically collect logs when encountering an error in MDM, eliminating the need to have always-on logging for memory-constrained devices. Additionally, we are introducing [Microsoft Message Analyzer](/message-analyzer/microsoft-message-analyzer-operating-guide) as an additional tool to help Support personnel quickly reduce issues to their root cause, while saving time and cost. +In Windows 10, version 1703, we continue our work to improve the diagnostic experience for modern management. By introducing auto-logging for mobile devices, Windows will automatically collect logs when encountering an error in MDM, eliminating the need to have always-on logging for memory-constrained devices. Additionally, we're introducing [Microsoft Message Analyzer](/message-analyzer/microsoft-message-analyzer-operating-guide) as an extra tool to help Support personnel quickly reduce issues to their root cause, while saving time and cost. ### Application Virtualization for Windows (App-V) Previous versions of the Microsoft Application Virtualization Sequencer (App-V Sequencer) have required you to manually create your sequencing environment. Windows 10, version 1703 introduces two new PowerShell cmdlets, New-AppVSequencerVM and Connect-AppvSequencerVM, which automatically create your sequencing environment for you, including provisioning your virtual machine. Additionally, the App-V Sequencer has been updated to let you sequence or update multiple apps at the same time, while automatically capturing and storing your customizations as an App-V project template (.appvt) file, and letting you use PowerShell or Group Policy settings to automatically clean up your unpublished packages after a device restart. @@ -265,32 +265,32 @@ Learn about the new Group Policies that were added in Windows 10, version 1703. In the Windows 10, version 1703, Microsoft has extended the ability to send a Miracast stream over a local network rather than over a direct wireless link. This functionality is based on the [Miracast over Infrastructure Connection Establishment Protocol (MS-MICE)](/openspecs/windows_protocols/ms-mice/9598ca72-d937-466c-95f6-70401bb10bdb). -Miracast over Infrastructure offers a number of benefits: +Miracast over Infrastructure offers many benefits: - Windows automatically detects when sending the video stream over this path is applicable. - Windows will only choose this route if the connection is over Ethernet or a secure Wi-Fi network. -- Users do not have to change how they connect to a Miracast receiver. They use the same UX as for standard Miracast connections. +- Users don't have to change how they connect to a Miracast receiver. They use the same UX as for standard Miracast connections. - No changes to current wireless drivers or PC hardware are required. -- It works well with older wireless hardware that is not optimized for Miracast over Wi-Fi Direct. -- It leverages an existing connection which both reduces the time to connect and provides a very stable stream. +- It works well with older wireless hardware that isn't optimized for Miracast over Wi-Fi Direct. +- It uses an existing connection that reduces the time to connect and provides a stable stream. ### How it works -Users attempt to connect to a Miracast receiver as they did previously. When the list of Miracast receivers is populated, Windows 10 will identify that the receiver is capable of supporting a connection over the infrastructure. When the user selects a Miracast receiver, Windows 10 will attempt to resolve the device's hostname via standard DNS, as well as via multicast DNS (mDNS). If the name is not resolvable via either DNS method, Windows 10 will fall back to establishing the Miracast session using the standard Wi-Fi direct connection. +Users attempt to connect to a Miracast receiver as they did previously. When the list of Miracast receivers is populated, Windows 10 will identify that the receiver is capable of supporting a connection over the infrastructure. When the user selects a Miracast receiver, Windows 10 will attempt to resolve the device's hostname via standard DNS, and via multicast DNS (mDNS). If the name isn't resolvable via either DNS method, Windows 10 will fall back to establishing the Miracast session using the standard Wi-Fi direct connection. ### Enabling Miracast over Infrastructure -If you have a device that has been updated to Windows 10, version 1703, then you automatically have this new feature. To take advantage of it in your environment, you need to ensure the following is true within your deployment: +If you have a device that has been updated to Windows 10, version 1703, then you automatically have this new feature. To take advantage of it in your environment, you need to ensure the following requirements are true within your deployment: - The device (PC or Surface Hub) needs to be running Windows 10, version 1703. - A Windows PC or Surface Hub can act as a Miracast over Infrastructure *receiver*. A Windows device can act as a Miracast over Infrastructure *source*. - - As a Miracast receiver, the PC or Surface Hub must be connected to your enterprise network via either Ethernet or a secure Wi-Fi connection (e.g. using either WPA2-PSK or WPA2-Enterprise security). If the Hub is connected to an open Wi-Fi connection, Miracast over Infrastructure will disable itself. + - As a Miracast receiver, the PC or Surface Hub must be connected to your enterprise network via either Ethernet or a secure Wi-Fi connection (for example, using either WPA2-PSK or WPA2-Enterprise security). If the Hub is connected to an open Wi-Fi connection, Miracast over Infrastructure will disable itself. - As a Miracast source, the device must be connected to the same enterprise network via Ethernet or a secure Wi-Fi connection. -- The DNS Hostname (device name) of the device needs to be resolvable via your DNS servers. You can achieve this by either allowing your device to register automatically via Dynamic DNS, or by manually creating an A or AAAA record for the device's hostname. +- The DNS Hostname (device name) of the device needs to be resolvable via your DNS servers. You can achieve this resolution by either allowing your device to register automatically via Dynamic DNS, or by manually creating an A or AAAA record for the device's hostname. - Windows 10 PCs must be connected to the same enterprise network via Ethernet or a secure Wi-Fi connection. -It is important to note that Miracast over Infrastructure is not a replacement for standard Miracast. Instead, the functionality is complementary, and provides an advantage to users who are part of the enterprise network. Users who are guests to a particular location and don’t have access to the enterprise network will continue to connect using the Wi-Fi Direct connection method. +It's important to note that Miracast over Infrastructure isn't a replacement for standard Miracast. Instead, the functionality is complementary, and provides an advantage to users who are part of the enterprise network. Users who are guests to a particular location and don’t have access to the enterprise network will continue to connect using the Wi-Fi Direct connection method. ## New features in related products The following new features aren't part of Windows 10, but help you make the most of it. diff --git a/windows/whats-new/whats-new-windows-10-version-1709.md b/windows/whats-new/whats-new-windows-10-version-1709.md index 0585c1b9ab..4e26d46510 100644 --- a/windows/whats-new/whats-new-windows-10-version-1709.md +++ b/windows/whats-new/whats-new-windows-10-version-1709.md @@ -39,14 +39,14 @@ Windows 10 Subscription Activation lets you deploy Windows 10 Enterprise in your ### Autopilot Reset -IT Pros can use Autopilot Reset to quickly remove personal files, apps, and settings. A custom login screen is available from the lock screen that enables you to apply original settings and management enrollment (Azure Active Directory and device management) so that devices are returned to a fully configured, known, IT-approved state and ready to use. For more information, see [Reset devices with Autopilot Reset](/education/windows/autopilot-reset). +IT Pros can use Autopilot Reset to quickly remove personal files, apps, and settings. A custom sign-in screen is available from the lock screen that enables you to apply original settings and management enrollment (Azure Active Directory and device management) so that devices are returned to a fully configured, known, IT-approved state and ready to use. For more information, see [Reset devices with Autopilot Reset](/education/windows/autopilot-reset). ## Update ### Windows Update for Business -Windows Update for Business now has additional controls available to manage Windows Insider Program enrollment through policies. For more information, see [Manage Windows Insider Program flights](/windows/deployment/update/waas-configure-wufb#configure-when-devices-receive-windows-insider-preview-builds). +Windows Update for Business now has more controls available to manage Windows Insider Program enrollment through policies. For more information, see [Manage Windows Insider Program flights](/windows/deployment/update/waas-configure-wufb#configure-when-devices-receive-windows-insider-preview-builds). ### Windows Insider Program for Business @@ -98,7 +98,7 @@ Window Defender Exploit Guard provides intrusion prevention capabilities to redu ### Windows Defender Device Guard -Configurable code integrity is being rebranded as Windows Defender Application Control. This is to help distinguish it as a standalone feature to control execution of applications. For more information about Device Guard, see Windows [Defender Device Guard deployment guide](/windows/device-security/device-guard/device-guard-deployment-guide). +Configurable code integrity is being rebranded as Windows Defender Application Control. This rebranding is to help distinguish it as a standalone feature to control execution of applications. For more information about Device Guard, see Windows [Defender Device Guard deployment guide](/windows/device-security/device-guard/device-guard-deployment-guide). ### Windows Information Protection @@ -106,7 +106,7 @@ Windows Information Protection is now designed to work with Microsoft Office and ### Windows Hello -New features in Windows Hello enable a better device lock experience, using multifactor unlock with new location and user proximity signals. Using Bluetooth signals, you can configure your Windows 10 device to automatically lock when you walk away from it, or to prevent others from accessing the device when you are not present. More details about this feature will be available soon. For general information, see [Windows Hello for Business](/windows/access-protection/hello-for-business/hello-identity-verification). +New features in Windows Hello enable a better device lock experience, using multifactor unlock with new location and user proximity signals. Using Bluetooth signals, you can configure your Windows 10 device to automatically lock when you walk away from it, or to prevent others from accessing the device when you aren't present. More details about this feature will be available soon. For general information, see [Windows Hello for Business](/windows/access-protection/hello-for-business/hello-identity-verification). ### BitLocker diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index d8903b9bbb..c8ada416cc 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -30,7 +30,7 @@ The following 3-minute video summarizes some of the new features that are availa [Windows Autopilot](/windows/deployment/windows-autopilot/windows-10-autopilot) provides a modern device lifecycle management service powered by the cloud that delivers a zero touch experience for deploying Windows 10. -Using Intune, Autopilot now enables locking the device during provisioning during the Windows Out Of Box Experience (OOBE) until policies and settings for the device get provisioned, thereby ensuring that by the time the user gets to the desktop, the device is secured and configured correctly. +With the help of Intune, Autopilot now enables locking the device during provisioning during the Windows Out Of Box Experience (OOBE) until policies and settings for the device get provisioned, thereby ensuring that by the time the user gets to the desktop, the device is secured and configured correctly. Windows Autopilot is now available with Surface, Lenovo, and Dell. Other OEM partners such as HP, Toshiba, Panasonic, and Fujitsu will support Autopilot in coming months. Check back here later for more information. @@ -45,13 +45,13 @@ Some additional information about Windows 10 in S mode: - Choice and flexibility. Save your files to your favorite cloud, like OneDrive or DropBox, and access them from any device you choose. Browse the Microsoft Store for thousands of apps. - S mode, on a range of modern devices. Enjoy all the great Windows multi-tasking features, like snapping Windows, task view and virtual desktops on a range of S mode enabled devices. -If you want to switch out of S mode, you will be able to do so at no charge, regardless of edition. Once you switch out of S mode, you cannot switch back. +If you want to switch out of S mode, you'll be able to do so at no charge, regardless of edition. Once you switch out of S mode, you can't switch back. For more information, see [Windows 10 Pro/Enterprise in S mode](/windows/deployment/windows-10-pro-in-s-mode). ### Windows 10 kiosk and Kiosk Browser -With this release you can easily deploy and manage kiosk devices with Microsoft Intune in single and multiple app scenarios. This includes the new Kiosk Browser available from the Microsoft Store. Kiosk Browser is great for delivering a reliable and custom-tailored browsing experience for scenarios such as retail and signage. A summary of new features is below. +With this release, you can easily deploy and manage kiosk devices with Microsoft Intune in single- and multiple-app scenarios. These scenarios include the new Kiosk Browser available from the Microsoft Store. Kiosk Browser is great for delivering a reliable and custom-tailored browsing experience for scenarios such as retail and signage. A summary of new features is below. - Using Intune, you can deploy the Kiosk Browser from the Microsoft Store, configure start URL, allowed URLs, and enable/disable navigation buttons. - Using Intune, you can deploy and configure shared devices and kiosks using assigned access to create a curated experience with the correct apps and configuration policies @@ -78,7 +78,7 @@ The following new DISM commands have been added to manage feature updates: | Command | Description | |---|---| -| `DISM /Online /Initiate-OSUninstall` | Initiates a OS uninstall to take the computer back to the previous installation of windows. | +| `DISM /Online /Initiate-OSUninstall` | Initiates an OS uninstall to take the computer back to the previous installation of windows. | | `DISM /Online /Remove-OSUninstall` | Removes the OS uninstall capability from the computer. | | `DISM /Online /Get-OSUninstallWindow` | Displays the number of days after upgrade during which uninstall can be performed. | | `DISM /Online /Set-OSUninstallWindow` | Sets the number of days after upgrade during which uninstall can be performed. | @@ -96,7 +96,7 @@ Prerequisites: For more information, see [Run custom actions during feature update](/windows-hardware/manufacture/desktop/windows-setup-enable-custom-actions). -It is also now possible to run a script if the user rolls back their version of Windows using the PostRollback option: +It's also now possible to run a script if the user rolls back their version of Windows using the PostRollback option: `/PostRollback [\setuprollback.cmd] [/postrollback {system / admin}]` @@ -107,8 +107,8 @@ New command-line switches are also available to control BitLocker: | Command | Description | |---|---| | `Setup.exe /BitLocker AlwaysSuspend` | Always suspend BitLocker during upgrade. | -| `Setup.exe /BitLocker TryKeepActive` | Enable upgrade without suspending BitLocker, but if upgrade does not work, then suspend BitLocker and complete the upgrade. | -| `Setup.exe /BitLocker ForceKeepActive` | Enable upgrade without suspending BitLocker, but if upgrade does not work, fail the upgrade. | +| `Setup.exe /BitLocker TryKeepActive` | Enable upgrade without suspending BitLocker, but if upgrade doesn't work, then suspend BitLocker and complete the upgrade. | +| `Setup.exe /BitLocker ForceKeepActive` | Enable upgrade without suspending BitLocker, but if upgrade doesn't work, fail the upgrade. | For more information, see [Windows Setup Command-Line Options](/windows-hardware/manufacture/desktop/windows-setup-command-line-options#33) @@ -116,15 +116,15 @@ For more information, see [Windows Setup Command-Line Options](/windows-hardware [SetupDiag](/windows/deployment/upgrade/setupdiag) is a new command-line tool that can help diagnose why a Windows 10 update failed. -SetupDiag works by searching Windows Setup log files. When searching log files, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 26 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. +SetupDiag works by searching Windows Setup log files. When log files are being searched, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 26 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. ### Windows Update for Business -Windows Update for Business now provides greater control over updates, with the ability to pause and uninstall problematic updates using Intune. For more information, see [Manage software updates in Intune](/intune/windows-update-for-business-configure). +Windows Update for Business now provides greater control over updates, with the ability to pause and uninstall problematic updates using Intune. For more information, see [Manage software updates in Intune](/intune/windows-update-for-business-configure). ### Feature update improvements -Portions of the work done during the offline phases of a Windows update have been moved to the online phase. This has resulted in a significant reduction of offline time when installing updates. For more information, see [We're listening to you](https://insider.windows.com/en-us/articles/were-listening-to-you/). +Portions of the work done during the offline phases of a Windows update have been moved to the online phase. This migration has resulted in a significant reduction of offline time when installing updates. For more information, see [We're listening to you](https://insider.windows.com/en-us/articles/were-listening-to-you/). ## Configuration @@ -147,7 +147,7 @@ The OS uninstall period is a length of time that users are given when they can o - Windows Hello is part of the account protection pillar in Windows Defender Security Center. Account Protection will encourage password users to set up Windows Hello Face, Fingerprint or PIN for faster sign in, and will notify Dynamic lock users if Dynamic lock has stopped working because their phone or device Bluetooth is off. - You can set up Windows Hello from lock screen for Microsoft accounts. We’ve made it easier for Microsoft account users to set up Windows Hello on their devices for faster and more secure sign-in. Previously, you had to navigate deep into Settings to find Windows Hello. Now, you can set up Windows Hello Face, Fingerprint or PIN straight from your lock screen by clicking the Windows Hello tile under Sign-in options. - New [public API](/uwp/api/windows.security.authentication.web.core.webauthenticationcoremanager.findallaccountsasync#Windows_Security_Authentication_Web_Core_WebAuthenticationCoreManager_FindAllAccountsAsync_Windows_Security_Credentials_WebAccountProvider_) for secondary account SSO for a particular identity provider. -- It is easier to set up Dynamic lock, and WD SC actionable alerts have been added when Dynamic lock stops working (ex: phone Bluetooth is off). +- It's easier to set up Dynamic lock, and WD SC actionable alerts have been added when Dynamic lock stops working (ex: phone Bluetooth is off). For more information, see: [Windows Hello and FIDO2 Security Keys enable secure and easy authentication for shared devices](https://blogs.windows.com/business/2018/04/17/windows-hello-fido2-security-keys/#OdKBg3pwJQcEKCbJ.97) @@ -159,7 +159,7 @@ For more information, see: [Windows Hello and FIDO2 Security Keys enable secure ### Privacy -In the Feedback and Settings page under Privacy Settings you can now delete the diagnostic data your device has sent to Microsoft. You can also view this diagnostic data using the [Diagnostic Data Viewer](/windows/configuration/diagnostic-data-viewer-overview) app. +In the Feedback and Settings page under Privacy Settings, you can now delete the diagnostic data your device has sent to Microsoft. You can also view this diagnostic data using the [Diagnostic Data Viewer](/windows/configuration/diagnostic-data-viewer-overview) app. ## Security @@ -169,7 +169,7 @@ The new [security baseline for Windows 10 version 1803](/windows/security/threat ### Microsoft Defender Antivirus -Microsoft Defender Antivirus now shares detection status between M365 services and interoperates with Microsoft Defender for Endpoint. Additional policies have also been implemented to enhance cloud based protection, and new channels are available for emergency protection. For more information, see [Virus and threat protection](/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection) and [Use next-gen technologies in Microsoft Defender Antivirus through cloud-delivered protection](/microsoft-365/security/defender-endpoint/cloud-protection-microsoft-defender-antivirus). +Microsoft Defender Antivirus now shares detection status between Microsoft 365 services and interoperates with Microsoft Defender for Endpoint. Other policies have also been implemented to enhance cloud-based protection, and new channels are available for emergency protection. For more information, see [Virus and threat protection](/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection) and [Use next-gen technologies in Microsoft Defender Antivirus through cloud-delivered protection](/microsoft-365/security/defender-endpoint/cloud-protection-microsoft-defender-antivirus). ### Windows Defender Exploit Guard @@ -193,7 +193,7 @@ Windows Defender Application Guard has added support for Edge. For more informat ### Windows Defender Device Guard -Configurable code integrity is being rebranded as Windows Defender Application Control. This is to help distinguish it as a standalone feature to control execution of applications. For more information about Device Guard, see Windows [Defender Device Guard deployment guide](/windows/device-security/device-guard/device-guard-deployment-guide). +Configurable code integrity is being rebranded as Windows Defender Application Control. This rebranding is to help distinguish it as a standalone feature to control execution of applications. For more information about Device Guard, see Windows [Defender Device Guard deployment guide](/windows/device-security/device-guard/device-guard-deployment-guide). ### Windows Information Protection @@ -215,7 +215,7 @@ Update Compliance has added Delivery Optimization to assess the bandwidth consum ### Device Health -Device Health’s new App Reliability reports enable you to see where app updates or configuration changes may be needed to reduce crashes. The Login Health reports reveal adoption, success rates, and errors for Windows Hello and for passwords— for a smooth migration to the password-less future. For more information, see [Using Device Health](/windows/deployment/update/device-health-using). +Device Health’s new App Reliability reports enable you to see where app updates or configuration changes may be needed to reduce crashes. The Login Health reports reveal adoption, success rates, and errors for Windows Hello and for passwords—for a smooth migration to the password-less future. For more information, see [Using Device Health](/windows/deployment/update/device-health-using). ## Microsoft Edge diff --git a/windows/whats-new/whats-new-windows-10-version-1809.md b/windows/whats-new/whats-new-windows-10-version-1809.md index d587dd6af5..456dc6cece 100644 --- a/windows/whats-new/whats-new-windows-10-version-1809.md +++ b/windows/whats-new/whats-new-windows-10-version-1809.md @@ -15,7 +15,7 @@ ROBOTS: NOINDEX >Applies To: Windows 10, version 1809 -In this article we describe new and updated features of interest to IT Pros for Windows 10, version 1809. This update also contains all features and fixes included in previous cumulative updates to Windows 10, version 1803. +In this article, we describe new and updated features of interest to IT Pros for Windows 10, version 1809. This update also contains all features and fixes included in previous cumulative updates to Windows 10, version 1803. The following 3-minute video summarizes some of the new features that are available for IT Pros in this release. @@ -46,33 +46,33 @@ We’ve continued to work on the **Current threats** area in [Virus & threat pr > [!div class="mx-imgBorder"] > ![Virus & threat protection settings.](images/virus-and-threat-protection.png "Virus & threat protection settings") -With controlled folder access you can help prevent ransomware and other destructive malware from changing your personal files. In some cases, apps that you normally use might be blocked from making changes to common folders like **Documents** and **Pictures**. We’ve made it easier for you to add apps that were recently blocked so you can keep using your device without turning off the feature altogether. +With controlled folder access, you can help prevent ransomware and other destructive malware from changing your personal files. In some cases, apps that you normally use might be blocked from making changes to common folders like **Documents** and **Pictures**. We’ve made it easier for you to add apps that were recently blocked so you can keep using your device without turning off the feature altogether. When an app is blocked, it will appear in a recently blocked apps list, which you can get to by clicking **Manage settings** under the **Ransomware protection** heading. Click **Allow an app through Controlled folder access**. After the prompt, click the **+** button and choose **Recently blocked apps**. Select any of the apps to add them to the allowed list. You can also browse for an app from this page. -We added a new assessment for the Windows time service to the **Device performance & health** section. If we detect that your device’s time is not properly synced with our time servers and the time-syncing service is disabled, we’ll provide the option for you to turn it back on. +We added a new assessment for the Windows time service to the **Device performance & health** section. If we detect that your device’s time isn't properly synced with our time servers and the time-syncing service is disabled, we’ll provide the option for you to turn it back on. We’re continuing to work on how other security apps you’ve installed show up in the **Windows Security** app. There’s a new page called **Security providers** that you can find in the **Settings** section of the app. Click **Manage providers** to see a list of all the other security providers (including antivirus, firewall, and web protection) that are running on your device. Here you can easily open the providers’ apps or get more information on how to resolve issues reported to you through **Windows Security**. -This also means you’ll see more links to other security apps within **Windows Security**. For example, if you open the **Firewall & network protection** section, you’ll see the firewall apps that are running on your device under each firewall type, which includes domain, private, and public networks). +This functionality also means you’ll see more links to other security apps within **Windows Security**. For example, if you open the **Firewall & network protection** section, you’ll see the firewall apps that are running on your device under each firewall type, which includes domain, private, and public networks). ### BitLocker #### Silent enforcement on fixed drives -Through a Modern Device Management (MDM) policy, BitLocker can be enabled silently for standard Azure Active Directory (AAD)-joined users. In Windows 10, version 1803 automatic BitLocker encryption was enabled for standard Azure AD users, but this still required modern hardware that passed the Hardware Security Test Interface (HSTI). This new functionality enables BitLocker via policy even on devices that don’t pass the HSTI. +Through a Modern Device Management (MDM) policy, BitLocker can be enabled silently for standard Azure Active Directory (AAD)-joined users. In Windows 10, version 1803 automatic BitLocker encryption was enabled for standard Azure AD users, but this effect of the encryption still required modern hardware that passed the Hardware Security Test Interface (HSTI). This new functionality enables BitLocker via policy even on devices that don’t pass the HSTI. -This is an update to the [BitLocker CSP](/windows/client-management/mdm/bitlocker-csp), which was introduced in Windows 10, version 1703, and leveraged by Intune and others. +This new functionality is an update to the [BitLocker CSP](/windows/client-management/mdm/bitlocker-csp), which was introduced in Windows 10, version 1703, and used by Intune and others. This feature will soon be enabled on Olympia Corp as an optional feature. #### Delivering BitLocker policy to AutoPilot devices during OOBE -You can choose which encryption algorithm to apply to BitLocker encryption capable devices, rather than automatically having those devices encrypt themselves with the default algorithm. This allows the encryption algorithm (and other BitLocker policies that must be applied prior to encryption), to be delivered before BitLocker encryption begins. +You can choose which encryption algorithm to apply to BitLocker encryption capable devices, rather than automatically having those devices encrypt themselves with the default algorithm. This option allows the encryption algorithm (and other BitLocker policies that must be applied prior to encryption), to be delivered before BitLocker encryption begins. For example, you can choose the XTS-AES 256 encryption algorithm, and have it applied to devices that would normally encrypt themselves automatically with the default XTS-AES 128 algorithm during OOBE. -To achieve this: +To achieve this setting: 1. Configure the [encryption method settings](/intune/endpoint-protection-windows-10#windows-encryption) in the Windows 10 Endpoint Protection profile to the desired encryption algorithm. @@ -94,7 +94,7 @@ Windows Defender Application Guard (WDAG) introduced a new user interface inside Additionally, users who are managed by enterprise policies will be able to check their settings to see what their administrators have configured for their machines to better understand the behavior of Windows Defender Application Guard. This new UI improves the overall experience for users while managing and checking their Windows Defender Application Guard settings. As long as devices meet the minimum requirements, these settings will appear in Windows Security. For more information, see [Windows Defender Application Guard inside Windows Security App](https://techcommunity.microsoft.com/t5/Windows-Insider-Program/test/m-p/214102#M1709). -To try this: +To try this settings management, perform the following steps: 1. Go to **Windows Security** and select **App & browser control**. @@ -122,17 +122,17 @@ See the following example: Windows Defender Security Center is now called **Windows Security Center**. -You can still get to the app in all the usual ways – simply ask Cortana to open Windows Security Center(WSC) or interact with the taskbar icon. WSC lets you manage all your security needs, including **Microsoft Defender Antivirus** and **Windows Defender Firewall**. +You can still get to the app in all the usual ways–ask Cortana to open Windows Security Center(WSC) or interact with the taskbar icon. WSC lets you manage all your security needs, including **Microsoft Defender Antivirus** and **Windows Defender Firewall**. -The WSC service now requires antivirus products to run as a protected process to register. Products that have not yet implemented this will not appear in the Windows Security Center user interface, and Microsoft Defender Antivirus will remain enabled side-by-side with these products. +The WSC service now requires antivirus products to run as a protected process to register. Products that haven't yet implemented this execution won't appear in the Windows Security Center user interface, and Microsoft Defender Antivirus will remain enabled side-by-side with these products. -WSC now includes the Fluent Design System elements you know and love. You’ll also notice we’ve adjusted the spacing and padding around the app. It will now dynamically size the categories on the main page if more room is needed for extra info. We also updated the title bar so that it will use your accent color if you have enabled that option in **Color Settings**. +WSC now includes the Fluent Design System elements you know and love. You’ll also notice we’ve adjusted the spacing and padding around the app. It will now dynamically size the categories on the main page if more room is needed for extra info. We also updated the title bar so that it will use your accent color if you've enabled that option in **Color Settings**. ![alt text.](images/defender.png "Windows Security Center") ### Windows Defender Firewall now supports Windows Subsystem for Linux (WSL) processes -You can add specific rules for a WSL process in Windows Defender Firewall, just as you would for any Windows process. Also, Windows Defender Firewall now supports notifications for WSL processes. For example, when a Linux tool wants to allow access to a port from the outside (like SSH or a web server like nginx), Windows Defender Firewall will prompt to allow access just like it would for a Windows process when the port starts accepting connections. This was first introduced in [Build 17627](/windows/wsl/release-notes#build-17618-skip-ahead). +You can add specific rules for a WSL process in Windows Defender Firewall, just as you would for any Windows process. Also, Windows Defender Firewall now supports notifications for WSL processes. For example, when a Linux tool wants to allow access to a port from the outside (like SSH or a web server like nginx), Windows Defender Firewall will prompt to allow access just like it would for a Windows process when the port starts accepting connections. This support was first introduced in [Build 17627](/windows/wsl/release-notes#build-17618-skip-ahead). ### Microsoft Edge Group Policies @@ -140,9 +140,9 @@ We introduced new group policies and Modern Device Management settings to manage ### Windows Defender Credential Guard is supported by default on 10S devices that are Azure Active Directory-joined -Windows Defender Credential Guard is a security service in Windows 10 built to protect Active Directory (AD) domain credentials so that they can't be stolen or misused by malware on a user's machine. It is designed to protect against well-known threats such as Pass-the-Hash and credential harvesting. +Windows Defender Credential Guard is a security service in Windows 10 built to protect Active Directory (AD) domain credentials so that they can't be stolen or misused by malware on a user's machine. It's designed to protect against well-known threats such as Pass-the-Hash and credential harvesting. -Windows Defender Credential Guard has always been an optional feature, but Windows 10-S turns this functionality on by default when the machine has been Azure Active Directory-joined. This provides an added level of security when connecting to domain resources not normally present on 10-S devices. Please note that Windows Defender Credential Guard is available only to S-Mode devices or Enterprise and Education Editions. +Windows Defender Credential Guard has always been an optional feature, but Windows 10-S turns on this functionality by default when the machine has been Azure Active Directory-joined. This functionality provides an added level of security when connecting to domain resources not normally present on 10-S devices. Windows Defender Credential Guard is available only to S-Mode devices or Enterprise and Education Editions. ### Windows 10 Pro S Mode requires a network connection @@ -153,10 +153,10 @@ A network connection is now required to set up a new device. As a result, we rem [Microsoft Defender for Endpoint](/windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection) has been enhanced with many new capabilities. For more information, see the following topics: - [Threat analytics](/windows/security/threat-protection/windows-defender-atp/threat-analytics)
    -Threat Analytics is a set of interactive reports published by the Microsoft Defender for Endpoint research team as soon as emerging threats and outbreaks are identified. The reports help security operations teams assess impact on their environment and provides recommended actions to contain, increase organizational resilience, and prevent specific threats. +Threat Analytics is a set of interactive reports published by the Microsoft Defender for Endpoint research team as soon as emerging threats and outbreaks are identified. The reports help security operations teams assess impact on their environment and provide recommended actions to contain, increase organizational resilience, and prevent specific threats. - [Custom detection](/microsoft-365/security/defender/custom-detections-overview)
    - With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. This can be done by leveraging the power of Advanced hunting through the creation of custom detection rules. + With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. This query creation can be done by using the power of Advanced hunting through the creation of custom detection rules. - [Managed security service provider (MSSP) support](/windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection)
    Microsoft Defender for Endpoint adds support for this scenario by providing MSSP integration. @@ -164,10 +164,10 @@ The integration will allow MSSPs to take the following actions: Get access to MSSP customer's Windows Defender Security Center portal, fetch email notifications, and fetch alerts through security information and event management (SIEM) tools. - [Integration with Azure Defender](/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#integration-with-azure-security-center)
    -Microsoft Defender for Endpoint integrates with Azure Defender to provide a comprehensive server protection solution. With this integration Azure Defender can leverage the power of Microsoft Defender for Endpoint to provide improved threat detection for Windows Servers. +Microsoft Defender for Endpoint integrates with Azure Defender to provide a comprehensive server protection solution. With this integration, Azure Defender can use the power of Microsoft Defender for Endpoint to provide improved threat detection for Windows Servers. - [Integration with Microsoft Cloud App Security](/windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-integration)
    -Microsoft Cloud App Security leverages Microsoft Defender for Endpoint signals to allow direct visibility into cloud application usage including the use of unsupported cloud services (shadow IT) from all Microsoft Defender for Endpoint monitored machines. +Microsoft Cloud App Security uses Microsoft Defender for Endpoint signals to allow direct visibility into cloud application usage including the use of unsupported cloud services (shadow IT) from all Microsoft Defender for Endpoint monitored machines. - [Onboard Windows Server 2019](/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#windows-server-version-1803-and-windows-server-2019)
    Microsoft Defender for Endpoint now adds support for Windows Server 2019. You'll be able to onboard Windows Server 2019 in the same method available for Windows 10 client machines. @@ -185,7 +185,7 @@ Cloud clipboard helps users copy content between devices. It also manages the cl 3. Turn on **Clipboard history**. -4. Turn on **Sync across devices**. Chose whether or not to automatically sync copied text across your devices. +4. Turn on **Sync across devices**. Choose whether or not to automatically sync copied text across your devices. ## Kiosk setup experience @@ -199,7 +199,7 @@ Microsoft Edge kiosk mode running in single-app assigned access has two kiosk ty 1. **Digital / Interactive signage** that displays a specific website full-screen and runs InPrivate mode. -2. **Public browsing** supports multi-tab browsing and runs InPrivate mode with minimal features available. Users cannot minimize, close, or open new Microsoft Edge windows or customize them using Microsoft Edge Settings. Users can clear browsing data and downloads, and restart Microsoft Edge by clicking **End session**. Administrators can configure Microsoft Edge to restart after a period of inactivity. +2. **Public browsing** supports multi-tab browsing and runs InPrivate mode with minimal features available. Users can't minimize, close, or open new Microsoft Edge windows or customize them using Microsoft Edge Settings. Users can clear browsing data and downloads, and restart Microsoft Edge by clicking **End session**. Administrators can configure Microsoft Edge to restart after a period of inactivity. ![single app assigned access.](images/SingleApp_contosoHotel_inFrame@2x.png "single app assigned access") @@ -212,7 +212,7 @@ Microsoft Edge kiosk mode running in multi-app assigned access has two kiosk typ ![multi-app assigned access.](images/Multi-app_kiosk_inFrame.png "multi-app assigned access") -**Normal mode** runs a full version of Microsoft Edge, although some features may not work depending on what apps are configured in assigned access. For example, if the Microsoft Store is not set up, users cannot get books. +**Normal mode** runs a full version of Microsoft Edge, although some features may not work depending on what apps are configured in assigned access. For example, if the Microsoft Store isn't set up, users can't get books. ![normal mode.](images/Normal_inFrame.png "normal mode") @@ -245,12 +245,12 @@ Do you have shared devices deployed in your work place? **Fast sign-in** enables >[!IMPORTANT] >This is a private preview feature and therefore not meant or recommended for production purposes. This setting is not currently supported at this time. -Until now, Windows logon only supported the use of identities federated to ADFS or other providers that support the WS-Fed protocol. We are introducing **web sign-in**, a new way of signing into your Windows PC. Web sign-in enables Windows logon support for credentials not available on Windows. Web sign-in is restricted to only support Azure AD temporary access pass. +Until now, Windows sign in only supported the use of identities federated to ADFS or other providers that support the WS-Fed protocol. We're introducing **web sign-in**, a new way of signing into your Windows PC. Web sign-in enables Windows sign-in support for credentials not available on Windows. Web sign-in is restricted to only support Azure AD temporary access pass. **To try out web sign-in:** 1. Azure AD Join your Windows 10 PC. (Web sign-in is only supported on Azure AD Joined PCs). -2. Set the Policy CSP, and the Authentication and EnableWebSignIn polices to enable web sign-in. +2. Set the Policy CSP, and the Authentication and EnableWebSignIn policies to enable web sign-in. 3. On the lock screen, select web sign-in under sign-in options. @@ -264,9 +264,9 @@ Until now, Windows logon only supported the use of identities federated to ADFS ## Your Phone app -Android phone users, you can finally stop emailing yourself photos. With Your Phone you get instant access to your Android’s most recent photos on your PC. Drag and drop a photo from your phone onto your PC, then you can copy, edit, or ink on the photo. Try it out by opening the **Your Phone** app. You’ll receive a text with a link to download an app from Microsoft to your phone. Android 7.0+ devices with ethernet or Wi-Fi on unmetered networks are compatible with the **Your Phone** app. For PCs tied to the China region, **Your Phone** app services will be enabled in the future. +Android phone users, you can finally stop emailing yourself photos. With Your Phone, you get instant access to your Android’s most recent photos on your PC. Drag and drop a photo from your phone onto your PC, then you can copy, edit, or ink on the photo. Try it out by opening the **Your Phone** app. You’ll receive a text with a link to download an app from Microsoft to your phone. Android 7.0+ devices with ethernet or Wi-Fi on unmetered networks are compatible with the **Your Phone** app. For PCs tied to the China region, **Your Phone** app services will be enabled in the future. -For iPhone users, **Your Phone** app also helps you to link your phone to your PC. Surf the web on your phone, then send the webpage instantly to your computer to continue what you’re doing–-read, watch, or browse-- with all the benefits of a bigger screen. +For iPhone users, **Your Phone** app also helps you to link your phone to your PC. Surf the web on your phone, then send the webpage instantly to your computer to continue what you’re doing-read, watch, or browse-with all the benefits of a bigger screen. > [!div class="mx-imgBorder"] > ![your phone.](images/your-phone.png "your phone") @@ -278,8 +278,8 @@ The desktop pin takes you directly to the **Your Phone** app for quicker access One of the things we’ve heard from you is that it’s hard to know when you’re wirelessly projecting and how to disconnect your session when started from file explorer or from an app. In Windows 10, version 1809, you’ll see a control banner at the top of your screen when you’re in a session (just like you see when using remote desktop). The banner keeps you informed of the state of your connection, allows you to quickly disconnect or reconnect to the same sink, and allows you to tune the connection based on what you are doing. This tuning is done via **Settings**, which optimizes the screen-to-screen latency based on one of the three modes: * Game mode minimizes the screen-to-screen latency to make gaming over a wireless connection possible -* Video mode increases the screen-to-screen latency to ensure the video on the big screen plays back smoothly -* Productivity modes strikes a balance between game mode and video mode; the screen-to screen-latency is responsive enough that typing feels natural, while ensuring videos don’t glitch as often. +* Video mode increases the screen-to-screen latency to ensure the video on the large screen plays back smoothly +* Productivity modes strike a balance between game mode and video mode; the screen-to screen-latency is responsive enough that typing feels natural, while ensuring videos don’t glitch as often. ![wireless projection banner.](images/beaming.png "wireless projection banner") diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md index d29e02749d..bf6797c0fe 100644 --- a/windows/whats-new/whats-new-windows-10-version-1903.md +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -26,15 +26,15 @@ This article lists new and updated features and content that are of interest to [Windows Autopilot](/windows/deployment/windows-autopilot/windows-autopilot) is a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use. The following Windows Autopilot features are available in Windows 10, version 1903 and later: -- [Windows Autopilot for white glove deployment](/windows/deployment/windows-autopilot/white-glove) is new in this version of Windows. "White glove" deployment enables partners or IT staff to pre-provision devices so they are fully configured and business ready for your users. +- [Windows Autopilot for white glove deployment](/windows/deployment/windows-autopilot/white-glove) is new in this version of Windows. "White glove" deployment enables partners or IT staff to pre-provision devices so they're fully configured and business ready for your users. - The Intune [enrollment status page](/intune/windows-enrollment-status) (ESP) now tracks Intune Management Extensions​. - [Cortana voiceover](/windows-hardware/customize/desktop/cortana-voice-support) and speech recognition during OOBE is disabled by default for all Windows 10 Pro Education, and Enterprise SKUs. -- Windows Autopilot is self-updating during OOBE. Starting with the Windows 10, version 1903 Autopilot functional and critical updates will begin downloading automatically during OOBE. +- Windows Autopilot is self-updating during OOBE. From Windows 10, version 1903 Autopilot functional and critical updates will begin downloading automatically during OOBE. - Windows Autopilot will set the [diagnostics data](/windows/privacy/windows-diagnostic-data) level to Full on Windows 10 version 1903 and later during OOBE. ### SetupDiag -[SetupDiag](/windows/deployment/upgrade/setupdiag) is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When searching log files, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. +[SetupDiag](/windows/deployment/upgrade/setupdiag) is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When log files are being searched, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. ### Reserved storage @@ -42,13 +42,13 @@ This article lists new and updated features and content that are of interest to ## Servicing -- [**Delivery Optimization**](/windows/deployment/update/waas-delivery-optimization): Improved Peer Efficiency for enterprises and educational institutions with complex networks is enabled with of [new policies](/windows/client-management/mdm/policy-csp-deliveryoptimization). This now supports Microsoft 365 Apps for enterprise updates, and Intune content, with Microsoft Endpoint Manager content coming soon! -- [**Automatic Restart Sign-on (ARSO)**](/windows-server/identity/ad-ds/manage/component-updates/winlogon-automatic-restart-sign-on--arso-): Windows will automatically logon as the user and lock their device in order to complete the update, ensuring that when the user returns and unlocks the device, the update will be completed. -- [**Windows Update for Business**](https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Windows-Update-for-Business-and-the-retirement-of-SAC-T/ba-p/339523): There will now be a single, common start date for phased deployments (no more SAC-T designation). In addition, there will a new notification and reboot scheduling experience for end users, the ability to enforce update installation and reboot deadlines, and the ability to provide end user control over reboots for a specific time period. -- **Update rollback improvements**: You can now automatically recover from startup failures by removing updates if the startup failure was introduced after the installation of recent driver or quality updates. When a device is unable to start up properly after the recent installation of Quality of driver updates, Windows will now automatically uninstall the updates to get the device back up and running normally. -- **Pause updates**: We have extended the ability to pause updates for both feature and monthly updates. This extension ability is for all editions of Windows 10, including Home. You can pause both feature and monthly updates for up to 35 days (seven days at a time, up to five times). Once the 35-day pause period is reached, you will need to update your device before pausing again. +- [**Delivery Optimization**](/windows/deployment/update/waas-delivery-optimization): Improved Peer Efficiency for enterprises and educational institutions with complex networks is enabled with [new policies](/windows/client-management/mdm/policy-csp-deliveryoptimization). These new policies now support Microsoft 365 Apps for enterprise updates, and Intune content, with Microsoft Endpoint Manager content coming soon! +- [**Automatic Restart Sign-on (ARSO)**](/windows-server/identity/ad-ds/manage/component-updates/winlogon-automatic-restart-sign-on--arso-): Windows will automatically sign in as the user and lock their device in order to complete the update, ensuring that when the user returns and unlocks the device, the update will be completed. +- [**Windows Update for Business**](https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Windows-Update-for-Business-and-the-retirement-of-SAC-T/ba-p/339523): There will now be a single, common start date for phased deployments (no more SAC-T designation). In addition, there will be a new notification and reboot scheduling experience for end users, the ability to enforce update installation and reboot deadlines, and the ability to provide end user control over reboots for a specific time period. +- **Update rollback improvements**: You can now automatically recover from startup failures by removing updates if the startup failure was introduced after the installation of recent driver or quality updates. When a device is unable to start up properly after the recent installation of Quality of driver updates, Windows will now automatically uninstall the updates to get the device backed up and run normally. +- **Pause updates**: We've extended the ability to pause updates for both feature and monthly updates. This extension ability is for all editions of Windows 10, including Home. You can pause both feature and monthly updates for up to 35 days (seven days at a time, up to five times). Once the 35-day pause period is reached, you'll need to update your device before pausing again. - **Improved update notifications**: When there’s an update requiring you to restart your device, you’ll see a colored dot on the Power button in the Start menu and on the Windows icon in your taskbar. -- **Intelligent active hours**: To further enhance active hours, users will now have the option to let Windows Update intelligently adjust active hours based on their device-specific usage patterns. You must enable the intelligent active hours feature for the system to predict device-specific usage patterns. +- **Intelligent active hours**: To further enhance active hours, users will now be able to let Windows Update intelligently adjust active hours based on their device-specific usage patterns. You must enable the intelligent active hours feature for the system to predict device-specific usage patterns. - **Improved update orchestration to improve system responsiveness**: This feature will improve system performance by intelligently coordinating Windows updates and Microsoft Store updates, so they occur when users are away from their devices to minimize disruptions. ## Security @@ -71,7 +71,7 @@ The draft release of the [security configuration baseline settings](/archive/blo ### Microsoft Defender for Endpoint -- [Attack surface area reduction](/windows/security/threat-protection/windows-defender-atp/overview-attack-surface-reduction) – IT admins can configure devices with advanced web protection that enables them to define allow and deny lists for specific URL’s and IP addresses. +- [Attack surface area reduction](/windows/security/threat-protection/windows-defender-atp/overview-attack-surface-reduction) – IT admins can configure devices with advanced web protection that enables them to define allowlists and blocklists for specific URL’s and IP addresses. - [Next generation protection](/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-in-windows-10) – Controls have been extended to protection from ransomware, credential misuse, and attacks that are transmitted through removable storage. - Integrity enforcement capabilities – Enable remote runtime attestation of Windows 10 platform. - Tamper-proofing capabilities – Uses virtualization-based security to isolate critical Microsoft Defender for Endpoint security capabilities away from the OS and attackers. @@ -80,9 +80,9 @@ The draft release of the [security configuration baseline settings](/archive/blo ### Microsoft Defender for Endpoint next-gen protection technologies: - **Advanced machine learning**: Improved with advanced machine learning and AI models that enable it to protect against apex attackers using innovative vulnerability exploit techniques, tools and malware. -- **Emergency outbreak protection**: Provides emergency outbreak protection which will automatically update devices with new intelligence when a new outbreak has been detected. +- **Emergency outbreak protection**: Provides emergency outbreak protection that will automatically update devices with new intelligence when a new outbreak has been detected. - **Certified ISO 27001 compliance**: Ensures that the cloud service has analyzed for threats, vulnerabilities and impacts, and that risk management and security controls are in place. -- **Geolocation support**: Support geolocation and sovereignty of sample data as well as configurable retention policies. +- **Geolocation support**: Support geolocation and sovereignty of sample data and configurable retention policies. ### Threat Protection @@ -91,26 +91,26 @@ The draft release of the [security configuration baseline settings](/archive/blo - [Windows Defender Application Guard](/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview) enhancements: - Standalone users can install and configure their Windows Defender Application Guard settings without needing to change Registry key settings. Enterprise users can check their settings to see what their administrators have configured for their machines to better understand the behavior. - - WDAG is now an extension in Google Chrome and Mozilla Firefox. Many users are in a hybrid browser environment, and would like to extend WDAG’s browser isolation technology beyond Microsoft Edge. In the latest release, users can install the WDAG extension in their Chrome or Firefox browsers. This extension will redirect untrusted navigation to the WDAG Edge browser. There is also a companion app to enable this feature in the Microsoft Store. Users can quickly launch WDAG from their desktop using this app. This feature is also available in Windows 10, version 1803 or later with the latest updates. + - WDAG is now an extension in Google Chrome and Mozilla Firefox. Many users are in a hybrid browser environment, and would like to extend WDAG’s browser isolation technology beyond Microsoft Edge. In the latest release, users can install the WDAG extension in their Chrome or Firefox browsers. This extension will redirect untrusted navigation to the WDAG Edge browser. There's also a companion app to enable this feature in the Microsoft Store. Users can quickly launch WDAG from their desktop using this app. This feature is also available in Windows 10, version 1803 or later with the latest updates. To try this extension: 1. Configure WDAG policies on your device. 2. Go to the Chrome Web Store or Firefox Add-ons and search for Application Guard. Install the extension. - 3. Follow any additional configuration steps on the extension setup page. + 3. Follow any of the other configuration steps on the extension setup page. 4. Reboot the device. 5. Navigate to an untrusted site in Chrome and Firefox. - WDAG allows dynamic navigation: Application Guard now allows users to navigate back to their default host browser from the WDAG Microsoft Edge. Previously, users browsing in WDAG Edge would see an error page when they try to go to a trusted site within the container browser. With this new feature, users will automatically be redirected to their host default browser when they enter or click on a trusted site in WDAG Edge. This feature is also available in Windows 10, version 1803 or later with the latest updates. -- [Windows Defender Application Control (WDAC)](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control): In Windows 10, version 1903, Windows Defender Application Control has a number of new features that light up key scenarios and provide feature parity with AppLocker. +- [Windows Defender Application Control (WDAC)](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control): In Windows 10, version 1903, Windows Defender Application Control has many new features that light up key scenarios and provide feature parity with AppLocker. - [Multiple Policies](/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies): Windows Defender Application Control now supports multiple simultaneous code integrity policies for one device in order to enable the following scenarios: 1) enforce and audit side-by-side, 2) simpler targeting for policies with different scope/intent, 3) expanding a policy using a new ‘supplemental’ policy. - - [Path-Based Rules](/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules): The path condition identifies an app by its location in the file system of the computer or on the network instead of a signer or hash identifier. Additionally, Windows Defender Application Control has an option that allows admins to enforce at runtime that only code from paths that are not user-writeable is executed. When code tries to execute at runtime, the directory is scanned and files will be checked for write permissions for non-known admins. If a file is found to be user writeable, the executable is blocked from running unless it is authorized by something other than a path rule like a signer or hash rule.
    - This brings Windows Defender Application Control (WDAC) to functionality parity with AppLocker in terms of support for file path rules. WDAC improves upon the security of policies based on file path rules with the availability of the user-writability permission checks at runtime time, which is a capability that is not available with AppLocker. - - [Allow COM Object Registration](/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy): Previously, Windows Defender Application Control enforced a built-in allow list for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where additional COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. + - [Path-Based Rules](/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules): The path condition identifies an app by its location in the file system of the computer or on the network instead of a signer or hash identifier. Additionally, Windows Defender Application Control has an option that allows admins to enforce at runtime that only code from paths that aren't user-writeable is executed. When code tries to execute at runtime, the directory is scanned and files will be checked for write permissions for non-known admins. If a file is found to be user writeable, the executable is blocked from running unless it's authorized by something other than a path rule like a signer or hash rule.
    + This functionality brings WDAC to parity with AppLocker in terms of support for file path rules. WDAC improves upon the security of policies based on file path rules with the availability of the user-writability permission checks at runtime time, which is a capability that isn't available with AppLocker. + - [Allow COM Object Registration](/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy): Previously, Windows Defender Application Control enforced a built-in allowlist for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where more COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. #### System Guard -[System Guard](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows) has added a new feature in this version of Windows called **SMM Firmware Measurement**. This feature is built on top of [System Guard Secure Launch](/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection) to check that the System Management Mode (SMM) firmware on the device is operating in a healthy manner - specifically, OS memory and secrets are protected from SMM. There are currently no devices out there with compatible hardware, but they will be coming out in the next few months. +[System Guard](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows) has added a new feature in this version of Windows called **SMM Firmware Measurement**. This feature is built on top of [System Guard Secure Launch](/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection) to check that the System Management Mode (SMM) firmware on the device is operating in a healthy manner - specifically, OS memory and secrets are protected from SMM. There are currently no devices out there with compatible hardware, but they'll be coming out in the next few months. This new feature is displayed under the Device Security page with the string “Your device exceeds the requirements for enhanced hardware security” if configured properly: @@ -118,7 +118,7 @@ This new feature is displayed under the Device Security page with the string “ ### Identity Protection -- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less login for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. +- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less sign in for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. - [Streamlined Windows Hello PIN reset experience](/windows/security/identity-protection/hello-for-business/hello-videos#windows-hello-for-business-forgotten-pin-user-experience): Microsoft account users have a revamped Windows Hello PIN reset experience with the same look and feel as signing in on the web. - Sign-in with [Password-less](/windows/security/identity-protection/hello-for-business/passwordless-strategy) Microsoft accounts: Sign in to Windows 10 with a phone number account. Then use Windows Hello for an even easier sign-in experience! - [Remote Desktop with Biometrics](/windows/security/identity-protection/hello-for-business/hello-feature-remote-desktop#remote-desktop-with-biometrics): Azure Active Directory and Active Directory users using Windows Hello for Business can use biometrics to authenticate to a remote desktop session. @@ -131,7 +131,7 @@ This new feature is displayed under the Device Security page with the string “ ## Microsoft Edge -Several new features are coming in the next version of Edge. See the [news from Build 2019](https://blogs.windows.com/msedgedev/2019/05/06/edge-chromium-build-2019-pwa-ie-mode-devtools/#2QJF4u970WjQ2Sv7.97) for more information. +Several new features are coming in the next version of Edge. For more information, see the [news from Build 2019](https://blogs.windows.com/msedgedev/2019/05/06/edge-chromium-build-2019-pwa-ie-mode-devtools/#2QJF4u970WjQ2Sv7.97). ## See Also From 2669fdcc97e773dda770dba57cd789fa7368e184 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Fri, 8 Jul 2022 14:59:05 +0530 Subject: [PATCH 039/109] Acrolinx Enhancement Effort --- .../whats-new-windows-10-version-1909.md | 20 ++++++------- .../whats-new-windows-10-version-2004.md | 28 +++++++++---------- .../whats-new-windows-10-version-20H2.md | 6 ++-- windows/whats-new/windows-11-plan.md | 26 ++++++++--------- windows/whats-new/windows-11-prepare.md | 28 +++++++++---------- windows/whats-new/windows-11-requirements.md | 12 ++++---- 6 files changed, 60 insertions(+), 60 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1909.md b/windows/whats-new/whats-new-windows-10-version-1909.md index 8f1b6a4c3c..4ca266485c 100644 --- a/windows/whats-new/whats-new-windows-10-version-1909.md +++ b/windows/whats-new/whats-new-windows-10-version-1909.md @@ -21,11 +21,11 @@ This article lists new and updated features and content that are of interest to Windows 10, version 1909 is a scoped set of features for select performance improvements, enterprise features and quality enhancements. -To deliver these updates in an optimal fashion, we are providing this feature update in a new way: using servicing technology. Users that are already running Windows 10, version 1903 (the May 2019 Update) will receive this update similar to how they receive monthly updates. If you are running version 1903, then updating to the new release will have a much faster update experience because the update will install like a monthly update. +To deliver these updates in an optimal fashion, we're providing this feature update in a new way: using servicing technology. Users that are already running Windows 10, version 1903 (the May 2019 Update) will receive this update similar to how they receive monthly updates. If you're running version 1903, then updating to the new release will have a much faster update experience because the update will install like a monthly update. -If you are updating from an older version of Windows 10 (version 1809 or earlier), the process of updating to the current version will be the same as it has been for previous Windows 10 feature updates. For more information, see [Evolving Windows 10 servicing and quality: the next steps](https://blogs.windows.com/windowsexperience/2019/07/01/evolving-windows-10-servicing-and-quality-the-next-steps/#rl2G5ETPhkhMvDeX.97). +If you're updating from an older version of Windows 10 (version 1809 or earlier), the process of updating to the current version will be the same as it has been for previous Windows 10 feature updates. For more information, see [Evolving Windows 10 servicing and quality: the next steps](https://blogs.windows.com/windowsexperience/2019/07/01/evolving-windows-10-servicing-and-quality-the-next-steps/#rl2G5ETPhkhMvDeX.97). -**Note**: Devices running the Enterprise, IoT Enterprise, or Education editions of Windows 10, version 1909 receive 30 months of support. For more information about the Windows servicing lifecycle, please see the [Windows lifecycle fact sheet](/lifecycle/faq/windows). +**Note**: Devices running the Enterprise, IoT Enterprise, or Education editions of Windows 10, version 1909 receive 30 months of support. For more information about the Windows servicing lifecycle, see the [Windows lifecycle fact sheet](/lifecycle/faq/windows). ### Windows Server Update Services (WSUS) @@ -35,13 +35,13 @@ The Windows 10, version 1909 enablement package will be available on WSUS as [KB ### Windows Update for Business -If you are using Windows Update for Business, you will receive the Windows 10, version 1909 update in the same way that you have for prior feature updates, and as defined by your feature update deferral policy. +If you're using Windows Update for Business, you'll receive the Windows 10, version 1909 update in the same way that you have for prior feature updates, and as defined by your feature update deferral policy. ## Security ### Windows Defender Credential Guard -[Windows Defender Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard) is now available for ARM64 devices, for additional protection against credential theft for enterprises deploying ARM64 devices in their organizations, such as Surface Pro X. +[Windows Defender Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard) is now available for ARM64 devices, for extra protection against credential theft for enterprises deploying ARM64 devices in their organizations, such as Surface Pro X. ### Microsoft BitLocker @@ -53,7 +53,7 @@ Windows 10, version 1909 also includes two new features called **Key-rolling** a ### Transport Layer Security (TLS) -An experimental implementation of TLS 1.3 is included in Windows 10, version 1909. TLS 1.3 disabled by default system wide. If you enable TLS 1.3 on a device for testing, then it can also be enabled in Internet Explorer 11.0 and Microsoft Edge by using Internet Options. For beta versions of Microsoft Edge on Chromium, TLS 1.3 is not built on the Windows TLS stack, and is instead configured independently, using the **Edge://flags** dialog. Also see [Microsoft Edge platform status](https://developer.microsoft.com/microsoft-edge/status/tls13/) +An experimental implementation of TLS 1.3 is included in Windows 10, version 1909. TLS 1.3 disabled by default system wide. If you enable TLS 1.3 on a device for testing, then it can also be enabled in Internet Explorer 11.0 and Microsoft Edge by using Internet Options. For beta versions of Microsoft Edge on Chromium, TLS 1.3 isn't built on the Windows TLS stack, and is instead configured independently, using the **Edge://flags** dialog. Also see [Microsoft Edge platform status](https://developer.microsoft.com/microsoft-edge/status/tls13/) ## Virtualization @@ -65,7 +65,7 @@ An experimental implementation of TLS 1.3 is included in Windows 10, version 190 [Windows Virtual Desktop](/azure/virtual-desktop/overview) (WVD) is now generally available globally! -Windows Virtual Desktop is a comprehensive desktop and app virtualization service running in the cloud. It’s the only virtual desktop infrastructure (VDI) that delivers simplified management, multi-session Windows 10, optimizations for Microsoft 365 Apps for enterprise, and support for Remote Desktop Services (RDS) environments. Deploy and scale your Windows desktops and apps on Azure in minutes, and get built-in security and compliance features. Windows Virtual Desktop requires a Microsoft E3 or E5 license, or a Microsoft 365 E3 or E5 license, as well as an Azure tenant. +Windows Virtual Desktop is a comprehensive desktop and app virtualization service running in the cloud. It’s the only virtual desktop infrastructure (VDI) that delivers simplified management, multi-session Windows 10, optimizations for Microsoft 365 Apps for enterprise, and support for Remote Desktop Services (RDS) environments. Deploy and scale your Windows desktops and apps on Azure in minutes, and get built-in security and compliance features. Windows Virtual Desktop requires a Microsoft E3 or E5 license, or a Microsoft 365 E3 or E5 license, and an Azure tenant. ## Deployment @@ -81,7 +81,7 @@ Configuration Manager, Intune, Desktop Analytics, Co-Management, and Device Mana [SetupDiag](/windows/deployment/upgrade/setupdiag) version 1.6.0.42 is available. -SetupDiag is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When searching log files, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. . +SetupDiag is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When log files are being searched, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. ### Windows Assessment and Deployment Toolkit (ADK) @@ -115,7 +115,7 @@ With Intel Turbo Boost Max Technology 3.0, an operating system will use informat ### Debugging -Additional debugging capabilities for newer Intel processors have been added in this release. This is only relevant for hardware manufacturers. +More debugging capabilities for newer Intel processors have been added in this release. These newly added capabilities are only relevant for hardware manufacturers. ### Efficiency @@ -128,7 +128,7 @@ General battery life and power efficiency improvements for PCs with certain proc [What's New in Windows 10](./index.yml): See what’s new in other versions of Windows 10.
    [What Windows 10, version 1909 Means for Developers](https://blogs.windows.com/windowsdeveloper/2019/10/16/what-windows-10-version-1909-means-for-developers/): New and updated features in Windows 10 that are of interest to developers.
    [Features and functionality removed in Windows 10](/windows/deployment/planning/windows-10-removed-features): Removed features.
    -[Windows 10 features we’re no longer developing](/windows/deployment/planning/windows-10-deprecated-features): Features that are not being developed.
    +[Windows 10 features we’re no longer developing](/windows/deployment/planning/windows-10-deprecated-features): Features that aren't being developed.
    [How to get the Windows 10 November 2019 Update](https://aka.ms/how-to-get-1909): John Cable blog.
    [How to get Windows 10, Version 1909: Enablement Mechanics](https://aka.ms/1909mechanics): Mechanics blog.
    [What’s new for IT pros in Windows 10, version 1909](https://aka.ms/whats-new-in-1909): Windows IT Pro blog.
    diff --git a/windows/whats-new/whats-new-windows-10-version-2004.md b/windows/whats-new/whats-new-windows-10-version-2004.md index a00b411668..90fc585a9d 100644 --- a/windows/whats-new/whats-new-windows-10-version-2004.md +++ b/windows/whats-new/whats-new-windows-10-version-2004.md @@ -36,7 +36,7 @@ To download and install Windows 10, version 2004, use Windows Update (**Settings ### Windows Defender System Guard -In this release, [Windows Defender System Guard](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows) enables an even *higher* level of [System Management Mode](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows#system-management-mode-smm-protection) (SMM) Firmware Protection that goes beyond checking the OS memory and secrets to additional resources like registers and IO. +In this release, [Windows Defender System Guard](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows) enables an even *higher* level of [System Management Mode](/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows#system-management-mode-smm-protection) (SMM) Firmware Protection that goes beyond checking the OS memory and secrets to other resources like registers and IO. With this improvement, the OS can detect a higher level of SMM compliance, enabling devices to be even more hardened against SMM exploits and vulnerabilities. This feature is forward-looking and currently requires new hardware available soon. @@ -66,15 +66,15 @@ For more information, see Windows Setup enhancements in the [Windows IT Pro Blog In Windows 10, version 2004, SetupDiag is now automatically installed. -[SetupDiag](/windows/deployment/upgrade/setupdiag) is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When searching log files, SetupDiag uses a set of rules to match known issues. +[SetupDiag](/windows/deployment/upgrade/setupdiag) is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When log files are being searched, SetupDiag uses a set of rules to match known issues. -During the upgrade process, Windows Setup will extract all its sources files to the **%SystemDrive%\$Windows.~bt\Sources** directory. With Windows 10, version 2004 and later, Windows Setup now also installs SetupDiag.exe to this directory. If there is an issue with the upgrade, SetupDiag is automatically run to determine the cause of the failure. If the upgrade process proceeds normally, this directory is moved under %SystemDrive%\Windows.Old for cleanup. +During the upgrade process, Windows Setup will extract all its sources files to the **%SystemDrive%\$Windows.~bt\Sources** directory. With Windows 10, version 2004 and later, Windows Setup now also installs SetupDiag.exe to this directory. If there's an issue with the upgrade, SetupDiag is automatically run to determine the cause of the failure. If the upgrade process proceeds normally, this directory is moved under %SystemDrive%\Windows.Old for cleanup. ### Windows Autopilot With this release, you can configure [Windows Autopilot user-driven](/windows/deployment/windows-autopilot/user-driven) Hybrid Azure Active Directory join with VPN support. This support is also backported to Windows 10, version 1909 and 1903. -If you configure the language settings in the Autopilot profile and the device is connected to Ethernet, all scenarios will now skip the language, locale, and keyboard pages. In previous versions, this was only supported with self-deploying profiles. +If you configure the language settings in the Autopilot profile and the device is connected to Ethernet, all scenarios will now skip the language, locale, and keyboard pages. In previous versions, this skip was only supported with self-deploying profiles. ### Microsoft Endpoint Manager @@ -90,7 +90,7 @@ For information about what's new in the ADK, see [What's new in the Windows ADK ### Microsoft Deployment Toolkit (MDT) -MDT version 8456 supports Windows 10, version 2004, but there is currently an issue that causes MDT to incorrectly detect that UEFI is present. There is an [update available](https://support.microsoft.com/help/4564442/windows-10-deployments-fail-with-microsoft-deployment-toolkit) for MDT to address this issue. +MDT version 8456 supports Windows 10, version 2004, but there's currently an issue that causes MDT to incorrectly detect that UEFI is present. There's an [update available](https://support.microsoft.com/help/4564442/windows-10-deployments-fail-with-microsoft-deployment-toolkit) for MDT to address this issue. For the latest information about MDT, see the [MDT release notes](/mem/configmgr/mdt/release-notes). @@ -102,9 +102,9 @@ Windows PowerShell cmdlets have been improved: - **Get-DeliveryOptimizationStatus** has added the **-PeerInfo** option for a real-time peak behind the scenes on peer-to-peer activity (for example the peer IP Address, bytes received / sent). - **Get-DeliveryOptimizationLogAnalysis** is a new cmdlet that provides a summary of the activity in your DO log (# of downloads, downloads from peers, overall peer efficiency). Use the **-ListConnections** option to for in-depth look at peer-to-peer connections. -- **Enable-DeliveryOptimizationVerboseLogs** is a new cmdlet that enables a greater level of logging detail to assist in troubleshooting. +- **Enable-DeliveryOptimizationVerboseLogs** is a new cmdlet that enables a greater level of logging detail to help in troubleshooting. -Additional improvements: +Other improvements: - Enterprise network [throttling is enhanced](/windows-insider/archive/new-in-20H1#new-download-throttling-options-for-delivery-optimization-build-18917) to optimize foreground vs. background throttling. - Automatic cloud-based congestion detection is available for PCs with cloud service support. @@ -123,9 +123,9 @@ The following [Delivery Optimization](/windows/deployment/update/waas-delivery-o - Intune console updates: target version is now available allowing you to specify which version of Windows 10 you want devices to move to. Additionally, this capability enables you to keep devices on their current version until they reach end of service. Check it out in Intune, also available as a Group Policy and Configuration Service Provider (CSP) policy. -- Validation improvements: To ensure devices and end users stay productive and protected, Microsoft uses safeguard holds to block devices from updating when there are known issues that would impact that device. Also, to better enable IT administrators to validate on the latest release, we have created a new policy that enables admins to opt devices out of the built-in safeguard holds. +- Validation improvements: To ensure devices and end users stay productive and protected, Microsoft uses safeguard holds to block devices from updating when there are known issues that would impact that device. Also, to better enable IT administrators to validate on the latest release, we've created a new policy that enables admins to opt devices out of the built-in safeguard holds. -- Update less: Last year, we [changed update installation policies](https://blogs.windows.com/windowsexperience/2019/04/04/improving-the-windows-10-update-experience-with-control-quality-and-transparency/#l2jH7KMkOkfcWdBs.97) for Windows 10 to only target devices running a feature update version that is nearing end of service. As a result, many devices are only updating once a year. To enable all devices to make the most of this policy change, and to prevent confusion, we have removed deferrals from the Windows Update settings **Advanced Options** page starting on Windows 10, version 2004. If you wish to continue leveraging deferrals, you can use local Group Policy (**Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business > Select when Preview builds and Feature Updates are received** or **Select when Quality Updates are received**). For more information about this change, see [Simplified Windows Update settings for end users](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/simplified-windows-update-settings-for-end-users/ba-p/1497215). +- Update less: Last year, we [changed update installation policies](https://blogs.windows.com/windowsexperience/2019/04/04/improving-the-windows-10-update-experience-with-control-quality-and-transparency/#l2jH7KMkOkfcWdBs.97) for Windows 10 to only target devices running a feature update version that is nearing end of service. As a result, many devices are only updating once a year. To enable all devices to make the most of this policy change, and to prevent confusion, we have removed deferrals from the Windows Update settings **Advanced Options** page starting on Windows 10, version 2004. If you wish to continue using deferrals, you can use local Group Policy (**Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business > Select when Preview builds and Feature Updates are received** or **Select when Quality Updates are received**). For more information about this change, see [Simplified Windows Update settings for end users](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/simplified-windows-update-settings-for-end-users/ba-p/1497215). ## Networking @@ -146,7 +146,7 @@ In this release, Tunnel Extensible Authentication Protocol (TEAP) has been added [Windows Sandbox configuration](/windows/security/threat-protection/windows-sandbox/windows-sandbox-configure-using-wsb-file) includes: - MappedFolders now supports a destination folder. Previously no destination could be specified, it was always mapped to the Sandbox desktop. - AudioInput/VideoInput settings now enable you to share their host microphone or webcam with the Sandbox. -- ProtectedClient is a new security setting that runs the connection to the Sandbox with extra security settings enabled. This is disabled by default due to issues with copy & paste. +- ProtectedClient is a new security setting that runs the connection to the Sandbox with extra security settings enabled. This setting is disabled by default due to issues with copy & paste. - PrinterRedirection: You can now enable and disable host printer sharing with the Sandbox. - ClipboardRedirection: You can now enable and disable host clipboard sharing with the Sandbox. - MemoryInMB adds the ability to specify the maximum memory usage of the Sandbox. @@ -161,7 +161,7 @@ Windows Sandbox also has improved accessibility in this release, including: ### Windows Subsystem for Linux (WSL) -With this release, memory that is no longer in use in a Linux VM will be freed back to Windows. Previously, a WSL VM's memory could grow, but would not shrink when no longer needed. +With this release, memory that is no longer in use in a Linux VM will be freed back to Windows. Previously, a WSL VM's memory could grow, but wouldn't shrink when no longer needed. [WSL2](/windows/wsl/wsl2-index) support has been added for ARM64 devices if your device supports virtualization. @@ -169,7 +169,7 @@ For a full list of updates to WSL, see the [WSL release notes](/windows/wsl/rele ### Windows Virtual Desktop (WVD) -Windows 10 is an integral part of WVD, and several enhancements are available in the Spring 2020 update. Check out [Windows Virtual Desktop documentation](/azure/virtual-desktop/) for the latest and greatest information, as well as the [WVD Virtual Event from March](https://aka.ms/wvdvirtualevent). +Windows 10 is an integral part of WVD, and several enhancements are available in the Spring 2020 update. Check out [Windows Virtual Desktop documentation](/azure/virtual-desktop/) for the latest and greatest information, and the [WVD Virtual Event from March](https://aka.ms/wvdvirtualevent). ## Microsoft Edge @@ -205,7 +205,7 @@ Windows Search is improved in several ways. For more information, see [Superchar ### Virtual Desktops -There is a new [Update on Virtual Desktop renaming (Build 18975)](/windows-insider/archive/new-in-20H1#update-on-virtual-desktop-renaming-build-18975), where, instead of getting stuck with the system-issued names like Desktop 1, you can now rename your virtual desktops more freely. +There's a new [Update on Virtual Desktop renaming (Build 18975)](/windows-insider/archive/new-in-20H1#update-on-virtual-desktop-renaming-build-18975), where, instead of getting stuck with the system-issued names like Desktop 1, you can now rename your virtual desktops more freely. ### Bluetooth pairing @@ -262,4 +262,4 @@ For information about Desktop Analytics and this release of Windows 10, see [Wha - [What's new for business in Windows 10 Insider Preview Builds](/windows-insider/Active-Dev-Branch): A preview of new features for businesses. - [What's new in Windows 10, version 2004 - Windows Insiders](/windows-insider/archive/new-in-20h1): This list also includes consumer focused new features. - [Features and functionality removed in Windows 10](/windows/deployment/planning/windows-10-removed-features): Removed features. -- [Windows 10 features we're no longer developing](/windows/deployment/planning/windows-10-deprecated-features): Features that are not being developed. +- [Windows 10 features we're no longer developing](/windows/deployment/planning/windows-10-deprecated-features): Features that aren't being developed. diff --git a/windows/whats-new/whats-new-windows-10-version-20H2.md b/windows/whats-new/whats-new-windows-10-version-20H2.md index b3f400dbeb..14b2588859 100644 --- a/windows/whats-new/whats-new-windows-10-version-20H2.md +++ b/windows/whats-new/whats-new-windows-10-version-20H2.md @@ -57,7 +57,7 @@ Activities are grouped into the following phases: **Plan** > **Prepare** > **Dep - Ensure that [users are ready](/windows/deployment/update/prepare-deploy-windows) for updates **Deploy** and manage Windows 10 strategically in your organization: -- Use [Windows Autopilot](/mem/autopilot/windows-autopilot) to streamline the set up, configuration, and delivery of new devices +- Use [Windows Autopilot](/mem/autopilot/windows-autopilot) to streamline the setup, configuration, and delivery of new devices - Use [Configuration Manager](/windows/deployment/deploy-windows-cm/prepare-for-zero-touch-installation-of-windows-10-with-configuration-manager) or [MDT](/windows/deployment/deploy-windows-mdt/prepare-for-windows-deployment-with-mdt) to deploy new devices and update existing devices - Use [Windows Update for Business](/windows/deployment/update/waas-configure-wufb) with Group Policy to [customize update settings](/windows/deployment/update/waas-wufb-group-policy) for your devices - [Deploy Windows updates](/windows/deployment/update/waas-manage-updates-wsus) with Windows Server Update Services (WSUS) @@ -73,7 +73,7 @@ Enhancements to Windows Autopilot since the last release of Windows 10 include: ### Windows Assessment and Deployment Toolkit (ADK) -There is no new ADK for Windows 10, version 20H2. The ADK for Windows 10, version 2004 will also work with Windows 10, version 20H2. For more information, see [Download and install the Windows ADK](/windows-hardware/get-started/adk-install). +There's no new ADK for Windows 10, version 20H2. The ADK for Windows 10, version 2004 will also work with Windows 10, version 20H2. For more information, see [Download and install the Windows ADK](/windows-hardware/get-started/adk-install). ## Device management @@ -146,4 +146,4 @@ For information about Desktop Analytics and this release of Windows 10, see [Wha [What's New in Windows 10](./index.yml): See what’s new in other versions of Windows 10.
    [Announcing more ways we’re making app development easier on Windows](https://blogs.windows.com/windowsdeveloper/2020/09/22/kevin-gallo-microsoft-ignite-2020/): Simplifying app development in Windows.
    [Features and functionality removed in Windows 10](/windows/deployment/planning/windows-10-removed-features): Removed features.
    -[Windows 10 features we’re no longer developing](/windows/deployment/planning/windows-10-deprecated-features): Features that are not being developed.
    +[Windows 10 features we’re no longer developing](/windows/deployment/planning/windows-10-deprecated-features): Features that aren't being developed.
    diff --git a/windows/whats-new/windows-11-plan.md b/windows/whats-new/windows-11-plan.md index 7f67c4a774..6b9654ecf4 100644 --- a/windows/whats-new/windows-11-plan.md +++ b/windows/whats-new/windows-11-plan.md @@ -20,7 +20,7 @@ ms.collection: highpri This article provides guidance to help you plan for Windows 11 in your organization. -Since Windows 11 is built on the same foundation as Windows 10, you can use the same deployment capabilities, scenarios, and tools—as well as the same basic deployment strategy that you use today for Windows 10. You will need to review and update your servicing strategy to adjust for changes in [Servicing and support](#servicing-and-support) for Windows 11. +Since Windows 11 is built on the same foundation as Windows 10, you can use the same deployment capabilities, scenarios, and tools—and the same basic deployment strategy that you use today for Windows 10. You'll need to review and update your servicing strategy to adjust for changes in [Servicing and support](#servicing-and-support) for Windows 11. At a high level, this strategy should include the following steps: - [Create a deployment plan](/windows/deployment/update/create-deployment-plan) @@ -29,13 +29,13 @@ At a high level, this strategy should include the following steps: - [Determine application readiness](/windows/deployment/update/plan-determine-app-readiness) - [Define your servicing strategy](/windows/deployment/update/plan-define-strategy) -If you are looking for ways to optimize your approach to deploying Windows 11, or if deploying a new version of an operating system is not a familiar process for you, some items to consider are provided below. +If you're looking for ways to optimize your approach to deploying Windows 11, or if deploying a new version of an operating system isn't a familiar process for you, some items to consider are provided below: ## Determine eligibility -As a first step, you will need to know which of your current devices meet the Windows 11 hardware requirements. Most devices purchased in the last 18-24 months will be compatible with Windows 11. Verify that your device meets or exceeds [Windows 11 requirements](windows-11-requirements.md) to ensure it is compatible. +As a first step, you'll need to know which of your current devices meet the Windows 11 hardware requirements. Most devices purchased in the last 18-24 months will be compatible with Windows 11. Verify that your device meets or exceeds [Windows 11 requirements](windows-11-requirements.md) to ensure it's compatible. -Microsoft is currently developing analysis tools to help you evaluate your devices against the Windows 11 hardware requirements. When Windows 11 reaches general availability, users running Windows 10 Home, Pro, and Pro for Workstations will be able to use the [PC Health Check](https://www.microsoft.com/windows/windows-11#pchealthcheck) app to determine their eligibility for Windows 11. Users running Windows 10 Enterprise and Education editions should rely on their IT administrators to let them know when they are eligible for the upgrade.  +Microsoft is currently developing analysis tools to help you evaluate your devices against the Windows 11 hardware requirements. When Windows 11 reaches general availability, users running Windows 10 Home, Pro, and Pro for Workstations will be able to use the [PC Health Check](https://www.microsoft.com/windows/windows-11#pchealthcheck) app to determine their eligibility for Windows 11. Users running Windows 10 Enterprise and Education editions should rely on their IT administrators to let them know when they're eligible for the upgrade.  Enterprise organizations looking to evaluate device readiness in their environments can expect this capability to be integrated into existing Microsoft tools, such as Endpoint analytics and Update Compliance. This capability will be available when Windows 11 is generally available. Microsoft is also working with software publishing partners to facilitate adding Windows 11 device support into their solutions. @@ -45,19 +45,19 @@ The availability of Windows 11 will vary according to a device's hardware and wh ##### Managed devices -Managed devices are devices that are under organization control. Managed devices include those managed by Microsoft Intune, Microsoft Endpoint Configuration Manager, or other endpoint management solutions. +Managed devices are devices that are under organization control. Managed devices include those devices managed by Microsoft Intune, Microsoft Endpoint Configuration Manager, or other endpoint management solutions. -If you manage devices on behalf of your organization, you will be able to upgrade eligible devices to Windows 11 using your existing deployment and management tools at no cost when the upgrade reaches general availability. Organizations that use Windows Update for Business will have added benefits, such as: +If you manage devices on behalf of your organization, you'll be able to upgrade eligible devices to Windows 11 using your existing deployment and management tools at no cost when the upgrade reaches general availability. Organizations that use Windows Update for Business will have added benefits, such as: -- Ensuring that devices that don't meet the minimum hardware requirements are not automatically offered the Windows 11 upgrade. -- Additional insight into safeguard holds. While safeguard holds will function for Windows 11 devices just as they do for Windows 10 today, administrators using Windows Update for Business will have access to information on which safeguard holds are preventing individual devices from taking the upgrade to Windows 11. +- Ensuring that devices that don't meet the minimum hardware requirements aren't automatically offered the Windows 11 upgrade. +- More insight into safeguard holds. While safeguard holds will function for Windows 11 devices just as they do for Windows 10 today, administrators using Windows Update for Business will have access to information on which safeguard holds are preventing individual devices from taking the upgrade to Windows 11. > [!NOTE] > Also, Windows 11 has new Microsoft Software License Terms. If you are deploying with Windows Update for Business or Windows Server Update Services, you are accepting these new license terms on behalf of the users in your organization. ##### Unmanaged devices -Unmanaged devices are devices that are not managed by an IT administrator on behalf of an organization. For operating system (OS) deployment, these devices are not subject to organizational policies that manage upgrades or updates. +Unmanaged devices are devices that aren't managed by an IT administrator on behalf of an organization. For operating system (OS) deployment, these devices aren't subject to organizational policies that manage upgrades or updates. Windows 11 will be offered to eligible Windows 10 devices beginning later in the 2021 calendar year. Messaging on new devices will vary by PC manufacturer, but users will see labels such as **This PC will upgrade to Windows 11 once available** on products that are available for purchase. @@ -69,10 +69,10 @@ Just like Windows 10, the machine learning based [intelligent rollout](https://t The recommended method to determine if your infrastructure, deployment processes, and management tools are ready for Windows 11 is to join the [Windows Insider Program for Business](https://insider.windows.com/for-business). As a participant in the [Release Preview Channel](/windows-insider/business/validate-Release-Preview-Channel), you can validate that your devices and applications work as expected, and explore new features. -As you plan your endpoint management strategy for Windows 11, consider moving to cloud-based mobile device management (MDM), such as [Microsoft Intune](/mem/intune/fundamentals/what-is-intune). If a cloud-only approach isn't right for your organization just yet, you can still modernize and streamline essential pieces of your endpoint management strategy as follows: +As you plan your endpoint management strategy for Windows 11, consider moving to cloud-based mobile device management (MDM), such as [Microsoft Intune](/mem/intune/fundamentals/what-is-intune). If a cloud-only approach isn't right for your organization yet, you can still modernize and streamline essential pieces of your endpoint management strategy as follows: - Create a [cloud management gateway](/mem/configmgr/core/clients/manage/cmg/overview) (CMG) to manage Configuration Manager clients over the internet. - Attach your existing Configuration Management estate to the cloud with [tenant attach](/mem/configmgr/tenant-attach/device-sync-actions) so you can manage all devices from within the Microsoft Endpoint Manager admin center. -- Use [co-management](/mem/configmgr/comanage/overview) to concurrently manage devices using both Configuration Manager and Microsoft Intune. This allows you to take advantage of cloud-powered capabilities like [Conditional Access](/azure/active-directory/conditional-access/overview). +- Use [co-management](/mem/configmgr/comanage/overview) to concurrently manage devices using both Configuration Manager and Microsoft Intune. This concurrent management allows you to take advantage of cloud-powered capabilities like [Conditional Access](/azure/active-directory/conditional-access/overview). For more information on the benefits of these approaches, see [Cloud Attach Your Future: The Big 3](https://techcommunity.microsoft.com/t5/configuration-manager-blog/cloud-attach-your-future-part-ii-quot-the-big-3-quot/ba-p/1750664). @@ -92,7 +92,7 @@ Along with user experience and security improvements, Windows 11 introduces enha When Windows 11 reaches general availability, a consolidated Windows 11 update history will be available on support.microsoft.com, similar to what is [available today for Windows 10](https://support.microsoft.com/topic/windows-10-update-history-1b6aac92-bf01-42b5-b158-f80c6d93eb11). Similarly, the [Windows release health](/windows/release-health/) hub will offer quick access to Windows 11 servicing announcements, known issues, and safeguard holds. -It is important that organizations have adequate time to plan for Windows 11. Microsoft also recognizes that many organizations will have a mix of Windows 11 and Windows 10 devices across their ecosystem. Devices on in-service versions of Windows 10 will continue to receive monthly Windows 10 security updates through 2025, as well as incremental improvements to Windows 10 to support ongoing Microsoft 365 deployments. For more information, see the [Windows 10 release information](/windows/release-health/release-information) page, which offers information about the Windows 10 General Availability Channel and Long-term Servicing Channel (LTSC) releases. +It's important that organizations have adequate time to plan for Windows 11. Microsoft also recognizes that many organizations will have a mix of Windows 11 and Windows 10 devices across their ecosystem. Devices on in-service versions of Windows 10 will continue to receive monthly Windows 10 security updates through 2025, and incremental improvements to Windows 10 to support ongoing Microsoft 365 deployments. For more information, see the [Windows 10 release information](/windows/release-health/release-information) page, which offers information about the Windows 10 General Availability Channel and Long-term Servicing Channel (LTSC) releases. ## Application compatibility @@ -104,7 +104,7 @@ If you run into compatibility issues or want to ensure that your organization's **App Assure**: With enrollment in the [App Assure](/windows/compatibility/app-assure) service, any app compatibility issues that you find with Windows 11 can be resolved. Microsoft will help you remedy application issues at no cost. Since 2018, App Assure has evaluated almost 800,000 apps, and subscriptions are free for eligible customers with 150+ seats. -**Test Base for Microsoft 365**: For software publishers, systems integrators, and IT administrators, [Test Base for Microsoft 365](https://aka.ms/testbase) (currently in private preview) is a service that allows you to validate your apps across a variety of Windows feature and quality updates and environments in a Microsoft-managed Azure environment. Enterprise organizations can also nominate their software publishers for participation by completing a short form. +**Test Base for Microsoft 365**: For software publishers, systems integrators, and IT administrators, [Test Base for Microsoft 365](https://aka.ms/testbase) (currently in private preview) is a service that allows you to validate your apps across various Windows features and quality updates and environments in a Microsoft-managed Azure environment. Enterprise organizations can also nominate their software publishers for participation by completing a short form. You might already be using App Assure and Test Base in your Windows 10 environment. Both of these tools will continue to function with Windows 11. diff --git a/windows/whats-new/windows-11-prepare.md b/windows/whats-new/windows-11-prepare.md index 532493e1e3..84525fe130 100644 --- a/windows/whats-new/windows-11-prepare.md +++ b/windows/whats-new/windows-11-prepare.md @@ -30,7 +30,7 @@ The tools that you use for core workloads during Windows 10 deployments can stil #### On-premises solutions -- If you use [Windows Server Update Service (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus), you will need to sync the new **Windows 11** product category. After you sync the product category, you will see Windows 11 offered as an option. If you would like to validate Windows 11 prior to release, you can sync the **Windows Insider Pre-release** category as well. +- If you use [Windows Server Update Service (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus), you'll need to sync the new **Windows 11** product category. After you sync the product category, you'll see Windows 11 offered as an option. If you would like to validate Windows 11 prior to release, you can sync the **Windows Insider Pre-release** category as well. > [!NOTE] > During deployment, you will be prompted to agree to the Microsoft Software License Terms on behalf of your users. Additionally, you will not see an x86 option because Windows 11 is not supported on 32-bit architecture. @@ -42,14 +42,14 @@ The tools that you use for core workloads during Windows 10 deployments can stil #### Cloud-based solutions -- If you use Windows Update for Business policies, you will need to use the **Target Version** capability (either through policy or the Windows Update for Business deployment service) rather than using feature update deferrals alone to upgrade from Windows 10 to Windows 11. Feature update deferrals are great to move to newer versions of your current product (for example, Windows 10, version 20H2 to 21H1), but won't automatically devices move between products (Windows 10 to Windows 11). - - If you use Microsoft Intune and have a Microsoft 365 E3 license, you will be able to use the [feature update deployments](/mem/intune/protect/windows-10-feature-updates) page to select **Windows 11, version 21H2** and upgrade Windows 10 devices to Windows 11. You can also continue using the same update experience controls to manage Windows 10 and Windows 11 on the **Update Rings** page in Intune. If you aren’t ready to move to Windows 11, keep the feature update version set at the version you are currently on. When you are ready to start upgrading devices, change the feature update deployment setting to specify Windows 11. +- If you use Windows Update for Business policies, you'll need to use the **Target Version** capability (either through policy or the Windows Update for Business deployment service) rather than using feature update deferrals alone to upgrade from Windows 10 to Windows 11. Feature update deferrals are great to move to newer versions of your current product (for example, Windows 10, version 20H2 to 21H1), but won't automatically devices move between products (Windows 10 to Windows 11). + - If you use Microsoft Intune and have a Microsoft 365 E3 license, you'll be able to use the [feature update deployments](/mem/intune/protect/windows-10-feature-updates) page to select **Windows 11, version 21H2** and upgrade Windows 10 devices to Windows 11. You can also continue using the same update experience controls to manage Windows 10 and Windows 11 on the **Update Rings** page in Intune. If you aren’t ready to move to Windows 11, keep the feature update version set at the version you're currently on. When you're ready to start upgrading devices, change the feature update deployment setting to specify Windows 11. - In Group Policy, **Select target Feature Update version** has two entry fields after taking the 9/1/2021 optional update ([KB5005101](https://support.microsoft.com/topic/september-1-2021-kb5005101-os-builds-19041-1202-19042-1202-and-19043-1202-preview-82a50f27-a56f-4212-96ce-1554e8058dc1)) or a later update: **Product Version** and **Target Version**. - The product field must specify Windows 11 in order for devices to upgrade to Windows 11. If only the target version field is configured, the device will be offered matching versions of the same product. - For example, if a device is running Windows 10, version 2004 and only the target version is configured to 21H1, this device will be offered version Windows 10, version 21H1, even if multiple products have a 21H1 version. -- Quality update deferrals will continue to work the same across both Windows 10 and Windows 11. This is true regardless of which management tool you use to configure Windows Update for Business policies. -- If you use Microsoft Intune and have a Microsoft 365 E3 license, you will be able to use [feature update deployments](/mem/intune/protect/windows-10-feature-updates) to easily update devices from one release of Windows 10 to another, or to upgrade Windows 10 devices to Windows 11. You can also continue using the same update experience controls to manage Windows 10 and Windows 11. If you aren’t ready to move to Windows 11, keep the feature update version set at the version you are currently on. When you are ready to start upgrading devices, change the feature update deployment setting to specify Windows 11. +- Quality update deferrals will continue to work the same across both Windows 10 and Windows 11, which is true regardless of which management tool you use to configure Windows Update for Business policies. +- If you use Microsoft Intune and have a Microsoft 365 E3 license, you'll be able to use [feature update deployments](/mem/intune/protect/windows-10-feature-updates) to easily update devices from one release of Windows 10 to another, or to upgrade Windows 10 devices to Windows 11. You can also continue using the same update experience controls to manage Windows 10 and Windows 11. If you aren’t ready to move to Windows 11, keep the feature update version set at the version you're currently on. When you're ready to start upgrading devices, change the feature update deployment setting to specify Windows 11. > [!NOTE] > Endpoints managed by Windows Update for Business will not automatically upgrade to Windows 11 unless an administrator explicitly configures a **Target Version** using the [TargetReleaseVersion](/windows/client-management/mdm/policy-csp-update#update-targetreleaseversion) setting using a Windows CSP, a [feature update profile](/mem/intune/protect/windows-10-feature-updates) in Intune, or the [Select target Feature Update version setting](/windows/deployment/update/waas-wufb-group-policy#i-want-to-stay-on-a-specific-version) in a group policy. @@ -64,13 +64,13 @@ The following are some common use cases and the corresponding Microsoft Endpoint - **Configure rules and control settings for users, apps, and devices**: When you enroll devices in [Microsoft Intune](/mem/intune/fundamentals/what-is-intune), administrators have full control over apps, settings, features, and security for both Windows 11 and Windows 10. You can also use app protection policies to require multifactor authentication (MFA) for specific apps. - **Streamline device management for frontline, remote, and onsite workers**: Introduced with Windows 10, [cloud configuration](/mem/intune/fundamentals/cloud-configuration) is a standard, easy-to-manage, device configuration that is cloud-optimized for users with specific workflow needs. It can be deployed to devices running the Pro, Enterprise, and Education editions of Windows 11 by using Microsoft Endpoint Manager. -If you are exclusively using an on-premises device management solution (for example, Configuration Manager), you can still use the [cloud management gateway](/mem/configmgr/core/clients/manage/cmg/overview), enable [tenant attach](/mem/configmgr/tenant-attach/device-sync-actions), or enable [co-management](/mem/configmgr/comanage/overview) with Microsoft Intune. These solutions can make it easier to keep devices secure and up-to-date. +If you're exclusively using an on-premises device management solution (for example, Configuration Manager), you can still use the [cloud management gateway](/mem/configmgr/core/clients/manage/cmg/overview), enable [tenant attach](/mem/configmgr/tenant-attach/device-sync-actions), or enable [co-management](/mem/configmgr/comanage/overview) with Microsoft Intune. These solutions can make it easier to keep devices secure and up-to-date. ## Review servicing approach and policies -Every organization will transition to Windows 11 at its own pace. Microsoft is committed to supporting you through your migration to Windows 11, whether you are a fast adopter or will make the transition over the coming months or years. +Every organization will transition to Windows 11 at its own pace. Microsoft is committed to supporting you through your migration to Windows 11, whether you're a fast adopter or will make the transition over the coming months or years. -When you think of operating system updates as an ongoing process, you will automatically improve your ability to deploy updates. This approach enables you to stay current with less effort, and less impact on productivity. To begin, think about how you roll out Windows feature updates today: which devices, and at what pace. +When you think of operating system updates as an ongoing process, you'll automatically improve your ability to deploy updates. This approach enables you to stay current with less effort, and less impact on productivity. To begin, think about how you roll out Windows feature updates today: which devices, and at what pace. Next, craft a deployment plan for Windows 11 that includes deployment groups, rings, users, or devices. There are no absolute rules for exactly how many rings to have for your deployments, but a common structure is: - Preview (first or canary): Planning and development @@ -81,7 +81,7 @@ For detailed information, see [Create a deployment plan](/windows/deployment/upd #### Review policies -Review deployment-related policies, taking into consideration your organization's security objectives, update compliance deadlines, and device activity. Apply changes where you can gain a clear improvement, particularly with regard to the speed of the update process or security. +Review deployment-related policies, taking into consideration your organization's security objectives, update compliance deadlines, and device activity. Apply changes where you can gain a clear improvement, particularly regarding the speed of the update process or security. #### Validate apps and infrastructure @@ -90,16 +90,16 @@ To validate that your apps, infrastructure, and deployment processes are ready f If you use Windows Server Update Services, you can deploy directly from the Windows Insider Pre-release category using one of the following processes: - Set **Manage Preview Builds** to **Release Preview** in Windows Update for Business. -- Leverage Azure Virtual Desktop and Azure Marketplace images. +- Use Azure Virtual Desktop and Azure Marketplace images. - Download and deploy ISOs from Microsoft’s Windows Insider Program ISO Download page. Regardless of the method you choose, you have the benefit of free Microsoft support when validating pre-release builds. Free support is available to any commercial customer deploying Windows 10 or Windows 11 Preview Builds, once they become available through the Windows Insider Program. #### Analytics and assessment tools -If you use Microsoft Endpoint Manager and have onboarded devices to Endpoint analytics, you will have access to a hardware readiness assessment later this year. This tool enables you to quickly identify which of your managed devices are eligible for the Windows 11 upgrade. +If you use Microsoft Endpoint Manager and have onboarded devices to Endpoint analytics, you'll have access to a hardware readiness assessment later this year. This tool enables you to quickly identify which of your managed devices are eligible for the Windows 11 upgrade. -[Desktop Analytics](/mem/configmgr/desktop-analytics/overview) does not support Windows 11. You must use [Endpoint analytics](/mem/analytics/overview). +[Desktop Analytics](/mem/configmgr/desktop-analytics/overview) doesn't support Windows 11. You must use [Endpoint analytics](/mem/analytics/overview). ## Prepare a pilot deployment @@ -117,8 +117,8 @@ At a high level, the tasks involved are: ## User readiness -Do not overlook the importance of user readiness to deliver an effective, enterprise-wide deployment of Windows 11. Windows 11 has a familiar design, but your users will see several enhancements to the overall user interface. They will also need to adapt to changes in menus and settings pages. Therefore, consider the following tasks to prepare users and your IT support staff Windows 11: -- Create a communications schedule to ensure that you provide the right message at the right time to the right groups of users, based on when they will see the changes. +Don't overlook the importance of user readiness to deliver an effective, enterprise-wide deployment of Windows 11. Windows 11 has a familiar design, but your users will see several enhancements to the overall user interface. They'll also need to adapt to changes in menus and settings pages. Therefore, consider the following tasks to prepare users and your IT support staff Windows 11: +- Create a communications schedule to ensure that you provide the right message at the right time to the right groups of users, based on when they'll see the changes. - Draft concise emails that inform users of what changes they can expect to see. Offer tips on how to use or customize their experience. Include information about support and help desk options. - Update help desk manuals with screenshots of the new user interface, the out-of-box experience for new devices, and the upgrade experience for existing devices. diff --git a/windows/whats-new/windows-11-requirements.md b/windows/whats-new/windows-11-requirements.md index b2aef79c6d..fe1621a610 100644 --- a/windows/whats-new/windows-11-requirements.md +++ b/windows/whats-new/windows-11-requirements.md @@ -26,7 +26,7 @@ To install or upgrade to Windows 11, devices must meet the following minimum har - Processor: 1 gigahertz (GHz) or faster with two or more cores on a [compatible 64-bit processor](https://aka.ms/CPUlist) or system on a chip (SoC). - RAM: 4 gigabytes (GB) or greater. - Storage: 64 GB\* or greater available storage is required to install Windows 11. - - Additional storage space might be required to download updates and enable specific features. + - Extra storage space might be required to download updates and enable specific features. - Graphics card: Compatible with DirectX 12 or later, with a WDDM 2.0 driver. - System firmware: UEFI, Secure Boot capable. - TPM: [Trusted Platform Module](/windows/security/information-protection/tpm/trusted-platform-module-overview) (TPM) version 2.0. @@ -34,7 +34,7 @@ To install or upgrade to Windows 11, devices must meet the following minimum har - Internet connection: Internet connectivity is necessary to perform updates, and to download and use some features. - Windows 11 Home edition requires an Internet connection and a Microsoft Account to complete device setup on first use. -\* There might be additional requirements over time for updates, and to enable specific features within the operating system. For more information, see [Windows 11 specifications](https://www.microsoft.com/windows/windows-11-specifications). +\* There might be more requirements over time for updates, and to enable specific features within the operating system. For more information, see [Windows 11 specifications](https://www.microsoft.com/windows/windows-11-specifications). Also see [Update on Windows 11 minimum system requirements](https://blogs.windows.com/windows-insider/2021/06/28/update-on-windows-11-minimum-system-requirements/). @@ -51,7 +51,7 @@ Eligible Windows 10 devices must be on version 2004 or later, and have installed ## Feature-specific requirements -Some features in Windows 11 have requirements beyond those listed above. See the following list of features and associated requirements. +Some features in Windows 11 have requirements beyond those requirements listed above. See the following list of features and associated requirements. - **5G support**: requires 5G capable modem. - **Auto HDR**: requires an HDR monitor. @@ -74,7 +74,7 @@ Some features in Windows 11 have requirements beyond those listed above. See the - **Wi-Fi 6E**: requires new WLAN IHV hardware and driver and a Wi-Fi 6E capable AP/router. - **Windows Hello**: requires a camera configured for near infrared (IR) imaging or fingerprint reader for biometric authentication. Devices without biometric sensors can use Windows Hello with a PIN or portable Microsoft compatible security key. For more information, see [IT tools to support Windows 10, version 21H1](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/it-tools-to-support-windows-10-version-21h1/ba-p/2365103). - **Windows Projection**: requires a display adapter that supports Windows Display Driver Model (WDDM) 2.0 and a Wi-Fi adapter that supports Wi-Fi Direct. -- **Xbox app**: requires an Xbox Live account, which is not available in all regions. Please go to the Xbox Live Countries and Regions page for the most up-to-date information on availability. Some features in the Xbox app will require an active [Xbox Game Pass](https://www.xbox.com/xbox-game-pass) subscription. +- **Xbox app**: requires an Xbox Live account, which isn't available in all regions. Go to the Xbox Live Countries and Regions page for the most up-to-date information on availability. Some features in the Xbox app will require an active [Xbox Game Pass](https://www.xbox.com/xbox-game-pass) subscription. ## Virtual machine support @@ -84,11 +84,11 @@ The following configuration requirements apply to VMs running Windows 11. - Storage: 64 GB or greater - Security: Secure Boot capable, virtual TPM enabled - Memory: 4 GB or greater -- Processor: 2 or more virtual processors +- Processor: Two or more virtual processors The VM host CPU must also meet Windows 11 [processor requirements](/windows-hardware/design/minimum/windows-processor-requirements). -\* In-place upgrade of existing generation 1 VMs to Windows 11 is not possible. +\* In-place upgrade of existing generation 1 VMs to Windows 11 isn't possible. > [!NOTE] > Procedures to configure required VM settings depend on the VM host type. For VM hosts running Hyper-V, virtualization (VT-x, VT-d) must be enabled in BIOS. Virtual TPM 2.0 is emulated in the guest VM independent of the Hyper-V host TPM presence or version. From 5b1d225cff3790dba79b55a1fca488ff60318322 Mon Sep 17 00:00:00 2001 From: Siddarth Mandalika Date: Mon, 11 Jul 2022 12:49:42 +0530 Subject: [PATCH 040/109] Update domain-controller-allow-server-operators-to-schedule-tasks.md --- ...omain-controller-allow-server-operators-to-schedule-tasks.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/security-policy-settings/domain-controller-allow-server-operators-to-schedule-tasks.md b/windows/security/threat-protection/security-policy-settings/domain-controller-allow-server-operators-to-schedule-tasks.md index ad7e4030e3..4d00465fda 100644 --- a/windows/security/threat-protection/security-policy-settings/domain-controller-allow-server-operators-to-schedule-tasks.md +++ b/windows/security/threat-protection/security-policy-settings/domain-controller-allow-server-operators-to-schedule-tasks.md @@ -27,7 +27,7 @@ Describes the best practices, location, values, and security considerations for ## Reference -This policy setting determines whether server operators can use the**at** command to submit jobs. If you enable this policy setting, jobs that are created by server operators by means of the **at** command run in the context of the account that runs the Task Scheduler service. By default, that is the Local System account. +This policy setting determines whether server operators can use the **at** command to submit jobs. If you enable this policy setting, jobs that are created by server operators by means of the **at** command run in the context of the account that runs the Task Scheduler service. By default, that account is the Local System account. >**Note:**  This security option setting affects only the scheduler tool for the **at** command. It does not affect the Task Scheduler tool. From 9f3c1189a01d3feda0be5da08a3523fc7f459f48 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Mon, 18 Jul 2022 10:15:57 -0400 Subject: [PATCH 041/109] Fixed minor typos and invalid characters, added reviewer --- education/windows/change-home-to-edu.md | 25 +++++++++++++------------ 1 file changed, 13 insertions(+), 12 deletions(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index a3600773ff..02819afc30 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -8,7 +8,7 @@ ms.topic: how-to ms.localizationpriority: medium author: scottbreenmsft ms.author: scbree -ms.reviewer: +ms.reviewer: paoloma manager: jeffbu ms.collection: highpri --- @@ -36,11 +36,11 @@ These methods apply to devices with *Windows Home* installed, institution-owned Users aren't notified their device has been or will be upgraded to Windows Education when using MDM. It's the responsibility of the institution to notify their users. Institutions should notify their users that MDM will initiate an upgrade to Windows Education and this upgrade will give the institution extra capabilities, such as installing applications. -Device users can disconnect MDM in the Settings app to prevent further actions from being taken on their personal device. For instructions on disconnecting from MDM, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). +Device users can disconnect from MDM in the Settings app, to prevent further actions from being taken on their personal device. For instructions on disconnecting from MDM, see [Remove your Windows device from management](/mem/intune/user-help/unenroll-your-device-from-intune-windows). ## Why upgrade student-owned devices from Windows Home to Windows Education? -Some school institutions want to streamline student onboarding for student-owned devices using MDM. Typical MDM requirements include installing certificates, configuring WiFi profiles and installing applications. On Windows, MDM users Configuration Service Providers (CSPs) to configure settings. Some CSPs aren't available on Windows Home, which can limit the capabilities. Some of the CSPs not available in Windows Home that can affect typical student onboarding are: +Some school institutions want to streamline student onboarding for student-owned devices using MDM. Typical MDM requirements include installing certificates, configuring WiFi profiles and installing applications. On Windows, MDM uses Configuration Service Providers (CSPs) to configure settings. Some CSPs aren't available on Windows Home, which can limit the capabilities. Some of the CSPs not available in Windows Home that can affect typical student onboarding are: - [EnterpriseDesktopAppManagement](/windows/client-management/mdm/enterprisemodernappmanagement-csp) - which enables deployment of Windows installer or Win32 applications. - [DeliveryOptimization](/windows/client-management/mdm/policy-csp-deliveryoptimization) - which enables configuration of Delivery Optimization. @@ -66,7 +66,7 @@ IT admins with access to the VLSC or the Microsoft 365 Admin Center, can find th ### Recommended methods for using a MAK -It’s critical that MAKs are protected whenever they're used. The following processes provide the best protection for a MAK being applied to a device: +It's critical that MAKs are protected whenever they're used. The following processes provide the best protection for a MAK being applied to a device: - Provisioning package by institution approved staff; - Manual entry by institution approved staff (don't distribute the key via email); @@ -117,9 +117,9 @@ These steps provide instructions on how to use Microsoft Intune to upgrade devic These steps configure a filter that will only apply to devices running the *Windows Home edition*. This filter will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune](/mem/intune/fundamentals/filters). - Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com) -- Go to **Tenant Administration** > **Filters** +- Select **Tenant administration** > **Filters** - Select **Create** - - Create a name for the filter (for example *Windows Home edition*) + - Specify a name for the filter (for example *Windows Home edition*) - Select the **platform** as **Windows 10 and later** - Select **Next** - On the **Rules** screen, configure the following rules: @@ -130,7 +130,7 @@ These steps configure a filter that will only apply to devices running the *Wind - **operatingSystemSKU** equals **CoreSingleLanguage (Windows 10/11 Home single language (100))** > [!NOTE] - > Ensure you’ve selected OR as the operator in the right And/Or column + > Ensure you've selected OR as the operator in the right And/Or column :::image type="content" source="images/change-home-to-edu-windows-home-edition-intune-filter.png" alt-text="Example of configuring the Windows Home filter"::: @@ -148,7 +148,7 @@ These steps create and assign a Windows edition upgrade policy. For more informa - Select the **Profile type** as **Templates** - Select the **Template** as **Edition upgrade and mode switch** - Select **Create** -- Create a name for the filter (for example *Windows Education edition upgrade*), select **Next** +- Specify a name for the policy (for example *Windows Education edition upgrade*), select **Next** - On the **Configuration settings** screen - Expand **Edition Upgrade** - Change **Edition to upgrade** to **Windows 10/11 Education** @@ -156,7 +156,7 @@ These steps create and assign a Windows edition upgrade policy. For more informa - Select **Next** :::image type="content" source="images/change-home-to-edu-windows-edition-upgrade-policy.png" alt-text="Example of configuring the Windows upgrade policy in Microsoft Intune"::: - + - Optionally select scope tags as required and select **Next** - On the **assignments** screen; - Select **Add all devices** @@ -164,7 +164,7 @@ These steps create and assign a Windows edition upgrade policy. For more informa > [!NOTE] > You can also target other security groups that contain a smaller scope of users or devices and apply the filter rather than All devices. - + - Select to **Include filtered devices in assignment** - Select the *Windows Home edition* filter you created earlier - Choose **Select** to save the filter selection @@ -191,6 +191,7 @@ You can check the Windows versions of managed devices in the Microsoft Endpoint ### My MAK key has run out of activations, how do I request a new one? Increases to MAK Activation quantity can be requested by contacting [VLSC support](/licensing/contact-us) and may be granted by exception. A request can be made by accounts with the VLSC Administrator, Key Administrator, or Key Viewer permissions. The request should include the following information: + - Agreement/Enrollment Number or License ID and Authorization. - Product Name (includes version and edition). - Last five characters of the product key. @@ -216,13 +217,13 @@ A multiple activation key activates either individual computers or a group of co | Scenario | Ownership | MAK | KMS | AD based activation | Subscription Activation | |-|-|:-:|:-:|:-:|:-:| | **Workplace join (add work or school account)** | Personal (or student-owned) | X | | | | -| **Azure Active Directory Join** | Organization | X | X | | X | +| **Azure AD Join** | Organization | X | X | | X | | **Hybrid Azure AD Join** | Organization | X | X | X | X | ## Related links - [Windows 10 edition upgrade (Windows 10)](/windows/deployment/upgrade/windows-10-edition-upgrades) - [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation) -- [Equip Your Students with Windows 11 Education – Kivuto](https://kivuto.com/windows-11-student-use-benefit/) +- [Equip Your Students with Windows 11 Education - Kivuto](https://kivuto.com/windows-11-student-use-benefit/) - [Upgrade Windows Home to Windows Pro (microsoft.com)](https://support.microsoft.com/windows/upgrade-windows-home-to-windows-pro-ef34d520-e73f-3198-c525-d1a218cc2818) - [Partner Center: Upgrade Education customers from Windows 10 Home to Windows 10 Education](/partner-center/upgrade-windows-to-education) From 3c5207a5af0ef56630348f504e90ec302d2fdb75 Mon Sep 17 00:00:00 2001 From: themar-msft <33436507+themar-msft@users.noreply.github.com> Date: Mon, 18 Jul 2022 10:59:35 -0700 Subject: [PATCH 042/109] adds info about sb --- .../secure-the-windows-10-boot-process.md | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/windows/security/information-protection/secure-the-windows-10-boot-process.md b/windows/security/information-protection/secure-the-windows-10-boot-process.md index 8b7acbc1b7..6cbc6425b8 100644 --- a/windows/security/information-protection/secure-the-windows-10-boot-process.md +++ b/windows/security/information-protection/secure-the-windows-10-boot-process.md @@ -85,7 +85,23 @@ These requirements help protect you from rootkits while allowing you to run any To prevent malware from abusing these options, the user must manually configure the UEFI firmware to trust a non-certified bootloader or to turn off Secure Boot. Software can't change the Secure Boot settings. -Like most mobile devices, ARM-based Certified For Windows RT devices, such as the Microsoft Surface RT device, are designed to run only Windows 8.1. Therefore, Secure Boot can't be turned off, and you can't load a different OS. Fortunately, there's a large market of ARM processor devices designed to run other operating systems. +The default state of Secure Boot has a wide circle of trust which can result in customers trusting boot components they may not need. Since the Microsoft 3rd Party UEFI CA certificate signs the bootloaders for all Linux distributions, trusting the Microsoft 3rd Party UEFI CA signature in the UEFI database increase s the attack surface of systems. A customer who intended to only trust and boot a single Linux distribution will trust all distributions – much more than their desired configuration. A vulnerability in any of the bootloaders exposes the system and places the customer at risk of exploit for a bootloader they never intended to use, as seen in recent vulnerabilities, for example [with the GRUB bootloader](https://msrc.microsoft.com/security-guidance/advisory/ADV200011) or [firmware-level rootkit]( https://www.darkreading.com/threat-intelligence/researchers-uncover-dangerous-new-firmware-level-rootkit) affecting boot components. [Secured-core PCs](/windows-hardware/design/device-experiences/OEM-highly-secure-11) require Secure Boot to be enabled and configured to distrust the Microsoft 3rd Party UEFI CA signature, by default, to provide customers with the most secure configuration of their PCs possible. + +To trust and boot operating systems, like Linux, and components signed by the UEFI signature, Secured-core PCs can be configured in the BIOS menu to add the signature in the UEFI database by following these steps: + +1. Open the firmware menu, either: + + - Boot the PC, and press the manufacturer’s key to open the menus. Common keys used: Esc, Delete, F1, F2, F10, F11, or F12. On tablets, common buttons are Volume up or Volume down. During startup, there’s often a screen that mentions the key. If there’s not one, or if the screen goes by too fast to see it, check your manufacturer’s site. + + - Or, if Windows is already installed, from either the Sign on screen or the Start menu, select Power ( ) > hold Shift while selecting Restart. Select Troubleshoot > Advanced options > UEFI Firmware settings. + +2. From the firmware menu navigate to Security > Secure Boot and select the option to trust the “3rd Party CA”. + +3. Save changes and exit. + +Microsoft continues to collaborate with Linux and IHV ecosystem partners to design least privileged features to help you stay secure and opt-in trust for only the publishers and components you trust. + +Like most mobile devices, Arm-based devices, such as the Microsoft Surface RT device, are designed to run only Windows 8.1. Therefore, Secure Boot can't be turned off, and you can't load a different OS. Fortunately, there's a large market of ARM processor devices designed to run other operating systems. ## Trusted Boot From e2b99f8291dba9fea09a2cfc8eddf9b16d33bca1 Mon Sep 17 00:00:00 2001 From: Nicole Zhao Date: Wed, 20 Jul 2022 10:19:02 -0700 Subject: [PATCH 043/109] July 25th update for what's new in Set up School PCs We added a reimaging option for Set up School PCs and wanted to add a release note about the feature as well as a not on driver compatibility. --- education/windows/set-up-school-pcs-whats-new.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/education/windows/set-up-school-pcs-whats-new.md b/education/windows/set-up-school-pcs-whats-new.md index 29c5d1cc71..0a1d486f7c 100644 --- a/education/windows/set-up-school-pcs-whats-new.md +++ b/education/windows/set-up-school-pcs-whats-new.md @@ -17,6 +17,14 @@ manager: dansimp # What's new in Set up School PCs Learn what’s new with the Set up School PCs app each week. Find out about new app features and functionality, see updated screenshots, and find information about past releases. +## Week of July 25, 2022 + +### Reimagine option for Windows 11 SE +Set up School PCs has added an option to reimage your SE devices to Windows 11 SE during the create provisioning package flow. Previously, the process to reimage a device was specific to the OEM and required technical knowledge. The new reimaging feature in SUSPC provides a unified way for all OEMs using a simple and easy flow. Now you are able to plug in your USB with a Windows 11 SE image and a provisioning package on it, and your device will be reimaged before the provisioning package is installed on that device. + +Note: If after you have reimaged the device, you notice there are missing drivers, the IT admin should manually add those drivers to the image. The SUSPC reimaging tool has been tested on Surface SE devices, but since there are a variety of SE devices, the SUSPC reimage tool has not been tested on all SE devices. Contact your OEM to learn more about the necessary drivers. + +The option to reimage by getting the image from an OEM is still viable. ## Week of August 24, 2020 From 3e8b31275308b8ab83e3ce94a7c99f84295e6881 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Wed, 20 Jul 2022 15:07:44 -0600 Subject: [PATCH 044/109] Update education/windows/set-up-school-pcs-whats-new.md Line 22: Reimagine > reimage --- education/windows/set-up-school-pcs-whats-new.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/set-up-school-pcs-whats-new.md b/education/windows/set-up-school-pcs-whats-new.md index 0a1d486f7c..9fbd7080f1 100644 --- a/education/windows/set-up-school-pcs-whats-new.md +++ b/education/windows/set-up-school-pcs-whats-new.md @@ -19,7 +19,7 @@ Learn what’s new with the Set up School PCs app each week. Find out about new ## Week of July 25, 2022 -### Reimagine option for Windows 11 SE +### Reimage option for Windows 11 SE Set up School PCs has added an option to reimage your SE devices to Windows 11 SE during the create provisioning package flow. Previously, the process to reimage a device was specific to the OEM and required technical knowledge. The new reimaging feature in SUSPC provides a unified way for all OEMs using a simple and easy flow. Now you are able to plug in your USB with a Windows 11 SE image and a provisioning package on it, and your device will be reimaged before the provisioning package is installed on that device. Note: If after you have reimaged the device, you notice there are missing drivers, the IT admin should manually add those drivers to the image. The SUSPC reimaging tool has been tested on Surface SE devices, but since there are a variety of SE devices, the SUSPC reimage tool has not been tested on all SE devices. Contact your OEM to learn more about the necessary drivers. From 6957b23ca714f7e57945ba38d42685259ee07aff Mon Sep 17 00:00:00 2001 From: traya1 Date: Fri, 22 Jul 2022 15:57:28 +0000 Subject: [PATCH 045/109] Initialize Docs repository: https://github.com/MicrosoftDocs/windows-docs-pr of branch live --- .openpublishing.publish.config.json | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/.openpublishing.publish.config.json b/.openpublishing.publish.config.json index 284f6f33a1..aad198c643 100644 --- a/.openpublishing.publish.config.json +++ b/.openpublishing.publish.config.json @@ -210,9 +210,7 @@ "template_folder": "_themes" } ], - "notification_subscribers": [ - "elizapo@microsoft.com" - ], + "notification_subscribers": [], "sync_notification_subscribers": [ "dstrome@microsoft.com" ], From 6907342e032b50a9a4e55ac81b7e57fd50d785ee Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 17:32:20 -0600 Subject: [PATCH 046/109] Apply suggestions from code review Apply mostly Acrolinx hyphen fixes whats-new...-10-2015.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/40333b15-61cf-454b-bf90-a1c67f6d7d54#CORRECTNESS successful sign in > successful sign-in administrative sign in > administrative sign-in whats-new...-10-2021.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/a6ab218a-059d-4a9b-8a72-3f66086590e9#CORRECTNESS Enabling passwordless sign in > Enabling passwordless sign-in password-less sign in > password-less sign in whats-new...and-1511.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/7ec86fba-ac0f-4c41-9bcb-1f24710a59c3#CORRECTNESS successful sign in > successful sign-in "administrative sign in" > "administrative sign-in" whats-new...ion-1703.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/a653d7e8-8ed5-4a8b-9975-9ce13d7ca166#CORRECTNESS displayed during sign in. > displayed during sign-in. whats-new...ion-1803.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/46d94f81-3c35-4b8e-ba3f-67d7c2068239#CORRECTNESS faster sign in, > faster sign-in, whats-new...ion-1809.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/181fce21-0f94-4381-9acc-b34a8eb71b7d#CORRECTNESS Windows sign in > Windows sign-in whats-new...ion-1903.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/e4522b50-b9f3-4302-a77e-de0213098209#CORRECTNESS password-less sign in > password-less sign-in whats-new...ion-2004.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/85ad656b-3c21-48a1-9225-90319374d094#CORRECTNESS passwordless sign in > passwordless sign-in whats-new...ion-20H2.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/163b5352-672c-4ed0-a93b-fc2e529d65b7#CORRECTNESS And two British periods to American periods. --- windows/whats-new/ltsc/whats-new-windows-10-2015.md | 2 +- windows/whats-new/ltsc/whats-new-windows-10-2021.md | 3 +-- .../whats-new/whats-new-windows-10-version-1507-and-1511.md | 6 +++--- windows/whats-new/whats-new-windows-10-version-1809.md | 5 ++--- windows/whats-new/whats-new-windows-10-version-1903.md | 2 +- 5 files changed, 8 insertions(+), 10 deletions(-) diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2015.md b/windows/whats-new/ltsc/whats-new-windows-10-2015.md index 4f42bba988..d9638bbe88 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2015.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2015.md @@ -44,7 +44,7 @@ Enhancements to AppLocker in Windows 10 include: - **Encrypt and recover your device with Azure Active Directory**. In addition to using a Microsoft Account, automatic [Device Encryption](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#device-encryption) can now encrypt your devices that are joined to an Azure Active Directory domain. When the device is encrypted, the BitLocker recovery key is automatically escrowed to Azure Active Directory. This escrow will make it easier to recover your BitLocker key online. - **DMA port protection**. You can use the [DataProtection/AllowDirectMemoryAccess](/windows/client-management/mdm/policy-configuration-service-provider#dataprotection-allowdirectmemoryaccess) MDM policy to block DMA ports when the device is starting up. Also, when a device is locked, all unused DMA ports are turned off, but any devices that are already plugged into a DMA port will continue to work. When the device is unlocked, all DMA ports are turned back on. -- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings". +- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings." [Learn how to deploy and manage BitLocker within your organization](/windows/device-security/bitlocker/bitlocker-overview). diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2021.md b/windows/whats-new/ltsc/whats-new-windows-10-2021.md index e10132e61d..0d4d858f20 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2021.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2021.md @@ -143,7 +143,7 @@ Windows Hello enhancements include: - Windows Hello for Business now has Hybrid Azure Active Directory support and phone number sign-in (Microsoft account). FIDO2 security key support is expanded to Azure Active Directory hybrid environments, enabling enterprises with hybrid environments to take advantage of [passwordless authentication](/azure/active-directory/authentication/howto-authentication-passwordless-security-key-on-premises). For more information, see [Expanding Azure Active Directory support for FIDO2 preview to hybrid environments](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/expanding-azure-active-directory-support-for-fido2-preview-to/ba-p/981894). - With specialized hardware and software components available on devices shipping with Windows 10, version 20H2 configured out of factory, Windows Hello now offers added support for virtualization-based security with supporting fingerprint and face sensors. This feature isolates and secures a user's biometric authentication data. - Windows Hello multi-camera support is added, allowing users to choose an external camera priority when both external and internal Windows Hello-capable cameras are present. -- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less sign in for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. +- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less sign-in for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. - [Streamlined Windows Hello PIN reset experience](/windows/security/identity-protection/hello-for-business/hello-videos#windows-hello-for-business-forgotten-pin-user-experience): Microsoft account users have a revamped Windows Hello PIN reset experience with the same look and feel as signing in on the web. - [Remote Desktop with Biometrics](/windows/security/identity-protection/hello-for-business/hello-feature-remote-desktop#remote-desktop-with-biometrics): Azure Active Directory and Active Directory users using Windows Hello for Business can use biometrics to authenticate to a remote desktop session. @@ -189,7 +189,6 @@ Windows Management Instrumentation (WMI) Group Policy Service (GPSVC) has a perf #### Key-rolling and Key-rotation This release also includes two new features called Key-rolling and Key-rotation enables secure rolling of Recovery passwords on MDM-managed Azure Active Directory devices on demand from Microsoft Intune/MDM tools or when a recovery password is used to unlock the BitLocker protected drive. This feature will help prevent accidental recovery password disclosure as part of manual BitLocker drive unlock by users. -s ## Deployment ### SetupDiag diff --git a/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md b/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md index d1275f53bd..c6547547b3 100644 --- a/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md +++ b/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md @@ -57,7 +57,7 @@ With Windows 10, you can create provisioning packages that let you quickly and e - **Encrypt and recover your device with Azure Active Directory**. In addition to using a Microsoft Account, automatic [Device Encryption](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#device-encryption) can now encrypt your devices that are joined to an Azure Active Directory domain. When the device is encrypted, the BitLocker recovery key is automatically escrowed to Azure Active Directory. This escrow will make it easier to recover your BitLocker key online. - **DMA port protection**. You can use the [DataProtection/AllowDirectMemoryAccess](/windows/client-management/mdm/policy-configuration-service-provider#dataprotection-allowdirectmemoryaccess) MDM policy to block DMA ports when the device is starting up. Also, when a device is locked, all unused DMA ports are turned off, but any devices that are already plugged into a DMA port will continue to work. When the device is unlocked, all DMA ports are turned back on. -- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings". +- **New Group Policy for configuring pre-boot recovery**. You can now configure the pre-boot recovery message and recover URL that is shown on the pre-boot recovery screen. For more info, see the [Configure pre-boot recovery message and URL](/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-configurepreboot) section in "BitLocker Group Policy settings." [Learn how to deploy and manage BitLocker within your organization](/windows/device-security/bitlocker/bitlocker-overview). @@ -101,7 +101,7 @@ In Windows 10, security auditing has added some improvements: In Windows 10, two new audit subcategories were added to the Advanced Audit Policy Configuration to provide greater granularity in audit events: - [Audit Group Membership](/windows/device-security/auditing/audit-group-membership) Found in the Logon/Logoff audit category, the Audit Group Membership subcategory allows you to audit the group membership information in a user's sign-in token. Events in this subcategory are generated when group memberships are enumerated or queried on the PC where the sign-in session was created. For an interactive logon, the security audit event is generated on the PC that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the PC hosting the resource. - When this setting is configured, one or more security audit events are generated for each successful sign in. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information can't fit in a single security audit event. + When this setting is configured, one or more security audit events are generated for each successful sign-in. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information can't fit in a single security audit event. - [Audit PNP Activity](/windows/security/threat-protection/auditing/audit-pnp-activity) Found in the Detailed Tracking category, the Audit PNP Activity subcategory allows you to audit when plug and play detects an external device. Only Success audits are recorded for this category. If you don't configure this policy setting, no audit event is generated when an external device is detected by plug and play. A PnP audit event can be used to track down changes in system hardware and will be logged on the PC where the change took place. A list of hardware vendor IDs are included in the event. @@ -132,7 +132,7 @@ The sign-in event ID 4624 has been updated to include more verbose information t 1. **MachineLogon** String: yes or no If the account that logged into the PC is a computer account, this field will be yes. Otherwise, the field is no. 2. **ElevatedToken** String: yes or no - If an account signed in to the PC through the "administrative sign in" method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. + If an account signed in to the PC through the "administrative sign in"-method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. 3. **TargetOutboundUserName** String **TargetOutboundUserDomain** String The username and domain of the identity that was created by the LogonUser method for outbound traffic. diff --git a/windows/whats-new/whats-new-windows-10-version-1809.md b/windows/whats-new/whats-new-windows-10-version-1809.md index 456dc6cece..92e1871b97 100644 --- a/windows/whats-new/whats-new-windows-10-version-1809.md +++ b/windows/whats-new/whats-new-windows-10-version-1809.md @@ -245,7 +245,7 @@ Do you have shared devices deployed in your work place? **Fast sign-in** enables >[!IMPORTANT] >This is a private preview feature and therefore not meant or recommended for production purposes. This setting is not currently supported at this time. -Until now, Windows sign in only supported the use of identities federated to ADFS or other providers that support the WS-Fed protocol. We're introducing **web sign-in**, a new way of signing into your Windows PC. Web sign-in enables Windows sign-in support for credentials not available on Windows. Web sign-in is restricted to only support Azure AD temporary access pass. +Until now, Windows sign-in only supported the use of identities federated to ADFS or other providers that support the WS-Fed protocol. We're introducing **web sign-in**, a new way of signing into your Windows PC. Web sign-in enables Windows sign-in support for credentials not available on Windows. Web sign-in is restricted to only support Azure AD temporary access pass. **To try out web sign-in:** 1. Azure AD Join your Windows 10 PC. (Web sign-in is only supported on Azure AD Joined PCs). @@ -268,8 +268,7 @@ Android phone users, you can finally stop emailing yourself photos. With Your Ph For iPhone users, **Your Phone** app also helps you to link your phone to your PC. Surf the web on your phone, then send the webpage instantly to your computer to continue what you’re doing-read, watch, or browse-with all the benefits of a bigger screen. -> [!div class="mx-imgBorder"] -> ![your phone.](images/your-phone.png "your phone") +:::image type="content" source="images/your-phone.png" alt-text="Your phone."::: The desktop pin takes you directly to the **Your Phone** app for quicker access to your phone’s content. You can also go through the all apps list in Start, or use the Windows key and search for **Your Phone**. diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md index bf6797c0fe..4dbfe4141b 100644 --- a/windows/whats-new/whats-new-windows-10-version-1903.md +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -118,7 +118,7 @@ This new feature is displayed under the Device Security page with the string “ ### Identity Protection -- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less sign in for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. +- [Windows Hello FIDO2 certification](https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/): Windows Hello is now a FIDO2 Certified authenticator and enables password-less sign-in for websites supporting FIDO2 authentication, such as Microsoft account and Azure AD. - [Streamlined Windows Hello PIN reset experience](/windows/security/identity-protection/hello-for-business/hello-videos#windows-hello-for-business-forgotten-pin-user-experience): Microsoft account users have a revamped Windows Hello PIN reset experience with the same look and feel as signing in on the web. - Sign-in with [Password-less](/windows/security/identity-protection/hello-for-business/passwordless-strategy) Microsoft accounts: Sign in to Windows 10 with a phone number account. Then use Windows Hello for an even easier sign-in experience! - [Remote Desktop with Biometrics](/windows/security/identity-protection/hello-for-business/hello-feature-remote-desktop#remote-desktop-with-biometrics): Azure Active Directory and Active Directory users using Windows Hello for Business can use biometrics to authenticate to a remote desktop session. From 947d9f12e3adc85cffe5d83e68e011c55366b906 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 17:58:23 -0600 Subject: [PATCH 047/109] Apply suggestions from code review --- windows/whats-new/ltsc/whats-new-windows-10-2015.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2015.md b/windows/whats-new/ltsc/whats-new-windows-10-2015.md index d9638bbe88..94de09d07a 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2015.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2015.md @@ -68,7 +68,7 @@ In Windows 10, security auditing has added some improvements: In Windows 10, two new audit subcategories were added to the Advanced Audit Policy Configuration to provide greater granularity in audit events: - [Audit Group Membership](/windows/device-security/auditing/audit-group-membership) Found in the Logon/Logoff audit category, the Audit Group Membership subcategory allows you to audit the group membership information in a user's logon token. Events in this subcategory are generated when group memberships are enumerated or queried on the PC where the sign-in session was created. For an interactive logon, the security audit event is generated on the PC that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the PC hosting the resource. - When this setting is configured, one or more security audit events are generated for each successful sign in. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information can't fit in a single security audit event. + When this setting is configured, one or more security audit events are generated for each successful sign-in. You must also enable the **Audit Logon** setting under **Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff**. Multiple events are generated if the group membership information can't fit in a single security audit event. - [Audit PNP Activity](/windows/security/threat-protection/auditing/audit-pnp-activity) Found in the Detailed Tracking category, the Audit PNP Activity subcategory allows you to audit when plug and play detects an external device. Only Success audits are recorded for this category. If you don't configure this policy setting, no audit event is generated when an external device is detected by plug and play. A PnP audit event can be used to track down changes in system hardware and will be logged on the PC where the change took place. A list of hardware vendor IDs is included in the event. @@ -90,7 +90,7 @@ In previous releases, the kernel depended on the Local Security Authority (LSA) #### Added a default process SACL to LSASS.exe -In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can enable this process under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. +In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is `L"S:(AU;SAFA;0x0010;;;WD)"`. You can enable this process under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. This process-when enabled-can help identify attacks that steal credentials from the memory of a process. #### New fields in the sign-in event @@ -99,7 +99,7 @@ The sign-in event ID 4624 has been updated to include more verbose information t 1. **MachineLogon** String: yes or no If the account that signed in to the PC is a computer account, this field will be yes. Otherwise, the field is no. 2. **ElevatedToken** String: yes or no - If an account has signed in to the PC through the "administrative sign in" method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. + If an account has signed in to the PC through the "administrative sign-in" method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. 3. **TargetOutboundUserName** String **TargetOutboundUserDomain** String The username and domain of the identity that was created by the LogonUser method for outbound traffic. From 8c34d54db99422159f29be4e33013ea202396a80 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 17:59:34 -0600 Subject: [PATCH 048/109] Update whats-new-windows-10-2021.md Fix line 141 "sign in" to "sign-in". --- windows/whats-new/ltsc/whats-new-windows-10-2021.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2021.md b/windows/whats-new/ltsc/whats-new-windows-10-2021.md index 0d4d858f20..b5b2625cea 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2021.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2021.md @@ -138,7 +138,7 @@ Application Guard performance is improved with optimized document opening times: Windows Hello enhancements include: - Windows Hello is now supported as Fast Identity Online 2 (FIDO2) authenticator across all major browsers including Chrome and Firefox. -- You can now enable passwordless sign-in for Microsoft accounts on your Windows 10 device by going to **Settings > Accounts > Sign-in options**, and selecting **On** under **Make your device passwordless**. Enabling passwordless sign in will switch all Microsoft accounts on your Windows 10 device to modern authentication with Windows Hello Face, Fingerprint, or PIN. +- You can now enable passwordless sign-in for Microsoft accounts on your Windows 10 device by going to **Settings > Accounts > Sign-in options**, and selecting **On** under **Make your device passwordless**. Enabling passwordless sign-in will switch all Microsoft accounts on your Windows 10 device to modern authentication with Windows Hello Face, Fingerprint, or PIN. - Windows Hello PIN sign-in support is [added to Safe mode](/windows-insider/archive/new-in-20H1#windows-hello-pin-in-safe-mode-build-18995). - Windows Hello for Business now has Hybrid Azure Active Directory support and phone number sign-in (Microsoft account). FIDO2 security key support is expanded to Azure Active Directory hybrid environments, enabling enterprises with hybrid environments to take advantage of [passwordless authentication](/azure/active-directory/authentication/howto-authentication-passwordless-security-key-on-premises). For more information, see [Expanding Azure Active Directory support for FIDO2 preview to hybrid environments](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/expanding-azure-active-directory-support-for-fido2-preview-to/ba-p/981894). - With specialized hardware and software components available on devices shipping with Windows 10, version 20H2 configured out of factory, Windows Hello now offers added support for virtualization-based security with supporting fingerprint and face sensors. This feature isolates and secures a user's biometric authentication data. From c3e88364dabb578f95833f0cacffe37b490bffe7 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 18:03:14 -0600 Subject: [PATCH 049/109] Apply suggestions from code review --- .../whats-new/whats-new-windows-10-version-1507-and-1511.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md b/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md index c6547547b3..5078ed991a 100644 --- a/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md +++ b/windows/whats-new/whats-new-windows-10-version-1507-and-1511.md @@ -123,7 +123,7 @@ In previous releases, the kernel depended on the Local Security Authority (LSA) ##### Added a default process SACL to LSASS.exe -In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can enable this process under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. +In Windows 10, a default process SACL was added to LSASS.exe to log processes attempting to access LSASS.exe. The SACL is `L"S:(AU;SAFA;0x0010;;;WD)"`. You can enable this process under **Advanced Audit Policy Configuration\\Object Access\\Audit Kernel Object**. This process can help identify attacks that steal credentials from the memory of a process. ##### New fields in the sign-in event @@ -132,7 +132,7 @@ The sign-in event ID 4624 has been updated to include more verbose information t 1. **MachineLogon** String: yes or no If the account that logged into the PC is a computer account, this field will be yes. Otherwise, the field is no. 2. **ElevatedToken** String: yes or no - If an account signed in to the PC through the "administrative sign in"-method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. + If an account signed in to the PC through the "administrative sign-in" method, this field will be yes. Otherwise, the field is no. Additionally, if this field is part of a split token, the linked sign-in ID (LSAP\_LOGON\_SESSION) will also be shown. 3. **TargetOutboundUserName** String **TargetOutboundUserDomain** String The username and domain of the identity that was created by the LogonUser method for outbound traffic. From 0cae079c5ab93301a68e5373bff4a23963290ac6 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 18:04:59 -0600 Subject: [PATCH 050/109] Update whats-new-windows-10-version-1703.md during sign in > during sign-in --- windows/whats-new/whats-new-windows-10-version-1703.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1703.md b/windows/whats-new/whats-new-windows-10-version-1703.md index 48815f6698..dd6617500e 100644 --- a/windows/whats-new/whats-new-windows-10-version-1703.md +++ b/windows/whats-new/whats-new-windows-10-version-1703.md @@ -15,7 +15,7 @@ ROBOTS: NOINDEX Below is a list of some of what's new in Information Technology (IT) pro features in Windows 10, version 1703 (also known as the Creators Update). -For more general info about Windows 10 features, see [Features available only on Windows 10](https://www.microsoft.com/windows/features). For info about previous versions of Windows 10, see [What's New in Windows 10](./index.yml). Also see this blog post: [What’s new for IT pros in the Windows 10 Creators Update](https://blogs.technet.microsoft.com/windowsitpro/2017/04/05/whats-new-for-it-pros-in-the-windows-10-creators-update/). +For more general info about Windows 10 features, see [Features available only on Windows 10](https://www.microsoft.com/windows/features). For info about previous versions of Windows 10, see [What's New in Windows 10](./index.yml). Also see this blog post: [What’s new for IT pros in the Windows 10 Creators Update}(https://blogs.technet.microsoft.com/windowsitpro/2017/04/05/whats-new-for-it-pros-in-the-windows-10-creators-update/). >[!NOTE] >Windows 10, version 1703 contains all fixes included in previous cumulative updates to Windows 10, version 1607. For info about each version, see [Windows 10 release information](https://technet.microsoft.com/windows/release-info). For a list of removed features, see [Features that are removed or deprecated in Windows 10 Creators Update](/windows/deployment/planning/windows-10-removed-features). @@ -153,7 +153,7 @@ For more information, see [Device Guard Requirements](/windows/device-security/d The security setting [**Interactive logon: Display user information when the session is locked**](/windows/device-security/security-policy-settings/interactive-logon-display-user-information-when-the-session-is-locked) has been updated to work in conjunction with the **Privacy** setting in **Settings** > **Accounts** > **Sign-in options**. A new security policy setting -[**Interactive logon: Don't display username at sign-in**](/windows/device-security/security-policy-settings/interactive-logon-dont-display-username-at-sign-in) has been introduced in Windows 10 version 1703. This security policy setting determines whether the username is displayed during sign in. It works in conjunction with the **Privacy** setting in **Settings** > **Accounts** > **Sign-in options**. The setting only affects the **Other user** tile. +[**Interactive logon: Don't display username at sign-in**](/windows/device-security/security-policy-settings/interactive-logon-dont-display-username-at-sign-in) has been introduced in Windows 10 version 1703. This security policy setting determines whether the username is displayed during sign-in. It works in conjunction with the **Privacy** setting in **Settings** > **Accounts** > **Sign-in options**. The setting only affects the **Other user** tile. ### Windows Hello for Business From 151517ce24228cb9bf8f1dc5acf821e84cde6900 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 18:06:26 -0600 Subject: [PATCH 051/109] Update whats-new-windows-10-version-1803.md --- windows/whats-new/whats-new-windows-10-version-1803.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index c8ada416cc..159845ee44 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -144,7 +144,7 @@ The OS uninstall period is a length of time that users are given when they can o - Windows Hello is now [password-less on S-mode](https://www.windowslatest.com/2018/02/12/microsoft-make-windows-10-password-less-platform/). - Support for S/MIME with Windows Hello for Business and APIs for non-Microsoft identity lifecycle management solutions. -- Windows Hello is part of the account protection pillar in Windows Defender Security Center. Account Protection will encourage password users to set up Windows Hello Face, Fingerprint or PIN for faster sign in, and will notify Dynamic lock users if Dynamic lock has stopped working because their phone or device Bluetooth is off. +- Windows Hello is part of the account protection pillar in Windows Defender Security Center. Account Protection will encourage password users to set up Windows Hello Face, Fingerprint or PIN for faster sign-in, and will notify Dynamic lock users if Dynamic lock has stopped working because their phone or device Bluetooth is off. - You can set up Windows Hello from lock screen for Microsoft accounts. We’ve made it easier for Microsoft account users to set up Windows Hello on their devices for faster and more secure sign-in. Previously, you had to navigate deep into Settings to find Windows Hello. Now, you can set up Windows Hello Face, Fingerprint or PIN straight from your lock screen by clicking the Windows Hello tile under Sign-in options. - New [public API](/uwp/api/windows.security.authentication.web.core.webauthenticationcoremanager.findallaccountsasync#Windows_Security_Authentication_Web_Core_WebAuthenticationCoreManager_FindAllAccountsAsync_Windows_Security_Credentials_WebAccountProvider_) for secondary account SSO for a particular identity provider. - It's easier to set up Dynamic lock, and WD SC actionable alerts have been added when Dynamic lock stops working (ex: phone Bluetooth is off). From 23aed99956df6b10c785bf53fd47cca1e5327c62 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 22 Jul 2022 18:07:49 -0600 Subject: [PATCH 052/109] Update whats-new-windows-10-version-2004.md --- windows/whats-new/whats-new-windows-10-version-2004.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-2004.md b/windows/whats-new/whats-new-windows-10-version-2004.md index 90fc585a9d..e0d940dbf9 100644 --- a/windows/whats-new/whats-new-windows-10-version-2004.md +++ b/windows/whats-new/whats-new-windows-10-version-2004.md @@ -28,7 +28,7 @@ To download and install Windows 10, version 2004, use Windows Update (**Settings - Windows Hello is now supported as Fast Identity Online 2 (FIDO2) authenticator across all major browsers including Chrome and Firefox. -- You can now enable passwordless sign-in for Microsoft accounts on your Windows 10 device by going to **Settings > Accounts > Sign-in options**, and selecting **On** under **Make your device passwordless**. Enabling passwordless sign in will switch all Microsoft accounts on your Windows 10 device to modern authentication with Windows Hello Face, Fingerprint, or PIN. +- You can now enable passwordless sign-in for Microsoft accounts on your Windows 10 device by going to **Settings > Accounts > Sign-in options**, and selecting **On** under **Make your device passwordless**. Enabling passwordless sign-in will switch all Microsoft accounts on your Windows 10 device to modern authentication with Windows Hello Face, Fingerprint, or PIN. - Windows Hello PIN sign-in support is [added to Safe mode](/windows-insider/archive/new-in-20H1#windows-hello-pin-in-safe-mode-build-18995). From 65a5a2be2bc670b1019e79bb49caa9aaed1a9f7d Mon Sep 17 00:00:00 2001 From: valemieux <98555474+valemieux@users.noreply.github.com> Date: Fri, 22 Jul 2022 18:26:35 -0700 Subject: [PATCH 053/109] Add .pdf to memcm --- .../deployment/deploy-wdac-policies-with-memcm.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md index 2efe41d1ae..165f04cd82 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md +++ b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md @@ -88,6 +88,8 @@ Configuration Manager doesn't remove policies once deployed. To stop enforcement For more information on using Configuration Manager's native WDAC policies, see [Windows Defender Application Control management with Configuration Manager](/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager). +The entire WDAC in MEMCM Lab Paper is available for download [here](https://download.microsoft.com/download/c/f/d/cfd6227c-8ec4-442d-8c50-825550d412f6/WDAC-Deploy-WDAC-using-MEMCM.pdf). + ## Deploy custom WDAC policies using Packages/Programs or Task Sequences Using Configuration Manager's built-in policies can be a helpful starting point, but customers may find the circle-of-trust options available in Configuration Manager too limiting. To define your own circle-of-trust, you can use Configuration Manager to deploy custom WDAC policies using [script-based deployment](deploy-wdac-policies-with-script.md) via Software Distribution Packages and Programs or Operating System Deployment Task Sequences. From 75a2b5c30c9fac1cc301b5a1eb89b4313cb05d07 Mon Sep 17 00:00:00 2001 From: Scott Breen <39719539+scottbreenmsft@users.noreply.github.com> Date: Mon, 25 Jul 2022 14:40:10 +1000 Subject: [PATCH 054/109] Update change-home-to-edu.md --- education/windows/change-home-to-edu.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/change-home-to-edu.md b/education/windows/change-home-to-edu.md index 02819afc30..85b1b85c00 100644 --- a/education/windows/change-home-to-edu.md +++ b/education/windows/change-home-to-edu.md @@ -30,7 +30,7 @@ IT admins can upgrade student devices using a multiple activation key (MAK) manu | Kivuto | Kivuto | Personal (student-owned) | Initiated on device by student, parent or guardian | | Provisioning package | VLSC | Personal (student-owned) or Corporate (institution-owned) | IT admin initiated at first boot | -These methods apply to devices with *Windows Home* installed, institution-owned devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Windows Education* or *Windows Enterprise* using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). +These methods apply to devices with *Windows Home* installed; institution-owned devices can be upgraded from *Windows Professional* or *Windows Pro Edu* to *Windows Education* or *Windows Enterprise* using [Windows 10/11 Subscription Activation](/windows/deployment/windows-10-subscription-activation). ## User Notifications From e22f6fa8dcf0b2c38a50e20933c36eb6f12d50de Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Mon, 25 Jul 2022 08:50:09 -0400 Subject: [PATCH 055/109] Update education/windows/set-up-school-pcs-whats-new.md --- education/windows/set-up-school-pcs-whats-new.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/set-up-school-pcs-whats-new.md b/education/windows/set-up-school-pcs-whats-new.md index 9fbd7080f1..1b582619a9 100644 --- a/education/windows/set-up-school-pcs-whats-new.md +++ b/education/windows/set-up-school-pcs-whats-new.md @@ -20,7 +20,7 @@ Learn what’s new with the Set up School PCs app each week. Find out about new ## Week of July 25, 2022 ### Reimage option for Windows 11 SE -Set up School PCs has added an option to reimage your SE devices to Windows 11 SE during the create provisioning package flow. Previously, the process to reimage a device was specific to the OEM and required technical knowledge. The new reimaging feature in SUSPC provides a unified way for all OEMs using a simple and easy flow. Now you are able to plug in your USB with a Windows 11 SE image and a provisioning package on it, and your device will be reimaged before the provisioning package is installed on that device. +Set up School PCs has added an option to reimage your Windows SE devices during the creation of a provisioning package. Previously, the process to reimage a device was specific to the OEM and required technical knowledge. The new reimaging feature in SUSPCs provides a unified way for all OEMs, using a simple and easy solution. Now you can plug in your USB stick with a Windows 11 SE image and a provisioning package on it, and your device will be reimaged before the provisioning package is installed on that device. Note: If after you have reimaged the device, you notice there are missing drivers, the IT admin should manually add those drivers to the image. The SUSPC reimaging tool has been tested on Surface SE devices, but since there are a variety of SE devices, the SUSPC reimage tool has not been tested on all SE devices. Contact your OEM to learn more about the necessary drivers. From 772993274b709d672aaf9ad9fc7dfec16e4a26a0 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Mon, 25 Jul 2022 11:02:50 -0400 Subject: [PATCH 056/109] Changes for #9917 --- ...age-text-for-users-attempting-to-log-on.md | 19 ++++---- ...ge-title-for-users-attempting-to-log-on.md | 44 +++++++++---------- 2 files changed, 32 insertions(+), 31 deletions(-) diff --git a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md index ec72b350f1..c709b19adc 100644 --- a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md +++ b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md @@ -22,7 +22,7 @@ ms.technology: windows-sec **Applies to:** -- Windows 10 +- Windows 10 Describes the best practices, location, values, management, and security considerations for the **Interactive logon: Message text for users attempting to log on** security policy setting. @@ -32,9 +32,7 @@ The **Interactive logon: Message text for users attempting to log on** and [Inte **Interactive logon: Message text for users attempting to log on** specifies a text message to be displayed to users when they log on. -**Interactive logon: Message title for users attempting to log on** specifies a title to appear in the title bar of the window that contains the text message. This text is often used for legal reasons — for example, to warn users about the ramifications of misusing company information, or to warn them that their actions might be audited. - -Not using this warning-message policy setting leaves your organization legally vulnerable to trespassers who unlawfully penetrate your network. Legal precedents have established that organizations that display warnings to users who connect to their servers over a network have a higher rate of successfully prosecuting trespassers. +**Interactive logon: Message title for users attempting to log on** specifies a title to appear in the title bar of the window that contains the text message. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. When these policy settings are configured, users will see a dialog box before they can log on to the server console. @@ -47,12 +45,15 @@ The possible values for this setting are: ### Best practices -- It is advisable to set **Interactive logon: Message text for users attempting to log on** to a value similar to one of the following: +It is advisable to set **Interactive logon: Message text for users attempting to log on** to a value similar to one of the following: - 1. IT IS AN OFFENSE TO CONTINUE WITHOUT PROPER AUTHORIZATION. - 2. This system is restricted to authorized users. Individuals who attempt unauthorized access will be prosecuted. If you are unauthorized, terminate access now. Click OK to indicate your acceptance of this information. - > [!IMPORTANT] - > Any warning that you display in the title or text should be approved by representatives from your organization's legal and human resources departments. +```text +1. IT IS AN OFFENSE TO CONTINUE WITHOUT PROPER AUTHORIZATION. +2. This system is restricted to authorized users. Individuals who attempt unauthorized access will be prosecuted. If you are unauthorized, terminate access now. Click OK to indicate your acceptance of this information. +``` + +> [!NOTE] +> Any warning that you display in the title or text should be approved by representatives from your organization's legal and human resources departments. ### Location diff --git a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md index e5f5ce5eb8..a63123134f 100644 --- a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md +++ b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md @@ -21,7 +21,8 @@ ms.technology: windows-sec # Interactive logon: Message title for users attempting to log on **Applies to** -- Windows 10 + +- Windows 10 Describes the best practices, location, values, policy management and security considerations for the **Interactive logon: Message title for users attempting to log on** security policy setting. @@ -29,28 +30,26 @@ Describes the best practices, location, values, policy management and security c This security setting allows you to specify a title that appears in the title bar of the window that contains the **Interactive logon: Message title for users attempting to log on**. This text is often used for legal reasons—for example, to warn users about the ramifications of misusing company information, or to warn them that their actions might be audited. -The **Interactive logon: Message title for users attempting to log on** and [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) policy settings are closely related. **Interactive logon: Message title for users attempting to log on** specifies a message title to be displayed to users when they log on. - -Not using this warning-message policy setting leaves your organization legally vulnerable to trespassers who unlawfully penetrate your network. Legal precedents have established that organizations that display warnings to users who connect to their servers over a network have a higher rate of successfully prosecuting trespassers. +The **Interactive logon: Message title for users attempting to log on** and [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) policy settings are closely related. **Interactive logon: Message title for users attempting to log on** specifies a message title to be displayed to users when they log on. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. When these policy settings are configured, users will see a dialog box before they can log on to the server console. ### Possible values -- *User-defined title* -- Not defined +- *User-defined title* +- Not defined ### Best practices -1. It is advisable to set **Interactive logon: Message title for users attempting to log on** to a value similar to one the following: +1. It is advisable to set **Interactive logon: Message title for users attempting to log on** to a value similar to one the following: - - RESTRICTED SYSTEM + - RESTRICTED SYSTEM - or + or - - WARNING: This system is restricted to authorized users. + - WARNING: This system is restricted to authorized users. -2. Set the policy [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) to reinforce the meaning of the message’s title. +2. Set the policy [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) to reinforce the meaning of the message’s title. ### Location @@ -62,13 +61,13 @@ The following table lists the actual and effective default values for this polic |Server type or GPO | Default value| | - | - | -| Default Domain Policy| Not defined| -| Default Domain Controller Policy | Not defined| -| Stand-Alone Server Default Settings | Not defined| -| DC Effective Default Settings | Not defined| -| Member Server Effective Default Settings | Not defined| -| Client Computer Effective Default Settings | Not defined| - +| Default Domain Policy| Not defined| +| Default Domain Controller Policy | Not defined| +| Stand-Alone Server Default Settings | Not defined| +| DC Effective Default Settings | Not defined| +| Member Server Effective Default Settings | Not defined| +| Client Computer Effective Default Settings | Not defined| + ## Policy management This section describes features and tools that are available to help you manage this policy. @@ -83,8 +82,8 @@ This section describes how an attacker might exploit a feature or its configurat There are two policy settings that relate to logon displays: -- [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) -- **Interactive logon: Message title for users attempting to log on** +- [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) +- **Interactive logon: Message title for users attempting to log on** The first policy setting specifies a text message that displays to users when they log on, and the second policy setting specifies a title for the title bar of the text message window. Many organizations use this text for legal purposes; for example, to warn users about the ramifications of misuse of company information, or to warn them that their actions may be audited. @@ -96,8 +95,9 @@ Users often do not understand the importance of security practices. However, the Configure the [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) and **Interactive logon: Message title for users attempting to log on** settings to an appropriate value for your organization. ->**Note:**  Any warning message that displays should be approved by your organization's legal and human resources representatives. - +> [!NOTE] +> Any warning message that displays should be approved by your organization's legal and human resources representatives. + ### Potential impact Users see a message in a dialog box before they can log on to the server console. From 084c80691f6fdb0262e50217503c4e7de061f062 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Mon, 25 Jul 2022 11:15:16 -0400 Subject: [PATCH 057/109] Minor changes --- ...ve-logon-message-text-for-users-attempting-to-log-on.md | 7 +++---- ...e-logon-message-title-for-users-attempting-to-log-on.md | 4 +--- 2 files changed, 4 insertions(+), 7 deletions(-) diff --git a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md index c709b19adc..8fdc5659f9 100644 --- a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md +++ b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md @@ -30,11 +30,10 @@ Describes the best practices, location, values, management, and security conside The **Interactive logon: Message text for users attempting to log on** and [Interactive logon: Message title for users attempting to log on](interactive-logon-message-title-for-users-attempting-to-log-on.md) policy settings are closely related. -**Interactive logon: Message text for users attempting to log on** specifies a text message to be displayed to users when they log on. +- **Interactive logon: Message text for users attempting to log on** specifies a text message to be displayed to users when they log on. +- **Interactive logon: Message title for users attempting to log on** specifies a title to appear in the title bar of the window that contains the text message. -**Interactive logon: Message title for users attempting to log on** specifies a title to appear in the title bar of the window that contains the text message. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. - -When these policy settings are configured, users will see a dialog box before they can log on to the server console. +This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. When these policy settings are configured, users will see a dialog box before they can log on to the server console. ### Possible values diff --git a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md index a63123134f..e69e4bd287 100644 --- a/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md +++ b/windows/security/threat-protection/security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md @@ -30,9 +30,7 @@ Describes the best practices, location, values, policy management and security c This security setting allows you to specify a title that appears in the title bar of the window that contains the **Interactive logon: Message title for users attempting to log on**. This text is often used for legal reasons—for example, to warn users about the ramifications of misusing company information, or to warn them that their actions might be audited. -The **Interactive logon: Message title for users attempting to log on** and [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) policy settings are closely related. **Interactive logon: Message title for users attempting to log on** specifies a message title to be displayed to users when they log on. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. - -When these policy settings are configured, users will see a dialog box before they can log on to the server console. +The **Interactive logon: Message title for users attempting to log on** and [Interactive logon: Message text for users attempting to log on](interactive-logon-message-text-for-users-attempting-to-log-on.md) policy settings are closely related. When these policy settings are configured, users will see a dialog box before they can log on to the server console. ### Possible values From 2426c06108ec57f3e49c53d3bef908fa7775ab5f Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Mon, 25 Jul 2022 11:50:35 -0400 Subject: [PATCH 058/109] Fixed markup based on 9924 --- .../hello-hybrid-key-whfb-settings-pki.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md index a43a8e5673..6606eca9ed 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md @@ -79,11 +79,11 @@ The certificate template is configured to supersede all the certificate template > [!NOTE] > The domain controller's certificate must chain to a root in the NTAuth store. By default, the Active Directory Certificate Authority's root certificate is added to the NTAuth store. If you are using a third-party CA, this may not be done by default. If the domain controller certificate does not chain to a root in the NTAuth store, user authentication will fail. ->you can view +>To see all certificates in the NTAuth store, use the following command: > ->'''powershell ->Certutil -view ->Publish Certificate Templates to a Certificate Authority +> `Certutil -viewstore -enterprise NTAuth` + +### Publish Certificate Templates to a Certificate Authority The certificate authority may only issue certificates for certificate templates that are published to that certificate authority. If you have more than one certificate authority and you want that certificate authority to issue certificates based on a specific certificate template, then you must publish the certificate template to all certificate authorities that are expected to issue the certificate. @@ -95,7 +95,7 @@ Sign-in to the certificate authority or management workstations with an _enterpr 4. Right-click the **Certificate Templates** node. Click **New**, and click **Certificate Template** to issue. 5. In the **Enable Certificates Templates** window, select the **Domain Controller Authentication (Kerberos)** template you created in the previous steps. Click **OK** to publish the selected certificate templates to the certificate authority. 6. If you published the **Domain Controller Authentication (Kerberos)** certificate template, then you should unpublish the certificate templates you included in the superseded templates list. - * To unpublish a certificate template, right-click the certificate template you want to unpublish in the details pane of the Certificate Authority console and select **Delete**. Click **Yes** to confirm the operation. + - To unpublish a certificate template, right-click the certificate template you want to unpublish in the details pane of the Certificate Authority console and select **Delete**. Click **Yes** to confirm the operation. 7. Close the console. ### Unpublish Superseded Certificate Templates From 831be4c8e2beeffedb581a7a56a7e35af3c021b9 Mon Sep 17 00:00:00 2001 From: Tarun Maganur <104856032+Tarun-Edu@users.noreply.github.com> Date: Mon, 25 Jul 2022 09:06:24 -0700 Subject: [PATCH 059/109] Update windows-11-se-overview.md --- education/windows/windows-11-se-overview.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/education/windows/windows-11-se-overview.md b/education/windows/windows-11-se-overview.md index 9f89ef79d0..dd98543603 100644 --- a/education/windows/windows-11-se-overview.md +++ b/education/windows/windows-11-se-overview.md @@ -75,14 +75,13 @@ Windows 11 SE comes with some preinstalled apps. The following apps can also run |NonVisual Desktop Access |2021.3.1 |Win32 |NV Access| |NWEA Secure Testing Browser |5.4.300.0 |Win32 |NWEA| |Pearson TestNav |1.10.2.0 |Store |Pearson| -|Questar Secure Browser |4.8.3.376 |Win32 |Questar| +|Questar Secure Browser |4.8.3.376 |Win32 |Questar, Inc| |ReadAndWriteForWindows |12.0.60.0 |Win32 |Texthelp Ltd.| |Remote Desktop client (MSRDC) |1.2.3213.0 |Win32 |Microsoft| |Remote Help |3.8.0.12 |Win32 |Microsoft| |Respondus Lockdown Browser |2.0.8.05 |Win32 |Respondus| |Safe Exam Browser |3.3.2.413 |Win32 |Safe Exam Browser| |Secure Browser |14.0.0 |Win32 |Cambium Development| -|Secure Browser |4.8.3.376 |Win32 |Questar, Inc| |Senso.Cloud |2021.11.15.0 |Win32|Senso.Cloud| |SuperNova Magnifier & Screen Reader |21.02 |Win32 |Dolphin Computer Access| |Zoom |5.9.1 (2581)|Win32 |Zoom| From a488411bd203603993bfbd26f78ffe8adf04712e Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Mon, 25 Jul 2022 10:08:20 -0600 Subject: [PATCH 060/109] Apply suggestions from code review --- windows/whats-new/ltsc/whats-new-windows-10-2021.md | 2 +- windows/whats-new/whats-new-windows-10-version-1703.md | 4 ---- 2 files changed, 1 insertion(+), 5 deletions(-) diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2021.md b/windows/whats-new/ltsc/whats-new-windows-10-2021.md index b5b2625cea..d79885ad46 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2021.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2021.md @@ -115,7 +115,7 @@ Windows Defender Firewall also now supports [Windows Subsystem for Linux (WSL)]( **Dynamic navigation**: Application Guard now allows users to navigate back to their default host browser from the Application Guard Microsoft Edge. Previously, users browsing in Application Guard Edge would see an error page when they try to go to a trusted site within the container browser. With this new feature, users will automatically be redirected to their host default browser when they enter or click on a trusted site in Application Guard Edge. This feature is also available in Windows 10, version 1803 or later with the latest updates. Application Guard performance is improved with optimized document opening times: -- An issue is fixed that could cause a one-minute-or more delay when you open a Microsoft Defender Application Guard (Application Guard) Office document. This issue can occur when you try to open a file using a Universal Naming Convention (UNC) path or Server Message Block (SMB) share link. +- An issue is fixed that could cause a one-minute-or-more delay when you open a Microsoft Defender Application Guard (Application Guard) Office document. This issue can occur when you try to open a file using a Universal Naming Convention (UNC) path or Server Message Block (SMB) share link. - A memory issue is fixed that could cause an Application Guard container to use almost 1 GB of working set memory when the container is idle. - The performance of Robocopy is improved when copying files over 400 MB in size. diff --git a/windows/whats-new/whats-new-windows-10-version-1703.md b/windows/whats-new/whats-new-windows-10-version-1703.md index dd6617500e..c6f958b3fe 100644 --- a/windows/whats-new/whats-new-windows-10-version-1703.md +++ b/windows/whats-new/whats-new-windows-10-version-1703.md @@ -65,9 +65,6 @@ Previously, the customized taskbar could only be deployed using Group Policy or - Settings for Power: [**Start/HidePowerButton**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidepowerbutton), [**Start/HideHibernate**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidehibernate), [**Start/HideRestart**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderestart), [**Start/HideShutDown**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideshutdown), and [**Start/HideSleep**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidesleep) - Other new settings: [**Start/HideFrequentlyUsedApps**](/windows/client-management/mdm/policy-configuration-service-provider#start-hidefrequentlyusedapps), [**Start/HideRecentlyAddedApps**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderecentlyaddedapps), **AllowPinnedFolder**, **ImportEdgeAssets**, [**Start/HideRecentJumplists**](/windows/client-management/mdm/policy-configuration-service-provider#start-hiderecentjumplists), [**Start/NoPinningToTaskbar**](/windows/client-management/mdm/policy-configuration-service-provider#start-nopinningtotaskbar), [**Settings/PageVisibilityList**](/windows/client-management/mdm/policy-configuration-service-provider#settings-pagevisibilitylist), and [**Start/HideAppsList**](/windows/client-management/mdm/policy-configuration-service-provider#start-hideapplist). - - - ### Cortana at work Cortana is Microsoft’s personal digital assistant, who helps busy people get things done, even while at work. Cortana has powerful configuration options, optimized for your business. When your employees sign in with an Azure Active Directory (Azure AD) account, they can give Cortana access to their enterprise/work identity, while getting all the functionality Cortana provides to them outside of work. @@ -274,7 +271,6 @@ Miracast over Infrastructure offers many benefits: - It works well with older wireless hardware that isn't optimized for Miracast over Wi-Fi Direct. - It uses an existing connection that reduces the time to connect and provides a stable stream. - ### How it works Users attempt to connect to a Miracast receiver as they did previously. When the list of Miracast receivers is populated, Windows 10 will identify that the receiver is capable of supporting a connection over the infrastructure. When the user selects a Miracast receiver, Windows 10 will attempt to resolve the device's hostname via standard DNS, and via multicast DNS (mDNS). If the name isn't resolvable via either DNS method, Windows 10 will fall back to establishing the Miracast session using the standard Wi-Fi direct connection. From 3e8e8075566d8b4eabd820fbc44c0c5523538492 Mon Sep 17 00:00:00 2001 From: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com> Date: Mon, 25 Jul 2022 11:14:16 -0500 Subject: [PATCH 061/109] Update hello-hybrid-key-whfb-settings-pki.md --- .../hello-for-business/hello-hybrid-key-whfb-settings-pki.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md index 6606eca9ed..5f2d0ed289 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md @@ -21,7 +21,7 @@ ms.reviewer: - Hybrid Deployment - Key trust -Windows Hello for Business deployments rely on certificates. Hybrid deployments uses publicly issued server authentication certificates to validate the name of the server to which they are connecting and to encrypt the data that flows them and the client computer. +Windows Hello for Business deployments rely on certificates. Hybrid deployments use publicly issued server authentication certificates to validate the name of the server to which they are connecting and to encrypt the data that flows them and the client computer. All deployments use enterprise issued certificates for domain controllers as a root of trust. From aaa34f2f41869b5840ae52df34aad3bf378474f7 Mon Sep 17 00:00:00 2001 From: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com> Date: Mon, 25 Jul 2022 11:21:46 -0500 Subject: [PATCH 062/109] Update determine-your-application-control-objectives.md --- .../applocker/determine-your-application-control-objectives.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md index 395698f788..1136c55fd2 100644 --- a/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md +++ b/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives.md @@ -39,7 +39,7 @@ Use the following table to develop your own objectives and determine which appli |Application control function|SRP|AppLocker| |--- |--- |--- | -|Scope|SRP policies can be applied to all Windows operating systems beginning with Windows XP and Windows Server 2003.|AppLocker policies apply only to the support versions of Windows listed in[Requirements to use AppLocker](requirements-to-use-applocker.md).| +|Scope|SRP policies can be applied to all Windows operating systems beginning with Windows XP and Windows Server 2003.|AppLocker policies apply only to the support versions of Windows listed in [Requirements to use AppLocker](requirements-to-use-applocker.md).| |Policy creation|SRP policies are maintained through Group Policy and only the administrator of the GPO can update the SRP policy. The administrator on the local computer can modify the SRP policies defined in the local GPO.|AppLocker policies are maintained through Group Policy and only the administrator of the GPO can update the policy. The administrator on the local computer can modify the AppLocker policies defined in the local GPO.

    AppLocker permits customization of error messages to direct users to a Web page for help.| |Policy maintenance|SRP policies must be updated by using the Local Security Policy snap-in (if the policies are created locally) or the Group Policy Management Console (GPMC).|AppLocker policies can be updated by using the Local Security Policy snap-in, if the policies are created locally, or the GPMC, or the Windows PowerShell AppLocker cmdlets.| |Policy application|SRP policies are distributed through Group Policy.|AppLocker policies are distributed through Group Policy.| From 2e1df8ef2f2e06c7e92357dd453999a8782118d8 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Mon, 25 Jul 2022 12:40:00 -0400 Subject: [PATCH 063/109] update links --- .../access-control/special-identities.md | 194 +++++++----------- 1 file changed, 74 insertions(+), 120 deletions(-) diff --git a/windows/security/identity-protection/access-control/special-identities.md b/windows/security/identity-protection/access-control/special-identities.md index 82f5cbbcda..8a95cb32e9 100644 --- a/windows/security/identity-protection/access-control/special-identities.md +++ b/windows/security/identity-protection/access-control/special-identities.md @@ -16,15 +16,16 @@ ms.reviewer: # Special Identities **Applies to** -- Windows Server 2016 or later + +- Windows Server 2016 or later This reference topic for the IT professional describes the special identity groups (which are sometimes referred to as security groups) that are used in Windows access control. Special identity groups are similar to Active Directory security groups as listed in the users and built-in containers. Special identity groups can provide an efficient way to assign access to resources in your network. By using special identity groups, you can: -- Assign user rights to security groups in Active Directory. +- Assign user rights to security groups in Active Directory. -- Assign permissions to security groups for the purpose of accessing resources. +- Assign permissions to security groups for the purpose of accessing resources. Servers that are running the supported Windows Server operating systems designated in the **Applies To** list at the beginning of this topic include several special identity groups. These special identity groups do not have specific memberships that can be modified, but they can represent different users at different times, depending on the circumstances. @@ -34,61 +35,47 @@ For information about security groups and group scope, see [Active Directory Sec The special identity groups are described in the following tables: -- [Anonymous Logon](#anonymous-logon) - -- [Authenticated Users](#authenticated-users) - -- [Batch](#batch) - -- [Creator Group](#creator-group) - -- [Creator Owner](#creator-owner) - -- [Dialup](#dialup) - -- [Digest Authentication](#digest-authentication) - -- [Enterprise Domain Controllers](#enterprise-domain-controllers) - -- [Everyone](#everyone) - -- [Interactive](#interactive) - -- [Local Service](#local-service) - -- [LocalSystem](#localsystem) - -- [Network](#network) - -- [Network Service](#network-service) - -- [NTLM Authentication](#ntlm-authentication) - -- [Other Organization](#other-organization) - -- [Principal Self](#principal-self) - -- [Remote Interactive Logon](#remote-interactive-logon) - -- [Restricted](#restricted) - -- [SChannel Authentication](#schannel-authentication) - -- [Service](#service) - -- [Terminal Server User](#terminal-server-user) - -- [This Organization](#this-organization) - -- [Window Manager\\Window Manager Group](#window-managerwindow-manager-group) +- [Anonymous Logon](#anonymous-logon) +- [Attested Key Property](#attested-key-property) +- [Authenticated Users](#authenticated-users) +- [Authentication Authority Asserted Identity](#authentication-authority-asserted-identity) +- [Batch](#batch) +- [Console Logon](#console-logon) +- [Creator Group](#creator-group) +- [Creator Owner](#creator-owner) +- [Dialup](#dialup) +- [Digest Authentication](#digest-authentication) +- [Enterprise Domain Controllers](#enterprise-domain-controllers) +- [Everyone](#everyone) +- [Fresh Public Key Identity](#fresh-public-key-identity) +- [Interactive](#interactive) +- [IUSR](#iusr) +- [Key Trust](#key-trust) +- [Local Service](#local-service) +- [LocalSystem](#localsystem) +- [MFA Key Property](#mfa-key-property) +- [Network](#network) +- [Network Service](#network-service) +- [NTLM Authentication](#ntlm-authentication) +- [Other Organization](#other-organization) +- [Owner Rights](#owner-rights) +- [Principal Self](#principal-self) +- [Proxy](#proxy) +- [Remote Interactive Logon](#remote-interactive-logon) +- [Restricted](#restricted) +- [SChannel Authentication](#schannel-authentication) +- [Service](#service) +- [Service Asserted Identity](#service-asserted-identity) +- [Terminal Server User](#terminal-server-user) +- [This Organization](#this-organization) +- [Window Manager\\Window Manager Group](#window-managerwindow-manager-group) ## Anonymous Logon - Any user who accesses the system through an anonymous logon has the Anonymous Logon identity. This identity allows anonymous access to resources, such as a web page that is published on corporate servers. The Anonymous Logon group is not a member of the Everyone group by default. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-7 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -96,11 +83,10 @@ Any user who accesses the system through an anonymous logon has the Anonymous Lo ## Attested Key Property - A SID that means the key trust object had the attestation property. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-18-6 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -108,11 +94,10 @@ A SID that means the key trust object had the attestation property. ## Authenticated Users - Any user who accesses the system through a sign-in process has the Authenticated Users identity. This identity allows access to shared resources within the domain, such as files in a shared folder that should be accessible to all the workers in the organization. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-11 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -120,11 +105,10 @@ Any user who accesses the system through a sign-in process has the Authenticated ## Authentication Authority Asserted Identity - A SID that means the client's identity is asserted by an authentication authority based on proof of possession of client credentials. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-18-1 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -132,11 +116,10 @@ A SID that means the client's identity is asserted by an authentication authorit ## Batch - Any user or process that accesses the system as a batch job (or through the batch queue) has the Batch identity. This identity allows batch jobs to run scheduled tasks, such as a nightly cleanup job that deletes temporary files. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-3 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -144,11 +127,10 @@ Any user or process that accesses the system as a batch job (or through the batc ## Console Logon - A group that includes users who are logged on to the physical console. This SID can be used to implement security policies that grant different rights based on whether a user has been granted physical access to the console. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-2-1 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -156,13 +138,12 @@ A group that includes users who are logged on to the physical console. This SID ## Creator Group - The person who created the file or the directory is a member of this special identity group. Windows Server operating systems use this identity to automatically grant access permissions to the creator of a file or directory. A placeholder security identifier (SID) is created in an inheritable access control entry (ACE). When the ACE is inherited, the system replaces this SID with the SID for the primary group of the object’s current owner. The primary group is used only by the Portable Operating System Interface for UNIX (POSIX) subsystem. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-3-1 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -170,11 +151,10 @@ A placeholder security identifier (SID) is created in an inheritable access cont ## Creator Owner - The person who created the file or the directory is a member of this special identity group. Windows Server operating systems use this identity to automatically grant access permissions to the creator of a file or directory. A placeholder SID is created in an inheritable ACE. When the ACE is inherited, the system replaces this SID with the SID for the object’s current owner. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-3-0 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -182,11 +162,10 @@ The person who created the file or the directory is a member of this special ide ## Dialup - Any user who accesses the system through a dial-up connection has the Dial-Up identity. This identity distinguishes dial-up users from other types of authenticated users. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-1 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -194,9 +173,8 @@ Any user who accesses the system through a dial-up connection has the Dial-Up id ## Digest Authentication - | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-64-21 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -204,11 +182,10 @@ Any user who accesses the system through a dial-up connection has the Dial-Up id ## Enterprise Domain Controllers - This group includes all domain controllers in an Active Directory forest. Domain controllers with enterprise-wide roles and responsibilities have the Enterprise Domain Controllers identity. This identity allows them to perform certain tasks in the enterprise by using transitive trusts. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-9 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -216,15 +193,14 @@ This group includes all domain controllers in an Active Directory forest. Domain ## Everyone - All interactive, network, dial-up, and authenticated users are members of the Everyone group. This special identity group gives wide access to system resources. Whenever a user logs on to the network, the user is automatically added to the Everyone group. -On computers running Windows 2000 and earlier, the Everyone group included the Anonymous Logon group as a default member, but as of Windows Server 2003, the Everyone group contains only Authenticated Users and Guest; and it no longer includes Anonymous Logon by default (although this can be changed, using Registry Editor, by going to the **Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa** key and setting the value of **everyoneincludesanonymous** DWORD to 1). +On computers running Windows 2000 and earlier, the Everyone group included the Anonymous Logon group as a default member, but as of Windows Server 2003, the Everyone group contains only Authenticated Users and Guest; and it no longer includes Anonymous Logon by default (although this can be changed, using Registry Editor, by going to the **Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa** key and setting the value of **everyoneincludesanonymous** DWORD to 1). Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-1-0 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -232,11 +208,10 @@ Membership is controlled by the operating system. ## Fresh Public Key Identity - A SID that means the client's identity is asserted by an authentication authority based on proof of current possession of client public key credentials. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-18-3 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -244,11 +219,10 @@ A SID that means the client's identity is asserted by an authentication authorit ## Interactive - Any user who is logged on to the local system has the Interactive identity. This identity allows only local users to access a resource. Whenever a user accesses a given resource on the computer to which they are currently logged on, the user is automatically added to the Interactive group. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-4 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -256,11 +230,10 @@ Any user who is logged on to the local system has the Interactive identity. This ## IUSR - Internet Information Services (IIS) uses this account by default whenever anonymous authentication is enabled. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-17 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -268,11 +241,10 @@ Internet Information Services (IIS) uses this account by default whenever anonym ## Key Trust - A SID that means the client's identity is based on proof of possession of public key credentials using the key trust object. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-18-4 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -280,11 +252,10 @@ A SID that means the client's identity is based on proof of possession of public ## Local Service - The Local Service account is similar to an Authenticated User account. The Local Service account has the same level of access to resources and objects as members of the Users group. This limited access helps safeguard your system if individual services or processes are compromised. Services that run as the Local Service account access network resources as a null session with anonymous credentials. The name of the account is NT AUTHORITY\\LocalService. This account does not have a password. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-19 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -292,12 +263,10 @@ The Local Service account is similar to an Authenticated User account. The Local ## LocalSystem - This is a service account that is used by the operating system. The LocalSystem account is a powerful account that has full access to the system and acts as the computer on the network. If a service logs on to the LocalSystem account on a domain controller, that service has access to the entire domain. Some services are configured by default to log on to the LocalSystem account. Do not change the default service setting. The name of the account is LocalSystem. This account does not have a password. - | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-18 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -305,11 +274,10 @@ This is a service account that is used by the operating system. The LocalSystem ## MFA Key Property - A SID that means the key trust object had the multifactor authentication (MFA) property. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-18-5 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -320,7 +288,7 @@ A SID that means the key trust object had the multifactor authentication (MFA) p This group implicitly includes all users who are logged on through a network connection. Any user who accesses the system through a network has the Network identity. This identity allows only remote users to access a resource. Whenever a user accesses a given resource over the network, the user is automatically added to the Network group. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-2 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -328,11 +296,10 @@ This group implicitly includes all users who are logged on through a network con ## Network Service - The Network Service account is similar to an Authenticated User account. The Network Service account has the same level of access to resources and objects as members of the Users group. This limited access helps safeguard your system if individual services or processes are compromised. Services that run as the Network Service account access network resources by using the credentials of the computer account. The name of the account is NT AUTHORITY\\NetworkService. This account does not have a password. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-20 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -340,9 +307,8 @@ The Network Service account is similar to an Authenticated User account. The Net ## NTLM Authentication - | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-64-10 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -350,11 +316,10 @@ The Network Service account is similar to an Authenticated User account. The Net ## Other Organization - This group implicitly includes all users who are logged on to the system through a dial-up connection. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-1000 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -362,11 +327,10 @@ This group implicitly includes all users who are logged on to the system through ## Owner Rights - A group that represents the current owner of the object. When an ACE that carries this SID is applied to an object, the system ignores the implicit READ_CONTROL and WRITE_DAC permissions for the object owner. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-3-4 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -374,11 +338,10 @@ A group that represents the current owner of the object. When an ACE that carrie ## Principal Self - This identity is a placeholder in an ACE on a user, group, or computer object in Active Directory. When you grant permissions to Principal Self, you grant them to the security principal that is represented by the object. During an access check, the operating system replaces the SID for Principal Self with the SID for the security principal that is represented by the object. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-10 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -386,11 +349,10 @@ This identity is a placeholder in an ACE on a user, group, or computer object in ## Proxy - Identifies a SECURITY_NT_AUTHORITY Proxy. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-8 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -398,11 +360,10 @@ Identifies a SECURITY_NT_AUTHORITY Proxy. ## Remote Interactive Logon - This identity represents all users who are currently logged on to a computer by using a Remote Desktop connection. This group is a subset of the Interactive group. Access tokens that contain the Remote Interactive Logon SID also contain the Interactive SID. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-14| |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -410,11 +371,10 @@ This identity represents all users who are currently logged on to a computer by ## Restricted - Users and computers with restricted capabilities have the Restricted identity. This identity group is used by a process that is running in a restricted security context, such as running an application with the RunAs service. When code runs at the Restricted security level, the Restricted SID is added to the user’s access token. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-12 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -422,9 +382,8 @@ Users and computers with restricted capabilities have the Restricted identity. T ## SChannel Authentication - | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-64-14 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -432,12 +391,10 @@ Users and computers with restricted capabilities have the Restricted identity. T ## Service - Any service that accesses the system has the Service identity. This identity group includes all security principals that are signed in as a service. This identity grants access to processes that are being run by Windows Server services. Membership is controlled by the operating system. - | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-6 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -445,11 +402,10 @@ Any service that accesses the system has the Service identity. This identity gro ## Service Asserted Identity - A SID that means the client's identity is asserted by a service. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-18-2 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -457,11 +413,10 @@ A SID that means the client's identity is asserted by a service. ## Terminal Server User - Any user accessing the system through Terminal Services has the Terminal Server User identity. This identity allows users to access Terminal Server applications and to perform other necessary tasks with Terminal Server services. Membership is controlled by the operating system. | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-13 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| @@ -469,18 +424,17 @@ Any user accessing the system through Terminal Services has the Terminal Server ## This Organization - | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-15 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| -|Default User Rights| None | +|Default User Rights| None | ## Window Manager\\Window Manager Group | Attribute | Value | -| :--: | :--: | +| :--: | :--: | | Well-Known SID/RID | S-1-5-90 | |Object Class| Foreign Security Principal| |Default Location in Active Directory |cn=WellKnown Security Principals, cn=Configuration, dc=\| From 3b3fd2119fdaaaf33cbde80091863151cb1c0fb4 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Mon, 25 Jul 2022 12:49:07 -0400 Subject: [PATCH 064/109] minor edit --- .../identity-protection/access-control/special-identities.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/security/identity-protection/access-control/special-identities.md b/windows/security/identity-protection/access-control/special-identities.md index 8a95cb32e9..995d23b020 100644 --- a/windows/security/identity-protection/access-control/special-identities.md +++ b/windows/security/identity-protection/access-control/special-identities.md @@ -23,8 +23,7 @@ This reference topic for the IT professional describes the special identity grou Special identity groups are similar to Active Directory security groups as listed in the users and built-in containers. Special identity groups can provide an efficient way to assign access to resources in your network. By using special identity groups, you can: -- Assign user rights to security groups in Active Directory. - +- Assign user rights to security groups in Active Directory. - Assign permissions to security groups for the purpose of accessing resources. Servers that are running the supported Windows Server operating systems designated in the **Applies To** list at the beginning of this topic include several special identity groups. These special identity groups do not have specific memberships that can be modified, but they can represent different users at different times, depending on the circumstances. From 1424c60e2ea7a362e6f2db08b63c8e46b8d582d3 Mon Sep 17 00:00:00 2001 From: valemieux <98555474+valemieux@users.noreply.github.com> Date: Mon, 25 Jul 2022 09:58:03 -0700 Subject: [PATCH 065/109] Update deploy-wdac-policies-with-memcm.md --- .../deployment/deploy-wdac-policies-with-memcm.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md index 165f04cd82..e047eeb68a 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md +++ b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md @@ -88,7 +88,7 @@ Configuration Manager doesn't remove policies once deployed. To stop enforcement For more information on using Configuration Manager's native WDAC policies, see [Windows Defender Application Control management with Configuration Manager](/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager). -The entire WDAC in MEMCM Lab Paper is available for download [here](https://download.microsoft.com/download/c/f/d/cfd6227c-8ec4-442d-8c50-825550d412f6/WDAC-Deploy-WDAC-using-MEMCM.pdf). +The entire WDAC in Configuration Manager Lab Paper is available for download [here](https://download.microsoft.com/download/c/f/d/cfd6227c-8ec4-442d-8c50-825550d412f6/WDAC-Deploy-WDAC-using-MEMCM.pdf). ## Deploy custom WDAC policies using Packages/Programs or Task Sequences From 4fef75d3fe12429f85f77df8ad2f40e28125ac2e Mon Sep 17 00:00:00 2001 From: Jimmy Wu Date: Mon, 25 Jul 2022 11:44:24 -0700 Subject: [PATCH 066/109] Added Win10 support information Added Win10 support information to universalprint-csp.md --- .../mdm/universalprint-csp.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/windows/client-management/mdm/universalprint-csp.md b/windows/client-management/mdm/universalprint-csp.md index e7ca5d359c..fab5cf6f5e 100644 --- a/windows/client-management/mdm/universalprint-csp.md +++ b/windows/client-management/mdm/universalprint-csp.md @@ -15,18 +15,18 @@ manager: dougeby The table below shows the applicability of Windows: -|Edition|Windows 11| -|--- |--- | -|Home|No| -|Pro|Yes| -|Windows SE|Yes| -|Business|Yes| -|Enterprise|Yes| -|Education|Yes| +|Edition|Windows 11|Windows 10| +|--- |--- |--- | +|Home|No|No| +|Pro|Yes|Yes| +|Windows SE|Yes|Yes| +|Business|Yes|Yes| +|Enterprise|Yes|Yes| +|Education|Yes|Yes| The UniversalPrint configuration service provider (CSP) is used to add Universal Print-compatible printers to Windows client endpoints. Universal Print is a cloud-based printing solution that runs entirely in Microsoft Azure. It doesn't require any on-premises infrastructure. For more specific information, go to [What is Universal Print](/universal-print/fundamentals/universal-print-whatis). -This CSP was added in Windows 11. +This CSP was added in Windows 11 and in Windows 10 21H2 July 2022 update [KB5015807](https://support.microsoft.com/topic/july-12-2022-kb5015807-os-builds-19042-1826-19043-1826-and-19044-1826-8c8ea8fe-ec83-467d-86fb-a2f48a85eb41). The following example shows the UniversalPrint configuration service provider in tree format. From 967c4b2e1cd984e9d242b7d4384f6362872a6087 Mon Sep 17 00:00:00 2001 From: Nick White <104782157+nicholasswhite@users.noreply.github.com> Date: Mon, 25 Jul 2022 15:31:08 -0400 Subject: [PATCH 067/109] fix MicrosoftDocs/windows-itpro-docs#10065 --- .../feature-availability.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/feature-availability.md b/windows/security/threat-protection/windows-defender-application-control/feature-availability.md index 4edab9bde3..751028a760 100644 --- a/windows/security/threat-protection/windows-defender-application-control/feature-availability.md +++ b/windows/security/threat-protection/windows-defender-application-control/feature-availability.md @@ -36,8 +36,8 @@ ms.topic: overview | Managed Installer (MI) | [Available on 1703+](./configure-authorized-apps-deployed-with-a-managed-installer.md) | Not available | | Reputation-Based intelligence | [Available on 1709+](./use-windows-defender-application-control-with-intelligent-security-graph.md) | Not available | | Multiple policy support | [Available on 1903+](./deploy-multiple-windows-defender-application-control-policies.md) | Not available | -| Path-based rules | [Available on 1903+.](./select-types-of-rules-to-create.md#more-information-about-filepath-rules) Exclusions are not supported. Runtime user-writeability checks enforced by default. | Available on Windows 8+. Exclusions are supported. No runtime user-writeability check. | +| Path-based rules | [Available on 1903+.](./select-types-of-rules-to-create.md#more-information-about-filepath-rules) Exclusions aren't supported. Runtime user-writeability checks enforced by default. | Available on Windows 8+. Exclusions are supported. No runtime user-writeability check. | | COM object configurability | [Available on 1903+](./allow-com-object-registration-in-windows-defender-application-control-policy.md) | Not available | | Packaged app rules | [Available on RS5+](./manage-packaged-apps-with-windows-defender-application-control.md) | Available on Windows 8+ | -| Enforceable file types |

    • Driver files: .sys
    • Executable files: .exe and .com
    • DLLs: .dll and .ocx
    • Windows Installer files: .msi, .mst, and .msp
    • Scripts: .ps1, .vbs, and .js
    • Packaged apps and packaged app installers: .appx
    |
    • Executable files: .exe and .com
    • [Optional] DLLs: .dll and .ocx
    • Windows Installer files: .msi, .mst, and .msp
    • Scripts: .ps1, .bat, .cmd, .vbs, and .js
    • Packaged apps and packaged app installers: .appx
    | +| Enforceable file types |
    • Driver files: .sys
    • Executable files: .exe and .com
    • DLLs: .dll and .ocx
    • Windows Installer files: .msi, .mst, and .msp
    • Scripts: .ps1, .vbs, and .js
    • Packaged apps and packaged app installers: .appx
    |
    • Executable files: .exe and .com
    • [Optional] DLLs: .dll, .rll and .ocx
    • Windows Installer files: .msi, .mst, and .msp
    • Scripts: .ps1, .bat, .cmd, .vbs, and .js
    • Packaged apps and packaged app installers: .appx
    | | Application ID (AppId) Tagging | [Available on 20H1+](./AppIdTagging/windows-defender-application-control-appid-tagging-guide.md) | Not available | From ab58d827dcca98b5f5d4eb10ad360e2d8c58ee31 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Mon, 25 Jul 2022 16:41:01 -0600 Subject: [PATCH 068/109] Update local-accounts.md Move comment to fix table. --- .../identity-protection/access-control/local-accounts.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/identity-protection/access-control/local-accounts.md b/windows/security/identity-protection/access-control/local-accounts.md index 55a2147186..b6149dcddb 100644 --- a/windows/security/identity-protection/access-control/local-accounts.md +++ b/windows/security/identity-protection/access-control/local-accounts.md @@ -246,10 +246,11 @@ For more information about UAC, see [User Account Control](/windows/access-prote The following table shows the Group Policy and registry settings that are used to enforce local account restrictions for remote access. + + |No.|Setting|Detailed Description| |--- |--- |--- | ||Policy location|Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options| - |1|Policy name|[User Account Control: Admin Approval Mode for the Built-in Administrator account](/windows/security/threat-protection/security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account)| ||Policy setting|Enabled| |2|Policy location|Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options| @@ -263,7 +264,6 @@ The following table shows the Group Policy and registry settings that are used t > [!NOTE] > You can also enforce the default for LocalAccountTokenFilterPolicy by using the custom ADMX in Security Templates. - #### To enforce local account restrictions for remote access 1. Start the **Group Policy Management** Console (GPMC). From d8d608165c7cf72b729962b98dbaad4a226eb956 Mon Sep 17 00:00:00 2001 From: Aaron Czechowski Date: Mon, 25 Jul 2022 20:38:48 -0400 Subject: [PATCH 069/109] revise link text --- .../deployment/deploy-wdac-policies-with-memcm.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md index e047eeb68a..287aba1869 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md +++ b/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-wdac-policies-with-memcm.md @@ -88,7 +88,7 @@ Configuration Manager doesn't remove policies once deployed. To stop enforcement For more information on using Configuration Manager's native WDAC policies, see [Windows Defender Application Control management with Configuration Manager](/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager). -The entire WDAC in Configuration Manager Lab Paper is available for download [here](https://download.microsoft.com/download/c/f/d/cfd6227c-8ec4-442d-8c50-825550d412f6/WDAC-Deploy-WDAC-using-MEMCM.pdf). +Download the entire [WDAC in Configuration Manager lab paper](https://download.microsoft.com/download/c/f/d/cfd6227c-8ec4-442d-8c50-825550d412f6/WDAC-Deploy-WDAC-using-MEMCM.pdf). ## Deploy custom WDAC policies using Packages/Programs or Task Sequences From ba4f86af1fab62e3dbaba5f40f788aa660a26599 Mon Sep 17 00:00:00 2001 From: Aaron Czechowski Date: Mon, 25 Jul 2022 21:31:29 -0400 Subject: [PATCH 070/109] remove contribute article --- .openpublishing.redirection.json | 5 ++ windows/whats-new/contribute-to-a-topic.md | 81 ---------------------- 2 files changed, 5 insertions(+), 81 deletions(-) delete mode 100644 windows/whats-new/contribute-to-a-topic.md diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 59cb04dbbd..798ab55b18 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -19584,6 +19584,11 @@ "source_path": "smb/index.md", "redirect_url": "https://techcommunity.microsoft.com/t5/small-and-medium-business-blog/bg-p/Microsoft365BusinessBlog", "redirect_document_id": false + }, + { + "source_path": "windows/whats-new/contribute-to-a-topic.md", + "redirect_url": "https://github.com/MicrosoftDocs/windows-itpro-docs/blob/public/CONTRIBUTING.md#editing-windows-it-professional-documentation", + "redirect_document_id": false } ] } diff --git a/windows/whats-new/contribute-to-a-topic.md b/windows/whats-new/contribute-to-a-topic.md deleted file mode 100644 index 77dfd79528..0000000000 --- a/windows/whats-new/contribute-to-a-topic.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: Edit an existing topic using the Edit link -description: Instructions about how to edit an existing topic by using the Edit link on docs.microsoft.com. -ms.prod: w10 -ms.date: 10/13/2017 -ms.reviewer: -manager: dansimp -ms.author: dansimp -author: dansimp -ms.topic: tutorial ---- - -# Editing existing Windows IT professional documentation -You can make suggestions and update existing, public content with just a GitHub account and a simple click of a link. You can use GitHub pull requests to edit the technical articles in the Windows IT libraries and then ask us to "pull" your changes into the published articles. - ->[!NOTE] ->At this time, you can only edit the English (en-us) content. - -Across the docs.microsoft.com site, if you see **Edit** in the right-hand corner of an article, you can suggest changes to it. You can specifically edit articles in the following libraries: - -- [Windows 10](/windows/windows-10) -- [Windows Server](/windows-server/) -- [Microsoft Edge](/microsoft-edge/deploy) -- [Surface](/surface) -- [Surface Hub](/surface-hub) -- [HoloLens](/hololens) -- [Microsoft Store](/microsoft-store) -- [Windows 10 for Education](/education/windows) -- [Windows 10 for SMB](/windows/smb) -- [Internet Explorer 11](/internet-explorer) -- [Microsoft Desktop Optimization Pack](/microsoft-desktop-optimization-pack) - - -**To edit a topic** - -1. Go to the article that you want to update, and then click **Edit**. - - ![GitHub Web, showing the Edit link.](images/contribute-link.png) - -2. Sign into (or sign up for) a GitHub account. - - You must have a GitHub account to get to the page that lets you edit a topic. - -3. Click the **Pencil** icon (in the red box) to edit the content. - - ![GitHub Web, showing the Pencil icon in the red box.](images/pencil-icon.png) - -4. Using Markdown language, make your changes to the topic. For info about how to edit content using Markdown, see: - - **If you're linked to the Microsoft organization in GitHub:** [Windows authoring guide](https://aka.ms/WindowsAuthoring) - - - **If you're external to Microsoft:** [Mastering Markdown](https://guides.github.com/features/mastering-markdown/) - -5. Make your suggested change, and then click **Preview Changes** to make sure it looks correct. - - ![GitHub Web, showing the Preview Changes tab.](images/preview-changes.png) - -6. When you’re done editing the topic, scroll to the bottom of the page, and then click **Propose file change**. - - ![GitHub Web, showing the Propose file change button.](images/propose-file-change.png) - - The **Comparing changes** screen shows the changes between your version of the article and the original content. - -7. On the **Comparing changes** screen, you’ll see if there are any problems with the file you’re checking in. (Occasionally there are merge conflicts, where you've edited the file one way, while someone else edited the same lines in the same file in a different way. Before you can propose your changes, you need to fix those conflicts.) - - If there are no problems, you’ll see the message, **Able to merge**. - - ![GitHub Web, showing the Comparing changes screen.](images/compare-changes.png) - -8. Click **Create pull request**. - -9. Enter a title and description to let us know what’s in the request. - -10. Scroll to the bottom of the page, and make sure that only your changed files are in this pull request. Otherwise, you could overwrite changes from other people. - -11. Click **Create pull request** again to actually submit your edits. - -12. If you aren't a Microsoft employee, you need to [sign a Microsoft Contribution Licensing Agreement (CLA)](https://cla.microsoft.com/) before updating or adding to any Microsoft repositories. A bot running in GitHub checks whether you've signed the CLA - if not, you'll be prompted, in the pull request, to sign it. - - If you've previously contributed to topics in the Microsoft repositories, congratulations! You've already completed this step. - -Next, the pull request is sent to one of our writers to review your edits for technical and editorial accuracy. If we have any suggestions or questions, we'll add them to the pull request where we can discuss them with you. If we accept your edits, you'll see your changes the next time the article is published. \ No newline at end of file From 6daf5333cfcc3a78f7e25a4d9aefc44d01d4eaa2 Mon Sep 17 00:00:00 2001 From: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com> Date: Tue, 26 Jul 2022 10:04:21 -0500 Subject: [PATCH 071/109] Update windows/security/information-protection/secure-the-windows-10-boot-process.md --- .../secure-the-windows-10-boot-process.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/information-protection/secure-the-windows-10-boot-process.md b/windows/security/information-protection/secure-the-windows-10-boot-process.md index 6cbc6425b8..002293ab72 100644 --- a/windows/security/information-protection/secure-the-windows-10-boot-process.md +++ b/windows/security/information-protection/secure-the-windows-10-boot-process.md @@ -101,7 +101,7 @@ To trust and boot operating systems, like Linux, and components signed by the UE Microsoft continues to collaborate with Linux and IHV ecosystem partners to design least privileged features to help you stay secure and opt-in trust for only the publishers and components you trust. -Like most mobile devices, Arm-based devices, such as the Microsoft Surface RT device, are designed to run only Windows 8.1. Therefore, Secure Boot can't be turned off, and you can't load a different OS. Fortunately, there's a large market of ARM processor devices designed to run other operating systems. +Like most mobile devices, ARM-based devices, such as the Microsoft Surface RT device, are designed to run only Windows 8.1. Therefore, Secure Boot can't be turned off, and you can't load a different OS. Fortunately, there's a large market of ARM processor devices designed to run other operating systems. ## Trusted Boot From 3ebe3b3d7d0543023bbc97176c61b7322a645d66 Mon Sep 17 00:00:00 2001 From: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com> Date: Tue, 26 Jul 2022 10:07:20 -0500 Subject: [PATCH 072/109] Update windows/security/information-protection/secure-the-windows-10-boot-process.md --- .../secure-the-windows-10-boot-process.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/information-protection/secure-the-windows-10-boot-process.md b/windows/security/information-protection/secure-the-windows-10-boot-process.md index 002293ab72..6cbc6425b8 100644 --- a/windows/security/information-protection/secure-the-windows-10-boot-process.md +++ b/windows/security/information-protection/secure-the-windows-10-boot-process.md @@ -101,7 +101,7 @@ To trust and boot operating systems, like Linux, and components signed by the UE Microsoft continues to collaborate with Linux and IHV ecosystem partners to design least privileged features to help you stay secure and opt-in trust for only the publishers and components you trust. -Like most mobile devices, ARM-based devices, such as the Microsoft Surface RT device, are designed to run only Windows 8.1. Therefore, Secure Boot can't be turned off, and you can't load a different OS. Fortunately, there's a large market of ARM processor devices designed to run other operating systems. +Like most mobile devices, Arm-based devices, such as the Microsoft Surface RT device, are designed to run only Windows 8.1. Therefore, Secure Boot can't be turned off, and you can't load a different OS. Fortunately, there's a large market of ARM processor devices designed to run other operating systems. ## Trusted Boot From 955657d3935f9309dc38c57892e0127083312a9b Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Tue, 26 Jul 2022 11:37:12 -0400 Subject: [PATCH 073/109] test contextual TOC --- windows/hub/breadcrumb/toc.yml | 3 +++ windows/security/TOC.yml | 2 ++ 2 files changed, 5 insertions(+) diff --git a/windows/hub/breadcrumb/toc.yml b/windows/hub/breadcrumb/toc.yml index 4b7d13efad..9c879979a8 100644 --- a/windows/hub/breadcrumb/toc.yml +++ b/windows/hub/breadcrumb/toc.yml @@ -55,3 +55,6 @@ items: - name: Windows Defender Firewall tocHref: /windows/security/threat-protection/windows-firewall/ topicHref: /windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security + - name: User security + tocHref: /windows/security/identity/ + topicHref: /windows/security/identity diff --git a/windows/security/TOC.yml b/windows/security/TOC.yml index 3c1cbaf40d..94380c945d 100644 --- a/windows/security/TOC.yml +++ b/windows/security/TOC.yml @@ -316,6 +316,8 @@ href: identity-protection/credential-guard/credential-guard-known-issues.md - name: Protect Remote Desktop credentials with Remote Credential Guard href: identity-protection/remote-credential-guard.md + - name: Configuring LSA Protection + href: /windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection - name: Technical support policy for lost or forgotten passwords href: identity-protection/password-support-policy.md - name: Access Control Overview From b6223f333c958df5b293e783156ffee9b55e80be Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 26 Jul 2022 11:59:47 -0400 Subject: [PATCH 074/109] Removed WHFB videos sections since the videos are not available anymore. PMs will re-record the videos. --- .../hello-for-business/hello-videos.md | 24 +++---------------- 1 file changed, 3 insertions(+), 21 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-videos.md b/windows/security/identity-protection/hello-for-business/hello-videos.md index ab3bdc0500..05c92d9ba2 100644 --- a/windows/security/identity-protection/hello-for-business/hello-videos.md +++ b/windows/security/identity-protection/hello-for-business/hello-videos.md @@ -8,8 +8,8 @@ manager: dansimp ms.collection: M365-identity-device-management ms.topic: article localizationpriority: medium -ms.date: 08/19/2018 -ms.reviewer: +ms.date: 07/26/2022 +ms.reviewer: paoloma --- # Windows Hello for Business Videos @@ -46,22 +46,4 @@ Watch Matthew Palko and Ravi Vennapusa explain how Windows Hello for Business pr Watch Matthew Palko and Ravi Vennapusa explain how Windows Hello for Business authentication works. -> [!VIDEO https://www.youtube.com/embed/WPmzoP_vMek] - -## Windows Hello for Business user enrollment experience - -The user experience for Windows Hello for Business occurs after user sign-in, after you deploy Windows Hello for Business policy settings to your environment. - -> [!VIDEO https://www.youtube.com/embed/FJqHPTZTpNM] - -
    - -> [!VIDEO https://www.youtube.com/embed/etXJsZb8Fso] - -## Windows Hello for Business forgotten PIN user experience - -If the user can sign-in with a password, they can reset their PIN by clicking the "I forgot my PIN" link in settings. Beginning with the Fall Creators Update, users can reset their PIN above the lock screen by clicking the "I forgot my PIN" link on the PIN credential provider. - -> [!VIDEO https://www.youtube.com/embed/KcVTq8lTlkI] - -For on-premises deployments, devices must be well connected to their on-premises network (domain controllers and/or certificate authority) to reset their PINs. Hybrid customers can on-board their Azure tenant to use the Windows Hello for Business PIN reset service to reset their PINs without access to their corporate network. +> [!VIDEO https://www.youtube.com/embed/WPmzoP_vMek] \ No newline at end of file From f2db77be543f1ffbda3ba6d45fe9ad7d50d7d60d Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Tue, 26 Jul 2022 12:09:01 -0400 Subject: [PATCH 075/109] fix breadcrumb --- windows/hub/breadcrumb/toc.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/hub/breadcrumb/toc.yml b/windows/hub/breadcrumb/toc.yml index 9c879979a8..de6b8cb43c 100644 --- a/windows/hub/breadcrumb/toc.yml +++ b/windows/hub/breadcrumb/toc.yml @@ -56,5 +56,5 @@ items: tocHref: /windows/security/threat-protection/windows-firewall/ topicHref: /windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security - name: User security - tocHref: /windows/security/identity/ + tocHref: /windows-server/security/credentials-protection-and-management/ topicHref: /windows/security/identity From 9df62cd3ee5bcf28e941e6236ef956aa63ce6f08 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Tue, 26 Jul 2022 12:15:56 -0400 Subject: [PATCH 076/109] test --- windows/hub/breadcrumb/toc.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/hub/breadcrumb/toc.yml b/windows/hub/breadcrumb/toc.yml index de6b8cb43c..59b0182af8 100644 --- a/windows/hub/breadcrumb/toc.yml +++ b/windows/hub/breadcrumb/toc.yml @@ -56,5 +56,5 @@ items: tocHref: /windows/security/threat-protection/windows-firewall/ topicHref: /windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security - name: User security - tocHref: /windows-server/security/credentials-protection-and-management/ + tocHref: /windows/client-management/mdm/ topicHref: /windows/security/identity From 8dad8bf157af112f2b68fb03a0f9c464e8f8f79e Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Tue, 26 Jul 2022 12:31:46 -0400 Subject: [PATCH 077/109] create separate breadcrumb for security --- windows/hub/breadcrumb/toc.yml | 5 +---- windows/security/breadcrumb/toc.yml | 12 ++++++++++++ 2 files changed, 13 insertions(+), 4 deletions(-) create mode 100644 windows/security/breadcrumb/toc.yml diff --git a/windows/hub/breadcrumb/toc.yml b/windows/hub/breadcrumb/toc.yml index 59b0182af8..8b8af8d182 100644 --- a/windows/hub/breadcrumb/toc.yml +++ b/windows/hub/breadcrumb/toc.yml @@ -54,7 +54,4 @@ items: topicHref: /windows/security/threat-protection/windows-defender-application-control/ - name: Windows Defender Firewall tocHref: /windows/security/threat-protection/windows-firewall/ - topicHref: /windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security - - name: User security - tocHref: /windows/client-management/mdm/ - topicHref: /windows/security/identity + topicHref: /windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security diff --git a/windows/security/breadcrumb/toc.yml b/windows/security/breadcrumb/toc.yml new file mode 100644 index 0000000000..10d7c57cd9 --- /dev/null +++ b/windows/security/breadcrumb/toc.yml @@ -0,0 +1,12 @@ +items: + - name: Docs + tocHref: / + topicHref: / + items: + - name: Windows + tocHref: /windows/ + topicHref: /windows/resources/ + items: + - name: User security + tocHref: /windows/client-management/mdm/ + topicHref: /windows/security/identity From c1c22551fdf382c03614d94d82b165b95a95e465 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Tue, 26 Jul 2022 13:07:55 -0400 Subject: [PATCH 078/109] test --- windows/security/breadcrumb/toc.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/breadcrumb/toc.yml b/windows/security/breadcrumb/toc.yml index 10d7c57cd9..8b90e519e4 100644 --- a/windows/security/breadcrumb/toc.yml +++ b/windows/security/breadcrumb/toc.yml @@ -7,6 +7,6 @@ items: tocHref: /windows/ topicHref: /windows/resources/ items: - - name: User security + - name: User security2 tocHref: /windows/client-management/mdm/ topicHref: /windows/security/identity From 08c59b17402de44ec18a8cc2f98dce300eeaefe3 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Tue, 26 Jul 2022 10:17:47 -0700 Subject: [PATCH 079/109] Removed duplicated line. --- .../windows-autopatch/overview/windows-autopatch-faq.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml b/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml index 311d9aee92..29d2234dde 100644 --- a/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml +++ b/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml @@ -79,8 +79,6 @@ sections: - Microsoft 365 Apps for enterprise updates: All devices registered for Windows Autopatch will receive updates from the Monthly Enterprise Channel. - Microsoft Edge: Windows Autopatch configures eligible devices to benefit from Microsoft Edge's progressive rollouts on the Stable channel and will provide support for issues with Microsoft Edge updates. - Microsoft Teams: Windows Autopatch allows eligible devices to benefit from the standard automatic update channels and will provide support for issues with Teams updates. - - question: What does Windows Autopatch do to ensure updates are done successfully? - answer: For information about the Microsoft Admin Center, see [Manage third-party app subscriptions for your organization](/microsoft-365/commerce/manage-saas-apps). - question: What does Windows Autopatch do to ensure updates are done successfully? answer: | For Windows quality updates, updates are applied to device in the Test ring first. The devices are evaluated, and then rolled out to the First, Fast then Broad rings. There's an evaluation period at each progression. This process is dependent on customer testing and verification of all updates during these rollout stages. The outcome is to ensure that registered devices are always up to date and disruption to business operations is minimized to free up your IT department from that ongoing task. From 488ed8130fd9da9d428a2bb031a75c0d047ecf1a Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 26 Jul 2022 13:26:28 -0400 Subject: [PATCH 080/109] removed missing links --- .../identity-protection/hello-for-business/hello-faq.yml | 4 ---- .../hello-for-business/hello-feature-pin-reset.md | 2 -- 2 files changed, 6 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-faq.yml b/windows/security/identity-protection/hello-for-business/hello-faq.yml index 12d4f1203e..08bcf8dfa9 100644 --- a/windows/security/identity-protection/hello-for-business/hello-faq.yml +++ b/windows/security/identity-protection/hello-for-business/hello-faq.yml @@ -101,14 +101,10 @@ sections: answer: | The user experience for Windows Hello for Business occurs after the user signs in, after you deploy Windows Hello for Business policy settings to your environment. - [Windows Hello for Business user enrollment experience](hello-videos.md#windows-hello-for-business-user-enrollment-experience) - - question: What happens when a user forgets their PIN? answer: | If the user can sign in with a password, they can reset their PIN by selecting the "I forgot my PIN" link in Settings. Beginning with Windows 10 1709, users can reset their PIN above the lock screen by selecting the "I forgot my PIN" link on the PIN credential provider. - [Windows Hello for Business forgotten PIN user experience](hello-videos.md#windows-hello-for-business-forgotten-pin-user-experience) - For on-premises deployments, devices must be well-connected to their on-premises network (domain controllers and/or certificate authority) to reset their PINs. Hybrid customers can onboard their Azure tenant to use the Windows Hello for Business PIN reset service to reset their PINs. Non-destructive PIN reset works without access to the corporate network. Destructive PIN reset requires access to the corporate network. For more details about destructive and non-destructive PIN reset, see [PIN reset](/windows/security/identity-protection/hello-for-business/hello-feature-pin-reset). - question: What URLs do I need to allow for a hybrid deployment? diff --git a/windows/security/identity-protection/hello-for-business/hello-feature-pin-reset.md b/windows/security/identity-protection/hello-for-business/hello-feature-pin-reset.md index 2ee149c236..7633011c29 100644 --- a/windows/security/identity-protection/hello-for-business/hello-feature-pin-reset.md +++ b/windows/security/identity-protection/hello-for-business/hello-feature-pin-reset.md @@ -65,8 +65,6 @@ For Hybrid Azure AD-joined devices: You may find that PIN reset from settings only works post login, and that the "lock screen" PIN reset function will not work if you have any matching limitation of SSPR password reset from the lock screen. For more information, see [Enable Azure Active Directory self-service password reset at the Windows sign-in screen - General ](/azure/active-directory/authentication/howto-sspr-windows#general-limitations). -Visit the [Windows Hello for Business Videos](./hello-videos.md) page and watch [Windows Hello for Business forgotten PIN user experience](./hello-videos.md#windows-hello-for-business-forgotten-pin-user-experience). - ## Non-Destructive PIN reset **Requirements:** From 061651f447650adf534aab101500cf32b5abc7ea Mon Sep 17 00:00:00 2001 From: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com> Date: Tue, 26 Jul 2022 12:37:59 -0500 Subject: [PATCH 081/109] Update hello-faq.yml --- .../identity-protection/hello-for-business/hello-faq.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-faq.yml b/windows/security/identity-protection/hello-for-business/hello-faq.yml index 08bcf8dfa9..2f77d6ba0e 100644 --- a/windows/security/identity-protection/hello-for-business/hello-faq.yml +++ b/windows/security/identity-protection/hello-for-business/hello-faq.yml @@ -63,7 +63,7 @@ sections: - question: How does Windows Hello for Business work with Azure AD registered devices? answer: | - A user will be prompted to set-up a Windows Hello for Business key on an Azure AD registered devices if the feature is enabled by policy. If the user has an existing Windows Hello container, the Windows Hello for Business key will be enrolled in that container and will be protected using their exiting gestures. + A user will be prompted to set up a Windows Hello for Business key on an Azure AD registered devices if the feature is enabled by policy. If the user has an existing Windows Hello container, the Windows Hello for Business key will be enrolled in that container and will be protected using their exiting gestures. If a user has signed into their Azure AD registered device with Windows Hello, their Windows Hello for Business key will be used to authenticate the user's work identity when they try to use Azure AD resources. The Windows Hello for Business key meets Azure AD multi-factor authentication (MFA) requirements and reduces the number of MFA prompts users will see when accessing resources. @@ -79,7 +79,7 @@ sections: answer: | It's currently possible to set a convenience PIN on Azure Active Directory Joined or Hybrid Active Directory Joined devices. Convenience PIN isn't supported for Azure Active Directory user accounts (synchronized identities included). It's only supported for on-premises Domain Joined users and local account users. - - question: Can I use an external Windows Hello compatible camera when my computer has a built in Windows Hello compatible camera? + - question: Can I use an external Windows Hello compatible camera when my computer has a built-in Windows Hello compatible camera? answer: | Yes. Starting with Windows 10, version 21H1 an external Windows Hello compatible camera can be used if a device already supports an internal Windows Hello camera. When both cameras are present, the external camera is used for face authentication. For more information, see [IT tools to support Windows 10, version 21H1](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/it-tools-to-support-windows-10-version-21h1/ba-p/2365103). However, using external Hello cameras and accessories is restricted if ESS is enabled, please see [Windows Hello Enhanced Sign-in Security](https://docs.microsoft.com/en-us/windows-hardware/design/device-experiences/windows-hello-enhanced-sign-in-security#pluggableperipheral-biometric-sensors). From 1ea0374fefbb982192b6ff4b353b047c3231bd58 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Tue, 26 Jul 2022 13:49:41 -0400 Subject: [PATCH 082/109] final changes --- windows/security/TOC.yml | 2 +- windows/security/breadcrumb/toc.yml | 22 +++++++++++----------- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/windows/security/TOC.yml b/windows/security/TOC.yml index 94380c945d..aa38fc4f08 100644 --- a/windows/security/TOC.yml +++ b/windows/security/TOC.yml @@ -317,7 +317,7 @@ - name: Protect Remote Desktop credentials with Remote Credential Guard href: identity-protection/remote-credential-guard.md - name: Configuring LSA Protection - href: /windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection + href: /windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection?toc=/windows/security/toc.json&bc=/windows/security/breadcrumb/toc.json - name: Technical support policy for lost or forgotten passwords href: identity-protection/password-support-policy.md - name: Access Control Overview diff --git a/windows/security/breadcrumb/toc.yml b/windows/security/breadcrumb/toc.yml index 8b90e519e4..c7cf229b3f 100644 --- a/windows/security/breadcrumb/toc.yml +++ b/windows/security/breadcrumb/toc.yml @@ -1,12 +1,12 @@ items: - - name: Docs - tocHref: / - topicHref: / - items: - - name: Windows - tocHref: /windows/ - topicHref: /windows/resources/ - items: - - name: User security2 - tocHref: /windows/client-management/mdm/ - topicHref: /windows/security/identity +- name: Docs + tocHref: / + topicHref: / + items: + - name: Windows + tocHref: /windows/ + topicHref: /windows/resources/ + items: + - name: User security + tocHref: /windows-server/security/credentials-protection-and-management/ + topicHref: /windows/security/identity From 8abb876b88df23098ddf8e1c0dab8cb9229635e4 Mon Sep 17 00:00:00 2001 From: itsrlyAria <82474610+itsrlyAria@users.noreply.github.com> Date: Wed, 27 Jul 2022 02:19:33 -0700 Subject: [PATCH 083/109] Update waas-wu-settings.md Added Microsoft Store for Business to the list of things that stop working if you prevent all connection to Windows Updates. --- windows/deployment/update/waas-wu-settings.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/update/waas-wu-settings.md b/windows/deployment/update/waas-wu-settings.md index f198383a31..fd23bbc902 100644 --- a/windows/deployment/update/waas-wu-settings.md +++ b/windows/deployment/update/waas-wu-settings.md @@ -98,9 +98,9 @@ By enabling the Group Policy setting under **Computer Configuration\Administrati ### Do not connect to any Windows Update Internet locations -Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like Microsoft Update or the Microsoft Store. +Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like Microsoft Update, the Microsoft Store, or the Microsoft Store for Business. -Use **Computer Configuration\Administrative Templates\Windows Components\Windows update\Do not connect to any Windows Update Internet locations** to enable this policy. When enabled, this policy will disable the functionality described above, and may cause connection to public services such as the Microsoft Store, Windows Update for Business and Delivery Optimization to stop working. +Use **Computer Configuration\Administrative Templates\Windows Components\Windows update\Do not connect to any Windows Update Internet locations** to enable this policy. When enabled, this policy will disable the functionality described above, and may cause connection to public services such as the Microsoft Store, Microsoft Store for Business, Windows Update for Business and Delivery Optimization to stop working. >[!NOTE] >This policy applies only when the device is configured to connect to an intranet update service using the "Specify intranet Microsoft update service location" policy. From c82f421232ba2b40969ab47cfddfb07a0f92c143 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Wed, 27 Jul 2022 11:50:53 -0700 Subject: [PATCH 084/109] Adding Harman's corrections. --- .../operate/windows-autopatch-unenroll-tenant.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/windows/deployment/windows-autopatch/operate/windows-autopatch-unenroll-tenant.md b/windows/deployment/windows-autopatch/operate/windows-autopatch-unenroll-tenant.md index 03abc5724f..7ff238e112 100644 --- a/windows/deployment/windows-autopatch/operate/windows-autopatch-unenroll-tenant.md +++ b/windows/deployment/windows-autopatch/operate/windows-autopatch-unenroll-tenant.md @@ -1,7 +1,7 @@ --- title: Unenroll your tenant description: This article explains what unenrollment means for your organization and what actions you must take. -ms.date: 07/11/2022 +ms.date: 07/27/2022 ms.prod: w11 ms.technology: windows ms.topic: how-to @@ -22,7 +22,7 @@ If you're looking to unenroll your tenant from Windows Autopatch, this article d Unenrolling from Windows Autopatch requires manual actions from both you and from the Windows Autopatch Service Engineering Team. The Windows Autopatch Service Engineering Team will: - Remove Windows Autopatch access to your tenant. -- Deregister your devices from the Windows Autopatch service. Deregistering your devices from Windows Autopatch won't remove your devices from Intune, Azure AD or Configuration Manager. The Windows Autopatch Service Engineering Team follows the same process and principles as laid out in Deregister a device. +- Deregister your devices from the Windows Autopatch service. Deregistering your devices from Windows Autopatch won't remove your devices from Intune, Azure AD or Configuration Manager. The Windows Autopatch Service Engineering Team follows the same process and principles as laid out in [Deregister a device](/windows/deployment/windows-autopatch/operate/windows-autopatch-deregister-devices). - Delete all data that we've stored in the Windows Autopatch data storage. > [!NOTE] @@ -33,9 +33,7 @@ Unenrolling from Windows Autopatch requires manual actions from both you and fro | Responsibility | Description | | ----- | ----- | | Windows Autopatch data | Windows Autopatch will delete user data that is within the Windows Autopatch service. We won’t make changes to any other data. For more information about how data is used in Windows Autopatch, see [Privacy](../references/windows-autopatch-privacy.md). | -| Windows Autopatch cloud service accounts | Windows Autopatch will remove the cloud service accounts created during the enrollment process. The accounts are:
    • MsAdmin
    • MsAdminInt
    • MsTest
    | -| Conditional access policy | Windows Autopatch will remove the Modern Workplace – Secure Workstation conditional access policy. | -| Microsoft Endpoint Manager roles | Windows Autopatch will remove the Modern Workplace Intune Admin role. | +| Deregistering devices | Windows Autopatch will deregister all devices previously registered with the service. Only the Windows Autopatch device record will be deleted. We will not delete Microsoft Intune and/or Azure Active Directory device records. For more information, see [Deregister a device](/windows/deployment/windows-autopatch/operate/windows-autopatch-deregister-devices). | ## Your responsibilities after unenrolling your tenant @@ -43,6 +41,9 @@ Unenrolling from Windows Autopatch requires manual actions from both you and fro | ----- | ----- | | Updates | After the Windows Autopatch service is unenrolled, we’ll no longer provide updates to your devices. You must ensure that your devices continue to receive updates through your own policies to ensure they're secure and up to date. | | Optional Windows Autopatch configuration | Windows Autopatch won’t remove the configuration policies or groups used to enable updates on your devices. You're responsible for these policies following tenant unenrollment. If you don’t wish to use these policies for your devices after unenrollment, you may safely delete them. | +| Windows Autopatch cloud service accounts | After unenrollment, you may safely remove the cloud service accounts created during the enrollment process. The accounts are:
    • MsAdmin
    • MsAdminInt
    • MsTest
    | +| Conditional access policy | After unenrollment, you may safely remove the **Modern Workplace – Secure Workstation** conditional access policy. | +| Microsoft Endpoint Manager roles | After unenrollment, you may safely remove the Modern Workplace Intune Admin role. | ## Unenroll from Windows Autopatch From 643de1c3ab5cecfe5f8162be7da5abd1fe12ebc7 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Wed, 27 Jul 2022 14:59:49 -0700 Subject: [PATCH 085/109] New device registration overview article with workflow diagrams. --- windows/deployment/windows-autopatch/TOC.yml | 9 +- ...-autopatch-device-registration-overview.md | 114 ++++++++++++++++++ ...autopatch-device-registration-overview.png | Bin 0 -> 34390 bytes ...h-device-registration-workflow-diagram.png | Bin 0 -> 572636 bytes ...ch-prerequisite-check-workflow-diagram.png | Bin 0 -> 324531 bytes 5 files changed, 121 insertions(+), 2 deletions(-) create mode 100644 windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md create mode 100644 windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-overview.png create mode 100644 windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-workflow-diagram.png create mode 100644 windows/deployment/windows-autopatch/media/windows-autopatch-prerequisite-check-workflow-diagram.png diff --git a/windows/deployment/windows-autopatch/TOC.yml b/windows/deployment/windows-autopatch/TOC.yml index c56b83ed47..c6e175c270 100644 --- a/windows/deployment/windows-autopatch/TOC.yml +++ b/windows/deployment/windows-autopatch/TOC.yml @@ -25,8 +25,13 @@ items: - name: Add and verify admin contacts href: deploy/windows-autopatch-admin-contacts.md - - name: Register your devices - href: deploy/windows-autopatch-register-devices.md + - name: Device registration + href: + items: + - name: Device registration overview + href: deploy/windows-autopatch-device-registration-overview.md + - name: Register your devices + href: deploy/windows-autopatch-register-devices.md - name: Operate href: operate/index.md items: diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md new file mode 100644 index 0000000000..a837e4d35b --- /dev/null +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -0,0 +1,114 @@ +--- +title: Device registration overview +description: This article details how to register devices in Autopatch +ms.date: 07/28/2022 +ms.prod: w11 +ms.technology: windows +ms.topic: how-to +ms.localizationpriority: medium +author: tiaraquan +ms.author: tiaraquan +manager: dougeby +msreviewer: andredm7 +--- + +# Device registration overview + +Windows Autopatch must register your existing devices into its service to manage update deployments on your behalf. + +The Windows Autopatch device registration process is transparent for end-users because it doesn’t require devices to be reset. + +The overall device registration process is: + +:::image type="content" source="../media/windows-autopatch-device-registration-overview.png" alt-text="Overview of the device registration process" lightbox="../media/windows-autopatch-device-registration-overview.png"::: + +1. IT admin identifies devices to be managed by Windows Autopatch and adds them into the **Windows Autopatch Device Registration** Azure Active Directory (AD) group. +1. Windows Autopatch then: + 1. Performs device readiness prior registration (prerequisite checks). + 1. Calculates the deployment ring distribution. + 1. Assigns devices to one of the deployment rings based on the previous calculation. + 1. Assigns devices to other Azure AD groups required for management. + 1. Marks devices as active for management so it can apply its update deployment policies. +1. IT admin then monitors the device registration trends and the update deployment reports. + +For more information about the device registration workflow, see the [Detailed device registration workflow diagram](#detailed-device-registration-workflow-diagram) section for more technical details behind the Windows Autopatch device registration process. + +## Detailed device registration workflow diagram + +See the following detailed workflow diagram. The diagram covers the Windows Autopatch device registration process: + +:::image type="content" source="../media/windows-autopatch-device-registration-workflow-diagram.png" alt-text="Detailed device registration workflow diagram" lightbox="../media/windows-autopatch-device-registration-workflow-diagram.png"::: + +1. IT admin identifies devices to be managed by the Windows Autopatch service. +2. IT admin adds devices through direct membership or nests other Azure AD assigned or dynamic groups into the **Windows Autopatch Device Registration** Azure AD assigned group. +3. The Windows Autopatch Discover Devices function hourly discovers devices previously added by the IT admin into the **Windows Autopatch Device Registration** Azure AD assigned group in **step #2**. The Azure AD device ID is used by Windows Autopatch to query device attributes in both Microsoft Endpoint Manager-Intune and Azure AD when registering devices into its service. + 1. Once devices are discovered from the Azure AD group, the same function gathers additional device attributes and saves it into its memory during the discovery operation. The following device attributes are gathered from Azure AD in this step: + 1. AzureADDeviceID + 2. OperatingSystem + 3. DisplayName (Device name) + 4. AccountEnabled + 5. RegistrationDateTime + 6. ApproximateLastSignInDateTime + 2. In this same step, the Windows Autopatch discover devices function calls another function, the device prerequisite check function. The device prerequisite check function evaluates software-based device-level prerequisites to comply with Windows Autopatch device readiness requirements prior to registration. +4. The Windows Autopatch prerequisite function makes an Intune Graph API call to sequentially validate device readiness attributes required for the registration process. For detailed information, see the [Detailed prerequisite check workflow diagram](#detailed-prerequisite-check-workflow-diagram) section. The service checks the following device readiness attributes, and/or prerequisites: + 1. **Serial number, model, and manufacturer.** + 1. Checks if the serial number already exists in the Windows Autopatch’s managed device database. + 2. **If the device is Intune-managed or not**. + 1. Windows Autopatch looks to see if the Azure AD device ID has an Intune device ID associated with it. + 1. If **yes**, it means this device is enrolled into Intune. + 2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service. + 2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Azure AD device attributes gathered and saved to its memory in **step 3a**. + 1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the Prerequisite failed status, then added to the Not ready tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune. + 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with anymore. To remediate, clean up any stale Azure AD records from your tenant. + 3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days. + 3. **If the device is a Windows device or not**. + 1. If it’s a Windows device, Windows Autopatch evaluates the following requirements: + 1. Whether the **Windows OS version** is **greater or equal to 10**. + 2. The **OS build** is **greater or equal to 1809**. + 3. The **architecture** is **x64**. + 4. **Windows Autopatch checks the Windows SKU family**. The SKU must be either: + 1. **Enterprise** + 2. **Pro** + 3. **Pro Workstation** + 5. If the device meets the operating system requirements, Windows Autopatch checks whether the device is either: + 1. **Only managed by Intune** + 1. If the device is only managed by Intune, the device is marked as **passed all prerequisites**. + 2. **Co-managed by both Configuration Manager and Intune** + 1. If the device is co-managed by both Configuration Manager and Intune, an additional prerequisite check is evaluated to determine if the device satisfies the co-management-enabled workloads required by Windows Autopatch to manage devices in a co-managed state. + 1. The required co-management workloads evaluated in this step are: + 1. **Windows Updates Policies** + 2. **Device Configuration** + 3. **Office Click to Run** + 2. If Windows Autopatch determines that one of these workloads isn’t enabled on the device, the service marks the device as **Prerequisite failed** and moves the device to the **Not Ready** tab. +5. Once the device passes all prerequisites described in **step #4**, Windows Autopatch starts its deployment ring assignment calculation. The following logic is used to calculate the Windows Autopatch deployment ring assignment: + 1. If the Windows Autopatch tenant’s existing managed device size is **≤ 200**, the deployment ring assignment is **First (5%)**, **Fast (15%)**, remaining devices go to the **Broad ring (80%)**. + 2. If the Windows Autopatch tenant’s existing managed device size is **>200**, the deployment ring assignment will be **First (1%)**, **Fast (9%)**, remaining devices go to the **Broad ring (90%)**. +6. Once the deployment ring calculation is done, Windows Autopatch assigns devices to one of the following deployment ring groups: + 1. **Modern Workplace Devices-Windows Autopatch-First** + 1. The Windows Autopatch device registration process doesn’t automatically assign devices to the Test ring represented by the Azure AD group (Modern Workplace Devices-Windows Autopatch-First). It’s important that you assign devices to the Test ring to validate the update deployments before the updates are deployed to a broader population of devices. + 2. **Modern Workplace Devices-Windows Autopatch-Fast** + 3. **Modern Workplace Devices-Windows Autopatch-Broad** +7. Windows Autopatch also assigns devices to the following Azure AD groups: + 1. **Modern Workplace Devices - All** + 1. This group has all devices managed by Windows Autopatch. + 2. **Modern Workplace Devices Dynamic - Windows 10** + 1. This group has all devices managed by Windows Autopatch and that have Windows 10 installed. + 3. M**odern Workplace Devices Dynamic - Windows 11** + 1. This group has all devices managed by Windows Autopatch and that have Windows 11 installed. + 4. **Modern Workplace Devices - Virtual Machine** + 1. This group has all virtual devices managed by Windows Autopatch. +8. In post-device registration, three actions occur: + 1. Windows Autopatch adds devices to its managed database. + 2. Flags devices as **Active** in the **Ready** tab. + 3. The Azure AD device ID of the device successfully registered is added into the Microsoft Cloud Managed Desktop Extension’s allowlist. Windows Autopatch installs the Microsoft Cloud Managed Desktop Extension agent once devices are registered, so the agent can communicate back to the Microsoft Cloud Managed Desktop Extension service. + 1. The agent is the **Modern Workplace - Autopatch Client setup** PowerShell script that was created during the Windows Autopatch tenant enrollment process. The script is executed once devices are successfully registered into the Windows Autopatch service. +9. IT admins review the device registration status in both the **Ready** and **Not ready** tabs. + 1. If the device was successfully registered, it shows up in the **Ready** tab. + 2. If not, in the **Not ready** tab. +10. This is the end of the Windows Autopatch device registration workflow. + +## Detailed prerequisite check workflow diagram + +As described in **step #4** in the previous [Detailed device registration workflow diagram](#detailed-device-registration-workflow-diagram), the following diagram is a visual representation of the prerequisite construct for the Windows Autopatch device registration process. The prerequisite checks are sequentially performed. + +:::image type="content" source="../media/windows-autopatch-prerequisite-check-workflow-diagram.png" alt-text="Detailed prerequisite check workflow diagram" lightbox="../media/windows-autopatch-prerequisite-check-workflow-diagram.png"::: diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-overview.png b/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-overview.png new file mode 100644 index 0000000000000000000000000000000000000000..df6d9ac790aa3ab8bd6712f8e4572c0d36617279 GIT binary patch literal 34390 zcmdSAhd-77`v-nYNLD4;)Voj#WhSeIWG9q$WM}WqF+x%lA-giO_jV3h*(Bpw$DYTr z9h~*MkM#Neet*JGj~@3K_w{;R`+8p2>ptNcYKnAc+0Ft0K&SNN@iPFR0AHSxICBcT zC>yyZ-ne?Bm-66*e07BN3 z9zS^QX|z5`vwO|lZwcCqF#Hu-MyA$#CHZn$9g$8!#^l_j!KU{^115#0gOPj`?}I4* z(Ccr{K0N(ikTUrC&6_uad8Z%Zs6I@GgrDiYJxzN(cp`M%K)9J!Bw&I=k>y1UG3-!w zr>9wK2>jCq|80yMrXp7g!9VoU%IcDq;Sk)AKw=OGkh~92l3sLEoVrcA8VjBaAS1nS z2?S_K*Do}ujY-!=gUbLp>BZtHG8WSHHuITA(lwyw|KCfnd|n@~k|P|<&72K5b1WLm zXS?xAyV2r6T3WO7By9vd&;+K+Ul00WCKV|uFB~hxSmPEzoad9fLQYP7th(FRxdJ*G z?*|>LjrJ)=KnN}E-IH&WfJ?%+jgR%!_|=TO_+ud1m1AuNN3)aeJJxx?16C&R&3j43 zW0O#3UIu7bS$5t7w8m4fIlcxytQJnGuo*#Dj2KaIx@s8GJZ8*Kh`c-d*0CXaajdqD z9s%nu^euvDe?8@P5Cq&ZGwv2RbvuAdztR>VSci&cf7mNW#LXt%B92~gNBUu?xI7!} zQxq`d#WEf>2eT2)8Ha-lfPq7p?Mq8t*htY$jh@ltRrpA&4Dw-uC}`X#-A2}m;Ib-X zGe5FZy(iag7r!cS)M&k!>3ct>gjY2LZ@DdQtr9wW~+yW&Gxnn%$+r=+d3rWlJ z>2ZiPU8Wp`20vSpLKe@FvD}BhOvLwx$zCknFm8G=$a9!GXm7n-_cfBrSieCRel(;7 zJ9XN4#Z%t{l0?SxY*B)VL2mt-g0G@kDqYX zCKksud<1c9qIeaVBFZauI3KglbV=Z*eMpH-spr-#bHlQ{I9{^PtG8Wt|BlbuspYM+ z^Wr5*IR$eHTU4Giu) z*u1Ebn=kzGc_YuXin47<2t7{Gr`c8*n^3AeU)eR9)PL2wVw>#6uf{LjpiASk0xh;v zqEt114_ZRes#~8?zecm_7X%yzAU%hX9`((X>01r&>8j_vR4%-`HT5>`hoqm`ilzW2 z$5!97^t$TqP;qf?Uge8|`@$~&(N`fxnm$uEvT>}Hdm)*GVCV{X3(aC@DD(X96tgaD1=O$>x=)hUmVG%L+Q8>8ZKKdskV};xHS6TJ# zr))NUP^%=q*Fix`|FtqCzJ>VqWSw5%bU-=VYKsl%wfv4>99e)KghBgh5wYAu$~0s4 zf7sLpxt$?HXZ^%5PNp5W+K=N^iZY6m&n*hfIt4Y0_rAC`2lYP7Q@wZ`cn<)|ejo9% zovlo|LA&B4A1&$BuE_Ux@6egyvPlAbQl(K^YoT=Px46ux5)%ao^p;z*tsQ=Lch}~0 z)!EoWkM2qt9cofn25|kCD(7YXzQ8V;5k(Q6_T0&z3v1>AnL(}nxB_+6Hjg@!=Yw=M$whHa0Yv_KJ{}Jk7CmNUT}&BW+1c-F7tYup2mZGT)8xv>U%O2lLGPP~i z%u-@#Z`25>;W#4FloO~vAXJ?ah0WvAy`tmCQhRe^h0vMl_M8==FA>=<>$`=Etc54h zFJO7|Q(y`f*YD8zXm*r?P(c@L@oV%8wyK8uYx3ovBUz^DDnPz0qwFD@_~)RH%CSSW z!_#oq>05`|r)&2wMU}Pp@+zHsiq6q@E6P-kZ(~S&ZzGUzU0KzzZnrjEP!^s(+Ujt;a1rzn>5)a zW%gUnj}lTfyYy`PfoV-&!@TpXN8Ani#%KM?5s*QjcQYkGv8B60i&%5PY5NUB$`=>Csj>yMdv|frI z9<0M;^~I;|vJV`kx6tfnZ;qNq9iCk(#KjIc3~@L%l5M?;q4qhCnpd*Kd`MdnC9B58 z^!SDFbZ~ip4npb+#}tO&7;F*5T)F1;(zder9V-HHOVk3gX*T&TO}T^W!-6a(x~oH6 zW4m)+(D%7e&(!3+;A2r}#s8Q4dRK}F&N>}8xA33>#X~xpS`|A(NmBYGR{$t)pXRz& zdR4hj=~3Ur150<4rcu%GJ3Nmx-NltCTV}OvueiskK7Y|^$e;eIvx6@!AK}dX1O-dH zqAMMp$_vCpOVd-8w*?XmhvtqBqEzA6<6=a6=W=RyRtzH`Al_Pm4P z{GfvNQ97D?YIv8#V|6o;)P3-AcMU?URj@@o{+5KQGMi1hCUrqTa=u4_d8_?qY7gZP z^Wj0=wwU6cWbNCJgtI&lL%#~)W_*!sX7RqIgbY-!l0}!_TNEds9%FpnDT*H!iIu&j zRAV3-7%76J`L&>GnS?6mgKH<21Wn`Tg!c52M>+xzMAn?Q``i=+CR!U@pN}sHnspL1 zwzVtj+6P^9v%cnC%*TzkKJBQ;ty2CqTG0Mj`H^A{RE?G7?GOF~$XQNtAHbI7g`S4O zDI}EKujx7evO&(ZYM~-K9w({3=97Kj|DU~ZK;_<_WJNBo3@HB^BUpTNj~)*k-7=`Y zZM2x9StN&_4`*keJc_BvX6;MHy0k}Q9eL97;TqlsXxFxTYf*q;U!>g9Ob@r`&nYiG@WARLj)VI5u!_8()eO}v-FBHyv z#$TyZ@qzJRt+&rn7`84}Rcz}k3+g;A9Qthd{i|V{IIH(#PUE9vb1;DBxIg+;qx32~ zD5>=7K=dOc_D?nmY@hi%Mxj*N(i+cHxmp!In#d`e@{KI;K7;ff4B*jQkM+4#%Y!xT z5)hVr`>xIo7xdNYh4&p3zgJXn_j>h4662F@HR%kc`CNFNG2JnC6Jg>}Dec2Q^PRsKjdeCf^%I z>Wp)Zar$mHZNYh;UXrbhU#y(W5lhaJn-?teg{Y!m^lRG^O8k8OxO^725i^g!ZWUjm z8p@@aH*|qyyg(4xv7BMovaa55V(`DMGWNRl9h1A({_SbhlXBcg-DV9bMK#e2GHdx| zw#JE^LV`y1qiSEuC1aqLtGF92Yb&pAaNX|$s|-#eu)Ld;!fJw_cabCb(6;#~k>wl7 zKIocCHa!#x8hr3~4#N^AJU}q#=_Xz=7=7&^#9=r6$H=OvCR2UiplKIJbqHTc=Qm2 zu;sa)yHWO~oOcj9>~&%0h5c0noO_hUSIA9ogLNoC=lq4EU#B+5L9FEH7nbdw`ZkFp z^>)?r_;TdfakZiaLCO8RGt_=&?f9`*CGNPgw6{{L)mxH}kqRE7=Sj*YBlRSD@=um; z(D|y%9-7IOJ*SsFn5Ge|4%l5ItrU6+go^_nCx|_frtu-ALeUAPe=SO46)%5+wpU0l zx_j}Y1GscdsCYs+Mol8zIDzS}1&#?xG6Dc)X3sI4cpGDo}6fNhckI>lG3MoFKYAX5cCb z!!5I&^cs`Lyk?(lx$>NZv}=P;x{{IOEzh59dGGI*e;d2t-^YSrhi+Kq-<09x1~I3%dvl5j1cKoE7p@$xhP12sGcxzblmU^|06U!CInH~ zu~<>Zgk&d#sU&vNU;iT{wN398PAs|NMj}jnbV9gsO!&_rWT#1l)F*_Y$9^+*LddE@ zB3wOj0rMv$!kqIbI|d%JD)^6(nY5$c39GDTB*Lr{8O?J@gkLV45R#FMWy3i5CHY7 z@yQ7%SAh0kjc?BfSUz(2NkMbTcliIku~lQevd=jJ`Nv}%jGk_tsRuuJ6g`|l_p;WlDe1ScFhHr!d@ehbj< z(vaQNO%7yT?-MxXC_8ll=zoJ69;yr*D{o`8t6YKKO<8Z#;buMifnO(IV=-+x7z`!j zr>CbirO8Fc()3SH`^F+KxR)m>dDlu=b7Q8neAN2w$pCG$q8XGujz zi;so+dc?t&H)8pbrJ3(RP$u>t3Zg;*Q~rp2>h+ ztSxoA$+w<#o`Vp_X8I1yxUAZ{cw1a#`mjM8j2F?D6-2eotl|4z2EVs966JjcNO=ed z8ncdy2NPyyS=Jf2$nHWas@`}PV}6q2=lopNnv@x|{=n^HGM;S1tms8tBD42sP`x zW%kiSi8ua8}ABahEFOR*E1?fYz2mX_}ot<0zA!bsvk5afW@>#dn2P^+NNe#)^#K)HkD$vL^5KqCN&yoeuC?tWjq6y}HOgI$>v=Kr)B;%ls{| z0rQ^XK3VK?DSEGdNk*OFTYD+b+QaSeuj`d|OLMVK2(ba2(;u*Dq8XO1x)We-Q{{7pj(9dx)sQfDDw8AJ)+b0SQ!K1R+!HhM*!Su7Di1fKIoGdi3{CBH{Z8Ipi~$iZ0skf% zqhgC5HoG^?H0@SU`f~w0JTiSu^*qr|k1Dy_WyBH^Ky}oZu;+!)Ft0jD8}zqnj8~;c z$=;iaj76f&s{%pQc+k9#T2At=J4)#DZ9{*b=^}s*0s>k&*1P;2AEWb&Z}?y82zyxC zU1C$1$+I?Hb;(y;Y5Tsofil;xO(*i*h$+J9X%nu1jRwrr0TB%Bf9?@f^;pc+Y{VmJEQL5iK_q?nfaPzm~U^+2z0*1Bw8sG0zMFGh| z9x7KU9H_To_LGL3GU$~3!gFpWcG2a&V0v1Nvs<1O_%hluEA+hG9&=W_(j>_#M*8FE zG;gZCvT|h};aoI6p-z)Z#&VUJ=V{>dwDqj%w>!^CCFSS?KzsQCQ23r!+VlVQK9!Qy zbM&OFk!Ed_T(?gu*Xik%Pk~|Y{uPqyOJ>ugo`!^Lz*#vBtEcDx$ZS9|mj97?gJf_1 zN9Jxe-E@LY9s>5KSUp+(N5=k;k_-4B+2Y4QY~=sQG|i@sPO2S9#>QF={~wwDeM
    za32-af6jI;M*u}`q5K(?#5*89hFl7?l<0p)%79k0lvytehxQsi}>W%ljSe> z$cv{eFzIh>h$|K}jSz#ql-tz6?TaIYW5#3$5z1)l7~rcLgY1FvFEgu=nJ%@FyF^J{ z7{A#ySCt;JyP{HO{nk@?E(NILw?bZB0F1B0-0}Bl8ncbu6~CMYzOW0yR{hwPh`+0* zID{|U3k9UfmnQswP)vIeHeHVI@2%P9qG{ZyKd2<_D{<+Te;wUkm95|PmTRumWS*4t zHH*)EbeGr9^O6Cfvmg7WtjIi@AcV^*r-1IT);0TLC)g?~3EsQ$(Bm9gwVh3+?dW=` z#EL)(#)J4Ay2nc`0lJz)PaD?5hxjZL*`V%q6!w)FS$|~$JcS@{pFH5WPH(9ONKx*kM3h z>g-X_TI$p^IY7A~&?Q$`g4Y~@K8^3IU0?)8D<+|#{q&x)Yd#)fN>aCK z{L*>R`-Dt>T_iJTWXh%8B%$GtvOWe&-@0V;SNspMKL%Px0uvXccpBBo-y-@Rtnt#n zp$tg%?$Wi_>GvbB^8eg>i{~h}pS^Dduw?M8IgHJXD_TpZ;my-x**D6$fqS5(ny(3O z=ARE3HzuA_ad;2v`Vz1Fur0zkOoan9znL+xoH9osxXVw-sOeSW3X}Vq#Mn2g$iFch zqCSA%varY-NOg-45+y8%-p zf!^FtwXdvO*8p9aO(J~-%2zcl1pSJb+Kx?Xz6Ls00iyI3aRZ;wwizafb^P*q2~_T| zw2v?L7bwG7aP_iBfPGvhM7zF=FJ8EqQ|cRSH>MHjr-}2|hSd2Rei024-sIvFC_Dc6 zHjpP?RFQrc;=D)I7CD7HZ0>tW8415|mAvmXS@jKX_E9hRO)T@MslZEUOv<&**}SQC z2NSaU@i$t=yx_Smh4p+Y0_F4jANCkY%Ewu--gT z%d78bY7%zcZCk@-y6NA=eEw5GZ&$RxAV0x91$8%|ksfDtr)gD3o`njP-i zk)r&oQQ$J5TjDuM7hhO|{=*GfmU75XJjfLfZ_35PF_wwj6+UrRoYr1gGQcFlVajpk z!nDv~+PEjUxFFQ)>koz!AHM93Bz`CMcOS6ge`kSD+2CAvS%f~}Vlf_803@y8#X zsc&0mk1#EMYDyTvPw%>n2*8e-^fyLp?_}Kilgm%`qGl_3Tu8=gAzoXk=7>DEy4md; z$&l$fD<5sthOn;=8>&M127v~qy`%b>T6n1oW%O_TOdFwiosKchmxgw^BZ^7Un`ZYE znh~G_Ewwo0KWmsrap&%XiGe%(*+ntFigu+gg$4{MjIyCiy$c><)iJtvUa)_cNcM=q z=VfGEj6w)%{^5w5!io!fEwxs?{`{S8AXB1{LH`46g`k1-4;9y^xdg|9cFX)SwmhO1 zF*4~m@d5HK#?gSd;cw>!Y_jpcN~LoG37C zN$Gz4-l)2Q)NJ#loyktAOf zvvE(0(=%|`xa|=k*x=OA_IWG&R}dW6q{%$x45ro;Zv<{)v7%0gCCO$+DJ6!V*5<1xN5P^sp`<0S~Ex z_+=UZ2<3}xIz}L4f}uw}D;q?rNYhPL52%dFdVu(;;wj4gZU)2sS5pkXtP8`gZ;dTA zfihk@It5~;#F;N)-~0!Uk^&bVc^KGE&b?jh^PKNU3;7{3WD88~PRBhel+;%D1gpO5 zQ4e$2kNa(;49OVGe9PZQK<-`f3W18`>PIZ2>v&~#B0anml!+4kn|)+FyorXeO|_2u z&i4pEynBxvf}bvMH`#<9O-Yf^o=QpzC3!KNCsDSUv3WW>QY9@=2H%VG1)qxu7(UoY zE&mwEx>}V#!s@xh7*)SLrgbkmke#;Cp&DIeO)c_;8^%LQo~euH62ZvQN~)6spE0=i z6He&~7DzUkONrn7vEC_x+{D(HqL+m8dkN%4vi_Cr4<(oakfpdeZ*LzcM%_!<_`lA^ zeePh0?-15iQYEEDALd*pe&mzpEU>~1KG1Q++!!0xBqX~=X-KbS)2ad0IZ6#&m!l-2 z#kl(yZdbT{I6Xb+;D2PWBm?uCkKU6&T>M%urZ0{nHppo)-veP)h*D+>Aw{a92052u zu56EF0c$?cod6bFByo3v?INe!jKHgBek`kfIz=LzSJeq95N|5umr^94S5&MG@noJu zixvAe3d|F3Az~M9{{Soe1c>;4FsqioGOX~A!0$Ixj1RcB3?^S|>n`hLeUu?7dy>zWgaXBHtvTsJ^9sbMDGTvRp}Yo6wJ|GQ@WtVQV}b zAU9*3+}`L;M@}&CB00f?U}Lq56VZ9I=4PCOJm1jU$X8IS(XiZ@7sW6#uI&OCl@fSm z5+((G7?;S6pC)llm|&UvYVf~r|LBh%m#}7pk7MJVSA{^U+SU>uNZmyz^KVecWHoER zwLrHc*=IlM6RecbdHaXF7}YeX_{hY}+2fvBT{1pPlDam=#4!QV?7j6;!V2p@fkbi@ zf?ZH|15KfR9$B=BqX0a#RReAVE=HVzF|8`UYg#9=>7c8KS1-mCn> z8lX-X(B0*ja-4*O3Ib0P>9t6cM#Rnso z0!HlWAnF0Z|7p~fC_Zq(i2%U;z?G<=#e*gEnki*!hh~2Tm_+j7&useCzo)yq*Q+-5 z2_%CBdn{`Q83nqIGor&}5T~;&Sq16TfMdPm1N*A6Ypc4Tt#2DR$lH;P4iiXFSV&HT z5i779#HePQkwJtFxueI`Q}4!3ZAv*1f`(!9 za9fJbGU8nfh{Ko*Esq^7Yh;fBP0AM*9qa63FGv=Cvlb%-M$Mf+8xdUQ(@9*0dH#EK zBfgi9nK%HmQ~wyGcCmKzC%M?mio+F&wxCuAh7l2Z8IR1$mH4S@S+I!&?wf&Wo9&js zK^He^Juug^u40}*gg3#gtqDI;NBSuKWi3!w4$s)%wb39@zk1(~ZNT*QhQA<3 z0O-n6^`!vW2Y{6RB4mp-)$v3b2o0xA{@cMf8h;8jJ#9?7gGE@l_-}vS*!U@s?&QuW z+FO6W{z7ABeB5gT-4T*~jVB*o-AN9lZX}W4hAfJcGm;+50*uk!mXy2zX|T{Jo!CsP za(n;~ASvd+`sKK<2X<@V1eVQ~y+HeGY35$tYU!9W0^ol-8T>FSb*`pTONsl#3O z*_#59xFN|#rKCsvSl&r?G?FtkE=_vXT-b0h+)EwQF?1awugV#=oy5_oSPk}Zm+EfB zU<{77Z3qv&4$`Y|lOP;^qst0X-zWAwqU5p#jB2)e$zf1blEcB>@GAGt=JqMysj{NG z79B@PKfCC_JHHYs(*na-1DLvv92cA>ipjHi0f?sdsMr6ir1gqk(7dV*c|LYou>Tqy%Ne4U(xbzan? zL;FcffNSKC?l=h8;O_d=CosOd6GoVmBMA93g2fnMiGE-){eWV+udo)S?!WuvTvz{h zEeE0;cl8SYHcU;n|kJ6nV(y;6P}yd&TN%L_^_ zH2~(?<0b@O6nc31(Hdc1G40;czVahe(i$x9u9#2HoSw$yOK%jRYp-S8DMx?zDLQQC zPCn0eY|8*zUUCLLfMgDE`PAd$Go5Nf-%abUhfMkHBiiE}aa--#c|+Dy%tJUuYLV0@{o{dIsgRZ>REnh+XN|lunUNj7g1|L}Ae_>ny(bjnX&|}g~SN|c}`U$%1 zgOF5qp8xIojW z_Yg-{tln*yFUaBi>xzDr{bWgiWj{`l!|BarhN9&1*I-vk53yMuY?-I``Mtm6FPHDx zVE9N!XX}_hp^2+SDT$>nYYsbnSbERQq~1r@SQDWQ2)cwiCO4PmeZt;ypC}SP4pL+P z-8*1lDzdQ$tUH?M>H_o;;~f_L7hDm#S1lx1iKP;Cf6v5#y;Vb!dPKzm%Q-9i?LQ0Q zryT7&nUaw4rZ|1%fiv3r_^1i^QwTZXq_q`=DBF4*pCs+}GNM$(d2XeK?5;IPnH954PVgJtyq`rPhl% z$XyJ-(KA-Sm+bg+Clym4H1x~wlGxu-<<1WwaFO?8e^0$?h9bc9qG0!TCMdn;4+@Ze zB6qKwG$^+w`*GF^5VQo-m-XMX$jd1tYn9HXX}Q-h(x}{n!v6~P#oogBl;cYg>c%|X zqAANXzoQFZ{$@7=Dv{e{)%gjhr@><`QZT%A695+{4y_L5Va9BV4BZjtBZeM(?`y&F zw(2KFwYyDaHt3eQD7h(KBi8|WDfCg1^AaYEu`VLcaqM;WdUg9?6}k%P5BgPCFC2@m zb3l~xq|PdT1ZC}o`(gJbU|Sz7Q@ygXIQ$Q0#P!YpCfsl}bCAPg@IlzCk#|i%;@Wzv zf$zce_nyRyIW+}Qq^b$9EU7)Ol%D_i2!#$Wp()AFQ^`xVjmitxqvCniV?lN|6;gJC zZ%OdmytNf|+;^q`Wykr3{ zO_5g2@BGpOu&CUwRKM0c4zQUysM`n+DO<73edis)&qwwZHQ;h$)4Y0PH}1`$i^6CT zwXCP7!C40;4~d_ zV5h011DUC&9s5$i!$6%!gOHutX56Y&6m~~TO{xMsv(Gm0ZigN;md?AxTi1Zy{FwGy z)f?W|oWYX`x{3<5yKlgY_bIGGod$}X!VK(Up~a|jxx;~MQVn@!6=8wfkt6QR!9BM# zw3!KDckrb{x2a6>^wH-e!2<@QzjCsn%?))ArcMz{U$5uxJ!<74qY@=gi`|E;Q4eQJ zSF)kArk8Xg$Q{uao}216TO9nPSdxR`!^O#qIrc+hiTe#Jib6xqGMIFJ@kyewRkZt^ z(G)K?vkYbRFJ5kZJH-y=G-Bg^>38-cd+KXl9^ZGN`mi`$9D+nr^?hEoRF~nR zJgRs`spDxt*fgXv@~i(@Y~C^4jpCSYj`N#G8XdJ|EUCU!3RZpI8Ma?gB*+b_&i&<~ z3lg8Yfb1dE8G2}6>PfMpDY>Dv%~AKU`qma~I)rLW)m_Zb$gDlp`X$1=vjUJa;zQ_^cU_E;SH^hr?W)#6Y}cQb52@DDBKL))m7_|9tY zRLLSeTTk4x4x4!BH7-dl9sN|#`EVlEjAd=4Q<&7y;z8Z&#o6|BpV|Zwf;7eln(7L> z!T-8gN%`AAB#-Q3L%S@t2LAfhizl6ya#ig7XFnCF6Qo_6S8}Ky z4n__V2$M2uwfo3=kJrMV5@AM1Ke!u~qP4+kgvIweyS7wyuA!m14=um)(U#`gT>^Re z+}p3Ay+$jX*I>H)CN$Ss{Ua}^&*3EhgDtZ+23e?#pN8&)b5ZeriejqkT_q zwsMCdF43lvHb20pTZ?{^t4ohPIW_euaGZF-Gmh-Vs!ZjT*CM%QLvFUgU^LrMucMIo z*q9=}0X}(;({>06*}6N)f)j92#inN)L~roUXoiA)rBA zZfmo7+~y$dM-8lQq3!tGC#K+w6A;H1W%nfU-AzaZ$M{#?GavNS(y<;yJoN|)`)vVP zi|6a0OnJH*Sg`lr)gD>DS0#6tJ_r+QdNou)2eO`?JN2nBsa&L=(ZYyxh5GkcNs()4 zP@+H5N++bZzjx}6_rnK6Fb|cRyQhEPzYb*hFN{0X%m#Avna&BDliihV*3A5Ph*}~n zeurcA85*~gA_)9);_AW!adVdD?FS-A%;Mj-u*=GUxZ(UeWLcX zdjz$VH~$pqL-8-MgiW-*FJWy1x0UK6BSS>jZNNaxQnC2Av(HVMz`6LFu7`{C`eMW}Lt;wsigLMR2lr8Ehq zeEXWnvXU77f9B!9KDE4FSiAp$mv^030L7WkcTx9|Pdo2A_3vE<6Q1Wd(-&H(#+5kNk(~9~b@4@v}0-=id#{Q`s~9 zR;F|}Rj&7xzho*4RoDa%__H5m;ciFlK+OekmSLFkg7NFvm22yN(cMk78nS>I)@2lJZr?dTqnPQ?Oo{M-DYMK5Q2XvfZ9DK=H9g|qibqnR)2mOUNcMKD$y+-}J zAB=Oit_P>b;mr9BV12S3my+Ai)n7kjJ1e4lyr`EYPd z`05?mR-uT#>DUGzVYnMFc2Yb^cr|i$qC=>@)%@E%|F9gzvB_4Xn|I{C&Y$gd&rp;} zOqjnT)|5$hhe{npvvkhTNr!_%gR&QZmmf?I*VJ;txm!vDcQZig>o}r1@cdfb zY5E6$E;7VzEqH#9>b9Ff@LVH%;nZmHOGfz51{cxTP5J<=!K1UfF1j7|liMve#FhF$K0lFRJ?dp@{n?OqIB1=I$`L*3CQ04M!!2R-@L5d< z!r@)>dJcf{=jxPL% zQr_5u^p~K}g`XC|BXIKK=TabIh%OPk`8E_NkD-v4DsK#)%>lrJ?akm$c(?##!1_!w zSJh>}rh{;QYhhlHhuqQgR|+ai33^Uh_1u`l*$Na=ReYGIi}GHa4<#*8Gu)_3ts;ALNnW?FhtXA4=i2F$`FB9OJ4n{v{7P^gNQ(O%*svFu4}n5BLAMnfplM&Ep2y1`wK<*TD94`_&(ompQ)wbZ>Zol$kVl92om#BuHMhh z-JfW2_2o~|I?tig-vs!7cof?d0b-g%o+Qnbug(9{3q~$5Kyq@lpg{iYr2If_%sH4fcbAz_UL^U{h9}VO3lSx^jeY2 zZIXjvzy_Jy3kndcK}WAQi$zKpIXlM)+AORab(pwtkLBTxi@Eb)f;0?6-T zD?(xO@wVUTZiu=T>oXh_Fc%`WpE$RB`hU=~&H2>rursR7ju`EK8gKWVYuUUA=a(e; z!}E~s)4|u9bwu8jCK3o=4!a5EQ5jd zL67lTtsm!nUNBbszBon{==Z5zdMx-B$J`g{ni- zk(PamQP=?3;2##jLGa@Gn;Wjl_(q|?x{^;tGgogv5)A$bwQq%BQC5Kec`Vig)g)!O z?_Sn@jVbhvF@1m5KaOc zk=O_R3|PpZ+VQ(kAn1~s*|(b+v##f@fR%#!p^I8}9CypMlaO{n7VfwJ_nu$vA*n%l zpoC6IS;I}c<5&{J>g^s-5_ZE<+jGV~WVS+eyw;zMwUQO6WewhLSn1lq>r{0ScV2hk zYD_O14o^43&H9~pUvzww7qh-?wzh~WK@Iqov<81WZuf`WNhaq9jnGsmr)d2^TX{+Ssdivx`Cs? zuq=G5P$c+c=Wu^+Fk|Vt-YdKJ>fLst^KoWe_>)C^kZ-m;{z>oCA(K&&dgNW!vahps z7jM-#tL_B90IeUFKJ+E9jw>J&^m!!_4KbaBW3hXzpLv14A1L@zNu{DQlKnXaIQ~Iq z^X){jk++h)FvpaVh3VGgf|@?Ws>7`vCo>pJIcZ*UE#v#;H=v@Kt;jZB2 z3eb)x%xMex&d^w5>598o-`wc5={&A&aau_P5F9%>U~D>piO2sW3R&%JlsVJ*YPGX^D>k@=GTV z{k55dAXOH9R1sa52tniw+iqp;@0LcMj(rvIpw@{&lWN(1(%3Fo%WAso>zSfg(yf0V z+7#VT-vx7aWpXe0WBp;7bkq2>=n1GOMwCCkhQH4y2cI=jDA4c{JiTbpIadl-EO1uQKp zVZ!{6vAuZefgNGb*6;K9^A1(gXx@h*;2`W~#>_8`Q z6MR`i_JV2SS07z@hc=y%t%Y2q_iwYI`@ZhLzn4PPVFic!`1Z83bet%x^Ddo$u| z$DCSigf5t=i|DoJ-SIEWHCpK`#a1@WQMj!UVY(qvK5sAzAE_1eq#AD^g4|V}I-~`~ z@MY&KVO1LV89j=@u|~r7s4mo8*7LRWm4g&@VLwv$P}mkkUt49=#{)#5pi@laUwrE$M~}1qh?gRoK6fqq^-B8-R>TccQcKY`3hcy4SNSEe86FJ z^D=_nGWb-yPUs=~(Xoi59?TXFsF>0+#0T7%NJl=LD%74TuakL4T z(9<3#0Sna^X`OO!W8ZtO72F-ny?8_B^O34k%U%W>)pSFeSEs!=fZd+k4k+j%4dBgj z!=7q&rU|*5$Jyb{f=WW54`YBi7(*R->SCG{?c!j0)f%$<4Z>IVgxt)|V_+AT*C7f9 z!%NZU>6AQ#lyGkPbA2mSV;F(j6%a@iLM3Bx?^V&iMOS}on`-tfZQaTD)O!h)-g~0^$U2LqlDkWMAhy!CKIvy61JIr@vlpblP0fIK` z#>ZF>KU38qeV*eQUpADzZ7kt+mM&I-58+2-o2}n>3mbndeU8eS<41dvOU`en? z5c`(TC`;%8^I1Zb<>BhDCsiS-#*efc771+DCfmZix^ot#G~$I7mBsEQcM8YG6w+GP zFGysz#dBqpt+Qiflu=uqX4ugTnQK+SKloI<7qdZd^vdrhH+HqJu%>jRQz6YskHtv) zE>2tZTw<~8dh+dsjkUYhW7u9~xb+dLatyufpxtBY@Jyh+l9s}u`M^%9xgc<{PqxUD za2Bfs`WoI^dmT)HXDTVWKneTC`;{~BNSz;ZJPgXP_>6?Fjoakz z-*f>oK-BoMAeYWPX3rsK_LZXj;pWeeu)IcuW-4+pVrI274C2UAgJK2U|X{^u6pCbkaI9bRHjZ=uzv~FFE^HK{(Wsy2|c2 z9P}gqid=Uvwxn|75_dOs!HNvmt8o1J8E%7X_UE5ZT$v~78$ZrcWnoV`2e)8WU*UDXGPZ`Q2UP_h>aoZ}zs(Wc5yyBMSW z=wJxpcQuW7dnxNa*wDih3p)KwfLNKz2Vly{VO_v%9Em69Hguv$bxAx=KcvaNlt8DA z?pMs*Jhz`I-!2)&776MNNH$DVeZQkr?ZwCLfZ%i)ar{kkvVqiTWXHAmnD{%e)t-4e z<|vOjg>G>x`?{9N<_+OozxA#h+q7e~J(lpI8Z?KB{b8IE>3~AP-P*w2Od;zxG{lA< z^M!#SH8)hS!kC5gTW7`@UV=}e=*(^PIUUYD_l`l=%>iW4M~4li4$Yn&B1pE;}<_kTD=n+K1`=m~W z>j@3Y9Irn6*ezy93H^FA_4=pUA$JQ{f#Z@4LTD$t0O{4y(0O@oefMkk>!ltuQ5kF3 zGxDTbamqJzVjoY$7SQm%JR+SnF>Jtiq@b1j*bC9y?M!Rwt6Qc}T|-U@^pX4JH>$fx z3C!NEgbMm>%Rimp;i0+*D?w`>WU!7Pgr;3#GXvl63wp^(*rPWma#ySMI#|Zl06Kp`@E^`JR4E*VYA8 zuI|KV|9H)Hn?e19jiRkdF=8Hr42sx&#BTh<5tS#C5_q%Um+RogTfU+M=xC@!K6{&OWkK_O z>oMf(wzY3=ZEb}`8Nkt3gxGysqug&U1b3)UY8S+&UyImlW^pDjUM!b78dqVCM!pa# zq)PR?JcrwQaAEws&LN5OA;*lw>FOS~j5K5f3tt&($| zh~?(~f2#ZHzbL;a-bDlpL`6heML=nllu}Si5D}0LrIZFKX#)@yP*NJCLArzm7L}0h zP8XK0g=K*y_MT^V{d`~dhx-TI-xhu5#GIKqbLPx>Px@bfORjON=$aIlpEL#i@r<|Y zHHtUq_*J8A&t#m+aX&G<@p>cz1QqP$q%Qj;XbndTy<%9g8dI5IHuAA{8s@GrL^kzP z4VN4ui_Ocilg8e!JyKSO3$K@A#DLm5QGea_DRLKmjX3nNE-QX?cDr$wd%LKQ%|<(f zq2IQ;ah1sh`mFuhBwJXfVEM9takT8{t`v5x)mW&8eVP5zM8LdoX)BsVYeK0wX=k|N z>3(h8-+@cpuXgjA_c^x1f!7}=oUso!8@Vy;gP1F)>xM6NO>z@`a0@Nfh}WJBehMqy zN=B>551T20@>=KoN{-Rh7Y)e0knCPVlCCx5ydP=BKU{%Z8!FB+mob88dIMJzd&3L) z@_rP1Is@kUGYWP)s@9$$iKd3uMi(d0t#S($A>fb8rlz0u3qC)s{zg@NR%)%p-fcRd z9IYXVkiRH`A5PkP?0UG|gY+K)ZrlgHCvuzMHa({H_RSvKZ(LV@i$xmU*^}q+VF=gm zk82L7bPXT+hLp#&nvQa;QVmP9qgl#Ee9C@=s*cEoou0KePhIE7yyK5&NEz&ctM22} zG(1rHd&UNpp>zoP?@U+igMV<|7MBICS^-0Qf*=%{ScV5;2G+fkhi$h&kfya#|6*Kw zF1!BQiJxl{=J}|Ukq$UGw@;;)m)b11QP=%VlrSeR%g=*z zU94|1Iq@N5NMuap3u($FhKo)*x6q>h2fhT;t zGd;3Wr|KFIi&51B6zMy2p1Pls-p3s^LG{cqPpOlMi3*KidS%czTGJcIeu%kp!&i$o zXN=S;w|vNLP8H>%KYs4ZGIjxROV=E&!H%_-sFmR@Lj(wIJiRY{rMrF%|32K)ApDrg zxYh5oY_Dec4d{`0{m%w@>9?Kwtif)yaWCsSh+B?#V2{>(k&@k!=(A^e?2^J&il6L8 z@;NXc=eyIm88Ph4mBiwx`@a9!T|0q|=Q$0tlv71)N>$6ki$!5DW&y7JllV)jkmthi zTl#4Zy%zD1t83blL>d3dC7Us~?L{3>Qwyy~HAGJ)OcE;?FoWX1M$sTPpvPK%^x`p- z)_A4!Di-Cb=aE5Q$qIMZ9#9&xVFdh5^g}`D|x)(S0nF3H;1t zEZl)l@bKI9O1%dzf89bMFNRB2RfC0L!L^c0N3l>U5?#bfo(mM@uPq0-gs=bzShRA+06Fl3GF+JT(fT&9`BQNrlC(2jnHpeD67?c{xa{aYKjgI-Ir&1 zQ(*JrRy??uu2!p`>}p&Xxs}P^mnFm`H+_T2^{McLJCU_Zl=AO~PcJNOhz;=I)|)LX1F|^qlZP zEjlbb&Usiyx5ew~t6&da!w{Lf5&7HhvjumwhX}V1eAfL3v>7>(BhRDTwy~(z5xZE9 zhyo=-#0@xx`@S+8%9J%*QEWyYtM8L$i&|4dsM@8T^wHoy(I?i#MhN_*IbXJ=i*fUf z8*2?^l>%sruBIjjKRVyP)se?J}7G-Lu~!}Sc|rW!*^z-4$l;+MTM~`JxOJ?ZjVyfzx4pg zm77ye5Q3Kjne<#L*?kG8Mx z&k`;B>sl&MET*(&LA#38kLz~8Ca>tc@^(mvzGitFr3pu85uSxJ5s4s+;FYY@dvw^P$A(vK z6KD#h>wHwKd`K8@Y+?M1o&sknn3^+{+{U5?6qAMYbvWY|s@X8d46dS;)k3r?C}%5% zWzNoAm0ef^Uc7{}(KuzuME38@aJP(AdDa=OsAWT>6uN3_aNB!;#@;xAx1Mc0kk^!L zgx*fOVQne>>7)IEyWUbS>C-p*KO2HH&D{-DiVIg7=ka!Nf8DKjY5VtEYx|@*_F8CC zC0wp#b28V9NA%T7E6d%` zmbE)5F}fvN_*x0JeDh=l~B9`++VbS=%xzOd;vlAK_#tY7{M9js2G%^b__28G;88r+QUX^?I2JHY~n3+Zis-VelRLSrj|} zvuEww-;dPN&Of(tzD`X_Z_%!G75nVkjOLoKtO^e#i%7w}!qpRM)-4+Bh8U14p9>pNq5Q|6#WXQkGTibds*=c$bhHNq1!OFK#J8Y*o6#?q<@e{(pF;gkun@QAA-lLA zxg2PB8!esJW3iZvP#zCLdGU7TgGif%>S>+)#T(T0 z$gJcZhkDn>(R=>Km@?`sa1=CGQ;QYib$-dMMo2n)RW`!*mpVNL8dc*e>?fs1?foo= zXp6PhA1~#^HhP8-tnW=VLtuR|%UMd+IPcVlz#((JT_f>S*}ZsQsvBf`4}EUs=7$99mS?3 zSHE_-+n%(Kt#CVCblowqb=5;@w!%Njqfx=@L;I7$Gvf_zr9<2`e?t$A)%x^m1zh`X z=T>JnBD52|AMv$MJ9`bAmdhk;B5pn1z)HlAj1~>@^+-}4mUp&l}2PPq`1J2iz{T^I8df1cR-n542!y!C8omt zN^kum4b>yYPav;?M)uEmW>|uZu0{13|Ht^+!3RaXQOR&-hbjAn!=TXNb4V>dojLbi zy$J8u%xV~M+g)qc5i?`q(R=Xk;$?Q&y#=7{z)#|gHwcC}Y3po=di%!=_g#4@+;hrY zvgXoR^V}%HhBxBkR0esaV&&&y`@GkgtmY#>adE!XTVEd>+m!R7r0=|1K<~}AR zBdF3|ydJ&R%am3}Sa~awiEO-KEiuo%l?`#=ee1C}Y|!bRA6S?9^BKE;bAJeFW^ijm zQVqKQIGZhcpgebEU8qU$YOwmFVNC|LK9pFO$Fn|jnh&nw+915p$_zh~^z#Dh@^B`7 z!OQA>ngsT@^a1mrG>&R6#2Rgf8}Zri-Pnhdy7g3*{ZCXqE+7m+i5+tMQ|=+ ze4%l4b;7#oHLRDJ9LgPf!KJschVp7vAH6SIsAWdLuZ{+qwI+>!(mYjH7SG24T*fRd)!pCPj>FI6a~?tB33=kN z>YlhrJBq36K(9wqlO>Ph{N2CtH@$umy|VO#2cIL7f0JxTk`Lk^?b z>N(KJ_zB?~;F4U&v!MWguOB6KU8Kjb^!XQG@@kK*Mexui6XpB1uORW!1D8CBeizC2 zz~T+?qc!KbBmh1;` zOsU~k;`+*f-Rilq8-WGLjqaPmFSHH`o`=xlE#WUd>2hT5IH0}QYgtIa>{iF*_5;>_ zyA5tyKkv(x<_|(T1GI&tR>{{k19^<*#$b|G?R*zKsRqoAeI){Z`s`Zt6nKN?`5ss! zq3tz2KV3+9y(W$E_Hx{AAcx4?Booukp?&GuYq!)S)!8pInZ9`T^SC^4>3<=6UBnM5 z#kT)CSLPd5f^C4&{Twy5>q@1lI(o^V78%l4wvh^hZpOu6P~Il)XmM^h2n|#6=ebFx zL@jE%<)GcqfIteh!9!Z;3_hn{Tpf&zt})5Y=UtpEnzO4Dw%ia8vuT^Qnx8gpdzQ5I z-FL)&5?I6wygDYwjy#_hY?q-F1wzyozSM9+<99wI;hY11a`OO~xAYr=z|{e2Nyt!2 zO95NOiMlf8-=Bq)?$QM+8HOMv`Z3Efr9c&L`ntxTW#uC;6a)C$9gsYLK*#Ov4gW%a z`w(4Vwufn&xW(0IZFfutvDl@(l*9M80kJn4D-peP-G~KE+YMS1P0g;vebnVgJY-8Q}F4G$RaAy?KGJco#yZQ$lQl)R$S_%oON= zjIE0LaEu3S-rxNS|KQH=0Q;)o=pp9)wcnF)B4mp0 zoi`awl+ZFLW22Y?A{z4`8JzcT_s|l#uoQ+Gop67UXwzTT92}}xp%z%gv#Q0A1~rzMF;CHf~vuoArBrv^VB6i+lvbPqVpf!8b(`Bfo45QN7`?cu50V zq6vN}9t`fyBV?%|(e$r^*+7dWWdpi_c7c z9qo62w!+4idVy(;X+;*c+I>PpE)Qgsf=z^6?OP+kNuqN@G*X(#)D#8fpaKh?LE_V% zX&mDX%SVG#hi%q|Rx9BonKdos0ogXI!N-jJJ2C36!@dIbAvzBN&Z75?%x8nR8o3-B zXiE^|R;Wplda|KoR?WW&Y53H{vq=w!kkn8a*Ql&{T&iAwS^P$SJz*kx9`Qdh?+%~P zd&s6jy2@o#eE#$_2-Te|UyPls=&xjQP*ssuu(>Rv?+6QtUWk-@6cZXc*5LEEmA(;d z4-TgtLLYu*v;t|pz!d?OLYQ#Is{64gJPO;dqYWJxW$QaSP|KHQ9ODSf-zH2dtZX+( zpARDs&CNEG@_r_}V8VrhVOO4cd$g)AA>ko-; zuK<8eNRIV6rqG+j-XDe7En1H? z;hi;UL9~fQMeW-2u9?V+-I_VYeXYM)`r#<+MD@IQOt=|^SE$mMIJ}Ei4+PxI3+mF+ zwRun1VK;Dj;ZfV4%{&aXY7{GSZW*`xG;%(| zfHvtXoD+R4n1#}q9dK*mTEXf z>v>dcGKj_9I#s6%?P%wO%NL~x7R&9OE3jC@jWt0%T(70i*ZYZe0o9)_y%4jU_m_N1AKP4^UdCkSp-wp<)ns6 z$-i*bggqG;FEaOt#izzxg$2gB72CgE38`&E=Ae_iL5}|)@bpI&W;YM4O9D=(68@4g z2S^nZ$nEGIX*T4xg=ddh{k@|AcCIIEDeWL2d9qJm`YV9Oh~1%}VUqS0fsO9Sfn?v)xoZ;F#{6 z+=-tMhkt&hHwuZ)WjgIs#M=b#l!*kv$UTcelzZw*N)HY7i7KXuee04&DQQM399bw)i$dl5x31Qb{tDayceW?$%SIGasg= z+lof&^AUH0#aDW)%bW#wYP6XBgw;*Y*C=@>iY;D!#kswjld6DcQ#TBupLgrKH|lSX z0-VVAohq8#34Y<*m~j!ocgd1dareXxS5G}BNkylE<@ic{N^dIv7}p+5 zk@e$QquL~A;3roSwn)ATUB>+;ORSzqQBc9F@u#uR<=oQWnssE-+}Fi=`|F3^0&4UG zSqRTXN?5ek8a?FX?60RWW=JdBgC-XuEPAn35`m7S3|6*Y4uizcOVWmChl?>ZvI}B z!pL;cY`F$`kXAxn7fje<#VS!7auMJhB#yN$a}fmEBm`>jDymR)oF+PUE4Mk3K!Gq`KzN)LwmZuG&1`Ram66V zc}{BW74{<@dTniwIB?$GnGUV!xa^8W*o|1v`5rI4?%MQ#zp|baXYp$e;~T48D70ru zjun{gl-z7{PkeXboPAIfa8mJEm*95jHf-8Jp8lNac8Vkk_q(o5n$98tn(`k(q#(?;hlR?S)m7-iLdb>T{OP zoXLFe?oqw;U~>oYc6;UpEzRxunv$PT{C>*;DlVm?xW_3$oR6?UwJ^u1!4NJu>Zs zytOw`u`{sa)O)*!L2v#91$C@9%GSb~JxFvR%+tEqtGV1svU@K`>Ul8;`H062EVav8 z!%yI@ur_Nx8e_nD{^}bV%5GII!4613xen99^5Z-bnJW|}LC8S-^WDRChr3zj;@+w! zS0V1nJpWFy1j3ei(z4*SvIUQl_pO4}qf?NXe~1A89<6sHlT1hMofv#XUoX0e(qz1Q zGmS<8*?!OU(-re53*`NVXwzn{BAI9CD)US;HYv9gt{M!$Q@(gBedUEt3O_@Cta(Ib z!AO1zODWx_14V09QHkFM3yPNWdTL$AUL&4vkv)a0uH>Abyq*0*L|S-p%_8Mj=HDq{ zMnC=Dvi4s(TXqap$#QZ2CurDh?<$ClQ!Dipobls{&06D@!^zhRjQLMo#+_r8E9cFHx0 z&+VC)v2aZA@9)QQbf-NVq+DljW4_4463arI1M;_y*7#1pw%M5Ft95ytDy^(H(A)mT z*2UJ;nrUWPUVpP19c*9P?kOpIre+6C#)9L;b`CF7%19fr*J}R+nO+Wim}TXMrJT|? z+*J2_74~aspO!pQt1u zns-8|0d9c(x;eI|7rq;qWFZZZ4dl1tW0txU7|GlRfLK)x&@S8BvE6a}dZVG@VGcV} z;Gx}xeN)5eycb@3Hu_F+m$!R+XDdJ!HDjL)h0QmMKZ$(i+bupuGaWC2C9F8Y)uNEX z3@!y`s?Op-?CLC17_CECm;xBfsSLYP+K-U^;H&&MDYU$SS1OzRL8K6py2kc^Ba!P+ zXG86{x6RPq>*&-713hM!<$*Ev2h4t34xTGz(T2g%7fMjopkhdIoL3Qg|8TzY!L=aR zGR9-%^A!VM3u_$8U4*UnQ`MTf0t>3QCT^JOT&Rylz8u?&qf@#|ir_JJn}M(BDfED_ zTdHB%S#H!<+hsWO>vi>ZUG+G+6|kFtZ#PL9Iwl|A1HFF{n*slwo}nb zw}l_-|3=;{n)OY!(sp}`%mh9lf6(?RA17J6*M9pscK(UfXI1gP?`Y-u+6z3QIt~hh zcAs$!Q_Mf04IMkjweDWjoZ6%j#u0HB=89JQHB!seWUnnsOn|d z+%vCRFIg6#XSYjh7MGi&hQ~uF;wH!V5d5CYpTY}`J8HC7DB=7JHW$Jk2~&S9?YkV_N347AcX***K{f=gu)cBpfqu#K>UDRv{^J zN|0rQSLnhO3}>04CcrR}-LKs=)ULHv^2zAnyfD_F;OCk<@dto+Jh*@iUA12+qFFgr zksGFhz8@(nasV)ouN+x#JL_j!8+83*SAEHDe8YBs;dC;K%!{a+kJQhcUqKq(xMKkc zKX{NaIN2^6X77DxA@h-hlAkqVZ>jE`%`ypcYDZZW zrs3D>agQb~+`B&-nThW1H=Bb4gVR`+=k>IDV+khwM&(c%u~(Y938$)f+mRMc^m1EA=A7o#8k;1p{7-pyc2 zf;-LlGE7?&RGv^cQqS^>JZ)P9JuWhFtMnRNX>-rKyC1yWLO?r;&oca_&F+L_ID7^x z4p-7}w#JIK&|b)#W)VT-MsJm&c0B7QXeg|CDnlc4*~xbPASzLY?og0C&9yK&XDlw#&vJ;XFsP2T#_+dGFJ!9YToN z`K52{{gPIN7F~T5{hDOgKBBv^(&{A~GRIkc6Rh3P&Uv0Jpn!#|ZpkiYhrf2l-8{m? zd;1d`<6m00F@eG});zQDSMf5|d|aY1F6%gNVdq!hLjXP_;^my<?(H?4U52|ijb3aKG9=zg>fHTuEGlR5GV>? z@81~;Y&5z47r;GVpS|yf0t5=lXgV-Yb*nGCi%IF4UME`zojXD&@!AW;Mtis7s!+Mb<*CCPWr%8^M38;Ah*Xet?hx1$NJ9+Wm+~M zVK%pze8|yarQyuJa|;nP2a-CS;YvH7=pUc)ld|HBh7c3z3&9gMjSI{B3dcD+h8*Ju zpbRa^FRMpQUM*?cAA}d=d(2yo{%%Qm#da`J8wp|R)0a%w3AVnih7G#hG zQSkglopiWA()yeG**T4j$yRVx3eaayXph_ki^IdL*HZ$E@#@TGzNnxOPMuU+CuU{A zp3e2SJt^*?cQd+Whh@5{JzuWc3(a8$z_?be!@k=}cHX;9=Z7lM&hx=4XnP%w1P|tU zU;TcC(P28EiNDIR6cOG_ zKv6Xi<-eNY{gH-#~WT-x=3jUR`G0G8-$a_6b|GzGwZnBxDeCtF!MKzAjO!flX2+rl0S2%|2f!76;pxEH z4<4ZA2912i)mD#_8_Z^{k)5ZE4)~>l7w3j`XPn zn655sW4L9rzWolyw+45>IQ+P5@MXT&AOQ1!iEcE%e5d0GnR}Y8#6$nG-+l*=%+7<@ zOe2K;Cddm)uD)6>YLdk+feNf7EHKI!7a&vH9%kJ8YU9#GBr>_1g^<7UBG0G>M<;O=zcq-zQE;F(K7+@cCRG6X^fw)}re@v! z?f%IMvFXtY%{}(8EB0Q~OyESTqFR)$>t6nf*TjCbeC1WA zXChw~25N;;*GXp@+R+lQ9p}rQWI1MzV&Ovn1wP?#mNAKwzEar0s=x&qGGoR2Q?fK6MHa(1T`OPfhTOq!O%5y4cKO<1jl?dYJAZ!61 z?Ssr$^tlmYtt{O0htR>xl3g0%hFi1YgLTg6PhKPrJ7HG|nqu&Ds&U(f#;X-83L^L# zU7Hpz5+Ec(;I|c0Tld~SOR%(D89Ccp*`%mOtdC*xcr(h!TntoLKvonCSBc-d(MGJx zJpWN#1#uIABld7`8E)0_UH*{bVqI=$RJgN}as%Rm^N?4DF~dXHA;4R7?5-JnCloLM zeJEh)^q2^*XeeBG!m%GI({LS52{iqOw=!WHmN4j{H3Da8;f15-3m|(jAn&;Y5MGAN={Yh zG}3PDeXtR_@m5Dw0z11IV&M41y&D>bGu49VjW!rB{lvimekT;av}r9sqf1?eYs^3) zb`NCc{#b&ql1mg3x^JoLimf(BDkj!nG)zs~=|W(j@8$!pkL|240&LKTHL|E0Tj~IP+V$aU!7b=WMJzwduUm^7&o;JxzYFJ+pK~01;yc77@ zCyoe`=$C)#K!jK<29|IKXUj-z*di1&dW6_;8<-snvEi>AJ@zD!O+hdZqKSc-h$tfX zNSLxzpM6G2BQF2qV@Vou-j#z6Vwp48h#W5AGO^*(cNhtMV#CkL7u;q^BNpqi2Nf|O z*+|w+n+zc$*xq@oh!`i;vk65U@ytFCDm&Fl-kUa4VOH4flP*j1r67!Ln!< zDoThAKVs^!kM3voTRR4t7PN*`6EvTD3nqh`Po;ri5Wik;C<3s10;?{bKjP4;h>#)`Bm@OYID71gNRxhdFT*MV zFryNLNfO8|9bicn?f}^-K=xmaw=tm}dtai>24tciFr(K0k+okwz_R?;o17wooK!*% z^mepoO_0DYsJFoojKszN$hNK=oIdd%Suh|Yt~n(ztMol<>;EHrgOO1DkF1yd;54Y+ z3g!;xwjKebypp-wXz>{5Wzd4M#2;kFaK8+h^lAJ>%Y=PtRFEF75|Za{Ngi5 zDr*QhNd|f&N+9Ts)gN<;AP7){25H8mT7=-U3k&oC|3)Zw7w7*UNyrzUv;Y0!nr3|U zzka9}=ym_&j4bXxaeo9YoAe0ClPVV7oFn^+`A9SzCXZ&tVc|aNpm02xAXUp4CHSzB zG>Mx@(1$lkjki68aUOgl+7Q8On-~0)5ZC@yr!=4dWSk_KGWR(mxIiENuMsY&5u!P% zOKy{c8u?d#@-0nWnz1Hnxy*;44~b?4l(%;PA3jqi%_V>l^!AmNxXKZCp+Q=aNC8 zfQ*qO_~{6UEQ2Id3ojrt;zn%p2zL=8BcfSfjF^B}qDPY8bYqB&0Bf;HiM@ z97M+UuQzCr7DPitrMyiJI9c+qc<40L2m^_)Jt&w8uEFNtNNhlp&xkguF4_4OSkvx* zh9lsKy6acofxURl9Nz(|7I5h&CcUBQP`CCpbl#PRTOoCnp7YOTPXw7 z2tBEhJZO|2fg~~sh>Ya!zU`5P$TCS}LM#xO0EsLZk`s?$64^^aZzQ$pc?9tb_K)l= zAiGFOA}fOyobq24)EbEFGD&qFn?htJB(gp_h>Z0g88kP_Ad(_sAhMKyI$#cw)se_l zXdyBY5?Lg)#BWJbnXU(Y$Vw9C>@(oQue2no9&WH`Dw^#ob z&J1egG-;`>L%n@fBQ*kYZ2;N7O0h^tgd|BU0jF5-;Y-qo;C)z+0Lg4~h=TPcBe5V1 z8b%#ygi4UWIFLx7)+nBl{*VMDua6Ri`aC3Zmq@ijKO9-dZ7nGw?))1>5`KRU{5Mfc zVS@AoF2VdNiJimRCby21E&h%@Up3|NojG$8QMWW&ZGp WUj0(j{0V3qOzHl^d-<{^Z~hP0Db{5G literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-workflow-diagram.png b/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-workflow-diagram.png new file mode 100644 index 0000000000000000000000000000000000000000..f72ad5af4d3a5b1088429c3e4d761eb40d947f6b GIT binary patch literal 572636 zcmbrm2~?9;*EX!R%3CLDtrJ72r4>;Ikx3vBhbmPRR6s7=UtfKm_g$-f*HTbc$bFx4@3Z%{ zuj|^mbJEp$-D;iH%a$!$cl76KkN$MPBi4Ur5mBDqhv`R( zM`j%w+UnapLRqf6JhOg*Cpi|U8u{>UZnv|P#{J-IXe<)A+?BTXS8{isoFiS%3D>ii z_TSy_u7|p%XX#M!b7G3=!P~uG(C>Y9F70Mp#y8v7eE-vL%MRTB^5=s;G~vEmcCZfS z#OX28;wyUGY{P7CCkhM09?veaBi&$&bKpk{5UVnU=IH$&{_>}L)0>r@pZ)B9*;cb( z)BpOq``4Sd)-7Am`uwFYt*(3&n^8%#KUCena+j+&~#~PN|;H)Orv4lH+I3F3Zu3@!u*Wd<0c7o)Hro8X6z^;vcPI zVp>;M*LLK3PlqiBEgpMM;b4_-eqY18KQ4dZ_9AifegY?OGV=I_)|H*%+azHR^rQPP zB>dekT?4i@Hobj)OLx1`$Tb^=BU*RHdv@?v2mP@oS7G@nKqTQaa!}Ky6sLtQd`rE_ zuj?a2-T%o$U+*xOv$E4*al)B|Q!66*jE5n)67hIoMPzryvPW*CTB8X8cPoRKM7zlG zf~>GzTlOc2hQ9nK&%Zox%H&t-WI+~HIU=Oa_xdcYpzc&z==esJa%HC|dFG&m&Ezvl zLGuz_M143n+4jtu+_&#STmNn#{~0+cFA!I+9^dg`ettfPgpsyqT7pGfT4yC(rhj&- z{Sp6K*B6)7X#U8PEO6}yh=%!Ia8c1<2)Q|Fd%^hkl@>!DFaE(HTJI3ST$4*ej%V7k zWAo4(FZb@}=QEyd*)KV|wgaJ2EliV1P8j5ds+73HjN@2%II&1^dz5J0s2C9lk3q|jLdGXuy zdCK2k7kAgpzfM*UNR?A1Wbuwp@T5pw{oFRNeG-edHglTFJvk%he|4@NydNvXP8AZ- z;`dt{znB2g$XnTYz9_Qh@^UNA`Q_JDOHa`sw>aNZ=tgf=aa#rl&-u305B>7DPuS8P zUY8~(CxcBPEzmV`1DIm$L7^K7yExy+%(jc19j=w|nfP-(l$*f~r0SxQ2Abo4wqg9PgS)3^MyQg@pI^M~j++mtWsXJMquX za4GgdEA(?ISC?Nu3x~tc zXLa|v|C9WAL94-cSwk~8>N_61UtM-%f_@x`o%;|5|Z-%@81phjfojhc-k;pm(2ppLRbHzU2(1>U;f_&7xmT3 z&I@BUm;Tws2M9IG?8kGC@9_P_CNS&RKYNo|umckyrLU|u#yDR3N5{UCP`4~@Z|3t4 z_Wgptf68iBD^v6x(rcE*{ck}8h$t7|W%>jQq0PYGhX~*|axeh_0ky(q9nI}kC;ky! znz=07WcurRF6FC#_B2>tAiE?D7qtJQh~BCEX3Kth{e$;66Wd#^y8p9d@eTuapn*!I zHrnKq3;z*PSicalWj{c+n|!tE{z2~Yy1=Ojpo685OG{15Pe{-I&rwPDWRqe?@6dI% z*6W?+@dE#S=jji-m*8J-FNiXGvjBGJ=QxC0EO1WItL3HplwD~ua>hgaI(P+tEUfcRt?8+Fh#DW*J`~Y%?+BCz)}P(U<{i1 zZ`@aM{Nngv!RK2+-z>eMr48A4?ZX`-;?G4DjnLf_6*(&6Ry<5CzbFCc zksC1&S60DYV#Y(t?l9dO&_e-qvAu9Na-#EbyhxDu#8KM}L7Txlhu@iepBH-n zrO9*yTsF40nqNEx9wTqx*tJ0l!T`fY&XgxePZO_}A>XWC5OL{TlU5OlCy5+3WP4{x z<=pxW!Y?EUrN86wTry2iJ=C2$`fMlP*sldUV1OU}rstCFs$SQIHs!;4XcMH^pZyzv zg41s#zeJ~D#uPn}>Tq}qHvoF&3QZJgY_=0mCRY2k@&dg=$&e;(y?vc_RN?lBanP(1fyVkShQ?}%ferk21);VF#QBn-V zVSGx!+fWwo3U?c@pnC1Taymx`rky^B*R$LENqsvsJPLyT^qNb@!$*0y1YISSF%u|* z9%|mjST#!qV%I7{@JBlmAcNhrUc-{F9U>5%->BNx`v;xWDmy5C@tCkJ7X4gZ9Q$^i z?NZ#THkzBwvQfegZpk{ZM*|kaL(K07xd{f}C-5mlpJm>PR%#OfOTu6Fe*8}@K+SJ) z3(1$b;6Sxu+M$#5g0nC`9U{L)7jYbB*Dw)*R#J+!*dv+*Y}ISgrG=JDgT!kO=N6T+ z!W{pd_?A@g1blf7zDFfy8rmO2L2aqCwR~cpGrqvPpapJLeSoYsJ$c)2(2jZz{xCS; z{Qq5Wpx|3}M+1f#M}TR672P=$5}Eh>Lj<`PEO^^Ye>!Fx9)IOk%fdpOwfbj6JOZ)b z+Nm-i7q7tmFsPlnwr$lo<=cpHLT!S@Hv!|up`o1NVO3R84R_2* z2=%&vA9)z^DF>}OdP2uyI z2p56pecq$u2=vuobh^%c*t9SX$1I)sfL_;2!a+7QNI{+axOz%ZRU6*tf1a4?Na_fy z6IAcZ%D1=1LVVL1p0@>f7+2zJUP_D15l!ar3IR zNt6Vt{|H%9c^f>s?cF%{pwE&wy{^(cX8GJNd%a&rmH#zZgvIK{71~eX=WL`i0}rSc zA;dZ%)nW1Y#}BV>V7Mhz1cy3jxei;B45g|(;}kf(!f%~?V5{(f_RW@=CA)YwM)P?=wy95z~+;}DZhzwo0$`anjT zsp&B1M`i7BQf$r9Dr>6VW@V&GwR@JZD7xG}Skzrt?WNVS^cKbrW&!3*l%lMm5gM@Y zFarB-u%Ujn2wCiok$A*B@F3LYlym*MDJnTWXz!I*tJX{(;>f9a6hys#PD9-0RD-5N zcGO|MY$S#wt~UBN>`VUwLr>8MAf}y%gBetv~e0lJS)1lW>w4+}t z8*jw^|5fq-L5H9&fo8F)s_IA3sI_IpWPOG-%7*>Rwyi62jbcQCQed@kap}(a@{{x8 zgA}?>;*?kOQn~-LOqW&ro5j?~Kt=*-WbQE6PmHqwk3Wkd6TCw5y>sC$Recia)JU{J z?1%VFNt0riYu}_+!7NodYZVqe4h1!Q<-(?yBrbF6*K9i{jAPY{rL6Dk;Q1n8NVc1& zx<@7MLPc#l6J7hGLs<=#N5{>lIkAeQOREH1o}llEfFwMwuqT>?u$9FOdfTG z)fUTt>vU6gzx1M=he#Y47^O77%TzQXjUDrE5X{}scG?%{P#F_M?)}b5E$1e71Q>8i zewT;)3OFV?-gw0dsYKw>{EUuZ`T zhUD7X+HOlv&MdS-(0-Ff&PjXCY?v>UmvGPsfyY8zYl>imoF;j@pIr9lUlCr$SX!ao zg^ZATAsk|s@1;GerXBel4yWv<{O8`M<{MPiBZXQiB-y#u1}^maAWo31FIG$CN$L+b zvpb zK1!OK|3l99cXJ1IZG39Q7RNs5g@J~1f>uyC1Bt=wu2T&jwzRuHDuEwR+O<9uV_D$j zzN>PVmXyQ2g+U}L@d?H49oR+MYGt~ChS#-qT*rW9j;_rwsitT)^#q&Q{-@@L(Ep#| zIQQ7hWM5XYPgw1xad|}Yl`83MS>0?f-u!SaH^rfQ0wArT2%#QqJf;l5$_w#ctV45J zI^bNzf%BLGaXiK>7J1jfL`@q(%YO$MEoAHC#$A4@GFYfK+UB zpfe4IU_zlhKn=i~HlFjwdYj_pd-_KzM%kJbF$N7kp#af4q1cCSIH%7Sh%U=&ZukFD zpHl(OQ%ZK>a1@~?8d~-<8xc_E6;+aNzlnYn*&z1Ia|Eb@`|9bs(54;vh@=dou++H# z_i&=#R$HXZRLQmS=2c_d&9f!zFqCKu& znBnh3?J?1{)NWN?QF-e#3F24}or!REqH=?m(X|aoG&<9)&Y}-#jkO8%|4_d{Svjcv zmK%xZ77k+LY=qo{X#n@WSlkZ#c72jTM&U4XCVAy}=77ZYSsXUvn=Sgx+?I9&$+c&Z zXoeD9FjaAZr?9CG8WWwA)=F_vPTMs5YCb6*4=c9IBKY)-;hq}fxM6!F^dggq#-6?# zVH|SS0Z%#|g!idLv$u-!E!p2)vBzSIoOL`$$w}M~>u<6g2Wv2%M z0(X$(il!9bA4y>@#LZ~L3ZHhjAhgoEsZk|S>lOmsMrV&lY(P0w2bBrT9h^?V37dqpl^&>n=(l=vMvp^j6yT@G^fBiTTJ@drsRVr?|fjvDz{OPt|>QpmVCgi~N4|`wr9B!?+fRUK@ zYU|slndPSP$#K4OpP;n_TM@ef6_i4j{xV-Dr8aaKr@WV^2CI`G^ho}J+v1bkh(_x6 zm~HDbhLtIjt-UdIgoz4+i!Q5dteL&G%=)^pSk!vGeJ6?EA5*+Dq4SZgJ?Cnr_BKw~ zJ(#?EZYC_~fH*EnY>armCz9Cz)ufSb_~AhRu$h_iH4%h2VS`O$^RMsAHSz`9xG1O}#J|uq9EVsi$})3F})o zn2SW0e=%S$YhhMJ-*p<#-9?vhy=xO{S9aMFArx2So$xc{7CahqALZNgaigp6Xrpw@ zDH73S_$CAS;-i09Bo;E?AAqmI4|Q~OP?0GHFf70o%=(qDdC`mqC_UFmN4=Zq4M^ft znI8lGgkF`UI9{M3(ziFhHV3uFV@u(Y0&Whz!FURuPZ3K*L`? z?Q-Wq2@#tzg2oh`_Jpo3+~X{;XCz#t%?yXJ_Uo89~Je&U>Ek77voq+i$> zsS9*HSGeZN<;tVk-?u7UPK_d6bVlCshvEe$_%B_<-*SVb)DpeapbZugV;aL#5K|G_ zgjEy_H7bd3(8uo+$wnivFU_}{f*{9IYZ>PsW1LLLhn>EnTX3*n&iEWcPx3!Lj|@0C z94rvrIb;^che`l2`78DsqMFO}bGZn{nyc=hCjOOu;kHhJ+)FB_$1u;lCqvNZ!QbMbv6TLEp4P>cYp5<@Nu%)hlCXRFgc&TH95F!_P_Fk?LTrBTFY&PFp#Kl<(D@)rP6AJ$kmGavh!~ zq$;~Rk8l=uc9zh2vB7<|PSsBv&QLeHZAdV;RbLe{#X?MeaA~mOhGNe|_NTNK| zs;r9$!<*w)ZY6n1eqoVKWy$_$vvDrTQdM}v5!dG8-{ubA;CQFEDoWrQ{Ojb?9XG6= zQ~)i>qp(=SLL_os;?5+K%lf){HAu&Z_g)_ett{0*eS`1FX-I^{3twIR1vYt2ZDCh( zW{CSJv&R0)^}KV_nNycl9?#5TJ|4<{WR!TiG-?_hKy&4FbrW%8KX@m>x~q0LVNh1s zVn?^AXWAj;E6*6P93g$+&PEp$YQMRWcDRua1U6i9D4Z>0Ci)9X_WiKXLf~sGF4C&_ zM>)Et*r$WU=JnN5sCQIk;h+wDz3$oRLnIl)M;)0v74cRK!5>@UNHl7%I%9(A`Y^_X z3KU!VPYIC4xFJi4NS~KVW6x{6JhYB*pr^*;;F5UjPT6pzn~oJD0Pomq=f+XxG}J!| z5121qT%EnE1i9Ji4<#tkl`%#2l3N+bu}ANar1#$i{v7pEI-e86*Q&;iEm|askn=Vf zMi|t~VC5m?rq--q6(yoI(2_g!94RzjG30P`hgw;qd`i_=Srji~ z(K;qjs&nUqTJURq!{$Uiy~Z5XV^65Q#c1rS_-|*Kz`qmeA#1Y+o(i3IM9DTn0RvbmAKwx z)?VtfGse%(P07$rI54x>W`|SJEX`umgD=PL+^6>WUSD{=q3%bUy=L|=nJX-6vW?(m zlVdX^t5>h{wUZ2H!;`yzO3oCTX928zxQC^dp7uD2Vd`2ie4_g)@BS*IGVG>;`vF$)_Jj>#htpYaQB2_j)@h`Le}} zuc!$QuhVlv@5AGhO@h`~1fCCdSKdo8z~^j~T!$p&n<7acsOxS!8qk@aRy8Hx54_R= z*Y^mArfGTJR&Zl~=7g2!6(dKTyD3W?@^c-7VuL%TM>&`GP+v7in)AO}VU!*F^fvu< zu%^i)N3wRfd8+{`Z}{ogsOMb7<<_>E?`kG9P0p`_p`>nz#S>R!&Estx$E+amB||#?c;gH8eU&q-eadC(-nd zgzuo+x08GjsxCM;fkxjUVhf@+u;xos((h4JIgv6h9;W*AHb=AS{0B^K8~5?6R?)=Q z59ru6f=CbF0V|ij@Z0hJrB@gYk!T%{Tv@U?#U`b}!yLk4XZmvLExC=eDqELusLU@c zEdp1~T-9;vUf67Z2@hJEAg_1CML8!f!kuvE(d`4iZyZ|lES}nLlF5SAx35eDL3gxG%=w~ujPp{#r&3o|m+XSlD-;aU9hl|DzboJtkxc`xkl(esVL^ z0n`*bgh}EbHPqqav`9Gbeh6G$Q2y-$dQ6+h?Irs_BslyXdK!NSV3LF$7+@WsaDptP zM>zQgHS)z@E2m=ex0~&Zqx#$#1>@E0x2?8zp^M%orHpqe!4?1)dtMx*q7u%`&yKnRQ_M^9q738<(ulMb#2;bg|z zoFRA93wM-$9Hqo__nwQ@)VAckVyJc;m1^O%zIwPsBpCXU^xGgepxEkJf07BFe5;Co zAS$tG@|kcSdGk%rEje_0=%XW6)l;IKOwfP_%Ys*oIyDouxZK!@pn2c`v9*;1v z;X%EvalNw`TfM>;P$x6W@Y9_v?zcn3MA%xrDV{voXgHGT$bxP^R%>IC(lR_m@bRw_ zA3OwsL+nIIK6Lx6b2xM^M>fiwda*EG6sK_iF&cXwo$b|@LyGZG#Ug{&@>BwT!-^pT zl9$(oc4@*?;pv=KZi%k#+#+seIAkaPr>jW5^riEYhBH+Swqn=y0RGP(t~%$)SuGHW zO0AxKE&DI(kR49vkK2}>#p_zU@OvLehQ{4q?8Q3u#K6{Jl$DQQq;+B_>%z$nc+T=s z=r&s|&OvJ@51;!}e|(b5p{yb(whf#t#Dx_y`bWd%Jo!BkJOFHqBTgkVi`m%hU_=mq z{;(e6%J8=miVPW5yIuHc-}*M3&u>sFMmB?TI_Wsu#BrZs@zQa)JJVTH9zf|i=fzKm zg`CcT5yBy}!x@aBl5=@*|E3JlbO$VkNoXtoOx+FeS@O;Nw;bUsFIr~c{GL`3uN=O+ z_lO4!Th3qHv6Sttp1d}vwJBV9#}pp^%CNSL6NQ9-6BkwI=?1|ODAcy zcGQ$=Fj_-CJ{>oL;rWA?@#OT6YRt~5znvA_C{Mn&b~^MXf4d0wa;Daj0xK!0n( zMWyQ3c&+J9JKV$!D^eJd8DUM8JkN0Z;;{}q^cOy@;~AUza0U1!fScpTyB+8hSx|-@ zZcePll?($K+peWu@&o*g&)z<{CnP~Y`@O3YN|pS48K!CH4mrPRj9xDjhwoae@)=+R zZNT8j=J?%V*W;=jp+O-rWBxhM7Z?cM=Jc44QWY<6s*#2)3%l5q57ZWc;%z!9VMy2V z8tw{>9Jv)n6+*xItD*^{A+MLf!@$|`*A6?{x65(S=6Qu=RO94?#}kjdWYg?eM>sme z5uU@JgeHd+yMZX-nZ_;Qe7mHM<%Fyh%f+SYgZyYGw8$Z2{L*S3G+&BH^j`0i%!v{0 z6$Kk5NL7GeEy7;ua46dj8klBX5`}+Y-UrvD0;v{3mahIlMOIgPQCw$1!m@kQD0%?0 zUc~b26MFDc{)f%Z)>Pdx+gp%dpS$Zi!#(Hh>Cl&Suf%g_BM4CpgN3*#H@&lK zZZnA3np5n7LrKrorcD`DC$C(-@$flb>2qYCI<@UWfDu(rB# zIjimCo??42le_HvBY~V z*2R3wfp%`?!WRATq$tM52xd@V=MXAj9D3!lq4ZDLs^|s5YvYQL=I*}ILynx^F5|Vq zrF{43Y=t}B4Nnkc8>KPbM(47EL(oW;y#bD{@!7FO;)nL2iluS*NoJQu$KsLhuZKN11EYsTA{s zOBFduKiN6W>Rjox?rV}rrMxrzF|jdVkBo`@B$dXtcyU_`6o0onMrGiHuBq3rjbAnX zzG3iwZ3~^B!zEnTOScs@(g4fob9UGa!yUq{$&)1urv*V9-g1HXJPIAKqYm&?<)^5Zpy&+NP3d_qQ45DUWAw!_)@H=h>s<5qohi|*xo5Gnx} z;4=efe;_96KRRWXRH?6OsC>;`Q=C@&>Kjlu1y_VbsZXZ7FRAH-aAZE7V)(bLpIof2iClNWI+UXk_;kQcceK$;zvQ-YQWF>)OnTzm;+)Ms zLlA>j&IAQP2E2Wt(E4oCfSp_a8!TNv=4qmyZ{0~hI>S1MC$}oI2o!kDyac={A{-nU z!&+h7!v=egRci9s9Ehuv#&j=Kfej zrH)Kvw5`K5yn5~t)Zwo7xNV+5H}5Rz`OqkLfxjKG#YO2DlkP{QXrC(9P;LfUv*hCL zx1VV7YX!8Got44p-dUcwwNnAz&Nw(Z)WJAPvR)t>c`zG>2oB|zhfvUB`tQ^#JnKjc zVeUCXE!L8_H9K7)W5<0kk}?0#_r6@NgduXVUtePQSh5(Sm2#8H|HxC$x1`=ve!~6? zcROrM!mkYb?IUuK34|OkC6v|jNrh=x%r13w!qi!yHKmXp3ucsak;5^yXKV0KZ9<*Z zS`K`4nJc$oT!+@r+48w(=11w0i2C38Md_OcgUY_z$*~Z<>eWP1ft_Zqp(V9UcEyDg zvQ}lVfc93ezII*^V0X1$Xu^%l?@DHHCesmSQNS-=V9&C{wLie-o-zx0$L*2nQ0AU* z(Doz;vXP>!~f)BedJZ@?bc~lCA!Z@-tk*Tx=SZs58M+ z-b(S!au9N7fHI#m<-u36QjS%Z!7k9belyJw=pR_lq}2Bis8CNti}S{PBT3Y9%nr{lvT2u9YftE3(6)OQTuds zI;}leo8b`HR${pXp@0lEOiv10G05$q==#L!RpW0;p}dWg($r1}yaQ>hvB^WDjWxAh zU~ROYVVxhY4nsJ|yr2~l*}NE?Vf4JE5Mg^uNMl*RJ03jj`<`?Y7#y18Q1GY}u($T~ z!pF%-I>9Ku)6VI$`hPWx3S4X{v{&ZkC;rU`m9o3SixwP84mZKY45@Rx=j%?NDM*)i ztvMYO<~F~(ktzzndObS4P2w;Df)_aQdhFb+aq})`3OX+S5>;z*`YQ8AaUto-TxrzK zzGqRh2{rG#DOoY^cK5mR4lm=$#p6`qR&$_KW?MEvO~RI(U2*1=T~F;jlihCUSaL{v zK`<(4_!1xVhnP>S)NB+-9-MzzZ`WIH8(;ytDAfUM!5vu1Zik3cpEL6jD^~SBZ6UD= zK+x8D4cU!Hn>=iIHId1s8)*Bmhx#57lQWGLuNkIfN1#!cv>m6jY4#uaD}Q{f2NPn= zk|z!M28w;BJJP2-lJq2qQ!j=~FrE#F@Z#jsIH(SrI5+R{DBmI?bhe#7FqJ!47lYtK zS*jIUo&Z$(--tYqB2IN9U)_JmO~8|aVUluUmH8Hdf2elCiC$Z`szK%H-m4u-=&m@0 z`RKu`l25U5AUXD(DL`0(bUF2YzqQ+Ww9*N5rwhdQxsDJ4oBI4T2a18QY_ai9YN>wB zYQkPzlw0OB=VU(VN*Xg59GNWTQa#RyZLx*|gM{b2n6&)56Ui7~wy&%ex1v*lc7j~! zq135Mftnkt@nuGKGp&jXZzEOpN=wX0)TgGyPsv#{=j&8+F{mQpn<5M>iR*ItA{WQ? zZHA8{X`Z+>yYV+O${nfD=4Q4_RIwu@2N0lJ6^Q;p&D}fx$>xYT2A76VQ`t^;Po{tq zvX+BuL%F|e(BZ^91|s6wTqe}XqTJ$RH=Q7BwcvhkLv#G^JgK6vSr!=qN}4dtp|9~_ z$TbP#tVDIHTlVOEWYF1k)co!Ss)$wYp(G>b9Y*TAcjDn!Ll2-1uXHTw-NmDbi^t!$ z`m3w=UQZ#bDWe{VNO5x8-Mhi_r%?ir+5m0=Gv~sy^w8~L6aBh5+_yhUBfQ$tI8Lx< z&!@pet7jI09pTE&LS2|RhJ9Q7&Jh0;q+gi^9CQ6$Ib8k-ByJ)8i0Y3eXT}jdzY5%X z2y`p11zUnuI_+^oe*K~-N1_!MWnP!YEnkYi5-zAYnm2#C`2ymix*|&_AA1Ge0Q8@P z1KRcQGfB#yjgR?;4YX~<-acCM)0l!k!UR27H2#LE*=_>_>-ACuZ7ZrCH&2Kvo4@07 zoD9knFgp z92Y@eU(A^HT!d?&FFl8lz?M*eu#I4fdrDkyT)Ex{U7@=XkYX}-Bs$7%V0c)Mt)7d@i#zim_y(AB6lNQBmQ?nlp|$9vpj9!^DO0EYIeQ7 z+bM$hJbTYm`!J|a3KUyJzo0~1U_p7QUpFjL%7f9!C^MeM@{Z;HNBJB07vg|IFz>!( zS#0K(V4MO`dlvu=&9OUrVm{~jL1G~~OTUeU&1fdt-|sdG>5t@miI!DpbpVeJ|8 z)Ju5g=RDhi|H&17HOqhTdzuaj7o%(6cRzjl)Y(gG#*H;}WV*hWBxp|TbzN0Z9*IVs z?X^>j)I8rLa_^BOU!RjFhOnBxn%udDBS~(Yi2=qv6jJ{XU*69ErON-j{>5Ju)TiOQ zd&uT$w=uElo=g}f?{$oWIpv(&y;3q+`0A#NW6JY4)k6ZiN&?+$s8@kIuGLa_U|q^x zsP@~vaZ%Y#>jrJ9!mkCo21?W9u(3n=2=qY7p-V2+2}Eq}YqxbtOD44?FII4XeRD=U zvgNs7+mjhHb|18SdR2?|Tm(1BpEJP{eVx$xNp3pBdLI<8^s7p*ctvG7l$!03YHuM} zXzG=){6$Sn(D#b_ANk$@)Lep+6}Rkj*8EL$j<)9ePXx&&{-4YQ|tD=B%oWP*3ej8c>5Y z4Pq#wC?r~G)__n;4RM4uHZik}Fe8J59)-8)1fP_xwKG-RNmR0mvS<7X2(mcU;?De0#DydfaY+!|UX!c= zZg7FOj-f%}AnY)6D~HWzLA}%ZHM~5@aSZ=$tW)L@t9>tv+c2Ydj9O!S*DEqNwTf6( z6GQ5FD$pE)18$ketX%R$e;#nxmjZ6qVSl8>zmMehLmU@fpTDmAv8!!Ugz8bXqgz$P zk2J}}oqb2Zbamn2W#)}3uj@tCErho%&-IJ2g>@zKxaD3UhDXXwFKaxksST&^64$lE z%U-Wu(ji%^`fN3Q(Pw7!RSq8_@(){M&xc;;M7L~+_|t1!+YcP@d-~=D(-;Zfw!GIg z`SRFGi^m9+ocmPx^AQv}>e*Ok7eqS_=?#o!s`{ZDb1Ra?g<|=V=kfgfSrXKf&s%>r zm@kh9M+1nl)Wlg`xW2aH>nUB@?~C1i{sfuqo+kOH+o^<_GxNaCS~n*P>X-l{bFb2F zn0iPESr(u6b+ZS9iBtcT?UkL-W^25b%e2g;;DTdS`|+d`l~xzWEhH~-cZr@M^6};a zn>Qtd+TNbl+-duiKr(a&zU6kSWFH zpX_kfkx<<2kS#{}{SBg^DDExvi**9QOx?;Zh=H50l3`lW@s^HLz8I9`&9K}$^hnJC zvyC*zX-l;7jBXFI_VE-CSX(&M!cKZS+!X?-p-|VVF3^QV>j00{a2ubUeOfG!7#jWQ zC-c5)&=&I9wYG$GkC=P)mZ1LJLseNi(3y3x6%C6wSgZf2iRQ_v$Or_&)KPaUZGpSz zCH~8%cfduIJi5II^TT&7+Ru~2;Ip89D)vX&PAVyGy!p{1gk%lay#vQ^l-=}EMY2~cu{5jfF#s5kG@45ueSAYAo&!Q`3(V;82Q9X{c01hbQ z)^^$C^K_FWw84qAK8vToolv${Thxb$`+4$FNZ6~%f(W&TE>EXQ91SKnwA^#1h8R2X zj?%M8AHrbBhgIWOWK+@JYun82`5-Cqe#_Vsh^lEm1wb-2o`d8A>=-GaM3^3Yw|Kf* zYf?+c;?R;lBAkvMiRv2xRy90S{PR^@?J|or-IJ~?>M%9+GTz|q)^C>-MJ=;eKo@|f zC7k5T%RL*;jodenQ$bm8(x#-Z(yR}G@*~8qKNVK<@z$JW^1lAjvW`K*6y};U1HNv$ zZa6apQ*3yxOo9#~r<8zhX4g8|)P#=Q_J>Pko4N*rRkOtbzPl zIbKuywhvR8Q<6Z;1DQeWMUR{&dqEV+=GtvNj_xMV^)y0|k*n{Vyize4vv#Jv6CC3z%SiL3DBO^b zQPInu5x1>ZEpE6(u8uAf0oG4-8vpj>qG^)ha^ouXx@&-iLJc~9VQ+4`c5X_sjQM>a z!+qq$0t3Zza;vh&MZLJ2_XO(wkX!Oq3GziPWXCAb#U4}0&7b7JI**KHFM+<#=1Kyx z=2>8z(2!zW`PT{anr>88uPOQFZd`(&+LiK%4_uWeZs^n!Xy2iMHFS^wy1Qb|w*~eO z|13`5$);jng=0!YtY1?@42wN4{)yGGLTYWTU40H{Efk6D{s%=i#iA=G4aovFyuK%L z-YJ#GuG6TMli|vOKbE{r5Ypjo{c12=bEePMBZLf?xdCBt!{fe-8KsW6g=oW+yB>w$ zpmTrVi~?gp!UTwW!K+l+mO1@hJUNoG6o?|gB`yUZs3SEM69VMHs^v>p<-Hq9uaB;u zTA{mbkh{eJarLM{&4h)-1IDJ3(v9ww3rA%M)FuHb29_}8aZkIt{F91R4k*VgQ#@J9 zdaDf^Ub5o|sQuyA647n*N}$5$TwDS6KQtO8_@nW_ra;D@0%^nvoVw8WaoqLYq;|l2 zU?}^lr#P$9ge!E!?2H)V@2Dv2pcFi?)O|{IhHQht0Woy$Q}6|EAEiPUxSvXF`lL;k znZZD0JXC@}M|l@92DJqw9f%v*^#Fi&Xc5S@6@rV>Fy6!AHoUH+%Zzz%u~4knP>Kk2rnPT6t+6@oQTs!};L+zK8fP z*CK-IyqH?zGwYZ=*v(ykvg0_gR&lN?F~B< z8SNkTEKafeRXpc41^2+K<3ZOD?W?jDFCPc-VsXi)O~~yYTamTib%3==qm}+-M^&xE zpk2+q^6Be5QaF`CZVN{&sCRkt?sf?3#kt1o#vxBzi5j z7Y^w0_F>}GX8aI=$P-npyK*v8;t7};iWh$^-VJUGxQNjgr$fh<03X^v^t8VZ-q1Pa zDZ*-D$@gD#{(C^7r&>}f?KK`lcOuY5Q@q1??-hSgSrdSztef-qyY4RlgCl8uR#5qe z8$J%WB@GbpiXU&7n%Lm%lI%*5ose`3^=XFW*}{E*{Y8(-ULj)f>e7$Mz_Og;>T7L6 zb6%eRJB`7?0lF$H`y;o|{$pB9axn3ErS@?1_#-2eUT27AyG&|Y)5ts1P#+_4DiXzx zV2#FO&wWENO#C8<0r#s~8i;g1wcfzVx3nU$bV`rIP9A7fh5LdbAZ+k?^xV?io5AJw zdVj&XX67P938}6_o5#Nu7+hFpx!X0Hhp41P! z45&dy2j$le%U;a%gk=PWq+V8RewQQpGS2S8J4}15O|A~@5AN5N_?uH4t7!JbrFwu( z9VkKPVIE+(X@f49+1kf^rvZvR)5St87jY+tk{LrkChnD>&pI7%;s~EC`DX+Pclr?` z^qqt|&jHI{c9;{paG&uOqr1_pP5v3PT@ktv!CC$&2L3a_&N}ixe0YJ^b#t#r;_*j3 z;l%_FXQz`JSErtHO_8Mr!(C^%E|5JmgVaR%^YGS(bBH_RPsrICRm$^hQ0YKNl5n@?tQ!T{4SBr;>P7u zvHkb0Jq=NRQZz`Avb*sox=KVKFNz^I;}tG@H^7Dkv}SwM zqbK3UlA9|Rz6iO-WddN@KmKPx3H+Vnix>ewNwvH7q4DF}1bz+;L(+$E2DlMD-zHP} zhXrlB<~uktcMLZV3OFi|$4$!gx5EBEs<1ZDVl8YIOf>|klMhsNfHrJ+2%quiV!_bc z>FroT5TpI%AmHihlMr+(0Uvf{GAyRzb zxstqcJANWL|3u<+EH(~+f1U$48EO~^xgDgme*^a4u{eIV+ zUzptme)#Fxk2Tv{k)zUNL6YCO6a;pGGd+XZqO)q;yBisMKH$w1{jcS;9CWQbvtNnF zckHfNAN?0Wn>)g3vz;DYB*tt;lv+g!t|&^Xd>+ZPsY{bSeSN-5pX3t^g$L$Hn)n#5 z68oUfmb$n;XD$LgU$OvZHz@p~aWeJ?v)_r$@3O*P8H4-0n-EMikxe!9jGD7na7(Hx zl~TcO7rxqf%gyG}jXwf2>X!GsSZaHqG(sIe6kbDcKK~9g24(4L z@kcbB^xzO>+XYNWVHlWKx4O7s!0Sn%SOPj&`lBNxnL`Y&W=MiSZd^!Z0INmDzV&p3 z+t!{o1(Nh`YUDXR+ban8puRHtzp|t4pJU470zr5&-;C`FfsQa=G^_N8X?nGSeZHyAw0D>T;$_h!kj zqREid07F2wJ-9$3g|Z^6smK>pU5h$x|17;#uR=g!BOck!C!j z$AP3rrQlSf&A;W)Zjjl+=<#zcQ(oN1k?SS^&>~PrZj+wyfx$iTbc66ioCM~qorL!< z^Bk#-3_^yad)e$!&(;ZDIbq5C(H9@v1k*h8E(M9OCBtYDZD_MsmMZbEJ?a0ub_+qd zy(xU}9t{v*9<-cTmt?NpRsY@Iwe2{~qO8#1^0jAc!TXN5ajU0w;eb~;q2s^8uL0*X zoI3}lp5yF^JP}+wXlS!TW)-%pHFOJ^#lW0bPemt%>Ou@~EujQXnpx+NQTj(@dPTu% zOH`DrE||v&n+rbB-MH9*Zfhw2U5FT=#;nC7$ol{?BWi1f(WMlxE2w%>&n%r#s@N1aTDhE--ZJc2Rq@sL#*2)8YX?X(9t z*dHc`9AFMgBHt9np%9&wQfU8uHucd!BNQc@Jplu{@z$-dO8VL>W#g;P#S%|*JhNhm zQp;^=+_p9yS^@4nA2=RP&OYlzYL3Bei|NB2x*#nDv}k+?@g;y9Dol-i8phn%s^A{j zl^nL@AkN{o@xM}Zw*jPBEGwkVaX0f^!(g&7yt$jcfX^0)aw!^{rHQ}i(K|Fdp8kve zo7(fN#S8I7FAzcjpWnvOsFQ5R?(DnQ!|6q&}~w>=r(Gq={`+UbHDta@3Q;-ZrJ^N&+qr= z?;NM2)6Dz*x;*dC$MgA&rt5Qz$|3)MA4fVqJLfFUcj-+QFYB2X?##)tlGIvZ+YBzO zK~i{EcUIh!twGY4?^eBe8z8?!H4}T{ob}1Y!i}#ija6(4e7gAhLAVJ$Ljb)AO>(~7 zSj8m?| zQ9!H1`+wD(wRjA~IkT2p>Yol7(pdtKo71{TADtvM z+avNuc^kJvd~zgq9o4u@8AF~HxRDSS=2TXrrlv4}$hdRDj8vDohETEfQntdJolZY= ziah%s*rj?Dn;Cvc3Ho!7UuIvYat(q^^OEw_x!2cKszBw^wRroxeMSrO&R&oDc%t$q z1QAp1QcMH3LNQMrUA{0YzH@%0eUQz-AJl=iGHT87Bau)G{8m8MYZ)C{TCK zmPtwk4uJ`}!DhAiH%Xv)K9)JC37Eso6P_W5A$*hEDU5|MYWSR7OLgOUVQ*dvy9a3d zMj}2(6d^R`Q@rqk1@1W=Qqbce#n~le)LWLeus#!FI8h`l{D7VY5k0jRghMP#_Jsg8 zQ`-p_L?Qx~Kc*I{qIWUCkWC*n)jmRCT}i3RB(|d$*)3ocu^9eZOSK5NbhblncI;*? zgrYU9D`K9yfh?F<&UJ0@9~wV3J+`6!Q8sv&dd71>Ec>#C`!3Y^Oo*J(ym63(C3hb@ z7oi^(am-{mps(d%&q7w&nQiRGClKFz;9*gm48b-&=N8XnFQ9kdmBs%6g`k=7Ju~z+ z4dE}I*aXyv|^y$R;7NuFc$i=dg}RR!eAJ`F*Q>3XZfmDZY@)>-u{ zUxrZH?}DARS<%pN!70Jw)PUXZ+bABmn*jU1cy9mWXnHOuXKH&ucvz40lLiDp(AkAe zSqt8=cHmq;iFR+^eI@G$GbfzH?Fir&D2=c0u(r9Kh1@E@woB;89#BwW9!$Q|VC=w3 z^6QsUp!!U@F*|Clw!$MhRWtVNLvP%opU?Q{ppJ%Bavk?Z-TSE`AanQtxofwMt+P3L z`x%h-c>{nK*H#}!_d=RqK5K-pl0&z#n}dPGJA^nc-jACxm1RR%G(AvyNIf`{N*4$X zB2K@vm;!O{JR8XJDEmmn&Rk*bW)#~h!@FDLl@F^VHbEUBMkVd@ zIZgO3egFNqgdlap!=uaM!_p$&$-E*a)cQ7&zh0r=u!&-OC1zlCt90W?MU8x5J@h{V z&DBVIPzKzUaffGPsSP#hEt{!<+OBU#0e`>=ojT)$;^ykK*U$pdR*ojk+YF7C2ACIi z=0n>BDAv_B&^8S?58(aU4lo?uyY0MdTIGG=g8cI7b?wjf^~&w74-bf-v(Fp8fq6O} zcg&%tA*hF)a+#e19S{&(8gdM!XbR7sZ7bz_YS=7x?=x~|`H`s_hW`08rq>-mY_s@{ zO3CxZIji*AOA-{}g)$TT>{|^9M*EGUihjt&+n>1m;Ma3j`5$kE_Jvb7k~`I}{4m2R zZgu;WPA@064>j5TO2qCgpO(m?0zJMJTd@QGhwJF>X0#{cnj}cN5QT2F+ZMETYd*0w zV%EUGtlF!~^p*rabjA7BFEAi<_jxW&x;lT3Vckp7st)wP^B>q0=s@%{zHsic!IaKp zS9UCp=czQmf%;oaGu3l-%6;q3eX2$cC$zevDC@e8D|Pa3dY7<+C5~OTq$d>egEz<4 z@m1I&p@DhS9RIew@6Q}yNY3kXAWhj5?3=P4(;u4~SV zx^SjyB(ap|Q;DHq0yfD#lZ<~x!W!`=y6HQ-=jzthu1Q&?pX=?B5tG$mkV!}_TAp)1 zE@i_b8yoL*tT-p%v~ru|03-LOSX88ff6-ucfN=nw4T!>8Ul$LHsOU_Y=ccs%^`5l8 zCe(nSGh!yT`D)g&a@FeY6DDcOZ_Og^r2>wBab<4YbdkILrAmvTA5ca=6C{}5iUYI^ z0g*!9nr~KnctI>p_GI}UQ|)jU%?ihA&-F7s8#>aCp!HHMtpM0zuD2}0{mnAqibmGD zN5nAy`8HwEE9kl8Ggo#mfbh%8J#xa*XL-KuyTaLLnmNvcdnDwirkE2I9H)p8Cq_;PH|1I3~bZ^?C%oRQ~wY!T5|nT zBg)niQWg+zfNw~EY?!gy?pas3p5e1FWWX!%{NDuywxW#Q%6t zJ>p{%8!aF2&xWX2<}C8#)XGUtT^247yU=T{$ht!;c=;gacjulvgsy$|5h$;Yw{IoI zL$Br!^A8#N!;{Y*O*N}`%?z%^=Kp$oB;evY3dfNWVP-v;1|a-$!qpjvSL9~RT^2!Y z5YnTmc8jo5Vf=+qUQu#?gjYg!IohFOEHn{*&YLOaB~X6!=Wi%0ZaU_W&FA~;nf0sI zZ@?$T(dH%>GJW@K(}A&7 z0KJ=!PD2Wf2sO7nuQG0}jX;V7tDD z#94otk&0lTx@=?X->cA_Oh*3^<;m|JU@8lqE(A2UY;Wkshk%Ki5Pwy%m%2ZO(#n@F zh3i}^hxa`4vK;;`t13b9Hd?3ilOu01H-n&%j}%>!-jnc!4GA0m_?f5pq($SO=(>A9 z6iuGD;S>7V%!TRI*l@brngRZXN8r$i?1V zN5`V?R~sr~S&JhtHWYOZ6B|OH_If}R=I_AdySckZZZ>zCo^HF*Dxa8x+jrRaUS)R4 zA1zH~SDml9g7@kVJq>W7V6RY)F9;ye-99akw0OW58eMZvN1xSpBg&1c5$_js96@wG zSkuG(kCQldnT3cs=a9zFriwz7Uc`4m0kVxCk*Tqchnp9g)ak)S7cNy(P2b9P%Y6 zuao_}fJ*7C{hRSe7uig0+D+CA?h+csRd?@XDyABEC(JQR@J-sSG*z+usSMwApQHHL zUDzCZ-xPnjxU&CVNG*N!ZSAn+ zN}a`n8Nn=*sEYx6do*b0wRt~j<<5qtAgY49URsZo2ZGV1EQ^FE?VKMy6Ra?5sz-=+ zva-+s`_o#>ZV25?Roa3DO)9GKQLNzl2QQkR^xNUJ2Ag8fA1j&A_AK&T4bt@t`t^LR zZ-SG?2sG|XVMgs6_?YDaIYf>74*o5^*k8^qFtEx`aQ+mWQ7Twm$#J%=w7%vg6>`1K z(OG7+njJR*{VsUge^tJni$C6(@hq%T#Cjlc-iaetluggc>a9J&^lICG8Y(^(s}C!@ zBKZN^ud+@aFFtSYjyBSm-qq9BY5SnC+%**YfYX@0df$fyMhQ)>T|eaR%D5(4Dqaw&Ce0O44qoU$#u|N70jz@qDdpoGv+Vl?_@XLtQ2vemmEa0kmlr&V=B+^ zdL?_Qn2F}MIn--Kt?j4;Q^)3K*oZUO zjN)2O0a{1fBK6@Cq|ww5l2i|qtOgrT<5Iyh#8d4w)4H_I?9tu)$=3m0KP2_Mt>Jy3 zIMO(9q`Q2e{Di{BB_tn=bk}uVrck;`P5U7#HST;VH~CpqVfa8xfgyi73NWg)xu;s$ zzs8%nzoPO8N3?puGgNgFbu4~Pr=wH-ex<5TDdHOmPj||}`n#)58(To7 zfDmC;lh3D6E`h%952o*41P#E}RTe$oB(TPV05)o@QJLFrT9>aq-w5A+dL=o)4rl1j zG^KhZ2(ubP4d^y1b(zb?qQpfM<7@4khlYfC7D@M&@kJXsoh7`8XpnkU(6K{EkR8+y24dWMWmtfCe*A7QR{RWcCF(BJsUxd}tGXxA*xtBDS zps|S)FcH2SMQxr|74z=owE9=>f9q*ye@q7GCTO@BATM@_bxjbynmS|lb<9+?Qap4n zTSv=^60r_Kcg3l!hjh$7UiktDcnvaXiqOZxLT}|GZbMUCSC$Gk&VmXX(?w8HMK|?6 zr@~UpqZsY4o_E^5bO3$rwZs{KNb_UEw3-$k)Lf*UTLwMs@{A#F+-IM4OXYniHdTw| z1btyRtrQ-byg)l_#=W`iycIgo6=iy>$9i{q-lH>o=j8sErc=#wR_%N5b~0`TRF)1m z1QqcPnc*)Ad|9&AgXd;3R0V?Jz|j`Mw#|&UJgbkayTdw8CG@vgHluZ!Sq@3FY+w$d zgj!*<>Ux}RxK0?>NcoYmkrfuzdHkVG(?_hL;=y&?qP9O4#JU_e(Z&lMb5t|Q^Yawd zL_xrYXIYb*2cc-czx6uTR4?fR7}nBV)Z8wST5QT(yEzg<`9SzHeLt-g9JOGHOP6UV z<(26ocBg}z)O10&l4(?L-#RNSRXGz}5k{N~MHprWy+;-0+{OHz;K;>IhPvqM+Jr@3 zaT%l^Q44Y%n8G$KN$Bq3k54>IiA{!#SS=oX8iamWIw`NNb2H6&T48(dfww2T6h(^N zw48nLghVX>J(qCXzxroy94(d|}>v&wXL+-59HE6Ptl*Mp1vYAN|Xe zg~o`ciQgK}$s>)8jZ>OVPHbrdI2L-rQzFNJ2onad?9B0uN8}xf?L$AG5eW`rw$LeZ zH4=;;Cv~oSA6!n4J@f7At1gvL^TCB~jO75ZNcf^%?!QC@$DUW17RZG5Z1tvpc8u<`{mu+EH-QQ-HZ8qLk zI8$t%G0AwOf(H%(oQNs(WP@%kf5QO5bKPjv2hgcoy6Mlo{O{mA^m~Ms{kbiEO-Mi3 z@w0qiuMNPRk&F)wNcY*}2}tu*=(684BR$_aI5?jAVc_}LeK_q7W+a&P_%H(iKihLG zC;{@)_Mju7J)w%~u^`j`{T}2C-z-cU`(UdwC2&UfEeH4UC~jn0sy4I}GF!9HZ0O}w zT$;BO>Hk*Ca8$@;@EdNtNe8Q?8FW2_2~Qk75*ZbC)oawdp}F}a{GvahIaotxy!c-m zOtYQ|&Q2a{xA|wQ+t@TtbH0Ju`g!fY^a4z!1-ga}wiK`!GqeJJ+LQfgZ8P9R&)hDt zCu)rEHo$NsH0)}C&lb~z&3;YiYH7dE1VojfG$(7~R08@b&cAgp_rwNePcjw&{g3w= zU1y`Oolt_nTJ*VIpWAD4E>jzd-ayX)y9(=xr0x_X_(o!I{QjoNph1Xb+2lt`i9JNu zpz$Fqtkhl*%>~>NjhbyA)|mJY;-p+U`!4EFJ{#ozoJpl7Xiax+bNp@h>sZl5jIE#B z1*#K066}36bh$r%?`yML0&+(k3jA82RJPvUy8_NofHY4H6y?yz{02Z@X&d{ThQ24X zy5m1;AnnJRpr6B3cF4pK{`@HgHq`0`~Pwx%WW_o?aS?(=1!#ZzxR*%#$O}-zTQK6Lg~l1em(S! z8qaUM?eE@LQRFjy&&fXJCU^Gcy>%vP20aaS z38F4el^5*$uV``Nb}U@}0r>szYZ$xq#^4=L$SpkgHCy4|ujJQnz%T#Hm;ZC?^Z)W8 zUKoJB1D5@3Ws?)c$+v#J@GaNntK2;C8t8``{QDa+LE8WSBU?;T|34bpLaXy?I+vTw z&~yHGDx7#B@Qqo5DE!Dn%VWr(4y~B&LRjwu%J`;{jjk=|jh?4bK5ju3VMO9(uBd=8OL%M`vUDQyhN+F?_ zHgQ5<(vQ`1Is`PuRBho)D|v?%e&~X>6!~JC3PDIDh=`bgwoAp#$;La`)2fgGPTXQO z5{yeD2M@Rs_$~x~u|A%wgb}_5OVNLzaWwxmY1f2z9E^J2pO-m49D>jWpKVv83E`VA z82K=f6f~HxhQUSqhnRbJl|%H2>0VBmB!-4^s9^Dkr9Ndu%428);0AJ&P+VagF!afg zCaQqp5mF7Nu*4~XCM~0Ns7@R#c(%+klE#hjFomAnOlg-PAlCw5js}FQkY|b5BtlOz zF?Cv%n)(_qm_gN~l*o!%F!v!cs0v2$rR*zVGRA*G=9NJaKUE>)5I8|h6YOw@KTXmCFi|aYoDgn!zx`4B4vef8 zQ+z6G&KGZ=p1~KA<-KHBphvKziP<$kLdLLxFGDiL4u60#CNLLm^4%Skp&J=(;2+@* zt_{JD*4kiTrWG7M7da39N0%rqGw}y&D>E1e=85%u+?F_T1Y^X@?>iuY-j0wQTnF;` zemEqBl&4P>whO2N3UYb~uEfrR;wzVm3Maj=?_Fd(e+ylA-3EMDKiqF+92S~|S-~W@ z-Vcvsbgj$*j_o;_Vah89Q}^ifh`fM_cd7oek(H7V*b5W@6WBJSk$`44x5`DgV7MEM z6KlosD!@>NL0{NQ2BeFDli?G`CI!P3GwJfGbq;&Qua)#oVTmx}#bu$-6-#A{iQ78! zgKJcg0mIZAgeRO?mROWbLc9%02U0{(1D$z`3&3~*h!d@n%*0gI1_(8+DxCl zboFjHz;${oIKn6;iMx*8(Jx5j#I#|k=oJ7RBezkkhAB@YAwDKdQRKnJmwG4`4KHCk zzvG$6WmCF;r~OFU;QEMpY^tX9o9$TT5rMkrI#0*8OFQjzCN5n0_`tfp-!Xwb%Z@CE z0~N!KR-};_0I5aJUc7LP*G~GBZefgefMg(-6~}RzvSvKLy z&LlnmA^(^_3eBbpMP2vcqwhGf@?MuC8;Jzx7NtZU=}G8p__xm2ep2}TFTOqb$?h%( zQjusUT6W#*lD8kspZVQlXmI6=m;td*7=qt zj5*eBRkvk^UWnDiO`bt_KI^DjgU4H-OQe-|yXtz`Rhg5FJKl?8Vpp3x9!v_K`23{J z$vfUD&tH}0zFF~3_Z)0uDoS;jeTqHtgGd$L#0W+mHd3gszGHQj}3+||>*V!{dS zCN5cPJ$Q`Lya`$`S=LMxnbp-von;qxt_{)pU2o6CH|*S{6s_j_SSj&~gF98C7b0gX zq$I^t+Gwu)QR^u=MFw!x8z8+(}-{cV$S(S=xNJTNkJ8lq%vLSZ*Wu_pP)F1zvZBkFsCjvjP@@S@x*ViD;hOx+{&c4UrPc=%6# z{&&i^y$nOo%zZ_5CmMg{gK+MJ8j;vE6t?}&yROQ6GxS1&zIzb$}< zTpva2vx*|QvUjSCH}5-5wpjjcl}V?L_Q1#S%FFs28qrV?1(O_dANGDRFSsnL7n!H0 zURoZxw!dOZcNCZ{MN@bU7c@_Ox#omq{SYd@(G{jFS}x66=eoku&+RaQ;nJ#TH8WX$ z&jeBnyh^7q&HRE%6Ex#m#;VqFA8q4Jq?1Wb5)X1&{~&IINN~)OvPer z-KeLiz=AK{vi`~G$s>=;a_84XJ_Ez*Fhua^_Q;_EJ+w+kO&lhz{kz1-fkri3!t(15 zOgG6XBq}AART9DZz0R>p2v{De$DBNI=S6#vakZ{19O-p@7^`{IO{+lj@K?_Eus&3+ z)gN&7b93~VzlHDw3W(;%(zW_me7WY~HNlfdKzTqU<>-<-5y!S2d*+lT4l?J-1%n^g zeQdr%O}Gm)uKM4$Oq>~g2781%o_u_Ae=k_Pnakq+L(qf~zGWPY)|nxD97DICxZ&F; z=P4!X!VJqg`$oFJdGbifNpJQweKkKf7JlS|x2I437q?xsYX0~ny33Gk{s1O-j>1}p z?&8<*zMf=^b(6hs`r=q`JA&6~h8l!CG*iJf5JY6i?(fhlcYuGytWDUnR!H@-Xhdd@qya`n<1 zns&8J-W>tWpAiX+42_lwc@2&hgJ0phYjE($d{O070Jn@>+fz7oMEo!p85=j-q}wXq zwCjrvFHJi-)~-CGtJ<7usFY|3EN6qu&v4QZJWNRle+VJmOt@0@@E2fujBEQkjM_YOZTe*O>!uKLtMpmm)Ma;PyC@rDH1{x7(0 zZ7wpBGkxRDSCMNua9V&-1P_fRiP25C`moG@;)L?DjA|q=puVReGn)d1!t?LZ-7RXr za<;WdJGqTF?`YaJz<6Zs)xbv6x?t>g>6dFZwZu#c22BSAcei&rJJlVy-QSQZPhb=( zC_#R}$N(|!iiaSt*Vp(CIe0Nt_^bf&<>$7Wt(jP_O_9xE!#v7gKzy(JV#CXhftW$2 z7;hx>9_KO_8yzPu@GWdaQkbNNW&tM}9Uv;5q! z`f6K<@%j*mUce-oa`!HBpiccl1KrYttWW)c*O5;LYJtcbO#Mt!zjC%|=t-J8)9;t} zH@pTZEI*n*$#~7rQDzOle!1q(W8x{@u4Ibe`a2ohq4M$avy=2Aqlkv(v}8Fw%ZI|3 zjT}?IhUl-zv?uLw@b&d-N4J6adgf$l3?nt=-2+4;D~S3a;`>W6^A5xeGBfi@{_`jf zD6a@$xp^49{)Q4+_hWW@x7U|i_wbtW{D5+@*_y{$z#NJc7$Vc3@sJEUr~w%8OVw3$ zZT=S03!Lk^ffYgMNe-hhMxeYF4z(P_U*sX;J?F|+Jf>j{C%fHz0ZbZz$G~449$-y{KULF%{DbSLCw~%4a zpxcootm}#a$K5de-Bp6x=!FBh5sc`dI&I3As%znq=aa-AI_<*GSbT)=Kq?WWeL8Ze zAO=0;;`lGP&d%KzM2NlXiVK={tsopvvCF^|C=uvdnW|b4IbY~G$7J}paO2GkCs!l` zwq{dQOJwR-&NdY!QMBs{1CyK#kiw`Vz(z{tPAYykzg#o+Hg%F1=DEYf;Wg3aB~R|J z`IvcFW=6s)f&~3w&wviDFp1Li>-ZYq1&mJ_t~-FtRc*LY2{BDnpk!GkG*-BPi0>~p zZ21ht41%|C)f-@e@(Ki&^DZVTndEq)0(b*>zOJ+BJHCn=w(b&syyO{UgZtFKXH~r2&y=V*C9LedTPAP(Y#E zZ@cp`^Abp5Stc08M~`a-WjyTva?M#I)2fi6;V0KSUWL)m%BS8%KJDd*$|cMK7y3zW zD8W063_R8G{|es~e-0*JUJnz`=(l~qk_8J!-!lP9Z%06Udyj3{Ssa>lZfQ&AXG*WQ zfwqoG((Bo~_{>ERI!K-5QSUR_Oi*PSz<{f%_6?a4lK0k(;`a~}0@G$O#kS@Kb?q6u zUH<*IN6w8KJ3YNIXq|$i;)JE6mhABGWX|qY|0UM$ z+*Dur*@kMe30(Um`UW||Qhjaw^6z^zsI7Xw$Nme2)3fR(+W$<)9D-Ib>ynk(sE8&} zQ!F)?m$Z@!oa?O+-?gcqWrh*{N5EBdahZ~KB@BBIlkojZ;<#;6?RNt$J$tkBjU8D! z7_E;M)DrmqiguDT9>x3veUOJZp52m9qkM&!89Yp75j?wIZ{EMMvuD{*vd_kU_kkSF zRlBY&4%g?hqwB5YH6BcXzZ}ORbMi$l+7e2O1yw9cp$%uVn0pwS`gGo5B*05-AeoEY znqRS4F-&octF}m+$-5NwMAkV#2pnFw|37i6!li}YcYhyu;nHzE)5zf%4T7lOl@`Vu%@e)#_0ABEn(_nZ+6zG72stYA1JzkdJ z!cWLQuSaqbE+yzW#E)60G?k(+lyOqp0sN(9gyH6UOo_-t?m-A;L=#rvuD#X0_5sA_Yp$2Z=~|-Vx$?sEZLhsO@SHF~i&zOm zW4~3R+wi1dsvx7?3pK=SlDt&KY=j#`3XbLNJYBg2CQB_D=Oc%e!{N44Y}@NghD>wG zD+_|8#Dc(X(v2KyKe~YT;@B9dVBW0au!oq#ZEh;Oq~NG?rJiNsAgQ@QLj zmlZhRH-}qI;mq=4SS#o!$oIyx?WyuUrnDa=EG6SPPi^$=^IqovVfxE%o2%m@Dy`7N z#qaqyHOKRaP8%y>O!jqwrXpNBu$$F+&+g*11gl0M9JegFl?twlPUH6h6@(k?Ucp%P z=UR@5w$3LGem6p4=_1lzFgnc{t07$Jc9)QaY}q;iMo!=Z#nN#{Jqwb9O2T?3PU z@Ee~ybk^@1CaLM!3#*l8;7>C3DMO_uj5#&D*N?Fzt43hyrYB<@C(p(ZAmSRl@5uOC zY_3Vg^9a-|zUcL(6pRTsmo~x^#s9LCYJPhx`*VHlu8fqp=2iDMJ5Vkd+vO z36=OU^V{04nqO1+@*cXa80dF4O)O=~s~M=^;g9(VhSLEH!dlg%74+jcbp^v+NaSm z6)9@w#Bs6Kx-6h#l>(vVTqa(kjq9{gbad+|(f&FalC+K_EjPs1*Ejjjvqhpy!{(rS zCpvM@9k{Dz>Ju*_Pmzjv+PINij`_%rgzryu@JbNuTAsStTR&cUKg?WCWCpFGE!WV! zjk|HC()csEblOml&m-BNK7wM3Z4@L7R;p4`IQz&L%qZ^-p7jt0B(y2Wu8F?cVLm~WGN9NVuzb~tU)f?W}Bj(Daz88^q%uv-?s51E}_lpv&MZ^ zMm{#}_B^VL-^8Hu+c8XU9xV3>nlnE5am_=5a)KLi#9!CM84HO zdY;vMYpT)f@Z}yf89(2fE$0*QcxI-@lP;|DxQNS}BZ=ylB%@5Y5j-}-+x?x(JzQn< z_yy?^rDqR+8eQGGs6*Rbenf=PiNtC?83TBEu9VSa{tBLlwm6Qn`9WIg=V)7|WKr=7TT7EE{I>s9?B{^Kx@-4ZjL|5ef=K+11 zw+fwFN{&E@tNrD5t%}8z%8eU&z8Q$S0H_7}YgtbWLvBIfXTbqJK-NPachqW|!w?_) z9|X*~q4xg-6& zK8NgWDP23bBi|p!RZAr@f4S=$LY~M@U^+@zGh}@9vjTBylOqydl`uNP^HKXU!SK@C zC}K{`xKnr!%d|v7V&9IFB%OPR^IS@MT_9?|-@8_?E4cME2s2Qbl^z`VV?r(u@-tXv zAKo6f*CLB?YPQXkHqKR?Ce@c%(L{|w)S+m$6(!@h`U+&?9Q`~~(Q-lYo+RssG+k#< zWcR8}u&qVrn>fMM)a&0guB$f=%i7#NJCA2+OlT*3^TNjM6c?L>U zouzoCR?mprteQeJdUw&Nt;7083n^E) zAg>oRQC@wTRI_?1h|^Ut?UArB>N_U;PP5(`^d z7;Qx%x1p`bU)HWK6)4`R=nrvMqvTGCvZvap5uxFU1gdBNWYg+D6fP=?;RKHSl<3ji ziq)AjT^5hi+?i9uX$RHr)-u|fp$9`{oXFyyVz_1oiiD}ZD>80)r>bi%d1vJ=eJe?= zr_gcI>d|`HU}Ti0u+%1YlZH3Upax%2Ll70rB1l}A;vz`$uCBDjDsNzKzB0*WI5liW+<{z@z-(q1$;bT1tk~Yp9l8%wMNCh+E@i|$g7s1 z%!cmR&2EPL`NGzlODZ>cHontcV*Z(bk6gA%POUG2Tw?`|pArM6%nfwy-BII)P%;Qx zfCcns4`NZ~e3I;~6U?^8rd-yq2SsmVM;N+85NuNkHm$S~jq;76Zn(WTnLMh`0BGpRE_2a@zm&{5Y=$7G8F&PhL{ zk)zFh<-R zlb$LcP_>XZlJ=tsGGFF*wl)|3N;2$z5wx$umjvOgZzmbfH2s0@FeAvN2q!?6vpGn} zQ1J8>S-sewFzrLHE)3*m3oG6=-lx;vL-&9Y4rIzL>oN4D4Aap=P@4sAdjof{heQys zMm^&YkwvtAcbB#T{09F+u=$Orx+knZ%6v!TJpzHRR|T^;#Iq)CxV7X{mvPr zjXU_3g;vwQnGnedEgT%$${Oggvo8eD0!hrD+IKHE#U<2%q2e!V<#g5iu~<1OgwqU~ zyuK$$$&69XnHnto^y-k>T}U2e0MeS~C$&@5D_FE3NF-xbyJ5Ug=A;*%Hu#u`z6&u%4etlP6`rfUrAM1GhcvVV#+kby zykUb09#x}p$@sQDK~hRcM6ak#o5?jPTrQE2gl{r+Np2_)oEwwMY~f}~38GutwNRgF zf)Zqj2x3Wc9~o-bU|i9d<8@C0{zEWB&3q1KczG4|r`2OyPAa>k_OP9yRFg~S%H|?L z0RyYx9+YAjr4c~syHDU*6yB8~4-C^%>>R{O+b+x?C{#&r^+RmPVQiJay|3N4KcbAz z=kvk;x4|lCvX6?sGN#NqE_;~pVu9`kj8}cm^YMVM4kzf2=0C($UQ~03Eu`Z5SMZj>NAds7`N)%BomrnQ^Nb@12fDH61bz63;UbuzlK&leG;fPZHS zs`LlJbu@CNAh-fRl%TsiRa!l8!@PaT2?ITu=o}&}atbk7eY))oAdy>&TMV_6 zV?%r9f`2isiVVP>o|+U?@DOiJh#scC-LhZSuRT1)7s7cz%j;3YZPF$DVRJlkon?t8 zxdw>$-}H#axsQ=bYcN+CyuN|Lwq4lUF*#unOxNQ$LFhK~+1F!MNvm5_)C*tR$+Zb& zIPEa1*v=mxBzVayf;8VC7AHap){e3eQL96uzXrqi=sx6P-mn3@#h-R;{7M{l7H-ng z+u$+Vi{JkdATC3V0T5q*j^UI-WYM3UVuG0=d1w{9iiV?nh%zz6n>+MAAlH8!$bbpU zoS<$se@%SHNKXxHJTUGRj2fr+4fOPP^$j%cL;?zH{7BC|CI*$yO%-KF2`{Q)MJRdu zRc4t!O?sa!uS-$E<3EYo*n`py7?MND{j?irbVsA#!CsZOLjb07C}_Ct><9wh_5NkL5=ixR3LGJm)00OV1L@1eY?u< z7)5adP4x4_d`e@|aY#yHex6lh(N}{JXEffDgNK&rE9lyQCOgI?$Zjcmz*@kVsjQKC z_Gu=*H^eWL5%Nb_Zbei^uzUH~WZ=wxd__7b08n*hY9|>auq`5#<8F>Cfuzp1Q!CI> zFMbZ5F$UZLK+dVjBgl>Sj6QihJem%nM`qvgvO&?P$blv(Sh;a5-PE6VP%P0B7tcr# zdyN?RBb-v$Iv5mr+RpZ`JV}zI?n9wq_dkW_pDTB$nM1VyGj#*XC>am~IIXwDxB40Q z9y#ODhT6^MZs!Pt4Vg{m(#1J#(FBQyH_0C|&37+&S3elzmF5@% z7p|9{+dk_E1^6XBCf(=1(PrsBqRuEK$e4f)hk(y8*v?yk+RB7ncjK6x3zJu9kD7VJ zeH4I&Md%Ut#k#ab#kO@^Ro!be?1j`-IAI}M@T)O1dP>}9R9w=scjRBVjY2^30oqJF z(qo;nzeQfb2<}d!Z5#@$Ck`ss=9>=*TMx$^>v{K3tJ)J3O z!Rpr|-u2d?pvgXQ7431itvso%>F1pOjHw9L|5HrGXNTm~hf9!G0yPZ5bhusG&}$`a zTn9{kotW%1`r^oA+3c!r=to89q!ZS_CK`}UI6S)BH&$ch zxs0zEVG!D)R0hJcj@*bqcr=120GZL^YiS1NuE4`6Xins=P!k#eh7cgR6hifKfrmNeYUu(po6!e z%pPbiTqfzzIOw{ps9bAjf{aft;wQGKp{6aXCnRay*hJWXqbOCStZ zS_vq#H$5Wsy|+lKr<6re<+t>4i)le4Ito7XQGQpxJ)#qBju4pJXm3rnK>Dkx6+y5R z5618(=82QeeVU<+Zc|<}hGAtL196L}-l+@~M0H^!HUgw&Dl4~8A=fp3HC@`dO(kL> z28rVwscKS61azbtnXz%1g-~(<0lw^AAWc6{);ZfV?>^;gah&hfV zX%J5_7YJ&MCS(X+zGb&$&35+cf^0z30IozhGlW3J-`ff^hFZTGEG_+H^K(@9U z^Fom&(o9s*HeJ9g56VX<`PpCjX`hc=qCSQmEtcH*1g&?;6ogjG7 z8@~I{;2g}nKuXf+x2hp!<%#5ka?<{nC*!fNB8c?-pHMnYFIChH;Px3)MRTx|M?h-1 z?SXlL+X|TZT;ASiLl)(~cim-s!R3HV2We)0)#I;>IB^sIAPs#l3b*pH^~+P!Q*gfev3 zgw4mGNY^+;84p{&l}bxm-Ke6j12o$!as(WZ5{e-Ozo3lVP$}VFVk%^p^mCD@*_y|H z<#vghW9J9>z|i^vEwLftjq3;C-31FkJb6F6jp<7eummXX)tHKKH^Z&uo>bu7zVN$STV^Fbc$g`Ry|c^d?bN%w zO1QDdcZOY@o^3a^r*8TSozTdJ-C-AfPQ3IH&iUo%S?njHa%)8p2A!YgH-NOIq7+CJ zc7P1%!`L_o9O@l>nTP!y9Axntr4EKiJ|K|s8jiUn3$X8{%PfVW(lGOrG+CJOnsYb& zN2|kEi&e^&C8_poH$Ib;{@v-t7k}9LpRphBeT-%l_i(*tR=qF0tt*>;`e3EGHO;lJ zjzQ%FlkkF%c=cxU9_(;BuQEHIySj1y(J34LNVWedewS|bJD(4?CarZ=QQi|0S-CFC zr+Qb*oJ5@#9r)Yf9)V^f)4Z9|F<84NWd7D4?2VNcJFjXpRWtZ;ljr^^BiT;59roJd z?@p6z%Ks=Z-{i%hGr4~AWiREjc>_gWGhwCC`_&(+$7ZaorUkygv?ef!K=^&nUyGxRL2{}?;(@5mTkGv zDBVTezr1hby>)-EOJx{KwP%fgPhozTHZCK_%M6Zr zN&H?NSndgaRrhzN4-{=)srlhot2v4K+?iF0(^1u-KJC8CwkWMjdwFUdH(Z!G+7_fQ z7a6t=$5_eRR7@h9aI?*MV)7Mp7iHX%gTm;_C?9+hujZ_Hb*}vzYl&~}T8Hy=c6y_C zjnF#mNwpkfj=k~YHiH0O#VgCLhdZZ?(ay1_)v z&CLz-PTQW%PVzaZFZ}gCfUS|#Q_x-?%NvB5TQw46#HH23TIg>b|hwZ!_Zl2{`r1h9$be!;M0=K@4D>_@w&T~tsnTsHg{oDsyR%rZ6XBLywA0sp}*`J z(Q=Hx?;J!(=P#yt&~twFwHnr)nN@6+r{#Az!!xVUDR-jD1Tjo$yzYM(*|RbyrO_+d z5*Ye<9lP1@&YZ;JHTQq?2pR0|j_ueyGb!dpH*TsAJts}K2Vtz4qh_izZcbYJrhGc_ z^+lSHz;wJUz=$UtuM!J)imW5l%q{k03sH{8N5 z_iuT@HHmxVJjS60qptdtH;)R^#7FNZUiM0!3fF&!3jA5zfB(msRRaS9%I0BLeQwmn zeAk^kP}HKVN8F`ra8#Sn@yj9yAm2-GQldHYnk@SW8K>0LG$*8On=YK5WR5S%nU3Wt*^(~4`^y$ zB5|IISD_5ksU>(xR1d}-^JZ&7rAh7;LKLvgE?wn15TJj_;>CAovlETX(0Y@NU8sGP z+R~7k5A}pz>tCMYTl-(OQcyxRA!qY>#k)9Nh4@t2vF>WDx9*LFn+~4KA7?}BaW=g2 zUH6Xg`SVN#vwBWm^I5({U;RaDB4shWuX6;h&N#>6DX0MFrFsA9^8K0csa+`7Rf&I3 zlPaMU`@5&iNgXg8r=&r#naUu(et@Ka7WZrHG=xQB8Os_rNChCyu|9en%g z`0sO4M-dhBe^4(cmWP&M(36`C)3193b+gHo(RPxi`n{91$>STDEGAmeB)6do?Y)lG zQir#{;s{G@7v&uKtcMnwKCSkZxoE{>s}{&p9@6%x@^8kQC>7_{r;X}3{EISr zFYK4J((}2uEN=^aI=uKX^#aaE?;TB3=8MD6HT`D$AWs{)ZeXyQF^w5v8Nz2TP*d(n za(rPG!Z(KhZ8u(-&h$TxiqxY_w!L!ayYyhJsLaD&^+F$=Agv_fyX03f^EujA#^}c2 zs6rmvW*{bVg4=Dn4I9ET3^JJyPB|LfZ!2B4h1~ivhG5z(jqo^6&E}HGYZU>1>~n~6 z>DdC?=uP{YPDM>tKUwMDlI`od;Z#coL#+};zKq@616R1-;NSJs&*$69Tru)VdCRGg z5D8*ip?IH)R86@`e3i?e*9$#DT4BAYz>b+CT7K5bRiulU2g@?SpPMqW@u6YobCXfd z6Z?hxXq!Iqdi+Tg0wdwTt&7)2XZ>lmd{a|-Q_~bB8Yp>Wu7!8Kwd|LxPC9~)a@y`0 z$l@=6>IvTfWp16G%k=U-{g$|&pdLR-`K*y{@&)7G-BU)EnS<{AWMTaK{z8OMo#*8B zc3#paOtM#1v~#BtsG}@_mGp+$q?OgEfN^4aB^Fb1DIo8L9^Dnx-nV-H)K{r!`qrS% zrCYLKR8|<6Ac(?TO*dZcS3x$Pe2=yhn&Z6vxR&y?a93=l@3-dg7w8 z`mVRZdOv>XVcgW+0>LjDg<=+Gw=C66H#sJ-Cj~E|xbV@9=FOV7Ef4isz>D`H!qi}9 zL6L6WPk3Pu9TU`7EYPCTF3T5x)=MX+_mL?6MW<*&HPTcl(;|c)x$yKtNvTzcvt(0W z-i_JF5^VdvvUEA!D~*z1v}AbFRaq@48DaoF)bHKQ5-_&4Co2Yr~UY zFaBovov*m&is2T2AD_L$ao@p*eW;UPI5pMAj7)`BToflK)Gue8x=E-Cx!Epfs%BOBcZLBgW6l z^wpDJtXyPt{->pCYR4|WPHknTt)4t?@gHZY8ku6$j)H|RC^)6F8uwS6*B^DU;6!G zfM~i}EtN5$Snl;T9o;!6QK`~@Tx{;rwN64-cj(rnmYN#XO|EnAf12}4JOG#`2flx> zV;aM3oAI3`@iVK!FQ>0M?E#`?_vT>6o6yK}Ho)Fj&M52o4Fn2KUpuifjopO0>;V_&HYed@Gri}B>Z(aMCXbRZwCu@kye@ip_d zY}pnIo~;&~AVSAG5n}wl=ezD(ogXPd{>arD-}+DQNXjo@oNev`BmS}76rZFZcwo{h z8FiZkj*{3+u>~V#FGd<+_R{y~^vg6!*)Kt|tX~f+CXK)Nuo&96qN@u!3~7=9D3C4F zn(h$sN^jTm|G3SKoC4NNePqkQjF!-GIvcaSCh`(vcL<+nYrkRaf#bf!iLiAC4y ze){lu`+*eHze?dArF0)_O_>)nXT_@0j?`@2heHwL-CGTY>x_`X(H8AjW& z`sMt0yF<{FtQ0O?Wz51m>D>J_F0l%ko?UTaH*w4eq>7uL65*z~dmW~1Fujm*;QGk& z`}>#uW-L2%8a%CmxSME<*&g_YC|WOmJ8~VdgTlG0_LHaDf6tMRz5=^(WrNCsF|yi4 z>ybAx)P)z5v)9dNJg(5Oot(1^bR5Xnc^>{_3h1iOlpS9&59fi$qRcxEwmR}DUvTSM z=FZ*=v<5wOR$E@be*M6kD5#KMFWhr9%eevym-9EN3RmXtKC1VNWZ{;F$hW~RK44)6 z-pCu>Ef>_K2p`mgu6y%*Ix&BGOzU|~92A1jd&tZWklgLY2~PHcn0DiEv_(Bu+~E4U zr*iB4Oi#(cMgeM^vTU~#hT5*8q>l7AF;V8ca)Tb?7GButX*cdCZk^)uA{fz_2>p3| zjYPwjZnLJ=F(fM?|(8`lhQy5GR(aO^W8Ll+i@*A zI(jH=dxNvspmSyw1hYImJXF|6uAXJ=?ny$6A2acsI}~D$iho$=oLVu$NQf?f0}u=1 z(GrdH%W&{-_6e9;@f`aNg@{8-Y*GvE*yr*AFl!>V^62RMr@toIkK27~AJ7Dm`oTQ; zTKTf7myhOtRJ!`;Le8YqcctJ#Wwd9{x?_{GGntGlOXW?J}YHG%q>W2CpREr10 zzQJ#FscaIQ;C-q~dk8{Qk3Ol_A1~3+`z>nG=HWD^DXw=dJIvZ_F-^Mx*OG0?u88ou z>na>!1~?7bEuq;XBDlI#T#Au4Df0U6rjYQq`l0TpZoE%CFlEDv>cP*_;cKRb!DMl> ziQMyA7k%88sow1g(s18>^vtRqA;Asn+n`F_afjpU+cl(}OSk+#ti5?S6m0uGZkGy` zLe_RFTM-e4BxFk^$(}4FJ6VRY^$w>jq_)$QIj`ZiVNdq$IAsNQw4^*j9bl-C$~KyQ?79 z&A(UW%eNEJK57YZLAAJTj9bNp%j3ws0Ef7t)CRFky%1ZN1?wRoI?&a1TnOR~(z_IOY&cOL+{1w-gVJ{gm!m-Y z&~k)g&U0Po7ue};J`HmFK}@uX*Qpb}e3K!*KTFegYsDao{p?v${9=JulocSTZDee~ z>$>mGTwbbJSIHRy(X)_ueCVtc$UaQG&!4P}2quSI?T#d=G@Z-v#1cRJa}Q35ZEoOg z5pl}`xA0CW4&A12S0osQ!ynZ2bYi3QUZCXA!`J$@429`p2Gxp?=lT(CB*Q+Dvf4==+g z=1g^44&XXC5b_5b=}0ETQ!jkEo2FAjLc&0&?)!K7XKEL+M(`_;!4ELb}lZtP z>-x#wC#5EE*SF8cYl2Ta4L@={<-aGBS3Vs)`4pxzWv<3e2>#KkE2*3VJ4iR9s7VSr zGj+vMNuL!Da*t+H&;bGxlsW8}!oX2B=TQ2!p__fP7M0pGodI02B$Z!}8<5L=CJAWB ztMj0(Uw9XvqDvPWDNb9rZ~#00fuT}*yhzq>g9OiMt%0!@;}q44OZHpI9S)N}15gG( z)^JZ!fK?+D1u%}4FYR07c6bbpEFi%J=%;6b2H4~LD+*un^C zJqVbe0R~lUfQb@bl0H{07X7p2PAR`@3l1T1ZJSf>D=t4ck=-<>4~dW(pc22;>UDts zFU0n$X^`1Hmgkc4IYSwtL}nLkF8xgBLK=uI#5C2eFdrZ2{E5WX7bN9dTfub647msR z=_sF-Z*^qT7XgczaLejA0A;o?xn-sRyz5AdF#(06c<9$%#IvkmF1LGucL+VeuPF=6CqWI!h(`J7BMpC z1lI4-CBwT32N^XW{bxD&Q&#qNao}W_Vs8uVlbD}Y{)+|>oTQ{m_iXwy)Ilx6LOcL*v^X?|gk`Ipx=CWYZ3sf>fUtBcKC@Nc|0a9`@REZhUXi(T%zH*mr< z_yV9{<;$Tz=E2AwW&i^3bDI{`E$uR(q zNCBde2&^{hax8ee+D^q=D_1O>LZ0DrF{Xt=OJfMQ*+uFHn(7S+>X@nPIc zJ_pD6kprlSw!nl(RdM3*Ao2C%&K#rmNpcq!!|xU7U!S@}Bu5yAiry7jKI2o<)+;bp zE}4~FDp_4!1s^ikbn}CV<*4`>?0xf{K=wP&*cjrKbAPH@S7v7iTz;WSTn6~nJ}4Bb z*&H>DjF>LFEX7nP@?83`SX+8XYSg6ZG@U*dDy3XkcIseFG%jRC>2j zs_EtFOP9>XeZxl(u7{=8jXw606cc;hKv|Tt*W)ZFN39ss3N32xozI%`J9C{yn=d^r zSF?c1o|T2g&yJ5JpbNZ(g1$~(Q3>k8vQ(qPqQdMYDZCReAIt9mM+=ZM@^n-v3GD$V zb4452Nlcw{>VoXBf@1&x{a3-p*+2skMiOvcUz>VeWv|=ZjISK3qXNm>EZ_gJYxqk8 zDXXk2o#_A+>GDun5#YCf=^gD9rn}yx1tW2;SWRO{f!tS^g3z&I*ikG8Y0G+xnC^5 z`p~{`i^qh0YHt1qNr8`wm;7vESJYwE2~i(12hslEE2Za3I-sWkUK9s4G+W~7S%oW7 za?uO}a?y@N2<&|YC_*4jZT2OBKo-q8->m?M0f2gs*oY9ng~6r8nP%2{cofo~Wb{Q{Ld1%NyKC?IQkT+ecz) zNpavrP7q5;7+~AK5ecRjVxE~=b$7N+;+(Dsf;)l=;6;^sT>Y*_CiK0K`V}&!cXu1G z$8qwXjHOm>ekISx8L0&$Aojn$RDbsm3e!S;bqt-2-RK(}4!1mv2&(SS)zj^GG)i%(C}`X-+uasBbqmWPVh zxyz@6$kVP_BtOUhuZvY75mMq?QU@3_d;&Z(^ge?LRB}pAWE-Hz0&r9HrRs@8VA%j@ zT0o$n#>+%W!=UtD5e!`UZy@>}yTM-D$D1BOLfcJnpXNiA>_o*7Ili>;s!8lHgs@bg z=}}&6LA%f!ew~=#6|5zI`fF5L#L}GiP?VG*7C=roLC4l+UmYAU;p>r#pC{&R8 z45xpm+S!sd=ZP`yv`Zq%?E`P^?5wg8KGao?(LCBEC%)h*w59N?tJY<=#@wu|I>Qy? zpPWIAj~hgt*Oq?ZJ{`uZ6)$*$B|(Pd70npD+%m$g7m~5CHr+x^MdhhOGnBNEmhs-b zk3s!z!qcUR2LI9{i>6m6nq;841$C`tBAt8#Mp?J;X*XkIV|8?Np6n)|Q6%h?wAM9U zDuVU9OhM6>Ol$!InnN;8&!f)HKzPEx6SeJsmuBK3NnH0je<-wjk^ZJ1%I0h>%9TL< zdfvIkhEC0IJ=S6L?9)q&Anj#YZOz^$?%+dqFf=dlQ*tdOleU!QZDt-BG28W54=#?9 zAiKJ5G~1p6luOq()f^!2RJ#wTqXp;{I&LD5N1bCq!+_)=-N|p_s6X@QGYM@Xtfrc@ zERdjJP0)Ml5_m>R+4CSd6WNdyc>s3NA;*vX0q|sR)qU&O<|HH%*~`lrrH~&9`+i3Wy@#}{6 zeEn7R_4T!d6ubQ=5O(FK2lZ6{k;S#)_;8T#f%XjQ(v3G%0g^Xw+7OM{PP4JpbZkc! zTE843`khCdO9S}lJjg?2Mt?I1lpvPY0!0{43MYx}flQ%+9z+jW(T4*~eUiu*pfpQu zfaaZ5v&7z1as1R19+5xE@@sbB%1DAM11hA`uN;En2P^i=|m1uc{aKiOsa zV!v(N-p>;vLzV-1=etQ+-%a8xQEmuKh0}LYp^6t8Y zrfRje9UsA&H6hzbOvpSs#0qxhkqS!CIv$7s#OUwrk*Rg+ved5(pYt#H@1mYw<;DxK z^zHS{mazVZIdx!+O_8E)+I?MJ20I}7 zoZ@V%AdAF;>(p7vS(VH5ZknQM!U0?tNr$i+n4R6}(Gt@$1v?L^wfhDKUpW_97i`I4 z?k?6yNi;P!dPeD&mP&F(Z@w}!Qw(oWm&EmF_#JtY#l<`LQkPnNdsS+FVPT@U%bEEYJjL7`+qyhgKrb(;SU1tM@hB9AN+5uop}3?=RD)AamXuuv3IzWFkg`HIE(=fs znmr}Fpre0rgHoOxijw5t}`bWF`RZq&$;wpy0_99d@rK+QnQdIu3{;SfKu$rS;-ntYU z5CMUjqOdE`qZi5Wg%a4yN@o*Qoj@NDY_B}VmftfWQCz@MX_L8vM5{e5a$`Siy7_n) z%VL6-_bSN4`eT@oY&X^C2n{lDQd2OPwkn>$XHn^H@EaaJU0rH9M#@J}uaICeNEpLS z!n3lBz8;&ZaRD8-yGWbdY*S0i1VM;;17@t&OX$9Lg9w8F%}%nGIi!AlN47~ReIV)oXg{lP|_I`bsJiH>e@hruKCEh8N{)4 z<^Ild|B)-; z5MtuuY{`$liQTy)h&J35`Z58H;-zM?KT@PHx3Ey>@Z`qMRSrZ|m1LAG#ti$kLw@#x zMy+>Q(bwE-Xc`ywwvL@m^i{F}aB*M$WH@SG5`CW*R$&1RcZzY}2v*?Une^$bZaAOT z6xO0{$2o;ypzsVhl!zA))OLZOz5xD~{|cf%!AaO- zmm9;DM?OXZi5VlUv*9b_Q)RX1#IwURTugZ@;Tq&XPzbr&7driO=U>2c_YPou0u^oE zLYqf!vL*B-02UJy6DwgH!>z1XH4wf|-2XaC z{f4G3XvU8CL~GnyCTZ9B^I6L8$q+zKepk)1}xl~tL2`z zXb6J8wx^~2TL=8@efm#w4cz3%aU{gizF+j|1B`8H+US zbUVpk6kkmr?^WP+_yuNX_FlfUS^*xS62Rocs=#d@v;f_?-?Feys=(cCs`lypa|>T$53t17_L4!jOJJX z&kWez7807WU#~BU7B;_$eEt2>6U${^yB0@dx*J}lZw7DXP!_71d}HizD)KX$2~5TK z_O~>c1IGU}$XI1F@37iNr4>*6SZs<)P1PG>^gI=?oF`;IvUVYpI`< zYISbEZbd*ERr#_w@e;E18*@ z$1dBs0YmSp3sB=9Ymj4+Dko7}7~(rM)@N3h(b+#o4Y6T;KdK!!VB!xM`LvG+GMY%C z${lhE@Utx=U*LdXG7VwdPg$4vQ8PMuM^aKn@Z!2_<%n6YAchn3)fNA?XZw`J0NzI8 z%%+1`uX|XI-0<~Dj~7k81cvic&=z0S+4ql4 zj4Ik?;juA%;hBlr`>!X%P<*eTkM13I6oK0?s(2P?-@D|HepmWc3lt8oAQs z>}+#nnLQ}eE{5)j2nEwE-6^bgErB*84=7t9G7UsBFmxF?zRk*QY)LbB{-Y_qNivb zodLkdidMBUH#f+sa@SkA4V%WAS5CqWo*$fo_|4DF#UE(}99>?FA){PA0uesgv3uXT zmsI@C;MdE86LVLpw6{1}S+(F&C!dvKcXXHTIyf}$Z|A$>%6wbG`BC|X)D2+YRlpOc%b~+=aQhG=zyd0h;BiKJVt@ zBA#*0-sLg%3ORe&KrYL!Ro6!OGpE z4m;eUG@USAe;}Yp}5X;>o{X`RWjOe zJ|kE+$Gc`Ws=nK%Q(8-lbpf8kj5*dA@S`z+)z$SqfB$Qa`FG$b>+1D^Q9X%t=Xki( zZ$T(CA3)vU@_7ohuod8N8{4A)dG+D``1rWK1{nvB#^?%u+Uq`4k58laO1FO#ZR0lP z?(3dIvfC`s0*7X5lYs>qR7QHPOFvtP0hxvtM9ZSskZyFQ9AGJhA%c(eie8`LoF;?z zJ*9;i7ZAzMl#8Hn0y{UqjvS~od{_FN=q+GS7&>~@M30{U`Y||LkaxsblHdJuiQC=m z`0^&!(GNF24%2gBQ^}&3cv(GTK}#auI{c9^3=L> zY8?didmIms>J7F`fcdAU#x?b0WBMj0To~Fty(sWpmA;1O^pMuOp4IUSJ?ijRXX0) zW)^XoMfm^!gs#TP?b;OXoYD`{es;VeTBN_(QD`78L5LKv1W|dNx!_jn+7(+_iOra4 z#fhlu?l%;h1II@NF!6qNY}Q-{a^XAY&)gcS2gE~E;`Ns7O$F~ijspFqHe-lg=?}?I zH4we5a)|(G>wOOHq@*OEkmXh9T-t^;HZ{qlhj1fG0v|oBzfg)yJ8nja_oAks8R$8l zjP7u_G}JHE`r7FyO8arUwNDt$SZ5z$}11)13AH3jIZ< zuEV!Ib8>Q;x6T(l2CR-0QRut_;*%dRXSKrO|1|9mHa{j14J!y>`Q3#n5WNY7?|*;G zqd)=n#8}946+B#?pC6~ya7AeWa5SH3X8JerapJdk7DqLAHH!03Ow~Yi{tn9ggOl@> zwJT7qTsY`iG;?l{Z>-93eCzr`yvQ;HLPtq{Gj+Gnuktb-R(`u z)pfRBMpWGje%b6E15-GlLY@LD?4WAu0xC^1Qlh*0P0yV>cdRq}klFikmk8X!ht+cb zshR%z#)r6n8hN@vVyvZ@Te6sb&-vx~;Xp=odr$fxf@@~}KJgU?Uj2cr`wef29bh4v zU%)fLnYp>kAfgbBwjq(phplBe345EF)4`D;Iyiyi1Yp)@P(vDW%qIr}*;B5}L>LVy z3avbSQrmb?_^~|AF?mkxsrtL?>jeuS@E-Az?tt!(TU8LE$PcVr$A3f7sms3wNIs&w z9=Pca3(Wti8y?2O1Po>Yc?T3++|*I0`|8|5+!7SM=o)ZmN`PCe*cts?q7l6 z*RrJS+$LH+=3g4454o9#%5;nc@BU4agGXlL+2)p(mH@Nc7A;~a#>oAu64=(>yLB8t za0nj6E-q3r*D4~zNzCojf3rXT=4UyieEm;vCUFUXFXL8BNVhcm<|WddQ$(s|MeyP# zNPQnS#c9SsKaa_$9E!Ox%5eUW^NuG4KX-jyPH-V3xr;JK6_Vm|m{a={QP3|v%dh4iWYl!~KmlQb}*O*$FfdwX8h8fLf zAnO|+cAh!($ZOwtzsS3${bV4`zJQ$gUA6pK?){4i#qI+8Az$&Ijpt#MwLwR&KcFZ& zUYmCBA-h3C);~2iwTf3(S3_RjQ1u+kJiE!&)(4z+56SEpXp%JVevEmK!hzSE(e=1J zLJsSeQ%5HgYNtn47JmKh9)C{dxCgv$%VB>ORgcw_l>Ye5?n?6R$>4V`V1 z5P(r}G zXjRCj!^M8&)>v%y9uC#*_NZO$86(Z72#a^v>oMS@&T$^JQ$@DzSOWst>61YMusZ)` z8U?F$2<`Qsp%QWAeZlyd-PgQ+sh@kH(RCa?f4<1a6(q@vPh8l1Yy|nuF?JO|4skY zT;mDvbc)9-mCFc*{w4f)`SNa^+t!{Q9Q09j2cs=V-0(UKaAQt27zgf+HQ8Rwo%7qV$ zR)@Iq`Htio9IfJX+ZuJLZHju1yqu&K9I$dty$E-_BZLDwf#O; zYK4*swLiF|^xopiz@+bATx4Xz-&xG8$s)ZNN$gT2`rQsunqnwSA-N3)y}cl$gT|^; z@zIoIif>M$I@m;Q!2Qr$G~NGRQR=qM<+i&vE3ur+pmJop#eSN&2xt`up#tJI+0-6| zSXzb@EYHfJ%wF}4(bqLZO8*x-N}O2Tv(F#yV_he`9QJVV?A?0Kx4Uh{nN@E35wCvG z>UUhEt`^@xf;)5so{1gV7!Xu_p1tJ-e)7$PbQ^|ve;oONm7QUp!tbwY81xaCWCSrB zcqojE54jQIpk=F9nEuK^@(kHoutn&C$V}z+@zmZ7ZmE1}2b^nHyU`JF+K0kpoL_%` z9OtYeHvUeddgTwrnRZQVyTgbbvM30$o7d+DIl`2B=ijTH?k^!gPu}PSqoMa|aNb@J zC#1PzM^%y;GLBPXV=Jju(L&rod9iA4DVNyW86E^f*QRnBA+tVBnO4eXo?^Kw^8YaD zA>~gf`E$9AL0^L2^jHVo*=W=*@yx!P45IgKrk(v9q7t?KH5|6VYofCssS4SxA%7|X z3rX6HYZnp&OJ$|YNDj_q<9F?NeHCj#Q4gtN52cdw2veKj9D4Kn^yvQ%}@B+sTSBB zlKOu$*Y^E{WO#q6sgM*W8{5XM^S8DlliO1xLB(QfRZ2WMQN#v^8|OYSDu9jp{xciy zh#Q#CBG>}r{-#B-bIWLw?0xt$7IXVu$I zg5ETz_q|_1T9%Y#_-XdiN0o)dbc18Ciai?6M6yNQR_J;ssrRn4a%zt@7+{&?4aJa6d>`&NG>U8 ztnq#JO~4p^y|>R@Kn3a1z^Njl(~(gcV}JTU))q4AI&i>j_%B>xXZUc<@%G zkmAkBntO-?C*58`i3RQp0Bv-Sd~IOemRGKTaTJ-kfUyK#UFLh93yZ)}{p^NuvJ+&0 zLhSejq~(OYYQaXzw?VR-!orLPKEB7vU+Q&3>4SyRZ{=%WUy=!u!h9Yq6B(s49t` zD*L!U+~p5vmdnOmfQ(rMm@J58jPc-CquR1tqvcA%pcVn`lnHULD9vd2gfk$o6gT*} zN&9v{!@hFzWJz`{cy|*g#uVT@zujTmldYM(&)5}8A|ZRuf>CUb3W7#!?F2ehj5qMl z)C%(6-u}h_Sux4oe<6p@#Udfdg3^DI1U_-J&roO|i?Yx#45{5$W8!|q*%S6zBamRu7(j75g>h{Q^!(;+oys;#% z4c|q$P>|F8yrgBRsj2aB7Mm1wT7fA%joK6AGV%ufv z2d<9bIYUFk$5ZfLSraQiPDDIaWvFfc2fx1wLVyB%+Fn0-gUi#tkPS-Q^%dO;#~W2$ zs@`X48VDcf6X}m1x5^de8_+cw3P<}SfI|_M=?=&9Y2?^_$^{z+g0F0>a*w;H1LM@P ztwiT5P+OhGsixdLe7}fFK(8#S$Sm9l;^5$b-);uB1U$q~`gH(~&$g>SIe41oA$ z8z2WD44VRnY}~;7i&q)LJs3|c)g~2!$^SY|90#}sQ)Rbq4<$%^D4=0fDUYyBHd<1w zBZ45XK3OK%Sck6LnlIN{XOwQmRPSSc7qk}4X0m!PC)hN<;T5R5>;j#Louy$U?DIfv z^;y52fI#$blvR+5rH&@G2(V7#5eUSHD`1LWD6Hg zn9z%J#vaK{D@h$`dg&l5Xdpv!rOXI)8V3`6JC?4^H3>&9jPxkQ%4$S2v}W^w9^zqy z=jh07L{-CKT9cJ6z1dfSmm*(RUfu6tl;^rNM{B{)DALzq8%^wFt~#gv zjeoS-uxZVK(8mdfiP2{`TX)lNRm^>UyydjL9_P^LulFwKYAOU*TAQOn#01Mw0$Kx% zCA8#pbBQvxy~Rg51UCd7vmxH|lB7c*dm0yme3y5jmhWgAhhYY_p)LrsRba<$#Kima z<9gJpmpfr>I?m*Fv;$+cmLIN<9Wz8pB)M(J$Q?5D5NyNUrn>6kEDBwKg(yK8b<9-+5Ow;eli#u7 zX#h$X@BoUtWxYzcd!8^vae%RyBpNmvjNc-EVCJWx)Zp!XAGh^B^k=Es} z(u>cy?YNNkcLf1vRxH3`RtA=qmz&gnpn&cfAF1{&$YjlVZ`*UP2^Vr-6kpgb(cnt4 zb7QZ)S?9iy>Ej&E`>sH|lV^oX#_@$KJud=zJQoD!(R>jk)8}FYfFNgvyU@b#0ge$qtl!v@QPc3a<)_1A9)HK=tGo4QZ#&^DIZL3Y}4d4FKwa@B(djNdgngco* z&ux@{8D=2gaBcbpwe6xB=jT&licNV;gF$U^BwFerLvg$U>Ci|W-MJMWlUo2hd9N3k^x-RxBvGlfg+TJkR z?{U-K%c&O2Gh=dK90>GEQZqGRi2}&u4%e4{jUeDxHHQKHB^cn%p}ZSjkebIG9GYP6 z41L^$~8#p5p>=;7P?9LPHrFx0}H&G1AF*hMeC1NS;}*4DiR0>vO!}BkZ>^%DBI}a^paUnDUaX>PRKK)DL}j^UY%G3TBp!@2 zMmD_$7-=93b`w)6DQnHa%L-9ha&*dnE(z1{ zSku!>Fkh~5E3MW9Ik^~@N=8Ln#@|m)X>EMWhT%!5|80(L+=6MXJ^JUM8{fr&V{Dew zyK-Wl9og}Q*EvZ~$F3uusW+V0;RAf!U$)2J_NV?qJgMKJrxnNvL4kp5_xx*|W>HWB zod;#w8)w8BtQje;dbrZHKORV;mf>=j9ox4&-ns@ApTJ1ynpnGw;WD~Ovo?sAp&89k1J_IPp#r_TzS0su>0<@* zQVLi`?reQ1lYZJbJn0~mW?c~hxf>CPgR&b;fr@oo`tk2RhMUc-+OUV?DZo)ivc4GQ!$ed+uVX*gD(91`P2C1 zMdOaSK9gPoC>t z9~Oxc*8_>0iIl5Dx|Z-F##MclHFWklNsDKP?O+rzT#rJ=R}Gir&&Slv?m6Q#;x013 zf+SOc`gD`b<3-jMIomdJxypI9!EG~20}dj0f?DS66oaY@ay}J~ZxqoMnr#cOM(0+Q zPS_$WcH2QmoXRCt1$h-bN6B&(hCqnUEq^=h!(XzMZCR?nG~!S-G3{nI^r{xB9D}9q z*e*xJ6lLeqQ_}=7EM^5swRD3?ULSjeyQRrD{-T#JvdeP;ueBZRRu>sW;G_6jIcgU% z41rGW4Z|aR*<9XCWO=B%?04$)SoFr!3T%<^ehLAC!E)TrLdnGJtuW+p1OX_KrPt~# z`npT+?dcwI2rY4#u+&FL7K6+F5RVP!| zr<&2339rvJ&SB*o`nl19&*Ub{m%q58=wgkjFstlgI^pO|8*2e?AD^~S@njEbv6rQL zB@ZTL!gIL3^K`n6wEXm^nXRig z=VvjcrSJ`{5-S4$!QIGJ@>4MN3x*yHk`Z1;Al1uS+~vVLMM6(feUB_{L+SB7b%{E= zeYK<-z*b!$SXoQQdBwXjPn&6)IQNMKwI#}~vBA={ zrL1F*0L)K7zk>{A4q*c}@`J&1B#k0fB_->LrM8TFtC?|bYt0E2*Q7W1c9czsZM_4J zmu{|Dn=1dUyM8EA%QHXzKL$VS?^T*6|J84s*+74a`ECsu7UtNZD!C1qaJi5_Ot|SK z_T~m1>~tV|lk>M;x9c-IxidC{=HfGW58z;=as|aT)3cHrM;7wMmiQc#0*5o^bQ^>d z+{)z|%+K`rr%&nzJ1^%i`zDKwR*tcbS~)nZj7eW_NMSVv$d0Z>wm$YeOlEbzKysaf z#<=**H7e+iuka11=N*FuU}f=feW>VWa=iG>;0x^grXX| z6jpt{#eMr!D@V>^XI&haQPxYk`*H_2J#>-`yaaiIlf!ba@y^;~bvE%T?T)Gc$<};I zAEtRACfadJ$ET4U)p;r6pk~mWHG{$tIshBcW+UO!dZ{=sd=-+p5-nUFVRK z!FEA%i8i#{%z7ohqBy8>Lp^NcImW`5PFA=@Bcn;gYm^2o@ zU;9+@_MG``MSn{M(l>9gKdEWAgxBKlp*74+NbLfTJ*CZ(jZMIdzPL^)ap}y4;}env z-y?YI9`}jKdL1fVoOK?I*@zHkguzD+=f3q+_;4RIJc4K6`_ESej^x zBBk>Bn!pnf<{OfQhzDe!|G3E3bbev^I=#kdHRrv>+a4BPM~3=`q5s8186UGWi}U>a zak&Z7p!INU`$`od8TB4tZ3XM@7_Rpg<7`#q4>$`Z1EizF$Iar{!Vk)FyzO*Z(AxS z{F&b`F!mb4Cn(e3^>Oip8)ut)v-w;75j*ilkO#xAUUhm7>$cBKN*23$??fxJvbXv9 z#MAH7gzY~DO4VZj;FMC#s$1>Ywv86gEzw)?^7`mgsZLXd=|Au_@1zD!JQJ(gezE$} zm!ul>lzg~wZh}=dIxy-X^@?HH_W00+j+5f{UB4y^a?#v8ws9%B~SxGzl`+$R&(5`H5tT(Z{52GL*Y0L1iVzbHChnPQAgS?1t>`{KXCW#Eur1 z2mi#>V9V^~WOoPPTln?5_VU8YSO@MQ^izhh{in6@svD4Cx{{-n*3bCH3DBE(k?MZw zYorY`GcFn-*dP^mj6^4*t_<^AXy2RrEpdBBtWaLKu5 zqR~Pit*Nm|H^ZFW(78gsAMS{JJBYrLf;Wi%6gVSBYX63H{@aAW0U5>U!)+G{BMCV9 zB~RNEJ3kl6spphiV8M2;0=Q=y)JD;96NjlgHkR&jQ{v3cy->w{mi&=j-4r-WoaOxx zSj{e80n)?E6+z#n)Pzg9#1)#@7JIkph1*pfM?g3kt13cl(e@X=iln8&jUTB(+LCqq z_AG!g(AugsNomM-Nn*`#mHrXg#b4;I5H&t(-*B|%(SIwTrQf9<=6Y<-ky!=f#bD>^{gXy zDmM5>i|5VsqUAX}Pg}}8@~Xly;c}jrZPb<8zE0BOjqPGyMST| zob2fqg7fhuzl_6s1ZbCd1K|Wv6FqMJ9$BVC!Fqlxz`$^sq1u_4v;2Lq?8+zN*bl_2 z{AIZwBO-8{A))n{A#(RXr}aa>g^z)P$@|BCY?^^+(H_WE%`q2iBu@1Y1su)GI>%2o zprxX|fy+&U*y{<|yO@k#9A~Xgm&4uN!id~JV*mK!2-WYQ#>S~UF1Z+78T^y=gh_#F zHA?6)!u^@+nBNc3g<*p|=FlrtF!U(3lK!N9G(&!dGgMVHHrk}Ic68kjIuy@=Zd!^t z3AfoxPYrrxX(=d~qQOeN5SRXMo}1v&;9Yf@&*hd)T(En9jj~JOvA)Bj%m3b&cL>fsC0KN)0Tp+8~60g_&A?d zMY}DA(txf5Mm9S;U6CwN7rw8)ukfvCQhjLn+1crqa9iFp{w88vte~?a!otW&B9*gP zZ2fhu-EKm|!7z%j$PSSn)xaZ!RCstm=pKKfTO^-+f71dz za)y0jwe^=nk9o;VFTI8T&^r zu;B|q!l2#r(aoStJBl}ncVe}aB-SQ}W1ZD8ii&3Jmhfu5Q++dWC5w>V5$Z}DCM;hdbDuJb79W7GKHV!K9+ z=X^Va$`C><_fl;)?51tOOn_;)i%Y!(3F)D8~=TXc~P}O9SEA2|%0i*Ee?Lm~^7QD)(uN7C%+ax?&D&ikn zG}kL(^qY3n?5qH0d8OFs*$(zC2qX1O)7ucL$UV~2Td77L0iwd~Yn$QK&Dnm0YU%xL zivlAm>Wyz*D~3MfGbmH0OypbVbhMNpJ(+ zg!}mTcs;pbuBzB8j-gJ*z3-&g(7Y_YbM#%Oq{NR@w2a@Og3ZCmz&M2kVTNZGF#et( z^Uzlv>HzFqx#UoSJHarJIvaqg)lP9WCV*~9K)Ai<3?nGDj&_VB#(xhAPRFN4g3P3t zS&gwN!XMk>7IfCL5rxce;ona$hi|`}Pw6>+q5tWIq5XS1qEDN!^{D&7OH~OmNmq(A zjlQbFLM)jvIK=l;;w+f%-dK0y`@FGREt@;CThUfF{CG?W;*Q;#xi)OnQ);SoAJn+! z=XgGRaJ~3~nIs3q<<|x9{kg&(Nt>S)%XWJ9jxQ3IFzEEOpn#F}d3u*ILhgP~h^qLF zCppaKxv)(K4c9X#&ndivaVGvu07DQZQ;z4Kj};=iHRW-@W~HFM zA^Fg2Zp$wb+>to>V&7_wd}S+>zP`SqiD!Z46f8Gb0)MUSGpFIBsnyuNsm7i!GJI1bUfe{vF^YVycToV+I2 zgy@S*5R5gB*DtpX4qJ)Dl4oTpLA0l@zrxN-Qw-pX30ESgJ^c>DBEOv`hBwQUo5tl% zLSJYZ4cYe1WX&dk5{zEZHE<*3Vgdgi#{}gu#+9ZLyqo*CMM5j@59R9X?;Q8PJ!p2B zmEG};9%LHP`xv?YBOMQVL2Nb^ni3}PLFUDSsx?El)OrX{nCJ5poo9Y-Iiy*qquq)( zrqi^e(*xt~M7!x(tYW{=#sD4;LqpDm1<98(oJ@9m5B__xhu#0T`y`^LwDxS`0rs4FnH007`r+eH++g9D3omh z@K!6g>M~6p1+&(estFi3?5BObG@~1mTa6+Xpkfxc*{!WVQFH`!#0I`tAdc6>gAN+o zu8)Byf%%b1Lx2rmAE`s5eO9O>F4=wqPlsvh`T}Nl*BI1P-MG7pMY%a(*>yygstKlI zD_K*(M<8J~#^6Q2JoVAZE{&(b2lDMn{X_C^oc(+td^g}pZ=OXi#aeY)mLZ?NoS_=L zasWk|P?-Z)g5B!W=SPxk#J-mz5(3YI5lNlvw%Kb2RwTRednF--T6f%0C5o!cOz{#` ztPCbnCnvME6Fj30cCph@ZaqC}o7nrcewv*m;$x#F1qFgxik?rGTw~64m(maqxY3X8 z<_ZxNJn77}o*;Hev0hO_!uLIvTmQ2~!kL}kg`Pr1ge`}v-Hxr}Eql8g#eL{<(`ZtK zLA`gO+pxHfg)`mfsg2n+j_%hOZ-)K4b9r(G+TQ=Eipq|3Kk%rDa4fq~6@Eo!P7;QZ1NkT=XuSYWB zW9#I32%R=%^tsDZbKD|2NA1`3@{s90pD1Nv?&^{~^co4D^A;D^rD^M_Xy$Dcs{Ywk z6qYnx9ss&%CxJj7Y!TuZiPi3#j5B16*(h*O0v@%L=r4q4h^4v5Gx{2Ji#>vfJ*0y7 zplw%7lK1@1*5H$CeM|faC7`@nS2Y5p-}HiE*;S$Ui?rOrxpDMd`uTxEFqrp;w34gbyk-5Hr~enLes8Cr6@*{+55>v7iQCd(IPNR1~ITtY};U%TH2SHLHjE)BGp)L?~p zxFXkCiNNuNV0C68q*%2n#je(DI9v$G8U%CUzTGF~)!#Ub9?4xU{hs=NSbNhzsN4SU-!93P3W+Hyg{a8R zkfgF#ma?X@lr8%@BPwJ|WM_m3Wy!u1lI%-%Cd6PcreOwSX8y;d^E%J#cc1s~|Kxsh zJv%S-J=V|h{=8nX(<%b+aP^&P5gxYED^mcc($kO$`i;Tu^rq-euaD=e^mg5ZHIlId z609*u$?+67>9M9JK+RYLjIiR|3f359jk3Gh+>dnzb49Bvx38y4UQE+e@zr!;W7#Wv9n*Thdcy;-E)UCI0ugzt=EW!u8**?2r zJPU?rq&hfDZRO zt%v?_j!Hm|60#Zv$@^miZRIOfTzXAmzdDd)BF5osnaL?E_pN(hJyh zKYhl1lK<95k%KhU({cu52oh0ejx;8en#TNYY0t@E@48oGwhRC|F-|GoV4Y8}?w0?s zFNkF56cuoPHUcT569~~a`gr#_Ql*)zPbI+i@yj>Y>flyt1@g9?02&}IrEUA=oo!~iGEcEA#$TY)Ic;gS{<}r^ZYpr-@X=jmDT9`+VPJQ$E-J?BN1)k zJcGw=b-Qame1*#7s@0gG`!eM(DYjiiBi69j#-V3(CoJ3`$`Qf!ho1U5!aj^QK%#ah zBr+=0M7hQW`D>~G!e*nTj^na%MEXhP5Y}Hrh^c8Ir1O|$apR#p&T(4{4pqHq)*(<| z8fIJQ(s0$o3S=L&_nSCdgaYS=M=34myv*+C>Cz9{+vw-MV`TI8EAY?eF1#F|4Q?^3 z*X#e66yJ6Y32_q|os4PM+wn;YH)G@hZ|rY0Kqo@LvHf>U6`(rcZJfm?eNZ29+n9s0N5W5&#Tv}&O=)|WO~Amq)I9;^F@ zXLKa}#%z0`7(fK!qCA=?Xx`CtYS?aZ_Cwpl*HiU3Z#21XTT1xv zicc}i>I1MJ{2y55q`aN|gb>Y3fwU>G{BvGkz*v?DVWSCDr~A_B2d}4qC*WOhI=)D6 z;_tIj3lX@}QXpZaR@xVKHs~#r(nUA$j@$-24k%Y@DCNV&{2W$y^wA?lpu9sGB?gn~ zUv6Vle#WsXLvvpim|Wo!_&GVD-(JPNR1r4vL|x-a%L}#`+HbwBF+vWhF3*TUJMflpOIymc5(FG4Zjj7*b`u*TQ5a_En{(_dKk7rAoLx9R$ z65O^?+=ssqq4-|w*k{+Uj=v&tu3(FqUOPG9<3D@ojIFb>-jHNubhM;d)vF1nv(3b_ z1Olna_qCnwxm+ZZ=jC|<6vRq&cPTwmc8KZ6%k!>5-M!!u`CIpigMdz5+dQX9Z@@m{5&i3d^8H^mPza`@gjOctmmw)AjkHT zANd<*j`9Mxl?ojq_B~1>(dpYQ1v7!aWBL!=fEoIIdZ_t=BX8+8_E| z1*r{X+rSGh$KSu(uae&Ze#t762MtHJk|vH3cXv{_Q&1l~;X0L?N&1T*&67~DZ*>r> zrx|gDtk&kUDYVHTgH5qVMA4i@!NF%ZkJmg7h;~slVJn^Gk{VD+9RV<8<5DNlt|&&0 zbgpL#B-5}QVbvixd6dX>U540BDcS7Q?9k`~{rHzhMF$*XuT@4AUXvAF_B7_J*Nd~cNSP55ErKF2=``4mpC$#40o?nLylIL(5{c~P zv$1l^U1%4iE4)_E{W1}}1u_*W@ z@uAc-`T1FzcyOacG4$_nYp<>4z!hViI16Z5T4zNGU}j2ssJ$;w#rrO%rxT z2yjeoD2Hm5QpAH&yDN0=fNm;0@#WP&X|=D9jEp3Z%`ci%I+=IFBJRBZi$9@RTx;9d zi#;f-1t*rSfdetcuBXU_ngswESB0&K5Ux`e7A6O1;o&tc>vV#M-@RU5t7p6s2}SJ)C0BP?zD(8lX7#UMRyoB>|6FnN&L7% zzx<-sa?QA>o^5lZJ{8%D_Iw;Uo7otyQ9a6Kg?C|fNO*fp$@|r21VFYy1_I?u%{mt| zQLY$x`HuJ0mC4%A92%`p;nv}v*${~I?JfX?nvvZ+V@I?4)$cw;`UlCI_nws|9sM;w z#TxM&L!h;hm$ueX0tNj=U)<5x$LZ1f6hs?sVl#i2;98dWVP}+Oo(Kuz z-mh%YMv&gB*CmSRyFfn&Ijr%T^oAw6*s}OCrF7CO<*7x%7hw{k!CM)x8wzp*eB&Z^ zO*i@`GR(C#{Ys8|N4aM8W1etFNFLGSci;Ezo$iN2R_9nb&pf{48T`Ypx51iG$yC`u zsP^&3ssV{@P%1iPSI*^d7Rm#9RaNcSu37crLjuM}6k0{xoRrPsV*6IZ+p^SSQer>O z+_~l(C+i0d^#<{7wSP;pflMDD;9o7TsfY5qySsy%smNfHFqJ!e?3kIsPSHZ@2l^#G zt;-a%hp{jkDpBqIL^i}@G&(YJ`#O|nYT4%vv(Q=JeJrTaa(s{ia_HsHf)CjkFZD7^Hka&~%43C2N zs{G|P(l5R6ptvEVe^5qz=*!Zx?mNAylwKwB+c|&n1pc%oa4IuYx>CRPyW$;Wg5X%m zTcqp^BrK5o;Wkq9Zs7QCwmw`Lae)1Z15cL6#`jJrdDys4X+=+hS_^*;A`0|=gyUEG zOZkaYhyDbWXD^(hY6G+bEu`HI0gzf|kvGt1z}iLB8WW?7|BLyryn<%=q7~TuqdjCz z9+XS8w-0lHHauTYN%7of1O`(b9CYHd8M8nkgxM7ghn{8#ib5DN(DM#u%Ie%yj?prm5T1 zFo&g`^DUODkY{Ui3*dc|;0!_qw4L*o{M>S~QzPwk2bbnWS;R$nkt%i{cxR8qM@K?Y zcB%??jFg741@;3N2wvp|*ZUObWNiw~eoV>C7$&(LlDUxU{eQ22U$FS5`vuFF{j5y6 zhyCt2^32`dS7C@-6R&o2E2Qx-FU5y;2&jlg<}|M@=f2JkmN(Un8?hjO3%7QgR8f(+ z5>HQh6ay2~uOxLdOflNh*gL!V-@f(}$t)5iVE%w(xE89uIokTrUD@iRv-~VqaECT` zq@(JU2Yr}#%&qPL`!@HsnZp9cTe{I)?>XF)pYHa}cz?~y9dTn4el;z88EW=MQ1fN< zuce(=LjP7Q+*6(9TI_(cyPHqv3@Xy`oAe;m`1hdiEn3jqp&cc9xm+1_leXk;v=r#j zihA1ZcEmr9Z~H<_ItHf;AP4MAWTs_Q{cQw7x)TX-0y+A$N zEe6!Qxk48Ty6>F^jUr@o?n8r53nNDIf;Ii6v@cTFBv@=HQ zEvre44u^QJD3~h0@eJR7{5T%@@pVS3^5alUacbSm9spfvlqWYV(-o&~3$t^`-b`%{?Wab> zau8+88I&$8EA0F?q8dXsT3vMcUz&5k9gI|Wgxb2{?=+8sf^aNrO>J!!Dj;@@n1)^2n; z?ocG?FzxiGd<)yd9xnPbze4OX_Z3W8#&wQaS(Ua9VY@Y6aZ@(YBe}v~#+JV7k<~-W z>ebRV%Wec|`^CMEqS2ah;~wXDGkt^J55s&3)kAkIBqw*G9>l}a=bBDz1`!XxX%k_5 ze~xDmFMn%Moa-a-A~dNlU`xS8YLQ~``WW;*N9E@HO+8}X9Z*5n;G|`xgP9=UZDSZ; zkdH2n{B>tt1paFkzF(LwZ&U)bU4$=ErGhJxJn0}{$)XtFNwlEsP!T-w-xeO3flDCo zEp>&w+C3pHK>Easz3A^pgASN(>WrCN9N^DjLofDY=yNy&V5l!znuU4?12kkBz3q@< zF#j267{T;exccdqYp?rW`W_TYNue>XgB%BaK5P33_%^qzZ+}eFo6Z<9|NLncGw!}4 zivs+b!ybp41=PZl2)AwYr1Txv4%v6hX)5fuR>rNKv!n5gn}h$_EaH{5}!JIV;{hOcgbGJ|%2 zC_bV4#(HgLfQdv*(Z9reZ7-SucZ>dnl1cdvI1||Zbl6`e1D$urakws=qxI-%56T$6 zE8$T?cd1wQlgbDAj>;lWxJVHX0;3V2FE)-+vIR21{O>bKnRk5I)Rgp{Fx3N1w#9z)@*vR!P}>6FsJySVn#S7hd<9$1ThM4_ zr40%n4Za|v^9Uy;?BNIDe}T)8$(~FCT=(&op0xV9$OM8ixrzFf)uW-`v@H#yKp*P8 z?RsRZMq*^LN`7X;`WZ$geW~BqMv<$8!ck`wqvc9$hl0w`T%w5 ze#*Gi*2vrWX+8b^MgyV7ISNUq8AWg^ni? z)1^q)m~{XfJ1yE{vq|uUitA#ZCK6vEbiJt;Xj?jaU?VeOVK(KM+lyX~Q{(bpJs_V6 z@%*Gz1n&=TAb04Q$nXT)8#pRa2^Ng^A5m>%|7ptY)&9N;CumYwYwv6(d4fw#T#bz5YA`3(7E7xu8c5@##t`Ts`c`WqiP@aXrr`vF8E z!EvfoJhqBraryV11YN3R*qwdUYa(D*)r4jiSFUG<-QlSZZHKdqAiQTar?L3@tgKMC z^3{Raotz>#Ng2LVQ;ewI?X7lOYb01GzNb-t^wja>f2fq6U%u`w5dXltw;#BjaTh9O zNKFP-zr3JGfuGq!z4H%OmlmPC<#+o=A3N74vNU80SqhTYG}pFwfDt5?TzZ0dZkbMf zzxRg)fZlmYQZN$QDt3X~BkeRg-YJ(ncY%3xSz z!s5>64l4hLRtAUC6W#=CnMXp|5$Dyi!dt4Kk^r@S|{VW^eXx9Skf zQBTm0BeLS+vvR60zWX89LiCG2sjnC1Pc;>;qk+qmsssXlmYnc4w+teY2-aAu_9y{= z$-C4XiC!Yp_jtwsP(JL?eOUStPMS3GS7AcqY&*}za^pj-jSR`g_xI&B9}n-~rn@T# z+UEP9dq&HYzjD2QIOpyI`xTt-fv)H>o9^VpEFeZTUgzT`h8#J-#`ZQHFyT|OA;+m8 zr~j4ZkrS>WBQrcW2)5a~DvAK2GhJps2r7qE1F*CSm{al&?OglODAoq@HWky*&QqcM zYrW-CWqAL$9f1F$K39KMNkGl_`b``1m~VAS^^U%MK6>wQql*vQlff7#k2{7=h_ zP0BO?`st2|vP>krub5ma#3ae}0SD2YbQ*yg9D_S{aj}020-S2X1c1`aLO!%8I`b7Q z!#l61PZ8l#%_m~Ba@vxhtv_dG_ItPH{J*Dm^f352uJfJw>I6q8-#8^DjOrd=#A+suh`q#x2~d9J`B4&1ss0dUczTKV z(S_@mr91y0b2+52(fpij>)>lCVN;O)fKu_Y2oCFpE7cRTAd$0O8uz~}QZ;s8@8Cqg z{A81aVWIG~QlP%MN9SJpsrqOF&FcMDK>Dyx{BwL7UIw7Z8R?I2z6^oxJ3E0rB4YP~ ztZGP<(o=c$st8pt3Ws8&*9;z=*e{kp%fqqicO7%k?A0Yw?+csr9khOj1k3h<2EXBp zR8Qs}F%`U&f;^Vg_x7+oubSz<6%zjqb?wgJIabV^0eC0$~5@vyl`u? zqN2hjIeu|vWo3E!Zj8oVkftyEILVg<4iAKdy0g|2O9*Gu)<=%XmIw=jbD`72maBF< z2)1sk%V*sF{|*dPEK!6-6?i_)i33aGH^io_d5{}8^| zWK+2cx_!@pNCcQeIDE?iT~VczJ42l(z3JHr>a4{0cw@kk=!Bb(2Aex(yzT+u&c;W89Ck?9qms@Pv8IgbU^KNM0MhU6LE}xy>adRMSry{0kG1`O2yxQ z`xS-0fBS?+bQ|01Vj}V!On+c#%b9zdub)5CDO!aqzI()+SV8$^c{#_5j|>8DAP7{N zzZJ}v0X?r`fj!k{LhSc(gHSe$QWCqr@0pu#A68tly5aF3akEW2^#qZQ0A*`L1mvRP zCh*MztDrOg#r`(vCTR6uGXDi)#}^WehrTGncan6N*P1q&3omn;g23jA^~K{ao`pF5 zZ(A@Gr~Pj%J*9savT-#yYaZidvvCXfMUh8spi~m7gXXs;WYeD5I!k8WRU$uNTC}WQ zZ=nv{%g4X1gIQ|x1KH5-AOYOh_YjXjd2VWYdisOREB1fb+dw`19IY=XJw%F+B+~9| z33JRYCZ_>pt@GM@jV?g*YsQ5|DbQ|7JH z!f7jeo8uT5Tyhq(p8L{>gL=?_sWl8`bKN+xP3+MEK#UY^VV`?Ge6cRn({buXU^7oS zSCEMc?as>>XWa()96;WYrG`tN51>7w~R!`U8$i|wM}-a)+=7temq=14*_M$L^%M4qOLUuvG&Y z9@R3IV5kSc8Xui`FY2kPkhFj5V21FN)Z@*V7_RhG)+6H7w=J-0fR1)DI7XfFDoO_* zlz}8y$nP!rOoD7)35T_iOq1HgPPb_JCPb(xMHO(Gg`3coF(RN>98YSl8F+7i;{es4 zF-PS7Eg|pd`YWMsLAOzUzw-9P+Me_4!oPi9UAi*F$ZY1Hllj1TunY;Vh|jp`J)8X+ zBfPKkQi2&3(uDvYc?;q;T?Z^q>i$}{Bj6?y7d~#H3#)d&OZwm2r^!b~P0HW*LQZ{f zDEtEWnfcbt*|8vkwAax8@%Q{p1z(x)`w#vIJaf>f!aG|`cAjH07I)J**PiRv&+mdz z)A{Gd+AlzQ|nqD(;?%%1Q$25U_xEbbA|f3a#P(8mNH1mFFoT{QE+ymA1`>b z*_`66LWp$U$91+v(GvR$vWtTfMHE9Tz%LYXHk-Opdas239ox#=0e&`6c=Cn;oPLVM zN5q|i-d_xMO((bo6ly%&*8t*)n0yYRHQ?3upcx;1`d@J!z7zGP|kyZ{Hm#1b*+V=j%5>I;E$XsoY>**Fv)!$SVE2uY--S zPDNV!*=Z&a@Wd)~N7z%#1jWkp>Uy0E3NFY1o}RRp-6q$%WyW61a(8<+EaEyf=mvi< zJ;@yfRbe<44pmq!qbB2c#Zq2(e+Qkt`sY2tWA;B}-Cb4!#xyewhU^<9hx%>Z=%m#+ zoMbOoMN~aP<+MRf-(+K6cDRnTt|d?wTekW?P*TnZUuU1rI-Xs1z@>GP4+oGWGe+!(no^^ zVqf;F;i$X*Ult$Hld4&a1&_S?uBGKF)keAE<Ab5c< z06-269_~=TJqOy z+eq1jAH7?D0OQmBxB~P8x0a4?^`0jULbjU1b>&Zij{$<>*xAa4cX!6j{&Cs=e1=yM zR0IEU+20|iD@~zP0fc2Pnd*Y5%4wE``3Zr{)d(@KVv;YTw})Zz!3U)qaVMYgzkLU= z@+YN}7bi?5}JM~?}`s%yeXz06K*tY=@(5zZ*R_)k{m zmF`{3_WEPYDiMzluU`1sFSi;pWNdo}fD6=g#sG9?@HC2)P}QCj$u^t;JeWex4EXe~!2zNYfP|JE6->3rR&hkSgM<{vHw)mw-1+ZX5zQ9} zY3hjV`^KXC*JT%8^pcYxa& z{FCWoR=chT<9m5V3#3w5XYQ7}FBMp<@AfUomOt?s` z%XvB?qh<~=Pe{E>P^G^zefQqWKk113)_^sCO~hXLdZ5L)iW#01T6(9l1b(qAqU6=k zo|>a@ED0QXH>Rqrn>^@WXq&13xG@Vf>oQwE>b0j2$D-1pq%H!UbVxmigk-SDyu*Ex zP3R)<%tM!??Vd%g^A_&4-(?3I4WFYunsrZu$b`DPxw%@NrB0FQ;L=wS5d`E}SwmnUB9!ScrNe%!m%+W^R74Boay z-3zp{rOZ3i!2K~b+&x9Tswh;LE3s zWT$gbtIdnE8s;XurG{c~tn*fL+&*&mtH?OKdNvmPUR%Q4bx zuMbW>HS=q$ESun~0dhoi8zAQ~=P`(bVAj|22OtnXBn&kJyUBQ7fyg!Vk+tEb&FHm0#F2}ajCDc3MJVri$!uEOr_^e~edvH<7z5Kg} zs>?>8rSa+GX0TWLgB3@92j~wR=Y4a^|2Enw`yI@PE%|k3>A+ia?m5X_HDZ6Axq%4v zHr6;%agnqk?^*XT(aeapL`whw*|(|6vz~yPRThPPPPOA1Zl2T`>8Jb`Qu~&U z0&OxRM-58CQ21rQmivcF<_gTShQH^u@z3gPpK$jqn}FqocLl!F$$44U<;q26E{vNd zexMahAs5c(jCmX7S@ca1$+&u_r2FCYyVvQ;FDwjG4RA-tPmzGXs!~KUI~4)mP~yUe z#a-)4rn*($vuxwfJbzi_!bUXx7&SoBefkoXuMD%X1q)+5Q)Ix&{yAOurN*6kNy%i~ zLf_Aa-Y78(Sm)*ls$E_@A+dRf$_W5%r>^^Sj{J2q6m(|m`TgE{zn^-E*Cw#^f&GYj z$!gpD-IR2xV4B8pN*b0yyebk^xSN-oe)++g(pEV2tlKqt*kh(<3fX?{UE`IOOZ!8# zKUZ+te*;QN+@}W0b}unHM-BH)QtCHhKIbk5jczd<0+tjke*%%5{s7z?WV`|unH!v6 zH+3~S9884EJ$*-s9Rz#lKqGTJ2!S<^gMyb8*R+2>Sjxq`Fb0#*)fpsziyI(QeG_V~ zc@Rx{9&lbKFrWwd^8g2j)J$~K3CxLVleOvTIZQkk1LP-I{Q(28FJc`cZUuiL$&-C> zqw!t~6E%XxaH(JtJc)~}MNa@a&TUA1lxHr)$}3`_T_$=15Jf|cq&)=9HIhenUAVkf z46I7zSE>``+n?oUW`G8yan2Pkj@zXne9_DdgXpkmO_MXgb!@dh104YECeo^!y;)$b zx+OuIjDSx0c0_Va^L6jD62FQY1Fs%Ca!GYgsD|!)d@Bm;jxs9>br7USV)~eKqD2Y% zyq`qSZlN%#l3Qm<@%#R*cSjj6c{KuQYE;IZrhaL& z)~cj*Tw7?h(^QT7hRZYH;ZVSlkozQ~`GB7%4E^-0AP6<=*Mf%5d2LXbIrWTQGp&Eo zXfoi9x9Qc|cbCory6$pHW}BV3Q8E%(J?^`-=p+44>0@3Fc#;Q$j06X0-{2se)i$mm z^&BX%&fZO#VSvFBanE407u?b-zWSf7_$+$+Y`#b_%jkyN7duHSn|HY+&Sn2Ko7iO< zU&mfkP}mrhcNDD9Gid-J^}2&5)kaBn`NPae=t!x&iNot#rllyMYsLrgsgq38(@<;G zZXQ6G^IHsCHK+@?jRRlQjmzbA5}ur9WY{L(xX?P`mobVxFo0zdJ6J69EBIy~=RFUW zp<|o5Pb=Gdaw2Jkuh%K#JDF*%8Z*DHTytGqt(GcAaW$lSUYu>+sNouu$|fIT8kKQt z%vTmv8bUeM`wyR1#ku)9qYV9=W+yUAN>>Jwx;I<7^(H}6_H#GX`TW0XWX`Zu+vtX0 zEj)F*KE14OJLn!$mVz2vOv1Rh+b2Nzez4e~km^HtbYCQG=pPt2l@#ubq!Z7=nGPgX z1*)3JU<6V};EZ2%4I~q3x=-K$wd%{O4lQZ^OJhfbbYOHFPf~ieDGn;AXxN4qrH*3s zOd9yUfiOX*-v<%qC(=NYr6bT3w?|sKv(kc9c10qnX@JZFPj+`Y;s$@h^UPFW{7S~8 zRkHp^3UEl*hBUMBJJoDW1oLNG1*|A@;75>i7i`5w->iE*7PLvBtra`Ht}j78E=6ua zc?$nH1ei(BACn@_gnrYwZ9hCR!t*`k)*?qfqOYOyf29UBWNncB&roG1jv_;Va>r0 z)%#&}Yhu-ai?(5L1$N*}62-V;D?*_I3)0Van`+X#SvM(luTA``5+VM)#by)v`P*=) zaO6=5i@Lt3{`?z&EZE#&N+)go$;-XWn$EpF$#%NjLktuU8o((lV#xTM`3@+wL7$xt zr-t2fq3ciE1^v1{Rdc!sy2_2_Yq}*5k0KY#`@L{S_VI95 zF^-p^a&H6{N+O}>BUmp1M z(|AaA1P}!`3wqdNy}ogG zwU*sP5Tv<%HwYU^q!&w`7Nuxa%6)tTI#BsrxtYZ%Zg&&^%$#{OWx(0wn7_Y%tOt6y zSr5E;gYyjwI^>R{72`v)@L|KPo^9m&4}Pa?v}n7>c6=jJn+`!KCR+qm-SI;Y1ny{ zGtc*KB|WHMjf)@XpZFiAshB_WNz8eQf)+u10~j`WoE0O=IBV>(1YOUO z&w609N3^fHMjv%#N*t`d+O|DlM>jkIu`zr8Nn7*M8CS{o_a%#YyAc40lAiE7u$Mz<M{Km9;3kz)TKvRcyU;N@@H{d86G3@^&P`+Chn>oRvd_X;olG|QqV zWt~%l;SzRkF5*?@>!u0KC+v?hv#vC04qSEjAFnn3b?lR!$8+Sx7qIEDvCz zwwT2;b9W?qN;N6d`9^eA){TefK_>iag^KUrYiG!zJwntqP*&NU# z;r)77>dOM;dPwvK#}SG`K=$Sxu0%T=Nh+ zO88ktf8bHjl-3;k$!mbYJU1OC=`Eq z8wOp&f@bJ^!<;$%YwO$aCZhTlcwlaGuZ`VMP!^^O+s4#Ci5Z>NSY>owFr(Ss3Oi{< z!1veJFv@&tC*Ndt;UCH-dq%Iy&cJ52W<;ekmq0Bm*G~2ejl!(9z~})UlF5=0gNHw$ zO4sdeIJw?nsiP)r*$B=WiaUGdxL^;oLfu*|`x&L^4a|GySlKs`HJ;3rb4bZ8n5`R0JWo#19wwPWkqfDTkbYg?IK_Ry3sPbX6dw z=&dC$ZAE&{P?1#mkus5AbS4;>O|o$z1bVsI`w7Bny88Or+)mHYksw2K{7n__*S>GW6Qp7)H9v8kJ(gSM(2Q+|~K*Z}R{o>`$0M+?B{(>L!w+-*wsN{+P zOjXh@^UyD(dFR+z*N%5u$`<|?{!(kw_h3K* zDinR4qN_D9G7|EG=JpqK6EjRvVhOa%=*cf-YfY1Rid%tkuyqi;x@H;Y%Tw$3JZa8> zYonf5c&VRZyEJa|9&QKcd1)uvpBQdT zKfKx6=+hMaHC^F`?9|%e@z2LUwbyfw+*R&Q_i~S^pPG78TS>snW0{lW9dEm2@s8cn zd@}$GT{2Rqc$L-RT4f`eGa^Xhe9B(&QAG{`=ZFtV&8e$3O(;Xij;AV^fU`5~o zw#x>idN8Z7rRNru&{`;*%+HuaVmhy!{Fpwz6fN@g7m+qX*zB>nX6X(aG?^ifp|cGL zo@0h*I0g0Dic(M;-j2lAcxTf2s|Cm3oXKrbU+^=^NP$C?2S4igSOI`luz5DW1!{&t zC{4(83{CUg^&{N5tbN68*?#783CaW1kr(g9(VY9s?I-=hPteCH()0f$t7D#CWg3zGVx!jJ;h<|Wy+gf+c*72uD&|Bh_oqnd~~#? zzO+T}?VyUe)7?rI?V=RB-V1s3Dc?VA)qT(Dp6N!n24N6{JJm7DZQ9VL5t(bJexWE* za|k{?lbaFKsI)r}D}_pGQ)GCL}$uQ12jM&*eohKbvq~QXVP;6@VtI{i3;%h422njOF5_n zrTY1`4hE(Yubxx|jx<^EVZo)7A4ORDv?fBLeee!@#%zXfdr#`1@Tcj9;2vPxgTz14omOja;A*`kIZr|=X#7mHnU?Zsqc+{GP zyYJ!)>eyGD7zmjf-!2(j^kO-xL~-eySMc@}&w>s`F=su2ltd@YQrX0LXN8L zD$wBukaFa~O@_!J>e#m5l+Q!aJCC~Nfw2ut&4cHsY8X8QhI~A;YuPE4Y%2=Gh35R* zy(_Y+@@Xz_Fw7s&p$l8reB-O{kX|rSjpFYO^|dl4yGWZgr+!)U2>C6GMFn6k7FYKJ zDg+$K5$mc@%r(f&oCtrca#X*P@9I%{aEakx(LYt>r!7l~(e1xG=Du4oHu{o`15J10 zLP$_FbeFslc;qj!dQP$>l;qI~7*!2o*qW}o8x1!Mc_ye7Ar z;#5UR9c4FA!nXo9Vv}*Ao#Vj4QSKUW`iQJD#^-fh0F9w@Mhsu- z*3l-9`a0{QKaTtATK@4j_U41rA^pa9uL^M`Mp!f5clj&>bN|+IeM%2_lI}7$;9-K) z5jfy|7rfB(xSb+7(Dg;doKfv_SX@Q3*k;Fes=Uh`_v>C=x!QCanwUB~s&O)4sp8Tf zjPls6sQuLCCljd1>1|Qz1PZh^jkF&w5|2>=3#@=ID-)ig7Rc-bz#`9P zn%z4+Ky`{w;9%4(yv>c8UwCpwBpK`2e1YgrqTNj0nyY;NwSDX+sfu;Tr(lWlV3>&2 zk0!?^ocg}qC}ne-i+1M%KVr~^{4w7`ma9?NugNe}bzB8k^$ARe(-W<|)!rZ4?(t>c z$Gpnxq;cUk!pv&uz->UsAc zS=3q@B1+JmUlx!d<|h0zZ&>8=WirsOD7HV0vJ8AoyL$HS+vBSU=0`t~fv+tAaEoZz zL!B%a|2bLWAZxxG8@-cUr`#JHH$zo+y7GIIrpoJxyG0G2y^aL(C%^W_G{1J}Rovb5 zG7Ep$8=2H^TEr9d^z_Qg%8y41pNm;VA05OGNujh#PK@M`Y>Tx@mEo&X7vc{`9>mQBB99EjT-;_^La8-X$t)RC=&i7{b_d!g~(5iP?KoaTU+bLuug@39Nw5VMiA5VF+HhClvo~V%Q8A>GIIBs%*Zxh0#-JrtjMQww*NuMH zW2^F3AdS`g2`6JLCZVOxE^`m~?7^zy-&^u9nycWt%H$nq=l%Dpld3I^;2d$gW@6Nd zIL$UIF|uNBbLt>9{E*==SrwC_KQnP5%TJ4#WxBJ3M$ZY2&|#4I%N~-xd*3Bsr;3iV z`UtjHQuYGJ*2kbYRjwx)%9t-c@7KRJds*|c%eN{GLhTCoPXD&xJy%fb$WK^0@G(MN zdq)ULuAJw*x7KGk*kRk_C8qg~1e+xpDXkcD<{d+4XLDv!ACt>Rg5}z7H?*i)v=q{` zonBF?+q9saGT{t5c_*|Lnw%-3L0vmE%c*Xyr$-rsj#@XaJKlQvA$t456!9&5LT3xB za3+^N)Qo?L;l_fWj=uU!z;Yu^+`Zj_CSO-QdiUVyt&QhFU*Y;%3RHv0uCMDG$;?zl z4tnv?KPs`e+S$Ay__0*u$xqI^{mADYm%C28{3N=)okgu&Qgmv>oQI^`-3v;^472tW zxqj4{*MNztJc?M!Ycb8HPYH~4*LOB)V@7~s2)9;PZqlhshf+EW4?G`H*5AKC zaoL{$`}RhwWKt;~$ymf)7=$VdP$4U~S6rtOWZVke{rVfmv3;w@(Y zjJ?LvV7|U8+d*q%B+(8ZT=NDPYWVsRatH*rg>8pKTeNqkyV!J95;cIc(-U zVd;y|C>>W-IKS86^F{kRYt(S;%#Y?QpA&EE4t^hY+o5`MqO%@X)YBf#XuR6)=p6Xv z5<}rhvLm6Xjx2V0x$r$R70D*K1NGQi?^o1507QBu_m&r3OS)JFyVOQMK{!oh! zpu{xCtGwYsug47W^3~PxbDjL6gRAj5z=`8^!-Q39a^eF}5h+BfHNgGd4m%&xDf&jK z@j#!sDsEQQ*NEaBO^c=|-nQOk=>%^+V0t9MRCRanIX}*lGt~vO3gU60LuTUSN_8-q zCK)EIWAgm^>*w{C3-;*eZSa47eud~{S=K)z=KHwPIL3| zenq*C^B50WN?A>5X)M0%EqCWgw(>cyW4oZWUT5e}^+`Jr*3%8y9gQk)^#66@KrL^0 zzdvZf{;gh&^`+jjQDZZ;>>Ewf(>3g5j*H`4g)O_FJS(rjL!Bj7BV1#qB7uUZKRH`B zKBd{Yu6q0Ihcov%J|KJADUJtrP0k*Ax=l#SAHmk9vWxrjUYA1K8}EbVIuw*C9|EX< z*4G=MdIQ2LZ$pg$C87?_p3LA|L*Cx}DcWcWKo(#+vummc|0TML$%E&5$EfKy7Nugf!zbl!vZGU%FXvhlFRIzQXtRENt)b6~zvEX4f zEhG>Tmt=cdpNW}y&@TqB{@zx_t8}{;1PUO9pY#)ZG=xddqT)(JZWfxoRM~3URn1ic zjl~64u@$y$LVhjihEO3qQ>EyL1!#?13Aom+0!%mkAg8v-oG7;F@1*5&Jc%7juKN5m z^6uLJ0|;=`l{_Ai7@zo{at9#ksW}u#_DwE(%91DcG3fs0fuy~v_ap3hWgOb(rzzk- zbS66C-ydMJvRA;z3Bfe+R~uBovFAo$MX%qBhOJV~wfmrX%+nZ7nUzI!98Z`Fs&;F? zy4DemTj?L6v_R`-prm$iKC=MYLn;I#gacwj=PnFvU_dmJADQ-dJ}{?7d9Fwjq&}Nm z_PJEwF$`#;s+uEDa2s<}y-<~QQGN@whpr&!3U^uW%AED)1P|`+-`(`sSv}k z*i&n~>gP(=eC0MMTgqj#;_1J{EqnGODk^J3sfg(KIW%TWT$WWOIF5$c<@fm*<-Lfp zkFnu4N}%WSb5;PAIG-~r7CTa82?Sw+ZOu%VRuV>7(6RQ7fLvAUMRp^a>jZsn!A9F4`%GyWt=m6q=NG5hdr*~%hX0_pJS$MZ6Efjlp??O zFChy2p;nmO%EFcjVqvf^dV_x*u?=UrxSDi>-MjWsKR}d@ja{dQ5^UYFZUc6)rkGe| zY7`R8*?wHjOcu|{O2cu%QSsdGlLLzvqORZ;$xBc-iv-Z4 z3XW6aveC)hwqU^-j<4yaB&77pYPT;;?g^Tl3=8Y?Bi(8iPMS*q64?c&I_tyVM*PDk!{l4wvmL!B0lD%DvE&JF;skDen zMOllGtYbGA65f@yLb6v#_AFxzM)rNpI?UMjF&JhrX6ARR_w#%{&++R!e{_^Oj^=g0 z?rS@*^E$6Bit{ERO;cUH?S*21_|dJFAuPNifIBMn`*uM5*Illx$wea;g^;%KRXE_X z@6kYi6VMHCY>9%5f^8PdgY-T>Op?~R*QvNa;&GGi=sA5X_It7T`jknqruuahIiB(g z0u+@wl`ehnfinE~9Sh&oF~fhhE87psdc*fynY?|>mUU%{eNgWi9nWg51SHRbrwFvoH<~!VG|iAxQTb>jTEvBm%si*+BlZlXn3T9@ zZgynnXFA1s?iV)_uaSlOi?&wzz7n2?lt0@Jd^!z8OQ<=(_Q?=e+O(T5c3;yy-AuuPId9Rt zvl)!N9I|de;$Ih=NyC1>p81c91OeZZ)olla>9#u02{`jdbp9r_JyKN_|Ia4ay8A1& zrjc@)BuFdb$Kr~?CH|+S?^2ljIyNw6vw;#@gT>bYR_Gy?GqQ8Oe%-Y^arPmE)U#VE zxZ;EzdfyFpEs8D7SDv*=d4zyw3w}KW6s`@$zS6LD#D;KTpc1=i09^g_%-uybhIs6) zJNi23@Hn?W_qZsyc%q^>It#qvy}n1ZH;09u9%QPzIo(o%%m(7q)pFmYnT5O=t$eAWY8eB*>PK$|XxePv0{hc>mB=~ohfMYfOc;Qz zLL*g>E)d-y?UU^D*e^O3o%sIWWwmvD^K?h4AIJyKp&p$f zYGC&|)lE8oG=P7dw+tluPf#}*i7wSl3hL@6r+C_`Uiy6%j_yGJDAs6D%VW6;`)Z$A zz;zdOWC~#F>9j#S_iS6PS5G;OUvg(s_~5<^hisiFuO!)&rgt)lVu1wHVKGinw_WG( z?Q~O}g@bF3XcTu~fs!e-*lKPgee~f{tp7p|udt|ct-8OnzMkkWRK;dMKChfww^NN6aY|r z*9R#7V?ZYt^ix~S>YXMC2{(lNSF;*V=ItSWJ*QfJ?7y#fSK*Ve_$2dT*s<%E+nxeujq!rKy^6-JG8et8 zv%efa|2BL_s}8K(fAjX)OVaNBqw}GtZ^RNrss1 zzAR)S0_?N?l7;>(Hs-(fJ(@Vr-K7`>c6=QbDP~{+V!98HQrI{BkBiSLK_lP&GSaz{S;mn^Ya_C^LvRzw$$Qq zHXIU?AMn5s+IXu+KTTU4uX%_V*?6`+{&+&3P=V0@I@uA0T{Am)H{G!sM#NPXAFr@% zTPGUJU)O8PLMRA~vA&?>9Wk0A{|r$rL>;o9AdUm)4ugrThAT~n)M4U&IgUQc>vU0Q z15Ms;3(?A`A0wai07WpX(tZ}VsU(96u1 z*D}xUJMhHy$tF2LAst^m$GTJY`otaPqj9YVLobU8_qcv_?Jl66yC3q#NhU$KL@(wF zP1Yipi8wj7XNlbJdT9ZSLx4bF|38g;!~1L6a@#_f{Zw$nGJq zm9a~V{k7){z}B9(tdfwSHyUpiZm<%?o%!ugjM|F+*C5Ent2?3k`^Dla=vxE&P~lU@ ztuM~+vCYtQm6}ccV+lZ`&gf77D?w_Cp?Ld@N@R!8aNQRKr7O=;T=Cj83zYKDRnp#8 zAOs8RV~MjK9vEo!wti~RTR>b`s4?5T@x1Iu<-U6ygF4h_hd-JrUv%It``)CM04N#a zHUXmM7=OQYgiCA8i}49kI{>#s-U5u_J`1Peqq=`84|68_%~?c}ujbxC9y>j_-ve;1 z`+8+H>}-FHVBTkks2E?TRVZ9K_{}?-;xHMIcKARER{@8|*yIe7Ww1n%qid^fkCAMe z0kaCvIJ=R;KBcc0pE!D6{Y#wy#&(FNY zOinYV8y52>g;NXr4D>ag4Vl<-)f~xE0}NnCC#QTT-QBsfum5gIk)}fbu|YYqIz+!X zSG%`+PAEN*w!gno-1~q|+@Vy5rkx_GxRLE@jT_5(-&mb09ENUNLLcm|z}sV+vaNem zwfZFLDG0!62w*o9j_3%yf6M^$^4YTUE&Qd9BAx3&K%8j zcA6*9Mn!4V1Z~`aH~fMI3({!h06)n7dLP{wr1ogYu8>C(H!;yy(=Od^DrS#fChE0L zZ*D_`TED&BVR~CSa9bD4ns?J&;{JZgh&L9GYhd)A)ZM+@KlAo1PP!`G{WhPYZxlV| zDx!hI^~y5CkV^WK_@r@^nWhwx9yBSQ; zZ1>U%Znp}F>|t(ge=QbbC@jfDa0n?Jv9S5_kq}qU&f{0srfro1m=>a{?OLdldyIB^ z<J+ncpJCP&zi;&=3hH5< z$7_P)4@b^#Pj$vQj+9;e)+lG>lV6nbsk9PEGyg-b!9`EKCbypHtaRKhCV}MiZ0m1OdCOFM@^L9QHNZEkfkLoD~#tQFD&Bkx7s-1PDJW}H#N+{sUgbAF)O zq4^bPYTc-h%<|Ur`v#}Zq16A`VOKnEb2Bk428XV2!fUn?-xSPV>h`7PtvQ__Jy?UZ z1W>0_!~-`PtAg6zgNgcsD~XzscA8?kDGp#K#76ue&)Opi59rMR`qI{HCD?*2IIF9N zSayYi6{<(|zkt!r_%tH!BJAe~>bUf?%>;RR1tTK?w8H*@4!@LIWr&xL|u2te2K-&O+{8w+XkWK5A3$vbl#cO}d= zgUIMc&-2XXdp|NI>G_@cod)RzR6U(acuy2x$d(^qA9cTzROvngE_T1^Waz*pw}I}V zAs~`zMV6I?gOs5=T70Y{9lH)f-}p``;{FKGB1M>sziOE(V8@ad-1BNPDaW%P`KWhP^3CZ ze#sg6wm7%A_$9u3%-<3WRNS528;e5nT_J~59{eeJBST|iZ>z1zKd@9OIfZLhJ^r6> z+uJa=Ud`<}d1hF&o6F-gaFU;yk6cvwVN&Cg82gI8DjLic3qYhsm5zD~!qOMj%tnEu zo1d94k56{`)P!(eWQ?2|T{cm8eCfZYDRkL9ml@oLH9Bei9mhB>qJiXr>PEctzmpYT zyruNN8meJFB};wfIRW(*v*8^*0X>DNQfLXB*(13g+^iO|Sr%m>)8iC3W@Z)3RpI!4 z){OFb0QK>Mb8$_y;}xHJopkFI14lk-Xo{1uH~gf7lU2uTE$>7##g`p@?;yD7SIGmZ zRe(h7b4JqPeoWp2wphr(yeYVTm9y$=eyNNpL0F8IwofvW1++C8lllZb3jAD0M%eBcw zb-hG?X)_KaLQi{kbxJ=ZbgFr+jE&cZx{O`A%i`wZPa|U5b^l`xOUv%zM18GE_mOX` zBYg_3K=0Zm8wjnDEGO@O1>Iqt^~mUNCXOk{OqUrA{;ZoesP0PD*Gq)GhbZLtG6Kb) zB2>a6BCKb6Vn{*cnuqq$sr~tyxmmk2b1H6A1M$C|@*03wMA7NP9&yQEzTmZ>0b+93 zIUwY4qVkQvlCsWyVtqv)(37T*gYS+|9G+ouR*SWc51oMryH@!B{ZF;gX zI_RaS8jl9ikcysdoYW8?XnYckw602-PFEx)>A=ZL8dPtx`nI<|!{vz9fa7aw^mTVN z|25r)9-9dfzRX5fJ}orqam5R{86}K>wSQlNq`gk7eJclvqVk^Vy?QowUhlSzG0!1M ziF?#Tvx%GBn51)2mK?r;$FT__D76%)1nJ1>sgAdWzLMeC!%&B2zUPnwijj?zWPes@ z`>(3ZOm^ z3&ANVkYz3f=h_Kpj8SMwpXwXqOb$Z5WFrYgy#Ax5EsWpREhqntY+Crc`f#Ez`*yi2 z4AR=euciIVAv2LP8O_$^*n!SaC6#13JsA|DZ5xr%g89Uw{*YoXQdQQI3iS6a&aR&f z`CnBVpE5B@hLsn%O5qbt31a9~6Ylt!@C2Ssy$&NL(JJv{(|qR|ZKQZk1C#XsP($9q z_mNZFj`yskiNNTQ52|O&WeKJ&SuC&zs2He|QPTsa$~1K0Ao1{YYGTI?N7jCpIM$YP zo?yEE%J0wDqxYGl4sra>D$z_rYYFTId5Ir-KR1ouDsaM84C!k`$Fin3$Emx(75TJg zEo8dr{mpjL_9FJ_&CSiCQ2Hvvmx|p1XJSqt7gt}eB=S3BBztyBG4yOhGq-5WT{+ac zGGekn{Z?Z~_q61#$4uPOrJ`puYi0sjY@3`Q{P6>QeXC6-i+)u3U=tq1K{2OHE6LrF9S?{tFKMm=k%ojUadGj+D2Tj#P-nb|9K`GhyeY?i#I4#B z*1%$0k*-Z#yGS^HZCE_nwF%&&;WIBy+x_A&& zz5gDRpXWf(T?!g@Pj5QKnAz=hO5Ar@;Db;6{@mMtKH$jfSG(h;DM)ZmAK49fT5dpM z5FOAXcQzNVrPP|Rb&*-Nka`t62AO(EDlRO-dlGEz?7rutsqYOdTJc$rDwcb0Van~E ziD5DC)>g;Iy_J6nn{Tu@`LDfy;KF9hi6Vr-&RZ<=YvCu3XlaYJW;OYO2@rakH_m%` zK)DT_NG5wQ20GO8OG?~#zy61tE!m|^LdtSH@nFn4-*5d(l1^v^r`e+@46c%_MhFL^ zVVm}^^*?SVzAjSW*Am#HENUVD6mESXAViiHa0?s~fx2g5VPSWqVwFwyhdr*s8>~lc zGR!fGrg$pFyM7c`aSo8_qU9HQOX@%*7fc>FPIn3)nK>8GAQo1PzXUm#Dc3oAK`U;} z`*z8+kkFqyb>+<^wyqP=zr)iL&eY=z>L0wdNU0TY4# zj9F&nJE{zok&yvLb)l6{y_dO!&AooIF}$V^*>`^1J*$}%+ES2{-&@SpADanaiEd~W z!)bN_7JF4Dz^vTux#W?_jEhf7lWsxy&ts-=FQlEy75hE<>rWnEfSs3fa&Xw-Z6|dY zSNfEs_`qb?PbM;6%q9)=_F8(ElKB%2U6~ci?LC|7tjD9aeoA1r^DB9aUKt*lco&*S zI64Qg(|vqelkYRbDA1SW_=t z7+(%vF^zydu0VYsX-QF*Y%^!#9;c|ClbF8Wf#TO!RYW@aj(&UYlvt`cg$ zj5Fj;G$cR&h8G3M2yOFPJ;#rX>@JpN2qem^hlUZ-evs%>*ZGfV6=iyawhawEvVU(S z2T`^X^I6IF%-=ZgbsE7NS!`N0*$c{z!-o$GcJ_c(V(@F9S8+A21*Z!&Tm`hW{b@mK zE8hD0o&CASK-bgA&=3hm9k;iAMy3%3fh(f9w@I#@oMnFXVqvgF_QE# zBmzFlJ>Z%hf~VhS-deA#3pbQTjqQ+V?a|E_WXk7yFT_e5dR;v&xf+|D$TDXn>5)ec zgkA5fWSL8_bl5oUZ+4zBQn^o|ufJbOLBZna3m|g`%8rEvyB9BNOGWD**@ZF7OQCTa+WcVF#x%j!erMPFoRd)g_mm32DOqFCAKn8)dyotU<`4e#jcf6lrn<6W})o|MW z$@_4pTbSk$U7r97Z3Jz}1}q#OwUeeuH7W}uj%c6bOnqTz_t{Zx`u^8Mwl2k7&k%d3 z?-EY7wkwg{|LiKkMa`zyCsQPJ>?pbU9W1sHpG4%g4(`*Q+1%U&@_)wS81LE5PayZhXk-`gKdKcrVY zIc~_j9zpgU7OUAwHCN|W3u|lZ zt`x9`9K2Z>-%SJ^cRFtK8RAg|L!WNd7`Z%oEkqWJFZo95WDxLGGZSxV+|l)T+Exl- zb6%eSi#6IOWAo^TUEU#nElbxc!yc)LZ=yl?IOciI$4@a&$BogAj^(x8N!_>_R(u2t?o@!n5=C+!>66t(;FW*9g3 zpZIm6K9$8b`nn2x{rsv3Ti0^M5nw~$B;Lc$KgwgVt$y(}j0VX@iS6J#88eZL!Tg=p zi5LM>H>^1$2J>2j9 zBy`zP?aTkBJlD2>N~pGW?b>uJOx_WvMVPWc{t}7*A=4+1B>D^axXvk(5!-#~_+1Q7He#`p$dRyE6n)ed=$(nvb zndj7R)k+^*7I2r1Khr(E>-Ycbel$GA=zjb(`O9` zQ#Ld-0N0e`uArb`k1fs3&VDi8nqN?1$Cdi?{42dARriTHj{Wh2#|#V%zI^!t>RaN_ z#!w13G5*3#%$yl@PA6r~?$)V8z~LU1TU|XQF6UzR^7#8q+vRWPyvO=ktHR}vXid^Y zeu&Hd_7u}!&m-4nxw(Mh6PJBt7yJ$Ne*gT`-=a2YH~%16w15B)qE zy!8xtIuWAupWEH?F}o#q$Gf&hovmvyD4MMH+eLhMAF}t4hm3xDhq?IrsozM_M;6IIvUE5$0RGGBV|yZUGbXW zxvz}Mygkbp)-h~{Z_VC9kib5~R*cBeqrkR722p)>z6xLPvv8bL(KlvHm2UGr zMv^m52_Mu;vtVcM`!`n(nBd%AQf*b$8bOe}6&|l7BGhUaiYoIjGcuf81pVKn9w06N`Gy}MaRx1Qg&Z{Si0$iz& z+WQ6uC|MXU3h)HM=6wnEFQltBxx}}-SSVbQZ`7xzQ}C1!h7VC01Cf=jwv(>F7o4rY zFA>$!y)iKpAonOK;Tp+E{qIC1HSxpY-DIN#c;`@EExbd@%dX5xU6z!WXCx%RYAPUL z3Z<@lIt?Ot-};>XO1HEGo^rvt;stP)fKi)yOy%HDwRYew+Y6^1bbz;<5aE4+dl9SNwWtWEnSYb|8esDuY0JAe z1@gfAuP2hrq&nprclWpB$UHH9KHv;Io-EM$r`~yqZTXHWS5<>`|h>IFo=c$grFEF_@fg1pXZEmDI!^;$SPH?RPP}1S1MLNuAhz91=-6g{P0u# zJnG|FRY@Kz*U$p6%Lr>>uB7 zIge$Ido+9`*BVD##_Runz6Y-VuM?2XpZzz}lL7MNt=bmt0=9(j0SKvr`qN=K@$I@V-1Beth+C77VA1~@qgQ3LF9n_2v zka-S>j@)rz>#93(eBZA~JzZU(3&6X7zk1(Rm^6zhj+;u{YD*5UtgIx5b9hCLo6h!Y z-^Xq}ieBN~@5`GhpoRBvHdx)}z5|LhFK<^@5+D*SE^cTXb?tD-`%l<-4drvk%*IWA ztdGXxaAHlSy8$HgYTRFA>e&E~*%Ge-;6UyVR^;Y7lW9;A5~R2 z{aYIqEmDTe3ggcXnW^k~^Q6GfsJ#!5M@+4Z%L)XB@K(|s)Wp0}6{y{qlzT6CS`nUv zMf0tjjCAY9Rw#u`1~vc!>6!O8q~9Y(e$F*33zw=>SUh#2K_c=A`)!b_1!+t87kp_U z|Wod7<`ttS)JLz zoET);tt0F^AP*Dvh3v!{REQ8)^75p8udNU>ubApRoBCVCM(qYvFlf=fm8t(vN%2+v+s{_g?zmUH)Sd_VkT3EM*1nShD z^jXFdreg`56%9@S+Ik?72K~aYNMI60MMdCp=QFaJ{TKF=m~U1&47DP? zn>5K4T01Wju-CIm-DP5ras;)KBea~yoZR#sIC-;}e5;M`;qLSs@umz?6|Jb6UWq)pz`-To^Uwy*5hp zo&v(#>h`$+$}!U09H9$a>F9)tr(b!@BiS=D%98GDW>D=51gm_dln(Cqmdw2Ft*y;! z$b0DZtCWma<~$Fy{^lMuotPD-F7iH1+L~!kpf%s=T2V>qZHBD zXWogv7hef6S$|_VvWd&yi$-_$(WS0cZK&bB8OFFJOidyV1l;W)C*Pnx6MzWi%+#C} z{5Hd4?>ZrU_T4>Dg*Q3aeK26&4Khb|K`bM^^ce~sfk9MUdqt8@v}1~M&Fg0*&X%(% z_&8@D{?U1PZn1mv3%)Vx^~EvcT;82N19S3s-_u2*I>WfF&4uOV<*KTxw6rv!*kVQ( zC{`=!?&HKks>Nl5(KDedp|H%33e!%89#%hM{biAp@K`Eu)0Vsx}^9f{Gm5qDv$jp{CvdW5Of6hbq@TzkMiU-rv^;?5)}A(Ayf=W}N8$B;U*@39eLE z9X|bTuGBbbQ=zx@WzB6B*k8ZVn;3H#Q87+=ROm%ED13omNS~pvE@b8AjsnSb5I{SG zbI4CO7W&FwEO90^(XM)Z)^w_$dH_;w+&_>|?K2%>T}59Ijj=z^T#k(N7q3J(Imujm z=}9c3+0?=-9-DKhZtu7{;k_62dDO)s8$sqZ%8-3!aDdvd=ZH3wvL@x_RH*SG775>Z zwk}yG=-6)Dj9#0WvF4G^8G$k0x_+J3YDnZVHz|2&GRxNgGLzvnxfA=vcl`gRp;ud6 zs@iLhH0J-dy;p56r6CgS`DCOV49gOj=y|)eqK^7jKeYR}CA{K@Z^VVp#~#9qk6a=S zViY!(-i z>a&r}=xl@@d5+N%oH^;|r%b0XJjU4sHf1C;W8#2hN)Rs@1PlrVL}GniT?^;^_g$Z; zVTE({5Q_m0w`&AFN)LFhwtKV94f`#EtMsj6guag(V2JCzd^0L3z}p*fyN#u-bl!@I z1^~);6w|Qd%H)At!J96&K0ZP;O&Q2PQRcv7|ng9nF&HBz+IS|$?CaLW@4rTJM-;iaxdX|LMQob+0HFNw!sFwK>1Faf7|er1 z8ro5VFWZm+NogWqgGi|xG8ebfF0fKPvS&WU$6vxPKXfHvi)IfK{XLuP#-2I(^n&={ zvk6qBVj_8Y^Xb|Aar7CdO__6<$em2adblvO*)H$r&z}HZq83F|w&ySnJ5LJe0|3ji z&}fy+d^U4sw-$BH$*rpEy!9*@do*!%+t~LTh`fFfk9XZ8BTG8T)oZu^P0HsvyFkw1 zvaeDdqs$Cm1taa()l?_^sBfWPRhxtEjZ=pzD!ob8npcj;S+YRlUf-3mq5_bA-E6H|K^QogTCp~AE>|e@J7(>-}J00s}JNx|uA?0=J zi}&uNYCP`1VuC?@e`X(PGe0+H)U zuO3BEW4U^9!LMFK6pHD$V~;M9jP#zkQm$S~^-IHbo{9Qf)`vCUVP)$&K8p^66?_)* zXXMU9sMMpt?7~_DubkNBdIRCK<<;Ke*?MjI%Ok$+JeqeKFkBY2!ZRi*-m~$LdOHG5 z;j|8%nyl?fJ;sZoD>!x3ha@_6R?;8(PS1ErnQ5nBalw1A?8aD3%DXR>uzgeK13bp- z51CbAk(RB_UvA&NjWVBSeBt&)jOjBz5XZg!Hal_jNp9iG%K`>xwww_R;EHE9@_o}8 zPhsVoHC)gQTsBW}Ng7@|^HtD?-<3W{TXqX4_XWOEhk3j;sL=AVvN%w;!(r#|b+F8R z>Q~b)Rql(zqAoXJG)TvbZ8S|<{&+rluN3~cLxTea&gKR+q$Ez5H5^N4+WtV+3WMOD* z+=_O0cb{hv1(W(RZYQi%*y{q>NWpylX7_9GsX4sYgIhICWtNQ*T5zqGCq<=DA+NB& z4Y|ePhlg8YtXL((Jp;ut-95vTmPOQGK=rt~r{G}4>GncitZn2*-DNL<0_H+Zaz%q_ z)h)<$(qD@zjwuz~(B#30J0h7XdENqzPTMf&fFfQ6qnEVEE2U1)pI?etuD9-IX)QGS zutg?dT?8~viL<>BpR?-H{)}%`VGliglp1>!ka5lgZb%qcA)tL(KcIC^kD#wbA|F%N z<1p6kLdCO}!%B24k*)RT(-;)hUl9LA%f>P`Isd$$Dig~mCAnLt)w1|R<#wScd)Fl$Xu>;Zk^p~>=cRnH7jh*$}^fB(pcG06V+ zWu&DAA`V!=J76}ov3y3FLlrLSV#N9RLNvfq9H}7qp7L$7pgFt~%%OokORq3%rcHQB za77ERSk9g6Iv(K|(zjRiNh z#8`!OQA2OPUjevuDXDZSf48&-xnq;*g9OW+8JAXQ5Bo5%GL9)L%-g)K$a`|7p>Nv$ zQ~0*Cb!|2uKWudUO_i92W+|@^B8(ZJ(mPJt@L>wAo2>64CR+3H{K{?xfrryYB@U}Z zfF#Xp%O=sT40z@i{nj^o5~4TzZ_5N!5ymolC=z#)Akcwv*JIk*(V%r>`E(Gs_ZZYY zHc~&$_n%22%`aUax{-jAX^i*7T$7~Sa?qc$+yHWgm9A|o5; zSKLha9)H&8Z$XUN8-2R1Fxc}WcNUl?%OZzK)mqKWA2cc|n`t|FQ~NFj9-(fW(iL@n z<3flN{GL5;z>!aZM@6N!5QD&?EN{J(*dUk8+0OK zOGkSid2*9`Sg`M9xLaLj?O0cQfToq<878hqSeZtyAfk0`q}F76Bs*70>}f&(;7lVm z5TjpbmHOq8g_@JFrS7mCjfb6wegFv~cF9h1`C!-)y1x=>=5JLhgfn&2TMDPxaxMzH zXQn0Q0+R*`{Hsr(kk0KZHiUhA8<{qv3A}vibx;@m-XS6KbMJ6^7rpt;Beisk}r6@?lvge zui1$ASbax(mLBVbi0M$uTBeJJwt5<}%G8-Fu&M1FcJ z5V*X!s4eckQXQBON1sl|Yzg~{cPu(!D8rqmuI)|LTF=S(2oX7p1NSDrl!`7LG_s!{aRYep(=~on_-7>r84D!72=9b%J$0;k@VzB9R(?_ z`;3S5vy?G$UG(#{_8CpSv^X8}&X>o{ z_6*aUw4oyu*$(vxO{nsz`zZJXub;)h@JXErH&0J=9HPNPZT3&vF$D3&TT2G$L2)-g zhg|>EA(7iT+nkLo@7IN%YCTOEr#011gJGkU3=1k)$IKd#gkuiSv|jmJq+cwPs+vL9@TDQKlGzMwo}on3MfKLvUf(* z*=Nuy7> z;z3wH%vm+?5EIPtq*ttl6s*E8m62TV92vm_oH#xkJ5 z?5Xk7X|_Fuio7>iZK|2dOO!+`xDk&VITJnJIqeM-I7YtNIWi4@fp2b z-ioN+QoBC3!7`gNB#HG^>j$dMO7KYE-i+Hjx$Ozc@_VM1=@U**?lz6SKwE6}`-8ER zwA=4k$$YWmn{ak#zm?uyGy3?ad&WL?`Y>brH8%`^8R&h*po&uVwz08kC1)VYV9ji^ zDV@r*6=pPJjC(IN)?*oK_>zXMt{CSs-|WKTkI>U;N58b@6lcQ6;oYzT{}VExnX)wh(u7V3iGsfpo^5oo+*?_UU;j8ahAp$QYIH&6Hj|-n(JrTX~ zg)gl2VNr~wMs95O~AbVU0|ZA zcG1(PI}c$|1b;F zy=#=RKE09#)*U{I=+$$&@pF-4(>f|;0Z|gw?zo!)m65e6s;2)SFW=%)mwDpmj1^vf z33O@qz@%GpFDYNQkLZh3AGvbC3zJqEo?ttfX(Pi9?@z+k`#f&qWZ=c1 z9M%_2tLzJYHIVwqkL;e4du=4?K6^3Ld5lT?2bXVv=?1F|K2qHl3KkQelQ?xgK+i@d z9zokfUK!LJ32U|jBZ-pH*Fn)=^l6cfpbhX=ZAkgLhPZ&(;J-6!xa>6+_>_pRAOZ4M z`S2i|zQVhs$ipnNU_h)~h_8e{Y7Y)SyeWsEUkdH(94sB|2obIrylKkB{iL)6keg&F zoT*MO;POXK-?wtKEKuuW!2%6};7IEoYyquaX!h_>tT{JG(`aTRwRaC|pV{_V-<+cm zFx=r`VDmW7Q~T=Y6M)p}WV_W*2&Hp#e>a%zPD298$p}{TZVTQ#EUx04n4Zi^6=!19 zP*ihnd%HB(ROOS|mD>rR_v2iF{?J?Fdc=#(F8JcI^FPf-7pxC6&$l8`tjIBrqfdX4 zh?y1~f((Qd3~mNjMegmeLv3>OJMb!9*$bPTdH9b=li*r#8D#9n);IX5ZCpubVKO1> zGU2>vF>RVN)kR*H-ZvbkX%q4Bmo{V^j%IFQ`N+FB?TfQ?08 zAkMhnayj-y9?N1ya2WS}4v9V7!YY-~{cpBE~>00pU(GM0|^h=I1#UaOJIwjhEF^CWkrvgse()r_bzet+YvE+Fl zEZ7b+{>6W)qBx9jGB*--kJ(MN!m1V;@H8QDO`63aX=iHcR5l7AMUUDy^36AQdX%f8 ziJh|2DvX`o-b+H4fChD`hGO}I)Zs^Uq$Xgt@-ZYedU=R*_XRVTS_HgvIZ5qzA2>9k z12pk;tI&FI^BF`Q&fU#lqgX#E0-Ao8@~FjmGTvO9-m;RdcYHrcuR1%90!mT3K8yS@6Xm z{d|J+uilMQHB)m3R6dN!o26>F`r7hNS?pfq&W9)KWhWVUha09&iZs?`i6}hx?AV+E#D0TO73^Wp~x~gHN%GZ}jFR8!!ab~R* zt<7GePhU7?C%Hh#l7l=XO&O9FCazGt^s$kB^T=YSb)XCTpr$8uiF0b68Vu1^7iwyz zNu4R(03vR3n)$hDYCIV-jmO482+|Ro5{wg%Y#b7MF`*-7tY@*U=?B@t+`C|yw|~kz zk$1}9G}s3k+WEJP1Mo-8vE`0|B#S%2C{sAg(emk<>T?F*t{UrAx&}{bwO6i%bYq_8^Y@)(Yoj9TaBBJ4NzzML%SZFVMJ0Z% zOjo!U@_pl(2_-AVft8h&>gs?8uA|G~ima}N@8Si5mG2Lj(oriFo{J(?mb=u+Wq&Pi90VFXtb71PAQVY&b1Sn`Q-zzD zMY+T|f2qpXZN^k-l3f(AHn*niE#%pnTn840|I?_v3`pxuG{=z`3bT(=+63pfC}%mzS!Mv4{dIVbM!Is@+(Jq;|O7o zuYDpxjE{|x9nyd+iQu}vgJ0bQNu_DLNS9>64qzw)zUq{t-@)T;Wji9I>M=8Hy|fM+ z=%7JeFCc2dt6^aYMHe%DU5oLRaOF}7Mk$vPoLGu%o&~n9Gm6nc%P_w!!I<1>m=1v5 z?0mqKbkI!ET*ZGceeWmqr$t1*$yWb>*$n1VEegPr40;lA6A+5HJv^!K)2Da*zp~As z5p+^QUb!8RPkM{79yf8OZ!s3vJn2h#I(Or9kYEFXZFMzJ0bc?1%0KPu)PNA3SisF+`!Yq!d*xw{4!E+9JaL3?c4jfV|vy_GeF{*n5{n9){#_|a@^`~edZ3# z8X#?iCKBaZex8y287XJFXV}5I)uooKJ5ahJPBL;NeLeuA$L`+W=upCFOfz%4{g#*M z!?%eCg=|bTZOk1YWdzNI{+AS$xSul=_KCX;|L;-FrV*_$CETZHRiZGkT%O?IBZ%yc zvy9wJj|k%C-xPjDeGoq1dVHD>OqC>sW1Cq^Uq5hd2M}OeTWYqA;=tHg>I2tti=CPh z@z;-8x%1KMJ^GTUiM#}-2&DK#URo5jdn%4t!O+RZQ>u6wLs%J~`U^Y!oQ=8uny{&T z*{Ci{z*+zR{;FSa^s1G&Z#?1;zjzJH-tzWC5mR}_Mn@FkcFdHD38C#I4J}`t=N2P9 z>0ZIosvPs_56KvmeAu+fy{bMBdB$^InkNM~JTp(~!s8>m!5^xH<^W9M&0iCfLz?RX z?iZE6aWL_$Ma9zcazhp?Pc>*yG&kQ!yf-F)>eG{ox~!1!xaFwk_6uwmDgGN4T$Tpl z+z}ZxDi=}wgFz|awX}=t!D?jd$fY8?F4+aEIXG$gHNp6(EiXAxUM$kaM4wvRW-dX^ zT_<19iH%6VsuD}FUOnIdG~Q5n>EQ8FT?P~z8>v~R-)kl?ZKkg|RVCfDOM>_Q zH=_XPppUlaNzd$fPYfUsd<0(Che_E6{>qoHF=N_8l4LkS&eL*?8+eB6>8U~YyUXh5 zca_u;td14<7VvYm4c+yDw-hFZ5qgnFr;X^K2e5g8d2{C}KG>!Q$uzXa>e^*X)RfWo zL|l}BKMxcc)bw+!E(0m0rfPwPwq(D4Cys~g7K_cUoktGrnZ{vOaZY>o z$x<+4@oaJgK+Nx5AWf^bKJBV;DUDlN%LC6MrB`UWPyWh6wgc!o2uB}1Q}%pe zXP9R)uT=ZRBtqDF2OR+XFf2hJSeArrV2DPFr>8zMHBDlCG&HK{3z}xn^Zt3xwwQR+ z)cDPAe2Qx$`+oq{n7O98q-&myg@I9olB1M?x)_E*r_$7BlWd;VIl={8l^R;8^Fste z*5cx#@#DuU<$zXIz~dq4gw#0lG!3v1G~S&4ny)|RbYQ5zF+Fhv5MPJJg0U|exji-j zj|DJUZ2C+96<6iciX#+&6KUF^bV^GM5wOO^8M%V>yW>2IagtjL-(#pLUNu-l*P10A z!%dNF+~M0D#U8PY73v+Rij zDOUG2ATmCyC9(qkN)sr*qR`*f8wVr1`Fiqg_Nsi9@7Dqqk99Ubmn8na6;4@EEUMw-yH1^>ZS`>+RRq6)Q3o#rlw#LWMLdSoYCc!ynWtNJ*qf8=d(|$Z`)xXayG$JI>zCOmA^^nZw7!|NI{Ew#3km< zoVT4j_6NQV)qH6ad?_U!dQ^NuLc4Xes~uQ^^IlE)1TgWVq=lH)>2OL%vZH&7a#0Tg z(iw;s#`llee8h>B2IsN0RVMrHy9H{;uQH(f?*DIB6SVcJBkM!59%$rm z8cmk11Wx~>Ta8T?xf#Qc;?XSb@I^m6X&?ddf45~`I#NlT?;Vw+9tiE znIEHau`~&0AZOPI^ODHvGVPF(Mh9$#ZImTsdHZ)qqG4^lP;3&7XtfkT0=Dly z$;N(WrmHWE>_F0M_+@m!4j%pX~EIg zj;~N*uOmOF8y_AS8TtQcd+&Iv`~QF32t{ZKS*ax1$x233rKl9@m?4!tk9nj)WmQ6D zmL%Ea92{F5TO}FC-m>>R=lmWoT-Wu!-k0}h-M+v6xo%f=xnAdW9?!?~G48`cKD53^ zcO?sp{k47~$fOKFJQ4BY2Z+Zrsy;q0(&B|%F@olfO(@@;z`i(Tykbht;K@^`9+FHs ziI3Fwn!^zNMDbksSs9BcB{%D;3b{H9&pgx3zj$#;zj>BxYxH<{c$)JGM~vP2OkjXu zpNip4eCzAE#nd`b6!zw@yKQV7(6Ucj{;8Y~maCmya-SRZTbrM6Cht_WU9Y`aDTAtmMl5_vt)So%NB}gCPK`9E zngU#PpgW9_i<#E6b6m~|Z*oDKYShXcmId)9*(j>f{#ra^ zyw~iBMimT6?0&;$W8umL!$tW>_Jzx3dxrf+PawFjRebt729?f5xwG0wHHw%`O(Z(L zO{zK>5X9i^MYd@l=o2}-B-z@(1IT(~nM;{7H{^#+#vs47R-y5iWzml-k}?>3P3n$} zFKyGJ_n%A?=v^`y_NlN8WIbW=^m=;uQ+z>dU+=oYR#i;5(@Z|%d&HyK>~q&T`ql1!`rJ=IhAYlj9i(F_0pPX567?Kz&2$yYf; z%F7-6a9svfi!akp$-7$lOJ82nVCw7W;rq2k`bsiSX6LkOq#>RzLAC~XZChKL7Oh@E ze|=+apD25{r&34M6+H;b@s+$r{Q{E;OHYz^SpH0@BCFz2Mak`slpL2_(&c(q4A4-L zmww_?Ryt7~Q>%C`-q%Rpaql@7%lsl|T)E*7Ta zx!qw4UI5?&=1CV0HV{ghN`w60iinmv7mj)do`)n0sTLA0q+Jf_B>JU~f|R~d1?y2| znf_pA?I$UYN)rJDE6Zle7X|%p2P0=^XF$032&nI$7}_4i59oxa^-Nsi)L}1B!C~5v zp@V9RoXY6ybf_XQxmcjVD#xW*4V(XgMrgtttm`6rYX$a zcwBG!MuU(WJ3?btDZdG|;X&cO{T5{|->H-~jY&toi;u7H+-r6zwPv11Q2Pb?(L%lg z#I}|CSfz+T{_#8+w4q^P5P$X_nZ-D+bx9<=;ZR|8+@BTQPR z=O;N*BVmqP9GG#Lg*p2Kzw(rhTduqERI~@yWnpGEt>DDh9$V!L6-~Uab^_OIz&q3$ zMJ3zRh5v(_5)>2!5#>w-V04c5mz8b1$f25da63;3$ zaL{jGz!$i|+D2({p(nBb_sGaswcE4Pz|H#k^IEf(eQ*xd9y@Ng%6FUojoX7PSZAm1 zt9M*@B6qL*8ZA-u&BfaZUSx86S)(keq|ST3S`1?>RgrLWYyq!FX?3083<#CWEOl<~ z=-}fJ|K4<%SI)#vswJe?QfRN0PAC2-046$}0dSpbFKofsn`sFAatE zH{6zUD>bmylg$kgG*A{0$Bykk5!Y3_y@|0?N+vRb|K^mvlKvG##b(&6O(2Mbv+`_z z^qDSDt}*N%MVG%Oraj#s(Z-~sT-I{wi;+60eavHe8Wq`$Di#jqLo?~uIDdvx*wOv+ z`^~~)2^=3t4`vZtN$`LmeI7dEvhsRBe7%n zncil}C7Y6*DjfT8|D7$^_!rT9Wf?JVmOJd86Lke6*`LZ5ujJfr)RQCPQ>xA~%u}ij z<=yw$5g#gkmDg2@py-4QpT)b?drWsWXEdBO(`B(CEpEddkVH4`Or`!V(nD#mB@z>5 z%P#lJJPheYXb$rN>T|;Q; z5Pl)$1zRaVBU%psN*enhyXjs4ZHh1#8pDygX<5l=XVx!oVZ}Phj7+ZFp2gI9Uq``?K{JsH+en9onV@>xQx#4>49T188O~j5Y|4;4r@uDiMp3u;+|$u z@)Q6wbd$g5_)9f0q=7vnQV0u8ikC8}UYtatv@HMBlsk8W#0{X?r6rpK>2I0#cUD*X z!46cEzSR#a;DZ19CjqSNRMlz4gTb2brqssr`lmjkj4jQWSGKM3zkrrPh4UpmzZ-L~ z>>)57yMuP9)&TWdNeMJM!DgJ{H`mPl>SD+lSiSbY3TuOv6-jfuznkZQ&!~%IdH^ zYx^Lfa5TOtC{>^f3mtJC9(H#HXFi)VCI;42(oMBSY~7>dh7;_4_O4)RJZ=_;b$@8m zK0NhcSp?8%uiYli3fysd3JtGWgr8;{F}L<#JY7ASvmHQDI$3z>))Ul;GHua{c4C5P z<*nFWWa@-()^p4Anv*|!)Mox8pG&&G*8PFZab}6;5ZZGK+gcW0Fl6H+<$6q|a9E=0 zsAVGI!V%p3sk39;=%2`a;X9l$F>k-HVKom7^gpr3_~~aDSEpr_hH)6K(NtAPsZLCf>L2-4uZPi?t9qNY6RTxx ziA26i3wPh1-Pr@gwr00pPP1{+$M_1fqr@+Fck(d<`^|w!?AV*y(f0TuDWcI*qf*Ei zQ<_Y?Mx`i@D`6m?KYF<)IELPJTvNkiXq?j6;JG9SrBFTvBl^WxfAU$QuDc|8ao)G{ zN5_gk&>FkjXJ@_cC6mdRg#O|QAK9jn5s?nHp$1*7WZhH1FTbUPJyH#=a31lpJAAKJ zSfz0cRZs|H&8zCw%R&1O-)Bi3i^R#BbhpyP^grDxSo~833WrXRxdW|}JFNN9xxGW7mMY{|w>r<#Ti964wE}4k z&v%(u8YirfBYp9CnxgX9M+4;}m!}_Tc*|8j&maZxDA?i9RoI1GorJ>Ew4G9)-P%k~ zy5Y1~qx{?IdXc5a&obM^1zKgY(Xf)}voo6Q{919V19i?Y@i`84MMgw9cp{ z3${q`qm(>LWghoI-%(Gqj#SwUq)`5Oe8p>qrA@;G8(MVzvZRVe=Dmi)SXsF;*fQU- z_Z2(v%OG3N3$GL&+!JHPlC8j*I#*LuGo&{N1JB7li|-Gmx|bX_`U0^1O)X~byA$6j zG7&-Oc9MU$J1T(u>$ic6(bj(VxxzV4E-p1nfn-8`vhpRc-k3x=w_>Ex%GLOx7}~P! z7G~|2tfQ2UNigKASe(Zx8kuJ`OgxI?wM*6>m95FZ#{YnIv9vyy?V6L|a=DCiI( zd@fQH_F8~qmdo#@BKm^I$BENZ8e8f8-W>0Bsek1#_oKik>;`5i-vK31w@|EU&&Wl}O`!9-54Kom1$!c0CrssI>YQ zM`dJk-24mJob_{)3yZ0_YDfy!uV-a}o6AEl^T3j!wKMAUjhfOucVE)z z({magCgZYYw_n-^m--edPWtF~%&CSEoBn;?zVtWbW7F8P7 zfox2@^np{3efj}v^1(;`KHpC7yRs~K0LDBEqBwg){pYji>lRNtm$?w}dWZDC(?o^- zuvbzG7%kf~Nk5=QUl?K>R0{+P|2}tlkdvT4pu?9KJi5K|yVCRN8^wP6zs_C3NwwH3 zPU11W6~8cPz4Gm>F5(57#?3ZT6o6UYD(L(0HK2-E>NhgF^P`sE*U}o($?++SPkpzu za*}TCV1H8ZV6HiN@nt^umw|9)olIF%3)Z1*+}j%iUW=}2?65S-4y_xN8YiFR5-UiZ zCMF-QfG>In_MxvQM=AD}G`oVQMcIt-O(!R(?mW;l2_f(<#}$w|ecI=KK@wx6ObELb zpeqEBZ+=u9V`P8|Ly`PWDcFn-ym`Z!@2ehp{6^#|;TC~&yNq!Dt7-)>LMuc5m?1kH zbDAHSmp4fd**w6>X&$|(>|;YFT-o`M*_(T7xPhx({csq$t9C3&-^+HfMbUPX*|qVG zMN|C+&KM>AQZVgtKJ2GG5D@CF(CmDdg8JlMR`rY^y4BtOrSG912qY&WoxH6{Pck?K|T z*t)jiLx2q_)zB=4sapN5YIu>6j?4E)OKK@IL-mPXk+ZO{Ki{@zFh5`EmkOVfd(-D^ z%v|1h+d|~L?xX>E8fuzxzDK4*-Av*u--zu?8lKBV{iDRun;}s2SCB7}0U`gDz9@v+ zVxQGfqE)U(@~cmP5%B}wu8=)Y@Ou#k{ys$MAq~4U%wlyJ%74ct0P5CPKBbZV#x1RS z_UwYPj}C3kl^}}Co#p(Hg0|Vzh-tONF$jt6Q`Wk`wW-YFKwzr?*ULCebPtS zwwaFh>5Op?YYLf^h>4uP8Nxvg@E_b|7syD-R4s~Sz@3eI+4l!2u2RSyM!bIL&}6EJ z7sOfP@@mCz*s+B$9s}2g5@~~B_fC+|s0rqcGDq}z z8te#Mym?(*8tvu}1p4#f`PVi9`fXQB7a z>96s0tp~VDpiFDcJ+Z`lZf*)%c<=yeO#fPCn_>#$6cAd(N7npAUF`STq?eGIF@z6* z&R)|fs|?oM3r}GsvsESF%1+cv>2ILO!C?p(a)~Cx@~%%$PdqV*rn+QVS@Pl>YOKYhfH`E$ldYRw01#Pgv&W33H`ct@l|yN* zY&zYJ7*ii@58+>?jtT$FzfNDRJpU()xT9^>@Fyub{6Z9p+2PpnU4aC(TqVc|J9lgp zur3H#%tZpU-x$N77y1#kq&%JrU``Z}k1K_d&vdP6FZNPua3T5RJqX^{P1r;)ULKyz zJ%hmQER2ors)$ga^hGJ5d+;f_OP8!&Yf9OdRd3%#b{B~H2QVB1P@#F_Ue=y&1q{QW zmr|H10zwUtC7j=k$u1JZ7%WaT``ah~gyOBINs~pO9JG>9tq8hL9^^$3Qo%r905vx+ zP0T@MB_p?6Kf}YrzfwIk@(z8_&weP2;<9=F&a$|V*#5eso&z;RWyj|I35Y%tsO0FI z+S&4Wkh3q50!hG3#X!*Wwcfy)j+cxXKDCWNqTFwuV^(qwq(VB6?*%EHqf9B=t+^ua zW;fLJ$?Iz!x4PHKb>xpJ!si+k3e}jbNBs6}8>|k1xgNd7eV^W?V$6EBWjq?*de2ci z=t_YdlbDcjDp1eBAP~QK@yyFdmIz5|e!dEMbjA<0n2;{;sv`z~9- zXP>@rc`J;Li*Y3I15_`gPixE@be+yr0k0Ka{*9WWf4@p~->$y^Nr!oUQMg~yWRKTsL_dbqt5v_7Q-VS=t_r&z8c8tH7v7Q=G zV6fQP>~D8@hGsBUEwt>GB=60Gza`_t8ULL~8n7yiKy_>@`atJiqnLyAtX$HPpE^(N zqUYEu#bE)`FH+W&jn(TCAp;g2>%38Zdzy4_lw{6o>-268yl1uPHZ3pwsP?!&7e7|QPhTa z>)PLn-@C|$x6-6`;7z?@QDunoB1QZJ*}2TNd&w4|51bOR-@+z7YpzPRU_Ot}vk@Os zFuA(GMrK|qT4K);Nf+`08Z&Up+HF`c#kp}nd8&&cpEQd7rIpbCKt);`q`nFZsS>ge z9z00Xpz9mE#0hYsL4agEC-5GMd*7c+<1m^(%cRQ!f%P?4S^hoEphWBB{Zo$>?%mp3 zWbz1O{Box!Z+C3;Vw4XJtsp^tVY2-r%E>b8_hg-Z(*iuF%dn^q05>v5 zyIx=cMx@JTze|C@O0saSGgBawJVzFPmnu`rk!;@*VSqQEC%Hx5E#2!sP#o0V-1fr^ zqxQh9%Z#keA5Ptw^kAn*_|DGi`wev*;x|aumNZ_Y`vnS_S=@#D5m}@qhQ2jDkhP=m z4%mym7+FO4L2yI8zjcU>?@{HmYkz5%5@eb7R8xx{Lwjnq{dTf8`WY`Qyir%gD&c%Ri-N8RyGI zLG_;WmMLY=0yeGYmTaZ!8vXM{!1b%@T^nhy#KSoVV7yPvR=s4QvsGq=hK@Y&t`L1F zi&n6ya0^F+%xLpmg$>M z0@RL{EI>a2^0xdEHDq&$X}do^K+zL*le zMwLg^B!~4#Exqq4YAVexb5LdoI()3C3<4Ya*&OCf`?1)9!(kR)&q$urQaS<)5qLiij8Jq zV2~6svaw@O_d|K5?Ub{b67+DJ*C5Zv^YwHjX{=Pi+n1UcM`@6r1j=MeFBf#a;qp?{ z6^SgRubNqX#JMwDoa;J|cbfe6-JwJB3#}fd^0M3~P*TI<&ahs;Blr&_`&e(a0?pMn8D> zIP^heL`3QHhoXLg*EKaYMIQDS4v{JRekhJS3GZxUK~=dahPLml#{PJZ%kjBCt9 ztHj;?0`zx}^F*@OL1&nDP=}8tWF=(N){xu@srJKOl*1-H0uz0B)Ts-8DBcB@Ud}KS zl?SotQYm;Vu10k8zrz8Nb&=mU*(lH#-i-W1*>3Q0$-!=|Zf0`Lt_3qqm}Suu;5`6& zTwuqRc{~Y^$KR-7`}An8GOIuJm@kb0D!K5~%9)kwD>bI<=_BLg1CK@Eih%Ah_Y|@a z54BB*TAXT2y5fy&r+JN$opgmAj;f``rSY0mz^OKI&pF0u(ZC$;z9E;6pAzkQIW!Ij zWYj09(yRMjAESFmYb@xa(V5E7&heIsm@4TR zT5`bVg99aKTO`kZoPtgZ?ttNksE7zhO2Rg%_|A4Sp>Ypi@yaS026pC!rcoVpS5{fe zw~tQ$Su3t7&YT8awZ3c38@(_&ihdNLfU+j~3sQg<`MpnxAQ^1abfNWfF7;ffriBI$ z9*DDK6Se?FKdR4sj5iRCM%STgOiORd18HyEP9BDWb39}xezimn2*1x(((L->cgKtC z?l+!u?;3MDq#*zV^_770eUEE^9R9q+Znt9qOR2c0IzUZ%tFEwkLDRdK_Wgk}spzYa zd~sm~<@lp62HF8g5(TGafvhMGnV;RkgqWP&Z3WBhU6X z0ldc#m`g27qnhr2rQVnK))!xr)W3(56Bzuk!Y%#O{{VIi&SLsg%_J62+zjVe9H_1{qM+KveM?C1s9rKlBjJZa%)B6=3)tD*q4@dTo!7qp~m!uaFJC!Rh3wkpiZKeGYwZy=O(Wngr4 z6tg(p44>pK3{Zf*Idjrxf@)rdo+I^&)Ma}A7ZsJ!l1{f;(=XiFdV9s-G`G@?tu@^;i8zli4`Eksc2&gm+Lpz-&Oe#=i%F@J;TG$UnipnUbVtlX$Ssx!%^ari^8 z_X8l458oG~w>WAgyS!xub=Z(8PTSsS*?1v!_$CN_X`S>*?59b2Eo=@do3bcr_Tfl= z)gdWEl2;1dh+|Q!x&BrtBzSyFpE)GHv}25Nqx&XHX!#98plb&KM5I?aAk7vo7;vex zEf&;XrWk@Ud@go=syI;&X;_0JRzfSA@^~}8gv|be?UeBsT9)_Rs`9U<=$kBMRMfck zr)^>h;s}(#Y8TkUIeEKK)0ju%k+DbX53|m<)7K~Zntb27#b4#kQoV02HF9F4k{hz! z|3RrYs^aS3sx`oluy4U~P0Cg&JMRJ>U<4i%A&*W+D0?LIhlxWfP7w4rWS z8#k>Wh3SQV1RR%ERk@_1y*}Srbaq_g*enGE)h!%o>VjGd?^mN86ZC~UyN2Yh-r}Ko z7%N*@#~iXyF^kitZa05v*EJptw{X;53T6R@+p8%?9xn2A@ zBK_1CzLBcP>I?b1b}u^{Hquh1z08}=!l?Kcz3||Ll>TC??#N=LTUT}`WZ$2?iJ8>e zqf{BPz_zk4A$x)TbwZyV9H0-Ja7B6R8g;6rveUFz-MskEddP};=B9?89*^~=(>3Ec z!^y{g5elNxKY>nvmkx^L$RPWPDrfIXmwkzID86B=Rom~i z$-;)x*el>M5b86s2+KT0St$lCjsVHGjfO0%%?~To*9;8fx88onU2W?y{LCB8>L$ z1(6<2liye3%2R)f1v4!Rce&B)_9x2jiH%6VPUxP}Sqw?r)+BdTn!V8{!OXmh%gOD< zVbJ{TMPEEDzK#LQ_+*b)*O3$nx#@%GW{U9!94jQQ-0j(^Dza5?tZB>GM8)=3asfM3 zPlN1Js(|NqwN8mGG9Y}4whEuAPKwI#&NaftTG+}`JMD8iKNMnEZ6>LKtQWdN=3qANhDvF{ zmmP#%Ye%iK*S$d(fLYj?XW6@N*3jkRoe^Zvl-$8!;QjxpKv(;|*4LHpj)?N_rE6DV zjDBmHz-Ok?t>Ia2SEioYwX+po3*+rx+{6SsHB*iq|*&D3aLqkSE zFWdSwEbNQtWVsE>h07UHHFTI5_k?WchtBAp2=6_%H&lQ#vpw@bYB%{;2RE41P< zv3@c>&oTbXi}VW%%hkkpO$BnNitlQIGsbHi9|YH0w5)Zl50u3^k5ZjF1%J4?pd;R5 z8u(4_$8_*cqo7~7c;3j+a4*U&oRY!J6fJ7z=6*;AB!{>}o(-#%?5mmF?niV1j1DLz zg7D(Yjq~<3Di6!y9J<c@gJpVWLolY+DMnLrM4|IW;fTu&HlG7A@^L_SC)~E3&zMGEb(N(7j5T#m}OHS|J z?pf!ez>Zfyuc@7Z)OCF2UjY$*pcjCd&zIX?nbm4AKs114Yi>l0Q+7gvuVo@|o%)RV z!Fa{Fxm*x=yi4qiUX9Zye>&E0u8J6S(chbrVI3c9-`dVZK2n@iJhYTDl1!hSdk zUGU06q37v@l)Kwu%0|$T)u|+_GHG^SP2h{Q7xEZbU>>zbOhIm;vZ?HaR#a$a483!( zu9ETvThA9+DoRXI~|b6gSfoVay^v_KA1L z;B`G}9#6Kbf*B*cncS*jS#cCr1hqUPtP(`zWlg&TZwlL|6QFSj1f;a2m;rs$lw}*! zAy(Rg!(v;`d^7^RpfDLrMiJ$2^h|`e6Z|N3&?4mhoRq{2;#6g0ONlo!ZYPzrj5npx z2HI5s?A!UtD0N-!RlOcD&pQx>eX_IB9`^Q9sFy^g2|Ms6>7LB;Nbd=-A>vz)2R1&= zOgA_&CKi=KLyQXC;UrM7r`$uobGS5NbFU%WG#)+fWIwhycjq_Wl+Z>Y!4c_P>j96v z?!W$M)4xqzIJv?l(b!96`6dw8vsDmSh>1j@%E_ml7D zNtw85o`<56=VP9lylEA{UcgNQbbPp{e8dC!9&e^y+0Cn5N%qAY_I*ScE?7&>Kl%XNl8hZL?Xj8z{3Hp zff#A2qaSW7f4`T!JZ@Iy06He~#Mo#LW8)Y~s`e%G%K$3u9y@INI(Q^9%z#G;gT-M1_c`8r^E_ikE48S`-_Yg+RFW<*k;)N{cC zb{xI_g~P=f?b453_29=^895x=ZI2&*7(4k+g=I{kvL>5v(zofB#kRthJLcBF!P>Zd zL!2k7&9m1!0GK;5MptdaW>4-9qgqzEb^o?HyWhZ7KHD&-irs#oMUZ(BalKI z>Mck^Sj8J8zbLCDsksN&&rCnH@PIX$EWz?i?N4A3E8$O9w{~ z4Zb1r%&IP~f9#p{uq)fe_fbM)?H1jRnXSnjBb{C4mZxhY1GtLXzqRR%%%88Y`}KM% z#;Y&eJTysH+9prGWDXL9#cej6SKl_?n%C1g#HX-75I(q%v4UPn-^k@h361 z-?kdNsk_lM%y|r^G}gQqSDiEBQ`c6{Gu;mqUouca6HtiiOo8!L7o%wvxK(g4zd<`X zPHL2PLe1TN4=9nM=^TrKs?cVwY7wu7d-Gqb@-=rUx90vtspOOtG$=ps#^`sJdWa6# zwc1^mMf0Z(3!~r%-{C7yy5Cfj^jj9#gQ!{%y=Xp|CnNi<{kOR&E;IzAXVmZY)*5wk zX{qTwB8rvG#%-3!gErvVX ztwDONHT=2GsKT!f4b4UzJ)%lOqRg=M_CA+lkh{KF_h zv>|4Y?weYun1AUla$4|?e;ZmYhRRA^356bDxknZlKpy}nnGQqGeZJdkt?mLH`k$3q z@d`pBDbUPDJf*(+Jb+9CgRgH>Kz-^~rN=)3)28O+MlPLvw%mg|wjiv4{OoL`9D~cZ zSe!=u60Bf6LeA9+5|4c(4*M5cg>^H${K$iwjtd%9%Wk28ToD@JvcPJt&qutBVDnHEgDRz zboty~aS^6w`oy1Y6g!9=(>fRyNz5>Ze!eEId-L;Yp=2sO6bfHxyyKPT2|Io29H)*Y zIx&Xbj``q{4u$AE{`Do~P2F16Rd6usaxejB==nBu$1x4Cl&OtS007a7&lyH)Gu*C^ z&{+)gAr3Cr`u>nbJ-k-qU5Dl;eY#e`y5aM6ctIs*n?i#V0F$_wq^NTeJ3LDtV%?WJ zog9d&4;RaW(jy~SmG)Nw2z1q41gfB2L8;5YJH?cvsK?A^EULX(OI zUfoW*7TO(nr7xD;(LWM?y{lriGXE&<@e~fBW~{VZy~J zNX(Rwm-@jt}gzRzPVg#C`v$-(n#&3TSC$7{y@nfx^Lq z%2--jnmTGua)%l7@C5)Am5vNKq7JWC%6@QrzMDhsUZ1SbNtP+ zx5i=}7qmxROE??jkf=$#@cP>kG;^|N2Z~dl;0jtVLse$WVAz38Q{$1sG2ZkpY#D>| zEGsK(ygY#e`f?snLekRGX8Pj9y|Uba{rzQ>h?ClSBg1^uW$|9g+)(gfbBJbBW3avp zx3m6;gG}M{%>eYSQ;_k{9apTZ#^0;Br8D_3v_}CZ`qlr?xFY2D6+j>qO7;U-uzHnU z459Yy)%+!9n3tv~WPybrlO$kduX?+HdelNe(2lG-4z3S(2;*j7AbGtRkg^I{@iU|? ztM|g;{eKPl=D+ei%ju|+7+5?H!Y6wN^zK+$-40tGFX*UQs}4>ck&r-4(2u4*Fg|CX zl*N{edG!)c-)Lz)+}zL*oX?F2!WwbmZp-GCy_L=cYF9JJGubC9?@;R9twQ`rOgHuA zi#5^3jLkuM>yH`JG|^QzGGNC_@s-{p&5ZQvSmuSv9zCiv*q>#|zMn9i10?_$A%yK@ znweB*>IG@VN|}xLD|J_>Mr+L{VG_AoN4|tn4ZNounmh9xJ$f`Y6tPrLS4R}?IyAO?!6nRLGc#{M)8PCCfO!cC zOv>A>+Hx8`hw$69-C-2zxEG2b^I?V(i08&BYH>~IV#D9P z>3v1pn7Ulk>5pADX7-vD8X2ZZxLxM$DC?-EriN`9gjE=skvH9-Ip0HpxHB?TKB_U2 zZUI$2Y4s)aVd(AA`bPWh8)9kx>B4nY5mAG4;SQ>N_b<*_unikCc)=vrgWjnr4Mn+r z){7V0DK)RUmA9$4(-DC1bcZ|NgGxQ@2sxQCnw>7Z?dljD{mC`2AE7wE^&7K#eFb=G zu~+WyKt;vJOZFXhoyfS*ud&%ugH6Ru6NU0Ma0u;T?A00u^{y$yDTZ7EZ1 zcRiwS!G9*+dQKlihLap4;bgZ^r0aOltwr2(V{OAY^*51`Ru&egxe6Q^cmIGhm8O#o z*NZ`Gjw7rn&)F0|B9g5m(Yz%qzf^14!rOl2{uhhHIGE?;R6#2_jU9+}nyjA!-QLCy z$0R-cZow-qKR?h{qCh31xuxZv=`Slc_ttYMkC}BJaajH^w{Jc;k-K8@sPR@doBQ;2 zoq&$az$?&$g%EdSsZ_ayj($J*oHoP&w7}`VN!52RaKmr|5Gx&r3@WfNHz*m%H!`f|5f)Jb^qeW<@-cvZXF8t?U?aI>d9M z_a6CoBU1ntoLl1}iC%xdOZz??JH1ZHEtToB=(hsl3|i^NB7PggWcu= zrE8q9n*u>-rdI%6`gqxSpf&nzETBbQjswr6%Wmr4KVvENJO*^eRbYf+Kj%#DlZdP0>71e|{{pZb^a z*ctiY>qT!NqP5y)m|EwZ+_zuQvWBAob;jtm5T9 zgd>))(9VL=3N7I^!m0TKas78Jl=#>3^36;sl4CRpOk!wY21bPlVQ%o&m@(9W6WWF50M1omqmf4`g8uAN+q-%M@qga2db& zW4N^+vgj%vQ;nFMnfc-=T;nm{HbBWI=xvT{)X*Hu>S3XzT`W!s3_k^t$GuJwSdEhd zf9jcoVv%uLhhSw_c(0alI14ND)~zBo$YYl-Z&|2$1uJEc{evVY{Cf!u|n?nPL2X7y4wp=J^-4! zv}EnsLQ7c5fr9kGuwL$#HHW66;gwc@CXmF|cWEY8sS%8^{@BTrFR_4FN~0FWsc+U3gI|EQ$UHfGN^j5KG$U`MD+&O+FlgUsI+v2 zBBxOi<9V57HT7XUJ*Pe0y6xdS*@Igp_`LVG0eN=y&4P&~xY7R)ES@3y-h*n|$Ai6T zX8*xX5$c*V4d1?XYVUNLI&@z><$Zg$yW; z7X(#6?jMJ@N+VG2vP&fncZJ#^vuO3SfFZ07dV<>hwYaV4N#xANorz#QsA@24bBR)Z zIl7WLf;DHa!|7k*liuONtIvz%(#dwgwfV#dT*Uu0b#DEibz`rD<5VE=JT@+!fV`7u zKcF7&yKwgcnA-_It$|!mc`az;ap%iC-$DVUF=Y3lTVtc6rs_I-BilTyGoAxwVR-)l zcdgaa$5tx`0;dh#UlQaezkWSUP?=BQO@4D+Mz50mb#)-H+d5y8JlG&=uBxgEGOA!3 z4{HcPYaJMrBct%4<ZNuNDJssD2Xb2}O42dD>IzU8D;!5!%U@Y}dGPoTeG-BH-k#_6 z+f3&iwZrS#7xuNaR#4=CLsx-WquKblHA_8f*6L$jk4$l%QtMEf=^PxqbL36$DM9sc zIq*>hbLRft&Egf=5A>+G+0#LjcHCfn9Muew@4Kek|1Yxrf3bhy=N`VcI>!4;8#yrP z)hGBshc~qUMZTsgox$+$&}?*30%+sJ$t8DFO$xqKNCiXJYvn~gfE_CoPNrr!5r>lO z@p#QR8(zOQANy{QFwAAZv@iC8qtJK7c9#XNwXBt%>(cv;&yvy$&g-jQ+DBhDH#dW_ zL^{>ms2oeH7o?Zr!cBA%*3@6{o~sNfNOqcK8^#;pAvZ)d!UW(yZ1Lf%e7auL|0EK* zJ|2@-owb3{e8-^0Sjr~wDTSx9A@HCV(7VAN-3ZzxQ3ZVFN!*&fER9)-Tu$7_k7vO@ zlb$|gET@MdFOWFN3%Llf^>yqAp3!96LuIhH0Q4&)U2vZi&z*R{rV_(MGjndKT#qGd zzlCo36)NWJdC-?YKAG!Aq32viGx*OX{o0^$gB83$-?bu_?xs!cdeC_94SxWPb$y6K zOzcE6)JXxz0QT-~PV)e`K}kM}AkZ_UVGDK1cpIKQPzC^8-(3bSX=qGqQw1)?3#L|E z6emJeWp!hVa&-pP9@S$kqagSJ8Xh1Fk<{}PH=1SI-FzT${?@$UYUV19q@-FCe(0fR zW@iO><$dWhW_29TSufO=aJ!NrErIih2y=bd(v)mpwo>ZyOG3E;Wmr*8tAAP8Bog5ce1<@jIofJM^>v-tXLyQ^5I z<=D!$NUHk^3JStb1Zb(kD^POAWzDzF0&3n%8)My7MHlRC$ z)CRcFe~gPWgKy;%oRsM_jTYpj{PBj%it{yqmA`sNRn~5JNv_Gh39Y)xv&pQfu!S7H z@&k6Mj+R+gO;X@$6A&2k*VqM#k zj7PhetjxY%kk1}LBj*aaY~uAMSQm!FxTp<>@v5SR zg!3BY8Lq*e{amxWSXG-1z5DN<@jC_8t5+q6Vev&g6Af%akimw7NPI`CLc3$&sUen< z_@1;_A3|VYN2dHIRgnlAZ?!jYb6W#!W&Gx{O`0gRu9Mr!jQQ7gEn849!*kjZ|~sXARKXP>l74i-h5$xL(P0{e^)TYzK*hJ z)DbY$W1sh^L;S<(QH|BeHx1+C4on$d8A1f|r$=$_p4L6ExBn&;?KwCyGBPwYG(HX& z2!NV^O<2$eUOjZ*<~UJ&*eZrOI>7b;Dy1Cf^=96q`!6^54T?->xb6Peqaa_AvsNBk z)IE#DXli;q!07kZty?B0CIFSZOzQ#4GyP_B?rD8)+KS|6Ur+K2HVw=W_Fq2gn#x6S&T{Dk)d z7eEPom_EOnO0GKvOrH5OC(^~y+<9?Mj-hmD@_*I)+<8%2TkBvuX3jUVehp!;gd0;o zf4*u^0qI0A?R9W+;#G2orh)YB-6@d=t>Z2SgFN=7%PkUY7z1rrdarm+be@=@f-${n z05`bRJ|pzx&P|t>mw)~Gb!O&h?M|E8!n!87jLyy%2R08nZC&OQVrbppbOH_(av$|B zzFS)`A`U|T?2PLWeCFTq)v&d21Za@$#lt={{eLpZxPb_aC{*wB<*9WTHDQ-sXeO^o zyF^6PXwkMcG?c2H$k@6R?GyZMMQC5}*94cjuICK+3437h9p}ZFE2Czmlne_dikU#l z<+SImhPpx}f-A4kPWy*N?f|BqR{0}`BjNIo{+LyhiuuYw(b`=Ve;HCptn02kD%YVO zv1vNh%Gj&#d4nqBFaPEH;tE^zpM6j`A?3}P!}mQ>8E`Yqai!2(6&5MM_ix{~rfzrS z$Pvhbp!yg{a1j~=M>}qir#bx2tMpsp&GVFiCnATBW4zEV4zvLd+~Xo1W50i&RQ}f3 zC@UfH{M-R(5TFi%TgleDQ%kvrR)#6MnW*DaLcDq~OS2!)MRm0QKejgTWvDxiy0e=V zKG&zM8CKDNU*MGx5CCG+;64muJNP|cP+KmI?z_5uJaek>Q*RcHucboC7Qz}>}tUNHE{;T^4rf4ABm3MC1cr|k) z)b`cQ7eH7=b_-8RUaS;S+*s)9%x;D7@fM+R-Qf4yR6h2%61)(~Z}yRZCCIt)@k08H zZ%w~}qArvRxqHE85FHvP^|%lNDT!M+`&*8y{tH(bgizs z+9Y>Q%9U-{ED`r2y_n}K*%NVru*H1hUJW0F0{YL92GA5&Ri#!BKbz3n3}BZ^1N`Y;WaPL@2naMFJ7$2kK@9)kWE2l*;I@u|-3B7Elzn80diBjixdufq zTzgQol|;UKb%HfzdllEdbe$%nDz5tvk98TfO)o6SsYO9q{9Auv5u863PFtR_7(81( zY}|ir_ngF4?<{m`##&EusCSWnwTpQb1UQF(=AjL6q>za8sK2=RAqWY9sRCs-k z^k{={J_S}?X@BPvx2STvc0E2Z z!*)X=<~l6&U11{s9E1YY1@CXu(eu!!TG+1$7($?YvE6_QnbOC%NGw}nvb#L3>Y#T` z?&zrsD8>ZYUrd5BWXghI4N*lWo5tM7M$2MYWP=xT$hIBMAN68qOpSIz;VAU|LN9b$ z;u?8PBS$jNT+OjV$x5E8%)Ga6Q5pLz<=u@WiT;Ng4MPf!0ys2hTog7SOCjY1DH!ey z(BgsS_jB4-G$k_Nr!CGcG$Z2nTaT#qN>Yd)|`**>oR1**^3NET@awN~%j06Fj{6_RDkl zf9G<%Jk`D=Ko1!moX1O;79uDjb{opE+vDW~EPNZPQ8$q&2e>c^9$&pDctSjaHM;UfmG%Au;=g&Dv|aM*Y>{vd&FD(3QDmoZOz`PR5&O*#6p7kD z8y~61)^`F)zHV|l;(vx%;*Zgi<=u??s&PijSToe2&?CQE%ZT4d9f2T!7${q|R)n{Ge^SKr$R~6&EVDtJ9_or0j#S{|^ z!f0;J?3qKq^RFI~A2>764{Ro6t#LZK{>D`1GYI8Bn1X$C*B8%3#E~3cpp*Wi5dFf;@)^jgEN&we{bP+2UQC9~_+Ir!ajN`w}rJiX3pb8e32}&E< z)|@{e?uI$67S#zIXQ6Q(Z`Yicv-+2m;E!wVnBkODaLrqMy=@Sn*P~B5I4huOFqgvS z-=VEHo-f>F@|}L072+fJ&?`8103Ss4%I4vDU?F&=NnL3NaK%xCP=bsl7y9 z*7W}dih=a;Co@K_K(SZUpnR%ub5|IflU1;&IJ0`lFUVeln^v}A=MOe97@)(b_s+5iS6!hO*m6-JEePn`UjD~|AFx4xtn@)J$+=8=uAd$fDD^wG8B;%A z?;J*@vXu)#^%^i!A D)x(WxhrZ*-pWH%dbygdZ8;>Tv7|J|@v|wY7`xYK=M)}m$ z^%8bm@X6m$tZ*zoyr#K}0aDW(#sRM``u&)477RZ?ks?|c3VZkFN&m1&D`7_t?$nmDNE-aRe}+B#DL=0z?h7j}F07F44+;$(5*(t0s9yHVf2HOadYyT^JQT6L%DIN24KKeF z9k(=DlMZhTzTH7WLK>~Dt~6Z2am<=+|QAJ`nbHE#$F2`&0^j)-oB6Wie-l?~2r zaF?*CXnYfPU#;9^;APyH3R2jPFfv7Bw>w9n0qI^jIl+%?q`=*V6$>Lad~kgrGh+!3 zY*d)t+aMuc9aaFcMAZ=axO!V5eDbjZ#~rikl&c(r_pPUYK2Fm9_zpNThuL`8elMUg ze!5fgM?4Hsz8)=@m((K4b5tq|kV?QRb;RJD6@!QxTW*0VVy*kU*H;Uui+`hIj z1FCa@gont{PuRCb!cEDx@5u!g#a+9s;GFH+qu5hwMLQqhxMS9n-@XxZ<3@S6ypm^V zQ5;L@v>oXhp?XiNchUDEX@5OI*^ z7?*&O@RGpYkmr&ogci?<_zgI*=1ONg8<}8c)K=>c_{<8H6X&KiU+L@Xo;THP*xuCFcixA2N+ETvq zE-y8=d|ur36Pibtdqvv!i4fGK+)^xbu1Fc8LkccyN3t1-800D4d#VxuEo#}*AR8_E zFeH@Uc>9i?ep_h99)ECX_~I^KSR6l{yHzyaYA58(+tdl82%&JXM;JF)=wg2|Y!D zRZyY~B$lHXR7B4U=(~(Y`Ri46Z#BctYN|B*WWNlqO!6OuYzdE1XnQ*&3cvln#8FPuVn zr8v8xa+R1P1Y;ng_j6DRm(@8zp#(WzJAA23NS8U8qB1dWb*x$bcGSKR2k2bc)&_|V zgm2$gisUg<9YBlddgVB6#4Ux5MfMiKh|Br#U)!~DdB5v9^+qAH^~X}X$I4L{5&>>a zEQF->DN5O(E-6Y%L7rE=zX&1f7Cy@%>+@h_$FY_8uMmRi_J>&k;Swx_g0f2Be_%b@ z+AdmHSQr|L#q&PSr_Ls$bo;h8WQ}8_G4G(zfCd@gkVFqjD~{mq^(!&j9K&W`52%|N-dP^0pMIQM(?^0??v{@O&xRN@gyj{=;I-BmK_T;7Jd(g z!fUm)>uz({Avart+|e{uG=^raz-f96t#$f~pS`V}9kA7K+k8{^mgeEkPSb7SQtKxU z&&+OidLII}G*3OXM=ve&1R_fbPCSI}AVK26fk-SCn~_23^)kdkoLKz<8hS9zHtbp7 z%@Dy1NZHe?>ACI|8z7B5!v1+cfU-v3v|UD90od&U^&|@8^X;tQ!wa{}(2BGK?)hm& zm@U725d9PPaboDqX@=B{90=+IQ6;x?=S~HM5({$wz<^6z;Gl&m`OEFw&QzGO2;Prr zPmUIG_`N8;knK?I$FQ0jX@|}@K&0wYmM5T}lx9h}^#yw3HZ-J-wT0R%*!9bJQ8$)QA?KHgh4%M^;TSEGLsQM!6YQB( zz%y_jwn)k5fQ8hR$|5btTKZ}Z4Rjn3KLj~{%ybC9`O_h0bqa6JKHuGjWtpTZHL2{W z_1NBFfPuEy-uT$q{*m@v4PjFn65Q%6&_E{pZR`jFc{Hzfxo>uoY8~w*M`ONKR(>u< zL5b`VUS8N_2(k`ZtqgvcoPGa0BoPNl()Bq=Flph&_ic1}0mgfH&sSlVg-?*c&*n*tsp^TLEuCIU)i93%lxnhMrx~^<5sAuYmFV;4C zoJ<{L{TNJ_j&+-JyfdkDGFd67;jHUweR6jgXqJN#Znbx24Oc-<4DhME(xP{TutlVW z5A2p1WhfQE)tj{n(}T!`HvnU!!Z1wBr5V)&t~AnuyUvdBJ}WCkKQ+L0+K{9z-AX4G zOJ%eOTHM#VH)G09L&x#?Od02=BTLIhvIp8_Xrt>ZWGA8SpHqi$Yi|X&24jHR8#i*Z zMZY&xu;bk2soCJv_A087s;d>i0DAiaa_#N%dQ(#c5z#ek)~sF~7#ytNMA{<7C@DUP zNCUx4i?(g%n4Ve+o1 zKhgY!Z*h5Q#kx>^$GsJXWx)v^%0SlF-<7;~?;iB#h3f&>Ie1*4b!sLt0*mCj*oL46 zLj^e|~|WUVJcQeC@8yeGVD z$(q+f*Nk09l!93Iohy@He1mxQWM=n@#<@^awmXX|-DqQR5+dy*I0A&O;A*Jb{z{)7 zSW`Yw!Nj=Vkfg$$Z`W`JKwr32=#S)+Zw0y9R$(go8er4ix%{Rb~;aR?e#Iy9h#~-Z;aF z!gRME3?C$~9crGMNsWQpHD|OBw7F+ARrBg)jF~XHeZ8|_=H_x0H=toEgpt$6t`BVt zvVzN{IjqW3^UwD~LTM?|1llhnd)%*fkZ?h^)x4&hfT`eu)RP{1`oaF{Op)U+t-c5C z9&LL3_1#mOt{#%-Rh}d8~dQj`=meO+RO$CVm1b^h|rJHC3H;V!}4P;?h0HZ zDk>@>0yxsfB)qAq=^T3&hCw$Bb-XrK&5Jh0%Zv`gvLRt%vi2wgM6a|-k4|kQ`(`_NwJB+uQz!!m)^ZFdlitZ5Q4B4T{Cdp$N66JhuT9S$A;H1 z&oOAlnP8#R{@ZKh?MjT1=D+8Vup39uS4?JVFEaClkk(8)d>xynF(}k2dz$y4o$Dc~JJ|$?utVY?A!MMRztSX&N-VB@+Q995^wdmJO3z7^ zUIb>$>%~3Yh<;orY18i75O#sR)DZ^>8L6qM5COTFm_^;nHw^cyTR~{Nt(8Hk7oZ*% ze=gkS)+x-P6n$AQ0U~(OzL}QhoTz<< zdHuJ8KF{lNd#_u(9n3Hx*tm_)~BD+Pu+4lYR3I@OMY4;5c;EO;>%!hS&cP8pEA^D z_!Yj~u$7jtoE#&#C?BvSHQty?@0a@< ze&?30+Q(}WRi3%@Ad&zw8|=?*IC}=wWV%i4N<+Ith|etW@6v!5IR*vsYm}a7Uj(;p z^xsxsP{+!ZD5kptllqkb&sm!{XC1gNuV`Lvgv)$hK(BN@BTS(-EpNq^Vx>-(r~gJ> zQj$8BQ{K|jlG%7)m$EvmBEcZPVnc+!oFj1~d5g`NPt$h&UmR3k=FBF?dkY@zKJhXb z>d4>O-!ruUzv{&mL2HTqwL5;9QenF6gJok#EES1oFV0w* zq&_Y(x@N+G@A0X^?7E4yT;a&&(ykl%Jl#`Db2~m6_KrbMe5nIF;mW$bd&iNJ{3cA_ zsdp2h14OfK`Fpu;%jSc4vR*Nv1y!j|&=KFl|V}{7qlw$S+;qn9S?AeVHK!p#sr&Gn*F{heKiy^hi3p zSRL|m^$wDBj_ko4?VkSpSrsH06*|@Gy76hA;zQQ_y}UQp3oDj95Dy7= z;Qs1IR-YJ8oSEw3#bDvDw43&D%KC$mNBkQ{Vi)2hBO?tK!f)Dtb`g+Nj}LEz)3a#N zqUHydZEv5;lx{w4{Gq+mkWU#yH|q>y6vC9fn|3et2<1?;i&;k6PPkN29-f*oJ@LtY z`-h;*{@r%^>-l29t}p#?uWC#5ud-vnw(>nn+&HnjQ$b2pWO1*QeC#h^1ZdlGi`KA%vl%HuDX$| zsSc0Kr3-I}+nIAp*CdSGo88@&cfhUV%n3>9c*GALB?vjRX$KQ&*uJ1Rd{BJdb0L4X zFWJI3`|xQPeJA`0JS+CD*6LJ478?P=9yi-^!jWe1u10p_n@-cV)x7=QPeyh`$Nb$( zwS9c@*e;xjq(%DP+B0ySH_~P2CDQkpsi77orY)y;?Ri)_mhOM++Ug|T(OXX|;6m6H zp+L~?%zv#FNy)JLz(TeNBR>~Ca&?sVA}^2e#me106IXUUc!AK<2YKD%+F-byJG;XXu%j6SMZ<2gDvc(sB1np{`Nk|Dr1{3=b2e!`uZse`Vs!}YK$4$ z_S){v)ZX$})IM#)Q+q2wimZymEgu>^ttfXo%d37QMhDgJ{22BN(g;U4#2irY8C~Hn z-L?v!uTqv9$??9*P;aUsYw1GDiW`*K^oC_y*Mh&a(ntPo-UG{8<**}Y^~>Q)$R8)K zKDbemapE_Ju?}n5)Xk^+3PP1z#^M?1-jKow5p1BAgw3*noo<>#p!A1aoXK~?Zh|`) z-duL{<%gLIz6iHy!%6*t}lL!f7=U6;O-4C%^SQ^GfQw|a#QNU{k37A|IqZ>lW6 zQ4|uw>$DDws&dKD3OmJ2sA+ruCE|V<{bo>P@X_EzC>a|s^BF`Kz8_6gn3HgjzL_JW zx3_am*;u+}R`B4}oqO;u`v%oyV>dFgwH~^wHiEXWH)|zrh*?Xw43e{Q)L|F9RE@vX zu>GTE!oZQWH?(IpKIdVu^a~BE&rz?h=p1VPsP1iIuEQ2Oj9U8IfrsimRP4{VY+P@# zz2@^US1``4WnqRFY1&Q#y~ytO+6|60zn-S3hfps@u1|~2(>iWGzgrsPAnkb>byIVD zuwDDMN2L>1h#HrSKYvPGy?V-(Uzrh)wg*kVhOug5gs?~iR9knL%cq`8>ng6Zn9maI z%#@y&tJwU`XHsIneUS}5f<717^L10(6t4xRmO?axa6y>Vg6P18)xWLb}N*?oC^wZ{dG&sTY$n*hFo3@~!#drXek<8!7&>>Kpim zM`Ki=*)zb<;)OVQxg(Boju-h;8<9ezJp$H zK&XJBahXS=bGetS=5Ddesl}BOIyoZAmZW;A=Z#sOVkxH_z9kyEtk%4m@zvTWeTOG^ z$s&Utp0TE#9$S`ZWo&(O!}$QObPoU3Pi~uTvZ(FauXFVAXS-xGQBLryA3D*=76 zPw|$19vcgMeB?MQlsO|?9T#F3RBJQ%&e83!`4R+-7oL2`KhizDBH@|!-C}p}e8*c| zmZHVZE0erVERAxci(J;G3Lnxw;Gt|{?8KV>?%j6(;+XZlk8QT7bXC2kriannxm!>L z!a73R1+?UO(|kPeE5lh?SkCK^`k$F#7|Zo!$m;3|gli>>_1uPJ)0H0X&^~}lsC#H0 zJC$hh1Q{BOo6QNgMW!JEb&E1P3(Kbi zSahLBWagF}9aYx!y$4Zv$CFP44l>`nR(ECiP0~T^vSQ>9_N$TmathC49UGbJP%0+y zVpvt}Ax@qcxkc(B%S%nSvTm!bHj;&Y_-Qs$Wb^0bt*!As#cRq`rF7rF^I+Qp&(tAN zRwb?CthkS3E;`Gnk_Z;=lD7nzt45ABq4aYC$Jw|AvZ7f&o)KI~fW%)xxhGw(j-+u` z4041Xmc{vUr9CNzk<0NY9$^)P=NVZ#ONorJ*{p;Wg%2`d){9@!w0_NmYt}i)IB$$s zt5t4eaa+HYFI=irN5D@frq)mo zZmTD|E9k`*)Q?@8#N|*EQkT>8vz6qRma?&Id926Us8tiOr>km2VVkmh8ozLwj~da% zi2BG(H+Xhv%xA)=uB};U#8R+}FC3*e7XRWZi}K!6+m(a5gpaQC|JswlmK0+qVrBK9 zd*;t!ahOwK+3f`@c4aku^|fl_LLT%|2=Ynr@5WuP-up z5`HO>g>U;@g(roJs7oos1-9K*`%Z7veav(9zK-Bi{mE)nW(0*J?Y7B_?pwzAbplqS z!OVSOQTfBfx4mHDW*I-+xddSg_u6cE(amOc{cs$}(;BA_WsXZgiizzHcFqj-S1-T5 zGTb^%hciTt*aaib+5(GQG%3-w%YCd;O~AB25+2XOl7x(w`T2RS|8(R3w7T%96W&ia zEBvp;c^r|vG_;U#R%E?^RgAc(Aj(hvW6Bs|5%X=z63E<;&yG$Qx$-k)qn%!AyGft6 z-NK!=M}e2C;!@l}RmrZ$3h-5f3j&7BH9n7QBJy!ttqN=P;SsFcw+%IHNk?!IE3K}Z zibyC2HTJ9%^FMo>xs+}o*v!BG!)tWiq!-IS@zN0tz;ji!!mD20b1dLayR&cR;rC`X zgXPmBWRT|&Y3!>cvDv^Sc#{5_2dg&qp14;Kb#mGkMavaR$N0#9ls+%{+D^o3ok00k zxPfs+qjs*3xr^O9@*?{&$s+vG=x^#|wsaHVY#4P7;}B5uEUx$hxXIsf9Q zinNUyp)g_(D~`HXF4+B&*0Q2mHlI@@XO`6CmrHum%^bLe2$dt|&!K3s#kK9holfMG zq`5d;e%o2$#~i5}KeC$0XXePwN?r^L`g%`#K-cmfJvXoJbyn;A-w-24cZ1-{dz**P zNYAccNe}cb*F5cB<)fB6_MSz!=e!N*y23H|YKpDpB4h)@^I*f7FAT7R5v(mngh26s z59I%U2eO&VAU>9b_8S8+Ebs|f_mB27z|lfVla-7;F58+w{*g?fY@+1!EMW z1xuFE*P)3YoiRH;$T|3L)NVz`*LWA|WQM>SmaNMJsTV6}1{Cw-^!t8Y9S$_4G2z6a z;)PvRK01Z~5=d7<##X_Z@6KIeFmsBY?RD+$#57REj8Uy4J(!25W*$_s;K#uJnMw{9 z_^QXqz>HgbbEUu2#n=$5$0}#^7)!w7AM0DSMHx8Mx{8R6GU`RA-ON!V2XaQebPA$$ zloWQ>S`v=Hdv^_a#Oe=bIXvPLkkt8jqrJ+fxcWtlcW^z`TMw&IW0*ljmhnP4mT%C0 zW*v8^{G^e!+_Lvr>mIXOY%QgnPh1L$xH&?58m%b)u!t z&JEtj&AW5%GM8dc*9Q*;og1$)k7K5r0{wk8|S4WZ)sPs{PwfWc>(y@=imHWJPwKk~P^?}zUNvHd%_*~<7ZsiEa2 z0_!&e!jW&kyZO&Fl+RYCI$*v~xfnrN{~ALStb`Ss{e)lrNznfR82oU17DB-Hjn4ff z(p!}AR%t8c{JRRrTv(k>4z)Et8P+bi%7cI5FIiuE5M=NWEX~|&xBsM%{{b4D_q#_I z64Z9r5_wK}7JI;(leYbkj9$KQ_0z&fRV2B~ zbJ=VHOe*248_V6lme<$jtqy0svH-q2`>FWwlT4g}t#ps)YLbq!BzK`LoNN`1+I`;O z51a)34X{($ZvOqyk@Vk>f2`mbDy1w{B&-ueq;aN|w7Zb17B;2BVif!~j{v=3X@M*- z75B%@d!TMCo%U(P;(U2Pc2=N0&H^4qR%*WQ{v94%%LQ+q-4eHFAW(AvJqz5cH!9Z) zqS_tLy75?VmxC8}fgM@hlrGD@$L-M!mSleOJpT_RrNvdT+0p$}K~#d{TX435+=F#4 z|K*YjgsbQ9L~Zb2)C0cnWG=k*l8BXxz zy=x?6O{x133t2MIjhSk|YO|6VG{4e>Ah64`R_Q-}>6z#jjl)H;k!&&Ky4k-hex$GE zrj$+UIa|iGWsh~}`X+kx3=EmXFlcz5p?7v!^0O7M<5)t9yQ_w$1g*A~F)SF^K}I>M ziH40s_mjn(G4_KO>^5bd-G5vUL!V@rPBPw;1QP7mAO`mcV?XQjS-kL{CFz>$F*;u-2P@k$IfJeiopt`3yBU)l7&=3@rJ8;U6K4``Ft(Fo zT$jtW&yhBbB1<6&F7cO#WtmT-!&#e!4>K0}=e3BsDz!2^4gP0S@$B1Am2Z+`Cv`** zJ6$&UcK&#HADfLON1d>9czD|Nu1?PlB{_P88Nv_EtG@r_u!7voVOkgS4W?Ej12g#@?^PDe8O;Y+ouh$X&iFNpm^t&X{GWUO`B{{SK9Q*naet`G>XBUDyz z7w}P2u?k^LHyBHpqae%G5uheKkF@?oJ!tTSYY!CLa=)DA9)uYcOzvU6?fA2Mf{8)3 zI{>9~N>WrwrXgV(0jsNj|Fw1eB`mbDTVJ=gB5iyleDPnRhO*=TW2ga<@XS{~lY##V z08S2PUaAR7i@W*Xm>PslPMAJB=ZNArBj%fDUegcu;1ogUu~>ODXNAN>clx4J+4}4J z_XT@*a{Ka;F+Y0$hCWI4@gEn`IE2m<=h26-6L$cK$G{Hc<3-ECBTJc}ffpYS` z{epyMr^oQcZS$Ca61Z}2c%s(%-@{*Gl`BamfaZCOS1}Yb?eAFf7g}H*TK5VkOmOz| z2f+A)4n!nePt#3$Z;6U|!KRYGK#fMfiZW2_aqs&|!O|q@oETI9Pbd`eLFZEjzu*+= zUEa>|y4DCYcZFk~A)oxg@@p<6@KLOE+2?5fd{h!b^Uu2-;Q2vfE6~Y>>V8&y;Z6E| z8grC>xw@UH5`sJD^8tV( zXLVi6wS^{cad!M#oXOgsncaC^h+lYRrb=h#yz(@r>G=mB zGO2N~HN$X7in??0o8_fNfxue3VIC6=h%zd$|MFwC0B2UYXYTN=H%0Dc$Gg%O$)$!O zw*6mX`G&>+V^|&}{Au0F|Jp61hseBj+FiGI>Cd6R`Gn!+F9;TC(O7E{aOWajrkWAc z(=dIO)wX48Ra!Y;w|%ThbNm2_c=z5v(4zD0 z|F1~U3=Ez-7FS}+ec-?4N=ozlWz1~-HAp!fWUu7DNm#^Uv<9B}TwLyc+8LV*zdwmwIroZx3VwHJMruqGBVR9VeCp@t zKgolkHa<{8k>g(=WK~X7o>Yqb`;eRrJc@gAW#qvJ>r137`~3wDe&#ZZ&&VRnlTr80 z_>e!XdaY(&e1tEY(aW%vwOfHOTzmS6)SLQE>pXR{r^s)-tdBX=Z#cRX2^5SU{w2ry z3ky&sfPO3B^36~mMW^=Td8uS?Jq7v&UhMR{gNoR(`kR=Pp#m&<>;7v#Fe8$hH-@N>o35@qo=?9W z7FX~sVHpujp0Z-qKO&aX8>MM*7*?MQ%)_Jg(XHV1b7J87kA0@V? z{+0$|Gx#Y9%rs&2-bE=+G^tH6{20WtV%5zqaCL3v+TzH%-p0BzJ#}aGLFP2N>-(7* zCHo}-At67HLoy9VsJ!;UQ?Lk(k;+sCDY;rymtMsC(B@!LeFt;Y%$x+u{{Ki4ngfu% z_mwg-Qt&oi1FckgHJZ^^?oB5W8unmNoq(y4pG}>P0Ds=qx5{+1MvWf@*? zALs>{=u0^-jK_40P}ON!!|LBM6=flyJon=tSk#KfP*IGItX9W?Pb-|u^|G95czta0 z;!}~dixb{}tX?&u*ForFeiGv4Csfi{d>CfD6x-z5CmOHtk=AB3I;^pOb`|#Hc015t ziSaUE^jLb3L_&*a+**0+!O?hFiasyHX!?2=d&W8Ey?)rC?@NcQ-e(s=P88$4*@&nT zc|u4<^zL3l%!X)%3>-5Uqxd~UQmOPV{2mPQZ{4crrKs5Ir?J}c*_ct{xW*d2vDSMp zT7y;|qc}fBAl%G)o)>R*y+M+XUshcXa zvw$R$A1$vH-Y0FBP*&G6Bfm5MUXf<-HZ5YbOlU&g_;dF22qQaw_yv=`Z%{>24o(IC z4f*D_d6XAVI(<5NyL)umHJi((`>|qyF|Fkg$U+3l|6GWEK&C84lkphq)M_W!Zf;~8 z_U+A6-_>{teSO=*?|VEGP*bBB!(m}>`^NYFyl#n-`m{QgR8%$8D8$>Yxte3}<_waj z);AOXMK_`^AOS390>WP~e9F70@~zS@$MuxcT&n%trH<)6a#h=9jSZWXcmIaa^44$h zW6G-X5w&rTO19|_re7Ygb?k0=fDEiMcCU5Q;@MM=teTqfbdSC#4iuM6tIO_j{d{8d zEgtW;=Mg9WwJH!5H$-3QKHuQK=jX(QU%)SJyl6r1!!)=;ciJ0;r9a3W&PIvQ9=;5J z(;ACpcQAis1U5_INL}r;Xw;dj2jpMe;Js@z#aYK^5MMB=k0EB5;2as$DK-{k_Q$k~B2_ogF+#iM!P};n)RfAAjlbD8HC;zi~*k7(G@hqYoEz zFeY*m3|n1LWWFP~BrNK|Gp;9COvjhVAak9ThM3~2=`sED6GjlHp4B^9h$XW>BYcYW zJbKw+bPk$dP*Nw$_3*{`98jb~LnxsvY1_abIf*xr&A5E7VK z8Row)eKcIBMpOOieFN@cy>7LHvuZY9_NF2k2u`!y$eRhXu2(UC#XJih6wT~iAsa6z zEJ!1Oran!f_&uJE@(>Vcu`x(;>8+CJuWN{6asbRNX)b28MJxO__6* zwwaujXs*qChjHc`NWQQ4^j25=i!GRVtVJ(%`lL;7)vG)Y{nqSv@Q}h8$%B8dE*is6 zhE2EX$zJ2oB4g05YfQAM6l7lera)n`3e*)L~|G{zY&MY8SklN&A}X;O-Z=&qg=Rsyo$x0JT&4 zWDQ(LCn}eOE`9#EQ`_EdB5V8^v72is$+sxiaa;3;j?oSzEt_fTt+%CyRMtmn*e*9Z zeJH8i_-^)La*hhyg(kU;0aH`Eo%vj8pQGOB<+EqlV<&RBHs!lB#QGvGm@8p=9uaSZ zre5ShcumuSIV@H_pDS9`1*BQ^EBzJx`zNBA3HQDJ+qN_b*>p?x80?OW$v}> zF5{xtQK5%KH5=kV+H2^hjEMe{R6g(`S2F@_DyjpDpup#l^ZwetjphJ zOp3^FTqPuUD!a?8NxP>}{~Wf=YrTtzP)z57VzWp1>Fadb z5bwdS8xTt~&1W~f=PsII@_D+llFPv0!Wji~_XQI*=E*@hqjsw@au}ZoE@LtwgTH>==hz_Wt(JLXnJq15`Mh>oBaK{A z4#zpNzty3}fZxRTpu**rIQey+iuhh;6Da)^oC%UuL@=wc~}Ft;wjv&o=+a zKK+sXjB3guXbv?tvazE5QoRn6D)b}8zB;>TQ*-LRzlp=_XzG1&^+BYG$^&zj3bsg5 z%B?Ni!`R2iwim^@XigbSLT|xou`m~+y-1_XbbEdw21C@tw7&7uvDemy_?)>*fGEm_ zFoMfUUjtR+j&@2}Cv$ZkJI=X9yF7@9)74%rO4wN8TBb0VBfH0VrM@3sG}4BQZ`a36 zfyb#m?j#J?OT%sxu+nLqow=Fusde5QxQ4|1o`yuTSo6n!f(+NXc&T}9-g@Za#B!zT zBjI3QOoS`sgddbD&g}P0QdkQ50#u63&sZmFk%UUy?4PH*S`mrh7t*73hZ$qzs)Iyc zQ8eX(hZDj(82k5&II3B&G4SO$N+m`ZO(|(5=;pNUv1u_{_F6MZk&j-V)p#6fGE)D= zJ!S71u+oJO9(barT<`Lb+OwQNZ<&KW%Og^KGDr}F+X=JM&SA7hW>L#f8P7kDMdi}@oA>eOdsgR!knE}$*x z9R&fpI5fuPm6vlNH@Fwirzv=`@y+ka@$Rl4JHG&mq7QDOG+~@Bt1>v8S}QKN#|6aL zuLwU=c}>d*)lVu%RBv>ctCP`{4$OJFohfC>(_%#b#k^20_S6qFX-#q%eJpQ|%Cxr# zK<;bmN{dK{cd>S zm)>Ia?==ueXECUo8~u4w{M45}<49 zbeF$sIqu_xa4XLW^VAky-Mp4=Kn$sG9h&2g9Y6LKJB+JKwSclReT(?7@zb3srK)N_ zQKcF?rz^O3c2N$lbG9PQU&BT}!_UuAw&e%|2}GBHVa>9Q)fPlcw6VBDo3i zjhL*Gl$uzNjAG{$v*e1$g`E^zj^v z>?v=|K9an*Frg81-u?M$VSlE-7&wM-L>HvjOw*z%UZIqY6LFCe%E>OpCz}enDzMX~ z7Os|8O1LVnH4awCX*}|lO6#->DQFmj^^)1<)RxbSy5bKQC!O$0sNCCY2s2(2HHMD| zAVNt8(;mbxl~RnuP6hTPj7op7uZydvMw4;LM+WpRBS})s({}ATq;S^@fT+pu;u*PNC`DFYm!Ud8xMAO%BkVA8+dV&@+Fg|O~x4%fLRmcfc5C*sii@|0feEx556gw zRFzv`MX(=Sb*C_q&!j$9^DG9ixiW|WidIS~{af4@E64zvGca9M11`Bj8|;-@Co5G& z?_z4ccwe{OAuTrJZa^S}i3R_dH2Mc8xgok$R}kwu-d6*zIl^UnXHDqYJUQn>{iub^ zD~gW@zy)#mF!b7eS+RtcuV46YZcJ(jINQ|Q>5ZaK%fGn9+ITDj4OZLU*3j??KQUBT z{!CA!#&{M5tQWw9F~CbHZyj_xTZe{HE^JR5&Zuj;%7~2@XN>0ZHgte5mdite^N6Oz z;X|9=6IkUcpi~O+{?nd-U}9*Y>zWkNo zjwem)?rfT<@!IJU3cAGZa5zJmuMA~t$ofNa*ZIHd(a2JA!H=QSdx_n};>!JQwchzQ zSG{H^Cdgl#L6?6loSOkukBTua3gZ{l&{@wX@fIN&y@k1A<;Pz+uIXnwJJLOX&?Kq7 z37Aycw{EFurLCirfz*t$X6pL|>XBxLoL|2mB*Cuo0fZTya0FnUjnnIHs(af2fSYhn zp*#MqekvfqGxm0&DC@5|+#VwJjJ{ZZNj>losnZ}VNg%0bqaCl@c%KnleCW+0vqCPl zXPMdPAkWIJQN7AY&I0`O97CYGEn`qIgIFjQ_C(=Q=z|Hf*Lq2dxCRX`q|UA|I4xta z(NA2m29R}p!kB7zcd{F}Z~og?i}RWFb{&o0O?h72UZS!$E}5D(_0^~ieQe=bY$_${ zmD&%7<+Qca)i~N=4exF{8i=x;U)|f>(V12;8uJWoc$l|UubghWqYO)O(n%AKE1st3Y5p|b?aZooNL+lCNv zScXljdl-6kR&mA6Lr-0Twl>(2L5O7(9UU46PvEa6#q+jUCFWgqj*bg2CL7PQXb zXHT^MV23CTHwn0^QsqIZ1=-0NoXtiDdDoHPAC3i65p2an-e#u5s0`>iK&yzm?sMRK zS~f-8|3+&Mv)*$4R5|5qy?zGR%TO-W?zN(F-8EcNei*`I!MY_mWYgLRD18hmQ9?h4 zWu-G0n|QTdB=_c8yANij`4QDJacINF!IA7?z4#Go;BHr(>ZT31Z^Qnh!5xtFZb`n_ z_qKeYG!dY(tj25E;r_vpRicwFAR~Hi(s`XsAp|+RcG4B16dLsLtr_O*IV*au>-Wg- z{kB=hGv$m~OQYZfB7rG%39MdYuY{=3>ec&Px2>_DSkf$Bk59H_*w9@rJTfn6z0&Dt z!3#9ac(d06=~)1+SvWf9mm(q$zAVBMXSplR05$$$Jta{L}*yNYeT+w zgMzg6%I+E@oA!rq^&Gfg40SX=%$3}W_(I+O`i++U;9g%ejT5PWtXJT)n3;6F16)XP z_13b#%!}MbU@n;>MFWFS*cjU9Z@ootr`?Y~Qm-GqlAIql^ST5i z{xZDJ_5shHHyuIlx(S|Q3hbmj4*~ssJBZF2YpNEVxg?(n2G&A9@tUn6p19Cn$)>mz zn1rV$)PlBf@uMJR2`-?Cr*5)u!Y7OZvcUnpv&p_0mtmqE;NA)7(FJ@KKK$JD5@jIE z{sLa=UUY6<=sSp_m~qFlnDy%{G;-zx|J6W61=xs;>+&1V%3-nxO9xrjuCZ`mVCQoY z{z1caJf~HMrXmPCa;F`FzIbt(?)O}bx3nvHKZRzzw`zOUofE+OaRkUb7fkD;}J z+^djSjwGf}_YWarfgsK66!z^mDM{>fPY^}laX6t4=fShZkRV&jlmne2=SAfh!R$Y*Vrephdj^;exgqUD33m`If)nE@mLF=s&;>r(0SziMa49jlto$(Hg0ac(;i=+Ml z5DbiLJt?Tm*gPDvTNI&uBq6@Uvt{hDDCQy2|CwTXdSbN{@P2VflLsa+1K<)p;pxaB zhpeO;vXb?S41(0px_O1Lo`2QCbK26YYCjzqgCZSDQ%g&+K=W#O?-z~b@?kh5N-~1A zua9=Xth`7huy~;Wx0|LEn^GFp6L^w5Q$sGwdVdGHi97L2D%89CPq;6*#7e%+tMuCp z)_Z8Z4U9>0NCsLL+}{L7@ym%sw1+S|Fh{kgCB(!w4}8pl)w`^^P&)i0I}OliMn-zh zcZPx~;p(MfPU!k_78*dG*DShJ=gc&BD2`zEM2InNz4q(csSg{d3%hGFL8X(yUrMJ1 z(zkPbHCCeAJX0WN4QFMeo51}a{Lr62GNO<`dPH=?kB%03&b=xVt2L}h(#q9LN-6ex2A1MEc80L|xzQ=`9W)X48iH0{o{t6qr=eT3aODfO3NpwOX4$GM!Z4Rz zsJ@P=p{qr_y6w=wT_Q(^FT(@w{l%-QK6TIejzfHPZM7xAtf zl2>;R_8T$WfcI6q1a9?UJP@?G#u3apArNI--l%uU-4GA$#m-#yBKG z0hU=Q$=V2rn0xtta+x-p#yZ`P+P?yAPOVW7dIJ7rh;F1%Tu6SlZp2n*1}7Y1-(eBi zNr=5BOoqkZLU9h0o-LGZ6*tw~3OD20$!FS(M$+T5w&TFR2gRneYxqnCk%qCW_6-%` zww9&?X?Mq2a&$UZE_sxir|ORoQ9*Xox8(hS<$|+qEGjmOB?>S8AJX1E9O`|2AFtJ3 zwL1FjA}hjbl~PDYDuWIyDxs2;V^K+tA&kRJ?UGeuN~ChC6h%zJXv`QzOpcSpFoTJ~ zlrhE_=3oxK&zoBN@Y$!&@3*h@$GXE(ZZ?)6; z*&SG(Fm2NjQKWh$yVe_L0sqN~_he@X|2O)fs72D{tKJL!W!f0jizw(}8Kts0RjZA0 zFv@`(=%gr7;k6#~*zVAn03P_LPS&9Xm0P3kytH|Gdgg>U<5@rd=MY85t8}}7Vy-w^ z91%01ShA*409hFg*9F1U&lHqb$~{-EB)AvF@g$W|K^~Q1e<9F|oRd?K`OT?!P3Qxd z^LdokM1>cO=sHhsB`0u)%X7S_i)7RxXj#NjzUTCoV{`dkdri6|?XL4Pq;?htCb(!b zsGYP_+TUJLu6fA`{q2vD|B$@(l3s8 zdVhQcJzE-i1ff6I?MP}!6-n&X3WQ!w2JV5J_n$w1dJlz4SFtywMx;CR|ClK&mBT_x zf&`A3x7uRs090bAQ2Jkxhq6TLTu_krTRDpyGPEWjzJqkDT>a}3)#%?Ji}lMd%uTfi`?&m*T9klNA*F;qdf$=euh<21)W7N@}v$nHR&0a zx%158g1W%BTo`Z@8QwUmKP^S?kNz252Pq$>DF69T0i2mQQRKke zD1^t00rDbGIibK-jE9FTKXIr>63lm(H(1p1xI96TUZxew^9MbQHHZS52#pUzn zy5rfgi#jZ96?~0yZ0~PyQa$0CzNQf*U+3~2#<-$B_@+C8UScOLy_*%ea8fWI{nw^q z_5jp*h~v{yeW<)d4x3AGt4#jZ>F9rrHl29LvSv62;1CWLK$x(A?G(|tc!{>xAYVEd zb$<#4zP4B83+h9QHlDFTv$M!EmIKtJ@9uh`XU?koYo_SfqF=GH^7)f3qoq7oJ=EL~ z<>sW{yGb+H%qx84d>Wx2<6WzK@QQbR82Dv)>26&e-lQk+g3g(m)_V%!5_{FUKs$ax z_F!wZ6rteza2S51G0_!jxdT&koyhCdWy1r?9=&*uTeKU-718CsV&2v>*0x$^6CVss z5ZuH!#m{jl=xq2lW7<231m3GrQ@V`=$SqY)=mMylp=Exv8W3+sz*|zM5+L&LMLO5R z+r2I&+?_e2bsxfOc9q`#2ZNx$n+H0ZhFRe2C{dn*NxtO`&K+5o9K?9!SaikjTwlMBKsAZf~7jH8P@xkb3 zyc!3f8DZbMcR&f?U|Ean2=>wx@-lTgXIEhd$4?=d^!!t>FmT{87yQ!^;Wsyh?gtoZ z(MRRTyHf(i88upqC^@Td7ha{_4}z#k9d;UNGs4^sBp+7ROeA@ugP#SUr*Nm{wHcqM21sVZ6%0CXC< z2jE2YN?phGJPUe?VPbq?=VT)0-Zx+lsox-J)w)uMOi?D?;{tCc0W|M){I3rrIx`S9Z3CbyQ$^2MqpB zH_!+s4p#MWI!|C;uU7208?0IW#gNy%3lmSDM2`=)gX8>qcZ%U%tCKnTQ_5?+N?H;KL;gdHd-82W4ZbR>k-8#MA1UY{H0 zAQuskgq}5*GnhJ09~x84ByKNW&v2~@eeK0;OD2l03k1jgNjVUj=EdtGI_PVW(v1lNm0LRP`G!#U&UGbuf7T9cHtk-vC-d&_TB4?^uLF6nB`1eh0jvxm%Qdi zDI1nC>!}G#jwTcE1hG5x3(&OP)dBJm$r`hb;Oi`!I}{nMEpsc$t3oGz{{~Z6>p_zJ z^t1azm*nllilQKe3?WRqKeu6Iq%4x(%%Ya!p=%ss zRk)L?&xK&f{g8;w434DMiLIyj`aYm-Np8y@&geo-WkrLX03Z#H=cZL8T5JzVS{h_M zwC~MQKYGBNS;!}zZbnN*!;CYv(#>9#0w`QU_kG@bo-MQj)#Y~#0sf}({rB7V-<4!% z?@n5NEcg=Ki>QZS6VPPe9lN0~0-$Ce@2Mr%QSaAP**irbuM>VjIRM?m1qE=Jd9(Z+ zMZQc1WPq;Iv&P~z0;EVAp!u;!?)Jp^6yl`^TF#WoD>^)j9iu*^Z$NX@c&p=tUN!4g z$d4oOZ;f$@KYn3F_I@a4f;98cb_4smWmvLK2p@0`s$hBAif>mRqO(t{ogfEV346@ zIBQ1kw9e{jkeAk_V1bDGLrb7wyRIS|04s}ZQ{2cKORR`X^$Ud}rt+sWOr|i`{SG{lO z&ZfM-sUJcd@F~yJDu9$3(aBl8oJI0U=|U(rDB%E)+7lD&Pn62PoHH=drA{kvrwa$L zm;_K2Azhw*^VF=9Z5T}o{x|ctm+n7h?PEAj9Zz+nC(G%ReXD>22LRCocXz%4YrMhE z*dXF0jgSvVlJT<+WLyi(xxuJ3cp-?W30iJ{kXnHPW4BE`_1ZN8{zMUgJ-7zaMZm5H zZ^g&ogktpvS+2(k%goo|*5qob zAk7144D{ALJD&k`kj%=T;8bL5C($U_5kGO?>;K4tt^uBSu z`~3$-l=Vx$tRV0pC23tF^2ok+r)4W?z{-!ghq&~kD;4R{Y@80}y(qP%JK#Ifx(SBD zkphBXt`9S zkh+Umi{8pdRJ*`Gj;|0{=|n&IVXT;XABjC))C7nWAJa>kkPpkTWXL(x4#}YF8RP)z=QnpZUICr%iY19tp~T9?RFgs77=TfE?|; zF%!U16*9E#{+bm}K=?ID#_w^?OrFBd)aC`ttcIbG3-_OFDq+tgwOa(KJqQxsjK7Io zF$A82V(#&mkGiHcFR@y5saW^BW_s%Ua^)Zw0LElSZZgcx9W4pi{LiOZH(OUE9rYgK z0#XJ?hbWdnx9~1Od(E0P6(!GdB;g;|BDuInns;!U5*Q?;|Cp8+24pD-d{9~W=7NYJ z?%TX-jLWM#fR~KcgPM#ORL$LG8Q>nFvnNhyxJ&k`_lL1~AJ%n3?qB+tkHVFqVWqrJ zpDrT|9q)P*E<^D3O_x>e z=xo3uM`*P0@P^M=6Fd1oOWElBL=}HDx%J=0YE9W+wI&|xe^6AiI=>c>j zZn|&#Rz)O&$IDcL{KHB1zm&OMk<)KG3SpWwO8QF6gfa6p^sD^|o1t}s-| zHR&#jojH z6<+-owa+Z=4=dlcb7mPjN^6iss74?ihjO=;0g>HFW>+3%xn=-SYl9wkERq$8ulP+o zk?$_Atmvv9xbXk0!n!rN11hXNy#U%go8cFm0K5ATh9A`g5_u_fTy(iW2e|!kAM0Hr8TarrwE5%JMb6GA;T@C)4&UU>Sf6txcE3gUR<)7JGjtI|$5K z0Gt^QVD|n{oIm-=EexmyDFiLDg5gurI2AL$;|kv30XgL~wG!YL@J{k_{~7V>x$tjC zmNy`GBXqCMVu&e=wBUpEVl7>0bL1PB}+5}XaB16#Ny6(U# zMO%H8%)5q2HNa`nj0_!mdAg;yx+k1eP_Zd3^XvmEO!fC|B8_54vJ`Xd5?rVG`S^Js zAoo>V_&U!iEnqIeFG+u=EYyJ)dfX4uI)nTy`JHk#W%qY{DtOa$GXqBeC26jkk$o_R z6^6(CsswYzDM(=ItX|y@2=}}S*!x2#@K6Aw8GU}$d;2DEH2s$YMQ5kJ{)|W5 z??o5!Q#z;P;psKgzZ7yh&tac3V*f&E`-fW!QacP$W){mc^}Zho+^J;^CZe?Lsag<- zVP4+Z^E&(e|JD!vfB76u|5`X~$4EI5nk+{XzZ-Xjt81tr{yM3M79*_M;iD(ntchx) zV*}Yr8;wyZy(^Lig14+K?*aX;Df`rFZi^JOi6vlOOVAJHPAe_?C3iPKPJjaDSSoT~ z5*FH_d%j8@jg`^AO*QDQoW_HWLkqu{;#P1?UZU4%5PKdRo}1hij=dQv~QOf zG5iZ>0{z^cf7tH@)Db<&5_8H`YFjbaI?gX1hXr2KNjlUXYz3&JBD1Nbjs3vsx zPZy-N&X=F=WZ=eRCj^5J6mycA! zSkMTxqUMNx7np=~({8}?iKn6QLyr8}p-Tm5Q^e?d`mf~arfCC&_wuKXxOVsbm9B7Iks z9MDJ>FdS-#2gWd9cYuX2)8DD7gV=f!5hKUcA(*Z`ugaA^420x zE6DuS!l}{c({LM*Q`d7u($FFsQaO}#f1G{mz%;)y^*b_e)6@SNYTxS?{qZ}dJWl>2 zKVqYU9q#}K-2-mQuigB-8Rg)bT$mcNUHVmeZt0AjSyKE;-ho7T?@@9h&}P8vu3NTj zc@%KKfCGPqns^dmV_>~9K;ZYmriSx%crXH<$zi80lfZeltbOb`g+*T#T?D}g$n&=q zy{nl5+-uK*ZRcF+-9wM2yY&^*dKkn%cDjR7oA&|Aj6WVZd|QyP{a@Pb2b9+ntt`IV zv&X?DDVdWKJGacA@vs@msqoCpKo52C;hGvMgiq19$jRJz(`eC}41^ZtJ-+=|0Cl6= z4lG8sKSqfBI#-&RV;Zv$7#G7P#DWJwq5_N*YH-(joOkylt@GJ{(r+;}X1c(9ap+rj z{KuDrzX{&PY7c%e6_5V2a^#6O@4b;{kx;+=N^KMzdpP_yK!$zf}d#j|| zm4tva0JtD+2T>Q~0ZzV%Ue~x5N{~dM$>4=V0E$w^AYATyUwSp@$1j?6N>+TGE^84I ztgc8W#{(gA2FOApLD$?p%0k-Sy3nJD?r8KPe zUUa;MyO;LxvebXXq&MGVUU-0MtJL8wOIw3B z=VIJ$2$NWjuKj83hNZRN(Bc0+rJX%AdS@qMYrgODR6YiAus3cqEQINmg9sJqa4#s! zx%a&QjDb1PmD0`ITQ^VB^ag#Z4{zTJmRbje@aJr=GwK?%br1E-a+uX51l&DGdHIW*ey zCd;3PlAo^;lVot78Ky(X%iR=RD5NL5m&9gwb%PTwF-7JjUtL0b4+|bbaIi}6 ze2u(78O39iL_Fg(rR#4;C^q_xB~SMXeLG(5omI)<>i6{3-YFCmG@*Pgws>Mvg0%gM z8^45F2pcxn-!(K1{JgVL;GaDT6?P~H!C^@6JH+ zmU*pHVY&JYYfKcZ>5&DOu%8Ze@@?$`83OQkT`27eW93J_;E)*?2Nt4+Kd%2M+IF#N zW&bGHBoEG{D$Vz2iNg9mej*>%>a=Y1Ts%EnQ ziWkgyW(jWY;2z#Y*?{b!>HSy!W*h7i)23tc4kRP$LU{QUDE9`n%lnl=f30Q9Z+^5+ zSv1tG03G37U`up4+pz-;&{m3+)ihM;X#l3ED$U+;2%r-Gt+E9|xis&5X%+Fdcx>!T z@VV%Z?mZ}Ke4|~ad6%PPzHEO@?2#r|7F%*d#A7-Jk;6h7F3+0tc#MJ8jvCoTYCRTo zFIImAIDrn;G5k)5D`M~)a`$EYike`?^K;*-uzF4{>92tk-bPo$7pL#o2&SfoL zr~a_Sb!#N4@oYhhrjawD!S1k2=hlraO)&W1@KiqbwZ&;Oq2LBpmhX|bv1|p6%5D1| z0a0R6mBHZXgF3Xpk~tz2dNV$iT^Q#?ycrL(C*M25LBUd=>D==YKCD|zA3mkwDY=i7 zca6A8c$JiK_NGefEtN%!Cc5@|@8M($(XT~`@Q*UN-7R11?$GZ;3}C)lk1yWc{YKmh z7uR=jBY0;1AN%9YPe;E6f|_rIk7l?_?xHbJCV*fDIEH!00u>)Q zAk0Y71K^NB+1DC?3Ui^>9s#!Tpxf*JA!I%!OaUN?CGb#Ju3#-j0?gFKFJU)Hm8={kb`#l6Ho^364Y1sLC$7a|3p3j#j`*zo?{R z!tk5XcuvoOqSONkCM`-bb9|LhFEdoZT=l@PA-exwdw32xmu}J{AiAZ`6W&TaAKdhf zWJH`RNdYVWg){KkL;c@!Ydn%$A>6OAXiBOhHcgNbR-pKnn9o8ae$bH|k{|*JQ&Uz) z(HdhrWDJ@IvOEWW3?dUgkv^R-Rsj>=%j3aYp`nBgWVDbno*&TRNOBW;eO&D$9quBH zuP9#X&;#GvS-&B;@BN<_F46Smt}<4>xjd`q=X{f{RmMTI46{&sD=RD2e(wy(3~kx1 zVvW@E9k0#+8BmH}tr79{NLW~D*97eJW`?Ds&>#IjhI_J(6y)9R6PVHzF88Xj^PM^M z#dz~XwJp8yX zJo2RR=bl)dg#K&^x+B}PL(0w|FvZX%%v-!XzUlKD&5(IE2uy+l#H<@Ih?KNUB0M!Pnv8w=rhsLL{r z!u9?X9*JUDoWCc8OnI4iVMt*yF(B{iNPQ{(A&#}i?^-aYsUz>jOb?ZlPy_YIDPcuc zZljp3SE93)mZ-lh{nAT)UOMrdRGatG)w^Oze0>o}`%CD`4&?hc>t!94hy`y#5sNmIiYAIC~5v>GjY7^9z^0tASTjeT-DT zK2-IT%8|H<=0()l!89*M?0JidrHl!|*0tt1N*ASGIB(LnFf%T2)=P);7Q1vORUT=1 zF=P%~*4wEx@J%#Q9EG7i?w%|k{MmkSYi~SN@kADe39S*as+SB|DA!*6)a z*C7jJC0xHen5UJ}_`ghhMMulrC) zuY7-sCBI+(4U-{GabV4s{gu3YxTx}C2ZOm5_D0?2XO8tvgoi68#_Jp^Hq2SHTyJ}~ zMX|A{oDyUp78GvmjuzOl&Oo_Vm(@>h$+443U`x_Six1~V)vjiEViA#%7wsEvue3TJ zE^q$u15%THdf!`+ySlKmepz*9Iy1O13QD!YP93{@^bzvSuos@>>N71M-}RlH%A$uB z2Cg*G@YXkUTK}__R%`f@y=dc#e4X;Y^n^*d{*@^YUz_SaSkthT!zl4dj@8WXazb^t zJ(;aa;~U)%%c(S61sf)3KET2iRKAZ>tFZWTg1I2{PR%>jFc-3&d&98P6`R-Qo*qnR zB8kvpn}PZ&=K4JBlmu~4yni|{{WJ~&q*+L>$LQU_ju;Abr0wA*&Oz9)*2fhjhW5)& z6tgsde(z_#Jcg8^Q8PK3QgPJ3($%uPJoxTAZ7-t95u5tu0`UFTT(0>7qm77SotVl>g$~Ji7H__k7gZ;FU32BY^5#n_YFM*dr->!<&P#* zd@oQPg2(s?3k@>MJ>F<{L;`35yg0pFlIFUsiW)d{@Ah^+r)gHxlv( z1*=eQ<5Yg|UFN6pT&d&%$Aplsj^AHMKRlUI+m7nVvu~X&T#?fIy%I+3Y@=AK|M_Z- zrAel9x8z`FU)nN-NyI=t4N6;v7-Qp*-~RVXW-Lwdr%0; zA&+GBqb8#m9FzJ{*H*M}K#ES_*|vUsd9jhgMD_&jVIjX)>k4JTo=Qx9%w#UIOm1!rD)#V zc_hL*vi`{yOYa_3T@7aaV?CN?Pz`f?Z`T(?XM$d#)zei&OC{DP_Ya}>-;*s6-Ak60 zOIE9=T4^R<@2{ad51~RcnC#+w+v{B=v)e^4ny!{x_T(1P=_FNS^8-ShRr>4+X z)W*@5SB6=SsopBg8sukE60RU%meQ&+Sd}!%B76QvqM5c!c&^vjPjS0 z)HSnY<2AVESufE;97b^J3T&xheCYjC!nc41vDcGvxTIhFhZbq zstZvo{3R`QKkiMx5%hw=;==T+QONPLRv@&NI$e%r8XTn(k#zg5A=YE_Ag zZgo3C%s1)E`lD2nYVWrR0+;;2ij9F7iSF5;XtMTf=>2@c_|?f7$h zI}{U`?L$qB1}GEg6JzPG1u*z>T~kv>driAzraMuPj(>g%0}N}UZ=Us|Mtlxf<^SAd z&l3$eziQ0vvtnx7)sDMYp)kv}&5zbAE(&6Eb&i|b>QmhLTe!B>e3Rt?VUIpw*2^bn zw}*Z8GLEvC%Q`rOMh^$97QHbz>~Cj(Y9TYlsPlBv1NVUI1 zt}JW+*;$pOZkEwU&C}pp&@EZdGFdN!1B5b3?tqet@9&wDx4P4O&xs~Qi(rG;-wGqy%2rvv?P02Xb3p&2 zD>0jOnfLVS^tJioVIo$}?`o?f(gL~pr5QUeu1jNCyjf&AXTLT!rgPE~hD~`*lO<#5 z7~#|W#>u_Dk*FS&+tnS*(!3nminUkKCA4};-cn6|m|tZA{;*@!yCz4kiFvN`G?(ms z%ZN*7IoX}?NS|8~7J2kQ)MEa+wPAOUHdV#93EM4wD$(-$H9>6JmZ2B>h@FzFN^)A* zZZL`{ng&T-%r~Q?FV;2K=t@)><9T=zs98%}%xdL;;n**GzFT!k^A_ zKDy=buxsAPqw{2w%t}EumwLz zJklxt!9E!NB;sJK*HRrmzt~dj_KNg8b?JH+AhpkB1d=P>of>|mRr}6O-J(ygTW2j! z%kg*JLB@l2Wz%qJxY2WRABtje<1wmUjjw1`ol)r;z=)o#vD@(9uwh ztGI?93zu)}>}X&tD&ID2@v<6gwb$ZhA&0BEN3uOOiH7+zdw(2)L-s35izo-_dMs@jVB5W$>EB7 zh?Np7ANxk^Z{Epu4`Ey+2L5a2X#Nem9~!@A&iv&JLXK_%X!=vA{Qd@@v;;sj`Y0th zUY;ue%D=gzaqz=`8-7A84m4G)t8=#^kW7WyWDarpb@KR_YB2F57FgS zRGHP+!u7YWUB|5*zE)EcS@=ds*{$iY5En=eO4de+m)+38*{Nl?8`iQ-`hzZ}$LHEU zZn`=d9~t1-?kYj${?GF-Co84j?zc?;{O1^Uyv39BT`4B=yY1o4)XB43wy}y9N7nU7 zoP}OKErbwp3FrE!y1Ax*>ajjFim~Z;Y1C$&i|>cUkq_EToY+E1@b&)CE_zPBa0C1o z-7nJIA~OOwVd|kq@~wu_V8KY03b#$KF0KnNTzaAZICTE@mV&3%%N7QJ1EdxJH zlVyY>(>Pbp&_acHG&OiOGQ4oS0A_qEI=L5}d*s8q=z5#Fa>|LOsy#o@6gJNMf*who z?9Z(6a4P~sP{Z%)-tNhM8m?XVqz}C_n#@Ws-yZ2NBW+kfWsdhMQgC9@2v}rYNTClL zUM#EFQ^RR~j4unc7_KZ)-TPx9I?7IUKzk`aC0c!1hS(`7B?{H!w&}*aEm(ourqGHe zu@!VCm5DM_3+y0{1@PRx*;q`x&qWlG1ywa4*W_;uzLW2n#%26P;rf zcra7Vl`kH4ini+q@qZJkUbIX$ns0k5uaji1vQ*g+B9JQ|1q}tvv)s-m8hEs);+LF@A5iu@nvQ5XC&;> zLI;e_Z0mM55*cR5a%9z!)O{ zliP>_v$h%^LBDR+Xj}q}ai)dK_EY}!`u?8W`N5pLCbty5d6m6_8iHO|ZsSLX42!$^ z1|2qnVT_qj(>mnNu{eDgOH9dy8W2W}01qqciST|XQiw1I z=!~Loz=oBWIr*^-7lbYAZwk{)rK<6l?PV*%t5}T&;zb^kV_$``m7ntKT3hFH`TYZH zyNe=C3Ol7X3bYhMUA-V!FvpmOQi`+(PW?RK^vT9}^(lXO^U_Q&`f(50+Jztf{JSd6 zQ(jmd6r(E+tG0?b5`*rqs%hXT+}p34+U|woo-@_feLC7Z4Efj0~?;bac^y3~B^4ju8nt zSM1x*YX_Wv0H9j(kRG7;nUJQ~EY77ClL*`FBJdZ1S)lwQ1J_Y^gC z+iY)r#cDF_e)MvTBG-gFHaMR-)l5AXbzx=Q==sbPoKc6`h|1`=VVweFjS&UNNe4nb zhKN^%Uv54st0jFlzmoBqro%)5q^;hKM}Ue9TN}sGfLD2GewFcU?fWL3<%g4Uq~%wD zcNy{_b}sIE;=mzZTZZjDWks#X3nvSltwXm$3kzOB!KJNdiZ9=9N6o9E*GuJUO|j~R zbFRd3HkQ>6>jM0iVFi0Xro}GD^ma1y4vmiIM(sN^8vVQvwfc$_CJ_Q?zZ#5c#2aD4 z916r(`yh*6{#DW4Bh2vrLf32MI_p$o*slFz2aAH2rw(g`B*7H%u5#86Chpk|Z@IIt zHh)JfDLlUrs0Yh>v@%?NAz~8`Z5jQ)WS<>cAYVLy!4;y&Ywv2ZBCJC{@U~GC<_tY^#;5S# z-Ju19*oV9HBsTE#50PMftd+L5ifrZn*X7c1#kp8vY}oB6*+Fx=p-0!CyWBHAek^La zkNfy6AFd(RLRTBdfjJ0oT8j&L(H>=(h41mPg(d!_N?~5|0I^1PpvZLHc3f9n<4OKx z#7T;v-KJ1bSKsJqus@tUsGrk^s;2Erq*?GP_9!miEZ@PvL=`pXd9v%x+=J{_{I>*s zK3vGRCYKDtJtXQo6v4#{e$jmFx_V#-HlKF@C~jebH8{;7G`iOmEp-soNrgNczxtq| zwjd_w#rxL>AUGY`9Y@^fA;=+vu3HG4z2Kf+E~5D&!)(QX{LSWr^mJ&?{ST*h;OZ zQkO2DNM8(H6fYcTEPDAm&lPp$9H#5E-I@b=X!&Eoso~7$`t+}w5O^ zS72xB>_xYl8|k=rs=XBGno@N6j%+A1jOh0do#XCer*KHs5rvHc2byC)_i$3OjDd)-*LG`akt*uzqE%v=HRu`tQ4)v z7;g_}m)4ZopNh>o?yDVR><}aMB)+SWeeOly^nW#O!9yjuAgj8*!Pjdsi!57ZJnhr|Gpx3&=}K zXU^rAl&wV-Y;b7AU)iE{Qol5FrPi_P1kb##?kMu)xvOHXeoiIVL5QM!TsPlcU3cPg zE9yYVY5h8d;J2?KRL%qU#pWBZ*+;5EorSW&Vof_=@@OymNiN&LeS5X==ZaRh6206Y zjJ=fgsJ1jP-blJ_Au*{QW_G3sJ!HEY;tBk}w^!!| z1F12kS!ZT!Ud1pP*n4 z*K!(VaYzzZn`|ced_{vFl>u}JKlwrW(%^A^7bkly`8?l`{IeD~mVw zpyrKVs&BN|u|s2E{c;^3Qc#vAx^nb|zQk42vb!AMf7-cQc`J7LlIt;U%oUgUR%G4P z4=N;GB@96!^#qxIY}kXX$Tx^`zo@j-YGSjFyxOdl%JMb}C_aa?k1G^AXLfP~ry1

    kBSmSJ&p?(u>{V(ozy))4ut{LV52 zch&I=b#%<{Z7Ag`Zw}qy^w@S1<}nwQ=%|GC_Mp@TOv-9&!rgfC3~D>maVR{S!OI^F zci-MpFsU)H7UL)oIE7?TF(-MF191}@LyTWR_2|A*_B8?SxnkmdBHv=QarcQMt)b53 z*}t)Q-52v#gWy}xE}w*^lOIH)feBR(#@|N zINXa&5kLJ8vlZmlc^`H(88-*5=rENFXmi#pzf>eJ`mtE=kxaaWQ5+DQwVGRECbh^d;|Us8OsK&!V!X4I|}uxS--luexhHx@VODqk^@flMbQj%;h0 zo=aOro9_NW3I!vr3C8Qx{R2QaQysI$+JJu2o*aGPZt$c8d%|rfz*5s9;BHy|qreOb z#XMg}rZMnHsZ;{eX5$Gxn-ca|%AQ$CvM}$L0zqgO%{OecZ$AQXAMM3Iz=`SWp-|Nhpevk* zR>Yv+3xk9{hfTo#aQGjPWgo^K2zMz0R8*Lux%LLY7C&8jsrQwCQI|$V9UsF6tDk%VlyYbMxvG0Ume?#ad>Xe=xbaO3>q+H`-gizgB7^ z&;~BiC`Fxr{iemsMB$h0k-Zz$Mpx1Fr4fr9o$l$6MT%YGY>8cQgk^B>x>WTrxA+>z zcARYBNsjOJN%z-*Y7QAts)o9ncoQ@R=(LpX7nQSyAe5_zp{L@j;>F&>89?F27zbvU zMT+zm=$t1?lOx$D_{@pRhRTZI>~I@~tG>YBUytn0de6HYgMJp25lG7Ki7t`+WbYdl z!*fSV4C{Qhxf!PTG^jSz~5$Q_rbpSL_YJXi^jcw zSQqO2WJZ3K&yw|wWG#hG@#NS$WOEG|g-w~;2U6#fP_h9TwiVk0zNg?fdpx}GY8vuC zvf8LsXvQn8-pWkvB1INY7d!ct5?{`tT1bz`KFBFsC;`=-pN*cmK0gHV<%G>s^1|Kg zkp=bN@a8%u^J_~^CVF65^iO61-DFNC7Q+x?hz$c1ond}GMg(=7c(>h9z-wr&td2=; zvY4|^?RslbDiTaIL;?lbKXARjXF)alqJ6txP>*C4&Z5B~86*+g(4$W%h2fDOyc1z> z(HGC78u}Tm>AO61TR%$LpAtuvE$Lhqf>t;~hs~wq>6c(|SKdhst^*mzc*OJh1u};p zI~G^8^in;e$V;OGvDNF7Y9y9Eb&X4$RWLVRw})pfDqY)cTi4&iNO=51Bi``cZ{Fr& z+w0|-zj=>HO1di(;&6_?YPc7yeEPvSLvP`LIOq8h3P)og$+7iq?gkaK-?WbJ-pd(& z9(c#_eSu8BQZo>U^{A9QmrtDCOsAD}yILoJz$WWlnc{c8SYh*=Avhurm%lwaTp;aA zj$#S-4{6baBhDUd*IF0m6`qM9eE}ivlZ|<|cqk(>)&X}YDylfmgojyU+?~{*0K7L= zm(y(1Be;@O?>C$8ayQZqdj5tzbw2GZAZ6>~aJ%c{jVM-yx79@T-Hqc?pL=kFMGhuX z`+`smGsvKD)(})l9Nb-DZddm@9G}N)&2OQ&ZEaxtn0K}xtd+(G$>?d(aovJ39x05! zUYl>Bks)hNGOL^?WIAHk>$0#e{ixbdZdj5WE-{)okC{9gsO^bfNX^TTb=wmmPEVL5 zExPWL>Mp$M;j^jpG)LTDmlscmJW&HZ>KY)7gXA4#2@SQ8Bv z7@3rjUBzzmvRwoIIyr?5%9rXaca^kwA}b8EXp5GciLZ-t7*7Xp+-KB#h=eI1JqM}V zRpykI4Yq72PE+ilM>mO*EjY75yl9tQ;9zgBVBMI3%j=h;^6p>P(FI%0SEDkEu`~E= zhodDjvqOVX@rwt{_ZX;m6>t7x91|6lNDV-VTdsX=zUyM4d^1-11k_xQHE#^4IRBIZ zgx;7(2faN!@<>^&e3Y>sKMLFmP}A!h;!S1^39JrZjweH*&C4$Fq332j%-<)L1yN3U z(j3QE%W_f16?26nx_Tzvr1@p0>YDg9XHm86uc2QD-6&ns56M6ugPJISgpvPR zHtf2bi2^#sS!0Lcv!eUuv(zzhIHTcX2t!u3_Qt4ze=&e!MP^CK=?g4RH?0~wt~{Drp88SM?DC$h)2J@}KS3SLU&io!6uUOtBWP8-MH z6oUB>s4WmYXra`MjtmcVH3VxeQHCXLP*LOT(B6PCXY@{Td-;Q4#^uS;Rf{jBSF`TN zYquA3$``3|C?*SnRjiw`Qaz|DmcW13dlC!ZWjYEX^t!Fr8Ev;CDsEQ>$w+Wj7h4RM zq?jM5zo|mER8>>0_>0HNav^W8LuO9r@#8m zR%eHkkG=<6=!ku_EJp=eO=nV8vjo6}-bLjBrL{Om1!o6p6`@lbE0FD3C{)MO0`ZUD zxu++xZ7%pb$K{vxv7aK?)AV#=+Dt~mtabdV-5`>K>6hWZTeBSedWM#^1NVm3d5c2v z5FZu#Io8zHa=yq?LzlRci=U?wHp2=klmi zogDGtH;rLC;qa>&3h*?15E=>NpJyW}fHwr_ewi2ki1YdFl{%hgJl)h_d)RQAxdC4< zBx>twlo1<(_}0~JY9f`-hKIE=M|EC(7#OR$f)g+EATGUVFF8@7?c7fd@DOh62eHwE z6DqB3M+D)KziO;huBBXMSLICMU%MxlM(z;(lpGco#@#i@ZSpat^psx3JKEXdYM4up zbjEKuzuh!oRr@~v==s^LUk${vh3-G}i_Uo(?b_De5!P|fo3xG6d`(L=^6EU^;SN`Q zR(WKp_LFyQIn7y{2HQK>V_t)K!=MZq=1(#$K7Pq-()N0Br;p_^wjqhh9<#MO9w;cV zY~NKnQ~B&*(o%`d1FCku_REYElYPGT@RPT1|Jk9H*JERIo3j$c-HlnW5TbA#3|_x! zB4NfCT;B*vufB_!ZxK>nw8xKceK^Sx)y;C{MRx{J-wx0L#qzu~Ce zZDVdZuGcsk{G?cZq!RPmi>6)99ULC>9}tGGI1-Qy_HvOvU5V;o=UZbrNZL}=WT5%# zwl0ZW&2Oj~-p6kU&0EY?F(9xu8h4B8Ta@LC*j$SSvtn+c06?;p*ZU*XZt|=QX#7AW zA>;Tc`hK)b)S+w+a+dZ;dSz-LomoE;Y1GZ?5WVnQZ4r2*>xm##Rb%gu)j;KENd#AY zjBd;$mjJPEDuC?VO=V_{Tlpu_0=wvOkc{DNM3DGajekmJQ{oyq1l z+TPb@agB%k6>Borh&F3JMTg4I;##!*0L8_pWRL5#x3lNE|Cwf1Oe#VrF?Y&9t5;6z{G{Rv$wC?IH`F7Y9D6zb zTs+5fv)+qP<@0FEzhGmprN&nzXz=j~x*4(q>!o~ikdJ@2!1&Lesq{1hScp_YVeArJ zzfMzfs4B`>zbjzN^Vs2*V^ze;?}Ig)91-6sd6gAQDJ*TO##~l&qZ+7D9v~nxgBR;^ z)|wK^WAxXjP|as;Zf)8F(-Dv>T?xJ?hS<>6Jij%aJ>anwOb?0l_%_(7*F8MtRT;xp zQB{5@!nWnviEXT`Vih-IGtFczZB-_s*MhIdq#- z>MH>B3(U9`l?0d-EIhT|WHM@N`c zcFf8sD`=|B(N4xHQl!ZdNZG%%(@7r>6{lF2mkpSd+Nlo8mX+~ zk5h}w(guvSXLNp_f+3jKt35m?2&Fv&2e?G_fpw@-L>h^F$#>$(PNf8z%)sdmkN1B$0Hrhzu z6uWO|4pLrrIIdEs;F&d4ZD=TYmg;-Z08ftFLP-D3M3rbLK>w~NtR9^wcI(-&l3=bI zTG3-xqm5%7m2Z>HTPPV3uL49Ws>-St?>Q=s_kWeI=TzXSO!SRAl47Rest_$L7`!!k zE>_FMYrjIMI@xgkNjoh-pjfI?Yb^08@B5xZ@;w(tkU0+P++WCv{PFiKOO(RRw7veb%0ejN9V}zZ<`9avpWZ27YBxP!gTV zpfBe$L<9=0k&oG^FRk}N=5V+yjKQ*H%R0&<#Wdk!%-!wQLJEZf{bjqCbuZiR=Gx%} z-iNo?g}Yfs69f&LZBRPbyPjjdW{wo;-&Z5HdG*r)*Zn0W2u-9(^3rqu2JZ&%iQO}u zm=0M4ngNGU@d1|uJ0wk&ZI!iENlZ+Rq-bys-VFPaS5aw~R9(|(H9Hn zP|JQYuBga+v9PHnTex;&L9ft<+!e>!uU#QT!%hk7kcyh&vQ8z#v6B3_V!xpV9)veP zW?D#vqf$>F#C2weU8;FAe|R_{-h_}_#kkv!O2+LOD)c`6BI~4w+RPlZrIl5j39eT- z|G@|*I;$lASs#022Debk5Te>H6Jm1|lp3G@t88Axkh2HXBH7V(8?L#{-#{S5-LP5A zJ^i}9?BhNQZGCN>$TyVRKQ~T-|ANeC4ME$3S)qNN$UDYzkeB%=dj)-oFoF1o2_7@= zmV7+1BUMK7NmM+nAk~bvnnRUrY{)z$%SwMk^G;`T&k z$jyF>ytBci(9BkVIR&t67%Ms~B>1w~QPaiGu;wW_T|R&-gycouIjXaF~dUktv;c1!3X0<8%p1nxqDIr3T63FJeXy) z<3ykhipxy#evc9zsOdg@v~rF?ZY( z;i{+pa@ycdjO-I<4$DT0j7o%CdlG&wx?K@EHFDR)%faLE5|gHZ`#v;g&Rc)cKtyN{ z%Wc7lk4$FXMz@hog=o3DqQ}cZS$MfiLz6$)pumJJRm30NzYSNvPaCsyacG@uC3-ng zKvU(WQ4xp~8L53sh==JkdtPY!Dv z^MhiUVR0GE@Koa$6-jBVbC`=Ady=V+5@O5dO@+uZ_9IQ-{Y#LUsUB|s`|*NAGSjIw ze4%kIN1Zm#ix8>=8<;KZWIRH@oa@ZDQT()V^YtIG}Lnt`c&?{3mps!Q)Zor6=(ysr;+p(`00_#z3Lr zibi_Z@ZM~#0F~7mPRj6)$B%H>bk|kbijR^+tqb<3?siEKKCWLRxub)RD2V+tcey$a zWU6Min(jaXF6ZO_A7@`44~6@-YZpQ#$=-?(-y%Cht0haauL;@7GIldclCmTrWGB0^ zuQ5dt*|)JT*=HxZ!w?oJoj@i*LB_ZtyQtP1VPoN2otD3Ecpdk4G=mE=+vUwGk zLg&cv2KT*b_OI8NL2nb$4=Hchq5v3;i*ft6&nRqYkUKGV6AiWKmL@m(>Xf7o0SRsU zK2YPOaS)izq`9}gzm{O$@DAg40f%ENjI!4HQDb24zOISD^G9Du{F6ysBDceXSv4N{ zkQze5lypZUX#_UvS|z;(ltF-A1C#z0SebgQ$WsD}e-8r$vwXmoi&rR-UyJiDhwOd% z@+?ZZ+0rF+4$I#R4K}y>JuCeGqNDv$rx%Q~wl}}z?M&!sU<0N0U6P1l59+)bw{)~f_UB(`(rz<7th`WDfhprfaFhnb)`KjJ(7 zu`5|xyXNK{mF7LNb;#AN=~wyPaxmG^P{RD;%X^2HDu2!!R#d0&>1$&0qCb{;*JGtiZ_ znGaQi`XCP$#DQ1w<*ROJHfuRB@B;u?oO~pzm`HzH)0q!7@*at_^hq(HR}2jVj596* zaTGRdUn5BobQc4#o2zQT~4aGMsDE1xfa#1 zG?ar9W_)8Ci{+Jh_+ctjzx$1}n*{-WcN`R&*)PX8v#Wtc76QYPr~#GkuK}mzKI}E< zIYIK6I51+4dUbu>Rla_h5(nn@1p-{m*fnevusKmTdnV@2k$=cI>3=pF&@-Q+7;%%| zGj)IY2iSAGwEP9pvQ(J6@vnRTl5>^VxI_=bcO$T-7v}=(vM_Jh53uDT!jW-gS5XrS zXhMv{o2G-6H1kkDNhP&}!NsC~wA;biLEAMFBhZitXM6 z@ChqNkLUN9kNIKx#DiV{BDj~Zlf`6m@xFG7fee6rn7$$>m-Ky8Rnbo$1Da8KCB|yp z(rS8!zJNYNkGjR%Fh2Kj7N=$0s1HEt*jvZJ$MY@tclyVHzS_ECY0JIVtx}3LKmBOW zu|Jm0y!I80>Am6>cG@FfV(0nIOAYyDq+6jAFEuK*zDX!+0IlIyp6-89n@X&4IazvC zfO_$BGKj|T4@UYCpxuN((Rz|4>0^83RV)7mn=pY>8Z?M;tp6Y2iFAtMYj(WXxaG5} zsWBw$t(m9NH#6;$hw(penS6(JNofl5dtlo_caWDca-@HwI&kCdw7K<(?;KxCz=)I# z@|GVh7NB#CHtk4R8fhEFxR$!@kd`XqJ2;-f%{N!Bwu7){{=$d*C{p-ju0HTCHx%FW>^N5J69*m8<32 zrYRt@oIiawH$q;B2N;B@@6M!8SY0!@=VcL`!fVKdt(g$k6FyC!U!A=bmG|T#E)r+& z^8SQ1=40zPxx*K?-GX%+Mp*Lii;{b8aP=daz!Sa5q)NVpkx;0s>N}8{axLG>svO4h zFPcDZ)}@wD-`Mm`o~9cq{kCV_BU0TrhRM7!=hU-QvvJV^TFtq8;tUspB%5yMNL|_W z%%u<)Avv;p;N3`0HgeB`HCI87@+b5V)FU`D|n(_UkpxmMP&i^UqUqt3mBkF3y(%HEzq0LC(Y&GkUs(D2)NQ!c(*I z_+R=oFkIIL?C&5&ykGy-FCW>Vog!yTDuLrh!N&Daq;n$wJwticpYnhgOUHl5S|Q~n zk2)`0C>e46@3+`G8GwB-%g$btQMqe*c=9p?uz)XX$ylcaUq&9K4jSmY#X;jm@y|sF zKS#GDuI*VP8huD28|)-k4a-X+yDw~kBP;}iHri`q2SVA_r@Y5q;(DaFwwm*8UI2Oc z?YTyMv(80vn1Z9-SPdroYqtl9d*SoJ`t993a-$|9-o&-$1jMpz{!7eRF5?M({gB}w zfLeV=h%Rc^-wo-;aU*LPPJ#0|bDwoEkjHQ9px+zvv~Jj{D-#Md;I>&Vwgqz#%ej8$A< z;<>Ypn;XJn=aut*#M8x5Uzao~HRl1SRk3k&MYDETagF^lDXkIWUov06p`g;Z)|79} z{{WxENhsZCb$0&3*e*X{MNgfV^0NA@4BKg8Zzkm%pdsk$Td|MV5KmngpWbk+IajHE zSe-7f+~{zy==imGwMgz~7s7*S`jyqrvp*N5>UvD^>PSPu)z`(5@#C%=UtuChK_q@i zHgV~J#YDiP0L%`;twA!Vt2bjq90tQW+41QbWMr9ul3VRGy^(<-R6UT2l5Lh zm10fux*}yzh_!JNMKNrsn!kQs&ON18%S^B&)}UTcd58V;kad$bjQ_#LRYVcNil|M?Ob!_&yE z7xa8^LZc-yX&ObvGVmm%%Cqy1hE;|bCH^16b%`&jGVW)(@~dztM*H`rr4Q#?Ba4eK z3cYnd(b?Gv2Iqqrsb8fMOc)wC#4RGwEoRyatM}Qb;u8`K4LA6X5e+^GsLrMQyYeOy<}lypR2Og;QSBwz@AJdvk!7t9uD36I!& zp*_qR^*Z?;9E;Xp9!~wIEdfWt{^01d+%D+N^Kl6g%d|t48j{E>tN9^aT>(U&JM`Uq z&8(bov`6zfYoR<=_T7w2rLbNb$!A{awHbnU#r-vp%pN&<4|%n2f;PRo6V@tNsPgdm zAmv+{s^Gf)vFGnHt|f=K`lx6=u(Pvb)$qRfcG*(%E>pI zUANBA8+7B+b%mot9W?fpSGRCyO8#8=uUk1=1Zk{aV(5*UlhHDzdri?*hR$nMMLimd zqu^aRLH>+5A}*jtP|OTMIKX`uP~KwO=?$KCZTiugG983=#og5Yh6|l0q{wd|wF&*w zX|UNh5;zLiNf8h2oPpb5rP2Wl zhW0i|@lLm)W^&p6#}<2iHuar0RYd4@gM>qnkG;mwb{2yB!9XzibQcdXn>v=r=^F}+*DTh2= zI}aY*-*Wqqd9e4YLQ;8+Xi?^v45MkI? z>LlFiAzjMP_Ni`}ejRJ?`%Yog@^kN3m6spOel^INKdAWgTEHV}qp|NT;HUcQM3RQ-b3);O~<2I?jmgYadRVd!1N@x#{h2JH1 zNM#Vme2_0D;lyrv6&JITzr6PRE`~H&1H&&FlFnLsSOwGZ6y4g@M+s#}HD5KSl01<_ zzN&zLfR4}SybVl7J@49z<$p$ZG&|>++Uv-&u7CVUS(BNX^trlQyFg@XsN1u1dwOBP zc1(mLk)eY^&eJDosK3yQ&Av*#n1#yzDtvj@=DNhYKnPJ=S}*$-i>EFH4uC{&)jyoSHZ6S{=~9`Ht0-CG zzI}cnNg?!%vn39uTu^b}uKR69NuZhh^w!|u@#CLWq`ar>srEa}mLx@zdLh!Iz8x0E zpP%63WSfLh>sJE;?~lII)X?^XuY_$~@{INP=;FFuHut_A~yn@N)=oPnLHMAMFuf z=uL0%_WE;rKOJNHvz1f|-eKN0_qS5pij??|^!#t%yqPgN&lTm;4DA;ow4^m`_aP4M zeQU;+TJ#S`0~dKFD32|@?t}Oh%Jp2*EI)C!Q-d@+-BivNRdJ3j%#if0CvoTS8@fht zmzJc?jkNt$I|IwWJI38lU{mis7Rb?UH8$#gX(s(YezwqkYUC(KQ zV?`SKk`hL+X8#bLE-V(hC=?48>_tXK4zh-O4aMU-IvC?+&t856BOdsT>GaJv#1RM1 zQmJ3nT+4VE8=1Q*vb0m&xmhgA@gWsk$w7l{PvX@QY6khlqp*&*P}81{33t)Ex7Qw3XDS(h z)y+nb<9?^0#IxqAJ*e2^du%J2;lCf^Zb|xO%6bgU{x6q!E(_4#C`HP8xX{yQcD7WK z-=+&1&HkLxuWWFgev<7^EK}(u?=ec`ZxJntZ9>1L^#4&O&9XvIP9O%|_$D~fH1>f% zG&CpFBvh8jkC22a-r;Vw!hYsJ5)-ErVEeokQ1$`sp%b-OOJxuChjVSM9C(BSl97_mf2HIT1v`3 zdh9Bo>UrXqmX;jUq@<-CS`woZPehap6GWy5(Z@tEEt*oP<%qYC+RJT*4Xdkqq#mn! z4y=S-w=xiTWvg;`ixla(xn?djH&YqX61zODy}zG|Pj?S8-WHwWEZK#nJdW z&29RE+`!9TgH;@nk5${}#+8?bHSCVCxdUl`_F~*c;6i;ewR4g>jTf($! z;%d>@ z27VjnoZ$oG+emm6k_hP{cD0U^%B*;%>iocz@Yrbrt|n*vLfYMc`%otmSRP^s-`Eig z+FAkc_fz!ezrLS!A<44aVvmS(X+(d!=W^@e(nuy<^VL{zab=JvAl^5+h~@tOy$>A_MW>3jGc3Q%n;m_sAtP_ce+X_lbQ43X7Rn2JW-Ukj23}3gA@83r(3?eVz zEf%{}ML%IPm)|+p)zvlFRBorRo7C~-q(HEalKZ)|#+1aUMkgN9a z3kquNhhRp9iMP+wOFSJN9W9lVkdT#C3rR`g#n30`f|qLRLyftp+w&FetLI<*@%e_h+1g#UAS zSELc_I%M(TKSxDQQfw-*xlKsSp9Cd_BIw6_`@zXYd@xi%IW5q;Fr$&|cG26(^gaS< z0oJO(Nd|MQIOp^h?KfANO>Hep|ZuJso!AjDg=EutEHvo>gMLz24?7dNsZ+PaId4C zU6@qTMVTLN(W>>=MQ`DPlbsdfJ~!0Xz8S+%xI`hmjZI9RuZEXLw)lsazfDL;NUZ*9 z_Ap-l%9R^8Lf>Ie_b0cdJ;*b9$yn5AcEi2&u7D};h-hHp-Rsw`;){ zu{_pGFCzCMo?`EX%(aR>eDy$(lmAdkfQqjiw_4{Z8y* zNQE7&on4cj9SLoDus1r8OZJ%4jqYdjLW$&>4cuhs>Jms|DCq{16PW&TkDO-+gWr-Z z8{U6KxMkIt^L&y`l5aaw#d5;;1t{2jCbds+a3tn&tppn*PbI+T= zWK8`-RCm={8n4DF2+^6z-|WwDV||JyY^SI$@M4Ml!&EZ=BiHk_iBG*D*BUl!7LbZWz9{O0Dd{jr6e{L zBSkreHe&}VgPJE{ZO1jshZ%La_q`$AfgIb6RuV$I2DhOAY-e_at8ErnY#I&O?seT1 znTqKSg%CnkAfz!Aaejc6q`Ap9ADo=}R%UOpm2NFT+-!Gvo8x(;qCLmIZk!F(?mj@8 z`CLQHO{gwg*&q=&*3R{Ewbjk=TpN@#QZCdNP_9{H?N7wZN=R6Hs!2;r$GuKmeD62_ zvi8>@A=Har!Z}bF%mP;$qgVJinCMFxi*>Zn5CIq%e^Y&Fu!YO~bskk_HgI8&#Ww2E-5JUU>#KuIr zBI(}l8mHHmew_c&Pc6@IuP!Vc;{9ZFch}d1|5Sh`t~0^{Efjjj@pFHMWm90H?8kG@ zbJr?+XFo2=jrUFpr7Go#csaOMdQ*-RoJvofpj};E)uEA-cV_YT_tp^{yAHY0#;QrJ z(Z$Uy5yzs@ZP?X9UtnkZwvK@yQIzoE^0b&$;|I3%l&5)u-y>C&D7h-pVfW5K4}YvR z8Nna(VSOOeL69>Y@XL}8;$MR@ z`Fk*Y_Jwmt0I0LM%{8nsh9^Jl^m_-2L_)_tg!4^_h+Vd)eytW=I)IhOPn`B6m&<)( ze*0oxGPjQU_YC(b6(#V9{NJm}YXIn@ZEDhU?AC^RV=NE)oD?Mc&#@rD?5S^TmQmXa zOdJpRiGypVHQptJZ4hCN2(j9bgM_6f;+D^pF?=DeO=&NDl3Tjz3L$ie!!nz|WY?qg zW1JtpwAl59H9k(2xybb|uVf>%4e{M9ULh^CB4F4;OAy8n=nUN&R%O-;j`G@_ovp zvFQJ}yc2eADOWCU6vz$zb26^qAj7Kn4+18@9#f` zJ=6u^{ajJbG3p`zGzw;eC}}7y{SbO+@Y5Le=cP~KY*J>za^>3ElB?|1>}@$)A~!Y- z6|?Ycu2)GBUOEn}y1-?VZ6)1JPe2(SxPEI@FVhcl?(92D5xey0#eEKD!n4JCFJT?<*^N+yE!TV_XX z0;|yu&2s6wOw?SZRWB&A_C{`+2`Ub52q;7Rw5cSQo1-xwp!cyETEUB`M35^EfoqSQ zB%K8CQy|a!L=%A=MTBncg~73g0P)@XDy~3U-W{=nW6ti5H@eT+xivy(qwV~O2JXb1ih-dmc`cPeT?Gk3l8xgzO>)&&Gq2IUw0K|ccYRMTVsTb4O)vQL(LVNmkP&q$ADIietli+t7c+SQc_x48x~^3nyoYltgKW!MMXG& zD{H3)SYmfmaa5`r33s1%3@bx%>{@29ap7L>B*1K;t1j1r<*6^QpmvpseiF0Z~U4Q7%JD}xmT&1yPfxe4 z(U&dJu4UcL-}96{nN2nnLXRJ5EYv4A4mm!&F)=C^RM?r{Ra#qnvS{CuAKjJ#SjshVpeO7Iadcrs-&H{p|^wSH1Q$7YSnpc-xt|Zuj1bj zSJNd>SV3@ABE0*iM&g_<=F_hw9_jj3*0x(tW?fSPS%fO5#XdX5_VGb%`4ff!{hq%N%g;jpF z>R`_=X)Op?U%p!h_=x`@E&v!OZrcwVm))r&$L%L>&&6|vZOzrdiQ>fNs?JSa5?~YO zLo4jSgIC=Dp4;@j0l8ICGgXdjkam6Vxg{XzOPt|Az9fQcg@f{w_`uH?md8|R37g%! z)z${E1BVqM+J^DU6#4pqy7oVN(Su75(1<6Z?D{?4fLt@AfBc#Fpf}!yT!s;$L{K*RwRZzPfr_TYKQ%_bp}q;*t~L zUK-g>3EkXEK#%XJ%%A9ci7eD#rUrFPwLJ3N)LcnJu-efH@^tL=s zdMa%a$I$DtAA%tlK&C;G9xVQu|6Qq!++QmjLa-yhY4#T#I<_~f;FvEa3|)Oy=C%vr zd-%9t0>+YW7bRjzQnh=QG|u)3V%@Vl@-BZXw$E*%wy$FfeVE1GUi^n#6xS@HuF6!C z3(punq2#gfnv1~om*oWd>;67VM@#FuXt%Kkw393Q`}@puJ$u=hg9+9@G#tQEZi+~{ ziC*xbm~Tpxc_xzNtol&!X?6pd6Da*u)sP1>x~tb>FA^oj!X*vPnh0^=aoGl zZHOf%gqS+=bjPLayrE#e?7j=0W43M>p$F_c1_&!Z5-*(VXwmd=7NFr9O$6_hAU47n z9>3a>R$pH~)|>hl5ae+fdrN%n?cNJ%*yan%e<+hIzxhXv>D+Ux1ia$@B>X2r{D`n9 zs(QZoAlM2OME5iBEpw9-8F&QpY}?kY^7YgPtf@k1@H=?!jTOz znatZPG*PN`$0=Higx{p3RN-XAoSD7(@kh|D{;vk%g)-?wGZ)t+)HhTKY(jg<^B*SHI}v*q#U#3kq9n^HjUp ziZOAEjIe)zI9}Cwg%>>g?iYu$cb-fN<~fO*&0Z?8daWW}WnSM66WTt2o-MCIDHd)8 z+Sxp7%+7^nVkEToz6o=e;`&q{ZHCUhJCD^)pYeC~3G*})b`P2pW)XaIqE|cC{rwz) z4$t6|tt;EjIJgA*czra4bx`+%Y^FDLIY*gRoCUb|0u{1m=6wAuIabwe_=in#VI>>V zXs=I+4O=kQG&9=7ed%pDH)k;3Y0Au?oW-2pi-A9 z&z!_CR*`x_s0~S~D4e+XPC11?*@%CXznruMdt?6CC?!Rro;wV#7u}lP4OwsN6&pKx z<6dGOX}KfZw(`_!9iyIl4x9(-ztoylQW!lnn;4Km1;zOj?;oLAyM^`7%X<3QyC&tx zMWdBAsm!6#uw+ZaG9GgiKa26!=d1F3qNTX_to|UnKc&(`P%5pBEXu9axw55$RC^X= ztCFZ`*oKrps<#U;y-f|3ezH=OT!Wv<4)iD*L@P5>OIAl9#3tj7cRSIPN}E7` z`BO4t=ujfD1|f`{zCW+qe6>bXbdRtRvpEy|A#b zqyHo~cZCDz3N+mE*xakCrY5cAXOdwzr$y{KG|Q$xy1BXCEo#tm6fx9qud2G@T0V1f zb{0KU=&+(A>}fx9t4{pRGjtRXR8*IHmDbfcToh4Ru%hUJu66rWSv~#7gX8`<>ZS$k z_*?s1k50Fbg#aQVhyX_qUf3UMk`Y=GucW8d_{=QV_~;9KOD4Tr>gZ`I)0KaIh`(l! zd5lxX#5#N&M6UJl_MCk+TmfG~Xq~B5|4KXIzdj+0W~7QQ4l=J%=@a@^lGV@Gch~v` z`!!yBwIcXeAwUe0342&LnMidA(6=y3|NiRLSnM1^WJS2qHTa7~?)xE3i7LhBY*cy8 zS=#QMj+m=;t~kfT8f%AATtkbamwoeZ6C`=sxToBNa;h%7o`YAtZd`*I=|qW_CUgu! z9^GHM5%ppD$g29io_+fJA=71Pm1tI@2M|Pru*GhFkm=mwbG}~gFNDO~BE3+8Df8e+gYdh^U zi=fRL!V@-YC`-SE{98(v&dy_E&HrH_Vy$x|DC^fX%$oZqWL-gmrISDr8EQbF{2d&A z;^6-csM3;$!F(?(yR>M(zOiv@dfKvnr{)!Q5|=1pw|Zc)WqaatN5}K3Tvh9x9ZCG;X-QWl`a^nEj2dQ1q&MDRL-E;BH|G1kOjy|By;o8iBsH>!PSZ`7o;S zNaGcW4TSoq@&g^P2Y>-WPfuT+cKbxd@~B55AC2{K6<(a<(Ptgz!4|u_UD7+fK-tQ1 z;)IU0@FzUIPjuZ~o|&+=7gzh1`;WpuQ#Pp95NQ>%Ec;Hz*<7HwlF)dSat3I{En5x7 zA0N6ik6iORSH!Ou(kk--_7-`&IM`Ek+~bkfnFa4cGp=5~zN|xr9V@f%$BvXSMS?tn z<>H-7Jcc@&>xNB`XEFcgnn2TXZ=5MtN{i9^>!IcMG{ym6FQK4n;U(P7W8-%%F2h2mRc`rf5&`*7qTFBBH|m*?PV6eUf1@!m zK1wGixyZ=$>A74cZ}u6b(hV7{Dm3e^&BIbANb-c6(V58ygdgys!J_o?#?0$hBj1NZ zzrX)rXN0(Vni)f@cU_*kEp7GI zK$9TB@*?0P^Ds?E7tZJ?<5ppr{Se0-dHyF%g)}gGw|!O(71mo2ZH*ZC75ZqC`lOIs z7gHLT&;@akc8&-ZH!S52z3ALO`7NeMM3}>i^s@Bvw{EiZ-_zf&oMNx6FQKYB#JF%F z+JpT_W-C=oK-wxpuhpbGPn$zaI$OHRR#{}NmVe%~W-#nWDo9^K`B9HBpU^GI6vZ2t z6BD)yEeVWau>#5=k}Sa47rb30b7(KL17)3s(urhr7Dz}yi5gMe(F4>$aIZk;omS>u zSx||7CgZNiodA%7ucRbP!w=AfRtE4l z%vYFCTn3Nb4}R)*E!3~`8(;8ucuA&pSU>l!;8T+=ht*MrgEKh+aFN7m#c2J7>mCF1 zjdiJbVGcl9uNnmeHS#VTapJ&)byF5NLQg?TW17smE5oeAR}_5A`Y(23f%Jy zr9{rr5Az9Kk722GKu=Bk8?4N=2lnH?DRdmo_03m_O47MNaf!k4(WrrSdNVW*%je0ml?9${b;}VJ1*KDBB zW0<9q0gt<0e8$;3`v*g6pE?gaA!1eQ@$Kf8w7ozweWRi>$jXgP#t099x8><(&6U6> z+p%NOPya|Hlg}wrS0!kn)l09GFBQmi*V7Fw*IUI{$Xbj{$XrdS@c8zMT`zWkC-PRD zoS4e-vMZ|R3$%^I%gFXUX(62Demz0mN!#njD_8Njn4m>i2wlJ5t&GAPFHvg_^NYrE z>nCc3@5#!`ztH^7mQ97Zb$u@89`C!{+~SfMj1RYH9E<|HNO?kN%#7mkMUfF%Co3PtaH0$ zRuj^cDR1D&nG)o~?Ha~mrAB=j8fNa2ZaNqI7@qYsn=O|=lu%APV;`P*4VCwWUql#yj?TT z?3+6nxhzJ1uc3DkPWJuZDZQ_ul6-gRSK!GsSRNX`b*z+8#qSs#N zlG}7W7AOb+_`_(6o7G-3+rQwop5tL?8MtXWV42Q#3c!qiS0|l-3ZDjJ*2x91BBg(= z&cMCXX@J$k(UX%q@=t31)=hj!paUhW;znA$bspGDc6_>IN+Kt76-z6H49qF%JQs9U zBtR4+Vw!B7u@SeIQ(i@n$Dz<;v|k7HUCmuNk$BqD*IJ>LCZ+*suN&smHn-{y?do+i zM|Go(3>4RVrqt8R+_MyQo;i!vGT*Ub?U^{m8N8z{dHPa~G5q zS3aUwHg!4j`Cs)75Gm4Y8mGU!776%}r`zUxd@#FlkdtCvIETYxgD#C}u$a^VJ66rE zT605GR8-Y4UiPJHWFO-&(x2*sdC5h?UgGW!d^h91Jfsw+ioipnUc^KF{Zq<(=2V2$ z2-IAL!*`FWV)FOxpdK%$>W;=I^FeKcg8iLy_(w$!mF6nV5GjH_pjvJ>P%Gv=#Zs-k z8p|cRzn8487j{EXUln}Usxo>_ZOui5CjVS9D`z%vBES9rsRzNWTQ0D}6@V-(06iQ) zEiaSJKLdh|tIy7yv~Atudjc=WcZ1l-31J-T*~8C2t^pN`HWv`;V%i-F+Ac{MVSoKm5+N z0G#z(fA+`c-}&wH1Ia!gzUnl)lYW_Su_)niLy2Fp!A1%^2Dc);(2GK$F1)KN-qnLq z)aW7(Turfk=e$R5)HfN%H+D=4!B6lQLB>9JOTTmIEDEwM3HET!J2Ga6Mm%8;c>e=& zq@C}p)b;*>xj4lcfe|C~Gx28wj;;uwx3=UAlcahAs|~+$8ZG;r;*lcMsmN`+XJS93 z`_x_Sm5G|mEFE;cZgzJ$ z#%I_pbKQX6Pe{Jg?#E*kbry!Ey-KCJCF#l`seifR!)GY{@87@wkF}MNxO+-Aev)Qc za9BXhjQ?RBKp&g&#A3@#pU9h3l2OkWIUlJIi88PkvdLJnhQ&T40 zM;=TRSF>BGpxD>ljly&3j#*}fOhbYNf~sq_#>QzKwUqc-0q!%S(vawW4`^_ZB3y*D z6KrhU=SKc&xv!(Po_6T6&+T2+E34oA3K9lR$G>zxs47Dk-EznDw+%}OrQ#rT@(tkA z*k8>sQuC(OR?`nWK7g{K{NAFzw^W?87K_v`;l1D-q;m%9TUyV1;bG9T)}tRhY{m7o zeOYuV*RDj310;E_)??o*|H;$=ti|GDh~8Dw?k5kg{7RHs`tu8R-S-KH4%g=O>}@Tr zsB}Hi99H6bcS%fgn>Ej8mGwHk(MnkINpBTWeq;B55V2GNiast)832FgONX7>uU99b zWj`3G;XvLoG<2IHN2kqK{qthP7~V!%p%}g{76m66W*K%PHAsWDeqV^<5N2qzW*$5{ z_DgE(!#DUl7vf;G3^`Ar)(}NSUY4OFSHe`k4&_|o=ikld6yMdkN%R+j#AsCxEuPT0 zy`~b2DNy+SDdHfnY;Za=gcj!uEoI)%JsCk9-0=ZGJUQ9^dg@rZcB%rz=W(Uc5i>wLg zj>2h}X$SM20L0+EexoFc$!bXLufD7LUVh&Lz^r*ErKf_V0pK*NhJ^K+w(E!kEyHZ% zqsk5QWez8R2~!W>GOc3r3PNeo=1o+lZr@F8p-kcYhb-PcWdGEo#b2cr{*KteUZ^ky z#-h>|L6qt)$d#zll(S;a_d_FMy7hHA>BHlQbr+rsve{_AmC2Z9oE{kg*iOi^6KaH_ zk`m#4`rBGsV{gMd-TRs@v+zb6uF&#&o~5`rD}kjJp1Ya;Ft#{*b!!9`7cU|ROjsXY z>F~0{-t4_^SvfG`0q_Uehj!q~J*(cmg}|HC_Fv7t zGqjLa&S}*8u3FPxeqosP7UN;&lNa)wvhQ)(>xtcDw0%Vx!Nqk!)ka%So5vjZvwZgn zJ`avLnU0({7QzYf@y-4!wiD;xVd=M{wG$UU#w-%<$xh$S4?2DT0CN{t*Z$i^0e$Zw z!GS!r7wV@e9O{-&O48M04yipp-w{by-B@}dFQwIzBIKTlXVViGS_9N-HO0qAO%)Yv z!!JmR>6c2e?GzGYAo!nFtR_qgI}jdu885DkkQQDHiZqmc~ z36G=jhS4|nAD|I>W9d`$sB3%SUL}r&SZkj$ToHeHQY^aH24RNDY$ISRg|~qshatK4unh^AB-zjM^YZTlWml1wg!>ZCMdr~cNN|s5 zQ#rx+LK>waDJV$WYS&ftLYESM_iO!;@kV73mveZ5W$ONGnH$7EiNY^Y8%>ks7tqmC zO?aq^?bz@NCA?EmeUQ-c_Uji&pI98OgD}MLL3#SeQ|Mf_E3CGIhh-Ub-DP(tb{c%O zJfb8cQwp0$>XTh-d0awJn;A_EpLm9%^o_Q-=KzJpR=yqtrY1#|4|jd;@eFf}rmeNL zx~4{i5Derh#uC#RQ6=4c>NaZjh`B0ckQ-ry&tl0^?xL~IJiT74=0i4h225)cfVMO3>%Vrl%1_(Fdx13XkK68G07485H%D|{jx8YqxY~*V zCmqNW*1V@l8E3G=eQb+xYmV!xBUWx-Zc>U3&EO`Z`^nDA>XCn`*1`3U8zb64?vyTb zU2gWB0I5O`RV6$t_JNN}m~-%PrP4o#-d%A&G|u?gWOB5dF$0q$@ZOO}PDHDV2{u-x{ngkMZg!R72?{;xp7bMPHOWGn&f=&B2# z6t>7xjo+0NkQ)M!eD;QB2(3V5&VO)e_ms;1f4S3n0FV^I4n4hNX<@OLkk8G{o!{6L zSXC!5W?MKAXkyj4*x&;A&riitkFGU*u~0X!OS;noyL4C*!RHvIujTx-Coi@7(<0XJ znX^{#)j@?eNkt3FP|%i;P4zs1Yd-I&5Pn@jl{O~GmggL~6J^52^UBHiva&KD-UkwX zz?t1+zhr4FVj?PM@7Vb$XEk316TY4SB%Kf~-aw_SuP-?Xj zPAT>}_Gk?3U>|uLhyG%ryrM=5(?#`c5z>-J5&^xTqIj9Eye4G=ZMGmVqH5^r6`^fm zXj)+qhbu^iA!#FU*dyvqlUNc%piWN7zA0BoHA;VSXN=@WvE8$I^vk%;v><#gK>AP6 zRwf%j88bl03U2{4N*+?upmipw68x(Yi=m+*KYTgE34>7~%!H85&}SOPZR!K$i*1M| zuEAzv_x=W)Ac2H~hAOhsN5g-f1b{Fk5C%|JFu@h9u|Sy4!b9%n+}|({{0Km{LDqi_ zG#oQ;1lR$^_rG|4NlGrJVm$S4-EQpSZ^~pwBSexCKj#U#pL?up|1_tZ`E=-(bnV&w zq05-Q#iSAQGoX~gb2WJIi4!yZUvFiYCnbD!8&=7teh?2Z$+fk$z6W)xPpe^i_p`?} zV_5V=lG#qVJ2+e@7E~oixUBqvh|87xj@6V>o8ie`~ViI@M38jVdFE|%P`SEhMtztrMhPtvJ4y|IuOa%0X#2Y_0R>%j??o>kAz$k-+nP5oJM%Yk(-7d*IyQ= zT&J*#PD&5j47a`S`C`<9;tq3vn3ANtJonx$#K`FAojUZndsbGbi?v4#j$|KOxJ)H) z44tRP9_BWg+At=7lHN9|z!0^!p+=&I5)`IMbqrWm$Lfi}lf6ow7WWd9YtLf0^NJhK zBfdsEvX27(YU=^(nmx9!iI1vEb%8YX{lc*r2FHxKz*#XBN4R;_9cEnyg=JaQ$haCe z==%_GI&wunDU*|4fHG04K8jLf#WpbXYEJ=)cl~#A{4@$8doTeOdB|Qnkkpe~GxY!x z&VE?IStM+-(5ewG%Y+OMntV5<5gxG!Mj;Hf_5EU9cO0E1Q5zxv>QIy?-#8 zD1L_{=4S)OZ{&7<7j&HdF;PJE^}dH3`CU6X0cJJr7)nYu9iW&>*6Ao@xH?fy=su+vqiWMF(-ybXdq}o&d)~r6n`xH*r;J^hD!qPCxAkgm=l2j}hiSfV+&j~=tdj1;4XwiPC?sb3G9?Q(b z7rSZ_7X1xyY~7?{u47|aacl2=;z&#?_Hg8HzV1_n8qnR8@P=ui(odL6i}nv-Qazgc zG1Q)4lyxAx!DnepdT??S^N^y1?0OGrz^iQGaJmlAfc#JFop?9-C^mE9xY+`oFHNrR zOXDi#;@z{K_k+I2&Lh$#j81N9P<^nt`&7B11av!VX8i3vrq>3)@K*E*A+RVh>%6jJ zj%mOo{1_Tdng?Qy!8>p|=CmKyk$sK_{E!Le6YCoQaLO~I3bSfyOgH$!DzV*Dnqj{w ziQ=KVgJd6$UNbR(C=t?poQh7zG_D=Yd?)bdu`oj^eg>z<>ZIV-KFzbiwn_3#^I^$) zj8FhM1vdMu-9&+{j5MQJkV1)5i!o_OfvpZvqH<2f3AK$Wi3V@0pBDs)rb6p>6Nljc zV(q-+sqW*yZ-k6UNSQ^UtU}>%976Wq*{O`|QT9k>lY}B8Tej>ih3vgY$U4U!2j@7> z{W-3yYy9rt@4oNf?{WWoJ-VWEzTeO1{eHb)ujiYi_pBM?Q}@l7zaG>TFM_>5DhZL> zx0_28g_tH^A~N()L9pkm>83}`-(DfWn_IvN9v>Oh%5_Pc)23iPm1$+N(%u{wp#$wY zF4lO`LbHGi8USrc0*v>2pUz_VcmlP}FffQj1xQ2Yo`8v9iPr+L8?6(VVCNd<*Z(Vy zl?Hx^t+cFW5aPve+3un}jvXaVw$iE?vR>n392yZuKf@i+i_LGGFE`6t@ zaZ+-6%-N>W(v&fV&!p<-#U;P#-jt+EOir%A;5YeNTPsvs#pNVFJhP|fhx5%HPys&2 zsfEw5eAH?MGMJ7a?mn}>SCfr3E~$Pf;^&4rBgMPd5lsLVIg?i)OIL&nWD zj{tN;>P%Q`QL)LJkwM~sREeoah|9wy3+xZhZNDr;$zinGd$%{SHqU9ZO(IUZjGmQ? zh&7J09>U2PI^^9{{6)=`>J5w?pR+xuRpM--NR8#`V;YM?3msYVv_iw zJs%QD_i*uFTp0m!qIY$58w5nR!L0jMtEDXmw%B~D8FYnJd!1jN36pWc5euk1yLVc6`@^D^9v(7&$>9pEjDnSq1U2Z%!;5i=Xd zRWtulmDPhFD~nA87-}#!BVQ4hE{eGSU`eT}>L(7Tt5yVdUh`>X_xoNxL3RhF`5e2u zoU!S6eZIoa=~b1PFPssSH(u{1nAL{mI3l9-D;R+#5_U)+2zY-fiEO zB}h3%s@AC9^UkK}BeEBdpNkq6^ssw7>!@!Y9OXHS?lKven#S|NQ3}TAq-e1#`BEy9 z`usQJLRwZpmgK7A<;@3L?c|KZqr$kF7W~yaQ@RxUW&2k( zpgQNHl=60L*Xg{O7|2Si-+n;zvGuB;2v_EP*>CDu2jktLvI!}#G?)3F0}#QVK1-Ly;`ycIFSmYw=>$Q66TZj``Uf*rgJ**6!{_-XKz&Fx*l~EBgHeKpiOMej?fV3 z$WEduHPKxv>AbH({lBVI#1O6k@7XfP8e`Gw`18G_OB{s_ylDV)6KT zKK^a+5WAQPkYJwf%J zHBWZ_1rDkIDBKE6c;;=s^~ysGd!J^SJab%<8JqG&2Efc)$^=Xr+I9w0 zu-V1$PBkzvID_liq34Pb{lX34*%$lnU30AK=HVf#&jbkV&+vSQ$90G}%7s6TJ=u)&aVR97c=zxf!k?=j zrvBgpLyvEgTF?8VnVSgf{YWQC=`G<>UM^Z$;cfo37i(87QB=nn$er0^@s6P{MaxAU zkA?A8?&;Eh@GUJX%RsZesQDD41v~nZRcdtWE%=;RlOrq79Lk6zF5qZOm+&#I5sc!i zjvU10GYuOx^v2PS_bt@>xOiaCGKx>kbMv~v>@jCqj!aWeZ8e(2=+(35&p*k?_axP!i$i4EJj|o|w@t8v&a0-LwC84`azEtz#QY3wZv@E% z`6o;PUyVUa{36HbJL@lOn}Qo&e^nd{|Gb47nWWbE zN6LLNks`K^*ZkCVlYdKHDIdy=UBp790;{6CVxp~6|gD2 zng*qjQI=D0_wjxFGj8gOl+hBV$FF%B$BH3(vWCX9%`1~vaAb*Vztg_KexhHti;`=Q z@a{%(1o1vl*m9KopESasH$sz9@J*wR}H#PwjRjrgq)3sOy~ z7H6?md`!%V`NfPEK%+|9A9BzMtMJV)R3(7-q(}Nz)uxU1vvfjl2Kf>A|{m?w`J%Knu>mYh3E^q`!V50DZa2)Q3Bzr0VDT+5=i8bBY%fs~Bz zXnFT^HRp@S`BfvjXGUM*J0NIn%Nyr5+pH*RF7ZQGsAc-E#KGlzz)=0(=*-?gu3EVq$!lJ{xC;HU6V%7D+63f*$GNH5|U8R_{s}DXk=&4q8&%TXZtE{X% zvKSegm;{p#+>aIrKm91YVE(W~;sP*uz&XM*>H#h!+!y%2n+N!aDeMM0vWNEWxm-4H-wm}=P~ez zG~J`|`e&G-O%V(}{?<12t%g~ftPqBVjUJj>1bcvz^l=-cwh|txGsfo`-&|+xsU_t^ zEq+sk{k-M5RJF5DqFZ^@=Al}ZQWA8*rG3hkw!ec#zOosgc^&u91Yr$*+$VMW+yiI; z|2cp~i0Z`zCn*YT27Pn8u=?y8!=vhlAR9}kZ)8NFDP;&NjEO`6FFax7D?n{Jxi9zt zf7?=(QQ~&$^FK)^F*vOUwIw4=cx-X{ia!I{B<4wOobN>dwYHYed}B-U%q>kYFKSEr0~bdEF8f z4Jn9*ws+P3a0Wv#DPZ=`Dc%oEkYr_KY|+R#X`Y{FqX4mDS>xDmJ0l};4U@!VWaLtNHPg)w?HXV5#!m zRXntt0?w0<08pl;`tc(+<>V*mlSA2d0_%%6fm*uDJuISU%8ky zHZ{M#ZWn6pbGA}o`I2YDTQ1sK5Lt74!cTrzXGwDM^TQ$#8|MqGS&&@?-Bek~*wj?n ze*T%-K}LB5Vb$i^nyogO>v$*Z`6u7if$Ll!F3LR0he`mhmg}JiQjnwGr0G6#%J?+% zBNhjaSnSEL)@TD3IqQr|*?P^ucn=DC{6yxiJaj7zJz3>qpvyUCz1BAcBxTp3+gTP| zkG7hprl!E#Uk7H4Yl;vQ2wa1!2vp{O#407O^`DbO9e|5=Y53rz5fs3|etAe|X4g+( zCBj433U(r5%5Yjaol}SCU*90kYxZ{#a_`r#NB^avXzz*thK{!_rO-uRaCYnK`)q&b z#~ffW;LGtn`uZyADU8>4lK`ERa{LP?^q?$3JabO1|56@(BTDBGJM*3X9Y$GT@t<}6 z$A8p9;QA6;rHbqCtE{Ma9|5_0w^e8agTcg``hH;Z$bJ7n-}jwi*SKG1Z#?N>XJ_X~ zvS_(tP`&Hw0N~5HCbBVg584hoW~LiWEDSC|(yJ6<$~E6PL`r;%^JPqcYjNqY1Ll2i zc6wT8sqmt{pNv8qc$MjoDzBFA3QwLl@M28c-gf%NdIG*NT9StGRA?l%dXV(VeVBx( zN_p`KY5k2L#=Nb-geweVie9bwj`Vm*7^&vwNUlyGG+t6!vCMieL(|Ij0LC~;NxUz+tpN2HuMOg08z_&b>Sk6u2bU_%g8@>VNFXmlfNw>4_!s22F= z|9=3H*yHe~WtrfvOOiNM_?T!vkZQ*7V7l=L(dheZNeQPQ$D6t*&*SF8xZ2k5q`b&3 zKVSXo6sDKOD_^JjA15`FAvmZ{Z{-9q&W*%?H#pqC=c9J&OKm(KAD<+Md#=2H7A361 zF7qsooj|E%ELuMHDzn`rq)vmf6!tNK6`;d(X?~8hUx(zxp=vF(cb5#3assJytNnq6{K?H)5DKx=<5uqH@5*>8z&I z#EUb?(_Z*GBoN1T3>D8EO!o}!AHjX{LZ_d+%LXU*B*O46{)1C!>ECR(0`TmEvo19S zi~e>z^3-9rgtV_gJ zz*&=Vq5Db?oO<{&;3?i?&IHh_8dP{Ou&?wYu*=wk*0yEey-Dmw8+NqF6ywl?`PGPN zRXaKW&B>DA!Q?E~7e#V6CHDubXHO<;WBM5@WL`SF_pgVl+HcPfijBc8bRm4bT;4ZY zRXOY&%=#d*XZ;qS9RDA1MRGi#E)FGJxd%HK@3m@JR+{xjft+vdL9Nk0?lMsF?+ru( z)!_!PiveQlK`oZa#mB-TkTf@T7oWRwm}BRrpK!O`s~|>Ud&j&asw#o(i^UR3N=j2U zF2REy!8#jDOHbY?uE=HnOwC9UdmhO~_x6c3;o{-LqARhF;5gE+eQ6svR`*PPc3J|= zMAFOKS?e8wDFiq2lBtQjJy5N9bKy$K0DvWae8R*ayBE}+42cxpC%kTo1@hb)3Oh&T zXC5P2qua+-j$fI$xnjouI?4}1PC^_o*BG*o9nAb#(G#)Qxk=b#X(3zw-^SuU zTTp?|0J`=k(2#-;d^*gNfW8~+iK%tSl+p}x2OCf%jLDf z*wsWs3fbz$yT&5jqH!@o*%u`>Hp+Pc)-xt8sm{aRp0XoXD?6X{NNwRwu3tho#iJ;z zmsOX}3)`3Pcm2{&2O9ADr);)Vp9gAi>l?ZCHyzwUa)IkJaWMbGca5}iy(nO$Q^NQw zVgXr4%^%q)ec}W7vZ`2q;bctnWCDHyfbRSQSr&t1MX>&u_1lLPVYi=GVqw@5-X74f zl*RvJ=x_=)ySD#-O*ut91C7%ql72-Hqgca*@i0)}@h{$$=!M@$D41WA^nHf; zYYfDWc>;F$kjd)jyOlb?tFdNO z8(**NOK-3;Q+c{iwGg<9$5Y+?6zCO2nJ7WqMn zwsC3mMgRCEB}|20p#u+KlpKZb*vqFEnM!_)ZEti<%Oi#8P{tJd%J$veTyP! zb*UFRuu-;)+9MGdFe~)_rC{R@*vruWPVN7%uSMbWpGDt2TtT2$lBiW!EQ3BRurhF^6LT4J=e4rbuK_A-MQt-Ajv%}^k zKmh9WwmGr%t2!COqP|S}1@Y}7024w_5jQ*q_4i*@^A7Hr`{Slx#v=E>%z7pmBEEfRWKoQ%evHE%X1Smrujmf4c#G<@nNvEO+eUOZZ(+r-Kmd8 zC!FEqp@*lZr?s^;0O&iOFZSg*wP8hOS`h5P&@KCZ=ut1$<7~fg`mYV6x$tY2F@wL) zC2-u4zWZb1#rk%I_zDJ%`@oCpQ8Rw1AnaE|g2Yn>3I9K?0o>__miil2bRO_PR8^PS zZiOK-iXfK$$=(|gKw825&HI31c;A6|g{9Rpcn>%+p1v+9DBy~JmEo(ar)T-($;FEo zJq=TeO`K=pwvlMN83|@LIdmbK*SfI9Bl_u({Y+cSiujkM&9O!0*;I7<=Lg_h9b70!PSGwxw7x~=LKWO%-KiCl#>DeHN&8aOtH5&|+)mZ)`rSld|0jVPey4Jz!(&xPZF?b! zn|Wd&IrhfHqpoxrOxBXvV#5CpJsj_+Bn~OyErcTny5_HGZTR4<92U9C{!ie$vnLo> z|7-qpfNDKlgkuc;rH>5YM5h*-X^Jhi+}>M~KnDbvWZiY5f1LKXe&xR5e+&3=9~58Y zb_=)GYMvZ+s*9>!jr(9vkkB>Ch$FbV)s&|CcRN`lEUWhRau91&gATkZu9=3i)#`CG z@Gdt(#f6QYUUOGwH=)h)Jql23HP>W#R9_ngZ`aSu(V`iw&dPhhRm3z3_~4oK-5<#{ z6*8fh&i#H-ek+IR*^_IJu3zNm=XW{t%Tj0q;Qgw{7B={lk25K;fX;tuEp1y>wA{?r zR=N5s03r;FFh=mlini_0#MT0H6fCy7-)J%N7a$J|$a1s^$1oQ3!$MmCE7?sa79!!4 zaaU$YP;^9pDQiXIOmeQED-d^ZuUMr%tR`HpCR2d&2my*Z)fYF%#kc~9zjDz;EMyc) zfPDymfIEY^@E?4Uu!!*_Fl7Lh=NHrc+Sz|J$+#W`>5J#5>~j)?ot;KY<7W4N0z>|B z(w*KFUr~d3UcYH9lB9i1d672ZuFU$zqUzt<{JZpTF4NG*DH&(|LU*g^GF&d`kc>Uryk*s84>V97Wz9_0O_f_5e1KiJJ!RtsY!% zDqaEBWeW|0G8G>VI4MXlfrP&u`V+Xu2XvQx2=0&lMty@41}9%qQEifJS!$((fDy+N zoHGS^;k4YoHsI6}$Z0QrC=BufG5v$%*AuXmc7|R9FxYANb03o#Z}RoBRN5wqEDh{p z%5OdGk`efJ#44&)JqvOB25=NdBhK!9fMJc8x#KA)8MEYcr6rF$sl?g03Y*9TTAu((Nywcgbsc;mXD}zkUB^+1uU$d(4&-P#3@cHbSc8dLnK?9#a z>aK5UI=V?145011%e`{d1xR>FU7a|PZ*=gez{{k9X!&U2PL8->d12sj{ z@2x4~~^-v`2xwx|qHyE*o3u>qVe_T87-T6$d8E?CLNgEaT$13c(dCt+5^`8eCOx6X zGLm8Jkf^e5xw$(E;Q2grSYy!2ugeBl3If~ZwwJRMy>2N&D0Pj~Sdka=4mzST(*cp# z#>+wucqavJ`RKzhkC3~vl<%bP^2rnRZMG~Ay55i4IF>;PH#{HwJ(2=;(lUlge*|DK zz5{N--Gv&&wE;OXPz8qvUeYv<+IGVhRW~;J&3_}E7#sCdId1Woc1S0ObIHbK^suNU zGW)qq4HzwVjxQmvSopp76qo=b@th0sUWrOJ)`h!Q8+%xI$B@%f8N2eMBO~X9`7E8| z(Gw2%R2L;4;6ugKTA&>x5jqddzsgP>+V`WMA7LoZ&1Td|HP zLEt+~U}6|J^a0teo{c;v5$xM_=4~@QbqI8i&ZvR!5qH#PkoK{rpsB@Tt!AhIn+|z^ zPy7tZ#L8+JQgxOjH?<&TZg_BedSHrbH6?O8c>hcl>scEG7uX|xS9GHt?77GExl#iZ@ORXFF$f&uB zy&Mk{1<+TD=$Wks`!@^pp7c;eto3u>1Vr1Mgcj%M&W`h=6eSA}mCmjhoHm zSE>PtFM5U>1~Rur+4Uu2Fw96$X7WJ#t`%sZYjXC|^=u>^M1Ek9-k(idrIj7qf#=*i0$Y>+Zb-D2!mqg}dj_aV;Ko zp4Y{DtH{f5<5p|$GI|6sf9PNb0Or(%A73^;(5RX@E_Geb+uYpLqQ3=Bh&J5>QWpLR z=1%aOeWr3{re`@`gMBScp#}N#VL(4tAC0*t>lv7$hz9aXmo_!#ZXu;OFMY}47f2d? z20>4wJ1E-5CIcg8noF#!LQ-kR21!f63-q)`4!#ECD!WCYk8atUgm~eAM&;c>@@Y|- z4#uPyp;g$~v##H&`Q$!sCX}$#-6yovebC!=qXpI8U@<6zeBn7=yTq}XS`u=14JO4K zta^SVB~cTG*VcK$gH8*amEC-HnGe;B51*!SgbRGC8u&1myJ4R})1NwOfM@ z^+Eea`ufFGQoxDt0fj^XB!L(zPPBWi!eA&l_K; zOI;oZi8ff{HTm)$&Xw+LyWdqyM{bv9WVv>4dP3<8=uI{HG_hxyg=Nj?p?6!HeSDxD z24!Q17W|=ZqHR+)f`Q=V6H>d?F|5Tc?;`ABT%ioo8Ww$f znl<}E5&iwU?1UUwypUbnYfKxmOBw2RNFfmnAK!i#U0-ivj!*qlpjd_Gh+Z8&b4S>l zL?w|c$gqv55Ab$7b>MOs7?F=ZQhc*dFa2-~S&FY9C3b(Y^s_aVGe>j{;I*|Z@vDMT_c@4GturoHO9Eth&|FC}7fbYH-c6L;O#+d$teC3|ua@C;Y zF;QU*pDV`xb$w$j)SgO&%kgPz@9*VrU~mjt2;9`F&2+Tj#-`x*8QQzFLI=_b2(RyF zuvLQ_F@DZv5W>75cC+=Umctnhy@Q|WPJ7~9r*o?|qfrgvYHUf70GqJ`i)744iaAI% z)&76#POS+xZ-xuecv1rnD|{^~kma0ttf+~~v3_LZ%rWll)Jt#!07L6S)*y73a$&(a z-;BwhDY*$~VqBBDxz0a)T=>LBEmHl@r?Po@J`gkiTsO*3)s71Bf%vlP9A^378OJeU^NicwR<$a?4 zxR{?ks#hllLE&ISEpAC%?oE;Rk>9|evx7nV0UQK*;L_A9-TjN5@dd0bMIGO7hTd1v zzb(G2)wWSa!u1d&8g`^F1L(K%@lP)wU;=3AWayZ?}MM660)Zf*zFC%ku&!R+?8?Q&#&-)`E7mC80 zt^}`KZqUJ+_sWQ;I|t0%;chctd}x6Dd{yl-9C$YSZxH%Ce;yxKVV#=7?>E?YH{uv< z#1i_Np&E5O)~;1aPcohk5+{Vg$9POHB9r7~s_5cAT59{y(Y1_#TC%$(B5q#Sd&0=_ zU0%JTQH9Z6{K|Px0*CW+a&4JJ`tyDM6By8gRh*m&-S3r7g-#G;*Uo_R*%uyfee)910(v2p2abO6}Va|?{(zenp zxW6HL<0qQg4&!%U*$~Q$+6~m6m>h{uB{bw?L*w?YN}L7iBwyuK|^7BFkZ+fR*w1^{(XL zr5QG3CgJ+I1M0K_pGKhS!Ci@~XP0XqXqmPS`^?^i3B^G9VvXO43DmrJGvT5&iq)F? z8y|5Y6@Zaz7$vKu3RryLWgoi4J+Mu%s7uC- z29~rpikjGK!#XdA_bKy2SnD&VXJ+CGZ)G8o`NIx7&A+3Zq|q z38(fN0*C_V_rBcu^`T#!0tUnG4&zmH5T%vamD2*Q( zGU1;WIB^=;b-kF&ikJ9$l%z=s{BCbX4dzxTv&mug!@ExRbGV(x%6(dWev*7TClN&+~ds^oV8-_-OwiDhE`FBa_d`TQ-1z6?aI(Y=%( zO2G06&_Ps8BawfCVNyqTrY`zg8X2>7H3^#5EpAreROq9 z@yqe^O!trJ<8>d@5}wEuY3=i58xLS-BU}x18xRJ(gC^@@?92{}&)p{$Z_R4l4!EH9 zQ#am{2UnL)Bn;7Ug-ZHv8Fi~@Fs(H|s2@WMJ2hy>)>^02g8(PhoQB-)QinpqQ%Xvp zo0Z97KV9bJj8pYms`2O{lSofnFaA5jziA-T5)`!0T`>YtMTKEJ5N( zY8~Sq2&v0ljz%>;aV19PQ-Dw#tH8;lTcB3^ZP-@9&903$?=5dykA<#+80-uaYb7yQCruIY*Nv%0aw z*{VtNH-DOunf=)OiLaYD$_h+Zk&yQnn^<}U%C41Jq6K7bscRp3iCjdOt~7suED&?* ztFCL9vn+rGdGs%RSidH;&>fWeIvVAh?-{k)Y;kQJ=N(SUaq7>D-cDG>%hW#E6fQpD zRUa$Dqhq;)Qb_V?W8z5VY~HKC7_x>RIhstAb3gb=z?z-od0~@W|8tbZqqhT|<<=FM zG0xS6x#GdX{f1`81|41X?_0iJt|g*P#p)r2r)C8z&X9yT1CCzduamz}d;r4w;Od}B zUC-9kqwMdmxGi9`H8XOLTbcd2sk${`AEdzNz+C5;)T{#;i|zAuaS_}ZKSn9s+;sfO zS?(a>+x&Jvh?_^wSLmheLS*59`pD?$V4e^L2-ZX-nc5AoY@Z|(k0G}MHy?(^v=jeZ z4~-<>R6jVXCrl&33SHT13b=n#LdGohL{6ns2cd5Hi+fWL|Kr#vvh^3!8t3eZ%3zOb z$I>Y^6=F7}XuXjsL$Ia~UwxI7m>l|DHs3ZZTYeOqX?viV^y$lUTI9Q;y_n4l*3ij` zz~p!2?u{~p1XTS#x$B{^i>19|Xs-QMP^8rvYT^gx7IJxUY3QxB?SCmv29@LGg9xPG zz6Keb$`~1ZG~J{3tQ}-bjP(W)6utZa;))Y>R}VNUBrb~iezM||TYo%fD-%o{XB{4D zZh#D`vmZm7YfA?aPovDA-Y4l1j3(Bo)=+y=JtgyKwqHUb0 zxOt8i%J-XT*elZrjut?-KCo@8K$TN4T%ydZ78PwD@YSPye@G=2VJ!WIY=zS&@IEsp z03s{NoT9I~ppeAnsWP9MuG;uCBQibGHI=PqrBaASz0c38wVh@>kLPu;Cp|_EIyeDF zsk3%8Ndi{D+|Ulw8x|@qgJ^t*prWs{P07&jebGK~PK$in*d+jpzVor%Y)R-e!3-qi zHaCXrYhC!+qy7yfBxV)+0pUNBG>2DUUjm7+Yb-?`EzEOFVu$x)my>#28NJ`cDgDcr z0Wdx){u|G+PRxIJbpBXz3$z^E0?vt9N7zN5z_Y1aH_{9JfPo$gjbKkmOiWJ;dbf8F zk4Fm~#SSua<}MZ`jW>4scYuXD=Tf# zfYSDKqZdwUe(W`l2$$S^WnxYB`rfEVl3$Tk(Tr}Cs^y~Ygc2K%-G+l_EakK746Fh5 zGLjCyz=msMPbv0N7J06X-}}Dw`+bX`TX}*KM^`EIRKN3*sqSL?3Dh42${6}g7DKXb-;k|$gjX2$w_vp*`xJQs^*wf|nCrN=+7dj*}td*-wG;2Ek}J~-W~ zkKVL9Sw8DT>WV!5npte>D6rQpzk5AeQiCLNOr8jgG-iVoO-_VK$C29xJJy%-M%Mo_ zo%Jr^zQ0IdKMb}z-Jt=@-I&6&odL!$ZiK?^`e0JDk(pAIe^BjW?AR_hkzt^5NI`aR zD?bZQBtvH|6s};=z@J#BuD@D z6Ba?dimdIcZKl0-hWMpzgUsEB`&ainEbG8R70ol=BboM{!!i24CXge!>jivXXrx>X z3;()UNA>)y-4VfA$+_oVcu_BMvYWnKmN=TB*_wOfE6`hJRKBTrxTa_fE`QX$+g|uJ zTIvx{1eNVEJ1o=&MadxdO$F4lEbt`W*X48H395*(JQA z6U$LyiMC=LECo#EV(NqGCuQ`pC(Rlld-pq`d%AM38JIk9lfwrfe2v>152S+~(!M5e zaUG1*3;QSgv0Nr&4r*%YcPV_=@lm7pj{Nt=#(8}8-3LEfm(BnPsF~Z*%#kPeX0KB` z`D5T8?{#u)N6&yc%}vc+T;skJM)xw!zKt}-MDvihWmD7E(`fm@sP`Px_hwLUZ*|}+EBrYuRA-7 zo$yL4X8U{kYuL!NXP+5QZd4%H04XCM&&(%-klA+cBp_)7DfI0e1QNyjs+A1jvbK~T zk*IcF{~JbwBZ1iP?-{x+on0AY7!O-0Lev!=&w@jt!)(99$sACDEi0L$)^r}|-8Cy3 zkP?VLn`rS_=_Op+Sf=LVN)6{L9k5G{`|agMGgcz}b}Hl|2c`LdhlloZvphal#H3zI z$I&rq)a?S7$feDnoH^HbSVzd$G~`0-XUK-D^%m&iYD!G}rm^WkE51=O+aajeuFMV0 z^zRwZEk6(Ac>|qS@LGJRJ7alI?l>2iDd0X5%NnoS;Q`5IVG+f{0e58=ZbY*(dgr;s zHpQ|x?9(D$Exnh%<%byI;IUV&{i64% za~?wLe04`+oLZW9Xzq#>*@>?od=cmSp2B>AtVe83Rxp(^WLdKrhw$vA1 zrf%c+iFu07Uc0RSG8)2r)tTGhw;e%D_+G+e`vn#35^FVGP_70Zq>yt$seppnDJxiB z^Nc%-40_@jiO3_*rfhM-cgdc_w)F6|2WJw;Os2kFyk^zRb#g}W^M53kEM6iu;tcEu zPRYI`RxqHCmY4wV3ri6THTN8iEG?^3mz#J5C@yIeN}^0s@mAb=-9a!8iQPQPkb~_x zutpWw2WT#vB0q~WJxF3R71PX4qvyWj8KyxJnhHI3&8KRjVK=oo|4mA*`dTTy`k^t; zv$najLo|!{V#G~uST*^BUTy2nJhlH0&*&Qs~Jm*z>f>aF%EeQA51 zrW2XN4#OQa(2g{N#o7zdmKL5I<9*h5N*es%@af7P=<}=lXshKtilk2|?FwY?Mwf8v z(crq6jA%|^q5qiuapjJB66P*`%f9)AP|*+huN-XEzu&~ujJrAmk-tZzCFsl znddf{GO-|$l1NEOnXhV9^zl=@z@YHH^Z?q$$FgWjMKe3^#C>C?8Zf|zpCLVp6)*@_ z=#L$8x7EX;U0PPVd{($Oq!?mt=+|V^G=sVdtTM`zBxGn~5qX4k##7TgVQ&@^^}WVD zG6wZ)EuN%n+$jsG2#<4PM)Dp4qDN1W(N=;%>xy4pdDxQq@CPfGFIGGo zI8*j%F@Ve6RMaO-UC=+}Zogfc<(}Xs3@DtP9ZaQS!}_D=QEyPoSpaaRFnT>rr;rY? z{k~?%Nxv_zl+0ynOnr`liNDmdh673-yZ=?50eoTeM@4y-8Hk*MOkUR>ji&-i;V5vb}< z+}(B;I3Yjb))D{k0_7OJFK)v~UKE%-_ifLA!0)xKi;60aO1di%w~&vBChp|~3n3W7 zSsdWW+bfoKb}CVtO{md9W@$Y@yvpu%FRP5LtT8$0GjZTv`;r1zKj0(AL3aJ>Mp$}V z`%8k(5yhVDw_a64*$4X`X1y*_(!_pNeo*)@I2|w~=V`_Xxjf?orUM_i7+pz6Oh0E~ zDc^T_@0&P*FynTS?w76_u1J4oJ>!?^*kCD1gn60Q{~Yej2h;2e5vfaV1tg zYCe}E@`Qx3$z`$5slsT|EfY{Ab)fH_y6L0~^mIt4*)tLuYI!;P{odM&!_BCB4f}*h zx+=YKm|e(4)V1DgZ4fxn+gwJ>>{=KE>bXu|sky>snYZpX$u@1$m6=yj_g*RLnCnXa z{zaL1IeaQ+Y)~7e`OQ({Hn@-$7sE_tS$)wLxrFUm$K!z#p7*okSBkYaN+Z-DFKAF| zUV2NuJi~J_X$71{8eOyW`=5%l6jRo>C9*%T%14c)LaSa z512fvCZdh_B2E)fKcP-N(s(X+_|?78FYNL}wA_uG3t6sA`Fm8jMTCD2ts6KcVTV5h zX=rGe@?=^{Q~=Q{)9=tFUIG=%s%%un@_Y4ZMwAJ`9#E5#MNPzE8AbeUo0y18f6xCu z1(mE+I^RqIDZcU2pqL0gmf7T54)tCEP8tNO+C*7ymq%ubyn}Nc z5EskmD}NqRXe!wBDiVlG&tDak-Cdd(CD}`N&%(;}=&Y#*mKnMEuO!7&-i7kLxt|Ph zTS(QcAt4)m7&^wKp!Z(yU)Ms^7IU(Z&xq4Fo80JTPgUb zAz29LUA7L!IU>NWvC)0unUKe4vxqAE9z+%t7C9eXu~^UDy*~{{+0*rkRjC#36@4Te z`;}q}uFEkkh0Wbu3;MiHLcm;ZQmG=0pUF7MW%WPrBqwf6ocj`4(;JmMdt-+(MIUR2 zD6+}e#t%*QN!Fpxh2{=|#A6kEZIJ)<{f=c3L=e@<>T&Q`Gz&o6p6%a#2MxUvE2*J+ z_Zija+$eA7Jl6zL_^L){a!up}N`pEldze>UD8=eAw8c|J>;k-CW_QKsl_!Tr^+Xc! z(C~c#Bd#QQ>UI>eR{h!Z+OkKy$#pg_pt}FZ1%v?CEN1uGY;DDGmtGYLY%hTK27w~Cf}KFNWPnO| z-0Veoq%&P+%}Le;?#5BVQoS>@DK*&PUz>Xqelnj7-l6l-?5fWdF&++W0LrTuhb~H? zSLO~Eicv9}>z8SAwS_jH`u9SUdK; zofrwPr!%u1M-*RcJa~%Ge&bdW#`j=d;>p|`4yh{d!fq@BBj^z-Xuq|M5m=?xK3J+2 z4p7h)?h)>lIRp|T4-Sr$djjc3s8GBI5w59~;_go>YAElPa^Cd>8$-)TVj)Q@l`6bt zYEcO&a};k062kQE!V$iW44PtA7JJpY*NE=~F+IV3I3V0W5(% z7Z6wg?`1S=>I=9tE!7q@RTm@E6$oK|Vj6i#{90*g{?P+u0ghO4+2~Gt^-8)0919>mY zE2kVlAPKif>Dw0p5PB?n%HNP(kiJu+u?l9PkRqqo51^%^vOELn0Xl&asVNP zvAWgKy`Xyq`@WRigS0$SvNoC5GRIH~MS3H!n=J*_)isI>?qJJNP&Cv(?cinq`PM@j zY5fPR_v*vYkYUkH);pgJe2)jB)8sOJZ!V-813OCCLPL=284}M-2Nw?ye~q4+kCUE? zQ$0OVlX=f_Yhf>arrjBiq@0Apmh6b4q1``u_tVquy;u#O8}&Kqe!Wx~CTr#^I2%#k z8=rVTwE$}FL#f5r$EOiSvjicm4Qs&HD7v5o6!5iB$bT z)i09rf;}ydq%MlmD>p}5n^Bd?1*+8cxYIbgUVc3U^hv+dz0r8k+qe6t$1dVVl0l=m z&C4Zso#s&foxo2|J#yfHxlsQUjJ9fnTZ$1!&o8=9T;_JZEQMm0UKC7zRg=86J;a&R z8yCCjZC>;opU21BTfFWWA^A3Q2E6XZ@}^T^EDneR?~pO|%f@O4GUx6Qzsip^Lq z$*=Nj`h6$BAOp61bGL~F!2!GAG|R&ZOc2*)W1=Dz$rfebv+wIzi?Z)~)-cAFZS36VbX|R}KA-RR zzVGjG|Bm1FN7r$*IGFeOKF`6(UohTxb-<}(yGQzwMwkKS0UEVx70h8_`u2zPNO7V#5o#E+Szn&+u01- zq(Mize_5SXth_f=ja*97c1dqv@12sNqg8&f)X8ROU*OHg;`-5)?nZk#v8QF}+l1=e zlTE|-iuy-n^!SwDk|!1$>jdOVG3$|eb68Y5N{H=&{s3Nj`xkTz7ze6w7Vfspk!ytq zLr^Iyc-+w5Qfl7WEY`C*K2C~)7-D_w{@WH4)}IWNgFjh2j1<93OySw^d6(slDI2=! z%2qgQ9m*ZrHgNvMY$=31Eq;(%kafg1Axb&X&DnHlY@I^w(TmaaU$5;(VtffF&B{2B zcDG%bu}Dji8;@aJcCy}zrib5|wyJf(jg%?9{c@aON;%MbLwe=X{DDhzGdzi0v5*6TZ7B`!Q(1|XtjwM?<(blj zkL!e(m264cjk=(no(D&hW*Z{d3a?c0P)DkzD)WnFyOwlko; zfCE$o#1aFDw`Gz8(+k*;=quoR5F0xqW`sS7l%A`u*v5F;xe^PNP=BPR*I`e%U>bw!yLV1UFP(3 zb%*_S@%TW8lPj6mc4n#{9*k0SOZXNO!`3*|nLesdj*LwETzf2G!NZ|U*;GpAvY?_{v8(bt3o&C-?lGUaeYaKj%0 zIYB`1^Lz4_bKEWIZ{LQXG`^P&T%05M$;U4)i%b}$OSQzAMoF( zA??cb*=I*g&=nY)nwH4{8eJ=m-|dq->mEBct|;Lrm-o?30cXzZZrH-TlBXF7@267NOLeTau;M@IO_M!}!rd3YG;mH+Iu1QhU4ehW@xd|ms<;{s zIOMI&cpSLD9QPHo-;Dm+3)FcZubv1g-V8zMOVV7p%Bx&X$^*-NTjxk%@M8PjS13ZV zOGgK!H);fM3$tyj;0xwxx8Sq>10eY$%oniDZ~qr#&S;23UH}rKgbD$&2w*Bv@;g9} zQPbrmAd%kS6qe2wMkNhyi)pp=_xHb06gvg#;@QRWX%0@#bzZmTYqIH^*G6(L;7(pI z)pinET3Tj)z{+@=FND{#o2sw934jB*T_;mV!NhV*6cROIk!ZYIDBnWx0C#`nTc*le za!qe^V*jD}C(Y|V?=x5rJ|snzx*#1T5?dvFiJ(i=a#Yj7$$DNjTj4BlY(nCKY}C}P zqkB2g3i(TK5vFe?n#!?~9uzzUC(qvOl9rN0@elcwJGfS}CvUdtp3NY$v*3Aw7~OxH z84q7mkCm-;i6@9-Tl|vrt%j)Nb4b`ZP#;2)d|{3xQ`Xn?qd~G7X!vpo>lc8wi;@nV zuvF|*(D9|l59XG`(p8;~!a24}&Pw_H~Ys%{;A zIOdD8h^*yL_5*!^#8?++6+LmG=~nr zU!oR5a6RXvOuFtqldJTo3K@7~y8C&xsqW$NwNU2rSL5W5OhqKHwL#b4eU-%MRAVyx##hn3bGUTGa&fUAFyDC&*9kAv;@@ZqOe+Io6m zzYJu7%h@M1%O8cmxf+MNPkXr?2s@Z_|FU5-Vx`V4?T-PGk8R=<3cTO;57wv4wS8)5 zJ?t3Y{m2+z6Ee+F*Q-`1=?2Xw)VZ6z($tcw`&U9DTyHG~p;~j7I2X09!Gp<()GNnH zy1>0xBLk2O{*Kq00x#iMVF$d|^*e`@QQR*)l5Jky(S*ZR9zeRr3WgFhnE2*DjOP~n zHsuw%_5yqOlc7sOVr6a3zSiWaje?k}&c1=6;mn=)Qk9E$#;|C~aT#^=;YknH;2d;W znj6sAJDt^k<`4ORyXerqwDse`8x4gXK7#{Gp&V<#)`=iZBK@wEY}3z0%9u1?BjGc2 zR!{JB!NQ#~as9W0oUA~aECmp#8O|-c1cTjWv*!B_4?+#kPwX<^yj1Y%yn$rL0oBUW zm6*tFb7*mkvYFTVjNAj6M90VlI_`%jq^JT5_@;<7I83Mcep+t({4i(QyD%)!aetmn z)0Qfy^Zr6GSuwkJGxg~(zRVQ8)SJ(jX!8sk@<_n@n(rYceRo@BuMI-^_D$+DABvbgKb?rD-}&0%wYVk`3uY?4rmuqG_t;b&c(EYv&_H%{__jW!h- z+s_KMDbWzTDybwE>=v9UlNw&OJyfhHA>Z*1`3j0%&T^%b$O`*vA}ynulP9mdY_wpy z7VWPsb+Qk&Wxl)JYD}`Hr{4|HEf?%rOx@Uv!0VHqa-$I7BtZTw=`6t5mh?)Z8ja1x zUXy0ASti8GOX2PbgImA)P$?wOg+|N!x};oJF19`LB)fixK5|Xwhv~FjT&`m!>u*J6 z3~&TTu6)@sYZWglCyB(Fak-hK08*HaO}=x@hWMvbN?S;My5x{Lo<}d;U{|rVp>M@I zfCLMPG9K9%WT;DAy7@@`%}Ld`I*f(gJC9o!%v10g0dD@SLnC?=Y0~oQ>c*l>18JBa z;qwVMQn^Qy+rBx8@s+IE%L{uh4$+v-_^LE}NxO5a7ArTi9P=-4o%dyxKM<4vR-3eB zCI9|9?tAZ-Y^+7+*P1HHMDO)Ww`?ji-_D7a1>dz?movl)MygMJU$TGYrqEWCu@H(# z-^)Hl2vnMto6*|a#@N!<50vMx%BfFT#Bbsx2{r<~P^uLdBXc7k6Yq(g_vu+zuEQcU*eJ5A^UKQve6}sTM`Q>Zl({EP%pwK+ju!s`$nhg^jMK+5_5P8Jg$rTg zOYIK|AyE!PrBzjw+>hZO>$Xm-=jDdFi@46e9(ekWXuI0x(w@A5;H=JlNXKWqJLIo6 zjwK*j44Z)PXixajn9O&t){}1w*1D<4pu9}REw9Mt$lN8wsIqLc$=LiMM)qdA{V|8~`x|V^xtKbq zAD>=3qk|9C>1?ajL)BtrOoYypuCfeheT5n(T%J35`%~pwB(gsd(~{qVEd!F`hUrY2p87>H=jO!Lix8G_c!U#YHQ%?2i^P((a}JF1o_4W z_q}pqF^UDdw-yYN0fzREMyUQA1mF{TpDb2bOjTLcIp&uP3GMHz(TVzlx$GbsE&fmp zgnTs;ko$Qv-y1*mm7_JSZ1TKT;bP>apr2&kk;>pw(+<*b5W!dvK!_og>e*((K_D0) zQ#jm*I%ffxgbTkU01Y4aQ=Gi6-NM0EL+rYz^3xiNpEZD4@1i0&$L-QE#=1@ zQ>u466;_J_n`VAWnaDm@*i2)ie+b3&w!ikvielAjzD z77ZDFC7?Hy76L83aL=3$3k1g{oLqXiVZ8x@OvxE3=I=7zD-kD_>K}vZDwU)fyc+b^ zRjv)zS(kto(J#gP$TiR)8VZrgn9Ui=3SLTT_QiO1cXJq%W>S1?D=446;6AtLFh4-WcE5|34;F@ae=n1v zS6bc`dlV3G(Lwy~GXrl5ILqBnH2tx=!ztlDKm0@*3leRdhXEC4mq7nVAP z)XXNy2b3%la)~bH-_XM%A}5a8tduJ7s+$**=Et)cZGd2JS6kexf6(MZH(yzuT!WLu zT0YJ~?b=K}2g=%Gr_h)dr$VNAfzoI?@sjLZt7P7_)}t>ORkCzA`1)ESRoNx)Lk`)E z{7dDy-Ooj%VG=-QCjXsCZW|zj5rL=sX$vD;!F!^v~9cUWi!Pvl|Ad`#zfzoHTGl>5@i7pO*aqNK*U7#px94mvYLh-kja9cRP6g46w5hX$y5ccB`EElL<%N)QR}0 z`CsvpZe0f%a}|rN-wP`#*h--b4s&`nW-cx+4<9~6AY!wniX-Ii?PFk zzYPz+cj3wvh)R;(Uf?heOcToT11=kBCVx0lUeksYM!u4UXwDtxXHnNFU-{%r<39TM zX|TdkxWXjQ9aEre-@sv6mKD?^?r6L`3h{Gx7RcNwGVHWT|43yKdR5{2r%+0YeX^PQ zj}QF^0QmDWKJfFZH*@J5s&j8Fm@!W6g|Avq0Y1DWh1y49^9Ap4=VnPe5Bq0`4OAEi;)W#B!ENXH-~bSHTcTRuQ1edyL^q_a{FUa#bGAVq&_cj z(m~=5f8e30{w#GuZ_ z;aPE&YW2y{(d5DqL!7FAC`a2tc~!5~b4q63>WWYxNXHCo8VYxiL)(af zI;XLgPXe}ExTCz6_o%HDcHyX|NCH0eR7J0(OO?0+`K}d#)mB)Gstj%?KikgwJRN0RzmyJS(VrE(F2LVVxV+c zaAQ&+)z-IyHogz>knctos|DCSes}2why@+r{U6PRRI|YC|Igag{byzVJxpRCjH^3! zR`~kq#YW)Q+}zv*_?Rc-dEclqh{k5duT`_kP{9RG8z0?AZiK5TJ# zvJvr3eW}%SyvpO)?Cof15IFr9qJS)7T>g`-dmu(D5ubJOWOMb&r9fX zcH83k_(wOdM43h7H1Wr&LRpeQhiAC(n|`i4MTk%wl%g9Nal?A44-gdzXDq{So;jSt z+&ZuCZ6u2g)Q5d%ci_Lm>^R4iIx-QJStqwwNJo2|%cErjvxPz}YI!6H+*3Kg_4sfP zphV5|u1eZoURhneztF(P&u`@I?e|>u9vfG*2Z{tIY|5Q~QFVs@fervq|58)wa!9cs z%lEFf$hYY5pcBo1%t^(JE|3m>m5>Ap8AECP3vL_Lq-@(zOVNbPFQc2c)?d!)&e8=v zaHlkxDmA6FZqB`Uj?<1Q-mN=A?2pkAGX!`&c(kd^D|=#okI?|cO0&39Lm&4@-*5`@SkzV3!@J(_wz z()fZ%-`$z@16Jd}B|;ukVYtZIihdXkh@76^HQw?qFU|Bl2hGOoAM1qeN`*BltHdq! zBGm4@t2{S_Ac|u-Q*H4h!%{ERcW4NzX#fqbawI8D<+^e_DM!!-q|7cn=7A-1x-2x< zP-U&@Sw1|Yq2&wOb3-XZJPu4`$e>bZpXe?$SZLW%K}>`^VHQxfNaT~L#h9nQ;=2)vlLAG_-ypL91yua|_g_QJf04;0j~t1%sO>@Xi>ksHRMO_Y zCxiSw)qovT^-8$npI8VyZ|0Bpg@4=RjLG_x(`xF_K!$ zDg9OnE|!p|_a-G=m&FR3&{L>4TsL2Bb0w}BJ}Lf67gBSj@pUofZNPD0itOBHkN=f` zl+8}_`W`0FH&oYVkf_VQ-^51RcZC!RC?8JIW}}Vg+MM&KC2r|%`~W-*~D^vl&{C=fMs9f6*2Fx z&j*Hi%^6IgDQ(vk+;9=sB7HzEtlZm0^K-HF0x>Wi|B}wAY2_ zC;)=?s(iMuH95Hrfa}go88^YBlWNdI)tQRHAyI+XQdVfbVw%h=zBe1wdqo z{-evJe<1LHCGrnz?k~D~-edyA)xxlY?&6>_B5jO;{HDW^V1FdR_ihteNL;;Qla*_P&8v{_&|McyoFtWo)b@hncQjPFsfG!@48DH__Xlru}aCIpSzYzZ0*Z77B zH5pwe!Cd)QFy+yzt#=GIJE% zaOIPQD(k>N>#ri`SJOWR&jUdJRtWw56MoCYf>fQqvtla1-*A8I8ni4pkMYoPytPstC4c7ODdcM^#i+ooNNz z=d6oeJW!s=@fw{F2T=T6c&*ZxaU7W#9(6fVjm!42)2FVMmgdw!3R_|hZ}8M#J7*m(*{7ts0drgOb1Y6&%a7bU&Q$VND zwY>Z!Zc8^5^f^6{#vXC9`;YL*N9XguxK+O^4DLUs-?0S0q}E$9_)yb9xmNuRqdlb_ z0z6B@kxR?vIkN3?y~@i^-8y-yPNmx#5Z?E(v9a;-^F?x-41M3)+uN~NZXvm!Hr=@= zhkRl`fS2L}wMxN_j;AlE2QKxz|M>C8Z8N@{QoSC~Kq+}CRjDBk3N*;;LkfHm(Xemw z#8{X-7XEnuYuzWBMR-FX^&B}5=gaEz`y->HGaS3+i2YYT`$4vIW=6s2HCCws(}()$ ze%LZ=t%AEn83{gmCAg@D|Gpyw1~Amj(TPvKDAuQc|NdQOA1HW-z6tcNoHWW!@lH9s z#5DRzZdD!dO#eEA{+e@#;7=g$=YJD6|HWbhkgtDKQU9MW?x_nPe4%}KcvzVqZM9H3 z=YuwLcGke{J2;CDtaf&G0{teKq&8OVT|r{F={gGmIjE?$^ks$=WV2j7&3^8%gKI}c zAVyHm2s;1uwnn6UVO<@S_gtr%n%bpRzuAO2JGy=*NQl22!A<<4{n>1b%4+ZE_(tWE z%+X)?Dz44|hx1GtOKxdtnKMlan!m!w!B^9)`X~&5dJ<{4VrxMCmV{1EPk&EzPB=|a zw!`o72NR^W*FE%hKEe=YowU)q{(XGh%3%0ZGb$UEO@tHXb9^U&3PETB7UC8#x5L*;NvtVk1LF;v(q_l6kI&mkz*#f=nnH*pVDPwhrm9@jzj zbB5FZ9_@$6tSUm?jOm?^8g^f0^VJumWn1H84nRq96@V$|YzUiuy)UJnG(EVDJe|II zj*=EXd%Fhud4D}m4)8py-QE5HgyYvh5U?%%%}U+^DHjc-tRLUMpVGh17~;?f@8vma zN~qrI$v-p$OugSkxU0Tf7ZX7u`!?UqFaQ4^?-QPB^Sdzv$jgGuRLSN0gM;EHY~-0x zRaM_ig%wIW0sh-sA`V1+L5EI{A9t&43Tn}n=!LkbQ@}(9+acE(U?N49b5>3L)20lC zD%z2GE~ON3AMSG6M7G6(p8n23WP1BR?b3G)AQEyd=u{T)j*jxI(3h4%5<`61VW|*% zQ3;8V3OU@*6k`Xu7hkD7^!k+bj&eJZ{_L9h1vqYhLc;E>Gjm)`0BvAPbp_ATQ}pId zqQ(pMb8M_7`wzpg+9=$on;~DZF-YsnL)b49b>?rukM=Jq3?_aD`e&qxy2Mc&zBwrQ zTjS+4VDc{n_+RR`Uxuc?XD@6IQSrPFoo2ePFVjB+Q6M@CXS+cu;jHlMX(k~zr#eBf z%=f0~mBNUre$jJ1{zp37ftk6?44-qEGdNzmEf86PjZknZ+&7;}EsrRKG3<}&CljG~7 zPumi0wbZ(&S^9xb{f`w?G5~_Ff1T3!gol%`lIlM$gZKqo_($7NmT2qq=g(%%jRht% z5XE2dvN@{86%tb}fHwbZ`^czHc8#%+1j9Eo1@dP9Rm!BMfV1Qm&|8JE4V($TK>u4t z&|+95Jw#j_t#ijoP{P`MzCFhNn@{uAZK?>05BnJt-11Q$9{blHq}TIJfgq~L_=~xvC41%w^0`apH+MN~&*FKlR5-!Iy`l|36f*M}q(wg%2D79R3)800MjHV2B4j1rywhy%F=(&+2rSZKaZ4 zY1O-o6l49luX*|TM&b$VZK@rv>32kOVxfj)9UHFTbG>S|a|pt2eSza8@&tmGJq89C4J%q94KkrmFte$Mt)61dynb`9Pf&my)bkzb`cgU=;n$hV9f{sFLX0yW3(}73==EX~(Zb^+i#(9@>@)=7W9pZq3 zDL~hm;NQN+?f)hP3+noPo+m>V2XJw%f~WM$Hm6$stnS^tOWTo={jBHf$@n^3hestxgbMHycS9w1Rlwwio}3}e!tHY}$( z?4e+oiCh9u(7yA(5~e@^M%hvK-#S42<=_R_0C#8sowXhO(TkPq|5PB;rQ?5cUbD*Y3!KF+QPzyewFk9G=Bhw<~WDVesQr zF3Y!tfocMHyBqvW?_411^*EfAYG|y@;a8R?)MD}wpu{-&_cLMv`C09H?2gPI3r11? z_tuAZ1pb}G^>54Z*IoGU!!{9+iZ%=108dTkq$&!z5f9Ezkf{l-i&*vq0?OFW4Y%F) zONrEQ58-(i=^r~dFf%c^ZKVjtm6n!{jEp>gekw0m=_FAU&F2A9>ntR;=z@Pe6V5DF>wBg(o&uJWa!i`O0G>%6 z00N0G8JF7v&5@ZwbRQ^%`L(D(zRU~&rb6VFn56Pw5jWd&L%7(ydAm9~dg`%Rtd~h0 z{Z&(65&m#D8SIiluh(N_4!3o9lI)|qj(a5ETHJz4bVFVv$uv4z^Q^^KFZN@$pGr8JYenN zm{b3FMj!%_@*n_{l=rd64LJt_)t+dn+aF?9AKBP&DqJ5lc}UNgsW;E(I^GiF$R9Zv zdP)h_$+J?aSpEQ@v-@J!H5NPd--a}tBe(l7YLvRrVhTRkw2*1`Ub#=3nzjpLmmURy z+ae}d2H{707roWG@9Lv*9<{6yHL7utmz%3`1w+M{WJcZZ-)d~L2NbYWnu?>AWO5&L zp!!{{$BAAYeVarnR4XYbH(IxNfTo(N8yhA4&))Pm%kYoANosG)17wQ1ou~s6IzC0X zPRG0Q&sL;!+^;OJ-wn<8ga{Xx+mbK9wcB?1B{5qB?d<@~LXFpWVP z+od{+Bf#zEHH_xy?hZx3WW0My;};iNl6*;lRQq=~<~F`t;8(DvG<4X3t9rJnT$#$2 z$?AimrXJo~c5ahx1H7EQ42F~M{&TBqYkg-ko)k{P(6>FjY-|E6GcHuHzK@IhvP-+H z#O-QD*fy7rIldBpCys#?G)8_UJPAXxXQ>4~pUJ%OEXyOBJ-ciQzBV<*)^SvdBT%cL z!0C9Kd#J%)=i&iFww51Q))V66)6eq ze?crx$k9!FGU31W!(QG0?D+q&4)A}k1wUgcSQQSLEipe&)(u>U0SpxQD8*|7|0fp( zn4ee}z;ZhkHD{PJ+fG@9d;#G$sUQd%R_*>qghxEfCN1Quej%3!2|)XWgyu2P%{y}2 z2Lp(vW?bimLYe(50X+sb*Sk@Chd*51z>xky{s#}HD&!)|RBGbHpr1!oX9dV>!epCx zNhDjGiE!DE{H|=cN9ur2Hz`p@B6VL47?_v2Ps0QnKJ{A$DCZGFB5%`ccg~Jy8T`~qsOCjqG?s&(BB)ST&lfXsETW@U z*W+8hGn;Z;d@7nPdu%;~ki`6G!XR+-c>SB|r(ArE?|2d9hj#-8VwcWk+?g^W-pD1U zyJ)0eK;D_li$y=~%FM|$!}Qhj!Gmgv*MOKQ%?r3-B*+OL=U z2u9trmZ-|C+12yJ`Q9z+Wl{<0gxCXl37$LluS+NJUx12i`#@dNW0fhdo>5V8f+{a> z`1w!n*m72J=5ihSo$WfA~$w<%kNf#Fup3-f+ail3ZUR6-gU5D`3)@z*8K(k{4LtfNh zm?o5n)B7N}#eOwT!c+-qZ^9%4g9A;ok>nmz+&nUZQr93ME{=Kb+CUsX$hvIb%M|2y zTV{(C+<~4>FK)D(!)L>$QiyYhxlP-UfV$$}VDDSdP#1AdPEL>+>vkhtd^IA%lKV-P z9tZUi7`S9S1Q{h7tLHkMF`Q~23qW8+i7C*xLjYrMj)2ZxU1P^PDTvUjVTrgvYB0@2R?bO^3jo;g7Sd+Sh}C4adx7`=Sh zN+1K(_M3xH-$OU=nCZRCI{EU7Zkttt#JT~h-Gz}dYdT*TA5>Rrqijwc@fF(N(980H zf9SMGA8U8f{t?O36Si4W@}1H-B1{(RErO$`zewO2WO$~(dNe@?a$pU)1QCAS zncwUT5OvC?a9CQ3GeiGg&unUinv>ZQ*yVT|tC^%d`I?E&rcnK0r40ur6!`wmv=|O&h1ftF}{en0dAL zNxgitJ8C4{B?!>$U+dTdPQ*6@zM~LvN7LI)HJ4{DOgqCW7lA@YkQxAZbJP+jCs!;O zq;%)p`vd5#-S zqdjsW9mm>V6M00iCC|U&NwoDgIlX}>ycx*rkUI%wkh^ z4m|?5imR)~T5BCD3!FTS⋙=4K_B0#6TF{=Plee>3{%1)w`x8u4vjv@7uEX4uAkA zaOo$A+A0=Mu!BBO(d*t=^8)Sl@rD1mA3k`{!uExy3?PlhYgLFV;$5{s;fs;XiQdv} z5pFZgDr4{#^XqwUhDwj;*X!D-cinh4a2Jz83mKiAj%&UFioT#H$KpO+aNi+(M0SgD zmuw`Hj^k?m7Q2s$`icD855q=?V|TE^Ez+K543p*K?-*C zKu31V9)&q|D$%}TsJ*MJtGl}{p?sfNOzPy9tB6dI)-(b0EzIQTrl?`(3A(u0a&jd( z;*p6=VQJ}er1gTT?DG_lh9FLRg#f@gai&fDvM7(koGp9g`M~FKNUX0%0HTphkI*7$ zUwg1`Ffen-y0&TXgReWwVu{T{DxvhLeofgEZ!;)4o8(sFpiLKG-p_mjX`r2_Ns}IU zr&X#y-Z9fo49+q(B+s_#l&@D!?4>f~jtvc$%Rmx@e8(~AgNe6&SLaJ4{oYG89ZxM~ zIdo_I4O|5##ycq*et|Fen)_7rGk zp5|txO#)l&KX+DOL8A9!=46M;7*m32GK!kX$T@D&q4F;`B7-8>oc?2;beo=er;Eud zWrx7w$Srs2LY6rn|5{hy0-duYW^X~MSGI+jX2!t7PY%>V;SgqMH#n^U#~DAyPCx?t z(=RRO9sC`zB-(m-8^nxY(9X{$^oh{##CLPw~rV5vy|Sy{)+feyjieV(kZk@)`R1klO#P%RlQ|=+!%zNEaD!v19hc*HtX~z z(bcBpz32Dwg{_MxjLs%|jK@8p^?G2Bj$-yKL-5rPy`x6hty!Ns8wSOr%ahfMzgteR zU<~`l0fZSFi7TN_f8TTd4pOXB;s_`io2AcY<#DbE>P0fZySF<#(`|dHCNKQF$@0`> zXUx6d{H&y4P^J$l&C#=RGo|xE6JZTr5fqPlu5`!8yuy|8;>)N}Vo<%dwa5Q3>EG_8 zkkUJqNCy%NmRg9cflZ^jJyO!O>zeYDZR|ilaAOV@m=LvXG3S|(r`Ct&LR&Bmy`z11 zKHjnsvQGN?rffUkULBP@CuzDcl`TB6y}ey9Z30G&NlfZq+1UWj{Sa2IkDm4zE{Rb& zCM8JYsnPHDW721rW24-`j{g}A8j*q7rN@Vf6J>Ne%>$XIKmkhT_Z;e*1 z3b`qk z%GGi@b?{zCZS1l#<$^OOzHI-iH`D^!5rt@=NBW6HD4p_DFP-I$qHC?B^|vyyqpXNe zRnxnd`+!{2HouU}QjpHAAAZb0iVPsw3eN95KJM?+{W?4}mm{N>PmDW=Rgy&aF4dlV zD$Z~YKR$greFs|$Qp(lK;}t!S`=9WuFrRa|FjZ6%w)BXxENtMq#okHR#N_Fru(^de zGhf3U&T`3RHDQY%=kmobEJcr$=8{26Qs19>V^cu_k{)Yc=R`J=)ME;3M91vC*s4UE z8R3`x2Vn08=!?f3Za(U<8$5rPDO)b6h*!Nym-spjMJBiI1*@l0VQlJhKTAhC<|DMz zOzddE5%0ROC<&cc{edRn^Wu*;WplKW*z59(7hCwTj0+?y-& z>h+=E@R3;C>Gf%tTD&Kf;br++AgxSP zc3*6zM<5<^mwaYuXeiQ;&oizoL6Sd%J^opm{kTDD+8KH%vsInekcq20A=~xM0v1Um zlUIT6JM#COeHsKDVKy4%8xgbHt)(C9HkkQvhLF~m2L8F3VqAAj&5LoVDZW|6Iair& z_o}3oyW+)PjiOj!xxD4e6t!1s%9?Gp%GKn&4)ZUuo?fou{X_@K&dZDIo!e3OSmX~k4%7#BCtdRG z{7UHzytGHz3m0?lD@^#TL(^rEvRQyj1l=!l zxtCurZDt#?amSNyXpuak`$!6o#TJ7fgl7XnG&MBxWmsxwb*WljoJXAnoD2P6dbkUX z;#`l~djFNUy~;BJbI6H2UwD0Tf^5F4m{}NSmK;kw+4@U^$3$F``-<&Q?M^|{0*@-n z?jsPXN-g+ChY|GWj-^f;EqtRiBWmGSJ0tAEZ&D)+<^z@t31U~=q9?21MP2aAiK;Tc z2+F+#-{F!pgWu|xs=l=xx%V@0q~4+5A&%)Z5EzE6`s-8W2rkCWe|v{o-Ow-ZtWDkF zRJ{2pK5#kDk$5XU86xX@PXOPlDqM4`4I-W^)c!g;I$CJilDd?p6(ui54I6sI^j(pg ztA$73^2z6&;K)6ObWhm0w6)l9AVL)CYVEUk?&&QSw3_%G@3q!jg+^7i2}+x%R%RH+ zQ|rPeFxBu$oh+LeMLMt3ntC0ZOJ{p*K=vOB)ZCR%b~9`w_GWmRIQcX7{M9z~IR{^EHQbT% zo7tqR$_x}V?GD}l@#7ln&t!=)M&z!UeSzkevy_z1QIEFzN-aLZk{5nFuI>%v^e&4g z-O{}Ef(TvJIx~AFef@5*vFw}&DI(+2qzH)7(ugpM%~V6Z?j-QqTGjlZ&-BQ3QNO^t#~`BeLi(a6Belh1M1+q#I@%13T)f*nI4 zCmlZoLUDXNR6L~Buj6APsk0yXRl=EPZ@GhdnTx^aigi7sJy=UVAo7E!N$fsV(KN1tE^ zMZpA}^%|sH1awKqZC+1mKCjn34FPdl{bUimk|XTkNgM-R6IpEYCCKS%r4xN-PIG4>_^E*w^*R8E31KhK7?>9<;_#u>($vU z$x*ZGQz%rCS}UYjW36AS(ad;1-0*Vf0ZwgFa;qrbQvC5{pg`~KrYLndcDdNi$8xvQ zs7v~;SL~4A(fWYe~1d zi^P&aZ|uyu);*E1#bnJE!;aZrO*;YP;V53rFV5H3ge__Z8Y%QS>B7 z$4+_m{%gpch;0Rf7Q@|~*9-Rb4hJ$GW7pNO2VP<#%KUx_$-9E4sC|AvR?^WgYssC3 zwiZ_!%DgPB{dwcbG&p1Ua>CKw4k)$FW_n9V5*@o#XvqWUk2K}a_WGY8BU*9bH)`Ch z1HDjii#YYVTDafO2dIfJ`-|)_UFCCJ%5faZKDYG+dX`kW#xa;jQKnQ~D_iZ}q(2Y8 z$uS1fPQ8qn0d1HfPm}`R07dM+C)b8Wvki=URI72vT0VrSA!9t@*CiD z4R<)##|_Q-m?^1vLA}~O^vvwGazHEYP3FT^CWu?+1}vkd&AG2NA2OXD$-44I!CwJ8 zw-G)0JaWn4QT0b_dY6X~jptA(lrt;wHjDZYzxX@GnJjyL3l;}HEcS|+nWb0{VYWwD zYXEo0%q)X&n@o{sA>BXw@c=!Z*>j%ZG4sN8rc~i%=buF5R8#Gh;RodAar&GGy8n6& zT2EtGk9(KKaOHxgw+J97k{6vso#k)3D&kH;o&-e|EJMIhmPBW}zqK^Q+lh zpcaakwGg|*Ui*=B%sOoAME{Jbh1D7l*VW53pQ&h1ID@GIPdlIDki(^vvxEQc zcG1!CoA7#|HmHT9#jw=hW>+mC-X`-WqC{t8EAPOCN6WBa9y77Y7tVcOFA2SY1%HuKA$Kg-S?P)2eV4OPjbCbWLPwI?wp z2gL*MiNPzy4lL-`t!^rtyKgcWQI>TZo(o|iL{^aWut3Ep%kpvB6HbYTA9H=66c#L} zER(oqGyAG)pHAkPNhXndPG1?SHwb8^F9!fZ?tT% zZH5<{EY$>d(deN>uYb-8K;jWfJjEJ4^lb zZDe@=xJTryL7DL23o}A>+xMOB40F@G-Ma7V_Kw`k>J+|sqL9zgX7A08Iaa;~WFH=J zNCirZtwvWsrpbc$+PvPg?lcuX<04j~pACD85TW`OLKpE7Rt59vcTTk;l?btCzVK`v zV)AaZcM1JPRc(~uW*Z_~tag~IP@y%{llT6y%0doTG*bat>&fKpYLd*`gjWw{kWN#e zZs@BKXnwDTc@E?=o)tnvje@3TaS_{`r!oBPR0%cXvnv;utWet>)sxa|jJJs0=(cYW zR586}#L`0&G}gxzPEnP=emUukg_}f~@}n5B&tA=l@`}Z2w$~n9oAa>pxqljTjOIKO zZ7i+SGzUDZT3?HOtY3A#Fhza5*q1?@-`Y^@cC_}X&*!OI?KXkWjq|fvvst2jNl!G= z1N85VxQ{Ke4Vr)ovd-AMduj3|CXzLn2L6H!+nUgSKjS@`+KQ!ih+u3!pP!S?dTok( zQ}FPdk!ap=B34eLZQZU2P)6)dAKh%$o9_wxLYuYO!Dcq6V8fF1EOL#!v`&eLd-D-p zYsBQui~`l3R4i4B0O1J$U-skL2w-Zda>P4V?stL&Z0U~2wDu^ z8TK#q^hEUEU)!pB5fJ_A9b;KG4-J1suK;>w?sWF&-5|HQ1$c~&*vHEZ9Q654)Sj&~ zZtfGAm6=IuCEsb7`AUT+Z}X-co)80TKbhL1-K(CSp4PtOhx7@Tb5lI6+B(s58%|^7 z!jd*~qz3WsJ6HVIU%!M!AU2oe#7hDs6FlAC?9x@nts`poj&NlMM#mENoGWK6IQaw8 z48%6gNbSM9>2;gXfaN^Tttci)RMaflwmbAXftThZiqCpTXc7XHKS7~8-qz}zH%jEH zH&bh0o>sJL*kETt7{7u@^!dCRwo@dxcpVz)wT01$Oo$}23+Y~1KvJD8JC2+*1qTbg zrAo$DBZ2Sk&*^>p_uDK>f>Nxxn894q*WRB|~c!&oX^c-m4t zOFQT1IpCkQ8Z?@ZryX770xT~)s99txeGb++QD|4aGI1&(vqgs1=-Wicm3MPiC~(oV zv7FyP5-u8WF2r0)tss)s9J)ld*PepyhDq2xJOyr9f92G~ft(t<{DYOvl+9H=mQ(FBx}Z~eX{YM7sgcp_ z)$!rY)d)y}>rRPvo6%}eyO!2z5kL>sP$L?@ zGAlyYb%5aOeigDT6uyD6nl-Us%49|G|NN1xO8xkG!__EiwwD`EsgcaC!MW zlm0fqC%_V8kT9x6Lq-_HFDXPAnX!Zzd{F>Hq^hgE98P)cmxbR`#8oPLixwnk&W@;u zJ2T1NZQa^(Oua9gb%7#^t?}xG^&-MwHor_4w|3HE} z=T+dbJ}tfqdq=)&B~L|qFZZxtS`hhEZL|0?TOBv)w@T5k0sF7L+`d{xW*s6D9=I1y zKpa}smMFbH?U)TSKlaCnLxXuTmpRSW!2Y;HGjIi497o8Q+g*cJFkQl&h+TaWaXl-M zBQ$SK(XQtU+#z|lE(E+9D>IMgt}+cpLdrC2C)tdjukSw2J^Ek7y?Hp)@83RbDJmpc zBcl+q?=r>~lFGg>gDlA&S;ra`vP||UV-MN)?5U7lj3sN)SVqV)WPh$HE#Le3-M{;H zJkN1F&p)3WAIZGm*LA&?^E_YYnB&@tF&t-VmfWeoS0KHXtMZLzM6uW)&p z2|8Y;s%f8h-tJxs+;cE7NuTy(th&y8!4&#=$Xki{nNoYYji(to9j|&z4C;NW_G`2 zxH)My4`pJ;!+MseONxUnKdz&7U1@Y{Z6W75O%c=JdGY9>);^N6>d`Bdh{vE3t-fw!+}tPJ)yLDv-z)t~YtCPkwLjOhtIR zzaj5S%R~?mr`f|8xP8yGl-oxPYxAtX;Au_7Xr=8TMjdkRCxoBTj%p*ek%X`&Vwny7 z{L^&HJfSqWWu)`|4~AQ$a{ymp=+%EgYOIFgl|}7spALsSIuz&jU>*^T6Ws^UX5%d{kUs+kgrH@uC<#oSeEs-bjQYK$RTi98!h@Q&9=ZH zaB}egkHrmzxldF5hHhF3D4Rwst}+Y@ z)(I?4Z|k>2t*+KYm`(DaZjWnV){oO$L)fHul$_7Vxnc>nz6eoXp0g3Gidm4WLl&|F zH@JmR6|L|!RLq*kNq0xCyo>&0h-=yD^4Vs#CH3-b`uBi0$LQ1J2Ylrvksjy0%RIhlbBD!KatBa{H{|njZY|G$%uFg$omsd7 zQIvzw4>HViHFdEj={KhIFm_I|oaOI;sni)br&L+y;7Fb(L5Ebe$mTKo$N$y_i~x=t zG0g~YKR3*1I(!|o%LBsJa4h^fVisCWacuicGu~N>uw3bP7FCeN=vG1B;J(d&)961sm6!;0LHk36yJs;i| zF3fz7s)HJrygzvHjPx|Tn$10da2}ohV}w;xAM#CSD2n^yP$WXJ_C^%3AeNkZY2zF0 zf)`7?yIQ&>pUT(zT7a@lCCnwkeB(|zG`j}1@;t_!7?^914#>YNjl zzOL>qFtd`OVHtyXiH?{HSpH{d-hs>GR`=PyxsA%Oj^xd8~ zW>a~JHM2*;g{@_!QSUo?Eko2(8W(~aMbxy&W{00! zIKsyqb1WHI6Ys3tRV-*=uMFV4+QD~1M|S>BE`j_WitQ{#WK ztJLAGp++)Xzc^ex=cM)z^)$}R^1iHG2HTJv@8fi~KjiVG=h1GRY|JOc~UQ^1^A zx>^H6FYbCLJEsd*_;4D?Q0mMQM$BatKsqqTdgNFR!*6{Id`kQc(tIz{`t2 zB?QhuV2M-c%c)(4m9G+oIsM>C&G{5DbIyQ-JB zZdzM%FOY{%b=a)>Dm`skv?jW7);+pKgaLUr31VL$j6}(tNy^GG=2JOt=uc?Pi8I-T zJTBGfqFPB{m66Y{(-6z;29G5zf*MFg%*zpGR z?_wPR4rIS6;0N5#=t4ZxgporrlN0W$7Ltv=kBD4&RJi3Hdu%bqV>JC=@Z^>VVy682 z$Qf}%h#LJe+Fie_ws0e~ZU|;873%keh!J-kJ;RZkxCJ0^T_ugGsw!bBF4H;FcR<*4)2^4L=j>T`Aq^u*zJ#<`4a`a zIm?a0Det}F>tj0n^PPD#-Yxn2y!qh}?N)h$Ud6`1foef)Hy{3n)&$|XbiIS`YMe6P zTWXzzkQCY0wqQ~G@4_vqOH$e>Dc7Ff%gxubtbhMZS@khYlfE>OBk#&?`n&f(f(y;+ zRudUMIe#6g6ke$d9m8i#B`ju6<(MoZ7UEC+RfUefg;;i@4sv;_c$U1BS!QE*?06wwgM?J?n?)}D035O*7KBw^ah zi?5sfP4{(P-O4eDA~jN45mnMd;ge(bmT0(saXv3)V21yPY9mFqmu)>K%l3k5C%sEM zOY_kYhcxbCr47f{XG9=0nl{fy^z^&U>onUcOiQg-&W|x8sTR7B+SIRzaBpVp9URF0 zBAl62x-uC*Y@9&!q)!JpapWD>ci8G7gA&K=xcLK82lvN%mKcAuJ5$nv z;_2XyU9B2jH|q(IZM2lQOw_84)YWO!W{nV-!o{z|U8gGsTs)`EahiCMgq-umOvvRT z`W=qD4h{vvD7laOy0AvAKf~4#?r}?N zUT}3!;hAzsj^RN`>XE{jbTSZu!_Yntum9#u2Dh2}TQ= zs;CyN=zjuQGS-14@UNw(3u1FA>%q73LO}cB%PQ^q6|h{4sasY&IxsW4h=_=Sq9Wm! zFsD;ovW_tx(DnON5VKguNu}u;U<1lf?0Ly3TLzL^#%NPJ83tyM*C;giSUmQW*3js< zs_Sqrb&yZCh`4lP0HN?W-67sPu!?Cbf6a4DafQy(nn3z>SfP>Mxa!!0L;DoNrtw8%e5>|8VBr`ogXAbMMlO440L*)klRXn z(nhW5U02)Ly?itJ34)HYL!C8iZ9llmw1-$}Ynw~FQ~kBsD7_O`Yn$@P`Eh}z@ae_H zq~;Ngm-$`ePe257NQkdU@_*!^ht_ zk^{U3xYTBJQSb?B5D`AO6<&g$5;$fE>$}KOY=5QVvUtR>9(QlG(Q#$Zm{WFZZBsgN z(#1Rcfo6FcIYDpl^QC#+Y71xVW8jKl4@K`^i!tJ&q%YOX==tc3Nd>ifGG*nkQxo^Dqa@{R@7G+d+QnS~I~%sG#Bs1mPu*61?1&k9 zeRZZS747gE6TUjCed{JNW5ZP-(mN1wnKgSc?zMr}R#MKI55KjXV8Wekr7mIsPV@A} z?p+JZ6_%HjwY1n~!+2SweAB2Vgm&XI=tF4tkr(TcuScg4~Umpvp?IsIlb246jDlvmc5*soid$o#&OEBKo}gT)=QzimH)co`B*J zAObTXnkZ2g)OQ}~=_mRI`*q~Y`XGODi!ila%{)y|p|3@jJ7X)`O@FU${FI*lQXULJ z+B_OtWRW(R5w&pFhp#Ph>LeDY_fp#`DO2rrIhXfKVx0v%Qv>JkSi47MAq>B+FMZ(( zmi(QTuD`c0)uzzK*ey~+2;rkPwmzySuR5nIJ(GIgeij)ZYU1mME%9aw4nIr9)QMLf4 z_8r?Cl=8#MG1KCz93kL!)Uj%wqujh+O;{TMZfFX6S?YnWP-IUWoo9}J&+{bi;GDM% zZfDnS!fJ?(^1-xAC*%5=i8fHwzE*!}%AcdxjtZEWaE=KwsA(DM!|}nG&R>6Ywi=8sXTgaC__gU;9GJSVhLt#Cp#kAY>b*N zbjG5uw%HWywp_Wn+brUIHXEu zeMPUq{bLjyZ5+vuNF!3mw6y%S4`L^HvQPNP@zVWJvPVh#hmvjDVQtrU3}KirdK!=%-A{Y&ca|jZ_7~{AFFd_rgKUlcM}`7 zZ{_5qR$NACBpzjdv%gxLpv{>cKN z0Oim9?y*YFRjt2HcN-==ydpr~vXefkDRl#R1LLo|Ipzv>OSlE>ZX!#^+qXo$oX339 zS6sj?7L7}Msnfc5imt;86{zHjivw;gepl?t)mDsVkQEYoV2HBu8g1sB@owx`7K!I1 z$}WRpVq$@p{C?H365({4?HW;@0KgoR{gGWDgos3!nXtvTK?+rOk0Ov>>yKxiB?O1? z>i*8qelrsxf_^b)Wh2rej^01tW$%XzmM9w7HAGxYqEEOjN7+l^{#NOe6jhl^wSpglQDrcHImEpGVviLd!MA5=Y?9>gp`~r_Iy@X=~kJ!^yU`DP0#Uc zB|`PAX0!ALIs0zv?ynS%m?A=QlP_XC?GPug7jwoC@L$cEWPT534NFSij4G@#AYEG} z^bDR<=4QU&ZpUI@O>6qlfWmu&hnD=hjr3irbq6P>*273zV-sB9^+ttet=T+Z&v$#z zW?4P5a+PxzDd;T(QIg{`OU6_;Wq~I1wl4 z!R*B#l%$YQbczIlaNN|RRgK7%@sFvW?qz0Xx-_AaNBG?~pg7;OC%W~48Hey(wbM_P zXVL<*9`6s*b?(<^Za#_{VD=%C$&{#tgY%r*ev1?1RrY^ps6leZvreD>J3<<Sl9 z-nBe;j)SpP;cNf5#yHBJ3*n?jmwXNeA6wMFcZH;7e_CgpXKmD0KN(z_1CTU0u9x%p zSy0cGTwLHbmXwKEsMGDesvhLvl=kC?3CF0k{ws5@XD#ce%c5u6klN}l$7vQ*sY?-B zOvA`f?-+E@>gZzDW7r56y~`rH(L(!LeXw$#ki??{2rV={)SoM=QQf;^2eb2)UK9E;% zyS^%a{qgh+_Z1OE_fbCr+TEm&Nm82Zyd<-AU7`!5Ym9? z5@S>`rigLZ9_zm1_5H$BxLqCh$xY8O1Tk)v3qY^5F*;8%gr}|@wyzPiI@4tu=D$t% zbZJP7LTHNxIn<4cz31WeSz(?zr?KqZG2ld=(y`mVMjLsr&gd2VrD;#GKT~Y5$Eu-! zP(x9~T)(SNi)nOLPzNl{KcI$d`D)idJ#*g8W+BLWXotUX5A~M}26gUrVk|IkEB!j6 z=m(Rb?ImUri#P~YXPyyiG|BICuV>GD#9F>9=cw=gR_|%gij-TsIe8EFvmpuVXV=)9 zB*M&I5@1x;kH_!Jt7=4rl$De`)#Y%a5?#dzS7ejar?S`}K+=VUg&BPAn4%_Y zh#%YhWXkdF3TiP=ylL)Q_dO!9Sj@-g#~(m%bsCKgdcCvO@Ue3V@@k;A)nDSe^@M-( zChq?C&+-oN@})+fSYR2x*4MPMpykT zl;x5ImJ&moeh3V6%D7uuLtj=Go^NgQu&J{;Zpj|Dt%RwQ4f>G0a(&t}ANPEyuJDFk zW4P-27Y)!9oDjANu^TVmVN;?tEg~gQGMy`k%|~h9C3C8NnL1qI+`Vx6xgKctC_l5l zx2l~_`dcI8@C{tR_4VT*QsUVo+`m~>uL)bhvRQ1}Sj-VI?Dwq-63*MWR&&|k58^(~ zq}@9$?|U|^cG=(3xBgPk8iDlj&ou(rERM!CX@wlrS(3K7(-}MZ6x0|^AqKgIal54| zCfvj;oAheB4Jbjp-eGYVG|X5<%Zo+J-;Aajl|=^{ue5Q?ldPQ>!leyY3Tnln`T&jM zz9F#;yPDLB&Vi4+k$}i~=+%gN{`?)aD2hiYTzPb1Vd00dTgK3PBNc89ATVuq8Z@R~ z8qsWU%)hS(qXr2=S_vdr2b;j<+=e#<^Nh+O5CqP4`nF9aOXzaA>sHASfhs5l%0LR;Ys0JPyYz2cGhEdwNZLoxCjo zMpBW?QjgbV@08lV4!SRRLeZ|S)HVZ>7oi;8vHEJnRZ^a=__J#R6&JMEvQA}U)t$wD zRVy?(3{jvmUm%fIJzxmo=i8FNG{^H}Gs^Zb9yA)Fjb6UGD96P2MygssuNXRIv)ZW$ zA;Ne)jvu?(knv?-Ja@|MXE3nxW~^e9$u4Po4qU8GRPs^`97S$)Jg^- zxNVNvRIMyXyo4fhmKg&G26ni5m={sR%;Rfc_0Za^m*+0a##Rrg@Yv&|3c9{ZfU6&d zC46z-!1j>W-^qy|aqVPGTtg?(lllon-|>h~4!P@Fi0CI^i`i(+IAXGwm?AJH?@%YfFdyD4+l-~y=Iggco$6IXpe@Ww z+qJ=Rdqf~D(31HfjN?hla5tJ_zh*x#fC9iCHh*MOn%0Zac>_b3MWYi;7i@FK`JXn% zB8q&c-YUocfGE@jpVo-d&yG)Rl9T)i0@%q6G*{u0T7qv#CvdAA_gy0bIBhickc*^+ ze+~UrS+eGY?PZVTRLZv){}az-v9G#14sCR!Nb7W+;T4w3I1((*^fL(7nltd>{;9@c9 zQP`Lw^IIaw=}Mr!c%8er$f3UL(B}$^E~>IDTo#m>ygWG9T%mQFz6@sN?oPYKbmGHg zs`J=X8SKJRqEK5r=zTBieEK(Xc{+5Rt8fYrK*kcOo5icN|o%^xFGj5 zWBnn~MKPJ!j2^-C_4~;Ja#oo8^49ep?6dl@;6x5=$>6IN%V|7FqZ4dH0a`v5>a@G0 zOhf9{0iljqOw`}y~oj^JF#xis%Wgx>J=#S2(rIU58X?tu0e zPt;5JuC3*mnlcL#i_Ygl0^Q4ocU%_(#2uZS0DI`M8mb5z>L1{>rEj{=%tSO|fvL-x z^}c>TWz2ETu(+$-Q8GHxRvumc1EkHO{+>>)@4-$jJezBI-}YUhs?92bEdkt902j=QXyY(A97Cy(#w(*2 zM?g=?Njf(BkxnF~oOM9g$M55zeB{BWBr%{%qWP&y;sFeN?V$nb&(!2~>rc#U;!DvHyYz;m%Hy_Xfqj$*O=$E|`|RNJ;NPi~XTf zYU#WE+`r|1LND`&qy^T28k{Q(La0;n800EtWSluS+IV~W_|~BbRqqWIJI$E~xu1$t z(CY?^X0|GA6%In5?!VyX3rEI3j=4U}(a~#t-jCV}s-$!0C3ThSUSUCQ1gSMVo4d_k zQxZ8!*6XB0W8yDMy~VG>XSb&Ch4sD0f~YJb*{P`a9*44gVAHipYengMdl)#U4S0OZ zoeXs|B382Y@3Z`!u?oO*0(+JnI8YVTEptIQ1739DxC_=0@5}u>hsEIOCyF%ciwRcG zTvN$icV$Z(9(Vp63#y8G^eWAJFKmWyN(Q7@8A`u8XcjSSD>+bk<0UmecBi&|K*sJQ zMF_xmuMekay}Yk?-Nra^W=4tSctVfhMdtY8&$%MxH{%Oo;%%pkcU^5Vy810M1wo8n z*O|Vgu=PUL->EW%#Y(1HIP!AFH;;D8{Iuy_62oxii{gt<*Yx5MNioyvHtNm?qlj&kc5X z#i#q4M$XYu*^8;jcdeBtX58u6ip7&21kt`~FJ8Q`I_E_c616u_SZdyP?nn1&nLL|q z`Il`mHxokvFbT8<4{pD@MUY|v^O9GEESgulAqi4uBZXSsuC4$Tz<~X8_p(KVsGM?2 z`CDkSb~EVGSF=Kxtgkia0FZ*<*gM7SoI2^#^sU1`CH5 z3X6+@zSsVk7%L_9v^6iVD2Qh|IiG!A4pnHeR}xH0X-7R$1XI7@gUl%ex5MzX$y&l> zg!n8;I}-M*&Zu7+p*l08D;YY)>mOSX5cR(IF)9YgbzoZP2UV^>m=(vJ$Hz%3p}G0A zMen8-K(Zc`#Ue;d!gu=n&vuf`3-)_#PL|J?!tCQa)e(7P1PwX4r!`aY zFD9#j)vvJA^yIZ`*Y3qMQ{4bH6(l5V>NM&i-3#Hrc6d@4(=82$~#h{x{6QCby zPmu~EO#*ejnwooG->5^#oiw&Z3Cj^HwjLge8}3=wJ_`xYAk{IwCRv|8<9`{IkS&6I z#WNt;sT3ML`O#hEp!IUl&KKLJ%4kl(M&IF_rL_u53*Q>rpFV83Ue)_N9Rq;G($MEI z&nbZu93N)>irjrvn7A(5WNMx$KQ6GLFstnBTo}DVuS5W!`JAw*`UpL!xD{z|^cs9En1hnulLEGceF-8oZp%f$Vsvq`KqH zD=FXp(YdtthFXWW+h^q!DXcaHp+&u&*lhGOOk$M7s=s;zjhOc4HRAJTCeiN^b>KE8 zr8{!mSTUSJLz%2%G_*+B(Ar|LAQJRD?6kQFZV$_HUFraWqQ4;!F!Q_I%KGV9(9YEvVmwdgx6oH~x1BsQ)P6sEj9{WE*H%z|z~B=>WLVS=@sa%0w&>5Pu_oR? z-fC?AX&ls#L|{C-3UgQP1MsGmVEl#bHddzI=AGLUp3tfHWCgjfk-MiHAMl}M{F1|k zMWgghj<0qf4vU2DiVg0#UpmLgIPE!Sdtlp3I>WPd9C$~%DADk?DrfXmc5JKg>XKj` zZEY`y>*qVxO`M1;TC9Pe+$M>?Tc^rhD2!^jSw0HJ4q6!>cs%S8d|D~&>RNYfU~K5Q z-Ialvj9a9Mr*bqmqV9T*Om+AS!vLFh<+R1{Hjg~D73!5iQpjm$Zv8u5P2o5as2vcS zMaJ!(?RV9*hV+U24))_i1Qb<{#b6R>7}_&Fhqb_}zSMjadK$y*_adO_BjKiA#~tdG#&hW!(i5;#SWu zg$~sxb$xhLQB7y9(%3XsyH|D?%mz-GXcnfe0eH4~JJr6@(#lFvRikI%J3`2C4=HaI z%y1J`>5TE?aEtOJEAxt^uSuk>UM2I4ZoZIu0haf$szEfIbDr;Vt~E-{j!g08alX4(05U9x=ezZ5CMIXM|J_E700nIo!Gu;vnw92H$%Qn6{wdWVizycjj6M*!3ev~G@m)cZY%gu7_)4PY{ zNfL?qa&tf4d)>O8&i8}wM_->tvU9Vayl)LmqrwaflCu>ab~86O0;^wZ6lJSTF&&77 zLqkJp>z5xN4_~EP@GVLz*y-lXoh3q~r9lLZ}U%nW|urZB!O z8y2reEenM{nUk07Wgw?X-Ttc4;}EcDZ0N1!_FyAMcZmV5CI0ng`vz1Oqu&fr9QA$YuZ&UOW>7iDP2 zZmcCWt<{DtX??LZyP$>Yaou(q)_0QHApJ(4uP@j*erk_T)#D>6cR;eh$oP2I4wL+2 za8Yy`3?Sn#a@ui3#_d>&xVA`=_^l*@-4<61V->pxd!P1cpWnh1@ItVWA;IRp-4paN ziateaIom|ok*U{C=a!CdhM$U(=YHsI#iweQZj*Uvk!b0SHD;gva?q-9VfM?DQW?+5 zs1M};+Rc;-qRTr!_nL#U%>l37|F-Ab#gXY;)*oL()>hSDu$y;ZLbFa%*Z}|`xj~!Jq zZ&6HXl;^Jq!eCwY@pru(sfXH~7FZ59x;V{zt$%#QfKXzKA{?^!Z#&7oQnP*Q^hTC` zY(NR_-?2k;0Qe9WucrVy6*T!kFR3<+t0t#w8D5;gR3E&U7nj=-uw%T{Cpy#v=F~TT zMs=|N`xXC;4joO<5vMsjI`YvUO4S|I-6OEh#x+&ZhE;ln1XPKh<}ruNB0Zia?@4_u z4IA=@Z7*484_^$o5gh7pE9HT%Wx@)o0Z|%9ie98xG+a5BRSx-jsbg9meXgre6gf9w zw*Dh|uT*BHC#b`##1ne+d1Ntf^4vx11{HsVA29R!<^o$@*iN@^aMwHVA9Q3&oh3`2ccG47 ztq?(7amf%ywq^n)Am)p0s<{#33D47_4`4=RL|b~ZI{DyDMi9qt{45#P-67F7cE=6o z=0uPFdKoDZ;bm2{*L_A=z0V5p)vu z`q%{EpKe10pVpEjTmUADz~}vrE#l*m{1K4==&ecue=W9g&0Um(rGkGH<^p~`y zz3MMgC@y#SJ<)WkstF(|i&^RZd4h5?GEIqNv_mTQ;Ux1A=R{CEWZV0;UGZYqfQ8UH zNbskXsBIc;o#^v5-hk73Ka6mPY#q$nZh6&x-5$mv^-nWH zX%0Cv8=aD#J>#1DG(P@S>uDBUclAvYxvBbH=8Yl%Sb1tv4n6qwX!z3IA^&fA(m=@Q zFvijkDt$acI;7Iz1OS&%Jm8|km^N4pl(0k3=Mik4vkQmO%%y55YUwC~iOwYeo9S;v zMp9JGe*J0{bLvb@W220yXdK@Xmn;|xR;oVY3C7N)N!bbDk792yM12?Y1Gr=QKSF#P zDcynL$t;}LR(w`a)EWUep!jZNa^7rvA7meVJ99&Tyf1{3rKst#;Yz6*@y3^8K8XnW zU3p-9{*{f@z|=Hqb*C0Mx6}($9x`2!vx+f#zZWe(SnNE(;=RxjcrH!oqpkGM*ZK3w z!rZk$eED0IP1pvMIQ@KN`W;T0fM%d&I)*nDy=xPAr)hN2zfKl+H!uqN?xFh{Y`*NX z6@VTV$iR*3FDRab0mtm~F~9?S6^x&`0fgXy*riX?A85`@{(119*BgM}4=&JY8#t)B zKc}as2Q2ixM{{=1r2>l&X&&|W(94UpyVzBaU-Q?p0_`jP3W_b!<#)-ZWgQKv7 z|MA?J0Umd{N#AwfnhrlT2yUnv;*Mj$i%h?|s9ORX;NZBwLp3wg_ z5`+I%!GGVSS_EJbuYg5XBvdAo5Q-%yHro33sazBAX~JGRmCv{O>PVcA-R-Z3939SI z?`jGBga5ghznHcKz^NZiKx08slj(n=AQs^VE_(9y-P8J!Xg`4|on-Q}wLQ5cCMFh- zHgz1{LE%p&2n#^IAU8vFJ{|;_Qc`~KG`~SRa7ILJi}Al6MhWftex-NDu4mu?$mQ?R zezr9eZKnpo>MGcliXyAa`6|9Yw=(tO*Q9x~gVx`hSsnjj?3uvf(C-DWx(-I1r+({J z-+Pk-HKm#E&*y}(9mFYw;8WD;qWsaMV<0CD1s^pHKS{(at-oS{GD1dbW*jO0T;Zby z*mXybjGuN*@(oV8A-WQB^fB;%R1N;t%Q#Z>nU8G(D**6wN5=yHM{v&X)O)oUe9-O6 zND!5BWrgGdRxbm9jkQ+}D=ef;EGqZ4qvI5PI{}3S3ON3f06?#*vx#Nn0T{C5z@0fF zJAZxLg1?6?8@#_2%A?Pd1$NHg2!nU(#GiaTNm{Cg1#j!uTuRu_JKTl}fBpZT-##b! zCn)}(_z;k1`D4+Slb_k#xf7$K0U=BV6e3Y_4$peg_yB0F8U$4^zEc9RE?;!6Zhz9nGb6O>(r5798 zFr2-5f2YSwe}=AKA6oP8#=vX%`&n3zKJ*w?T<-a=3(!6h?7uTZ_>CPT%#t0wY&^uS zJ;8PaOoKJT9o`z9_`4Y3`(JCo#`&LFO4NNn;0j*z%*^WxAQyy8N#+5;$P1K<*uK6q zi9myPsZuGyjJ%}LdrN8_PJAbDIRjEa{43=DX2*Z)V1Vd(q)HZy92{i?#2=AquBcqT znfoXuusJw-KIY$2O#rLADK8!W`(XIZL}Gl{u>wN=uL+vlfik{7?(K_pA&~BjX_NuL zv#EZBa|ey4DeU?@Qfk>hbD~cOvID$UYEFPAN1NWzUnqA6SGWr*kaGZJ=71KG{{6(i zw(8M{DS&dNmMDMi)rG5v@8<--*iLd9-asB~qHp>>6V8Qyp7wW4IU)k^lRSU6Kc4Mv zf>z%quE5U%FGLe255KZ;kE}SI!B6b=QhBomLec&C$LdTu-xVow@v8dz`jQf0Q7#RH zp3z`bXS3|Zbj|+?8~ zdGZMVycYk(xzR<(8LD^YW%c#rNXR&-%z+bnUS8hg)oIC(n(Hvm-mb0<*Sfb*@1hOh z#9N~OO^~ug4Hfp6o3_SpDJV zws9>rIr+x!_~>Ht4`7ra^mRa4ZwA^@*Nv&(=iDJ(bhZGs)7d~y`n zrawgsDS+?#yqfqGIijI1yJ_WIU8JQv_`l1o^0P6$$>~|po4)xs; zmWM~BG~nld(>kJZD~Q90zbWBlT1C36P{UcQmtHP0My!Ba-pzObqL!`c_~Wec8(Z95kh zeo<}SD3FhT&(Q8~f8XM~hn_R{TVM7BHDDLPgpxFQjEtn@_FFQ62qY4)3j@jw6lH0*As^|X zTL=q_jQU}W*SR!cT4mhRR8{2xXabUrmMeWgvWmnTArF;<@D&alYJM~SGdi96mEeA} z8vsG8TB7{(6j`Q!$|`^aVD(cr6&8Ol(9h|kpY7eJ9)bx?AHsk4Y60j#o7Q%JPo$VK zq*1cSm;_LiPgMTMK>uZ*bm=!M5<}?_QsBH{qzanz1Fk;0}+OinT66Sb&_}4!z z>lt!@P(mX~anPt6n@@n8LT!tFH8&f0FHldVK%{6##AUka$*ca2UjNffcA@)Gb!zeF zSla|%;}LZh_$M2I*D3twf79~dOK!I;vpR2Q0Q#sm)I-5geV?XuU~?bP^3gX014Q7N zjN811^j#{RC4mwvsv8Ep5SlXy?f#&aQco#TY%YcyqC@ySqTYG zpkeAFn&;(QH+SctA2~Ih^zc0x>8+8JOPP_d%q)DP7}2D|kk?(58i( znVQOYd}FW=P9rd=7WQ{>iB?r$XjgjDYw0NBUFg;Y)NVK*N8Y0~!7zk?I|S)q@=c)aGAAe`xyj98z_dUf{rtSZ zm9y!V0b}0xljMEmQ*eDZlH>@mkzz5s&TMFJ_*0u`4{ zFUm37*Y!$fe_z>)<6OFR`)@@TIqg-^-WX>F?nQZTbh4&?&RbEe;eN@0M+AAv|1pW3 z{ruTMuz|Ec)FIk3`j|8E&g3)w}`n`vun&&kzV)4l2TOp>ZAxiH;D)$mZT8ZV(xl$2^t?c|+odOMtE`vCipUGVlSb}#WBJmMnXdEex`HGHaJdWJL|C2;B2)qW8=fKH~upy~HgX>Y~ ztG?j>XT64N?Y4MlaE~uYK$A&x?`YC`o9C?aPr~O%`}V2W}91%{3d+ z<57?|IWkzjPm5-P2)w?am8C5C7G}a2@a4?n#ZHsW@p220&`RhmPiz1&y;`-De|dJl zB+tfJaI#F&RbxT*f>hz_@fqPiT?_hpZvHmJA@Ky9t zmjD`FH#FrxND&?(`{f)0>MJme_+QG^2k8IZU24Ax_`*+rmY-rW)2oL-(npz8wDIIqn;ft>h=>kZ%ISUrh?S1i~FL9+t3I zC#1q1Mg$gIw@^^`8>`$*j%nypx;vGf@t8RQY2X-0U)_ly>7a~WdbE~ikv9Wt_e&4e zd4lA7q+UUTrC#kYkty!52!D~QvM@UJt(ptV{sAc>*qOPBDb3`oEQy?C&@|- zhz;Di?Z;}WO5QiUg!Km3R3KuEO7P3 zYB3q4rN2EPTdZ@5cG&Fx)4!$3Pwew&YO5*4V}quD65>&(V)Z{wcAeAN2W?;l>x04R zsqx{tBos=GhbAg_=STAp=`WTl3k;bb%T&9`dN)Ry4R=kzR#eVr^-9p|6VIb+Zx8{7 zymQRD=LV94UhJG_QeXUue&6ud!z$c?{Z93hyobO|@ZA}+B+emXr8DkEnwks?I}{|5 zCH?2rtrUj6TB8|?5ebboH7ZKteF%6ZKGLJE#+%WNe1lzPbLHvYa=&$7b2drO*lJtz zEcU{pEEN{MLjO5~w+Z3CQ9zBug61{XKAsnH7ht(6d}ujPBi3G}s&SYx@4CRl`Q;@z zm*q=sem03w-mjrX<@IpuCsHB@eHA;*(mxdiBbE=v^Z zRCqlMMtH(&W8$Qf)9Q186=H*&uXo*raQc4Ca9okgy-a5DPHOu!nWh_D@X78n&gY16 z>-jaegw9N({`t3kVv`;TAsEeejJqD}RZz3s>RPApbGOGQxxhO4T+sB#$tB!?z6;#( z-AKF1+qNk8#v`+c#K_DH35^zmb<Ov3Q#Ee42`d?O6JFk=ND=aZU3wx}h5N3j|I>UK5AHzn__2vOKmr{3e}Ze# z@E6V>of3Rh{No|DQMA?j4>BpY-EP+8K)f-T4op0MmcGoDiGOM#JYd)E|DSGw5fNy! zcdSG0DC~Jc#Mf*dsV-s?^+ahhw>V{p;#2el7v+M$KVu%q4S=D0*q*1?Y!k(;4iV&P zBIP83O8V^;-{L?SA)#h+VA%p&f(^Ky(mIA-4YOsgN#ut=fkwBvjJYH}*sO*1h`N7s ze@X1f%2W)jIT$JH%3frd3JeEdxq$odDdyn=h?%W<^6_S*L;XF{l5B1HS z35~wIv^MXYvak0d<7)DRmes1^VKb*q%kpyKrUkg-9y`ikCPaWq&0)Bgcb>|KIl}UnPez zko=7+LCG)^st-So+f9?|{>!)!r?CLz-Tm#)&A}=Zt7Yu21n3Uf+Gc#ivyWTnqbsmvZZ@j)X>v0L6)bQ`I2q%{dzm9y~GYw{dZ8hh3 z=`X%K-#gSb{lJJ5vN9t7gkt7_cw9@YE2PZ%ZztJF-Y5IxW_Wq0#HVSiu>%lbj#3jA zC%az0{@l1)DBKpHtrS1K9c%-C3iXYCN`ikjmH_kl*Uap1=E9dV|FcO~DT~{=XBqTQ zZfB(Q&^CYj<`84#mYg$%`%l|0uy|0n6Z_s)R>wkupCu(p`fL_N(cm_Dk*%626pDWi zsn*O+8>jsJl64~c7mvyc)J=+3xC|IuVXYhu7s6knw?VV|mMj!GGaS=_c=?HD|I2vIeVwN-XvF}Z7SBRE zctc}p;VY}drS6a)h`UOWtMQO2kA2Re;E|U7S3qOG^eUvp96bo8P_aOqWns1YVo(dM zfIdE>JBlcqdBn=C>Ye)n>i#Nz_hh$-2*mqq(#xyU9)wKCLy&GoZ#xJL>(fk~QW$!b zN>Ph54~$5o`z`Io!$|Flc})#CLE(PX9rKFFQSNt2nAMiF&(clcsDHJ>6$27Z0gJu< zv++`%s0cYE!S8kJ1Ee~hJN$!S;Yo^L7$V>Ve^X`wzhRMGUJbRETvrjp6%S6F@cZgw`fa#Mxd-1k!wg&!!>SZTGWDVcYbQdrZX)Nkc8 zmM1SMceqH| zbgbHi792ihXsQDX7eAw=(Cq$zaKuR~6(Vva$m{DDRx35To5fpe9b7MP>W{;gqv$13 znwDq0OTa+5XluUv=%9jR)2kv5NZmVz(~`YY`rkcIM0f0^O@8Qo?R%_Z8eUF1)th1r;qdG)UU%=_9a~d0wo1rp zgb=vLYoG3Mt?x1Vm~YghuD;|oGxhNOTcB3P>*?&I^la$_7+dXgIwoB*eoRahj}Y^$ z_wkd14j_589_Tt=pBMvr74Q2qpW6a4pki%dJvSwi|2Ly9iaz|(1mEs*<{co|pa01AA`#H_OB(8*Zw8kU?kICi znKzxK_zzs$@rcw+bzJ;^Oum9>;>Pyi?o>ft;QXoZl|U=o5OPtNdpN=w+fX^qOVs$ zSgyV-%-`d#}4`9yi$*c*zi_WsKXuM-g`s7Pqzhr}su zyOIrvn<877e8i~xnWFY8nFMCKqNae$10drHmC;q{Fr#GH;$&x`v{~0Odf6YHN1_%F zQrv&H?zC7;-ZVM5#e(Z&)&>L&&!KM%xQx8N3yjuwlp}v_A4D$*JL_d#4$NFm+D#b# zJstI@Z~8SGyu|iSjCLaxSX3hIuVh;5++%{ z5CX>In58SjSphX3gOhV-EDb8Ft2Y3eRD*jO+L_z7#Q^J zb@-d7!HU`x&z5f~w5%4Yyqc{Y{z&TE(@FJ$as5%Z{H8-4VlUgLJ$z-j!*ouse5!8&Q4uw>n{%pk%AIC>BpZ<~75fsx| zSq8Sm@Nd4Fnd9C*sY$k#np^KDZ6*E$kXl3K9TL5OOe%QUzR*!1AU;Ze3eLdU!5W;5 z1p!CvlBzy7&as9&#_3{;Y=^{r@y}=L;14Bzp{o&QQ`IiX+rA}TA11bi-_d_&%u*y( zDoGz`2^+ud!kK*i|2W-uZx-V`ZSy=MBLk*^3V*sc%yy65yU(D^T~i4%^Hr?22n#pSV$GGV3)kx`{1 z2hKh8;ubrK<=QIu;}B=AmPXwS^~S?3<+HlQ3I1L&>;VPyZ05ly!_2aEo{N4{WhQZ` zSCcs8Pe3ebpQ|`_+@0r3`Pjw|7kJ z4?%yu=nIAlnpX*Ju{Xk=TW&c3;K1Fz^>2*&;wvr%KuJzEQ0opm&JmE?9w!C5Ue3c` z8LI~NB3T9n*xOA#SEb>CmYqt-~PQ)`2}59d0q0aG9tw4zOR zVyDr?XBj28J%Sm}#7P+sp4i9_MjERGh+;2S!#~W7h|ynq_RGmIj~xZe^TI!|07)t;FaPF~a`jv!mSv%4A1H*=ex9H~n^69R} z7m%MH(e%7WR0rJ!VCt=<<>6x-a`q52I zI4>En-ZXmf;DL=zHke%>K79Dd&Bsg=eHy1g$=cGBp7MOd__kx69sU;*4K}Kew>CC5 z0yD?ps-aPnzS#IpqXYT_iWh&>RE7k^uiO2Vc=)yK{B9+YcWJ0nUe@jPO%B8L(N&Z? zs5{^WFmQ%y*}jWoUX<65zCW}01}(bv*cdtmto`oTEhsMuJMBCqcS|l43Dhze=QiFIsdD75@LIo#jDAKShTcUP$=c>uO)!M}1wg7vTbZ&! zX!Z@Ry6~r!*6^MO?BNIST6_tILuzqKB8k-;^Ds@c#(ZLK^u7UViBF^HluR}&;oSGO zNSm~BIRvv)7aF|)fh%3R&|!9e?I|_$bMNWfnt^0tqygho{v?Fx^_wgdhXiG;NTbiB z0tT~2LHyI>9{o;Icg6l{ionsd_mk&X`t25{lqRrsHu}omUsloxqqt!U<63AZ95E`> zMI*p5MS>hah#xYXC6MB8LR1#fv>D9{2ovo1aNPXXr>cr@o8og0ho4*ZrFUA;A41n*dv1pWvGuFj>$U+V!Q}MKKv{dSg*hd*oVFU#)K&xQ)_;_9e?J zcZEPj<~_EF*K0vjQejrPkGwDi$uw*gU-9zTB{X{e+ykO6Q5d$A@azO9>^T__M?r(SajjwqpYgPhsTVudKz`~gHUo$;~ z0Xm|{Z*VMffQy@3xc|hvxt#vpijgeE*ahX-t3ui8?Jfe=p?DY)*uL_-DdZBjN@}F; z%T^=o6K@lBRdOcJPt?@ZfLkRkn0ANoGuZ_DY0od%dsw|2zrcvbn=g&>MlP6j7TD0J z6rh*(y@)frYW`-XtV}OaD9WrErW5|I+y82>5o@iL_WGHoi2-mx+LiwUad-=Jl{KR? za8tH+G|5!4)$wH>2DQXZAvG>8t~Ut@65x+*NH*7xiqkE z36o4`LHZ7tg#P7oUq^sa+su8Kp+$q6H8A?IV>U)A!GAg^tQ99v9a-Mp&D+KRk7+qG7POpBvrddz~raH zLQ-voeBq9u5=PB31l_Su9B94M-Ebfb*1VQB?XX|yv_mfty*>%yX)hUMMupZ02~1V# zBF0p8jE1(BR-r3}M27fIP-w8gvFJGWk195cWvS}Uq00t6kHHg|>Q^a!1uZ-rgVp>^ z$oRh>iu`SNhrq>i5u)klJcl&_Md&*r9H~_-xG+{7Dsi|MxPa6~grmXViq#nw^(9h) zgNJT)=4SPSGWr%Dx7#q6NCLfX>K*p47mg$)AV8b* zyG{^r6&NZ0WCL``5ZbZJO%ga~LSV0d@CwZU zw&5944^I@Du*9a*yc);gU(%$mt_~x1383P3-LbTs0p2g%bPlH7YDe8K=?NWk$;H5n zKQIJpBc~#rnGHmcyWFa1xC!>;X9dQhRFS4Htoc-`*t3QQbT!;~p%NGJywg;%9ff2Q z9@JfAy@Vz=8YKiD`!N@H8@+j@nvGjgQi-zIv9i|M;v8p)4K!*^gS%2!flc!A_4Q)H zGIlEuL>F{M^~K|Lzh~7yJpbwhM>8Agyh&4u#edTn5#`nIhf=(q-ce64?mv|b2q~f& zp{N5KVwd3x=A^$$tP--S?XK+M6d11X6|87aErk1Lk;7FF1w3hR26>Bb23xiGcQwS} zAOHq7(T`kGM^!4G*k?rhD&6fk6e08p-JNIAPg&^31AGDsTLJK^)4AcSFRtIrW6g=+ zt}8?x&wowy{{JEBtO?s!N+m)Tvc|_UKhM7Q@dksLBz=jB+M~);^=ZOCqi9<6!sV$7GsouSmF-!Fk&}hKRfb{06u^-u~MgncZLH6HoTNrtQ$o?HKmw}M^|k(&YHM;p1h zx%~?mALP6S8RC`ycA5XRVv#b?JdBIb$b?fz$-8-XmxT+I6~j3=R%0y8x=ScsPE$H? zxR{tsMA&uZJ1@<&o8je%Qy7{s{@wK5t7gU7u8Ne~>Ezcd12UI{?mQdXaH~4?6Rnqn zN~Sq%Hh2XI=Hb_GsH^u+*KH`b!bma`-ha&GQpJ?h!2|dRs)bwa)X?7}1b7k%zkKx( z#M}U=c}<(}*R9^;EjUWAiEH3MkI-#L+?WvQK{%&Js!+0}7u?a#<3dA~MmOHn&=|== zc_0)dj$$JS?%H27_6tf_S=)^&pz~pLYx`$wQU9quRSHjTlsGL+!U`Q693+mlLVfFY z7>WQ&VQ#l8IW@P7RF*DAjmH)oakgB_6)o}oqOu0~dAt?VEu0ONNX9xWf5TCw(~IZJ z&lcd)weu~ZM%i_{0F|j9PC2{D4u|O;da(loVwd}tsD7ul5-)Ap}fG3dGAo>Hn%^N3YaP(ilwbUBye)^0e%kP>duUk)d`FvlDa0J|K=QsJ&% zvNZS_Pa7S>$x_;|)OdATIk&D$ufgCn(%4R)#=qZ2b6r$UH&{s=7KH%vSs#kTcrSln&VmPt93%UApuC0zgA>@$-Tx#yJpcMSD5^arIhxOM1|y zdz^gmmaAau6$=T#Fhc_D!%9Y%iMDJ|B-wR249yIDg+aI@c_LTeW4~F}aoGh@I<>G2 zOKeYHG83dy1knpsUKsq#XVi8fY=W!VGa>p&_UVIT61CfpoAr$Q<>M@#luE5L;M2YU zSi~OG!pPWGT{ZhReFwj8kJc^qQorX`0_QFpTB7wUc{gGbu=2^qPg7tO_DvNR-)5W> zKv)4WHzXM6`o1ktKMv_m{C5jM^~KJPqGgJWS9Yh*aM}MT7(wn!(FlPQygZ7%hj zCS#xgeuxS>)lO&`gVQmONE(jyUCb8OT&7aUp)8L2`U6#g!aLT79W#`Pj^*L4Uw?m| z1Hb$_y?9!}inf4pk*ay^a$06kYZ~RIs)0K(Em6yN-0951EP!Q#D0{crYB<8Ddp!mF zR=1u)!kZT2XYOtOvAWU1@D!+QI49x+pPiE}X4~&oGXI(?xZLrvy|oMGfWB(rA*k=x zB0?{4m-70+U&R?7*=~xEiZ-cn{QBxJ@XY@Lya0_q#jK06(XkceeuarFV}B8l5zUjp z_A5r57{1ue^m6skdhFs|KvssM52Fjzrq!z=o;+Eoo~|3uPJ;Dec}h`25?xc$N0X$o zh%Hxl&`gad7j#|vuu^1C`yR$fc0HHD4|UL^LQ!k~{@tENSvWCoWsRPdIVJH@bRSAA zyY_lH>ah&7qnD^w10AImOUTX-)N1dl`>kj}j^UB>6%*o-apn#m&#n(X#2019jb!mO z(ovAASUzD!Eb07{5(7moL*o(a>ak~sg32oxW=Wx(2itTmBsB4%Dw2TS8(J0b}^DV2opbv-bK1? zsB+J1yWnQA!Zde46tNymd|s(fxR~Far>c(SfaLoi{Vybwd%bQO+hMfdQ zz2DZbdxn`Dp(t`WY=;UwF3eFR=^n1spRShqxDZ{qpq`5^2GiZqQRFZ?2yLK+e5pqK zxa*(|)92YMV`ucMuO{A&%KaS7d{lwfS|R2NN)4Ot#t|2v-G5IXFSg{)=hqM#N9&t7Ei&WUZulDb4}(YxFI%;G8DQT<^{F6dhhK&s#UnnkuHaMpGgepZ|FF>VBU?4@(*KRqk z-t(f=9XHjH?;*h|y6<>$mKA!e=<`*7xGG3n*FdGe+MVY(oXl<0J(DsS{OgwEPl=*^ z!WPbicHe|k>KHBp_Hd?EQDUg58vjhtPTnX7<>^@iQQF*GV2aK!71~M_giOv0Lt-Sr zZ6~|&zGtzEp4jt@lBUJhs$aF5B!QCl+$>akF&-RFAZ)k!^nbwqh$@}*o&-u~wHV@q& z3Y|=IfqQ>qcGzb{$0Q_8$)%u0hdIe~w8~S`&Brc)#KNYFOY+Q#mO@@O}17U=24PP9pdZ>6i{$dU(hf!-pEsjgxKjc{I^ zh6;5&IiRynW^6v>wKX;I!;t|Ag2Ym2 zjGhp8lCA~2yn6zM`RaoRBaQLK!jI#5enXeU3PY7HMcPJ=*iJb0eSQW~sj{-Nz1eD1 zKR>^`AnPa3R)sZShHn#EbaK{l(vAX>hWj{W-KE1Nl^O$}vOZXFw#IgBRgwK!bX0!I zT@I=5s5{Box;k&#-@$8dV)TBU!6Cm$Cqjja2v4(~8PI?U*rf~ISQ?Zke;!`x=^hes zZ29LS9%Jh0=VTbX*Da4P8wGb?@~Y{1#ou$BkuIFwT;)S(FSOb_h@mY8+84|>mWDD7 zZ4JL}ZhEi~*PkFhp~g|lMB)&;j@)K}PGuf!xiG0?ji-$TW5Bn^b%{N0txowHBtjoY z#Rybw6}tWve|DW_#4~m=0D5;n12rOiW9UPm^=_!VRtW;f zORhRU1?^pWV63kscZPJ?OxpF3^&D1|0d|!L;uxTSSTp4WnMkpXjXl9_f*N8PgQOm^;-M?7a5Gx&RYeP>tBk)CRE zc|5#rkIJ2D?Rk<5x0+u-U4XIiG1hk5s7z9StkHp70}zPg{jTQSbL zGqODK^lZvbzSVA|h2)a{cZT|gq7sl-%gSo?KLScwPjhoK6eP1M|3S7$t$*9@M~Eih z8CXmLk%Ww7n>S-|A>ua-&J@KF3jx;#8xFC{HEl4B6hwK-RMqiA_Sk+0P{d`lEG{l4 zT}=qNjkdp?-FlqEJlzO2nV}dsTaj5+Tj6dh?dp)=km4}}UMP-g&rCd9_U7@#vhe2W zy+4VaE@gpYe2V2(u!2EecVAbrlbu$FIQa>l>XokFVnC(9iG#PM+*^OtVB_7u4r6wG|6do(2I!h6-%kxhZ-*Us9ye@@2w<7;U%0DnJk7F7B~ z-toJCMoce8$qTMML)~{;&Zczzg2d3tr{A7xrY>J<{sxYH zY+3)jW|lNl{Oj$)33PNj2}1+Ouf&!Jm7ov`gGV1GY?&ZP6E`!Y&5h88j@hq-?a8hr zc)xgo;P@qf>9bv8%*GxG@bk+#&5r|5tpDt%NHNlmc@?xm=o>c$$$esQ15+Ksh-8Qz8%FD}Pw&x=tcR}lVC`{(zOxo5N6TAHP z_|`=ZjOtY`U20&jwkYLuv@Nqrl;%NmdTj@vHbP=uZSAR_>6jRw*ge#jw?JoRQ+D>aC^#dV$Z;JB;yO^48lnHwi(Ykd&k*+FeP^-s2L3ESbwVQF4 zM_-Y>T-?DRJZeV4fNl=%`sFSL=*pR=7Y$6lm~PCI34VB3K6waEPPoiEPTi**3Qag+ z)Eytc?=vIw>593}pPA(E4)tn6ApEoTeeCUiM>zVTV_&w3eh|%?eQ`>x^>&NdGe;Z! zNK2HPCAj3LoqZhmOz!OqMYJ9z;DqgXNMFO}^AE2LOvG4OV(PnNYO8u(YwGHZus=8h zS&}94KiIGnF7B>s-`5BVIUT1O4T#WVg@E`ib%&G=fjQ`~JE7pkgK9@J@c6~{UwQbd zzusrbrcoiXYT`XZhR#Te_lyI_P9;?IE|D9G!shp1h)J`5EkA#yR+Sm>QO9?e*=DxZ zT(G~(Wl}HbGUpdw-{ZkGyjN1buW18{HY6sh|7K`$AtN@u$Z4$dt3{^Zhs&zw0v}lE z4VafAEy`aKd8PwCUS)rpz<)RF!$!vM!R8LIe)u`;_UEDVZN|7vkEZJs+V*^JROVi8 zw;xko189HPxR?&KU?S{^op#-w-@kuvYbyZI9sHjyJRTt>CXc&~!_}{=zJTAJVTwg9 zw`iY&N$f7@VAHi2vYyh!9{r2hU%FCZ4r}LI^gp4-S3+kn=Oy1&KN|F6E8`Oc=*Zj( zZa#<&!D>L+pZi)1YXBVD;Pwp-k)E1k*f#b0v(%CnWKQtQ%ElB68b%I&nSi#E9zdh( z?c(Kefn9pb*FJ<)&kC{ac@wY91Y$?a!k}5P!-vf;Gmko$n23~R?|43A7xat>7Htx4$D2eF(-+l+4W__|Z|x#=b` z^?l0m_7|l!_LUpig$%)bCS1fr=H!M3%^%cbW{MwCUpmroptTb(_Xv|Y>=e)*=&z8} zJVJ>G5C54GUb>PwE|PkN@LlmxNNrAg?d!Cvlf~k0u*P@CDhf&ois{wJRWuvTgLcb# zDdkEiPCQU|$#OZTSeg%ynwM@q-9fQ;eJaGBa=lA5_)d3x^3W}ra)X3*?sskpt6Fjr z45b1^jCi?DgY!=*gj@^QH$NpY8Dcsk-G?7B3uZ6Aqmwqf*W<86OsytpQ^{tu;BVVZ zn8U1p=I*F-OISyWbWf=(y7F>-g9q!~uurCp^}+T^r-DzbJ44t6pqQqs7&cg$;;@tm z!R7d}Z?6}cTrQrpTL7b}Uvz^53;5YiK~i9R@K8`X249Qi)?Mn^V82V5`&g4m%DEc{ zN4cb4IJTI@sL_DQZ|Eh#rf#lmPNw=}b#@mRV*Um#QvBt=`MSCc;9W+%7ro?}o%3+i z_-AWtN6$?Z19n7>$~w%$7kzIEwIjYY2`Uj);q?u%N;x&q9*{KupP>#mI2uY7-u`j!6HzGa9)Y0c}r`8eA%H5Ro^X;3au=z4Ng_r1t_ zX&>#KgW9>vkEh4CzY`dRZ4uq$|H_gyh+dH965z`Ko`!D>oW zC-sD!oK7uAl%B(Rjf$51=jC^U9;RL!yiIx6b;LW&VEO0IxV~6=-p{C;kG<5|5-Y0c z4HbVX>c1C$m|}L7>8&>?fyA*)lt;-2^5?_)t*&lUYerwLjk__>su6ElD6UI%(-|aq zT}fKU+NMLWSh$OCoQzEiKu1ctSzjEBbARHWHc@VG{CM|!!s0_$2&Fq_n!*y!!4oRQ zUdz|)P_U`Z6vU~wD47xfiE^Nlc4=LzRLv2as<-!N7Ra^lGdFf`&pA50>)y^Ke9@xg zJv&jF%lNSHl-%OZ)LYD6){oGaWVlf#j?Bkx{)xDLJo-MeIz3e94p<+VleR{eNJCdx ziXZ@8Mb9eOJDMX%lw2%8zuikW3cNS#bo?@wMxZ0r@H|PvYqLHEYYK^2h2{1s+@oEj zX{VstV^d>&>1~C%vfJw7G+fuUWd}JT_X&02byCE7850aZRlfne6d2d4mJ|>$RIjpR zK+FnlO@K52_Y%_n;n+sJB>hN^anCyhSFuHmhzY#q5O_Lw@fQ(-C}a8&NY?``yBqEb zjm~a(^@seRM;30^-ZxR?+q2XDL^1ku~h@6ZRSs5pB-&3hnD{h@YJ=~*z33@Oi{vkt^f)BY zG?R0uJ60g60oWslhmTZ2sN*0Qzkn!De@WR4m=O@O)rb}r$g-?X? zFpDHUv_)T~*nOn(6_R)SSrrGz@Y7Q_H~`tmn=1k!m1NgjzxhqWjJ?Naw$Q1^wmzeq zvY!{6WuFalyYvZ;%ypVf6Eif_5~(3Q{awbH+4+5I;LzGHE^#Z@WjK)gW&)wp0dguO zW~#88GU-Y_i(4y$4PROy|#Zx;-Gzm6)R zh6;8BN!(s;{-=Ln$xGm>x8TKfUwrd!$jZw^nrsJEKoTf1uK5V@_m6Nh&FnDB(oBt6 zyr`}huXt7E4zFmE5jK+$5{e;5I!N;Dm-!|oY8=*Wx~!9bqTlsCr=Ic^`lI1!Y@~Ak zq57{AY*AN@hfE&V(v5)ifA!TgRhzcsK2!d2?ulQI@DnXhZZ%j{p z9hok;&>GAHZk`pFPc|qI_H7DV4s=|~t7kQFbd*tA*CuN4O)_vuD=?M1%)@gY227N5 z##dE({A;{bA8!00|AAFvdf6M}xJN=JmrVZNpl<525StaoV`zP>hp9gQlmUmzrdr;n zb>ry8Gc2cr$^Pi2tsT#u0pucJx{xtZUU2!P9vInEyYRXs7BPJ0C$ix0+1j`PCAhAb zjB^>0(zZ4q$#OfuYNRQFXFsFlOE!rb7N>52 zB7%c)GE1OiH1PY;W}+^t=Ushan;4`1j;T<^G-i`^^-{GNRbuJ4^-m03PwmEhoT$3& z&Coohu2?XCx!_5d>7?AZLy4XcBz^5jA-XE)fEl*f>6@^Pu$hvgG`zjez&H3Zc8--X8NK-Bs_NUb!$`D zJ@ejP4#`xj$NQN$p{S2ueB3@lXrj$fSK0NS{lyfWi(shVFcOc<|3C>Q+*z|t5>MOp zYgboNn>|%UX^S)i0x>r-TGp+Tf7&f5KMu9TbdiolK8!ul4&y?GiGzj-J8c>0 z2AzOQ!<1{8*AP#Msau7W|Kcazj_H+B{h#5Q&Bat-YKY^BniIdO<) z$tPy>gZz(bfCYbX!Ub2vwqD{i9;Ol1FHJ6El$q)5Y|aK zRdaXqm^p~dYVUrCztz4B`6N|{%SpI{9#4Am6CWQ-f$OJ!v_C&(dHIcpWzEa?EWr?o z_1v^$^o**4ocZqg3Ck1Dteba%a8X=-(x&<3_+_c3%iEuPYvxn?c70y3St$7J^KF85 znEJ5|cLHxX&gFZ+HS@l@z{nMNpAY7_aRcv@blk$;lyt3J=FtAUd1qfe3>mD6nw7>b z)l~Os(~!Gc2c?Jh`o=Lv=xnY<2r9gK@q@iNc5$=^MwD>oz(kRL@+MrZuq!OiOB)#| zwX#z^$A}neEgwQ&^lF`)c0DIqL|dhCA)QT0V|od8%F|VU1Q)IggRVxXN@=>qZ+me- z{$GG8Ny-%g5#Q-k_iX<$+JYmrGj(l=qFN}s7-A9h+^6lbp|_eQp? zjWSm0UtUJKD+u4&KUTKWq?{51>nYI91M6)54MKEV`o#!qpAakdod^Nnt!RaR^U>;S(9__#Le2% zn|x8)+xn9fIUGZ`wZ+I|^TU@pKMxNdIL3Q260{+2!XhFrHK-0X9IrC$v!oI}vS>rF zSk2z-54K4L1iI%w>5hlUzEQQs=cET~83LG=K#6LVepi5#k07-)a8~7tmnG`ek(6%#POzXU+#d9I;$twILQbs^ySS9;sjurtn}SLFsF?g4N)RM|F3{ z&nbi2lmuc;l)nm#d)9{#oyR(CIARHOx3(Ou5p*5f$m6>=xz=e@zgb$)liC zPA(G*U5gwvPqYGCSDp>dn=LHsm%?DJ9scRi1hkbUZux~#^dhkgs69>&4ogTC($Z?0 zu0w$OcU3SW|A3j3b6wt^t5uM|KhCF#%(L$a&3&YkL!p*0rbV?AD1Cj74kR0 zT~@1mw!Xd|@{5_1)*&?MKf~?zi79}U;VN_`*PeIyW?0|)2cxh)+8v(WT`n(YzFS^V z5i8n`;ZiksuH4Of$2Ff$YDTzn<^Z|>u-w$bj&u#7T*xye9e9>6didTV*SdD3>s9c9I`~lr2f-J=-%Y z;x@MKE|L4f?CuKFc_L=&zCEyKa$V<}`!J*gHuQp)dOsfDJx>LW@$ZqCM=EW$yKo+% z(KOKpv-4ZKoXHbHrw7hveo58JHRpN$39XpXMnKZ^l2$WeTKmGfY?l&os-= zlvUTMf4Al|D2hm5hq^AMwkK2n=3}Jz%Qa%h`p8HX!y3$dG^@k!T9^fQ%xt4pF#AGg zqFu#aN7!lAm^nh^jojPe+s`8&z#$R!tI`BM-PuPr?-ga(>pk%~9Y=J>S@;)jLg|U) zNO}dPgM~Zd{P=M}&dYZvdhF7qY7}RN zq|&;;C9!P6fmqarFEd|?p0<=8PW8^Zf5^8berv{2^ixNFinq+sS(HZ|$^OKpjAx1c z5~cy9rP-k*z5WLh0(=8k-o&_0cAR*wd6p33lYFMQlX~UFQqtDc>$Odnq2D=^cRo^m zr?2H8C-VhPB57GIM$~Q`h7Sl{DRE9wk!KV32;<9>k*!tpA0=-XD7;~mx^&u1=DwY_ zTa~?9Qbn<-hvR`Mso7hF&6jHvE0){V%?%kB?gTJO&3yp%c6YWDD(fpDE@dn(PaH*4iNFSp`JZBxahK?vPx4?Vkx|41x);k6AHY%|dJ=m+PWvY5zz5qcK) zb6!z8$E2kj&gJb>a2g5f>G;TJcq!|kCf9`54b$HSf@|vdN{MEy!P2~{DrU(Yw@RKf zyBBPI+6h=Z&^6CI38K~gM5cq#OG_cmER0vMS zAUkMovMnRr6LKzxZPK2##tbfjh5j?kdj)FzE863ADw|Pv%{!mYd_GwMiOc*44?yJl z;^D}|k7K?NJfhYT%Cygn8xIi%At{(7d~~>yiwxe?<569rVqEKj;I|@FU;DiDl@^V? zlVTFXarD~+g>fW!iAmQ4F!xIyR|OHbszF|J^s4)rw>S^h!r5=tqTT6Y!H{7o_dh!b zgjiqsj}+F)D|+@H*|9&SACW(?rQ?_C>JC%8ODub_v~K*22R>^N=qZxUmOKk5Xp7S6 zLBQ3kllk?-OpQpZpcOr2W1>bb8xMYej9Di2NsAS^d;KH2FE7e`djIyy;cAKvsF5Y68Cv6QTj$6?i@c7`szr}2 zXa4(#7s;3E)#`AXoQrWL;+;l5{>X3bcAh1phhoV~0E!m_3lR}ZKu<4;fvp%%Zef=&#<>@W3JU{xKifn-ra`+$R$4-ju3=yYC1T(TcVy76o~GB z(Dx(#UH;zemx{PDu4<3?HnB;|ORl4%=upu;QXg{StQNi!!Z}0J{GXKH7ZvnWdNxyjoC^3G4&Ie8*TME*mRX>^>0;58$s5=O!ar{vv$f;#jJ!~5J*6eoUe4Ns`H6v4@ zE3WKqJ{w6%S<6~#NGKRj0ImRd1D7`av(0?4n&-#4lLPkg0~THtT04Db`WNp+Lc&v? z&WYn0*9ZWJ@7Qot_nZU!<|kKnJt2YB3d#@lC`lOoFn@PvabW*c6<_MlWB^fwzm2-KXwd%{ui;GrRPg(iN@GZB0DJwzfewr^NQ(N%X(z zZ^7BZf$l$a;C3M;P>65eqld-{s5hUm_=H&YsIn=7oU*9XACi!Hnas zklv@s&d;Z44ZW97?Tc^Ot>E%ke>XpRm{6vx_PMd8WdA$vj1%wsli#2Qy4d(D#K}`R3AiChmZ537vI$!##dH+)>q(qV($Bb&sxPiadal zbZ$n09Q0v3I8k_9D)R4@oV4nC;4UlJ!7wu9oF`QPV>39sq6gH`Fax~2jNPx0s~f)k z)>H91Mj>aO8|oW5 zgy0tCS>IeW^qQe=F;yq~Ox!6m?uP$N2|q&sH#iHM9}n8g43L;D?wFxhSz7w8u8{(m zd}Ae86ouE`#pGcIvJ>svd?sez3FIAc)FmYG>s<{Rdl&fTvMXR$rSFC>32C5gPx>`q zMjZy5=UjH zinhwBx^*+;yijFzJ!$wt{GQ;eG^WRjOg$Iem6=oPb_fB1jXjuCTig6u1A2X{nnO3a zYvHFW=rr`_8NP`KYj+=x5~<&97;J_mw-@XKc%`Q<=7!eklNDMIo4b00b`n`(L6nD- z?Cz}E)-!)jIx9;a1c5!a!)@6{%O?ao>wp)xIBAC`gRI{f0BTD#W3lV5qAA|BmGN$f zd6ZNW3XmlDv&Z~qU&ww1BzV%@F zshaW3xR3$NF+Rdgc~2Q|4rls*94^Z~FqQ81K0EvR{NkPNOoAP2fThFxx1U7CL`7qc z9WOLNy*162+AC2L04iuPGil-5IaM%#+kWoByq%+CLEz5K#R+qRF||pXhGFz@3GyR5 z^K?cvBBJyOJ>EkmwMVxbzed-1UJieqwMRCSr1j&VKqbjx(EVPM!qD-0nAaW5S|^t` z9Dl!Lr!dEQOq%&Nj_l92b$#nJpO47+<~cX&%a#+Y@I%dW07blXHDBkQDv(CJ#r2UriQ3xd&9dKI zdPWF4BLsrQH@(lqwjzfWIS5Yv9*1d!Xk*dOET{VZBp@fDIYKj^*@3uLp4AiYe$20$ zRBbV1Zc)1L&A4lA_3k2-`)%Vg8II!aVZOOcGYVrtx2&u(sjxigR+fjn=fW`pw7Qi) zVP%#T*Tbb3Tbq!98*zmk>-|Lyef+Jr?yjCLx-aO!690W_!pWOLPH(N4hW&!mz<+%^ zihn_CPJmy=+7K+!lGfGCzN94mvCkg2icpoc|B|$DV5=Pex1oyLU(au{0ka?L0Eze# zYgWEjUH2hH`f%sq?PC2dBQ?S9I0&Ksd{=}^wfXauX{4Nq;^;-)DT0fR=Oy3=D!`tM>t&E*iljG8T?V%@ReIIcj5wQrC2>OTPH%C8VH&YKs= z7Bx6quyo*q9Bbm70!UkfX=H)i4xl2pYQ>)H_hXWFn##&+?6YL;SkHU+1&@8B68gg! zL;B{tn?0{GT6p(zaBtSWa9l+|R5b5%&nf?W9POtnm8tHF=00NWE>Vapexz*%(5K+Wk973>}-K<-;^mu!l8p3pZ05^NR0C%#e;X$VZ`|&ka z=nAVQ&nO+@=6>Y=O{l9AF=%1E6euhKTLnNoAH#;VrxIwCjWqhUGx6)(;=EAUeKr}!qpI-zuKF<7JW)y2?cj`)zYVKzdz1RK z$`d;&=aEvrHW)Bzg22IQ-m2unLZ)dJT>^{1Zn_FVK5M7Wd~!b$Bv7@3A#CeW+y0y}Y&jtfe?KRxTZj# z7cfyB6G_X>yP>cr0O}!yv5r=>gHD^*(6I}Qmo7b8;i8@_y?eBx^3&t}1-OMwjh{ba z-VQQp?V4QyuM%LwmSoCmt^U$c!9x8d$rE{*7ttU1G`q@gom$As>+LmL(sL=lba~!N zz7XgBn^q8H7kxF|gIHX@7BjRG!?U$TDIVJPV&F@mi8G@husEqm{N*CM!g)+;K+9&{ zgJruP;cr)Gp0(Q9|900@(DU%&*9$v@rT`wceC{^BUfb6)Br0|l7&Gl-)xFK zxuINIQ2T_H0l_L+j5bNhJyJ~a%x!#c;JvbceN0asr#Hub%rNWSO0>$2#`B;i}$>wXzQv$)?Q^{~XC?TnsF z(AB+}@*eirj}|Ki*0H|q+!8gR=W*_JjQ+qQ=8}C!khO}5E#&U_wyC4nc}TXqv~#1W z6E(Ll*LhiW|MCf(sUhoB65V8MW3%hWHIN->=ND8VTGcV?uc)G^Q8qTVN_xsiHn=)A z;;uW8R0Qq8z4{8rzuc>9Ve)gi)4DD zx2v!JaYo+JvDx6I=rL7a{|eUG6t%6>64~`Q>cQ8C$@&4%5w{r6H8X0)MfPejAg3H^ zK~GwwD5I2LW$DR{7K09M3Qe;|<(Zw@&aO)nr&k-{Kkbgt(5aJF>5$_5KM;uD3CPt0 z9SrV6&Bzl_{x!z>ABA(}3?SUooGeW)&mYKM>y~2>4?*j20N#s?ASx- z3%nfPZCvA)!!LS}mtlC<)(=f>s({Z3^>rBz3iWmOhKhTYw2tMf%7 zy-a56KOJ^2w{g_dm=@!skmKZH!QQM5yO%EpdvoOlyljadB)9TjdOh^~yJWb^gnGd~ zH81~WKIDA7OL}R2dMoTUQ>VrVHMXw(BmP;Fujj>npZ$p7tlg0piO%{LC`|$XipsJg zMp2!D&((32wtFaPe}mFZj(-o=5M6v*NM~Q6FKt+n+f`ITc&f7-eUthP`GWV`3s)-X zkiWIjm5y+823+dY;+7)sQlZ{f_nkGc_I?<|eN`Aa^&y$LVO_k9L#3GX;EBE2^|rZ8 ze$5=tt4q#xPv_?V*N+vd9}0JNZYKDn@~^iotf5w*3UJ_-A4iC&glizr-OTo2~zYEyuBP+hA*`J{y%;G?Bi#}>6>an1u0-7d?DNlb;$ zSL$P^wa1l?7(-s1YRQ6d$&v&--b2q?z3llLBzsaEYL!w4R(Jlmgr=RG>ZH|l65p;% zz`wY)+RAqEM2+a!--u)#Q&^33ztcTx5cz8hT%27uF}Jj|)D-}b7YhBqhvmU%T^jTd z#!lL~9@4s2c*@THJ7nV9; za1yclfHM}`NV#O;xix{6bI;nn9I=#a9)s+|G)Uz{^ z_LcwpLfqwiK{RXJx^+rY`~JWJ!(YbeK*Il*2&O{jol49vf5gB0vH)-l@&3VTFnRc% z?N5W5g^X@0p;e&dbyXJM%0s|3PQXN9`&H!vaN6`ctWW z{BTegY5>k*}3wEjQYZpg$*~%_l{V`&<_C39zCZ0Q2Ffa2DByU>#(8)u?{2lp;D0z9; zk;eGA`3HqAsX#@JYJ4x+b~e(z*=2dlS`{nk@ukfXgfL4N2hpwqRM);5jMCW-p8wNV zUmb$w5+xB0t)8#-@Ax(xM6VC__4S1+*g4DtZT9apol=<}A`!Zkkj0X)#C2Q%W0*0! z3=N!%gG1CRDmz1k&i!HPF`MqH5k$^9a$_R4{`Rh z>PLs*`oEBV%;4%lJ2#}o`t{i0cO?F`8^aemk*QM&x-4T((TJ>Y^H>kKdq8kWmcdz- z2${e#2)r;iZif9@EX*;?_CIBI7RG?S`Xx)x%#6Pkx1am_g#miw;JH;?PT5ed#XP*-_x@9DO#wm8@vXm{ZCzqA zX^@5XMhC@MAb_?9V-0vw&?;RHcHh#ZQS_ZNLhDCeSNCxSYq4CgW{UXsFfC*xd?K{M z&QpeMq+fm9ul7}Q^Z!HHdxk}sEz!aR1(jq#$xYA^6a*C{Cj~_XL@|I$5CK8Sk~2tB zL=X`WiAoNVlnmV{NtB$LjL_sJH97ZJFQ7AX?m73l-;Wu8In(dnyQ)^LT2(cdKAJQM zlRZYyad$fqqpHAA6ON)+eq9|Fo+9-1tq;q5(?0&l6+s=CwUX(CgSK1X{J*`NP8gOw zD^7yfV_4v(7!`olcnZxySfc?Gl!f*N0%HhjSD27>C6ttzrykmXLb;^JsSmB4-@&zk z8!?}WxChl%U)_2ZdM}deLlMR%-I8~$V~v-5UdvJByz5v>NSrhqdy%1YltJp}*T|uN z_O>8!ed$5{LeN?eAQwwxRbQO_ljm zetMxL@%{gO%bgCVUiE5 z^qv-9b#<1Mz!=92Nm3h5l@wWx9hCkl{=wf^DZC{F>89dG8%5s#+I#NB$b&q6sS9j5 zzQ2y;Bn8x48OO)kk;L0?l&?3Eyt)`nh)L7EIH4P4cbnPpAbT>_!o|P(yt3ptCBnWO zm%j7zx}+6_JlkX)^sxwOljs{6rN%B_?Wqzle7aug!O&7=Yq6ekEUfM>XQYpcDoZ)+ zepAA><-O|bne=5tKxK1;pzRUCXbS=2sLP`(@9kpLh%-k#ib|2g`Nw%}AW0I^_VGX9 z?aX{d#YJ&X*HV|2OuDHt2xc(@6Z+ks1~xuhLHiLs zmduCR|2e30D1Lbc+`W)72+9frU6KL92?maLk&zWm$h52?Xx8lHu?iW1fh_MT#vgm# z5rgq0KTp@Br>B4X60utp73dS_X@A{?Z|L%*r?@nje!gbFo?sR@3 zcmnwqrYo6;<5V~4u_;1)SI>XyyQieA9IyWY6ija7b&7Xmq46xMS5{&7p-SArnr6aNi~sNl``%b2n*jkKLL*fn z=+|L>j*Cb zNv!akpmdx198M%X_^ZPmCq5-6zKcp?GJ)x}H_X)OvR)(2#q7JgOhsxLCJGU9lV$}c z=?tew9?d^HRpAtC{xsGGpp8=gN4OK5W51uoP zAJBKZq@<7f#PaGo$Iqh_w~-~euto*e%vQ=LE+AfI4mf?l%%T%KVJE%gU_SCSReVE3 zqs98NMcp%4V$OGQ7`6l29}09={9tTi^0;Wew|d2Al8eHJlg3pRC0+Msw7snG-O#11 zkZ#BCWe+~$glZWwBQ)sgbl%=9+(!p;iQ8sLTofRE;?yckQ5-pxcG0WyDv7hRGuwhU z<4I3K&C%<26WET=2B4jIL!bL}b$*O5YC$d_VVp9l7j!T%^>%{6+SseIn^EcEklRzS ztbIpu`7KFYZv`bX9@?s(eXy& zr?XM9iJ^vcA@_3Px+6pfC|;j-dBV~4-{ZI)g|*YM+e5<>17VayUyXw{+gK2w$^3MKfzYwnXtw z6f~Wwy(m<0p}>ytkhhu2O6m=8Vt8JnKF*U;AUSfJq{6@J9K=U1Blq$67#VC{E&_F`ab#G<{Nbrzjn6}!mJPT zNJzSns+pM$JvJUSTWW;Dzhb`<~3o@NPF6u{3)k9M0kZYJIYN z!w&-|J;C6qZRF_eZ#48O-|F*XP^CFYLi{-zDre z*H@B)o=P(P$C|wvD<%WM$bp&~r6Nh{r1{?dn|Hp8PMOujx+N*Xh)rHIH6OheYrjw& z{3C^)w9;!>{%V1Z5yYgGSqXtOt!gXoHe6SW)q}G&G_Xed%9TE{FP)g+3vIL0ORm!7 zAK_dmjQDzGV=?dN(dmQbq1Ka^^&L+^XJhhv+1+)L`7!8-mID6!7}kvA-zA4+mG@VL z-RbAW+mCEiRhh|eq&&s^$SIjy9T^W^NJ~&4s;H9A8TREZ@Enyn3Wr_sREk4xC7)yx z&JN*pn_tVwNWAZOxwLBLGi9*8G5W1O-dcRSiTLlM`xDNAU5#{L`{x#gM3v|SN}kRS zjF`#gmm2%_7u+8jQ}~THNt=i6)>!$fzaM)>8r&;U9?Ir;7dm6FmRlX6gUp~J9!9)3 z>2vW_{gl1C7?s=XE*YqfG=*r7(C`OWSr{9qokd4rUi7A;#_>Kc2P<0MAyHlZeT9PU z;}9Pn>8>iifTTv=s*HFxVHSqFz4|SdZ=NxBY3iLKyY&m&P%9YW{H*>IQA6A23?vyWs1>V!zdlrCouu7huEuTZOV%aL%u6R+c<|r}8jr z4W>5L)I^9{kV&!sYIq=1^^sA9pcHOlPD*~V#P<5&q@wD}cZp5BOcgMGS1~q}zDV`} zKzi!8`T=GVY=*qRiKc!04lN!9Z_knI;dkwkT~MXGYcGGd>fU8L09Amdj=gwAMz5_c z1N$h(XET3nGU9HF`KqBfrMeU%)bO|h2}qPwQjDFPU;+j{A^%9W5C5rCe~oqZMMXq- zK3jgL?fB}5&W5~U97Ve}w8dT`J!$Y>Af_%Svk?$@#y33>v9)JB?7#6QZT+NE5iUvN z+62|?+VZECoV~1xY0=N0gtuO>v0Hz7@p#Pu?~(}Y0?m@-_(}fuWb=s-ygRIV5+o_t z_vELIQ&H9@QH+I>1$oIR)a3XedFxCS9xup{SVJOQ9!y{>P`+5&8rKp zH+17=;W0PKY>tJgpqGDu9vN_Qvm|-4k(0t{BpW_5i+V*#E+p#>0-p~bIQiLFSb}=j zW<3nj|5a3XX^CykP&%S=qptX!&*_-RC0cQEpb2NcH!&>C-t(>ca;Jd4lCzSan8m7% zBbX$To5Z6Ee7|;gM@XU{=;_JJ6^6_m8dGN8eHx8+$=@@S$WLd)molI`Bp<1BL45Is z)_u2)PpnvB2mYUW1o{9riQ|#`#^t-b+A}X^6Fz(;ua(jzV-hP+~-&TCFS6TeZNVu-uz2~4KXibVke({ZTNdG?CQnP#{CMU4(C=^W@l$%xh+(|k`qU{qCWaL zbNtM3Q{ryS3XLPHRCD+XUln=#8oidoqnKU3*fVt{ul>ht#2fCsw^Ka|iUp7!X)v4? zGi0E6u}WbJ3~SbIA`^da{nhlh(Ewl>&1@=HDD?LT)j91jrNk?pH1)1|F~d78h+26kIXog^!a?e>^Xh1<4UC2vi)AygZC!+lID(FEYWniaU*bLP=;tfJ1CZT@-vDR7W(YT`Pxh>yoYku z5^c~N7?E17ckupXzRktgKd{YWn_g)SF{L)y9BQab!?SV2OUq9W1sr^C(64Mztm2}% zfwkfrY1)umE>z(!@!X`6+E2~byYEmym2;#{>9x}h0ngdZlF7s`qI$5-F_6Z1Ii8PN zPJu1hR5$ie_DUQ)eZ;H*uV_FVt{gvQdn=%+yWXy3{cAY?#WTS9c<#TjhjZs&4~veH zf7yTGt=u{4hQP~lPkQ&Tj~z?PV2X)m_OrTnYb9Ur{;0LJb=`7MLP<%942>F;MP-0- zI(>To%Zha-x$|;z9*ThvFwk(P2(-03a(c}3lw^tw9id@gT>r^F+ z4L}XTJ|+_@tR^*>!ETxzlzr%HYvRMqi0&r@4kNMivI@24*DJ!_nK%- zBt=E{M7kJ;Td|+soF8kZF0*j%nPn`n`r--o^`joHH)PxFP`shs=P*^F;p;ZmAkg!@ zWA}hyDkaAc=Z+;rDK1H5WC+%Lk7ej}C8bC48%f zi2HvtHA)PTLGJ^a=mPzP`EMWGvh0p(9k!LhEwseDKE3OEp2G0=L2n&-7aLQI*Zz;J zDLQVwFnFjiiXt!Sym$u()as=&{1_O`CRn9V0nJM{>A`IY3JMOfh8o*CJD8qu(95o* zZcyjRMdjw0ZWfq3@z--*G`7Yw@yU=swVz%;`skEF8?I9;`PPpsOs{o_n;Y%)Gnw87 zrGGtVhb5WEd5=A?e>!Hz{!{5E^UDgSNS#Y4XG6p1OtX$!lX_+L>z$UW?={5TzA4+N z+Hiq-k*Pgsd`!4nxSHoK zO(yvylElp3L_{n`=(H4I$H}KhnZlz2VlxU!3pSvH8H6TjwU^I>eRK8rF@%mH&b=D zjBwDFZps#S*h`3uN4%}HVPa*qQe~dkt{dF9AJ-!EU8zSvGV|%vG#>k?Tb4|nN_ofj zoBgE{uj(#obAzmK^36hi_n_mM#{!EZkB@Kmc@7f37cNkvO(_gnxNBp>l#Y`VY{W^~ zeojtKcI$oaf3#2s9TpF7mP+792ykrfhhBIFo!vFSMQ>|K-cWqvlpC=jccfj-0eFou8%)wXSXeT;OdI0@W`yf*3}6} z9#O9YL82w^H__WE!R&-AA)~wL+GdX*KQ=MR!I2H>%)%f(OhozYgAV?yj*dmqeHb1W z$;{Qgqn_cQk2~P6aBZ&c-q1`>fXMo~sKPI-+{xgFoUx6D;!esUX7Nno=eYtiZO9_V zheWjbsG8f_jz|maM|158G^B&oFmv1;`tFGd348&X^nS#Gm~-P&Rsh`4w#~BkYAl)62hJ{X{+UCqxzKi z*9yL4^JJ+2H6tr)4ek{!J9ajIf!cnYbj0iP9G$PSpMrq7s<%c}kD;a@;`Ft}*F;El zEuyd++{A%}c&c_hB_X{uAuZ#Tr3~(`|G2xz7u$Dt`<$%D!xGx2EBXs=q|9$a3`RzQ z{f99?hDJt;U4yLZlX(1`l;x$Y6(gk#6LKM*Oq8EVO8D(`(6Hv@wB9k<*DG6GAWUO* z$dqgN$~neTNu4S!4vhU@&XHWR>d9mr9Iq+MAD+ou(W((J9W`fZI)2f3 zw`mVmW&Zj24|%kH)R^L@fq(y)7&hKUrR{qR39Jl-SbsknGCW3%3`?T8o49nmmj^i2kfm-bEyky@XeWQy%{on>e z+Wq>wU8nqCM%}*bQtEqgg(`zG;$FLB?MM^~_UtT-U7w+woVpo1_FL;$A*B z5JAPX4~hX}ajL5$=;o!;09UrL2=J@EwMQc_b0=V7*BO;cgun+>w}ba&YC!yn2FtyS z(N(D;umM6^I!fty3ps}}TKLdxgOCCS=K(C~LN)_i!5 z^>T;$zsZbLf23-M3c0!wI*36x*spRBt@Wawj=L*V->i2jvVL-Aa-7Juf0wQe0CjCd~!z+GadkW6DV99nt9BKBgb#&M#-t3Kk2M)6)@=Xm>1? zoSMsw!&QNj`KHuLEuy(iNNo4FS{d_hOOFS+?l*QkzcBL-fH^~MCB%HH1OMPM_u)n{ za;y38dSUi%R$P(SqoeMplrY8cs>?LR9~zSv54;w4Xsmqu>a>&=C=vT82~{+Jdq&=NQK#l4dPlSgDpdJn5JFlFlqB8+x6t$sNAtGI!Gp z_#-XVRRuZIn5A*^QuT4V6&jN2fFN zIuE~6WO$TbnDOv&+eQ=w-ktxVv9gqO(R{N=BC#s8x8ijE$f%>5Oo2(+QHDKgUfZwr z;nA%J{o?~OphL&Sw~G^3Rw>3{>5095ajBgg4ATZuHiR0018@ZKL&;MA28wX%JBKeX zUY+rih3 zpe&_TbYxl;jsV>%At52Xy}fCKJ+NFeUtrhb4`w=>w=R!u&NPWNwj9nl10FF2g}k7h z6S~Z8KTqzw7k(U%r;PJlmRpG^kvEi5JoTvk78snbQ|Tu4mEXG5{Yxe%Hk@C8iIu^dVy6f9Jo8H-Sp*Bt>P)rE+>Fg$%9li(;xuZ#ei|2YXqWeOz8w>k-@WrAQ{YD~3m)f+ymg0; zG3NYZ`zNZf1HwXUcx}pZyo3PhnyDo%1qH?IVBcN`6NobI3t+8V?|JKwH@8Cp_mPP? znw)(gz&{9Y+5y*HzZAXxk|i~-TW9-d)fv{_m)knouENXMoFvGXHCC_0pIfqAz+g$Y z-&fG7c%q5fdN|u5_TE+UD%D>BsXI9F#)+-(dLsDsmrTk2_gfCU_H8RS zsEeK#*`-wJRXl4KBT@%$1agI5wgkJa|L1zU?J<70`c3l@mPuTFu|>6WRj1#y^^QU4 zDUK=BC2nT;@M{p~g{P&+V^eZ&nOt-#_4XoRn7xkfC z@?3IWUS4w*B%Gsh)Xya?hpF?P0rYJSG|z#e_UrsoZWM9RZh)I8Sv#$E$-S?N zdgtihw-5=FKZ#2WRi}O5lrr+}ppK#6IsGFy|4Xs@(z;|#S1wxBk+4afz557t-O)i& zkxID+Si$~fZ*L0Ii>WrM%)?oqz>T0$bvL_K=et!WYe_V}t_Je|ZH;JtK#^W^Q&rV& z)%i1OrQ{`zQwGPh^PS7s(zXv>W4X`2$-CqnJZY@CRrZsdL3|*%ow>ow(c~kHNN2KS%Ir90N9)Wc)PO^s@Tl7#j048-`hVind zWKf^FR_pd1l)QK*%+g-^bao)_#Eb&DF1|ze-4*;6-0}$#(RMj-2 zNtq#2&Ph?JKXoxcsSWmjQ&qHi{L^i$!18b}9$&965hMvC&9msw81<67Z7xH+;#&5D zT}|@^RoTKKHF4;WSr}<&)kP}Ka{uy67m5>=9gOJ2r8QT|7@|ap;5s&!QXgUhu7n~V zp*J!*r-(iMy3Tn%%s$2>bLiR5V}I+nlLnlX)$a2%P?Z-aY`bi>)TO1R=5p3omz;Z| zHw!*}shR3V{*sA)Lvi-oVCzfC8*9p<;}D@bzH9gW~#`U+f- z3>{EEovHXAVrp$<<{RDkF@|B&%{&>0HPzp?dAc)X0{LeX^bsswe)=BFf@;@>{! zEC6**d9hpd;5S@D7jQUGi|POW&MNe z*=t(CAKIsNuU{)!pLJg?Gb zFkCv;%i^!)+0+z$4{hJYRq)^^kO6bc9$KC6@`Sf$Md)HKug|nhpPZGN6v37Z6$#DN z?>EZ|W%@qT&Fh^VyU?s2m76PEDI_AYCSK+j8H0tPS@f!O(tn3Ku1L=<%X(GC?TR|h zZsvsr7psOYR>$TprLy-)+np@PlV~)b=b94LVt#j5y|8Vr>!-RuD$ID?cN!mdjnCOT z@N3^os;zItp`y)TBZA9p#}8MF8Ifu2yC>Hj8LCsbD|?*>zEUa^;RbDnX7x=^o}~Nj zMFzwvTIteV9Y*TddS8>VxHNlY?HD2bt8F7>F?H+BF;Y8ru>Uh>Y^lK&Z!6Uk8_oLW?0{cggjvKAR>=mlQX*8r*%_6Dm;i>=3SSbD( zHOY{u`L+_g2u6Hk`1gb&1IQr z%bmDzb&EI!tX@OH_Ue+NW60pq$XoIw)D4YCgY<_iRUFc0y+qi!!UA@3Ub5)C_&nO7HXv1y(^1xVx-51B% zZ);TU7PzK~fxd-w6B9pW&RLm_;UAN&Ih@a!mg{!I=U*{SD{G*fIrrGwdI4I5lr^WN z<|_XZxpQQ(1m7xGZzD5TBdDybD<_wLv0OBsNM_HGUT^qn=7Re%^z(XpoNC|3DmI2= zd7#VeepKGINQWtcvkY-_X~;bUiMZ!t+1am5I`nH&XEHu2LygYA=G%$v6`Tl_^P8;~ zuaD|>p!hdmFE5^~Bb775c~9*XQ;cE~<=8)5b6YC{H&_RvwN}<$H$_MVo-Sy+t`6&p z+%YRSJ5*XI*w8 zsRE}t;j`+wR;I5GUwGbGUMb?3?Jl5*A#O}#X3AHn1l4+E!;VY3930O;IUEs4t5Z@& z&LH?_r~rCnQDt$;IU#v$u-@g-C4*8s9%lix+xHPvpO5CuYQMI0v5-u_r&(D=N-$wn zmetlF*dS#-6&s#6>fUCOylpujop$_#Hw4}&sdy>HH|X=?u=-SsN#JxZ7+#PD0%RaD zg@eetZY=dL?5mAn-?R2hxWVB%@{RbJ-2V0ly*{a)W{;cW>!(@z+8+zLHLZ-ZJn}xHZ z<;jGc75Se0*PQtLGf&6H^NRR|Sxed(!#leo?T)(iRPH0nf)f;M&-C8S93!?dmoe~? zIAYMtzwW5k_fkNzxy9yWG-WznAHEkKuAciMntd{gHL~DdOTPR4H?Dno z!x0ITg&XVZleZ0&`rVr-Tk^rU4~Qm^f>KOVv&4CA(IDD+Q6<(=+tu_-5@9a#vq7}o z%-6msv6~MhW6)pn+m{BY;DLu^Oc_Mki)V9N^k2xbk5fd_tnAi#@7N#{Gqfwd?NoQz z!|x?9ynRY(C%g^qfXLf$EXb|?=3o^HtqwLAbpd)wql^ui2iWV&vEMA5tgs(nt(To- z_nJE@{F`_+a{w7ViY`;}2H}r=pSX&=>3vPYmR!GX^u}OEh;x{+67dQD_vCntlS1OA zmHxttr5ZRoX5E|lpG3C|yXHeol7+6$Sf{I`AfyK!=JOA4s;yUJgMNyb9mTNmI_uG} zU3hL1@aplR61jHJjQ(Ejuqc_e%`yRK_3BI4Ks&{tO@{~c(wDV2*GJ$a+M+v|R_`ZX zV_P2cjNkFS>&Eo-G-evT*4fpS1uFjD&Q9OkO>J!< zO2?UGL_~aU=k=r40PYPC?9$hhZ;eA25WkQz%m6MemF4KArGY}@J~1Y0JHyJO_kT6K zkmthMe~18n6zZM);xsmpOz*9VmUd>oe;`1gzJBqUG>jM8&GYCx1s~lU(AvA?V;kM3 z5SnlcXlx;jB);VO5cIj(TcsHqU$?k;LUnYXddZM~C^^1(QQB2^=vT7dO||0w(TdT) z>QIVDM?%sI+&Pr{aTH_DBjkf$sl=8Rl&Toa;sXl2wMjTV+tKZ!-n$(W2ptB|I=9M2 zc#1_)N2Fb}oYp4WeAs^+mLYzn3~(O$2~l^xC&RV&%HvEd9dTCYr7Oe~aw#eG@4*V& z;9L(dv$N%De`pow!_11;isVAX2LISI3_GFaqwKanZ8s;MhdH`jfzKV!zWp#`a0Q&x z+s%UMd8rwkwt_fF$Gx}F+gJ`XjC?yZ0zoD(N~dcK2#2M3%?fgIa--osN7(QoH#0M1 z?(AF=boRl`J9J;Bk5y_l8ovGMre*L_V6XuO(!j!48&wM9ALH(qqRho!LED_HBvnIa zr?{x-cSbU{l>#NBe4QaW<8zUz-oMkNt(5uUQ9FEWpR@JoGQrB~nHa9x(TvV?I>C^E9pA)O8&u0(Gv)`XESSj%y%JiH0s zuGnF;gEv&bbqTNidD)|Hz0xvZx{PekpvaCB&drDYW>xI2eqWD>Br@8;?y54gcfxW6hR|z%E(s#v2rkLhid1f2zU>-n@^r zpkOm-P;!^km3wP;%OiV@RFfAMZBD}GiV&X_96?k>Cxbx9IiZ@=#b2Wmxv47wTub5y zfK4+WkQNBs@t`ZjhD{55!-SNKjHQw~Q7&uH&FG6iAgvL6)e2sxoQ|6M0dIi+Cu-r> z?sIY;{rx(LA@_(oRA4m%CXHE3)O^^N7y2laYT`>!4kO&tF2$Rt-0)w*OkeJvA40zv zf=kdfKG`G&3B%xMO>3#>ubXN95^pgw1c^D>yy$35$@rr&-7`%Uji{zzup80jOrxEhQA!cvi3{)KbhG}z_&#s)JQyAs#>x@u4SdN+a4i(7buhkBbCg3`UeJlAcFRYrt{mR9_P-2MA3^J%?? zG8oR^e&-#+%dpgbn`9A4Sj8Z&r@43vKSx~YlNVqGzR`3jAeCQDE3Isntz@}5xOJpn zv!g3AW^Lt{5us&0n`QS&ktjZXZJGJhr9c_b86@*=4&tka!t*Swc&`*{Fkb-+q4w7- zMH&8*Xqt8lx8&;}uXe9AuZ#RoNH?AU7N*)S!|}Of+EMNG)$K5||`TrTRn- z88`T0mKVFgW~A9V=GxWJ>*XGFS_Mu_t4-_ch@;|ZH;PHDn)Qp6SW>!qXfc@bULn}J zu|y<=As?*U3!*R#CuKG_ALjY3Tk-lA{c?9HEbx9kN2KvQ^;1c7cnpIph|d&3`+6ID<60?F=fm;PRgIWXaViaOts=imlM8$P7L#`YMGw5`I& zRv5T|lwMMhB&#SrV(ok}0=8ybKVayTXq}1G7`NxxyejPrHBj*|&HI+w`(%1f?j=v~ZAmj$`#3Plkyr zbGBK&`qTxCcF^x+;W{2rt+A89KEJS2rU3ngqwuYX&&S4CK7^Bs$E?ALT)D9t-%)XS zL>@vO2v}m097wwEi5xN)?bWC=l_KYYtsVu{uoBta{4^gK%GSwAGV`2@%iJZ26Et%$ z63IMhx&+0{{83a=Qt7~H)U9r|&t^?1x`z3ei8F_K{r!fKu zVD4hWr)ZGGevY2Nhb6471jZiX7N`k1Elr;qa6A-AX+`+{4g<#sR43q(ld)tk%OYVw zL{^0OaMn?3dWfC7-pZCODZ>$Rl_G6oCuFp|XH#y0YVkQ4p{)HjO2 z$zL!w(h#VfzsVOfx2Vh~VqL+adlT{sg(7YRgY;|+gM{?k7;tXuOU@SEpBu<~TwFF6 zQv}m8Uyprza_hhaV{+rn0dgAV7+CPQ0H3K_4ihr51w) zWHv`!7vZUaGq60f5nAT=Z z<{Y_@kG^vd{WjA_@3qaFY-t#x|GL5*+)56?`yOhn>5A;%VudySLD^!HeIsXN2+PYD zztcye+2?phs;5IiCpGJsQAW7_x^MA9+?f4vSgs@hzdeSgroxd$%l6-fkmPeK!MJh< zvFcobHn|ml)3vc5&_`5i1&Vs35|Rj{Z)3EHqd217Bj&tQJhFd)bgc26 zI;-S!nR_^M#f4P~?v>-?C(*|nNnqFSImn`>hM4KWvou!8U|`P_0+a^Q z`yqwKvpZ|lEz4eQcI;azm2B9_pNBNd1d5?hf7iJ9#}l_oEH`tENjFu1j~Qy(W#!jb z4cwrB>!u|`jKj8dnXpmF`G7;7Wn%~hp7K!GV zetB^6AT5Jh;Jp#PcH5xXC z1L^O^j6JFu52iyX(xEl*bW&hj;Jp=IcG|-lRW)) z59|#cDh)KwhUu+`bwmIt_gT zN-sZh>EKoi;;b!5%TvR8GlWD;L#%rKiGq^H?FJr}|1Lj!3moz{T>rqg zZ?Iey*cdu~&1a@ldJhRL(T+}i4b?$t|DkC3a0EwE0gFdDj<2kXbX>0|PJEh=-nUe; zOqNSAaA47@d?Qa*8=+#hYDN1T9#9y3|ev3pnnR-KtRkmK{V%tz72TajqrV zXn7E4`SC~9UtNmqOiW{wlP0jFnP6yQVy(Dzf$b~*#rIAAMV}U0zWEqxo_plR{{fX- ziHig|d=rG~;_NV4nWQ^JSAVFWp=>XRmx!zG9@s?t> zdXYFk5$n28*YWw028ADzO$96i$%h3b(k|Z6Oumt4P{*+eq!>8y`dSIH61hBEjB*T4~VY3HX-9s@}c&2yk61mdruY;O) zS@9KHF7o+jf5}%j7TY3Z1FxmTU{1e&i)hLaL%wnTf5J40I{_6B>+01Hf@r(-MB@GW zOlyRf{i6)|zS#PhtgbU^ZEdZiv&{Y*zuvcX4-XIELP#rNGYOpD03n~MmX+B-6jOU_ zvQ3cVY`_xpG!QBMa=84vBSwkjMd|5v$sOZ9?JKKaIn;`ON8BCkW}zWdGcV5<G>ddc)%_DMsOa8^8H;lF~adq!k!G=a6In)USkx z$3_OiOUlX13-I%UcJ0H#2Hf}@6E}+8Z62JF??7-@b@qXMj~xgwSbJowI0@2st&a_= z!$95sIO>Z-q`xtnJA!HT)97Z|*yjEuy@sL=2l6N=wO?xAMc)_}B}qvT;L|i(8&Tx3 z|EFui6;H4>8>Hzd?8#a&7bSCw32Y^q3@~Gz@=IHV`UPDJwpJs8m5tFZA-OvF@%r+I zAa3@xAEE5TIT`%)M9q6jS+S)~qdjGKBr9%du&{V*TNg!x-$C5f38O&6-TO@}{E_o? z0(x!ve2gRV)^$Xc<{SWu+}DZ6t;4mCKxMOQBC}$+qx!d6^k`&DR9$t7`{pIG9s2Pt zBJnB@sSuATsqa%4vpd<*ayS4LR_^>2JQ02IVs+mx6f6P*| zOvVB@MtRXA?&}nzrOU&I8mhd#fkPSnwCTd5J5slsx}kIclAw+CwLbRIvAv@j=VBrp zCv$KzE7g$RTdOk5^insF_Uv$sajOV1v}G~Re{gNps>-}sVr(Zn55JJ_4*EdtC8NmI zbR~Yi-Z^pFot-G&B-Y<1NFSbfd;viiF;}R&FOlJP zFdn4%F~|qEl{>IAl#Wht1E3spaTy#fucrDuQ4v$RX==RNd9bO~%vQ6!#PV;q(X!<> z?wWIu;hAH;7UFsVM^1z#B!nfO7>5*2rlSZupll$SD~%*8gkK)QIiH96PmWDbNG{i! zt=D2U=R^W*AwA7Lb&CINuZZm5+5eSbq{h6R)CFJMiTX7p$_9+lG)(RWm%OdAKWx!^ zVSIvgNm3c`CZrV(@^Bja*tu9bIy%ez=UY;Fe4G2R!EhJ~qJa5L$fu z%g2H2VUVuusoGW##05P;^aI<7=j6-n%&hgatO8eHij?ClNVZnrlddLz1tK6gKruJp zlwwr3%K!FU{w12xWG}kLLMZfVUXZ#>nez!03+DNm9RrF#k818{N3Gyk+f~&QaS{## ziM*-x(M8!?)%pRTdm#P7I4#_>u0%NKqw`RxGa)+d9XSl8jF!W$vkQZ>wOyh{sqR+J zhV%z77?ZKOf~!k2a-&$ODnSq)faOea!E>zuNv0#DBpRCMf=V1+mqY0&jemrU0N?mz zbnr@IZ#WU$A@Ur++ayYhpFV9f#cIti)BF3`KlwkNJY)EZPuV={?dnog(1m$4 z;J%uw=ewIaWs1{JkqaI1{X{ty=e+=;cHNlLnEp7SzXp+HZ7Z!w+IsF^9U}g=?8h;u$99W=Ia!(J z79n9FJ%@pBUWikNj8oA|7Di_Nd>#?@-XRs!mmDSuG!c!}L@QLc(EheOJ@t}u2i{Hn z$yz-E;M89&D3<|4%F@* z0_aWV)zSrLcT0+7J73%WzS&XA)r0VevJPiXRql}ZkDXS`L>&m*^i5%Uc!K99I(Qol z0EHv*hr)3VczJ3Mr+n+L@8mmRU@tDJmfS=(xG&V={H zV42pqW_?^&PM1UFj$qPUL)R0n#5^bvV72w5gm1X&aGXFK*cN1Z_CJe~Hfg<0O&7?m z?%xlGp0U^P(&IZWeo5~PCw)(^MfZo8LaMbIg^wUVZnls*)r`$_qiq+->TWq~=BIp7 zoEs(KVlm)hG_~){3%$rOyL*h_UJ?Nlx=eD}A_ zC9bV(3j!uSc`X@bJ0liXSpYQ0N7UkW;ST?p2GaxxU#{Pfd=_N4{WzBD6zu}1m9g(p zP&f|a-K@p+z>8c2{C-o;zS7&9)@6<*G%=C9aEH{-wnkjuzat5ai0pJ{4)4Ji`P_0$ z+sd}9W6^8Z`p9KAt>Y}eeKOz?t`}~_5$w#~LwgR?9)3lpQY;J)KN@jEPop8a0_YC! z?dz*2Kdg?5eKg+*lZ-&4@K=imLZAQRqh*nguKl*k@H?(TN&~tZ#{f-9d!3Mt7M@IP zmM%5+0;>fO-dh;Fa*Wjw(N!FmOl9gET4E>kj#+h>>B9gPW~p^*Y7 z3ZC}u4sXrfTo;2vTvVOVmg{kQmQWuUUC7LXD!Q zS4Bm4HYAROJTapf-Pg8bwOg)|fP~>B>2xD~afTxexYgq!@B!c|E{~MQ_5?BXYA1Dy z{`$NH(Ot1?s3+vsNH{?l&GF8La%LP7Cm$aD#X-I-dlUoKAdNoI3 ze?Pp(bY}Zmj^24F|A9Ac0XJzsu#-0AK0^vJ+ioL!$8BuOTRT5<|7UY;^8!foMsD_= z21R1`jZ`}=;Fpe%Lr4^(x_9b-=y!go=M6}#cK*}Ib|N7Vk!u@od)nH?R)0%%tp2vL z%CyBM>*O<6_hfOJdy+cEWTkI^+&GYJn~-o$$KkQSTrd6-!4L+C^B{SGBuUlV9JLDx ze0C+)<8Q|hLPUVi6Zc!hm4N?mVSgIt#`G9mLh{kItcJj+Hqp!q#OyBB3bB?vzt_24 zAxW<|w|)|&NI$;y?;boW3(}XjVrbIwVRy8o6e2^gb0wB6X)W7=^b+HgKV889jzidk z6!#$l=!&SvPrmV1^L{$&-HCirs1g~CIXE0+jCkWE$8YT(6ZP@>yUB(QIOwUr54uL|B0dRHGG7oa`{ zB<_ENbpyBI&mU?Xj{n8>Zo3@NNQ5|mtCY|DjR}Aa* z+-;SGexV<}ywW&T-58cyvDn8JkGnJ4xAaM@V$9uCM#k0A+9d9w^K2v{uRI`{vK;{U zpRkgzECAL9vh7(=llr9A~PW|YelGiofr#-#R?tfN1((3xvzlk9v zeWOaS8Jr>H*HE+DQNfKjj|*!yGiQ754|bQ^_lx{h8igUX^2JxWF}s`}yKF+?=>2_+ z%LedV!0F$=fZB<^&^Iw(`}mKeKfK+_;`0PT#*O+nZdR)25t?vb3ZT-~-ytl#hjin@ z_*VsS!h*ZIJ2cclTMe0Y^uBQzt@y1UTu8**1W!q5T*_9q#yfx%{V;apd?{$3=|3(l zE^-|n!{d3y0s^d5oe`HSOpllUUy2mku!NaSMVt4%Yju>40iSNOjhk!NTR9Q#6#8Rl zcr~Ei+7q|;yO|qBg}-jaI0LNq0VtI@RxgD%1H8;fAO1&kGWvfwh(AhK3l;CP^qYJy zE^`Mr$t*>pDP7j_mq$E-bTmc*2s`tywuu%um~z<)ql~(`y88Oe{QD2iURQ`(YobrG zY)yLZ|M^#zxz@EG*KeV&$6PZofRe5|l(@2Atiq0qjL4uS`gaERHEc2X!w08t-eucp zyn5m4Pmoa5NM3quFRYeVd8onJ=J{47-DiP=->tDj1)@3B!GPCh7ZbOb{bqb_tthK! zfofV{eLB>f@oTQ_teRL8h;@_0MaE84M5BNwW~qrT#SvW17Y0&RH?81c+Kl- zg8y45A~6o7>N=Ux8)|BBQZGMwjc~SD+OzTwIr9OXKM!kGe^kruYrOGTl8aXJGSqIe z?>c})M^l13{=~8R-2AE5^)B+)3JR|CiWhuqEkW^r{IQXdTn?n9W;f}w`s`qK0JP;G zg`T74k=)JBnQqdp{{*sI`a0&(0B8W?-0v!9k`JN&0cci9jb+zMe~&Zw|_+WTld= zVPz+Kl`Z2)vR96MtYaSY{GJD`Pxt-(e!joI?!WH)*89BQuh(;2*W&^(af$l+LQd;k zd{jO(p54#sb9`yV_W2)hr#an1FnU*=+HALi*^=PE`^RBfMpOi(Q>eJ|<|&(Me%TE5 zd`8ywa{xu*HSnlH*UV>Sk_F87M&1^P#2er@G@OXO)B0k=$RbTOat|+rF@;8Gs{0D( zo)+bk#R;o<2!DF4#Qk$N0#a}UF~HXs2K|JEk^ujG@N%RT!$8k+qH*SOb?|V$`YuWs zFTIN)Jkux1`Slkx71+ZX;8}m>rD;=&5Dd6bRNk6!Ro`QZblm>)(8{u-kH=m^1EFV6CLzE0L@%kRjR z1h3$&AgQZSvf+KRjjyD=%7eq2dFy#(M7h8j0=pct3*SiECY`LU1=MW;VgQ$$3xa*o zKpgd)D=DfLt-5>akebRORpZ9X7X)sO74E=iFXCN_!rYwu=vqu^k8;rneE9HT?>_VE zS_W6I;%`Xsw99OnZm#dd@c*rRXjF`SfLJakZ-qv4xA3K3jkDVm?s1WZsG^ldX?uuZ zi^ZTr-aerIra$n#66xolht@Q$Ye0_E&P?>j3wEhtAzIU}XZi1sMb`awC-s~vF!ux`8 z;s6!HwZv!YDB1?aQqjv7TwPous`yt7TM)p|3EDoyH8>)|x&tH8d?qbDxM?5&^@cH= z%MI~)sx@;|Mis>oAW&h;%Sn?sG(Ypna(HOy@n^bw9-PJqqpX9&UWf!#x|t@b)i>Y2 z;+*0!D8 z)EH}+*UT}VjG>$VTPx8^->Dc27O3ZgEHG$B-+uIC5m|Za_O4=Uor|;qY4yFV)2Bj~ z2w&~OLjLNxaY_-ht*S?-@ad0%&*{I~h#Ro7Ur>8$b4^WL+no$7zjA9hEc(O2FM=0# z)|Ih+y6ZTV{qS}t**)4+AASCI@FHqy1tbO7pB%>KGpTFjj7Iw!p}^$_DnXE54i(3w zrc%@2m-oQI>8G(gJ)KTZksg)zh!hO}pw3*M9O-*>UKeOQNg@fp3p3O2`Q67M?iy4i z6|t}6S%-aZSzRL=8XXytBBGYhC@JAc0{Yo^tAk|#Fl?a?_MZ3VS9R3Th%3s=JzX8} z)WTRK>SY6e`htj$aIpKm(?*%DD~_w0N+fo!Yl)wBpAiq-@9H ze43cu*+ZmV0G9Aba!>g(!`MXap~cSewOv^Au?@|+wH3F^+L|=j1mS0%Nkj%A2CPR{ z^GS}5*dyiInq3vMpL=5Cs&r3{-ODMSd|=g|ul_v@LGAVVc;vi45TUiZ9>-POcvg~@7QjSAev~qg&y2 z5#5$$9rki*-mzsfHbMpVxyos0?-y5zP0Iyz(O@_L&FZJt{=}s_t(d00-xNJ;o?a|j z|5C+ERo7=nLErOpsF}-Pr`e>E*h2on%d4Pw-LA0!1ji&a$?_+;%NyJukZqQs{*vK> zlX9C%78B#OcyoncNB@sD=06Ipo8Owf*xyS_v9qR(?JT~CT_SqZSA`qKbP7`)EtdZp zu-N`tRMFE8b*|r|ovtkA95LbJRkNi#3kO@#P|Qap0bNl^&ewWZ1l8CW$hO_`4J za;xux7Zdg$n7&f{GCTBrgJ{lvVBep+2N9@%ijAjc5xOL($lKO zIsP(f6`V*&M74F?Nb`0H0jSh3hj;%6*oAU%{?cog zDP}cc8hg^BC<7kFLMX!poF-tk3T_^a;qXhbR%(qg)^Uou^DuBUktdwV23KR^Ux?<@ zG%!!}E{-20QLfNECE26lI(m9(4le5B#S?--vaAv=I1nGhFksLU6ZOUt7$k7GC|PKZ zALVT9t#7Hz(~JxY6=A?t#iBFe*S65mrj})AY_nXmxC@>}?t**~jOdg=B0(}X zgJG3J9R~Z|GFrQNYan6Iwj@!Y8l!rNruBkic>tVkgK0-!pKDx0!5v2dK0&OHk@sI)6`UvNzY`Nicd=0QY_L1pzyF8Y`>uQ3 zoBJs5Cm#h4L2axQ3A4I@D=$LHo1@IKx!u+;9CBly+_4kl*3&_6aUGyf!=k;g(I`lY zqUxoim}%{N(S(XPQ>M)KhFw({^>X+NX&hRaD6uY2R(#yDE*AE_N~iRWW&kEhTB^!2 zub`gya(7qFM?{S0k&5J~yJkivCa2lf#3K*Yt|r3y(YS_CD|(U~o&Q9y$EH#}<=iU+ z#vot>s`0(GGD={lOwt*66mRhQ@Wa!*aq?X~|>rTljlFo`0gO9sY*jF`6x#>XApnN6v8gyRs zE+nEc{_gJ7s-?u8uXZ<-k$EFPPwe5qYL5`$eNX?CstlzU{bZXWx9?S)?P9poe)fw7 z%09Xie&OQ>CwohJ`~9TY9~8vwBPd~g=ZmFj7MaCTwa&!7apiB5;r7iDIINUgz!rqV zQcm06!OAwsBNi>9O4HI%H#gV;r!^L!%w9ajmB3N7TA7c9(cA`qMZgW8j zm%j3971>Q^iI_!>{Ft|>qM!GRF&cTW2v15(OEt!5c(o2ox-E{YsgNBo+D*L|dIrMi z+7SJGa~)#${{Jx4^u-L_A-yn&#mBpR?7Xhv_{8+>PhouOYznIGWjMVFz=LL*;Z>-g z2&oMoZV?!0HEp>aA2;t_6{P>Ietq9`_WjkW3TOV%f#TC|$oo@D&@S>hnii8D4%%L! z1Wh8E)&rN$4t_iu`i4MxV#kMUJ7R6Gk)5ZeqOvsp_?5Lm?@slt=nZi!S8T>YALAZA zx8nl4-e)o3b8qSu4>x_LeaVO@S`;^6=5fmvS4G^qCDKy@zquYmlN4e{fwsr<_5hk3 za*m@Ovs5FhaSbF(P8k!8RRI^X1oqruYmiRpywQM89E@I6;$6r`J6+AVIZ(BtDwl5J zV`gU7Kp%Z$__iAUMGa4pI?BB|xyOD)h{tOsB#YrD^^WLcIxe{gO6m`aA00}B9)3gk z2$s!sQoN=Qy*)l(Ay)Q8euI}onruAHwl?^OexbK58aEhQtCE(t{z9jFeT1-+iyZ~2 z5!@o}|IlcmFSXyetW`E4SzNR-+0BbQbx%HZ2vfnRDd(ARM&uHdoT{y0re@i?JKpR4 zhXwY&nExWNBJD2Jje*krBcd&dXI638Ls`HREtfI|vj}7SrGjk06;?YHPd*)vn|A8F zmcJxu?KrcujwD8ZUerg^l`}b<&IT}rz;;lm4=h0lInPODJNniy3_D+`&#fuZpGL1~ zn)GNqjL>I(K=fjEm?F9x94v`^b?FGRZtG`|SG**8ig764alD_*#tJG8v-#OJp6?Dv zhl&>LGtlSea<0*|KB&-ZPZQPRdeJ!cDNd)--?9G-wQKj4*YFY*;3g!Ei`3BPS*o2h zWA;m+mabi#ald^|Y%arL*3F<^PpW2KnBvLsk&*~#6T(#_j0@Ej^=?GUa^l*VUrI{Q z(v*q{^d0v>!-xA|nw}HEBizn&b9lSI3gKrZKJ22IY^v>I4Fz&e(`)0G@Viol(3zwX zKBEfVwbEY-S#*J@85v=Tt5JO0YyE_)=GuT)I~?JSBt>ZkqQwp;T<2S+c?azVyX{-! zbf`t1CgGPq(P%h&CUA?Kch`U@S=UEUCt@WRlbHURJRWC?nP^u^HIQjaO570ekL!0QUnQ!AGi?bC z&^6b^%qZ7CAd02K7_DVKkUb5yawP!Muv{amaMcl*Gl8#)irB<=zzxY4?t59!XU9Oz zJE*E36Hx^9n#$@`0l6~fGhX;%P)KORpZB`6+3{ap}YHySs1ZPmCb+A@L@?lQ3H0NASP7U^?G2n+)|I)!xM3@73v0%FWV~fRFAa`o#vwWCeUKq?+dXU*)HN2d1G=u<^ z^^?h?&~85>ygl!;UX(9@@1p{wwSmdkEdZoYxV>W;|_Dh;+@s_Bq5n z!@UTc#xx68wRLfGP?wxxOh^lLUcvWafCwaG*KdF;@o3jT$k+Z^J;uXs$PxsD;rz`~ z^RceoDraIy3g))4wZ&d6TFR$ChOx|}h#h?A7KeF3$G6YHu zR$G^3s}1s=MJ>DNNe8HFX`v1+Kc{$HpE;T@Z<;>2mX(&~taT)^`5l31^5?4g9faLy zpq{=B{yeq~CJx++R2ZRX;|zc^tvJ4HX*)oGNqM*x*XZ-NayB-eF*b}rK1oS_Gl1{~ zNw_THl=^o#XvoOPtN35acLkv4)vvDi28x`bA#pcvtz|ZEuPj=6LUC{w75w-qfEHU; z-9?9;$@ZF3%Eey0{?N^C+x8&G8FcqSHNLM*caxLUqud*AbUtPl=7J^7xgyEU?&z~#~FNoYvSmVTNA*gHv2$+qY9@@=AC9^8~Ee8 z*7`zFD7|-iQ@6f@z@pi8xfKW_pPs|s6WkG!OHNixL#7%R3*tsk6uNpB_^|K16)3zm zU%{Iye~J4%)hC^8(;hN6Nj^w6ShSrox*;rV!Lzz@a^;=Ix~1?{_-)^KBD^pQ1|Ko& zk|*?x$Aoe&;P6MX;_;cGYhIbrRblc3P=L`jf>q?#BIeiDZw#3Cx0Wi|XB|?p3Ui zp^f=Hc4d6)`LEV%H?LQl%fgio-LwqlSi78IDR$&}osg(#m>^9~e~iM6UCmf%!!7os zuo&&~ZH+{ZfP+b@Fj5oe(wZ_11XuO9X~U0EvEheW5*I7s!Z4dJdcJ-E3@9a)Gpwzx zW%GS>63TlTq)$rlP4T14R6_Ho?jL@^Q8jpE@|?I^5mQ^ptoHYAIY(58lXkI=(k(Gc zjNORstg3zsoWCKNZJ5arPPf7f*K!;y##`_0sWw*{=7E7M14r&0k{#c)lCQ<7#nq)B zWw`4u33V0SSEeUL#G)$P;iH(LoXg5M#3WEeefAq85;ka97+tnczbzvp18~K<;V5PxiBZciV~c5n}!FbTdxrwE$u^Xy11lpJYkC-gVLfgIsV}+Y}+^_TtxV$c&E{>*~w-l zgN%<93(X--Db-*o~`-prr0b-Ng%E?Hq)`BzW3qSd>O; z%#4l8jtju?LEb+xenlAVaFRh94EXN4vu92{9e9L_?R2SGfA*0<5nXVmHgR}y{g&S= z?czzg#-NSsQ&9Mh$T!sepXW6dA@k(avV3}3o|ZYSJ?apa~sG{3y$) z*;un4wfGlbs7dk#)8SV?KqC5mvwkZ{91fuQkmG=8xY4VuFf;I-2Vh)$#c$p`P>&pg zP9?Ccb?r0OHr0wwH$ibh%tNOz7C8gF@5o1rn#o8%gR!fR_|A8u%(gPEBuINOPR;gpq?XSFk9?Ylb> zVLNlKk|TN|sk8gi0XMXP*7GvQ>g>jeXV{b;Ii?NE*U{u__`6hm5*EEXXFwBZbOl5@ z8``@aSAQtCz+d_0o( ziJ>HcLDs|XE|LqK0qsWI#d&$5;V$B><`=fFd+W1*wZ$*E8+a_bvjDS^(G-j#jr8~u`o*|T8I&~Q~_p^|jMW68HB=YO;gPUS5SVoYq^L&3H zS2~zcc}74$S{&;1D)LJriiQ(>$(dH~ht6Jwl*xn@FH#Rgm*+k$XvH!))zB%4(iAzu z80CbcTzBBln<-aE;+v$a=6B{W451`>Ea~iDH6Remx>&n7(w+7+d%yK(-e#=jU^lN{ zq}`WuIk#9s{VYKSrIAY=I7+N4RWcH;YBu&*xH1kbM{aAri#&xTAI zRpZc^^0vKHg=U5L8)pKmR2T7WzbIWMTLn9S$pwF^IGEG z`So?=tZu*fba+A@cZRQ<25mqUSiV}8-cAh5IMJP-jiP*C!mv4_7E4~o}2qj2h>)M;wugP z=rk)EPN0_f_w^OV;7X{V;`4~+X#28;sMe->g8iN}KK%X2&4;6hwd^I?-<*$0G%z(6 zO0w(|CC2BHJy2IyClQsRvQFwQylMZj?AwW?5dQJd-j&WAdD z$ElL;og>;+7d@Y^Ur)n^w%{?hp=cFmo98vjC$xWR8I>sexrd4>H=`x(@0i=a1{Mg= z|3M{*TpG(7n^Pv3nT}o5Qq5mz`be3o_lGs%cqhH07CuFI*%Uh(z2vlNsdDQ;_8C_4 zEmgAzmb{n6k`c8M1I-FZsoR9*_B<5Me(%p)vp{d(?NH7q5_5>cOnO!9d<#t(rEiWA zCoa{0Wp|GNF=M1ZLpBPW!hFD`&fwtc>?ZW#!ntJ)NugX%hKW7ctrJvPBBn)rzY+?6E3a z(E*tll+WnWk<=U#tPN#&E^h#u*QMluT3fI#iHr?4=T`J>-4Sj+UdvTSQtwY&Q_>y< z%7Ka4UlZ*uAa3$XT{VHz_#1i=+#gRbgR1P-%EivCJMNX|GUk<7U<(<8C%OG{;Yl|W zcF498!f&`29&`~v03T)d*r9{c%}PSC!d#bkdHeXxhD7I=_y)A+mX$nOF8MgoQ^cb4 zgj1EeoKE54Wt{TsPp~U1*EmeNuAlJ{U;lKT_2^6AT3Vj?wOr%Y!&0~$na;y8B(+nm z`*yW-bd0qW-9IIvB92>H^MoeZc-V0&l&n9q<-jFfM+MKJPme2fyY{-5tPnr@>gDvj zkE4~@Kw6rlLAX(5_s7}K*2O~ygj`UtW2YsZvt`)_BSPFY-m!diQD9tDQjr>-8RP}m z$ZEk(>VJFh{+M8p)Suc<J4HaP{5ntLTFKfD+M{l{RJi#UnEZjU5~8)k zd}aeRWy{~=rsoIWW#kb?yq*~^%zv>6u%@gz&aiPhc~UbIdEKNWxcI^x0O3FgbM}X} zeD1kcnK_yILtfWoBSNyd_XD}LrWRiYIv<=f%@fT;S8yF_D1wLn8( z54je4$+Yp~Voma5rXvAoAD&96+6`Ww700Y~Kw!)e%kYB8%XbzDt)V$}~yJtF4=?$}4?OBv;J5M7T8w8tDLttX;Hi5`EF zT;a^czjrD-f`4@B=G6Pa;p2)sZTB@^{dR@eC31SK4_R+haPUP{iOja~yY;%`Jp57z z7E^%rd3)KqBy0n_`iJ9d!zVZBbeFRzY%^Gbpni+}V-Nyq5=tzh!{`jH+G?RU zUDNvdx)fsHzJ1ef$U_O_Z~J-eU|1#T?uFVV^@@DAT*NbPM}Iakh6Md*+)$T67=?+6 ziOpH2bn}ZBt03O21-(4@;oP}1)XQ2;hkbV?1#Kwah2+kTXPKUMvc!;f z63lP$9(iU7V~fji8T!tXKpO9~w5w$D2~7y;+LvgK6DrQqLX!^{rZD9**3W|$I$cC0 z`aH5P2cUK5VF5&W=;XCjWTb+H;vmroM2r{+kzB+M?-C|9{iyhSI3Gf6mU_0|woYDa=}gtN!u`UPw*GOUma;f~m6~{ur3({~DMS31+7s z9+{xJ<=5)!iuJWuPAoWa!XATp5Z>bIx;|@6rx22DetPWl$#OgILxk6K{Wi)uuae2d zoYF;0FeY3lgtYQ7v{VawON;x59-)?V?&HS%r|>w2iQeY6ZjQ+#P|tj#-EF=om>|w< zdNnvVZFrV^Y?Rcvw=)GHLdtL8%A=!{Gh4bwjUPGn{F2%dg<|{6{xh~c31Mc#{Tv~S zjIzac)u$N(RwOECbCuq=u-HWK+DhoeNI+m_$@8oey4!cvg_vxgovNZbLGyxpPu3V_ zJ^E#TZX8LH8y32Kx($V@veCAQ|c=lDw7*}Rbxel<4kM$SPj1_bl0gM*=Ked;HOy`11AxfbIi%^ zU2_l*ywwCZzT38Q#wZSm0BYciznOrjuIY^csYWpW-j`gOtEVDlJ+STunnRX;wze;5 z3EhbjG%TtpBCpe~-DusH{b`nQDhp0(V%rijp3d%*tzNDwh&%=~GxWhGM2za-Qh#}7 zCCL!)@N%5uVibCL?^7Qphx^|hT8y^Ws%ayRorn6apwUKo(Kh<{h*!=Dr7-_hIPFwi z3|kqobu=#GDys|M1mTkPHpYeu1#GwR{M{$jhV`Z6&^S@jE61gN9>mgc<@&Fj{Aq|J zX(z)qc*zfWkl&X;ukz+c%VkL1&5yp^8Nw@1%$+Scz5;8J_slWYegf-w#+?sRAZ;QQ zp{`W5XcV>Gj3hElEXwV~jxHx=mx2anl;rx{FimAQsXZZk0i8JprS;wnL1Sd##T>i< zU9KAka80PkpN0AijT5$7rA(p7p}J5Tf9G|2di2s%z$!uwL)Ca8@|(09*uJ~wExzr% zJNSw^m%`EN8;NaFoyVN#U|gr05iw}uZOUKzb-JYvN^)XnwL?Xdnp-_4yacFLx%1Ct z!o)igu)|F?c3%h&=1*bz--?oM+C|3Cy`2x+#%UBgDU?vp|l-?LkgwIT#`H64tlB4dzY---olIHkk@jD=ENm@OR zR}|895jY+jU~uwrAn_0rV`Xl3vwl-68XeLc zisXg)lFn{EJj{J_!Xi8REyJ$w=r40>agsj%m=JmNjAJ_2A;((h(-ni4-41&g>Ye@J8T03?4q!~ey8 zBG--gE0;6eS%bE#T^R3dqxju}5}q`?WQv063stwwd~%7}@`giW(-}h4(mdh1UitZx zGKd33x>1`~wO-n>Lbu(cfO!Mfjf9oWK@b!T5k0y_yyuWhJ(} zw_lICAX*NABAO*^8Uoxo6qvkJOQ_S8CF84`v?LkJv*y>rd&MEJTmRML&9W2z2k*vjJ6UGmb;z8 zk{#c-r~}06!ug>yytB7EUnL6kq+Qcme8nCW(lPca+Jr?EJ?aN=eM+)Mz>|G~m6i^| zw&YSGx?4dq#`<|UEgir;^jH2i8UDLDNAtu1F^J2toz3m$#~-uWun+(3fC*24N1m2| z=)Ax?=EkwfaJ)cp;-uR({7IGT(PIRe#vQj)JIA%)oSmNsVLM^T?$5rc;aosxUY@pc zlSRFa^l_v+Q(B0Y-OBR7qSUaJWc)Q_mT`279(NpHAX~{ zA&9X&E0tq)cb)-Vm`fjP`!uI^eQiYz$>9{~;g)G~dpIa)H8{bJo7So0>%V{)c2M_b)FF*+3q5;f^!?phs%VN@!XtPsrJa6BJ@%oBelR02gSb z3spYv1eS*@NS_NlTK(ehFp$ovo|F+kVXVfF6{5*-G==#BWKhWm?bKO?PJ$_M+l$>= z4reUwiWSD6!ON-x8DAV-f&x)WZ++TSln$(0X10X$E{m#AIr9W@MC?Ud4|{M z`m*^7nis#Rcgugj3}k3{p5SwsbiA{=iHhshYI6lf;R3;B3r7x^i+`%o?j2~k)npp~ zSWizyrBPi2mn21FQ_+obxbTMO5p5^kf(@v>!Ef#1$F;RJ$PlDO-Oz(MvPD`>j(s;S zIZAW+-ZnEXc-I4I?VkaN2)0AbOq8?%E5?tv!Sjd3tA+-d7*A8j)sOkNO;2z|i-tAu ziQSP5D7n19X9s4EieyZP>vXthg+Yq2wa~D+WVZRz;%EdG zOR%=l>1Ozdpf+XXwd;-_?OMU129PKSoFh=^&i+oxUxmI)*Fe{_b8CY9AuoE<$~)wA zIcxdN9CvJVA>RrVy09kta(v5Ms9w*Eq(d6T zASM$eTMWJclC-T2=+4{K31T!xa;bW-=g!kj04I zImDGd7^?hlGy$^2OCIzlMn<1o@9Wm+G8~BEq~GFe()a%2DO1N zG;@c+)+$D2-1cMDTG=|DRU(8CwKQ@mPC#<9HNPda4jE|1Kdn{fCOT!0WFGYN>uNb7 z8d(OAm6-Jv&Ep5MxyI21EA<8(P7z|XV5jM50R#`Ia%aj5<|);cIXF0m1w^f5h91#4 zhs`>um!UhHt&Fmlyzsc&vCK>mT&V*~OfN{?2S=A2AkckAujJ(&`HqmZcfGmRWw4JxIzR}o9 z253&YQzsnSA4Af4!uU)cMG8okb_^fbg3o>asrUaO`a}`c8%T%GU%4d82N(K^sEQxk z>)9Zi*o35{%dovYS(5Q5!{qOD8@s)!@&>mA85)~cj=V7KAKqleF?0sJ1-ZNOY%RH# zx^?B(O;p@i$BvqXGJ77A{aR~Aa6Xh00&&>wYb6E?qL=b5%MS0=Whw2U0>fp}w)_Mv zX|uc8ZJm4%xl~+we0yPv4sY(-E|ITGX#-$HmXVRUbfU!38jZ~b!?pW+=S4I2TG-&C z>gt+XTLm6P^3OJI8=rd0RWiDO$F43tXS(Z&@k{4)u*Wb3I^MgtBdh$|z0;5R_9h3; z;5=>PjEs#tOWY(Gl%ma~E2Dba+NvFsv6Dg$j^kG3HYb%KM37?Sc7rhb-VVQSq zRd!{_YqyeZ;7j}tyoSeWVlR#$IbFj%C8n16@=)HJH)Z|s6!W4z(pqDOFH;j`0Fq*R zI{Mr;(1;uR$YDVEafQWC<`}UrJi9vUCz?-dI4cMvURHFs*>tnN2}5%BD})`^8#mBnt&M%l==^USq`$mK9pb} z_h+b{qUi{LbBfsE`f!n@0z=%^`3(Pp1dtZC(a`93qalGa>+KJW^zTOo0peUi{fRmA zm!$*%1gD(zXEsgWsd{gZ6>@-r_U1gy9~RlwjgQ|G*kak48c~&anC^(iyTA`IW2{MI zvmI{0NO4Tl&I~G@60!}q6INdxGt>*Yiq_z)buq838N&>@q@<;pLr~?7aOQTD9@G14 zDk_WtRZNO>d=F*bz_9WK1I)o^8_OXHYN}sAMC75B?lv#WSB8P#!4~#p+lMfK zZRu#MTX*e2M?=h97i>hJ{f|$p? zn^0%36M{2?J+7T9i7e(YhkM5d$wi=1Zk5$Ctm+ATCr+GIu?$T^u#bGskH#Li zXfQmG%{ktztqE!cI|Tgc;$1Av%(sN26k33e=04eJ4Kc-K;BUAiLxd)*i`vFZo2#m- z>JN3cw8%iFMnklt2S9eP;!UjFJ4@n2FV%I-TfqE+Xf8^uWD(z;ikWX z5v-qoI@dMSG3cs5vDskF4RcNgUrQMyk_xnEBNB1E-u@Qd!1=-1x5QY9Vt>tC^EPXf zIO|y+WnqW7qbcgBj|j*NMNh(zj5moDhQ9X+z%y`c{-wj%OuuM#y{j+F#qtg?N?-=# zpLOqm-qz-fV|7FGf3?3~Fhw(4#xdz_Gc7RJ%}YGdvoHLyjRK-W{EVozU?VRfmTBOh z-aNkce3*Vb4!X2mvjQUc@Jj{4X1N2~UVqWH2<3&Z0xAq9&>|o=o^g=Giz7j@1CJp& zvXEC?-~)J=*sXiXY~r@B`dGygvXkLi`UM0q&f`a*j}bFss^Y$MkwQ%&C+YxgKxz8* zhY{i7ClGGmY#2~R&V+vKtZ3rl|2XNF<-C?q(nuKyOj@@*qXif|o1 z{9y;%h^si-DsX7@TXQ`TTcazya&M3R8vu-NM_Cxp5A?)Oq|@O!MzBqL@MAw^Rrza` zQ{DPyzYWpbMc;Q>YbUesWe56x#q1hp(>U4-UZ!fY}xhZ%a3{qSCd_3 z&-3iUlHGvDMA z@+?3C2~)is!+Y952;|aIpot~BKzh`Oh#^k3j5+LV@WQ<^h~V+_E;~8 zA9`m-q|Wg6jk=`XQaiIUn(Z}2L_#VOCPWy{Qlv-ikCS``5SBt#2?Kj10-+w8P1yRQEnQ3@>}vC(dhW-uw`t?9;w&L-#t90GTA3dTi?Uc8HIA7XvGXq|2(pza7q1`?2}%b*j3 zq#_{n{Z`ChF^(M-QeVww_9L69SkgM28@==nKKbpmy5VI#I{{8kC~!=>0ykkD{)9BA zEm8*qp?G-B3gHAjnQ)Gyo)B`O^dHzT$1E1|-_|b7khU=}Q25%`<}lut0V~Fg(|h6P z0ig%TJ&tAPa@w_;Y8-&mb9_H3=r|DXaP2^E`b#)9E*YvM>I;X8!cGmlod#>waG$j`q|m^x<*<-9@V!wUvEmuPIkVlT&&y4lAv-TvoH)Z1=s-8vNL zUp%7s0{_}`4VuNqdP)d_A;C6-W1KkOF(xDN1EJ9Gy!CIw3U$SF{epLC+bjeF8qr2l z(#ocPz)Q_|IQ(15+Xrk(0Sy|iADs8(nE!H4xB7GM{rvfo<+>he$$EZg$lej;(1|_| z9wV*d{QRzB!oNw8@NZgl>Pc#F=>N%1YlhI2e|5WzUx6<_;O5Z1(_@$?!*Osdx>N7B z!oakKqAKO^A2#aWj)2V^Bwte>AH-Zr%M| zF!QGS7K=j8NU3+beJ|DWlUCO+B%1dhgu+ms$FdjJAa@va#mXirHYN`pQ&Z#XKQF_l zH~tTzS;554^9>Myqj0Ir!Hge(ce8E9SOP;YG( zXzBl-_l{iml{!%ND|~jZ1}%}EvZf|rR8*r>Pgc6ZkQOi?GWD3>6M+60Zo0$&DNvD( z{{s5HNMYXFws9A=@7PjE{&5#Qs$yu-(b1`IWaVQu&r(qjKam1kDZ4A_1XvY6HEv@I zb}(|>;y?5X{}CD%voHt2IAJegQoq|@*!jbc{_AGAxM)OlbM}@;Q6(L@WuVghUqnegLKjz8V<)g3^)|6p7z5TN=0_-_7N#0-RG=H!GN83OE&MPWU5D|omI zrdK%&i;H5mWuFaA&i;?RkUFcer_06K)!)CQuG!Bx@Eid3J4wNf;3BwP<);q2g0?nQ zso{4SyFounMD0gRY7;$?u(igW5c;D{dY9rA-|5_Q)!tW;xVsbc`B?da&)V*3k4gd$ zr&^@%P~`Ygw&-^t3_m>lX)=5!Z`>NLAt?0#zv6NYNZn#tI7EUEq_4XBd&>H*s^Q(V zFMO8d=fA(|QTl+8HbqbH!~OM?{>xoQM@UTzdx;qvE5*VrsH>x`ZC|yX7_swb#ZpJv zEr(j)hC}UWHv5kch48&>m z80H?idka{Gpx)Pc)tc_h1n~2z)|+9)8(OPTH=!Fm;?k2#*+Ufr!&~rIbR$`NB%h}z;FOK z^{CdhN+)OMH3Q7j>`L?7f0NT*(NZ4vlf{d@lMDCFrV|+xW)-%l!_5QwVte~T2Rb@B zK8IF)F-RH};f;DjU`P!elb^z1&|e~NrJ!%hb42DXL%yupB*fHhO?{%+)vM*y)f-(3 zN7K@f^OK(+pNOIr+~$06OSbckRrpE$HyFc{`w3o1#7PFarGA$y_k4yE|1|N*Y4)3YuE|D8-N4OCfdQpvaE<~pf^YS#aVPv=h~F;7gn;Boooqoy z7&boV4gkf{{QU3W@4tuU+51xm?{u&;H17ZXOwp_2RdBILSzXYIVNW0R1W{MlLo{>v z>rOTEE__VYnx?Tarn>qe!AA;Q$LSG;OUfqe+^Ji4_Zr*JySvC_7Vd7l;#z=m2?!7KL#v8= zL4)@_|HE7CMD>M1a?IFdn<2almNK})$}gH4utq0sI2@B&8c9o$BPYISvj_1T+n`S=`wAvqxYZ;ZvXIkM&yn;EzQln-dj$xczL z-+@|pb?FmBD=^)PPV+su>6iW6HgmRR{cF*Is{MuU-wTaeeSBDWENx|~WM#4-_4>JH z+HvfT7o^sXU=q_>0?Cvr-_={*~2g;(OoE54tfJ3@G3O*u)?kt2o*L zy>4CxOaie=*F`~L;qcqH)}?N|oTLt{Z2jtt-!(XbWJ&E?6h4xCeU1Em3Jb_O|8K;O zbkL18Jw1YP;e#D3tO1z)I+~9x&9-LWo`qvrR{Y1^xp9T=AzVA^JB_V=!6+gohd0ZQ zjCqEh2DzGz5TcWi1a7TNfZMK^D0esH!=(Cwe>hi3Xzi{V>Fl(v0tMC*UmCUo4pu%f zBjc+}{aEZv=3-;m@;+}ox@Al%;#@PsxGR(=%zJx!YqDEhXOBu8ix~6kd|Oo1ZQAzM z>VD*#6|xb(l@h9T%9eX%3Mm@Mu}LCB7dY@7=cHI}3-_cLRL2VF#EwO`yNKBuI%dE5 z|Eq1gt_gm-Ax>LG1tsUb7$Z>^{La|6_czE=GI8??;mW0}q(T7FF>?74p^E z8Siat@N2TMUe%BE0nMkCF_45@ke@O#GW7XFPte%vXNC&GI_vuJ8_jsT#actN;}N#0 zIE1Kw!6d#M72Ny82I8y=ED%`R>sPO0W7-_vxcn@SD7r9P1`>4_lLNb8`dBib5_2ri zD2*3+)mqY**;|ulgSfhA4?Lw_#A8LO_&7szb9)wkd}aNPflm&*-XnV|(3U3WhR#V` ze6k9v+4~nsSBdJMlYj2&Vts$0>4+|oWB-Yy%)s(irn{szqyqm@X+DAp&i@oG}$WazWEx>0jes2@|G--?-?%+Jb(dgZiep8ykgIdT;;m@kfWV zl{4tI$oQ^>*CnP6@3Lrml)+pm%pE2|m2OiFDcS%ZfwP)YU>_70{dg|caj$AAN05D! zoXQ(&y>cYDco&s+6$Dhs?2(iR%*)Dpe*0AFO!Aroht{y=nlf2}r@N1djm_TYAhiLf z>SJ_AA+$X*t95lxwv+6ozcU+v3BD8y3it7IU#Gjuun|S!^H8PTtMK+u$(u2c01Psa z-dI!EOp&1bUxVD)Z&|Niir=5os4k^J(tbFi@*O;3_KXY~+dLC4w2gwQe*l<|r7L3X zaru(_$=53@B}5)7r)lMEV?dvg&@!P%OJ?6fKKZsFe1VL5*zFKPQOrInR3 zB?zK3um{QgrmY~Bx=S7%&GwON$3g7qP|H*S&7l3O9!EA&o1=l`(XL&jfu9n4c&f+W zQsNN(M@T;5WM^terxeyew|o8lxg4IetBs9HEgc_iDV}lQs4z`#*CA|c^#r)xk(?6{Aiq4I`yZxv3QOUb}z40-YR zD==gGR=}41Tl0S^2mi-h#(`w*EFE|D@TfHvH_7V+*8H#c>3wSP6r-|Rs{jDM+s-G4 zV%bcmexKu5qE4Uz<^}idnqBQ(6O#`T>|xu&_=*qfU9&X0C5c=WsUVo(K@O^=72WwF zJM(1`MgH?D%1=b6hSp|$%V%)6Z=b|T9O&hv+UEwEt(>LXb&u}&Xd`OTbP{I!dXW>+ z=I+3t8OoWh@CW`7jHY>L?x#>D41dfc?|0mxA@MBY)Z34<-8)<%sTU?kb5ek&+@g;< zdCvRWXw{rLVsG1BgkO)j=!m}EyS~sd@bz5t>2XWAstEov!YkyT?>goI_@iwkA4bjA zidPh(B}}8WJhwfhT%CAKQ)%5RP1)r=7oAKh;j}uVJz#INW1N0L$|o|5CD($YF5`_|gQnD95d7E_=YD%_mp#XowE)6$Xu}o@^K@m zGM^$^lUa%W)X-D3Ohm4C@5X`Y@GCtF9Kk{LqlQl-#~i(hu|pFwOF&q76@$n<5idJ_ zge@I$Q-P!^%W1l(p}4i4m&V_ioh@Ro(C(G!aU@e9ogmQCd{W{rPDKjutxY&>R+_gG zg-EhXQXIQ7=Ry!u}3 zHLW030n4Ug<7j5d1Jn5Mr9IkR3+Pjx`Ba9ADWeKA-WrD@SJ=ODdD|xwyX_hD_9m0r z6CW4Q{{l#F#AmQ)?pyYtm~gCE;lWRM7t3oMp+=5P+Y76RBEJbxo$N^ycJX`_agkp^hfU)f zZ|>8O-@8wxe5P$NSoP!(2V;S{5G$kO%if{cY-PPdnuB>1RaQ+!;O4GV>vIlsEB4l6 zj~*L=_#~OX7C;*Tm(MVvUtW9zwAgzI-zOkgO~(OgucgIXdwma6wVuiL4H7hge*3uT z7xPiieH~7nxgK&~Ri1b3?l9Zgnqv^+kJ2QCooq&)!n>xNPWCJLpj&e#sbrG?ZG>WZ z8%}i?p?KT8(jV=7iO8-dEIRY@^6Y*>tm6Ymw?q~tnTr>h^m-Tr1trZh?5BFz8p`Ci z(S(Ku6VD!5p5<9#XAT_B-5*H)l9BwB!leh4&6z{OX*V>To+^CBnt30%{yr^}@}XjU zUVKE?-s$}IED{kd@OdlG5rnO5C2bH3{%hfe)!WrRI#IMz!AquDOYhk2hVSNBm7O-Wc4wHv)Hx(0ceO(LSB|;d(Y!R-3UR zb~Sg;eU+du3k|FiG(S!5_H_;Ktc?lk_(oZa7&>f!V@iDl3aw#uT?iB50CNgSLF;ewF3%6t?1k#XT4O zm8CUJi!dZIKJM809OWGjS@2F3yf%BGrR%0Q6yno&vdM6L`}teQm8agG#glrXhf;2= zU~^gbdZcC6#_*GfrkiYIQ++@&LPXww#3jJ$sXfEJVGjr3RQ@l45s6JUEA{-8(ady} z@%*!z+t&LF%#grrG5QhpS<~0o2kK1Aiiu-F9>i?wYaF<<8B4~BFuZ=)a^tdq6n;_C z$yj@ACn|N?Y5%Xg3uJChcp62j=;G=1rlzKg9Il)s9}<{TP4CTwNw;EY(ii9L^b+lvctE4g_%-rbW&fHs-g@WMXfpmjyfkl5 zFVyTPjehXGBYhP~wGw4JX{NLoP^#R(q1ZhU*mF3Ey5-xN%zfo)G)X*IrdV5x_t3f_ z&C2>Sk#5!WsOsciX;`&=btH!5w2;{h{w}Jabg_KJb2hNP>A!Wr zO-IH6bvb06lRUlq-6zDtJ#*uAA&LZYATfME2&SP$$*!RC?wOk}x*g%=E4ixYWV$a# za%DU-Kyn?|k!1`Q*xFd8IR}SjW`#R3=2PHi5Ftp*ARj4dJ#8I1(tVi&$o20YWt}K~ zli~VP*z1>Z%%xi#cMBm{Qg`Imb!Rfj><#BUk(>5tc!7u9X7)wGTUXJL-=GbvLiBa=1H(LplSI8YcO{P5Nti3Xcc{`3JH&pPWf2syek=Y0Fol%<>7uV#oX{R!}wASmJ22gu|8SNS*TSv6k1ESxXZaks`$UA~qv|op$C+p}nTn5f@s} z#7A-Kedmgl8|b1XOO(GRC;9Lu0BOopmg68RYS;f`?9Jn$ZomI=OHwG>Y*~s>i0s)Z zMT?Mq-y=lXvJMg@TV%<;@5^N04T-U2H`b8s%h<;ShlpUgOX zAxOb**eb=(bI~^Mj(AnJk>|-Jn7519G=H{RcIHQq&12j6(?N1A6^5!i#G`$redar( z=jZ1yi`j!UaI9l{tAamsYG^JsGe-Yiq4-xLoLzcm)1IA%!M^uBnQG`3-ayEfuE*kT&rX4Uqmu-i9wuV3cS9T7Tn zodhq-$_ON>OriM`F>NDAC)&5Gu+ee3g-sXoy%B{bSxebQpn=N)AKomRmIDDsS9^a| zh+0bF$`sTm=7OoczDL0_l~69Lr0e&9>>Vp?g230$FR_@dQD)nqKz&35S6)J1E|@F63!SM=1TQt)tYvwk@Vq;bTYZc6N3^KE7gd^TWTnk>BjEe#PF#Cu1?V zil?XKx;}9f5bry3_kuq7EGK2}`u*}5Mn*<}T}Thlkxt(G@tXA)fWb9E?%(?pSfgZV zs9SqmWzWrh{h)ZwvhKf;!)LLJ|%=#M%FdE$@TOib?iI47|0AZ z0ETPz{8v$lxSf`QEt;T;KE6sWtK)eu1N3iAI%Bba6pIA(sq6XR)+2c7H`wkyX1bw3 z!VXpCGkrP-v#j`~%c-yKQ&Livm6hS=sUbV-7|L}ip*bk|f3~9nm{MAd^FjNB@1Di; znfSIXR#5e&|Eg|t-iU4aFWLs|s)Tu$)-WdIP8<_AhdZO8Dqt>Q=ba#Fy{5GTF- zWGqX|>egfO7U%<#wSDRy0CJdn-}w3C{zzAsk=2>cAH|$ zUrH|y_#v&0DNpwVcpOv@MRWsCnHddiHFdVy`sR_+SZSlq!gk;hSU_s5a%Zvht(FrtFA#ECFbzl z%QI4-yoSR+R=E7~@&FKjJf1u1udRd@E`|U;4_9s6zij4rDbuZ^M9CMoT z=*Y33@GO6kiaX7BFv@~j+xz`0bg~0i7Pisv$WPC4rGaCA_H=l#+cjtTWyPhTEkb$| z{yH&3eJ~|ITj)jcHW)EwPsJ#nc575qs+wuU0ExAv__n-gAvp{R2;}U~lFk$3v|t?p zJ2b|MQn1V!X`0@*Gw7;ildn_O81C~jd@f+PeW|Gvloqa>ABj!)IF>io)74`JSkalI z8Mmh*|4UIFP$!;yzoj-t4JMQOP(TF^py?ajW}pS2X|Ef-#!t{g8YF61jNT%d4NXd& zP&cH3EIcY*m=V&Ae9V~?&k6Lh{w#~|cK|!ZQbc)OFJJqku)<{0SdO>|fs#y}u7|6XT4&pYR!ERS>RN}0Y( zIxJm$n4TElf8$xV1JH@6=~R9%Fxg2H-1>DZ5Q=$s{o0h(1(f>iPB@dxU#nADDg&n{ z-_p#toFxM*2f?7xhZR^w8u|B()i(1n!b6|1rlL4XbRj%-zpcIJlm|CHiBO+{lP5o# z;1b-DjRmO)4$8dS#HTAgctyqiV>j8PJ^&$GvufNq*<4DZNg#hsT&zBH!Q_%%k7nJ# zUx3N6`0SHT(9+*-eo$+9s@&(p%-*wr(@VH)Fb-tZ zVC23K+Os3(26XFb=iPpVb`lmt|6k0;0Me)YFr1FTq1WcnWW>44TxGP&U2C=M+_CaS zFVK9XxSyd0G&{}>W32`QzVFD}JpHS`%0ZG;*oVK~X|abDxA|@wY!?-CnEI9ncrilx z`cubJ*T&K2&_=#-3W3}IQ+T&g@!9Zi#ZUUs$D=2O&-AHU`!;%GDzUX|KJk=ljJ9XV zdSg%Dw~`$j5mMgY`8^?UvwkuX3{D)}*mQW+-ScLn*3T_rP{4Ad}sBBhsq}4Q=psFvyYnf(1QRGTkh`ik?SJ}WMMsR=AQN2{ zY<9`C$Mb(ZRVAi?o)>t$56e81xQEd)ul1h(=_0_~rR6}(tV%s3RPq)~3O9yr>m(?= z0Go8KgeQ@qwXevY{&rcj&zN56|9hS+|N3Nd=d?6y!CuGMHRSw|8)Xp7n(2R03YW{n6 z*wOh}w-+^qUDf?)7pJ3(2UXPzH^2^yThc7yn7u25uVPPlIcRZ5n_a`dj1mCd;*E;r z#%Tv#fNQ%^JE5 z{aRPcX=XBsXg@OSd;f?!>pTjiLdj7mFm9u+s0WkT3Ogzh27f!l?RPu3Q&ng0q)+5on;;8-$?Pg^c({0#_?f`1 zJ>kCYzGY9NypMM}Pk+9U($$CL_d431-H9@T9QD#!IN2C|p#)-inZhyea>9k~o!;sX zRN>*dy4lbVbj~w{!7SWL!{-rk1EAH;dLM{w?R710KT8d>3pp{`?_8fTXMYzxK`CRp zC2pUxeWLE*FeyHpM*1biL8IR`Ib%=~|F1(Uwbk=`Pe~>DB1vIM-@CiF>en7In$#yj zy$jOle&Ec`WK|r*#WBDjkE^yZV{Qf*mVoad&Nd^vE^nozOz7%BEH-<;I=5X;I9?$4 zyZzqsSdgbPEguxI*UB=L`^`(}Sz7{p?pEaF-W*%-`6^jOg4cDrB0FmEpRFj95YI2H z$?|^g)$G^%oJ@v3HzL8Bdg^TX;S{RH#YOeJq21kGzuAqWUN|RZA^AT?@-7ULXBQv6 zE`l9SZa`uma{>mEmW~dXBfA}Xt*rN8RnSMTGTf2xl-liO2cMpRpx5QOe=B)``E+SP z_haFUF_CWJ)k=Lp@x@E5%ee~;=rBF#_`RjLdb14 zv4F{rw_s*VNRD)+k?st+q2!Kd@8rFl*&WY9g79yyF@9+lRP|qazCVljYg&8Bc6ei; zL6x+cCadMiiBg&FRN{E-tFksf<$mldL`d2d6@nwnOFJ-Ny&ov6QuJv62#BZ>nvC8! z%4KlNLvp4lWgd7tI5$zQN=Ao*_P~khIU>AxC80skS9=1EpCfsqOdxDs1YTOR&~2;^ z-?DA_6*uf_<`hfBLqDsY7q!ud5?~j6U2+84mLy^*#mR!By7yRedj^Mlb%K z3r_N(6Xw-TQkqQ=jfEXmRt0n~jrfg=DDK#lx&9HVK9y;6-;cJ$W<*dQ4JKHZ6 zK_SjSsb1yg^288P_iLO*HJBzVEp=QSF8T-m_S2s_J16Ht&^H+FT~%0kCPf}Op)K&Q z_?G&e&wE$)2o~t$4gtX+Ph+Jsng^^J60`qt06bk8u9oT`j!(f)r>x{}L<3d~9*ANF zn!cmLW%%+Z?ThXA^AiJJO}Z7Iq-q9|d)2We8nof|^p$7H7u4ErzPz0+F5D~N5B5bs z*!{y;r!UW?-@Vt0Wi(XPX<7l8mr~sLBdS`dNB`iZ)T!HU-v>j;3fIBh%jzrA=C_An zhf0g3Tyj|0+2p8Z%pe#X2V+{c;?2WD|GkU^>u?4pL~*rr8?Rqe6Ym8tdTT;W0tOq0 zS%ZBe9#wi zM&cRqD{J4%ATsFr69>YXVM+_SRe?c-nsB2cQ+HEdoSU79F~58_2(R&UOszY!Ek$gw zp6!c{6tv;-)LtBN(iw@>+4fkYUg6hbslZ1a`sm+#S!l3xpH&v}gDh)??$QGFoP0C5 zgx}SBsNQb5QF|#;l)r1z(%{!;TqUnCb>H?073Kx4D8DsekDC(H|15g_9}^u)(JuJY zvw+vfx?wm*Q+j>B&A#$PkNx9M>Ziw%Hn&< zU`(xaYk+s5mO1#jf+*SFad+R90R0Bing9J`fQWE^|%xlY;4e~*pOBEO8f)_J@9 zSS0ZpF%(OVAes&Z(xe9m2SY;_rzmSu?mSl8x-HBGyyRDSHzRfF3hq@>)KzU3P~^Z* zOtxQw6^99a5hRWo2?g`Fm9YeN2F!`GCtdifj~+|>gZ3?rDbCFthi=Btd}_gq7MzKn zBu`bD2b~WCXz1>ju#H^$+F&eG2Xt2bbIPf2yM}$c^BsxF}Mvc2m&% zdjj!z_`7u#B-kRNGKkCn9G) z6Yg^~nJ$Jw1H9yjOnChRZg(tPUe5ssNpb%(28f8N7Fq zx4l~VA#mt;T_b#CdW-p%k8Km_LNKFN4V;Ir{o8^-<<5<9}p z>eG7@bMRzpb>_=u=Y&{Yt6W{JvbpODJf2nBh(wuHazD!}U(?9DHxOB1)ft!MdL!wD zVsV{dO@8^0d0s6EWy4(k_=_BMhBwtBd6cu}9(U4SjTAib3qt;0^7J?n<(20jqPX|2 z;>aBuC4Q2nD$$Un7+;~eO>Ijq-kxiZ!Ab*=m#rUf<91s38N-5 z=$X8QSFXR|F1&Lorr4^ONKcBd-$x`dF0SKQ*|M_)ZE(Pyt0}#Ujx|q?wuA9-ANm=W z)JqF*YE1Y(Q-WW)ocJ9G9PeTFZQ0qQVM^`_&|m%3F*h`%!57POkpj%#17^+f&}yw3 z0Wn~qDJpWVwi?p?#qvmPYqfQ~_Y=SO&(-RsujkgnWzIg%%&{!d$k(-Z`A+84Y@j3) zhut1hUFyT^?a3@gbWO4PobRBe{lb}FQCc46`02^+i3TD)EPZxos$~)JU|tA+I=3WHp*jGFrPdYyu|X?VU6mG+lQ* z`33bZyu?u)x9>@Du`}BRGrxZQ`ug?jj~|I%Z5>@00rZ!e?JeB(dVg(bG&- zRO7Q1Pgwsxz)?SUFYbN772<4T@6Y2EFkUiDx~*m<&Jxn#B_yQIOAEuHR{@&s-00jM zEM5C%>F}gHaKLZMfsX!1&bBe^u&X_y%ZRD&S66>tTA#&U7g7%wN9xqSdl*W-)k4So zloZ>*Bfl|c_Z(@E4b4}$#!Z%`Ijpq>mv;ogb%u({00v>+R}5znVT>-OEOyK=jGI#tlKB0u|6@e?ei&gbabfcX!*UL z3bv}jAEbzEk62-^Ij$pm-|OTF((*BNxAJpQ=C1pT|qv9d3J+0F)I*JEWiv7MMK zqnnv5H0KJnh;CN-NZ}W$TlPyj!8@!!Pcpi2r0pexlUkJlzi->jZY?r&M)3GC54WpO z-P0jbKDNOGv-Odjxoaxx$Vq(pZl6*R!3=qPW1Q|zxI9^TzFnXVE!IET0D2$%P{kJt z?L3R=GAVgaKeYT*18Kvd+)^4O*3Vktc6GF=@=9+6|WLa(D+k980(&+d0_u#+F;+6D}>Egl^Z_9<1z2=}~Y> z7>>)={`I~p)`POSnfichB`2|I4AyY^84W8qEJt??gsqF`|1eb4|C*c z|D2P0JbtY{ACla#t$qKYfQl^H>su7*Jyp(fe2VgLIM5jIh zMOB3LmVFjeBo^k4<|mN`?N}wWxYP7Ho+ z+ItVSCv|&A_jY1pWDqIhu^2OO*MH1PD&tVZc5T|g5l4r|trJdZdV{qj#5*lN#gH#n zLsl`PUx6*6!vbU*03&~BW!r17KN3Qm2!6+V)iIodD;kgPHohNbuvfV+{;J-?=6Y0I ze6eGV=5e%fi$7}fKbQ$Vo9Bm{icWp)sHJ7pr)`nWT!1FAu9@#;IaJ(V%qFoO^vF5( z{e&>Z?ew4X3B(Q#w2;AnK317!5Hj`(0HRwHSHA zsYLfstWk2ayGqt})rG#rvSM$r@UW?=3AH-%$_Mp8CFKzw9G+0D>>ycRr#X_X&k>sm zXaTQU;P@>B8A9*-H>XZ-#4=jfP1=`@u}HaXw$d3NwK?LUc-&O->sX$&*A0TZJ}XQ( zI$7rE3E0tu07?fY5PR9FMj&>Aa{-1KZou!T#5ln47R4;9VhfJueBj4K;Smg*pti>F z3bQfIg6op$LZu0;i4|!T7-82?9$9E{mhhaxW$-fK)4qOjXg+10&hk)AcW<)v0+-+o z=02?J)n-AVEyU4&@rf+-;pRPfDEX_|>y=^f4ubz`Hdvec!T1n%V z(}Dk(l$_jSAqb|G!1bc1LVL-C!`VgpfUlxvk@^zjrRE5B_k_zZOQW{hJ1*~of4d4< zi`AAj!r7kq5$0_nAl-V|p&o$@Y?wJzx&Or~3d_EpwLA8#%#`(mblwCq##R>G|2#;~ zv$7h4v+rnu7hT!z9Tn;7(c2qY5r_zCbo)shw#ui^6%K3?#b<1-1%=RFmRz^&0Vc2V zX@Z@>EBIR|Ssyr{AixQ_tdRAocB6Cu*xzV}IA!X;PNgabHa|6my>*KhW=3O?4e!FM>a_DEv?~}(J@gr>Jkov1l%8SQ7bFKEZBz$$CDHwmbTMro$-h^pOVoYYA;D39i=xlWeD#LYanN(M z>mjlJhb6epzA&$XLXNr#VY3x~(DufBGbM(l6H2e3up70aM&!NJm*&#Tz|dm(y_I(U zDR}Sg8I2?$O`V(6oY^t>l7li`qBBqV*jZKK-qExY7ECBxL!PzxqVw_@IX%5={N8qb5c`hd9PB5k^r7mrjD%7 zF_LkAI~bEOa4%I^q;GI=@YAPH$B61)Mn5>deT*hU`QUQYL+cxXoarxir_TrHp9H(7jtz{_NA6$)#UkK*>lHD6MZ9d$+a3JFN*!z6k`~dKo06G0c09EIXT%Ply1>eoge`*5D1JtGT?Z^HZFt5 zPP72)+)181J{g&Fl8VrgVDGFbnRfu2ZaQ&C$0sI6*~$VTw$cT_vSM;A^Ux8bHoU};AcQ(3r2Rnr6 zFud}_TrhTY)SJc?aI=l!3Mvw;bMmr@(5$`q!s<( zcO@rZo<$Z?dJ_1VC&i?pDoNeXgyJ4^M}xA|)04~;0h#B=H}*lIa%1Of!zPWIH+IVB zixTl}ky_5Vb83e4o{fTQXNWP1YaAs|s&_4;4rUv1k2wdIcLCiJ#`eXbmBrQ7H3rdJ zZfbKng2O7$>(I*ONK{%n)W0fx zsTU*Y9;V+QBAXDfEQo~(;1ayl{B!>RrAjtv@1@jxBC{CY z7K0))mc#A@F+h|vZ6QD`_>tHb+CebG_eYb7u5#tr|r?JLn> zkB#v8ptmhEs=8mk(O*gTIK;wgxXAkMQhVK3P;g0e^{R%SRWre#0`)P^$7^C)yY3zy zjEd&~h|gbt5xQdKE?3T2@%AS%Eem$LSEuburfEb=>AQf57?-W$L>!ueSPTc zn$^sJUy;0QBSL_X0;#D(X627I?~ykOnIUZ@eeh^$>PBf$xa{b7P#zU5_lUUMNGTIK zsUX>DL)M3P!}Zd!8=ExH=%^20_YI66R{xXQn*a~a_WPCIRx(f42liosB}hU&RMDC~ zd=KnA0F_W|1A1(VjbUM)AYX1d1PijaVmMaA!UYT}5&r`|?TRlvfAlC=ZLL0gXR+5I z)yKTL@cDN34UjzR-^?kJhp0vg#s>rh93CEyjg8$&yCo#VZrL|x=j!PAlsgS9dAfM_ z?%IP33L1*jURDYesT&e^z(MNwjxI)boIU4xe~mS3oq=$YIXO8c)X@W0Ynlj6*^(-< zHFwl>ID#}?BsV}o*0IG@zeML-WFV<1ucyw%jDG9u7fZ#Zr(wc-MW6QPp7tfNV$R3e zEswg6)xsNoLn6E9;JbqUuKA;u_V!aJL%AxSd!@$zf$R>!H|H_aepTu*&=?k@QL^!?|;aq%|5YF0K-% zs9LKv0nKHn5*-aXh!%_~0V1VE{eGA;m?F1DRFf$5t_V|(sah1tlH8S_C=Wxvk!b^r z+4Siy++fD-_uljDRnn0+m?!x3G1ak$Wzo|$PB{QQ<>bJX3f4i3ypoZQrKcs&_SV)` zhGID5^c|7Q2L=zlw}Wagky+phLim>U@4g>0(8-bj>NnAug5)@T_DC=kLQw-lG=LPD@@J^ zUkQ5F_;momMAnzuquYg@EzOF2m-R>(kl%BAidM zqM@r8Td*Ue8-GKQvK`AH%I`+Zz`rc+tpD~BDGj$h2BZb9W-(p|F9{#r;evP z#b21+U_a<2B6u*sZ9%gc)n6MnYfcqg6eD}e3WroozPmAzA}KO3E`9WR1it1fIV@A? zUr!?3Kb}ccTe_=Dzj_}5!09S_f=Rqmd^FHJ!925K-=D?8+!M8;$<94ixTg{~JJ>M+ zm>Ro#_z#^3WAZpcR8R`5;T?nl8ccoR^TyZ3ouXkDcth!tEDxUl&d3)4aD)CJ6h=j9 zid1T5iSl)Ec0z7Hnr;BzH#k5`8%pnPgT1ceRyQRiB+wWPTpJzgWnqyCti@V;d)yXU zGyxkZ1bF~rYSAv9#QIiJWsLmct8?H!K0PTdD+}dLOH-}oE&qHq{l)e>pZ$P~a*~{- z;QFIDF!Ezp%@*GqW)4Z4!}1=cl*l3qQsnn)Y8eU*>n$oQ*aaCTll6E96i_dsYx!|bazs^e=$3z??Z=JXSc zh{#v>2B)TqVX6+{8~(s(4$Q1OT@n&lr9H|^W7dxjcLW1N-Ij}aq@|RLr_N&D+l;S@ z#sGO|#VNHU!ATw2?uY^sYxUxZ-Fg_zcuM2vDbv=y6^E>sQsxRAt9uSqu>y3Fu>Dn< ze>^#bzp$kM)T)>wRk_BVYjI`q1&~MmUW)|OC{Ff0a65Ibo`&iReg_sH?zCGv3|^F@ zblE=Up|qbz^TtT=YTs$`>M$7NJ@?|14@#)uqFmht<71ywBFRf9?LQ>lwef8w$4phy zz?AWtUaX#pMbOuQ0Doa#2c08|fIG)j-){zMai?a|K4(xIa6B70e{IZqg)6n}v``@Q z(XodvWcoGiEJgMG-re~KrEm6C@9w1OVVcw5w3@fB26n!d(~PKhmDP`j9sCLw6uhrd z>IV@O>wT=8!boBILgHo52a(mRof!QVt;dhwwahryWTF{%I0&ip^TGtT)5Ge8MWf0l zht+Wbt`%0d}|Mh+|-BX-NyVak#UHNRhgc-(W;kv?!Qs zXJ5>n5PhlFe6>3y*A9u}abh|L$_Z4=B(&n}lS>D(gNH$Br~dh{u)yE{=yOf_H2%#1 zXZ1tKJ4}V&ci0Ks)n~=HyBzI^vivngY<%fBN)-HuyX%ge*ZD`ucN%`3>V_LQ7ur8gDRIuu`DGLo;HbK`0nQ z=5C*P#26#N`>8A|7;FQmIR?zk;cylP$eTjLibb->{ZxUdu;{mp~`a zOQsq-Z1J~FePFJ~+S*L48yT0zSh~>gasuS;?9G-sG3CL!Po$GjVqWwr7 z%{~9_*j;}lQmb5BG^SuD&IOae#H7#>a1=UIs)up!H1J;Gp5Uoi*uGz2*sG5W2zB0> zdL4QM6sotgCBDj|7lWB&?QJ?rzayBqISD4)tDI z`8Ye)=@gvaiHkb1oce-t>{$0e&-PaKmH&z-s`@5nhn2n2G)^ZWzT; ztk;glI@mS-%)L9MQEXrQ^FY-B8sGc@>-*S;_a6Njh6|=P;W;5;T2L~;O3jRQ>;5BO zuB<2W0Nuo3Or|X^t#qZABM8}vN?|D|vFc4$y}rAUTJV{Lq)6z!jnA zo|^hYZ{8h;rS?BaE3*m5fRYj$)GNq{Js@Y(TWcFA@BvL5cdBTS>iiav(mlL3)KQhWYhOY}TXLkermakU7ctyvhgOuRhUSgE!>&^ux*b1;KyE{sxO`!q$q|JCf|2z7*&9d|5F0L};WDs?|#X;0{ zS^OP!zXQs(4L!eecqfhKz94}8$WNVD3&TB7JHLLV=d(s$(lyQtQsS~DZ||`WC9&3d zg$-3;8)fU5ZZqlf4-Mj`HY|~rx_byZ11u-52PIaw#JD3NkA3L<&q#_IL|0>*zKEEj=ex|z?2W7#389Of>RCnQd#5zw&o8CL!(K)DpWr2>-?=oc?a@SOsfyKA zn|Cv_*p=ivctUY6e=Bj{nY z(sE>F@*&=G0JqSc&~|}GO^EI>mPa|Jj41vOmd<@OG)vLv$f?nD=0>*D{fD!2=#J(U zq&uxm>O4gs(z_>TjXa)Td&iq}q(l{3boAox$>@b1|DZhPr@-biD{rxBy*einiC=Db zb;CCdf~o+OG*N-QFdn2p^ZWOr{=8}{Mo>Sk5x*GH@qcrtCrFOD(?@5@yPruyEXylA z4}gci{q1+grv`5*V5W9>&WATQ)P(;kP`q|tzIbHZ?7ODtE_-wZ`q7#z20Rvo%loZ} z`5Wq?Vfhbg-FLEOWS-7vNGRal;K0dgmH@(b?uK*j{gWEe;YS_0>G|LK7C~x#-s`&N zqiZRTygNujg7V!3)6XB)7a$TloQY0fWek1zM#V-UE6;E1+pd7O(MQNN_##P1zmcJs z8iHt9{Zh@_R27iMcpIHYG2Y(wZTqZ+#;j-*PjzYRTfss~lttg}8(wt-*T%N{ za;ze+c^9HrC&7R(7D)GEuurjxO4k4ogvNuIinh*&1kN+x4bqDZ%8e}KR8=Mx{yc1K zSA}RZkWa5%EGXLOeaIJ`WH|4$%_&lMOG2VnPZoHvv~q#wJzbX1dx{m6vDoUSrMzY1 zdG~fu+I;Si?#dU9HL=fUKT)5w41J}6x6yu6%sovv2Xr01wH+&*zL_^jPd#zGP%koN zR+Hg~(Zg#!MANNI@|bE{GqR%iqAk>*YsOdl7h{9goB|kG2d4vXXcZuae4=;mSuv`( zu+?T{kixHS>$Lm5E7$IpGs;D)1$TcK;=TLGHeuAuti-HEorknnA)`TpA(h|Afms$AMGD3lk0()W;Rh<9e2+Z${3 zysSr)2{x&KVF!~mujCRyu`wqHkP+&HdSkExo1a|MAKVZ20KE{^-{>yEa=qJ6`odIi zA_-zlSH#EJsUn$TBLQvA`h4ztsag5nYSBi%2GGffJFFd=_-&3;%<+z>s3Xm?PE>xz zC8+v!=y=_0=nZoBe6T8lo=#h0FTm}C00hooKN05L);A@S+=G}(J%H-_ahA7oY zYhfD&OKampcV%&D|5=v;{)O}uhs=yZ0LQ7B-{M2Dlrn{^Fg@|gN^=p*4pvIvqp9)AJ z)m461_fh-yliyC%pq;`xQHH{hVqE1Mn0|~bu&7`(wyVe_uAGYY`N+PT^r#4lIF;Cs zqb92SNDmBv@dny0zp8~QlF@!m0#U@?}*A z>d(I0g?T3*<(@?x6zuUBZKz^j33>>npV!!oj2CeG$u=n0PrucSJR*6|BLg(~jntH9|^O}1ZQp&$6TzE5Or8gHZ`4fG0B#i3|U3=NpBwwTTj#?p9iw=skqFY`4yyv zKhzP6e2ifpGc48_2 zAxjP|P+`pCkAS8W+4!IgGj}t>Xg6Iw8qH+evr5*s0;Y^^+8wNot}bJ9(9$bl1PaT&qKnyi7?!MDBXe%oAU;n( zqe2z^`KPYB=e=G8yxH@GIkG>tCQkkC)xvWGV%oLddCJjt^h3CB_=2-U$w|{60CF|5 zgMbHmGetxK=*&XzzRO25tY#PqWe$(cU;2!?t6&?6IAO7&rF-1jgcvq%Xe)_~dd6*Q zN6si3+oj*`b5FHqTxQlUuVMTm)a@pfCQ~6H-jSo$FOS;K9w-12RxN)U=+qO}2azLa zu_yW7^M{+A28Oaa=jCK0e_DTg->D%hn9Iq$_r-&6H_t-BG8-bNS3DZ-L5KC2xPw-M zpSR9i%!UvJm20R!&E2!fvCCJ6n^z3Nr6RpZeLOk4FLv)l&PtSg#`80nwK zNo*5ibsO6BQZCwtTd6N_1+x9a-_ZQkW|g09kThF>GJr|QpN>$nnA`&qancd=682iE zj+NAKTf_>ru2#a$T|Tfr#t*9IWwTC}B^;Lv0r9|QLqqt`@s3O!(NJpC`wo{>%`?u& zX?VxHBd`&$UG~$1JioIiNNx|kuA6*H`l4(s%$VT?K`#MO>ngJhc!(9VPadI9fGSJ3r0WR`fh>2wXit~z2Yr*4($u%*Nk7~=Pv_X z^gP_t`*Gj1Njy)MOc;<8uza**&5Z#~NFaX)R$EBtV8Buma#LH@-1}9H0ZTZ1WB(D# z36wx{2A^_8^)6BdkPJ%}dh3vva6YW~`0==%>s*oi@WrN;GCks5o7D=tyTc~sJo-f` zZQs3RQoKH-Jxwd?e8n$bS)Ofx_h*uheHM+$(3@b_;HVirmkaZY*aJD8CCDa?3S=Ta z?&S+=A|pRK{B%gPpw3D;Z(PJ$ks}mX5kD@1%T{u9pBr9=k1wDKvO|R)KFSpK6s43E+ zX)bb#WY&DeShoMn{rql5)kpC<=28iQiNA$Zi3}IRg$2kkT&&sD5c%jAoL)tajQ_Q@uj;u-(Rs z8*Wh%f3qCQ#DgGI@9x!zL_rQoxf;>ZuWd3bJgZm7uMeN~Vtd!(*V?;^I_cm1@^%R7 zdfek@f^l}k)n*yXf&;P% z6b&EgG8-heY-`sYiZB_WNZ4ba^{2X?6ds=UkgdD0SLdyR&OoIKHX?`USA0U*wJ?{t zG!qIoC@epiLM^Cb!Ht;Bi*$iH6zS!k)5kbug^a}JK{j>tIu-kzR5wcXirg&`)wfXW znOVyY1t%g!a9R}m+fg2|XTHZ?g0mvCIOzLhjrVqU>D3MgSUiLf;Vi|sy+alshAefE zSbI^h-_(BrEaD%%bp+1uy$7A#UFF5dR9uY&Y4x~xw+LEo@j93~LDdgKDun?ymcc0y z3)`ipaP|NZUkjNJdwYA2V)=B7v_K!Gk*Kin(Dbx}O&&ydY!oA^NT^QPTt9YDssX@I zGPNG_krj=|E$+C3wjR*r6rpte;x>pp;fe^ke^n>mHCoA1YC9zsPP{D6cYj<%Rjjj` z0sA(@GE{~zuu{v7EgUsM5Y0UL6j3}tT{yv#CKW7(a6(l~4zYxzVwVob2Z^UQcFnH1 zOO^mLs4qRKgb-b3rQn{{UaEQiSX9f_k}CFv$Nz>vJp8iGuAZX3R>)5%b3WmvZSi

    dbik?#F!ekFly^^oj~V5R6u;xJUPtgJ3L~{aH2uAbO4NpidK5x3hb)nnJ%-U zmbs^>NM1Q3VV8n%aYA(H%TZUXhl^I?znTxG)YSvZJ|iO|OB)|EWt7VL9QF&xsBhw~ zHT491wQgbD`IT6*h`APOS%X(zLvHye!XrMn87mdLSK4FO`qeA74{c!YBB*_Ua)r z{wptA_rUOSlog6!QFSa_6{$R87_%3B$uP12iah^j#aMH({gFoFo->VGk=KQ94d;pu z-8rCz!~;3`=c0=a8cjL{I2~VUg>-yC_U{0(g#5g*^9j)^&tOtJ?&U=zuRy7+3;$^G zW>sJjy?#je;PN+#Upt4J0YJ64?LYWJ+cfEpLq57@`)e3d&z)?wWH09A;E=Hv;wOd@N>8Pco<7s*2W zr3&^ljGkhrZ~N8WsiZQKvZT4Z2c9x2<2EdLk9|1LwW9_DIn~x6%c#ZAURaKvZWRK8;J@P6*xYCXP=GDiHT-*QzW#^ud^F+Z8P|(r#-V|B>nsd=g zcyQH#Zw#8VRUyBp>5;eb+SbdcgU8l)=$)V;zq-aA`{NoJPDHtOC0}@Use{oDXeu+h z?Zo;B_ZNY}{x1S$V7dI_$zx{ESA=qvZdkC;_9@FX3*{(JcR2;br%U8tM2qwZPoHrj zu9MOFT6>oKysMnBTk%6TNl8hdGacx8!KF>*p?Ls$BKi^(9?}2{-=fT3H8hNi=Nllc1O!iM+OM#J zR5wq=aal2?{R(n~IVCvK-Cm{zDsQLCojVC?jN*Sx_tu@%?#2URl$Nu`BSRR#J2v2<_H zMH+daP*VHPo=(v1?&s&%neyiUQFh(&RQK&)G!@;HNTMwfSru88s3_Tc*KJc)Hl?A2 zD0_v7V`XO?D%pF_sO)jFw{!fi?>ScM{`K_F^Soa7^K{qO=W~6o>%FcMQ~q$u#j!}+fGx2LB-OA;^|OD*KAXJ1sf(UvT2KP-!V zhTC#lLqCzrlyzSf#FR@XM3cqgGR~mhnHA)zW&|m3!+pUpTwY(wOGsYvqy4WRczkVi-t&Hrh+572hR!@-iU?~;0bNgi6uEwxw1$G zS>-sumCmah*-aX#CN}1kMn(n%MosJM`$pLld>utGRhR;oI&vE+WJG zjJ?)$X+FhNhKYyV9x90nI0=VP)ejWDz|vp^rGQ6F%8&lII1nBjN%NTX3=J&!MO zKZrPD4HJi(K^?J?Gb817WaO=?5PnmvA1pjNi0PZQSYUrt7QhXf*w%$0HhAL2v3&F%sC&5XgtV@>NElP!^DyV?1TXL8d*e4n`5FV@|bA8L))5q*GT^`2l z6xAYm9baif+fTz_Mm-H>sns77ZbTOUoZ4K zUa4EVR`cZhH~F*_TQ{DX(n_Lf+#ScJU;uBVn#>%YZ<>^ z%fwkW>%`C*>0|dX*3{JGECDJUEn(Jhr77AqQ${&Z!@^PewaL!xPN+kSS^$YE77_#StPno%M&pUc4bH zdq&~?zh1k#3gU7e?#|D_*kd_s6uk|k!)pK7&t3O`x4}qNXz@Q9Kd?i`DWo2}Y z=~UU6ejfLU6HQh7zR3=y!=pFokJo-64z7T4A-iOFrn{4U!Nyg;75|$sOGR!oU3xcM z6Cnz?nAAluFoI8De2&lEDy78`OhZQ~ckSBs^>*{fj4dBMNL6p21+epn<|9!FD5qn2 zDh}RvTvXD(jd99^!XyitzA};*z$gXGOR_0OILZ!g1aA@)i}@uH`5u8jE3oN!b%^vDZ=?^kp+!r8UmQB^ZU_vP8a5VI|`+zIRC?1@E3e z)D^Mxm5eqT))srkVky)PrM)RO>C8RZm(+tfbrr?`eJZc8rjyzzhZ*a(i=ITOH1@Sl zrcXNgN%_S*(s`QjUE9V)k^}2z%Je^>7L}PaX(gV=Y#DdlcS`YQsS8!nmhbJEDI!Lb zPe)wGUM8Hfx!mn0W1Ds)dfG;C{AF%lN3)&e5qVMKSADfG_+1a!hV5~>a!>d~3RPWP zQErFTw=3t~Zl3>ilj|T}J3@`k+Rt+L*b(+2JLs|SISDs$4(5qO-8G+?tr7E z8>RntbL!Bs6Ih8xp)#@OU8<*C1|l*NgUCS>G#RCV^1M)%CYY#4C*GAgEqntj98pus z9uv2XWGWZ+uhNJpI&u8vvRkceVuD{=A-(e*pVnUG1cyS75z|a4n_%G?>;tL$^*51} z$3v^ANjJrvQ*eGuuW96EbKu}mKs$1FPAPg2F*gCBEt@b>${DPk&)QbVsZ&WK=^w*C z?T3mCiM_A1%djd^qdqk_F$O(Qr7CmnWVGO2cDFZ&=JZYOLfc|}j)y6}6++MRG`2kW z*I?1@g^jv>pX^+Q>??g&5Un&6{xhj$RxP^2R_EC^ntWz#{L52rI=B4U)Q(GRD_8G& zLJ9%_$d}`8_4c2aH}1&M%ZU^3xZEm#oea%jT{>y|p|IEWzOaeOYl-wT`|tTB+$A?C zXL&!aIG0Pq-lgXj^GLZVj^}r(@xn!@mt2)!y;CzXV2_3eME-m>MkZPgF0KdF<{Xks zismFE%8%P+z+N`=n8!@B6zP-69^wznY1xPaJHJSl5d55AtLPa&qH${OOpe!rPN2f;k(cm!5VoL5$B~#v1&-Mvu-x6eYr|FOsF)WzbB&{~*d)bQ_0v6bV z`?lme9bg`^|8smJqU zpC?Y|CckFVWtr2*{1N@o$TkhF(&3d?jtr<&G!a`TldlK>!IQm)hR~8|{##=~wZs|y zCqZFqpvq8b6h}It=&-j4yWJRBx*Ix`qyE2kDi7E^et|pE;+w{{iy3McHSl_O?R#uD z#?`|S&2`OvqzU=aPN@WdoebP^sc+zn07=+(_oL~T)SlXSc9u4Uk4Zt`zGImHw4%%r z(26W4ZsMU!tiBgb6r@4Q7atS1k=WkiaQGWW=G}3i@)??vGdUB$QbfKLmFO8CgXVgq zWN=%Sm95CK`DNLw@IGCZ#QS7Zf zGIH3=BT1^6ReiBJ0-tE7hg-T5zRe#hwe0Df{r>(;CoV3&Nppv9L#u>zZ&y!e(+8K* z#_xR~5E?&Wk>-)scIM6+vJ|c#eRUIXVABLTgNbRC&e($fBb{+w^9MR(f_J)1$kep; ztTC(d%)3?^))#h|rKAJ{_jcoqvOaHOUGJvWofCr-<@J*>VgLBF37%UbDjOw$0tzU0 zHgMJYm?4GpVR(%$AH77R6!@D!`nr8G0u{>4wipM#U5*=ST>U; z<*!&b@sc|ml?_>FwEbt$LXh-=@hNdp;ZaPz$$Um)`dx;gA=&{*g9*?DA zYfBSTJ)w=6#{2YTh1g}Cw&qC zt!m_qTiIcsq@F_)}{yu3DGgRb=Qq2xPjIou5Tok!rjk2<<< zC@*Ba*1hISrW%o|fnZ^oC5CqIUiR8I^b9?FOMe5hlLpw7ByQh-QBw>um?ThSE9p=+5{y*yN~MZ_=y6Ae;3~lEqY0uQ7|U#&KWLn#E3AdB-QYVq9q3KH$Mq6= zzQr7)V{hbj{!lARAxhR_16Le+zXsyM1k+2H={otHp12jwJRIh) zx4$qyx>Y`}--$->DBD7qM+s82JCiC>bz`UD2U8&3OX$gAss*j17L)xzPEX@os0E^*C!Gw zRgxJs@i6tiT4C}I&OyRYgBQRpAj%HqF)NJLVpT0x?0M&V{!*0(J->cV)Dh3ihE{ej zbxCLqf5%;Qctu$@!wJC%MJ&*o!O2UPzJb-?}kJ zEfL(qw7L)&uvn^VFf$6B0(^l)yY6&Rj=~M*SEh>E5dZn6Ea8$mL&YC z|F9g9uwIfJQUeN#QfE*%PnBE)S!)xrUSI2 zb(u%39+_seeQsztD*IMM$#*86dmRbWTYSsG2*i$im>kt-?BN>zyRI#rd?`cW%tsW% z`8PLxsby{p*b!4gANIH?$(ZHD6J~3I&13ZQI?=107E?j;pk;Pa`)1+|EcsyUE93Oh zXK4dxIaWijh{NM(UUK7>N!dp(=>c)ZZ!IC8A=RD;Zx-etQ%g6F2MywPGhs?CyREG;wTf90IOIAM=LCRQr+9BZ$@z z2^q1#FJOTThDZx& zed|)6DXL?#o4{c7(SKo9t#K}i&9j77w84VU7?1})*Wl+mQBe|P4@cuM05SRG`&KF& zlPM?NygJ3{Bl~L);A1rTYOM!oxEFWlK=x~HQb-rTIJ*-vF0>vaw8@%OjSwOLi9Ihd zr6cW`6W?6fXf5Jy0np&fs;U&hko~!%u1-7ELFx!4dw@^ebZ(nh8PzMWu}ie<YZF>`M@enw^U>$bBu_=%W8LEl zzRXM&*1!s2Ja2L^aaV&>ZD!j- z?d4|k$$}F3c4O`x>rWi%D%fX7>v~MB`RMaH*&3>5z2J*SzGKACmn>fuDw9&R{e3AJ z4jMc_=1bI0#Q`FNZ&`4gr>F1n5FEY_Lw?YTMi6B|%%^c*hUkH;Gn~43{_KQ_;5eO4C$2rl z6JCx4g9ruk$oaiuQB6Z+o1MSjrV%sb@GpmjM22!%kojXXl`_y;HBWocSy+al@TojJ z{PkI%mrbh8N$VTwAM9swA#)J6>}J~3Fo4gC0FT`z{j zC@@j^xq_DxT?HiYvdkmAB2u3ghLx7z3@adE{SB-d5sYOqq?0x29OE;qv0IK{f(dpS zB#dW`GR+Nkh#l~`$l_+4u}|z@=rpBhT?^iR(#kBTg@L$wn-4UK3hB(QwnFMmF42`Y zG0u=`rOq(QUtxKXQ1VrV%l`-n>Sm9Fc(Fc9AGFGiEiHOGUVesrY7ATy?Hz(KK=kD0 z2~s|xK{pvJp79}A#6a)jWUQxGW2P5%ikf-V*~Ny;YZUk=_H^(GgXarHx8TWCQc-z1 zpOTrGc_Hk1Ro|V|po)L%2Fwq6`uX{7eVp%**9ks(=w0&fu^sSXABwe~fzde>Y@SW2 zz*asHmm`li;DxNm`%q=xUY{HuBI_VF5M0?vMa0@c9$C=MkXd; z${SZ`YG~jF{cb}S{M87Stl?(R34&&9pWgn?CQzOc98~L3Fe-6xGAot>9n<}~vLvc3 zdmv21G*jhtU9Mgq8 z6lKk(P%!xcdmXb{bjXtt1l5^2@5u%}h-12OTw`yc*R!6zVrli0TNQhIfK#nWe{S*5 zTdf2+B6K0thvjn;=Q9Bf&GIj|hy=v?nfW>%(Iz~*(5spa4UDHgh5|*aJ4H0Akk>t- zk3I7*ArT-yDDxCTfG-PKT6s~qzpVtiKURWABVK=@-z6D7;gJu)9y|&c2S)7rfwdD@ zn*g|A0!Z##nE*IoBqK}!4o?fh)v$(H(-&TlB4eXbtWJ`60@*%RDG)y>eG38 zCz-I4$X8Re{dNM0`megitd3A_!-pgNYUg=1kGJy}A(=>i<3D*pO$QojeArp^6gt|C z&-kE)4mkCk+T*I}|H>YiIk^d^+~!?1(_Y>bprUwmB4Zz^S<=8< zaq(rHD}alJh;c?zAfBIRI`Zo|h8Fr(%Z{n;5;^P6hOwMFcJGta)h%bL(uKlGx(Bco?j841)XS+<4DA-0fP z0|Z+Liz?)X^i&{iaF{L^tw#~097Ae^nrqLlMA?QaZ?LK3`{Cd?j|1m|p;ge-Zrjxx z7pa@D)AeS!EanCYeLK0rHQT1qgNWy!^UO zkExR|Ac!&f$RYLl_(Xz#^&IZc^=hFAd$TSyJia)8~9UAxUPiIm1Mw4vNU zI&au3aX7wdfkOvU{(kr(YxzTs6;s5zppzh_v@lk}4TUO1*gN-?ZK^i;tT$v)KWBf* zxes;>b0mg}9HI2=cvU(h8*l&uiayrjr3`poWO$Zj5Bcv@Z(C}AP`$C+Id8=$t6(h8 zAvtvrk!54zjuGU^8F|q2WmDT%S9fLi2XrPTQ}B*jS(+If$Bu8QTs642TNv#w^MV<2 zVB7}%LE{u1xps`$u@_J-0xPaEuJOqz;FD?ZB`L|N5|K5SNFb?R);a}{@ez-W^MRSL z7YI9e7C`_Sk3Ep-fX#aLhQizM6+`cP6|QSP<1MhME#9`W7^FQCz`FNvvG!Zvvb8Xt zhZr^R7h5io1wz~sWFpC?%UfPZz@fY9Ms3iwDbc<55HdtBE}k~Sg9pa(EQ*W->KoLR z-I0G=SN65HRDC?#kuWtIl-a!Pw~Yk_xDF+e#zGz%3$H!USk!B_H_c3>%?o~ZJZ{@XvaZ6Xu)+J%8~gJ#2{}aPPBZM?>uIeT z3u71y<83IpWI2GIPK)=gILO!a8H3_f{OgL0#afZ^`BRahVPMEu9ZBHw zP0Lx^k(XcE)u-P3?{%_=Zy(SBT2nh-Yh4zv$?U@bj|?SVp>l(Z)~%=uHm&OGld^rH zbRn0WGV6I5+JK;NB8Ouci`Ak)NWVp%PZ^EXByZ>&Ji@85%jos3hMB`B%m%DAG`>LW zgoURIc(GuB`;Q=^G%Y;z)uI+0*zs~mXD!$9G^CpP?8<0!1H+*BIFLrg$s1s6fsJ5o ze6ktvx0GV*nhqJqsH`n~KDAu`Ig@-Fdh`?Zb{K;%IsStlRh!IemKm=MfJ>2r^J2B& zEJE}4L&1q@T1F%e`iLM0C{kav*pwMxaGuA7IW<@UA`y_zSp70Hs3`w5uyR#>(tX%N zo-T;;khZ^Xn_KEl%(NBtl}TdVZtt!XEx{YNSoz@rP79cx7mYSdBz-ldf_|NhMyC9K zD*zl^Ibwy9O>iEkRBC;CA*{%hmik$AdHwRodq3SvuvnKLm0zNugg&O!0P{u#H$ zY9htnh*}o=Th@ss_*cV`(ADIi>u-RsY%xTiDVh$Y>i`O2IgF#ol&VRNu8O%FN?+rR zc>pYDNvGGw7NtTl@Q*o+QgP!=J}mOfCZ9s8Pp+%|N_*)63ho2iCsk93vP`qXxD0Z2 zs^~2O$d#0oZoZ9(xM(5>Q(8v{s{|9^hgMIxsu%KXru1)V_YVws7QV_TN>E9(cm(5I zxDNj(+TL zbqj;?PUH_SSb6Uto-c|HXhjg3nwN7`f@H~SUc>YC*+jJZyuKTieE}{EjE#&eu=2pn zs%W{b?~I(g2YIXY8%^RudyCgmd~Pxu9srgi`8QY!f|?$jflAgu7YgH6R0+VM47vSh ztv;kf;eW4J7OAYQaQ$tnhQH@_cLYQcLqHTNA66D^08tVPq#obeDW-7?P2TUyO2N&c zD65Gf*0s+*=zLYW*VLUHc+VKrci&SEom3nH$YZ5CpOyS*ZfDL$^mzj&1uAv=eiQ+w+joro&CcO6t z{on68tc(OA+CxLwD&gjY#eJRoXM5X1)24VKTv%yAll6!^wc^0YNYjMUg5Ldg%~hLN zgV4IVm$X**g8o$Z-rrUDp}C6AhUUuDG)tgp4i9*%&Or4Ts@AtEhb5k{RJ*;@kXn&iL*!f2H21@I^5-2Odavl`Oxp2Ff}r_ef?T z+rteBadw~*I(%X;9UYgFZ!5AF&`RrCv#uD_GvQz<5%;P{j|Nz)2~L2D-G)nW%~FR4 z2F~{ppCfLd*Y2pTy}xs4%0^ZYwMXT;9*VBw$d(*^4Gp3#jKwgf%j`WfFOLz^9#cjR z?ad!Y{RE=V9UZxlG!q#zXN5*kqp=#JwYa4BDhDL<*oKW(1ZyU*w6hxmrL$q}5t zCY{s!{1=Ft{txqpS|WAl+1Hy}|4rGS$I%LiS9=TvomJkrXB$OuT>c$_iNcbIm|>XP z02!pNY%lT}T^-#1`FU{L#7h|5uH=tDiX<-!c{#9EkpmgrBtdJu=k1J^xswPBk0g47bTL zw!=_zePA8P<%A6CX5%tx8}F1DAEk!d^47VMw6PK=Kn~}Ap~sKh%6nkGZV**#WsrF! zU0;xc$G8Cf1hI2&rH(!XsxZ*L>^ZGhou*=d-wM3DM3M4a^spm ztipN*@~wGz{I5nrv=WR{|4%pARtYlKKF-G?#lO=Q?u4=7=%*E5!cj(oFX1#Z8`~;= zEDhSMP~hHcKSB^y!EJmwhskP1;9Y z8d_S8kmHhlJ7xLV`?*_e5=dhTo_3McT0y6S=n2r>NH7mItsawnQ;E-@PT0I8W5YEF zY(@?&*N+GGPtiypRpNZgtQ{3Fyv)#uru2UJBx4);0zv5sWQ5zrhKt1{&%L-acc-e6 z1XuNe;Rui?;Y0Wl3@}7l5^Ra8L6M>uun>T!*yWv@vA!whG2!ousrX%erF_e$5px@8 zrwhbDJNW?ZbaYGEPM>gqZm6{~A&%!(T(Z!X$%ijoLJlVPegs_$#1QF!uH-sz92CO* z;aE+*T3$OxdQgm z0lK341-d%Ha%sKD%qG3KbbB&G3=5KAS=DId`-&Yogik`mY|$I7$!xBr(9qEhgU1qS z5h5h_&Z{Ij8irr%(z9v2oVS>aJWF>mS>^*?4^Ss)N8T0oHJIta627;V3t?elkn;eR z77e>s&{L@CrZS%=*(N_M+8{o3s~rVVdk97ra6piKH@-sx#t5H$sJffZP!R z;~10dUK-N{`^q}diUGU^2=+zR>FTy-Kcp6TH4ygYL#tn^1}@K z^u5b;`>O_~jn#*8t1{5??~@pA1@>t2YLBNU1vIcV1DUBsvw@~z9oWxz zJJDu+_xQ~Ksz5yiJVCyE#sNWYHu3Jy-M^*XLLQ=W{eh_x9~k% zWJom|L>e;g(;`X&dyi*!B*133}xiNqZzt8oygP`K-;ltX-8;+XKj#)vW9 zrUVexOKsVVMqf9zE_oU%#-`h7#;2ClsQ3`{qxJONHVrfq(g_F#^5O?W*m9UT@Q}NE zwZzOaA=*52f@$GiZ&^bLmaI8N$750KYUHn&q5kctL)-X#cu)W50RJng__)V$E;Prz z|Mi_5we+MeyWXjCLig$CjFe8}RaP-`_-EDX#${IVq{6>%yEW!KFVGzn^F>%io5qsC z9STKFuuMTeT`)_B>r7=Ge8HmYbyf*7dCaoK7v{(2>})n9$;^{7ZQ28ML1g}B7;tf< z(3^S+b+Zo%<)epKlqB zzNrTbO7b7Wx*6EyosyDrc579S>H47SL!J<0Ixz>bwYq`SHq7b3_?g~j+>88$>k5$7 zhz4y=n?IL(6KK1Fs^|t^K&GY|?!9%t{lc0AGz5t3-sF|)Y9_eaW)HfUFLilZu$TXA`AHC=9?jC#8MwZKu)E!`H zH^xR8MO%B219xR|K|{GI_<7X_`5n^p5?=gCi@oThU}N!B8K#jC*1%ADAA$hq`-8AJ(93os%) z;CVa`7(#_ox&Vk}>fa)kvy1J0d1&3p=&7@znazX9>IN}il^?iJvt1Lr%^D%nf)yey z%EzD+&GfiMBnB~%7v%{BHiqTH2Kx<%!=nxkaU+{n=AA|cGQ_G>Skp2uz;QYydrDra zNwx4;20#{ zp0S@#IQ9{u7<=xe?l#?|%T-sTcvm+2`ssSE5d6y|_y4M^c!A1{W&-h0o6UYvR$BxU zvFHj8ScsJfXYRmx1Rs_nLU!-eNtR4_`ls2tU0QCQ$ac1_kE+uVBpO3SspWV@W)Vd#lv}p68r*!fevW zCuiw))(}1HERs!`^G^xl#FGD-q*nVG7??DrSULs-1w6KXTMpjsB2RR(?@{_t&~CFE z%j7IlkEg5;2t0{&m4|-cX5MCC%n>(oQmS8N2!qmYMLu-&20#5{qY9<1-MrN(B%Zsn zyu8~qb2;hib-fTAxWuL*%WTNxTQ}o-uEnu`0f*_GTo7>a6MT=~0_(vc;HSPS;1bCC z87|FShD%9&NLltNTzEY$QapYbflC9P#eH^?b-)X_1PgDsTraa1V6Y6Z%-$cUa;nz5 zReR>?X5A;#veO>EmlvoEg5~KLWLBeRrb>Kye*_a>sE z(1=7PWGV+ zen-_5ef@!|Ap{h>4k{Zk|3&&WNRWP+Q_Ir#F(W!`_vXpF0_K|E`Bo|2-d3v^$X2ac z8P4YdS2*2{HBNW27%^G9kgTBh<>;xy}9|)E9*HO7zq_nR#3s}GybN6EkQOvw1ogwnjT?8@l*oI z8t6rEq}?02fjk;P=_*;=kLDg`KC)({CL`NO?Dq!1$_Z+-y%W5^nx89Sq%kw4 zh@@VOk_)UO!!ow>Law z?#q`~k_$No@~}$pbB8>Bq0B?3AIQlyy7m;ca=@yT>(paUPfs9AhCgRF&EC^$Vohvf zmT0Ko$t4Or8)BwSzZ6e>ueT=@Mz1mdtH(zbQ0@Ow2<-Up{36sKZzTvdo<+>r*sE)> z&I#MhR~V?3KLi=qDbbD~^Q@>)_!GQ<`6c^taI{#!QV0tRRkV$4l>r7^MDQhS ze*O}x46HV5`ten-?5W3>kC;yMR#2v-%?xQ^$EH|rEzSsAN}t(PHxP;9Xa2pIoh``{l&Qmk(FJkO2la@1gL ztRTQ%eyxxx#onXNYm&)rSdas#SNZ;52nC+rV`>R&gaU>x`J40b_Eo_a``-w*3g~2( zSKpNvKxj5J3kJK-CWgnx8o*|O)}~g+iJp72M|@b3+^%#n?&ZtgzxNg@8id<6|D$mG z_Ku}eQDfU9hef9v7?xmZq#K`qMIP*58CV30G-_@o>cEfsXBP)bpWx!)D+nrBEKu=j zr9D{Ygf|6B-u%49@E>5=)wHue5mt|AfDhm|Bqya=Qf6ih5$)+l39~-6#0=P90o`o$ z9W?}<1}iBndFtu8%8eZgU_pwbQFa;|aYdOR5E&`g8)Sbg;Ew!z0XM;3*KT^G`+aU{ zm*c}s1$Kxtge@x&#c#K2-xs$A(mdyVQx#sn&F-;ceyf#OP5$xS0Lef53lx@`Sey!v zMMq(%mX&Cy9{*wC$}gMgbh&ImlM5@HBMPmr>8cwnojdsB-&k_jjYuj8%bCCSmti?u zCXlck`aS@5PE7npjTOZc#TS*=hAGSeJ&GS2@_=tOBb{JI#8~C$%SFp8N>Q}c)L`=T zzj>GldBDBfm{%6?t;hF&HE}@&lf$`_~XQB@ZjWE;+&rPA03m?ghVfd-Vku;{Tf$9Jj0TE52hKwOAB{&I~^_EM|GuDiwx$@_^~W)qPuf^F{XI`}@L&Gf@uEdSoZ$nU7(~$Qxh-j?BRfxz8Ci6%pG_;-qDUuxN{O zGq1H-PfYX>_h)=ho#KTxB;j|)LqbA8{Sx7m`4OgmfyL2_V4qB7O=-i3YzJft<)~is z3BP=o72m7I<}Cm9uU+w0{O!$t|C^irK7$@~tmeF9w~Bt39=46AvU6~R;+hX(qbdD* z>9t=vJlHX-o-38hzpAK0%izI2=bywAorQpH?%N241=sz7KfyTj)nONhLO3}PE5OOp zNTPXI-3vaHikGk+d9Q4_gg!tt0|R@(c$Ov)nF4N65_^R5pJFuM^sG`|shAVXwM{Zb z%6kvobeijbdDA=TsvPzd-f@WU+-_<5yYwoVg4BZD;I{H>1wW{?0O&4RHPkfRVUJ!8 z9sbhCCO_Lex%Zmz#^h^G1lhHb;kl@lO@97!wt3`8Z%OzCrlXbpw-ggLy(psAmqP&p zAl*Po7N|^r&mMtDZP;xh*Wv-YB}E{0x5d45WzDS`{%2jc@;5b;F4(g!l7Z^XY9zzg zKSeT(#uu%2>Tt4W$D0u^20N>yO3w^&^SwDj0;G5nf(O_v;{mXPku&P;FL=N|W*hgT z2K!343&tV|Jx6Y)5GAK25-2J;lNr#%A}Zy-v0UkWw*y)fu~|)7-@g5})M1jipDbtO zdhr^EM2uZ2Zv4{dP4r?{g8m2fhi?j$LQ{T7>Sh^HvkD+fs&$q-mVI@8+mWtf z`Nw>xJ`HX@zwaj%aKz#FrA>(UA<3jDKW-4NN4QanR4A9v&s>PX;Lg=`|FPPG!eIvC%D%lxbJXKH(DRx4NR;Qve2w%@klqo z<0wj{`6TEh>fk;1PHbMPELSA@tlOP>&Tq3($+w3!tis< z0l(E1l5LmD+O%z4lz15LvjZ@itAcF|2J2_*!mHhq((X$?Mmf`W7C7H(z%}EQFm0u~1YM z!Mg3I1@D4hKcu-8aQ@)X42U=*i&e4ys$;>n)5S&Zi1N1Q6$`Y8xnSB20W+X^{=23i zszg*o1pM2L2@j@i(7FSb*>0)O4dC|^ao@$y@mc4Kx81$rG4|yt|3V+bJgy}$KW|~W zITSsz_U zq3aW^_5XOW1;;i*8Pd)KUr|$OXiVWm_kY0x+oaYdu3_JZ-g%FV38Lo7hRW>XP~an6{6n?-F&c6{M7Ft!a&de z4>p*0uyFigv6+#MXf<>b|K*{~odf6Mw4yy{6gEhuiL4zu$ zy+;lyxg{mxdytmgf#p(--!r==8ig%yzsCrMgTT+TgPa`Du=;3owE_UJ$L@O#E>Ppc z0WkL0_XwF#^OTUoS{}!Nx$!()N&ix zd@L3joWCp5V%*Qgk~pogjO4i#&kvMy(U}O1Q~mg`=$`|)>zo1#um5Bk_sS3wx_|_E6Mh-E`d$OC^*i z@Fmt_p)iPW2`~IHD*G^yhq4<|5!Z-7=m?w>X=W>+z43xbV4q zNJj7X6eb zT7|G%3p^_rOIyf4Kx+Q1N*EfA21U-$lyThBztGy@Wis%w>W0RNKGvD#&19$t&9NAk z2VxZHHxm9e;Eis`JQ?(XK5WVL+3t8U3E32(qS%s!rgHplsGx? zJ?_Hv{;1%s6x{sCCHgh}(C~_BW;>kD?(Ul${?7`uJTD)??*hk9J%n{v3k_J<6p?2! z-a!aW&KtWK;$YkGcBM@k9)>n)?laOR2|=55Ek}(lO5!YCh@ap4-DNj9;I(U7OPNpu zK0?y_nNd-|rs{c1@zVy#&S3nXK1u8E^eV%nkhd@j2VbON;st~?PGMaTd8Mk(U|d!^ z8+97L!{U(8_nk}MT`!+d&X`MBo-#C8)7h751UKRqFNV%b?wM5GMuGW9Ki+qXQ^oyy zAvRW46m37=dw0x#fd<{be->Qm&A3rPKe=|3F4R zWa1Js`scM*(andPGh^2#n%PK7O7vQWkMC<% zsCjMk_m>S>X#EGvYo{e95re-u9xhQFvmT2XYk_qKog+o{@3}s_yz-{b@2Zt1VWP6} zd*tWk7b5k~;hXwp$VAmj)AEcc{p1jA$m4F~M{JOAaSELK8MTY zf6J>ufJV7hB}PU-koXpB7C}oK+GyO7=T@7~-12YtL4`}HL+1%@VDIBaq1Yu6<{9DC zh<;_FgGD~3Ou8}mLV|-&B5N$v^k2cI9f)QJeRSgZsihohn+1mol9mtKCUD^HLr?16t6th<@YEs_t|vFvKfBc3zssnbCgL9 zPmF+76*xh>ixt9yJP=W4;>VZg*G1b<@bkC4b}~$2Cb-zC+ODiDv;VV)eH|qNTfXh- zT_m&yzEQo(co`&8gf&&XIyZ0UXm)NsPt~$SCECGZo3z7V+DP6^=?wgo?>a2ac$Gh68;1y0T$)c_6D5W(%7Ve8;ZBs=Pp)

    KLG|BnL^ ze2wL_i^eyv0r0OsxvZ7gR{{L7_98w_G3DE?uV!EC@L?AoRjv|lRUy!d>>ouDS`qtG z-lyVE6}%=EDW1eiJ<>7Fz5e2=^;#*uynliEbkigv@kF*PxXM|JhqE9-3`71X6 z5%J?-DH8s3=ai8&*_?VIkQ-U?v2s`AVE`ShNl|Fl!x z{7ZIu#`TVKw_8o;rtO~z3TzT^U1?E5+4s19o%kl*l>+;>C!O&XC*@nOOz3N2;Xtv| zY=kTw{*5bt&~<|1U$b<62k7L(D|G_!J0GuI{ierMWy4umSYSEOz&w{q-QqaE)#!YP zPZ+a2B9eBT|GK59?OC4cdFQ+Cbp8QBTvMDBJHGYkW=@Z5AiI^9>zqYpeo2f;4vuH~ zuqlP^99pik>z|s+Bcg%hL^I7CTMduC&3sOroteoKbFZ-Q$j^)pgh%|M$;ha3xHl5E zTz?+ED#dswQ!OWHbZU`9z7`*W(fMut(GlH=f(*5F7F=`=MK4l^s%J;de<;hFtuUz$ z;jTueO6a7*KTHTNX0vTpeSzAnl-NenG61N}&DO0NT|~`SzsyP}{+Pe$IZOmlYfnLgLz9okY~pBip79hyb_tA1c8Ba(?Xt{y z-6Wn;_afUVotT^koMOUGhY?GQM}_EdP*NDNwiFYk^Fe=;-`aMucln3?i&o+HsttIk z@6cD+J&bhSRIPlzGNdb4Mov@Zo{6UB*E6{>OW%Xp{c#QDY!UO;TEth1dlrXCIzzT@ zUg(@J@tDSBV?W#ib#kb!v-2CrQCeE%$B%Hh&!JzB@ff^)pxr$VF&dGimJ({t5 zv_v9(ut*7~FDBefUK}MvPn1r1!12*zlA5`>Ijtm@Ygbu)1A(0i3Ic^jk^&3mla0>j zVZXg)cJQ(t);=#Q4^{}nom^(_oj!VAkaX$=IHFBp;b3wX0SPQQ#|B3&WMuHEWq_kqA zM^n|enDJSu(2d{&br0BCE4>pu+gOPU=Mn1OXX(55D`%`6zF39K^4XY4Bq!MRV~PVG@8K*1ovuB2 zepo6dBmaC1v{e&-+g6RGr4sT%GQ`r1i%zfPhSOB=o-X80-Z(<}q^JufcHgeL zuRSY8jrCA?{IPv>&y7rPZJ6AdV0HTLg5GL1=DOpcbsWEy2@e)Rgh3v$F3*`%)xOt$ z&agHGVlU1keG#f^8OWK8dLiBS&bO1>_o}a>Pw45TnVs!LxDPtzPF@y$z9#LKIhbmA zE~8X7dzUVDeED)t)cwnJov+$QEL_wD=t%$NlNS?Qu4JGRzDOThYTq?gwf*6Jm5nyA z^~E8rVMah$xXgmCb@K-0Z5B6BO+sDO=4-1zBJdePYHRz$Ivj0wckWli?+>fD)Qioq zEiuG_BrRtI>9y$alC%`9xKqY77x6BB_DUMFXO6tVg*qQ%;YBt)(NlG)zEMgepm>t~ z+VMl-Cy%z#y??ZIUnCXepfuBSAi+#X3289>Px@;)9H`^aV14FdLZ(9QqFLAtUH)?p zA`2s5wLZ`F?8`vszA3oO+}fqcWR9C{=iy)a5_}h_{_2apXBxx8#;OEGcMe{y{aEjT z*a7f|%TOEVIExF8NgRi_Qnr>cul4@0y^D*G(Vp%N8m=40Gpx_@28V`%pR>6Ybi9Oc z!kZj>T?+tQIYl$Mya|J#P@Rcgfc!DXp>Fi*?sNU@REsu#h!F|isS11{_Kh#|TO`$4 z9HzFe-YFaQ5I9flRd^uCVKj4cPzPOjDfH|CXJKIr4a2+8brnV>Mq!RD|8f6P(xUSi zNlXboS_FYyKuv(Za7_5hG8BZq)IH1tycu{E{Kg%tEtVLDW0d;j;ofE5nU16IJ|H0y zQHz74m1L4P`r+J2kPT*`R$ve5L55)rw!p(tMjzKx-`yR%G`KTAq^DEbqE>CbX0`cf z^In=@P#ms_(Mo#vZD)qY@KYdbQ1^Tyqz!qyiKvt*=_2+Zd4Fu&)iE+B=sm!$*Eup{ z#Ru!BUt~ABr}#iJ8<5Adly}k>MeX5EqRLmTq|*o)3F_BedxkD2_7Ah~J{tqU0s9z2 zKt9v;jJ;?UY0{h|9#lP)$Y>Rj;s+Rsv1QiD@TojA5@z&b6-`^Gdvia@<^%@gyUNOe zcm9ozn>V|1KeIXRXB)jKeWyY1)!&R7wF4M30=KV{;eJOg=-dS$DA;7TktbfdpQ z5c?v}aYn~#F~xW3LhC}IQRf`CbHT%LA;TLRfi3g_mF05a82kxeE`}}@bI|(>3!FKV z@%HW8)YKz+t*HIa0SKXt%$JH7q@FQ#B0Vdj3ejo#GIOFw&q@`DKuXOI0$jmdDaiWy zb=Vx^564%`}l_YbWIQ3rb+Cmmt$(#X_0lxmiihV&ua0~qWFb#nG}c{BkWUiUEc zp}=_;mqGD#!2|og62g)s2>r_N=#Tmpc_(8N6ZM%OPsk2hv(Q(+wARsivztpj%e=&; z^feZVQ8<6JQRpx%A5kDe57b-36TCP(CN&WH3=)DN;#q}tW{c_!kaFA=iDrU}U*9k| zyz1Na;Y*<7JmbNP1<{3R^n4<2bir{^6l;Rrm?^`TH~!dBV?S-yXm23CrzsZu-tlg1 zK4edOZcs?$g2Z)kx`pZOR<46ZNWu!CK*g6i_9Z@Icu>0)GEF0ilpNm4X43SfIRav-79>2r#eTxe33jAkZ!jtP zq>qSvMH#k$S_^^F?^+{*g7T*`1=-qkcuKEGL9_kTqXBbTZP)9tGJ`yQjA>L6d9-h~ z9UqOkMe28K6NMyy$+4|(Rh969AqNgZdHZ`(&n&UYpq^u-HBD;)LYuk;h z`iRC3mBF0M#b~A_H9KQtal4c zc-w!i8$UnZITx#GaLT(1+1;Fnn>Uc{W)y6PC_Wb#@%m#IpueO);28h7tAWs8l3oA% z{_@;PPNZZeS_-vnY=!kfNNZV`1+8U=7);0CXNg_dJqLB3DIa?Q|6zWgy(u&s;lA?0$=X7?S#aVuqhgC(mst9 z#6`fI=-JwTlWQJ6Ifi!M0+jE`2>S*2z}AOoz~r4eH~L2KQs_nbgm!3GS@)C0-IH5B z?z9J&g7au`hn|C?7=o>?V!IzJ<1EF5hoqFZSreJ&obbI5Da3SXe^t#3ZKhM+>e)ud z9?Kg$-~h>-5Vf^7a_4OC*gn#4nQbqi4gperpS0MYQ5BMDySN=xbH7vQr@hErrYN-Z zMOe7)a{8qMZ5`kl0x|QxHiy9#-21NrslnHAd4GyZaZA0Lw`e|C*rpsrL`0r3T4KOG zAfoi|ps3z@{&Dh{*F^6-Uj}Y!YHH-vF*!jjiVcY9&#EIm#Rz&F%{+pon;D_wG3^>w z?0O=#pl|?6$~^LsgFBbdW7&6Q1#okHCb)sn9n;fS56KNPXocOV%3JsV(|~J9`FI`+ zbwB<`SH~v5k|wBPc-Hs-SbOtusQb4Km^PJA36Z6=C`-14Y%PjXsTA4Q>`V52rcz0= zr9xy-k?iZ(CHpS2jeQ+r?8Y)?=DmjW`#tyF^StjL@BD+~=xAm>-|KT;=XGA&7E|f_ zIJ9OU5xQlLXT1${w>^1{OPw%4y;QJ}D|7iU3o3;Z!fMHZHa&AjU&JJN_d26sICXkb!uJk_cV zjf`LfSBfK{dQ$=qERgMYU%VtmX*S<@v0WhUjvDE1a{3T#K+g-K?iPWneh7m;#B2NJ zfrvyZ5umZym6?H;aJw;2Nv%<=IlTrSv$8pJsxWuBKyr#p4pDG-HDqu#;62P-`Vt|C zMJ$&>sE}M&4vcqg@v#lrw67>%+`6CS+qZUQt`(yewp6?ryri?DV`mUkga6~|({fj) z*IH*hk=!A*VTgPIqP4~3qigv`xnthO*FXDqgilZOiJyS6h_Vjv7#*pXi)Io0u=4UT3NMu$R?;Y|Skk9{-#3RAuYd%kfI*L>e+qyCsc=8`00E)7EUKc${g8)Gz& zjT+e7tH83)L{w}YWlZ4Zy027hp9*`dL*n{j9vrV4@yp;iB)jU_P$t44E2+ZL^3Tn* zLkjgPE3PZI?aj@9Q6PJf#x{)f(yU04+Tp?JUP-&*A$zQBu@jxEoxv6_&?u`^__DpT z=I@_$D8L1dpKGCP82Ft~IWbCJQ+OxbH;0htB{MTK!-y3?hO9%cY2@WCPI9D?vgHpx z?B6}N8j&s?%U;<68TLSi(aESE*tG`mJ}QC*2$RpfXsx1f@LtOe-wM>5DhM}g*dfD)7j3^%sVUTq@+&!wpx zx8*~}l^BKDOZdYu%R5^?T>CsYoAdMh`a(|#?BsGSa1s_U8eJBKU#1*{;zf}YH6dOco9bY7)P-3CXlpVL#rbnxx$&IXa#R#RY(uL zL~V%oA{5WaJqjiHFyo1fD}){TPhMrpFMiw|_1VR(oD@yzJG0p?>6l!j0Og*ro)9_P z@?(Nw(4sMfghtE(0Lygy1Gyfu@&*I{luo3G%%EP)Q8;!EtJyA%ukX$Ja&U_>0^$vk zm*tv~{0Cke*Fa=Lc`9#nGsO!9{}_(udnM{j>Eqj*V0GDCX%dF6dMkH~<6D1CznA*m zhKAe^*?p~i4`B6Gj*2yPYy+eID?ImWhW;7zLMa?YzuH))%7nHF?i6hF;4EM2hS)1_{}@q z@XN}_f8b=y)!cklj^K=Xc482gpeWv@K0|+a(NNJ)^u{K@XeM%QaB)IJ5R7GP)}lrG?=o3oD9j~~xK)x}-Rrklna?!CH zJaG*JKVXhfuGY=nQNYRJiNse|`{>=;pZiU8zl!@A7f)rSjv-f|D%%>_%zP{?_YC+& zwz%L~ucc?N<)O23(T=DPgpA zdx!ZwW=iToPRhm;t43|8nafcb_FIM-46Bu6_aiCG9fDb*@Bk$I%TK65VT14|%XfbD zFgI}HWt9f|L(o}St=R5hVXX?SyQBX-19b=srJi>x3u0iXJ`(}zJ+Js`=fC>$35Gq~ z2viW&)gOnf)#z&#Y!u>W1PT?R9<@8_!K#{MF$LZ!KC+SLNr_<}VgMq0LB!g}fW{9k zT|7J|ipZ7719tgH{G4vVN*q$8qsw<&u1)vzij=hhu06=L*%5R=_-Qt}S{B$Xzp%u# zO4wvwlwx~IK%`KZHa>24kIK)J4rl;mUk4K0s5(*~vDX`@cx{CxRWIsq18|(!>750Y z!BFhN9R#&$zb7J;sR_VVhkpqtQo-g@#&n-`HzpxK(%Z2alHNabzM_73wNG5O0nvmc zO3`_TMqHf11z4>LeO*w|I+2*%9qvIxWa=ONRee=URIv6Iq?ioPE8+#detWi>nJ#mOVVkCBX5Ohime=@Pg<>95(<#2${&gqJZ{2HJ{m5H{ zcK@+0ndb*+9`kNFyt`PD>XUqP?B)BDwhqO5a;JUjA(+~_;qL!6ZAgM2zY znIH=N=q~Nc%Pt~e5fKscHqd-D#!5640M%v0!8^-vk3^P}5~`Y`;6>HD2lGrOYRu;i z5&1APC|0V@9V_^WG*oD#eP3&U_3$%EIfqj`BcCGPw9wa)gQu5JtSF~xs`}#C(v?rs zMt3%`k2mV#_NIcfndEqkyn(x#WE*r_4DnzdRFC6l#soB-ooY^g{_Ak>{rLe3MrRI|sJ{xiWIa){@Mi z+mYYyeng-n@=dVaotrgRCEr4w|C#;#u!m0mnlDVWdV&hQ|KgdOL=vOOZ*qBMAs7PJ@0N7-F(KVvRsVwlOL>Z9a=4!z_#Bcu}?&Dxz)15XN7am{5a>2HX(I!p{{)z3zj{VMtOix|p=&wOlw9iSHX+>2siuAmP*tUY<3T6c)B6t+^Jk$V8!_0XbT^ z&ZRwByY$qVw(>)Z`nZURorXgao?Dssb*5XUe?L~S#WbQSjfySKDU=AaUuWxOTJlT=0S4CmtXA z5-OysEUsRWe0z2Y&fb=IQtf7u*7l~6RMjUzcw7H1V^bOP-6Z24Vr$EflJIlIcKv43 zc3DVRfm&IF&x$Kv{5JXX4a?^h%tv$_8yhF7nZ;AAX-73$ZmBcTm1O(J0zO5&teWm# z^4}eG`BS&cSqo*V`8_kk%%Y9;;o>&kIgfqD;P}*%wMx{d1_uY>;nu;d3`(UXJ1ht} zbm$OtY;kfTR{Dwwi`ZV0ASZGHMIOc>yF4qb*Iu24W%cIfFTpnT&CGn@2P-kZwef7b zzR=X+$G+U$ni2JCV4x??MK0=Z0f$)Wu`Euu9z&iJfwC>3b~v?LluLyhE*Qx&S}1ph z=2zP%Zm_KU80>h%+BB(B)k~`L1plt_=4MhE-(tGcUZDDO#I?{Art@+LP3kiTegwe( zVx7EY%uX>xKe75A6%kWaK0~m0;JQ+-z~vdgk~Z@BIDa}7n{s+KoS#mn2eF)GehE2M z7nY2Tw8~wIbXNXQgJJL>*rV#-W6e_{HZFVo-P|cE0q(aYj2iA+5<5yGN@EJ)%nX>n zt53l_zrWRUcCZ}eE?9vIvsH{lz@$nvF9f`LwU*zvhbYK4)HlIC?1xe(zB(Hm9Be8l zF7CY)L$hGN`0HMS4P54u+)T~Y>r*rG^4YZESu;;VXuG$V);$K;2;Hy1^O`)~hga6o zk~%azj;eMpEC`jsahqa>Bw`7ctK>Cw0oNsmz>jNm^Wv)^HNW#P2t-(a^+D+Id@A`&q>T& zq(8lb`&1q4(}JxIRkp7;!17ew>tWtU%t0>)Bn43YJfp1NBkU*I1R_R2Ynzi_!em*5 zhMd+d@)&Ra47<)dJ3BWrJ20F=Ru%!PZ^;8IB~qL($>qgU=tFWSIV8f|ocHau`o_kL zRaTiOuAA10hzgCnM1JmjUiK^xxkpB}^xh(aJ@fJLL68v2B9G*ei_oMl^w7U9T zk8a?J3KN!`NG#;Z_kNfy2|AvNN`wh_*(pfqk!(MF(6qA~_P( ze#$$26u#alWr0NSJHsy29I_3!sffRtw3dmB-+K#r0vt3*cQ2K~WmK2d zm@355^yP?mH2Pps0XVXLGAY=kaZtP0ZpYjJy4P)iPxlIWjQNAy+Gjx#2FaW2ZiWKg zvj7L&cdkk&Ei#LUH6?c0TSUQywS^vOnD(esZ-%mb#y0vZ;;l-T^#)Q51X3TPR7z;GWnyy|V@aT~2)$+_|kBe}mX5G-(C zgI+|NOD>ftXY8%sYvjRl-_V1?_9yoH6nl>JC{`+lHSnxElur@ajwGTQ&y@Q(EH1bG z4kKKJvIg%m#>IzPs#95+ghm7x?$X%w>NP3*w>QE1g1Poj=Owq#!vF-LXORDo-6hf9TO?I1M}O|=6WqNe2j-gr{8F@Xp9J^%vIsUbHbV43%W_&?*CPZX zy)|8p-im2!SpEbA2nfp1NWw_5 zyW=M%J(g#_eWTL66N=E15{AM8eSm*Y!(;mbmWU?lf9M2&g862{`}d} z=k~2o?#%b{&dzu4)8lfsTU_DzPRHJ9L*x{bO#*OA^u2uDb*Q;g& zH?Owc`qjQsGOr2f*jsv_Y)cUZ9q)X|n!9!HzRn^`&Qivk(V3GQnAZ)p#EtA7^ic z;sqP!gdOiUfVp}uWL3~(s=CFdSnA2C1sIA9Pe=l*rK4lK^?LT|qWbSMGqS(;g$h$> zT&ARWMe?2qdW)&<6ei6TcBrTkJo4Yaf1jOwHsPrbn#)GgP+=r^z7|aLdBfA)QA(ys zXO3FILJi8HNzN<`P9_RY%h?VB_?0n=E7Y>!r#!z#4^*ir%dEZ?be5f6e&*u?VCdo? zvt$Wmv;X)pYdLH~#07tzBGT^%ek$%IfGu-S{dW~D*%IaJQcq8fwIyjvj8llC>oh3g zIMt@5Lg_(OxuIDkabO%4aMp$h8s5C5l!@LTecD+ss%=HHmrNuQ*pcv#qO4aN@TnP*~VMg z6>c{GF2F9BzJYo9HeWMllW@GZlaoQb==I-BCFt5$E$TBVtX6GVyd!$KnpC(^tus=h zu*vm@>CXhWhUly;G0uRG54KliaLiY)JYd((+e$IHipnFqqmHbRxOGW&ml*IUiGf;W zY4X~_vP5J*_Gp$^v5f0n{PX8oZPUelKyX63@oheW&Kr?Ju-(_|6uQ?bFI~HVeFGcV z_gL~5fIFjoZBdup{Eu1u9-YgFGUeS1Xs0hTMAYvj+G`iRefh%DBBF(gk>i9+uRNFN z5oPkbkPuis4LZdM9v;|i*U`~2Gc(is(Tm&~u%mJ``G8yR7cB}`zUwJ@Q^Eo{H${{? z^zEsSSxX^tzPWjS*O0SG#KSoooDk8CF|9%9&y7ro+1|95#Kw3ku6eX*i|NT^6mJ78 zf`YC_4Nc9$*I0J8Lx+?jr2!!emP``6iqR3bALQ_ z@_<>zp1J1Nf;prdjy)4tGno;HCi97j3(VJ2@u0sQzvGt`Mn=X_4?QP&`_m|j$(Gk)AgQ+#r zSJUj+0W-fnJqy(qBj|K4hs$#h6q<-uT-7|HM(rS(*lPL-t_i|w*ua)h`(UN|=!XD> zU(6;Zo{}v3fJ!|oaig(u_KWjv2`Mq&!!zzWZqKP;w%r#ixk44nh)&j_{ zF9hKYQjCytwsvq>fKWn;*cFX*HSL!pc9Gt-zh+@pb1_zY7OBj;5!X6Z3u+_Coy&V- z%T`%#F467Lf6dOyS^^ft7|avf^z7O8>v5*8#8t=ZscTDD9)35&Mw~t3`&;QyEPqo- zY9@81t(DDv6F9<=Pp&^yh^MZuUodW$idvrK zT-C}DW3i?_*O7vhu};r5ITE%nhR#GNLH-EZeqYcp!}&w8vezFKSbqyY4{N@OHE;RA z69P}Qrdz10s&bz$bcRjU%j3?)oldKAtG(gm`p12;ixbruEg>#1?>DU++n`-7str7& z?~rR1cX7(Sn8E}rNxnUX<%s&|U2(R9VX_0p4@4y;(N$)vEqh3%IBu^T5-@?1 z&#cs#En~0ePsdQ(Q!FwDFmNi)EuU=#~I|z=k zzihryG+Kz5vuRpZ(rVP1FDyBv$JY_bVx*2dAjhvo6l%nwR$N93ADkUM^kb|0ydxj? zod=f5LzCWSGZc7_ANuUILDwjf08A$ZS2g7s(guA+f*Dr z@-=r8F4UazD1!ZQ#e&Vk8Uu@W-j4Xl$3Q5Smi8mT^X4H=&e4Ru>0Bz?|B$mJWZkla zGxZrXdB@TaTv5Tv9*Y%G2ASoIN<76QX1tK>hz#V9y+e@!DA8%a&qDWK2j*!R8Rhb( zW!Hvds#_>Q8%3jt6IpkQNzdbo@Y{rr%D7n8s7bHUE=qwFnV!nAETj2SlO}hUIHrx z_9^z%qZ?Kd+qYoEzj-y8?nMK^@_VMVNwx0WRG)_|C?1c81cl3D1NEUvu58Euq1ZK( zY3%DOCn(|*f%XXn?Uj)ekHKPki|xuO*K;||kaA4m4?}RuOAFEvBNf^8j}MR#XHpTV z%PybjZBU$C&hrl9$e7Kr-2j~IWh0BhT|y{12M>(eSj5Dva->Iyjcwm)?mLU!R|U0S zqn#G}Dc3VAgUvKzI&Fs=C~RU))kd$;Pn>F_1|~Z*bnfZx@ZEm7Mt{L?Xj*O+H6(01 z=qkAX)K;5wN~QdjnzCD!P_9E*pr`ZLMi4!~d4x)*z+7*i1!$`-`}8uNsaVjfK5uHz zpA&j}Hy7L@8vmU_$c{GxzZA#D+`d@{-DuEQY;T{THWaay4I0%|^`tc=Q4zWoKR!#H z4`CMkxRuOeyusm5hE@h}gmZE+jPhF>%g*7uT&4;Gjd3eZf&%4#Ohm&XQTf)}MHRc1k z4L9-m-r-{VJ}C;pPU2q!NKOqu@B3o%jI@=KuH60nN8c=V7O{=}BW|`fHXeo08InPO zm&(WXGcq#5xLy9|#xf3j`958~W)L&IEdjM6L0JwD#PGzJ){Ym%S27 zSlGa=?3hpd{^Apcn9N^TxNTJk_0j7Vj48jJ`wPpL*Pz@TrkmD8KV8wFUKm1ysqZ7+ zwJ1tWZGxH47|bsw32akG2c?qENF-N%s5_lP5g&*Ad`zAfxxX%D4dO%iuJXDCFv z)yx%lYDIdaXHJ}S+@u?;A3kuGwHbG=taA*M*Ee;P4!#rfLMQ$r@uLn=Kk2}v!PutT* zg^=sz=5_X-5(C3G{2`h;#md-USGVWHC5o>RmN9r;Hr6;*OVQ+88N4!Ut0zhz82 z-{~^Y8rDjhoCr0w}C<&1FKSer@4}i`lSChZ zIE_RC@rq#7U|j%p6S&3Xq$Tg$boYyJ;gn<3gxDH<-~3z{*Fmp_1^lcIT}oFR&rxAL zA%4>~bV6uc|5xcY)6b1?MJg6ta2T=cZ$pKItqkVM4*XJ;v-fwzYHohx&I22~gihU^ zx+XqRa+-=m=1g`8B5HMRs4~F4yn()V681Pgo%VJz{!K}S79Ex)6sQ*xF4>pk1V<>o z5JVsQb#Q-ouN!Q*=?36f<>2;hvdSU9l1e&zk~GnP=pS2KTN&imnyk0`1%HDOF(ok( zI$gC3TtE!6)z{ZYAQ0Bp)@P48=CcOvS4WT#x{IQmA!J-nZ!Pzs(Hokqy`RoX`JVE> z+!(qb1iI|7HcI%o4lG6mL3fu*YvU%MYpNgL9R-=T9Tp;rl2+2Xe2;qjSjG<~&A6HQ zQu3fWtr;I7FT?Chw`b3`u0tbFk7X@T`=4f_AXa>7WiD-0E>YZ~nC~~`#0+kLlEx}g zAucxgf#+K1$LZ9j&XBI7X>-x-zAvg8N-cKcw_zP6@=GP5k=K>a6usxY$#W2=)#0V1 z0}6lM8z*7I+n;`(rY~M6^qvur+Z{KY?L7gVkIQN9ugimy7SAx;e4BYfPzAoGx% z;di6Od5r=4_cs1an_+GJJ)bROP|gsT#R3{U%$;@UQ9630EBr%XV_lv6$J;40lHnAg zzqc1cj_NTGF5g}wMFV07!%Ij=P+fgx7F^6>$h=sey!l|#$9eBk;S$mwo{GCRs!D~c)s~V5_<~0Q zTfnojvUCRQzrntPABUl)tgdcGdv7{Y^ZMs41t zUle_;%IOot-9e7C*S3IO+c34$#Lb#@;n%NUkW_my|Lu^O1kck6)^?F(V;8Wchl^`A z#LJCnxnvSPL`NlvZYEa1WNf8g}uJ<-I!R#lHY|0m7 z);d!YZ}3}Cs4+7#`jnra4~&z~qu~UbUv^d&SXGo~G*M0WPohacN7H*f&$LXuym4JV zMSPW7=j953{QGu!u`n)|G26bcWHU__F$K0bA`?v=_pI!zX;5<>W>(OXsj;ZC)r9n{ z{qCnv1@QvfvwI5qM6u`53t`3kf^Bw}Zw_MJ*U8PR0Zyvb=%k?46x6K`u690N`S$HR zbd6v62lM#@a*K8id@ z`FJy@(j?a*s-y)f^69o2<@AS z6#$~ZIv{S?<;B_WTROOr8YNsa$Aq+L#;&&0B+tIPe0KC>`7YgP`^d^)x#9(AAIn$b zLECFSth98Lg+`trw#5E%$6^~O-J^G7$4SUdY>N4h*N+ZHjGPe{cfZ$2UvR*3`s);M z`ODjzj$^eg8nxHOeOrQ3?r-%rV&l5Q5J34)5(NcRQ!z67L@v~eH>J}CNL+$l!+Z{D zvaq*HzUJHLIcZz$C3kwQKU64*qUC}rem#rrQ^a?y#r7rwft%wala8R(((l0`i;Igo zY4&GzS~4#ZQl3a}0_!{Hav1;~G}##EJo5YMYHmcP>o=hDu#O3p%?f@{u0KX`S5IE( z%v*^R!t&6vO@X*Cpk)0>Q2@gD_-ej~4M$)cnSt<`3eDZWxW0-2 zMfP`ib=Kj;T`KL1y<*FIp`o>jwB^s`LnXlT*)Z@oTLoobyt%XwLZwUMkKd)w#mfCT zhUdI$RJgYL4}Y8ljnP((_*LWPLybmM(A(nj**>f9ft z)3tr56gb`gf=K&1bzbHWMY-Bhh3yj;HxW?2?Dh|eUU=e?tC_tn_>p$yd!sPqS?94m zJs|k3OE<=*O#*F4xw?9bqHsB;WThH$HW#M^DLFfe3C6#ims%>MKuV_*<&e443%lRD zicbuc_HN~OD4O*xo-Z^CK(2WQ6zKeUTX_*)nCo}>r_o98{i9%Y0e!0Q=K>HhSR}4C zKKUg+-ps}Z)@ET`VD>IWj!Ru-h3i**)-DZXlRp|{(t2LBD+t0YdHJuUT#Zf{RI8GMCYv*$Z?Ns8s9t{jQ{_aX#af@R+qs^6bR|-d7T_nWU6vV|iE9tf_gU1`R~qSNT`TU$c_72#el;qj;W`7J+jVZv5^et!ufzdyV~0@Z43bS^OL z_4IwP9Y%7Uq)6QXvFC-N<1NaM->(C4|J$vl2WErAls6*$~t%8ygk9D4WUN= zo79#6$G3u<76ngj^L6SbaI6Vf`qrj%@W0bK@RV!bLV8i2!7rXFFY`We&kAi+bQ5tC zyv=ylvoAPBU>)4ttrymRY@qO+h}}%*3FiD-HSw==;WxVwySb54R^T=qZ*YW=Aj+~4Gb_A8jQt21`)j;?zh&6kL*YyOVA>x0!hkE@} z>u)3hHg9C>hyUaG{lnqLuR=^TBqk;XK&S%~c0FjHP4;cL+yAeZ;tt39-T3XD%Htj2 zuH6ofX8-Tv0cA(5pP!$OqrC*Ym5==QiO)}l7T$?wuRG3-H~POE=Rc3B1_r)DRz~sI z_vYOyrZ=A3@!lhiPdoH1mW2oT-v;bxLVT5gvHi2Z-qS|2nT}GTTvfSCk?XO}e-&+H zU;Yn*a{u#tl!5B`V+?pX)a(350=@g7x20w1-kG=oD*tkW($Z3w>UPAsC|Yk3($>*Y z6>`#oe5>dGZ|k=rO0)U7jnp}J|LEl4xUhZk^b{`l`xP{JH-;(?<{TQ~p54CrfHFjDsadfKZ_G0cUr^_Wecr01ha5aP zkC5pTO@Uc5cmIp08vu3+K6-v}=}(~i0WSQeNBHNH`xmD^D~DK>&nH3d_q9h(SqRZe4ekqKNV! z*o6b+=u}*c{ZtX;Y;_whGuENY5tY{)PRSU#tITy@8LZ7U%{K0BZ5^TKgzq~n$y2Il z?WB<`wHed=3wQtDi7Gf{)iTJb>kHQ0N25&7)GVdDxb@(B?XGO_)s1V5?GyBoe^P0( zm%ax++L?!4^SIdSt~YMbRSJoS+^Jq<8@a2cqp4ZjWAb+42%(di&?6v4-_m;z<5AnT zH(c7)*%@s!b4ybu-Cc;`tQ(At71lNJzoYxLZt8Pve%7fcw!TrhYS&AB&dt=) zi+Fx^0_4YzL6yLOOpa7!!=&5 zUGNs4>#bymx%ky}Oy%luQHvwVN&iK){&lhbmpnr=b0Z`J?;qF>);>T;V-pMw3!80D z_iM2%`4?IslZj7;!YbpK)~M&9bE#+>V0K-tXM|8?$O9LbjvAA8DglTi8SdBJ)z#%nN6B-Sps9LCDCl=L2@v+$LQ^PE z3}2ua#Z+u|xR8DhWgi@fYlenL58WlnHk}^HG_>b@su}&xVWQjF)uL^$cb(M?SouiJ ze53aOL7#K-YYyV9_hoL`6#qu8WmTU7)pgUpg-CtR5N1 zm0Ciu3x-TcgyEi!fB}MnyFYKc$5=L&rVhh!SYHkPtt*Bl1l!lJ<7)K$RtklBF;O@n ziVPVm8zKdv5Yc3Ui^s3B_UWyyZr4<0B0G&Fx0xn?F1&nq!CsKf<->(@bvVgOtef%Sz`O#`t#@0@xFWirZqXb z51Zyr)~kH9VL|~tv2MUaYOkvE5oG;`W+gQD7qL`XSXiW;6TFsz=-Ap@Re(mb_^MBb z%gV|^V3n8s{)|WNOmCu?|H1p9ezu>k-(fuQKxt?cAi#xI&Q2su`e8qn6!rD(F0JjH zlLCrR@;vL>8R_>JCyeQ5zT`ep`B17~rC;)j_1m$kp2g&R+8iB=0Cifrf>?0HfVIs| z*7pm3ST#oGT6hrk3fcGLQ^M_~^!QdVgf?GXX}!f00*6h>%p;o%D6OZUQsxuACFwnf zgsuHA{gnCUG~Mfm3ux%v-(90^DgNrI?<29%_(J;PzD|UZQJM1>!(-MroRZlF@AFr% zS6Y!8Cpd?f`=?AwzT#92ho@!(jB`oMPc$3-J^IDpq~zhOW{SFZ1l-G!d@9%ArGP2% zqDkT!n&7gl_wK&cK{5?U`qeewp<*ppZ|yxQZTdvSbMW6iCfHn}pH1=o5?!c+jwDu{g`yWF zQCD4El;^3LGU8F{1h;J-&Ii-qwU6NYFqoRAq)DTTvn~<2463+%7YSlJwbkW|BuUrnLyIWgzz-W|_(Ov(-0?mWwB zBU!pS+v_Ct>fP~Ty-UBQr?HHvM6&Gp3j~h2S4M7b?{QYgTpDJF;&8gEZ5l;w@m`YT z>?7?L{B2`KzI}USrRnwbP#I3HJ$n0Ojny=L?_8-jgJ@>Do&^_4VtQ%{ucNqRIK6v* zT4?w^gQSM#7cIhrhYy=DDeg^MGzQ)419#a)6;6XXj%wjYO(bf8?&5 zoN0*FbC%tKumv0EnCvs(o#fWYyR&Du#TzVRzN zlX>dYEljh##!yRP6{Z5iaoGq7OLrz2n6D00szOv;GwZRwyZ@^-v-GUTAEaHIIT)lI zES{xZ*%QeTGXlzzuAMXWoEHs)h_f@b-79a&9o0!PqN1hBHGAdKm@NVt%j;?PJeEXY zI0rQO;UQxL`T2!xEl%66=|yzN_S#Jmt@$pxTZ*4>LJmIhzm!TT@K$wvY1m4CS?XKr z+t7}~)Rm%kueR}5&W=wMHxd1nOFW>$00xlk=?NOfG^hsq-6+``XhJMdyw6uh^hd$9 zi^O{>$ay?*99XVIWG0y-ll6#(E@RsSdN8IIT)ySqc&DGj+rnwOOSWRXnChUOqG z9?$Bj5T?SdB{)a3M`llTM})sWw7XBiQrwcxIc_L)cF|B<|JZWxY)-jmn`#*In(;oj z)ag^JOU({bUAitz90tc!=l%3ul4!fFA4yN(e?YyCQ|wP~zNG@fQC*Jt9bBk$vx{(p zweuHgY&b?Ja`gX6-RxR*PR7|`QKXyg+R6p2;|CYtiSEXk@C;W5aG7ksgPcQ#R z=yN7oaj>%+4KhF4(lx}xk}>6MV4YR0^S*+CX-?vk9{JnWJw!_QQS;5Mva+(XcZUxV zHe=;5oiVJ3d>~d|a_ZdLTA*VD1Z|yW$vvy3M;X0k9S0|h z=0@(w$j)QLHRJNtYLQ-gl#?}N4ubrZ45uSxSZ;+L%^TxPOP}-S>Yceis zNP1$aifIxRiha-EmGO9SXv#sn(tcEZNvcD?XFw5Zf!$aSn$0DI?E)?pn5$oD-!I6=u&&rPftZ9Se(t9j-QNuwwCq$EGK%$ z&))r(0cGYVt$g>P!)^4~l^;q8nUJ&3IgME(Q|XhQH)9OztmWP$jPBPKX0WDlr>z*j zY^IL(YHixOT2|6u7+5hoyi!n?Yunw8-lx|y)WkIDO%pm|X&eaAr{)*}jh~9PCc4*} zogIZVf-EEy29(shyadslPjI-;dU6wO4fw^y0US{0wNJ}V8J=w<=t!^UIqUMU(oi6m zx?QHhQ$Yi^h2`tm5u8WB))h{qaTN_09Y;1S8dzHP*Om~Cb91eB>$(prWpnKAu|ADP z!a+}NOW^9u1BS7(`wic`i_u`9_>0$nm2;utu!xN|#O|w+HT>2M(yGdZ|B)pH(Irun zicWoP*n@z+lXYLQsgQxHGr)k=qa4TcpmL0X##SNU`Iz`}^Xy zCLKpYnotMlcN^hs1%?tF)!E1y)X(vY?W%`FanevC7GBH)8tc`em&amgJAy;cE`DN zIl7BiX9aA|9FO^%Qy$qJ)x$=68sv_&Zh=Qm_V61ex%E#4s~?eeO-h%JFU=DW7&7d} zwMnDRyTy-m$f-9FWVX&170I5?6GuMNqx-@%FTl?~JkHgabbQC?XtIziN#l}xYZ7%9 z9P4DOqeaRMlE!`aR;LTei0_%`qtrtV_UP*^^(DOqVj*?&Hr_7M)}C9~+y#e;1$8|Y zj|y^zpc4Keq1utlUmahNOgd%EdNPiQPm= z$WSifb+{MKSr?axQ}w7PKoG{OaZywA(7YD0>rhY0)-D#e2+b*}<|YPv#z~q4J;Oc^ z(~tFeIzRuOYvUrVwIfFo6qDD6 zlEsVFFl?rOg^GVD@ewRM2 zo!Q>~PC|+|Bc-d=db9(xxE^-F;I%ru(=olz)>C{fne2@{=p0uP?tDi;zVq~zaG>FW zH3Zi%8jGvGQuJP~sTyyd;H(1G2?I(~60|+jZR9+hXIEGk<9;9cJRBRk&^Oo9T+k7d z{~=#8vI|kkSZjMrxa^Q8&U2^^gS4^|V1dKcV0Mcj*cH%L9_;nUWmvltOp8{Uu1r`c zdsM55(&gHnHxQf9c~e1}#q}$7hrYvh>bf+9SQ2a==I?vGksk{(&sv>L5?ny`sreSD z2e|hVgTxc>tmk$9ncjgg%>kL#@)SC$i2zU%;lthqokjt~T z{vlkB_6e%aIIrQ^RJ~GmSTN4E_%=`a!L(?6%qx&n?D1_F%*&@T3wZo0Ml&~hL{$d{ z7tSr&WO%hG%1dcFhLxnPX*7R((2K>R65Ifm~6(k-zPQm`vHw$=nQy^T$R#xmYFsFWcX9F;bbPt>b<6` z%1Y`hkztqX{}5TNOHkn%tU4q0D$%fbrJcd|QE9hY>tRWknZr__i;Hx0bi(KhgRZIIr4n2P9E$CasdvraGU4oQaFVmMJSljM7JsRP zbEm-kPmIO`0otfAO?QG9wVu0&*YfL-(XqZ0+xq&Wn})hW@)a~l_;u=?FUhj9A7fNM zYwIDYj*`eLI9X2`-6pXo*aR7k1ZVibtIH24+?^!6GU>Y-vVe)RQjpGNsO#Wgab!J1 z%9f7b@Pc{R^l}_qUL8;}9U8qn?Tjw;+m;eT_d2oi zP#0A=D;jCYH#ZU(*Tzf;63q3E=xOXC@lpvHciHxTHd7~{ONQ>jqeMo`D_%N8C~*2T zkjY5LZ{l9ct{Kjko>VC&)&s zNb$0>vpr}gcyb!#B7usP63vD^kX*pfYaK(E_VZjO7va^>M|w?(%jTyCW(G<TP zdfqGTw5H*+?8z`;c#icinKFqW&+mvcT_`oa1@s56yuu)qEtt%l9YyrV>eDZ3Rfc;O zcMERMAqHDL)TPJ27Nkkok8k~n33X-1#CUoYIGN?HVtdl{L5%WkzQ~Dn`V`G|#?;(= zkh`Ppd~H8=`?0fJb`1OH){tG_LM8>?(J*NAEkWg?t6+D7wYuM89&Ub8uwSWY+6I*7 z!?pxa-4z$riOX%M#h(P;0Cd9;EwOKDM;`ThYVxlc$_6z<{WmJlU?5U^;hFvEh4Jq_ zmYt4{6Z!|^(9+V7O1TxBD`p66SDJH4N7243|F{Ck%x_ttEiA2dF8x)gqWp?kqbzU?FWfP@twtdfo(AnFjgn4Gfg%eSn;YkWQpFBiY zXj|O>WhQ118mY%{-&c@^uXk}o&->bpJCg+=9s`K5RW0mxA0AiE;z(TD16F zvY}n3d8dFEigw0lnK`l6x7o#L^nJ=QbJw^YkwCApFr=B1^4K#YXWvY{T^G3jz^TKv zOX#K*>TVLKzjr(};_^MkDm8JoaJ$6Y4E~yp{YSwOX28{cw8#f;QR$28^i)*jg{$%x z?!p|7m9BiT`yg+Q91Q4W{#&519VdA5Bq}Vd#I~WB`kTGr4Zbg2JA)ZamhD*P@A8g_ zad3`)n?s``vYzWnN>ytl{MsF6C^WfO(^6kQdJM5gHl9fLJfGGs3rqT*pYy_bc7BJ& znO)TtOM-GK`8tg0sH_|BNRQOJj+&4^vzb)k_li`0S>D%#3?(*H^w-ui*X0s%;TJD2 z1dB1aM%aI(#)KFZ9;%ky?|;_9y?|}bMd;b+vj&EDAe?`y;U~^w;%<8Ms68xbiO@*n?HFdJIZVe3F=`43U;ckY~OdWx&z!1*CBZ?oz3@}YYQ6za=6-_$`{WInW8PA9^BD}(Mqk0?L!!I;5x;1yDk~!Ly-~BN z&t;>#tV@Q{wfMDqw3pQBtb%p4h!VGB{A(ca|E0J@#Ky|%f!X0mm)jM2#2G&!Y3a#P zOXIJyzdzGl_wNGBFHZ{c^TYeJ1h4VMpm47P0s`jeHK1%@eVRs%nI;yXF8&0PG*LXq z#Huzr8_%dqZmm(b+3SzJBUAKlYADhfIh@58@mHf+@6r2LmF2Hm*a4`{*3r|WZ7PTF zjf~_J7tBQAB7cujfFdV|YIHf?^I0QL!Q?qei9k6TBxga-Jv2f?&;HG$T&`8<^1?@U zD1yKg!9TwI^~zvHOv?8hkpQjMMhN`B%JfWHOv=t&$(+?-`D=01wFBoBxPwGm%>(Ur zqhN-}^t7+TD^-`m%yN4^gNopbgn>i)-hFCfnvFz)9K83IfEef!srr8y z`|@}w_xArv(n`C^Rw+(Nl#ndbidL0S21AsxjIFF=rf4}5QVH4GaI)`=Wu(Qvl?-O= zgGmg=*v1%s*FC6np65K@*RQ|MALqPIbKm#p`druhdM}f$^8X7=`Op zor+A(&uI==1)6b(8STL6bN_lj{pX_C2CNs__4c(nXqlVSav25P<83f|Apd{K&@=8g zH7D>l(8%EaOAh~MeN773xUA18JUk~t)2-)yAA+X|`91Nnd&kXbh+V=Jor3YKMgLl4 z|C{ns(t~ijwz0%qj=%j{R8%y@pfPheFD54^JIQ@OFl_^d&1S9Of!QY@4_a$HA#k1u z__G=*?_&5&N3sFhh^%!oE{d(~nbTQ7T>Y<)AOmPH@nz>tD6`rl-9$E68W~iCU%+4p zKx_p+l8(o-U^9fZA$j%I&+i65LficsLV%*eGvtx#n%+Opa*aDU$AfvlNUpk|LuSw3 zwzv1-IfRqkTRjNd{`G74R|?t&I!tvYDo%GP6iPFGxv|}C9wGV{GiGCUq0z7ZsUojh zd}`Zy$n*Y}YwpjpCN~Grf|um)T@Dx7|Gg~vcS1HW;0g)~ke6ZXbP(1i0*aAJE zO67{enRJ6U5Xyx&GEZ%yY~-E1Pq4Kc-LNs3c47FZrCQ|aQP+a?0IB`=-1k2SE4S(I zFU2J$%AVPL%fo{M`ZM7ABjhbau4~R?z0S&Yqj}=|cj3OT8r@puT*W(T?(5#oB9$_+r}YRN;K_ z704$R__V!#2`yT1kUuaDAn!|0l`~cHh4<%QnkTqrdH;*T<0QNVprJV2>J_Yw?l!(7 z1R}tWabZ2J)`o@#u&)3qTy&7(pmR++HhUU0OH0|D3nndYNrMepoL0!X6g+6*L96)6 zHwkuBf=#V9RS3VXz5}_1;IBNI^3&1~jK98s03gQyq8^HdAQ2|9_YtJ0RC8!MpW6i~ zHFZv&u5N>WfC)Pf6FpM)%U0sGZWM2$Wke<(m#w~sw?b^e)d zM_)Ms9Y79r0MS*RP>PLE#tp~Xq~w?45f2>fGs!OTgtn*hiojF1(K*hRqd z8W+21@?8HostD)m>S|#D%Xr|D`5a&5*M!I6L{Wi5JC~2uj1`6Neqz~zZKM^ge)I#Q zV&h&N*EY*|dnR2o%H7>IE?6FDE}p&+ZSrHR$mK=ED`jO%g>=8+Ikao{5YkzF>`Vwi zAg@GxjGAI?cM^Q2eY?q!Oui2DcPF(;a~4=tPN661dzU zmw>Yq;sLjIdM=w6oj+%#DzfaRY(`i!W5#M4^&>qE1m}VF57E}jGk100s46c4iT3Ot z3+uRlD{#LIx`vW+ehX2$D`-qt;6wRN;hxaypKwDQ>DS_#Y^|-$kt~HLv7R6gr0{2C zWeExiaVRum(1o#)ksM-tvm2Rl{lpuQL5zwm7NOROy&OGwtGnFEvoOmzF(19a*6lUb z(!$~%0}P4WlE%=e*@`(`hM8FIo34Qj*ll@{-N)6fSKZuT}Qt@-B{D>*e;` zk?o{Mw{cSkx_!Vmf?X3OG0haw1=k0A!^=O|?`E$cTjo?}dC-`$9FAuBHVWUBI5W*o z_31|0yLYWDlTJ~(`AgA2*8Qc0G&#M0Te3R%_ry)rwe{xq`6vS`3&!);-2QuDU(gPG z=PAp9*U{1Ub#Tq1e%{=i*}l!Sfx>D9LN#ZNfINHly-74Fmj8`;mUda2uY7gbgA% z(Z22KFt7?^=8&XSy5&bXcz_1xr2ZH+S&9Hph?=OGE-}^dcF(mF0+{z=}croWqSH+9en-^!j)_hN;?myid=Ku zkFaij4V;{gP)H3P_B^6uuCRdZAzm5s!CNs8PT-z^VjVaky6pVgm&WB$GSq0x_W6F zflOQM*uB30q0+wW!MDQE8*)9p;PIrlCa9X}WHz4Udw;ok1jUup#Aa@E;uYyxj% zYug=YldYhP<#cp(0Lj60AkN<8MpaVTGl_%t3&fO^l}oPfbM}{WO&W8v+78Y&Wx>sf zkMb{#2exQO-p;%7C!I7_T-6j3wf&4oup`A3o43`%W8MB5_wcT=DhMidxfA0xnd*^k zm*N~6am&T!p^ebBa$cLJk0Oo2{4id>k?z*@{_cPgt^#fU{QV>wmLBxPSBH_7jVIn) zjB@Z2KuuOP6UOVtrFvetDJ|VrBQocpq<2K4(DAlTe{hZ@ZTE?7Q@K=?K4+(6AnZ>K_haaG*#+p>O2$qxyj9#UU%tGwPF$v(AUf$NF5f}b zJ)-j99#fc7lgs(q!jBy&k21dmS{JHDpTkpW7rp&1g~L~<)H|$k8o-f){J#Q>aSYs zGvyV5vzDxlI4ND4Hca3GLgJ#LqDI*de4c;$hq5$tURm0XAmnNj4wW$b|70+}hyV|R z3971w@845oy2#={m(HS`zGHU8~1)dvk z*w|#)rDoFKEb9?nAWtvo*yl>xViTa3;z@p~EdmAby4^B@L=%Y9T7zH8i`#6kG{$ng zveNTf_6W7^1e@5ED_6EVWoBfg>>FFLvCN>(XU)|G15XxsXP|p584}H+@lJ!ag&yNr zal5@)U~F|cqG9hUyZ*t!ntD`^Tejt6ROp%Q^a~GZP1X_EfSJ8pk9z>8b97jNf)1fc zXMZpp+Ppf7_D&9%7czg#RI%%l+#U z0)2}p*94c)Ecxt}cX3KgXc|}f1{4RhRtCr}V}QSveR%p#GquKQ(&$=_+;*fw*Yhg0 z8#6aR9-08~Wsr0*|B60)7il4%N+9awiBA%C+y;T_tU@=l7S=I4m1A=sh3cS&YQRkv zSA_7{t|a7yXL|g+3d$xIdOND(+oQ?*cFDQT;wx3vl~;;R0wbIB@@TN*@}6HiUyvCu z)#bH$`{21c59PU);xFqr0&iitws$xKwg&wt7Al6uUA^i-Zio7lzIA`8f$j~(JR(JC z<;omb1qxuQ<4VY6{T?M$*H3AkvpX)Qz73Pu&Um{F;0(5 zgpb;*>7U+mug03O&nAK5v28(eTDIxT=jP&Njf&)Lj>*PL{13<9Kama`3A#NDex@_T ztWA?`mhA!f~lF_N)Y|K#kLFe!uj>MyV60Ie31vo5H zg(G}Aj03n;4&YWUgYkzH6wKMz{VY{^0wfc?f7)yu0gw65-ZK-7%&=`7Gyd20Kg}Fm zU2|YB-ko@(>DxCigFxy1%3S`u^qYG&vfdoXu=F!M8&kc(uB&ZFPUgGI_mkB-jBTP$ zMehl?jy<&EM%0W`M*%L_k6>nY_hb^~Z2a}&xR&sVBl3>QH5i3eSQL4agoVBR6ZYXr z@yeyC7kMvKIGR7+xJ*pQ?2?jv!hPQlyVlEsClRqQg}>R5{!CiudP@M%QS|6}A`%j- zt&gLy9x_q3R#sa!v+D@G30HwM9eKbrEQK zvc;~DkiP1Dc6NjBw;X4(JvFf3KMqKM)-NAu*cSX)=X)=^aV%qeShkXRq_I$Jcc~lU zn!V75t}6l05>#d!7tl)LO`e+(#5&0Kd?n_LD?PrcY{!&0_LT;eEjnflTk5cG4mT(4 z<8T7CBy0C1{Z0$}-jJqsKose0x!MHd7%;)bo2|9wYufdcoB~A0@r?t4=1~=2MmIj6 zQ;lEp<87`jM0*0`m*ge@wxD)k%qu(QBZ9H)5H>m7&bn39T5>Rx^VP0rI#!aV#`kV} zwMdXR(xkr6Wl7}Yr!mu4pB75;SsJ*+{B}RMh$zShwmcjDrx27Fl-c0}oeibt8~`lF zg8A>@hWuk*IetwsnQgt!PcD1;(I10@LRk`hc{D;mooLH~)( zl`W%d-HYAR#cQx<6OVW?Uqug|FLMt+EI-)WYqmCAVCepd$V{azKDH8l3pp)Schz$^ z4cv>~-BYB-*pz0a~)Nt9DjP*}4iJUsSnte~JQsuE-Bg3%92Th1S@FqL(T9Gf_f zdk^|t-*0LD0#8zwe3wmGl1E5vDGO-~Nc>X1IS?4imu;`5IIHMXWvnOziZgn0pdu{Z zQy$}@nn%39jbmw!yNL0xsR$MnR}0CE0tuQ@`-|76Gy49I8NevX%C5iG5=r){KZN$M z2{-kS`84Xemm>$oqfs#PD?#yxc0cKh$@2%z4X7qD z--7Opgpy?zRiW*Dw7w{n$(me~9hI#9U?ZZh+mNn&jbWc?vxd@=5!#8(Hv$+n25#@x za7uLSRQP;g(;^(b&GLuyBB1}dW0P~a)WB!<10Ge^V_xxq1&dJ{nn2baj8_n3+grbq zInSK};K|59TTMb~hT|CvlAG>Ka0d^xk@{S7E3nmYl;u|+Fwi`H?kfHojqW!$>gYj4 zy8Wtky&vm^^!VmIh0~%hbqdzzt46pa{vlbDxug61Z_?{|PvQng=vDq9R2Hu5po#L= zCJR<=$S!Pd_Md6@Gz;Y%h#jO@a~rAb7p61oD;a*X;^O zAcf3OmJPBy3*Ze1w-_QT@}KXmKc?x0}_b$KjMTdC(GQqyeWXU zHQE&`8-fyvVoM16QROO3b+PV?<_~1x+4JBfqrD>y$u2mCICA{WCr5vDX^>I!``;E0 z`ja!pNgXr!m4*wd7=?k{8}}a<8S3E_L5!uPsR=VT^I4{k{^Cl!*9JUk`YZ;60TGvn zhpPJ>=vkB}DS3J!MfiTb$0flQKyFPj!3Y+O7)!aN;#H95U|2&vZzLU!^Pu+w* z3f7J(N@B8!SsNbyfl_>}jvvn97m3ZZ+_0<3-PVRwb3Z8rL1Q=@d&UavAAV-uQQgs3 zqGXstXg`hROaV)UB>H4zeB3BU!58-Z3brJUOzLk+pfOA zV+Zj#0R{VlBK%QkT{gbgK$e%BIKNLQ1lB36o$WM1i@EjVQz}kUJkra0RkAJ6t$!@o=bzG}8Yt>R|Av%`H;`gdDID6E;X1`YhMQ ze(k_oSA%ME98}lm<3d!y6gZ)mU6(q8+B+*~r+BevxIPM&7Y&%4VMDf4?gC0o^T>hU zhHv__CPUj1@9^KYf$7JFd(K=#548=%0_qj<;O%lF&3wbNXL+0>Ew?#6Adxw=xKW(fs5YT6h(be@X{(56QgGn4(7xC=u z8fl$K5GW`j;#t>o`F-ih1arl@A5FgBycl2a$bNcEpi!Gv0h_tlQ7KEujGfChU6*=< zyyZN`L-dWl_Hu9_A#pU(RX6aL-zOLB{5-m3T+m5%$tEwqIt{@#ug@f5w!?z{63w6i z55Lg>I<9OIqbyBbLsFZ0-8p8i-tHC>j(JmDtXa|YSaL^pL4|F=%tnu!JqqF)xJGn! z3a7}jyAK(0kaz98s)Ux6EheUhW!YWCpjM`qcvFj(Jc;u7v83dr8E@GY<=4D8cTs>& z#Khz`iDWnPDnIEDW1^^;p%Q}Yupg1*zhnG!F`#K}gBk%*6AZqxw&~rsnUuK9u61Bf zGwb>nGUxi&HtjYnkQ}8GwZQ#jxJ2$AR7)LeBwKvw+j!edk@CRVNOkma)GyZw+svt2 z)%SAQex_Dm1}jX{lT`WUT_?16g2D78w<=F6I=q>Owp&Zn0iD`I^&*i-j}jX)6TuVt zH}d|u;>U-X`=PNs=Ot4WLA*FSzsM?b4Cp#HdLR%Y#p+ptgp3HBWxo=dWGLq(%ekW6 z+HRCU3iln0Yl%`McmQ{o)O;DMoLrR*8hg;{zSK?uF4X~#68F+Mhxo{LfrAOJmh zEC8Xnf62Oo{%iS_5lEK_3F?@%=>}N*M}4nqImSOzKy&bN$bI-IGh6%{H!%t= zCNH(I%UR2E?-py2;BM{UM&9+|-Y@?6(Tm!u!A~)l-Gpk21?nN6Gpl_pb+Pg5yWKVc zPm(A7(Js%%#>bsJyjB%A2pvlR?ZT=L)5V`Q*yx<#Em}?i<9JX;we?WI!(x*m%}|jV zJo_Gso|L5F*trP*^-u9Fp9a%Y>vmO|a_PZ?gK7^Kv%O1V9`q1Oh!w40U?ZYe(^HU1 zp^p?q*|p@3<_Q^~0PGIl%jzH0A*-Xn)1mDM-@dg&+hlHdgvym%LWDso;!>J*>0sQ$3-#P6NuObFBAPo9H# z=`b7varVT<9F?%m8`&MP+2K9M62y*?F+_U+_sLfWp&CH;g_C#pXD^Y#R%G( zWg>Yp{MiyKsi*A*VOA>Hl0%fS_8$Yd##IvU9$1GieR;t;fU(g=BH_A}C|@OT@J3cA zgl6ekB&JqRx_NutYmAiRAGd?Qilil9g@AxSXd^nIfZ90h2C>J*N0CAHnMS)_s&AP#B|*Qd(he5o7kFC2fjo4C$6SG*?g*3i$=Z^4n9caKaB zLHGy5ec+0niZ??7yaVAnH*WH2vRMqbiJ=a8ZkL@M7rHeMWel8r{SDOJ{^IJn1Fof{ zQ$SSR*%vk3)!#Omp;j}#GiRKYQBx=68_Cqm%&UOcxdbJb;wf+Gr&{>9|8Dnpvc?24 zL1H}mHp>*HUojw_OK$aFmH!ncU0H*f%FSu(K$4{Dh+{pDzsHW?w8ENDThD!PvXaL+ zBIFYT5Nt!1%Y3O!vT^;^Cu>nYap>WTLDi?t>qL?XY@@nVAD^ac)u#8{Y}j0Dow0MB z4XY0vuCQ!1%1L$ieYWYh(Q<~56A_(_?Rb~;+NtwBMyE$bXk`x=5_5{bN`l!i>Gg=j z_KQ=E`?>u?Ys#0yY(8}2MS{4M!Rn8Nf8 z4E9xZW?$!a&R^(hM8rU;BY9__xv}8dC9jJYIAj?u@>XuXd(26Vp4@EGQy6~XInF2SW)zJe`f=6t|Rj}69tZ!Eb z!}>&G>lHyH1OEz@6ce+=_RZJ7!q7$A8#=RGh(ykd+f=9ME7o=UY+7TTC8ehxhdzkUDyIXM3h**=FwM8^@Q z;jWV;i=DK}V_1O{WePXMHp50@YCSn%@J==|9}A%Phgf_uB`VhMKS;4c4K}>~W;g@rEMV|B6X-T z{Gc!Gwl{=QOeaftdR)aOny56my^=#Rl;EW^EwJvBU@R<*YE!=**WK!Yr;NxCH@)A5 z@z|j*CN^h8{M520Qev~FdFysVMKEnZ{Fjxg5J!9+Qd{AzQ4kSdUv)sLb>wExmg=(k zh4ICG*C5Y6)7oIi+K$X^>xK=VUifbxJj7l^ICBj!e}2Th8a+D8G#T9P-U^n#_9(+d z@eG~^B1k^FCVc4nPaB(?`^RW6HZ0*}8`gu6*f3IiNAqnWqll{kz8^zj{F}V>B+`zD zB@`q}fV3sSFz^YdxQsGz+gi_7GNnI+*urQeUu6()?2-HHI>qWh>Q|e{(8$Q1v(KB5 zp&$$$LYQhz(>1O#>R)Ieg-2 zvXn@U;?~eJR~>8x4k{KEaSl*le*@p36L*h&0p^pq^b;9@9XOx72N+3)&(-l3}>iQM& zk_L}D+6wEL+K0-g9~?yC;3I=fBstF+E~L)cIX7t3*V;oqlH92ZN=;tuIc~eixW-s! za)boCPRCs&w1NJ&ZLS_3*#mbF{0gOTOba_yE zj1mgNh^Rl3%gy1UH?)I6L0DLr?bk;>o{Yp#@Ldi21Po5+kv010ou`fOa(Z%U;brTy zu4+R^f_3rDKBd*=j55!b+D|~;C!fg+dakkO%Y!%ByzfWt1v)yWD2~0hG0xk{+8RRC z$&5C^QlNAJ_T!?Oqxi#SFiDX6R(%PWr7!8ps>#&@50wN7n^oEB?NE<2#w6BYsxnk} z3<$S9X`Z&F(TH{hAA)h*W7Ec~6DIjN?Tx2yh^k#`o=!(T6loW!qGIMZnyfmecR5@q=tq_}hCh&Y{t7#=u)>pjW`uPTF?lO1 zX(j%d%^o_A6Y9u!!IJ#sMiD?v@m~mykH5`^6ta&jBSz3H*+_;LQRQt{bM@tIyG6Dv z`Kb97jP^C~#5%Or=TbkCf$+~%B|Kg&5kADcJP{P}2Dz$bk=)WklepjL1KH3|(=ZYV zRa!gH78n?qaIF>wJs3C!5^+u9B`A}`_wV6}a`V36R{Lp!8A`uYGHGn$`V~Bs`&PT4 ziQ)vtz6F?bI7w10Ni?BAFL}7`8bct&No|0hY1K2tx>JAVVe%?<0HXBET`qv9`5@`z z2^-5c=k(Pzo(w;^@%qIySJQJ7cMdw{H|&=`H;&IXsavV6rO@`!tC(uHi;-3Gv-#td zk0nQ>^Xrq63zEUP>V?Jro9LD3PYvR@C}EGg>P~}T)j2^)R^4Geh{Y+>x3~SNL=wdv z>rC%%4gTd{DK> z>Ag7SgyR?SC^tq}Y|>*l+S2wbN!deX(jjiIoNf?bE2K&*`M2#MH3XfhOtdHMXVbI4 zbjv^|LoPUQab_5qSP>w?uO1ytYy#~G(NJ4>#3b$T&hAa|#1u=^_QIDPy2o=D^y*6{lg(n{^#Xp|or?}$@U|yoG z8*&}2OZIhlHdvl1Y&{;{Q&s)zmcoOUBq=@~J^nHfvDE(UZS)@;wHGdITmkG0ZV~R6 zL4c0ECJ?R@R3;%A5blraw$|kmvL$&#t!v3sp|-)X5a ztkTy*B_j7B2v9cdSa|OKvCsxmZ~VEv<21R}31{F7D|;=7>>OT(ze*vdy7!eS_Y9~$ zO(3vE@i#rwTpS(PryN-5{#(n{+g+YLsQ&ymxyC3ztGxbhp4FN_+p3-e`Y6_;BJe~8 zFLk`*&yUJ@CBq+6ZVuRiugSQk0-+2l-tFf5J|co8jzFRTww2Jixb>Q1Eo!2;pb*z_ zepqzi*@br1GBrm`U zS?s*}hxr_YEzSBkddY^(&ZFQGs=JKEtmG0Cf%p2uQkp&{E53R2`!07sM?=I?s^X5r;4g8?f9Ww9A4TJI1m~yge&$o$yfn@sZk1cyqsqvFXbB)TUi1D~6*w-^_)(UO=dW~Ok3HrH8=4V5AllKkl9-vb_%q1qDK$({j*=!g%@;(k=2Q zFS5+#!0i1CQRT()y0;kiFyyOTu63Wg9pbxdrmj!63Tq`{3jNE#!)wDjIlOn4!kLK6 z^Te}D7m>|xt@X+B_j5LYfNTsSmV3VfA0w%4_nI-+SM;>BwCq8RzRB1=c|j2Qyj)#F zv`oPic6NJI38utPMC3R665U>N|42SOr=Lixd#7Q<{@ISl)H|LOM|@iVr&;Pmv;268 zFXC7QOz!HbOkkbDELZj=v&pCKd6_~$ca89iy{INtAI!y{7!8-Uz%HFu!+etfbyAV_1?6>c-3^RwI$4c#o4Sn3{h>^0(`n`RyX#YyKJH#6DG zO)?-^a6ktb?4yyZYHqR@qxRJ_UoIH!5^)+AJ4r6Y2^MOpHK`I)ZV_wU_M8z{jW{|3 zO&>gCEld>A)i%g`p^GVG5iX_g{c!8iGi8&#Igs`+NSNV3=7q*oxyr`FoStLB^Rtg9 z8?q<~yh~#WlE*}}0`eg>aUv8uJxx@wbU$?H@+R(E&H(y~iDv1`n>%g<7_=2S-sg@) z9b`h9+Z#gtVG-UaM6S8Az;E$02H3;j;I9pTqN3vTV*aQGI?Bvj0RQQ7?GMSR%pDj1 zdkPAG>k1@ExuOuF37`;oP$pMSgNIM~OJIP2ZLfryt36n!z`xbOf_0_nJrH2=jI#5A zvmPCNV!Wo6M@M(g!6b$k5V~S{OS|iWGZVhbByQ>F*Ps1PB$tS~9<|mn9rF$g2+ygl z4Mm_sxitVCR-Zm!tG2{!cw(XxAf}-_dGf?uVWZh=28qA_vvkZfePiU15wWwW_aT=OU8tR95%n_dUAfY+*pHrl7+4v>S{;++$Fqj5F#IjME)b% zb?3kWF+WXT(hG~fJ3xLItMYJnx3>U`2=RmV9~!2CO$yZyzCaisljOl%;t=I=&55wE zIl0aBKFL|{oc~OpSPJfGJ%K*Q2+ZPa&(SKPIOfL;zVDXHG+IL>vWl{9leRITold{P zo%-Y)B&xFY&@vnqUgTaNo)yCaBa>X+ta=@;qJd*DQyRx z&DDhmqzj6p0*D~!2$zN&ZX3v(MdFMD2J!;NZNOs8oD-PcR(u)?V_)=OApvhO(IMx_ zgs?!!=>`I73L!*Xg3$9?VCK4u>?HHeh;cLlz`O*;ky-Lm)=@Zjv+==u?vU*eK?3hj zkO6N?cQMskXK(j<>t1LH2E1W3kPKb!XkG~_#P8&V^qwGDcY&}$u!Szd)JqEPjK zSeSNY;&XGn0+y6=i(S@QmK&`3&qAmmUeYU)f&{BS+aR@1=1y^MGlWC#YvEtYM6zY|QGg=^c^&{*ZWAN28e- z+8{)Is2xFNQS7RW4Tsxu9K88!Cw3b0bSiV71!x-blrH^%J$!d5&q*^*WBgQ59T4>Q z$d!q`VkJNv!C&S7Xt@&WG4B$g7W|in;@uh7CBG_-={Vj$;+%u#o7;35h#2*D!{M0I z)lO60-9_fQ$5@3d&ECfBv?SLWruvnaLKjh|f}?kp8Z0dWWwdH`iqf4CH_>?+hw7Y+WA;Xc;LZVLI=U#R<_U1hlicYKH8sk&q#)d2 z+$FLPRcQ1Br#Fn_bxn(l(_uimd)v?CdiNvF8YD>yT^MRE|5w6?_A=(@dh|rsx-(L>Dj7D)c8|@NWI~SMgbZ`#BFBg#h<3qw1YyP4|Kicyx$xmer9&|F{U|;

    Sc8;R%M#-I>@8#=@rs9GvV+jiAU^$~Vqm+_l`=^t7GB(7{5H}dO@ z5Xr$VgxxeN+p3G{LgCFH@z<7ufaSx@rm&d#pZu;80k!#!PcQ1e^ml#hb8kmSpd|+L z$whc`bmO&-CMPSuSjSIoZO8wyCQ$Z%`ntwUuLQUa95o&@W;&oT z8Sh?7po|RlMn*ys9F76iT_XblZK0tP#BtEamuqJ-)z68|4WfESbkn}!ulkv^8V9{L;@O| zJ-iO@n@SfifdTU`D!6x-T+6NgqqC57KJ+EDWc>lm5%yeTahZ=h*H%OwQ3O|TJqN2r z;aMGBRm)#N>zSLD)(Mp}ggtairv?dS4lYb_vD48iA>|F?VaUh&)1i&1hYz8wV?3s$ zq($_}R)X3^VU%-ab}R4`B&ajTFpx#a6Of^ISS}nH9^Nm7mbsIKd7~ohQTHpt;Q5t* z?;McssuF1NAU1W(za*B%vsdArC-c}X-q*v1DW*3N7~DVzg+}+P2?oIP~=fb zl-rM@hZ-}%@Dqcucr*uId0NjCQM?`0JbL+8l)L6kvZ$-OgYyfyz~q8CF3u^0`!QF= znhwndS?+dbltqVou_0z{ngnCV{f5(MX$f)h;+i4GNtNz0&_twMJq-G{&!_26Vi&xm z64J-==0hlDBaxq|^rvN9>qqG*)3H0%ue)LPhfW5sdV_b4AG=9)s;M%xFWhSm8eNtno|o4Ip8dRenfzI3ZDy;NW6FXp8*)wwE#H6L$t)b~!q%nM5Gqcm=#LN%3Kg2DuIL5sGVGq38 z^77@pzv`Uc%1MuBkB@D!)Bk~gURw7zEcGCxLyjyAzZk-qrQpLJb5F(kB$(gi|B(oKe??eo zxQs6aycGC(8QIwYR-70~799pYa1A6B46KKAhd-x-KE0?y`koUsl{odgO+r{6TS1J+ zR^ZpFt`y!U=T@;f>}d&asbDZOtb%(nw^iWW1D0o?thdt|C^*xQ{OZ;736=+`$)2`d zjBF+lOtv*ncLi2M&09c8rlKa@peVu;n^Ccfy!KZdpx#!v_mO0n**}4@Zyfn+^OZ6X zcAEEGyv-#S>;~g2nORw&sDsSi%bcT}wzA(g4)8cWuIGi?s44)-x5J>d+}5{G8i$DO z6e(i=1qcJ26H;7j$Da6f-fD*;1S&YJ}Q96 zlU^&V>D^RN$TGs=QghrO-*H`f#n}=m=zUAjM*upxe!-W+ybE1G5dG{iw-v8G)p)=J zz`1nn6F?vU^Z?=uDeF|L_spLN8UnSkIB$4lrUFRNA{qTChmTcXMJ6r0GG8h85GTPQ z4XPm}!N}$BWddx}?wg#3A#_f}Nj-$Qd>Paw78eY}zuq_iL3V9`;lNn)xJrZN0<0L|VJX!-_YjxC%#97;7K2Or8-^@Sn3 z(a?m2lpn43fXYcJ&~bvhLU~n9S$p-CI`EXit6zn_m*H_F=D zf=y3mss;@6*QmcGBy>Y4a>&EYv2#^7tp{3&Q@>kh^zmpwm|j_*eD#lzZ=Ks+OxJwy z6N)1ZAGB{j3B7kd3jVvY{v2JYe*7tq;Qeg_;?uu52ZgQU8~)3xh{7En}jwzciJ$3SLPq( zD}P^$yzW4+q5S7ML+hNr0JN?{+J`_)k&Uh+wT-YcUU52D<pb3G6MA&3SdeO0m) zGAjN`_P%5tc}5DB_0rav7QYWPsP8qEsPADMVF3pVYVZ6YCNLb z)}bKdJ8fA{hz=|sK4#EAIF7Ey###IYWu6Q$e%{7wj;7+8Nf zy8x`5c=?^$+G>*jJ^%Oy$X(sP3^h~hT(-_hrmgQ(=d%GHKbj;`{QP|L9FP%cLwl8K z2h{nl{Bam>0X1R|L&&}CcxyTgH$Bn;w@4{2gD?jnp~ygF%3lMSeJYL_sNwIrMTVAL zaG5%A%&@#pu>7VBTqD1~z5m%IQTIZZq=BD8wAdBtjz_%TY6ZN=m#VaR`#Xk1F5(z( zYgk1YM5}>T(!THusQW;^-iF!A4vxMeaHd(TL_~px&Mw#zmvxt*q zfz!(#&9@gwKfwxhK*G4cwLrw$Wrgxx284CwDgGz~LqB6VB3Hz}14zrI`|v9xBeuFw z&FhOYhiD?!HAQHH4@?in{^n^vN7XvZr_?-Kxy*QOfbBig3+|g8MoeMNlHf^e~ zxAF7m{{5C4ma5EzFrLco#jus7<=R<*@D7k9%cAl#UCl=~TAs#Av^`k6W|vI0${n9S z&H(-F&>+#xW=2RyZ6;q%%W+s+`YC{r$N&TlLh?*6ogNb#_&GofIh4IU1gkax$6;Ym zx_S@z=gfT$b-W0T+0~Mb*#F%9&89Nl>jla{=Mi)srd%PW-E^m(PQgX_U zrACH;6WtwreoS`qM*#^5ZllA7drPp=>~Rk=tuE_W5~Ck`Xv{lvXs6umEbruE^_o(& zp|>IG*&ljm!iC4oGR{j&S= z>)ngv9eq@+(O);Tdf`7%%st%C)-9hj`tk6!hlDlmFfOUJ)r1;Ju1qYtrqEZF&0X~r z7$%P;Bwdsv{G`Fx@4}?!*Q}OWm5s~zOlMp-_+t5XK+4cTO4FxYju_WMUBlMH%hs|B zE31)v)x4d4b>PHJrE?^Uybzkj5B!10%~@e$>_(Rxb}AHw5&^TBiQa+r8D{{+d7CU#1ZI*Oy#Ukv&3Y&tyukG zUu}Meth;b|gYx9UN47oIJr}Ofb99Yl4VRuupa!jqow@%ef%~dxwkJbzmmK+p<4X0^ z6kGC)g?P7S+KEd^3tl!nQ0ja6+%aX|cR2&Ap{CaC%29s}VpiWDCD3<~{;j#!3kOGF zrf)AfWV;Kzyv&gPhe0KZO;#`2PxZ*#RosRxas&2^i$Dn2iGi_anJr2R@@BXYnfh!63!}=%U-4czET%n zdU%^rB~AIpM$O%9+clc>k3CLxyKpyZg@-~*k=TkAD~iUnC)^S@TYJe`Dm;^Mv34^~ zh%0#jl-8WRq8nhm9j#eHqJ?sk^V+ucF+(j?g#-nMcZ&W517OCoR>vje8=2Kg+DrYz zZKnEbNvB@WR4|mHZkcSNbCYb|=W*pti#UUQeYAM}WmXKgyer;dXK!`VHr&}7T`A2*1$%B3 ztaMaL|JeZ^7ljfce0K8veI?{?_4OP2ON@O%C@{G&PZbErsajrKzzK%*vWpv*^jq7p zM@BM|qdF=Jp1|!Ix_**)6kF5I{GevQc|rt4g5V;2X8(Wn!lgXiGWXeE$ zppIyOr!PZ~6SmkT_Ar_0?f4Bm2tPlxj6~SBtLE6YFkkjzG#;jNr9GsB+X}Oo?ASxY zjlJu$PL9-GK4#hZwZU?)3A%g9Vi)sAe?Awr+*FELV9U~b%?j(DZB>)I?Pi99k@j_P zAkX8_p~kH`s8|evi=beztv|$sccWz&i=Q4$%W5k-KoCI43GPCiZY$~UrXVM6|4jZ3+u5V9T!~Cw(_5qR%PuwK87Moj} z%~)8M8G8FN?o2@sYa{BX*|bTHpJRC~uDe$dOO<>QAB9cK7>Mm9i#;Q+$j#4EFc^!N5Wrv7gT9#W6N_rg!~(xN2w@AXXWbg>A$e=&~x7 zoh8`d`;=&zZnCkMB@fbLY0$rMfy11HH^liGe|_R)9H?Ir-}D%(VQ+bik{J)=nO=BaO}N zq-JCG=76chw`(ElMe}W+iNgN!_X#S43&hk9WEJ6GJz{}{7Ib@PJtOfO-Y?7s9$Lkz z&ZQYLd1(BsGn`%vG3cBiy#U%3c!Om%1#PnO5Sn&p^wSRDs`O=6GsE2s{^Sfl&8!T# z|0M;BXu9mw*zBxWw2bKU%$WpQhPv0PYs9>-&0|Ezy~8{EVsmOX1e7Fh+&tFbL?h>{ zLukifPv+q_ki%!U8O9!t1AF+kas)MUo5piFWt;YR*%&B;jFz)jV1;j!oJ%mT4c~RA z*a_o7{jw<_Od*4NO{H=7aJu9pAi<^-0_9Pa-z|l35g8EnsnIj$mt^UaY#x|?;+)uO zeB^5gw{nsJbPN_}00A``8NUs_vXF+o-2UcI?USwwrvXs^1B*`&SFF`hJn%T5o7D}E zIycf|tk+I`XegNE>VOr5$&gJ8JcP`IM?}V)@D@4HW?bfm57@n>?VG!z{Gkn*9lv1* zr3E`+$w2KdN$SMsx=8K&C1aJLL!>L{iFRiX|CN{s4qfSCr;dh98|#Jt^2_T4xJ(yO zv|izOTKDK5D(lq7a1t^@2GBUhS$R5$!c?RL_EuL`w(D8jMX-!P$DMC;lH3ZSh4D$N z~(fp;mIh{?;u~!!!cGp1?#!Cb7qihi3DJ0{JEe;i8sTo zoSor-(c}=`K}ePf4MBJ0n;orIh{ zwX770w(`oZzAP8EW4voI&MSPh7VswAhDMFcr>%U@AuEbTDIb(v3*BU-t0=8mjk&bf zMMX!lEN{L)aynjR>`g|y__i?=INBN{W*c$4%2c3@=0fA(rP2z6leaiztVP5YD1Jg* zxV$ZH-1tNN4OK~uN{>^y4&{rB=EDdsWm_dNyA18%1i7S~+p+cq7?l)J%sE3l@yjb( zYO6pbaw?Z7L-41Sx9oZ$Oaa461lWkQ0uE<{^(N>PEK@WdF8!7aa_q?cR8RV_;)f_KCAV}THY%|R6*0Ijri$CGb>DTGgF<{ayZS$aVu_=z1AJP~wIgXQL$3$v?XX z+cMw&!+a5zPxB+!BNmhCfDdGPj$e!|(3Aatw0(IvmHXE>36-fCnVL>2W0_~AQYw;4 zWlo{Y^R&%HAv;MjZy_Wk^RP+gc_XuJp2ygxZG6{_I(44k`#!(txqfedbe-!u=WyTO zdwtjXtk3$awQ|zl-Eq@5PM%lg&kH&57Qn*g78wNvI*p_K1@~`Oab4rBwNZ3Wa*AiZ zSjpRWCa+_cR!X{cbMHmQd+j+`Tg6MCgAUFtK(be>oUr@gmwB=*Gao;=B+neVcMMv6 z?N2(Fp>sD5rXZK|t*Hu>QsZBe8Lbvh~S7C}CspL~qTy^X+Y#)aP&Z5A6eneH8=`{(%eb%gb!& zPimwebXo0wfG~=_?r)41jC9^Z3)z+`w(OuHOp{e-YWt*rv!Y;YD)mRPj2su8+Z$2; z5V{oBk$a9gvH!h(2K>|3D5Be@$W$1|IP6IpK)V*OX(WFp@BXz;x=!VWtVug4_p}7# zKMVTL$UVE(6r_AdUKg8WqM^}+!@U{+-6&UGr&BYYsFWb8VxjEDorm7+Xx~$_PGuT4>U?A zpUJtzlXAEOKmPS1%!IU2y3)CActfQUnYl8du{N`*xS{|aB7q2U%3GS)O(D%d4a_q6 zSy@Vm{HItVCBZzWHaZ>#6cWqI!qce_)U9s~lG!LL=hW7iF9*L`uDqphl=g1XwVlfV zywzR(%J97VRWQ=$Ls#?}mg75eSL|(Ad-WS{L zq@Pc#NZq;r(j_9gU8>Do^Rnw0d8MHx^h|2%o0iJlt?ViEK(k6bnMgR1iN)fV&hdG_ z5?NfbmP%?|dl21W)NyR_dsPAKKrRi~r(w2yYS>&LMl1ZN*1E9GV#NEplZSXSbWrr& z`y!n5bw05fx3*fqytCAfjFFCcO`aa%qNDB)J@}V1D26>~cv%yz@vF2=CDmNp$61ya zcK?XWs&wu0GFd57aN-{r&n<7r=N{=M^jR(gH1_N+vGY!tGRyG#C@@_0Us z9P&B~zeYrxa&W5>B(__DXCv?^v;LzJ&F^8YbZFVK|V*@56y^CuB9=S%NhvP#o=kk#umM z1hcr!D?~(Iuj}^m&^T;&*t(Y+^ccO*}*eJ zp!(r~uX?uKUrF5!1|1V2Knd~{z-}jKK+G}DFonH4G#Ldsxy|*fDie9<$P$IB9HAO_ z_JR})M?f`FN-QtA+~pj^qQp3st@Im?)XMe=OUt`RY3_(tUm{$gxp&Kl@GN>d}8ODAZsKC2XG5B)%EwZG_}b0%wr?2WLR67}o$> z%IVK*yN=2sHtNtkGB)N3W}JmxlpyV@o&NxJUr18&mhsz~^#wk_T?6T zVeRK~-?kDR>txIJ(mvCS`k)`3z~b@}4oo>2!cQrTDcUUvf<>9UR$>!BQ-w9sk9uqz%0y_jA#`L_1{#klIFQa=Dx_tu}@gS|6^JEn!Z(8dBXl6C$k%yRmohX=H7Y<{p34?@n)Q(8-<@ zI0mc0gMKyMrQ5?u|9U*W+Ac>N^2qxtD!)LO{lI1)o(Lc?0Na}*e5`IkKa7v@YE_jt zv~Ewa`^(Yj{&-1jH|8z9&wJk696!%ME&FU9D6z40A@YH{RHgfLa!kd^tNjL8VNg?{ z6Sw2ZufDHhoM2%}Q*aWSpFk;7T_FUsa}xvuA)nG!y?e_pN6n0cG6osU(qylumNvn7 zQcoi^U0QlX!w+#~smsFhf`s~xvD+Kr`fP_N_8%d8 zM&ZV-sSxiqZs?UU85u$kCz@%iK&I0@e3R7TF_P*1%L&}AM{FcVxKJ}Y^ZI^~N2MYt z&>k0c$cYRx!bb0B(Ut$Q)9P`S21@Mmg@G9>*Y_&z%guSXxE6OG2GRc9-@+4GSPJrm2;3?x z6hvTr#bb7)4%fQV<}BhncozTg9Y4l;HtW(31UKkL;YEkaYw3eS{@Zz|kxd%yh4H9< z6kC9G7WHWB2kQ<(7szi~R+S6SHrj;}^)FR$1a3_1JjH$-wsrv@pq{}XdgvvLItRiQ z;L85*PICi)%=izeLDs^b)N^t{9vaboeXIq@dvng_#4qY#OVO%>u^gg7&gEHEU!NC9 zJNtO9)3F903R(}%P=@A@$~dL)6?~V2+4^cYs)tG+t>7@~CpNj*(3hCg^v!+}n$}y1 z<)a@LxP4ii`H=TQ)Gl&0##=PO$A3e@0{s`jpX$L^xD=`0Xf6o#z5`5X{jvVPr%(QZ ze1ED_8(+rw{xtW$g={cGgep|%jWKWdJ2g;lx=iGQijk#Gz%Fp$>?AiC_vDTEc>Ttz zx?%QkVwK@QjTWoM>L`1y#6o%f>t_GUb2BHra>;Q=hW^?T;#FMve`-&}L|{?Oi_$&_ zKp;+<-WAT$vmCLx#bi^0_X{g+>KQ>=+q+WZFa`cC>h$#XdW1Yh#YLFwwHmE-SQtEb zV3n|x)j{w!`!N6_hw$;xq9pkidgvWl>rW_Viq8<9HcKK}b!S#|Eu5p3S&f)Zu@iI!;pD5-6NM+Q#>Yh4xZw?g|o;7BLjx%6tTHKW|5^)h(LYH2rY#SsZ)# z(wls%tf%NCN6Un-_oK2+Je@6ne}~kLh1-J&dG~Jugo>Yy9!Qzp z_hSLyCF34Hg&$n*zciaQ^^oaYtK#lkW;Jt!{kkY3fHUB*lhL1Jeyb#~4oc2Vbd1)u zjV38_FC06x`p~jbC8tcVG?0{6?dhrC-^ph~)3=rVBkz=*nD{S5mtyR2t3e0$*w7Hl z;Tg*K5T>ArGo5?$oIW=F%PRU$&(wwpqb`0VQ=o^|ujvDMzxq-i&Ji}_LxcI(AYLR! z_zOUcNT$gCo6^W|&GCva8XdjQ^(9F(>nu8Fa_QmYawhjOtCGj0n|jNR?%eI0HzSpg zpzFw&@OPNzdXJ2GHayuZ5Vrv={<+p>lW>kMU? z8m~zlB6I7W4A|u_r*`LR)pn23hyxLN3fd#D^(!Zy@OPxENIZMex}Qt>1Lw`dMZUoo z3MS5+d4KKe33BJ-JC48Nkv{Qi=i%wsB*&e}T@O=xMLN8ytDh!-!F zU~5;q)+H7?%qJymiQPBs1T6Wamn{NflwdR`tOVLg;TD#bB@AIKfLm>JYHDG=HaVq_ z^{j+s=*|!}$yQcBQak#dc=OK*q=#-%ZY{`guCcNF`lOC1kOv7BW zqoj+L?T>FeN`|Jof;tPJ|F!l==y+TwOQ1+2YoZg6xBfyc4?D$&_0F949#v%6FEd2t z{LzKKlnI1r9tTO`;RBbRlTl6W#JnS23J!>D%tw=sToCn@kMfhjtA-%uj$kW~D zk-y$wiVY(TnsT2X3w>junXT_^Wtn(L;e{kW|95ED!r{8_1z&yOCowd1CaN@sPfsm~ z)Xo}S;f4?Cp*K$0=f7SdbK@0;O)z>?7#_fV7)j*I!rIbK;k&ahkfew5eh8F-%NM5*p@LTnoC3 zz35?3!0C#0{;{*tQ{*U1T2Drd*pz(A+RL*^0Y^4Z|7a-lgH`m}k~Z=UFecB36Hsd+ z*<5;TWg!OWP(82hHFPjI@TI)Yr~Ik8)eE962P7o&7wweAZM3#GPY*1}0@4{=E4<$M z*0$IoV9j}&-Klrs=v4F2RgJbFulw*JjLAtBJRVT!b=*At+q-mou>JMW`QXM^K>mu| z^U=_m;sEyQw)%4JQ5A~eDJdOi3b8VC%$$!8ZEd&ecIz*?Hy*FW+zTMJ;;wMHd_62i8gkQz7nCg z?3`Z7&tEkjyWS((YyL%IzO9!1gp}IQMM@(wVOSW>=6cn7k}?Dh%PvO4Nn`=cqB!0MK6F653mNK4>!YnN6_ z(|!<3gmQa#n&P^zlNjhbQ}}l}MS&T?T?jK%qtN?hOV8UP4)IA-x)m69F*4SdhmD4i zio$X2Bsjap=TPW%J*>s7h+hzm2)oQvMuHvt(I|3K$9XNsB@PaM1gl2ZbWipVr*0tdn~r^bJml5dPk>oCKQ# zuV8blgQR+?D`||IW$Pz@&)j&09X>m=oQ-E2URKv~cZ5l`vKH=O?)%XY5Ls7FZ7+0^ zAgOtoJ?%s7!?$aLZQB!#SM7TOy4W06Bjc9oglq%S=f6G+8m!cqZ}-t3B6v705?6AS z<&V(PjxUo4JvF1oVd|IBn~tMgDZY|~Ys(d#-=QdWtB}NDWpNt5g6)_{l%GWXV`s@V zqu44N8Te$LBQIvp|M>Qt8ka+*5$Y!U7Y+QVvA=#^V{sbfSeW+ zV{T?Sa&GDw*x>qLThTS0Q|*;b3L*=n^dnIea|_1T`%d>YH{@`TNeV%H|&eOk{FeLTnkUV52a6*te7B9^$!!R9>|J!zW|Q6hn(V>7y*JkH15 z+%`m|fjf@t{aT<-2VO4URwP?vfn!Aaf8h4Pj&J6%hSy*$A5#qDpC#3t6QR(%u{L*f z%fRc)dzv0OAACRGa|3q}Cy`Vdph46ee`wEX;<$LrK2z*$-~5=|6j?ppE7ovg|LnlY z#APt?L(*X469tnk&M%8p;`RguuNw6kN@*;9Yf=Ya?})9cwa!cNb8tJC^z}UR?v^f6 zqix01II+yy%amKc7d+bEr)(Ab5u)c3_Z87rHM}l3$jW1CqSGT={+;!}8N`d|tTH`P z=Rs^{S-I)^tDf#=ddQr6C?v4?$ziOuwt3AawCvm#yy5@&g{k z#>Yvlox#_43eAr>{&xtjL&$a%J^w9WWG+0+A zSg}1RV&503arrx{C&%rwe)&U>+s$C(-#M8{%}Be3{W<6a^V|LHh^uu=3*Q(l^E(gJ zqQ1=ZFOZJ(YmOLVPo=taKlAmQNCrf4hBzY1L~X)UyJkNBsq3NYlJ=zT%{X-6r0y3o zy4g6T&b;%?+glpWJtj-V3!TQ+UJlqeyFWcmVHgtz%`CEa$M#$y8IcO7fD2K6`1<_C zC#A56XY4Cc%UD7-+7`~d$bu2Guq{uN5$cDgymF#%FI)I>;F~FJ zD|~I#O}bgOwTO(!-ISzO8`x@mToP;ofjcp(f80>3*b-`7fu>2j^(A+UFEOIJ&a~xQEfJKPPNwh~ngk1V(vh182U@ixk{dR$gylm_QJ<>qV`O)4A4`4|HhQ6pEwV{Ufl zaStrMBj9UE$QMVISACBkVa)p>p*kN(FS)??NE3Qe_mNl4Z9GZCNo9UiYK zpS}d03AdInFj_62E)&p$JfMV#XWbbPh<|$c>YbU_7benx>(m%yz!$6*ArH23?`AAUrIs2qe-F6==l!X1^G2~PV#h`rzgLq?G^l~m zM;-n5kbdkQ;m#Ct-n>~%#4(o$OE7%Lg0#60sMUaYcZ-?tqj=vyr3tMyX8QrRptYh1qK_h@_URxL@jwaoIIyqqX6UO+lWRG9`&`IH7)K^K?J zPc}RGO?e2zOvZn5-EPmX<2L~;O{GX>@>!Q^*txl{G6}_N^+n>&y831eC=9!5)zlTu zX19s<55d5>_gtnGd>EVa%C0tmH#!$J0@}sG8Lqz4v{(7Mfys z5d1}Zr%>)3vxhYL!qJFV3vCTQib3E8x|_S4caAC;j-C{}I@yr*g!wGKCfj0Vc=+To zn$)Lf2~vL1$;rtfHrl$Pa>a#e5W*Wds+ICOVLkHq@84mEU&2r50e3 zLx5_hUV|5FbU+MNygqtgI5*j>`d8(lZpA%h7DM>QP5Fw0b7!}LHKb6V*6TE!IN?q% z@9?mNdz9Vz`#su97itaW?pUcrUdVq-8+Ly)VPKZ38116UUs)R-W4n%b$}CsOPUGhu z7r|m3wN0bL>sf~-%%u9jI|p2U-sX;H#GvW z=0i2fEikMwC{JS`&Zo1!zBd&9N3UYEkB{9s+Yn*X_i1U3s(nS(eTOh!16>y-_P+RG zvXM?G7| zMlpAW<1?KJ&@soKGPr9(4!g3Zw`#BD9j`Iv z88bxBG0|LK-tZ}7?gP#dE;vAW^<`pFf6SPH!B;~Y`$~TfN9}1^$zpLF2S=xCWnyOd zG~!d9p8qa5UWrL1ZL@YV5kX~(+ygPt3!7$=iBVO7C)bnWCgbH&s` z$Ho$d{sweU5s$r0PHFRxq$Sp9?0RyztLKuyEBP=Ttk_xej}qQpYkG=shnfPihtg6$ z+G1+M=9s*!=T8l~%qOc%>Y`lF@x<&-qY*ocBmos!#+l4F@S&vH7jkP!Xi&D^ZFM<0 zIrj$lvCDUhF;LqveR&h^!Mq;}8*y~6QzeC3I_9b^)zrv`Pu3j4LppC*_D$S?Zt}y* z%0p!fjwiCR9_$0LC+SWqDV*>V*5f?L!Pogp9`$F`ml4o$rloLe&*M7_ki1cZ%;Lwl zvVDW3;H%F|_^Q7mwQEKwfhv+!YceIV9Cf%un_iz4@%r=RK9dHd5|ef)BIIYoj*bI2 zQ^n2}%0GG2mGr`5hJUQCylSMf4ic7qhI{xE=3S`o2jM$OgTphvjG>0az#@F4+U+pb zb*tWVH+P!u)}*HxZf=KrE3!Zn;1(O4wx8;+-r%4hhQTZM#+6tg87N*R011Jn!S;Y2Hz$m5vI; z(tA0bXVLXI_I4k-tiE{_hlGeWa&M*n5V_eiPs?r4Cxiv@JSC1jZ95RIV|yKxPlxuJvCK&Vc^OM zKO7drNkc;eC)u&9V-Yk*!Hx{fVpgBh()_jDdGgO;q ze)5Gr+KSNPFAzGx&OogL8%u4D_wcuGZ)Ry0f|<^yBD(|SV-$_mRSz<6<0?{id_V+b z?jf^YmsIkHFWmF-p>w*mOmQdUm81_w6nf#4$k#Y9GCgt)D2?*@caVkefGoujlJNIq z8@r#^Y+?JS)vFy%%kS_H+t;?7WcVhsA4I2Z;rjbMowk_#X`1|Go6_*T zle%YxGlN-&lN=kba$GPh45QitIn~SF$!NRddm{u=-U+?oAEd@f;;Fx2A|eW?^CT4# z##W2ZLz`CsDL(n>Gz$w$XL_mm`GsDyyN<>Zl>6;WV3=&&J3bo_2hbY_@9G`QkSmi) z6tQq198Gcjd`u$KT}2AU2OAA+cRR;TmSHBnX8K|zmV5k>t|9ji_{OK7P7gZhYF%3x z(5-s0kNsN4hu3TxI`*2Mwd_<>nED*v<%>w6+f!lu;thFjvUqG=onrWTPP&Zy*mDJz zQJ0@dFR01(wIpi`d(sDxlcx|<90H&+m}VhiGbTdovZiBw^LIY#P=p*rS>NW_2Xso zwdhslY>S&8SVOBq@|Z8$i`5-GSE$cchGA*Lvwk+U<4~ws$Qu$mI5nPG)y z)@+wz`{&wi7X1$>hR;sXm7Hrv!f4*2YiHNPvsaQ~1;FfGPWMI#vSzX;p_7SPUr)~j zn*w$nX;g67Urx~i`>_lv8$Gt1%}CWY1)R z+^pKz-}zCOX)?W#rG-VNC{4j2uK3P{UX-EZ1HxdoKbgUxW`>#bR3^n63(;yd&Mf<; zThv9t3wUbWVJWHWjhGhG>pUqE`zy5v&RNzazkHg=#ClgTkUf7scBq+EVgUvQsS4~i z4%2BqVN^QTl+tqhk|0&dHYWEmhavG+67oXZK%bA8&c?>upIB+56aRxy(S8@D89+tR z=1r*BUQ`R2Vx*tSljP9$%)GMvUdSHsLJkA6xhhiPqEsa_ zcXJO^#V~o?TQ2D7`C)g)X+Vc!&)>3_ToOPkRo#<|n(@hY!j z>f~Z?LX~hf`+y0d{nX*kMzz?02G+}YMz>8TJF-?5Vcv(4C6A|yeb^f^Mgw)-gC8!e zxn_r^`R}uh?Y?>bl&QL)SC)U%%M1?Jr_luF6MrV=TD3GdSs&(|+qZQFM=%fMUp-o1 zZZx8SO6%j0TD0t5`3zv9UK~R6gP$xFxP_XWhQ_QsB(!f7nf8tJOAiA8NVYcFp-ZKS z8aXE;+Y2lq)JwwCJ40(JuRySfLT$p|Yjm?)bf%#Ny#y}#9h`Sv%+uwpL?e!FsGxAr zS=i?U$U#D+b^syp2fEnGNE@rkRqPzQzy(=|UQdpQAho?_O?Zb-(R5rGzEu_L84@kg z3XjuJ9qTERBln%4O%BV)J4OX_rIc`idYM# zgSjvY|8VV4UeG}=2_TFYYBTNjYO5#9uQ(-Li$^kxe5qG%u{l;%d#8(Y^PzzGp7szE6G5U>=eVJso;1l!cRPmt zKqjlIdB?UQXw17I)Um?-9X8}9_tizpN;JMOHZsy_gK@~C)MR(sT*L0~f2RV-;yI_F zF@KF$Hv6OGzNOQYnRD9yN+ynanzo-iU|Z+qu(WtGu`$@1IBGR=bx8IKLx~(8R&ynN zqM*1j;q+~j*1qboj;=0a;ysZ9&E1ugrd(MggO7&Z)PLaXEIvB% z<JVY{=xdWlZx)%accta=VkFa31M5C_X$g>4)pCE>EAsTM^qs4fW2;T z^Q;Giq*K-w#{Cbm9nCjgnx-gcCMYqKzjo2nR(aR=8U zp0x?&eFR^;CH_qtPpvn(XML8*Te_W}kr|=@l&hl^p6n&|sqo>?9@{M1k&+1FLQFQw zukMU5i?R7aMjhRs%8xTp!Yp{0!w2`hvL+fx_#90qMgQ^;Dz9HB3a|*m?R)^~%pQok_ z5__2{C-3Fhj@KV6X;j06NIC>*g}sTsfEtiSwKsJNY(7M3vYO}t<@-Ce@`M3{W|PXB5Ibfp;bHMbR+I); z+C}5fXpF#^Gmtm#P-pPntS0}6jRH2@4*Ls4#+*ZN4E|Z6Ab@_g$Ga#>D*f^0;UKJYRW*-y4(<|(o7-@*{8UTUBnMf{Pg#=qv_2fNXsj_Cp;~MhD zGH+dNp-U=v_%%O2zm1r%t*}7Sb(YZZu3Zo$n_rL_E1y~V|abnp~S zZQIP@AiLo@xa zHXP^}QFSXJhD_p%1E0FZdx_KiCS(6u_Oa!nu+A^`vBwmV8I&V3gL6`wh1c@L;SB<^ z2TBTh@jsb~ZuVK}n43VFj?~h2)UE(F%*Nu|m7fQBIP8PUtrNj4b!lPW=M8v%ui-=i zIdR(iv4H_+sFR-FbEQ2Em#7EY()2r;y%WCnf?FWB9KWlq>_NRaAH__Z9yEdVxaS`e zL`-|Plfgov33} z8u}*bzgI-Ga0zRskXyVTn;w8%N34~V3WOkytdl-f%KG}#JYR?WQo*H&3$yWRo|%eZsBMtVxqz-3RbHq}@(| zv8kg&m6vW9cFKCIz!du{XaTF)C}yKD(Ed-3HMmrZ?KGu!V? zNp5)p$z(l?hr$Ic2zkMzhcb!U$?sYN)bNi~@Xf5A#Q{d_cN{rR&z{9D7g>bu;o-OD z8J?&KCvD@Nj=mZo*I)WY?auzHMzt_Owf{!U5p|Va@^{7&V8$n>$f~hNf2TWl*CX@S z?n2%awwtyQct?xyUnOhEZ4l87&@7=AU`s$+T?Kq4$H$to?d z8O@k#a)nSG_z^m_c)cWA3c5_RS%=T!YgZP3W|D3xB@4ZMFdldlnO(lVshP zG3bJt)dxnv=H@}Kp_PJ=qGrg@ZU`lPyq>J8p@D8R8#F#a%nsCpK?hfhR2UAbhH6n@ zYfk!Sgax-T+KGm8`*w9y<*n%Kr+9vb|RD(31F?LjoE{!*nOw zI;zdb4`E3Ak{jheS~$FIBDBjS+q~t?5B2u(sgI=Vcz={^h>-sFiswL#Q38JOu{^BV zo3`pv4L#txcd#_lb7^_`x^)gU8a$MO|5_n>?;n_CN24H=qdWg19eGGU$3-@~z{V%- z#?tRg8?{gQzZaUYKkeg3*e%^(F52!r*WO&-8PLZ_2A&M+$&~jqi0E_Luscd4 zd;~J|K?%66r!BvV@1O{24T!oK*ASy{tVN(Ls38@o02&I2gaBX6hNN_AZk&8LaN*47 zW9A1rr9RIbu1YIB=$-K*WO;cx`3c2?VPT`=dkcgru4GaXy2lw_$e8S#)o)I`H$f_D zF_F2EbMN|OcEeaWF-GS_@q^ev!yzWCT2Uz}7qiI@5!SLq9(flz7^ya|Dse;Sj_@fb z$AR(a_B;t^SKCjCCKjp|p0R9gKCQI(u$N%dg%zDs!}&pItoyFMhN=ft)L?dccxC3U zmMWg>$jpt>N9XrGZ+T*iGVHV{iM+-6EQ?Z%6}4^PaijVrSm5^C+kb^+(!7} z;<)bSU$Sh@b#=N z-Q04O<74^8(=$we7=GM z(-(Wc$L{Ydda*BWY=`H72Lv_}azbWKrpfoG#lD2UgoD%DkKnSBYD_Q@Mv z$8(|6c7>~ddiu3llF%;RmXa~Kzbc?h_~Cyg%Lfe(qJ$nUcK#_PLR4)3hJZ-S{TRQB zbP^0VcZB*MTo_=+l_q*7%cw<_iL1WjX{;5iY}1qd0hoI6#2Q;l7h`qlfU}l-yufZq zTw#?Fjk~p_FuFej@{1q~kY8|hu+lhJcdDGKURfE^Saj_&RCQy!zRpQ|XxyE|!5r$% zv9ppUxH)KV37%@zGcw|y7ZQxSRWW!#@X(<{yGp+Xi5$GIeLVBgxh0#)$3~mDNi#2gR8}*I#oyhN~EH}QJYxeU~zlA(3=F!Rr=gd zu}XNufOE0R(jL|<3=tMaFH+5lre@Mx?`!|w6eXFXsp%>k($!H zXzM(p^E`sAWER#1!Me@msgdhLAA3gch%c%LRWtJwxy?xeI>XHrL?aGjqe=rXSg z#Z(X$YOL#xg0N7M<WWA}qT6OswW+51dISeyMy7Rrfy8Fi z%9c|y@LIN=BkHuj=Y^x*8Je%yYM(y87Slkq^&ChFs_8Yf&pR+u=1zFDn(0q=x`J$8 znI~Ujf5SaGJ+4kWpS`v?`LLDDfidyjKADE%y9za(`Ru;+y(WwKPfN9K?V?0ZQMB@x zN-=c}YXaq_W3DCEu7cSX)_1UST~i;V*Z@aBam&{M9Pu62^iR zr81q_oIVZNez;Lwg||@DzLNlEFU6N6<^COOa!5>a3I#uXLali?4KFY^f7dm^aeUlO zNoggGRITop>Rnv@^@StWA~jzA@v6sem6I4wxqD*yUaMaRu2B+?R2xp$_ca8<-SnF{ z18nRbU}F)_cCnf2Z+N1PWHFxIu~l1C_;!k~fIJpM8=HdL(z`(6_VH72VP<5cb`rXh zEQ><#hN!~H{WBA{Me|Z8Kb&UoyeR5orp;;o(V?;fZM9ZGsqGMFuRfMkM&I#sacq##-W5#HKwAX$QsnhQsd1Vk^0Nb z+@b|V!c{)$DQ?idRGg7^n@OUF#A>sKN1K6^Uj_<~1ae`5|EsF8WJ1G#zI1eWa(`uU zuT0LY(=0(6q23WQf`zdQW`+&Ly&0?dZ4Pms1Galv=C159V5(gg?o*EVY zm}oI6V4~fOfr*CI727^5*>Dsu5~LQy(E2@u0UoEd9}&vukI?QPwm+zeMjfx7J|z&yC2GwV{x3%rzR&$ zKDbU}DCVlzIg+f4r_JeT)_!vroS&>sB2Ln=Ij;F9Ev}X>FB1!;R)DzlWG_1B7D|g@ zKgcJYvOd}DAhYSz`lZLDR!$y)&-}9ze&OW}LkJ1OYI|SFTPY$EqxCazn&((SPG|~3 z?+s-a+LHm}v?mDPI%oE`wZtQ&dCNhcB18n>^QQ>F5eRNw$$PdlaEcOLTGz0Vk#3@T zdU}{u`Zs(|d^gX$%T5?Ko}tes~G5P`BTEIVN6j)XakRF)Nfbh|W5i_c!1 z9C%xr_9D0@wFUOc1*wc zXZtqNsp=a(GhKh}8F`p7%ahkO?a#I%YU0?UQmgow6@vVkt*iy82GEa;jH+rN49HJr z`Y^(ioTTy4`iD4R))2Hxl()Z6eU%*bz5H~toug)dW!x>#qg+`qGzNw-spnW3wy)?2 z3p$*ny4X+s?7T2{o?rQK>mzyMU*|{1$1N;b-zO&ebltspTGJz)81q7fB!pa6%(_Amkrs-GKqBWey=!Zod(FMc-_Oh<46@=j zp8^BY)!v`dfz8bMGl$E}GD|CugcF4xuDMzEjDOpVdCnWZF4Z#0(D!3UK1}vDRNHnS z>8sWA?CflS+(PKU7sq^`^GI2S2LwsOM5PDL?2lZ0`VNM$Gr=fxfSL!r0(}+%{urGn zs)e%Z7b$K3K3#pC81^{vP+DB+hl7x#Q$Qnto)<Lbv?prS^E+tiRXh7fk!=`0!2Zl($2j znnyCb!^{-`?-#=}-WddUA@Z(^%`&-$BKSDS)@k=3B_Dire0*g$~rn zgc$^nw06`My&UqcDH?3F@*^pV6o;g%W0Y`nC?G{}F0iT|D7d~U_dm5vx*l^Z-1~J* zeh_#Z%8lg`Yk;9x%*En4+;>wl&YyKoRECa`zs)4B@gHWQ4!W-p$-V0Xku>%yiexghd2M9Pu5*FQs47zF~!W_obQu~^^zQx6!or3ais zbKA!RtF?sEiv(V~X`rW97B0)!KXl}KHRE`kNa%b0b*@m#E+ppzHJ{heX`v$@u7$oM zZHsYpB|KDNoau`&@nbShH+x8kVty`E%P-%mM5w8Zy@yQ@ddBL~E#fF=IRZIM0l>W1|_os9|IR-z4RTF8y&o0(vPHb1-VM!!ij>!{Ux)Ad{pDVwn3z~rB-{u2y1DIcdu=g8V(2(} z!d+N@Y#Lx@0h~uTZO8qY7%nkzt+nsTy%0HWiGuG~!Jl_z(me5yj8&=GXI zw`w^OG0b$c(9{zyIc)!Zz6Qor?&{6{g_DT*C0~83=yX9;qytICGEH!gsD^j^ z3uPkf1*@j1d1dREyYt16(NMabGa`p(Ef}QMaRD`bDNii$hJ{2y)Lqt-f;?aJsod48 zw5!EC9_ARto2S(UlC~+c#{Xp1CzD8WFl;ohAgXuW-`-HGYT0Ap!2!M9g?PLZ)tj=9@SEv-RKY-FFe6u&nWiPgtDa zDE~t7_ja&dUSX!@3J!NeO^xLnvW;V=uX<#x;Z$~*X26R0S4&p=n+L@%6o3`zUXU9W zPel6TICBI|8xp9A)6T&ii-7rVUPxcD>ElK8_Ok(h6p_W~O~mdivP!P3h;_9FCA8{3 z=$vL}SV1{uZE!y1t>vBPR+YZD(3gfwCU54FWh4Rhtj0^5y}c@{Pc0J4sWarU$9#NA{~J@LC?z5E@E0?$p~j zihja1w+EtV7)Mk=qF`BpXe_UP`fIdI#<$>WZ*tXjqg>l+_?KUL(8W2-CpOEx%)(OM ztg~AgO#bNxG8#CQT&zQ7POdilZ1_s~kZx_o5+|+1_zg{9BTmMwXK$rZ;sgJcU-@5) z5vSi2D!%2y3~2n6@F%HyTFL6P-1DAUrjHXq5XEaYV~XMF>FIi6b?A7*DM3NOB@22` zPlDLg>ba|JX8BMc#dpA^C{bru8;b605(4pkD3N7>&-cyx;&u;n(g|fveWYI?G?*Y=Ky62d<$&g&<+T4qVkKl8&EK5lwD!^%wbq!l#8pEK=W(*F zs*)o83E4h1u zv`2`inV^cHC8pZ=x0aY4C8?10KtqFl-EU|@`z;Wv)35~rO72=K@q_h5B#q=FdtUqi zrxbS!A+;$h?}+zXST5{Nl;1e2J0y0QrZ>N~zvZIKfD_qY8f^ozH*+a6K7KcFFFPv> zuN#RYtgE8zmGRx)Y%DB>mFM@|D9wOM%;C{Z&jMw`#(a85=yGY63d&wL@l!ZBX000Q zed|f(-j~olL?HTes8G4Nb)Gm9CfR}}5miR|mgLthq zxGwdm?}mD{JmQ~N^?w3F&QlC0tu3nrEMeE*V*ltuTXI@b7INR)aM$@LS*nd)cef|_ zAh$n#P;E5ek`dxX4JT7XIpU2cz6N>Psix*;7w@8@)mHkq*V!8?9Y5TJu181WA3KQ0cmHYmT z=C{vEx93DWnDUNNRuUphRj@`1x1O_$7AK%}?4kWNiea^<&~A2)Y?ff$wF(-bCaKtA zyRD{W(39ZCYEhB)Mn<%|?f`C7*vWjabsK|*9S-OFIV-%~4x7(?tbHEp%(5@X2Ir6> zu0-H9psYcoaK-D~i*B%e7p1FsL5ftvT#P)C+Ilp25` z-Z)iY!{yUFh{vY4no!l*=~8z;`jIcGx@tI^o$;E|emBxGIyj&wuq;;aGRRt_qZW$7 zKo71SxNdIF7bXihL?LG3`y2|QJgp+Fl>ZOnnMpg)bE)n~gU6Sr=OZjcSC891 zAGsC``Z7`Fm)M4T&bLnA=9Jv~qWe?A)8kTft${v~DGbh(ZTG^+Vr1F*z>C!7gW?%i z2mMgP*7I*j$Gtl}cYo`ts~BhRS}R@XT)BUaiGP_^+T*m2Gj~e(A%#Q$WfWaK~UWs?h3=Tu+P zY83dL%9yxu8)3KAUR!+0$p*>1)mzzYi{6H{s{LR*8i=xcupJpn(F)x z`a>9EdB(YvK9boFknTcb#JDds=X$uiKS;hC2yTG5Wt^ZOkZ!=jJS%Y)|-!m~+jKx64E) zdHn()Gq*+pmXtJB7cvG12Z67i#OJ`;STaUTvDUN5QvfKrP`?-YT=$G`$T5!QT)Mcr zV(Ex&B=LF{5>$5_NA{tW#8^WMX7hxtH843ypi0s>&p`$N>I6wymVd1%QFdW$#d z%_zUNW;c5G{AI$Pa8f&Sb0rEr)3WXx6@T_6N&>V?Qtm&Q&$ihHH8VF^2F`~wPX^Rh=K%xP@_v`Ygn74b-kH*jM z+3!X7?0oTzfr=v;<>^?m2HP(KRWhpQWgp|^NCx^(#jwf^$9mj)vTV8^ee-Cok7doP z(4?HqZ2LSSpR}LZOy=UOXGLFc!`1${Sjhy>3UBt7=)0&Fj*7f=_b(HtG4EF}6@MP$ zzt_sK=Ji3}`BEs%N{?z7Nm|LtgVOu$%)Fm{9kj7);cJaA#ghA1R>a>%0A{8Ai&?I9 zTig8H;tXVfp$2Gj;7Xp*!R?uU@3cX+ZpqR*J;GlOyCVQd&VHE0>bCL4=P|*MVLDD? ziD@s(k{0#a5iQzO%tKu}W#wkRTJe3<6acX_a;#_`T)j$lXJeG9c9TW+MHv~lEb%KR z_rqATFYiE|{~*vCjm{~(e!{Qp9<(c5u7^Gl8O`{l5D-BW-zk#GGVODpAP*(wwAI(= zc&m7v*@v|IrBEj?nupd?#)j$3ngMG~x2fsD9Wp)GOx>`8J++}?LvPuTNK94}a3(e* zflyUnS648T(tjtq%Gmbq&Pf;N+uKa~683%;7ZrU{N^W%oMWhM$d96)vJT%^VCc&lb z^6}pI?VOSB4n%0uN#4omX^(L#uBw4mBewCJ{ucuiaLiV2I?fI>_|tRW9S zmFIVm?6TEHrZ_AelA`qx_g)ZiOl4yZWu(6FC4^YLcQsZs*WT&tfmAFeGWD+Ww~}(3 zj1>rYJG%3w55#+@{Z}kRyM5bj`-T3aq5WgXG>SRsY*Qv?LYiG<_he0J?P~gF2LM5X z9~9y8F%3?0Z0>8zUMfzFpMNiy-CKR4x0JtlZfbUR7VPCBB=&4Z6K9IZkI*u=o_V9| zP$G0_{#P9h25xA6w?jN@py@Js&Wnv6%yPf6O(Zz%HvHmm*D7K6DMM#DF--EjfwuFY zhv4vrkj_!g3IoL=9jsR^Kol6AaT2Bmr)CdAo-*`oF!vp~>CiLFm#>MM91l9o)U(XU z?Hm~mMl~p)PovI!1X1XhxtR^Jr6vN0<&tMJ{XT<>Zg9HSjFM}IXT?m)ymJQHTz%k{ zE0e~jz0~SEyoM&-dFUSN>G29>-9CZgOFR7Bnh*(sbNk4h8G=GW_G4%bhlf-YZmJZs zyO(G7b5OfxIa>ugscNu_=_~WZ$T`@0&k(vF?rG@iLeKYI5&0a4p*&~qTazYi|st#Fwg>-20?>ck*x-!TV9yrfj^v_uzqjl z#GA$1eDi&C8o%*vv>9u)QqM!y!YK$excp`O6ihMka2_YAFu&Q$lwkKOK>QTzy>I6D z*f<4hp89i;ak38oR+r;4$@#onfe+dkK-5VXqH~v;-RQq{_~y9lbRz+u?L04McNB&& zdNw{hI0_1YPO9p&{QUcOJ(Vpi@?wn$FpbA50&sD&+oEnr2SG?2SDJ zNJh#cBrQ$C)ojV5Hu2(ZS)jM+Z$$y`>b`$&&V@y7nNB^;K8%3W|t7 zZ8p@HuJ*3WVqthVCfCQPFN6GoPW##vdJO~=cUhgWoaiyjl8X_vCXM0(RA{5H$Dev% zA7Kq(4Q!qIoJ9YBNPF{msQ31NoP>&yWGPEpPzgm5V^>N=yRt7?T8!-bAcSm{kSs$& zl6~KkWwP&N9ZMMdGPYru-!(etzRx+I`}_NxbAR4{oX7d&EIsD+e!s5kdTv(~wPdZi zYqFlJynO#@#%}HZHo{^{0N8e-@^w*=1STCdUqY8nZ1&z?P6ONi?~~of z=1?WXKk^0Zzk}v$jeQt@*@wzAjdH|kTNl2gqJ7Y7pT9b`?3^~rb(=?esJ^saU7vw* zbgAK&L#S@0|8!rVVCC(r1gI6Eu1jiLTeHGokxj;?O&IM=MGj{a6AT(IP2iPwOv2|5 z=;}k{U~}4;OssXo@=SW3kn6TCLxg#zWD~-C;O)g7qYoF7O7~+ zKIyJQ!7P#9KU8K@#=q{qWp|45u;MZ1A-=qon24~0CJ&wDl^w{h2w(t>!fJ4SM}r^u zgf6`mkL)Cqrkp;P9X{RRl6BH5=3P)_y>&d0vue!G=#=CG~w#B?JUtcmkZhV}! z6r6Zpuj9&6k;=3LyrP|rjm7?=6nA>C2GCeXCs6j=X@N;1qW{XDgt(rQ95Do>X&P4g z3T^M?e|8dyV^*PpqE?HrW=LdVmSjU?W5TVZ8OE48PnLJX%~@7Bs4L-CPu{KQheW_+DtsXjW4EW1lZh73;HO8%JiTb(#h68lWO zC&T_!go6)Vqq^CGak24va0A?EviqQzXFGcD#7Kjm`CW}8uD*z|>*BQOqZzqFj$dGN z+{NT0ewa+niv))+1A+soY_`@mdQRPlzT>G!GfI7@-k>q!!ujPXr4F5x%Lc3NL_|?M z**yI_@&{o=pUD(Q(Xok#b~b3>O$39iCn`aI0e+W~3#B|pCTv10_yZuU@r+ zzV-HP@LsuF8%&TYmI0F&F+P<}x~WN>olONT2! znIm%65VbxgsJvIHfuqc$7~cFEL`-|YS^N!UH#OSauw>2SpoL*Wq(-G_?hZXE%e_aO zw>mfzOqb%&0kkFJ$7dQr+gk)@6q(p4Sh z+^Gj|e9?Be71}!UGNSL~>CiHz=;s(9h^3@-aUiar_x&13*V3;dO~SG2PCM#%AC$dy zGcVaNr7?guw81QIme+Z~Gs}%iJx^#bA}xxgp33&(KL)3NIN_BaP%X{DhXt1s1acZynHOI;ll7`Z@NUVh(C?arE2nYp_}Dq3x4S(;=E8*wQc^|v z`Io7HQDG#Q=UK}7dHD4rTi#r7R&iY)>_7)V)6`7mLRfi-Dtq?p4h>q`TI+)eWu4Cv zSH-ibw=(VPB>PwGV7dXG7<2 z>_949lP`hj%tXyxgXj@w^;793izDH#Cfql=R3|4t78M=Z0Dr-Gu(m2aFF)*20Li6| zJ2n>ckBj$LKF3hs6NwDtzu+{Ap+Z`YTtRKYKT1OtsV;AxQI*B4p`pR#>-Z@xZ9K4V z54&!&)CLqUIr);Cl(u_-RJx2CS(<3;dnuypET5L!;AFP&RUH)bfMX8 zaU(r}4pK>eOyreq&h#zzlo5k`*H?3$L)p{LyRxHo?`NWJK9b$0%B4DmvC&GdmHZ%b zK$8SnBZ|f~eB64|yzKWlWS^Z96%X6`qO~^eDvPo+GBUETXo2i0vkkxk4Ka@L!iKvU zkB1ic+SWU7pLLP;rbS5^!|hwz{amZQg&ut99Nof8q7zW2E9e zj-&EhgdKS+h?;%)5lZobnO8r@guLxxCr;{`=D0gLqAmt__`aOvyRcwK@J$HxTE)7D+IDiqfAV9m#hk z$#7qSc*?OOnaa#%UiLk}V3#;9=n`%DUJ6x=Yw!LAjB(+pOZ<-`-hQvRZtMfiEsd#M ze`fg18_CiFM<7pV@}t$Wj19Wk)ZnapKmca3Dn2J#dRw~<@@SZ=qD4a900)$a|#ML>fq{~wV;bux1Gb@ z7U8~F8>GyP?9Wi{PPwIv806EEN2}J>Z=dg+V-#JkE6}61K1BOfT=d(DzWUBxr}N*f zu7kygK3!YR7o|U1&Un9iaGLBXJ6LCW$p09!xGwd-i-kz7P#<4Iz0F#D`t&Knex5>| zvLm|YVe5qT*>Hc%NQ>#xiXN_v5HaAo$y0L0O)kFcCNQGg=WxNt(eB|GX{kSmlsIKq zF*FZ=D&)RE9uQsvkB$NjXix>;)e`zcd$rl7USW_$dtl9;dzPjBX5 z{SMhp`?1j?lUs|A|>QLso|3Jd8+J**%KSXd(lYm??HLj2@ZX68*hPXVnw8; zJz(BG_tR>Mic|*A%k|ENKXg`CXRDwWA2708=GlC#^~ZMhV5|y_sgwAf>8RIBk0*`Y zRwl@u&aKxFHAqfNdKyH|qx_Lf4Xk6v@6@e|9wJ20?iR$*8$scLf*RWS`7t?^W1icJ=q^bMl5O?mrmIw zG>^c?&Qvm2DV3Lsv#Tmxs&N`uhYnsO8j7m~In2 z2i9}cgmFfKL$N!zJK|YUIjV>0gcoNLmfN))>N(&Q9G;9XDbveC#IX8rLtVT;X&cC#0q&H=!8~xZmxVf9@9Ft8FqSwyzT_LG0KFanR?EGtRsAGJ0coIDy*eWsAEs7Irt)|gX$2S z#Pq>Q4o^vW{Wfs5(`x#|KToOP zDwU=U$|MR&Me+6{ig)7i_}OF4M~@zb=znaPefIiswqXxFSkYyzIgE>wy(V|23Xm5;)U6(Y<2f8qi2ze z6Nj->kM9ivm*of9M8-sFg2U5OF9e!z+MggpE`nQqth|XSj~P7gnl6iymM2X;7RCZ{_vax#jpqs?i+eTh^ERhx z7gcL~&<`^)bI5ceaqDucHB1(bo`5#XQ@rPMojT*#0pkPVf$VuNujS=thxE5(Od~CA z^pr8*`DMAiZEeJS4F*hmtHQ7%QTjX04138s2IR!wOycBPS&1ZN*N~ck(sZ%02_Y5M zOwa?NhpDax?tOlKzPY)%iqU+N{J{o?7TICO7ylT?tmI;=KasX2w9dFS8c^n3X8!D% z2ta-nL-z$)gD@BR$G&~r@r|iz0^RV~nDm%#4YzMN=IbRt^T04IDzWOTrt`B{|5&M* z+u6j$Msz7*0lk?&7msF$dd#?r8LyqtCEq?-lmvuxvvyh7kmI-78a0MbfmmPY(yG*| zTw5*aq-U{OrRUgt)_Hc^@@jL{9k11Grh1&W2_^UgF;NXY_PIgJ zk6oAB>dV0&uOp^$NJNGwp}nJHFFpO*aDOtO!7OEti> z4~o;6pLV3|e1%45u?3R@g&NB3S0_bf=R0}O=OP!Vc`7Lg1#u7n=CJGSbMDbU%)!h9 zrrDB61u1JA=OQzYyHE~)rbykbTw~^b@|L#qg4_1f=GC$db@3hJir_!COpW^&D|yRf{d;?B*@o^gX;63I6X}Y%-5ggTTKQ7$ z7h@1cWWOhj_576WUfee#W9KPx|9+8?VFKlQq=(`0{GonDv7Nm7=H-cE*U)$4If;qmU=HZ(H+}SIp+WfS{TI-UjgIT19OY78eGPmv`w$&CdR96{ zzyw|zYLm9Lso0d10L|UCiv5q9*whM(ia=FV;O8D^SdZpux&v-6f&;~B&d9-1#P`U# zXJ*fgV{`3w*=qrC(Tmomq0&XMGP9iGAF){0P8KU)2CAnDUq#pO%^q#Y9b`yP9g8pU zzdC(!JOrahC!bWjEEwP0(fPV|{w+vApH@GC%%me{-j4DmJL?fz&MzkK8pYUHB=35? zbiXKoM?`I_<#bu^8obifj19)&4H;fl_&&dW9(n=WQtFK)m@nu4(#=bY%kf;WJjS%k z-u#8-Tau73B;UrnE_4K@5eK`VuLsMB3ZC3ek)wRMoZVH|(%_AcD6`=^_mea!BP|_e z&3Eo2?KA_XBvAm6he^=T}!(mz9G86d7T{MR|}jp@mCD*U0bUt-1!%S_I`C zmUZo8%$;?dG^qJuyw|{z}L>*5RaKSC@Q^=JjjM!n+(*$V_^R z8e<`(-Y*DXN~rB0-wo6ZY`j%vka2c|((VLqh^A`sF!$=+P7i*g6Rc&YBm=#U4(D&D z$Bbn0XW!i|({F@vg!T<}qZxnwTHa-J<6V$4A`jf{NsYddrx+JCt%7=s<&xnD8FNth zpQHAFNKF5O&Czb2TCy~6`ce0lz2fkkKM#%ASHDc?r^UsU8Lf}Jj-hq5x3@Pn#lfjk zQBm1Jg3Wq_W|}r}t!y(Qg4CVoimw+hTp(abxpSly*_Gb$vaJZs+0QN?@kgW39v?_? zbE}&bu5ErzuFLrlh55QM$QlL7^J-heUHRc8^Q|&z(kLTxE6a*UmpIQlyAl(#5iXPE z^k{kg|3*(UvYF1@*%_OrBq_4mLiy z%xHaV!?lQU?_P_Oradt=GlJu&Zo8H7l69PwfGi2)nqx#?l{n!MIvvxJ)D}!rhw3jCYbog)%UB2l6T1R^4)L(mMAE z@7hY6uU+JrvE~sEDGN}UrMHkc=+Rpe-=jM1ob;y3l~zT`zi15O2YzVOPAjeGS!yde zitN7me0l^)C$mV7S+`tI`>l#xS+?0)xDV|JxI95E`xgb}`r5(>#9J{Y=aE? z{u|*7WL+{#+x`hJps2v~#89e;vFoItchYQvFp$lSRTpmD!?PSg7;VjKoXw9F=nkFpsPlX_W{| z&T>}`-@H)tCh=Wq7oo15;F>c&^+L@=#O?V#B}KTxXRq8>GQMS|; z3$3w?>&jSfS#d!0sLZ?hqttf;cm&tF-_$%zXXCzxizP7fu>k<(IkX%w3_+Wcmrl); z{Stm8QJ18p1yLme@M}4&ZL9v@*cO~THx6>qp$}v%H&e~@I7%E?`u=^Fi3g3fLL0pq z^z~=K$B2*ajXqYXUykh8`l`(}xT5OK!H?qR;tIfw{JN|oVHM+}M-C3*v*WNnY*F`d zmg{Z&hHKJj9uqCglWI4!UYe_>D>94#(N*g`a(3qQIBv~h&AD`VDQ>ESO4rq-j%qU} zZ*DNL4Xbn2IkR}##JHPsZZ63*lK!y@$SNm6c47q%f1Jc9oRFi69LVz?zX07UbMn9o zlW4FHeGBm7pdVB2;9Z0y9UYu#6ZC9n$emttG94gLni>9QK0D#axdesbM8)S7vJP{P``LqLV;F3HFFW{WOLomGpdA4DJtDxXu1zJT=dg%R=cbs%24}MP z$qKB8NZlrnCZ(c2+)Gd^8ly3NO{TIq3!GhP0osL;4l>Vgy|J-hoIDcKTrf^5@R(zIciixG=o7?hj-TQr& zz72^)HOC4nDsbv-31iFP|4VWnN#);d!9KLfDQ??Sr!|%J@uj7*9%8NYWM@Nn5L&wI)FWgr!kq?8A1$MrLv?^qO!Nwo1Tn& zj)!wgr_@ss!8Wr4po>5Y;}R@=DQR#xJfP0aT?jBcsAA8^ zJkt^uQ@%(zvviSAaE_h6P}RtzlLOWwnk`7^Zp}@8%*i=dCIg!F;)Wo@(n!#Zz(0=K zr1HZA^lZnToJ(yI76f2G+0|i)p9&|HR@%D}v6Vu}9({wD#YyBovnq=E{B%RlK-pF* zhv}PF3Dvy5dNYN#G3nfIg!qa&<`X?t*I5!8oZ){@pqR?w9Nefr`M~_^T;lnkh~{De z;QC;IK7T+gN;-1yL8VO3EdN~=mkGkI&w^=isRJnvv|bW#=T%j)qR2Vuu6>oBGi1R} zU@d9Jm&JVhX%C+I8Qe8~y>Gg|X)|VTCUT6qM~8>Yn+);z$I`}%$C~UlA{F`bkcK<6 zOpr2mxvRgXCdOlId0dQ#K$qxs%@vR&XUB%3B_%9|D}#S3izro&+`6S~8O_ir&a!8S;n9M`=+nRy ze2%?d%}r5cNv!@2O$!XayR*FIXHVG$4FVvBcqGi5qm6sY^0Jf8)Xk7Fm5(;lrq zz|Od*kizur?b#VmL<*x`46c6v`STcDVRkr|A9T|DHqVgCD}|;}bi9k*jy*<0!KpF- zSG$Qe*R&BdG}ojrXa+fu8^UKdLqS^z!#pc12quAAHT6*C3m)?%XOLLe4fXo$vADlh zw$&T-$Zad#wKCXKV$EKBiZkDvs_#en+M0xkOTw~)t?l{X8Wyqeq1Qw2>-)U@m}t44 z)Dwly+}C*Upj>Zvzo)Cn3;kP1UdwqyAm{eDr1PhmKp)97%Ncn>n%g$Xs2@?J9K>C9 zqG)0EOB2wX&+tE{zn2mLZCSI$@2>`pLw+F_YzS*yK0=knRiyLq1`4I6WQ?1gwH@)B zu)aF-He-4+cQ+70crV!IF?snamo+4DI?xM9q`{0Sb)B;-3^PhGK~+-)nG|6t$)&#T zf$^pR=Z&zu7Q1GT=AdV_&Xr&njl6@lCcH{A(}&%H3P9|)(zaPB z`@2saLdE~ceE*}2le-lz=u)FehrUky{7?misdjX90HHQi_-?Nw{Hjr^YG86xRpraN zcI}$K$&hs{k#)FvUbkf6Dit*DH`SPj2R)o}`m-$#(dNTah7*0g7T)OSX!s_|rLkX{ zPMtbse{H1TM)SjJlb0@Z77{-W@?Y3nRH?U{YiGab(c@b=?2es3e%u#32n<8)4X`rf z9Ou4vVY?UQTxVva){ZY%r}3Tj8xZ-CzCaF6G`6wgh0qg7+3dD*(b3m)iZ!mikQ#4k zv)Wv0AEDbVK9@P<*VJUru_)cvZeiVKQJ~#oT^*6w4c~$U5=8`eZoz?Wt^V}={6Hsv zalRqK&ADrHapuaBADo1z%p$oqaF=axFbdw`T4y5((w1F^_wzLdK8lbk?rU013M`&3 zJLfsnzd^+NWY_j?7$CR)gJ)OF&>dBKM+@`W?qwxMc^cg3 zq0(E}v&#=-v%E?31Yp5HHr7Vd&>h3Z#wHq0AJq&?b|hx>^%XPN$$Yl%|X97;;^fYgXT-N#4HZ?DRJz35P!~>-)ch8T2HTCvy_fY z-m3Vf-A%^)JvgZrQ)^H*zrNhO>A!U`nJN1EnpY+a8;pF2kTty>ohDh*_nY{5Rmzb& zn(dl>$-A{KZ1#{-C7@jVd_>-|^Sc)xQt3bIyZ!%bF|&n03H4&*9v2-^T}@7t(L~(Z ztT}Szl`785%j+7SDB4ifr{cTorg)yI+icKvhc`^#bORL@vWXKMcJ_VaaD`b^U@8u- zl8CR2z>=sVo*}XuN3gKl-iL!tvr3LbRUl z*6i#o6!PqC5y83h=V?6TtF5MT3E&^ALR9vSfvok;J9jyZ&Bs~Cu#{s!PJJJHPGldi8F+Pj?o#WGM6FpfFS&9Kwvs2ia>BOcpGNGGK?RUm6cE& zg!VYHlFni_vp8kmQJ_`av^!=B6nvP|6Dh2D5It*Jr}W)u;x}@ve+^&z!6fjPWB5BB z<;MoXodpzY=4i3~#Lf))w3L+oGFKk9KvmqRV7`wYtO*Qb#6qXLHP?{$$gNaLX8ei* zr_dU4w1IQg)@_40IeBu%2%sM8ciojuMCAvAPCmOVd@^hssr5XL2f_v~k!uQAc}9i2 z+J|QWwty@gfC*k-e)k`1LuLMIZPW={MXIQb4-0tI1VQNG^Y6?9IA;7QV3#az%d^v~ zjAO*bN1c4?nn+|F#s$YE99%RfAa@dOQ~65q0|tRVTYuDOAST^kx{tia^z32$LcE{b z?^0MN-(r4zOt&C=6os07I)^tgFWs!`#c_RNU1Djca=ebA$fLJvNx@By0*??Yx>kIz6=0 zJ6k?2EiGdI!7r()!$+P&O<2(MQLHA7n9ns+NFxex@RJ|0XXF=?9$_#qHR-7{b)j*V zoPSN(hw*0e=6*6mG`35B&Fp;zCxcTy)lCvI)YsQXB9V@ck|8R`nSDV5U@CTy!CNsF zknHB=0r#}BtWkFq^oDRxx;mXcQ#QDHZbyAmGxlKyi&2riZi(U04!qQ*@qVm9~xtUo!E)G_BIy?7C>n87v3`>SQ5u*KDZ_WO1 zRCR_$WcDW~O}A9q0f=Y6Ir^=M2%fTb%d9NS9O{yE+*}MTi1&=ohJ&^Qn(Jfo!WH}X zNH=Z?Dl>vRZl^8BS8t8d?X8eb);x!|#R#zK=e}!})QLa3W&&lZ{$xDu~@PK)3WmmN4iI({Zd_+)u-CjQjz zX&i3;BPVr9g>Mcy9~h@CNzb-_rec??1YvJm+&M z4)ADbyJt<74m*0lkPnL!7JdvX*4oHYO@(yJe5MU%I`CD8YE5D!tKP(IAXgVQiu^Vq zeB2L-)xS#s$*b@>ph&xf9gCVy1>(>nYV@^G)Ea=Qt87j+NUR%)Wl!$4XAcgE{jjVy z>K3RBbyxLKEGOXuip1oC8vF6bco}2{8hXl$5@nH&G@6Z>oGaGpv^&GR>_4YhH&I*f zwPg(qY%YW3Jz%)Av&BG^1||F4xsYpoBMWOdoar%U4tOBthLe-HAdHj-h||i%iM-t^ z#~V;_PUhgVn5Ii1HeFuReq?&Me&i4&kh2;2+OG;k-#N?uEO?4HRlpUp@$Z4;A(o|n zjx4O4su=+*L_rSRT-MxSR39O2YqKtp9W^UWx+klFYHL~tT=s+N3vcg=p=W}u@NY)I z9TFJ{@l`k}fM|cvmF#xeBTctSSK`lj0lhzIdZQ&B~l^7asu<7b_9f&xliWMf4+&%jtLg<9d!T`*JI=_CNtRpS0B zYAp&JA5H?NRMxO%_5+}zo}Po%dC*M4_!fT6*w)q-u95I-e9XJ?a^4ED<>lpdUFK!; zoftC2*sA6YHhmCv{oED)RupBMlz{Bi-zE;fa(?~fNnC@hWIuCL)4_zZco5e~ldp_N zkIE+@gBb*td&X!}x#?**=GwHiqHe>@4(%p#2Lv)v<70>rod!EMfyd2v(0Z&g7t{oV zSlnw_81o2O;@GWGvuxL;9ZS?=G)sOUJ3Mpd4D4(c6;)itFD_;lpb2@BE1!n<@5$G` zwd>}IX&E=hOlakA+;pY=?GpJvtkTgwns43<8z)P>Fycc_4nn&u?n6+<+VFd57IEnj z7uekT@iQmBQh&S48*ThWcs_!QHVS9gEqn6E_bqdFNMHoi9)4f;VIgoWG&EdSQv+SP z(vdU3#RXh~_eg*RUgN?6srhBQTtqXO;w{U1FY6Een?u~slYtfBaQ&r>{zZb)m_`;& zoX1;Sz3Nv5KcE#qmAINO(JexY(c&UO`)DRzCBQ-$^iy8v9p^8}uP)_Ppv}4yOVmiL(=P*&@gYp4ClZf8EyHJUq&Cay;QtQ4J5z z!n*}BIT%N4}j=Lrp2oxk|w z>zEVd^&$+@zm{8N&PfUhXz*P+EJIGHy>;}jW|047jZdNNpp>0naxO(~q)fr;q897$ zygm)iH=Y*YxS{8H7JA9EDFfOxS_c#;rdWu^j61UB+Z0!R_5N5;wi@Ruk!i4R3%9BV0csBSlt0jT&=B}{il*t zi=W(ph=mBsp78_ch0nTFlUdS}xkgIW=`ub1nqxI`dbi#dWJ8*7hMS}p z-WB8@IHyz8tnE$B@-<+5)=kr0sx0RY@d#g!Wl(CnlO|pOx!kamK5HQnJK`m*Ir&W((8a z<|H*9N4SCZ%|%DYzdPdj9kafR&GazUc9XuexVQ+)CYY(fzSG`*XImo$XvFKw58;6k z_1Uxe-ynF`m61{~1A%K9uJZwbf|DcjD$9+HjV75WUA5Y8HUupn5 zd94@(aSdlZDzsKstU`NmK3W<`wex(Qj4d_b>$<((FrSRvtZi3oLj#oJczvis8+#zxOF~A5A&PYzzMA#nf|ny_xldy{_UaaA=)wx1dG#nm)261fj-cHBrL59k zDvwWiP<}j<@PE(o$0EQ5Md0%Dt>-!(r5@Z$vP?hD%9!ZeSvjGZ3^3_Dl-5FsVlwg% zxv}1tewpRts%@Mm3rK1^q7zv%a_SM)`W*{9^CTBO3WkhzKapnHlM$H;@#F6ko%=QD zsxPX&@kZqQ^~?ENHY)9i`2)p%dGbCLeqg7bC@;#AvOna>bUb708@1e_?zv3792p~n z&NL-OA6Jx_nF*izmhU1HIib=K`L z4)Z&@zuov8r0$@NXjv!xjPAfCI%O&4C(04ZbwR&_>(B&P%Yy$aVuQm4Q!ghY`|9*A zh*w_W`<0Z43+|)+KGb}bSVjwstw!fU^Uwn=i!Jod4JvLKgFgGPM3p?r^0wM-!fHAR z$;L9%w*B{SlZwt|u@M6PyLbR9O5IvI3m*s*TMV`V+~(DAf43J?h+&iuHYn3MbXg91 zY9z=5K}QWlH}rQ#M$~awn110pf;@mbCqphDtFEs8&|)gV$>5~`z(JQ2ZRu9ycFp~! zMl+w4OsH5Req;8oJrI!WPTqs-S7kcI!Okwg?g~`E)6)`jHsx!H_sZZNPg$+9qiK1g z`?#RHd&EvQC@3gyGmZ_^YX54xrvsxi;U0%~bi`^0WnR&4-e^u+fv=c*zgq7i6zs8+ zlO$oO2CqD@eP!Zm(?ww>Ia}R4!}#=Tt^;}dq1w2vSVt+QOGuz+9QM?W;=XV=jB4Bd zt@Z6>aoz8Gd`)?k0%ErPKyN)R99SzEb!${OBzD?}ksASW)U6VyRS}%FmR4j$#MQ*M z;NW0jSQhLNtbU-jfd{rOYTC`BHf~|bfG~7u)zxGW_HcOI=pv>ARz;H6#)&bX6Bi%H zj2v7bRbuX`)!sBlL5MmU#K^r*c4zmdmAKHFt##Nrxwg5or2v2#>!lpm0uz+d5&2b7 zN6LO#DBV!Np^W2B$gGN{M~BRqWbWLZ@g!Z1QYL-R!I-N{tBER2Xv+6@-osDT_tJq? zOfEtPqV~>xfB^EDtoN96AA?oM3t#?5`|QPZ&TBg}vKB+!qZNaue~Lt|BbuT3LJ0S#S$_x=u#urf+n@Lh za6`>tHfx<&3dF;18%$aOj4RZ_{s?lbYyMlSyTkjht*#Q+hfQH2p(9j|JJ+clY1en{ zmD8(Ri}d2EozYeB>3`n8Cnjy^(cNZ>fK=@k7Ya_5&DxMt&XW0(v*v3;qKt`+4P61x zC2f-gxYw+?S>(z^JWTYVQ&Z(WCQrcIunFYn0n`au85#Bn{Z*Vp?Pnob?&W4W{ZqwA|S0!5zxK2A-iB}n&5=tlvV0wB8R!@97@ehSS*-Rf2 zws#;aU3_QcPUn`Ii8UH`2ba)&U0q#G%?cdZq44O@iQpQt?o&+-mVPQ7(dWk95CCw= zp0GZ{Hn6_dEh?@HQcRDZb$R@FOp{P+4cLy{8)+lRAqo!uiAujNxxX--=lw(dSNuVg z&lQA$nG!^wfMVfLIyyS%;SKaIaCN3RtjVM>Ei|nKTP6>_b>I@az@)L<+$ujO+SHGg08mn(6>E~ zcX^n zg6g~?!u}9}w-WA@+oHDgtF@O(oqM~_-z9)(U(o@hK_6XDd%LHtkB4OlTYG@XU8_^& zvl87Y#TRUEG{I!xVQ@~7J*ac^JXPe`$N4cBF7-V#eSUS{GP^BG@&!xx=Uv*hr`n_E zFD~(avM=+r=cg0k6oxJDC&n}eSK|cHM$%-}K8$$33HPCG2F8QJ{{MlsbQgH1tui=o zMxAC{B8zP-EJ18T@H%cstRKqejY7o2m7NN^?%@H%Z(HQ;f43|8t}*vW^Hi9*+6R}? zwZ_9elUGlROF0o|#~~Lo`&l*~ydT&2vLMi=xEOL1*&u?aMYvhYxf5di1bAWb%NF%o zq_oRdx zUl%e~ZbU~&2qyUAPM!D39u*}3j8+~lWo=G@(YUr%C4EsdDcYFg}*oWCnd8% znjRaKvqH%Bq5;O7n21quv=&Mxt{s<|%XEl?C7Gs$Pbz=0nw4gIUnk)A=0;%p;`atM zVV_>iB)muxJx~&h3FMl>;p9-OOwf)Yi-)9A8}|5Hwu;X1@d}j9<$rDP&=x3+z7x6c z-c6gneR~@H^d(%fNFQXtpmO+#=m9sE37x9EDVs~@t#S(SOl@p_j(QGS^-rECXMdJ~ zyx?dV7Wcc$IZwL!5C|hFp?emlZ#}6MkCimKEqD&-&U)2(mSlGEKZ@3S+fCQ-9Px#A zXKxa3^m)^t?mlmB)A|V8yI5T6Uea{1uf1%b9*}=mT2fMFAFX9_dta+9wfx0p`ssWm zB2Zxg#EJRqEE(#Cwr`%c2StVTo_MB{&>N!A9diTo=vL*u${U#Of&ixb#Xx0+LJII- zmi_#%ULA5Pa+nM<`fwSpPzyEd&_Fx_XlO=9M**xP5C|X(1-5!yQUkXBqp!ci1MuqL z;9!ue#S~oqXsO-}07!mKES$1)UHOpO4K4xz|CiQ^VqIG^J75(jSsui6+ScA4T0L+M zzyo$Iuy> z-pYeY`!^#un$WB7yBe3LHSQ`dgak)84_HVUk#BrmlwP#4xwPMm7ye?u<6~Al>xdSj z=FDr@#04oA29n=lGa22>dqY4Z7giLPDOO^WN>|0}}d-^a>d&PlIDAr`(VB*nM{-S#i& zi>CT-LSJNC%|%c{+nPhjW4 zJ!w?;6DJ9o#K%Xg#0$I^?HJC`>M?9k%wL!V+qhRDS6J}a`$l`KqT%}qy%zoU5u4&9 z=Yl=yzGui=Mr?+wBSzWcYn!M{QPcvm2YTayg=U*;JN@SFOr81N8OPe0w=M&A6+5*0 zE19`xVWw8IRI=MLSLl!O?sXduO;nPmD2g#f-w_;G&Od}SyK$l{`b6P5#s2q{C-+mr zW-~Wf;>%HU>Z0Jl3`;v?0Suk2Bri~+z53tCuM~VV6L(td4*@&;n_p%Jxk*b|h!2g3l18oKLFv#VqOmwV{gf{lym=ZrI@N)uGr)0~ z5===lX^hW`{Fw~W^zEpeMMe*i_t_Wvtp;qiJ~GX{VnT_$Cw7lDa{S$ZY2k(4OVAo# zg5^e1LgL{m`(HYUFH9%w5*+xF(WfHq+Ntk{IV--vlsdb^2og75_jhxo`BuT1f!*ba zP6r6Eq^RpE?pk3#$oPeL7dmL(90E12Uap26w?U)xbVOJ8t=K#54awT+k+!w0LFQ6g zC`1N@y7(DcGMN1+S8=?Harrs7(cqX}qKKW1fp_}ISeIJ4eOIuyvGi@bVw%bKOZNGAE0j#C#`cs()Zt2$LP) zBM*qL|Ll30ng4ALkIp_$H*C$xdrGpEjO?z(yW#|Q<_73#gs z2l{y+M0D(8!Uk(|B>`wey;I^Ai^hYFaY?V7!$gKG3U)stuLuPE$vF}*I}KI$ndgWQ z$1ilzXs`Cl%%-F%r`bfZZ)M3`HWN=q%>;hDv0K^a#R z@>E&c=bKGyD|gS~f9hVZYq~3SP92uvmD+#3jwJLaCH31&bw7_bHYntJdw1NgDNWoj zuSZXsDLH_vJxjQ3;vT8Du`N>fd>DxHtWJF^=8_@&1j{lDrNNI~^5w+A7~J3UxX|%F z-m_f-r&-602Y2)v>w$lJ+#N;=9WbAw(P$`U@87HN1;ZU>Z7s&^>+kPR4=gqV!`2#G zUbM6o9{dDkTfrTtd|4UwG5cP~SqMIBL)6*m3=u$OZqp%pzs-o(85kLX54kT0A!6qN zn7?oVwx_nd0I5ZWu*SKb^BNL87f#D;4~bFVW{xVr24Gd%=KTwZlcsKsWsK~!mlNGv z`D_3nseBBt=a&N$?;XfDOrAN1tFa*9?|*dwK(mL>G@FCg1+q5vy7ih3>7@ zJ(&FXXLl}QHYr?Z-MOGf9hI93ju)L0#}G#dO}Tf%QdyVVqcAE;69os9xA>%@K{3Nx zdSlUP(sm}4;Col^(e$+|YHCfeX1Um`;LS=kFr>x{B0+n>X4%7~js@ALvg<`}jU zb^x}M(NouYi1&M?3|kGhMMX;2w|5%&Xjjtj)uLF6{Bv2V{s(1=T><#k2aWc^e6e=hzwl>nr@o0YSobv~ErT`p-wocr)+K>MHM6~paz``2_}cSen> zjK_!|IORS7zT6)_?APXppxuHdskU~{3k)3{9o%uCb4a>#^7Uo^fPjl}E!%cb@YtpP zaUi^Dz3sl>@8HNI)2gt`$Bu#QFfAjGeZ7Ai`)*}-{Bi7iYT86DM!lv(GFFVwq`a6u z)TXae%J{0V!>-}kLpgD}@amRc=}Ul)CS4Cdr!d5a1JimPSfWZ1WBr2f&=HbSQrGj2 zhR!W#E3){H^K}_scXpW0hpopzj0#VUop8~r3v%gC@{4^tmtzx^7X8*^fgCNG4)w;@ z@6?XhGW~EN6%l6M+SNS?TzjrF?mQ=)PVDonPl!X@xS=h8P-*Oe&D#0a6Ro*A`W25~ zv~eHuS9Y;X<`OUCyOKd{uS+s{qbqtZytlJV`^4LZ4sDew3EjMX?{ywUyZmKp|6g}9 zDERcqZ?_3Wf!zmx#|$@3{(u>(>im7okfxQ48Tu6N8L^#E3xcxKPSi(0?yDD?J|@0o z9XV&dKKEh9OMy4L!c%_ zzM9-1(=nt{`NzuQCU_W*gmj91yg-R*-ph|}@9I)~1o1etvyGP=##F_F3J@-mLkXbk zZL^CT4P4wqgIR{PNk z`*Yz#g2A5JW_20?u|?3nm8aPDwJsbFEHabcpO(}WA@Y^*t#%-b|%g)K2$v{_+XD9BRJ;ipkb)UG_ zV`WAfkEVy4Q2?b>?=UGm4jBFo)kukQU-JpdstOlKG3@rGmPocdvolk9Z zk85$wT8p|9QZ4Fwz6a4#utux!BrkUYYX{tYAU!fLhhwq+tB|1 z7?l6UR@{HJeg<&B&qN$U%TU_Fgw`iZAOTv9L0yAJJr$B*4N1(oIfjqBn^ zA1NwUG&jFG!~@ZL+=JB-IV>NNtwJK0M%wnaon{Pt!rckOkX6!fZv&)C1Uz{9M%(RR z9C;&+;~PWo(F?aKyIWLro<%=W8s2Rn`8eX@Nn8MpJ?@$Ei*V_v(TByF9X{e*_wRzx z`9x8nK4mJ>00l7>+562mEieUiO6_JBbZiYU7dJJFs!nK@4E0K3b+tv;ES z$@y=@X)qw4{)Kx;R|zr@e_3H6Yt{w(qB7sr$?=rnmdmZs~Hr zLc8|TO_BjirV5egqr^oI%gOE(Np;~C`e#OYnLmfYc2lyqKy~QUArH#Uw!>xnz*Ib+ zFN6fK%Z-05Z&UC&_^Sds1r%`pUIAxJ|4;$-{y_z-?r`niceTMVU%O-h0r>`>eicE^ znQ?LrJpFqOv?15P>_61NCm%ijT?0>dl560%tQqZGZr;Z`R+PVbtIAVZhp+AhG)~ow zF7;t*tw3$V~Yw%#2oZm`Y0Ic zE!D$&ZTz!-VUw9Z{zF%&aT}2H8qVb-!wf)s7EGs>CGwi1j9NQ8Ux+R~&m0seCAe@r zNI!q0{o&af3SGpRHnWU%6X)`u62f_(Ihv9uqBH065k~;+P!il2F7GVQ6g?Ax6!nYK zLn0nmH}2Zo6y}}3aE$bP@uR(bQDLF;Lj04Xva$k+(fx3Z3dV8Bna~(CeARPSQ&U5A z2XaYu!j)~iCwouV>FdqAUbji7g6Q<`*=JZ4+F74 zJ;=mNL`GIEgJ?8)uj6~rczYn8U8-|p!3;d*6I$n*O4P*nOol|WJ+4Ug)0V#_!i|V+ ztflR(?hV;-Uua*`qG)c|+Tl8wd3sY95%U{38K1 zg1qpv;q`D^K;Gxs@N37I$J~Kx_weutOT(guQi9Mh^ui4V3PLGb6WjALumpf1L*|th zqJtX+R#37dbZfdH&(-0O+3wSOX7;4enF(?SsX;?={W`=lHE)7Y@#(Bd_ARUVwQGpn z!=Q}+aYi26z&XYZ8{IbyAA_kr0vF$gC6gaXK^Ut`;|BOE03*(WrJU|x>5A z1+{_S<-uDZ7oDe@4bZ**khNqeFJoq{kG!P?_*<}WWCxQi9Ov=BSvX*?Dd*|EGiKY~ zAi>k8PYVklW$gL6zAo9ruaVSLO4av*%%}Yjr$nD4E5kl)>?Y#}iPteBZ)k8}MFIhj zJ>nK5=T0J1#LBEK<^BrT*HduO)8x6BJOszUh-vxjsX&YB31S>_x%y!Hi>(bg z)Ald$NowZb;M1j+e*iv-Y@|tIL^5(Tl~I!jw2wa*7zM&>v}0(;|wJyOAyTxR*G zZj<;251B@@akFJJs`=&c!Wx)1fW@t^r|)k9dBzy(l9X6oU{j7Eor2GMuT2&fQMt0t zGwVNBIiLe_=&?pzfpAag0uE(~iHqwNSRQBfy9?WqE^w{~q0as3&;xG3gj90qyNI-g@%qgn8>B1^t$s4 z%;I4K>53OTXz*jZF46(fxct@U&`#@El|D_uG`ysjDkiJSt~9XX-ZWzr8T7<%(z3-Epm9j z0a|4ne0X_l`}Q=w`}Aou>CnKT4TlvEyTlx4xwtMeJ=G@HLVeMR$<$Yjqh}@5K5oJ zQJ77hx4rGgnTfK36VL?^IU^r*kx7tgmSH_8e)A{tL4isMF{w}=kPosg9?U|7HK*(& z8UF9p;@^ZM;`h0){96Bac;KJ)e?cr0kb-xN>(iwqR`v#OzF_I2@{y=K)#Uso{Dr`< z3%#)tG0Y@p3y|s2W@@TKqVigu2e>Gvmbcqsf?z71QR+BghX+H(*CDSKB0YUS z>9PF%yQp&*++I)Z&9fCqf%$h8$lE`xKqvu0x@)gt1{C&4g@5ee7`!MURIqQX;uCKr z_gkAlgv8VPqS;QEK2FuoxU9-|jr8}OqcEv!#mxn+I8%{5-HGr?PEJlriqA29Jc% z2Ylt%pw-_}-@PyxxH3f!$N$1V?Ec1}5C<5%unkq`ku~~;k{{5-rrO%SDUrYAO zV2HN%4a17FGq?Xm3)~z=ka=5_XVyZKE`DdBAO6rnkqi2^3qi>{!eT~8iiz;fqnsqM zv}{1%Mz0tV&^CDeDf9}7iLJkRmsd8kkvsPv4MUydONX^-$(;im>kVik=iDoy7vEJ#I#Y}mA&BCT-(C7KjzxLpl8IFEmdcbbIoh3 z4}Cc{5r-f8)Kq}9qvCgu6KUgi4l(tdLIVQ>p?w;lk&LC0lk2o}%d&Q&ZLS@-m}<@>wH@jA zj~(AS>t_GWi=L3uE}}2h`o6^#){M+Qs7O~V_WYH3K6k^q3ms!2JKGD}P1qu0Iz%!u zW=6|sUr?o8Fifp)-Qv)NZF%BOCeA|^m94EJwI<_LRfB_Jjg5tQ#I$VQFBeTnEyo{h z86Rpg(fCrMW6SC}%9mc{EvDS8EdIrGn`3#fQWrJc%vW_Hg7Pl!M4B{-mX>lUW z^wvW@#*N4BURr+e3J>ZeLgdhwzXmtZ6VnWqGQP-=Bk{&MmsyUXs^1|#`U z4o9hdYeszYr_4Y3Fq@vBwPUZ zH@pf!pK}{5Wav}exs|hbWt?~x*VM&YO1)S6a~_i`ykh<%1qJVh$z5i9M}i_g%K3O@ zbN(f9DawL)x&9TmeaVS{bG&k@KIeE=&;}ZxwYIjtbV;ijm!nr@CS8ty5#M@mk5!^L zs^6a?BB;SHBi-1d*_v-8mrPq&TZJK+M;U%7@+sQN!7rnWU79o+x;!T!N8LlPlmLG# zp3j%f`1adsQs?r;)uvo}-zQIef?L_9BcnkML z3mKo1S5|udG3f-=fzot#0s#+v)+GtS;!{3@B_+qU1^BV_*ovZ~IHq%QM3FO$eq^_0 zkb4tqOo6(aeM0C)C~I}QXpQbG@~tpEza6&SFQ)2(%2!1((AKE;GKVpPvM)meEAPj; zBbz;nkdv$fi{zJvMRwJ`Sslgjd;y$Z(S-3B@94gE55em78EabU{a4U!-ktCjgyYcq z43#`Ws6n%v^opC;5ZT+RMGM5l@*E4@+~M>pS(>{yOggm_0#k;%F*wbx_-$x@Nz$uj zF_gzc0$xI8HjOqJgj$lK?V~F%qBt_!+6+XmXiRGRB$6&dIY@6m=;{s5i1Zx0u-(;> zuN~!}OqFM!NV%@NCThon;04IFyafwPMlGeStb@yEO_XdbcB@}PQ_ohoysZbiy5f1_ zP)m!{`DB<-_2LP#(M}oN+W>=wOqPAknnX5x!C;WqLst)gNdUsaJnZ#%pq&NA+d#{} z>0KY{>c*NT+4m8w+&;@RXKlF*x34)S#@HQ~eK#Sm!X+StS9!GTX>HF{g6$E<0=vSP z^c{aMf+s+&5A2jn!eR}5VCuJ0>`7at?vk=|-F)TGg0{fRCMoJ0{Dh>~d%a#$LKsxr zN4Xt0iFi!8d<Uva;B%f7zg<_nQ?rUxV%#Mio~QOhi9v;2u9RJJ-t4!93xc|J;qCNs8JV?}^+%+2oSC z%5VNdYmCtz9wt1qwnyl&Y&SLNQHgre$WrkK!>um$rb|KwWCMK;Czk{Us(CEz;79K5 z*o*#?y@atV=ALY$(6|6zWVUtl{p;7)Tm^9F)1iB_>9Wt8vmhoZC@27;eeIHkjF)RI z!VO(S+Ap`+etqcb(mq~pdVcVh2%fda*^h;oEx4qV{1sXCGZ#}|M9JE@pss7u!EB5%trop0~vw)Gww5Im2at^hUVK-f><6=dhR00iV zBi-PmcZMrNhqjS$$T6OY$;mB#$7o%7pm2yuH^(>Q_Yt_y-ngcjGayyY26pe!V1kmmURbwpFeBpP_OE!T0=rO6m|=px{d5Wkdx z96gvwA`wtJBV$~$1R%h|LMa!PiPwETNi5RM8Q8Ip`vptUpYqsQG{;rJRS0Re(f-`=|FaLpu5OsC*kbH)mw8o!Lh9Fu8F=~ zv$n}y;t<1nj}5ADy6?9p=tO5XuqHQ(RnPVIL5t(a9m&v2A0Hnx7O^$nFbjU1L;`j5 z>0N6VEl|#Oa3@r{vN)H2^tO%v%FF#Gxocbb6h)|{PJ#R^ivgoHK3vea)#XxibbWw{ zP*XE9m8 z0s)joWR{_S0q{e{wDUTh843Luh*c?qc`eACc1@D;O>ub5S{&)TwBv%*T3oQ?heLtIM4u2^eruAybIXouLJM0|waqM^v z?(fs5PcRCs?s8SPZPR6BYybxb@Q47Yueb@XhuR}F_6vZb8rra_;MK3PG-W})WGm5v zMkn?Y8NE%2ZALveR~FdXW{^+k4c6%ohYj}*E?&SGty%&J(+Nm0o}N-b+y(j`$97Qz z+xIYfGE-^G$QwMPB;-JBMdkMVe+x^ORA9;(Gu#Z`U6@-=e-OExyBLYJ^cz?UYpSu5 zzoJ*S3;e}+i>k*O_1lL9O9Cb5f^vU^dV00^p-^jjZz;XBg7#9le8J^+e0@!XL+HJw zmoLLRUu_KyCc`q32U?$vb(kRTV(RVInBAjz{a1D2>>tp(q#Gj9U6(F_2Z3ep<2IF? zI_Nd1+xRLi(%1@~7}nYevN_1^0gzX0!rA6`J<&e?z+d=|0}IOj(BIiYG6VS;8pKTy zQjtuy9SN(*$HOJjnIRY2TX!uX21h>}!6=^Wiq{}t=d2tbk~H6Qy<+U4Lh&ZZk;`V! z3ni5LU=5NUK1gB$T`qlS43ZccHqjEpCyr4t^Z_2Xw6d}SufFi=Wtk3pU3^1Zg;P{E zM8(cWJf~B;-@dq2hojG zNTO|bc5TYhQ}*%U*kS?4xZ`QfqRGn(QPFl+szs^$kdu(uHskp^zr|wfPm8PFu~Z-I zI_;9W_#S6wQ?OlqpDpk=-$?|OorDm~g@j)c_WZ5=6{V>v8n_d60XlTq?Y{cZt{ zGZTAI6n|ybLp_T__Rs=W#W_d15A5##c4`MscREflAfzAYLR7&dcs|>&XvpY0 zT{pU^OX(wV7)f?L;~g{!qu{Eru&}JWd1TM}J4ZId zi*z7oeQ`P!MtEk93ten#pXj)pWg*9Ch{+p2w9~?USSbFJYqSrskzJjpDogZ)Hftu_GiPXW+N0G&LVTe{*}12Q*r%bh@%Z!l z1czv+Yil~^4dU!7cZK}-yDAJCalc&3Pf5YGU6!)RJvZp@i5yNI05(<-oyMGl5q` zElaz_{xd6U$N!0y^;-2)0({T*4L&Cmuu%_*%qK8N>=J!Lfdv~0S%|-P9vPH%naoK^ z5#sVKFAS8F5EkC-qRZu9-fcuJKT!=gGuXfFb}F|5>UoIr@gR53+c5!abt+HcTnQOKa5 zsu#622Nc*anxV8*o-8E|s$bR9)isToL;?{!qNUV_Ay}7z z-H}34C@+e+J5uOLZt0Ari9{iV7iFgKN-KuKYf!S$D~&ga1TfT-tVrWXbI3BTWJRW| z?%kc{qw{g?$tZ@@&EZ?GDRByWwWOikiqRFweWM>7QY_LuWXr1>#*8PU**v!D&H0Z| z0`VKX!t?^W5c67$m{+j&(j^5kOGW>UdF>;=q?UZKcCkOD!f+}C&l)6F67xzk;y}#~ zmvcx;C^9c4lmtfvDIwzaNBA0>({RRs!{W^KX(^#|>R>S&O5@>5&%2F>dq_}8Iuz<8 zp#AmkBH3=e17)OmH*&L(kKjjp2*jhh{u?#-RuGwcCHJq2l3m?-m(|u7H|OYm(-qb_ z%bBWJ(p3(0eardtM+Np@~)wj;Q>ylQL+jsdOwZy>RZL7=9AM!!HckV%Mf-Y_SW%u421H57FBBp<%87UEo zp|tn~mvD9^L(lq|djWQSwX4GL`mHjmfV^LVPWJ}KJ?(kpi8X758@%~By&&1zF&CCk zkL?;IIltJe%i=sM+%P+P_E6zFlk~=#niB*W=otlH-`3U!O$JLAGF>j}%c@E#2pN{K zaw|})+A%&Y{GiGw)P$KW!s-5iEE~SKX<=6)9+KbgybdoNm52gUE9vpEu{WJIjV@`+ z5S!xqKnF9@R1lluZd6Q5 zNu0H*6f7Vky?d=>Hhr~= zW0Fwnqt_aSXRXe|t-Z6!D^k-hL9B}9oo08fEG$hCSz6KA)xx7bYkK}~azif8y|~33 zqQhDN62kYVV|t|8YdQeb7-@6*25M|dnBF-FVgB*S?Z}xK|J@jwrfJ-c)LYVY<2o=X z$AT(*M7(~t^vE`%ID*Cyx#(yHdLP^^+L3i|DX)rhlWOP0h`_}wspId~@gQ+74azA1 ztRNw9M2mmGsvo>2-5Z`Zae&2DH?`15HhlvS>u}w+@R~2oildKgI(>R0moMC?M)7K1 zWv7dhUmG7!Ct=6W2Zx=D=sotpgxTClD$V()_13Zy_qzp~CLwNpS8pNqRlq-4&tH6R z^c>ii>hf^O*9y$NyrGk2A?>SXFq$2e{|Y`tZB5j<-ew^5{QQ6n;+<$T5p)HVWKUn* z2g45HIeWEs*28GU=H?A-URPh7-uU-{)_QX0ej;Zta@{WU6dE3_ZM2cx`=nRm&~s7g z`h6RRhmg`zyw&l^SXZMriDU;8LnOF@r?KTwW@5Px2|jq%nJI<=QjS z94OW8;WF2hJG1i{GtLnoA@w2HSKUF1S-J77?-2Z`$Do7Rpp(%4sKhg{nYEgvr-=Z) zfst}v!XtflnF7MU)jv<>noNP2lz z{Dq8y=KFh*y}cvBb#e+$Ds)*^c}@`m7X~m&it|w=4(05^>4kj#=yd{ZsLN(}Z~S?u zX>%MQxJw^Yx{XX}+(uSf1U&d6$PL|VN$G>~7Se`0s;4g!$S-Z8HZw&jhIFU&rvZEb}r5Olf*F4UK>lx19|&5k^uXJXdhWfH!r z&-sUspNEhIH@gimo3_?urz$6VM`lKl5*TGdaY9GtC*?@~w>P>dkwOOx$Yiv@>l?0L za%7yIyHS~B9PHOG7tSsjbc3Qx$#`|8%N2TcT=M3>ExD{WXviKOUSv@NdP$%u1!#JD z(2m08(-Yh;B?a$B&d`(#7s6ywL&L}dCbv)a#r0PsEg<3jydk*jQO6Ovksczmc<@g_ z!g0RgQ*9~v13!R-*7D#6LkA@jma3h+@oWfH)LLD71aW_5VdFdL`Go8@08OI+)mmMB zdhK;`x#|frcI$Rq^#s>fK0Pku5qsAk?r}a5+X)A1+&!COpe%7_7ibt^7Tf3#=-|gc zLI=ax2Pcj9gmY#`3ib9~eUph~g6QdGSR47a^7-`^L*p{2x6)L)oc)XG+YM;Hra$#J_HM>bL7keol zdN3CHJ{U7*oLTELO#*hsvI2I@%|Q!&DoP(mUj8y4O!VUJ|B4{jRYg?fLjivQ5# z^&!c_S_u5c0&^rUi_B$ZXV+E3$ z@I}^r08~TKVIHbsyZLT;_uJxPk&p`d*bZQaB)EnL2GX6PRKkWnIDbw@R_Na8A9fj{ zRvGzFES_Dt=Vw5?)23nBHoyFo|Fp5&gWL&}lkYsh#$=ZEwQQzyUQUx}oX?EQ2<%C5 zT`?DrSFo*)N@~BZF;RJ=rL=`#Cb$c!rPc3&e?NN8bn?q0$lxtyfFkp_r4_rhpuoVo zvi@?!Z1*<29(>pC@*hPl`CeMo`f{sE=$Z)4z&sHHGa$?}uzWdm92nS0a`$D#z^)E1 z1p}jO?<-t1Dah>6^sY~~_lR5h4jJ)X82Rg#G#Ytm&!p4>kGiOU+jm3cdhk$TSw+nG_hicu z?3B&zSzJx=fWF6?)zd*dCF)Cwt_;q&rI6;oInZ@Quh9<4D?E|EsGh!<11hZI`4v_b zv+W;}T58uWREV9ww1^S|M7y!B6L{>7bWVjL0rBLx^kop2#K9*6nRzv z4+w1FR)Pt7IE^K-P*J}7O)e8EK`w5+4LClxwp#T$hAtHOnY7P;Ut(GBPh|7@Sq|7I zvo92y+UwZte@h%Eo&n-G%p6&$aFoY2O9(hJ}2WAn%!qz#2Fl-exqyJg{ck>mJ|A{POsZtx9F(z<8 z0|VhB3XU8WlNrFH@{rHWO9V-m0abJAGo^*f(% z?C3TTm9XA1&ZU6T2&SBA5XXy)<>|A`qif!Tf#gGINp3{>+ zZ#N+Z4<`Gn<-*HLuela8X7HIrWB@LPL@Hd*cl9u11`eMG#AA>1@*JI5J=SVKA%(NE zAzR8k$)#uv`lL2FK2XM9(}qLT?q^m8AOkl{6TSr`0gr|_JRY?LA< zm>Vu~_RbB$@LN`B=H3Stk@Vd5->EQAX60rMvuNO0-YgpE8jAi? zez2y16N=1Ib2**m@|?~>HxP76oH_HNUj}b0N{|7u@iI0xU=QHAh?_^8ot@z| z8K`+RH5<%_4L<;93cea)NJY7Z@+CCJ$T!}U%_uMA%Mg%a=R5>Z6DmzW0P~g6nInAY z?vaUZ{R#jnp32fl;kSfI22@y_+TFWo`STsH7y>a`*%yJ$X+9#m!jN*{=$s%ZOi;%A zmb>DLuK4Q+gMhydsqa}1Ap8dr4kZ~#RFsGM**bB+C>FNO!zjYGcl`kd2r?(5J=ZDu z=FfA9%f;oZ#!O(LZBRf0vrx&RvkX(c3AYu;hueYU0#N-KsOQ#laKN~5!3)ym1Hn#b z_Ub4o2-I_;w04LszX<@KgH)nDg@>JfJpVpCr8*~G|7mzCJ@iN6>GoKx%8HQPMEh5^ z#l+=y1sz(=9=Fqhzk1s;524W9oMHk9g+V9{p-2d9NCdCWzSUvP8B8ZC^}4;_3bFCF z$0z~*2hz+lV3NdK^2(*G$Ivu9-u`9(7Sga=tHqMz2KQ$@$p&EV{+QhI z5J}AP0zF2_d_6|MjX!}iT&x^R$!`#Hi+JZ@V3nMX^K~r6aTv5-EXy)1q^h02US(T% z{OvtI)0x)xwqM(;JrwZKdS3;;kZhH6KXRpj|M> z3luEJbNjFMk*-GpDMKWC5ApJR^fzw`uK?GE?Elw=d4cxq}er z;%RZtFnvsL@$k*ftf+>XM)}@7=BuM%2(pnQNbV`k)WXaieg?7am>Jl&&REKylR73X zwn2rhG+3S-pze`Xc(^~~qH-<08qhLEq=dzRG7(L>CvjOm$CA1{*9ue>qzGe z{^86gy7DHQAtI5QazN-X+aI$^VOtv4Omj(mXh-zY5e1NQjODt~?33LJBZTVMCwB0! zkW5QK8Q@dlDK)ZyeeDObZ^BTf)W$1K~hE+P$}AM-9m?I@;}(!z2Lt9m-ocZ5rf zbx0n@Ow}-l@RyS%i)UP~M1=I{(GHej&kU46fQ39mQ`kK+<6pFc?YO5dBm?h5uDu?O zU8-F+B~W@O*(}iNLyhZjTl&#+K*h(~bAUC_czT*5vqbMn+7ac*1CteK? z6=1R0?Ckv|$oZgA>XM>$I{;cN5>JFR}Vys`f zE4Bi_FH%MXy2;>XR-~fX4#*0u1ZJ24_s%_Va=|IBZ zb^{4Rmw1=wD8;`hyav?tH0I_#*N_FYHG448#f&LK**xO5>H)tFvF0W59y1{}6&|Pp z-OC)$#=Gi|F_m}G?CywOlV>KPX88#iBS%|rCJnRZVQ~?%V72*8?u8mrDP_*#o|?z) zm_3@cMFJ~M?`MxP?hnWr-61FDRM2ihZ9N~`Zb#?VfDU|&TS)0HXYU&5hRog7JacjN z1o!*WQ;D_0hFj=#B1h*DhNfLhSlnGU3rYW0;#l;cJo~1_o3jG_7c{N@O*Xp^Br%ip z#8n-rrs8chOeLoDzHR*G&hqpUJ8ky<+W1@Vf=w`)s1DnDqpbn=mE(nD%orwMl0C>> zh5ZcrZ&Dg?86>vziR~8k{o|YII#eAYa_@&gEVVc?Q?Eb3>b~#`IChv2(TmZDqaF`e zdLt%4JidZ}a0;73Are%A}@8^K#0D%Ai#>T%*rD}6Pt3@R)!(EiBo|t&*?SD)VL+I-Rsr5WN z)$Yp4m=1$s(+T`9DVrHi>!&{6>B0bSlxp<6gI5qs7VxD%sqku_zJRBa11zU&j-Hwj zUpA8v^0$ww z#d39&qOCX>D}NavIO`{W98d#;v4UI#!c5Z7fj{)e#Xo2YA(r#Ob zJxFdV2ykZlfZ_^LFbitHbFXpl7*bW(QVT@wh-Gm2t z5@UvB0}Zn3#)J0LH5Vz^Xfj<7mnqrHZGO#%n8mDePQxVzs(+5Rs}hFB>~BKJ&1<}6 zX}Wmp15;NcBgpL->k;!5H@@+)m$(|!Q;3mH(#g03fXDbHIp4|x;l9G+6z}-O9u7zG zf}2)8sJJNRS5;YAy7K`DXx1Yy9<5z_x0HBE@pB}$8X{^#q~#GZmdHm>Cq@prw^O`@ z3NZ487G;n44fl$K-0m9Ls`glK8oS01t;K5;9_A24PmYVs?7&%}T1BuaQV}aP*-;A^6?zARMIogr*&5XZ*RX|D3-_XsTK6)xw^U< z8S#WD^9O<~i27ioDa1WVMSd)oLyqV(4bUz?@-dcjP9&r2FnS9`1-a&b)Y zv8!(#S_^MvcV%W}{dT#a5SYAkGyj(bD2hF;X_K>@o{&MIJ=E578k8zwfcwIXjnW(E zB$VaBLei7zSwfPNlwpbS!j|9j9v!_XZTsbpu1fUa10F$co%m9s0u!7#6qpmte;wZgTj5gcfXRk4tIT7X5HD96ve6#YNw8lh(#bWO9-ysq~2JxHA{ zZozLuB+h*3L{L5Lv5+?3E!${_LM0m3OKfv83JT~`?kQ+&)DBtb&~xvC9f%9o-yxAm zFe3`nr_$6b6TpgG(z;5rBDbt@(_ru7vQVOtJp9SH1sb_%Hn#%Zp{yqmS;jbK^}UAhd^Ghpj;jRCU? z^Qk;1F={DRdQ94t`kp#IX*>BsdYa-zom4a#WOt8v@W5ZL^jwm{t*n#R#`HW*9!D^q zZcXpm6Y|L@IenW-xG1Pzj>^e_vau5(cnxV9RO&<}3FFZF?wDiC)ZXH!?cVgjX<0?B zd{&Kh9-H!1WC)R|~@dct7sKcihaUiQ!0m2S$z zqTCoxsX1lXOv?)IMmV17!+liTxb%dVIOau2bG7hR0~m4=Q2OZP_DR_&&?!YY2~E`& zSXfMNnKQm5&j3K;?U3p*x z*K?#|zY^WenuyY>)NHcAO}ztQztdlOOlrF=hbFkU+4=d2$E5~NR;xtxQkvVRyW7b_ zLX?C!ck+0|L^o!vz;LQ{czOgo)h2`;<&A`gxq+95X?LZh`ns=!fvYB0GC<47tii-Az}!gPbhARdzvB_&X&Tq36`r6+p#M@;of3khPs z$YG~+Rotf{-SC~#1f@RDNMo0T+YetYo>W80NIrXfAY3$wYJWtC(G8v&1#VG7A`E$P zlYUj}*+yd(gA2#&$=LDH99~L>oO$)?X$m4)2K|azYxm8MgUREQlmQbRr#)HW*h?^u zbO)4v^kss?RoE}to@{dF_#4lg>*xz)vq?r-fGiG_EoIMI3_P;%xn`g>i=P6`shw``v|y1J>8uA_~S<5XYi+|L6Tdq>dcy4N^AgBKD&xDU(g=`Ih3 zQ8PxHIk~xm<<%e8`_z(3IOfuX%f(FKbO21jz}8o8f)tb*+}B}+hc126$UNzky+)s7`MJ)H=1#HGpIo*3d=6Y6JQTxnx%JGB!>A+r+F zT=7Rz+|WP+@YHzfvD@mGIBaTo<4LAYo%E`(LbgP>bsBDME3o8OhqKG~@C8IG-4xyp z-6c1V974<$yjrqB0e?WeQj+kCCTfhh`3ga$Qu^YpeUNU1^Iq?uV!ID|Iu}bm=-qm| zi5;%=H_?w1{e1T+7P@Vo&@6PDkaiy&#Y}m{QJc=Cxt`QhrmFwNEk2E*zN*EJxq3OO z-gDzaJvm3pQ64H$dcr?imqAE)ImJ4sB0vQxDM@ z8^L*|JRws*DdP>yxn_drxw+t}!6QIQ1{s$Q;kQzm`Yj1Z9%jd2b-oU?i%xR8PmW?n z3ALE+WxABIY@&mSeplg6|8hg>E354M4eQgn)Yo3!wiu<7igRgTWxrf#%;Ich^txXL z#CBsd{U!&K4(e)N)gYNgwXt}Nl}m;8xt;i$B3;p+u5?{^YuRh9ckWe2!kWo?Az@)* z&|DcBs;i}S_pka1EXT9Q?Jtd%(9cLt6xw&N?U>NyN3_o3Uq{IzF?G`~-KEoV?RTcz z3tRmSxhk{6SoQJ#v7Z~PvZrdf9Y1gK zKHGzl)ex1mEu&4RB5NZm@o>+P^IO!ysxE1aX$wukq&(i*7$tvU^`?|*z>b20f-+DR zmARyKYw15*+4dpIV(oRNaK(`kgvK6+YNG2ik>6Imm@G39@0yDU*8f7F_(XHe7k13< zi3Cq9DLkF}B3qYoRZb;zZ?CSvNW;{=c1zLa95L4!i>?l;MYiNEc?&vF3yCMG~1W3Uw7iDPDEWNu* z)}F|zqWndBP?zomea^TOH=Xa#mO=3s0r{A695hXgovem{5`Pey#z>>1y?dk8d$%>M zUw|4Hi4)jhXSU;BgmG?wyvpN33dKE13cLf_+FJFoTnG=?Fl4O-)A`Vb0nsu&p(>;P zHT@TR?ER<;)o+u-?$SWX-*vQ|)>l*!pw#hJ^C@MRO1ywH^UTJ^6R$JKx zr{flML3P_YPX!2@Tq?9=Ekzn*33g_yyImTVsRDu;~e0?suBDt}Y{5({j35HN4QM zu~N+MSg&!k`kwW5&F&~IFQbWf=!(s1VFtt6+X{??x37#+x(b{b+<9U7vQyhv_6RiN zwh{&CKd=54(st(Vb@CT2)2Z&Qm&o|CHG+&wi_#O7Bid?m+iYJz0~#po=qPQ9`&a@@ z@`q`H{dG}L8SIM&<}D~%RygFnV^oWdAXAap8D-sl!qI(G+g64vIW@Ti{iXW&1q^9M zO8VD)bi+bobI-eX{_1XPwu;RDw!44gu(9vdyyMQT%+_;1hc}r>`Rd=Iv$;{*ZWZb? zS3*dfQ!=|Cqd>+?E41dxt830N>s+sw8og1u3zcZnqqk3Zb3kZN1eBH)mz+yYLYR{J z(;YsVK!INIw9e#&a4{V?IBk(M(*bt-(BTmweTP)<3v$W(22Bf{hP7jM8zr-=i?KoW zp#cI$j|4=N9VIy3YEm_T{Z#3ID!P;C9?`bEfpzc9Gfw{NM`31PS6A1OgMz_%w%uiy zE^9mtG~il|st@XRcU^ayV?V zFM4Ho#ib?}!KYHqLQ{zWaeF=2oL8eS@c9*}Cn9m0vR?jri6@hpP1|cuhcxR#x~H=p zdZ{UoEn!u34YI>cD5LJ-_z8VUSrdx|dR><`nH_2_uQuaC_4_H?h;{x&kQ{J*Vi%M4 zxN?d^XX7}%IP2g730z8|K6?NNj}lP&{>{K_tDoTFEL(dgnozt25lk>3f{FeW@aK~o z1-Wpun$4;YnO7_1d3YYpDBbxNW0CXuD$_UHlXrdWzA&a;V)SHX%wF|=&H*XK(H2hRHc z9%`g-=j_)mh1h{ZKH+up_sHG+Fa5#c&;AQ2gC1yWy4M(;aW`Ro4{Sul21NN~Q^K5+ zhA4Sy4O{e!KKqrT^6xXuZhJn$KMib{zlF3WQ|v9aSR}18^Z#X+&ipOBiRg)8NJnWo z?)Pe98~l72yDKZAwbj<-ZFba2@9slwZ*Ydav}u7dHK-6OCpLC#Tiz`6|aY z|CU>wcNJ-gmvxk#yn%a!kj${uxjol8+zk*VJohofKoxdKQ)uJ2=C2TrS}HQ-7TeYw zt=~&SX_?Nq&4;;IhT3_8+aN~#t|5D#4-(Y`yvczN=31dGg=CuT^fQ6QQirbovXVG& z7=1x6isyd`K&oyhKG2g`7@YK2Q+MaEacn#rHV9kj?gKR`jG>|20 zy`b64q(fy8h7o9kr}E)u+DP3kB_4&A%kH0a_`4nC;L0Qd+kDXHeXHYoT#D;D}4#{JtT1{yzR0A~iqT`SV(EZfW@y zFk^uad-&-u(EIs!325W8K~$BJLPkj>PoKYq|1SzNj72dHh>E!VQ#ElLB6bSewin(FXm_AAVC@`VIpLK7qk#x|Bw0(LeRWBbr>|G1OZ^rP?$9*H8W@KXs}#+yq#WsmAt} zFLAn<&vEC?bC#@TkFpx-&?yNFAY(?83@KPA_X%BTQ)&`-7Bw9&Kh@(i02 zB({HOoG@1j69}0x9evWQU=*)p#zLY0VE_RbA|0l9*+7k-C{$;REE)8z`f7dxJRQZfouS} zA()lfbj>e6LP9zo6ctKGtCzd=%ZmcR(PfMo&(G~|K+ZF>5>iph)R0JF%s~-{esrm% zKdk|LqCvWEddMZXG6#jKuc8hIdSt~cOs)!DjzVcsDMKRoF~cuCVzajd>SIzMI1xggl0c~hR^@%yZ>bHlHEe6?04QW)VJ8li2BBpTP z7n91#Ee~U~cN1wwGoL@Tq+7Y+^Jw3P*Ec&pV5z4)Jl{x`TTMS9J{=bdzP59x`SW}m z_fzK;wR?h723GM8ip0NLfU-uk9JBv0pu0Z>HQDem#qN9~+Spf;q{XvhH@B)PFgAfM^U0D@N-kzZL1JV;kzK5Hn$Z{@1t{+tdDOM~@D*MLWpwYgPHAk>3_wK-< zWbe3Pj8e%c2WCRni!8v6-)PC8VW8w=2-tgf6PaACCY>I2UqmZ>WEGwcghqx zz0;K!&LmQ*7JDGb zs^xjj&I9Z%PVH`ajs!DHODV^}4w@DebJ4A2Zw;JF^!;iue?VEj-mo?%I3eL5%pcVm}HT#+6Q9cgc z*sQt#d+m*S7q{D}pSFeI0f+v3JtRWA8@w@zV}{o%?8+_P^0M!(n3;5%%cf;4KCo|p z-Y6U(bEaK%aDagqCLL$j2iSS!VAvwELYA-MBaQN{DAd!OL`b}cwtvDjH z@$|k2!#Q!F&?hy^ZC-9y>oWA$!m9~ieh3~0afv6x+swL$#pGye$e8A5&h2N)syjiHvZ6K%@ES+N1zYw+T2cI}cQSQpyAWK`}{3mTXm0-|L zX7$cNvO=>ou|g#G*_x;%*H}WSIrJYG#AO_c)6X4fNHNTFv~V?}a1#oww@aBx7dk(m zo3vwgp9&sp*xqjLzwMn+c=loI@o=uMo_=tPFx*Tr_kK)%50kXjs)c4 ztQZ+BdE`g z!D?Vlkl@Wwj)URYnt7BA5r^?euhZrOorV*ih|SppX~fHuq0935(X?5k&^{FyH{v(= zRr(Uib*H!mb`flx9qRKuSBJ3fM>&_nfFQaasU-jeMwyv5okxkH^`G3H=6-L_xlx{? zIdz*`GtC=d4yL=~_GxTky?Tuedv?VnqkcPeBsgiRq_$nU?!yyIyeZNvi1au`lx@%z zYRB;L*^P~iq$xFN42!mVJZ4&2r1)cUPUD3Me}ChJKl!@?DfellyL@8j!-|G;o4_5< zv;>dlMp=l)G9vE8xqs@~0Zj3g?2L4Kj{X~t>R94{dZr96p_zG;@Syx&w89e+G zLQM)!I;?4ufl5lxR_YW>7#L+k8T{yU5zzCYCAi#KrCV4jCun(W4SYFiPn@J|(NG_9 z{@8@PUk<}|LvDs(Gt(V-#FJSvDmvR7``^o1abiW;#krqLx7Egw1I8_s-k$B@Uc6`c z;)NP7T}v)G+8nBqK&O$EDZ^HwOdfdL%ebwcF+;hBObzp7+k?XWnCK$XEcfigem@8x zIm#o^J?qj__0+JFd05@n0SKJ%veu|`v?Q`I;GBS+i@~dfvayVo#EWx{XQ{;*phtCa zR_*RzMlbA886~-o)_-Y;xHMHdxsSx0y9YC+Xz2Q7gP}C~Yw9+$U0fK)fuO7H=qqe{ z=r4=}c3EXF+mqk4RV1sTS%XDqn_YObgFlN$uH5%2^*1J6f2m?fD;r2%ej$Ds@KpB? z5O*fy;RIp$nU}94c0|5KB3U+DbchooZCOlv*`wN0t-(n{%80e__VIRf-Mc-Culcx zzi>gGwYuqYeV;xaje27BW8kBu`RDZi7XQ&xeXpAePFJvPa$f_x7!nfV!ez0Y`g}k4 zr7`#&ES)wxsJ%&@&iW=c#Wuoy83jXOl}0|pt;7j66&MQZ#8Esu?l&Q~G&_Htg!TE; zmX?;ZL1)b-mrze!=KmVx8O0AD;eD51jzK5bYDg-xR)bx@FZ$41hb3F#N^N#hpBqZJ zIX47(iRtRZf1O&OtK0oCHzQnZY>Gq}E}%HWGX?a?sNxt%&W5qv;UOV4-pIqWpuH6k zD`k@5{IMcF%xs#FaNwR2Y zO}AM1Wh#^JsI5apXTEajp;E1jz8}rqh6@6-e7*9-b#)l=BXwqq53|Rcsh?QET$0PH zScarWM#r~e(X*a}tHLSrmKz}{0$#g-O6AQP*^tr{{k(1IxqC|oIHASv$E|}mp!Dx# z_TRWW_k>};kTixe6@A!i2r6ioThJdx&d$6f8Bc*hN;H9eQ)R~5I2aSzkc`Z|78Ha@ z1jkiWsEOx3dkY!v@ilHNmJCoHcI}`T?aX>d8fhqS?*y;sm>*Ysd$F(o>n2JPJ`#hE zWgk=7aR;8Kqs@~nhw1Ny-IY;O7hrC}nKK7r%t}J@PwpM)qxcDqcjw+E9M}pof5jp1 zetTy_Wqtac0_4ez$b5LKkl?Pdn||JOqfk>*YkE?9_-UEw&~X0fr^?pupq0E*&I8YR zLhO3jbl*LthBRiw8L6clRJqN1Pz23f&6P*4yD$aVuVB3nihtyQZC zs0gTxpa`f4R8|Nhsa5vgLLd=B5{4u~5<>Rx`378V@Aq@h`FZ%~p2IEg*Lpr5kH>RO z_My-U(#s1@cOo*Z;i?|xyn{vT!sPfU;K7H&Q)yJTIj%wf(A_2$IyR-ZBLTAZS82Z(M3vR=tT9Q(Snqq#zV=tngJ>w~JgE4>A%2vd>eBbvh& z_jIy=N;VqvZg%;)yaXKn%S)-kH+%^r0doD2@lGX#AO-?TVaveDKwl83{DMAFF5-2? zg1t{3F>qoxG*5f)> zQzp$@n!;wWpqd_LMMhBG(Z^Xy3hKr8SLVN}e$2{23)+SVGCpfm8P2Ezjbnj9JX5>h zu*|b|C-#yyi8nD{$5{6EvN<6{+*2L1wlk7b67W>?N9On~ldIMd%{j*6tPUY9hK+?M zG&J2mp)?V$;ycBKGE2_htwu&AkO-5Xzb3DEKexjx2Sx?C{4H2`VwpZS9Q?`WWtPt# zuy5}jXnMF)4dtU})Ic16b1E7Oa|50pd3IwANvjP^_%Q6r*;30_G&g_r+a_=~er5%; zWKC+9s2akT7o_miClK6+ye0Tx&dmi2N@Z(T4sB8dtIG`*s!U_ z{gA{L1%;T8xDQcZ`K`eC_smOePEzj4$poAx{z_zd%YkY+4qsSOX#7~kkE1;Ixi7q` zq?_g6Mr)1u2XY4XDec}C;~{0Zx!{M_Ln39O@62?>b66(y2v?w8xTZgBML8 z0FE|nL>`v#i-*NJIJ!3lA6z4+3nzRUtic(c`45ld@1itjk*QK z^C9E5@`ZHf36#{KZlh%bn&|5=Pnq$ruV(v4s3Cdn?1EdFTcKaIw%gJE{8=!xSPy27 zeLV;>ieUOhk*KILEL2_5qJm&TFhuQKyr>p|+%Z-Ocr7oDNq(#RxS4!S=6Ht5RZ!3V ztY@qfjU*Ta*IdkvT)yND5f3;K91uMbshtCQaMYOv(`)lo5TgS7(|)O=3yScTd`TRU z=BmXjznl-q*iQokRd^4R@5`vzd2L}58c#kQ=DcL$E53IH3V}+!Fj&gjO3T;J@hr&O zD}?(Ed&A$h2fIKggtWEloI+wu?3C{_3?3h-eswK+6xWbk>rH)nSan$N5RH>;%A5uE zmIK5}$4eehttA9`hwR;Xg85NuYj^colCt(OProkK zoz!*`h}xbWen9t4yrX5-IV`vpL1iQTYVs32)>`@GxKhZV96&dIyMP|a=*=82 zMcg8wmX=*v{Lm?gHSjDMCM~#aT@GJvj0~9l@DH#FQha*;`TUcA88)$@9xZ*pGq2n$ z56%GIbPo>B0O~EzB2|r_y8^$kgs%e9DrK?el=cZ8!Bd@le${zSVowM-aI#3$m}DIA zo;3>BhZ9FybGdmC{KF%X%bJj&(*wZp&S@Dgk8n1|I&dsqG8;EdQ##T%Fp+))_)g3h z@(>bnA~Xh9F1+@ak?Edyp!Qv)r)f`@;#AVAN_g|a5B_gzj(1_lUc3r^T8tF*Tu=b#mt(?$>YZIK^0tBbf1L9 zMhgL8trJQv6N{4hfTQkivQt&GqoqM3VO*drcPQ`Mb8w1U*SOovK6vdEaM%yx6^1i? zcC&J%vDW2X=M}7$Jy8YPGS35YT;lV&RH6jz{ykaP_2?!XuZF_)O zBLYC)KtN-BoRHzw2Z^RQN!CmE0QMZA=hnpi zS9P3j8FfrxFJ)_TsYR9Vt1Bi-e;2tLD*B)oT(1OKbW*&FUg|F|FO+gy*7mx{Ps;++ zkb(fjoGu)6Agw zh&3Q>%9ypu2jBBbMf=^BaPT?q%eX^bqCaF>-WsNOc>+O^xDjKbD7{ZR7rvZ_s5xF8 zla-Ayx15x+ zGG`+3?soDOr`VXo7lXEEy{`7Y50h{b7`XAKm#K}$-r26C7L~zJL>Yls<}x{K$Bf!o zeXLIEctUca$S9$DZ}Ps3dVcyC^6UosUcIUwsCt`X5`TgM4{~%%IN-=l%PH{578Nfb zuN)jrySN^in)ZcJ`xuewYFoE~LVfu6dR4|V*uE0R0rxt6qF$bVCr&?=pkLKzr2<+ z(^yx6%JW$>>tE;dfZHJP0R-blG@@=R56r+5ifv9_)YPCm;J5ItL=s}soQ;}_?+wLj zvB468-4%d^JM+Q2EG5O3-~9G;V&A1pyD(gUPrw=5_eV5RyIOuEeNHz_kl{*y5t;vs z$z4(F=-@ChN_8tt#xP%0s^?*Hl!>=8H;m6zRtIf@n=lF^CXTKU66AyCIylA%E3~=l z?b~3yknHu-scaQJ5Lw=E*jAm3VM&6zpEQ$`fF^1_#n7fR|Jog-rnS9}<9nn{s@GRq}PICkXm zC3zC3@BTdyk^D#s$hP>*XT1nMH;DfnkH&-1=|D-KGTIUi1s?4X6HQ_K}M;fP>|}fN|Gs zm*o-2;0o&mf3~Ltdxs3d5r0L%g;x5WW}GUSk_>wN`hSfj0?UFs2{x07tDc(u3#R2+ z-rv5ZZe~nokio`*b4UIE-XWyqKH}82*ds!jXQ!oMm+}|7= z#9^3T|2dE``%Qe#;ALWN_eC+})q{&*&)a#kGHP7!bmOianzs10*}* zvnbLRb(YhPA11qPkBU_nQU^fCX*Idph#NcmkV=`1%z?v5yB_xtqs~5ZD%C5l{`5IP zD6~}o7&6VK!QB7#CQcFO=WTsI1aJMvhDO~!aXWXgi1ADkz-9G!^9*SKNNvTm)GrF;;29e zfE;Y+VKPNf`Z{F{I(E+t-8KG8o)t37_OH_8OuM#^$O0f3Q40!hC_rMhRdk`6_ z(U=Jd9hLpvhkdAWd*yX*aV&lG;D2pRGPRVTw6FLbs~>KND*5QQ2ZptQMjz|sul}}Y zEfDnVIl+~Q4?pmdS-)EuOm{H@u>W5sCZSpt9u z>(H};uW6a37S=7VsgQnZYvEKq)ea*naL4~+p1HH7;#xSV3~Iz~Fs!D-H4y&;?pZ{@ zExba)o!WXnP#)m*%N3?i9Q}>x{!)PLOXDo!_XZW7jyl8&y|nyey3HT@|KqEWM+*@u zmA|6WBHCy=B7^jknw~Ki+!9UrJ*OrK@>@h`e7Az6;oMd+Ob;m@osajkiNlYb%%H8e zM_Tn5C z{l@w058HlG&EUwz!eUjeK!d8Jx_>Nq4$_nnMwt^60Nf$MI=$;40pFW;h&_AI7yc~P z2{u)`*Au>`6vA70NOr+$Xqqlat84Ua_BLh1TrxPQf~g_0Fm#hF4Lx`^3m@{s`XCe&&2UtmE}a7A8}Hu>!0Apf;)ZnEf`V*LocKezc~p(0SDRO&P~|@$c3Z{{305$&3DD{GXfnyA+Kz3oj&JU<6ww z@=k63jW<5Jd+JB9fxWP4+4^L^{+u#tpEV9bj#&!n2!4xVR73vWTv-oe zl*As`;{!i)suYz}^XRft5nhUyl^X>s42ANu;!lZ#JN268x)1d~SVZD)Yt%Qh3})Qi zivuDC>XfeYb_0W|Jx@p6OMdntCC(lE58G1U5a)3*?hf1J*7V0XT92#HXsNSRSO18j z^94EzhJver+XUFYS?sA`ZBEElT3PSE3gx#N<)^mag(`1$Q;3A7Xo|p2!F3gtX~)T@ zTOc9#>DAUj_!!QEMIp+(Yf4Rx#x1ipIp5U%R@ByZq@%Vcwzt>Xze!)>$U~ z{l8$V=en==ryZVN>_E_X;#~Kezuoh4IVYA)vK0hH|F}@`zEM7&BOkS%C&iwa{zYfD z9mW5>Fd54=nx|;Mgno~?IR3u(yAM}-)|^h^+`&AzM%xXs@49VXz37a~70mS;IVyju zqk|K7VeGPf&WtD}Md|XxPn=lgd71;{fAaW*t|MmhHCxXt+Q9W;XYSECe3D&Zu>rR$ zbk5AdC2h`_t-3Ql;jD|S;Uz^9)<`Dii(Y7+s}`-OitK@(tI7EH&9X*0k1LBnqgxv7 z$0RPLl6LyPKiY=P2QL@R2`F$F?e9KRNHg;>sm9J59QF*hGKgBR1#M_pqk4Y?BrX<< z)zR4ryxK_hnp0>3ccn?n?9jXAfntgW{Qm5^MSjSEtR`;VuGF+F``#&+j*{657LzNV zL?u&XFU^G}r?Tq8t)}mrl8IvMGGV`5IXGELz%4_cTZ^@v?l=rP_QwxOk7gGidb)t+ za0L0Fa_NaV{8p{lOvgF2Y{3Rs7ng=mLSy3n2M-Jl49?R4$acJvzNa;%3>p5^yuF47j4fa$R$*LXbQ!9eS7q6WXw8>l z&!#@$3i-gC{DxB*?4+r`AK4R{K$&bXg^###&sqMn9&T3AP zQ9YJ|jUST{ImT78x=5XmH)r#*Ip;1mIBQwlrvAWlzu3Th+S~~GORvmWSJ(fJ@6Ddj zJ9OD3jyc>>-iiGE1HK_-?41070NV8O;m_Zr95G6PYtr|Wx&5aHew4{}g^*Gtm8I23 zpTaF1k^JH`y-y-#JpV1%L_(8OWLI#kbaW77roSY7&4NGPs;0Dh?sicc*!H`z_eCrJ zoU8w7Or0(6F7UkEbXJaF!r9eNsO?ozgA&vvLG1S8vvTniUw5Ap>eODyYA z^~E}Po(}SgwkA9XOlokO{*~MHo>a6Lt}t7pWXRe@=hF?HHOKp6+^L*Z@I(eWsK%YM zHuXm8_DCV(>T?m;wDw`bk3>@@Jd>iL%?i|7)s(b>5apQ{+z}(aLKM1RthkuQvv74! z_aI}rsRV@#dh=4m#ICvpE9>26j7eAcIKGJYXN`HNW}WQ4V0x|sauBj@U`4i1s7}9+ zI*n~+Xx?7f<1G#6c}YntQD&A8N;cl2{@|~gV(#P=tJ5`W)0u{_8#BjmmE1Zja<-*r zEbE?o?$F`aY}Phc3F?|Afz71|X8~!U4>rZU4bCP6&jpFxlXF^6pnX-z{0JE!i+ zEE6N61eW%EIJGH*8!_e}KM*l@&_Bm3(3ke%1)%(lPFT&+n_H(_bGWv*@c~9L(qL^W zX{6XC5*~(=OU5o|sE2JFx0AnpnwDvoR~fp6JpGcvqo=AFDFz%RV?4WllfzPdWW%QZ ziBEqQd@bFo z+4UDl6FPz~s{diUN^|PwXvM(h?XYk=QudPDXa4U4q{e!0uys3pap@K;A-7jjkKpaeIShw_;alPWutTX2s-7SN!mGw2u7W+bG^2T|$cW+~!%%Pmf#;+;qd~hUnGY z!3?_%cEq`*&LiGrGMO{i{oy=A{nwui3i%I%Go-5X|+_rq!LNg68g<>d2aCX}HW4tNT=c1`%_-wU!^V@JYH};-h zXx~|%fGXghJ8!D59~)>!*sg12q!yAXu8McyyZp;s^f4s63-n52}2n)7~_mSPoU zLbAMEM?RSv9fZPd=1r<_=p`BNvoPU|>tio!DZI3DG;ZJ5*^ApZI+uxC&{7i) zNl9FuBjpS`VoZwguG>wTkmtGWu2dqy3y{|tYR6aZAH*%iE&T`=`R!mQ(^5V6{_JDY z*gAJmPk3%wsHurbl3=~CzG6?u;QC6A^|V{#R0{P=istaE#?M^X6b&YBoZUNpC%~g@ z558FO#|6XdYAO2l(3sU#HXcurTDy@;f`mC14UTk)s8RzvAnj1gK`YYeI1s{?Cd*Tm zg%dXf6PrcV)=L$WYmdsS({i4@f$yGzZab?L4QP9l3-A5u|1u0sDaSm->3l@pW{pbu zvmFeJudexMVq3XVFz)sQKl*8^=b#U|+8;dWYVGXT@&An2=DfZBIIV!5}6?$?Nf^st=M*n_ze8JC{jP8M=X)I{ZDMA-prs#-f4R8>wM@c)Ox3 znC^X4@k-hB%_I+vhpV0|D3*AH?r@e4ga;LsvaQE9PoGc zPFFGQvt(Da)aKj+0zCE6XZ%!Cw#-W2?NBVSU$nnG0=*qB9h9uPIJEf*ri!+-$6A^f=HFZH;o;vlaz7LA*F?}iOD^E&cMyBq=4`*+ao7!63t|Gm9DN?46KGP-KO)-YcydWsaEAY$=!(c#KX8xO}kPxZ=AwJ~##!zv(l!R4raA42d$nGx`Td8e`P zfAx$7*!_eYbZze7?IrPjR6Vm1y&a z`$o$Uf3JtpkWN-wLn;GW{QlL(XJIpD(G<47zP541Mx}JD$KU#9bea5}F8%^%3{B#< zBdhr(vi)egXQEqXEOImwDpma@;>p;fBbd`8O5X6!ramA-dcC~YQo$(15n3=u#l1D? z+k%E_>(d`z??tle!8!Rk-zbeZEG9h;(KBO@1F+UX8yFmObaZrbDh=VK$Dw?Bs??uo zp`#*?d};JWUzNt;TMNNR8FGI{%mnl$ZR)C^vue-pWe6t{yJVJ zRfyxG6+>eR!v0VKE1oh@K+K`oJXe76Et3m!@G`g!ee*P=uwplL#V>?{0KxDg#wo<| zN;+zFGRhjBi5iIHKyc`2NcaimTnh{PR(~=J<6VIZR0T$Gt7nKZjwV_A0{Rb!>Pya7Ea5epI15PG9CS*kE@T9JSMeKR!D5B!#>k3zAn z`lBl1lLxv(3pJ2wFpDd%hwWD3Dw|Bo;t}4wy1|Z~dVlE6-z5mXE^}k4B7k3%7}Tt%k`1I4TGRlZ`xXRwxYH^lCA9$KBh&H%vjhyn#;{R zafc(&j^v27<6dPiMVBSQc$l++=eoqn`56&-X$#D;Ig|;b72tXsod7h99pe$e?NBDa zR{B&2cDeb3oUz1p(YI@JR(<_XTE@4ch6XDRuJKIUxq=>pr>0CueePn7!0vm3UV5yH-7M(~oeP&3L9^&8+<&6q7$ zkbBR+^b#emjIjKP|prlv{S<6mK0eBiaeI8jP5z+j0Jc^F3E2T zSh4=T=ekG{xR%)GGYs(zSXc!_kA3IltpOXcsbJ!^k9pId)wtuM)^10V?dIDHj211j2@K5$gx$y3=Qi;a-(D;^jO7 z#P7@Jx>wgz5#S>4z~BH9=2$6ScET?p?h{@vZ)XtVbP2L9u*yA|y3zPPU?#09B;R+W z2$iEE01)<_j~~fJImeXYKLQV_RT(xcQQK4U>SG^C=1G8?((C*8G_lKP1dUIRji zl}kmO>{YjgpQ}8nm^aX0Eq9(nbRJl*En9AzJZwI{F>5&N9=$ZARV^tgslH{83=(ZM z&K00*oNv)khOwE-uWE!*>PK8lb|S#OJ$Tc9^U`3sTDGdD2rjMizGy0}ff>_b3R)TB zaWO79+|Y14wV*q%{YISj{AW_wrzZ&1r$`HO&Ulye^_teq0E2za>oF++dASWR@y*%z@wVcQE&8OrKUSkiyGT4 zee~sfnc%KmNyULW58u~k^j+6Pp!FgRub;`pgRpYVhnlmXKi}#QI0~KetP32aHcqU-~}-uq3eWlxsjRU&6sUw8Kl}j2M7KKmwb3{t<#)%M2e7>0!cN zu)uXpyx&kJ2Fp;Rhl-dvfXPUq%trhW5nUV>42RfFr!};QBh%<)c|`@}=_L#HGfQpr z<_%M2$X$?RJsgt%drIG+I|*pZQBsSb%T1+U+TAD3kl& z#CR-o{o^y@ORG9(Wj%eOO?Z_|s{ zz`cKoPF{vTufP@3-ZP?2#lslc**47c?Bbmc`$V$E)570La5J*4X|7M*KR>S>AghTy z_aYeY3&G8Oz00v~8iV5XjZTT`>ap{<=(6-)gEfbDg4TLV_0H_RzNd4{%9AAj?4T~W^l(}pI17mA4j=~{GmjvG&txIOoC1y_ z4mrn@Wj6$OPx>Iors(g;Iw`-#R>v1QgpBhDt-k|cMuDc?gs6>)$Xk0x80yh-bWRj{l})>V z$R4YEQ#@dC%Qyliwquyq+E@V?5XB5uNW_C&hO)JjJsA-Uf_f%)eUQPZf|n%gBUMs> zzH2*|J=h%xNT29g5Y3?-m7#RdIry$QN$)bIH!%(H%7-=1+PUR7BeN1lYy59N-~S6$ zJpCImbDIv8#DKZ+%QZu9r|ri+8*vJ|=RIC`AF6}$O%W-%tE+3dni?-PUfcPG@xbt_ z^SrXuc|hE^x?($X51?CTvA)?pef{qP8|Eiu+=@G+n!#80Orzba`Ve4E$wn#6yi<=zgjaPDpd?mL~o_}G?a|0|J+L40LkBOL+nc@ z|C$c9s;qlxuZy_QG`~R4Kd1%jESN1C%qxw;yESof_59N zKnzQVRy4=W-rj!5r=%K8{{DN zA{?aP^Zj!NZ3W=o8xZJ98SiS`2p7!$NPMQ^JjVJA!q5z5^RfyhtO%U})s(d;t7&5C zNof7l-C^_M%kCE;V=z1zte)g<2?&Xq32R4QJz>I7Cm6}dQ6@tvYh2+<&Cqlh)s&kb zEb;eB-lkUz6M?cEiE;7qWrq6t1utIMWVS<9aZul%UthD$vTgM>_F7f|ux5v#zzEK0 zBXUMq^x?n9I|j9^S8Z~{9yb8*CJG6Yjkqe}74HbU5jpvTkJrI5gOU4Y3WP(0Gb&m| zl{N(90xnE~p$E2=`$T&s9vF8hY{~^-t2ln&HBvZuH)DYH;14pG2|DEOs7fB#X|+A; zfc$m8_GdTqGAd=RyXzv=4iFdjO^b`IcQ8IaXHEWG8=AsUuVXM6Mn*>V4xQ(uG*(GT z2}yl$EC22rDyPustrQeGEjyw%nGDX{eae}GQ8H&ce_$ckM3x00f;8KKDJc~F(FB%J zFBAQYTDfN%yHv_ARnqX!L0`#)9&{Qp>BYcXFOTKb`caTSHw#1I_)| z454;Odhnp;MnfVgVCc}ms;tJV*&_k?ZZ@p7{hU5E`um?WHLtZ~V(%cUozWu!w)}%0 zxrY++tw$GY&dv;8he;FS&EV;+i@=FnK_fuko1#^dP}h#o5CCKfsjFf{1JAcvs{h1K zAu|f?aHLP}fyuLUnOqnP0$0|=wP}Es3h&^9DY^J?nL84_QrZW4MhL`^iq+hT5FXL7 zx@R7C^iszmh6Z&mkjTQKqBqphvm;8_8jp+WzGQLsnfqYsLTDdCqk=UcdzgGU90hVX zu?QzdJg_o{-q)Itto9UtsB94nPmCOhOi#ZsKgxuWdTv`MI;1nOu9vMxD zC*XPIDm7f?=_3(+`RV^i0vDht@Xk8c_sj!t)it3S)k^@IzaLb9hjv@w?m45N_#_Q; zGV9t6!Bd-t53BiyK=hR1tHd2&hsKP8`g^3#6%@U=Y!_%E1?mQnS-43G9iLwDEC1*m zvY-RVJ-t*a1we(s4{MW&H|D|I^eGk$c2eSwr=-rHCM_V^AKSugUi`o4mappVY;ALW zn5IRbw`NFos?QKupgD~JoY*YwhA@Ofc}!aOoQ4xxx@Ib8XJV;!;$1F=Co5AUGq1OW0%%lH|HoETL>0vTbTL=Al}L^>a+D}U#Kk(m%YA`CjKekO5Z zAmT&*N$z( z1Ts4YOKWqiK}mw82_m<@9d)QiqQdgk-y%VPPR6e^mX?-Q_lpbuF`SAa?`&DKi?`Q% z)GWN`;_=C-TIN&NSJJd@2t7`@Dr)%g!Rl~1NMVYh80$SaK(!F{M98JWk2g7XR0;+e z5Ae_)JCaoe;0Y1YBGzWjpvu4p{_{RJV+alpRk{v@H$$n(gVT<{KBzLy3u5WIL5Xp0 z{-^=82x&|{&$_8Lo+u2QUL*Oe3WPuHVSUW$6dlKeaF|^f5+d5u+uiLjP^OB9!4|(z zwm=@jB_@;<(_U@9hnPX{@dOkmv@-Wec7$)}J@9a$@d3EjQUv$I7U=5giid7xp#lsW zG}i~`2! zCa9X>MmjcelWC}c_njRb0Z&SnW#o`(-;~94h3?E?@Hf+Gv*#Is;K>7Q*#_xJz^GJhXhQS~%nA0F-}bWH0+b z#IN%fWN=KuOxA6<&nH*-t-lYbABEXBMN3axtEEXE7s4~2c5yRK!Gl~_7+3#R*A0BP z+u5^l`|||4ZqRqcPw@11y}1;ZZ~CWU_tf$eHxm*PT9e(s(#wiIb>W@CLwd;A!lsTP z114|s)kT?17IX8|Mmr4N z_VJCYttu^|a`?wu)uC%QS0Mmi7GZo2?rlF{-<#=O)KZ3s-5c z!XP%5#a;-k>;PCZ2R!%}uI{KDd|bK+f)0fW`ARmzAt{cEIUA}Y{S`D5{O#Il#6sN% zQL~S+!>cE!lP7wecUs(bwDzOVE*3jj#>v@LrK z0#@y-w*ZklL?+b+6Z`71zjgC}D@h@mydLtZesnde;`RiI_`Q)1+~}auKJhs3&>$$2BmQpydx)&<_=cX z-ehRjcnnn=l?rw1wSnv+v5>BG!qW&IO%JlbCf<#5yR5jB$sQe69g`|=ZQ8{oJH9k4VP7~LBlZmebE zf7Z*(%f~0%Kn{ak)!VCT^c{M(yO7i)K|6}<>as_#QMIR2fJLgmezfwi05GhWJn_uk zt~I$k<#B3f0hx>&YDs&ZJ@)8sX0Aus_ufQ#McnAkVrcq;cPEOGF=BsPqVunS--Zj6cVq8|tb6v(-KBi8 zD>R81+ie{Y$!Ohg-cC0s$!;UTU3bECp5N!Z zH-lGLB9)hgL1+bX4ZxFtu1VT>ce&>7DP#;8^ZzGbJ$&13)9%3bbAd4b!^6WPwW04w zS%mhk);p5MLo2=Q4C@)DMR#@wRz@ApY|qVT=ROSc!WPmt-~F%b^@ix>%S&$D*ROYF z&$D|F6*I9bDl&4&k?LysBKRO(&~@tTP#>Rg;Xx~FYao!Y?apXRaipxzOdW^%`L}mUc~3u`D%5b(sn#DjN7*Ugxj+?+W-FOxvK-;NBBwyL0B0;VQ2w^ukXeuUVF4s z3!SrZqB3)oa{ZBMgWYXwPhj5rIHg+nB2=}(5N^+#bA^NVG6atfOg?nd7M~ct)^FNT z$tituh@Dp79Av*Y`k2`HxiJxK+hgq+Go1rDg<}(x7nD6{oK|5n)j^jJ* z8<0`0w}*U6gG3Y`By1_-`IH-T+6}jC`HxA|DmxAO`oqyQ^X+7Rf8mZ!)cBh>Z=ls| zP;l_-=zi!+6%Z~o*rSHzb-_Qt>-@8aG~QvTKWb`frb;@9R|BzLDDQawh~bk6<6uR1 zl#5+JWQIwS>W)m`_@1gVRsIbUC&`)2xZeIF*dZj zM4kwbkQ~yw{>ud0Bt51u^Q+N}sAyp&?|>6mcKsmVX(cf=bv5(BuUqa`Tn{zryk^1fsIXiGMF)s$ld0V11YOs_H@83K) zMtSE-Jd!64rk7C!Zs-9w59MCR`)Prp9B3xcR(Y_yJzwbXNNsBtcQ9}$jAHu7a*E}^ z@XmxD>&`0sBkWL&6>x(Vr`ka|f6;36M3Ma#;o%nb)+2oR@b9l1e%p}aMC!lh#|}Pw zwn6~EKU#63uH~%c)E2eYNQ+SXNWhJt{9fp9CZ6R6+1g3}Qmi%0Mj1wV7ZaH5heQ`Y zm+i{8Gv?X6Q!1|>SBYRJX{ht*=W#p97|FchK%w9cWe5DcV-Bl+L8#_s6T*$PwcAHj2J$dc)|5RSPoT# z2sk2-|16=Sa!XHdZ~ddWWsAfQi}G?`I}#@}BUJVLdR(_Je6X0Pc6qUaJ_|hYM5=H4 zy6zqj7avu3D;yfRky=KfaHRv4l>J}A@|lD&3&0xa|CPpd(Xy*wsbK&!cBM^@7Z8xYDgCgujhsv)->$vP!5} zQhA-dC+E!u!|TaNC>ogsnhc{6b2!lCXUTNb?^=F|M^FGv0_sM@LU$`TODW`cWe#eK@8sxBNETYP|55@7YZD31y1w16Ec;$*aj~&mjYk9S^bT*^bP_^R z#g_)=^~w|(`gh6qHtYPA*6;qZb|RXVp0A`e4AMIPRvd)qeRaFjP0ruRRMu?tEO;Qy zDlLlkx{0X{!qN69G`Z)nPH%>pJtrK4Hm{)yg=Ewju=^rdU_H^ zbexLbp0sm-Exw@VvxOR<*u77Zd>p-4(p5fEjFT1bw7Kt+#Iu#e)H1G#`S7za)a@!SqMzcnC8sZkTKZ);^$xLvj9X+YxZLK@J|SpJ&V#5$A)EwvKfjjMrvsH1QdhXCT6Qlr?jOWA?m9Yb<-L3FjidKvbImnJ(@dgNw~sE-t{EOa zDNUDjkuxAq+r2w=eYSAtSVvp$h=a3p<0b1u)#{i-|8Y088fz$O zkrx$oX`r=MZpey0;ZG8+TFE|%4a*8GF|k_EpSqG%3#r_{QUf2M-Y=tH$MK7P80Y_B zpo3PnXu{8>11q45!wdC!4+V8Ati2cOYZ48`74Y*)w#6B zerc5dF+Q}H*}PC6iUxKoJ-eB_m%hFIWMYv$qow5#6glvXToQ=)H z=)I;ddo0+3lgN;wut&w|)X0Z780*G%YKA!XJ8{1sQ{BC@ASak}(qv0~W%9ds?;eLV zJ@mg6wP)$d;2xlN7SiVi3zrJEcxeltX;`>o+B`KQ1P`$;@9rKLVK52jOUU#*gH8#_ zuJtKX{D!b`^t5_KRN$7J7UQ4ZKu3OkI)CdX@^#qo0zy_r@TDLfF!d!bsPIs~|JpM;V%CIKF|${P5F=$P3qU99*zO7ajekkis5_N8?H6{Dxvebww(aunuAZ`w2WAJwCWyyQA{D_Qa3Gn%2~$-Ad(So8moF<=W~R z8ajtHx(B9`_xHHY1ekJIx+KKlQa!36*YSfL_~YOL2nZRLUETF5wO-a!wkx-|*x|W` zhK4W|0$M&wVNh&XwN@)ji{iZc^QxrJ;5d`#{(TuN&mViu(Eix5b-Gpw$yM5+>rxl- zp?{f&4@sQPn1^0$ayN;bePqD5NY4T8zCrLAJ+lZN^qNFJHrdBprs?CH2t9=o^y_8M zZG|P9Cgc`38Q1cMsu&o%lkBy_d4j99A!Gl(H^R_yvm!eyE{x+3zRjpKwq8Q75Almw}$qOggH zi5ojAQ?u$C8{N{B))LjKHpNfpSvuElg}Tu3(rbF1#D{7@{-h!|8-$qT*k)Q-(AY%> ztWPhX<;(ll)mLEr@f{9Xg^>0Z(yCq`+P4$8ZuH^1L9qQw4XLPLH#g1tgpQJ}-WQj4 zN_5QfHBH@bdoJIUj6}?F?|k!4a@;&n4?0xB@by!d&T>Qq$a1lG^VR;KtfQRODQ604 zDIo@1w%E|UlnXNnI_euZE5a{aIQBgHR04>PaO;jHUg;0tOS#_Cb7D;1?-IMty|{OR z?OdDA+myTn)e#m-vj@LUiX9 zHMQs-J3nx)54DF=HQz)=HwcBoR*bajsO!7Z{gv^9_uBpqDLV}X&UBUSqp@DysmmFY z5A(^OYrR_AY@iJa3}j5Sv}U$L5k(r~ap@+dJ6WhFTRD^wlk4Guf$d2z4bPBVpm(2R z71Q^}9!9p^e^y(rc$E%Y-hSGq7g~w&0@%9+hFoab$2+lrBzy5Dd+v2v^Ecy8fy(@9 zqM9&r;&)OAXY2K(eY^l=YU8UYRxI!C_esIg-_dtH;xR>M?YozmQ~k0JtZUm+CkQg% zp~7|+9AG=vIX16yc69X5W-vmuXc}xr8Z5saf~GV?3sptGhBTyr0w#N{%|k{2-=HXX@ztN&Yn;-u{Saq_{WV`6ln1 z20@5^@NdOx>^7$OJy*pg*EF%^3y3xtHizGp=cW~VBj=kdcRFuR8&^Vwq72tT|vCXYTm5c zf5t-Z&uuF!m4^&KWA;5;e$6IVu+)TJKIWKoCU|%-BH61`7`aU``ywv@-{SLDPiMPw z!Mj1p+6rZhN1fY+2Nv_zK(4tA5<3#-nP{z4tN|^hRm9>NM8=S5cPYKU2-#5V)AcI) z1|{h?w{p2ku&K<{f@r#B%R||1FIh9=I}Em*+s}90h#0mze?i9!exie}ccBfUjI#Gpbc0@m^YYrSX5o*;u6|Kebb-e@011v)w~1g;-Cih1%rYNx zF#qD*K^qnl$Q*JT?h8L=Z@)gs-=*mMjy%Im&)9FTdl(*dP|)Tl**%p)=BrST<|?PRlP* zQp+8hXsM5r}bi>Q=apRN(MVL zC2#@O^;~4mQCU^Pvlv<9Xz7GzZ)3W-qhygel`&XifT|p5NwYM3rmp!q2=)=lK>s`( zJ{+9Q6~3e9m{C;jN)vuuMNB8r3Cv#^Rhs(IjdP}hOU1^lJrE9`d<|t*pE;f%R8zEK zYmR4cM=Ex0r}Fp84v~uW-;Q=`8VQfO_`AjO1OmZElS}FxH&@<2=qY8z=S2i1Y28C5F$&IDO*55FpL0!T7@tK3<07c1WQ;UCNw|@B!v9#V0(_X z_MHB{*LAM`cev!`eV^yPKU3s|=FW$lEHDh{-OgLqKN@hkwv&|z%JcM5(Q2RR>VGtK zPTG)>ZhzW!rpLNMLs#9bwA%O|ky>u*o+rRk1=YPQHF2bFTpF z3h>2whyr-VBFx#OT{!EPyz#2G-gEe z2u!4JXwTOOUSY1q=j7zXPPmL<-25g0nCUiKA6CVD?JCX@!QaVa(9~A$c#6@?ch=L1 z(>6j?rB`%Xs04EcbQ-K53y57`Q!%Y0s6OC2v)=!l|1?KF?SKdZ>{0u+o`RMVTX=nC z&XvmFX!^I>nC;aW!(hd-fN!S_h~wEMN%X!)SGIeD-ZOcAYwHLoS-%2=+r(8Lyvt&j zX97X6WZ&9G{HbDltSpcB9R2bHO4F@2F*X1m2nZH2I)|%ZH~DdTdRpWx2UL^^Lzv#_X1&l)SX7Brzm$!bf#^Fz2IM2r=`D+=q}GpOPeXmB?s;$ zwg;r9$1&!(auvf9*8&kLjXyAsqwjgE8OGyUJk^@`fssefrQFK#3)4rl zED(=4x`D>FikQ*UJkz0bv#O4hDA&x`huD^0@f;cT7?`p2L-Om%`YP1{gR_rt4i}G< zSxs*(w%T%Ew-ekVJ<;woK!J<-_}JK}3x4O$<=IPay#J&>Xl?~~4zo(P!);^BpMcNz zG6rND|I|yl&qu~eR_z3AVcxz}yei+@_$kY@E8qNp}3a+RP#3JXtzr!6x z-Fv2`-XyuT_=a%d6hqHYTN}I%L!U$|I|vnh&w@3l&B?`O+KykFy}^DaUQoLbthhNE zgH1P8QFXt+hh?Bxr@fX1pq$4s8yk_Y_aMu+d|>F{k?Ts}_tBm<=I?w?0`QZ8}lN?mUD?rzEVAu&Z?X3w%rD9?bCS|bH6v?Xqw2A3CM~zwT zg+H1pVwX@@3GmzLRo*knj#!$Ca1~L=LTFQAf zw!e0E#v-O1JQbDxF~*DvR5FP~-AMFB3W})daRym%Buuz;R2yhHokBipy0_iXKb?o? zRL&HU`GLX4*oH&f>waR*)v&MRkvak9jbarR9Lk7A=%DMFGb&zPIqu{q|ICgHR-Ab- zy93=3!!OV|yjCwB~Fqj&nqcxBI38F@$vTO_J|I{tknWAO)9 z-k48WN*|dSi^mrjZKvpF@NUiBePHSm@S??Zu_=SC*Pk>#q)Q7|V;9~+p$ks5f*6gn z-2{Cj+tj5jdR&CFd8j4m7+G7UuOH#*7${h6ds$IE zSxlt+mz%~)lhlBOW+?~lriOFd@&~nw9C_bg-muq3u{dA&OYGx~0+C^U`C+T+o=bmt z+dkxy-t@$n`yB*jPmT0yHnT&OrNZ)4#l1kQ#*sq8r~ZFc>jl#xx5HAGkHa|Ui48jK z9}pl<#xp%vrJ4t?b`e}11?hd2Lfu$MS4)nEp5vtb&F@|Pak~aG$HPcL?09$cJ9_KM z)h!Z6zDeO)qlESjxjd5w)a^>uCg9r0ybEG(zDsNNa{Fd%EbCPB*6y+d;&iG4(#8u_ zS3XV57Dgo>Y?%NK z1i3d&3fNY$B7=II4m$bAt)sT;yzX~oXO|&PXjV7tTes+K$vQ9$x@H)fgZgE5Zmve_ zM%&Ln{|sC-c)tRe^@Vv2HhEzfUxH>;|8Zqnyi9WfEirJ+sUjkB|8J9;;ZDJR2FSTP z!SMXlQ;vW$`qfNy!xZ*r$*v!9r*eo)#j1&qW5n$9$J477lzQp@Ddd1vtDC}ZA;kCK z`Hjq4G$QuPlkPZ|+%d7E1u3F<7n*D=oe@hVR_2dv4mOR@%Xr!9E8~ltMlJ)fMhA4HPU40hk zsFK~CXQvGSnE2=MNn%{L@$QVup~aVv(7bn^=K5>CSMS)AZH;s3nkIZ~*a7M?V-L76 z&0i$^YUhBi%gTYE7S;Z<+F%`VcXDdAR50A)aagrc%*S?U@*s#n_Q{@+C0f9Q@ir@o zWBz&dYbQWkfFC&ztcFE<|a%jy^TZ8dTz`m&;h^Znw{3C_zd zcmW^OAS<0qz@KuQLSt*-qFHy>(h7`rAJ60+O9}6lE6hJV=uQ=zS)tNgdA(CEC=z>( zwT;bryb0!p=K|wX>*{`=hP=9z(bWPkO}TTRz<5IBm{gc!Yqh<3_BS0-7v*Ye_6ad& z7eNRLZ+q*50Ne1pCRwi*`|aMBu-ymHk)pd}Yc+F}2)YV?;CofH;;NF}4*NR;_&|8En6~a*`H&a-VXkY%gijM9hToISXJm<+BMt>h;+9x zj`*wAzv7UJI&tli^(NKc*qQc?GVN;$98x!JbPr1PlQjU^PBkGRDWl!(jIr% zPfN9UeulC;6fNMpoOaIi$*dmqSKQ{8CoyQc0-Fl2Ujuc+)#Hs99_8Fo{qmkG=_zB* z8KX-W%=E;f&IV!?s{yRg!J~%kA5`?t#nr*1;n>SHtqg#l+U-yw$Tbz}FLzKJJgoZu zfj{t(#z@)L%|yXh5idWIJl_rvtI6PL2XKR0aT$l?`(e?nZGlk{j5w@DzJ{#4BQyI?z3Gg%q}g^L&VSR98_zB?n-BB7)*7wUe7ww-j@u=vFX3jp2%LMado3dCBhOf z1&~Ft`QV)gU407lVQzIDfiP@AO44Hy+8`8;OeX7ojk%F%p@n`s;+6Eyqc=4Txwc;< z9Xwhr@phh!3!Jt*wV7Pf%eR$tE9P$xJ;xIqCZXkr(bHz^`Y3D8k*Yy|&@F9yZyWww zGSQiZ=A7ToEP#z)>;aBy^K%^B%5kzcOhcoR{R8As(Yrw8^5hMK@4N{9{rSDC75(qy zpKXuGAU!We1X~JHM_*q)tVc^--5^nqWh6Z5xsE6rCv=Wf00k4-t!ziJ>vZwc$DDrr zK(kqB22A0&@Jq-1m`5ibhTg*^_!!2bNpPt}PXlJTjW36utn+F^D!vThe6jT#h?& zC7L)7Hvl_$e^0{(j$h&*?#rb#u6G5c^z?PH+aY0Q;iZk2NsxG!TS}I@)(ZCJ7ay6l z{WeUzpX#zC6PE=x?wi)@ovgoX;T|Y~mKQ`vH%7KwsGQ?Pt9P2TfUp0KsWZalex|4Q zljfAyLW|lKxk<^f#}J_ww}iR?%s5n^uoMyjw*dUux6kNz?dJ=cvHz~Rnwq;ZI#oQS zsiAR>Z5vTrU;pNkkI$aa%mIl6i?!5Z>I(sj!$tL<5Pa+I88K6dP*PB!UhS+*8pqvn zmGh$OrNA(TCIUZN)S8{S7*y*Y9&R*I>A3i`9s0k9=CXH8&8@R09gwXdur33^cMo9x zEC!$UacG87OGRB>xI`4JGzPks0fcX(n+nYP=!3Nz@Hr*p#`y&&$TBP=Fi_jYc6A(1 z%ZiL&C)2A5Fy`z}J4j52F}2kX!(ZrD%wro0oha_5&m7h_ z=`7C*n&Paa$s09NQ46nyg^B7Qf zLbUjOL=0EIvhLw)-Z3B|KO{_T&8{4O+mtU>h+Lt;|rjNnBP3D_5v0yhCi_E=zo60xyUzqLRpyF8S zii#m1lTbH6#Gh0U>4n9b=r5M5>Ig9|>19LT#kfs)MI1Xi?02|oW^U{j9-l0Yh@@XU zlEl|vZlm7JH#0OK)*I;SASwhFWaO+t?(*Bn@*1mm=+f7Ja`#6ut|!5-$*c`lBhfV) zCh2yw1%J&ix5T(+b04y?`hfy&I58zw3)?~MEK>Iw_fp)Q$+>@2+!*|d!8m1&@ojcs zjgQ?36eg1+E_ghwUN=h5#^3F{jBJ)0&L4iyV6&-jK`VhQ?rv+dq>8+>tp`t;3!0?( zb09bdH9s3N^FHGP}sX*NP~x3NCDdA7%j$!&V+4>YV#Ao-L$Fl* z1w5$iccCdmp|!V8|40<;3LnjB%so^1KqM~EPb(=Bn?lu@F7W7rK@#AsT zMPQ3@z@Bn;&RpGlK5cP?UOQ_i4!e9A4ytp_Z1SS7?G=XSSx!*eEU{`RJ$Y6<$)YYA zFOSK$>_`|gC~2MyN{gMfK!-^-Ag{EROi)>w=D{U^JuXGNb=qQE8%WC^{f$~v7Bz#PV}0_GolEI3rH?CWzb%1 z(^js(;?$Ikv-wp2fWF_g*?)t7Zw>nC{|6rQ60a_}O(eolMKCHse_h>9xD|Gai)_pa z8-_#7m{OlourE1rZ5-~Tl{*^jZf7zHDLxzj}5%Y zq)4t-A~id^*U4x)uY~Yu?`4ET|9%F7lg|};Xn4|MS-8!;$WdR;`x_kgh*YnOl>=eHN2_K#QYUs`Xr z4Gs>5x+ER5wYA77o_z4JA-$b`u{shWj!LWU`qkY7{G+n6^1)=#LR{MirXT#p2G|Ay z_F_p(IXS-s7>)?&k*C7mT1+A@`uJE1N}8c2v`TDe9bgT9kv3=>de{p~d{ST7*ufq=9SKuFZ5IWy~bK_+jZ20i+DEHQ6Q>{Q?6_c;Vn8jxGn=YBQEk4Y9`u z!gr^q-F0D=~{(DX%%~UM9X8tPE=U#}A&cpp@PE zpP&=6LJaux?7Xg&S<;KsXV3a3&pdE6*V6M_ND5jQ+I(G{MDamV+Tnrp! zz!{(yp41DVVEHj?Yhv7~L|-Y@B9IX9YE3Z4B1)OhIGj40QQKd$i&-6AR(#o*HPD~_ z(45T~c=ZbPGAJT(jxrun`O^Pl@h+3~sAp*E&S$o3rswEVgDGMT%|{l12TK;MV3jD_ zGE;tp;`0#O9>da@_%S!E{w&t*xjkc4H($`_GiA{q%3B=TVjO!kF7~uxgPQJlf&IOB z9L>r<;#o}RQkIBGdmBr91QsJ!BsJ-+P|twqN)Dt(NJmy8YbwRmp%vF5$+3P)ioYW!X{=VRG7>I(xborr+w*6z z%y{;CETq?N?qCdJ`Fh#<`coCn2vI-*0N_Uv7zZ32@BsoexnwgzbWFM1b%uTlzl2?@# zsVjGlj|diXJ?rS)mw_Z5#0m}4ajVdy;@58REpTu>?!G=S;D$^zI!9UQ{>EFA*H~j9 zoYu67smivGC`qT$_Qr;E5%t%Hy_tUc-DgDnqdSHtVK+&UJMK|3Xl?{*1x5W{&cD=b zIo7O0q!6QK+wk=wY^nqGQ5TE;>Aor+0XFtVT(2^gPmR1$wmDPnY zBh8Y)`4w6wWs_IwbjuHI zhuswa&@8UKNscYi?ijeC4$&Om8Ol)%P6cC*&nuzT0nXk>wyJ|Kd6=>~wJzcj1bplX zz%ULS9aer4xvfJZ#M{&JXA|<)lpt!xMgGf z;c+?o#b-$}u@|&R{3p2Tmb3EY=OSiTwjoWn&r#rmXkxZK5O$mk6!39Lvsd@v^uiwUw$Lb;O)0cciGfGP(%Nv^sV7hljAW6rE6~i`y{iIi{p8{~mJI5f8^bCA5uh zj38+aTdyM>p8e=Vx^Hq6>-2ExEwi{{yjz~2KN%BlhVMP89#U2%)f4JWT#L* zbbR&e%Orr!ODSIjem4a)->%(@ezps%4uE1W?DK8P5rKhJIqwVGz)+0dl;Gi7cFu4< zy}FD><72aO{) zzBVHW>GJ7G?Z*-PJet1byR4irwcoA~n9|-!q+0$#=j>mr5^l-)f9T;Nv$Iej# z)U~6n1C1x?w<6*fUcde+-35ju?&O*D68$vrLHzdI0qEE_W}#SAg{OIRn3S)-!yd$9%2Zgu0`R7WuytS{?+B6eM5Fq}Py=lCUNxeNg>#ztDd zb+5Bu5d{tPbL*6B(ogSZ`j@ZhAs!Co z*?A&aO0BjiW>6Ucxwvhhc#|rrn&bmnk7?n7PyPvGNr2tCg;hs+c9-jj@Lct|d;LVU zgdnF&%4Paih!WbraHq~3Rwh02Zw}6=+x#e(m76%nW|Gzj$|-LVHczY~$-rZ+g>4z3 zcQKbJ{pN5Nx}mO)Q&1obZ@Bc!_iI=24#^So=K?imOU`OqF5LF1*i}d~?#f=?8vubj zl*^W445<`YK)(K`6g@6V)1yH#e1qShcK~5sT?jWNkh0Z>o|9>qCktwjTPYEE=x= zeZboL{@3y6*w2CezZmShdIfeN%-srtId;Z5FX>Kk=)J@@<}2OC=y?|t1R=F&IPg7E zWuh!uGs@EP01VI7uzin=nVW%Z&f%Kl1A3C*e7s?VZwlNUGczA3R~JTxu#M&ARNTuj z@P$jL$^A4k7i6G^8&W+YyhgC!|FY^q~Q(x5z@|d{7GpS5*Q5 zcjw;}Bq>L~LHhd1vXVt{1XT1qjhK^zr0hitQgH#-0oT8R-XhSio)Q3@+yrA58d z)F2D^Sw61WDQ+3%ciwK-Q1+u!UwLEUE>u`{u;dcJ`W0%*i`7aoN6ioJnk9J)ych_Rz4|fIiO!9ae zIeERp=zzN>`}ec$X<%#d`iJoQXaqVh_866)1S3iQ;A-aWDF?yQ*bh4a+Fvw@yyqT1 zUx)OE1jf|lRZ9Uuzl95q_*tqGFe5b34c{Qa6weYQy-TmlxL1g_>-K5%bDKZz5ULL7DI{~$j8@CX2JsK zo~bZ z2{BU2&$_+I!h`&a#=TUarfk#ru$_8hk1fIx&KKB~yLHnodwDyQ8_bcN}fa2cF%WT*rJjQS1Q9JIAr=lBP+(e=Kc2gAGsn`|EJjjeR< z&1ulRn2OqF8=#Up3U3?kNVj;@GALyN`(+2UU>K86awLlNSE!Ij`J;s;hj=>{Ki^)G zY_OhaJUj*et?%GexMCGEha{;vH)lcG3r9plJH?Y{tdBbqNE6$w=bTBFIaAT30aFYp z6PrXsbA3C(+;FFQC^`R0dV!!kVUef@pSW?2yO>>}ZlWoi!yQRIGHt*TOf_~;wMz@u zb0kzfG*;KYt$&$VE+rbNid`EXcOIZ#H7POV4}v zi%!Nt%GAuE(n%-jVgkDo>DE{fDPuI2RHRl*nGzvI?{iy!V&R_*qg0Q;Wq_QYqvZA$ zIX)aV=myLB0b6Tpa|MS2)~(CG)1xv^CWNjZ*3b$GbMDd7&>$WdOaj-+44R!9l%-i> zTNf-?K5`{2Y(LXw2lwONKo<6xE(&?xPakVpdckm@7+kw8P2ow*(6HLh>MHwe_$KXa zd#D2j3Pdx$7$2feD!WumnQ5S`jr^HqU@K>SYh77;JA?BX1DCJu@VX2%k&fe1#NHA_23v? z?iY^T69FI5rG8ft-KZnebN=0w=!{X9YJc{_-7}@4-A$q(+(f~*$Kp4sx+i<(&)>|? z`Nef8pACOj=X??+`wL){hWeinKF#DkkuoNI7k};#*Ezr%PN_1L<&eVL9i$U5Ler+% zK47?<3}xMp7z&iQQcvB)>n!B~4eQOlkHdX9Bv2i%r|aFj%<;V9(eNT?K~(zLg%^7O z=?&_-;~nAO1KKubeb`B>vg<972~n|i!f=4M)HfwdfOV<>XgW>Ub7VwhI#unGDyoTi zbSowX0+Jx(=q#s$mz>tH`$u@5n=BNpIfCHQEbV956hR`vy_?i6z8+#$ArQHnlLCHJ z>-Dh@s|^QiUD^87X5og_Y=fes`bCbz?%fwjuO#uQ%AcXcu?@Q#O4ks(;wGpi1yN+} zXTHgvS{GBf%>y~tLcW|JS*;a-F67AMbE0wRjL!YD9DHo%p4b4GZC+_3u-@LJ{u_Qv zA||@6j0P`3<0m7p40nVTYePxEki3E|3M*>V9QGOuoYtO2a=CpQ1IyIH?`v{ns`Lg| zo6JY-SW;4$PzZuo@aq32b#NO75Jt3~i*))FB93dXH4pBr+)R$ZY+dy3O=v7nbRbrZ zhi1)K+Z!rf_{a3VF_qgc;`%u%u?}?@NmE^c?d%ElSgOt19{-+8oKN?X`klZucL-oQY&wI63J1^03JwXmcU2U5zjIn;la9Vpu_vw4 z)Yz+NxcSop9T~>?`yUNzJS;o=As26QL{Esq56Ul4bJ+&`?PtQmULCFPoe>DXe_4uS z!Xj>=kKs7Eg9C@L!}yG&Z@OLo129Jx?mVB-6% zj8&2&J$a;VqpQsUgW3~MMqcuDQ`##CkK6)I$#Cx;pR^V?28C0RPpmE$a?fxo%@Nb3 zlY^VXGhmN}kg=4mF*eGp9(GSNc|_uV z3B<%zIaHW_zPAz3XyN|o2}7j3|Ze* z!zM*=c7Tg&0GH-mvQaA5tgXMq(4oF8Wa1?X-uxDm{Mggry4qAI`$ff9I4a?336uES{U7}e8_xNR z#lgOB!Gwdsh`z;N8iL;#)R#_8Ii;?|ZgxnkQQIW$N+UX$GsKalJMUadca|mcGJiBS zOf&sfN+!j8gA>pCA%1lr`9q&pwe5ko6W>e{T!((9Uww{V6l=Lda9@<5L4iLvHMvTAMGdV8Jq*#340tFr>Jp^~1MFYD;_*?lO5vlV&w* z;LW7S)L)iWO9d9NmFElSd9kC!Am_p3kO7*JT{?DA7rJGJJ z5HEoy2bpLd3>&v4$Us0`FeciaQ&vfY8WGV+L~Rhed-VLQ@2MLSuwkS^j7GwuJcWQc1 z4koWO)aeGiM9UEfevySQJynyw*QAK$pja?h8}w1|i=nHI#r9=UvF`p0XYlUMjRZoj z1vU{p;6T{D!B8A#yh@of6q{uroWGDKNZuSt7Z_$R&Ezj<0#i&lrch%pfO|Njbd=Jq zJP28WGeP));jFkLR18_4yr#jqUOrelg5<_UFW#sm++6%P;FB0CLuKpDH zbQ;2L&trC1=R%c>K*DS(Is1p{7XEzj3Bm)98E(LLE+Yzd$PzOtqqzRB{Tm(r90(ee z&Pk|8_R5Fb5Byl@ii~hO`DOqt^`}ZRx4go*VX6nzivmH>%*yD@2E^_m;o$Z|_~1@Z zxi6U0R~L(bJ|jHVQ>AgAab0e=GD8M8Hc_H6_=g8)Zu_DcJqnc%X2rZto+>U>(pMiK?iS{s6uO*bpYgz|ce#nF4yYp*@ShHT$G zyT)pv?M}POYG+aPvCp>CaQ^=Oh7<<~N&}f5A`hr~158^mF5052KX|NkLh_*V$H}^f zj$dSD4q-GZ$1q2dGMqbExTmO7NdRY(u?@j%Cd74F!{g&e@U_Qou7qzKZWgX^O z3xAGjJKa~AxkYuV=3E8m%)8k7u&YVRCFRYkF#lQD; z{4FzlT)ji_Kn?0lZKss>NJCwHJPRoKcowvYLfrM+I*s?V9>4ts{}`AQl-$+XSzEam zk{#d^PdwC>=L^CsDr&~+pd{?VkZE1#K*w(7#=E|05JKCcLRX_^Sn;jnpcpdsP7^pH z%o|G#p7&bKTrC1qt;zk>j*gC?d)kQxdksB3%X4=5OTUo2oeenpk zzS~ukZy9_R-S3y=a*N$JeBUx%9#9OE5me*1)=8J|pkolE_J;kalyF@G;lMLN{9{5~ z_!^~5b-!Wf3E#oY(=J+zxT1oZ`O`;JCAXNq@)pXhAApW_JWQ+Ez`^ba9Ml?xwSN&c zn>VN5497O)S|wX=cWt=h6h>E2GRtF$cX>y2Gf^i=ok!jjgmx|4b5uAe=l#G{S*8kl zH~zNEf>#ETGOHU^n&6EW{VLijPQN@S#l^Q#6hXbn5pSn}EsooDqi8D{doEIw#-pHwc zOnFd__^GZVf_v8+OE@#J``m;|Ms`~ZwTd02IC$%oTobnN%nz=30f1+~5;;3L9j#UX zyIug`h_rP8O2cqv4-vPoo=(v2sF#ePkfZ8F({rHS!0j@`oT)1TEH36TCdOO2J15z^ z^>Io=>CooA__Cbb0*=r?X)pgD2@HePEYrclO^s|x0aYY>%-yteO(?Xgq2FnF8rhw# z(57V_)UaUA*x*vPo<-(CCQE;elk=Ma8p?`8%}SHUp8$hN?O49VR>%NJ6#Lr`$G=Vp zbyd;36PAqg5W*iA`Z-~rTa8D`ozEm*{KXfAaeqCeFOiS`DSiJv@bp@yl+wp$RNs=x z%4x?D5tmL!G~3DqCcXD%X5ftopM>x$AZ2y{#?VwjK*4iBtzSw2*nxc#5_T5cUo$|2Vq&ELr?PM13;Za$%uk$cO^YK(>1D4P>^(Qvz>y9Bg&4{CGT$HhNoYvs9iG!F+qc!81*g zVXrdK54M~j!vNb1&eO+81u$ps38hWKIe-Y3fXCFA!DFWYP%|{wICSN&mK!EL33^S<0G@$5LLRJX15x!Jjf}Np{!@Rbbr(tBvfy4%6@7Jk8)M- z`2|P=(5WUgNN}R8nc%!ALA()V3o`t5O;~@>!akF>#n^RYeDOub7Dm{`fviLE%tNkd zmKAk+LzJM8_TJp^r%sm0`W%MPDghwHnNb&o7_}KVt|n?74Cb>S4;MbBT^?z2pP1PNNS0wkZa9;I8uxf#r}|-Cao*Vsrj|x%W>L+rgEI|5mYR_G z_`L&d?qts29HHr-23G&#P}~a>bi@%&rdFR2>Cgdgao-tp)Ph%yx{Nvt4`fX*00S5; zK&^0H#mU8z)(US~LPrn2F~-%|8NGD7p(hK(_@qNCe5evUrtC1koRq6c<#&y^CvDn; zbt?haI$!Msf00^(rr<=!^=l$GA-7ag>o14?0*8lbkpJq=UYai=N_1D5$oMvGq(u;1 ze}WsBQjk{tsTn>qi7%;DXU3Nzf05hK8)A$QP=LC_0Qdo+t2uma@jPCfT6rGB}%g1adx-SU;9fwCmuI&c)7 z%$Db@emyj)w6!D0m*|bJ+3n=!7JRSTs|nLs3a4rd>zj$2-dJACa5IWIA>2MV@6zr$ z8O{iBDKNF-gfT#YvY{Lu)7a3!iyYeRjjjEZCT_91qlb>9kG&me8&7Kl631KSOGPeukE2_!n2QH^baFcJQtxMZTVy6M$L4}{w!f516yj2-H>>OPQ|XI@f-q5uV0%HM-KYdayoWZ~6IQan7rCQ%Ll@d)PI98>47 ztVUt}HmTz$78Vwc3wl(gUg5p_xc6*0R4L*xGAnxp;idK-9(pxfa!a;pz1Z%xYpgs| z^h#C4-9Gj7saf@O)x;NanCv!!BfKA_riLClj=ClubOHx1LsCM1PMm^j%B|4Q&?H|Z z_3-e_`25IS_lj9N;vH|&A=~=PwrRdd)tx)jeCY;>H6Ccguv2S{b~-s1m8j9eHNZEn{TDFi$h^ZPv$z7L(J4X zq!bj}onVw2;Om0K>iXO!d{#=*`SAYG;_B3DS;~u_%rN&pR{J8Dm)e-Z98c*hkW`i|B9i7%cKc*moZ)-Z z>z)u=0-8kIXxd7opUvrE+(7>;)Uod#K46L<47=#L@<Im>iSXx+CT*?CKJEmoPV? z`g`p(>tM}KffE$vTIeW050l(eMWxLVS=a6-&m>CV{%DC*gF#tj8?i-I^z)A^ zo7SZl+v10xJ^Nuo#YJl&#{W%5LubsoG+P^++7m(9+wr2Ar2P4Ei`^4c6XAZi&RhEu zK217;M>Lg>N^p z!S?Jlsf*`;bNTS(E(^fv;br;exrJ;PP}oOEous{1Nrcl>}g%xCK=c zE*^(yo!Am3W_#Li6k2p+CNuEv!$f5-E)&2Zv^=Lp77L!nI2jeOvWR3^cd^4lONl&W z(KyAB6a;@ZgzI$*HY;^;P68596gSc9iRCRaGIp#L=g24dJI{oBViri5pd$p4vF+{* z;ikc2!%v#lm3Zu7IZ|A))UXGVo-Z?gIu3Qet=55M%T)lZvH>q?=ISJcg3F0I-$pfB z_`VA23ZC)o($L3^|E&SKY^r9Xvf~r$B!DJikT`h+$m9zCxRjf^rSLD)RiS^5C{+!e zRyY#M(&+%hSaxVe4f}rZ-p(%}-fRD4V5{i%D32KDnjtznOxe8A@4!Hend$d$rOCfH z0)F*y9yvrbCA34Ud8-I!lwRoBm=J!yPY@E%2;XHL{$mLu?4nL`0Xob$&z=(Y z{Z6NmQh`112_9b7O+UURTHXd9K-evX5{GL`oP4z{nHvB8sN5RESbk3`THvmm{~s9v z;AxW8Q6 zX=gS{ZNp^B?bAGL$g&{7dk9_7A!K56C&Xy=e&Q;X55;~~e>c)-8X-QUdF}7On-4}{ z;01e%{@TvSN+b~i1v}*j&Vl>XDq*>dsU^72zkGQY5x6_+09yOt|U5G7y@Im6-G%PK~Yv$$)SUHVT@) zawLhaylW?)n+-4G>5mDFx%9q*wqd%;By=|I=1X#c`Op&#cQ?W;|4wxvtTTRJ?T6pe z9}Crq?`-%D`Uf&i!mCac&ZXGx3R|`NwoBQREjEl#?ZVZegVmNiwUkysRDd7D9yJ=V zc|urx{ra1b5Qiqnn=ptKXxS>HoCCzPu(KEzdHC31v!ZihN_qj)>!o-u{iomi6kfg8 zSqm6K>a}T^LBW?4)3Xwk8`8F)L!)g2DK43V5i_fEu3)il0oV9dh5CxWMT4DI-|`F8 z#o=(K!r46iZh#OsAt6hGb9`_Nci{p#^pPG3&pw{~&q-j@^7l}!!9NQOTS`oQpf>| zoyEn}brP}$5tE6*Kd!AUl7y1by_}UQqOdpxkHqns!Y>!8AIa(N-~TE|DzF5$WZ}}d z;bi^n$s{Pi=_*|l4xz#amY(>#o;Z-sVv77@*TbrR+6I3PhQK6R+V+8l`4fu&*@N0>D zDYknz%G89;i5!(VU!~Te#T$qi?{(pK`w`v|_p?n00o2+HAZStDUfz$cZ>*bvsFzO#V$EY;=CP8Rg}bwcI^7|N77J30yv zBzo0hdTeQ_cq0#)_R)O|BErURbPPnk(66@+x&09UH zTpMvF%|aVP88_dI8nV9Ok-TzdbaVO;FYLs4vKD2dI=xnSa+_A*Ahx&8fNS1&klM*v z!{$729B(Tu+|9i-%-!!im`;>T? z%180~FRJxCc5Q_2h<%g9ug4m?2$#Dwl#tL`0EgYuODWS4#im!wGWKN_!hZJq=fejP zK&YguK@?eATgxZ|KR=BrP;DC9FeXnf0V=9pm6_zKgLSG};a|JW^Ziak*}=65-%#k| zlyw}Q6XWu2x{M%_*TdCy#^qp@dqJp1q%|3ZFN6AeGTwdcvLh;EWfPH%kDW*##{Hxj zJ?qq)OT3OQ4Slpk8)Ts8r$$^$&-q{Br{=n&HHBXqni3gTB0T*h_bD6vit3>Ua>l*- zRhO4#rywLX9z-RKniKt&(}{tI)+Og9IO#Fv-pUs|7&D3j5ysoQRnB`ww=3j2CKZq< zd`q`AVL`{m2h2;$1c~Fpvpn{$Fx>~;(;BmkZq$k4zW#-#&{=qXOVQ;M%btR$$1uHm zSmwK!{j??XG$ZewPx{y8Js)v>zkXV~(OlD8dDRP|aqyn08lzG0J~9Ai>#SGzdGRll zhka|e>12UUM`b4bWo0k|?m94(3i|#~%C#C7k*hjCfS+_M^>@31ja)uX8J4Bp23)-p z+gW!Tu0dhJDCS4jVgp-p_ZsuSf)@m7x7BD>Fx@K%8S-X8fbTapp2-2?*ju?jrlWA* zlvlOJ>@h2yOY$CN!xK4Q>`yl8xejeCF?Rs4k0dm7;F@i30~EuU+bBR8>KuV6^k;Dw zF=?y-wDFB;zzz*(q^G{wi(`b*3wENxpckD!)5dD(v?h1;CAhfyMszcx!u^|2vZBNH zTbQ1vNZ+@)?ltm{L|O($ z;J#QTX(vI^NC*Y&S~Eh5{vP+X&?ib$2wHL)F3zl;wxJUvb0u8>g7BBBEsZ)Bo4%qB6j5MkjLAioNmo52b!X zf2k__c}ai5+R}FjJMaU{lwz7u#$ZD?1Rc~r-ay8OHo2BPewr^7#war!Oe*%Cr$;kp za8JvT{DzXTd?J`)H-I+=B!lCXbILD=EOMAx`YEu^H)}Cz`we8zU>D#$%|x(aM4O8r zCfhy4lR%*m?}HvHeaVm7kM4!aqfy3UtwrNjc!`}yN$wbJAH={=>Q z`X63S=TECDK>?actH0~;mBJZ<=ehk?#%mYoxe!MoDa(B4FDFVLl7);({Ig4 z<@_@-U+}g6x!=c(--MCtiNWc3s5n~%q29~~RHI&yN>xGtxr>K?+T~rzR`qJ57<(n3 z;h{w@7o1LVG%K`bB|xC-Z;jUHI24# z|G;=}d3)sUe!q_X?~G(nqBJpfxVEM8m<(1vx3+7fA*ma><=^_VswOTNLjSt_n2D^E zSaS*{8}X_l61>GUvH`ynxNhc#KvL)G07gw*ak3X~U~tej@MHx9UVdVK-aA^nDw>S9 zpbEM7?rn~QGTusOYq?fP`35;dT3z?4$*%?;3^&6VawJfLw1qxdfUwl3fcC9&47H$Q z(uvw3sEt)37xNSK1hP5~%IeF4@$p?HGI+zI9`LT?%$X~dg{p{4zr#PWEVTb$W6m>U z%xLyrE7-MFf|msi@3mPVOW-yn(KFpgAmygpzaOx94>x(%=X?K*MOC+fBSNw~iS)&e znTG$z-gn0}dG37&Im&TCtqhe_S5Xm=s>lvX)mo~cAjqy*L_k0`VTG0|3JPvi2m!4| zwt(yrEh3wM>=|VR*^mTCLX!7)CoEfgo}TBt@B7d5@agB%(*wzU-Pd*f*7y4x1ltZ5 zA3M9Fbmedvw^7%3Nbzlmvu4|n)Y%lP$49do*#UIU$6sj2Re`xMaYK@K2DKtHGxy7d zU1m*W51#Zolhi!pYE9`TUGCr@SERT2OXy5upEAN6?KC@rl*tQJ67i+TNN1S$;pmY0 z$XLsXRS+R>Db{G@(zZ<>;6T?M^Twl;q2GT$^a%8XhW8HTK-xx1 z7xvwrYIv@JE!dv z`HpGiN=iPhmAiH~xXSGQoxj=scdF%YRXi!b=;roK*rrhLAeD&q-U|01$DvHm*(9&B zr#~s#_kDL!!(l?Aknh;QL3$>V2)CP;2!}Q#P;eb59+YadLkF8EU+*G7*by?3dyf2N z%Ux*do^OTRm*E$Un?BB)5c|DaOZ z0T081?mg3LdR76sL6B>Z`qt~71e9qU_e+Xu((83yQO|PEr*`z0h-2A5m=+u`SQYqIv9XqbpwkI_4UR0!aM z{_AnvPw-U z6k&w)v;p8)$=+I?jLPK|7LIn(I)765oP8g7> z$1GEtagW8m8psul&Nnw1OZ>9^#`N|=^SA8lnGNkHUy`2DH*F4(ulEAS8|R2-i`KEu zHXO|#huI6)pWu#hzuM;3sHfTMN=wKT3H;8DHC%h(y~zfx>XXk>-Fw1h&0x56pEzCJ z^h@)TFm$4~vy%Rdoab42?wMboD{Ytfpj7DOfGtur?D#NQ4m~{UUX9(g-h!MEsXp1V zy$@1`wGEW@_hH>^5BdeNnRK2`Ut7Z7hjfGC)w?WYKmP4f7aBE(@$|PF)^+Pu_U^sY zBp)HH>8j_tgJ?OlBSI$KBKT2`_K1N|8q#y6jIe2>?RaTqUHRwv$-K%Z!KN5O-V{hnhCpbF_RWPqhiU;zt!T*REc_$U4MZX&b+YOnf|7m?3Q!x%)Zzx z8Ld|3Ln+!_CxWNd-UJ<1cg|(g4Bt(ZAS9O%WmN3GLuNw2ciB-Y&%y?u*jdhg50GiW zuQtu;V$(;Xyq*s1wzCi3)lNH=t!D6%Lm;H*P;&7ZFm-clwpCxpoS4GUOR{Y z?vqRyL71=>p0asmE?tGRUq{co=lY=-m3@^R9UZ4|CeYdu(m0{@5qM_r6qR$KEdN-R zBMk8Q%G}aYp^2b%)!y&%E`a)RT9^8N=;(W?T6E*PKV+9dEEFTS)NR`4lz80Q z1VGI(5*Yaj!tN5^!l$gwVJvkavEQ(#x2OwiC&-kt;yc|7f9qlG)E2dmIfaZi>3QG% z9myow&gaT$0qVtSA^=Ui(AAZ;;E!Qb);v4;p_0hyET2AJu9eVnlkx)Vo z_mNI^QS9oASKB2hyjc*9awQ;Cw6Ul zS#k)Yc*TI740P&Kd<)}Epb2Sn!Rae8-@K1W&anpjeLhY5(Q0H>&kx>1rm{Y<_1$uG z^L&2Sc97aCjQ*|mFOcp#h3)%BPL8HniF{NjYrAe(Kz=c}e-cKXf>xFiN%5vz$UJIt zEH!I%%n!6gYO0wj?qkVc<-Z;{b@*O1{=ml zLWYH|Oj4WXdidD?+XUbB?;w~rEYPr*+%?5E&ws?MR%r!8O_2-2p#rkBRD% zGIQ(sH4a+l{HgXrFqfUz_fb055ErhC=*HZ6+~L2|TF7G(Vl=7t6{BuKrWaK`*|{Vk|9?sE#mdupDGNmR14G?ULmu zyR_!9K;EhNHT{nav$}MgOJ>gs((2_w4GVUq(D##DTFzKl6!v(-;DGeE$x|M)uWL#lReHS~{3VC|obUQRM-g3y83jTGme8h_^=7`&=x!Lm z`R~@F>Ns2W0&?oS>MoLWn|JTtJxE2`t>u2?SOXNF-MEqaV~$owACmM26JekgC9g^D z6#EBUjJF$WKdD|rN5n0kmsXGaTw49#uiQk$1SGOUqNM?dVPi9i9%w`NlbBu2Z@HDf zf7ka{b(@eDT*H9*0$tT0NNyNj5B|I|>jddq)QzIKZfj?&v2KWnW}ihg;Jk!FsdF<* z0cWMVB|C;<&qJkenu}0rfux;%a63#bgG(RcaGuqWEdS_$H1=DhZ%p$rG_u-S3G)>+ zp=hQ8@6B%${NL5BH@zQ0V~iR|*Nanw_B|t`qbkWzW>yti6CK~^V5(lgR(d#}ql=WD zOcn^uHzq#DFMZ>;P~`r*?In8O9WDa!3Fh`ZaYk?=8#Z|5`FQB#2CKGnQ` zQFL^&3<4`<6_tLC?cRgq5X+dI;2nw2X|p$oA5ea3Mci1j5(M(A5JKL<@{w3qpK`e8uvZnpoif|MU$O6KA; z=c22=G}#RmBy;{5YCQeq%Kxp_%pG7eB*1ekfRY%$n0duw%>IF5)e3!cp;Ucd&VOH! zb7*~1{%AIP=me$CM0R%)!7y`m$=roMYh-J1(!$|V`$gJQZ ze0)8X7tp~L7FPdf@g89dfH)guWxYi_AO-JT9#X#1=A*|rJ>=sWKP@)3SdI5U#yjOGWpZI%l}IzuDH6nsVO~$ zvVOn@re_J}BJ#qYjKm*P{#Vm_<}TrXqhY6W5p0`>Iabbjq^qOR_Io zIs~q9bLgBjiutg54)t;2D}mOZF3U)L^`qOXQHDP%OvvNME(KpwYwMd<^RJ6M-hLcC z-hRjD>pQ=$*QkG2y{9!y;bB(BIgL%;(?3KsXt9I0Y(FWw{nWO@w;CTAyXVt0{Qf~c zI;-hF`MhkGSlH>3U4!)BgAX;b7$@}`skBJZnNgQEyA;&%)IJ5#i0W0fXokE?A-3;G z*G;Fc?CqG_a+uqMvsLFbHQmqd4BP?um)=}x66?ZL7NkKwg&kHm;Wi+oBg{CP6YkF`B1+E*b}M801Hz#Q|F);oIae4ss?z&zdL2LrZg>bQkSfUCUTq z+}75HowzaGtz8wh_oX}8xcrVL{Ik}C^SY6apS_ozVomHa2nv_2STzS-Xf;MG1G6(! zOpfjyp+u~zRVqBGp&0a1 z*hI@?ROf5YNFn|krchSZ(#*OJO|%#U)ohFf|9heloi`pyoH*#}=#1$OFfZu(T7Pnz z{^Y)I873#J+0c>D4;sBjV1Fn<$BWMCDdscT2>QfR@Dm1bD1&`3ae^erKf#6`;Nu*!awo(jOHT0 z!vc?DcDclzUp~-UsfRs3%W|Ygl_cjrr3c6(J4rZ8;&z*m14eEjopv1r)ZhNF`~oj* z46+(B6kr||n$F&VN$9r~$lIK{X?C`^{LbMpj4TA8lNUyaF1HDm)Jl2D%$~g@{hFOR zBF|=r{4}!^bwac(r@!L8>o$GMDk6vZc-cO!(_M#5gTnKNIBXXDJ8B#-0WgiEB44jT z_PqiHJ%v$o%uQrXAF7)N4`90^$b0 za;MZ-Le;2DSaW*<w>i1dT$))8lYhA$K19M@O_1>Ee*HK;{r7=5;;cXB;^?< z`bs-=>J34_^t+2ftv95jaNg&{V^ggPnG|a^YN}Gl1!~b+=pzc z^pSwXm@5mbs)kij@=W-0RbJ0=Uw*+?!6mLBa?<-sPH8$S06PD|ctkMR&?dpq1;-_` zJNIhkk$7@gUjMqEI5W};jXC|t1{)KBAqP-%<6Bh>m&2ZvbMyRmIdAJ?^L?#?w0&t8 zl8xm#M_wk=$v1loYw(y44H>BgrW)FY1zlOqJ!{Tc)d;dX+)0@k0rxbultEEk0!5Kt z^)ds+UQLev_&!e}HG6)g+PsyHJ^sSmsKW&Ao`yo8T@H+d?m*)PMw_rmU@!zU^)W`i{I{4~ZlGe1v zep2=KlMM%pUUE)$Sb|1LoR#zsTjn9uY$?OPg?TaZI`u*riIQ_2My`&1V{5Wq$Xy*B z*YhX%at!tK~$aKaL4n9b*mF+ZTvR={!v%bE0k0|H2W7-^H zH)XYy6A^tZGCnc$0wbWF(qomH&)c3mAbQ+3?^F;R$39EZ1EEl8kEa8ax_)u=K%3zzpehI^>?bZ39BP zRCVJMTSiZg`u%0Ry{@$k*rj8_HNJ~g-&JmirlzAhZ<z2-RLeD=i4rOAoLKY0W8Lw5f zan(ase91;U4Qs8!Sk!UZy9Z8nn7DeEq^_NYyWvhb(c$SjRwDi2jt-1jvVbg;Sr`{n zgJV$$WHvdFk&I{vE>_|oPcPe}8AB2&T!u+af&U~9KxGJ;p=CW(mq5$1Tr|GGTh$AD7x7EcDOxj6jA+LmbDykG-Y(Gz@ z9hmXCm;ryEJ9?TgNs}+R76OkrWs*B(;Q#MFAusoHxOtlTN?J*n1b{h!Ym!x2UDmS| zB7vjLU7ThK=a=qioEh*eL~j}vj)))~zk=n(Gu=X8N z!uA9=D_M|OSq=RGbLTv08F)T$B$YjN8O=ICoaQoQNpByBZ#B=tpGyi`H-^xasn#Uf zH)-e8*zV%7R6AGUIJJ3M_MFq{IHJOK%%FYDUY&@T2b~nx-v#=|3a713{xn(!ZwASj z&97M%x~ zINmOkUf+YzXo(XwJBV2HXxpgYMgPO>!RQ`4;otZ#Njt*&|w@VqG;lV%Wg$ZR5|7Mn63k5h8b{X+P*f%;1J%!UdOf+pro5!Q=2V$vVANj zFA6)7Zz2k}andU^AFg7JFb${S-8~g%y%`!ZVPHj9glW)8HP@Y@J@Y;|dKI(N2|fEk zgh)T?!tEiWSrLI_*Gp{D*8KkE)>FHc)%!MxMVJPJuiM>DQhruaX6%HfM7*E5<_|Uc zGt)+J1=W6ZX78BF*uZ*c z<&%%GvP!ywQb{(NZM(E6=S%~%!7UyhzNpK>KrVY*V2$kSJ{n2QsK4x??hgJbXuTsY z^YGfA*T}dT5>9mx04rU2TeIAd#pt_tBPYKK%yb2@)Xp#dF!;vUPQF_RS4#eX;J$$S z-bR|*322vUL22S4BaK>w5ggEgd>=?U=`*SYi3dGg`L)OWxD1;I`Y7S=)xPMvGpuEj zNKy_jxd1NG7hBEMrrl@1LYxw;ZV8FZnjVWBp%{ceRJ%B5pEUv$bV8u#Kg32DT>*6u zFR5J3{k`DrD007)jSy)EKV2o&kMDHD1-Ol+(|%dDk8M;KpQRocpe^Xq$7P(!7aXsF4gbC z!J33`HwvuhZCX&*M{fc3;kFO|oNNf0Jt@HKD+N;(+*1~;dD?yXfIuYndPHf+2sq~& z&4u63UCk-bp!Hac^<{sV1LmA9uHZqZ!?vA(NCauip2S8f_npLX~BwPVwMK3+DE93v4M zA){rM*ckfkZPrx2G;GK{H1+p*J8Mjam;W=LLZ{TyTXL9P$SO@Zr#WZu{DnGK`vPO# zw^lp>)SYKH%#(0E@YY4tHSBHmL&Jm6z||t(%L(S#Lr4HA$1!BLkMEui>qaUrqnRi( zFNV49e6uI>#r8xJ1TxCueQ!v%EVZ|J>1?TU?~NIztc|=)e2=1?gM{R|Iyo;@@M7yV z?Sf>ql=DeFzXn(9p#}ed@YKyPH91-Oe}PiS;zXOeVD<_gUSYfirK355T~$=XzAg=A2EOO=7R% zZT+PmnJ0r}Hg3e&ggo&nJRakF*G|B&w2OG4D&Ff;S62-GH;X9(rrn+r-(Q+YJK3Cz5CF+s6g7=l7dTi$_^{?SJH{+RLu0 zT;`!`wSNYai7IUF5zUuYa|6%uvram(_Ai`tq2~pqlggucH*dUh+cl8BLYjE~4KDil zfVuf(O3}(as7X7=t8u)&Jbm44qG$h+7aK~uLoOQQ&-pvfoRmz^-NIL$>;_Ps9OZa( zoCsz>HB~$|5mU5#t&f$0&KRAybZ6-p_no}4%-=$kJn zoo%zjvDOuP|M)W$ZVcI|FNJo#Q}9ziag)G92kv1B*p?%(5=^JwoR`{gZ#I!2 zAsVZ82}8I%NX-$<*!qBY{@3)C(&=j~^VaS`g>JUbr%9zxN2ARvWm7eLa zpYP4tuJ`NN#8WfhwJP~HTwkH8+NX0j_>{7l({zlk@P)n^V_{c@6mP47g5O1KjD?&Q ze9MO&pCAv+hZ326ikQ({s6*>-!;qI~J5Ic|jI0V?AWvlang!3G#N*)k0(TEsl~EWE z4)i`*_2GWHVa{o#e{A@wQF+(ht!LDp_1&3Nzq_Y7QY9-EYwi04 z>;Y*kO1&nm-|Yb6=tGsq+EP*^IL=>Ln{juHDlQ-R`5yKKSTc}wX$x;2&Ib^SZwjjV zRYkkfU8PF7h)tKyj?(HfzQoD3d|5OqGPW<=<=t-?_zL|U@e00J$N|U~W zw2W5fNNMXR@_50JbSZF6ht`shpYN4bJN0e*37q=={rkltV25uNOn3RgK%^4aY)>!k z$@7fg9Rg@?l6bytJKwj>3HK`;oxio6vySA#$EfPBDx>y@-CD7EPfO@J2fYmbDuQ0u z5tezhHeP7@aC3UE((2l^n8x=MXq9`I%_zIYmXa$sG@1Mq4($o}D>qDc^Vr)2o8_g-}fFAR3~X#p}f9kcCz9~hvoSonKKNN zSs#C!KMQ}c{Fr`_fYEhB{%NfVE)tI|w#t{DZ0IbALrJS^)Vu~~l9@}1aYSt3;7N#D z-cOD(Ct6N?R(|K$vmk;o5s(-C&hW1Q&_xbCFbTd*wdQ9Eg!!-oh8aA3OCom}EvWK) z3(YK32+%F2ckv>9IZPWiWq}6KtX>Q$A8l%H8}r(R88qfpttP|-^i=~i1u+yMKVRPaDzKzqqsGb+N&5pIEUXGNo? zN*5-2*C$9;`j--a1?A5tbon^Y|76C#Wi&K2AgK3NX;TY}-4X5v6zt5Ww=wBW$+@9r z9xe5rBJ=mXWOgW3Y1iU5By+@KGZI}5q}O3~%z5zd40^4Z?;=AL-H(DU2^EyCWrP$* zT3fYV&97Vo)Pub1#LOE&hPiqCg8{KNc3#0J5m2c2_D#+3NXKkl2&fK-#_HOYs*TT@ zlbOay1dXg$^F(|#Ty8^MLPH`XG9-n`+rz%J(EmkCTEia{d~>5sX;tH`d-fGfRu$DeMB!n1<(fS%#w}w?a#_2 zk9-G|!0bbb6I!f_DBw3hm-uOc>|kd?uxC8*5mJnIkwq_aa#~tldo4--@jaFLkt0c* zkmM;60MEZcKd0UbsRAcyRc-KY*x?qN6$9EGa&CO!%*$<#q~Yx^pTshk`0e``ul`S2 zENlOX5(ql(Y-vje=+RJu`jj5gJ$efC2TvOQ7}(DjWyhRn@6d_3eq9s934vyoAh2tV zti)r9>=74i@`@52Fd(@EVXI*zzf2V z%se3y#%Q*-Hd-KaW6ap{I(8;KvFckU4f-3GdF&@eJ{2H=?Mp{VGZ{qy6+isXE^LW} zbrnP;MU(dei(HPyY;r?FGvsv%;8+xl@<~p(`QLLI>sK#*TQah6=c6|XioByi8wUwX zOHp1?;gBgYeu^5kE(H@u$X(gr$0Yn;Q=N8SOg39%wN}?26jGP=nHQ^k@mMaAOq`7@ znz9mVE<~Jl{&r41{6r5zn69qQ1Vei)#`h6rO)a?T)0pTz|HNbpvhSt(+XAcy9+;f0 zM0w4u2AOd}qcrt4p$QDDrGW2E+wF=n-U>S0I-xM`2R%F1C43p5j%+I@&I(1wpp}ys z?Enr!hm=N#fT3TE5Zea9@6!Wt?9ADscymTOOksZ+Grc)Hqj~xsL7ef9dDPV#D8?kv zVm&F#2Qnm5*}bU+jY|nwEZbX=(};CFv8XN7>3`)o>@#4L-;oOwr)t9(%F;hmsvvb| z6m-Z7pf-d`M*~07|KKiAu#U`TqPy$4b6c&J=+P)`vDnI#BN@UW1$c~UkaJn$3N)5Y zZ$=&`TB?4Psvq(V0P8?EQ)hdlm(hN#0K=jpufu&fF=lPibyY9-liP01Z1a;VIzUWI za~*0@SR(xOJj6vfVe1wVTL>0RsQ#u1OMBmtZ~|(hOU@PT)>4M&9{Mw;ATZ*s0UYX5pnUQx{YHe7L|#C0RW0O|n+C-c7SPrcXU|);Hq>~g&cplxJjQW? z98(1JN1+umC}q)Dzx;?1U=GwhfxZLzo1UuVOM|!i*ItO}HTl)Gz!8v^d03PJ>APDA z{pbwMn`~Yq9~I-%34HFHZURz3pHpE@*2sn?+jJ51>>l{sXeWHSHBeZsZ9dCIN_!4p z&Tu{oM8I|u`0@Hxqf}LJD|S*ZH|8y)eFdh~G>9`xCC$-RyLD1iQ=y>`H+Zay)92!U zGcvQGmHibzBVuqjdLsDg6XL`az}mnYYR`@rN1!=yw52z}4H>*3GUugSn&D#(%-ZF* zvhnC$Iz-x$k(nRxVGSl8uHKL^DyK+Q1giA)~S zUTHS?KJcax-y#W5a>t)$7}_bG7eLT4_yKyb$a~D{I;C$-ZDXCx+{53Gf8@DHzXdyo zXwnwFcrf-2yRFY81IB(Dtdp&>qNe}MIF*FPj=w)B9_!MXmkCw#d3nA-!eJ-+hq=Jk z6>?d8AM9An)LkO;Xe2k4OACP>%K*#(=e>h>Uf`uKdAh+MFQ=hl-O5R$YF_vcAp1)K z;#QB$R8jA^gSp+ANc!-hI0Vg^h{!+%z|rYzGkO6cqx-^n4)IAXE(5K~O3tWc70CWF z$2Dd?Ol@@Gxvv2;o=@&T1rfgIB21JsDA&9g6Ih$3_5Bsw(0)_H zx4L{FTANfj6-6<;O~5UL`DI|j(goS?UkCe5j|MP55@bPCLu3PUATa_^MIf7qj4lS6 zTk){9FN&2b3xMmKcZ+rHW)lz4yJlx+ySuxg!zxb#jFYOD(I|MV%oE@1BYg(=Ihp{4 z62?QQpsUdt4pD(KB+3ZmqzP!Aiu~P81ZHaYYdrI+A$-rXeXk>vbJ9`lRy%xWzV{d) zGH~Fo%OT|@4OkjDB4B9(hVo@+J5mcRxdT1nV<8L6swu@zcUxmdLLf$jvjQd)lBz40 z(FpiJU)XFR5gC6Dg97OaYsS=S7No_P4J2uey6ogqGfF^X^jFs+(H+alubaU`{t?#9 z-&Q$gw+>LfTmaBq*Y&IdA`T{;DJm+~kVw!d^aFOL(;N8cz~-?#^8pG|!bOQKi)B{< z-=_qlec&aa_W(b;16E3fcZAi2-71I{Q14S+kfj}qZllM6tdUIW=FedPazub!>x@UU zl)yO+P~{T#AgeUJUU{XXI79@^ou$HScNF?f*XyGTJ%^eWj~8k-0W^d9dk#8+NX0U$ zMXCg)`I^Qzk~jrq3UyMX%Xhj17;KnXSdf#G!%tI4w5ikp#FB_5Mssr2mu@64Rlx&| zi-5eDa(94D*JrRaPe9^L1)sy30dVzCXSt2H7^!+#YW% z(*!#%L}{AxKm)9fh=*a=>||R+(YOd%n$?f=;0NY5OhO5+2Ze^z+U52@ACs}pe2H^D z;;|WmIJcWZbIVk{%f~zI>qc&dXj4psWH2KZQSC^o&XRmA#e7%O+bl>6oMlk(Xn5Dw zZMDF~N8@m~m>5ovY{4`nv(P1o%+c1$1Cwr%Q@(gUy;csHPuw;a>zNEJ)zA7N^MjDA z{~kU?3o>O{=<5kXuLxMqOiu)w(R&AWvJ0+x21z^Y)-3EwB3QTH43jerQUvPT zaZ{ulK-r*~5lwRDOb$pIII3NKV{9Uq@njQCzi_5WDbR09gJL{6n2p76n_KZNEVtr@ zHQR*B{g_Img746eoroaK)|rpJ-D94GSF$SD&@&Et6LP?ANFH!wQuNX6muH!j4OMz- z1&ewKVU)By5B{={=Cw7Fhl!pMRmfFPTS>FS2Y3N)4F?rCr@JA~7!f8D6G$K zataCxU_?)9GZZbx;Mc)IpyBg@54EUu5K^c790SkundkIwl&muBI7+ka>pihlwVs&_*2N?5s%mrDl^y=1N=y zR0#=u5qc|a3&B6d7!MpIcA~ok!GI3oOv}Mi3i4(!_86 zOP0i^pjwjej(w6JuoU=u@m##W`;g4{s^Q=mBWUc9&j)Lqg+ z%Eekr)=wMNf5M9dop*a#^?L7-x^!mr`gvObei3+Q&zpxP)_d8p)VQVh+%}Mo&L1D) zAfL&X_Sn%EcN8NYd(=v!xqk`*Y{DXV`$hRAVCCQ&4`+}zsUvYl2V`@BA7N^`lkf|2 zZjgxv`7jwPrO#(q4d2|34k8#R3mf+uY_w^)J^>4Yq=^kDGnmjg_9bXLaO~g*@zn#f zKvUfxK~z(32dRxTx2#t@*g{s?Lc%a6fgjI-!k@YepaQUUm_WA^0=`%8vU6`5hH_>~ z(U2(s#vHsh*!wp7BC>84Bb$1`p;0BNqnZTHqpHe}Bs!icjR7>KdmI;yx=M+D~(rntHm?}8bB z{~DeO=S=-bz{6|w8`aW%1KgP03 z!SidPlmitN6iRgRAmIY`1iT+8OznL`0+-Wu_GV!KYYK7q$S^y~4u86x)HfhK&kCSk z89q)0nkF#ho5hqYH(vf#h>>Yrr5v#4V5R(Ejcm9-U4`bjRY;(qCP@SBn!d6yJw3eu z@f1w^!%E+6c~zgVK}g=_*D8U%M`|{pQ>}?Ig7(*+(|xtBG;KJSf!ro?zPJ7y{fk1y zCIHS-TYGPJxuNVNLZZsb>x2l0ZxsRCCl(uGV)|R9T%1{O5l8^ApmKQs+ZhK-#YijT zpsQe0c1KHk)`&VvtmJ)8*8L~8$Tqy)vFV&WM^hn@1e7!An6fE%Aj*nk=LczwFGi0e zCl97S#tGX(6eo}Ezidb5+C4IFFFbro*>I>B3g)jr-)t99>4UgS!z2US7ExS*Wv@F zOihE4uT_b2KQWNQj560wDYLQOVI`;;5b8QUaqGoJ&5#X;b=MG-pT8Y2!_n1xRilI5 zp9?q4i3CcYz=O=&xc-+ce_(t9-yDk(cAd{8)m2FJjALp_`j`d_i)7tBKCoNYPFCF( zlmjmGXSc)&DVu**ce(4*)vk0%`RNLm^}U$A@M0c_^fBYZH}4LHoRV2WEhFy0ePHh) zWZtDCyUeyU#ea=Rwq3ArE2&Zq(lBtN0<~A9_PYObZT?h@Zn3IV_Z)kLPz3-${!2+_ zez7CLE59+;uql?Roai@kW|w*Z%1BhVck02$h>vw#)Aa2}nx*V3)3T)ksSDq0h@?`! zAPC#uB&1OI5G10srslKGnS0{1MkkMH-e(t_I@!@~EXv$iC~5mGG$ABDe7>Iko5gcP25wp3VLI7AOHIx^%^7 zu@mMc`8*%2b^uY!| z%CZPf55q!|)Ad{+VV1@SxT7iE?QhS1l9Rs>QKL{nRs(a8g7DM7gcRm46bj`V_g|g= zJSTuc4dekGQXHdx_uyi*4tl?h1S!04I&Bw74mc_aUPh|-4kYQApYP9i1ebgn?q40r z(!X2Cyh-0;>Ojyn-Ts-F62gUhi_8-WRjV0a{_ca0JA)%@7P0 z@WlO$afT5Gu z4!uvQA$~5^(!X0EAS*+EivQQTdtRVWI%9K5M#AcM5$?X>-a?uYL_q{TS+n@p5%VZp z?%lsc*_Q4ZDAS`yj;Ie9ROl|rUIZDdo+ntAynqDc26F0Ndn)(EKZ;yFaHRk;!|e4D z%n0aHiX3IBc%%#=4n(}}#@_fLV3IAXso>G~#YFI(fl&`R*K zl|C`FOaE>GT$R85)Jy&D>Cez<;c$PJa1SU{VLd;cL1Vx`97*FenOrEP0I~Z9@WDl< z0)^6g#|I2_DW|#ukwlSqNFh={Ai&%qs&i=vpX?bgQR!o>?#`u!RR9OG^=3} zXP7iwMVggc^MG4ImE+(f0x5Fb_INCp$Sp37M7Q1IAt-w03@%fT$hEVY8M*TF+kdh0 zxwm?1&U=BdCO6481s%M)=ir85iXD~{$uYt9;W;jxAr~%o)m1#rT0rTIw~kGZs{-AtX*OQQ9oYTv5?LIpVZY| z;M3s0Hf&nprs2O{)fy~OD5xt}7RWL9<(_^2`^f)K8ynygtsTH@RG9efDs24R&-+U! zgS0iR0_crf&AX4STd+*1S0CO%7FwZ|tfZudTkm(809s4zw0yecM!bq^CM=^(PP%!y z7k{iLgxyU!wd9=N*BZhXFFjmUnrN(u$kIzBthIcgc9nk0Qn|k!%!H)3B z!9>>K&33l#}`+i z>mKg43k{HIo>+O;1&7bGN`;2Iwx`5|FgB6uMa7oWYcZETd9lKSN;)tL1Lg=z_^C7} zX-VbFYIr5JJYNfZHB0knsDREYr&PZj&_TPBp^@mHK5J50dgsm^x^Ll`w8oVw_oI3g zLdC>v=C)@c=cZo_H8d<0 zLMdZG%b;+Duz*KZ;TEaQmFLF+%DUwomYKV2IJ!;k?nv+X8y^Bz6pmUk4*Ih9t#?9(g1gW(qDQXn=+|yFX|7KvPL~g3S}@ zql%TK)vI0u5Sx3jMNOH?;eCOE@HZ+d_uGdx8wc%&)gwIPlN^^iX_wBdbr$fovDuRC zqJnjgkDkpr%j}f{C&>8=FY(xE?6NqV`#<~6LykCf>lc@Q^n;uY3a6i##2`Qd`a&GxtwFJY*mi3saXuaoP7q zKAbBJ-|rDy$%rdXAs8jKhvDR2aF==9TFm-@{W1`ZEq(jeCejPpV-1(E7pfKaVOpI@ zwiMj5t69I>43&x{PJ1t#u)^H*IrVM+wE*`FgKyhIjh1TZE6`WK73b~lo?+(Ebvi6q z!hASYzvKMQ+`|HS(Qla72zC8_OZ36`rjBJErWBa4DF0XsHfQtJj}P5hR>QC5~z z{fWXzT9J*?($caVuANd`8;XmNYVGLQ{kX6N9>bQ1O(ZDq-+%fyjc7F(5%JxUHw)sO z#)p=)bGdq&A7kG{v#tQE5A>UAh*6SrG2BRas&uGWwf+;c+rpnpiI721OmuYBmdTVs zx^Eh(C-Xgg^o)6uPX`Qak=m=W!^#B)mGAO$cJ}wzRB<$R?xL*xHAOVG=Y2_D@_J|0 zcIe_@)2Z@_Kqm_B&_SO}Bi&EeiB3=T_cc#akh2#q(H0x=h&7Z-ZlSn>N^qOz9h5F| zNo7m|BELAQS2C1b9!H8+yF=QlI&uU(zd*45Lli}=4apYuKpDh{Hofs7ccG}%1xF= z^i!M-27|G)&fTZ1tPJ~p(d?uXTB1(4FRA=&bM^@wPG?7DJ(v$KL-APiXn+m-K~*{% zhmM>hcf?wy+C5)t9nLmF(vS&EErHr9JQ$v;hkGXqtWqW9dFn#tQVX2ryG|oJ>+o~p z_UlLRI%98G_vH+}T@=c3j}7U|JXjSgqwuQIlVE6^HyVX5-pC(sg7@_inh82@G$V;E zh7%~Mq+;tJZLi@o>qeegrIxP9?OUJtZt-hhy;gs@e4w77Zr2RIA%!z4 zQ1k=ql^9z5+n}F4F2G*<`xiV{G5I#fu_$Bnk_WAMRBRC>3{?V$U+3nUSO;Xn>uD^0 z7$rD-QzEvWMx#N_Y+^*zg9oba{Z&YJ(she}v}Zgfbg4shN%emntN$_XW3vBj>j*km z&AedoLZE~nE%T7S(@ga4ZIHnB>vIw|Eh1{DHOrO{KtXLpX?Qf#MiKjg)#FfGXqeg@ zaZwGq@Qc#%3KU!NEVD5_9i??){{Uond_+9Itl#^>MOm`Zsv)~|LbeP(0d?g=2Gao= zc!}h#*#=L!KiUA;LGGGEYnhEE*425JGcY4?o?DYXEm$1Q%D z8S)N$Zi>d5+ZzYf^eOpcXM?LtZ0d{J0S>z2=lTAQ&Qgf49~b z>a;<~KX&%s->jnexKs>QDF};%#rcpy2@B#^N-peDP!sYP0t%w+^BoT-Fc+LXewR8NdH=Am#dCRz+1XpAc(SsDi;gu3sB zinVXKrb*tBb&>tLr?+QjLa}5h6z38EUh8*RHMF`&^1W2i#rJ`No$Pe{G7rVV#DgXp zIfol8oHtIjHi0uC0|qxdGpZ%F#UsSGFy>w#t~&{~ElkWj5nR8FrjA%MYeiyoLW_J& zTuZlWiTKg*H};}+SvH3&v%|-JYrVC2CkCKE#(2s)sOG7}{sE2zVi{cTD!{n9iKe)? zrh*LJ=uHV=&G*O4{MHf&2>a<5iZM=&;gW4FjE@N+4yxHL+9EBnXFAhSmH|VmRFw#R zaUSv(I*>G*{Vo|^pfmX(v2A*p$BB2EDk@&^x?9@B6Dw4xDU`j+%C{VK=~6bOSH5=L z(R5l=KC490)-adZ)M({K-v%4Kca4U=w&;+Vc&s5kxp@62-w!EJ>`IAnZWVsEakFJ0 zleT*8_I|cfXTrg0u;ykS{)y|iLALl{LtTE1PUaD*(3kKAwxGGc%T{pNpP>i-e37r0M7)*ab~t%!4>~l>}}wnWZGT>DB!+ft*h3{OR$GZpXp0 zpW)8Qcbz+W!w1@sQo&CXs}pYA`8e$P<1=-?{UTK%?$%;zBWza_U7ndAqnok{{GjTt zyu;Kb*EVIy$(Gtfa^}6omC-T7qFHm|v^D45uuBS=n==!xzW>|h1CvIu7hxAdTDE7e zJZy9_>B1>zVOwloYj)klM3`7LIgkFyq282CO>z0Rsyg{;N< z6Dtop(25nvlW3$EiHAp>4oq~b1n(5=n~`f$|0ds8huhL+r4mDLEOp~9oDj&n#}wT%R%rZj_@(afsXu>i7>b$jgYJW{Sk*VTwj$M2v>Y2x z>N1Zo@3EZN=%ovc`4S%V(mH6=4jzde!L4sFzc9!c>?{8q<1QKv)e;J$wHDPQDM zhC!oP*uWnJASRTsKm2RSptRO|hg?i^052>xM{eO#7-hV{Fvz(NnnDT2YZJ7AJafI; zDf|tzeHm^^v!RE}j3e%WP4=gRbWz$_fZTZC7KOWiDl+JHJ97Vq9}$B~iO@zVeLQvYLosl}`CzkuVv3#(?Q)9MO|G`hR2 z1^1=Tk_bm?2S}9zxyYk8(kh~_1&uo$+e6 z38CJ}pS07nxzS+(;ZoPOimtQ#Mp=2C_3+G0j@x`H1PbK={p;lQWIG)%pd%|$O|cp7 z58u9h8+x}G(xhr3om7H6d}}K~AFnvqh6)xNtB3fFCxdEiY3-3VQ8q(@nV@O*DQ45{ z23z|S^r`!@g*a>9BpWW+CxVlRPQ7dASwnM1Z%tZ|4^6Hp`xZ{nl$tSDGHef*Zgk#000I#a7W~u=+~Dmbw73R z@Q`$XT@{5+1w(_8s;`FtrDJFUlqq2jI`B__`|hBCdZc!9EQ}FJFW;o!-IthJ^hgPy zB)4FArtuOuc3>|Yq`D$Fw%MC#@TDrI;QSRt18^6)`M`zqZf=v{U zT&|riX_r#FeJsAkIRt_S(C2RiBBV9$Yk*BGbv4sB#!(EkE^0;q)~H(Z=FOX$&aL3? zZqK^t`u)?E?c@tX1v1iVXrE~Jw8JG&L~^HHz7iG_+D+b~Xc7IBMXHUbUYaSRuq1q< z31efqTZi(rd{5C!OSIoM*BVB(=*jh%-_u;X?mH#K=thzCg~$%Y(qfU?-Vvz>j1Q+b zM{G=x-Aj@aY5c)|1ha`zH1SijQb9tnKEL%9awkK8vz2GT_kthq(Te4PR^Ml5da9+j zJZDI~%D?ZJcy@2evj`2ib!ol_zy+>;lwKlk9)g2`Kwn-8c4&Qh@v3o&Rdu*5`INt3 ziC4b;%q9)iif37JgIznj3J>e48r!z}5oW&kE<7@_W2!ZedA8Z*tD=`zNHTJUNsg@1 zHdB4_=?rjd=IBVegaFTVc^qbvTeio%Q3Us-B$GKQLhFC0z}nRy)QF_bLn`!eoK zbBqn%X=2p1%BB;~vG9|0&%tBjVxN=Ydb-eGf`H=g$0w(QaHVJw;u}HA1}~Z#6&XmfD2I zjE{vA>BQNwBJ^*S`m;C2_V0U;pYD;i!crXPt@3Tgv5j6+zIp(Co7Vqu3n1Ai2-jhH zv7tcNe5B!R$gX!zC7}u$XnXp;L;mA9!w=z3r2c%zh};qrqvYEXCl70ob?7|@UYh9j zl{m}{PaOP4WbM-yqY)0kXvcR)_0d>w-Y<=2v59FdO|KT@;}Nl ztob@W;|EjYbLLg6qa=U5^5}fL=j&{G+bK^@+m^QDttY!o-&Si5x7DxhD>~auI^~5i z#}}u#mA;^sjra@pm69|4a1~CQR&|f~dp2&o9QItRM7x^UXb_mTcKzN+m$oE>7)SFC zzqM|x7p?xkPbTn}{Mb#J{DX7-_(VO;OD&L6TBW(KWADhUN$Zbz{9<@5jPHW}1idV} zH3NVDiU$MBt~sRZis9->Kohf8-!&SJPau>i$?F#**?2|(u@UCs;E(_~C(b43YL=Ki zm3pzWbgfg&U`lAGx`IxmEV1=EF|OduTFc%U)rZ+Tvb<*NLIWOQ6XPy6sfc=2j=Hp9 z#xgM_i51U0qr|#+OMNj^(Dqb(`lkyM%6moDlARdJ=0ul9ZS>9sk(bi;Qw-KVeP27T z*}%Gs^saNzeMkGlYBKOH$uh+$!`J+xYi}7q(g1P#zPv)+`L3UW zVbVT!{D=Y`Vz6IM_K`H6tqQZI&yX@pz<=2YMk-|~OjyY{~%(=6_^O*YNi zWz70a>P*vT*EDalm0+c4n&WI^UQ)avnv`NBkeR52Si7YKA9c(|%mkw>R1iZ2LZsSN zA}@GNLlh|uEk#{*6uj@l?rga;zwVFw2R!flJm)>{xqQFpIfvQxU$#{cVXNBbo-A1? zVmLc#4H)owgOevla82a3KUGkF8h`1)?mKvi7KFV8i4QB0=d@R>12Cu|PqZj0S73$7 z>4VY00r6_FQU-!jstI{D?A=$UV2%G3T64Qu%x0#qHbjySXqJlxW2%)p7|??fd$&vb z_U_Et>s9k$R@MS%5|>74^9{Nai>oCcM0j2w*UYa1$!<=08#8<-n1K~Ja3X180Ev!r z=y9q%{as`{55cRNRR*aZ_KI&&#tHx0-Y+>UuU15#TxqBehQ@h&!X@7$$Vq-KnX!~K zB`l>rwi|~_+Vr+c*3Y4-|K7^p8ufidKWbJm8pc08vTEediJR{YT#~`#7xb_C7ETYB z`@52AS|p#+D&l<*Z%=(MI$QK6-$f&4aCQDXw>XUelF_GLdGBH7>jqHR`@< zGdcDWW$LlH`Aq;v`W%J;>Os;t^aX(Bx1aS^W2^}{yl#54joV98w^*)8_fSY>&>{=4 zLhtu}px`doqw!gdEP3ST?aO7bObk1POeTv&0Hj2To0j+wP+l{*n77g$;@K!frM(#< z{zNq5n7E9A0dyYtcSHbs%bl28Eb; zZ9lsnF0Z?&E^jL4)%8MKR)^{k0z1s?U0<*95i+muQ*uD`(-AxVHYgaGOfCg^ zcP&Qt={o|=g#(W>?@JgW!cT_9mQO&=cF=! z!lxRa;-<#DNULu>SIeGuy9XqK85f62Jb6Uf6kvl%N86Kq+wf%`M}RFviinrBDA1$my;PtGR!j?wdmcGwalE@vlN zcTz@gjFWVu6Y?ilFh@mFVGVoqiI_29S{d-U6ow$se|)^~o}k)&YwuRwnN+jd&~7Z@ z4REd*s5Sv;VVQo+;MoyEeSzpGkmRh}bEIQjf%;^fLbvv#djs?VG;MHP8J=GWDXs?w zF(5O(a%)({KNzWX-@1xi^DdSW96b4i+Z3}L+aA|43KAk1YHS@q|3R|>^sw^^&t-f3 zTeSWq060BLi9?X~YHnOZswJVXrp>Ll?1#Yyv^Tw;%&gzjVp-n`fEhpJzTg^`0*$Dj z4{<#1VgpF5r}ti-cXSOP@e@@$X<&g=FcP1(czp1_3^!f-d zrT`Q&%v6zgrSkj?0RrG0QDbolZ}lEc&~oydBkDcoJexVWaAWtm@QFxm7o-1=*@5I| zDGcMB19tW8we1nh>pU$=LOTR0vVN#T)a;!bwA-2Vkw?XNra$+H5T4C6cM)Tu-uBmW(K$xUPoOg*atVI4z1)x}l27Xf9?T&jx+ za2DbNC%#yGZXW=NOU76aO$5;`4RgTEY?Z;1!(s~luHxqe%XGGsA~~4BUfp)B=j&=k zY2y?kqWxP4L@;wzm-w3qe3%tQM&AYQghTlXaHPzpevhPwBXs_IfVO4yVuv(fxEfau zpCZg(U@5AY?k)poFr$D@@r^>7iG{e{d>OuH((Xu8m~y~|&|*@U_9LDCQvZ5N-cUaM zT0S6=<9BmCs)x_jg>WzlM~5tS4csGU&4pcVrFEA*44gM{2>|$8m@yQmMNVcpUl>b# zr$wXA-1I`UCGnlkLpjpQ1X7oK+Ii8|mgg%Eu^+0kEbD5=l41VlMoCF~~QiE|Hw@ z!8Kn74PiFS#Q^FA^dI(1gnT5lFS>uSOF;wtsZ(E@si~>g`VVW`4{U08AAvxj)yozJ zJp1Fj?xMHfz0wMrPsA+F1EPQJnjZ{np37ulr~#-CIQHRTMv}GYveEzR+5Tr$d*4j4 c(ic{Z^S99KF$Z0h28sXK%l8=9mYFeXqiwt+N=FjT3=K$> zEIEUKgeJ!(!&ePD^Bm5c@BQ=sdavQSludWluBsL8b+1*mx8GBF$%{m{i3kV?E=oOl z{EUDA5=lUC{r=+_WZEi8@gT>4hzfQ@1*tLe9hZYMeJtCTK2W@-k(m1 zEjRTq(~9;5>RE(jZ@+bx(u+R-g52V?fQ0Cyn!HPtH;05`O*~Dg?_6kkXkkLE{e$E; zzZK^6bFY0LJW)OQ^E}&u@n>i(@&}}!H`uQMwE`eiMCFOIgPRwV&7o#5aUW8zN z|M643cL){C(5W~GvUZ>7%hq@Lk8kmREG(AHWn86~*TlGT8!nm{tvJu7raWUj+3tB1 zXp_`T(ZWKxIqK!bPja#Wi`^1tGr5@}$NA(pm1YsfD@E?xF9wKDel@h-1G7e5_{UBL zD<@lf$N&4;zcL^o_drl{IK^X7Gerc(qa7=Oj^x)Lk% zia9?)XJ0O9flz6?u6>amwvG+fpO>ypY_{m)OIIU4@?vtJ^Rl!RpG z78FE~gqupNzApC@0(7=MnXOX9w*nGtX>)gP?KS=-3v0F?eFgs);cGd zR+ehOdbadTJ@anvUp7pet3q`XT{sd%W!End3l3LGkw+b7DKZ{Lm#p<)b)`MkKRhg# zqJkI5%jhW@IPxXz>{F?&tBFkqW}CA7?i@AMt0BC#ZKmv}aoKa@!KU{qwr0Lrto7D5%H^1t z82gX#b}GdNEx6KXBJ|Djp_aIM~Yj#JTh=f!k0MV`KUlCFsr6?!eZ8 zp&?l}($AqlVUZ~3PQA;-bk>*+!G42vyAc1z}h&kPe}Sigg32yrR2dM z`C5&;Z-i90e!u8cL)mRR?1L^BI=kb26SFn}qt(jD;SzfdCN*X(mfJ>pP|obWg9J^N!+AvRjoQ2OX%@1 zaAX?_3CSyrX{UPEc5KH4B)>rgk0j-tm>jkHM-nCmAcYbZhNyqZYwgN)C-b$)0>)@> zWNK=vu1;bHm9rk=ymZUfhk39*L*Q{@1gr2cRM5;;nxz-}I(q!PwD0CO>e*=hV2SH8sJoG0M*i>mm4w%(ue#KTg$FMn#JbwXvbuV9-wY0oX{ZAu zF4)15&k*XZw_0m+Bw-c;58k-*9GiyCrN6+08!8>#($Zr8QHyg$5^|POO$I(-3C8X~ z;B|96gPsrK^a`=*PIaWFYWmaVSO1R!I+?xX3cQ#0mHz)ozJ=K5e@UK(VZSh_F;yw0 zW5lsV^E|Y#4Tzel%L>>4g6-UGc0Zbd;bBW=$Znz4K!3kqDE6UOZ-&<3$cTLJz(C{T z`wcOveB<#(wG2(EUi4!XH(Fl5!3{GF&9dGNu?E(Jhq=`4T9}>q$f>)5WZeS1yu6(m z(xW_%vPnF&LJ#yl=nk2GS3cj~T%e?PXc09C zsTMbUCeEygvj6xn@CpAyvWYyu>K|4@(Hy!JKF;9{kO=uegtnt)Dx}pnYB6ywfjUvPE6TMl z+1%2ywsuz=T`szVig#;mBOA#pK)#+rOibq$YK^WQo5ER;uAm6z>-->t{-GMQQj z3=a=0XIybZ>MG0RzId&i*YR#6F=}4l&W>{-rjw=TLUjMY0Key+Gyk_s`3qzo*CNfP z0^j?^2=LO3Odw6IQOgiZwT#+$6KAJO?KqqxlSe&8`v~f?WV?8(J?ieaPY;9=s!W&A z8JfkREeTPdR03B!{5L}L^&D3$yrkr#qNW}`&P>KEl(^-fc_B>ag~^3g%yOq`qggF` zL-Z_Pl|Nk<>q<)eEW^&H*ITRKr%8p3kZ+pG=_!*@7H*Y0ds|gqy)Kkh7*ogmSR{#) znKt*{4r{AMA1Sqjm$i@cmO(V5`*2>1KM$dRSv;SiZkYab<)&h^A0!CAwCIdzc2aZV zm{pGvl=i@x*Hl;S7$bXc9U#q_-2XHa6TZoB#kFYe(V_2BJ@o1Zmwu}cCPow?1qy6*IGZJt&)(zbQ2y@$ZR5r38i;lWACR4VadpF|j zk-qq{{({$!c-RMuYbpBXV#|dny~WiXXhJl6SsMEODa=`xA+Xg9lJ+V%;Wr9f?)*ib z)*4jA8RBjS<_lg(KceRPL6&Q^{0WxP)t4g*n2Axa+atMd<{c4mZqopag}>^xx~mZ; z1$WLcETFl3g{_b{$dhSh>4ex4Nx=oy2zi)6dg?RSRvAmo4=6qRwTZzp=fY2BgQD-G zugRpeFh)hhTc$@_rpB#gLn5Xe#(fJs86xFs%kR1Mb5eG^g!Jzw$Z?@9Z^_d7qdITb zAuTx9sxeP>vj>)g8y_>%xl%cp7nGDMOUXsB-Cm1q(KhC!P;#x2r__$~AYb9oIds9= zpc2)L$N7O_B@VQdwtdd~R!Qm;OoqbLc9;eP3Wrbnlod}2&?i4tzQ16mxH^E0N-(ao zToolNq)VH9|J*XC`?+a~+)B1q08DaUsaRgo0?Vswg3}c;gUgIE#Khqu8t7DXPa8>K zOI~qal@2`Uf7&>y=?|5> zG_@kN9aIP8K)FeDK-&I-G?O9}29t4v8C-rUqwkjE$St;H1|N%zFI8|gJ;P$S#u^Yg z_vC7r6uokUL_gd_o=K}gBN7JzYPjX}`SrXDbSow0h6cY1Q6}fr$>|iOC%yrwPAf#q znia9H0L-gVzzkc}QT9T8rey{F-lNP)SB z?;kac*dLG<;rV>L17ROVSwI<5E1TbFMUtrD%<014kLSi`wGl4~T%C+8$m`W;=hA62 zVs>rW=CJB)H1FVw7WZg6P7}!8|Du#ioD7pc8p80B|D7oJkGQGU#W%@STX9d-bD%5% z?fx2;R#sLjQ~HvL4cIHJQxouUZQE34wG5WB=Sr|GrLUp`qFQZ579Xwy{tY=3ZHQ$u z%5hD`us)0TvHvKZ8?~nR5W4mBn#mc<#l=O57~}4_nK12f$i``NsEsnn5R@b8dRvmN zGTkdTwJtqY)(yhjxu_oZqH%!G@e7WL3W!UEGH{L9$ReXRR7g?>H0#HEj}4#2ORKhB z5@}Q8W(sSyeseWVdz&iFVR$c$tn-hZqztLOw?bvMG4@7c^Rm8au#`9^hq>_{T~CTP zRbU-C!CKCn+6jtS4FueygH>LNUTq-b5?Y>?sl9`tKk#diq7@GI=Kk7P0HH6R`O@14 zo~x2d#jT<6+Pc|K$=gs0wKq+5sBy39X?U{qv7l@oFX&WhCs>0Q%P zVCBDi-Ry#n5^OEyW}|5JsAh{lx7#0GA!d2B>B|E|Zk!FiTrLMDUyZbsQ=!w^IRk%- z8fBZ9x2f8H>Gk}^ji4B>P54ZMy`MPJ<0fsV0%9hEkDvJxO>Ao_mqK7%=ZH^eYlyk3 z(-xKDAJ@@I7+&!kC_5|vm{b#)(?)d*B_46-;Zt#$GpLzmlZ`5ekBmEawI)?*Jt(J> zuOQOX#P$S#(6H8I+P<^5Xdl1I8ze-Hd>}H1guAtDe{#oE@RXV6lELR|Zk89hy@AyP zb&N#o)fu(*cC2C}eg@p=Ujes093GrkJ6wC9oDhm@jfusvg-Rr}*mHOqcE}$s#y( zatfBm*WyhqTRwF2WQ^V;oR0gl2+bDlZ4oIZo+ICk5$9kldjXTYsHrZhT9lEE0uLMGP@qgEYzB z3x`ihy6aj?dhm~Ewy5%6^sg!(CC(LrbU zc2)lTj^g3`okS;3)iA(#oB)I`mF&kH=~q$v4y}jq+%m(r_6L(xrv2yYj3xMO(x#>* zH6JW!C84`zruSy#VCrG;R|pSH?o6F$2L{GIsz)mHekBGu#`f-Rfy_T7n z`SpVDam*PEEWUG5BpkJ{JFHlJnnEuj2*z;ETmp!QXx zkmH5vW=|Ir#UmZ!w320HK57C%qRd}nqS+D;3x2!-6jJhsSblNV`sG!b47c(QzV@_MTdkMSuB(@gPC;HMI9%r938$U>ov@`7^tbM zqo!U5W;}6&)i8zos}j+xyQl>U_YHhX)nmqFPnjgq`Dt->_E7{Uk>yRaX>6-2yzGjCi4okQ&$+0 zFo=RT$wnqRPUP|of!7*;dmiEA&wY5?{fV1(zMc8A&|vSh0r%g#s+Lpcb1Y+q@=8mi zPwTPn*_F3Ej0q053^ZN}kPl z9c^DzgrgWQ??5rbsbeU*)ir?V8&zKc!A~O5B>Jqk`whj$x?)UtGF0QLxyJ#sNphem zpK4_9w!{XR!E2Gpu*rzqb1mH#4maoWxy9RL+kZ?wl&p@{c`Q?!@U7h4!q-CX=1Me& zK_}fcw%T8!hMh*z&6eyV&%=}5{KD5=*a7wz`1O(pFE;egSE`S8j6CRtr$F(I=Sp$fm4<9Lndp@r&~|LYJ<2GtOGunMnG>XDc@ua zKV8Xk@%rGvfV4O>@kBVXL0VL53ko@<@}j@MyF}J;68?y}ybWE34-Imia)_#U>qaJ} z7t)1O{NIMDJxViNCg0*R?#_KughV7WaFo%TgUHw0XqNp3`y(2FFH$LuBPZ{H<-o|f z_@zsmDty4?v-A3{Q6Pl8^)Vrh+%O914AmSHgUE#$T=U~x+x#8!41Bn9+e4Dgz0y6F zI~`Ju7TKiy#BJBSfIkq}d4h4W$*RT2#IY7HwEfwV%^Y^BL2B4li9NatP+H^RqOO^k zxbC|PmW5frMfsIjRTzoJWATVHB4fvBQu>@<6YG2t&NBIQK!BbsSn>A#%p_B&T#4l8 z2Z?5w#!Ou1&zhzXUBEHfw=rP7I9=Lvu1Ziia*9U4L-(UHzbf>0b$_4*_FNVt3(wUB zX%sVY^-JVs6F7AMZKPa16LIzJ8;u!d1q=@2b|zI-PceN_Bxw!kM4 z!77cgyc`zF)Ctn6%;imArS?WjU*0wVI1}=S>r9;=9_TvXRCl4+>EXGKX0h-rE-z$@ zBTa0w!VD0g!mOp;tj*Z`;O|iVWYi!pER5S_DmzfGO`iGW2TYnsASKlR&kP2NmZNp! z{fs8eHXdl=u>?XQo$P)GAscF6l(TwPtRYBLH#^yHO2rQlzOT_~)@j7`PX4h{XPFXt zi=&9BnMNsQMw-TU`daG>(Q(lpH-}ZquZ4_kAJrR%tB4Fb#v0#f73y%tKV6HW*ra{d zF^yTLs44L8&QVRm*dcirxToD1O*N#Vl0hb0xL4@~Ij&I6U;I@WqG2YcLWV3`)X}u~ z{%P=zbL|!+r-lgdvZ}8U<)=7kZKbj5C=LT#tYPkNw5Reou^*&imozvH%ymU--lD3z zsg^A3)Y;06?20DFL0*gOy2qg6>>aGv#b#!>3e8c0<7e6Eb>6RnT zLp_M%-jGZ>%%}`f@AG8#qQ$n|Zw@nDRG?SOiBh_P=4Xd35B_;~7iXsf@1;WZJ*EJ$ zq0W_R<5}MWIp}GKsvEq?2WvDzwDG|HCq(l$o)sJ8xDJVqvPaBCIIO!pbM3Lky%`j>Dk`{VyvGcksQ-J@F25W|dnZ zF66eq5Vr5rJ0^IoQ4Sw!+b12ep3k+%7+^ZT!5b0%h>se;cCH&3n1d{apNA!&`9p}X zrK80K4}21EC;yX_)7$Pwu^$^DqSWPp0IrT8khX8H`W<1(b`*hjG!}nk&bIQEmH0f z>A8je!(0O_b*CQJb?E+&Vu$A#^TgKMe^hc*9aJjLYm3wvqgenMN@@*-lZBO4GA4lQ z5ZkMW8AGd^z>_!74PBGRc8rVp6%iGCC_=dcB#DR|9Rr5rEPpF$3M6j2(g*^5P)ZyQyl&C2a-jCbVQrBb9v8@oErBSLc%*7T8v z2GmM!)(&*GiiNn{a>Y}iU!DX1S+SdWHCI^0whl4ij3)3!%vISLU_BWyv5_95j z&3Sam=uR7eo4}3Hj{X1FuqU~B_g=*>O8`rv)0!*^+M1djoV9SjLGlF{wqh9PieIVd z9X}NAK;P|&li_|CZshY)UeqnjnvB_CUfxugra z#1E(8QS+mI6o-qj`0Ku~#x$Ehv)yty%no+fZ-AJdnS|9G}gdCCG52sU57}f;V zmTRn0>2%D4pbW1ze_`CrtgeYwh!&C7+~)5h11g3~*JA8HucKvIW1eD#nVClCaj25a zp0on79ZPLs(-y+vvhmp$DjXmwF_93E zI{@b)1p#ipn9agr3@Wo*#>lT59+Id2@R?s@RjR|nKz?7Gv@$>Bhc+ME0^ zF(|)V!tc#yh-D6tU<+L^RunngPw&I)?(g-qOba#NkvE6dy zBnKmp?N#27(bcGf&iLIP)C#URzfzBTyJ*%!pM)tyE>(-J(UZ*Yg%0qrqPM%W3M&rh z&BBCw;b=BNbJMt9iNhyNJ~`UztS~Ziht`i3h=9P0tl^pMJRF;SR z+z{m(M^dY|R5%V^P%%rM{>lXslCe82oy7VS#54*!XFeI&O0U@pLtid-k#fpZ$0Y~T z61ONbjt%6SV;|Bu@`7^TXTYY75XgzXdqZmprAYnZuC#`zbT_q53WfJXDkX^(W>5sb zMz52HREd;M)f#rfe}*^9^^iQ4N3w;BUW@Rm zXf`gZ&Yd2E*`Jm1UHM;G-kT=TSfk5~EuRoZAD$V3BKUP6n!;G^n@^Q*x^(b9qzzE= z$0ZZ;va)79byNkVouP0C3tjpy-YRH&}}|APO@4j?V3zj_aKI?FxPu_~ku-svNZjWGKLJ^9Q~g8P{fFE2aM#3ZA`~ zT=mNvFzIpi;J7yO$=U-Ct%jCMGe1x}1^i^Aa3wwe*r<{Q#fH4O<~_8LOo4(}vX41jC5&m75U*|{ z)2+^qT}M!bE*b0#EfPC}w^YaRaJ1)ohnI(zR$hDJTKQvakZJ=e3@c>c4*zPpY47M(h3GET4>arV) z#!Knkk=bJ*E7Lal!4#xoH=Y>CvviIbok^XakXQ~?vX7t zU5(rz# z5{-;g5 zV$Ja33>>$r?>6ftY`?Bs7<^T2?wHeNB>t8!v=!O=XxCVcRV(fO5djD}c-J#OmTs4@ znGoBK!fxuxSeJaeHX7$)e&6B0IPE(3q5mq_nbvR9n6MsUyHIawCK1?`E!NUmSXelx zC-Y0B8qHO0vwx&n^)nJz$H~VEf@DjYjVwpRY?uNaE}mZdoO_dHKF$a|+b&h1ta>iE zkt;-PAfZduWN99;=o+1bX)9TTb)z7KWxIY91S>%CT`OXY|izLxRA5#Tp$l zD6M|!*>dJGRIs4T4gNxfjH_H0e6lx==RmLZRq{T&=lwoik0`I1dJhT_#S zSx<)lV_e$F5#e#OY#+V2_-!w(n3~vz={)V{zoa+>sF5$TOrlSYO=cEH0ez{(2Lwr8 z6aOI~!q|tUM$UZ$0~&T*H+Yhu+v)BN3lU~#e8fqUFdj)^%!<`{h3Y)~mM#W4dc*Bd zIE}Wse0$ZoK2WsDy-z*cNpbHz`pi8f_MzBlWx>?71y7@0M=c&UnYf`#`C40>dC`T7 z83wEwVbW^SRzeZoRumJlr~4fRm-;^o>&@+utUL}w+Z07YK)3??QV4u0Ajjl&m2ezy zyM-oN*w?%!H+1-FV(()O7cR~t!FI8z=48FbsurW_TeB0Zz4&o* zyDtSVU>TF6(2)&kdDD}X=WbGGCEgO<4O35J`IZ6o)V;7EyWY@oDLK7iko6W9zrk1{ ztNOgYayjRV^YoiGD8~KhU}HAy ztUTh9wbwf)nTC7kOZgEd1tmQ0?dRYg!qy4>MH(I?y>ApYk+1=`_SdL2j=5&Ig3}ns zMX!Zm?o4R|^Q{h8A*Pr}z?iNSz=ghlY=17DF(qf(nh|wEiC^U&Lzgg`Sh_v{wxuxrnD=j7^&Mm=ydSy$7N42wQ-Lg*FdM zptrw}CB=0oDYz9k6>~S_G?&*(Xb+t49%yVL%5;w&@!rmGu`QOjTkG24;AKRl!vxWn zFetzdA;YULbklp?lScO}LhgG=3L3oZG&ct%F2yfdn&(dbOx$)r8!yg41`?Y-2N7nW zb~GB>k5Bxp3(sh}eG>uYKQ29sAMtfjJAnTJluJ~~ zxFD(|%&i+=<;QKk&epb*am!@8bV$~#P&#FR)>eN3ifhbe0#%RGH2u;SY`?%U6avPy z)6t`4U-#NwZ1a^%uCyqeotkgC8~3T9-#u8T^QG?iDOt5L70ECqzXvh`oU)s3zM;aJ zCclop5Sa^W^>*W&>8>^Mb244skgc~uS}!$M`QBq$Ses|fT`s3~jPOcoiJZU0>VMff z&CAl18G=kO{YT)3efQ){-yp5u-P>Pg_#kgS^F}YGLhDUHQZ;K%Y^GbX@HLT| zOsGua=4|3*&YRS#heIwcBH;~1rQ>4w@;!@@=8Gt3!pGrAe)3NN|Mo~>ZS z)#O=Zh!PW0m@{9n1+_zlFtkg{Sgpj;C$Qm5i$u59%+w6~vfrkN=}+#j)R@23(I7U< z>1wEYb7ftLwlRsgC5kFJ_)%aJPbq35N5+kv`6+Lbu=1v?GKkra<7|yE~!5*P)fc^7#?QTYGNb<0FXxt^cKPbrPN-bECaU^XG zl!F?YcPX^#+$2QjZ*9rl+>wutY8R+*`SKQ5z?`}LSc^Beo-@9Ni2dEv1jMidZl%&O z-Ondcdd4$J9F~Ln__#it!L(L1kr!<(m&|s&k(0Ib>oA2CG4U%eQC+^y)>e7`F;%Qh zRMpq8@>5LKHzZjL^7XVmMvdeKs^Ub~7piPBNfd=!rKfMG-+Y`myqc0CMlKD%J)mb| z3^@~@{~*7EN+hIRYFbV2amUNpob4e|d^n9>Z^tJbcFxzWwhrwV)=L{$iU|~AyIl)ZD&V}Il~HDD%RtkTn6$Fou8JLVhe0TPb=d4(ZITk$yCnhC~M$jimc?C$Qan5hWdh&t7U z$?7ir1bB`8RWfRpdDUE|yK+oBR|Y;WOx(>x5B*37=Y<@Y@_4BRIj`>jCn&BW6}lWa z-2|@^Aw+Z>mbiCwE%Vv2YmCAjI~mvWi#+)cRcS$*zy8l@{(_#cEQ)6HOPRgA7{z6c zjN`OE^HXi;r}+NsNN!VNug?pMi#)_mbA#4njRDU6*c1`NG1_);c`? z;n;NG>NrpuI{(a)@LEu#bSq4^ModztHeT7Jbw&y0lE3u;7cRS6@U|&Abo&w~wLf>< zmlBd;)tQp_7#ZfP39_)xDS^+hZTw*eh9jBMCX9h&8TU#%Xm@6=2T}1KEFZ{@Qd4^5 zTqkh?XHjM-xZ8J4Qnyt@a!l4|n|Wv)SC@C@o8I)k9PhvLO=w)H3YdcJTxrPAyt!>t!RKO%hX!9AX?&(?!s}38pqAL zVA-2CrDQ+cjIUMEvcJ<#^U#fpWZ44SlhBT^E$&vNpHAX=YSri>BPRRKDsxDIUc7B| zPa&OBtoJ+@_1xR|~C5U$6$Vp|zt~Bnkysc(^9qML)!nuv}eBqM_tlEai$Q z6|+k^Bhg^AR_u1)IM>PO`y2K$i#%J?8$o<3kTdoUzw=7O+&BX(@LMIW9@GnMM)qIO z2}Je^l%jha?#&Pb=?jA+O0cB2979pVnX=2jMerumja1+H+jXwWRRVOoP&Yg4T)XG z{+HRY(?!+;Fh8BSeTwmQDxumKQvV$+*oZdrta@}-OgTRR(RZqK(g%6)x)+A^< z>F`Xq^M}zGM`IIjbX%u~1#j&o1Ivb*_Nw-u%Ap$F#@akm@VRa#Y}L!X&?L)ndCn1> z+436gE{7VK#!0?}w>fYX?9s698nHo3a-&<>A7eDKzcI)Wdzg2y=&UY{m;YC(cEQle zX>*})bn)EqJcPauJNeQ*YG)A}=?M1uX8ln*jhe+T4Cj)!TyzsvKS{k&DzHAF9lIow zY4Z*~&W~YJiPX_8oApUKqpVumT6SIHbM+xt=9Zb_eQqOjb7N!U^viKtj_{YktAr`i zoK_s*@C|c&go#nfdX^?>E|1TrA62LCHm=7|=QiQYoQE*|83n#hBSf!Y!di*yqXAS8 z+g}@v`pk?_FZkQd&4rV$%!hLr0B_hN%Dq#=IN{i3zm(|G$$DGAJBz36_{bxdcx}#Q zg|k-v%qf>YhmSHyCkK#twjegOweAn+U#Va#+Yp`PMMe!pNetZd)C??|msMULcOPnNUvZw>ivQYiOD%S5_j3ER~h zScjOBy=8Fxk@8d50M0ipNn{u2a!uYz3rmBJqC|0!is!M#JoSrCCcNkY%l=lG-2HzG zJ2F2DI|SdeX3u>+``);nZ)-%G8|-3`%R+^N7wvD#fwD_akLu6oUn*bz+TkFuQ9u9n ztZTN((K#ZU8VgHHRG|j#0_$7(PxzC(n4g=a&c8g7z!%}|{_#dY-52~VB%95kg7`ws z`QuZ!|4*%PI7insm7~gzV`*tAaAXksZR;Dt=sS-q{{$q2Kew<5ysM=j3V#a_pZE?c zfZjAlPENd-ZmR*X8CwtO@9#HFUOtCEK3ji0Cf|i$0gr%$`PBA9c1X}G1t6B-SWq8X z*E4^k@D3a#LHqQDO)j0opIBr1IoB)yV`b0QXp)A&qZa&BM-9EJf1Qy4Lca2rbX^a~ z7!3LS6FA@d0Mv9{t69M_1yi)=j+)y%`BiKuAXkOKU|^*c6Tt%GUf`_ijgN4!sKMc3 zA%|JzjYHH6$-PSz$%F(pcfqqDtiqxP+0QDL%vNl#xPfE%1%-u}gX5`^aQ_m`@!$CW zpELaX*}pRQA9nD`6DlbGfp6vazwPDt$|kLz(v8J%hT$(G{kw%d>_hDY`@uMShwa}V z9$!6=+FdMVKYB#351eGL|LL-SHS;z+*p54VaMa+OTBf$gY6E@TU*G<^;K!`gkue%e zPDcFPHllbTK&A^Ki>~xumaZPiGKw1KYmOKv$NmjI4G~OP~KqI zF8i;?8`Y=$=wqKe5SYq!cE{z$$)WzEH~7Qbk?L@(Ua2*B`}nyanon%iD4H=hMl@ZUlJmfx*i2w?7At-P_o{nkj5II$584?L5!m z*udSN4}1S=PVn3?$2rTN_h7m8sw1r;5E9C2K3~!(|EA%9Fwp`Z{h48$1|B?6Qf(PX3`@Jg%`@p}%p+;-)=Sc($Not&VC$N`d0Ud?b-9l!b{YBSV6?4jO35 zON-sG054pz-KeYM{&sjFK~cBeT*~3z&?sf;x(#mLU=ZkcJ*c-$6Ti5<6F1{aFjy(V zSR5`kdPGvSQ*bZ=!_1dm?Wf;B<1#7u(&57*$h6fR-ck9IMk4dsQ3Yj}$w!Q&XCDUL1&l`Bt zJcfkOECL9ibX(YF33*uHF$K34F7)K5r6%xsfbpENn=W^lMxD()i!S!SA?Qa-S3F&% zPcGz&!3tkvhUfA~+`-_e0hSOsSkLCZ;zrh%JVaRO9ILIf`vab7q@ZcHyVcW+2d(w= z6N$3TR>Qch!TwynS_o$SNd({X0*cc0?zZ?PRO8I0%&s_h{q61U^JL5LmJ1wYcEYr zFkeVzu{V==qvEYlO74OmFHeWk&sWR*x6NeZo%vtOLu#LMpgw*R1STjE=vrB^r_y+ffLu^#8|$=Gw*DN~*E8s+ z7AK{^_iM19zkOe`Q2Gu6Fja)?=~&|t8koF7>Tlk!W&wEZe65wtnJyf`gX1zjMkStj zXB55;UQg{f-ff(db?AEJ&v;eQo+ltFNa^hzxZ)z1wNK%9d=mBVp-G6Lf+VOps*$aE zW(A{DhZ~Ob9o3_Q&OE5I1SGGFd*dpmtNiAn8HKxEw)g;&LVsLC{_76jgtCwjG3?8Q zC4=~b4cxnc5J60N#1%pU-+F){gI8RJoVIQMdstyGY+TskK_bi7ijl=)8&M)szOq=D z$bJK{PD|{ZtK0KkfnJfacRwG@{A)M@lDnX16up;+F!54mp&Q!=XS`jXAt0Ae>21rS zUF8GNXnOtc_D5IW9|Ak%z%u~ob1#g?YL%KoW}K8MsLQj&PAXI^tK$ND2SKb(%0JQ3 z`;{bE-2|W-uDt=IhKl>yQe&qi6<~Klf}A{KRZmtUNp6D4`Qn3fpG=6s%3d}e=98Aa z6X|2;6tuU@aAoz5;6C^mo%i!CNq-G!^A^O2b7dR#=0_2S!^?sSvjqoXA?2gjcN4#q zU3~CM5iZbY7h1)GdfEwBAvo*9LV0%Bjd!GCX>|g6)61fsO=u4U2BOWg!3oZFA|N!+ z_lGQu#CdGbo?Sw5pTHdNSC1eeuNLu&JhhiS?1KHWWGNW^+y2W$=Gb+S;w|HTqDzAS z;VTZtg7Reln)dO94FQ<^N1>HE2}lXmU`!9Ied#I+`vr~7IwIvK&DF1u-XZ4*QL5$ z5OYl+*;Iod!ZX7+2n)kRL^cci%`OdQM^d`Xh4glOKH0S#7=rf>-qy!~9xWw5W#km9OkX<&~dURhAkk!5gcII4=PW zwcJ?_0W<{gVMYn6kHgpvPP}7VTr8fe^~GC;DdME|6uypUx5=07$U;1+2Jun<+DFo? zW(cN1Z&y4$BuMF~Pi-f6?pXfqI7f^pt1aJe$m@A-A#1T7&$F(=09|)(#Ai`Lv z;H3e`hPKAZmnyywWue@iNaf|teZJdQzS_BzY~${IARptw4^z=|o6n!_EIBERa3KA& zAbQ}Lw9z{pRq1l=wKt?$pYc?^pkQcYTnwm&9W8ufnzDc|cpL@&_Z}7@ar>VBRcF<^ zH+f=PdLoY9d*?(Cj$1&60~@5)L;I_V(7=768}dn)+`V;={EWyB5A}f0=AAjAU=HwX zBW?gNP@_}0V^=w#eEuE}w`h)RA&`igUOZuh&u`~A&*z6&dk6(&;3M)icTx_Yqvf>X zhdzpw)F&oK_eVf|Y{}N3j#2!^@hGd5&oAH&A7-rQHVa-waOLE@PJwxK;Z0(EcB$Cr z4t$s}a9U})A_C2W&u+jvlWLFmg#Q}KJG)^#+X+v(p-+Dbt@!NCHoVYOqx)iA?Kshr ze>Fb72$X|_V2;w~H#;DHKRLBYpudZ^RP)whb`jV8YBE!)lgn2I%YO&rDjji32tI#{ zNmw{lhrGlKU$ZdL9y!+uH!jhEZB|Z!nthxj8-ud}N z_^$i}?1mU`H=sU{qrQU=CXB6=&u`;xpoK+1tSdoY=qvoT%X6q1sE z{y#f-uY4W9SDZ#w7771WkK5{BN;&7|&FEo0(QmQuw*YDfQp_iVD-A%d7YYYE?hp|# zKX|VFXXVOWh>Cb8X-7j?^&n$#0*JHK34nTHlMBH8{AfhmLa%%bjuQc$C zAm9T&txK+S^~S8GuIV)OB!H|ntmot_Q|o{+zsASHj2l#qccu?P>YVZk->28u>pfaL z`^e8UPTDglDO??Jo}Pv_?*Wh(#E0x|!ufdpNXk~#B#{2frk!MpuNubh#p4su+GejE zc>Oa$p~{gRP!VZXO#%#<39b5ngoVGn0HE!4Fi6rMoQL?SjAKvXdPZaRQ!K4U zeC`B`#K#GZ+!O7OhB&G`5Gm3uDoT;veG9D;0PLN}lRD(cah4rNi)c5APU^e4 zda#Oj5YGDokUk0qrURgIk@w=HbiG+9!<+$*u*e?(Zu;z|5J<{uw%HBSI`LE*apL{7 z-lu?>)Zm#%ZG+e1P~o!+`1X6n*2Zc0D5SuAeS;(4Cp*O6pp>y)n~wwU8m^%H z*sJ3uv@ig(9o;Y4(AFr9+kD}T^SDp`J3f{hGIxWbqmI*wWfP>~?-u7V*}%ecfJcMz zsm*SIrLr~8$<2zxeQ+Fip!92Zn%Z1wX4$IrfWwx!-R!A>$eN4o+Z)4~Iu)^w6pGB7 zYuY5=4&;3Z$MF>z3slMBjg(od6RUsD4HP&Ja+C)FL5HQehv8r(mCrhpB8O`tog?DG z2EniPExYCysTcSYR2Qc);yHlrr##?1porn zwk)M7*G6Y(V~`}x4?-W1;0hJNO5{B@M-LA+O?xjpDCattfzu%yi~<4zroCgE_;MO7 z-4hgQN}~Q2@X=K|sL0*J)6LvZTliRZd2JV+G3K@3>(%1<m4fXf3cWeA?*N2@(PzQ|jg3BB*^S-|vP)c*S<2r8AxapQiBC;H{o~2TQSItL1b4v3^_jbk ztRm#LDAi=rqn#w7_k_D9f-{8ENtYMH$S-!t8C!^MCT@N!5NrB4)I7sQGQ1$C;6qun z-)9kSb(hSb3mgjMIU{vR^dbD_avZ~{+8b90;qm8^?$Cupd^~${d-HoMaEPw^?1&_7 zVJgojIkRdAm9)>QF0>9F?0*|r-ye*W4xG7~fyp&qb4^rUjtge*?^O&|X&-E4HuO$R zOpHb6|9K(e1t$r3J8FlF8gpb*Jk}gKFN%!4)WD|2d2y^Z;06{&OiZlXS#RJ*>9R4a zf>~64A=$BDO4*1EEe*q6BZAw@tcrEAnj3lDb>hI-=XXE4PR4)mAXMNPh5u!##bG2V z)U31K#ZGN#NNZ$WUbShvJ@wmW{*St9@T#;!PM3Oj<3C6!k(wV!N>5-$}$%jJDc<44GM*_moXA@A)*p?e;*g8aQjN8Hijv(35#P;(RGLw zPv)00XkqcOAk`^zzRWY}x;7;@5ceb_dfw~~@#iOweEWKHPE4gO8UhjAcQ@}1hYme2 zq1}dJBV-+3OBM`vlZlP0g$8s4%?)*v_sh|$NtMf6Gr7F~9HMTrpDaf;-J*35D^+Mc z!)EPDPt!p2zKr}zze*@oq?Od&!dpA#q2!o6`ght$>2ea-;ZCnXy{MD^)}zDBgk06p z`6qp9f2-)|isy;HMg)U0G zsFe(%grjwuGE_Xw!4a${ycxk7PX;;yo-BMvGzv9vcb@jx0e5=SHo~)a>qV-YJ&0=X%!vPKQD%2Rl(# z%xtxYU!0wRNLtVTkFGb5hq8_S$EW2>{^LL0KRnFv{;vSf)wMz)BNt%U59B1%G( zec#t?g)Gq~dl*}Y$iDCU?_BqcKA-RWp3h&;^D=Ya_jR4?ocDR3_c`};Jwrn-*>Q7X z*zlmev(*sX5RUQeq-oD>6>Cf3Vrj*CVsxdP+HG$mJ76-}$|KT#dHJ1iPT7u6y#veI7yi zf4b$ zCAYQ8OcPbu#IuJ;*vX`1$UWfP%2H-}swH%(#=_3>#O0jRy>SM71xZ2af7;nH9Ga%? zwb$(7fAE^Wz;}Kk&4=l2ciBO{l-s-e54R5c8aa7X5$r|}UU{(V|6Q)Lr%#t6zn!bs z<;hOb+?lww<=(h_9kN zW-oAff1f$rza>aT`h<*K;;hbn)r!qxv)p?xN%2FqP(8<>WV`~j9}U^zvb|Oo6ormk8Lf# zQKw>+?cdE;$CMi5u5>;F^I=%vP(;Oig!|BC(&W?8H>2C9F0!Wv^xVp$9waq>O7FE` zy^!;7<>S>VF@-m*9s5gOq{@s->2q1mg~xw*$&U|#U+z-D*xh?koD<^57c zl^NSb?B`zEFM^j(wd(QzaGj1*j9wNvu+_5Y8eor1+Tx$eAd4$|MSPgQ+$rOU-go^g zzg{g}(xPg)sm|{FyjbJa-DM_hLcYe*W{2%QM5eoUM_MdGB)X=)(J+#DATZBYK)U?k zjMmEa47W4AZfqHh3G$B3mK~$3mn=pYLc(NbsW}I&cb6iI#AkOR+tTc!(@y;|e%JIU zqZsSwUS4kHg^?5XB^I1^bI-^RX z?NfEzI?<&iJ&TcnASUVmUgB$g*QkIo^eu|L{kpur?K4ma`!h2Yg8+AbfsRNxW-QU*{Yl;yt7a%M&;@y1SMLxr}ywXysk51EtyR+ zJ|cH?m9tqQU~>>@m!P?wRXc{%5B?jeAA`rtRn`sG%FeO0Em@McK$8DgO5*sg?Dg9K z5sLoIOuq>Vx{|gy(2#_${aqQv- zHPA{sAma1W+Sc&ZGjFEJ?g5=Teor{Kw49tIZ(}Fe!BAnc{CLyC{~(D#M%?WbNzPR_ zwyjUZTmBWEe9(4sbz-sar=?!kt-PfF7fW!MtDgf158OfqY9F)hI+8|l)_MZ}1RVc; z=-J`pugi7n@`S;@1*Us<`urrkAL44BnRrN!~;XR?V6* z9<7xO>t3pv`f+@pu8z*(wnE!?yZb}7b{N~JCf#1lT!{5quFkj=Ss-T&{xY%#+RY}Z z0d_v$7<{5sLkfHnMG^;BBZPhrc`8KSS8Z&{wNRz1PMZGZV4l7=w$cpF-OL#FSZ%`d z@DOpB-s_^jv^Rl?|0;OOGoLD$7r$-zPuae*cZO`AezjY`Ns$_)^A{^JcoK znv8gcFG~MbBHo|%^z1Y{gwBeJhH3I=3-TTDTdK)AoEOq9sh1yelV4!7*6_4%cdx!1 zSC->#u6%|vN7LyDd8yaDP<0iFhvVfJ5Jdple87PiLTxI#~k+guK2HRTI; zEWdmNT+WDpM1V8yTZtVge%5`tgp|hm?%;__0`}d7v_i*#@6xdF4 z;!}Jsu^;mZ+m)lj0dz8krLBzM!?N=d&#{i!hlf~bO`Cp($S9A_%*|OhEyy)1Xz}j* zT^l87*8V}7@l07IX(2bLy+O)c?+#Py)J)^g)=vP1v1#w!0no#)Uzs??Dte;e)}2b_ z7ka-3G%9WIj2A3MWH^VYHFCzopQA)n;;iivXFt*r$qeosEz{J3%V4@v2=Q(5U{rZ7 zK_RqWWsspcS?3V{~%1F7sZB)2XSwwLdjF4)nRpYju90YORxv z@#5nMk-`2A3tdeUJnj|emCkzV@8tmv_ag4FSJH7jFQ%&=(serX=Jq(gzg8vx4@u5L z(&6I$Uq!-WzNbW)!{07f?pxg-@-f<)>WjvY=)DAwU-yp`7=x8j@56F5@4Qds$K@_^= zK8PXiSbDI@wq(iL`3u{BZc`FZqv=6Y!wsHU!M(3E;lG~9QhRXDjBe>zg%=IcxPxiV z#$uB%PEy)O0PqnISCuw zbHYe9=p37&`Vo7r9x{$?*|$2KHri1{w@-}Lsc=ROp!7rA?ohG6)+GOrF(MG>@a>F1 zIU5;!OSx?dXF5yWx^MWE_rS|R(O-Gy1#gm4`R>X7$U*c5Qd$gu&b>Q< zzMt7n@D6V`RT|Nj0B`$RmcRwXWYuAE)m3f6p7lxsu;{XPY89UVcUx*)`5wsr2!*@y zpz>JGX?f6>U7XlQDB!sO}tGXTBH1;V)ti?gG3Ojl-34VN7gF8h*v z*!$)<2$r2)o~@rwOGgX4k2%nm6~>rACfE{0V$TZ#Wnyk%^Ky}oOMsPWUmvSa4iqis zxxq8Xd>9o3je4Hf59)Z1C{A3m+Ber+*>Sly)%Tj}j}6qix+_Xq4;$$sfok@xUVp<{ z4PQdXXBKwe#>dnKXm1{?&)Iqc@AqDQ)%^^aUCThcPBnw& zEx{^|k2B9Uhd29$H0QAN<545)@vcjKi#H6i8)$Uo3?~=7G>@$MH_9%@mzM?}bOXW^ z-Jx=2huy2?+R&B8-c@$N2O8EkTnCR*`2wFfU_Sy9-p-=g&)%o5geGou6OZ_pZ+X_K z$Z1uiZ4T-psMh^SKANnG4k;;Lg)6G7<7 z|IX~lH{JVRk9qSQE1AuHQh0qf&p(=HSYbrp{B=>@YXzT^8T8M)P1$JJTRW3QSHZeT z(X{T-hjS~HXWkz}3PN6yKR$XNtJY(=j#nDO&A#dVT+J_dxVfXXj^$4^&;^(09OE00 z&kikG?h1>%-&j0I(}|;U#q^y38&S$?9{MFtcE8wl{Lf!E+y=6lPMy>0gT2cy?RWAy zRG``-=@|chK8M?;<@e|ko;-PS_ky2ZSlty-`?++%n@96|;0&I~4QBT1`e3`cEgDJE zaYyyyu-6ME^R&9*+Htk&+ADfAr`|3czir6o-uJ^+IJx#?a-l_(7h!OIq_{fjeq(o+ z#W_JL!=oU~>xb}^b6uUxt}eMaKjZ)89Jd3n?a^}Axv@@(rm54?2DX03<)Tj9qpKac zy?5{4AFgM2vt-z*o_JjvYuWVuv^3+c&c&7tyMiiuuPmENA)hwoxfQNK0bBPW9La;N zjJdE+vav^phkmP$k)QEvOr6P2GIN;!-S_Ew;^Qc)24FFA*dPQsWn(DJPbn4_?AiKc z3jP&>kElkotp$sf#I_(9`qL1wL*2{nn{=gAl!Q4$h8(~QPKN69?m8;P!==;HwWE8 z_G;PNb2d8X&%^glWtue>Nd!i&yj(2^2 zmSs?R_oZx35(3Ad9D&cel|Nrv-S0ZNdLSfwhv#gp8?})zeWsv#5sajPe_GzO+}((t9dsP z?g0YB%Cj{JXrF-htDcZctU@5m+BFYE)JrfAag5@^8$61TQmA zJLg1~D>*+W zhUP|Vi|BT{n%qJ1l79b7xB1}Y0BN(k`aaf5OBNs#W1L*jbZ& zdMrRaO9v7Eg@hyhCI6OFqM{(V!f%u?gECp?ipde`nbW#HrV5Wo8-0eXGD;2ASLnX$ zjUVx17M3ZLGd(PD&V8!&tiu$-)Hq@HbVHtq-$BC7=$uk4KO3hFOsDfjRi|orR;fx? z7I4K#Qq>EX+NVG>68a+cQ&`@(+bP{bp4%4yV;E3*uYzDFO;3@&tf;I}XONIl@7lLl zNloNZq{>eT`5m88mJRL83(EYg>m&7!y=2y?Ok9j~{*cl4_18#F{Ehdgb~Ud{_G9;H zYd)UDn!hY3np{?^$@@eP)HaiE3T}obMfu}j`|Pu!5S^m#n`1n%zq{U#sIr8#k%~8F zqF^`~x^hXEUC2OH7cKvk{P>}i_ZG;WTy{)|`|+B?&7R!njw*7E9APIv;TR&dBXTAMt_GPTNy zR*Y&*I{0VAK>TdU_=A+tD|(z!XT7DkQUahx(mGD>lf<6LAFFkYv2;(NkA0A- zg6Sz^!WGD^tw2Y^eui*+9GO2d&$rAm|L$c=*Ju7~>72!zBPIX6NyK}qW* zTr+p64NaZ|XZY=JrSB!5aeAIV_f}4InSuiR^H}3LmB;K>8m@;ae|0)0$$c||XL)SW zw{|{p*2c+Jk1AO;Z3OKDpL>p}(qna|SfS+k{LJnh-?dg53ah6=;j&nz^T5Mi^<1r2I!-VCz$C&l^XoA`(~5WcN4`k1KHwF0 z6?l+y^Mu=oXSB86yPH>1nA*Ea16_lnwImZqrR)|^3Y~1Ydhf_V>NgqqubHTevL$p6^nZ~8YoCxA>4&Wl+n#b0bt|o(b??v@^6l|621W?U zScRpy`)dzN0i?4emiLu0!C5|{T8rF**I2J7CWlbJ{$6Ygxixdc0|i*DLff3g8~*AS z`&n3=Cj5>!M`-#4$(f1n$>A&F=7>_+Eaji%W8o?nq~w5WWI2}+;da*W%7bh{&0__& zN9;S=vF5_HVMYOOW<1q7@kxS3LW1G<**sUF@5)mVWc$qPe(JX3PvX7B)IUMuTDi4mm3h zg_x&|$5+W^ja5-egG3p>h04!9*|UP8e*d|%WpvhcP9X1MNe@4W!Q^FuYm!s}wjIMhI$TWMuI zBnuVNG~BBcrTtVn|9f*C9~TXx`o~4{=UY$NF*7uQzJ<6^=+}-Zh((}*u)3O-rfBQ# z#U3q3mXIjm0Wx0HQx-uWZ>%^@PTArmRu-3wHfQ!m95`g71We-)r}(CcK5Bbsy1j$bp-xeD{#lc zku#Wjf~AR@gSquq^;j*@XDNZvY4d$_322iS4N#t$kYNq}K;?jP!fZHu-xeuioon~4yu6?{bmO_OlPVwaSK6{zc545$a$ zbHqHp=72&ZxG6s>VFKa#DNkl?eoT9`;Yff6$hrH}RQ(^N^Eu_{L=q-M^X3On`N9QD zqd}|uf+vSrg!fcY&qEmleh-^>_M{MVmSzjj?b3&FC0B&7f+vw)ez%Hx4@R(u*YIe( zx<~@J#unfHbyg%~S?H`wvd6rAV$c~(#jA=*QsYgRp(FN;tzvcJWD(sYx~8c897~9| zpxNx>OzPP&b+*sCj9BCatU9iqEU~wB4w-(iym~Oi`-SYy?FL*_2azM|@s$sHC?0<* z*r&^~MW1j?tx4^~mnWY@cZanHiwfqoVHbQ*t^oBK4b zbyPIfi6P{P4}-e(-v7M9r17lPiNN!#E-PA3a^ZrsL8lc~!EJz1JFBiz?Y!Qd-pk}c z!QGRAqN^z(%hS{jfVB)AO~s=*Odm&NY}Ur+s@)XZy-4-{X`3@W1K z9a@)D=U%jAV6oD_e<;*Wb*sT~s;dSrdVG~XCt%4McxkomVVK*28C+{W0=2%S`@|3Y z!PJA9@hlw7LOSO61OqRH)sLDkotDj@X<`n$xp>XukMx~i(=K;Ssk|%PG1_|QB`TWS zr?7^S0bRPVqs3%nZGZtpCJMqgRExqM(*2|2F8(zZ?R7?~CCYZrwu@kas*_-8o2v7< z3{^5zm(}|Ld@Ch#V<_044?1OuF}eyQdD!LNV5GR%Q)y3P1=8b90{2H{m|WUwqZd+F=U<=dg{!cn(ae^BBIZA@ zQDl!xz34koG~MGR3Wc3)K25wE@Xg_+iMZNk{nfsNyKGeE(`JM~Q$$(f!$R~5Qg?Vq z*9~+U@H;Vv82B()FCPkar?NxSCZ+RMEr3?UI}X6*m%(bM=9#t2vFvd^6O^fQG}IU) z42P73=)aYN5(fKlfss7qVGCFCvF@N=mmRF@A5?vAnE~LN$~00frMGwHnQPxC8Od9* zQhTj)h$?Ru=XiI$-Nv>rE=piVdKp!Qa6zS@uJgmU4}478h3Dg&g4z;0e(!V)|P8#{SMmws>c?qo+)ri{`) z&GxOm)LbdYm)=VQ*#_S%lCb)I#qiAwy7Zl4n)wqDg9k&DX125Nq$!t3Q?GFN*k|2F zqz_FF`!2xVOPbn3HVCj&(vlqD{mGBXSftGXS)b=|H_A5jo+dnJ4Jo1I5bfbfF3n&pi zn4bG^sNjC`2c<1>)Cu1TB%3yV#Da?z2C%WFsdaZ2vEd*|%odZ>#jnsM4@rr0$QD~f z6P(`9kLm=96caGNYnK|Ru{JwLJ-nOl5^art3<|q&sbo~bT*t!1S4@ggWBCB zphACm@V%X2;LEUjL<-;v`(a6bC#DcCpB8@eNU#Mv^$fR_KfTwcGnqGskb+gNFaYxH zWA{be>T-vHnf8Jv+C>?w4pBd87Y8$K z9ApgC7q}#vfc45h(PbrtwJn)g=u6!Jcm_k?rG7(0`?b_K@uKdwYD8k(7swu>>=?eh z)Hq#^4y4xba6;{T!rc+72Wrp4g;yc`JlF=xi9!-J*eZI z$yCQyoa)n6`yTBzg}w3w1TFaE1z=k(?7#;)1}o4u4T(&NrMYv zPVQAW!|BQwk9n!w1V=08AsIF3(9R;)rZ9-SBX({>${+&jf|)u&NU_1x+A?vw()qw* z)DPIWlI1x6y2H(VMT`pr#3YfFQo3rlOsZhU(Moto-bbwox!(!{hzV<%1=H0nKO{}$ zGdjs?{;o|DNpP91_E+WXtf#VsSn12I+JoP@{NVG;zVp5dDBpPvhPg_wiY3i;w}cf! zd$Vskv>vcK=DX6llT_E&NI~RzD&01O4mnZANvVT*&ixP_krk4E9rU^)Rc)1k4+g27 zaOI`S6*$_<9+JEPY9~et?sEq=k=+{ByL}x_jCT>1z?Rn6cQ#bHcQ_PM&|PZI96kz83VMneiy@FjD zHdpTCdI}fbyae|sOFCz(5oZZ(>%$6_*AbQBbd*vKc|~JKBZUjM35H8a9%FsL?9=S2 z%){`8-b>$aclUTyP|=Q$u(3H*8WnhC?&_qvaSb;Z@-6JNs#Ul)cr^=kRK?HZYMNF$ z{}f54b!5R})Ao%#Q5B+k1g!!be)*P(x%?HU6$pWsyK(r??mY`dBCDdcT>L4J0br!m zI)ut;YPQ4k3Ick%+J(MGZg$Q>JYY4?QDEaHoM$(Twk-smTsdu98QWl!FZq}%zlqg( zchzo%9`)j7`HL5DhM4UU-+#MKOm_~NW2h(I*AS>eKD)6ND#a|^2F`A0%=aJQREh`1 zRDc0?LuKK*gws}CMh#+Bq6$Q&#~9UCiAqZ636cpJ7QaUNkJBGY8r`w9RFtZ(b?4_wkG;W3WLJMT9|sv#?jVUfzWh{BswP}zuxUMU;QsTZYa5?Bl#_4(bxSU`cKFY$lr&Y2Npo& z7)Hf%!Ui#67`PY^{kb%Y^*4G{Gz>y-(xxdt53)on^umns5N#uPE^bMh%QHWfr zQbQ^a2t2L*4(%N_`Rw2KJw+^J9>w9r7UveA6{Tnzqu@~_BwrC=J~lDCG#^tLAnOPR z^DuElqaWA@Jw81TI_i^9Od%HiuPRO%-E9>HF)pSBHZ+{I8tHEpw;rZCg_=C@zO;z0 zPlevQ6}yTD7C;h26%VkhK#Cp4K=b zg}@}o8>rbj&;l)iO2~5BBR8*?PRKw~W8penxCum;5e#sSPOen7vQ!_H8bIj~-5iZ6 zm23|WIaa-dIHn_-R~WoiN#1y3Kr7Blq{RFmh^JCAf>n<~k)M+AVK-U{C&(!-5J z15_T3?w}bBJDY+Yk<$nFTxgC>hMHdAT^s(=6p4zI1L=A=5#`{``;a|?z%&*93Eu`_ zKb^O5I6??L-J=Pa9;hGlOqT=)^EZf&Lf)Ql^AvS0-ay;~{A&U*T0XS1_P$7*Pow-9 ze?Do(@DSG3AVEm11s9^T&AJ~OUV>Yv8=}t9TPp&1`jFsKyoYGKT6Tc63Sb; z503w$_xYSH^I;L58BvJF6A>XHnZ%!~1>a}5t=b3`AXL{D8*nv|(bnlXz{pbH-mg8R zv)nKbzw6Mk`V0u)G{|D-V9Yuz+Ae+2@xgDe=H2FXZ<*9s)4aR=c4_kBvH)MZz>jNN zKMlaJ1TR><5xKia><1+QFqdaqBlqA2IEP}_U>ozZ3^&u%B-u^`V!!?{*vK#R<8%{~ zXPRmw(6cLkF?XTtB6!o&O@MEM>Tp{)Q;8q*4v5Q$`W?zsKU-~wfh5>y97}sKCb%xV zK<nsUnck@YMMYCR^P^E3< zM+QpnnfqN{>nxZ=VBzlIwXess;+$1jKf8DW57M-@F@j>B*c7guL;~YNCRs*6LW?VI zT+o-iQ^^3HsIHmN9nHbwWH0a&>0D!Sz<>~mmFUmv7>vz#zVV z+WnwHWO1}EB;B!=IcvtM`wLj&jL7KhI|JMuH3RXllD;D1ENB^imTVUG`2M3NDE5>F zW&7rcKP0iVA599V8Ly4@%A&0>Zz7OJTbS|-v? zTPz8fBVfx_#yQWTNL(OP4Ml=Ba&ci$ zqZc47U~jS4xyrQ?LK0wA83w<--Jg|BPX4G!|K|v<>1Fq-fB=hXqTi$7Op&`2EYYxl zKG>}@-%L-||x{TLs#EDJ%c6}U?@)fBU99*4TU2@7itTth3 zk?=iX?C}O?ThNO^VE^9!Dk*8wsv0^yQz@+MM1kDY>4#tq;(dW@E^vBovDvRwIguih z6n)!48=m-nY(fRES;cwaIeY0q%{zZyh1AQcWk_I$XX0=shVkbVx$u(^M@Fvt`rvrx z>-i@o2XQ$3HV)>Rjftv zAp^l75Tk=t&S)}&BsJB8^bL!)WGpttT2b}Gz-D0ir>vpo)gS<~#pmQ5qUX&B=w~*D z6QI~dpAtVj5dPf*3>LU#U!Eao+kPzT*W<*lz3f^iCkCT-L#Y6U!5zL;-1{UtzM{>t zgnF4CP6AY@LA-T1LRn4bGN~3PkfL`?Bxj6!Dn+8Ir38zU@V5GKvpV1m^#qo=U(1=X zd%$!xritt}m$D;@mk0WjZ0TZ`?6$KvvdV55%eV?D_ax;>e}2W9|B zl1B}Epkv>_P=dLu^NeC5H!w0j28KAl?ZE&c5oT=z*&_&#@%hLJBJQam(MfL5|9QfF zQi0T$-{7atY{x!t2y}+Y%qAZ2_vZY&%IX2DzL_Fp;EfT8R}mVUN-~4zMT0cIJ+N?0 zBvlenbU0h3%S}2>WS*1bf`lF316>>hLKp54K=lAwT)bmbgYdK6IOk1=*Y3Xu9JaFk zQ4~4{yopNHLNQz+i(USN_JiX~-s9~SMEyJF_wqDI& z9+-)F3`R5z7dL(G@%!HC)*BU6IRK{#5fGjrHSWxI2u2;PZrH?_!*u)13S$EhQSlB^ zcQV}vr>Xj%`AS%*>@_#kKgaNof#3Eo5_P0*ZlMnbbMa(PmWEd&fm}$~0ucez3mc|TvFu59BosD(JtJD_Hb<`u>I#T!33s1-GBss#7=wx{=g=!# zE0u|bMa%M+XMtLHI$lKi9M~%c76ftV66~^IOA=l&AaWLc3bpb-}q>x%|@(rL9HPxW7qHqx89W3wz z;D`i#?P1EMy_=mGsQtnPLo9<$tpWnLXUH?h zTgV*{M@GNoL6jFb+5zPZ*tg~#EmF^yKT(2n8z#T~s=T8vSqN^J9lHmb_1Pk);Ht_I zq{08H9Dsh?Z=FO*O_r3@w8f!SA3|-=YY4bc4*5G=2DwkWBWtou ztc-4h*gqh(X6!bgVDZ_qR{?aG7AP5 zusZyHin+zw5Ct9$t8CXvO43cYgX*Z}ogIh}0!7>SP+{QgYH23r-nm+d!3XN^7r#9K%k!vBi`mDtzhKA`Elb;?7%24Qe5k* z7U;&YHy*rGR{P#uy@q<85#X&*>fl}FU_Faal=KTA2Zra+>}m?aI!%!nK z;khNp+4sc>nay5Y3?RX|d(ND;2L8fMNeJ<;VQ0Y|8hpl^@7;Ge1{Iz&AIkCk=0_N^ zVv(qVs*Xl&pahWxmERYN(Ni9=Y0O1Pui}AWiKz>qjGm?6ke>Mtoy(va-%!|}b-0$7 z^mN4a@M1#vi9p+rVFRml7tu)(AyGNEoyt8|01=13DVH?9Z|MN1{0%IfeNj&2W<5Gc ze2ZU$GWu~>uRgW#!nhwVa6&Cs(!AQSK?PjbZL(p?}_ z(G<#t1|-9wT%Pujl3_y>xN^7AhKjGp)v&FFt-1vu_fRE1@sF)pWxxSTkgHFh1YOq`uJMLUz^mPNu^WJ)c%x7o5t&RG40F zPl`Hir~;wFCec{aXpAyXTS&6cGja50q;U|L>=9)HNl+iczhli?$1kMBwS5Y-m&p}2 z5ICBpDUie$ksWn{a5fx>tMiw}3B`Rp2d;uwiCrTO$3Ih{Jq|_-AJ4X`zm&A;6*%kJ zHRQfbE+7L79;!4#r3KMl(^xUVE{7z1w9ELgr5j~XIYp$EO^b|rjcBM~bWvLf=p~A9 zmzrb(n~FI=5WzPVnsWiDvMsjyHorKE>iuiJMs9S~8*uo2YY%kIx*mKN7#5U0NDaW% zmsXhH8x7H|9pg>WTZD97)40o=bc>8s)7Qz_+BM9O)uj$42CXam)vZ+q=@u3x6<`GM z3ARSJnfc^txDAM6eIkF;=?0v(H7NawjEnh!;b#yJ}`rx9uw{PIvLj(a6@seZ8i%zFMW64!5FzE1-Cba8iLp`3zjO} z3w?D&aq}__VHO!;7a1=nj1ukIA&DLMs5`^wpFs(hopA;1M2=k^22T0z?dR3cRo^nd zXA8A+--$SQHKHEgxWU{!_SlB%;PcP+GFw*_aP{cDeqN=3?YQX`@HvBD%_TN_DNHjz z`1%$7*Ko3IYlgOka{o<%?qy5ZZ%ut3fcl*jL^NMvh}@I~RRJ+N;QE>UX7fYef?2&& zkWNsnk~Pm_<15qz^B8%*(e|`X{zSPRmwo|^0zA)Z?&v6DnM~E+KjCrCA!{W1o2q8Q z++Br8lh=meciM}}tB(W|XXYI&L8OM49{Wb($VC@lF9q={WD(+*yXot<*yo}qFybeI z?D$Lvk*gsP7x`hZHaf_A#*Axu?}gIs1d_*llXKo|P+)Zv$pA@P79a(2u`95Jl9u}p zQ3^c1?-v8_2<(gm+3YdWrf#@FK&8}Fpbik{m54Oqr~m$gYr3R#K75PRI7kHm)u8y5 zw;xa9YHkmW*ds8w;Q^>gd)P6aUGM+=1W?RNzrSa-*jU&AZd>3p$bLHbiZ{==wb~V; z=Azq?BoKFlusE>YuaU|JLLZkUE+q4g zzK~NlGfrE54H{G!t(S}0ttUc&O$eS*W8H`8baS!5F+@K4j>2)IXvvUGNdR<5?XL}G zSumvpsaRZ#G1CXtjzL!``q8mWj1C#;&U4v-9E*IT-izYrhfwKacmMf!T-hoPK-nyRLf)+~=k>vOLVx5A)Gkh< z$Vc!orE=41Ef>8?;p{M(LoO|@4ud+{ETpSkb}7O=4a&8vMh?G#O=1=7%d!LF%nYM` z{~Uk-zG_6M1&qT0><}*{+gi((|7)I2A%zcR*7z?XLNida0G0RHpG=ts;fkzFs zrRVt!m&HVQd4c!8r;u52I59h^FYc%sz5MhqqLMn{q-#%CkO`Mb9}*D9P9-5~$3}`U zvx+8VMZ!k0^Cj}5F@{bZlv^3tQ#)WQsGWFP772^cwFhch981X#&Q^bBT`X0>ZK6?f zM@T_v0|-8#Cb^+B3wlvNjdnOBt5<#fjIsC{5fHE7LAAxF)?_s=OGNA!nu@`S`>Q5$H*BqhnF(Ha5f(m#FQYjRi9iw%<0bUNo|xW&4$Aeh zn%cL!b?A?O>tW{^3rGe-Os5h-b&=Q|g!m#;!(XXMY#Y)Ivz>>5eLvAR1-@;OQkoAL zqZAl$P07T*bh%B>BfR9KcbHXW9dU!2GW-d-67k&Rf^r3hltD_G2^LUc?=U8mbrxv8 z-v>2*(`E{U*SNw?%i32WCrodgM1e54At)Q@U`-+>7;TraOn$wjrcORW>G^~gn_Mh) zNPEE_7<~rb^TH_P^Brbnu?Y0rAPVjfxyV^CbG9%ZIJr2>^ej;DJO|2)Ww#Cs77qFD5VOasaG zg^=OGZ$tj>Nmey5MJASm#J0t+=&34W(yOrx#Ka|<^Ps~p2cl&WK=`@ySsIRIH~U)$ zkan_5uED$r*ZF^N+As`8j!7Yq`P-3<>949$HiPsWUAs3m*x_8{AIS^eqT$#J=u}g0 z9?5tT#Yv9m77e(2ij2kY5$N$CZY?;0vRseLGISi)z=WVFuQv*DacO4c4JtIhiY8IS zBj-P$7GhOZSIk;f^_6chh$-Q0N*`notV{`%Cu1H%SB&3w9F3;vW(VU;D1!(rd`+UZ zcPRBr&3XIK+@0O_P1@CCiY)Mk`rO}hY%%}y7BKd#*KIdMVVR$h3v*1x*NUB(~E<%HYti2eWn2y@|N z-IIXuG;{WSJX9!dY*rFgH`Ac>3K~R5^2>bUfS2seSJm&IQCyTxhVTb<+wp~vsj^pI za)#Y|K*^vqtZTXo5^`ucdg&4<30K6*rFv-t4qnVB*QG>Za~no9NS?wPP0@)E!)B13 zPJ2b}qTQP9K6x0Ua?Y-2#}+OCoq}X5&ig=P;$PHY62_}(1RmIdG9dm91)uKSB#31F zJcN{f_!#vypkBIqiITvx-Yk`IBIWI?DNM(Vz{s}nWkdIDXxYFf z66&uEnN7bV+&A3?vAl2HcbO0HYoB5pfJa-jkGNmHYY35(hXlc)9E7r6a&(@v9{m5{ zo~~iN3baF!%h?$vo%r}KEmFRqyquDXVKoQ4hDShxM{@C7b;6^=40WidD9Op?&4uj7 z%D%rOE|=k|W48w;^ms;@SzSDJarc3cuwA+9aq04uEFFFu1|Fd+7g&&Xy%E#}R8&bG zT5kz5rztog(JUmkwFW-lh59p79%}xWLOI0tl=bl zIxsY>fmpK{m97#w$xGQ;I;f6=&YC zV0u2dO|}TDukkELz$O@{P9vR^MLh>gu&1*IXbzZSpA0eAgQQ?DSLms07&&MsJ%=R? z_-H-Zkj(E=XPD{W*oW6N-z;Y+F@}b@IeC==FG0lznb;NORx6d2=kyT) zaym$}cR4-}Tu=Mm8}A?MCwvuzpP~)J#2_TceYAC`<}XAkgsAPKuns38Lva~={=jSo zIcefuf~Oxs@Jj1~?>FfHJKP_e?TWH!od=e!($^~q2%;DuZ5G!W{?|jcsc8QeiTExt5|Q1^Z@l1aN8h8Sayi)#|9EG9%fu=w zs~^zpN)dHues9+jb}{J1rBGN9!>0=Kw<^R~QFp!s)Lx>yt)gGN4re02wh<1NCx+KS zvNU&eGwnpCXZjU&iYI~MmCmuZu|I~~qqNUn#XuYA9Sl@D;2F2QL??mud@MIQEWNi; za|Z2OZp{e~K=5aiyv`0s|5E|QCE%;V&e7Idu@Lm+{n9MZH2rR#_Q;AA}4{l!@-4N=YSW!Bgv5D^b_&4;47 z$o2NOmS8en8pw3)uU$m~)yM#DYmc<-H3{dcsDSQUisUZoD+FDLsX2Wzu9%o3^>Sl5 zrd~#tK~Ys7sA4hKX@lj1oYI(pPU2?&2519)xs{@0+^L2dV&iiE!|ZDK)^ghYaiRA! z-bE{ua1CnEhzTFl9YCdh;SV%df*Pi^yUazt>n|I?{uekQMm=XQyQCp;3+u1&=pfbo zC@oUmSJ3G@^l)pxyh$HO+(KIS4=#QUs{_BmYvkE`QxU0~Ji$|zhNb|l#HxBV)?kz% zRh6a&cPIElO%#5DqNA0j{>>FUdK3+yQ@%V6P3jGNzV*=LxPgfem*P1JFAR*eW)PpnkIKDOy(FYRE2!oITQbUSk zHIVxL3p(;#0&jbS9n{h9XiU|R%YEk*L@Iz7Fx-g&VdK?0)p9O!lU;b~FRzEK^1(zA z2V`A|lq{chsI6BcIf#C&&$e%Ej)V}n24{DB{5-U>yy3>F*&<_ruQ0uel}(oUsG(c( zeEytT(5S0 z_I+0bPE2Uc+MdbEYA}-Zy5RbC)io>4oXWg874!hy#uih1)o(XIvkG6!Z0@*07gc)B zp74qjCUL4_5+{n|2S>nTMVE^nvGY zY%M>4WT3cJ^F{(Z8x!J@YoHj8$?vi5pIPsLeB77o?MDZoiK|CLUZ9Db;zVQ|5}un# z%ME0@pWnXI{DQmRDbw=MM%@re#>oq?2IorbWG>&n%|P!?nbWy{l!xUp6nK7X?u7Rb z*9k$1wEE>*rv+zkLJmbD&d;Bf7!PyKW93MdnFi;DrXw850o1%C+M$^fc*!gDm?3NH zvN;^-A*g=PbRvV;ZA^_P+QD!qkl!c+DU{(MI#C$I6d<`}Pm3y)X2xsE{&u&sAzeb! zT5J4^p?;rHZX;xS!ie9u?yf8>&5(5UbKm%ukD&(cM^ztoS@}QDun*3_gV0-W5!aBE zfcO-R7UCR$X9|8{LCz2hnH0af7vwDW3Va`SFqs5%VCa zZi7RhIzADJzs1aej=M}u?>;Jhgmtiv7&I-2j%x_9lRRxu-R_eJ9iV)aT|N>3Y+%a7 zGgJW81h)}b)ciq))}^$x()}s2OC1|em?spk`?2QO5FkszI?yvNAK?h|hGT8{i3sWR zCP31$kJ=OS&o|;~c2IUvoLa7C5Ibq*WvPF|i*m%1?0<{3tdw9&eXOXDPa$_yg>A@P zu$n5=y-`%c#CI3y-e)6y%yvSr#|1{0#aiLrI`rc=o<2XIGn!Q+O9HYNtui$LZT;nT zn5VX~JjSFyda(iK?0`O;p8B{zwysy`mH!1<&MKe= zpgNJ^Knw_s29O8)TrAOmz3}UdGnb&@K!o3}{0>>NHvKr4legY()X+G4DTOlrCARo& z{#iGs*d(`-TWgWMN`zP_ODfms$&i0U*JEe(oKmFt@^Y@#ZQ+)cFzw~Ai?w+LbHhzN z$@W<44rc-o!A8CmVdM+uXLc@Vy8y;DEX;lSAD|AmL?r;jzqfnpii}&xLQ8f0U!et_ zf0=>=Lmt6uEHJWDxuE?Fs~*xae7?ZWvU18k8)k|$i3lVlW6nxYKNFjJcJSzd;{nqj z_d*hS`5m%sRvh$jp;v;Zm-*|Jv8YG`T`81+P|F*>hUcI#zVu1(PJ>YqMd=&inxIEW zqn}rAsYJ=+s#MAPX^;v~gKlc$l`Bf1yVfL5?A{A3I)X0ekSK>fvOgR@@h~OeFI*+; z+8h5GR)8qhZf+jw)6fE1qe((TkffT`6_l~Tm#cJ0870w(fU7kdfqOiI?wI=*5jCcO z_s1(=3I?j3AO))Ep{x=<4Ma3)+Tg3+-R|la^@SgF32Vq?ioqEVl=gMOn`WI;Jl7>?<;M zqx4vPd3dngnxY4;4pJoXm#+$EC=IcztAPH78a!gYK@u}C{U-D){C?3OKD4^uP zP;3xf zIux5c)2{OX`ld;Hj=+0!ul_xN3+Gr%t;2kv)KA)>A9U?=83qmbMi4+O@iZ_QG!pVF z+VA=A>9`)}!V*s6S|Ad_yo|rpqSYOfYF0pDmJ}od7mryDsd`!Re%~_Z8+w zzo|vlZ=`{4A4UInHtFGI#lJ$;M|ElPk|g9s;t7#!;u5)_iM-hHw4I4LWje}#bd+q*xiPowd_;p|N z8^p=cR8aU^*m!wB(P6x=1`L8+A2j4B2Ys2i7gz*gk{=}1vraA=-sgGlXWSI#fgQv` zdjW}to6i2_GgzxRI4*`;6&LRPcP~oIdv`Yku&YY!9&$w!Kq+)T&sxbBqHz3WzUeF+ zE$yAAOXN9EOc$$}L(?C$cOZG3ir3kPI15NLq5gk43!EY?$ANm7%8=c37UNe#@5!Sd zeTD(ok+8D?M?AIWqC(wEXV8Qm@ll&@^Bvf!G;8Sqk=~bFG7W`-v`h#q#ztOhzM-Dm z^15-DNmz0ImI{;WSTe54;#LO?!)L(hgL*=4deUG+-nG8GT-S!7gS$5RHjqRip1D|X zB6?0|6;uS+hLdCObvcR!^H5H3#}2HaNR$Pk553!PSe5`H@X0h~ah9PRjB?ig^;w3? zD~Wa(XSPyD?1>%?FkLEQT90G!q>!TcsNe<_7>~djJT?1e{8+1Rz+O2hdFb+qzj=tb zy^MDT#$@_(1N{xS;S`7{!ykQ3rcyPh%tPNo%VCEcvNED(P(ea|fa0fy#uG}b&I8*h z)08kHb@e29cE`UUMOhVVe_TMS2|8mK)d8&u;cF92vtT^u^c6&?urW1;3h;<117ixd z;fhnS_eZtM(9Cf&)}!7?1pGA{XofM5u$aOZ!UCVpfMpF0HMu9nYe?mthEU6@DF{UygY@M=dwA2 zru7$~Sazp4Uy}!5mHy~aMH}^q1ITQ0T#(|hVl!PAwF$l-I1eBjd?B!kGCJTZKu$(N zFg=C3=%5y%q5|{rKxmm^4d}99KsM(4-9Y1+e4i&6^=xM=-7VmPkHW$O=8&=04|-3O ztiJNWtDgc;g4*qN$E2YPnd7;_V8urC^8yTBdf4F3BmHZM+*s%}X`ER$l%{m!<1A3( z5GexwFyst<*6cIOzQgdjCd6x0oCSG68v4L%Jj+W!YEE@5;)Nt^FlZrAeE`4&%?_H5<3QlA<8lS4Sh=}inNnQu&n>0z6Y&7H&sOw!y zKsU<|KJ^hbU$+n*_1_2Im*2%EwMdZ}Y(vrf#4AI37+_k>SamJMtfuzR!uRxOZl3a?}M}tCwC|r!u&`o@w6xRWt?Z{cfpLE-2>8|#1 zundD;26|vLkyzt>9UDL5`6MX>0KV4zAaNLc^oL&IUgL--J;$DeQPea(E~k(FSR0bZ z0F`+JZ&brMr$Bw_<86um36FYC248a+h=SREZrhePKVxiMGyM|9%Q`RrZ5k7xNrHK~ zVHnEaXiAI*Mw`}5Yug>Y{~(gxFARQ{ehZ^|7)2?L?TOoe#$qD!I^M~j4OJq z8#V?phW+yw3|Y{3&>#RyR{Rou5S$}u1lmGt`Pd7MOxtBX#iY7ND#+4C`fY2InS7`z zt8(iXu!3D14AF2AYWKeuBj}UB@<9MU$)vEEW1D`6_{7;lqqvXtC5TY(0xaQF+0Y9m zteZxlvO4{8#+$da3&V1pcI%qU9wc{QhC(9q*3`NzH-wPetYE%N2i2SDhZ~B5JO`j{ z9I>Tk&8eTfL?%M*d^lZgroUre@4JneQX+d+mloH-&1vfkK0ON~C7@+vr( zv5O7bs>yXwUQAjk;A5o*!9hWc>vOR(2ent_%@7Rg>15!FXVyAMMi8Sg^yXb4sr)*A zealVCkz0EEJ2T>NzoLL6Le8iq9^p~^=PnXXEWQ26pO{B(wdeNWd(CoJ7n$W{8Z<7H z*CiWTILZ|N?-0C0DL&2qZCD#ax{!}VQ5bzI5JcGw-jdmZz@URNm3YwmuQ6MiP~$>X zk~|@H2QoJThfO;T=NFlxvD&jgb*=W~K|pxnq6#*dL)4|nD4I-YGEZmXA6z;U#dXE> zAUwEs%m9ZHdABYgIQs+e3nXDVr(rdy>Cxtq`;0FUmt6~@24EM+4r7N?DEcyui5VJw zrV;<2!EBtC5c*jKd+fD1a1KqVAG2f2p~@(;J`Xt&er1N-5sN3m$eq!PPf+()djEff zy>~p-|NB3Fq!L19R6-FFQFgXS_Ethf_N?q3Wt6gxy+<+>~{PJGU(Ujl`1A1jUUC}7q4Ip+?^RknSO;97@n7c-4TdBOowKf z$WC@D93+S8GL0e|QB%mcP5$Q~;k`q<=}x2A+bFUdO(amhi3aD0MlS=mDo3pjDtxPh z_+|_AG9a-7_okx(OB)zMk1f#&9K^ussWY-}FEpS(q-X^o4Z-}hxE(p7(`cq;(mx{V zi3diqde3t)r$71Rwdnld=(mfz2vvcecp`z`UdPFOBf}K`kLG(w)<{Yha2ve3po6H} ztQ<54hQ;9HiBYqjXJ~rg+g}8+;a;GZOhD{ho`n_Dew!vFy3Unfz6`Z%0%)AgnXclI zyf~{HKgdnR-H*Otc?hzCfi7gTpRe4&gVZ`qX%=I;@^ys z5wBPQ7&!;m_Q4=5UfN$&xK}<3K7{g70-bvuVr&o(qWynl9IT`Q>DMMxA;*3uuz80t ztF|WITYO6JEf2P)kCPaD(1dOND{j9&@KV+BodXi?3Kz&R zZ>aY|kcHkxEj51bpzffKEjplEJeev;Lv|()z*xkB>m;GTB-Ad;@gMOLnhx^4s`9<> zKif2XgdSR4@=mcWoD5};!_##9@Z>%Lwg){uW1T3iT={!LRn!tvM1|WD@!`JoLzbVm=z1SXAVM@7W5q zd_hfQWg7Wru`NMG2_X>L&-PmUoa~n#nB);*ucs@K8hq@plOR`bW{qb=}T&3>mvb})TaR;wo*$4QDI-b}G#%qj_ zrj?X44>BIU4asS?*WHo$gQr6eVVsc31Aph9hWNWig!J$X0GM0^V;$;&5Ou#t^c^WD zUTj8;G4%TT{GdRhuKn#x4?F@iWxoNw1FafTDRzvZ1ht(au}k%*dfSU@mhBA?rJ5q- zwOu|7!PI^!ZEjCd(t;lj1jK_HWPIg`LtFSh2;p>=`?1?vG$scy0)M4TwlLF-`XEV5 z{{|0;x^6#(SyVV#lF17RcO1vll?g3QMq{Nmb@LD(Fbz|bG z!-!F?o-A10gx6YF5J3I?N}Z_k-Fzj+r(%zxk`!suNhkuRDV8@v%nYjE4ZJK_UjMh3 z!z~2%0MVa`EEwwWg11#H6Ab=9RcTL5G>Xcp{Yd$-ladkzzd>{hpr8AcDSoI3Kr&w% zA`<)$A$1HBW)LQX)j6)6b0b3%QRs*Ko!}{|0;@*y&`+x{OOyf=G~$LLh=PKN!Y_sh ziR~#9Q{DC`#+|_b17kLY)3uIQ@g%8*27;hF9w|NeYSN|G6HMI|fO%7I^cjiU0lUMAIs~98_|up5S5!kZ^BDGi zGHQ1mBenccV_*Oe;$@7_!EUa;1)k1=3#3EAJH{zd8&}`F-_w-5hFPXzq1D}Cu~&Zu z8=N+%kbjyE8&=3hG82S4O+UGF(PR!J=G3?27lWWvbJ(kn90)kPurywOub`;i?fRkS z35-qd_LnAE;?R(1%D^*>ZDa!Mj4H)+^AE{K(Q`i$=)X_(Y|1%qU$?`1BwBBogxKVyioklPDMe_E00 z;OBwrLiSQNd=ncpvD-HJwbxf)|MPZ@h*3lI&-XuTzFQlOzs{X$u7~$OGT8rO8#{8b z`ZwRt8Tf$V0sSf_1UwQCD zi`6<>d6N?Mx9w+V;$f0Gb{4%z!-pj3@O81b_Wo%vC7p&gI#+8l;!lJ_O^1CvO3;l_ z7sVJxUrqM3U+zDU?72@%nYnIb;dl&Qb%)VX7;8SaCJoZ{i!^5o}Ob~*ZH}3j-cg4_MAQ?o1*_~ZctfxW%2i?;k$a| zlKe#_xBd6wk{`GvNR|SUlYzghaS)b);XQkd{9E55%R2&04;4jC;cw&j(dZtR#1`&h zRBNi=j$^cxnAgeMiNIbl?CVU*r~8lKm@_}XJ_nw8$mIc=%Xx`iM+qrN>9zRBuMi3}lgZgfC@{+d2z z+L}+0$KtHAh19pWPs*(OVS6!MP7{iQmFi#k{*2VX{$QCXrB(6`jPF3Sxb$!94_=kZ zPj+`p3d@z`yoGc9=Jnv8g;e8X@f((69a3>7wxYr+R6NYzdwIU^S zJ|8`X^+>&v+8yn9@bANjy=18w_=B-2Ph{zc5ADXXb;5}s{HAdq|C$x(I0F>jS&3N=Xd;{d$(VY7*s61uq7qP zPJr#4+^7RTGtWN*_qjv>Pf=BQU-|f#xns8}vUA!bsym99b_0OYK?y$sUiq3Tb78^i zi^a&6z#@V#HdVAZD0uk|p@$Wi> z2XJ3SHl5WkezOx^T)t(!83kWYcHIx{aLgqcyO^Aq$twq@?ab%broNC4YY#H-E+KNZ zxl|DDyJT0dEWGI)o*E~K^G~L@Fg5(6fD@7~CUyV(=Iv0<+lzDWm4(aQgRf*s;^Yel zHm$7T!N1ag)sjj7b;;sFII8ZJpYAKpUH^`1dS>%$Qpb`n{07qnVfaNgY?H|&u*;Go zKEi{r=s$BMYX=1PBE+~+0YS(9@Ly$u;^GA;=wYa)-R{m#7LpFrm&s?{zBn_pT{4d8 zJ~?t99zT$cL6YnUOlwb@E~(Cc_()ytSUI)+v_)x#$gCNB5gEH6F5`JSm*{+6KbQ>$ z69hr&cm<)v;xe7fx4LKL6$^EnnbxBlb?}+w2-;qptF`XdRv*p2OOynNRIpkzAMc7E8&IS2p4~?~>2{ZsFZh?z1S?*4<&%EF+j|CQZ(RXT z2G1ZZzC9qmGg`3bB{&5elo|1C49>$Np#`FzyScpuR@3YI_p<@V2r!u;|8{c}ev?Xc z1-$N>5Qg_zRs@O+FM^)ghk2rZcvZX&e}(JuZcP6^*uUwO>Cjc#FE9nilq(?sPRlz1 z{%`TPlcy1RQC5eLX3ljIWVc_2$gs~={Tl?Lj0!@IeC?J*gGZob2Cb$f8%fW zyZ3q2)wevRwkii(*)V1XV@&t($pe1S&@m|m*Ys?kw>6R3@N_5{(*%m4rhQvoq`?6a zJEJ_jBtCKHj{C}u-Qq%@NZM6ydZeYs{R`Qx+3Paj-0rqTOTU{A4VD^pDML^2H03n! zb0W+ox4-FD&1s&*JH1=z3FrmYCwZHV~kQpJ_!qgXM3*FD~ z+~B?_USfP&;iT;o$PB^ta$>$zKlPD^BzJTBtx*fw)g~poLTSy8ae+#Fwup5CV{<=F zpp1eaBc1ElKkmO*9=fEHC^bf3ygxvIp}h9j+o+FE8I+fnLmaR`NlKI%-Hk1XFSmNr zN_pw@+@KUDegyfRtL(0?KeJkCyf%3*50c!vJgG$_WCMuZ)r!9IyVsuRf#ktvk-3*V zECQO|--%G4C2EgmXST(+-TxEeeUWM05+f{8>AZ%)L_Yazy)P}z z=UpZ@Qec-;jVSnZwtm+w`9^>n7;J6boO5cg(HDiQ#XMj`Tm~l)k*y04Cw-d;8Vq4F1u3m=lZ|^_LHNXLf0nvkyr|V0)g54n#g|g;c0#1E0&go0$h@56bZf!67U7f)k3)!lkLi$!on* zS9rmuK9XfX*mfKJ639x_v%PFRxE=0(=gDVTj88K@asj{u>Lp2{};hr@MU!GjNpK|hz z41lv^4^K|lJt&cFg(IKMp z%6!cy=5iTNe11(`Ks#PLmh4^KF;*7>CP(Tf{tGbdpN(#&t56)(UAUjMHbvWVGuL6gC6#wtop6{XQebxg$aixP`#7Z1wD39bh>a+EA9Jw!dEK-e zUy1f68I6#Nunj3YVR()W^c=jBcGDrXWiz;$ILABV3SA8xAgbzA2DHr7&gTGDPx*u| zUZmM=2TWiN`4V->ZfYH#O+?{ia%*P59&_ne&7T#3!1MM-8oZTL$(|mR)1|FRV~4*& z#UKJ#N!rft!WP_&C2W*U3qc(Q=h%>Sd(dC>a6#DBB|3~6!#_M1(j+Z@F&|g#kNLKT z8||konu?f&S^>c-&f1IpnG>KC0Z*B>UTHi?v9bTsONcvZij5G~${i005&!YDqGnL- zLc!+&I4+8hKGRPm#v;mWFdEG-zK>1w&!-!8z8zO=bNhfoZpZRVDeSGl6i*Lh7eMJg z75#g;q>&c^z;+L72%(ozu~VbJ%tg!E{Ng!r@YQlx8U_xB)(_ODFlxvCt^P51^3;KT z#ak%^AH?SK{Gk$>8cN)-lnD>yr%nhF6_dScf~>*Hww9#rlEj}mXKALd1Wn*e7x_M9 z#kCVT=k4^x-tZsU z%v6{?n;j!=RZm?!fT8-A{4*7GzoVe8F@vID+g6thhRR|WUCk@p=>#V+=Xw0vgF~d* zaeCb8w+3vM)yQ-M;kdr;`0>Yau1 zXEcqliL0~W7D8F^jDRntDR~r??LT{ibLJt?$^L4o@DxeBoBax{L?osu-%`xAb99xw zP~%C~4Ge}v_HPQ*T;85nnUqfkkN75Z0&}f+uT*fqgS~Yf5<|(YZJFd2zBtFkEcBiv zt%M=&WUtCeTz#D5*i?D%DhJGU@l=*Mf2mB4W!8>5=`H@o93_uwVdRz{l@78WK#fH+ z@n%X%w>eKskK>fPnU!}0`8si2g#2L`O~zzjE;l}`TrSa7F5jVqd9J(t_NZ0hr(sGe zDM|-+?AYQC0J%JvO_BLmHdvx_S#~9B{)(?C4XMI^(a4&OPYK&UOEYANP=Y5i9EGY_ zk{@NemBk8|KW5mWdN9#9;~2xMbE@nH@y!#29vNZ`6%{Hx%~6RpnsD6b@fb_Gt2^t^vZ{F0zM7RLK;bQw459MCwHT~)!&ia0l%b^~eI6EFn z97+!DDiOhmv7K3b-GV6>9nvLM=7@hgL3qypU4V*svs3aakp6XJ5TKIKktD=13pVdM z{20$5p(P?Sep9lhz&Z!5;OtU)n2f~}jwmol=0Mtkg)ZfDvbHry#-qeXpu!p#xPFa+ zB>jnzBF1Om(R#vc0$6$782`voCaAeT#gw@Cf7be$_48_oHTx6*+x$ViP3{HITl?&wte?W!%qa-`1i$3>)qhl!F7Osi#Q5o2Up7bJ5J(A*W8<yZvvPZwsQU>;C*jJ13{tDXX$Lm$UD@P*>s~XB2{a_P;NdMt7-ZC zk>z+mF-l($P7Q#KQ*?S}M3nlQX-UUQnC5raYukBA)@Z5f=LkZu;679_VkFi7t(s@_ zt>S6BJYWyhicsEad=7=zjpvp!s1jOvt%Bv)Ky*bqEG4!K9lZ$OZlJ`ZT8MbmN~?C| zO)dFq`Zt8$V5HZp`S9#4IGhGbHFqk&gqzw<_+XpH#}U0#@I2?5u?^(o@7HTIo&;Wp zpHxyeF`Rf3#ZgFgkwLOY&bXs;#sUu&Uxqe?rD)Zb<%Az5J8AxbiRY4h<$-u6f*Lp{@JbD#{u(@9!Pri z9WsYSC>SGOKiJ^>oMIP(Ek`hsKLFYc*UM_^9~8bJ#FNR)fXJUqoaiJSs#L41l7%_x zFeJ-R+o(+r1FHJM;ds{~StaMZ%OQ#gi)Vxwk}H3MuqlE^+w2c)Hac5HBPb>7QN-#h zpVIeN68=2{X`W0k|7E6lm3)4mK}ZZZ2rv*OdC*3{u-GzB|4_d z2)d0GLpjOXp5j$`^L6tQW;z#giIo6AJ++v7QoyykMx{v7^7;j4=!P;uP9Xa0aghq~ zqX6GJ-FHKBswb)zvm#Hsx##1(f*~hCdxZF0x$1ELrWhZ#2`avl23Qx{?J;shP$Z@3 zgOjt4qFBS(=?GP|UbY<*5q}&rHI$^MXyyGT>fj`(ICh>MlWrwYx;eH{2Z@$LBu_5? zh4g7Ebt|6dSSH3eC9FfsHx{rh`Jkl0SCEhGb{Ia+7EOG3Qj58M@uq5cvm)pwMMe@RDamzgLTK+~n-c+be0q-E^b8h)R=H$|q@VHCov|r;3vg^%`XN@Zy zf&vaM8qPtIs{4SLYTPqR>?t|O|EzKY-Dzo`0ia+1BijcsrphWNo`iUW5m7VF(En=y z`f!)TWpOJjK1N&oUaF6lTF#P z+k1L`9CPU;GS%bR>=LIhU(Z-G+}G?;w+TU%dZq)umi@dU6n^dfsJfTL_CU!vyKzuB zcZ64lG@+Xo?=eti)?EOM0(9BuN-{js%$wB)q^Xq1$N2M9&l+$I21zZ7GXB59n6tVCuauh6=Z1RO^9-1s?JL{0Qc1NI2X|3kt`&$ z)q)6{rq>U2)X+16*a{SVEM?B+{`UN)m6oPUDVH<5fOx@`+gQFHTOoLWu@yM-$s4Os zX_lV`#@SH8`JL*m%fDx&5KEbh$$6&z{>h7u#PlZ3uPnI1TR@3HEZ~oH}{@AI*lCq3?V7k*vJ7_B8(yPzrwz(>EhSj zIy|;Su66|QJx8ZdS!Hd^YX^rds%b}t--%4#T42mij7b ziOjPLa!t=PG_%DRXazHKG?t2CiB__6nNqb)iQd(9vGy2h#zDYze^vu#=su?!2B05!uqX${T* zNM-E*AS?+=bkKM((8m44dE{^xMRLjCkUMwTnx2a_5j4E*LNc1%cWiA z5O|7))GC>V=KYc1q+C!KJQRAv};hQHIS=*kQ?7Xe(GSn60E4> z1mxHo?E5or$yL*u$)EKfW;^c}$b1lr$%cPm-ao9tZBm}L)A0`!z0n+3vbxHnGJCA@ zUcI6^R+;8J$?x2J?n7d*zyE=RsN?FQW-E0rP#8Mexqsn8{OB*#&rp7JORAbZDybon z$E36Sc?zt*6$^BJRQ2rxK50xx895d`zhwYqD?NJeQKmv!9q8@h$ZWCo&}Whuf^BdPoNMnv0V&&S+$H#e|#T zltreT!y?pQJ;YK_mV{_mr^$1D>Oa*o4q@af^h@g2|3MMYaOd^E)advd7j+}}>!V33 zjnQ@o-GlW@?QlHi(tWS09*=Sl5;4S4^X7%T^W?@h%BP*BxBM8!T!C_R5REJ8GN#eedcHL9Z`Xfn+UfNaR=Pd zQ}Wj?b?y9&(}{0=5dfyDI*9RE_y@UT5w-Fk7RW3WLnWW;r@z0{D!no_b)dL#;X)tv z^lO}5!lUVxP7xnCP$yw}2Z8A5Xqy`bR~KS82t&6V`JztM1B9%$ii{5;8DT{E9tB`b z!x=z_+yu}O(K1(p2UI6D+#;cD$Z4L|Z`X}(9}imS zi)E3PXjkUlAqIki-hD2FPw2&nWsCB4i<{~^ZqGk_Cz~jMJ5K{E6TA--2G+UTJ$xoj zyW~#2(h1Qq;^c$7^XZ+x%{{7zJ3F!ZTdyCqwYLu*;LqY#C@Cqi=`~uW_4vK*%_xSw zx?u6nx5bnbcs4HUl8%g5JAJ>V)eJ~*#1pYR%sKJx8t`=4F{slNgW8R%Kd;1N!t}-p z1nMUUv)rN1(|*6G;mgR+vLFJro+J%AxrH?#Ec2VzJupowT-KY4=t1`o@w86A90vRR?_tg+$3$=_~v@lq;}Z}s9C84FgK z4cTI>KTAmIr|w7U|LW7EgqZNs{P#YY?|7}jJ{Uc17|NUFFU(W zk>yT5qucU$-Gj4UyggT9NwiZ{N;7S8SgbjVIb2S@KJyOjsxUN&aEKMKhrb+4A`=5? z`#x6i1x76ul^X5);(Gy=Lk?Vhsja~-05@-zJp+L&I|r6vreIe9zVmLHA#FZW#y7uEN-+=`D!N6!E9 zLl{TDm(Sn(S5mB6*wKro6s_EGkOyX*2{0!J{~q}mHWMrHqWCz*bk4`iW54Ygg;0QE74n^l{E~p1w+qv5V#;hQU z!(#u$!bj0n(PLF*by}_f{s1@50uzD>GXqNB;#K*Og7OT}84R2B)yM5wus8GTUHdFP;X!LJdv z$GHnU!S^r1yjBb$B-26jVlrwl4nddIrdW0jKIo*ZnCv-&AJe~iA6n!;#EqHlZuOPZ=#<{X0-R48&QTO2tpEi5B%u?A6J^NMx zF`+FsoMh|aowo0E@_2uMDnNx3Gf z$kOO(-cquW<#J~{$R&#Re7CGl83L*L6w1$?vC&5%UneqEGQy@kW3#6$TiI$tP*1Y4h;pa&V3mBF}wMdUXSZIud`O)mq30KQD=GM zN5SC@>Jz7^@~#cU7&)iqHq|H{(3%#RgLl4|G+b#Jz7p)_F5?>|k4uW=&Mm7~3b`lI ze&5N{ML~>F9@s^u>Zc_gAA*eYyEpNuj*JxXO ztcVDhBlI@&tOzk`|gr4On<46kT)ySSS6NV z*~_9BAG$r>6Q>jBXi}isvfqdJP_bC4z@Pcrl9mSACXJ!^B zVu?>_`!T$X_VtyhIm+IatuBh{(W+9`^TuaF7vVV5Dd37Tflbvzai7{29+?e4M}HUlN2lUFDBTL z6i=M185|^(d(;LOvG-s3M<7#m;=Nae3@=Z(S9}^QqjgFJ4V|BA65na$LY#a*a(dx|T>}2ZRTG*)}864g$Z znQFcK?AkG@y}E<1r6|us!|#HV?q`q_-3<*lfog}kaQ`A3KVztfpRDH)prC|Ud>eU`cfV{$Jv3pY8=V(ofg}u$CZ%U zu|GxaqxeD=iUKAr&d@dczc|YSC?bG%BrT=++^mKD zfv?`x?<2n#kdk-ZF{stc>I&z~N|v5=UKYMCoe=bkJ#L{oY&K!5BSb2N;I7N?wEL|9 zn-5$kZtCjtY&6I6FFa@4vL2n~TK=TcS#;1v9Eb?#;|k3`?|Ck&PSyzW_*!K+f&{=0 zsme}5s%fTAa#1x!y@HJ?+PcF}i#%U&+mR{{LB2CEm1_3L=!8-|ZPk^LQIwgQp9x&f z(5#7mfa-lQVI384+=s{(g;o~ba~^pH9Q=N%nQX-91EE_aR8pNq47ULasA)n6W6>^~ zkNPrqBRRA3vtxpBWG6#suRqUz```Cx&jkun!ss?T<2|gKH~2Q1KiB&o*5#UBrqPI- zF~2z}pxN$lHF!9wIWa6PW5E@r0UR%?hQS2~?IWJwR(Atu5S9N^wSo_-tT6U9}}5GNJ}H+}I}N`$6#K>ePfC^%eaH zQPVQ0eF}fJZb%k9Z^zGB#uR- z#$jlsxLn}8++wao085WuE#uVA?zqZ&QNCUyVXGPZ=BM*phaeM8=SuLl$Joj;HA#o^ z@Q6Vnz5Fv~d^vAk6VdWB=zYiy_prI=H^89Cn6=;w~{=wnQCg zdk7;BUfB6FBZl3+zsN=1H=jFZwcbJ&yE>E6@bG#;H&vGkU9e8rz_!WcT*jL=djXaQ zV{^x72XZnRse=eU+m$L4xR91purq)E@5k_b$9p~=8VCOy=kIB#P^01HiAUzN!&DB^iM@Mz9AQAMDIK z5O4X7egI;o^4aD47&RSK1<9^NBhn2V-NWf|#sy!|f}(y>`J8rcNIVv)P%r>#=_aVi z>dzWXSoaG1)BreI|Ms_3X*x>Hkt|`2AAV2)A$3O(=q8^xh=;#FI=1=>ejmT_6ns{q zs~uLcFW%LN+e{j<`me^$`+e{)vEp#aH7!H{??v+PB0Htf`yBq0n%Uy4 zyepGMw5uz1t%+e72#P*U%akX7kqmUyphrWbjbjY`yYJBFKX{b@6C{PW)1mWEspCS( z5rg)<7$bjYhfgK%nx zb-eo2O_f5$_ZDH^lhU*hGBS}g*)E-LmqnFC(ja`3Q=TuU3TjwvyeswNEY~xk2)1@Z zKTQv$1Qu^VdL^gi-0+yt;!OFnOfto-_4Sk{s!Wq0qQ%%TW8d*Vhbmzt5wqX(cd^(; z?9Bhynb2Gg5nk~tE0}LNtQhUmUnAZzzozVV-mvgsk)2Li&nb5`ytze4UsBX8jjNZ7 zdXhNO9sevNWL_ob9P@M3nrBh(3JwjmNy7pc&fDqZAXu(EkAf(+%XIa?|FAq~dH`~) z-4D0JM!TJCA8l&GXLF+#AusNM`wkp>R1~wAPOh{Izqf02S|(TAE3O#Z*{KjdHQ_GO zl+P8^2<^E{M2#IcbbyAm5pDRL0y$&VjKv$xWwKv7t}}n73d0JtG#}2R{(bl`E=dPy zn)mj1Z!mx9DK2PQ_@wd~^~e&pAO+(Y@SuCZhn7BdCBbzB1Qq8UDj0n^AN`yt%_TNcucg({o@uYc9Wfc7(w`Xr>oJ8m*FDs}y0c^vEZI zR7S*+>Yvz^qEZ{JGzOGzyOJDO44Z}WF_8JkQTYA`D5a%KjR4TARzK(PJE_b*V=e2@ zU`&x0fL}0E;CZ3?kmo95j1AeF*wW6iix)0T>R<)EEd0VRT%#?ri6+_n{ieH1&%l() z+;wt7Na{w;RHbGo@yYAfo7Xc`?Rkt}%97+vu~0S{?_(5&u5e+`0bu6-64_x?ajD`X z69#5R^XUOH3$V#0iJBTBc6O#uN7L@d7b{vA8C}^4xhI0XRgm3d6&HMBv6JhR8RQ4> ziL)y=r*t7aUA^&y?$rhUxaV`)_N_r_@A;(a$8dZbQqG);Eaq=gIA`^iZxGwE-@ZAIleJH}0F^ys_&HX8jnxV`KIvnHNO^%* z_=odxGabTwKur8%wmj|k61Ah(l2$26#=^CR6VtmNGs16PVxsKE1L21i=oEhXzZ1R3AddWlZNZO?*^nbv$HC6&u`VPh_H5(PSfJ(tV``?+uD#)fH{;I4FhR-+?p8 z=$%(Nd5$>+GD6yqX;2f7`wMG8UyV+$W^7j2LwIM@z8`QM_XU#wkq`W;ntu>=t<2yQ z4(Xi^JSZx0Q6JgSc@Avg9YsY&ftIQM@+eNgQllofxJmP3oBHJW_T1pQFSvpGoANc0 zo!Q~CTifbc=r=*aPs z5_}mh@B(<3ROi3o#|saBcDs4Bcc;59La(4|+e}_Z_X8>`wX_fdg)t59;*l6qj2eQ2 z%C#sLbuYKj1%HL40zl6^w zBbaj}GMp@)uK!gV?W5Jx{=%`M08$rMZc=-wF*ZX2_?i}InL*Rl+C5y?5zRaInP2L_ z)eQ{h&$9g0D_V}!&4LFqGTQ8Wtx5+4e!l52H~haW@cX*`*AI}MgUXQZv$z{10KW$X zUm^;Y(_DT*WDphDX!GYF+hRiYWFj8tBA}JMg+vBKm=mth4}_OUB8jh7W`~SO@+jri z7QlTIFT2m-z~Hswh7N(QYuPRg-&|fAjz?F494;W>pegZ-a2ew@*m1_nUz6UcHpSNb!G)LPxfJuEDx&jE@%YEL zpfV>ptKqM;Izot{ef*b1(}J*NVX_6S<0$$AcJt}!+l8d0q?ymQj0(vu4)vL=-+bOR z6}u04gteqLU9Gvf1yO|TWo|O!xoC5BX8Vi}O zfTF*b*G-E_Cwa)rC-td*i)M9-^)BPiZ}~k_)h!Nx{2m`z?d6t)ZhKVCXmvm5CcxbL z+nVrUBr~pNaJSrf@1>WG1s*!p+GdxBrjjF*Or_^5DEc}-I7FynpuHyS!dD?{mFTZk z;BP_^-XZJD$dh2Ai7gkE?CEkQg+cTAJC1&Lzy* z3VmnLm(~vV)Ra^hctsF#zRGj$EN9gVX%}<+v!$tvUS0GUOXhz4ys+D)L<6tfTt-UW z*sdUuH`%Xcv(DdDBmGp?@Q48j2giwZyo?eIC^Ii4|QZxq&>-4b2~#_ZKo@T;V>gIARtrQB^$lqM2fLH_NBxo8Vr}X^Y>*o*%<~R?@-c ze`A|Z%8N(SRbw5HB#l)#f^NMCWL={vh0+!?KA zv(pQ<%)52tSpH3WS{??y!+Y>d%J|WWBQ+pqM=ARm#XzMjEVZUIZzQ)xKOWhnb#Z*m zMn~I>Bij}Y?EZ~A|J{#j94U)fv^4v99hutKl00FQPx#Suknj8*RqD9c$t(^%9Rp$< zpRZhsKlDG0dod$o}G_&E+izFc|{u0NZ@ojI3<+nBzqcjP%)y03|m-KT)XwOQmG!16q za`G34`$>Ky>1AChsCygYZlLzcO@X!DZNzpZ#S2D$(^}Q`1Ru{PGK{TAs`dcg#+IKMEIiSXQ>r*yFay-{pv4E zx%=3=_I7yhg&tyLE@K0aBav8|#Znl;jN&wx>N#Lt`^VXnJ@rFlNNvxMnJ4 z-uL)Hvb5FqT;zQz5=W$y3bVqp7IJEZAZ4=!FJ7>CoOSAhI`P7^qi|060jzG`4IYb!HYOJ4b00q{SQYu}mD;gX;H{}TVSqQd9Lx|b$e>#M3<6yNUrD4AKH%P zzAUA^xsURF0>n1aak2+7dM@QLG^# z7mboV`K83D@h5whN#fd9P+`*0;$r{fhAhef29i;6I0RfS_Helf3GNXv+@J;>j7~U1 z?{0PbbeM;wrAoYvf?bvD_WfJ&cij_gweIa=ljk91H2$H_LlVQnS6Qy}#~B!Z4Aaaq zzaFnI@P#qqqxV3INcFY1QIKoSxCO{;Ezzleb;-)0)JR3bl=ub^cW_-i@z!QzW>DsC zD5Z*VNFqpm{)N=w;@w7=0U@q??4ZNzFN4Bi+*^So`D`|JK5pcp+?@uZ6-oC6j&XNh z@gKX~C$*Z8G^eujM(29^xi?llyv4^>oeolZn`fE2JeXIS$aK-?N7Nxwlny;MDMWP2 zsaIN~{~@gmyS=I_lr=+Zejj%dFU=4$3g2Ypi#K{V^!BKLwM}QirBkn(xCLZS&YLl^ zUw<3qDQ-Svee6ljebh~5?~dgSVGTR60huZuFJ7b%&xC5cMD2d-Y|)$7=W-veEg5_W z%GlW0Xljq2yBd;lVTo-lG15gKV_yk7k%^15PW*bm+$Yf-QrlaN6c3oGH!i8x(558^ z4e_7G+73#TyW1|Q7C$_Ik(~8Qu0$2!P`iGpsE*zAlMy81n1&W1 zNIupS@x#SopkJTxGva-GgPo>c`m|U@QISa@dC{P4A)7c2v!!*(J4&s_4j1M{JC!fY z90JQ1Af*V^TaE2lHKHlP{QUR^H}QK{O+qzQ!A44oVPh?PKpE3Ce-Yn7PHPp*d-Iy~ zdW@MrW0WJ|z1H^jQeDoR*f5EziQ@RcVs{f#=LJJ2A5={$RZXqGiHkFa*k_^ zbpK*nr0F|Gyl{l!+O%7C4c&bvi?e}#?(Ftom>Vl2a4?o@(fI?=jAvKS%dIygLO1c* zC>x1xH(8YNQ^a){u>q>g2mMN3GMTDj)6A1y&ROn`Jq`EtWPm_fA*reh^zBwNF){3? zHi=;<{;#}-uLEwtmN)@f_eH?cexD!r=6S1&P#>2s9WaGQ!b>SAQhENkptD6HZf}>E zt#ogfQi*fjP=ZdbZRR)#*{e!4iH#84*BK7)s1$Od%Cn=iMIsA%qvpusnV*-0sLjq^V|**hv~XGKZZN!V=Z>V6-9s#DzP|Fk zAggsnNY|k#{H%rtY-L7ONy$+dTLK}`21EMbMt{JD5yq zLMsj;BjCYTDIA6A6a3}5VN1=mkg&OZzi^3XPB&Xb=cN=AKjj@rWJ-tk^b9_kNTK=L zDKRz%s`>IUcWvF>35e%mxyzsntX5VQT=0YYVR|MGQ;pj2C#2FS_VyMwy!78JfJ}+ z5?D9<(p|BC?xQ&uba5e<_jhe)3tk6Rj+viQJuh@V1GUM2wNzy6S~pqHh{{-p@lgSe zi$bRiUXe+EG7squv}x1VzfGHSYG%dVdBNv+)_XDiJ0RrX$_}N=E3fd3<iLDke4-fs~f`Oc;&? zL20T58cYHF3f;hv2|{?Q0sX)?zb@z_mZ;$O3wpOI@)3LuwrQiVX$?3P{^@8lF~!`K=F`%- z=bV0hdNkucX>2d6oBQP_8Tn+iP^p>zTG*0Ul;BqpHgg+GOZm0AJf;V+FUh@Ri!wyK z6n6yT!n^W0SX-LXXUzGTi|?e@xm>T#APT%?KhjL~lRA#C!yDL4p!VSIyt%GUHRBjxs z)}tr?;7)38h0kmxFCRhM4H2fk;TDiK_}3Sp;gAHDh>z>x2TnxsJn6%)yL&?s3{NBkZyd^m|Qy9Z`nVQQKfig zRa5IRA~+@v$iFZD)%Zc)!*kkK^iU2&toZL}2CVWmjHsUDxS#H|<7QkTY|i$!g8$lSXhinbm-bKb);ULOD=zq zMQl;ff>~PW$>WR6Fx47O? z!*0pm`~LlT$G6oqbUqN!N=j}YttEt)MF4xAIS&&<=?$76ohL&vYO?t8my8R>XGAb( zqHYCCr#&6F+N$}}6WuZcL$~119trVE*i+x>o)>^unxWUDfaGzw4J&WovV1T1&B^l& zn-1^Z$e-cx?LQD-d&%|cuU^TluFvI64wj539Cw;Q5qZ*sabUKDs>aDxMdfj%pkBxC z$@g+jAN{nN#}2(7$ZzxW8 zjpFIT@3TjC2shP?-PH`7nNJO?CEAp5jLuM6b-7CMv5iWXXd|re)%zl!%^CXs$IWz8 z)pFD?V}FGH;TpTF=zgZ(h26BZbMe!YIVosYCg@YypFi;@SM23_PZ=5l;dsn9lGVp> zj)@o0QV8k>&4y*-)zIU-YehiVhK&zj&Twuc(KKkHvAGeMctq2{%DV92(6wx><{vay zRB|fsQ(Glon{?yVpy(IdSS)RGay>!VU@xl_s{u`)vO6?SKi>EK?C z&$VnZR=(lb-(4D<_$pxYsDho^&od9;5ti9@^*WPzCq5pRsTPsZfqBZxL)IVHx&!Z| zd=$`tDYkN`F?vDSocbRVV@tW|KA$H~L_5^;8z`TKyanJtp|}a7aIeX8@VsUIZ5Wvb z<*eaL$Yxqn>JnSO-rUDHF$Yg~#M(FGRoR4?$h!dap_Z7pvgw4J3H7c`c`Kv`^BDoo zOYqVg-#KkC0bo}n^fKvOT>AS{C=WhbIqNv*D|ixwOhZ7|ko0{aPofA*9KW-uc}^z7 zj$J+|F4%SDXqp?j^ppVEU6Kx@J-g(pmD5HKV2t$v*Q`;AZi-ZIkalO1rEy_E^8&dQ zJ(fS_5l@8l%unC6`NwvbHl}zs>~9IQFjfjE;wUs~3TcnQv7Y)~OUksV!&5Nt$TMNG zFXmxdR`yM#9m#KqpYuF#@1457<8qElu)GSr;)ae}5{iE-cAjqYclR6G5dNizZM`4g zoKDk5V*8Oef&ZDFZGw~JwDIx7FO%NtMB)In&lC^{#R+@~H$9tt zpLX-wYG`0(dZ}{%WBp5EFMeF(6mMlRAcOx4>r1W4N~5?wd3chcnmX{u)AZq_1>j9R zVG4$>D`-q%&enY2lmC!-Jzxmu=AwY6G?V%=?qht=`yh~bnO^`eUiP~VT!sfs`$No> zNYTZPJs|skWc_tml-v6~jt`=sQX(KK-AG7-G}7IO15z?H3`ln

    za32-af6jI;M*u}`q5K(?#5*89hFl7?l<0p)%79k0lvytehxQsi}>W%ljSe> z$cv{eFzIh>h$|K}jSz#ql-tz6?TaIYW5#3$5z1)l7~rcLgY1FvFEgu=nJ%@FyF^J{ z7{A#ySCt;JyP{HO{nk@?E(NILw?bZB0F1B0-0}Bl8ncbu6~CMYzOW0yR{hwPh`+0* zID{|U3k9UfmnQswP)vIeHeHVI@2%P9qG{ZyKd2<_D{<+Te;wUkm95|PmTRumWS*4t zHH*)EbeGr9^O6Cfvmg7WtjIi@AcV^*r-1IT);0TLC)g?~3EsQ$(Bm9gwVh3+?dW=` z#EL)(#)J4Ay2nc`0lJz)PaD?5hxjZL*`V%q6!w)FS$|~$JcS@{pFH5WPH(9ONKx*kM3h z>g-X_TI$p^IY7A~&?Q$`g4Y~@K8^3IU0?)8D<+|#{q&x)Yd#)fN>aCK z{L*>R`-Dt>T_iJTWXh%8B%$GtvOWe&-@0V;SNspMKL%Px0uvXccpBBo-y-@Rtnt#n zp$tg%?$Wi_>GvbB^8eg>i{~h}pS^Dduw?M8IgHJXD_TpZ;my-x**D6$fqS5(ny(3O z=ARE3HzuA_ad;2v`Vz1Fur0zkOoan9znL+xoH9osxXVw-sOeSW3X}Vq#Mn2g$iFch zqCSA%varY-NOg-45+y8%-p zf!^FtwXdvO*8p9aO(J~-%2zcl1pSJb+Kx?Xz6Ls00iyI3aRZ;wwizafb^P*q2~_T| zw2v?L7bwG7aP_iBfPGvhM7zF=FJ8EqQ|cRSH>MHjr-}2|hSd2Rei024-sIvFC_Dc6 zHjpP?RFQrc;=D)I7CD7HZ0>tW8415|mAvmXS@jKX_E9hRO)T@MslZEUOv<&**}SQC z2NSaU@i$t=yx_Smh4p+Y0_F4jANCkY%Ewu--gT z%d78bY7%zcZCk@-y6NA=eEw5GZ&$RxAV0x91$8%|ksfDtr)gD3o`njP-i zk)r&oQQ$J5TjDuM7hhO|{=*GfmU75XJjfLfZ_35PF_wwj6+UrRoYr1gGQcFlVajpk z!nDv~+PEjUxFFQ)>koz!AHM93Bz`CMcOS6ge`kSD+2CAvS%f~}Vlf_803@y8#X zsc&0mk1#EMYDyTvPw%>n2*8e-^fyLp?_}Kilgm%`qGl_3Tu8=gAzoXk=7>DEy4md; z$&l$fD<5sthOn;=8>&M127v~qy`%b>T6n1oW%O_TOdFwiosKchmxgw^BZ^7Un`ZYE znh~G_Ewwo0KWmsrap&%XiGe%(*+ntFigu+gg$4{MjIyCiy$c><)iJtvUa)_cNcM=q z=VfGEj6w)%{^5w5!io!fEwxs?{`{S8AXB1{LH`46g`k1-4;9y^xdg|9cFX)SwmhO1 zF*4~m@d5HK#?gSd;cw>!Y_jpcN~LoG37C zN$Gz4-l)2Q)NJ#loyktAOf zvvE(0(=%|`xa|=k*x=OA_IWG&R}dW6q{%$x45ro;Zv<{)v7%0gCCO$+DJ6!V*5<1xN5P^sp`<0S~Ex z_+=UZ2<3}xIz}L4f}uw}D;q?rNYhPL52%dFdVu(;;wj4gZU)2sS5pkXtP8`gZ;dTA zfihk@It5~;#F;N)-~0!Uk^&bVc^KGE&b?jh^PKNU3;7{3WD88~PRBhel+;%D1gpO5 zQ4e$2kNa(;49OVGe9PZQK<-`f3W18`>PIZ2>v&~#B0anml!+4kn|)+FyorXeO|_2u z&i4pEynBxvf}bvMH`#<9O-Yf^o=QpzC3!KNCsDSUv3WW>QY9@=2H%VG1)qxu7(UoY zE&mwEx>}V#!s@xh7*)SLrgbkmke#;Cp&DIeO)c_;8^%LQo~euH62ZvQN~)6spE0=i z6He&~7DzUkONrn7vEC_x+{D(HqL+m8dkN%4vi_Cr4<(oakfpdeZ*LzcM%_!<_`lA^ zeePh0?-15iQYEEDALd*pe&mzpEU>~1KG1Q++!!0xBqX~=X-KbS)2ad0IZ6#&m!l-2 z#kl(yZdbT{I6Xb+;D2PWBm?uCkKU6&T>M%urZ0{nHppo)-veP)h*D+>Aw{a92052u zu56EF0c$?cod6bFByo3v?INe!jKHgBek`kfIz=LzSJeq95N|5umr^94S5&MG@noJu zixvAe3d|F3Az~M9{{Soe1c>;4FsqioGOX~A!0$Ixj1RcB3?^S|>n`hLeUu?7dy>zWgaXBHtvTsJ^9sbMDGTvRp}Yo6wJ|GQ@WtVQV}b zAU9*3+}`L;M@}&CB00f?U}Lq56VZ9I=4PCOJm1jU$X8IS(XiZ@7sW6#uI&OCl@fSm z5+((G7?;S6pC)llm|&UvYVf~r|LBh%m#}7pk7MJVSA{^U+SU>uNZmyz^KVecWHoER zwLrHc*=IlM6RecbdHaXF7}YeX_{hY}+2fvBT{1pPlDam=#4!QV?7j6;!V2p@fkbi@ zf?ZH|15KfR9$B=BqX0a#RReAVE=HVzF|8`UYg#9=>7c8KS1-mCn> z8lX-X(B0*ja-4*O3Ib0P>9t6cM#Rnso z0!HlWAnF0Z|7p~fC_Zq(i2%U;z?G<=#e*gEnki*!hh~2Tm_+j7&useCzo)yq*Q+-5 z2_%CBdn{`Q83nqIGor&}5T~;&Sq16TfMdPm1N*A6Ypc4Tt#2DR$lH;P4iiXFSV&HT z5i779#HePQkwJtFxueI`Q}4!3ZAv*1f`(!9 za9fJbGU8nfh{Ko*Esq^7Yh;fBP0AM*9qa63FGv=Cvlb%-M$Mf+8xdUQ(@9*0dH#EK zBfgi9nK%HmQ~wyGcCmKzC%M?mio+F&wxCuAh7l2Z8IR1$mH4S@S+I!&?wf&Wo9&js zK^He^Juug^u40}*gg3#gtqDI;NBSuKWi3!w4$s)%wb39@zk1(~ZNT*QhQA<3 z0O-n6^`!vW2Y{6RB4mp-)$v3b2o0xA{@cMf8h;8jJ#9?7gGE@l_-}vS*!U@s?&QuW z+FO6W{z7ABeB5gT-4T*~jVB*o-AN9lZX}W4hAfJcGm;+50*uk!mXy2zX|T{Jo!CsP za(n;~ASvd+`sKK<2X<@V1eVQ~y+HeGY35$tYU!9W0^ol-8T>FSb*`pTONsl#3O z*_#59xFN|#rKCsvSl&r?G?FtkE=_vXT-b0h+)EwQF?1awugV#=oy5_oSPk}Zm+EfB zU<{77Z3qv&4$`Y|lOP;^qst0X-zWAwqU5p#jB2)e$zf1blEcB>@GAGt=JqMysj{NG z79B@PKfCC_JHHYs(*na-1DLvv92cA>ipjHi0f?sdsMr6ir1gqk(7dV*c|LYou>Tqy%Ne4U(xbzan? zL;FcffNSKC?l=h8;O_d=CosOd6GoVmBMA93g2fnMiGE-){eWV+udo)S?!WuvTvz{h zEeE0;cl8SYHcU;n|kJ6nV(y;6P}yd&TN%L_^_ zH2~(?<0b@O6nc31(Hdc1G40;czVahe(i$x9u9#2HoSw$yOK%jRYp-S8DMx?zDLQQC zPCn0eY|8*zUUCLLfMgDE`PAd$Go5Nf-%abUhfMkHBiiE}aa--#c|+Dy%tJUuYLV0@{o{dIsgRZ>REnh+XN|lunUNj7g1|L}Ae_>ny(bjnX&|}g~SN|c}`U$%1 zgOF5qp8xIojW z_Yg-{tln*yFUaBi>xzDr{bWgiWj{`l!|BarhN9&1*I-vk53yMuY?-I``Mtm6FPHDx zVE9N!XX}_hp^2+SDT$>nYYsbnSbERQq~1r@SQDWQ2)cwiCO4PmeZt;ypC}SP4pL+P z-8*1lDzdQ$tUH?M>H_o;;~f_L7hDm#S1lx1iKP;Cf6v5#y;Vb!dPKzm%Q-9i?LQ0Q zryT7&nUaw4rZ|1%fiv3r_^1i^QwTZXq_q`=DBF4*pCs+}GNM$(d2XeK?5;IPnH954PVgJtyq`rPhl% z$XyJ-(KA-Sm+bg+Clym4H1x~wlGxu-<<1WwaFO?8e^0$?h9bc9qG0!TCMdn;4+@Ze zB6qKwG$^+w`*GF^5VQo-m-XMX$jd1tYn9HXX}Q-h(x}{n!v6~P#oogBl;cYg>c%|X zqAANXzoQFZ{$@7=Dv{e{)%gjhr@><`QZT%A695+{4y_L5Va9BV4BZjtBZeM(?`y&F zw(2KFwYyDaHt3eQD7h(KBi8|WDfCg1^AaYEu`VLcaqM;WdUg9?6}k%P5BgPCFC2@m zb3l~xq|PdT1ZC}o`(gJbU|Sz7Q@ygXIQ$Q0#P!YpCfsl}bCAPg@IlzCk#|i%;@Wzv zf$zce_nyRyIW+}Qq^b$9EU7)Ol%D_i2!#$Wp()AFQ^`xVjmitxqvCniV?lN|6;gJC zZ%OdmytNf|+;^q`Wykr3{ zO_5g2@BGpOu&CUwRKM0c4zQUysM`n+DO<73edis)&qwwZHQ;h$)4Y0PH}1`$i^6CT zwXCP7!C40;4~d_ zV5h011DUC&9s5$i!$6%!gOHutX56Y&6m~~TO{xMsv(Gm0ZigN;md?AxTi1Zy{FwGy z)f?W|oWYX`x{3<5yKlgY_bIGGod$}X!VK(Up~a|jxx;~MQVn@!6=8wfkt6QR!9BM# zw3!KDckrb{x2a6>^wH-e!2<@QzjCsn%?))ArcMz{U$5uxJ!<74qY@=gi`|E;Q4eQJ zSF)kArk8Xg$Q{uao}216TO9nPSdxR`!^O#qIrc+hiTe#Jib6xqGMIFJ@kyewRkZt^ z(G)K?vkYbRFJ5kZJH-y=G-Bg^>38-cd+KXl9^ZGN`mi`$9D+nr^?hEoRF~nR zJgRs`spDxt*fgXv@~i(@Y~C^4jpCSYj`N#G8XdJ|EUCU!3RZpI8Ma?gB*+b_&i&<~ z3lg8Yfb1dE8G2}6>PfMpDY>Dv%~AKU`qma~I)rLW)m_Zb$gDlp`X$1=vjUJa;zQ_^cU_E;SH^hr?W)#6Y}cQb52@DDBKL))m7_|9tY zRLLSeTTk4x4x4!BH7-dl9sN|#`EVlEjAd=4Q<&7y;z8Z&#o6|BpV|Zwf;7eln(7L> z!T-8gN%`AAB#-Q3L%S@t2LAfhizl6ya#ig7XFnCF6Qo_6S8}Ky z4n__V2$M2uwfo3=kJrMV5@AM1Ke!u~qP4+kgvIweyS7wyuA!m14=um)(U#`gT>^Re z+}p3Ay+$jX*I>H)CN$Ss{Ua}^&*3EhgDtZ+23e?#pN8&)b5ZeriejqkT_q zwsMCdF43lvHb20pTZ?{^t4ohPIW_euaGZF-Gmh-Vs!ZjT*CM%QLvFUgU^LrMucMIo z*q9=}0X}(;({>06*}6N)f)j92#inN)L~roUXoiA)rBA zZfmo7+~y$dM-8lQq3!tGC#K+w6A;H1W%nfU-AzaZ$M{#?GavNS(y<;yJoN|)`)vVP zi|6a0OnJH*Sg`lr)gD>DS0#6tJ_r+QdNou)2eO`?JN2nBsa&L=(ZYyxh5GkcNs()4 zP@+H5N++bZzjx}6_rnK6Fb|cRyQhEPzYb*hFN{0X%m#Avna&BDliihV*3A5Ph*}~n zeurcA85*~gA_)9);_AW!adVdD?FS-A%;Mj-u*=GUxZ(UeWLcX zdjz$VH~$pqL-8-MgiW-*FJWy1x0UK6BSS>jZNNaxQnC2Av(HVMz`6LFu7`{C`eMW}Lt;wsigLMR2lr8Ehq zeEXWnvXU77f9B!9KDE4FSiAp$mv^030L7WkcTx9|Pdo2A_3vE<6Q1Wd(-&H(#+5kNk(~9~b@4@v}0-=id#{Q`s~9 zR;F|}Rj&7xzho*4RoDa%__H5m;ciFlK+OekmSLFkg7NFvm22yN(cMk78nS>I)@2lJZr?dTqnPQ?Oo{M-DYMK5Q2XvfZ9DK=H9g|qibqnR)2mOUNcMKD$y+-}J zAB=Oit_P>b;mr9BV12S3my+Ai)n7kjJ1e4lyr`EYPd z`05?mR-uT#>DUGzVYnMFc2Yb^cr|i$qC=>@)%@E%|F9gzvB_4Xn|I{C&Y$gd&rp;} zOqjnT)|5$hhe{npvvkhTNr!_%gR&QZmmf?I*VJ;txm!vDcQZig>o}r1@cdfb zY5E6$E;7VzEqH#9>b9Ff@LVH%;nZmHOGfz51{cxTP5J<=!K1UfF1j7|liMve#FhF$K0lFRJ?dp@{n?OqIB1=I$`L*3CQ04M!!2R-@L5d< z!r@)>dJcf{=jxPL% zQr_5u^p~K}g`XC|BXIKK=TabIh%OPk`8E_NkD-v4DsK#)%>lrJ?akm$c(?##!1_!w zSJh>}rh{;QYhhlHhuqQgR|+ai33^Uh_1u`l*$Na=ReYGIi}GHa4<#*8Gu)_3ts;ALNnW?FhtXA4=i2F$`FB9OJ4n{v{7P^gNQ(O%*svFu4}n5BLAMnfplM&Ep2y1`wK<*TD94`_&(ompQ)wbZ>Zol$kVl92om#BuHMhh z-JfW2_2o~|I?tig-vs!7cof?d0b-g%o+Qnbug(9{3q~$5Kyq@lpg{iYr2If_%sH4fcbAz_UL^U{h9}VO3lSx^jeY2 zZIXjvzy_Jy3kndcK}WAQi$zKpIXlM)+AORab(pwtkLBTxi@Eb)f;0?6-T zD?(xO@wVUTZiu=T>oXh_Fc%`WpE$RB`hU=~&H2>rursR7ju`EK8gKWVYuUUA=a(e; z!}E~s)4|u9bwu8jCK3o=4!a5EQ5jd zL67lTtsm!nUNBbszBon{==Z5zdMx-B$J`g{ni- zk(PamQP=?3;2##jLGa@Gn;Wjl_(q|?x{^;tGgogv5)A$bwQq%BQC5Kec`Vig)g)!O z?_Sn@jVbhvF@1m5KaOc zk=O_R3|PpZ+VQ(kAn1~s*|(b+v##f@fR%#!p^I8}9CypMlaO{n7VfwJ_nu$vA*n%l zpoC6IS;I}c<5&{J>g^s-5_ZE<+jGV~WVS+eyw;zMwUQO6WewhLSn1lq>r{0ScV2hk zYD_O14o^43&H9~pUvzww7qh-?wzh~WK@Iqov<81WZuf`WNhaq9jnGsmr)d2^TX{+Ssdivx`Cs? zuq=G5P$c+c=Wu^+Fk|Vt-YdKJ>fLst^KoWe_>)C^kZ-m;{z>oCA(K&&dgNW!vahps z7jM-#tL_B90IeUFKJ+E9jw>J&^m!!_4KbaBW3hXzpLv14A1L@zNu{DQlKnXaIQ~Iq z^X){jk++h)FvpaVh3VGgf|@?Ws>7`vCo>pJIcZ*UE#v#;H=v@Kt;jZB2 z3eb)x%xMex&d^w5>598o-`wc5={&A&aau_P5F9%>U~D>piO2sW3R&%JlsVJ*YPGX^D>k@=GTV z{k55dAXOH9R1sa52tniw+iqp;@0LcMj(rvIpw@{&lWN(1(%3Fo%WAso>zSfg(yf0V z+7#VT-vx7aWpXe0WBp;7bkq2>=n1GOMwCCkhQH4y2cI=jDA4c{JiTbpIadl-EO1uQKp zVZ!{6vAuZefgNGb*6;K9^A1(gXx@h*;2`W~#>_8`Q z6MR`i_JV2SS07z@hc=y%t%Y2q_iwYI`@ZhLzn4PPVFic!`1Z83bet%x^Ddo$u| z$DCSigf5t=i|DoJ-SIEWHCpK`#a1@WQMj!UVY(qvK5sAzAE_1eq#AD^g4|V}I-~`~ z@MY&KVO1LV89j=@u|~r7s4mo8*7LRWm4g&@VLwv$P}mkkUt49=#{)#5pi@laUwrE$M~}1qh?gRoK6fqq^-B8-R>TccQcKY`3hcy4SNSEe86FJ z^D=_nGWb-yPUs=~(Xoi59?TXFsF>0+#0T7%NJl=LD%74TuakL4T z(9<3#0Sna^X`OO!W8ZtO72F-ny?8_B^O34k%U%W>)pSFeSEs!=fZd+k4k+j%4dBgj z!=7q&rU|*5$Jyb{f=WW54`YBi7(*R->SCG{?c!j0)f%$<4Z>IVgxt)|V_+AT*C7f9 z!%NZU>6AQ#lyGkPbA2mSV;F(j6%a@iLM3Bx?^V&iMOS}on`-tfZQaTD)O!h)-g~0^$U2LqlDkWMAhy!CKIvy61JIr@vlpblP0fIK` z#>ZF>KU38qeV*eQUpADzZ7kt+mM&I-58+2-o2}n>3mbndeU8eS<41dvOU`en? z5c`(TC`;%8^I1Zb<>BhDCsiS-#*efc771+DCfmZix^ot#G~$I7mBsEQcM8YG6w+GP zFGysz#dBqpt+Qiflu=uqX4ugTnQK+SKloI<7qdZd^vdrhH+HqJu%>jRQz6YskHtv) zE>2tZTw<~8dh+dsjkUYhW7u9~xb+dLatyufpxtBY@Jyh+l9s}u`M^%9xgc<{PqxUD za2Bfs`WoI^dmT)HXDTVWKneTC`;{~BNSz;ZJPgXP_>6?Fjoakz z-*f>oK-BoMAeYWPX3rsK_LZXj;pWeeu)IcuW-4+pVrI274C2UAgJK2U|X{^u6pCbkaI9bRHjZ=uzv~FFE^HK{(Wsy2|c2 z9P}gqid=Uvwxn|75_dOs!HNvmt8o1J8E%7X_UE5ZT$v~78$ZrcWnoV`2e)8WU*UDXGPZ`Q2UP_h>aoZ}zs(Wc5yyBMSW z=wJxpcQuW7dnxNa*wDih3p)KwfLNKz2Vly{VO_v%9Em69Hguv$bxAx=KcvaNlt8DA z?pMs*Jhz`I-!2)&776MNNH$DVeZQkr?ZwCLfZ%i)ar{kkvVqiTWXHAmnD{%e)t-4e z<|vOjg>G>x`?{9N<_+OozxA#h+q7e~J(lpI8Z?KB{b8IE>3~AP-P*w2Od;zxG{lA< z^M!#SH8)hS!kC5gTW7`@UV=}e=*(^PIUUYD_l`l=%>iW4M~4li4$Yn&B1pE;}<_kTD=n+K1`=m~W z>j@3Y9Irn6*ezy93H^FA_4=pUA$JQ{f#Z@4LTD$t0O{4y(0O@oefMkk>!ltuQ5kF3 zGxDTbamqJzVjoY$7SQm%JR+SnF>Jtiq@b1j*bC9y?M!Rwt6Qc}T|-U@^pX4JH>$fx z3C!NEgbMm>%Rimp;i0+*D?w`>WU!7Pgr;3#GXvl63wp^(*rPWma#ySMI#|Zl06Kp`@E^`JR4E*VYA8 zuI|KV|9H)Hn?e19jiRkdF=8Hr42sx&#BTh<5tS#C5_q%Um+RogTfU+M=xC@!K6{&OWkK_O z>oMf(wzY3=ZEb}`8Nkt3gxGysqug&U1b3)UY8S+&UyImlW^pDjUM!b78dqVCM!pa# zq)PR?JcrwQaAEws&LN5OA;*lw>FOS~j5K5f3tt&($| zh~?(~f2#ZHzbL;a-bDlpL`6heML=nllu}Si5D}0LrIZFKX#)@yP*NJCLArzm7L}0h zP8XK0g=K*y_MT^V{d`~dhx-TI-xhu5#GIKqbLPx>Px@bfORjON=$aIlpEL#i@r<|Y zHHtUq_*J8A&t#m+aX&G<@p>cz1QqP$q%Qj;XbndTy<%9g8dI5IHuAA{8s@GrL^kzP z4VN4ui_Ocilg8e!JyKSO3$K@A#DLm5QGea_DRLKmjX3nNE-QX?cDr$wd%LKQ%|<(f zq2IQ;ah1sh`mFuhBwJXfVEM9takT8{t`v5x)mW&8eVP5zM8LdoX)BsVYeK0wX=k|N z>3(h8-+@cpuXgjA_c^x1f!7}=oUso!8@Vy;gP1F)>xM6NO>z@`a0@Nfh}WJBehMqy zN=B>551T20@>=KoN{-Rh7Y)e0knCPVlCCx5ydP=BKU{%Z8!FB+mob88dIMJzd&3L) z@_rP1Is@kUGYWP)s@9$$iKd3uMi(d0t#S($A>fb8rlz0u3qC)s{zg@NR%)%p-fcRd z9IYXVkiRH`A5PkP?0UG|gY+K)ZrlgHCvuzMHa({H_RSvKZ(LV@i$xmU*^}q+VF=gm zk82L7bPXT+hLp#&nvQa;QVmP9qgl#Ee9C@=s*cEoou0KePhIE7yyK5&NEz&ctM22} zG(1rHd&UNpp>zoP?@U+igMV<|7MBICS^-0Qf*=%{ScV5;2G+fkhi$h&kfya#|6*Kw zF1!BQiJxl{=J}|Ukq$UGw@;;)m)b11QP=%VlrSeR%g=*z zU94|1Iq@N5NMuap3u($FhKo)*x6q>h2fhT;t zGd;3Wr|KFIi&51B6zMy2p1Pls-p3s^LG{cqPpOlMi3*KidS%czTGJcIeu%kp!&i$o zXN=S;w|vNLP8H>%KYs4ZGIjxROV=E&!H%_-sFmR@Lj(wIJiRY{rMrF%|32K)ApDrg zxYh5oY_Dec4d{`0{m%w@>9?Kwtif)yaWCsSh+B?#V2{>(k&@k!=(A^e?2^J&il6L8 z@;NXc=eyIm88Ph4mBiwx`@a9!T|0q|=Q$0tlv71)N>$6ki$!5DW&y7JllV)jkmthi zTl#4Zy%zD1t83blL>d3dC7Us~?L{3>Qwyy~HAGJ)OcE;?FoWX1M$sTPpvPK%^x`p- z)_A4!Di-Cb=aE5Q$qIMZ9#9&xVFdh5^g}`D|x)(S0nF3H;1t zEZl)l@bKI9O1%dzf89bMFNRB2RfC0L!L^c0N3l>U5?#bfo(mM@uPq0-gs=bzShRA+06Fl3GF+JT(fT&9`BQNrlC(2jnHpeD67?c{xa{aYKjgI-Ir&1 zQ(*JrRy??uu2!p`>}p&Xxs}P^mnFm`H+_T2^{McLJCU_Zl=AO~PcJNOhz;=I)|)LX1F|^qlZP zEjlbb&Usiyx5ew~t6&da!w{Lf5&7HhvjumwhX}V1eAfL3v>7>(BhRDTwy~(z5xZE9 zhyo=-#0@xx`@S+8%9J%*QEWyYtM8L$i&|4dsM@8T^wHoy(I?i#MhN_*IbXJ=i*fUf z8*2?^l>%sruBIjjKRVyP)se?J}7G-Lu~!}Sc|rW!*^z-4$l;+MTM~`JxOJ?ZjVyfzx4pg zm77ye5Q3Kjne<#L*?kG8Mx z&k`;B>sl&MET*(&LA#38kLz~8Ca>tc@^(mvzGitFr3pu85uSxJ5s4s+;FYY@dvw^P$A(vK z6KD#h>wHwKd`K8@Y+?M1o&sknn3^+{+{U5?6qAMYbvWY|s@X8d46dS;)k3r?C}%5% zWzNoAm0ef^Uc7{}(KuzuME38@aJP(AdDa=OsAWT>6uN3_aNB!;#@;xAx1Mc0kk^!L zgx*fOVQne>>7)IEyWUbS>C-p*KO2HH&D{-DiVIg7=ka!Nf8DKjY5VtEYx|@*_F8CC zC0wp#b28V9NA%T7E6d%` zmbE)5F}fvN_*x0JeDh=l~B9`++VbS=%xzOd;vlAK_#tY7{M9js2G%^b__28G;88r+QUX^?I2JHY~n3+Zis-VelRLSrj|} zvuEww-;dPN&Of(tzD`X_Z_%!G75nVkjOLoKtO^e#i%7w}!qpRM)-4+Bh8U14p9>pNq5Q|6#WXQkGTibds*=c$bhHNq1!OFK#J8Y*o6#?q<@e{(pF;gkun@QAA-lLA zxg2PB8!esJW3iZvP#zCLdGU7TgGif%>S>+)#T(T0 z$gJcZhkDn>(R=>Km@?`sa1=CGQ;QYib$-dMMo2n)RW`!*mpVNL8dc*e>?fs1?foo= zXp6PhA1~#^HhP8-tnW=VLtuR|%UMd+IPcVlz#((JT_f>S*}ZsQsvBf`4}EUs=7$99mS?3 zSHE_-+n%(Kt#CVCblowqb=5;@w!%Njqfx=@L;I7$Gvf_zr9<2`e?t$A)%x^m1zh`X z=T>JnBD52|AMv$MJ9`bAmdhk;B5pn1z)HlAj1~>@^+-}4mUp&l}2PPq`1J2iz{T^I8df1cR-n542!y!C8omt zN^kum4b>yYPav;?M)uEmW>|uZu0{13|Ht^+!3RaXQOR&-hbjAn!=TXNb4V>dojLbi zy$J8u%xV~M+g)qc5i?`q(R=Xk;$?Q&y#=7{z)#|gHwcC}Y3po=di%!=_g#4@+;hrY zvgXoR^V}%HhBxBkR0esaV&&&y`@GkgtmY#>adE!XTVEd>+m!R7r0=|1K<~}AR zBdF3|ydJ&R%am3}Sa~awiEO-KEiuo%l?`#=ee1C}Y|!bRA6S?9^BKE;bAJeFW^ijm zQVqKQIGZhcpgebEU8qU$YOwmFVNC|LK9pFO$Fn|jnh&nw+915p$_zh~^z#Dh@^B`7 z!OQA>ngsT@^a1mrG>&R6#2Rgf8}Zri-Pnhdy7g3*{ZCXqE+7m+i5+tMQ|=+ ze4%l4b;7#oHLRDJ9LgPf!KJschVp7vAH6SIsAWdLuZ{+qwI+>!(mYjH7SG24T*fRd)!pCPj>FI6a~?tB33=kN z>YlhrJBq36K(9wqlO>Ph{N2CtH@$umy|VO#2cIL7f0JxTk`Lk^?b z>N(KJ_zB?~;F4U&v!MWguOB6KU8Kjb^!XQG@@kK*Mexui6XpB1uORW!1D8CBeizC2 zz~T+?qc!KbBmh1;` zOsU~k;`+*f-Rilq8-WGLjqaPmFSHH`o`=xlE#WUd>2hT5IH0}QYgtIa>{iF*_5;>_ zyA5tyKkv(x<_|(T1GI&tR>{{k19^<*#$b|G?R*zKsRqoAeI){Z`s`Zt6nKN?`5ss! zq3tz2KV3+9y(W$E_Hx{AAcx4?Booukp?&GuYq!)S)!8pInZ9`T^SC^4>3<=6UBnM5 z#kT)CSLPd5f^C4&{Twy5>q@1lI(o^V78%l4wvh^hZpOu6P~Il)XmM^h2n|#6=ebFx zL@jE%<)GcqfIteh!9!Z;3_hn{Tpf&zt})5Y=UtpEnzO4Dw%ia8vuT^Qnx8gpdzQ5I z-FL)&5?I6wygDYwjy#_hY?q-F1wzyozSM9+<99wI;hY11a`OO~xAYr=z|{e2Nyt!2 zO95NOiMlf8-=Bq)?$QM+8HOMv`Z3Efr9c&L`ntxTW#uC;6a)C$9gsYLK*#Ov4gW%a z`w(4Vwufn&xW(0IZFfutvDl@(l*9M80kJn4D-peP-G~KE+YMS1P0g;vebnVgJY-8Q}F4G$RaAy?KGJco#yZQ$lQl)R$S_%oON= zjIE0LaEu3S-rxNS|KQH=0Q;)o=pp9)wcnF)B4mp0 zoi`awl+ZFLW22Y?A{z4`8JzcT_s|l#uoQ+Gop67UXwzTT92}}xp%z%gv#Q0A1~rzMF;CHf~vuoArBrv^VB6i+lvbPqVpf!8b(`Bfo45QN7`?cu50V zq6vN}9t`fyBV?%|(e$r^*+7dWWdpi_c7c z9qo62w!+4idVy(;X+;*c+I>PpE)Qgsf=z^6?OP+kNuqN@G*X(#)D#8fpaKh?LE_V% zX&mDX%SVG#hi%q|Rx9BonKdos0ogXI!N-jJJ2C36!@dIbAvzBN&Z75?%x8nR8o3-B zXiE^|R;Wplda|KoR?WW&Y53H{vq=w!kkn8a*Ql&{T&iAwS^P$SJz*kx9`Qdh?+%~P zd&s6jy2@o#eE#$_2-Te|UyPls=&xjQP*ssuu(>Rv?+6QtUWk-@6cZXc*5LEEmA(;d z4-TgtLLYu*v;t|pz!d?OLYQ#Is{64gJPO;dqYWJxW$QaSP|KHQ9ODSf-zH2dtZX+( zpARDs&CNEG@_r_}V8VrhVOO4cd$g)AA>ko-; zuK<8eNRIV6rqG+j-XDe7En1H? z;hi;UL9~fQMeW-2u9?V+-I_VYeXYM)`r#<+MD@IQOt=|^SE$mMIJ}Ei4+PxI3+mF+ zwRun1VK;Dj;ZfV4%{&aXY7{GSZW*`xG;%(| zfHvtXoD+R4n1#}q9dK*mTEXf z>v>dcGKj_9I#s6%?P%wO%NL~x7R&9OE3jC@jWt0%T(70i*ZYZe0o9)_y%4jU_m_N1AKP4^UdCkSp-wp<)ns6 z$-i*bggqG;FEaOt#izzxg$2gB72CgE38`&E=Ae_iL5}|)@bpI&W;YM4O9D=(68@4g z2S^nZ$nEGIX*T4xg=ddh{k@|AcCIIEDeWL2d9qJm`YV9Oh~1%}VUqS0fsO9Sfn?v)xoZ;F#{6 z+=-tMhkt&hHwuZ)WjgIs#M=b#l!*kv$UTcelzZw*N)HY7i7KXuee04&DQQM399bw)i$dl5x31Qb{tDayceW?$%SIGasg= z+lof&^AUH0#aDW)%bW#wYP6XBgw;*Y*C=@>iY;D!#kswjld6DcQ#TBupLgrKH|lSX z0-VVAohq8#34Y<*m~j!ocgd1dareXxS5G}BNkylE<@ic{N^dIv7}p+5 zk@e$QquL~A;3roSwn)ATUB>+;ORSzqQBc9F@u#uR<=oQWnssE-+}Fi=`|F3^0&4UG zSqRTXN?5ek8a?FX?60RWW=JdBgC-XuEPAn35`m7S3|6*Y4uizcOVWmChl?>ZvI}B z!pL;cY`F$`kXAxn7fje<#VS!7auMJhB#yN$a}fmEBm`>jDymR)oF+PUE4Mk3K!Gq`KzN)LwmZuG&1`Ram66V zc}{BW74{<@dTniwIB?$GnGUV!xa^8W*o|1v`5rI4?%MQ#zp|baXYp$e;~T48D70ru zjun{gl-z7{PkeXboPAIfa8mJEm*95jHf-8Jp8lNac8Vkk_q(o5n$98tn(`k(q#(?;hlR?S)m7-iLdb>T{OP zoXLFe?oqw;U~>oYc6;UpEzRxunv$PT{C>*;DlVm?xW_3$oR6?UwJ^u1!4NJu>Zs zytOw`u`{sa)O)*!L2v#91$C@9%GSb~JxFvR%+tEqtGV1svU@K`>Ul8;`H062EVav8 z!%yI@ur_Nx8e_nD{^}bV%5GII!4613xen99^5Z-bnJW|}LC8S-^WDRChr3zj;@+w! zS0V1nJpWFy1j3ei(z4*SvIUQl_pO4}qf?NXe~1A89<6sHlT1hMofv#XUoX0e(qz1Q zGmS<8*?!OU(-re53*`NVXwzn{BAI9CD)US;HYv9gt{M!$Q@(gBedUEt3O_@Cta(Ib z!AO1zODWx_14V09QHkFM3yPNWdTL$AUL&4vkv)a0uH>Abyq*0*L|S-p%_8Mj=HDq{ zMnC=Dvi4s(TXqap$#QZ2CurDh?<$ClQ!Dipobls{&06D@!^zhRjQLMo#+_r8E9cFHx0 z&+VC)v2aZA@9)QQbf-NVq+DljW4_4463arI1M;_y*7#1pw%M5Ft95ytDy^(H(A)mT z*2UJ;nrUWPUVpP19c*9P?kOpIre+6C#)9L;b`CF7%19fr*J}R+nO+Wim}TXMrJT|? z+*J2_74~aspO!pQt1u zns-8|0d9c(x;eI|7rq;qWFZZZ4dl1tW0txU7|GlRfLK)x&@S8BvE6a}dZVG@VGcV} z;Gx}xeN)5eycb@3Hu_F+m$!R+XDdJ!HDjL)h0QmMKZ$(i+bupuGaWC2C9F8Y)uNEX z3@!y`s?Op-?CLC17_CECm;xBfsSLYP+K-U^;H&&MDYU$SS1OzRL8K6py2kc^Ba!P+ zXG86{x6RPq>*&-713hM!<$*Ev2h4t34xTGz(T2g%7fMjopkhdIoL3Qg|8TzY!L=aR zGR9-%^A!VM3u_$8U4*UnQ`MTf0t>3QCT^JOT&Rylz8u?&qf@#|ir_JJn}M(BDfED_ zTdHB%S#H!<+hsWO>vi>ZUG+G+6|kFtZ#PL9Iwl|A1HFF{n*slwo}nb zw}l_-|3=;{n)OY!(sp}`%mh9lf6(?RA17J6*M9pscK(UfXI1gP?`Y-u+6z3QIt~hh zcAs$!Q_Mf04IMkjweDWjoZ6%j#u0HB=89JQHB!seWUnnsOn|d z+%vCRFIg6#XSYjh7MGi&hQ~uF;wH!V5d5CYpTY}`J8HC7DB=7JHW$Jk2~&S9?YkV_N347AcX***K{f=gu)cBpfqu#K>UDRv{^J zN|0rQSLnhO3}>04CcrR}-LKs=)ULHv^2zAnyfD_F;OCk<@dto+Jh*@iUA12+qFFgr zksGFhz8@(nasV)ouN+x#JL_j!8+83*SAEHDe8YBs;dC;K%!{a+kJQhcUqKq(xMKkc zKX{NaIN2^6X77DxA@h-hlAkqVZ>jE`%`ypcYDZZW zrs3D>agQb~+`B&-nThW1H=Bb4gVR`+=k>IDV+khwM&(c%u~(Y938$)f+mRMc^m1EA=A7o#8k;1p{7-pyc2 zf;-LlGE7?&RGv^cQqS^>JZ)P9JuWhFtMnRNX>-rKyC1yWLO?r;&oca_&F+L_ID7^x z4p-7}w#JIK&|b)#W)VT-MsJm&c0B7QXeg|CDnlc4*~xbPASzLY?og0C&9yK&XDlw#&vJ;XFsP2T#_+dGFJ!9YToN z`K52{{gPIN7F~T5{hDOgKBBv^(&{A~GRIkc6Rh3P&Uv0Jpn!#|ZpkiYhrf2l-8{m? zd;1d`<6m00F@eG});zQDSMf5|d|aY1F6%gNVdq!hLjXP_;^my<?(H?4U52|ijb3aKG9=zg>fHTuEGlR5GV>? z@81~;Y&5z47r;GVpS|yf0t5=lXgV-Yb*nGCi%IF4UME`zojXD&@!AW;Mtis7s!+Mb<*CCPWr%8^M38;Ah*Xet?hx1$NJ9+Wm+~M zVK%pze8|yarQyuJa|;nP2a-CS;YvH7=pUc)ld|HBh7c3z3&9gMjSI{B3dcD+h8*Ju zpbRa^FRMpQUM*?cAA}d=d(2yo{%%Qm#da`J8wp|R)0a%w3AVnih7G#hG zQSkglopiWA()yeG**T4j$yRVx3eaayXph_ki^IdL*HZ$E@#@TGzNnxOPMuU+CuU{A zp3e2SJt^*?cQd+Whh@5{JzuWc3(a8$z_?be!@k=}cHX;9=Z7lM&hx=4XnP%w1P|tU zU;TcC(P28EiNDIR6cOG_ zKv6Xi<-eNY{gH-#~WT-x=3jUR`G0G8-$a_6b|GzGwZnBxDeCtF!MKzAjO!flX2+rl0S2%|2f!76;pxEH z4<4ZA2912i)mD#_8_Z^{k)5ZE4)~>l7w3j`XPn zn655sW4L9rzWolyw+45>IQ+P5@MXT&AOQ1!iEcE%e5d0GnR}Y8#6$nG-+l*=%+7<@ zOe2K;Cddm)uD)6>YLdk+feNf7EHKI!7a&vH9%kJ8YU9#GBr>_1g^<7UBG0G>M<;O=zcq-zQE;F(K7+@cCRG6X^fw)}re@v! z?f%IMvFXtY%{}(8EB0Q~OyESTqFR)$>t6nf*TjCbeC1WA zXChw~25N;;*GXp@+R+lQ9p}rQWI1MzV&Ovn1wP?#mNAKwzEar0s=x&qGGoR2Q?fK6MHa(1T`OPfhTOq!O%5y4cKO<1jl?dYJAZ!61 z?Ssr$^tlmYtt{O0htR>xl3g0%hFi1YgLTg6PhKPrJ7HG|nqu&Ds&U(f#;X-83L^L# zU7Hpz5+Ec(;I|c0Tld~SOR%(D89Ccp*`%mOtdC*xcr(h!TntoLKvonCSBc-d(MGJx zJpWN#1#uIABld7`8E)0_UH*{bVqI=$RJgN}as%Rm^N?4DF~dXHA;4R7?5-JnCloLM zeJEh)^q2^*XeeBG!m%GI({LS52{iqOw=!WHmN4j{H3Da8;f15-3m|(jAn&;Y5MGAN={Yh zG}3PDeXtR_@m5Dw0z11IV&M41y&D>bGu49VjW!rB{lvimekT;av}r9sqf1?eYs^3) zb`NCc{#b&ql1mg3x^JoLimf(BDkj!nG)zs~=|W(j@8$!pkL|240&LKTHL|E0Tj~IP+V$aU!7b=WMJzwduUm^7&o;JxzYFJ+pK~01;yc77@ zCyoe`=$C)#K!jK<29|IKXUj-z*di1&dW6_;8<-snvEi>AJ@zD!O+hdZqKSc-h$tfX zNSLxzpM6G2BQF2qV@Vou-j#z6Vwp48h#W5AGO^*(cNhtMV#CkL7u;q^BNpqi2Nf|O z*+|w+n+zc$*xq@oh!`i;vk65U@ytFCDm&Fl-kUa4VOH4flP*j1r67!Ln!< zDoThAKVs^!kM3voTRR4t7PN*`6EvTD3nqh`Po;ri5Wik;C<3s10;?{bKjP4;h>#)`Bm@OYID71gNRxhdFT*MV zFryNLNfO8|9bicn?f}^-K=xmaw=tm}dtai>24tciFr(K0k+okwz_R?;o17wooK!*% z^mepoO_0DYsJFoojKszN$hNK=oIdd%Suh|Yt~n(ztMol<>;EHrgOO1DkF1yd;54Y+ z3g!;xwjKebypp-wXz>{5Wzd4M#2;kFaK8+h^lAJ>%Y=PtRFEF75|Za{Ngi5 zDr*QhNd|f&N+9Ts)gN<;AP7){25H8mT7=-U3k&oC|3)Zw7w7*UNyrzUv;Y0!nr3|U zzka9}=ym_&j4bXxaeo9YoAe0ClPVV7oFn^+`A9SzCXZ&tVc|aNpm02xAXUp4CHSzB zG>Mx@(1$lkjki68aUOgl+7Q8On-~0)5ZC@yr!=4dWSk_KGWR(mxIiENuMsY&5u!P% zOKy{c8u?d#@-0nWnz1Hnxy*;44~b?4l(%;PA3jqi%_V>l^!AmNxXKZCp+Q=aNC8 zfQ*qO_~{6UEQ2Id3ojrt;zn%p2zL=8BcfSfjF^B}qDPY8bYqB&0Bf;HiM@ z97M+UuQzCr7DPitrMyiJI9c+qc<40L2m^_)Jt&w8uEFNtNNhlp&xkguF4_4OSkvx* zh9lsKy6acofxURl9Nz(|7I5h&CcUBQP`CCpbl#PRTOoCnp7YOTPXw7 z2tBEhJZO|2fg~~sh>Ya!zU`5P$TCS}LM#xO0EsLZk`s?$64^^aZzQ$pc?9tb_K)l= zAiGFOA}fOyobq24)EbEFGD&qFn?htJB(gp_h>Z0g88kP_Ad(_sAhMKyI$#cw)se_l zXdyBY5?Lg)#BWJbnXU(Y$Vw9C>@(oQue2no9&WH`Dw^#ob z&J1egG-;`>L%n@fBQ*kYZ2;N7O0h^tgd|BU0jF5-;Y-qo;C)z+0Lg4~h=TPcBe5V1 z8b%#ygi4UWIFLx7)+nBl{*VMDua6Ri`aC3Zmq@ijKO9-dZ7nGw?))1>5`KRU{5Mfc zVS@AoF2VdNiJimRCby21E&h%@Up3|NojG$8QMWW&ZGp WUj0(j{0V3qOzHl^d-<{^Z~hP0Db{5G diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-workflow-diagram.png b/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-workflow-diagram.png index f72ad5af4d3a5b1088429c3e4d761eb40d947f6b..3abdb9288eb5be31531bed1521b9f527ff76786d 100644 GIT binary patch delta 350652 zcmb5Wc{r4f8#Zh!p;A;LOA*Ric8Vbi*=64q*>{s{bBhWsBq7TfYxaE~d&-)9-x`u_ z#*$@*8D{3aRnPN#j_>&1Ki>a3j+thr``XU)yw0l`Ja_*gcgShV(9^+t7|R$lXXp1!)p{9&l@??6HoM%X;7RT)0jN%k`$_1#c9}e?E~-T z(7j}%P7%e&rUn#D1*>g(u(j+^R;_Z9&$b1)TT+dTSs>%hKsNr~}tBPC@*lozmIt3dz-9QIo z+SyUmg1&P0OD)f)ThKoYf=(woa*%O^ROzP zFM1lb=^~Vb8$=cHPR?6TgnIL;aK;Rd4W*@?L;|*`NcdWc*M)E2zP*W#wr+SjxTG&= zyLX7+(F^{F$xE>;{5-wAy^Ti0c`^X^(AbP$1-cSk75dOJL+s4=@9p_RN!dPzit|lU zXD_5J0V9cby6rJs8QpiU#{l*vW^nG1CIfe99l$9xQtbd(LJBNHIPlu$$&}BXH zGh@OtVt83Ol;7|x-qO<5QABlKRjjbCS`RO#9*@L)f&P&5f=i6cQzA>Qy^P?`FiWI( zYXmrcxBBx+tu`1aX7G)6&#?|hd$%d4yx2ROdP11eWQ}GEZVo|hpuCEz$gkkXIAu2z zzZXUNjB7WQ$~Vvr9Db3Pn5#)HY4AGOOKpm69E`1%Cj>SJ9uW8PtoN71MN<{D8jHC8 z{Smd=FU_p?Tl-1j5C90Xo_we~R$p|>qwetav~7zNt4F~Q&5AOPS-Vx^V=Ja+ZlG+s2U9=8kTB zzLU6-=71n1Ni!j_aI8716U{VFTW@lJ7h_;euRxkzEw9FEpzh9YSk2dcS{|HR@8bVxU01xl?9Ff_WTIfN`} ziMNPtq~isc{YJ_C%O$`*mjceE7 zII5ZWnh}C)vnCQCm{TlsYP~wk5t)xa-?60f-61LJ2YY$NOul;_`}L)p-}G>rNWupd zO8yaSRc+yJPc8Ap$luMvyD>2;>7!_eUr zr?f+Csg?dJDwRV?AnjuBj+TT@9bB3%izJRUC^RxM3N?67xDtm1s{wqril~*36sOFv z%Kv#L>ddpuX$P+!Mm*)tPXr%)R-@4G3iw|^@Z=pmVXzhwDrl%L0Taw=buF8cc+MRJ zX%(SxIKc?ucBXH)y!5Kw{lQSd2%yJ$lkvuk4^7 z<+tJ<*J2;~lwYlB*HYe&=^wJUn#jK7Q%D z4+sXj=YQj^GO;xMcnZpJN?^HFUPfllXyie~#28*3YTq>FAC*X|Z)ngAT;vv4VpVkL zD=v?vTNhjwZ+g1*@G8~RLTs|@ZLpo)8T>@Ao8k+0RNN@@)oxXZIko7<%`aV&Rt|^loBwv>&)`1-2%=$MbxtbxQ z{h8>AJe3`o+TZ?j^z>JA1F3wi^-iAEfqA`C4>`^;Em)XPoA4!!nh#J9fuW1RXuaSX ze}?&jZcC=Y9Bkx`Q*aplp%BQQYD%V?cE z^4IaEdy8L(b5M0&4)2|QRn&YZ4C_FG?4j7*uGm!Sb>!b}Im1toZt`0odu{XrgdAXq zr6#B!_*#}6R_kM@cggljEX64{9Iam7=K8v@u<%WBriqgVQx8hM@t(qP1(hO^^kFYv zya1oo(>dSIA?EfaYv0tC1=5u)qn7YH%T5%!XT)C$5gjTeze557&<+( za_c+8fpR;7Zf{{>Ax}QG;u+j8G3~NDJ%;xeI5wf+hdfVx6@pdI)Uw3tt+|+7}6Kj$#{3#YUJ6WaUaBOeFyvVQ#ZTIyQx^UJsQWHD`+~2 zl}k{%0n0t*`TsQ+b*nv^m8Oh~+^JejX-a~I2+j{1uAe5N(N^-G?`LAf_31ShXvkz)=t9c|CQ4 z!LeSGO2To7O9)CB8yhQo)bWw4%hiTTfnN$kYddPDLBt-F>iw|I$sYaL1S?-ioq+l_x)7G}3|Q=s%4K=Vr|61F{%a@d4h< zuH2RqgYuM9P7wiAsPhJVihi?}=aVZQ)}JivlOmZ*&0sji;(9Fc&#q!gcr_HM=d(VhwfLe-b6+d|Bv*lMtBj zNxQTf@ZuD+Pd44Zim~3YG&>je`?P`C3i`$_!UfOp~ zfWy&bS< z&uGrZ>OpEENs8DHIxnM;xQv_c}Abb{((pT42P&f@V&OP zMb@}DkYom8Y5U@`X0#|`9WiyoLQzH zv$Sil=}K+vS|f?E^gbCsqHrdk06zKX=;%lOZf-@Tgj1EKW@ewoh@zsRk7ThW-wX=C zE>0;u`BY%%sgI91P*vi}a$YY{{M6!5wuVH@hEk(BYI^z+!w-t|%oz|ZyN5;!neKRd43ubKbSd$Iexz*^UH+^VS}{GoHS&S;|Hdu?$_fY(~bUH>dAgcY3F@Rzy# zX&xiIiUq&HZT&xBDJu?)Nbud8Dz`CAY35Zdp8sHM@k=B;|+{=?YY`3~ZA;ivQk7ktbcSl8HJ&J_0hU1Z>qk70%O*aRVG1+bORhSN{WlcAlu+0Hp=<9 z^j_e)IJQLV6qMox0COC;t@>belT%DyD6ou=kLM1|a9t?1$`D#!T(tkRF2<6wsI8@? zr#(>@v;RJQxv=nfsx#mHNw9lifEzw-k_pnLh<5q#GQk>srCz}ZgfEVFsR|&Ah_@u;|(K#IgQkDAsp9zV?!=hDHTg68Iy8kuh;@B%gIzmkV zzDlG1kRTN>{Z%O?v(AS`4`cJJ#>9!rcbsSk!sf{QnA0Dz3>kR8>wVw8so?JK%%V`y z-EjqK<03KID~RLQL~`L#E+BTUA6dM{fKEasI8}jB%xgsZgY#$V`Ke=LR`EtP8KZUG zTBT(Hv$wltuDMg`MU^~JUnpU>21Zcm=aWbuA0O9GqoX&{WrX?>5XNI2J%>(wg38f{ z%;-}KB|n#Zo7`Ob!ydL|3#Jz4`(8@9mU?dTb)k0c`2POWq=VuCVId)qs6Z75LJcz3 z>^{9`p3H=Tf2`msOwg^AN0gFMir6I?^JPVz+dp~~meKt-ia~Ln4~qHR3Yu%S>ZuKCQB$xzN%OqXNwkzDeVISlB6_q zX9d&b^G|(fIi<@y<>386SXUPyI9&T!$u^nkIQ8xt%Y{xWRXeQj1uG09`Q!5>g3_*U zgP@>b;Z=z3BjSW*b#--Cre&oukaX#k%vOb>mu*)?#Qcb1|=X(CYMhtJ}f4#w$ZJj_XvVhDwU^bqq(9 zf5P|41pDspTAFrcB^xOtsfq`wb{;t@$QQKJyzZW{ny!a#s!IM&$e2o6p(!ieU>(Zx->OzYOS zg9$Mx{QfOzcNJJ^p^CE&^!0zTML8Xq&#w7IPQWx1MoVA-5o5h`$)a(+e4*Bdrp(V2 zY)2-Jqg)i&x`&TZa@vWLZi^27{<5wjiEwx}knI}v_HFOCZ`b@xoeIYoxDCul4{Y-ti3H?7N85_ku= z>$m6o1_Ck{nou27elha#=a@YewJa6bI8lyU0g&;Yq) zF>H1=FZyf}Aot3_UbKAi$w>}krH~w6FR>uB=;;F;U3+(&((JhOY1s!8!7ks44T+48( zzmWV%7@2FFU#}ok)tF~HCR;JLZr!Se&{p*?qSv(m0xUC*YXCwdt&v?^TtH-*D0>W) zM?A2HGc@t3m^E_fxc>oUCo2!sgrV)Y!Y14 z5tyuS0-RH+4biw9xzl5Ai@0>^$gSV0Yt zGidOiD+LAOQe?ci#YJ5u97=oFb*1>9A$ogz3l@!U#c(y{b6&di+PC=CwdwPLdMFeM z5{Prv)$kNDe@uF$0SAH^LX%Wvn^wJAKlL%5Tav>>oFIbeE*#55xZXfoN((tuZB0o` zoSdC~(dWSv-(#%=W|^_EF-S0+MCWogY9pF11Def&4_@7-Kc%lezNO0R^d`y{nnZ_A z8J~RlAz(yMw-FBKm=u%&(}ps-d;OxEONobRX+wFr_u9nGVk()u9?5975Akxh^bb~4 zD&RCN+n^?U+v=Ij#C}EU8!I%Teqv|*{r`yM$|d$5Q0OZ@NWaKy$r8RB0PqsBFihhE zR<+v5F-dl5RxZl~cUt=bAH$RST!;9A1Ij0yt8TKgpaFiC4gD$KfZOu{LhRxhh49n*k;S!11;GGSuszc}fDfc@No zz_5lBGf01CTn!2U@H4W7FfhfokEWU^3cqEsQbJm^zP&Y|98LPZ2|IXg-GFS;hHP$Z zkXCa5uI~Zsk`sZaD=~k8rPxCPi&X$-usMLa04my`cyR>I^D^l;Lqku#M#%9~2Vtdz z(f5swjY~L9#G&bPk^4Rq96qkL00Zqrmy8@}aX z?yeg6^0ev)#4=y6tPNQOk#on6Ym8w9K-8@%33N?xv9pg%3X+tHwx|i|fmD^lXRyy# z-agX`+3+V8C0#zlp}<>h6E$B&0lv}a~lLA~!y!@byz z!;_ku57_mCZEZoSP`$CoyNhsDTDPpT#DqZrY#<-bD2oA7OnnVO>XXz7*+|g&L3M#L zG~w|NDkUJ^N>*Kv49*-v>CDO8C#4%eupGMj^GYtqdRu_Hs-?~uaNZ26>@ANq{D-DJ z4r$l2g`KRZ)h6Wo9A5z!5;A{=oNlw1XCOF!yoOJD?!B3IY^-naULc|f3*&O_^Fyyi zEkG3;jNPcTsI>xlw4@0TBRk{~eZ;K;mQbW<9mux7_G#kZIR!6(5D5+>3W5uYxB*HN z;qlK&D6sB!K!p|nLmIT){&tvO$I8_51qoE1w%HwzbgbVpz?=8(%xUC#F48ku=b-8A z^c03Zy|!w-j-xpXG5L*()vdVRrceVK<9{_YaE41z5*}IC&y+QTJ$G=drn>qm+?FbP zw;F~VSZC=nTF$RUK-SC*Q0|8GkIm5_7;Esa5l-V{RiQ_LElQ~pvRM#;9-%)buvz#5Ie<#{@bxl==zW|Wh-0;DVWE)?2d#O~&_ zx6Cg@Z;9;Z%UUljEw#6|gM*KSg+&~;Q3L~U0I5wDJuqM;G0r;L?O%1)+1>3&_^yh_ zdx}#diArDuYXUw{2saiXFyAe{f{HQR-4!^EO~ml!-ITSL)x$U zwxv&A^8kK=dLLMpN0P`M1wKNEr5a_BeF zNuM%`69zZu@t6P|U$7DcUjbKsm?lun<~O#SSSc#L1WwlR z7Yh62^Iq_i_rT%caBxpZSom1|`)bmtPs^{UitpruEW!Ldc@_6{)jIA`H-(#1^0}Zy zSypyaO6r2tt|M$Wbp;%_>Du;G5?CvIjzi!!*cTO#>W8$u=LgDKzqdi4&=JiAN#z3C zEVxShXjT^b-6Shnz;>h#hb_$Ee(rdjG^Ub(P`bn2sCH4rSrl;v!hQ%Mxt9yw9rG2< z#F$bm?!Zq93mzbQ23!b(%a5C~*d4WxX@M<9qtJaF1?2TvJ0|qK}qMeY$OFIP?5=Z${6>D^QSzrgoqNqNVt^p{4Kiuzjhz@7 z=jVcI$NUefy&N&tNc#NBaBb=W2LfZn?nWPv4OEhT1%qcm4g-68dzab~JL=>3I<7x) z`5l(GM&MG-ZUXyq{FJ``EKhk23$N}fZRMz5e^^*pF)`Ojmu)F%M?Vpr#U*!tWK`@? zKi(H?TJ25x;o(cT2OiYJ?FpioJn;1y+%=&!6e1O{HZ8wQ8N zff2~=T)`xs>U3U#0uPGpwoJ=Nte(`9pf40ZpFscT7a{Dpil64;Ax* z+})s-$9M`M706|}fupiCKmLKDw+ujAy^SfRE)b-Y8#)p?)dh*`d+u5(^-s26tk2&M zS)xK&iiy(JjL4+)+}gZJ$!7QC*CdLhmVNpF(TE)bE9+<+YL7O6WNtN<9~FGCE_c93 z7{y{I!y!<6XjQuWfAy{t=xECcS!{yG;SZK(8!Cxr;0u<$D!t{q<0!AsuatKLNZlapPlCbu4w5S-=b<1TP@Upjdb#l(tipieo?dPG$*54e)_r#v?Dky-++o%?oBQC2r$?LHO{wNKO z`);>BY0_FuLDFM3dp`nUz4;f{i=IV;(!OQjJbkp+smzlBdFw*}6sMfNTyiOd%WR48>Si&X45^B~NB>5YU0OH~pgK10Q-3REK|d06$=FM#wK4>j^k#u$ zQ+hzBmM5;;%P36&l!ogb=s!bV!0;SIC3JUMsX2&Gb}lcl9^>lhIY8PNb03s`FNgRB zH|yo_^v%Hc0{4NR0-ZC>>E!87iV^aUudgc|crgP|#XX2~z^&8Vspsf=3_sX7LErRM zFVXB>sYRtFrpaTRo_X&cKrK?xTMb6xaevOQ0t_~ zoRvywv0Wq|pQC_&H+^bl%$ZPhsm1H=mV?O!7M3UuHrbG@;MUPEK}xiPPcaNB69gj0 zJHdMdYyk$NB)sO)OeQTL4!^9mAqZo;ndhwiag#?oVCdH2yfqmM7S>h`xIj_T>VBad z&$RmaKP}aEu=&@JIT8djm~d+1d@~rC)QPHBx-lzeN|JFc5=jSy&W&D zUAI;l>V=1g$AiLpZD&Da!>+0-N%!)(i}Ul{ae@f}YaqPFciFVNp0}MIzh?zIm*S}U z>`K>E7+6d8CqY{D<3m^7S=z^_L4_JH$W-&u3pfk{4P6~}VnT0>SA?&k`|xQAwC7fHz-2;Vj;spqEr5`L@ud(=4@ zl%Oj8#K3o}x3+m4$v>ULz?>b?Y4d8BC%$Cb7Ff8qZLBdly%Bya*~L*b4y=H$eXrS{ z4PKduYf0T>{Bpec5yWYftMuDkB@%TeulN%sxMA1Obqz*OF=W%erupvh_+-eCU0VR< z`D9rRUPr1xvd#2a>`7-Tf^9O-mA}2wKV0rJc~2m)pzmeKX(SN$FHswm%;96Sk7c2?^>7T%@Secpj|B=HYc$C z2v~^xesP2;F4-f~hS*A5`;bPGa;s*M3SSsV-#NlxnD8cx^mcRh7mZ_w7kiE{wN}XS zqIRh{xz!?0Ud6DD!`cnG$X#2VkZONfncQoXYzFP~N74%dMwss>;Z!-vKlx=)J`=iA zs3s_85OpwXF70tAF?j!hhgB0he*O>`m^(CXCM-uoV4yrZnqZajS!)bNj5AIJdDGYS zPwU*jGxCp?FRL%doQ7%o!pq(Z&pe_$f2Ep`zd-uP=JIy5?rCVCkUw&&M#T*0BgVXgAQe_er!9Y|(}CjjJxMPp1Vx`Bb15Rd?F+ zsPyV8xwyD$>iWR(5C_whzcxYhl|V^|Is}t<#Eo|zv7?`}RWz1gs+81NpB2GB}R!=>iO4nyn@Ek>|s8vHmQT4I28J)oN zj+zN1_xM|{5TXo__={%Qqx~aO_@4DB{i?l zW9hK<-9QVG@)2!%;0Kne$l(!6GUECU>QM<@4Jp<{w6RQz1SMOR7cfyr zc(5n|>`kMrg0_2Xl_{~!aywWS9Rv&%FRBb-B7fLW{dh@RKR8wT0c?Rak%$7^mozqK zYPS}Qt%G;>U@Uz_^6`mxEo<{~8UKskRxnOf5-9)G7c6s*8|;!GK?2=rVN1kkzbyhF zcm$L|q;a&`Tgg^RqL_t3&MD_$T%3}VLv^x+LK3WDrgE zi)%xa(ps~`X_P?l?L-|jRMoVFq2ksZAdFoyU7zA1(+JgMPdmE1%f_>?F+ZH|U9qNQ z-21^lo*9l#z(iCXx?#>jJM9o^K%wy^Hra-G#I;W1UQnpPR7N zT(r>8K`;q@_5L!?i27Aa;?JlOsuliMD9v!wsisngnkz!`aAQVK=Dws-E8q?!kLb9P z`j>jEQ%UFsu4Wa}nDYb{zsf9hx$(C6(uLKyg}atfEX#slc?EO%a%9<}1)vt8*B-jO zyKexBq7RR%0@-MAZy`b?ZY*`>)zw)m0iJ_z#N(&3cB1YWYpj~Iiy+O)eP@I{4O_gQ zJh_lO$FFv5EIOi{2WXYk)X_1wY#rZ}G7%tBpnDIfvDJH*_JweyQ%1}46t{}iY4ifG zY}+b7>)o<1NN*e9?8v@Hn|tZpjPZm;S80(VY~;Mshs;RjPwpK`k%PgRS|inD=4)x4 zq?J7YNBeQrsC6o*hCY0aoUaT&O%TfTgjspD^e&H9$ zq%dyXx|yuZ_&!6*7h6{x#m-UcDi=^+5Qbd)Aou#6dth20!_h&xoeKmI{OBOWuW9g>h$Jbv@g@wXWVngXqG>Wy7fn8nhM}&WQwd<{J0!L4JOFKpY+tCI+e#Pl`$B#6@V{{VVMnJ` z7V>`Nk}yxDF?*=lO82O)C&hYAx9P@!d6rec?>*is&ebCAHB;uS_npxfDT%|Vx+S^+qB7_MI6DfqwyhGEk}Yr2{(S+TkI0G8LtjQl{RJ2M%0_~AdZ<0iF)JKy&I&3eT1jso13k=Z&v)2tkcq*Lwl;AZ59 zgGb}}F@_^+7U;%0T9<$sPOsl}u-O#2RDr1b)$8!R&Wi^$4lqKFB-2~j63{j5#QsE4 zvUFGyP!#2HoFQ4q^YUZBFd zcWX+m#MY2a!qwJKsiy>M+F;TRAPL!Wen0(6XOY%Z5E~Tr;nSI6zv=xEmacN+x=V}w zq0|`F`U(6pAffZIs^r^wH6Llpb#bim=U4Jpc;g7WX!}dttE*exoSw|Cg-6zk#t7fI z_hlt-l-VfnKxV!qox!r-4QWY5N*c-aT;Fk7y81w8b*4t_boZbVq+~a9p&U-H0y`lr z=wq5@M_^Q_Q&&Be{d(sFLV`I=7D%i)yXb2~P(O$S#0oO-J(1mC%h?!C7ik-mMZtuA zix|HhErQHxXURz1LyvD~G#SuSdyZ(S9C6U0M1jL&tiX{}!kD;|glzmi6_c?JRcscw z5sfQ1mRyq=`YOX|DIg9LSop-MW3T=bQGhha$S%}2xakV6d48&@$b~908r8Ix2;E^( zfvLc){HzCmC$e|pvqsc|V%dnP9&M4H@9(!tEDUWrOee$Ljt!mH3>nH6EMQtu7#j=c zP{xe`Nd>}b?8Jl~Jk?EAJk3fsK602-Z3W`0=AG~Wq8plb^Y~bEFa8skxoy1mEQygx z$87}{G;S%szSU)@1aFrb@ef2hD-@UyqAf-<-AjrQ$~g%$jMQuZQyRh|S;o(;WszyT z>jdUN8i@QZ$woII!_B8y^S13sVizalfGpVRR~8cb+xQk9RN)o2Z*c+hf;!o_p5;FH zLF_FL_Rj%yMDl757i?#H@$z|HNbvU68Pfi!aoMd`EmT-JNb$ceBG6ZrN+I8n>vXiA z1Hk?G$^_S6ha9Ly{sg7zCu|w1EeXft=myZnZU^)4(1a!_G8{>CH>taxqYY20O9m~U ze2Nt7R1iG-_0d*X4g7J7TA6hVHU614^#v{Y-ZL*?OW#9ikn<^n{Z4jS-v7aU5)#z7i(8JNC3u>l+ z#C;J;WO3uRxZ)$1Qo+0(9~!8o^wRRO*NdyQpA|d!i`QE#F9Wk}P|jt^!(T$}A2lAu zxv0{cbA3?b;4B2OyaiW=7fq?fB*Q3kYM6my;M)Zpa{Q}IF<_yS95{XmYqJs#Gq^+E z|KjbNS2?bp_Db^GAk9TjJp@RAhQgBQk_&?+G#^E*)Z&zPT1kdJqWD z(L1#D|M7*+oeD=fvvm?Zy9bQ}h3t@`_iJs{R0Rcz6!+7kwm!V-y;6 zD4=ZbcN?nf?Ltf^(uMr&?T<;n8W==`=|xIblZHvAehR4&Kq2?>m?wNwF6;z`nS&+d z&Oww{8!wd<0|UdF2acQ05rK2Ys0!!q%o6xBiy#1zXbI-Xk%Ln#0#wL5qL({vjMEm1 zQxf)l%ulVq04b_|4oaq09)Ea=C!XT%i)t^K;O(EIT%Pd%rx6C89^eXKd(%7_m`jrw!=3A&OwTIT z|17h9l!KyY9#b`6_nYo+OrtVzH`5{HeVY&I^Z23z`j*cQd|SE@@`kKQj1x5SZvgza zI~YuWAnymh7BMG|Wc@76MILxTme^?~L88xtb2@xSM?IR&=bOO84T%$#YG?;2)Nm4F zq!AZcRmH1yJw_q!FM*NvU(yobhjjIpZ8$MfE_gUYxd zCNtoEtJnt#_mF^{3cgJTaD)Lz`;osoe6FkLEn}DN$qI+$N>N$ofJG>^!4!rj+BaD! z`61CWt7RZ0CKP#(p0Dig;=`;`*1(IB68i5tQ*%>gkeB0H^cQO7e~PqwebBhsXdogi z`~n-=U8}B%VO-%ti1mc=^d7W&Hzn#HT-!f#;LXfrC6?kc0Dpi2FXQ>Zx0!Otd+?^? zNzd_{KGNNBG}Voz*K^_R))ZkjWoHu)X~G zA)aY+(fctjwFLXrD55ot4Q;W=H=%+oMZV$T$o-(kKV!G4VUM^nI;BWKLEcqYQ8LIW z4=w_x;l3y!ceO^{7cyB*OJ#9w4IlULZ4tSW^rS$ZYaJi@n(17in23)im#a-LWPL>~=sPc)H};lXm33x0j+1`#QKTaUFoNB)BxJ4aQtZ zX*oi@^!m@LjvN-6AyK~n_2a1O0&AZWLhexW0@E;=EM!wm(YNyh<6XFV+jad!A67g+ zE}3*WPI1t$9arzRX!RVrkmU}m?Pfo{lEnY!fpKv>mM9Kbrx!|nU+b>3%W8W;j|$%O!;9G z+0jB-t;ov3I%oRv9r^iFs;~BigoJb%$08Be_BjsJ3rG~_!ofs2H|z1Pv#Hp{@Uvxz zyo7;R?lGren=_g&Kh9L2r>Pnk#mA9ximbi2vlu zd?yaLUR(M2P&A|7s=}vY`H<_{j;5=~ z4(ie}*qVq#f2uuDp{N8IX~5#LD8R{h2ldJR-7EZoATftH?Ebb-wKwq80C}C&cdq7`r^+PZxr$}=*s_-W< zjUSNSl9{PZmV8P4CnY-sn#DRC40OyN?hpi3q*PU|IHx{J;w%aItW`>Cdtnp=KWuv2`b#--*I-+cWIHxn3&yVGCQ62MISo8XI zW+dR?mi_n_r4E<+=h)2nP%v>HeTkm=Zl|K zYsZlW_i%9wFH}bO%UN_m@^Q5yZEQS8Ta|s~dGA%5$)5_8X};Ag?Rz85Yv$PS2JPCe z?;a+F!2tn}Z2~EiJ-fF0m_}9QX$?|EZOxV50rWPJFixp+e$5S%$MkNy1+NA3MWT7Q ziJ)+BeQh+RF=Qx~#F$--SU!MAmx-Ih3qk|zPTG0gs{8GijVWGQxrk`sTx8ZT=DLg{ z-9SI%=&{da-lcWn8madw%oG>dMy!%w(S1Z9#((ablw!-W7? zN{&~RHWNt)zYkOt{F$UcI{$$a4}c~QRbbQ4_Q{6M<3iGo-}h&2N183UaYu9tbe$2d z{Fl*R2cs3vB6;e#g)yJ+_CJNshJM&dw@gYX5S``WxKUx}?Ck8}5iQkoSF95I zX!tBQ8E3wpYcblr6rpBeW_BM#rw>`(GON8#IGy@1mR(X050@_mbFDN3`164K5+@#) zH+P*DBM=C3v)mt*ipp|K?b$zC(oQtKILz%=kuyF9HT!WRETAUXeulo_mgn%5ex56{ za%FP80ZspkT2i@q34?*ELx5%ze-N~lcVV*rQY~tHtH#dJ_aElX1}ad&Z?@KpU~;$ z!7oEwdFO&cPG6tJDGF)im|wAs>})}soObr=O>ifgbKua4R~!4DpZdCgDZcv*U zTNa7y$bOX#tIQixNZL%f(U1#TdDVM(GjslTEVKf8go0doieov^ejsT=3WDB~`3~ru zTp8g=9MWWe0^5!SwI|Xc+%I>{s+rWe8FUCX%71nbA9lr*3 zo_sGF_|Z~$BIwgjq*XHve$dz7Pb+Dz!9rAV$ z3?069Dt54k%paoiucXVHnab0YKE&fy+5);9|4m3xiCrn?2-g@-yI?6TG&GFiY`-qB zidCX}qC}jdjyhMXFpZ&jM+Oz#_vr3-)3dX^)6*K+qwCpB#y2p{>oVHDc?K^F?p!%Q zZhbZyLYuV52;2u5+KpS9B5;9sOX$2rIfC9VH|^46_X|jhjqAkYP=*iU4t)bmX{kd+ zjT;a;C>HQ09r~klAz?3d@MZ0elB8%v?^niYdIOPXZKd<>x`Oy{Rs!HKp6Z7p7 zy&Ccr#f)X4Gyr&5nWivvA2OC|0F>&`6^&o#R z6ncI!WA`QQXnQW({g3rdBdnWdC3R1yXK*CW#TyNbTn{!5ULE3HV5W-Q!wXVO)FTldXL7aPVB�KZ>UL(a-|3JEw>xB zqfN$Yru5idBQiGE&U3q1`!~G6bAZ*L^~?eNO@0c6GLENHCmu0@N>GTJws<=`Yl#C8 z5g?eDPgRMh>0Vna>}CD@?AMBRiVUTPlCWN#MQ?{v_%{XSksliol3yG;YR{hkvPQr5 zmBR_K3NcyYVZoq@;hiL|?5>nLn|+Te;3i zfz!~?=)PN_f<4ER1`uwI-=;(Y*Ioh<4xkC^2P(hup7MAir=_$bUvAF0y#3%LAk>O4 z!0?}NPB#YY#naZJ1q-g+j!kTxGro<4r=)xvXGS~`YKa;F*RQ@iAvzN#5VsDm42o?4 zVm9lMWvsDsQOCc^?sdotn|6#1`xj{W!fnDu%GFjGq>AfRTE&lBI}1 z9TG0$tvu}QbT8E4%w)wZUAq=qX6Uk^Z9l_|2MyL;0tOPf%2cTnG}w7Q^Zs0gi(G@w z5&XWR5H#WrEDA<8uFsUgI`29xl^1+%oj-u+Dzc%UC$9xFs1vEHM4ew4KIia!@LT<} zV`N2=_P%jSuFoTS0j0ABW3&@ZcFL-Ofs&6`M>07h=+kIZ!L-LI287A`3Q(}n?o-kq zYmK^F)(Qa~F`?Yxl47G6^KoubO$B!cDezL{6o*44iC?A9tGG)6`9wWj{AYu0KIZ`1go4 zINHs3Lm$^c0x?A(zNQm+E~n7;=T!7Bf>t#J>v;aIR@gDVxAshFfKn{UhSi_woV@uy zumEEjbaa~4I66Ky_W1GRweiMTyjNo;SZPNGmit4OwL(Y}<05`*9^l$iVs|CksTFha zg3Qw{PDE|(;PE%->+V0XDqE>{3m*2^D=*~R*_mwZK|?ty^3$*Xu z(j?6DL78lb2BGZ_t0{GdHMO+n&$xQb%*+%PIPA#S5#IFbm70*bADj`Y@0oOla?Zzs zkh8hpI_{R~H(K?v@$u}}NSMB{@|mv?ITu~#Gh?q`*#kdr1pNP4XTkrkB-MQt8dgAc ze-Wy)e5*v*Z1iMWYq4UcK5s`9$D@tQr98)qjdA&((;*LZ&`=icnPjw@6pw^Oika&csR0$!|9Hu@u}<;NUh!3kqF09nTx1<2*z#LTJV^`UKhfTjOY;_H&tX!C-XJ`Kj-xeK0yO?OfHCYz^lR;9#N zDzr@Pl-i zbos)RRv*#UrvoboPxaaY=yt^s#Bc50_f15P4u1ab8~U4W$RC|NC&`eO7JD!y4cq(t zkS%QgVXHA8|B*a=$us-@k8bDrGNakBSh5>1`i0hNuS<@junJM>mjnAs(y$w(r_kVU4HGY#R@4i;zQ1@(Y=zYpCTR9dfGV zmmVw%Bkn?nbq*~a@^jQrq$ojwd?Q1HOS9bpNlD3+{KNF7mR42_gP*#AN2=3<59ITK zD-h4m)zbGU)M$=)H6~D^brjOvBd4k5^pyxjiL(by^IIT?!+qeLlP~ULai` z@tM1yp?glFPCWFvNAipK$4_+nX|E^lii<2cVx!zu)N&-hX6my|d}t0mToID809%jc z8ts6#wuEkUH>EWTCrnUe(BHDO$A9VTGkn1sln}*C%}0&LE+xEXrsk$jlypewWu}&Z zUO(B2)aacizD)WuDsxCVlo0WR7-;{AS!kSAT2(l--H4#N52f6sV|w~vVS`^8=mAv@ zbIh{xy9NrkRdEI7e?%mK1W8Ywg6f3uT&=P_$>B`D zcVWMl!BqlMl)t*H!O{L4d?WLs_Ms){Ot}ScSVnW8y3&-2NXM8R{W0lB_^Lx#YL2O| zMBu%a18GoM7T#%_?a~^_2l}aYG+~iZ^wR5|Zf;D2vH0~jSqCd&{nt#9^l%H;)-Kw6 z91nO?C4S3#RqR^3wq-xFkAft}#=7H?VyNTZk{$#N{SBn@Q$qNijhWqxU$K-+*8-IH z$Bor~70BoX83q?}Y#%6PcA3sxix_aw?gP{W*8-Rb!(_J3j5hn?F+lNE1`04pcI5nO}Sc?{_!=Dk95r&|D3wHhkBg%TK#jOr3QQd70UYc{@^a3 z4ZeaPVV_XU?spk`Y_+=P9-yS;FPU@so2!lD-Bax`fVc!2PVSAeyVCpEeiQ4)jcwbB z4Dw6^*r=9Gh^w`lH=51LP42SzRJBP&*0B#yO_f#YY4VS*aec21aIQPLa*NJlD|y%) zIFDbMo15by=Q}!TF#f&;u3V`qc4B{`Sfvfhd@AcmWVzL&ooUpeblG^mV^X5Ec3eHM z1>U==!UdIO{kQad>6gwp6HP5sY0#;f+(b8@D`nYA@km1#Q}HkJoiowl+!e6UZv#q{ z`1NUK?3CYLXS>urGCn~kKtn{zRUCv2-*3rm0V{Y6Rggyx>r=LvuBBs&K1ykQ)Z(JL z%YkBXA?Jqr3>@6~`s#$2-`o|CgX0Rj3^^vFdrx>>v;s-_c!8{t>=m!K!yL=<)kCM? z>e0D;&qE!2Q1jn}fNjBnti^z%u+M}WzT`aa1U(pt%6ed_^vr%4^z+HJ0&t7qdu33O z`Xo>Kg`XEFFJ$~mzVzKHt=G5jE-5g|iO}Y5;G?qqVIQ5d|8+49L@$Ab+WDkDl~mg+ zA1`Kz_$ueJnJJJoOr9DQHdYcxeEIjX{`3;IbQUIrs9HJ4VBtu|yg0Z67< zA~tA?%=bPDHWR?WEAKD6;nz84ABt%cTlS^GJj?nuI0Ydq)OLF2VD0mh8CvEr%XxV7 z#nCm7kgE=Uh_vJ;lOL-)K0Fyy;Obg2-5>aR;K^x1u451RFe9T^ocA)9atzyO<4s1@ z@RXKIuUZGbC+|ezY#V{INPTK@@@|2QG>f$Gid?4I1R+YP?3Zg_?t8-2F=~#p?IRjX z`*d*vA5A;`w*HA#XP1nP%z~6iZY_2O(F{*`aGqKK3ZA@#kW`8N>CP92_i4hA2O*`E zq}}~}Aiw}UZ}Hcdct;MrDI(p<$&3H(Wc5Grw-WjLPFSCxJ6lLN-_bNEnCcT-g_V3S zKO?y_?lq)J4pDfE0(CoGH^^8Ij6Qy)U?Il9rPBj(eu~o`hu~f9FgdxCXw^6*?;>*6 zevEKt{xb@ROoknKTGDu4h8#w*5NrjM8qBxX+tfRijy+)Jkf;}MKzFp`yZo1V;I{D2 z;j5?>2p(`e`=9$o;=Mc_bD!Vje7O~1+!Xz{pA!1t87h0PgCN%oU-3SW)Ae+@V1BEc z;A3ds$`u4m8=>PMjQO7*4muM<(3vob|DE)Fx(q~M4fCl{d}nMDO9pTNzTBuZA=KZ~ z=S(QF6kg%%YB(eaZ{8JR$aaVlv4$WUIA_*b+~WrHh@^7JS6xl!lI1`zPOhF_AhWyy zg@tLT3aAn-1 z{g5u_yz?PovRBVkoGij>khw9ftP@ApqaAxLgHLb-qy)U2%E%wj7jhoOJEw)3x#g<+ zK4BMBbx+wUnoY1?+~m(5Jn3JQdN1C0qoKs{TBwS^THt-K1gq23#{mw6h_(b~0djb3 zC~QCz#Bij-f`ait3hq`W6q0Szpm7&+J>I+wtS5^EGBE{og$YpuAfZJ9`pDw)zgQn~ z_Ey&j+#OgfMB6q1eqdrMCt3Law<5s&uWcnF2! zXM@fNXy=;dC+ zVPR@?dXY+{>JT*G0Optt8Em529M|TkdhT>5t#_Q*ef{p;Mpp6dW`zty=moC_-9`bH zHxCC~EYdbadZYu}*@`JhBkksoWbF23NKn=&N(dAn z>C0`$YM1s%S6R>e_qX`#EeLa=UQX}JVD3J95q$Iw-d;-CV{;!4Di}T!BQ!Alc}VSj zv0uJ?xnSluuLe3u)$@+4As~vElVA}Hl-Bo}&6`00DhDJ8a~Sy`!}RI|pa6=dAyf?{ z*F6AD4&=9Xf6lIty#Y7l#ovXVG70AY4RpWZ{F_0IX?B{6Rbn^F;@P&g~5fa}s(wx}H z!T`7WsJfGj%P7M5(Zs^h94zIy55SuU)7CG~rZ?y}yM3d2agCl|Vvr{tiA2i#aqXRp zwGy`xK(30dlBIZVowJll5DC9fGzIOg$;N{-N@*=Ue$RLgmg2_rTHfRe$&2mj;hVr3 z0g~}=uFEf;=)cG&VYOr9;<5^&4PZw2uJl*#nXFhumhUgDS!@AF9?Jwp4n+Dn=4$nD zjbsjhemk}I#fMbc@vEz18V(AEHq+qcDO;S8|HDFw704176Z81IKBwUE0-i9zNzG;Z zUl~Zu-GEgiKPLvM<0!&nk*TTwLasP*oAe85wmV)2H1G3HYZQB_>4YBuzqAW-jy50< z-Fu>Ft{HE%Lz>)Wk0V}_n63Z&jemf9yht$PqUMJp*u@P`i?iRL?}+w@klQQ6>`K@o z9zGlymCQF@C}$V5kd>7UaJlg~`(ctZN2%8f9i-o=g#(+(LWoxFFpVHNVE;KnEw78q zdN)LG9+XM#;{#Mn(LxKpb3cFblcd$X_wRD@KX6r(QdW-IX(dfgrhRXb;jC)ANVVwp zc?z0u6U;9>J_yT{nRT-}hSFzMr#5%&mZeyw%BX}1$qqB$89_Z-q+ROkzIHL}Y@`7V zd{|FUPe(npARl{LpbP|E?G|2AbT*T4oG{{44a9s#1zLWPpnwCOqyMDTfRELD!XZFe zvA4&1dmDmqPk9@+wgJTM`!PswbmE`v1sSvmoF)k(c&d{Sh^Y$>ftf0&Tipk^#C!aH zr*)RkQ&TE0cK3q*MCwM+@occ88I^rW6FwxI>;6wbGEv(9qGth$fbgmP@9ZStIV6)Z zYF<}d4tCpyL4*zC|N0K>L0|K$t+@w+m-4s}AR$o6dm09^7*b-e5Ei~TJbL0TR(cH~C=N(LdEcqYE!IB$-as8-~?9r@*yuR690cvKwFQ(-Wts1G0`X zuWTF=9B+Tb4+CyX6Bi$;GU+SFPNf#TU(^n;val$w)DvK=n(6Ag4n5PB3X(0-yy*bk zU5DUcRIRhPDES@_VPR#YbkY6 z9rnvR3(d>1qXSv1tZN6%e zY=9WKy^s8fYyzG^fILY;GH)!Th0qrTc{#SV`Q0nUB1YI~)?V)Tl zTQjO|HM^EqSMr;DSG`4P@)J!p=!eEf*vAz}d=*9!~~+x2rU_lY`Z za9J-O%Xxl{2;AQ9b#cD4QvjHE^X66?J<#b~!aY(2n8_ojt3wwx1O73pnmy0Y2zowGYVC&TY~|THSC!#UztA zfG4Al?8)e9&~Swg-0M?h$SK(;Lv)&U4`6{tP7Z~k$3Q*ypPy=P>XrWAPp@TI2`D)V z8~aS1U5dOD)6&wkdc3+W&@0$`Mq~iZ0m@W!=^%r;}b3lQ)@AJ8tOekF-&Eh>_zUH7CFeWnn=NBh89H3xC zZf;u>yO*HNi4{_JGZX>-)Y+9gWE zjsn8q>JWKUP@dU6OZA^a<<0fgu)lMFKXIZKp#^QHMg;c${W343V1Op_75A(Zv6bhOSS^^x?3B3FnEl8 zUbRo7jY@MY1x{!FcmZUKu7P6W9c5|hnu?0c{&sfMMQpZUFuWZdMW>{=YD+24L*WkZ zt36lm=KijZcgIAMQ#$q>Y5Q9nYKK(6gKMZo?M7G=zL!aRCy=_R*r9ZJB;4iBn6knQ z^AR6eKkrYzbG0(uVF!qWDTui9K(AzZ5`&}%@DgM(Q2{Cl!P_ck_$+~$0@`PUQm0S*8x&~Miyxn~5?fs-e} zLv`)b)8)8{2cG6DV!$?wX-_fBEZI$QJO?V~IFyrf(9QBUZ?5`75N{Fq&thV1tP=Hu zw<88v$&3n86GnLq%=Dh&wW5c}pP@lj-2y*WZ#od5Wmp~nGlhs*>MwD(ySw{F^a)N* zNR8g3?Q`^--`(9&08;qKTMFB6-d`S^%I+ZGLAWdqh={8p|85+~bchf^4*b&o{w!}J z3XfbP5FtF>hm*af*T`^@?7ysy-&g$qX>tYqe~qqun8CgK`{z8dOb4!t)YR&_+hi1` z))2l!yjk%E%Pi`ahMKjxd8=*K8ZBIZcGB~&Gk_dowuP9oGs}vLFPw+l*|jcKnRu5q zHk}t2zwu%4^W<#^o~)caDx&(($H%1pw^POFVsgZhn%dez>w2$4c#v@}FFuqx+eV&3 zcA>3LRn&D!tCPPNjBg<;`FK00u_gAeNvq?}s^!;Tb%zb)vncO4IXQtTSoQ%y6gVEN z%*;l|#zeSiig`Q8$Vzf;bc=#0zVAki-oLvR1dw?rI^0B9Krs6)WcIJeEO7I`D%Z_u zE7EAu8ZjRth`&8keyArDD#CgEbJCNa%sSqLaZW&o`hV4_wti2p0{x-s{_yB%xW}zu zK0-JcHQ3r_)?yDWo!Ktw`uS$+=SshUPt{ue)bpS6DeQF`D?j}eBfBIYpis&HVbsIi z-JY@r`iJ==4WD-w;*^z?I-fA1_bgW%`+BFmUS`q5)WDP-bPQ15yUTw-92zQZ@VGhb z_wTp$pEjP=x$bEm=nW9M!CtdyiQP*TZITMopg+7dk@wAT&6M2z9p&e~u<-Ey{Y7w{ zOM?udt@(mr?2LIL>ow8|mp5Oc6j*KHqhBY*0v9ey|Y%ACBeM0gKI3Ieu)08@fsX8Zzg44hC ztuVgPY>smc^mvI9;aF@hzJF;=VBTyfF*vK_x@513rDkJA1xpSUO+4Z-e>AG0vXb?h zj#(VNFa+0Kmy?kRsdsjAx}eHcwMqTtieBaStLA^drC)*<`CYMt0BS=ZgIB@($lRsU zEkNXsa(DLgOL1uIbPndVu*|lU*w0*AjOl8Kj1ZK$Lb9`CeUw|NEF{y&*n5I`H#4zx z7!-3B8DchxUp7j<9*Syz`bqN+1lPn_9P1N_Ho=kSN;mAEyW5NNTjts?i_AQ0-uH}^ zKV*~AYn5~>#lF3fk?a*01vc?({`(Ekj>G7$I8GJbXbkl)K&~0Uf%yAoB~$L7!=5}4 z`WNi+H_7_9TKKIvL;pz5|96V>6U(6^&`IIBa~~x7byZ?_5#$M8&UKUHY~^xd&cq`L zX*}>$qAk88H>}jFNQk|?&pfrxMa6M^VplG*G&|~NV|<#eqvJW#1S#=^91zm{dPGq` zA_Sur6{-w_MbC^54;NI`CVHw07go__102xb-WrIGHAGvCS8{6chwlJ485KZ?{6y4A z5Icq(9|;a?Mt_4G9O!~9r6$kiACG+c^qk2K2-9*nWN+k3%$cIHJcfpb7V;%zl8VM- zQsg`}>OcS3x$6OCU&3p;o8G#WS^CPbO)v`mBouMBjiUqD979?p;ZIy3hy>m--0>yN zgpI4UH$R<%h;wJhwDiv)>CW`1oVb(ao`N25c#QocfrBRQ!JvbaAz1|c<9{~)4~>T` zd4;r1GEPSqc9V8U4W3W|1Q5rdHuxVPmH$5&mB9FY)a)bWk!n=+HHWtVxAE+7#)C;^ zw^u3ZOrN_aCwacE+D4r{sbmRz1OX?!-}UR)pB$y_gow{pDy|ah{z-DrCc3$|(Z@D8E=^`+$pDx4dJN7yDbMw7|N)xa$0jTquw;YNW z!Bseouqp+)uzxCPFvSJB1aTFnmMIb^O*JzOb`TtQauErj+iPI@dY{&|F$Ib@70L&s z%JXkJ59ZOXTPJurbv!-M-6f+aBg4KNKBGO8p<|IlJpe0CXxRjk-}qxy!Gb$=-k9!? zgE&wS`gz2f1=f2M)B5GL(f-hEJF#GKCeHmCIoFW22P_d^0J08`**juGE>TBc3sH{d zDYIf}nxx2KQP2X~fcwC)XiJ$=!0B%k4t%(KqfSvr@nt2UN^py> z-@a9pmi}Z!!Dv!yp_QN{MlDXm1&*NvH!MFMxJexyey^O<_8xGgsmJe@!x z`3~JRNvIH`mZC-x@d*oJ)JBvs2{3VLEy~t}FmdV&)FA4d@K&4}PD!00ae-QvQXt{M z1!_}D&4dpZs0)oWzbW4k9NOIUuuo@H#;<^GuzSg_Zm#}Ot5~lm7yFE4w$FBST(JKa-J`UYt~W{xg9|7j)Hvl=#91 z(3r8KEa*yEi=u&C9{Rn!wl)Nb_=$5@u4DFPzsozbv@93I9h$bW^HuWFB~Vvv;SJy)L3dVA%(@sL+EdIZwHXM3U?7qUI zj8W&+nW|^OJN7|LO!J|hmQk`(m+Ul!BM)>HSEVK1c!G`bhuZSOmT9r|KApOgs&=f- z!_Xr$rc}OSm`pB;A}WD+3wMRCIcRc4!U7XSjcyQ}_qyC;SP)&qLQ}cPebK*SznFT3 z(z}-=&G)%RPQUwFmyfCVqZYMkD*%ACpsj(4L=Mvunat}BGpSk58j^PN^j3hS?vKC_ zsAUI%Doq`s8r=*ksFED+Nw80t*}#Xz2WQ~ne86ON#WfjiyIl+^boyUAY4 ze*jaU;JrNzM{1UYQ1uMziKLR2DU-%sV>A2RKYmhzCa?sd$TeNBNZDe+0zzZn6VwO& zd0fGY79d`XbI>**0QeW0Dz})HuY-Z>>{qm6gp8OTifYYW;(rnx**G~vTgYbzse2(W z0v+_SzE0BKsn#r+w`H6^b_U$USo&CrLgNm??-lPqm^!@!bl=X7StWAY@T( zXV{t%gMS&Jst@o}-d$cXNw?ftsGV#@fSAH?2wzWXy1-kWR88P;;3ld!WIRWIA+Gy@ zjQq|l+o)2tCjISk*OxaK61??+#>lRWkK?_T(r|oGhdhCJb3G^8iV6ehvT1UYMzPew z0NUex`4riADp!H{IT0Q#ZBQ!do$0c2<`Gcy&)qA89!Dkfmq+j<+txKT@yv>vIT2p7 zf2>cjbE!^z2U^u6!4tEKg~xL0k`<*CJ1+K{spLa<#;K6YC6kE~+mK1z&AV>13g_5Zx^IWPo0lf5m{~6=a&ve35~l6LKUVCxbiN zZhwK*)yh*Bg$UTJM8DseG%(qo&UVKr3d!R^wXSI~WFS*VdR->LZ|TaT5}R`5n|vK3 zmdwmgaFV9xgC6l5wT+Xr(j}NiHBAzlT%OICB*C>u@s6du!Fyk?m6jYu<%~_Ize?IW zKo)7%R>aYS(!2NdRx>B11)EIdFhSiP>GnRZ74r~NMtKG$k4ntH*RvXWn8W;P<}Fqc zBv{S>er+{wyLGE@Ku(q)QK&T2k0muBegpZT-$ee4JF{&UB9?N>Xxot#AT`*t0 zto$gDYQ9W1`9!sU6dPx2-1`1bIF`lSwlIj+w`T4v=BQKFL4Cc&`|d1pA{jzHnq4af zH<&S=FHt)D$d8mO9TuMGKvjsTSJJO&zcnq)S7Vl{@quwv1IVf_8>yv9pk-uavTqz9 z4;{`s_p89n_wzEHImp|H93N|?^6b8j$#)TFsL&LzV5ei+rIe-NR)`LD6A_i`F2D;5 zKPds6zTu4ZA(cd6|_^EbsFsVB8p*)?@tcl;mUdobk+1ADeoRadun zO9#;j?(nJFcE(QoXq`Lkvr&xvH|W1;G_-noHwJ%7U$!hj z_cQSHl%7Al_tI)V8mF&^(-!*?5>|H zZr^BpNTgf@=d-psay&f8VTW1am* zR~<`ABikc%o33LjH7xB!=#&2-yjN2z+J-tb~queU*Hl#(_TO=26EokBnU(R{JDt0bLY!m-~ z8XrOb+xby}qE(}6L5>7nl^A$8y5E|=#tmyr?tK+y?x-3P?P#wGB``VV-r8?4RP5?? zn*1uLE15M^h=}hOTOh4z)QgHtVT2iYp#3*9u;$gbBJ8bx0oPN2)40 z>n}MiPbVOS=PFseWI$D9z^&<)(f&9dd{BiyhH~I+vB6zq@KuF zR-ODtkA!c!h_QV;1yB3*#RZ?Sb+zEmQ^mYlkA$aA<~j%g`?#GtYSD`y7OuEln9W_N zUia3Z?({&NIKtz8S%q+!V3M`PQ~F{kmHS|-*RDO}T%ts9yMa)?4>(Y<*X@>%EvQfS zZCxc=OUhFtjSm#kq%od^Bu@MlEPq9rYF8LbeKNPUrIxQSdVR}(zP_esutly< zje9%&&A#Lgg-k5KoAEyQvUAdi7$^uFA@}lsJ1G;urU;{vsdamI0A%chnxiUNWE^`W ziJqaDxVU4JhK4_2F+Zn5Kr=ND=~D6s?Wp5oj?R42-E0k!AS$GLiM9?my#~XKpK;GV z?}MEh!`j_%&U`vMO8ug%?f5B@?jj?ZYutkYI!~zHa2>^v!wZ)c1DYc3Ah3hX?U>sI z+VUSh>l8(uOVM|3QbU^D*XV7c9Zs6Dj8^)eb-^6I!`7IoI3nnWzcmW}1cgdH{ci)JxlFcf*k#eHbE5J~gw9RQsIxe(q5^y-0 zgP7CRWXHhT6KjLFicrTZqx7+QL%(r|Oqr2MJdfA<-|oX zzRwmVgh|TYAc%v>cUnb&WEvdBSDBqR`wCtlxf!>eNO65xKiK=-YQce8s!`qw%Vh() z!kjPLe210y^cH!iuh}-|o{6fRuk*P&wI$iby$0ExFYM|WQ85d*XKkOexT7WN{bfYPv+QPY1(=G{F;bCvYPWoa5w8qC1m3&+@$%{sXL@J zK9)nGdumoP%ft(>GSz}yh~<~Espk@}1{I7K2v%CS@K>zOC-S-A>M8fK!d3(3_{7{| z#m<$N5m4=eH&h<}FUpY7#EGBsCji{(fAIa~v~?)#90`dQd?P5I_QChyuEX<>32;?v zHmXvGga}pYb=uX;{o&v^0g#lgYW{{2#UEf+`F2CYlElRiGL{^gQUG3hh4I|NnmDBp zqLkA2u)doUL!b+Sk|3h?NahPge1YC9aTi#NmN(eG(v=?c@4Uw7o6+O!sg8f!le7N_ z`@(AEBu!2Gqz2z3SBg;np11q!(fOy0sOdvl5>)Y)ve7a}4Ps|#BVkZI9URWMmvRQ_ zT%wLEh-Bl3Ataur<)7%r2%)nnqzmWNZ5>~3o$^8h%A2!`i}7f_tIgFP>Cy$JmUVr- ztpgttD+6$F2UUzk;zIoblCv5NeX3)yjKdnh|AjD%wh;@>PZYUPQyB6SEu~C_3=5bfyz$*Y zk8^n+j9BK3vfhb&a$%{B!PeNpZ&U3=X-c>`Tgp#THf=^#ec96PPVk+^+US<^huO1s zC={-qV)&|m`t9pX;&r*$&{c1K*m$^IeyP=m5)}w%V1DpsYu+KACQGzP-(G3`2Ae6Y zO0_peZ1|n9YFQ;ty6fE0GCTMR{j_2=9e0DemsM>wdx$9eFw-~09dj<^m*%G3+a{6i zwBxV#9E9$l1wr1kmdx?g4JhNm*xLwZR$N_6JP#$KPrJzLIg`UR2O3z+^_ZVpE1Gg$ zioXFN(XpRWmclz;9a}Mi!c|a7QpfG$CK=UgQD~ua!`dblCfO8RNuY@_V=)~?J?HP{ zlU%%G#?%&U2xtHUlEn!-NB*v{ng$vV`N=%_5@5(n$X0jq!q6$y8d%yg-wBrL%ycT= zrEt=nQHyFydss_lADyoNC2cIJEyi{G&UL5fAKWR{nTRhEd`)=kwHd8#W{JbCM0+V& zjrzRs{MbCUNy`-Qeho*#Lu;TH=pgC0*(f;OdWvYD=2&-sDsFuwu09m#EWx*NR9^WR z9LPc5;T=sB+W>}JDk?M?5L^_|ol_Y*V1v!_?gHUy&g@VG!6s4sxi8w7PJWU2 zL#BkG-}S~`RX#I#&U`a{dLfKhkT{|s9mG$=5ofiKNmP^WsEqa{AWby9Xe!YZ;Tg=3qtzr8B2$Ax=ks6}~YmB6Pue~cv@&h-B&pD|r7pp~Ea?7E$K zX>~U*yUd993rNXK?!He(o+i;zT$mVy%mvutKT$Fr){HS6-JiLNWA1NMK3U5YRG}W5 za+@;Wo}@tRKeQL};-X^I?5;Bu_S9Gz;*7EDz&{kwT6u5R(P`Km;CZQ)Nlvo6LtKZaAe?WR(@XIBS%VUgKjje;7l=0+4fUc zfSw}uYMW|dY(`h#>mvoNu=`PSUVd2&@2cy@=)e{Df*AC&1p>k509T%XqY~4xQN%nh z%O4VbA*}Pz5ULxJMQK|;!S0!O?A#dsB8Fe z2k1)+r?TL04%xmYDTE^o*M^&HC%CGA`n;fWEmUgR=;I?<)Q5urUl?<-L1!-ezO{OfvKHiZyH;A~`tu zR>>G{+4BGo^y?^qK#BSl1Y8Rmdt3(+1v2a&*o#Lsm2TBGRzf)A981pMeIP-!>)>0aq@udpQlB;(KkNnwa_+Y~c$+C~N=4K62 z=>%vAGrrgZM(^IitpLPk+U9LgdPY2%0$8reeGZ2Zfo{%OJ+&@?op*ohXB5SgwWq}L zQE-v755D7VVdEl|GIg#(1s5u~5*KmnVfrENjeKP}xx($;6wQ)@56G6`3F6=L*gFhPkSB$X*$chxRviDf~S)+So$U8dJWuvmPv$2sKAkF(1k z*RTu>43Mw2;B?6Y;*5OxKbbANPHG ziVrY7HRldq$q2`;lP|?jN9j8BhNs`wY*bBkZ@yuJysrw$u9dTQ2FRZVjJ!sw8nxSH z8Sw>awi79uT+JBW(v|cI2ODOM#j3}jODOQCpfb)QHuxVO>6HmKem{)4@-!&t-=y6W zua@xokjT%k#XS9xY30Ef_w=&`%Jj`6`iRAo<(37N515^9Bi&iepJmWy@30CL{epMSPe`R4O_m^(y3U++bcPoD4LxJGPtEho?_3!#;?_#y|B7sqm_J^~1C`S{P? zh{ba`TS~!ENo^5&qR?1&6ah4(c{rhnyK!sUm?Mmp8QueszSxyUCc2wF_kWX^N}kJE z`L#k7J7@{v<{ z?*4YWM`r(U{DYOPwvW0sqz+}qsg2&StHfAj7LqD~*@2oBB5R#V|H!^z_!iww3{BN8 zXukB&(PpJiII79&p>@gFKALBHciamwQs9@7vqx6q5}OKnpHHSQDIjNEp37Te+dQ|s zCYs}lYbv|J&SmTTC9Qbt0-d(}wEUfWc0~QT{=fmPF+8;~HExjcTb_`^sIva>+IvXV zjF;bX&#dv=mTW*4Dc7VYfFD?^ZLD{>=q$S*wER3=V1efQYZmzGCM-1z266#D&1F3cw90Um5rj-!f_*^`$hlT~nvJ z*R5>^Tkt>oO~zvWX$?pjsd9Nu4a9mIJa$LN@H&Tox}geSL47xnN$-GnI#X%sh}lG& zS%KzuZh(Atc-L{Xp~-ecyQSpTOofh@L$qE}7+4qZu|!E3xG_YI_AD zhI&W=FH|~J2L^u#>0B+V!}}FmS&>%HsA-h#E4;0=l8(;a;!d}?(@B{YkcBT$`;K@3 zXW5Op*d{)4KEHbbk%ET5EGjs3UWyBl#l&^AOKL4Mxkxo4T>JW&QoxT}y+E!dl7oK6>Qd<`CE%jdpZQHpCsip5tj` z-tS|7da4P8AmuZB^p1AZbBsYAfy?Cgv0Q8A7J_``fEnc92sv;L0SD9{e-s$n{Mokl zD=uEYFKyKofAdf}`YIask$Ffk0>XT(tQo+n2L*q&N?u%T%@k_;sJy9(x{82GH7}2M zYvR!EQ!em_pZ$DX=H?z4lC+hG(y7pAtLV$UdraX44))yxHP|7wTWoZKD( z|A#_*kxqY3hB(iodfuyAJe>aiQ(o@N7^};#wL41uqNov8l_UyA(^9j1iLS%+@;L)w zMy6#8m-}X5j6h{HlN(10ZX6R^e(w$V8aw?B6CkGXGcp#ETP-?%N8>& zii$Ym+>Loy;A29=Nu#lQ})Y_IPwH=Pn%wc9yzk1k8Fnjkkm2 zZPwC(URqT-bLXiUeUYRmGYL`9op*$;1A)073C@0f%qcz4XoJMIT_Hm{o3qll@Z0-M1tu$52lG+O zXN$};q)1Iq?w0Ejz5ID~BxA@{6dguY;m-+0T(_%H=6m&cuWy>$IxK;NqL1*Y=XK4m z&;wBb0P-`NFRs8slyL{2ILJDGI72d~#cD`Ncb#TF9bs}u5w0Kk+$)I^{yB)DZUq=@Yj3G2sU7UELd|k7!9I-{Qel03^HQ&>&ExpQ~v&P zsBPB|6l5ciK#{{_$w8&aE6s5?b|W>5p-)fsBGH^p^syvN1J~#hxB3r3gr=Oy4>e$B zHz)b_<>}t(5+SN1VrPyn(H0zQrfqY01|lHFEYl}h7!%JW$qY3qLm9juC5bSP(%U{9 zIkT^*)z{v7l`pslN^PFT>MeS4UyAO1FT3t6I&IJq{pu;gtZ|*A=af3}xH@j}2zk)N z8+RxDTf;moqrxFg7;x=zHTeb!?*lY(RN<4%V|ibOhZf*#-w0sVAEGeN;)~Qm z)AE-MXbNezJ!#G2>!U(?r%Hp8Le=)vf46{QjvC@^bRU1aIx;DgZ^eOGLn z=9&mvGOT@IRVt%Y8f-LfR5C5<&;$8kBEMXB14fv6Bw|mWgz+hTNaaP+KLRXmH1|F< zmo^SNO42N);X>Zc%a?7<*&*&wc-zdbUPdiX-+?C;dOhuk>HchGj{)T|qFn97O5xZk zQS1#F6eUD^sxNSocXLyyPbTp3?4oeV{0Lr1R`+|)NB>kpc9(IjilZ#bk^g1;Lp_n1 z?54mHV0x!(EUTH#GEoU@N+`r+2YwmsZ@O5jU^U-(KLJy4M_h3H=3L0FjLtRGnROdCqSRf8a5CS8Jw! z9Vt}J&8?k(Qr*P}QvLz1J8ov7aDb-za)8y|>qU{!09Gc>bhnY`StEbO4w_hY7Rn#m z7dYIRHEw;(xx?9aq9xxu+N*R_@^zmc;_NHc-YI?gE2l`CU%{X>P}m#n9xl4^VgA`5 z6p}1V$_HlCf3J83yTe+o{>R;6AUD(1Mj6cng5B-I=BB3eJ5X+Xb|H8<-QXZL7^0X) z@HU*4Ona7&88P45H|}y^8tk-tI6>;r*jix0+y30J0Jo}hmc=zWYct5KeF#=8qdZw| zm0{Pd=;;x6x4whVx!b{mr??!|<67sML)|$0PO@?UULK?Lnk)zBDixp? z)SI2}XZj=1XfRg}s~-B6@!~V1zQCx%ju@U%3;EMy!+LGd>Rm$9t^G$vY$51oepYO( z{9Y7_&DJo#Bbq-N(kmiAlT(<1k^Zl!B^8@na#I0>;ZN1_ofQ2&fdi66>*PMftKz6R zh0H(iW2_lv_~e(-yae)WoeW6%8$$MP`4alv__ZkJ_FUNh}9&E4gfw`Y9)lc zw_Z+9wz0#W#YPh-j@?Yi)=!9y30K)48??renRBy&MC%86G?aThEytNbJW1YK7PxUl ztE1~f%27APM#VOxUwPcfp}ypWQ9R=shczh;fZp>n@dndgzn31bli{|18EHr{ny+~t z_DVY9*>%Z4e2*xrOhzRiB0bx1{ev@{R&Z0Ts(SUIv_B^Ww|n;0VEg6FqGLi-0ODHl zDs%st)tTbPS=4`x{UA%^hLSUP+|W~Pn5O>F!>5wy#h6C1+c7*xi#ae5CGnKaC-!Q^3FTULmD@Ps)GIMjSZI5sel51}9x~I|ht6+BkEl-rZ2#qZQjs5~qUpnn1? z<^(ldUU8n#mqG31znuGJ@%Z9>-MU9z8yxR4sk|o2=a`Q@{tV%3nV*SWgeC$?afcTt z+RnfVoO9FLm+bF8qcy0LW*BV7I>E!;IKjajzI^4rUe5nwRsFvhYEE3?dScn#T-nm! zWg63Quy5^zaQcQQ8v8gpUwHxYt10%IqenK<+bjTQzhh}#+6Q4sM7KFN7pk9-Z0^;P zY;sm*juGQ;{I+3c$@mrTd@f@7&Zm$*G~+j)#b5YcitZF9=I*Zz=LZxw0Xmt2bD_Lf zY;ZrSpGBi=Q=v;6$+RH9NN705a|x7YnZU<)xTv2eJ;p_iO{o>CU4f~8nNKP+aeaKp zHAp)<3eu!lE>_mT@{m8V0Vt19BxTg%V=*?d-^AD#B8w?Q%nCgu{3hs}l6rqblhf>Pq| zO$x<+`e$@WPO1U_?%#zfe+HCSh`QUmacH8qGdpoNZQc*n#>%t`qg^!tDdW#{hAq%? zP9tGDGoV|SX1i#?&%>7oy~a&BoWEs|DeF=#zjeTEyNGnI(PLJ7!t(~g=RBD}^nztU zchPkv@D;?dkR>Jrwo&!hPMbM(;)LQnIVf!&tiIeiS>3wqe)iR@LMM5*Y_ z+XE#0{q3uCxG(5Mp%(~yy{b!$DIwg8Gc9RPvc(uMG8xLgF1fs^Yyqgg!7@zQ>A0%# z&sGkB`*XbcjOLFW0;@GMgNMR>sho9}s55Rhg}jEG?F%bIN-Y4gK*gc%)dBNB`BE0# zwGSQ>e!iQmgE|_9f2&;J1%p0e96OAp{#1UK!FmgPx9*a_3!$>;Za=*rR9 zQ_+pe(~=y;-(X3#&w)3Eef?3`h7w1!3L->pUJ!<&Bx?+(jwVNdBfQmsq8`AM_khpLjJp3rEWNkPVdQ=LcDodx46kR2@>&0XDRiigiQ z{?L3^hH+hS)NqXfFKtf5HKiNKmTqVUR#13Kcad5ysJICz{>Z-+W9frnN6ANLFn@>5zjwy)Z$PH z@2E=EzR1|eaIj)BAPWZ=m!2^Bbs-mnpxYxT*Ml8?b*43^s^zcHoT?bg`#kx4D1Cn) zpoo9t57enJ8#8TNb}yHx2NNm$33VmE=~{*Tu3XSK*;&J^6Y%NsnCy{;QlI1CTJ^1A z_N_saM1tCV9xh1ofVhdbxYHWA4)tKZgMcWTW~rB$-q`ASw)t(Z0_`zMNyY3}`@YX+ z=-W45jo-_d$x5^m8^((#)b+aYG|s5#x_xdL&2JMyw%FC8a5&t~_d{)IqpXX=%y$Wp zcR0WVE5QBd!e#Z}Rmy)4>WdhpZwWy49F|gJ?i07H&#^EH$c|M~UU>&XC@Q@=(2YaA z=4NKEl55RT%Le)ThuCH-#vI_)uI$7?{t2AaY&(c;l#|w3r3dxK_SN*YRzLc5;;Pv* z{PB0`>L+zGWMwnSRpai}VZRT?(6x9P+&%Ux!1VrtmPCZ`bFbXq;}mY0yw3KJiZR8N zB3@NO@H2Wsj>uQSIPqRBhq~G_hZ?U{CXEK(V04p#OO@Yom(^F%6ZUY5xp6iu9rK9D z?UZK9xpPITo8+eTkYQlOVs>5#5mtAJL zX@b4h{h=Mv4%}jqX`os7McQ8iAgkWPaVx=g^> z>MnZmg}hM!p;2PKgC=Aq7LyBnX>wQgU7wqAQNBhA@vEE0yD%Epo1KCtC@O$H6O)cX zr4_xpe`h@FfRUTZV&dm!MNjbswv#kPc8SUSd+!%z>@g0;+lqfShX$}@$Qf62k6F+W zd;Uk5w6QydTFKHwC@-q8u<&TC@8KVU{-63?TXnBr|9)%!g;wabIjstFfo0OkA^%ir zu*geaW*`LjzDqDrvngYen{LSuBs}DjY#T=;&l4#cKdRKN+eJrFMlJ_e#2O^>9m~NX zR10@oZ{}+6T+oBzWYo?-m?ez+sl@r?Y0?G-fmn3xO4+8b@PeSyA{wUJ9VYtD7Vix1 zQLCX-*d{*zC$0m~Dx0wl=@91zBS4Rd4`O|2GWTAvQ!EO(nRq6*f_h7-5u z6W-ZS_tMBg`--*kw$ukHX+SXeUP9JwYA4F`35<5sGL#buns(HI)PU}o&|yby0u*&$u5~?ryI{av-$b29t6Ofb<_)A zwgol=z>#)dDszbSi%L2}Jf4moxiKf^XDATU_~=QJsbzHhaBWxfq&RJ1z&fDe?56eQmI@+K26f(*2U<84pt^(^Q zfl?hZ@5$gG!Rs>X6*X`cMs8UfH`O5=U>MQFl~tC#ExWOxbh6ov_lj%H!4Z*VX=U!U zGWDFI*BL!QL>3yAGA>?tzOBe1{{M%ww+@T)>;C;oQIQe^K>-DoZUGruKuRe|VL(cx z1!jmLZbBpl5k^9~JCsfl1qJDD1gW8?3E)h;(6VlftGq0bir ze(q4vk@-?fUV7`fPwu#(!%|R<10HedR&`&p@((uHPcTlGQYgMh-RVS|Nw7r2l_Flv z@zOBsRQt4b-@!e$!wn!>G46L;GH9M|InZ?{mV;++L!npdXSq<=ax0cZ(EQaZ5|>v$}Hj)-%6O>)%E5(}LB}To?wANCRQzz!M^O^u^UAWSqt!6pKySOdb=*WU+s9Vw8D z9H(q4u?AqUvNqkOXHkbiud;Z>nvaU!bJFogNmYH!cXCBk^d@O&YsQx*XC1#6{2=)E zML}eyxcR>GU^*LUAhBx(>bG)6kf*6>JlG)^ORWX(R-L4pUs|@0;d~I#|6TPx#{PL1|@_{72(l#CKeLuoF$mecJ zq1B00;@kA?N42m_MDe>zKSP8>^CMvvCyh}Bf~~upTXOKswY!oqOLC7%nXA>F+UnP( zt-Xt5Pvt%eMQI;u2Bb@q-Vt95R-edXSKcKe~P_WzfD8Ty|D%zx;Y zf$Iw>pY_yBzl!SB3$uIFki7mB2>OlK0tR*icm85?1MDA; ze%z8Z7wWh28e7}YXFR>MA`V|YTbyuU0Pu@(oBU#8=O9A%<2B^SGrDVU*<;6iwtez~Yv)vu&(H3)!RGY~JaHl;z1Axt*X8kq2Tt4j z2xVfPLNBV7+nh$T6)WQNot7^=|F}t*i949wrFPqy=B_mfU-yNWQ0LMU4)Mee{Ld`9(lC7`Iho))1!&8IqD7@#X|{~g$qbhnn7U4 zx6H_(q4!Cb6HEZz{W=ULbb2U6IpTa_q{O*5# z*0#XwJ0O)*g*Msr2M8$uW(Hmb#RQ#Nw4+M}4=FoW3Q6Db=$YL#H#cujD{lqa&tM8z zKyRip!CnHc3TKDTRg-rRLTSwNT4!U%k=PI{jCua!^|LE(Ma-C{iFcL?mJ9{$ASn^)wraM2d(s{xjgn-lw9LTosvJ9XE#NVj`whY^9~QchY7#Je~BY_7?!oPw~yyrSlBCD(q~x z9}d7t1mV3>qGU6N%A6~C4>>BJppOqk;_zxus$@q{A6uEUpRcPGH7L|}u^Q(VHAsHu zEHMYJEGL-9507pQldW~ZQ!{-8Ng{*)}YLd!oBb2*b#nzaPLCAxuX_L!WtFm^{*y{UJ(OI=R#6t3waec|yA{H&kz zzZb0azr^=)MO={6%KAZotc|p87o7qi1o2@Zv)zHoZN27Oot2pnex&Fr(OhS2AzHI9 zz9Cgs!kYsO>ig#X$g^C~d!0aAnO)UfgplXcg&J;q5M@CvRJEll|{O}=3aO8u^ zYd-@rT4Wxt*;C~)n<0^r@1?}@!r#qru@6uLJW7WS zwO3UD{qa+1R^PmLunj;`cpWteD&e~?Xk>iUH8fGVo^{k8VAGAqBNHnj&=52yyd z^N@7`2c`Y}{Q!8#ai)EFT^(r>NnL%t-P#)VlE|oUs?ikw#gRF$yn2<}Ax)Qc008R` z3nmSp(qQb2+fCgVMim{kz=tL5_j7MRiri7h3kkA3!hdZ{1K)mbSb>Y+EaYrk3VY` zdNApV#}fWYCbjB`%>%WVXpTo{i4UXR`tU|3FpVjDUARd`=$3$;^Qp8ztNy67#6r)kyd2>E6)EVfPB*2i`npXNp~) z@TLpozKgnId5RhvfJuB3D!#BrQSzR77Q|fny_P{<#+A{}-au*Y_py3#o+xPdBBoR^ zq*8Tfs4>WAU>2`~aSf-#fz5@?`fI-$dv8|y99wE6E#7L<`@)irib(Ud_ zUq%%Z7I5Li`gm|ZI2U$p-{C=Go$FTM8Yt$TDVoLm7YPOjBK|L!+V!1V+g5n&WQ%3K zE%@DU%_!1BBzt)CBt^4;myFeUWu$7p+fH}l<+mW25Zud)2u;g^jk$%t?NkB_VO5j% ztW5_BSOiupRmm*h;Ui7r_tmXJ3{WNVMihjd$Q%}d@!UW8^Pn?1wkJ2Ntd1~BbuR*Q z3#3}-xB=7mAgsmJmg^J;s}=JopB|kBZ^=Yr;R;wB@~5>>fNJ!WU`sl&3;-RU6-jjE*twY zwO0VT^)YunKNQCuvh4#J)?eO0U?UeDUVoOfBR_0OLR!u8{T(5H3^ydpyf0)jRfY7%6hW6euUa4Hh1<8-*lI4sk=m~5?2L^u*t2LjXm_j3 z_>r@o60{#4qDmXDT&0Wff5P}yYO91(0R{j0UB2dHyYejWbDzq}%Ib3`Mad^D61$+& zcN4==DDss=V>g!m&2mbu{V0vy%hhGJ=}ScomOuZQ>AH=7IOig5mUFT5=(-bl{B1Yc zjhrr)S_4bxS0{epF*p+;kD8uQ-63^1WU2i*P0_G^qJkrQ{w2-86Ud)SMa@aY>F#WeUBPN-D?zK+Y@ z>L?nGE_Lt;X0B}ybXl!{>gx-g?Pob&bsh6)FWZPgLhX_|_isJu9f}rvcVBy66YywT zjBDNlh(X}d^e?NLF=FAMh>XWnGNg2T#?M972=7}uIH>u|Pz$F;z*mnu-&M7dPSQ$B zN%5YZSGY~#B;fR2$Kh_6QIij2mQ3%Dzz<`jYr?|9pJ|?b;K;ge1D%+U?`&nXzh5qb z2KzCbq-ec}4S=iY_{htD#)#PHQfZr$Q*<~!Vjvm?;3?f*T`Z_VS1`zaZLJIs`OsB3 zg0z4L-$HWJn&P~MBBVi4R@1e_Gk|}r6wAC8$Q0}oyoZKd6-K8yzVSZ>>+>JK>|v}% zwHgXapZgfRLeXksgv5Wr1LrY3zzMy-QZ57Z=p9o2_3`)Du*@Q_H--3<+@9t>!+BkJ zfRFiYx+Vfr$^T#Mu>XP%gZ{(z=3nfvKhMw`e<3IVAp*1^ad5DP!K%vjLlR9HZ-APT zQ?PN=2=j=FZ?~p?Ci??2HxGD{kP}~<+Ta`$06e+No(yq(U22bFq zKo`Js=N{G+;SnoCK`*miEBAyfi}x5e?zIVuDu|V|2U_+H8C$pI77gMfSFbFy3>u8% z+%|aL1u@Uta0$x$RM#aK*J2!zd(>B>P=OVCR2R|p9$HX!=yQXGf#o59>ozu5r;gT_MeZWl40}f?-yl#Rp(u;FnPpq*0 zYo*TX1~UJh^2&EXh7M--S?2LDRh&oGvo1I-9UZ{x=W>zDLOi>-^)5^Lg(kVtXP%(( zlHL@U2c2HK#J&(Ese~n*r&ok2bb8wRz20kSa6a$y>AKQQZoM`$mqsD1O2Z>~6iljy z^Gx=CR8;pWIv9_@ga12y04S&;z?S?&=X>Ax-tmTVUELpe%8+w^p5RvvVo~hCl><<< ze~f*qu_fdM?DKp2(@h7eJH;TZud|TjFx!8h_qc=YFZ*N=Mt-{|D>v=l9@hy;0}u~G z;q7~K51)X^oZ5tMR@_>rGBu@n5T?l4qUP%@_JDS0{8cWOcLq?WPbbmS(#lF&j^}&U zx7?;6Y2ch)v6kziqhw-iyuiy{i%U=awDh{Q^$g-qKIn)OBD9Mc7*C3dTkZ8vVV`B z`u%_K`Tdi^{Le_mZ-y+`z`y&gJ&xY?_G|O8Cdnx&DI9T$i55fI6(&YTnP(qo#6zz` zjuoH$Ong&-&?(^ZfVBteM64bj)(&oqy_*=2u!2Rm;^4yZJ$zm5?up-)IsrGI|=4Utnn8koQQc^y^l?wy?lok;=LzS|nZvGaTz(gl1oT7Ipx+S4& ziF;1s9SQxZM)f(+|N63Ijm4+wRKE)Pq(@m5KbsP`cZ;F_UE9v-fPgtxeXF)xV;1>L687m(ADwWK&YNUT>zkM42 z${pDu^;*G)AbA9?LRFQO#kAi5(6VF)q&fMF`0rIiDk8tx@xHrwkM)#O)XdH<{2_zk zkykP2pFe$mqTZ*V(D0Roa}M*&&mJbQ8s>oU1MZp*;5zo|yq2eMC!l5w4GoQ~%RJ~Q zJJHh6#iVEeS&iSSCW~nE+rfE>ceYiMw2T)vn|!b^DV?=1$t+30V3Sj!Hm1CZN~c;G zx&=xyv(YM^J$nCyNx;-E#{~WB^+ezL{i6R=WBtiv{reaG?>N?KwKI8uOw#%7n-R|~ z20JrHr=$rsSbuMiDFc9Y;f|C(+_(JeuKH)@C^-!1RKRCuN5i({d6!ZZ0G=@dyp{+k z{Q;+$RVSB^9EojhZQCdDkItK4(7BxRIC2oseRz0z#}LM&hHScv5T|H!D<*!fFI$PE z-2>PM!FB*2`W0~3GbvbD!QQ#1RSa+fu?!;(@(*nbmN$VT7Mf1%d&=)>2kLZA@~06Q@tARxjgCi{J5 zrHHtAU1{kD9nEECM9%PhMENf8a&Hxy<^_%j^4*I|uU^2$0?D2;eL0{5GLpcO!NC(A2VRZoB<>n6Hw_Sr%w9j6Lqg6)=%jxi0p=YIebUD@q|DfM z3czUpZCHbYGWIF*;U5BC!3GOCFfgk|WZ$~4rglcSOmDqwV!|kidHy~yzIgZ}Cg?Gj zI7LbpDSZB34Qs;|1a`I+P}=!Ax7PvX%&X+?UMj}jwKe-gvaIQR0f$$n^+US66>+vo*^XX?`fnb-_08#N|CLYpj0iz_(hykxXc z59wb9=11u!~)UVJBWUr)1NwWLtG zjgA=q3zKCYW5ouza9#30Nu@e3BFmHe4f!Soi^X0;XG*@&C^y)BzFW9TkuWSF$;W@# zBXyXPe!uCXpy(!Ekpn#r{rvZ!K2*Di?f)yxf|qnI28VzGL4*PaBf%vph83}(jrXrF z`HDl(BJ|y^w*A3qVq;?igJpm*p_e2igR@_{j>R>dpX0#q8KQ&;ia8;gLvSp{CB0gJ z_4xSsB%ev`qOjs6x{oEg4@KaE3_s61DW$UZok03TRHY9X|4F?3n4+jCMTLiLl?mDvKIf4md{x+hVXc^~J`qX$SRjZ(5dMb1~+zRaHAG8<*)VA4FB2)b-%# zX6Z<40y1pwFsSUnSK@tqXvW-LftC3mv(gZWY6+rq+O9k$0$R9 z(Xp%uj!=Q|Az4F!57f>v2dz>VQ8A-5yshWRE5 z6KMcUeM4=S9-><|y5v2`)vc&~!B0!A>7A!C*J)}IAR9%xe(mnIDT8r+({(U&Tvn^P zd2y6EaF3YqU*{?A(q1P0yGEx%!Fc7$+xYn2{Nf+Y>j4yTQl$L6hN_P@!Yp3+i3^i9 zVq9Xg^!y8Qi}CR2&STJR9S`=*2ry84p!XB60jP53q6JcXO2GG8;k4w+v#H;CGP)7G zod;&FuC%bu=c_d~Elkb2zFE#m8QH@djy;$Byx~~;F2tvWg(sy)GXcN5Trb!6XH0fU zY>YgOWOgM$^Qvgi>mVgG%9}xEoEM30uCya+uV_;c#Gc>%p55-m0~N+zxc7Jc=`Y*6 zS|4VNRaav3C4E+ouSd;;m+B~u6}I;>a^@<}&o!R7DV6Wy{MUce-v1i6GpwMimfi&x zE8$P8D@g$L+I2wlruGGM1kOZlIiyRs^wfnHOra1CZEAE!O#XIpAX$Y@dp)oBwNotJ zH8C-X7ESBWS)VECH#*}pZ|*V0hSPHL;LM{%bY3J6y)U9 z=w~WT0~A#NN4Qgxd~Fc@%%fzAYDW%Il$#0u`8cJk-~q!SRg_u^A6t_!Uqos#j3h6$ z2)Arpq}$IF6oSG;g!5}m7o8vqwcw?lKnHVurIK*O22Kyt3TK=-TVEg(TB-J@5W&BW zf(O11u;p7Ju9cbw>#Kj79($ivdQRmB8|JZfWM`~xK;kmRQvb*sv^8jq1tdiQ|zTWB!nByfUEe%kPmxRk+$=a9r?Y)beC;DUE z02Foa`OfjM@Z^XUk@W+CK6ou6Zwu0UCb<|0Qie`!bn*&=!>xO0JJQji9gZZl`?=lty1Go{lR_Lcpg z9{5yG=tfLT=#Y;l)7H}yKZeEqjGn8&0YrdNWy&A3>`?g}fNZ2Fpe=IKeYg$Npge-S> zl-XGNTitags^stJw@_nwxx7&Cr^wHkozb6@yl<#16iPxQn~i_jJykc?uWLWSUeGWVaQ9*ov7zbdO)d}-1Z8%=dS=7& zK_1BgDyaM}PNQtwArxqFEYoe$mhdV1rpW4Is+OWG8p{j~9LRPWj#2;@od5k&RrI{Ut3cLi#A7whC}%mf$Y z-J&}(lC6$?Rj(#}EmwGt-*^6dlXzyzOZp!rdj#8n z?552S&Zz9Fv0_c3OpB3m=QOnNjov5-cUyQVtK}(ZR_p%;>Yl4z`5^_yng6)m-vWkS zc6{&8=*i8hq5oN_wkQP_LS`CI&Dmq8z4#HZA2ygFt)u7&xAiIxd z2z-WOLn8^V@F^N~%cCa>CMNur!BUaMGRxvl{g7fQJ7h>e2}Ll%P!5EmXE!$#Yd#|T z9Anc*32s1XZZD@U^kjNm{qhr&z|7m3HRD+eY)GDpnB7XnJLp~4U9|HDJD`BBLcxs7o;xjS-;C=aM1=Ef!_5|fg2KJ?z!zqRaE z7R+Q5;cR{XvgBda-f_g6Q^(kZSA>j2I2u-L-77+RXyh0kf`TuI+ck_@Ek>z%x~efy zYRm8_>@<;psi7@73LEde#JoI?;`3v3OLosFZOZi$NI$z$+#}A9YtPCm1qUF}1Q91T zH7ot#jsXHgGBaY|?RV3YxNL7VaVaP&Wl1|wv_gAeWi{R`GAy}<4wH8%lf(Q$%DS7? z)!7aLgPVQb+iPJ<%{=NJe%qv2i4k-UMTu(fr8`MEv?HiTzxzA?%o~pH1w{=z32xo~ zH248?oA6F^*`?w5sW(@CJ70iq#@}KzAYPX(@Hq>Hyn3BZzsZWAC;%&WxRxo3VPR|Q zM8eyLYCj+uf{JfEKupM9Pe$(R;cgar{hLIR;PwT0S-76%a?oFg(>Ay*DSH~cfCG!R zkf|$*OD}KsaE-Raj>}1%^a2adY$CrUM*2j>8edvQg0=XXrzRa*r>F1t ztD2D(2OeztDMQ$=YZP_V5tnOPY}G#gxKDe!kbFz^+2-tLXNmkM)qXF0mX3{QyYEsj zY<+^Z>1J{Wecp%8zmo8xwPqfCj-jRifu-YIlPzXQ~}J?F?|R+llg zvrbX^c)~%fY3I;w$mqEoYrpKoZ58yOa`-efGNN%q<;&bnLdD`)9iBMd;4G|vh^>VV`Yhsq%OE!MAN2A%~utoyGIV?Sm!qZ}=)}gk|64cbx!iuuzc{IfO zy_%CTA~O5HE%JWPZCw!=^Yn}pyfcQw*cWQc0!*=l$@{KbNe>hFO4SOZu^Hod_6+F| z&LY;5a3}J9W3$@Lgnc=)q#c<>_dRE!SG-$@A~($Ze1?YCdTwOoh485;y8L^Q%IRGO zrb+s2XxNcfi_?U1H{wd_KF#2DjEf=R?UBlcJ}=o*3`&LAUE}4j!F^`FR$V16_q@S5 z=hv>a6Xms9uiD+=Z=bzfc)nK)_ZfOZ*d&XG`aI0*17YTMb3+^#4T6e|NoMzj(H^d< zj{8`>I`=c8%Z{m5hYpi&SqB6d0ik8y?qp2&PY=IE>OK8FcyclFHrY5k=AuB-=dk4E zGJehJr&#G)`|g%C#KP*5r{T)ujo37NA}&ZN1>^Ojh1G3f6Hl3uTH_9*WP(g_(w%jV zRB_5o@X?5?OcL&t>ZR`b#G#QdG=0}FleDwekrA8nC7P5?jg7^}F3l@mV6b0|anqd} zKG(&Tk0JQU2EOS_@V#&5)l7n zW++{_SHvl;s>F!@CE&!jdqn^IWkyCFRa5`njE!7P$cFlWTzT6^U)!d|NKzaClqhZfBQp?%i^6d z318D5O-@b>@=J@`1m^n)CBZ9GQ&W6ZstmOVmOP0u4v@18Nz+}=p6DL0fJ(^qccPb& z5hUDOH!8lg2wj&F2z!7xuP7aI5YisMK)R<^g+?B$#r4l&bU8UW9^7-$Y|q!X46D@kY8(j5t%GqICT)h_K0q*fcev<5^>hTRF|IR)ZE(sJKQwf!p>d6M2{+6ri@cu*V##FdOz}p?szAN5U>-=?`yWB#{EZs7gd=H#)xE)Nr=NTtxv);-!Y(4n+eu55Xj{-3HUl42ci0(X`mt1VmEMlA^b>^J{f)%@lhw zX|GaY{XDZ5FJ9bHy?wa+NT3Ti0XSE}m%l_yj&~5EI4;Zi8N)3%orwB>F(~k+Z`Bbt zJPg~o3d(rw?K}^(*<|in`AVSN@*Z&0W<2dbx}xcwec=DDxILuSwdrb!B+p`rN6@&M z)rs?(bzS?{vFKtmD5Kyp&vI}t=V&#$EF?p%gU=NdAf6XpMSiU4$p8)Zbn?=6=kIw% z965G*?D_+&eH9Pa+T{kI*{*jeF3C=#+b~$df^FOBldU*K&scO2IsksJ`&)a6PI=Qr zExBu|gwb<}_$~u{g*G}2b^N)Aeo&{w*crT@AI>&EskVmLw|Lv+D()#JZ;1;sZj@gP zt%iT(x5%9^u{<-sHcNe!oJref&K3#FjxTy=QekVNOZ9>N4hD~ShGhT}qlk#Tb0XTK z>FXK}^Lstd=9xK;H`$bH%`e-pFAkR22=k}ME3m|l$C~w7%e+m<6$|MV5t+9ya@l~h zOBOzA_z1GfG(kvOfupB&ZaHHT`z(PkHNp`;M%~GYCTo?HXA7-ov^L7zd=S)ZrNyRlaO1H@;_y zB03*2tyW^2gxPd&Lq5;4ne}_fFNkxcpx(U6`DM1IBiOI+(MDdFIQ!zFd^WJGwiS+? z-m4w0=n~I*#}rcQkB^Do?f-##d5L~v-IHvGc|gqk7j2dx#Z#Y#5BJIf&>jP2Z-3xJ z7aW#q3P*XL=442ThX(nh9ygm&4}5aV6mqHC3*Ahba*SR$8i#w|OQLT_Wfq$Ac$g!Fd_YKnG?YmQm7nw%`igi(+3FV#h zjC%&!*Iw&9qa#B;WYt%|5A2UJ2CIM<4P-Q}4-r$YRq= zl|Ya&SFmG4V{G~Hdz-7asmEh1wvn|{Au*Euac}&@`&s)eo4+AKZ7i4LTJP1|j=0jv zFWZovn9qyY$`!h=!PgXD6t1VIC~*n6P`h#2JY_Tq<%>Lp4^@cWFOVp6PCvP!AhT91 z$r3)y2NY1E=?NSzOFh?Dk)d2N&>4@|xoorv^5X+8>9MdVqNst6dA=rAuHpARu3{bh zKfWQ-&!;3Ot7*wvN~9K>pl%3%dN^$SNn*@sU{KEeL#ul_q3#9?nnWkzbDPk!H$fJg zW_%!KAJGYu-FnJUAb@LxUl$yKb*bJ_a+05$A+Bcr5bwgaf9WHvOl_|y_SFnPLp{br zoIp3GTxTO5ExcYmW&D0dryD`k9T2?O=L|-w6(soyj7|VBlFdOPJP2Qzb?sM9c?!QYO|~KS>c5@35nc8jTI7CwSDv%6vF-I`X1|M(q#`WQcrnyp=|e*F+0GW&@mYM? zBk%4VsiV>R;ND0!mmS69z)(lY9ADQFseYdo3YSLhEJdTZzsz=^Lw@~&LZP!PZdFtK z@F_%{>uT;)k95ka6;(jjw^4vwZ{NSdscun%jKpim$tBlJL7#a#a4KZIZ&k2TUnKWr zTmnUpUXEMXyrM3Q*XA?7*~Q98`~`8Jl_Gj(BodZaKP_`0W_XZH`$^(_t9)IVwwZ*< z*0x>CW4rQ8yWYcXq@)iGmgR^@5hU{7fr^SJufNR*i7N94Th0-IICkOxHy zM=_q8O0aqw52cC0Dba5BY3$io{I-EKdKz6BGYsAATl_E3d`X*~C3K_SaLa}~b1R&E zT<*5F+CkUz-E;4bT0o$;yIDymL#o?IH+$*ju+xA=y&033Gm$Dpf9utCF1Eay4bHar zc20$4%>=1^{7Gwq?JWkWMf}kA(V86;6}pLsJ@47f-+cUFEQ&<$;OK!bd4T%_pA+&U zHO+SHHox?Gkoh^yGco+Ftc1JHOs^UF*v0A)b-!}wl)jRCT^)w8oSj3~->AqM_KbL& zSdRbb&91J8SDB_66cxj~ssH?VpyTF^Rf^3c11%Fr{V~joJZpE`wz)FpQ<9;t#o*x1 z@h}e;Na`Ua-1+(QnPYLFb>jyZ$BO!e9+Nm`DUX`A@tZ?m@mAit0dE)K$7hy!F{XG3 zv1`Hu0tl%LOr3zlgy1cow!C2v1D^&wn_Oz%(2Y{suqgCgf^1j}A4_`kHSwLWZfanD{cknEQ& zjJK;>Lr~iCDHDG)DVAK?-H_jDr%(umwGbia)os!qhL>EA2`YK>q4Hp*F6fj=YMEYWV@rvxG^L2OEN?!Z6ON<2y z&bx)luVdn_@;6O=aL(I`?NDaKvUSqMc*c+qCb(sAv$c%0YqI74Y{zo8QL_tUU!g3U z^6g9pjU|}oTr1vm1))7?x)p-IB6@`;&n%q)Kh|>zP%DP4=kfT-s|8YU0Dl4p0|t2| z^?}>~sMw_T;T8D|T1&5*B<&Bn6AZp51i}^WKDY03a&pH!0=>iI0!_(rg0F%iYe&7U z>AIV0k6v!lbQ}>R+2T)FcdYm(&3aO39T={F+GqJM>z`LYg~VO`w1p=*_~v^C<(wwx z;4^w?mHa(^>u~v_P_E$l<=W)3^kfY|&J>byB;F3Kn#H^w9YxP{jLA#mGdC?b*Yyg! z3(*My)`viU85v5>%j-R<)a#GMl{p1 z>?c}9R@xgzm^s;bamI#>-nzRB@pdoIbt)WA)(cu}aLdCmGqRxZF2a5is-eeNVZLR0N=YVDYc^x{>2imc-9NbwdU7>wL%hSv@=e2w z+4FE+pY*j#Pr3`~OcXkHH$6pzl-@++kJ&CKzKriUBF?l*O0;_PYW6&(GTiXSw};b> zuxj7Ru;nd}RKdvEnqcB!RHkSxSr0ZW;SBZdmuRw{q&mFjfx`+=gg^`jv->Kp@ zsDDmm9vS+;lO|(ljT2N2t&=&e4jN-&VPs|!3f`;{;uaE%vmPeh#HijV>=P}fB)bV) zd&XV44dP^@a%=x0e*I6*1UEF99AeMM5)AOKFyD-fiIf zD|HJ2?;fM9RE?x*=b-Y8S>xMHOS|3}#G&_SZz9P5`V||&h=AOCfchUXukEuVQ_i;% z?WnC()Argq^5&PT9qRgzD@gTZPkZGMUJ0#3ep}nf=nqrZDfW1!>f0JrweV9`m$;j= z(J8RtR=yrx)aVd1db`12H zE9D`_6UDPs=NJoSq8D9~8*>A;epO5mu~aoU5G3zWMM`Ex{E)aJ_sO`;xwXG>HjPWH zt3e~PVEo#pCUse^+#f{q+FqH06hkjjM4?k`Y^~pkp3w@Y-oF$~s>^6)cD_apV$hLjZ#E8gydvH6pM zjsn6b5Rk|W5?;oG&oyg&4`5G*o7X2lieEGmXylG1m>*_+Dwp)$=y{y81atCx_h6%Z zH;df^Ki#iW%Nhf9(v7=w?*$kW+aegvB}|-{?8MOTkKMNx#jgp1i>_pg)h5CD=`}Ot zs{aR{v_$R;!QGfItVt{yK5MsL%QN<`A@HJ9AtCtE8lE1TQ_+n}GQHxKmDl`?g-$4y zoQP>OuUI!;TTs^`U7Ft-j*SkR_3>+$C>y?+cdd1sQQ%dvsLJj&=$l-W$(Cl$MH4;Q zl0p)Dflj(l$1=hX)xGGH-$|4`N#~_N?7hYBdDf4SxF5LvddhE>vVY}Ep@htVkfgY_ z03$@9v+zBA% z>}H||=Ack$ywAMy0mT18>PTGu5LZ4F26Yo$_=meSrEXO zBxBfj!z!_#^9UUYuHJ|h$tP5SnskDLI1wJEZ>Jq&I+(Y&Y0|b$JrW=B^kFYrY5t0n zPPR!e4ttcnvJ<#%;o6k8VXNV&Ieg2ENu$vr|C_|7L&5v&8n1O5bGBTlM5uP%dm~Zx zOXeh5(#j04A|$n*4bb1(VS(uik`DbqmFXW#_jRuMtfb#dGj^4x{_J9H8H>#)45yVH z4%GjspZso0vq9jZ^6N1VNkg`}tl0Y`L<|r(c>9c+T(_A}!!s}O9wZDCF1vZ>{o1he z%KA*ADUsObE_u(4pdC13@-s5q;?H$BimV_P7Fnb`o@}~@Is{5zDp9m81jZ2451#23 zToVKto~YI_`CEbe>27u5RyS;3a6LJ|=hP@6l<|6XX5KwDw1}-SP3DZZRbnRXw-QM7 z^H^==xLVt7dEU;c-e7%CWt&sA=P`zqxjsFe8gPC29YOXExw5Uv+O6%u7woZ3xY)KI z7PFn2c%j$>*e@2WEcxb7sV(ZOVC;FYVfj+*v6hr5VAx5QiI6F_?L7_h!&FriJOs8 zOnsM3#C(1nY%kW_uH##qJ*e{9Cxv%gjykH;m~dWssBEQwtSc3^$mP#%%tx*9Iya0v zx!FDD%Z|P|+GA(O@5>FzNgHL(FI%MS;(3eh`}|&k1eq%yHCqj#oMeU}s2dp6$96<0 zdM)>`&@L7lX~%tS?h7G428}$yZjzoyx!pG|SscjLEh^s3+f22X;|+LmfKEG3RFfPs zl(1+&(1|ZgtkZFXmz%ro-eWXW-X{K{F~z%-^;gswx{@jzy%)NZR~(SLRZWQYD1WoF zUTk}@V{@L1CfHC}3tzCjZaSAca%;{=777gHINb|)(vw>?)Y0&|Xk>#`(s&@f7{=Xn zI@eT%KB(h1 z99B(=21rf|^BXi3cMn8WeK#+#4;x~=sWiGHjg8lySc)O{(aSel3x1%r_YA!aAwLF( z{c*xptFX)hg=!^Oi&>ab$*9R1LGesqovosl168_&4OMdLJBig}0V$?T+&3$BgxWps zaKZYJGm7vEhPj)q5;lTALTZB>ZYzHtrC_|(%4~-nd)f5qiw|pC@uh|h&I{Rdt{o`F z-BzU=%35Iw?kkVgcln?>kjcbqb%1gMsL(2BQ&fUZZXrqU28{Xmm)a|ebQks0MiYVK z>}R>VO)oi{9`?G0g3LPu6quL4Qio0{@V;ra`kXVx`0Ntz+xNWLp z=;UNh64CJ9yz^C@;x*|NMGtvUlYiOX^qx&I;;N}H(+oZ$)VdKb-gZi|q958k7o}?8 z*++jyTXl1P=TX5`irZ&=8(m(H*By6h<_RX5&5NrPrMo4taH)HX)#UbhCVVa!)_FrB zqbdEvkSCq0-+YnCz(*Fo;V?2kqGQtvh1Px=G4?;$q^Af41tGhFf+wYux#o{bM&7wa ztVOg1BNp27&guA}W;TUIL|!OKwN|~nv7kw2fg+Mz)Yz03jUMplN=Jj%)%H@-6Rni4 z614~di}9B{Xmk+DTRO7#lj~Z+c22F4B@;nl7-e)OZBNHMzGr@HNe7_-RO`Shl=Q_^ z!^4ELD%3#*S!J|$hv2i-eimHfRJRdgpZ-ey$-HUjIIB;~O6)-CW7fcXlh;*Yip}Xv zA+Uh5ocLmfdxHw_TtAKE8^liIYxi6Wl0nKuq@Se$YA{L)=rc6TTs)Wy)O{6iG%T4+Sb4i5~G11*n5^tgEBQfx#m2}Wr9?% zK671)uw5Qw&wl?a0n0gTNVhfuZ>Z>(jV<{G>}n%x$=k-JW@ru4GY85+Bac8 z<~-}y*F`xysJowNmy=ez1aBUz5D!bun_lKyPZg9-om%%c$9gL9&PK>fvcQpC@L{*r zTeyx*S!lbP%Ja?ny2h=fi(h9e&S8H2DD+KtZrzHRL(cV1?%tgy0(S2@t<>zbrv`91 zWLX#6c0#Ff`6?+z>PnUWQkk+hs%gMt(>+Q*f+YXBJN6~Jaa|;DXyTIf2%nc3LoTDa zk2cl5n}x-5HQSddJeQ|cjCzeht#poBnf=WiKHc?uD7v+{%pTL(gCPFM2t{E7OQzH{ z=cxR!CPxRrT8i{kUu0_jPZ)#Y~Gc#@}ePEDLp)q@=e0bS^pjD?xe=${kxlSU9%PJ{Tyc2*@O*TV%~>{0p;+LQQjGro$mW= z0>&lQ;12ifsWxi5!c1|_QPxUCTZ-mM@Ekqm8hk)U3_Vwlzc5`nsnAd?!G3>WGw*e3 z|2;UUk*YctVZC$B`6%=FEnq`L3G`+>T4NF6_f2OV}qd1D#G>RM)7&AG=OJ3w{C~48ZHkvCB7TC%G3Q_ zdzQjKA8YjdY0fHSyD~*+eBoJhIA#&Fz_`&qFW?FgrgHRl{COwJBu{>IT7$F39kH%s zT(8A2iP5Y$iUUjyOt9pxs|UcwKJQ>x7COGsqQ;3Cz1|tDmR!8$L+jtbft3=CSzT2=Jfg)dxt zO*`|32BDg8NAFFGNTkRI`GdS`Em;i zyXFm>sM(5e|j~Cq4oOlk#9k|78w7yg;8(DH< zltuN3Uau)iavZK*ggB45Y4;45q4xckjhp~((OG&jm=B=4^vD11n0nMeml8E(pGheV;!fr1bhQ9EWWkZ(m{Oo!8 zyqg6D&|y2p%2md0{c1jZ)vXRhC{p+hSAz#Gc-+x!IO>8SXQJ6P$`_d^0de*u8&aSk zsBGAh-Y%s@*xb4st1#r+Qqm>SLjP``sMZ3X!kF)OHJ7q=lQ|$a?b+m_hGT8VyatHS zXN)1CPes;U%Tcn@^C3}Vi)aBz2ZsRZpty_T32`B-hFY=z5vy0}=qU~4N>+b7&H0>* z>``5A!5>_sJ?}{+(lFDPT!~&YJF)xapD;L} z!wNBKLMv1K*ArKr5~poA$ZG4nyU;4TVW|PVtzcNcuW5Qp=F5*dV5f(RK$zsA9NyLF ziVEqP7HaFk^Z7zw^3Omdr@9x;(9OhaG@oyx6teLm$3A%a@bj`>08sC9;@So%@NlmUM#f+xkRPdNT>2}XxL#zGW%=)X4eO^<*O~ZYZ zqFK|Asqvy@t&1vTS^p#=qLFmN&aA5Q3%+MLfL{mH>k&-Cw|Hrq)0{LFZ`5zwhE4j7 zYC)S9nr0$usFJ?0jtJ9#=jt(k9qo+VeSp6(@kU!ZaIZp-b}tCC1pAy_Ld_nZh8~(B z+}kva6Je&P8S(fW-hbWFU7_Rbm$U3#Xv?(>pZnDM$WH#j<$`mJ6Q^UBDTLY*`xTiM zcRR>(*Fp9F27=_zfLvA5|Dc-gV9R3EwXr;}<6cM1UEmE((_&xdD{fHL*9#_kJbiLf z!7tt`R3KSzC;m}y^w2v$<2+n?l;TOOgyJP9-teXWA9Xl+r8hYxO_7se;*{b5iWR^HJciHGb#NrE8?bTuD z#C=Q+o;O}{Xaap^m8059F-D=-F;KFFFZtXvPFub{!ASOXR@{TImIdV>w4Xa$!)8a6syy6Ht*x`RWF09^dsV$vnGv)y=rl`{ z*q%3URX+fF0lYjsW&!#t`qiC=6|;l2Cq<6BpX?xLzZ!E%vpgRV_h|{+7O2Sf+9Gex zw)(qRmR#w1rRvegB{`5gBaaHxW(HB(^CxFn{-FC<%_nYwLY=P#?sAB%ZGo|ovp`(% zNW>bDx?m~`Cx-)qvPPU>W#bCL4(r0@4Ji8Ncs8(Gl~afqQOc#dS+aM$66&;C5L^n_AOy zTwWNtAzaogEszMV);};Yplg^?tZ=JF{7ilnV(go^q$QFuvS^4h3e)9F^?cyOKz|E2 zGUBM5E^t1UCdp?cWcieGEtD**AZ`u4TUY8QKAd}`aVGbtAU*hFX?nL0D%Xh>PxGIZ=U7ov zb#Q;x%stSUcI+KrwouJdZPv;CB_4D0Yb`Yr-A-cPQECMG;IL%76ITD^tDEKVWUI)s z-LG2D&6dhfq;Csme5EpLEqOl{UG;e8%edijEodp^QL4D}JFataGf|`1e{(}U zhB$H!cT1b#?Z+J^g`m9IReKMy0JZmO<(RxeB{W|yFhMvOvN@gJH&qbXFYfGa@@9Bl zkiFaMMkh(!?U-yMnYz|{@!b_7C5%QCv;}YW$|`H3gS#uNJIG zXge@n9#fOkt#$mKcEu+$WkiXFuPLXirNbooWP!>{bq2|#8Pj3n=W(SB_Ny`Jl=7$m z3CP6%G67-?GGjv7E~Ulaeo(?F+txwz-B|(gnZxat<>XE=e^bz}t1Hb5PVkb37C={e zmyB8rvfjMT>YB?KyiCN(!}y*bXG|i??H3Vcn;0LYN|F5KHQI+95dBS64~xZ zX}8Zx5~O$2M!QnojYBaOs2qgA-ZnCkLJe63#ZG{7iOtR}WN}eFTb}-P%z>(>lmFxZ zQ=&0N#no+};qBN-*vow9OOZvkN4hm7%G5I#jP4#&F~Z(|R9R-c;d^lGXZa@kKaFyuVk&3!X$gy(#)YF9@#h$|a<+}D!&VElD;B$@^NTw8~j17<|M;p68$e%FEj1bhY zkBUQv0@NfuNi{v^M^+_(kg!|vQ?!TmH*RaP6tF$s=rsqYY^6rynSo;ei}PU2F0%KV zK3t}?qY1$`RA-MFD)sh-G`HOeml)KFJlhZ8(`nE{<8U#E0&iYGnC#oJ2f~4C%T#mY z439l?8&q$95%!ywIfp20Xz|bhEXgUE^5OPk+CqTb0mZaRIN+*8FW)3G$62v(U=)sq}9gPfcTffVhM&KO%n`?RCd@i zckZuT-v9bSO-z!>{hf|ui@DF!k4v&YiX#oF$wiiK$Hcl`Ydsz<*Oc8=w615v_t^Db z>elVXFH%acZz@|@%G?oX8fyt{@zm_Q^~SmSc+7HE&Cl6ODs_`<;!X=73F1*;6utn_ z#i%c*y-ogh*?w)OyND#@{gr#tGsY@}K>dq(a5+;_Q+tX=uJ1QX^#qxIdM=(ht6n+Fcl-+BH(MnsAdz!cQ-(gMlNSJ^a_!ZU?i z`p@7Nz0zG6Oh^r$39+CPm18dRJvG1J6>=^uw)6hJ=J87`iZqo9`D_W*A z0NK;pH~=`ch1!EHcU@+GR*JBmZV{9_cVGfUUyakoVvI>b&p=71RZ&yY-xSFaSy>iA z{Y0j7r2p|xNLi(7>+Ozmk>^1_q=JG5o40bXs%m&Aeo{4sDXxQkTkov!1xs@Ny`QW)n(>brn$Y=WO-6o3Tp95vE()OBPOi0qayF-@2) zMZemCpM*U5!8B;D#FhJN*Rnj~tah;d4x<+rPE<1_t1WwR0u-kRa*gNTXi46s0lmkA z<2!3PH`;)g9U2*NAk*Sk4M6VupS^T4*CjVP0ubi**e;_K2W4;}$r^5QE2UxmkQBQB zi6fmrAk08BHcyf-{kU_XI-Cj|Kxb}P&2xBj@vU$U_n+UC?okfMOz$^eSS&dfO5ruR zZWZ3d``ThwajHQjG?_}gij7#NrhQrx2%a>$i{P`-u78kdiXhNADB_PP$xkU|-^ z!^?LK!U}Ep1`6~PY$tQ&VdG!!z6!TGX?Gr{7$(Nn%$+)CyO3JGzu}R0KT_cvR|&0^ zY+Iy??Yn)-uI&TD;gKPqTe^2z*|YCgn@`Bj>(m6O55G8>36M(xGweyo#m*a;_XYw}fa!FAz(N5?4WSUQW3Jj0lRiD{LH8PzH7o z2hNsima&XB`CDbsmJ_Cs;G8(sPdh92XfxQac?&z2C%HsQ-Ir{4@~d-A_S4EZY^~N@ zE58L&-tGLiql;Z{D|KL5YDUn;G8|{E-=J#7ZXZ#Xb*qn8K1tgFb|uI2ITY|oOQj{K zCiz7#y?n9JrS$6J#VMF!_@uVT4faPvCf8IG?lTxD6Auk*brP!UUe_ zIRcC%y_xQ^iqY`B{&|aDx@Yn~K}$NFos0Y}I9B33xX9>NWw(=xrAGb7+1c5QzVjU5@x>=5$`3dzOmz28 zUf#i>3r695(pcF9dS3}e<%D80KR@F{`he014u#skJ} zxJ@O~#M^lH!hw5AQjO@ccDOiY_7-}!9c~LvjH}m;<;15bTHVNaNnEUQWbp^ip zUjVDUPBV3G@%>Z*6SUJIv*&wLblbbXxIHm%;x5qajN&K;Q`iBRJV~N41`ip41-I?rNV}%Aw)stv}<|JkAncDrPhr8nMMkj~7y-Vw;2! zyz0IBWMMP8G^oc#K=MWHBG5LmvC@yM<$-cL-W4Z{vCk&7cUevdgiWC?>pMP6GEM>> z%jxn7s`4?{c(W9LSou0QIPjDvpVV+ySx}OdhoVW8lK)FI@m9YZ2EXRKxPJYHQWetZ zWTdy3AJ)JzAqHdOHr$xG5y<29RoMbL7tX65pY=J-=~i^l1(fFy?~B;P@dN1sVnB7W zsvSwnd#zBImHf#M@Oh!$VD$YQ%c4|wJN^B4z0D# zvo@Uixczf7-u)wrC*$37zZIZwQU}&+o%y5684<_U@)Zg{J>_WnqP_%#E3$9OrVdL#=GEUc`uE>oY!$5U58Ab6?-?JP4a zs*OxI2TtF_)Ve`GFZqu)5Z^i^(3Jrt@`IZeRSS*eGt`w(TUPc^K$6Jn#RfdA;$OZ* z$&byw-k{utlU;XykweHdkaPv*J$`5zkkyAij0&GD&-h+gz!LSo+ z8#Q0^0Szz?FQ&NWSp|?uA)^V|#yakRap_#sDkoU5TTy?d>Yg$Oh=FiBFH5RGESl9c zF*2I8foyED#S*!t%31r}hqpd}KTqKP7ARrTX~VutPtA=^ocV9*z+4~^=)mMd)y~+? zlywCbf?F#945d4OB_TTSRH=2Xkr;aVB7zOtW5ND!kYGzjmHSyM#5HyzXCJvO#bcci zSYroWKu}6`w6`ym1U4qo+WyTTT}VkuvA0p(2yiPB0A252otAcr5iM^R`1~mL70)4& zrh@$ZC4rv1O)L?;(}1|{{idm^;M6hK=QMkefN@3la7{(hz47zKZ#Q4nrTz>8wK~4;S1aIGX5$3_;XORFg&M2A8RWM6{3<&Y z7B^^t5{7422?L}uo4v+s!=!9gxGUhviun>4Zd(CT~+uO&VBErJL zfLmGWCQH(`$@h+bLn6D(IdU>JtrVF_a+z+=%gqITI?E**YvS@!Qc~VJiI3cF^tr9| zPRt$ITSVcNg7$j@6!!pNebdX_f2tIxZ^WG!l+{X+FcamQgJ+0J)A`i7fN}bZxD5VDzqB*^IqqPmZ|HB>|wJ5aq^@V&x$m@6!JV`kfw@1WW zAgOpbcN)CW4^$^!V-w_=`aS^Kc$;5U@NjXj5%WWTh8-r;#(Fn==D{cnc&q+%c=LXO zwSR<+Rl{}ikdF*Gu8OG``l93&}gkM}_qnS$W6`*&&?=*AJa4;0X2VHQEo4P#=C2|t6K_=p4+ zVRSDN67HcP1uWbV*uCTa+3VT<`a}KyDkczY-^i_Za{BtK_YZ1tw)MuLVs&P!~AZ znY9x!)GG7uoo}uH{(Mg)5yp@Vgfzb!KoJyjOIS27C0KO}Oj@ zmqj| zt_}!^tqkwGgP|`d6bi^{y}Y~tpM;Brjcv|Cy1^v_eP0D}T4p5kmzr^qqNbnJw71&a zzxT)!*a_Dm`nMnhIErz+%hHjFOGJjmb5xNd~2Z_G$(_!@u9LOZm4_0#Bx&c&qFMsl9)w zZ|p2d<%5pdZe+IwA=+rz->s<1%M#e^PO{khy17ZRj#RKC?#4JLHp_pZ8KyXRqA!S< znRFwJ)YnnkKitUuu+AKXs^E}&2WBjQD+tVJ$V*DbtX7ovOD^K^_%rz*u~@#P=JSVa zmyj+-L1QMs#74~r#7+zU#=$Bza1*c~ji|Bgj%Ynz+5W#d^l!q6;BMIapBN|q3WtP0 z8N)}kA0Ixq1o+jdU%M90WP02z$qT_WHi0;o}scT-u_%Cx|mSp;0( zU|oM-GGJ>1Yr1`SG`1Yh1Y*;lCFWCD#G}ChkR{8i$;lfgZMEnZUbpvKgYtaL^dB<~Tcb)cp4?Wh%@Bw1w{nQpSOv4NVG zl&c%Uw?Lj74#kV#QaC_2H0=GrfSy6&+T?=z*w?ShFE=f!ar@k)zgToH2uBi>x-9(L zS3r7(1abcN(FW+@b>hXnU}|po=W^gGRJ;1JSyb*i1y@X=gc9L2Z z^!t+db!j2X|9-&_6mm%9*H?CT$QV-#@hE(SX(~j+cz)3x+$QgdQzHw>9tU5*D#N^( zPXVp>QZSP-GY1FIbiR%}d%|3)9+@iQI!^$pDXO4#QA`n-f0V^Tz*iRgC5;Xn=9Jv+ zqr@@8Bp@J=YXvR~CRA=vz?U?b3{aK#eR4rx?|}KEQaa(%g`cJF8;^YhG4?hS_sQ7$DHuc{sMcqk}iQ0kG*l0v{euKL>~T zZ*@U0s5bM;vfvg|6!>`c*GzJ~Q%6ZFnL}!yf zkwveaKyVYZK)&af9PMjsyZ)RvxXg68Gz>tAUGIh{SPhJfZe2_+yLp>j_|Eo!_z*Zm zB?EuK;T^zC&O#|Y+47WF&}yIzJ|#vhfTD-Bob@|<%CWO-^!Kojnh?+5+1z952GQpNg*&pF zTeCe;ZurW^kNcN0QY@rtHQ%^z2HW&$^u=W@w~U?D?h9JVl1$5254PzkCf>=MV`ecW z6+{1i$^47aeZmT+-XN)TKM5J^nC9}vs3x;EFZUu90NhLEOZtFCJoFT zbk^B`rzG5>$i^i$JcjjA*(fd(Xe!U)K)7%Xi#(egj3M1P9fZ9j6pbPV9C{#O;xCk+ zn|ojDGkwCG-p!h~IaZqjSyD*j`%3ATBb^_h-brkK_^0n;Yz1<*!m0t>I;KL6hp~2c zcJU4#Tb5TdTy(JIG?KnzV0R_zDOfz^S7BP5?9)aKC2+i3AS4{%lW$|1l_GQgouD`Q zPEvJc6IU*f@$9q7@LYMnZ-lyYpo}7L5)H-%2296dJ#Myugh*f+l#E~=-M8f%Vc?lG zPGB{CTn|_d$K1ScX~~0gJ%Ahdctg3py}jijU%`)o?u(VF@jVmCZ#akZ{Q+0L;ns8H zyyUSum@>$D^wZmnaoz+ zr8%Xjc8FeSH%(pwF)kv4N#;cqCSEn)0`;gjPBoJK$!1O;6596pTp#+x`@xbaK3DG? zO{|z6XOJH)!(403X6yCCB~$_jFN^H(zzFq3*!DhalC79_|w!5<7qm1oR!cO=H&i$40^?|$na^Phj+ zk>FK6q4Q$koRD}H5#;dJDwH`5n2Lf9aXGmJ9ln!VgvFpd`f5N=%nkwgtJuCv39-tZ zry?)mo)~vo`?rrfA)FY_vAM+{fPFT)yfr?C{kpKN*t}SZ00ZD1I~7E0Q)G;I*6444 z`lR;opIR}ET$)f$TuEx`*)9Sr-HAIH;)%@<^B2P*Zc$@`pf3<^hT10+Ds2})xJ3r@ zV+0EaQ8zCA(1}~XznDt>ES^`^yp(pTN2w3u>ZuwPd9R}HN5EnAd2zj<^w8?(CsVct zfU!8O9W4$g(;aO7sYFx&Edw-QTKRm(|&r?rTnp!r7WOcBKU z;#L02C9C0H9!>QU^&5s+8kY*rX?B}0DiXq9oGR_)2g-xf*&H3O%t=DANkC)#JHz_r zg7g1UvXZkA=>NE6^-W{uJ*J#?B&!32nwHWZ$ec(HQ{SI-ok{Ck!NRzI+L%_d)vJWO z+b7(0dD!yRjkn3nIZJ9JkYF zyd{)S8fvj7-T~`N?n=i+(pwA87)^Y;Bx@hb+o$O37o%BO{mMe)9N}GS=j4naTD3I& zOK^%^^_(DmYud9`e6FW9RZzhAB--K}XiaKXj*6@*rf%T^1Y=wu!U!8!CA3~de}Mno zC8L8SwYBVS5SN{2oJjMMhgUUUEpp!bwLnqPHW*Z~$`@hR?)f2OaB*K&5}<5!E5)k5 z;#-4yT~4AaEuqIJ4n?VXRZ2!{cg}Bd>iW)VQ?T%tS9O3rzh|CdXXQ_Qa5HGH!nR5M z!vKt-#u_aok>L^YVS&KE0ZT_QeuLE5nu}zFh@3M5`S_nigZyjJq~u|WgsCT@jjk6& zF8Q;wuw-K%s^mt?^-5E&0QAoN1r1%Iu=jB+UnKGoXLgkqdzZ<7IH8dHnO*0FQzL9} z6L~PrH1+^z;PLdpX&o|#`I?ypvOMbvL=B-{Pco+O%bGaaE#nNv-ZQ#!MNX7W2*c;x zQ1Ldn0X$INDW5YId9)$P?rtHiR%4t`^F$8`L@6a|zA}+?36HYZjM2+EDrV09p13(= zf=#XeMg?C!um{&`k6d5slN^_<%4i-h-VV}e4;>j1nQIt_#?5+4jm+;-w1^nR>R+>3 zzwB z|ChY}|0b>fpXE85Fn#Z zj9aMvpva0r{g@N*7EN0a52QPRX3F6$&9K`V0l~q&H1F+O(Ni=a2E|jHI4-sP?7(E5 zM2Oy$u_~K&0RT>mkz(g9CkRI-mF_U>+;rr`fqHmA_Ic>$1r2G_Q$RNjz20{?=vGz} zQl%$92dA^CU4}Wu3w3CtlGYrKMmHe z*RX0C(*^v+W;p@Vzw=hOV4}56O~1*Vwn+39jkA&aNFQLKxPR=fPw84R`Y$#I*$*JtA|zg0T`&5= za&kuP90`G-Papa1YKySi2WZaLMh<-sP#BBwfU#+)pBK>l;@I zJjwB(Em{`?nCPIUMWw-7I#M3p-3BQe_RM%N(_xOLg3~dCYsF`X^}u;8i&Gl72wC$9 zDDc0DNgnF{q%v?Nj((BQ8G2$uK(2O<2(H4nVVk$~9TkUf(L;CYvT{^KnR}WhZZ5$Wy82 ztBh!3n3-IE6TI{gS4LBx{So>eWBuwvb&yE^w$rloXD8}9*1Fz_ZWF4+^Y-nQoHm(` zU$;;8C6PW0c+4YN0@z`H)(-Rx$CmWx*;6I7-P-fo2Ezp-rK}euYIq z300MT2?O{b%RTkLM^W4Ud9l$pD0do7*P?q;#f)!B07OelDrD;cTsz1a0xWx4S_1~{ z#HOc0jS|^b_axwRRh5--laVYfn++;XCvP|Od%LqXriH#M`GoRhTDy7`So1y8e!pHM z&PoK?l?s1454+52n2d@dTha?1QB8WSNX40X&lHoBWNz`aV2C&`KSfJYdZ7D8tGBXQ zb)!gAS#olcU2GlT_(OaIc01uvLawJPJXCS;dWxV()I|?E z0pu^_BFhu0+pGIpzBDU6$`DY{u~I};IUl$bDfskeVbRufd%{GQH5SN-(-ZP*rsOZ_ z(VtLy>79rC@{O6G)Azt#Y2sj*pz*v*k9llnE&B^A6zV0!J=NteEZ3O!K3v)rtLf`E ze|}=po(v6Z@=;JVawtvT&Sv0%tY^D{hfbA{XD?B z2sC9p48&8y3rEuB1B7IaBsQDTfYGnog8tOXdeY^v- zfIJbuTW4bM6)TM2MkX|YOI+pnb?qk^4{gcrED>bE#`pY55eBR{BzK!>H6Y_%2>BC} zeqs8c-vEJz1Nr}K3icAdJ;3;rBF<#H5o8_Y)ZmH+fK$`#Sjk>09bjRrknrr*H0ozV zf*oK+g+bop`PXLeSAN${+E!MH@$vRdB2qtq*VD5eGmrxt-^hKHeq1#2(rBA&XZt3r z(X+{=W|Q-Ba!^8gAfT&di+=(z`A`FTEzYZI(JRIZCSMI!+jbRk}2e@?I_UE=c(1qetsPR$PlJ%1HU3t zoycPg|4Xf-HQpYUGegkQ)vIg-n%^BU%^lSp_epWg+iUO@AUnBlTm%~`;lD`M_W^u} z59Z`$X>6Gyj0|VHrXc9rz}tEH&6`EF38LK@&u9UTP#oCms%Qi*^xwTUaZEZ&C6*@}FUU-u|mSA5cD$kV=qaRT)qriZxsxnc` zxX{tD)U4?}{_$~EPT3b@tw`CxIiAvBoimY;AbPH+NBfz9`Q#~ZPL|ef_nEtX5j4)z zkLJYlTwj9UONGP|!-~8tNxF$mD|R8diNI~n;OP0<^;d`epPeeb)lOWj z?gp6YUbeh``Yi}s;~;E}R-=}8eroJ|!)>npOJb?K6Y018VZp?pNq=9r7&$>2ptinw zX-{)GLa6`Oso3q%(SR16{IG)^dTtc11O>gpV+P>Y?4Gx|FJ8TRb?F>z@bz#5eYLzN zHCDrC`vMaI5G9CLr?u|iuW~YYOrL1xt89z6tRGP`+s5rK)6XyQktQ$g#-enym{MLZSs<>;q` z(_kJWA3alm{a0+uR;Q$2@yXcE{{H?+Kk6=^;Lvoo4?FN)KP+nLHMhU$P`(-VN33za zmAzD1*n1ScbXv+$&e~CMl^cXrR_E~@@lam0men@UadeL3GG=!oa2V(oZ+9DPZYmCr zkUo^WIh1h$dKwWFsPe&T>d7VOd&Pk(sZQ^{M6+lV8a2T0QJD&r%6g^s85kO-@jd+~ zCuBZ?iQwXpv*eZeSznH#)H1xE{f-Qd0Y}IE)z!BekXONS4)wa|DA=|YNy(JG9y)Dz zJv~FcCmO)Z7SeU{d#wsH}xZ;A@&flD^2m7~O;8P~ViY~{4S*bTL+H}2V z0Aku6FAeuaq4X2m!B7h@^~ou#wb^!aQK!L_oRranPI#4`LI+0J!}(mTjWoL|j9W54 z?{-j3Cu1`bOiWYrJ%NHI8O?nL&*%w9(hZV@HWox*+!`G~OOTT_!qdDl6SJ`$tSo71 zX!x}coP!Ug+tG2;)X=t8&TWT_PU>`)K*}@D%=*uE0DG2U?6qF)>|4&PSzY50s4II zGvhWZhLrYFjrhZ1lEG*zR>X8_ZlaQ}-8fQn)FHa>T8fZ%p&&gUI(pWM40H!y57HR1PMMP@V$gVlWG<;Xt-q`eJ@)F{y|tePJ+(b%gE4b*NJxmcix8le1CLb5 z%zyjC*3VC^a-+gCv_{4m>e3$bx36e*esQm(!2ZjYF9m|!2s^-;`Aids{XqvA2?=GR zAdJohxP)oqXE+!*3J6KmY=dXRwCSiHW$GS#b@fJ=GfH!PspCjtUr$dD4reQ!sHm@} zXIgk*|4>6Q*^4W$&P4wh%fK1?$_m~X&5o1#0|mf;5)cX6Uw8JsZZ#fw+o##m68WO& zRkY}ts}QYnEMEVd$E*r4QZ_;bN*+0zoVnbYaxrGJ!Sf^8I#&YD*QI}y@rvN_E(rQ={R_sgLhAU|DEew*8HlsrgFHZs=rR7~_49jy%?r`D>j0n^ z=9@ug2}}&c10D~dHvSu`yTEaT18~j!S&~J+*vRSe4&%@U&Fq!r{!3O*)b)u{)rm7$ zK6=k789eWDxK5*;5Aj{AKC(CfOpALsnF3o`Uz~_pJYgsUtO}Q(-g9G=KlZkid$@6z zOxHq8oJX%x3Uw7C!^g^upj23#%&?K%12TxLjpLhRXA^nL4q)!e_KQ!SY)0q+OhFZ; zsOpuQbm~}1YrSWQWt@mLljAP4V@=YYQ{wnSskQ$U`s3Qd7%=@k9)X5jwwEBk*(W`? z8k{b~(?5wCMD`}&JsS%Q(`W(nQp3+-RVQBl#b6>`wM`kn zYF1*j^=y50ZWv6w1|~i`B0H1gpLB<}AF7gTX9zSmB)$~XLJKs04&Rr0C6Nnbm2UWL z(k4BJ{6`kGvDe?OO@@Vi($r8K%L2I#59#c`x*-RDBfLjThuT38z6||uJ_+b$YmadM zW|RPy78ItMGi z|GA0Lz*fQS+M;)5W$q**VQmcB0Ssb#;Bvo$Wk}q%reBI_&`xcCPpdyjLE?^fO!w32 zRM{!{)2aX8!}kRtGSE3AYh?UgOs@nK%?&O($Z{`*`F=2vP45HX6p=E>U3uC3ol3I# zIteJH$=~E`-NNH9J{-O)U&!f%PAy0jfXp~z-eb(y!@^>6;kpp1tHR@EeYy3h#@=;R zH@nofv%(}&?Y5Bsrc1@UIDlkwO?=)6`)KQDJ^dnGR>2L|mhlIoI69yRvhg3ivxE4% znl}o5fkPXnRe9*218^mD_6s-zL@o+^GXdE$QQF1Q*4DPV0dV60;SLn|H*VLJ0jr2Q z@%~K*3>f6A)eaIyz*qgjf&*%gAxF)1m{)cuEO$K8Y(l7BNJ0m$1 zBFYWH1Fb zFCtDtSU=T+jE?2<}*nD|JpRuSr3 zWR42(CI`T7qjDx;ufp7YIBGS34~MCz{=n;4PGO)qFDfBH6967CHTdbXv6OKY9ic8l z>J$-a%lm3(MKMC)AX|49K`S{6V-l?L6-d|F4_yuAPC9iJrw{Gq+J)AtewRF*SQ`Eh zj=nk+q|rfBr06|(6#S#+g038g%N}ojj~78$T3Ka?2n+ML(e&6$0Zl|Y+D#sD8gey> zK9Q|bJwXJI_6rtV0Ll}iwZ5A*YolOn7SP2F$u3m8Y%EQdkNJ7y#xUEuetzFoGe^Db zND;((<29+>js;O2oS;B;9X*vVaXe7b@mT@8zy zpLCx{a@!^t@7V2ZQEE_?UL?(g@Do?pRiqLU9Gm=HE+N>$MTYw)Ag zI}Hm)o15sK1BgJXt*Qoygf^r_Xu{;sxwHrcY7M_-oPs=hkrr{EcI8z;&ChO^oi!5_ z+MW)f51U0d(jj;#n>5h#bclzr6|~zy#6{S5bj3l$RRl2)T1M|XgeantYr-VOqcMjN zddyB=cAHzxhLkMHPDvYij=r>#JK$TDi_jwwuzkz4Vv0L2lU|}_4VZr4pOo;O^m?YYd8KK5f-FWqx;?68_8_<^b4%Dm*X@P_*|Hh1Hqy)d7$%+_- zu{SjIzFO<{y{6=`rtk~kCNBZs8fJNfgE(29#)d#sQbs1Bk(>xoSTEXv6Tt>+Ef42J z%)_XYc8IJBerSI#1QU(I&Vmm84z4_r3sD4v`JlBy0!#9?occ8Q{$MQ}c@Sq|V6}M=Ct(BV8Xklg&CZx0sm8>&e3b|B0S22vSMVW} zs7dXt3hQC9XAmb5sF|chH0K%cG8^SyXAnU!%FGV*4nKkqVgEhzHCjLbaSygt{!##u z1%sw~#!ZM;wB+n}0)rV_-QKlW-MdDE@^-?;s#eKc_9kX^=&PM$Eon76WhqtvM_-=d zJGzGNNoo3spBEYh;s*c8z45^?uw{ofz`X(tGS_KAH41Gz1dIJO!ZFtVuc<3kVK3szU#5xOAh6lPurK+UZN7~tbD8EUk@nvEV4*lApy%8?INdAmdGd0 zXKred9conaQa!IV-AWyGfX*~-^*rw5pPtELYejM0KGh-cR8<;UJ^;@M_44)O(?ZL- z`}p_(v^|LoPS8D4cmZqX?69-&zH=f+oU=P1?sbY(LW!)fq6IRmXTlh*B=>wR4pnG` zo-S9bSX1BJW(o}_1>BNR@9Ij`_QB(P*`;7>FN2iYnfrkkdJEAuGIJOfCZok>u9QdM(b!&Gek%qcPo;NVxb%&2Qng%-3pC3;%=KKoK zJh18(_1)xn*+%OazKyekR>ceGNI6oNtta@ChbyZ#xqcZ^>+!;0kG*r-Sr?Gb zN0Mt?uikg~ez1gRh*2nPRYgGRkG0j_#Q{&{nI(Qn47_D%g z1Q}L!%H)ptMqha?;pg{@2X_QP^7sz1P)B`)46j@At~66XZFa-Om9GtGw9qh_ZthJT zv=aZ_B1s49(D^$c7gRDK>xx?T!^qkZhR8NpO=JpWABGEc*@e(j3 zAnF9s^SFvfs2^Xt>m?qsg$CM%q5<Ex z%-0%CPMW0e!a|?fqvxd!eo|4Y`fOp-BJV?iRg5f&_v=m0A-`|`{D6lXx5LE4cFGHG zuaE7l6>NPI5#9zl(!r$LjlS&)8*Mq03iz$!_TN8PwMjdR3I*RN12DV_ucY0-Gu76v zgRS_DEAZ-mVZM{Q;R7V$VqxDX8QZwnw^0RJd4cN*lr#aC43ojmvSu3v+p5TrvgC}x z@wqS^$kHWkq&V?C#;TV-Z@EJTT*v?MBX!$jdlFxrLK+sSC63j&exLn{cdXqYB`tp; zZGlp3^qtcLX>APSySYl*oYB2=Vwj18a7cxaXi&x}6ted^&XXj`PMjo;WF(bD z_TKwg*?Vt}J2tJm;+KAzX(y6)Hgx~}_0t`5BbRh&!TVMRb! z=DL9aEAtiHoKBbi+ebB@u||g{O10-%U2@OC0rQ7ZM~87d)@#k(8Fy`Zqu!~iG%A4( zQLfP8W}OcfsrXE)C@p>{Sz(d?0@p$ER|bdr4hWdAwRt$!m$DvEAgyt4h?2>T`9nuE zIaiNmCxPB*ogaX?YU;Hq_Drvg2H&gdl+DM@{z}A_O8_ROXlW2XlM1#9lJJudoHV`2 zgF&8TJ%Ar}R~&Gk71Fr%z*dGtS3p|61EuKrib=kY;W{kyA zvw`D%#ZYk!{fBIt6sJLCcw>+=*8K(eKf*~{SctfSAQ8D_cg7eeqge+^`WX?gmL`$) z-=SyMHdeN`w>=gMU1mE#vH~p(zltPb$3BP1w;r*=Qyo}Zu(*>>p5=DFMlSxvB$oo2 zoLIm=xwz43R~L337Q%Lb>fV^`3?CNNu|Fv>b=P3MZLhj9WKMJFs>4K}<>xs2g4X4n z%2AwZ)_H!v{A+#b8#})`rC>E=``CjUxN; zLpD24edsdf3UO88Y1GnB0xv%sjJKc^Xibd2qQWiAlk<8=`^Dk9nYIN}NZ)a(Ch+i` z3DkhjvoOSA2n1H#t)`zTIO2sg$>y~WwTmI1UJO^4-Y%^&8fpiNw&fozJ}C1|7^!^{jSIH_BQBe|&H|eiM|DbMh>I&yR=$ z@-63Zi-T&iLG;DRos)t9#Xs9n~o+SyH)N&kdg+GacBuk-azUANi< zivdseSa&rk{1SJ5oXU(Kcf>7|@Ec>(ZOP%=5>we9Uu*bmx{Ju0{_Y$CT>Y1$p%Z!< zk(Gx9mreLpwbiy%`)1EvxtcnJ_sY2SM)=ElrqvGv^#tvcm*v;9x0PhArD7#Qq1<1v z`QQNOvox%SHDUf5<)d;J^)%$>=)p{gu{t~Xdt+$^oQ5*iH2T6j4*;sADyCK$&{)dQ zDyS05z44I;#|#32VWIn4jLU$3tU!qkrCwDsO);-T618&Tg=0ICi3JD8!DF{F;YAT)^;Gn^2*QKjn919Z00HXrPV{I)QFnQ@yF}X+rr&N_&#?c#DoA_QOGcla{%-c==wU*^MYG{wN(NU8bR+XqI30)-y@@Zu-ZYW za!6O@4m-B6sfqf8_|Lmt61Vq8}I*VK@Hv!at~qTl97PJG3_rV+-ivJOont>-o+ zbHT>iJ>L1p2G6XF{(O4owM_YS7n!;!ZA9M7BdUuMO!9Xltyg{yh%H|E5@Mr`r8zW` z&JrN-e8fcx8=J-N1f5IU*p$b}%rKt~x!+?D`z50+e@XzGJn+1CQKuyfmtOqDojhsL z?AtU-MK1i+xxVw8Z>_X@H*uIwl`ML4w+h_Uh77)bS!stD|mBPC?5D zgyjjvfG&m^@yz_IIJ)2GwO42-ci`^_AefTtVrg_}2djf7d+eAuYH5g)v_SwmK!DFJ z?&jFm$`X*l{9yS8o~^rj>5+oZ0oQC=WzPXKLV&IG4O_d?vvjN+`4|X8f3Md|!z-)C z`e4yc|6=@~h5r0xGCWrHd8U;7KxE;NHbxYfVBqvcSAp_;j-u6}BlAFG>pPZnQ+h`l zk+}0v>XBC)bqFwXwhU(XCtmW%&84i^SG!_OVYjJQhtq_l0$FzyC!q!b4ba|J`|nLq z=oh`z$Dx1T$#JLDzoXM(a6@6#a6E)K6#@#{KETh~37WabTKDHUtxPlmo;@Thd5xu0 zPyb@vu{t*62BP;QWXMP%d_+PH(8jIjuFZ-IpUsIIx*Rn+Hhhh_AG_0iY1vZizQc>} zp>A<*YF=4wLXsFVTvSpal#{<<63@^PAsb`SPaco@mX@-SzvM@g1b3t{ z{n!#yX`WU-r;Cos?)!VrfhRVP^x_s0Sz+=w(~CY^@T(Cj&1Peb&rRtcp#% zD3eLV_g^DMe4rbBz(0;#Lbau1J zrKr3G-2W12hjK`d3cN|xD*yD4MA`+@kt0H$*li)6g%`FWne*5!S54YS*^hQ;_iYjo ztLVwWE z22t<5A)#E)ygOs}W{N9Io&HFX10N2c?Mt=otNu0Vf7?t3vjALp{!k=9IG*ZxY?%yv zISNB!-T}12?5=#M&81J@u=a17370Ysh$!KDOx*py#xQTkdvgQa9XIc&=JlV8=W{(T z!o0t^%Hz>?EM#~1#CI%i5?SzxwjjE7vZ!qTyMb|E=UBSg1gZUzV--&ei;LYDgzFO| zQhz(+f+l>%#|pIf&no_hp7M9n230sKb(_smxF>%3JDkmJwrdbS0Y^QVP@W~pZ`GL+ zhnLgv3xw>}I=O1H7lKy27L=}1u3DdVk2Ue3bG){4&JSf~Uwq>O@W>f9HBF=(i6suj zL2)a-U-I?m-#)}B7F>uL_*^$h1MXk5^Do8E8ZE!{pm)^8O&sznZLc1)h>2&-%Ok!JUQTfscfiL=h8~$yX4x z;DTDN9>kBMZ3v|}klgbSLnluO%OkoZO7K3Tt$7b?xX&w+CMiZbm(t(j>jph$M*J z0?5}w(tU7?Y7o7iYy60*H{1ZE}UI;L*jT_0xNR_dk#Z z3U~Mvm)q$LBv=w5e4981iHjHxM}wZGWH&n95bi0^Neq&o8E^)K#D7mq|6e@@a1gJ_ z2T`L}EvDqq3GwXA^X&A^)XQZklE>KHP&ErTukKXf?k&S8`)ZrFuCFkc%m-bDs@SMq z4Ti3~;0D)MIa7Y+A=^^xXU*I1O#?WtVJLzs7rDHw4|e4goh7@}2Cve5j*?T42HIv` zu?!WxUW%2>w=1h4R_qxqc`>euNrFWh7&&piF?paFtk3Iy!Yx{|T~}Av+>haa7hun)_ipSltd5SqXdX{;!np}hB{i-nJP-M*M#tm73!={! zaFuz6Eud8-^O?{tnl$_nP>-oyE}(w@MxyTr8^!;Yb|81~1MzUu^eA{fvN?*03okAV zBJhQf?L?DN&)C3Yvd@)1GZ1O}BKzVp>=KMx8S_{)p}vDyjbFVf|Yw zv)U^Ji=d=Nha2ZDIc_JfU+h2rrBZd~2sy-E_EgFHbWkdjCR=X$_7_^4@Kx1E8yY*T z=;v}YrXa&gWL|-7A;H;)q)rYGl!yX^~bTwSY6U ztz`eb^WIVQKmskT>J@_e^ZFMFbi03B^_)bD*y) z(lB3nDel4|F1swgwbNxo>at)O)Ogx+WH)COnO+B^ZeYq;1IdP=w~qkH05VerRVle= zvS{jSG#7U(Kx|~7S8M}zt0-p6_UA8#+>BtYW z|D$bjR|QD+6D!@+@bGY~8$aLw=_dnHWx9g}J6x+jD8&_Aw3s?d4QD|cEtr}K4-W_P z;BBxD)xuzRZXTXu$7yYCkKa&#Q3opv%N_HFtn=iZ?D8nGXb9P|43?^)?alBsaXPKYG)EinAASKF&R^tyA9%h11+{~48^(*z@j4t91pbyU674!GR+r1n&be6R${@Pj}ON)(U|ZMH2)h z5Nv^L1P*7{lfef@_UcBYBqgs(&H%;6fe89lU)20WA#j!OwdEPm)upJsM)57&panDq z)KJ^HZPn%m)F^cCEPHt-jv{Nm0>KSca?=%@FgmPXDp(Cx@U9iYTYpKw%L5mE{tHQ90*q2Vcdjd=8*fkKEw*Be?Lqbe( zp!Q?l4HP%PsQeALij_1(z8h1a1<)%y*Es7v$HV2vz!(IY`J8bexl||_88LeM2sDxX zk{1&zQ?m5*G;nuBOExIU`~k_j{N>Bug?mSeFrb^tFvTvMVS?Dt#K>W|@;L{A5;jk9 zSYccC_ep~mu#og&IvA@{ecrM-c^NFcQ%}ZEwX%v~aVzT^Z91qc5x@2Rm!T$u$#MV- zWx5UIKy73p`8K8CZrCz~*`jX+?o2Kt`ri(V5lzHghli2S~&lPnV9Glh~M)Q?od{=Q7*Huha zpU=4IIJU0?5wO({%+`ev))?Hqwqt`x+p`X*HZ~V+P%Av6BFq`ZWC!0*7;w4kpTCQS zE>}VST(y6U1z;a8H!h&b60j>+fe};i5ncvTVnn>#hnF>gh5^kzk&%%J^%O_mnF47J zwPQR^ulxyd`#7Qo)!a?8`)QK*xMab7G2UAYs8Psv=0*_a2oaR-X@${o#g6yYv@yXU z2AT3$;fy~IRmkVw{P67ucRG(`hgpILH<(~~AKcY}EJ%jBwgJvKM$8hbVx;%ZLJ!}e zVTI(R6nL)MK6Z7zD$RQ6g9jH-ywlsRhRdzgvLe{!-K5FVGyv%Uxu6d(8M$F>q<+%! zvKWxqqHD;=&8GYd#=%y~E6tdP9&~hB`jjdGgyG&?8BnPXD8Y zOk5acm5@e_mL8rN&A*De|5knSTWC|cK+2I309leOW_zm^7l1kjh}ck&c~g{ZKom9y z4LQOy&S=1zQz6%YQUh}6`0Y;#xZOf`JebTWvH}}uDOo7{c zclapKgfp53U4K9O!62K}37L9_g+A#9qqWRysUJZr%~Q5#KutmGQ4&LDjf=zjpif`F{l6;35omDdRPRu?Iqr@F3nGoYTQg?&u^32JHv6g9Csp(n@(nWt* zwIkw-?O1-kVdIf2T7xt~$J0b$WW8jb;>HlfxB7-_zrW)HX$&~QHVcP9)3(`cU784= z3uUc!c-|RH#tzAM6Ki)eEHtuCk=KZr8Gl&$tcIvjuaes#N4~I~D9c%IB7l_VGadey zSNT`?gZ{gp+O26#ywWTNe4mH-L_jQDzN{6cJdji=YV8<_VEFm(>CwKhllE9)7Oz;BaB7 zz}rPII9Xo*Iw)yQH6G$y{SswBZG;XU2P+S84-a#27pG_0aYk4~Z?W@OeA~jE>a2S# zcTt`ti6N3N=_5v^bK;BCH$UAPFya##^1>=Rdg8FN0bq#Uzry1%@`Y6ms^}v5 zR_f~B6!_PaB;EnN%b5o5i(~k5=VLzQp|9Y)5EGB7s^i=fg9iK0x@rq@V^2g|?11Wr zE*LcM6RkUM;7bo`;$Nli9is+ke^kWaPvXkKj`(ZFXT5-2ZLqr%16VsWaZC`lK0DW) z0dzT359yKDtg&FXKPlf`qrPVYS_;5M12D3fb9UtjM&9aN_$cFa=yLnC>J8hA-OMLKvYx>Xs~g0cXC83Am3MRNzLk8TaV*OBIt73Yo6WIt&B6j1pbyuqB?snGTZS(>1zRCk zr&`oaC*dCJmPynTPZUNyFiYfge=y!Z=_6EzAs{Z#37;-d+rBIsW);%UeG- zJ(MC0tlyR~IEf9R(c_^x7wNvN^K3PXYE z-ocx6Z-Bno zK!36O+wJL_l!4WtX|cxfN5Iz~fjZ2fQQ?M&Sm-I)RQkxHIP%uZTtxa(oPEALik7c; zTF}&aiE8G?W<%bgcU;`XUa4TUN01Fy{-G7K#XDcW=uD(=+MJT9taBISp}n$&i6C}I zT>;qGyo{V0d)P4%okvhrgMcv5xaf#3)TUvFnkY0D%QBYLb?ICGDR<}I3YMr;8s_T> zsdF3SB8!@|t4hZ*!~)bQxB8>>6y*nrGGU3$D%n3(eXrv19bL`l7lNGV)i9fi+q%s z88V2<(~mP?kDZ+()huAY+DC=aE1~WNO+yK&o!;>#(G{ufb6WXbLWHW8~wIj^|Wlv&Q~8W7iw$Lq*8dh6bR*}6p8lF%})G& z=`G}@W1VSMXi$>$fH#1m_c_HG&+~UQqG*|uC?3WwUHei;b1#nKh3o0FGrnS7L+-gu zGtz4tPoCZXG;oLF5LV>E1u+aLQESG+ChtA%@S$$^=VCST);S{zhaBTdh&L!vC?3H; z)8A|?Hoga^^vBOtyc}H#ujikg)FCA@+D|*b#>Zu`Yt~H{_t91#nbOTFqj4<1eRORi zfx+8V?PT-$SF@#TY;0zhmL_aJ@7AA0JT;&*JALSr)wW5AZh>7|8Y9s&u@CDSlP^EK zE<(p1=X>b*f8b|+Izf3QB|AG? zb`k5j@%#60=|3ynv<%J7jRXeE*6VlL?G&x1?mDRbmZEl~oi)v$dM0sQL?QL2EYGP^ z(H}p~O-;ou#EaujGODMzbD1^XVU zNNXsc{$8f|nE1HYajN-rJDnzd7cXZGb}Lpx+5Sh8_IbfzD1DIe`6F%`DpLRchCKFg|jmFL@yyhzvpam{9!783XaLQs_G)d72sEnPIIO$ z+tp?@&(6$z#0hA4cz8e@KNbdyAxq0k+#%IQfbqK1+}u2*Z6Y|66Gyii<;&EZ_q>6^ z;F_GJg{Q0QdyO8c8OrMu%a^nns`XItlFoyUbYmAxJ4Rm_M7-Rxa(=>bC?(o7?9dYk z$sJ-N%vCQb_HO9YOEGEb+Tys9pQG)ZI3*<|*qttm=v40IP9~{t)o%ZxnY)*DZ(IL% z4gLL*Hx4Yt`ZA)fk=>?PrT{x(eQ0XJm79&t>oz=7Baevv6C(C!-gX?NTmVCcuv-sFSx zo>_+HUqUw_XgDBIg+(xAV4&%vhvkj23dvfl|)Fu_|Y#cFw;6O(E0M)Aqq? zS^4r;vQNl~X&KX*T{@x1)cZ(^q<>W&Z5qaxmAA$aiJ{Cba3LPch!mf-vr3DKVi$O- z@CuX^jPI6|bHq}jc~L-7Ec#oh*LZE>sHcRuki{jI70BroyW47Msp7MmMYrGKM<#I= zSXFcTX^KO;2MU(T!8qZfq9xx^XDP0;*cVM0NG>Kt1W}?2iqD7o@jK}0ojOsqy0PKF z>}_pmWq9m(jqzCPJdzMVRfc0w+G+S8paVVOwq8zc*DpW~D{khTNwq%77OX=$+g|=# zgKH7ezp^|2^sDmHYI)LE9?|7x> zjHCtG!bjIOE3gLf|HEVj{VuS_HRj*>)~UFCbLyEF4A1A;>%@f3Bj-2CF_40-(QuIVtoxNMH5M0x6?txo(_sGGc)t*+Q4YfG3vZ0 zlttDfU|@0YRXodqxb3K$0e%f&5(5XMTNk-ZM@=6#Y-i1wdwI=ZrY7c&BXiP zDilN@fhJjKweT&4Y=d9i=xC(Kx%o;Wtg(U=9SVcEA7;mvb~aL2jV8EB+)cU1J8)Yd z&N#QQFechkvhUkKH;})zJmhLhfB_tI(N-+VQTvqwth`zB*F?J7(Pm0u*O}R`UeUeI zIbCwgbxk2naMtwOZ^3b=3q#vg#+1f(#7;soapY4rbo}T_fn*IKP-k`I zG&+@y?2rHDEznBZF5H zY{DXQQvr2&$%(lX+*B}4ni3Km{Nag|sE91%EiRm~u{GP=;$pVz(e=%q?k(SHs(LqY zzpZbuCExnJ%r77LOsGESl#q}RX!Lj1_kyVpbahRk!*#h~mwIoQ+t_TZ?66jb&_94v z#@M#ih6|MAYRm^7rg9eT;9g;PCJ*4<-$z9~IsLiCOa`eTWs}G*qbL@YiEepJ!%YLm zLWIyOk7=Z7z(vkQi$0-Yqh@2PL90EXIeUCV3Y=l=?iv104CtDr_eZ~YLL)&B1gix! zV=d8zPiX9@xw#q9myKvHP``Smk2W--d3Fwvq~0*zS-a9#GrP9GW|Kt|Sea`$fjT$q z9w*gK2<-HB2|>>o(cGpnGc%Jw!;Haibz44z)-k35`vfM`dAVtv)61wQc-YvM3Uf`s zi~|=JmpY?%%Dt}HZq5%-4&;tDxQ(!4!J-^(!SmN+Ujyn(@Dslqoeb%I9GLMdrCTpMiJLsx1ZgS! zz$f_$>J?S)pm{$EaN1Oi+O1xtW2^CrKNnt$A0K``l+X^btAAUf2=nprL7z9F5j)95 z8(8@eLAfDbJL)}Pwjpk4)h1wowl$%-CCuqE%l@X3KSo6$sS~JVAJ)_t{KVbo{%Sro zB=V2cmXsIXA(0w{lC#aA(+;>Si*H@DmF&cY{CgVup zzMZGH)KCb$JUV_Sh&>J%Laiaal1$3$Ch!O4b9D{W3Cz>wPBBQ~@agN)_sS`_{I7qV2wDoeUAFy!ay!LaWzsbwL@gnl zqr;R%USam@WopNRYrI@40RF%a<##waX zt^;^&WQT}`dGHLt@s?|8q^;#i#*c$*WwO`;)Yi!Am5uwC8qM+s+kk(WzAh7XJ0bjg zioi28YP+hPwAm`lMz_J~xzSUdZRI*fHT=&r(*TR#d*nhu4z{n? zDgy0fg7odD!a`3+$IMLF?_|wJp&KFU?da21Ajf!Fk*q^qHG)rraZf$Z!-Uz6Go>z2 zRPs`19=&$LmlWZD7(A>&+y_sCXJ-z(eIb<|OhaeFuB2#cYRZbNcy36q4QviT1BThs^f*_TCNUt4^5q_UeqIHjklBCB1JvBb5e zV%b>Bt1_31Gbd0#h#NAzWTW?Y{FS&`Jgw_(CUo@Ly+h=@B%bpt zV8w698B?{Y(ym>hUTxa|OCk=sJ=X?;;S8P)R#sNGZyDo&Lsm8ck;p41-bkW z4`o1wD?#h&riR6HMaEWD8#22$b@!q9S)UO_{DcQK(aF!jxVc?+?58eph9EI&tA>e+ z4ka+Wh5kQ2Z*O6-n*M>U8|KkJv9gl+| z5lg&nJS!8edKGQaul?u~AWm3NspKac=2&SFubsChjM$GG(K$KwsYVL7c%jt2JA$UK%C{KU$Nf?Q9+>b&NZ0ACFvQT=D~?BN7MRnS z@vwrhDSQ0XL0qil^mn z^GY4Acfz;FyDLGYyQ>qAwrK(t#@z?!#%#Kk*cSXTG|<83|6=i)oix-ezPeEhd}=l^ zn}nk>B)!F#q;&K79yL-fr3~eN((`G-uiCIlVKYV8niqYK9Vj7 zh3vebPatIk|q9OoA{Gp~ZyYnda z(H~hEnJMF@TWV?n0Yy?F@EeXq{FSu-?bp50gAo5?*#W+^9Zf=I?kw|@s_0;i0_bEaK0J*XCsD2phXPh%bu$FgqNmx90-KY^n!%)D#^SuIS0dTKQ) z3_m>Uv(j z@TX(pWVX&vPC2ob_K2=d@d*8G27aGnR&ZOuTUN`-59%5i5H>R+NFzfw1NnLPHaCRd z-q#E+TB-11f<6%Y)1dj8h>Lyq?s5N(c$H2JUl#{ASAi--!D(7ad=kC!9^iQ?$gvmk zB>N}|EjoXwoGCL^y6KI5%P^gwy**jfwowuSaZT@`^tx%RC#ULZ}(K)=CaxiV(fTVLq^abA1K(2MK{6VsRd{*bA_5~v_Ity%!J za0tyh+o?~%pTV;@8})qV*7XqeIXUO)_R5FBOpiC0e}mgt#wDD!Fn^n39aUXt_(*LwKL!j9 zPVv3>UerH&?e&L>Dj5b(3Pkt=9UYs&qW<=^1@Sb5voZAa$zZ;r+^Xee5RqnrI>g{@IcXOhhF4lV_P!D138E-CV9HWC8`Ou zsy0ql`M!Z{n;K$v%qPtOCCE==oN7Z_VTG*4!%qVmxO)H8@vGS9FO$ z+$bgigA=}uaG-wrVQEwKOR@VD&@7dalkNsLUI$9k&jl|D@6O+dN=mv5--%+6p&b3R zTDVEY2VR=TxpdYK+FEMG!?NnAg~;iVs?}6yqz!VRWQz%&dxI&{T5TU#kMH?-r7H~0 z9_w@G=O4aZJpxLG11oj9-Z(N;9cxXVh>TZ02QW{NuhHyo@J6#W(l9{R-qp(TBuct) zPXWgr?b|D5U~d1|vwL9D<_9M%2H3qs)j9r{QIX1I*2o|EEvKt5HAx0WE%8b!z0d^t?QG(7cV6-EJcM6}*J#$HG<|O)hCJk5n41sG!L?p-JlW z5oLj%0ax-sb&hytsK;azSAW!@J-<_@h<@Eo!w20Ing&SWgd*>NB&}n4CtwY=aJ-r@ zDPO0zSGZ{fVcd_=@gsXN8h97&cVyRkGJ#xb`COowh9ymsayNQHWuG&CBQ0~qY_~=H znZzRcdt)pEHAb>VhWslU@M3;1;;Vwd1tYmSUjUGNcq%dJM@4vAVkA5l3c@>oTMfJ7 zc;IxFoMckB_z|Q=8Tu^psXMXHgQ-}5l?3IxkJou`=S{0I=Z=77xft@DgPxmC*?_ID zOVNX()Q-U2#B6tCe@*;F!@bw43Dbk?=R_Nb;LcWu26(fUr+KEgOR4WW-G5>(1S06n z!{ed1FMLU3kHZvIQyjTf!w;@zk>Lse7b2TeVh;aUx9ySZmxRfcO_P&aRZ?uCSJ$f<;l`He7ok+D7y?sW^G2>A&P6y?jKMmt8MY%Ft8Ri+rvS6asg z zJ30a1+g>gbqFC`b;53@fjQEL5*;sf#S-bAN7w~=#(@lXDyvP~gw}bQ781|r2n*|sM z13u>69VTnJ@~k#c3|dsne=~~P{IIoQ2x#AbF+9poEBUhurpZIH8!v?HtT;%(s8pAL`|zVLC=s$;1)l}N+5xe+2WBhzf2u% zMdL{Lok4hS|L>fiUK`aUJQn2vt|_7GocgBk?~{DhKb z`P6>eq^F-uxeZ2n%N_?r-(@IpS?C*gKZ@_;f9j=q(MSK6r_{}lDLsAynA zX7qJ?>DXApv=^-?R^kE3xR3FKRHsKMS3jUTRa3I{skFH{^e&|K9h%;KyEzkb)-4%4 zV4=i>-?pJXH_>XyR7ePSk$*&DDRJsi&#t7}wjbQI2T9mvN%m<@DAU8pWc$%$&ZYAY zs=4Y0G58p_xL%QlK|`mE)pWM$5i_=9*DTepzIdWe4Nj`mk~ob5d?NsIU%+{OXM(@{qr)T@&<=Od>4K zPn@t-cP7&vyI11GD-h)OlWS$Zu&;6+%m4qx>d*eQZ~@I$G@U1nG{nUP>gSuFL--5~ z?g&9}sUr*wAYTPZ`0BR-GkEb|8;^NU_S~l$K~^WyvKUFV8GbCjmz7GNgsjZ;w$ymC%*K#{>nj)Hm40J5vRiZ_gpvx ze0b1jJ=NCnRu#UNUC(UisMZyz2g6XLox#zaR-h}l*{>r4O6a_#O?HnNlxIm&e z>MH>*w=;z}t32ptPI3WY;*zP)Gkjw900+!zX1XS}x@dWv{0TsI(Ttv$gf`JkN~MOl zSnhgpcOo97kX<_5X252+9e>R`a>S)C)e2ymDXhd5s2Q6$6aTW4N71~UG@K9q4VgNK z=1x}Zap`v~6Ia;11ZEirq4T{*g>5;LYa~;Tx&bq-yM7>4nJ4 zV@5*;1_qUc6!X&LBlU zKEQu*tsolu24iYrCE8=ysnHLf0jewCsAoR#k$r--psl9iES||3|3M@sV zsZ#Ws`YjpJekp|=8J#2Gwa)AR7x`j|ARpf*Y+&kVG`lX+0djCqdku>14j0R)aKm`F zf)>z%**C@`1LMD<2*Vzhp>}ng8UCyb(*esD*+fM}AIliDw3wZ!_jXnK%U{+eT7XZO zb>#>8+4gysX1ARxbadYFp!8am$<5FG%=~SgU4sE!Jhz%b!Df@m^I%^_Gj%`e332_a z_&4;JH_b_Si!#rX3ea0cy1G?`vmShneEPgD1iqGmkpn0IPMn0+fqltybvv9Vpvwa@ z&tnL#7_WtDO~eP+q?Bn(^wk$M523Cu9%Z%wY>3;tm9Y)A@dSpg!p>n=!5SNn)2*wp z6?MJXygV5i2`Q=QCIdWdc$u6s>?X};QpxVBmv#0NQaPL8_;l?bS_X9K&}*J~Hi0&< z(Y)KfNpY*$2D#Y+kBup_I((?PJ;HVQcl)wHwwB~Y(>$o1L-*xTJ+4zJn+nEGPA3uJ zW?n@=H|j_;=Z1Zd-y{mBSw#6k7oX}ETRA)LFv)uk_#^Q2tMwwLjdwS%axP9EbWI70 zU#8f5uJ9v&fHw#0Yu%tX!y9CZ1HMLYx`!!W3exQH8+(kt8kx~YTlLT!h7zc!D>^L( z0B@B-kD31x?Q}J6Cz?t|lzJ6VaaU26mfu2`$7*e&%iNYd(!gjWHICv<Xn9B-JCBOF z`y$l47)|dEu!|AyL0*ByrZ4NY*Fph7IuDODZ*E_w&J6Mx#w`Vn_KWbq-dlXck7FTF zhm_V^87V7k3zGx6hNLF>faJiZm%ifI*HT*QGl;JO2!$$dKe+sITE!GyUSoyl=VWHC zg7Lf_LJE7_L1pvZlL1Xve~;!L>SrXD;i(}0;c-x*NrV<;J(=*EoncLTbq4TmM(*?M zab#Ne_)O_{(=O+{hkn#Dkpzt*MkMR6X;26`k$&Z<&8B-SKI?p(PisLZc_S-@vrB8C zvYj@atTkWQV}>S1cLxXYNL&*nT0YYMw`#~deI~A+La4&IV*4CxNzGjKj(gG+3N<#h znG%pOOtikI3;{?75=mQ^KDOw--Wa5uT{#^K=>$N?7G+NkJ)X;Rm}CSe_v>Yv`sTi9j0gmL@ zvVNg`Wy+^fzLUpaIqlzDlK{|RGC`PLgh(F!n13?0J!iaE-B3f3xzCd=($tQtHP@ru zya3L)gZZHMwU9mTqAtAm1{3y$C9X)ZyEENV*ko|l(g?c5a=2pWeXKxnac!qJSLKGx zjvr%1cvhAq-DV!wSx%-)Od8nDK($2eKzOtV_oY1~rXt`ArjHM&7uxoVwOvm48t9QK z>T8cEvAUMvfNxpw51Y1_n~MvzD@pz(vw$G}*f8iT+jk)|JxgV8S7HudJCOcoh=LXp zeNN`i5TVPUwB-uZ*Vnz;+kfSFNHMe}=I9{69FR;7X>^(~%TAZb*ce)C&d_D!;)LBn zNP$>C3K30hl1TS*05tx2+U>s?QSF0fYHR69KJz4h z7Bp8Rq;#s9g9d?9^Pmq!jw9&Wx75_b6%K#m3>6ozIC7rg8@QYDE^Q~@(b187rblh= zWOsk=?d{DCg&Trxj{7xmGBIb#|4nU~i?I5iMEPo-WG7hVRe&7taq7g1f0Jd*S!0O! z!-}@aB-D?CQZ>lnB%IF1B87hAYpve(HSu}g<}d|rjWPH(h0=r5bY`ItEKqLkGnsG- zZ&iT*A!1@ZSJMVSzzVGQ!l}VY#EoMlaK<2!JD@izC)W&t;@t?wb*a?!!-s8I*>Y|( z%S0tm1o>ON%CiP-VbF4|z%#FP8?Am(P;=QmSz7cX6u>9sma=yPy}fz}gyvo2^aSnm z=(8GHK$OA&7~-QHbjNS7nD|=y8UU(44@dEeg-E$uS_Vd&c}eyclmTTkN*hPMu-A#{ zn|1DKjg1XT(V)xE!R@nW^zXEtJEm;IJn*p)G-!GtyScXrH07h$^DowvJut<&_Dham zQ=p699yEO~i$GSZU!>)0_nC&wVmDA1rkP$ycfIH-X|b7n4xA4?qlOogL<0o@cqCyV zq2bv!fUC4dPZ!pM)DjSo1c&0yWN-pk+cLa2R|IYY)+e0PQvhbOx>$8HSwJAYvwJ}p zQN5FbAzT7PuOL<1o*RKcgbHu`gW37Bionl}fKeAZJ#mG>T!-BAMSo9~mlXQ?yg zPF+|B>|IcEBL!Epr*qCgU*FuNptE7>=c1|wmvXAIIz+I-H)X0pc)kKwRp0nS-PMr? zKm03PYz%i(^Y(4~aIh_X#l_LlmibF+>S)2VHAE=d`8gMValWuBzp8DaS#Fcpwd#B-h97*H&6pxd{pgZ89E^?_kfRxcLkYz~+sO6@KMvO@oiWQH2jj zRZ*V14ET4AyZ!(8J(u*Z7XU;ZyDIFhPd5d?lir-`=BU{nlQ}7i5JeVNmTg1ia3hhZ z2Bi8x=0r+QL%N-D=(XS_`a&eB;;nHJa9|VF!60)QOOT-CI&6cH_4|BDNSHWR*GWhTHXY)3(>Cka17w%#csZSOqxZI=MDL zZxQ)q0CZ;~6XRq?oP00AEt~=;#a=J<1Hn|Gsd@VvHk>qFBO2RMswj~7DY!6{ISOO` zyi6?khMW%fo;S9P1Th&M8TnI{91C_$YzrM*38)itvf_MGTSupJU_c%QgGoz2ycZku z?VsY8k^6-Rjz+I>r_p}*SN4viX5We(lRsgh#y6Ce{ldjgM9}YFdKG%IyN^hhuW@l~ z_$UASH9U2;kAo8ymXn9fXt1NWr-9JT8(0@XYc22QfY3gV7qs%rK^>F+itBX6MEUT6 zCGVRLs59Y3b~)m|W^~f@rGYQ^G&efK4JD=2rkLY50olR5Q-|gut-xm&=NdlHD@a2l zG-XRNdniMna~#02vVQ=^`EAX?_iz996l*E&a~xTe=#Y0bCm_}S2{bKmERwR8>2A)y z{!(`;0>6_Tem##X4x`xr+T-NvSo+g+MzjAUWPn7sMJ#C}-Jh6SRW)A#3>oKt`;#9Q zn*zcwk47J;<_jI9;9?s@Qf*HSJqD~}VfP@@(^b6KmKP<5F1~x=|8e#nj#T(>-*`BY z%m#%VX;CuDjAJyVLZxhu6&V@X^U%<+l5(<1*2gA$M#!Go9GvXEH^1u`)#rQP&vW0; z?;j}VocH^EUDs<}2_cxx)#>11=bDEk70ZX%JU4%_B_i#brS#WqcqPazSa#aT5!hv( zf#AVps?^>!3ifY;MH-Lw5HN~f?)>v!F6 zF8ksPok>SMY3yMfPlXpSl8r6K>pLEs?ulSUtj`L1Vmmw$5~tXCX`)5*A|hT+3_|A1 z)0uZcF(8oo*-cqT7soQpA5KF>Wrh{^La?5l?vG5krfqbw;nGG+fz4u{J;hkf4c7H8 zJ&qw57B>mqLC;oqfPLeII7xypZNnydAs7$%`3v7gOCESJ3(?$lFn{gGwtE4nu_Gu; z&xD~6I)` zMTs5s@(LE0?Sh2&9V#%!pD@>K71Q6^DJsxui`q9k>i#0gWthG+V)o<>eoQ9Ddjy3p zE-WC7~znSZ0agjgc>jF)pVdW0x6Qj8f+Xj!a^E?(hD@|?-bH?`cM9_IATP7j( z{v2}CBhDRF*uF-J+b!{%^c}d2xNabQc2I}hj|p%1*9;C^d2LYijqKOO`w}cex9LSD z%#cHHIBt-UNz1C|E&)U~KN6-FLpuaSK7%(P4<-wXBK$sjV}b=Po_SCUzO_tKN38nk z{jQY13*}ercngpXR&gLi2e)i~4bN5K@_*35YVH=Ef|jSDwWWId57`cfywxrJsaeF$ zU70&I>m~OlAljl&E!KdvZLw_pP>0J%5p!5>&&c8G)s4C!kd+~_Y}e;HX_mYfh#$sd zwh~+YRvEbFoG38|fCndXGG(bqPnxLI6V z*Qgm~xL1V0 z!S6S%B60}z{<%l3X9-*a9h(dG(~zN<5!?$OAlP72wiT#HTfj2lu_QdFKH-xRm)2)0 zU8KSRliU^~=v1R)p5EGKMjqTENISM5iq{nSo;Z22#}^z{hM2q&eMDAj7D;fn!|P-1*)Y=_)h3vWb=KM zH+~6>d>>&`Q(^q@g7&8~33U&NM;z(Ul#uS>*aC4;0$-!3tP0ir{6-FXQ+X_gg@7iY zVG?R#xIrk4aCshnK@nbSa`@Vr{@I-KIE!TqK%AitW^4wjw!SmzjKu2U&)BdAP~g05 zy%y)zwz^jR@p+V-v>JJK2>Puo_jxrv6V6<;&v@+O+QR-CQ9B*t`K0aMP)*iw=_B-p zO#3C7;4P=x&w{%tzYZWHU_EOKV{NL_CdVe7U;xp}$q8hv;1w3Kfj>F(B0pUn0k|QY z=lF1#AGiBq&FJ%R(?DNplu2XO|0kTbrHME6AnkM1aabO`mL= z9s`Hpu5oUDJ_u!da8i{&8aAzpkj-rwjr@W+y5}}FoRHClGe`NucLmB=j2VLdi4lEs z!R{6K+4S)>(y!HitN{krv8Wp^>+P-iD^vZ31QoA{Vdv`D7Wdh!qHY9mo&Ys9zlIvn z4-O6|iPquEO@nu~Cq`~>DH9Q3TvKmgPsVCz7BPPJ)14c|_LL(|VF*sBj(c7uS~V@X znp2^n?`D>oTtUV400ct{NlssYxZf3?CBpY{ZQe|cqcJPV83{ZmjET@aK}*Xr9-O(< zedT8W3-jBy#lNT;SfJ~?rw z=ZpdhJX|i-$W2AX$;tKf=MNvU=}0&!{eau$A3^^(#Lc|bxunopVBdE_(u>3w^W2KE z(*X$?V6zCBalIfcJmRTbGW&FtLEv79(vov(=+F1t)#J}C)lnl54*$4Ya^#06I&SL& z>~nnJl^M5vG`4ltQ*g3vPdtLc;ar)lVk_q);KAA%#+p9;RL|z(zd_C_fVkz!1Jgz` zgg_OQ30_$TK!s2>f-LZ*yS?99$VL=yZ3Zh-L0j{@2heTWL_ygQfpxgceJ@{{qIOC| zn*~-XAHqzu;YUgfV-c~cTK*tNX`M?M@zH#hAo&1{2POr=fc38j(`oCIyqQ0{GbmLI zI5}-;e7fcv3_M6wR413m>6-3<_$NBTQB>|tiOR6DYH{Lycqq>wQztx>Fdq2RW|wpMXIhfc_#OL_$1&Md%Y*o`R?)1z$|-l zY-uRB=cAox-#{@WAOMV}qj^WzVVI74EhZ$S_`udc7GTi-S zCG2Eplpnp3W4_bn!~muIn}EwFDFs3B=VzuyL|K$|xKZ1i8PD)Y(Yjhb{yY%a4VSwe z@q)e#KAr{PZrk|^XG>D^w(#EGtrpqh9{%W$!~(P296&b$Ka}Pk7T&~?v+dA?P5Kx#m3P$Q+@3+Hn_csR00&pmP+6GoC z0{G&RExUIfa$R~&L53i6OYRC1Cd0PKY|A|8f8LI69Pb%b<=yv=uiOu+N6 z?FR((Vy_MH44`+(c*W!u=sZ_?(PBm`=3bK^OWgmLZci9n*oe4*nP}!c96%6S-}zT} z&L0XB`T{5{7Z$+d5}=*=0@dU_n9sL&M3w*CXZ(4a^MTl{A?t8-V_O@jr8RO{gN#1I z`Tt=!_=RupKpTBa*Q6cHWDn#eF<;-mYnTBroY(7~a&Yy}_-TYi2=iwGT=}?EQ}i{3 zhRy;WZZ0$tFnjIrAJrSiM%L@laAVfptj%zLhIhg5gyH=I3E82f1Q583c+y3b+1n9V z<#nCOZs>ZZp!IISwUtZ5(6RHFt6amPvtXwSq49qx>URez=8y>?IIyxoN zQzQ-SRZhkh#MO#wu9Cuf);z+cFl zTH_~lCf7=mJ&Ud9B7e_6zZu*FLHXnYVCXv3(5m_MW=^E@41W(l_d4WfhetyXRN;fH zC-T>3x>(jU#^-+~Ch+9tFO}ph;wF6yKohiKkG4BgNIvipz%lp}IPVh<#w|M##TNt(!3Q)lDNI;apanGt30h0) zy@JSh{4~)|2sQJZ+dSi+hs4EX27YhPSzb2`pSZ}a(SnAsKx6>sSM;m|$VLh3IJ67@ zT4i#$?RXl$`RoxGck@^GJ9c3MfNK(@fe+*tRgRzKlwBqqphC8|j^lS_kh+ic_0RHj zN9Wgk{=5OgNlc2z9C*QiL5e=y{Ajnk{0$0nhK1ZBvz?n>Ocb|TJ81lYQQHUFqC__1 zrH!L1t!9BD){9}UCY&~AFPobuCz2sESNq(!qG(0PJ(0(;L@V~9lg7=NY}*~$eUcT5 z=?}jLkNsN~Bd%-!aeaf3tL*M4|$b!8TZ?!yN}2IYo1C^G?vbWH|HyAOQi-D z~3j5gw`@+|Z`MU%jnzy%Cw1 zjHBz2jqpLO{Ok_^0?{<_+V1OsKbp7~mz8w#=BefZ6Y8Z;l@5;6Zr1kpYEG-(ZIw6 z-nX)!Wg@<_HeK$V2_18_*V6{;>+2zxr7OqU9DP?o;nn_ckrEDYz_}bj-}@G!SlfAx zc$#z`ZZ^i+VoC=L>X*tN9&5U8Z)>B(Ah9rs1N(GOUqjs)&)Mr3&P!)WW`S@xzUNhB zD-P%N6YiDiCGTDUfDK9@CoK8x3Wz)oTtLUL~Y9%lAVW%#l!*e19r;JAO**b0&*)(b= zAGQ3df?m9Q$*e1W>Sl046Mtk>6vHHXMFN>K=Q1<9UrUnx2j;nvVO!&Inh}9_uMi`F zdT+0496BL+a>~9uO>0cWrn5qn7$_N1`Nz%foR?Q{e!eWU5_x`KR?)6{5)D z8jgK1O443b)MbJZ8B$B=8Fe9RKI2QTrB`^FWUIg9D+{S+T->?->1ls8Lj zIqfcu^Hs83cPIO+9h7+3n`7<-_YxJ$uH={3bA&w$3Na{iEk?iNH@zkrI zPq}BjH$B2$H@?!4X#^IsC;3Vjyi9r;R&CdAPmZ2HXjS!a12Wgdk-sjP)sYAlkLje+z5SSds3Z7)M9Z!+WIc5!4c1+#|wzs zOGC8EICiK}V5D|r9!l60Tj-a{09)6ZZTe!I&yLHv(Og~3d^vH@ukz4jGjEf-x;^O- zH_D8)Wx1xR>Q_qW<-t24-$x)xtkr*|we@K2X9-zOOAD4j{`P{&w(F#kZ%eeCa~OT022`JXPzU>&ueym%IkKS zo};5?D$8z0uEg>7jUDt}3)m}5cEZ$3ij&Cs~Vrx2pF_o6w8$!k4qIbj9A|*^%&)E~{ zw*{_u8L4cnx!u@6bsjj}cR5aTr=za1%!m9JD+N)ee71wX5;Hg>LPYI-qcm=aLYH{2 zHk|xUS=65Ue&*hGt@uy3S&+y`t5``rPleRvglII3zaiRF^r6#g?M@KUnrGo1w%{OD9u%F&l->w*}vJ~ImeOZMjO%yKS5UH^twa#jo40lOG!$MZUKyLdvMo|B6&F{32tn@^@_AnLZ2}DyH6-)OgxOs zx=Yas3u0Z!o{{#S%N5&P&Ka!9y14J2n`!7CfNB9#gdcqy9!v2d2y_TwKi01ku!0?c zN<~$W`y~50uTAlOlJ3Z-71~B8e~%A?!nl>bYc?z#4d8>aNlV)6JCTq6(s3-qY?h*jL|N7RZlIwvZtG>p_FwoM&6Y8x01o`8oI>?% zj=`{D=6YF%b$8Zk2{&nc`A>(urOzC1X!*$`$pMobWemNnkN;?~1^-&b{V(X7KkQ9_ z0wpM?={}L!|9rH88Ah2JxWcsf5N^5tI9k8Omxz%|>3VtU1!S}uVe-qG+ymBblZtoaN(QQ5{*a2iuutO> zCU~kX=#shX{$k3lA~6iQ>%>Fmnh61AT*eY?Wf)Ipyu7&A_(9KCTHS`2BO+YaFdX3O zR7Cl%|1)c;MIMhdV$>b`#D*NNYpFg3zj3-7ZX>lhfM4dTOI*v|{e826+?J{h*5RDYP-3sZ<)X%&_fGEzOzdlmA(+^FAcrWf@O0eLRkrB;l!0K3vp& z81&^L{8OKCElc$to01-h)l+wiT1whUO9j~;X*h9kX1flTsN+m8eH+-yDLLQFJ?6ME zQ1PuXCNcq$AB)$WiddTKoAEd|haMgs0sXz$Q;R_4&<>Oto8gK%o53-en<_wMUg)j5 z-a_NlQ*rXzlW(lVzb+C8EdgI1uB>^=w0Igy${r-^6z1JOrk!s`h4u#SGtLA_%NL)| z7M<9zbQ)&i2fE;AG~!;*LQ7X->pvk_MfBK4bv=j`g98F8S;YDHe&vMBkFCy(X#wUO z!$C+U`KcN1eb$A z62Gdrj@zg}gfVC*?%5h`^u#SqXE||HM3mvDAM;g6@2M2XI{V`xa&|4OR`@IxzBo1S zN(N4Bw)lmW>RW+FAI>H#y6-Q?KdQngJ5_o;a;uUJwtY=vODvom?}R*5JRMs2Y#DpJ z;7DWo02w*SwAH?XK-w(2{y9tYZ=`)L#`*COI27 z>{1nf2|ZeF$r)ij$ec^4tpYuycVWh4nuC&Jjldk*SWG{ zhpbP$1H8X<%M*j=mXnE&j$Nx4hrh^MVom&kBsEaXSXOl-fNr(LUrVX$4Lb-^fpo4~K6C<#H$c{O3CA1ySo=p+6(wC?h?>M@o!~W_jGOdT7Oo7VBfc26 zQ1hSZpG)s7T9bb#>Bvr4Y)?{4DGktTDL^RAI$PpdpK?%-jOG)ywFy-!goq*)_A|!~Wbfm+qn=q;*y5Pw!Q?c0(_2o>M&K8-Htg+Tg|Pp~kEu zRy0G33*32$Bsp_Ja_GfGjit;^onU0653>9kjWN2qH;;I`K3qF-z>{o4N$9K! zlEruiFV(!JAxH4*up>q(93;t>|EPmK)r%D7z^|ZyHSuj@ak02>1{CGW?P-10nBR^C zf?;9waSNa0%Zysn#k#APDP|%I0O3lLig_8$Ds=u9(EdLRoEOR%s6}qXj|`C3yu^e& zLVv6jpExt36k-CNY}2j{N}H}ty+=mUT?6U+HgR7T<}d=O1*QwLimBuf5GEx(BJQYt z3(MjGJWl$&4Jx>@)t>?voM!95tQtu$-ugRa?X(buNwL4ZS-iVl}LUT`@m2a;(N9d@TTCycj4kg1PtBY}m8e1IuZgdX}_)1+)m0{15 zrk0#NA7L7^r}u8S!c{KhQQqSrk-I)(JJyY40XVS5AgjWkDRYDBP1SqOaszTe7fhe86s z%c(zP_Uoy=y@&walK6z9fy!T6;+q+M@%2rPL7Ez{M(sl2WSP_I1(o;`psme)5(ih} zqYH8GskQZ(amx^a$SbcLu7jxNNTr$~EiUla+_^FIhrOjNTFXy#)E;r&^XARjy%&+KX`FVl=- zADNosu`GCZ{N1YnTKp)qpuVRJbNMaVdlxXej{E7rjNpR05o}XAiMAWcRPSvrT3aqV zZQRGz?pIcVya>O9uG4bQ8-#J(Z^2+4{^0;d9(&f>Y&*9k|YC#G*K%V<&=? zN6g$Bz^S+2@1*nIN*_Hr3;DCk-Y|Xrh^v(nhz>g1021kcA7-r41cGjt*0{;WANQBu zIgHdIpzJV|78{h9fPlcIOK+^t1AcCL2os)SYvnj;bkPqI+{7(=nk+U{gWHolNr;ZM zRQTPBc>Is?EJscqe4}{Y*HTP>HOssE znha*IG;R4(9P-+%e4pvs>4SuV8D&<&MM(-`e)4MvOT!-soIIb5&xVeY)VVPO1%%7M z2IbmhOVX;3qEkU>D{?F|?gD+)T-l!}AY^A_V8Gj9nNuI4R&!;36;%474DUL|H+A~OIWg$*;QISO3 zVd>neZRQ&~ExYoTF0V571CK|PIs&QY0*QHC!*PYHrGcnHmyAs`NXy*pZ) zgcP;uxp|yjIF3GK!!NOn#X5pcE1=kH&y-7PHuR)NF;jU5tfzBn+P5UKuN-|&x!7oP zj4r)5LSxKYJR~WflL)`>5%^wkRcD>2D#<4H#X` zi@jT%YfyJtTl=JfOIP)>wPG~JsPEi9@v=QG;DIeqZ^X*}g0d=4pi*zLWf9!0X_&8S zD%(k>X<^XbFNycO)URy~I$)x%H`dV5pe6o;SxPluk^^$Q>@|6E7iI@%gUte zecJAY$+1!+et|LkszxlFwC3cItO4kkaTmu?y!p@PAvjq@G`helcrjT2xR@dH=Tp9e zI**ZYiswtEiI#G>B`&E&E0AxP#hVH6@%1>6cpM@^C87omky^!zW4_JQmnF~{F03hv zUflDa6GXZx^hdJV1LhNf7hrpov}P=dAG(eqA{M>`_%8|ZREDXB-mM~qcT<_2zb1*h zHaooFn|jsZj5f(ixSg;;QHLhR-v~y!QN!g0F^qYC&oFqJiE*W7 zIg11d>~QvcxYlaW9Oq{+*RB4jH?s>}oWFCL-XtP%jnRp>^@_vr?aLX{*@+l#r|AiW z0>;A>4vrhM5o7k7>;4GkCemYw9VJPy8R??f5@W5&bJBcS-Mo-$9|GiQvE_m*rW{e4 zZ1H3fm$~3R8FU(QAr~+&OgrAsCzRzDSQU`a>d(`NVlKrDW_zTmq?#f(&xHqO+V@{9 zRNtrJaM5q>dLySaO-3KrC%fQP)to45XRWDPG4hFmxbCEK%;)z%bBva=DtxXmlUh9B z_t}GH%N5Q<^L8b??w?M)w|ir)zVCVN#(!{!jq|4Zg@GmfqdiUY~E~eg1x#6 zC7g+Jor89_+hy8uIF{ECIoG+l>=BB5_qL#QZ=cKh9(pnEJui{hPMO_j9KgWusTlhH zUV33}fsTeoXmWD>-baP`khKX5)|I?Qv5ou5`yqLMzB?`>SKY;?P>q(M?oEka{DrYc z{5NR*qL6EA%iNcNjrn-bWnU^fe>J80Io;CqryPmFG>LUZ6bDf@rqhy%O+sg5mg)oR z-I{~#tmH#N`(-N%%UAk;VG>(JbUQyE+!tp?wxeNtwX1`7WerQ1gWaZc4cn#!OEq?B@^u;E))Ol~ z=F%Xi#?K#5MUViZLzd)@gYezgO!wq>c#X(V_DWQ4&&gZI1I<@#EB)$hL=hGhO|f5 zdarSjls+xxfoUuB^Y-w1dj2=7c4C;&V40+aysnDpSC5-F4<0176yffiobp0K8(n@DY;JzId+M!XIx3n&f|=|JxtY36hLff}k?Ny3 ztwTI{?^fln3b)-Lu&UVZFi`6y+nF%h-zYFfDI9u(u)cG~CxW>JE?Yh%mR*dq9{5^h54;foAR`o^L$HILHxm(wc%P8_Z;#GF<@QG^nQZdmR-vbVv)U! zH}%e#Zi0&ECUfgqUK*k5HUiB4g7@M&T+iWSi)$R`N@sB_%eE=aOrdVVv9C6MmHT9l z_WnaxRdJQs^w7+&f5=AU{id;+B?x;WWo#EXIXJc$NKof39dz2tCCZB4*bDlQ1kfE~ z&Wd@&x*K-wx?8cVrHCs;kFYwW2rhk4?~=PYFGDnB=FhPvdauSWS7=$9Q=6IY-$TJR zozOMsvXY!23JP7};yB;tAnj+GAgsw(4+(Awl(%fp;SBD6jGLtr9s8ATGa_#v35IOk z;(gvK|L;IJIdtv&PN=zr5Q7icdks)`rAIbQPJvJhWXLM%dbrYU+7hg-1am{1s%Wi= zJ;2pZh6Mi6Td!`|%BI}b%p#H^jsFPJ!F0JLP7KP6oZ7e!vf9M$f-^njO|H7Q1L|2N zyW(yNygGuW6n3922)3&jAHvAJ_PR9Ybmq~%e_}o zOzNSnbJfy3R5t=%P%l9?L)K-^Rts=$ypF0-xi>Pv0~r_8WveeN1Ey>s9^@EH{_Ng? zQ|Y!?DxIWD#}yAgdv+OcJnK;aOUji^2yW8@euKGH_D^0#*4SVQZaH?nva?Y)h$X|M zJQ;G25)`I)yKq!O9GJ9|K_6VFo7T@ocv_3Bg9*g=${h*76~_q`cUv<2|D+f;xS#QA ztWb)fxf*X(xfb<<;Niiz`q%%RkwVCsF!~%kn34B+#^^|1^rqu^=!zQ3>Fc4nENZ{B zYjTCA5p<*WUTVUYX1?ns>`54g21sg=j7$`57j+S_>ogzV5e`2w(mcd&MXZ~v?$kCu z>VqQ*s$56$rV2z@92eRg#cZs$c%J@l<*J4xm`GfvPi<1xb*yX#v=!%pZU7z@&7bff zmJ+`A=Cx^?+{8p0Tjd5*bxmh!cbeLiJ6(a9KYB*XJek9(-_fe1B99;}IP~OAF4VZG z+*4+=%^AZLg!C_lwJb(d#_WD9b$ZNy z#qhVn*M_od-6@CR=+x|ChG=|UH7+pIU9V1=+ET6uJ&*&2cuYt2P%Yon^P&BV|JI^F;@aJ`jiHl456~fgXfc}; zF0oz$Nf{z-1pEC+`@0|XMb=yoygq*H(?zE%+(QoS&kk808F|X^qBS@v6+;5>l!-Ix zhD}3vca42SoQC1?Zaufrd?uSN8)eN=M!Z|qhP8t%jsGzIB8zevK85;cQW?$ZcenyEfz*b1AYBV0FC(B z7FyK5IFnpqQAeCf8-{!ymftk_R$bLIF3Jl$lOF|}Oc|UGCeL%~;D3}@& z0zfFAG=1vht$u$5qi{NDUzUN zyQ(d)V7)cJ9~WhwJp_^a2^TpBL&U(AtC01^JM)kAYcPR5bT(^LYwe2^PndJ)F0Ad`tmX|T0%BUTO5nB*UfKe$u3LX>nGYWdtHSGX%A89-9yyEEVXJt9zvHKq$g=bEk=Yc|K9*}l zD)NGYrY7w!{^I%EzjT;^uP*AM`u=Kgy+7G%vRjmgr>?oVbOm;?d6sCwFfi)Nl4E`( zcQu>FGQgG)eb@pl{pYGkh$xc#-Yk(TDOr14&NnieLDSQex=VupmH zmB4!Wn4-%6Q90KnU_eR{EoJYzFHUokK6_r+!vB3Kz}YwDM8W{{q#U4&8#^$75 zEA7j~Hbcx48$uqP!@c#J!qHL$1Wvn*oBvo|)9_2E( zU(9)M#Yncb?DDoxsaibv%l(*z1*_Q}I9||t^}hjfG(8fam{L890g38EEDL;tnCWy^ zwSr_t%2==>oyOuQ%ff93^@9Tgb&h%tJ>d2_-FsFp!!Akfd~oay2|fGAhKA3JD4~vZ zUJHFSO7+RQll#=ZUxGOc$=YT6&w3qbu5NRH#lAYl#Okxf@I6NO6<}Af*IRW zi=en%iha^I2yHtE@8~+bzWDez=?!3Mf)&k68@F>tM%wq4FBDsI868Kj8`P<&7QqTv zVQur&v05%j;#FoGE)E2Z>9Al-#aCJP=5wc$} zvhzw)Tf?8gT=a9tPS+zYlE5^GJ=1_VOT67Eoy9=yYk_~@IZccUWNz)aevCy)2=czw zUY9s~)m<*&zYXzjWmVKp{}b#1e=_6%>?FAf-|#P5J>V^4@DT2()nsy7oU|-+u6WuG+66;`?ddJEYfxDbo0}-r;JEo4Pw5UW&FZK;B5pR%)ab<@ zL`%+RJ2qI2NaS|BJA?A#KLKl^%Hw5j6|X^o=siOcq2(mvDBkT^DgBy!2-Gr;mRPZm z2p*=+cs+IjS-|p{$W8CNex7k=j{VytMTgO1)8O>mohAP*k$2L&$<}ebV5z$Zz1gSM zIVt#?SoIJ}zpE)P|16>JBH9*J_t8=u|F9>p@rsdDYs@!5(C&`ez+YgWDJUeAX^aYr zgRg|BD`W5(EQAC>TBZA*QW_c>x#YH&F&OB4{3O%k<2@j`Hc)()806n@BfsJqs}41j zFeqQ#^zxkOB}~gz5~NKe6}2|u`S}}weUkv&GYnl_a@S} zW#nP&HV^zKzn=N=reaWPZ=a(BbB-x4X|VOq;DB1B@zfnc@pZBFWELryxI?9iR zEg?(&k7jp=EsYdQu)fo2>z)}p$2B{@T#L)IZ9Gjw>p}Xw(xH40XFBg#4F>EY+b)YY zbM<`XIu{ijw6*b$!+v2P6q@<8DiF%c*(3geH%Rja((&ojr;vpcy(uXOQXx;}QoyzE zUGZ&<*W33!oaa0pA&zc;Et)^5B(+^#usdGwos5ChUsAjsPq-_Q@WD3^#@l?nASxEK zlNC#dicKk*uXiVcs+8|v#%~}2j<7xPv5=B?y6L&aUq-4?P#?H4mNN3->i-en^*%~v zhipG4IqLUHoCXO#-Hz)!GWu~g$h3^%nEquL(=TfrZmD$pc1F%y&p;vtvrCx7TFl0T z$YkbMIAs&fEo9bbAv3!FB1JNlCYsbCGH2q8UF4&k zs;#T9c`5+?Xvs&MoYC#JeZRH1Pla7*ZIHSC%U0K33 z{rcLE`e_hu-X7wHSPSAuYwM$4%mpu)zW(ujahK7bE5zm>=A*|>o%_Ci=iHD>u%Fo_ z!e4iU@Yg|rMUE1_mbxCAS>R)yJP|b?sCw)V4im-mkZnxn2#qpyA6&v$dzUG9{>iF63>v*o;9opY>U%XGyUdi$v0m*+*6 zvl6eqMe1Bs>Yv%pNIQoW-M5zka|%?7c7>ontAsTM<4}I^p zqFcX+|8x{bY;8zEHq0GI1Kg2*LR(g_F=dSZ=M@Sy@*CB1h)vk1U<5Tdz_m z5v}tQp8ykzsAk6AZTXt(j(jci|33O+{+fMbAwDa0_9FH>^(G7U{}?o`m4o-!j||fy ziq9}{$co``Nv!_kxR`!^W#uIy74}z4qG}GHTErPfbGzjuFy+xq5XJS`%;#km}|~<#aXz8#&Qht)NC3Unv1N&jXDi*#6lOI31rT#1@gl+)_s5cyz^ual0q~NwvVBhD{2AP53Adn-M6D^`!O}9z@nvgz zQpmHN1f!to?}W}_%O4v}4F{2zg20GgJI7AK z2?1~@^F%ZHYZbvM}d~EAM$9}~j%t-)i$DZp!aALOiNf4w-{kzg6 zZbE9?hqxVN*Y{sOyn5q!swfo;&EheUNkFkj^M_oxzJ04|spQ6HPRhw!Y5}R$Owl6a%cm3y%sOGDo9Bd@de;3Z=XC zfr0|qNqyPq-OO+{s0pxF8mRAxZ!kMyI@@P=>j)DfpG&O1DWCi=N6qMGXyF2E2Wu$5 zF$CdHp!x?S>(9&}jY?0Vrl2r%9dPcoiOp+oSA_;>AW8cf!3GI|cw3M+#IL_1WDV`y z4(v!dT+!`joUlddy8|RXn&!5J69TdbG;T)wSbgu>m;cKyqU3oqstb*WlbsiS2UJ08 zvAJ?&Qr*GCrMiRt%Q_*y4gO|G>m>-+uS)J3+@5o)@Z+-HLGm&S4Wnm9)97t^p{H&JB&x1LnXth~g;B(CW0x+lp5=9?xoBKxaY}HY}Qg z4NlEQlKKbVAm+4YjZQKTR;uuM*77VJ&pETQkfBEYGMc=VfdCFcHbXhyIhomV@$x5Eqqpe*g^YH_QUO9{ReF?N`ekHmQI-T@+Cz0HmFd>QY<@9AG1j>yp2AZMMT zpm|$C^2MiOmyws=@d|`2E+^3-c{~d&kMGW zy>rRAJ2jMkjD+}E|?A?_;rED zm=1VY!x>F>tO^?AXq1b|$u-%-I=Z@~EfJ?ZOeDF^i7P5tm&r7Cbhz;r4f1&#Ri3F6-My!wpbLztZQJ4!Qb-I3<eK&Z1GVR- zZCaT8xUerVE>1f87|#iliqVbL$^2PQj*qnb2$AF4aY3d90tOEktHZM(@Q@Ho$}NC- zGD=7TIEMLW?DLGqA^=rjc70pS*9d^QbS>k%F-<~Jfi*BR$w|mE~5d`Lmc>`NEhHf$f zkkY#z1ZmrXUVT1AG2NNckj>xaDt(Tv^%9&1!uQZqtKp&B(^SzPH9`HZ6dnT~Nt&;{ zTc24~_>lZR8-CRpa#&wI5rW5Jt2kjTGk{LmPNHK@0PQ~*l=-n1w=2PkPD)A|&9rym zg29b{rC$7*zD{gyPAF;q*3PtBM*l@LjyJO>1u;bo4=j}n)1YBdL$mXQ+|t@Jm<3}V zoKrxK{Ltk!e6Koea3HcsY4B}rI6iZ919n&~SKk~Q9r#L7b_gv=M@L8V z)AurzE93T~xvC_kSO|u+n#ge=#*$vvt0Zfa2L;*g6#8 zKrJ*6y+}T^ucp!IQ_{Q5fN#&A#o6vTtUF6pcU;z?SD4>Z zy~&d7Az`=2zeUG{RjPc9YKwl}kQ);H9}8l!xrRVSwC>N0^wl>~l%N=6LL2X{_W?Vb zs)I?G!Fmzd+x1#&oU7KfZaDc6eDQ0G6P^2kcIm3G|Hkut8X%_)Owl*>*OVXhKoCdk zW9U@<;9P%B-5x9VGQ9gKCx_$au<|5NOSNBVby_UH2EP(Td6%4srtQa%ednr2Fr17Y zPwC3iY!6lM@mLxj)~6t4KUXop(gG~-0N|Tkd{nif$7e}lEAhCUGVS^ge+qRQSH80Pv^^jdQd`hQIgEF<&{6;77TKPo~HJB@a;b+e+@Okpj zD#_Cx6Qi-`&xPhosW40$7lQG#CGrcQUYeP8&_(}*P&d%VD@sH&2FudS|r$<2P^z+`itQk9>$sto&5_cP`$YCmob zdN1yKLT{P(@jI_QSex{K2In!GRWnGJVFiHd-UUZ@oH_A)DQb!S`wcDJ%6UvrCGyt$ z`E12pm0IGv(pcVRpj&B&k0s8S0aIGMQdLA2NEatSSr;ysx;ZdOb~~DEJ8yNH`fL8V zxUMxbX?F%7(}36fu-ah!PcYEGqpytH+&w&+%dYTB94gJwxpPiNdbG@oCF*D-Z1*U6 zG&DMD-qB!1pDK76)*pOgJ$k$}7wzP&h{RR8?ZvVEVu~cf!vs4ZfOET)JVxuTXX{W@ zMuqQ4T!(|--d?e0mEY=3K?G=eQUB$nk3{pwgcc=GG%l5|-t)R1w#jD-+in73OOl*I zUwO;@%8D(_YSZ6rChT9kbiCW}`B*6Fg+{us$xylE6(NU`Qt6L3 z)Z*>)gFbAqlQ*e^`Ucu1=CpV%2E`C1{j2~tVUr`b$x-vgXQ(t6#+pf&beeu1A&ea9 z;4<|d2x(yXF)8o`1bu7~X7^o_Bs(Q?_S=V=sT-$~RSb_h(X}muqKVDY!QNu^ zed)F=W-V1mUsF1ZiHZ{5n&Gz|Iv2}-49xMB%gm#$y4cKGg|7i?cK0r_^P}7;D<5h_ zBuA7B9!$gPdbrU6ELj=97q!g(fYNJEXp?O z8YTpkG>}q2MMVMWu0cdmDd}dAkP?vYxj=48VnD^AK~TC8kVcX2E&-7kx`&>b_e8zp zdA{#>-}%8GMew@zxzD}VUVAMjk?HR~DoL7EgX}KpTT(L62n8SF0GJR^{i&TD1wk`G^#|b?o%&MN-|2mZ*Y0SOL3SeW zQ^t@pyT`r!s4gGm;)MnYEk9U@Bbbk}g{b$-J178!4Zno_%U?v-(Ug#P#D4tN52#l3 z_Nrp3 z58dSZO(uM#I^IC!#Kz_xFBC#K%UAZ&4*LJ`2Z`g8!N=DDB{l4QF8cqES@m%8B{6Y# zT|n!&twTKX_uhT&T0VAgs&}*BbQ=h!Q1x{No=;*g5HW4ul)6DsW!Bj}dIRfm7I5)m zzEsx@P~8Id_F;VM6fIC(a`{M=+d4IRI^8#@qvMgE#|5kh%7=!k#mV4o3voxNKLh*6 zyQE9H+wsHM+)|G+7TrY}&T@ym!U=>M*+Y)9@su`))OP{6uga{GjK3VAi3_%6xi6tbBv6IWCjl0H|=PfQ< z+1Ln7JYwAF6%ZA52Lzf+_)Z4qjl#q2d0V~=s%qDrtj^?usa@!O}W$3S2i zs*1Gp6xH!-|2TnMzBTO(YrfxWe++_8X-E;DthHhN>+Bx<;CDc6GXe)9R*Q_hUP}wSDXM^W&%T zEHdMMThs-s!6J47y9v~w446LLeJHHFfzr* zUz_QO6|i$^no~Tx=#>a)Qkh4ae&{~n^J{l6E*EVMRXu60^4TC??*$obhIJfD0qm4_qLz--nM>V582&37WK3sn;_Y`=xV%-WRYYls zM!8UvJs=KjQxV`TOS`p`v%Y8QFh%Z`&D+26{XL*k-xkj|t=~xq1+_TdVvA_|l2H0^ zAmL#NusZ~XI{ENA#OhdSf%MVP=2H=U%3Fmjl>enJ6)&9>HB%MGwUj-naXM8$C78zl zJI?wxJmC-ha;QVV1EW5`I~oay}W zS_qjK;NkQ9LA@_3SjXFa(&k6=xI+|g0@;Wz81YNorfSSR=uBK065xf29I&u$2V3N^ zZa*K@T9_|Nmt|n(?oM9-+R8wFRvx%D0NM}qH&?g37oNNR!AouJ>fwB66;G}ENspoz z8|sN&OrDf_@x$)gv?F=Z8)JInUyyEizMe)M>9}Dz`zH@emF^V9$S+w|E9a8u>}_nE z#*2Lr6;zAOjp-7%m4@)iXImBr1cRL~Rm=Avs5bW}r$CaB&eCT$WJ&_AaIvjI z2s0)igI~=tJwouc3fu@7@c+jq5qSDNWGBRSPIcmk@yh`@+6CM^JX6&k{ggfXEoHz{ z0@fLjd3q@GUx@)ZP%Z#!(C=!eB;+;Gc!{dR#NNe&AGJ+*r_NlD7XS+$ZpM2N@7Hw^ z3hP$mr^e4+h{3-;Wl}uJI^7jV_}NC8HSZ&UxF`s&l|ymtO+QOKJ&Qdpy}6_z7UL`; zBMXpG^t*hiQ(jy!NtkUMuQ(d1{s3|^_kBR21kRQP`rU=Shd|fY3z_FawG;J+1ugw4 zaO(Y55!i6Zv9TpbcSF((_Fb66CGFw)NHE|AywIpZ$nO}`ywB?JZ%Mua930n+)Ba19neeELE?|W?nzx}>< zXozk%yVBOmdqUdc?q^(R9+eq2+|3wLI(4kRJ9Bh&r0V#b3U)*_>t-G2;!-EQU4QS? zPwb(E*tz+#kL7V)y#9xPR%T!ci9|3ApmYCaPzzH5^;A z?w5&g(>G>bhY!K_5^KpI#PRY&^lw;0Z}3g)_57-;$oto51SiX@2t8d~qDd_isJm>Q zKAqN1>&Ij8o_-ltx%$9#@_#_SwTKO~pLj+u3k1RljLw;J?>qc)Aj{6;1as!i-=u_` zA)L?F^8CIPun6_x^yQb5N`zp@b)hpCf}1-dJksvoyVn4gwy(fUQmTTF*6tkxB9#aq zQp|JPe~awr`+X00gW&H>8$J7{wnQ!gVS{Ag6XH!`Xb-P}bx!aaRF zy%pKn$5UIr0c7??{yPO0AsCgt+tKk|%FS*Sm!hZg&$$UQxBC^ufh~AHd^;i78U8I%eF@+ml~|6errdPFpA-1;)@sxJ^6&tH4Y;&gvID0Ph)dyE0Y2bx z*LDF6QO5^>qCV_+ng%#RT6`)jpkm4!0y8cgeymcjp80c?0?}eKnHkxoIO6LD5UZi0`nS%oY)5t_$GpEudb!PxA*SE z{i%4eC>*o87ENb;z3=+Pl51DbZ_-j!+qbcTm*2p`#0sOan@jMtuTE|oR-*hy48r7k zMNA_B0Up|UBzIS%=Zwe!#uQWlln+Fat7^uQqg*G#MJmTz#eaM-4NC}%L{234zM7~T=R+_OV0+}8Nha4o*jx}b1?9}wg3S3vW_rp)=927mz zh|IwecHP1s_ZSE%(s)0j7N%n$>)1FGA*6lW8m2w+$co70#niX>6aaJ^%q1iw%u0p^J1>P_0vyRl z=&qlb*0|=Mwl}T5?z>0{K7d=^v@+QQEd;`Mk+uYyFPA4H1dLz@p5UiKk- zvSud0UuRhtmCs0rX)0Na8O(_gZ9b6ML!RI8PK&f_@Yy@DDisP>=d|$MU4HXd`+753 z8}V@-;td7*YHfr&;!%Uwm83Hb82kP&f7SHvYF_s?SlXXt=<$mN{e;Z*d>)ajCF&)K zsKiFFw%c&fu=&9nOs!Fyk*6*}g%y=j@0Zut_gt#S)ir=YYJ=};JZ2OwnxvtdLFn1d zd7`c^ako69^2%`s%B-`&q8JeW#e|fG+@Ite4t(z$gON=E7cA*`oWF%HZuX7J3-Qp< z(2|mpg1W@xb!cb4k4&V!;D1a8cJbS@aMr4QFwubERjzk(2*>b(^r>e1nvoRVf16iv z`q`KLhiUi9w);}{c#XB+_Uvf5ifElj01$DLNphF$DwLco25T)%F>cLmx-C<2FON6h z!RmrY0dIKwzL-#&dPm&U5^suAbo^P<%IK?fp#d{g@I4yUht=ITm!OR1c~-F{$-gIy zQqQUCs?J<(3t}e!jdairLcn4-Mt(TFxj0n$LPU8l1MR-pa%#WmZQ_~Le!30yn>H+G zBWNU1Wh!PrA#RD=;aIrDf}dfrXZqcwtt;^qmF3{D&orlLC@ZN%J{R96vli`k*k0aM zrFg;tQ=G)JBm5+lsXWpXzxG1>YhBF_k=0i|TTry$_59Uou%wIHl(2{lmtT%{`d9f$ob#FVpRhvsLok_~ZYum2q97|KxhfZ1DDua#3lJXbZ!Yb= zpxIbls|1Ic32wn4?eM*92mNrr0?r>x>5Z#g5Uf>BQB+Z>>Rjv&cp>KSV@C^UJiW`r(VakdOaxqcfL&4T-ai)RXRS=Rv)A zDBfmjd%kpf04RC5(k;OKj<27!*SLE!$o)s5^KYxDB*M7vK;h+B4b@7i8|X9(;;7x+ zAr@L97*guO%KCbDG}P}hMX(CQ=3Ue6w5K3fxG~Gx>9VcksivkA!&|7gvJA8$vouz~ zP;N0J8L>Yd1QhJG3ygp=Qyrty@wz_ZO&mPm(dYcXt!fsZRG-+cTzBK%q?f&`tLxLJ zgydz2-BF8j`>7$&yI$K+xKgMom|goH|0K&303+^zg?7X)oCDO9w>Rt^I@SB2-rlF4 z*P=F7@21aipV^Omb2R_xcB zy=M5j6X9BimM#J}rk0o&qsuvZb2QS%Pl%+VQOm0jV>oC=CkLoR~=i!R?xo%jf9;y(< zG~y6-d4JUmtQ?`u;e7-%tKO^nR5d?#>1}T1HG=h$BMiu@Q{7E7V|%yE=5J2XQrN*K zgYn1TyS{F*`9pN+0+S&i?Em zJ|81ecQmoCmNoGG`*&bE2&}b(m6CmS86n7UUZs6kwTt8`IXiZ>yMlK!f)4Yqo=DS8 zpcz8_YZay{J@(mz>++C*hI%veE&B(a6fvw(InVULx@)sfWM168mY*kxl3beVcZwss z7_j2-tRx0ZXJk5nS!Rl4?U^(3@a<~%q^n$HKe5lH0ewb-ZXXiK#5oWT3=RggpZR)$ z?`QCLT37Z9pl<=DPMJqWf|s3FJJzM#=o2Hl*Na>M=`RHV%xO=k#k*&jK^yfqalSye zPGL`$>WA!GYKe0#hl2j3mb=ZJOk@BcXx0=6d?|SnOBsPboqQM=agwFVk1w>C%8b@Q zP#r}ZVR-hbgG5iB{p*;TUP7MSbq!%K;k1R`5FevQ0Pf{MWMs>Ve?tMvjW_)J!;SUt zJq)S~^c!-iLM`-&Uv(N1luJL8o9BL)eC@Vev*Xna<4v6|z3ag^5xOaX z)dtA`??-IGG~M(OhB3{qv#1ODrR#Sf?ohYd>Gg+}>^+Rn>IzR4)_vJdPA2R6x=!y( z=V|~1H&Rc?2LGFv7i0~_`KsNoWiT#Yl=Lwf;b7pb6Y^G92BdI zUZ5oVOHwFn+YD|m%jX=ru_z0Z-IqI91XtUJ=}<)8NJ@o(J`2#4LkYYmzgoP7*FP{5!j$Qs`NDDva2oPpbmLHYmff?*XBo7e=J-&& z(jf_NZ=OY}O68bdOm;gdY^wwKo?bx`&Vh|pU8%PHgvN|`&?>4-)=T#6U;ZY~0HZns z^Ek5w&h5EA~r&fT7+|y9$M{WJ1uP?(URSRE%a> z5gmkg_WeRL{sU&j4PbMS<{9a&$;~+JD;pStO`%+SII-Xll|Z+(?-f2ryB5hlfdXH% z?r?E+bakalU4PU1-i;gUmRDCH>SH_M`2q+E{Xx_(EJAYPSrBg30up=4GXi8rPNJsN zX80Wn1v^|wQ-J~NZS#OS?iqFcI_}WE!eD}HtBX{GN98VmVR=LJuO;wJzDzQ zO|qX~Whco-SbHgGI}+Hw1L5dudPi75OzKYuOSvvE{6@wLv6u~FXT)#c%a;sGZaubl zgV?l>E5+OD+fM2H+UXfF`XjXbKPZ=EFZ9pK{&mpMd2opgAB3dASLF&@y0ZF8M*|Mo ziA6($cx{@=0{5=d^|}a^r-*B3`%9W;F7Zc%@*XX8n1eO-<1&S$V-IH*)V}Am$Ht>J z&l1XSNDHb9kQ`k!WH_O6!WL}JE)l4j#Pn)pvyQd}X}v-M5Wh#rT%mb<9ym+v zi@UYD7}zzsz(r_`d2azbh2sAUp+4+R>XAD2WpU@09aVc$OBhQfth52>fV!|nPL0qe z3djJc7 zl4@Og-&U;9d+w1!*J4DDnyW^>X#rERhQnJO=`3<}Zgu)4t(*5-rMseTwcb|0p?T3f z^z0)>B8NKSZ;7XDeF-1NUHh2p5sYurFA#PoymcNr^#xsCSXjtf?Os&0KC8^H!f-I82$i>QPu{TW~bh-huS5fUsN=i50v|0)> zQIblrbccJ*;3p*Z8d~R^zPrREb;MH4zpOCkjtQM_#~;HgjaFHmswSk9c`j1}qLJcF zf6^1;4``|=C@4U8wUlA*15^IQ&2>kX%H%H73p1qA=Fg4Nyy49@GG&`vwp^j(MaL)q zqGg2lH7V?n3r{V_V=8Cljncx;)i+Q=s%vwE=N3N@=-EY^_Z0sm7)p1cNO@|y%(LCp zjUlo;x;bbjV8IjgcZ#*DCB}jTedsE{sj91okVQ5gBSewFU&(-H9?I`NS!0K?F;P+`xBM1_s`~ z;)_SBLj6as`}muaZzban&MOQ@aQf1zJl=s*0a8ry=yUNzu;~2$Neg-#sxZiZ1H&KV zH(4LJGg}6nJgnc(EV~u|X=<}B@v?(>qEUg!+0#Ii4LCvw2}QThkq3MQMZnjuFAZ>v z5_YAmC^9)4PUba6mv^6=)ijQ+i;hZW+gbO;xhr0rI`T&nUs$x#<%+g`r_b#4#ekRo zwaT+PQ7KySh!Rqn=VF>A8YVzl#tu03RKlnE3cN-J)V*u@A4O_F7&!yWuXWoUz>i*Ts)tcz4&U zdT6l${0BQoe*HhIc#$e|xa4(dckEW?ak6D{cMw|+(4bQWf`J*}O}uLS32DQ9FblnG z2Zp)`y?2S9S2{z6o{0AxbrSg>Y2b3o5iDY!jiIL6-eTfXv~eAXBExo=lQDOkblm|j zV)petU@q$9HD&YbYm_YahMT8xqEjL{@L_LTd=g-J{e<{kIh(CM5q z!>c|n;J54je&AI{UPKTF1)qF`8)0{(;=~S=#KyO8@jm|`C#MlAeo-dJ>0VBvfOW_B zWlUWDTD7oXlLE(4uaIm$d5Tg+#6eF_Bp-ZlWpQb#a`zKZQ@bQ$_X7ul^+8&n%NI?% zPn>U#b(`c@f+f!;KVNpaT=R3nfuv{Y3m~Y1rk6#^QxFD&19Nz%3IpMI(8Lt!a9yTu zzn=oKdEyZbgof$h>V~C+lvw`>$(T^XXqvHKC%g(j{bhgubN}LwyW|(+Cx$p(qiZP0 z$iQF#(k31CzmRwL4#yTj?k05HHJG9SW38C|e89^cYNFJB=hy2gva_T52tTNYLJGop zFja6|{T{_Sy=Q5pr;J>o9(abh&9BMQE%svcbe?pZp-@TEnaNEW8_p!0vI62k@1bSUmw!>ms7Oe$_Rb_UJJ5JqF zB88JKFQaXtlf)o}x@+z>FP+>SlcjHr8jvCT`9`PG_2`WHWqucm2@E6_i{g+gG}^L*a6Gu@xqJ9)`12Mtd=;d^NOUU^Uf zwU4y4^x6y2?{?)=>oh?Po9+hO_ynjM9om?B2%=A8Xzz!dO}%U?53de_^zvw$b~Sh~ z65JKFnD^~WkK140&epX%iJdP7x$*MqqviQto1LoGDPCMz0gZEUS9Mk9j9AXDI@-|7 zv@5lxXmk1+x%mi!hZLF^4R-2W!RoTBE7+`C_Q=EXf-D$1=x9XvPyDHU-<+eVzXoX<}El4_suY#N;hcnhC@E9osL1NHJ;f zcxHXL^W?ORiC6OW!o_tOScn+~M3L)vlRqmR+!+FBcoI#R2A$0Ea$;^E`L7HD9(R!m zt{+aSOQ0lo^69q3^;2XYdh9O2nQosuH<&+3((|Oh;<_=nFdv-TS9()}Q1E$5a(c)5 zWQ~mmr@bF|c!T275`6X%M3y=n@Kc^ZdnlRv*S+~sElWq4i;g_NTRM4sRZFNxD+kj7 z3&Y`%ckrWiM?286hx=~-3sJEf7s#?>?Zkgyr6;$;$om5qo0TaeR~$VaHwhgyculRc z7KQobqaM?f+=iC&lI0_eHp}+J9I8D%Z@rC;%Xh5M{B>H~-yP34>_;h3XZhj4$#iqn z(lYANHcK_kIV7^InCoW7%I{gE6Iu3qW|;nc6LC1v$y_+OE_(y9{e5X9%|8@X#_g5o zkN5Fd75K%ljF8|=SA8Rb8n^XHAdoi$bv)6ic&-N9nf5pfnCR3 zS;&EXoev&=INV-7MB4a+Jc#Z3r`?c@mf?& zOw4Ige~{{CHXl;$?Cx&?eKZYXdz8w(!i=~ducLTRImojqGZ&78w$D?Iy$Ng z9@|Qsxy79$8%#`#99(jPpxH$`_l$KK(y@9;|<)jFN``QLD;wq4l;sTzl*$9>vooicbqd2-Vo zT=WkPPE!3`~{?#xIjv&T!!mgadpM{mRJo@1c=d5dEw?b~FimQ|Kh^$NV zf@+Vg^uk**wY^-Fv?=S--Vt=~eWVeVD~Pet!~uaoJbijs6Xrh#_m{lMA7y@z?mYGd zx1i?!nh?}{gPvN;K?1M)O%!n_2lE;At5wk3j;ER7fxDJs#0%{Z%WPAYvkF+GkxX9i zM@+osu*YkaSOkau(L0#i4(mj6Ye;C_J~Bdt)VsSjiT~GWf(%x=j%(ln)CpdqLP7yw zWZ(Pp{3^GCgDpb`vk3GOFX^o&s3tlU3`+n`+DsGGcevMB`Yf1U3x(4R z2xyb^q#HDY=O#4gw{NCjFas`)t~Ta}C>rLri(Cnk9k&Ilj;JUB#u24?NN6hIMO?Wx?=lBz^ z}W@S|^H{kId za$?i~w@B(Cs3^bnl{ys=P#t133$0-m|Coy`_=O zGu#f*q9K+?$29Ad3WPg(N3LwwQdh4W$*o+jG2+>cRy({*9W?i~J4?gb(NQfQsLcta zX~UrQf|eB59%~ULjYoH`UjcO6F=)G9)qoqd%t+2sX?gU9f@b_Ep#U*kCePpG_xus2 zx#oAX>9TFfadgrhikX;yTTN8)Zf&*lIV#8wHajX9vP+#vk0V-usy8x_Uug>4T5w$& z1T|}imXxSJ$(WbEnh5lV(8-l|PIV^pcP(TUy4BUCoTlv29)?6}*A^7lRAdn_2@iF1 zcg!6I7`K@}8J+XEKr7>)kWK1wJiExWP*EXPK`kilA{^go#t+tASda>g&bMe^Kenu! zTHikS&_S{H^`0CCBZ2>NjijesJ`u!+%hQ#EwnC9pE38Ej>RT=UWopy9kQxhc9cJ{a ztE-E?s;|B1H3G7$7OX!o>xSIBgpXTu$%C8YKs}p!QW|kq+`IR%(=P{wkMB9Zi|z+&!Aj8bJ^ET<6XtKLUn6NGhz>3>%?D zNsk)yVOS|~m1HgtC!I{YXSw0B1ZaFt3MqLs3~P=mgp*u^UR6tL`_c`DA@ivZ90_+q zGRRY&5@T0hd%t+`qV$!=Y`NXUbIo=)jl@2TGtD!961+d@G}80!!Yj%j4WV9>824dS?j6z{ps7qC{q4TF-*<{7Iz?#NloB;KrqYj&$p9K(4~n+qxD7rR`r*L$q_@VW6EMv_FHI*GVp3A!KACT&O$)N~4?}A17yUgL=7kJc4R5Q)n)0ACg)V`qi45C~QBx&Mz*`fo6U1-~q3t zWRcPg@!)K1)?)v?tKRyO?vt-DYxo7`qmCu&Q$#wfMacT$TPw6%2a-ct{dmI2RancI z(x)6ykSi>fNZRCH(xjESC$yXu@%veupwL_>wjh!#5aW^G%`P~EbxEtN5bu`SOXx-m z7{SZ@_H18*n#dYdvtm#4)--Q~BW_#X_HVN2MsM@$7LTrIJW9W=BsY$RV^?EnWsshx zC+Ck{;v0B$E0;g6F?uO#9vX1b4F)6+@-(NjA_s|6OIuTkmI{?F%FH~WYPQm${YW5w z7CP--V}xqQhz!G~pgzYR9k-}W;Mf*hq}k(>$05CDUR$ySi0NSdx4W~$U^R%Pq@rr2 z$a!Ay{61(25i28nGy0j&h?5nvRHUPl5X+VHHlq|$raCjV_~{Y!j54y>Ux@E~$hR4X z6|O@6dQXl3xe>M)@{oF+?hw}tHNpgXJU(~go=l0OnrgtS9p}w^EtQ=}G znCx10g_*+Y4K$M5-xEE%3(zWFdQ1mu{W%F8BtDzRaEWnLpL_f2q z9v;=?lc^D4dEW|ysz5^Q;n@)d6L<*mnH9l7&17v(A5tGT#ZTO&nZ~!j7GEcOu0{Zb zlh7!narjaP$f^;nz7RcJ*P%&Z!Zl?b1#yr4PGBbwv9QMuvnk+|c`st!W~(u8NKX(0 z`E7i)9$OZc(q{AL$&)1|RAJ0p7Ckvd)&~tQ=DT5Aml0FAFARYxS78}bd*8=jhPDeC+pe0lsbTV4(8&Xr5!plM@NZGBb>HC;|t zp0opIcbtdX8u>W!mbdLG#R`rc=CL@K&cy8UW|A;`dh0Kr8^5!CQ^n_e}6Yn8HT7E`d<+xW7r<*hBgXEh>PIZ-=fJ#SLt z=w0&0-qsToBI7DvUR5~R8mU?u5Z^yT-`^g#wF4nt)TUQSLC@X7AUyAqVlN#A03cE4 z-ZK1$xgU(}WOc`vrwWQDD<&Yjz;59Kjk4RT)4Glr z*AaP*exvfD6F6}zV(IN-)1g&_!9|&P$BA?_7$gIUGn9J8WX)r#{>^9u8A&q6HYkC&5mJ`#*2?)L=; zXRd`!Ku;?c7(cA(BG|QH7yZYk$@{PLRt^xcDbT*-zWm{-N5fC;TeOZR0G%eiAN8-s zZPisGu?wIwM>H(8LvD4YUi$$_eBOpjzY_4=+4A(6r^eh&8~}20t&*Z89~`5hyU4}D zX(XaiOPu{`w)AMU@AxCi=yeod>T4=k)UhN;gErkrD;ROqGES>pWhNdN%L0r*+;6Ye;_$0C(Y5^Tz3|I`)6|IHhb{cncxLL6J0o4*uuE@pc#@!vj?GS#YpJb ztuHtoBs)kPUQRY5$V2mIu5=k-gC0lbSZIzS4~5K2mu)phk;P7^=36A}#8W=EP@A_% zU{oPFX?YV3-N`Ip_*QdJQnyJM*rWh}9~srFq9v1ueQuJ}F+Wwg*66t-+s!bPB~lQk z(}Yk*x!)#%gS6_i#4*lUI=}TG$FN&}H6Yx1d(tiZ82o-)>Ea#q>RvSjmFYN6r&0}n z#0IethFC%h4U*5F{)0*0kRs*%kkcco*I=7;2~F z{`sm?*~gEK4|A5~u_;6nHXb88)gcrqcOm7c{*v#G`jA`gET}su=jbe^0yQhabA#jf z9rbux8M2I5CzsiW^;2_2MI~IQ(z{l}hXb{mKloJhb^^#~3O}@-{|tDp00HKr14#Ib zAL3xJ@c82gQgK@HEGEmU3A>U}Py29YQK4#ZW_#|BM=3;%NBnhpLCZrjci;|GP&)6j zx*PRSjw#0RBR{;VX5gV_KeFB+bIYgk*_=C&mQhuQZIKklFYuDKd7{pnL1jGCBjU>q-< zi~`l1ZM0!vE%I!!^@S*tTY{8}oh>NT&g?SLinyR`hV9m!S}gqFO4FyoHsqf8t{3E+aSo@S;pmamlZ? zaFuS3uq9u8^#RJQXe=Vyvcc@!Yx6Vh4DTvG_T5jR2NmA@{0@_)3$taG->y3(nN525 z#%n0T=^eP={Ly)$pQZM!K5u>2)-DIN_t`1Y+2lb`mSC_XKq6o>H%p3TnWq96SODak zeO1#`rd{rupMB}pTT!4rGo~GZbatQqN-_(I(Irj+N30K9)agl$r1J}BS3h2OU(U+N zc$YYBF-Z!n{-T(K4#Kt|*+C=E2S;;8No!>5oN0fd7AnGo(_d%REc)>I@G?hoZhb`= zc|IB=HtN&8#xTfavt zGa%S-Z{GP^aG~sxPZPh!eauew|8gara;Ua#30+Wo_?YKvHuPQTY*hZI0{xpuRfFUy z@7pliR&fSp;UjFuC2UC8@kRp}lyt8zl61OTmyE&Mg=jY%&k&C5U{`6?VKJw-IMnl> z+eN4Zxd{Tdkg?&zay1SSpCy;^nVIFZPj+6WI#onFuU0uhgX>$CHGwC%Ab@m5 zQ|$ZVrS2Oct8JKMmYgE{soE#Ec2?G_2LC}wQCGQ1SO_OjGTbCwRJsf8uelt-I|e9~ z8p?y46xjd2e=zMH0;=8^$IWGKgR_&>O!JT_!bt%1%-j`S-k3jWu zwZJ>Xh%F#v!$)fi412(ul?P?C(C6$15CV@bU1e@N0^>~Wix1+(HB5nU&|EtzJR>;} zb<9m7%b;t$=zOW2y#$`XLjKf843z0E=sAja<0vg2k_XUA%5hhsM6vB#Ipyz9+pAq+ z>9DXbfy|fk+sJ1+t&y8ib+=zXdu44;i3*R1sKp&FH-#$LqcNU?wJKB4nVlz{Q=+YR ziQW;09lToSl=>0CpNY%Obd==dKV-GcD>AsMam3??d2ey- z#cy$2BOxx{z!*Ds*GAl3M@8F3Eu$Ouf9*Ba#FeB_Q*LlL=Zq0c_ga@u4B}TATlNG!B$i?qIM9K# z{bFn%9UQT<#+cpJznCn4fvpfgTm9zS2fe52UAP8pIHB>#yB{mIjZLgkwBUee-3bfU zG>{9Qg%I{&#F++1n9Iq1QVOe?dF-Xgdo8u|io)B_hWB-1({r1iFjah1ta0%%e>sEzSBhAOw9xA~g;&se56Q4liCj(d0Vtmi8cL z&W<9~oMVIdvoksPcEtGkU!G!pJb1nptp+b9Fio{i3d@v}Ubhyq;AfVR4StaJ`o|k4 zRV!;_Nj@J)F`51YYwKo(jN>QmVI>VAnL~~H+*cRW2ZJ9cYs=PhwSXoNK=2ph#M_1Ht227N1tmSal{A=-9)v|ZMq*L>NH^N=g(vznsS~! zdsZkNm!167qxnhdkomRj>p5pM)Cs84G4$iMrF`0vQ0D4^_41K&>&N1foMV;A56|d9 z@u0noZlHm^6}~wl-A>$(%N*J*W~FD462j(4(u__`@vJHhbbTyl?ND<0%ePzrD-^K= zUwz!8Id}9@@@TDU{c*l)gnMpz^Ei+SFK^Q4a?`MbFHb#wgqN-Hy0Jp8G?O;@@io^{ zG?wBzba>1k<&*zp#`JKUx6!&Z?y$hIc0q9_OIZ#`5d9F9W1$e+h}_L)Y@yJESr_R> z#hF`XMO0~hU`6{bO)+rWqyr%P*CYvi2~T4o=>f^XMPl!R*E@s6v-CVQJAL3VYD=O- z#Ko<}wcSA_t;EVYQG#vBvwTk|b;plf(;a zcl@LF_n~C~|0riZBepiNG_!QkNwYC0TkVuy_87h9B1sEojQRFXlmUhZ{<7!&ZEclS zxKNHkfwW@ch=*-gsu z>srrg^ilfv7PX~cu>8}};PoT?3r=LnL4 zCx&Fc&b{))oKP?mLtiENT*QpntOn&Z=n+c{3={v4ZLQ<`o#d_g9WqN%C`s;15 zmUD+)ABT3WPjy-2$q4ixh9MX2!)bja2gje1KB5xYWlAp>FvK$?Dj;%S)j7Oo`hF2f zHo&4g7?HCVP1F0Gc1OJf$E7^g!c~4CXPq^I)`?% ztgl>wYLj|)O_IXt7NydO7<2cFP0bA4cWNQWoXB*+PSXEmo?Tv=d$fTh%XRVRY3nu#HcC0zBFx8pA)2dP|K-oVU-)>D5OOMo_lnLTr~Dp_v*CpC%7;-zd*L#=q~F;evl~P7N(IyBI09YKCuZX z6s}sh$pTpvp(g-y2cA^uA0<01IYUC&Pj7jci~Pn$J?FCt#@;Tw+U6r(`GT&~W&Bcu z3jVly7t`RZ6bpzF08Ir<1%P>^KB(seW8zi4?0uOv6laP83m^=9{(MUlD3>|`su&nK z#(*0yy?;^e8sD!Q4~wX4o^hx!0Cyjpipvxl8a`YrccrQ85eVc_KdEsTXU>;tvamOl zpqIRwU#;@MYq`2j{t91MBoIG#+CG_)$2j@@(ibuzeMt}3%MsI>L`_Ppz{adtO-Dce- zfz)1ldisWJuEW9;FuCy=un8Oxuc{_0K?GYW703CmOmI-7)VU3ofXEpZ)q35hXdb>Q z(=hMoL2*!UnnQcsLXx*sJO1az0x019EC0ch%PVElhj`rfa&n8!V5{|$)xq&r?nhgC z_@+mt1(K{ru{q0R3PcO?=P!pdsKzeIlMa4pVA1Lhkd6+^>=>YV*beAt>#1;i{fDq6 z9ils!?*lYfqTX3QCLc6feXCTu=$`9(7$g7M{)c_{huCW#=H?|ynV}*DIuJn~9fJ%p z+Z}az=@eMbu+H)ulhw`VZO5}u{`&XMqDn=O^f=mCR&_lZe4FFsU7ED4&3^0Z`H(A=O^kUxU=29e))AEqD9m~DntWEbid z)p!osiPWz7k!!EOeehDiI1k+qmL2lBg|mhiG=?Pom{>8c+4pwXXk=V6t)n%(6ra|x zE^0+n#ahSrM9-%0rWl!I#~L|^@9gaMs^(ap+@xX z=i%m4wnNxDwWXODM@Ee@L1cQdz2P3a*j90>L_-LfC6$Rvv5il0F8nzHxh<%5h)lh}Bl0Jv$%{=p0uY z+4C|`1~up)U$>gweAD_YoHLz1^nT6ZsPn3Yk5u&CYkK}gWx2Wph7~w+tbx|Yllp0Z zMQeqOiMQ^>G?8?GQ42+%QR2Rk;a>R=wioEer^DQ`a-~RWYEpMi4xuU0GoQW%Y9|f4 zJ+h|6)HR*U!G^!d?i_Rr;BPF{<_}aD*w5V5XssMB*Sa$poQEw}Yg%sCfVp$snPXcJ z%XHJt8>%k0Hi$Vq*VngGu1VC&1aSsVVT}mG&LZ{ z&}b(}H#yySu;WZ9NGTl<^)631Nhub;gZe*|eRo`q4;#12DMBeylCsm5R7wjG654xc zXcsN*+YT+EPD(>*FKun4(vtR4p-%fqdw1UJKBp2t&-;E}|NcIY$GOkBukl?MmLQJd z+p(;AI`sL3sHmaDV+aea#PVrkr6n+Dw$`-W_*~Z}?)odA!K1KGVhi?#1V*2J{OZD| zgJm#vF0%7b)u{1yv0}GKVouNkv?`qCcH}{27FSocHSB(p7*^_uI#~!Fic%#!z#@_u zPYTc(VYf(O_EJsZZ>JQEn_>l}Fo!6^o{Ph|JM2{{49|v@PJ#`P!f>w#7V;^!R0?xu zH>hF~;#%p0{ZR$%ygKk~H{jn@NvLGx&i23_K8cZC50}XVus2U)ZjudPM^0iCxl`Fp zeu!Z{BnJK2Rya)wn*#TUav+a=#h z*_J>kNkK}^x&tIr?j0*V$F_U7e@uhy0bLi-!|`>pZbh2i;}>+)DPBuFA8>vVk;Znl zVv;{Dx**No>6pLU5R#h>lIb6)N{ z&^t9IQC+R*O~6&{XJdQznn!%Cq}Uf9nt1$HrfCPc$&sYymd{E}Qu|NxZsE+Phc76))(qr)X-~-B zwR5L>Dw~r^3a;Z_*YVqJ^KcD<@$OOnC^aqX6bBzp)p>QV&8Pf>=R7nBDrVkVbG7V8 z&&}JH#Y7M6=fQbjT)Y*;%r&+D@>N&E>jvYPiy{Gr15_9Blam@nr5<9Q0fWrES8@ss z3XX(wE$T}9CzNd7@XJq`mrvE%&z+8q9}M6{zumjUZ}&xP#CoT7zOp3QESe7hj;#|XJc~Q9>Xw*Y zi0eRlt3^R}Da}jfPGA80Bk=Is-fe6n>zl1C=sS?>Z(^FMf#Yx$=dV*pHj9R@bVQdg zxXCsoG$ExbTFZ~7ISHqrlCU`DTo7+2bHQi3;BKWxpLbtRN{&5WqMykBX}2~07bum^ z7nb(<=Yw26jqSyT1nr`nw1O|Tf`^bm8h?E1F)&1eGTrJeqAi#s_}m>w(f55C59qcj zp7m$0#A6(iue9hTNWOn3X<>T4vM}Z6t8ouD)W8E zYnIZPTvVi66ZK+n{k)9-5FdZ0s!ElSljC&9O+Q)MmhMlm%M{u^*V^sziHW)qW(WEG zD!8r-@6B>1BF#J*GL!`S6TE%hlZG1SRC6+vZ0j3zD#fKB>N{XLENW!#oki?2WohamxA)EMK?9nW4Y`7U~X`P(R zi0S59q&;5pe5h~7wnrax@&2N~qq)tvx%lJ#wS#@Vy!3h<0-#$Bw`X5YW~+xF{@06N z3#}weud6R}bI)Kh!n#>us5ba3Y2OiB#{u`RR581ebcdJe84k2;V%8392)ax_!V-dk$R{(eZ4Z5#b#{WQltL{2uXZEGdX=mb*72J*+q~h%1VXla^rX4 z0j=iR_3RvH$BYz{0tdI^BWq*t^-EK~xfhqUQQ(w~tC=9(MZS~SPdzIJ_UMitd0@6s z%X5gl4e4(_p#??4;0ZGhmP+3uvHL>NK|(L$18L&fc5Yi-pqP_4P;mBh5{)dF&<$hm z2g#KTuLzBH242!s#Ie+7c8V#$^`dAZX2wo!Kl$x-(K_5aii7S+L!cr4k|(A$?n4; zrmoL>KXuJ3KU_QQUINMd*Dq#$Ud%kIMJy>(nvoGUi}`zXG65xin;4qIc}oa~Dsy8w zRvAD*6ZcDd-$MVEjD5;Md!{c}Ebl^shO4{KLt$*-0}LyYG~x~vE71Kj@r|>o)?=PH z)tw%njJQ}OPfx<6n{)m99kC-hH%CI_*e0I}&Z$OS`T}E7Yik_A+D`fBe!Oa;(^2o3 z&b@`YkyJ+>$nFkmOSquFyHt8Il5iQR1?=nci+`J=^YNi^)p28aeNI-Q znK?{V84=-f-Vz`|7wYmer{YmK{3_tAq))!h#d~JHW$|2!Nx@c%V^s|k1Ft}EHV&Im zz%SA!lv*VV2p&1wL+*nULyYxulmZBp92uIJ?Etao;#){W-8hzBiPC%KQ!2>&N3rxv1yZmuC>@`hPE1o zo6X@5Ybl~4(3%KmX!pG~t8Nt0GBGu+Mdr0q3q+f_FZKmRy-367kO)dtbTo&$M^swZO0S^)hOERxA`x{n1|yIej4Rv`Z!UGw5wk7ICntbS@B5YxmUQh zu;ybl(W6=}`(oYU>&68tHQl@Itg9@LG#%Ng>QpKgR8eT(;fb3CGMc;HT4!gf7muo> z!Hb(YTCBchBh#{zw)_0f#ndZod|uPH={|YW?!=R7zHfxii$8f{FGu{P1SZPd@;A>U z@8@j3X(WU6wY;g!8iin)vr5;@e8r>9;`-vlo7T76axe*6_L-Ym&)G66D{dOB(FXMO zTwz;#2QV6)mo8mMfSqlcuZ8SYD>Kslx>FT^r6o&-*fxEGw-%ZF>kFD#Cg_SgcN&nF z{%3)YN?b`~&Jpr5yNPFI@r+hZ^^eN7CfCZ`Je_W2Iy2AB{W`3QmG+>9-Y& z=PzqOb>E%SGn2`l{=M7mOpP*GMg?v@PU-z)v$@&<5sBxn?e|TN<$ibHZugM?IWkh~ zXz}_WS6114L{zTNAxhl%kGm-?tgjKTBz~(>Rx*|%puPpP-4kVE|H z)R%^sITl%1SiW9&v1pg`{@zlLI8sC}F_g;fZJg0Gr#_l;LuFwX`()vu zW2DX822*rEePQ#~bv8{)SN;9l?*b}Q=|3KR-);0!#Z~tR&L2S@9ms*RBHHy%?(Z}k zoL}CpG0J}{O&vtW)4Ze^S26X}TCcEQNnCu#-u;~N_}WLEMRAZBk@(B!tmn~u>RGc9 zF4>?vrB73u3OW8KldSr4eD-3WS%Ol%$dF|@c2oFeG39kzcJ;@ok0apb+PrylKf#2l z312oesl(+b&_HxO1#zH5jo@|^>8;IGdI3{M+<|AZCx-;T%)06{N`bQyRFu^Bf8lDo zM`M}$FaK0O@mU>~RNBz&tVvP#YmY34-)h9zxOP9`3ys#I^p7qdUDS}^lXweA*!`TA zj|+WM4StBM4`?OPUrlJLR-yOBE5mAxZ_er!d;%xV7IW$* z#zaAXf2r^kE9r@0!~1tKH-#G&bPnRrKEt(;otzX*6U@YxUNPU2T!F*2&;$dLGQr}F zQ-1S(8pMK4pHkD`=}?RqNu$5Fhvi)xzUv@v`%=#mqFp;`{LdXQbbWWud_Z@PQ|ah- zXPv&;G<{y=GkbkZP@B1z@#HvT5Z~H4uVsw9zrbZ04$kc~eozrFi9L|TH9hO<-|V4Q zTZRg>_{|nme;@~z|gKS#slp(C=E?wGHR&6xIstTUArzwk) zP4?A(?RbaTe1&yMV;b{Ub=;897eNx@+dtUMvoo^l?{uHNgPVH8AS>8=zkcAO4g79S zy}ELY*}JS8MAK$w)F~gFZ@Vi^+TuX0SRl41LT>NS_D?kC-XK|UKe2~s{n6ufa6&;A z(w~S@d0#FmI2e)Q^7)+UyMp3xMu{DT>Ogp++)~4FqFhS(C#X7+t^$OF^Pwe*m;qHS&B3kw5u zEUbhQWK1;TS?LYiR!X029FhoZ5E!LGo*Fn;^eJP$yt(Zjcv_ISzveQ^4x{=<=hf|1 z0sr^*I>AobUU#d>youIx^CO4t^%=UowjtbU8e~nG;QW0Rguk^S78UOMOO|J4Zl2Jd z!`{)`3(x|DVh?efa=gFWUFNG>=;{O~hfOrnQkRBa@G(jixxqRu-#5*$C3Fb$C3DIk z-=Zee&yQ}uTkk6C=7~OxJ;aBB2+AMaG`5Zv%gw_h?mS^~_3G7S#;rI<%L+ghFgN*M zDA7-amvqDW9^~PPkW2rS+f-t;Z@xU={Wd4DsT*IxCFQ9x-^$^HV+cP3?mb5HKHB0J z{~^R4M9uA#%|x1qwou;vew|6y<>-ql!=tShDmu^?CI^k{Gs7k`&r?1!NoPt>X@o~U z<#0=cWOKV;@dpJi4@=Om@Afr2cY@`zWCw0_De8C#r)N-qepLCnv*GH_!)< zZ01z4R$>4!HOOq*&>u38ffB>Ar^60;sY+DjWZd83^s(%T04MHQAP=;!YQJN?JsFWU zK{dhf_@PipqAnOnCw5UFg~nYHMBV%QWkbmSL)$0RyeWKAD~Q8?_S?7c(KK-vhgs|K z73T*Zbm3UKH_(tD3P~~Wep-B%2HFHZUfv7$TjBZ+(ae3E_4Bp#0XtE@a~HuogXOu3 z*@CEUt_+;aESv|W8Q+8#kZC6*rw$%f@9xie9o=mSf_hJ5)UyGW4UevDbX`=K8^cuM zuW|)w0wMksY>$7x=udqwt$ERt_9QTUVvSEDitjX2JFYCh>p{nfw%GF|qdTm>cVl(Q zGG6X#OSV<0I*D^8%LqlKtVDn3K@d+0TYZJI#)6^`<4*OY))Ux*>p!D}7qQKc$qh?jG0@#K=BLTMQb(*Pa4GCd#&F)Rjj5`lR z@aQL+g5a!juCTFv8_~K|bw;sw#RYNlWKKK&=iuN|PPP3>mGezOP&C3E#VjjL*ok-qIYfa7I8`okJ=WNeMSmiVi?Pg}q zRXHjlQ3%WKj3*x@6;*qCyEk(Sy*-^tY$03fZ}rlOzmp}0zgXxrSP}NuOy{oss1ETy zCxI$PA=(=^{8Xcx^e)8v3+x8I4_ZIaqisD734=yGwY*5nwgZ;V1*TpUL}b)}H=mBt!> zMt7CzG4PZ~H64GVUB?Wr-Rh~6ME3_+d@ENRu5{Sha14!Ug#!+@L$`q_te0q08o+*l z%%;@(c36#oP*6jXhyD?hoUDpVmt{GQ`U~Fev+*!h(4HdrpFoJGQo&t`)00|za&B~= zHIfh&4LWzg%(?5(=RfdbOKL?93Rc-n>@Hah9BEdS(aiG*lN7&mw@+2lrhWg;?$}(N zGJMrd<7GpDYzNv9$yXcV(}C57XzW@Jk5A$2GvZzqaGkqPtqqp*N4`%4PoaBNqer6M zEx{WA=c>8Pzk5kCPn@b*Q}3~J7MRTjgX4{l14|$?jB|b`GxK17{}Bx($DcWU@lLw( z1lOE(bND>qdPR#;On$k#x_%AxbeU=xck@5=De?thsvSfbJY-%^+*G#3-J$#!T6!9X zqNV$g|A%Y{jSfQu>3yNIx5K+6hj zX{Wr})C5maK8ls_Vn_klGS)s1jkrLK+vcm^>RK^`0;+~k7avD8{u+F{O#$BTppK77HWBOL1!dCf^ z@-`|U3yb)_xdh-J5ItB>&q9_HBv!aL?5@WcYNXZyS8LJ`Yv0I%+V#`xnGWaK5AA5{ zDsX9La@UZNkwFmT06o8RO7o00H__mjZ4T1*j=H)C0LZTLs#H;omP7Ta<X}mi2nuz>4_9AO2eW^d@-V{@kYLP{w*^Y$U0YA za>Ol4(%7LQGrLLX9^U@=Y$Qm}{Vzbm49GE@M{SfBwVb{i+w;*rj9oIstZ$`K-XVpI z#2edYvzK1qNi1uWRcE%XsKQU0WiFtqFf&!aVc;kIRIANk>npML&Q7qC<5H6o63p%F z>=Mf0!xXI3r~&_8CfKufvat!*i58~7j%$nEsDqK<`K`tCi6Uw7dirzcy04=@vvW^d z7c`p-)RIwU+tI0Bf2^Gj#)w?p1>3HJ;orEru45T=G2A?V6PJEZD26$Giy3wB{=Jtg)0y7r;~-ZF~MrRF3@TeB&Bm%e-SRW)?Z% zgKA@kL34Unwuz-j#Q!j0kixee6n-sIELauOA0*%jc)yZV|^`yRaV>8Z*@-C-W*MpNE(M&yHs( z(n0zYd&9zsYy#w|kVNMtaN4LbOqO2rxv#J9E{1BCska?J8{6POTcrGXRaI;pn^8>9 zif0Zx0!@^XG?roMuVQ$3SI4gJZ*z%W*+$=N+%L_m;9@La*0;{0`c|U>qQ2GgDn@F@ z^zi#@>bT4)MGr0QZ6CqzgBqvvu*Fv~yjumPD5|kC`~2$c)kJ;SBzdu9`j~S(zpMA@ zAyW0W&(|Ir6&ddcxcoW>`E?^4*f?+y1Vn&?0PCQSfds~x8`yk(%mqpZYu;D9Dz-%ajMkgsoVoGz_@ctPk3Et-mRXzdyvyOwTgWQRG;hM939 zKdnGi*bUz%2)3I%P~}IhoBK6C1y+i@y{d%HQFRcl52!0a2@VOR+NOwiyY!oeYkU^( z_=IZD8B-e$lLAW7u$lyfx!+L?f|pLcdIF|C$G=7KGn6-f)*tc7HW!yL=5;vj{$J9$ zSmB=0M%m}>_|iIt4eQ^$F45=bwpW{av%c3xB%h`7K)^-rFn`>MaK0AlhAW00_dsjj z#q`V4!X?6hSLmSbo+KEl2B}o4qWS=?5i^jy;)F4gHI;1rsw2W?fm!>aZ5hKq#2IO~WvOic_#}Kl{2p^14yp z$?02jJICb5g6G$&fmd4to}d+1W4Ypv?T3mR;re&Qy{|@I`zqc&IsaFBF2qYUm>5p3 zZ>)A0VJH4e$;CboidM|bpK!QxJngh z>v=fa6Kv~)Z5F*OS5kPId%I!m{o#;z0|eyf-KU1t)rIs-OwNtSty{E@Fc6oL*l--h%QNE^6z?GV=K6owuFAqcZcaJ9qgx^n&X;-HL`%K^p3 zQJ8>&j{c$Iu^C%Y@dU8_t>T#!C8>BsKGr=nqL+$f76z%vQE2x zYJJdA?6_kKrAih6O@sM}F7((s<++m-i(;?*0unnw_W4L>op-*CE66~k{K%7RtE!@7W{nZ{9m+@p4jG=&aX;<6b^ah z^bAU#y3;(Q46#1PY=`1!T!X?%OkrTUYw8f|v4v+KvhMJKST;5eev)3@>YQ92UQycL&`orb7TgZKw_;hT_eWXHQPix+l&VO97?jIy?m=6q!SqivRh zOusR)3*A=NAo086$Tv8xQ;0l-z0+hKK0ccte;e{*U>)5~4eEN|vPiRV$sA++abqCf zC7`>U{%ISAJV+3cfDuye*}rtCFZE2{AKlN$vIT6=0s5&-0bJbLYNa+gEIOW1;9n1T zSK++-3#0ZvGsCp_4`9uob2tsCZ557XHxLxE%Cwsr3u9u+9&&y=7|m>=EME`-!N2DX zt}F(3s)n=g%$ru%)s@nhImJ=G9<|2D zz9PQ2S=jj7Pv+T;poc5qT^yQV2~oZheRi==)#2diDPOdngF!DeTV}7kt^t3p!Vk zZwJq6m?5A53ac^Rj151H+OI-FLe9>WF#4VQcup38!~@Okn=G<%90e7vO0r32Zxh72 z4tqDUGsG7-%e=C=NR?k}|H)6I$i4)Pi8>R1b(enN1(*7L>8__=V0}$Fy}efirR}Huf|Z;cl?DXzWQ%tGp-$5Z-wDT9JZ?4UIiu-QfV@+ zjDz+FU#jufduC#mqHDEN^Afr}7aADC;awPz(dN-~dn`C-OjC8n zwr6CK^CP+1D#%YMA46_pZ)K8cd$wxmMFP2rVzL3RSp_a%vcWk7j8Feq_5`;p)9?K) zS;#bBUG~nM_*=5@xOr8w&i(_oSRmG2H=UvaYta_9y5b#>Y5MhjC5$%4L{} z$<;6qFzSMqcNe@S5YriOMfptk?&g_%XI?y9FmJK~M%)fgiopWnMGITsr%m1t2Tk^T z2O(^bX@QsKB#av<%(ks(*;0J;u}JJn;*BS#?PS6_wWOvk(~-kpiP<+LAa!3BhY2z( zDz9gi{T_s6kp=DF?`@#_7i~C!d{%g`jsbSoJKoK_$#z zl#przyxshw!s5$w2kHhglzMtlm zN$&V^iy23qtGrp_D|B+=ZxELS3q_v-B2t+)KPX17a_=fPJPJT=y1J9)@9{$%#*f`) zY97tNCTFv!ImrhJqAw+r{G*I!*(dO(!C6$H;Nt)+M9CH>5ZAoX}PCejX0T(Du!lxtaZB2bgIfZej3g+`h3c+Zp?G^gY z?unMQ@1+BY!&D9FbM}cPkMU?!jDsCy3S#kI7#4|bml>prDd$X^zTzE#0qkbHb@V{A z){=S;?Dk{wz@hteH{_{)0@g%{Tgz?W%{=&PnH} zgrH7F(pF01%jNegGSEXb!!RixPoY9cSQru(AajN$3w!G^_zz0U%6R_ZYh73P+9BX; zYls=7i{nH^)YjhaFfGT2PRoQ%Z<>;%LE${A`QPq+wtLi(m{j>8;myl%w%^c|iOe(m zorYzpXUUE!6)n=85Ei~v=dYC2obol1`u^2S>|1-x_U(Xvlx{ny;GR^JGAcc=K5`V= z0QQ?b=HeET`?P#m)bIW`5seL0xjI;NBPohY+!vns_91E z=sV}-oZQx}E?y>HsulV{8dOx#sOX6}bm*@Z6v#(eo;r5h%Kt^S(t;#^=YmFvxQmeA zIg6QpLCrE(qUirMa8P~6DvJTsyvE&#<;(kd{8{O!GtkfDFHXCmSTh&faR?zsRQZOmV|s9{wRxNKKQ1e-t`M;gXE0jbF%(FY-*``TDHZ-eI(q4X%O~^u(gvp zWFJCEYVlC0z)>{sm8W7ER5=c)$^oqIQOK|P2K@e8@Ow=_I>4JTXCBDN$U?)BMr_l5 zBlj^^8sTxi4wu7PN&uj}mcQ-mlbo+U!*wR9Y__UIr4O({-NIqf)kGIyqXL5iV*=By zvUk~vfI!5jOrO8XjhjM^9@d!L4{5g#uCF|Aw2`KN6BC`_7WI_n>8PeqyX{6!LoYSJ zf*+LLYn|7=xik1HI{&x@$#dGFvHG1w%|qIw2RBUGm_hQdp_sB|D&*zp-dMO=l0PO| zAAfuok8+Yg>H3_Y4UD{6PpIk?J~4#XUSu=w5X6hNUa5B^NBdYJn(cy(dX3>csWXax z~6TjCA1ckPWsKNgQ67P+YHK@fqd)m1m`py8jEe8_6mq^QvXEt-sdbOj6{xmpWf_p zV@&yAQ1Ci0GP2k#Q$<7qjjBXb0Ur~WHzGjP^#zPxRfisEF%hBOinb` zJtHi1X}d5R;A7r&)G&m_r1bW)n}4zgP^s;`~6VV?o@4(I&@CxbFy zf;-jo$PyOJFkgnO5YYH^1kAfioE<&}2|7YKdat=M%YHI!`9hCR7-r-1o8oE`O*t+R zzhft$5Z)P6H3vsL3t$;MgvX6vu+NN*Ce&>|s-rCDf<~whPhcZlG5k#JMYCTW#o;6F zm-pYcrVwF=Trr&7=ELvezJtG|l4_7-t+r!SX6@suDmm2a(=w4QVR!YX*ecq8(hYM` z$z=*1VNK7=5%IGljKNRAVsjGRtw?_aA38HiotEo+dJAM)C@1$3LO4<742A70RNxX} znVRY;H9l4Y;S+C^M$r+$`i~KTP=4Qolz)dir=w*1G6jV(Nx2&oU9YCVQzd4QIwr3sMYpe)&U zS`CuIW?{1NMOMe)5glRFT!S7M{tMNwf~1%g@P0Y)juvPk*oQ$A0yRL9_wI#y;>W@( z44nygf@Esg-Q(R)t>KYDzq8CEzjDOhkisxx@zxkBM5AjFtb^#nJ^da9K`%BP4@&8t z#()G=xNkXu&P5c!nb|Rt+M@S4H1AF#)b~g8K9W*tm~g;8;RZaa7u(^f;ZZnorX;s0W!v-q z<8}Zpu&e3s^EOz%^m7tmKk z%MnsRY&$XW+;Kyh39 z!QS>zn9z3h0S7XGK#9#RfG}hDBB9{-pc6gm&swP9@1`yH%%z}nX=w?*yzZMDy&)ys zexCn9hI^B6Jola;MS@?|s@sCn#)iKLvWYS%(fk<77E_i=l3Ux5XZ)3GtLnwqAf^RZ<7m z20F^DJ!-Iu5Wo?Gf)6bF{5~aVW}|M0$QGxAXY12~<~-Ig7`0ikOZ&d$F9^`l;kmJO zw=w&G_g}1mrKcG$d37a(N7r6@UBS__biNhTR*Z~{Q9muMtdg%B z?iqJtiGsXHJJFDH2Ox;{!}m8`Bh!vzs0sc$q!($fsxjb4rb|mwFNwTP8JJ-U^t4|d zgrlbbg}XQl&Hw~V()@gAGDBG(90+*@he3SH6yq8i8n)~BV}2@spyQo+?^4_Hi;B)ccn34)b3*^%ATtoWQ<+n2 zU9P_^#(0J5<+9QC>LLS!Blj6=>^>b>($`SB-{j(@<}IEk?qb@4UUJd)lQa!FQMj)*g&Lr-8)V5NfQe#4zlh@b0m;{2^G zAE51+TVSCwqu)|hiP;)tA89zg4DIXl!dw9hAOzI?gewn_4+(A~Cc)2KA`ZhX;DU*$ zjm_7Ji$=7c5w$dy*;6YYXh2E(zSym@gQWas4Y-UE78Vu~QX=oniw$0rNlgD}Jvmue zO`k&^L=r=eGip>r{&cEY%ABGZP7qsC4fJHNH9x$VM5_%A`S*hT92V@VO|FZZiL%1+ z!!ItP@V*e&;`UWn>&_=9_q8c|O(NCgCKh+h+H}ZB9~)ykGr)IuP4U<|3Ee_6=<`7` z+tf#E!1iNCtlnoK@2nO=L>i8#Y{Z-65n;6IMEw5DX5{f1r&w<(75yQX0#)-5y``@) z-z&OZp&l9ii{(33_PlK3CIme&0&P8h5VRJoS1(<4$JvNX+!A>>`!GjcU72D|AAXb1 zEY|DcK}BNY5(VEH@fBOkX|CBpk!5Z1@)G*T4tl5(!X3fWb?v!Oigfa{D_{WzZ-K8- zo=Q39M&xMLCulF1!RS}4xuC8S@38CgbGW|ay>#;`q==yU zpsWrv#@oHPFgO?RB9NN znd4uYhR{~0IJwg5E?WNG>Wq$&T3zzh&Z{)~5*PTrpX6|(!Y>Db*6r)EXwj872|gAn zD7xb%x<+9&Z(^8{)k{8?Iw8-ru1>$JQiH7xe%qFs&;^W<9hO$rf&3=WG@_UvB>JwG(e~> zZ5aXYon5U%&(rR#{d>!1H5bJr%5C6EFfdNG^An5E|I|c*Bm#OWQA&{wE8Tv(Q)6j9}l1jiX z+Z^UrK8jU*%bH0u{>SR1$?u9znoLOHq}m_Nk(JmSOAkIySkPIQcZ5L758*&nii#ts z!lYQ`;$=V>wolEvzPfUl*}JrRREbj%BI+6SeZt|!$%?$`;XR8TQdv{W%ikcLl@z=k z@o4k$0IC38Kj3Kg8a5X%QZyFa|j`n%7af~h1_y*ex@y7S6WO6_-ApO{4=el4|5KNf2`K)$>_h>}S z@-E|(yF*IzbW-0_sG!wyu*amjJJ_KSW|5E8>tPT>lU32LX;Ld2)n|@uu;C3g5uRz+ zEyIn~lpd-5sb}%?k%_88JK4WpI)fSPPCv{(v(ay`gh56%LULtW%0yI*U?6=r>D2_l zKcmY1?_S{IM1a{1C!2o-|HP`DYb*_Y&e4uESMaty~;1m9=;17EY)5ueO>OF z4#CK^q6OZL{B;OscL;=<1Nd2f*f9Az;GnRfN18qwltIJvO{0g=vld%qKNoG<&&j_p z;*em`%#0*qIv`;xk^f@DYcEUZM|A!>Iq2|*%qFo^dopjVDqnsJUx?G%Y8oU0YY!R+ z*&qpVkU=Au+~}Hry=+#2&Vdg=2G=)^At$@o4k++|SDd$LDCDtgklwqB+?`*H57NmW zY?Xe8QqEHsC_$%2QjbO){U1Hi_yI!n+x)X9emec?3uK#VYG^>Gh}jELT6zC3bs(x0 z4&{YAK0t!qH2zH9e|CRN$NOU@vOD;Et}Tr{J8VU$j2k74c6iv#hq;?6E?;qJ|6D-` zzF9i4HG3}K8t0w!HL%ih+xUnUvPIuusX3e7eRma-Inh9yJf?Q;lyu%bjZwJev@-gh z``u$p|Ln01Qh88tiuolZtahd^$Lp4)(_YW$noZ>s5z!7CVFdALB<@)&-)Hw7CDTLj ztOF&M+2_aSCk2q`S75$ltXVtv-Z%B>{H@sEr{QODP)caT9Ma5_+J%=pk#^`GfL=Gq zit%^=^b`QjtNtxAJ_IZ-P&ev%^ld|v5mD`Up*kC~V~OoW{8~+4osRIA7?Jl=?q&aa zQoQtT!qjk>d;h$#^%la^2?J!Ta2(=!-?|-VF0k@0$Cnn*NVX`xRo!UYTlGS~`qu*f z{T`v-l%;~cX~NI(l!DP#wlI4wrt`+szJ~Kf`Ld4AF)$w8GfgTphkS24curc4lTH z{_8WJoY*Sx&~+8U|7Yy@{A0=*(3GHq33(qiJk7cEF?uv#cUxa=6;>@*ZCydZgd%=y z-E>FT!KGHsV#1JVyRSRluaAd}+%21JKA=aV&>wv0!OL=T(=;+POI5cmmu@Cg))U@_ zPhrN`q+pH2Q<^1VseZj(zKRIIG5D@=AoQXGF1*j?Sx}&$i{&FV%aKX*i?9}v8Moisa)^6 zex(NL%k+HjX(-C;T}&Z3H!u^**e{3n&u_S0CY`Y>R$1p~>dCFk@|GY_w~*v5sRzr! zAB3zJgo>}i9gs<9Z3tBO&IHGGywr7v^18q<2R(PjtaXK24-QRZ$d-K*N!qnh8~$Zp zv5(swiH<;JWl0w?R#(r>Yh4dG$&(+I&Zx%E<&1r(83e5wo$_fR<~{A>#9ezU>cii< z#wLWVyN=nXe-7FK@Sqw{o<9)Z7YIt%Nx5mTD6F`myBoS3qJyQ{8X7tuQna`*9COv6 z)1qu_#a$Tane^H6`{t<)i($rwRC`a*9N9uIZ!3^A=E#k)wb^Z=j9qvMF9a#oi^BNq zjRgWo@-FK;aT!|NtNrXk9#${HJ>FqmWhvXSoB#8-Deqb-5Mz-)H51Q7@-%B53SpGRQ-Qat`!D zG#x2xyW<70O>pFHr*aLtdaDU8_6Knrli4l4xRi(;JRG`EN5EMZ2?+IEs&JK$f9d=C zI-KH|-IS-b*7b#1g!+>e`TVBVn}H7dq#Gt0H2D6JVU>y;EXUcvg7NGbaMVY4c%Iqk z2Pc-sXW=a1iU4nfkrt9V`FR|C@jzjr1;P<@RG-m$Q)CIrYx#x+=z3}iN%*c)5X{n5pIUbD75BQ-z41= zg}*S>dzN--@2?oPxdz{~@R17-O|ZlQV6o#hr85|Q8l@Pq9kDPpugRTWssByg^p?+JF}=_6U?89p_hnb~foS$xFwvl$4Z2ByTFm(AAaYa$^H6 zs;umHR)}e6T!izPr&?RP+>NtU9!MvlU>g8i|R88CCxJ%jtt;ba;B`4K5a2 z*9+0WDK>>u!otGrRDxexoDI`kv3uVDSodwn*QjdlH&`uP-7QIbfIY@2J<>wYrE$-4 zG=CVFA$Li1lh*k7xz_H{8I)zdH}YWFAi=}tVUYW34a*E3#jL%1cKw1a{?!~lbj34* z`xDN@2Ag9xB4GKh(@I{~0V(XI?zeKJz&idpRJ^^eF3q@x6*aU8=@A$BT&o_}+?Q$| zQ0S_7xtBh7xl8n1Vz!Oa84p=@k)Daf4Gc57TyFb0Q}|BjG{Ig)d{2b-hm59f{;Z9@ zm1|YHl}72U7Y~6{k^+lF17J@=l5Ho@B`EG&MClK8p_odRF}5c$x!jj#<7u7Z0ZmRt-StaOZt^O&^>}z7$grFMvf>p|05R>t-{%Vtx{W!@P@J zTkXqcgNrJ*Wm=_V2_sCO^T%$FgN&ZSIKVs)vgm#YfN4rXuyF1wHB^J>^Ke>h&^Ujq z;zd%pLRcG!{4@AVqhEtzO3fv&>?J}P>`$R6<64~m-^WYP>X#U>BG0!L6nQ~2rsh7p z;L_ehaBj=u84n@-bs%`k$giPa>`tedy{$s`l&9T}1 z2CQfpX4@JA&Lp+=8}b6cPtVG@;kHyX&|;0ZxecpP>CU@N4Jjd4M!Q zRkofykQ_|Gq@MyfsJJe2UF5%*U7^7Ah5a~Pt-w?K#!n7;V3PGF>q@t#T|P_gV2p;J zu6|@JwKHa~QHrDbx&r$Nfq}~xNU1$D?IT`Wa-IoR^Tk$;bmY%Yk1VavP8eC-J}q1m zA`p5wu8?hcGzHpHbqP7aKc~0PSA4^#&@+D8o9XbZW*t};kq_%dK0SY&3pc^yZkJMG zO~Wy4%h^Bhv(8wt1-Fhp)W}w~|GeyQtXKf^{}07{*Y`FqE%EVTaGj7Sp#!lo920{& zf1l&-8Z+=dXNR=&WUczDB$Yl_*0be4MKne2Tm7J5DVgND6@aY~!C;UzLbuh^ZXj>7 z<`D7rna8C)ADf(A>b*396#aObb7gUXK6+tdsLO4naRdf9>&2fV2iOnwaL5};{%(mp zvmTMP1?-mb(w7&{<}H}RwTOdlZWo6nSQEN07EtD@aeuC=>aoeO5DG3gM3lDJ?b-Up z{CCa`)n_j>U6Xi0$t&sddAWA3Sj`nSI0)tRW{OBffc-2Y4wxcc}!#_P!d2eAk!ep11_iF<#|xP-jlKHG)l8AC{;>|eOVpRh!r03#aP zttt2URb}~v!pV|nkivqzoF5D$y!-KpN7wa|l1R~Zal$tlN#^7B3S(-ACwgt?g_?Yq z(+8j$1T4^YrFYt08o2Ll#;4fUx3xA|QM7cSx)wR4H^1)qH`f)bGg=U)4y^OI$%R3a*62L&>%?w zR)7#)qdjYo^rT}89bU+6(;ix>!NE7L-d&Apkb+GFqgL*>@s2NV3_0WLx_vL-t^q3vX=5<P@IuP0*6||8~d?`F+U^-gK3vOlw-##gNNz_6INlG?t+XjZr9w>RF%r z^1Q15VOR#?9#F3P&SX>fSyl;G1Kr9mjR|L!_TiD)?^Nts@ z^s%zm29JBcN`vX~4!-nwrl{-EEif$8v+oNs=8{xcwl|{VypIr$>}RUc)|Lx;wtF!S zpwLyI@b*5xY^2uL*WbrNGr#Db(mVv}8=5kJZCA$(>(F_YuG1tMua)|we>;~E*Rm6{ zu!IHj2OJCkSG8f+xnJYMsx+BC@S)~ZSfI3Y@TIIHdxHDXAtMO?Y9(p|i{0x1+NQg0~r)>2^}d^7 zK1cGnW3Nj}WU9SM|47&3Mysdklp3f35+-Dmo&}kr4J@ zak*mP*EfJz2vT|CBJM4@A7Yvk!X}?Gy4Bs@OiyQtF*vPg4^Exj5JS>Gxh3=Ohe!J# z$v%;g*Mho^p1XzfX%JANc``)2>@GX5QW8S5!j|lQ1T*4~E;fhgZhQZ2*SyB{l(Cv* zUBXYcrT5jgeFx|gCcBw;&5u^{5qkV31s=${+fDQXy)VeazOp)<=@=VoYC-R=!Mg|V zd32b?$*B|48NqQ$w*mD?FW!NiUSgv4hy*Bzn0+q0#ST&{%DNRO@YD0q#^Y}<^@L`2 zzl;I_6uQpetb?1B-bo6(p)dVn)cs0Ks~@#?7h3vV&2f3Q5pO zFiHS^aGIS|+Wbp+!!IA(7r}E-lX=$@9$Og1DI3kP_jczH5)wMJl*`K#}Ut9GBned|4Lweix_B>P?#9zO{ z2`f;(AvtLWVnKdKJ@DX(0=h}OLQ;F`mgPf{`STzx@GAd%_u2kP`p4*7CCP5wjGbdn zJYlJDM_bKcZaz>U~TY!eLs$Eb#q2Qt4^5c z$Wzqq#qIkN|N63fCZ=_ME8XojZYV`ND0-~NuiGt`qRjt~QnV@v78FR%f2X}rT@)Df z(iN{uaBoRpaEZUvCMyXSJeOG+FvTHD6rSRu5R9R^@O_7uHpo~n2!64#do1U{60R?M z$Do1evWub=g#fDV8*oT$ev#Ezrcny9S)=vU-S^p_5S!A3SMy&UtKcyf-WXhhs~KE3 zS@l?s9AaVvv&Q%=I0#A+0Z>z*ZIJ-P3F|LnS5#>~7Y_{JV> zGR@(*OdH6|K<+BekeiF-dPN^hnCzN>#*qE+r8uIXKc_uDoy+>wktxO0J*TvEY4Dq{ zoX7{^sm!lGM`&Hd`icmPFm*YPf6eLcavfdzrpLYAdB~SQ?2oKy$$vIgc%wbrefs87 zch{1o5y7M=6$htQmeonX@Es)dNxt!tIpkMUjZ{MxBSd|br(~H?9iV;qPIT8>3D9LlBO z_i#pANcrH@D_)2Z^DTp3no=^;oeAKO-FM?xm$&YV5PgQH{dCq565v`|V4{by8^mH_ zSX%_M7pZBXJ!S-lUO6z;V3rb!fP+|IaWuX1Nbn0O*W6mvzLSMERLm(&X^y=cC=F<0 z*vdut%?>rG$&C*!OcxOr$h2*+(;UJfmWxYIEMr7wUHFrqg%@mMjr-j;t4Z zArV&V5s390TquOd@|0%thNB~`>H71xZ?k zVmSypu2xnwwq(y1;UsX2z4^sx#D84YECkL&+xB(3OrGeT{t0*MYSs4qdZxNGy!0(x z49C3d1dOZ5&`qQ-g~olnd%W+UG;It5)5J}}FWRl0!y*F8xtCbOpScKIcg}vJHV-F? ziognSx2I?lTim3_8HNUVx=%K$#(%o({ua|pMMw7{Ru06w7UEJ%8nk5z@cc{k>2|$b zm62RLWI&XWtR4g2BbumBLp2ld)otaoR5X(*)fXQYOt@dhAI2v zA&3F!UvH2MOW_%wxiTu)3F9RV1e9R>0-wtEY?W@2e!j)xhYU)RMtCSwXb>bF)a-!#iQ;^j`s{j(Oh_w&g%XEedve&Lr z)H`QVNk#k}G?%GeY(~+4nFbjNMqq%>2$!-FrXxe!sup zZ~mF?<8dDk?|Hq?>zwC#p659SSzgZn|vV9jWxcfbad)9IE5e-02hHwR-|pgcqLi*)MmCLgmQr@GxW5 z%=@dXhPPrJz8bERQ>S5+6bK?uHvMPaihCS{E$@iWQ(yii-0Z*j7fU7PCSDlVO$5yc zXwNKn29`_Eqcp#?pPOt2r)BU=8q^smzPonV9qinD*Va=63Yhc>6Xe7n?q+?^4}FjX zFXCbc+N6Wdb&mX2I-a_`Y%sK~iOk8#d7R#h#udbMGcu7cUKsTFA7HV;{G)KDrl@lb zQ9~x)U$0)hx;mDW_Le~|s(uW#7T++k^ek&}%rzCasMA9OtBxWxaB78hRc>G$Z)$4v zUh<{0JCFMd5@u%_l{~>gT3<}h(chV2LEFCdfd{pBEhE#o@q%_e?=%*nO=`t>(eTf1!ml?zQ@k|@t9xkG7PZa zirPv!2nQ+N$#d7%85AXm{HXg(sas07*80pgCa1f@KmgkCb^UGn)n;T&pFx!1mpvZ6 z+v(zu`OFgyFg!`;Q3Q;JTDaN;s_5EGw~L)29&N_?9;u-(bhDv19+n>&&{}$lCGtFArR}E=JED=*bz~I$h@kC+RrouxX0db9Y)dLg`CF z`p;{sU+#qV#veXVT85TV%;P=$D08$ zE&*cnO<@Z*lZ<@){w^$0_xM{|#iz(im`t~IP0vm8-nDKDyD2A}8;NlRyye5|b&q0T zEnxW&GP6YSE)?%OF!V$-;keQ$qkmh+HVcL0*?=MQE@y1Uh%G;U$DyYDG3Z+0rVe!& zx@4NaZ^;+yZPG&8^~-IOlqyY;33@a5`sdQYKW!j$^AHQj>*!gZRgoY(2ijw`9hpac zm~WzC29t0u3@)lcbW!i!JfKG@v%*RUwrBUTI*t`y_Ap=lQx=61N8QrY(4Zt0A1IiS z5Nk0#UcXP+C$+9TB$$`7w7Lvwn`%sS#3vB>Je&Rch-gk!*vks|+%~^qo_Php>Kc&+ zN>dc=?)AEyLcY+NVo0Fl;}0(n>Jj~h8Fw^u?Y^LzTr9kUnJ4$&Dup*&)Nxaw-KFr} zH&Ck-!nt?;oqXr}v2iB!Pe<|%ws_O!PXTF%=wR{^fJqfJ2#BafCgOc+V3d=Q>Sy0$ zn>SWyqj8f8>Fe+V!_dd0}|FNFE&@W+)MfobtsjbbcGVn}i zO|by-;*6?*3hA*_Gg7tr>vC^TQ7qsx<&`e zSeH{*E-^KM_RT1T*83!r!9xVrx-F~d96g68&}VSJTLxKn@#@Sd2tjNb_vtbaxwtdg z*$&5DDx%Q6E+2A0aRt0?^O6;oA6s_~NA^daL`OWaTJZjD*d^|`Js)+cGD(yJRqVE7 z%6eOPYm=3J4S zZz2`oUB~VF?SHNi|0xLof{zj_GynZ3zvl^~d)AGZu3>t-r-IGW;7aj^71e{VhW*3M z4V@h?S!1UP;!f2`+6i61`0KJAokJFKENRU<*Cw5<+3ux-KV-hh-$n@kN39TAO+n@x z|1b|4r5;{@#?iz6Fw*Lv=q1XZ8?1$6OfnGb6*_JFyXLE;*&Pty935v(sc!Qiz3G~Z zrxA;(ZBtZsd&sW81!R{&K>PTC0t6u)D$N!ni$b}-ao*fw`2OWh2zfzXqEKx(gZhFT z+x_%L&DY^!BV<)I+$W34Na(NnVa{V{cB!uZz9$F$Q=!xYzSEjUZ*mFWkj*5=C=srh z&BV#*7p|YpB!N_T$1cyFJ0ze|*VNf5YjQ$L>MJN;-+Gcdh+4)9+;6d7WYYPKh02Xd z?xxK=bb--^Q4OJlhQXN@rl!2Bnyj&DMwT{>;fdAN0cIC>=6#afspBc-W@)O{G2{** zV{;=6T(Gg-Hdr4c=|+MW&B%*T$4%pA%+Tm#yH_}peEX9N`{t%A`LL^j?Rw#Ra+s74 z{n8{Zy_o@pfa+Ha5BIwJ8h6Ib^$@I=VTOiR4wK@6JTpqO_=bvXNBLmMAF!%CxE93| zL~TTIhPUT1Np9%33*VMY-%IHE_|La1i+ePl{FquXkAJE|i1q#&jm3sviDiwwzM?N% zO!w7DSDU^P0 z>e7(NRJ4S#6xR#!4F@)lPKnGfw!%~a`jY`2WfVqhGi49)u!QPA3^>NC-tu)U{1Ec!&tz5V~b)=_)UX+_0+;^DMPwVKJ-g8nSoqeOlzJ zemmAM$TsIPTZx`%%28IfC~Y;dkJeWl8Fya4yW#ij>)SVo?iqMjcYjj=gXl#!{wL=d zl)nXSI(=c2o#FlRThB?qE6LE53S}f6Bts(^b~cKi*zS&1aG%T*KZVPs&fRLpXT1Ji z+b<`rH}|CqX{Xs2Y347t{{GQwLDJ)4<o!e6_D=E{HXje|Sc2d3BD+f{fOhb`4b05MMO(ajrPbP+ay5Urwt0}dGUNeg$j>Ld{HTXDHguJ`Sgg)&1vrh=Bk%R&UITGt6pVl zQW@@*cV&&G@9OTSOuBXq;x<@sb}D=k{^I3ikKYs`S9)W3MX z{PJ9P7Z&BYmygM54COu>>Cd|jKe`_-j?M#1CSM3jFcf8NxzJdH}^Px6k5h=5ca?)K7< zy|;G^7&o8I;MK}8tA1Z>^#LUNVU^1b$>;S+_KZ^Rbn4=>P~0me*wo z*A4q)(rk8)6|nnQ4Z&x**`IYquna)~;o)J0F?WQleqgH|!dbHbGEEkro|fIC=(;tw zH#+bvbSI%4zA3{ma&=vVHvRB-c|_3K8c=#VI`&T>{w`Wdvc-=x)wF!XQWsVN!$Qu0 z05xK${QdPp_mQR+WU<$;!OD9TP7qA`6^6Qex!c(~FG8KY+``&@%)mdKdBxNOgbO03 zN-ZtEFYJ}%PcF>o@SesRl#h$!mWYjBFY;yx&M?~~ffi}6q1_Pbn8f~QXc}^)he4C(~yeX~V_tjnpt#R};HBFAW zVHMA#q{96%IwB$$-V82~x2X|y#LYrC3R_!sul`|ajJe3y){qx0AsyTzW40sIu2xV) z-2yzr1D>t14mbTf(f0PpVpyflvIB0?i?qg~v+Z;p&1%V=gz z_RkIvs%zD*8d=o9#J#kmvZCV`w11$lx3)Dfjg5cmFz3kSo*sP$wg(GwS7nzSq06Au zW6Rl^$}6m~1&#Giv?#U^eJvwyzOmJs*9kK3r*H?nC|59xF+FUgdYu1aNI@rhD`^THRgO%M79d@fAr|JU2#I`RvPyaJTO( zbcZ28>dFA>3Op8$raA(_M8M-=ZMLA05Uj9TT3YJp=%}iynx3AnrBQp+P>UpFVabSw ztO}uN-IJN50jrMzl|ukOlfBP!fc6o-8b|w6ytDJzeH~b~(7i9-7U#G%_IUHmdyZWL ztE&q5vf>rjGql=_naAySJ5xEH`+|R{xhX@?NIU#S94D`+7_{{(Oi4MI=S`8L-OJu! z-B6t$vHORy3P(9Y3knk9d0uSf@@GsD!^%uI6bya5!+aebo#6QXc)!ikID5lr`&qFE zC=-#|T5+Y7QMI5DQE^f8P^KogXBm{O@9Rhc4cl)b%e`tWuw>kFY(Z68W|Z0 z1ESY<(Uz$G4nyfz3rsmEX=9fCMORC!K5^~->V^+Sn z#kqYK`fS(PqLGgnGDMi_HM2v#yDs80sU*WU>sGI+akAI55ke4*QXd_Ok9XC=dXvM8 z)uZJJ*&)s@O2}N3FUus(b15aqah~S(7H<`DAe}|UsIR5X&%P0>82CiXhh0_^-s@U? zy&MJ}T0mR6@EzS_Dx8UMf}hAt6CXNC;$U z@L8TC&=LqNQ*K8{R4QWhF%cHsLzEk{n)mTOm6x%?X>(~I^Wo)f4aT1W z!g97QouV%EmAp2s%5LAO4o-0`hWhOH=bf%cuz!@K6>? zS?O;!jJ_FSyR&o(NUNkXPJN7(LVG$fZ>Zz9>nS-;Qt#gA zjWODYcnwtqjkl+n7Pt^=o{PZ614$s%4k6qO$Hn%`$xw^EbEks+E!-667Rz9eMMQM; zXZm=2uq&WwD{>^7Q&LmEz2q!>#~<);;00P4wa`AF{;advN2Xy z#@rLe$AiTHy|-syQMj1#ODtAP@EM%vW89Kh5_V>#SgI(fxEEX_@J)M>efz>+yl9Hq zb-?3x64uVKY^=weVV{b!3r~aDQb0AE4i8>V{dMk}GMt3eo@bXN_FpAPG8S%%ifKBgouHH7mVL0`p;00G+3mjKBxz@Gk zo!BvzAHkz05#eEKf=;jX`0)m^!js}b_ifQIl=j=_0C^rVi6{@-4nBQiFw&0jzFHuP zH8cp|<1w-H(+ul$q!-cwV!?&+04@q7xh5$8;u=zKE7|I<&#SLs4{F}l~DLt-{4@)v%{ zgaL;7^V|D@eGpdbE{TYUfZ>@K7`VwOS%x6^q>-R4N=uw}sU}5_NYPDA8&^uoGwGg? z0X(5tROPgv&JlbO2Ws_+zDLBKefwrqF^;gA#=_!T?_jey0%!I9uHgC~|F9ZQ4a9oR z)^$$>o3R$%9xSb^+mW!&Q%Hfe|Aq$V%tpfR&@ZsKAG~&ghEjXRg~M-1~AJES;VA>>2_`3Q=6lq!1uv z0~UpldZr;?`t6JKhuM-_!Q*GpvKsWP=WX=SQ#5cB6Ccr;$v*#+17_haqPCpKxn6>O{%B zv^xFnZpo$Hc5py5qL_V(x1|rxH##rt9fd=3(A=ngCt`kSyI0-)!c`*^6R^Yxh}qH6 z@S`m)Ez8Qv$RQlmb`%#+RKd$B=Qu~YZRw1R& z_7#HHcQ2G(85JThYppJWF>Bv}`3a_`UIIRkrcpI?y=Qf`Gc!c>7Njp2*})cnC8!WC zRTOC{AM9M=d{mx{D7?H!dGa$roEXN+P6yMC$!5l|y^rAr|3JJrK0ZnYZE>%ZX?kO& z5GKA6L+R(`yTi9yH)a)8-}JgbVBpQeb4=;7Z0L!1jDlyBHm!`cCQY89uP=bP{*Y=R zZJs2QXEN=zzTgcpTXjlIB2(o_^Zo z_ZFv?md+LT@mBrjGY}TUFKi*5SqC3)qc6M~-_j)T;lQ-x+TpaF?!SOy^|&#zlEBqB z|6HkiyaT#vpnJ^rlR!Fn8W!AAEZnaur z_LDdt3_D;;KYt9U-la2ITDsw#&c{Lkxq=4N#k03dZnj5D^9TL_9OpX23K=|LLVD=A z`#De4af>lwI)7m|KPh!ZYQBZkvH)>%Kb~AHtVSB`kM{YxddP^uu8f_!~|E; zxFCnyophJlAhHjm(l|Lz0|}9@baY8FvhzVtgNpLeka~2)iUi{FAAi+y=c1PiM^%8lAc+NdX*>gw-3_ccwhQNt8}*utd!S?szu?3Tqw z7*S`qby`vG`&tI{W84Y)=wf-P`N}auK)@FDC}0DiZb`>3cc2Fkd6d|?xMXEwwIRXc zR~8%PsK6-46|~o7syaUU(bHcD&BYEDGQ*nFdrsXV7~HG&{KrExFIuvtAt+vAywmJ1 z)0_!wx#XnuJ7#7_=)te0?Z)!Ai3t(^7<^o8+58+>S4M+ot-hGC$BGe0G=}Pq2=0Ez z7yk49tphZo@4lkGKk}J9ilUcMtNssc`0#G4lBQ{eIdv7Q0v={)oIRY_<9g?4iUeC< zzVp_7&V|mm*HhQ4uq6!Edfm8D;l(}=$rc=%pPwJS!Te0`MpMtpSG2M?G)1-FbFP@$ z{F_NAk{zm=zq6khy%`ra7auJ?f)OUzkO{Q@ILnA{)Tm-bG9MI?kvW=Cny2^J=TGuh z?P}QLhb=5VTA@sHZ!@;wdwO~R+Ue=(NxZVqF8|84sukRE`Pk39I&wL9!|1s~+HVZm zv^59k7B-CfdWB{;pGXTodJOc6iin~jurek@r<&<$3DkoplnBHf9jk*ft$(h9ozi;zC_wj@NFMn^0) zdo2zM?b8URXLD;1^Z5~a-ft^YIG-is!}-0WLD)3UX?g*H;2VDO$bbtIWSEKPCYAkV zT*l4p?AY{Ob1N*_=HaJ77=j2mnsnD2tk7U1Tk&!|+M7b^#8Mp@(o}7@s8;z`ve|I3klxrTrGl1Xrr>t=9dZ&x(#@0m`5{u=K zQW33wgYT?dZq<;#~(vi6;oeSQQwz3SBt@^^EOTyw7&vpPL_Qlm4S4=rn#K+xGL z0%^lhA2G4MGc07}xFj^A;wnWVjM(NOA?@&<_CL4R%4!A=IlxQ;8%MFjYKO&%n?!#y z*;ICZekk;%>ieWVj|D_`7;=AuXkNa`@x=W6z+JndcsPD$`(1GTt#@?#xh>SnEV(b| zARW^)jTqre$#vpTf6oZqw&uD&~Xb^E?B8L7`-tknG?b{;=2xO0p8 z)5%Qi@dp+H<#!&Phu$Vm+Z7Fsil0WMtq1sv)M}6$rX%YFBlymaXceLU(a@n|-te<9x zJ0;IOKCybUtc)HWZIO2g1p3K6KcmI5xEObL!M7a3#L~+AQf^d2{_??}VD&o0Tv37U zUE)5=)YrROaDNbN(~#NWg4IW4=N+Ms2$~*=PYV|cSaR%pOXFX)o*wcDIoSm6C;6`C zp`DoBAB_-ZHbTRzx%V4d42~VqW{pEfyV06yJJSN5HF}1g+v3)8h4qH4(k!RJN*xPI zOI`hH?(LEkZ$KRt!+H7nj{@dllg#J0j}rGF;=c9yliPk-(#U1tEj!Xlr7+i7Q>78s zEXfewT+*zA3?8`(KT#J1Li3a?A{)6j-pPPjQBF?o>51sl zvD2YX4c#V@8;tW`LU3a$0`Z@h*$fsRCx*l~Mr=ENSQDP!1BxS+m#eK%WTK%oIa@QtjuKpJy>}IkuY|5!ad&@$oBN>112}^y##xr>C7=ivB?Kd1$Hx0Co)7 zJGTZ8?4Hu$fg9?8QiC=_ua|ucx&OX`iQu&c|I?DDd3V0kQ|Y`doqy5jeyfr!eV6Di z#cGg`Ru`_g$x!)P&fs+;(4(!eZR$HS-Fo_elWGV(kOxM;e3^fH@DBxEY(&IZAKIpbutPaQBY}noonOm;I#&Aqh z5(IP;V-pjIgOE`yNsR)>Rb5@Z71<{SkKtCM%vHNd<F)GO=|BdR)=s>F552&iB|7K_lGHm>nv53AU>$dXkg{cD&Gwz}TGlJIeV1 zauTZ)ctbpy8X_lp3+TQ1ULBIia4YIEhK_Ou>Vb11?~1K;!gO;`r-8mpF5+ET#Wrea z?rjRmiGKGp+j_f}K*-kugvWg62g|panPluwcr?FyvMINZ+&ks%3OU!+U51?V-@biY zr7sDzJrViQ>JPYgTJO>&xWpdrZk>-b$ytd^8%7dcrYu9hIV7A=w~ziN(Qf{w?5qEl zrVH4#t9kdnJ3tnub68MaJt{)s_=Eh`#%RmlWxbzu_iW{LCh1I@iI3yan+-yzRYM-z zec=1EaP@P*E|ZK*Uk*>$05M2@-5aSTn*1k2{^$<_r;IgSHLq05bJRxY%n&hV{RZzL zEm`5_w}Z>ia@%-!N+;f9{I;{}cw0({(hB%iBKVq*s=p5jOhftzAGkk|-x-30XMM^S z4BysJ>$5-m_S_3>albz0ar<+`GiNcQ>YaOw-b$>V48!SEme#@3ic*ii!%jt1wTabj4No7I1<)6;Hg|F#7GAvGdX? z5V{R}76Mtg&YbzJy}DhLn?np+V~eiu*pYVteXxW3Q>$_C32Osm<02O#m)H*X=WZuQ zF4SCL?GM~t-ny@NB*~LHG~NV4ADctkhopTSZVd62-%p&P7vDCf%)8s!)nC9Kx0_9~ ztb2p&)cs{~S0kaOc5*K;<_$lqYcpLRms!Nu5BO-MU0k=XoJ)SRS2)$ij`l@=X2R3h6L0FKq4KCEs!MxM<0pcm6FYK8 z4ZFPW`0~4pg}+>x-J4{PCL3t@&3?l}5I>TPHI9HeN*{A_V8PfA`(PtO=5h3xKI0wX zX_6c!I-Vh)+@r8qyv4on@y~36wE^WcaDZ<8!2o-9gg$XYF)s0MBQKvAxk?zwq8+DdpJMt+eUR9ds6v?pUYoGpykMvm4enudMw= z!)QAxG8!toAOi4w4~HMP?wL^Z{${~}o_@xJq?@q3Dm6S^w&C|si#+P=8Jr>Eaat?3 zX9%9}T;X}qAjue+jqf@>=PFssIlU{|_w#bu#SepSn=}D~5RauuEVo@dl3+37>YXs2 zD%AJ*V-OTGmq}~y8xVG37a?qL&>R_FCg~gpkFIuiv2$=}0;-UWGYc-Q^> z!BF{-X<-IKb`@4{nx$~FdMl%c_QKuq!t0^+%hnF1`lHc9SuRwzDI0;PA&qNy9j&NR z(#PMuJ5T%glhhID)>wDgGFP54)+8R0#WEZ~6i;MVdz;D7i_|dA4C>S-t(hD7n7Rv& z%KuC&7rTC?mD;K6QK&$Op3O`s1O2>1cpF;Wr@$I*K&zAyh@b8z70>I+65Natk_kM_ zVKb)#eYtb5i&(^df}<+ZUr8D8@BhfkTs%M@3#*D|y1ES0I%IdH-Mj!a!0DK)D-2fQ z0HbRQhUgQ4$VgIff#Z+jhh0n(oQ})do3!0ICFzrc@tonied+B(d*ess3(+zdiur1L zU%1Mn$|(GYM$f(vKWibjXk_GwPikV~mMfm-VLAcO!O>nQwev$!XBJ%zacr**3>|#` ze)d+hWMXQn5@u<-s_Nk)ohB=1Iyy8ERIjn8_>xB09-Ig#J zn^xN1`LX{1MIX0g@Q5qjz6KTZwQQTG7 z-%SC?=hmjCfjy_Jb_AV;wVciSO{yxxoMa8P^b(?;Bx z8m>sm$iSdGn_}Ieo`$u%(c1U~2ABN5d6*rcuSVMH3OG&qNW2!W=YmXEgQgC8Qif2N z;f0^Mn}EPmy}vmS-@ag9GBf$dU{7 z^n&Vo+z`;_q~1=AVrt@}t|XWo`t`?l{_(4BX<%qRn^Jud>abI*n(f9~g`79J7hWJO zv%~~}IoQ9FHntor5AGjQ1O;A#s{6vm0%^K?O<&;zIw)VEvYnnu{QwmQ*SM`U*S{mQ zCKkNw&yTSBzwY?j6_1^r1(tX{vI7>cpFdL|2^Sop6Gu>Vq?3|s#L<7<@EwWU=okIR zC$uyyjzMl`K-iypzF|5`^vboFDO4Eh#t)BNE^+^bhV)Qpf;U)C(o*CmYkps+>9gJc z3bk-#5OI-TNA*A$=1jm&)2gnmanTpTV3Hg@KJ*DO2%<^nY~q9GqoK$5Kzf*j<%b<* z|A9d09#Z-3i9hLIKR&EFuvFVL=z*H-bIBa|*QB;44s%NMnrCLx><`5avL?CtJZ9Aa zRgqaalOHTzP2#t|g6qFdc$qb}mussS*U07U9#J0`C-~P_xRPJL-cc2-n)zN=_qbi^ za6eT<{I9GQ9$WptqBrv2?~r~q{&6#~*i#N~-oLLAacM}5kAGnL`Uxd!op4X~_OtyP z;r=sl=-#GAZk(c@h6@ip#67&sy!N&3`p%ixfMk~G>ow$vzW}|48Pcx@|2?nM>F(uK zq~FV<36}tKx?Y0s_x}U;A2r zsoD`w_nn3g6QP{}=^smnjh?-Ze)PP5`BiE`jGN>a=`qoSk#0nbi2yI%#Mnvc^2T~_ z8u6dTtg2=W)5G@z_})OYP`{UyJZ7;)QhM~bWWng;Wcgg3*O z4R_|NIt0mgAJut!coaUu?~eWiL(ZTqvQ*XX4eUJB#%#j1O-&m^j#$zzBAv@$OCLdC z30`wCE3L2dN`u4KY9`MdyA zz%&J}Aditckat1>>ez#bV9EQpTCghh7>qVd}@iTV*%S0|S5R)=)3nw_@^%#h?um}i*RGY>l zlHR}XiLO_d2r0K%6*%W9|#D)!}}byvzT3 zm%lj|5Z&+Ad-l38H!lqsiE;3`aEN=4BXF-u)y^#HfI&<_>)c)&1^MGY+%EV;S8No4 zD#ITVPM0sb10JxowY9ewoAaoyw>yOE$+B~Dody&i7o9EfQvu0#VTv|%N&st^HkQl$>GZ}-1fQtTs0sTXSKY{>eh1}da$+O2$OW-tua1kcPk ztbX?NR>qOu-H{DE2qSqQC)L(uA}C;>Qh|#O6pWa9I20Tit>aNedN-OE^f}zA*|xDT zDXI2=!tOS$W+zR*lAej|f81B(|L=v>Qo-wehN&Ev#4mKGW38oXrariNl#%)z4aM-LL?z)4;^oxV{XrdOpuj z?%Yw?D=N?4(x=;l>2BK|#pCYknuDIccp6n+?@-}*8IY-c!;KsIBXqgLf4iFXl8OBX z!Hx9Fj}oJt$2Hq$l+z<4dNXaX`U{O(6&N`Q z_eb|iwzjqTO$hOZ%!&A*-ESJEEB>8J_~DBX+seaBpLHzA$^uYPZe$)o*gvYt61$>> z23`I<-23B%`JK2ik?m@ovpsX>OWqMI1xJ&yDL@;F3jB9S_#b*cwKv)*Ywu-!eSnuE z_Wdm_mM2@9dV60L6eS`5)ZYF80w;LGAvcS816_J1VHKq6YhN0!DZP}jM13MqndfYY zGLemMH#u3#Vnrt6qm0lv%CLRoT_&fR2!efadb-4k4@&+8jvvJdGbhfan?#F(flPY4 zG5aMR7HxBX=$(%8b*~_Z5uADE6p_hsp_Mvy3Gqv88J=J6b@x%K>WyCzMp19i{z{|rFCosS^f*vA!LGBctSpnbFc6zaPzsLz3+ZeM*{W$66EAyf zKIK~`gxva0s0lL5a$ofF@;bKHQmu4~X%_PIWTYWbJDHE^*CfL`gg>Ry zyUP~FFn7>KqeV+nddj`a&gE`4ung`RpRRmGgss(>1i7={+OAn8@!O-(R>5=9i==!Z zS?QkMy~$nKTnAkn5vf`dnm>0DnW$r-`pxR(6tVS%cMoK+%J@$c+^5y$F-z$SmKe&J z?Byr&tYki7hQ1fe0o58}rR$e(7`#CG{+Ht;6Zg~RjLe2I`j6Sa8kwA7jq#K&F!U7j z>qqxFa?u^n=2c2f9$D3UC82mFP(B~WMP0B$W5}Ta2d9kt?};FQKmG$5f}S_eMm#KB z=%?@lhD@d~92Y;P)|HN+Wm8Ha`3Tu?d?WE$MjX({3yBSw=?@OPoRd~H%s%P zW$RaFa4zzXUmPwrJA;f(O%b@Uk7-^$g~9T}`>W^YrMkP%O~(vXYRTi0ld~{IIxJ4q zZa-Tg*@}P{;Q6!BY&$2n=g@2u_NI&E6v?~QhVUxZG}YWo@miWIEGXzE|JEAfB~pj@ z^LJyank`hX%ZtJ6$Tsh?XM3A=7PoJU++Hbp;zVgk)AJ~T5@O=xJCa@5h#|0`W!b8& z*b9Lw3pE}u8kbxwB*$qLlQc}PJK@q$-xG_F;RH3rU|~g6@&5$qWp9axo#CAQ8^V}? zibKHz8*aF#AN)_0`cWVlJP)JSn%2=g0&qTzoO>Hw}Ud!`x-+~%eYs9R1(&pY7qoR{6H{8`$j{nIMF_Jh* zdnjwemg2IVGAG-zKjlHst#SXdY^~<9r6o6@%#Tshb-DMG2vt>lLPp#ji8={L&rJH6 z9KHQEp9ebm4WYI+cW`n0Zz#-?gcE#MxFI{>*Q4#X6p&@$X}ix=Tw)V`>89#^ z(~RgcW*hLgpFXGLeO~r;u%Nlsc7_zBY$j&(M|8{u%*k<-RDgK=N~>^#uKXV2rZN)? z3*SxAjaA2Yrt=UI(rB0vL_Yi8GR}+4%)-K%f3P|mn*m7zB~gtkJ??x zhK9B@<%I<5e$V*Q;3zE#VBGeG?wwB?aF0*cul@-FCnIkf1s1AYX5owpscq=>PEKw* zz@hf%Op=VG1;|Clekr-`>lKmUN^x|sBRQ_>~G zg`9JD*)d%akI&|dh2?8@TB~}_&RIFpelIY%WTWj{Y&o)3hLzf1SZ%n18c-3g>ZO>O zn)4>x9pK@)_HD1vhVCJueUiMc7WP@iCNE2aSlxNG(~*HKe%?>3-|mYyFM`Cu7VZ1l zVP4U-hxKKKRZn!;W~7IB*{Z&%o7V=ZOlGdy`&C zqql@1e%swVqizj*PuI&;#Kph>Hr(sijMx)WJ!<9+b9e9Fy)5Gjb1pWK2i+WpJMm{0 zV=Yy$1WUU#5pyM2@Jp%ULiW3t95+*MTnZk#ezLwqSZ;Ooi9!FVkyXHkZ6&eJTLxal6e`kqi^uAVmSMfYvs)vN1C;Lt zWTEZs7P2_-*>Z&hw+Z259HDBZ4OVG974^#UwM9S2;a=j+PY2`-VIq?-@WPP%m?j;UlM{|zA#vlS@DQCmswmNh z({I!fg75F-0n&=2SuitBp?|JvX{E%(qBc%7gqh4}gZ3Q`b|z=cc0$mvol~5Y-Wj8U zBQXaQVC`B@NoLZYQnZ9(sbycWx#&o_ahj1$R0eVy_NJSJSrnVPO|dI=Xqgb)EBX)W zry~|Ic1qhCnA<`;n|gVsBCQlA&5ExeIG$v!u*_i6JEegX??Fl>(#D5wdj z-AI2UxTho9h17X{WTtOnCsk#QZ2K4Iwk8Qr$8WrswGU)^;c5F$^GyVP40_>SL>H%O ziFx^CsxdW{mjk(RiJ_i?CDL8)LKYeUcp&M?p1OyNoh8PTRqvA(@vcf4jxcazqH=6? zN##(2<|~VPH@1}!VM(uEl3ml6Y}Ybx+if_WCooDU8kc;F({?0P)&)2ChU6(gXy|G+j$vu)} zoc-#B!|H04Hv+qP9-|Qj`c+V5*QA!}zq|USJwemE$Z|#$-CGXS-M{@Aq)gDjh&j0z zhys{W`%|6tHu}TJUxFk^K_@|G<8t-vhp*`?T}CM;CnB%e$Gd^hYiT!>UY3{*#)Y+XuXY&N`C6CVMw6)M7DY`Rphpn~s^x2{GyCZ!jRmL{fLk>2l zi6SMWbIE>RNc$a%mzgVOHZ5*+BB7Hk{U@m`<4w1Yq$pNQkj`}85^LTwH{hL~W)^J{ z_S6Aoz@`|h6}=65@OZR>iPsxm4dHRG7`S8nkyJC3Ldh{JN#8^Lh8>uYf-F}p=kb0c z&5YyFlrvWkvIA622QMaXVY@AwkBQuw?vkCB#$gJhLk3@b%ZVaNl8RlYOmG<`zVf^_ z)dzA1-6!Q+R>Q0@`67s%A=12M| zctN}Lxx*pVoh3DriEmknFxIgD}Mg;ME=divpvA4c5RTP)Ap-I(1E^VKZNwxr?8k#dJor@ z1ba^Bb=e~`4i_t^cAmW@zA5d7_!|US+_-!TiP$Z3>Qt3|(882xLT)h=^rlU+iC;Ja zpsfO2#qiZM%8g~m!W{E~0(<*1`cd8wmCUKg%Olrcr$D;=_M0fhd?8h)n2@9 zWocK!jRd_rN3Suj6W>3mDd4{!2>+|{0?K+I)*Zb$t-@oVZv_0d1n8j@#Pn_wlFSch zLqCUYOGk%wUh7rELBUOAq1xp_D>J~{l`4yaY1@+-vn=T25P2v=MOmLe_4Mo!Y+O6n zld*f5yM4X#&52pn##?Q$UHnx@n^pwLMbIqTe)7f5eAy2DWc*Y2Ny_%X@?@>kmQ%jb z-L*Y-+p6Gfi$p90QxN%-0X z-?1ECjBH;4U!H7-!(wYgmw9=bJA$B;RMf0*-ZYO%LCA09-OR`sq|vF?%Zh8o-2NWL zY>(|k6o=hM&i2}ndlakMJd;J4KwAarZOQHRPCViRs@7$N1C$#P^aK8o(zimvQpdzG zd#Xo}-Ua;PBcqKe|K&3NmrAdB{!IKYf)80|_;5oO&s~gj+S9oX>2Z&}5CSIf#K$qY z*#&fjQMuExy=SUCM*aMlO+Az5GJBq~Vf7#V{^2mo4cVwjwz-}xKhoQ7WdZX%@*aqJ zcbTwJTT4jWdpMY@0pKnrdTu^J+Gy|D?-btI*RU!1YrWU?moJ8j$a`cOi};Yul@5?e zTI=ZQj;P4yguAD|_?SK?5y6tABHYo(9GSrf2QAq@WKThN^yOglQ2e|h30j@t+I#oICJb`8F?tZt7 zKf|4prZ{uZv|j33En`3{lI(ejm0XEtL49lZs8Bgm>Iq%}c}5O;g28{12j84{8Q{pu zAGAfUtSY00d_pgud)d+TQo?^%6#iLI$UFmci2EYGeEs@aMk%UpnQxH;#ryv4PoiHB zVW4zX#rIT}vr;vCOv-LeCzW(5ug<^OP5#y#r&@GG6gZdYqLVT*2hBM^SC1p<*<0s5 z*U!$$Ax!q)Vrl+TpPAM8!YJjn;?52`zM!)+I|5xrbIcQ7lF6=%2EhyY?zd67_lz!- zcpq`~OwzDoj2}r!NvY$!w}4H-pIr1tB(l$nG}UDk)%j+ikwWw76TTTf zX@i(J=CD9LX<}`Vcw;W#)t)bA_14)WPMc2t&~qJgz9~LCn|z5ZN*|-1fc7j?COz$T z5%(m^hYy#NU!8|I*w=wT4|W3G;O92gc4(QJ_BSrAs>auLJGy3kwb-IVhG7LrQwDb*f_wyMMZN6J#K@QeTZAc)jg4*TMff`)oB{RnqP!Jy zO^gmEDS!;@HaVwXRVHWq#ONx!Gkfx5GJk8&kc;)fL$<=C;wkrvNu`gR zTV72YAWw+rF9<%X>wV>uW)LKpYg)3|m;Cy8xffLoCM3ja*xA`d5U*RBv5A}=3C8k` zIPmZ{6g$rI@I ztn-a?1}kv6dMwAT();v>^mLy&7fP-0{{5(Oj0GWTD!e&|4`BPD)hflw!Nn+tN-es- zIwvH?v2-*fr+U04%}dhTvYC5CaIGl(tLC&;IAo*)b>LOC|Fb>zj>{e!$2Kd@4lV3AYvJL|a&bzHx+` zuiwdtU$y?vg{f}KXuiUc`A^AS*_2Nzj`G{=g;y4{8gn^jRK_dyowk6bjHoK<&5gBP z{o^*uzN;+`qh8@6e_4&)TX1+p`$Rkv3 zpKeqq`{IZh!UxIsQFBv`l%Pn$Ytb(BlXkJgMl_6}G}x2Jr3+PaJq=RxzRX~xS2uNY zTXXi9oVJ+b5BZJ1k%H!43iT?V9XLNu_OeBz7nO2fDSqG@ckU*fGWisODK1`a;PCkj z@4QLixfOB92>GHjo}|#Hlm_HpXJSW7PEuhL2qMx z1F?Ox)6<}&)?I0S43d}(gF5nW<#tmqcmUl$w_5FU>~g97YiJ1|ryf9}#9Sy-dd6fV zWn|1u50;g1^$S(EvclxR4Kb>sI(}RYa%jKHWj)rK0{GNzBwRV zZrl!y&M`d$J)5OduiC}fM9F}zFW8iFWf%u2m)eBi08TBZoeLmCzDPNVot^zgx7dW1 zDZ4!_Z!w}WDw(Vv?2FH%Z1ntOh>VwH-QNBMLYL)qY{*4&+(G`w3uk>*w2=?cRm|6h`Y0tK`>N+u&e-^0U0&ebyq zVYaz;?d|TNXV>2TRiTu(XlX?ke* z`^%>H5Jjz0_zfB~Pqe+y{{z2&oBU^9BLjmYxqQB&S%~i-?>$?hd*QUG*f*n|KC>V} z{?65z5mNs6Nq+K`e&l*0TU`gQELptm)R}DmC$eYDHBQsagXOt>#bvrB2-KYZ-A7}w zkKL>0qUG6|a7V^_)f+-@f8^{QYI#ENt(IwY^x<~j%F{jbheFSsatgCt_Z*k`;_!dexm}#>i)V2? zy62Z~!-8&Z-giZ6bXm=1PP$6rXdM)Imfi=|u6j63vK3;?ryof7J>2@{{{<2wYr?DN zFCp19a*mB6OeR46u>ThN|Do%uGhELLKJv(9YM`>6z5sWtRyq`qS32hX_WXq& zecNl~zdTN$ZMeH%TBncJ!?NNmbLEGV?fg09e+J{IM!?AuSaC%r#tQQFZiMX+0ocas z9<|dnv#W~>7`r~=DH|tX6!XP^#cCETgA-^cUn>{bvCUuyYaA$ z0N+SNE{~~U5!*4fit|UNzhf5vJ06)V{wuK{Q!~-JmIQC{gZ8%`tA66(;k2R4 zwBx`1a;x_pl?hl`d-IutApREs3>ffoSBk?tIBlY4!5BT|8RpA0@df!E^W|94SeT19 z{P3lT_hRwmtO z|1e@uLd@GM6zC{Dx{BW6Y*N5Nm~&KchvRQqK&R%{5Z5gUcGzxd3xA@dTLC6KH}MHj z`Fi{MRILZ(K?DvHG4u<-WpVOb0sElF-d|2S#OTmJN8L2J4*)}L0A!9`)t@N*keHGA zJ+Vp;(=iI0sil7Sw=$@xy?gv+XEA#07#=_9fxOsz6Ss2k8uLA#HRM=#3$#tm3qU4A_EoUd=AuqsZjr= zi=U{1ADMf(JFTgysnA>4+0jubT4?FgaG3-;-|n6~ol~f%Z}^v*h8h07n(zp5dUjZEoT)+K7S?u+%YT@k~fD-{>#jN}_aD~8-W|*FLjv4b% z1Zb3!{OK+DyC7Jgw02Fu_%wGI>^{BVmAFi5L}ZO9_u>->$C}#G(&qS5__ufa**UPN zPh5!IUoPuGG@j#`qyS9h?$NJjDnWIx6R!3JR3vEY{{RnPW6{vrq+Bb}?y`5nx13_; ze9VLaq`Dvi>RLi?rrg45-gHwp|LiF=vcr+!=~MI`gTU@dq(%?qBJ$3;)9_EtgIF7yr$b-SImnc0l>y!>Iv|;8SeQ2hyGdPY+}X z^#m?6#Z2h-aad<=*Zb!umUy7o<=bs8gnXBnLe9Ro7I64=b)L3aHgJEB!mN@f;~>C0K&k%)N_iYv#m&e8GxyBNP1&6#vX1n_S$gD4{~uWA!fpl)!YmuFENJVCvNvzu zfaB6CSvc6CLM&y{qn840j4df^{PNsBOumPUi;IPY1=N{^z`&I7ZNx!lAtqpOqacgK z$`3DpW=XMAYe({z3-*|(Tf0_&paN6Pr26oSjU*Q5;zz2+w!?m|l?$w0iJXObsr`TC zX2E?g`4X9d#pVe6=C;Bk8AGwL=3dM4vjRrFuwQm3TserI6Vs}QOqQ^;wB+RkSJ(FH zqb(E2RF5iem_# zDzFwD^rwb=%*?!3QSgudL>MhtHz9-QIwXz}&t(P>rb=ifTY?bMj{v1j)K3#{{}H(8 z%nrO=6v`gtuq}S0!sIJ)(Lw1LKFb>c7ASGZ9=m55tAo!_eb?G-MH&aimDJJj${hny z6BBOXG@@G%w0C^X(}_^@(S7*vr1=2U%ziB0Rj*F(Sc4^Z(41WStc$tV%t}!N;8r#C z&$c+t*WttEu8Y6|VRr_VU?(m7H|N-}4|iX&CV4>bF%ELMi>mI6kW1kyqH}5z)v)}F zwgGNz&`d(v(AwqfiMd?s>0-bIs(KSM`wYF(bv?ruFdZU!$vvZy{6i5{FHzXilT%Rx zPC7iilm^q<`r3(6|YgsCOG+XQx39ZA<0S@QGp7)U(`zI1xt-GUm%VoborBP&Bb-B-?row&olSVz@T z>HL%?HPom)0*;+zoqoZo$}igHr!8axK6w;Kc#wjdmyrUhGO0V3HX_2}9R{euK-ze? z_j&_g-0oMO#~-JDF*vh?iWD>dNacA>6aJm!Xi3Azy%KW4AGGcdF&*fnph@wfs`aqznH?UJteG6iJ`h=sHMIoQ(YV@SCHl`8-2RlY0-fU z)eTG^+HpUMH9>RikL%^J((X>2Empye$DN&>OId&Z#Xqsl0B_-Uqc-+_dVcGA{E7%U z^N+%9I^f21ZxQ6zk*H`8xeJy}qAr6`CM2#f#?$VK?JK?e%ZERHnWk-@pWn%pt7oO- zdBJ%ho#8jmU%z>v)}&b#?+Rlkyc2o-li*z>m~DG|S~hY1YA42pTY$LtAe4o9 zywb3J7X@H2$p55pU&hR7Vu*FQgUO++18OgkU=&7rYb62x7!!bA0hvs^PBFkCChkHNF+>x;gnP4-TE0|S9K(bvK%WQhr`V?jpjT0rB11z5*0KGdk`)+Bw z$DgMUs-najv#ijQ%Zk8D;|n~#6yJ?u#hQ zXIquD(}xs=Be!ctjmheBVACj;tZCD#R;8-NYw-eC9BHq}LKZbR_HQt#a=yjG%H7gl zzm@#Nl&4~HC$S^6RWruBYr3QWFy9Jo&O5)!M}&puDDnqzYg@X zJIrwT#U1%LR(x;+GM8V!7C*(>jg>!D^>`R_cc&5Lkq(JJZMiwUEGRDG`7NIYc(?lU zv~DLLqg79T^|`&!=n9m|Q(*(tF@dSQ#XEY#jAnI#6@h>p%`A*B*cpDVWwqd$4~dEF z+SMOlo>%-waAX&EFobW9_Xv!Y(q2%j4zdbU3gBhv?pxPsji3a6!M{)FAtI~DsS60O zWabC#Cx#w~ZLF#TmCPrb0ddTjgRT}-j7o&@4F(wXn=<)NB%3M3=N$Ev7Ke{2dlqRZ zO8KXHnsLN(_5_-15|`iWNWT1ay>()GNmBC7f%|hj%3JPnS7F7sw$|u-m*zU%P!ot> zv!)7wa%v%robGci$>vCpcX~51^n%7qloTW-EloSh(0j&avkeZ%*&WMYXKQ-{#-G*u zN<9}@BbSwOXj7j_61*Y-_64))7wTGCWS#zFa*w&MvS_mug)(@4@`{6fVf^5zU3Nj0 z5<@zNRHt4{QXRVz!ZOWXEl+35EjsF3wTQOQPibq%6k=b}Q69l>`Qut9auajZD&?H{ z#W)WbKW*__5cCcyyUSiaCMD`PGK!C|^JMD$6)<+mD%eijfW(wiJQI2W0F z$c*RoVLgo*n6Gv5nWd)A?(WH8fwdUz(ZBX^>Q~qbsov78i@Zu)8>X;OPO!wIh|(-* zWyc9JXk&FS1S?<}kYjuB0#3A51)}jJlvnQEnWRD| zk_36DXnmO8jC$_v6^}PO4pF8<5k2EK$HNi-CRsE`c^aQ<99%Gu8ZF4uE`HbSkJDo3 zNr=-#){ER~{u>4R&YcO2;I)n};SGzvm=qUN%l@bo|5HC^9f-RBnz50Pm!iMQ*q>C! z#|hcxY}-u5Ibl(hqE#M*|6s*xwJ{i~t(~#1RYqagJ+dw?KY$=e61TMUSTPP@ouR;q z5%XwY-{|e5F6IiS5p`QT>N+R5p*UMBIwqlp;yCr{nkE8+!e2;6j;8J8@X3t78rcS^wJ50d+mVYAWq)-r(U6fJaK+d&|wC6PpWZP-yJMCIHa!q|= zv6N_cK2^J$c;=2eu3bw<*g8&u;Gg6RQi?D>8r+#>;h$Kl)+q;dBHFDvAeydwRVz>G z&WTq)ap-e8ZeabNTn`89tEAKco2idyr)8_#H4;5t`(LTjez~QaXI1Y_U)YP4vjYFpzeV45)e84FL1p&t6X(aEJ!|VeyD7EHMy44^(+NCW$N<~A0q$Kq zwZYt0If6*pJ5qaR-sJ^W0ob&XHA7Lb^`ZP#liF9X?oYy}b^YV%tWD-uFd1v)EDsTr zl1$SB^P9RPl)vrV1pbWHKiqfPWw7!+3c3B=YrOjLzRB;1666a1WzyQ=$$0cWZjF3n z%G34p;XXr>r85Y%S1I_q$F+M6-21~#-Q@~LZGyQ94->T-=B9_}T}h`yUszIGlh|eRub%!M=_@y!r$w(|A)QRwCFs>#6H4 zxe&`Z$7Kv@ae;}UzxJe+Owpn>zdho1L<7b5^AsZFCHii?WslRm{*p*HTi||?U#)VE zbg#O$C6QmqTKpUwDlHp#;5U(zwfXlA^^WC8sqjh!EaT=hb)~Oa(HLmGCP@)F};B7mKF?2T|v+$LX=yQ%BXe+K%0 zx@L(ufHkend+DZ#pCVD!Z*3hrz@unc6=3NUN;R()Yxat>=Y3?86}O>&JkXT4x|05M z19q?5$TmzmEw9^_G z6kMF!TDuVQ3#SyTCFq{ytAIkYOihwQZvYwhTn0;R)eb_0Kby#cfvj@lGx@D#63|4F zkX!yl(Jt4iK}5Z(m4(-<+PQ4c<>9uHAeuID=cdM+L?s|xm&x1-qs{#Ao#yo$502iq1)dJMiIYtqkx}WeZ%!7^P1skgXGxbWZpj93jE^F<# z3HC#l>~4IU>CN2^VaH4cq=_oy_XU@`Jc$?U@cJFZj#8&T&rS1&f~f0(De$prk+ zIN%dM-U|T+U<8$&llIwvn+4{`^oGnZo3gg#xVo_o-I2VFh{MeWpE=A?b zlRJ$%Nd=_(ydTi2Fc`KrHiw0m`yLrTY~oH3RBG_|d@?ll+=o8CqOPxELqnwSNr0u6 zvCIP__-AC?mahxB651YW4N_VLRcQuC#3Y0p>aKc7IVEXXUqdhkkKpYTS2czhv~|}B zS4*p^>Xy7pUhv(9+R{=TRP+7&>bTQKPsZ95$(F}&Nh{HbB$#%jvEpPl8zlNx5sZ4C zWF=~~WSf}T=7}<%sY%`Pw%|6LS;7*YEVaRFZ0-9NEPzU*d{#wk9laX;gzQf)^vb#@ z4E72YLwq5Y30~kEP{GlKNW@`6!Lzow%><=RoAmIA3Ogp` zfZC*57w#goG~*Gzq&j}GXlRL}r2S-baw6g>F@Ox$wR=l*7ZSwm&mOV}9_%K5@At-| z#%;}$&>ex{|IT>Bu7@V2eFrW$GX%~lG1{H$IO ztz)7IMlf&e_pCb%q7~d<*c93J?=k0zxVSAT>FFW^k99m*qjqt~wRKwVXHO()txLKZ z0;Z&x>^I;-tY2N6ArfTQAnde4+#+u7XnKk4&4+LQG%)CMw@s_{>Glc)TJr%zyTKks z0`|^^1~nV(n8+rUdw}@DPdMufF~s^yJQtFG98U*~loL=9j*)WWH`@A>!x!l4u z%yGc#G`FhBqQ;B?<*Bc{_XW3&#=I~wfl-xeUBAm*>wzIA8yWN7N)5>#(7$5Bad~Sq z!f6&AT!nb9AMeY92mqthAP@5aa1f2u`0)-AWY!HxQNS>ojM15dVku_HKAn)hgTY;v zZf}_2em|ejHL56bSbCIc>Bf%cc@O_F6*bENbe zUj@}5a-kJA7J9MK7g1Y44q>NWM7)pskm zKL`kA!k)d)Z>m{B{3>}7s0a|MsMzRS^Gc3PgEN?2ea60EOJi> zWRVBsDuV9|eVX$1mTQOT{-}vQF|R{&Wv8&y8KEj(5H{HJsU1k;Bdgr|(n&Fv80tsFu@9Ij&Eus8 z!HI*t1O6&G+9N^VLQK|*X+xNh@yHZM82RxOJW#>d7wqErX2jqTUH$MKwFzHo`pxd< z?w`ga0V!Z%1I{1{5VA58{&G!~rh9e%hr90w!3BMH^-it1A2X+R(L0v&-6aFMMn{oR zP3Dk6Yq#|^{Z4Oui^CIx{XK_o90S01Og7Z@#z&rYdPbuI%dRVM$VKy%JMMFOHWW2j ztdh97!0GenU$7IBzepVbH7W&{QhO-0)r~GEUU!PjDAK#fUH<$Eokmg4gwA%Qij$t8 zEoN;-a7zm?A^nwaVfBh7=&`X#?9k!K5t(ShGv%l{DUN)Dwtm$qwS^%d)9cxwuVfQj zs&5`)?|%R2gN8`y`Tlkp;oOau0u?Y{eFa?YTyn#3PPKIB7~RxQ>&`Rm$%6+4w67`^ zvhpc6->XXwiLQdSjE^f9jRe(u{@d zN_%XFl^yCT0xvmeDhXAME-~pEa&kfW)paO?efJXMi6-&2$BdCynrQFdcCa_)XjGRJ zi`qzq8G7Ws!Ol~kT97rM-wt>D1XHw`!jpb!PSf}Ao!x4@@n#?H!q`oV4Ew& zVX3bgD{-v9UP^E+3>5(AM#-AXu?@u&$qra_)U=C$2$-c8Wne%;y6!!m0)F^Zrz{=j z=wE537n9@LL1qp5!G1kib9A?#_Y3D5;Dcymo{Ocp5_IfH;a`@MADX^(LFaIvyu@0% z@=`~&$r08khnrT?l%0Jg-0Ov!4gR$$+0hB<1gwBbnq~*Cq7H-g>i-O+@oEXGW(TtU z%Fj+$2Gx(B-T1HHZqtBgn7mi*XF^n26A@!QNw_pc{<5Z_?0Tyc7( zwAM_@0Edj0wH%)mySL!_cxBiU)jC`ImFE9=M61}#gN38K;rCj{Q<|f(WfJvw^C!W) zo2rKEKgvd$RbNhcKU&?_e`xBMqsVYz*XVHM@lD`lhqWor|VRhwY5V4}=9cUt^f z*Qb1L46#_S1o`P_vx^W-t^)-{hkZpe%lbav)>Z_U&oaet0e_PdsU>G%L+YM>v;feS zNV<9n%(IOz_h7M}9cdqni9~IXu#nN~9@Ni{SULU9%M{j5Rp-1EGxvl&<~Do1s%YPB zuc1wKosQp-ONFd;f9&I}?q^aBkkVz>Zz#WK*jF}S{=jPJL;n_JaMhy}XPr3V5I#A% z=%XE?O`wNE2?zh)z1-e+KQ@>NKY+K3fi=;|(y1IW0Eufduk~!kCKtnX>(-3{bd zPF+_M)}_0I!8pf~o}`;s*J$0W99lKdjC8kkCtT@ro0oQMz6Nk1^zP+6OayIm)tK*L zJBwF?Ptf3p)EeJ(10CWnz4{f2p5vNR&2(jU^H^U9Tf6J}0#l6^P7I5(2GAF8*Zn>k8T54@VuG`F z7$cVkUeX)!5uwBBN56inV?ofC%ZG%W_6*9y0JA;a8~?f}K%e%dtU+fyyiN}HWW8;x zuw~so^Y+t5*AhCyXB~>Ko(IQP$Uj6aTU*3;Pe+jaFL`4(;p5*`Yo(-)=()y=PBZFV zRKH-g=YD)t^5y0z_z7J#HC_MeluU_E4&nLd;^HF&X+oT0LtgC%DQ%C2VHZtCLWPYm zW568jPmt6(=1IK=gRZ|wXO9XT8w)@#%B^&us$C-In#F&h{}CjqM2MCoUyjof_3d)4 zJ!Rm##VNE(308&2quuTel>iDY!TM7ToIb=}daC)Nz&}n-T*d5fO~0`pYkUqQArhjW zq%tH-+D=4$`I}6H^r7^O(b_EfT+SOUAjvNCr>Q&KzVfc}j@AI{{zavd(h{Vkucz4aZF;|iWU&;GfwZ3`4mv+>Dw>Y2zVu5W6@ zGNL{c=-TCGG%2r+ixIBN;yV zFmbtStTB@3P%VCbOAaMnRgsflb@YsJT;C&boNd$bVJY?Th;r=7HR2{YP;g8&6%nNR z!`FrK;_HLIVQ<=iF;(GvHN%{t_xX@ASXWn9ELz7qDBZF{3~8Sjgu}?asVQfK%l5vK zoCk#+cydF=N$$4I=9qyqYG9KJu zMfqzNNLT9$*sPj$7kr7@EmoCpnq6GK3|9eMcwpmIUytbe;Aai|x#sJ5d6lO8+@*(- ziPq{?H?hpxmP?Xvp>4~%IF|vo!O6*A*2IT2)VJ)_1d%*-Y%DU*imqfUis=>9RIQh! zo%)z0a?k-Qigmx7b8)W>fhLx%9FWB+BV22We>-9(tFk%=-%Kf>bR<)@D+}o&RsNrJ zB`+8mY3D2xs|AR@AP>Jz@j@FoV7Jf+cuC;oW(qbpS z;A>4g1-m^2cVG3`nO(cQ;~A1=V8-;S-!q?%t=|i0tQbk?)3IB|Z9*zktI#WS&-*t} zUVNfas8(as;NOk7TOmsXlbL_mnbi?uk?Nh-oCD81#!%Aaii{Gh9l%k81Vc{HT`GhVH!dK_cr zIWS004Y}6ry^s9ww2*Cg{0_-n&1QF=JM*szG98acj{WHE?PV~Eb#{gdVF{m>6hJb; z`dPg&SgZs*M@0sCk4l^^EH;^o-3CPlV78oXCK)B;{yN~rm9ytO&vuvep{OrFJ#;UP zP1M4r?!Y+quErBiOkOEwt-YhL6}KWU8kEkt7ZV-&K#f+ZF6HbVAF4j7iI^&XYqL5C z^~aOIVFQpl^tdP7n#*Ylg%5%iL6$#vBZ2)hYT;h5AkeOIno5R(i`XAm z4rPf{>uq6AW@LImZBrH+eB`EyHbPDQ3=DysWT&Utb@g2aF^@|9iq(Y_zqGAn)WsWQ zh8G?-;(Vg;2ESo+mCiH9nFXbTkaM7K869lQ=s z#1;OHm%pTAxe`dK+fl1Gy%2B!5srR%W1u`F3J*47VCxKZ=HM3xk0n(3D@YZ-(cZQ9 zdK|OMaFfTnYnW^mJoW-KtLE;Vz(~>b1NpKYug45Ng)AU~xTag0$CecnTox>_I+wL* z@_W}%Ug}j(63nIDHxpt+aNOwV&8Ie5u~bmhq3XR zkL@6ZQwx-TCrtPcn@9w>FEH zvyGn*pX=mX=K(zRZ;kX{$SE@FIEm~vPO_Pq<-$L{{fc%ZPJ1RysGEX&3SL6xS;kS} zD*Q$4z6oPE4iAJLdv<3ta27jy%! zF69OHrLZ8G2+jOM9qA#0;7b)mBBD89)=PDezPn0^d43dwGpXSI7K&Ep$JK2LCmS0o za}^S(U7svsG5DXe>kQp-!Pl;Ke}9McAHW|C=Foww0ssF)gf#0S8~CA0U-UhiO{UNk z>8htEdU9)Snql9?gzzKtbnd(dla4CaJ?n~=ebzyZJPpENXltPd<|iEQV&lP!+eNwj zoeg}%mhDPykcfBpZs+Ji9PUlRM(7^Lr`uHZ^JmSN;8$Terqh^$ndL2_k z=G4%5lW-YG$0V#{43tDGC~LFYqx@lQnIGSyH4&(QVb}zQ-j~p%s;;rifCr3xuvzLvzpBQKmdzJw3;hQz7xR=2jW=slG$ml}q zZQXBz)H<9s2BOd?Jj6xJR?C750+I(S93_W5=^fDA!+lv+G}`$1+sm?D{$16gK?$0T z8jmsO{(T&tmpIxk{`^ttvH~$5tZV`ma!R8BJ{DKCjY~*?1jPtpb*)fSsp)(Z+v;B0 z)QhcX%p4#*2)eqGOM@UH>{(6{!h@~$hHj#&ea=W(L%AsNbt8mH4nu8k!h;y&N38tO znJ`J4*vS&RQ_WbHG1T$i+O8$%@#En6HJ{WQ!%+7{{^#uoYI5q@d~)9J16Jn^L>3}w zKJAR9sm(N@iXaWeT>(vZPIGf}?kn7N(Qa>H>F#CWuU-v(O^MS}pB^P<*8!E0*EwP` zu{}hUInmpi55{W71Fr@{gP<2;R!;Xq&eY^X^a|RL^XC`2FP5Ct8;&R`=%iad@4>iP z#3gK;>OuOHf_3ZF*4|pUMJDC`Eylc4(U~qC^m}luOfj7EAQiKzFfrV6ZknC;?eUqW zs4y50F~rjsh_wIr9EjF=>aYC-AJaVm8PFNg@xBkgU_K5I1G}z1h`o- z!z+71(i~Yop(m8aPvf@Xg+u=HF~vsQSev)*oT|mIUMN}Kn1xZ(XWd&}oV~slP*2MI zhT9HjRtkTtDc&>f(Cp#r2Lc1#uV@h3wAyYuT2v4Zu5KNhB*esInQk|tX`sRe-&Z#T z$Krdtrc`ietja*=K)l&Kn22%jAcMQnW2*j$Tjf2`G}eM^n9T9gvZt^(!3%hD#TVR` zGS|h!p(X22%^Yx3Yl_!NPuKmb%PcR%1Uz}vzf{GlO~_8P^?)B?iQ)jjxzFq)4Z|Zm zA=)`l-SH-}ZB1c2y2eJv)ZlAQif$%E`KUi(A#;DQbB4Nv8u$vY-BjPPIL z<8Dq9F6GCJpPxm}94-U4X-`1%X_kP7Dh$5!UtKaX^6aVEV8Q`krrVGcj|-D2M4#aGCkudc%*-|74e1VvCVAC) zuP@Ds&zs%R<%uxA0oPq?cBEmsY{;)7qtgykN5_A_ge3@~3S53{Ns<#(mpVUp){Z*i zf>`lK_}dhofg@!)sTr;-CIX9BX65R!5H;gYkK&pPv36C z#diy5PsK6vn>Sb)ZNj-H<5ijC1z!WVx^J~IUKiszKIvJq660z$RNN$A?IICv_X*9F zKdl?`Id0CnU~D}^pxzeUac2Qlv&?(fLhN41jHFH>6w6Cok5)!DRm-!9)5>Mj-bXV- zy_;F^q--E(S1D%eA`7d;Y1e%Nu)d#w>=Uqe2yuXP&A2(C-%=7b{XFl=QBPu+Sc|tP z0i*F(JNuZo6uFCMpwmdWsljH-Y{?J7?7cS{xM{)AfG19m#9P!cakREngn0lQ8M%AU7uXRH~ioqSOLRw z|5J2{;N9Pq%L4WrB-*vOM!gP3>lZEl8U4WIr>+lCIQLth;&U=N_hxYh$eJVIk2@Us zONb^1;b$*gtv!aO{Fsv+UHR29Z^o%^QMZf3o0dVsdUslH`l_YK+V3V-Q1Y%-F#_`@A95P^?~Km__#Yq+5-F=#cp{ zGaf8xEzOlokSR)ed3m~3z5X2Tm!r~`=I*f%nk_lc$pQ8~AY@akCEH~>Q(gt4>}%!s z;H96fj*HAR0=l}hvnmcMnMQ{Z!_W4N&!AXAW-Mk}a+$ZLha%HEP&T?89rnn)`&6Ol zE+A0WCp%FuvWjmM?^OvGi(kTm2R7J ze7k4jo%uDYwiGl3#-U4a$!jdh+fD+*I_6kAlOzp~1i@pVL|RBjFD@ACKHF3s;jVcu zH7Bjp^I3bwQ9Xz&y!}umAGfG)9j-6lG%`MS=7hM2)=`({RBhcy&2eP{`qFMv)ABYh z_UO$072v?14DhExGYO{K^v)1ry92{tgJe7tvV}m()(olO<@x!vnfTGSk6hY%e{#kn;%JD3juO z>)yP|%QcidT4?S4%w%gu4y8h7@{jV%BsU?FSR)V&h`1h|P?U)7r+>``XH6c>s{ zFP1=VF2u*aX*`JMVYN3;jQQhk_mHW>S_5KSUaL6U>lL1lf5WkLe5ynBz5X0u3ZyQC z2j$+FwY)zOM}ZrzK6lffXMWA!LNhT{Q7@3eI`sx#%nvZ7n2AF{rcajgnCU!}Cy(^v z(I)HoKTQ?@{v8Srr?>g7sWNBccB2+(w2}||`_#^Ebk#p7zAINW>Z)nnZI&z5pChz^ zR>-=K(S$RODAA@PE~WkL8}ouuL?RagnD4L@`l&ov25;;T#A@4`gJW>XUg!1b5hqbR z7vk9u+0qw}@3XTD8CpB73)_x>!ifh3QR=+wQ!A=&G={zZdFs9We8PB6t|ck**rxVo zu@g%Wg~z`Uef$iEpJx|=Y8N0$v`d``Z42^qxl0B>KXK^E!{E686dE~Aq)qC~keqJ0 zZALS7hSlqtDuW>O;qICM`jhjkT2q8X?R4jOLJDSJpa=oFm`d-N2{sX(b^yS*jN-|L zBu*!64#FP!@!oyl_|iO8L`$2|edmwyX`sL^cP3HYlb?HlHdHUd=hswJRD@VV%JbBt z?zH~X-+m4|&RzMXkodKZfWNnE#^!pcPJP;fBq6Eeo#Av3;-rJx1bXo{7Ar|>bK@6QkBqcd4SzjXk0nJ; zjpvC!DT;)EOf=>fkkg2pI0FvUsk^(;%_sqPC?QEiMa^B5=AZM z(Yj^&)2Lm}R~DA@^H1-g`MUYUW8~}L08QR1EhSY<8l*!%jplSFUD-Fk=J00&8sCZI ze?wtZ9_xK*DcFiPW!-`C)knWEfc_>OYiiVY?aKCX-O`zZSd`;u_Op3$>3~MiSee07 zbcChdsWPFWd&pvm{gHX6&fCr%0hkWb1MkhRNowoFBk_etL9AY0gTiZmoUag=lroNr;sI*lX5SgRvTUhC=V4jS{t zto#>i5G(Qj-r|sSMe}v2*it?y}d>4A__~UFYojUY~>u#gu^wDYHKcx zQ2ZVNSpggeO2NFs{?IMMoNe#!;9eFwA^cN5EWhFcF<d)DCdwo}4%N4m>L8q>+)N#xfe7)F5msj}+SFid3ei>+zFKrZ4!*|2z!x zp;v;h=`DX|xF0F6m=43a=mF92i`VQ60~Ls*mfLM0t6PPpm|;*1;@^@8$Dfi2$j#N% ztTaJREdm$$_ux=_+yFdU&?m4RQI?jLcJ^NcS_i0{re*Q-M-n9*I>kt&goK?^tHJR2 z&QxF_no=k)GrvRm!#_}q1PZlK=a*Dhiz+Gr9%t|zCgB4EY9^dvSL=%V5$6vw^F}lN zR7TS&Z|%GXojbrrrB>P!Pl}{CP4!1waN@`S1SH<0qv^7c$orb>#f`$l=nH|Oh)6M& zpN%{`FE$KCz%P4bOS#^hD))m1jyfmQ^{3^Zr?1jNJ3mEKg(WRRq3Fd-3js@x#U1~KD4Afa|)N8Af`b&+-6b?0xK2k{Y0hhQYwMb2|5 z53k&o zwjOdvd3hdf^V9ZM08r2@k^4qxi~bTf^T_y_GBCazP2QRQ1kj`6P&pBhH!o1o`|#mt zY809_3BtWKj$Odh1M~w>5W>yy>0k%A0%5)WGyhLr!t^1D?|h9PRDZuZVHX(WqtMB| z!`-Y?3|IgP4o*!YBO_Zl-jWf7w6r}cD$9g~u3Ax>nw~6RAm!`LG0%39TyU4?-X6oP zr%G(J1DhCL6W?4RDqOI1#uek3vC9p9LGgYG6ch=4j|Qxy{nLC^ZX-}v>?CWR?{$s4 zJ=07?9W72W`lYbYau6PKdidy=y1n4M%9D+PuXhDL3}+j|K%5ia9hs5goi|b>;7sMx zNuDf}6Bp3?0XlyZ4CLyLZ3|iTyoAU~U$T+F6)@d5rRNTOlM$b(-|V<*bnYTg_KH+PR6X^p5YxDDDU z?3~}S7cvl6|4cY%&@J<`i8U*xs2id9(G`a z18dTn-uSwesopXE0|Fc@Fn}dr%q(f{tQFoC?ZMA$8!qTO2M1N9$Ug@afcEgjA^`-} z|5zaAH5?I~VSpAW^nzFvVBzB{nX5iEZ;+9>T0FiGrQMghl5W0M@L38~6~bOtbcMTB zM;kyo^dv{wMsRQ6<7&d?RV>H`h01ez>*Wf8?7Eoq#khUbH)%N@EgGgj z7MyKA-Ps;FTW*t|%-wYEKVeTOCAV;9!cWk%weP~ zK}qMP=Z0uk3!HJfP$ljbGvI|NOgA8|dFV+WhchH z|IwbI)ANC_hK3Zm%UQRKJM78i6=i2T!Ze)y6|P$0>z&L@&AMIpAcgxEcPB`U zdvzp7bW{k5Kk)E#V073*3uWUv#+BGj+kQaGnXTtg$YSij%a78Sj=p>FS?=8b_C*b2 zGFx5@GKJ|cHMI%Dxe0${+&1B;sbm3?Vr58)5P;T5R=}=hF&tAHXt^lG3F+$}>3ZD8 z4rSz8y515#_#$Sgpz6Lv0C9(;U+ z;0i(Wty61MRaA;Q>?fVDyE?Fzme;ObHZW+sQ*&^~n!=-Xm^A^wc)1$8*#@j=MPGr6 z&~(>2Uq~|0a=XR*QUspy$xeh@s~WUlok}sdKZTlRp_a65Ye9zKBhgXP+PK((poQp4 z8ZJ?#>boy%`8dyyY8Bkg8qkmdWDwj^{2m!}z|MI3*=b#-`hv%Q99>niXSCL_=he{% zV9%0nMBJ~dr-#jRrGEwYc2KtD9EoAxjdG~(b6~b66kZ;4yg!wUSPLY}4Myts`Pe%I z2!T+hQ7UumhDv)lvfByw-uK` z!;e^-y&K_;{uU8B3op2)rG$Lm&CYF~fj1XkQH;%4`?9mqcDh%K(iY zw_Ih6a*1%@Hu$#yxbGosYhwk*&j%~wrEyK5bf&~_-rNoML8a%1*w~JtOql7*?~=kj zS#c!lEYaI1J&QOrM`ew#xVShhh4I4~A%zr|)mnL~H>U3qW@4i9U9B=h=9Y8tqhm4l1$UwF^S`}$ zIF#x@gG(6>)cbgdYZ@F3CXOL4Z@VGtxxf6~NimKqueTO%axLfy56kA`j?IjWRFLla zZ~rR&F3hoEd!;lhoim<}!9A&dwc|7=&LO49l0GiLI}q1QUvWULOx2d(Cs zizgpmD=)5pQB@VcLEmw=D%CXHoy|Cmv5n6V`qA?x3JA`cGB8ZGE!vLgzuEprtixk< zD}yg0#Cy0;P3DN(>GQ))J4Xs@JpGhamXmAAWGl|M&@AOl>ub5=ti1iGqs)+bCnF(s z2r_Bi&-U*Bl0mIeU$a=ilsC5esjUF&v8hIGEc7ao!?Ck-CEN2k5A7OXj&i z;(^)Q)IMJtWjV_M%ULztGN&s|u#}^)gGx;{p7iAon$o`4OxoqNksRF5#&~H-k&d%rT4h>TbX1l4wvMu-!@AsDS%f9-y7E!^ zeQ7hT^|JgHj#-!eMdW?xHJn9Y`Z3@N2KH_&WO@P3Js_KF5!cm~7X@L;iM1crr8(19 ziHG=ls}Dwjqmwl!-(gJwBY@ zr|#QVaH$Q();#N04SXXH-s0{^ygG~7+PWT75CdC-f^U_NHuKf(v%deJwY035w2ZD- z=8!`>IvHqT8`Zu)IUJI^9%sRm+azv$@3(yA=J8F`am%ALuKR#Y+XYUR-u9A_al(|H?LXWMBaHyq>6dVIYT#3x@-6AE-* zh|cc$ne;#FXK7UV>oKrdHhMNhIT9ul640?yiJm*s9I{C9x4UW)On(h5uXmpeXul?$ zo`Uvchdx`K_#j9(yFbXNovpfd9%rDhuOnJ_@lE=8=B4{6$NRWVIP1DW<<=}hMaDyc z)bOe}H?@Fcos5#=PYaiFCX&-(d^De9U*8TI1l*^{YDh?VPcZ zHQM8UteSUwseHZTXEvWmjQnI0FBVbc^^bS}UlgFmA)2sL=|9tyGm#W`Vl(uRhT#@- zlyo5QxmqtQoP9={Hwm~|){h$%a1p{#uPa)d1<>&W7AhJ6%|Ikq4;cp)8Kju;y<28b zm$&2KF~fIrd-Mo__f@KbMoO3V8L!;-FV--0hKFRnKw8*4qegv>2Pe^I=1mRS2hHoL zKe7`vfQEs=WC1tMdER_5b*|8VdSmqE*!QPjLEo2G=b5HxwGVph+^&~CTz&Z%-)|>y zsai+HLJVN|*<@q4IZvF0tnw&NB)51)Bug8d453lT#UHaISHzXpOT{6CVn`fQcW6Ia zr$Yo`-#4|)#>j6zpKoHnERE2QjQ1?nbctME=%Y-z^FV0OQQ?FcFUw!!s-Yc&O9APa zPBW7-rMJ7G#VI|p?iKoqT3_i%_;c5gqgi$)YWJ$b($t~zIG0xe`Z0@mGbe>afl-*SdGNxh0#=e@FD zH@$(H_(ANmrORxVc1y&Yv_basW52OwGUZ6RtKg$v3pPfIik}p`pqT=l5=f~3 z(@b?|)!JT*GpmBPWr9HH(e&8Z!@bW#}}Ax>(OEGVX0fWlj8 zV97up>g(WjM@4hnatUGCg=jnfG&tfvfVN>T4708jms&;MEw4t*JDvjTti+_T;pDVR zr;hB5HiGBcN9KvI0f{;j7~uk*_E*~B0AzoqQ2M`r2Mqrfzzh{ri2&Purns=ziLEC@{j{N9V0-8k8>~tUwBd);zBe zmxp?|{Hg)Zu_e)-*mOaaM6?b$mrMp~Omhptr@ADTZ1SAv&Qb+dh zm+Hqu`qt$`OB2=ULQ6L#BA7wuk~kd5q&%!W0?sddfVccRg*iq!0T|j_8?<|L(nAMp zpE5PppeWkvmdce05MUZc-C-#-0&_GNwA%nIk()q^^aKP^bMl=6P>&A!;avc*STGJe z<}Y4c!?j|zAK6m6nCJ;|zl+cG%p*_+TprQ$5B-#~&H}UW*rszC?m9c+Hm_guT9|dX z=}1M6aZ|OcrW6npl0iKQr9D8W{coNxe~;+Rr_Fl#x%5dmtlo#^+11)pBeMd}q^NzZ z*EW}bk0v6lszlQ%{L1b=g_3XVdy@fea?MKjoeBoe)7e4D`TlHTlT~Shlmq)ka;|TQ z{MM=lVMT)aDvi0~ehOC}Kq-eB_UG1Zm>_JtxBs$K9HlA(_z=vEebIO5DH7scQv>tr zDkw>)xSG5)wj~LnCUoEmbtVUvU|}CowyDx&lI|vEgg8h$XAo3uBi%7%y(Dva0$nh} zSr|zUGw87r&JZLNH+5OrJsV-OIm-l@KsG~@zYqW6lKumo1O6Xt?;X$O-@cCw2E&aUREUp63IcU$kAxp^Y7fDDA0!Va+o_YRb7QT2oq;GROa}?_jT5W19Cx zNnY2aed?d~LV4#@Y2X(k*qA>vpuUQ-c110BkwH`%@b~x2CcE*vL{KPZ<;|1zmpdBg ze^<&yeTU#N1%rVmXN8g;>FJG+jKB&vCC;j#S8}YMq3r@4wg@js6sBpz5X88$D(Dwl zE-!b^yH~YsQ^EA@E}06f;*@ikfRzY-=}sBs%5fxm-qitV z#&s_y^gZ?Y8E9blmbITBO>**EO?K(M4EyhI!VtK%?^fl|-xAo@zm>5LRZJJb(4o0_ z>{KVrp`fnoHL^l%UP@hUy1diVqK+5hDo5}B{UePcYV{gZilc_AV9j-J&TCrlim zgJQ>Srh{$Ip!wJS*z;)*wi?q)&u!@Oln^5wLHL+W3_c&>;$>|*vR5z0Qj9Vobu1KY zQm1^qzm?SNirj8MU*fsyc1k>xwPei_wJYT<75!DKD=W==$(|3u-rIcivX~2~>a^0n zUhf_}&cxpPO4Le=7!gPfxw0}y0vpn`e!3=-hId>O*0*_TkYhI#0-;$6cMdDWRK_($ zvbZP))>HheJNh_#C`9gSJB2U@!pjTm5x0{FxGmn8EZRU^0-kh=q3t`@x_N)5_L- z7aQ)+SpLX;TSd~;R#*46bKD`N^u6L4EzZX5L}S4|6DN3PV1~|mN`*gkU6`~|(J*Ft zIzRACw{$&F)1YNUUqb`PgAFHF_UhCe=oqz-`~uT>LRbl5Nx=kD+{7_8jBjPerV!3; z-E!w+N|U;XK_6K#Q|egu0QWNx?109ZpVIA)ZMr>Fu0mZcxB6~X(j*avxO;b@OR2`s zvBM^lzNzEs&Zqc|6OCHmOqFLmH15BxWI(uk-*Ds;RG%4tko_(Br^gGtIJ#h62hRp@ zlRCs_^nzQQb|jju^n&o4KY;vlxG+779?dUQ24_m|;^g$$46sHX^2=K@) zqzTAKP-UDrKPzrE;zoT(XFcwayTCpEqh;0H6jPmH+R)T=oRNCDFE|WurK=LY5*ddr zCU<*r=z$r;;*E4=%;5uh-3xo#;5%<@or#P)JPT}a6g0;dEoL_Z1P}g7u9veAc<=BM zjH4nf(M)-d!DvWGI97_mU{8@Fg-bDvEHTAjYU(B!Cj>Z77uZL1geS<|VS#7#0d3O-zMOx22sc!}Dtm>^V0oKNdS?Vil?(<-# zSn%|Araj~?RcoKY)0c*$^mHTUO@dvvwoVg0^mQ3`!4e)v+o!YSZd9*=>c+chLK%6# zSfqE7cnaO2g{2*arsH|e_A!G;@jXh^b1G^(%{}PvUr4K9<~ROA>ruZ^N%1y8f)){L zovl!tI_V2-6U(IgGVgDqki+KzTE}Po+$o+&G(A(NwA6oKtxTe%##rT&%~oH1GBjZt z8`=7Gn`#(WFqP%cI7P5Pee2WwUr_UyEG+F^sw9lhVnM5csx9Xqz%%Z>M1De;ha z)+|LN^UZb}@TGti;gK~fJL{oF&#k5R^{HjZTCvZcqyws$s4l(|7dZ6ipd$JprEBly zG&RE?hiY)`yw~m7DDKMWZ1yueX)xL*H#ZmN&16qE+<)f`lc1AG6mH#$C{w1*8E_B2 zDU)#LEW*zaeR6)FMQRTWi^GU51U~v08~Y#zhQl!2G0Z7!e;~$Q`MopEZ{9u6mK9@7 zD_o-K)_5g;Q?Jb}sQ8cuL+S$NR&1MGYT%Mr8`;w?w%Z~29?Zs#+}^iv!Uw`6oT(Du zWU0VtE4>F#U}^@iP-c0UzPXe%8jPcXWk|#dlGbYLNT6)+x-WQoP0Pg&81CgLGOLAo zd>F0OS(28NXpqKBZ>&dCG7>AY825gvIfJmsHaJsb6V)KSR9u?;z%R38oA-C=G=!E; zcQRj1*}MyEM>EhW*N)+LTaTK}7a>1(Y54_4O4U3tEcDv>dmDmqdN)>_>h#l5-l)p<^h4o9J06wM#99LsMuIhSUEgp znf7J=p8KO)w|oQIEbhoWm$MZBjxDRYWcQ28;QM2#Fh~{?!PAok4X_%6ETWs8QZODU zqp4SS>hNLwg|;tW?5`y~Bp>fu^zGiCu#j5+qjQ2uNp>vg!KX@+3>5%?x%)5V%t{)< z&KXRMaM&AUYPr35Wzi3R6<5;)s}i3R7f&UWzj|ah>lP*K_m$vV0o~$@A*KSDl9XMt z(Vm5!vdUwoV>MP2>!en5C+g6{%!3eLN5Q*%>$gAajy+Y#0j?wmJM$t3O$=DChh3UqNv8ZNB4%Y}Qc({?*?wU)-*Ms=fB4 z>ra`10bvkr5z2@+E#ebP_o+WM3-;P^{k0;6rv1p={2Q5QU19EShEw~!IQSolgQpF} zvDJz@dcL_1>W}>6E4{WgRg^?KOXq!dUGnCk)j!W9%8wZnYtp`L&5XB^zpaSgFKVLoc(xXv+i+^0W z-iT^#s;`XC?2L(Qsa&q8xO(=muD*T;%+6C>8sF1JwmrY%7n>El+VwBZt7j4I9oc!akR2KtI{L<65d82ZwN41y?3C*{axIV(WMg_rCmPdc6((!H}{8= zTvg!o?V~sD^2>+=$-764-D}73xqYX%_>ccG(PFBgQv;T`J>(v}B_i}>Lgf(HKmIAp zZj;Pc1SVYIF^~B=`+NMlA={lRTZU46FqD$W%LX9T+XNhtIXgMWqb2r}gR07Uf0(oA z^7qKKl=6!h1 zej;PD{&IJB_jF&0ZMF466zrk6XVAf)#=GSZMNDh|twq#pU%{BvzcM-8cO8Tb(6eI^ zrK4Y?b}IM|37~;%5_dP-?a%{EqHqn?=gUr7@$gx*9E#f0IZh6&)z@m7Eu{nkpTJH? z-TD6iE%#&u+>@A5uOt9X#qPik*mCBdm|oHDLMOz1{slLM?5!!<%sVgN0Hg z-Tt6p`3!^#1!C26TPl6m{og#!Eh~`e5zy)Fx+JQ|1~;oaHwjA2f*u8j=EjJ*kCn?R z6jmtkoAdFWNfk?u#Of#sWhIR*e>sxA8gU`wwtoW!SAN)ohZj$`*5AqOZ#B*$z)zdd zkPExVdy(kn6}N+XjQUSqH?+R`;`D*|E4WAY;_cNs=5Y1M0r6fryq7q{^_kLw^p z>xQ=8iyEpoyNX1Fxp`Ma%B~PvFl@epMXmHoA__eR|RA%J!eQ%vAk^4L_OO8K0Cg z!`{HO$9XJ3M>N=G!f}6QNVRF<4HKd_)?W@sv@)nc1P?SYEKM@c!eS?wP8L&U>c06C*s{9(XOBTi0xrGI* zRh^a=BeFLP0n!K|8)>kfdl^oS+m8l;=0+TnvP@NR_zPQqNMH^6;~+ygJdn(H*1XCA*+7_2O#CW0Iy^#^RLKA;mu1o12|k@0=^}bF$Zp znsNshPb$vL`o`JRc1<0Ua=|B>+8g>3cST9jnFT=@@wZ;lWhQ5FB#Y}P9O2IwCFv_K zfY04UGSMW&Jo3e~31?zdnJ0L^Eg+mrqNY_AbVPY2GybK?GHo47ka zzs~i6{o$WK{pm-BGmq^F26AOy$(k!JQitYO&Cop*@s$QTz&dyE-7d%ca({McPw_>3 zH}5uT+jkNzjnW3X3ynxE z#a?APVOui`i(~rhwsBKTb@{QwQ5jBL^aT2G2+s_6qiz zB=W2bvKKRnD)n6?#NhL*+sp>oQO<1Gfv+=$I?9Rv^$$^;=d_{cGZqnappvgR_IGqn2Eo5&A72RFw~D?j5|x`*q~OB-C@a+HcV zH8~mX$?aU>?wVmv@u}T5W~BS5L))h0ZVj$jjosb3h3~!b!{Cq#&p&mPP{Pr4^BisM zWl{>ymyw`)nP$qgIGKz4-aDsJ=y-jc8ubUlm3gvD*00F2$85z#YKE$o*Gn3HAj^Y% zIlX(0YPzrC=;^{I(~11N;zlY24}U#`%V-z{mpGwgzJ3=qbzN!jXdtej#iL>7S$oIm zEP{t!aQJh=l7e9ja+T#cIb(2_Pixt4tmc*msj!dioPV_k8lebDJ&5&j+h4HeZ1fD5 zB8?Bbd%L3=4Ry3=f->h;alB+dUGtQ!+JtF*vE#0Od)SP0)o2!VvM%DM;u=J}&9Izx zW4A3e5RH9R?L?${)QMj{eigs{Kq`;8qw$p3&%Xp;!5uO%muTkpUVtJ@SiKR4$?WpJ74;#_~b&O;SAbT&A221;J>q>aU~Oc}zR zfAy_c^u%$WXkK9Jrd>DHoSl`y4#}oUox>~PUxORm{W4R-2f0Yf&4ptA zSc8ex9`rKIPWKngU+avB5itz=v<$a873mvYUYlk_&hZWT-gI%qUlsjA5{5>Q#f{@Z zTj^t_V)XB?$(KW%QOwS!4J*}Yb$CR})08IEGmrAjxz3le@4YYlH%WqUH|ZWUNz@Ho zLISogz-9P_UyAbca?XhcsaDL*h{>1Pez_crJYubPiwM-#wB9GO(lQ&lFmUcdI?v{L8aY24@tCjizF8Xt8 z;}`HPCLF!E80AEjyZW!S-6Nv>^o0KECXm;*)6r`B6K!322N-9ah=jT*t@j!ks_PJ@ z<3qwhW^)tN7FkBNQoc8S%;s=k`kz?o)`bZ4L%?1U7i_s`TaL5t$V6PDPH6caf26Qs zCvOR}soQU8KYXCmRDSW-JNTRl$MNoQ&z_e=OHy&lcFD^*9{swEFTMjv__%uY(%JQq znffk5j_Hk$U#2)U9W`XDo;lvKDT zQr2>HpAosb9AObjjd|DUMbYCb+kf=059dF{{NEw}G80ngI`TgTcuBLbJt3_22}PI8 z^ryXJY9YB2X8?p7&d{F69tol&&Eev-{lxP^ZSmouIE25|+on6k_tT7c)Ayxo#TP|I z7rB@_O2#wcDHw*uHZ%<`9VNvZA5>Su=Wa$?Y^5@{zMty!e~6i`)S-^~-KkSAh)1;K z%&Ktcv$^MdEbZa{EbkdP2xo7$jTts=yZWnQ{Y|%XpSR8>f82X6XP#<`DTyQ5)Jj(C z1=lk}OVHYg=AF z&P7eRY%{>3cEY|(%+t28wkb$1at=*SwmA~*=^%f5f`A=2_>A43#bX9-9 z?yrBmw$yS#Exd381L#pAM3y~x#DyMVSAbiRLMByZBfN|j3WmBe%FTrLl-3t|^~Ho{ z#VL)&{CPIH#k$sG)3V5sTV&RJ;{NOqLd?xWyx7o-T*?*w7xWQP_=;n@wloc?*AjBS zw@BS1d(jQmkA)U!EZR3R{oUqA-Ajm@MCi@F2=}FZ?BrHNKx+@8tzbk(H)90X`B}Lq zZ(frZlm%V@HJA2dkq^gtgH+q+SMA+Qjl1XkCQsbkW9J4BnY-*Z?ONT~9BAK`eC8U* za2lom4098Hj@zV;&BmNu4l#QEt!NOfO!cB~m&=|%`!o4|*yvO9Ed3k2eZ$e8dbTfz z>y_%24&oZo4)mgy)oI>DMj-2W$6Til#qQ4)By6JzJ%6`}XeWKZv8rx;Ob&e_zoPy< zH0o0-%V6u8kc`Jr_k8Z8ek0mIGgzI_Bt|!JMfAtLIy=kIrY5(_7Ui{@nS@r@j_S33 zk!11)!c`s=l{7Z=l(i$UJgZ9soO-IWn5y)*8O5%3I@@C*@Dq31`M+_cl$&xh|_g3p3%9x80>Zx~@ zsd`^saWB%gm7W%#a$2Ph(QV3BxS+r{UW?O_{Sw!zZS`4N@BsO+*X0ujXH>0ea+f5J zo#Wtu<}0`UC|UZV2c@=xitZ90+U`<%GE!4(ym#=EzrQiW`Mn8g@~1Euzj`UkA{{_b zhE;~8bW>JlCd{#X8xW8)e|BKdOP2d@EVWg4s=P8y%*w2Wuh#EUrfF~eAE6kNCswq= zC!MYOY$q?78oSJkEeFT}5V+6S!{G@5xv8yrZLO{&!yAdIJ;3S(-vB(gX1!95Z%5arE+T-whPm}Ka@upCi%kV`Av!9j?X7Uos={-u$`{qbm(p)DqP}337&>8 zN_N|Xcd?4KuBl#{f#~tLi%e75_QP?%w@Rne)MS{d6FcjIBv<#U(g?QD*v?Y+9SDg@ zNWe|&nP6>-U3M=LS~@rbqYkWz*s^-;-VXoFZ!oDAG{{z2IhLH9Y*9;n7A7Q<;m4}wO^y^zX{ws@Vj8&g=LkJO}&52d8C5re3+2CMvD?cRjS; zaL$7gajr4RC*Ts?_^bZ7R_xu;Ci35KI_!{7oG^b;srvV6>_IDz1tQWPdblrGML+4f z0YgE+PNE^-Q5U2owp)8%_ehX%xs{IAih?dx-g@mj)lI`>rsXfXI)`S(LxhI-4o{8W z{DwcFnbuytw98Rd_UI>CbFKIoTpAzaE<=IPOd)(zFN+Xdnxz@4hH$L8d13{^Bpdhz z%Rx2At94q0OyIN?%)P39dstOytlc7O4m3#7jv$FlDE8Z4I#@O{v|r0uE{z?&{XI36 zSFY^FZ3g*w(D!aw^N{=A{p_PbOQzJJPQM6*PtMX6IP}B>X|_6Amzk_TnGg(jM}$F; z0kriLa5_8wTr5(cID`h#snt_h^PKlGJA{!C8nnlW=sH^PtlGB`WZnAOif>QVH*TS* z>sEQE>PnM7lgYi`N}^jiwEi*V(1?}^`uJr_maHml-WVLmQc?_|6=g^D(h*;BLR@nV zd%K*Ur{R)$S0+IoIguL{=AaSm6L#5#XBZq1rwwgw*9Xe|?=C&$F1z-=P`KEk#fiTB>p|6HdK;yFCeu{QRSHJ)e1 zpIgkrqaM)&(e5_}rSEJ#N@*UVUSn|9 z?ycN@vbo93kZGv7aw^bBk%tqMiI!Q&KyHt5_ZGQB%w?=&e+nba2^yht$8PB}zWbam zKxKYm+C|c)Q`l)Hpb8JZnRg0cLtN%8cyVJUT{uTII~W>2KutSIR@z|sK}AL7BOhDV zf;L|#+d9k&F`mWwu5|4hiKcQK7i~eRYClDr#LalGmb-x-kTrcl+>8_Z^b z^d5Jlg^#(ZEpAmhzlo3k7ulbJbTl36y<{LfewBL~YgdKp_aicutV=6VZV-%oKB71{ z^M}j?oO7kx3ptzA;tzY;A7qq|$KtNYzyKk|ycy0_7pc6ZaIu*ZvC1L2&F|%BCCv(| zh_*|=mTB7p{yUkKgSu6<+0zf~t19c;+Mvne5oY%#PX_(RkDpAIdtW{gYJHv>y7>i# zgfb2x>C@nb=UwOEHy^(PW8Djg)$AOtE?pvAjQFPa&70Pf2K>Qa_72W8Dj8%BCu_HyBV^6)UKf<7hd&$)8Z9t^O#L*cTBT0UpqKRQ*Fo8u^ zuuYDGs-h61F@5>#qtv~zLa_#%Z{~Uvk8t`*hjnJB6Z7x7=MuM8IAc9_m(=-xfqDLf zJjlPpJkRs@2kk(9Bj~b>Slyddn!4V!9WF(;0e=Of?oYV?HD?xTsQ^38X%DfB?bYw| z5I&I_wbi%&w_Qe`iBO`I*4U`w$tkX4Q8cYJR$S#jH&+=6$NW_i9at$NlDr4OAu~5~8^8`9HAlR9Qks>3r_n6GW)7|4u^~G!31>cQ#42XEWzYodYHTST&&O z0I#J<)ekJFjnrLn-DYexlG6^b?&r>K%;jzk>zKf$jZB-Fv)NpQ7f~hJ1|=h#RjA{6 z_DJ#ulGU@~m)NxI*`_zt=}bki1P^=Ns>hJ^YbPiU2E2WH75y@E?A8UbPdTCMGag<^ zlaTesn&s$W;#Z|7E;dC!4+MAu^L)CERL0Xgtq53NSC;5Wt4=XXJ6X9%9$P9lhP3Sn z{e2y4xA)#zpr^Dpx~T+X8tcjRNLBPMo~UXXWa2f5RTB8}fYh9YaLGeg{7M9JqrK== zmd>>z@odYkN*og7*?I+%ee_Lp5U9e0Z!;)R(zjh6&g^kGuH6Vs5Mc$d9&aa z{`4S>N$oXPHV|=C(bh^*KO3)+-ifX9CXwd|^dI@SZ_E&BP~nwCVH_3vCj(shrS(%gZFa;>?L-QMNuR}Y}Qm;z7f$G#F*zLdzN`_on^A#@U5SddUOL7e2 zVQU$J`Xyf)D!*mH3I=C>8u!dhrMPHp}qRsGlumm!vFh<%j2GkNM;czB?!>XsNFXfE%AlTivcP zm?vhe#WEMn!%`po@r8 zI6p9+BD%}9gNuT%;%qsLfwc0P-KNaf6WTXewyqXy$Ccz9fH_d%@FC|!r(0-f&lu89 z)Em!!=(?jk8ToS6(steLW@PT=Q#rT%Rgh_MK3=PqrynuRO6QGG)2*iVl_g#;ZJa`yULCkH3d2;zt`25VB-SbIW#?PwBzgrCyTL7Y8pc z+`@|&Mk}+*OJE@F9etCtDKC&~8SZ)rmXQ~FCoav92hS@Rdl-Ux~$Gbo2)#8P25p z$UhJCuLL`mS>MF-BO24f&R72Tuo(F_xcHx8F)3-!->|r+zAk5W`3Nd7`ovgxMh_KBIL!jx40Yw_CTxYZT^ZLZVO9EIx5#}R(Jq}_8-0SOU69*DHikbt1oKr{K`>eO|>*si9p zqPIb|lx|@)A9p!~`Fl|vYq$ZiX^HrL{_DlPbz%_Zms^gLnPSuYFF`a3Iv6^H0VO4( zi}Bm}?c7gCIPY9)GMzAK=EA)(UEPv?Nc<)1$$zlaCxV=zwf276OQI0~4 zZ=MFnZ189yA1^PbKD2n7J;P%Z42GKqqh%PwuK#P&}YI-EVmvq z)b*SmM9d~9CQ{Zu2dZ&(Jr=|#cP29V>rruHe*eg0wOiWd8zpsZ2C`EF4&4 z+xW{k+sY|cwt<`PR^NoEEQ)KgA0^#09){DAx+TIwC<&aT2~`Qwkh0a7nu65>{JNZb z2^`Upge5QD7fn~@A#E)!uEL$E6*d*$O0R8UxllSGbK)#@EM4nEU0q!RgS4b{yY zC58aWjEIPn26k;7k&f-up{|x1fQl*%l-#_V4qUw|1}g`TO?k2iP%z6%2t`q;JgUE|>lu96QMldl+_#|UeJoy%>Ak&3EYp)h&BM21lx z!6J_)OT2}Fh>R+|P~-RSNAPn+m}M~80?II#L%vm6HjqEx9(+?1-ldwVTG&sI)a=Hq zUbpwXMIQIEvwVEk{w|7=f_pd4q=XcQ>kIMBIixX;|s#Fk!cDXz#0h@-tRG+QjW8>iH;M@5kj^8dQRLP+swudapos2-U~CPF`Wkie3c) zO~(?bCQ%iFVI;>st}4F|k6?IV_2y?Jyl_nWH*tMu(>rfj5{jW<3epCYKnQWKtY+^B z68cB)2PSSc#q>y!PekP4;VRQYkkV=}YOCt~6(!zeO?=Dz@rSFNIF}}|>!7H7wG7kPvWjTI*QMoX?}MR*RWnOr<)%$-O3hq8$&;E zVVT!$vQT~w*Ail`dpXQnDwUsbg5f%im|1Qn?@}NK4P&eJo!@KHcl{#toPEerc~&xC zkSy+F{=c{`{q|88pMWcr)tZ@uDct7nse{}x(a|Q3`LLT6KDYK|&o^8L z_uUn^PCWiC(6XHDv+y31iFnIC{bNHg%i!}{2P#1iT35**?#2|8UxoRFqAur?j73qyV*1Aq+LoVnBvn<)g#rQ(CQKZ2yBP{i&w&Dp zWIk^W$x4T)37Cwe8ju|^V2Ea+qo)iyHtL+JnJRHRuC}(;tEHeT8Ensb#3}wlA<31r zmC1qo1k;3XQz>F)T!gC=aZ21nTtXSx49X#a09doTfM-QSp9 zL%qE&NQXgG{gpy+eY7AzaIDpD>h!+-B>JYV%~ zZcOnHU~fBBfxk|P^ej>vtOA>v_d1}>)sZ?R&St>vp()d9Z|DWO)6LZRsh~$p+IEYN z)js@gHa*yD<+GPFd%jVroraiTTHZt@Y3?xXpa8)o#FL?tN;^$2>wQ>QewhS2^T(JN zr^&(hCVU3V4jJA=m71^Qo)Lo5@QbEVQ zv3e>Ar0>fu%QxlQq*S-_dM=E|2<@I7;3IwW&+@cD z!0s**>RhbUGtXBiFgZ*XH%4*ACt_~TPtLGnEc;~m~^P)Zq4hvs!1O6R}R(?>DVPd-+f zQH|7O{(`G|_7B#ln#}xxkl4bkpOjJIl>SQsH3Yzo#DwMLh%6I8VN`oHg|}!Q$+tPg zKFy5oA`O)qfkIR2cP;Hl9=L?z7lXL>0Y%te!W4)fXvCX5&xcBT5!Z=gdy2GQVcU9NcQwNhSu{d2UYir;FMA?ebA?f@}X?(?z^=@xE7YLxsQEO_GW9$0u;H{%#*>tn ztAVj?RixzB{K(Ye^D~9{4)o-}L+7>d-nfnYe94IH$IYcC&A%RY?;%d{wydxVQ!m~t z-r&PemcxRv$~$qcSwRr4sFtn*6!lL5wV*MsaUO5Sc2HLuhSrtu&hnp0+Rc%=^f8vz z1K03J9l4!OiYZgt1Qw*6ePe?h7+u}AvA!AcSX`Qe)d!G$PBzwuJlSKjqNH8n?}WC~ zTnl;J!MPY7l(*6IP;SPdX{CGy6&Dxj6swu2=JqicIy}iC+a}b1*mdxM6A5*GkvjaJ z+ycnIu?y7oysS7}bM2pl)5JoY@v5e_Dfaomh3PPr6|oh|P!J;l`FjZiv2UG`I&xvU zZ9{D$SHWpU*xh60{hn0!A%t!!N)D^+zi&8UL=Gx!DIqbi-8dRdATr_WZQgkCH!WD4 zmfZ4w2zf^L%r?Z?CFD-}%Ddq2UZoe;ISV)R{I56m|I`kkgz!_L3g7uZ6~6Zi>pw=K z3knWAS~#2NxN(QNgGW3|&<_LzP>s?LL3#cen#+?G84df~$C~1fZ-8>|7b%KAD?W6l zxzR092%mdoc-a2ijAZ!r_xGvzZCAJ#?o(;tf~kRuoS1-%ud&lfN5*x8>jy8LK`mf5he8%tJr@^eOOUmToFj+iTpS66=*8vW3?FQE#H~I9m<;f) z)S+?PLxB9k=q_i%{;wv2Ee`=Joh$0_q5sR_L$wZ`qzEw;yA?P_ktU6+IWaNrf*+%! z!`CT&I1#QJ$hp^JCp!Ya%i$^CsG-UQ)z)adN<~ zB*itLD!Dm2Dal*O7N+tp&EV`((q@1clA7vQZm;@SE&F;95C;_cqF@gG9T7bg$uAJIyiW6!HySR+FYr1KBQ=rHqn0_1(YROSw61ZguU~A(h(Ix48#Psmh#T+h0O1+4fWS|gK~)x#`1l-x!t$`JrM6G zv$w(x;?Tq=JtvOE8VGpWs`lG12MP@xy5i!vH;Wc+jxcZRirDf9%)CGa@?Rg10-5h? zTtO;g3=l*A2Ojh^UWt0Dy`2$PDuSwAree@d0gQ5sulUHi$GCqm+^FG^k+9cSG0Pb$ z(xnD$S|PHv^W-vExgNM^OnwNP$uZjLYBoZ=-$ zvsK>i!Uxec%kEOwF4=(6%NMp5E9=SA%ZxX=H26Wenp@F*^m{nsJqsl}+7$B8HB=~h zA);1jJRi4NJKI;;Za#W_Q5@M^Rn>UPA0Ho%JC_R_wz|%`%8r5Yf9w7GSJpp~o$7bn z`)AoR>;_z!XY*earNw5V{s}>WYCA2T=BXF9wJOdDOtveJfC2G88%#ijxJ#*YbVP)Q z!=5NO1^s@Ic*x&igY^PNTH31%-G^RO6%IC-d*c*_qs&}`~dyf>T64cB~pA&Zsn#XRt?4i{N z`O`o9XRpyev>E}*djAsq`rxPgWr6&T0#wys88s;skg_BjofR5cNdJl~OXtjXtb-fF ziP+2*rw&W61FpM@GBc6Pc1xf07={ZSf%(C28<;Z}x_T{tOaKoH&c9rXSmOitrN4u@ z)K>7DkX)+oQ9g!!d>PXZST2F1=847Z)jl5)o}ug)pU@_y;r&Y_7Qdb6i?|rYvg(-` z%4)GGEYsBd5Q|#Nj4F}QX?03`C*m4|RQK^vH5h60vq9p&YE$~(aD1ZtlZijU#Ze3j zF0KH$uw8eFmhuH`u~6yOUWe3Opob41kn?rE=luo-216dfKDdGxn+^~^?{^3u6aJw3 zO|w$Cy--EEcIy}nbxXbJ@J%to-H>5`FD_27`QFfA6dlA|%E}aVZ%6A7aoExN=L2sD z*Nly+1qu!?Ez2La}Z|ja$J7#59wyWV;J^?mLIO!{|kpCLvG&c)_5!8GXA-1B5qPP zVcZR}BQb$v`#zZO3t2kdb*a}~8Os?qZ1v+@8Kn zsdS(vr$xeq$U7oOC>dNg~(OoK8G>lh4;haeDH{(LhE2(DfCd; z_}r=Py>Om}HgBm~U|H@Kd@!k&=3#(k9|WA)6L z!RjzU?~56O^$h|c$xh*REgeMi`LHlb0-2r7;x(#|AC_i2hp>VD79cz6uTMVW#PR@f? zy<`s^*gFIBMT6dr?fro1A4LX*7boxcS*2iOEZlD|A;1oNh-yQ5?+t0J71h7w9}tjbG7g?aK=M@)y(TnJMgHV8m*KrAU`df&@Ffl-;{%@9U4-P28~Bmf%D)0SuiIV zs&I@>f6oSQIVpI{L5|3q3TSVcf3@XPcQu_Ehwd~t9XgLhJzUn!Z6bce&ThR7+PU5a z6`jsOydKw^fU6GTyFCyHEWusvrJ_OiZEbVpu+zxMBymkF=I8T^=Kuv2iGSKf2dC=$ zO)kMI|0Fg1XrMawIaJLUdef5Sq^2J3h2hl9cy5c0Npz?FiW8YPAWn#sGqBiqR4Or7 zRR*X*o1U7@gsz>N$>dP9TF1=Qv{cM;q>}}&x+31N8k`97=aHaYkbm`0YS@$R!aHQW z*ncdje^iNJcnZ6ljr8_Xx}=~$p_TC@S2Ej<-}~PPoYiOP)F5O$oc%LoJUKT3l}&Bw za?UWe7|9)uEok-@T~8L3IDIe?Jloe56`eUYZkbH4p@HNLE)+1sunQPvvmLcr7>qMB zt@kK0wfE0n#b?10Y3FC|)-U&QRzkN&_ua?_l`R)E9#7=FTh zPcf7<$y%X%KK6lwmuwcZ)RePQQ$X9*r|4~Q zT;CIF;){Bv=G6Qj*BGe{NbKwH9J<16sSHR0c1`ZT#zNsLtjz!oDOUfLYKi=7*|JK< zexo%n!z7|<)u5&PFEq00jM(ZP5p~*q8vX1DNn=5j;9mOM)u_D9j4!RYmFEL5G+yQ3 z-rRgSAvHA>J};Ys(8x$a+@jebLB}WrYicUbhiYm5^-y7EqLBziCpG}jn=(qpanoJF z>e&KRC%`miLz2qd1my&4}xpqEPbAejJ zVB@|`ZxWBWNVmDf(ZVWqCNw#t0405sW?(cO=@qC$V3;Rb%#fKaT1uMxK`Se|tg_%; zR8*-q=lBs%)9!lx@7JHFundVAf(x*2s#DkF5Bd{X9%lLK{N#8nc0 zqibf5>^(p<0B~U6bND3@X8b-|(mrL+#PcEt_nk|GAKfsLU{2OE*u%!nm?iiS))d@+ zBK)01ZSUCFn1CA35aKX7JgiO?ic4eFIis^s<;~~?2k%kOvPCn}bJ`w(ARrxa18BF` zRmsq%5NXoTEEKf+@+ohpUf>q1TBR==&%O*A;TLqnwFnIw5HQ@aAkM{sal$kiyeTU| zBHB1Y;c3U78d_uv&yHX>Y8}(^f}02`bMb4!z@#fP9$8#JmaqQuRBb{6k`P&n&#$%t zJ4_(ff3(X1N@NHYJ_OJj+_D;rv4+c z`V&~u<8w!g1j!<4`ojvkujdVXEOLmq@d*OW@$sWUUL(klxJ-z?)qCjV(TLf<9Wiwd zh=t_BsELFDyUuz$CiqgTU3QR>+{L++-~F_r4?im!pWo91ytG&b??ZDs`%Z;#I6-Yd z4A&iSEd(sWO~ZPw^IOBCwV1d#q)hmInVF#OY!xC=afY6ny2Y)JruqYBb7~h!&4(d( zxriGse9$pR!A?&ny?%+Yvaqy)hw`~OJ+tpyabF+U|yFtn9#|C;Gx-Cwd85+h(%Nh_^uZ=3CMGBQ$VML5^xn)@ z+xP&j9e-HZ6!I9dxtDU(h?j|L0OCOKmLPDxf&7i0emokHwaPgrGqUco1;1ZK|D&l* zPEdrqUe}3Ssh=ivIgI433IW=(9njgPxIGDY?0wky)={xyH-OCxla;TAbCS zd>$%qbNb*JADy-tT7G#|`qx$7tlA8{#{?1SvDhr2j1j$`I8Pa(Cw+-BP$OoX-Y!lR39+%bE+)o`l*1gopkS zJ^VL#3Yk^oR>9{UwXw4k^_3RcjI(Zq2LJ9A=^c-nK%k>pAy^F#=N@Fz41>S)KB$f7g$Z(*owx z=2e08^)xOoB#-4vf8l)G?4OsEbRghm*vm+|`DZwERo`-8seNkY}7NF z%K;l#S$Q2?l$$+`3=+!ZyGpKezurEyUU6^ZqClT)deGTT^pH`c!P-q?1!p z&PT_B3)Eeq>0k2 zG^HaQ5?bgz^q%()Id`Gz!r^Wm^ zLS#*J)ouhwePPOR4WB;xW(RRW;ko{#f(D?bE_nF;BQn1yh|@>B$Dhdw~d1+&|A&E*$qDL03CiVV-FayVE;EZHO{+TU(t# zMByOVc$ZNvGH^$yN#h@=+#f+dx=HVDmA33aEV>hy)?bwhv8b0z{JGtJux3%3CJy8S~=;2*Ghg4!OCwrH{ zg&D)Kvoqppb0#31=$BY@9$u*ZiOqTb?ZvhZ1$0j5DXy{-61Wq473syD(ZU~>ACabp}_Yy$`fzL;NP;qdYC+Nu_QDSgP>-I5{!@1dq#UUPH70xM)fLHXOSLT zf3vqOU{M)1dQtkuT9y*b(_CHUekuCt3cRVc)=f=wo6Cn}M69Qg7Li1ix(~bXY8Wix z*88xsH)^PcgSdtdC&9YzEKkszp6+vq{}!R%ZhwbRPl}C=nv%})>)gX0dVd)?wFD~i zdw9CJPw2#EE)Earf}7I~%;+rq+mt7lA3JJ0-8ITD%G1R$4j#^5O?bGvX_H+#`mVz) zAJyr~FYD+!_XD&Kc#NH;ZVW~Q%v>5aa+@2X=`XJZLpai(vym3b%qQfh`A$~RMO-=L zpVR0}Nt?Gce4ao4M_AH(N!jD6lgPpZW{9OM?(N$jLnn${7)=Vw*rSvbc=oxlaCZKT zh~a!oGgam+A%zj|e=PqL9A&@ydD)tEvc+2Fty2+a-cDeFc7Y=>G6DUieKpG9vFE zi`)I_?c37X(G3#V4V^1rBvTT(Rohb#QH;J79HrRY;}<*dUJ1RRlMLTym%f8e{2c#w ztc@947XH2U`7{n(P+VqaC}1Q*#3>-~#l-_sOt|wF6!0H+Xp`QqR!4|t!ulz_)m&PY z$diIaOD&?yj5_*`gkhUZ-Qq2mZe3%lPw>dd(&3H2=98YL^G^1e#k71ka!6h^xi6)E zpwzH6fnPmcxuvdgtRZ=u(>v}76zv>%%OK-~C3ICVsId_rt&I%Z2S##s)&E8Jz z*ztqK^c(z|EOHkj7tF{0NeFpwmg6Vgm^k>;TMmym%EWs`luDLz#Ud)MGj+yHQ8k2_ z9|kp@^>jM7kd3NIVIg&m%0fNfIo9OIq8Pg<^&R>fD`?kAWYDI7Ze6#)Tn!8#j1pHFQ^Ufm2Rfv5S3 zh`wdH$Fg~wOqO(Vt~qL)zd1mov)Jx?6*-K9*mbKDJ>uqs#4O8WBS}AKnNYtcXPui> z`}h9#4xUbb2?_any4YBVD9vU7Q85tF&r>hH9CHtvkNHEpPjB3Aa0llLqy5PK7r%9!S`!*cL@b!|<^7YZp z0&^VeF zJs~;^>X#@iYc(8$>Vj&Om)q*=$?rV|uAWCvXM5o6ggB01SPK#5e)>1qpckIf8(iR5 z(k2~^Nl%xWupVZPh5b2pLNUEc!SpVWav0x=J!kbQV%Q z8QWccWNy8agMVrfU!`s_eg|aOscBPIjcx{G<$>b6EY*pUPZnW3-LdI_mXDX#HC^T=YXj%w(0^cVnjnT>G*lattZXdz$O*|P{cJ!StV+So! z$;X!d%SbRK>1Qh1AZ^Vp=m^79b4CMW*lB5Q4wu?sp*z#N>CDW`_wV0BGbN(6T0~u5 zYA4rEhgMvx8(B{xTF3owxT7*Sm&WtQd`b*2lMtt`KFt3jHy%Lh{DJ2bp-wu~nBpLZe1ABhJJI^+x?e_S$1UCvkH`OwCcF(Q`?%n!v zY5+k#l2eJ2t4i2BT{19h+Md(Ahs~u=YRV}{7{Q`z(Ui6QjAO_n(@Yg@n8-Q>!+#ab;Hnt}>A?i_oO>9h`uvvm(Y4i&Q2R<)Tc z_hVACuVA=D`m%Z8>%oGa_o+Lyc`NWW&AW9X;tRGuo)#z3{xihhQtnKeamqRFDvhbb{p0I3u4&=#DJgttH)kR^$T#7slaDD0fGQ)0?nk_}>onmoi{& z+V_92(mSZyLEdpJKSDHlp(i7|H_htdfjvVUnMxpZAGlYw!{bEm1vtzwtB_e7yBTC8 z5)s)Mc%tJcC7Rme_c@pyNM|Fre!cE#(z9;of17=vt6Y#i;Lp3W267=Gn|^WPC46V_ zwLxveUca?ICI{+BFlNQ0s5&tg_Y*J*bWe0(e!E5q9bb0u2E8wQ!#9pTSBc|Vfq$G3 zzg$Kxxf;SqIJQI{uc-!K;n2D0-xBQ#wK1h?y) z)0#6L$Ui_g+NOZM9)xvUn-`{zwe{96EoJ2%p5%g1zg3*^uWvFh)BAj>b_Do{r4Zv2 zd+orNC7~HSzPc&9kKUuBwpN}7sin}?Pda|^rK?5+Ji@=z5}+GiNc$~2>v`~Ved)Z+ zCkMpo0^Vl7ccF1zjv+)xx74CdJx>dS^M|kkZlHP}*45r~x8J2EZHu$@?tIPB4EwF` zYOa-QqEUU_x5B>&-lO!<2OqUuBRUo+zi}*I{}2uO%3ATi?Tl(hrX#}mGL+_D3n?xs zj<3`Q8{fVA=t&{@Hge|mP{{eLE#&06((^9zTYM{WLL{~E6I6s)HXv1Q9-odsDc${+OfLqkK0An$x5FwciwOiG)h z>v_n|v>~k};dp%@a=P?EJ%D7j2iC?SdXI4|QCk<6A?_i+$j6?Q_Do%d_n|$;y~laP>s0~Fb})U&CIBM zpKaLl{Vd#v1vdTTn@Gd0Pq!hQ{+2>o0{aSZ={smon4MhjryxDN2vM#r^YD`1__)I+ zH(znMRXYK`R}Jvf7u&!x>rBiUc;33q*6XJfU_%agq~$Pr)jqy~gDqo=dTm_bj%m0& zQ>L@4CWkauMs^B{3Jv0@l!H1<5{VA z8{+|Q?ukz$e}Blo@@M~}CWIE_n8#%cW(VwZFXul5bFxkev=bM+8vgdUXS!AL})xeQ6#`2XXe`%!Bi5;48O$RQb!vGLX z(q7{Tlejv=ik<>C1fmLCH8FNa)N4lW3H8K0`l{?jdCg3V37{jP%OH**a_KJKBz#jM z_TINgnC+@U`{r|=1m$}%eg24Uxav%EV)oAlwOf-e(RmHPzlzBwg|s2%-<1!)R&_Y? zI?N$-wkz_zXx@cYH&AMuD|Dw+CIhu?*gEy1FGMghEDGW#1FuZ9#Ew3JR6(qQud37) z(cc6otR=3hR?=ByIhW@-f=hP44cX#47BxR8*EiKyf%hLV3ofQTd+Unpa8thkefNcf zoSk)bgaIx;mx%bb*+ss zd3}qp4y@r_ElN0L)ypg1I#V;a-DH~cq_T?2oMI0(r?2Dk#7y2wz1+$v)0M-LQu!J= zd^D$SV8l@KxbmyAT$>oa+=*fj8L0{X$@~Ks;_AIpE=Iea=eIW%*-W`|^&4HT&7$54 z!5(?Ex*)Yvm`nLzfEnQCR?K|YQA*@=g z2q$wyy;E2fAArXDSD>3#lDmenyEC(V;3b*$8n=dq+Hik=x>2!F^47NW{Xm&Ta07lcy#KpM(mgU zJNHUbjYeUrHksrR7YMvKgFKA6Fq6NWKCg>zUgfBAIR0>T?#mtKdlkcaG@Jqq4hgC!|Feg5`izzN$j%d3#++04a~{Os*)VBuJda~*W(bfH$0YQ+dS(MLhdUn@mY z`cYcSNSMet&;ONGq&W3#BK^xIW9+Q-`Kt^#&DCA#+{oq%6T|?NB@G=Nk?Nx3TN2~r zxxcC8GJ}|PD?Zl88A&nsm>C*}pV>w>+GrElr9VN)k!h*kv#_!>1FsFd9_drrN^uHT z=5KD;s`iar=iB9~DXX17oJ{jZwhc>UM5^<6^d$j3nWMF3vp#Bt+4@)^PAb1qFzG$dxDiC=I@OT9H%y_$Q9B30W?) z`nq>+1q^vv$A80_UDj&l<*gV$q|RiI^L4QygV$au@NlnRnvTmNOFh^5TFEp&+B*=O z_!oPb=M#{2WKR6{I*`=p%7~aGr=own*%<{~RL335nnl&H6)F)LW^UcOwU87RUTtM= zZjQs9*x}90%F4>jti3i^jagY6!U?!Eu%J(-@4uSh4Mraq7#~{I(5pPViD7$#p$pWPxTnKgy21Im=Rp zgRFzQl=HLZ2P}~(Rl<+y;TlGjFOQuKQ{T+cA||q0-CR&|gNdCLR^pktbj)7o z*8{WSdyY}mHef-8RuK<|m;qTV=u8=GPD8YirDYOF$eWCLj!x`;9o`DX@~GyJoHE9J zNM=Jr!_4gLVh<^vd{HynYNrAE2m`Lunik1{?xXM8WCLsDB<(P7OxXA=EGm^F z5Eft6s;`do!xEUurl|0f;S@YyG2LQjY=j*azd0xe)z>rjB#d}eI4J)@B!7p=XKAd0 z49?Ca+rs^3Lv3wWg3Qh01%8y7nFJ!o3%hSh*RbMCflCk1_f(KkUmJDaX|*%Jd;n}~ z=Yju~g6t?vA6OuScTf8=wXI!tXh5VR0Cwp2eGE4+JiJ|7XXoc3`Fj=U@9F$yWCFWM zR{FKE3pN`t*lsf0$Vy^=^fd z?=o?FkN%ypV82jCldM89T?M8>M{f!FGP1RA$byt1LJeCM&7b}rmB0EO2DjruxlRrS zOsgu=j-_^~^owX0B_x%aE0?Qu;`VlP1$pm9KZZD%>A=OSx7u3ZGmxbx?XVozJki?O z8!h+>^Ge+mpwlS@;5cbd-cSbQZhV=hqaG@vu@h_kaE~@t@>*9M9InSxg~V&j)YY4T z+s??YgM&UyFF2VQ=!S}_qLmr9+xs8zHiHz27pV|%lD}FFY{0ha*Ocb7fNG`h2=dHo zj1-N;+1ocYHQ8`5D3!gyNJYLkH8q7iuW_@olP>sYr<=QP4^%2xQ1ZlrQj?Nu(Amt4 zc`HH(58qHJB@bucy8m#bok;W@@Zos*fFf6hMwM}HRT!}43Tg4FKH^`v=ixQ{2-lNz zBtGH5^R6RIic>AV&9s@q;BbZVt;K>V*pY8-FZUnmxwV}iWE9*O{YYZ079pJiPKasL z%PR3e!)-nTnH*UdPPI{&>ACBcvK1ZwWE%Rj*zMnF-4L5;+Ja2W-{Ez6paN$E{N>vo zI@wDdmOFX!xz(YQubGzCR+poQne$^!e{AK3KoPQ0zS+pYUuWawN zs8GEX$o{UUN=~t@-JC~eB0ARsqi_zyEO7A;*kb(s{Z&;|sw*pn5FsHUVc~?2A6sT> zjND4yAJ_28xji~1uaRA{f$_4Do34(|J>$@*r~%~VgFH9X1Hyxj2Xa4JZK>QGa`^7i zv7~%ww%FEEe}f^9gvC0ac^M9fglno|#Eo5K(}T(Sbkr3oRn9%y5qC=W*S0Umfo4uG zvzAIbj!f&vka?tC?#8Yqor62h@bPeShrM|5A~I4Xu6{FNvWuS37G1OCdk#CXrzf-r z(b4;E=6Yz5W25Yw46qIj#WCrCRKPKa+_3@ug}+Q#(fIwVIumb-TXyfPmAe9--GBM$ zNFhLAPdaz=mVMoBt<6IU{FFfn-P!hGW7PO3LnwL>!yw;A77xAEdaXL}!TJR*{Ykln zy6XG(m^u}E0ZjP>Ym~3eH2Tfoosa)Hm{(?D18=9++~>;Iv^M#l!+VdSCJfUN5pS5J zQU3J|vZqd+5)-qcB5SL8d3n&wrb8WzkP=0v^w!44sDm>3uAm88Sc#>^3{dAVb8Q0{ zYP-z%2iMor2O^@}Ur~$rW>(yhM!y;i;aX?X)P(^hX-xJTDigBEO{}C!Q9BcxFFMqOH$SL@s zA9=am``qAzy!K{l#4%aX@Z8lOGP#_!gylA|^J&?qRDubEcFdXg%VS9RcE>QTI#9}- z%2*<<7?71xU|9`8+B_p?OPxviW4Zpfzt-%Wky*LnU1Biky+C;wB{m+_*Hs8h#sfQ3 z+2_ckZ}-eHg6aLyGa(R_spdo#_;mv=zp_m)O8DwqB~K`rz2Fz@2fN=;ewZx zlpN(Vdmw8fu8P{v%BgksjgU!=Nz1st_W_N0wo(_A2`)TpWvY6cv1Ptv;&NjYOSmaZ zr#DhFHoKrHeTql=CA;$J%xPKM#^`G5MZPZkv0;xMHW~|sEVoU9D?v23-bb!+ayl~G zRg3LVR#e@@KJ5pT!nn(Y6?6ga~F!~LQc|6P=W)?`3BEoJftqO*>?1gIQMn)WY) zYZ<~H4gR`{B7f>a`H#D(!z8bCo`jJbro{;kWt5!D;IurjAR0pbZBE+UCt_|sbsRsv zpLIKRV8U4Wz%jj+Rp|{NPbu%DU29mJ)1X} z;k@gKQs3yMNQEWc0nw`i)W*noZn=m;x~;djvs4+mF)B`J|k=Z`6HZ0;4ysZD#AK7)|Bq6!W__B0Fsjj0~jAy^x3+i0iG8WAYCO+UyJboqStU6y z49z$oQaw>37OSC}Mg_}E<$DF)Km35`fizF0}4K* zcV`ZOkcIgA}f=^B84Rf{Cs7L{2kk>+!m0;#6*QzZ)edBIkf|kXBEOXU;1{lnT|yxl8FAu zjY)sJY9=^qxZn+km)VysNN5kRqS z>`k~VAwO}%B~V2?(JcWP5;7PGeet5}MlEjc90Wq0x*~`>T;#^?8A7dK!`9KQVmh-X zE-LVxcf^$WMa+peFO9yeoWvz(M%@$N>G`~p{kvJIdAmuk$*{@fxITytwz$6m2PJE8 zEkpuA>cZoTD`qJ&^W(_Cr5c3xrq8H|mZl?(dz7p1v}k2opKO((Rg=`*3(p3D=Bu#c zH*eoEQh-fQ^n3wsOrd55*Tt!OmbR>3^Upm!u_h+#$tP?)&D*N3-6Al%UL{~z7~K=E zw?^ANhN0>Y5Ym)cH?h;kag7}5`B!J^Y!#|r&8`o&-W~+*-nU- zgGdh|D3muT8?za^GX^ksGoMx9xwe+d*YTD9%hlOdEULKe)= znf}^}w2MZL5N3@TAZ*gr+ry%)2%JT@{q>zLkU#VEDXUk8=L?;dJ?!4)^hPbNkQU>z z2q>DFscBn#yN>1O61_~D62F0%q0^=5eQ~Ui`$IXgxSe@BB_pUIAUw`}n#DsQUhE0R7mZb@2LqL8~5?hv*4f4?Db`E_>m0_9U{iuHFy~~N@kgoJ37IIk^ zU^K6qPpsq&U^|P>3r9~U<2Es8JQWmQIANkwHM3!1|0VJ9_*Rs zvSZ?t7ek;sY3{nc)*q!p-{b#n&ja$Wiyji0=fq*Ac^mmLp$uIM&|$`5utNZlI6XZL zh$8eye?B9)V~eeVdqBYUtiDMLW^hC;g=#d?y0ZPK)2W6DTz2c1dv z(v^{EpxdP*s?EfU4iudX&1B=)&nk^Hy;#(_oBTN^#}`hmEmVExqSub-r>u%>xWl`K zCnoZprpGHLT&BLZwkK&1vT5^}Peh5xq3quqk!TZj*W!9Yw>ly@*^@aQQcWVvt2@*=)VkODTa~+9 z=%zd}-br}AK&%<`AAFu!y}!%ec>g(((S2_InF=8}O^m$A@SPf#TBWBvTQ+X!2#XPV zlYg22$9L?I9wByYk#Fsgm36IF%{43vu-xOoqdw`*Q|%O=Mc*IM)YF5RT1Qh857Tj? zPiwTXkQGRy;96N63)1ZZB zgF($$&>9sLt*@^v%*@2m@#RtvVYZp(&RkEuYnH1{=-e(AcNT6ou>O6xCBT@D^dk|bd#rm~|b1qzKZ2&Kkmvi&Zc zsrb>tN4lDWg~glppVMtoqKmRtWQOVz0?V%-BbV~+e`#v)!8DWOALvJOPQ?UoaP zgol*K@MY$N%j;jn&9V*D#+|iIMXfA4+$RQ3z24~rD&7c{ntP$Ud&H)qsAIf)qn%>| zBM%mLKb*HB*4%e0X!F5`dfV@GA#*q-dDK_ywRH3k$sdGxPJ*-Vg`fQ_jmJwj^M}atZeqR9vdL znT(H!t0YRo#T;Rzty*5Nz~3>bt(q)~7#j~j7&$aL0Qx#Sf{eHq?jvW~wXbOOzg0l> zSWL%VJ94yAKAJ3j%^|nq)^Cu;ch~j|!Ha16UMMooGC90IH_cIRF-D>wj+^N+gbe1p zT5!5{zj1J?6WvSbuuV_mJ1KGM6ep`Ev|qv>90bM18%4G{?V*a7t)}wGy`YP_Vy;(WXqg1>i{#;$E~C z*Q_XMb~$@(w)RR1nQmv?fn18K2h!vE_3Pf}_)-30Ow#LEnO-h_zRzJDY)}`OF(f*V zbsWr&c~Gsq`k3C z?_6!vnPI)L&1vf}eeR*(2XGZt)q0qHQ2m5z_<84)(~Gw5PxDyaG@1Dr+b2PbSecqx z{Z&iU+uDGvj2!>VYyJqVAY&x87>Dyej=c|~Z;Q)@DHXY>2|XsfpeX-z@+bpNAjM&1 zg%G}m^=u}SB~e-myy<< zQk@cG_dd%p$nh?GqZ=om^*ZbS#h#EV({jPP=pc@7Cbq8<2|13zU}R)u0Aspxh)h`+ z97F~uC#_ELuzD!Kl_{0IoM(Nff?;(^bs6I1*2d4fU^|x0HePF5;2QP88WD-`a+^#q zWL@8P*3!fzx}&89#6{i-bd7ej%xqng$NY;|Rj^ZduZr?cBJoO{($9PX=e%26PKl}u z3aJiJ4zs0ac`yZ++0PGYpZuVQHGqN9DBPvU4jY21)oVgZY=`zoGTL($c;1GHd?=Iznoj=LaSvTu|66?w!WDhYe_~cz zJ^iDsrY)OQM6JGXQLIor%=K$NNWBsR?%-@F%rRb*<6T@raoFaUBJ-;d^dS-lFIm~$rhEOaitFfiUac1!9M+mw7^7-?@9b0-GYUbes2+d75 z!il`;5Xu9QnN*}FV`kr76wezlY{;I3$-{IO0R{+wyoHkaS%-<3)qINXyruI*z38yFywz+)TfSM} zxO;H(Y6ZIX=YR@?8%(D_e8Z^%->)w?6#`;F{{G;>+S=Mb5E&UOWIcXNO0r`A@gvqN z<~KAPbiU;|wg-ikq4Q#D`3P6{csuy_TvQ~}OJ$;ZK24>6{;Usv7u2PWl|*cudv2s0 z7zG2hz`*4*V0~I1JgTYrranCbG;Z}(pA>Cw*TW3owXzc9VO5F+`3y}zGRct~RwczqVrGS&#dcWQi=->zl7ikDj8--BKei_YKsv_ULg;*P-UK z+PBsqvhyQMU7zFP1T6_&!(g4G$bmQL^cx&@o!G5yY6_NOD@Vwsen28v%KCte{KHH~ z%jo+ivAv7GC=8MwNpV?8R9;WsP(I(Q#DGjD!wUhg1r8%BEF8KVio_fGBS+<8+}Z^^ z*!#YYGc4?bJOjq{dbghd!e1S=|I+|}w9vJ^dXvkvFgkBbXNBzq)B2q#KR2RHYX|*b}!>gbZCDbdH`HJeOaya<%Y$KT@QzKJjbn>Xx!QfJwpL-rm&o zXy}zvG6misC=`byd#eW{BO}&+-j)0{m}#jmYOdSi7C^C?i;9*(+J)8`>5&j$x}M=g zQch&8r1P_tA{oj3&cBY|?dm`B8=n;tII>^lSiadg`v)3&dj4mp5AQ+1QN*~9yBab@ z_uaerTgnC zhYOW6K+;?67~6&mR{*Mfya2+(XiN!g!w+BGGuYTuPiy|V`Rboiu?-jp^~EyAWDcB_ zZoM7>eW{`>vNS{V1;GaLdpuWkJX4-6Q<~{E{fePLSJ9e#`&s$G7q92iOPf*Jbul(j32<6}{O3@J7>-V^*yRfhj z4wPRI4j?$x`nNKi%z)flnIEk>Bi_=Q;gmEBF<~#QWgER6SjwTGKtg^w=WD;>+nNPH z$+Y`iDv^S!>j&YrkMeXhUYvf&oMDdz{Iar>##dtId2XdY=_}4IHRH${Np{Gn)+2h$6grmL?=?;EffRW;sMe@m*sjoP;QDCWiDwV0s+6OcoB%_! zwzkG%u@KY%NDmk)4N^ezcHy8nE%HdLwzHEOsMkRwsF10^NT~MyNqTo2&g3Ug+RQ@N z+<-Vik2azMq|;`NZv0N(i$nu4o#@9Ie#-h4ByaUd+|O}zN+O-j#&br&mvJ1?)8l(y zU9IwjPC79Np9i##vN2&JllvL$Nf<1x)Uw`qmn?6+uBV5Qlw^$9GXP?v<(|wZWO0;m zStAQb{q&%7iVAC+NevClPa~~k`K#}y;pMS9<@*xhf?!KNzNi;3K({l<3yS9p57!>* zy63s0&SBVF#N~|j9c-PW*bT~(`RH*X=$xOOy9}P^e-@+0mfJZGXHr!+M8@q(`2xjJ zcN!@h)1^UF)z{x@2A=SgaLC-FHHndKZ!1*xIzH$pp zbS~t4U6Oyi-s^SsRi4Efh*Tl{IT3<8wQ9aPrtWhd4qUWW4&^%-_}!wS=)!1Uy^c#( z>-)>TQb&`1QrLCA)bFZJy1-!5j{j{+GD>DjVM-PLe?R`YT+1ru;mr`WJa-7{ z(N>Mxztt0&zIE67tmHGn>0{bNsqNO(wq1+bxXgf(GXU+V@uhU>!us-coBQZ{EXS^~ z`t^Sw^e+2kD#xNgz3O4ubcaP!4d~HKsDqnePaDEH z!6yi~OLlA=JnER{=!u1J`GPU5f>)d;@7Bqb=RYBMoqS9N&%Oxi1U(d0$b3u9hnxpV zUI)X$IVMT{b~OC7MRC)jFF$l5WHa~)r|(ZayM}A>&6yIBsqGxU^6k%{vA~ULx+;gW z%d;w%q{Y^6G<6!%4F3;)7QlaIe|4#LecHTK7`}C-!$#gXn&oBiC%^^4<~Ipj6X%SG zkWgiH_1kOjVf2ClOhago-}$2M$*wM>tDvAD!g)U5_RWAtYPz0N9ETy9riIxT8r%1y ztP%cqu0q)8i5({;CHqUsdnwf7vRhC>XFwpck3@;cE@X3Ce{QD{;uZ^j^I1r{GhYI% zurVHNY;68dpO%uXfwbE;xCU3bE~qPYbQD!7kQXxh@d_qT;DVP9;_kY2^1*ZHK75^z zx$XoZBCm<)<#_U~%G7B3wi&qol6F9Xmr2xfbmIPqpm?)iHa1!a9hg{O0kSfleQ@Zm zgB>*NjSBhWhKl28XYo6ze1>F|tJ3}IT^m;K>cc!d@IV(>EN$&@pr`-9IFSDUawM&p zcR@BU49E1g-el9W@KeC+7Z_2JgI4JP^Qan@x+Q{VWTxts1)He!QxoYY76`{@HFV8>C|7u0MFI#!-YAbv*VeH{Z;5Sr*>_j z^;M#vPuY4M*}Cbm{yLU_722jvhkL#%C&5PRJB8B>Zs7CzAj1U=9X=%^BO?UnI=INl z*3DB$@y4;{^OC`bEPDm|3+`N ziQN`&lem4d&0c5^H{2@W;oyFHyNtho|2rVly!~qwE;sWtn^UrrZ6DA;xgJ-f;N1@1 znp(oD^G6%6mY~wH%mhzqxb2Tz)N&Y7QLUAn^RsNhvAk7%ujx zbTnk~m)#0xs@dDQzkD`%Zg!TkaZ8lmVL^59*ZVv76nhiVfQo@6x?hCud22(%Mv?;& z2By-|^P-2ZTW+oxx#{7BDCZnzoKtKCdhiyt|EWMQ(?xc-ow!*Dha|}tKzT^=^E>Ck z{Fl~~rJo6uLpejlqNX5iA*ig$)nLfv_$GXmJeHAn{k+)RNgFbY`oz$XwWtYT3u>RVeiA(xXb2n-+0nM$exB*EEc&FI)~ zRZ>?X-Vd_CBhk>(;-1R(gyecVGE1km#V!4yz{vYjTh1)HmTkhKMiuI2U-$SXKlwm@ zs%E9jTr?E6$}!toTT8b+^gZ3^<@uv|I!O|rULJ$ zn9UzQKqf5Y7#(T1PI+=R_Mi|a|BxM{ui(s@ji~ma(dU_RTc$V0R_dBC_TG`**P_Bg z`F!R8+qs}{X?d595g&>2*PZ1>*U#_BHZ4vV27dC%sb^Ym`h(MsZ7%;{tY2nFw%+wb zPz4DuXpHm99hL~Z8%r3?A*wt8e^=tJaz+nnl|cS9{>ReQ)fSHmdcX(Q_|3aC-%Zp z@yAwS(hXZh3$F!Am~V_P*X=1^@;#U80ul1uzWv20q>z?oI_cO3Ik%VcG0$9^0Wu$q zIbnHh7S8G6=r?alaK$Yvc^TfJ*u0w9P;Wny<21Hsd|()d@OQ|H1X~2wNQ|L27(!48 zYq!&R9U@w?Dmf|KUbkTOb(=K_9KoD{3scz*O-=lO5x@9>PW3VM-=AxeXwf~T*N_lrBxZTMx+IWi zCms^9px^1WJ8_C3JKAJ-WKdyl^x?2LBh}MMajm9BTB50u4{koxQptLEmHPee4|PIu z_UhNfUFk2M-ow7~4tKJ&oM;O8XJr3A$Z)IV@Ci%dB z+JW@p3;h2gWXMlSyG-;`yn~<^LBt_P7=R1a*uM#KY3s}}MJ+`i#cah9zkjjLjCGF6 z$(8xTHZ!+t?&Pm+rh1%BWI3_^Y->x);Ba_ZNU3tOt+(Zp+>w{qry90-w{wt1httP| zY1eIC`1?KneLW~M)K@weKzyCp{f0Z6D3g9H_YIrtF&uQ4;Yx zr8gTbhP3yeaj|9arw0YC9#ZTW#)cqX!c570@rX8vs&n8u?Pxd(2b)d7j%yp zP_S|9AcXqBT4Tu{kv;Th|M+t?2;t1-J~~rD`rBg4a^yM)-(t6Y7Sgl?dQ`z;hb zvZagMkXBO?-s|*qilwgcWshrDrIPGBY}$@!q4UP9GAYFyv`NJ@&tqa-D{F)nreWGC z=s{R##8+aYH}BV{VOkhGSx430d-e(`L7LV*dV@Xlxrmx4HuZw5^UkYlb2TG&B?&{ItFxzq~Idp1<%jlTg6V5?~7Z13wGCf>xV!Y^3P$0^=DAY^O4oG33p3B8=8=UD7|Ppp!a5HsUs}qQ!*jSYI!ulpY!SJge!NcbcQLwYT}yL`1chPsE!xNaVTRtU_n1*H76ts#G;97k?5(Sp{kl z98686I#eW+;zD0wneH_%_SlY8^(07YuoascGR=-wSY|a+)22@h1XuL|0!e&=h*^57 zVsfEdThWbEQsJ2t=G5UVqrZl7(i-jZF8`)tuRhNeU06MJAwD;W_x6E zWyq&wd%uoN*>gpLms|r5VAqgzr>vO#M&3Qm|V_J1#85d6eb+sM(mseX6?P}vl*lWQp%rh3g=jYX? z(ml6*|G9hmaSVgrjwsNk(Mo0+Uf0Xt50nP!q~Vv?SO)O?_k@M9gPIzejTfh0IHX=6 zG-uqWl*Gh8@6EE=G8G$6>_t6vih(S8#L@OLyZ3{Q=~?(EJo6Ay0%bA8tq%*MM*_YW zYP!TMiH?tze&WIh)HfcP8di(zsjji;6McH~CUtYb)Us6D3P{Xya#G#y8v#q2uWG6~Pm5uW4a0c`$qe71?F ziJwWJNvKH_s3%-pTx@J?oSa^c4}b#078C0cmS1K}Ndc*jz@27V0l~N{;uc?ertUNa z{&9rWhhF#Ql+dt+qf*B|0q7S}mJ^1bwxty+r;itt=U#BLff0A?H>pVQ_+I3)ncjuL z0%8)qU>%SjAMX=v{m^l^-=*YmiC;~XVZivo!h#;114;4q^30t6zgaat-TZL{FWb3Z zi;%QJPX|#XiAF+pmdAsXm89-aka83OCsP3lGRI3kX8{FMa@J0O(;xMf&e| z&6AmsF|~kU{aNG7 zsVGI*by?KqcBpkW4bp||TxTi{qP=NS+KzQ8ZJz_i-_I}RIr1t293g+O?03&P>uPD8 zZ9l(lKGfN*{m3Ks-H&tGCNJIqx3;}i=R4FYkjgX4J(7*}_3oR(5RR=Z@ z={r7Q)UiS{0%EgxQ*cRfy!@7EU`@?>Dh$h@+NP??kf150N+I7SjE<=2Fu%biC5#|0 zv#*7GCm@p4?aeE!injK4ubH7pIoGx-%eWjZUEAV;S?K{M)Np1ioVFHZN8Y#{MvN;xqNV2v2_#PMs|Ws6yU zwScCLX8#4rnN>p|4E{g*I$&;KTYtDMc9l(kY;~AFZFSZVFY$GB%y@4a9UXP%;<+<7 z{<7iy`vvbAEO^Kr-*?Bvupw)sgFj`rkh!4;y4%}rzb|*Xu-wV;{AsyM_)+_h%p>tnjY*^|dm?1+%^-2{0pi3XCR|Os}29|UP$2NL} zwv7ubL$o91BCKd%*igpBYvuqH`3cIA?E3mkZ39PAB#8?>WnXsU;6oD;BiWZ-jh>&I zv)Nr{aPWJT;hQX*KA^#ADJBeH-|zt~M~87$P(8-j1KPjF_V$qknDj27gP(HyE*g?cnvQ*UJg)3w12 zyxlF{sRf+&rY4M)e?{9j=+c~KI1I;SGK5M6i&?J5#)66S#kl>}XWXh!LSpEdIFNO* zpFbZa5BOR*TydY2q*-b~P4}GB5-9hJ`(-0v!bJ8PgnIq{z$U~H1`ax5ll+=WhFlgyNy0o8Jt&5B%gdn;1cm{|^) z2SbmCf|<%rvVnWuGxG*ztpB?+afw;-yNJAB9j&-V_Ipav6wi^KQ4@h0nVJ*)l#R!E zzf|$}&7NmK<1!8uRYq3Zh<7BI7KgEZ{6KP?57Hqe)2U0*N*#8#d8e@ew{p*(-UYS?Q%0K#qA_5r5m{=c-=v_#VCF% z)Ieol)AIa22+GI2^ImhlyeZBW772p)QfSQ0@P8?7`-`#-29domh=2;WIMQGb69H2_ zi7#b@0{wTu^vcQ#Wb^{Cx$X!04NMRi}~uGPG5-*agdN;q3tfc_%r7|h>@hMnzW%!BJ?B z&-vJHD@Q9UD}DX0>fGhd%pYK}Xs6NN*2t{h7sWtZPAr6EslEZ!?Sb3t>@KNRbA}S zxZ^=y7at{_kMz-(rYzWcD+=_uyv>EhmnwPhWPzf33!7aEaG+IRSYsPj;`b*CmOh03 zM*5eW{8wC5kjf3xp~>o$jTJqJjGS%QHrwE-iW7k>B4TbD77gGyQ{KhX4;%Ijmw(AA zw9qwE-5#o5DP_=NVZU!yM%Fcuuelt5+2HKyT}ac}6>`rSFIL?MS-dJ#n9ZW~Q2*@q zL!U3%T3dhl=vjNf%tcvVD%<~k_lX1BUCS1{40e0=1scAMNnG>=Y;}FhjFu;81&1wO z7v-oOc=`T6><1z$93?$ZXFI%kN+&$$!am82jNQkm|fCTc~S1zPaKZWS;)!? z>=>gRkf4f7OG|It<|7|j!OFfOO_LqbJo&SE`m!A&}y-@f>qu+YY4cX68Myu+s*%p})sTlOqHJruT7 zq(1x7DCs^J7_FtcUMBRIMA@0%6H)o;Am$I_sgfhoO$D)mj=IqcvxRJDA8Nk%3Govb z;5onAT%F})=0VBg@~ukF-IlA!_kTJW^W(u7ND5(HB4qs0E6>`!pAojcZzRY*4DIfK z=!3fYHcROCLYGBh8n+oig#f0Kn?Y|hZA59{yb~zlah}cHx(xTvsxO4nQueNWYL~5JU<*YOCK>~-5_fIi?yDHZ&dv@n!!2f0OH zn1c2WI%gcw>F(|h;*`hvcW&FZO}u5K69l;&O=v)ESY zX_Nv==W2KPhziS;2ZKhe65Eay33@oMDE>~Qt1HuqH2CC9ei)CG!w#Q=7vGT86}ukX z{{CJ3f*={nyI{nIypuJ|LKVStc8Q8Qb9Y8U&*0T7i0q&*1~Q$XD(m?QcIvM4DX6GG zpj4FwU_r^no=&%rtaTpCg@)zTftUE4&vpS^HyR=@zX*p#!k{E~BkePcpd0Zmlo`lu zsPzt*Htn#F-+#|xtrI7ndKozyxuMvDb)TzXtJR!cI_VpstX@P^b~W>qD?xXbj=8J@ zZa$(|GBe~bbcYX^fVQ+H;V>Vw;?y=TEYBVN^0^hR!5}JQ==h)#13yvu+GkWpcG=t3 zN2K?WYteFD^%A|wPn>ThbAhQMj7Tn#tbmdoG7Bi#S00B6D`6p_hm~EBdVumJyan(4 z(wPVsi#xP-5}R|#gA!QOuc8Va&3U%wZ&xFRo9!BfLO87{icbB*0$Tle_HrAXbw4p1 zm*rV=Y1id|%f!oS%RFDb&d@Tc%JT!7IbGP1osT*KBWflF)Ap5ubOQLvhEv^32p z3RgaE0Eg;9g1xa(8ygN%d7ojX^o>yp?BXc=Q1NRs3O`EZAdiziJ!kIE^Eiv)ALVh# zv}v+pnZEhDt46a|e@2J|z@;9>ziH(y)V4`&Y;cBEliJvOmZW5* zrtVCUP1%dpW6n6DK3ApmaqJ9fZOetQmQ6fIZiHuCVaf8(;dDe|=@g`9p8s}PLQ{oH zuJ3JD1qP!IotKoaJ#*|_iV!-x8oh+k)5YCkzBFO;ag%KRMc3ci{5O-IBaAEra?G+9 z=3Xxjb+y`p!{0qVW#wY;jIub{CNiM4C<<*bDFa%u-@EJ^3LS!GK>laz<8Dao;l#Yt zV&V~iZ72=RN~i=nW5dkbYd?T-k-x%mt6jy`X2?dZ`WHB^9e_)a8knCC*lTh0V@4C4 z;4K*3>P@V_|D|piwc>enD@JO))3$w21wzeO3smQx>Kf@7oiRFRWS-K+Fk{8^c$T#> zJhmrXb#EBT>(1OUu$pXxyUo~DEmrXl#c83VfT%*F2wDpK&q@|)V}@dzDdwwEju)>)23PTd_^?qa$8p>w0+-SAYS|h#*G!&T(heig;w@o_dQLJJ3Lo89Va+ zV;HQpM%U|D)0G}3fcfgnq_tltyI1r>5T>QD;RaU8TrVvZc8DObc+sF4j_T~A?C;td zI{SNIQnzbG3b?#U>~AA=wAzAmmA=f1Tv#2o=p*J?==?7`Hp3*^#%9Cuy)?dt=;HCO zYNq!cqF*kkcy{ta!%r8@gM(+L?1epBl{J@yNS?T!w1P=0K z`Uno%V^_M{e{vDE&*a6EM?0ADCk)UGeS9<~V&RoNYg0Uc zgAYvni;{}qeHR=NgL?xgEjWH7b!nK6vAuK7-?DqI#ix__*-l>Q$$lK+KzD^As4s$@ zHB+>&=gqWUvncvqHXnP}26f<*Avl2x7LT9jZ+u(0w#L^Ai>^%l>WEa_?`*p?e@DW< z<3uB0Nzt7->spbnlZnF@jj4$Zau&`g^|3aK(QUC9{$aO8kWNpAAao_|%8LDZtaJp6 zV5JoSn=YPF=T|)Xyr>R%1Vy|syFU@x)rnVS%xWTv? zuuimebY9(ZgapXKVjGNpLMQ-0e95(ol4jhU%A2ZMT9Dz6roa|b8yYwK=TpAK+YR?$ z5fyL2wak8t6jt`6->-x*|BN_V8=sVLNH(QEvH#=s)~wd2W?~n0|R?|j);B`X@#T`k_def4)1(9fQ&rANH1(!1{GRHUDL?T`SeTz zBI%3rTo~qpJd*Q%;LcFyw}*Ci!Zr%+Qkbr5Ey{!0Is_fAgPnkT9c5$h1O**}74)8- zfO5U#5;TNVI)1KcA-;ggjIeYMr}jG^CLW&5Ii2P@T+PGe+l-Y3=#~681YLTfxNj$N zhIQTqiXhN12}MZz2Pnce5=bMQxlpF!(A8=Wdesr3RBIBfPO1IeGtm5Er*ms=e+#iW zUloQLGd{uuJ3vUEFW&1nOkv5|djV*7K)!<_?Tw{Vzu`$i!ODL9(#0R2zQ|kf<$ZyP ztB@tuhY??V6j{20r@EwQK-S5D7f5rKA>%!p<1!t-?`Jrl|0%)tm-w}A4%b@kVSI&s ze7ho49xy-l(RdeQek@_&{ri)82Ebe<(UpXKhn ziQK#iUC`=k)f-uXfq_tuRdx-Pl#~E!2M~IGYlj=WeCYJ5n>Ra?LX=QS8#V;z{ftzd zy)?7cmc8qN{7_lJ(4(5~`iB`0Gm(iN8{vF> z>@uCgO36nTW&+*AXR2HMCo9drwMqYY*0|*7wm5TO!WNOA8>1F?C&~wJB`{2}KO^MD zML1hKbWdT=aCuoveySr{)YdNT$HVvv3`}WTXpc+|na*!eAOSsArxl#XW?+bm7u+X@F-vfHiKY{_@w;KH_NzuY}>x)^qbj}J6qstGI`=B)qHLMdz zOdNO*ULMpv9vwG6efqSMljI7|{Sj|2?3Ud9g=RQl9@daW7%HnolDF3#63?#)@gGc&W>*O|O7YQb7*=i&t3CgcHqOxp1X4bq#!W$0Wnk6g0#&baUD3-#6^K4MR zwTWrbMf-V9GI(yzMh|ub!HhgdTJLkWuzYdK^D0XKLE}cJ$2L75Y)RLtlo5yZd(ZVa zI%c*I3e_ce6uoI*S~K3Pd}lk9#F?s--ym&*TbKW4V5E2(G$#9C8Rdb9dY6FKgw(q* zAOM~=D2Rh}epxEkeORLiN$UKFNj*S&vtrczx&(XJ{!GG>Ok|yU+jZ?~D@CSN81(a0 z>fR>V)mJ~fGgq>0>#mVhcWrhoGg`2FEC>G81?gK^yjUTY3XJxp89Oj1o1Pdib&xYL zJ$>%nqv)9-rDyZ=^8r5vZD+7^1VLba*W(2sa!pN5E;#6H_YAWMnM%LQYFBRXI+G`- zIHzGf5;2@G9Qkd>!TGBi(WfTFr|-%N$~k$VSr9JiD%IdQig3ol*mBOs0Mk}IHIo1uJW2y3>MR#1%N?bmc&5m|ot zy0(vi<^F{3T~U~Y^rw8!t+*^qio09~LAHz3&M&CuZ`X7sa*hOMCj*ZL;&*e5@ zN+EskT)q%WnYDOa2-ok;3++BwFhaD%;eBJP3$z@r@`!OXT9l;2Yp6l?#>>g{-iqMO zSM&<>L6fDnNr#>8n8$EXeP6Yk99^QT2HO*zUW|!!COFpYujE-LeJie+LH;4S{n{FX| zdzXbVWiZV)!aNl>@JINDhzFX7o#<0(;D=#I6WIJP5_bCZo;+Veks!zp83V^gJL-XS z($KJa!5oSUt{gAXP(!+zZpqbYDkofA_})!#|Iwh&NqPABma0u-`x;z1eLPxn*2x*> z`_xq8g&P{mp=4g+S-8!Ay@ZI!ZN;c|x4QFc+%SWOn3*X`&l|Mg)ZI9jEH_s+{w-4C zPM!a;X2#Hn;;@=U-a0<|9X&L9(`hhY^CV>X9K{L&z8CoUeWzzh5xN$!E3p84*3o}JvfXzny?dyQIKd#qzu3t@R? zjC`oVO-g6PpXrYr8{QOKYTI&|ljA7YIXB~4gyoR<^mKKvFgTg@u~OeGO>A_3pW!KI z%|R?zk*Ms=O609OHTFZ=?9QZ)jejsss_nV}+$Z#t;Sn+0NTuKWP+Lrvy$X}&@m;K9 znfyhYWoKSk4hH5rTxP7&$z_^(jR8YJ&o!2AVXt2weT0mgm?XFNzID(k1PCQNyJ29& z&c-H}`YaOeT{@?6gGI?mLE%Y9{gjsjq!pGn-sAQqW>fEwq2pB$YA0-KZA)^>lU=iD z!JPJJXk`~J2Dy+z{i9xwI5q6!I1R*VEMMaB_*CQdmap)Vlw0p)wquO%QePlK`g3j} z!i{Md=bo`MYthqz8wQdf{z~`Za?zhp`+3)llubS98~#X$xr1k^Ae-^ada}G;%idNL zddzjsdw%pE?tID*!-C;D>Fr}SVURgNaR;}rO~QWHU7-EK3QTBWGuT!ztIEmRAW;!j zW_w-+86$OEj%UN!@6XG^b|3T`lxp$PR=t-#v_QsEB%}3?d2x7JyoaW@%e%Gt`@Ot4 z*NYtuSKb85!>ylTToFnht%h>Tm+_%TRH|QR%?#u2lo|Y3Hrt3i77@Dw`~=;m(mN)e zr14Dk{0itGUOjaOw_v#+RqHl5&FUi2UgPErTF#r5TWjYRae2TS5CHe`R26j?#+R!j zD;ieY*Alo;7!i;ah_?_K!6RS0HjktkTBr}hAgMFCZXO`RvK>dq%g@4E21ZCuh7IDl z&uR%XbNf0CNJN+S>OMp7R1M46ONK9rm$c;V*nn?^$42%OX&ygA|L-&2~knLd`+*5DuoB$$!x%MU!fio9%`9uw+T+6L%@=LA7cpj zCY*-jZZM|ATF2U!8(Z3pRjqPoq@+J0bLTIHvpvUsg>_-gxo zrTE-yLrbF^r1B|RZ0W_)ErkA8US&eqa`w5i;@}}7K*d3Uw>`S>i7#`JgCCUV??)=~niRtj`onz-V!sl@jJ>O4DRZYhvEU^fFKaST@v?HN{&KCaGVh7xH!R42l-8q}5JuMOyM zYgZH8M~{_E4PuNKCM8VP^SZ?82{G*E0T5-O$FNWFeTHHW)t)?z);iO~r0iimXOY12 zFzk8OKnXn`Uo()hoj7xYL$-V-{oSW?r?z-!LhEMJSL@2L^oR#<0Zazj9 zV5;~+W?i8QyiZei)%CUaW*m(18YDgvJ7G?TcdNVBv|O#}7Ts)ls+~9^MXFYHK1AwB zyia(FQ&tB2yTC9=Mxs^KviF!OGgU(du(r`CF$%0J6T-7u7B0Gr@-s_TN(z$ZC zkZo%}r7lC0U_f^- zd~ZNEf6;(W@0df)G08|G%*Ylm5gv-1lm#*j$XNh!JV8wE?VDmj7gWd^UV)rDV-FoW z{_sgZ##M1H8mvMBYmB8gu%j+7cK9wtRQjV_@KzO;72UC8<<(PEk>kpv=7+9ps|vI{ zj*k1CvU8%Ke8^HwEo`9d-;qZqJYFzrb zzTF+Z&Ka!-d%6gLeSLUP`tW?EUtUaw#q2(3*0L3zO-8-@Ie0itm753NvF*Uj4MCP( zDI=jFDyd`Jc*bOdW($mGW8+J}^bI=P%*Q3J#i_NPGU<-X^qrI&eLrQ_yc5qP%a7xI)}*c)vn&?_$lExnRjCY4@Hv6L-j zF^GJ=hw2DPw01YkEp2}mSb(T{E%8Rdax7s;x!!vV=7jaxMIt%{$C26@DH#OG1BwjC zp*E$gbd(Iurk>SLV80csT9k_E6YCeYa74YLK>Hj0*9}!inC7i=J**7JU9~!J!DeO- zH8KD;G(SDy9dmiyW=PE-foC*H7O#$4|lTcgG=D^tfQw{LZBMT7QC zadR=H!4LdvI$7&i}IXra>!_E zsG?l%xaHI*s)QMom(f$+>C1QQjLhh!b%wGHUb+F4WJaQ=?@gk()FF;ZYz9i26PccL zEhI^^O=a|et*FnHI=1bB?97w<#ShO764z(VG-Vo1Al%8+mHnr|$>HqItwUbB+NK95 zWLkXajV3+Gqg^E_ z-2hvR&STYPF^uM9oi`UIZXX}Z+GLNCzH~%Tw#O+|jj$ne4eA!+d;W1HWmCp~3Mwh7 zOc;Y;R2)EDK+zv*EFG2sShJu2hzlrhVatm79xsTjLywZV8rYCL$Rl*U&PYdWyAZQJ z+;CQm9|6R>Lm0)>CcLy3YpSVKmBY{r);gJ_Kz+SJZYZGv*W~s_r+wMj*i*6S!=-15 z?6=|QVZ}5CDYByhN~LCumtIM=T@U<&mw5$p=`C{jXj_aX>8eiY>JhBys+kZhGFxv6 zSQ@mWkOT{wwa0N^{ZW>uKKi#=UZ1&jk$pQIhOi*SJ$*)CwaR_^0YxJ24NH!7_#@iv zV^f3CK%q1z1S863G#Dj$7|58AHHc0sDiDlTU>g0)R_-wzmRJ_H{~F;gph9#6Npcc` zq|H>{Gu%8Zx_*A9X0>)Arq8rHFW+JoID=q0Uk)fK8ZV>i;PaT%ou&y)AxQeYsF2KW z(8Os_+6j=4yj_Trwewq{RRT5Y$^~;~Fk#DU-_)g&Lp<-YrI|@J3h7aCG+lH3O{SsC zciS{SQ6pV&7=uvMreltVqNn4b$oV6LB3gm&ZD)gtP~@oEP@aTMrH7(Rh>iB3+_l#W zT#t4=SgX(Lv$-8Tq`DkAy04DGPbvjfTz4&a@uVfRx1c)SJ^_SguYevZ2(zD9L?oA9x7JY3&fZ z^p=5v?rsOl<-_QMiB+Yw-Wgz+l)c*f0{i^nw(w^qJUczc%O=O~%BJ2}df8+E$L9Bk zK2oIX?+n5*iIkOe=T_oLC7eY(2B6{^TmG1 zAy5yZwiyBzJ_Gl%PY|^`KR7t^W1{e{>97(;BGwmhznTtcwxHu+Ujd3(mtTxb_s#(J zcgJwHiJdf(2QRmBg$sQ_y_Nc?pX*H@^(_zMy35zc@D?$125U7(zvbpuvyCXGM)5Ab>)6%Igk>A7bW*`( zs5$_gSsdjFa2maQ$21lhpQYOwnA!5IZ)TP@VP?qR+8KUE3zDd=$THL$Hbj`){#?@8 z<|Arn&S=Wl+&XS&c70%HYy~d2a!*az8Tkm<86VxwMv_zUgnYN_3tU;cIM?Z)_TlIN z0Fb3a$`Tn*Xtlp0?VN(Lo|edA0Fz2RSt{-)SriniszAo%8jGe6CpW6efNdeaVq1S< zTA^$FE^?o;P;Ex;9+a_&scopr1qdc5TWUbJx3hPU-5ch>d0xcje?4bf=5tShgz7Yy7aZ9UvFU);1zK# zw`XO>oDLO`9msx!5#(R#p?wPxaQymg?^)xnUu|Aoe_spur4ySPQApjKTzB3UdNm=6 zupo~iSPY%)3%kz`$YRACo=`sF!F5QFbu1U#yt~>bW7z3gS^JNyYLL4gwSypU-0$j<;Spxf#mUm7h4ey{!Nth4f_*f z{LSB0=UC9}BetDPVE20T}E(_Qtp+}_=99Y)6t9LZvwtof(6)y+)e0WP9Gw%`op{kI)a%_G9tUF1>d z9s=1K+A?~2dYhK9%()D=2~V)Gw(WDle*}ycg})v>8)@mexd4fbC%F5Ut#9;Yi^@mF zEEx$v)H7_yew?tiwnK!d=i#6Cg>fMGTbqT6LHbqpJ2S3=b(p{9aCVxo~iK*NzQ3u1TfTjcoa+fNUbLu0`9kZD;@XK zF>ZN*QC=<{J2%K!KP%6KNz+f7ho1pQ$23fd&cut7c9hZrZQ(WQv3@2@^;V5~ABiY( ztyUCKcq9GM-3fR}wkz&6*qLSw*cmd#(3ZNL-z6a}4eP2vD4ikIar()L-JEH5-*>Ov z(C!s!PbQvSu|rVmh4;M${kuCFETc_(!fPUUYzwk)jjS6u*sQ*38Av*T^bgEST)dbO zP1)jjfatA?Y&L!heXFqR)`;0+2J+Wp-<-Uj?l=T2|7B?vwngpS-U-lRGG?K@=BEM7 zcv5X;xx|4U!E)jV^FJuK+&7ig{qVwE*GD~jDqhhB_mK-yL_0yY5=aqw^v#VRMO0E5 z+5gUNGv;`pqVOKR?gm|^dN-2qJ@g_1s%#=i31sDBUW-V1FNkcfe6@TcS1K|X-bDw_ zwaO|lHNj{QeN^wkz4= z24Smj!8VDc39N4L^E9S{<3K^mdP2GB{0f6o4**dD7l|-0 zLmFFd7pU40?$1bxKF?`ssp|K&TN8bwy17E4K4B@~$3V9M2w9C;{BEf+vjgxuK^d6a zTW*~XP?tcOwy6oCWOi1TF75qW)D5tv0vzPnrvF$kRJn)KjW?~z5Ti?UU$WBj+dv%5>|uV?D6DQpP5+LrU>gJ@zwPo2es;UQ8nk!S^so>!;Q zJ9p#8jRNv*IfG;k`=~(|z``8EqI=i%N-V^v`Iqh5W7vUKQ?ns)YZJG^0rLAL!0OjsV>`m5CxA1j*W zm9632t@H%Xu%VSV-O%b$pw1?z4@o8p4Azgi;Bpl0QwM|NiG-!f7?t417ZTvxvt7u~i@6dAVVp2Kb*mLqI$H^_}Pd0QE_g$NRJXJJ?? z#N-P0ZCE-;?>^bTo!ot*+toj7J}C>TVfPNqjc*i$X#yw}LGA=Zc1lVL&h7cWkV0lo zY4v{X^p+{LWJ_km;5P^VsLh+WPuDw#-`;d;n-_Y8ITH5XYR@90TTeGJVe&gm){nz` zcA*>StO7ue^(Z?IOyuMnIRkfcGP5B?XfeVs03Q72>!)SDYtd@n6*VYTeN}OkF=3;{ z3_Cl%aV5%@i3F9vO|cD&cw+>~kh!_})|EqKiZpiMycS-xxyU9Ab<{yT&)n4w-=>-HD)K37{SN?%P!ci`s{av+n?Cchr-Pbl+?knTgr0 z6t!k8;daSW2s;hEva6ku#%AwJhvPHwB_0E zwoBS|R$tw7?8_KCK;IYBLg5&ktRJYj94BlBogomZcSOpDXw zVerG?x?~1cCGW^v$2f$bWzd(LZMI_c7JCer^O9)+*OkJN{_GY@>1u)Tqy%J)pQQsje4hzQsehIXD<2!+#>L zPJg)Y4i*O6q@5vuD2KKNB{w~*ZR}%i@#PNEfoJmg^^obcI7QjzZ)*Vth!$HaH|6o( z1HRh~^f_dfu>jc=#BD$?SW;5E$|XR3Q(|Sz<7KHQ;v_Kdmxv2rg9KY4IY^-+Lf|va zcHos3zRP#y03rOWMA!Q84QE!?{3~6myl( z;_~4wR_FS}!(EsOEV0ps3QY>{exbNVUBopFPtSs5h9pJ&0+iU*fi<=S5<$#`+ts9r z9I)8_TMo#*?H6;vet5h;tPU!QmMry_>~Y!!xBeNi&MHJo< zNvd`MLDFh4&N+Zx#=a#Ih9#X#YqAS)eAl;NwB-!>!YkucT|@8Oxm9O#@#2?(F>+19 zMPq*#nhGN{sQQu)o*gqEdqX;L`e2?y5jJi{$}rc_Ckxx(`+ z2H`Q17VzMw;Sm9QHF?gDbaGj&*Sicj;S~IW@aHe!7Z3_LZn_=gnkTh%F{3Ig5-a#- zs%e38g=Y+|Ok-Q}E~hJ#Yn7@lFhckks>D@Pk{MZRpgz2)y( zU^UmPX+R!C>}yTAIw$i6#rzBOMNsyR8%$6@zX(LBpPj527$H05C7Xt{TokBvYo;EE zx>wHqMRkKehs>K@YYcgSF1WGwrt}o_kmJZ}wDI-1y<{WwiXjFWlQnd&rC~kA1ppMi zAZU{JwoWy0!6D{_$iWTN*E}KKZ1}UdY-;Ek=-tyfTdGockw>F1EF78YM`=qokBZD= zJS{VWMyOS1e#o{hhX3bvT+J<2rZJsdxghxfGc@uoS%Dsy;c!%aFac-rWrOX=?S%) zJsq0Y^B)!`BnEe|VA7M%@&`RL6O=8k;K4 zbwsGJwirZrNj1jH!-i#|eIK2OGRQkHgZ{L;UtgP%a%v^(7;&Gj!&jW~hcM&LK$E2n z*I#K?RVFn54Y_binB|@z7p8HW1(F?`bKkwGQ-x@f5412KKLw`9GjBw?t7G9-i1_Gs zT^my`Pb0EEjBhcm=^k0fV0mf^lRDp3BcJlI>Du#(MHPZh0!^Qfmv=}ewvzTx@!{!^ z01_|b{NAtRW2xZwjzTe@zv0BcpOdNhBwlw*N&=FelM{CnmB4|1v)HR2C$1l0zfqqo z+|&-M5NJA6WyU%iYxc&Q-^<)`t!=Ot2s+cuFm!+D;fC@|7TfTcb-lt%Fg3GHijvsF z3=ItpgmN8*V-#FPJd2#ZP!OyQbwH-ChR1YYCXO(EKXuw2rRO@fWNm3V+N|=WRHJ*kc~+o=6U8^btG4D;kRtJfz|pUkC3?6q3{q?)ZS8V!*ff6@@7E%)-dpo7BJ!?2}+6dEKSxxsIteo-n*1yM|6 zfMJ&>Q^nL>S8SvP=&w~*E$^FcsWh01 zRPI;>`+%jS5UFP;KY7SVjNquBhD3E~2m5>6vFm;Qq}w8cY-o`}*|J`1c$ulp{2u={ zJ$BXQn4TMDI(v9`1l7Sf*WJ6m8au!f?SNcKa_iPLzWBlwG#TWH^M>sSGEINJMeq}m zl#N7T7RHS|TTV*b>>J}$4ay|9k>WswAj@Hz=Dv(u8FoJej{gF2g*Wa?AM5Hi}`#TprtPEDL7}dL7P$f#2(U69@ zhl3l2aNML1SRJamTtcUkXw1tN`z_;9q=CdUw&hC`)^>I`>&ukl12kl-(Z*TA7 zOo$E!oE*^SBn8+cgx)VVLO3vw6*ZEB%I+iL?%iXXeGU2jZ)d9T76O_G)*O;ABvsw$ zOXi9S^J}s19Z&ky2-thxG^Iq{1#>Rb$3Z}12c+eS(vOg09?^K#k0M*|w``3+$HBO@ zWhW+LXNURz+3nQV`+n4cJ2WM2nW>^NYWH7=5 zTnsv?n?7eit2Ixh#jaOBAkx~AD5gl!-AAW@SXxod6=xyTY7=&0ozI1B9BA(}S|JMh z_ado^3JRUH%0GvZ?Wdiew5{f4xKH1SVX>osJ1m9~8ezAu;p+SJb)dz4JYq1xcKXiM z@)Q{?^$SlQLTxvvWb09D`n~l@a@jJY9@z*9mf66aO$!PQtsy28RrckP?nNk_LJnY} znZ%>!1$9~vR(Z-6`&}IFuC^8rQQ+-kcO#OV$j#Y9N+ap1!#6v<#qM8fK>+nfOOH8& z1qIaz^)z{@jA`J!V-Jr6NgA;94Gg3U(ImwXvCS=t?en8-NQPGHIwl@886FhqixOi2 z`-C{le#l)Mr!GFF#O3`7Ew@%^xz+GuZ8mrEDcR6M258*_F0?>e`!U=oS&7mOK1`U_ z%;qwzH}+m#kK|hpCkdl39UVxAzGIKE6H)#;3i`Z;_O~N4kuiO(Qg6xk#@z z2Jss__d9otxBSGGvpQ5UaJjXL3&Rl6`6m2jN+k@pa^X+ll#tC2q1C0=_vCzJ z5d-INt)6{q zCsV?Gq{ojRSG^m2i%l(DX7@3$PrS9TDyq*gXn}#e-?cX`efVe3kY`YC1nn_c7jo~O z-yzk9YPn-pQ~~3DTt;PPZLkL;$h^NZLGuq^e#kRd;GA57n#5nR{GU4L`yU*#9jcv= zP#p2J7XzUb?>t9h;@GKTJ(5{Mf1GDy;C@R|5Ap?R3K*GjrY2(WOvOGXW%gb|^UbmS zVdf2PfQ&s6ulR5wV`AFSWMO^Qs+1)4nZweUI6Y#W!hq)(LOG>|1xK}6h4=M+qLp|^ zp2KiAU4?WAI;t>JrSQ0h*8b;CN(bK=#wqPCx&{$4w^_n^W9je=%T(kqntwHqoIHi) z`ejCShiF4hAiHan(0*?~oL!KFb4iC=7X5;HA(suavs}9C9G{Xz1!KsG5l_JcQxj%N zZQZ(P(#&1%9MhfQ!!@VVW;31S65$hB9rSU&_3PxAa)%Evu&^ai;RN$0@-4aTqtoR>3cYpH$70l%sOiZRZ=fBZ6;G#KXmO zw-z~6bo`vT3@B(r)&5Y8GN52xqbfeaC`q55VhlEOW!-Lj{y}?wMQAH^NqRbz3aLk7 ziVsGf&`v6yx>=Jgr?h{-aVSnm)1pRXNKeRJIi18OvqN~sLd@`i!x!scSGwq`Fl!=6 zAqUK2MjnO6fy3rbh#b{nj_`4C7z(c7zcAl);S5)DP-VbPvDEg%q#jlc zOD24dsyK!1#=KcDI7bksQVaII$E!&BO#9c3`~cEK&|i#> zD`RR>tExWgIe*NdHZ;ck(PB|(O42>q=p>1$;)uP)ml6qe=y{tkFh&9Qj{?ZGA)x8GZ=JKV^M@Q|U2|PFOq`YY-L8^{$@hq%siRve!xXN{g$Y`+GVJPfynHq5UeYOAAdApcO9TN~{9 z_!V#NsgD?VHKf;`zD0CrsAm8&7*X8O$`n?1!c;OhV!u?+q`?42%6I;JNz5PM(lw5B zUX)A-bXW5^i0m^bV@`72?mCR$=BZ%ekZTw;1Th4v--Vjh_*nJCq79pmMJn7$HaiB1GwA?Q78XWJr266b`-N2bh!yef5pAbfS&%=VhMY?z)aVy1NkR~{1XDp-p& zog2{Ll?|E$bNLCnx%^8b6ui-kx_RkCg}Xo(Q5)7+R+=*YahTc?cv_(jzP1qjXM^8(Wc?M@oRWM=H6Qz>5R_l?)M&VqjQX%A#_gAH?EUpwu zA%@GHzsht{YCAp&yl7*}&^^T{gV&XZrHeU@RI%~%QHu9j#dvAY`(i5?zsAI5V!F3& z^=+gp__B_Igk|a}b;4^3{^o1fOkG5|e>a@12Ff8$*aMAX*WjU%(A;R+bTl?tMu zm$Z0Cw7PS^wKrLx=;6Gm?VMsn+M%5?Zy45m@}`)@Yy`$~wf^vUi?Y2`3x`=MU@*jy z6RrLu?RNyh2-j07bT&oV7ykQHM?+95w^T28M^yA2NXHV7bOI(LxR)kg9O6EM-ycXql?s9Yl76i+JM`MPQ`_8 zUp13eCUKqm&Up7$T{6r;+1Q&EkrBj~e+Mn5qRK zbypOvMOx1dWJZsk$9+mx46Rufj6E_Q$yn$POKCQjyyX-5%oSlk{@!S24&)c(NXg(5 zU^gK^$YfA_t2TgPDT~LZM5Whv7pI3=?KFy=XDYlm)*chRU;I_q4Zf6-I6`>Y&7$C4 zR#rx#jm-2Tc6FpDw6;15f0NHf9|Bhswgn~)n=?X&GAQeab(6dy09F&7x&{>BjJ$#0$*_rhVdXwQ6!i2src@A z)h|oyX_f23UY(y?FMbL0*z3-*6QLaK8or^AdH0$)R7uFIGckDU?|1#RK{HOke_Ml- zeNBvw92r3q&^tS8yST_sMosKlER0`iX9;X5`CetspQ7#ny6?OO=i0bFxiL`PuQO&V zQp*%}_0CdlU6uQ>&$Y*2X?DB=Qx>R3Z(R_7P*c83x!xz%xP7(lPV+{j*=WI?p4shQ zd!gR-|Hd7ozgx|cEIqfN=9011m^j0Z8)wf@!=EZJF2ZBQap?H_tB(BauJdm*am6Sz zmt13GJY0|O(%D8YwsLlA-wq6g({L>3xXI*!RfkEZGUlVTZI%0hs7oI&3*((2&7*(W z9Rz>poqy~PkK5XD)BA_Wb!C=giYgIN}Rm8h8Zl@RxI6VorTMxu=4nA<(e!*Y)_jqLV< znI?IHk;qO*=N^NAfJw?*4Bxw`s?QK=?xyVWxfMe`9Xbj&0)o|BajcUFP=9 zgN=Jh;DTkIqlrWU*!M$*pUA;y8ZpJAwRnN|DCx_ zvo`ws2j~AkGPh~RhWs!q`OnO4nzbQQxHl77$={#b?>aVQobo<3E1Bjdr=1)63xCJ4 zA-^-3{1?ZDeAkKoKGFL}$>hH{Hsp6ElmFt_kl&e1{tGXOd`}|$E*|{XH2}h>kKp8f zLo)dKv~DUSwbz*z%>>u-hud``rtBcN!*RJW0w9MkK+#73#hKqK?RX!PkU<>sB z={>zovdPeafF4BK9;V>HCuX3y8%LBRn*2I@RV6E9kE z(Y+1&A6Y3e%dBA>iKwDM9rlzFjaYJA7w9Oqn*@R7cpa4(7k92NHig4thdNf<9dQRDGXSSVm=)1frvr&!v=A7X|}7&I?y zp~A!ERE@$imcl*bmRF2v7#WHQ(V;1@$Dl#ano{k#0uM`3#p3H?-O0HF&FFkqpH zzl=8gYef7jApZRW0>#I`X4CA<7>BeSQj<$vNOk*O)de{F8ltPS~L zR`U1f_PdS^`MLVh|0F3vCinIxVgOW}|Er_~`JKt+zc@DJcP5j6Z*J49?Hjw|`!MjI znALs2J+RC))6b zloezWXN6O(Zhu(j*mex2XW7()Lf0tRZGvG_GhI-|^}o4SG2uEYGEpO+$?n!MSPoU6 z9#kb0-vvO$UsCVl{4IrNl(u7mLWb0&rkB?6L+Er73 z?cXObC*%EG78?oC7GRL4Srfzm=&z491UdqU2ZdQ3`uRwYNu-~rtQE-+7)cT+$~pc4 zuSM6EDfP@LueBr-1|eeiZZ1%*wt|tZ(4LrA8#A}VoZ&~L=gBQlMlVp-l-2=d zvZt%E2;*;cCtdGg{O3Tc8^p@qO89}Cu&6L7`4_#m;AL~)b5<*}z8^<(aTY(kIWgaB zd}{xh{P?Y?nlttNOo#0!cQ+ePMvlK%XZA58&I)0;M1yNb$iBHvb#zfU6){U7b zBBvAb5C$X94M@V;R1S=*Cdx3H`22lk(o>{|F^gn(qn08gq{g>4+h=IMzITWT(~eFU zOnj=gPv@r8c7!W;=8iNY5|(WR$>q|H@1MHC_Jy*tGM3ld(2Xd$6H4XQrQ5X}cXjZb zFOk8Rbjw?I=gDcgIN26xGuQZu$pDu_%PnXIrXLj-ocR3cwn&36kt4A;bHLVR#12W% z%&con2y6U|6jn>YrUjF`b!EldBlc{v%eop>et=JrluxC2%-pi2U&Do*AEM-3p|>pQ zaomT&j#nx{f(Ai)dEv*RAD2hVFU34Hol54Yglm1;vc>L8_PYG zn=aIrb*pDj!u(7j8-H_|6<^qeZHlgt)UmsTeepE12Uj_be{oTXW^!!v6QdcJ$5X61 zc@kmw@MbP~7)hcl_aKv`d+wEhpD?n$H_$;P57c^S$#c-xS{!ptkUC2fYI$0z_1UvI zmW{gM@rS~4Zt3QxA(AUeY*R)L{v}EdL#K#h9q9XIoYO~mr0qWAT=FQHdaNaaFvglr zns%fIm65@*zKFTtRaSF&|8N3E^Ze- zM9k`d6`44YI}%F5OX6A*Guv5PeLeX*#&I~EnQ=)WHg`jG96s^6A;i=9SR2-056Q$! zM_ot`?Pw)_rpX{< zF2g5Qvo!nTqpP)9tcXiMmHi1meG|>HBQ+T1mZ?sQ5%|4sO$2`R_Op*jd1RMCU+f)~ zKi&|TSvj|g<__dlJ4#&w;j2k+;pKt$MS;Wiix{J3s8XC< zegd@zix9`2VGmgIr=9H>lRUz_O7^=TgnEv~GUjiPV#WqoQ*t%}eucP%#6XVorez}V z3#4%^xK)YydlJk_$2aqI+7$6ucg3sqHyf=c1u`eT^w{39P1m#BpP?BEoU9S&Wn>LNqyYbiJ^DosV>II(D;KkoRv>MY5j4#HmL+fuq z;GpiKf74{Cma;bb-iFdGYW>3wHmwkQ%R_t4f;`nKvDxU;z3t+%po|W`@2rx6O;w0~ z$&+&L30?P7RFA0Vj?&%bdVw-gM%{B<#eWQCzd(A;mL0DktzrLup-g^IcAPE?fK{L<$N0~wT1DM#xwFoW9v zSSmBxjJ^aWQ9?7cazzOGt)P`QQ*P{LJf-7}O*a8DLi+bo)}Nsb6Z#5!M^&0CXwK>tO4BFjt36(ic|EB*m+{stNobWA7c-+7quwMbhBDyy#I z0vrg)3Qk%OZ~-z?2eS7vK=Ro7Dpdqr5Sc*{Q4y#zVi-vs$R-Q{fk2cMAS4k&2qEit zJ%Co@9g8x$CL;^ z_;%#8jv;NRX*+tXID0&xivxvE!NCQqmNUX4A;~*ot}*bC;KgS8*SRg8^Gn_r^f%+Bd4d#dC`Lt4ow;lpo(`|^Kroyi$STLajmy&nLKwMdm{>xj_=ZFSki%8QxRLysc>`sI9!zr zwXzH6!T(tH?AhB7j_pRA1wp!&7%u#iGz*jIEasDO{H4n9_rHtCURU$yia>wj)5=Rj zhdQsW$OxT85K4)|II)uZTZFoNM zs*c&yZFpl<`vS+_K!2m)!9KE0PjXDRlIeHs;U-D7SbxLaBYY)Xa(Hp!&`T|HT;|Mj z;Qfg(o-ftt)*-Kl{CBsWwtp2`4^rf*7neY4{Fea~nzlaNy##XVKO1NjxD~yf^)G^K zrCgrO&kbe4Xon~E#mW9#D>7!=M#o_f`I(Nitjpm>FuEF2ae^jZ*`L9zfdY3V*SM!k zJl3U&MS90HdCX;#p`J3-nwrT}-1N{9t2e)Hon%b} zCyAW9r0~$7A(_1%>R#f%;9#Hf0>gG~-4JHk?P#5L;}v6ir1g-Y zRu}25xXed1y)>TPnt^>wDJaM~@S4aOo~xowFwv;K>VIy$VD!yZ*MB<>256aWLDIVB zXAFMH;FiK*kBIVwP@~Z*Tic+2PNK?ReD+9QfCxQ#ct3?!&+^`3dZ|LCr7<^x!^-I! zoK&_Z5l*ri;P5|iYjxb3hm8;dx==0bbeq20=`Gm{tY+bA5|M;235j}}mP{gH9UYth zRT!2L8qtnZpXa6WC0@?@Yn5=8L z!8D}KkqN^(Vftl4A158g{y{ZJMa6-n>U=CsyP#xOHCt`ogOmTjxYE_$t>3RvwnOG# zO5eB=#(FE(na42@xm36uN;LWY-eVERIp|yuv?R1J#dEuL7adpx7Fy9bJEy`7$n zuJRobOYu>!y%8U2n9wPGw*WpMi!+cfE`ObgolZMp6TfOeW5eYlX_rnJYK+4qyVdBh zIN0A2EkuB{ye%e6#9JfQ92*A?0aajo67@G$?YCUJeF-r5Z_xreB29c z0MRB)G?8gj7oVRvbfeatuBQ=U#YMf?Isbe=`A8-cH|)f$Q@rl30kO#Jsy9P_)dz># zp~eM9ngCqvxCu=iYaeUxENe#Z&B`zD4KORWP@^xqfmaUTpyNQ&PIu}gQk0+M#_FOF z$DnU1bY$(ei3tqy)-gi|d|6w2Wm+rc3^Y{Yx2@=ct%Zwoh>xqR)Syidg}c6`@ME*n zBP3g}ZHh3RH;X6dN&zNcrTZ$S0S-N`Sp?LeH88!4$^rCWsN=H3eA88CNAq1@&zQj= zG`#^10fEwH&cF^A%*1`2lzOQ6qSx2MBm*dDZ4i>6^5g;j3)3kcSvYj*(xR8!>h2%h zGwTcft0j1xHy=7Qxs&j1qXzj9R4*VPT)6@D_c64(5e3_Bo6^8u2n(PN4&WAn4TJ(k z7z?9=sCE#x9&QW7i20=Qu{Xy+&E(%{ca=?&d&|o!({T}ST&_rOVEO7oA9)8!>cAHB zXwnypnX+DGb!jtiO53?nQjw3i*cJVdrm@cbOuz>Ur>juQ_aH9(oC!1@MCr(B(2~$n z-L$mUe-)NXA0y;>hhKgfbj&IxS4!1Z1lcBhnrrc&obecC9d(0%zqT6Wo9TH#;G^;9 z!Te)y!e)qJX;N6Z7 zRRZ|ULaLl<%q!KQ?N>;4h7+`Iw1l(zOjpLBlm`a}DVtQL{Yn2&m3IC4^Shjuhqs`` zO&jY2>=`J6pwFb4PS+x6B$aO&^A4qno!RO{lX57 zPImnBaveF3wgTq_K*3GFS3;1MS!A5plF`%qsEkIVQ79rIA{W-j@zsX+)vU%|%L#%i zjG4K%97nqi)?8;A0gueI!P~RAF-TY5PkbNUGf^E__A*f8>i#gy)cL$=ZRfAVLBt=6 zii!Of(~N{Zkw5G7Ggv~0K4;TNz3*cOHSC*NBQJ(qR$n<}*gaKAr_LJgroOi`U{TdN zT?749Cu!wPyI>M4v_S#Pz+n8L2~RpSH_I4Az682|coNEPOz>dc>3EZ~b}9bm`NF98 zFBS%u9|k@8s=xW)!!1y^V&stUOhw-h{VE&|3=se-XbQIO#PGAq$jETa)L#~)Xqz6K zILjZ;AMYp_K5mgejWB{n-k1>bPMMgXM{xhin0n=0vzekebPz@Ezo7XI+B>)eBavhj&K)3P^;GJ~eS!#^RDkf`A&v0SGgb1`u&rD-#$k z*zQ^UmN*e2neHTk2tTgrkbvPJJB^=P68+T7tFg?^a;HVNeCsySsnW$p;jX5UlWmMS zr{lE)bvotqO!W2Lp#|cS!iLFthjYHftzlH-?ppI@XQGfBRZR+=W7U3XGM&1 zOmVyINgXrhNmRi?oVzWp=XVYi{-8!>S1vxjN-K2nRi?@rf-J#K$HnrIL?G0Lg3RFuChY+u6?V&*`g23Y_`?m zBy?)jS_3d7Kr8D${>&C!Av5i~JKk*ESl)GKuHx#mWXr&x{Qdm&oaz>W((^3f{R@}M zClDD*L@LZj?eRfq}Pu3OOceGb0ZJm@9#ZyI@4#92+(O4Fo3<@k$Bf%P?~V*MGfk> zW?PLuVGtG$J$$%H%M3iew}K%Pff3mmufM#)v+R9&I2v$#)&Ndn93$sr^quNNIi@6# z@%W{2$3hkkAztO`L4hnN^*nq&Y$tpV2UHvwx8olPW0T_|Nlal~qSgV?<#K4i8Nqpz zlMiuI_NwJk;|*OpP(eG^(*yRuMDvHU$r?0{GVLqZk_jML@leE{6 z#{J}#)eaSjGuHw}CO}gycziib-iYQOef*hwQ;!SX^IwCHK$tMsz@I6;?Yl(PAOM)H zQT%Ci5>0m=^tJl7GJ^kucW1Rda-vgR=n}CJY;Hz^4lnu%=YF+!F-F!zbx?Iwi1`lb8 zm3 zq?BwjD^0ZP?Qe5E4}F`Ui{(lcm6m@Ms#e1Gzik&l>}g+Fsc`ys7{4E{*ib~qJ z8->ZD)eG*C%8;8rl;){?>HBaeCc<>qxrTBO>2N;5_F!T(Z`Rd$x=yo~%}S3&)NvSE z9#mEMGJnw*(K7Ki|EKrQCN^(u%R8qXM92Rm6G{+RQUdMFQq z?m}?YuP2RZB5cW2lQ~n~EhYhJ1n}CCSq6QRq6V(`=^#&KCCz9dIO?4jpi>@DU$FZN zUqDn%hM|RX9HK~c_C_ss-<@kdsGMc%Mz?g0_&Bp@X2U0;Rqc_QKn?5l!0N_M(_!dM z7BIb1ji_I3ye%wKJm_T_8C%xEA#(9~_~AdeQW4|>kRzGrKAJl;nq zua{=u*wd5O3Ffa+ zS9LdVuK8LK0qx3-P8$CB^LIwpOCPUgw|Y2-|Cw+6Y%{!pVx+@1z_SqMV`FBoOpNd_ zvwo&t;c*jt*)Gx?P;)F64$b28v3%;O(CeU&@Hxt^*IEIgyLh|$Cjo(FzYH5xlJJAY z6b4|LO%JX5k+~CPy<^Ix3!wjmC+^DgpZ5oK*PZh9|JaGM)vzAIl+VQ7nT*mIbvLqo zN%R+kQeRxeL4ace&j(g1dPx;5rz(ZxwMrAmiRpEgXmA*TB>^}tm9l8JvDL@BFpCGj4k{TJ;S&&A$? z2wKqiIyCMJBJl-eA}D6<Tm{hxc7^XFK(57>OT6b#6L#%QSASJsEwWK?lOkaAwa9 z;Io_|Mpp|D>@xm7)|8Cz`ta9Z7F{%Op;XzczIbGy_9T{QLiR^yRpp*!RJ(xnJbEuF zN+iJ1j;MYfVj*Zgb6ehP$I$&%7Zc{1qZB1azkILHjN-$~CXGiG*KN#)Q6NN@n^3y3Wisf@&$} z4a_2I(r|0eg(oK*`mTPv#1Z!xW-uAyCmt}co{@7~TmBD2?D#Z|EM@h=tZ<`clt*^d z&)SrH>QaKteqG-2^F1IZJP!mOx_&n*DF7#_6G&P!Acz|RVIYcx4{HxR(+3cVOjy!d zf<|s7kU<25=pxBFtDn#`Gf@gX=O_PIOwugLgUIs)+NSK&voZYZX5=$2rxSK;xG0O!^H`HE)z@63|WdBXy$>>4b8?;>jlRIB zW^6W7p0VGAgufq{auoz|r`1k{{G};B76ZZF; zPybB2I!+J@4oBe;>Q$fLCX;xzi^)O%l{*C`C^1!q4%)-oDORvc~90H@M(Pio%gzHm#-Z4@yRL5Re#W#+SqvZbjDA^8H--7jrLk_ zYL|oVmB*`+E^eyv{Y(4C*I%!m@00NFjIaLXvT**gHKDdvmL{EFd)gJm#l1zc$9Ib+ z^BbxUr5@_X9A?@aPyGuwUeDZ(Yf!qpKUF!qN*d3QClAV-3RDnQhftEQ2^HNrWUiczh-npF_GJl|p&!uP&$e$Cy_u(0zB)I;ph_Xh zd_jn|&2<$@=q)B98X^qTOkQjc_dKs|MfJ&d6EE@@9x7W*fxm}8f^EpdFtY`^2V*tU zU$sy7V%256w1@$zjqzBTyq6^VmCMn{_0e$SKf6k(O4T25c5yZx&>zQR!>|YMo=#&r$E zk)o|F^Rzb5BY&Lv|JRYz`*q6j#6=!g|6oM5w9}@;{d%{{iupHfN8Y-MzDR;UIlGB2EPHC?hwyYfuT(+aNz8wsux00E9c}!0hrfNE zk2_m2EpF#TRAAtC?=#$*si~=7CwDsePrYU7n#CJn@3cR)T`)nhFD@l2K2%U%&wWml z8PTcaGQo9CuWFI%>|!pZBOm(2B$*~tp3U4%{Q0567KChL5clnNjGLfNa^M}!W zU;tv-`g zG{XSS-%;7WV4}bOOp^D{n}XQKxQm9W?a3Bx(bsEOgM&{eSv%eDiaQKfn^(cAx-%78 z+x=SRnLO?N2A{IXBdyY!ZuIfK>LFukc-WX_+e;-EJ!&}e9IOnz2TFt}nzU>KdIiWW zx8=(62?hUd!ZmRcqJsUjAHQw`m`E$NyS0|QXRv8rTJ5n+61=TF6XU|dCfE0^qzKm2 z_)XH91kU1oUh_PYh)=8s6qS_{0NJ00(iO$!M z_CIIhCd&~iBCwR!Ss|mZl|Lwcr&3 zsVnmbn1vqaO@%dK$}AHn|BpDgbWqpq^k2rA#zhS2W6>myD{IY$R>v{?oww*hJ!I<5 z>G%V(8V!@8r~!+~6FRTw;E_8npPuGoBy9wVB;g!=8S*Ll_`K<=S85qKt%z54`?V@@ zvUo`&SUM>{b(J6C+&Ke1y+QRM$J`aT?7nM4JzC_%`9(uV2Dgkk%B zDdILV@h%@T_6iBVg89APKjqW*4c*+MYi7SW;iOBi=k4W+N@p(4i zap*T|#qF3fVQ{_n>J0P5{8!$?+^qYGjV`I-L32lhvtFRPXw&_cmp!c4tZ1xcoJr`t z%#%z!$GR01Fro->wt$z;bpw}?u_sEro=}<6Pp^?O8qatmgdCI8H5SD^*HkoTaYV2U z`at{VjvD_#dNFp%L4Kr;e(K|L&zr8EMH6M%#Vi|&N`@x3d$WVaqEs+G*L)C7N&@>X zCAum$KzH7PB||&iA(?xvzpaKSD5fXI%r6ZY43AeojxDu<>ox9nPAl`bhi~WQ^4|{Q zW?kqya?hX+wZI0x=VeQ^ZmDkN#QQybPNxu=M#MKY&hnq$k(S}%d(uk-PEL-|IlgCY zLa5ZIwuO-rzpr}*~*7dVz<&R69r#YCOMUoA(zJy^HFO3P|n)0vj&XnAE0d6!Zxy-Uc9 zs!OS5HJJ}3Zpmno{f!EX~1WW({usANzjA0xlW#E(3wTtSi{ zePCf)ZCx+>^JQM>Cym=^6C5fUhJVwWAxRc8p7dqW1qIp%tBgzqN6Cs2;n9!wHE)7p z25ZRl{&}xod3`X-P7I_C`L5;3f=xoJ;_^$}$(zQ+8EmtNN&;-d^(^@4pVlMqIi&y_ z$UNigg(1R%sYyCbGN40`dU*fgiJ%_p7$X=78mq;KKD?~*r;bhc3@S+<^p9NNYw&nF zSjvq9q0F)gi6tUea%{bcUUw(?xJ|uOMDmrpNw!WZ^-j1f`?OB!wjucKh+=hBZnWs- zq9J#6&-01euZP14AxH>Jxd@RSv4E`Drkhc|zPXvwHN+h#qtoV`*$jlvts(Nt49>?g ztkYZO#XkSza{nR^yw3*?i6 z$RoKgF6yU8=EVe7&3Fv!+j6Ed;hd;cW2BsT@2SG3wNt&#nj~r1KuuV2PvfuwIDqTu zwnZtr*4imHvRpg3MBY=FuE@efe9&kh&-4C7E2;joY(r_2xIr8@v%Cre_9(g6^qnBj+%A)-V8OU@mktWIN(G>Vq ztNmU3w&>UI6w%a!ZkK&)d7oIH0`L>N&uQL{sQ-iJHTkC>aP&F~Y*Ysk)go9)uQG%l zLdKRZwfZgvcxylnz{XUvEoP(#;g#p(WqjCk8g3Y8GV(i^Cin8#lXiGQ$YH6=Z^mG$ zqSx%rZ=IcvmA}RnJBpgKF-5e3zV8o-WMVRtI(ZO`^ei%K%OzE$6P=|~819g8lhiJY znJZc9fbdc!`#(i^Lpk$znTeAd|I9mZ-7~)FN!k!Ida|K_EM77IbX4HNZ)4tnERsoCsTDFUUY?P$Xjyb27Nj8 z`Up$T#?%eO*vQAAQGE?8S}w+vp)|wH){*PY`lYrM>$h1-Zwq#63{CzLW0W~>k^8x$kbb|g2v>OSWBhRD;O zA~m!5JmM3X!cxt27Nq+@>Wcd}kR)8tY-kJ9#bAQ*!)JCmZk`&Gnoj-(I0$Bm&qjc1 z#_Zo|!LLzlO!l0v`_K;mGhLpKj7^c$N8P^JdFu^`c#%0(LZ z56|IP1HdLl4z>1q#@kINo0;+p@M%Gv?8nJG0^7-6)>L;a-sC=ua88)FSCPPvZQnIc zG8L^iX+();TRTIskuZeVqwWHcdY8LTR|b}4PA~q10~3w^K>5tX{JgvdIvuDurAF=U%KaC|-L5_0+_~E(VS|T8%R-)X?*XO=K_WgJ)A9s@ z)A2Ge@mb!A{33%h^gMqMi~9zrE!ufOC1V$pF^{A4t?wYmW{DC4Y}Z8^2~G>R#QRzr zze{XnM41MsY_i?-{_n66zwzsfirhEf1Z3eRU?N5|H3+wJlp4JKsiJ;&3|~{3CKl_LvO`(e~+Az1b@WV*RK=h^QT8U3KA?T+W)h++WY6<7!e6bZ;T}=YO*U~ zOIJt4zU;oM$X;q`X-X+GcvX?3mcI2P8`1c9P_d{4GzTapfFEYvw+u9ck1@>)@C_4Aht||@tlxtFH2?q$&3O2$aK2-5Lzgry z4Ync4jxXv)Wb}0T3m!rh#QID6Un=Rhx1~pnKH+KU=&PAq46e2~jZ%aS>{&wLlmteM z2<(x8MIO?K1D}27yl;CUc0vX#BKX z9zoy9|Br~+ciJP)+*Y$0!J;h`^%oxyp}ZrkWswJsIKFRgzSRujZJOuu@c5$O`c2?p z$X^B`w_(V`+1%%$r%#`T{HmOs9GLtP9UZOR)!pp^BNiYDIXSszWVN2YhMq56N$v62 z*jS&OiyR12JYA8=eXU-t3nN@S{VF0xpth5!oTqR?J zzP~U$j0zYkt+%Ap4Eg3*v4n*MLuS&#=}H~Bj+{tj(j99ed}i;iA!h(-%GL?$dkbXc z!MGBE-IDjq0Vy9l)s1+ZPrTpv)hw?FhX_VcdkYwgjvd@trGcr-TM6cWnq!)eq-|k5?&JQaGd2_>r?*Q3=PeVkzCFy2cZMm z*z$M1ZlgVM%m%0rDqt*51h=}?*JG!3=K_2{z;`&(WXs*lxZRXZX%B+j-7A$2EGWF! z_bOO$!zmVXRFoFa1zit&4y4MVrv4nBW3m7F#JGmi*#PsplMB% zAw`V?&9KkgUNG`H%$7FU=Hzg^-3yszWrp>51rOQ3W__Gq4 z&wXG`3TWJz>lOaFpB(Jao!>yjHgCW7A4Wt93-qB<(1*;OJ}?;0Nz=DT8~rvdNsBvX z8ea~Rk*ZrEw{Q9m9RIo0;bBkZSKXO0eO-U_&-&GNImbrV`7DxIz0c2_bKj zefnO<`x+~QfM8q!PRP=BerB7qdqzisz+1@cjvTY3$bn{7tGhWvW@JmmvGQQ?7uDzCK zHF5N{!cT{pz*;*hG1>i^(b3rHiR>9@i3Cyr5zw1)F^}r>*#1fS(K?PuN5UmB%N*)x z5!^BNoCMUZDx%D;xg8tS3VSN0lMglOMt+}S!q7l5ThYql zjWQm!5~5gfBPeB;)~XMk!OV*KTJ@fP*C?*M0s&j68i~4pS&j2Pi|bA{LCpCj)1929 zaqITg#mB`xrM|nj^I4riQ_NPkkz+0htMjGLP4|X6Iz3z9xgaFDmdoY7eS2G@{M^{7 z{x$X*mp-cQ{MK--u8EzB|K;;=-*`IQpYIr#1~uBM*mR;~TpLcxo1mo-%0lXEU_Qay-u{c-448}o4$+cJSravty z>Ff?G5L}wy|4FVNpZ%85z#d{A8Z26-;KY4K;V7-l^^baaStY}%)gLc}X@Y4?85;V) zC4c%r+g|>@yL2;(V690QucB^!Y}A_ed0Ldff6Y24F%X-NH~RdYm9xTII4WP>DxDuO z-kN(uaPrMKj6=G7`D>v9mPRnK?221z(qaI9+M%;lx?9giCE4xd$@hcxDOrl!iH#EPAOU zZ}3O>&3qlgun_e&D09^4DQ8FfuuGZJ>i6%L_ML{)s=ZqhBB{uhPr*0$ffEu}M{5j@ z!xa-UE-v;r7N#cpQ>XU&=-(4;n!Pf5qNSFRx_>9We%o_?bq1bz?T4=vcUfCfi;5Bi zUlE6Xi;LU_qd!4kJnQL_GZvY`<8THdGHM%-o$@d3;-2RlX>{j1cThh}YZKG?3LAdi zXU?A-$d4L8318}rb_QkyN*YD;b!EC_)Lk}2ljuOqc?q0nz9cgV)HV>)3Kf`Tq(InNi@_c0fPPlkIkPcO?NKH&3cU~R*dlR@$vM0 zNbag{Q<=U+^tbv-1(^$_JUe6yV2kZsWi|Fx)Eb^47^i&nu+e=pvgbMNM}$ty=?l#1 z3Dl_-k$a9lgIHgD5EK6X1&o^f08#TWC6Day8X>D!#%`oxW|{mz@MrG%(y9N3dfhp! zN1sa_vI8`>YH7K3c^iZwPX(8Dhz1AmyH>zxw?o~dqmL7*my6Ulw`CvPP2ByL!cRwv zV4`Pbg#&JdZg_VL>eV_N%qqG^x)fs@-WWl&5LA`XPo50sPk1*2hj1B~Mlt-3USigCIi5!m?%&QA*9cn z984iR@GSp!)?0*L$2=)CCk8C~N)5Tfh`0^&BV*&^Ne=-euah6qLfMHiZhn5+;{+b7 z`ZLT?Y|N~-XBPP|=V_^>g^TK|y^A_Q!k}&kxo}GofO0poe+@K97>Y=3?1~BvwKZDd z?+2=Od3_P4GpF84w&|S+dAjMdqa+`MCC}aNW1NebW_uNvHzBNgrGb2O;82os3 z6>PE))tlfFVSUsv)GOe)MLPKDW8VJd%SD5oouhrE;3uEJ)jF6MJE5SCpwGH5UhHja zfX8Mo*DtYHjn!G?-LbSGHE>@#pUR#6nD$YKY1h@lhZv(m11a45CS*hBKYr|-?}Ww1 zm)Z9z?P$0Bpnn#EpFg7_B03{iE-L8uDZgVy0Mz51SkW4~-CBvCo2$jU(cqsPZfGrn zZw(C#L+mhWa6zprMFs<0D6_|Zhl{Fgtrb7*e&bmUPpQ-O$9}HW1OA^z&K;jagaGt{ z27#zVgGV$QlgYO^JCO;NzQ3NDyIk4@%EW_%bSVS{;95YI&Wz$IV9tRaPKug3Y3G<- zrYZhqCf?nP#_YtGa)s51t0~67Ab_8UVut6wl)wfOhUXsJi9dRblDcT7eB zpd~QkHg9zF9PuuiK9L<|3a^P;e!fzU%^9|bs_1S1>A*wH;s9m$+9!Qy*oqppl8a>Y z8JIc_w@Hdd2Dybb-3z3XMfxbHJ{@w$I6;Vq@=jDl%o&h1#JxlvYc-uP_^?vFbUgkn zVdA;M5>&weidT!uu|#T}!fuPayt6hcS>k)ekS+kvtJ8UIa}U6t=s4{9cRSth!+c*D zt#|h9Q^8JmC~yfDJiK0SE+G_}zA)^ZQD{=Pkw~O=;+}eiAOEeqVnr0utzJQUXBG>k zzq7Rc(Q$Zj>ut@3+C*@ZY-2SRxct+g7)n7_af-E>+5WH>MD2b+msiR}Q_(0HKn5Vg zx^mUSC`VL@G63K>QZ*SyJ=>>uN71Fh)Wt!UZ_dgF7a zlNulluE2pOTN@t3di(Z71jb&=yC`|DR!9HWhJNCDA|KlluRZB<>>W*hmyw4NPwKsB7xKBLgdAK7VSeRGe%-3tv%1XCJ(Bipl*rieZS?mOGS$1|KIvf$zegAA z;4ns9(Wr1}K|_Nz(XCNo{Q_TKH{#Vs1w90=7>X|tmzT-PMZJsZF34sff_ccBfLz8?B}bbT>U~iHp-m@8fpTBmAR(dQh}TOOd0Cv$M0SYtQ3g0~g-i#Z86%vV!C0 zT?y9wXG(czj&wiid*f9!>M4jEQg?!1`|XA=6MoQ$cM>F-CLHk;At2yghtc-!*V)e# z?)Tj@xegJ{blYV6(NVQG;rPiDzonl8%Gp-1%Jg+^7FZIag1w9l9LX~dE zk+@}XED@h2Eqa!%XHU9P)>?R(^nFF2^V!nmHI!GUR56D7`pP1x3sg1SKCppx$D^`_ zz9q(7I_4$zzxyDbZ`kenT1C zXEP24>u-NoT;F-MfJW0OxBCGnpFC!r&J+z%&nkzXS9bukA3&c#WMxj<<0Ff#4;|Vc zf4Zu*GQ4IYQ+Onf$6(+a1+m7E00$TZB6U^fIY?5vuD*L|?L?CwMOUreYAMA)g4qWiw5&_e2w~c$f zr&cwc93`$0?d_9QR;p`k2t=X^kC5Da^*Of7Ifvea7rLZ{=Z@gJa`p(CT2zl&o+|B# zNYi`&;Vtg%u+Z{@%qZS}ZR`r%wAC_!X?%liM!pHNm-@!yZiW;WKYWk#$V~jOuTMG_ zwX{7FS-Z@{zLGOE^fTqBliy|q-gTu5-ropO#cMs9*tc49Jld$UD)cNOC@GUa;SV?2 zaSu0VrX8pb51baQr^W<}mm1c8Nmpj+XSU&&2-pcU&}H8bLF|v|oqp<^!|+&ef)@?G z?MmPNW5;vk1*Y~oCe^1)@8)M_TO_x^n@4sx-LosCB?4J>{U3w`9!7lB+avc0>QhV( z6WhdHXSPy!K3DsqgP1%|l~c*$hR2_42EpwcWGa4+ll`$bQiKyyy{t_jn7{O6h zreO{CoLC!PYq!{}(dt5e9rEb;W+t}n8m=eaTJzNgWXRWoXR}H`_<0w_xtDs?Gymwu zwytXa(6et^T3XuK`m|fQ(|Fw?XDqgTOAyOpb9;_Gp;WKx)7JZ(Pu#&Wv8~&cQ}EDP z-;UPjGkGFY_TfWg{Of(g21T!}n1b@ds?4?V+Worm>J~K5{oFuZALHb~hgC(<+6{={ z)ChaZI$m5BHeGUesXmq6GJQOUVbiYiYjMwak$3xU9ss&rmVdvzofGf0nJ9LMXtiSZ zt%T{?ZbvTkd@Vi9aB%3&brRn^ptyQBH(yo3>PlDao-15W`{gLtu%yXQKy@Z0Kl83sqL)oQtpLtbOSgXeNl9@n9K+ zExjg|Ujem0(|(ifWAaT_)Ay|pQ}q4Q&y?!@`Ed`6N8AlRX7z0xg!$V|M4!N5ha+wi zH~jQU^Mfb0PB-;V4VK}R+*Y(!7zFZq@+#vaFw0DCrBU-TGuLSvBBo=v9tgcWlEuUD zEJ`u%`TdGebJAd}q^-Suoj<~WutHZ@aHag-ea1qo%CUW(^uSRGu$U*N5%*gzY^88s z<8k)(_Ayba)Uo2*vAR!6`inwR3xBN7mE!E1 zLrN=n2K*_I$bJ%J25!71rgrzfa@KIya=jR=2X`JlV;tpiBq6AbMMT zwQ-+J<1PO3##@w2kl>o$PhAiKa+;>9`K8M5mEf;_Ti}<+~-r}CE@@-K!sBVqE z$trTJ7u&fq%!})$^cWH@k=d!Bs%K)7Yn;Uk7baLd(LaJ^8(E4Zk}@_O0+v(uj$-wi zbGm-pyF%m#ei5htidiP^s9=|bagvGKyA&+ecE5f5#~5Vw-Wuw=MztoZTrhVfsE2LO zPmWuP=*NBQl{M2#LX<*YI!FQL&PN=Yklyp0f?Clj3*3R;VuoMM(7e`uEjQ4#SbL*eFv zlF%IDrf!Ap$bZNAPff2L2QWmR#@=Mq3|*c`JEryea>_1k9i41S?OqzFC$=2cp)~)+ zoP3Bo+S=OS!WWc4%%EX6Cs4wZ#Ede5#~jOMmA4p2tjKKNMt#^N{PQe3beb@BY{E3d zf3p74l*)xd#Pqd44FiS;Z$TlY+m8pTZXgV;&$movyR3E1^ms5SXmEL~IXM1y2L6-` zL$n*4s_yp1Ikg1tzf4+Q`TVZwrTPI^!MT5HoU|(lSNkZ7@u_(l=A5@nx9?M2xd(*OunECklZ$Tt{_Vn_W^M+&LHQ zXvL_lQr2>IN}Pt|aC`oi{duPcXxAHe)Vr)$D;#7%F7=Zx0y~D`_Csm%B=V*hL!&H(*{iy zuKjknh{A#gcMPZl8-je_Fe{+2!fj+<%3ONSjKhffb*MG!CuLO4HPS-G+#eBADe-5p zw<`kp=Y&GX+}F7$p>3Bs;{Dz=Hb}QtJqTT+xHQ94NV_r-qYoEJn-r;~_I@vyS@wV7z3YuA0o& zu#qW!Bbm6(dU#4dK!kgH6PJ+A&~0zeZ7AKRaaUJKdx%@cX5a6MZPb5l&90E=T!_OZ zSE@Z0gyvD}nbw6heI7&{@)gCH8e`L3kPfoXkUsH^=~vs3AW zQO)X@^5xPUb6O!DTkGGM>7Wx;rIclIORYT5r~El?Vi1(R`?!_}dq@xHjgT+=WAc@P zR*)8wSrJSinAXn{kgc49Ez_rX`8d>O+&xV&@LsW3^_ph zc^)RxPWNsreC zgpIkpq0r%gUv%SY-@ixRL(>?+gjZ4WfzV-tP5zb_KumgcRm_X9S&MaY3U>d~+96MQ z@@?OWAYAHK!e?yTS5-e${yA&_G|1sN8LpjiH||JzgBTbAe&s$tWNUHGo>NH3@5c7s z3-IIME;CJh{L)JgopNtB?tVGR|1%ReV4Ss|)xGYO{`H|K1V?p9)O+1joa(*wo6v8A z%e#*>R^aUMEus~CyO5tDPETV`o$I+GtfY|H&H_{K8vmZMRf687oCqyJ==8`fRW&uw z)aVOsnwK>!=rJM>@1I^742M6dY&TE`YfQ`TJ0U_-d1hWW3BPW{_{TC#7f}dtL!1W8 z;9h0rzNo9gc-MNhyWH2iLn)>b@kQcerEFc|pMQbOG**#iV=CrA>imo%cW@0PrXX+6 z=v%*OhLlE^R3Vrq#YxYpiR^Bdb`@GfkxZO< z&Tqnn5QP=HKI8dBT`1jQ*C#90UeRhkLs`PgJ15j$-enyXa3X(~B8T(HPbKUUK>vN^ z$Fg)R!1$e4G;u?=huA++=3>|Y!dt4t z*vVTyl=+*EV=gh z*>P(Q{uteohHQ}!F!hT@HtdHa{jnhOYbgaI^qc>UI1;2e;#|Jmm}T3L)KzMG`m_&z zhbw;0;JK^kbghAOQ@j|S+C@katmv_F41Bb1?X?!Lt@IF8RaLs*@nqwpjkd>oCk+s6 z7)R`i7gRvC{ZzXH=!3Uo;e#M8VwPS7VUj`wY6CNc!AjHVE$0^bMICGsz zAJrpz&|%p7BLa$Eu6MyOZVUSC;8T&yKh2$^EClTE@bwrjOt!SbGG9B9e1f zkM45=@lJe?$j-6hefn1jI1jGpy#WZoD1Gs_mY&f4431mZd? z#^U&8_nMGXLb0LAq4XAV;NYG__B7h$rQ!8@?W!hbG4A5!o)#G=%tLaU?|hj-ES1I* zd8j$}%!~`c(<3L;9Fo?{FU)3gczWemF<43xi$6`)Ca8h%U{X2l802txydU1v!ZZ$HV%09uU4b>9TVm{)e+f^AgdKzHp^;%u5}-Z=r${gNy~b&`exLq$3c zehMhzN5Y0Kao1wog{1`S^}zGz&u`ruFyRwz7rZz#c2B%~0`6silT^US9bNac7gmQd zA6;8?Hj6xk|3dVAz^uNpI|l{9y%-xfH>wt0fAHdj7qD~6{&%1LdshEw{R@BQZApU| zSFUNFub`#-Xo=r>4d{1J>gC#vw*;5}pJ}@l%BEV3|M@CEjc3E*eKqUzosGZ@4@zXx z1Zw-@?O}y}_P#0^em`7?&Jra5%x_>m6#9k-1(6{bm^oyuXr~o^SAzfeYn1BV+ff&D zDh>&Y5`%*ZCzqKIcHoxVb8GV1&Hvjhc~oa*mW0=+ENB9bU0~jxR6bZT=q+J6Medh2 z2%~}(d=eOwvVRlx2%2YB@3JDa5I?MWbphsqrI#S2ma~7%r_g+RR=MC*ziek|AJ}qV zqcn*>1h0~{bXVaGqi!O_I3$bK3^wJPQHp+daZGK5g3n%Lebybq?mes34`2U+&UUGo zV=pTzs*P2-1c0sr-x9Fq;UpPR26JqKWw&UN~OxN0o zAG#nO#)CT0e-j-MQFyGPu&l>G{CwzA=KAsemR0cPL}_a{>tQdGVn|tRmfs`Zq2-qH#_%v9>omt zO2_tyAOzo)T#CgiGfDb--Ib;u5$TeBI;8|R^~mAxE&!JB^KF z{TIvq<2yk+ z9S%5Q(WT^kCC>oI|J=82?sLizv1p&wZB*rc$WJa!tO}!EO60_v(N$XqE$Z52qf;h{ zTt;%05(R@;HVD+y*Dts|@x#bM{%CKht9mazZpYfmP+!xFp{G_=HuVh*#A86F@9+21 zm34O7O+SJ;thyMHOla7&ddC`lThfDkO6xx;YY(k>{`jh2MqOQ9W!75_Qy3WJs7;QqW4$3 z8oRIdRYKLI#m2^tICf2=W16XxDeBuCrs@pnxrRv$zxq6rkuKTKVKvCfXIZt3 zXOdGaezu}gSuf0dn{Bwc&Wub}kBGbW)=k1TR;+j^xjnPcNZcU$WN2_uXf|YdlX&el z%N12dKzZE0j?~ufKKqa zs2rh+(9a@OG8X}dLP397Gh_Oic_K5T{v%#wH`n0lQJsp!YwA7O$IC!WM4I?-LCzTX zqYxpSt@<{b<+IW6M%T}0I_Jrnml3%2apO0 zuO*U1$U)d;(L_&zsf{nV+pFrdgZi~I#&ff#&A>VJ#b;M1l$DmAP|qcwlTd)E&l64) zW6oW>JW0n@mzTdeQ1k76GIA?HLg_Eb7nYOZmps{VG9;nEXuIjoVlYy5Dw6Q!muuR? zG-@K+g+rE@Jr^=rMfP$?QG7BT{g)=~#VuXc1EDCs&>Wk&-L^X<)5oWmb#iv@QC_66{o8wrW^}?AW-vxn z1$#&RJW!=R?(gp}+*_cOC!%fXl~u|I&ElTo0qw3j2Fm8d9}%nn6NXYh-g(|_RMI&< zr384r4O^D4L z+1IPD=Gn!f3)k%HrFDRsz-fwAzB_c;P%(IVp>=Ai7_onTytT5LRIk&w%=T(mz_1SuLh1M}#S+(nJ)%6@c$TA%3qsFU!sL}4QyviX03`aYViRKNgaL2#MtgFxT1!fPtmcmAS-cKx-Em;N~{@zuH%fepRfXg9qfWeDIYCIm%pJT0y~( zEH{h>&zeojj?=mF3+JASN{~}d@Hu+CQ)#d6xdq~O@um~5Ju=zdOFMWZ3^@>_KWMp0 zx9|`jty*wMF&UTDmNm>;Kz$9uYZhIoLpJnO49$;|c;fJ1r%NcN-W0LHAr%!BYg%mC z8059^`-)o=E|gvAe^&Z#9@$J&%A4JTBiVWechlYoiOIG5K0Ek7Yh7}wYxfIydo|H$ z*kksPjRN_m{ymZ>4BgYta3zM84<^n$y_1=qo$cZ549BQbOqq1!eq! zkwvk%M*D~CA7d&~2G**L!8FjfGlLQ`*)=ug=h*+UbK%hck$8UxEy^d=u{PmdbEQgL z#>v@}2j%ytQn)aTkx1DAi*c=<5nnB0e z{ewL^;e{6H$X!p6kV1DCB=4VMWSv5jEbHPfM7?ZGqcByxT;-SUNgH!)RR6QLpR~^p zU;i+L&}p$+eaC0|+L5u9)VY5Yr}hOF6PI4U{uWS`k;eGG>Wq6iIof^k2VM}exsaQc zx3H`@<~-zq5S<`z=#sdVJ}y4Z2Rh2IolRJ?{KMyq&yKC9uxvZg8NC(_S5TQFYWGW} zSaj7*X`5VFE}buMENRp_RWq3{9I@m%K=evHGL+9=*cznaglPCFPgpb`Dd9D3?Q-l- zI@<xNhxu7RHKC7k2s4an%=VT_4?(S8#&|}h25X!Nh-K^>H(;n9Z z1Z6LpMD`G#srya-&jx6?+D@VI7rt$r4hR8N?~f9n|D-M7!mJofvHCX@97g3oYWB;&m5#aOv;VLgPag&KQYx2x}Ao04dl;G(15wm*zH z89BG@GMu2ky2CD6+A((fI;uc8Os(wC$rq|0(I*{GL$O@cmginpZ9xV*je7)j?+rhu zrH@SQD0x+xcu~TG%Oc^*=G8m!e@RoD(Md=@U*Ab!m|Wn0Q#u3S=Pz$BgSiJ1;V%F% zX4p)?94<9BHdbwuflTNA$0Kq;GUQb@27*4!@5%M71M)B*Tv1o-``{r!%OPMTJ6@W^ zkcWs~z4{Gr2Dz(b3n?&CX1<5((MS!wzmW^613~1cX*M*cit6g|V_jyI zj~~B20E3jY)Rnw+Ca}H=-rNi?yP;0m9-Y!~=Rl9XavDA`u;ZU_HTy;W&C-{jYlIAh zB`3{;V8(MT9|Gd`TSYkMVG#N{P_r$G_hYXa2p3bBr2}{2y1NRr(tDsJ1AXNC!R(JK zdBWyWNIAaynj8Xp;nGmPI7?a3>|d6Xo<2i#cA?8gS1ICvJI3sa`ioPvL%OJz&l-K7LF~ zSwpV$&OOO#@8-RIdz?D|0v~ZiSJy$+GxfMSKDS7@5N7uYaIwAD88N_&Ni~w;4PSSl z6`bei=gZt{^VylD`VS=+;NgtIjI4E%Jc6p+m_?hjpIT_^=m-QbjN7ucOW-{Tr#q+s zxgMllCJ!jgfvM=m??aVp%r_zJaridU-kFe#V}_mwE1t_9TA2G)xnvAYv!QX0oyuU(hIKtM^xiK-NRc09|VieE$lq^3-htjmdm^T6k}gu zhoq<91?e;hTJGuaMG@-hmXdn>itVusl$e@hEvK{Lgr-m^D-suu7_3%?cT19EcU#Hx zi}8ZD5Z_;6GJ6!R%P&iYK??V{3b&A74?jf_&*38?CM<-JM)6Z{56f(YP|Hy74%eWt zhM|djie<4RJOK1A8mFQoN;m~uK^(Pp`k4PkC z8o8OMsXM{BfbXVt=%~?@HYP2D&5KAGIc7ssqD&72IicBly4X2~O-(&y%W8g4wmLKoZ#F20A!_pV=*$S~ zWpr~dLT&jK`_`7Dvgcjue}ez7>E9=qJXcV{?}kzoXu*j9#dXe)yio6N)|Znw^RHaR zzcbFzITKs`BwsYx)Dn5VR1`iSq8>(eHk?)$Sgl}v#C9F**^NEQ%g8%$ z%zzUGR>_C~Sn}<0Q*kC)lsnE;%_!A`qMos){e|uV$@tXPn04%k9^?c2Tdlk|AFK0z z=_%Q(S0`4i)$%b+Jf1zUJcl(6+gVCNN*;h%OV5X^y7ET}MECu(`Z+v5vcIL={d4^i zfoO*;VIdnmPS4i?!Q%qba8ifKE)l#B(V$*q74TTR&IlDozqDSqtp7*`AMJcC1~q{-T1K_ zLEWdV%@JqAgr@u7=Bmibtc_8DJDdbVU+qr3aE*R}@G-?bsNAKrx)|)-&~_G)oNvQr zH**VOXQ#!>KH6hZgYqy$MeNH8IQ4;cD^X{39zjWNrg-KBd#agkJBc}OSYLHhZ zO07mG-1)0NYV$H#_q2QFNWLnS1%x-q)ravhZZ>zJWnd!0-w%Tk!%L4!&2cP7thDa| z?y#@#eOZh70g+0)tG$^rDAWbK$F$x8xenL!a)9M}TIqyK4*weoK;W>AAc`pNyfv5+p|X%glz2G%|liPRXBB?cz6W{Y)Fu5eeB>SA{V2d57a6rdG;*a5hBmG?sB})k9@%H|i#*JxMQmpyD=-6QlHcRcI`EnPvDo0hnnNGoDOeUja~Fmo#!ooyC7!nRpwC_qh>T55 zad4H!4HrBa{&QU38p-%zyybI1^(_KXStW9||Cp8%#n^nWGs5sil@kbm8r&+Y;vmDs zVLuRr?JlVz;_}%i585WVT8LKl%AOj;PrYdH;OdArxe9;K=d}#=_3cL13u@i)^+Sum z+3FeU>D|dYMaBKFuyvU2+&W?)UR=0Z;5v)|=zvm3TvToR#+ZFag?9VN-I#1n`3WO= z;$`!g+-W&pCOIOLa7{j&O&?9AFX8n8A|+fD$#uu_9q0E zq`=hEj25ct9<_*a&fv`-7#Hd5Y+#KMz zUa~Hz^N`%y12z_%U`w~GZEZ{Hdlq0k3q}-AmimT=J1yqntq7GM)mL;GCOv}D`j-JU z1cGjIfTVb%}h1%rF)1fqeX~U?BQf+)%{h4mRK=n{*?VN}Nc=_gzZy zmnMk=?P{MU2pmpDRWShBO;HyXPc-HyG^8YY8haPh+hZzC^F|@Vg1e)ao|k|@Y}yaf zh&%Ccnu?~nB^tkGfz%mCnRkrEb!_syP-Z%D(_j5kUP22AL)sMeqAEv@o*OG+wx(-N zE*OT$j`ht+I?$)t8$=dD%t^M|Wp1cp=VWDfGj9DYM-sOi>`kI(FqTfi2VT=6c-q2n z3(Jte-#k8401XkhNr7pPl%Bm{ls(rIq23mL=)$_Xue5sL*%G`=`Wz9VlU;d^)SGJZ zRQ$i%75|u5M9J;ajsu4evzz*E>5Wf4nCMVdQGvvf%q2I*U~g%>9z!*Ot<~kGA!q9_GUZ@P_-Coy{7DT`>MH27-o59W#hF+5k zW!)cj1UMnZ?%EXT7y5>tbrA<==JxGP5^NvSYED4dIKAsOfXllY-FjJiS$pZX@gaH~ zVzWHiG5NkgGU=FnNFiuHhv-uB3u5>lW}&7pR>v5=tU&<*FxL7|77Hua90;)RuW_Gr z$mW`Ms{=p==P3m6ikgAbX$ba~{K|zQu%w+3Vw-uTVi*=OSmR)u+Z(hT}dI74Sf z%jrrAdqz!vb(uP?2CRkYacmV%nODeUqFDB%?T?I0^%K?$`+1v@ywF~CLuEC9YV#+n z9u7EA(bHjBR&`VGBQ#9fVPa|+=wfZFa?B7nwP8%VN73iIrj{{G*1(d4?y>OZMaMN3 z;qmF!d+|3I0^i7H8#Y|d2`s!>Xw*cH%! zc(9VjRGO6T2*x)&Yku?Qe7Q%eLHNC){b-7lNrmDG;DsNG=sMxsE8g;Wd65{Pja!4+ zv|6%9UThXpA{2 zY~(d{w)U#T4Qy=q=oGqPG{U`X`r*bTBGC>%^bCLR-gtUKhnl4p(*PHT-p|&pxotFK zz@~`jZgO9q;45oUFj%$2p1R4j$$7HhDC+b@0Pcf(p69bA2l=^b$N+}8+gF~xSVrP5 zNn3}bmz9Q>UL%&`8x~%;hA+P%&*v=V;O2&x`o5P*$;-1_mlvGIJd zK-;hqo%=ts=%=%XMCDlQTyVQiU}j&XsZ=0Q=!;jSI%{ypQvWi2L9#sJ@=Fm82=Nv0 zS&#RL*1V%RHApL?BuP|KsbC+8ul#;|N~8ZMBYX1cPXU3d@zgkvHzT-w;W*2C+Dl`K zkpPaI*ZNMbs&En;244LMam_cr)ar?mdwD_M0-Y z>qu&z=vgAMb559Vp&h>^cp%Lnq`u*)S@;JuF3jSngv7gRQlSqD?|f=HC~73=1IW_1 zU-*0)7KpmyP8zLW?CeZ_c6Vt6v!Br-sKbKRE?A>RZO)oV%a;Rwp9;I`Zn{|^?nU&- z$9{Fi&bOhy_rNTllIQYd0@-f^lyQ66bkKoiQ(X}UT1;BuA*Yj9I-W+uF!B+0#R`%$ zFaJ$ByK5{?Lz~!Yt+C7{>;>%N976wYDobjV*S?_H0zL(cqHAh8Bs1;p!#wkC``x8` zAJ*HRW})fN5KpAdWd#Bv>*$0mmRq7WehC?;tN?F5nk64U%kbbq9tX|7e6Y|qCpY{6 zrxR-g_^<_9cr3QHF6tK{YWdqBo#3SPDhbnU(^}N7^xgtetM}F!0}D`arq6!mLHe3Z zjjK--8wB#B+Y{Dj)*dq1;ES!XY6PLEpPQLo;e}OA0PbIh?1s&3hqr?{WE=CJ^O`Ml z$p%}#O>JCm_yxkHpnKt0-2$`x1r-SsxoP9!z_O(5$q37~UD8*fUS-TfiWO@zC2dXZ zr5fgmh+)IyFWdz~6LWNx5z>Yw-mSbA`3%Yc4WPYYt4uPyOdbZ>5%HWbbZWKsf7qNm zlbU|<@eg!BP~Ci2RgO*(zp(C-_+NKq=j=$*)9!oqYGQGr=wF)T`|fDD;Pz}{bb63k zX*#42p1H6$8MaR*L@8O=UhXbPNE_j8iaMI*uftK)m_Iy}ytIL1EwYrbweellI8;~E zK*^=h&>o7uvfKS>@KE8FeQQ+lCvt`nJTP$X@<~=!0C!Gfp3HSZ?UIG=rP0nc+)Hj8 zO2&s)hBlV5IsCyjb_kUfqPQ5Wlg{{A4bf8Zi#zeNmledK zVHrJUiS2n0Pw5!Huq>6>N?Y+_eo`F%;AalOL+>nOXm=(wk12emwbGk=)YQmG#pJYe zf37K}w9B%!r}nhveC|(WXx=x~Ef}N0av?nM$rl23LYd-f!&Sfz5V(q~cdY_>oUlo0 z^{y}4GxUX_n6nq1&z-xm#o5DSo?xrA`YU^As@Os^;k$^pA`0d9`2t7+{4eye{trd> z0&9>3TJoCD-H$gqXhJzd3NpTxzrJZ-T`B%>H!8RGj8d(A-XPM>*uR~ z_!K~Nw@Y?U0IndEe!f~2$>VM0=Jkl;gYKH>>W(=u-}3o>ABld5M+E03o@Pv^Jt{5D z8&({;HRC8O*t>Ew;sytb1<1S3_{At>0AckPpeFz40BP1j3~j->7r9|s%fW$xW$g={ zC=LF8sDr`W^#quB;3Cn99@#)PO8pBo^uE1O(mdYz)4f*e7J-U&lwqEO6!@(2`d6#` zrcE7H8+?^~YMh+AZw=(!YOT_&#~+(nScpiEIu}r4U~{GNqIN{Lvf%LkQjBXn`(!3@ z#K3YyiVhFgx8g2>8IR`0t`q(0=L{<1XfTrOtNpZ6&@yi}Y2^y9V)>;JRU3AN-w7+1(6IGD2Ow zhHk{il|EP6%~U#zFGY-5)08<|hH08jzMgoOnRfuZCV?B;A%)*buQqAf`~Q=KUjgAq zJCA8-eo0G(4+!u5Y$IQ@ztcc%tn-P6uO={D@R>vFHw0+4>*}pm&H1b}y68iL635;A zuy$BQzOb{30=wmLnTLd^^&>3oPaF;>OPQ7=S;#kGly4MOU-C6W)!u2naJf2VC{UBn zYVV<$LvO9irKNdcxo|GjIZ!oLv`8cpSqAu#j&YbYuTYPrDQkOlLp_=<<~&^0;@PfR z;Z(iBO4G0+pmv*MI=hJAR9n*s^Ay3vBSLj;EjL++-rS*-T* zgM{0yp~jG-H!Zm@{bQ(8v+0^MC2G(M`30D>#lVIY ze#E6Mi_@g!%f}$%ykJ;hz&TY$9o6CKh&UOp|Tab@5+mx6^=D(*~W{<#=Mm$YJ<_U z$sStR+giPOLSJ&((EUtkV0a!C|Ip+Z zUhJ*5Ood<46h0PHqjGtB_%7UXXJVdcqm6$0kiN^vnFv+RbvOt3V3z2(Otba43mW%3AX)Ru+M;!UrLuF zn-ZnZ)Y@Ga+uMZe_lSDCfoMWV+>lHihmq~=^7CaCWvwZ^WPb;9z9p1euU5vdY9(4* zy9j?y`_iH-yV#NHrTHbY@&#nYSx>zCbGV@Z&p;u^%dV2GGvK&fxlv<7Hu`J!Pxl*2 zebN#SZZ>?xK5$zgY78N?KFkw|MnRC}`RHilrcQGP2AkzS@fj-Tl8HtsA%rwn|6mZ- zEK=*8>;$fFEUR1`viU<`t6QuGyZa|I!$iNXgsF`b0?*P0nI64u_gGeh)DF%)J^D96*o4Wb<2^F)*R_yWG&s4+D6q@HL|!b z)C;Ymh^6ghGg}!Vwi7z-&24o8uzC=uOp^Y51~&w2i(twyJt47m{JISHgnxgUd@7)6 zI>+M%-bFYXv@g%0Y`@rj7xpZ;hhP3u*B1H7Xs@ZZEQBAJ*-2Ltwj9ejEF2`Pl;YeN zB~*VV7ft?BmhvA;riUaJ~U17n|==DvsL!wBSepH&*Oc!iNqSxapNY+dT!L7X?_3 z9TpUXx1~g#lUgYHQgsIR_Ru`!mzu|~4BhIK$_r&6COMzT3fCRvm#eh*aP-tjt-Qz9 zo=#W!9*E($XC$}vgnqUz!e*DcazN)Rw=_85gi{VkX60m|sIoKrq41zh`4FWNiD|_6 zr$-@<&mO=C_f4^1M>!4LJZo%P8f^Cs9#IuZ@+d2C*6hb;q-LYgQot&v?}Eugc~$!s zBd|SvZ3LCL>2koqc57PktI$#Ar=dzBk zq0LhBIXH^f1?gg?)UT>ba>AXvUv?TC`X*BR;r$+Zk-X)xf5Rwm8Gro>^^HAeGTd{e z9`EMYge5!pWU#-YE&{z^)Z?x+CzHt{q{|cJd%t2&pEaQqlXyF9TC3gwa^&-!y0@HC z&cNk=*mk?K4el^{Dj@SEm4@eK;8KC?U8vO!P_gD}WT&*69Ta&?svTvM1z!qZ2ftm| z((di-@~TXKPqDF~p`WhJs1|=B)S1B==#k9h%Z2^9Ns&yE;HC+E%mdJqE$tku*3I&r zB<6a8xu->4w#lI4Pn_qoN$q(B_v2CKdhZQ$Z~0sFa1a!HOcRt!afH$zKWrhv*&1L$PtE=t+$vZR-Giu*;+iyRR z^xa+=9&6!otw7!IxU@QqD9?=?7?SZjh#1z3(P@qb#!35Z&Nd(m)rW!gz`3>zp;$@YGHg{oR326DqCZ%g_ z>^lR27kZ`zftmK{QCIQz_nghy;>gFEp4X0ue!SaRyFe#NP!CmcI)7YTSMIHUR}UWZ zW*pQSVdHC%B+-BY&dVzso>K7kn=OMzy1G)TGgf-1QYaoL!w1x&|1Oo8<<_NGuu`;6fk>Mko*`(`c)(54F$Y zbGG!cM5Dc=3yl)Lff%$3Z!t z`7o%5dj~#A$>z}&p-f&j?b|oL>e*MEhUF3OD_0(!6V!eI{dFLR+IgO~wY{v=O#$tk z{YL3#uP8>bbS6=@{3UkB4da0Cdd;l4C)iLzvvJl@s7bH70KEMex1HkoZE|9CNDfy- z(t?tjsMCmp{+`erU;=>>2(gBKr23*<=v%&lOQlPr@&wQ029} z6axM4Vvjt1IyDy|lfDghHLissRKGU19m;K|X2e*_> zGot10#3_?vrzs5Kr_Jzv`EB|O5~ebrI+?4+AQ}cXqT)za3TG7dD@H)sWAVhqSQ8RI zKanQ{j0n?h;TserfE#t0a=?kC@hNKrPvga3_fUoIB=)39$oC>xT;$kV`Ms-s z0~GX3`l;^+DiRudOQolm^POlEqWUoFN_WW(6LO&_xov7Hq+TAHsQK7os4nts5=J$v z%3$Gz14%pecx_l9zU~uV3LZ_*U9dIYF@=4FNOUbQ0V_I~q0X0I8HP{#NAphA41Ugr zkbw!D*MC&uZ;t!VqSrJ~%JT@pR*-jd9~LCAEdL_yz0o&@9~?aMzSDfkgz+s`+ZjN) z)bIg(^8V3zm9#(gyH+p%{IatytqhG#5fzBNNX4}W(zqOwe;hRfF7z*iXSchOtOV7N zTkZhrYLMYvSzex;rswnHM0p1Vtn`MH1LqwYs;lpW^^T8XvfPV2e*lLXN_d!7n|c-( z76|!s&Xb65o+Dl0Tg0=UFLw22J^ym|3?+V=!5_#q zz}N|rb#JH#TPJ2Usv&jV( z-*EO`axwhmMB1crclHGN5`Mo-<-1gl?eu{?!^6WOrfJF@{Tx?yc*%>Cd+|MLj z9$vSe(gSxis(ZzH_61Y$&yQIx-#K-Dw4V+hvu1zX8hc7ZgMg@`r?<(%meLV4JrP;U zXE{(2J(S!Btd?mWv|sv8?mn1o!tdL}sYXyE@JVaK1LP>zuG zF8P|sd)-ndC?W0e12;^>?Jh(LPO~mEDYZu$*~(~qg1l^pay-hrAHBPNcg5(`1x7{p zQ+oLXd1DL(6RUov=b{}|q5DmLzl#fkb{tNU^t{l?lCX8xo{IFz?smaf)D<+_*<;LB zL{XAcdaH&QJFyMw%~VLQLe%i-|2{FKW_7zN8Uu z#7tyI{f6bH2ygF3r4xb*-yf|ATDxtdh!+Y&q7fQA+kT_KV&<2z(m8(QQH@ENWb4|r zRx{+k1EHUXe>b0|iTB+0sdw4dyyj9(ir@oxEN}i3+84pxZLm{MUYL~)QB3LN`G4;$ z)A=s)Ynzn{ILDoTnbX`y`Js0zsa;NaVN@z;F@|VGV*5(oVb{C7gDz|UXrEYhaxpl< z1(JIQz;zmNkuGoGGi2wKW}ihNnS_R4A)q$)O1{l6B;A5}AtX7@=sUKWW2vqdr$;)r9U1*4N=e662<- z(XAnUro~R4M#8nj;0$og`Oy0#f8njh<&9%F;&u%yl}K2Y>9r(Z5``Crmbi^f1YEiD zF!F}_NTr>rqHnoJ3&0;sg<-p`)(osYhy#f9OcEfkTef0ENooyJ9LThH&ZuhI%mJY8 zI!JSAHAopMVHu#pK$)QNC%JA^N?Np+*S7WxW|LS3!)XdNV*5{sF`WV5@Q$NPH!T}s zWTUh)n!e8vgQxO$v#CO`(JA$1|1i7CHOH}THJh+miMO{@{Y4J_pE8ucM<`onf&RiC z$j;85_hTK>qYghA$dY!toSMVG&F4K)Z&cFnr?$}U$(bptN za!}48Lu<;6S!bupKtLLo>yz2ze|q+oI(46AcF$bsM*0nWWVD)wiF*TW@$bfKS9^Ul1_pJs=;l{GqN8c0Wyt?n6b*>N8o z3C*V&wHNNE-TPJARcSwA5ig3dNwAmiM+KNw*<(15aP2G{bW2M~)i#`Z@3(+Kf`7Dd z?V0#64$_4wWia3XExB+e1C)pdmE=QHjQPI8B%B*k11^e?d$Gw$8CPVB{vq1L{mQ4u zB;Tb*24t*@Fu8m)(C{bLkibIDqZV(SdLlF&b`XPq4026B*?y^iMEZ$5W4R>~CJmq) zC!PCW1(vv3{e;tjT9uKBJZkgwBQNT6A_XLxfafPDDAlRv$}f=wt3Z6epa5a%>9nht zV^dk*0g_eQvw7nZ6I_UT)aSbcng2|WOEzkenz|Y%(QuwWMg&G#Hz2@~@*vcmUcGfY zX=Z}@7>3dJ>q%gvY&^|b-ltM*J3Ax42EALjvl|~Zg24Ae=F6NW!ot&Sg68>{zBznPR&pg-Jy z#q9xI_h`JifuZ3HF(nT>WP1csh4P&>;rm;4j#{BY*zuME;d3PcrAXNix2M45imyhWX&~&*U_bB59XjL|c zufMODiEHvaX@1#HOU{28RV04rNmz$`Xk70B9}VLgt+T6S#YI4=cZq$j^pN%+GBV<7 zf6WSdWzv_=I*(dfF!AyA-5tNhWei?sR~glVAxL&e;a4*TaRQlhUqWQBmBQWov;|!6l(Ig6d(upDDw&sq1U2rOcU*l+MVLVl@l>oo*8HSwHuZ?|DZ5wGPzZ) z$vM%@leV|Vv>@_DWCm}_A317Wi72>BGrsA$Cn+liwii{AN#Rb^f;cXWf>RFok_Ail zF11=@IftfB|9)&m4cz?~HBga~*24Z~8n#oEnQ9Gpw6*D|Y4X#nvswCtW0p{;|3Aki z;HEk26yBSS#MhrgP}9nwjj999E*Q-8hD;Gewh6-MG4LAG)oEuRFA#CUIN|psc-PGK zd10qeeOS4)F)|xR@V4U$ws*?7r%!mib*A^UenrqEn zMVU9ccWkBROv8;q74y;BG2{8ONXhXA>~UbsC&GptO-7E{+TWXp>wj~P1;>A`IGn%!dreVMO$%o6ZZ$oetKT3w2lO`@+r z(bmyG;=P824%7G5lCIcq4WPoXV7A&RlBMA!2o9Xx-%C?^2~+}pp6zpMpNW>pKxmgS z_tvs(uM}z~G1+kOUA{^|Q(;q}2 z^CE^WM3bggZ?LVz72WhaffibG9?YM;7V!@YYB*g}9~Q)>PDD2vIE#I-hW3G(BX(Us z?v|;SdNWLzo$)4Q*206BKX2=hkLvH%byyb;Gc%j>PD8MSVtfMjW3yc%-2SQW029c< zgG%eI^0hnT#AR}j-^2f&D1oKFvK&@>&{u;A3>|p{V<>VY|5|UO!L>G+qNsEYu3365 z$2>T4ik)n6`CR3P_)vYt#nt2gF1bD)U%tT+ztjR*P=gEpgndI*Ro?KL7u^G=f&~wB zcpIy6qvf4$*)PVXQyqnd9fpC1m_4wy#0|SNk;K|gSX`W#W?XkUQaz-7_@Qv9a&*St zHaOtdSxXC;65@oD#{13&Nn5!V6K`ansJaSF$TP#?y@XwRK&CjQ9&Vihq-O5*(qGl? zx3eEE-ww8*{^R^_f4}F$l>~`F2fRcw9_C^w2+4G$C?Mxee>lG(STOrZ)GzWkxX5o| z^QeV|g?RVb`pfZdHde5U7j|-f?NYt?^Gl#*^@CL|$}(ojwxeb(zW6^4_5UddHn(y> zNvF!ah1|D*Ooh$56=bsh!GmusbW|_(KYQ(AwZhtc%k7H;n!#U26X^R^ zZ^xVO|Fd||G6u=U`Ux$0D`fi0qNaS|3tCgt(k*ZvJdJ&|K&dTQ(Hq<*6{T8 z!3Clx(5b{BCQP=pc>470)v3LzhmFCjU}=Z+XNW+bO7r}#8CEh6lvSLoIr1$eH%pMLKP$l!^uYR-`H z&MLESt)b+BSN6Np4~uJV5VW_fUWW%kD%q|X?e1IzF$p&*H1y5Cx_7uyo%FH*uoHde z@pIR+1TsuuzURF2PQAx7gepgt2s&=4=l;@XB`-#HdfTv^PlIM)B*H;`ve5EvlS9Z(cmWo38;I7pJ3xo#bb1%9(@b?Mw6)7Ix>eX ztU2-Yq#zHoz9XU64=KO=eJL+-*BacLMT&?Kp=`KSPSb@ROvsotY?5v`d(1^}URV=M zIzjRHp`kZd$y+(SG$+f&S^*j7v8CEz0cUN#9P(UKW|kl^0Pnhl>dDp zfQ^=ke5=>e&NKe3%la}L(LrESNAdPOgzNu+Cl6Np`?tOU^Yqi>vDGCO(h%z6)7emf zA$Xx4AW|j1f-0CBgMlh0440n3y|x)XXpvKIV2KReSD+i6QqG7^7d{KOxFLQ&kN}2r-)(*CBT9gEEa15 z>%m-%ZCHY{LPC`h?0Ef~s7E;LQ-?~5QSuL0s5Sx@#f(I@x@QZN0U@Xz(`6&Z%5mr< zgj!E+i}X7vN_$d#3cYsBP4F%JhbLPZkAap%acgBQjOd@Dj=J%Wg+vEa7G=--#m9(y z`|agjMibOPP%cw5xja1$e7U>yDJrizZG1P!GzIV#=XB@`pYviEchoH zDL$mMwYSTaVRl;0S2Gj2^WVq0d2)Ama^DUz>}LGV)y7=%WQZT zZpk<2{HY)3H6i-r)nDLYF#syO4M?}AjDm+*keC1j8CZQF&P(xh01_*u-`>09^IEIkqov1Ud$3k`;o7m_Se5++q69@>Y=-n^&R2k(Ql|G$ zu|s@r0cdbzd*7S^ZFn@|a}HoaS0|Q>e)d`dp3K&IR9tgc*=RD2hRw=I%qi6*Kkb#l zGFK5R?*CQy-eFCj-~VvXD%1gO1+lVREwbxkLr_GtR-&?GR}c^cBAc+@_@Rn|f{GXi z5YTFrDac-_MPw5Y*-KeLR%DZeB+q#hP&z)}-}icc*Yn52#nqu1_xrx@bI$9$&g$Ee zKl2mv+(!rC`*Nd@bqBbWi_;9R#4N>EdkLNXh8}Ytug_*f;wh9{W0CGP?$O69Z%9?7 zqBIigfmP?yjH7bMtYl2N_51v(xfN|=?KxBDC|OL;)YJEX%2dD@9~Nu*6265L_J#9I z+7DHBg$=r~-C?SK+7`Vkdftz~a>ML81Lv&3Col#Hu|M(7-;w^`cE z-}^X?2V)u@#&a}feH1LN(@iGxo@7l89gR%9qpy^`DS|7#z3bWQdFvB%Me_yIoqqcv zCBN@0xXu4SBxpz7roU?G`nBgj4sE@C(*i$5l&A22jo3isvARj$)TB}J;5Fq}Ss6I= z!{qKS4?RSC0H8yhHI9uxlqxJfV4Ci$NeOx~XO-jUC>JS356`!D3_C%mi)rPh`k%9_ z$r8=~$i8BS^afc_Pk1IbIm@1bn$ftprVA5VFUq2h6zk&m*Uorfw<${Zyx1LVf@Pm% z7MS1g1UFwaV%AIvyxRb8=$6>j|Jo{}Pvn^96X>JRq81!315=N0eL@O1|51P!Nd0Cef%I85T%UVb&?!{ELfCKSjigMPf|@WU`aw=~g{ z51Q8lz45mc|NdrgG?iZEnRB*3r~@N3A?>sc86TAI-kWHtIFWX5#Mt}Utq9g*S4M-S zq9l@h(bQ?+1YKp+U%~Dd6=Qu#-z#oap;t#F-W-8`Yl?HuC*Pid<6V5X$1r>8fPc20 z4IZfcnGDmhCounkoYj`L9y)MlX1OavV(Np`ma>x{RqfxjWG=+#NI`w%&2P=1+)FrtRFGF5d>R%q7t&s)G8y1(s>;W+@G~TPto_0P@AqDU5I-Kmjqb0t4f(X)k>)nXDk9hhU!}fQqU~ok> z-Zw!UJxlwFvwHA^cJI@}gvP0+r}2S*5cQ3r(>*#^?VG8g`w?&C-Ge%b?>5%oDp#G5 znuGMqX=lVg2AYi+7PY7<32rr8n<|v_*TNGaR<2j}nm#X$4k>$xT_qPLD}$PHx^(>*i)q*e{{joV<;>)zJU0q(U>~y8O$m%SsqpPMLtgneURc)omaW(inL5?5lj; zYZH&Ds&ky^E5Jp~%ns>i$LtqscosL%| zVZ!k2d$OK=xov6liBGkfPmDBbj=vVi+VtW*JZQUiMC+ov&G4hfrqw}9qcB4b3kaJ7=kd_rw*&y7d@9YI zYuEE#>m8VjR%o4uZ66tZ(bN{!SFu6WAjJ19y%u#!RI`VHC3#G0p^- z_QxbBYkU__APF;%D&7_h)l?tQsqXIX2Kq}1W_i}V<^KDRp&nGZSdlxNTySPk9%NmU;{B{roY@Y}%yH zazENMGOo}9ra$WmZ2b8U)%lizRHG;C6a zl&faBC_zp40B!;G0nA54?cM)$K71%FCe)=@CVC@)fpqdDM>@tb<@P`PL z5%8eE?7tU}E#~0;ea0oP>(V;tY~z+jNZz1j|A&?Zw2X$yJkX3*)ZoMk7!M+gcCgg1 zo<1CTXgSgX$%Du5PsQ)Z-98A7gZy)y+8>|pv?`W-YjHFCd$J$pY|{luqGCUtfoZRn z^x=HX{i!XH*-0%v>;lNfF`2QVb#I#BbFqOIC-;nr$x=G;V<-Cbe@XTq%a0<rw z6yM1t5*v&JRIUF$&g~Ycj9fq8x5`GNti-$G*w|fBYlmtN(G$MI?kZ#5`&m<^SS_pn z&DXl0GvEKxijsArx=}-iyqH3Eqtjzi9iKtf@lZctLUa;oU|`@Gt=FJ?yTf>v72sm< zQOG=v=!1#4i?g18@B97lO`_4c!icwjfD#Wbq{l|g?wj-yFaAojvxoq*9CpS?{c|3MwCE&I z?4NuV!7z!qr;A_aU#4H&v=Bur6CbX!hqS|&ZZIAZ+{WY7*i+xZxd292+~OwW%lP+z zHv0!rw}D+N^~cr(BFRKR!mha#b?nF2yEr>I{0Qab?$BfPW%xd5 zr)Gclf1=}h`U8W4tmqD~>nN!QAi(Nx>5VT2vH7UG)Ip4x=HCWWCc_9&x^@ShMx2uN zst??XdZyjFzE7fX<~>5?^*I--E~cWtidjLFE@6V>?9r!v)eDFb(LaI+9F z)pr+LYH6=UxmqIfoq*I%EJQ~uw%#9k^X3hdXhD;H6_t-&3l_SlPF*UMCyL7m{77uk z5|G;(NFb<<1ZjH?0zC~hYMpK+45NxbA&h_wrLY+__u&d$ za#hiD`}=53o_7r+#3x0&|1Y%TVxMGaAG-slj#Rkb1b1U+9onjexM_@ElGtM;Agl3r z9pwh(Gz{o)>i+nDY>7+kJt&~Md9jZxT9ob(fCK%7{ z^Y-uNwTJ!RINXb)YPW-v4MZc9HIH8crqRs2r2#sxY5m*j${?yDgj5sH)mincwf?^l z$|JjQ0SV9%Gfny~uMf99WD5mC!$7e|iI2zD0RJyrTX2nT#-0JGur*(R6 zS}6R^;Zt{x-V)X`xnN#9)=VA$Hc)C}>Qm+89mz)WCL+ntTGk7#Gp5t@wT!8aHmBbg zQW9VGRSZ1eZWrH9G zZE3>R?uGQgzEB%hi|4u}3OT5mzRK%77k~6ve8D}etPW-244=B!MRCGSvU3_n>-}Up zeWKNYPd&@CE4lwzJo@Xz&0n>@_-^h=O%vp7UJz>*oN1_GZc%A&jtu-bQzX_w!AEOW z!f)fvLF9vJH-l6szk8|u(X<(LeZ78^WNMQ$LnZO_Lqu1Wn06D|U@d)B3Wn|36Z`Rf zfoOUz`Vr`-XnU?X@2`MQ^m8!@;Y`>BjCDvC&Sl@5BA|$0u|d&>i6O zlQl+tp8)i~221R8jHdSwRQNw!&G?k+!T5fesmo0TtERVAQ%cJ1Uap#^a*#nUsqszu zi(hD{vHXB%Qt?NtP2u3z{1q_T@J zbSi$$(5;rb?EE071Z0vPNYl`tb%o9xg4yJ`jg#->ZO)`d#osdykvs!e%+KXiNaRRf z%ZMUwau@pBRZHQNn+hj)za1XowNj%whdVXg@$H z$~>i^J+;suyK4H^D)hicR(Z8HdJFNEG5M}+p~c3=DC8-*%3}BWdUxM03W9}yZ-V?g zI|6~xW=b_Errgf8e_j?OxA><0MGSNHU=;h$hf}6RI9N9r&x7ndcRkuHB#m=eQ0>vG z#qdhK9$QW)Y?gcFPXF@}LN>;#cFNxAkExfA)XfTmTFgI1OFk_gq5|RByFu37ekaFZ zg8j~M#eF(LDGMV3n%Wr{iFV33PiR2AVjl86u$IFoI`c8>;xx=ctYI>bnHi%T@#1hN zk*IDwweX&C6F2Zyw?0TgCrp`p#ppJ9 zd~oBMq53v=K}}M(&v5SI(<(#|w;*`4BH=H`f4Wsxz)t_5>y?W~cjiSZsVMo!eiv7Lq?d<{MmTr*- zX2phcI4$xSFL35%`dJH=^<2%#=7=G;i&_}_lw$p7V^l7bJBGJ(%=*Wkt*Is?kOIc@ zeR9%olcfjO)vs3MGOh34_t~6)j6d8bVL7)fb+A;&#id#a_eO@ZWZ?pm%jg@RG%7rR z&YVF3G&m95HmqhqFY7qFh4|-~~z8=eZ*cg*syvSU;GFgWX5BBaT-CQkWX0FiZl0coaDK-SH)#qAAmC z&}wsIoOD#5NE3#wN=zt>eUydS{t+5Xa4G`l0o2`Q>@82#T6dAf)rBYy>+?Z!<_rUW z>R7zbVAQ&LrDBlVM%vs7{&*bJd+{;zY4OQ}`DVxB)hme2*zm&ReEz@2AffnEA>;3n zg6dG7@@)Za&)i0Tl)S*nxbgDB2;9MU!BQ9E?<;m^y+r$T!0 zhn8;Fpq{D$o-k2ZNPy=~%0wNEU4|c^r3*4MAr6aH%bW>d&5mu6w#$-7#7)ajFWrS? z+?t``p72SW{ttv!UW=AS_a^s7Psx0l4OVPtH?U=pAO(mw&4v<>jkF_b_>LQ`uW!l_=IwRb zhz*}Q*W}#@MX$1S)08t`!2??L+wFA`OwT762}E5rQggIMDc$9Dm;GAQ0)|ADOK(ol zWwmH6;Q+&2k9|6gQUs;T!|5Ay@jcz0Kt)UqGMUV(s;b`JULd?KuNMVQp+tQq)X_$Z z^{Q!RHG_VLr?I%G&PVTtl1%`sGv5=cN+Ga;N*qvr_)aA6TkiF6Yh8_dJ zON6c^37>oyvv7ed3WhRt@(5^#@wEBu4;(hjcf9jjq2hRP-fGY9hAtzQFN2322jl%< zZQO1_k1Q?S>*niGoxmEXxxDqI1&;pK2Ma35yLq2)(1bX^HU)!2aM6wUu&(wAAn0W{%A7AHnu`8mb zV;Rhn0P6)s=OTs`f?k~t@N}rkwvhx_aF<9-x6DUv)VwRqB>FLUHNs`jNpqSsxD&_m z>==CDC+6i5LeJgyBI>d>ucp?dvuAn=J~?umeYq5FU)z>O+jG^kp4Ywi^nxuP15>~V zRrQf4BXz61IP!Jd_wz&=63GhEmh}5n?vq_Oty<5uLk*i=vNR1;|5zxV>y`_zks!dc z0oqpgvmu<1Q%Y$DePqTU&WF`HhK!d6?cix6XK8?n_^JSz_;Y*(v0tg*5B`jo=B12S6f1_oh%GZ9jaqZwafeXJK}Z`_`0#^dCC9G|+ZB)1P1Ad5gA#`oxzYcyjSH_p3;kaFw|8alSo4Dp%62I;ao~ zhhXGYM5~OF*h{{s#`fe0*Gaur3m(*2xA>SkO2i1f!1u`hlZ=sciuJqub3%#?!IvM+Acw_RD;go z3AxuG9Qe+>hWbnKadBFpEBK`XZyFw?6pry@=U?S=K8+y@0gl`TdOVVGM*i->Gq#7r ze>g%Gf84t#nY!mc_AIqGSzFqY#%K%Qieqo#drBm@@v>w@k-sKYsw{XjuNUp~Nz%G{ zd(+2eVY=PaB6%H^eq-HR0L~`gJ%^ey!-*}_WS_wvMxF0da_t3+At%7Mk9`6M8I@{l zhF;x4u0)lCK|%h_qV)7j#PqJMw%Oi$H^OGSTTe-xuhYV2cp6k~fRU?yp3u`Xd0u^} zyt*F4pS&e1=VvP8j0uSvr=g;u(NQ044emk?X-Xg6cflAnkHK%2Ha%)O9TR7D!_8Z} zKe4aKJS2^H=L+Olq)gH$+N_;V0eZBV6$ zRbV~)dQMJE&4KoY4ZdUNAoy@eX(0w+BhIFG34S&a`ieYzP)&JV-dC!;u0FAL#F~ev zZj;mcZ8VA#Fek9a_@vaxp2vb-b*m+EZQ%HM25n}f1*{T;Y?2QQL3J$g#E`u1>J4|c zJg~hUeoOXE@|J8x>!N#2G>9p|h+S82Z{$D+bt2l=5mps?&ijwA7MGRai(>FXAJzY8 z&TL-+z$drink@PJ{}_zg1_b<2FG< zq0ZLUGvLOVnVFfJn_F61LNsoxmvZ9E4RJxp`4GNaeWz#RAq;9{Lh|gTZE1v2$##K- z-XkX0y$kEumJ-`@kDTCbmwz&C&Cp~0sAlKvN6#}-*>3u`$!-JGqKm_ArrjwLBpGXb z$A~+KNEN!w7$gR1{r$i20)mITO$niw5odn&;5Z;7d^>i0O4ca`zlGss|BjC}#rgRJK#qC%z9TS$J+JiFq7lGgPrbPrOA?bMtH`rheFj`}Irl_#{UeEJJXZKQ^ z&VBD6RJ}3e)y>e;*A4a@DLX3CXUzG-^_h10ya^}Eb>8Tbg*FdxCE%GxA&P}tYt_Xk zg9q*T3bvw4RJ>nkT6)CO;Ht#?WT<*d_qNy?*MLa3iFhuf~0h=KU(S*|Yv;ZDe zhoZGyaTkFde0&#(SXTkJuNc)fio^_8fv0?(xo6x2V)>8}Bv6mF2pOe4i&Dn}N zVOriA|M@HPz#p%qsAzx_JyE;p&|8BayjoGt{a*=A-cw>e?H?iVF^3u+XPc*A2MoqJuI8QY)weap2wdqGYVuwTNz+7`QNnvK~d78 z2GbSBI?N-{-WjBQ?t!jZOZ?SW;CrI#HGvJtYB_XOkN%E!AHD`2v}GCg=ES;>u2Wm<9@x7BE>)sN<$)bErIO9`5Oow92BkE)+7HFI|V zs~b!F*;_yy*O+wr3I~La>JcpZ`ybPxSX|OW`md zty&%u`03p+xP66N`J2AI6}C5hb3!tqM1G?lXFv(bAKL2+oo~}r>-pjk)j-r)%`2?I zXuZh%PBaQ9Zw=gAdcd;9bQ^H^a=Z>G^;PVn0SJnq3v{(l>}o1Xeu(G|Mh1RZZ&T5C zr#-Oew&sD)2mDWujL5wxuuJFFAjHG;ZV{@1%)8vPP}>v88p|bmQb`E{iI%JTEGQY(^AygV=(&3x^;1#IHBUsJNwsFsk7*<0SOEK~ehufo{=5U^@Se zE?Vw?uUX67vw9k4(rnTY2Pbm{wZk_^VJ1_|-;tukVXlh&RH(WXp(5~XHc;~w=r$=h z0PsgvBLC%%DDe(F)nDR$5YF9^^9;j&E0*22FDSU@UFt%as7=kRr>4v!g#fKc5Rxy< zb4(t}^p3y(3m>y|@!mT%N3EK!sHlK-mW{YhzI&{>zJ6!AdfWw1)?1wcdp>4I569f4%BpG98Pyz_;t1rA7FCoH%G zk5W>g?s~`fuIAnRmED2fF3)s_E(|kpx}-a{Hrn|si;|+(b$8?aHWSh7L57fPf-&L0DW$xqF`Ia=+O@LDME_q=N zSN$A%M8Fgx^RIf5`L}J_ozja0{%x|)WcmW<2@Us)+~)}vI5Kh6UEurU!zP^B4!me8 zE$C|B=uFVSbG?!*&Z$l-P^+i{%e%nG94)(mN7fo*!ScIN1+w?|Y|4@+z;krt{4oZqDsfT3^4B(Da^`PT}}B*mj5Yp5b@r zd^|ab{KXeAjE^gi65 zSd+YF$T?o=cqoa~=`s8c%08a^)exUZ55gCpf6#H7MSu90r~!hWU}=~TGW}QzIK(I{ zXTDSjYiVH-Fg}7+xC%34Y~Qd<5n*9`p9cMiFacM-q6E%5!XK&;8RgMtCq%M9XBeh?HH7|`Do z!Kn+VCfGM_N)JHe3_LtACe1~ogoU)tKt*ysgh@H@F}sTc?D^C?sN3}emXujYDVfK& z_%x3_yG=Y9As~WCo&$BgzMh0|7;GRJI`gB~3<19Z`Bun$TpJo}o6NkcUMRIhq{j_N zmr%T>O?ygw#^5rxhe-v`Pn1gmX4&%gCB{l(j0bEm7(o(%STq<2)djOt`fG-W-C#sN zPCAV;di%V)Tz zOkM|44gva30sfyG?~0fxisdU%Z(r6J;@V45zxuJ8VJq-6sJ#aR>yu}IWdey!mVfi> zDjn7CV8Z^u*5TE~65kNhO0K?i{)MA&CU#!b#V~(-Xlz-9c%3JAocaL*sA9khyzHBn#u6saojNmq2?({o@^^I% zqe??vumtm&BBq-Yu&mLS0dT4%K>;9DY42}{si4dxJU%d!c=iN8cB&fRf@S7GpOIza zBXw$`Cx715hV`nmv-8hC|AgQU5Sp17_D3?Q8z~N$dlkwLmz+?Ckthv_oLZ6yOqek$ z+%N0GidLGckGSr}RcM0YL~uvEpEhdvjcP%q*qB|HTVD@x4hnEqmap^v1Bsx}{}I3s za4VvUmh)&72KJ|ChV}b0nanBcIF6tj=?T?-Xi6CzBJbj$`~ndA;C#XIYT zeZIjze^v`3T{m0<#sVu0b0;0GRcA)!@Xe7_;q=_G8C7;A%06Vp6ppR8nLi{|$Car; zm$|twbNk$<52aKrcLAQ;7om5vryFq)NSp!P0G+x~UKXNCAV5%e%}wv4FZ2ZWt)9|Z zVjsH)(u3&3xZ(wNZnu^%1aKgy8T^Q}v^3PlB(+XLG#7S3iHxMJ+)AuNh@^x>7ml{G z($I7=md}6s^{95#rv78Z8&LxMh){_OHcVaznQe1~!!3m89vpPAtO9Kl6BFa{-4Imq ziE;-t(8IN{4)BVZg4Sw1LZ59ich)AJTg`o6qd~_3`3fPL{Lebb4_t8c62r%WAn!(5 zKSm%grj5Z|+&%LcW0fq>#BBcd`E7C>apNrzNq)<=8v*m5K12miKc;H4MtSiGMt?L8 ztebHqFl>DCHh9I+mMYfaz8vt?+o$A+7_ z9+|}l%_SRR=ii44@j?$5L27_DgIPJSZBod>gfuD815NZF1&vgx~23bMncy=@{`)T&oW{H=?bQW5{%4UxS;AKEmN&`h892$4NMyh1SZNp1@76XoFk02@@DJh+K z?mNi{2V_m`DH8dr=uWA|(s}=Jwy6b@I1EL1eev~qKqXAC;daOEXr5evY5~m$AcP54 z6*Y0d^dms^J2^Rl!2#ECR0sL=ik}YAkwSV23mX^AqNq(k-(GqUy@F`X^+Z?!r~s8u zK0yc*_=Q=;>K;w+=i4jw;v+Og35t`Jg6{g)(B0C z+uept7dmp1@g*~+NU1H*{Hb@5c@0O~nuTVm5((Y&k&m{&Y1(21tPW)F)-8r*RN(qS zYqm_Fs~u(S0!w)6R8rIL#Y?uO;OJ*Xf97+L&0=FE@|Y-lRX_^amFyv-u?T)b`Gr7v z_@YEuLK8|(Yr*G&B%@rk;X&eoq0?>s)h1GyC&QoaQSAgym<4G=hyuca5P*eRM&ZY9 z-s80S?S=XI4AkO)Mqi}N^UXu*K1eJr;{C;u@(uM+jigX;d(oLh8Z{k5B(?SwQv1FF zI;CbYhe7xE(Hi^9iqeqCgRH=VA7t4H&hvXFotf zy;*2oTLRU!a<5l~wiKqe|NQ+>$Lo(ke@F+Hcnnm5S%w+6=wQC|mOg2b(YjerPL$lh zPw`PpdxXJ-5?vypufovw+XMMGso;RNIg$=|B>*d#4_Ppf+mM-g+F%WOJfPR0ZLGs4 z^%}SPZQG9rV{nPK;wcr0dtbl!z7M_?%-fzv4l@K09S!gh;A4ZMFhH)H4Yh5QRh_e2q9PEWhS? z!pIDuWhQ{|Me2MKO=l4mO?S)p82DM40ZA*dQB#;2YPsLN)pjy#YqlucEm)eHhhOr7 zvF5NB;1jh%HO(~=xLhzG98I|>^rd%G5bjH=HUy%o8#MY6&!tldAs=4M2oSXYl6uuY z`R*q8KhHA{5ph+5(~hK|Sy&_(m7d~&Ty>FYG}f&=B&Om9I|5lr1hoD;vqm)PiCzfV zc#ojTYk~W#9j?dj3AUyLYps2|<j@ha(7kG zuSPfG`l$|@<9#3MJWs8fZrJ!(|3Y^A5SJHJ-j=OyE~Z%x8k z&Fc+&k5l*jb_E(iZaJk}#|(sH+~QI_>={|QXB+K(Y@a7j7~!koYk3)*FGWm6D!Ffo ziVmoc*AGfV+F_0W2^W+0OVsMKm?s5+oex~5d%PC$a^~6~_*|DmwAgxg7=ROKd8@4C zWYJnbrf}c;zMW^=`~>%eU)f?{ck)I1V->g2% zX!v!R;ro;|Ox$w|1X=s5sz@uw7D+eiT8T^&(esew_v&4%6E>)p4_GXUb>%t zmY=Pe*)93(#>ABW8cy8C$CNphHI*asu`k>kVcs!=Rl9Tamm37Gk-h1DCr^ajyUng$-ToqqDizeS~2 ze3-_+ZTt_*JHPUUpFJ>pz07w8VVOS@1)U)KVVPmWU?AMQ$YP)8m#9M1B8PweoTB(2 z%}T>TG#t9()%wg+AyBCiG-O%TL6s6ouLWe!d{M^y!%%k_ZB|^&74~Kx*|-_^iYF&>Rpk_)1Niv z;pLl-3F-dG!#(gQXdcpYIdH?Z{B32&@tF3(4 zWnw4s&VMC#zAQ~?`Z`uItR(?MK-imQ|POz>hbRxPLrHVoTa z@tH({Twy~NV*ufWX_hq`dNlt<@>lF{BU)wfQWs3tzp#cYUxykR)Xtcj>^eT?wHpX( zUa;*;tWDT|DcH759%C^6WTI|_zz)$BfATv-$jnol!|I+Cv5E4)I`Oim(aiv{ApUj@ zqO&fuP*>6Jg?*p(#0hj-kMM9#VX zY|nwy8ru8(ZIvaH6D>s}Wom%wCV&m!?e_PuAX^kRyE8`-4NQj9LbceU@-?nCGbH|tOsux*TpE^pxbVUq% z%C0Z3m8BTx+qWWo{?5)xswSQrwchV=Z4-(#E<3Wq>|yqkF*|Y>waKexbYRen zD8jGqan8lX#lvH-;2Bwy(IGxjr|RH~DYD9+13vJr36M)@qAsU1SHO&A+JwZ%#@2+2 zYxuadJjJJN+;|~ky5bh_hdbK0`^fzBeY55vOP;NW?Ei(!TdXgOy9feGT8#uB0>f628eY#La4(LD{eb)SVf@{H%!cVf!5G`jr!}LWav<-lc`U zOGamo0$cb3W0l?#k+tJb+nGqoi`kt;BPDPIWy1=3=BHA=GSQg(LDs{4x^f#H%lvk_@@9EcIH?P^i((yj*laD6gI5c2g>G z;c$MC@nE7^>6sPw<-JTIyc@UB(26l38MaBsLuJvU!K&WL`}-WjpBZWd)IjAvuq_!$ zF56p13X$U(2VHe9tIwkSIkFYj)el%JM8=BkXDQp3cWx6jJ}jaT$$gzGn18Sp$cG(Y zZlAv{UqK9axbro94gagjoXy$q9m2IV+C@LVB!nEh$_o{SB@zco=w*g1a zD+n&u4Mb4ftv5b6Xqes-<)Q}X^=-EF+&c9y81Ij7PQj}?+sB;w)QJbv4pOO9l6H`~ zB&3W*TrG7Y5b}5Lm1^ri>dLhBBVT_TepL~C*_GF&NwExO=m2T5w4PtRMrJ&cW& zZ=U(3ys1Oi?wb-mNRr zQe?#c2%q_iOOil^FKIJ`7p{JO5bx&Z5bX_=L!jg!LZd|}z|sEW#UB$eamPs)>LJ^> z?c5FNiOD8Yn_43D6VE>gU-~8N3@GzHoVtW)g6Btzjs7qg{b9l!Iu`MZ%zZYctZnQ&2iL&_s1swF_&`&3hKm2Yg!OC6)4Wty{te8*DA^rW_!jS~|QH++UhEfjKEnQwXxg_Uy3a!;}E zrBW%aLld>(&lreVVfP~$?Nb>Ied;C4JQXlFH`^@iCY>5%kX2ra#mNV8Zn#61V3ahZ0KTsD&BFclvI@Gg=d$PM|O)Q=Wfj{dzt#y zaksTg<<~*URv)f(Uvweyr#R264qQ7hYQYXypI@6q+8-(2b0pUFfJ+0_?b(`g>!#oR zXfDHm`V)EvJ#Rfmjm9Cv@o4coHFP04Apk0h#) zMz;pZG}-iqy3^jBH511oL`7H(6Hnuc5wVW`Z+pddQ~D=!uDkASd)`)F^OF(ftx<8p z#$3z5x0ae7*TL@3Oj3V{Hxyt1=(SgMb6pRUNq9NV(HailE&t=qNd z>z-dM&vBgU$}aEhl}j?IjCl4a4xhlB5Nl6qcmpQ|IT-;O;U-A$M8bCC2I`*_8p=f#MlOkq(f^{i>WT`QsAr{vOPAHBWUU_g1} znhBqhg5m3b>b;9cY)OMX&bukCSFYW!R&h1iP0dyqFJ7A;)as&rme9mo^r`$v{ExX# z^Yc#rh2oScI|s?FT%tI1qu?7n3z|@eG<`# z4Rg`D5|`Zoc*)jkD%>%npd505_0$g>K#UI;KCe@;JlqkU#USL2_gzuOd7GBG#cfWg zj_PrF({s`~<%*(5U~G+ru!RQae3^DFrRk*d1+jI7_H!zuMRV;%y~g&91-0wwi)(H5 zwjMhj5wJIF{vI3)J!j!wYEP~+i6s2_o(Ph(hzCis$ECV1JX4}0jvw7-)b5PcIHZ;EiYd4KXBIf^YgX2l9QsvhTpgG;XZ7;2f9GK8I`rZj_?UT!~ytQoTPo{AQ# zjWj&09|`4{q78x)NR}<>u5|MwKFe;ajb)v{B-iLZY*Y)ITz4h!s)B>PLD^G@pyb4( z7US{ZV?LJu87}Wc2svfp66H#7mAi9|M(aQRMa^2I#kh$i6j}!v;9|G>09sX1MUB3e zV#^hWuBzs;Dj#QJlk0=x<4MXti{;3_9n>E(;q!+dnA|6L+ITdlqYyjsV#dGtOjnLA zRYC9FWb%cn$74pLjkB-B+G_^7n(7e>Vyi^CKN)N=k!dy-K!UsQ_AW^)COV=#dPn

    Kwsb$T*KJCs^=yeXLhS6#^B9RK zJot4mumn=#;!fAmn~y4bW!=&jDjJs0%gi5d9!!$z84+lkYh}CY8cwQ@knyS7qr!dc zQXH!MiCIenfnPLQ4I!#4IFF2ldHp&rLpUxSb#>NMLh*6<$9W_IMR+sAN$22IlL z%KT`vaRTMeExO+~IO=M8m8S7?nfa(bnN`#rve%r#$Js4s3)cpGQb=<0sS;8?JdDVg zkDR6JlJ7?a78PD|xvpL^P*+_3-(_xT%^~3BxY6(56%Ro0&(8$!oD+<(oaerV*H%Y_R9 z9_4qR^X_Fb5(zCmGS)+6ql5s;rRvrTEsE})zbmk5q0G0V0CV|1RoX;fx2|i?$M(~DTk2D1o#+)8FO-oW<9Ln{0^!Z^7YM+B^lWoHSU&Xf58 z#`tANA;Gd=*F?o;{SayfBp)mRcCxV;66qaX;O0&h%~Iit=+kB}v5$YWHeJGqmu&=o ztpGq}aq)S+H#rZG{^E6lC_E%YpKTt-ASq%Wu*Yq^Sbe`gn;b~fs3f=Yh1L5t6HZ*e zTQpkst*ntq>1zoY8Q(D*6pB;j=oD!J%xS8|9J%+ZU{TaWXKj-g3#^Var9L&3lz&4v zl)~YbEu=9~R@>hZP}9?!VwNyb(bDQ{MOs<>EAkgD$|cNvAniCotE=qgZ@2%f6Z$=l zAbw~ucxUL`vBp~U6T0q@4c@gnPcYha)wlmFwCk0k;O+#0Rq)QqVP}1wPn?prRML~X zll$sC7kXXaMO7NV@NA@uxOiZxWK;W6NjQt+|PZzHkewf-8hhCN- zulV%PaewZ+riB??edf*3%%T6oP6>VTq@io+5%1W2g~yDr=|6B_bd@NLk*nrRNk4=A zbBh;OK$N^!jIBEA$+9N({2&G{{9cl(c|me=Bh2H(Vt+78;2PW8DJm*hQjo1N*p*7b zjgNxAKO)bG+*v2Q1_;6YS9=z^(i9?Gt7i*4bfm;(>Mk-xa|Qp((r`IjAyVB_DkT3E zNqOn+^Dh=rdjsD;31(Qjo3JYB!DJfusK8}z#22J9)xaHP@T(^Z2no%pH9{#M@4)=` z@85@x3=P2qOSqBTmfW8A9&;acnwgriql*kC*U8Q4?%@@K>u(hN=sO5Crs}i5po@-a z$!@aEf!A&lwv6iJI$q@7`&KRFyt&BVxaJqEQF#Ld^z^Rqv<{H-K}Wt@n#u9MkiS+a z{ODJov1yx0sk7?F+pf&l4KlM~^jf zry9-tphm~|%&&?yO7s$;jEw;J3TM(}n+M_((8a`r1>c)gxAS0V%F!vp?Damczt4~9 zVpc-^zgLAUrYeqQsjwXrzityUE<9%Nqhy=u=LWEh@_A=GR_yAV5aE-ShO?#nf2hgX z`8nXU;E|E_$L`p_flTN%+^DN#<0Yr4IAl&`7NH_nW(O<$-OB12dM03J$CD{9N8_KM zWN^WLNkV~oKJJ2D8D40Z5(X@Q;L|j_w3440!X8 zEiEmKa;uG2G`>M!Ymi`}r1*Gf3Dn7R28PIHeeM9t%F62WVTW9{zCCk>j_!(tirjWs zc`Ruut;hecrMXt71zk zvgsnTN#f>({6B#wc3{IDX|9kIVxkl8d8~GPoJwx&2<|+bG8@(A^SrXY#C!)~8_q!@ zw?qcJ@Of&JHzh%+E4twPG04* zFXf?tYJAx-1xaJb?vqCi4buI{1y&`?_||M6zhv}72}pYQ4EfsA=z#p$*=yt#ccr=quvHVxc%Sdy@&1a_ow z)A8V+P*}WF4wB0p6QeSeX@B`nO4eg7Tm1Xw50v% zNMhcSpkDVJnv-^|SNCw>z7)2Xq6ZM(V^=*W#Lz*weQ|MdYAY|zf(ki|SQhFMH{VU_ z7@sN?J}%_}!W(mCM2!kxqa!5^o(oP6W zPkbXK^&}3jXI@7*vZmRjt z;!Cqer#6$m@T%OXP?E|OW6?fU9c%cLVW>8{d-qdrZZ5!1e)sxg?7o>9 z8E~^AJ)%hJdcUesg1TB>>&2)g(nT;DWE~NGky^*+3gGtl?(}43S}J9+c~`-1nk-@p zka1WhiaO?L=@-+$rX1{ykOy-^K}Czn+S4}GPoMH)1$Ab2=k&SK_63-< z=RM#5M4fp;5;bs_QF%Iu21!<z+2gCvlj|9aq<4ynfvJGXI@@`tXSoijbLvA!M>L|M}*k6$zy?Q6kKZbY+)3zP6W_RQ$*m&%=0Iyc7?lseZrQ++G?Iag5X){VN=cZ8+?1 z{cGEgL-k^l?0>X=cran%l(@Lt?FNRt{T5SSCIQo5q-i{g(=l(*SttK(h)UTT5f{OS zZaQbbq-}5)+!(Zfp`io{ z&kLma)eQDe;l(&}nnog#o8u$1u8`&8&$$T;3k$j_cBgfl)6Wx=9!qb!*tbq)GT?y_ z4A~g(H2l+qwKnq9bvx+zQ`dybdYLdF*Y`njXLnA>^c#sJ;?m%fb)L8n_{+NCh{Zhc zQX8KR?C%qtG^07Fd^t<^z*SOF8EjbxXl~PeMX-!uio`aK5T^cT)-$Z*O3`TS>ekx` zX`jL=cMpg?KUJu+-QvsZ)6e_fpZ{m7L807glKVp4xNM@FThgL&ApP7iF|Wn*&w`=p zVEt2h`sTmW2?lR@7{wVE8(YQyp#BidNuV~|%zuqb&`~3BVy^u9s5P$SGbv9b=*FikvQ>VhW-g)rtIPkYt z)ahY%-(dYBr#~hmW4N$G6lxd|(k>t?ahYnkgFz5$$&V|uzerG*w!snrb{oFwKdxzS zhwh6kk|e?-70~x zrC6~3f+(2Cq^wi}-unEc&_`hEf+!a;_QjmkVm`&UbU0GZnL9PV>z#}E_+UxTRss8h z8K1(r{JZ|hs+WJB?yv8a7vY29V;8^QJ?^z{1g@TcuNwSw9CC14;g{!$vDJAoF%@yH1%rO3r(gr= zKJRUMe1CDZr>q0vmWBWvL*tu{!XDdan{d|>3H|zOq$XEFnW*)@n9Y9&^?{#-H5*bv5o)5G;VRMTgcB) zRTgUxCU-L^>fk@s2FeaNUteEc2RjM)E^qnb@z0M3=iiEEu7}Z$FWLyBNX_Q)$Nn>p z{`;h=VU8qJZWNCcH|K?MoS&?*?gSY1%Jaw!wAVWs=ANbu6+^EpQXXh7x<<0NG z@HeBwzhB-@sQow6J}rk@l^72(zkk0A39q{<49%17hdyj`^Fjrh9x1IiVOa6IDfPUGp z9u$?Ao(*C8#dr+g9L%$2ISE|~T}l@go8dlyVi2=s?PFAL085-JEv)@`imc-rn1SuSStL^5&fP9xd#m(wcN&#j}*@j7KmSUQx~IX zRwyeXLl zs>PI{Dz4V^%G`BRneDnXP?K$%Y24G&GR(jUPdp^aQ=)I>sF^6WneF_?1^<7eSBTMS zrS40}w1H6d9Sqv^RP|!2vuih@$M(_&irp|@T(6L~{NoCfJq+FO+fF^`oWn<7b-8wp zzCu_;?9Eu9j9!x5=CNL&OdiVz;0aLvznc^bL8r&viDX zwyKccS=AdGE38xI>y94zkEg%VMSX_d*DCqg*4HYRZF{KCxSCpclFlv+tIf22|E_8( z=YDvCm2#&Ri~A9io=xgF3-P+S=QF(4 zUg&?s%L>uADMyfcT3cJYx}=4L`;eMzWwQx(y~7C_7bXNvhN?YVI^jD$*ICLAaS3SX zn#$GUBNv7f6aIm|{$pSNOC_R-r2(pjclOi3o$n{6unUERhR!sl`Zik>{qh>frrSUg zNsk9ZD`J>espp_6r(hfS@7fxVaN&yJd(O`7)h2D0fK-pi)K#m*?)O9A6&VwR@+>?{ z{a}DXY*;Q|ko9}w3F|ucfq?9mKSp89y^BDj9V-`W(MKR0+@d1`y8 z>Q`dvK89DrdZC=j&w&B>I)*B65qD};_4K$>(J+(3r zYlOrvwLG}s!yF&!-|qzeW=|a20Ep?z96dIe;Pog=p3C3mNgjHTfhBs)ZA7Is(L=2KQ4*{ zkCqOu1)@<=WTLbCkJ7fO(Ul)2y2N9wTvdeYd|vB19}fi`uzmQfLS zGrqUEG>zcb(t=(MT4ev+^8NdhvEJMN1v*)J z4;p8W*QtE8W<~>Gv8pFP4Y0D~A;<&bWgmP-ye5?Cv7`Xx7~RBp3>k5xB_Q7Ia@>|RQf?5l@#?=8t0Za z&Iv(9kWbIJbVT?*!k@(Uv0QK)uXrHUr_v{R$?DB$W%oj2E?t(cxxWS-eO@#~W^lVr zj#hW_zF9UzWShH_^z#qyBP4~{N$K-1V~MRk_>wyF$3zb6qUnd$=g`_ufX>V%c}X&O z44$;|yYO8G`RX{;tz#kn@`=wwv60w(hQi(s)ZM$KPJbC4vAX7%$UbmK zp!{HkpmaV?Lb$ty{dqbv89D)jPZ@CwHm@|`@G>Q`@5 zQl@`jf`8R1RLX#|PTo@bI9b4~dkyjxzM9)qItW8N>KVlIZWCNK$=AB@PLUpHsv}61 zr$H;DBv67vXgS|n)wr#Tx4l|2ohFJUjcQ6)@P)w%X_vz+dd&T zWV7Qmr?q6s%1n==)XTR=3-vGjn3}>dq2tN2XU`EiW?$ZQb$y4oJmOqGGZ=%{Q)|^M zXpQxhBxfFKJLhNfVfgFUhn8BNPY#sg5xKS~nu%)5DTbce5-^i+Lwt~H6N$w`8) z;-b;iuDL1Up?8dunihX)6Yo8E(1=ZPYuuta;8qu~(?DIIh+uA9qaB*S`zFO1G(RYRFXIxMHNGANeRJF5b@81kQ-tcj*E zAck;WQuWV&aAH5|nY^E9Wo0J5d&i#3dw4^ab8R!Ngq$xU&}Vs3DUn@`^;LBAvD0%O z((j5?C4b9aK0aL^t?wke9c2R-onxZ+{;mYq2EHBLGwnCV$Hx87f1bie z*K~?t&JBMRPe0rd-+`!SP`j=qEi}C+b;GT1F8kCu-Z5UXt6Z5@bY0OO&hk$fdBD z`!|%;(d~XDiNYeB{aOO>qOn2(0>U=tCu~;r!`o$hY$r)p{O8>)#E&^51CRYKBvaJl zY7Q@qS{N=$eNBE7(*7rPg{bYzZ2}cDW8;O5BtPXMchDrj;ECPcfkW7OwIJVXMSB8F zNO_8P_-jdiXt2Hrf`@{f`(uaxr3zGf!hIxBpJaqMk8Ts}#+sUQ`IL1L9KWC37Dn4u zv=!?mSD$h?BnvTrG^4LVoD8#);2g;up5g5Z4|{iDSFeJFxCOma%wWjOf{~8Fk)@uQ ztTL@uwNRE-*NAoeO0eXdjf#(N0{7_HZ zTZJtea(x%gD!cLe)&`vMmI%kegLem59&YIzM|>RM4z(b2Qrn*O!s<_)#kS_To-3 zt85#w-+6W@d*p&sjL`)Rztfq`mW9H!BhE=eJgDQ-!+TbZZ$^;riPaVHo>^TDa0rKl zuEQ*`d!^(slb5W+z<9yz@GTkHIjp!=Os=|I!Ei#7^l#%cCD9$r9Ztz9M(!r$Qw^)O zhC4m<<7DsDmrK4tDJMgi5|6?6 zmTdQLVMkW(KkXbPcE0Z05Obyf>4I)>twuTdUT#lVP;6jWhm2d|Msw(&Yq? z*220`JbpN?0RK$VHyacFh;z0#h9&QK=Zt=%?2?Ozq_DzPJ>5|oQwYTTDZ_v?JV_5T zFz0Mba!7ZUEda0$Kb>?su+txsAJ5Y6`po;t!O(0htsPOI2yf(MRlXztc%4p?mU&nP za@H^-TlckbuaLA8E!RX$EUVkPqgIt2HQ(KGGQ!r-L6c!k}F#-dcaculb9g7<>! zO-*<^hZ%czOAW1_EwcGSrFmCD5@psWn&i=}o~rFvK?$Edxw_@OJ2qbnLW!I|KkG2~ z$iAJe?q`z;k6)`S&;COM{u;FSv7Z?q*#9K2Ty{Zq&<-E0Ef!xuNV)T}ZbCLo%~axG z))em@YIFuI3q5htGc1EEZf@{EV7Ro)tDWyoZi7u;9GVH4=ah(f;{+q4>EVaS5R4Xf zZ^2h2jM=9kaT4j6tnrJcNt&Ep43iSw%IpUV9ZWlmto(cehs>tpveQMb>ACGt^SSjv z>W-i>6#QFBsgt;S^~~8Wdn=-BIy*V4(+C%8J<;`+4Z&SDEIGXi`((`Bf_;w!D)yN_ z<;knDO(Ya`opw&n&)+{$F^NMg4}+b(UT`xY@dRCVn(iBilkW06HUBn4W@$xS5pYY< zJ5(}i=~ezc=)0N}uMy`Y-YCG{>onDq= z$J%B5gxETv`EOoxU5bQ@OA)S)MT#ZqBFA;vcXspuzwny>Zyh+~b+aHjNF<58`uMD+ zt>^y2t=Ro`{AK1A7Nv2GO-;o-Uo}leZ6|BYX1xKa)0~*?-+T61_?O;4Zt1fZ!Gu}sA5?xIC2T^@JmWZO zg(Nd1JZr)l)mq8DjvLvhbCS`D){U-w?4p?l#q==+Uw%OO%+PXPZMIEU7iO=1 z_h2LQgcohdu!V5|q^4SJG9{f#_G#==2oAa6ZQ4KkLhlx7HID z7W(m)mWbu*rzOWUkJdG4z^>yt?fjs^NHCkaO{U&MK@%1bU6|3`g>bM zTr#TNGVxu_NK<#rX-c$iA6&$4orr?IZbb-BzuvWR`3fkLodG_IfV1IQsZ|rV^~tZ5-0=t_k;0j^Ts( z1&1Lcpx}Xt);q9RX1>DQDSuf;PsjEsmmWt~;mVAl^{JyDeix&McSUxy)13f9 zB&AF6p`#uAjZzZ($#eapx%yBkSETgl`BOZ=8HYiqo^egWNYgIyL+x@J^+cJia|H#m zCvwD*r~34NG0zDK2n>yJH6$F}J~EOh?6RhL!L22MIs;C2qQ${H>Drp+9k&+8bBU

    sE$nVWL!`Xg?(&CuS%V;~e?Y8q;4&OUoe`=& zTO5pZ*=Q02h~3yhH{3Y%Crl#f+lrg-L&bO`=*^UE$SG*yu@S#u?{oDskm;ta6fj=DaNGsRcY8x^frW~F-uradI9HN?H!q3eU8G4*CV8>)Vp;8 zGPoXe!c?wWg5weW&sLNC&FKdlx-nTUYxuM6{<%(5m%;#@3sn;3JO-j&pPqmVB@E)C^olN_@<#X`tn0y~3+vC2F12*@4u4F_fs)DJ;=Elj= z10Hyf!CEY0X(`AG=c~!$8cwv$qpSF%#}A)o9Ev`e)xjxu}X#F5}@2icfTHyVRm6-&gd8Aj}Cr`uQt%npS9)F8c3;J#T zaYG&${^JH9swFL1LODfVuJaU#GwRF)1qIy)(u%^#S;*4Njek*`BfUau(@v`db~VqW z?dD7~%|1;NzA)35@ZlveE_Q@gEcV3{nRx6Y9^yz?#;wJzhY^ zjfjyQg)=YlH`dN=9K0-pN4CdX@IU8_@m@mNgFw#Y9_3C0n~ZDr!MRIIq@jU4S34`)fv9CiN? zAW2iG@#HO3H{ExRFErUlm>~T;dZ`!-_uN3}!@O1Y!Gv+?OMv(yB^LHno(3H)fQx_C zvQk;k!h|mVecs9G#mIimAm}xCgRDsDILXWye=_>6RewAkZTU{iMP)hprO1%;)qnA^ zRz>KrG&bGgI+Z9`UD3wq^RT2#z2#3y=jlJC(xnCm;`+_4dlkfSitb_+V^A0M+d7uZ zE}E2-gn2t;Zaq7sW)9sXqn|?w;2hl%Z=_w{C4&9N3C)glA@Ks~amNQULEFtQ*=00n z)-Y7vZJOk=pn3g}(?V)Gy8DSc4I_s`G0%QD(P%q%ZOEMxev8l683>_HNybjk}})g1 zZj)yI>R6kwKh{09N1^rhe=AC>#IpNrAa#7!8~}+h>~7cS;4V$=cIw#00;WHGLg<>( zk$rIEWnJe@ALM6VQgfMAYwROX-UepR))I+OfLQYn8>`m>(2z1)nn`vJB57F|`3#_A zcE^cr+ugFlcJN@jrh)s_XAe1NzrRdHIt~B$Bhxci*S_pgHrT$Gy`6t&lyAWF~ zqNpP#s!nnA3GuOo(k%!llUCdE%I=>k@}Rr)M;Ak#*(Av+#qlMz<&W|45_jFx+gpCDXx?i&IXReBW(JALw7jR~+c13S+|{ zM*OqG0WqyC#6Y2Jukh}M&NV(NVdGAlzRzYFL`>1(ZFrqX_?+T}1H?SXPyOjk^a3Vs zB?q;__)`-qq$M;lTm^TDWwykLb_PWlQS_iIF<+8?>tI}n@`N)o=fURDd8lFSd~t9W zi4&E}=CleaaNrmF)ux9@v(7%!lyr(ooF)IJ)x(YYyyyBK8zrYt5^s(_^pocXD6^|o zH^7!p?;o82P0=_t9#u_HlY!rYJDL#6r>yBD4HXXNp-m`{PzupMu{>+sz1pMfzOy6M z7E|Lf2?2~U=H<|l9ukD=%4OKO5Cd| z?(25HQ`%ug%Wu)0X2SRk=T|go5>B4m9%DLRVtfMt5kYyGQ8-g5ktH*d;hE=Xmc4@OPBj3=%BSf(C(iLx6xS)! z`}YU9+gs1p^x(6sH@&e!*?MEKQ|%Nr&KUy z4Yc&1Hbfxl6&Ex}OReaI??gU-O#L7osdsUE4)uCb^S8CldUYd%*D6n8C{SDeseP&W zvG3fM91o8X`vzh#($Y|Uxe=6&h#3K^EX}#7t7zAmdsG2P={Ic9be7UG8~gOlXw*rH z8WR#;1VqF$f-tdo-dIVB}`Fx6`Zc zcoqkA>bdhjE&oc&o63^In)8ENNlA}9(z5nW*V%Rg z90-{Fvt|*~xJ=!(22AlS56zfd53vd@yv=G8@=(0h@VAxRe@U0H{VsMR1>RsxCC{%i zP*IWRFUy}(g#jSTow;InfCwG_!@q;&cL@XyUg-F7bZBUiO?@HtS399={C{!n2x2r@ zvSpo9MfirrI5IR)Xu8%MIpJQTwSJAbjG!}YY#O#51Wubvzt^B_J~ycwY0Yp2_e;&_tn&~ z)Mk_LVdpQ-2Z=Gdgxh_j#s=TbKTsvP&+oLkTOPtb>n!|q1xILW9;OnT&&Y7Of>ez;pQ1#c$@Bb<<-4F2%nUYzwFz)j&M z@=Lk-qXyQeX|T6{;+IPU{>P4|-DOWxQzI==S2WUO1TG^u4QA&t`FYz*>bQWpr(`+c=$xBDGcZ&Fxu@NXpCV@~4Lm zbsMr`;OFcA30BBnP~!Z%%4`Ai9{O&d?6pxaG8)Xm=MOLTLQ+Ec0f$4cx|&^DLYZn& z68m56_s?4zl3|9-{`A7LKU>^XTGsCfgA$TA5+`_K(P)q|qCrDBe=&2*Kiw_zQ#$iI zAd*>o}-ZdqJqfrVu>2aR$QB*Ns8~HM5?C1C?Rhs;;Hos&M%WdRfsUYal;+&p!`gqyK|)2MG|T1wq0~2qnQw*%V1(S=J4(1gd=t%q+o!H)nsCNJl6wIOp#N z=I!sCa9w`^wcGIjMfT!=i&g!SkRW)K&ECz82<>gqOh6HWQTl?7*2T0NeZimCrvZRi z`T9DsGTl-{DkvU!C0Biu^s)lZA>Z#mkG}ro$a;^AV(5J_MaicPZMz~D7cZW<#Gj{& z^;?FC1F+%@st!Oew5x2D;*>-Q$uh0dsuIdzh*AwR zma>j{ik2fGl_*;(oa{Se8ELU^C1V-;U=m|Dj4|eSJ*cz1@B8!D`Qv=f;d!3>y07bd zeV0=O>;#FR=oeZazD9zO1SO*FxYNyUjpHStbq9_hh-=X5C_ICkncLlvx*9_+ly+s` zsWXK4{og$`@_&&}P!kHu|L6fhiTaBqHmg^uZLdOjhVZ9O`8C#5c!_y$Y1OB~qelNv zDYpkZJax9m3+LSwtTx?t;ZVz{>@TdJe(wI#*Y3*ek=j6yYE}f$5 zN37r_ZSOSk6M>|7=wD`~zQ7bl*J{UNK8a4|56JDR9QjMLITs+oT)DCK(ro4GtMTMQ zMntk`uH-WGJM(|qR=bE1DLf$Pp8^2+#iy$2YPq6&b1(j)%Vl_$0%-eR8OaHF5kO|K zyVWCH9oc1aM+9Vs?c<{Q$6M;^>cBMvq;`=3Mgxvjsf5gFP)9B1aL=1IyCe+MWpG=* zFzkf)Te>mIz6wl&E0%CWi**G`*Q;$uuO#@L$C7?p8G!@Y7Z4ak`CdTuF$@%|Fpa*C z!a>E_gIfh$&dX?Ma&z?b>U{l7IXSq<(dxGg{G=5mEa#8nZTz^V-;Vh0)if11{&@7E z5L44O`p}hMk98~d@-gTLvY;b~tZ;{_Y>X)lc&32fug-PN4x)c6AWH(ky(S_8fmquF z#ti`QQCi6|R`dd(jEzg&Fnw-t6jMNQc6PS3gk?Su)4Yx@@M$2ENa7g(!R<@gRqTS0 zolmTq3H6MEm5+Yl)T~`AV_IkVbI)X}#&|nh$AwG%EhJOtV@-ds3!GkrzE)MWQcCq1 zp2Ng;4nnVmz^4=EhazL~aGO%SbKNUAeb47;^6RtEbmzU;81%+S9YMR7Oxn~ z@A4yab;Bhm5gu>Q$?wdBq~ERW?n{12+@FsmD~}MTtVc)qY!eNw+R^Sh#Ie8aLnL06 ze^>8~y6OUugU|k0;$v>jNB$>w_qS8nU_#d4a+j_$#*i~mtGuU3PZ+gNctQ5et1%5W zc)SH_$p0kT9rTEef@v8U!XhHvMg}F|JbQFBixS)9LStP!_C{;~r)EPynR*hh#`fRp zDs^zr&oGJ4MX>X1Tq5XJmX`Ne;ECjtz{X-`i|2F+Zepo-suntbx8{U(9o59IxFrbQ z>ichBE$_{qxkYxYRoHb$zJnRr%1iF=@&dOCPF1+n^pKbySWVa(UHZX!H+vu13{7>E z2C!8XNDQmD;pEPE{xm1qs|#a`xOOftkxf#$@mn-O)B7#IG(EL{k0&o{wv}_PYaD3-t~Pg-kWv}SPP$WU!E2hQDaGdm*f-!&;3? zYqSi>gKdZUltZj%oGYwRRg2DTXS@CtICHy%{Ywlqkq#y5 z>F-tYxi2XFvRNeM9Gop$)iobv&94=5Vk*i@HGJ5OJfh<+j{s#vvOMU6r*aM)#9e-c zx^PhRIJwoYOiIJY$HtO%t(Q)h*J$C-Ky2%0(noR9cwqC=asP_!=3UDhM8p^-TR=XU zHWZSx+0ci)GvMQp*W0hy%Ehe+jj_QS6Rn zQsggw9k08$v-r2(VQ8uP?4>qAwzje9^0&@ZQYCQP+uMOAVb&jGYkIvRq2!s=e%pBx zDyphQSN1siDmW*wU2bj#7svgZb;54vT>g_uWfxX71ch%s?G|X?Xhz7{ zZ0WXUZvX&AB+~AJWRV zzpdNXlt1-l8}oGV;hHruWc6P>^akYctZvHiv$9OrxqldS=@72^et91se-$Is>004f z^>@FWn=35E1WGut&lRLLY-saus;|%TCtr7V-ml9Y8X5v`$7z;uX=g^2QEG5>o}6K& zFn4ki0FnuDy@kVZtdY8-{SB!P6J5_YYWE}3-dpZdTBowvrql0?j57cbmExu_6HOe21YWq6z07;jOKqmIHG(`T4JaMfKgJHJ%E1f= zh%%ARn7hI|^+0J1%*#>Q`OWBe7w2ubx^D?-;wy&4vtml_KXAUu*m{zT9zzEPbRiK*adC0u%m-f2 zKY^ST`CHGL{!7o=h63su6L#f*4g6%WzK8*rV+a&nb>F`y$#v2sfr*{bc+FD~Npq168${ZkJ4} z$C#I=w=&N^WHjJI34Z+Dn~%ByPjqZpsSz8*kj?yHG=OY8bLI?ye%9BjpN=nMPM11t zTchpEBHA>Wv`IeH2pWp$e9Ut>a*hOELM9K|L@Z zmg;zhuwc#5cWl1$%a|)y+-Pl3h*CH2EjHADb}c0fDE#FNrnPJ-7_%C;c=1ZVOtG@Q=9Hp;aPjE;~L$z z%u7tkG~<76DqK>pOxt3gXtK!nVC?;4sX((}+QLw1#;0U#m^8P^Oq8j0j08SV7|^sh zPr2(m0c$l_)hl)(=|OP#zAAs>@y(sBf*G3e8^avjI;_Hwp%0oD>*2&AtIO@g?e`ek z9Kcl=SyUX$6jD_st;3z(oxt5e;?bjQN8;#0RSvg(henpPY>3jVmpOKdOBOUwOy1bO zq1d6*vRSL&*_ea!rZ4*7GpF0+6of~LaRMf^pG*vY4CfNNV+Ms8Zc|>URdhna9S(A1 zYi?VZ(E1q*wHf_iv&%SmO|vQOBA7{`v+qI-o7D_{_2??+XBt{K%BO<4fNo_0y5%$w zdq7Faf^*HsN_|G^WUBvfdyhk4E&th*Kfy{5-oiB(jHvx-Zs+Wr1zYv5`0EYdzIhn> z%kEX>3Ff3CH+HQbd9yFg%E#aK1x( z9x2cVF*m<^BBAk2?6ty}=8%a)iuS5iIHeT?3~hsyrLFA~&cR8^^2Ny)X5Oi2q+qN` ziG+yxMHR)k``#aRtd$2>BuajgV3QH^nXK-$X1~iwrl&qLM@&j;CH^Re;3gMtbMxk= zjhq^!C+-UHv16}M;dEQ;Z`+`jA$i1iCDzlYWa(>9#^+6()lNbUPc{+rk<=CMGc)VF zzhybnZ0Y`ezA;p43;xvuEt|X_YrOAe*0a;bhvmzM4%O#N>@0RcuG)&M>%8puEKZGY zKaYVF#hN}hMKtjpcr$sGHnH@4-5<;}Y0EF1c;UKTGa_~URKy(nYnB=b%) z=iZ<;-Y=Ybrc`5sbp&YUl1+FW#i}-a6$d}@adLgXzeRZ2m$CKF=OpVFeP;IFmg3$1 zv5T_f0DREc$M(pK`iR0X+YnLHgKZMUT7%qT*{g3`l&xZf4KBWYtw|haa(^z#DFc=fz+;?za{_#t; zepNYC#b>zUg64#J}iUU18=Bq=52JasWOIO+CWh2!)pW9qqGCX!3&XuF)}erXgnDXH8xYq&288EvPO($MSN6EAod}3)479XX7cu7?1`hK z_n-^*{+8k^^dxD~clo46IY@kSNl?9CJo2S}l*|e_3#> zyCTj>J%@6C3)jkmbOGmERTd~LsS%VO4uUt8wigj*d;{OdETE-iWY%774x@S19>BU; zhnTs^eHwG$%~gORQZJnT>V}g}0sAs0(1wINqjHH)iz`}US@E*1m(d%pHd&Qzx~+VqFVL9c?J}sRSY^~J-lV0nXq0hm<8?n)m7&YK zRoo(7qMCpgEN4U`w^;pfTmXDRS3+VokM94>w%@JdTGZ0o5;Z!Pn=>Xv_t(b$MjtzUoB_}MGus|=>k+z_M> zaoDyi*7SU=710;?#oA1Xyx1XJovR+|6#s{GRrN(>X89_-o5qK3g0PkR}vy>D>HoVpU+aeUnsO zofg>qyMrJ?^r|A$$|*u9C*00J`7ZZ@Mc!q6RH|=2(2e9BfaC*{Pq(0r)iO`s69p@a z+_FII%kH)|Ga5N=lQQ4ED1K8qL`QrT4CHq0o-t{<&lICYjwA>jRn&M&0N!qZ9|{9`#kB$A?2L< zuh&b0rLbWLKl@2%45#vyP^Mq=EsZ)}A7`f)RW!0|lWqd5YGooY>3e*Tna0l%V^I+D+$JDE!4 zbVN27J^Hf`>^s%gM9GcP61I@|fi(<8Vp_;oP-&zu8i8=Y+_Xx_pR)EVR-zC8wGivx@k z-~a6+VKB)zNoeQimK)8hVCDPsuHS!LV5Cn{2I1FnZEYCIhn}T-87wR(d#ocjG*c9T!+0oQASun)tF8sMam3Aka zWs$rAdl>vClT;++<1^Mh`~#yLp-CRj5)_M0w_3NO!PN$_rdHig2tpAX?)q+ap6$cW zLwD4-^%kiZB_VC62;3>)x=_WRjE;|6gzWEA+o^uBiQFVftB7~q5B$l>0pSBov1az} zZi8OyfT3a$@%?S=gESG^{et@FzY-IzL`-uYx1AOQcJ&f!U4dPKTho=PezPXvO78YC zr@8Dvdi{^=CzFJfZ1W1phoPBS|6U7SdvarZK4DPkC%>BSj=MB`e6(*qG0tU3e1r8W zj9-WeC-yB9H1`vE7P{8rkQG7ecqqja%G_vo{;1`{!EWkk-^1|zfuA-uPYEGeU}z?4 zm@xQRp_3C~H?pP*(`rAUX&}IZbOmGzY}-q&$(+XQp4HPgdT{tWFD0uBhC|$8BaTD% zyvC@e(S3j0&l$|x9&H7i^M`*M8Kxc??mm4LJJ{ME4cJ)di@%KqoHfDo9C)nv`xR6( zxv7wOHO1m67wDpV_ftQSV>hVercJcXI5)Y2qg|GXjl4S}naoorYW;q_c$}V|XW`fD zYgt2-!8M`J&a9Hv4Fd^;GOF2iKAYQ{nuu5^*ZgSk{^r5@dPn}#V}wC(SOGlgLVJ}A zU2{%0&umTdA=;*MI5+V(20BZ@3x&$n##US>UwWUIxBc_jB4k|HL4DB%51$$>;Z~2& zR8fxIyuKpsfPOchF+V1$WD=(;OJ7CR;74?@Ei~I)f!{B$bMjpWB7wbi1V-yh3mU*{Bt3IZmk1ae&G`=fs)qg zowtV?W70d$l7rvITlod5{b#~7 zu}3k#y)SIir>fQ8D7IiX559kfs@M9xuxT3~LwN zgG!}7imywL2jAwuf%?y7KR)p9zl@%7gECVSCQEX13vPz7f%bE~8)7VyZa#~Xk`sd? z?Nh{%e#t#C;#k&(CypVYzxHOwG>0oAZa@mAHeDj9CRQYZ#veq&uXK`tmbK4qSw@)X z)rm%W^r^@ToFd#)R!IJ$x-TIZ1AO2o8@9bWfaPZ!9o*@4lX7s!+O^ zEx@5OvoWfE2=I>Cekg(dOU51SUrR3+3FyRKYxMpWr-@6MM(Th$5dOWQ`G_Dtk74Iw zm;LZjdZy$zUVJ!KLQ!UYr{i&}-J9?r{oUNo3%l#ZyI=V6qX)f3OR&*Gegmc<8pwujX^+kf={8vDdVbNXx%I&j=XG&8=r_^VlzL6gAiN7a_zrNRP$s>fx97G@8)(8lH=dFsjQhyX4g}}omis$ zR}jN7Q~q%M-HBZ?m$>mSl@#qH=Wcu0zdw49S~}d4U-De@>Pm7@uvNU*>3ps(iIOKsmj#}2 z{O6O+Ar<9t!9(-ZBirlRuwh{Mg;Lyupie3^zkpz_{q9$B6xQNc`3#oJ#9+H3uaijR zK?CQeih~MZu#UddS5h;(-?^B266mknd&7r2`&uW{G^)n8XN`}fRn>@iBVj}O={aTa zN*7@ilH3)oeAM$F_ucLKPScv8#7T`u-X1Z-7?kx(X46`HSLA+$IauD1U%oMA4TzuA z?MWk#WAAZ7xh=3?)X{exm@Jy@`GojCCD#en+LrZr-T z2*i2Z|eTRGWvT5)=X#Kzmcnhb&g1abWWa`=R z17C*&1RxNhab`cBK_uT&Oosu@zz{LqQ_+!mjo0z(f={8KrcUjN+x_i#{*!^O{}Rh; z)P5a)xDGp`do_e-SO(hRMF2bI*u)v+sXmEekeAw~esn|WY$1P~nTY~77 zufoDInszddur08)fs8ihscLsFk7C1s1}+C$JQ%1emM_6>?qsG+r)DruAq4(s@z#@Y zig-ffDccKp-@bqU9GLrue6QUCiv6g=aOVlC<#tB-5rR;XY9lYmCe2!EYAwxg;7%qw zJ_}(4hnsVpqzkmh-t6n#-{O2xz%{k$W}^>gvujBofGy5gEcRSLw0`R=H?c*nL7=i!0pw4=RuH%9w-L!e@EU$_8*{%K2Z; zMpw(YUSH0Va(D0UNY{5!T?|37W| zP@@yk^i{wh`VsSb?C>mIWnimo3wRRSVi2Qv$+Q`tM$nmdPIxg5p4K-t^|2W*)-B>@ z8r6b?*(gkBThna{tAM8k1|);Qf*U;brBaRt$K@qTfr2K^$o~nqu%xm7HeTOGI;k&+ z(#)!-U13qK?^5{dTI0=q$zQF*UWSErpLyPZ4hzB9AY`f~MbD(dsPpAMglcKhkhJ7T z7x}YprrBB#o<;t=jHE8-Wrmx4w42#b^?K6d<11}M>V=c{W#*}CNHUARdIjti$jGIO z7*vQ$gAcYl27)nApo>cW9jo`Jt>2_~6uI^X%U4vRXzNU$Ck;L>=G@8?86}bf!$IlvH|ACwaKd^Sg$Mrqw`2(ex{4YhK zXur|wIFumdcV#z1lC%JqAyqC?v z1LpWRu4s|jw*3i%3#D3t70+__1ePLmO`^$z=7vVw#0E!OKXG=+*lMvHI3ORHI}sQ- zUB~^Vz8iWQbBeqjh|X_I9x$`n3m09elbYbT7+_jkU3P0xi+3y=t|EF-0-`L|0PRjQ z*)BH^KbjKoE{o>?4a(B`kO#7kUtx0=oPS~$UsN|9m$ST_QRJK6bZKHD)yt)po_PW@I z<~IC08j4KTh=;E+Cr1oJxlXHSUZAiz-!$fLc!Fl+qiqz1CPS_6Z}s>0kGon8Lm*5d z{qdv*$s!D58vp)1JXBuJ7t%@}Z7^o(lS!nqC$3#4L+NiJ222#jvG&Zvoh3iO zEcf2PF2{bVlO%go$mSle%|KhzjB?C54(+x)w*wlRgw&&$wu$#NY+S}k;xCYq; z^!t>TL+K)95RYt}&>q?TQ77o_b_|gwEyQpVxt4@FQWc{>qI!YDdr90e`!AB=F0A0_ zgvTz7#ch`pG6zd!gIr!aT&F}RCCjS#w(g?V1)MIAx25joFf+e&$w6yF%iDK>Ka7sE zC{p25iw&vC+TD8c*wG9`x$?#xFX3q0OhWU=9`Un3uLwBsn|1jYD^7EmRq)9`iVH+* zxb(QP4P@>(wMhs& zgv+F|wPmT4d{NF|%WB%xOPj#x@xo283jG*so{@@Ys2vYD8JUuC9F`-MydTHF!O%|< zgf}!BjFOVxIX9JzSJt`S$IX&t0=$tAnVpll1#EGE@f|%*-zHWW=Vp}F-p#qW%HO7BLjTu9QbV3d8lCKN<9#m$1sz8rg@Mq5bS!MSs$7kkD9p{7u7g6{0d7$)65Er@(di^hJJV=b1 zHJkL151t)XA*)bt$;ePSj}i}T+8ol*5$XZfPwjJ?bBRUv+bhLT{*}^B3J$>nVvr9R2t{PfYXN0LX?K<3+ z{62!y>VmhY1xteGxZ~B44a;7;aGBt#zOtqb7-?b|o$mAqdz{+^;ok09XIW_H*J}NacreITu{aYnGnik;cY~qWuF%nMC*ut%_M4V8 z&3}culrRBJ6I+Qv>6SJShj|_Gm*{GY$Dk{@#0!*8zp7kz1@Bq@pux)(x`cnssa}(T zRn4W{v&xCH=YsFROrVdsNd%BOjd8D*^=QZQH}f2VMxME8d% z++*}jXOFzg3>oqyHU&dOWJO@$i?C^$fJv1m;6DO+c_Qx93ecXy@cIf;IdUg2j94gu zRs9!=+KZz#Z*iPq2#2{;?K*c;#CBCpU7KtXJ)VHe_bmZ)v2|+{$etNWr$aCOVzFJk zfNqVe@h3{(&-oMr_A!iF0{)J%45PQ+Yr-MdmUTBbH}ArXy-C|Td0rU(#+;plj+=pn z?d-~_9DJ0Yh$*i3rnp4#{zyDHC(%f$d8cK}`PoLs)!LtsL_K647Md=0U|4;;C=hz2 zY(=P-X7UhFSz*pA`I6q?Rr9<=$*-$Q^u=yWgSr>)!cUx*Q>%X`qT6DW3-g|y`0)<0 zr+*f!eBAihVMk@_oKZg-V4LIUBUs%}D(?BZaAY>hq`u-ZuL3TIbWW);yasI(-{h;FbeDSt@_#WF1%gLl(}{Ew#a)YNU|2 zGyX>qLr@2dDj-xH=E9O;2MK%);L(cpJajZe`FMm6FJEp{h%a^xI1+&x{-#)jX75GV zx@URmi5@P}eu={UxB`r>f~v-dLxY!??r=T0TiQ|F}kjIwk2ArP^iJ zX-W0a!+dB2;V~b_g;Shu0zBtCnL)hbV&?7-w;nxHHQk*B85IKvp9@(XT2rNJ>ko3f zj|BdjirhI6v5CM1g1C~VAVp2=xL+c+O~ zeul02_V;@+|(- z>FOWSQ|a3-{C7S=P#^OPXF>dwEe`3RfE)O2V$=ogYR5m#79OR8?S1aA-g+f;o?K`kk06tW#2Vn{)D$Gl~?>Z;|$6X#3F|9 z>a0JurhI82-G9GamI$rRmHGQ*^9sZLC9!|{A*6~lS6MtO(GEh{o+`MW@%6v zhvE3mCM55=LnES+hnb%M!79-*o{E)iis4-=o96 zMHdf+8BNYR9td8OawZRwW&U@M-G$o;yTYL9hz&>u0$*AYu$MP~w&?Mz%XQo`s6oT( z81@`uR@)!3x&qflzWP3iV4d>#=N4o{i9k)d#VKhi$qv+>tBG?ZQAx6>M=S|Vk$<*M zW{=#R!k#9`yxh|)xa@U-s_yW$@`8}F5D$q)=Ne!Ja=864Pz;+o^Ldn>9*=JGOdcF$ zG*b80r0@btqugxrRTOjA9V!W&g&=YijTc5hRu+9V^u+Ir<1`2|z&)FmcdZk(`}}*u zrFVv67!yLPt-ZaQ*JSPui99NLm*+!_#?EDE4CA+nk>umqPdUsZa(CEWqmcaNr!n@um`;?=->*7; z@rc0cf%GfP_Ap;xNbsv+FiefCQ6T`-kbshKPDR?fgRNP1o`TgA$abR{In3O*0kVl4 zm5V=MkKa{1cZk{aqr@xCj1YX#=Fzbi+-0J zvvIO-=vh1MH@BH`ke=%4LLv=KS2|1~U0nqhdPhd`N3?q$tMSwzU-*yU#FX_1`LT%V zWV6K@_!Bedxw_maal%>6#9Z39Ham^qx}^x!dkeX515U8_;Y=!;z^$y5+>qOO(!_jT zeI50IAuIrJm>Hbm9oWwzDq16B%&G)Pnay(z5UiGRAN5~%a1CO0V~(dh8*@L>Sbfdp z*#+S_-%h<|aA3qa7~%1;!3^dQ9U^saJ2^36&EYS1ylT5R(-HMO{UsGqpOcErUa$~J z+K?uQ-9_ka(k9iDfvqyu`}`wD(!>s;o_Vw?X9sI2X3iAPbZd!)Bi83L}$s+=UVJU z=bF}3TTuaBoV%>J`e)!vk zWdHaO_XRIlu;52qt`+U6oZ*9xAvoYyzQO7m@@kjBbOn)ja2JP>dAD&G6b^^3@j9lO z&egG5@k(=)liz9b#&7z^aUm*CzLgjDl`lfIBL;CAW+h@ZQJomF#UrS{#h{benCrt{jEH1x-#Z=(_k%S?zOAdwU={1_~&Idh&G7;6RNdE$U6j&27#voUMJ;D-7@Z zum-+s&D7`9_7-EbXT);&^C;+Cyf&;a)c8_%IVZZB6GL)=Nz1}p64`|Raav4CQq2e z#U2^j{}CR}Veaw#;V$$Rq32I+x5w)i3%R;|dR#R77wdI7WX_u$&*$f@J2(<}{cKsw zKKZS4`nRoD4SuUW21?IqPvB3$3h=+KC{ob!?3(HNzNvN2#7N-&7t!6ji_WDt|I=zn zJ0AG*vS{r-+#$|fqj5=qhqf6Aj8fr;l)=wj-|psukc{@uilwiiAI(ll>3|{{#2LJ$ zTZKkX2j(X^5p|CjQF8{!00Izvnb23%!pBh3J|0z6)GYpFGoo=p6ysQ)*#Zm)DLVfM z4&oJO)N0smR`W-Phxf{0mDw`G0RE(1xoVSoa`twa>jJ3?hj+ z@vk8&)!q>u3K^HzLDM`t~szKHXwJxLtWEV+S4uah7^C{+&=y|W`NGdz$SGcBp82U%5{Am@_ z@=-S2jD4pvq6@GA=xxaA*JsZ2V;7muT+5x|3cF0mDNd^`3X5UKHC2N3hFi`~tJ7-K z{n9G`GoLpuQ9MI|hGeFU*(c50L<<$E3RSB?;0@}uz~~1c0tcEzvYb_sc{$rxZ$U>EZo7=Bel$^9c93? z3NB?EgP#`7Y#|K!!)l}#b886hJ)n;I%X>Pkg32=uxwanNpJ3aNoak=T$;uo8mdcj; z=}!MjsDASr6X}>q7buUg0%w)2psoHLaHzi-`T#WMX7hqhH~9J=i+)U zIuX{HTu#r(00keU3SZ(L=C+pn?Ii&Z> z4SD$^#w1d5mJ6g-u1PIBQzQc&aS`?qpextTdvk~GLRS#LJafcl+3QbLZZH{eFCO^> zAPIm$fDS{XJpJbTp`R#T0#&jwXLyuf2J~vNv_6d8$BM6Fla?OouT{G#lVIKkb+Iwd z*y#@Pk9q+XZ}&}4!H7Di9Hk$?UAhDs7R&R7l3%aygPcBLVFDxxS%7rSzAe%Lx>|^i zp2bnF34s;6s_{`wyTj=n#$bUu`sT66mzJs{Sv4pklI-}OOy36-bFwtjz(c)`0*cI{fvU76i_Jp*fTUSw~VyGcv(Xp{|hHff$d^0G6S~X$p z{P!qASZJ#XAx8J@rteOn-APO8rXMiiqX6%bA!okVnktRaHuUpDpC$AvW*FEm&re&@ zJ=p(V@5ifk-&=%tgWVwDNxo$5T%U9IO!4#?)cpZcUk^Nl7Y)|xa;XS>N;aWbO1xXX zIYdI8J1bV+tO@xU$Se6U2ZlI?tbsl?){r&o#hE@75?f7*7qqL_O=89!f{-zpCYH1Z<(p+~xn zj}`O!$=e}9qkrwC%sjA{nh7e^(a}Jp|L17r?Wb^M?-C5Z+OcGfgIsIx$&P3JUOo(I zv<&)q=h&gc(Ym$@^>(QFow?&M`~tMZ8SWf(lOJzMg|Vkw*6$WI$!P#4BsBOLC{ekq zAe2zeJ`FScU9Z5%suQkOJFYq5`7;E%ywV$TaHstJ0sfzj6MZ){PFmzCR0m#`YJbS{ z?Qy>sxiaO}Z-3{BtXBv1XdJ+5fIQPS{|l%IK|J3|*nKT;pbtJIE<>{CE1(a{JRhD3f3 zlNlB5|JhFhJ)1~RH*&KTuyoik6tCO`em*l3L+Op0nJAFieU!Dtzn6yp*cr}dPj}NU z3SKS=T+)hx*u|T_1KdwB2klyBR*0;7;yCO8*F|0K-ij6{TKvjp$SnrVQ8?m>rN25Y z(_C%e`!Er7rF)(5C%gc2ka7rz2KDIHcI7iiPCb5@c;(*L>(8sU;B69!8h1pz3*nmr zi62RtqFi*z+nv;E)c0(4qm-uWcQ^TYjPb^+Nw94aag!%ltz#Nwc(VZjUHo-Q_I6;pv?;7p#UV4A9u@>fd3VUUQJIM!g`}i-^>*v-Eh5Nr z#@%R)nv5d}tUkg4wrBd_c7@v+o{5E;RmE5%qv|lC(72ozqcn3M4pDK;yrieMrg22g za48kSw9v}#Kjpj?ZH!CWe>cV{(_Id5aU%}M@W+nffYH8TS@UkGI+aqt5Xj&uBx?Q* z><2Gys@T5u0wKh9Ga$9nCM6!-nNys;?-x;^Ia-0a70q+kl6=pFi#x}D=n9Ptx$jqD zOaeUG4RBJaIf;5j1qyuqw<$*c)fJ*V!W= z+a>Qo6M9y84A3;#b`-utk+DswQdRWfQ*aycDr>VXVEE8Xo&~U5f|#L!*V8 z>zSIRlg2+DMz~4gNe4*@EiI<>Fj{$h!BwT+icH>$r$AGAj7Uj4sfPNsA=KP7C{C<25T?3#Lw9!dIT7M(`W($Hvf=4wWOhSvK>5wv2||E=lQ4*?J3A@3eq&{ijSf$2eg4+Dyn z8*aYhJk_UdRdX4(%=X(gE(Y;t$NJgN(q9B3$CE+B8LO{+eV|fSMNv$|q3sk@P)dep z*RFd=BrxjD+#K%@E#xMrJD1%E5@?=Yff3EfSIAtV1a4R7U%7dj)1}P>*kcwhHf>rB z21gzzyPUrpzRXRjxjLS9z!`sDwf@3jjNeg1Xh;}`_QblL6Z;16&Up4jQ3x*o5!|*A^ z=aKps`wXWYvNNyE*m)_uw#~PBcf-SpKTaP#pba!JQ7POl=Ci}haGOxwS?V&~9N>Mi zclgo0r%ap92tiQo4k6;366`#a&r>gyrChiybSV^39)9lCVXhjyI%Lh)VgRc^yL|pS zW)_yb*pD`;zuQ4HLit}~i8^|%?k7zQf*HuA>s|H(*q)t#A@xyneKQ&~`YS;BCCneD zN&W7mCGzo(4e~jk$5l5h;12ZmGGYyu++?}rTt+;>j{oKfn-E7lwp^Bj33OjCTyC$D z`m-IZHu9y!1c-`#y+yQdwYBT|icGvgi7+`oM;)lm$;Ul-03;0RXBO5i>cbN`qoZkw z;qB#lPvEkBxptCrm{8R=^g+Xr`-B4G>dK^?9CbsC^#|#Dar`N6Xq-X-HZ;uCMX_<1U|d8BJRQ4?J=BT0vVq|_M)>i8hHk`1rf6_!_^Ad(>?!Z zMMcB;4%Iz{_()VX_A5|YB1raG2{blxtkN%yqK(L`a~L$|ehzDqUum#0)FwhTJ$zc! zId7jdUOuW;uLHEN2SptDM&q=Par2?gAA3=g!nR0%r*c+~Q*m4Bsu=-h^qZM^0aFQd z-ND`Y1UE598rfRjyx)N+MXRv!Gdo6QoAGj#sh7DW&(`2l$V+*~28uqR!M$1)I&mtZ z71dry7p3uGxo6RmJ>^E9R_N5vBaVYyBpk`tqm6a9Rzk2uVs;UQXSlb%MI}9v_R^fz z*x%-_EAHp+&C=%vFLa7NNE`CB{{}9JpC4L;gj8P`_Ch6OBW7C{_mB{sTksdX5vL$lm> z$8OMC3N7&Fd`o|m2kxSTB2lDBq< z5|<`gErVa7`4n1kSD$YcNvndmg-0mE;NIUC2$Z%_+v&6(5^G~eYUj^~D+YG}td&-t z-%7cTEvXnGT7iqdSJ82^4b})Tr{1u)yt;W>CTqZWB5YWH-$={gG#6Z?uPwg*DRe=> z&=Y&qnJde=@y35Z?e}EB@RhU=jV!!zh@|2s(;{k3jm_%7=2}DdP?qN zCZOAct0xZ;sqDE;)@+X89DEi3b~WVIXus_>RoYwnK2B|5o`mMUi~{oOMBWwXM@fnkfNig_(KKz`$E9smg1WSA;;gJ7b@=0pq1N zy>ckT#qdw=@YD2izx!X32&jOJsKMc6L}TT|pQrQV7-^awE3Q&w za%zZjwXX8M$GN-|%Z4JF_`A*W%2&|AaEelq^z$}%+~xp5b?P&M19_}c z=Rt#}H?c&%s6 zA-)q0{!aUIUX{wsc(;6ZyaR5OT}V5UDEATx!nWs{AFfo2${zW@xT2>hHtu4Vk6L=} zkDV9w3Vb%tHBDXP0A{ia@<)(~Q#j+0(5utcOujv=iQTsNxPTTWmKHNLlmq)Ly z+4X*G_6W4pWEYna!?Fe~yu1vRvHbFm-V7&>eXMgK$s=T}8bB%1x_Yfkr*3*-gO(MH zHGWWW&UcZMt!Qk?sLy6Z6ciwbGOTXAKXfWqjr}IAO>zqx0|vZ?@tMZF&Js1~u6fW& zc&N3&OywyF0dk?ydCH$qcQ8-O>(~F#d_z}}pfh9Cu5GX;@~{Fp;l-Sr2}7MmL^wxI zNoTjMegT##1&tQm!R_RwWzE$UphP*DO_4)<8KuoTUWhj8BDZI-x3HT)4DIMees3%< z1NJ^OJYhM|3FFz*DojEQy1A&oG758LocG6$s`%WO5qKNIbU85!1=ePMkgd>;ga2#7imvQy?{a6; z#p_V_*-I$M5;I&so0yqO``IIt? z6O-A-`=}x7UO@ApQ-4HPR|L1Uv%u&=x%_FxD(CYL5|LO${8*VHV-K}ysd;LKQ(ecg zjhE>;c`oO*lU}VK9*04&$}oQA`V_VR#oqTB9F_az-HW>&KXfJ@%Di^zJs3BaC`}tH z7cFo05g_mh0;)nzx>qGcp2mSFBU^Qc5c?DVv61#lD+U6CW}+-wQPT+A5gW3zQ7A<%|#SAtWU8 zoXqo-**4EJ+q8|pb))I?e4gq1d-|i-dA-g#?0w(w_gdGwu4}Djt^Zhe)vEo?EtDra*(#CB;B5Df2f8qC?mVJ7);hoZLIi0LHV|De8>gtz$HM+=N&YE`B zIQFZCPrqch8FLaR%tkpyvS9BHwEU{SU6@u07Vy5bb$(mZDa@EzpW_oCzxK|g75gba zG+RX|zdbgvQG8HlKW4C;+mp{9nDRdNOIlhp7>_7*tVX8Z7a9lgX;N!t>^MbF{fYpi~?$4 z7pZ~<86mCfCWLa@ayD(h0IzFM3PF!{{F#i4+zE#Y@uS}^z~D-2#mntm2G_kVp{dJb z>Z{Wm<}C^!Dq@J>(7dUUweH73h zv$i?bW?hrcsH!wu3V69xc2mzV>Ft7ZE2ln$tvh;U!P)o9VaCwMj`+F#9V_=?FEGc8 z!%enh;z=BnKsC~M6+OO;Z~Kk_;TM4He!kUK^4XNK#O-@8oI=7|C0fihE;)~oml;?< zpQeVMNs;uOvaUQgEQ{FVv6$njSy}i+DIU+4LJNyl5^?pb_ru!^+m0^$D9?qx&qaQF z)J>O84w~^rXa*nATobfj2>DQR;=t(?Z47&VoOBYQij^*G`PD2 z^N+YbaN}J{p%`?dIn5GlgM9Pk;qPY?)5CB#PUl$ zLN??h9}m5Rtr1i{I^qhnZ#Jdu9OnAJh{lN9hBh5sJ9nMj8?ozK+pB1jmOwwjYyP$U z(o+k-Ks0NC{XNy;^}5k4`Q~bmz{kHhhjeJHPJgqtH0lYe#rLG_la$`IqK}NUJw9R& z$>tUr4HNMEFs{h_&v8Y!V$$kwFTzR}&{aF1$L-%E#w=?6(f|jqO|`#elrzpM_?~-F zPwvzm&M59GzHBgPb{mi{G0R0KmGhmHjk3$vXegBFSJ5qWlFA@XtHkL z)}^Xh#3sHb^+Lw8ypSyeJE3$M3-J3jf!Y}r^EKN*;1%&6>rg6 z)MJuT`);y5IT=YlP1rYq7{M06rDeUTBr7Tp(pCc)v;Ofe@3y%KyDP@nJ9e$Q)<7k( zMGrS=GwCC=I`Y^V&*hO)FpbEK8@Xl}fWR5n65t~H-H|0>d)&dfzrqMj=~c3cfT6_ zlI>t8K`kC%VVfZeMdm$ar1UeGCdph$ENXyBs_uqZx}@Zg zx=B$biA#cV{Dj)Jkz4E8{Hc!bPlph+(@7YcAAxqdlH4c3@|T3tkiQJW{1%Oa4;zY7 zMaaP~y!(}a)f09{*V6>wO(&_PDO&RUuKmcXy)T8`Zwyi?J^A*}T>%f#jjC|*R+Wi& z>(`yoxRexu2V;%2<>2<|9K1nl{s^rCVRAU~A4i8bAGQ`B;>1jE&+hrfFck@5z}1}J zCM(p>2)oRmhL`=@uC7OE>KKtr=O3uP7a;MujCP{@e%tHx@8*YJHz%noDW!}fd`HpA zjlL&!NX_wAjvj6e2=sB|aE*K@F^{ke>WJ20;Z3=kpJE3h&V zh4-b8*iiYddAs#lG=^|5{1rncN4hpdZF_t&jiW7B-Et+Bk~=8uZCLE$`{^ z0KaGt_cc0}fCKN=0#lTr!=x-qF?bo@VQ;#&5{&7h(!yy}xH<{(^yjdtU2bM0o!^^uKL!FwBH1P~f%E>EO4j;0ARX%V9(Ky$;s!+4}dL z9p@tB8owSLtyf=OGsqT9EH~(@)MQa#8D^^zn=h$-)#!U^cKWzSCVBPYfqyoQeWjQG zYo=HT*4{iX>Va$oE~lv-!3VpRLN*q%Y&iNds*p|iv|*71%Wn5_rTqj%y0BAITWe9C z6%!R=rrT_|+-9zS|Gs6+VpAY!bnvf%$QAP4v*9vf3L{z!aS#IAt0~wCtdr zZnx7*F`KLBrJqk7iIw+)bp`vPF1|lOk^oy~20NFvHjdY2p@+!-j6-GZbA*BqCTZ71 z+siSruyB0{{`7Cq!p|EKbihhMrZ}53^48lhX!f2tQDOz~PLkAKx()bf3LkNhg zX^S;<(|pec6V`7lYMV*tcz)m!-&1#o5|$Re(~Aq)w*zPRsXyr zRhBntW|H)RMQ5tnf)`)sSf)L}#yMETe7hHxZtU)8@$*X{>wV~Xe~Z2A8)8(ULsUWT zVTBFlAYcxfIWiGWSoISYuO z31O13d(#<$Rsz2!@mc)mUDB#BLcxnwq8%nH>=PVFhFK554ZS zB3li%1AFt%KP(KTKf6g#mEQYPF3&}yE+6?xPS;;P(8^k16<3=!}e zFy8UlFA;x84=nxSvtw<;H7&z&3S9F?53D?}s8`M?=0}SBNl&XjIr-(|uZtw%( zclpnZoFZ&+yTMfU$iM*9^b{rhd!~0GXWDmXBcB@ntqA`!M75w6s|%mVJSNH;8;ZJn80H||Fw4?)L)C+2t7=KO%prZzay$QQaMVTUjw%#9WiHqML5tGuz? zA_}|e6uX-6O_5Ej)j{on2PZ}=V+Y7wI>-HX_{yr@zEZx`Z8&6Kh_1ZW&?~*NvB$h^ z$;x6+A2;vil>EqX<50eL!1>&J`Z`M{?&w)E=Ss zFRLnY=!~)t?b*6}`y}xKaAD<{kPI!#o{8J_<~i9iVFwig#1+;{OA8P&vg+*{Jc0Kd@s94zV3 zd0}t4Fdu1LPIKUE(tFzuKiPQ>{p-WU$RN^p6RvY3fv?Rq()AoIEn*MIKNsia{Q<3E z)zzJM1Fqcn5gQml&V&_3@aU?(Bek`HFLB+A^uTK*>)Ed_k-GjR290sLR5)&n317NG zx#XfP18(w3ZW%{;L^32Ub;(B#~vnv8S(*44p^N&%bBrJdY&R&(D7D2kk9BNf+6Ue=f6S zL@!ZSYv|a}CI-nxFflQSsheGP&h0Glpod8Xr%Km&N6t!4kYg-p-5GHr6LJZwFV4pK z9o~2WM*^AeuV7afwb0jqGk!K0gIN_y=hS5_ey@)W)b-d}Nf(@rFu#z~{+u&0yK-K* zX`h%_&VsFysI}(S#;Lw}8NfdMt9jSj-`Et``>i@ou_4{_M)&SM%XGT2{`0_b|N4tS|BBr8$-t3fU)Gf^wIy7`$`peW655UwBE@F7 zSuezkwyINQtJPPX>yK6=?)s71a(70XO-4Q=U8E0b4pil)-+0A)hI+pYzaxcTx}(TV z<(t6bXsJuZgk`vz12S`7`Ixn4?`*8Kt%J8%;7wcPrQF;VqmgS}!rf+H#pYV7*p5r6 z4qTu#Bol;H=}Zpv)2j~Ii}f*#QBMVtx0B)|vP?Ls@Ojpszv=8>@50W|QQWlm(xIJ` z?bLlI)>LyAFCPRxxX8*s~-W%lhCs$TSER}zg#kUq_zuctRMF%jor^DU(2 zp<_GM!Z7n*9!abAz}U*!*#@)q%Yohz%5#3C_mF2U+bG?VNecZ~c+HQ&*>a}8c=`~0 z_%Xaa*(El+7%LfVwY0tAl#6im7H`aFj@V0zRqIqOt`sFr5(@<~ySJNEcU~jW*K?%s zZAZ|f1TP`TRFy*a*Lix@5^{h?lF}vDpo5XIwj^lyJ*hA}ueGd zyl_a+CGKL9tdYrjp%dDUs~JvF@cf71Dx;rP9?M0RxRa9Bi`sxx1H$Sy`tlNqx7_1v*lV227m7~Ajy_M`#$~c3NinaJae*wE)F}K-n!^f#84o^j&|M`dq7*-T=W3Ss*TFD#;zDr5#-&5qM%sU5%?< z!fphR62<5;63)$-bZ(o1$jv+w`{jixco8-uLSa5)wa6n!@m0gfa%*XLZSF(QXU35oe$70pIf` z8bO^1d2Fp(5R8sMFiM8-O_sv2X-9B4huK!Qbo@8%#FxSkk!(?WCg3JcgQNQvdT{Iv3HS*`*w~Q+1b=VYPh9< zx>_W)>JsJVFNRq5`@vd9euCt=$aPt`SrxAXv9au^s_@j%W^8BKcLog~+AB;C)wt1f zvVO~j@)ucGW{V(LDI^&0EGEZ&VRwTzK1IqcgB{pBp{d zqa;?25a-(k=0+U;*|<)oxLH<**DwG48W$sz;cLurZNJ2p5orW(XzeZOfl=fT7LHUZ zoLxIo^i*Gy;Huf~u;*2zSt&Zpi!WAOkf&Jc%$nW&AKs#eYBK6gA&S=1WWxe9`s4dM#N-7r;jqj?ySHu46p$7wMf}c(`QU4F z79JPDCZUmUL`@?xnQ$9;?D^)5xcM#F!j$kf1Fa&W&Fmrk|2j%e)#y>;@0zUI|81ex z#nmexLgXa!eVc0=eCnAt_eGJHa};PkV&QUl-FdvXHtuSHrl~>Y}Up*9c)9 zM_M%ooA09N)rdscYN_BP32&f;HA9WZI*nJ-Hv?2%Cv5d{Ulq}k zhxcZ*)V%Hh|8q%KwU#1P1h)*t82Q8t)uJtwXLUI($td;Dwad=hEEt#7jq))1EntSO z1V`Lx&*th|cuT-nk&rJ8E3J5kOCVWU@D_fEj&_n{IVh9yHZ|K{-1znK320pS8S2lE zU8f;4KeRKlC4-HA=$LxPSxF?0&DbHewCJDOlEV%Eli1EjE@Kbqz_z=vUx(hXDi{Si zh=)el3jM**_$cx@_0aNF!%J*#(!nJhS?&8IAoQ+gO_ohyvsY_=thfbax+yDne;2QA zA5Wn-T59&EOn?y(;Emany z0C&_Ikt3U#vXXvS$OH%F##Q++ddTq)9NSd^7>J&F1bJJH`zQ41eYAdrEIVIfsTM8@ zsMvfV;$wfn=WEEJFT|$8<>m1YSIwbI1^6HbC?Vu&XA0!upV7Tyd+N35maQ%hb|yl> zvSQU4gARoQ2zITh?9lm&yjU8Dn(8AA_}rCz^rNj`ziIPfiN*TVKQk`hIbZ7PIm5^% zk)uQPKPpJZ>Qv$AhaLH!A^yl+g6#?9r?Y2pAxE7;EGEAr+Z=L}WO7AGIUVQuv0MlA14Ed<7r2B) zQv_s^Cs4z}zN4n*X5teYNg-i60bbr-_LT2S;g-_%8 zBr}ASXy8GgRL9EeRHyTj&5VCn8o)7=@t#<--Sz7Y7z3oHQlK*aqC++4*w|ARhdFKe zRqXbf+D1Oe3%X+2&=JmRyMg)-!1%iloX&-H;xDC?zb*-BkP&Xry}Maz#1T8F=tXJE z-ByJxsHAm=@BWaiiKQ6qhrrR=E|59P>?VmleB< z#_Q4^GoQs*rkgJh4xTtlllbH;LBc0IK0f}vwU&;sY(btXr0{z73dQVpSONXx#}8Oa z7&8#bi#7iMX#dxhdhGV;01lA~pLhlFtll0ywxYG+dxE*hX4JkZ4Rk8(A~PSrKWfNP z=$}2ii5(%8eqO6lM>ybWE^TwOf$Nms{>OFNs2iAHRO!#&wp0#1pYw(`=-x)*z${TZ z+(DJIygE3-dJT`HmMEtu@p2)fLRnc3S|;JawJd{TrV>36sr{}!YjMRh;;{5Qk{R=q z?OdMHQ2{%ruG(gRpMx65lP z74Tz*FJ(Z-m~7Vas_u%Nrf0PJgnPsQJ^NT=ZAsndl-ZBf4sg!_(IaY0#Qfff5q2mfdpE|Ijw3NaSKqzl~z7twR;Mv}2% z6~4#U;-aIq;-%^{6Eu+7H-~N;8 zbQCV4-3to~KE24{T1ZPjqwJH&gL7>p_Pxd4l7~987)upaGmaez9DTD|pd^w#?V?Uu zNoO}AbgJSggolr1Bw6$u)xdbBh-%=-NX)=*Q1=84-b>_^*8ftyL>i7+4`Q=Dk_4(MRVRRa~Hj zL#FCtWu;v3c;#U{l=lY3-$nK5#y>7EKTtx<*&oZuxUuy`o}fFSD1Y2XP?uvrJ5T#d zIn3WEK$=h6k(R=xHJj%wK=XPbGV{sr#e4cmA#9%$^HzIFYTJlX1mz?vR%D7I8ESBo zHZlMUngQm>y~g!P#l~$hL@3n;9US^@B#NBPlY5N3?udJCKFvE)Q&K)uRs*HW9)n%H zF>_AT_uk>#NdtmYzK&o9MBr3-NwnJHtZG&~>27Q{*{MNKG1%C804F6hPvhqj8IZJ> z>Ywg_ckdYbFW;5TZ*+!8=($CJpISVGv&>|#Ir3}a?7s(}FIQ>Q( zu@^cJaIeV&O}z3hK|$)6EOv)w{Pn-fDz_BN;-`2vh8ZT0;9kY=WLX(-D6*Fyawov4 zSmKt9;40cY7lP}dJkN8P5%-)4OI`Bdth$xcE4c{ike4Yzp?5@&>{351AHV!D;TzaZ zPwewUxYaU?Plvu2<&ux}iygRmYTxtor6tnS7D11|5j6awEY`mHMamVVuhe&0lw|g{ zl2Q>v<4Aeoml*oA^116*twwU)?^Q?ByroPk8s>|n_dw1a)NwodW)HTwwsEBzO&7mP z?H{!DrzKe>958^y+HGlv9$?K6AUJFe(<$`4h56jKJ(9IE^YoF8+|#LWnT$7b#`ZGG zm#r7sF6c|Cf8v5Z$b$xbx&2ldH@I^ofLmgas8d@HF!n1yEqWSZE|9wb&lXTbRDmeM&kExyK9d ztiW=|&mXMGd!+owawmtfuVAAckEUO!s8URy+iBBNNb~H(b3Lpjp~;soaEy(CS{s(J zS|97;ZQa^0@%LksHu3(wu67$-&J;~fyme9V?s1*7f~f&4gK-Y^SJ=-R zluvE3nj32y~n^Y&9$i{q)k;zB}lsk6o9V@6gA&Or~EA1OZm$<)Dv z2iud2%+Aeso8ECS5~JK}YYd}qqu%mZBj6^WHwxI%-Jc>`EDQ%|P)?R7M-&iCn*Ki|W4HRa@SPnPOHh^^ljf2h}qwiscThHyrl6+Kj1eGE7$ zVx!0JT2UEFpJ&70y54i*JXHT?q9$L&UkzVTN;kjpktMMFeKzw2JCU0GQh9o;#khkl zc$P0Fw(Rni^VtIe`zJ;dVwU_zKTrxY%$V*_X#G;P#k}`E#o*ZqgsxDk5ly4n3(oBw z56)hW4-YSxxx?XF4@uTk<^(iFQS0gI8fPWIX%02aJ>)B^V4n4<7&>ol$6EMU8VkHe zVszr2n=$1d_s#@;xEbko>6o(-2l#5wq=GrE!pPV0VTVaPy?}+ed8#l?Zhv*b?epCj z1Bd&B{&Zh5M897n#nf>kmEyIzaD^&Inq9+9>imFtJazRU35jdEShadXu5TgpQ>;Rlk156fM_!b zd7h2G*C$+ief_P^EVSXV|Ce~tZU?0);6>ra4ZPTzUj=1jsE_jaK-Ty~ZLVT003?7( zJ#0)Z?SB+qUCQiz-?=6$(HuxCjyy~cE-|#hsoPatIRV#!ma5vrgAqrVAS(>{QBlXZ zV`a61&7_CQ7O6P#{_1i2DXz8@+FLg?3Wd0=(+UydRjuS>Rm&9n`j4g zW!|I?!o}IQJT)sTx%+;Xzg&cUpG>B*gs3o8;q;x%edQ5MZa3DtWVZkHRy?Xf6!JrfxAiMwddH%Igfl|%#%*S*kz2lC`P{i9M zBGQ#tB_Fsb>N|Z~)v|yL-!}Si4`dA^@^A=!%S&WJsp&#ic$>#G9uazb;GY#M;vY|` zkn^*D5s`@X4i3r42q;}xuy(*WICR%Nx;b0Xq3<8x=^=o7{g%F2Y5TY7R0>@s0agQL z<$!3N`BnSAh5i@EZ+AlUkT2~jleR`0j54QOqm^I5@XLknm~z2%wmxG*>&Zjy^{SD6 zbu5>%4R4u@x1}vFz+@3a3vPF1yP(%(jQVOi`#+vvbxsdV^4((-*?HsKNfR}Gk2K$g z7b)z{Pr?bz$Nw(WHLGZb)ZqE-}A z^ZlRP6~u?ijJo=?Y&5s8OHZInNDcx5h_^D{rbDHH8IqEg=?3}`B$VLf_P{F2%aAF; zFj*of2);@;vq@|knA3|@$G?R~UK8(BwQ$XxhZd`JkX%~dPHTYQ3s!~EdQ@<{jh;bP73dFm=6-K8^x-$eDOVA8KZ zUbw%bGNYX6>csX?ljU`A04At$`K~{{=U(65nf=OruNCPm8;FFfibZ$n%ham_42cHf z`fB&<7_||}lM!MJ;&^RrCAY+v59w+;(OJ&3T1xq{-x)u`XuP)Nf|dwIT*&nlp|F$~ zN`hKzh*Lppnts5*X<#h>!a{FJ->s1y=%8WD{&&RGf5J;4=)o>oC#LdQa;E|~aq|BX z=0R}K#xC-qL>OkH40msM7Hp*ZW{iw6@kR!bj9=C0A?4@K3oi=#kYo!9LV^s-V7nSO z7A-JNN><^~5+g_ArAuUnW%=%@g3KI{Hb2lFU}7SO6=@^K40LrRNv1nnacuiiSyas0 zw&X*n-*thuWv(Bv@;APxCR9eO{<)E%p>_+5Xdb2}yWQd(bZ_rlWq=mXIQWftD?QTL z9>(`9o}x^h)$&y|cF@(Z`O*e^M=u2>MU#n)!0N|g%b_a+GM5<&WqGnRmXpVF3+iJ| z?MRkp|Ae&4wY3nE*gG3odMZZRIy#JqcZG5_c9xBsaHb9QKOA^n`;n);;K+M0p}N9NKlRo@Jka zWWwtFNcxqZ%rwFm3y>y1HqV<0B1(H=JhAy{D*@Pjww5CdoUjZH6vOI?($NT4h(V%h z8-U)6|M?r@Z%%n)t-&?zi*)wlt(=t9_wqo;I#}Y#USvHHJoLqFi+L-mlAxi)cwL%x zWqeVPl_Ox-*7>>Q7z08L>p)ORVOb@z$3%`AiMg47l@X?? zF6yB1Wi)~#efbO&k=xW5yf>ug$;dDu%WboMA;}0S6xiUOB6<9P{#76SLjSV!gb~%L zndSSiRaQYx!U8?_sx<)rXC#5(%$g%SFOhF-_H=3uvpQ#%(4m$&7I6ePw2ToaT8gZ7 z(o#(74B3p{!BBZ?goN^nzyKH92p^tae$UuYU4%y;cqq<o~IOHQ2fe59|>5s2vOK2zLPcagfUB}uQX(KF^-H-rari_tquN^aB(b79QHseWTv z_j~RULCB>cEwlZXg)l`~wzHouyx{_VwP)vuktN$hu;l*cigta{aqQ0sS+QmN z=iuA%131+{;Bb!wzK;9vO%qL=f*J|r<{w6;`k?9&X=b4Uw@5w9xL5h;=U`bsxw)HI zIc+(0FJQL&Z&ss`Thneo3BSG(5{_A2z^>4O7P2+&v$e>9*7RWF$w8;WZ1t5-5?}K{ z1#D`$@QiGW-9M5_oZ61DgW@E#P7b3@@j5{^$AKKWv0tEFKU67BjnmsLoxJYNV=m=J z4VvVN9zf;qTW#eT8`|1bPSXv-id;`+7_xsE%V#+g#%ve_%>&~jb%;}iD88nqYqpDO;LGQN?;y}-|q?Y0B^ zshP7`OZnzOySRC+xCh57gGpPsroylI$@Ug~RlU8pyk0ekU-dsXd?4$NkFYCj;(v0H zfIB`Tq2(hFe-}b`)ZSmzu(&9rIL~T0ZKA>Xo@(D@;KahU!f*+7WOZ7LW$-M%YI#Aldf!+X zUH4N#!7o>~%+!GbXg=mXPS%MVfsU#fJ)j7zZ|wINSk8T)-&mja__{#cr)%*l>gw2f z(|)7l#B_gMn5A$fUzuUQN}wi1R^%B@j*txylHXi*?~5>u!S_FsgFS&$mR%}=`$8D)YE&gu)dIHDA* zKgOO<>a?=!HGDQupDFL95V2BPu<}YhcnB)?elfVUr!2mSZlieL>=$+;sxCtQXcJ${ zyShZ+252ZCF9M)39gxtjynfqdgH5!%lS?nn9?3@}+% z2}?*gnU1#!u@uL0%Q?xyJhwR&vFqBm1y3RleWT&6*X`9M?Y}WQSx<61vV}0|aNi|UIgna4O1ksPM2M>r= zIPR|*jrRUf;BRE_zoEc#DDdW|f3@e#W%1C>1h1ua=wyx!l&P;m5yVETjme$~uhNPS z9QAP7VS>}p*^1J-;qy*pF+gxN76f2N6pj~97BU$b>z!sm@}(;*Dr%MW-wrT9b;+yu z8vk|d6*T;?(`AL>va?yz1AHp+&V7{qa$Nk_q?FYXw&J{EkV~Wll=P%VhpI#)DUI@a znna8Gs~=)yWGF4%59Np&_H~|GI7L}TUgc*qjlRL$eNz{@e?;!>$$!2ldt{q?pBrR3 z5^_Q+l96is;|ckX2>N$<+U69*YgA=wDzwbrgo}IR46oriu}M3E)jmJ@)+kPB6>UjK z8Q)v(*CF`eKXU2)`ui~g4;I@0HXVWK?Z0*!AsbdB5!a)<%93#~c-;YnLbx|ToGXrX zjTci3D-l<`N0V4eS6HXUd;M^=qOp}Wlukx!l743`cuoWVA$FNXS~%+FrWfhnG*~v? znS*76vyFwuv7%l1WX1CGfck=Shk=R<>$Now+5@AmB=%+?PDjp&BgWOU&?XZw(X4A| z$TcUxA9b^|e;@yW0|#~#!a+cL*`;8wvi_q-j0X=UEkFezEVJG8-7dzx968r|Jwxqo zcr9CtKZQyO*UIsoyhI|liVWY>R6JcLHBP&4XGe4M_FZm-Fb-m$RF_Mx27kwdW?w#R z#kJnj2ZNre+mU1kk}J=QVn2K`;O%zi`EH^Rw!4TkQt1baWUgp-H1<1=0;fe94Wm@c zszChfv3<8)j%Ex7YKuy=s|@`UOGQ&nZER5uYw4o}UdL#x&}V**MAU9`r(4^z{7VTO za)4q`^3e4pD|xQk%h}lv9aq)lJCS8$U+fiB28`&JxG?hSCtOV>eK(t<-lz&H**a#8 zGC{AVB}tJs>c=blB@t>K^PHLlp=0oYYZmqEX4V&C^%a`$B_=d3*f^1KqVsENI&T%SE4RRwJ_$sVWjb*Pbncuqey2GV5MIHGsJ^B<3|2(( zgP&K-H0`p1I&DpD5J#rj)D+O{M7PDfe8YM5?Qk{Z9O>q@c@pbkOB)Vx|EuY?4wzHE z?&ptqrf9rmt$On8YD68;#=S4@U1hg{UG~1AVpqb$l~iA{Q>A2cO58|}*xtIkbh@1F zwqCn!s^x-~Q~O3lcY387i0;VKaOAQ5-t&qq;=l2A{jY6ZH+N8?&r!In6!~dvOkB+} z2JX2-CE#rd$3wf;iIWi$>7#+-ugw^&EG@+^vz!z2l|5{*x{QdvT%laVnX_P&r&1e} zr+^IzHjFCu6bRdM0wC_i=)$`>N9o*h}&I2 z+@dk=LL=30yrPEIH}0L0<(o|TR*G)`MHT|<8v2p9{YA6z_6^AV&OQX=e zE-Zgy@ATL$;q1imkEht$F9MbW3N< zATtC>l$uA6670X7H#Mj$=uTP5X|a!T@3Yx`aQ5;peWt24!FI*q(NwNm)jd4H2+CWF zNC0o`Vg$T3tk~G{MbVnQV1XbpFM`$UBJ^=1tCJy0=MK~E9kn6}jDJgNOZoeS)%^J- zlcaB<9zv_jwI$=j;^4ix%L0Z@`9E+?I$@l5q~ip^mT^;qsztzSvo;tf@dncjWt`*q>au$0;JP07W@&K|LS*W`4QYrkV}8P<=LIn4 zM^+)hyooqNMUWgg)zskeUV@BwXn5GUcsl?7nXvl|f*?4}-Dl7wg)xW>JE+IXYAwD3y=ebv2^BNEFe4#TVdSqz1 zfJ=Pc7KU|az#+Td;hSeof1j9Wlw)t&@0E|b2E6`u4LATDt|NZeW*VNOScm4-tk6)z zMOar?7q>$Hng`*zaprA$On+Td)8Lq5*!%vfxr2T}paH`|28Pa17zRmYQR+jtL!+qR z?1k~ZH$_R$11b}nU>#n7vOP2n6Q@bGDnDcau`WA1sLWCAv3jOL0E$En#K8dkz-}}t zSpKR*dL`|aw#pl?iA2t-_^PK!rg|`H1RQD1a^7x2qKPE~;8 z`=@76x>;e1SFS$kO7~B*!A4>Ih23d->0mRr7($_2-PkB|#Dx^;p|5;l_Yp0{^Ukc`Yz? zJrk~f+n{vZW)E`h)i$0aaNCy{$;MU!g|U#Cg=cr&Ny#{O)-hHI+D?8Q6{I(+{$I|D zrXx(9T}Ynr1m9R~3Cj?#Br76t6ScfwVk?+AZ+qBU^ZbUrIXCnbk|68s837uDl{!bhFGbXU1tKR@sOkJY;lR{6rkf%LDI0F5N3Y6EbU4wV~V<;S-tyvpA{rX%QdZt6c`5zKTm&>a*k+&6z>0zVL~jyF}MGP$F%wxxg# z3~8CnF_re;ewj2)x6KG-`1}iR;g@3uVtHv}PaR_-SH(up!wJ+RlcTmNO`R7OYD3Gi zRO9N0RD;|8jhT_3#PWUoySaF%og##ZZ4J^c8BEz zKlfKXDp$2~tqRe$2O0X&W=S>vq%BGaOY}chLHfNRZ`Z#%=FyHyy1-!8AD=h$cN!p} z0LbV(0w6QdWVZE-v<*8^CG9KUnS`p(nHj+n3ocaw0a%s6CA;IbomUHk6`SRaph4UQj}CTGlc6DZMJ*|&ydXU6a!Wt*z4-S4X$nB z%$>gr7}?J{CLt$a80}gY>*9+t`Bfrx*CJzl*OobG{~5haVjlz7YAj+j8Rc2mvGa}V z|HoqS*3LU0_Y_#fmzPC4n%~7V>)dajVq;jwIJ95k$`5g|-vPYW(qhyvjr$eqvH7EmW;Bg- zvDo{lljJu$gy(hWveo7D!p)p39&whKKFS@ z`l;uJ_NvOCwm6EY3k<{?wd<}wjb6f4m;1t47UEyN8%|uG`p+JKI2CtG8SSRKp3_V8 zQG6(*c*SZ&F*r3fRZFZ09IZRa&(FVTj?jbU5Sx zI);xYJJ=yXC*P18?hml5C4QF~>g(ZY{*v(S5twpfTJ8Dk2dwWh-8kJg%Pg^5uAKu?5S z%>?orPiVaXvULhpGk`>|xg6bJOGJxG9CG zZK}zQZ>?`Q=~CdC>@5nn2A7OMQ8LHV-;jBkM8tjJ$TTd?A)&F zMJb@x92!O=43g0e0%Ls+y#sX1G)lZnUo-ZR-#=od66tyKaoO${(1=7J`m!rixwy0+ zKO7|9ge4JHLR+BZ)-0mP56<5b50hNA4|?rW1VudUyMTb2#3SD8rq_~?e?_eS4u$-u zFytJ?VBG4GvfpCX+MBGun%EYRMI`~(-F0^ykB}u=+je%kLojmrI~Y}k12P#RUQkC& zP`imIp7;vfY$qEU8)5jezYzn}HivQMs~8>R^ehNt!xw=ZA2Lk`V~G__b!_D=!*ibU zIlz$%FrFY0@b;kRwq;_80JAVvY)Esd29f4OTW=xRAo#a>jvLPm)^Jj)YlWr+DY2*% zUyyx5z1snkR8zm}qgcu|!xK-M7)Q^ey~jyjH3#R_LvI|Mmls83U?2_XdcOT3l<%S9RZX6Lb!CQ0n%&h)5*RwVLo{=YlBKXe`oVsXC+%RLhes^ zhAAlukR{4np(3yQ%!2uGXheHpca>sL^$9euNs-MEj5=1pJk%f&IcQ5dg#2`&RF70) zLhTF5X`EK(T26fx&YVR*;!L7DgIb26u=RlQ~c`?#Iiz>ci{#Sv}23Nyn z52@$Nfq{X~Bw)4ym_;(HG~Z7s@JG6xJABd7$|^%xtYQ3cn`qn9ek~eDX=+S1HGi~#z0{lNlRE|=s+ zJUX@6%c{mkm$>ucWRAGXior~J$}38{ooM4}f1fVjl1T20cUD4eRiGdPZ@9AWnwc3- zkPHA5`H1-+tLj_kL#R=cI+B`BFJ<%>*L@AE~Rmqnz_jDN8Em{A8t(O$zWaIS=a?tQBHLBxD-gdm7R=B=TSwE)J@$HGCypIe;~>4(=-avpZG%KEEus4Z&N z^ZiL~j9tHllHaPY%)e%&gXP}xjZC_Ecim?HvM6w?pXaU~Cj@$VL+{QX{UQi@PV-P1 zWVI`2$QL5!KgN=1#Pr^Xn3>m>F^i_W!fAaD?R5@pfN12OZ#qVT-3RslP$8wXvR+Z0 z+eUu?M=VK^O6Vb(`3S`?G*^szLzl0ctLy#vJN^Jk<$8>?w0idRALfg#yQ_>Cv)sQu zG&ne@#@uKvY_Wu}={oXfX<&o{FJ`6%Uw&>q)OmgQ|B1;lr5K!@wP>(8?jvNzIXBuW z9UkZL3z1CU9P(RKR9~4#Qu_P*fzBSsXTaK9GDcj1=F`xVfHFBTe=35`yGGY797i%P zURc?-p1@zlp>d{hqeo=3MP&5tx3REu+w%A%2U>B>dXkSI;pYUuI#4ro)c`yNJne$d zgyoap+dK=O_`ve~eA_!VM5OrWK~XUj<^O6YP5R%rGX~qw`7`1`qVx0fgQ@cmFvAi= z4|S!1MO$c7-XK21d|Db^=v{M`2)lwwZOzOSDRfPWJCW<9fA%_l-zE-lFHWiVL=Njl zOV#x3crkSKo))X#bX3eOq<~|_nH0-9St=%p7#h@z+ ziDc~tNi1&}U3eA|0Oh8`cos3~MRDAMZYzRX*(M?$=-4VLHS$!6?xCgt)TN$bNpt_o z6{_3oV^p;o%+oJOOS`0rUOurGMyP##3-*bdyMHM8~}c z-$cRfeCafk9@jDQKvE7HJw5g}3dfkeNIPE$w4cUu)4EGrGksmvXQ}KoF+uiklkUn& z)d|YoRTU^Q@P-x5%w&~*XChN#2<5dkHM!FXy|=^5jco30A9r%RwZ*t6X7?9SVd2L` zFI)V-^6;8LL&XU3}eBENbHB?tW;*A%^f>PIkDr(?1}PW75%Nwx84Q2Etm_?4d+(4 z2ZX0~x8$e|=A^ z*u4^|k!go~+n1Py3r)P^_`R^iI%OHs-?q*i$$imosvGDC*=+rYJorh|k#_5rTXyrk zM*@3C&?y(QFkwT9mj(wrPfw@h&4Ot)Mq4C2O4YK|wOXL~P z*Bd)ad`313&_S2M=f9(@nC<5j?WNct@pJlGj{R=@gX=~-2U$xTC`#H{9#w!@yu4^n zz~JJ<^nNH{2A=k3z9lyqcxv(D6;Xrzew(RUnkl)h1Ec=1It4U)AT?$~;PKZgb}{W| zO^gL<%PHG>>O%@AUH??KDJADN_tNQvImZ;NnOfgXXD0Q}yQ$T-c?^uZa??H1)jchc zcI!BfC+W~LD?%vP*X=^Lr|=61*o|P-?H^E4xTsLf>|C1O%TDc_=4cs!sHn4u=qYhW z$lBX@P7^vG?5gWPI9qN1AT;z&xUS1- zLt$@WNXAxfPneT|&X}M}!jcsSaW)hdZ+ z?^lB<2sG6>OZW+xkmBYzN>XZeqnjzl_E)m_Y4-cj$o{E*0$f0~Qc#Yv4E~|taT;fQ z*(uKhjSXBgB}If z9Yk85) zn(Ps+n0V^{BkjB6sciWFNvH@(MscKpN+=a^Y^5}`l|3>Vj%2TMk%X*DNOqDWd+%hN z>`nFx#~#Nz#yP*wQTP4a_x;?@_j^CTuRosG^T#vKbzPtFUY|3lX1|b#n`6V~hXUzO zZsp0iUsK0kk9yJDw&qCeKKyv3B~$B7ujLXRADi!s8O)+pGU_Bv`;kC&aU11aAmlf0 zRemOl=}`;%B!eF&{NCq*SA3`-RB-!rauP=vtz@Mc60eKM%Xc4TZrA!(G6wRKAA-E0 ze-w>D5(IXBP5F`-XbR)@o6ScQjjngzUPyvmfZx{6ORBZPBwo@2ZoR)0LMQqC_1?fd zw#+#|IOjq0G>Ll9VMAoTsie8jZHG6a)?0K^3riWpc8=avo8M@*kHC*QU-Q#zRJGWB zw98kh^!f!NG>$-IUX?_e5&`RNd~edI;pRllKuSJQzvk>HL21(%eD(mm-o@O%KhXL{ zY~gs7LG8WHm$`P1F5|(OkJb4=)1X-=EIP=XmaHI>NI$M?*(3VYlt^XA5=z zt}>M{@@4BanolCQVwU>KIkm# zplLtFjId!g&2QE~J-}knf$*5EI-l}rbzk0|7wMimJJn#;m8~b496d5ZUkKK|FPHE| zi5O*iB0GSlRV;g#? z`!Kzo|J|a5fJaFjw*(CpyOh^!ioxWjN!HZXez+DFpY@JB(>q@)EYyGaPmxlB3uMy3 zHy!LF@!*Rennqd4)(`yn_?TEs(lO&@OJEfK={RQxXZa`TE}r1Hk3|&C48#td`CTyy zpej*^gfm-4x$N4c`($fna&#J8=V4w!Ie6jcZyloL$?kM)_9rSRNseqqK7Yu(#H?LPMi^(1mwTUzNlw4=KYChkuu^c;T`ffE0-4Yo$gO z^p{-L(0MTwXZCLpAp{dcK$$ZZ)!T( zQ{Zsn!UYSMX0KldUzdwTRtUC#eeim4Th;GhBvUXdta8m2u``g6e5(>;WMl*f5^vqQ zHPu^Ghah=FvRxfT-J4|mo=ONNH*|>aw!qEo>#pOBBdtxHkWvU|SyOzDvrp5UY1FcW`$Ce!*s5u)&-@Qi_TSr{zB>?< z@6gOo!{-In2_nP0@@$x`WMpM2*2QDT5OV|3l_InJ)5p?Y6bRicm=gX?#&G^9-h~h~ zz2@#>iy{(@+4nsH^%;UlHSQ7k8>1aaLeU${Ag3xb5R{f`J~Jm2h-Uv zYS`#V<@UJ|oMJz}_-Vm68_$#0BYkf0vBRgG5jtl+BD-r`0=C(y*nTGXUFPY<48~&Y zy5?@915G)&yDg=b)@=1JkAp4i&1JO{9cQuVb}8ilBF}Uw5XXIm(pgPakemBlvJRwl zmXg62eSLfiT23za7MgeF9ln`A^*a{`9S&J&)lpqTYUgqKDF8*sA#rgzIXN*gF%C;p zph=c?Tz+I>(M0NRb)ws9ekJ(>10Xjb+)l+_ zy(hcDtV^|u^oA=Tr2?Rfh#(8Ghvbc@dpLI{x!G>BOFup?CLTokthqdb$YN~_4GqoB z8zAD!bTv8)2{*vm%ZnInWj+{~<7r*(xbeL6+#gw$Tnv;*{Q39<^MSczs-IKktY#1Wi6sBb`S=s#d9WK{1_2=8QW*>8PHqHaoh1; zm)4wyMDdOb^ImJwLElOUsYad(Z?)eccH7i5%A|86}S`^yHQFL!ybNr>CW4SjAmV%H1a)pY39DoirW{3fx;H?xq@^Fmk@- zlj)PvG*{3fjy)-#bx@`^m(>UITSN{|D#NFaK>pY#V|H12ryTE={XU&@bxp2vd z*4Cf+84sSe!22Nj^|z8sMjkNo(wWG0rv^{Hk}S-z2fl?aJ6tWzNWYy!6`pqo=w=S~ zUf0;iY?Z}IRTW&sVHs~MC9I1sOnDgKOa;$!23TI87sQ{BejG7CaK3uIP{OXIsC-)@ z1%5QP$N{lsQAVn)P(=by3urN*Om~WMd%`sxbRWN_e8lC->WybS zZ6C&vi2$=|?XhONgb#mR(pBBM%0Z$o#kTMuEO}a@hDDv*xTG4CeL^Kkz>bgO8Su*z+NF{1|oocZ!+}$4`hi)m-Dp=BvyAVc-qS)))N@V;RKvNuVd{Pd zW)aJ49UG7QVQqQ6)XcXdCX^UMOXKzCm}>=*K`Bq&S$|GI6!#LfC4n2H9d=`bLs91J z*|`CHdq}s@Db8zz!&gbHsQTw~SCl6~hspwLECy!!uNmcEI$mJlmwF^uQY~leF_~`B z0?O!Ab5{BkP5S86q1A!y5g7Mxep#1@c3sh{uYsRpM<*uTVcmH4M^zOSY4o2I>mCoj z>!_y2QNk$RV`#I$yMABuk2CJ>C>1&r2jJf(!d}kbA2V`Z9Hq=Y*Iq)}Atl=Np&um& z^LxC7P<;)dvzKK3vqGoORYOkB<;%W)e$YZ6NpNp-)3(netEx}IrZU@j!;;74H{rqK zdWox-dia)vug|_WOYJte~CH3Fpme|G={BXs1eoMNY z_uCI2KG5y+M0%`8h*>K-%N0~u?vooG_i(o#1=Fagoj+ppp?(lPdX|FeQmL%OUY;RD z`9;ND76X5|Rd1z)LMVgs zl$adN-DKjkV;>fpHSMao;5{4|izz75%|b`Ad#{Fwgfm@!5#ers{kp#@J@KHx{IrXAZt}wN-c)SoGw$8JfGFZ3KDLSwYya7Q+uYnb9tT*;21vX+uQGUYH~UN zoJHS~?}G#TCi)c6(m(b@-g6qhm1OYxgq&KlYO((~RAqkl>XJ)ThfQ2( zhkY`4W}!chWC~&Okxup7eDz6MdFATw^n#2{?NS}cC>@k)%~;;hAsDHiig$dfQez(8 zWwa~Umow}6#jMQqfbNEr3Cv?FU1i)i0a=v0wbcnv{T`FfvY=kkFul#D2Avd%17`G} zWPL&*pXOOy3?-*mkn4cvbh5GvAm>($GJ=}{S6&XJ{LIWueSLiyv)MZ3i}Vl7v%!tb z{W0xX$;n!8G>Ig*;HAwGoBH*@*S*>6i$nu=~tQxRJ_H9ZG#k zqb8yq>$Qr4`t83~R;V(4^zHS8k*rL$3~7AKAU)NqS$LAOV}*BXHI*siuekr^wCq9A z?@eyD_K#q`S_rn~iGEKlStPsL;r(x0(iqG#ANPU5iXDvsvVmsqwDrVo1S#SOiiTI9 z7sIE;Q+2RXr#|RJ1>IhR*xb^xosn^QpgSIb-^fQh^?@C*>@|l8h0AWBbSqn-{|E1QH>MuctVR(u{}FKGS!QF4#09{Qkkg!TsLPfI07fB*C_A zI};NVBjZ{Kxqhi=6;Tu4G@=Mj<;RK9ztfS|Tvxs|Hx{kx43PVDdOniRo7qhBRC|E2-cxDQ;6YN&_uloD zDF!pAwOBLk8nk52O6@}F99OIW4~UK0ogGny(MS$iJECX*?u0F;_#&&<%3YdP2Q45k zRAk)}pOaQl7g0d;kGGjHdtAS>fw$oZg=D6UqL%DkxtQ;p5(d&XKh2Yi3b8>AHi*R; zwUPUazS)MX3#0i+;G2<**w_&;3v_jx+`BhhBXZ&PGXtFO(1;$^UM}Iq7vBd{cO!g} zq2tn#g2wQA&>A-_k4GgW_-JgcRP4TA$Dx{=mj~*i950t>gX#$0x*OmGBid0dWen~v zM1KpNeq{Q{C@RxdhqDqO72R+xIvO1;J1g4}fkE>Ht@sng3&8G_5y}{9zS>3@p!^IN zX`=`^-WMj$j0E6x8RX;g7ldLuk(Sn%l{2qF2Kuo40pu+0JN9~rKi*N7*l=nte#;Qf z$~=C{%lX@RKD?r;q=utKoy+j{(lXZ=1=pmwl@YqUx_KD|tqW;a6QWs9xZv&XN=!k!SM8-vWY_$ICOwZXIwHWEaIK$(vy*}y!GE|-^+;Jptivf@Aa zgFGf9EgfdbfAT&33QX0!y}5*h#U5Ewn>Z4u z3$1s5X&xoB5Z%cimSk5K%}5it0xfY2Gkj`Ybvt+N1cWRtEzJw@@~Wz;ijR*!wVuWm zIUCt;;m*7l(92d#igWQRuE@65*6()!AX|Rw-w;+1t69&YO? zbZvM@aG$LnXkEj{tcH0}qVbGqa_6$$lfbBfRQ1wR&8BhYq_#PP@24x9+lyMd+3G4_c!<5| zh@`LE{(PTGqjS0Srhl#&uhQ8dz9UCZFRhm#Ozwu2aTT`xom$)i7i8xppLLxWs-Ma?&9CvsQ{qiEov?aw z#1dO@xG~6b$<^5}bocbm_ntZ0KeBa&2m7gX(0pEL&9+#TbE)p}jPAgE-51G>a1})1 zN7_lvswc{*l?xm42r}yiIR4(>so}KRi7)lt{*Q0Grbm1J*`@N&qJ@>eOIbP^Ye^T8 z{kq{rrtGE{`f4AXW41i7isUhG-)?>wG3kh`m=qepw%aU@6s+Ja1ZBxMB*T!gEOyk@ z&naZSVdRk`c8zxxYeit69&ygH>6$dJ8@Zv;|LFS&w)XCE+xr%Q6vhysj#ZqxF7w+7 ze`ODv^42Sd=sU!AXG+~3*wVW0dMtu|H_r&JD0^WdIHWFY(rGkS5vpt!D?)IP#s)Gm zx%=`fUB66ntkXRCk$^PPXKUrzr!2e1KrjQeV`&lw50iI8>|1QBjf3uZvC@(ln0r=NGIo zWF#ms5YTpss$sB<7T-Zmncnemb?dZG`SOxgz$LSo_1WiP7x4T;3v()6kkcu|uDWH( zU>B=vIC{BCr$4}+v1q7SAR;-1DjT?ZI`38No5D6?RWlLE7#V-2YAovfLNah z$jr|HAk)+S1)l*3?36rvWU}a|_9KqAASua@CKfQ>#{*i{YX3hz28XAsyLlKQcBL%T z(@b{QOYB1CzkS`G^;(8Op8Q~hypIugP=!w;0|6=S+Jzi9FFEnar#62PK(czke! zKMQv#+<&}x&(1D*Y6K3I&FS1vL#`86k+`8O7J9Y^<<6#^bQeq(WtahoE7!f}=*aDQ z(2~oNdw%bH^mqY{4q{wIv!0PP-4_dlyY>ag)cgfwqju`)={S>6#``KDv>XHJi3KDA z;3bCODcP&Yfm-kWGZ4eF#`iok4hLV+S06Vn#$n|azBvfu(Z-9_!5DXpGUCO@GXTn@ zk>Y*qlLMX-WWZeFtwIn(5xZd>pyP&?Dn6r-wih+xWeci}0R(J-&szkh3bxEBMA!ky zyHAi$O^fD)uH76V8AUbL>z~TzB`dfRAa$LxnG}k7pyr`*)Q01_>P%$u=6IXJoCqgo zen58@@DIuC3h1+ocd}?DFMzaCTts4%20q@INVR~nG{bs;m_>E+0 z-qP|{2S)77CCQ51O_`*aw5JKij~~CfF5lF?(^Khdzi3!}l#rqVw>C+nw+Q~5$c}@F z0$a^F``5X}tvjkT$I~7hFKH?s#s*egm|kRfB>@W{yN z+X}|=L6F11$v>M^hUv~(g=&lZR&IMqhRQ-G{q)Qh%3JPE&mU1sMEhG!^?(ur!y1&E zD_OdsG3=*@tGfEi)>0WPU)>65X7tqRskDs9Cx6l3 zi)y%!j5KY>$q`^1|3?Z%#5s}4(Z5!0?2g%&>DW_0(DnI(!0Ex(d}`N;FzL|kyOmO( zrg?8MKSvZn9{JPZ6MGWu=-nh<&s@ITD~6edDce)&2~!&U2$qtj{AsM$A9fIEA3>4v z>U`DyRf{=&J(g?OB|JD--ngIFJBmI^Jj!^xAvw>Rmpss#W{hBDY%-UAu1U-XII?({ z_kc3d?IJ=*F~9-XwRZreZ>^^xci=Gn8@(lvP|XaPJ$(2%K7Jgmi3JVp$Y|q1@o@JK zBb>c~5t0(-1Eu~yltqSYhykonTfs5emNlNTWng-mHo}D4k6@!B(wjk%#)iXP7#HMV|HDwgqi*lNLy`b zX#sAmKljacd-(OjE~|pC4Y_=oKkeehi{8flmQic$1NAdH1w9vNU`)TN$~w^J>X6Z$ zZoY>;8}2zA>gqIij|dNk_rF-W_jBEmBS&m64(42`zguqn+=;zV-X}+b4DdPY`tloXmLp=`U@)?Q?R-q@X}1XS;=yww|s-lu_mB#F)ocOZA1eAv*2i)2aPlb#-Q3bJ9)C=9W$7Ia&>t zMy+3dwk(;RGK?^h6scf=)#)lYT6??I5@b!y#CJ|g+n-sx@B@SxtcKA^sVKb5R?R*0R!y#)T?4bGbC zT3?JQG_LD%Bqd-OZOET27zeePTzwh`f2cPhQj(G;B?~tMdK_~B&wxR%>nWJnIn->f z2W#(>?famQ((fB15*4FZcI}S5gcG-#&|mS{BQB^enr!PabxROdkQ=aVb1}{h+HGm# zqWhdKF@?u}j2-^wCy?>^R}=7C?&!3sm(q61S`uHkxyqcq4KLMTVhKWK%WkQ#Trl&a1D16+wHl{M->&25Qz^!5s<)~4q+I4Yz1~3yn1BZH;~wQ!&+kI# zf1tTc7Y3ozv(;NX3~OqtavIFW;+CfMp@VQC4DaUVc9CB!!r-z;$v0$OJj=v+%I}ih zD;9T#o)UA}*ikMU+pZC)Smq_TlHE(>HP49Rz_JN*|2vE4_m%S9eem)1gOM+E7hwCA zVLm}tXXLpLHSPZW!@(EJ2WJ}^8qOU!4u3$eN=PgZ>U7z|KnlYo3K5^Lj6v`TrTOAa zwO92+H6Pd;8w=EAhrf24J(%A>4A<2mO-)Tf_fFrC2An)~iq2KO++sYF2oAC`bZO@> zC|Ga2agoDWy`QoVN;m*C)3@O#Yb-e}*Y2QIdv#A!$o|4PMPp}Gai&0!D>}j&=G0GF z2Sk3Z11vjFilNcmOzs9La7yEQX=y36gP^1?I(CFLIhM+j7u~U}c|^~dE@m~u^5=H7 z6RZG#`Q`tKCHcO-NNWz&vRTB5oolTr@<|B^-9-p5hwo+lkWjXVE?gH3V(x_@mNZ?H zbe|@Y;YmXPb%Hdz>G+V!yT<{8fY2M*_+OrT^S2eg zG<&Hs?2xr0O<2miSps&HD17(HH`X3JE8z%mKjzovIT=+(aN^=a4jxr?WQu0uwEa9D zs>mUTorGd3Un;&!-}gu3_X>6Nn9FmQ!MC`MZOot7ZfABQPPtX`4Q2<2b#l^&u-K`G z(*$F)!u6_7JkLk=dA4R6`%7q4#G5y7fGQ0Rj#}lCm9Ab7B^#ff2*J4TQh3O)%Ft)A zy}Qzw!comvtmge>S}L02{+S^N`LiSFzW#J8ab562>xJZ@iT=&*>GDZQNg+FTe@;vs z*!KjA{;Y6w zEKGV(1`&s&$BO#aPi~4cSz}y0BQA!)I&L*fw{z@1^dbsOTUQ}272fOeTh3#WHdEYI zA}20*uEBv}BD!?fkeR7z3_dzB5##9CC9M;`IW#C9B16_}U%P8`f2FB1$fHm*8A*sv zp|lB?wH*2joRcc5aidB?&1rgX?Xx zHP;t+^}>y-kq(x;djZC#cx&BnBWY5H{^)}7xgt$-qIdgbo7ADvFP1-VZ$RC7?+B-F zldL ze_+=3->W(Dvz(K_Oj|VJp~qQ0D|!f7yZ9+7giBnu=hV>1F+Y*R#r~;;BiASJ_?h?I zv<0;X=Rob#rl@%p%f=WFfGEs45Njo4KQDM|&+gqo)xN4YFqb#turSs#(W404E3IT{#sk`AKGFNL?E0cjvn(-~R&DIulc@t&Mt;rw?{`9i z^>1qxr7_bmU;2fojoVMKQ1?H7c32Qx$L1>OeXl`osjdZ z?Is-HW0L8q=_t;NmBrZ8Y1F22FIpzkZw_*^{ghl@M{Bv=n%&p8z6e70fO$?&KLO$~ z=))&Z23+JHoL$D_O%AYf!5_reaC5KCieRJxr?fD3pcz3ZcRm5%=4SOjj;lKxVAbX} z;YDF>s|WW$3^|9Pr|ptp_>JSJNB-k{iGm2k;@<)}LKIu|G(`nDUNHzhhMWwjS(d0E zn)i^WwO-}RiJg)r-;!0wHr1^Fy!!6)Gk5or{zpRW@b3(P;t?7O`BZo*FE6j}2t&bE zr)|;<>kI|n%!g#&P)S91in~GjkS`556om#|;iohrcPFhr`+2ml!le~izN+xY>2Y^d z2S_0s@(%0`n|Mb__#zp=86a15ql@Lh7=Xx9Qx4X`S1NWhW`29?h!#6>EUPO}Ox>fT zj6Ck{iky%WV4re;rbwG-WkEf|#GEgMUF6l7HC5g0AP75B?9OpoO)5M;UIMRFR6{cT z4p2`=$L{hh7!zR$3%+P%ZEXz&B={mf>sErCyFyfPadB0fS>gPYD`Vv0+Ixw+Jw2x6Ax;zwj)=eBIEYg?`!nvij3PK7!B z%2kB^SNZrqT-DLqpKaC&Hz*6;aN_+AcEVfCZ$tFO^1xe|0`bWqr#YOv36qDu&>~-N z@`W3H7MTg*p%25`w96j;{*7eD34x0Mz{5|>IUo#*NlZmdU@Uul}Z)LqY zpb=N~TyqA;1+)1XqSpRYhEjlaxZf(LP>lV@soEb|f7nkK*O8h%d&{;IqJGD~18U@5 zF0S8&rrY+Sdm)$xd?1bvtVMIc@IR^=@BLY+QM|m$({jAQVPQ3QkHh-`Ou{#3YLcM^8~1S@Ki00NFlkkJi{HP5J487$!Zh*o z-c{GBHoEbdRGFbNIZJbz>;p4;ba>AgdH~e= zpCDQ0y75y9Jz8{{yA-I#+18AhH>JxrDK7q;?0Z3qYS3L)Rt6G8OG#-EnI1c~!w(0h zD+z8C{J|rz8kx!xS)ddY*?T!|#WPunN|4vV^s2bFyakTCT3Xh7kH=lke{coz6GEsv zMs}SNIqp;*s~RzUc*KAX!GyCCsVO~Ds!E6D?w1UU!J}JsNst9;wjOMpoO@G9py#A^ zUcHt(E!!8Lktt^l7pbC*m%OTrYIQ=`#x*_egcVTF$TJ{6!S%8h@X(o%e-7arGq{X` zSUpH~K*<81?aIr#b;i%Vh7M8TmlP(rt@j~cM${-Edv`B$)|8BWrKe3CPj~p&DT}A7 zyh~G{EXkLpo(K;^I#^y-4j7BPU6j<>w9nx8EVA)}M?4{Y5z~|@Y=0JS}I};dinwxKI2$=v`czNzF{J|Fb z=+VqCG#yzSECfFfIFX^U_Xy@39-L8GsI9FvPQ~h|R(_>i73eTWw^YDgF$B1~L?2Gd zu`$Tn8c4gBZ)=~_t(a%W88OW#EJptFg(?6fo6o5v6JOgE!vBy<#@Nl25S5eggFd>F z8{=8Fx(&j+BxGcm!q`XP+gTaNc|Ld?brjdKT_-<92hIV_sD&Ar)YTQW_+@s_rxkY6 zxPByneB+UX_ggOHj~#&rI>Napq$k?0g{~+iS(fj|WsLP~EF2%Ni!eiM|GOE$#dM&e?vm|HV3k3|fKaghImJ*r>8RTzc9lO;T z%Fn32az|(U>H9%8j_>{hGn7`y%&vT|EP0O-FEB}u7U!i&+3tDDaxjJTl~!&~`*bQn zjskkYe43D;htEq*O@%Dgin~U}#vt|ZueiJKr6{u{6fJJ{9YBC zw``eqJ&4QfhR(0*&qZ$cTMd_WAWZ7?oMlj!QhuNuqFm+o8%z#Efu$_CxI$LBoN(20 zGP1~vqgxh(h#r_&_14+?{yUoHq=?O{G$c`?x4?#2>e z5a!YAm+Ba}AP2KG29$gteg+B~hCD+<+UQ9%6=ceCw#+Gp{B!&I%u(pIxBB0UpTk5 z;1}GjpCfo47B1Y$Ns@bM`p)06eqoGQwNaT$PL zZf%=pWCY_w3}yvg5B(OpE|1Pf+_0m^Mg%By@!> zG)>P57*Y&k^Q?OPph^u5%-i^yCxOnX2VYp@=)5lh4%^_8a*8Gp4_Xm#G-b#&`!(cl za{ud)tHkqeT|`)TAC3Ly6o`HwvL%X5u2|I7SP$m2%cukLM1)|)A()*7 z=p_VRq}ZbMmhg6!pM+&m6WQVB?C|Y|4IR?K?YN|zGWmqv3%9G-s;4MUH}Ub%f2rq5XL*(lcXq4b7 z4uX644*6G5l$ffjaQstgpB@T-MG&AOTjI(jN6*S~yO_8RXd_*JRAmVeaCO3s72pnX zsihC0q#)RN$144-Xn&z7Pk9G=FM8kdK{9##aIi&!3==>pJXTv<`xLx+?m37f-ChkA zg$dyaO*l2V`?Vdf=zS$zS^$#QNO42=*4H~<0#9aDovZD`Px0}DRvwxYbA8W-We&Z- zExgZ_J0IHwN_K4%_EHX^I>1a)0)~py%56MUq(1{Bh?f64!ckdqvkjrD84Q;&-zN)3 zKQg$Eav0F*SI?&5Uyl*kFMmZBU3&mno%&3&7- zAlUY*ILjlLEgl-aX=rJ2OUM?!4e&wcoSZSX^}HzOT{OW$q*abY``D|}Rw{A&^$u?* zpEcW(7T5~97?6(U=BL&ku8#vanthCKS{x~!l4wuJKW%-b4z>bU{gaBEeyu~NXhM(Q z&yK|LsBN3<@~Zlp+HPKuEmXKO>+F_o<*prniNE=8u4W=fpME?9246V&erQ;|Zz)k!`jxx_vBs1oZK{7*hJ7}|3-Ji}E zhK_;?ov4`uBM&Jr-Gu3xah0C>jJH{>?6_;{Yn;LPgJ3j01);z5-os6R5=6wpf(zlA)PnF#ejGP3HC-qpu-HP+pct@a=;-Ji ziPW#x1~Wl*y^8idtq;I+em$fVxktJr)-*$`mtSLR6jFP z=}8{}&VwJj?U3z~Wn9xo1R}As17}25%&Rr(y!2-!M5GdvPE|`Y!fQZ0srY<>LDQU( zs*9j7d8a+OMeP)-ZJ_(C2gzg-XH$s5UK{+=DD=OlYpFvC-Z(R>PmjDYcj?t&!VAH& zp!bJmVSoQWTowps3kDz85{@)1Tb7sC1^8ygTmU5)_+0D;)pmj;O2=W9NqsbadXe;j zEZku#$fmHz_g@f9I%3h`^b>;t;;o*;amrZNNubmJ2Q{mHk}e00qe8&OVFBih$dDm$ zq2@})E+3ScPPL1MQ<)~Y4@!TslclEHUw$BL&kVtJ#ccPh>wS18mG~@9Y*#@P&X;E# zkC($PvA__9$?um+tl8%MxKV79pHHx8I{OP!sk`Pg!K-5?GozyzF)DG^-yxP)`3O19`yVGHfn47cw5Sb)nIQ zQo^^)Opc6kM`y~d>S;l0o4~zr-Pi35HBZo=={I-A@r9o<`QhU6>N>rL z2x9AGeztvH!_KzyoW7b*_DyL?NtGS+kK>!W8m(#N&nz%bWMk023bUX#%wAzjQ8Tc9 z^|0A5EU5F)Bkd2J0SfJrS8(^PmEJ17f@{z5VY!_TL{%V!{Ql+E&wn!1Aiq0mDC5Xp z3dHEaW3WgoT(3P`~lUUU(Sm{8dF=~A}2-V!*bNx))po_oIV1>2E|wfMl4H7 zANIoRY>)1S;fA>eQUe2inOdWKL}=nThM84iV#kCbl@_yK>_!C3Dowi$MY4iYA!J^I zneqb@;DZ;Hy=$huLf(uHucF_EegEzwKFvRcO}xA$Fwi}y-+qdSZkpl~rF%3u$&zT? zTvlVy#JGx7-W#FSRQ<%$R%5X6>=*=4Y#bzmrHIpLZz>@83;PJKUCd;3brO(0tsiZP1BYC zLlBJOeK})ITs-jeO9!6o{7>iU%mrB<`+uai)=q}g4{ zikgD8TJ^D#4arQQJIuY)c_1)WNt!Az(j?-BP|rg49*pUgLq*|-a!)FDzokCBlNwH( zIm1z3u8JdPgnA~~n!(B6f4G!#LW%yu|0<+H{^okCf`_`?1~97X5zM)~E?8xJhj|{9 z2=Ktbtps%v5Nowtw?t2A-@g3@ey;HF4N;js(3QJ=o|W{&cy{81Wr0oK`1C_K-nzKR zvnKd}BnmEw8x6L5fCB#IY1ssG8^V$>8xt53CXHPpfOMflRDEt@;vv63IO){2waa}? zCV|p2A)1h7l9(Umd9&yz>DkaYiVp3eT)WTpTJl+Myl0Ym-k2J5>%=Yg(2+MiCb_4# z&cnEP7Oopf35y3O?0jw~K0EPYi%`$!lr9x%q*c!gcU*jyC2?vKoG{aMe%am5mE>6l z&kaorM|fL6OC?2HRdUm!_nnMafP1c;#?^ih+3IGh+o1Go9VbHC+OI|3Xs(IZN)ENI zWcM?Z(!`=usMN%d$x_hmdzp$OZOjW#P=ZQ^|) zfrw+55+>%zjR@obS!GALMpAmh@UYDuKEXgT)#!g4$p-Co|3*6pM7-P3&$YQe)F8I_b4X=0f=%8 z1^7<=vdiQXbb$S5hVUewtaMy@=%9A4rKhA^N?w}p{iW>BXPvJ;kI%bOClVlnlBCg8 zO}2YvepE;X!D5aSC4IVDx4d}sB;kk7rK-A{QYY2mGG3wWmrEF8cU)YztyDYmB-}_p zm*@4(5wE%=aj&cnU1^qhAD-qkk)qLC^OI3#=O2>WKQ=h=>SiZExSI@cToxva~$G z>gnz6%?M;Q6BB8fBP(3mf&hL2if!PAL$<7p+OTaW1SR+%w_4L)Z4D5_rf!fVy1(|v zOH9nnz>?e+f^4u;fYqNq4R=)=o`I|)MMV8%$0>D*j?+hFHWtXRuan4r1-KA=nZADK zEc&pCb8QhbC;hotmqvaofJsX4!;3m_Z@yGqoR2OZMj67;v1udEwM6r#feVUiM=ETF zSbr#=&Z&^zyr4hC=!PW^2kvF1*^03uyq1^(6~q{L40gfI=tQR+0!g5%(5yQ zAH^>b#MS*bI)N;+584bT0h=jUDpC#MeaH)CxYDvABT~Awam2twtCVrOCe?iCznatr zQS)E)C{6{SU+>h~c2d+BnJxcj`&bk)i{^QE^4+C(hR8c75JA8I0;5fEFjsB_=qPH| zz1cA&R74q${VAL{*J6f{-@GO2#NG5~MoP0_j?|3te??%2=rW)9uF`K%k9AN4410Cm zCE#;yRR zoyqmzOygzalb?8*=9n&8gpd?B|rs` zNjOL&2*K{A#q1F}W-)`%Z9W8DulrIneg5(~pb6m7mP&MpQ3=9n)KOEe^%R~xSI~$) z`R>mM_XP5ICd zu7uapTmHBbJ~XMLbf!*|ei;kqM^bJq?<$j*sAW7=IN=uY)SirJ9e95W&v$(Qo-bLK zFs;zfj|abb6?mTt(Zk(BZz4h@rKBz)S^ER07t$5kyhr%k3@$m^O=QDeWS~t&#)l6% zX;%3;b;o%{y`Ijn3QG!q?K(?I5KV^W`;(D0)iF*%~ap;II0<5zgzv_XLYSt<};58e)iG zq$^Ia?rNMp=$mIMy)!H0O1}=9v*~zmWjURJWQliUu3g5dO7b_T)(gVFAjJN|yg?L&hiVP-y!9X~VDHXuU~;7>yreW|#H!?a32?9y>|OwuUILlr<;&oh zPH!wLJ2T;7?bYf9Fx^E}<_-QP&BnonMPEmkcQgKtEtM(d=5v?0=6z*mI@h|p>tTSl zly5T5JqWOVkk%%8UPLw=jt*sb?U}y(a(pb?z`|cdb##z*Y*_lt;W5jafslB*0r*)P zdV2x7RB=0p7IGxkaDZfc?EGmKJ3#U=8AR7(Ec$jrem65z#o@6J9EI$d@rkLSUtY>l ze^nS#BjJiqbprjhiELV{TRd~imYTG!kUvp{bbRxprzOw`4mFD?t)njmBx+|+jK>*yRIo{>zGU? z{}w=L9DP_Oxuo=$z&x#5sYl^tGAJT7w zUrL74lu5U6LTILABNZ-3M=(a`wy%X3?o46{?1Ch zSMbu((NP{hvu82K&bf2Kjb)WVYJXp}K<~z_FzJH28`r^IZmInQb|szsEIzMsAAXOC ziHRS;@#qtCJkP4CAtT&ho@TcFM!=7iPk%88^I4Jp&~)IfDkQ`(J*O2{EgmeKE#JfD zTD;fVeCNurn6R~w^SP{0jOnu6P&Q$+SkK3#q@@8=R&3rZW)6%Q_QnMZnm0A_xvbOf zp{f*xzO-Db_M`9mVPEJnd5z`uPStBVs24C(GK@(f0AR9|h&~xwn{$0U)}A1#Cepz8 z$S^DQ#{hU}3byB5?mx1}m3qBtZ_y6$49{c>V?g|J<-gRq0dwTB`)Aj4@X6u+t?Nyi zFeCqB(RBa4?fu8DSKflO@3>H7kgZiPi-xd*k3Sn9_v8qr?;ZWE?^#j$Uiu&U-h=n9 z|LS{3TSu@6UF+AhNv%v2-~COC%3s_s%hOl}FKq{G?y@OE;*Xl>hqtQA_w`)KeF~Hm zytLINPA^-phYdm|3()d(oZp(@2sp?X_yOW)RZ^in;t z+ihcArVo~P&=C5?yI zkka;UHUDaRYM?y-_pVn`R+iA}7U;R?dFy$m%Fdr%uf)1Dhvgl+ZqR0YtnC2X30MT^ zdxRNB-*fXYKj=Dl{&2vj4s$!D4zDUto2Xi{{?}J;!g>A9F`hwYCKE=!`5Bvv%E+pw ztQn5oYWe0j((Fs%lxiKFH3i%FsOHJK0#)&CV*%kD_e&DJwB)aeqR>&bmGqtEodKI} z3-73#6RW-+ksVrIi2pBx!QEJpU$p9{XYD-MRQPkNTGl8$bb082V2<(*1po=cz>f!4 zL)n1v&f~!s53mlq0O#)N>Kc^Pi|tSFi-5%!N)^qByA-{#^(h%h`e#a!d7+7JL1Dq< zN%4A;CTg+}yFI2`k8YdXmcU>tgz{5`G2+st8l<|qejP-N52uXNuUX72Uqol_efp8- z`!RW#0H>K(t#n>7z4xbi52SokFNGC}^TS!39nmM82UKweOydl{ha@&LIbfV+9{)JE zmu04haY&G?#R?IV7svzgJUYbUB>3M4(^|kVMR>n~k8Zq45O@5Mf7teaV6^(|{+`h~ zt=jXOVweQ#(HVv*ADv5g*$eu!QYM$XC|6m4;RV-5xKs~Omkf!Syg>3sSP91UbAY*;xyVb1}7$No&ZtxWy9*jmH z>9Iv$gD~7NOu~sG%g1tmh4HJYco^xjoQ&^+ne~$e9Uj!R0@XC2O??XL97^wcXZ@4T z4LH_>{0>A(P5ujrI@|D{fT+L0p+r}cByplW!!w=V+q1P+^cqJv0zsM=?dAyf7?Yzv zEpvG$vQbyIm>$~g17UavS-0j!H1wFX-?@X_xdW57hK6Fud`^T*M*l;vKtE*<^{3rC zXAWKOfGF^s2ugfXMbif`kvG!#xIr-+h}#C+8f*l%K&0Wp@dTOQ+ViA<>ymLF{#%nY zVpRc}gO58lxXl!i|Hs>R$5Y+E{~sjXDcwyCqoGKlXxKC)BQ(rJgNS6)vECX|DMGkq zCn-BK^Jv-*3E9dxwlX`$Ilt?D&LQ0D?*2Z0pZomLAD@qN^BUKBKA+e1`fKG%5}C~Xj=(ib<(Gp)>o;UTlnfYBLlK;4SX2bx1;Zg zl1-<&uDNYKK$@92fqmZ92HJY8D9vJ@p^z?n5dY>Y;rJv2my)MH0MjSL9 z<18)}O-}r17Aw~(yI5vX=2Uj~%eU{)rtuN^__4TnNdq2)9PLg=#P$@q<5Mm$AH4m@ zWpdRjA!%II?y=U&z(&JX>gF4TTdMF#9&ts+Lp~wA^9=r$G|0mgE%&UG`P01p=P};Bp zNr#uv;|#ryiHX=dqIKTs zT)_qxgXf0z;J9u?1H^PEWMsy~2efqybpqfFjcjZXX#d;EM{xpwXf=Qn(AroVhL2~c zf4bx5GyPAhbe#Oeg&i z_C!luMZPw}l*7@!hBsz*=H}+`J~TAc!89#J#kVcrV9X8+$Xs0E-2z%~F0C~eZI7r~ z{^n~yi`fa%OXxgcQi9==Mxi{eh|4`4hS&0 zv3u$+>eny-g2`=M{9OZPVl|F9eTgMdrp%&ag7?hqX!z;79zRk8#^OI-F^X2^wzogU z|C2%<`I|(3N+Ew26!N{dtSp>|K*5Qw79WSUpDGwq+D{K8-=}CA+1%a%-?9xp+}stN zdul&?`LcQBVE4fdhZGLkhaY3Qye=du!92r6b#d-bb%D_Y2|Evu3Wg3Ibym|Bt zRdr%&rSt9^4yNHFFb*G$(i63I--2H8_1jZ>D^UZDWi$b?{}20QsI5eU^jfV)_)v!W z_uF9%U;=?&@)$sg2mD9Z9ip}L&C_N1lXp>3Kn{U-QKu2Py)K%Yr)raI;~9wD``;{0 zNZ!7u*WN_B<@ZPieQsv!xhyV_y>Gbq3wH_UdvhO@;?w@7-qbsJjC>~fnhMX&kw209 zM_?G&iaQG$@PB8+L|RkI$_=m#SL$e9PNcH-cEdiojsPrSeS%=(s!7 z4ZZv|hDE`xehOP1UV8rhBL1?M$iK#|$US+E@In}MhF4ZOR`osk!z-QcJ43H^t=&J5 zp&G|HYbwd|rEA%IB#YJ>R#wjiy-cx-O#VRl?&h#1=sT3YZYQK3+4T0>jY-zflP#MP z;jP-UUgO!pb<=1e^3UK8I=BoP#J;38w$*tz zb~uooSmDv3xTf1B@B(K`BI$<$`2FfU>%2|w6Ln~SC|^7 zP3x6IX1#~~%VxP5AVSJL5w0mijlDd>P(S^qp`y3+eJdd6$h+pi@S%acL3r>{R${QA zu=|X;b{;CYtsbHgxauM>FyZbD!L1hK8Q~uUt_Vut`udvKCblm!Z$78H(7_DqPrsLV zTJt?TsB1M-S4(S0bM)g1>WS;~GYnt2LP30 z-p#`vR-NZ(3t0|$Eb^x-gN>02TJB_#*ZyYY{GGsQuCgm_!Ot1Eg^g4O4*3lV?i-e- z*Q_r+hn{U_V^zTG;ju_U-oGNUzA(3sXmRMYkHzcxlGbwvl>0pm6?s}#JP2^UF>3ZEWEq}G|({1Yx(eg6@oTc}Nd@8<;^Q`sboky$#-OR$lR@>q2qWD}|-B+get@ z4h#y7c~&iUedBrb2@WR(BjddbPVsJ)b+~+4k%K>kj>wfyI3T&YHfuTYi{&+^n>`^s z80#bC&NTxbSrf)z+!+mzld_)VuTI~r-ddO>!f1%0d`1zo$C%zhV&C@w&vc!`acbME z>67~n6N-EJTJLJdKFm9ziJaUIKh1xDZapS}L$l@CUlsoF1DhN!h+aq&HeP0%O5 zmXi}^{!=I0`U&W|=e2BQ?^qcrmdY`4xq?*X+Vqmk;5xUc*FbjmhkjzK(cS^y;Loz| zCtcIn{}8_#YBG4O>J6t={&DXM+_Ea}7r0hX1{9w+Gc&t-Rih4{u3c&*RYZ6d)$nkS zX^a@A%Znt$uf{7aRa39tkfkRZM_F29u`ZEI$xlFvX&q9~3;$CTj|YqXz4v7!Ez1{| zVd|af_h8NjB^IuhE{CTI`d-C&-Zu9nJYPS%fZ-{pTwLN!Ow7r_B^eyt!5n^{|fkN{d^W@%&5e17U*I$LQr67%sIwIHA#x>nz zMlM6qN9{*w?eI$uaT&g}-NA;Z31h89mSY`@zjb;|=#EEz3((7U7nTu+SxUKW%^dD) zLS-UwTRo#|+qc4%Y!Gg3jpB;LEX`Hrk!HYDiABqV*(SGb1Kbr7Rn|3YVpy#B{Xl3B z{XGa^M}WM-(CYQ~p~(fN*gy}#*h0&W)Cb=(JAlW=Y?uJ`xC5PdyBN@EL=e=fVC(y%~J0aSYjT`v7OF8mWn;< zZ?La2T;ks?SOjyFvu!b~{g| z!8HCQ1;p>LY{Y94*Q+wis$`G3H{|EvW|PI9;`j63vLny-$`vK|6t-_(UiTA_qnN8V zNhbw{nii#Pmv-ZA-(hh8^%4VDmB5vupInK+m-NX^{kRs>BWo;DqSAHfYMVYf`n4>A z&Di4+kqE1L$poe*-H_0=3b6|?m1Z?us%39Vom&D8X9I2Ee|H8cLBqD5p#M>>vGMUO zo<}K-d7xPSxQp_M}Yi%u9PRxibdAANpKzpl;#UHIq!b9XRGI zy3T9b@am|2!JnHI2;8{a$Lw2t}#3B{HS=~Bt*^~If zNH@5Pexc}H6jFPBu-~xr7>dL3^Fsr=278A#eo1Zcak|^Bux^0cAaPLmb^Et=Q~qGJ)Vtc?f1uiIUL__Xg2uDriPH&DAH73vwG2j zgJBOUoqR7mRNQv*`9rq7A~plkBJLJ@+WsoVtA5_3jO1IX2vUovbxcK6R%W|7#)|!{kQM&u{ zGEqHz5y>xnW8P-4vh&arxLa6QSX|t}61?Pd)tK#_RT{RKs}D*s=OgHcyh|K?O4VB_ z9?>F#xFh84c0UhcrnSh{barqjtJ})M?v<~tbrL^Fx88Y!3LNLht@kJ^fa&ojkyJoBX)w-}MZv%naI=my|==klbHr%@)PtWBdCk7s9^K<7Z zxi{C>2eKU#dAc=r{Wv&^5sJE_bBa+f4IF(HJnZ;pZaZ6(> zO;5DGF6?DAw2zBk19!6!AAV>Z(aL-(jZle?v2kf^-%!R_#He*60HKIKf&+`w`~i=F zhbw*~aE(ulKH9=?3H!j3uso`CfNDc3BvPJ z@~8{IK4jZ2qGRz9CPk(wZW(w-pqGFoh9$SiiuX@JseGguDWXqy)cJ6!@E|qyY3=eQ z7IEgGVHEwmyjcP9wcJ$hx_0F*@ByRsD$Z+E?;YaL_mP;6w_U-iNo8UO1I(zsq|}NC z+DYMl`4!#w@Gubcr}mOwy9N($HC9&}^h<{bH@p~bMhs9FF!6qC`0gRXnKzX|te>#E zq^d)(tyiytSAd1@<200*IN;iIy5>z{h`uSj2CT6Y1aOd%1E{W0i?_&XeWrQrk(c0o zYbK1DE$`yJt3`FxLSdpENZ! z1!ukR#x?0?tJ8$)#$wyhG`1Wb19t&Oul#%dy5oGd;sU#>-Nb!3jW;})Ozk}?J@PsA zP%Jls*GWzbf&RoV-(L1$YsirITI_7yl&-Dh?#{Nw1dejY^YTUG*A`;JEU%Y|koTd7 zA-;{~&su(jS+g&T%bajzcicM7{K}|yJ4QpW&@=8^;3q$b`xc&n;L3ppSB`T&e3WEQ zgTG9zz6U`m>7mxvCl1z}lpQRD8jP>e<@bew>`}ap!$Y z-n?iE?t$C_n}f+72M=fQ9Sezhi^E1oRmn4Gh()tm=SU47=In4E;TMpSzkK;JA>pib zsAYPfO(g z-LLSF$WCVO&uq0PLEtIrpOoo4$YXzE!~kj~^o1sBt@ILd z1=+*yZmL1sFX18jgx)M&MvFde_zSHFEnnD!w0R5vaNN%@CX@S;KbRhARccqG%ix04 zvNh_lxadR39O^t|!K;`tfcL{JOT5cEpJ6o-e#fvnOuO_*-X7;WdtMTIaiNa~8IL1q zP!f4Zf+gz-n23F}8|aa-A5V{u7vS(H%JGp97ZluVf11Oqs7;Stbi54iqMujey#!8q z%u9cz@u}KR{ph5b;Bg7870;FsekeY2x1w$_tDsA#!z739 zOoDdk)^t!x!#IV40y(0j6i9QGB2PYtK_lSIAvcBUnnH3)Z!9aXNg3=N1ZQ_e@>8E_ z7fHwRaLz~oH-@n-MBrIQ0nLJhLeYYWL@SsQ^PphrK_qHi6S-qY02z9g8loR!3^~E| z)R6eq9lI0VwLY&s5lWY^IcV!mMRq~g`b3Ol9<~_0MN}g~t2~PLtAA5YpZshnjmtu{ zF6#+~FKUBpptesdYBq~ev+>hhx+FV%smR~W2AR)pW}D4E;%jpLH#2*yQ_6Iw{0Ypy zqWR%()Pse~ci3M*b2y2YeK7e1?+4*(LPkv0&65uXK4( zbEtjfG_oetI!7xS>!tkwO;D?>NdtMi(L02G_&-}gXdOE3wNZU<@gQS|#Qs&GGOJr2 zFk9&3r@gpGlKfgbSwrP3R5b!si*oVeksLh1A{`zKgprTbsf@dJ{ppbh&bVhL;(&lp zIC7!mu3h+|*a3j>n_b1ax9%2_`Q$vKwc0k=AbXlJM`Oy@ z3Rb)Evb#dQv|~E%o*mvbG-CH^?`bBxDT#&A`SS;JJ{Tm`l$Rgxm4?@xz>zmLHbP6l zl7$S{aywH?K zY(rBiWOR7=U5j~*ed03NBS-X*!b2A6fj#GH@U>3961pcIE+4tUh_QVlbgN8r5)Du7 z6Bi+fqVBF5`AQ;SQRg4={@q-H_x)V zQPbl1M8zT!l~L2;tWijekD0Qpcq8!VNfgUEp5U(VnWy|OIu-sPWY5iFF2RWU959-I z(fk4w`qC+d%SBn)OV^c*hHrMUjrSI~Yc~WEn9DNpYwvGz4N>=u7A0dlbK#V=+P>DTZU7yN57yj`-XycsZw zfkxXOn8c>&$(`d6$Df|qjvkx-pEV(g>iSJ+og_uIG2tFrCQRXz!CMas4sRP2L(!B$ z4k{Lb-3RxJvbJUprB$Jhh-4ExA_TWDzmm62%Xx%-sc(8VRQl0A0~);Drd>~`{Nh;y zYgk@cZ9R4D(hpd#65nP459z|-H|p4>vu8JQc)+cy5i8?Xvb`+vz2@m;EN=9oU*Lt{ zj-!tZ7>#Wu6YZwTB&At((z1M~2icp(Aymz%lTb6u<{hu%&3ia>0nAKgd62|gdBzUz zfbl~Ard2eIWk<GLt|$Z%tEZI z+rZ*_r#7;?vaWbbBVprI>ZmY6p^ahx3RwuEda$DY@Q9b z*0_y~SnBE`y5byulUwXB>FFIF`AeM3uc$!sp~UlEgPOFhC2P+~v0+rU2T9*lYDvqY zPrfkt1g-19q$&@PjEeN990vbqZ8|MvgI09YlYAGSI_9zwZFLlF^$C%66&&beXqr`O~D{fG*57LejLNQ@wnN zHoXqx6L2yC%TkNdb5VfLn_fbUhb(?DeHUKa|NCdx<5=C(EV>UzU$z+5MfUo&o&h~= z4MQTQo~cGJ0UQuydrlQ2Nj-8VQo1|JCNK9AUz>++W(bu>L|qs8Yv|odhf3)#6oC}a zp1)chj0F9dEt6#~d;FovD__-Q&@|U2X(`rLiH-w$#?jhLIlVeZ3T@Ij9i%xa^46y^Z#YBLO|xL?V{&?QMr|>C(0@ z9mx#R)>iA63#R4wI6^U{sK2_z{yMd;&3`w4DTVyJmNMI*CUdBNkx4m-8i6_FqbT6v z#Z0(?+Wh+^CE-m*8gsaCAq)i7)eXsJaQtGGS9K%A1ajD~8~j?IG#{27Xdh%0^P3md z8|CTWeX21&t9ur#XC?>UFQ7*vdg;j%w_o&OavRDD4x>)5FmQBd>s>#igG?Kc<3!xn z?G~!h4sYDs?MH+6u0PancRZp6j!(aBDwV)o!5dwo;CHDkL$i>(&%cG-1+w;x>+cC- zPYV&~=)CbR1x@U*lgn`Ca*aq4S~JZondoYkLCKV;-1-7arV+269dP9ucRYW+Xq<(~ zIrGWjoigk=1SRu4EPgsE`aguFX7`xKw;J0K3e-^hEP#eI1U`(P1XUJ1Pz=Lx(TP3K zW5bC)?EteDp%`ZmIwRI3iGuXTfu#)7W zhFpP}A(uY++*xTet^8_7cVRx>Eag4; zbiIFEzXpm;y3%S5aU@_CI4K#@5A`k}$gM^`7JSmRu0LH0i_#XD}-1rJePgsce(&I2P|t^AbMo z@eV7dqwWfp)uFLXx75Z;Zr2yo^Gf@*q7|{~Ls?fu@W=(j@o$SDVZR~`;Is2xjfkb$ z**az=Ro8;2nycYK-UpV~ek)qZbx@+!x4WeRH-#v6=7QRpPVXEu%aX-Lf|(5C>cJEX;SAzt2Smfj`&e*yHIioYOsVoi2gb>eh0>-uwy6B6=&C!LW_UzpSb-Q5RD754opy|GSKDZo&8?|Q87+QIKTWewCvUA}FR&;T=rIaT8(Jb|A)W<(Zl(vv+jn*vYN-5oR_Z^LFXo;>N5m3np;Py9)p z*sP1ulj4vl!#UZ)az>+j3C4^W`(q|gemb43gAqQ!&9*7&fubznv~B|gIbaKazo0_q zR#c(eVgy|q%M*h%fR)kK*4EHS5G?}_C06$PB(K2R5AH#@p>0CSfgQu_O97wZk3Ux} zMi3Ltq-Z4)Yw-h*U>qs0j~9YEc@Ca_g~p()JjeliUs7{GH%9?FX9la%<$}u#ZaU=A zC-WEtCj;_@+84fkMiES(j3;CQOW1C=JY6e7o4E{NMZvT*$e&V9a46_QO^jwyD2|CS zde>#y!5-$5Nu3Hsk>?`mFgQWvSpIL6Q>Y&=Rc^`_ei=pB{%BqUyOYI%RUN3^Jj1}K z_GLT35qn)hE)TUY_i}&Pm{ZP9iRtklu!t88y!=0+ejgvGc9zw3Gge<_@0cEQb?43> zA}8~Ihtmx_`D0R2)L}g1-<*V2p~4tfv6K;mj$(&mjQ&yPR$5mYiy~bw`VC z7&!!c$$Lx!9B~f^SUEP1UA9ir1jmJkf#q#J`Q4uC`Y9m@m1Bz6g+JLn8ReLo;!~Iw zkKcI2?7TO0(Bpxe+{H+6;YESmXt_s0EMHD}Z+l@a=QTbg-@|c60e*mmS+_j!j`o@s z4dfanWU$-GX4;;Iwj5|yICt(QGby$d{#rO&Q?9whfH6ohb$Y z;<*fksD0l%PKODMJo(@OR_#%A*2=Sl7x>;5$sz7`K8_NIw`DZ zjk<-x|AbqR^qyw}BEAQuK;nSu#5k*-uM`9PVPWGO{2_3A>uVGXn_(Ytz}5rCj3@B4}J%p12FOzAX;0?#s(w3`7cQob^F<#+p8rn z&sW8c(byrn{0?Az){-$+BraC!3H_URgvYVQ-0R#2Eeg-0e0ut(*;|&0iKy(5qh(xqcbqsiM)~(iS&LJ(Bgj-hp zD?~>dpJMoUA4xINz#{SKw3S0io36HhwCUUaEzId!mD=%`Uem6eB6C!|^9b}`um$xu z&}$l9$cvpaCzGrxbCMI$UrS}6kbkD2D()iVgh>mhbHS#o8b}U@X*vk~nfV`x(Xba~|HD6AFOheuX!&_oAVN6YpVq_zEE*-NFk|?AX@oOFOcaDD-r(O3QOF!2QarA~ev|J$ z{QkRFkl+>TiY3h-SKID+3B>Qcr0$?Ws4}lfZ(Oxl6V9p;)Fbi{t*9qqDm3<1=ZUv; za?&}ybF;1ke_7f^BodR*ZgpgZ;IV>-r%yPOaHTT1?*lTHPCGLuC*+iVPyDUY(h18_ihh0K!+EH*oE182bD03g}d781qs~)aF^xc6D zmG_2AOr$tKdzHHs<$;>lMt_}8Rbj#5S#lBe;SB6(+T1__-Qd%INr{ zhO}Ax4yoUqjHPq7@A$}NmB_bUI&FB#L@&~mVTU85x+6%dqFN@>f^lCBSkF(VAi3%E z$)tVBYB)Jh<{fFQp}pyGTJV#+Gc|z-ntlZ8SxZhOjTVhRl1ACzO&Z4oGH}&wo)t?6 z--hRka>_;IIekBOs`PLw@Zxneq0+idYnK!n3O>Dec}iFjf1nPJ3`9|)o^H}G|Kk2T zo0&1yc}}MJ3MtFnh+YgTd6PU#ZDfU65XK8Qs5^?^j39F z%{kPSd|9c2S_x?Aqnbggrfxn43=?RuS8Awq_;my#_wHW-^t5uV^>7Of1+n81S$T&= z7Zov0Sfl)x#q4xa(1Jo5Q+yK-)&{$DKpx~7!x@egGi4PrMFcR-`$P}?;h%DaU)tl| zy$MpeLS|$C4r0UmX_ZEM){EhR_v)gpZpQlpeEeP=Wm=D*^18oQZ9j@Ogywi!aE!QZjYjNYTUhD(Avj&}LqHl$Ht2WC)Uh&}e9xZ081hc~~_*y(w62|Q81 zY#GQp+xF(~C?By53v+y9Jr3}Evy$ksKm0STY~a@7tmFETiE>7N-Xfwz9?jv32TKhd zX=dtoNyhMbo5<1C20kRx|3Nv&=7*{R((nr7+FN0`rJ98kd<6&NjC@Q#l{@q|B1uOs z0D~T7#Rm7E!mm?=lDS$h#yICAn27lDet6-2D0MFVoq5AZQtz!1$roIuLaJbhd`!8N?Ke)!bkYb8$dQWpUSYeyFm$w-*qJjeij3kbw%NTrsypYIaJVQ0YL>#Uiks1OzKuxG2+LB>2}#`T)^&Mp=Xf+UExcnvvQ#$82az3Ue05Lp2_eI7<(-=jczA(pMd3ohHZ4ZO z@xT~c$~rL#wShaN-2@SZ#0Sxj2qW~#64ewOs*M0DOot4#E~6-9o$V)Nt~Gkr9b^TKTB>vZ!ZiNlC%ZM<97wk3K!LcI|_L z!K(^iLvUpfE2~4U946uhd8nzvz(J=blAAy_B9~)Q_=Hz?uaN&eq;+8H$*0pxr9?x>-L&%j={3f}2X9pMyFm$m4swban`d=PaceMGcd~9F zKdUq`tckUo>}0hCbaJeqjGoq$lnMfj7pSk7R5Pu1EP@`A@uXA%iE&cD_-Ic3`go_n zqg-5mxWauvhdVfEmmW)=+}VtS9LA`8bH&n)(F@X3y{$KRs zlC~)aiGcj%h^#CK2wPCjRhOdnB#)JhAl4lpj@r~u?9F@Ls#JHPlXw--Fq5Z|ktvfg zj;oFvN)kFxehOKR>2fZ;ba0z!kofTCGQq7nFc-wT;K_;Y$hb@>h=zh~1tu!8O-v@Y zj9qYl_GOfl8vmkhh>KdZfj1$&Rj$>4{qWMsZOZ-!1$1*RpCMsUc|lMit5Wv>zWs3V zenqOcG!UUE9n*+>ceI5Ae&eol1=${EkeP? zPJ&E@dOVix&`4svyn{m6HdR!tT0PpsDwC|j7Mvlz5ok|HC~ zZsN4E(?p0Pp+%}!vC}0)-#+@@<2Q@PPhzAcUOW{J5{V^S9TuQ>goitU02CJwL?5%H z-q$LYp$G-PoY5*GZgeP}o0KeTT()|WgbIW~TVmAEcIR_X+~_!|+d#{9PiheED$Maj zc0hebT_^}l1wG@ehz945y>q#PLA()$ohOoxz91I z!AL5=W2g3gJhJ{|KSp};Mf?7sF}?N4x(mi2C8MzIOP4I6NIcGiken3L(vRbE9>-CV`$$T8|V2_gWhuAUqLN^E{Titd1f{%L(pZ2_xL*=+>U zd(M=J+6$57v6hetDGqWgnfRR>M>ovR`69VIb6(m1;1hewN(aV=8pCNTy*^arPg1daI?R{ z1AS2MH?hLS{-MdSrJnIVg&fDtW9m7MV^U5%L&$_{B)RrNqQePoC9>)toMMv*`Ar3G z*um9C<)I@F=Gldjbfvz0#b>NE0=r!Ia$?P8Ii`%rNLewY3TEhc)m-uHy@)sq7jxh%<4qlj!gKAuSBXJ9H;fY zyGdl6(`kGN8S1S-+LoOr6{ZbZ8=Ps)+38iJOMYXTmbGDh5{K&A8`~CRloRmw)y%Bd za`c((^z`0#Ndp5oOl$Nw5PRUX`VF-aqtHes=iwsBfKJEb-{Yl3AFe%$~f3hj3!AqB;BrTBn48benYqe?GLHyeam31i7!i4~WPxU^eR)@xJOK#LEPTh!!In;jm;+B(vrB~I4H3cSM;vBbMf+iCW zGJw*_qfh{}ejVhsP|YJsk3~6TpqlVMP<%Yb82QGE>>i7D!HonZkzb{qCf$%#4%pjq zns1zaRx9D?k^qdT-PghGwPS)#}*5%V?vV%$TG-beYK-|X0K(C^+6y8{4 zWTt1VWm({C_joX%)EW`&yfmDimZlz!7u*elF!Q;#pNzffFj%RPU^3 zrtYRIEmU>NdojCO{z_e<(a#~VJd;pfkzx2wv#1P7Uv;RVJ!B#`YtbIe)%(6*lkZ1P zW_htBBP1^&&~GV4LMOuTi82TsQ3s&oYGi1rV{e#h$F|z_3oxTXk$f90jdnZ?*3a;k zQ+}F5B00rMf(yW!nW;RL_2&XZg(Ne3G7EYeATTCHmnK)erT)pzdq1ntjTP2f?=J9> zNLySsw;c?b?gu-2MnRd6RLNc1g)50&KV;%J;oE=feMugJbDoBaco<(cydDzGAR#0) z7_B?WOKIWhj-WMAz`27-4!W!oW0 z=Alhl?!;4h|6QOP(jP!R8cP*f8Q~_9_SUSqs7u}E7&-zF+>cozK){Xvd8?PRb#J+C z%UJwCfbWL&_^m}!#LqH=-!RR))ix;i8y?4J%#fP3w(3!OeUpsJ;8jDlm7<zpteu6ko1u*I8C2I}-{Zp+pa+`ckY@dof&aIFR93Quic+0Ivo-#W-g{rjr! zhJ){Oay{{rR^tSxhO0zE;TnGWrMXElO2Lig8I2aNK-~+3xD>ofF$u1}WOs+WY>Y^7IwVH%5!`w>%Z$ zieA)&qy57NFIC4iTZN|nxCg)Em~kIYxMZ_j9RyDIgT7$0?y%-x-WNZ= z##dQI(GY^>g@FAmee=B%K`qntAC!20;0~oljWlZyd(FzthsoSy2O{)p^6B>tIN20X~&$1V>E0kKkHw28uB}> z?a+fvdWu|ubx{?;)_0(MdWh%k?Tk$wTg=ztu(a0bU|ms}5eKHrQ^{Pk<&R#8Zii=< z;fYU6CfKw#j#7cSW)6_1#mAgs_13PjjK-Ytssr*_^*9H6;oAFQy?I+u@d6#n9(1jM zf1lmX&VbuhXH<63xJ*9N8F4w1T(I*G`dqtw<@V%;C?A?;o zb!fi>j^f#~L)-IJODyf_YJ4(kszA&Q}Z#cP%-z!^_t~^r1~_)USIIDc4hF$Hj*Dd__||(o#&7 zkmZr2-DDNLr?k7yO#_P`AG#FB>KXm0mD&x6%+n6|Oaad9tj}M2r7>SImS3nn4Y^~j zQ~*}gueFUpq#x=N0$}|!LA5o?eel|lD$xqIo|@THzEAzN@UMU+We7-Ahl-cm-%(Cv zCd^4WzUeP!6{B!rO80rMU!#T89i95xRewwH&Bt9&{2F?j`VuXhz3TrP7hvjFV07A{ z!RTR4Sn`AD_3f|~!5dILmU%v7dLk;dr8G}bulv+ja*Jl>lxEvhw*Q!~g1;B?so$dgm0tzXmVgPCh|TIL zB?@o`8Rq!~s&X?z3Eau)6=fB7f(R?=(4|c?+QN{zePI+!n);5j-&FWo5_?puuv4XW z9!P8!B1Z8PQ(uQod<#uYPRMF@dCTnE+Lc^?L#$AGh5}j5-9_-*&_UFp?d2Ep%l@Hx zjvG&ietbxd|JUPooagSp>*6x?syH{fxSn)XXa1iJxWQ1O#MA6npoAX7=l z?3+UEOyd=Oh>G%}P)eR&~h{%zE8VQv>*Q}7zw6X%o5@9ixB}}EXYik zlRDMxn7sMY_Q*q!DNeDt^OLyKyGZ$^u!$gd9iLRS;wc&4{8K^{3~t6HM)$v2pOTE3 zg<8t#I0Xwx_e);bbBoPM2UV_gTh`Bkgl^llLD-iD)iA8=102im@1j)ehFZz zHd`K0ewgT-a9&e+|BzCgJlbGN(QG3#_JX<<(1_~KF3+4Ebq?K%^e|vP*1AG7mi^D% z>g7u2GI*`+);U9&4=0pdKLG#3+msMaY|J*e|NcR`&Z$me$fh-?iJ)1Vh=Awkrf8O< zJ5(M)*GAN~pH9k|8&U&#q&M99EKTsrnn33vIf4{NWFiZ$r@7>V9NrNA*_rLs?o&=1 zXjkyb7BA$H^fjT5vN!avm;y#=6aiBa#sV_Xte=8D%-zaU&N+!TXB452IF{Z@?h5cM zsxr_B4%a1>(*uf^=7p%JW{xwmj0168m&#%b)xp2Rp~y5II`>;Bo7S%akjT8klsOmb zw-e8)UAS5k#TvR{{d#1{o3gu4A_7?=*wdp_bI!>QX4~V}-``}J{p^D|lnIH`H|1{^ zg`({H-O_35_d5FlgaTt5u9a@Z5`jxYem=Efp5q>O$N`_+dj8j)J#%*wh1`2H{+btY zM}A1R=7w%)q&)R8Y*lMidpamD@Yal8+QvWH`ys^bkrez8wz$d16 zz_^Kcs_r;~sM{BWXiz^@{R8S8V&UYw0tK3Wo6MM2`t34fT5uNr&#Z)rh9CnVMkZ>S z>c2&vM!rT~G)`Z#nl;q4uURYK$D4=@#p;r9woYTGr3}fjoT=m_f`CJx3ro7s_=rp3 z1pi>ur1vbM%)5>hee@p?^uj$2LD_GbT3VU6I?GP<>+18RSZ;Z;{F|x{N0` zjAi54ipX7@4quf=l8NpMtzira>FJg9lob{OnRxQ&B$Exn6Uln-0p31m?i7Y80a^iw z1wUp+!!n?18 zgcqe7d#qZjbF$CguOuCVsVXJ+`#7hDFN`YP`KbJ7}NGE|AC+q`2Vc~`KA9rsCWjt0u%=LUpSCo`VZvi!1wO)vZ(I*?!bkE!Y!qVE67f&9{cAU{EU{wvT2nIpKGTQK~uK_BENsLy`|`XE0+ zef}%Z2XUPr^+AmWKL2yj2k!s8sLy`|`XE0+ef}%Z2bnu$c}_48{2zlp2-MoNPcubo zPeXnFE6@k|3F`A-fj-FWiKuhk&;K0sp>%D~4qztg^Iw5J$b5q#=cK6rOV9_I)nhg% zC;tyXpV|A*HjVoHSD+7cP0ow@{H>P%AAvr|Pf(x#3iO%Ee`pxrH0twTfj-DjP@n$_ z^g%FlTn-KO`L95qsr{de`uzU|eV)X9z7#91`l82J&OaPxx(-u1N>R6m{{CkDf5gaz zJ9V=;QbkMJ1aRN_B?EMGuCPGiQbi&DY2Fi7@K4~YhBfQ8_5nO-mQJE5Ao`)KUw|Tv zpAX85@sSsxFKG**!)V}Ub8o-o7k~P-zqwN6rvSS1-cux*(DVtIHQK!%#rkOg`{;rd!hU^whNf%H~q)J|7YSV3}HXZ%%30P7CPwJ6pTjr-iKvx2_<| z4f)ASFw*R(41Jp2oQGa6ZS_3*_VSMETF23bNM(cVgyBz~)SmqP8lANL8AIp!Onv@| zQCX^%K|PaDNmNEd`JneN>tEpW{N{tSOJO~2L-3z~qxlW6_eQ|f?roUbJ=*>Mjmn<^ zROOW0IE;1yO?`fHC+0x)Kl?7rYUJ0#6p1zgOxg!GY4UsA_~k2|kJi!gUnqToah9Ln zKy?3#{{|_(OTlujz>YT9E@KxRDi*@`)TPCzr>8@M!CmuWpq{KpY13g5%$d>Rs^I%X zrVWG3avxPIo55`6g*I6TFmvu=4OZVnVnl;$ z#coa&71DRGo?}XM89M&f;-_VluW+~fHVI3O<$4^dl_bjA3pjjM<|iShObp8VMjfG3 zzJxiQzcu4Q_rW-~$bnedgXAyol>B#*yH*!OX_2|s7yUa?AGy5!` z^v`8}y*8vV5m7YrQSfN6E!Klk0tXvyZ<8ZD)`(|>*B~s5Ox|;| z?k%PbB+X#a&=>38w?A_T4w2mB;x5(Awr3gk!0M2d)ZUKGtl2mGqd3thjPR>rI6FUXLnMy173oF57}Q4kZOAA((e5kgkV1% zyXO<%3g870+U(HmIRB+$rVP!td9rXjrC98rCf1s zVYBt@zaS2S@bUIK{176!DGW$&JiG5ve|jWH_ebhvH!ruWuf85`r6HN2yedQ#Q*&3jCR#_txu80n6Eo$-v%IkRjnkE ze3_}<1Op3ux{Scy5?FC$L_|bjZ*P9(85l!UEfB2~Y5R7#ySjM-HebU*n% z;)d9Q64}?_db}@bZXS`HW9GHGFTd zZAu|z_`^u5BT963L5X**pi?f>hEH5{7_ZauQe3e86Jff~`!Dk6J2_`Kb@;XYq~i6u z7Gjpo@{ZFf?5@lWGO)&cnYk~=v?#*loRqSiJw!ylPHM1NDC5PN&{&6v-U4H2P0)!< zJ{Wl>qq{m@H`B(%!HC4!n{BpT(nu=D?&b989HYO;;JW&)^oK;ttU~F~r=6xg)4}j# z??%=cQ;W?u_IGxcA57X+QFjGrT+QF`iB}qNtGlesZxle8bkgnaOGuXCjysc?nw8~1 z4m*3HTYs=abeITjlITE~=%Otb$R(D&&+B6SX zFSoF^oFP?Ez2r2wIu&45s)gVPR+2YW{wu;PF9M9f!6Aoq+}uM(Gb_O z#@#KtV_ydA(z+7|uZ;&R%i_gSMu$Qdpikt0XU})3t0N9O#Y}LEVCyU~U*|YIl#oBd zz8psWP(@4i-k?HCNilCZGAL5@#SwX)G1IOyLS01CD>pZ!7+1qkODCJ{lenBJ)pB#z zwBm94Gfm_Hzu1ZViYBSbPtTAjL$s?9?Sl#~+;Cc;3E|6J2DYl44cMq{( zbY}ZsR1^333V7d?5`-#>3oKv}OQTKKM_E&LoCvEJ=S!)^ig2R$sEOkH^X;6A_w--BRPK8E3WqFZyi~rA?Lhp5 zZi7Gy7d)q>-&jSTtkg~<2fDEA!Qd(B?^OPK)gP5`Ii(%)oTZm!D+IOp8@jYZd1%CG zsOnpF@YRWe@qHtV8GDck1zm@48+4_x-xIbO?czWXn{MA5P1x%!d#Epe__Ug)E!&e- zyHzN)xK52pYnx?IowXN}bB659O#27PerBnHe*+7MVSXZw=yp-{@)olr65tSFc$uq* z4Q@d0|1tL7VNIUx8?e?^Y!&HS2Pz7+YEcnT5yKAFDvAnDknIL!M7FFvTB}qMP!S?B zq9URqP+4InwaVUG2qZ!X0V0WzgpmDR51`fl-uL@H4*uzJSiPTnT-SM?*Xl9J+C?(t ztkMWa_%*5Yn#Zlx$KOj_lj?1VLpY-rarg{HE^99m7tn;8{;`pWGmd z|7QY!r=7kx{?cZBo?b=Bwe;=AFNKXvNJt1(_u8N+#AsX;z(SN5K3a;QOh$;4t52oR z*5SM|PE!4uXl^f0e8d{syauhT{Mf`dqqv$>y4>W#xf9;r-cwD?5UT6NSx-Yht!HLA z=uE=5eK30Ee|9e)^|djzn%@Mk1D5o5sGTChHCFp1eMsh+zb0j+O74mhpjjHFEulkZO@BGFsBjb=e z=}MTs?^N=9dk}uGE+Jep;RPUae{zU(%)mdRo4V`k@Q!`oHBCQUSemt@MbXRQg{-f| za;lGe#`JlFbIaliVj@b69qhki9UN~zzwZ%ANLBRDhgXwT+n~h3j`M}EE>N|3y%Fsa<#8Q|HIEuH~ zGJVR^kKxFXBi&D1cRs5zHLEWf8VrUnqtdnAv$uKDis0Dk!z@_j+^x>71+_YWPmZkN~j!#caTzj?{ z!4E~5>ktyBs}3C<^K`y)8p1-+=Rw669`TbLRrh4~AyMx_$oHLT%JV6mvvUxbWupo2 zW|xoiD*)uby^<=+ArlZCxl}?7WT4m-HVu3XGy;L5F-_#>pPj|)iv@e0K4Rd- zuGnzdvvio#G&m=l%&*6-4GE1gk;&l0LPoE{)YYaOSvoS|n#nB_cJLYz9*-ExpHEq3 z5M;$uC5w;QwOjh1yjgnt)hkz$cXL7B@+Cckf?HE<2#zH)ZDxm@KYt#Ypg<%2iCo%O zQ_puw)j&@S6}+ZXPJ@g$eUZ6n%LI-?C*g>87o0D9Hnp^zGCL9Foc@$MHFhabZ?xju zGHLG82du$CD7=T^jFFW0^zp%D1@+R0tMgx1KOW4+3fhK=GXCJG3LH}f7C#8a@NDgV zqcRVqc4zoyog&`Ed|eaSyDJvNU~x}%?7Gec1hh%-Bcv{+U+ zyrkjj)(WLba39|*E|%@%?AdB;Tmq>wd3kGdi}!OoJhNe*kMqCMpwZd^eQp@Ilh3lg z5Z?3qtlN7AnjY>{!+38qZXk`nJslGcz5kybeSTvMO}-6C{5XNhX`hylXl~xUR6m~(T%!gx>O-t=_@$~lYO+qm=nN4v+Hz+~af zKAhhkTU0;ks|LrWj!3}VRt92Snf?!^8n>m?=g%@VGcz+ZG}O~Oz2w2!Q>4a;SqDGO zD?^WJrkWGdub1-Z+ItR22*7h}HfF|__`s`;u@?ejO) z$*3`#YQ67<%(jn)TFyt@hnTN?SK|D7lv10MReG{B0Ii9?679QXPu({TODricd93Qo zQJMR~2Od}Q&GPSJwAg+DoPoW{ySB%=OBt@t$jAoBv`q4u8Afj&Ik@8p?%PynQclm z4r*}Jg=~962KCE!b)!}`>rj3T%nq9Jb$o?3|6OU8F-zOVh;yArgU_L~u=*IJDU(LI zDE9w3xg*1jlw{yTAR-wTts4Qd6VH2=*80qF(#%wJm@K>(_yI)V<8$bVKTy)rFLgvH z7s$_eX#@1-By+kiP9$|)&$XeH-?Hyqs>nu)SG+u32@b_uW5L{d>|3bmXko2`*E9p0 z^E`TUW+707n)=O9xW?`mkYvU5i4pQqBOGU@LX>wAO@rwbIK13XThnR}a2pqCMJKM+ zXo~Kp4T<$IMHlFg(`@@; zPnB7MFGU}yT|joB^ygz#t_}MXI4m@T~k>8C#*@ znvUzS{=8W*7I+&>1N&wOh77?Ni$YOhWoU@HqD2)&hG3D}xrnG1#on=2iHMe`#w5R0 ze!^V7He)>9^cu)&f7c_7^&)nnaZt^roT%kX-jWc2i{OpuNoeIAFok1IgD^KXR~5A` zutV*aJG!8RZ^@TD678K@yz0vVevJJzuv7*2aCttAik%S)ld%Z-OsLb6iLdxx6&MsQ z^}=u{C&Wt2$JgN;=-(@a`;B_T-n9ogL*sp!OA3$j{dL+iT+Q zaJ$D3@-Ex1%PZ()#SNsAqCM8X==tO+jcP}2FF_NTmaq6g8v`HAm$|}w7+Lw{F-!+r zim4}|DCwW9PJ>$t5m8apbxOxkAZmMd5i6p=ZN4|B$b7roo@0H-Pc)pXS-0y zASOVUeOvz?$(75%EdE@JEszv}GfcV2WU@#&OzNW;I-Y$s8?WC?4ITf`*LS96|9l2X zCS~=_SEZqsjxr|LZ{)=sFGZasz?ha_Gx;G?sB7SP3Jg(j-MSo>Zh}sBMSrI351IrSwY=SBmM*M3MxyKzSq!($qh;G=OAy=#6N}Fjk zZ*Tj@jIXck@Jsz=c6Uu}nDdUTjnF-PYT{m=hdTlrKl;rO0A?uRe))2Xwt213i=jf{ zH^nKv#mt(?$rC2>Ays^6OrK?OC8wwhe&34N#-jzf7TqK$JV6%*K{3k8Fx&CU(V9xQVT10f2gjQDE(99Vx;Jc zK!GIs*~tXwZK=P#x>(9>S=Z|MMY}}S{hr2|7 z$+WyQ%n*4ZQIWI>XR0Vopq&p}&O`Ma&yLB;#vb35U1S)w_fbSas@jVirn_2Ss{9gs zLAB!3r_|M7W|@0eK`*7Sk+x@*>Y>ohE&D-PnG=b0*N}YGF)sGVr9i{XH`QJVFx)1Q zfgf*rmD*_HmE}^@qB<0UN+a;FoF_+YnbDi7kJm{ZPD(B!g~o~1ds6nM*Ylr@p-*j~ z@Ad2IfvR^8ObI6`@CZk@gaMG$UQU5UTUNY;d~>uxm$)9Cb@qiR`xK+;YFodNLVfsu zCweoUoBVKH3jR?fqbtI5$HQVJ9HfK`-V+T7X#BZ5`$${3)$DF&-Vd52ttAgg>favo z@3Af&&uQOM9U=KI>8a`+OcS95h^j zqTI+v%x#r{8E`_e$bbaV6&OsvaeSs8J5U>L!zc`kIJQzqln+_x;u-A0kmjm)?}88^+4JYqS*pl3kXhbx zSXQOuNzxGio-Tl&TjSgoAySUK77x_T2uGg>8^xV;dP(=4nror@f ztwM{R8Cfu?Mc#I#Udh?XUDAq`pfGoR?S-xGPcYH3H_K6EDaf8c`&FY)cSQel>o?`g z|BLmb@nBpz5EH1U-UkI>Iv?#_jR|LIs9Dl}^28ekd>{VjWF6N~<4~{~)xfvEOER{d z>i+NvgTj~o#rOiop_TJT+fbE!x@SM~MbrLijAjP~iz|bS>pz)R^if?IySR%14ADNg zG~HsiF$lapF7Bbz&Agsd{?ASPl=N`#K-8o0l2uR@_+N_>AwzHKAI&;?i3WJE+y`Lp zT0>bbkqln2PVjg8gCMWqAvor*i1?67pEHcpB~$uAuW$eFaU>vHa52GpGV#?@gL%Qm zJkR|aF#bQx%{Y2f@Zzt5YDAk$q&N)k{Px83$qRy(VY--s83xH&wc6@zC3vxmo+ zLMO`rG)z?DC`-7*&DagASked$b*iifRrG=N*G?LApmA&DpJ4Hqy&OKhNU$AozN6+uldws6k#+o(MSUZ}NyFh8Wt}eIrSd?OFeftkPaw`;YUO z#xhfJEhz3Y4m3dXCq9cTeUa)h4Fq6xn_+aEx{x{mx=yR#;3MR{guyup|lYQb7__wDAfZY8n}) zrZLEHBr0fLw{?!E0wn-~V93K|h@e&$nX(EUyJqI+n*1vx3!O^)Z$WaV#oH&S0jP|m zg@sG_0W6POzytUPAy`zSF%u;^Ci}k*?PEFIYft3-;yC)~!T;IcWa?uA)4t+&ta-RG zy5y4|9~jXAMt!`KzvjE1bwJj$<^)wHJw&hf)X$$*2Gf1d0Pz2hK}eWZg}aM4g7f>v zP037i0FA&xF|`#`IkW%3|2SHQofQjA}a{khXnD76ew;_)aqKqnUWu;||@pOy^?N2p5MJ}i%hWKZ8O)})bh_Fbv zqDaH3tzv{8j1-T~M|=;(BV(u1X&da&9)Zkw5tc@k$4od+a)o(>ft(lBY?vlR2p}k~ zxYlP}S1>gEmsS3R9j@D7r|r;6(2x7p>6?!me@V^Y=%s?<64QeEKRaB2YUnjNvJXyl zFK*9*iF3`ym{zYBPI_0KAGr1A@40hVY-=nq9Qu#=Ycg&sS@wQuf8#W9*qCQ4y+++72IxadQtII2!0xdQOH0235PCvE533@h(c5JMmn-CiI-0|R6;M+>#aku8qWPi!7986<)%iHmRZ_P zH}$>~wY44XsO^dC?RAP-Wa*8$<#4}smT7+!=*o?Pv5h65ab^2CIm18(vSYnyqDfy=|roMUtNMYaXS2HdWYIWxzS zyg7aLik*bSbI!7cR}@KTBbk&ZdZ~H7TC}n%st10rr63=gWsPzkR~CuIwlvy}Nt{b1 z?euxmubWaImAZlSCpJuZVCAN#w3FeK0%ZZh3&1 z;vTLvG`nt*FS@g9NLvk+o0etWJMG+2GFvgo6@c$su;UM z+%H!NN|6%r%dqFyh3}hgKn#2T*N@7NW+TOipDh@)KUzRD_b!*7oWpO`ipy}AL(39u zba8fW2q88mCEUMnWMFWC1{k&Dwe$n6aa)PoC3QQW+j5*e#yrS}R(%!y+Nw+zx}-<< zPP}Y;AwhQ}iiN{Yc2PX^aJhoH)2lwzpwPg1BC_O|q03WQtWyYKS@Di-=0uPq>+~Nl zE)r}An!^{_V)k`J+^%tTbA60VbQ!I%sLHez(VDM}cmz$Y;41mRoV8#|b z1w{3PBvK|D%wQEa?m5YS*~XkujOxmH*@|){jb0oUS6vOu9NjjkU?F2N633)UR)<9C zel%{gHZPlV{!)XJmgQ~gk36?a4a{fFjUcM@%1re1{Or;xm<2BSN=J6_?U@mM(5j+{xkGRH8x# zt#&D5QdixARrRhjkGm^u94X}eU1JfVStt7-_~Fw&%C^I!Hk?>-7`;@cbsF2vvAjL7 zPg@!;@RE~PVa)g4FWGd9`lH{92NsTwak^czw9ht#-k3QI%OMM&dHuTY5cP_`QV!_HMvYo=d!S$&Wh{zDK^3}GIuv<8bX4r~pd zX|)Z@GFR}+W{cl<{+J9h;ibe z&V1PVDH9kuW-mVwId{k}+cUt2_VFfTe2q_9&Dl1$POs)jZExd!oPyn8Z6;}?*d`Gl zhLKCguB5AnZW_0hzk8OJVVheSvV}bTB*D+7su?Q=93*2r+kVp{QvFZ+CO-3h(4{P! z3?$ik=TBS@jv&JQ9JV z@y5FE;_DZR^@FZkK5nDA2ADN5R24Wm?)-^h#`L~qrWiR_E#CYt%+-~(yB8XD)+b`} z`R6Z~>FdV@m=g{4jE&WTGsIN{d%pA6zU*xX-8kf6_~=6ArZu&MzWkeWpPc$1W@dr4 zX6yTwm8}s<^&~c3GNxc!<8Rg1UYp=e!1si5`pXk4DSwvSHfdFWF%h#?N}|jQSuG%HQwMA ze6puz3;whYjvnfb?MR^@*sI^cUqnNaaE=}Y9_#(tGdu1&JNjD zUOq{2r_Rz|l^itvgx8SN2X)&Q!fQYA#<8WXDrQwP)Az5Co zE1yh_3B=$x^Cnd}^pf-snYb{<^|6<=6kb|67QgqKti|n{oXW&4SgEP0xWccoNLgH- zE#-_j;7kh<7emt~^p$SEE0stP0s2ToZ22nvL-?imrJs--za30oTB^sMU%X9`#@4w* z+l1$rg_xO|CJQzQ>nnD53~i|7SWkN?PNh)4q;L+uYW(a)?HI31@#C!C>3aeG!7%7j z#a|bVuB$!JuZK3QF0yd~MQZIzE(sK7TQ)e*C8A1=@BwLuS~gaZM#qC{wKPSZsv?}Y zA(+@KsS5dJ%sn)B}Z>&*fEfIEwtexkbh@ay zxfvcsl*NXkVBR_F@ph!WJ$fR-v1S0kPhno{v;A}O?izA8OnDBld%>vPTl4cBwFiQi zuSf_@l0lRuBRL~o$9-uXv@l*mjYvoj%{~);Fh?Te(zDvhLQaWX*i#;fGZ8wfGH%UB z0aWs4MK%k$z%>C%H4KGQcyeB0KADt0AJ2(;p8s|AeX-1srZTijzj zV)4(3Y+C$sF)&c8=F@?XzT8wbbU^1Nu32jn4Y6 zc(7$w$}an2iQS_8t@~pSXsFS|ubN%YDgM@Lt*N6*gq(U4`BnIUf$ov6RE=9`J)n__~xhlr6y>)|UU%%u{fJHdnH;k=m*^Mu;0Xu#t z7Bze?i^X8?24BS>FD&Q?x6A=onk5Cp0k6$bL08DrR4L;nS)^rH2i%X-AL1pK;P4L+ zala~M@+wVJ;9b4yvtqlsC*V6En!x3(_#v3+i!mo60l8lSl{C4zvev4{9*6xwynh}Sd zj)Y28e}y_M)+ifyhOO)c?`UcTk<#nsz55i50z9z=cTC({gS{u3&b+HBp#~mCT934xMVBV8>jCW6!`co}zbkxx=O}pr;(s-n` z0PK(v_ZQR?pmvd~3F zJtSPZh>Iv%jzATVlz0sJF~OsWtQVidz;3gZ3{;vj)Ckx$B|9D1PuGg>AWWFs;- z_dX>JDSVl$y5cutzQ15(5#uy!LnR%xy6I&N&qWO+asc>eETr0ma3VrOztf-0#5i|W zA>x79X%Fq-;)gMpJVYStmp~D>XY*5rH7duVNB-dwO*`j+V~WmN{cVxpBhR)c=j3dK zR3uYV)9u^i1&cd39CFTRhmmi;Piz~MR5IJ1f}9a)`ii5!`*@_6Xe<1|S5U5KaLeM#>!G_;xhkfUG6G6# z*EHDDQxk^Y{$Hlgci6u=ysvQqy61RNE#eZgQO;AG#h7hg%u1JixT1m@^t)Vd>AO&f z_w=T%V`V97>!VmY&S7I(6v>Q9?V~y0%oTSy0G&vQTsQ7n_DXa`A|${x420_(FXyL6 zBGML^IdeDzW*@*!Ha-auH++mo1V=-e{6_gxVHPs$O0#h8P_ApE&Bi4zi@sZzz4{wp z_A&Xtg@x}#4GmTteB;@+^Z7jn&&-&RdE7O~hM8yHJ%uj|3YLmsE`-m@(dQb_>RtbC zkN2|UR&)4&@Y;oL=QeIPCx)KQh~%YYVrDcL>bJn0nsHmMx}mq9fB6;QK!vDLe@^RM zH+Lf(oG}r$!M>gqq-dvv$@fuY9T@UhstUH}xKlU)9&$-uoBzrU2_EaCMBq%~UZ{NZ zPZ)Cr1aN)kli1?$d{}+SIe9 zLb~*whP*cOiEO+34YPL((fu-WV`oB7lOY7bgVyP z*%>c^N6On7h&ofEtP3n{PljF$(g&=fRkg_HeNm+9F%dumyUxdtJAiT3yAHW}| zw=3yUZW5ohq#Pbr)xwywBYdU5E~TV?q;syb9z+123zthpoUGNig`cY}skpb$11(3% zJ|-7T)s`){O&>O2*pxXEdXHWj+^UwGoLt|sTLxLJ8t3z|HBPr^7^AohmDe@GX!WBm zB|A|_-X5eq?R^Qij?P<(Y+dm{aCx=YB{N|SjARZ~(8^H9iF3x|hez6}`Q5qgH{x~X zKbOMJJVik{MVg;|*8Ox6AV}O;jEnC$_@a`D!9*8XCS5wjaWX9iYJG9fBmCf)?wLc$ ze%c=iIZ0<+b7_#Da+Cbw{yCrOxe#*~<)^c|JAa?zt}P}j9{2^H=kp-sU#NY2sj6yj z-ottWcNPAtS33s6yR9RC9!wi};{T{-bkqyGSh?v=^rFW0ect-=JxuU9E=9!wV}ezH z?qaja9$n=B>TSUkw`}d4m5e_z?(2WnWstJv8K<)K^= zxj9?<>PQG54sk+0F@bW#HS4!SP!QHcx2c4C-u1T?Q_yFTEEEq3dyqLV6^Ky)&@C(Wi zrwqI#B_?*AR4F$$ceok5-8{Xh_V1yA8PB=~ah&7dGuvKcnbCa`Jyh5W7PO9u_zq{_ z!WnAx5D_yQ5L8hJvk@64VT(h9;HbLkw1yUOR2rQuuc(0ZwiLmBW~oiC(g;Uo&SibIHdCI?HrQn;u$m=N6ECo+C&`7?6zI=BFelYabzw zFDlnAf7t3%!+J@gQmIAas3>LZU5`skWAya(nZFf=`ul{b-6nV*o~MSO3UxSh!{f8! z%d0zQWj=e`TpA8+oSJ{12RDmrp@F{$R}p<@E-)&I94r!@lKtI^v~443;6J>=rYu7) zDDVZe4~!Ty@d!?Kt_}Aht9YmVUXg6^w19RBT!L(Cn#(h{&-Z@^Xj>wWJ-bc+Eql3b za6W!~k00UclOp1J7+7c5*3@ipcx$Is#Zo^30B=3LR{xdQjdMy|@{`sQ&QvM=d;?1td(DR1-)6#X5Ur{obVb)>*Pc$`OU{S%-n z$`TqJqIOQZ(du(85ehhpwGF(J9Pul$hrH=zrzbS4 zJDunCaWCyN2S-|s%~dPy?Cr->eJ@KbNpvGvs#K{_yAQHIAY8yvFMipcp343{_TP82xfJHC`$~$LWU2z{u+h zyfQ+@k$Gz@m~W@d)zx&x5QrIB~((AO9S0_cVQ zxkEMraDxpfw4;o7HEx0vw>wJ6P+Y)SpGC=vkxVJGKr$GqJFw!xI*ipc%km(${?m|P z^WrORmmsArEC}p|*sq^5VP+AG7v!jrq24mSV3lUb69X7Ul#>@E@$*dC zzO5F<-DEnD;t7N@BYpk+moE=xv_ti4VBg>0MA&57wECEMF3Sf1utSh<3{D+}LD`6c zLuG6i1wrwixC@m?Kl(jgJTnMAdNV-W8k|wlYO1s$2=9M!5-cIGikzo9s}Nw9A@I!? z;Z@-IeGx@r-~dbj)q=rHXC~^Bzo#m@hfizBnFr)=`gK0LBv&vG=DN8ML`w6Nk=8pn zZ|`%af3FL9z)-JaFc`+h#&-6d=cTm4l9G}l^`Wi&yKkwS0^@g5(3!MsNjhXQI5xK_ z#|F>ag5~rPen*J*6WAD$hfAo?MYfNHev&E(OPG{U4lrI#D1yLF z;^c|OKu7v=9@Jzg{6oM40`_EJK_j!?PknN_WXj3WO1LBRehmsAcqc_c3tcs;Ic+gB z2=CZR8o#vO$$s(TO!D8Z4Rs9-G`Hix4N+?7oP7U&&5eenBLCsT1FJI|uVu0Qk!}`z zQ~P;+YRnHmYidTcWQ5;=uOd7+K5s2DIA>=%ufwznwdQci*GJ;Ttw3neo2_WoB-XW~ zFdA@%Lh7PmYaskXOZA`nDrCkX9S-!#-7u(>E|Ux6K$6Lvh?vG5si4Vxe3+LWE^|Xe zBg%V$eFsB)qFBwf5QV`VYkHKzM=y6EhZ!2wxj=*p3Jc#-N6)d9!)x3xsr!({S!WZ# zbOh5r#@PgGfu);%+-C*4&v7WRLtT&xhu+x1MlS@qcXjQOrOk9v2MN!`m`P?>>|zcM zCm}aCI+YfJ95qGive=`E-$SJXuUxf;t1`X2BEnIQ(mHJlT=tF)JxXAsyCzmd_Y%QM z?gvi#&~^)46ekSSCZyp`Wk%c(JUi4taI&8F^Py1?6pz-qfQ%HMTxK zdiRQ7`^99F1s%XK>7`OB_A z>v~%on;dVZSs{pY>5`r5Geil1b)!EgE>ou=6jev3k-TP|`=#BK;P2dnJ%NuUksjVd z3Q58NNLPL*mpO9OOtgxm#xC~2=u?(yPL;a3d@;zt6M-}pJ`xiJ$v1Tk(Pyrvg`ZF~J4!R4OfhM>Seh^9gX z79l>qrRVG`5&Xx-UDkVfHiFdHfAk_|2G_oT>pH?OJ&LOD@C)EWmEHx>-6;r>p|XJG z+%@7)+g^`=P1?_tPCWn_KONPIqAQAkH4c=hVebV?=L2cs?>xYs35cSij}zhL0dTuR zLvCSV()~{P_EDwBWTRA)(y$5pis%E7Ku~5n0wQ-y$(9efCL zI+4L4F%0I$1qX|E_jY&N50tGyU~s^1lr0e9z08ENOxo+s_fQMqHJ*sUg;eG|&5HC1 zxd(PSgy4^FEkz+8e5;-wq9-1{m5K2;YS7#el%1ShuTTmDGKLL6^0F%qIi^1)@&LO!iG(_cI6{g7q-ykN zU*uT@TTjGJ8MmvbX`4=GoAqC8TSRFX{=$WKgW7hEj&&{9wlf?HFT848kuQ1t#P{Pv z-PAfudtGDb`av}{wf6JvdWLaqAAg@^OcSrlO-G0;%<=3FZEgw;B{O3 zHM86Q=t3ny}0*te~yEA7f9qUvaB0xC@iYT+0@`-}iDAK8hEI&v- zFA-a(qcnRV+yoHHn`@P@^08_m!LUIIV+r2JS}jfTxB#Bvw7s6m$#5qZ6vWrR({lx1 zgN}4hPtO(Txk4`nU%|86^%hcmp4s0<-BX{Fw3(Qg*h(mFQ2Oy}xKQB)T7!~~9+Rc` z(8HLr>1s!xg?R;cWuTT)NDJ=_HiFpAWJMjrWfH`If)&K6QyKl8u>NnbmH!r84ucv| zF+M&Hfj%fK#hF;{ZFLmPp*CK<`V9sLwaSEN)}rhE)RWh&DwoelEkW820=?vqO3SaD zrHwF+kB`r??>Mi2)qZfKY{hOpjWJ2H_+DdOUDAb>hI=_XA7iMF-Zf552ygU>QH}nt zvVBIB8DtN_ZPRWrK$aa5s|U?~HOpL`X+6LDX6r`C^yu#CxyfT|4a|se5Pp5`>%QY5Z#6 zvGdl5+sfrvQA;s~9SnM2H~B1!H(a5OD;fHhx9Dt<54{A4$JTqF3p1^aZ5g6J%gRQ( zpkVYC;dPVJhS_@wqfJV>3&9{5FS6N2SM0<;C|G(}1$+mHi&a5KaXJAf_v<9fBw~hwhb}8~L zPmGSTtoD)qYUk|CX_xc$Ka1_!f+|Hv8rz10ard(`GlM5aO7tUFbl>!Y;i6b9SMxsE z6@2df4lqQ{Fpe`U%tXu7@0_Qnr?+>OfgA=is<&6w=-c-gIv1%&0UM3#>axSGU13M3 z0CZM=^Jvu(0bm9(dE&X7ZEH&RgU6|z`D8MFxFzjH*4U%F89DA{KX@S|c}4u_&6NIj zs0Qur?R}BOdH2pd6vUT4%hn8UF=q9;n8e6kn!VHjyL@}W^P$3B;VXBVrd?b>N~_L6renvu@7yDicE z+W(J{e3f0{3Bl{1zen7h%O|@+l1Xt55&dDc$sN_zd+W6{y;XIBX{O00h0)GotPrE? z^S9xPiCY}*zUOiwL0hfGU<;YOE;?{bFmg1c#K_X>Ms`C+zpW}mHT^Q#`gGE}kZ{%X z*8LXkbc-U{Z8X5+Mx0K~nQ})C;U^405K8A2l&qG@%R)hLg>WJmC{RR-Hr-vWxoZl@ zK;kL@dBTtqxSk`oUA1=ww4V=vzWwg*?x_uZN6R90er>%YX*|5j%hsr#VODr&S3qU- zk&O17^mgvUP|xrJ+UC3e6UE;Uy?S-omHXz+uUSgA_oHJcevOWb8g`(%?0Xq>kS^#t z{Y{9scbM>?m9;ehZltiH=iU0}{wf}aycMada;JQ_^?32Aux3fzh%6vWwY7Y8II((f zXimQ7mJ^3w67uSNv^p?pJ06*F9wn1&(>gjjOimc#i+M&VsydDzI{Q<)9m6+{+qC|S z-@Q1-FJbijwSgZZeWXJ`4hJwen*Y$7yM&~ON2|23*_$R#R%VP+u0Jwsu)S^V0UTs6 zr&J3m#8ev$<9EM3UodnpUGV6@at@yU^hezT5BPU+LbthD;(K)XFL$Hh)BOh{Op z9&3--=>(-IV3Vk_pzMC*z*M{l%CdF#%+o;L@bc!5z+BX#5SE^vUXh8I`Y3I~K!u8F zH5ju}r|TSyhhBqRj_2F&9gtD24TJy5L=ugZ#G?TU5zo8agwt-cWy^m|qgUH%&^H{3 zp;;J`{rrSGIx*vK-@b)rkAXo!YhwDL1B`!|&|tS3nvwxO1SCG5f9|lxdmQyAO-;>I zNeAg#K)5Hyi@;|aJ&iO8QglZ<+xkbPnNw=sVZB+zp;%>%uvQ1k28ud6byN`A74cAV-XoQB{eS?fO?+%a8@6EG4mZx`!-W(V}%YQEP%AVV9VePkH`#PYMfbQR4pJts* zr|Z6wa81b9x7iO2V-B@ROpI(VlPAI=C5N@H|2DxgeG*%c@zrR0bd0c)cfgS=yMB=G zxQdjTx`uiG_bqoTu7{X*M(k_x;pabXQE^YI(%`tQ=}cJF&K{RnHl$lP6z$v_6S#C8 zy?mGzJE_w!YCW`#MTqKG+J+Pc=j}X}(SE8-<340;MK3yVC{x}jb}ZwsjTyZ`j!xO= zZchP69EeT#YCXU{`zu79r{o&DC$sG>Q-lZWVBUC6up?Kw9fO-Nce3Z=VqXrBbGJlm z)Pz&gz5a0L80VfZaZi~z_@s;?aK#R|x~ud$B%}p|aG(IU4XHfX-JU13f26iGlRFeJ z97-|!YdK}#z{t+T9_!93yQ8cSoE3n>7RTBlIe*a_>_nm67U7W=_12?&`N*Gd8vfXr z?O4}X>tx=XC2;2WgU|uiu2NKV6g;dDouNCXevoJ={ zUd2Qv>mlj5v#+zE%I$O|yPt&KlZor=msqZRR8_W7$6%s#U#q&<;AeN|B<({QbY1y| zcgy`kTm6yS9x6^r2)n$kb1Ye17(B`k*rn+m)|oDNW>ZAW!u;h~wtC{%O3lcTQ%M(H z4uob?HAqKwgt`3Zi5-<&dU|{7AI&XWBz{U)wTwdHN(U+_`yn|* zTz_Ow?P=`hyF}7dAbKFs5+uV(Yn~q=dG{Js2YQ|Oxb2^l z;DdE43l~1p?dl)Qc~mpBuGcNlg*9ZyPc0v-50)&vQ+unq16Se|&^$jllW(n8&y-$BYW@hFtn!FHFgxxu=OG5V^D4Ksini0{G z!gwnh9UVOt&fgDr(U%$}8P9t00ydk~zm^)H=gl#DwdIeIR+ELl{lH?fPO4B`?hj@* zl)Rp-_82yB-*MkT!pnL*92iOW861O_JcAaDgX@Li8YSh|i_9AAOTS~;7t}BoY&T8u z$zw=&zs{pX`U(1eC)n?tw|=J#`={iGL+kyNH|+8@t%kf{$cUZFBaWdx$y3%E0iBM2 zD;|PkK6>3xOfTHYP|-jOc?Vj6wwIBdz4nL(AQ5hN#h0y<1Ald4!N+6 z_lbIXlGwVAh3^Q_Jxa^x;AO>x=RHc6KRLO$#Ed~QZrl*#7TF4Jlm%4q25!l|AH67; zlj!E_+d^2{t8{Vq(JXJ}izOWyCh{P8-l4sY*j}-M+}YV2e|KVI(I&pGE=`FP2b$~F zvU{oVDDgk1il*72Pz-Qrc`$c99acbS>s8X8@8lG<@aQv}3=a&{W5{26k{N2D@;tj266MaIo@`W-U}VZo9&FBCR(5UdKrcB$-yyqI z7)g92oE@Hv+xCXO>@gzPf|tn9r1?k1PpDB3Z!p%6?bHl*>UZS+Ft%dX&iw2k&MDI^ zgvu0{3;sB`>7n1{=-o?K1@+vIUSlbJVX$ziV2h`Y@VSPi3$D#WGg9y{-1+_818fG9 zc%g($&o$_j6xp^uV~XDrH;tZAuZRxVlHFqR^IK?ftWW1})jmtU?kiZBPt2?cx*Vtr zhN0vo6%PG}Z`{>SzI5(yhDLpxES+s%I%hYir15&}nLf_^o=wj^im`VFLp&@gkyL(k z(Eb00%i@zzeq}aWv?#KK;CN`>k4VhiCr}T6N>)>ILnG5B!|rH$&1i)pT(`OU=t_DO z^auH0YN=68r0E|J@V0`!wzW4QvN|X}rF$+rWPRpwy1(>YL^0lJweKn|Mbz){AcTKk zgkeGQUrg_WgUf(U?A!Ld^a7brtPN5`JobKFK)CgK>l}^a|)J1&g)Z*@4B!0qB!Y($wn@r9+I^a{d%^q&7LD1Q4=8-&Tu!VhW zx|g?1(;Hj_bWKRqua~{B5te9A$SrR&BJzf-7&zNgtaT%~f@?OxWApB@8M>}kWGBVN zapd5;^hy)!B_)?@8(*i?W$*`{6p_6HXsg8Erv+cw5yWzG!Ss6nPTmq|uPb+1Y*D|St($MMr7{3wg?eiK0SosFt1 zFyTo_Nt-$7iPnUs0j!AruE@+hkZ; z(pZHDtj{c<<;nZj*H_^DkPiFI0>~=}ZdI=j>D!54Kl&~ zyA}6Nu$*e2@U&BwU|OQZr&*Z`?eDXVt1ONmT@)PNrbg)%IqH~oA83qR%+{_?ooz2U z_{6Mz+ed6+h&*ILZbWlMUQW*87cuh8N3s0PX;s?w|B_K|ON{+PLX1XtID*aP9-#k( z8A)|G`i+`eOpmQEnBa#xBdMBiqhcC_LSZXTT6N6jed+#6!qC08c@P$D$akWv8ji+! zcBd|9Og_vbr*@{jUe|1(6A^(#K#;4YHKQF8N7EROOSP5nWMZCfP{z48_OrM{67+JReS+j5D>nE^-?Pm`4LZ1_!KWmr3hzo6ncqbPW$zHzAntNT= z{O!17fC|5wq$Z4-__HXOv-NuNUY@@SwefZIU>xu656M9>-_w76#6y^(b9UX!EU3O& z2iCW3sS^ZR>`-Mn2@bFv>KvL^J2^P`Wic4RS~Lw7Ez7T6@?rxefNj$jX`RQ;Z|fY+ zIO6N?|JX-;p*?Xee!Z#gU}|Q<_l(E%a&;HR#SfD@fhp0anNyiDpaQB(EibH* z9uONoA{i_0&39UQllN_dAXq=>k76}e8&mv&tLmI%mPAk-hR|9YK@}@|PlA9Cq?my$ zbT!P&YxHDnGe3{KzC&Z>%3t-4Jh#s*COu+e1=wd@<%%w7$rfd1L;Kipoma)+-~mD@nHon>VlMKWn+| z@9nE9RfY{fKJqzN9&so~u+)@ZKIV{oHfUrhGR3n~7`0t7`x4I|Y4LuyP1jH*|NW3; zU4@F}qfSHNfyKPFkYXo;C|(kxWU94Fu@;DBt7wpG5EVDOOn}^Ee~b4J!Q>|?{VSf+y*0ks*;$-cwezTjs%2pSjL zK!l%FAYsR$howD?nggF#b#pO1eO*5`R4=NNo+5_<=IQ ze4F~>^l`Fltt30>p^YFTBO^98R^4!DkNT=rOW6C=;h2o>srUHzJaVqIxE`24Y)~$K zusm*JX<|jQoXh2^vJ<0;?9}!R6B{7Q$xDpjsl$QcJ&v)v0*2*pc2qGBpHnX;r*a9) zue|kan7`oTWm788=^atZy;U# zQ#${G@*h_`(2A=$k!1)bd%$L@2&n9EQL+BJ(QZv+;W1}F*EpU)AlPJjS)JqR!b4-+ z?~z9{;LA�Ht=7g90^OGye-04nA={+qG!>_Jt}c)XtJk-KMQRhnapVZ(}6C#v@MM z#kKsq+i=I|?pc|kVS9O2m4@4eKLgV}nkXF_8XBmySmTMqu?^64+=}7qz*-jVU_$V5 zymNkytk`m5zeV`UudCZTg=v)t%hXpTWnv}iS&)wfODo*+B@Nu4bj+Y7hG9O#YwjpF z`Mxi$?@$xpXFKRh7WDotm4?}LH#JW_8UWp-RiKFcIdY_Und=!IFe?au2m)03AXe@ZKvP&f9K3OGv~}q4@utld9M4~?%(wV&``nFuzGTKqB}f%{mljx zS?PXvQ=M~#*=^S}rc(s(1V-jGtTX>(``j;iKmW=3{2wLje;2Yg93q1E#%vC5Bk>JY zgFDDY+VVdVKa775m=ma9UvQE_;=P9pmm z@8#v??X705)K0uWX~!iqdStFmU#N$F*Ke4?@3xz%M+}#_4b?4(H;}~5Yt&HB9*-05 zfqg61G{4HFQvqzF%Eq=nsgdc9ruWCF3A7i|kKn@X5l`|vLHe3)a3I#2o2GV{Ga_!K zcTjfNW=5KqU~6N;zpI{M5Bj!|x&hOEWm2kUja;67^HT1^1-SwSze|ueeE2OIEdZs{ z#jo35EjaES+Gqf=Jqm~}(v@0B$Nf}!W%m0A^a$ft_dsF`=XM$b<-21~?37Df z4(eS%%aLzOafa2)ucW$aa3^Ek;Z;e)HXT&~Yk4eoO#37tx_68h8-=g2*YD)yn)Sv_k|TyM)pOVkrEn(Ic4mf#1pZCDEDYUkG zT~d4yd~)!KV0BMa10w%v7CJb^E(*Ygn=*g7cetIB1=!!Eul2yI*ROBlHu5f4E{=OJ z1_n}9JEywRw*!J+`{2Cnw=uodS?TF>MY+`AgXE5&w2TDi0#Bi0bn1FALapgX<{8XA zUk#%>_*O5CWtwL2BZ|BroIROy{7`7$iF;_3x1f^_?9Y4=E8}Xi3cbZ1K zWyL?jwf0FCsOTra&SxA~{DNwrRueQl{}}Ih%jnmt5`sc zkB_+=;O(8~AiXh4`i;G2_s6vn*!6m(jzrU$Qg2B0pll#@NgZ z555#UuiE_;i^+#O-vQmFFwSS&8XOikV6{sFe3a{b{=Y@ilAPutpx{e6eo{^dg>#|S4Q zZ_rClpFaIX&7Jrx?M-~RKFHpRTASo~oA(6u&1Q*`KcmD^P=Foed=07yeBJ{0S z_&>PZrQ9o{v-mALry(;UH!uHNQ6p)!tx+LtJK6{u)9@EDra5TBYoPaZ0Ud;z_0>kA z)39*}(=x#BMT%-b#$bEB>2a%lh?~g|Unz|7CERLSrKNN7K%xf)CCr^Lij^oLV7(1cf-!sZyW8&EW0)zf5+S&2f2q=E`i=GO3bn9MC zA%4P!5P2HHqjQgK`+{W3x<5=$8$$-cB2;y_yIr_dqm0-))7aqKbR{)5tVKafTN|Eg z{kpok9T7KJUc3qL?WFWmiK<@fGxLyAj#ymxZ1RUH=JJnj{0YCZ)P5=}o=7Y(-c8fX z5FKxFhK|mD;2gZW zll~-STwqsz+2}LV6-x=gjTK7?_HJ2eX@6O|SrQB3e_leDqflTh0-H|Cp~04wuoG$B z5)=SfMxzs^Ez^oYto<#=Ch{y>6z|qu{tT`Z+LhD}Vd%Te%(QWuJ^;bn<2yf{lUQuk zJFXCj&3XgQ$j885M4bvoGISoFM;Je8YRXbl_xJ{z#W8GcX6t}m0bltlZP2eCfSOMH z=5V|Dz%@jBrqv>J19y&XDl;%3coCd}g&R=Ulr>2b@<3p@S-dP+1C%JXYRG{C(W#JU+K9eg zrQQsDJe7Z0!pnDU%U^)P^)vJ9kzah4h0_YAXdZv!n{V? zya=p+rFQk;8CAv|xrz)m>~I*VBM7;FMxJEt^;>$=rTe=s&Kknp{PCG- zazc;E{>-Y82CbK z8CNugv(d)Z_7c$)d&6sq`H4-^)Gv9dV6-(u*S*YvIYpb{KS!h53$eXRGv2k)8wpaD(fb6NWU{K$o1<(2IP(X!&^O#X-}w;HE}b>6?zvH(F&A90dX>XjUO4o{V4QLdjL^D7^oYa5 zioS(}diZj<4hqfdg5V$9<5(fgH4_=Ec2pidp-$S4TDx2QStketItiJ_6$fFsscQug z1lC@5lR!&eR-KkM>&?+_L10N=Ij&VFTyKk2X*pAd8o=+9Hk5QvY%rec6xzE8fgQYp zPOqfv#!h9g*LBiSZNg2L$+IH)yAK0ra7fydU=eD=HT|Yo@?lMrXBEPVD1+f$x#d{O z!|r~ifl*#feP!jSB_&y(UD*yLC{!v{?`!OhBugF4dw5gQw}{!M-#p^hafNd1RI$|8 zWjY~v*6Q4LYDu2}rQlvH*d6Z87oMPC6h|?$=A4EY8}7;K;Xtqg>{{^(o%y?0Xl|(` z=lv;A2&CZ410WG>e}RXKC_(-xXlYe(euPejfo@QYpT2_x`peM&1>T@~#fBMqabkeW zNL>R1#fV-VO-;ijeYUa4-fJ^iJXzT_Rsj@vbdRbX&92KezyN#x$wTcHk$K6y`lRSf zr~J6bXCH;%!zcO~#bXpC^euAGo4H6R;Q_n01^ot@nP z5tu&X;YQq`!q~WL@$A@FT3g3dcqlrSG&Y{B61fDNq5EwZg3{#=L5>G`9frIJrza=$ zNN?j7Za@-g{;Rb+6*D%+?}l9U(kojZ(-6r#uav5Ay-gHPva(ydm(VxeaLv*qSPDJj zh|V6Y9PFxj^J6u;Oj{wkmSX0DFuh;pqSXl|fyyn&B(7F`L9VdSHZndfezS}uN7q~R zMyK5K6<>vC}g2WH>kB-@tisilP{2%!P6GBHzLcrR)uNl=_kjicr_k@b0Rg-+}O~ zA*mFHv(jN1h=5zc#|)koe(T{yn5#k%RFstH-*r_bPvTSD6nqBsQvp?A$eS7B<^Zj><7H3|XLt+ygH50aL*EFg(+^wW7X0QYsEr znE+vU2;tx4t_Ii>bF6L)F{fnGB){M+RX)!K2OoAtZAifDSW^ka&2m$Q5NpBtq?5vO zoY2_tDDtIV#lnLb$pyT7Lcwkg#$rr@+Pu2yp|iz(19K+~OuNb-gv@Z)F%*rP=;)=} z>VBhSazelVW^{j#i5~N>hVSE0+cOJ}^Pi8i3Lt_u;W?z~jA#w`fE=kAwfWH-f5I!3 zxWh@mM*^T*K+_Y)sK6oZSNeNw+CbHU!8Mp-W5b1`=zzm;NIHJ{GCj)M+Z#SdSeU+R z&}2xuXR%wf2IGR_N*fSvdBj+vdo-ua1cq|q_irJMlF>DIY+U@|DDfqDXf*o~s;c5M zI96A7-Qpr4V&ag#etwN!TYuV6nE^Kcy1y4;CGV!XMf6Px!_h#u;TJ-^aO6`4CQ@8Vxv6J-0A%i%2BN2+;#q zP9_TsR@-W}2+WNP$qj}Ex`+y)B^5bun7jHmvb@%sWY)0;LHIctJ`bxdRD&|0)i^z1 zH(&5S>u#-aZrQv?9GpS0kQYf#jn~0-(z}W@{U&{s_h)hMpOQ3%zGgDd*|M3tHMiIW**1x2aNR{-ow_DN0K8J0F&shkY zWkhc<#etkkAT$|v$;ZL$Ixp1aQg6rUHdV_DexZfvb$$#M@ zd&|hH!l{_`WsT2DK~mqHFfotBWf3z@ak<_2hvyMD!Q~DTiMFf6{G4*rwXbpOF7k+uutkI})}PQYuzitkE28$87+}iRP&fj{i7L(^ zcC@3;F_Xm5N;oWu_K%2ysvt6Q)z-M2p;>fwzGOG4Q!a9TS#wN&Gyr2kZk(`tgo?BM zM|;!g3Dtnh&6!GVef0(>W7x0W%)ZJy7RYdYC0mSb@O(Th-=s2^zm-tP?!BtQB1Fk+>rEna`i|CXgVdEL?V4$KHi*PE0IjBV>_^ZDV&iMTl9L}e zRM$5s@y!z_{Gl=eMSFIEuMce(i?MVuzy?@AQok3@;=Ph0Tl2!k(J*s`S$L4=aosC+ z#;3B^XhpVy!5<*AM0~G{Qqk8O0f?wIpcm8hOjBDM@JL2{@D&zK`dt-LyQ^ojT<`En zjEwbNRe2m|_QwYk+P_fhQ@EiUPQmY5I8%?8V&T+&NOn$9F?k3QjkU z2xlb8_`Q}+j){S*U;P#8=et2yOfa!rHz~L(*I^=B#}2x*iC>;6rGVR6)49z3EDrt> z$KcuV&O_`4I|#_dL|~alb%@9F)Mn>%PRl}<0&>kO?;^zpUlhz}VT%IX@Ysy73v7T@ zG_Yc8+Dr*IKUY{(?RMEprFB!Ijfcd`FUdfDs&r25OBvZ-!!*oHZ#J1TA!-ej1F`yS zAC&jysAGn@1=CGfG&`f7Q1SyXohFA%NZs~8-D~aj1K}KW3f#`D)?>)rP zSN!~}ge5Jops8A7XA@)thTwMScz@LALMTZ|?vJ?G2htsjzp!wPzrUR_bp87Exo)If zlo=>~RQgm1k#mkV$JBCAXo!t09A3r`D8O9Qf)mig9Eibi3JgB{+1=f}FUQ&4oX+z* zO<{+IAm3CDo{v5#HBVTls6FaYCiyN@6}**C9zJEmPE4DR!LVSB7z!lt?R=ujtOklR z<}dn_<{mm(=;#M5C5J4H?6=1Sn&k@jtI0*CCzUkKfL_UCAM)eJZ+2u9G7SZGsS?*; z2yu=ts%os}f~yyH1PhN{cANc5Bj7Z?FS6>DeW|no^va2dm+NRIr>KkvvkE|FglAsZ zQBaF4Vwmqhf|KSZ!L}gp#C+O!m00%zZOGb~CU7IWq`^udkR~`1#)1d_eU_;}1OCfD zVrAd#`{(HTw`0CeUTG4;uwE$NH%xIH(Cdw%Sj!ky0rN!Kd}iHX?LJmbY+3O&6ZX(x#v=<3cj)zN z^s5j;(gJNVtm+jZ@JjJM(=X7^G4#F9Q5$C$24sdaK;uy{E z5w0VStu^&iZbZXHocjw0=D1$Iu-|XSaxk2~JhH!$o*g9lwm4rUB=4ZKtZS;FR;^u$j4Hbf4 z?#yIHyWZ3(7sPrLP$Dn~f}G(JXmWt}(dj{2YM>J~d7@6CDjIG~xHsX1I`Aj11p4XP zz}RIn|8qQ4j&1K`4&wy+*#@6d4l@D5EYE+r!%rAjD2m&rzQag^y!Xc&Di2I**vlIrFXlq zYFJ&~-=I@YvnFYCXqqLj0vU7?Y;&M!Q88#y7 z`m!QT)$YkL;c~85{Q&P(Fhv)!MvHRBI-GDy^2Ys6D;z;jdVU@naz`c^d(+l=yz|xO zH`N-7X0>hOs*-4 zIIESIDH=oen9!FkcPQc?H%Pw}egEzG*(^8t#Tam&L}&qYxciPJgY>Ahw7QU}sws*a zYxxA^XzgHsCm)C5M6fg1xHepU`zzqH4R=(HIgk^P%1v9pSE&JA|9h3%iLaU z=U8l^D&*U$Dk*i032w7AVuab@1-hu9oV5Ax@=>R_T1HlB^QR4X0--q;d6P+){t6>^ z&?u^Px#x#>zz{}!WS-E`tiX{T?i{+I2~kwvOw|}Bw}QDK;FmD!fivx=TGzu1I!fD+ zR!?{gfz|^-SmyClqpDA%cXeuo`FeT%YD(Ri8bZ&!BG`ErhptD@!P_ws)~s`^hpBVK zgXC}G+svNy>CF;dC0xoUU&;xNzSE%>p9KWLwK)E0yh+!!QZrMwQAmR1C+kuVPwERN zn^AO~v}8ww@@BAM-Eh+@=PclF)%#FUgOz5X1M=jbtUJ?LGG#Cj+rlJN;d^wz}n_I{lfL)tzm`kdH1jc*vVs?GHtr-oZivK6(DT z14R9oZj|FnJ_CnUY94pST_|^=X}B@FD_QCFnjVjiz0a5j z)^CdL5-EmHZg_Kz0$gY*?epO8XFy@uw|_YRwY2^yn1~`i+oehf4yG&kUfu=4Cd{@( zPq#8}qs5GxG6q9{dyu0@-fTqasl-P`xjpbmB_;TCc5g0oX`7mwdbTr_qAj;?*k?5T zHqVlci<&b0ZO0I@)w9!wpAZCj3AjOV0k#B}Rz8eyVM# z$$sD#;m*>VH@{@K0yN=GU&tsiNN@S~_X*?rp$SvHvk@T``XxkJ{A(B8B-A zyG4fOv~5WK6Q$^EU!1tkZR;*#a1t;p$d5;a2SNsmC%F%a?C~xJ)9@)-gKnPCUr>Ke z83-Io7iYglKb7{1#j*|V=%c=F2;;eoUbt|mUEnDdfMN$!~At```50BUhD zQvx1iw!I1a#JG6!UVOpxTRlW~SZ1%q{<8iTa`zP`)5U9aK~Q3z%M|kCY-J5Qm#v-- zZ*WeP14Ba!Ak-zLktP|BAj+V6F5{y}1k_q>LP2B00_Sp*JGm}-B}e(qjF0lI>TyRQ zts@zt8>MDDXnQD4mwfb=PtEwu-T^S2NzB@T{Ws&K_n$JNTehmhI1r(67Xab}sT6`; zr&e@zF60Dm;QW48VELL}@`+%+ofnd=(uP8_Ldq(U%Y=H55On+ewcMe)=(B zfgn5YrS+%ycGv33@QoSp4hD$pDnp#Fs+Jj8BT5)+@#ij_P^CN$YzfV*-~Kq4otw14 zVNo^;%W3a<9xt3S#n5w;C915lZ#kDN`{qP9rm?=BTTmd1Y`psRhfVAG#}&x=3&C3R zgp!NeR!g`2D)tpJOuDmI_XR;VoOaDhf~Ay#+#)degr?6!YkM{-M{Wri_6@4sTpz|u z4W{k%8_3Br%9E!mrI))O;e=_^vgI_y5}P0;c}DtAXGQtT+GLz)881s^a+n}OB4&sL z@8vP0G@?|rQcF8BgxD(c`ml)9;kZ^)>&RQfL*GTgM1Z|pQE7pjbID6iDGtAv^v+_P z`@}%rl|*4!-32bZ9CUDZkkmJ>HChEnIqBlYwfj~9$3!B+fA}1T)45Qr{YBUzNZcW> z=peOjT>IrYcvW{$P5Cb3ors6v*d18_EsFoS0nR^HbT6b_R)p~EDe=nm8Sr;gr8>ZZ z4&FkjIE}C>n1&Cc7hyZ%6B~W3FkKW`Zw^G~e>WImS(f@l?H8a(TpRWopzkl4VlWu7 z!e&*wSW)@Nf=%R6I;B1PXSoboYAPVCzXNPFo%zhqwHfV|qZauzr}0{ruW#R=i?Zd2 z@)qiuP19Kb|D9dBL4?lmM?6=^ZMFu~NZ<+uJNXsc*IJr2%=4N*BOv;)OfCJbBL{ULdq9_wf3KX+m83 z?YEaW7Fy)5hCfNh-xd2y_XQa>8Zs8l%nsU0#PmD=MuKI*{9(c&N|-mV%;k?z-rvpN z2!c9s!+|4hhWQua4^b+;iloK2aP|>1wN4q6ja4Sj$!mlDu^j18YD9S=jFF|CAUn>p zlM0Dx8z=Z0Ccv6C7~+{!1Kz#(lG++QYbE%&ZmPyl?#+c6qbCAO&GfOnfvQ97nlfTZ zK^dU~!#>&2jZje;Yxz7}pGYLaIa$;I!lP=DV=-+VXa-+TQ_<>7Ql0oI<6OdcC*7@-ePo#|bpDu! zB<(u6R)cVSX7cKte9?BTBer+5vbuk^4s6lPh^PCi4msVK$AlVnP0Gs)%U(CDybs8( z^fMr*^?z7|0Gt#@vIzCXRk`%#H0oVRL+?Tbsilp>BZEKLBN?{}Nu9!d*-0-L#pY9- z$P$A!YSeMTcwxzL{+{K}c9)P0zaSG#MrYvP8alZZZaC$v5oub^&3SO8HKRuwJ7`{f z69fFoV1~r*3+@GyJj8;b44GlUywfZmS?J#jZrhZa5mNrsi~?bK;xbtu-bIsI4+*D2 z(^OlufIpdba@LS7oN4N$A1*EUf-9x#V{j^$9d*9y>|7HZ7S?Y{;HSQLy$T!xzyA8e z9hg3A2`(M)zPF^J_TOy6^^{)n9TeLq1h4U#J6<~NEL%?GR3Y7)3Zmug?TV$!dL{N5 zR`geO`@bZ+r=w`~lW^=I7Z+%`eML@>Mh$x)uXYqgu(7dFax7rqy7tG7B{wocW8w)d zov;X(UL7qh^3maBuu{)qIB6jdv`bL+p~BT;Q4tYGSgw0`ANB>aai{gr$V&kRIIGgj zMnlCA@o8<2OlE~g)OFQVJ7mMFWryme4;d@!-m?ov{Y8`E^k+v!NS2n>ArC@Pu zb6H0Rll!R+H38&}1y@B%w&8IAzwlV*I94e3N5J4Mqf1a!Z9VYrj$!NBlkRmPrz~}> zxs{(}l*RKWN~8iGvyTLq5BpMn4vo{}eeTpV74*S?EZ{pt5BlWnLSPRqHgnvyCXn-J z|6Hkff3r9QKUMJU={qjl)ICT(`HMI6bKbg*g)OTt#Z1gd@8cYMHrKDap~m&pvFSFQ+x@5y|ql zlkhp+`xm*y_^bo*L2%E$K8(Qm`cejO1gsbk22gSxt^`AzjwVEnc19E*h91umMI{s( zCvMUn^_d8sJv@)(@%pz0muW=a*XG4l>kn@*T_o%|p)Th&XqCd(@PwPpuQFeZ@OK}D z30nLG59#~~G?>+0ZyDZOwVg`9?p*fmOKd7nawJzzhCi6IaexTizh)0jsNHszG%V1` z_2?5w#%Jnla9zFOo-2Lzq>GF2i~Ox7W>rVdF*{&I<4b@&+%@d86fLPP_Z&Wr_M! za7i6-yb_6|c|*ZN1_OGMR^saJgfafNLd20=VNXceIYi``obUAFUKN-<&lYnTWtX>v zvid^mse!sqS%V=B+BMJgaqdsak+`TQ<~-CuZ?UOw-)?_F3pmPYeoKyWFWHhCJwJy< zKM{GSpK92Qo#NMXKAY@&@{o9a+CAW~tzeUe&B?pi=C`s4_G0DH?70q(Jx2zYO%|LT~g- zU;gx%z6ebmR$QXzatsB#FGNJVKGo1SClvkgsua(Hp~#ZmdUA}j<~v7ZfxJoCKXG%7 zOtu|HQu~a8Vcbgh!=X=CdUFVJyVmz(zSHNzO<%(I#umzQhV$2n4%!G!h-TG^hFXlD z0d&0lz_dL|=-#0(Jq<ofy0OymT*ZviM~35h;{_R6ACfseE>@ z2}nTEk=Q9Cl>(`(+YX;j>t@%Ny_leURYAHk1hpN%hXvgmU)PouITSmnjmfL#+B09j zS*_{oqC;7!JX)Xi%LnsM)c?~_{rlG?FR8v6UX(BD)Ix3`C%3V?t>;QT^39++AZ!Xe zAAc2X?aYV@v!I#Vtb`jsy1Aj3X-JTdc)f%SE|ZW(o0A!w%=ijiLe0(1_*;n8_o!Mm zLoG$@;UU99U8qeu>X2`y_lPNp`qksNg>URDJZybo{(+)2pYgx@-v0rJGUbKvjoXyL zWDM^7A$+<^$yNgb=~Hu#jhmZWZLD13*XX3YR-MZJSi1BPoSQ(9pC_+R;nY^?V zA0o(WS#YR8sgYwtS=iJoG(5+xrup&b!Op*}Q2tRRQCzji^u%f6?ZFTJ58m!enajid z--5Fnixq!MygCA(8O%`5%{irRA94Ud&IA4Q0`W|Y{CBr=xVD{B#m}QBM2eiAy2pg3I3kwT*)}*;+ z*cLQ@G=mH99I^b14~{VT^1$?@EQ@COLo0ORn)X(D=q^JS;K3jV!i<}77$gcBS?Q8* zws2Z4MP$4T64j1m>fGl~=7mPsfke6QdfLtMmj}wOSzE2kS&{}Y6b}!$PG8k#SkD{! zvS@O9h*kAUT`UY~`NDy`_;GTG%kUYfVag;GI^_}1($TrY?`gT5dr+|`zH>Dk^t8G` z?TE#HWZm$cvvH^q89Hl6mC5pf7Omq@&Ish*-+PTrPpO9QV7-3b)+Y&k?$RRLX1_$f z3N8R-l0_&?epaA5gTgr>-k(!eMTR!*$r>JZ zqB!Mb7)(`Vflvozg!WgIjRC#MVb`t!WBMQ(JW1fWQ4XSoS66QvE_u5H*$H1TJ)<`V zn^zj{d;=br)d+;3$kKlxO?%*=X%X8|xnQ9#quH(k+vw#yA!&Q`fY2zDWv+NF3v{x|(@M1#LbxU~OUG$F zs>43t^)m*#=Yp`I>Bdun&dw8*m{-BESVY^SQriiCFhdpl+l|Sm;fGY3bL{mpH=+3J zQQ;@>bP{DSbl!FL`v+DPnLMHcRncO20O{E<%82YKu4M}jfe>Vi_$#bPyJ6>bmu{A@QMZw@EWM_6|0}=D6^4RX< z#LzDAh%Q+SY$z6k4pI3;U!B2yXC>W~1fghE)jE%ghh0=^lWtzOl`QpKgzn?8IYN!A z>O92Cx`tdejVzn7D#1t>W%VvnHGfan$%JnATUlYlTbpUISmL8&bGQ95%w8q1nPT~| zl^pSJ3S8llJ=W_mvn74`dIMnNsmtmqdezjEFS!?EVtU8O^B}$F)V`wA6A$K(H|a_I z1;ZcYnh;{5&nzx4H#W^DRE8jTNgtXWFeb7cbzWQ}q)&izeR7|7Xy`z+ek5yo0YHg* zH%a^T8Z`nOiB9xE|4>=c(|4DldzE|p?}9FH-S98os9b(s$(c!ivBR@m7-Zz2rG4Qn zF!U3R(`8MKm@zA(F3=%o0V3x`=-wQ!<}xYCE`AQXPxgA&Ufo$jnjCYWxSpe9=|!;? zkxFc?C{>eCVzAj*G45VoT>XR<->jAvr72)!Zl%!R^t7$Cw(Vi(n9|E~XSS zmiNu!>Me?~DSL@sKU5b_uls3$_o%K*vYlYP@rkZSf|Hi1)tT*<`!m!zncM}-O#a6a z#cVn;#U9G){+@+QXmBhZszqO@>yj}ZYiVjuJ^-Ea4jXpm82zJY{rm6qHZUDZJdn;_gxW0tW583aB^}2lf_;PPz9PL)}B>~+n!UJ$h??47iJ9& zeN}auJeE)58hYHc1y-RKF@piguD3Y-qxY>c6k+N&9YZ&LYmNg} zSi$$9o2uNju>KEm6RKEiVF!eX`rg%u;ltNKR?0?4P#UUWu(QIq26c*CQn220Qq=#AeQiYZfh$f-Q8m(jOsGQ@T*qX zrpxNsJYVT~DZe>TsZ&@aZiT4H30&oIMNcO~eNi=r@++F)8L+Ff>K5Y;_~DgLtNf-* zawI>ebqq}mCP8(7?U#fAS)63OVr0G^zVv(7m_a?Yfxy!9Nyc+!p-{cMFV$2#8nf)C;8%Hjy2 z%)S;SxnTO@AH@6r#pLI!>Q1Ct9N>Q-?-$_ad>riSyT1k9&4+f1tW6P>-=w^tOhrTP zo9XJ4PCvxNtsGy zuDQGsad`Jaaw<22Ye0f04a~?l1@gT|3`Pm&W=>6GW9Ily><#*fMZ?@??1~hhGmxjL zb;aO0)OB5la9fFi&ySNs$grh(34s$Gb^dE~x*-ijU%yawhY65{`%B(y>fj4 zr1{4kXMhdXC9cmC*`PcNsW*{ZeCm+LK#K8m@jZix#J@8%h1SrOrF`-Sa@+sZt7&_O zDob_$g7?uG1gX@*vw)p@LhH{PvsPNwad| zaYU&6Fnyc@2)Sd^1{@9?P0AtDD)euIv7WA))n~!Ac=2>{ z35JIfOpeVThSILx47&}$c|mK7oN>I+t@o4eaAnO7=j>-@@SUyiyR-y3QQex#Mk!wW zU@kO|5F@-}OxuBsd{Y}S7_xN8w0${#^MpWhg}H+nab@Vi@jI;JZWy*TeRfNXu%Ge2 zgWKqa9Hz)R5xBRxaaW}{jX5}tXlud1fInAJ*)7>G?-Tx8H8WwQD)*ndnG+|LzcE1~ z%iOYxg`p*m9jgAl^)2D)!sy?|#>Pe#XeXQxDXQW31?-6%XUpAoes(y48TBBZkAIep z0(I!_{{a|t7>+0*Di$a7nrxRxyi{}kfzs^wJ1dbT$Gpc#7;s9vBgn3unPvv zb$2N^ZyMzUz=NzdPXiFp?@Svp$bSw*$K4bL@(SZPC%(hrV|1^b-; zBbFWbB)I0SV{soqS;9$emQKG2>DUR`ME^Mp^pa1lrd;)j3}(+RfqE4yM6YpM&&|bA zHi>RoK_NGR*c9jH;(}SZq%hM35@Pc4HGXs{5nFabP)^C!rVF~qJd(E^z`2(|N>ZS4 zRK2h!NjaB{RQGA8QqcHk{=Jrxv8w zye@5=H)kD}pkpFlJX^?{c@=S9S=}R2g543`7gbmM!VVs>_e`|6045xtV$bj(M*tL4sjq(=+@XgEE(YHpuAfIB#Mc>On-w-X2LW?V}0Yx=>7nsrqfmWU|9 z@cO=|?RToLt_!l~ORry1?!b4|EUpzi8N+^?W9IUe^*CT#(|SQtVPWB;OqqSIQ#tf{EJB>M*zPQ|)R0&oBGEM9H4`7C z#%J+~^LygY-b&<0D0e?(WX3ky&YqJ8K>m~;gAH^LFkbWd?_m-i<8V0jyXRH&51mG$ z&n1p)Ctic*w_wLdH9NLATV52aa$;{1f_mae zcyUcyjXbX(a8d5dmDgDRCvFnTPisnLO{Vr2NUKVg5y=Z^yF;QP0vrSfGwPpKwgxqe zcQFpDP=2)-h~NbWM$sp}fAo+ghQh|87pf19PhxXS9Sm4DDtdl4 zG&54+yp8#sP*L|Y`e0P7P_Qb*%PX58HQcesn%H4# zi|gHMT7QQNCId-^xbr*VPmZ8{VT2He3K-X4fA*dGd{J{`J-8QlWY6m1pM3S+w`&fI z8t&i`ZBsj9Bpfe?ts=`F>~tp4W0b7w!(#z^f>GqQ%DXGmnf5V+bww1b`YWB5Ix5r= z%cdEow15!$=?K2hIn=z=)g>8}Fmb|EpBIk5%*@=gNs^4jaQWPvvdOpd7i znWAmO#YP`BZ!YmXz;>d!;ph<$rM+Kf{&EI3O|{tsm#tO#2WTv;2El?tvU>3$p2 zWaQ=4QU@ZgrWKMAsDg;!mvBc$bB}EKb0UNuIQ2q zFcBts4wU#O5Kqf&hxH;(2&8zosMQ;9hFz+B;22*b>iEo;VxUDf=}UA=`>mnp3{dZ0 zI3tCQURT+S_;YM6@>6PmWOvDuC_{Ka-khsS_#W1SQ{Cxu0`}pzPp+=-`%i^%(0U2krsm=0Msh|7m0r7ub>t7Tduw*6EE>LFB1MgIalSG8F}GxSuN~siAw1Y&|Ov-gH1K>_QWr?hLD$a;%d3HSn06{3$GD(R-(~P_@$h0ttQ7{(1rY zA=dp|9OwS5OrzWF}Ez4fJwr^`uB9q`f)lisKJUbEHXb{Ok5F%tx1r z15YZM3mN?d?V|%~(^1-}{Q_w&5c~SV(Viwi&MRXA75~jXWDtxG0bd<~PZEf0CzX8! zWEn0(K<~!aV?s4n@@cd-;2=Qe!JRT5vwd2*{N~L!VPTHVkbX9d7wVvtQoVsCEbJjWNeCYsMP=mAD;8xoSu+%v-y_{*26;g9tx zM9vw~$I~DRj* zCkrY$M|F6xCWw3YGOCo2^<_Y@FD2}#<=*0A`erFri;T^}5}(x76-mP>m_F`0HE~3O zl4sInZQ+;8^bZvDjvRR%A`@DH60mf2(rCJ2-aZ+M(7Q`FMnVVTQTSf}T7wTFSHK4m z^d{VtmojE&ja<0>gD`_M02=mhuGu6@DIXAizdb z*LJ+L2lZhMIqO0FU%T&hzl-=9e}!K?@VaF^8z^!(N^Lc#a$*fgTy9)T#`utivguI^ zLA5WO=XF7`j!sUd_?HXqAXC77=$6Q4P4-s#6BrfLPxtQK>lH<0CW(%Cl)3&GJLgek z@RsRQG7oiSL&-Z^U{4MB7#3r~uOTKXJtDUdr$QmhA@--C4sOX6sydcwh+LAmY771< zZ6nJ!5OKbnBkv9(dQ`ZS9+&uX_OylIQb)<~`r zx1dLCZg`T`&5du*7~w~poh0edwrUR4iR^dj1P|l->J51o{m1BC+>IRWL#N61!ovN$ ztD}NL!9rG?p%?6?!MX$On)%uC&TPvZj|Ud0S>E8jnhdH&4+9>}XXF!f0h&K}MWgqL zTN4x&ADSkAJ<-@*d97PZ1!+NgVYgP3kcA{P{&j^6tQ4q46xrC=$f@su0IeBt<(b$r zr|nnR1@-Q#ENbCV3bj_vc7u$lh&;B%)CFne7~*k{eb8H^|QLI7TUh5>tB*h zLJ!Q;8jnMki3xmCSA(YC%e81vhqfNG=>px(sx0`O=vg*8mGk)#l5y|PP~{z$0!(ytWn(A4 z1$7&U20jX9rezGLwgk<2wi_>)U%FJKemItNzqmE|K znStxn=EG`jxozQsd;>eQRT+P)8rJ}4KeX)AiLCI~*}KVxc)^C3<5$t>gV3F`7Mu!r zUFqzmvGSqGown2F%FyQv^6`?-y(YoQXsh68{7zqOwEyUZGt{7_Ec{75vWX$FYaHGS znXa!30@s6aZr$!6kw&Szqtbv5juimq5*UkT&z> z2sXO>%>MW+u;L_Do)|_UlNw7M+54bv;-*IcjR8=|7x&H~l7mZP?+>Wv{s8ZYWw@dhnc)?L9%2X43>uzTf8$36zxa(OTWV1CY1lw5f>`b*)vW<-DZ#rtY!EIb8CMm8_4Y5-sT>-o1O_VSQ*g3m{c`^UQ#pdLhljQ#j8+@1xflsdA~Jn!!_aLH4Dwa`@|qX%u5s8TrWDFa#muf6w-YAXBQfCG-gSU^XL zQmuoEfLQ1dlu^bCNE2y_A_@Z1doDAKqM%@dh?Ia0>C!vVL8KFqUZb=iy+Z;?-hBxm z(|+s!;r;M_cv-GBvy|kXd(J+)Jp0*uoAf}#gU>dt0M?os^LMS6{wMO0Sq8Lk`kJ8p zO}i!wqRrcET`ersr=$Z!?1$|>qxELKHcBl6LYEUwUZ`i()4iq`-+rGwD+iFZzCE3W zIAQyh@#*PD#Qbm1jb-+0IbVoxoV7EhbdqkjG1A}=y9)VUauU zFQ!*ckv_jHau@utz{Ag7vPhx0H_`c^%Gn$CgHK2Ag=ww-R{CkN!rS|=vBjk~?d=cx3;4Ns%LHzAkqCnHbjfKO z{hacy-uMLfFP#N-$D`vo+*!jY|JHfp+_PfER_JGd=RU#7cN7(e!FTm!zmJvor}RR4 ze;TR*KqOX@`4nT7f>oGXQ0VP>vP+tX$ZV;E+uXdZXO%rVRKPkQByWJHfeg zRb^#1{{9J0Y3{gMx6|iPRx`nSX&9Wy(U%0E`PF&kh&%_5_~)Fyit;0><-^0n0FsEJ zV;ny-Mu-^$4*=7J+K{*DFfCoLD^LdwA^|$(Hzh~m#nm~tYC$#jn4;R@*fN+dp{5M( zKNkQGFXjv;^}37>R{=39EZ0zfB<`oy2Q$0#4L{NEr`NS=rIFrD32gTguXP3|F5C)B z=c$>yT&JEp3N4HALF$~lx4{In9=<6BgP#nwpy6_Nd->EGa*k8^l{X$ec9Z+~`tdF5 zoclTGv?)|K;Wzxsd3x2MLr?IAzj6v3hdn5X78q(dTa2$M{rB`sPWek816!LLCh?}G zrX*e9h&6^$(BZ`X*Kejz2F%JB<8yxHOg+%n)^bbGjQl8Yezwvkuf>LO=odN)kh?xj#_ z=Oq0HYO9R%d82J>1a?`+oi)`5>|}%lsu#cd6z5@Xw9YeU%@7528N>>y_+Q~K`IjdN z&vCC8t~6u~U{=h>uiptJC%4f)S&ezRcOnjciAcyY1x0u*S>^dU^qbxu4MOMqyfk;; zp}u{ICb1hFfC@K_N39#tV*LEp!$Vrbi6-3NBuZNDYv+;Q^&c6B;W}_dgt!x3ri?_M zH&_*4thdU=8KX5}v_yxId$X8~B&?EBMQnNfHtubt={I9L-{|H~w-sv#ebc$23v@nE zAFSbzgZS-SoKhx#gWd1{3jV)#p5hI`ebaQ!(*dIA9;>gKJQ3xhc~A6lr`MU?5uqJI z7wxSLh}H9w0VHzIJkB~FxgW@ zMI~OO69sPy(di2?I~|>l1$}Ia>>$zrKgVAHoXo^u#l&LE-dLl(6wfEGM&-h7ti(AeA1!IdM=c&DuW+(&${KIguFDI!v}G42Me!e;GLl-iXO6chw`^!>^X zCr;Kup}~U(*_X1E+j=JQUvktp4g;Nc!O@$hp9zm}v7b9af&t3h_PGm8&G3I?YOXA{ zIjo8|(c%;`C`s_8f)KXxH`PH_MDHSh7xY)T%4<>e3Wjw5uTkX0Dk^kV?WhDfw0Bz= zhMQAj8Y^6ld4P^3PpQO5{KzRT_t21gViHH%i%$48F!m`92@iLw1PbMISz#z(fzG>) zgPmNgp&Uv;jV>d&zy`q|ywpifIn{?Q&!IB43b-Fp@=*UiG(0Sm02KfgepO*H^_B(- zd333eCE^yETo}*eSQwctYd>%jtvkT4(%@9(f%e@mZP1{~j1J~ImjIoAQt|p4oO+6X zFH!up2SRdI=n!E8bqqhx?L$Yg&eET1crG#U7Dx9jq=@jVH97YRqU>v}67XWAWn_94 zcf0hDj^4U77ec$r8eFO+w8%Yf^@Mu50rTN9XmRP%y4&{2(lF9v{~`(pEEk%cp6E@4 zb9W0nmwDPIVfmn*VN+ox_(-YKltUKKUz;PNod;j6%PGvh=qhi_qE1exYuAOFQv zZ;##q&g>RZQ5SAUNM(P{LHXAMCs&%{pnb3%w=Qt*IZzl=0*$K#BX5iJZTb)6$LeFV z$UVU0`8W?K?{I5brL3svv7)8@8VWeL%^NqsT)Te^&-mwMl7|z7iJ>Wpl+Ar+(5`z` z_G^62c}^{rzti|^3ZQA3lQiKyv{#94-Hn9|3#+Z+Upme#k@wI^Lvp+nX!gDl?N$@- zPyHdMNisVP*y(6bIL#fbZfc;a;0ytHMW<|*0#VQ{?D7y(>4++wuo3S0uiC=}+W{x7T(Lp}e&e{qygW5*TQHiBkNgo@Sw0lZ4*EaxM9yLl z%u8YAX0b~74d3#1FQ`PtdMcCN5+2Q%f;ME|yWcmdf}MY9_3JT^GY4om*)G@J9Smmq zZyXB2Yy`#cR?fGUp}!yX$rYuCBPp>lO*MIdox_7NYeSih6WCe)Oy}z>C|d81!a#DW z)vxGFipr>BCw@hz!*XRmGa2b%pQLNZdXCYwX5@F(sQEYp>;>*Znwu`ZjYlcS6oq2a=5$~w+B4n(~HlTPwEWXWya|=RkoN>LW=gpv!pAQ#$?ZCr_#oR2#^u6CSj`R5yXT9t!*tf2l zx~{OLr3D##Fw?105qc=ifvi{hL<# zXP}TA);&ZCTw5)bucfF`OPM*_UIy-d!F-PtF$)QmnEaUhFtF)}-lOwKWn9M z#`rFc@x#AR_0O5oiSz~!=mQjpoGHS_@GNG+X>UYV_dR;_h>LM&7q@a*DuPiSZ^@R) zl-i)f2p{pJloUWE;HRkR$%3O1&wJLzP1S5pU0c0MoJkW2lvrDBCp_cc-g7dd8~()P zQX30AjDcZFOIB`Dx_Z{G8QPXi-A;>nSgBbT6YXlbD_QWUrwIXfGy9Hib`T zR_7yyX6t}w1GD7O~stAIzN5*yOksAJj(c4l8wOq=kRPD74IdhkWBDz#N zmk>7hOFgFKuCaTo`>GjEi>n;3OK4jUC+N0LcU`s1a9b(+Bv68pva&KPqicd0jZEU^ zW)e`DDy@CkYs&CB&783*3^otK&9jt)f{Xn*(kKz^_@z{vX{XM$4k~N$ z9z9C*G{vd<8d7^yYqjB4X>=C&nQlqJgu7hfi%c@fr%_DhCz7Pvu1^$fKqYLKh8o^9 z--H>%Po{myJ`I};OT4Qqzsm7`@RIm@RgbVcx^|Ku`Zcz8$M{oUvQL%=@qDi1&Iawn@e1>*(Xp6g_D zn-`huZsM)tK6za+K~J1f zSCEpjw7$2O+$ zHg`wIG&*s6skX*M7@Pa#$3d0A&3B}cu_FG|RrCZ~uQ()pD6Tukso>p3Slm@u+~A?1 zi~pw1xW`Ydr7EhmU8yH;g^9L_#<>~q-i=OA-X<{WMLlmh<=f66K?~xiJu;q7t0c^& zXNs9(T_BYKt|?T6X3pLVE4&d9$6B4E7Itklw zo{{yLw&V_&vz;V=zZ^Mj@jap1h>Ts=`rS!)#ZyE zArlcwRd`lU=ciT(bD^~xE7AqJ8-p>DKX)6MwHcVxlVn{UW;mH3NUe0KB4FVMnd+~H z=oBcGkj41a0?2N$+}4-o)UGUrVD^RWt~U1Cr>f7?dx|LRE7itMq+r?~>I=i9U@Rgk zZ$I8$YFW_ORpL@9m2|T%fTV<#kH#oJE5jCM{=25k4|dV&IA>>7w1F?vpzY?ERUwph zbT;0BodamdINKggbwh-nq){*d3r}>5T)17rzt1NztBRy>^qcox`K3&ZE?l^PT)dbA z%?cTE0mj2^+1e7S`o-s25|WdMtnQmP)JkIV?dH~~Sk#}sa#H=IAa=*TFLLAW4iWQG zHo4%pMsnye*i=La7reQKOlKAp3><;iOfUW-Ky|8N;H{H#!(YcO~FL?k1lBB8(8W9e=1ow)--*=u97yB*1 zFj?Wp$s&J#h&CbGC(F%sn9i4Rx+OO_~FCLA5=OUR5ELMBl^kniQQ6AJJe8 zh<=)tIdsV3>z}u`jFo*OKn^*i7K_LFPjJ{d@hoa${zXlUDq`of1RtV&saoc^g^AqM zptx;A0Es6lb7)GABSHfU^5p<0ez&-DDnquz6}lJo3zCu9PYxtyeI7z)-fX8oU7iI0 zs74T1<<7Eva-)%bQp(fejn9C|l5ez2W3GZX@>^(L_%Y|mE*W?`s1nheAAbk6&mb01 zeGc(=k!=^yX2t|(=SGOwv7`=apsD+S6w>9>C}l*N%c$%1T0H80V;ph~Hy8LjCj^gvHO#)cO-wtMCl;7Jm8lJQUQSQMD3_EGKVomHta20`-kc5E z2vI84R?KEU?4{jtdTiIa>YiQIZfc*rTmj_;wH+?pH~WA-!kBJmei`uuQ#nG^SHum^ z8v45(^6jS^?Ot$B>In1P7JA57YbtiC(~#LgW-z1}sfVzxl=c+5Cu5$vD0Y&PiSUz@ zRBWOcjd1n63(>$}7A9Zy-Nx}m0$wZ1II-InyV4Z&>*4zAVqTQzxqvZfYfiP8kn`{| zb+ddVm4NWL;MphNgO)1pD(qd|$Ca3?RI;FFoRq=+wjFmq1y@IzkEql}M6km-v-Hc$ z8UV7aii*{uo}(WS55t0qd>6*2Ok|XwIPSBPIO)D0OOM0OW}A8_1~Vrc$)#c&{FV6K zB*%@qvnM4yFR2XCs)xdET41y?2dp=XjLuhUx+qPB;15Xzs4?2gVya_XrMeUX3(OE$3D<&WVa z%u#!S9%SWKfY~l17F&4490v~>X=k~HV70|%R~_~WcF|E%iN)Ght`a65(^0HOVdg$n z$fc1gD|>XR;pT%%F8|pvI4afbnFfaIl>Ek?CxgoRaU|)0qU+!^ZQN-nKjSdJ4fRqG zM6HNKo|_rL4^cD&Lga5Q+G|BG2~}Tc7YR|4n;M&fqq9)9(vfcPeiK?oirQ%}6P3Dt z!vRgR>weP6z7w%qlFaIIT*u7x2;i%u?U%qgzKJc?=m>{JaXqeQ+q|%E-W}gu*c1j^ zzH*M&`Oa&x(Rzx(ZuxYT_$cW*tnOpOBliP~eTTqDS8U8bwJ4v{pi65JH`CjmBC>{z z9d_VHr@+RYgNOvJJhwh>4fD3lZ``c$@^-80=0BfuHL_O4yU?|-%q%h;)^hcY(5f(kWF9FZ#%DD^A9l*H;>0{Gp=rS%p`481C zztPRKX9Hg>C^n}~=r?L7`^lEa&i_+oi1tzF^JJ9kYz;Hu!1V{hN(9;d+vnGVYIsTZ zNquSBO@F(+9}lFz+Z{)Oh($V}=Of8{PX1F)3SH>R7d@)M+*a5o&}UyTlUIPxQd1-5 zEC;@8t&)Yeh_ZApsp}7)N{w&@Cvdk?El7MfJc>g?L;drQDc!J`+vjE(E*0MZ4uJvH zm+D(-;r&-Mp*ONSA!z18+s)?Rxa>G!$spwSO!t)u9A^j@*h(?1~xb6-c=Bq2Wj>Xh4+D_tNG(r>J7Y(8AZj#NIUV9{!S3?!yWP8X*MZI_2il^JJro@m=zs&Y$xTCa&#)Jntlg>8R&e@IcTB zRt63`ybCI<;QltJ%x76)=;!Y%w%Tj@)$INFD{oglG}e|MaF|!yi<|vKdkYgVy9NiKN2O5lmn=AWkOg$Y=X}Q{>aLH*{4*vD6I6UbgQ9Yi z1TOBUku7!upkxo>YD*4I(t-ssKHE87ZwWWM@Aqimr?~mwS~a}_#uDalw2rRIT-syu zWDLgG`N(r8xo&zzIlH5p$&p#NbWDC@7f-J6f`7Q^jBo#|H%_enhc}-2(3*1x8(SPc z)rQmNhi|7%_u+Tja=u~vGqb{$GmH(fBIm!rRBkH|J;3{D&GrLLew!>$r~bgY%pYo^ z*&UnfuQz;sICDs9UG)aH`Y#md^mCj}EqO#25-Zi#AO9WP3OM$!jduTeG2#@3r%u`$LrejqAem7X z=gasAZLH}We3{#Z_S1__XpTxr_fd3b_98mfEQcfiHhH`=odIDI@%ECY(Hi zO9k0VmEWDp=K`%QBhI_^$eqw)o7k^V${85Pz@WqCK`oNc-g>EiPPIr$NATuvD&W$aOPxz*moa@b=Azz<`+ zDQ5KWfI5ssz1n?GIG}S%23{=!aJR;)^lYyi4<|r6a zTiCw8#GWZX@&5uC5Nnp>_%z7#ZykbkL+AvwuDH_>V3 z_OfVxAW3T9_t#5c@J6P_*=Y)Ia@(_LOh0ROo6-H$GF7F{jTsAjru2uxSevgty6x`b{* zYUBb>NT%o4b*8fkWLiQd8Ry}C(PhGW!K4Lc{abvq#6xy{K9z^@n(V8&n4ov~NJct& z=vRR0=0o_;DbJOK0_X@hgNHH*DKhJeTyP`=3Q<4f3(~T(nwsspjY-^~ZT=xph|nd5 zAaP7^;T{4+brAb@;*oC!sHe5nKKo(gn#|VpskDjNv%*wo`$ar-Vb@rQu_6DfQxVR+ ze}#-qJ;#c`s6W}!k^-T=Hvh!ysld+R^KknXgm>A0-UP@Q>Oe2mgGXG$%e!$33Y+jn z66r&>{52WM!eS-bnd7(XX?^z$R`>lD6qJSEX2i*}f4W_K3BAL-*N)Rz-Io$q6JNM} z!~#AnI3D|fq!FPMvbqmNJ@HX?pkdKRH>~b^7d^0u=AcMlqp7LR_s3tPi>q4bcSS1f z7}xBrXLme8!oOxC0d+kEBTS``9^ zJ@{w{Z1aX$837Q`Q;hoBbt_+xjIP{9{b97^!d_$byt#yhDDNlW)F=@il8V)~d1EKY z9hs*hVi(nnQicIQ14c9Z77kAg|ImbUwdViOI&do(73-oSym~4D8iUX@U&LbLc%vzz zysr8vhk~%{lKAKHMKXzG;yk`!+64cD1Lr~A1DtN@tLQ;Vp5_qe*2QRxiSn0L%`1|r z=M;;R9!ED&|Fkq_bAM>QTT;YDLX}y=;m`bf+G6e&p@fCcx0Dj+Iq(r!>4fDJkWx7Q zk^|?~GcktLR+!q97BRCuAhmHOD4LJ@nWk>%0{D77=!>qz)qSb_N%Zcdy!w^-2ZZh- z$*4!{&V9d@3RA&$kVHAGNiBUM=Fc~w0{!@l|Cv1islOnh3WKf|F&yv`)N$XYvI0Ev zhnKWc`#c4)qBRm7?51c0mwPXja|5v(134!Gn+R|@tkOT&ZJYukcb5b_GRA925g9)qZg=WLfK zGi$#pGCx)cijXc?i3^Qy)2K(mck~Se*H!~r!N5BrKW}m~asHY~b6u5F(h{uYwE(S;ks}HK z@XI$rn~t*V9UmCI(X?-FY_z_bmr!kyEAUz-S9te=$u;3HGPozct{MO^61$^OF(fng zOJSd1m~18+)-21Lrd6+glu5wuQzcHG7@9ppAj_84 zZm+^OVEuAWqfvd(r7YL;RTwYuud^cURs**ZSZ{zc(rSsc1<0uUV*eN1Lk^b0=Ne~@ zzE0J)ki5o*MtAT7fOmn*h{=6Q&-&{68j;1Pe;NI@;6c3dvGK*T`Ezc)DssVGT2je# zc65S-MMl3I<%_g!&q;@Rft(z7K#-BK-a#fn&H2nZmOpYbV)`kOrjBPOF(-YY7ZOAm zkfzzQa2DV&u6UGYKcwQ+IqEk3h*y5fxfSu*8%O&3wa^#K7z<3rc)=NHs8G8hbenRA zgBf6fuS_adZZ09Ud@fJ)_eEGdJtV2#mXS@IqK_cA&>)PJf64v;h{jR|65}0xiizT- zHtG=gM(D#rluU!y?816X4?gN}9nPkVBNFFBDcX;t!ax%w?FNx8kSjXhmXvSI?CS~`@m*e5 zRWUNtY3erQ3-u3hGyu8-MW~#8GMa#MpFxJ(Ik-hU8B_{n)Ygy4S1n7v9vuMvDh1K; zl@==+>!z`;8U}e3%~^YNQWvl(6y5bSmrmTT3V8`81b%j#y4C_>4E?wzB_*p!B?4G)C$Zm9!A{F_tfl+Hnd7%5|6t+Rj( z{NsH0vhH`;$w;UqGnvPapvUXwHdLcqRc>tQg5?C z3dO)%#BInZv=vP$uiy?y=GqxNo&%Q3Je5Mg!rM0Qs)poI7)&{hh+uSy=FLFLb&8)z z8*VO_9k<6%yBiW%IB+Rs>6tCIrn9NYgokMe?JI|<=K)qe0j`#DzPl52e~v~Nvt5B$ zYWEY^%nlItRFaDSqj}hu`c2EabR)_&Q0J%-KDnsi_Q#RFeQnrPO+XlK@;^En)w<`S z?N3=L04kLVLIh2+z?&g58FNHwr)lzBD>+FR>v9d3kkxNE?MV26rOu;ei0=7}8OALJ ziJmaR?8GWMOt;Tq0jY%@562>CYq`spA@6d-$q6u$ozC}$9B2pyxMM43*#^Az--ZgMj(9#4abwOq(D2iy3%JLR!X30B;Yd3n*k%eO$PZ1(yq4 z#tx4WI+00zDKM##KieRM^O#no=#BShB7|LwOWubd%(4fjbo~kDwt5Z0OT&DO!BsLje@!aaso_Rwx>}vu=KRcG|HBW)AD)Wl@W?@DmxwheVKo-6CaHx z@-Og6WJ}2ZIB7xfat6Q!&IPxqvVm}hULQnX9~dw|42R&djB65(bre>eKR2AqB-Yw8 zWyNr#qV)C=QR?ePW*eCXTieo_JpY-PH`|C<;CpPta_Sy-?;stISitpt<(MQ~m#_3C z#$*y>+b7aODrOzCn}gZS-4S4SrJd+5}c`}qhAi7UkHsb;asr#f=z-^xE$oJqDQEF<&Npd(ZUOsQNc*^R&m+FBH zmgxz1x`{RT-<|*@(6{}uZuV2*J`!lt4?Y~At8)Q)H>$SeP@w!40pIL8)(NV;JSMVS zz%l0LxOp76_jxDR3X1d}Z{k%5iY{p07rH;d{qobw1e|vMVS8KK{A8`h2rL3lGlgy> zp-LI$T3p7htSJ^)%4b{(KnJoikp*sncJI14r`3Ji&pY>~9K%0R)mN;xGe}(pvf5R|z<#{}>(!Bv`hMevguOM0+Oc5diE)#yX4OLW2H(Iz$2D$E^Gu zIM)aW6lnEq03z?#!*w`K8hhmlYx-$nS+FP;4%(FPbOfIl$hqa_6{X2RVz-xfCYU+=|*D@;xAMVC_M{7!R>2+&vHEX&*1`mb2+ZL@<8Z?VZ1I+}k z7yO`ZF)jnNO7IY>MY`KaEu_Uqvto8pVIzL+h*~B`o9K2KcFrTt?kGw`c+^vsb5j z%H0cotgWp<1-iLW!3u&0sh?>CMeCuSfYVnMyJ31MSClG#OXgX1ZGEUT4o349spddN z4&E7j4G-cZ&>7k}U|jt)!kl;c@weG$d@pd+irVz`DZu9{irX zw_nKA`|21(m5V`21?+tFnN$NSpY zEga%ze^js?I#IO+n`BB9S#{(7+bMVDI}KZ|q@p50&UMj%#KGe8BVz$msICs$U#cxS zj-v0P;;Oz}0XwnX&p^@ftS0@ zDT*Y-*9HZ0XDU=1_*BJ2rmlfK8v+-8mn03YjwdjvvL?3={}Hw|=V@vPd-Va4PuD|U zQ??u{gesW(Z?{``6?n|ptj{o?k}v+c<)Oo^sIo#ZEzu)ZR#)Ql`D?1$2rsVIm33;e-mGr!u zzy59s8*{xlg;#sTxkFBr-Ml!_b3J#ag%4LVsaziNYvIFe)pvvrIdE>sosLi|loRTd zUtGxh+IWD*7Oojy(+k2++QvPx&bjrG+6|Et(s3SR7xpQ5VRU%Zx~HFQ4g6NaG)UQf zqEYBZd2*%@Zesacv{8P{yJ#-+htY`?7BB`-6=ZD|NrbcmF&V?-CzXQfdFQp-TJ?Bn z`+`)wqYb2gw%PkaLLS$vdNCle$2C*~IbXoa31Bdh{~`R`aW9Y=*UbuqtHx3UOm%_% zXoZ;k+ukSRZYB7o?R|yg2MAWU>|gN#+AZ-MS3`lvo?HDIF^BcT?i*M7szD~O8H`OELlFziZ2WQU;Fm` z_m204NAO1miYQ-U7uu=`(PB=CHLzNZl|m}&ml2nXBZeGs}6P z0H~Px4ur#(xu9T`wez0SEAjrNRQ1-SJOlcR%bA{XzpF8*_7hpM1sII#$YLg!OW`R> z8LSIh&gFvp9?b&fm*gL#8n}e_WIz2+yl3U^fI3n?aYCU_vrKJ)3&Ns;j0gL2u0vKV zkslZqjG7Nl(mgTH@vHmpsw~0BTrc)V6lV3_zyMxN^cA zCFjzYa&0S*@;~nS!agtT0W0C3)*J=qh<_m&{1=gSn`A|NL{`fLQwHrAZanSTa!pdJ){>%z$)hOpXaE!MY`e&5Z z?S%s*)mP5+B6H8MVpm3#2|GM2>_5ri=9<%|Rdv%pOJADVaN83P=oHYZ#LY{W`HN25}^N_t|pf6uOf znu$hD{x#nel!z|M8)=G*hs@?Fxd5dSlw-Hzz@q=}8gj|JV=$BF@R|2Hckr+Hn_vHb zHTeGtHE8@FY7jV=9_5N7c@q%RqFIAdZSsO4B;-xfN~|ay1)e*DUHBTvhVutRCd{)- zdcu1UrBnfzMkbYzH#b3^{VH1EP=mJ%;uOG(261v?U;CE>`*3DX%UiPEG98F1uKP`F zpF}gdNqM*WnWJ&YL8#%dj}azpRhAYEgeHMx4TdOvsFqoUcpWU}$8QSa6vT@JadM~x zCrT;rRb>v67=xtw3evpT`e)3d2{A@EKaL{CY>h#fL}p)BWL0e3L4I3SE> z29pox@X1k}B5X8#brh!uyC;%)_64UF`}%VJ0A>YYzJ9wgj)sqY#c8^JPD)VVeeeYw zqun$Y&-AWaG4`H&6zc0WB$CA*v^Vg6KSv9{OJAI3PJJDk_C=Id+#cH8pj2Uln?%6W>&`O7e3s{mTX2o3EBLgJ3Eh z)>bDt>Uj@4P03FYG0O7tAsq6~gH4HN$wq<#4Se4o?F7R0@ieu;^Z)$ZAaFtm{SN)G zTDgypcA_kl$t*Lc33f++mk}f@GHm4%BYuJ>rI~sUTfmdDG3`03VSe?BP?Zt`Ge!7o zxGbu|O0AD=(&d2-_`V$x?&znqy@wIl!b@y9CQ1A^j{i~AFRc8$!1dlBBN;CzggzV$ns(PmII#mg@sYI|{K!O}z+s;^CP|{r_Hb4^EH#FC9ly(i_jV|bE6YxA zg}_PD$H)iJ6s#A`Q3(JCzD>UEzIT#y0=JMkK2|ci9nP!7vR5d`H#y_G9 z*7Q+v=si=D)drIq4dMqv0^%}#KW+0|1q9LSo}NktO_0@#rZT@9eQyyhZ=2Up8zsqM z=u`El`LnRF3bEnN=A@=c{c;VUz8RUbcotZLtRPl>!cl<#p+Sf;3~S$1b}nY9)`> zX170+?K*<3Ve0}?{kB#;w~R5dK0J!qL=J0 z3k_Q{r(E(+4DFe2&Y@jywB1&ac84S)rX6oJH{4>NLDo$b7wqif7aXc?&b)Xt zdFnw?^d6I&{ixuz?WS8IZq;+%h6+w+Cl%VH-_=JK_AzdbecQ+MqfaR3{P z-1U7T+9LkQY6%T{_N-(SPD|oNd$&xK!P!IOX8xzLGg>xSziCQ)p+tg?K_Zj}%~jS7 zT9SIUM{N8p3}2Hp^O_!Srs?JWxgq~+lM45R`cb>G%~nmBG+w9C4LaBxLh=O<D#RvCico-FvEt6?uim^|jq9eESU3TNSN|kGOE;lk$1Z)!IzV^%eqN*;`CeG$v z8;ylu8{v&-U+bh7`3Z~Z8SDO{_!Nn5f1zxoYw|Mub$?b!*AqUeebW;Oy|E7)Wiv{5ew5Y3mG)R~ zZM~YJof;T&`7Q2sjQdeRo9x+FZYuTbgr_H#VGzuh(PqOd_DKy`x6zRR;uLXyqyYP> zTx0&h$dSX(a#I|W*BJAKyU6^KdUC7twEOAoqfG|2XC5K^hJ!CL`Jk(A*5z>-4%L0~ z-S^qL$WKBMdt>VGG0)L(?XLmWq~2Vs!0aM@orK5yTE`X1s#9IEY5J#oiY#Xb$BrK4 z-tf9fXUN%ihqXpBDcD%>Q>Emosm()q7h*2ZU8RV(#|5uD%+WpLwolZ>%jQJ~HjkQW zJ{m5GlRcA)gU|l zGX{EB3@g@!3jT5D`L!6Q51CUf=bacWJ6g^*YjqfWs#F?msol_1aJi9m-r3ENP?%_6 z{BELT$a7UsF*)5Myv$l)ZRe1uQ~lQ4{%@6$B9%&Fy(TVs!{$SH+m?9E2rI)jj}7*7 z@0vaT9FJu!`h~qP`HW5N=veKfvpkMcT%mNh?aLuEXJ*StKWabpOuG-w+(b5u$z3Z$UZku&CgZIY7 z#Lf2N4b~C;iGJ-05~_GnV)K1sRNjRR#@(}WA(?wJoabx&yq+U*Q8yc8c$~|JZJXRi z(%p*U%HBAI@^&n&_1!>T%WJ-wtJlY*4{>iGTT`VCiMI7B*uBfk6jJe!^ik0bR>^79 zH0?l0pWFK#_OymnUIeFFxO~I&DNP6K>w3Rg8z)+)x*OiK>n?!?!<&ZQxToEj*!#Jc z;zpbN)^-WAuDYndS4{M|aP-{(p^%6O$rr*3jO#@z5*qQxS7qhp3ixG1&ML%LCfb3k zhj+c*Cc}!dFu${kG(ELP8EwkEtwUKq)CXoG6F2>N6$4CPS?AftG)2|^Ma^ayiMQ`l zb;+lNMaUf)1Q*NZ7Hag}jS@Fh!oYj~prJa+xYolScpdAfGB*ugRR&fkuusAdIKx7( zVwraAYi-;ndd`W8L)#2-x;VW# z{BfNcck5W2T4d1pRFSh{#{SQ}>P;4GISMnQV8T81?cSdU2iV2dt4Xu{OGU_`v6S>X z2EqQyu+ZdKFmt+1y2%=?9JX?q8_BwfP!d%3s->KCHK~(xEF7vj|zI$yp z^+bh{=%*Zd=1X{syst6uT$)m{E7|O2I~VSnhu>J1px|R@uy95Jkx^DQ&M)oyiC;W} z=Y~4ja*wl(?aVmWUTocF?6t%V^#}!)GJ}8Z@G+9?ok5Tcp zjB~}|aM|d1Mzh?q`SjOj$0uyeyNmd8r%Vl#BzO&Pp1o}NOKwbr9vq^YYeU^Sdd4oew-8_CSQfADb5=Q)><&_3 zF(dc7ZCm2SP3Z}3nMJp4ydGTKGkv2uULwgjH71}uj*pNys5a6PJbWhA))h;(Eb%I= zvdW1Y$G(6)u^h_1kgt~PUOZ+vU))sjS6zg7Se;R^ZrQ6klT8Z?03R^C#QEpjXw$q0 zXxizK&EA1$xz6Iz;@Ss&cO<+G))ovf(#?3HmRfMb>D)m0lP*4ScO&lrhdrPD`tJ>S z&h!sg7W`&;G`lD>Ev~;HH=<*6lGeH+6+`Fnhgr05&h6Wtifx>^>c*RMq2Aj0>+}SY zaL0_40R@uCFQ}zA%$$9eeH1ox3j4`e>iRSC`Mjo?l?Sg5aTZXUr5L?bhCZPXRHK&f z&7_S638N8ic?XoUm7h4ib(U01cMkF64HR!sj`1^=$>=Jr>af_=vj!@oj$eEfcZ{{U zny=IYJ|ai`t{Zxa_1wE{OwPa1I4-z{`=E+S$Kd1R1rtB)s1Po!f*@4Gc%NQcbd!Z) zAyr@Ml+xbM?K;F4b+@FHwLFvUzB<$0%MBeV#UrzZ8?vulcUC|0mZ7f0uw5mga?NI= zKmhsHQI`m3nOA~UZrGLP3NU}Y=Ll~kaW<5K&0^e0)*_!hbLOda$qx6&DJjkGPNxTK zh3@wnw)ZLz?j`(TMkv;mg<&gxUR`z;rWu!Cbh^F-p9@-$7hg&LLs)S*UftKs$#!jZ z{pP!rWOEqVB{h+P6L3q`Kph65geJ3r>vr9<$I4`5abFe5I|P&WPFH3kob^^0hfM}+ zBieQcXye|yMsNfk+Fw|mQ*A_NR}*@5p(ew%xJ_2lbSm^7KEyYi@{VA8Wa6EJ?x7z3 zh)!XD-rT)1Ekm(!TR~=2~)@w%Wr#&3%&4lDY0;xut`F;G-)S{ z#1;AFAHEaE+;qD^G_~n%>6oEW^#K_~CS&4{8Hay(=DpFTIEzTIE%AOLiq7#-Wo^ft z-cZ8RzX7^%r`fuz2O7yGR_cy9Q|+UhQleCqI<8vw1O4`#sWESErcHBjv2DZ1e#J6_ zmX5v76&s#=Jq!=8oBc9Y`7w6kb~8Hf9l)~6n&&2nGH z&Ma~MFc_hq0h5{ka62$y{__B{85<_@N54aogg#G=36F=QRA%iS37PiK2BsP6et-@2 z#rr9@Hf1*17(U8~YKp>}UL0HF;pv~E)E++vnCJ|=uWOt3OIerwyx%VQOJ&Qo=X-uF z;%fE#?s!EAzym!!XC|VfXzS;6&bj6};Ov$ywKr5lteG~45-})r*Km+oA}T?cugWHH ztqHGh>UE@*w0ZO9<3B8asQS>_YE_DitZXVBo$>7d{b7+7JdwXu0rT5@j@p!bW#wm1 zqo08Zn2?n?azyu+W+QLA^Zf9l0*yfA^4*r=dp-|mEIQ%$hxyI#;GDp z68@NwNT{)q%%Z9-kw9+1z#w9*7B=raHGK^}I+^H>p_Zbez@$g*Jp5X?;&QN?V zeE_bgxAu59PZsTw?G}>|C8cmcHd)?OniM`zzvlNkGfg+=vNkn)u%~fx^Q#VK*<^SO z_J6k!RvxAnRQ9nlOwBisBzbXDcBSXW8YBPsMlJeXTVaGJGHLZSmsNYli$cB+s@nH=twR71>{ z6z&VtA;ma44W=Y1BGs-~ZIWwV?@9(U6(55y@HM^r`^>LuS$SmlTaFR@c!2nz{;CS+ z$VNGQTK;L4;d%3_z37KYj=Ce;OD0CIh}2EtE{9Aa+HD0-XA#0hjY=kB(<2jU#m9V4 z^zHJ6yewSa(U}@;c*F467(L=v6F3(RUv_$ox(jZg3-56ljJ)JdnQ)CTwEOsE_+Iye56GW%r&+Nhb zzKx4Er&wcbXt0%=(LjLlO+EM5Mv6DLw>u20aUGk# z)K3wr)4`##AY2sied>oA9=Z%Q2|MljacqJiO~(S4U33FJios`6p@dGmYHx4BGq#Rl zw55f()E2CaUlGAaA^D|W7x;4QMLvvi)HQAFpVRRz;-rR|bzDxqV&xdv}ovYh{+6)3qd{I$=oeUB!FH!VR}urtOai^YJB%k zScZJC8XBbc^!Z#wePaq@;Xg}4oe58gcge(kocm5i>vh^kJlCnC2}48-%X;2uSytpgnl6l zQd_3oZxiRm9is`d>=XN`ap{XWQ346!@O=mG2Z?0p&DVA;ne0G7HPd}m1W#C(ErS!% zk##r3V7~tgRhvJ@Wmr7tyo8MDu&xogB{!=Wl3VxVNC>w$&n) za|ojFcok7P2Fxbq|L0&0Kg>Blm^&m+D76C->ZL{~xwcKHMu^^P-qOxOTtODD#6AKt zu5_z%!b>zq47r8vC)E&YpE<&_cOaL?$ht!=x0XSVR~I=cDd}Qgq*9FEkcXH!f3wV0 z4gYD{Ye+|=@WG2IX044~w}sDZ_24hfQL&Mu+C!Twk6ue-e2dQi4XaE&h}r+r;=J1} z!->?*#Bk)OC3H-}ACB_X6Qt)t+8Zi37e|5qxzXNXWy^5ky;J_%Hpt=Md=R^7M~uzH zm!EGOo;E-V8~Qyz

    vI+HAbNCj0GToEMaCz>SIerFF#W6Hd{@jF+ zCyb6BhbqDsFmyZZ2R9ca?fU2R7^%g76=!?awlK_o&n44Kz?Bv@$|0XkZJ`-M(|v93 z?SjA-gpYl`-{bC0q;Mui7i?O+7Vo$3bGcBV`z?vOX?7%*r&FDdtD_a-U)c(%yZhdO zw7B1L-DeGa+r`ae2k&&8X9}L1>(O;cy=cg?aeQ$$9V1Pn!>IH8je7PXsrCAYbJRwM zrTD;`#+ZiD$Ja%Y_2>F;#O$ZUR&qH0jcU=Qy;^8u0Ke)jX$}54&UPt5<4>7>MHt~O zF9iS0^L9>>$hcLxZfLXcO#{K5$K_v4qnPg4g56@{W80we1Q?TJ*#Cum__y89lVJNI z#lETTWirUVonsh;U*VVFX^}nn^9T-Yq+cVZ;MYb5*MS5DNI>4+_r(}aqsGY2-`a%# zYE~&!JT){lAbA?xB$}D$=J?>NY%Vl?GO};ee%wb%Dobc4WsHPa#B+6+{3#23VYVW< zjw$Q;Ic^jfsknW6Apj9#(I0C0Ew(#y;)rKLT}2mh90hIRs;%4NvQ|--_;35g*_ij< zYk(p`X%#+5h=&p$kOz;t^B?5VvDK~dxYqvxtUGZ(SN$f4)Mmh=3kq3qGXpPE*8vcW zd&PNq=oHrI_<={$d_q8p)N=#cdu z4M}zcFz|{HAc=b~{I3+{MT&3USNU32?Hi6Ha}g(aRCGOICGH&9EVTVCZ=`3savYOz z8ZA8E8PN2xVfXt?td~cpVf-BP21GbGj!GfIvn0;&3xP9L_SX33V|Q!FYqTVG6B}C& zAWC9Tf6VF<)ExtC->3YzCw8>R{QysE%*eMiw&vB(%yAU4l~8|fGBCvH6^+D}-ork7 zS5PBbl4BhVZm!*h!i~Fe3jIn%#{kQDw+ALGbdOrgpk8js<4qUohq}DvO}aQ_1M;@| z4M*;|eu8K;cdoZ#lEvM(t5_yB6R`ZJV>ZZUdxKSmgfFljFQCGN2>$cun0pNM`=Fs3 zbvZ*8WgEu>#zm^PZk5F=)Xek<-c7v^R_dsO-$e7GL@>-?eEXkqz-a{Z8A-Mn=rdQZ1%<}IzIa~+lPY0AD7_F%SIv1**lul z0Fa6jWB3Jd=eM29;ZPEI2)4Cw2DX9C73ouit?np@cTM4^w#eY>B8Q|g!Q9A#f;DPF z3?uPBNWjs80I+-EED69aXBI>IEIwYOi!|))ujS{4%wy?%QQYQf`3}8}6X4+K1VtI5 z8%vo^`Dtz7P%1Pz7?VUP!2!t3V(pD{XpbEoVTP{!o-cqQ_B8Eydq59xnHtDgIU0!pt?yy^bF^9Z2*=&iv*Ep|s%^-gQWuMyV{erV8}e(Tkt-amr?-_m6>}>>0Xy>(+;6oRz4!{mHzZh`rx=O_ z--+pUjbY035FRk-*P=V=%&&r2`A>|EM0sR2o}s*92bkhts%ExFydRiy)vAtck~7+& zwNckO+pT1+J&=&XwqAhF)5q^=E&PT~N00Yh%x#~=oq@;Fc%qPI@F|CZipYKo{N6*ln6m01EV*)R z;{|Xj^Efsznt%URo6G#9@_rr1l$CyUfF!nR;+gV&P3Y8Jh~zwL_iztPe&0SNDe_Hc zR%t#PjJ!k(JnAJ(6Va+r1jW?gTGF1)!kK5h+#5%Nc_|q87$VtIH1&P;w_!VmH^(bv z53al-#PG^dQ6vz;ablKP-Yz22cNqRg6K1q%F^v$oq|k!UCgKE0G3WGf|U{~A4qQD6QY3J{=81&I~x7%A=@SU z2_B^gcbkJ4MyJ1F$0LW9xwuge$TCRWLjn_nKNVsoK+#cW3XPM_Q|??^m#3K3I3b0w z3l^D)q0aP73oTqgW{PPs%&utV71vP6=D6Y`@y^U)rO(af5-ZN2RJTDY1@5M^t&z=x zu(qX?+i1enbPoZipNxZWiwV(JHuYtP6R4}BLy{cocZvq@0+^2c28qsCw7^GA{ijOf z1qE!w7MkC(F&J~dzW`_40-}3i@hrA%$0`9Llb>+-Qc&mEl!)VVya|g;Dgctp_W@|{ z)wGsR#Z&!d8O(0?_u)e%b|)+_%x1&OS|VTN_cl;}YWCNk+;&68%jXoV&c z2VzDil&;kU0$uxNmNx=%hPxi4G}2QB50wHQRaNA{hjJ7E^r^mH@J>>G3IlI!0GJe}YJEqvG+&_)!rxPg;0BcVJn|3ny`&d=aCp z9v<(q8wjL0R_W!J;fA{6)xFTn^#-2Ix9#xr4ZCaX9+;wDU`eH}Uy9zRYX|%BqsX4% zWEj$M-HV9g;N^hZN*G`AzjrOQ82$6`af}mMqKhgbwWrc%4g}e9P0hv#bfK}dgtC1g ziB2u4nmBqULKFN;;u(-tAPvp*${PaB6z<+gh5K`9f&2^60oe?2zmD&BtkfGkRxyf`TSKMM zRph;rr*R-x2)`^!qvX8t@d1?h@T=~(cJ>IbZBsF9Nn&AQWBKp89MK7wRwxKEgBHu{rbQXnB8~{}@UyK5HoS zrbWcmOvaqMvd-Lf?|};B+;Q8jmhw|y<}2$XII7$n^k{ptYgNLaz&V%_HaMhl9B2yl_j*H!rk0!Kvr+9%M`xA-w+BQ3ZdD z-Y>G215o-m83Ih?k-w#xN~(9Fty`e$rlfaQE2_9Gbz3&c)mCwkCKXt5|U zEE4yGvjXBIyoUk(l`~tH{gOs`XFN#_Z(ENrvRTr?BaBwktB?NS>9svTf+kLwx5052 ztLq~NIgFJRdG9~{9tl>dnwiC~sl-YCw$C*Pn;_7>v0ydSWhb_kY7}wr8l0YR1UF;T z>5A)`DRQ9E)j#~3mK|AC?hnbkS(iHeJ~Qcv2`Sro7`kv_3}n~IS^T%Ldb#Ow?T_D? z*Xy9rP@WHnMLwk40v-0!jpDv^#Eu|I0n)X&Ng(v&}OpUQ?FvqC|`^JTq%D} zjF=uM&dp)t@YAM86HI_&#Lomqcsp_RJovrXfk@S(drb6?jhp*s40;zs2`X9E% zkiK8F{V=U%1VvQjN{eV+RMh21PnZwI{<8uCwR=OKKC6pS>Vj`{5xA|B3~xrPnrh6} zPgbX}Smux#$izA*1uG&|o_^_7jU$SDRvy+42r;KWtbKftUNHYUQI}WP9TfSSTm0eo zB`GMshpY&tl8T*&a{P~kUBnyZV6N<``V|sHBOM_I!LTcXI5c6|$Xw(HQf7iwTk6`8 z7a#zoY)e+4oJ3o+D_r3)g#y%xPFq3@57A!+P+Nxr&h#DB$Lu>Kd__Fom5vy`Qsx+L zw*@AGQ#=_JD>@qBCpJo&^9;&3qu{W{R&LoVBB{$jcQ(1yEqo;IAz4xjR|)Do%D3Q# zSY}({Inxs}gL{e9&4$zQXbLN8i!?KDyu&aB7mPiB1Ye}i_NVyt@t}yawZ|J2XsO|3 z68(X6JdjhD=~&}>4mjtcrI`o_NrJy2IeHryrIU+G8_*+A%o+~fNhiVqE1vDU8h!53 z6UE#YZWv7JwZBmvMYg@t$m8)jIs8Jofb0AB*v^`+6{$q^e-)7yuNSWCYMf>*zbjKNLgp@XJ5H%7FoG$ z@3V>Vpv}(UFV^X9G~1ye?X5YHPfLezC&t zsqZ$RQ-=^2oe@R#)h$hh`Js9qX{W^Eptys_X3z|s3t^j-MCQ&fLl2L%*eH)FpZ)hl zoG8M*HNbyLM^s@e*3vc9)z!75bZpuN+5Y%DHI(w)%Cj^4Yn9)&%Ex-gJSBbxL~uG$ ztPBDv$)Wg`M2C7r zvpjl|to5dA1#J^WR-*~GxjuO&CfJz?!yZ-Meriu0YeJbhqLo6}c9BU;d*rJ$TpWe! z|Mu0*cSi884?>q-Er9@4r$(5{nBrG}On!_kn#q|>pfm!DN6C#!6 zfAp_2AF(cWfGRQO*gCU1UpeJ0^5)H(s7m{E+6OQ0E|F+hB@NimWEDIe(dZ%?l01!o zLgSik#6gGLhdx(!L(@aUYdDTEoMkL;a$A2=Jls=9-Qc8~^}-DTlSC=$S}f2Lo8Kn< zKSGkM+d&xi3iD633BEBBvh*dPV2v?n87aW;wP9aQ}M!8QlJ- zzj^d~@m;9nrI3X%tbcl0MXxn495X+HQA~+#5r}_(S=3CVtAtMUpmVP<+Etvq0$@=84LP@z7oNb95pd#V0)SExR>~NR@*YG%PK|&-Kk>`! zyB_qn(y$vT6>WvJ|BSg$Qo>T1Si z^c0mJqDNn$Kc}FYbn6WKT0Y5kdFaR!@+ziC0*@!F8 z>5G>xO;!Egyz!>9jf|tYlD(&==c~TlSKHasN1sHk$e*Z6A|d8_bp_R9vZk)dpisMm zscf`_QuVThyryt`3cwHbOQrFM_YgOl8DhI0@)Ix?mRsBn0<5|UR!@73o`sF#h#M$k zzRW24{;>cuxdC=@9TO63_)YcgEhnx!98F_+<0aLWaprQlJ0uwsR8yXS&zDC_ZMC*BtEKYe_Oi+cDO`6LV7$zceia&x-&6XY2i*bQfsoiOOo6#)?AN>sB ze^s7@@r`Es+h^#QRZ8D?sxh@8nT;(gK>>l2Cr@feiMq{C_H!h4x!*eLX&U4D9ppA+ zwxk6G31Jdx#d-k?nu_afVB}TQjYAY61#=hogK8!-7)~gKJVtp(+(G`F38ES>`-nDo zTKHXvw<pvL>fwC(H4>ES4m`-J=J3Z(ae18O}H(?pBN<%ht#O-?#`j+0HY zy4^v0y7r1TKQmi%_^RCPI!H9cXwSrjpgh~6iFt?u@4tBP%zaH{shqY79ya*{8K#{4 zU%tkbt1qE#HFc&HBkgyHtC`vLQ<*X?RHfC+ZQYc8Ew(uq)B zieV-osP6~Sq?@|OT+4X(O40#L=L#eWhXWIJZDMO;$36*t3HN|U1g~91bm8h_Rv>&j zWEJ%*Qm+vm!;CU*dwoZn)m%vP;Ih02++O$t%L{NJ>I7H$SP&2)xCF)j=h~0h>4WUl z@Yf`WTc#Wi>6*dz)b`9BY4VgRKB)rm%|QJqL^3t7{B#Tkfy7TqCf zD`NWc&n9mj$ml z3(@gzB8KOaetm2zyOHkKv{h!8FGj>J;+p#YKnxvK7GnmBahRcSbQQm>(x(tD2M6pJ zxbhfIjVGmC<@8+t1`+k!&vXGiSBSM)Kw`w0F|acDaS?jfAaoa zlGc!tSRF*Vvzh+*c}=sm-8AFM!!$|or zT}MDvSo6hjrs0zBbE!BRWlL>x*=SM)`;_H0R7Lc6cegf-IB)wA>E5{E^7<*{a56fU zjp9lT{Lgc;h>39^ms>%X-qC*NYdv}5?C}{#U3+(;zl2LBE+lY`Qj}gkO+HI6^(2=6 zLc%lprMn#E8Rix16|tm4LG$hvL~K2{>6{fhpIPEBcDmC)wxkbA(2UsnIGpMisjYqQ(uhShejb3uH;94 zVoPMhOaT&lkTg=agM zV+mi2kfJ}e5d)wT8ld~#Vn?WcDFgOgF|JF66J!Ysi6@*hCLMqH(BiH@xm@}0K2KNY zbyoHN4$I;65Iwy~*OEN_&gpYbb>=gturD$C#FBN?pP(O;ZRf_vCGJ(tP#LGR-5yU9nta zzxlGPMzlZF$yDUr+zWQR%E3sT#vb{lTeX@I+{k2B64F?l=Z(8^asVeHA}q6ZU*Yn` zjh#!+V(V*TQUu*-<;+l7MH*G(xeW1$eGvaCCzjHQp`pQ1qIdzOUX^OU4yr~mjc0*Yjs zgr9k}SzVa|p@&%aEe+56jr0}QvD-Hi1<^K&()SM(Lvv>^+6GWL9L|kFy3PTGtB; z?;i{cN{X{lF9;#D(FjDm>(1o|ZodxFs7*Cb!xMB*Gp84xIBL+mwi2k!!M8}x_FHUA z{!D)2_SHB%(}DRYdF4Nfbt*jE@vfu?9i zVfLcQka$Cxy!thkuHrfg@lvhmBjic4hd3Tp%oF#z&+1X(!)GSp$Xu=LG)p9?2GHbLzgz@d!3s%omQ{*x3AV!@Jo$uPwoF~`e zj>A7wq^bJiJR~$A@|a5ZU~KlSd{etqnN!wzUA%M(cyAW|T&=qK+`zYk6}Ru{XQVZs zRl2V(p+#p`ywm&S!i4mMY^14bnT=FV*E1uQs?@g9Q{!3_eW43{#|CkulNR@_8e^?q z=O68fi3m$_x`d3=ITycn^0p##MYZnDC})^zF=Dp`3}t1UI|Wi{_pl=Vf)t+AiW&%4 zK3dPPTcCcoE$cl;XTgMyCae)^IWIvEM6Dt{+A$(Xm-|@l`2}FOOEXDub$a68At_~) zWd$Te!CXe`qPxwife&3Ug2#zuMyY5Q2hGJCN>1(6B? z67iQSlOJ{Y>I+DICbGHA*|CVil0uy7HE1(1|JZw>w{iP+EE2fL?}eg2MR*dq6hu|1)Bl% zb~%wsDPi?IYBz^uSSD}sdtY{y!`2`Fil?bsAtk|GNfq%PHQo`akdE)nd8<-&$VBHfH4GE<2@xl(y zor={puT|fy2%o<%L2_cB-KHmc07OGXbSY(&($A}F4kacdc+gE4U!zkcRtq45SbxW0D^G}n4i0_T4iTOwpE4=pW(kKTknu)F8mljK0VTENC!{((E<0!>HGrJlI8pI1{P_D}y_V3=fRhMMpYoyJd+ zT(qN%iUfyru+N6~)S7JtmA1m5XV!?lTsxSe6ndEZje^;Yz(#=szUfe5BWIGs6dijy z+%)2{FUL$hyG*B$YQ-jSGK)z`=W=_1nd!+&SIG;OZkl>l`Y~8ZO*ayiS#92$v1bHd z=UjCNJjpUB>e+@rrw%Sue$hU0GJiw2?w*$HtS6JdPO8JDAuE%S`3^+$wJ}4)gZyjM z$G&{=74j&{cgkHeYwzNQc~{Y8YZ;V>dy*tGxBCT>0KNu|e2^awXB+KGj#PqbBN!}n zAER!7_WR{l$2WmTqTEyDfF@RoUZHn3D!F^&G++(>)+fVVXxffpiSP=mCP>I0O+4ie z`s29MMSq8rTKp^|qZ-|@iKuFl3OVolIv{p#)!6>HvEyv2FIcHJS6|D%sEN}%Qm8%I zC8r|R$Ua2hjtk)#640@n73P;qHVz&WyrX{!F4V|P6D+Gg(0tEM#d7pbaQ$;}5v?OT z53&TwRf(OXWX6i;bh>(;V#$C& zpE4Q^8F4u^icA036gm1|-6HENO*Pf@JEojRD-n)Vry+foVfwq2H$uI1$|d;2rfw>6 zWRP~-1_YF7Df#<&Yfm?kQWExL*?v>37&OBUG<`)U2nrG*`{1GPGR8X+(|IPQBJ4jD z3T4!uZUg&J7s3pY6Q#u;rIjBfoV}@Lr9{OI(BWQoRAxvC`4f3iAtyo2hj~s1Iw%33 zL9h0UoPB4prjyiruU;;nqRPEM&EKMjy$=pbBlB`>$27d=Gkc#G4?$J)-k20 zBANS!O4Y1#W9y>CwxR$Nd#4RXo}FLE0+<)<^mP*LQCR>R$z$77)(-w(S??RLiJgz~ zq6!US!B+Q^QvvEpFSd?l;ZL{UcVg40qG%^DFMfmtO~B@o1<&coBOGL8WUTMxPf&_R zD6ghY=SCxA30_!QyXhTOF=ZBY<&#m}l)14wC+5Ej+^4R)aWFZ#Igi)dc0+=Q(k<;J zN+~*GsK2^287L&XTTR?S`)R7X(A)=~cPY9EeT~W4bFp561^CxDfHn%jbmDar@a76a ziqGsz`Y?kn&=$LLL4;-%>GaKJ9*P3fTvBc%sT8aEnOsP5gO#meblldqM%=eH7D ztF%c^xmG5@aW4`ZHYYUQO_``%!tKGS;{)z#r7*Y>a9kD}iP*H}8Gsd&Ow}BGB1mF~ z1L7wz`YDMEs;X?}20+F9Bol2%tXSAxq_v@k)g^S4&|@#}CPP zkkx1aiAqkFgf{D*dKi`|z%4I=e%XIMs`4o# z<`_B`-;kuxcDl9EiP+ZKH^H4H!v$B}c5W?xpM6MK13iuhXy5+n z;YSiJ0;dfxUWtYp;d6yP_-|fXqO<&a_&K_7Sfb`!Z|>Z#O*LJ&N8X2RBv|aFq^h{V zZH^zJUn^-Go=AP{~^A zSS!`OR3$`P?aI^RXX2tuYgEB;o<>_ZPak)Ms2v%dF>zF$)mH2>icd8l zq@K9hXkNW`X!CvSz2Nr&Z{+bDj4UoM3w1yAb?VFge~IUcF-y?_JLon2UQv*~s=cMs zxP`kE06;I4X-ytU5hR{$DrKBnu|FY0ic-hs&OT z{LuU|Ecxf)GRngJP`E46CCDJWuF49Me-?=l zjQ(NVA#!L-Vb!Oaq6{+99p0jhl3%;oPCt^d{j>gGqOIijY|>hgq}J5kg)F z#Kq9&rP@W`B5JXE2YL&3e``a6{FiP+iv5if4i@OsOr7oP?$*=OQ$J`*bS(1dSwvri z_NdD|(**}zHxV~w=iqK3vRreruk`0`Pk)DiiCoIvvADLDNcv0Q&in5jY*kk`o(Er< z`kdOAV`uz!OjMcWePrG9`L90hxJzvPNq0v$usNji3P4YI{lgrPWdD5UKSsH7Iq=C- zpWs=(acAf8&E}W&fWy6UNE|e*arX_ruEk%Srth5Gxr-j&*Cr5=kD((f17D#*);v1= z5{7i4^Q@L-c%Lhd!#}=NRJ5lszh?A;i1U>$;Ce9F_GTTXR9l%*B&8l;49L5|j4>Or|#wE|0#Aaws`95=L*6#RX} z-}9v!>oq>@f0U%AvcVf%bCUAS>%Agzk1E)%Mx!P!gldcT^Lg`(PojD9@~L);LSG_Z z#2&iz1}*yaf-53v^^i-x&#Fes;9Hz7=GO$`MfcCfrS@X<^doaq81LUgTz>r-=`)l- zhx2Bg=h5YXV%R}25B%G0s|1a2+;lQ|sio$do5qj9Gf91OgGEj?E3_mVeO;X9rX`9| zw{p@%?vEPx1od1?qg+O$A)@P>Ch`P4>k~SlfZc1wH&f1A1 z=T9^s^V?WD1)VYDl84qW>EBpW)LZpFRLLC*c#`oeunJ$~dPJsJyjQdA)O3h{hn)9C ze_Y1yy>Hl8977*O_px@-co>yos<+> zi_~Ev>D%lmD8oY8>R70{C$!>yvE;|cs%ZzSw||&RM%oPWcP-B|Qo@cj-vCDzo~kq{aR<<@o|`ar1``x9~;t;!8aym-E> zNB`_`25qPr%Bx^m^SQ!<(bgCJ1a?$19POq-=f3u=h8W^Y`cAG*&}mZ4mz9hHF-Dj6 zBKiQR;X_3-2kaXXZ{?h#(PzwTpOSvaS}V)yI-Z@KT`ha_qtk?{v(W|GISOoP_t%85 z)8vOzyVOEAXDs;E^#U@E*0WW8RxL!s=s=)?O6=KsB^_~{BUTZQJPVqZZb=VWXo+u_ zyrI2-B$0BW)TZ7QI6&ivx)1sh+%#^3tXn@$aTW*iHi+I-1qon`>XA?NXex`3ptH6;U&Q;Rt0!FF*X8&^M=;uhgjm8oOimiQVvv zPt0<-W?V(+g!M|@vy;!J+Aq~qem>+_J1(eear^ewqct0)g$AQUIYBI61XGw9#z)=^ z&t%A>#-%&{>+&XSY81DwSds^MJeZRmgru%xaSsNnr7n-o*Sb--uBmuBtlWHsaE6?D zkZH_-^|ZED&6IiE@2<0Jo2{NVnzIf?=)Ui7#Bh=4sf-LAOCCD-skgEiv}Pb zBAyq8nuHudX$$z%>O?U7-}ZZG<7e-ru?j{KKm6SM`q8i?m8Z;WC-Dv^_wbCh5uUy% zi}M6pbm3}&51Y)(>Y@hf7)0JEH*{EN`zeZ=L<{rNO6H{R!zzVCv6_G2v?8S{upSK z&fw6+wpcacS^Xl22{yl$bsckyxTcl z=|Y3I%?YON0x579SVb zai#9ZfCf6HcS;9cdsY*Fd#Cz)q(>S$Lkxf$!-HpwZO~rUPd=SU+hAw)^2LF0ua&Hf zTLeTAl=BS*-d+pxAjqJ6J&?WAnmdm-L$bxi+f6e*Bn!5^Ru9UHEKgfz6JQCAGCbIX z3(yD@hX^D_{s4JjOW1pzjydA9w~FR?kPK+bqPW`*6vvGC5_;(=qroLm8%8a2Aq7pr}QBL3|-YgDc+KsLgfVv4_w$pFO7=!_rBIOKEgV)AZ znH)`|G91>#-|rL}K#Pilb(CVl$zoO5BJte>>akk;ym*QKsPGA2<%kj>f{-YH9VI%iGV zFH|-kWGZwu-Ac|v9#Gd;dic5~CN~LmCPnnzzpht9ba5I`k<`q#EOq7BAb)@V7cY+B zY>`}|+qDc|kI{^~i_*FIzNC7otglqI7N+%DAkq9p!}(*uU)I0Xo@r&NP9EoAS11|y zrf;SYl>SJwVEoQ`;>tDcyLVXt<$)g8CNBM9J>PiS>oqefm1duVeDec#RGjT! z?nes2LCquax^Gg9QpY{9&V|y@;2wm+6r@LMY2)hk3B+<3v9qZsru=^ zr>U|GJALajLYKJ-7;ie(xnvjYFTbb4(lgrTjfr*`A(4U9EW2PO$x|)Nvts0^CCPvYNx_8SWu0Y3$6rMf;jqV*pbe_x z@<1@Onyz#WUFZ;h3lkhV5tjaw&LWwtpb7ZZ2IR?;rehtQMb<;=Pi?wzl-^QvsLCrS z2rnKu{-Wmf@3YHyzg6-dZ_c82$`0>-%Et04@roRche3ud*7oL25-|q7r4K%H(~j+v zvk2Z*;L3XC@+ic3IA{ml;TxbGjLNFMA_}zV9cUYMt8lAVvR24Qp?(pk@A64BqmD)J zSeiRJt2Xu>#1M4V9A_B^s#Gm^FN`^90QDG$k?rXo!MS^Rh!eI9m-1Cw?SSw8_WMfg zUW4Z_CIkmyf!h^ngMQ`(Q?@yjQ>iquK+e|fg4v*io>4q|A59r%$B9rwte$^0(ULUs zm?lx9dNlh2MH}b>#zY&=y%R*luvMJV#D|q~fPDhKEC{#9-VGws_Bhi}H(`R^56~9A`4$q&H9+1gP}GYd`(DPyVe&<_)I-1=Zc5k>QL&Z73gA@8B5}RMfPWWJ4=4(2T^fS^IL;1iBV^@F_rbB z^=EDx81Q4r*b>#*U^rzVSgEA8q=`L)~YK7Sc1Q`eHIW>+Qsc;UaEs>=LPFA1$# z?YF!?gadq3?4~5-hn21_Y4MjJKhO8HgCd@=o*zG#qnbf^Jpp3Ysa8C4K`;~=Oc#92 zqh6wRT-BJ0u8XkMt-YP;Vi7FDSv#w$+o3Oa-gq*rr&go8#zNWCSM&0ga(%`(nzLaa zq{jMUc}2R;(R4Iazqp8tDc8PR&=XUvS)M%&X0_8=vWVeeTl;wz$)4DS|rVQ0n#T@~$) zKl3+DSVfQRT0&)|vsc@wG%qne;b-%HVL|oK%}N&bGh@ke6b_O%-hwtT*>Lzd=t9Dl z3D=Rkm~uk|8nKbE02&-iQ>l-&Q*k(j;a~}7=puksGoMB5HdSx{kkS_M5aRV}@NC8J zm$AY-AF~lvd73ISp3~iw^t5EVY>C}`#CA$`^c*y}SQDGcq`-sSeY5LZmh(?kGT$o6 z9pDHVHb})T)l^r@+Ode@g1B%}({Ac(iDWWJx&n9IQ0QdI1@kfvt?7jPbHxMM9A;`` zC#D9UrFRDgkPrDgTh*;^kk9fjIAMoU7&k7|SAxR3;BmF>Ui0?l`)%~`o{SXNYzQ&F z<9plX^D|4EJEo5x&y;k3-0BWkua*F_MWz#|YBksJ@0iQ%X#?$IQU0;#w8W8^0=Lu` z3kgDOD(`bn>CIYmO)V8tpgOq!yrd`- zE!p;8*tf6{$w2EPOiY6at^;kQJ&;&-H&hSbmb(Y-=b`Uw0qD{@@KQHdW6Clj*nvUA za{trxST?QSaWYZkK972aVrj%WcZ>@5?vdgob*}wuj59^@vHKztDIGV+p zYQtE@-un{vmRetGV{fL`h(wox!FsSGkxIo#^jJVv_P4zCl-&@cNoujoKG`7MFT00j1n*2UqBA{>8ns-` z-y(aG@)Nm@%~$8mEl@;t&Q7y9O~QOj`+Y_mO!mUem=VmWAijsl9$lPxNrEAzbWcb! zd_ndsC>H?Mg3>z7GHN~Pb_S?r-IcS`-N6Zda0C26k?9SCk9)U}F9%k(&_TIqbZ^`n zgV}(!IUIDL3}5WM9tB-aQ-T#}(c2%aAEWN%Tm~ZJ)AFXse%_RiB}%HlV|nPa5C)TR zdZ93a2c?5JQMY7YpSzcr2@>-SwS8ujpLVOrC|oW)o+eQt*mC<^zDiXTVF5aP_?$r} z)2Rj>pfP^x8TmFtjn&ql)4HYLtA1FrJFyB~;+0nqHN&n0feu)B+GDcPp0YId(fOr} z>)V&T49U(`oi#TuhvhWxay=bItP~XR?WWBN1h4)JNMpZ=(u(YA)`2bT*tQfp-py_A z=!0t37fgNO_O-Q5($zlSukJ)q2}MSueso>pi6+waa7q!|6D7SOGa(&v+^27d-Y#Jk zw*EEwHdv;Fk=612v8`{D7G{pTF4-(~vb6d9YZ0Ri6rM6xF?q=GQj?1cO%aM-kuX+~ zcf6D_@9J{gri3=0&tz>fOXxCcz(y{Bcd%xY8mY^C!_i9gAoC#vZid~_Z2~GDZ0-Bp zhL$#F6-5iZW{Z%39J4JOJ$EgnfD99ZYprUaP);g`1nu+ z%hvOsot(pQ497KtRs7G`w#4sAi49%^j9MrHJZO zLLGM3;I}+l^1ey3F^|U>9kaN`^J|O5i z)WGpzEVuiEEH_P9r1W8}wTL%nrA4=q z=ndQSEM5Y-5BV8(VcYSJkhOQWAmblHft8yv@DS>sWW~F}OqYjd|6?E8Cg3}NZd0mb z)Qjd+M%re~T@gM`@}WwmD}0FbZfDNEcak`UTW>E-#m<&rab?VV;RxAlO zerBD!dqn5@^;@zxLrLoTzD_yE9w8N$)lVj4VRdPr39iCldC(L2>7Ym#*8F^3)Q58G zq^NCY28v-($yDoju+A@@X91l*U09;lJ3LO28}BsHdppF3#n+UCMf_a$({c{1=RjqU zn0m1~gwttbfd~QQ_-MZ{DW97@gK7NwXHtPPAAM;<{g%Qti275&((``py0r+}@F`$j z{vTOy9aiP@eSsc9L_|6iq`SKhB_Saoji7+Elprbjf)dgVhwknc5Ks{5gOrqrC@rC+ z^qp5f-`{hed;dSgnc1^v&)RFP?e&2ozz$YMKOXo;G{is*#XK(Y6D?WinE=NHm{W*L z)hL&JI0trW0mLs$yaY_X;%?d5#$47<_LoZe z`|S~JJqIuf6$FdE0Vl~*0p|9(!^Cm}u76inz3BgKjk-Apotr+DI2-H!y<$P*8lTei z2L6MAWYEiu(lLIjs?FJ+^zYs~SI z9p&38by8fQ__f6^B2x@`vdS;wy0_Ybu<$cIE24ni+hA*&Hn?}x1mtf(oWJU?0?XgP zd4Su78GXUCx7OovfrdvKzK)h)PR%_LuXy(ZeMHWUi0d)8E zthzSQ6Yi7~LyT#06+1an8*orZDrp=x)a(ROQgW{0a0^{iB}Hb7VJ%hM=!U5!nB zMQW^gV@}7uV5wox3}c+ha>{PBVVnSCPH2e4aQGvjVGO-V=Hoo!U=*Y1g*5PSqS1$5Wlc_ugtffx)HBMt8&b%j98dQE_?O-=(Krd@lsxN>_| zZGIfELOyK{Tk`+T^7?-6du8~BkG+I_e5rn%e9eeu=fV{3%O!{OQ+i=k?YmHK3 zAOHP2{+WDqBh$=l=)tZ?n)rxDhgq4K!Mh6PN1qLe>XegIO!mUchaS!`#ZP#c3oA5m zs-QNG_4hNcEYMi&sarSgXf(m5J$FU_ClgK|1MMu}(&j3Hk^pk1-50&5Py$L zd2K&8)ho;^Ig%KiV&iDQ-GDngVZN7bDbFC0{ED7eXoPMbEWdUiVoKWvB$Y+}($Z`K zF3thrOVA7|?e^;X3i!gAQ?6TJ-v(fby6cps_Is^>gAp7-h2PUNGyEjP<~*ny6eqfzON@q97H>dnchhbmzG)$my3>&z--S zw>`iw)(WiZfgKMuwf0AFZ1Z0@I5?E}jy`L)DqY%)Jn)uE+Nprd6U+giNT#z?XhP1! zS++YGRh;EdI9)_E|Hkk>zUc*iO)=CrNNSJMul3(K11;~n;~lT8PjMF5`F~Rb)*9Vm zjv8J{aigx1_YO9*^&5=Llh-oCk9YB0lL083X8Ez6$=nlgL{2kEo!L>RL%@VD zuDWv{0)=VIVah-iP%QISFC3}gYlKyWfGv6Y!baF#=mALJstI@KO*LIwa>s&Kl;HCw z!O-7c`#>*^jOA&t(6*btX7ilhazgfv(nur4Ad6s>yvUN!z=rqlp^UBGXESe~%W2f1 z8&QHeYhQ9m9fb@@)16QjaezW(bUzxBvr#N~I;^+c%?18pze&Q{Uh}fmN28wCe0?H^ zMN?-0l#jEY!UMAz3W2WJK;-)=#k>l*;DN?9$fggRF$I`l-l;RR8_AE5tpcbm=6T^B zp4Ux;Y$)Gl9nO-R#OXR?)U8C;tQ&&dW zN`@|*5vsb_lOTEjf+tR<&c~{nPC9?1R$!D2)zBP7E&4bDSRd815m*MgR;q%m!(X{L&MhscK_!S6!P~B z!xlTBC5~VNjKjY~N~F;LA%R#4D+?7ng`34E~09qL zHg%G$6|1N2cigqT#=`5MV;|;>D@R?|AhFEnu3t37u4m3^q465}ezk(s`~5?}Hfr%- ziOMRAS{W2Im!Xlff{&S^eH91o3aID~@=#=cP9-}x{~WFj8l=i~Ml1i`Ug7}HBG8~o zr37pVK3rd9_Z@P&*v z()+*t8Ww#`#^z8)nR!HP-PBT3LwLGxT)zzWV1%t{a3v>$LP1R}dA}%LMZ~^IWD?1? zs;?z5@N{@DAiCY)zF? z<25q7?}`q^-N;-{(K*BK$LrQnHW;f|_WmaAnM7Vm^=nx{}=|Q2U=yWx%UT4mD!yUUYV^ znEJUaVONYmB9R*p&6T1MirNbm(?oK8{V*}t``KS&Elp2UDG(DB@;1 za0fPR`kTiw&|&=<8?Tt`an8HU@jtLT?G~Tgty=!|GW+WtD{G&Ra*)lt7NimPZtm6*d+3=&REu>MSp)?NVnIqcQ3G$|(9L=4=! z5ETcHyvJjD5*OdKcUI46i?1NwQ2{a>8_byV75uuzWVM1Mrg0JY2FvcJ;|0laYLHW>&JvrEsaez z2L@3Zc(>UY!GsvP7F_T*$7CL5cA0x!wf2U+S)>bI%g+}Aet^Y+^QX?UTtKjUi{WFg zRy|d}dPl6hL|vR4>5~L8<;N8O0x9y&tvbU-Wf3+!6?XPZmefP1CR;lOdzGTum;H%p zfYW3BQnP$AzH5bWiNLGWdS0PC&751Of9*4=yLT{Lk*vIl?|h{#Rj+Hu6Wq(XzJQK@ zt9#tKHvPdH)UVe%5=fM-0i;<|Le4f7yGGVFI}DFp%8eG7A3CmEK_O zgcIy4D`9RJeAol5!O`b9k{jFRaR_hRT$|VsKGhg1a6#|uA2ooNMf%~_>0-DyTbZXE zT$ojcmW!Uh>P%WUffG$PG!m^%YiLl(w&djcbtxvS7)|9utS#T3mOXJdCF_HDTqO!`-U(I`zYHT>2KO)qasdCq0 z5C^1=Vc5m00M_?zKh9SfSQ|scM&h^_s&U1@LY4c;3BdSiGB|B1dJ>xh`uXL?tTZS-^?menc(vUPZam4N4B>us&M9CD+Yyk=7SV1maePY$y| z&K@M&5^1Um9i&y4$K%O%7Of`9M!%|>q=ixW&22}K%d|%Tx|K*VqWz>8DSbotBDIwGXJY16-hC;%{IzK_sj3ohHN!K#BB$+CA8;_lgR zhU2^Tsr*5w4`(ceWmKw5=9Nn01Xdo;KCSna>}nH)9z|E()~pn939n-6-*>OvVrjI{l(#06G$+`-V((~?OvYG5vkb|ucA9nG}Ha7p)hHy85;ZPLpXHMDURisc= zD+z+7@yMzegbuVOw`ZLOo@b${l7x;0$`ReEXLP)igd~l>*Uql=Ki4N3t5T8X>k)d9 zf9KY#_wSzVzSdx>Qb?RBN?T=okW0Aw4q0#mY>X5TZ+iE^8!XPC@X@FY$*I5tqo(8RCLWkNG9 zo8i)vc8uksY^}r2`NH0jD+T?%^2=gQ?K|(fSrwA4Pq#_$@vLZ=R;j4djDkf>>yQ4P ztL3!s?jmUz&gR2-Z8TFFR$X2biqJqN(q<58L)+Wt5P% zlX!h<6fbaHt!&6vqYDE-AzJY(#6)9>k9f)gXa>v7o+W6h^2|37R_sd>5aL4?UZC0B zyREF1yDS6lta z|Ddi;X^Rvb>b+r()!R9^+WU-nlU-l>2*ti5hUFrXT;`G&YLlVbp`M! zD;aiQM8?cqaNRL@M0nzkv7*Z+;Ti8{Z^hPwEGcRH@L?~bA1RR3l08YfD}CQ9JAssz z$+eH6Uu)GbTpPTc{x(21;06fBUz7A6`B`>*(otfE!XhuSKSkIidpES0*bGtNXL_fPtKROB zXLmr=##HrAb7A(?>&-r38F2Ur8Qz@nhCQ)!R{#;2+cC!yyrp0(skeVw7%i$DT)-uo zj^ET7PsOljcltu`m-^}odtC5A;EH3hiIya&h2K(}+uGVD$1$I{Mb2n($KSyZ#fr=w z)!XlUu0gu`PCjr*Cq2XNmNT7**N(36QbK9HX2rj&04)re!p1Jkr0GCFk>h~zUbrrN zncmT3!EXw@!eLS~7$IO+0Nz=y!=nFg#E|P(r(zTJxCm@pkdH)QcNt)WsmTZ&*#;pV z*au&>@;L8B3HU?|?0jB;0xyJBvCO&Xq;EkopP0YzpZXcI$)%uDDM&b%oS@8f*(YKR zmK)s3?BStLo9Dbi5oCw(YEnJzS4dqK_2HW53UPp6*zePqWKz7aoG=hic;E)gEPzwc zc;%|`)%Ov=2NdMUH2!2@);5*ETP-oC`?pC>8?3A739OFn!OA4%UJe#d+LfxFn47@Q zQViANAAV>k^6&G^bR_K9nyAMjdPxR+iW^k+qVRiool8#${(U zBf9`7K>qrg4mkZY!&fH+M-u)JM(1-v3A}%-Z*bMRW@v&0t{LeJ5~_9NGSQzXi)}&k z&4)Oi+h6!C>=nPQL!O7%ANi2w-XG$M8C~&m5KIOqZdCHET;0EsP-Z8H6cCQ3SPNXj;QPlUJF5 z!Sn6-9f-oO@e02+VG!?&*!m>#p46zmHpNF0iCSX74DkP54FL`b96+~YDjN-mT7yC< z11r|J2o|31y?+vGdGN5q@!qhQE|RK8{y94R7v7Nm3ex*Azx#Cqz5ZWRE9dx|W+HCAcD=iB-p11X8VO7v9pgNi;AwSM3$;`*acq`TcZEWG{= zu&{CeKi9zFB#1(iYdca&>E|trS_=iA_AC=ge?(S0RxU2}@=af1@aXfEHz^co{j~VR zVJ42kuDtK7o>_Wn45`Pxl6%b*%;jpr5>oo{t_&H0Gqs_N#QG{4btdGJ62=U_5iZO| z*giK~7>yndx!_yP56Pt3skt{~b=@5D=o8VqVt9YKj|bWuDLA917OO0n&SbzQYfGj_ zMrB2netpT*%RH$W5#&3T5p^0p+xJ!)O;exN6H9B(hKYc^B{o5Ru4nx?xDcP8a^+oO zQ8>6};vdq$4wj8-Wj`|<+nNViDZ9Q!cM?pP2mucl{99(8IUhV$C`ZvbZhB-M*+t!M z#O#oFa9@YHs6FlMhbm61GWn*Ff|>{O;IOt>SZjUr!^yas+f?J-P%Wr>qogvp|FijE zy6>_4#t&Z+QZFU9b<2Ib=jT6G)DuT?#f92%$N1XAPY&q81{+5Ac-i31L>n@tPZn}7 zit@K2T_4vPcU#+T7Eif_NTeV5g``N<%0Xq%ylTES06Sa+!n_Qm5azIDqBkw(Xc2_a z@L!!V!*>Y)-%zHDfGsDn@VdIsv^D1in$8_!qRTq$qXzMsYqQgs&?)((V~tc zdRXx1Fpr69hnppfq=#a(9bjg+9>yE=&)9CRnfiRF^K$JjR&26>n5af~y)xt*Q*O$n z){g|lrgShyWhG41-|k`^cm5dl;FO$6lE)pLIYSasA^i1WWX6U?w#{mLbolu@(h<>u zGD%58aVCISgemW$w&av2N>ia!+9)5tME#|pIW)3-VGte4c? zQapXEMw?Lo)Xa?DXd35DY*pE-{6L@XeTg`Y$)~wXaPvsxvtBvssOzoz26gSsd1oDNV_uEtYS0*<%W=pU;hmDu zNI9ED4{qy-q}DO^r>NeTiO@xQo7?|*b@}}Ft_%@8jYXEb5L{#0bjiJd%U4{ZQilYW zHmp^Gt_Ak?{6`=`*fAM{gyvf-35bkmz@@zgD~rGvh~NK*ehSC)fFS62NV7;Qph`yT zC``=x{w6KiV%(%%Y$Z6e;S{5z=vqrg?_l{u#8eG>^!e;zIQrMbJBCGFy=WezJ@U+~$-Q702Vf0D#gVFwF%hNS_kfiexM0>1@iH0G zl&lgJ^UZm!lQ(^|5@&ul$*xPw6}L072040#Lmu^_lYnoO)6<*R#-VH0M{ROH76%jX)aYGn$p#d zXBE=qy)B5HzT``}@+pJHm!4H;7r2S@27BA~QD`1(I0o;?DzsYEPPs^z9I~n^tF%8E z!fz$oq8ARO+bpcZO=4f523kfFMX^qb>!mG5zy+Z+W9@U0&SKikp-k8I#75&ZeLVnY zT^^kRPdjT#43yReIOU2KUhoypZUMz70@qo@Fo}PV@s7>Vk21uQXy5|yI1MrMG#PwQ zyjBuafj$nB*ICm*Q>G2#8(W4yzP92AJOY8wqd4#aSRP$QSPR_;v6JzTX7>p2QZy)% zz1 z_P~;R#@bCQe(@7SO<$GWZtkpfpzC*M)!9>ZEoMPq1BKq7vpbnm3gXU28O zHw6JyDK$q{36+q#q+OhzpTZwW8{vrD+kwx%0xTV_VjE$=V-qm(fu1$hXB@z86mWY7 zbL{oGO}U`su6jupN9seG4jWBiENct=r5}$smi9{~<&G{^#)S^Bz&MHBTlB<#pCMIRgRa9D@5k=&hu}7{ z*}*atez|vfRJ)h0dk)imv!<{U7l38kN@+SUM`Riz)bxRecyw-7#P6VO$}G*jrq2U4 z>bij;ahmOabE#ymCtcKE{xUtMy_C81JcUZaSys+4g@1v#6STYp$XUk}!U1&FVap;> zM902q$GOumG>_&|>Di4fPe^cz7y9UajzHkCTpoyB-bL+qo0px6E}wYL z80gZZWfvB#5A!O?VyaJ8;1@tgw3qEIlc~(54{2Q71sI((+<={W(2upD>)K}52+F~- z3rR<6A0N@K_&eR@#ujG~5bo?D+qM9Alm#WT;G zt0y%}PT=>swV`g`xCdAVgCE_hm}^XF7dY-HF+Nv7#$@n3$@J;lHmd8U5IZ;Y=+v$- z#5Xj7Kpyr8F7$5wMDK&#ZAMGA#_5*}^WO{Mkx2f6y(udIf<0l4CBz(^92cUj``EE z4*{EqfQSDE@N6VfN_XIvRDmH_Zt-Uzw7vNQuA!WudWqNzo6B?P$5M&zZ1ME$tDxa; zX2_QTQeUTO#vDRkfvDlo5&Mz7Wq1-oLBYA1JJ=OjK&H(lfuYZPr+%u@;HJa4N#gOE z+k$wQi)z}Hck5+Kky_2Yi`XI6ry3E0vC@asLM~FFMf$0}0^Jw~4Y&HgX0jtZ=7Z`d zdYh3@+pdQ25SyDBuj)CuSnsm$R5CuTT&bA+KxTf^)Nq-!PNogm){N%5V_-UEDKG*3 zF}*DARAJJtC&6UYg885WKVjOwpd@G*Fn%EY^ssQtUoR~Cg&#F%mkATVV)=cvge{XG8lH9?x)my_=uUB8l=Wn=pw zHCQVgG!JjDJ(^hlnCFwK9L?roY}#R_Q2`)#98|rHr(U@Zy;7N}&r8id70uK-qD(6s zU9p~8lpmI~;0kraNWhH2=BQYpzcTwHNrYeR+cJgZ1 z&3_F;p=qc!lwCa@H>C7sJ|I~Ug7Hfcyg$8m_)9^rVlT`z7E;c5*oEwkI<6mfewj#uDHAbwwcZ3a3t z>OUUhTvsz!&gjl4kSi`H-x$>cmxvx?e)J*Nlll5yHwEVMX{$r(18 z?k}!;MDv}`vWNwXHy7QSCNFUgx8N^VSTOH?`|6N_5Bv5*EtGrak*?LOj1ww9xl>(g zOEAY}=?Ab!0AdagHHwAR;;KUe=pJCXBQJHz!Za9U=-nMm-&~! zI-k2RjnZBRbu3H&6#IES+1@vDgw-M72^}*a*Fp7Xi-LZRAvWwghBstScrV)i1TGh5 z#@b$cdBZ2CRLW&KvUsw(cL>bK!3F(rK|Vc&-b9WL_uzK#&Fc?sd>hetRlpeShvrtv zyXWE=@zx0E4UQRlnjkbDzUfgWIdb6$pRy%OzU^!?Tg{@(7ORVgLh7pE*rVEB7fzim zw4|#R7sSPdsuX_(JnZL67he8)9{j-KTZwDggFlks;I3|Q-tnxnw78a#pj;3J&z$iq zL~Ou=IVb=k7Ss7=>CAvs9Sn$j%7P5<1(IsOag8r_evuQT!XsT*dbt4d!bC4i5Cy#A zrl<$I(iP6l5jD7KmM1F;;bj^Xk>e1E1a1#W3q1s!??+%O%`S% zo~iQQzCU_tg)XbF;$4UZ236}Z>B^N>7Whk&8B7E=h@&4c4KGFl0W= zFF|>Js$d=}!r;77U!}wB8o5$m<}&e_NrzjQ`h?}_Yu7_kb|;U5KHC^>$WZVdSfP?C9`PQ~3TaZG-s3YZn++_5bE59miiIj-kV}`v|Z$%BC3>;CA5-&jAHE zAgJ+Sl^uC06BdkF65xR8s~wl@f6EbLZ)oKBL77p%G?iZif`j1`?OFk-=D>Vap;W1P zNSWt4dRSKIJjLnqk&b_|+r|8MfFT0pl68UU1oH}lfluWEI=(#Vl(%K?Bo5w6?`FZ9E7nw%RU~_7Bf^2dFLSZUp>iA*!kV<$C z0h4QD6qnb=m}v@06L`8ULDMpz~VdtgtgNnqj;=)~}|KgHm$yil0=@^1Q%We;k$ zq<<_0l+)S=-PzSZg!237@ARTf5~4`x5KlJT^1J8S@Nu!t{nn#pWs9qbPoUAx=tK1? zb7Pd#o;D7Rp@|iE@opMamSAkCti?>HA*{z}@ju-8u^u13kSi+sHOJ{8{wswmIg4InDP`SW=Xzn`s9^E$Z750uegW z`?!Vi&orVlD^(AlI0>&9ew98ySu-J>d2O;H!|mbE)#kjis`+`W#n4wkG29kQE_nm% zIqQeWeSK)N_RG45%>#+o@no6fY>&nVi+pjJl&Z-+A1@NPek<7;wtkrXjwTpQ?TWVX zy2^6jgyj$NlWx6Q?A5ZDAQ80yv5oNMkr?~0B?f=ZE0k6|T9O%ms6!f(G4~QTB%Ef} z@6@%m2h9h@za`-Ovc<58BJJRrFLBdz|8BbWIO1Ra(NN0WoZ4n{dujTo0BPA%8o=%C z&6?#49NWaG7vy;Fj2l|8pL7lxx_>@cz5^P3V&~6EQe#4A>m&$RxPsNm9^F1NO+OK% zWo6V{B<(fV$ML;3gnas$*t+MP4~O{_*$QL9p?#BexVRZoSIKpACZbMe4()IM1L!p% z5G=0Mo{2k zK~Lj>jAw!A7%)0FTS_ObXcIxKc!O90+$G=NLd!2dHZbI*hDUy1{IJ9KZ$#EUHioPq zxQ}SdM_+w@{T;djPXcas8Y=$s2}}wZ@7Gl!pUf{Ol&t_Lxbt_<+u*kMGY*b7ExV8v ze4;0YslLTO;!$xW_kQFINFr0TR^8SqTKTScf>nASq5~Rnr@QqrIZw!k1$2?gI~igb z<}M=pFK5aut2vo$Y;9FKU;F&Z+G&`!$I1K|_fy;r`r1n&le%6+c6}jCdx+4!Co)2# zx$XTE&_!O=xfEszrSc8}IJ#JX zwMvW=SGhi)2MY2ocjYNn>(Lr@PKsfIBLoH$}jOYD5zHhnyMP+lCrMhhV=fuv@!Ap6Sla#F}WSm>(^*6wb%J4b5SjTMjbw-!ORCn|M z*Cr2NrZ8NcxK)Y&JlVzD^B0GMB3i?JVq<6eLLJz6lGP&@PH&euw_0e41Hu~LWc^fK z+jH2Ki=irV{fruDa+M~bi$VoyMY~d8&Ebv$l!;`Rxb{M6NduTM78qA;gUJ@YNDei+nRhW4Pt;IWml_b|e`T`J3)rWSNY++-X)N9$X9JwW+_GL!{`u zpk$62#?atB>3hB1ryBR;JwNpwP)Y3kh|E?yeUb2hldyxN5cPgBT-SMM@1DqL5E_jW>x_uXd)IGb8)e`}UkVF}Dvgg$eTFa?&uw7(mRn%f?t zN-y-8FpmORP|Gat0BCk;OuY>j0XnR&Z&f*HOK56S&PzDl@}C6v%;K|Ki*8&jnQV(-6*kW71JR<=b| z`mb22Qj=Q|d~)((Icj{6t4K!cuu#KblK@jSr)xdBM^~Wf*&)O_ERMNI7A#)%bf<oFOpG-Q zZy-)Z_nB`>gSMGlWi` z;EiWL4et;4HUt$02m;7b!l@xvu!5W&O~J=GOY1L>Kk(M77I3v1kAuXrO%kdvVk_6N z$N^2`qx!sWab6xgReTCcNE1Q42D?;xb!AeiGuMS+^G+$noE)|$J#*N1e!Vk%#xJye z4Gf5qcG;}inA2tS2)6-e-RD;gFk2`{p$?BGYHX%++kWVF+XJW> zFoE%G6@aLsBZVz=@YoqoXQ!uMe^#v)w60#G(t4uR3cysfcpMp?jZ(PfhA?-%ZofFx zes8nJ2Gj{u;@oH?n_hh8z#QvknquqItkqAYNvP!n+nB&+CH+C#QF+aX#CKuDE=EAT z0vKoGTRh$YavpZdX5xjw2FcASaA}R~d-T7k06H1gw@TvO-tVUy>TkQqO>qW<{ofrS zKBsYD8RKSur6kl4dZx{K@3%6X51SfxrWjl73cotchy`MP$m9ovPEQV;wn(7G?Zt?= zS-i(ATg@l0m(O`^&7EQMt7!LjP}2GADGm0KOL~=f2BrGjM<+C?k z>tKJwAP_z+M8XUDNUV<$MUQZ0$;haB7>&>HyF1RE$G+^`8w$`fBcRdG`%#i_p#X4= zOk`8Si!)a@u_`I=8H(o3*c*T@wh4ht;RctgiC(*0tgA-X?3Tyo?ODSzAu->8Y(|f1 z*KZBVUhVH5+#24al4vBZ_Z7(hIdB;4Z>DlFN{n6{yq}c)%ySn%MCMSn*=Gqm7({_F z#qpz6n%&HMJ)RS)GzU04qc_Vu#hk3-P>0v)!VFoIG4#Ly#3xx@xnH_FF(INv{HGO$ z&$KbMB&{PC%#8dNFcv?;Mh z266JATZqszpIV+{kZJgFL4h%Wxfu>Hl@A7jfL z(TkN@hfF4*5ZGhzZ0cADjBiNW;;l>gV}eO$6(bveSc)Fj_}0pA@%Pk={kYC88yAu! z)?qbP21{^E)qfJW65al41Wm1PAM$T-A(%$?rz_b>}KRiBs0rvvF&Uang=$O*D;QHjdjN`Nz| zq*>jOpmm-P+06K9l74w3|F#BzWkz{)&8$F0%lkSg0FTQB*bbYnP5{>v2i94<#JsYB zjg2w~os`=NWRr*L)Lq8m!1I+%$NWe@YgfJr`PNd)O(D)t%mw1&5Om(P>O@lz#{c*^ zwsCZ-v06>VwNVbThTKxiS)y(Q= z){Im)Pf?bXNi%h?&&|^wym2tKQS7@bE_|!b{F{S8#N$1{4_kk{r5A7SZy`T8lkg&S zi(se+j1-@N)V}_mnyyLh8umTzzq=y}dn|56rD2|FnA~)3I2J>r+my-HQGGB{ z|99i*03FpwEsY2sY$leev+2vnOw6fFrpAYHAdakvw+Yn59O?MXb^*XuM0TYyMUOP5 z0xnB%685q4S_{}6DR+RsN(t3EaWQYm^>@tB`vT3}(RpCr^(z*Kjsyl#Q@j&4 zsEy#EYyALT5i-?gWj@1WlQa|PHmyJmX@NVwE_}fZmPwxnf>>J>&YZh&=k<74A$4M8 z#3M0fPEZj=t-#^PP+V!L9ML}|D_CCQIB;*X)$<_YIN zg)0^QLFlSV4hLXU4TYZ3{`eV&I_#v%!p0C9<`ON{AdMON;dy(kHCdzyCc$nP6!Xag zT||5B_fs*;m~(%~-Cb`>YWCI-Wn(>dUZ0uiY1EqtHbbq2yV2@Y#H1oy^fo=41{dls zhXv-^YNLjIuf?0$zxti}rT)%Gz1-B=@uBg7Mn?X#Z~-*gC2$k;XW1k<(_sbN{HrR% zRKEjk5RW|KeaDYga7vP2=D$$>Av*Vmx=9xLH&Q7!KqxWK4BN3zsOcO`hN}HW;aB(} znq0M#81QbGmm}TVj3)!>E@xl4)Jd_HNVV7>98|MpGnr}~z6a4#2oY@)WZ3bvKOXRn zIs&g%>t)c5Fy2+x7tQv1Nhch0;`UE$xJN z+vdgj2typT_|79{e-Befm`=>yGMU)+cn_~J;Y$t=&t9#~!NEDj zMw8mR!&g903*8>l0XWkbM*PP(%1G*`DOk!RDvtE?8~y!{g96 zBrN^xy`a^+`0=>~apN~=V=nB-uFJKg?0L~4wAr}ALmvz6Ml6_JJ;4O>%MH1AOpE>E zs&39hXmqp*x!Wq5y1i?N1I!>?*y+_!0}$+rWG^`)Z%HQZo!DsxOGR?1-&+X?S5`de z6m!}CQObQa5w;Xz8yyZ{+?{Ox3Q=Yb8t}(GAZ?q4tPv>C=o8RJj{cSj700qI{MdBj z$Nh66>fHG{fg(r#ecJesbtWsU2i4=_M4H5lD!YGOQT$+-kF}*=a&M#P*n3vxnYzvw z#Nf5e)%H}TJDcZjm-g2nO>S|;-+jFPq4aHg2iU~c*8})6nHW6Y-UU6xh+a1yRmQ#k zc!XUH8_iP;u#Ad(!7efYbmbyBdqH#k6P4h--)t=Yp+rx^Nvul_GqUP{so5<=Ne6&W zoNoREDyc8N#K2)F1+a}*=2i;~R~kZB*(Wc&=wuy9348KU5FBOCh?*^xm7AwopBwFi zG|hV(r~`hhDD&IA)YKn|Ema_mK?qK>b@#E9)B+__2YJ8mIRvh~*2hLbe7`Ww4q|hnAH*im-*aEs(UGwXX$p#4yn3O5 zuX!gB7fIl60B5QmFdJdWVC0{bo-Ni#jo*@lIUEz$nf8V!TV}v4<6AOOteuCMl_WKw+!-yE_SnQ>2iT6jLClx!Z7M$(sJdQASTIznsk)w{$G@uvjUo9b zS7}>9vd=&R%fxh?MrRQ|$?F?BOiCZWNnSD06XL;|Lo8L%6 z-x3s>_0DMxwwI(w=p_I?Web{=_A@JAaR{HhY`3^E;dgW;8v_(;uRV0RESQQm@hvhh;5Lzy?e{sH~83FxBU??(}| z9@($HfB54pf?Gg>Vp?dpn*^3im6@*uT<1L%Cz!Mj)na!<*~>ko0$%DB8d84-Mln>u z3D*TdJA;I5B6R!ZE}L~7Qvlp6OoI(ghyW+|#vQd0@C|3n*VH*WUyDZV_0dTT26#W= z^Mm9L!@dt8yl@GMMnn>Q=o}bGyIz>*ytM1+ zl&~rZM+1V5`sNwwp>*F&GI(qcg*aiRyW3dYus?YC={~AtNFOtNrv;np8#pCU{`nw& z`pca>!0Y-x_R6h30m8A@W{+eub)U6r{ky9(gy=2q^o?C)awLbw0nRnJ8o}aieZ@p7 zhb~^lnQQ?A(5AV6Ph-fs1gh)~XFzW>zDyG;%c zs2dU{LP57BNq;?E*EZ^Y`j?3XjUWn)fU)>;(FdN{;eMPN5GetjjLUhd0oxIPRzdS* zEEtif)}H_3H9*UlwpIAZSf2&&O+T_BjwaO~X$3VF7!y@quH(D0nJQD~CrsF@um;=7 zLt;N%3L*zmB>EQWbb)`hkD{^L5LJrP_XNXH$@X5ViV01;o5U`1mV^DPM5*}+V2s7L z*vIX>5ImNtL2tk*-nV~-^)7(v9_PsX0`mO!?Crf{K~i8S1O(*QwlNPhd)Dv4h%Gh) z!5Ejj(L#8GntRv>wK>B${Yn#O-SCeWAD&R5tJF(|!#Fj#5KN@t^iCJIk$_zP>fPG* zV`z8=SYMxdorBikW5@(Mwo*dzHz5RQRb4l)$Sx1rgF_1sd;NQ8qc<;=GydvT21vkx zv@6{ZEgfS?Np2CpiX^hWj!*@oXP%fOER{!q6MhAl9ic@N+kD&nWE9{Wm|;iTBagF> zEx>XI2W;7z=_~wHTagf)aX(ocqn8>DLliRJKYl-9=(x+_lM_8S6SWB1}a;DQ^aeJ!c{b1bZaXwDfw zL2rM+A~5-&Az2b zV6Gna-+;Y`bMwH<&Wq-{CTnAh3Yh9`kN@HC@(Fws5fBCmu!UpNap@mL9ISC-lrQtJ zsBTA#L~{{_C_MACB~CtoT0kB=E>U4ZTD7h|mPxj&q^ay+hF>Z*bIf-$3}>+LzLN+S@BE{u>3Z5pWmuOgV=J2C}0fPz^au>0vOmLs*#-d}!V0^dwmBlDT|{ar$L zgzN;MMy?Jx5Z5NNfa^7uw&iN-P6`;k^8XNZ-SI%S-`k#*oteEeBeJshUMULM6v?J| zD0|ORC`D%JwO1i~Cy^0J$exj{-+A!;{Qi4CpO-xMeV_X}*SXHQ&v~}OvU_9X+*PHF z^-MY6_R7H{zlE_qqD}lxB9ha1%yHo?=54QQkS-2)}GcG-4+7#h*Ul)(HS?+DIsiT~+_Lwb>5f0m1@XK{$T zntd<87vHVC{vltrxgeEHTxq)zi>JC+x#u>%D+(2NaD< zdXvBQvE&8#Pqa8d*muccDMHjAUmlX5n>;72r>OuRT-*ZdN2d)^Y z@7;8s;OKcm`2YnF*!F&~-!~aG6gx3a0zv7R+1ES%K_k<6kbHf&>#|)d~}Uj-(%``y)`-~KAPY2^c=h~{_Oiy zsXL7en-IUfmEM{BM5D~F^J?lX-BNC^eFzM7_X%4|iaMdgD70{txIS_>(bv!b)7ZQo zk1wdIHCjz?$^CUH#XI&OkK_NgryJCr#ITOxDF}7=2Ua9!SguI`OyvtS_o9<49U-j-htZxWkumgctnBo~Fs!VU^8%M@qH~Jvcga<{Asepne+Ms|iDh zo80;rqMe5|zV=h!x8_xU?UQ|H>3dYYb#|7ZPjnP-O4{TPh)gM>&j-Ud z(9OHGmBvh{1b47q1)?Kp7WRZe4X!?YD-HR=1EpU4UAFcRN1* zf=&H>$2PYl#EnFn#OC-xVne#9NMsn0B*xP|gbdGnp2bfQPqILbzkulZj38@WnaHz| zlSnE@B($Xs?WA@ifES>NY_>}8hYWWU^EJ^jHKzn4;~99cm_l*IbtH%I-zyxVG@`|! zhU;j(s^ndAe$_O8JJ`lC^pwntjp{FauaA{L3$;La8#KuMA3(7Jmz!rK=+M)FH-4EchkyI{Vbxj~o*)Ea?3;OPps^p^j|K*iYPZe|)xEtw-w$^c1JN*2xIlLtXmG$t9wXB`jKB>7!D!H4fJt|o~ z1R@vIj6Vm@s$J6TeDQetBI>L(u~ma}Mo!=61{m{xXWzZ_-{-hqtoS%N1o;V3u*NVG zH?`J;-WPZ?d4>v?H{0&`o`MOIdr6s&=2CqB@>K(}V7II-E(e@7?iUm8R(%U8;33+m zP)bY&fHI~0aDXwr=)=eQmg!zFsaU{-4#M`j*}|8{W6)-TLhpccXHiv6Wq~N5Qya`p z0`4k;Vp*y&m>ZOl)#&XG*SB4XfW>o|OaW)@(0uTNA>-ITRHK7S_GRkQlcqIMMf4i4 zq%2BqX9m`|8LhzR-0@CZi}zUT4vFDy&cWe@4Q6wI^!9UTli52#m3RGM%Jr;_6jCp6-cdJWvq4X&JF%aSDrxmh742ypt z>3{2-T=n3+nlBrc8Ao#2Iisl=I$XJ~R60^J@IcF4?8%4Xdvrq@kmCwD`_WSCazoO8 zj~|mVQQSu1ekVojJQx-hyy}Jy9byxgr7j@I{rocV1_Nh{x4MoIUtF7i@p1?cwUP^BU{PhjDtpNUE!`kPN za_>e*TOGc@JNU6w>eoKu8WyGrVNkGz?9ggn5^s&&BcuOo^(zVS$+D3uSc4nbTcVa@ z%4?P7)2xF7GQ5-H-ORIpZd#0#^E`W~pnpY)z%uEdzYcV`6R74Dt{G^%stJ_f8}GQo z*_);_R}r*xB7SDGlf*bTsa^PyoK`Zl+2K&9jPr;&gmM;(IEhKw#3k|06&%vy3%G%- zPro&=@6LQeY6QZv&`59@_SS+gdPCfFn?wceQ8{=mLi3^?Z%pJb7Obb&P>!y{i%Jh6 z0|AfN(FeHMWhY9|F4Cw2ec907(*hF)G&Nq0H`ek8jTAbFQjVji7WqF0T}c&9sB8-3yY3NR(&=Qq(_8+vHj zw(67WD5CR|z}$~#NjvGM!oS~>4gZ6?i<|l&zpp7MkFz~n|P*R}e+N4yV%=1qFux8z;NqTa1tDjf=5JOG|l0~SBdmOZ97mM#X zdn3d7ZrG1$l!=UV6kQDN2t`tIzssOyq~k+J#{5aQfdTM;7_uW_KFQ)uYwdzg_FXrW z=devQFsly|&Gd2`WEzG4x{aX7UC>hY`gc6%E0+Nd%irJ6uolZ=CB|(D%Zq0R<#Qh7 z{m$($Lez51Z+E}7jcWtRi_>Dqv`*(?{BXYf0%b?BW{StRFUxIs^YI!5Z&;OU=|N-K z8d!3FQ;J~&LfrLt+zW0jTQW@lo3zCcXi%_@Y95f+Mab?H{PsrgvpyN z0TE{J_F)Of(Cx-E#-pvRtr?1E>UdtzYF}Qy%lfsD{-ReWMduRQ>~q1%pq#VgDJfvd z0Q~j3TzezYCY+>k$ z`FnB3!lQdRhx6B;IJCM4P^@+YP0Pr#y zYPgO)aSjE+jDU9`6erKS8JD&}fVto>pj}Y**Wct;2UoYA=ScAb1ZDdIkya`$+TUj% z*pGeXzh?p63_q(pL3+Bm<%gV&p`-vF-YwoVF)o;6-z|XvIX<>b%fBAmSTgy+PhaN5 zDh-SfmdG$DI2kTmH}65;8VjAj-TRaAhRO3kek1xN+C0)QWA96IcFer=f~vVjp&`G4 z#Ft4`gNDi{h-8gim&s^_6V*gvv-*TrhU; zcL8y?eiBGQX!2k!qq+ODU1CLnlfGB2a6-l)E1PeUp~iw|Yj#K>_4Un5vX0Y|+V{es zna}ryXJ5v@{Fcu8L}ok$3YA8YJ_Y-i>k!}Opxmg)yLRE#*ftv3l4&Eg>M3G~D*Yt7QMftH;9Ubnjdi_!=2V?$qv)1utUu zu=U;gv$ekrn>gFwcr&!fahEd9IA@fM?xK)-9oh#mSRHk}D{w#ml)D{|?8qyD4lysT zSN~#ossTNQjr@nD^=_R7@(nfei;E=e-Fny|NSjHavI@jG#GLmPbVIXz+6~frWhleL zUuiOQR`~rMT6170Q+eE^zX}`K8GS1CspG2rYe&e-9hXsGcR=Tp#LJI3{!7cMNV@rq zP{c?gr)fYso~!=F)vvVAUDNd(Z67d~kd>DYE-~7$rx|>YUM5!Yg~2I13JBYvb>c%b zN=*HRY6+`yo^*#za8-6$Bg1qp1Lr>q3X>FKIyFh(P9;-ohmf>=DC|a@`bJ2xZbmPb z5U``4@ZPkXFoluE(hmx>F>~ZbMD1(7K+mWKIW~wb;^i_)+>e6-LNpfDyJEBl>b+-m zFG0M`A*-5EUY z$9AA9?^~Sv#!!`%%6yAIN4L*|4bd5ty^?bGu|>Cj1%4t_`~X*};PE)$$#oEpj+*k2 z=g%Nd^e}1xDpX=X|N?hM({GsFapGN>z3uHjhNlimc+`F6jV!^aEW6Q0wuax+y zpuT@04hr!;c7Ki@5yKw0Ry56n*2}T+83n?BSU-eF7jS8%#sOt7<-9HG^HtOd)J{}* zKv21}!RB2YNzXrgor1;W53YPN$B?|sIe5fBqJB_zlPag}zoEqr&973=J|M2VIk}14 zj1|(rQp>epS!CJ3z69NW-A(@)<+jsHX=Yr5TjtwMYZt+-{RTDgHq>K7^M1G5@I7G? zvIUPh!^XGM^)$a@?AxyfAwVK|gM6p#C(7=O93*QB2&V*UIE)^9XREi^a&kUDe3EA0 z=BU7Br|3VBF8Awsn6_jz+WB-nnP zCQNiV2T~OaR2xIw!$W@ECJt`O?lYffVB1 z`q2L^gs=sH^Hs^RMzQl>LAm5rZC1JY1V&~@=5Hu`GrpA$Qs(1Na?aYzMn@@)&}bBS zcM%E3wrMXOo(VbNm-tPZOo`7*1p@G;8Ef%7d(Orj#xu*eK=jW`G}JF7KBTi{rPj47 zqf+lJkZ9Vp#m0munZg$5xdtEnw6uJYdpe84Mx)N}uebJWBl#Q&B%e7CgYsyDLcU)R~j=ovVY3@Q_NJTzE1?f26UP zGrLAIMC0AV0y@u4!m0L}5cr3^nk*+Xy3&qi;UWc_&Yrs~6+mG0fGfB~|+}k;a=bFK#mP~RQLtof68KzVr z#W%J!)XPN;h)ZSRr5TuqJ+QE;FCE>$s_gWdC>$M)_n_Uwo5((Ye$Obq^SfpS74+sA z;H|jI8LwKl@A)ezRYri1@5;K~G>vg?L4ZvDhSyEIDE_OC@tYaqRpy9jPmu9 zrf1QVOasWpTIVW9OwMpYii+7xX-v$!TOxw3{uzDL76am9E$Xu@43X1_kUTjWIWKS}P1Igwz7U7Ie-(WV6f_Jf z$ep{~-l#=B=4LbmX$^9;0DVDH3>ezy>lDOX6CeIwGAt;?U?*K6xx3_Wgua5#34DQ6 zwm0}&ny0#erZ|+2$#rW2d6*4NJlNntl6y!u8YX!_Yx?J_u}O6MQ61<#)cpt45#++$ zF3fh!o`pa_y<<f6Sb-IxJ8&5IShs?cg=B=BDyk93Ksb zNP&E#$)(u;1P^t71xcf~oY2LUZu~Anlk30 znbey`>Y_#*CNhxuJ^c3`d8E#tX>34R^XG9n5%7MK4j?7T) z@=bDMrw#VqyCe3-z{HhSJmE=wY5i5sj(7K(6!-csz*@e>D1lMFmtBLz2t4I-$N?4U zfyJ+vU5^}5#C$TA3WEAmw5Es68TjpsPhS6Pza04X%iDAN@QB}PCQ?G#i?v&?M~lH6 z5ir7hWnrez|N71|WzNtLS{MJ^JZ?tXYr4;Tp3t2AL8=8prH)p-5~@?~=wgx7+ZxqC zkGB>H5zh68mYG6h*($gJ?GR1+rn+1`9JQ(;kP4d&a;A_X#b)7Z{KBoZ{boShzD4+Q zrMT6%twD`EEY{m$c9v;`Bh%_};DCWP*rw|7$X=iOD|Mn#5A=upOb zea2--y`V4M5831m#jAliyGPz}`t!K|>Avm7B5lswjF=|pr*@j1&Qlt&wiHNp$%aSy z9XwDPB$u^D@Uju*^^s$VyL;GgIDV|bQ@Hfka>*3cQ_$1UCem(8X%fk6JIFMohvF9} z8u!GYvAy!G=vFX=(sTI_AE^2I_*9_2T2|!OXnp}CT0L_H4Q=8IqF4EZ={^vqf|o8! zWscy4%uMD8#qtu2TfqH2K7u9k9*WcS&bSy@^9KYt=|m+R7ZwP~=9t`viedX3P?l}V z>+!_)$vLFib;1hNQcdjfr;T@Q&|dl+1i>s;O$d#fj?K7EF57n#t=%~>+k8{XTAqA( z8Pwu&t*^OLvyPXv78*XQ*Q-cCniR@!@xa6xK%MA$+Nj=*Q5j-yF8q!l6==EvF?eN& zW;rS36x-iDzlV1vX}Z+*rCA1UgJ2)Rq^6{1#!UVdRPa<^T*~Nqm6NJVjOT1Z>Mv-2 zK0}qW^s#6%vP;l+T;CEW00l*SW+~Car1-RMDA{~YVGA{W(;o&O)3!3uw7(-FIP~j| z{D z^A3_6c*qo-1i5iEJzD{T2)o50OYaspdhRMou%mJVU-&QKC%8x&vp9$uA=x-#vyOi$$s2B3nAp=?!?05$UQr+=vpBg=b9bbBN|w5S1`=gQQEN;V@CUzlNUdD8k47m zj_UC2NWg0J_@GkxY)wuwL&=)YhOOYk`~Tm-?lhUvR&}jJK}LOP4BL}dJbyg@qj)uj zJzbOn$LGr&*%l3aBvBV(4y0RzS-mai>=GX`E{VJ?#b`$0VjowZH|o26sgPPpSJK7R zqsgI{I4(NH(YptEga0`I7Ae?5=yCUUA8Ib^&9Y_tW}%I+dyQ7ju^tqU`+U&Q(f^@? z&QmByGxD^{E4{~8hPnuUwb`RZ3!rZ1(3N?spElGv)T}L5#3U*>09l5&ULF$2Wth0PnFL-835axoGNk~iqYATz&UDSiedwx08)K|`RBv;m=$h(IR+QZu50Iom=kgR>6o ztEcv-UL&Zyq|#lZE{QBd^S|qQ&%CrqIsWU>I@g?f-PgU>+B+8-fT{;UJADhpIspFl zXY8_qf2A7D0$WGv4=dWv4oAG2rRXR}vtV%l+Lo~D*SpFg--1z&I?n1}&zjkH(}%fk z*kgth1i$t{J7IldBgF{ujg}JzO^oX3T^RbqPy&P$c|VAo-JAwL-JletM|n(Se4yd} zH*aT@zaW@;fp7cXzW9bVTZ)!|YL*ncP)RP@_IDOc3m%fZ7VqxhIg;S1a?%Bd*%v}Y z{TH2*I*fMQmCW7<3GnAmTHxu;c};WHToZK_RHv?@XAnxcpi~!vuX=0_7JD?O)iTBD z`TAtALiddlirb;T8#fUQm8omPqstY%-xjx^>|owz$!luLJncuvu~m{0+`IdgBlgL& z>laJcA+3;cIlpOuFUBi{Q=0UF1!m9%9(a!3ymIahc^wnX30-vKh9DfHnu%>`Y6%QJ zp8vIvjnzNP>DqtN(2;lhC5F>)R6sVhCkLJfjrlSV+y?m72WajjjCsFOjBEWXy&gsm z{VrNUkWR}5_+0=5g+F+;E%kQ>6JW&cvA7-qp(_@2SZ8|iFUglm;#U6yDeDkK@5=+# zU)O((6ksXTU$tq~uQYuJg2Pelxn;2yD^-7V_hQ-TNu&?;XNV8?^f(6%8>f)Z`p5gm za=LG4sR*_o9F4OsuT4+i9C4>yX17m8FVRoV%Ms8s_Y`g$&rp5dlwBBN%#j)-oVz1Q zYmI#frd@8N^ngZNl!zy%G#1*M6$A=4hUceHV2uoD#P&uwzin>S5xdjUdL-0Fezr(> zU9MaGFG2;gf%gOp>6F&HY!v;(?@=~_rn&X8_^M%pAhh;_sLk*UVtf-WHdnTCxJh76dTDC zuD(+q)-bBR;z{`YnfQM2A|Hk|yx{G~l@-FR&fb?4hWFkudQSH#cKqcW`Vgqm5*}cb z8wAFz`OA9{3m8r~bSm;k3)ZBT*n3o5ZWt0Yv&igj@ZNgc5bba+x79sjLG`SsIjD2* z*^b#>x0)k|7n@y`XCybm_?L8h?uxrIKRTl7?*dOjAp8{EW-jzLOPpF|j60f~xbIEA z&S`i1-}`yAEXgJ+Z6N>V#6uf^+vDc@@wuR9c#_b@U^3VeNfq+~t%fP*=I<*-?Cc9< z*$v;j=1r^?DjTTqGUHBL*iUh46pvIPHl6h#8rgM~2pSK^!@yRSv=pt|-XBz?RIDp` z_Al?U9&a`1i>0^{tT4+dRYLBTC=hHr;>Jp{>4NRj&ydXrjzXt-b*(wAU6EO=6WnX{ z5;h@-;qI`J)fax1kYv7|{uhM~bm@Ao0lq5KzZZ&FEy1fJ<@BOw43mg!@BOU%pLi5G zuR?KL3P+GxGrcjB#*RP_O0*6zOd2?L_#RMD9|~V+_Kj0-O_!H%p3#!}y+m>YwChEIdCFOIgtt+%-|mA{{J{pt}`}_;S8^ zj{zPh7(7lv_^HQ{$9gpeC3Srx{_nb2_>bePv;jxxD0bPt8)8Y`z`Dnq`0M3R%bSOa zX!bE9EW8ZkF5Z`E+!{T;jKbgiWcl-Z75Ujo7Ol273-^o>DS%i3XW=#)+h2*ze}i?T z;{)oMu8{5{+*&jKw~8hWdFLuK-b0vnNxg0wN{;McuJ*vgjSMC3?GfA;_-;;HbfxM+ z?9*vhbyqe*`m0m5p-lDWsu(o)G>RSbfX2_iZuS{jB|f~p^tGrouoXCGr#AIrkVs+| zZ0!-SOLRCnL*SCoICsQxIswy2-!kz7GUg#{Rw9IQS2VU1zvVXgE9Z_^(Ea^0xtIo7 zH)OJ)!^J+sDC(H3TW@XeuV1Kk%I|w0cj@yB%HsQS-InvNlyQN>EOVg($+}x;@eJ-m zwvV)D%}G!LzIAHA+GLOli*eo)EZGPGINb$22!Voc7*J@^cxI+^bA_LufBvny76TF2 z+J7HB9@&`euVL}nhdt*w6{z<>w6c1VomZZC=#0( zqDIy3>N+H1CtUK%eMc@sl)Ir1j!8{DgX(syxE`J_xaeOu+q7VReBr{Lh05B#hfC<@ zB5&_P3d2%NX}w+Dr*$8#$z;Gt{sF?*Ha33Jbd=3Y-wa$)GpL1UiYQ^F-UUTA<7*+> zjR9>m1Tite*BEl55UWH!*MWW#w_}?x3PX3G7FG{T}d{3%TaV+UX3+*dU zFk2!9f3*X8(Ogh$Gn9V_ zL`p@K$3rw|RR-NjSS`nf!&#I5&^LvtqLjn_`*tBcaHLD0w4EgH$ch2c#D=Lp_IF9C z|6^--OS3|r(occt7OtYDfe5!1Suo5Qg$9Xkff7&{%166geBZNC|1BKr$cR;g)T0 z!ud4*2knJP*}_G{m}=2>p4YIlgkc#hPJG^wrFwsxP?b;^;PDn}U7n}bwZ*laQI|>X zR;i&EA-#mkOS)s(Ip=qnpk6!mo6b!LXJsenR?#<644px+pmUCg8KA8^{JD%kH7U5s zI)SjIHTXTKYn_h#M}}cE3Vf`$yo;T)jPmoj%sF zqbJ%QeskHg+MaKTkjZxb)s9@kx_GIzF|&OB;bV^fVxr}=u4eHLRo)!m`ZB-rC$~3$ zJF4+|ZegwNOZPnw?)2VwIg*{K>(B2iU)lBuvcR!q_bAlNMh;lx?eh3t zChDAX+~fQnwD*1=9lc~`cR%3?B2EVJH8w%K(z*6uL9q{ZDr2tmZm$Nso>QMbGO(IZdp=e?vBXp zP}cVI@?R_}yQZOYRQ%s-rf&h9Zwa_@CsnN19v3}UI3pHlGd^ZcsB@!8Xd<5n)*S5i zW~+6P!;Fy1r*4~5><#k!i*3#(cFUJ{0zUyVV_9b&TyzZ8W4Ix$N6&FcD!bg`W@!b?1TZ(~*{tVWaS_quX^d&j%B3wy!C%Ydk)Zm}S#Cm5+>!)E~?U+JAmgj!cE$B^}`#D!NsQWGNCn!Re#LQDeoo zS(mdP_xU)j^Gm*ZW25L@@B;sb8tS`jSEljNBSqJD8} zwhc>eYFagjdDmvQwn+f1-w~-apou3{ftgFnDDo=J0yF z9m4JZ=g%Kxx61;(g8zDdl;0V$dE9PSjAUIz&r$gF9Eaxe$5!hfSS`LX9|QfAEM|Zl zjQ&2o2=`qxhCBZLABPr~mzPKCgADjrq_1scetD>ozQk5pkKWw%*}u3UMl0Hr0nBpp z8=hrkoY$;|Va+z? zpy2nM#YzuTRE;oEw%RSBs*N(f1=~0AkM5FNL3%l?rF={8{RnmCqwz^15oe4G;|mK* zj1R$N7R26LsEOcY-oVksnq$XePrxqm$u!LVF8yb&M9O=ArWt{mpI7gW_&H#0Lsm_J zt^6j6U_DVBJ*0s-d|<8V2{&2P>Zo8HMH_L;nXY-_QTtG16yK5+u=nA5{~1h&W;Y~; zdAE62szm_nlIzq~BC@t``?rPPj8MC8wnbn?x?&3>`jKl^hp;S>+@s`A4fBJVXYe>5 z!AZpjAS4Po0^*v_m|7%=^!nZv4IE8k{>j3~4*evDaZ5Rn-A(R1i3k4nbG4UsaaGsw zDV5mD(fe0?$1|H2OHX#joIBdUd_9J!=Q+6;HovYSdN?ry zymte}B&e!62+;2gC48D84~vf8oU+0k-keHoJe0$@0E=O*XFJlmRNuZzK+%OU&`M%R z2+L7l_l|+(Jl&iUkgi=}`db8Gt}83RBW^B;yWgHt9V1mi9%w}%&P$d*iJ5JAfA&5f z#{Sq>+(*+%3g<~|Y>~-98Se)Cna-}-3Uc!Q0BYVmLZN1rKq%bBQzqMNxx!s9^&?59 z7-~UcrxrxKxh`c;ovZRPR>g_d9)l9vcfrvbO2FVlvrB z(_g1o*=h;qSpB8fc7M>Dkwhdg#SZIr0Fa(Z!N3Jel7wqC1zhV5PRE4LN1KZ*9N-ep zWv{!h%s-MEIAqn%L1vDgzYA-=i>$P*eDVV97nfZb_QQbHEy6!(yFiJ4Xc(+cf?1AS zf;kF*R9k(f_j2gweOXdVX;>Af*`V`eX1pDN9My>*6uvT;?ceeZZJoUj%Kf9d$-x`?E4E?L%3u_Cs9 zTjaGQ+;Dq&xgA4kNO1IUWz+)h&lbZs!%fKG>Ur@@_38Ni6>3L5VaC)eBmM#Qp9D+x zkDUth1CPQx6^GSK^d#&6Cy}Il(AVM=PosGBzbSQ=<01e%t#WMTct^^M$E&E`Re*cK+I%^KT|q)uW=j$XENM@E;oe# z+l~E|ZQs{#&Ex}=tZux9OUKT8=F0g=6)OGyGhZ<9^aNzoUbsK#1UPf~n)TN498%tR zH2EpSe(3SIedoaAKY)J4TY(?GyeoPs8fZNggrbZj_`B)HCwJN54S<8l$HEnc<)``h zvrqT$R4|SP0wQL;PB0}wr0|u+qyW-2UcGd>%TX3D8`_&GF**mgYlY@q=dt;W%Dv2Q zJ(P>5-&NVMz(i^(wdeeYBV+J;0bju44Y+gZ9!*osuJXZY#9RC*YQ6OQmXBA4CJ8^Q zEJrad@dkEtG_IU#mA+@ilw+vQ;a@f|kz@s(%U=thK1zz_Nq6d3h0RM12*Ym0{%-3s zrSl)ft?KHJRu?g8v&_Z`WFAF`Dq?8J|HmFUM#_vtFu*x3mloQUOiSv~&u?Qxm7!dq zijy-~Oz}t=tY1h13DD9@75M6f+S4)<;|~6R7TLF&*T+=$xQVv0<*&8>N=WXBlPX?E zp}nN^t_%iE*P*vALE=3@1Q}75GXY03%QPAA?0c2<#aA*k%9yPxRr+tdNUrW8X2XJ9 z0f#Tnp0iZ=y!|8nW;IQ^xt7G?8dvDn@j6nj_Qb6>h}Eq7@eHRF-SqVxx`yQjEKDA5 zJ`ehJEO0tD;isqb%y~o3d{<9ti?V! zgx)(*OK#L7u}FW?rn@ZZv~?OEV?@GL&%4rV)1At{nJ{R+_bjLUeESP9_TA6bOK=#$ zaAyvhz6%1hj%YZ%0_Kk=HINcwvJDq$f^{sUisvw@u;Yde@;NabR|3w3uU?*t65J^bJ$Q}{rBf)2AlH!j zGk0kyXfzgV4EKxLyOF=MM?mT;dk)a?4erbNR8n$##O(1{cwgSRq?g55JBB*IKZp$7}RZChx~gAluE~6gLk1?Wr-HbE5HI>}>7-2;(;+ z;pdVSE$%pD?`QI?8v}coRynn+zF&L~EC?6XP0^wjP^=`Zhe zJ^^9*-xWa8$(T>BK;})87ykFVt|^#+k%-WLEm1h&u z(UT<4q%nElmGO9VFxHHB9p$|U=J^J=%Nfa{iqZI3+-mBL58NNLTvO0Q(Um3REebV0 zf1^Bl;5t??N=_a=9lstsU|4_HE|V0`QZpD4|L1c@N|cMm&hgi=UMH9PeHulb*Zb`% z_@T!B;w!T%CW6e&gwaf};IUQ`A^?oJWQj4H4sQ|!4udsHD(+cR2K@^DBXD$V;OLmM zm@qutLQQ_V!dfMd7|Wspz5MF7RXXO^j=GB8g`LyixYFguxq^LeQswd#IaOdWz(Vt* z>0HM2`hP1C@526qHP*;?%)7eHuu5EzRR8>4p%Sb5m03pY^5;VU2^a6e@JiqOk|u4?^J~i4zTNdru@L_G3vx}IW`0_qAYe5kX~!5}$W|-$ zg+R7a^*{ljL>TB$p!~@#&DQ*!Ry$@`(w-z#{oqK_=x$%06L!6aaf) zvHpGvXC|!tWp#L;Z%LH(ABG&pbo&?B%mm_2IF)blg%V*`ug8Djn>eVlUVP;Y-mSur zlj<|-Q7q3Tn|%}cjJca>mht?Q*y^kkg9)4gW5GZePADC-{!Qu7SJ^#J*n-PO+9_fN zDEYRB(8z&c=GXeM-;xaDV^kYEahBuy3)BLP_R6O3AQ-yA5~XTJ%7T%}>{!)$X_=gT z!s)08zWSPeEA|YF86oYOD#2qn)T#lvtMm=SNip=|$=Q*;N!`_YWNFmTfdzt+!Ik<4 z+@vI#8n*a*Q#iv8fiAXaO zo)bv?YroOHOkBTq2Ul(hERxen7wE8En9Cn;nSHu^miyQb_YUQ*Jbq;jTh6+1hl(B{ zNwz3Fh7-Bg^XB8ky(C4j?OsPeU;$6`0EptNSQG<-ZS;1^6@J5ZlbXE8V9*-?~uE=HVWy+4TE$d_$qz$JG{ix*4H^Y>7`< z6h!@7KM%mcf}_1*uwth|{TBP+f)l`FW;DLWVo2e$kqyBGT-0C)FDg{PS3_@nKt^VF zjd*F1f42zns3^Ks5lv*jvV_}080;PJU>SZiTuX1HTt45ql9x3|G=Tooztmr zzY%4$@~jq|_!Zup5C_klfraSbmDWRuyi4&n%7B`$%qzGm2mulAUGpxyg~PrIP&e%J zGs2?YURua~;}2yT)~E5M1pdYtgUn;O#zuuOk!xJh9xm%Ul-o~^czTcRDc6_+oH@(b zIPSZ@tQ}#~^(ds^l0v}|3(liK@05QkB!?%U!4X2f@!LX$2&FMs9kO#&>aVMeVy>RsHPed-fO0pgT>tSr zzdC`0n$!MW z!DhdOxaV7pB+#xJeb-H<5@2%`jPdx5G5zbHO~~3{Om_w3cwfFkmkQ{;ku z=Vu+yyY7WIuab~~*?Tl8zZ9l5T5}NpDrxRo<)aNnmFFzX7g3;mbV|>DoWcj;(ElhB zvK9C~c|Qnh4X1&0mLyB(!;;;Y&kkLuP<~!3s$T*@Bs*&S-g0;+LFyV6oK;u{=2EOZ z*ibKUkMq|&a=cUiW6k`N9pUCSW3{#=9x~jxvcCQP7EboUNs#FHT8J?`@W8T1x`u&) zH%HB^5=DCKONd;RzCnfTHc&Fb3g&x?0q@Bf>o2oUU=i>5ySfin`0)k}8NIpjA+_p6ld+IqMnK%+`m+`4pt6BoJ z#7m6r<@C+%pT7YU`GjdrHQ7R@hz%=4wDLaJPF<}VINW!^>2U5m!=N66x^zzY|HWe(mFigTHWD}-P3NSR ztV4+BTa$uxHrf;(U)ulmsY^1m3>qcNaq%RX zRfSy(0~DM$TzTaQ_t{`iVY}=5;P85rk(meK_`)~+)+EP7%nbBOP@bZasLE(Y=SPYO zR0IpGIw73+ZE-x{nJ%cXUG@jYrE|ZQoS9@VTjkMoDFl|HI(r)M8xK(76Jgc~m^vuE zp?9VFRSYnj-bQm?+#WCXMDdTlmt4zeNqv}CmYWeggs6AGaxj<}2lMskOpr%vw^7Bw)l`L`zb zH{rX5JWCP1gWzG#SvZJMzxEVlWA<*GBuX!bf~p*`IX@lB^_{g@pJSXUdUc%I!Ei?J zBJ*zduGF{y7CG}QlcVBZTkb_zefVL+aI&Ii0I5V-pK&n#o4DFgtPIrSO^$5+L^PdI z+2Q8bZXED5%#NlYGcLty)vG!wmRDhYKa*k&C>(7i_eIiIWi9&vMYL1o_dc95EGd+2Z>qzW{pLSzwsUiUWf`C zXB#X5(*{|e%Lc=N&>a#UNp=Jd7bHw5*h!H3@5*vt8IPRVzOg*_^>}uUjFVl~wfM}n zjZ(GiWRelCS=ZwKkkBp%3Bb5AWN#~~%=1_ZsR2Ty7UL0~V_6K8%UUXuimqd^}wr=k(R8;C1XE%1vvS?$xI<%MPva(3g$+iPhkv6<5Bo5Hx%;)^9$aB#r9rHWS2ky- z7SpMaAy`Ki=v|=a(vT?egcm5g03RZL?G)6jSJ%sBf(Vdvq*9gmF!R`)Rg{7M4cNXC z2q*$!<#@m*@fTycTJ*9eoyu9zF$`*CUXVlryeig-eP55edv9C{IL1w6Q z{t&r!oc6(iJH9mv!3{}urYp|tn?ONnCgp#@r{4aIZ2xFJ4nPub-CM*|OTFZw693TU z;Nv}N%pTy+_7-C$DS?;Tu-LSvhMQ+1+8p$qHAU(G- z9409|MSMZAvW9+>)&kJOGzjQhD(R`QS3{IAOzCu^*OS>uKDO}sb+T=2L>?bv-1o

    ^Np$%2_6U2FARBB0qb)m4QfJVA2o^mkofTE~!mRG9CI_ZVyfbXX2*GZ?TnO zjrLFk1CnZr$x`J%jxX_>M5el*mhS)Ktc@|F%DN(DRey%RVaKy`sG0Y+;&j-DgQWz^ zBAA!ByTg=}vnS~^+4)s3L}Y&v@F=WpzV`wbIGfxr;QN6cry=@ae^W~Jx!{HNFEb?i zyCK=34pMaa?{eaXK>bupVl2{%m&OAG*z);j`_$D|v_7-W3eB@(AN?YXR`M{x zp#s9Q;e)zVEUE~~(pMpDgDk`zSl$za9oFy>=r_=sC8o%tbckznTC(ua9FBGwnrDtU zKZns6W2&Jp0!|zk&jN7Msc-@}MlG^ocp-+o3)y2R{mgpfknPm~v<{Y6$#i&087LnI zpnmb4%93fFpgeX8W2rX`W@2EKTb1+6{*oDCfDVieJndC2G(>3O=Bocf>H&V$$YB+{fj$^ zH7D$Z4>s^@|7;gP^<9}vEA&hDB{KGw+fEp*P|aWlWZSgw9>b0S!4m{0ko?rVQuJKf zI{Rc7a!(c(0}Bgfn!137ojiT-ql9$ni2j|?Jx`Jx`@NVIr5F4P=i}b0RgNyNWOmn8 z*@E-xMb&g^$4Ap5vrHsjWO~#m0T5Gg5d=W6fRW#A7j|!)Ij3w00C`{T^&kNv?sR#? zwz$i_#GaM}hpzG@5L(+3wO#nMd+gEOP|#MUBLuzE(G*DR^A61UZH)uSF0VE{d5513 zk%EbH;dVM3L|<5-g=XG74RLmpQ*E$@`zV1^2!M0u=+x_lq!;98DK?>3Hc21s)Sy1% zMoFF&oipeAp5UT_BnVja9II5?ewjD=eZqU>v)3^unaE)w#2{;>+K4K5JWx)jH;r-4 zs>o6&Vb>%{oJ}T%WR<8woO;fBpb8+xO&>3rE6my~t5p4}l{HNc{n$LHx6(LG&Lpc# z#-Pxe|MfTm*hbJ}A|wIwTk}Z8sclC}lpApC`RlQ&Gz!5;P?2~qf!$s(mA`>{c&z7{ zpFgs_C5VW}9+bVbY~W!EdvF}vW|Ey5n7V$Xf14U}&^nW`!|EI!>ZQ&NAC1L@P-Wb# zZuepCBfwkG2RExHi?;wm-MQA7Ax)%$Jf5*;aJ&NXf#4Y~q5}^07KR?#X`)NC)8Dd6 zE=ma!bP>1SC1*WN{^3AOmp@)QX2Ir%sn!Pm_3^#e7jZhWm_ftv*z>o%(jAZGSPo)7 z1H(%QGoD7Use$0RksXcS=>~z{b4U+A`F&^2R#dr0AE%=UStB`9OOTh!)OtP{z-d%N z&V8DzpXuHiqA3Ljw#Jwm`3UnX>xvJknu*W6r;FGJKU1n&R8ul(d9SX?Cdo8M|0QgtswNP%z6xx+i?a`?#(IvB>#Uz z@np_csb?a1d_#>XW}s;FXbfcKX|EzQ?>!JG75YjExN}5yh#adz88Luq2^e`Pkj(3M zkcCgai0QuES@2>w6Ia12s5Zz-1MblI5l;AAKw1T~>b$f3IAu}fL@bBY3M}z-HG{kH->w2f!$S#;G202D;e5lMiK^o-So+yj zbC^u$sU==i%Lr{MkfI8Se+Q7yF%axPAXwNZefVL;Wgfu+Z>RQ|N|eEwJh zAKYb8xVLETqiiH_;q<=k^gmOGmk!+^A%{(GSoxHDqMNLu+1SA5Iqy+>KfF=M;jK*S z?8_M*M4vfTE_~X5AwhI=rS7ybswK%%%OWz^`JmCJ%pB3d8dUy|sjm!(s{6hkLOP^N zxK0M4g z_uO;#UVE*z_d#)w+#&7}Xg_zMIwx%@7Z?W@S<@!3{a@ceMy^ZPMPCh1|G7`Ft8AjW zm|VU5x8T4E^Ga{1XPd^Dp; z9YVbBGJcfr;L|rrc?c@DD}R=NNFt&MrQ-0Rc*pz|0-%2;#eoo)BCmAb4dG>dsF-4w zGX6^AyDpC|=q(zn%+!`Dl8Vw?g#^G({Nhc}0Sp(dR!&Rr-u0W8JVWoy3$(70 z$bq^>>pQ0igvdw0BEsJ zA(`{1ElcJ5&yKDakY|~EFpN;VfnE>q+{6iU}ndRbXiXct9#@XK5I(%PU02hA&ygF(@YqFILN+&sn{Xt7RNV0$z`>dJF6XIZz&o|ZcG=>2<*6ludDI&TZxweT$0?X=WnZc{KTVy zNT7{9%LGD9E$392TZyOyvO+{$B{~twnN(t(e|(i3a|dO`7Y?&kq7G^E36vi3(7xGM zahm69^%1x_NoeE*AY~&*kXC=?`$TaC8bQ^={PsX6TK@K%yokw7ZkJUMf(=T=haRJa zH!*ScJCh?vsJ@<{P-a$Un-TqYP8rxW2oe8U_@Epdt)uG)p)wj`>*EwLfrpy^CPwo1*`L~=KAO?Rgvr*M!{gIK7w_58&zHFrWY zfX*QeLBf2{)Wpb#z+QuT;uL_UWpD)gn;bbHP^v!yZMVLCb9o-YZ*6rW`|JVVfIfmc z`Up`6Y@v`r&_;#%^4Hyy#v=Z{9U(g*Toatk^T6|S^EZPRFf>)~@rTw};2NI($YJaU zqA<}Q%(=$6CMrS|v~*7l^;?>+IvQG?g)`M`A)E&=q* zv35Q9ZXe;1J=nugs%1iw7GPADf*^uN??(99BNjj$JQ=FDV`L9yYN1o}Q>dnYl0ymU zPHtRF2qwSlkw`zNH;{fWDD+{sI*oy59%y`en#VGFuNV)7c2-R9T=$tNR(9Rtx%Bj( zou8L#AsrAXtgx~|8N&odazycibd!=kQK=g}$+m=vhF~HC)R0JA>@-cB^|0HGygjLM z()bEVKQ;WA__N{DeeI!V;jAGpshq!2uVY8wf0XRs&@(7%`dk3sm^Ad*+$gf9)Y4Z~ zhd|GT0!+&Tfcf$_2qxDrbrin#ny9!F>izrK`6E%U&bu8;8uk>5d=<7nIs0_ZOG6JX}JV@wI>bTtE!YLzO)_R^k5U6fImvN&m_Uf z-agnuCx{fdPu1@DshhYl7Fx=h%JkS;gi2kd(;Q9|;}FtY@l8QqVc73aP)~z8yy32+ z4e!#a&sfIa5>JQ!(s@_nVw=6Q&P;eECGW#L`;u4I7D~T8SI`d00bPZMM4>+=56LK) z#k~&tT$QFuEy9t96A^JeMb%$@j+XFVt>=8 z`qf@9ntro(#t`ZhpPGb{@b!73so&ImO(e|kCf`f}C;;{tw#1)l!Mo#*yw@VxX7rKd zjn6oW<^+5MV6q+`M>o`kMtX15d>DOnQ|+dobR9W4tsb}G5`NS}tBw^<8iUV^7KB5G z95O|j@gg`_0BMxJf2Jf!&XQD^N_K7kbNVMSXTXvzXuY`-i$Y{2$WRqK5qv_&WO{p` zQi5N70|Ca742+Co14pY;@V=r}!a(yjwai5xdwK)LMVxM0_;WgD10Z4B`Iq#r+`LC3 z*<2Dv-PASue+`3F7F{MuS{YzZyJh?Pu2Dj;P}RE=HN_mhkEPu9e}%%I(NGxUshb|c zM()~%ZM<*qT4`)pw1FUNpF_ZVW6J_IEqftXyj0q)u> zgdSC=8L8<7bPdG@QjV#>8;n#t#X=uGEycZm6*g@DJ!!bs6DXscgG!4x)H>ima3F zq7t1GuTb?a1`QtA=z~2?q6#KqG#2b`&cLq4nLk7G=17^c>yvZd=|xp-Ui)D_O(ce8 z(VV@DAL|N-TxzH)Hj40lm3l423=cSQiKjwpc1f>>q}m}~vmM;mLtf~bKsue?;q4d4 zCri241w_a0RL>o-kIY+gS)*pcuOtU#kNOgc0)E^^*jpH57h9ABVHxc?r;IPVx3-|H%_Vy{k5{~nA8y5@3_O7`w z;q|%CMe~3Lx+9k~3J3~-Ho@*1wEST^kjN}fU zl3;vutaCv9OXUQ3noyPynB4`>y5v15&6ayf50NLa3q?FvU`DT6HL}Q~&Oh)1!1G?} zR6js}KvtiE)VopYRbEmK(g=as1J3U{k|BXjtmFmtzZR9I!g`aW1(T$NGJry3j@vmV zBS<+YOkieYu61M1V(P-yDY+pEZUuCeD-Tu~?-gf0HCdg?k>LJY)EkwB9I~cTZfYT% z=E7KnMe`&e@9$#-rr!$E`zG;-w;~T&Q=02wHuv`=jB*f|wr^FMNgToWWG`31A` zYUaEP|E$&9x&MYDMIZKgI7H8SyTTKyf+M&ST?l;~XH(Kj3gDL#qQCUS!7rWmh7!qW z<&pB}CU7}{upOjOTSqRFUY_J59bN{q{a+;U$B^TZ3`HGl5nnCv7bdB9)1hb2;P%r) zQ<>vME)kxXOhjz7RNcWKhkG*eomYR`+kuL+NA{WFM>~YX{g{Bk^GXrlUz)6Tu;+4W z=1DG`s;9v>$SFecLk_p^-D5jwrPA?*o+`u~-0?!1Z`5G-Z}z#W9F5H$N9yTk_ap*?f=lN9{+BuO{uQb6oCW;&mJy`EQ?{-3|~+iCQC5#^ZB zR0e#zu+=HkO@Q|q7n*-)bM5~@A8j?Jm z;6`P6)Z~Oq@(A@@B$Q>IrZIVZ4a($?P&fpH%6(z{Bl;b3nPj>xy4ZFNVR#;j5M@c= z#x!x-;qe1DHreR!Nl)RnW*cJs_^A-C2b@Xf^k6D^mZ%Psr56XC`W%+#th)2IvEjp=av&!NIQ z-!sUf^SAIy(ymYf4$pVP78ioJQgPG~zLOwB*&caCb0$S4N1HJ@uWwT@Q|~eujvr2h zNkNpyY2|oFAnxi`q;TO4te_o znk%xfF5ZN~)?fm3y?PS(rMy1EJUWg@BUJJ~Q+F&G5r&>#ICEuyYn zFT?Gj#mmsObp4X1?=Y&i-8p0V=FS<}HwE9?6EmNvBz`qeWCr zyj_$YjzHjd@(qNz_>H2b3IfSu)XAk|6=Dxd;fG>Zm3w$kZMvtWYfyF@g;@xu; zz!Y(k_#3LnxnUj6jR-Y*Bp)-+|1o~y{JWR9Dn85rLLOR`KES8b7?gS~qC>Vr@K#)N z9sOkdlTkE83xz)!onuD4+rm%55{ChZ1rNlk7I=^)x!r5hE)+wRhA4(>h(hARPPys5GJ^>_)Ts5H18rFBm(hZyfh3E-`Um z*)l#(^Fm#C`thl04m7lpfg*F@*E?RkKfI3iuBiV7c7Ri@MxAnvgi1QlK?T5{;ye~r zQmOb_fdXAZd5CJ(g9oVOvVC$v#DCrqClMeR7XYtmS1f+n%FHM)QzuFf>U9N7_r?v} zfXD{!kAc59*pPy$448HW^?!UyqXBlC1-?l%yeiZ&!8CwU>`s8QKBWFJ1_LpmGSC`D zVY|%ca0L#(R@+(Raem#(MVkS=bFLTIgi?cx9IFga51$1>+OJ(t6Mu8xMIm$h8(5Da zGm(uic$MS&0Mw7elj&y9Dgh1vheQJ|qP(+lupsSLuVXDmT^LX^up6S*tFdtO^eG>l zKHsnFKTc-Jgyjh9_s?wWrTG}e!t1F8)*Aj0>}z&7HhoB)5lId{AQ3+=dAD9wqu&tt{59w)jhK$_v1Gqxban7RT6l&?~5Eer52TtRoI!re``b{$OHv-To zKp46JxXV07M?`@82d5%=gI2FZHD!tzIQZ#F^+55I))2uf6h;kwzj>lzujf=#0zot+ ze^8Bdq7v+}3Y1jR*&r^mjoi`8EilIi{`2LV!a;d;OA>|l2WvNJ%)N?-mAPY#xZryj~t>!hLGRlhs3T5dFGB`-sQ;JQoS zSptVRuZx$IzLLY)G0(IaO*<6#8&1OXAw7+rBSt*^QIr>Wm4lVh%l?Xw?Hkee*-Nbg z?i3m?fu0TJBl3~JqykNV z?R^jh?rS({!sB=bSrJ;3f)e1X!vUO%0LY)04w+EmP`kUY$cEkjOuc#dHH4xi`o0mE zciTzhAy|o^mR0bbazS<47&K06H!ZZWD`*Ub1UMK|_a+ya*o0oy#G=~xre-+dO z5nO@QfS#3%`k1)3^Ecbnc{5xI{t@6L6qW%ZKEpRLIJ7qe>z#_fe;3v}=1a`e3mx}@ z@zl-S$%PcIl@zC?+8S<29)lK|R9iagtpP%0@ zz)xl`9R&tR_BKSBIgZ09)87(gwu@6KLj}+}j_zNBnxu{4p~rRo+*NT_Pcw=StA^hQ#ikCWSaK=!GG!hrL0+jyHaI zFm`B?beIJ#t|$bp<6;gZ>Jnb4I8lQ0dZr!P_!CB^t~5Q~f6f|>?vH-`y24iRxVEf; zM$`lPVQ~#-czvMI^`HgVyzPzcVU*&-^-~ZG%DUHdFB9`1Uo9Ycc>%QLPW-}4vsdV7 z!t8X)bSL7yxMmr|>)-y3cCkVPY3*~W29SOG;lH$PzU0*;mMWF2ug1@9YWUuqkbt%q z!BUA7DxDQ65qJXPl7D)5?~h{&#}DeycSj}$sNJ$`|Aug_@m+&&&u-4Y{1}7gJdGH(+hgR(}cm2zXjz z<54533tQlm0kWD|mFOp&!LjG&uBbHtrz~o$>QRF5s__#pwFN=zI2pZe9cvAmyV*T8 zxFhl8&@iEdBp<|yr)V`(>XWsn2ysky=`pSkYVe(&_6=Baz>7LZhoWzT(fv}dL`mAD z2aa0ik^%+`b!-fb30~vQDT%Cp=b#b3qctq9$+W}~y!s<&J4)0=y&wDgD7omQ_ZJ}u z5*cUoZ33WNwI+Rl;r4Q4M=D`J69}K6aqR?fk&?idA&Hd}$Q=NQ0o7nrP z6nEGGsM{o^h3_UOVC)3#e`kdSj7vfeU3OCg8EDbB#ax~G^>vBu$i*#+xC3rd-*HtI z%?QGPqNM^^&vE6;j`gaUEb;gvRP)#{3z#iH310}Yw}@;{CBAS6xTy3wlOsd=C8#Mf za5Y_5$-S_7O?jZVq?V%+7E;a(2cyxRK1}vu?oNR2_8(_VH4cEgUhb;)tP+bOK>q(a zqhc&gNOW}@{;T6&L!TD{M9InGQus&ka0D@zH!r682$Tw-N$5p_v>$dWI6D5B^RCdr7N|i2igsNMd zipK@)Kk}Ouxq-f;OOCC*#(YcSg$!#F(gfR*kk642=yrj*0%(sP7w17jcN0|;5j#BR zUR;#7!6>yvO#y-UZ#{JJD-VUYM+JjJGVPK$`xw+2UOyD-!Zm-AyJdj_2!RdllZb&| zzTI6Y<}<{r$8mgyv)qqH=~ROYyp~t8@4^^UXHSXQ-IdiO5kWq|KpX)uu=^n|AUXAaSpM+pU1wxhm}-^CteQ%DbSXo>LTz$adE3l%%S ziTOVLf5Z+|sKwFXTm#*JlT@{Zy%o9_5E=n2ao_dOq7OUdq|U$H*jF#$u>*w|qnIFB z+cz1OakL}RKsfNpiI*uS_hV}k1{qpA|BMyfYy@3xP^nYW$rJXB>A?n^kebZ`UaY+{ zgJ2PmER`fK?(_dB0OlEFtY(}E-YpqbT%J{lc1lKg%jF=IV4J)kk85%5Jv6FW=`^Yu z?6n_sWsJ|kQB)!ehP__4y>hQ}_8hnr(|?sk6CRS^R`9DI0$@VE9*MFgt`*e;4y^PIhI|e9(Y)|7dQxP4Ytv~+db_hguXy2|*l06O$)EvPN zPp1-*PPxZ&Pmr7&SKW|B`{ZBm_)LzhC@x6KyZA6gD7uludl>?zy3ZCo%Tw;JpS?Qv z*+W*Zz)m-ZJ245;OE29)sWIlfeO*od;rYz#D<*|Y8RK%l*d^Y5%-nbln-EPB`#t-Gj z%}``nriF~CTYOpa2j?P<&xLN+;;Y*hiMov++A5}@W6_O#zaHLINPn|dsj52|lb!;! zXgfd7&@$yRx>L_;;Ka(LvAkJG;UKFqRCP?J|t0vq-z@v%l@g=4g5d8kBGY)MF zNz=8~6K!X2T!oHRui3YJ6#cmNcP2OG&D%XgYrohFI_)L4AqdaA)HyyLda5&pcEeM( zqZSk=G}Iop3nqVrp&-#1tHM8iAGX6%5KSMIp~tNdl{qViUx7X`L}s+PrIchoeC5v+ zRf&^O7Yqczt42pnSm|yJ8;JPhyM=kD_{Ab2RAdi3>4)@k!T#l!-dCtc>;Qsn&ZRT3 zB&Pv&Id)hKQE}g4)+si+%Nxpge3G-#k7mqh?7IQxc!z-cCGZ>52lpVh+;=_&Oz$+* z|Ji_k87G;jaOvhCeX9sBmOfaNnzN>HeQ{t0Buk0DEEZ~!)AW?&FCjFq_$Ib$MQCD< z53(4DRDh_3r4`ka&seLJP-(jOJnI(pHi1=yUs)#8Th6p_!s;9G5QPIhn#$iCrbMcP zaEEl;h2DNwCPVwhCU5P>vllOvo1xJ)vFjChoWD+7)PMfNn3o}Gup<|85D)f4|Jg{R zjkA-HC0Jv93;v|OrMI`NsnrFAz7H5(TGM}ZI;0)l#cb&+wO}te0mEEOuS0iPnDbK4 zdkUH_iQy;W2l@B#Jei7Wu;(7~JrlG<7zU-#8vX`1=@s#1Xt@EWMFlB=cD(+x>;MYt z?>Z0OL-*Hm0C{|{r6<37=`n4-$C{|)+z?7FQ@xA8f}xgfW$~k5o{aBJWSKcGmOE)1 z9eAvaHQb}W-y`LI?AI4V1 z-)guI;9v?`|0`8SU;KR;urn{+`HH_BdQ>v|Z=nPX0bYKm$#@0uZ1MSQJwgC^Y3IeD z+>C=}K1f2)@z5c}D-Tsu(vH(7aZP3YpQ4%WyVLz$!vZY?LPxZ`(qXf2{G4_4MBZ#M zqcTdG7a6U0WX?fx#GES~kwC*%O#{dzjKv0iZ;|}{FO>Xc{Xj2fetMO8&r``?7>X%h zA+$rhz2a`$5zJu{T*%07N-QGy>^Jq-^w(4WsBMCt7yFfuZB7|lQDPi6;>AqI%76{Ah*ddY;P71+SLS`kr@&u=Fn^~kMeWH&T)hUKF{m_oPd5DuqhOi-Kvzs zHeGc5I9)UYOHZE$0=M?mPQun9K(G^riW>6;I<4NGDK72(84?2C)nGP4u zu5^4vXVTmkYKGrD_^tL%o!@1&9Vmf{9@oiWc@5rh^A7K*xaPQ!<)4=ATla)43;)E5 z9P5K1+bMrO4sC%;Z~Q0xUB@kQD2!*|D3Si-bDN4&6H)6xiH-|f{z04-)h?<3fOSEQ ziyK?H(%P97ydOT-v@?tj!?w&}pT=4z4G)I3>rMYigpGXI^qG80Uttzy_lY;PgZ5tS z%E2)lQBC|x9hrUmwlu?&_@RxYQFkoQk-clo;2>=)n=r_cVODzG+Wk^HN)~|iwQV6G z2oVU_$r`<_n>qC?9JCE`pRS>)CYN=b4_c3kVZ+OF1VAiFByM+@W44{)d=2kAs>lfw z&LVL{I4;^yV#wF%$D7xXgN0G6YXd*pDB(&%rPVVh3EfewT0IyFm+k~#8Lv_?Ve9*A zJOk|@SFI;q1_(!rzBL4eafC7Om7#}7Sa|XcA0`-OF>EyO|3dMYF3J>f-0X(C->dg} z+C23|JhyMm%zXa#>1xzG*BrQku%K?rkZzOrCRJPAIa_~hwyD?h+IrX1Z&f2Etl8?I zCRdXvn0HpdxR0J_7w~?KZ}wE#My~&wY73V}4qVB^?kO7`SPcjIGc2V~%Jm3VA(7Zd z=+Jma5}`;sS-mySO?*=I zm+kKxE!SwCv*5Mt53rwgkG4mFD#-yl;#D+y`}EC1YKYpr7gAqWCn(y`(&D|}oocbz zWYFiY_R;Q+jMkgob1t<(A4=Oo#aSQf5&t=Vv}4W2`HkA1;_H)|Ot~zV> z>uG~sjoBfsYbznpfThRr=X{}kka**O8g_}Nn(+N~Q0zzlnGB5;K#Slfu9`ale^{wk zA-4>qJ;U@NEi@g?MuUMUh=I`S-E$;rG(x>rZ+!_Yr`Z>q={+OI40v11d>^Mux3;m+ zmpi$l75Gc8g8~+-9rVsXNNglb;P?8H^>xg%a)Dblf5&PryQ;cGEfoj#ZOi}tC{=mV zHJ7ht<;317ghTx3CWk8ic8^DMlY}{}FhMtA! zn8^8_%c64B0cp@<2}81quiU{QiQnGjMxOTi!o zd2x&y$_hH?-+Ex?aBN%f`N(re8I$?}3Q@|h0c6x>5LQ}hg;~MEVkiv54?Je0e>*t0 ztJN;?V3U43V0x^UpWTsTxxWNL{AsM3xb>HEGddClO`Z&Q!PlL=NB<@02tais-VfqY zcMM+aYrzh9v+gQUF~Y!sjv_Z69r^5mHD;lHEjVyAk2V6LD!UfWYM*Q_G;*Y8?!&k( zgMza1_|LzdODd3fN&YRjiyMHC5FbcC$~Uy-)7PJM0fY8yluZmswGb#xZL6#x)P^4# zo^fWznLa*bl7AHw_QlCCA>Xy;$Pm^TcU+CYd9_e+kw5(Snt7@IT|`#WH;)c=p}Q zw<(1StP}=<6D0HX`^%&bd@1Zt`OY?j!{R5jBQhp4zUv|Q+4>t{4t3TqP|9@r2kp*& z8~3bz?jw1)^qOS|`zAt~V zAE?A9G8^e|Ao$C;{I3$Zybz!q(s7=nM%`zmHFVQ{56|?fff4LQCuS4ODR} zW$`B_BAh45I7c>L@X~Ws4k%XuLC`lDi5%C~JGauoD7A@+PZu~X)+mrJkmSSp_r8Hy z+y<$Frs}mUvTvQS~P?SYs!!Qm7-0qq#uxa@8{cbR3>THhe(8nd` zF9o}u-ZtFYR>?Jgug+VP9M3S!lXaIq8w3JJq0=F>e2%uz-3XfROJ-ko@&91gzALn~ zySFr6x6}cH&K4J++$x;8eL4i#vha0eecdtJBnLVfiU5?MdG>qUc2nHU8NV6mB)&Yp zC~KNp33BwrZx(v#S-){m&{dGTp+#V#rkaU)*k*kiUoX!`Ed`!@{CF#8tWR=+t084o zkMq}tI&dkC>9q({c#lAYZjVm2oaXvqX)4S_NTGaXhnlVum~#tsuHbsda2WYHj7TLC z@a?U|YJ%@>qe7r?8{2ukRC#CBOYV&y+)@v^L7R9#O4y#3AuK6|$O*ldxN#FD`a|4t z{CG(Ib1g^z56{Ioy0^BrMyoEJ&c8fTK3eLf!TW4_ z>4GqF%_p|o^-B6c(c_E@CY5zu#t=dxeFiR`v8koSP*i<>w;k4-L(D0dk7o48RHp=C z_=|c=7pT&eioPGf|5*DTiYny%W>14{_RSVXKUDF$P~3Zm#I|_H$<~{ zs*de1hxfve+&>~;1SUvGhpH5-{Z)>VsoqRL9eSVP{jKT$6zb3~!t}%Fz0co4lX4+{>7}5R4vSw>=_0@)j?jr|@G{Js@fg(?PpAS=3U6LC$P(Yf zgGrRSQ)>wbt_dF#n{ILW-!d^Rd4>U2uVbj(O%9@qH?UAN4nwL#xv?&Y0dzgF&vGvK z(a@F<5)5Z9A5$L}p7+0kc15$(=CWt#J>2(zF(Z2K!Nf}Op2Eej;W}-$={ql2?g^Z$ zjm!TGzDY{j_hPoXskHR(;Gt>LHGDKIDH`W3H>Srz?R@`Qk2x!(|2gJ^q$#U4mS6Eb z!W4gHsT?t_3LwdnoLpZT_j^~jzP_HBnF#^pwA{7z#nG;=E+;ypUb@mT^w5mi?eVPC z08-%OxDV60uJG+kq*ZEs(Yt8b8{Z(9!>?)ak4rSMY_ebRm`(vbR;y!bd7o^=MBnP`?I-2v%-# zM*I6=>`i*Cl%b|0J*n-XUF%W$X9{?nH-$Cnai|q<_a~aV<@ep-3{tprBij)i8uQNI zR6`f0-;Wikos7N8%a`!+jKK8kW8?=@F7yY{way;WT-Jd<8-r_Jsj!6TJf;nkhj$=4 zKmO7SM3iZ@pO5+m24l~6NTR7z`j^!;E!2x~SX*1yetDh)TWY<+fsv_%cLUOP?NI3E zW}r1PZyj=y+)k`Hw&X>Y!_Ql}q?#w|U*UZh{ih{de(UrHniQ{P4%VEmk_`{I2fWJW zuOx`FD^%D5q$9g0p@%!;Z7PdoXYh?+Oz) zW&a1EkXx9gpE#i-Qmtu*c zu<`7L6ZtJNttUfaGGgE4@*1Z9!}jxYH|h;|(U}Cd%7fxxH0?XFiYi>(-#t@}s`KkG zDM=al6*(XlFiMC1z#C>k?7+uMJRWiI|8UJxCGx34icImy&r#yN)hvi@PeW$P3Yc?l zsW05seR~g4ZGs!ZB}6}tjM(10-3GTwD@4Bd_VHt8U_6M58eiU6#D5wePgiPp@k<#| zFpPYX`1FTM_|?nO%E~v_vRgJyH2jFP;F}TY^>gJaU=#Tf_Lq0(!50x!-%yK`l#{Uw% zjJYc2;`k3Z8h?97|EfBYOd@Op^A9^a4lC^ayoCX!kx)op$)~7oOZnt^w8^C**Ajv< zbr2Mp-+{N}f>j^n%p1r$o}oFPvC9qA~rle1TEZHE0z1FOND3uk$Z@B10 zklZMEPxWT)S88JaiJM2>N|VR9Dg`K~^zn2z2P_I#A`|A4nVBuwor{%cU%z=Xrfrw> zugG!d1Bt12ugECzZ9-1x#1B^=UYLGAs?8Bd^XEb9%;$y8o`|cjh`-ueyq@N-KsX3?3^=M-F`Pf-FH@raF9B(1k(;nxk; zhi*)pA8i5JkQJ756(`cV0oa9iGvH4kmVh z!8uFGx%3>-NL-*Bc$gZWTB)`t4U*aTg8yaqIEDxSF|V2sI;bpvG7FH1u_5WpNF~2_ zFm20rSMz!)|0hRyFQTVup=$Q((T-Vm_=1nIR|#p#!RY%kSgI_T{qXv|Sk9`D5M!8d z6l-`DTlw%P_RCe{V>$V4Gs?_4@;vJok2FwA%eqATlF^{BZLYfXHb>V*b*UKPbqW@W z(huMcmt~25#lsy=E#2+0K`OAwlWfR3*;+Vm(6-R<=X|YcW9~0HSUAWFd(UYe3_Y}vuuZ55#U?yDno9a+M%jGSv z-=U_E&qIP_PVCMFVV)L(?;U|)XzESUmqRRSV@;|VO`)0^qhkK98$AXFteO=o^#7{e znG{b;*-;+dYrDc!bau&$h`^1;eF1cLvNO{6^|T(`aL~TJhD0QrS*M!)vu940jup{v zWT?5p31yIV@20Lh36A>b4jl4G8c=3c3MKVrwp2+Q`rs-VieQE4?pco<_4pN%qGkLl zNW%J_ zbge4jE38hihzOnh{Nw{NZwd$YinAL27URHG04)qRqoht|w76Tn|%eaAt2Wgebr`BY%WgWJgUxghDe20%)EDIh_prv>p zzfC|r21Bv8Po2y9#MrdItZ(vO0tiUYW)G;j4AF7VRG$m4^3@%wa8TEPA?m?ao0BPOiPl`fM#CLbkLr*_9R!8 zPt1>fveDCO8#$}j@x&=B55s53s`9ysv_Tqa9-<|`k&<+b?W1IA?Jt;#G{`gV(b9#p zBGc-4GJgZ;s&vpZGR_X}42w$mcy)$as<6=UoDu9-q@s~Fm-MQq1k%*FhyU5bHzGK$ zx9*eQb`A0Wq>?+AogamLK6iwcn8Nk<)lo_SMgwU@MCqr|RD9~u`Gs=FegMY>%tB!D6AS)z{wmFP`zfllcit=DyCU+`0fA1GRn+(L&^eHVnkP z4duPek?cSDCtY5o;?X(x?vs7ec0))4v+;(Fa#V*nDbAd@U+w$GUrelOs2KYzmeQ>r zHx<#CTxUx!*Le`BxFLzgcW+-yClN%*pl-bY_;R$SQFMN znV<)t=9NwzYd%b_HgK49nVdHI)coQ#CN$?z$+sGEKVMF8P62uPb@|cR$^a-(tDG-i zekFF6mX73K=ik3Ksya)xh1%cN4zB!rdr$Q;=ZXHA?-#31)SawQp{jU7d0R~3|JL~Q zXswo7FW+N_tdN_M_0>#m_x-L+U*XUCq^ZW2r~lFKLDA(Iw#JoUpG5uqt}g9OlIU0L zG8;Lr4bKsTlcf<|_?e-%YDo&RyDAaUKBv({Ex`mC>~0RQ(UfC5Bv>$M_2dVP?eO4WE>r zS#paYReZYDo~`iqLC)1_gnW@l76cpQcB{mWW+79kf$)z4Kigz5Dv^C`jpkurs4xrA zL&v(GEOG>T^Tygwnh7g;OQSOw5VCoXz!+Fyr61Ry#K-77ex@tyqt^Q=cpHik(5jZ` z`eEtWJO0MX4@KO$n}@*&9X4Jur1_Qkus;|&8r1X{`X!(LeSy#uh;z5sI9jUM&_3)&(rdzqJeHgmpm?mTVON+IG+1oz|lCd3N7(yol2|?L+;o z?OMy_vVyz$`FHp$QIl+=EG12?WF2v9ivu_IW;O zKRBN-)`)3b=>A#yZF&lKeuM)J44)O#vLQ^znQfd6pwr@()g6e}hMVV+@OCe1S{T=H zLcT*#UYMje?CU9qwTCnYq7~Zc&nSHze&$6Iwz^wXq@v+TYW zrvcxCw*RfPMf#azd~^Lp&&+t^5GmZi`}D^LUs9S3BRZs=Klf@jm5ojW1mewBp3FDu z99A|qvJ#HH1?v@4=J{Pti_|me9yb{87CWZIKz$1TBTJKC` z3fC)7BxF>+iyW4fI5E^hw_HVT$?{OZ@b;HYuV*7NuZZocHW<@Kq+Y$+!k#;jI=N4f zXCpj69)PU;DTws(zJPXm8LVlenQD@`Z>SId6hN{O8I7ab08DJ~@EvzVdkE{y9YB{P zEy7^c8#sHR{okwfK7(=IS%cKuf2M_1u;x_4qkel#A{H-EW7!Th39+ai8N)aAHo(TQyoOb*^$-uxL zrR&)~G-&!xbqJge>1*bR=VHDU)w}*Li-s6%lqDDTj$)%X3H{EqXLUJ2abu>+h5;SN%3Y#_twJ^&=ycr$fG9f2?3C5KF6;arK$Jn%Wg6O6DyM0h=Tg(Uj$? z**?m6`czV9tU0yyj?S%rq$7TVgEgy^pZ(i!UCp}O{m!oH8>8rMy2T|_Ah4P4N6@K7 z!sq%~YT`{T$f$)u5?oAw1?>@^pWpl?%-AJpS7(7`Sx}kDNf&#zEJo}bs}2OcwVWj+6HN?ZFA)k8d zO0smmw1vo4O{sNK`B2#rfm~N1(WL*$u?WY^pO}US)A7?Mmdb&PfcQf>a1CPqfTjZz zrPJkr8`DPyXag;q-0;OEw8XAy*}JWhe+|gy>fbd11oIrB#w|Z(R%H94Th-S~mo5#I zv=mwQvC|&;+Psz||E1;nTh<&$Eo30v`pKHHmGF!>-8}GFLM{V_68!gnAt|PxUkbr~ zj}D%iX7=m3ZZc#nGwcOjNRq5ni34g4fVgm10?55~^isq;$O-ZAPX~O3S(UulF^>ew z?q3Kn+A6zmAN5!if!~nAV;iu&BLZSiE$Yt~$NG$nx*jT(i}YrI@_yv7a{(txQtBX} zCe%#*{qqK1GebovLXvKu&i^!7g6tMHY*nxx(sch4@k1LBL=@?}K1szh=Ca zE}Zz|Qzs=}R*%Ew%Nx(%RY;tWrHd5$twnlkykGOr1EFhj&bfDg^zZrX+gVvvQr~p6 z?!#6btr%#ktGl%CkDW+jv=+TIhrWm{{m*{PTRB~I7a9txJ%%ddqLAg@2GP-2-I?y9 znM@x@c@LLY)!=o!MkjZ1v(pp(%}ER36G=H)8DM^@@q>2<%+XQcGSJ$$WODg z!V2)PB9)#SRZWiqZgFWqiRqNz1R6>jJN2Tx%Pfn=YUp=FVv)z(IPMgTsmz86$&_hC zrff2Wo2r8bNJ3t-q0x74?RzeE#RiaQ2{I_$R#l6ykC3R+-k6)?Pl4gA!^wK)n7*;| zGKILgT!x`*$0FpOJm?G>9coX`fBl!o`cuoPhY(}NGn9FHv)~(&QVJ4Jp$hSTTE-A6 z?4QDBJsn3)^xtD5c@0%RlDV6tuk0BxQHQ ztYa=rMu$FDll>5$;xEPEC^2`D`$7Q<-ysLk&=imJJO=+X&>Y^OEcSVKTJTM$DqMqn@B1c4uU$+~{i)^C} zrjIPn8W?})Mh91Ii@1OjbopILC8_8mmL`I`c}N!!GcIQPi|4XV)mN9x_sNO(E z#F{k({nw_EsjS>~Ewu4({oErkST;Jqr3BC2n>xbe6cUV&5DuM}ypDc!n*Cg2}%gUVmsA7P*IFb}8>EEoN$R<&wPk8exU zpMYzA;f|W?edLilh?^t+cT;9WFaP4ROKH5lt*c7Q42(=M6q9e?zRlI0VL%xn+M}Dv zJML*3y$N@tH1{M7ox5sl_gd~uvwv=)xKG1kaL;?;72Qmd^SK#2wUU@u^WR#V-ad(w zZ7^rtv##dk>76`oH>9)P^sd zeaHhlAAC*gQT>oF@_kV;Sm8_ywzFaw#^hwhc=BU|BYljTAvimMhm=55_yG zzqeA*6!L1dS2dJ4hy5kl)nbA|rc1pF-jK}wRkpQTuXm~)zpA9Emsdo3j z)BpCeBwQJ|olQm5bx+*b*PY!lsQKR0TN$Qp;_R-sZhihJYCpF<)+6w0QVQ0)FQ)P> z3zzkWr=Y zP|uTnBKna13j0*Miph5;SBpdppmtcB|GOH#+$EYLafHt>+q#3&{U`V51^ZV`Fs0_` zuU0NU8j+F-_v`3LV}ulwR>a3+y!1p)2ibu$*!3*Y5DA{6-|Rz!A@>BRK)!v4qcu|2 z6N1k*=$S{L4FfrCU=AVdBfx|Bq{BkJE0r~JR#q(`tt*#w zj)r)|RmfWuN9z|TRMEv%LLr%wk4En)`i(mcPnX&I_<0L8y$MQVw7 zi%@vWjy|e5?PVdho>Sb*cwJ`~>z!X3ZfpJwHB9R#%_YeW^ipCO^O(-r0z&#A$LWqO z?pXVMvOWG$x>ddKpx-LNQp+i$!Msjr`uTnzW2M`ey+^HKg0><4^^jUR>BdPi|@wEubAUI z=`klFqBAh*5Hf|T!?$=^>$87^nVJUlCX8o^GJN)M)@Gr80o{bVNXx?2D`zn3lm}a1 zDiy%Ek#_qFr_}FW!z=&3hMbe!jrp#2_ERa%YJcsQ*cIBV&t&=%gmkt{l>V8nayC79 zPJ7;oV%?Vf%Czf8mRTF02jM=(v!CQdFiM+YeqVVvztYY1hz~cN{M<8e=mhweZm_@RNmbLj-mI_NgrfFE(M&J_hX!lyW_p;o)ms!D zcY3aFx^pGoHnLKRh`jKFmDE|?H>GWj!d=KpGAA1^UqSN_J;&Teg0ZQ}etQ33V zgG-c34V)<$-I(C|&d(FIdAN^f#3>EUcwQ}jQ$g3hJGuX|PcS~JFqbx$!_ojY2#`_m z1LD2qd`bxYW$(E@cq~l{-0^=iF{UoRI(`zPUNk{mIlE1O^ay3u>`41^onxs}-ThTo zq$TfC3W!XNZe1IN;rVsXz7VG!&GJEkl>I$7SLCadxi+)zISU=!E$ zFE??<7Sw4Or&KpYOtN|mUn_aca-p7>Ma$B-#-3Dqtx___u1x*pwQachP zjhKEft4mz-VFu}3W$;|y4UAq=2xl)n5jD7;2}K!2BX+ONoKih^4W8`p8jL5`JP+L& zw@;ryZvuedC0rFpo4rDa1)JQRG>dHMukLPIR2WmPM6r+el=|m%1y$yJh zi)7wL4M}m<=^RB)e(`yrG? zb>q23g{jI#A;wLXpD&Wni^NNi9rcc+np(X~nQ=`|@tlv@QFXX3Z2_w73ZZKlz4U6U z-HW+)(~%$b1kb!FZp)!KUKylCOc+fS-+ktdR@1aoR(yFAz=L}k&&tHg8qP7I4|@ap zNfEeHsHYbwa;R#S-%x3AtCOp<313UA`OJAjhg5{5AG`@gj~5i?v7G`s830vqRKa{D zbVi)aP&o-Vuy`oXOmixi;0wVtf^OlAi*KOw<)#re;N+ZF_K+q)U((0Cg8QG2RR*2eQ-2K9QWFWkJ~w<%#vJ%jGp6{+ zF9wM-%bC9zKk0z7_qXQJQo-A-F|smG{Ci}^pL=;{6-!|NcY?0=iA{pJySo7|64#7> zzRg|Vd*%I{wSrdpXMfyStB2ilnUjI&MAlpLC{(JQqqQ(V6gLeWIK-g*K9DV$lVrD? z8nm6VUgH%qaCEN_4=qj%KujY1S(4#I7noNr8nw`>;PCd0)kxp%yv&+x{L8jfNI7g0;Np4LkZA zB5UBHTR)O@{7M!+3%P*U7QcLSG*244+mW&M{g0otg$M|qVwCjfQ{+#^lm&cxTT!8< zt+eQJCrDbD&O7o=`pT8XpDf$`C9$r=R$<;yj50u95s?*MwUz1hfN%zr_-cyM&u#^? z*G9T-FGXiv5E(N8E1AqKmFIgRdr6S*`slIOSf_xST8&Lk_O2kc6uvh@?o; zh{;x4Px#RY_<<^lbZnL0bMwMH$Qb(bwAkM=#b>I&t@zYY=>C0l9H3tiQ8h#Zs%b-m zHNys&yJ0juWAA>|lx`5_%n0R6b1>)jkYJ7%Pl!C3z1D@!mS8aHe;B|+9r&OY4zI|< zpP{Ej==?cv26-YyVv+P5XrO?*whsD%w1wN2Dnd?Ts&5Ywz?FLy4>>j-yie9?#8_y< zYr9j+4&F{Jn9MiO3nsl&hEGnwSX;6NqR`5X^Kl!l4AAr??AOq|@XZhNASrE0v$6EU z?nSt}kuN~GIgwtwF!%wfAwyDd;A!OFRvGm82A7txETBVlOkRTBx=r2}JVb>j_M4oT z9Po$iouoxWk8S*Za4@#dTw*`XJ5_opaw8s~Wa|0am9zZqNhze|uQPEy_YJBOn*_|z zRn=cgSSRz4TK$sHd_3HMn43ONrDYfcE`ft2)kM+KDtKLGkiCjvoDM@CkC2>RA z@zF()?QPBJzCeZ!l#kN;AQ{2R*+BSiZ%HvMCd>$T z{91w!v9N5Zq$#N(;;RJZeHITU#g3lkjp1PyjyVxH5T_J73gRd52ry%paqQ0zu&5w6 zYfT?w{Z%~P*4e|WnSn=w)~EDa$)NJ+Ql^$Zf9l`U8JIOG}&bO9HQH zv$jIbv$3PO)Y3WeT#?sMRcEw(8bP5*}bG%{B%eTt)Ky@u_Xskb3`21C9`%OoQiWc@ky>;yz$X-8qoD!p$tJECfaf-1sIdWcnd>#I=ggu|+?~}QxMD-O;};SyL8f|h8>GLk?AHOG-9)J)P_r&v6r^(qC&bF$t0U&HU65W#eFeUyzJCB2+Rq%?W|IU#Ak`PRpD*hO8t z&1lVJ-{nty>zs5N7M)be@ZMa5tQPc}{hIy-k~U zJA#1kE=S&{1rc;C3pP9aY=8gYVaWa?s{Gk1X%oR*y1zuAT7T$a#4oW_2Z9VTrnN7^ zZyKSk@xYdnI_(ubft{4X!Gn*fPw54WR|O;Nsi*muF>CjykweLYQCR%oWj>tM=z5h2 z4-~aVT8If(;!ktEkmrmcyxJBVd#vf?EKBOs@tjw8c1FRcFmVjNoPN?Fb%?$KiFP^bDt}I6>}jfwY%(_cLlv3(~nJ z`5b;zeiPBJ?W|##;J2{4f`3g~^N2FQW(UoZu|>ZNk?{G4FNS$~6h-!_VM~1$0Hs^R zq9_ST%YUKmT)Op~D5l`8yF~B{<|Spar%b4j!yd0RPeJTgjCs=WK>K$(l|di$7&Sd7 z*(=oXC1HnL_B1ZSF}k1!wo;mW;m_OOU46_L&m@#0bXW5ueB_d=P7cCBmi>h2u!q>H z{OwgZ_*s$wb*N%H?q0tPi>$@+KNF2tKUjJdEQ+lJFer;Y=5A5`yT#{j z0-M`mW`{MCe$55HC+GqCgdscyOW-hP-6Y@TFZ0_#L z)rj<*#GhICR#+6>!~c=jL?{p2{|6cDz>1pgb%V^IYQ?_z=irK&y3zOg<=jPbtYyC1&J zKO%;MoCxHS5Bj&Xxp>^aNCR$-K;aLP1^ll|a<cVSY4zTGH$+mXDKE;b$t zRh9<=8c^5-7{v32jH-HOn(yM7tX63`o>NC52zLhE)20WAF-gkNmbtT%AW_R<$!tPW zjXm#v>PA@K*)dkD+#|W@{pP&!$!@T9NCa`)R2@*&B^#3DTwqG(#goLEN{3ayj|sH5 zw<(7OCLFLAbbq!$>X>6M7{5qY4+H;lTp z2##w5KjcXJdnc~Or_I?DTJzW32qwktn_RdOc%l(J&3O9^rNj6XA4E17FE|W4TQI3% z{>Z+n4U!>1z~(hI3CRB#QgAmA=@-((m%wPNBfr<1*g#|No_6nNzj zQ(;bZBNt^J^Yr-HeC_5>jIrTUIU9K&J!ee+-TtGmHBVlRk7+tq{pG+>RmIYrpEYuY zhLumRJ1GPqWXY?ztNb^=>{a*9@Q)wU7x)LwPrQmq-*cx=Q?d{)v0sJZa+&=DfN^kN zx!R^uwA{sL7WBi+=@{R7m5Jjy??24;7;b!vazIEVS!l{U3{k!}d}p%}FbRB{t`HE< z2CoNo70lZ;sX6`(Op9VZ6+zyuYBhU7n*&+B$jK$%hu+nNE*k28|R=eSvF-#*=Kg4E5E^ohbW z{Cs>Qq<-R|Jr=A+Xso2(H7X7*Za3f7$;-;Ro^So;V3gAuFTec~*_S}F8=PW>+G(OK zbxF~8tp&1ScOH-NCy)FHYSc1+7LA}sjJ04}N>Yor>=!p@+ENlmm#f_Nd$9M*Ha9n) z=qZUeuyGkyNx%*Qx{J_dWsF@dLzJp4AI!c@D&IkM+c7C54^l6t z$4fLauz5hv zdtT3mjf}(bdle$0DEKF@)TIPY;c6$?8am=@%(9 zXgxxKHT1tYXd$lJw>}W^ zU{~QT<9j@)`orY!AUsTF;Ur8pWov6TD?Wc2AmOw^XBTT z(Isse-UpB1WZzlt%f9^#Fsu&4_l8nlJ19IW8iK#+)ii!CF@WG6S(k-b+dWY{7tvYc z)y``^T%06Ae$GRh$~iVu2Z)Fc5O+>7-Q*gu(kRnGi%{JCx<@F z=V-c^*E;@5=Twg2ZA^Vhjg(BtiDr{rTNmRs^1=_PxlIQXX1C%+A3f)GX>(!^RaReL z^hEIBxQ=h=ukF20h)m9iKQj|xmG8_l`=0E>WfIKw2R|q8OSg~MN02-&>_R0{?}%z) z7m=m+KSoY(3zwQT33Frz#ohSsxsHZVef$xStGu9l#(F+Qttj6#<8+nN2M$9mCbH)7 zD;Z`Q(jbp+v25LYJ6L2pm|R;JTD9Cg}O% zYBKkiOjcL&Yr9<%J74sXIvTG@ddtceZNobBSh=MFMa?AARTfa6t*M@LQhT=815icW zzS;N`WU#Gb&WK(#<$xLxv3@+*2HI@Kg{FgpgP($nb6s7bu3y@ZHY<7qn_}+8v1&bT ze0k!3!a|21w5^+$Ni(&FTy#2C=3%|fN>nsXmW?~~KWD3=1}?SV5L`VGGA6Fpsr#_K z{OmwWeE0P(#0Fq%{}n!qQT)>7p_JUF^8$D-zq+|OAhe<;@B@%DPrZ~s${8}uE|@4s z-^eX^0;@?7Ey3yw)6g|mol;&*=d5P&L6q3s7oN2r+BH$L@P<)4tK|gM@lI9a)l<;B zPX57)jgY8E2Qn?uXMfb&{Lt=ll5vt~usv zCx&ZJ3XC_*Gv|Z$6rUOFSTrE=g8u>K`XueEJ5&UvXmkN#x; z+;)L#h6xw@{thMS)o|Cl)1kmTPOr3WfT4-HaK;^ty#BLlP!u2(_ft-Mn-?zyu;@qp z)1d@&lgR$U=W^DfOt3y;x_(KU6vKV&D)NH(n)d8+qh~beB;z=fw$RK*rPChCO5>HD z0wH1Wv->OOP`<8s{OcV_fcF0ZK+n{McFViUh0OkP5Jx{hyR~e%@C-k0YKc%N>iq2} zpVx;X?MM%efPbTWhl1R1AK*aNa%P3Pr7{k;j{m&aWf@-h#4egIIrF`>WOQV%xH~IM zq_P^!ETD19+?%}5dUQ;=&|}I0$CTA3Kf^PmY_&mPduwab*IQRT$|a)Q^U#(2Z^^A@ z2W>;@GyA5SB*$W$0^B6EY}op$2kUC59+h%zej>7>>q+YY!Abi+{M+`@^$>|!MZBOgy&t0jG}2nAmh zC>cdAyT|7+&|3ml?^ykF`qUU$YCoS@;A}01`9|;WqozER@{up*DJ5wU$#+h+2Jz`Z zvtbw+a|9^W@&^&_JH=+fU`F+1F2-@T*w~tQf17*jV<7pi%BG?eosmsBxAH|JzcQE4 zENeq|3agnmkXW0ea(=Bz1iaJ8%f5;`3jHdJme-enypw#-S)aX92TczK&|ErUUrQ8# ze7nQyRq{o+BZnGlihv<&>v#O`B;%IW*hSE}v~WW~aj`jDliFkl45cM{ucq5&IKVbr z&8G_ZFF856Mt}mc7e}t~x~_)^i{~bJ9(CSL(@(*;R^ce0<2GL&&1L4~3?}RC(z&?1 zk8p~qPAa)p#JR{f`4i9>%&-x=AB>sQch>cZyR?kq$J=ow3Zt}uSe@GPF6a$*y@+{v zVhaU6=6~N7qj?qMZ0>;X@MM^^52#tr-^8B8LOd_DekOGK}V?^v;}WIYQbWmz+)d zpM6ToVS&QM|V!3UV zQa`=2j*iYoJfC2hpnlxAa%Fgt;FcCB0c_)i;DGFso8IAG>^EaOg`Nsc4mzK~zcy++ zgQCuFva+)D6Ps}+zU9cPXbsO3?nJ&+l$0e=1GilC3e$ zl`lE)&sK;*B(0oyUK$r&8%Id*s##Pk&MR#;ZveLHlCWbo;k_G9epl!$XO5lCRJ9^3 z&0x+kia7CvGbzxeNpod$cq^WhzQ2klW@xbzSeI=u$>ncbHiepmChOIJE(zj8; z4(n5mHfxW!U^%X<^8Kzc_7FyF=tB<0*8GTyPm=MN*CV&d?ZOFInv>pSUe$ zJ6ef~axcz@AOt>h1IfMf9}-(t8XgkdG1)ILz<;lxvwl-yWB*XU{D-w{RWywrkLS0` zY*c&dkCE#Qh~L4*{U~X@HgQK|JJEaMiEayTbzdZn#YFcy)V}qo8J@1n6s30Uuem0i zn@VN0Y=W|H-^PA`X>$`qQ#eJwZKvOc!!{Kx#49-f;|ZIuBy2fS;bIc3x(?RmoIt-BmC74u3p|>(??K_vZs%g> zS{&S<$%QDA2uqbwFqI70MJjr2XZ`Nuxb1XI8*{eXzKC6R~`+Y zWS+NezUcGJI+wd={rR<2;YblHO<`f7r$s?SCpn(?nrw^CsMMBFEi(`M!m~>EOOfBC z#NV_&Ho9$mq78S1w1*=T=_o@2E=6>@~Z-ue~ita(P&1r zhC7XlODh7>SrhT>X|sjo8erQFHb=0fC=jU!MnZRQXimT;U&Zb-bpJr~1qieDB+fz} zdYU!=&72~SdZ)W6O!MHjh(4GX);)}4OB8q&WH51o0kM1?x@!eokul<`XxW%qmNT(hs*5>nQ5OiHEzB2{^eq>Y zEXbR65f3@|GaVJ|v(UvTJ=!GXxNtdS9#g8(W#B7qe5fb=2UUVa6>Nkd46O^g}YsQ_OUGS#>zc! zl1AW^G*ooofnfqu+AkmBc?3pWp7=*_TPfcjm&1m-^pv|aBX zbP-+s{r)3h+%rG1$I5u%@9N2xv0UT3_5=@82V8;E?X}rYo19CC#CYJ=ad{aP`-q`jdh>JLi4Es$PAEcob9I}TP=VpRJXP)q z)d*`!QWH@Xh3AYBj$3m@>lVXABlKAfUxwhtCOt*cSH>o_{~&)y@wZ2wJ$vCJ-a56z z653NUv%Rm{FWMSh6bKouRYhVq*}_XBnuxYu^82Hn|&61(tZ6(C*S-jnPjz2FUy)C zX9+p)6-`_CI3u{h!?&Ye#RahJ$uiFD?2u zcM4BfckZ`AQ@ezo3q(6M*4D73+?Py?Y$#kjuxHfs=o^d7Zi=CN$%kV#BOrTJc14%b zxtmk$rr@n<(tSd>DOOTyI$zrDoUC=JVcYFMe(P!UH3sesrp{Fa2tPGzCHpCVvL!Em z<>U2m_6K>f><=Wz4}$9hO;%M@OP)y+Va)wT?+_6>6>b1d^~(pc0@Qm%JMDCr<))dy z9;i0xPhyL@I9qDL=@l5yVU?K9Q$mLg-qOkv2eZ)0)+S|yE_#$oo|MR150)aVqoz5I>cYEG^0TvP#Kj#)}<>dyD*`(W9X}ByFS&2uhxJNILzXFDV`wf61eTcc6VhfDlx z`Vl@MTi*u7{c4owI<_Ma>CbijYtQkifmQNs;&Av{Ql6WBX76_VlC4?4l-IMhkGVyX zVuceje2d~W+X8Py3<)m&15D|)d&m|JCj$LlMW zK8ynqsW$PV%&p-vQ5WFfN%ntd_HNa3Pi+!!pfM0uybupY$Jvk?gKuLcjX3}3mz3t6NaB4kttNIfOSN0c3_YPJRV{=s|pD> zN3It9CU}zhfU*Jlzam~2SUCZ9yDhlj1C51bOPW5^17B~ZaI=%kzsA)U_}}bAU}V0K zse);WjeQ-?@o%UV;0cw2{prUl5dunEl+>75qI_rhXPlH*Ij?o4H{vZ`>hb6=T-RH6 zGEb==NM^LpH#W+lZ&i9zqgB@cotd<;s#{f~0%v^MH~EIN30Nuog2PXzy#22Y2T}5O zBn5v^LzLxr>}4}#{#{g1t&#=p^PKvv`rQ2{QMQHAQNPQ0iIu~9d!<^mibak>^oG9r zN1r1ejh*!hf*|3dcG;CXi*Tn5cIw5mr6kNh;T#gs-FY@~?WJ2$6_Ja{F1>VBfRU}o z0ENf&ip~ez#qaobH)zIo zj&%BT*#^5w_(mi}%}BxBjM3IF@%9pDg?!HMYMp(jp5TDxeUktqF8R};wp%@SFn-9q zF=Y^BXG1=O|Mq$@otOSuSH3+U&pS8756fFBH1Gx;?4OXZhpJ7XV*<-45RwOz;L0p6 zJRe5U{i!WbwO?bT!SLR@SFbQ>wp_as<0Fl>NC;;qQ{J0`kWhC@y;TBKNR3A6%@G3A0@F+EL7o@|CU(bY9I1OpZP22R!?JS(N2F3p+m)|GV4%qlE1;^aw1WN6-f360|gf_X)3) zQA;$*R}?Kc8uny_S9DwIW`iCz$Y0hjJA?+BSI`2!??FwP(ePFmhCLB^B%b`JYLreG zOR++5;!I_lGSb2{5nA&MPS;+{9A0J%+bkEmVa|fY>O-Ri6W&{34zW$Z3A}NYleid) zFyUWBP}jd4^`M-6Oo^g>hprK}yz6ZoTEfSu#PBW?gpxo3uXMkQ=zjrW^{6-0Z+iIL z`r$T_0)OE}fc@b@4(&l^q`G%pl40`oOSF`~|9?a*azLf1L;#`)P>LW#zQ5+n&2gIP zY6b@_VAWzp=P!~LJbMUr6Wm=j2Yt{t+T1dqpa z_XeN)yJ?DOXoX%PVsC(T$Y4{xKhpiLcCxJt;&$-gHQw!{c_>^{Dd!F$){ea(y6OXaQ4xZ;)ux|SQ&kG#d$${nY z{W`X-o6(cahnE2BhK?OM-4`SiSU}De?cTiAXWQ_)~io1()pIwGVJuGzo;?$F-+(m(gXY> zBKzy((En9{eb=;pUTL8B!`#!lMC2HG7<@-mnu56Q_6cR;X_l8Tg07^l=nJ`M@5S!uj1%b*5Tl_*?N>;@HE!F3KGKZ z4dP+Lb_km;>P-p?CR+9dX(MnF@p(}%|+hx_9RHWFMU#4{qosKf4(!35fKZc zb5RQkPu?TM?j^bEjPh=a60LM+Id)RS4_Wt$ld9_R8?Smz4d2^82;aVm^AQU z*@PFBMfV*_QmF}2zEhu^*?neFG=S4gODjyKWg6Wg$4Gh$zps}jJ(;seYlC?e(peY) zL3D+9*4)-+0N4Aurf>??n2MC5K@_3K-L<^%Jfxui)JcL@{GYA0z+55Ne|s7C#U$Fq z%eob`&vl-YF#hSWizmV)wlMkobeU!dkq@;STn}!qj%TO&K@j*9uE5RV*b%q^y<^B0 zsytma#CUAmTz$vX`XId%c8ZsYOrjrSyA%^tt$rT*(B3vT8Y}kUO(D7)53Ka+B1Hb) zH^5;v7O1F}7j?u>tjD>d3hgWG7Fqy7>@Qc_s-TH&}|0XGm?c+ap4!dY>2zHON$F1?R zzECg~$YUKsxHW>6YB@Lzzt?afyGL{BoCCSTV>NvltQ)B_6QO(0yri2r#Xd{ir_+Cc zwigikuH2x@t3{T-T`#t&E)je`^mq<{il-GLbjaa6-E{jMyp5n=sZ(+c9CalM#2L;Jczi%pYL>M z&V;9Ib^aoH;PBtHC72oK3NI?q-Yuzg{R$?5qpEIs9(!Z~Ljf0^@XX=9gw4o-kz>!} z*0^ZGvXRt#{XR)P?zl=fjWiU+U8yCN#?lsSU**v5BbjFp0Ke|db0Ub(1NT#ecIO=k z-k&3yGHu3R_qi;PDzN3bboo#d$WJ_HQ24}!2hHV?r^Mgr?k%Pa4h-bo^)YEVYZEgw zs1o-i{he@`^9&`=P!H{1bgtVu?WL&y0;Ya>(X;b~N}=RD&ykt1WvU`K^aHk}_O>Q# zx~KmXpuAofBP-IsFPd`~e;U$kUYTwPTHRCNtG)c&yI%#e7kt?AHle!2ix0ELcmeOs zT$*f{+k~02bfD$CH#%^96kDH&b+i*U^c8&+{asq8%+cD>(QzihlKb_fxKY(8G`Z?z zxe1g6cc!@L6sI}jzl(1zvQeOk3%Q$47lLH30Q{QWQY9zzz`Y)=o5XoTlD4R{ z$h0(x_ZHZ-R=P5i$98EvSq(!CAIGliq_J3>dZp?h;_o9)+t>8QRmA5(`@zX#*5Z@b zT1rn>Xd~LS1m^?Yq_zobh>Qi!2|pCaKcoz@A$|j!wYtJzUjhw)L&9|{Q-W{6&X;I| zoN0Z1JtbN~x8!XfB`_91yH!0}cw&-4dxOSu;d*B#3==@IcSG=93?SJp z_Mh$4cbtc<$=0FD&%QR!@T~1g(4+_Do+V^yiAH&0f#L@}^ccmWwVVS9st=YIo|*gh z_xHoh1NMz~1uGtNQT-vqHag&?!5&|_#LeH!$aWih(~|)iIm5(99uN5>re0gQYzMBz z*KFP(_4Tx!`xVbHSR?Mp)VFUFI}p4Xb~R7jJ@j0o`1D(B${OKTE>tg?Eo{47Pnx2e zGMWQPyjkD4wQGhinSj`tPF_8wMYsy$5L6}=!o9e0z%i}~A z*#R!`?D(UsMJ-V@F`AbI7pf0lF#GWK7!F?Z)xeS10B`cCrj-#~-xQJ7yrT&ryfyabH%{v-|xrS)( z=R`P<8J0+ztr^XnkqHlz1i*zIpE!qff~uUR}>m2-Z#j-&J3~QtBFG)7lnB(sOMqud(uD%+E!Bdk%v- z6^Q?^$h5o5@tPx7naZuOeDJIHX~|&Sh4d0q!zOACa&!ISl2tF#-DQ!6`TgID2l6Xg zo-~#N$rComY8O;oavr89%pLL9$NyBC!+1R}zbgKgfDY6_VC!!3jsQVtm`#M}NP|7! zdFR-DsSx~(tk)W+@qGdR?D-I)MRVJT>v|N_dN~)@QktAUk z!x69ki+$`N4BYNX9I$4XUIV_4TUi-mTEtP2=r&##FF?tembeIWdRXWZH^^73Tm}Ku z;uHdn1VVY5G;IF}xR8G0{V{^DN<1M`LB4s4mDvnJZ}|FG6oTFUAnwq~!VzE%g!g7s z^C%=d9>@Qae_wavDu7$<57Wa zA0zNEzOR*bA92ikrgT!81aDvRhRyz^R`EY?#YYFxO00|i`I`xG{S}8dX|^*NlRLj1 zuou(u zXr2L&EBj6`G0VynZoE6>ZHhx%_|?oX|Rsp)sD zy|0PoT*sjPLPV!6c$c5|H;rd%1Eal4d$o-bpHkZ{5`7{*7Za?O~)ibONhmF;U%RnK#H!i+QU+6fLn~y-| zBf@(n!EI+yX?llCr0-;eoKb!lv5P~wjelPK>otSnp*4NIOJzYn5<#Mp_0Wg+D0r<1 z=!WPnJR6*TxOG}?DD^DpLO0ltYKp0`T+)}VxL1v|uMNvtXWaRAE0Mau(wdT0qw-3< zHqr-FygQCYR>x|yUfEZxTjEx#;}MFm9~0iNs(PV|Si)_<@k0iS(ev8y)#^LI(EZIGT1 zN{H3ZP62<>WWS1lZZPLDAjyEC#p2e1%hfv}J`u~6>?Wb_#cSOI0%#P14~|%Ek}=^i z^|fKt_AV?Js*cFMRBs#$JKp1jyPQF`EO}LtL!B%7u9hU6~ zYtD7&Z(0DCF|)SS6mf0lf&{r7u^lZUg5|s9i=p{FRK#Oo?*+rU!QD}vvM-8v+)mz*`rGGb_}8w`tfkcF>&sU??6F*VZhWRrL$QwkM~QXeJ(3RY$eA;hB@8?tghC zS4?D%l6x}Ac#g{8PdJ2S-@bh-EiJ9A6n9W(X%NeWF%a$v6;G&B$o5TJvkS>`J#AJ$Oc8>g z_|1DwkD5#06>KKix4B;A`_-{!q&T$91c=bw{cW70?j@pE8jq4Z%1SIo-HyZUbzdX; z3K)$x%+HtzVHU@cU#%_U27cxC6xSKV!uR_wjvM&gpWOa(yz6>ijyuzo4J)^N;6v91 z+T6QAQ6)++VTMsRFo{hsRmZC%VGrn4N|JsH@3a~!Fq^sV5Ht=(S!UI z2hm||K_OrLLx1A7vcDEF`U)mb7(IDO;m^7zEvWeRt-%F1lYa*eslV+0j;Q_UxRJ7$ zxn^UDU_Nj?zifYcm~m23+pOeiZRP%njSLCKd_lsjEMbwd zv7dCsI^d(`t>WGflQQI8xqLaceaVUIdZ~qJRc)0P*2@nW1SHSV)X2ZDN?iPGFnNFX zm5GwncG;v2@>aIe8&r&&w<(K*j9yGRrls#t2FrN`_0Yqw0-oT3PwohmXJ$ye*dao9 z+icKHVRJbUc{{Q7dYqcWf5rLpz3)x3D`4}MWixb&Ky04%>Ts5PyF`niMF^#Z@2?~b z(>?cu;R`zM#fx1(>kYG}Ht#N+`n8uHcv&`t4oM_bkF2k)GHdO5TjYA2(EhzU6p3#y zJ(so}`Mtb7Tq9I)+z;KwS!Ae+TdGx{8R0zn$ogsSlFo;erkIf`+ulz^;JFDuD%MSq zDtKAJ=3gYxgGiA3Ubdt}^ro#F@y$gS101I^V4ZSAdA}Ra&g&Y-5XP;F46Gp#oV9JP zetg*2hi%i!EPQHSxgk#KZBhb$1*@%j6Q z4tPE$&!6knnj~;TMzb4E9QbQUu|}DiKb=PD(lyVNP%W2xuqY;e^m4X&rxiB@h2-fq zl?FTuw_`@nnx#t+de_WPVCY%vR+`fA>o^$6JW3KT{XLVXaTMh}uh62OubXn{)DrMR zs0w(qG#Ph?%?VsM#X2iK4;@?wOSk`m((Brfe33B%i!F-!BJRl8(b{K1y-*bx5Q#?K zWtD8)InMz5Yw%%do$R%MT|Gr4>hmc=kpKn>X^JnL{yrd{bQe6U@_E&;V#r{$LQ92D zZHWMY@-X7^2XcFMiT%{F+lXw-cTe5-H(5NEfCNAP&eA1&^f;-4_tBHrGk_{kS?PGif+W;i7{Pn3!PuZk}s5?5~Y zdj3?eUgiE$hxS=zt5C^ploXm;{QV_G!aM38;|2<>C88Uv)t;<=7@|;;l-aiW(BSXW z_$O{RB70Rf7`C*Fj4u-Q_qnd}#%R9=_H4$RVLP$aWZD&ZXdq$GAy=B&YB9LxRr(y6 zplcQ%OQ;R=w_cmqXE*T$$nNw|iCsc|h^j0DDXcB1t@2902!82Xw0$D@RMkZ_T}o25 z$%=;dZ$J0HChPq9E8ID`!0mT{|KJq|LTmmF9`=D9U)iaNF2D`^meK?>PPM;(u_J@l zU&ErCq#>6-TH33;nx%2|vR&N2$7~Fb`2~DmX5iZq2Z8vh=1eq$*s4_{p7oQ*?oxBV zokQQC6w%`ioiY6bjiM0twr(h|s5)9m!vWxRe|42*9lKwP0K)@c7Zksyoxj0Kb8%(m z51pDCvV2_N!M%9eO^s^l-E~DzNb91(X6?&@f=mq#liuU}?+1ShA~?DhF#+vLx2U2Y zk$aGst#V(qm<9)q(dItvkS4Q%jr&mU=1p*`9_}8nDZWYj1<+WqMuS1uM}r-}e;QOU zrCbIofl7F!m>G--t#uIymjS&MVR7)cI$KfcP^d{H_i*RXBbg}WVwcxsV_*eAaGo$I zT5rm7g0^-ac9XL4!oQOwHrcA2Y-k<7@|y@%T~Y*fN7UD5Yy7c`1ku9&YgI<$A7>hD z^x0dLPVR3%RWv#0D)rF~v9Gr^i(?r4h1IR5q8SyduLwC9r8SoO@ttAeeEROADbvt> zj{@{UxGZ2h;BG@Wg>@^_xC--(HdwD?ciV&&w2e$J%aqAWOr!-Lak_>6Y%0(rWi^^y z3*G}&G=7eeAMY)DTGE0nm)+ejniF>@lh}YtC)lI#>B@L@der#-BfKM67%=*pL^=G6ut-YFTOKx4iJmkn4jUW zjkMp#tvXs!4-MMk?=>{1w)foxO3YS9IE*qMO3sz_I%VsY@ps++%#d+Kq)C)%(g@#{ zTDuwEyNkIU@f)k6Prr1S`O?^A}VTt_04YSH7*wsZZoX894ZO8D8CGi`}pz%QY74ELA)25_i^}9 z$%D;ZZPuLy??J&eI%K&C78r@-=61Bx-j3xLyB7@#)?BkUHu02}kGom?%;Zdy{in<* zk#yb5MRgK8Zm7ouw(vpVh-b#5*KY2U)lD9}a)^F1AEP?J5N#Ge`(`GSH|Eec@C+3dvMWJ zB+Ycrf9xbd39@r`e>4^9*W|^?{actvO*q*>844;s2op%--!*hQB1H6d|528*Rrli3$+G6` z{IPA-pvCEd7f;=|l&2E%6Nf_8mrv|omd0J4(kg7wgobrZ**@2})0M`h=hW{v77mJN zTbA$QPn`Dpz5R8-lrC=Dot>I$fwc*?>>}M9k;;}Ah=Z@2 zB6G!}%+jRp*Z5Pe;1}7gJ`ju0&iJvv+{N;actt^tf1S!1=0T;wU0s3$VDX)ch(s4*FF*|5KKeTmx6{tNS2hT9CGDZJ6iLI3B`yE(1 zEMu#MA=dan6HUN>2O zG577;J$2&Hl{mBvpm^rFmsf(XXE4*|OhBPW+%LC<)Sh5ZJK-eca-o8SmdrILQU=Y+{q}5QmksSFp!RY=qHxJ@ zWpF=+!)sU~iqbwTOOLSQVFJJ6Eih(rF*-!eYzv`CSy#z@_(#7u>4Om7P$&G1Dm8x z4Qd|z{)sqI1-*m9`Of=MyFxK0 z)aVmwo!{>}2mKwF%loh7^lsGR%HihPl*pmG%ShUvoL=)g_*#qQsofymjq5IvMw+VF zus57T^&DZiohK}wDzUjpQ8Sfo5rASN-ODacNni;gFKlctIMYZxB;Ms%6K2>^@pcPT zDD+LcRDMq3)98|P)uFCGIGtuWO?WSMrD(Oxn~Nw!fBJ;-f@ltwzv-%b+{tr}BAZ-O zSvo96G1>Ymg?+R)AAp-&z5x-kz6-$e$zcDW+P>LRt@cuqp|jYH2uS7J2u0^OHYv9^)-I_Jrawil8Dbzj_`%gM=Uy+)D! zY`VB(rs|_;JqNF`ULQdvp?%;^1`}*4Y{XxsIC#gZ90_9+5T>UY=^5%f?YrJSk@I(N ztn1x#FE%7_kPA!jl$}GnnRBgJof#WvpK)z)h*Nkxg0!+MGpfIPYdKfrffUqVK=AR3 z$Jfj|dKJgU0VVT8G0uNw@&=sQc$T0r|WTN zPUgZ)E})J)yvoDacVL~fG-Hk)q)P|~n&jA{yY|58(r6{vKdZ3Km$JMkU2c!F=I5or| z@;LpmnMr~Hx9uq(ksVg9$Fd4!N#t7bxQ<2~Lr)-VwiZjh9eD>qN zbBZB1sq#$dsOXR;|S!k{+Ufz>j~BZ(e%qWOuov1srdbh#D?_ z0qVlFJ4^jyg<4!y)N!h%%}X-gTcJAf2*Zqs^7rRChKG4l%oK@NGK?eL2i4x=TFKz_ zRbBY&6sV{akNbk#!`k03?`4J7Amir3LH4-5{aGC2nWFirTA1A(Y!a>co{|Xiy?e`` z_}ZTC@VG16*vN|+_MP~vg4ILJ)C&q{irTSTtN9jvGPIGrbx2KL&9a8;ipmY-piQJ9 z9e;9oN`9S`e{b32&!<$}O2^bFvMGVv_M}U@ekpcwl36<WYB|ZC07I2HLYlPxMwX2%99x_oX0V+{6N4aQ$nHqhrryD3)gf+Q4_lN}e4F-Y zdi-fd_u{dFk7Or5J_2A_!QqG9jR$DZLlP&RhLB2aw0=2|BtLh;Z|44asRG57FK{WC zzw&ciXwpA$WyA_YilkOEdo9VqkzF!?e&kOF(r!{Um+XUo!zhB6V z>Kkl^Z3K_sD^9VvP6%Uf%c%p76MnB)=sM;e920CtF*HUsD6owu6g}Ae8_ax>f{vls z#UCj;HbY;ZXs6S+b>iF%8a9e?huXM44p@htq1tw{{r{-C?m#NT_I*S&L?t^TM6#0X znKB}TB94)ey*Kevp^PZw7#%`JSy{*Kh-}&O*emncd!65N==*+s|2xNdpXa%+`?|0D zy5Gl36ugxdFzo%W_PdMGV4+gaq(dLUf#V9?kih%J?@$FDL8{) z_%7-;NoxgAgx)l$g?(DM%$GWnCCd%o9Q-4!&*w<^Vc0&-{*bBEAMX|V1{3?)HqjBZ z20#U;{{0se3FZ#BSP5YH+b@@YT5w5Or(r(Cj3`pDHZ!eX1TV+z}GQyO`zfX-i7%5`DiZf zBM~QdJ$GwSkNlx>qVj!0+&Zp-45d`M1+Am6DXSiCvD)Y|bB(@{N!KrlgmdBrA+b?M zzYA-Ld8}{oC!<1@+qvGJfKh%$4>%OtpRwW7-?^W`U`!C4jH5t7dY&;7vI{>JnY{&H z*;oM(vNK~6VSz9tkB`KO=~WD49Y%HG}M4;&iIHHyR;|{PGztCj z9Kx+I9WCU8_xgYK!ibG}G81A9g_|F;3|&a`;9DFuQ~^U_`lM*_$;TZ9?V}DE%*Fn2 zS_E75^rMyX#}IGnJ1>QCs=b4R&kM+R{f;$|&bVE2o|kLAlseJbJJ?RUh`Wjm1>Z-P z2jvvtjYn!5w8uXD)weaGLI54tv*Hx!G=GODb74L_tzqI+-w=`w?!oy?SB$ z)lbJ_>Vtb7Jda0)X}z9!=e$B+x@C@k`Ca`h7Js%K#RiB*J9C;-*!B(BCe8Gtr%%sN zQ*mxD4^r|r;-`V0ekj-Uzp{Qo-`%B6>r^}C>tZ6iyR@?oiF5izi6k&zR-Z*f+vDT% z$9AW`4f&a#ck~g()>@*$zCup@VeVl)?qM|kWe7*(e%T~2nH(VEU1f``WsRQP1sASL zjY3|=z^}K4IxOWwpa03{&x8D-Y@c=OAn3~PmN%?1_0fhtyX)`D%O^t`k2Z55DK`lE z)c+-a`LZ=A@-^6%cMWmDxTU`d(+bw``sISAvY4ymZs4U4lHQ*6pKiofjU%Yx~b|KXHoD@P| z42-_*3*SU}t;~TjQrwY1$DDys@!Y*;y^?3;d9}@K$Y~}Y5zjv9I^chHm=5x`Jv|k_ zAGYKZQ9C)+B$vZPFx-{g5|eho)r?z0Z;<0$zqenx>_PN!-2gZU<0|48%V_SE=jE93 z_ov=e?0sY~;QWIWVf}noye=l4rqVzydT00!0(otgA3w-0>%j_)!0&Ee)#2J-DXwhp zcVu3Stn z8^*s)OCpS%l*&bKz6woQPrR|%X@};tZ6>l>8flQeqJQ(EX%X^)R*wVy&!bQy{9Edz zDXtv94Vd^8og3~4wx5bGT@B~q2R~R--f7R9?*1x`f{N=Q+X2x#h@ojHS93}v6NV|uS0Vm-o+gA`CtL?0-Ak(o(VAj#_pT`nR)2?ndBA2m$#m= zo@qOiV1-~@WtD-h{tuA-M0J*CaQOeA`-v)2Mr)uF7JHLA?)p7T2`yInHD$-~BCKEf zJ<%ntyWYsboxQ-zKWFllNlNz`2G^2~DSYdZlgc{mm*G-W^RR4k zH9jBxK&+Yf_@RJt3`>!@3hhI~kc;F}J#Hcqj9`>mf@_sm*7ZGi-EgD0%+J3CmL?hjGa0I{}6p($fAo z4{S0kyVdJNO=EN7pr;DlsG&2SW=HIui8o#WOX=x^8_)Iaq_f}MT9}lA%B`#LGhL98 zfrNWgNApY8UN_#`zGG6xi?7dYdmLs{TVF*!=$8b+)sKAK^i*&rx>)F{H;?J*V)b2L)5`_ABlq{>p)kn__7{bsUc zFlJX)BTihw42~X0{msjNP$qeJelb98O;3}3AwaocYZbkd4vrnP2aObx!(ic(`R>dl zXH8cxp1j#VS(zavB@$pumGy{hqM6%|3L1F~W0I)19W4!edAM zK^@II2_a#uQ}ep1P2&ZW&t4m`)@9ha{iW^Q&jSJ)4!h!4r#l6=NpfC+HdbQ%TVP-2 z<>kdFDFlqDxMeU8)skPi1n`ZtE|zGV_SjB;@3rLrpxbU6=*mM`2eeMWH|2xdF*o>X zVYq~A8^OK#l~)T5&FGi4becx7+~KNDSL`Y1zxQINHt=2a-OQUpmkQ*z88bL=v9{r4{N(~=nKux)SMXZ89o z&2-S@FK-qz?Ma8?cmj%Ti#8EenDv}RN9rd>x!D)ERMO_((ErfEN+P}dpR#&9uy3~Yq*CX2ZOT_&Q(_UW z(025O%`y<~`s)xnTn;OugxT`mlCe#-_6clVnrS;&B{_oLIPesB@omfy-_|gs^PIY4P#zcT$Q2v#Z_B#hBSQ!ZQw+88iFxL4GrJU?N=t8Fm>;j zcBRem^ZT>=D~jrs1YNGuZCg(V_3oEqGC?H1wie>GDg5Y~=f&R=H$V@mth9A)E#K8< zH;!f5k$PEu>9jy-U#y}TQfo$13%)SKC6h%v!-xuHsED;%;KTC7l=~#-;7UKNJa=Ev zfc+2(LdZUCH z2#1Bw-wZd!VoaHJ^PeCz5RE%i3JZf=DXe_)Wck0B>JDo1COKkJ-ePjXK& z4r^(G3ng{2^!L%w#0nky4v+}ttZVg?2kdt6qI3v(_wO$$tjf2Ij3?8DjDp#UrZuiA zXg~GY{8D+nc+Wj7$yo33#ykV<^Jbayj-qu7y76nSu0A8BlWt_)W1pqIXD+^lE5*ac z{$NyB&0Chgn-t#+mut19gqb|r`SUY#+6GI)oUkWEY6m{3rEN#W+PQk`(-in=UE%MPGUD_5H_z(6LtCIQKM z?<-Vvytqc;fuY*8{?Z(?9J|>+RVMwOmRD2^m`bE!&aBO9y$S4Y50^rbD6YcVd2GJ8 z6RnA7A?J<8@{=dFjj@O)Vz6*SDxU8(=j=#(B15cBA+Z-9lv!w=UzDI%uw*$1A^4*n zAnv@DP}@3cANZoV`M2H6iT4oEaH(7o{Rl;AW`n*&$6iCL*Jp7xD@R8S4&e|>H#avI zS!DcxkyyjW*|yEEwwINPbOpUnRqP7uOCYv_kA^UUi>*r0zwUU_UgybQ=w)k&>AS)8 z`=QH#Tl?V+%xr{KLS>DdobQ1~_$b3jE}l(mkf3h$~O3@n^;jf-_f+0U7SnP5+VbQ!F}*VcgXFYYi{`xQ>c zhF39Z?r*CO{pzKrMP6Tp<;$S9@+tltQhj&9QhtN&*%D87zM7~Q^&PG+}1)faqMc*ib@jU%=YQU<3OpyFaxjF;H9 zdT5`aV9!X?Hsf?77hR*8p{!D4~7toR@t zx>1`FbwHNstWNgnu7QY^g|tMrGmII{sryXfUN-5yYGi81LmP*yCjA~l40MCc@2C_W zM2qvDC#CdP&2aLPuRI62wJzP@{x(QMnTitX>fGq&%oAovFb{gJV-6eOG|&&JqA^Dopq5L2r3=M?KqZZ ziC>mpKVQ6fQCOr3AQkgPkC*z~=~$ylN^uo`>Kb@4W>2|Wwyck@Q7kW*181SmcJM?b8oCcc z@U~zNEYVnRWA77G1olbrT}J(|mGGu%XZB(FWBlN+os{2Y&`Nb>6ijA%N^2-K(Cssj zLI~Sc84ovl&oEcA*xo{aPw=|a8D~_1CEcrwwXK?U_c0s6A+HzvOQUL?1|a{{J2`LC zQaF+#=t~Z#aTv@`MZH4Fe5;pZKY#kQ=(#IU#*t0Mw~p%fsEFVBfxi7I(oKnRmh5Kb z!6lo}7o+)ga#2r=*l9;F1xD9HnUb{nUCis(LJ3{3sad9ZGRf`Vj?Xb#Pu>W8PyOVU z&vu2FZkX7B#dE9oX-7HOs`(sB{ z_ZHO7G~d5^m4P9x7T=)F4e&gZ;_9cg>Dm$&v3sRCtR zNJYCPz4a0dJ}`tsdDQLzq$@LZxIN^%?nXa~2ic0Hk+wUOma`p?wVfYWvEp?S@$DMYkmMSVH1=cVy$l!AlrKTHsOhUciPn)9J+K9Zd9`K2|W43d5?0A8wa62&Ke=^$~R#)_VeGxzt=L+OA9+d zs=CGqPJWNM` z9rRbqm#uxhyIWd9B!ao$eXm!u-byWh6M$rER>I!qA$k<$^A{A*rChr{>|wh6{|w~sI)BuOAc7xZE4(K_*NPK z-usnrS8ny#{O7FnrMVX(M~zMsZ-TG^2c?oNMUEDBj@AxyjcxBk$zt$AaO}mCaaW$YcRt;Tp%FRuCU*D|KjFVBF`bwjKWmo{j^+0d!@{m~{$w6o1tHw_*vW0-3 zSuKD5%j3>+e-Vd=RiYG1tTYNM@u|X1!*@GlOUq}hbSij^7cDjBwq&&(O@hqmZVeoj zUPtYwfzbv)Xdnobru74;D9J)Tj~wNm;npqUQVarG5rZ3JA}%Q}{iksqqHoDnn&3L+MbhRb~nfz>QA~4XEKkO#H{u z(`)p1_X*y{1BT~rN>52S)v@88IV(|p@7o|X^>I+frMWwEp=&6?*B5M)ES>X8eRFis zytn5$>2gV6vm7e545Mn0dCD}fs1yZmH$-mLGldpYyXF#psBa1r8>iN}Ysg zLz!b?Dot%>3xQzIYz_}>V2eeoT5XNs@kN>=|4mvt5`s@U>1^exn7tReh#+NCo0+-% zK<>21ogR;4LfD!;cuWXYG$qRLM_QE^DmirP<>kuv+Syy@Ly||BHaugbjACYHrQ6O8 zmknSOOF<(7^+Ex^YyPfIv;?S+J8~EF>9s#!OKe=J71|PPs!7q( z-l-Yg;0Yg)m$VxUwq&9#x}5J@V#55hY>j#*gX?Xakn8p8dpB7Ozy22?{{DPGvPJd#Y+z4A{l+^?<F1YH2VSKWCao9>%WIs;*U#kdUl(`^(-vVk)NSF!^BevnAg`ldovU zd5yno)%BMVMB%~Y;;27%Dk(na`i zL8Oym%E9A_SIJ><@dx2r!TT~An;tYH*=NYVlKoo^{QBZf14w5?O02WGf^y1xbzPNZ zVpeCzFoq8k9Zvwch{2UD+6>w>ZW)Rbyv^=;0$^bfPc86;-_%?gpeeB7=b93paid0! zn)mg!pgVbj3JG-K&P#rXG*;VX>svN*x+VwF&N3R5!ACGuM43=S3LKOcy6Ei=m2iBT zw+>QJTNlr&9=O}x+Fu!(KJ}GACb{v&0jP6F{tQPJQlpuyq+xl2cc#cK26L=(ndhH_ zSgwB6ic=6^C$wLt%DN9dF zD=M-iectKHy4kLI78Pyp+2!KH< zFr{vUY;d;`si!=4;MX*Ewi&sD+U38vdjh-B6VSC&p!5xnGhgb^*oMWnGyZnhjwvZr z2m|Y>57v`bxM;g`@Y^6u`dP&Q?c9UODCA?2lVa=Uu!My#em!rmIiyJg8azg4r$dvo zN__dZ_{zkvaEWeqYfH=Ql>4X9H@uFx?(v@f^sAyOGB0hccT)PuxGqk044;9>ziK>~ z8F~T=zS-!R+LsV0dndLhs{}_ZDznbOG}MH~{63`_7#5uSEM7*Fd5yB({~oA4+k7@M~9Y0-^iO2+;cKs zO69ic&K!31n(HZgM5;P9K*lbP!yO$TRA(jK&f@9!6S3{GCF020hYNA7yJKTxX!0gQ z2#^mU@7EJGJ`G+QyhAyiays(8BLTyYgPh`gAI=V*R7VV?|5Qhf%E#4F7}X2WWr?Jr zlvL<&vkz?4(M8g?`g(fZs+(L7Hy{@blv1y_I-3)MK4|%f-TKx0saR6@I(*;90Cny& z>-qCXt4(BF^Y&(`YwIJDXs19I&u;?D#Q3Oht^?N!8Zu!Ylaur@dU%_|PY{J5&hpE!_DLK>pCrJbXha7>XT$a9r z6m!uIlzWG`__et(rEZTIaBxbZUc+F%s#!oB;o$r5j+9N_jc=~hjc<+k@^B?r04UC3 z&mRz@58G}>@E`T3e=1gf!R0-}?^Le@_P1HMy!lO442w#&0u(o#T zMaB4Yb|UnIHvplhM0y1T-T{xqyNWAe)6=Gh<6&Te?M0y`Ay%DS)|H8+P~i=0pit3g z-R!u){&v${w3H#z!n#RH%Un}HUn2jjT5r9*sZj#|O~~shMup_C^lo=Eddn|?s?SyP zkGgkrPk?ovf>f(J+)*R3ZXKwVcFML~+tZ=0r!K<9#gAr-B7%ZeZj~`kU2@5PYz7uQ+&K!f zYiXPF))$+FWKWaZ&+7*Y8SbN4DHe%+KMMyw8}~ z<67eKY|FDo-)>PVv+L;{1Ue3iKKx;i1FB!?Cfn*zu=&dZbLJBEBy1D;QB}U^ZvOu+X8n z&Ua9~U{`}BD&_>r+VFBSv)9#L#{1D`&YH<8zuv`8eblxQzhjWhn%m0jY81G8n|zyGneNWrl~bU;gC*v-}+dx`q(sk5x{-dwllz<|>Rn=Y_AUX4CfEW-SG9>S4g3g&@VFn?qto-Qhhh(2P{Y^?MzMba1s50t3 zWfMq8x1X7+h_eU)!(0iKqHpUO|9daE0c!%VfA!F)?R3|hSC?crVfxkZ4F z(9o_b6k&Uc`p9VYD_-4jKlOzE1pb*VOrBz~2?I)9smu#dACeo3yqB3RENzU!3gi%e z>zN0-vp9TRxG96SN#pQ|+0k1Md;4by(U-h=Z?Qp+GrjJfsN#ODNsE!CmqQdNePMkR zm0@`WE2i5%r(7aMaske`aI~qzXsf1I{3Wcy1gj1OyT}UMHgn7SUEioLtDMl_m9Cpu z;C=o}hdv~v9mu8C@Ch4qc@38~(_^U2G`dKU@Mw3EoRDjBL};iRfOb->44ujU?6^JH zalIq&8SHCk!y|8JXZ(wi$wnK{>LlKme@QNyzn?7)?1^JM?Gy$vT)kT2bP>}y&UnZA z=KM|{$ZlKa&&V@r_h1TLuOVlxNde;b*7BgyAT2LxJUQent3OE>trn@8+0|>P`%*&y zZpWjuma*4z6etdlr4t;iBcW423|+zSBAS<0AAQ(ZetdAcI>uyBm4+f*BDK>F)Py-& zED|BMr#(o?7f8$B0PL8v_jnTDAGf~M_0R!&#(dhOrM$eHtH#vy7j`n-tv& z*M`|%psGm)cAape%Qx(Ix6O@&7!XkI=!%JjP31Uk!N^0pq7Nb$MQGtu@%pq@Z6-p{ z&>dWHq2?Q?KPO`)c4momm|~8;FHAK9h{_>C(b=_qORf>PczL5yzI%*06ggho*iV&i z*&m#5Ne;vPO#Q+jAyx^;bY@CyMypVt*fZYVJd$ zkq7{4*d4hbl6>X?PR3*nai(1nV|1qNg{+X==whhIulSTFDn$tZm?gPbIDgJ<2bQ% zWKzT$vrGCAsaF?()o_BHOzk~LTl2Yksz&%jKTV2d8wr)4U*C;K zr25kzG8b;Lo3#YAokP*7Ns!qKP@6oM$_prej8_%+slC_>BvbVakP`QgTqs!LKE}oe z(qQIGvMHyhbxIyk$if$L@7S|cN+@w0Fh&~{6Z?}f z65BNaw>~toU^_=J|NLU5w@N8j_NJ&prC16zSMM}Zo9TsG$94j5lE}TY4M8IpYP7X+ z;@2di{}tgTPDD73^QnSZ1eH2C$&RljhEk0G#2}~>jl!mBmy#Yt=qxZ83JjClbwX29 zQ%g%r>iUy=Sz4KU-^KXe$TD&{QK*pP=8WfuI4U9B56S8qLmr+aYBlvoagI#S8y7zI zOz=##EUTAebUBnWv(XKw77E2|4pUbjO#3%PoLg4Ryq>#>{~; z!RxBnuc^W8#p9}V55H3TJ4 zkBfAB&bmONGuMjU>#~G#^hgJWTK#Wz;irUqs^f2}eWRE+A#j#GKT(kkB#<3&MO*1K8F9m2u)V6u z{b=X)7GXGT!dn@L_(t2_^P>|i>7V!M*eX6j_-y(v8t3gQx_V5GLJomEf7@;W? zjp+9yS^Y1-ovZuzepuWbST5l?6 zAY-i=`l0OI_ob^z`wM;ieB185-W;4;RS&2W4x+NgTkpomkGoRYzI{E-s8!I$>x%R> z>!2YYpH?!rs)?}7tdV^6hmpv6aQOOJd!|nJTdm^kv#Ov&TvkW;Av@i@A;OchV}zs! zZa2ar=YK)CRcp3TtlXz8ALY*-qbk#er<^v4HjP4h;slDk%d($)Go$e9d}i$il?(f^ z^75yW3W>p3oz{A{@EH{i$2CRt5%~n zlPv>fE)!%-J>3f)=$%Mb2B;vAkJ7WziQYD?+pg5|(L>G@n8!2OJ*v^!QGL8awrh~i z2OVGLNC1 zu#8D(TQ8ZNYioL9pi|L(wvXZM24hAx`c2}Uijh;nR}!-A#rwlNwR>HSZ`>|hSoIQwb{po~36EwM7Wq818I*F?NRyG!i2LC$2~J z^@if5|Lt?hX%IiO9CBj)U`t&54i1WkxFd>6$qK`#UP0kZ`2JIYlN=~%0@{uQlUqyP zvjiJ?2B>vKeNBrm@88M`D)&sT+&*i?Oc-I){-NVU&u zuYdsuUs=OnXl@H7IMQ7Xf1!UhKsXd^T>8J9$_DJ)ONx*#rr)kZ5%)%4FPJaicL=j7 ztxsPx(#Zp~m=2UV^epr)&MlH_E?qTWmpTgT2$9v|_G#G{0>`21p}qy)>_NthK8j=Q z2|_)BjBi6cE#!9|)BxPYZ<)F0%YsBJdhFM~{e{LfliOBX&m zNY`TGI_q7@@nMyPkE*P)SZC3foFF z?&|Uzs$+DuZ(R8z2Swk9TvcPXTT6syTFRYlAO4;-8PN5>R%8F<2`_GxAPAp!&i)wY z#i~=gZ%@yeTp)^0U(FLs%9;C=qV;NUWSEj(BzMGkCPkWK0M7zGCVmJL;4E?D^9{GX zP(uiQ>~n#CYq4x>9$RHE<` zBfe%@c=&X=Di(EgRAn{rIy*Tkb@L6=Ws$;k6_-#FmK1}yOFo?$n-)Y=oD%R3=hmf^ zoSt!vJiQY2bkZirNN@k+&f-Q`Tuj^^ct=o4aK;?A_kYxSsc%Q!<18(^SF)4o`=^Av7uyjPWzf6}+Pa+ahJv@r_}FT1CA zlmX6xE-9g*3~onILZ<}J<8iM3T=5_fs1Q$}Q|t_t|G%ugnJJroQ4V%i);ApnO<>sB zCPWN$ijff1euz@&)XfWnVVh*1EEbl@!K>7MAXcDL{E%lQ%0ct5i0#@RX`N~c&pw2G z30S<*v{kxkS@9!dljglDqt$#XgZDFS{PEl5&9x*i#%*ma;R`g_YuLI0d-uDHAojw|mVXZW@&L|fa(Ahj-fp?I_k=07Dpdl{Xn&@A~kHCM*n&!y_(|>trqP_@g6qAlD;$dkvhn>nN+#Gg|^=Y+8oWjO;*$f z!gjXJ&CQrxzlu_W`9P>+=OXeE$9kWZg0bgY?swxkiGOoMwCL>AsP_M!Tg|bZnT;bW z0H&K_R|ASchP+AqFA1;&g#PBT+#Exi#ZCJ~_ST_Et&!EQv>d1!$$a)g1^w<1xoM^3 zjKyK1G?u_KVP%DcP+}Es_u&xqtUIYJt-5|L?wmB6y?L8{-v1xm?P|c(+)>roTcV;C zbl{SA2iDAKthgPMJN%hu<6b$nZ#?bQ4RXVP=E@(lY5Z4_5?Yp)N=$=z;j7_oRppID zYMi(O5v*Mt&@Z=9$t@vt+86yaOKI5LEl6T9%&cabEZUB)=9;ORtmR}L1;t+f2;R6R zPqZW_y2V*vd4u3{Iw-qAxQ_hk>qZunYc&so6x7txw$D0b)ogILyKYl@>s+!BBUj3i zlA3MoUmMX^O%d_8VoCgWx7p4oex}C*4e}G7y9r#CQt9JO@Y2YGysal6wDtw<2Cb>4 z=76$_b`A5j)%#jRM8veC4)j*Uv@F8ZYPu-6&UT4*uG*V|zEOFFN@KRru&^j+b(rtU zIkD{4N{$SB>f95onYn3seZ#ialPRDIBcRSFEcQgo7AUGKLg?dUbykMT`8Fw99faN> zBj{^Fps{%@uy=l%!0YSLaX32KO**sC`fR=1Pxh~edWCn0OBI!uXHxhSmy~2k&JT&6 zv9U3?^R#YOnQ}2(klY%pLI+!PUlU#4`HVs_zx|j&*wIcL%Nu?O|6;xlD8TELj8YeZ$r_5vr-V#Fpcm9|L)h zbl0~wtQ~G#fO(ot4jPJN}wWIKuEY-KKX=q1ilvP6ieq@q5b;DkE}+ zHPaA?c)fESjrm1u7&&8MyKC_Y1WT(qWGm5{@CCY2Z#M$EzHITLJZOlx}tNAiOF`a@$Wf zT8D$k@Hh=@SDSl(s3?49_to0fQ5xzK(%q|hv6#-O6>%zN_A#ph0ho1>{LwoOjY8_}t?%%iFyEhpOYG2#7x_Hf? z6Y?A93O6w5O%oF~`l6dXkMl{_Ul@vL^hfmy21J#dZx<=rj2gH@eEm2+h+8w&LIL-K zzK`>K65M4YR77+CYZ;4GJZ_4pS^vJinxCAKl2Th+3)~jX;w-o(T!c?Uoun=XY=psQ z)qOdGBGvut_7y#nj2tFMpo^Mc_r|ULk>|XzkHyPHTcnrF@6P(}-z_b`uF9R@btV7A z1@>+`WXXCO!eQvH_`I!YxI%oMhp+dLB8 z8%#6m6f~+?et$AX?eCHM^U|;!Zpr~Qgg(k2&u^&IUvn-L5!XD(U+VIUY z&w$G4>J(8v%aL%V`=%0g5y@XkxYC5g4$r=J@a(IN32OJryCQX0_;anm3;MP=+ryBB z8?Ld-qv%nZ*+;yH-@7Z-k||Fc!qW8rd{*HJ#s#fKw|^8h4>KH+bDWzZhHUuY!MT#( z;#&nK0m%!S%-;(Mxbnb)OANnqe7o-I)1jnQ;gSt8-&Bsnn2nX5!W|8UaPRtIg`L`-4Fv%j^H<> zMFqY98dVR=2MwjpuBEsIxlh9Rc*L-7emm2{%$G;y7`{{Z%l?$iPb1$+jXGBMwsOv&VA@KOB;Q`&_47>b7GM+5 z)P8b~W(#RnUWrhPhaJe)epNpv1JA6jEGD82- zB{D{Hi-0-d51Q92UJI`2#Rpm_i!ng|saXBm^F+U4(ybxe;4<1=k8fPrpa7-KkdH0$dCWf0N#^k*WSDS zJR(yM2Fs2)IH(@Xzyz%i_YrJ7N?mg@Z(!Q3OL7#|uTIE2$?w+oxiomCeQE7m+TrsW z$-Bj?(A0=8J(3^3GzPR6k1Xzj)>%YsY-~oxd3t!e{ENFRT9FmJz=7NSExhQ9Ag&`nEruYAU@S##ly;TN=y-=5QB_D zoeQ(G=D-5)?X7=Q*yC$-t&>%wY_OkYZomNYq z>mEqQru%a?>MD&}(cev&yVBARYvPLGgoHT#wQgfPIW7r=1|hHgHz(8()*ja>Cu+|Y zq4=CRn2PEkX(_v}^CK^O84pR5`120_QY7Ux%yu5H#{fA-RRy$WX2PV+rD3#>xsRxy z&Ry`aD+cz)0nf&hdi%Cr3uzDhCxzqn$B-&DiI1|fjFm%oW12- zlwU@xBn*EV=E0##*p|}e;(a)<{$&|t>N&{uqA9;a!#r=VWHL#3v$;s@1&gGJbf%ZL$qZ@=Uo-)vxwZ+xAh{58N z_x}~YJAn9Y@5{Um;rs5e`^Vyi8hlZL;1L2Ly*#{5?l7XHqB_sANdqzm^H7bYLF0QC z9XptPcF&q?_dqgU=<#L`cS%V(irLn(w0?+4Hv}9QhELw#Q{4Abl0l39(%%A~y}NtZ zEzIp(AV`UIzk%>P2LD>_1|=lSvp}1F=b21GK*dXzR2*z>2|Cf@LEt~(rLoN6V`_b>t!_FcY%H2DVPhwvm;^328KW6l(3`v>FKt{2hhP_F&I&(o#g`utLi3z z+L>R}tz?Bvu&O-#OoN^%m}wX?f~iccOOp^E+;xB~-Aky8aTosPh=&k3A)($)9_7Jl z#9DQt!k1xjz%)!YMMe>K_VW`?hJO}aadk&+YXFS|HgyWDw zUsV+}qdI&U{{T18H6C z=#jT23NG7AkeSLbBmQ@@?uQ>MGK@Ank-cE?O-9zAj|?he;*QxBbJN@$R6Mm=*HD?c z>)}0e^jB!IZua(oCb43exPt>(aRQk?fVIi{zj*K61ls1G8NSm0@8UB7H=mP*80;-D zeU&dWdchSni5Lk={50lf`ePu{!g9e|E9<-KiBUmP#t?u^SZFmO?F1YfzS)m;SbD(s z31l?W)1|?yuag|yl!-B2T~M*$aq;S#hPR0BhoegFFu;iX6kugzYisCCPfvyv(c6x} zbFqI{+5<#TDfp99z?fmfXmiP(=rija-T(g33+c^-GLc}_@~>~8Leor|IS181IPu)P zawNVt$3Tt+$a3U%*og&28w5Ks=sdv0;mSb$$Lw{6nz)^zcA~9A9SRwWii;^3_CtY| zJna72PrTB3f}pztyR9tbi*Hibm|Olw36u%G8HKye3(mNo(~QgVNL$Yn?`Zh*6G+_I zbpilj5dmxO#wYC>^Ao#~uj&_5=pVMiTw6m8ZWfBPrp9mKgQFe7q&1l5bBj4NYtl$w z2g=HN5p5N1OAnCZVmR=%4ki`~7Hw;Qor}f;N9)m5T}Y$s2JjG?cht!XlVFNHDaPc% zd6KEZXM{vYd8t-=olCx?A5}&Hpp3A0M20}W&YO{d(`7rqu`yEB+Cp82rjemLs|5%BeE!y&WSx4Qu$^oQc63;2zuoeyCPTVOSaW?ms#h0Vm_{(;x39 zQm=y~lWzoGOi_HjP;htG-}RKQ>f++T%cF|J%n*46h?g5`c%R*hMd6Q&5!hOQeiKJk zu>2QA6%0iWrig7}VjA2>Ez=k#^RSSEPl;h|GJ{}-5LSK8j70sc13n9Y2YUD+bOZo= zWoQzo1)q;Ju=BU0y1H<@`?T~{>j_o&?n$So`B0q`E2cSt9oPX&Il}Kv335IO+9LEN z{Y$mz?`h^g&^tC^&gQU@|06|wald~~uc(!ZK*p6wBlKj(W;R-54lVJ%qazXYx>q%e ziHVQOKbt?FFq6U+Xmr%q5rb_y$yTOv0DWX!OCY}$OW?wP%nBQJ@Z1}f@v>fwgZxmD zwB~3}%9@i?rk4qdB>NsQ1SLVknSr6x8lkGtFSjsi85VtmBR$={WmMJe{2xyBOt$4N z%L#v8PzCSxi=5Cqn8+#ZZ1SuSryeoikTYNCF62l~tg!lms_mb|D-)!kh_9o5-vaX; zpB|8#gW{P>I8SiK=I~)7N_{H=9KDUlc{`e}QZ~p0ORo_8&SdwWoPaF>6};lBvw{~) zd{8Gw#rE?fGUbmux7dJW2-9`gOSudze|Q;#1jbq9oKGv#6G&tPJ4EP3pJJf{yg+r6 zz~1V)^gl{}_=H1fC?Y2M6oYyV7F~%=$Od&gI63WjE1`MEUvg}TC&$P2HY{8WI411M z&4MFvFy@vMqSfAl4=wF3z=sV$M9dTMX43A8)F6lvr+A?g=+U(oy$*AJ1-`W8QuQRv zh)_bWiZb_ss3AEmsj6hu>#?A2%^UG*4-_QSNE%s6U`Y0%6jQR}D@q zI=)xJqKSCT(d%1x#}{P)vaOv?4mMF%biM@B!}F$+4}XJX#sUH`anRFI2F}`)_@VmQ ztHwh+sB}C*0p!3p-V@YGUI~9^cNBj#XX-MSy)_PjwVyk2KFAbSoyMm44=7>v{{9=0 zx-+nB{Cb}_=ffvDzJb9@60JIfst`!vY@olgkGJkhTHI&H~ccXGuRVH_)?A0`MCP0^4t0M48$YoS!rJP{$MiBC$u<4)hq45<hNE)Cg|Mu0j&S;YB?AKwuVjn z$rbwr>1!(@BJvbx3iL#{-$;YE$D~b{waSTuj0)JAU^dN6(A$#^onlUE#P1AHw${_; z#1i@T;$y=GpribB6F#$RlgY^X=f;{$62pZ5BER`v5$zm%$Q2kynbrS_8o&RKt1Azr zs{7j86q2CGAD|ZG?95|QbbC~ z_^ox$(cAC){`!6I)xGEJz1LdLde*bn4pFU0v!kU1Jo*2A&ZL zmcDlI(*bwr{>?d%1C@ei%g8EZu~YV>e9rm#NPriL?=z34suGd5;+*0a9;K49_P~3;VM=d&6eKtA|@zSe@7Y+t5IkI3LOlMsLofC?`iXSaX{BQ@@uX}Ym zKA9TfBb;A?`BE*$B~@pyG)fwfQp78fOR5)-=I%3W%jrz9NU;nA#GG^*&P&s}ZkZ5< z?MVpMACPi+T|!G5N$D{5d5bM&I~qFcYU5+$PP`5QdwS0Xrxc6m)}f=w3&M^0yQ=05 zR13$^MDpyq>W$adm9Bl?7BBvDtGRi3{8?Z$n?DNrZI?z$K%gn`M^Q-PB{-zKP&BT2 zDi-_TsP)D~TduuSl6=tsJhzu*rj@m_#h3R|UlPlwCTG8?rG!7*X{5>)OB+?JXHZ0|_UK7Zhzd~adOopj%E`POM9=^P${ z>)6gca9h3P9G}!$wpMt-3S4N|jT5AFB6|`{uuDRro1z3KVzyc_z<)lti&H470A!Z*hkO=K_ew43Dr}?!}4mzug&_7+y%dG zht`>{=IHhU+I-x~1*Oz3RZ@SzZ8%t1eFMkLoN=3AhPRB|(U5T$QWe;<#)*#p;c&9i zA~1*ydC(Q*f)ZxWsU2lTzMpR%LWdwp^=ZzUbpuyje;^IYxxG@?^g`zL+%&cSvMz05 zcas6tI>(F8rF@DFtmu#AjpBDU{hA8h)BQ#f+41_p+^hWZ)EA6D@wofF@hQ4{ggFc6 zWPcYbDO^Cibe=1|?G8A@5-s_GeG;50t7NSzrn-l!8XvPg=ZfhxDP=W2TwzOthMe0gi>GC+iaUK8dLg-c5U#@o=-a!!heq6-NZ-w?l(=x?xA)kT45en~nst9tR z@MEP$IfV*A!NDpjDlUl@PEHAX1y4SI;~cQ!ii|s2NocTS1ph=Tu6#FC0w+w>uM9i; zL#wbjL3G^rtmThQ66~#CrS+XDo^E;K{RyWU=g-?lzc*admQx0b;1V>Mtor~;Kpq1K zE6oM8)BB@IWI3*b8H;jUchfi*4riK6;uXL29w$(*g{qP!8TRN|gCnP6W~W01c0cXL z9arat#^zOcgM`KzRDJ*LTJS@8iF+(~xM#6q#R~8&K9mxZsNY@M zr5C@J)!L3UyL#ejrk`!_qilu#hw;D5ZPL^>2R%D{TD|RpLUQGqCu1(jzgS>v>F}gV zqXODH_dbYoS@CR$_L8YeCyg}UgcR{(*M`=uVdN~u4$HGHp zZ~6N#sNW7&!o=&ovEGR46+Wegq)Fpn&!#tWVLbFT+vcP!U3O?}k@!!?Uy}{}d_sf2 zUgMV@0XEi=G*{wh1Sm*@hhOJcr8>?0yAsY<$P5>9zc~G>m-_296RfV5B#m{IJMJax zynTm?>Vz{b{s-#Txo4&9NSje+nYLBEWPvfT^Q{rXNI%r70Bau_OmXb2S|>t0kX1w^ z?!P~4-cQNPgv_J=VoYx;*{uu>Dyb6_nS76=KgGAA03z$b+yjTyG8y=rp6QM+E5YAf zyFyA`!1XgzIruj$@K6SY7Z6Ey=5yLkOrCwIG>l&-vEiPFpU=!w(kErt9T*(&3jd*2 z|2X{E%$n2C0rDhDbctuVyI1A{U+DMHS($&*d~D@*6w|zH&N@~3tyI+IjHE*wl?)ZV z;JK5c9_;vX(lySu$9Y~{e8Q4$?K#8jz@ldr?Rea3GX36m6UymU`gvt|_4$5v=LEW@ zwawfpLO&fTwPlYFg~x{x)o^Ek+y?0^lZnRFcNB;RYEGMu#byQ94#dSV%%#VEm>xqp zjJEXmyd=Oq$Mo8e^k-SKY4EBMDqO0FIRgB_ozHNN{|&tz>*`@1ql03S+q6M&``O~J zqRw?1UHrXAbpl|R(1Gp`1O2_x>lG9fY;5&RAJ0xdC>7nl-M;Bq@bU(uKFc46ab)|KJ!VT^#k;HtUUchSO-JzBC>UD;sdnO-*8nQw5k~cV zK>T7BkN5@B;aVt9_>@H)l2-&g>o7l8mPjEC?|9l*Zsjne97>lD?}~8O7A@a{7^?g7 z-yDd?7VU|16^f}YmOyum?#*~Tc z@3}e>;6-A1d&+|7<$wZriIOas&_g<2Amvn^TmU?0M~TsIN5}8yQ!6xGx@tbWE^wH8 zpYSy3*PlZ5P5fa!MMI6hbaF%JC&q#DhDzb2gIoX75IDQ;S)+Lqu&>8H=*^Q&>VyH? zLzu3~2eef!W%+jiDpba5_e?Nd;i=*mT3LTm>p9e!n-!_)8X6(X!5u7@;+p8mISw4$Ue~3;e+ayS^V6!7%2Obkb7?SWc=xB zmU|xd^e^{JO66I=RV&ic1C+|{a#?OU+wgGA0<*-!$(f+OB3Vee{zWfqk!lwAqp9Xw zGEm6Gje8Am{LEvi-wJ@VW%KS8yohrA!U0W;sYb?L&ic&RevT9J?QR}QYTsTdl2Tgh za;BK$yuD_PxrJKsht7vVXWT~GWxnsYQcHcev)*4bd#(tfN@+Lyl7GuvAVC}aJjjlY zZ#H`0PJRTQSV@?Vdk^2zE5%qZv$r)Nwb^!6rGMQyNH?7g=jeKWu#p_PBkvHPC?+x@-N^F-hh#3oIZTGHFH){@Pt>kEWW9J7M@v)M-__&4=VdCA&3y z{Cs-H$rlM{n+`-6yGAWj3@REUSrJ&M;h%a!Q@Kj9V)$Nt!kt0yR4UELe*7*F+Blse zHLv3?n!$Vn1n9g0v9M1Rkgjw%=Se_MjwlI*@5eEi@-$Nm3@uOEDjZn zLzw;Hoc_m$Ny$QRUgIp~wO}q#ih8txwJ`4p+ME3{R@6Lt4w#~a{RIBVC77sJ$qeZd zX)ItevRjOLoBOQ$bx|~ARVis-zPSH(>}`{2^A#XXVQj4L>J}Trs|DELeCX?N5~=n- zp2ehoAXj}@2n+%8QVBU9TRCHI*$v|bt}wVNuT4f)HhD$(eBo8MhXYSnCHy#%nCqDZ$C~Cd;aGUedB`R-) zWMY4pPZEoabD1@37L2%Be9e)9Fx-F5D5Fe!;rXVI+9$W%ZBT!ZI)Q)t75AP(*ALjU z-kHDAzn#mvQv3DYyL(}NAP^;Sun+=I+i6)IDV4={{|?;$_wUkGAt;|BkyhS^BAL9R z!=K$vbAH(>$Q>WPpOCxe1+}Ad=A0=hzQX*xfq&te(|ktw=Q{dB8ML&h$r6|q1U=TZ z;Dv&>-r=80LB=QQ;$3+9$+F>5n3;g6aY1ZS;q#h{;;R)uKzOX3l-$2P^Hxv^MAx8g z1IZU)cb`|!9+%h$A@gTTrJL?n^d3e_*S=fsDGOXo%m#=E1fG*y?C4K6O6MMj;?o;-YC8axX0pjSi=1B^` z?=%RZ{+0(d!8Ybh#yS&2lSQ6mBt67yjPA$|m|tilC{&t`IAc#fOOZ8A{-1sSOd~Yw zR4ucjVFtZcPdsK8P!_-(-Rci~`NgGjMytZ{lsTSvpPM&HO3e6^_kA*S$eQ!3PI$L( zlgZ>XIk}#(KF~HO6Z^gV0A$RgukS6Nr=yW?WnEQd>nyt!$4+KyD@01h*gAcV9qGGM zvG?K!)0HGm8s3Mi@DWD*bOzWtnUACi+2!GCbCU+5K)?iiH*X;td*jZpmb1Q{GoGwy z4X>P=Y(#AYQsnm>PPChL${ngr7109`XH}-ZPHR}CTpR4ZzP!XbzPQ{}S)RRqziewuW_;Nv91oAUc zaWMIsxy=F!(3fPQ^a>J`+Mafd$~o!Kr#Sk^my(q47-r+2ybWC5)mB$t>k{{Jfe@X3 zh?|%Oi;z?V^}eUJtZ25Z<+FJS@MfQYR^NbJxiWt)omua`?&vDTq;MkCR45mk22VAH zKor?Fw4o{%-?*P^=sp$hF*ZB+I#XFbfNgXb|8MxIl1-D)Hx9iDZO{?-^#`E!`R!(( zP`QR>Mq@$EHt*rYibb=R8yOlILHFG=rT#zX^eyEKt(V9wQ2{qWEieUqdr;%!R~Y*A z1E$raC)u7$&l%_`c76al6{Cq_d!mOsoIgFs%zxq?gU#Wc-OGZmY5rVdVC}Z@ct=Ox zs!Go@4bsi$A3pr5q;cf|Om2*VbnO+t95-~ zPY_p%f~7i#9Lo5GkkQ&q3**awG>@e1V39_ZRGI_@)JgLXzS+`+a6-nD>Usa3>4X3z z+B{!E;!r-!`PHje>#vpgA88uze*O3F-J-YfH>`8nO$Y?gG+Ckjn{tYpvapp7B==Epe~gsVBzSf zs3Bf*q%1_*x~fASH2$(Q;aG={p2WwQfyPfiWaC&Gu zRR~}6&$KK(x6w0{JYX^q?q?y5#ZX`{rfBvl z7i)=sbKH@WL4LPhGv>7hoJ!tZD2pS+uM##+yj0(~g!m$z#yOeibch+1dB;-iQGpMU zqR`A22sQp-3QTfykY>_-59I+{6$o~WNS9QnI4abB+5|GK!rNdX6!w01K6;y9reGq< zeDz^W`5&5YXF;j24-SI)dIPG4 zR|jH1v$IVLYLcmo?rRUaYy-})(feQSM&U%;@^8; z^hmP$S&Hy)8@;eOfpNo!5c}=6hw9~Tl{m=A3~mZ*Eqn4-E3tEq5IA8Ypic4wnE1^}PUk1nvei zx{PIz%p&*6JN?%1k$lvp{4IEGg_v6LB4A76rpClcoZncHpt5^YEPErv3DHD5Qd->5 zQjeu4`;=Hu`Lz!{6b$U%rZHhpKrxLObZ9Z|nthg?`0M z%|XhVb)nto!@nVloL`laHdi5FH`^?eT8pZjTa^AZph2bd|BafXcB1%`rWn5hJ6)Vw z)tem}2)aS66O!F1r8EeDHP6k~=@K6H`U_)wUUha(`zDio1z7O_j(4s{ESNVami&PC z?aXdr%dNb$p%r?E3HK)|h2ew@&cFLPr|X0e?;|3CA*XnL#7+ML^#i%4n+2m*cK5RM zv=izXlvdw##VMklS^tS$id5>lu**ZIW=x$MF%ZP{al&2h%(4UH2chT2%axvAyJric6B_ttvjf(-@dfLY9Kg+1eCl+~TLaDokTUpWB~PfinzI8y2&eX6zob<3X_GoI zW;C?sT;ZpT&$lh4jQMy`XxyXrc?>3}D%$%SEApb?`Kem3uJ^tBLWe|KzB>4D*UZMp z2@eQ9>0j)<^bXSvm|gkbv_al`)|uy^iKqhuwiw;F!K6;T+mNJiKjH_PXeFR zeE+d3`*&E52oc4gs#FfO!YcXH0?K}FfGItUdIsavxGiXEMbfqED#a5FVwkx%T{kiP z`v8Im;HZ_nSq~&?nYtjr>Lq-`x`xmk4My(-1OEOio*6_z!c?=sojqe`bAz`}K>~R( z{?Vxvs0>imikFN1c=<(&RDEt(VqW*gG$@5kFqa8r5;o zTv(}8SE=j#RXA}MAJ2Ik^^0&D|K|y&RV-e%!+R#wi={=lM+=QkcB!W**Exgz8c4uW zQ=G3*iGa`_LA&$>ok5q1UYV*!Uwxu963>$JO@FN|9P$wT&H=7lw2DNoXxN06vM zc1QN|Q{zFE1%w>7D!QO%dtir{g z2WmiXy-r#+#_bbqoipV(V-SJpF%5((EFxgMitAfOE5_Rjg~1PAc6MydTaa}xO6zu> z^P)#|bAtXI2+BQx$7_g)GsvWv0|xhULaUK4hj6YU$LrQP<)|?*6W zK-*-7C*`jM-_tj6r7K)pxvrYQ{6-Y049&|3UV%MNGpSzkCf-`Y?oq);dn+ZQYIWud0<^U5c6P#Sx}9Ngwzp1fl_48mGTtO$E7mVAYy=_f z2c=CMdkS@H=9`B0c{=R#U;L#CbMjzN!h@>msgQJ99gOY=^ak6$y99!yckw$r3Oows1#?=U z!}7340hpfA@MfUgLmnem@y(q`FO?r-AA4WY4db#SVJ1(|S0Li@c)~xiTk3CUh zxgt)3rS%aUxFzoZdRk^;K$g{amtvxEuTX^8mxDZ~ z&1A2C*mz2bi(e>)$VG}E#C9tv^&?y@vFq`9W zkB*!+%Z`s@g*!S%%rq5F9HZIfD#94e8%7I}KHMutRN1yj1ECUg zq217yH}=xr`8YjoEusJMUvWUx8%XzZzpv8`=5JC-e9p(Q#jkc&WAcdJ&giu9!%Hbt zd}g1bQkZOkyB)pN*UgL`V7%vl?#z5TBr^`z)#Xkf92`pw6j{&bX9(EZwS|rA*&?P* znvi45dJt~U|MdYZjg&~`1w>3j3lcq zG8WWFi)Zn1F8v#nqqcDtBCgCACRs8fZ{)U9i!V!%C}~v+oQ4p<1^7n}`gLR4`M8Sc z|8AHa|4O*q@j2v1`bq+70T!%dxvru0wInb@5<9dP;oQTy(Aw7xMPUA2^B55a_uK!h zz(a;Ws0n%q4y;63oZALf3uxB!?#h~_O@SLbtOMi&#|1a3g>J*BN`<+j%jfeor9fsr z4dfBuM?Oj>0lRV8TyZ;eAggmVGwcYHx z`Jg~<3JI`>?-`Hyp94HExRfYa^y=E)V{%}FHuUi{8mBE} zipzMY1$v^p`!C<=CY%rKD}P<)r&y}PByny2dsb!J(;Xm$llAXuuq;HS)Z5HJI|T|@ z54xMI_ecdJ;U%$HL9?U+~mYBTas}*W!Sjkg((9(wZx|jpDMMwacI7~4;rBSBBK>Ul${46*#TctM@pPdA9}`U@Ju~rsI45BvDo5$#$N`u%?5lUHMJTsci$7}hw?r?r?Lud>PSb{892Q)%3 z`v0@nEyE%mdzvICme`ONu+2L(rZ5d!jmUS=h=sb41%tQKLSJ7vT}~FX0ev)ZNSi3P z*|Sd7By5^6*~Z#U;Ysf0Y{S<^gtE7RqvTTb1hVedtl{L!zrvfz{&c}tI4BlefGt}Q zOD(#1_*U9RP_!c+DNJOnOGg9Ox}@LRJ2bFuWBrCK=A0E`O^Wk@pO0c@2L~Y|ki81Z zo2V@gkaMNzDfqnSTS3Hfj349+IhnVi&=cqGlC$5? zzM;1*xMhfvnfK1c0`CLF3cig6YhH46NB+c4=qUjmCBV;07|Kvv{uKNE=EL4IIW?P7 z!(|FD?7wCFe-=W~OPU3;!sK7UlE9!-svA_&qTs74D)s18THQ_u)H+qOab?$hW#DuH|=NF`^E5fC; zI#pKyJH=(C6p8AN85y(;yD&5S+e9~4K5`uQcnJ9C4vHu)17b6oQViGxBa9ErW;*z& z{%NIoM#7=BjJdcM(hMVBjs+3K`pb@z=1CDewUB9FH-dHy3Bw zMeb)-N2%2Ye6jc>hA-xx6l%RbZ~Ns>8n+2yU@go42p=&9hYl{(Snur-Zs+lw@zr|r zWG6nd&28wWfpqPL=wB+SaKazg)6nRXEgRkK3fqW#N%w)AnSvx|^5}q--VQ4ml{9)v zo=B^-_TQ5bpy%!I6uj{t_@~pcf%7lm|G_9%Dqck3Jm>c)^5#tk&h^=sy58lN(^K0! zI#w(LAB(4qQ~7DrchrJh&SSc6w?Xelabaceyvxvv&QL}4-`PO_giiGR0y+J{XqM)1 z`Hv~2NDRv*L?Z3z!vDSSDHPv9DZcF|$n>)%=t~P!2>JGJ0F4wi`bHe9-MhOB&4uLDERm#LPcG4gu}Q3ccL=PEcfo(yk8julisX8awX7 zSTqphb62!F`x6M>0RYrvx$f@*`OXH$wMN8)N$B=|X%#=jx6BPRect9@naM>JEAC0S*1QU-BK^5I0 zau=(82-raVloqk9aP;3#xMLVYCP%g~0atvsVbRRvef&|i47`%eQT;PKz)FDl{_Fh( z%0*0#HNkglOB<;D*TFqH6?wz(U~bRXmM*-@wVy5whnbK5FG?2QaLsF!=jzX589sJ4W$V0>a9jU2od~uDRO_Kur*j3#{|1i zFi`xn5$V>o8Nf_9{mg@I9QudA{|J}-s^6?`a1*B)t<7K?93$m$SL1-%qOeK%n8aVx zG8oylR0lPWX)DD3HfQieymPwfjFamJ9)iEireXJR!bPs{uRBY!yyc+_Op*QQnsI>c z4^Mynv15g@ql1RVbpfWMBKHg;d(A>R1S^@>*P3pq4yDA1BTgA2I+H8{u>91t%N8L% zZzHy!D;{7=59Af={(XZW5X*bKXL{aZK@2(-G zVcdcIvG-7uj|=A=$JzN^?I|p)A;mV%a@RqUzcJ|%(9f@i8Tdf89{y(8PH_^s48McE zV++)Ljsgri&aiU!FIEqr_~97*QSywiGltk(^u-+9ixlbxBlVDhnmp3P)ZROaO&t~Y z8y|nnPqt&Qg|3TYb*O~Buv%s?`wzk0mrVJ~OOad`cEQq0V7-kpmib`@x9~liZjyLp z`ypUcFjX3Wrw&wuU~2CJ`4u$PkrCU^ivnD%G)94xV)>d>((8WiJq>_(QEVY<;cF~Q z09wG)-i+td#-x6&HyE*o+Tz7<`%rb&p>JMMDDPmRHL+pIOQH^PUEp4+_ws?48`pXp z#Di}{hkVBDsoBG1dev~Z3CVVNkSDW1(!_lLPf&Ps};ySG&m0T;BDleerq3WIHHihh;DoZ z%$rPmBxdcyDd8`w`x!gsk31>G5uwn-z*L2nt3|^fG`3+({8GjWFmlB)gg5y?k^p@w z;+qVI8tyqkD9-y*MxjKq3e-sK4JL3&8a6q_?54ds41qS4L0%(x+5dl{aJ-yoc=#pP z#nvO&{wzA3UMv&*n2*uiMw$R^gyY6F{Z;dXN16b?ko(E8+DeRVg{YY{IhfmB4;szy zlyLrYB&t5_TaC;(To}w$t+^(74aX`)eXlT5qPEettdxkW@;_%m3`82&`A34vh0Eb@ zT)yza`d71luAJgA3|bxN)p2IVVK3K+7FkMs^pq=@{{o)5?btqli=}V^{snYgH*~JOcMniIX|)054u>K( zpp@j}1>_-ZFp=lQheG-1jQM`rm*?7nTcO~psGH%Jx4;kLdpU=D?he2@km=^*m)X8b z#r4Kv=U@|A{XChs4#$FR>%zRXY}sMKlBaML2=v~PCd68QZPs~BckK)ujVxS!6&5k( zkVDC15ZH_1bC`)#_nr_4_C5B4az8|KaU@az4cTKC5*xxxTlsjp0h-A`YDnH^ z(>z*i*b~omefMq+36%W8bmU@OxE7Bw0LHrVtJY7?BO~HiKw1%wFsuDo1!`aOovZ zxmf5O{qfgBhFdSyqt8|xTpnqDop=|iHzfZI89|n+;hkbYdDUD7S-@o&_&qoMm>fn+whJWczcDP1OU$C zh{5AYV&M~b3cRQ$Qs?7nT^LZ?+j6CGvRm3LoBF@34IfWP1srzzF{?jqI+O9>`b+q?kdFOW=n$>@3|a}a zaozf717j)w`+eim(H)E1d)u*pTryO3Z!l0*@Vm&Rm9F*9cmUH7oZL1$?_dj7yJlg% zlBrll>VS)-;38bobOz$yTh;99o058{De2nvpg?^ChBkO4H_Mvk{TVOcg%I9;;GjUP zAl#z_M}^L=n}&6DrEd8-_v7h#aE9nu_W+QePG>>^N2CU{5$9%ogY`nR$&C>fFNaH+?ag6`w!xG2!_b_#QuFgiZN7K5PftoKH))4Mz zutjubUdr-iG0l3IMCi|)r<43a5yMI_a$=~s9Xbr%0HCW-hx+sfuK)~A;U=ZaMVA+^m6cQ zItvr&hD@#)%KN;I?{~Vl7c_!H4&)rtTm>42ESu*zzDsN7y|if~NU1RRTxXy6=cYL3*^v!c;p z$WWd&hZ#wUia*kWouynuFloU7!y>C?A_3=CaAsc!1q5c#w)GJ&+3s1NKwdClcnaic z+w1qJm|lXzdwrggwQb%+b7p-wP2Ow!{`UFu#4!W+ zGT+DZ@S8i3p1+oSwXuH67UXuc$B}v&^mxAKK&#+=4JOjTtULwiKBs;0Y1O@Tv_g#7 zA7gDbb)G#faiN?DHr_#c4remqqicP;G^nddaVhQ8x z3n6iq5`)nM--ngo0VX49^p9dh?FX4O0kR!sbb7n7ECzx}D2pj+<^F>17sn-g1I^)t z(Mxt0>I4F(MgXHyDH(G?(vb7#ggoY7_TfVh7zGdxCf$pN8y4mIEgg0UY|7H|yVpj; zBH@!CW#Kr+4E(w^ztny^AP{#zAa7U%k_J<@eA8E1LQVV5(w&7Wi;gIJMo5|b426+7 z#L<&pLh&u9B9|c*zSdX$>^abEVxfjhRTo~K=Xl8gWAVga2HS*4e#Fqzu);F&NW-EZ zeh*IUlFm^S-mrP@cz*CX12uJy!j)$*Bzy-dW;2T-H4{;emv|k!$qowrlp71gX@t0O zlr8)o60Y1407!5T&R>iL%RTsulJiAo=;g^c?8Smy&;%1&&PkZuI)NSbUw9w6jEei( zpy3(62975i9&+t4n-IUTzg^bQH?M*(7{LE-#Eq?6tL}g=n*+Ygg~dUcu=F?hod9e~ z`G#77-(T;RIL_2FUzvjIoVwA0Nv&n+mqX9SJo1%uW8C^e>FBfz(uA{_Ucw8fZ=-WK zb8A06CrN8BR93pq-&eknG#Va@m5Fjkpx|zpF@sAAqoCLToLHOjE;fP7jq63QW}88; z9VJM(C)veI01kR|8Cl!jtJ$tW7`>R3$#Lz-k@)`#VgX9Z`nY!Pl1!k+wz2t{uMbqZ z^2XJl-<908>;5wQXdyauiBvnVvJ+4r0P8n|H*|u+1vF+QgziL&UjKV398gV#Qzp*Op{OIHK<(lZC9D4S&R@+%yC7uRdLiF1q>3v7mnU6e{dW8rB>PAVa|>B>#rVwpxrBaX-5 zZa98WA?@zef;>45umIfb?gUnU$vFa%5!17J#2!Xxm-vC5u9wpQbg26tgu)Nt87fD1 zL5K?k8)XW7!lUSZkL&Ef7fn4g)z)ot8veiZ*c>zsek7 z_MV**C%nsOO(Rn84EDu>Z-DKx1p3S1e(Xdi#4kO-{+CqQ!2}LOSGgCDTG=$`>QAy|gXiUg8afAm{T>Vf4F@nf0q(31+Fe+xJZ<@w%2Th_ z_~aH?{M0zuJ{I(cIK+o28F7r9*#6A`OVb6zhyfpl;+0FocFUmBrqbODVVBIvL5bArL`AC6 z>hNIQK;58!|6qOPWc#~91Xvu5w*fP?0!6Fm(xV_I?zI%zr!__17J%{!!05DwmGdy| z;Qnb4l(3@hxn#|dtY6BL-pXPo6 zUdEYDlp4D(9#uH@ou@FX&m>AHKH)_b177GcZiHJYgQ5xqQGw#2hK1l0V?nV^A4uqa znmKJR&aPPLFFMJ=s(!d;?JB|@#TJSJ6hMj1*_(hha4FB9n{T zX@ZMi9@8Me`-m(aWyeoA-iRv1%V<KccShFbFIpo>{+euKAhe7&Nf zCHMJg!oxHdnSfCaw>%2_y+^AY-ZyUYT2M|SAT|(}GlojAeDamuEiynpYa6W*K&=~W z{9BQ_AN4p&Y{_$EPikjSY{8riiDP+|I8SWJ9FyuFoD@8%!2*uv@XcXhXe)NeD=X*J zpm(7Qv%c<%$vcdb|5xB>Dmh+mbz-NbGt$JBXkfCy!8BTnd}2l*pM z8KPZG-(tBjb`(xvNwb53bi4U%5kOs!z6Q6stBk!d1G1^O=Nd~(+?9QDrB z*8{eqr+KXc!!>k{J}5Y~s-02n{;K659ZdU6@ZoGD8aI&6*tS5%M$a6oP62T|)itbw zF6$BED_0RL61Gl7Ij26!_Bc$*jLDe18X8>!!{rcSuVPW+*O3cdU<$&b-iFS?nOf6k z9!Q#5tmy>0Z6rDkZX)}sTOxC-B>$1o?;l7*m{<&T+LM)7RN-9W?+OJ0`hlDZ6Im+z znuy8_n`S2axwXldiL{=ajr3m|P4%8HswE_C0t33u1Pk4CsRn$r(w= z27ni|orLC&-2>$@*E~B%D$YYW$4btGpAisqw_{J-t1$JGE~&O~8O7T(QSkM8{S*#= zW0b?Zq~XSk(vcZ z@%qt+H-QPX_b@O&(!8wSo4XGt3AEON;9reN%{eD5*IDY+nW1EzGHSX9+t6k9zA^d* z;a#K=)NX7;qfP>Jcx<&Sm8Of|?5Q0?xFPf!C%~{gXeE2z@9nUxehp|z^Prc?UHkQHaJ*=9ssdl_NbQW@`Sk(z zmBD9|D?uGjzl*(Aw1nxSyngTA{mGeY0#ymecqqX513^N;s5_msS;|XtP%!6{4f8~> zOD=0?|>Sj2Xlbb0Y)(lQ65zc9O^fkqRF53@^?oLyd3+>FXJRw)HC)l zI$wdQ*W@hduyxFir1+Nl})HH%x@jzywl&shNMO;M%nW=hApMPKs=p z*@Je?H=;|p^%&^YT4jVtAqSsm8cOyni&V@#JMvFhmf!Iqlx8B&IY92 zx#Xpw{UKd?QYws&WQp%6BY-jvk=Fhr%@u({kpTQSNMPm>;oR4m}z+#+HSU>@?A74Yx1#ox#3q%t>Yt6sBhq%hFiTr zTaYy}0@*!!lkC}+pt6UmtA<3$4){qc-`zS* z_E1Xa`I~q^V#8@JGpRx+amj5d&h{nPNtoCxfMjCZ^wgdoy*S$Ro06t# z{7HyrLm*KU1N%r&yru1LO;$|bg?O_ACOa4Zv4m(xhi7f9Z+2MIHMhk&ko+OaRja_c zDywBF92AMZ71+fPC==!?nmxQ5<8NsNqYl5tS^njn;VjQ!L(prun}L?`5F6;T5Ty=% zzm61F87J&9baq|?YWeMvqi+GsevRDWX?Wy}5#Sqj9%eibmx_@9P>a!}nUjUx`SxX0 z7Cl(6^a}2XyAZDF?b`Z)d`8)5cF)3cE2ihlG2n?!9l0cnDVQKiMviG-4 z2VcJ0j#)HZ-`DaIl%lp<7&wNmy)Xzoi)(S~JNgzbdOAehCXdxn=0K6Y!2P#o%N`ch$QKYKev_Q>Q6XlFA zTmVlh_2-3jvIPf8aA=^7_fjdI0}9JjgA~gO)cV0w1;TIAPZb6R5%2kR-ZqDyp|4FM zqQ^?{GrC~z9yXo1v3N+#=_5b9`lGiYoW5vuAj#mT zE}+5^MZGo^AXYcIfYTLU^aK4mB%$W+!Mt$T$&~KU{qm5+gvCIYi65NAool%uQ1kCr z&!U&L+T8eGZTks%gkxbo6-Gg;_B_h-8>^>H}a3-=Aoe?lMaDRZ=*lO-i=q+ zF^kbq8!i$tQR*>OHI1K?>abD8axLD8`nCzUtGU|q_G7$!z26BUB4_hQw;t5tR6V05 zbY~LK;ystHbPAnHxP2@%+$Nj-MxsmjEOr1$SL=c(@X9XO6!d}wi?}*_k_y_(reaW> z^_US(0saOa9+3i3115lO=y-b(BuOQEgZ{$Yl|zrW0TpcHWuwCN%jdYbZ}Lx<@z`k< z_Mn}QBy0e_u4l&#=;E8Y=&9eQEsmUJt5-!IaF-<v-D?^>FZqrrSQt8( z-VLTNpDV+1~emL{k1s|J9%3>Y?TQ+GHh4GH6VJaf6y+1L#2j*Xgk?gPz&o@*Q1 zea_tsaZ7Lm$BGx*zYdg>KykKjzNorw2P<;Xl!Cr7IC`d|UY6ht!u|yAs?L47L;}0t z7X(mn*2unVNqcm9%-ZMYN*nA8W5gtdGcl_EfIL*pbn{ZJ6Q3rW>%?2e^WnVE4~2r^ zK-ILng^i^^&Xu#049;WA7|?S3J{d4nQkd}z8W&>nM@s-bwfj@Y3M)XPZK;>k|MX*{ zF_keTATvE?ow};K3yM_$==aUFtz26WhPz13YR>c&7C)gV;u+rpIc4;bQ!heeoxirv{ z@w&Hy`ycKR6liXOXivKcHPtg-#6cx-QXK3tTfeW@!OObWV09wNytB|oecGYGH#vkj zVie^Xdx!ogOw%gXX%LMVK#d|A2XJ5@LA-cc4W6o`+iIEC-OjR8>PA8^KtGq=NOEK# z43cMY73{9RxDrWB<5uJ(&d(&ADPZwPN$1?IhHCSb=(}Ga%x-)V#D-Zuf+Hp{tdhe_ z$NE=;t(mIZRIt>LylYk2%Ags^{3H@}Dr712aHHz|;Yh&QK87(GrgO?g0inVv zy%B#r5Hf&8)7EYQ^z^Abp=)7Lbq_bOREhC7$)yB{;s9!62kX#rKp84X5smpJioUjscSoRAz=h|e>}9R8X# zt9-CR0g{6d^NIL|eWMN&Zj*!e-QCka+1d*;YiL7hU1>;6;&U*?)_0KTvl?OpEp2Au0Fp zbhTJ2ohDJwJ^!Gk7`qvh76;7mVkIXFko?i?o;N?tk<47x-0!Ud102lgf!UzPCod2?ahs7fr6y;x zEeSV$N8HKUvQI5eSPrVZGy`h0gP9yBe<%bBZP2{-_K4~z-I4C#{h&LOh_JdVio5`X zMfa_|85$tB`h4!9lUNFEzS22DJTsqC> zdb}XPlJ4{84MR%0L6e7f!rXhcal51j=x}hJ7jeX)I(R6TM@GMPd-4)go^9Gg7swGV z&Z>Z!`#SIZGyqMw3&C^78y2;|(PeT{vQ(^E!wE@_RVUacI_;2E&Ea!_^hJE( z@+kOXU*4pH&kCVr6{nC2377BVVWeYdSvQ|Jw>Sun*^DB~eC2xul&4FyrJ)HuU5jwW zp^;R-1v~$?;s#_k02JEZRW#ZU8?rI`X^vvTv2UwAXF7gvr=d9L^4VO97ny70jAi>( zX^<~$wD}C#s2J3>QsKTX8Q-$NK=Wr&3o>xybgBcf_<6#D@ThDSu{sJcnP_juBXzka zkR>IXYZcuoE~!E3B`p=RS;Ex%mft{wMa???1>Ve_rD6Q@8+7?&T&9Qa^Ew5Mb{~N% z$*uh1nd#_8MZx&#sk8V$zPx+ov9YiKoaJlko}BBwTR(xo8;r;r6pfqp=YvpIoqdvj z;qD*%eoW$<^*k@s@Zt!!#$u^Px#e;%pXmDXvc68OpV&DmL3W(s;gw5|%KI1%)0r?% zc--=tvgQY^#>`(cM!9v$({Shg+9x-EyeuQ(_hRKS<@={k=jvKzeM)x-c0LRL7nK_I zrNRF^^)0UJp0m-{OPeCP=Fhs$r|T@%7CisOkKx)2W_8B&Pj|h!$I2qE_;JkQ@!o^F zBvNF<0$quyL%FTTt1g{aDS!QA-95*1I$h=d@9)iixn*#~(}?i(n{IuH&+bnf1%Yoq zhQ$7DgGo;96>b%Jdv90Wi?+ylJ>AR3XMS^w^X=i3TjKk`ntuHJiE-`+UI+>9%vsr9uM1Y2kutFNL-oB2dymI#N%K){ z|C4*J@+CE|#w*;eW_p)SA#t1vhLUS$3SZb#GW*>nS^a#YPlvL5z7$1d7a2v}F3tXN zWG)n!Jg{EgdA&H|<5l>Vt)l5_^0qq`&(hmHlDMkXIQjU27R%x4y#e>e_M0uAlWsdU zr*~W%-+Sps@dusO>3V0wNqxZG{dZkLUT=CweJt)xP}`xNY2Mm#v3cF&Sr(GD3(oA| z+o@>4Jhj)j!T#Ra29}%3et9?F*s*z-J`D4PaP$6#hR$u-BfTk+dzT%gvYI;H-+Xg$ z%ZWYwx%Mle^-^!1md@?fik0wO5%&h2zV7X8nB&@d zPd35)*a>41x3Y>yTcnK^L5rPFe6e86I(YN4C6{`B!I@Y+=UHq;F&tZqEo3YZOA5jp z7VKP`{=8^!_b>0q2`3WN=YQU~OXPGv;q3^7V=l znqC|hc2Ym)hsehx{M=bL=eMp)5GC(#{$48&zcwdhN8GgP=SJ#-3ccE|^LjtMKB&*9 zn^$|p^y|eS>1n4QeCB>%pO$BBqVqs3bed_y{MG01d0;9B{XF+R4|u%VyM2Ay>iwVV zL{HrK=1fW3$4^M6A_|U>+*aJOMcaBxTYtJOKI8TFB`mh}iqLOQ@;0^zl9sEmYGW^6 zI+Hvr$IwzIZj-p)g2DP1Z{FYA^^GdLwCQm~0v~x1+?uweU%Pln83h_I-%Evv<~D?EA9(miS9;orP4r@QPU*X=MZKN4V*cBTvNihBWG0t2ZnD6< z|G}H2>&6d)LuK^)IzOxmwpP=29W{nrL}qYA>9Z%>gFW9z7p#k?Ds{V>EnUN67yRNQ zod)>ny5KJYKKts8f5#8DTet?q#%Fd zCO_iIYaiEJdzUq6+?@MrEWB05f~RSFy(g1(lW-Zegz{)H1jPfEZzF&Z^Zf#I~@uy9I_)TFS&oFKM++W2@$IborF5rtm zYOVUo$wg=5ZiAsdZhs2o7NC1sI zuh*Y)0$--sPiRcKo~pRT=;e+V60x@%t|Y)Qd=IAofVFYY&cnZ7UeNctK-Ik7?2y?~Ude>0m%+I@l?O81m@Rp%L>;8a)XpmgT&zp=5S1l1`8QUgk zHV`t{v2y96jRi(jYAQsl3D1nhWou`+g?t@T`S>+F=-A`zgC4uzaji!6+RywCt0BCd z?w42>T=5FLG=z@b`b5`}cD>VYuDi8ohM3#Jov?y<>N`)wlowdnx!;~m`p-8$a^k>w zu(tYiuzNzb(}&eNGRI~=%z3Ln(Eg```Z_}~Y`(0l-XSS7MW;(Owj1{?4>p-H@gkY& z2q#mw@v8pd;Wo2OxA@lBwO9KVEKtzTKJaOE@Asg>WsTp4!1dE$fG&Yj9vl=C0}PV0<^HtjF)5dx zQd0$43@?$v4Lyu1db`WE_xr0)-2e%Emeg1XDV(g+;tJ-Dy+CrxM0 z%X<&D_w|(o1{OAlsH=`T$+uW+D?_#xK&n@M7 z^B}0DVs80!dAd*2lDg|Tah`LfNRj;UW2nYAt+*l624Eil0JlvnQzCPiUNG%cwNSQz#^lfrN5*+g0Z?Qo!dBqLuO=Ps(PqAy|v&4 z!$zvfA<=Qa_a609oR9gA*nbnYV$ROdB~eOBu8J#sMn0oj4*ubOt^z|k$pc0fiZ&UY%$_LDykNM-8$<_W3$Qu3WYLU~cs~R%< z%2`_Ky1I=$1`lVGwCiTZ_dVAw*r zlKcR&Ngzb5})~A}QkJaI~V6DZ>*AcHF@rDD?Eb zdJ_(&)a1&GqayS=Ng ztjU)@DB1kP*+Z@WRR8X-Y0tef`|nX>5&?Yp30wgb#ek8?Cxe_jxb@{e(&CnoJomxj zNzdl)7W69s1?#O>-jjPS?Qa=CV_fcDgzG_JdxzS)HrmslchpP11^O8vDp#MXtGbwY z?dPd|H>pn&9|v~vz4YLMzDu8LY#NWG-Q+kRWQ*x1tjcNAd*0gt7;v35?}rA;LN94C zo|b2zEClqgyTMn=!oXjuDQ|+-5fNa(UX)*#8SWjiRBY(mLq&~+72&f@j%RlWp0^^^ zR7+LuopJve#x58&p1o3#<#V^0=u*qc@MTEDw?4qIio0V&Bw~CMq%4TKp+{{BKZYow z7ndyL!iLmcOJAmn?HlU+@+RM-+Pk(}K8j^@`4vZX-o9sNo##~ie5a@T3I#NYv-I6{N5+7ienP|X|+g4TOS zY((8}b1Zbf;o&7XV{Eqly;^m?OKqCF(l>!DBRdX2k;@>Xkv@Ep^ywr3r$AVfdMik` z9hFTvru)P)xLX#+uh}k_V=%aZ7ORrd*-%?1``rLv^k^&Ylp;#YOZV={MM~Xm-Nkp1 zYMJt-;JZOUQ2!YGbJY6T0nA5}$4kyq=QZ{^l27JxNku3C9!6=_a&CD*IN1$}#qS_g zR?!y}Enr(%0V$txQLqMZISdo&LY=t?lZ0lN0JQ76QjN1!nQI_d7piG|wmI{yG}VWo z#b=z+SX%Z0VP8WP7kZ5|!oKooE4n6zMXb3RlKU>!RA3cdgt7LUlrkvudB=r3>FIUS zW1nF7YpB&U9;X`4l(OPjknE~h*4!MrRKCG(=%P+8U%yAn7X+@J1+57Y8I?_rrw6@+ zA|QEe?(H`7=*n3pe)!BR|TKr!t<^m+6BMzG5VKzVQ?ElkhVDV@OkRFVLf&ntRmm zhWe79ys%H&dMR%@x)IQ@$a$B*oGd*Nu2QQy`#PC{IwuQ`W$Sf00reD%XibE|&`7O! zH4Ek|!LVJ`P;c=XD-Ob1p=SQkjo~?6TJbt@zm;5SYDskChv6D|7MRE#BdfaY#ceS( zjPc}YTa4i5OV zj}7|!*49i3awNygB>Bt;m`$1v?Zh50#szMk?NAktLPDnaSNF+XcwO>~H6e+n66<0! zxWCQT_nueLv`jTD${TtpSV&Cx zw3X-F$4hs`D(E-pOG9|O#u=gM7>(u(soo(+pEUmjtTPhmiLW?-=wC0Nt=<)_(dO-C zEr>Vd$ot(yt>7h}w2Rm@eXQYX0-%?-YPh0T%CiMQv|(~GG*HCSEjLh~r1XLER1OnN za@=1qZ7o3S-DUf@>Se>SLSj?tI@~EA)GVgt4pc*z7M04nF#BHyOq zcpPSDHjND3-ck|SOjBRHCxjVCDob1J^L`k_xWgRBZYAsJ)PJ812%cS#P-{CV4O91M z6}{g+h+KHE#Een(&cC&wtS?lHeA1JLZr4RExhw3}3*h!Lgt6~d2;=A|>&)wk&}&LB zj@k}&GANk$ff`8F61AqKZoOUJ;h%I9P`aQHgJmh28=oKALiNj$9ci>s{+^9Ufvatj zO?fXe($~@L;!4SrOp*nH3S#HT0UkrZ&x>+#X#%rT^N!le$}Yf%rat0NU5B~4rvsJ4 zBRF{a^a8EkWnj}f)Nw-t+$mGofvDwrDc>YAS0wDWYG1`(j6hA_LqteawF0#wH&G>V zvMccrK_9gj7By5HUcJ3G5#)Hdr}>4uUw-$HbL)jdHG6tp4sbarU&516y@O&trEsoaRvx^_`xTl4D;zK zAC_)7T0?Cblw{e|tZOy)IU&2{cbFkvCktQ04`YjQJm~9G*Y>~iom!WBf|K1rB2UKS z^tTULln-kl&ch=}?!Z6+oP7tQ<|d`N=&NeVi3|)FGHm=_eOG8uaxAJ;b)A%8SMI1O>%DrcR%Wv9hnEau2q|HYnazh|7#9rR zD~3?d4z1TSF9iYb5T{m)FP91bz6{z&6SQPA(T|PHM9BFK$FmcbSk(A6-;`lZ(1MW1 zh#QOG@bc{I!72l3RK2Q`1OVH3`wtxfIG@)DuV#=*p{-NmX|6MASK%#Sl!vVKV#0)1 zfUAddUf?QL&Q|nBFP&=Z&4WTPJpMDc+q1M1 zG66musHZsE9K@<)!Lf%yx#O}U=0~3Sl=iV9)5AQ(W$0VieygE(yyp(8??^NRkkajN zUkZvd0?1B8+}AXeXQ$e{r`}wd`tDYOu}O3g95=goLj0js^VlFVTi3xPKFR46zvq-HECcEMb)Y>^s1(R*0*xa-G31Sc5JN*Xa6mEL{pDeOWO_zl zv?61Xhjz#eaoVd+0nhj>=~*yo6?*yAv*H!WZxnE6(Um5mjnt+Ia&NH9(o8=R6fu2kRE$xZneDi+ek~Wtx=(xqBQ{T14sj_Dr)RYL90$Ubtm~El z03E6f{8l|SW>W6z;a&Ou_Blw{^w0&X7VgE2+(L`(dZ0g9uVfqLo9dq-%uG4SW?$dgHZ3GH00mC=E@Jr}E%|~X8CB6f=gi2=$?w~nZXzdFZCRR9%B`UgW zdvXlbm*#sVDu%S@k=y`wxLn}v8Jy`U)LGGtwn{T=IfQA})CFKFMV00TwiCtVzLbd2 zWos7lVujP{Gntq{P~%MKhntC8tI^EF3F+NSK0U@Cu;={Sl(e^#aY4KSr_S77z~eF3 zGVY9y8qX{dr>}`o7E!>5dwY2H8MR~*sGF1zG@mzu(zS<`QQr5)G&_KeFYq1&nf)5<#eb_|d zv_s%MVCOPHwvdL~2|-Wx(KIfMXdQ4(W#MSQ>XN_6!!~Fj-fxAaEUE78HK(@)$9K;l z5~6UrT(PQ%F%`*ZY6~W~TYhSVI$$1i5h*x6M_;&!6cVT=7~odU{n7zWw%l#2cI~G2 zh14q^ZNKV^_8mTTjeWY|%(WRyuH2cRnIZY*yCF&5so~OQfPv)mbeCIxu&EXZYxP~R z>$OVd<8EXm!;IGmjC?((Pc$&l2+Up``f*}f=reCp72i%5j-elG+tQnOIyDHvngv7c zSm3U=ukSCyscwV!`p&iSgM)$FGngszT*$sMQb*inu<1^Yh>Xu9DMkAz%-d_ zLtyA+i0s3O-h{<-_G)h}`iy?;T~6|v?d^FCV5#30j*5JayGWmq zr{_Q!F9R&yaT*upQCY;h6BA!>Fd8DcHNQ`vI3?yD${Ip$AqO_nX3EAayARW$1UW{B zFX@|^WXzx`z-T#+P60#)TWVcwr+b*A91+x{Lmb8B;s~p>9!m(YdiVR?1w3Z+p)xo) zH5Qg%Z9ijV?XwF1c*&}mDU7jxrfQ_LcEAa%*S~1myZn+CWmf=oC%G$_F z4~}a-vg zI4+MxdN**%1t-Hrcc?!-?rZ+wphrl>`^qfAx2>}AlCeL7-Cw>Ow|KAPLXD>%K1}K6 zU?n}W@6Er$x}=zfaCg_m-JNmZ%GE1iaF`3>DzvS?GI^u}#k}^et&N1y@zAz~Ap@)~ zG~4F)QU2UiQO7{;fqFI^-4bAP@PTFch&LwB0hX0tUdnq~4;Rcf2QNx0HK$9BUo2xrt`af5}j`kRm)E?-p)#j ziY_wUfesmQ?R;xDVr+a#h9+1npiQmQp}#tF3jXOLx6kHqsQo>CiFqs@6!d#qaqY2_ zFe>0a-de(x&K{Zr_IDuLxl9NR60Z)#+W>U|lR+~^kd+2X$+F%OB`z9E*nAzWx(DIe z8r%#LAl%;r^AIY~tA zIR20vhmH~#LI`}G{DYqxpRYdNz4}|aI_yL730?;J#tNT|r?YkGyQG_Np#wEqig92p z8#^p_0|GXD`XJE(Ehr8~FeHjRG$dsqYM;WkFl)ejqMFi4q3^B%wiyP~`cUeIg?MZU z9lbpps+Iv#PMZsjsj1m3hU#rJ(B=oRZd`f$;({ptCHAuudr>N80 z>l8*rLb-*~LguJZws+sH*5@=mS-DUr^vedxxn&nYx-9Yrgo_Y>^=UiZpF}176vQFG zD9ozW9f@Xv729b`qK?n+F1N%`t1ZnKO7`-d#RAnYE;xlTkPJE-gcf6ogalqlmJMyI zcG}vt{!EpKyLYFy<@EP#Wv2UM8ZGw}v{8+F5dENUSMd0LtY*zJzfpn{kU0e6g@m*Q zy2`U&@3u&PoM4t=FL3{$5>nXc-GDWKJa2G2g>)}aSs?a)ZtUJ7{U8mfx=To@H*e-P zctZ;NTte;k%DsC-gc@1hQ2vltN8SB;2CZKc_io&PV>|tINtDd8WfQ7>CW(X_C8yxy zsZ5valLQ`>iIKa1w2#=R+lcd=Anb|hfhVmWaOR)0zouVJPDw%L*c_< z=_Ms}ie3jz-G!4Ma-Rm>7VXGq-YUR>-^+ zXzoc#EeWy`HhM4JpN{2i37|aqP=wQ1xljVv`5>&+;ry7sF`j?bI*afzeOR5ZlJgsU zlbqg{9uO#BNaW6W^uk-V|7A(ftqmD4mEh_*KwE-(UU{bR84NJqfMF?YEWN<+(N>&H z1!jN*!!zkO4LBIioMKAu3QahOk7<%IOh~G}Yi;;}H4;rCXs^&WLWq9(sO+7Z7Ygj7 z%C2MEdwV0xBg*s|RH$7JPkz>$@>5!3>XFmueOs0E*Gip9qQpeVhZy#u)7?8%<_mgT z+f-~;KU-Lj_iO3;IJLfV0rVYHOpO&OysFVWWCNi0)=$1^aohmoyt+)m9immN6ol*J z!<0~do`pP^Wg+~^L1Y83(D2RsK*hJ6*l2sBr1(%XMQ+c}-ECWPfb@Y%$^)pig!|i< z?iX+J|0O$|dbGW(8cnGi;I~iRC;{#}Y$2j378tk}!enOi@NgJPOeBa1@gxFG38TGb z>yy!k7?Q*nM}gOAw(t?gP-^Jq{|+C-`OT?Qx%t$e9&o$*cT`bC0Mjm5;z5yAvgY`? zVwDH+>zh^l6fJxd@E}J2spfTjdI0Mb(zCZXdS5($NXu9*GDK{+0~jK35k5kFO{g62 zLXqW-IgHG>i;FyttG!DO_230i*!OYl_I&UhX{2{tk_IH=`JAza$g=v|3HtEO>3^wN z^@P}?ajYRRG39{jLiR6QI^<3lx3@zQQJNc!7s#@p8csF){k?woP+-%cKStuud;VP_a-=9i0nTVE*_D&FcQxaADN?l4gY@g(44{n^unL@NRA4z?Cz`ox0KG9_G{fJfx0Kntb2bH*#i$+bN=|nIJLJy*z$)E^R&~zZ;6__o`XU5JXnof z{VfRt-@6As>CcN!FbhqRYA&*P_+{1BbsS|j!r4~9CXwC1 zdoHBL97_E{z=_U^^87y+QLtIiDko1?w}0kBKA!@H2cQ(he7Qdsk~z4Tk3zK96#2>& zU!@}@o8bYoDxy;IY?*)%##PdxO~r1bFiJK^Tu2-+CNjyIgK%Rta}iGfWPqnsq0&MV zeOC_dT_on+2JprtNeVl6rg;`x2M!u1-=I;%R?`pD9yroYfTIL_yn?-J5OTk<;hWschu*M`ulJ${B`d&Z0)185t_Nq6RVRd$PQ* z#=5xjxc#4V{OHE_`P5)|au)-)67FHoaOw3htHHwjAj7l+&9rK5!!wl5Ae)g6waoz) znyN`E(u?&%yEiT5$K=SppC074GXW2?v%V-+MYuLUTWz`+-YzWe4Y zu(pZ{nspl|bHAEwmPu^v$oJA|XrZG6CO@&AWll~G_&&zqJ$2T7OHXo1YNWkbzYu{R zJQ)Dq$bi>FzOWh$;?Y5#{p*Xj6+6g<)bgo)ZB6*7O>>l$XnAB;VP|uCj{-g)s=W>j z)^-5xq}|%{m{paTKu4tkp1Dv>MnA|CkJFW~2h}Bc+tuE<{826!bHfZrAnD1zj~-(U zNu;@pV3W>9ZV12q0Sc-pG^HDlE8&q>y}o%#256GzFe{E*JUgIEQqEeKQ;Qv1V;`g& zqE1U;Q~W%;#F_mQNcu;14?P?^+(3dV=GwD4`-2bZDBwvji6pWO{SYV?c=<%r^Zg&I z{AH50FeAmu@`_9F3q3vWf{CbhIFf+ znP1kF!)O+0CDo}fSJaWPA9>L?+6zB}?n}%=KoAX1>%w%PWxq*r{2l0&TmXNRutJlL zLW~dEFpg&le7_4bcs2Oofx{(l=8TvylBJ{M9pKA`=Nhpy(a)TH#pp)ZN4{S6AFm3f zf5w3=u{i`-FS*$5IyJ5NQ(yZ^V&J#tQPx7^7q?nJ&@>4X+(UBqDX;sMjBI$XhI;#3 zAT&fbG3zHbTR@}xPS6`r0o{4b1za7o!}`KGg~o!5uN>=Wc+U018HoQm+(NF@oY8_W z5ML5{y&-(Q5?S>2n{l!jweho{(*JXzDn5RU*nEIJ*1k1Zk%V?VEg5_oVBAp2#LP00 zSL1VKM?Gh7&_JFfs5!Lr$2wgWI9{F$!s8CD;>34f4w`P8uQ@voV(L4j(qQhwcTMk~ z&kFbTBHwe0f)X!uwL7t+6894u#X?3SRysi|63jD?`_Kjbwxi(CYkPpDi*kx5fuVy5 zd>y9{2bjO3#|6eQ049JneK*h2m~ZpEWoPoOF4#n2Eo)H~U?wXLWPadr9W2ANd$a)F*S^ z3y@2f;L!sbdpkC{jo|WB3Zm%8O44sgfkb|eDE;1E(}=P#Mo;EaPLpFm?9MJWv)Nj> zkL)Onv^$1`%z=aRRoHQ@jQfpNR*9#5%~up9Q9t?lK)A*&;cnXqFviT zqfVuOc2(@}Zp-p^ei{`xeSTjduiQvu;K`$ZdIBu!1K0gq9^XHODr)0d;csYzPKpN> zNfj%z0jVU1k7ereY02OE@*_rz7o3FyAIyAdE-vl@z*`p;sLz3avydAV3FfEYIRi6o zy6hXSjR(>SZItKtLsAN60Eep_=`^c*V5j>dG_c&GF=rxVCOX^hu%Mg00GWYSc6^O# zPA!x5t3Tbw80vnJ)R43dVOC!Wb#RT+;EUgw$gKZM^pwQoK%KhOlEYl0e>?+`QEC)U zq0uyY-drhHQ5lS9zcHU8ii){>@}Q)M$=zwpIe8QfWj}Xgg6r0;17Nh87*^BNFx&M6-#2ayNm1~Ll}XvhBlN?2Qy_LL<^1%BskOV<%a-sAl?fE3l2*#D9;7y z9wDJXd8f1P<32Nqg7ZV#*JCFQCcSzvZEs(%BA50z)8r79KhNBT;2NUYdgl;|KpO76 zc!vcLU6GTkx!KM#Hy9+q9)gh9VpnMR2u2WiW58(Wfpl}WqNq7%&WTk8y8{D+WR_=VZLk?HLXoVf9%Dh@0BWF)m^9&Yi7!J{6iJA3Baa8u6UF&eTX&u8(Dw=hV_ z_Ft^|a6545C6G9{lB%WLzec%7)&k)6A)eF!4V~FG=6K-dH0_|^N`&l<;&Y^bfUcQpIR&1 z`L54hj~|1^QV6YEWI=c!*zJn;jxg&y=cgHBK$+=^IMR}f#2nOnteZ+f;M$K(yASg56;y+f}5Iq0}FMElJ z$$4KcPXh4n_zdLz4akvR;&Kiduzsu|EMy?iBt|$uAjZsBlRb0i1RSxo(;Sv<{KXAE(Z^REPm(D=Rr!gfLCTy*G0WtJ`QQAm46OlNhpW~ zj++YCEU6+(YqR|!34G|kb?Sk=`kPVy{aEMsLvSbs9b?g&e2YodC zBF%~kmSdA45z``7+!T~{mC0hjku^)*0Z^@2{qbX0Z{1k$#Uty5{X*56zg$Fg9U@AK zPVA8wvpB8pDlKzE%Bj6{O#t`n`N|Uw0xTnsPkun~&xI#Sqdc--PXqftFc7+36=(up zUObAaHxM$w;Kns1pA4U{0L^Qm=f1r>LcnpemtVI?&DDm0^XOhcISZr?a?#{e$kswt z=%{_n12wU-rGVizczRl>I=}kCep5)Fuk(%E(fPP4@xiy-WUet|(Ac(b4;$F7>Vo|Y z{q^ez)L6XhE3xC&M4qQAcgc29KQt(l`)$P$VT-xUhH z)p}x{Hz~TAQ83+kplH1aO`dr6?2q9W7fiSDi+xvr*z+?jjutb%5l&q4!;bkXfW@|X{A76O z{lNW)3jTn(T^>v-u8U7yL#GzpK2I~(`^XN|CDOsyIrXZ_m&Me3w_!~_!PMa47%!?O zOz3QGhFNTFQD`k-q}nGX-HVB-k6Sb!5CfgBIBUpb-_E@5|1+#BI+0a?cZlh4p3sx1 z3&9hut&5`h2w-ITddy(50y(k6G9S(xJ@mff@_|zWvlKxomMygmo$k@YP1~abJiDH@ z^u7wi;+(E&z_Bh3xUgcjgKGSwL74>eeEE$^fI#Mv1x1Gg@?edw7T6c^;Jl6NV)oZy zg@cr_N-fg{bB~^QEkJP_`@)BxTlTvdwy`|U-Ms_cJ3G*Qp0j`Q@_aK~`#ZQ4e&WOm zZKx!{w~*-$P8gKwCf9-c#1A^0qdVfOz}{u@H~~aQQFNS%(XZc(YtFod;~fsdLoSvEeNo}X33U=3z5e)g!}@ubZ8i+ zWN)$Xd_$TEc+cM@9|V!^;DY%)KBzFC2+YxZzIpq^0%_|g+UzYR3!{~|j#v$xtpN+_ z72}KBUW|FVq8?cm3rC*px(`c(WIEgh@3|e1nSN~9O?ZY(Y`^e18hHRtfroF{QsW6N zhL7}H(DMOr4`eO58)gG`3*=Sg^eG$2pd@F6O3Av3rEt83=UY5qFF|gZh0Pd98mKGJ zaqYN=%2!zqenB?lPNxxops}O&dtDcE*+R8L%8yC$Xx=!5gcxkemSVbDXe1_8gUa8e z2Kbi#SrFYxqCc9M&m!!%t;h{xVKNE&5*RVA8!rgXL1`rMq0a@lLZdaxpaTB0U0uDK zcou0Zs_Lp@pml=5G+jvJ4on*8{FF$Kc3TY*nHJd`ufr_%V>RJ<7XBsX!ByvXOKH&O zw|Q*hb7>woGl|goaSEpj6lRpM|q`Xl~7icSnoBW)x}x&~ZD%(3BXZXOuD2?UCE zTU>N5`&zIxtwmM^W}RC5X0A0spkjY&=x33aW%0b*{Y|weGRB~#R;~pY2uH$bT z2457Kyh*{8XpTSF{&J(GLr4>|0m0W!{No*HhwvxIjmX=`W7mu?3Yb}#+m(EcsOS8u z&wOn2W&;%XEgEwF^e?V$1D`K&_L(OW5@5B_=|a+PilspDB55H>u4c|bAyl+C6KEYc ztk~<|B}HKXMjq`lQEkHP7Ixi;gsxQ9vIoC zk$SDX0IU$#AV7m4b&b9Ck)NBwq6nkr-`BQ(FKrL48C3xr=?5*r40Vf$+lS6sVf}$R zP)WH6MJJ$!|Fbw>0zA6R&^H6|HDc(EnQ`v;2?`i8;k2y#!-V4~18A^byzK`_Jn1Yv zoPV><7%;_uv(OI_9S$Zw>-Yp1)4^=SL;9_x2H*s$^Zguu>@m;6Hsig7?J`hegnb2I z>i_#N|Mw^_gENE({xx7cvtbS^3U&UatSMs{Nq5GZYmkSM$%88zk1r5>*0UcGhx1XjgD0w%R0raDZ zAYuUqE=eg`2g5x$H#HQarbA}1!mgQ`nb$LEp1pLdnbetmhKV1OA-m_&CIOm%N!gWl&tFKo5>}N+1uJZ?e6Y&k7`=Fy>e>p>J87p4~#T5 zi5uD&bPC0&{P(SD^@QBqi4Iym^)yjzxIs3X&FVEJgdE3p*Gn*Je>$^ ziXm8y>xi}XIUS;fsqL4(Ke&JYa^QFfc0D+_CC}xYr{`oJnRJo>jBeo0t)F?0XM954 zrR6BoR{+QsgdqZ~(R&ktp3BvRQz66aT(=IgOW|ro~f$ps9@%6coGeB>~&giq?#56tJ0BEam9xvmjXzLtXur#j?H=h zO}h#_L*NwZKkIKiFM&frz7MT6TEL-@3E^E@l$sB#}OPo%cfBO7c zw**`Fyop+$cSPU0w>EivDNmxW`XDPX#i(UD>`Dm0M?@k~%-@{Sp4p$F7pR%|!DVPW zMjnG}NdH;YVMhf5RpFO!(Ch+s+hAi3W#zuJSq5!YJFzbU`o_k|Qlh_0r8PA8svWpE z&7*u(v2(7RyWK~St`)(UHvL=ekF`&3eH;Cc^KW4$IN6Dx2VifFW}dGi@I@sgB-mUv z*$QoolO~RMCGge8}aYpv^Z3r3OnYE32v_tR)o;Hb0ez#?J?w&L+_A zc6)E}CF{jB9x>QTNs{t8)AaPNZ8HA|#o3nb>EXKo|EU%u`?KrJct$2}Wo`9KZBV|)|CRDyQ8@xfx@}-7nZ>Hi)T)KefLPsRKb-iS9+@I zQcd-CcXV{1IF*?22*^}T_cycX*> zb&6H%w6RlNNfGOA+LEf&!iCI4K(w9I5mDS1Ph3n+J+qpCWi|Et5%XT&Wk}wi?8~z) zTurAILg6c0&T;8*&S;EN|ET!j;UcpSCXY2`cFwl~?0;21NgOx^IAmoa%Z?m($#xlr zT2nt-6!Uw4ZW3ph9H#bwwJAVykzn;HPtUwb{%7am@dx^U{5VU|F5Sl(^w>&2iA~}D z{rmBa1dgHjNtSEZuBBT`6gRvbof!;qeAI>&?G)tMf{GM{9Ok?#Ha0eqqqy78E?~dv z`aO@_f9U$lX|LbZ)LmP(lsEB6O|5upL$Bl1sNK61Q-AiFC(c_QU(lC`?@yZEn&Jol zFGu5C7o$_mQgdL5nU+~xLqTP5;x&!r8iw>H=lFFiXhTaD9=PA9=kDSn_MD|AeX$u9 zrlYd5HZhO)K0t6Z;rGk@?0CiL(2}`?3I581@o=F2A0fn3rgH;VnE!n=g(0Px|+pVolGhHR;_+aY;A@ELC()HST8GX1=EbCZYf#XxO?t zFfSbUUQhzl>e<|13vLD+@24OvxAu+p{1hy^Meqy%GKFJTmPbcNr+4@FJYLd}r*u`k zUYtvS>UsL~W^otYR%6@7Am=UNhmP=9I}Pgw8X}`-ods}DUPTU)MOHWM}L+4OkyE3-04nx6yk&)r6|=OvX#O&pPYmv{$_5sfMrG zUOt7p=PF_jHy)XKndupD2;M5!vTOM@;l~`tPowit=S^&I3d@i5zD27Sd~4n$uypeM ztsl=*6P?aE9<8tzVGyzH&hiNbBK_Vx$1A#eliHboG;|LY6<>Ob zyoP)h;=_C95pl0s806r#vA5;tpi(9s(bCdNPuS+qbp~6-p+q95NZE3aX(%mVd3?dP zho35ZSyfi0H{f=VYLimvld74AoRf+k zpNK6eT;nQ}U}L>feuiWx(m&06JWl8()r<#Cs>t8rpgPJtuizgIM6#$6jqPqbBAu{* z1}{#{NtWW&J+q^P>#=8&dj!9Hh1#EI|4S>P2 zPKSOC;E&l2?LSccwOE2&S#@en@cPH_}o-m!&bb>MP^DQ0OYAWq=8m<}7y{agp4vkx$0sA}% zS2BP`2};BN+B@t|7=@{+{z~EOh!bZM ziuXx59TG|*f%OE+Ch(SgY+Zw5~;H3ij@z{2XyJk%#zxT9TlSvCh`o5Z8ZmHgj zr2t$b;f{xVtr$3U!z6HvZ-T4lS8F3bqH*BNgm}{)1n+@mScQ?qkB(6S@;sf7Sd?h^ zR-3`|cs0KTRsF8bIfbN}tE%}*gKUQ7PlRK3Yv0`37T-R|AbXb_U(|+6r12Z&rwvwQ zycn(%R1jz~*MDwDxFvk($Hp-6(ezYTl5v)UknI*4eW&ft-HF-FO0@8m28o=~;o8ht zCTE9A*j>QBvQ%}mxlQhrD4Dgml(%H`%sX5Z!D0EoHt^r~FFy?MT9}o7D$p|s$euF? z$oI~JnBQO*uh3H=D;@0yrJL&DD~ng+vtEWtoA}KpjT!->Ex9pC=4PH6p?UC_l*RFp z^wgbG7O)~J7ng=Ly7pU36R|d_Kc3%hhCQ~5v#*2Rqaouy?2IU;eq~@ydYJkxGP+hc zHVA27RYbGI-_j58{YF3a1Sb7JfYAL2NGC%n0D;d!U@=_n?jzV{&{{hlkOv?p(GYD* znCo&eCUOKw|1LIvX~{{uJ@q>Lhe+h$B$vyC_&0cC`We@kth3QXd~@8n5ppZT?%nTv zbmcaYw!{GS*Lnw>v1N(sIW=Q$#n~(xdb?M&cVRiyPI94d1C5O(=BfLlHnJ^ZwN!WM zxJ#^YEL!#JQ5WSf>(|TJ7?3dU*K3r4=2Y{%VB7;^N!Cs35#PIaRhT$+gU!n8At8Fi zC3j74h~MY^qxU#v8U`2>{y3n2SncA4O3wO@g33_-UEvWC z?AI<;Y!K(PrE@Nwq^lhZ)RXtgn~PgPJiO%N{GJTNj_V@3J&AHY7%0bj8BPqHo#d6IuG)6Ix8j07CNpA3_vmmMZ1^#fFdAtH-$dev% zIXOJ-?rPCumbNMgSKgc(3A#$f>HalBZ3Br@!OHh`+*}tF9Gq>CywhgW6u0hiCr+~t zoh}Sdov)EnZ;#s&WZLd)5pGbON(7ctbprGIh3Ko#6klz6r!z8$Ae2OXh%fpFTes2X z+i8PoqEk&%zlY4XIQzL4cltlR?qA*(Lzht@Zma$-qFnG1<(8bYEb;5sVu6Q(pMUhO z#BMx@j7*gZ2?;5Q#UEO+6U_n7(jjg+31izvLe9Bryxsby#nfLQVY`;CPDuKXFY^s9 zMeEb=d0!1<76mCVtBLbgl9vU{P^bG-C&$(5<4U|uM3JR>m9Dy)jhm_|408GW@I{Q4-OYDt1Ile zkz$jPn|uF=yr24EbA4@IEW0HC%yEj1sbI1BIW@(V!sdA|n*uWZRPFMoUuCy0rMr0u z`O4m}Fmb8(^nbnJ>9L#2d^h(7T7agHhCG6CA_m8Z6scC}LU+L0^9L;XN2uhW$b3J0 z@Ux$h;1)%)xA7XoF#siE_VyCo&-j!=--jFy4bIeJe~TN zk1!@#(noLb)W3S#U$YG>wL3R!7q@cooOg={oQLt_@AKy`0X4r7^;1X9ol z(Uxt;l438pD*bS0OpXQe6;RPU( zN>Ut`YilXMUUqaDB9en>kgRLl9$!Dm(D>~)3jlp9Lh}#BxN9R)7W*f%O2voShqe99 z43SId!ZcFx;2t?Sld>iGgt0y}S&`SusjkAKnd7d26*~W1mi9-XwFDmPPapcH&&1}= zbo^DzNvoMFw6W~-g_b)w2a?x?V%ii!?)%H4Q{v$i=+PK$$|09TBzOUf6DWxEDo zk(2BAKMN;p_Kd@HtPqM|N&^tdjSCS;?wNfr< znWQ-K-UKMUfbDv1k*Xnx2dmFNW5To%k;RaDpt}B99n($YqY81R4wp`~>_#;mWIGJ} zMezM{|6zCjfIbjV#?EiY;e`9}((r0~a>9*ddP;Shg-x#q(89;q*0$!%sB&_CQsZ1yM?!rnzr z6|-(H+nuN8%*`9(VF%ECf%${A=fEOpahzhD8vunNA4FJm-_J+k^EzfPlkT#;E~OCaf3IHlqg*bL9h{g zMguWdnxrg$y)-D+&w95oi~Tq)WZtsscA_XBu$0JZqKi9mc?BIR1;qylgPOOGNRd5I^TKp{h~d58`5-=C`+pQBw+JnN z2yHSIj#rZoU~u`;ua;HC^0`rU+jNc4E?K$EJ0bVwE^)I<_CA)^l(}?BO9mQlO+hlu zYV{!xp))~U$aMRT?q@`$a=H&VTr@$X)Sv3bz=s28gL%f>p8kgl@!tx>eRLPw10FfJ zix%B?dH1)`Rn3k?Cpq94)~dA++fQTxW(8$TL|8Z=rmYoVdEy2B_vVI>=7#&%_PBuQ z2Q$|zK$k{tc$={-OC1R2{a!)s!6D%1{MABu;yk@(1j+Ds3X#qMH0)}UX6(PN%ewXJ zySlnMwu@0+3C_;X4J?{4_C@H7|CJb4hemY7zc<|tBGHvdBh3|iH*D?yV_^d3gz7Ve zvn50DB;TtQERRMj;5KN5$AWlczlBM>q-PB|lo+5_(dH6UH!@H$1gZIabq^6RreIIF}OY;skRgppHpm!4kJ zH1EO6=|kkHG1vzA_QN*8DDYnR{en7Rwg%4z!}s_7;;tO*&MRjW0G)-X5TVXqf!sEq zO#Gz4TLDQ=ScxoUY^8i$CIE2bq5Jd0xu-3W~{$4cJ24j(RemaNfZ{Ga==-{kA39_IIo5I<%}I@6V5Ui;cUBy%;p$cU2S2EUNQDsjtn(16yzgU3daQh{eD z*)+JuwIyko3VAgv+8>cjqxig5dp-E(Efz}Lo#^t~B0+aKONI5@k14{Rv04!gB6&a| z?l!eksEIDPok0weO3+=}-sLO zr0M?}>hn1SqqGd1?=9<7aq+}v$)dX{n(q`ib#5rBt}~;jYpK$*j@4z`Ypjo(Ud+~dqNy*5u3%5UOQs6yVUu(&ms`PUrT7LL zz%0l@;x;;OBdZhGZ4^jp=Ey0&PZ}|!OXPqR@KfoO8ow-Ucb$#@iHe zSfB!9DZ1A#*_pE<;VFhGPHEL^*WjB$q^2c#{$5CzUNX;CPxJEfmQDI4 z>+HUJhbLXk;E77@VXS1Ml=ih^v88;0R2DO>?hTb+YW=C&D!z_4!sri@Q#FYz#X0rr z@1!{D%Nl*NF>Raln{MMbj|=zX)!|-x4)b?O3PR*`M`~k^x6|Q3n-fw#j`1~n>qI`+ z_CI)@+9IOXs3#TiJoP!;1f&oU0m@E==I$QG9pCAKqsC8H1W?~>^Q@Zl2em}>fEkVJ#B)K$u315lbhh^oOlEVs)py zy$cMqPZ}EsEh|u7z%n?jI!Xyi^RJ)OA%-;0$A`fC073X-XeWTKnM(Ct zeZuwHA+*b?rqsdqMGXacUYjbfh8JWIBZpE7j)p%?dM=jhXM&u29Jc5dob=wCnP7uM zeb%d|NzhFd!GO5c13gat>ESCcZh5nZ^paC|~fFd*ty z3?4N5LpwZdfwKZ*9 zZP#R?bZ+se-(}}-;lXL^yG1iG5!0=UO`InTY)PjlBbFLoR+a8{cIu(C5l^2}mGY-Z z+m)nJQq*1)rk>dLjJv=^OXFCY-7VI9(wwC*M}78;zJR+&IZRsN*3muhpIZF$H2KLt zT}77=K>H0V)tfz@=9;S2qj0ynLh$gWPOdZObb=J(yaLxouY41$DtKoTMMB)}=32h5l!{W$5>!O$A`J5HoAnWaEY5xw|W-{h99FH zQPGV|pL2Ej?WotHw>~hXaOO7MhXDlwr$)@m2wVNmG#<3OA5xEa~r8+aW@&*KyY4ghoii>y?IBiYK{6t0^A2vUDnHa>P7XwP@$@|b;= zfsXmOyQ^#Vq`T9g>Ec-J-6z?wqdzpV+&*ZqYSzD+n)0&k*Uf<68Cid5-Os;cqJsGG6w$mo)_R_L!-YB5)bu*_Lsjm4k zY+|fIHI*3Z2G+{2zzw6LvejSOS?MrZitLGH#+5vpk&asgIXCmz7`+U)lOTn5EH4(< zN_mr=Et@J#SC(cAH?PubYmbY$3*tQ`!|j$U`C3g)O|C)UHQi9*ueA%=cjucvI#ohk z++-4Ir*}Lk|5)6k+MfP%cb>`(URXj!wk-@yypA_^USF1D`gSaSH5gMR;XrUcE09>PUJhhp)IK)pT}xE*Jk;)ZQF`t z52@6v+z>V=ns(#zC_>a75bxOf#wxK?KlP4`&y^{!odQBg?+bz-#~7qn`Gb{X*TicFKDNA` zjgM>LS+chV-Y}*CxNz+L0Ox zLiXF)HQl(Z76;XRaCo;Tc+-mCC4Dv)*52x$>6|AS?ksh43-4iu51k|liB3$<$gFpL zTcG~JK!JA^Ok7Gx zm{;0A${l;L95f-FCncZ{b!4d4R94*g%xy;8Pxv!-&fi; zZSM^6<2bFQ8i$q9+#Xq(SbGt=S_|NG(E6XoA#p<(wp<5Tw1|rCerz4*DaPCW z)8vHxVFmv;X7At{bR7!n$ccKXm3-r-exPWpj*wh>bw`mfUMe0#>+yx>$^F`|`Tfw3 zw7fhn!$LL!lBag9c&xSKFgcr8Y*Hzn^Ig%o(H1Ltkew~I_i2H095DzfNvS=9D;2V_ z)X6xdMuY57yO>?K>;%-LmeP}Jd!Ao&UOp;t{2aBX{b|;vitQuUmxi%6_CHk zY*|A3B){l8&VujCfc%rZkB;(=Zs5Erj{ociHpFC3Io3$sk{i5^lGknSCU4hF2;Lpf z=U7qlR*9}mgeHI3d?mYxSU~Sez44vNxug7a$xeQ1(pc&V0PMFzg9%& zn^M|5)*xB4Z32^6C$5SMw}l}ayDWs4GV2R zl4ywCwJTb9KkQ`V9S58HEbO0}iNEs0wKVHQ zlev7(14!DjRkR20f}+&ZqR};SJC`>*3H{e~{twH1ADi{|mw)ewnfLay;e7YN7b5*1 zXKx+|_4>Y#*HLLDt+KW#Nl4k()X5skS_ze8-x*tDa#UI@p(u|-#N-~F1@dB1<3_ty9P-Klw=*Yn)>bzk>&Uk|t;2=zrH16v4ua&anIe9PMIbI_-t z`c+=m!U=HZ$cg-aXpqx=0^%Dq)fw-c5P=PbD(~L<$bDmYkJ&{HnoX=Os8UOHiIP`& zphSdC^p#cU0@6(~SxZEz?C)66t!WUNJK6Q%_bkwBmBUK@=g z3{ayabQ8fTMr-2a*M3j~B-%ZI+k5w+ZwU9_-|T<=WOvqq$TOb(V6w^Q4a_VFT+lqj zaszb^n+Ud2qih2Wi|2yZ#7y%GcR{6!YM=H=(^@1mbgfv>lfwe*&3|b(>fTbYI4Oq#01HS)E zuly@^#pC?OyqtZ$h7o3Cx?pp}5wOV-LvYm1UlDIIj(L}QM@qgnxCX+=%3?zg5nP7i zEqo&n{9h#T->yL+;vNi+OdWsb|2;f*5mWm3I-)Q$pH@65n@+Rc5k`i-E#wt$0Y|UiLe?rw|kRE<3=y>tdawi6AOYt zrbvMyxu6DR)B+zE4T7&@m-0K%U;J+SX%!MORbHIS3;njY32B=S7;SV&Beba8QJV~C zL<5OQ6=Mem(o-4OAnH_fANVKT?@xgZ2IlvFT2lPqNz{7JpQ5PNf4FBc(BaLgKIaHl zfzVUG*Y+7{ULZ9Snsh@4RwoFngHbgbRb=G#zcfSt(SL(F!aGs*Q^3^Rf(V%4*@$O_ znF3_V_H(YZ;j0`to?6}Pa-jS(GR4-*r^!f58?t5%o;~J=y%Qk{ z&RpEZSr*0XRo#*!D(+gqduj1=gxHMr)_YCbk%nd`Xt{pPbo{a;`A=iNBjAp7Gl-S~ z8t4_M-P;d}xq^raTE4BXz3caNI)za>F>gt0*0e}L>CA|CX!|9MbM2L{4` zsMx>VaUZpef1r#$Wig`u1pOE@p1|Hs`LZ>nyrM$5ZPQ2v+*W9?XWUKKgE^&&6xaQ@ z0E;DS?%k_O>^SF_ylw6=PV-WekHc)R%4!mH7vm22zNXXi-QEA_$63YvuUaOZpA!f+ zyvPKCoH-jGCA!Y|R5`-^hGb6pmFDc2Yv!3D_URG9S>I>?vZlTj# z?r7)Hzy2w$?Dl{G_z;Vwy_j)0S`r_k`ZlRaltieb_dbox`H)c`Hx}BuvsCLgZav!R zJ{KFz4kd;kq0|03HSsfg{>R{XE&JE>otN%iPNZTU`yLCNSF-wjn3n7BOT|5~hDR|% z#Agax_mb`3z78n=SYB=Ty8VCgd<=u~&gQeW z&F9!vl^KXJ=t9t>g@`F(J=!yAZ7!$klgR_?XD+NaRy6Iyq^R~~w8|y$i0FTNJ z>zk=*0^lY>nT1YjB&{=ed$Ict8H+wT;5%)@*qrE_Uu=YV8l#yF<>T}=9rW3<{!Q{T z#vgxc2r2^5j2p1RdOxi%Mm{6WWZ|3y%0Rn-C+<9usZ56tAMPK`%G z+`V^7j+MFTJLLXp{ZQfu$|$eV07`)u5v)+);v1L|zI@gYNkv>G`bBK%PL-V~sMKb6 z#AILXE)m(M!5)`AewC3@f_Fe;Cbokay@ki6l6=Q@m1{hE#$ykTPc50m>G)>2tkdgk zUoVfXb?MUGmuEP^)BV!P#6atn+v8_q#W*ETN=~LU8t&~8V6#ZLiEYqm}ayaP{VE{tvBck zf`SL*+E;b?nhZlsV2CZOG?o?P!2?-gA}=90yG!Yk93T3x<@xU9fcNlBS@IXRkdGaS za0PXSQ$aW1o}a`@W(GeNvNp+XRKNk}uN*;iEdxHnJka(=q1$xFHzN@o@(k(I2A7}K zti)=N?($w#VpE;GU(8L5Ey$x?wz(7Ir2EG z(bd)|-$%DtQD>Kd4M}E%1;?_M?5NUR^1z@eHgk{-b86JaQARANo=prR8c=iFOW@KI z`g?84=up>_yG=DckA_}>k-T1dSxsjLqEJt-eOu;2paK9vDW+cHW9mqB_#0^+dc#wzCa>q@#Dau{~r=1Ed{;Y4QsZ$)2`u#M3)Wp5?q0i>%BrrGk$ zc}H;D&hMFh)Y8QJm!8To)an_WB}^=RtjtunU0`AsE+8tjoxP$}Io+WN(`pibSDmyL zr61nTet*u~W4SST|MTpfIwSq|W5fF%8>FaitKD~TY^GGJKr!#@h>&X%2!r}xsiE zr#CP2)$YczyKm!fxnMvg0O3_Jzg_I@Hm>P=c&BH{Vp!K#vf0r1&%C$SM*?Tr=^}H6 zw7+ZNyEr--sO8Mmv)uQS2(Al8c9g*5dA#KeM?_o*~J;wA;aHiiYW6BWyP9b2*RqG;0+Pdg&OE&4Fml~DKj}Sh-u#YI4i9@-3@|a>`qkv8QUv z%R+Dq3KtAKmdnS9`?HQT;}N~xM5o8ZfxPX9jZ94w-8kM&*o$G6{4LJlChwLVRc=b& z<&8{nVQAB^8ye?5IV2{~J%Zs8AtVh82}}>BxIr6#$xuA;j2Ee;5y&9KAZwSKAi~^BOI)OY>T$uPfl|WW80EcD-x1fac$FMDgBqJyg*0{Be7q zBy>wfE_h~|yiAK93n0cfJ;&Ias$Oz!i7fh@sl_+O{WM^Y{NT>2IWlXw*dYp0@ zvVplR$3DGRr{Ko0j<2yLxRRT3Ch5BO<1+gBjSfpAyQUa-nK*d0_bresLI_b-@M|D} z4qoY406`!Ohj9;_7X5y}S1U8qD{gz9s8e37m%>UNN&+-ZV~r|*DF=UcMRjfX~q<5 zxZiLbzZ)VuPu%{%@~x~sqLkPd$*wo}cj(7jaFSJ2UFqFfAEz%OEa2YIGhStmAd{#_ zVR=oXGPC{Oc-z~jP_S(XB2Ico>hvUymkt7&XFPgIX@ouc^(*scd7W{AM_OauC3^#( zMoyYpv{X-mN@QnmKku0HAy-kdg+ByVAdm~71$YUWS*mCXDWO1oNUK>{Rkgw`Btyr*3{%|rxLt9fdHH8Vvo@zz zu%O)1A*bCt_0ZwtyF8iO+w29AGG}kwI1EBiwY-$6@9GkbAx5O~FhXF)b-q>eG*Y41 z6EnnTCpNY5R!4k8f@FY$(vB0KQ{3oA4ILBea30q=VT*X9P|IiT$L015iDU0zkj|p; z+t$t&E~})qCVAAicLZ0h<(v{7A}X%?_paXctRF_o8I@K)Igg=f^F4pYGk*>EMt?<2#Ei8G@*Oj`KX0ccG@<(XFv_5J5Y3Z8|6vhqsxvCpEl}P4EO|ANy%FxG!MHXl zren1EutlL3C`O>Ex*SN+v(f3$wwSu$(EAp+V&t`#j%T3=ZwH1fRZ`-M2Ye4a*-Lob zly8aFNQ}1Zc&|cylPSO~D3)b}Ln+zp7MHbYA$`oZpDeV>Ew;nZ!x+0;(G@0^QdvX> zhwqx%a+w;Bq*QWWX1-LZcr{PBfNir(oz^OxvX}d<0^6DcAy=Rs7qS$HWMaeyjC)T# z*Vm}7?Y>8qoVVXf#%SHv3bU&x@oA@gY<5J+|I;Z8|ODfeCDMRjY0C+)Te27(He zB69&M?R1;t`}#S~Y0D^45}oGIJpMZFRVOCfhv_ro(*Qf<@=d=Tr?YdQQ%nlg*gx4g z>baJlkhE4SIbw_TSgt$M;RkXPR#oIiecUs-@H)SJhS6WjWpZJsRSQMM@%8UTpgO4N zF4JS`jG72)-V(VBh-HJKL4n&UVoe1_&wBeq71u?P%rAyziW!&y&`N<+tRoeN+Rn+Q zo$|a|=tLdW@%El zJ^lL_2uh%7;X0kj`{d|jVQMYodH1*w`rx*RF}Y_)nFSkf-E@6`x9qi$wm{*nJ(B@Y zGV&%_>eLzPtYTfk^x%q)=a9=|xxFX`_{R3f#l!A&8sI*6huQAM;9fyMLizbb0tSEF zk`z{`-~0RL>@{LO2ajWhOl$G^l82AB7_Be7Zz^cbaZ-;v5@|CNn~WagI@l3CGVip+ zd#|mNrH!@hpjh=OdRk2Hr?HB6kmW4GEetQD(0=SgWLN@}k1EQ}2JUWW3-l37Q|5$U zQ(}Wj(*fTQ?K`Kd9ZZSbz3){mWWnt1R~|g=#vD?lXjM!SCP4PX=+w%3XJ$?M?ZoD_ z$W>0;m=ix#bZ@;|pX&0|@1)mruG42=yfGQ`@%g{S}_>OS*slxtN>Y)Q7vYE_%6s0D17?!>}Q`uo2dr2N1T3bFJy$LSzL zUKkjli-4*9Ska{JmN>5m_k5K}qfrjjEwglhw3KKPkA2+lyDDU%+|zDqZ!fSgndqkR zP9R_8t4dr^E9@59(n1&2F4M!^O8+1!dDWeOyflEk=lx3e=Om;QMhb|GoU^?>g+|VZ zzZb$T<>XxcCWEPZ-Y#~>;fP10tAmi~#9OiJqm33IYrAz|n-5|mAU*=McDn|nS7I#| zsGRovRJ&AreSTK!#iJ<@L7z`J{e_JFgZBfG%hT6j99806=9WL&Q3e6)BI>{AHq1Xc zkFxARCefTN|DHsnwFItFDNs((QwY_qg03<{qs(;4QY5Y>_%A&RBd}&);3T#U7w9(jKFwXPFqAq>vpoevlj=Hp%F8iHq z!gB6q6&8`4IR4%mK&>b zzheJx(3O~bRHmqi+SmF>V75!AYtZVqxz_QbT%XW>Y~uZ`axTJtW7s92iwdKVDY~7W zMACR0Xr3}cN-D6Ya@Yca3$T_4vWw+DU&Wzijkx_99d{=v5rfrYey)sdi4tzy zJ#9Szki0v)p8P^#L>+78+eSOmy`ff+krBvmov<>*7$m!1YlE3ZFJ0g8NjQ9@w}Zd$I`#tWPN}nRA8@~B-~K>`#zanS2o+?P zH16i;gQ8T|H$V^0b|-%|II0WW#{3reJa8Wxy-?W;g(Ifz@Nm`lXNjIRAOIA`EkwYV zDgCL&_@Mgpbwd~P`LMq0nn7pj|D^;H11~}S+b;UG7f^kMB4gg)0?(WU7ke*V_b4+5 z2NFp;JwX_qx}D`c)Q)ZIi~P*<VcRH8+O#Q)UU#{8qd^+krfy6=)d zC%-qb@E~5W9L_%(R8ssnH0u)2{@A(S+Bku(4U<|H9JSMlJO}m1Cb?!j=7$)Foks0R zI4$U(;rnD3MmuS|`S`#6{(t)U0dS5-_VwEQe8FXt$k@i4tQ6<(?C@4=iqxX8(Ru*P zwXhJOzeCaH#1wh%3=yMXDB(ulaH_BWi!1scZfGUa6t2-zLf&Tr$IyH5u)GrjilHvi zUzML0EV)dC#axWK|8H#r{?+`=#Q>O43$4*hLQpmI#?$w2vJOQ=C<`9$O!9DFW&hd3 z@W1G09-YzwV|37!hkOb|X3W~@H;HU3q2Gqg2ufq<b5^GEBf4c;j|6}rg zkpUH2TXOV>*$#?8vR}XRn#O<- z1DC5aBh+pB>_(MVoO#HiLyqXw$S*7<&-wjhp@RAG%F}-`m4AZFM+Yqx{%~X8G`DTD zSc0lX7!1ZIeKE z9KWOwRKxQh`iFn-cwUtSB^)9`C;X81Xh$SbB^Y}KDwpJR^1IpC*?s3O6$gifr3B`^ zJ=o?h^%Jt!{Bmt#(}v!#OWhQhXx>RH$w#v=fcNLLjo>xKnRd*}-{SjEcW-!51K#;r zwC$udhLiwBTgZ-Wc<8QT!^6S-W2*E}oQNe8{Jdn(0l-5rzjX6zIgmLy#(Q$_L47xq zW?B-Ig}KEf-D5v;cy4c*Qrf79KCKI=ASV#*r%&8Yn&p(^XM7SZ)Fn_M$f5td>B;6i zms0x6_nAK6iG@WEVw{?l{*$}fKVM(#EfPQMtYk;M@g*!G0M(IB4=krgpl!pRu3@mm6Ma}m$5&nEy6(x^|Ss26iFoiiVk}37sC*` z@q28KmJgfZIf8S{n;44dCUjvYBItAqxa!udl8&Qd0{hZ~R(vop-L&oWYWs!uoIPA@ zB!8+YTU zeVmv1m;ZPFL;H3oL~?E4S&lY*Tt@%+^NzwDTjV|qT*934W{BqxdK7bSE3>;z-Foee zbH%V?oAyWZx+u!h^z>!1xo=(Xa)U+nR%(THVe&}Dzbu(OF32cpt5u9js@`qP$2U5? zJmO%o2c7OaZy^Ieu23KXLTX`b;!r5Hkw7TLg5^ z)U;`@hjwZAZLeT7gE!C&ILi7h;)CkrY0hFe8xLbvuJO2DZABnPBK-3%+X-m6`XI|D=2bBK z6+OpASJ3;uZz!WYH=trLE4*ERgBHE@O3_vttD+n+%-BWhpQE_)ihRJYy2feoVl*=B z5}J|@WAIDd*|V+kGpAh&2{63q7KNUcS$1B`YW-q$a@12|J~30N$+})#s4%MW0BW); zcSs#R0^Bj*7*X%IBok&m@WA{6$yxg(b(S*n&3RPxHUmf{aBSj}< z;v7F}s)DN$Jh{Cc@lf1yJg7JXUXu+*pf6k4W{(I_#$t z8`?fvf;aPeX+MCL=I5VqSKWUpK~S+ptAVT^6gf zE!B5r_jjBwYk(((r@U137n2|LJBj+6O==WjW16-?tbmqDZ`g3z#yRsP z`9-&Tr1{+)tujbGp{nby^-OCQ6E(A(?Z4L6s!TGgR94HcPs>l`&0Ah=tmZ7dkR+_&OxaWXf_ZSO zre4|=@i!+{Lw#Ol(%SWWiVSXweQ*wIEk+z#!EaU=_3TP3~ zeI=C+C#m>ym2)h6u%Du-B~zo^K&1P;*#)?O&t4{B=0-zS{Y!FRWSSySv;A9>o3a^~8e0^9W%fR`1+>Z3C`Q8Hk`uQjx zi>hMwkGWgi_Xu+iK1?Lvy&zJ1(zoZ`Ys!U!9bC?H`Hp{Y$J;H%#1#h@(!H#`Db4e< z6E(${+T;Q|+AB^1ecPO0Z%y)+$O})*D0Isz9PP@rBP!RZ5o9}G%jxeiWYlxc&&+(C zUC2~ZPbViYJ>1~l`~A6IYEUf)R%hu$mrL~i6kh4oU}3MwPGM|aXD5tY++UnZWc6(< zA{;0BPpVS3VNMOQ#TvvGCbFvAU3iN!@AOBhE{po&0(CfvApvgk#Y218AHJe%DcS*h zwKx=wp2N9Ih}BDZ-yLjf+8V3hv?IFCB3z9^QG_%QtUT(up7)(*^745Vfp7UMeItJn z3%h$iJwu^qD(G|HILg0}a~T$}@>&pIIXYM-2%C2Sc2CTljp=l16Y4Kb9q~u~*J=iz zTe-~BWWjE|*yU2FM-Z~EC!HF_Wwu?>cHZkeA0r`_Hr2sqe*r(N z&hx^u=kZw4AO<$uHz_PaLhPEZfm-Y1Y(61$mke2AO6XiyfbedXF)5Cz!I%B$QAq+L zL$rhGUILm0RTbgVOSfR-0Iur~I=?1R}uS-Q2 z9Gsi-%pJJg9U9#gj$ZFT4diRb<|4~aRNIY=mr<`m}BpEtXfZCspjw-~g?=EurN zoI0@0?^lF}<>V!E#b1BCljSEzR(A*_B{4HII~zwFF*oC6dfk$|>LyLUCv)9kttA$< zB15@0IxHdf%;{?s%}EyneL3;ovDxZHGfnpFsobolmYD>~|NV=AOFuCRfUkd(mi{g2TJ$ zEw6Tq>DS<5Y8O(>r-%@PM7h{1A&SZ)psR!de>oWvPaxeO`1l@B7y0&l;Yq-Oi62wE{C7lH<^LQe+k@B>}|01Xh{2pSmsB1b!MthyDi zs`}02ZtLh&P+kY6;oHMRy)Yuu9^8k zud5}DD*}>TE(M*ar8$GS8q3#qILX0=xV#wj1a4ke75=q$YoW>{UCh}V76T2d8d$?s z(}VZV-Eu9n65n^cGAemJ-c2n={&h=+0_7TUrtOpr3-NJMH9O|rq{uL;J{#_VP*rfR zY}R`bU%Clb94%`B1mOl5A!SkXtg9{t22n?>2B4iqbNv01IuvK$1{tOj|$-i7>=3R43RwuFl{2ujGx zZC@=^4`;b%u_ora^n2qnG6Ec#8Rz^1X2h#2rzn$XVhquh>~H(7zbhah&IOz`1)#Lu zq!z?oOLH7^^#h^bo59ShDYp5Qj3@78}h0m;5RN)|~o4Jo?$trKrDn~wVr6^Dk? zg<#m_C6(=>R^erF376@`A|F&qi}$VDx6RA-%|h+OM|2nqt+E92Ze0(Rqg~L|km&nP zRIcp0xMp}qq~*93BjZ}mn8w`5rxA?V*+%_K;)KDYKR*7Ll$YH-cxSDz??G_)~ zjH+2((;chqF3?t!=xk&@p?qT4dR}RVNvZ znm-%bmXe%2*hAhWt3X?cr(@5#mKjnZ-TU!kwqI?*5lpguXhEG@?_qC`q9+SQuv^P& z4vH-=`j8m;zK?+xK_Qq@w?^fpq6!Wx=3g6Qb~cgGZ{cu|TWu5tZBIC79Z#ue!vyKG zOnq7oNPd?el=Lq1R|2#L$ugP;u2<04&CVA%(Hry{S$hA9)8k653sZ}i6)NH+i zh&MB&-zhF4@7lxRok^qqbbbG_A<4W^kG_k*T^U6yGP`3Kt;aOStg7wj$oLgdEjcqo zi7t;IOES8NRb^vscf39$Lpw#LINMueW>slMyPg)mwvf%YTkKC%hjqsk@hBG?Etk3-Wl)Q7&g5hD<QoEyxrOm+pl#iE? zGVbZ>>j3uQuExmOA$lqKaDTa;v%8N&K**0@jPS_j%Q&JSr_!mvoMze(Cw82{VBW_Y zrAk>7=+yB{75ICtb%2$v+5QBe?7MtQx+B_&CA#2hCtvpY9ILCEu9s5vq=sv;X62ro zJ>`J?)<$2|3~DY7rRJmgob_oP0v#zuoazf=6Wz?~UsR%l7>WUZ_m9pMLjF%WRGr0b zp$sU%z~R~}IcWArpEZJj7npb~;ogBn4xiE#eT(6vnHU0Dx)XCvm?mR0GExRM1a)GBO0|Q9ckiAGVX^;XYW!tC52XIZY3Xpy3l9?1xeu#d zwu~_V`E>S|BEA>rWwcX^9-K>9P)tqmFY?pSsm>QG)R?=bG0nY!80SvNobDiPB zKR9Bv+%rEXlXNlaG<<#iEP?9>-k^iNYhg#<64$q5ihJO`jy|HKkaTa|s>&}k?J<9C z|Ej?GG)pAw;HzkLMfTt#?0m7Ix+U6UzeN9DJ!B^J%YHtsbfd-^hyBBRhQc)32wy3?qiKd3 zR#Va&YBwv$@#--kEV}(FGUOFJCx#iuifRb8IkxPE9Dr@m2?a;f3nz zbJ=VkMY*QNG6hMQ`u#QHq86sbpDKz6N(rH{(h5c)o_Y?DPu(oa@!I^N2*BjQypgNJ z89~vcRr4k|&tVPk$(?(UPAf3O2bl)BwFiItrM5ozRDI(Vc@C$Y71V#|Lp5eIuqkS+LV&|}L#jj{KFDrAZQp75W_CLixz3*M^PYafED`8$ z1$CcB%*;PP?DYu(9>lof-lAf4~VEIek{qcr;DVZ9lQJ(#+&xh+L&cRV9wT(Cn>7zxI`i-~q+;n00BDfR6n`@)b{ z&Pq8%P3Lra)yn}9LC0zVK&7Q3*x`xYFYK_B!Zm(fPTX;_Yvf5nspziKMj2aj(o^jP zwq{W=mb>#=Abc7wau*iuHET;5^zqQ#^|oRur?;%!YTq_L$dRj)vMehR11}XF+GAp3 z3hv71WiC_rH)ya-%B({zD$>7r&V`Lq{oakSxyup-Tn7}VE#GeZ0T3`b>B{M(1lLTkhQ*U0q#{3Kst5 z#mi$!09`x+`?Z!=*JMWNN3Q{OBW_$aF^!SOn3!-`xoWy*O&3W*`~-$Fw?Afnl#-Gt zIlF_?q-nZwP?o93ad5gQ3ClbxfI^{c^{Yq5m1)1>w{hN1K5fZoqT(pxi@~wjPoo&+ z^4^UqGLP0BwNPY#oxMj&U}{b+ua5YXV|9lhrdx>zL8; z_(M){cJkWI=4j%Mf_^?9gPHjyLJXxxd;h)sA-8p2(tu^2@(VdXJ&~GSq8;Qxb*@!8 zr#b=gQ~eLGS+b^zVy{lJeWi<{Wket(i@In;_Pkk8S|uEG*>(bc6%eE8R$YkA`rneL z7c49-EzQkArm^5sNdCBzb<;USN)ju(e9V_^LRm$Gls(wsrv^TWx0Z9}iw!1cYom37 z+WaODH~K}})rJ5-;==MK=H_M3w8VMDr6w%J&el71j+f8XAB$lXr<66|*6xpg!`3A^ zr!~*-*eH7cJQ}pOiRPTd^eq7I@A4dqZpmqz4owbvt}k0Xr-_0eGvpA>{&2cQTYs=2 z(A(R)!1<`}C8OItw^=0*O1a>$Iy)`}$t2L6`|}P9@EyQaeh6%Q6Ra1e+qKM}{l{*T zIHyo?$CMt-$z@2Sph1$dTKn#io10s(S?rFh6*)k^IOS9k3Y}Z@R%gc*>fdzb&Q;)y z5VV#RoT3{}pqzqTeiT?!Q&ZqGACp?NYzlG=I2o(2JoP%;+rQ?2rnI^i%=BWUl7{lt zfVqo)+NCHE^eB;rU&zyTZYmrh6a*a*9(BcHIJIkMJ>u>kz(zqsE#$g^Tk8PF>E@wW&CBRBkw15pg0|FJMTL}#-eB#B%c4kwnDp6=&X!yG|l zNuE;XtJ9jhh0u*{;pT%{$AcQa(40U05kNI0u|$$XOk=G0dRJZYrg~@C8{NEhv>-Oi zY?3^sraE~_BuKe}hM!9~y)c_H!?&wtU;dBM|KKJu^VQ1McjDpN88;FD@PuI2Lv=(M zf6GJ9AB1`H(2SCWoG-Zu#koL4XHJFN!^G*@8Q#F^R40Lv@N$jA{!y!#NV`y6HMZfT@!td z{Ahl5pYA9lJh0UI$@$!Z4&y5=(m}S|n+ohwv2oF&SO1`H#Odt&$p1a6oBy-q-Q=Xb zvBw!|2^Sot^btB;w1K)0++ncE^y_msvo@tRC%oC^xRx8Pv-vxZEASk!zloLcxquizJJ zIFbfuzs226fBu`RT}jasxP?Qu{*bICs`xuLqDZ4jTZspA?wcJasP|cIx>f>R@}XL+co1LI$?nR6 zcfxan%l8D!GRGk-5D561&UgeKhL3eU!P8d5*L0RGJ7Myx$Xya3@mx;m zTdT;n@j)}Emi!%;MLQbLUH~>jF!!}$hF99QebnQGAsZsc$wKefae6Nb?5Li=;%8c< z5KDwa+cnb&VVSUyxX_@by-qpV>TG<+(vlZ;Sxw?876|)=o_3(s+0fNRkndLfJSw6U z(iPTSuZ8Y0$Xg=UAt^XiZ481l_4=O*IY2*>vr%9M6;{!l#C&pX-iUEpBX7jAY)4k*(;|TAweU0~wyvojO?8EQ-tKiN2)U=i{{9s~3duB_s+6B6 z|KGx`kdISP5QNGRzp<{BaTSOXIPz}FSJ|g*9kfon;qQOFhvf@ zs4Digzuj|bxgJ^x4?no`(+E~QKj}R3YIb;!*HYvX%iOlv`u5;LI!e&qG6;#XSC1oI zFeCsz38DrajM%-6D4Il4gg|{uhq=0|>$aXS8~}hMz*L@Djzso>l`qS;X`D1Wa#8dv zB!|vp+fOc@AmY8Ep$T;4>PCA74O!le)S{j1dUUn(zUn{^Edad6lhNZftUQ2xl=6pT z-Qj}UY7J`OI~^197GyEGqNAQDvCCpD^ENfH$4Qw}jmAV@6(Cz>?F0GVe@WHQ|MPt4 zv>MBjj(qlUbnzfGYw(RebMpE!gtTz`#1`#Vd2RlO)Ap7WA$sQ3$U(gkA=hkGqKI>2l125t5l=h{%}jk(c5LoBmQXlbb2$D1U?^5^UJ++JPQOP(pFI5zIk*-yMCp)y zkNsQ{zdp@Ozy{0~sY%H8gd&I?y^Sy+sbj1^AyXCJVMZg^sjsD`dnK=>w5?^FWJ}(x zM~Td}x-*aFPMl*w5362%Q4uu$vSmv{iYh3^qhqCPZf_jPk&OtbHHkz(H;7POOg%CT zY~J-UY)eerI=QGlVEes2^*&?roi`5>ANigcId%m6D&!r{vnIcAdW$*Yc0F3P62DCi zBQ|%x$NX7A-NiBBk`plSd2~(AuN(|AGsoP19%u}0pn~3*Gj`Ev#nHy#&kK49m`L=6 zrb!bHtm+y%dd!x36xrslMC(2kMjEhq=7+l!_TRFBW~jYtRaq>1qJdEQ`B6;MI}OeN zshA^IJB{9`9Ch67(^C{c^q{Y((P;Fk`8-EQGkCdL`(36qzk+1{%Jq{ipSexQU5B-T zPatiy*r#eHKCj9?i2&^w^d*Ic7b9i{%TCZ4P9nJ??6w4gMoT-*2XC@)O!`w!sYcFd zavMfr1^nDpPAmnvqqMGwdqs?zn^{?~7r!|7HYCK%h+jkDN2}qL81RVJmY0AcgI_I? zr!OLZu=2V;Q)Agsq&tJcAqA#NJcQGZ4%i{X3e@D~Lat*V=b;x^K-7Vke+%Q-k> zg4rt5y+RpA_$b-af_CItAm+Muo=^y~u76!uCa`-y-ssnK_3_^`l^1_lv!V!d(zvw;2T^q%7g3j$#m*lyEYQOb(|Ak5pVsTP^ zm{d;)Wi{XQxN#da^IrjqD)0&7E1==WR9H+A=~6Q+v_}l_r3!mWJCE#1*Wlj*sHDaz zcg)s=$ngwt@`H1v;mFoII^v1nBep{fi9)wWhiW!Td2{&UG$=z2Gw1mdzXT$yfsO{7 z=}Fu?WmQ5TM`|-44hIu1X*6LVxAGAfGbU zuzGCE-#s8RJVu#9RSB9W9c;!hJD@)*r?)X(cP~EJml66bv8;WU@o-G;H$9a zKz*31M^#lbTKrs0CVJL$HOh2Ke5lg?X9Yl5`E`Bnno~hM=K2Te4xn#yZ`C4@U#PDS zZ#P^!Smr>>T}j7~wf|)BHy>D4z<9&g%QVV_KgEUb_H23K@qVYQ9HW=~3}d0ed6gFx zMdGJuxAJBhDEkjRtjdaG&dJDVS_u`PO+_7H89GSW=FCx}ea^?D76qho8zB%)Micd- zVBD)lRAgip-zYcCy6xvTX=9p`8lH6TrAHId@^pDi{S(Y(Kx~3AM1yYyk)!ZQT!>r#&L=9O(hUQJF=7;!m$w54yRlCy37iV&iPDX?z~p z?s0~uFT(CEAfqTA+CjMjRK-BVrzg?q80Fy0M{eG_rC3~BQzKY>YP1ctuWEX$5CG~< z*Ml{i^^?T#ZpGokyA^1^DQhCVs`c1_owc{{c}BLMDHlW)fp<`9fMAxZd}Z0+>p!}LM~ z5a%DyOOp5ton>&UB!So3$S4jQ{VHTzr}Gv&J3D}a>$cX9Kg(R-8g*iKqPl4hfx-QN zw`mV@NkEaq#zdvkqeEWF(RPM3mf=#-2K~irZ}FUgvYow$3-wY(zZNw{CfX^@;`};g zj#VPS_8bS++LGy^jq^F`!Y1;kU|G>(#Id2wy5TfH^ci9!^s{NyrOYd@#p}5aUlzIh zPTBs|k4y3==ncY&x(R^`zp_=QbLp{N7A9tsySVi$FN!Bd?K~X+{z#|IZh)h?qnfl= z4tn{VV}xdvRAID2y|MV|8{v6c96gJTxwkVGIrm8q4kU)s5vx3 zm^7v2+0Yl3Za_nDJY z2@zAYT8f|k+P~#bCl1Zmm)A^++y8>g`&Pfl#BJmP~9%HYSrleUq8p@E&ZZpia^DAv{rOXiKge^WL zY4r++Qi7-zBclBxoO@+?{es(o)iD!HpY>w(GwEVz2w9n4bimq0~ad>B5gw6-i>V3Wf4Dd4?NlniJOwyE-i(6ayeNv)$jg9vfca zb!(&uCOjUj-Z5PK1K&Vn;XL>1$AyostHEzeY%->mg>d?@uavE64b-k)!FWPCTqX4Lds6KCwqeG%oToul$k>qJ?P z5%Z^3&BLeRlr7whp`X;3r$=Iu@}0?lx}UQ z`il-y-o2D_L+qLq*_iM-<6%j3k#J~YeG1>&;xQ;`oD6=fw*ivRt;KFbxGa1}A8Hc1 zKIZ8YDxU5B>&J@BeXhTueW38cx=NDglleo^0s(Cc7JX8csd z#U{5FWvXur85)JR631Y@;DlAyL5BjrOO__a_MU{V0 z9vqqovHW?cNL<8duW}i8I)&6WGj@ro=|+)`{UEa{HtqQkP+)N<=U8`3L9*eON=}43 zwK6A;OMV6B)%vkqBSDz7d;N&Of@IPO%&rqEIp}X=Q)3Yy-X&V_gr++6Od09}eDPST z^<9ty9SRh>op-g@Zv)mWaD8!*=QekP15Bw@6Ub&(C>1)S7l4@V=; zy#y_97ymh7;cTQL-;)a`carkm1L|gI`Z`5n+Yrcw?&oaWq3ySS^lET{um6^Gs~eZa zZc&<`kU5cZG9g8hG`xpTb5ChdtGqbfuwk^HhwX7aZuHF-xx=G4ubUzh)`4HFzm&^p z`ypjeg*on!NyU&V@4D2pKTLvOLfUK&6sC{%p!Y0@PR)7fa*`Bhg>ee<$dtBReE8zT z%5`tIEn+I|-QecmYK{xr-O!ilZu|&;BBBy^#<2qa0j@K{8pxHCr5Xn(#{X))vL6O$Pr{2pe zu+wLOCz`b>&TC!9d!8$y*w2&h6;rTy*TXLiYw~p5=qk!;lo$%=D2(ae!Aqn-UZll1 zH6v^JB>N(jE7~`Z+g)sAC{o}^iFLYoxo_Xp4}$9K^ZAjE1wCQpKH-m* zd7veK$Tdi}cm)e3xE0(Tf3QxxTXZ%8+SWTi1De+N9EF)X?R~Aj2swez`Bj@27*g*L zHz!hHA;|Rjr(ekQQ@Vej48CdDwKQ@Eak&g9KWm=Fl-3NKWvX;XRq`hrfZQDqx#;=*HUw;>RvrhO z;~>&k-Z}M(O0jVc0BHuu**5EF8X`jpoce<$3hGltVp@&Ua2e;Nf&(l6JR8!U{ML zk4l-bLGz=9R)B1)lc&R|f9CYn*o}X#?-Pm#`NuXh;!81<3yyr+R?WY7Jf~D@`Z#;4 z187TXk9>RJF9L8=YDNyJAC^zzyxEv3wPDu7-yHD3GrWFYEYzP&k|PT3ieGkJF99+Nk_-{SoS3pAk5e z?G~yRmK?Y%P|R+44pA^2d=vyc?px%78wLJkt0R@DKbiA1+ZsL`!GruaOvhTC$6YtS z0NS!{Aw?s#N^KPDOsb3N+S&ah7;s%2L=+c?_TYZec$)&oQ0oMw8fX643}*(^cW-ne z1E_!Z2}aa#IOT*^90r(17hhpp?oW>azggLLHo!##9T9V$BDF7Y`Vkt!b{N12EqWYM z`gQF*#}B+K#K_x)^vK5WTCTp;iNsU?T5iT(VC(@IYMX6WLeDp?0CAjq@OyMVuuX*$ zI)yuw;Qw2h?s2nxQcFD;{C6_pyMs<9{g&*FpCr}E*8nk6scnX+Pi`RZ@H|1kL4ASO zInwu#der8ENaAKmz6VqLjdp(hSBG3sGvMMM0#cI}`yy>5}el zhOYV6J`CRX`|sYL!#R7ez4BSl+J`t+O~rR<_Xs*T^@IN%-2PbksfFm1w5bT!XloBc z(6cjQ@c{a9iq|5WFoCRQRsFBk?D0k>$t#SLwLquZkiK!MBjM4?62SfgUO1F$?Yvb0 zlnHgZAeh}oedDCR6M4$1&Z-)LppkC<+S!si*?HMK_zH`%gcp`yhxg}nEtuvZY}dVA zQ>we)U~SbFl?uh}C+$2fn=>agdG>55MLB}&Fr{D?K|4H4_(8F}Lr4Ew-pJFV!QJl= zQiZvtfGMbS;vg%lCPG6JaK2i&>@8GQPyW`g@k_%@yLWIHzL$z<&dSL6V=6B$#1h4v zD)>Zh$-&q-swpL*PERoj0hB_t&q+tfDJ2t63$rK+R|3I&8%5(5Fcmemzd&i3H5~PW zmRW9FKJgZN=`h^X13Cox7K@@f!Ku~=PboQ^5lzv){+9!ZO0;@z3p&SN3cO^%7mRBd`t!J)8VfrAl1{h{kn$-unJE5TzoS=MyP`ZBsd7x}d_v=| zHh0mnLfzx9qvq}PFCM4{1Bcem_w6T84}yFzpnl$=8A^oaM(hGl3(NUhz!&(OBIyV?sJD;GI z%aXFwgVK#x-gMLp27jch62Ug?Qgjc~-ur)`nW@PwZi>bhQ03X+9m62X_Z>w0jEZAA z4cM7rmEaD>z@&E39N{n07cmKk+|rEd{s@N27;SB7cIR#sTr*~x+kEFKfR%v!sNy64 z3en;`h7R!=2+c6!Uu!al3Pn6?bv&QS!mj%OD3%jKP}|8jU$VUZvIMF(#$zJTuMjgm zSWqow@KQFFBT5mV=hx{x4p38gXw)qBmd6#oAvC+^p8L}Xu^ZZ5dbvK$g7eFEkV+Po zo{YOOt zJcXZoah25QLZr)=oloyj8i|gFQHMAev?KGNq8MhGSE8Y7ikPZ#=ebb$L*9D!-chLk zP$J&46+KBfN9Lt$629V6jg)H-JiXZ|SKU^sCvyGt?9j}g?T_=SO)o>yWqeCrUJi?A$ZiZ)s zQu_@PbI~UNi{Wxk>skdEjL|3oa|7TGl>NBQd47A%1j(_xD~fE|5E@X2)N#NE`a8^m zz3T5-vFKo!!@t2bdiR&6A(&?g?lkSu!_lI_JszjCPIxlj27{U3<@3Yi-jB%FQjeZs zL>0zkMq51%ei&;MPux2TsmYC8ljd1y61O;IXC7qx4H>E937{XS%G-ux1f2Uh3Q*2g zLP+J7=R#>Pv_z~PSR}yQ`*#sPKfmc`8W#lCUGbQ2?=Bu)6c|EveV4bko4k}2tCSFU zJARH|su>Ra&(3?_Bht$ebB4!XnSIENN|ryUJIrU;N{+ax6qvJi_=Ws4?eU%jE#N|w z$K6rmU>s_^YiT(JlzU(@Eu}KtK!OtfCp^xWbxZ_$OYS$PrFe9;f$VSlIc+X1y3SKV z%wlw%&kWNjik~|s<{fiw3T&7i26?d+c(sjp1VWw)VvfPx2|7-`%YQo4~ zTV;7P-o#;s%Q*}Q9x}9;{R&u%x;SOYAPP)A3l=E0lIp_>=^Te#rs;ud~dlq3Q;7%XM=dk3-@>iP3{}8>|TE*0hhxA z$G}8Ry3T#ww2?US=)%$Bt5XPCcjY$Oezhv9b860ZrVDj0_+vWY5Eu&Nrbr zub-H&{R}ydAj_D@YgPv9g$uP;#8k(PIB4XMiVPM!za}T->r%F%(oY#Hr6H^}Be^hB8yDt1C=?kz~` z?=nwq3}|>8f={-!wFQe6;p#bVOoVJCMPsSsG*1r$r(w;=Y)$1So;xc@{M$F!2?=l3 zxh0SMA}i-nvctH?_UtfWmP8KAnMb6C=IHYpON~~p=Iqe!q>Ns{$6+=n5-S_2jtUMw zhQ9-*Pdt|-Lp<=O$tuZSJ-sMI=}fCn<7BfrnzbpG~T zA|Lv-oB8lMCDOO(i(2r_%(u`9I zx~pzb9T<)~>*ms+bZWi$@Fu!!rRF+e(+W&l(4Ak=bWy#O$T^mAYSn7REhcP`9&-dU3zhLWcV8%BQG4h{TNEleZ)KdRO}LNdnijx60*&p zP^~({2iJKCj_nE*Uc#35rW1TcEUR>*fSIaDLJP>fbBrhxL(M=u{+Vir0`3t2rr-d$ zIaOmIx1WNF(~5IX2kNTnx1+9_qZ2xYt2uUl-S5^iZGkZX?cY$7jt>#AufRC#e1aWV z5Xszv9y`^`=eWQ>5@u?hQ#Dgiu?e6^S=>3zAvshYITk2Hu&*xlo0xC8-DwtSj}!oy zvMs`C`Zf{7IbgE{D=N+G!z&UKqo~-=UqlC)dM-r=1~9qy|C?dHwn{=3pf>UEDY_Bc zm0y-XG=!)u4PA24g}^$AYRy)jfsEWA!sWJvmPRpppu9ShKfhAl~^x#V%=a zcB5~dRkgu`d1MZ1bRdvzL6t4e9}WiMh^5;Z-hM-n*p zQrJ5x(R7UdPK9osXhDi}q4_^WniRvo?@okcZCcGm2enPRClym1v4ZU+fMt+1kDOPy z)+R>4YUUjFA<(Jty!LW<$luWmq9gmKh5 z+csz;Dq4SOBe>#+y$3vJZk`d(n@8ZwwDC7r?AicJ`&m;>&gWsQaOS1r zSO|UkuF^e``C$SZX^WFd^nMcKe1&m3UQC< z-Ij2)H7mM^ccAX^52^!tYk^FHqQa$uaEJAAq|~eb`HzBk;gP0LoeX!KMj_k9S`dVA zwODED3Vvwj^qKOBJP1|JPWW_}?=-&lf~Tlhjn`RU0;>}XO&oCr-!I>YreD1$2}qIG7<~(^P*yx#j&YVpuD@)7?ig-;A+05 z7%_rCOi_#x7@ZLL4~tk>(~)IH)XfoSMj&NW~(0+Y3ONJRzIo z>6=+r(@2ejnnCMok$(I40Z#y-c+4g;p0P+ALuH0-+6bam(n3pr8?kGeid6>UsO*aD z5OiJUm>#)TZ-9QIK41$N($C|xQjDPRs6^%j&a{%r!`+QXohkXka%o5>jyi{Iv{3cj>A*#AEvh`T+3LKABc zv0woP3j_O6;iEL+q9VBs!+Pg*zV0dz=Y_`abHX2bJcIsISrrEYF>IKMgYEXyv0RU)u z-_>v00Q22-5L$_ajt~5(!VR~xA3AztY@28C;Bik-hYsQ9p$vFr#QvW&_mkv^H?~o; zpL=5f2zG2EVSWRvl#QK&9Mk~~3U2wJPz-evz@am*zqr%}?A|eLPXk&FV*gdL z@sx{iMj@fP9Q#ZX7>O9EuL1x)lm@F3iZP`Cc5WL#s0744V#r=_Zh>p>yyuON?w+<6 z-pe@TJZv~jGxHWHSv~@CE7tu(E=CxF7U4_ z_&K~e1vxD;{;SY~AyDjiXqvmE+1>BB)Qqz!gC`&p9&#}AfEOFWHXs3KW(t16js>Ml zIFUo3f>_ln#=YTz&l^IhMR4<)_J8sET)KyMcePW_4aefBy)ujwT;Eyhp+ugh;iXty ziO~$9dkrKon%#S_{S}xzrXvwZM_TRrgm7&F@JXYy-R1dsh6BBPquiJ5!vUKTCv4rX zL`)o{Iwh0?&V^ue_B__>nePQ7Yh+havx zL5x-`uH7RToi+C2s7)w@r^ z&DdYE_zt~ziT#;OCxa$sT>Je^G}?eg#WyX`-(ykN0#?GhFMcZM`cl>k^5lrcul3Xp zIZw8s5cxB5C(pXUTxs{9umSuc|8pzvfpi9H7O|xNKXmkO45y3Gj2xi+^5i?5tJ!^K zvi9LiAOz>ENiS?s0-ZW2LyJBbJ%(<^z|ffX-*6s#Ia8DpbW_BRb+U@W#JLs9Bs#tY zEVpIh=TNW~z}c5z`jNJ-A1sLKlIp;RMduUrLPadssE70z?h_U3Azg>MVew+vC9K+z znjELJPY%UW+9&QQ>rrx;CmJR9(CdS6vcDGy9i?!%#=57RY$H*hBJ@NKKo(H3h)?Ee zuUZ=;>O+%B6y$63dSL@!pbG2B1tAC@vg$ueat2lL~Mp~#WZz2(bz#N|OviE;^yfn_{8>OXrvq2fE z+C0=<{~kl>d@TiXKywlLz)%ueSmnxrp+b6me|{d-Fo9p~xv?bh{5jc;x%ZE$s0M_j z#hUY<4OLL#@Le;&`YM}5hT3_HSQh8HV)iyO7BkuN1_D4^HJe{h5JRE zO%tW^OilPZQ=yoGU|2{wRyR>#*n*2OB;cgswj>3vr;e-wGJmVCK~&EYbQ5Mv_oL8okEZV!ZadZqjVXSX<+!IuFfx5 zdUB1Kg6f!DGyU7E6V(C*`jR*PcUE%C?Z>(G2Rzee@Lq80Xf$Z1(sTNS8iraFA{?Ni zOrnVIe=1CI+(qQT&;?7Un-HT-uS2^$E@;~j9U1<5_|+NTyeSM6!m+iBD@+}kgA4-> zu|t*daXOJXn(7qio?lRm-uD={aG4%yTzfUoUbtSd4li>AHx z4Ky>!Bt4o^MEdSV(V@37AtoVVy@7@M&YZc>JRx42Ou z^o#q{Gnjdj$d$O|H=&NkYGA=uoH|L6`_JA_9RbceO653lV32@QadF%Q8wNjSrSCqf5+CL+*dajy}w#?5g8e6{P!uk%{v z;@VgTuRRRn7J}hi4*zXvY;h}miy%QR#@m$Xz1X2R6ymTn8Q(EmuBJzW!@oe1k#?of*XGkI}RM%k9CDh%1cLhC&n;)QwedlKF<8_B-f_SUFc-EPOu?V3)Q233+fw< z22T8Fs@*b{%DM@&VPfNWF90(MK5BV|8*K~UPjIb;Fq~;y%U=(^xxf;W1SiMU50o`( zjohkVhi9#>P@0~$3V)HX0={+S!k)yF2)g?Jkf?$dR!o50AM62e0LbmvvCe2?m!6+PPevYnY16snh zA0*ysrsCwlEjO=Q_bdFO=|hCTD%V1!u3czVMs|irgEv z(o*E^l7vd#o0->j@c+quZC&n1YAFhSK4U|{8@#)r9XNaz3*nd#zyZw%DGSGI%9I+< ztEVwgwPCaDf*CduC>1}fd0J-(uygR24D0TJv-2w@3E?^zKTPpV53W)=e_8P;1HmX! zxT;;q!*X%F`2eUd@|!m^qBjU7&k#=yjd2lcH#m>DLE`OZDy}m)+2r*stL$-C7fL>@ z9_#^kcv;pPva~Jj57uHc9NVRTh$lsB|e;1w+i3GMY+-|;hy; zQFJm2To~tVi`#B*togw)`Eqvlu-$lXb9=>;9w?=S#rF0fQ2&8&j*!DWEOR@T{#TO~ zacs@O;yh<`9H**fc?=A6f#a|yD7mV)%dj$UVXoycEmJ=O?c_RNF6m`PGz9(xM2YE$ zp=A4t2}mQ?k7_Tb23OcBY9o0L9oBPR8X^=~t3G1rsq^RO$y=E&!sqvW8bhT6jxFz#O8ufz2)FScpc$bx_SF^J#mI)N9O2a|S&QN_f zYnBB#Kf>`N|B^npxIt55o{C$lX>RUSvf;=Nk91WP74pHuNule7CNZK&ZG(8z@fd6m z5%JvrLoRT4{+^EnPBGSHCk<<>x^P=ErYVIFlU z7I7d@k3b#wd_87!oo&k`-F3`*^T%G;c5d|5*qHON1QZ~|R4~05v9vcc|B2E3+&b6S zU6tOE_dX!HP_X@eu+(aISE2LS1SrAL9Z^~a+9>d2O&xqEK%1cTF;9r7XN6#-O`R9l z1FopRt5>$4i=CoqrJWOVgO!YbLYRZ3jaXEy28qJktOVE`x&Q?py}$w<5*>d3lhP!OxkUKH>ikVMIG}ooi8yO zq@#=|6@zAzmc4d8B%LS$Z+N0ZDegMZm7st>LW{;?-`~R$!YMvil8Wl#&r(UaC7!un zJ0{Ixjus)TBX22ZeI^3pjGny(OZw&lppPKWASANgbvbT##h_}isCT7xI1sYKxTG25 zA(Z0nDo(Es(S5zse9)otovqA3A)+UA|A`{4fnJ z2=h{$B5srB?XfKUVw#ak`Swc!p_5lY7O;Ubv0fDL@fHM>R@rMb!fV9(D=G+sYCno&dyNIQ z3&+#^{l&QSZG4ZsDGvKC(tfYw^P$6}ydG521AycsSQ@n^OP(k9r<2>rBIV8GWipAJ zBk4-H)~*eAdm3{{5}Tc7zPu?tqNDbYtp0D_H^NQnb&;Xq*YwxDj)B%RxsN;}&AES` zJV~C)H`+>RBbnpgU%~cr$*mw>FG2t8mW*sx(0eYJ}>M z0Es2-S|}6Qj$A^P^UokhO0Ni`LS@yOLwHjG^}2&TMg4Hjl)-zdS?v7V5=*#Hadzv- zseI@q0_&IDUra#Ar~@7Dst|Ux?B`UKLK)v@^JVQm*lU>sDAXC9GFcHX@1k&O-Fkg-^(zTFm}C*PHmswwniW~R+jz9oo`HVIDlgd!DM^n zc=W&jiXHE{j#?e*d%LRZ=-{d@-12${eg8$B9Qyj|1+`v*UXG4vP-8eqE$2Tf!m5vzAn3mjXx1CQ!; zG<#dZcNt)wxfbU?h48`jjhE3~6ckj8)X$Og*fuTF4v*AhTqW;00~~|7b<;TVeAr$^ zq9Vj)YQ|W~s&8&ge+}kd;fesvx6|ElS%1MX*o8>@aZh}Hxx1tU`~Wq@Af2K=r^@7_ z8mUhor%MOFC_e5PC`{s`Rf0=oM-?y?Kd`5sJ+yA{Q;6uEwadw z3kGhC)S0IzFu+0pw{5iglNg)6%~)VJpTU8jc`}Ud*QOR`YIAy^w!z&#i^?FtWDXWv z_M)EaV#c0zT#*+uUk-g6H5o?z%k~0lTO89)$n4`Qet=ubn}32yg)y3JE1Qg{0vQA|3q5bU8={BlC{&2?0% z{lCBG$33;{zZy&gBXgQNHN|u-!t<84gbhIB;Muq5Z$jctLWG}p^zMjuQCafX4FfMY zy4rHI2JYK@tq5{J+SVm}yokyT<0?U#p~hPhHjJPieVKDuj^8m*) zmj;v%*6?LvPu~7+{mCa4eL7s7_ypBtjdK#joPDCu zUMr!!9xzm&m|q2~P0=X7cX(;H6u9NUHGJi~vaeaXN1c`wJ4h zeruNmRJv1@294Zo%uj8w9kqAf^pYs$n7w0kFy5(RwDi^mXJYknYIcsQ^fS6E-62lH z&pmGGESry!N4de5z07=|F(EQ*bg<<{{bVFlZyd7}QRWym`{_X-ZRtr&o?}R{d}T7y z!1K(VWQjit8d^0J;n^O4S6pl)gx_iUVbx(G^9gG9GatyiXbDpu__{DU;q-@NOLwi# zGL5Ul#~g9N{qZ`vJ$0Yd>}8|6l%#*Q$mqQ#@*SaO<8&+Ujv(e`^t=&s=_ww0M3a|c z!OYYRrP(H&FSdsXqha)tLsdNMFS)%x(|Pfg%W~eIv^Yh$!=lZuo0S?&6Y3s)L zcFW=F(_qSIBitYKh`fB%?0f|VHvPX3XWJ1h8+B}XOXP>)Jqv|QdGCXMXW!IAU!rJH zV9M3GWZ!CSpyax1={eC-gPL8?)a39P=R|zR;rX`t{0C9jJ^Sn7!lxtjD|gM$6Ha)16x+-5QMU2oijvKXl2 zo9g@#IiBl9emN|w+3X^3VP{F{tOP=fhiq3Ca0@Ww{F&_kAJSynUKm`Zk4fQ6b?qm z!+F(h?tPAx!+hqGmi8vCzQeI!(}MoE&L@`SIn5lVWpr4IyudTg(A-fM_NWkFu$7~u zP<1HK|Fnw&p3e2l(p-E_-eP3vF2a(`TDe6b(k(8@lyCp$D~*aRTluPgHTC`ThADqB z-&J@)Uh$gSw%z~Gn_5Zc*^aX7(XF}8w&|vgJI+tR#w6{=OxCt1s$=5g7HaU1vZj44 zp?C7Y%olFu>JGnXvx(7_#l=EzjWYwGhhms9=}FvP zU7f0F!UwHc`d<8MWF|f}na{MEkb7a-I%kt9+cJ&r>bG|ttuCX9!*+>AW|Emb0|T^r zd18SCgV@)YG=5PMQn z!Y)GoQoT*1%fwjja$R4Aoq6R8&1Nyw!`139%Z=O~$&^~j?%ug>54#u{)+euCJCyRRHG;>#}5?tZ9 zqV?3(Kndr+cd$=adL z$jy`UF?w2tW=@6!U>Bqb@7u}poNSLJV`&(=|yrpri}gY+?exUMS|aZeYA!Adl^}mHyOJo`n6GZi7@9+SsNFm!n+wA549jw}EnKN%!NK6EEY~FQ@d&_@b$IL{yZIcFUBzO0e9l9+97pT{Ng9*_%SM0s&W5r3D2S4kjPiIFRW zcVRls5@Xdhv0vem{YuLeSwg@1F#Caq$>` z@@M2)PDmVo8@fB!zGd=4J#A)`%i*mgyzBmTg+KiD{DczOENYu4SZ45(O>QC~bP~sZ zUO;}H^LT;0_QLWH<-LsH`NU*5?fU;C#0IR#2!gf`9MG_$i+EmHr`y1q-wAn=-6FuX#EdvPt)2XjeMb%)nS?t zlaW#eLXM4)^v)$8%!6>cwU0wRSAUxj4dyX%)RCD6hnvb3vKXxB$&S`@#2nXTvL~tM z0~7WJmccuXO~jaYYo9OLpCgO%T1osJq8O&&n*)M$_gGq_WSW?>sKd~2V_2_sPw{|_PB$y3swX7$lps^Q?j!|5G$gq8VM zi$|+v*H@tm24{>8YiLzfPkOBote@l~UDe1aI(>DP+QZ|9TxAFk1`r)KF%laNsw zArH(l1g_XNW_uz}&2)4MlN#G8_|ur;Srs$U#8r(8`IY>u1qN0|os(@Pj4>hGqZp4k zNJ$HJV}{CJ1rc)bjf$sw@=_G?!V*=qrcyLpcbkh(SQB z>PgJ?!ir>j(3_P#+Z8ayWG`?Jb;+6SePbdeT@PM4lzrh*`53tA1SayG+2>bMM@D}w zith8nREXoYcVPCzS-MDq_O<>sgQoWSzBNV%&-K5)vc*T!WD zE)fBxO12R8r#qzzh-j0;TJKEYnAj7vD`w2tl}}n_Gv?@7O%3LQnpCd!L^ku!oDXTFS%`*n#&kaH-SF?a%oWWSm$99( zel=e0>W(tmEnN=*yP|Lj_iC}eY9eOfax_>CWKn|B+UK!skT`jYddo>gh}d{1LqkFL z{IMT}3A^aayq9na8RWRg=t$XU$O^=z_5R=Qvn%qnuXRQu+atY}DyRV$l>&cRPj!#7 zJJ0tb*zTAEtCnjCF~t)qE~^W)BsZx7D@+bY;TFawB1wg9H##@Y69sHGmHv|Tqb|_{ zTWNcToZSvCEKM<~d%jZz$HFab^myITFq;aYG*ZwubQpqone`%$lLYR4Sk4Q}#FN>! zVUJ@k_u9AEr<^t zejyxMzJC!HGX>rs{w$u614U@0GgZb|b_vd`pO5lnhh?NEj3qRhx$N!EX^zq1jzgc) zi3!%!d?!lAt!ZN9mQ}&i|4d%MJ(!;Dk&b2L+IZTau`sqy)&jPTr^zkD+DR9F|gOEZ=%bDsPvH!5ZKH6XFW>h3ZGTZbJ?om*R-MoWjcTSIsph}S8n{cs4g zEEdzP=r|#X2uLJ1B!>1bI=Rs$+ZhpNpUTbF$l?bKufJM%azanq26n60&PIW^emgL+ z$^1`niJcm)KjiFUkU6^klj@5}h~>k?HQh|iQnJ?C^_BWdo!kQNR95Y*w`Qv!2@R@H z`k00^l$$9xG*nuL!CTkX~)+d zqDQ^J9u+yZ$vh1`sxn9wivV8DvcxV^s2xhy?1xMR71kfs%-DG-13fB{#6(`b>v}rX zld@6I)e=I!W_e8qvRWFIU#M*3X07k_{ROf6i@{JR@?Gec z^v6V;ktZk|fC{vt^0VK%fn67)-Xa`>>cxPM`C#G5H3vyv{32|!Yik4^O!`;F6JT@KZu7alK-ZKwDN%} zS?7*n)c}{4G^Hvvab0`IQrU|hQaSpH#~}Z7f~zqsBL5D{)vH$pBKi3Fy@@wJ1RJI@ zmmThJh_JtU?V6zb5e9~Gg>+4(NPGGtA{kH#49mW-qs10@gM2h-!CFu>AO4Ao ziiTvmdikf}T+!jhiQVwkJbr%u#Xg=qbPp4c>C<=b-r2swYi2$Ssb9L~e!$aKRDlULwlHEkCb(uzUWOZm2PP!v?uA5m9AEr>NMXw8wWlW!7neZG?~00k zwZY>>Eb#G(TusSW$}UhpmY*aRm{9ZZLgK4k{(IeJqrdF+114E}QFU41hqoAjh>i}z}`3via!)v30}UvN~oIU!Lw({5uN<3S!& zoEps0A7c9D`r*NXc0;Y5=h{cd6D~b7o}?FPPcUmEe5jP*opu)FC%1jd|4EvmV-Ib$ zf~y(z^&PT{(t?75eka)a!}YOrI>KUN&9NZr-iR~sDa3LiP`Gk=yO8tu;bY%TA8y$h zeJ_J8F&fq%Wv(`k`o~AU$$CjvjNIRGseMo(CO2qiuT8(aYRy0mwY5#)>e=W|UKL++ zd_)v8n(Wa&7&RJywzxzsKeUza@Xl%5VdI)Nw5)gcqS)-h_tw~irZ`geH;rg^9gl8I!Y8Qo3GT z(Z3(>W9EYsBIZS#@}50g6C2JT#5tr{E+1L3&2wfVx33tVV1^kN(H=Nw*$09c719# zg7hL(FZC%aW`(qUa!b2>EAcQcadO9 z74uk{Zl{LglLpgc=o4RZWDbS?iX%ZO7Bf%-Y6Y;QSp}d!sNf+il|td6d+nDrL?Z_; z*9(25TMu5AeE)v_rj~%`CqD23Ih+JSp-wDl)<@^N@3!cK58jVcSy#KnG%x* zwR~ScONq%zalBtCsVJD4N%ZEj4Gp9^IW#<7qv1;{FviTIqtPv$MdDI-GXM42ULb)@ zA^6^+kyj2|ok}L1+7($outU?gy%8hkO9NIT5b$!43$C_-ir3naPH|nRFvU9BW1=Wk zkMeKU)n{dq8IR9B8b9Fab@#2ViF%f=U4#dzh7J!tOZb(V)cK}6sd=hd7quoVHx~s| zKIBjcR(p|hg{*nn>SKDuTaggEpMgHMZa;%9oTk9c}Xy zyZ9-{!S+L$vN6l6n={AERReZ;?PIXwlp@|5hHORM^E0G5LXqiRSVl^4(MJ`V;u@eg zeMgr({FE#OIT$gI@{V z(4j-q9eSr}qNfkkguaUB8NOWc@CL~BteDu%%`C@;KFTkZCOM8~X1x0)H^Du%|JAUB zx#)FIx7Un&=}vzAM4ApX@*Jnla%XhEQYIW$BFA>0J!a`U{mh??<=C=p^}8qal5d$o zXy5B`Ke-bg4rv@J!eLZg@t8NPxv87@tOnJxR7pP zpN}MuW9YBQ>kR4iU-%0nuDmLbDg9`u{FuAO)savo8Lnc|o>52Bw#@3ikBiMK5AP5a zX_Zi8XKG_3knr$Sr0UpYziWBJH-M|tcS);CenzgT|FqCsO8!BsohNpyyg1Sk)rTSY zN6sG=!tKE?5#PVQl>CqU+4FVTVm?3I#}x+C21Byrx~$4VvOB!Sofl(cdi=a6@=AmEGM0X94DqQH zW=LO@HOwmGk@vCIJiYeG^lkh{r-5LN^g229vRwJB{FPww*vFU5#~V#uFkGAu!A5~G z#N+3vc?cHZYz67C3_Nr3;ZJr)$&9e~0RaKQ!Q9MSyRj-#xF$M zoGst#k>cWdr>I6IaQ-vDoRb2LJUMQkWEp!%nsMHCW4={kor;edZMPitNq*DqHW?}J z!!HnvX0!%`Z8BcyCC^S_%C4GS$zXcs4i&{33rJ+^*Z>dmTy>j+c^<>`i@7@Sh1)hZ zDdB*;-MxDPzp6Hr>+ovCuQ|4tgX@?xuaJ=XiGx{c>;x9WTUs-*HBNy=m*AVv17nWE zF1aY99ipG!sUv?{cHYt{KPJdxN!IlOv7*xGU%QN?LErwycm=ypCBn=@tJmUvUNOq+ zef284As3lq#P#diN5xaBylgCo(v?8Rl_tV#u zzV`6wTb9!God0fU`*m&<2*mGf3G-n3yURQc816LSh-!2^sd$i$8^4A|vJE$b#nO zm(Sf35_z0TzY7hZ?5SBfg#z3@ZW8okVg~A=M<^WH{NF3KaHLOszb$x>JoYJ@^h3gw z&D-0%-1DxZqZm*1S#VE@j=IoVR3b&09l(mM(>ACncCAR-s@GqF50(Vip^!d_5Z0V^ zKi&sqOI0#K84!zRXA3%F*lB>D_p~uYGR9r*4h7hRz5h<_5jwgDu6xlnQZLk(5U?-X z0HD_csq9_rEikriX47STCX5K_MO_a|hd)<~6X=c}EhW^-V{MZt1kCv9QJj_)2>JeowQF9+f;i0-@QA+Ni_j-kgO&OiWMbJZh!mpLG$S1Ig$EzY+JGfZw1t ziR+g*amsrTK=P~$bP6EMJ!PqRjy*t9*|(O~ngv*FQj6$FU!RB2xqK2n0%TIJl)P4OP9W zPaXk-Bqm&@KFa_tX?Oxk{X@KHjAA-=aYNS@Gt zs0`cZYs;c=$(6QbHngSqr8oXSaJhqQE4V!$aCnK69Xu6!L~^GB2E^R%6D|qXeqo!Z z@L+*{xfn`!4bKE1Fa%~NR$#6|&9ZI2z1`#=SBRbxCpr#;dkEkRh6-0fJH2_vT`I#H zGNPeqZ$Kt;Qr?%AmKr46lsXu1FE=nwU!3sBP#B^PU@`xGz!N%y>YfQujhc)Xi(w}s z^`kzxdnzWZV_@%M-u1J)y>foo##|!|J`vYC6J{rYN`+*t3D!3#V@XbF$w}F3XPg?U zFP(`{u&I;8(CgG(%G#)P7tObTKxlXjFCSmE_RzYGLm_J*4LOSgM@Ic;>DE~BCgb1< zlgy_Ttse4X-Ufk}b#<fHUxURZ;XcKOHwUtt{j1&)vwVQ92>G^a82SiC@-Kmxf#(;%s0c_c4dJLJA}I16gzJoSh}|TO*oX z@7xI!)#eiw^%u^~vrK-k$im}N|KrCGw6z%4Rj2B7;jZ1~Tg&B>jQ0JAK4YjhZ=&XO zreQ=A+~np&&Rc+3KGa{<2=~Uf zhdlHpilLf+Y(-rlJ;rNyTh2|LHf1{wtwN9Cl>SOfwe)z=!W7cVyas%|!?a5KeELlB zjLAIvpJk0S1CYm){e+4VO}+K>JtO+)f~tem+SVXxLSB=@5)uY!;skys0#0`2JTbG# z>QI(l#+Mx1l2WdKV^#iKRZ-zbW<+u?Cu=1(|I%8_y*U;_m#lYLLbWEbOkt?XVI;&a z%e(%hkLF9oTD@zmT4Oq6t6>`Adg`vX8gF>Lc=4h?0;&TmFJr#^)-b_)QN8*3DRnyX z4HlnX3KHJLgEma2SHcYA}6a%;`wy34Hc<|7$Dxzx(IRr({v%3ysOA}h$^88sNm&sG2SH{oe0Oc zD?Q$sHe2bFwr$eje4Mt%l3-ti?`m1Y=ruvx;p#p3vVxK_O(NsV+YM7yXK4}rQtl4*uEnE3u!0aW`w&+#(ym^+MNo<#u zmv3tfU5B+{^m%2kW5*P9ZbXcJMTZz3Ja9OklX*7^bWw$66DBnbS?>U9d6k>x<7HOu zl71oZ;_H2;)hqr2ghPE9ZFkLWq&dx>}r>NA8d;M<}NI`NJ#OCW2~9aFx$GmB-bmzPYHD7hn7 z*+=5}$~>{Gl*?E0#=jg~_nUHF2x==Pc{!z~NfLi}kBhtrXVqebmEUg?_vdnac5>$@ z@%cM_cD7NT9KlzUzkTd@dCB)T@ifn;*vP=zSRW_NB150q@$0_p3r=MQiI=CFM~!+V z6<)U8-Z$?1k59Pv^bW%P7;v+RkX;a`6u~J(gEJZ_A-o^x!Jj+Yrl+a-Q{k2I_sx!` z{7}u0vXfWuzbyG^d|07R#>YGA{2uv*O9%VD`rIe6K^|HvKVIKF*P6pQR8e6BP=X*G zm+d83z&)*r*Z9G@o(66wjX(|Wi1?4rZ{&1uKC&tiv%96tEiZ(5DCK{z3(WIBtj1R$ zTW|5WNgDXW#Rm4G5K$~(sH__o|FQRlOQSFAhW-5k+S_u(FbV2Y1R0%$ z<%@z;1k{@Ziy7Q|?>edxTYjH8R9by1Z0kw2utn?YbRQ2=hu*N|*^_I>S3k+08%#6$ zem*hnmz-a&#)B4X2My1er|lYbW>G3SbNfDj{v5C?i?(i=zAU7c#)o()xmm<3{NfEj z^LrzBls@xw->=^D(h6UzIIVovoe{EZ1&?vM)c(pu`Ujxh_lP#Sw?)0d=BDFUnr-_8 zqO0B}SuV*A+%Vt4!B}t_l9uRe1NI0pS5 z95iZHBbmS#qlBTgqBoNCJ?Dk*VCx0X+6S>_m3=xxDS^J`xd~rdlq0k19N#qrt}hv- zvl>p?my{pY^z_8|NLK#-4U6W#E2iPq&q?&LcnO}$;N%!@xYkfzk9lm@W#9DJIqRHn zw;H(~u2q$(MG}al(HyFB`K7&m;K8Cnqk-kCE<=2Ghnk&m{0pF8kRg?kri5=dr92Kd zP2ShGX$KU?_bs7PU2Td@5E5g~O{YF80FkTa#`G_SL*??P8Xk(4Ce53eIh~mp-rHTZ z{4$H%Hu{(D`I~s5L84_{j#}2Un%vR`?p=jT0RN+k*P*_Z>?b#2fa3jx4pm(^FUCB@)!B zxrmcW)YOCw7kfh#@_v0j$a+5zZuy;=U=-u$k#{cmSQ9_}kfDYVWEKj2B%5R{mQ{bf z<(iLL+b@ZhMW11p<1D8misdGKi=GQwGi|SD`4KjM(3W#KR?#+U_W#)W@^~t@FK)$6 z_co}TC_*7JC7Ci;k|~7Dp;D#{Wj=JAx+*t9h!ZkTnaMmip_17lbD4+C<1w9g?MK~v zfA9PH<9=>D!+!Q&d#&$U>$}!w&k$#JVtchL@mzeV$S2`P0*!6@1?N$R^l@rlGCdX) z0=Tkz#xX^E{H{2dg3m_o-4DjkGl{!Rs9aV5G-kQUZ_(TR5QR4y=H^qTOp=}4Yd1gZ zPHZVd^a%n4P#^7bRq?K$&)$NDq~*8l>@vxUIoa9StvR|5r>h`kk$bl}?8!6!@Q};t zlMX?*H0;q#8;W!!H2v>XH>wq+8a!c==T;C7>To^2)}rZfCpcMP7X`m^xdY?_Kcb=oBR@OX%otzQ}5y` zmeePF(5ZXVC$@eW&GfBdLJEk-2O5#@JNY12&{lQ}$w%1Iv%Swn2q$kH=Wa>i zLqC={u0kVBm_XbTvl)bD((hcTe7F;}%1(?@X?+Jju=<_2AcmIjL5Y9Tgi3}D846fh%KxN~xNnBGT(a~sJH~q4!PYsZSMLbL_e&RC3=d|9viF{`E zO5G8?XP25z_R$TFjgE)>PE!dVPV!rScP~-wT~JkxycEoFN=ix!&41>| zt>>0ryel!n@|=-Iowlp?&P5~>_1Et_@*m4^4;eOhsdg(Dd*6x%92T3LXOO#LEeO#> z*rt}pT}3Y$J9Kd2&(^6o6I$$Qe@pVU7BdNPSh(nV>7r(RY!f*$1=Ng;i8a4-eA~K2 z@3)M!%#uGo^L#(;r?A{|wdpgMO=rY-tZ4@VD$!PtMu-3kam&ldm#ln!)8{5cbX5Kr z6%!H)EUc)&3sd?Aj6pr(CMIBUc)emEg%(vfkv)2D{&suDl0(qJ-Zar463TjkrV|i5 zHr^Y#8Q9m@0y_Q2@q|TlF9o{1pi;y0Yz+AYI|DBERyoTo1)F?kHYVyZwt)I3U*ygp zBke6NDjHH~#NW?3DP8H(6ZeVh_DV>`XT(-w1?u(v=o2i8P!0 zn(u*xuS-3dsPq?aa(rL`ztq^5+|j$ItrDfqvrpb@lKzV`@~mWHS&y^t`F4qg^%R>j4) zE?9_|L-NSI+mE?e)9O}T^gy`1afjn+7`mQRLZnDm(#A;Q$+0-yMLwetm{v&qhX&+S zU=HWapAP3{wYGGdxs%hvJ@2y4*qbs>pFSN-%;MGDWmQ|2x82H~{A{E_Fn>h-)><#K zpohfmg2yt%!UV!#VyMA;W8+WWBn!Ji$L_C2da`|kT&x=adGuu}fO3|C+nFwm;crgl zTX}ddf%_S1rCy|XzJ@$MLhRWw%3Me{o&Mk1Jn_L9#TTl-89_@c=z&g|0v<$%jW8@d z@jg@u0gGrr)rU5llbFLn!!35d2+Pq4tpLYHEZ}3|7jX9+>tTu@T8vvPS+ICAqYt<% z?JPx7Ia#s1r2BpbEzddJeO-)i@D{z6*rY%s#54)4a?#zC z4-pN+@aH87G>_JapEdIQFbW{+PFs{PJG2Sbb;JNJAoqOZBWX{-gw0WewuO}I^>#%NW#A=;Vdq203AR>k?i|(RJeJ-v1RB{(?9WV)Mbep{ zfgt^J?C!pRO})idcL?7Mp^%gy>xDwdHIS6nf#f+~Bz?BF8+T7{@gvjbg4g<)uAP{c zWE-7=vIEgSvB=Cxx<)Ptwb@JLl)K*q^3qE-3!8`!*lG&kuK`Ie?d=Lgqk_DLJ9dH& z&oyO2S@Lv79@Y$0TtIqn4Ls;@y4&#>-H7iE$XLdX0Rj|Ye3qZLLC|NtBjF;LNj(EW zE$PlNungnMA=VI3BMMxn5jvB-*8SG{)Fwufn@=xA<9~aPr}EA&j7FnGTc;}2)4dD& zpsRya=xL;)GL3s$%t~0IQHFL0_vY2QY67C{bxTiV(r6(Eg@U5ASv@u=*mVqTCgP2f zVn+6=_(&{FnSkZigFA`G&eEI|zk}w)W*unJ=m~b$uOGvo0F92awzSVTBTY*?65RMz zd=#ZHiRQ*;h&vw`dADf=#Zp&A1r9H|nj3^>Cc;_8UU|YQ*L;n$Ts*Q@E9Ef6d+K__y^<(Nej^a=SxzD> z?ER?J-dv0i+Kklwd|agM&attFK-BoWuP|5)4p!d&xvA5A$BNKEv7nj11yXfGc;YF3r!S> zI0%m;KdJ)7GcqapTv&qw0cXDbha#JA>CPVh1TK$-o8s|FZrf+##v6|kwCe<&#&!>n z!eLY6gN)_Yc9B2^S6h4vG;!Va?bDBbW@=|3G7srGM8=2g7i)}#@$>Ab;O3MqR5KrM zjuS4AYhi)|Mj`BRLu-x)0mG1lP7TR0^N0joe&A-Lp0@bQuun#W6q@VLzddz2R>v$A zFQQ_i94K}|5Ryn6oMT5m%V@%w~!ALaNJ}p+ycD3u>9N zRq>;)a_WXm-E#V6=PY_&*Ja-6jMDpc3=CSapdZ)&G=oFvv()sY0 z{x_R~l_le4BsD6eN;#FI6@UrT`$u7YZ|nxC#R_d47m<9O=D4vR z%7P3J7Dl?A!N%~n&(v2ezncgib6M+m7yzPcROvjQ3FHJC$6u#H{}?+l#tD%F^^Or( z$Z);jbytnrsP)(01H%}MPi{d4D&(DFFR^T>d5k@(ltFapE1QVCZMM*T1LbdN11VFN z9VAg~Rm25puUfLBL@SjM>HlA_s$oZvxUEq{2kAmiAVj zkUESqM0~2V`XZb0O3M&xg>=qjrDnl&uZ4R)&Z@~c@xW~pwFp4?p)%yWUYqRE??uHx z&Nh@GYC$oM*8F}OXxE5{OH?~A5P8jLIBeu_z}HRFBqPr}c%fSb4OtN(=HeHC5zM{n z6P{j#XY(M1p%d`XxA!~at%maVf}hnTHLi6WeR?w`K3NVa1tJ5fyy2jUQb6!n-j7d2 zmXq#h>@u-UceMn{>V`K9x0uG(G0|6HD53(<)iOK4*5puuG28f0D2>d?kZAN1*YSJwR;(5 zj)=Eo$ukwG9}-)x+=E#fOZ+h6tMBo>cbf;KSvxJ#diwR zGroVC2g1Vn8aQzel>+8#ZqQpww)>b_35NBwQi4j*%;DO_Q?6yF_v-b3?=(v{h zFwj94f$gyp2i>vpi+~2Ly-}jWt6n_RRUmvrGc!@@s#(V_9&udC9uUj9$^^HcNlHb4 zF5NWU>!Htxu_qz?91RB4(60_vUcpG}#AIcAyO(%>i|;}P>z3BgjX_f8m;E24~LCBwnqn({-aS3wsw@v*>C#J{MIme`RU5lz;qt))Q zLFWY#B}MET2uib-en4(bv(QWhtzc>Asj5U20#Y)ep@A*4dKhD_j2Cy9o12Gs$%0-a zhU$uCzUEcAPz9bZWFg2Cl8g}q7zUaa!9?5U-xKyU6Vf6fmPWJk+4P z^8t1UbYDs6NvcW^HoEEJB3Aib)ptsmr7)el=Q~ra$w&CS4*8Ne2V%4N(4p<~Nm|l| z15kJc1X_SpqmXN^tF!+}X{8iHah4$44O3IuB}d|G^NL z|6W+9_i@_b8-rFzbm<-SpHWiTcTw^IsNLbd5C}w-IeR#OsgtW`e0`2sl6Brkk@*KIRC%OjyyCHWy3iZbw0bdu<(r?ztldyP7!_L#Eas75 zCdm^Fdwz_@mI;Bv5#X9E=-?kKzttH-KIy#Ux`_QH;PHi+WsDo@x*e+%Q=YE-dKOC^ z^DLlJ9YD|qk+@w|X46d2DE-}KWI(z>huv{8ZnVMoFxDR&3%l0%v zoLDM&=LYcphkp0a_ot_``@o?Xl@cWfx!V_|F8TjFmp#U`TyCS#+D8`EC(J#QS>UYl zV!n%E)e%L4?O1m?_Hmps0f^+Ac5W3xY`PA44J~Q?TtISHG@?)~M+W&~z8`iaS4==T zg#1ZIH-3?vC$C$fi!lN=4wd58wWmD7G?^gY2B2*Qx9b&nHo|tD@)`h&z{n!fkiGr` z^a9}gqk4gV*!)~El`@E5td5FWP~QCklr5mTk<=&&^m%0t5^}%l1K9g8)?%D22|oW5 z^)i)s15{Z6ILcx@1B{d}4e`1d{fe_3RU$ne2SdDqqA@OXcY?c7eNl_~&k_M|O+Jjf z!m-+m(e9xb0wtG!uzoW?bL!3=q&MTup)#1P+^UN~F^)QnK+?1d6(_P#kw@1@-JK1S zm+D@h0QnpVxyPLO_F<@o)bnfGdg2P}x9VRk_+#@>!c45^r#Z!@)(H|p;D*wfx6tU`$!k-!i2DIXxbbcK2;1p#-~x3v0cpic^4el?LX!D_UARh@8V z<51~_s5t=$z^HKHsO+0?>~nLEli=%KvdK(tC1yFkN~fBpbBv565HDL}0{d^_nQJ{8qV#@@Rh0uJm7D%X2| z^XHP(s6iKbD9Ylh8}1(=LP>(=p58v$vU#+C;dI&Cp)Rq+JtzTlH!almVb^l1St74@ zMwSH3b@qT^YW@+hGU$5(0-=_97SU+V5oere1doS9T^RDgtEXWKH-RcXcVG6b#xkqN zYxlD8122n}jP=ieWv|5fXRTzSN`xCrNvxUC>#m`>L?gb6xxN)#p9 zjQr`(tv$ziO}NYTdNxzlR#{rM>>Itw!|t)D(hS&p4aTM6YcoU%SF8xP~7pT z9LY;Ds-9zw$`s0`XMnDeTBDFEXCfI9&9e=YbxyHj2s`OQ4O=IaCm}8o?eezF(zUN< zq+E8y&ly2=aj1s>II7OAp40Au>Cb;4k8@%By1*(u=d}17t0u%oa9jv`=usuipMM!W zj&ya+@`E~C#5yEDL*<>QDvT(|O(V$t3{@7R3ZVTPS2W7VHmv=$Vrfv)2ye)BKZDg| z%^%?0Di7qqVD!ZWtUwV_R5d-XX_qX24JHL2+j8p_?_k5^@j$! zG$@`VcdmpI@Jz5;pr6;WV@)ccM2D$e1BE%~&&p+oL3wzrJCler02EK_55z!4=&BIY z0ww%5s4nZPhBL)TV<^Y-nj@;$!FJvsT0q@-5zUB)q!DyS;247Rwx0Z&nhatkb<-`B zf-~6*d4k1#O3qM7Js%v0b&%jcF}f6AS)t`OC638TKixvs&#zx4C!^9}RBRaV#B+;^ z#D7f_RXbbXmm`5GAc!ukNsmGqDv~bGb#Icr90_PZSo?!*KWj^Q`K^Bz+g7h=qZR;I z2u7~abqZ=>7SlBHK^`$#*!!z_gx0S@-s_uJAo_O?kt)L^WC%uBF?~z-8Afe+as(o*PWfkf(gIKbr z-~?=TEK8yN3rXA8h^;o$*9r^r8}2MUAOft+O|QEZnpOZqHG(h`0gZN`uf*Z|Bs6=Z zuY?p74)vy?vdt%a)7j7Z2>bJ?`=V~}XQT>-DG{qsFXn9d?T-2`DnkUG5d(I^CZdG0 zVT!gHVKCw`cGt1{`KX9P^*0;@)!Jco9nGm4nfhc_eaG7ktsO5y^K?}8&iezvJ~Vhp ze@zvRDpirT9i+Mz&vNLD8>Ep_`>axoElhh~?q_|1J(lY}^DKlI1P=}dVzrw4x4)@| zQhx#}{EoIj*Vb2#s3~KXjpxmtk`;0ys_1surh+O(>2@FaVzB*9$r{Q^R(`JUbiICx z5+u%tP1#9tJ6IpKjl~dNmY7y3J%MWA=mSvdKL>T22t91Ds-i{^(A{9p-t7QpcTU~O zU5Aob1R<2SC8C0Ms5KsT+V+iM4Yi*@8%vmf5ug+T8tW}R-5BmT)qMdqDM7^-L%%&o zpFPb&zEyvS%FYiew>MF!bz@a>0y;*?z`v_xS84X(0hG#z>mP#_vQ zT(<4oFb*IX>V7fK*lqw)Pp(n5n70p^z}_X${YL|(A%|Bs1{Hhbu6?^!&q`(Y6O5rH*4G zt~f)rBN7w94vuHGHMT&krUEIE=~q}iJ*u&F{rD%g-A)IfJ|eIr zytiUd2|i(MbPDBvVz$TB9Yq}h80AeC*pIywo~cRs*J2h)D%vcJP;+(25$=C58B_b4b&r$`s!uuZ|9*A1xwSgT59kU|XkUT`#}# z_AzlSUt58Q{xp0O>_$OoTtcWa*y`87yn6pK-N9GQg$q#2KLor~Sz%|SdDf4cdtq-q zHmb)cSBc7>v{9>uzDMU0+j0>OzDM0sC`1snI$Zeu2~FL$!Z&}@1a22oU7v5EjEvV% zdP-%bX6{&ZQ&uWzQ}s$GOdTneWv*0Ie?f04Ea-O@I=!7es<(%l`s@+nbuF5MjCmjA zHs>x{eHKqlBCJIcHXLQAS*W1(C>XO7jG-&-awEy``(~nj+2$-!d@gev)!$$gxoEf< zEdvPaLw@j=?0@cLq`JSdb?4GQcZS<1V0Wr-qZ-|XR_O#|+WLT?{qwf6;qc8#*UiNS za+x9()#_hpXL28EBf=pGBzGpe#uxp35r0Ug}RpHOjH|(p?+qr8~+~|9L4RymYJW)uG1o zzh3IT@Oc7z>2|97o0xWjm$qOpZQ@J+_0nlts+dZ&R3{iG7k<4|Eo>>Nu-}sd&v0F$8s^2)m zJ$1NF*e&#MOUrES(~Wg$Ikt_5Nj3L+N8GBFh;1w9gVi+D{`9xqP?j+$Osl2s{VYXA zm8}8|58(sIt!Ja))FyKF4r?ma3)O(^%0^*I1L5jVksk z%ZAIGFP^wOS+wBU_b8ICZE?DC!(Juhir-?dWUhG9X4v>=y|v?bk%!orPEs9%FTg(c zwjO#d`8E~P^k?yCwRNlM#8?we7Tz0x9%~*MGe2@q=SMvqj}X7TpxGr#6;}kG=ia6+ zTCm97q8&_@q6)Wg?|-*UAh*vJibr;B=CbcQmoge6FC*K7b6)7`9w;Vb-zrS?_YHSz z2b&3v@h59@4+`fPsYE{I&k7$Pbb4GL@lqInpp}+iFT2sAI=!rhU%ur@TV#dZC`7e$ z5Ux)(@PK=hlDVMK_?~B*%dH&SsCe}Cz zXVw-pe1G#(anAO9QB>=aD5=l5yguBy5+1@9~lUSookuI^_cv530 z=svwZ(Y+Lnrw|Es)4Nr%pcjS;FuGIulP`TGlt?`7lBa)AdEz9)i7pxrnyqE;V1y;xWIAR+mpM_PL?j5S#a9 z^5#djdb{#?w{zwh2LgIFNBZm!xi5Acv8U>}*$^QmH%1s8Em(|?Xs6GrPG1b*5117u zi<)_&hwvy_L$lCLK}vWfwPiuB1|{#%+x3Bcnf{(gvZ~UW43i7e*Ve;md-0QG=z`W` zyZkLvW0j2ww@}cpW|fiCYs9^G_wceG4jp}R>hudMkZ805W%L=&uSY`VyTqq(juz^I zROTy|H5{gLclBo5^4iFo9?9xQK25VaVkd|Qo_d8R4ANN?_G*^xSMZZ|@7iP(n`G?{ zf&OP=vTo#*_^via`^&eDnZ_fdik_LC@5J6Fpp;axHn;v}qpI|B>z(Py=mojw^S|FG zLxOnfBrzf?yllN@#HTRk6`HFie?=>K|>IGr}^ABzevu0on$Lpzv6#{O41hAlTL1y`UI%@)C1ZLsmHtIL8R~D*FqdQ+`x*eV<5owi@5e+l_cJkj{ zcHpGb6VRWaZVr~0XExQ{mc`GuOI)GSH<_+jT8EXWGBRj~HO}()jOZJ*!%oh`_7L3Y z1vl<06=N_i&kR(w_m~c;IKoYp{;e?hD!@SbLvIkd?p-p1&wkO zXbzl6SJCdnOSF01ZYoTZ1m!jL)>wj@$}*eI)O{TZ0N+*8&`G1Cg8wM61FY$?dKKh! z(S*ulwA560cbBjJ_!MR2 z(_Wl9WnlZS;(}3d{TfALn&eD(mIEi%zB;L_dG>`dm- zoPPIBXyD7tfl2{ecG_QOMFJKvsE!8dw}a`NiE@C z=IDED5OruK0Gc~F54Zy(ma6aRzfPs z^{~*5gQ!vRDXzatBv&W(8#?2blO(~SmD0Kn>1@79T~emVSM9t^N?cx>Q_3;?&rtRQ zkU}PPv?S%R$8z16utJYyzU2y;<4o-5`5!7%hM-lRVY z2<@unWLnBnWj0S%53SoohO5c6T>dR%q00$An*omhe&Ug%58G12NVDA2pLQ*8^PB<6 z^~qr;!KyXpMr?go<2?Wl^yMNX*jh^!LeKOjslUvSh3V)yE~Wx(8xlGWN4Na45*+0E z{p}uMVeARKwq9@c|3XE!t@VvpQRjOQM zxfI2-cpm#Zb`ivo@DVQ~GkuDat5nR>95iE`Z`6z?3PLB;~FkuALk603NMW3qK)G937#^qe*gp2g2x-r0x*K13Ahi#6vJRYPt0u_ zo}9N}Jy9Ku$=Kh}KMg5%uEw*-B$nJtMVcR{Ap7S057ur3Gj1qJ0O|zGB0VY+g{chs`}7t*U6Id{jcD(u=Kl=0 z=cQ0XUg2iXO&-9-i!C~nSn+>cJ1It`i<(h&Cfi7DF*(0HM zTgw}>Y- zbW1p7p(RR*p2EyOoBUP4r3!jm&l-|B>%AL2OB8Hv9fzj&fA$o++9?@P9H3$aJ?v?Y zbd3_&(`>ac-LB~OufC>dc?%9k99t5anzCWmn0QcU{5xLGZ!8bbz6!+TnT_iVELa>H zYfph}Rsrp3UVw|V)>Da;%zOEAbjo$uVSHPNfi1lV(14)i^;D#=(xC0yU*CJBe6Nr6 zNA(SArr^-ygpRu2ZLs%IcLQOZlZ4#sK=7uwPoM>;9;5@WSs&V3>&849dX8HN9Duhm z`Vis8_73XqBWRNX+BtNO3$ScX%5`jr$3kFDvqv8Q!swDI;>*efuL?nw8|xB%1bfy9 zrhj)bJ*xqNCvX~6G9gUwD|Pp!>GEd1r*bJtV9VYEko(8pF!NcCmkRn$5yvqd21B(e zTCTsb(|Y)ipPCnq@#t^H?v+`io?zx=vNC9k$e_tm4m|?tPzUe%T&fT@K#q{pKi6cr zi}Eh1tbp~~aMxP(o6%v>s<~1gd z43TU_ask?Yzc%^-w)E!+py8(h5aM)X-Z+rK_wvm-L27k19ga;sjLkUfUEB3bO|x3~ zyn(>7RMu;UBYzYp9`Zj)nJtz!6!pUP;IVA><_iW+Wx+CquunsXtm& zSIg0^f^GCuOdZI%Jc&6Pq6<`fBa!WEzD+zj^1~PYm1Z^xkY??L!Ycs0@0rNcWyh&Y zyLbqlg=mC5Yo+cM;9|{w*}Sg5PzYwbHf>~^ZYLnd*hBF!>CbDj4*mzpvGFJSdU(R) z07RV5ilWuG!ZgrDz**t{dnG%6GFT|xg+iD#Y3#~hdngGe;WXWKKE;1mj#&(Fmrs4D zH8?NxKGIo{b0|yqo{uT3M{9a&JeC)))456VHOP_tezUW$c;$j9e zgBOf`|G8~W7eU-iL7aK2TsRAQF+^<$+VEb?fGzUhYm{1UG}UdcmYNRc&r#JOpzotO z@h;QvpKI9Oo-Qi0SA>h!*Y@Btq|eTSS7IY%jV+EP-?@K<;_wdQV|QP>r7_>i`rAX> z!Yx2Jd^M5tN6gNn5o7+EpEGKX!6-huMkVCt?Z`y9@UoE$Hez_wnZgYiu?JwL`SZB@ z7n!EYa}O0^;%8m^uQN^0vIA)iy8`eVaIw;7Iatuj6>(L5CDP{K`j4B$+HC`nfgb+@ z95Y;q^jU5E<`?R!ub5@O{htROU@htZ#m=+(6|FJ45G|CD3+QaYfd9FWt*E0yZq7R{ z0A4AZ1$`k>F&$Hi?Y#eaH(R$2QLe{eA*Uf4cNDu4Vn`K-N&!wr)cp6#UDvL%j(>^{ zz2rkH-cal~BD=XV@ZOtlq%yW8!L4x|Og^BX^_n0El?beUMUt;G*O=kYCg(XvJLYIN z`D*;zSoA*fbi|LwSotxh_wV16r&mCs@m6O-EN8x`;0F?~69nN1ibrZrGDUII<9Fa9 z&KE)}P<|CtQ`7uEa~GA}%bXt4(-}hiEf!)^#Squ@zlpnwmdp%L0cTc_H#51vWWDBw z^Waey5h%DZ4PfIRnlmpiZPj8S4}Jsy4xe~a!!Px=mh{>z$czZ_5_{NEzS`f`R0#&d#`v(etq8g%`g#PWlt9oVGNChy(=#O%KlD z3!qa2Ppw&#`3{r8q(>7U&q)r!GLS;9mb;7MGnwevWUu1&AG)}5SH*K6(DYc4hxM!x zItFGRoH(+NI6g;BM{JCv*-bcI6`!hb3zvS)N3kzpsEti}edayRI|Pkp{Pd0;I~)$| z(xap+_;}Yy6~@NKj+0-?;w8nM->FId_#D)KE)9w)QWY$4FHxw-41DBh;>WB%$g(Y! zwB|2ft~Yrxv9i`11#;hz8D`_U_Y-bq0HClf; zoQBXnC`IlJBJR(m;UIj8>enP~&z07N1EeW3@5fq_X?N_HYp0CK*?!GFM#%ZIK2oYM z{M}yN3#Ie{9|j`dA8D}Vv1`7r7Yc$^7Y;YGzm_&!`wH>Nj|9rMneXop95_HOt)y(g zjFERSu*(!CD%#{peVn7!cqxs0EonykUevrCmW`z;y#FpOcr~eASIvnz&uF->y}1hO zRwq>(ugSw20^6kzzuZF-!{hPAA@_A}*?c(ttY3%#k|V0N6(rt$WemQ^fu!^re)smL%2YggDbG(Y$QkD2Ui-tq<&H#Nt>Tuvt(;NDL zK^QQOW81z!?=6@x^>`mE;M9e zNqRPzG|^n-K3gJB@ZOs!7r-VbD-jm`9ay;eY67;wOcQ&8@&;yR?rg5sFgOj~JV%?A zVBaE!n*bqMC(n;1q?Dg=7BH44Mad2(u}R_PZswoMF%W7NG6+m?^`5l+6h>v6w!^VZ%6kp(~1=*L_jVq4bYz|A-yo%{wjWRO{fOrmyq?W;OmpljdD>0|9dN zefe%^S}(Ro%Hm6`E7zt<9kqR7ms&@FlG7D{Gv@kILtTVuN?oTj#VnnRjtk$|)RQV) zO>Ope3LSS8uwU@{EmA}#G3@%jM+>8=SNshYH};V4}ovO-H8}eH#})p&lh2W@LoAE%=$gpacd#VwFyL&-BOG zRbh?D!ir2;)zS-3T(<37+;+*x_2pqsp%y66g!fy@d_3Z6oFbN1mxC`&zVa&Ty6)nm z#3vr+Nf*D5lhUlbtZNNR6-8>|)A*;7hF2E#prr-)QwFKw-h1N6gN0-E?#7X>cYb`$>0U5f+%ZxgnP%9$ zEiKewV7ED(a@SxLanszacdBGThja!ufjnNv`G-=;Tt!92LZ8!2S(7ttf^xjIMs(UF z9jmmyTv-1~{(}b(ti2LE3G~9tsj><2LvVgKL3h$>pxeo~$3*Un)2s0p!nxr8HASUl)Ls}CAgp1(*0O4J@M>}5?M%ZUCoht@GCp^nT+VR! zYnY#K;$+&M<}rsBXH|l%FBfPHUnS5QZTtaoUXU0uf+Zoqn%D&Q-(6ps9q$7EJiMOe z^(my9m6)%Vxe0A7!*t@}4{Pp95wZG1=J6UrJZZ0#G+ubH9QFF}6D&$H3}nLO;lx}ZF~ z!lF(|OX_i+dL5vbMQf$4K3&WW$5l&4#LMcfis3Wsp<}exw9fip%AGN*sYO3rCPS)v zTDvPfH%_(0&h4FLL5TP*akdm-217I``ltK>T*+>&f!l$aC)x|@IawpRK11%6 ztHiyPJ9evUeP|U#r+Uk!#Ot2z)xt{&4}G_vgu!MR3LZ5!3b78Pn6#4WV`ZIhwRI^o zEdQSdW^c(Gb926}sYJGMB_OE|p#+p9r(4$z0=gtPMv zrNobSUkMX9n!S;Hj`^@m2s23O`sH$|(JLx-vT$0t_ICDr{w2{GaHCDwAG$!9)vxNX zglbBYU0lU$j0MY01xDNHGDNG)`rlluXcz)BwEaa`|J~V00Z1R@YN_xfG8qwN?`1|6 zHB>rLhBoZ^5}#|O=7?@mY%{p0a{4wLSG9Qv@H@YZdHW4HiqKs-XAk%l{H89WUA*nU za^-Tm)bboPJn6Z$1L=TkYHmYc+H)knT$-3+2F>k*7?cFURA1N+0f1hysfNYo2g{{C+x4bfRlMqbB)z(|aD zB@}f?mfUD#36_+I>(LG`HtRVfDH$FyEHZJ9ce38ds9WQd_o`-|l$q4xfWTB-Pfy+5 zcHhzz12<;`iW@RHb1?RYgkFBpr0eJIK`Q|CO_RX8KcB?rq67;@BLz0~w_>hRs z7nIOR{slOIP2v}V z3lzBIpDTHcl$Ej2ZK?~eW9S1U&Do8w+lhp?q|>H!pQ)D5F8{eL`Oy&x>l7Q`&u z>mq(eMC6L?srmc96+@CYIq@elvrmD_HfY@6DN{&RD!sB+Ap4$~RcunrwsDGFNRWEh z9NiEXiC;~g>uG&`C5k-&U@&GiT~o?Yz2w+#$A|n^n)8fo?;wF|joTZm#5|IOJAyRv zgz@mldP_#1z{~_|dspR27aLbW=W7>MFaKz^_NQ&0DhpAd&^W$gtJ))2+BkKRp|heW z!tiqz8z`b{+aN{XMVQNC`z1=4P^H#dJF5C30Sh-`p->X^;Qw0dcvWS8%3Ew|Fr~2O z#sgDoZRx$BQ1e@V|7~6~;rGEdw&+6jN3ZnUbjJ@Iyt~6HH&w>i$j;iHM^7rvMNhQl zPYw6gg)yg@o>JFj=JeKWd#aQt4kQw69khKHbn?~i#<_?$XO@R{rtL9j&F;M|Yd-bD zZfUA?y597vM$CzlbGDmC1-UUCc^-Bd!xWF>V_oBEF5Vez_N60zQ#+BRb6FaTjv`MI z_^L&KYC@?Xvr#PGyZih|r4N`NX(&_`v1ELGIZgaUK$u1G_rPF$*!dcwP zdRqB~r3o%lZQQngaYgQn){8n&z$hdw{j&0Q)6~&V-ER*p`p*kZ>^CF@+?bkd*^?vy zE%llY>W+U4>Oa}p)3c{*B);OKdzRC25FPYA_m!ueWf#%K=f*23P@X8ep@;q@G#+he zh*p90_4Hl7#F7d_T_(Y}YR@%|frcJ!{+ZkAK8n3|7jK?jeHJnNy}Q_vWD){+BNcC6 z@#gU!X02K{;xUr4c@7`PUjOZ}5UsGlkhKMYG?i*@xS-tPPinDDK4XQCtGLX=TIDE< zUvzsU$SXKk|C_UCX0b=T*7K{N_(@!FYjDFL2v)oq5w1) z>KVQ}cym8(maD-9fBBN2)bgI=`CWJYJ(MZ*Da)zg;X2>E$w`oTe}pzn$}O(*h8FBcjM19-BX6C@-`ZG{B_PsZ*Epk4U+sTX&RuxRSI~ z6<<~G_U|5l;nikrNTM|WBgAWKz>;nJ@w}FOZcK0+9k;Sn(m-;kbuL2WlU2$sdO9Aa zW`OuNUbg6s(Pr$`vRYmv)Dvo5h8-U=SKIRUFRR$OeO;X`@YocWK5uQ>KX34gx5~`i zSZd9lELB2UCLHEXDtpvcylHyLb2eacAVumRiwy*@=T=upaqgDNn;xE>kN8{1_i%A> zHIGQpllP}2cINa12D?X)*`)EAF8`g^9NDoW8dd}woAl14pv^CR8`u23zOYDZP8T&s zU)#GFujDb5bQpkNntiZSbKYI+6m=m0W%-P*ffa^V*Z#8O-7uKU|Jzh94+uI8|DOrg z(vluu_g68~mIm)FwQju8Z_s{T$^XTB5JTfhlMREKJusbwbn6rnH%ugh(>B$zPTk2& z>!hm4JkQhKbZqr%az)?ck)H#;jY}+@xU_jG^QB4B4q-a|>HLL}tIH(`MZ@pb3vDd? zkzUAGSU35!ht5c@*QJ5-Sn-v>2Kh@cLR`nI;_Ihh9b~!WqnPNgaN<0J_53Hb7o)M zqm%Zc3B(kNQ>wb@gkQDM2SjWHth)do_P;-kPQI$MC+4Jh>n_cnah>W;m-sEE-1<`A zaMGh!W(28JGu`B`+1KS4CofIL?Ng7IHO_As*&gbapE11C@|8e;!s2xcwYM(@5_CL* zD0WRJ7h-#a?A^Rl$~&(OZ2(aq-xSH zR{DLvx#8-37#;G=;K+~Lo{EX1*B}~NJ29Z=OSl&usXlwgY4mdbTlhT3mi6wLkDvOH z)g7!f>OS?<44Qg@?cL-0a=^seD#AcKYT&3Ntp@)p_X~M^V1`9{mSfvJKNr`W#wCTm zEBVmh%PxmkTN-iDZqT6PXaDwDlTKy{F;8+s`->z-7?ZbKeGBR-HETGSv2|5IUabw5NEihGF@@msnY|iER@TFGVL3JXPk)N+qV; z?~3P-!q(xy6P6FYC;mUmX>xsZ-7`DDU!Wyi{otsscw(9Y_`fh%m=>M5&PUpzeD|%e z>6e?sg_NSgM49NsXAt@$C%b)#?9)UU^SFSYlNA90Fi;S-!naoxq_&)uWNO{gOX}*w zNo-$s-&HbnJTk{9V4BF1Wl|nqd7JFg=ArCIs4@>(o%3OiUOXD&PBicm4yxJ!o!;=( zeb=IMK@?xz(M9d>k)MEg^)ut_L=6d!Jt0?B+>5S-)=U4DE-E$gX!-!=Vb?1VF&r2; z40>mEb=AC@<_ptzO&q9^G+PvHg&3FPNWISFnEYz43ZX-(CY@>5*acEWh(Yj~pvwG! zU?q!`Ea6E{h=cN09gURSFvuTK%QE^*Vi+z;eRp2NuupT9SKK(D`UTndi+i)Xms2%F zW^@AL_DZG*a)=IZ`SevnUHR==9{K0)zPTA&c$I~BvBaqZ1fuXN+jWFw8aWc`QkU`w z=So(ba>pu#5sYsq* z)aexOap*j~QK+<_|3N!k-g#E}ZgR*fL-TcT!R!Ti>Pb^m!$lJ}?~3b~R;O2b;=i=M zaQz!4f2(E?Hw1;VAOij0AIp+rknylSf~LV+`T&V9U$`utLBu5m<0HXb4rdVfCnE}r zGJDJk5yI;IUvtca2mbt{s!DLkdY7Xq3F3=m5T$Xv?JN2AdRuUPxf%W~0^ly<4(~Aw zQME1jQLn@5OCyWmDL(tcX8^!I>^CnbuJ`=unN>^|@iJn+mi8egrf|X{S#aa$^hWjz zQDFbyX7d29TG<6posY{nM=j~*ou?!u3~W2)^<^WnxRbv{SwUP=D= zB3~DRtN609AVjMw%2uD|_8MNUi7rb%RPleAkT*X%6W#bvRK~wv=V66ykHhr_$RK=@ z29p&f<$BUyG8w|PZf!*mApBJ9Mcw=)RiI^RvflaqnI`~g3VW3#9ZIzYSFJ5dzUv%h zaB2pLJ-DB4tbx$_q9S!~^HjoEYUiZB>CBf#?*vRaXk((=`Inu9ZFjhJpy!A2ev5F- z+1r`om3X_p%UCbreF96D%#ws>7Wgw(JxQ_-EMEf)Qp7U(VMbA?15z3KmY#}3zU>54Fv{>=gA)n1=6-LA+-3>==jHhf1xCLqOM3373fxTpi+NaSR;ig&%l@*m z6sw%4G+u|+F~K&~k8g77_(liQd4T1bEE%VksjbRW!9QB>*}V&|GMO-NMXG-F?;xjL z83BbQS>xL=An4fVd~3gW$lk80xpCow()_<6l>&LU6g$T-$TOfH!Y`qW8H2wu1omkf zK%%H#62H38XZ|sx_C)lGJt0D4<)hEl$-mSM?XP|i>28d3Ej!HMR6FKf+to9w_;PDj z7MCW)Odz1~{W=D>ihGZT4Sb9|4&k>99#-Gl=~q_~U9m>jz^CRlM5JaIg$LXA8W2X` zPE1-1+kJr$kpx)b34dR0HeTgu$BDRB@9?!V;)~obtlDZkg8BQCLg(jn+b~*@DW9l< z%GL+`JASaK{F0UNf67!*kHU7d6cw&A<3Z|zJ^-=71p_Ud!!&$oX-;DqDTwy`&-YWA z>w$;~RmQVdQU48!H3QtH#1YpkCx3M6F9`9lriIYc>4pIhgZ}?xuSP>DwqsMSOKGpl^I+T@a0j7pF@Ew*nfVANfCRoq1f;)%wSWX0BLjq$M+^4x1~eNP@i5blGCq zgq_0<_I6K|UTX$hA=!Xq;;dR8Upr;IblFKmcBGm$)XLAvz8R{zE0bB*@c2`|R6HxF zlw?{PAJ_E#IXM=qyUmb}l9Oj;*PikOQ@({rVP3}Xn#R^A_>Z`zMTFOWv+W-Zwlb~P zJib6QCh7e;KxK8`<23vR(z*$5vopXY3d?GEf@xp+OR6H`V(_`sgq^6f6WyCd;?uUN zCuA3%^QH)NSBKdwu`CMm^uQUn6&-e)Y;}jD$)1$)rcX1f+V3j9@$&P^W94}E6ENc$ zf}2IwJ<1=50chg!LEZek#zlPN3%9a5I*$+NdF81cPoGHYC;H8_lW8=+?W%$to{ z*b!eI*EFB#>?392~T;roQ`mGA9kuA2N**@r}|geY5n!d z`m&wnJb|$O?qkic$8P{CE;f$V^gRT4TpDFqO0(5<(_^#MN%@*)E55~M8-qazBe~!* za8?6GiNJpZ!h&wwp|#>$*m|R68pEImhIN8CQ5#TrJ>8=UURh<^Q;pgbZXXDS zN_f{bf;rpti+TOKKNw`DD^+rgT8jC>?%|GGPUgQXmmX#2)vGh@s*vG9V7Q2-d24UT zjKdJrKi4}B?`Qt{*#(55FuDlm zs*40V18Jhj*82#GifPUNbnDFM_IQ<-*Qnu| zOA?(!2|rr56fl~J#adkuNtKdWmRJRd3UQYukU5$8tT;aGI!g$*3xt@c{seHRYPNg_ zLJ_@Pxg*Z(aNtT~;AIxG37Vqa1Xzvv1$L`7Nz`C5q3>mL25?#2OG+2YO?yM?ZVs>h zyco%)BLtk7+MD&6f86nQ3qDs~%*BZ;5r}rs>eLq!--j|^3azw|sg0z-g8Xlx4nk!TF zY$)u8XUtEQYl;?Vp6hop(I!fpP*8ca>>T`2$Mq591^6FgHxacku36(`4$$t&+(LrI zKQ0xpnd_y5E_l5^rSV|!V1;qV-Mt|(ZEWu@I3uhIzIFCi+e+^p`{FMP2jR9vY~Q&f z{9_iOZjRwA8Z=v<7&spr85TXfec4bN1$uaB`7dgb1T>JpyjPMReBXhk5uHcyFt^TZ zpqI*bKrL>8yh++lfF(`;T(oQ=(xr}T88BcQEj3OWwKRM6q8IyoOnNqa*i_*C#Xa={ zb)=Sr?aXEXtv-Ir8^nEB)NDo&6RAm=RZp}NaCz98Jz#qg+#OCB_Xl;PxdGezpLAR* zv0|psPpP^3Q|uISzIzDWM-D9-7Jl?|CbLU{pjsK4MN(+-XPExh^E^g+aOCGg_k~3C z0pOLIj3AJ zJdCVmu@Qq1!s$@$Z$!E_AwKjN6)0siy78}?jo)SN7$3gfSg2Fn9T zoYwdg^lvD$M#lfr6kSK^IuBeIgx|5lg!NJ!>DMz(YsY6dDVMY_%`SR-xrqT#hnHsmlR#2u9_x1L&>`D8HXBvBKD+p92r^HKbLd6{7)hsr%1v~ty zp}lQ*!T0iDvyR5%uh}>Qg(*|u)WRW2nZ+kcy5Wh{+VJ_88FIB0?6XNJ9=v)Hic8$* z2^Q23{GgTMPnsZdr|gfY4738!rajR&Re*U5+fIBmq$mw_J)Ci3k|H?HWT5Hti|x#Q zI^VDil;@0Cf0Ea(ppRz1HarRqm+h+PEfW@D@bWy3TrSM@G_;DW~@+4Cj zb8L7&s%NQ(&hSkr(Ru*R`fLC`z7cNjpwy_ZR=oKs$L?qoz(Pi*(+qLrX59fxLgSxg zRUMJlb6?~FRO7QCG2< zjNRuWr>w(o zCbJU|6(K8OT^j4zKHrXFi^;`(JhT`C(<)kwM>OO7p*666L-gK6gHk}J$l&?+>`jL^ zdOs>a(sZ-Z3oTQXM-PPPz`_0?t&)FK6O^#ZQd6}eoS#}_M z0Wxy>CHQJX;fz`8<@``Xu&d{4GqhYb z#r>K%7Ph+bO1J zFJFm_JRR9dT;WUu`)~xk#6U(8piXa_V-$i@nGirfOiRQENWu%)*9QX8( zOUW%Wi)8#hZek&l0TTkYUi`2*Gmxc%Yf_e)wGEg1VmDZr`^(W(GEGsd))fmXvz2|c z3CZB|Bi~I7V{_J98H5IA+mbaSJG*Xxo0v;U;ZB=NQcdtT>e^vo=npkB=)$mbXPO|D zoK&lkm=EU)TaqcK(mipbnL4)#ORM2vEH=$c(Wi!5d6oL|tD}a@&OHcqu~)l@>rbY= z+Go?{B;EwiYtH42ZT_=3YhGom9B(_PY`-aWU;}5n9%KDfx}0Q&U_=8Zao$rvoFwhe zkVA?{H{^bgvTex+JGQx3OsS4y+bx(I zgocQzQzb6=qTCOCuDLl!v;}E|0owc4uj`u~6hznZP{%Y=F@Y+X`w?3?_0+awfutik zNm|stx9r4F=Gm%-t20;)nB}e?_!>6WhB_3zHB}UI2aaerH9hUFkFU_KFG+W!AX%`y z`xF$pXfDJ(8PL@-wtuCDSNdx-Arz+F*RJ9fgNk17^wv#mCdLXsaMwXseEbSqnn!fC zXBKc?Y$h2u9Cvc^Mt5{MSr9vAWmK$Y{@|CPfPUfDn*n+XgX+U^P0k+ZPwB;PPybhC zkS)uqM58|5C;(J(c7ED^-V!=;0V-@^uTL3ru?m`qfJ%@$mK0=dLr2WRNHX9;4Z!szyQs05LmF13EK*3CAK{!z!z)h{ zZcgC0IXl7}u@*aLWF1Q-kK=#DHAHU8M7FI7oI`#eJT!O+jY+NlTV88`@YXU(b9@}! z<7`iH<$$p05DR&eg~fPf@&|gJ0tLIch=!r=D(bUY~iek90+ z&~BMGaa?6E`F^~pMEVU%3Y86)Aix*bWdA{W@XI1yAiw|pPaFjrKgZtYm*Y|(!CtP| zKzHBm8b}vFUZb!ER~lLRiw6rMCTqpcw~0ld*c3{RqMrH+q(02`_Y{n zy#*V$jNUYN687LShG6^4{$^$Sno){7ZjVV_vUF!POa}q`l|4UdI~qh*(kCCeMNv={ z>cWZj^>C2`6>oq3=7p2E@cS~zF>#^9>Au#yfm@2VM}3QKw17Ty!;rWE?agr~!%cK2 z1gRV&eX|E}xyRznWhiLD^FzlUZ@NWWR%7W#Og`nyy$bVDKZeU;w96k4Js-Xxqi~FU zQtR-277)sN9(@0{`KTpwIEp}&htmiW`c`!JUEIk)w?{zSkPO9cYxj%Ic*eg!RI2y0 zaVzxLy@Q@ZU6AsvSnAwqfy*`?Fz1dyznHcAP1P>GPdYB;{_DRGm2Sx=|B#nB7*FV0 zGfhBNN5M{i|Hg{H%_@7s1{^$7H&VW?-*{5n^9v=r%3%H`;iy!TWw>Lw* zu_|+)-KhzC_V>4>sp_%@WOwvN4_g?c8o&>jsro!sMr`ot5u9;KTr8-P4C)MVJRcU& PpFg!(v-0W+uh9PoXgfuB delta 243261 zcmagGcRZE<|37}DQiRH=gff#=c2-2<*ck~C*|Y4KqgO`BJocU$iOSx*Dx1j4Iz-3J z$lm%sE?)Ki{PDZpe*Kqo&UHPn=VRR;_s9KtjZIP%PEousZ^IBVsEPgl@q6Rh?pEWk zE0>$=(`7^G?SHZ1PhV>t#V6PDY?6O{#d&-4>d9%t=6Ki5MVT#2W4Qwj>+@2+es_ttn7_v#6Vi{tok-5o@}a~fJMS{rRe zdIFm7j(f*CI{kR2j~S`{+)JN*#B`4Ug+d9)XxvO07yP{{)j<^HnM8gH{-$w{nSHdm z*J||lLccvK(?=Tvf0R^`Nn1uMBxHL^Qng{q7N3d>;I_I-eBmS7+e;`*Z#H_=btC7E zjW4y8dEcCc=-k{F#`*%dhztftHfsGcsS+PlHxx0VP#9FoKhzQu>kA_SdN@}D5`vhL z#Ol#3ef^D^3|5}AXW)X_nN!ups-10oiSb98O?@Nj zG`!WdUXu}bKI{kzg?%wj(1W@whBAn{o#bi1I&dt>^N5BLbKTa`x#-w?N8z^`^7!T} z8-mdo8wOPG`^s9E_4%|7O@WtFgoN;^=E@VR`pU=O9PQ@wxsImr+Io88pK1#5?4L%~ z6VZF=qHMC>uZ1Bck+tRRFC&k2$s`4eN*?+i!6ji_;w4K_s5%)+@|5GS4iq2LS+ei_ z%Pb!WP`#AoHHF(opQ4a^To+$@f>OcMRDYO2X(%#pl64Rrhd;A_q$|g>9Oos7bb9PC zu=CN9agz-Gta>Kw3Ce7g`z#skhup8k?sw--)WBsZ?}~ZTTn->YwfSxAy=#2YX~Y4ziLv}{t6l}&BI1Y8WI`02~YqWZOW9vhfhR=TIosVjw6 ztpwQ_^&KJbRaP$w#2GRd#s~El@90saZg>ZHEYB;MOMQ?1qQrU>b{N&|G^H?9dG{Ot z@39)#AuJ<>v~s?_(W4XaV1IZ2_-(2DBzL#O&|FEb2RPU7PceVJ1f|$FnXGSajq$-_ zwu^1x=I{M=IZ`cT#4eqO%g03F_Nu|)BU}||d&1vUrKZR?zI51{zi$CwJazA2fh@fA zPD?9Bx+f%kZT4r-t%E!JagMw76R;B{v?!GM^)y$MfFvb3D!a08J-1WLr||JPx2lt> zOkw>~T0->wQi%VdSSOzTwlb#wxKS%wLhIe)F``TIG_k|cmNyR`1{HJNLfwCop(#&v z<+L}=)~Z$f`7-#kq|@BOVj{+6s8U#Hrm5S3y!4*6FeN z5sAP3fF3?Gz%n}QtNbx)&uuYol_|4t2VSIF@L#ytwkl!cSEi~3z!#NZZF&zXe?CoA zV&o=Ap};>>2_Y=Kx8r_4dH8NjzhdRJ4GBSZ{Fe@l?etb1gqvCZWw_CG0(g$9N;{=< z-xkh3B+t%im#FS6VmwR)ipM2<2>8%7Rc0bW)z^vB*UMDhz#OJMR%O=V1uf!{vofN+RX%LASCbap=Oq9ZM^C^igVXT~g^kky%_=xPjT}Y5nQG z=G^_)T(fgKqluj>&)_1AoFZ^ZRcw>-b8ya*)7~OOuu~-h6MzjN5g)V z3EjL|fTTYZ<*eJ|`RPKE5xO#T*28Oab9*HdsGbXBcCZ2dZ1j?(r|St(vnDGli=SJl zsxgk0Gn=nk73YXdn;|9FnkT4;mCD(76ej34hjF~2EL(Y9y_IFAMTjyO{Oh}SAam2} z)?|FM5rXV}Cj@of0}{NH$`NE~Dn}4E2w2`*3@&+rcMrPursnrXMkT>L@56sK6b1CV0koyO_qHHWjes(@#Mr;xt6H+XY@ykO(0&53gfI$0D zPvj48i}%?1^IjaL_a8$8J5Mtmx+@0+F*9JQTnRx4UcM>F1LiMU|JFLVz%t@Bl>>c_ zknLb)4vZ=}!X=(BJI`t(>Hf=@99nr3c25ycfKnv+lZtyje#)b&e&8{)TRGImhBDR1 zGd?*eByd3k$HZh@Q{WLVDpRf544= zB57N>)vzfc>C((MXLFse@Z=E2Na{p+w}G|o<4Fx5 z0&}9jRlo8^L&>|p_rb6g+1MsU+d^se&I!TFgUS)(1Rm#pjz9@XgABB;qrcs^*Zy%y zBUWsTx@I>>fTFnbC+Mio&FGhxmP0-;M=BOZj2XEdTL6D<^^T>|%B6)NDOB7T5`wO> zhcO>$xz>1R`br*@yiGKTc?47j$m7)t&(MdzJ>LtJgv~tjzd~Z}*YxR8EWl%6tik^;RC&0CyUKJXEKPh^ z2OtH%%E8ZN*J^%i4h~|!INHj0??5z(Cj&?joVQa)d?=p~;?Fy-a^-cN%TxWs@avQV zU-F1Pru5(v)_L7aVpu1Pb!FFoC-d0+aXDULFtq$Lh()n^*s7G1NgI7qxA?%ZT1Yb> zgS(A?^JgXM-CMO9+6!}k^zy4L%DefX{QO4J-WxMWdywwjpE`#hnhQf<{ss(+$UZZh~B!Fl=Qtmx+-Vr%R2_xn#IhBq_+ z6LkdD^4Fs^DHf%-_FWpm4_v{2J+w|LDFuJ$_}2W&%7tXcReaC=nMDF}ZQ~Uc6`j5j zy<{|4kf(vpyP~ulGpEPG&(p(-?|wJGvS{m{X%rOkrAF@o1X?KxJb*|)ZZy2|)?&>U z=5iU&gL0d)glu{(KFO=P6JHk$en;YV^A{l7-&;M5w^;#ua@u9>y3RB-%0kI%7=p}F z%<(#hO~Izz)OAF6Mfsyf7ud5z3WbXB#{6+U_6ex0sbLEc7+aBa-e%zYi#n+}&m=mU zWYmHyLbs%BMc_%ckSF1jw4DvEEt|v5#X3Hkkne8bK%HmrQUVOk*un1rzEAOzKTfpS zZ6DlV0f{K862L`JXh-G~kTf#AJ2z;Ly8f%?_ZkL}@uIz<8eip1lBWm7Y-w8}{?sV6 z5~A=kNt^jYAcLE;fW5MAC8$H;92>G84*80mDhR#3LW@$R|BLa0o1|}E%f}V_qQ3u! zCGBU-n~E5P+W^)o%-f6qUJ#@Zg?O2@T5CK`zIF8an~gopyHtfnNO0wjCxlP__Ozs; zSLsHw5C#GmNtNESFD3BdW!5OQ=GQ;)vjU50hFu>f6x!WBBiXle^^Fwvfq$~6hmi|_ zckhaU{|ZYZ9|8(HJggv@-ay)*8ogC+8rJ65=_iA3m%CEab2zkprn-ny#hm@S{udC@ zGsgxL9wZZd7GKQsg(hicIAO~|Cd^-eDn3|DT=upx;t`fMwZ!e$C4MhBOEZoVG(kvR z1$bT&YHNS#Npv}Ri+rP6!9R0ge@ruOD0Rf|Dr>nd#oT$6>hV8|jj7mt zymE+nPgu>dH8=URVG*ZlTLBQ39VYs4aD*-~Gxs97H3RAdRNHn)WD7RjDrMqdWG+J9 zu%w|kp|9I?-oPLo;=G=uB9?XPR7e!W(G=n*4AF7mU~OV5@W2S@7Ns=NU%m*xk-URs zr*o&34l0|eGP7s1WB7yWnQO;Tlz+iMrh?87B*ClAA^EUPSnVoRjR)hVr9Gh(*T+~zIkYj##0HKxVsu2Aiyh*0YIlT1+RjV{Z}uD(L4l+vcFv^yht49X1_)w5rJyT zw-9&j8ebfyYP9`o#Ov`2=_5IgP82b;Qq<_pNj2lA(Aj%bdSeCdDvoMPBf_`Q8jEB(ow& zbhaoSXFmoui8j62Od;vE;A!D;j^eP+@{Ki@VuVsp#)hL$okqTMqul6}Qn^HTIl5C3 zm9De*;f$sKmk|m|DGCR6EPi<(z+D~(3MKQmpRhnov+7FPJbKV>8c>G)qLwwCm=UoL zOf_H$SA<707>Ax&QUIxaYs(cbzfG~j_28%PCr}2r7gX3W`f<%ugdQ2<^c5A#yv>mb zHR@pUs|T=4y1OUgmotj^+n^U!+*{Z6`EhH-dq@s+F;_>6?VJNYDgdYQ5PBTPeGvBs zw-Gyp--AvxKDO+v`eR44mxImqkR>?(I&Og6{ceB+9ry36qrzRBFh8ET*nB;JcW?5V zes!MA`f-ihp&o)cI}Vy33J$F*QK4}B{`^5lgDMvr);X!f5%*z=@QUw8KjoXvPD$%G zAm!pAQzar+iH~I#YCa5nJns;p1wwahQ?Mq(LWeBDd?~z)MmOV6%hOBdKn+sH0M_`nDmM3s1>XPA7ZW_$QHDPk!pRcUnQbu`Ck{3Fq6^Kyf7G@46y*I^QEXt%*ZW zj=|j;-v8&Lj7ER^+%FQy^n9s`|j&F4TSh&wf;?mVghM{a6A z?~QGmm_R6?g7lm_M%GZCe`waIz4X_FYbxF~Hkf)D$x%pojb5@>&Zx6;&invAz6ogx zO;uB8^O0p{EkOF;epo`_-@cbsa&W4vzwc*We8x-t$|)ZdCOdHv<07SQ3+evBD+?K_ zOC!uV!Q$WG9)%3NDZdZ<`UyZmB*zlp{(v%K9s(Z8KLC!nxS-ID0GZRMh)DoDBlWWC zddEfX3G-$$(<21YbuPr14pl1ERY@XTv?$_L=z3JAM*wGi<8XXzo}`>}72|S(Jls5x z5Ji0JPlsZHAf`QbjP+Jmn^-u7WId9*y31$ud=*8u=b-G9>gK=6yjg|L@7E8GhA;t& zq9l(SR?Pay1#`_YnxoWA<$%^pF+RY93`zp-H=kf1m`bZWi@#4J()99zEPR{Aj)>9? zbJ%2{-VUJ^vs!=yT$= zFk>gLl&g#k?1=MYn+8f>l{CQ0*dF4^5DFtPSr3ApbsR}LTwRXPbn9l@G7<^IGE+gn zdXWb0GgSx1pyb$pbym8KK=D3)s}AZehiIN${%h$=ly@z8)3J;Uv5HuS*6%FfU+93{ zO(`D%6va9;oVctCv0;qPlBK>gmXFW$1UdTD4I&ifKYtKu%Su(LAR&P~L0b$UBR4H( zrCv|_!5)91872EDNqR{2N`|o52zK5a-Q^1|WCrYvD#}m?OPy7eA9hLc^R5GW1`&Xs;klsKu|Tk$OQ;_I_o4H2RF9o zq!2zc7nKvJ_37p7&V;lk^-&hw&;wx3Ag>=Omlj2^136%a7U;nc>>v-I8jAiJw<;^l z7P!~G4F%kQ<~a8W8Zk%?U52ofYfQwTD-p_o`ETQ2)^u(3uuYFCk*gg8*w2CK5-zK( zjeh6guuD1XNWY!H=%oQJ&DK%fZi3_&q;o%wQXE3aYMr|R$>a&l^Gk9~fokg6;`B5^ znK^1J#jr+8*@aB0+NK1r>be+v6cs~zuWBdSqTwb&EyS0k)?ST{u$Q2||K$x-AK<%y ztxmjOK92K_#Qr>|SN#qG{ASL9k8>=mxrpIp9!XsTSy)ruD^H14dmc!ff1^?MafH6|) zRB^AhEnDb5N@I7g)%5~JopQ>a&)Iql>#|{j9j?_hd@-q7DB?~n`350C>gCl1WMx&p zf2B0>`4#$^kBI>FgXupe7~`D=%Rr!^z6OqY-XU%vyr{U?WPwZTURUFuP*B2Y!-s*X zAFeo;kUz-ROPwOTq+7$kCb@_t*5WuxVxnAYb2O@sa25ikYs}xj@(GXzTus8=+EvArla#=MSW+*&`Dh5_pZfdeW2O z3EHqg|3_9oJm#Isc!q&v+4Fk_z(^i{+MqZnOy}Y_`PDqCs5{<*OJ_$k?adxGH|#TG zee&iyVMQ!im>YTK(CWXtX_D1R*%>xT*^DmCMPTX)8QeQ=F0NR^vGp}$9{P*snQ{)x z(39=}JrioRN< zu3cYo+Hq~K{lH;WhEU#1f01|$!oK{A1BXX*7x*pFU4#ThU_}>M_#N4SXpfu5f?x_#&A&okz|Z&xD1ey zhX95s8fJ>{NNWgKIX4c|yR1#fs8EaFVJBW6foMjk5G^E{dmteLD_T`~74ebx2a`n@ zU;+DzgyL1c8T@Q&6VZLh`K0Ft&)E~nl zEzzOGw|^2S3_ACPV1D7(V-~GSn&$WK^17ve{y{ob0Jok6<|gO}DimDwaO@Z;O|#-o zwbliBGW-JO@nTxnwwXuuNLLqDZ}%Ohy`y93m_Qbfd`U@(b)VrXjmP$$7lSzV_LBL> zXRRh&{COBTZmW{cjJNy!zh+hSiE$^VVtAQz;yTpe`Ld&7;5QwO3@TNA-ikwo>f#Fo z>!%2_+@S~5`n0U}j6r~9Nfi1(NovG+OB+CK<~MD6pqiAqt&nNdIsWiWdu5I>cE|AeJK~)R)xgFE&I{XawsBI*FCO$Aur}tb zGD&^c(a1=eJt|Hu`OA6Bn<|$9ZRH%LKZa^M|EIHTYOnTjKOo&yx90RT$}rAPpFXv< z{Sr~`^fRhGkIy|Q>-C2#B^E^cRi)Ik#;3%avzWu=FzEWsN3gLXFjc}Kw1K?^&^t2G zP{!@BLa$M(DM$~}aU`w}&^lDa^*35-?1FIjX4%V-!m<;g>W0O40fvSNMs_4*gH$(B zXuA)XdZo|MRp`^T$ocw%8=pe5m|fGnHd{*kaH^A+vrYM#Sj@k->5Y7tu(J6ly&r{M~K5WwU-kR_;4Qy2l5zbzk@SDGWbjAE1C-Ks;-&4aC~ z>gceR6JrclH`>(Ti`M%yzWerHx$>ebO8GnragG@H`(Ep80W zuYdgb&sEmR$w{5OzRuu_+IIsGZ|~h-yEgD`d%Hp}A+vj?OcYyN=(yMtY}_ivp2-nM z%Me*Qakjc4({Dj%Y4#;85fz5F>)+s_QT=y9H&%5EqN?VcD=X5hKS!K#AIb1;x0lN- zmEF>{Zxa+3uJ}LtuL3?rjz4Dtwx|;muu$fvOKnNv!j4ce7%W?$?f|BI$Xjp z>9jhLFf{niQuh23uN1gwxqG`UG7>)tTaV0O7g7|lL+^2W;*gwY zIe9&%zC{1#f0H2wu{h%8&su)NKffa^RRRxy(LnI_!e{*C{LUzyF84V;XN~@E z{ulvcF=w>V^PsSXyHgh_^X?2r8#<@vHq|H|)0h=q$YaScZn)Jtax2KqUFKON8kZQs zlUr7=82m({!_LXmMP8f%4KyTU^{bN3&q1qoO|GHAFQFoRUK~VuOTozDkUf!uL54!S z_PYdIY(qK!SDW&a1z^xLSI0_>o-TJD9siwe(Gx3S6_IZP z(-(lF2IG*yFlQboYH?8Dj-vP&?CUF$u_}9e_FXZgS*fzWg?Mu&12gA}WjAUhL(&hqASqfN}Tc?{{xlTWHQB$|4|GQnoU0F-Do|@bCC+ygD zx9eh_N4*lMzH=dR$vJv&g;s6DCF>W(Sq7~t)uF;r4t=sN+I7pbDq*U06eME|FSp|V zk3l4zfpJo()Vmgsu_Z2^x>7eHV=}GwVdD7S4MD4v?wS5$&kgc9i1=0ic_Et^6CZC? zI#i(DEuFFVv3VimUakps^YKbtzP3zXBv;ddb*i_k`Td+guBp}g7D|&-Q$&r9(<%76 zd1A7wMp32`*`Z-%f{k9Uy|tMq+ArD16qsyj2|gkbt~Wj>XoZp7VAGANB@!LRI;7Es zE!+w0%w%+=62GWDLZWTCJV74s6qC;}RH{wbjEhYVSI5&wQ-)*OM+=&A1FN*19f%wY zx1Fc&P6yv!7C)=jz$vhUReC8kGSCc+#X&1Je!$WeT&n*ul0&An@Z>dTx0h6DO}ZZ$ zTIsXgaoGR!k;AQtUe(`m_hKDa2Yf+X1YKKOs9d27GJiCu0fOq+ECpJGUSYreY|{^5 zL6?93DL&A)q527kOy38g3 z)xW|Jpw%6gcFV;i`GeM`6XV);S%2Q3jGhpl?@BReIM$X% zyMvXf2-r0YzT1>(oRvz@Kgk?Z%uA-jy}lYC#m={S%Ivq8zuX1AyZeG`Z|5rco>82= z!qtfk<2aJgUFLhpWGp_V^Juba%gv=MBpVpFI$!#eaWTkPkQZQuAI(^5a`Tl>;0Z6r z?S7^dHq2vYHg;Im-;y7hs9D_e(z2t zu7u?Huq|i2)8)}yzA+!Q$plBesy{{iC?Fy0exzTko7El0m6aqt@4PCaDIFj1i#>L! zI&?lBv)dUgl}zy1Wn|XKyx>K);JYVzJk|+&B_0u@T^cQ>4lJa&GhUK|NaO}7c58)rQPX@ z^RQ~(;@@iiTJL*GhkJIFS}k_Y?EbW%dWXa9ppnGpgwWKCC0C>*;P_@XF|S%76o>4? zu|JlAw2!z&ock!fZo5J7A4lpfs{Wzw%Mnxz55T08duj`$n#p1w=OTpy{GCT#aU$}> z@kjKv-sQ&(`o0lYTF@B`qa4(_BP|*^OrP5`+fH{hI?{dc?K3EJQ0FFx-g(5>D_h(C zL%p)C$t04fJj;#|7K~i1?o`n;mrd=E^mM@*MZZqu5%2hDO7}#F<4WVC$SU1xMXJJ6 zvnz854Yk&NNJE(;1agg9H-FqDU6cQ;(62`{3h0F~kO6-K%cK#&pN zmd+36L_=K75eKVYd!|t~2M(Mmx{L51ckm5Ymwz^V%6rRXUHIMzO&(&^dpA?*d;DfHDSk}iM2oiwFu}~fqw5V+&n)Ei9nydTEo|EaGjf7 zdNgglzKjmdD$BfMdupEQte{n$<91W+y3;>*l8fIZD!o4L*=}o|gX;-b1+D5gtt**=JzTEWRCfAn`;LsJ%BFq@_id+PTT4u= zLZoy>jOFK}cv3(ylUte&fqjO}5yyQU_J09s9(j@B!`|G}?KP>{I!9EDco>hQ2?8e8 z?UZwVsHzjX89y!$319HMV1;?hju2NbCC-MY#G+`VxLv?zZqc{Gfz`*ZmvL!jciv{b zhOSqO-))BQ`RV+@A;4JOxe|iz1-7zGRnnn6EPO~Ju?{H96>txE%=d&$8L&!@(3?G6QkLU#^y`%Kh-hqF0zW7K4t%vS-s;* z*jHl*m~R=av|Jo~rF&R86H>A>Od=0y?6MWASep|lGz4SU&x~kx`+*{tyU+4@qSx!q zWwGmX84dqv7W7bdE7JyPhYs!;PcLM=Z?_j@!QdCp(hTNgG*Sf+e6=lAB5)xoCuhen z|M+)uWU=!TKQFa|@4c%})Y;dnLqD?e72TWWyYA>>3J*ozTCHtJ{9^x>WJ1B{Kn_6r zGqcfR-R0VwMQH&1tEz9SMa@WtBV;7_1dbo}<|7Efe8xWmcT*X7!w#jYjr2#dYf%U{ z2l4LV^df`vnOH&50EPse)4>DHmU#+v5y~V!L2R_%g;{#=?wqkPx zOK9WgNlKut9ti;_<^3L^?d`_#>u=!(2YXM>Zz;CkX&LkSW6e$LX+u`u^_WGU&%PxV zyy_jP^kGlMRYy`x3K7uvI%#B?okI9ij=%+sdiG6LzP0Hhn)S81wuI0O1faf3%|w&E zP6ELl$Td7~uYRb<;~3M>`AAJgyT`H^|Cwg6d@&De7m}ZvD_3*%JAIs~UmsRJ?#P19 zqv?efBP z^K6^OuZKAhJxd}Qql5VaTB=QHFo5@X-nZ^M`%Q1MPXA{3qR62q6k9uwwi*Lou{ePK-`bMzGnon85V(Te| zD3<|D&CSlm4JEg$28G9qY_-dJFS@H9_*}U3bp`d(*m}9hmkDD%ae*1Zi^@4ynA4Hb zKFi(ippX#jR4g#(d|loSLgh+}NIu1Oo2(!EKTOc&Ucew5c44;ID7On8<4x@c#oe$~ z_$kkzodbt1CHXuC)y194xxH7T-8#MIUUAFF)>fJDl`&6|IyzTKEu{Ab5fygAzyZeD zhBRT13gnDbGM4W(m&tzX)MOr|48;nzHlNC)+CFs(m#7U)&L{iF_n5!+78f)veNq03 zOx6;1p&}pfAwj4SSy`?|%XXv!0OAP_%t5m0R_*_t8pR?LsMiOMZB~9zNcGP--OZ3b$Uuz>R!%FrFz%N z3z}9tni(qgyhd+iiF0OHD4L9pFo?nMyRi2d5O{xR?@-Fvl$&Ey`lg19X?`+Gu+1e2 z>T064wkEH}Q!#dN#R}$zhPU>EpNL`~6lC{W#s-~V?&7{^3dI5{o784;F#)py;=XxA z@*a9RHpL4R4nRZ0n6uL$RaMqLkrO(9hOjHFzG~|gU_$A$g@}0L-~>S!KM&&x)Mtda zU(QC;{3ua9b0=|~f*2pBF_Mth^MV1cd7Y7>=Kvo6Q-K)brw=CYcwl1`*7SLOFe$eY zt<&tuGs5c=!MiHhpniKIWA%zAYhmM_TdfB%p&(ve(f*NxLgdpUFhfS)qVk0+%*jw4 zQYU9Yraa**q6XtQTHPA_yoiU${4?8lD1Nvo>_6lK8Tu*CPrf=`NU>b*9qar3sN)Fm|!Pmge zq&WY9Lr)Lj(BTx2=J9OzH5e{b?U|yrbv`3Kr-lXsOW`PpSMgXh2}%`#h)T6cVd`0J zr41T|3IoW+4(UuGd!f!Urgpp{Js#Z>$V#>D)PE|ZkzR)sb5Ia`$qEDQdUCGZ#`k~Q z-K{d_=H!f#h_GgNTC7O?NW>M7loZaj)hMml&I{D3Lhji*wW1~op~Ik!BvbknCb)Ps za}4jQR?i%sa8&m$sA~?Y1Q61we7Vz|2!D9_ggF_&q(OqH)!!n6y1T7sq^>iHZ{e$e)Un%JDAey& z^zB<3j#SM;$1*b7?fWcChXjAV?=&;`Uq#r~v>*Kp)jFUI(UKPTfP`RsNazj1)^eGl zmqdq<{`+A67ohl}g8$Q+cw7mGLHI5rQy@Z}cZES>+`WTCC>oiaGNMW26t`Oe3r@Z1 zxq<_?*N7cH0UEJY+t7o_^vXya@+(l+`S~3;Ir%zF2F8u06P#CTHjukL`pyQ{Y65lT zNOgGT!K8^d7V|aZV@+_^neq#=$$ch&>o@1xb*K2lq$IrFJMXMy`flU#Gje={JddG% zCi~;gf`e?Urt;V=5-t9zp|it*9cQF8n)p$rDW>K(F03TarI;TX#dW`r_IZk0%2YT*O>uM{b@pHYu%rOCVHxH4mN40($@z7E+ph*$XK zGj3&iM-*v)(P>tB+c|sEg^TAuI7PCiHETLGIjOdDe+|P%ycKs!Jm3vzlIQgJ4i6y( zF)Z(nL7fBr$wnjmFC>~A#v&c;9M$!+!7@*{;nl3n~BLYpB}?iF>#8vvj+sv z4G<1_EWMvR#+#1zeM%=VJFQN)qqDTsFP&?6SOGr#Thacg@orWUw0ZKlFRCo0I)Vzm zPoLg5pLRk+nZBS$xhcZ>Z`Pj$1gz*?tRSs$|2lyan!DRle=MWc&D!-Q)3S{ouR{1vj63BDQy zzQ*KXogzLEEjl-gYZaUH6`yq;cOub$YEP@t^!-oA%X+&G6bZFg7N+(g3-Jp! z!awNsq_x64)g|Qz-x7pht@7Mp;;MR$k#;dVc)HZPVz-w)@JT%H(hGZBO4JV2psR=i zIHo%Qlv4H^*{q9?6-a?fvIR=mI|Grl)8T-(lA^agi7K3Z`uis|gCq6b8JiUDjaMqy z*JH$4{PV$t(p>=P=aOKz<3NIYjh|%ib4%osSt=oP=@_v~n^1{<$lgN4QA5@MHx~hJ zO0S!5KyLFUv{!IOl4LV!|b`!jbq4JVnV>pK;C zlS6D4(~ej3y}{XzRyZkm1pDmL%~Eys=c@q|9ivRUrB#xyYhJ9jA9DZx{p$)QBtL)t zq`@4$y&oD~5WtBIicw_1C^tpya7#Cqh$|JpKAsV za|jkoeU$S!UspQpaY+8~qOY(q!y3;eg)!4OiK=4!>t^!#!>XT}Z;X4ppmp;x_9`Ct zRZ$z4|DA0yF)t1|$c68Ol4*od<_LK3+MjiUx)eHV2%5+}W@Fg+K@d@l;{*^rO!QFJ z68h6EpSayRM@{^Sc94@7vSx((9f&fNVcMNf|v~bEEkGr{J%cg{4xL=8NDl zA2`4|sofkc*@$_Yain`<{yp2ct3P}wClHAei-!6DpCe<(MxrMi9Ta(<4*Va>pHoqt zPr8_I!W>BdB#!@?T(U2WPVd@gsi}3mq>N`Ts(5RnHGD{!TGQ@-L3OiIJ7QKt@y%V|4l|iIJeiw>qb(P?L`*$~fptWFIQRoV#WQ4V zT51Wi@-J;=zXr;ZAHVRbeHe!6o8Dxk2(`Dezo_lZKKF{S+)AyXlER|2;tadP`6)vx z*3ibIQm&^jPykK9v|+$P`n;`i7)7$ClLRJgEB$v_)n0x*quduO8|4EXRT+fIoHO>w#1)w^YKoTQ zy{h_gv$2-0xyHlkRtX!7TijM__~$nE8G%==4;q`H5AVpkAFG=evOW}Cs8(8NyryYS zWt8Aj5(l;R>eUl_F+4YD&CF6JF+m(qCih-%C83#RQGGksuL)phD0Z8xy|&(_Q4KK4<8y?9uKcg2k^Rx$Th zB`>bI&pYeJ>1EnB06I&^4U}MM9V^Rit;oBlK-R~d#Gd2Vr?h`wq+gOu8)GB@Gco*= zs!`paGB9d*gdpioOe)Gcuh z7*L3CUpxQ7dTVY-=5YvxvQcmXXomh~*P!CV`I$Z;t_OeI;oY|(kx-sp|FL{FYg=zO zvJjpweX)u}JHfL&UAKJkH~OX4;}aK@_up%4rd@e&*~?dacHQYXg_l{Di3?^?aVpbA zPXM795t-`n3**8@3@|Pi-)fBiTMLF`w^wn6hG%%gr)59k`rJtdk^2n%afTmK+t2EWf89oOTeAu7av4;`x6_QIZdi#FDljmne6)Sy3te=NL+I-Y2ON z=?;fG^g_h6ZD(JOAwrN@m@R^AWJBTLRC6e(>X2BwkTeWL!vAG-OlA zc9WXf!m8vW1xBN>(}j82R{0wiNBXVvrKR>R)?dFr)#v$q|;3p-; zu(#&kAh2m#yml~tPHhv_6oLo9he`nS$yN1?|(VWTO$DQ5&8*^i2 zI1Y{jn|DnDzVYl1c(ePSSor=yY05^#ygMvP2j`dTGGhExn2-CEykRs^#ip7ixm>Y0 zJYhA`+nWK>XZggcZcxu#&P7MFU)(tfXY&83boe{r25bqKDX7A){Z@{8Pd-`Xt1d!j z!2D?dGCbnnNI?tB``ZPvFCq~4a*5te^KvPbxY7gt>GZ}ZP*-9JooduFqJ9O z9fl8Lj7vA99tR~5=suFPwEYK*%x&L3 zXlo#G*E99tz;GTT;BUzv?TF5k)8g<D4q;6%3*?Anu=b9E8{W<5 z)}6RPd}Ukzp{OXL5*HTOX!x7vgv~vpxD${20+KKsOakNR`U&&)uXpG*7vdrY`ve)` z!q*!sE?*n0EC3dK4># z_!*R?4a_^Mr`-+@u7MOEk(c(P0WnOzNGw7~BTGy68IXLHn8IS(SvO?rM>b{plPO+| z-+i5Pj?eT6g_J3ZFT#&~=lLoKO|zeQ@-6~Ggyw;D%O}kh``ZpVO@sWnklX8rma{pZ zg9?UY?x$4mYwfQ5#+cgd{O@`sq`1K;68urc0Ij^G&vXN z*4&+!yw7EQ64!eKVi4}^5Zb)*3eOl0HPWz3R^gFET3}E7lep|)lf9bYGH~PJVglaRiGRE z?$Zqe$P(p)9fP^AGCG{U!6tPawyojS_}6)ivu<9LXn@py6zwAVYLaqR;rsUnTASZ$ z@r!eOq{gkL(|*dEUuhFPm@e`Qry(TOndXz^3%8mtN#|a1`t{}cocpwqy{t~|x1XeB z(^0~urg|HpE8>wtqoQnP))p4%jfFf$Ow1dyr?N#EqE8j}1!Kdy^Ep^so6_dY1el94 zkJ9Q~Zn^NRa=ImV(25G=2D&L@A5v)5kgM&gh3-)XUE7yi_k~ijs ztFlifp@n;$r3sg*V?3j^8YV?B#?PGxQo>9e_|E4933{n(5tnJ|>F8i>Q1wnJR>ieCZAZ*>rLI!Caj;sAU-*r?puQV6x0SSd8rgA3 zHT4Y-fY&*AfdX;@C7va`Wi#y9`AGhMGOilyNYYy<`_Z(a>6 z!;wPO6IrwfLI9nzg*hQA6Xfu9t02q%j=LNjZfpgUFI5hc-7+#%6Zi6~X#A9`;_%AI zU=N|&lgDtf$KWiYbapQtSne2Le|#SdgM!VxO7FH4=<+7)l$Vwqez=D)iXWRCF^wkO>VjTAr|pvA&-`gpJLEY%(;zX z4z-en#$8}Eu}$ho#`a4V|Du1Qn=XZ0kTNihBn~5^H20gWt`AhPyRuJy{7CQozMhJh z2vS=~$-^_Xgz&}+Alow+;b>A?gL;eebO=gS_TZFF2B*k((T-y{v_wr;-k@wKk;rb z$1%PjZA&^>>K^5SPweI#$v`D-(|7NEo32;3Z?cOsytOkhnqBfOhHgek$_bnWGzc(M&s2El2exW-{bAH~xl# z`{e-_c9XWQBh@TUr$!AHI{V(L70gOF5^~j>$e)&?Y^KO0v#jD^C&=5>1Aa8kjN0xKIaOOXR)7l`&HFyKHO+)Ig z#O|;6b|@$2pxMqC`{o11Hz6wGF*E?sV=P))cR>Y(ZrHlK&3PT;Wi}_sbsgTp^K3y2 z+yIE!aNSH=7ngy7WQya@*O(j^o(Ww5Nz^bi0o$P&pz6DA%lt6!1Huw_RF#0I&p zok?{glb#VIeN5bm2-&W?YUH%j0X}2JaL*f-=p;+^1!#38S{N1jH7}7_(qRRnpYw)G z&;5Lsy7&TPdwpw$cgy~PU@JqVpaPCut)`IXESUD=M}$LynBLpy?s$z$5=;+oT_+lg&j zPR0ua>e|FRNzNLbJM|{ojdCx z{*`H^N&_$Su7|#!yu)>~jZvQz{ukPxQj?WRt~q^bn!cLKfAUq@Na7Mute$Y#hPFEZ zFTY@8cI4&1$*_}t!#Fn=dE{hhVtc))2yFiMI~!CxmL7JKw_k8JuXp^lMTukeOfj)~Upq zGvmtEp)Et02mZ=Ov~_d}vM@gH-mrXH@YLlMSd>iOum~la#X&x-aoR+O{YvG->pZPeD=!FSBgjY{(`rUwCE2FHtGf zU^%cq6NaM}h{!lnyIUezjsCtk3>JD}>|3ow6_5WN0hwlL6gkTeEqBv{%?b3h7 zA+bI%PIqaYRl0>&O^E-A#7j1VX7Ah}h#r{>Na>-sliU~oA?|&+ao&9gQ?<)Gl9=`x z4mPE$Yupn?IyH?k^uBIv3kF1bC@N(7t^^rds9LJ?f$>qM53QY#`{Xl8e&YX;_1^JV_wW1oB}KzXNM&ys*<{P! zTS8VYGcL0Ci#wz2z4zXVkS$6!$)3p;mrYi_&zJ7|{rNo}zrQPaJ;(Vx&*MCf<4mKb zf)-QgZcqFkOroHUvSrp3UtPpbi=aN`6_D4Xe`w>dTSg!Fv=StxSB_OmS)7fM?-$j{ z;?rs6bv`Mps7R5X^|~kGhw?$g5$#!Sn@qT?Noo}`7wz<7g^s4OTMh&@sGyJzWX+83 zS@DOzK^UN~{#t<&&J+O+=wwq+O2d{9piBja@Y1GCIsWp#`0b=zMz*ro;J#R1^Y2rj z#a;@SwXBx8<-+b9!E5a%~s+wq80PNYkhFFLLH+U!@V*ovQ& z5pp=m5U3vXyb?kC;JT*x$5%Z2BDiJu1TnKj@|P3#(L_u>S^fNFg+TBbJjY`WPA=@y z;ld9#rmyCbrvAObi0l8XCX5vpCCG!Fx&j^`d~bvMLhJxM{#BZPRvZ4vL&3nx-#xAZ!JM&0e<`lKn?20fGWYIS^p#1#=wns zh5?*3gTY@1NcEDDdS~$!Dteu$HuUg=hXU(fiJd$*CaQIL*7sj`^2LcpY4exAG~-;> zlhDD@*4PD9r!rQq=GPCNO5PkVHObA@rPs>){Uk{m9C2uH;xU?0wl+pOevh#DS!0{T zuCgDiCufJSB8_tapw#GE3w?O7WN;Iyng1-_EI0K6ydl~0fY!?9gn zs0Y9gwMI|>jCHb26G^5ddFlan&b^i-*1%bA{HBZy@v63&yx!Q}jr@1FKT{iz= zf&``}9bR=k?Awv~xF7qVXyxl8(nyiX=d$r({z$u=HTT2axTo!9zUB1#HM%z{J7c>H z_p(Ytb*ES>hg~drr7BtEEe|AE0{g`+BZ`ibbvGI`OX2J{6Ltu^6k&v|f-Qr^D5Sk< zfYj#kk=QE)ocv@N)V##|acJ>w_$NPv8hMmasui$;g0)nc5}?BG;!jZ@{rSWKVZ8`z zum$tq<_jUTl)aR!(JPoe!47?}0SMZjqVfm;LInrUg+P3>1{lUBXqqJ36B&d1bWdFv z=x&@OB#MV`+-NdXUAb`&zykmbctpX#WAy|W$lRWQ@)c0e$GRmb8;rfMOOE~X4;+CLyXi7ngvP$OWdYL_^U3J_5;>(g)eq)-V#yFl2m!H$NF|S zZCy_{)KSHsmH9v;^0dU@O=sfp^uHSfs?)3jIx|=e-U;!4-U7!Babx50kDtFH|SguZ^B&Kxxqlw$He55xpbE~Z)6aU27p?LRBSstyI6DAvI>UfX7Wd$ zcKXbKNTgMLZ+G*C~KHd&pki=;CAvWPbR!*{z<_{JQ=;bSw7W zNjPXHMtZ2}wS#^|Ob++QM!{7V8IcldjUk)Cl4ndtYr4_Vfd8JzIS?%e+CSQd0!giT z#_QZ6fC?#bo(GOEQ+11$%gm&Y^Q%piC08+QK?6i~n?TZ8m*WoZ+Hmsp^?-k(dvN2} zctijuJU(_q7ab_c;Wh!>ShdGzaoR}bjI6J6xk*9mzWoNu`vjC+# z_n4Y-0s;hIoO^$Zxx0DGEFyOwT2-Z1FEZIYl?WewZXntVeqRnP+$axLy{5t7EbiNr zrq<2ocTdr=bVEkMimAYA%~19UQoYATYF!HO~P)jw*j5rvnoiZCD7E@tt;>~WHn zIPxw~&x2+<9S~vtS;-ae4<0d{nMlP-`%>0(Rl z-PEY#)~Hk>ePbhhwEvownD3gu%F19h4L40Rc)y^)ryxN3g$9YO3nk_(OU^}QVdus1 zusbWH@Gr2)&is@hCe@o)pS#BSM_1whwrTZYaww>xn@Vcs9dMzKyl048pqKw0(XyAv z7PbQ-LZ70KAK0QuecCNiWliaHHY*rjCFir|)*a5%1y~@GFOie^>lt*`_%Oo;C6%Zx zb+)laeXB@Scu^J)eJE{hw(ozBZ!Bx8R1SA9DmEwVZnw@(glz5$0IfP7a{%@l$2EV_ z`%)z&dYn#J5}rzZW4$lt(srfN@r7YeP%VFeU=6*2?Qo968mi9~4DbHt26l?AKr>V@ zIGqGk<4RYseIe!;b2}!SnCI;`+OHyfVG{-i8qOb@F|oBTuZRbDpHzDTf%Mi*^XNrx zeo{m+TtxvT`z-HtE@+MawQd7H6#1XOOpy8i3`t_lAeBzyFOrOyxhg)_`&h2a&q&K5 z7wQTqamwr~#<;J6K9vnLda*6Ge|nBwRy!WOBgs-!z}YkZYqYZEbrB;qYE_79Ka$886fLH61p>>v97}CsKQej5>fGod{IW}E`wwlXB0*Bo= z@7*mdP~7+7e&_ed<J`|#Mgm0b#MpmnN~GMEG$k0#NO=ri8aH)ejRG>z zPOjqNiTOmBY!}I_@vI~{_2^E)RBB3!qW4KT${m)@;jWtc$tG_{+LdKl$g?DwRYCRD zQL|43#2Cb!0-Neo|DJ!|DDDcVU{v6;x&do_5Lu;TdR9d=xpuYxt$Do1!$C}(v}}0~ z7;$$m9KSSmqzVCj8Q2#P{BDain=t-df^bv?@NVH?)2q%w&*d!AVKzWaE{?lz?3Tq}Y4a&3NKAuNd2Dw#ZuE1>Yad~y zMdgSN69QdkyVd6PAsLEl7I~fL&z`;0#q*Bv*HJb2CbX^QbAL-^0wCz-<9EQh)Vj2( zSrIdUk$p*5w1?e3*6@f?@OUwMQQu>Wsvg?l|oW{D^>Y=pZE@pyy<)~Eed5S3h zAgPSx6u|=;x;eclO#c0CP1Q=-TD~EnaqDWOKcM&9=a6`FoCNc7o9LY;VF>D&wmOIQ zZyh@B`sv;UYk-TOpJR3st#>4n&BW;OzIfwqve>##109U#|7-Be6VKzrf1z|j0?At~ zTuLwKx#jhKYT_g(U4pqD#>1Wqky%H*l_Z)}AD+zoqm%I>g;>IsE;r1|5kE%IQjufg zEVd>K=qmWB4|rGt`OwkbNTklaj(CcXKyO?0miplRExZe_En;qJ)}_@C7$`RkQHlL9 zit4cVC4j-eHH zX6FExcJll%V3?Ni9ZCiNS`$w4g5fq!ALQm56Ptv7=7p%H?OOn73RbkH-TS`g zG<}RU%WSS`*wb%7-(yK<^)#_o96c}pF6Thbz}|j#rh%uP<6pb*}m70n=+Q*Nlrvq&38A!`!^LFVKFzRVSx?egA70ROoyfXn_T9#Gz`u&5zzA`q?dzgFk zYl3FKh|b>?L0W)Z`FeI)f9Jg!%WKBRH;Ur=ZgPA9%-SxpH;T;0htH}x#kni?s`Qt1 zbHEconBO9!$`Jn*H1L9DwYgo_+M4kOyYOd`z6b3Cn@($92s>ii(A;R;NeA`GAId5! zw};Gm6b)Q-6H!%Do9kp)5jFzVNu$3GG+fse_@*78QerXttSzmMc%5)pwa$k_@>KGb z*=(*xNcet2z37pr}_36X?y4rm|?2p==X)DeAF{iZdH8ih%%MM^~Y zF$}kRa>CU|HViiAPshpr0$PQK^Y&pyx$ch|YFHlA*xr_WP*%j^u^(A=J&ivheKD&M zD#I1YjuO2QRTeO5x!@)Iv*9}%qfTg{4yk~wPBb#G{^?=~K{2%2O3RoV>T1E2$O|6T zA6)9fO3C7^5jSPDW2SVtua9!LR)H*idUnbgkLVtzM2$JRFyPGAk^9{*9J!KD%Xo{k z%Z0hx*_d%Lxv!|p-u^}`%U4<;TZK%a@7jH;3>;d>!$EN60a)T22-CsT0SU<;>t_m` zVqPd4E@HwGd|!9S67>`yMAkI0D?1!}e2f$QX|g;+6D&(V(f-)jk+J{WZM^i(s^L#s z|7pgR@lu|d*9F9N87uHc9zFX6wh@>`Ts9uY++$#~c0C|nge-}+lJ4Yn>^=h^_)J0y z5HuifDW~v(cN38&9BGp)7t)?`M#bKDo3LtU@eHGD=PAKZd6y`MG-+d37$7#S@VQH| z5a`gz*IF$fcg8nO5J~b!KmQWhEyXYu`r+wWYXBg^P3Rj6%s!#EutE9Gju^!a{ zC%R^#NAhH(1}rvvBFi32aMyAJwSci>L0M&n z5>*JOlV_z33GunG5j=!|SFj!}q_vekqCDMlrSnq=_~`lf!l1cafR@u}&v?%HUUaZ> zE%Fw46yilf{f;>$9yUl?I5<6eS@8=z%YDp#X!_k78{`yM%^kn5#*|L03&jZBPVlKJ z7QnJxmcFt`3B5|Pf~3J?CZHkflR(fz%k%m9kdkPfgdUSa347zjHG*@Wxl)>Lx6lX_ zlp2=8cKuWkQ-nCMkDOsn?^^c`-UD+s&V6B$-SAN4x&?1g<$%V-3f)(1d3;@@zz*IX{h-TnOVn~>jTj841I0FEcWY!2MxV{*xD&pW-m^$S*H7rv z#F@=D$Hm2|6wpHB(~bL!O3S@O%?*M+iJLWCcFGa&H;xLoT`gXKJnPTO_x;zNAg(IO zaDiP2__`Ze7VwWb7(39EYhj8*9L&$@wDHnu+gs~{*p7b**!%KOkX%LI^>PtF8)8Nx0=EuoX z6Fkq~AM%sToheeZx~t^yD&A*$Xe+HK(2L9VF2l=zEy|MZ;0i_|xDOvletDyQJdpmf z8_DOn+WZS(7MErvz=)u62TsHH)rWC>XcaAz!lJh3%4Oysg8Q4 z9POol1tCN5_NU2E;(KAh@1lTSO-$v>17#=iDO0Xsy);oolDX!J*%lijtwfw=c&kck4eFM^4t*gdYPa@#Cd98#mjF*N4chlo##51I^%gWtZGReIvYm z>x~FGrgr$xZy*Dwmn5HKaH#TmF8M?dMvVOA5+k|>i@O_4t2pQ{dvh0{H#Z*ywB;NN zfigQB4~0WW5&P0yV#?YV%lv)Iv9956DurpTM(jfBhYa5U~QNMKflt%XzYf56)* zegIudZ?6X9zJfFZx=duq>b(LijvoF8S|;n^44sO%sm z!Dm^8m3xK3=w_$lv5qKPrEb-EKtO;Ta!E^Xez^bnM4Im8np3Xtu@H11nN6uzaU~0r zz?33{b%goG`F=N+vdS6Dk8&2FID>+CeqJRXHyi=Bd|v^7I$ibnZZwdQqmPMpU3c60 zNNFUk>fV9_UBzY!4zx`0(x=A`2;VoK)s~N20Ue~qECRe6htDX6^3BNv5We@iLAZZk z2{vL4c>9HhEkU4sf!Tf~DgPPDp^BZh-+ko0M{a9`lN(O3=_Kf~^8>>Teb=AODUp9$ zn~jYvAh1!v%qHvgr}0W!a_g6!v&tq3qp~+WX|-ael%lm|9;Br+_XrTowr&i!6WlMM zW1M&tLXpN6<&LO}Dt#>!I32^v+942BiJH%Vl(_Q+byc%4t3)c5HN{7{1S)SGaX*9@ zu~kR~Tr4`Di2dujiKi)VvGG&K$?;8c7@y2)^0)1CkYVJlc$ zlq8)sPk%t(A^JHoAvs)YoJJ4o^9>Ca4F}pXpumyOoe8H zdEbU?0UBamr2pXyB-s{QU^-zt={FI6ehZSvl{#HhR_m)quAeKL>vq1=OuZ7jla4&* z>d%@`^vmeou@LX<8H{2WkVos{?8Fo`zFNp>zIH#NC)LsJ&_B8wi&Rlv!+UyfqiIaO zh%&M37A{m&tn!=@f#|-R$^v`wrf8*`;2Dz%WVsXcjJ z2dYTxCc@Hhdl&&?ItO9p%OkJkqrAdD>>`kWp?lvLTCC`GECH%d6VujzH5lk(_iNGvC%B-_(b)O+^v?S`PQMG^ zM3nNqwwYnOuBk*XD^vi4ti*U9F`qB!1%0(@VDV_zqz&=c(H5vjE^&uzK;apL3AG_U zEp{Y0p<48It8TlosB3{0UsXedUI@pr@v999@KiHz#|Z3aN;#0A-zrcf^pGZ`+qnv& zCnK+9ZFUO19P2u`ixhk0O6IBIz|+iBEm|+T)uf`}L!Q5sp~|);c1@XEcm)_oT{`Rn z)Z>^EpQ7&JMfV&Z2?CNy5CSV<$Qto4e8O0h2 z@Y+*NbT(bpt=bG}mrWPpx>H_qduAi;ro27uth*YXpEd+B(SB~c1UsnDxn4mV&a+A3 z%(`RE6!xB;l3R*jZy>0vopqvY6~c=mQU!H;X5K{RF+iG@c6OdY0O?mWNsr_oQ7}o0#T2HuX_NA- z;;A?D-V@%q_Ig|9q8{^UAGEFGdaI3yyHOe-IpE;yW6n}p%;U<$b&p@e1^_vdZNl6^ zJ$`yfI?D0qjzaxupE^BxGfVV>^UP5{c{Z5<+w2tGOW=1{^mdp{K4@Sqc`?nQTqHI2k?6nCU3%IO=pS!5$pHZ`K{_`mc@Xn+mnmPSQ;YSatzS2*7 z*CAg@M(7b~Qxb>`NcX)+43*>G`fKov;D#-vM}Q4Eph9LIjlF1Id(3=DHvc> z_>d>dBRBWGu*5(naFc~Snl(pstDBqAF6SRNaKHQNEI<8NHDG|Wbkg1wd3E}FIukRn zVR*B*8`9BE5#oRz=Sr}A^R^+uaWlbdG!(AARpkBnAIV~`py{on8R`5#==<@K9Q0v> zr#}xf1NyUi?vi(E%vQxw2g~l#T^AWgs=d9vIdCxhyl*TbZ~X#NPodoqx&HEu2tl)8i|<_U9$+tzz7h%Qzx zwj{U2iY636fN(dYRPzRN4}NL#1NwzZBDL`{&?35Dn32RuxQf!!hb_$?VtaJqR@^{X z=KuSkUpz_N&o~ddSiksvaoo~yAvwasxk8zU0V;@Z)TiJiZZ~25m^_2N>%;6fjO%$9 zyM0iJtIz@+VUJ|FieWQ@Rp`_S2CzH$^K0kN>%sk&6X;@Y`XXyR1wfR090Hl6Kz%)$ zk(ayH$1W?588%!Ro(mmOUNp_FhsG$e;@1hTT_`GjYZl( z8`C$adwJ@n+n}!df6%Qu^I_}$^UkJt~9pSwVdsj89uPwT%&*r~-G}azc{#GKe%gv#yx?gWV$ zpZM*Fp5-&t4-4JgeC#qdWRRO)!Y~f~wJAHz$X17Y;?wn*+I*mWcT^oGWP3zSjWAbY zx@R^rbg|!ZI_D_>t7_&!YlQ*_k+}nVU!1FQn!dIAAYKN#qKD1Hz!eZ431@(lIgxAo z%YcR<>CfKb#b^)bT7Loq77`msr!OV#Jc>p03k|*}>u1mg17jCEm=8ySY3aMhS3ljz0-k?G$+SfM?FbYnh%3qEY?`a@3Ty2^+?DL-Fz5N zhVe21_v5d67MYs0N6cPM9;>Nz?)1(G`(|c$)8Uy{zoX`VWqtpNo2%-LtzERD_ENi( zk^7N`s%sRqF_UuT$EdQKqNGHFBg>Yyq-@qLS9Nr4tI(sZh8m~s+Y0TZ8ffzB29)~2 z{WamKX^gE#Z8#B=jLG`besLmpu1ph^oObWtTU~hMV?B)Oi?r_ni)#rbj4HgMMO1A>!YaZ60#QGXpG@5v536a7&14@v>4bd z<|~j0A8y9GniUyi%wUU+v}4ri(Kh z)Li6fJQ-p=&IJ8d@*PrL&JUes#rGH1-{Oy`bUSPW>S!Fs^->lo>|v|&6QP<(Pg_ZY zQ#wVeeA zeh@1#CQ1!BsKE0yv`))1X@&`$Q0{@ifbJ^F?;j{X%DDDcibg(LJLGb+v;P}Z*AkTi z2HXuk16Gucx4?L%i^a8z{vOUEb(6sQ8C1!LgQt?PA){Qb9sTSkO(S~pVO&A8aFoRkyI;M^`qJNjJ&lR;LL;_$%FumW1?h`r(MV?OdP`}~54kC(x#^6aavDzH~s4|yei-E=(| zCU`gd+d75Rfb)Z8Z`P!I)WWVCeDl%Fb<`C8ePMV;_-S|f#rE-vH3qWuea=+#A6V)6 z*();OKauqyMMKX}rnxg~+$3M7r&CdVq@kPPbN%OcKS!|mJfM{|(D44bGO>*3W@j|= zJBFT=J26#?2KTa;&T@@IAAS(jS1gV|Yi|~k?gGG*pSeShTk7+s!-0aQheY`Jv7B9B zWcdy*P8$f5PsaT@B;m62)~&ADAmS|-0+e4C^ubPLv2cB`+igaiZ*0DUn=fwX1wye* zsq4*jQ0WGjto8ffJAwU%4w^2X#KS?sQZieg4vAT+w+N`aGbc4p^KOtFpw z{#Ob%-{d#@*dCx)3Bk=um#P}L6lu!!a|3WeJvGag9I!a46be0x!QcP# zP_(p@rk(8v`jHhNRBR%9)wOkzj+oT`O(-fLj5#R-URqP?Oxl%8+0)jcPMv`yn!4_3 zPbF%M6RxTJ0o`NQ2e|BXRiF*=?IO=&1k&e^t=P9=#Aj2%pDrz&`c`f)xu6Nm|Be@P z(^>w$AKDTPgtLD4>WeyqCB{bX(FgjxI56O2uU=lJTMeoMhEZ2$CmiJuJ|u#)zEbxC z?9I^W0Ym|p62klR7f*ieI5gmCb%RF}G`ROk1$nd&-Kh``_Bn2y5boPPws23(NLs5i zyoS2%eH(e#W-{wg;Ijo3(*xvRf8UyrKjk>kP+L@|9y-0Dtv~2(t<} z->bP^#xgykDckBnt8R;O`Z7qvFZNY!Gq>}VyUkmSiRwP`3I(*W9rv>Ctmx^>k6K=iY=Qkqiwzx zZK|UvRQ@|iz+o6|eyda!8PNs;(MpvdO$HHfa0a3>p zbK-f>m^#y`v(U|^A0*VrcoW;qKNQkuvl!=qU6|q5+IKxzHlzRl_~Rqo8{g+X_>Sn2 zrVVNkDm&N_RbkecC;OURA|;A>g0~JBz@d!=G|mQDl+;y5Gs$=N+FTODmxrqo7JX`( z&ig|l*mcn8`QaZ;4j{|mbw#b0I$SuWj$Gh^d;xZm#B*9-IvAv}3f&_l;2>ot{X%=c zMG_1Y-XI>OD*+RneHmcG`eZsVt|wZEzq)z)b)_zXnSF>7Sez;_rRP5%OniEk=R4>+ zx$OuI!=h?Ef^$E_pi-3luB`bg^yDS%lLik=v+OOH9t3@(nI0bbyL~b`)V^B8Z-35z z*;0em&-FLyTQtu71dX-bFqLOG2T-LLCW<&8^>6d>lbN+I#dGF3#)ZEmE}}J_xq^N- z(ixm3y?`^KLM+HgQIVL6+hE+tT=(l{7cBK)AEIa^5oAN_wJl>ou^xC$N3VKS&6};R z(Kuz}kiW29{kZDY@aw>X&(&UZ(+Ja{vx{GS(dX9Buf&33GOLBs@&|7>)W<<0x>@q3 z6WMhsq(UTHq~3@YH-PC}k#bB&01nU)|6>s>mCj9y!Lip-C*Mc#g%(hp=-Djn*p#`C zLn@}ED|y~P!@nF7%)zl>NaE0fol2k^U%lQNe!MvcR|@uful%f{ z`I>42T<&DjP(0QUQAE~`kQP`OI4IoSxxg#t?)h*VjtNrbVp)_GOT|lnI*5{pyCR8= z8Nwz@!|fr-f#|@FEj1v90YgAMN>a4aKw`10=|-CuU|^rfe{W>wpLccbfhM=?qFZWp zUA3yVI}AK?KALH|JSjI>uM4sc^6!7Ud-J-TB{~u4FQeMq&ZoRXGrHaMq9x~+KK#N` z6bYI=W!m_soeMq#Y}Q!*g9P6K!90EaWfTz=V67jiGePs>Y zMP{(x$V__k(~kk{I*0ep6UDAMzn>yiIMZO-^wn&)P@)z|c#MsVb^o(O>RL=E6ogVS z73rijFK+3+%t<+;NnP8O_C1-|^1&^)n&&dBBi!peyQjN0_>@)#=55AWF!xG=&xiSiI9m{ zp+7Nist&)X%r=O>U1Z;E`b`Pi3cKqN*hkYYgjt_`I&W315g~ikKL_Y!RACIs!;{&QZWY+(312{Cq;{7nBWUAJ=-*S z^Z>k_nU81)W;KIeaJ|5`j4hIa|3W+O(3`Zb?vgi9Rj^!N9<@?Q)ipvXs*f%pruBZ!I*ULEP?dhCDLN@pJ{};>h3~Zbl=O@?iDD^ zu4xxR?dfK;F0X!maNEk%l6PUY%Q!0uvH8X|kfp=I+0Xc$9CItYG+rz^$oTI4C_?(h z594r6y0|iBu!{)T(2_S1$gA1+^Rn|>948(MXK{KEHmFW&Hq6*8E70!pskN}`o`S>} zi*Hs(64j02Ykyc z=3SU?)P@2S3Y#V*cI^0$iO#*8;x1y^4Z$0ztrQ2LtiT5sk=0xBhrbS0>kQ)2H= z(er1=$L{WH2lnm;^+jJ<8XZZqv46$kUj~DH4Lr+*kY_k01+!o}Z07uG@ z^kXph=$u|s_2Z$l$IBaKH8!7|G8OaBScHabJ+^Xsgsdy3boc-?pNslR7UktO&CS5F zJ}Y}7qeZ5AXkRBL&bPhow+X25p+hWM&NjR$sn_y68v@(>BnQJb` zwDM%Y#>Y7RNZw|spaMl_V4yK3SrKtWYxs?O^uJSU;kDs31G`SpBKf5q=Nsj91UD;} zyy2hP#T`vv}~?M41e>_x%}Uzr|{X8&rwp?r8ix--$jwh zrjgMC&}w|zudH_=Bc}b;%(tG|k7f~Ct>xT5%2&zNA*A|Y@g#9}qvM_0ckdzv16@*? z5AY~{tjLoe0#IFJ_R;k!=^o)A!?MqhGkO>6D}nFU<4Wj*zw7VIW02PPdMBdk8;bJe z3H6-*kEb$!YU;2h3cg(@uU41w{^>dVGRU$XMpY5PX;x+~pl7+}L_>Hus3;AUee^(qz ze^lh0z^snE%O!vsmUQt%!y}H+zGEr*L1co*QQTC~U+=6R_l;lV74)!BcI$XNH-w(c zm>WpqO)N9GS+pzSD#S29WvDZEB|Ir*=A<_JS;6mh$oPb+*>X zz&IY4jgVeY2$eoFOq8&#W1RAiqZx@Y&nF>pFflPP*Mky+JGV!5)6i&$BB$?)8t2ZR zR(O!^BP!5gOTtmPN@X>?CbPptvG94zUb+njpqn)Tz6@Pst`$$uuE)_n>)F`?m;$b=&=Nivop4t@+>MQs-Kyb#Gm<-GmIXx8@FmrFN@nEPu z0g)lU|L`HRPf)OG;>MX$(yE~>df&$sfYIKAY1T&g*#?Pi9q^E+$ms!ArIM6MRy!;%j(8%UjgyKcdGjUtPlI6C)iW`wJ|U};vT|ykJ|vnpc)C5xlrss6 zieW!J==Y6GRZDnUJ9Quk<=O9&%hP}9WuEPjJXV0UF+#f^gEAfjwM9zTsL==qGiuDg z3YT_hbYx*y4sfpOstz4K;_TsJo~e{Of3eQ^yvDBT&SGX`@-1CXhnio~<;RyJRt_1u zcw63QErG+-dx)L?6Hp;{BzvSG2Bq0c&9NG#=G&j@S|EGa!e8vbJeJ#|n?OaID;93% z=lYIqlj!Q{=L~&g&T=s#{@nh!+v@$2Z|`Dq#z{s@7Pr{r*J;T0Cpoo2p=-`ovadI*KzjBkl2rFF{Y242edXPTYJNjK zHQTGb{PD4zUfh?;x@N&V>EqL&lYo@wnUBl6=VYHo~*h7p1u6ZVkq2FwLK0z!) zlz)dMA*pclkmFAhSe0!dpg115CS!EJC?~+71hfJ)_Q1vjv@*`eNXQdHQs9 z;E7I^YIMcJBV*gUzTIz*u%U3C1j9#WSskaqB&vYdp0X7gN_qM1%y;0@BvxuNf~CF9 zaydSg<&Kr^3TmSvMk%_tH2UEMcZilJ-nI9jy9&Kxe3SnEb&8=jvB*2|;R zGGLPloZKA>53CfP*-I02#PHK1b>W*4b6L66l=pkNp*@qp+-r1UwA}ZEh8~4PGDJ^E zG>=rpY^s_Sx_llkL1H0#X1VcbGdu#SIAoF5mQ~%cuUs99ZChG1En1fa7xj%v@clbX zdkmQm?kZJ^R=%1DFsWiFX$27`+4z4C&Oe|e^%4u)7QUUS4rjA>vu*b{OlBc>y3QT(goc!VK8 zsY$}X&nT3Geq1&bIF!5`!lTH@s=)Nf1nHT2=bmzo8a=6k#D**TXT~FfwmEXSYW6X#Sf|WPG%j>K1g|jDh{`v^$z_TG%t?|* zae+$&%5%9jT>)I5c%{*L=iW@uT`1T$#(zTk11a0i8Rrj9@;y) zv|!oB#*ZlcSm>uVYf69FDnq-QH?gO``dznT@6nU+MBoUJx?Ib=z9YYD+V5Ki2M1yR zD8duWeE4U0R6=|HZEutE!0k#i)nRP4;DiK)1VCfu&*6hQk}f z&-Z3!5y4ICV6yUQ3kxLBMX;l{&q3oQ&o)*Exj{65iLu@mDn4Xa-pAGt+(Z@&cBD=) z;Z8k77088q2;4x|Bwyw2q^GVgbfiaK;d3=MTN>O%kIpk5K^}^Z-vxv#y;HPV(1d}u zcW<}ii?oSYr(83hR5;I)eS~s&yT|uZgSsUPvoKS=fD{-Zrg=Tf0FAj5O!ZQg0#p4^ zJgbxy)D=eBm*Xv18vH2@@3*iPwiyOK=&>~zi(8wK&{1Ij-0Z)#XyWMien&C_MhvYN zW%&1n-%9vEt8dQ&FDLn3QRBZRvlIENcd`9MYI*oJSjxv0w=u69OXD~x|N5!bmQviP(d6Dh3b_Aiq`ybZ{rRi1@BE+1INV zxn!FJuHsAi6 zq1bqrl5&u&$#!%!*P6wwIiw7s=Kdjz>LVvh>vIORD0tzPuek3lQo|EL*X?EfJT50M zJh@JZ)0;T)<|j47ZP9z;DqY zRH{aoVo5lJ%aoff(7V#W+3CCzP z6VYBK!klUb++<%Q!PNr;V!zHjkf{bLXXy5WZS!FOmfA&;eE+^|zR*Aa3cS?6vdh{X z!#tV{q4lebz>2SbGb*x$ckZvdnGD`%bMkbjMF&b+GR6_UlFodayY}O-&}u|q6EoxS z3Pp3@6%O2}Kdrl0bY&zSaN68Tq_0jv5#8VhJh*2M0~vQDs9QNs{QGx!$+GK#XQ?JLmE!$`y}K%a|EdbEy-v)03mk zM4K}N2Sqkit0iUuk}e?}-O9?!0I(3}hpHuA|K9pR$)}RecLIy|Fy-?hJzt))-{q+&=Bz%Y9eL?=bNJLj}l9) z=b}5+rLQQ0*}Nvl?Ts9iNr#r_xWkSLI2zZtyAw{tH&B16YsX|^q4ipyP7(txVmn7EsNd0s>(+soavBuR zc~?NzKRECUbOqy1_5^)j^l3mu_&bfYGKth+l&Y07IGDg7^%6Z(qd5}01KUB^-HLk) zR*<_0&0jRckPu%-@lVQi?yHyY5`UTe?g7a4jIRJoBPIUW2CoK5F{vGp2oU}iV>~z2=hB_#VK5K%K7_JP_W;Y315x84|Y|Z^c28_yrVLfW3%Rva()k6 zWW5(pI;=0q6!hhdLEm08BdebL9%EuknQ3NEwi#M{F_Mh$0yuV1%wYfuWR0 z67!kiF1ZIDl1Q9XY9}_k6b4P;j23pU5?IDMAOVa2Zc=I}vcTcN4EMtV`ujN7a2YQ+ zrDb|mjibHH>I&M-F%mPu*?wN#d;!h8UsAXmLD$ymorzu-nqm5z?mf{Ho<1mKvbIyUa_>ml+O#zJ=n=<@#y2+9FXPY$#|KO?85-8P-+fUoCuatgz0n)m+Et zDkF_r1mnXUXoIfvBLjh+=KEV7`65S8WE>cUy%w80*z6=bk>h3wA@C}=9&k!YIv0XO zsj9P?qSpv;@H@@T7SfWQmJkbsS?2$?MYgX%^%m`5-C`AHWMs_wVVb$$sd(9lN4+{- z?`@Fe1@lnnQLla3x;^x`?^}H@#h3QZ+40&QEScb+S$&(V;8v->BE1jFS!2Co7gF6K zbu>bTH%1*2_Mh&o3tGMmO49bEH!`37`))El!w4V{6oCqW zUzX|qdRt_4*8d~wy92rUzyDwMNOorS9?6!K&5P_xAt76+>?oJAN4AWJh!lF;t0GDW z31ufMD`X|J-?^`Re&4?n_df4AkMlT>bDrmX*kGv`U|`dhbudGsG&|7?<3dtF^i=ZP z$*W)f8(q#szi*aIZiEnGKN0wVJl_PJSSI%QodxX*S-ClezvW=3<6Qr)jGkCjp7l2f zH^8_ZKjJ;hYA}+E?xK1;qcI?nTyUcJvw&5fJ!N%oL?`=uyMeYh-E2&7r^*@D#rVM@ zKO5deU1U8;We1QCF0t4M!+6>gCtKKVNA6Yy-6l!+jFJGjLIiwiwLmCz>MAyJ%pjg#jJd9bjv4LubAdCHR0++3bBk@Fe9 z@L1>SK9aTVy}PHMhqbl9uy1Cayfd6-68Zkv2ba8z;2t9JPZ;qbyTn-)0TbjD!S>9W z6Rxc^=vsVxLrf_O)oZIb83`}#`Xb~#9Mbs$6=PGakxIC+hZ~HKZ_FVjH7>XwNPZB~ zZfKEReB9E-BAnYJmiHWe{GGVFeyIc6uWPT57hb=6*D9L1?`v8mSB8g_(zywIv`+@Y zrJ-Naou?>}{|A`9`*g!ptHoXkxIx)tV6mPDgwI`mKqP=-3K9@|H50~^paa1)w;x9TRC9_ zok1^Cvz{|_Dz7Ug0N;1#!kq8x0x*Z-?EkiSIm_NqHxvv-J)ovn)sy%E+F zB*+fU=ls^~TqPwX*as;zFr{kdT;Zv^xv;TM%k*M$KkOhfoN0E*VmWM$r2k4jI@sI{ zdH*+`%XFu79tJu>4D18uH+!|*w27^;>A~%zIS5;l=lbKgak+qYpNEVAmM>1vC3NJy z-A2vhhS@uD$X&Uw;Z>aw1xHJ|yPLmJ8?< z`s2YWFkjh+xS7D%0QfD0F4UOLUwR0Nhbu%gXM8YGqR3EBbU+u;9_g5Qm`75+%`-vc zyOjaS!tVaHPQwPF%=p1%=vV-R-niH`dFI8Z*AqX8S(%crATT4WZ#5v9M-jyAK?CM1X z8H+Cd4@4^q#^kYi>u|-tLfTW)IrHd_#mASr7qfV+iB@*X5pzr@Sho_4^CQ|Ln7zl$ zA{jFRRS-^oCo_JbtC9U@Z2E|DspY{y=>Zv>pknfrqY( zjB+r=Z|$H<9Z7OW9B(vy-uT7>9@YS)g+gr!=E z+pv5$uY0Q&86Q;#5T?7YmjzbROo(oL?5{_PCuGoQnpYv$Y`Sb*V&oFlA4hgU&kG*9 z{t%LIOyQG46w{6!VOkq4+3eMWh|8USz4B}c(V$clhd0Zf*Hw z%_itqUMSE8qaq!EqGsQKD(mhQ>*4COuCsaI%Y-*O{+>mL**(0H%w)wfmBRT0?8^9g5Y^g!2Vzo^l@ViBU}ase>7zKRx(L(g;xbu{}Q0$6;M zXBr*_$iD(O(u7+U_=Vwii3F%J!Y|0=iWA$j!Q05oB@<>7+i75gj-3bIMJV9C*Y9cR zfcYQ&fc%_~0kF0LXP)AEX>k8tN;agJ6G!2B?^*WyC%eCEX=y3NWXnzy9VTdvi2vN) zgWOjPw=Ozn%KMs;XJLX|;D_vu{5kxSknTDbyN&%|FQiNGes1d7m-4e^Jim`T zLRQR4w+`lqzRr?ds}JoA8+h?b*YhQ;E2y5uT=-IA z2qOlVfydDFHFUL?iN~H&=3GACA1+hy-j(r;3IpiEfvg~VdR)rv>o`7gg0kz=r*kl_ zTl#fa$-Mii;cq1LQu1Et5ewHJh6Zt_y-2&#=vMEVg#h-$UxNNkI}C*}jRA!A$nW8K z`Z1;!`M-UpGs17TO)TLJy6LA88Z#a-vvxaZ2Om9{EF3vbagAQcSn+thZgz-CfvSUh z+*+@VdF>b11+SzysOje1zi=J~nZLeXQrMuM^pYQt(T@B$Mbd?r#w)ShL@^nOzf5!v=__I!I0To|RF zBoMu848YdO<5!b+*gT?T60hW`!7!|jDJ%*xQG!ifIf}fW0HD;tM(!r?AXB$FRpX@R_%Dv^Sy)oFw(@p~?h!hrN0DA+!TPP2V3e4hf1TtR5_w=)?wW30Hk4?#L6Z2M)rO=JRS3V#2 zvPW*pt+-ZORCp{3=a{~5${bqR5D%^!&Vsg=-T$?{WMT#V>Me15=U-&8LGC%AlkZ{r zw3?$~QSYp6_~P}Tpl{#I50|XbwSov^@)Mp~?d6TvGV=>*wJ+fkrxVY|CIu-y>h^rG z|80f7Wbk}}cjq}wW=V*z(uXSa7X_SHl2oUMp#$;7=#|QUF4M0wiwBqLZAGVEy;ZI# zLrbx(_F1NNutD!hhAwOWvKaNcsYSM9VuvoJN)movb=PMt3*=2-jm!&}@5}ijaFns{ zk4z)!XS%Es@yzCIs%gHQ3mIX7ZD7Xb@An9(}ddU7sA2YM#58)Qk!xW_NR^zU~m> zgTUX{Qhn?s%=VG?d|g=kAx+WPZOhx+@4>{%XVpptNL1d-xZdMsiGgrO%AGd`y!5Mb z%AOb?v+ENVP*Z-y>mxsSyNucRB90Fe@%56)=S`~lnEVWx-z+kTQ1xjXA8_K+E%gpJ zb;Y|7JyzY&G*e&v6=FX+z>yN2v-!(iiW^&F??uy#iniqQgv4b$mO zd-z9DpW!ir#5tZ3T9W9}oI@7&cwYR-;T$mU&Li_qxM;r_zb_ymReBc{imeH5m_D67 zy^JWk%5|h>h-*~mvlZ^D=B!Vhb#`)YyQQ9b@n=Z8cGp+4=)iy>eEbLV1_*- zd7LzB@(dz^E|_?R&U*+V$$a`*1=aAO$0bygIQ`pB()xcaHjeXj;ZZtK>M$lEY**aL zE@}T=T~UuC9+L(Xe}>kdW{{<_Gus60Zs8N?hdg)b@y>?{p@|{daHE;?K9=JLx_^XP z5^Y1w^?$aB3(zvP|7tpZ!3aO>u`y2@@x<`MTF@sOm7}2{+U+e$_r>Y|w(Or2-7K2) z@cVOrWvoaoUBxs)I}3&e`)&p(TV2wB8qo6S5tfNYRT|Y#TtRio3tTr|vOi zo=B|Q+V>>5pe6-pba0yF1<48@KXx$YH<_#4wc7{xfjVDAwCUrozI3V)a$|Tda2Od2 z1jJ1~w);RO=5IkTuDaet(EW`^64hW}$wMSuTeyl_*16KKktZOIFVVKU}NxB1gcq+mT?f<6- zr3S?BGHXG(j%Dk)xnDcAGTbCf-&z}WDbsq4Y}O;EY|-&^i&QChb_rP3BgAS)7mNfY z&b^0b{vDWT(IIxMUt(0D_b%|;@Sg**8H{VEQcRTdY|lamOgGEEanE_NToxH{M>J}n zx`7R@Xz`ceboU~X^2%RS*^;z5MS6$-%fYGPbNf|S7)R`e7QAPk{x)nlxKGrVqxZzW z4(yMsOE&CoT=ea4mNBt(4&VICfwkMueH#mKFf03;kaMZ*aB#NQR!+L(0Z zK5kj}A+wmXe6i;aV{E_qhm6rVS7K&pGvtDHw_5aNRgl@FbNYO_44JaHc+9kfp{98( z_iaZ0MLkMlL#0*F#PUXRmZQ%%f2G2{4Rpt?4R_>J-i)ur00%ZbFC3D|A952Oa>}7; z=E5_pu^L~uT&O{+h_L)%cXMdaMOrBW`v6mWtg|==lJde}=BgX%)i8A?YBq$}5CL8z zW01oc^#cr)x)Nq;!;gj_0z(bF} zxkaPP-&jbu%F9Yh((y-b2_fkxm-}HHq_{k{%v41Q_l{{-3S&jt!c-L>C3JH;UUw{7 ze@UP7__5qlC&wCw*;CZxHWvabH`(tcPOBEQKsd5E>r**$r)<7EgGP_=Jvrk=F^6~1&uMyaRelFDzt2YDTp>oax!#0 z3q+?);GeYnVurtdHf#B?83rW3()fzbv0=bBJ`2`>21aj>MY3D{|63(st39sZulYny z-y-9w`r+3Ejy1e*7H-#@_fIKS#IQLg{`ZogDhZ9aOR$q_-EZ;>okjC_wIdRJ``T^k zi^-_+kP>c`ps4|Lfpp~Gy|aVI%?5Bkqythx*D3z3+c!>0|4tFt_~Nu80P7vQ&MlKa zg42}O6(KSDaD3~W>)%4R?wNUEuEKOr4K{)5zMRe%G7nXtl|8)qW``~RURdDkoF00; zq-89grS~R5;`0$Agv>+kh1t~_j^}q4O?2jEx4N}_aQe(C840l>UO0^Kk?{$yCZVgY zEsQ##dVC^S*w?4JN^ElyQejlvfYS6M4NJ;r@-D}+WZeoB@!O|hd{p-%UTfiPX=p6u z0cjow8Qo&_``S5F`c7=dMBV>8b_8~fCeJK9>xu&yPDi_Wxb8xnl+9E5g-$d2o{1aC zh9}5uqLjpKmq02dJ=%5S4dfQEp-hN#W)%iE96tD~?bdc7OHx5P0Cbey(W?K<^Qkn|Jd#w;BP45q4#9TOF7Tt2-U-+fabcyq1<&8{LZIww1aJR^8K(p9R~ zE6kG-p0QdNL3u65Q^S$n>M~uhi_J1IOC<(R{O#!g zU25(`SuaUQ!2*%Dav?uqJZ<2hu7N>1uQmI&J{);Ip!Bz$zM3!=w4d*PTGSA9^oeV1 zlHdnN>nA<@tLfkH=}aU7!o&3BS3SXk8~Ne4V4aUv4?$jB2pMOzj_~%`59dOeGcPJI z?0)@^iJ|4yfJEQ8M}X?Z8@YjZ7*UgMb(43>ZM60JSe%nb@IJXI_TyLYpA893d>_PG ze_n&Aq-T4N7Z;VHq2sdffbt!f^7BdlFGKtN$CNqJ#Wj%Br{ggmmuwoxWi!?zx)t0U zHU-&*E7}t>)A6~7cb<)Bw^%;6dK`Y~wqJ4WwW9t+i>F_86g85^UusZkZl95pn|rU3 zXeZ4j3o9v7{ic&(zP|T~(-u;N*N@iCkh_@XLs&vveZ>3?)biJhx;ADu|C-F*K!Ka0gA_wip}59lhjpcYy3ifXzfN$ zx?y@r_w3l`UL>9I$5YDMH!@f0sn`ft;zD7H@hj1qfVSSXxr*}u4J432T{uq1`xzB< z?<5+pK(AZYaKOX-AMgr3HEBNGaPX&s;4lfD{0cxh;9OFu{uqX}J3();gvnYhsc z+I7{&vteW|KR=&}*fmYIS9DCBNu*S!rYq7w3e2?Y@|4Fqi+pQ318vjzHBO5Z7Yyi$ z@F(GELKPaT zR=i&OH4%FPfeywV<)^a8REdFAwmtX(tu6-6XF8 z3Yv&L7X;NADY$|k}E)D#zaNlsq=utw|0<8Xp_=m}CEogn3{(+5|lLX=S9h}6T>3TgZ- z@DV)TR9aK3!rDmjuwgu9NJOL2yxPm_I+&tkF=^O~-tRmuj>nw`odmHF+5)hPlxf^? z9b3r}32Vx$);0VDq@Ps6d@^n>6>(c&<@!mF(Jtv?C}-s13j5!FS$ED_(6DH8KBN!g zB_LM=nIFBlDbRfm0jmMC>gDwu1l_T}kvDT-MtA+a=cnfotYXKOaxT|T1>KeID813D zvD?Q6FVY{U2^S`xsr-U5;NZ;8g+Rd-t@|E-yk`Q8fhlz?U2B&B*ZHPBf_mBgW!ORw zH@HSUG11zU3M>Eiga<@J*)oq=3i0-@he76dmo=-gWlv)^qrw%&6lCp z%LuJ&K)(50h6>hnr{Fu^o<)>*Viq@AQ! z8VW(;!guk<=&n~{G$n-Z3f60W3>#6D=cn0XN+&O5Wlj{=@Qj|PBJ34ZYH_-T>aCg{ z9qI>2NFVJD|6Y9!LlfT4sIfI5;^bPD0nhvg?1FkTm?2<0GI^zijQy_Oh;4&RCCjII zrctAFy0x;K+txZ_A@cgm=VgGeH>U#>?K~>en83e+eG?I{c#s?6;Dhi4>&CI_b|w#6SBu* zX=o(T5#;Tp`?wrb^_H`l6PH{DXvu?gv;6fPGq1Xd+1gGrx4V;*?ggmoT=#4ITU?Li z5fq*O5M4z1Nj4_*E?eP6n74-8e+LV$pDi*sT!S4P1v8Lkn2Y!fsVs(p_W3-PED2X+ z`1>`4DT;6(Ej>Dq-AQM5k_B8 z4n{|F$Ao&w_uUmjym>r`s+OcKh|r8QzC!6#j45Aj#+oX3>aF9YuRO$$&XB0?ubO|9 z?mC?|d`%zNDig%>N>gyVpnHBp6)srD!lvG7h`KpfUTY(q!5Ou?c0At9(0?&G)(;j* z2rAs^vhi6bn)oYa8u|F>G|*=lo1}CPWCm)1plhnqK^yD2v+=s8PeP=MosktC;P8jh z1G@yt=$w&kL4$wd6H%Ud_Gg$?04N$zhPv=@f*9i%M=@ zAASe}%OPW=temCIuW&~>QAND?Dk|Mte%OdHd%=ff_)54&qNf`F?^JUad|UFyV0!x0 z+%Ia#u=Q!=ifKTh4rP8`=-*3zsY2iuYL~728itw-WaFL%d#3Z+rUXnn4KnAq#aJaW zuG!kEnLRuy#91{hQ{Np+(&y^HV#mcQF{_a}c)W0>r&oA*FkRNKD(+!AugYx%B1-JP zp2nrYw+5k}@d=G)@Mlv(1ljG-rjE04FU|2XAfBMFI4&^Tf>jzo<_+cD8fwbqn3~aB zb9@29!BMsii2}Ip1sDb>se1@_Byq_sJvupw0i9}d*bMXW7pN%eYwLezi~ZXmj9{Ww zD+72TxGycN(}Fr?7@-i+rhW`&QVx>1tu!4vJh=dK{Wtnp!%JIB&wt236L3nn08w+L zj^+0jUY6q3tyobf-QV1nvhOLT{JJnu)Okk4k9`6)oe=F93T2gY&#=6?TPS~H@Gza8 z+4X{(x;fl(G>*;|RojR-&&%l>&Lr1(TeOt^Xr-;3OKhOAk~=r|GEkG{=};WmHO(6H z_7HIBL9d(!MM!sb$VV#qBA7SK3NJoc`4BX4G;2Uu1M&3n5$ zi4%WjN1zKcI0Nc;qm5H8*OKn&jwM6qDzB!x$r#+~K*Ff0$%0#yv~48QJyPiZmPWvJ zP$>w-hx&6rC_gO-k$^eoapws_4}NVJ^)IMA_f{W3=pj_ai&n1;xPY=A<_$PGSAz%z zC-81-4%mL;XvJ1AzQmU4OwEzw&Oo-OkPE`%wg06*FnL4$xs!j^I`1^%*IxMQb?yU{ znTs7U^Gw`u)!860{~(f1^&VRAZT|SIfxM#u43#s`EnyJm`-^Ydtd4nhC|n1!urC104S~{}5uNxPnyLq*vD=uZx@xa=VlG zcBhZp=H^*r(#$XN?Z|-uv@RP#HBKYjvh;g)sSqcOw^Vo#5ES$V1eT^`jmGNBi_dOU zVj+{apH3`N$-DzwodgR4w4L{FyY5rIq;QQ!3qqks?wiLw83YPv0b5S?BN4v`PqJnx zHsEC_#tIzEVZsGWk`8!+;zmdRq0XLyD$;l!Qc1V3!M>6KJ7~r3oL0rQalQ#wBFkrJ zAC{v~M~gqHURUS5UOF>xnon8OX85(*6qN3A-uu@nl&O_F^6=pr^Wp3TKtP{um`&=O zv|m1Z4mc3^Hl;awT~*bteM^A8)2hrO)RTh@z9qRPeLOx8IKEpO1c;3+I(`-L8*O}- z@s4+=qTXrL5$_BtC;>EDd*WOpj~{C50%# z+#TODCE;bMKjVD1Qz^p9&zI+VyDI7h#z2~c zP=q3-k^W{quUngA`d)xhJiqUYct+BkBY`WUx9G z|M!w@`qC$qP2Tm#D6J_vQlP~j%74sTbs9uT?CF)O+~3}v8T%{q8chYS-9nNTl0aSA z^!_)lpVYy^!a{O8p@XSe*J3E-9$k*U37ubZ%>kB(pu$@?G7i|{&>ElmCxap8L+O^EC4p6hVqzM)Us6W$#28RfXkw=K2 z2BimR(Ha~Ha`?z~8V%{ha>el^}92@^V>zZUX6eP*4Vr4GSiLm6};oY9x- z?#r9Fc7GE5E(FVK*)^87MYc>PY|tv!k&JkNY{<-+XO6D#uGbP%$1 zJ|I?pjSFn`sPR(uqbGcZQ{gf$0iu7XKxj3rK6}B)TY>F-GwT9dwD7%5RMgl#N_(86 zq0;8!){mH^Y(sb#uTgZ}Hv@Xu%HuQKMn+PvogHR-IYmzM4I zmoMsrtpyndzSuD;l6a8Q)Fv@sEYZw}toBd%geA1uT zZ5#{2JbMLq9DAuw!g=y;cfolM!+Gvwkqh+o?T_y^&Szi6?QenIZ;)iG0T=k!*N9o< z1Dsfgsa0re%N6L(Hir8`6_VfU1y@o(ocou(YO7TS+&St)=%0t+{3Yh>WeI7=Q3{_l zWO=F8TiQpETpL|EWg78TfW(az-nrsg|3X3dH{@ojg>s&ZeZe+`9UQHN-M@^|Ika8# zApp=ut8e*?TSSo0G^ib1b-LY7TOWuaV5&AvOt8$yF%e(B6zdn&>1ZH9b6SX~>vcIR zX={n#&n3a}LF|X5HC26Pn$xoU!*33bCF52>5}~K12X#!Auqd%)UcXWVK3qF!kF$wh zfuLmOT$Sr6{c4K zBbxRILU96bK;1rRA0~}b3}%Rf0Sd2Q_z&${@2kDMl5pv?uH6^|egbp%;uB46J1`OL zuFES3UV%SydR?VBS?70*F?W8eP%nj@#;n|94(;a|o|j+^|scY`n{ z?lA?Itl=w-DWX$Z{@q4Bnw_H22wfm{^j)F@p_zSbnA-LJ9pZB~tjrbl>lcI_gYly5!MCQjlJ>+1 z9XzHVl!ls~+8(^tL^_uv_A3Sx8|vW`m10fUM^XKLd9=3Md&T4i)$ncTd2#$GD%Q8Y z%72d!&l`i6)Q)Ga)O(BSZw(D{ZuW3|b)&%ZWzX4d=$O&q@uAggG3leQ<+Wc^%`W(| zXdSo_Q&mz&|B$o7pOdbyBJ=9&nFqd2k9L3zIMstsl)r!uX-IFhzf(*X6wkO z&=Yu1ImetSf_i<7Bi|Aylw^&HycPO*;)kM47`(G_S=BfH*Y+ZL_@B1Fy(`@Oq}0%r z5|n$U;mfSW*lqpHJTtF);k2|rY=7IPrk)H-&d4qBqVGy@^sWwi@tMrBTagAqsRu1H zmu%dmO$7?{gZR1;>S&%A64(3!4sPsO^L4n-LbrU?`^&~_Ie|-J4I1O8J--J0br}4r z;gHhta*T?QDO!|$%lO`8#y&ZxjNUF+8yV}&Dk*$JiiLJo0Tn#`AR=L{y3hWb(i%0i z7~cEdGcMdQB$Bm=|INu^pY2n>Vx+6EI#&s14Y?|=uvc#(m}m2556iY~W27}oWfc|o z9yaaI{v59SedA=}aqg_yk?QNeZ+MfwO~NSL$LP)ki?Yv`u)cgarmG})>FT%YRO8oS zm$vUMuaXaj1h4gCv&Rl6LpZG2=vzun2+fs@9;Dy) zmLDQ2Y=2;5!ytIi!{>yo%E~)pM+f=okSJ(zk&|keRY81Beh=}pY5&I?EXJiuE6*82 z(x9t58{`%E-b~$UhU8+$hLZ@MV63*QdD*L1OEvb!b;faaiSG$y{QuM*cM#)OTNi>4 z*wB6B0kIZkkYn_qemzI~LWIhi9o`@CH~|NxUoDkO`8w>?J zdw)3jw!Y}t+Xvzfi*IiSi3Zz!E-h={JKb2$ajcKx>5ZVE!_&ylM{vRAiQz`yKl+R;%Bgz?eu$Bq@<7a92!`)TqQw(1dJj9|F!vZcxTCZk@cQ*@^R*CIq#*VUi9S+&cV}g|gr$fLm#o32Qm5EcC$ZXs~Sq-p8QkoRP!NiD=+B#S|?RGjoxVMq# zVU(3&YUNjWmm2m(nY}5q{}iv-79P*dx3tP0zi$LKGyY@im`gZDI>ts9ldT!d>#52> z*QtVq*M+E;9@hyEIt$|rA8oNIA<9BpvD6E4c7_UV9n_u(O z3Y41trpX=UkI|vCul&$Q(Q%ctn>sjihv$VF95dTt5FB$^)@a={$4-#Bzt1N#_575( z-hk7kgt_7^aeC$8{woXjMw5avrhaE(Tm|MfhTdgm=se6o{F5o+;N_ZLS;alwJg{AM zGTkjyozSVF4ZZBwB z5Y@j)AFMw{5}li95eCp)#9d3s1&=u*K3O3JFa01f=!z&NE9i=89S3PHPmIp_8NYYP zW8EK&J8ZVsn1e_D*b1YsBXn2>ud|XAG#2JGc+mPS70`U)1K(`h(o-9bddb>bAI$KL zDJHe~xMh@r=|xwR9uV0)4s1|OxMK=`r9|{q!yM(G+$*2xGyDn@F9~iF*eb9{>M+C;)8vrnntL)t^C>1*_D=QKSyH+D@=LHH^iDa; z-oC#_2>+fEb~E2o$R(VKiqM#V51V7}LhZ;qF=U%p zmK~c;8_Yrtip<85y?jkh_9?m1Rj=sa#p-wOV3u5CCisE2tIuyLs-DfVhVCWCol^9u z7u}E*qnB67dz1>Pc_*|Xf;w%Ub$ee%kR9}gZZITi){prfw}4C9&R0!z!F{+dCtVHkT7jsi=VYni93@ zQ-CLk18#f;p`z^VA<{uT%2qcc8mtRCs>ZAb3T0#PTRF_2)o-1hVSmzaT?jLVM8R@&+JX5l@elRVJ!Kjj2#2?RmR~} zvh(9flKSLsRqV~^@DAN7)PH&P+BTjRwZ{b_zHaJiBn0z3m!#wLic-y10#k*5?nc3| z)W&>;V$T709A6s&oj~KKRnb3MzSd||A+eA5@ae8m*|wVw0X#9Lff#Rp?;oH#OYn7O zV(V)FcAA--3%)itIkTZJA^4Ep!NBX;Q!pLMy872sl+(G?4&w};>N!Y%ovJ|mdDWSz zl(xM?h{c0x-Gj!Wx}Wo+$eB|S6YOEW^76gH^@)SCMkzib?eSRAa|7UXnqhb!xW}Gx zLkwhT#&kX<>G1L}Vg@{O4@i;e&NCZQQL6j(GvL2H{fvN{hd|$I*c0R$zHB8E-*i(- z0FcqsfpB++8g*slJwa&|phKbGm+brl$*u4Eo=Eps4c40~)HWBSO_wHb%;mN_qL?nU zc|NW*lwtitFSE1`s};BxTdUeXuwk8-`T{=f$umLvSH$Mw6Ebj`^0j8b7iO?{^4SX- z33sOUvmF@m*w#Oeez~k&dF)e}*Fv7wOcBB>Yo`_zoL-KZCzX5N@@hJ8($SkzF_kZJpaJTTLI+Q-t4=V6P0iA^yhcJWhIL+-tUhQD&jbN_up0YHOl&m zb|lz`wB@dzCTi?MQbkU$j_9eD&6~*y%CZZFp^v8tpNHZIX-`#_e$z@@QeEcT6Z<-m zp#1S51dk(bKw&|5S67PA#;tSqWTBs5a1%0|=bUJ@!aZsdkQB5+a_^2?@_QbMzM=HP*kTeRS~(7xvAGeJe+B4e`AxBn|Q318C*5Bs=9jJ3DR@(NOVgF{hO9 zyJaZrMfbnIz5{#l;MoJBv4e|yu-K-)i6Kj!XU=yete+g*S74`K=zh!3PP63j>!R{8 zKh2XWIi0*;WX;MwyQdD()D8_CIY&q)YocBZk@|;%@hBQ}IT4m(nbE_s$3W_9>a77T zcx<&W+D}7G>3AoY;g_=t6`vq`x4E9=?#+44wv!#|5g9HgFEY4r_nkY~#fml-cQ!J>{>yMuJ5`2u+(g z8@|LPBQ>`~yQ$G%$O%tb^FO==0`Pvf0a#1#;4<-We9*gm>-2ZTXTTw91An>v`0P+S ze1N_iPvQpH1j-sMbb3_EFRb*xc!-_-#(eDM3en!+iIsEl5G{EOI{kC$Gfgqk$s19g zO>01ShXSxUO{+h-bCK?pwPw1epozWz9G3ECXCnAzGbZ&{g_D_sF_YTWkO)bzliKi( z-FSryp(a0Az3%2op+uHn>Jfl?GIN4J!xtfV-v93cQb#Vpma^1YdD>%GZ$27qj5u)k z1OO~4OK}|F!zdzVE5fQYX*GbsiaQ&S2SyksJkA=zd<5bv(Tx8GTp>Bh zF>*~6LnNf@f5YSDke)Lcc%@W9vJW5)+ozz!vSA$1AOf%cRNB^in@WW(FMr3jB ztZ>1%u)j4Y;Z^6=dZ3C1I$j8L_L~I3hCRPJPkP*&vHUP`-5K=ioM4s&%GF-jY z%caNeWZv`cZZp@|Gsi1W@WpEmTJK*@*dMsRu|1(&zSYYP)+i?^&t_P5g||pUVBxmq zycwsQ_ly4WgL;+M0UgVf=<_z00}5gOeF07v$Vh|sv#bl*9|@c+8wH4@*5Ii&2ji$; z=0IaZqzS?zi(1)#3+!+_r+{jDesDE*9`a`0CQ!?1pGtf)duUNIe5cSa)ln)qufUcr z<{>}!&C~sCXGXkJ1#)hY4_Cy8>&q`!fDL_ur{^4d7NnP%xA5g$ED1i7-i;xM|HA>! zC*ZdeI1kyMix;{)cH3dmbm9BtgzPneEUb^ho75r)p3Y!zMTbAxRBBn;`uS)hdd{T_lxsDka5gbC#yQ>unNLlb0KZ$C-Qyf=Hu0uN80cSY$cjw8UD*Fou53MYzPH8ewRgE0@8C^R{ebT9Bef4m$BDa6utjOi}`%|^nC_2LZXGqGv z^ZZLaO$&HE(yzYOoC+W7J%@)cZA!;A$02{L{_Z4WP$?!7EOJP58R&4w&tCV#GAC;u z8D5WIqb3egCvk5IICIUQQuvGO*T0}>g4aHTDm^=IPr$MFOk~0H)1p8`D`(#xpFlz0 zWY&Ii645?BwRj@f4$?3*AAeym3TemkQ+SNKw?3Mw%VHPqb$u>1O!M4|widzM0}~;| z@rL&V9VVvr$o8JnV8}WU2oPZ~z}*yp8=+xI@W8|Iiqeu2q!#9V0U4-dV}wdJIu@sg zGXc3zQk4Nuhs+vT1`h2DS$`4xqo%(rQKclD=Q_u`=I{9gH)$+$=N^Yd+2!?387a#{ zt=BkZ;vLvT)Q#tsOr+h%T@|!3A7tAtHUd`YkzA-O3NjxtL5NV0( zG+Y=B8c{OL{UbB45=35q1uoKmz55Xd#R8+eV|sc_NiWu*6Ak35W2b@SRXi>D16c`O zP-|+Ma39y)V~FVEZ{cUJCw3}(p;25XOa$`aY&C{>+2}YDy-APXsyQe#SGFQGBt?lh z^Pxv|Oz_NWKsr_`rM0E)SQ1CWpqy*xIqQ%tCh)+;ZE1Lg_g+_ef=Pkij*92cyRY93ZmiabcrwS34S=}kMnXl5ML4nS!i z2B&U(A-vj!aa@up zXh7daK$E~x0+@JT<2}90(r*;%Rf$RE^g4gf1-U61r%ADsdVfQ8p&@mbC+IJLPh%V5As?I6Pn+umGfZ1in=#46P5Ok91b&eF6}&FGRP z3B(&+0x&A&Gm!1*TaNPKE>E_L9BiUO&y;IL^MeT|E$ffy(Y`Kbp z_7Xof_jasFy$%pMN| zt5J0+Z~p((<5s~zn%O_#NzTRY75-I^A))t|?A1NI>}(9Oaz$$Isl%%^F~OT4aD|3_ zzpU4Hu`M}~tR;@Npa@Np=Xo7Gk8SrZio>tJ+o@ay?rf-MJs)(tkwq~m-8Dum&vG15 z==7H~kjza+-{IcTJG5aN&)54+;Y2X%e}r@P`yYw0y^!2i=Yql;8`C{P9+&WE)E*CD z6YkW2LAB{x>(={S!{w;&I&M5dWRH;x$W_spD>bNbP}yg)^h&^vdZWV!@VF^h>!?71 zYo6;G3@25PGDxS&Q-fEy#{|uRIDi5O(vP9>y_rwSR-D*3t?02 z4-_tS;*2-J_@Zo*NA>7+H7*9sJQG+4Lm4CqJro|szYBVXb!0oURrq^{pJlJB+Zg&v(Cb+q zdX2EdFQ=(-nVXXt^!t6G^&okG(JK$%VQ1z<8Q`xx{d_x=^=WLcIVTAU$<{Y7{rf^D zV85MM!SIUtyh=i$TmrC~fq!uspk3j<4FUj4cEm0*4rikuxi28sC^~;B_uu}kENwb^ zZTowF#LmHXUH_x0z9Mm+Ys5J*dZEz5>+-iEMqJOBcXFI(h}AQKfByb}~6?7+I} z*jQ3<`Uqwjq9ZlyMIP)~l0){|m|$sapk&&sy_rs}BtJU}1TBKFw(YEJ-wwakYYTAt zz{N_nRw&;USRzn&F|ZwjzGmYjzX@df-B$wg{vw}_{2KONL+=-(FF>}3pN^1tPK?Rt z{zoAe+YDHZX=Zz;?$IfPYrDq$$xW)_|6C7`a~7_AuOrt*NqMzEt?e0B8L_~ z6{zLhn|XnqHiU?>kLQocc%!8q!d!RM7kMAcBSoWHs`xYeJnq=Pf4m(6wrI;an6f;b zJE*uL7#gB)=5O8_G|o-_7qHmx6dRzJay>HxjWoOlF@R6wi3^M_2{k7=Rnd!*>ExO;-%^H@d)z`niCW1GeWbMJ{l~+nw1$pn+`t|j) zQ3tij=rg_AU02?fgMDiMDSemQ>-=s8UO@qh2-#J28)szM{h{CiA*7UN&h_5RPoGHN#tCe|&n0LW7dn&jyTYi}N~@YwiS9 zsJSRt0Cz1CJ8+q`8v9 zPtZIr;}VdHC3j^E+4=Au(xgvuP1``` z>SH}+sBrtO6URi*NQz-8Ufx3a&LWRXcd3{_uI6kDlQ2+xKq5&S z;g3OdiiD;^#*FE)6Wz+zxyAy9>(bYnN|y8i%AUFGpheS` z#TNb%XvhU+jyDF3yeOWe&x0fhSnv3E#U*mJ_1o+5c#Wjb#{U(E4nNP6Pj)`b+}|hC z$ri!s0IDCs$hAQ=99dSaK%>yHOK*^0KNTiBZ^L1m=7x%RU4CNPw--qy^Ju|}?-|}H z_1Xrz%^9<*(GY2rHb3P&I(8g?BvI&Z)I(@5Cfh;D3nd1DU@(nPq$v-!gvTfAYpNvd zuoHyGCkB_fR{XZ`(&@xbHW?5|QGlPZ`TL7A4RLga5*CZ2s_W*esM`AQdORV#!{Ex> zB7ltpjnAoQUR&iq@Exr}M=_vvq|f+lK;zDVo(?z*mBOU*UyE0NUGxcCb?ZSx;rlj% zr{dx9EJ_oBbXm@~b|;PC^hN?yN5F{U+5NR(hLa4SjjB0{HVFKW=YQsUb8qTtWvAfi zXBBKa_)5PkleQ-9Kf=~fkL!D-Fw1CBdL$E+7|gm zGOk@`5_k&A7-51}K&o0(qGNHS7Q=+ zJlQc7(sxVIj2ERBTJQ!Z7R(yQ*;0lXYu)%T-8ea20Oa%^`_pg5@E5sp3DCj)-V=}j z^)bo-hV!Vzyv=j&1c0Q(RzUx6cZVvrf-ih7U3u=lmE#2=+En#FUQ9~NzZ6ICF>SIw zhBdPVNCls?X`?1{XU1rqod}-uJ@#b%X*>luDFwX;>erG!(<`r@u+_qnm@9ea&%A!3 zOC^1dg{oXWQktD}U!z3~-!(6mgf=<05D~onGSW-q1$c(9^g@XJg4+5cPcAg5%u94g zv-hGoHzbH8Bn3h-|DcaM5_??&=g;MH?>N9Wuq`w$k@P z0#1HZ5eAhofMS5hyz8wh8l~_?AMcg__XM&~5Z77WswziAoL&5&s%%==^|o#;pu-Hm zPouVB6b>G8XK=(gn_PB`u=+n$Bt^TPih|KOF%k-NOiQJX`aR` z)UB_3{4($cazhUyMv7q*6-5NIDQD?dG|iaqhcrX-7NHPlj7|>xcJm&8PUA|@h5POt ze-m4Xm5b)Q&2$)I%ZPVkqjl(>C$5#m`N6*C?sS}*?G;jY%{mh~!OzD8f(~-#iEzYM^#r9mhvo2E7fq9R z#>TD!VI~w@C?adpT%z_EV7_8bKwAzeHBrao1*_Q}iC+*1eBdW>C1X4?yVItM|4^iM>D72ySq8(dIY z1pb&bY0XVReu?6b$UEUlVn%g1_p5gr;!t z9DO4Kz|c5Rg75l|(KHvN5LThOrIcpoO#7yW$N~2UDTn}5&IP_h|FC=f5cjxxLVj~+ z>pc@WZ^w4taP6e3wIYu-#3|*TU%68ilaTkI(eeYyMQb0jtj5_#{${NJ%EJfaL$zyQ zOGCG{PxN2+y(}Cfh{wGySID6$W7Y^s>$BA4=$^{h|5y4$wvHUe`nrG47LMKic z?-!L7W7a(I3Z&>O5FfpQW*vEq*?FYmt`}lc0R0`c%N*>F0{% ztWc!P$CepMvW2WpIWlJdWc$ucoPhYLpE%*KDLX1-q)^2^*NIjANsb&r@O&WBPAHt0}X9?J)%6lPH{8 zwI3Wx?*!K<)mH8-Co(pZiQI#|(>rToO{+5m;$<~&;eYZtAp^vDVfs3-cWAf@d(EYqhchFFRK}*FO z|M-V*sOtYVBia+N-MO?Bwf?y zu~L?;hg0WIbjX!p)n6WCQ(H0K)Q+V?blqH(?RquQh35 z>!aUGtaV7Nl&4ZxjSx^|cL`q2pgx5v`1L2#kyl_k(FJmOlQh#d^!!d1Z(!}+qqXCa z+{b_@te@W^1{;A;(T|>FZ6M%oNpJzw{0Xe@(7K~CohPc{P1yz9zW1l_Dr|gAD1N>v znymKzC96S^0#=kB(XVusQmoS@Lhjb(CucLyvI|3O(M6@z7iN#?1QNR;gna}43l)ku zl|y;|5>%Ghewzv9DFZ5=E=j}T##+iLv0e2(LTU1OqV|;`*~}QeUB?bdf}Z@yOLR?9 z7G?}>UvQD~4IIZ6M{TMS&<=w+6)!56Cy)L>eIr6 z1}fj?$Zh~_2AV3Yw${I`&Yu);S)xC@)J~o>e-D9cmg)`2}=Gw0Y;ZrCB0{_dGd$u>|L+XL@4l(9YTIi zIn(1sMS);PkY;duw#`}%T*KPM_v%*gB_`e8duZi3x;Z=St>P6rUcDBU{tXZ`#C+-D zL#V$r`lt6lnF@~yL|uzNr+shd(Z{YP9&IMed<6k{^qI<5<&QCLC5=#bM|+IQqdkN3 z^rjjOCdirH^UL{kN;L5^-`Dm22>RZR(O@Hoh$lHaHVK=!j$yzTwLB7txIh#MBS^@% zrmk*S&4f6F>g{19|Bk|Kk&x#ok>07%xoMISn(U2lmXJ&UqpgO_Xr)KkMAUWfTmy+u z_f7=E)}k(Z(#iB31c*&Pq%+=j=F!@I@8e2RKLR+~5nW&LZ>QV{EALRHzoC9q>#;P$ z!6x{Du0olH!iHs4zxdrL*%3BRwFVQ5-Fa%YEpWoB%IGC2Td_%t!LE{6;SYthoPsAmw!ii; z-)D;=p)fi7*z8Iv(}Oqoxm*J8*37X`fr)ql8`ezY2W;4{@;L$c|3}v^?rZwP18}~c zdNo=!0>4RbhFd*=UYbSm;LTTYC*aQK1fp68St2=RqwIa`Jo*p@wRw2Wrd{tg(9L>& z1>LNr;n8Ou*pBMLE{cYK#n8uqAJ*}2p*yF9BD>NjX~-!03FP9m+`l*UQb?0{so%+l z6H7dwOXGVa|1|&^R2)|6FC(*3_L10f`z|T|s%&PVXF(O)s}j4wXXodqlyq!sITyLq z!gO@Kq|4|ypk)x>j-;$6uDsvHy^mM?l@`Qpir_e^uva=*o#y~Sw|eZ9_rt;0!wWh&a03o z&7&o_AYvyG-F76|3OaDkfM0zUoGU>ngACAbW)7nH38RWX^b`zHO~`Ho7@U+(Q#$Afns(gid!s5z?VM zd?9}lK(b#@8UWVVw2}WZ5iY(@-vn10Imr?(3+2qItprOMgH6d!1R3(irPZWNlI+H%HsvTsgpO9_Hk9EQ;eORz#SicGC?+ozg_7oEjW>uKuCjy zHXf~}Z~wLKI@vQB^_LdEwY7&(@=zHnI6c8#LcD@h4t5f?j(HU4q34k>R- z$7zI-HP7a=EDelNmTa<+?&aWA8pa6hVlzf3EecLp^m=&&5F zvfWnUs@imVX_!&tZ+u&p;Rr1;lEu#75n|{j=>+6`@un)p?loB}WuCv*M}0WSe1IGl z!@xoQY1ak{|~b?oMi}%P0$~3wsCeI60RFQFh=V$y$robe+Du7 zd*6b6EWpj^E@KB_ats8(YeuZMs=`q6_gXpqENuJORPL`JRP6>IQmF7@+0{AUKk_oS zr6|SJ>)A0L;O@h*G*-OuR!niuQ^5bbF%7nM0z;a2ZZmh+$FM1zCuoT|pl0*C3Hj1} zkw+yqKHk~E@IhL+59ZZnI;Jt-S3L0ke!|H~1vkghUtUnRyb9t`GRpd)Juap9gWE2E zp041{-dpHW2;!kjy6@rZ%S#{0(ONn)lk${hg4!>SYeW3lC2Lv{1kLqHyF`o|luV^R zW}0v(8XM^)Phsl&H`RqK3*A5r+BotcaU3m?=573iPrU>(=bb+f&v(?Kda5?N1xQVh)7kFoXa789eUzG*nSqr=!Dc2A1Ks1AIf!(V zq2gwvqQb)|ZbwLzeNxLgJLr~>KFX#S+TggVafeYWm+XYPs_t<=6hIu0q)ClH6&Rn< zdu^?Wv9Ji3t}QU?iKu*n(nJO|$X3ORzacNY=vM&>loae7KQ>^+1}F{-zpgRR_66(t zK8EAv25Tb@_L!CaulujcXcEll&=cO+TXaO-a*NUMR@-w%Il$L+D9@cd#ky7e{S}_y zb|&)%VQUaXoNm;unLv6LFok2^2STM8peTvD3tjf@!COZNdip9Y^Gh5!#G`th$!x0H zKu>};DbP}(CiR&i9vPzb6ZmX8~p+sjK8Eodza%zhUK(TqGme}3mNd`bha}4nRnS_oO zitgKYU(GDFS-L`DU=TVBlx+_j2L!9WJq$h_NR(NN;deoCVL18&EdYLQYG>OJ1z!QD z%E8IyUK|v}8v#3bL{*|Vj=EBHCOgq)42uJ=E3h-_|7ZE!Cs36c{!D`YuFGmD9LkmD z>XO6c^SCv1m`-P#1fUjqsp%)**+kud0~t~Dsj5#BpwFipcv`g}(e&!{`mhLT*0ZN3ttP@| zn6a*9MUSKw5rVTAbWuKy4c8OhAe{Ch7okrukB^PvnPYQd<`3DA$&ldMva^se7KM<9 zR;B0c_{fx^tlD+Lk*QCZE-v(w$?`BtdYlZCB+tS5`q=p-C@y*a?Du+s2O{(i(4;~F zl@>KFg%o}jG6kOSAJ zr+9ItB)D@g+=PU^oGtOFVs+zN2yE6O^^JL`wTpm3l_hb!5AhtodQ({hcH1XCyq+gG zE2HSA$~I?F$n>vhaO?)_mAW;0`aJ(7pCzyf|L_$uJ}#)+7|g9}dY61qr+pM6HvGez zU|&0oN$jWubI2h!Pb{)ZUM65pwh;dpvGwQ^!*MR<4RN)Vvik_p7zXJ|WB9^D3lFb1 zOY1>0i?-en8N~bW$7{xPLX*utLnW}x$?S>bUtO_Tbv(JpH)*V{B*VpCo;m)Ho<@%m zACD-45(77_QvFCoSFOY3wv=?=s`#?_-uwiOmk_p%IpBpQ!<%>pr$CSQ7{SnCE0wy> zooon<*|XdU0rb8rxKQ)wKb8?stPV|pCl%i}_sF>#0Ai0fG>Wqm2PGioZ5Q-q4uH{Y z#skNMBEOdK{!m`C3ReO&p}6)rvGwBs7TmiAC)McT(Qc!jReFFfP@QHRhW5gHXzBc; zDxdB(-mp=loc_LVe7KgFUO}|Gj~k09M5U-J>8_&Spt z79cUS04p(I^QH_ElBV8MfF`aVUcW><0c)(o&W{$|B5-xTDVpKzsFZ>kd z)V<|{qP_FzdYevhrv}ik4D38%zA~CBh387qPhuYF!*8JDtpF*Aq-y^=g~MX`GR?$#?Cg~AcyJEaP_3x=pbtO;H zpx#X`$jRr=4?+b9n1yUs=z?Z5Fa5r~8!Ip2xH-2@x*RQ(K{PKiOLVM}`VITu4}@B3 z4fH~&nE~g9$$l_yZW}5W6QBX8Kbbc~IVsLn_37>wCKPqn%xf7BRB9EYB35T6Xcdtq zXqdFY9AfmP0b!#76;jhbV1U5=c&)2)rY23G(LtP4g03xG#7a_t{V@by48*JcU(m}} zgyi1|35>m!%1r?CPU1Bk9m6ztRsem|*>1Uh3>^<~Uy{~5#CB2mYSAN%@Xgt$6EA0{ z&r;#@asnPp0O`X}R_GCd=%06e|LVdQ0Hn_S=aKB&1>iND2xZ)y^r1xUhrC(;v5yj* zZ&!NJ#vfyRo#~?igmSeNX;?k#)Hf4w!`h8qRpGJ1x&;9x_l~_i>sl&Rc_* zEmZkobWe5WbI+dY6GIkSxyZqr0&U#pR1}W!IVk&pM5_e{y?WO21@lfmBX)Sn!HM_rDqIONhczzs*@uexO zc?*BBrs4~2WS#)D3o$1$DT} z;ZL7&Z6RC)MXL}K{uNTD0*VwPj)_D{gR})<;>RITSh$83Gv-S}D#B@}l1f6>aD7lp z?B!)|*MFRWUrMGvHX!4KEYDGGIh&hagz!_nh9?lU6K;oEHmr68BsH&LlN6LBbdr!e zuyzl?*|C4|+Do5eDxEAjE~uNv`#IVnNDPU_P*y#EenlLgnWu=lQiCPY0EEw3&^Tw_ zIE&-!^r1RfQWEH3d;&ygnnubPV<-oipoBp?01?z->UzRO2d}bY#tqv4#KhWX+=jgm zU3NatvwYE_k2^wP<=*w$Ut{|Bd6#iuibvNVuLCjy4>7=KA)`WyqEs!8Ez*ZJk#Bi( z~Q?>8&9Gzv?&nPR%47o*?*Gg3uRy|aksuv4i9o&pjX9WkwIIOwj~!?X7)` ziyb$~g!{135!6wK_W0q=L>%UG&spu;#D~}>pSq}(o>Kh5UU&fnH7*3~T>jb@j2n^? zYk-#OE7rJ)T6TB8TNt~B;4cpCJOP1r3V!-L{Pe4nY*@_M8&G}~@4g<9RF4*^U$_UY zp+ZUnd_y^RW+_v($m}r#uqS?YZAI^p=DUNH?w#X*Ryx8IO_oF&s3DxUa9B`vWt|qm z+2mhzq3#ePM?y#>?C^pCxI>?!2tCvYNz8|lqV^q#9S~6iZ>;=(v7?q0kR2MF6@cg* zZ)IUpTqhH6i~P%TokqGg8{q{3u~LIeJl_!*MCr@)9SSfXgTW!wL{u=5nUrnl2X{3B z;q7Zi(4`%qbI_HKW^;*8fKB6$+kh#jI(B`57t74_4a)^6iywuH`!l=XT2$WqQ;IXe z<1Nadl8b-9Z8jGO%x0)-vNsBCam71w=u^|~)v4F+wjITFWw>%cOX5ZC@I)=KpMG%v zU+U;{cNllUus@vikNmy>;=-|KNYK>p=KLq(;p;=cN!x-hoB_&V81*#iAD4rk#JlIM zY1xuxGc}TwFSM$-!VYQ!xV8UwtrzF83#&^mX@~yl2&reHLp=7%)G`oN+`&5wnI|AR z%l7Q<_GxX-juOOR$w8Xb6M7fUf`BE{NC~E8<%BK&tU~JqlKItN5ag@T{CNG}liY(2 z<4&Qq9^WNSirQS?W|9}*1aH731ks_lJHNg^5QU1+SvPKb9dgd`+4ahzBW*!!Z?u1G zkt&*ve0H#GvBcY;As#z>aQ9ks)K{qM5ySeiwQ|-=6UX(3ezSM=H1C}S>!LbM@2CNj z*JSLnPQB8}bZA-R@|@xE*N4l$hx-7IsAVZsZjOvZ?7BRfm!IEDi z8hC)&)%Yl>eoyz*Me=;-QKGqcc=%ht8^ntkI1+PIU?R-Hll5yJCC0{Jywkn%aM3lR!Lx=v}L4F31am4RCik(AAhMpIAvlS1VY>#&O` z*K3SacHO2&TAVI-3{`4TV67>4RkL~H(T1R|BZnz*%>FRmZBh=%Z2M`o-HS`z--Q(` zwUi>hR~-Zv=PhuTldtc(6+NK85p*14ZDcKSK`}OoTtzR(2m4pF`(cqx<6fipFZ?+o z!RJ}?@n_r`yNyQS2RJ&WbfyDGb=h`Y&;2d5mnA*g3(DqgyJteDP2coJC2WzeHoaCX zZDviNf(L?VdkW2fljo6aJ5MbdS3UO}L}Y+5&yl#ORU8`d58Z zCKb_jC4s3zvij&1u;vSBJdS|jIA={?kIR`3Vo^h+)JG<_D4(N(I+xOg@6~g$C92p& z1vS2b9u=hBv=JR9^^&$aOFbFx>n!lxp}x(%G*fnZ_9ny(d|YH{jtNCPAHC z*=rdxe)*rF?x1+F_SgqTfI;9(>-~|61$U;@^h@bv76()mu>koM)VfXc@ zq&nsN39_`PtV+`SYuNZNkP|nzJ9k$CIMVon-(tX$ETT_06)i5NviHXbvFHiGwU^FcoJ&x?vx$Tls)^8A4ol z8VqkkI~f$j@4_3-Km_0oa|mAf68Q2RqadXpm&tAZ>znlnqu<4Bbqsak2zs zC1Z%MJZ{g#R4(T<4_pEubxQC`p2UwIRCCV{IS^7?#H^%CHlV1f*`k5(-VNB6Pa|^R zx!IMB*e+|C&CNMdmwDcK-*@OPzN}<4YGfhE37SJK@sr2Te+Doiky7DRU~p zyy%q*4Qe6X#9HfKBhiT7`pDK$mQ(`B+KZdm`Or=F(X(QMuv_erj@#3;OOR?p%pC7Q z?P-k;qv#-nP!hAOdXkE>uwoa9_#~-b0o{wL(%*`C1P6WQG1+(L$Fs70_~o3z>Z(vb z11`QHs#g0sHcl;;L<`3`wy=V}pk%L-O01xBFZNQA6>5Ziadi=tTs3%WI21Ppe-ZD` zArj`tjAs#nPQ-mDM_ecW%gz&j-&uzz&JQK~y{@w(Xl-okN|3^;$HmE$L$M*2qFYOy+ZDbpU5zgv_E}Ul$*~PU zxiW9JPvMZ67l-t1b*hjCn`Y)w+9lOm*R*i!@TX>7ELZ8ectd1q!U)c4x8ptqlfgSo z{Z@3XO=P;=4aqPyfgLWr3p)TnNjZw@fK#&grj`fE#cG9_=hF#?h758gm=t!*A53nG z4f)bH>AG0DU*v-C3eNJa1Y>KrnGLL$yy^E7Cy|IY|GqvnoU$FNl!>)EQWwZ?&ngWF ze0dRag=T7Gq^PRyQgcB6qtZuDY|N#uPnLX9()!Tpk@{xCX5??!Yvs-V2_+;oilNosb{{8wmploTi z-x5N7>wAx=eB7tzyD8E|1V_>ZC>iioNHWZ5fw%BmIMm1>T#=`&8cCeDd3&MAmz1Zb ziTh6NG>6f&eGf#Hj|v#**mD&XMEdCr`^Tlv#2ajO*4aeX%ABE^IuGVmtCRbg&C%dyQd^&|=#*rSX!toHF6nCY1h>b_Nc#`RucN z>x92x*V!sMa?8vCf+}=(;N~7BQ_MC^v9;W2uK4P5`7&IFQkjd8)&wz4f3X?GkOLr^ z0@AP5sx2*e=~=_LE#;Y;5ok+_Hun+<0h9kx z-$JCg1Gh$f*;`-y9AHAw^;KpL+*>}6eFUQ)dnh%g+MrCLKM69VgQ=NenxT1{AOEpP ztr@J=aAbkNe*{A*M6=$^5Q-qZzDVV&A$#$}7xVJVxTSL6_c1muTGmZ1S)HL$fDX#h zHR!8NTv|@_X(lU&9L6Wat$KB+C?P5MbiwIe{@TpdEd;w za06|uJ?!cB1J-{`o&8;P<}QG^Q%6&2?UeOWwZ@uqk-nX$_eT@Ni*$Zf*KtWsxYyqH zjY$gH|FK!%aEPAkWDEhD>wHUZS8n< zw-gLq8~F0&k_4lk8LSD`S0xGZtdjCol4ee*ArtyUwFU(v(DuL&8_c+vzEz zSL8650AQ%cvk+xEirJ2}T;#xB9U3?XDNvJLXr_`+0fj0C^r+oWdN3oyc0))?Fz6eF z=up(79}di(41wzeua z*B_N%TO5;buI-0!v3FX&W3og#l(j=hi}u}aK0)Sj?v`hd*x*`$vowRF3!XKKerXJp zdh0ARF%n!c#*aVs#(-QDW?y#-svE1-sc%JQXi6UmpM%vP?W%`XI~|4S$Eg1?KuK+7 zPVC@heOyu=VEz5Pm0sE_D#yvFRC!D9jP8a1XBz%^Y^aR#jEBJYhXUlxN$n46lGFHNAGduC|$%&8**21_NiIso1kb;Kli{oApmXC zCJsyLFQ|A(`M+D{DX^){n_%|4&AioxffBM8{k{cU^p#a^^p)9k z)lFk}5ge@4;(*B7C%2TT7Xj&?^B-;PqSJg_A=p@Ns%7GwI}7bJgVy+qkk69aAHIC~ zGBh*<@uOVmZQkkThK3-ITjbXtnBRjlW3;3KuIdLpixJNgR@7EUuBV3tsfu!VwuK1a7d#(bP;vST%Qd~NqHpL< zL|QI+eSLqg$ei=46J&33^NBGvimoJTP`?VTZcK&ze*Nby4Ib6c^H+XAQP*0kQ`u!v z=@+UDYks6QKo)KNdV<)Xsrx(kBAh|qV@}8bzeq0Cb5i5n;0vezc9KG_b{ZV(j?Bq& zJREW%PL3|MsM&?C2{Hu!9Y^uA_u*JoDA|d*#h&>BIvnB1@{+$0`{67N88;q`H9cg} zsLQ68{svfbX0$tAxzhWA!{Qq3sWS?FUmg625P$y>3wCK06>ss7-glR$7UThcpAiHn*f(*A?dxs&*DfVAhavN4aE}VE6zkt zJDJ*~)P|NOAGA1bPIhbkdGAg%<8Sbt$?^Fym-uDfiH%>Q5zooMP_Wpd@+ZHe^aPA| zdtV)REboTTi>N+Ps5)6bFYgcrO7$B@{e4pXc6S>O-2d7USX=I;vk-c78@YA9Wy!#x z%{NF%T%#|zWt*Fr!N=dEX>{E0{tjXN{gq!Dqijm=RHhdBiqsm}+pB29meCUIgVC=2 z;*Yv$<|8YjMWpP(O-gYd_VbCPl%)EnPgM8-WBC=eF3}9;Cz)3hVw>Lwe*Z{n4C%&d zJeNzg@dkI@LmErBH|R`)cjt_f1Cb5Hz!64vyqt`w19^V%QcsW_Dd^j%*GskYpW@}E zSM?3}c;_{xg~v*ganVoKNPM+m!|uGY-S=G_dp1(F`fEQNmow7SXPnX7 z347nmWDdWYjY?u29~+Z3O8(I!-u3yD9{tUmH%+x0`e;_RU67chwCc6z26SGA07(+h zyg$J$*7ep7{*vo5ZE;efTb|&|(|i6t-9qD}$@Nc+HrCd$EF?1SDPg{Jpb^R40n3z4A>Md7qvD8Ssk!wwQ{lV_!qX_fW`nt*+PVvWt#+&2+ z>h8(c#|iOYrbSfF4@>#JomX8b3x4JDI$>rakoHWs`_X${-^Sm=e6X~F~vm{f0O45DzI;~id@x%AU^YiDEk}+MSj#=qA#x4 za-;n18M~O+nes=EQIpfPV>_dl)}ePL?XDYeqZQq1`VXSdrd)IM&@zqzb~g;UyL|5h zkyyZRsJwC;W?I;pe2Ty#Def&q@T1QbScvF(DpPCL3>_UVgW} zGd*?pX4RCH%k+Q&sW+*t)td&^#M7AcdlVf*Lnl%*Z4_cZeX?qvt5`l`9{-YE?ID?! z;LfY$sfhS$c1h;AV5R0ReksI(Ypwpd_348kI=K|}$`A0nEOoAu7S&}v= z>WXCK>^s@4Jr<09axny$9Kr6s@O=5Rq%Wzg04(A4OiOJFsjLNGt3w88oi!V!(;+l7()Z$5avKdtt3?`mq>>pxO5 zw8y}IRe!ERyMg{fcpMGq>*vI;P&_21l#6Z05YqL81@kL69A`{uIj<3@kWkNmE=0`sk5 zj-?olr^g$DNj2VUz4=nXv!NDM;z1WGbf=&qaDBmQwd_%;jh|CIZLu`DlxC99Yac5C z%|B`#=c!d%BW-4`>T2w=`dN#fKV3go6BRI6e~X9(nf0oz-pFn9bU#SFTixEVUxZGJ zeiqF|o@yLLY(0^^OnUT+WW@COmD0Sf!k-*|kR&)nbqBIo1|)lJULNBz22=X5kvB;x zw+(GR^P%zGtcRM{YSr%c6>+t$qypiUq-e3ROgILXx*8(uxnJ`X7Wqm=zgOV5sca&P zd~y$4`t9(J@fqfV?%t}~!Q@8vO!84z^1k<(oD}TOyp+a-~!} z5TP!>QU3x)7b>f-Yip27htt47Q`4p~Dv~57=eBFV*wv}O(E84~S^akIHS=hpfXz>; zqfw^s7A0$W8Hf3IwdC`Nnc zb#)65s-ivwT8ru&vuB~$*|^#>;p+JN6lNjyZc}^DUXim2a?Ae0Rb)yHor-?Z>Z zyqG*q?!FBKWJ;waHPBn-z$%Xya4_ASspCL&zb;t8veV)5Pn4D_= zq;3s6`bNs_M8}fEWj*F^#p(e`H{n^hU+)8%Xt|kU@aeCL4Y{7`}&$`adT{lIyjFu&+!W~ynzNt|- z2{-4I+&Z9eM9K=rEBZUk(y8`%9IHAY$5^q=y!4S`li+Sj8&{v52yv|P>b>o%^Z#!rzwj*HdnF)xAIt=;$&sr9|Z8r$BTzu%qP`Z5|u>F zsBweE@Qm{m-frEU=&l@MxM$AWzwh|N(k3Wi;)7%w6e298z(KuDUN!P4;kowWeQEp& zS-V?QTedI&fSOn8cv!aXQ|;}DR`O14I{cB_&K4K2OkCCY)VQfA&&0JF=*KWy+vX=W z5L#yw5(9_9Ox612c7FQa8D|pXQ?n$Bm7AEPYu~Dm*H?&CYdI!gT1UM+0iPgR90y`m z)Zn>6P7Zl%1&TD|nEz%om z$uOIrShn}}Axke3YBws6BUe~{d=O6WIAEIJf2M(+x8j1P}y#Q84XN{6PG5d(lskt5ekjSMfw{ z*IuypQ%M3^qgC&NvBPIIMgJX46O~5u3?mGUAZ5&?K>uH4*s&*yP>CVS@$AB zaoyyvK*%mqJwp2&Xldq;+IX*A*VgW6Es-9%=WY8W<1`HC2vJ9u-m!seQ0vAMhEzs8 zJmP;czxvRU`D4O!?CRcu=RoeP%gbvg{WZFv0lxbtT1#S{{Pt7^dW0Q7$FchrR#N7-6eS?T={w=j63zPP(g^yg5_6eP zI@|0^YsJ6pGYBU5Jd4g}^SbfNBuJ@+PH7rvVxv5^Y+*#in!AZLtEwfm;4$R{AD$mU zBe(f;<__N;5J$ur%tNPzQ3V5pYte(BM#c?`YPV1x-(~ZS5HY^upL-(lXXMr01nZD8 z^mkyb24d=yu^)mkf(jYuSXh2LzdWe9a^FI%X=IKI1d;PGMDlF^Q)!!Hj(khr# zA74ZfsrJjs`nBiTlDxN4+|(PK7$x6__qswcAa!8*X6Q(lMqFIncMR3m`!fMK51$6b z?-c}__CFsRwNmat&QpI<``(DIxjw|}zLeH}@hUs6mHL#=vc!SWH+bq}6;xd`_;Z%ticnRHlDa=C7Gzm@`49(=e&mwC-*j`|-=Fj`C5uT2)Y zuAoaA_z>hr8so=K=#3CJgvcI{0gMz^RgFhxk<6)dG2kS4d6~kPV5&7bUZ--n_G`>> zJ<*}7dCIq=v0~pJ_RvP&3<1XU^~^68%9eC*k;?aeU3syFiq1y7*Y-cQN~$M->WyAI z@tfEZ$br3qbeNf~M&5E}!_R)MeSDaSc3!j?o6@Gy194m1myVaQ;g;9o>Zv?nhc zXGpC9cYq5zyd#N@Le;ZqH3$kZ9~N26b|SNLZstXai_afCDEf29@I3nku_kTy33tDg zyx8iWbjnO0J^qJ9Ga*0tOV6ZuZ&>>NtEGqEYJ$+(%3abrJZMK=Mh(Kg>7<0{<{Q58 zSn`eSCZwQSD%fjHtB1(sYc#{s2;9rP_yAu+r7N=HDvD_QR!jBMYMwE}NUjqr^+RR9 z&rFZeus2z}DA+mMK)dAIe{%Z@%eX@^GV~KnFU&b{7jZ+2iuDu=Elhg!rg@!VxK)Vn zCx|>8ute<-HfMf)07pS?>BVa)vm?34Y#7ZS;Yqp>%O+_5AAPn3q~lj5nC-3$!Z&N9 z={xDEYOQRHoPBb7uqZ?^7$h)prcoKdj0G6^)--3;O5^v2^eKt@^Y%p!~K9_wA8uv#a(l&xZ| zOygtmfbNL(Er_%-g=zFuge8i{jNd+JypKezkFF1&@Dp#;crewR@nW#!bKsJdhMC7) zm6cCi+Pkb|u_IreRmch1q*OF=Yx+ip=!i_nFn^*X$I zOZY@h5EgeOK$O*^W26Y)x%Wnf3DL|6gZDYBx;WC(V2=jA)V?-#7dV2he$Zo=GHEFS zb3N1lmOEBsiMk2f4opWeWw(79-vVCLD6J$^9hn(sqD<617-o9pw6Z3RK> z2|(@nx6PN7K0o>=ROUML0LZ)eln^*{_5wt%Z-%sZgZDWHH{P)7SwmD(5f(IKP?q2N zc)dar(gh8tPtxtel0QkNgMx|>kI?q@>fhNCKb9i;_0UG50hvRcR>Vvxxh%l4-0dW6 zVnfcYM4P`O=;C#~TbhRZ-%Hxi`yd|hFU5q)-d;X>uYq@J<)jDVNzJXGv`!rDa*Iwd zRHVS$+RBxSS@3a`2jl9+Pqs@3fPB{NjXcD&X9+e(fk1sf`La)ze)Ly)!T)LiOr%9i%F+O0xX%UXa!ua{*<2Nd5jOgUswvh z;R|iQCH4aC2Q-{5M6wWPw&`Oic&v8ZNswBcd5}CQ&+$nVbJ}?+>kFIJsg0MMC_iV2 zFhh*F=c`S$m6C#ANxzbstnjy_*VUt*)$XXmCxZeOxEa-LrqSXgopT%ZqF8*e{YEu-$EO zX+5T}E<7CMAppu<*ei{aLp!P7U)73?wcj)8co zt5xS={(GT>-iOkkV>Wok7qg#A&xS;#l|R7dwQ0mYF9}Io*_1J_F#^rA4czUXtP_oX*uh^mV&Q~4c_%N3(`R+IKR+K13u`);hhA& zq)%;4&mJE>w?LB*aA#QJlf)mqsXhb^n)w%Xg~e{dYkuN&4trke<^mjI@F~?*nW70; z*;)C?{+#lYQ+RkIhgY;{E1LGMUk)5Gi6Xe{<~9#^)JR?rPdcDAG~l^NL0JACuHg11 z+OoXV+0yp)Ym(Y7-0`$p_Phr`4I7o zA+OJ5`<>b}!_y}D5b3=J&P?)4M^>WQ#l_AQ{YgS+xV|t(6Gkd32JduqXJAjJkAZfx zk_15Yq|>rUhTO=m;ZN4BMLSAD9qn5igyqwZHGRb-Pv4FfE#3e*DBJ_4V}a|Z+w%1X zjdpAS?X4O7`v;3p;*5)dW7+jw$~c_vfWytkIwkk5X?J!3O7RJJ}2Db?YSbE6p`Hqu#gCWG?(O**xoN{KHv=Zxtqc957 zbV&F3@OARDw+Zn4{*6}DOPb16SbS`{b)A}IZ6`$KeQW;c``H-DN)5!I>f_UAiKb$s z#jhV#ReioeOci3gGwNiejIQ^V@wy@*TnDix5hy>?Sl5w!Ufx;U)6-Kl`pwj`@mG`{ zoxeA>E4-dfj9XJwCO%_vlZCdL^CdpU?DDbpvcmf?HQ>w3@gR?K5lDPLvlHPEoEr~& zU`2JEP;do#X*iRaIp9V4yOx~ia*vh%cIMh-Sle$E7Ks&c3*|BGGv*jLKiD%Zmo5#o z1YuT-!<2ckXEQOR{pY@HTx-<5arzCEsv8pUqbEZ7^S;t%=oWYjO zw5#)pw7GmL*I}9DBby=dO8z%lV+aXNt`cL7amTgH9fuo>vUuR8HI~FNSV)-CpzQa8 z4^K{q{c*MEd(oU{TG=dKJ>c)Fw)kq7oDI80y8VSkIT#-Ty8x!(J8%UUHIg6m};e=RO9etP(@y}iBl4fP6NCnEImyp0WK_VP5G zqKJ2CJrTNeGd6W~TKc^oe{bydk+m5elL-(ayIe$DoLWzIre@deOqDgL0U8SB<)TK3 zoOs(7DaVw9T<1GAL^%v?#d&)TZ?`50S-sfn`3UZlnd3?+l*cGe z=G|->2x<^bLZeiKj~Sk4k$`sU*^AURnD#O&&VLh>`Y^+B?d;RK;Z!ri_ zkKl~~6IVKE$+^@|j#q|%C|wHq9!#W`>tqH>$UaYi%J*{>MahBmt}sQjocg6t9}tdZ z8-gW&q3iVRI^23cF6r$%vNBtIh33c?SEduj7sg_B71ngLwu@@k9$w=v^~aZteWYt?*&TQY|>J%6~O&;1@y0oi9p`^)f4A>-m_YPjk+AsrzWN7O|?Z z%D~c10hRFpQ7r*r6led;k0AQR(E)_2jo27X)Z<+I6Fh0ezaKNbjIa_|x$OG*#Jp<; z!1maX_7zy=B=53GQ)&w8k7BjXR4h8N2Zq&g#tI#F__Y_rg?@H5%AG$^yt%jR=omTk z)H1tG~{2Q&u=<3^<{LaN>gxK)jw-`f)5j=|qD0QtPP&D}|^LaWO8vbCP}N z!!!NxU6GA&r>~)nGnzk*3je|+sIaz!no*2Mnk>FeI&JP#8octs--KChQ`6r&bM4w4 zoS&#X&M7MuI}1BM580Q6orm7ARZT7o1svU1Q%Pq96Ta2lFgak2O^3wHzMrD@?7~-d zFEV2PWv6g5NThVY&e_5F&qqVu85zItjmApf3t8q5##oO5UUAadlI*q8e^FP*)q{@C z%U3uAhis_~8*c{`V6xW|X-Zp*=)>om~3n9 zJ$A@AF@4vFFZ8HHP*eLx-M#)8Pf26mMejsi-gk>XFREotnT$tJptUph@z^`CR)HFZ0Log!+)YS5LX zIFJJH7~D6_hKGvQc0!?}|?86ov*q&(fS-$IIq;#L4ZB3^6}43BydNa~YiU zPG3zyyS0Cxs%1(fX5W5aVvx&S)m8B+Lo(6Bb7LFj-gC&~9q>T$7B zrm6Ez%VlK32p;EC?!=7beYd^q@8PnFSPwZxJiLRyx|(X{)E4{}4wr2dO?E67DFZr$ zrO@fDQZ@jax>#)5^hAXb(Y^>`n51>6U=}88Arkej3n_|twQa9A_f)fy+~(^LpzK1h zz8-vu@BNDbdQZ%rfVGH4UXd0r!>xcNMBUdM@Pz=cSHne3vuIC;>SvK_Ax>KZ^J;=( zTzzH&e6Dl9v*mhw4Pi^iYLzdLZEV-fE}HTiF@8i5A&WR0t^3iEephY9!luE1!uTR=J|9v2^a>s_bg6}rc3F6fHh`1_0bECZA7T|^YmW62&s zA^8kl`FCLo(^_5O!MZV_qLwhsJErNV1oc^Wf(tNbrWhJ099P-!^D$WK+at=4Pr`5s zSPeyHqZwY>k@PkVJxs`@rjamMtje|yo*$~tri^Hi{P|Br6%lMW{ox&H*awpvQ?QE_ zMhLn6w+9g&)>jX8;I$3aK@N7(fzf|<|TN6lMD?RI{A8Izx%eJO{ zV!#c%ua7>3z=hj!+Kt$$0HHPfIVwS$LAU{NXztmXSc%_mbb2yDaFGi$M59vg$$SsL z3jBf`7Tg4IV?1;bNVY8Bv+1kBJo!Sp`SA_{Z6HLx1I;3dBwxEAL7@FMG6AN`4Od%= z5`z?ng-8fP!WV9uhiQqe)Q0%g%LM+}DQ=a68!0Ytj&k15R(efngJDTb7P-7>mVC+% zPxU5@tY*&nb!br$OZ$6QdvS}!V1~Eqq6tMJa5^==O~kg^uX^*U$OMSut^JY^j?{~8 zY|=y&U!Mpf4a!g0txB|syeeuLeDXEn9GBpg4lvGqWU-j((mi=T!BM|elWV1ix%kf} z3<}@jVuogSD_lW66`{TxtTt3hqmcXm*n01HEZ?|)_>xc}m57WhBzu&ZEo7H1TV`gG z%s53+QTE&GAynB^6wBM~++q_eFsL*${(KrKE({DeXr(Z3OIuwCrT-kqv zzt>1@=+j?!P&)1Pq;zRKrQbpsf9{KZ0AAA+=agU!sC;Qp*@|FFJ7EG?N8J_ma)}6l zk;sjen@yB+gMUcv=QefV;FaVw16zLK&4QwxhQf`s2u-sE6^<-TDCpF8Oc<+9n1dj# z5QuyK2d@&x%$}LvEm*%hpW;HVoR=SYv`U5N2bJQc13N4_oMq0vRAjYLn_>VCDgdBZ zpCx|e0b`A_bd&V!tq2JoCaDyhzM}ttq@9L%uUBL9hX?kIWFDn&&{0y=4Nxs`0xI3* zG%A|^r{W?l^y$mNFqI*279CwnH*5mV@~e=y^F>2q_P$E33*{pe7qO0x8s&PwMS18v>^zE0y&A@?hI zXMQLEzgt5Up90?4v&EKXs@H~m`;A%%eP#QG6hH|{$UVr<@*ZPIj;1@J6=MQORH?K4 zJvSLyqR|a(09eI(nA#uews6-!2f#?r3sWNB-Hcv^wY@Z^sI(ViIZ!##bkt~WKxLVH zFa4G5Ezct9WA1l}ab^m`t?;5YXN~{#6j*09Y22C|nW2-C`11+-95>9b5!RS4IjVFq6g^MW z8Ogh(xaG>DWzct#N=v5>=fhN9qMPQwh3r%Cp2Q7XT)2B4z8v#3aVe4}{YXHlKS)(v zr0n<$u_WQG7HXMjp+Kk*aDqEKAbfM4_3rO8L zjgbIIQN|ed&Q$?TN-elKFX@`auAVPVseV#&a9syi`1iio=Bso^*|z76-xal zY^jOSL&74GuVKAW6p8Lt8-1c><4+3yy}=}Xp=kGz>m&}(xU>281J3IkVe`k|oraYO z_>m1$1HKjo&y>_tfPfxJMhMZhSDGjrPl5Db zOLpUfY7&tz<+o)bjV|QtfgsN}-Q4Vp=f( z8vM#SG1hY{VgNL_G1t+5uPpj%Hx+TYiQjq-?y*Aldbw!=C;eyENIT|L($;kCmvf{lm7m~7#Z0v!w?9nmDH(8w&x-kRs^g-U` zo1G_HkNf`P7fvz;HM#ptNXTG#$5EKCl1oO?|MAhzbK#>OLlcw>Q| z)cy%i1xlbx(*H`J?SN9z%34|sNyZpida}n>Z^nv?w$Ul^k#xvSB8P^dH20@x$D z%Ds8ZMzTk!-kKEKenFJc)5+Pz7Su?D9%G?c`Be-CS~@vBPlete0cJkT>tCpUg|VsK z`5x{UjyUW&z~FD;DVuf9=%?igyhyOyHox~t{3NF3Beu5uP3aiBlJh!{*;kCSqhM;a z@KGngQ2-T3YVnr$3wM}8O^to||7}Ajmr>I5gX43v&U7a*oBdu{G49Y1>OF~MdOg)t zpMS66Uiz^oU`+}=WCrRT9gmQzkrlg>gg^Wc?qYM~LxQ2!TDeT0b)o*paLKSgQ z?F9~f>W}@Oi`MxeF%Vrr-G-!!{{iUl?wD++_C4&N$NYFRl>G;VYW(C615vxj4&So) zHJ(VTXbY`h+8H?)k0D(hRupfGL&h*X-XSJ5nAnz8Wot7Q~lEPB_ID z-|GtqtAV;2wg39(ko#5fKk+g4SH!kh4 z=Lh0FX9x0*USqetkb`RulP_2)#er0XN2KI?9*^7*1$GafU>|)&UO-MSYVWG z-pQKT`HShcZM7*0Xk%U7J!;^F-JuJ#{a#@F6rsVZXMn3-w|FbCdRqo%c5HsUHwjI*^Eau3YxvgJoG>C~i2z!E_)_=2*WvV`GNAJqHpc9~Z0j zFnh6)0=V<0mputvjut|6N8^MejWv*mV<3IN{Fc6Y==}QL0j%nONZOXy)c7pEZ)v(S zEw`}sn+K_cRgF>nt9D7B@;Ti+cDk_03z7iacJJK{dfdL7^`%FF;C03bw&D*gZP$L^ zISvF-)MCdN{EtHk!=3L+{BFO3Q5z}qlnia*Ghyv$7Ew-$z_*C_xWybq#4E_$(G5?3 zpu_AtI$yZtk?M2k*1=t0j;hR+hnrMbU@&qDGD{GF>e%|u+Z<|(dtOJA_|eB(WywJ- zB8lp^Zv-Nf*+U<&Sv7A8xZn$eQ$!|fq+jJCZ(f4q`sShmpPk#Is8j2f@hK@nGy^tH z`Ch@fJ>&W<=Su2n&*iB(UXn?QZ0kPi*;*gMMs9_B1J)4l{yRN1z(un6kO(|SV^$E_ zcv{3an6FLVavYjBumENg)vv^)BqKvZTH4#Wk>1Np#mF(&xr%%b8_p@5tBv3_+;&nq zUG4RNM0J*0$-)~i?&W0hKYH-`CcD~K7*{-*?o+q^we|;u3Q)l+PmJwvM2N5b4g=|B z<|wazx02(&++lpS830M6G+!xxM7eW9U~CL6FZCj&D^cdj!)J1ps=NOf^2FOFLRH8K z`s)Nc3C%o5@=+MyW0Ce3wNum+RCD9%ExhYr`JzfAch3LP+OP?*Edf~{qt+A;m&!+w z>#Cpz0v8EmcUSLEku`8FYFxh_8Wr?u2p*64vJp4YI358$s_@%*#^1wA@+?u*B-$~+ zL2_lbg%}LMFesP5LyZ(NN{fsLo(kh{PWqlK9gWI|kX&yvj~e5wnOP&o$YkTLn%LM_ zIAb7Fo`c2HRBq3cuMTiYNF`!8U}3JkR{Oy9>}%EwvLDa)oWwlRC^pbZs#rux+Ru?p zr8a;p%+U=;-8(&T(>H(k#c*WkEt{oinx2!UK=d{Pe_X{IB8$00FRU+xuq1KP?@p~W zG%y6d@#ZX^i;j+Nf4f=?fNs}0R+^CknyYw$pJF_saWw}%YorUllGelAA{rYE3_Nzm zCQbaSehZtst=tY|)7RGHe)ji}mm_R(vFu#1L>4;t7&<+$wfe{^-l2AIbeN~n!*taX zi##=<9eg5HSV;ICYxt!~&P}cmmE?NCHGaxCWM5@ALjL{fD+N1_a;q{&QPu3MN-I3_1SW#A+C_)mnAZS$c-Zir* zS?HgixcRvV)v7azNYzTRdZ%G@U?>#?MMo%z@>tfp{Ba$y7ns=Mj*#OFl4aBrv)E|2 zeGc$wM9)DF`(SU=p~_`&vxtnu>)sKk!Rfw2Rq1EK@{ODAzb1a_OFT1*Ob0;U0AK8* zv1(3wAJpPS6$Dz!M`5$LJdRzFI+va0K zF8xnf(1W@4wVi_}j{qGzPwgWP{I*wtO}z>PH-Qm_T3hW6Y+L5+^2=z0b)99UnC(2? zz1Na$EGfK_%u#z#BN!4L^F668QkY#Dr;NIG$6pM9$f|~b3%nZ5GFfgS88q5ZG;A!q zSy1G=679MO+I|o&?Zq*l?_8uEjJ&Xgf1jNzA`6cTdTXh(Fg0;t?@*JAye{WJD}&L0 z$w`j~i)#2IdeVAgBcDd@(7%)|cCXklG$bLbgcn=S9S}u(2WWNJt+J69G;7EytP1;Vo<1qsPKk(7$-gRj8sv9`{jeAYdOyN)bVdf>~*ew zQ~$~BYFFwUw10ENebhn_3+3Wdcuyeo_WPotR~ao+EFv4;_891x-Eg$%rfMHxpvX6> z8kpZ$7;|9axGzbgCkBMDM@XwTUyj7k68+=w^5?2%v7bQ+1zMB@Y0Q);$x<0xBU4>R z<#j<ko~By*odbj2JNx zJ@h-V7Fvij4S51+ooY^R?%gh`138$XUA*j)?ge^0GWvNvuB5k0G9w=qlPauT8))Lm zKwu@+zs;!%Cph)dMN$sEr;DhRRw#`3xEmZ?wRxR|es0eI2SMyxVGuE2SGaB=5>hXw z%NpmXtYUt5EcYja>DuceGS)U#g1s%@!6wPg7yj`-+NfUer-4WkjQ0yf0@lEFZ#q%Z zI4lG-ut#04NOda^G`=O#>;(PAqNpC7MIO+CPAEd%fr7Xzd{wGkdoY+7a5xf zFMLLqZTKVQyQ>fnegDjk_UlZ!c%d2?Ri^WNDnin0LY6(~Xf$?4CF;nET-zRq701JZ+X z4THZQ@8!bIIN@25&ESmsUEJ%E4X7(~E>V8wri;nVyNjc5tmzG7#O5Tk&6>Brx-i3L zuJSA3G9Zn-fhDtVhzUaP=rDRm zT@cBjCeY)pP55(RZgUK^sF8W=7gm**_bu~mbFYz)rRJgPpewCK;Z)g4jApDYC;+>19*_^;bLzLOkrMWncBA=Jh4;Y<7WUtk6Q$J&tDu{oiMpL_n0ySCGdVB z{HKC|QKR=Zw$ZyQ*W>(JRfj4YrJqu);5CWKjrD37*)q0_K)5sDO$lO_J?9n4sJo{gxH-0^tuku{kW zI+qIImx&0C3L&-1tX-9232XQQQk9^!ko~pN&$ZF^a*}kx_XMDk3%s^kJKd>G4`=7L zh&)g5Qoz!F||~yw&)_ zTUV!KNX0RJ+Ame5-TJ2-Qd-|PY~K!(G{-)ieLvLnn&fp;i*;!TU6FFg`Nx`T@s3nic`Nqz zW1{5Ec|^BmS&+^1<_p!qsP=6b-$U3oqbq2*MMc-~ihzMU2ZZ>RTNfY{tK6uRbP~4- zXnYH9gFCG{$3lZuirvB86Geo2Yt%N!m95PwV^XC*jFQRzMCsrQoeD*awZ~TR86=Nq zf5?ZSx|Zr~KCNN*@pmW`nvfW}fh7n+Ns;Ex!y5=H2BHIFb58I_r6ggj=*KA5T|wF>?sUGS^XmoLP#RmYkoTm)Qza z>_6-EH_fYiYy)cOy6M$os~4X>=v}*KW7E?2cNy=xmQ(v+MiaGp+2fU){(fY}-_Ec5 z*-31BQ%`OjAR#P@Y%BAVg*4w^S)?xf<(_KKGZ-2`+)*%zW>&TG=(vWJTP#gPQe~1FV2705E zSb~qKZI8)Tu}V55@)Bc=K&yOoe0~1q`eTO-eP}Osrx$bP9wY?)aHQ{p8f^79?BqM% zE)xF;6L3q2gnX2W3>XO*19RMOYWi}h{-MbwY>&N@$<3Wwqj+*Cr(W8)!~KyG!52EY z4*?#yVfRA-&z&UhwK;gQ@gI+~83)j&64`C?fN23Eg0&PVEVD1AXX-HqWLkxa%&2=@ z(7Rd^09R!xV@k5@&x3vH<%S4?K^9sE5y=kZNp3(kZ)7$TT7VfB&3$!Ds2Z9)6pZQT z>mRupAwP|iA703_H{RmhIiH!yMA0te$PxFuHDEP`xxbx~w~A@dzs`u|nU`L+%>_E@ zk0Xn{gX!MoSBmKt-kk8z)9fu&4w*zK%dg2)3XuG~*WFEauUU}xaZC$7>AC<}@metQ zcNZd7MSEz{hU^X?z;V^RS*xJ2c zcq_#@j#c0C2$dL29&ddhR`Sz*B}xku?q+ntEp1)muHdG1veSO!(IrIcVR!fC6M5rg zg4avrWg5#GF$mSt!Z+Rw@9_}HeOiQkHPpz{VwUE5(`lcRe4flac8!@GH+F7^4%TC- zw2ir}W<6UEH;AlB^{{)11q=A{ghHvgIo=D;;j30ur_Eavh*6|5*G^wkzQ%&3n`=l?{zPE*w-kB0nWznO-Ots@0 zP7+Tfq2@n*GM>etd6n*23{|?HfXlNI*6vHVwtE+*(`PIkFut)cS+4UKq{#2O1r?2{ zz0&Q?0yeqHy5^m}l6e*glW9^cyL1i^2U*TnMcu#`{dvAG^L!V5ad>;?;Ja z8z#9JWb*q>mycH$a-*oc+?rklbP|-+Cn~mHF?&-@-Ik0l=UA0B*t^$T8I0c~@l6X* z>B0v0zryv9SnIal@Dv{smccq}=K2TI)JYJ}coC78Og8|dX@tZUJ&h=@p>cvh?wEeT zQ$!~66$vh<#SQTfAKzy{PHVhoO`%O`?Q(VIulSt`2VblddAcPwq<2KE(mAFm&Tu*mMXeH;$SXpoBK|H2J3u`d80JMj5)BFrZ~do3 z;~W2B-se&W8cSH9^CCvLEN*f>iQF+!tYW2^3%PSlN(V;xMoFH1!Z3VM907~18fj@o zi(@C5qNQ4kJAT2$MJe0yYfq=~fvZGbLLE(dKUEYw*#!Qj+Z6PPk2yy6hsS?>1E7j0J6&rk%yWksSGn6pyf=6j+0&|yQD<4Q*JHex zEv2_fUQ?3coS_u`FoRej5nDW1#7VEj?&gR*$HS=p6@4K+(HSiPV+a9FKUWyt+HnX- z>*pOV+^hxIM*3%*&JQ^cNIGwWiNLiMbCDryY|v?TE>IHiOm_2kWuMaEkt+$_lmGdn z_9o?dDhARuWcj|$VV8l-;q%0V%Uav~=x&vVksrEa$ z5Q8j^;TxI}?73Zi|Ni|<6x|MAwD9MF6%Yqfyl4i`2_BQKE+ttxk015uu7t*_3sn)_ zgN0#&w$YpP?W?>!HLk<*SGN@pc78f5L<$?!bV}g^1K9CX?cP(ZGP2-}-NW94MNZLs zPPc0KHYwjVx$d8~CJCeuLL3Fu=)A=Whgyb5PeUf3dVywgJDB;f{&fr%CSr<}QKU1d zO41=Bw53DN3}ByzPv0l1ugJ8-<5U1dDFDekUW~f|7B?)zMVt|hb&JNHH z%z<)~Q7aVO%z_+|tPe2vqCv|BCge6!7h!GiCkr;nf)ANU6|PgLKtG_BD}+{hw}%gJ4)|VxyU+3+b>X9RA%!E2MylQ*S|)wuRFW72SoeIngFl)OBpxL z7GJA7|M%Y*ZULg?ZgKt0H!4ll!P-gt>a%MPD%d*SE`1oR5q8DK$v->TGbl1Q?JGAh zF%fF>pBvyNlI1+Bg1$zkNFy;)vo)^%dtm5RCR!cfDxfdit_rr299!qjH}`12jp0j&hU>P`i6$iq8i=}lR6 z^?T4VUgzX6__=#$b>NV45cxq&)4%!Tt?KWB9#hqnJpRHuq9IQvpQmXC_Mr?^NuVv66^%e|y5SWjU-TH>g|Bl67*Uf;Pp_VF^ zEcbec+7ZO}-}Ag26v!V2kS*7-JGBZ#HOg_q2kLE9+2(fTW4pVaD`BIT!X$+sFukn$9!NZw-9x}LT?vbjRfBW z*5kzCXM%4E1UchKiJyjbJoNR+%c9+kqiw%H+BbSnR=V=v8v_Ahx(D)itx^33!~VQ1GiFS}$^3mRL|Sz>#NqxLjgYeM|L*6G#u*#O6@DV$hO zd}Wrw3r$N*YwrpXgu|8OtFaE^AsSQoMe;<)>2L_aO%H~f;Q77n+H#$@Kc3PDfowa? zuOK#mL<*m&Oj^m~;LatP1%KK$#Owe?+Oyc|!pylOY8-$TeNyn)95n7p{NHQH5Y+Tf z-F@rPhVoWs));pv#fPE0kv#sPc%#`}EG#+DA0vUrp(say?!`bs(Rzy!b!Cbwy^U!0=(}le5RY2Q#LtYiLao znUY3MuAzj#+XcKml=q&7FSs9NCKKo`Y$dr5~sS)J5Ibhj+IjfebGMZE*|3%B@diLv3llC!zN zMhJ9KG6EF$#aVQX8ZkI8?|0I*up-qIG_ro#ROjp=`oKXG1^$^uK z`&Xol0)MpD#FL3IQ2%j*=Fcl~w_6r&3O=K0BrdjzeI}O5{OIz`c{aMCB#$ z?C`v|p$6jUbYdt&ex2nHer_uQSBBkvf0y*un{@VrF+TPF3@$FK&O>)3&ZwJw;?m*YW0 zG#;SvkHrxm6?reKnXW)?!)^1sX+3@PF!p@8^xv|jX9~H!h`i}k&kxaZlQ@ovoQ~P{ z9z{?Km^Y~OJyA7+YwAcq+B<*P4QXoL{l3@7wimkIy*yUl#g00WjS6wFQe;qTEX8#0 zoKesLY*_e53A5jYtz^=8j($s~*Zk5(IEPFR3nypR8-cy`7Do&d1FH#CeBupz+}63e ztU^S&cGLyN3a)d7D%AB3H47O2A!EW<#$(n-_dgLcc+1tXzDzOP zEOUu0X_aoWECk-LCU4@a6&oWWG<7T=ltV~--ihFo!Z2r#o%(QO`>L@?wpGR3AG|cS z3tZi)K=LN>_ivOczqq~D7%Je3e2F?5B~4SK?K^5ADIHYe-ZysomON*eyfQFB?Y`%C zbatMm(;^KB9kE{6+Jhn2;E9>klSH-q)Bbab)0%@#HAWdnh0B`|<=rj{ADy{6|0W5i z|I%HCskh(LnmYCt`f@U@+L&*`*LC-<=KF;4J@%3@M&5&`4_#?3?)RlRGRgf1s}{nc zp7wFchvtq;T_f1(Y`(mk2Z}P7zR&k3N=p^rraMdiukO86eNW|gL$D}$vY;UEi&2v>RS4fcc95`%pK~+7EK#my1_bFTN zZ0(+RvdwxEr~-@@Rqj~dXiuZ&+qfpMVSTN`#AnC6y!{mSqs)Hr0Vn_TjDv!i6i@A? zqxIkJCVZMor~B~0<7zQN1m)whdO~S#c6QsQ^+i0h#tgAf7OvbNYHLaz`}Hj^tuUyj zSeYoA2h;$jt-F#pvTo9Fhdn`({VaTZerl~{aa=e%Y*z0bUH4+Tej0mn^O={9{eQ)) zW2Q@?L{UutSf^!DDE{ZXmF^Joe~PEIv!X44;ZK7eSf@R$x?>zf{ zCM%g&)dcY$b{_l#VR15F@jIv}TOw-FDZjy;YW*5&_3S^#I=iDu6c6gg2U5JdE_ zd#uLW3%0Wnb2^7nI3gy^MYGdfS4BmuN=r*?YPhjk-{%RK4C`^Rj+gp@$G0J$2}FAj z0uR-ySp|D7jx+CPvJykNmVc@r@>NL8FsQGndhcplhz>TrKJGR4N|UA-NiLQhXu5sv z*Whp3Z(~}<0cdf1H;7nDIwy=$>Y z0`%L1ww7@!Kh+T>`Ms|%Bzrv~FREFv#<(A;Cr5x~7c35ycTDb7y_12N>WdEPn18$q zjMVD7ShL|T)SZaC;=yFsGz3?;`c*9h~E+M%inL})~MVq5<3NS?El!QSM(UG-2zZMCp5$lw^{Z*jal_KSXu2*IiOq;T@n2?qFLW ze~l&w4FS>BcZkW5-p0-A2gES8(8@qF^~hfQ+3Stiiqfv@(7jTJJY480h}2#+5v1ZH z-KOby=fcB8w|gLE&-@r7?du-_b{tbDBJ#LLHU-1w|P>sz`Z>qLlS#B_wMCjqT8_=Ukh!Lok=V8b8pyKQwX zL}$2_-cE!#S9xR6E$4DInuTdN++ z(J8e4?f`+lm;lv`8>?(B!Etw>S`Bq$H4B`@*|c5OO?zGKrti1NA`x zN#2_8^Ocn!e1fZQBs>0TBhOG~ba3AJo?^+RtU}-+Uo~rBrTVn5G^oZo;-j^-^|a+E zdkZpkJA&uZW-%fm6s2n{KcM=vITTmb#et*VZ=PYei`!JN+#0D{$2yjr$i8y_vhqkm ztL~#2xzj z`o)2|hP(lm$C(0Tk`4q-oFNpYYOP_3xAFZBQ?-wJvTsey&x#c-k+(ZMjwz6;dQE-% z{|h{O#yWFS_Mgi?RtKj;$Z1(Q{0zQD_o@#LB)`18m3SghR++OWpRPhhl%Dzh-^(Ua zpt=uu?^~Wy!#lc~SLWWu+vTs?lHbba>`W=6_~+h?;Vm*Hse=!o2lUyx^|u#0J3AW- z=5LTjoi6C;SW^0M0oiG&(NzTDgPwErq8*`$>rh?lci?{f zkfY!|7=z`AZP1k7h)1sBafXcLsdOyE0#@%@jPI+fjA4zJXhvKIUk_&NgpoRyNomTD ze=8arH0VWQ$Sa)N+>Y5m|98Vc{P8x@)UGmU!d;}Idf-75JbG?74+Z#tTZl-f2BSS) z$Cp3%)V5TA;031v$zXMon}<6q=!dfhaE$>>5np}6%%H_Nd<(XdRW7k%@x9V^BZVOz z)n#{%*Cd=18_a^Kjf}|%3-;^4Yf;zDWvF}tuN*HWL#pOzah60?pI4E4_R+-*A+NtX zsF%g6N#rIN&@Tj;Z-sei0Y-&lKC}^yUgU?F9K}K2j(fCi5);q&&ffrBsL%9KQ$Z`X z`Q-i%c4g3CEm(+PwBX8E%%HlEu#ivi_pSFkX~h17V~)XGrWF)wr(>0Xp0K@E;1}*O za%R+a>c+>3tlP*i_d^QHT*r!Q^umhq4FA_`XhO5G!2bQoEK)WK2^G+F4rImmTUJd+ zI$#}bj;{eZobGWxj$4M$pUU$?9W8Z<{K>3o255)A#2j@U4OoxJkn1kzy-?gC`6t)K z`0P1jF)Fv-vA$Y&Ug7o&x#1}^h^V`0_FM?p#a*kgEUluLu#4c%(|-365QRsRB?~UI zt#+@Dx@D+1_gD{xgguZs8J;p+Va|bfuf(~;Jyt`8n{4{m7Aoy~@@?qr7wg_n5301F zoSbQR_9@JWxb*4zFNdrH*p0lw$=#Gj-}O1$ky`W zUbHlj@Aze$2QI$F`!r$#&0%E%n|M_&Y?ch9;(FAQ2+4eQmtQ9~PG?;f zu1;W7?FC#(89gEfvi;thTe$6s!22T2{ZZsBhrychgFxn(?ktTIED5K!ID*Ara`<5R zmsjqVtoH9!2!t#x=M5=^{J$R_M6J&dKD1Ea@a#(r_J8=`LUjUtrLh6$F%uBtELv(G zzic7%v(%lEWbQ(nK55Ns`zM1hUkqkG90@klqpoU3$h|c67~2l!I+(7z2DQ+WpbfL@ zd%d`ECTvwm``aSNnglins{qlW81c=;ui--CKe^cfTj!KOM(i55cizlN>~d^8{bP-* z6&)G+h5qdEeoM$+d*Esel}w89%0`rJ(HGG&Yx&V*0f~_+Np&5@SwO=e%yQFZ-(|2P z_=xn+)|6IF{3{pSOunQBUp0wDw<<^8KKc<2=6eroUy}S)=!Q#JURI`~s|(f&fv<@h zDp)o>#di==^P8*OtHv{n3vbq&KgPWpTDbJ%k{(u%L$5rnELkhxgXgW)?vPLLi@hXS zCJHWB++j*~kUw6xQV_qBkkBGhb$cALSE~|V`tg=Ace-j$qEw^(`<{?8Rl;=h-^itB zIb%g-#1?p8?$c{aeU#hm4@n>4A|PxzYZo%g1S3kmavN7yR~s7}&?FAV-;Q`$OnjU@ zrc|E@(Nk%evgfHyTVhIqeT&H3?|To8!{!M);wPrUyM3BX%@4e(3aEWmdj)NR|RHQ z<$O*Ao;-UMlqMJc-MES`1z~k@N7oH++P)5$Th{pZ=<7P3gpzNW`b-H$=*2Hb|>nTn^{^ z1UJfugz^^Yl&1(;&6uccR^3XC_=CmRv4y#8vpz8+q~DsqJ9&FoCpRD4dZ1D;!mUj) zc5LEF zUszYowVwPbcHiEzAG-M0^|q9>V-MORhP`#1?Wls{TvRwvN9ruf#W9-t-s_FrvH3Eb zA@!b%dmxFU_q<2%-qxZ>q_iU6Wv(8-5;7wERihTJqe!p^k>HYR535j&{7hbfbf!4Z z!r1iOhUZLF;LTW0@9H3X%{o3Gc>^>yx8HgK+s`d>u1fKKWn{9Ej$!w$ z7yf(=b3{nSY%SSGFc?RK`>RmJ8J+sGK)$|`kbq>CxQPD}3EEFxULNj`^+mq1vl8@@ za4m@ef=0qUpAEoVy=37;<7-u4C`jW;t^V?6tQ*pUT}d8~sXey`>jjGt0sbI)>x$do z``q=x1Mg-~pM3d6qk$YW$lu}p>W{u&Gw2RXAModsC=A%Rd|gs;`ZQ+rEzw8a$b?!s z2*3XYC8vs#8RxZ3qqvjyP0M7Dk7%Ez!oSf1__s3~!7LSW!vgqgDq(JM`yw5{)jO$q zUixmJ`jqv%WBrzY3k%%8k`WzK;y2EX5nZSfI+bGu1CFB&*CQ|j>_!B1^Y^Q}h86Vg z6xwMJGIx9bsq?5-=jz%p7?*D0Jvw;~`wQAqCpW@0l(<7c^9hycDzJZg&o(W4NiKnu0Te%cv+!S`b{i^afx*LGDG2MPNRAOhqWDC* zn_*+A#6ZN!6NJOY=38C3YY2_PN0C`Tg}StkjEs3zkw$Bfdz^q$9_8%yl&AM2IqCSF zd`HI|gdTI(ue+_6E5*_$u7dG|yR>FHOY)+7szXN`k3#ju+r@<-BdYV6%9GDvFBXtB z0}?YQjRDVnLQgEXk*x5zhW61%e^ z$%<-F)q%?zK@?(?&AN@1>c9Bk2LrI@C@=bct5iH8qZ!25J;6zTg=rCnwFjcqz;156 z+z#XVGGju}<4n*WCe>}kkK&g>36+QF#oY)K*ymNG2x8zSrY5gE_W{lTIwjE0UiC7EVp^E6;#*=|toL&<$fGoEb_wV-OX zC%=p94BkKU6{&v-qmT!86+m5_a`30)_GYcmb=_NE+`&tZhKyE)uM}~=#5Iu`&kskdfx6g)R!Z#J61@ zwg@igo9ZR?j%KMVz$RAEF)9Gmo zMNTNtAsiHEA5(r`cBNt2mVKS8;&h@#lh7^S9#4-ulH#HKhxe1w+eEduQImr86A&uiR+*w@7X9* zR<8y|5MTBCItp?o7+R&iqy&QTF?Ma_IU2AvVB4SPdgfA ztLTg0r8}FT2!R{aXdSpqLUpl@@nzTIin*@r8P;E27XWX1pQT^L`|PLjOBb+aIEiai zciuFu1Q(gr-0^gC0!HPlJtsTa*B z3qXJ^km$HUzr=*_((J{NZK~mSTlh8tJKpP(NzlzGYiwO|p6<&o7Wwfy+^QK?ZZI_| zFf} zo636Uc9oV9a(4YOMNt=H!7}~DUE9_NRO=3wf$`I;u=c?#Zcw3%X|kBDTmIU}|8<;_ zyC$c}*)GZhXLK>62+!E2)rubfcEwo@x0&{_y-#zI2-I7DRIUEGz3!dfZAhmUDf9DY zz$`|ZLOg!mF%3Jt)`uJOlfZ_}fAieZM^;KOavdS9Iw1hEwH({mosN8U`;4Hn6fl}Y z=Wtg#LbXsEbPN_9=R50(K}6*WM^0lxqy94z^SPiBX7Xxj6nh5&qSfLGET>p*2bjmd zh%YrpjC>^WptiQ|72~ZfoA|dkYTNehw4hiD@uwiX2J{G&Z_@lb3@T zans`KI()K-W@|B^52GWQsU_*DR=2UCD9#WcJ5_*tonEW$gN)G#6@n6HOcNw}Y1Jdy z@u*d+A8Yl82mMo{7TNcW>y|ke78jA0-e;d)duWMVvwFeWlNTzo^aAjZW<6UEMp->9 z4K{>(()ey)^@|L0om0nlWZ0Zp&B}Wqn{0`t+8kI-TQCP_AEphFhRfoj2i3HQ{GgmX zz6h^L%wZW4WvWt@*|5b zdOGR*mZDX!CUwBw<2pZEmJ`KDQ_TNZdyHLi{BZEB?B`jJW=_tE9Fg7S)00JDsLNop zx@Y(CV>X)8A)+eX0v|S%kGy0D?tZmC*n~vBYR?xiti%uRI695MYu8!2ynOL60FNHt z*@<&`k9=br{exZ_4YQb9v^KK{LW{FJpt+^DzaHH?3){|VS8V0MP0(5qZSQ!7AFmh{ z?x=k^a@d=M>-v-@(YVPA8}^_;w&E*}N*O53&OB~xuZR)NMs78hl&493+zqy`aB)}E zpGck!oD~LqKWMu86uxwNU-aPv!rVoi%o^2kV`AyA9ai)jRWO5{8CKLR#)rAU9J?~h zVYQvI1*z-s_lCL66hoDkK*hyXSv^t)Tv1RB^Rn}TQfo?a_p_?lXRBC*RPM}6h$+;Q zi<_Vm+jC#&?S2z(eAVwTneP51(R+pzIb-?b*w(@>^%lXaQU2g0zm5!h&z9HPodt2} z4abo}qaXar9&`@!ihTT~fIM^Y$5odFvGalfuBIO}8P!;D3NDE%wvJziixj0t<>En7 zi~lCnc1A9}_wEG`!}9mz@2>-KIazdFFW-*5t&F$1PiTL`g@Y%Zg_-9bPWadFoY2mA zBTubf?t|84qgDjB*mKe|$!sAxsShyv3I{+G*-5W|v_!i_eNY~e75gk;;ndz|UFpuV zNYvEZxMznY>3+3Wr{~bM$srxfqXlJ>1xF<0`FOt}*6?GIqgum*y$0MR$7hxtLvr*n ztzXA99XBizhUMf(R_okiDEJb79EuO*u%rFg>Z&8M(mSqHR(lpMlTla7@GZyqj86&L zP?{+C4|tP@pv**aI0qRtC!cio0899j>=mnDesqC3y>H?HIPyf#WDnN@BJ>*_-6DFC z{Eq|!I?-bETn9G=?eW|MDntdlC$?1kR1x3F| z#`!he&bG!bEc2>$Epv#;TFTuET>^Jhx>`;&0QQ<{T-iFHMseSl6 zWncHO1eaC|0)eS~`vtBmcE)BWZ>}|RUx|^=r4!f~-@n`xU4Gc0><4ZC47X2Sh)O9Xian78!g zq%mz;mD9fviwW22$9Jk`pVuZ!OPrnfef5DNE6J8@?R$gAw+TiJ$h-+~CC7-vt;=@hXbf5Btc!Ngk`$Or=AduQ(EI+i=Ll{C*M{TY4*R2$X7Flh)=}uO zlh{fMP98TkR=W{`qruJLKAWHd%9kEOA&TBjkeO*hyr=h_QM2hK492`~?}kn^a8>n1z=~@}<Cw$RsajD89d+*b8+nqd_4j{uI4jN~MS8Pq zCa$w0M1K9DNoH8#b59Au-MLPQuu zqi}^(QZaW6?OQ$!g;o{2Q@l98Xz`w^`p0?ICDXCIuhmA|Q3xNmz{tULH%Ct2^2PF# z6!G3^)v_dUcj^iLzpAj%Zx0RwIgiU9LTU-9vyPAaH^;(DiTXoAO#-;4C7OP3{*5bQ zBC{{?(JSJ5rkyox=kd#V=VR`?W8M-cqE-mp=C`XaZJDQ|;q;^O(tV2sA6f;xU)#hb+k79yVFT@l#@b zeG&#!^89@+=H{)z+F;6zxxEc1`ad*8Sxp3rZI zz>WE-du1?yAZgb8Wh@{=jmm5~k$$d-D$Yf~9Key%tfA1i+XPV$@;AhjG59(J&n5)b z)SXJU1ro)x5oRF#JwET{{O4%29e=Y(KXF)-`ZJC*BVX~GJyGJ~G_~AWn!P53(Zgm!4m9@wfIo0?OS?@IBaD-HiKm8X+*3@T!SvJS<39pHOEgna0 z@&c7W)YA8Mxs645(*3>K9t6}hs^3)8_(8of|to;@SvpH-hjcJej$%qQN;7oKSINOP{!z1H_c&FYfR|1J#N}6 zJuW`pO=*q+mm!SGNq^gd!I}X17yTj_T+rkqodPzl5=XXyTyGSt0iO0eznl3jv)7X{ ziut94UgntWquy;T^Jb@uf9cmq>S*n&D|@heEiM4fHK^Y)`4M2p##<3(s~Oy-}; zg$Cvw?dWfFzfoQ2nEu)guqV>{IaiJ;I8LmyhCpYFyafi>xhqqazdw(T=TWS!SAX@B zjheOfDS0PAoLvTrj|Eb?X!^=R{)$R6VvP@#8o*^^N+^S)g1g?KD4DtOv3~|DA)wG3b&Mu60Jj z-ztHM)lL%am5@<*SVyO{vfp^~wRE1*_fAxxpX+fq&auD?Y$|Ws;{D`n@Rq&zEo8no zb`(b#AERaYaOVOt5V9VnI@r;R^^8TZnp#N?Y+XB9p>v}7Y>Pl*N8EUf8nu5T+Xhqm z;9~Qc>cp7>QF56q;w1ZJN3&ys1XxRMYtBtTd$JokkgrTTrhWJIAi!H*7N}NFL+1c^ zB|g)NI$ih>{SM()^mF;RGEz9llGT4WlR3bEK704ZjO--z8?=IEw@Qq^IlB=Ufl_{1 zvfe)7Njr{XFEmZ{L|QIdwE3%)1Mg7vjW*&fb(YUB5N`v<$;(gT$4WSdC#E;&<%FHW zO#&#nrO+Rxwi>s$cRK~)p))SfG6)kDTqVT4@IdBz2Tmbx2okHJIlR7$(0=~Wz8odX z2gn61KYY$b0#l5y<;`xM8mS-^)OD5gs}(vV$E^Y+0-}mFqBr8e+3UtZ9)R3CxDJDP z^Zo@bx@mPJfb!%6GBOxZsDe;B)H~jQR*v_N{e|RM^qJR5c@z>8$5*Gn*MsZ271gGm zro}|ucothZM3L;0p5FOoVW{lXm3e>_1(Xdw2uLUzz?F$F2?OO0jNb zbm{R9p+Sn(G7yWC5|g@2Z&$R2ejR_f4E=Asv&9)K{6{R~Xi5P)N)T=fr_i|Nli>JkzeC|9{fK3RKm9o1 zp|+k!ri;EdIJe_{#AzP|-HpTia(0~J4s+OGxh2c5|ESTP{6O*tUo{g^KNP_8U{6^1 z2nm{|yKh>)4%w4u{H|CbjFt#$866^TXfZ{rjz5iHxLs6fmtvR=xRaxI2Qy@PO2l5{@k-&aAT)YN0@N6GKlgD@5^PM=9iwu)+ ztM`*_Tg-4y)&sHx*5f{K>@$()lOdzCiaMXYya@oFdjML zrV;U5d&|)#^oDfug@pYu( z)f}f(9aFwG4L>gJtZ+-nY`unPyPz6}SLC`x=b%_=7HjuB{94;pq2R#8(Glrdgwcy= zezKtXM~V-hpKJ{1-i}=JgY?i5ef`MEW7ZJ0dV0E_Y<|+hhf%eXD=RLn zJ9ikK<|old4kmcTS$ZM+2g^j?X_Q1}QuoXP6N>hG;X>9Ut5 z8d^sedj?K=$nJ~oTV(rOt`@H}p~=cf3ZDw%7{Ke_!%@GlIz^X`<3av7qP*WnD~Dm& zIo_(4>(hl17|t;JTFX~PMC~^Uk%^1-NvD+d+=*72d~{#2f|XUFJ)0`S3pV#IN?ZEu z2K<^w&dK|9=}q~Gi{M*W4ZhF6vM%Jg#x-qxz1J)0wcCKT`>1JgaYq&DuMe*Hr^7=( z6U)$q9?bKyMgE2T6m&3aonZ-fU$yU!&paC*5_}tS5HYH@=j=J7iY42h(p%>vZ$4b|8Bvh+c>O0-g6nbPu% zdq>9t*+C!^9jvOyIZVkkAhh10zqpN1-IbDF41a*W8w85-4y0Bc z4D2Y$^i?-U6LSvVCu#Mpe5WG^unANO{Io zKHe$jK6mH|X?p(5s8_qQrr5}p@UFz}PPW3g{2SLr?Dt6u>FkVVQQx?!H_{Pyg(r=+ zUymT48Fr3Nr=5)$OMffWvMx|_0A)T|*d7jr_upNn_}x(KyA?(K-TV`74!b87xk?X* z%Q@oK;S@GrkGY4mJ$?yhs=>N`{IdfFb=vGrq2UP_JJS#ERReFs1Cm$SK{R!Vie9gZ zi?^TME9ZI{J3#`I*Us?bp_+)FI8Vy2t_B6lMc>2Z$%(P+|kwnv2f@cWEVB zifVoCQE+JA+-F&|r!u&8Pk=MSi+mlPTfFY^n^0q<3ub#kfrcxpF;3~7*pkC;aeimZAr08{{(me-NeNQk0uHjo~)S9$_ z>R+wh+@2p%O?&`_w>^B@`ljT{qTRIb;8rEkFD_P#ms(5H+s4H$BN|M=&++LIPI<%3 ztn6%em%7g$o}POAePs!pSud`=CK#nGTuRl+dDP2alL+S+h6zm?!YM~7h z%4zkQG1F14q<0lk85c&9HS=qsq(b=Va2v@q#iX>!H;CP!+SYKf+sr~qt8hR}WxnA)3(plh!j z!$MDi-uotwk?@rUHh*b&uZDY6xr<`r^L(*9N@wvlmke?>+Q6tUVe`}#E|^bdJrfcQ z+^t99)~cR8o^FJZ=x)&9&8USYKN5VdqF`#MMYxgti7al zx3znZiGi8-h;7)l4f>qP6N!n5y#rF-Qad)WE@eiSnao~B>Me;e8&f;tY!-zzspgHV zFE0KPN9-e z<;eUy&hlRV11JD*e{3%!I8)3R$iZ)@hf(*?6+G#^DP4Q_YFux^=Gp&#Bb8-on|pFa zQe}PxnMVam6tMNg+Vgei;62Wm)C9?wHYzjpb9R>fV&vz;lCmRS7tOP>Q((Tk3WU!V zP(hQ{MwDtw8h7|5oeo+-IuQP*bk56caJS~g3$lc=)u^jtoK2ER)fHb8J*@m7^P5*z z-b#0I>iF#OV$Zh!Fpmtsnp68gq_WtuPUWoJ9n`nQuBd4ailsZreGj%|!?w*O5Op&O z^K=N|uTKu~-rhwF?ghPl*_I>4r(PvRk%>W>29?i0&w@k2%PST8?@)j<0r2!d6*cQw zN?JnR>hFyLsCwnmP57yi;#aNVfo5zq*DHx1!qL>-UxUFuUD1+`KJi_BjXvmr3~48Q z;Tof}lbc(S=HO;!g2$trN1`QnQlo#m8i^3r$EA)mDMwK10dOlh*mvlHZ|taM>p;#s z9%R5hFXi^OIlsR?>|!6LWVy$wo9WSU6m*~hV)Dw_&|PN z*H-Q@?AWmERig>dgjcUuHu~rlK3Nvt9GWs8)si7VM@ag`Nh=&UoTCd<19^<&|I6{Mx(?0}OG879?H1 zrl!?2Pli#pFQoSw#?Ld059j>>gFLmhxog#RF%;_lJ~QpT1JA4x2j&s@u~x^^q3q9_ zow5?27I4anal)HEw(BHhQ$GS#@i3&47K%8@e#N$TrS%e)6V+7ufO`*~v~=CJfmc8U z9E#9jhmy}8bsTHWNU7Ak$u~)o!>}Fy5;ML{9 z(bx~{?9kq~urXvho?0WAk=_>nvxWBRxvB2#Q*>b8Q_>@3G!c|ZuYmOl;CZOZL<6AT z$z9(g5A&SGsycpQak&0~LCloCa#iv2eU;|?N<0i#4?F~8IP;L z!Y@~{jh6Qhn2=J3FEijjFmdL`b|iNsG5wbLTKJCJOK9&xX=^^+Zqfm^YWlY1 z)#8nAPmN0ZA72a|@u+tt#oU4MbC-mAb$FW6HGrp>no8vu^VXBe=aUQV&Wlvni5KqF zCYC`c%#j}UimKbOae($sACU*>y3o(xUqlKz%@ckY~6z|b`?AD}k~wWpP*TxeM7O-b?P@H1R*Re+PcO2lBs zUKVlc{63vV0GWw+k}K=dD?^n;*eCxWCM13Xo*Spcp~>o^;n(JTUb4#(PZG45v{Yp% zH~Z7-teljW$maW?N=cWL#Kdr^q8OF%On1i@j^U^Hd7kb|QLmT;hw8A_IcZ75U{+xe z6P?*@QY~q6{y58fvMGZvjNND6vL>;Zb zh+C^Cb*FF$`OI4+6&<)aK;G5`<<#D<9>nY|7FnzyECs69Tra3v`C!Y$A=x-{?qRo? zIhb>^{JI+?^hQS~T1lJu9Y8`j;uHBNoe`@~4+T*8dush)7_wY0xKI(AFL&H?bY1@? z^^B$_C8-*8Dwz9G-`%)(p&;e1};wr^jvHid&Dhj{st zMW3~sbU|!cStmXQqIl`pzgV^1u+zHOwcA7O{i$U2jsezxa%xM_|IAXOu+1E{l$2)g z!AoKE_k2w*uHy1qZbFu0P@BYpH{4j~;PdBq(IrBR^L=Y-0my-&JT_|!=4If z;hzj6a9bPz_4_Xia)jXvk!JK4;oE8yo)CtqgqiOJ9PzxoCY8>!IlZCs z&djGI!hX(t%{Psy`L^p|6JoKr;ATjF^QwuVW0WuHU0(JX+iIOe95ijeU=KiQKphs7 zmS4A;<#T5Ie1HA*kKmobK3u3L(~pi|qGKSu@azLZcz+$hzfr}} zzNUus9)-#uN-%={USF?Z$260**G(T|rR3K$EG`NhdlbTOerJ|UY3w;6CjWr}*~273 zn?)JzD}J_VwfY?0RWOH|p?JBk%elnl03_vFt*ug>Tz@mhz-{jDX~| zV;gBlTZ1O-W2&q-j5I}l_weT#8W{9YR>yYdZ13{fh|MZW(ynJLx}_|kgqK+Dt8Q7? zYiMZX=jO)qa;!s+qh(}DC02fUrFfde3}3M){JMO<8^|bxQN9H zEm&Fi-B8Jy$2|#F#~1QyN&8%#6y~Nf(W|tt5X2B{LBJ|T&j2%)8c_bJ``$_;H2#EX zyD%jaQ0IGxeQpiQl7(b=HE5Kjc4}068A?1Q;?WlbMFLc%c)o-wK(Jvo1jkf&4v18! zv4hW`Tm)wzaiV(=R54B-^u?kcmK!&`ZD7$>1?<&F+o>hql6=ecD~(t>dArDn-MiSR zMJyX80E{Q-C|zf_xip3W6Q9L>q4?GBx&v%ck1Rn(t%n5C~F@W?IsE zZ+&}w`#1&kbajgwg*8>@I@FBw(c5D%^=%Im?9bc6g$(&gh3Ywp$;kr)iM&*pO|pkV zam%*%7vrk5;5!b1W{U%fzP8i$%M?8NCvQ=&JpC{15>dBSOZpyYOx5^lGPcVYEO7BK zV$<1IPBX@B&xwNfDKIH4Hwj|Dm!Z4ilo(0#>Ut(rS&(>|!h7?2ZJkbL96!yUa0@6i znoHGnr;R2Bsp`Z><gDu!r@$-+MtMeay!-ycaUKG#$ARzS7VZgc41~@8?nM8h}`J{AoZ{LcoF3F}MovC;R zsUH271XwrHur6c%k1-lPL`%m1DJ!}CcYY1Ci}I<)wAfZwIfYdRfUU`%E2Ajgoc(W0 zuV=$rW;gb8-AB3YBO5~AD$R?9O6&4NgPfe4^T7nyxQBq!lF4+UtaBHxqN2^!zvg}f5rN&BaJ1F+d&6e$l)G}{oQ#J(yO2QX>k^c)jl>l~1tplZCn{K2L*1MZxHci73|q-981doLki=BD|kBUiyu76 z?>3dfQ#yffmA-IJFDVhNZ7;#33mx1AiQa)nf=s?P{b9x%emh?`7Dy{(( z`DM6vu=e{n%WpsZjQi*wN^-|xiU*|i9JbTTHO;DK7sy_B53Bm%M_yM3-E&+CJFgH% z5%@Uf=gRNGHnRx1wHvd`F&LGxy-?$uA?N|{M!ick?LH8q8P<$6D=I4X-@2=HMh{v? zW$ip!wa7$~-3W}Wa>u)?6-q!-S)!=L<&PAdYA)SbMMGb>6wNPy3Swf4j|X#7f|`5C zdRdUC{(rK>iz4-R$?oVDdXdEdSl(YVl4%M9a9scM3s zb#rFUOStJ1@;mh`&n6ZinX!Ej=#X{`u{76>^y4ifTDaar9=*3A2l}n`eE(0`^~Jci z-hDML#pex|zSFsmz8`sOH>;fxLYFbHzV1jNP?5X(y(1Yo023(xV)EQHxiDT+%ZUjS zgc@+{Jw3wCC~GTBjEoV6hhv6Y{!~rB20EhTe3rA)E=Wg!Pu@$q*3SuE_(epfhpch@ zjtA8CfCi;LgB-J!gUK(IWi$Kmy>Q0MkzZ_H9wtPiCr=x}%{C>POrPGi9OnH?kwsr7 zCTnmDbTW(fJ2Qq;+4M@)Dg7g2M?d>p*bB3escQG>JDK@hyRvg_AJDyNTqqh7mn}YM z9JAH9DXD61rQO<=K5}Ai-N;k)E(7#9MQW#9w?M)zs@w9Lp;T`xH0QuO-fjaZ}gulAu0s%}&Ln0g0lE$iv~(=;Nn!EIxPlxnPB)~0<6 znIju>5%wtil}Dw*`bNGNS#h!U?tT8VF9*4uf-Xm2FTj*2U9HH~oe1+~n;Kst-ysL) z)B2#EIR?K;yEk#3w947N+8`7-hww^A zaGms~rkR)aC1zz;cn++CJ{O1Ns}cN8!d@k2*H@O1l!#XxtH4Q=!@l2ubcXd2zRS_w zbpo%R^FMU2i7L%3qJ+gLzU&{xC!oX-rwg2M%}~$its*Rzz+T9i;>`IFr3>(W1oNR< zQ?dQw`-Oa|4W%|f1XQ$*yS`Si(|ZdqY3MDisz;yI*zlO0O#ZfPI(p|G3|e}Z$~faiE0bqbl50c5Xm;-AD=z8=cp-#4&1?=_yuMXL^A|hRTDcvJ&AIoY=q0|i_>$Uss zc2&h@&FKrG2i$l&bDKUp4sNS^TavZ56-Gi8jdvA#sbs6GR#ZAz5d7o%ePW6ZutbZ4)iqd_=ALZcoVnHnV%<=wY5K6N@=? z?mYzini!r{q(QZo$rYk*8X1m8a#E=ss=3#t9-~=IDu&evj%P#stEs(9)l2cX64&j~ zV#S`Hn{JLL&QAaSUE{`r>b$kkukR3=RV$zy5Fv%Dn(sX^#LVSx>_0(X8-LU0bcWKU z&~cEnz`6ijH9a@W_IjnV?6*|+@hGoc9I#coqXPl+(3y9yyEac*Xq758w%z{x?j7?H z=5=y0NM_X!+~YgpKP<}i$NeZ;xn2~G@Rz@ronc+MZ+?q|wXRjp1KC^bb-lx1dDk3I zNdA?Ja*q@qfxrKXsxBgAME-0R0^J47OYs0~h0$)6n{_iKRiHZd9=6vmcob(} zu}u~YU7NXXF3Aj1Jzr8=+kHq+a z@Le|L)Zvn&8+H}M&ylUh32zkp`~p@y6zvFaKd|ssDXWz7es#Eb>7E#$ zs3hHuqJC#>ftJ=nr`Suu=m8V!-}ijH->UD*T&r8KBf6}E#@3>NKF9X#G#G$A9S2-y*WGS{A5E&aK%qXF5rE9MmBlGmx9*sWmHq z?0UfS)8!U0weE=v(hj)&{1?>U58O^@_F_DK{)OT*sveyX>FZfy$}XHR(rX@qCICCQ z-@%!5csB_q-&ky~Mv3O7m#X%&Y5mSJ@Y0^X?|vugTA;es?T>nI(F4tXMO!AufiDGEX|=D$_FeB zxC+SA{LxToD>M?@5Q2ypn7wv9*i2)&zT;8fayL&VU$#az-P6JE%!#~{XAP3txT^;P zU_GfCb*sh2#~q?^wBOJDr&-byJ@J&hN78b~#5#KlzJKIorro3D%OB?Zq?K#KWzu4! zn%lQ(@t#6FndNBejox-AxFi=e>Ow~w_Ri+C3- z{~j`7TIou@mXYW+!HEN`yZu*JBq_&esG1?PmaH@I)n985i6&eS9zc)|ckii7eIr3C(d?uC)UbX*(A+ z^A;YCN>?$K;dW|ecHr{9gW~?Lq!s#dH=nvk`n%mh^xhKtA(f*ifZozRk}0SW5%6>< zP`)oW35v5nh04RknD(ui5=aKrXX5)es6k&QYeJHm|9?~64E{fbpERk#U z#(BYL3F$9rsS#c){B8LX93lp`b3T${veNW9UdR5cEhJ5k@d*o+{t|a)+5chH){LN* z&XCijU5I*4;bJzwtzpyidGgJ6;F6=;nD=&dpp2MW7b3T*A_m!hBoFeLrezN=h%(BV z?T)^ham?e#rDML-*SM=OmH!tMb}>VQfr9m=ET zHio`w%k%}n0y(s9!e2>=`GD*`R59pRj!r;DU-p*G4R8cH^LfI~?t1=@=c;@3|B-4q zWxdqpkJCUGne=$^tF|H)Wm7ymLs-_+WwY|$iCR?Lnv|0FJr1b-riv{NJ^bK0B$`k) z*mGK+f9Cs3ebo!J0+0>#fqsIs zZuwGOwB>Biv?_7|6P;d9Il?D-eY08iO_R=b^r#!Dts-W;pQ|4Yy zx{PO#@*QcBxhAkgBD`}wQ|9?h$L)AUhJO6I7JpH3NTZ?xqLl7qVq&ZVmn4CA;bzh> z7k$7h={WVASZ?=PcZv&D6rdS4&QFtHQgb21QecF3JAE{^7{?YCG5S9}4ah>f0QVkM z0z$D>{e)xaHN)Hi&`RBsXsW}I;hBlqQ@{Gw^@V~9pu&Vn+Ik$nD=|j{?)nbMa??6G zp4tci>(GH#h?C@#aDd>}kG>>P;OQ!f*##^x$WRt@`s2%cR+pmBn3@uXwy}SH-!Y%Z zW}kHf4{ief6K~g>X@|i<8IAggs_!Y^R%Kct#|84vE*W)$ie|hJiu?>8AIiN!jx3AOoGLHM5XWs>nwa@u8UZNy|y z)8{yg;1n^x43Tfj*nwv@eX&H zAR?wR#U7P|-fs!q(#FbteOhx^?<)*eUh>#r2i=Um`Ho)sUC0T@jw6p2oZPL2(`l)x zGaK_!oX)D&jIay^9%{rT5O7x2yX*P#7u*s4h~pEQ#0+(T(AtRwsoJ=V0Jd?i-Iw_P<%Gf*0#wL9})Jl>_aredd zvfr|S-X_{7POliWFMNGHvr6Tz!>At^AR*G#VqaSA$tPtfHd^7PblfRA?`_!;njt{m z%d<>@{^K^@?w_dV$j$pv;{Ima@TtU!U4AIqz!SgAJL2T6M_=rIg!DY2Susd^UtDc` z>BGN+*}C4W+ov!&8M3FcY;;g>ybCZzwmTlUE_+?a&K2def{nLnyL0JEx8D&A#^TSDxn%Jb+-4e z*?nryBQaTB{yy=f!nWJ|$3M=DY>(y*)p&1l!MTraC6G4C5wkLW*q6cS>y`C@P`<(T zpTtcoapJs|x3J2}bv5lEQ%UC;u9EdAjrLpLIq`4AQ)L#?qWr|${Z~u<+kQSI5?+Rj zMNt2E6)$%GfGnN1Uz}N1eNboje9&EAe3-p7J^NNq#A>W!6|3TtH?@V#4x#h&*1b2I ziX+iL65?1@HftZG#J0gw62YXBKI&5RKc2F)l^+hVL667 zlf$~?K!RK{Cc7z7ot1&evXO($UzdUwkd}4RwC{%_$D<4Q&%3VN93&}$cGZR`CMytB3Ravtqa zdoSzE{)h$@jZ0as+`W$?xIa*$U@Ey2;Wqx`b>tME7u6LvtS}G)?cza8CP{a8lu@TN zd~o-1(!;?`SLWg~`z6n+=~B)VIBJ~1MBkVc=tQP&NJtzLKU{nNUH zK<|=BqJPi^Bs!r+i^_yI-FPy0t@NF0mQ8hrGo6S}V>Xajx!0}`Yec0aI7KRoW?2ns zU-r5ZZ&%gGb#B-5Mx@lmSx)Z00hVB7uXz7jYSk)Pof1bKGSWvlf`zsDrCX_+L6U#= zNe}|0Je67mFe0u|SE4OiTdN_?A9k5-TMC@NoRr-UAAA3v|03i{Y;f?viHTQovLJ0H ziTtr$z_9AiTUjvdx57y}>wH1c$9SHXb$zXINz!OXGJ9gc#xOM9k3-11^pJegP+>L4 zwE1utYu7E(d3+58jf{OGW3+$a=`RO6@G?SU-|lWFSbN_nbPbvl+4&zw)4a(q!%*Qj z&ge#FaLW{(NGzGYFk<^6ws)(LGGmWf9wZvD95ZM3E{w4IXe=bTEhmdq74%GLy&{6r zpwQV0Z_vJ=c0zi(2bO&NW1tGEu2Kiwmq=tkAcV9PCUZoI#wi|j>$u|N{YZ6;2J#_s z%bR@aMFC>6gWG>m-a9Om$h{L8o41!WZ*w&Rr6K-1s$o)FYTOe9BB`Cs&@+|m*z(O*W%+i&yecn7|0 zFq`~92*l_cxxWyB4PQ|CZCN)iYYL=7#CYp(qhm80L<2dF=Qi`R%kP_8|L5g5-TRx! zF7y^&G}d(k3ZSAQH$WnID@~c~K|OSsQYBRmq((DUpLKOp&VY3_c~nVx<79B#@$cXA z1M#c0XH_)(+k_*LIFu{hXZ`*7a=`1`qhjk_k$2v=PTxu85nW5}PC|jJsSRJ$(!Ck{ z+`BNPl+@)^qoez!sL91g7}M2wcqX8y#`ipF_*BP0bjX{s=F^Uc)N`f_C(-Ec(-`}8 zbP?LjHa7{Dk+>w(@=~g!zq2=y7@x#}uz;B4zWBcCUO(J}jrn;Kb6@@gb2#Uyw$&3p zvgKZF1op>y5Sa$v3PD7rN+qY9w#XTcUq?YCJXe4X6ga2O`R@e3_$aUY>)3)>*kmDX z`;WDNvEr6~gKczG;1hRqVu2PLEBwBef9_i0Sbc}EW}{x}#- z;w;``J$Q57>^tZ{PoKA#E=9V_>8z(TY&5rD6p*%LcueVU@O|AWNta)4A^2p$$8{(D zl*qC4n*yK|yCa%ewR`mVfTZbD8})w(e*ODv^q>#)c~}Q%2`7c|k{vQE7|6@d1_(&A zk77D!-Lb+!lc>>gRN#x3k0%*jS4q+9CrXLBeHln6u1wlDX^(-LncgP7uhb(CP$e(1c=B6M_ zbl6`d`NU7`M-D$WEIfenix>l$5);-M(cixY&=v_2eeNM>s_f%mmmCoDSQk_!>Ieoy zG;vo0<&@QgX%t|D?!J#Z>UPLo=-@I#0Pi!rKVKSY zX+$x!`=Y{gh2``K*O_mJ0>X{Sf+JoQr3ki_kK>T;FG%5CtNHR85NoX(hj%0Y8YH&N z+7>r5^3mG!pq2l2z@|Ebqu*ktLiSOI-Z2ozKJrTxwle@P1RrS>1EJVOtgg zz!+m?xU(jDcFQ_+WS%F1M6NpkR&Yi1e`GSmQ1cS>Yj-ch;+S#Qc1}U2lWSK}djqVc zv*rQ8z9@_eb_PY`QN?F6kF*d_swPaq(jVA~ChRxjBn6B%G4GO zszR@8ZTbcEr5umApOdnPNdp_(j!1!2?msm{>oQBg&LpoB>nPAnc#fY~O|kp$iN~m{ z(Ss@q#C0QGw-={Fo(I$tc1^9V?;CPDjNa=d^Kf_$<+BbvdE08f^83@f&e@#)uiLg3 zb(FpmKwRDaRK)k2@WTCcT3HoHpKIlDVnr}$#E4%$q~Ebhmrg(Y%ot$pXAK=~#m!sH zj_mf-YApOnjC6coqKyBrldS1eP9YRoWAlb^WIX)p%xL+USaLHR*%j`th`YFQzKWXi z;G^4N5Jg}csNso_QgxdMDL}h|1z{uVFU4Pi5UEB21rUQ5S_PAZlfa>a+Ll zOI54eCxNt8qO9cvtSgL|q@BENl2*evB?TTr zd1I(vH;<56zh#xVy|8!e3q|`eO~8$V5TT=ct7}X{P`QgYSK#rR$p1E`T(5AYfnE+! zC2tHTZ{PI+jp$`O-oehUsoI{iA*N$SGld~mU~;_jgx0^mU3F1X|KdhK zF~OqV&px|Ted{4QWt64=t(_yK>PZoMj{&({??Q30%`rX=e`2{DQBi#am6T{$*?un~ zjvJt^0R6X;$m@$I3#^>Gxfe#g1cet1wz!GG-2ng#_|0%p1K1}7D1crgZ#lZ!0C*CC z4vmRW`)sYcM#XW}w@_R>vvok@UyGL=2sbd4n;ukZk^b?myOhyNNy(r+C=_R|+fb~@ zbpJe*pE)b=Rd1ruZhdKH$ziXgp3hlM5W5Mt7VcAUf910LF`tj_++i5!5TpCN^^FyK zb$f>U)HQKI|9xNKppoYXJ=t3a&F32T_ZsLl!gD@DESq9C8C%h7%H!WNGy}EIg&xU) zyb=~9*U*Wt?oo#YE-vZNL7{`(UL0E5pf0$Epf@;e*54K(hpqa#aEuB>fC56EunTs$ ziA;SZlMgq0af^t`=f&%nA=sg%eLMH@=#$7OLS<#&iADZ@hb*QhsZCLWYfXtAX4MU% zfzttZUN1?P5%$0BjfgBT+(SkV3SbCSz&zMz*0|vS?6XqY`9|(s=a1z*u1fq!T)?cAH?3LF1%nRwP ztdp*x7jA>6VgrYOn2;n9W!po+F(Kr?Ei>0$?b^8aXraoLrp=dIl}OGaj!&^H!UAGj_e{r02A7BBJU!f=?sxuW#S60kQPG-W?u+d* zd2$qif#40W>-%zOXctiOQBl@x^}zo_cbNf+E_ui66j0lJguGx@7l#!wlI!RMv{}X1 zBUsH>9YRHABYfo6H-pDr^=zj=M6LldEH2O!n3W!nXS|#aY?nJOPA)t9Xl5rX8u9=gc< zI`mb7s5%k)0NNr`Bg!zVub>eS4S!&DDNr}_zx4o5{iIw_buSXo(qr=^HGGEkM5e1) zjBi+LeTF2stz(};<^WORaAagWV9CuyeCS7i?Z3^T=1hEcv7^1RlH#Iw2kQoKlEC89 zIlABj1a$ZAaT479F7XTKfwW`$X~(d&7_qHN90GvB+=F}%ANcz;$OORdVKI9v7L}uO zrDN{L1ZXYk#Xs#5d&8J5?2|i4JB1oZxYhDj$k}3Jf<;9iUBO)`;}yXP=|T_(;!zVX_t(S0AW-%_@&{}5{^Jxdj|sR z)A`6(2RbE=$DRXy?I4YXNf*$0LkEtIE8Tyz>Ll_rVBn!DGUJaVnG%-vF`3}0YU~&> zQVk3`%X#ger=p3IF;HGQ3WN^eg=V9m($TS+`PFzXH325|ru;t$6Uc--2F2L*xGb_j zK)wASisVAX6n--VO1xE(~dv0Tj7qe+Ks91L%X>v;EV$c10FZ*Fpbp>>|T!7mP@~k6C`c zO%`~qnY)@_hfCh%n((pb#Xh(M)>-Yrp=W!K8i@WdQWq0r--FnHlK!Tcq=lz_m=sXS zfWjXjpCEQ*X39hA)1IdE*6*FUcQ} z$XBRqK%>(ntwxBVEI3CFs`R>xrA;{n>LV|*mNL@+|CeRfJ;41 zAeSoP{}@5ZHOQ6TB%^e$B+Q8-Ig{tt6KvuU6QKgUu|mYOh`xxdEOy-@}EJfoABm5 z=N+i@n~RL!GBkU$z0(*o-5iz0|)HxExep+9r;KhPgN z!4M-C!0j$d9O1C+Aya0O#I*de<eKlq8pX3(COK}NR;y#fTqbAK-0{WfCeb+O0i!7^UeNH@~5yDag6UtFPsIC zr@lqvWcp0*|2&0rWP6;(ds0r&sjaSBPDX)h0=&~M;z%qpYp@6IwQNI-34dGV(Ne_O zg9^*=*kc$^+uyL))dp%0N4?&G-e<;epfM#E%3(ja-WXT)o>U0>GiNGq;B<=*tR5!* zQL1rgSb+tx>s3}*Km8WwB={Ev<;mG~ec>O`r8DI6SO4jy45hWTQ<91NJ2&hTJBTEI zIYMv@1SyTW0sxy{iwOcgIz@GlwfTMY+yz)EQDD>s#AaAx_bWLY`jXn;3}!0;;>E0N zD)Bi*I1@8jGT1%hJHu{)*SRfi4^sFpby&0?NGIjp7#i6~J~99EIjbNlEMT18Vaxvg z8|MfHm;v!f{To5E$gTBc&;EyU%AFp6eu9rZ3Fsl>9M+!=)VjU%9 zqyC=Rm|PHCuZn47J&BwkjGicen+x=v2-gEm`w@Od`O|LwjG>f*E1AY8y-=8HIvB^>=zeK1^xY zV#frd_CinOKAfb=$;s*4S}Pu(hbBED=5fPW7y!(vpaS@#P?dU5^pL+^YXr(MO^y-( z4@RPtFccAcrO?_k5iMZ2+v{H5xxnDlCZf#^G%)P5zdB~C+c)*{oFI=+;JGya#qstJ zS1_ga0mHqZk;(#?^?$R@%4>7KK;rB0|8aHY;aGKFdmAD{p+Te~G)N*U8t{~g3MI`7 z6;U!3Qs_KVQG_%IDV3B8ktstYi9(vpvjzMSQgsxkL1XQhm|ngy#N{Mz>6o-K{@{rZ`V+F+E~$h? z<5J^VW{i7u;v-|L-@y3vBa<~c=IYx{CoXJ;Sf*YzB0Fa=EzNEp7HP1k-GFCcWpfZ|ghVdLrQ`o&D@? zCw*+wH{E?b^H2C6(UX~*#76raFu29;OPl&rNl}u4=HIoP z(HnPfphGXDwa$|D$5iMXgoEfO*F0=!pq8pJO=0p}&TIq<7Hm(gJjTP(WFtkJ+3Yxv z%-GcLj(@xkZ-iqhuB#ff02CP6_Mu9tmZWUdzfP}CxPd9epSaeJ6H~pU=P~b~lT%dW zMB5<#aOmHy`0-3uSy{Py(U!h0*UoZV<@Ht+R5If)&aRnPl?2HVr=NbXhgo;(P*QD? z0y#q`{4sxM1Tr_1Eylwwu4>Jyb!5k&y>XmkjlNO#m8g zuqj9vSe+D8AC&RK)uP|^j&~c#dGWYvUWmH3)OKPj&zRMvl<3 ziHdz+_s&g-Byv;WDAIh|rkH33aV3k;61z50jo-t;kA9CAlG`+#T|9pa4w}h=%aqvQ zb1U!AR)B25^X2O`N-l;V2RUdfs?vu&Y0wp+Nm-CWU5^wmS<|rvm`hoJupAtW7tb%7 zLJi=7?wPs_cBE^~!`h;2PF_D=ogJ#B?D}}W#2b~Bt=RiB1*QS~ocTLw!JzTgM-FOA zQ<^?VxP_fqkW##4mfBB4=N`wbkTxkBD_%|yZqpS!8~yRAT6+ZLbN~wY!ZSj|`vJWy&pn|oYh^FJI8AEP2Rb|!n36I_%sO=e13?I6aUw14frDAARb{wh$DmeH zhhND!=*waq=i&?1pi7%r$FelKBzsFfb4WB-f7* zDF1N`w+)ta5b#}f&*{m8{l&-aU>|4v>3H_|u{Y3)kzZ=Ff@T6aFz7$~r19OCC0>g{ zBNBGD9?vM47J6v)t#^B=ukChGN^jyGRLEy75eYgxzG9A#*TTMoJH95oa@u@v_J!Y4 zX7w``?n{w5qcqFDWQm=XV?oWFs%^95>|h}(a3OSnlf}jhI)qy`LhN?0nP#Rg)!sC9 zDJj%KR|o9jhuq(NAUw$(wG9&S$zvwGV^<@U(A4=(TIS<3&Ly(UrV#bmvv@6QOz6c$IicL%&_)mF3Y46}=8)Cw#DA@7n18 zC)KIDX5C2A_k{)1Rg!*n7V28^LhQptZ1cAUUcU=iai1(?Ky%VMne_tgOQ2k@+hzt| zk-DF&Z3meji1j%y(cYM`D3B_If*cqQs*7h;)`Y;a4a*J+*A|}4p}r_h$y3}UWzH!A z&dD_|fh%@sbe@X__%@ky(?#2MeEQYVDF;?nrzjzFbf>Ld3g+QYzVG=D1?TL!&Ys6SMZ&4?d0jvhrfG*3WM^ zP@?v3){Avh35Pan8X-aH--Ek2Z;xSQniukW>7!p!SOS1f~@Aw)%$H(}tT~DZBG;A|e znn`C~L;iLJ70ucvznTQqurr@YraZ$A3 zA)p2pMJx9-?=G$Bz4W)N;hHn8wWO;W^M>=K(3qojb1WyP)PDg#as2b}K?!fpl?mz@KOud}_~SXtwxA8b-psk_+}QwUR~_xZU)xVi!#0by?YT8%pWJ{y+K z{&p#2uzTm{=Cny$2uBRhB;Pqmkb5=8LTg{^xgRA5khO*=FAJi33RL%`Pwt0J%-J*g z17Sj(s~CSZUwm%7BS|=4|9uV7JP@P0*)?y3sNeQ>qL*0wjqI^cjqIKDq(4II`>!Bf zR(Q8LZj(_<%GU9K_W$;*H#+>o9VD`A51kFTA!F2G`!yxKZkuRoS-q=K=+ax%yOjQk zPn64@e741ZD2=`lX7d=acC zmsUf9UHMC!j(BAXH~l-IfOYiQ{df8iX%%Cwmg0Bw0)xE&RV3;Y#CUXvkLOau4H<-s zJlo&%I#&*`?lys^cM)qd6~W}sQE%R7cw=h?`KLG5%>>J=Xol{MgW}cOHqQyIn-@IO zeBuf%vE~>^Xx&vN^PAbWXB1eAFN%w=tEhb5neG*D-Lhl3py~oIFs8#b(q?Vb1$hXy z2t%ysmd4Y4ShJXjMfsXfv0q*n>S4`O&Bjz&cciMtSoJHIO$Cslbq2n}54H~QvNXN? zK`d(XkqfUyNGl};&Q{Ic`@sM>hs`t;U3LOBg`elaL0^A_$5M@bJ6eVYWr`cu$T@We z*IWq{g{wbLu5!=+JddbJ{aa87%yOa{!8Erm{Fy7FZ~OerIfLLc5QCZu+|rkhU*_@l zA?#Y;Pa7zRsF+2Xy?W{BW?=L3JXCAneV^l$DKuf(jJJoy+P|f^H>p-njNb8eqQ$Y+ zkMmD%z6axRu4@nV>Rnl5W>)sR_|59nsaS#6>^kk@28R`1wQ(gYN7UYlG|l^uQ%MGm zW!on*IX>xw_IQ#m;hn>w{vwjCejZ1!Y=%~BhmJrk!u?)Fcf^pspd1cQ>s7$dLPO&T zIdTksayVIj7BvFK`Rt0?3-cQeU6+R1I%JQ+qNlrYz|?>PR!q#BdffBr5pOd7^?GLB zVR0BF@q;h>&^oipi>}SNPZ`AJNII6J`%hevS$_D1rOVHWPlD!WWsR}7U#hIJc3Rbu z<#j?vsSCF!jU;sFtUb?4VyQ~Zj~Q2DD|l!bAGa6Jm&56A;~TJQkWEeb;kp8<+6d&8 zr#~(KHlz&6veZb%9CJCSGIXO(4g-xwpv?d@tbWtew+y1KX7KNxI&d0y^+OL+%7H{L z7}Rh;Vaf4`d9S1%MU6e01_Rg5ea*TjY(J=7zSH`tuJ3**%WwSx9sl_kf5w)+?ydjK z?`wQpWcK>62`eNyW?#Wyx#X#yfbsTJU1pzNq+6Vwr~IoDJJEzKPt5i>YV#+n|Li*3 zRsi^EcH5~~$rf)yv@vn0jr#Gl8$~2yWE)tUU|=!_z0P+XZ+X>(ric5s*q zL24ZP(oy_#QlTg6V4^nHO~rFZ#{$*qseXcBn*SzW&KgV!;x@LW9Pkn431rgb$-uB< z^az!>%R6%#6mdeX-h}}LD}}wMMq3Ovtrf-gO|<{4Vblo}Zy! zccH!o?Xm+35LX#OpMboX449=9axRSpfb)KDlc~WFvTbw5O#KskfW)$$c6tISGlLDt zJww+Q1*yP8wDB7!5{q1RfYp@xV6?PAvJs&tR)c7MrwN|H- zvLBol+-wrJDP{h#h_ly%oIwQYcy`fI6$mnmriQ!49c)>)-7U2)Yvmzt7`RZKYxaZ( zbTE=OS0;Lo>^?;WEiApj&y~TFJbx*ctzuP@J>z-GP9qZkFyt>1FC_Jb82@03)yUL+2KvMU8|Kg)(n#O<793r*2fFv0Ht%ko~T&q_3g(-H(3xV>w7n1uQJ;}qs~=VU@AFW>z>A4Ca&F8f)C@8Ece{`Az9Sgm?D*Q+Unij zAPXz$i3+;MUED&K8?05m7yY0@$~{ZtvAh*c z0N);%tiz4rmF7&k$H$dH5M;PIR*>v`)_%jG9l*Lz)!ZqI7A>0f_V6pQL4~!+iHV6+ zW@e4l&sR4CE!L!Ln;)dDrIp^Dm{j@tSy_yLdhFVSSJPg~i_BhYWq!cos`5vx2sM=V z#Hme#Pn z;mA2s8=SlF`g+x%@Y*yn&czYN0S_US8oL{uz`xt*=MR-j`+glAMhm49{Ge3mED^^^ zESy??hlT1{LtL{!qQ(vmNgYE2%J7ghx7ob1`#RJ^^`#G#u7Bc5M@{UeJW1-)d+0D@ znmmcaTOtO2%v(tdiZ9BGVU zL#x9!t5hC~~65nGiogHkDp7u5|QuV_8sj^mge(j4uqq!f@0vmKG8h`!{ko z&-B!!La@DvFL+dv{+RJGIzTPhX!CMvaj)m5q3Sas^{E6$&MwbJ`{JDENOj<^;1r{J zWGH%m-*=(dE|^()Y1_*3`k37F0r^5D{9GwE?BuW1x?qm-cxjL*M?i|WU<7uj{e0Gr z48;NrJk&5Yo?iiJNam={)zblL+8c_C%3Hb1l#mV#@A(ZV9=2Wq30+7hH(;craC)9N z17G;%u(YaR4NM18z>kBCmcAW-a=$Q%Qd6m0~u5GfL3tk7 zuxAjPyECoEQC5->t`z@|%`J8i7Pi7;48?DMc|`L|6(W8RcVqpy99jLkaT}^1D$NYu zh1`H+Hp2~cAfBeUqBkarnS0}kzR=h?3?|Ra8%vst11Wk0gSc*zsTT?#Y-%Jmefie! zXDU|sBN@Xdi8TKY4a5s*A778)$0T_s zUAXOVM1LMH=fJ;S(cmP^&vc?JfslW#IN+sv6sE%xZaVI12zXs=bnmYpZi{r`NJEm3L5QZK#vIr3;>wnfP1gCin<^FD=AY+E+{-GH82CtzQ zUa|_4BgMC1i;lXrlDBlosx(vWEKsTRyj#GIaw6h1-n%S&N%hD9p@9Aqyr)=$@=7tP zJ95yGkr^l2Fg%`L_7ATXT1_DrmOgb9iROb9{|m}f?}a7>Zbej{D4xlzX}aL~bs;4| z#vu1#5D&g7P1C`@?tt7wu%Qv97A$~XiCKAwa+aC#MeX2q47Sj|#{NHS!GM=_h+_&J z4$Hl`0>9x}o+h<}NsDQ|odLk0Kj*9g&>oqGJNJPjhPIYT-l{2vDC#?oRnr)I5FVgj zXFSg-0Bc?vRP3rxJlyt>vNuDz$+A+csXO(a~p!HWR!+oj`)k0?MiSl znJzSetf!Dv94=e+kBuljEd_4sfjqbOT>EDzC;Ep_J8-@|9Zs8~Fxm=l(*t>!I0*+< zDgp?y{-Nq4+lui?uj7*{tpnfc1z^Cd|7g*<1v_kr+y!=7R*mibx&@Icez^i+8%oeS zv()MENTT>ZT#Xg1E>t`BBW9(61X3bZIKS$1kTA3Ya5tb~zrF_P)VD-Onh9>6;gmKv zmZ21b=b_mwDxA_!H_v9!&9i*sYarjqPKb*G4j;r3!5r2D^9z5Y64%lbvh!avnk^Vm z1-Q1s95B(pxb`WizMyG2$xJy72Iz?MlYG;Te&@#0`sF|1t2ycI_LXAU&YM)8Vk;FPyV_lMbk_2F&%{NdHg4dS^_ zb1x;FCEz2nRqv_H*~7<;{U&ZJTkzsE_foKG3t+|dp>O{~GdLl`YZIV* zndcNF75*71q7_`i+4patG`IjsPurdscWJFgZpl{Q;Tnw0ItSmORpa8V$F+rY!t^S2 z*^gr>z9%5akO6X=Qe&`;jfNSlEOI}ernnVlXa&7Vs z;DQ0;hckm8Ac>D33D6%w*CG6SN3yB5qKzO?XStbRPqwAdrhc3>Pi{%b+?0TO*{U&0 z2i#!iVP*f~-O=lYdbKN5NTPg0Cd9F<_8Usn@6_j`eZjb+=|H$^cz#+oY68}v2F{X; z61fI_GplM|&U4zvCDR?6{<<_CWVRwb)y*%>cq2*H7cga6u<+#^;rudal%Ms+4O+Hl zTqVp857RIPw@_hRLtS&4GeXV4Dhzsv@OOV^2LyDt896T=XZZt&^)|1utj>>{j4t_g z923-dk{wmjnIwX=pB-Io80((c^L|YZwp3Cy`#Z8=A)FbirX`9WVuhcEJH} z^Y+`ccgFScQlh`(SJY_+hzt<9I6RbZq5459?*3sU@lH^*7~IZoFl7^cbR#Fdg8S9go~o zT(xhw9UlEGG!?a$LG^oXYWyb$-fKmt2NW^5ksBL#Xo2j(eadCJ;3TqCBUMV(c(^YA zP*_5(-u+s9&MD6zZr2cMVrr^9x1AZ0*5)}bsyr*UMn4J3ky7X!d_ln5&lDWx?!gP-&0QIW$ zKdw$0rB5p1n;~6jH*12qo|Y}s+x}FLNTbnPjZ!+An+xgr z!SS-h>N1N^nhGgo zabC`yqWB?qYG=I+?|+D41}OdYr+sv?6(LEe_WPR|q@q@&?!HTw+RKL%IGXHX)O>N? zvmHtbEa%$rFYZTq`;+xi6jCV-vl*v9{23IkP%@a)0M%r0_F|V;E~9`AxAJAzrOnFs z5AuPWTtT}>f9GkpbVskuqKpz=b6dj5Bnt~A&fNVKSszGR9t@vbL`(kT<(+@<> zj?Go7#7DjfT?HjU1mxEyq5A<1X{oqKM8!km4FfjA;+1qt*lqxDqvg5b36z3F~<=;pF+5xKGs}xpAl&}O%Al+ zArsj!oMiReN_m!xF&Fj>D)+}ZZC%LqX-O=O`#%L^G!D0en^YhWtm|iM# z1hGQRCz%Vnbs2@qX7d=1GUS(zIbN+^UWThO4d20j(Z5QLw?{n^+vsC*Qy3t=zT(+` zTA<*$tk(~qyXD0_Y<_lp4m#bEnQ!dI)Wd(vFYoo|mEDRNn1 zX2a}K34U%dTC^p2ZW*P@=5-3<1q+YS2mv8d-j@e~!78j0PIF@8hV~eT1;ZpBcvQN((VQ( z9g68~CWOwg@3VB>RG(M?8t9E|3|2LM`^(+anGp8x8-lIfNcsbLAw%6w>U=5d4e_Z}kpd(pbRVL|5zz!?o^7 z45~l)9S$yHhx&0oLb2+%XsQ+6^GdkG24&VrxgDY%YVcur=S>hxwJzB8gf>8PiG>PwC37VXX#kRT-mtc``NpMSf)63dW^s zwFp+>ToXVGAC3N-;6eKkbF#@>L>`T!CbKYy+!`b?D;~2XCTH?L0aR?>=$55& z)w4a*a$lC(+AZoN7tLQT;M_uDck75d1#oM-KftYYu1n~j=iUch+t6)6soF=-4?2g* zE@`Nt4~gSKSAyn zqb~RAH7eT7oh?H+$YcGjq0?73hM$I3&-hr*wjvv|qdgv151Vynmr+OIxzQh$$-_r` zMjY6^P#pSfn17Kr6^xIiAw@aY!ZRa?3)`^36=1M1$Ml`61r#ou`HxcuCDr?a1IJ)z zvGZX#Z4rzIk!4`UJzH=>r9U}+g}07iZB~ugM975EVC)qB=?t{0D}rhJmd--b)vKCq zKO`j>mu+z}F?6%Zxcp~Yr_*O-9L8L$#};mfXTzcR)E_;M=$g~uEXV>Hr>JZ<dcY%~^BPZHkl+^j*C<3Mk|El4(z~9}-f5 z2c%3=+6S8GK9166+)S`A_>Fcw2gYv@Id%XEd4)Bbo*09t%8dus6wXTa%ZIVxRiG!0 z`9oNWQJ5)m?gDBJ9Yct2*mGUzkx*g_yyt_+o_?Usa@Cf@{kf}#vA(>23S2*ASfcna zd!OsaG|L&J<76XQM>bz2Z1V%*M|JuN8AH!v3HVc6C@2)*OZ?@8Y(t=b7+2u4XGqN| zl^bT;9lXcEDJYy#)xSStqF2vyoj-t(a*+@wktouZIaS$wKtyrJ=j%(L9PhV`ke?(; z$`;X|3vG9B24s7V^0Mnig6_Ec_y0qtNIbQhK`C=x0bq2lR$0Fv3-ZUQtRBP(M^pbj z#I`RP4k^>w1&XBgsS(v;2I0WvEqe@dUIb2~b|cu);l}_?2H|YVrC`6$s>S5Op?!m@NGdiUw z+x|_g_$CWSPr3hec~bCdK2|5XL;e?uZJM&P=k$h&gd>O%$Awb5d?XkCY_QX;5;|Ff z76jJUCC?5%qL#d9)fb*I$MFaLN5#qcgiOYFu_dsGt3~s#dak|&{DMw)%=-r_{XBR) z=t`lro~a--jpxpXYPz3KK?38&t%`DHq$-zUzXpS2-d>OzZW856(Np^FEaja|qBMq| zN5N@j{5YHU@)D4NnF!s#e20g$qDpGGU=wq({#j$*C;(yYn3jkl_2O3edq=`~hA-N+ zoH?8_ahI9}RQ+<$IIfzRJ*4Q#WyGE~?y+nPzk`m37TR-WBkuPy4nexK@$kFY!o;=# zncCY(S0+Sqw+L^SoC{Q3=n6s>p(*~gqB`h;3lxsL;I_<0Vr^$pK*kHn&?g`tM^lU1 z3`sNvxop;4f2BM@2{Ul2xgVTrt>I+QZ424*3Zb0dM(pPl%r8a^uw~yGr02*YR$|K0 z&uj9j7V--l=;()WY3*a}_Awb2M-yLqnA?jIgxGMMR|3*eeL3Fdl{)84UTJi$ntnup zP-WB5!nD~@W-<>i$&2&M1;wjipaj$C!}K9=9I+GktUqH}e!fm!qR;#YsbgiIQKr~l z))TEFqi({8FoL zZnlM%(Ga7~g+=%+jfQk@NRnt*&gAmr@x{)u$@$1`FxKy1q%*4ApUF1gVA zPSDH6^=1Jzor^K=pFI3c*{=npO1!J(PukIrKVDPfAN*aQUCMZF@x{R_q%;BuP(A9YuB!1ymN7jgBqF-d?yQ?W&$> zr&0+$r^dE7kF(v(ji0hzWQ8415lZ&AdnTJlr#u1dnHzE(hM1FYUxa zRF80UVJHLQCDc`pY3J`+x-%Yh^k|EN0Kp2vD8^JZsem6vZkWW%5|WM1J*vSfdMxy) z(xh!ynCRW?wNWaimVBh^6uW%d*pVrq#Z+QZFY%mC&_dY6_$J|w9>~nWCyV`}OMQXV zs1W!kxFs*zJqp^bKLBS+_Z*kWb_z{`Yb3n74LgMRNtYPz8Vz`cj)(CBU1q&w)0vS1 zt#HX6AwCF4YQAQz)k_0z5$kWPY92e1w92x%`;n4too9E!=UQMZD*XqxMRw_U0RF(w z3juKO)7nE@>YN8NUyg_Xa0r4Wk^y~iGbfBrNvF@PIm1Z(&~c48U@QgrZB~H?(1RFQx>RmY9mQOlDHCs0tPl&@W|FC=|$07{NE{y~_l# z+Lb!dk>`2SEq;(|E;6YN24dWdB&4-4r$6HR{fq~9hJM}xN`Si`a%B1`zjxj#sM|W% z5`Gj%$zRnpo%8`ZDUf{OE)54r`pl92&ew(duJsP~!qv0&z9r{z+9&?m;AV;kD$Lxv ztuvraV6pNMXavJq%>DPnGJbumr~3&>nJgOsyPo0P+i@1(U;FA{+SPx*s#y~B6IX7- zBP~w)9yL_=X`d0)#lbMa7oLs}+nMQU0A0uW`)ibcPdc!2GMpg{4WgBZW%XB5yTp&z z1B&@f+7%WI!;)n#@1fDbOT`b3=7_PnqM)$9VhX}(7|x6|)kg}~F61s1KjK$&mKRzH z8U~FHS=Bjg{PWw?hM#cuu#e#bdaN|FjR~N8w4D*P*gHr%?V11)rLnEY6a@Oy8T7?8 zFHV<@1qG>RF(H~*Qs*`Tq>LR+K61=Z7oe)jPUJq@4|ImC2FbM?evq{gwlRT|EBs4U zMTs;8ZDm@T%0%8#LoR|9_V04~x8D&Wg_H1R$Y^)VD61zEU8(G6;GF;w+!4}HUjOMi z0-uZFAlRUDc0kk?+yTu*xmbaKu;*bC+=epxGa&*9&*q+Ci$%SuP)>gu%58m(glH$P6zJ`ztghT{zl@8?k=iXz{|Ct-jbRJ>&UsP5uXq zh;$`bC3viQZXuq0`e@k;*HVJkOvaEa$5v5l;wZ-8lV=KtvY5y(Q+t;35K;4AS9R+; zT>XEw>s0LJB}pI~M~|D%!%$XkB45j46KFgP6~HfMJnNs0r`Vj?1~qYdMazIjZc*qe zV-orH2b2}l4GZ#Tv}MhiOLUGLPQEtCy@=8a9RpUyM+BZSKn-{4PS4}@NO_&u1Htg& zr&0oB)XH z;fW~XP!7)mb;+5azxUoWE`qf}k&3C+X%8ciZlj!zE29aXO-8ngCbObOAZx6%EH%Ai z9_ZTHqo~Hg-mP5|*wIwFjf=ipTbes>l!AsKj0&R@6XGB$7(i4oVWI++dxqhu6Kl4n zL4KA7*C_S#yn+n3b8m-^E(Vq9v!#g>-8YlZ6M8Ia4JW_#bs?5Cv!|uce!a`o07MGI^;@D2t1na7mW8;Fr9O{S7bGpH13=gKiCC2Hq zc!-(-nyh}6ci*9_%JYEm0$3yoaE00|B$ms|8DhD&4qRA&a%JR-a#e9T?6UBz-Hru+|`FHLwC0p!_H&($kW+ zNVRs|L>OQ{{CrcHR0uYeg?Z#T-rh=J|Xc=dFII+dxa{^OM)4YgRYMbOBcL;7ld6}T#@&1>0yXU|DQ z949@K=9L9+z3(oktK%^J=d+01(D2hNWa$f@^Ged@&Z%nmpn~N*pLI(Q9^^SL5+^ee z7ikA18~`n&@0DALlDr+8=JiqEg>2$EI($$#v_IH++QlCB2{SRjYfQ_yW{5hr@;m78 zVV2QTb$=KbxPehDe_i8HE;v+r)SPrGj0e||p-Ioc>2UN|l({hmn=Vh9r1pwT2ZzpG z1G|;D5mSzPZSN=u3K0+#0IZ-N%p7Y=?{vV1M&_3!y^+0ed+}B{1dSmY!w+_g#od-z zpSH{oVEy`4Vbj_oVNj{kYqe_SM)VE^rm1-AiCEY?pjP?~Dno$DB3vo^&}f%ahMs2{+o^s80M!$;z>U}cnxZ%r!X4S9x$7ju9^ z_10npu2n|&&0uM_b3*3Rl^PUkW9S}q%fbg*Q-fD@R^7z#G(NjIk*JkJ7%|(*GdT z^@(&etX+Vc6)8#s{&Zq9*OeK(?QkL+^j}p=k1qf{AAKGyu!G^awSWI>D>_-)o;J+U zuzFWU$SSJ|Y@qX2la-gLq1ynweDfkOlOqcgO+x&}vfioL3T5RK@7_;A5z-Rrj{t)U z`6>dhwE+)Lz6wOb&DOl+hb((`%8{QQl}Pi`$Gf%xNt4~4njS9-l2beuW12p^5(qm5 z!@KJP`$zzc|8lh^6xSW0hv1QTwalRR!+SG-0r|#PaiNIL5R2KsBCgR?oR6%7-fAcu zV5odnTK#!X0_i;(uGa5E)SJo9n<4Q6a3J_FTX583t(ID;yrAUs0tj6m&sZ4;$){8L z=q(UMsU4e^2kK=!6nvB|{{+qio%e*uUv2?VNJ+BPiLO?_(1O_dq61s$V8kO&DDX$C z4oq5q4~p~WPSWO7?qleSybQ_To51uxb)Q1uK;bP<5Ql>af&*#3lcB%IepO$g$088% z_n1e7tX(!l!Hg3i#4h6QDFWRL_c~mMEvuE)x`05Dhy5_J%6!A1cPN)8Jk~2>akh)^ za4Z-)Tb#*VgybF#@8phDWDIX|1J9Tu1dG({jR|}aCH}~I z)ThkoQ&|zXs)wq^%}C}UWAI8tP7=SvR)rgC4qMNudylOKYelA^8Lx)qBw;fs$ZyL> zC@BDKy(9JMLK{#f51V!YdVL>N+UpC5>e`_Sa4^8PF}3JNT3LJHN`qrJ*13W^CQOy#DAu>|O$^7C2k{3(Ql zVCx-c475(8#<*Y?v-papy?)P`VM>hn)!;TV*^BvJgHi^`s3uJ>mee;mH`B9x8-r3CfY}go zigp#}S|M$(eJAH^WvBvCK5ibPpCPA)vEgNfM8#>d53;wu$B_qxLc{SU!|wvU3vzJC zr33rSIJ@yGoJYb$?g1M~qK{D9ifinXHv{&RJT`<=aJzo7?eLl}q-}BsrVLld0H&g- zGQAMH0L&IbE~%Ukk4NVVpD|*t@`s3Nu+32Xurl9fzm843B&3i{*x#d6YL!2Bhxt~X zOFIBmP`lB*X^tQ0vq2Hg01z+%;8GeaDlQHjgSmLu{w;j?4{E+KFWMCG;`ErEC?m*z zfZdajLA??-TO=U6zEm=_v&v&n>^#;{OOd^hG`Po`4< z!ia|p5rdhm(;xGp^Nyrz-8c6B3%!65qa$jM_6I+Kj6w^5b};~Zj#5=27Ea#&x1vEF zSCVK=P&-F&cG2{f%izYPpX7smVV{6Ug`so$B)E_lANDms09sC_TS2KJz6RR_4wX8#P0zz7tPrcQZ32=e+**`_h>kmWLt&l+b-6*#17t<^k< z|N40k>-cs(oWP3|Vc0`yoo2oI1jNT9)m;I+t5+qQ{Y44)Z;zW5i}*W=e>sH#-f2rdW3Q6T znNJvWI%p*&Jzfes@GfZ)xyfkQ(XX+`U=n5HZ)(#Fq>?)l@o{s9dknaW2($;U_Un? zNb>Mdn>?T%W58t%gF+j? zGg2sSJ?R=VT>9_izBhvA!%C0EhD8x@`4~>1%`XCm65$BV&^S0Nc>9O_x#ETU4y{=I zaR6j3nPBGfY|gi+NOH*+;fo;E1niGnq-xT>**-|1u|cgw9b}6k2&?p`feSytOKdU1MozDb^ zYcKN-jcV#T3iEa#DdGKOyQ)ZMWy0u*6G}&emAL;*!;lrKq)H9AHH8e;CCDR17>#gEbIv~wTk?ouA^yCTC zaxl2te~`n+5a=SpK#GFZkN*XABIPL4a@NpPGY>`Tqr|> zm;b@RHSi68Nc3RJxjmZ5d+2S<><%BO7hUqJ()Zzz_IyJ4AQ?c6A=(0F_UnzyTzUw_ zN!x2*!=;&gThr>Ru~{!MO9AT@T5A)mw7pi{lJZVp4>;ClVK{!clwtBP54YB4jX=xx zO>Yn8U*IL`tlFP@o)+7N{Df@i^7~pbjGr6rX#y6^c~q6`CAf;IKk`F4IZD9=4f>Ia z)1SU`Vth2>^y*Cz*ykTZM5`pbTTc}QwI_5a@NNsQio#t`^k(DOm@`9+fU@-j+t@fQ zf}R^g%Lfc-%3~|IRoUJr%AwY-%3M2c%{=ZE|;OE(K%A6zMA`xa9MX=kVSu6p0 zR*~9?#}D>Ge<%1!KdO3d@I-S;ZgR5S)uMz~SWb^{f(&d#CIVCOVA1JMAX|%dkaYHc2IU=1S3RxT)OUkQ2~0w zV8%MQ&EC~GHMyN}msIR|I6c8@o-@bryw8p(8|ySxhv9dQT+oaucufNCtpWPoBPAbB;V=1tREp*}rBareFh>j@E( z&v|&=O*9(BH4^}7ac#7!S_%GCvIr*jAx8#J1^rv}Q-xvon5(MxjITyVO^bE||&Av?i> zs5dh6vNRRvJ^lT%ZlqPnflhdXle|3%At4s#&LiI*-B#=&^6}!g*G`5q0L;)H8~Y!C zXKxwG)mF5F!mB-Qm8q2pXrpP!@*+#XBwkZ;xb-FsPsjYdjO?Gt$wb3zY7y(nk zi4=CP%OOd8_y+>%u#CDe04u}XGD+%O8wU`uvA>|D4OlagZ$gv-;FMFYK6%=?X2F-~ zX6qqhD*l3}lVjt_O3X3kkKT;*YbYEGYo}t~oX+v@ z*WqCwzMx2}1J&ds8GhJTvKWMLo1&P;*upVPzD<#&<$zrOD3c5wlQNAOIEwDkHwLC= zjVysiuhp2`{93mjgdzSrkGX+s$yuMh!qs0?oyNVG^X3YDuJda{5+ysv#*I9FEdVZJ z6@?INgcglGN`1Shc8pa)^}D{xNIf`eV_{E;A7>!HxSkSeJ8s*gcAoCSCUU#k16O$I z!@0QIy{E8igZ`z4be9_O^My>!B&Y8t95aMQ;yb_^#bytH7t~S(Qv*_q&KmbZ*4P-I zx_!)8xTwAz9AW(tjcF|#x2B={3qUat*^T46lPO#O!aw&x|2AvhLH9wP$2Z`xAs|F{ zCnkSCBWcfw9C(^E_;}?g-FsXiYz{TO3z|$G3X2dfT@E(FgijcaxCA(<+>KlC8f94Tdu%(r z++D!_d6k0IbKf4l&2|J(08QSD2gL$@QEFsu$ZAl~%sFLaLpRuOk(=f*e-eTIcQ`V% zGlfDvO~xyscXFe!;(TmofOOo779qJqiZEi1vV2(HfgpVk)Fz&Sr=^$c7ThPGXzH}} z?9*!iJ;e`4hm%F?oMDbZ`>3g?h(k!n;v+iYQ!^%o!#+NTtPcr0M`g3l{y}Isb~BPY z>}qmt+xpHgh%1i=+!X2$jBP)3!6yMe!@cK?eP#1^uP(>h3z0Qi1|4P6dorz7b_~J}SRk!dkK$p2>eXE*9%YZw8r6umkHYcH ze}?M#vIpk}ssUIjk6(qtYLC4RfIUd;9Yy@$o>nY9Ne*l_ze64{6xRon^jF%MJU(}M zXawOR!Art{e>|>VaAE5sp|!nT38>G3T_|Q0;8xqE;f)GZl|y!>q#5sbo+U-duon2o z&revrXzc|#)Gb4r;W_|gR0I8wLs$jJMmNT8`~cbx|9RHhkoH|yPmPAu&p;4D0zGL0 zSFI5;DhjGkWBt5cnO2eDH#*BtDs7#y_0d~l!o?OQB90yGP;#D8{<}pN3l|A(-*h?2MEvZRsgoU#R;=y5Bb6_BPY^h>)FlfQfuG1=ER+IRZm{@Ic^jV=C(c< z3HZ}4It5%k6H~yOoh~VGH{{XD9;)Rkqk~|y2}F2I0XSpTZG`|8wR`2mwg?_kn`Rfw zP;F6I6cJv?s=al`&VfYKVgZU;19fQ)E9k)J&+`yaZGBBE@04Wnp2;FcO6d~v!=Fu} zd##~mVEneZ=9dy+=7_}t97MJ07~8cAt)pAE1@-+>f#E;jF#(J*kvp&k+6&IPL4gelgGuJu93=(p{Hi;*Sj zvTdo(l85vf)Q-=L7kfPD=kMT>v`Uw zH(!%KZqEBjs)SKwlQ!$KdZnl>o|N!<#a1X=80B}eywlZ_@PO;7s{+!d zc)_xHI!Y!m#TRFpYcgPb^0IgTJZMI<%Q;WGL<#L=YPi)c-2@l__>uaAS!SKeW{Yeq zM1w6Fyff`rL4Yp3xfAF)n8=G6cH>0AUHV_--gRk^)dE1J=ZL-ar-DKdbHaxp<4uOi z^%o{XvA?#%dPSI56MTT-8a}{B4`=SL+6F=Mo4+3PzE2ms2_YnnICWZMGNrn!TDag1kF#@s;Bvt!z#tB{a zTLPL&P+$EOcysr#g=6F1;fWnL4I1U10J;D0JItySgv!mt+jM>B;y!ejC5l_|{@tv1 zyVjJ8Z9Watn}S$lTElBIP-rmS$Yy{7ARm&AtP0y%ae|?+BFse9H68sOsQQ(-9orSz zfs!VVGi-MYfkAPwn$=?-8GT0;#mzjn3(Ptk4l9oJ;M%cL3a+hp%``el#KO#0Y`e~0 zX}ULC15z_*Od{v>hEO3ETda(wQMP=cr5t+Aohv~#1Q`H2sIoghObYRwO$!T1f1l!> zP7Hu@r357*T62so2*2upF@MmRLdT?qFO6DVDBg}L2_ zJ50QbkCQr6ibMM;AynuKmrMd~=9(&Sj#x0if)KMN?7YopkiUF6X|^6}f^;WQqNc_q zg`}Ffk0>cerZ!|}F|y~=&ShnMs~rUWB|UzVJDMH8Kkx6wQuqz%tFHg5J}tq4ZXx2gpk9eMbfqIwv%k79&h(7xnS~bp2_+2i1Uj-SMC#yE1at`XRN`#OB*g zVTt-}Hi;L)FPur4))%NT{r6Bo+>Z>lB!8Zl)`>iXYV;yqB1HEo;?JFC-xxA__cGmV& z9{n(dHxiCtt66A|;G7=S>*c!kE~ogjdyXvV1`WKy=Gtq`;-t(69w%~$^cSm+RhF?! zOqi!B8IzQG?n|GnZozb-wdBynDTkiF79PK6C-ovKm+{YIw+pTYUA zO!>7|=F`zgLyhIxdGifVwTlhh9=!MFT}4%S$pH#1*B8fwe|!2%_h@mvq3Mpp9eVp` zJ^T4ickNJ@k(>S<;TDnh(A~1642O-}pRi*{v1k9+JnMsM|)8@S~o6Vc+a8vpF zI?5Sjf+hHaOCFuyae34DIXgmil6PAy%*Yxnh`jkMQHYE#dS0;Y*0dcPjUHvmntk5a zGzZ?=x-8bDr-YbQ7&O;YpqS}SX!*`ra_wy1rJ-9WGe5I0fLWHYsPG@uq(WJcIe zAT;wy#Dl!GXm78~_$l7CYl&?PyIh&cutIr`4SPcGZam>%75m}pZVLsKEQ>kXJ!82F z-{71Z@7;PWZ;9Qgw^L5&_rh9I-MKNsK|gS(#}fgt0Q&UZ1uJpcwrO1an26tpmNng5 zw8P?r|6Q~(cr0yvteI#?J zx#s&xHtX=j{)sU|zT3CXAJASvqJFc>*Y$yV?k}69Py{n*w>8<7s{O~{H6?j z#T(OX__4K#zvNSSbL$N{8nqy!@=5HvR=0PnN&4!&#`6mD z`ajHR-(5>3=Sq;7XThaN-Gk?|G1GitS9#~;lq-(#o#zGBh3D+5q&JN(eX!SCfvl6q zrFYs`0f)L8Yx{0(GM z{HMF%@y`ADw58w5dUu?M`|5*3{S@I|U&TBh-`F`DN(a=>?g>0H|NWr1S-a$uFso0S z-hF;}w`l;3@;+W)VX5o#JK=FrXwU99P2d^7cQq6=tk)`XDE~VRL zy#hSnjy&yK7b$$a`r*fmz@ydopzZ98itrycHB`l)-noktH-LlOHI_^|39G&M!_E_n zYBGLzx2)c8P1Sm6*LbTs4y8TmH-{&IE36pQD^v3E=#gbw;nBcfQtR?gTlq)h$Z|Mlb4Im$=+ zoj-KdzWa9m&crLycG+eD@XS}xLE@4=fR(#4@HygJNa~#@g9-0pqay1KTFU-3Pv-89 zUz2q3w%XeHO{1=MOpZTK$e*rN%a?8lJawYyg~Hl+Yl~wWo@neomdaBpqBLa^tfA!( zJYyxYTPK%)Xr{pOs=}fd)m|_rPF;9l2M@OY+W%(EEZLN+^9M$qCyj-ejrZRIPxt0S z8*GMeXZ%U(?l~jjei-7b#ZRck9eoiW<1&HT8>YN7bSFjWG0rIjfI59wc=x^b~7I z@3=X~T(qIq;*0E`UeCU+P_fcTe@$(7@hh^<=j!Y>>{}VSX8P3ga46wyXf+1CbRQk~@S?Y^#$rx(kN%DI8WS(g;wAc*VD$r2HhujWxtOw;laXK% zRM9xYShV{{mPxGiD8unQ+#4!P^mpo-J=^n2_~}1YUfth9MZTEc(h(c=)c~F*-&UAAR$S{^ z*S*G}(S)ZQQmfmglFi;XAY7-0sc$Je0ON4MFWJGa+2xoxooB+rH}j6J>lT1-{+ucF z5PZtTPor~r%z2_*o+4;(IyqY9WlJI&p;Efe2E)mP(%(u6;tLrQ( z(oHCijF`>j97=g+WPc4agG))a47Q;p+G0@*IP#9AjbHut-Q|A1xWnQ6yMsF2WiBPv z&g7$mS1kc>XgN=6+dd8GD_D3-2Gb7QB+fLN-?)N%b5{s>RZ7-g!tl3O1O=}_6z`+2 zhC(#ShYW&WDGh_mtk~g-qcktgY5}Ir8Z`M`gKXBkv^JD~h`>KH{T^5h| z;2Fc6Viu~j!A%Zy+I6LGkud(Ah)Py5}zf)~MyT3o!vX!%7NGCP>hM{`$ zSFHU;va+!?YioW*M^d-^(6d|MJTw|*t8m3H(FX2ym*?-FC=qxtr4cFba>-MO8^T&( zi@RP=`^@~hL@i2MrQtDOJ6G^qCqdA!zE97>iCUf5LKkUBWT^geMY((dOc zriOMUZAxb`0=I6930pb~d-*c&{iRd3Ht&m%TkCUMYFQigTHAgIFx9Qw4@jiRK&F7He$3D-d_*NqYd$DJn6Uo|R+fIs|#Me1Y3hqZOn zEUx6EVu~?h=Y3GZkXlOfJdWhaQnK(h^^Y`h)sa$Cj?6xUL|V%rTlyMIl$f2xb^Qfo zu`%6;MY4+^U*we^UszMv zzA3zvJkB`TcmtdXf^EaanB!xme~J1cRFAZF&j&s~7Hogfz%%Sx^XXwQ1dS6@5%41| z8rZ7`a&AeGnD+`Dc{C(@ffuI;8RT}DnXVrzfuB99yMIIgpdo|=+RQj(LxTZ;^bI=@ z{#*bkfZ&iw?*lOv_La9gnzF_m>_zi8wD=r%!cU2~HL0OnlA4s1u(L_RNX4dn#AV&k7TMTooUe zN5w`78+#3zMgdHtSIIUBlZ98|P_5opiccIG(p<2Jua3-rUp~xz%VEe*U=0l$Hlko# z@;*`c@aWI@`%Yu1h`^+o`XqK23fllswbfD0+{6O<8`@oqaYymx$jIERoo@e+lJfH4 zVwovJKwo}SPguWT(ur7O<}fj%p)8i3g$(elSP~~Ht=+Qgn98frJ-RJE@j^P&4%dE^ zq>~=LGPS?e*ejWUA?oti*yrXUGP%In9xiHsuLfk7a&Ma;~H^H!e=C$sglxDRp zwvteZpsdJuK^lRBJrOE^+%j4Yd{+BvjpB@;VXlBAxlBxnCh5Rp;uhVp?9-=$ z`6~zITx?5B1zC6j7X}X;APlHiL#b4cK^o*MAM4hw5=uGWOcNW5g_chZemc@Xg*}(l z#wQID)dydLf28JyXTxDG_-({7qEQ~+{t#Z*xu%rW~-sPGPA(% zG#$+zEJ#X%*5Q`Jy4KYAfSlY>2wc{KbtPs}svcn%4p7+1xZ5<)7P(yrY3EXgul5g4 z=jJ?)awE&^e2*a%PwP?zD3~)uG1#W)29)iUI3-L!PS}@!@NaJAn!ZTBMCxzItxMHj zsMdngj6G>7#El);&wfo3yB5Q*-Z3-Y-;p|$a=udqD&XRXAPL?1)at{HRwnu5p&Vpf zTZnsu5!jEJ+Bv8$Z2V+s1*&a5#$Wb@Day#`j!HOH&(Ghnn=q<{+Qi7|%um5IT$|z&jAgSh z{8_4b@LFA#m#W?1$JD+$pf5-(j}ag~Ka!KMuW_yIWvVHkJDg0k^Ivs4HwT+?#8)>l zLz$m0+4A!K=j?gYY-LxwD7cMWK|h+dFTPZ=!mUtF?q~iQi6%BKAKqFwFae1?DXaP- zKx_?oRSyZoTL95Odj>^qjY~6-!d>;8?g@*}8E&cO1{)8Aw4I}rU<&C80_^9!vh4TA zr0a`nu+ee|R-)4A;&!s7f8|rjJfh*G2Ze4y>sYG=zj*CuROIudI;sIIJJcIF|(M9)!pE(ji|NNOH2()s<9W z#NT`}(B8TCB1XPswz|!JX_wE^FYCJYzMf|rujro~uy>T8V+nVG`ZqIat-4@?nyQD3 zfQvDNm$oZ#Cn2mx|*sTR87nX z_VOG(-`G|2f`3GODx~z(c&%Mf&(Of`6<31a&u8Ai+Z+jarsR=jf?(&@LmOOUdY=z+ zK>8uI^f%Pg7mVzpCLnlcXF7c&Ofg5-nmOTAb(}AOidhoO16xkB;zZA&xLxq&jO#XH zRHKXNH9Lr-1J6AjfWt_OGd7*+mN!SGIYAaz@B!ti5&7UU!8_Ykc@+ksY5`Ci?4SF7 zJTx~Jo@fV?5;4#9kma84DJ$}G}BWPOy#3n&=I2_gOIQB<~Ds zip>zSsllHt`3!N*`Ik-sqsge=0XN``qLobt!KfgK#qthoQ7-xzrP;SYiv9e{h?Kt!w9G`tS4xAr_1^_ z)}{TdoXBYE`T9a|a!oeeX`8GA1UJempXXs6L1-RoFJ zKX6{RpB~G)IdesDV$MOlU1B?Bo=m!XT-9$X*`91&r#^+N$N-lObUnqs?}7$`L~7p2 zKte-QZ^)2E)E6(pML2dQ00yWSRPRChYZMJ(U38PyUgw|TXErlwdfo!P>#R$CA(8}OLVnmuB45r+>>p7A6#L#B5u;6;aK@fXd#xTHIr@Zv zY0$C=c8LsV6crtM6y{@I9!O4UzkMO^eXzEgT{P?kQn2-TxX~${a$5(=JHV(ffg|=y z*g$g#YqIq#H0*=?WU`5Vf@^Mw;zXGlz(%E}+w(QK#Am8SfU4*`ijzKq)>bJW^i5DZ zM?IYsnL_*|)hqaRw*II}rfcgwkuqp}J&KY))|tihD-25^a{J_Jm117>b)CHxInQ&YhVw^s7rZj^$U}3Hlm@B!I?9Z(OB1J1J{XP~-}oarX+s8wJEVgCer*c>6opLj9isG72C*@P zg?LJb)ET!>0D>0t)u)@*;3gY@@O|ajcjTfPVy^JmNkpEfZn-&ed}O)`5iRruPxmZh z-ta7|9h3t`Q!%pkDvnH}QSdL@?LRI$DGjJ)hDbnxBD{89lky3Bvfw8)pEohyq^ehf zt3WB*IKjhXE<4?c;5V=0s5|F7e@dmIxG*%HWrF6}!nzqIPL0ikeXv;LcW03{Q0%|uCc^712D+c(-wS)VfgunQ6Yq{VmWml>#U1h ztPJ$_Y3WkLq!!2~9SeSxeu^#YF)%d9B7jYe(U&AX@0*>NyPM$zM3qQfKhGC~>+Z5V zq=Wq=9TvgQ3}nc2V}O+@vr=4go2SOGNlP#OL6kx>7;ukY?4go=Y(HCa=lar}w6UyB zBHu`?pOekqWs}mH$Ag864<*qr(sF||l3l|IfNm3s>f zGLC%>on#M3cpJO)!0Xsroc{#~Xy1hoKhsSc)PR!0ygwW8{DWcpg}G8Lal`M;{90K? zmXhL%;H1~~az=J1%<5jn8Sh7@u}^ES5zBk{8;nqTXT5ixLmh%LJ~JP8!W5qTJ};&#{B&Cuk)R^cAsXg}#Xk!>(BQrD)vQ{2|chRc*l5orwod|G`| zy~xAXKa?tPcK0yMMPaVmtEn&ux?geW97bB zIOE;03!xff#>|%MKIyUC zKJeF6(g#w)Kg{GyQM%#mu?0(61WC8!Zg+vkR{H7It)u6gbxbo(aMC;)j*1~XaO$ah zNGY!tvd(`qX9q2=P6nLxuJHTR(!EPVcW5j>z-~gM-Rh7H`*Ft$~q%Pjmr;`s?fe?prl$hOUDWN5{nA_)$EbN@iN34NsD-DhGi3?3Q zW|JF-^J@mMWQZNC_U^J#{dJx4vlAviDFJ&1UszI#MCoxts{WZWpLRg@vhoPf&Y0AZ zSTLL}*d=~4P-45?VdM6bVscIGE5*H67UW%`q$L}a-4#*L7rZ>QHOJ_qyC=k|i%a$S zPmRl8v8=4vzMl$yle-Fc)!;F$^zE?55Dd*3GmetbAr7+sNaote8G8D3hwG%*rvjYf zhRq_lQ`uHKV41m&Ye(yS=zJ87%0AAIBM|PJ6)Jwbea5Cg!L&G^sTKVVFuVEn z{^072RgkzLn^f&2#(5fj1_IAJK8Y5x4MOO7AC#cxlbXRsU7>O~v)IgayODNzMo`2~ zvzc<+BzULzN%Nd46A{!yMq=>_#l03`Lw%cmBrCu&P4g2PnSLE+FNA(2J9UD@7X$Qj zfycMl5d^`k6ko#qLZ7*Uy|WWmX%Snhdw)pTT~?Kh@G5Or3)bHN2tKXwXzWtn<6mD0 zcuR(<+^E$gx(siTH=o&zJ;W(;FR}!D#cs4SmPg4^^4RCJfy-f6hF~qn=eshD&}l9n zrq!u8+6j{v1MiBr{TjOP;cKr&m`TcS2Hw zug@0al7A>R{M$U(GIVQ%{eRhAkd@8_q_A-<2jK47j?lCoNf=m^9Hq=jPn1! z&W7|p9n)fN3^}|zy%SMn`8uB)8S>23yrJlXN~bt@Z2;sIDjv7bsX;M9sZ^<$?>WW+CPBhlDFJmxfGa= ztznJb7~}M$7z2oUc#|EGYAFV%bH>8`LS#7EoV9sMToEjzo)-m8sNUlvzoXI=8esFh4+UKm$0=Y$V1s{C*DE06Rl1kXXvh>Gi##T@qln0^-XbOqq;sOhl z#S6m+XC0dyx(YqsJNOWI4qYw(dx=e2u*BlN(KVaeBjOxv zDhxYZ!0iL5OOh72c^pmJug*KX=SDx8d4p##N%!vv;>$Z$N|224qx1QSa}&4KdY4AK>>JD`+?Fg& z=iOxuZ=c}&AB%$^_!eRZT3i&jPm50`3h}JZ0sMNc;tWz)=QqGkBe?!^#(ZkzomCDO zb3 zmx8uY@F%R>?&tLR{UbbpQTNwstHSa5^5zTOqO2Rstyw_k&6(bE0JVD4ERM!P3*Q5B zpqpH5-bGBuq%SVv@7sm z%czC6kowVDeSRS#lt*4hpHqg~RRHw~yw~-H;{&A~6f_jSkwCb;^$4RL9Y~)mB5dRWZy=DHk#`^WR)rYKU6yI5eztQePD5iYEb(I6w zl(pHe>YvM8w+@!+LqPkZVH%~|KF90%7_yeEtg>CjDaE7)CR#c39*gvB6Tdgu*|;)NTvbevxp+ zO?>Ot4$gl;AD1unb~`#}P>dvoxqZyB?MYP7vK$vK;yo=$8aYttnI@g!Bf60;|FI5#zsBEa38*(3$B6Kaqwqz7Qq3y z`b8u3?*}7%o9;BR5tbHmSKKr|wvl)Ff}i(+vq23qF_llCS&xj6IEXrEzjD-bFv8fn zL4qtC9(XuiT`x2_i6?+wDo6l+B@=RG+Bw_nsAdO?Q;fiBb3XY>x%j$RM$(HQ!$dVT z_54h-DP2Ob%8_`=YGc9tGXvw17jx!$NO-XZBq3T%2z3xoPFGpHqj&o>i7^m%jz868m;MM?G@&`J5f+{so1w8FJU*#Q=p9 zOo%X6q8}x0D=t)d+978y*OohfH5G8a6EHYt9)(LTPYQUigScijKmQ#x+*r^cFrZCV z)Nj+G!Z)q4lyTPfi>h0HB*&V^Hd0zoTw1otnDB6PsOBy?Z4en_8avaS zRU0bF0Av0}NY^s_G8!?3yNdG!_GMY;k2TAa9ikyG6lE zjg`7vI^FhM0-9CgSP3a080!u!8M|9|6Ytj0|3UVpiYMcCzE*R z4VAcvL82Qo{>9DBuI|n!4d_fjw1q+d);rf*ZB0aI4f_SC^=AH2 zS&VOQ6nENHLXDT+z#AgI`|`G&bc_8LKBIu%A$KW@Db)!t2A8)pxd3wJvjF4sPXf~n#w+NPtnhfI~EpUu(%-EuLMfq%z4V8cMMb>MFpIXIqmr8e6e4szznfm>-r>L@~RSA)92a}io>A@xK#BK z$p)oqw6mV+mP{%+&1@f)6i6s)Uo(F6Ngy)Mhk#T}PLOJkPxWIz5LEF98@xzvKoD^M z83brhuZzCm&Qhb|@ME9u{1LOu47ak7MvHps{uUHMjGhNoD$1;Q!v=emiAi z>e?1st@hot$j*M%J{4cT2JJk?7-7-sZIpv7Jt-dA6+p0`kHz$;)iLT}&=;S!*FoUV z>G-?R_c+nNmM$|Q!!jVR!#G3%y_ll^@19pCY!<2UyNbuXkYqY``I@B9iL$K34h za9~6c?pKhBAZCp9H=HI!E2FM=^dP!LvkA~`w!g-b)0mIOf+C8gMX*>+)D;p-c@Xmi zoDB6~R=0&Lg_mU1Ya42K!`AaJm%~?psChtL4P7;DEz@?g%W;o6vBXksqr6#2T_?K8 z@2rpCV!|$G_SHWhuwbK-U_9*wECN4RK6z=7 zQ~&YtLYP*V(qWKkjdne!MRV^L>+TEdbTewH6rWl0B4Q<7@cqeqzNA9=n8k?qXL?s+chQc~1-bKXllKW^PIR;45!OS4?p7F2FbC{}>J$z!JQ zN%I#^v46ddJkNJm85vw$7sP|A?f?+8`i6iQ7(l$^_kB&wZ2J5aAD~wYT7fS?k`rve z!=pN~9#8@*Gpu$u<@iBhY3uL!WPcdxkr$Waap}^rIS-klBHB51x%C?M^isi*2S!2n`jqJmZiAZp)5jT~&^C@kq=|#a&6h zKnEeQ$rv923hYHn&uxkNl|40$XXh-#4mn;yO|i%G=*c0~Mn>Zjxw-wm!sQtAK65XzSu}?g8aK8lLK%~M#R>Qty-8!#fi&G#!Tlv@IYpThh^FL?P zdD<0}TQ=>5e(RqWEdzmq%3FNb9}DO-4fR|9OW0R@B4!8rJLnjZwT;T0*Y=372N(Aa zg-$bL`J?a`36}z)*EH;U48Jl*WM}7-Rz@r9VsB+8gO`n$ zezNVuodxsi$3?+>2bKzH(Uievv5Ni?Vn(O+6rzTgeV6Zi?8MLbZK>zm=3_@jWSsNS zBbMT?U>_j(RJg8{Q47sI_n>-)@mR=3NT4?Jq7PD1=nnkKgD~fkYBJ1z`}Wb$V?k$V zUxe&mzMT{hEBqzd)mt6RCGkL3T;-P&8OGQ8Wek582&UC(cNAyuk%nY)JLTOXf7tQf zg$#ngxy$x#HqbeWj<)|O13{r}S_2*^@Tgq@?}4tC+3HC%5D*~&1n=csi~a1Q<#%vc zIGt3Hd)>Fe2`-6w-3XR?;8RmIGiqx_%dLkLVOBo-MSlL^MBUazk^MlliQ9DCLE&)G zuN(rCd?tS1auQ2 zSP>L%ZLcy@$L$d;$`+0V;QoHzUV7-l`r@x3=Rg*IM1TOKb&w-Y3}tfAoRN5L`Jg0{ zX~zfBK<~5+ODWy=uPF33f}qFnYaQSeUCvkR9LmbNTW7BNeRioE9_}tF*)w-mIdIt% zi$7txPP!)#rk3{Q^*?#Z3I)!uLwzgZDD)-d8@S+*KvvcBpZ>_y-Y*r*{ObL}U|?{h z9~LRZlx}U*1m`bVVS5XD9FwzIe(zp2v@V=rA-3_`TXOgH`j6ODYf( zAmYZZDHJ$rgP;=?m1Y}tcIV8UNhNLy{woxs+8eN|pNY@Q0?DH+=NpDJGU7pdG{UuR zo%I;Hw#9(5E0!?(%-R8jAT#gHK{RC;U+G3mOSzVxqrU{{3JwX2O#O6xU%W*Y_TW4R zd(eX_g9<+}^ol{YWUM>bvIzvfw_G`L%^8@mv!CDin|6t*qOYd+P8y6}0m42|8yvu| zB%=ncA5Ra6rKCWNf?t{R3A9fQ{6?6KsE7KimN4E2hAdkS-iZ9*F5y>&U7+{M*#QHW zA!WVp0}1&e>(vFV4w5i@Q-SM-2jsiJBi>$#;>2C*KbG+T)#8?8JBE`3?yZdv*m-N< zry5KN%M?RFJG_Pv7j`=4%~ z4vKuALMkjm(+~$?*n-x@R%RfLe7Gs5ws4aL8;Mzb~R@!AR9R^ya%g?K->^( zxEMcJFhm9Op@)-H48wPC*$}9=vYeAERA3?JGT>1O$UQXQT~0&~5cn(3K+*-3LTOM| z^m6+EXXfc=DEK0`288m~PJE!@{r~@R3_aIEzx}~cV5w-{eg%X^=uyZd zb3z@w^6-FsV)fpmu1G+Naw`Ujs|G?fe)o*{)Te|gzkG-X>B9`QX8|@~i(T7dB66aK zSEo?WvRKOl?ztNBJQdpFRxg8uMMGN3Iyirz6{YV(CmtQa%g6}SYNPTh%s+vDK@tSt z zz*w4@o5p};P>Y3-3sA;`jyqT)M;YGZAca&st{90R8%hl#>7_V6nTNoOfZwnm3=D|x z3uNwx<$0xBBWn90CVIk2KaX3=+{c1Y=0=aJ;1iUlU-Q0ay(Z{Gq;BJ=BIFtBHva1_ zo_By!zS(bF3bBg?Pm_?U*h;}{H75F!YWA!dwO}#H+rNVPmmWReL|_dF=%o<4coEAD z5TO^$Ot*J7xe7}_hZnz3m;gdvsOt3jt$D-P_qM8EQ5@hm*38sX?)!_gy&sSax@ z@>!DS=-+_>L*e1yMh0qN2x*7vA9_sJ`Y$R|yJ0Bjc}GFt6>({i80zUzspNt~H&NP) z(Lmm7z{S4yw@&{o%wIH40UWE{qPGAz32Lu;dUhM6Y;f8bg{&UxpHFJH4Gcj2;K%h6 zUP`c$Q7`T{t@B7c)|jNv_2t|A#K{yUX=-?!NJ3_0K+6sz3PNy5F#BI4jByB1bm%P& zKb%7Oqh{0wxnpn*z!bb-n@o9v0zWk(6pSQ6K}mEEL+;5ay6>I6^a=!|5xXRPVi_AP ze%@kX3h$pHfR(Ng0tgKl*05BOdT~??OEqZJ=SyT->ho=a+q^Rz^D1{!P*4t=rQ0s3 zd44bWeouzrg#tWVjU##l049;VU9=?#OI&a;oxCx*?ZUX7hGg-rDKNZRNXq8Reh9ciqnGbywn_1tY02BNtqSIQZ-exK;yqP zIN{95?VbN6TP`L`D=2=D?k_&0eEH`4CAV{N`S8y#jQHf(4SlXW?H?56&6^!)CF>u2 za;01Pc&G%D8m@fyOBm>E1ODPihaCu4xw&sH4HDBXNgE%Le|t#(=8V|iE{XxZzT6vu zo*qtE9KsK#+U9Wh&A4o_G!D9d|GxbL%5-s0PfxsNMnq)fP)lyW<6;X@mA%$oSDqPC z6U$+xL=57dCJLWcB=lU+$vbM75@l4XOt$7}6cWalw{${r{d+d%r4L>jR!fYGyYt-R zkdzdc<@INdD#av{8T-7cjg5_|X-u{-L)Y;ibVywD+dc~qZU=OFpXbvp;geDO8+;*Jje^d>=P zcFXIJ8X6ki+jK&Rbuxwd38; ze%%L8kx)L%Equ59^w7iL>;o?)!xzjxpdtVNgNS7e!T1ee;FNF?#7}Fu3X-I>va&K^ zQ~o~uE|<$5j%KmV7Ojmc<|&z(qLPw2=39;?I%3Z%Hm^~Z*>LntaIlZa)SfpN(g%8a zjM*D=t@bSX7$MTx~S7&D@;fq={uk%4EDP5O0A0y;aQ&X*PJ-qc%2W!fh(+m1j>N)fB^^sl~ zDO|kDQd)lV>iVq<2;zSm<`%uB8O%1NW4T#s75mHo|N7DVv45m>nu9Z=3qYwfT>hv6 zlHXQWt^4t`0z8M)F2{?G&)od_SN+kCJI;izfy*J#>iKGBSa@Kvva$xs2THludzK}s zZn=B#(4mWur#OFHoS=R9@S(M_NMY_nBBhh7UA*YNs*>m#tEs`}`sRRf?hA5qm@1ch z&gRK&gC>r+A`T{V)gGA%?yI!Tj&>(yY?RY8z88~hL@Be92L0-xq1k%_&l)ol*Gw1? z@;|<)P;9O#PA-%)@f|*4!{wF~YgIwg=#?h8DVh`J#dZj(h%ijHGpxCBxS6XRZ2lmp zO7~WG7qwj{>SIjB4g$Z4;5nw_poEYLN_d6IP*AZ6IC-8MiGpDK-%1y1FutO@6pS@J zUi}KjJF+H(-LBZ!2s64Yh|dcL>~h}VwIJZZrVuJGZSPxWry5@MX! zmZ;$-9z9#RhIrcGos7bT3m-$v`n(>>t5m^B&mDG^T0Qmr*pc7@({kWudiQ=0KiLkocyB4zD~)uOkS1Z+C~ zeN>LhBMj7VLRypSUvymjUq}w4id_D8VOMYkP_7s%FGvRw`F5Vm_Dr1U!M&AjgUvbC zQP*s2(&3Y3gvC7B-g)YfSgjOWHQD!8E>M;E}ht8iQ)msb=rcHPN9gfIY2K z8T+2@%#o9!Gtw|;9lXZgD1S~fYVhK$kaBB@HzdjH8>A>Xx9-JH@jX(}+ZK3LwrS)- zm0Qx3LHgx*Q)hksoi6Q-1C!oscjZQ57%ypgd*E`%VmvwVn zyx}Eyg;m25l?SrWFZn%8Mg#c}N#arnp3%#axJK6I)a`wJl`thr24hev`uOp$>CA^5 zyTtbqTJ8c$@pAO-*n)3)nEf2DcVxhnJ2J1UZfL$NX=)HY@^DV-n9sGv4rs6}Oaic!?>qBc~2PIfHn zRjxieaT_h6|NQ2hEijKHrJuef!>*&ugwAuRTd{JO`o?{DT-{5WpBLOS8YBq zADA?-wni1BMj7H{dvm^T!{kQBb7x2B3S%44*pG)AF~g>N+HUUxM)g01kN*%oq+4Ou z3{=X7{Ogqi{d4C4S1>dD9NG@oKTA0k2-&lL@fJ)(g{pE-sD@I`Na`9mh4^ zRMnTqo*gAIUwSs!1vs-)k;&G1!=m@wD2%)cYS}~K@i3-(6#o0Go=y$oppopn%im69 z^Ps#w5)ACiyOCl0&!N|HVBSvdb3#8%rAa_s0v|joGtT@4%CO(!S|peBFlOd@NNX)H z{&BGDb#QQE?f3xe<>c(_%QkBUY{k4MH<)g?bq?37`Sk@|p=5uzulwd$eYQS5`n_jS za&8I}omH(@_$pMglQo+-av}- z0r9u5J09dQj?lga!Xd`N*;$-%VuPuoNd|G^>SJ>V;DDSfxH3o~56<6f*7Z0N&8uvt z>XY14`77|tAKKizqIDmS@%nuRZ+#5HWm8JkZ6WB}VuWJ5LP?4DA6(x+sur!E)EL2I z*K$(FGfPXGq1u6_!Toq7gGMO46%l3htwT~pSRfYNQ z7ZA8s$<$tbkkullOiHXn=kOj|n>gn7WZ}qNbW8@0_8AODYjYZBr)i0#h@qH$sioX}8UtA}%mhL&gh5r!2u|<{h{|124yg&v*S0iP$d$jy_9oM{BBQuXq zJ!j|lml+%(n?gk=n!VTAf2a6qS=mlL*)sIZ`5}bIB?-32HQ;alI~2o~1v*q3G>NdJ zv3SW?i(cxVR3Ld8bWZfwSs&|(sI08i3{c9J-LQr@VB2&%ED9KU&`)1Yd=OnI2d(v! zZa{1Q;YohM_P^JageI4!2pSo&C^GR5w#{*YEoSnK55eXlBO=t))eZP%>tG%hs58Io zaQ36J2Y(W}Pk;J>QQ+>V(`{CH1x1_|4Eem(`&`#~M{8?qTjgnPXEw{W`phZE+I4$= z{wbR6SfO~SK|>5)#^SY-bkIyIeq6wkS}*r<1XP}jf=ExO0~YTF`%RqOv0?*oyGRhD z$^U9m5Q7s&4JsHV<>PF{?9KS=OA zaR+&Zj(tA6=8B&0$o@-Ba?9qAX91n8*{=9o#)18#mFXP{g)o}v5x+i8JyRG76>YIp>btKnu-Qm|xO5EP}d)H_nO@K$I359jf9 z={eH%m8f?yiRPxQzG4ae*NJE64gSk1V2iTCf1bkqC6z_&ibY3Td5{|=k8l=a5IOqMVmX%yNBa@v-{-P(a9Xi`iDt2)o-8cd(YCpeu%I4dj=M3+pMcrqq z8jjkjMY7Lx$F5-_&{COpV4AJ}aXUUC!Se{>frGh@xL|i?TauV0TpvT~YW^{lRNYHFsZ?Fouds)^#0_ct%Scb)Wq)7O;f zTYTXBTPApr+kWROXLhdoDd2_lM}YjW287)Dfk!5?yL4Lz(P(v`?ESO_^hl z53^551+x#-;Q*tj&&uUAb8>LRA8o+jX#~E(24`Pe`68{`1pU z5%!#zds9Z818V?X!M-Fz zs)7GnRsW-?zI_q~=^;@@{NQ=esP&)4Z%+X`tlMamsh+B~gB_ZsXZI!wiRNtPX9kL6tdbZunvz^-lYSnpjB^%7XS zapJH0+56+()oSwb6{;1~_)C{(@E$ifF zuO66y*Z~2n;kwhWNxPgE0VjMPwAsAR`J#8#_`cubF|j3$HMN<=SBlc={sGRVS2exg z5ucuCc|GC7+?=zGvLU!q%djfF=)GXe7$XcCFqMgY^dVcq2bQ_ zy@I^wL~D10X*#O*&7aFSN~dV}&T5xhoO{ai!YqT(hJU)57*wFvYk_%td*eY=F{}FE zN6$h!9q%^FdKI5Z=w}U#d{~=eU^8>_9fO#QAvv!!XO_+88E1I>2cB_#G{5%>nicdY zUbYMj8Ya!8l8H~yM7fdurJ!N@T?!Y2A=^lS$oB=rTiRQX!q`t#+}3}!K)n0;xsGn# zaMru$UOGa6h#f)NicmR|*!|u+P*;U5#p;3Mqe2ikbo8{EGg$O+wr{-k)v<>xo`Vwd zo`&Q?nY00W9`h|Vn|D^dwmV*=^DgJL%gnyL!*5IL^ob1BQ`m)i8Pw;ZjdYEx*erX! zO8ZM*we8&3!9IbhDdDf~=0zD6^z>`-a+^Z!mLxiflZ%Q%t5sYr=<)1S+C`hIRVjat ze@?+`c}$F${W|_ zkOEYv$rEQ@0l{L+6`%%hJ3rq%@K5&icUZQN8NeGzv~9LSH)dIX+*=9;o>~2=jRQ zcJo#i7UiQS-kU3bwT|j$es{$q=`4F=8U7Ak;K^-$eG<8U*{>oF+6s0ze8Lx>^SSDG z&|5x~wRcq^twfNF_VHWw7<=PRj^jebp`3YJp)al~Gh{?C2^Qnzk7B!Pp5K6XNwc%@ zn;I34=@0j!Qn_es#zPEIxftSd3*p&-e{&8^f{uKf@$Se!&$?_0`eJx$-A_dNNekg=;9gYL7X31hSo z5G%7Gu4TkV+YF~;avEpPpZ#);V*L-x;1l2}YEO=7KrK>g4j5fkak__}7Z zlu-x*0B3Je0RYw)oSd#f4P13AV2Ge#=o!t<11a>n_jYXv`14kbaomzLaKb4X#{OnB z+TI>)$<>S>y$<~8(|tAE>(vmkt)3CV{0PqGu?nV?DdQ*P&h5cr7LZ@T^L@vJ`;oKJ z8`@PmzY`m%N5M@x^7EY8bt0MY6VwHv#~59?RHzhque8Kc}LEzC$fN$nTX16cI2PYpz1>zx-3=(4mcza-nPXCUHL;VCBNN zn7ASpecpi$giI-VUZ_n4j@E^(#!fY3z@qvJSNH3;GJTbtF9wTaIEm)wP9f%UU_OB# zyubHWG!J#D5nG;SL-+VFPHHk~rK|`Dpk@WlzG2Ur_`=peEPD@X13@cE7#KRR> zc2$*+5DebOzx1m#O^4S1gthTQ5$uHpeMg0@ez9DuljGT&^^Lwt2l|XOVb5gA^0W+d znVrX*JxmWmp09LzAiDvYCUy=X`}V#GuXd|G8!7he-OZ?AD~zekyZD@L97zWZz11$O zai8Bd9T+6R)uM=AIoBTkXQ}%;N>_gaAh1y~U+okPv-p98fEoB)@3cIjirZJ&31>Ni zmm|dM9kc<^V6XWdN^qO&^$P5>Ibi6*SIMo1zVE>5@w`8M+?hHQz{G)l`qEFKng0OOX%Ejm!vVF;G32~;v=5Bw3~SP&83RBUUYvza5OMzt~ z33BRb#JTKzyA9rA8ydOd(qV=~42ZNlj;>yEQS7(H4;?GmvzKI~wY}lTp{WvYhiPV) zFKmMyJe)sj=s>@hJ@l}!@D|JZodZS?zRXm^Io&bHXUaQ^YQKwl9ImnHy9CwCXE)AN z&btd`H;Dm-SeJ=-y<^<1erP6%7Fj*#ChcHQ<8uFy`JqnhKEQm!(8YOaiPNXv1$vRi zq@;rJ^jz)=u{XcSi@rIXUQ#Qj6kT=zth=Jv&DZ;dBS=?^u56GOWbiEBVKJ=QXw`pq z(%R1rV0!*(8|Vts9ha~m1p^25N{(wH8(2C|tXmGvB@7&Mt%E1;C%15*cRIg|N0;EJ z=wHBXXD8<50iZpVUyfPBGCKA1zfZe?5#%&`XPAF2JluEENFrS?*72jvvy&ULcXQwB zJv<(x^0r$^U5Em~WWbxX!l2Hv zEhJy2xetSj4D)TSvL0-dv}veiC>-#hnVL^ib)!yj;_3D{Q%sus$rs;MER_GYJ#6H zX-W7;NI#oYT%6=8;wGBS zH0xyb%#_IOnn&x>^fUL3vyaym-R8xY7)Mj7;#~{{O>@tKKMi@aFyR6i&(!|m5s?Mn zN&P8LTmXKZEx08Q;3}A-z6g%g0tF&!qIUWHlFM$t0z>B;whbyX9EGuI(7VU1S(Zb= zpG1OpAcMR6Qk6zA0l2Af_tT*N3J4^+)}U!_9{0rt!(lMwZ)HVnaqJq>6WpdbvZQ8p zeE&<$iaSULx&kIpha8bd#3A&jiffBDcNLR9+QwORX-Cw=r^A>x)lVE-{tst{LoGG* z_AdV8dGL@qR9C?_3z_!HI6-A&)^`?7_U>t5$dMbNQ|<$V0s&BBjRQ#+rg&v0q9=2I z*g~8n!qiO|)niyXtOQz@CPxh3SFX5%X~8QCvz5P;k+n2-Fi+f8Qac8Q!5k&=eCY%R zKIYhwCv-js^NXAR4_i&bfM^kNAPB+JW8kLzU;jVO-aDYFbXyVP1i zf=aIFAT)xR(A+@|{nPRWMa3P*N#V1*qK{0l85ZaR86 z%RO^U{(snu;{oVED1g$5?u=5K(P8^~wd=B1iS77VJ&;A`@BGxJ2%VF5X&2PZqwL)I z>ZbM6>dk+`m^Q@wG5y&8!?R|g(MI_7zoL!PAGl(a%0H!xl01yTP|Pni(p2?{KYMbX zhYh2}ECkao{)IS4{x9p+)!Sh3m0;F z)wbA3p~5Jj6x;f^J^wJ$|9^o_^aePE-c50)7}14q*GBJZ+Z=0FepCXS84{j}+q2s? z-;;$N^3Ce5*D_l?ZE|5oqS+{x88u-3%L@LV3y9s2m!*$?3pq66VpCB>bm=c5f=;W! z1|Pu4qAC$3_g5x&<>m$9uo&58{NoQ+3KlYS6p{_b808D>%39@^-o|e9!ttLNYAZ}_ zB03Rb`~gvS;UE@SeLTqmjvp?zOZ-31o+2CV`eT_Ikg0A89^F*A(bAVlC0V0G#$_x( zneoPa?k^bMI4@q_2UU&7vuppAxS*x=4~&oCdt7#)&5fg0gPI~;fR=Di8+c?dynrbn z#pj)&M-B-2a2{(N))r-=qI_o$3l4m#g1KM#8Sqvb@tkE%q?)2C?=Yv`QZ zyx8NUht;@wbG1{OI3I2F^EBNUBO&huTt*QiSK>k%EU7FUqdj7=`=I z?NO*0#>&ddy5`*eZGEztAzT1LIlh2VN4UErRYQB_`X#ArB(^MJ^r9=ZER*lH=84*G zL^P7UDw$B;_2ky&(p3$#Gi$07FF}>q!#i7j%)U$J1It5)S5^^Wy%)EczGtYhSslOr z)3yD!wCF`RS6~odo=>L9z8K6tuWOPnz)v^-)_(j<{U`!-)F7=%o%|UDtmf5P@>8LN zG|f$J=qwP_dv5b=W9(y*B+9$Fb>9Of&hvuWVa+T=klXRiQrg0mCk+Sk+xOh8@~Bt~ z?F~-!_=31RROb9I+3J5HUKt}5P>b+YqYc$WOC4%D!NZvRyfe4J5`@Z!H}`0rxdoMs zQOg&DCjV%mao!ap?bYG#-S%x_3JRr#TTUxNtb&^5x#r`!7wBxr3C%X`yrGH=(K!)J z+u-4%E6fqSjr5Y;GJO*G1P{*JT7ukyT(7tfAXS@xOwN|KF%-?F=L(7kgW6)EchU#mfgF&fiq6$?IwD=cf|gB+jvCbV)RDmpa@|` z#rz#Jhgtxbc^Ilxf(7@UTJrM2^U70sb!W6mk$Kyj^-FBm)uujx`-4Q%Q#{3)`L`nY zKP@dftO8xxSUYHd&|ma0+yZ6-Xc&!rO@gjw2HZ#m<#AuFscr4o2a-0UIYm<4B_jnH zr?;|J!uCW>B9~91$F2s1A*JI(1;JoxF%rT3ZD7v|&2cF_2^v8t=f^l9sw91&vd^Iiasy9A zkh~9+&8<}F2g=^Ry3a1VBD58ryfg`H%z{lmhkmV+2-_}B+YQMV{`eSUURJRP5UQMB zPpbiQOxXlQzzqN_2v2}o#&QAO`es3{75>GG?IKyEY8^S&+k3G5KejQ1fX2EdJTUsb zJ9&l;She1wcbZ-Ms*}WX!hw_$MQIa7idJr3AujqV2p`!GAY5G390lnoSS;4SHhj{O zR;wh{Y1g`mkeLb8vwfEy>VLEClLLAs&3~Dwk^WvdF1aW*leSa1=X$wdWhtRZ?oS6F zuv&3|L2a=1@0lAIbcD6IeeYGFPW1M$su?LKR{l!fk`D$v?nv%=TQlx$Y1rmZh%5hR zOwT}(f;%*;KjbML>LJOF3xL?WBWdRtVQD1Rs6N|kmCc)Fy(+HGOYX{V(IrTHy2dsd0tnReZ50y)+7-4BfM!X(y0`9&}|jADF#Nwd>NKV>(R={Yl(S*6ei+ z)Zkb~oDk97F1<{}1ItYPF~?z0A-sFks&Czof=|YoRa5#L{9PL3Ynix#H%M&`>`7Wh z5|`gGAQf%8bTf=54#&mgqGL;a+{a!HAGg*QerUio2aa&SNlu?Dyrj7u^1(`_D?!-8I`Gf|KjX8r)0tE z&AQ%#zhu;A3%hH+v#*{{p8L4!!r>j5Ndsp7h zQ6un-5~0I>UpsxOfiplNacZ{0s7)`oep#-Vs{IoJ(UeWhP38OR5oh%;UC}e8>zki)Wqwqm-1o(`>X3%q)j5yw#~NS7t3}ln^pQMI~UhZ z+bRDtk>9$DKD!!`(z+Trfyou}xj@l-nz5Wo!SQuIcCa(DPb;(arEvH&^99){C_u8D z@~;gaGD}#KdV8XE!(g=}hT_XJ$~Fk~6O_TIossI6wYLrd0^6g6m-<#mPDfS6!;^6C zq~QCwWwDYJ{g|7(^?x;aTJbfHP-IzGb2Bg}Up+ZSSjXtup56=8_g?Fk3Dp(%QxmLM zLa$<~QWGu<%DFhE5a`@r>II6$&zDa5Yqm${V@}^4XHAL`6Y5#h@9PQcMH&o%nu=wA z<$Jv5xiKrm za-Wij`=LDFy(*I6OlrSI=Ibu8wAMD{L^$qY`-YRGiY&)Ye#uJrS|4t8A7^{xny0kd zlJU#K{O#VueG^}38o$;RmhP9**pzDDvEbj+Cq-VGVh#bN8uU@|ny==HUT3v>Btc<{ z_SlQNyzjTK!*rv*-Ctd=3UVvGI5?`L8a^9(dV7f~Z~HxxvHF!7law(Q_-10TK*UG+nH~&3dwu_pp>r6c^H@DR^1%KJORPNA6*H zHLSr^6~fRV*UIyhNuN|AHN$6~<8wBL!kbKgz);TLZvDJvAEmbTVHK7smJ0J6$eRQeh=QmpAnmy4; zq`}hy8<2Le9rY&xeh$p=p4^biI?;Y(Z%Wld)@Ex#&xcOhq08Jvm!;&UKCjUXYueQ0 zc1}gYVSXFBVV4?N2rn)Zcx%)aqvG*1k@L7byYa-;7ujCV?PR!eK2<~~Fx`)OAEy~L zU)aYL86BO;J}Ns-Kc1XgxcrVc$S!%IPQj(9mG0GW@L&DvFw*5eOwM+d!zv%`M)Xr5h7OF>nmX4LPsRd`8Ts+zF5-*Vkp-|pPK zUpk7wkYz(va@$wL!dCa?i|*?AlkHt2E~X(i297Rl2**~-=XS>XQ6(?eTepo`MWUz0 z8it4~Ymay1vtr-~Gx3>6O-E;LFsBK9o+D*IH5E-*JCHAzi7uI{NWz@-2~FG_t~u;k z7S-A{5fllw=_BzW^D(vTQPcZQrrI(j3uV8)HetnidF^`9cN0AD6lHBxjnSz)cb$3E zMMWl10PStiL~Tirm;HO{{6+pOi5vUe;XM@Oh1_HIXt4d~R&jtUZ%;Ua@xqA3fbi{B zsMq04x~9u*YRD%GHUqY0=<^5u<*-F`eG0_4*xCr=#hbd3Jgp$tR9i1E8RFN4sqK_cJv!PV z;2`O{>0LnUPzVVZllC7(!;EW0EE-%=aitYGdLpCl(kzO{zTBET=u>geKH0-r6VA(f zGo2(}&hgb)+==R zCz>094NJP9<~-ceI=bv44RQef2co|%`-S}$Qp;{>AI0CGPCRzr%#wYyl%x-FId`x4 zSA~g}(YIdX=%v(G25O<^7D3ARro5>6_7PV9Z|g_OoNzKO5cG-Bl}$yiQzX=AQO^~) zdlG1VZvVJ$Vw6oP->2ChcKF-&G$2~CR+N_g7$&|x{;l2@bu@BPW4T3lUEj4IUAcky zZ!1S9hzxX{$VXn0OpvteuN{it!7PjaSwL3_cAdn88=|lqM^uPgUQh9VMk>m!|6GC64oy4 z_1A3$&G_0#^@q@9vXMRD`UXeuzJau8ncg3_n<%K)au-Fr>s-)Xcg5xFty}WR4xOh( zg~Q5ZxOq2B{1EE_BM>*p>fZeC6C*jJGw!gsGIJDG8!rE6#LZmAbvG1rU{MDVS_oN?BYvhmSg6*MMdoP9l8`} z3WuFAJ&lSIh#yzK+@AZ&D%gz_61a7-S0pz^2NQa+IZp*u9wZy zd_=g&Ik!W_BfXogDE`OJ`w*0@eL;-O@IlGid7v!Y)R_<%TYp5docDtcH|nOhPyhJx z#N7j3}`xR3ebPX(N6a z*(S+y_r*$GTUb!81YM%)mHW0GItN=@mR^T)v*9Luhq21WbM6$s<5=el>z5D9hHANA zua@0kmF{m700pM;xCg5mPgF7HUjFE6tZdCc^C}?9o6xz8x8sMP!-Z-|ZrGz;9B2?6 z&THCFFfA+fUYLNnREiRmWO*M>7`9TWo{oe9)PW~&C*(=oljWAoe3);$-Kes$>@k|W zFR^8P`2B3MUT(O9I*2pm7JDczmu$M6u;q6~x9tO#)MoEIkHiz@C{nypIbtA374XTL zJ3`V7Kl+51CEyo%h#J7~F(woaeaiFpsM?pedXF?@Lz79fC14E3FO^$cg8Fd#qcn{} zEIpOdthVZXW-mYkdw*NX@~%HV05I2+h;Gk2Rx+O4Wydj*r3bU$n{SZv=1OhS%jn$q zf=81wE;$3-WC?g6iP*rw=T_o3@}Qm7-5ckZ6<{L}?()EemFVvFn*>3|8@adO+raf> z2j9gv-~7%t?~I5gL`CM*(&hYpQ7yRu4qOd)vDmWxENUOE8MaI5_?fZSWdZYdSTn2@c;A}G&HoYHn z9R((e?RaGv2XM-~#I`xFald8eHbOompV?_6qz9bPb7*2x^&aC+ZAi^f(12^jEN(&h z$by9Wk`COA5EV#@O_@|$%&B>lMoWMSQf+6?gP!B}PVLb7T~8)ZbiZWV9)*mmY>XSb zHfm(2indXWGu`%FW5j zD{5IE$i2DTT-SC>W{mw`iqA9h=9!2v=ZSGgw_vdexb=8||BX=u)#HObr9%^Y)2=B~PUY%&w8n@2>j82kPA z=*8l5@y&fq<0uPzT>1*|IwEL;soDg_(2%&Z<>o~yjILL#Ri;Z3uPnmI@YiL}!=b0_>^7*h_z<*BMcuN+ZB$;lr+#k1Kh&Q{gxRr- z7I=RII$#RAV{ma2TsL7Va{PFm-F6;#!>?X{0lcda1hnj$ZDLUuegc9`nLm4#l*zWN&`wI&!5qDMZA4{Zg+3kPVnz9-EUt3B3Rii2=Dbs zMGtceR0)r&H?y45^59}!j`m_d+!dt`$b&}jPGPn+a4%e5O85=k5hFx&H(X$n9?pX! z9r>rTN1#t=v7y8e?$q&I@Rjn)+u1jKmcsE9^UVz%V7nYTToi>QURP{2r{E%tqu7_1 zR~T)|8O5TR%&BHUxt+i zI$07Jp4WS&oERkubWzcM-lyd4&8tlTZitP%mY3R8idFT|A9qt-cnWKc&d&A9`{u}f zyGxI)uK)@@PO1{Tn1CBFpaTW=S7JbrVFTP!o0rWj`c$~@--i6ae4q=Dpz|1sy1G9{ z2z7p8j0TUlc6FVbGjL3i#MrZNzT9xC;b+G-E->R^0_{wSRmb=5``52S{zLk?aBo7` zqkh98z4>r?m>~?^4|tM6_apUk zV-ol3{-;7Kat`Qd9r>pD5LmC8=^qzYXy&b1#%tWG{_fJ<9S1KclnIwSP)ot8HKJ@99{t2K7^r8^gmfr7+ryWYfTrSW(tq z068S=hoFN+Dfnxn0ni^aX8`(?)uVYoZBjuc5E;R{zxik9Qe@%kWH*Yto}RBt?*C#t zN6?E%{$mVq;beJARn_CHjiJw23{XT$X0bLibJml|&)uz)+ z-_`w7f6vLTR^}1pHky$|r;YrW$UXMxh6Y)Kj9!guzgcJ#=VlOLfgUUSp@QDCDTcmiBi&E`QVO{M2wX1*X}( z^JS^6;U-7J$Tq8km|Nc>y$qWR%y z()Y}#D4XOl8^ZYFx0=w9Zn#GPdpwu@m_}O(S^Jq)UxQ3+)Xku2o#+jm~hkP$lVQ%K-tZyDI8wqX5FA}*c&NlLyMF}3W z-`3;meFKCp#k&U6KKra*hV{PQ_d@}9p$IyGa0gKR?}drq?f?pJ+sdFIV^LT4n6v&P z6=K3a9p%@%S>-J%k3~Qq+X6rT`>+$gld`fLtvlVsPn)qH8WDVx$q@yvGcRQlAY zm3(m!Y8SJqrIQ{dPrIZ2Pj+w}>iJb)C|NhHyx3L;g2$FWAAXyx-!D~t` zqt1&&)07SubDf_>ruZ#-?q@swe)j@S|H5xqn$FxkBrdi^>0JTgN!H>WQK>k|J714H zJNF^s#82Xbzh&vZy2>j$u|$zppec^C&bGX+Z zm;{lxYHteW`evtXa=&JL86iC$)6R1eF1Zn)KBWr1<(X(&MO9Um0aI(H@z?^z;__nS zIQ);Jr!kV$*?DCRbJf}T6m4E1!Cok)nwjV5v10>`5evSjD1kn|Y@Ij0B7bP%j%3c{ z*QzfWGbA75Q5#y#e7Bw5jj!=BgA}>4_(QC46N~OzyK{+i&K|6r8ZNGqNzhu#jC-vk zrqH|4a7N#1v}MVjC$nGQ1E01BE4Qq(+u>J0 z4AUDTmCaA?+bcPJZ2z-<`rBZ6uRKhid*X{Ejl`wp(U?%WI%m&*b4|EOz~WLSe~>S_SEG?+?I7)q&u%skUKCjF|lMRv2kgS<=CKx=Wvwpkf>Hz)iZ&T zyu1j)dZKSxOg>SFYlxg{y@Xp8iy?hb4hUZ0EVNgsyd!xLhpF7v*(PvaLQfot>S%y}hr+lBaUS=frB&WCF$V z2W#mEhC(>vWt&wb4U84!#l?8lJdg1#O(gP)1;`K2YUPb?3-4_NthE^(u6`O<7tO?t zIOudO4Xr)cTW)!YHnsMNrRT3#LBYMjSBl+^x$l5!V}m;h>MGWRI$Ix-Ay0=zwOK-j z=d2!ex3KlKPhSh2hib0gSmbOX^hpX-2y~{{l`BRfsV#e2TBf#tX=`iy&@ta!+A(sW7Wt|qncX_JlM-@2@v==EUG(0Rr{>J~n*7 z{G|y}FwI1IO-VM|W@Bgk+|k`3-%+fSfmpZV#^?h4lM}XiYxtQFgw3#mM>QA3IIJ+l z{393B2zkao!mp)4g8Y07DL{Yemq53ErOUgG^y~Slryrf$yXoSA37++P9G(>#o-Q`j zP)h5hK%To=8MjM0RU>_Zn$@{bgqL0(+%rH^Tvre+@h?1TkJ$A$-kG;du+Lg03Jfg5 zc4yS#UY>4_W7VBC9iUef^gJ-a z!#!e*>kd@&T1s%gIma((U)E#b7+(@w^GlvZvQt7#^RAHjs}mejy3XV;JCb&5C3i(4 zvIhlMpBkA89SiWH9>z95Upo-$t5s9ByGcNTS8d5%Rl0sw`IL@Yt)}ww139s$zP43t zehU%iy&xM!}TE!OVt8!wZCH=Xt{B6Sqa&OGpg!tNReY|TIcVMTaL&|Qgv`g%3 zvyJ|2rG!!a9D@7ou9lXT7shEKE`K#gJSliiit#FXjWBn0ym=zMt}sa!5yP@RDXnr^ zY4t5s8?}59+S(o96v8{9JY5I7rEhs~6!M<RMO=tX1=+cvBE*lwX@VwZuZk*e9k=$yOVBEB7NqLJTbXK^0&N0X}x3b&X9HeQ~ zG@+(A)Y#%QmVj|?VjF2K>G5N0iX%%N!m{q5MCRCcOFUI!CMTbG<>OWKcGg8fPU9?MzAWed#!Qj5#Y6eitZGxLw8+80M&AIQ zgpvYu?M_YKRS&3DW*TrMYh_tkGdpmm6_$uD)E*NG)uLmh)(-QG4)P7G>Eb9-(_O;J zjtxNqM!4H4kdvSNsvScMG&v);KzC0SaG%Kxt9;HoUd)+8uenP)$K9n(YA@|}E2x-c z@0xGE~nh{maj_+$f?lvBnq?T0eDc zWi9IF>x!5!8Wv*v16vxV!aOhE;b(V~?vr-5k&3_2l`n_Lh^{!2cEkUbW_`Zq#pHZt z5>|FNdZ=rwzxTBN9p$coexi?Ki3qWpgZFNZR>qZrnflevn&QKi@%>j4@>RHH{_?!Y zGh265BxRIxtoCXM!Xua;)Y@61(Y!uL2?)!-wzevY^GU&nhS9TWiXA~d3pHZy=;P1b zQ=hU>#rdZ&@gvWUJT_9)5~rw$wlU-W26hXhU&#=8?~3Pos&Kgj zfRN(L5EB>8p;G&jgpyctwV?gTeERso04ps*L8}Drl2sX7b=kKVny1Qj(d34RYnXkH%)8M^!E1c<-@w>S}^~ zcb!zqTJtjGlBVt(E9t61ZsjDE1XKJ}EBjDq+OubJUXybYO{s&nOb`oZ2eGW<-g$kU zpW*12lX>b}%i$k{JXc}%SIm?l$;mV*1kSqlH&$5im@UT7_}}5B1n^-?M{Qvvm}8@D zW2nZd{OvlHdBo)*VeQSd=snm33N3$KFr+)e+S=N)BfX~Bnj&eUV{(Ct)81CW?t5dW ztgiE16-Nd}z0Y)dF-omakzVSJbz2B=dd^Jsc%!GCvIkdL%5(&|{c(0+`C9JrOk49=ZF=^SaOf&B8IA={*v{gC7=b1CdL()#$^YD$Age6a! z{2H0>L41^h>r$UcGuKcj>+P*q!Gt_toQ$HW;hbCZ|4@rUn84+ssHa22? zfsk_`3{nS?#ygFzf2r{l6%@2}C!Sns^sIOrH=*pkV(jZ!qLEKufCxw#Y|%+J5Xn?* zugNG;)RAK!Io#=+&o>g)IW{*vh^z6oM4z3t2`;5`BjhQI8`zgLy1BVc+cBA&IGyyp zCB1~95DCN_49!I6xO1ep)3h!;J{GRrW;u;3NM!m0x&4sjU2@`Dpd&eq-AUM9Q?}&m zf7=6duWzKE53OCLW{;VdBvKIiyQwqr-KVgF913Lb+fD@Z2@Ch+XCh6U*8 zt}|XgBmqaQarEtTK(4|}RkM-8$eD$dG7b4c`~vhFjJ(VfwjC)`*qXMKQi7Yu^c^19 zLh@Y-BUU}{VkKSa_88%c_61YX`c-bC?bx{O$AI6V+u$b${t6&kZb(8C;y^&onNM*w@PSDoT5o>g6o*hj=;w z66%K#x2sC*+GX5)T`z^g&n9{)29w>b-1LlUbH7~Z*3Qhrg-&Dx{w#wUn@pO@+zI|}r*7n%C z*i!|`1)|FZsWYy7>Bno21^JZg>3@I{t~)EnX}T}cNJh7N$n0aMk%)07Sk>=@-E7 z!TN>a)aV2HTNeUTt+ao3^7YT(2<+ zAbR)3v^~_t_2j_wTF7BaCE@TVT`P1;%z#wy{EBt^^aGBb;IM&LfpTOWaX!5#XTsk* zw#}teIq%Ka)7Mn!Y}-{*>dZW*YzeKx%yQG)aNe|3o1G z?p_L{{aETCMNu07fX3k80Kn;$grp?FxVYtL-}!aCuY$#1i#_oA`_d!$AH94-`>iwW z6j$~tPY-Q@4gt&MK*=rD(9rPAH=yDJLs&y3+3xe^#B+wYsE;T&=ZCK4+tg&(JCu)b z)YEek;uF(Vnbn3m6#}R8FGd+5GSh(j$S-tprkLIbW13A9o*k!`#qIY)LG~>$=qBb? zN17VRhqwYq&onhRc7~3UIXq+TxV)7sqKHe7r4NpL82F^FxC05VO?pWjmQlNv3*|HG zUv{kzc6*4Ja@tpv`*D!|Y|q3Zm)p8KYBOA5PT}lL4ceo@y1Db*y+Y6;6Gx!?3WFxa9jAuwPZm6sGfZ(ZUkkgQ4Fx44M&X~Q?q z3XIsyG^7W)Ei@5oJ?KLGD&Np$?DTN^JX$cN73y5duS4h#hx5zd)i|{{qT}Au%{XpM zjamddfS6t>R&1sc?^u_U{%s8k^qI@k(0@y zz3la4jn*oDrNeDzX(>n(eYz$(?a!2heZFvDKPE5`vTx^<&ZvzA?XMlCmY2PZ1*52a z2{HJ0Ro+XzQYMy}E5pf4R*#O}$lRgyNCluO?eS`YTZa*270Ny915lc%;osyIM0zOo7Zl`0G)#e!~ z9?6onMa}Yq({M&ox*quPg!x=dWi8Ih36tERhHF_XD5-cmY<-k$8$RF8YC58H;zXkJ z?6wlRNYGVtmtw@;%QNrA0gdk{w#iIKE@ZZbJzBWAME@+y-Vu@kQKET5)A=Fs$i+*x zmJS|48a!evFEv<6kqPN-k_UOCMkkL0NQ$%5va(}8SK^IzSg3gn(+k-&LvU}S;VG58 zu#zYYiKq`($LlED-9LoKF;QPA?0TA@7&rL7 zrdrQCu(T>~{-Jo2xC9cpw7`@phT$UpL~~&sdGsQKAb-bwrPA?ev;w8rWu0zy#-_EC zMoEnB)XZ0#I@0t@vgaWIdZ~|4;yMfM`OWI?ed5WXAG?@5S!XvfFr>K<^K67~ z#F_QFz<41e7Nsv97w+vYt*xyM3=9Ojp$TEZB%(}0*uFVAxmi`QztNBQaa;0Q zo}7%1l@VG^;?~?h8+Si<8Jm`AT0J8Z;!@{1^R`qtvH7gH!Gc8TvdiSGxHv_Zn_b(x z%Y$1cA;2l;ZuU`jCvh`maelmtnk54XFsn2s3R>G}TF`ZC;Vh%h9u#_a7 zBAw<>*-#t}>fb&@-Gg-=s+*$|{#*xg5(0Rrmd8g_QW7V5n%Ra%^_?DTCB1LW6lvY( zEF8!9ptDa#fGYx|magBNJJ#$?Nr>*;+3=>Y@Of)+=`6{>^w{y^$B!LLBakKX{3G{HehZO^3v$^9$69@J{u=&<{BwsWO8`_nS=PTiynF3vSNB zZ`0v`Xl-fHXO@tVXd-wrxxA&W5l05vtxSYbnsGTaqf`Al;~xvEw0M^|!U>jJnyE{6 z8H%A7?%gCqgT>KUC?h0gyVb6)8IOMK`dI+y*uW$zG|3O&ptyD;&hQ#6C|dRZbUGkI zv0cV_XvXSyVR53I_Y5t@SyduQ5b21S41mhY&` zh}`q-hg4sKSNmKx#=x4Yt|?M~+-~(5{N*Y1>z3xmtjJcaa84A4hn{7uy5QFWfCug) zYYQZ&VmFKz4gV#yc=K1xn0)u*q+*O-wq9zEpm@K&7ANj)6a4PmeL%IMDag>pV03o0 zlH#^jld)-X?I`+Qbg0Yyt%Q7Z=>&oqznkZ^_pA*aNa}P~_e9{b%9e+8?6%x?pU9mF z6AMr~$XE=)$q4kHA0t|~ZdAP6H_>V~R$5=kb+B%T!KMqmV0@-iNN;Y}qspmso4S^PlmSko%)lJ>-40!}oI>4cC+`uC^bX;NIe*cZ^beUp7H zyuIf1ed*FEUuLJr;oCZEu0O?{NMjN`;=v5-s?{Z9n(2i#t4BkB^>bU>N=N744)W$Ck?lAkS;( zD$@KLsYFwTYUts>n}5;_4eFB@pC{KZ9Pe5$HN>`NYSS>GUQUuFb!0NxK*ZL@roS=Y z5?TZz{+u7;ON<0YjD{EJ&d$zD>L!MUhBbIkbHGu_`p0#hHB;HvXD$PdI?v5`W5{jy zakuquG^~UOe}~mW%UibuRIGPA`OsS6Mm4m9gt6=6mJyc1k#vH-!8-kLi>Gn#TY$CP z7(Bl~Wjv<7xiw5>;gs)?qqG{O99Zh<8#xKG&n0JWmR>P^mGsOF1IYm%tT6l`UnP@F zrq`K74>4$xZo>ICF!5SUPC)-)wNZP9R9^BeLTBEdW-cNCz~1Y}#C%xR1|Bg8hgPw9 z28q1=K?Y2$kTN`HZC^z0!9rg131))UOP@P8ZuiWwSudi`PJ)-D*%1Mw7dLJKrNNKW zv5eT&avJB*z;ptcEJgQIM(yAGNnH$%=ueNgDlQ&Gi?LidYh_Igjf_5Zn2;36qoYXK zdl|N!pKEIe8uQg2RcD0;_cpF^bO5U!Z{H4QUbv#uv0ipTpPOO71;2!;3j>H~9uO7pgls#71T*)0SrOY}hMxx}lucoh&4 zc6uwEZFu@>v6YZzYa*SJ9Nk&_{$GE@1&^}tJ3n}1=c{v~3`*ly6n$EJ>@XZ01RxzT zdckv6KDhV9`A5~k1N9spw|KnnqS=V(_4Qt~xrNu=hyae(gw8P+?yp5TWz$m`yQrdff6MvvGkd^s$6c%jHj( zp~;lGL(Graa^AK-&iy#zGxl56to|iA0E*7~OAEn4V@9exF9PO6vErgPW6w#y=40d1 zSu447LQ#wh=|0WPZj{|>w*K2ow19n})(eMNX@{+DN9kCaEI>m#wYM zpX2eL#$XFv1z>_L)jg}Y2UY@p;=H35(S)1p2(z^N#1+|}<9v@DGTU_%qUVj-GgcebxV!2f)J>laTMQq4tm?npYD|fkueMHEgExOK@GH4dBnA4e_H?^L^PU3xfybx1Pm38&?p=H{GunHJ&%c8##M;_Th z^|{k?KA^-bR-MO!Cm{;cz^z?2!GSy-=fFLM!*n3%P`rqcB{Ew|9yv53To=z&v5lYl z_A!4@T!u`&oXqq}=!x~rpu?5spGB@o^&dVfJ)PeGl$F09BrvgB(nmIpotn2C8}!7^ zC0B@<(BleeiOQ=N#mU79$w}&357+E0;ng-pyJHv}*EfKbb?wxVC@ zgPc#3Nzj3H_x7_tWO+syx}mrUwZgVpW!KOA`uwZ*GNGf_o01_G=&zc#^#{G1>TrL9 znd~Weu1tnGb6gn@!pL#1&F)cyH<1jUvUas!^9<2($To9_=^=AKmkUZk< zRxlk$PTv9qcfxhdC)byN^4lmVwf+mAA@|tty|ELeUr?;nD$ynUTWSWi&tTV9IP$1R{e`xDYc}ZI0y42q^8?3L^jE7a{KB02hqStma#0(!zyA36 zhZ?VE$K!pnva-OpkGIufR25Am{ZuXtsPs3kJ{f*h`oP8L+?A_zC~V)xmEPy;YVtcS zM-#m;2egf!n>|uVEo(aGZM}Qfv|*w5RSKItnMV(Ly9sg%RKmd&JhCo_vQjLGZ~&Pg zZ^Dht_%=@5=L$W z-0Ucy6EBjxpbl*%gX;PyS%b>ob=#S#8G1=o4m!$v4+X23mY|JZWhT16RL<@LHSPLl zoYaI6H-tB^-nC}E@CP@b8ftU#}-n|?C&l;&7;?(@H}DFeJ{Cr$lJLLG0^;(igxpLv?u&qgBidG z87=_O-Q$`^-A=UemP$4IOE&&cgpfaM+w21(2FAxTqJBOBh0w440#asex9`2oXfQdh{y7qQ403pKC^Q~u@8$tL2+Z08Y)<-;V zbdB{-+@9XD1Mr1dQ(f|rxV?D7;7KTj65hEzQj$%1DRqReH+JgW+-0=iM>>BGl=c*{x*?y?{7IR|2L*pSB*=~X&$3?u%)w=TalgQs zmnU92&+ZG(;Rv}o`GIoAs7PSMK1s&cs4x_I1s80sbUhEmQ@=kR76HNw|M-D!k6EFfA*Wl9U`)-)U4+MaW&#~WHHq08FkkxG%YG_$d<(eiLf#rKyoXK3C% z)G05z5=S7ieN>V}A~EqmO|3%lHhSL_RixZ!mUI&4{C;L1{LcPADrJ-+XobfG>)v~? zPe8=wg6xghhrE`i(@NXeq32+kz~$I9tIPUGXg` z;AsvaN6q;NFOYU4tpLXdTcH`Cb>=|n+bWYy#m_#Ya%U8rvfU8^T+ ze}s(E$_~iE(Up=Z)AiBiZPg^^IBc}s)L^%Iys7+Pmdiz6I|CzyPS|Bh$^*6m>+x1J zyl-9nW>oi)8vYB(yA%c5fXEB?vTAR{D8k&1^n0U_XLF=9VWmjIdj)^n38_4Lo+NpI*=*S-7gFf~r4*!JRb((%6$4`8FGR%VfbpBJ_ zWaF;L`6W&X!1emft4iGZjAtqR$V0NG`LGBa&3?!l@-5&W41?+*nx|BA5=n;JD>sa!rz5|Y2jUq+ix{coj0F4x>#K{(lzwa)CXpHAZahCp zSwqjC$3!UZUZrday1#J-U-^a2?mSd>$0mhc^V|neO$8Z#qG#l77Hq;Jrw@wMeMV2= zm&pb=bFwp^-TNd+H07=U$OagV3tc)ZqUl*N=5{`9#{=LXOL`JZdi1D${c&sx7AhX& z9D%`zmtMEoRf^mLGb)?9|2li~EtG?(Wg@xemOVJnCk}lL(13m7*xGc=stUVujE}0# z$%-798p1(yNHZ|C&We(Nt*EJH->>i$zj85`RxugGmH$mzHm4whmZNCFvEBX~Yl0li z>Fx_e>sWE$M6`R}RfaPvwsm%%0bHtScV?L~JM-+~FJ1XXMdVjJuXdPTmGz1}X3y>P zE$U|r0ZX{DQ)2`8sHGAO3O4~z?C*Aj?gy9LWhg8G;x%%7EUmT|kR9(3jg)L$*_+7K z;mEBweU=*&)gyA;I?8kTy;$^)WJ}#cTpuT;lX(*`3&a@eZUqP+g>)C5niBy`DovJR zcy_((YDJ%C9Y-vvir60BocclvZNZD^;!pQ2qt`IAr_?2%@ZqUiiMOJp%sO*ZO8~q2 zU)oEatK?BcSta}P8TYM60M2-+-;JTeIFnjYiPkqZAZ5qB82Yx_~*fI zI8~rxu9k!{M6XR#pBLj=V{AZ(Rw$(UN4w6&_G#gTuT8(3Y5IEHxdN zAdDP*7-S-%^fWmz7pr-R{U@^(l zgLhmed!FKE_u{k(32U=dHk#AZ`Rbi9+K%@W(;Bg-lc5@l2GxK`E6OsNqO?l6BYM`K zMAV>8rlYFF!w7YGwp$Vu9(mwoJ|#Nv!i zSEiJKtel)z!>v^@iE>1Gz^X+ARTQ^sO`&`d_l-YR^JZ|T4;OvQLgH7?T%lZvGKtR6 zXNo{6OxRKIk*ol{@gf6<_?tGAY~4kPb@Q2WXqUN%>)R1?G_*l_5rRC?mu~5^pZnVv{iIWtCOvD%#ULcyI zU6I9(I#ZzMnHgA|=k_)+FWaSn^`%z}9=!QKIe5g+geVXfY60WIAMIxRk>Kr*8((P1 z*_O%px=rTZi}uLi#K35v;oqDdEu6tW9_1@u9%@3H=D)qu`A!CI`Re+6zHcO~KzAZq z5cn?IE9RHe`56Q!zi5wd$I=+krB>lrfsJTqtoUsv*tD#-{>T}FNBWS_u#@qGhtO`V z*VNKCN@wTWbYPLry+0IXSm?kYm1UICG z`DZlBf%V~-IzJq4UORA8femxYL@2y2C5MsePZ zj3AiegGw-7zWbZh+j~`~Yl0#RmARL41du{gpv7|%b_rp8G;hVkiZk+lbQUEZX;bIy zwmcI>C1+Z)Xt+VYS=r#*Hae0;07QqPiP3j%PzDAYZRW3n!wm9d`hpp{E|nQP@Qd+` zj}_* z44Fz3D=jKo?)E!1{if;;;77UbJ4WQY_wTytVl_|>du~Yo!MB&8c;cAdsuWSqC_~`r z-)yyr37SP+{g`E;`QZI|`h&of4)+$5+zk;o2c!H&5$^VHtrS_&(v2XG*uw~fpT1rL z?h}Qo-9ue9Jc?)|M&%A}BSjF0)e|LAg{YJ8&wS`EJ8{;Gp`1x8|NFJM-qjQ2HqGsi zi$E!k4%r+iL?Y{fTLdD6d&^e41sZIt3q%Uq5&sr8*S-a%Z;?a+M4!JuobLpQ7T=6A|Yv#0!m6N2q;L1bRE0~ zA|-j0Q~{9|kxoTLKtj4Z58ZwEW^In#_q+eypNGBInlm91@=Hg?R51H27viv zqoaNMK>dM|@{5YGKMctlq+nxpUI@rc@V%-OusGId_eEj~AgV)g!dGSx^c|l4KU2x3 zu@YYgZCMYtPmB$y329(!F%pu5zQC%seC?zQTqra`DaL9b%6^_iywrQGDT={f# z=ZfR9^8^&X5(rAU1Fq|5pnYE`8HsTSP%#8G{9 zAnJoX6P83X@5`XprFD8)0?uN(`dEuQ-TD`5o5#El$hF0Z_ekGCJuYN^lfg=wXJxeJ zpqPp}S5;qN5fJ(72rftjPartnT7(|;Tu^#SdcGoCx~0Sd9xvsT(imT9yjn|Nc!&e+ zjCIC_a%IB>-R&~d!heP;tA6_aR8*m>D8yGLvHmgzTZbYwN+n-G&TSFg_JD7oYY zEz36OO8Q_QT@K>_eV|@zu7%AB$7a3+Oo_Zp&Cgr`N>-gG($*!r;I-Br{fz*iP4%}y zO7r_hgH+^B;9RltH{{&)Q;gB}=a<(=aKVqcBfAC7A~8!@6tQ@q?a^}gwo{L!$Le@> zmOlMkGo1)S^`7YGZMy@mV!_(jZh+i<#CdSDapR|;!b_B<79Z<@@J#|L_Dg zUad{A>MYWdpOPMYiw^*YYElXFy8`>Ey<2&Q)E9 z+pk&ENIP@aZN%Oy$jT57lu>XzSa`o+-wSxw#6}-0S~t8_)03Y%W(IwG69N#{0|aTi zv>{qf%$Usn1pL38-X4saoEsh=xJkz-zznJyFVEOVNA;+s*X~>?xp#yZR6}k>rD1t} z*!PfbkEnw7#vAbqhE5g>y?RIDx4j%&wi2^sD}K#Rk2vbXUi!d>*zE-p#&l4lk4|@k z!dXGV(}gFU+8KKYWc>BTvm#lM$SHGT$C{6H|gAF&JeF2DM z0)dKZiI|WAF+xy4z-qx2ZgfasjLrwI*IhTPIsrGiG0w$4QUA&S?)u%CS2B-W9?e}XxZcI>uFwAbc%^#=AT_fcKJIOcCUn4V&o);F#gRq@;cBhO|s$s7+;Fc3rFAFwda> zI^c?BhgoJXJUW6?=ME}H5Bg^B-c`0NfLnz9jMnqOLa(gU9+-k z43$7PhOyuR*o!BR5K{Unj`QnG!rwsyP*6;4aS(L3we6c!nwa{D(gH_=Kyuh~J2bXD zVB)ZXnjl1Xvw9K^yr-naq{}(vLuUJryj262^nRV{LUqPum*m|0dyObmp-ANxpzv}> zz(vBATnbiZ>#`{0R)E_C{*S5vx7Sgd$?of)W|J3@E&X$|EO+bci-a@VDLL8SJ^_rx zR(`{M1QZE_?7R+u%mBcuSv>y_+h5;H*uO@>$yO~-?wI_1EInSC^C;BFwz2$#bcQgF z*UR7Evavm08A2o_Jp7_Dpa|5r18r)SnAdx}>l5kj$nWr~goTTnsmSeV!hseFuG2oK z)fSXUBS^EJtVC*EeJ9p9VA&2STW^1pA^6QxaB#SdBi{^t8HRUERR0Eot*n)R`&bKI zb;K4oIvciL=fxH+y8jz_fejz1$cBvRKYHFp_%=8 zbc8!`6s)o*Uu}2+!)GR{0P#r~GwSBsdRCy)=J>l6RoX1DGw@ibR1&R`$b>!$5|o6M z$7sHshyA44j4w<;chRGceLjSC{f$T z%|`2WYD0#(HxD|akOn{(?aEJEujJVp5;VHh4twbKRDei=DOfJMy?|rc$F_&hWXvzu~iLw{9$ALYW<#38KXG?CZLwsXs>MO0smE?drcbI^h$PrVx<(O3-JH7h4HrT*B+Q}wU$hV+jNpU^6 zJaR{`AK_g;1*^m#9mwr-Yzj0_XqrGu3|R_TqH3qO_VKBc_}SW3Q1xv1$~&$4ODV_B z2xwWmP^Xmy*&JY-)vvtUvGs^qZiRyUiPSdmcGy_mZtLH$K-7NkYqpUk;Als0DT$&) z8GN`^nB5J?WMlcN7^qVi38?{Kim!fC>=9LX{J`O!YocCB|S+{6@`q+wEvU z#i=Zq5Q8TWp5&FIGS;+Aku>3E1qGW3Q+9iyAWGKuaBt3vcDZ1xB>kT%;dBT00jvho z%q=9KY1YT4dBOj=1Ywx16>BA-E>oR*ae#WT1p4s;lUOWL9$(|Q*)Uy9dAtVYl|(z7 zo=Pc0NlVVpMhZ3okMoXaiGSOj^0dfE+mS==Z%fJUq9&iP9zWf3!;%GEM97G9 zH~IdzfJ;JgfBQ>nsyF*fwsm-bcmVk&J05Gb*~n-qERRXaO)UaX3Ck?^(fJ5j_Dt#5 z{p54`m+T?xYpQLRCi06#(!f6;Z+@H$b)n_rc@S+PC5;r<>1to|N<2Kq$yaci{aXTg zD|RlAY`){~y8cy;Nn7U?OT+I5i_q|c0+AZdr*9{u4SJUh2@3U4AsN^<&-~w+USRnO z5%0i=3gq=iGhKft6{WV2t3>bqb8F;Y_#l^P=QzWlpf#eDX`CzRn zYA=I@TXR37fu+aANVge}xI;dahY>%P&Obrnq0zNwX?z6yUU}hXU7EfrfMxQm=dnY& z_MJ$sNpoo;&QD~$ttzSL7!n+iH1$z+SQ8@hD?atGCdSXf9k$_U4C~*q!Zkrr@2{k2Iku|A%0fPC#(2gM<#g`aSymW zd3YA`sIsjh35-(q=Ys}9@+b}|V)DIMZ4U_(q7>D;<35_$gN<^3lL!QW`~E z2St{M|5Q!WygZa<^} zd3@y6i&(xQmym3tH%mx&wn9?0Fr04@zXPL#iwpK-Y_Z<~_2FYv)SDLQ#z*b)BawI3iQMgdSejUAX3an1!(aJvr_Qccr7g)mwAI ze~VeHe?SQ&6LW$4hIs;8^KD&X4rVV)05rsOkJY!nn3RTjH9zX_cd;0G9qV33<-LDv zP#Ow}<0H)yC-OE6x^4?&P0FHR!T8oC&M|(YS0$~U zlhWy+e&V#`r}0{{0Ta}Bf_K;52Hf}QmczdAaM@zh1dqvkwzRCjdci_Fb)QPbBO{c$ z`*{OFDB!3@$i>#4n$0bodP^n+NuLm>xe-#Vf1)gSmWoG=F`lmb&oR2bhoBiNk|K2K z@Ko!qOK-0WY`DgvKhOzzR{su)G+6)l_f#k)zToeGAeDmV3vt$^LhST_sDdL7q+4j# zUb;j-aq=5uJ&1lOi~JPHB0pgJ8(-9aLT!ww5wO|;Rq6pJ6RWbYVuAU#w@#oN2;J83 zy$9*kN?1*ca~H$YSiUiaD~g{XD;w7&%gJ1beDDA1c~`|>idBevQ?J_}K~i*}JPAyGG*_C&P2o7}k6tilHnEhXKk#ZU z*a#quz9_;?A_d3Qk{-}REH94TbiqSjWJ)^HbTf)?8OnI5Bnr`0wn~Wq^snCVYxdF0 zkVKPk|GOlyu4CRL#Wp-h!G)0b&FLYTUPh@kqhE{8o|~0Do74t)u9Mvb1mQBpcd>Gw|@i2)LF=BX3!vXiQa@IzwNXGEGnkpQ5X5YR?Y7*=ojnF3;gM={m|W3Xg! z@vlq2G8v4>_U|tnfDOYUw!J!PfrcCe@4Z>h*t);$H9I|=JRSGL-nS=xGf#B;nLzI+ ziRo3(mQ#cS+bEeX=ZQh+#8{hS>2(n45hV)OpukGuHi-|*j1M-j=$4)LV0(QKAmj$$ znF#&rHIuRr1LR0zI!5@~Ou=?GPZi#iFCcshLXy1*s)6h%!#ZfUo%}GREQ&~Qt651A z><^>QiQU|Qsu%Mp$aCI%l;t2eVA1j0LoIttgYO(8us2u-$m0`4OKH??F3JU;f%Oke*KIl&+5j*h6kPBRkhnKG*-vHxq<~YigU+Lq4(s{0pOKo}hW1y$@ZOc}33B@N}LP^>`- zjR>xTkbpk}$*Uf>7WW(=ITGhAZ39%d4~(S36ggJl+G_ck_S6r?Y)DcLte3gQ9kAlA%7HMDu#bzSpkeki5SUyz?;-9Q|$ii33AKNy$5zM7}<8{bui z?fM@;#&2H;5QT=Wz;Xl27Q15Qu&-f%%VBPZh`-qBWtK}Mn-|2;%^jqQ;(J(-6+d%p zqXep1u1SP^7c0fv*OMz`cs^8#+yHe7$%0^~2sDq9bRokrJai=Gf8gomp%-Kyto8+i zbHEaqKYRRF8#rQWI)6j>vf{+Cw$lKC3W*WBlzj<5B#Urh{WES)HY6&J6Yd8t-$chW zSA1#Cbp4Iv39t?{XhpibIg_}RcT0!phD0HVLl&eAk1PHEIgrFq2%?RL_oBf`AdcTi z!+WsW4};`i))&W8oEmM&>GdqfpVajz4M+ZgE70~;7*~See zdBaPt#FFT-mhaV-!M5E+Oc#>DQlaWF%j11MHjtvgI|qO!O3tOe*<+6q$A$l;ewkBZ z#Fy`Pv@{}i$mV+p5!~&X4DNcO!S$(oAZ^{8^|crHm$ccyV0MEyUOj7h3_Gn$Xa2Ii z^XZ%O7#G=~(l0OH>55?g~($Y=w z)Oc(rV-ax%8gF8SB(W_Evw;_jK({k7YoT5^n9|A)I&{jV7yeAotgGR&-r!!B3Iyf{#autxF+-t=gz1bxT+N2m2zC z|4E?PcgAicMxT{3H=4CO+liq%WC;Iba~b`%rNIExY)g5o#4{W zaM~vz8VK2U3`NZXa(eZRDjY6)$Od7`Nf@o2n{@!J`11?9EU@AcRKP7;AvdQl+x}7#&zgIBy!fYEha5e6*F%5RQZdZiqyLZUh*=yUB>+e1Zs%7b!TIZ~K$kFRtYz z#C~BaoiYQKc|dRmcG7+w*FpbR7=KyOc8g6`)XHt+NI#nEkZCS3Uv%2+IFxz<0xGZR z><)oJ9zcB#svFu;Psce218#ErVC<~p1bR9bt2dbd-C~Id(2dJM&{ZZjQP`vb#((1M zLoore9|jNy)SR;hg?2r3s$lwih^IXPpCP#LqlLOnc%#G0)+yudGk%EiEt&vVK8nQOP;G;FgXN3gMXXgIG2+h23q6Jl|pHXQ>Lz zBQ^`aoseve;P_U#7|#5H>=1C36xb2*&^By95kky2)xR#udzf4&Y*aAFV- zUmCn{4uDC`_n}$Qp?m(IT4-EVa`Q!;MWI<6w{8UQQ~x^xnchmSG1-td+qhr`bz?hu z?_jm4;t^D=3W+KlN-QCIK!|lv=q-;FkX`77y z*q7=%$aXndaJs1lq@K!f?bcQYOVmUs$*RAKY5`-<8(Dle;M|Y^W{wI)S92c?{)my| z5nmqq@%y(YwRltEhuHOm?$PF>ovtfA-NkvmTgcrsY6sNO3K5JOahfB8|6%NY5bV%S zZpEG{U-aE!dG<$7kEf!L+sA^<-{$S)6O5 zHz-_nvmq3>^YW$)#Cb1eWa??>sKik6P;a7bL`9>}3#1Fjf@pKwYPmD;T>dn(5gXT5uqd?j2{3nC=ORX3Vl%5!=!(?d;c1@cfHfUsDw zJo_I(xBnG-F_#EaYlrK@`3K=yQ^6)C#KNA-^S~aX{PXjdtav~NsG(~_3+N%#&bM5> zNo#C5$%P42w8&#_vfHyZb|ld|Q-^S-UlEU}2c(=DI-=SeHxQ2ZBAx(Ew??X>4hk?> z7~u5-R1LwK>w}1$?sdh+12hvKDkEG{^TQQ;Rgq#Cn_!9|MwL>r4{lX~GS2=mY|-MB z%k!;Am6dI>e�D#_EYWzg8Sj-C%6l%e^oNfGR;H>QQI7{v-ZIEB;LlKG2vO_j3RI7`|QZA@7qn?mGk13hxP z82L&E+%!7nmY6z-IKWEwso|ja1c4y_uNH;%Uyp~!^BGS&_{>5>cVK@>@f;v~@Lc6d zJmk3vRpU5lWJkPO=GGz)7UZBaT)|dJX3mAdB!OH-AN_ z&0WbIBeTOt6(a`@(IbEJU_w^I9gBLPw`5M$M48-4Hq(u}eGUu1=W*Xe9(@3c*(_Xa zMX#AbS$S?z$fnOFMYn=g^f_4!YK*>m;L{|4|MuOAJ9GsDxx%gW2{yNWnvQ@UQH&%t z7Gzp52z&L)&x_e`Oo&8~lU^=q^TzeApX;Ab+$W;`P7#WtryG#$%69=iWp_ib_2_rliJ~kH*rd-a7wXrC)=8bK^Mxx6u^KD*bv!9Dvjm!n(cO4?G&mUT zMzvtEi?@C0>(3sKN_g3Q&+GWlDVCMs<=NW2-a8vEr zPH7+RkPNn$D@}7FHrIa+AtyF(+mShzeus8N(w@m(?D6pMn(vG-B#=;LSpB*_)4M*t zz9_+dXkmTUeccFD9c0wcf_r^?1637OMkE=W)76sNIW3gD)AvKiZMuFaJ60=9Eq1m6 zvkj+eLE%=4ohm2m3*vAs#Unw<#&`dU`oQ;u>SN@Vc1lgJ=g)TrdpIqu&pe{v=H|hQ z#Vw{6#DNOolLo6N_^F^VdsH)zp+U7uKA)_9Y(Kw9Sa-CFdWK)r>M>*&?=Pd9el zrHx0$4}sI7A&wMEqPW|7*b0w+Jfjm|dzMOz@n2DK(xMrVdX9^{3}b}-dnwPKn3f6m zdH7VA?U#XG$-!>F_{Q=bqN42dxKBKosA(^%Fu1718qg;F+>7l`1@zH?J_4>oZXyuA z?xf_RiKmuGtUc?aow9FQ=qGSMovxwOPWJ!3|HQ`+ABfgof^i2f(U-vGOT_Z1b%t*- z_PC+~EP@`pNoVo0q&bZzLcBsMxvjwEcO>%<3YC=pWeeldCPM2GIH z5*mUp73I0(HZw-yK4)F?1-?baWgh7JqiNwl`QJ_jKSqd)>B9xT2k7PLoL-e+XM6ew zh1)LFW(}@9YGitSWgQyMD@lc<%=(6IO~_S!sR*f2P$Bp_nlx z2zMQo1Q0v(O~^+Z%Ci?3j$Yni8F`Tbvw{J0{4)3rFN;6vTP$fGt*QNcg&sbjjbmv* z@8k7}s)sarkn!?)EZslfRIrwzP-brybkg_AHT(0bp!xf|9}??0x15$j((#ys01v66 zDpSb;B1+T#{^hwz@PRX6TgFxN%%rHe*@vEgL`u5O3U7+%!fg!;L64+yEW1JUEmwNn}^g)mtjbe_E# z9`YwW$AK@B80y!vrRXU%yes|l`>ZR}rX9q0fBzqXj&O1Z<+f7_6+yW6{PH|xbEIWjn z*>mIy~Kf&n2Eh@S*HU2S?x62e!M5QXCo_YbuQnSdJ*vj%6)>RFSw8 zaCbns!C9PEdO*7|hm@3_Y*5m>hv0XT@(AZeyyN;BPlj1SF@HlWsaK-lb!d6)!!+bp zdSZM#lDCTFj70D`O*ib1BwUiBWM!XC@;q9YH5ehR->cSGptU05BnQ9MA8)A_Q4rJo zVXMNwI=sWd^o1hf-5p9+j^*aIwxiUdH+Gn{y>H2x^X%?+ZqtJF1840x9F>{S0rO=r*<=FL@=Zy9*_pCYeH~nY}-$X*NcWj&8gT3QS z)73M2B>m0;wCw<)2DOFug&#T8*JNQIWo_vRc43ZRUQSA5``9ydlQ>i$k#b7I({LIHRUp%aP~HEC!d;~7n@6rKUBsUj;t@^C05s0BYn@a(-$t` zeNWvtW%k2EKLdCvLT&5TH$kT2OInFlobBYQQ zywlGASiY?rh_eVIO%?2U!r(gpkfdsvMtICc$;EXqv|QbI-Eyi9y|!nsxoo?Gb7Ol6 zy)rRaZ7wO7-KH_ucS79mMp%hFE8)^(O3v$V#aL3bJ6y)QGVE;CmbP&wab*ELD==~CGOuj;bV2ieY=*5?fI1^JvQ7NlY0;z-w5c)m7X zOw{5yGt2IYL%Ed&+A;rdX)$N?mROKdI`xbW5M7;+S~s1jCed2p zLQ6@H)$x{nf_4l}iOV`%np%qEi%Uzzgp|sG$m5)hm^cM)i^=O|uNM89QC+@hXLccV ztyRiSLeT!C`|+Xy+uL1Tj8YNJwmscMLX8e=!WtI5wD5B`_HurPM~%tjxx86(eLfu4 zZ{tD2IqONWRC{TE4{y8Z&f4KTZ(7`$;>zD{)9K{Iv+8nseSQeOfN+PBldnj4u{S2o zE`P=TpYu2BGY(Np*!K-LZl~(c+IoAJ({tUdl_rCFo{zckU6RTEgtR58Uk8!*;Nojj zIx0~Jb&kU1Z`+EzIEhRRp)PvT8Mn59)e?Epun-`Z^ z3EBrT_^7{4cx1jiTrqFyK_wGT&0@VM0ZuD`NKmZ@EzF->@K{ajOCY~)cYyjC{EVVR z!h1?#Q#e;@dWYreqHfx2xHh-^D=UQpt7}B{294H^<_lmMt1Hn@Foihl7CQdBF57Hk zH1RT}@JOf6`XHRfqg9+`fb+yJ_@;yF$K`CB24ryHP?p@wY>?mL`m9ASx7#!buFs}ql4qz z+q&RGtqh{mv+o`kUwDAaGMuLxTW^_MNa(yB2MeMl%|2PpZJ)(9$klcjJW~5Z;vWvK zw{?Yd>s4zMDFbd>ZtI|BW`;HCt{szG1K+bc(%y#s1$$c-TA`a;<#LCg-oTA5w_U^p z?Ypp(_Kzu8ij4$?3d8>l-LMQ^H=46{W5l(I^_-X6+0w_p7lU;U3T?T~m?vO4q*dao zv?d^D=43nwPAd#w73znt|Mz*KR7)LLe#9GL z0=_=f7yC7rTY5Hl8;E=HLT*Z(V#}Vi^tdm@kDlx(K*tl?Qr8e5Lb4xzKr*v9hsl`} z*Km8ftUu6o*YB!^UMM!1>s=0acU#r4aXf9 zrZ~2~jT7;mXpxvSq1ubn9R9nolGeJB$gs-78Tl)ijx!a-YcH;RS2{qyZo4W$y^pr? z!j_AkYt}BDY_W5u4vvw5V_;nl-K zdSo#QnaN3zr|qwm4dqFz|#|RQ)SXxcHcoi}P*f zO6R%_e^Vs#fndkKw%{&0r|hH6nORIG5+aZflUNC7qWIsS( zjR)V6=VEU>XP}52zuxMqk}KOR9cI96IJsuKJD*MrSP=aftNPyI-xiKC*w1BjyT?a5 z$2(Pyf(i&ooLKfGE6}xk*olc(VcbfmBZuz_#oCbimBLOdeW$r%MdXhLlXWVnUtocs zi}`IU?4sS#N{YWYlGtIOIB*I77C&~}@!j&6;2gvHn!c;#>;dvJg24J(&`~)`)HnLB zPl7iP?Wdkim+}!+7TXfiVt0pEf_?cJc^L}eBVCdI7?@XX7tfnXe|*KEfT4-9z-jhq z{iC;W5aFk1-t!=b%EdbLW#Zdy{?te!>}sAmFNAgFv3xJG5wU$r?Q`S3$aPCeI%AS! z#l3{TjeoeNqNVU)y}o*4=DNhEH?${&oEK6{;*BrI?~shBQuJQLbcXdj1kHlpx~Td@ z*LZNu0@SklAee5@wz`mw}+@fe1^#e7qS#`zd zDqs~^$UQE;xQ_jj_2M)_QH;xR<_sN6Ek*A{OQ;{{FBHzH%sETXdDlurVCv zdP2#?GTCj+U?G+r6;h=*2cCLxm+S3EBIhj^M@sOw#7--X39neW`aH$-h`p%~Aj#U# zVFvYpr8s)gX>0n<9rnH6;G8g%c#FZkrTYg1FflXV4p{l4rx#~5t=tY!Ks1YbG6r^; z;iwjkP73sWhJyJdIzKKZqj^|{I>k~PvV3s;4kiq5i!*)4lOvABk$MaDepdy$VKQS3 zZ5A`0SE*f$o8O!NYH)5#0TGTGDZb;qXkk8^GZJd=F=WT|Kog&3A0JYzI0pfI=974l zzAOLi3NhP{2$lo;sGug?z#hpGS_{z|VueOUw}r^mq$!2_bhLQU!EyXZ9C6r>2oRyN z>c8J6r}3yCT8u+>CmKcl=?nNLGm$CFIb1V&Q;aNB*rrag%#vn1#+SUHZNRi(ul9>IK!a(K}W4o+`T z8zp5%#7D5kAs6S`1NSc=*v8tVVjC%PtD-g5v8Td#=Bjv+3Hbke@Mj59We}^wk)l{@ zZXivjPY!>d+(82EcwI8JMQy@EFfu8EBTjdDXl%9ZK8B&VP7S24w0$+H5w8blKg}gx z6ym(LNS&~w{O=lJA_)5T#3|GuBm1i7s zf(VY;M{?mpQ-H%XeV0)a-|XeNFqye!*4UYVk4e~@8C)g?2dUK`&BaB~h`wT-*kbMv z;V7P-AEh#pSN}fE0vt~VEZQWQgdEx%C$~^z2z2$eEcKJI41I$)ISGFxD7hJ0v9qp= zbu^#67?HgrD{fr0Ai=S#4HU(dKHZ;?dXJKep%5VillRz@?!%MJ(3ALB>yhvGjh@HM z;M8oYgs!kwMa{;eGInHb!yYxdT7oZp9Vt7ufjAk54A!SQdDPNo0he-BHB+>mKuBz^ zuNh(q!nR-Quo%t7?8@)ZKMj#PUSk=#EbOQ5+o?KHOq_IpbaW;y&JYuc;2Ju|z2Hm3gL<>hr)+)RY)Q&ll`{P@li1KXI{ILyeLObTFF7XrV`*t=Ufog5w3h;iYr}>7M_W0t zGrm?Zi=4{LOdR@G(L06XEG#TWNBP9W#4cQD_P_Dm+P|V5?vX5)CP2WR!UoybN9^tG-btKt$NV0Kc4H(OkB$Z%!stJQ2-U0wbD{c4BflfYLmn0V4J zid30gk)C?d4{=aM@m&%tTw$6?+p) z6qFWE`vC*0@EzybgK^=Fb=Ui>`S}U~m4ado`YrGC zS4=j3DW!Dou#u6`bd9<3;~el%;%GVEMKGgGdY{w-}RX+Z^qX&XxHz*s?;_qv=-bj`pMn%Hqw|TPtMG@$&~| zj=bvdZxE^C%NNvXG3k}aQ5F@RxV2pJnPKRJIALzKJ*x0ygmkCSTCel_u?^3QAL66- z64k5tjb9kznHF99S<0HJ{j#K~=~jn%DmN=D>x`)mx@%Oj(c8yIU+FFx?B1UOGjO15YxMb%ixLjkx!|FmAo_#QA zHv9Zn+IFKtFXG2&J}#aZp+n{Zx@aFI_59Pedc*>q@R|iCi_ERzkrvA&!ZAMuu>xMf z5mVcdRrARpqDLSRu?`v;Zb&b<@u1o{D8$@$g{)RovGC#a5;vj8uWwA)|HKLAq}zAy z+%YlX$Pe-I^(8QQa-_YzD(&U%-5-;}K?5G(Jm-D)3Rz*bw3;}+Z;WdqW&ze`2F8-* zc=$azMO*2Eg%hlX-n@BZ?Ok!ICbi~(v9a-tq*#y`Arf67$sVgebz)dEL_NSNK%}!~m2r%t@Ev0rQ@En;a{M@Tj+P_4j=d64f{&Yx8oZs|>HSiRYy`vSG%y zw-q{oDS<%75kB6bWX3C^nPq3sbkV@z_LO6wYLEI=!C%A#LnVT$;&|qu%$W zElSskaiiI(L*B9twikv;v4kUH0S6OqZcDU|P@GdLJ$~PMTrk7A+H<=x*Yc%>8)uB; zoNkRv)~xON5VYDtl<1VqsagGIBW7#=sL&|0Zp}hWRg6G?%%R{yK72pS6izUJVQntR zM3V$K)}M7)P({2j{ewMNm7u4m{HQjj%B zwDQ<9{xCCY&j?kG#LEn7F?I839E_O#1=I>6dMIC;CFaEO zu2zt9sMk)Ta1;^Ud1Gm{A*3hu)2CNzM=E;n!PvRrL>XRB5bjar@w@l%?Y4+rkH{Oc;h>AWIO$Z4x@7KBCn>YKD23%H! zevt1C+gnLIL1%6@IE7tI9Z1tDQ!-XP&0QlA{4#9FEKbZWXP6Mc<=AHRmOh)Q|6=`I zFtu>|%RFniG~rfSfyzb6%owUaY{t5DA3v+K{Ca;R{{&5t(Ua(_?rkrt`h#--t<*=| z2b5DWY$ilFa0S-a*#x;-NI)UbI1bNUqxzM#AUCAl`Y5Adt{xZ#_@ddoJ zVglph3De0zw@MpF)mnjMn6s9(nVOMXIxHB7g-W~xpjmDCU$M*WU7VP3)3ne0FaUgG z(U@wui|ci0sNDMaJCUT@&dzxb6A+Tq&It%KBqEdJyw-AMMky%v#%G$G&YGmryZelD zKYlSxD~?g3ui4IA{65ux=6Z1ZBc%+DvHn1j$moR+SE7TA$~`(sSYicnnzd(!2n4pEz41$%;l zHY|-a34k_X*HWvy-N5kDkzdBy5Rs5JXzXg2u1q=E`OY1rJ1|xe$vmn5;6b7WJ0@n; z@S=SYW|=XS@mkqVGLGuHIxVvEc?0F_nfW56`hR+Zf56=zd37-&zu(uct~$>UhlcJg zr-AP>&kO8uXJc(%F`w;_i5aCyg9Sc#6)5fVPlQZ@GsMMs<2vAO1=UkiF+7Q1>y{v` z{4lvp>hvY4M?_dWb`BO(7L}BgJmT#tJyN0X$j_4`Df8&wd^4@St80NndaaVfZutCg z#j>nI*Y>K6R#_$bmtQK%1a(Uz8f`D+^RWaAo2R|*E6kl$D0%(*^*!D2kPun?{Nh`u zA(t1^^3u~a`qM|s4I9n}uN^+Jc4)bMHlllfS~932E}nQo74EXxlaKn|J2}O5vXffAfZY-TYsA4zcOOA<{3H z#!m6L)c^V=O=|QGH_J3srUxtcZnV5$SmoIuGHq9)sbliLFbI1YgHWFEK9yr%v0}H4(4#@44Ru}g?%0z z&x{t)6CWXF_4nmkSQ$T+`aG1*+CL*-Vn+J&Ciye>!G7A{m+Nda(FsEx4ukdFHvU0Y zDgNU;_(7_K+kT-d{8|i%B6qxw7$ZWb80A@f*c)N>ik}z;H!q-@_Rys^XZ!HsgORbZ zob;udaQz#B+RvAkmH=QLeEW*zM|z+nP$M4tLst04OvlgnGPE+jDxTJXRuRKv0JZP; zGSLaIH75?rr{wyjB|(fB?!3?3o?m&_-CC`msr-P`E$b>z&Eoz*KADt(n3RY+#x*W& z()-1&0 zvgY-5c|zKd>OycwQ(jD-Al(^mmf>o{vn~xw`{>Mj8Xve|%FbFp{%A+2T+>BljokRj z)pgngquxRnYrBY03wP)DVsljD$LQ#|hj+=ndHwpA7GBlSqN67#Mu5{{x94^Sz*j-i z&&=yfJAXB+9T7{I?J#M-!v1RBG6{Pn267Dl{4~K)GcAqE4ng%xO2m34{IZ zz9ka@5@PO{ajA@LG`){aFh1l+Q^Dw{uPbctl`99 zNA(Ncv%W^X<|rc)kkQrTkC|nUE&kGAX7F^NQky7Wj{UM4CNS)>53m`N^w>811d1lPpzOO_sWQADB4ZdM= zNO!?9np-YVRIHH7xQRI~jz3VM(~|!YD-0zO>WX5cb9{WYt7qVg=`#n-tR_-f6Wr?= z&P14qfA&VJ4pq$fxJ6(P$_~wZdV?^t#7l6#c~{Ftp(I0eNQY8kMeOGD$8vdZ z$^XEw42_GPr4B9a>$^J>^*SP=Qtr!da7l>~>cB$OI-Ag7*(@jL{&rLoQ=amrbzo8a z4eODR=v-y1jFgBZ+cvKXV z5UK6@-i#8{#uN9T9;-Gpi3$y(oYd9gK(c>~&_whL;gc@qSvsid$nsOKKVd8^O`FDz z%>YIt#-)#ihcEqI2K_s@2O}lHVKI^_|Fv=d7R_PAWAA80rLK1w1zGBvn6KI|QB=^Md9?W(NBpuyJ<}=_8~fQE+%g=2JE%`H1yHw?O? z=sAd;lBIu}9zp#_Jl1w4UXPndWfwwu&4EO#jc%MH<0LB>%1 zph3jL0Dwy~*O&m0*>@eyvB4%qj16;!R*hgL!W{=nR;B%osF-K6*A>yw@T}|Cub)>J z#!UXMiAj8O72p@$-R9}T)Pf@lwwi;vnrGhe*+uzRMmK-(Q$MP#;A&-cj;B2&x31L) z?*9a=O_{1s^9};etv#5)E+~HiBI{p|Hx+tgf}cD+p<{q#hhV&9(5M5 zx8Be>NN64?w+Do}5*!11{%Alwkl)TA98(>U9-_jO5R~A2f7M=kS(5aLG{_4Uyz+vN zkFR38_wevAIC`Te7!=;#{F|K~BTN5hk9_;p?OsYn_zosS+qdl=!Bf@N)>a&d{qOcuBX!UXr?tf}vAsr8@83znp9t<4zC9tVc^5GLg9xDb7_F5DHtu$)G$jCTc1uhYS z?trDIBz<&6jbk&5%mf_+Lluu*T!!AQTlc8cL6-*PQ!LuJKGgn_)8jvT_AKmeltX4+ zcXmuZ>q^?CG=HuT%GCIBjrx4e`UuZ2mj<_0{{9{PGspipX9Q3!UubYiV+237#xTflmWXGRsM2 z4WkGG&n-Hx1=KoBjBKFL{p$P__?5{@Q3gDPtmaoh?lZn{GR@7+vz;h*{IOwXJCzjc zT}u-H5b4~!UcYjnSnOD>Q|MT&gzU-7E#h<^`E1|i#fYfhK``$=ux-d%w1mCCWPS-S z3I(;Dors2x=$1hsmSkwo^UM{fn>Ic2Pfl>)m%$$mwe=4?`P}N-ef6b%VlfpVW3>v? zH8zI%ZB^DU25t>s4hf2$xuQ|8!(DnpX2t}FpOoZt)bI1owio5i#tiuI+qr@qnz_t6 z^E9JpEOd!ek3aDJmebQL_BKg`BP>qh>?|IyWm6C5T6W=V404rsxNlhancr#hS8e^F z>y$5dd}1PerK4oUyS;_NTC!1>h51Vb0Kn^Z~{Q=UFHSi&xN)(@vj1-pZ`=+S78@{p(mSN z_Xn4rjmW+zM)8mMX*xH=+TA=Fco+SYGck9ytUE7{u^fn^)H;u6sffIG!F+*W5|F5v*WLaw;d>YEszsWokQ&!G4 zGCXjev!7mV>bPOPh>GFHa+8=q=rc)L9J$e>pKj`0&URv^U}lHmeZ6KA@U^44yiK$Z zH#}0XG9@K`ae0biU}=%&hU5ZJUywV6d~&02McMsIDIO2EeBNvMq2#c?|8D&Lrw3hc zUc10$*qrA9!1S}fQ+kG&;Dl^W8s7)DP6(jZ0vQ zH1H>=y=_aaY!6oP^shj+nW%E=a7Dh(Y$$IUGI!gkhSduKo~0%h?MiWHE8YaECnT^r zoDQGhaKF`^@*o|R?TEWreo)-Fj$Z#Afj~_-Uqd=PHHLLTo zA1}$M-Xm$xavSynt>74T-9tip{o}#?Iou(iZX}Lb`5R8ux6EsI)H8~`TlmLDi>N}# ze;OATXY^#8Vou!s^Wf~3{+J($0zORaHxEPB;V@htFnnE3O z&reZk&Q5O_8pKw-4!2PbS5<~R`}zL<9&dV9K4IYy+xol^;JUq`t;W9!Wyl`WCOovxWpH$`r*!gQIUy@Y5uNP!J8!!L9dlW z-Bbx*uTZiR-YUY%0W?iJukO1gkaUv0HSwyQ+c(ITHE8MR=uNp%4eW<6uLBa3y{cSSMM&{;c)^gn|e|sKe`1J8h zLY|KM7x#hs4pt~IwLfT(#t$?We7UD~`KHh3_;Q&V*_od(p!MKWyjZM6sNLMoheIyc z+RMZflyywzJusO)$c8qe41T^{Spo5O}ZS~gk?8baTvye1oJa6o+NEzpktdi z1cvEgdb_tduYT_9$T>(*wh|7JD1Rd;cn3(2rLviey2%Cq*(3&q{U2Lj9#3`t#eEwl%@n2*m0Sr)_Jr(OWJ}7v zgi44)_APErO^PDxwPZ<_>||eWO-W^6F4@bzgzQ}0`<%~L&CKt49)HZd;=6p7^Eu~z z&Uv5nJtrn1LB9FS#p)1GfE6#xjq+#LI$KT9nzL$3+WcRO?xHh2VJnh!@z0~tt@du( zSNUZmVv-^6;VzxLurxwe?@WNmjz?Ov&x=nc`fJh=QrS~H?SL(hPu4ru_IT(ropl)YQ}%1KIGUYkCd4Pdu^J4_S97D$jg<(q9G< ztdZme#+y!3GNil1H7CTxE(V56){2OvUK-afzWNtN75Jf5g3i$k5N@XL8L7L2bx8=egVzv znU=b%FgG_>6tY@waY@xKCD+pE?Ao*n0tUVGM4oZ)Nb~aSOevbGcddwvs<)ZT z=x|R&*&czm*a0yhNY}@8L}7r90PN3-{r42Xy$<@2Ltfp(qjOwc@NdY_!m57UuS!!T zNOEnDmF3Ud9$;J&Hytds(W1@QI<&2>p#e)8OnUC)?MnDvVXW>Cwb2N-7^(?}eIc0A z?`Bz78r4c87M6CoYfoS4v^K7D7~{8Vze(!S*gUkxA5Arh=PwnhabCy|UFa|9cDg&B z82!W``9NheN9e^c=j$%M)<@;1&ju0qYxKU9AOuQzOr~dK|LLS&a?YZ8EKI9wvA572zoWGce!R%KD+kUvMrK+}8wW>eXD zxtT6&C_AFbPdQ8I?-#-Dj;28yNkm9E4wI`FK&kUoUAzH=)$i?^nwrB?tN|y~WE*o# zi?6@>xZl?@!wJ!uYKX-17ht507=L9eDUKiiq@Xj=hz=6NvCdT9kc3a;*OP>5&&$jU zg6T9K4}7XBYkoZFpc>!P^ZX9(y@_1g1S+1rPoE~IFZHOdcXaqi zy|cOwIA*%X_h6Z5SCZIpDV}h zh!HdRHJ;-c>TRdGj)`O`b(ts(tEx)fdYlsG+7#14m^h~pCzhz)BcV#h( zef5CUQhRu#ROurX8sH%Ppd28i+2Vhh+~i~(L>^a7-}4RdC@rIRPX{+SQrA~4i?>kT zPra4R__2~)j#vOfY$YNUYp6^r2j5Au8&3ZaZvp|ajEJ%7^rFYH+}#c;aBu3l=Y+(; z_j@)E+5uw7W|hJlMu+5B0e>BBA~7)@$c{5ji}rg>*`(4)yjw(J#rI!;i0Tp-;t(}I z+Bh0oWe?DJsVrnVIH|h1xp{qS0%5~G_x!=K$zH}abH-%i>^|VWJ7UzmT~x$xHa z<$^%=$5g5wB&WfDL~Ev#kb{_%6P<|4H$QlJGtwbE0KBYhh)|%klX_J(#F-S~3&EbI z6cvg%33ro8@x)xrL?;Sq{U@q{L7U$&e+ETIP*?}90VbYrc9tx*dwZ{wc|gx%e??5; zHy9!3pZLnD^2y#B2-G0zEQ-NU(6%sVBWmA&u9>Nr7THFO3lYI72VB3(nJArkv8+I+p!v2a*|)`3(Ir4#+W) z<<=p9KaAbB{DP(@Ux=bP|3C3_$K3J#dh)LxC~h27Y>@mDDM-PC zWvEKw$vYIY396+l_y|!sASmYGjew#tTGM$J3-fWFDMq|49*mB)dmd*u2jNkJ#tf)Q ziH^5qKeI_N`=b|p<&3nI@*w#LzL6{W(G~WH#iJ=J=QI>G;kgK`^;M&ylb97h(rmi2 zc1B_kmLtE4mrMqElOhEo&dwRx+YqjVNG5FQ{1qbeX?kHH&d-R!DN2Rt)X;NJ$-h@t zR=yEY4*lq)vcJj=s6sGU%-s)6>5;cxN3bxt$Sshxj5jNsq*c;flN>uhAO(VCS~IX{ z^x6Yhg4`hFTH>XhjACu8xsv`^uI>c$HwE|H{f|kANY^7biN;S5HUA{i^9#ndX*oHs zeNJlmRFX$QD@X=}y@3@b8Q-=QV@%2~+TtK~9Szis#;t>V`;| z^Fws5k|XV>|5Ba3o{B{?(@^?-HHr9Do?cWEEebmch|_X#zloutD(9!3o*u~S&TmO3 zjCR;d^5X+S2Aa=f40ttciPY>4Vp165n%-1j@@x^@R3y2hr?6$co`zc=YWlbUkb**wV zXedSl{HU835|vsMqr*dXp-@yN4_XXSmO>Z%_#{GVxYKV>Brd7Se1-h%tBu5Rjx24t=+GItcVLzCc_*#FxRJ$= zl7U`U@AvBNChXg|0<3CVIqI}U(D1lt`^9-ja9$(`5hotO^R1G*A+()euU)zqOicY& zUdI;|mi+Zr)$l;yD`KF9Jjsl3ID(duSQ(dC;Zl66SBh$67@1ok88vBr@0fB2= zcYeF6%sputXiG1%s+<#TG74mI9r+j2Ud4OpXx`6%sp|auh9gfx478INKWRX!Nl{J4&xx}|dQ{WElPk7HlSb`Nog;^S>~?*2yUS#L zUy#$BO>wQB;x(#CAdubm_Je&&s<@<4NwpRNO4 zw?TZN$BS3Q!p%)m#8e6vK2t)4@g6ZrrYL}H?>B$frXxp`Ai#I*!QfLI-ldw6g2d<3?~!N%0WS8QHe$ndvhLb_)s=;yl#V|-YoJRGwskK;^Gh;Vfq;=gJ8fy}{R zVNO5~gp^r*M&(PY5Alr$NGeJq(xqBCN?ha{F+19RQYn0nVlJYfPVa4v_Y#C zKzvIrg)Av{L9Y|`*pb$s zEhwb86EO36VXG@wo_8jQ^S=m&XR9NfLFWFN=)R)d={)m2;8keDZbQj!+(r{){KHMkB^K zjGNPBFIaRw^vD0kCa{Avrf@wKo_{~s@}6jja!{OGi{N2UzvELjymn8KpETKvRv8fQ zXmVW3`RFO4%<8MR%FH$Ou2`n61?r9JHynt05|9RrUqxhgx_N{^dNCN~{q}nb)PtpkzUt^LB9ak4q`iD(@reNdD$oeDv&PJ3A&uYVJd4 z)Ly8@3@7JA$HzNJ8Xmop^o$H}+pH}6nO<2LV8eHVv>Mgxwft>M&e7 z^-0sr_8y4kIyjh{8O@qzfH3q@QY79VdVLgZsJ_KKRBFk2*0kBaYbH~EW%K^H$q{T{=am$75x*vT0vYT7cs=FmbrW|^oU$Q6; z(Rg(o8w5~|22aW4obp%Ez!;5xOaTHaouA^Wruzljk>c*6igBXmU3yN!mtN$Ta>TOm9CsnRBLyj} z;+6EH+qgH1z19*{Y?4~D4@rM2JT7Z={E`JPTS$>wu?%TFc{=0iK=W3tjODp58#Rtp zH?_$f))~{tAvl%ok3$(`RFB~yZzpl=m=m>3nNHU0h{HM1I00(qc9I%i4pEZVt2AOy z?yYA>e7|ACjIxM5W~%v`E#BgiO<1z|cONMAxk1dfrx!h{@l%CAr@aa8ADZ)}f3o1rLF9YLkbCI#M@hJjS2YCLCkKnGp$3FWZ*gAc*5i-0`MPi2@ zD|T>3iT$UvVbq}_PNED#CU_9+IiPcJovvM{%Q z0~|*VxgzPl2vHJZ6Ei01~P{NzfO)4WrS;h@`C*2SvM%^RBkgL>5?mBAk$H z_niF5K|Zm80lTH9RshcL-n~PdB6j^R=mk&}fJ&18;rsKBIUxS=lU7vlf>QKf@Ly6; zVM)4m156CkCk;O<2)GxDF^YbsEr599z^7_o6 z3Z>^1u)zu_6w^!B!-HkD3w~A+TxnCsP9k^JGNR@~wFH#Xp2L?jlFkG6GF0gBkU94-Hu0Nki!jeo6|HiV zxD~<&ebrKY`Tm=ZJdilhRbC|a+m=w1N4_@g{Y6^Hu+5)<;+=0$8|M|5gysIZxYVC`r?Cx=p~rq;@uxXd`NG{m9y{q%10Vy@56uqlzW79DD6;>=@of>WrpKr2WW zq%}TXVXAC}C5_0M_mT?dK*xq`;&1V?_>fVte1FSURg()C-vZE{`sa&5q!Z$Wg7 zi|a@*!4fi0(z%o(Ssy){K1v%k^nG<^^Vsoxu3IwQn|XG2vtTWg`MVxeOTL5}G{o-% z%`sA=4j%}B`XRpho4{+p!j2!b7QY0i&VNvNO+jPrBYwEWVw#cQgV zZ{NA|8FrBP?p#GBR0+Q6KvP1@Carn8m^#ovX>q@$fp;>7l@0y4m>X+ufhv05FX|w7 zMy`qZ=3#7cw`v0UhZw(q7UMSXjk!SCKdRt545gX0b{)@5&d&!>0S|WY{?rAQ&&a5< zITo-uc)=4A;N&J>9mHf}UZ&fy2cHtM2DoD+5&`S|pky*%A_HLq*a1zi1VLF)(M`P++D&ktz}|PTG~lZY@L@LS-(# zN((!&(o+FkK=hAlTrsLHyt@F!VWycEVxefpXk$XhPQG*yNki)CpDicCewO-1Dv}}k zhulj(>RkmVnu(SkX*mUzzxWFOD6r+h$)kE@)K+1BJq;BG{wbHxh>^gEeQkhcS06P6 zp=}nzFV$#RqXrO~i>Xl9D|`~)Bo*QR9ToDf3y$evLUR}wfr4ZiZ>TAVwuM4tJ8%ax z35pbRa!xrEUaA&>)Eei_3(Rl+;AdIlIu}P`odz}smXG6wyDcBgdllVWX0Tv+c z4rPxNYIcE&a5>ixZ@LltE*D}oL`&uqC`QV)Mag7}(?jpR%BGqTz03%IUO+lwm6n2v z&p7sxT`&sRA&g@N%>jGE{*$q9qdsbWSJ-2jcq$RiBdp`#n^tl zU(TXXgT}9(Nyq>@-N)rRLT`Y6R3JWTgf5+*@zlYL9RIC*!oI%asPg;L9c>hUf<_q5 z5xCrGEMJ-PDj(EW9cidu9aH@xub-eoaTS73vO2>NSEy4#RsLtTT&_e_{s>BtYP3-k z4Csll&ffP9(-xvVf>1YW3wT0LTM1RYe}sZ$X;WNDwJ&t7Kxb=XhXw*vfI6gUF7TCA z)EPw-C)Etr={Bm>@Z6FN(;o9y@r@GSddFlCD!j3fIH{_E0-Y{a*|3kXZPBJb0{s{! zp`Qv;=Gt^JlhCbz260ho2V99Kz_A7Bnvp@Nc5MgYr_Q!?uA2J$@q151<}=)3Ujk}hDN?_F?MD6Ut&IpCC|<0>_|AeNtkUAH)5r&r{v{TjZK$yy zMy(j`;|xRLoTG|X!;PwRY=p#*2ADDuFL4z%kKKSl>qRT+p++8nfM8@{bidu%1KO5` z$#zWoL=1t_iBv90tqikJ;w5B&@&gdw)&Ka5Ua#bO6UfN`poatJaSH_yv%$29Y&xpE zhdwL1RE}5l*wn;vlNQj;12&~Vecwy0Wr;$WHz+mfm$QJJAQ^OtYoj1@5R}E^M zupO7p%->FkN1;Kz>DP&_fOJ8dqTrnLdz@rE+)P*>p`mk+ZN5?&YI9Qsr0jJKi_Jn$ znVSy**BD-jfNyjJ&7hn!z#3i#b|sRx-Ipe?INktIu&xycShIje*yDcXJ8G*#XR%qe zD|<5mqVgy{`iXn&qB%R23Oq#wr4P8`Hilu24Y!s+VFN;HwZvPfz&dBl_68g> zNG_}+h-kiDYO_ZP?;W=?sOCp)f*>;T`>_kQ`D8c%(=uyw5O+uY5fqv2@tCl15~3^~?NUmkW`k2%2Jtwona*!L`!Ti8g-eXAa9U+%(?Uk^=r^S_FxuzkDKAJ> zPG|~!&cr(aPx&5>LBk7QFsTryV3~NH*kL-OK!tcd>U0DL5H&b4cWmG6<#6DR!ojxF zzost;Z9tJfD*SCc7Yph}g7B#GAokWnI10JCQ3RDpwV_51?pH3PEoOqG9O-|(U{}|# zVSE--Q$>&H&3-Aq^^m@8i&WDt+WG>mlrl?L&TeFqyR?5&>=%Io z+uL-Mwo=QUERj>1LRgC>z;|+HcH-_-VU~!Gt>6=hDy_KDJrg!vQADXR@B2_rhfBb) z#t}BVc{Jd%`Te$(;{MeR#nJgH9B#8&){#Bk>yz>Gt)z|fHcc5>*h{%_IN}B9YsJ=d z3VY?rob-QQ`77?uX1gqwf~KEu#8=L3z7aeTfqzikwxQUYcj@Orzv6r!)bu0$M^q+Q|d=`+DF)oCt;!EsZ;Lisne$D zx>Y+IZh;$HIYL4`b(Savf4TV2opd-QMQHD~Wu4YtTHY^{;cdRKrqxMYbDAl1KJWDA zr0RvdGryWl1t0R-lFD|Agf7k(>gpKZaru#Xg&Og*Wd-jI zh|M8%dx`eJ^gDpnA}=9bw8*!3tv6ek(?ehehkJb#`drlahJo1U!&-cuqJ#>Nj+RsL`{mzF`1mZTRfM7!)2NggQMyBSaHYuhv^*1^R5?v z-baVKyolX*IAQhYeXp$B;i};$I78Qzsr?g(=(rBI&9ma}JGm}&e-v3V?JFK^S@U6YQ!wlx(UwU3h1wGB-jj8GkreB60rM&1 zLh~QkV1#k^MSsjN)0B)}n6u@2g+Tvp$=TFO;sY;b*Ow1n-6lEM-0WB;@?N1}J^7$lPO2f8YpNelh4o z(DOc+NJRhdGMdDldGtrlWzGbxfBn{~D8zdFDESTL%7Acp_{3$?p81#?gVu8;TkH5M z1&NBio>jEI0eNFD#^pZG^^e|R#t)8C`dTKxwaW@u^hs@Xy7mkG?3-FG=un)) zthiA-sMV*lFvZ^9ndN@&z~19og0a{`mD&0`wFQlI)zeCbIsKY!=K_328Ky6&?WIKZ;2LTD29+tHvq52_^(y^*(CHEx$`lf^ zoU=D#yIxJtTjM>J3rC$Jx40Dd-YZuaCtM$D?)H~TE`0Ch5PL#2vR`WCBoZKzW0zAv z#L-U7Y8SMBj5A@f>n|CtkCm>(MSgw35p;XwooTg6tMTaCOstF}56Qa@K5Pv4i6$&< z1S>x4^-`HV%K~4iw_7v+T;P4nAW#6;wen>+HPGI~yy9e*tIbPyuYps(zu6FXM$vH) z6XNK13muH2OxMoSEwjy>y7;!z-M58yp@9!KGTPe_r`Y0dJ}bEg9qf1UOC!a>o&N|W zk&sQlP1w}l%XV&#GhU$Y&qTCp7OEy^1YQL*q52uz}%yV&R6|V&F0yr zWze$-+q;1pncrAu&3RoXQ)tnokcO>`<#xn6K<>kc3WjYku@lkmR2U#N-Q9j>;uWps@jNBJ0WQmx)O3qEL1WDPqE8;xm+*;t2Dc64m9 zu?m@5g3Mb~7PILcvkflWl5rbpk>G}pL zBs(@}?6%t-MCTyGR@{??S<&w24|V9~{~m8$c+OJLVy2Lns~&;6@c_aB@5B}+^7*{&`OQYt%d87AwFYB|KKEk`#O#UJ z&ZJMMr`k+KpCTN+Y7H=RiVDPjnjU5qM0q8&JLEyjBq|y#s?knM@4!7AkL_5~l5_K( zwKb4%yet~@O9l}e?$KPCb6S^96mM87Tc4LG^Q=b)N(`rT&AYEhy2smkHqby~wYo}< zHB%dHix>}>R?jP=_ms7;tNldea_-n`J&vv_F_C2k{TI&-;^hl1O=kyEWfX7GK(6rz^>_Yz z0=W)m19;d|S)9%d3-}lH^~B;=jUY_JQqzRLbw$GTURp;<%6XQgG(vr^%8&=kJM zbs(=h;3PL04&vw)-u?gX!Qq6jhnaS;njR;^^PaLz($$S171UdivR9_Tj@F4p?GiNn z{s{ng^G1IIEDL%sK-lZmXawk;Idz{qlGODz#_F+Pq*L(b|Gl0&`rANUKg)(V86CPC z3tPIn8#_P(z#RzPdxr)v?iG z?#OOHZlK0_&Vl&>MJ*&VIyNE!S|`R}l&@$8k;g20|9#MI1Epzx6s7kv{-Qa&-1?30qDY?YZx#m0`>{59@q{ZI@x;Z z$KxZ+6&(%C0-1Af#V;u8K0cZT;~Q~Io&9$M52chY_?kEK=`dDOZkh!!=N>_~h~)wf zsX^P}6^$uC5w7cD0DqAf`pf|q`jGK`3+oNQSpj*xK^n3L-XE>9vn4UOW(f=-(G#s;ilSU>kA4t?`HqQR#eeNOC!-_a(>EIq1Q!2=I-xg*BOv_P!GcS}cF>t%l|Pn3@-7k=rK9 z8T|!z%HP++rJGXGg->Wz=$cg(8%ZjgBU9ygB(U#{iyX`y$i7`j8oQr{=_u&5_S*yR z8Nmm!0p7l$D#;`NIUHR2J=O9gewnWzj~^$$ZLts3qHrEP8wXkkX}`N^SN`2*o^V&N z{eZ?2cO!6UX3c!d`5T;6fG=0SM*)1TNqO*}M|0}8!=@%O0E(~&|D&P-^19Lph0KoL zrd4|0Bwk6Q7stmU=yBICo@!}!h543v<+8fD7&R#xOct}2CT3hj_a~&yR0)=ur(=2x z#`x-MpKJiv%P4_=mF*r*m+_6N#I;y3W)(&FFC*Qc!LG6ZB#{MonIY{xaW)@-E;xj{ zdGtU1*o|HX+V+^aF0VT=4m0d@FJd}a=$a9}bxargch+3ta{y{sd>lY=Ryyn$DqIBA zhQ!g(1#qC;d5KLp!kMcLX3KD)62RT49$YgFu9nFAL|vVJpD4d{tAF3mssFBUR$RG8 zW3f3u_h&9s?wA7cvZA@XBn;WWrZKc1RpO*YByU3tmDZm|62XCe8~-1#H-gaOZ?f`2Ae78 zu^6y;iM7dH^CJ!Dg?}CBEvniZ4W^l>lKtaBoPznt;F(UZgf0(BEZ_u20XLgIK0jJS z6AZc}u!*nOt&mSy)`NVAjwZUyXYOV*B4<-|8KZV@+AYpu7rXUy&HdU4LVGgGzxJ1z z{XA8TlYj_>=eqGlY&;xJ>hl)O{Q#eZa^e^aZ4myu`glLAGoGX$_5(vb6P{kxZ0<)` zp~4G)IoSv4o4pe4-Z%ca=uqx6Fh@qs{b*^hi;z`AXC*QkCM%hNTw7(PJ-Vqs- zbnrjwGDf%T{{j(N{ z?U>s5X+fFpV2I+BdET*F0jIiJ)fEttod18{cChm?sWNTsCOC&-*u!LVmf5(Giwr)s z+|#T-{yVS&w<2`zCP%jHA4Ep*vIKZ>o(D|;bAg=V=OW`uE-V!2BJ{01k9*<>is@=@ z^h#@=T*QALw9oULZ(h!r4R|gid**SPPS@AoU#&2nweStpnpG=bqc9OHaP|3>28LS*E2+VTGH z(Kzr0f@6DnZi{RNT zKsNIai-1>#0%izz;w^7o>3E+QgTbjRIVEn0J!J1K!BC-H=l?pUzj1u&S%N8j0}R!; zeR#`$8<^YGFPMbB6q5b#%fXX?mxIGF^4A>hi3{52FVX8)&GBs!o8A!qRz5%yorOH` zzJ~SYaGHy&;>;`-9muq2|L0k|p>b)9jAPQ61ri2yVIgd0^=DVm;QxCe=NGFr>IY7L z1vg~wpru3_rf0rkr?KP5YdPVyR2S>!8U@10UF;$hM7sJ-20$hL$3=WsZh5}sBN!j! z$M?vMHpH&23nMX;301GqrmP6>Kez5D+eoB`zE zdoE2tPWF}e%?+!KS)A6^a2*Qe(;7*M`8H4;K;CB}ayT1YYL>SK47&qa;mawTlv(1w zJRr}lsQ9Z$>=Kr)wOG}WW5UaQmWt^ucPFgR)-bBMsj?Xfaot||>gT+BJJGj&LX1^0 zqedfDbv8k-GBTOl2#+}>xN5(t#E3X3qT}tSZ z3RBC;GzZ;|(4@xDP?`scHTHJ%^mLNPc9(a^Real_t{IF@I3M9PA<09x@V;Qsu-5E{ z8}nV=xmVu4xyLZyE|3%$uj;gWdxvoK+rea=B#$QBk*g898g+BmHD^5_5L9u-SMS4e z=lh|dB*7r%n0+3>F|66#4C7(28F~gzixcF9Qd_y(E4LP}?Ck1|WeE!0i-1!Vd@{ri zefdNQeLIBM^O~NW@QEcToi%(o?@xZbk79%g;rsWu%%dFof5SjBYWMEl`$1Fi(ndZj zKOR5R^WedQ^igNZ!gx>HZ&KsA0vi4dS^nt$*kMN$0t%{}_ac}bA{`xCJ4eGuUU8aJ zVYc<~IN?x#3TV5!%-`2n=SywAj-2=awF!%4ZKva`>^zJ2CmxTtmD<>B4)g?dNWS_z zd@t&{#y`1$?F3P8e-*v$b#sPqSc2AxHUtiF2jlqix@s! z=!wARHBTR`<&<-r8~Ql$m}5srMl7G#*+H3;(06$(&=t%90!XOmCL9#RFQv~}C-&N7s z&(2<}dHntFDIPuF#MNiV9s*QidkY_1Nf07(WzlnMzJ8)3mmaMWp+X1ESz*wlPw17- z9Im!-O!BCUXJIz(6|H`e?rG&&u#{J!;9CeH0e`%9Es5d=4Kbve_iD?@T-QtSI51wG zv$u-a_!??UM`8vplAjsj>(9-qPQ1GdKRpW;pa8lny_X*_vZvRF6x4ow>o?z_c*5QXT&`9}HLba_U8s(@NYs9T*m?Xz5tn?3AGc6Pdq zMp+T%&iEIyq`1&R()gX~CFg!!A&&X4ew+&!7s zh7znK4Ixvz!jq2vpIYJ@55ZX_%fWh;L9)B~jrQ>3Y=&}GBb4j7MxF|Z$<`R0sGejZ zaL9yF zd7xPV*-AXwl$8=@mELH`d1YjuXu#(Hm)PpkmeIBlrjX*u=Zn)v=bCnxN@0o8 zp|z$j1l6U35XgP`KN3gSt}**ET{A+(LPsu;LpGu~#;!I%s_exBJSf55+m#Hkzy(-f*j1 zFTOeYKqYdJB0#qK_@{5qDrZsOs})n*Dc`1RU#RD+Xl}# z--Z3~rijYPUGm8uev&QgId{$84*JdnOGRIys+?!_`kuse<4BToy__pl&r$@ZcJX%o zs?^4C^IWf^)zf$9p!Ey9KVk8pbB}9sSEgjm(o~%G^Qs3%WVVRI(@|0T|H?4PNnuPE zx-o@sJ`j}ssw5_Qu){o@ACFurvD>}h2t&o#SH$@Uf`{SwL#!{p$UP{g^qko#|WrD#l%1``+YP)Ht;Uk=dWgx@X&}F=QHBJrR%G_cd4{)h;CJ ziD&s_i-F!C90I0AJ#rrR_@^}rrG?P?X8vpk9D>EAGX9fzRwb zK|O0iyuHzOWZ&e?K+2`@?uAmB4q!=F8q97#Y;$iSW8hVHp#iJAjx&w2`1YLNC)s!I z2r<)#4s0plB{pZ$a}x}2gQ6FIB^Ui{;G)Xbx;hrH3YW+ppqk?qd}NBL34O!gzrHOU zpCO>FAeVSAPxl-@Eu*?PRTt(*D%6^NNwTfH<6@_mu1xj5XdvrHX$v=U;4|vsR-YPQ zS)JK8art5Ujo!hbtryEq0PdHUt%z6Z{pJVuFe#wBKqMW4hNmJ3V$2ohyNvnLw zz@MWeOWEx*r+nT_F;$iHPd@N7b@5jrmxPVxUkAffI0nYk%E}W0OFAyO_8PM#E2kBz zq14d6Y&wAR6zkFI;&5cq`^_r73YolKl2!0{e1m33{pg2}hnN)RKOppx)j@v56@IAZ zc?03GDkl=sQ~|flM#FE05)IMEFCO5saetcB>vdGjqn=hzT7v>1M;o3TeTi0OX(#U(v@xA(p+#d(4x1>FneR>pyXq=m%YDgT zg=6>v&oSMJ<9<d;i5HKfcN`S0V$({#y0!OQ{4jOpD7gDD$?4?8Z_-IABqC+qR!k;y1u zT4niI9l+*1Nr27~PxRR9_V2oAEyi+%bza)()x&%7ii9fLn~V=s0W+pMgbr9uj`fBuK4P))yspv%@yDlRyZth=nor!AM>wcej2;zJAi z)t3?E+v$K+{ou=+pL3sg3DA6c-!dy+lEBNl2}*5TZl9XG{Ac@#d+G8Y35_<62Hod< z^qdcfma6gD`LK{5g&fj(p|7|U^_*F)+@gJoj*hN$yrygTg5W^J`2Z zZVQ5(qr)81Uh$|vbCFEWFmTohSRnVXLyf&Y19V`Lis$AFIN?#K;WXCt9JC9x>mhF) z-|qw(%cVMV%O4;A)RvoweB|<1skqJge0-AATb3YYx#UuEP-5@CZX0*D?RHwAI|8VS zr`I5N9re}#K8&ek0*nKrb#YaqNHskNK|M`4qaoR2h%&SI3+ZsG$1??=GFvrsJ)x|L z%9i(-)&N9JHhg!wjX|)hTbZkE%K4I#U9&-V!+|Y~g_g25K8ez=*e7<^@9+Mtb|C%Jt=*5$-ANscy;+2anGM8igmzM+yDY+cXFY z0d7m<@t@pvYPCK6Ypyk%iR~OV;?F-)^fzt_)xqry+S#c0NyL0?>o<@c=UbTE)AKK*BJ@;jis`z%Qyxj2m+JL<+ zKgkyq(Vbr*FHf+mCHejoB}}MbJ?e#ou)}Zfx=srTUsvieb1uWI>{v2BiIq~~j|oYlxui?Yu0nJQU= zqx{{(v8{!x4xJ5u1~yHX7Dm%%!jl{_a=JK*d@H8n2<6;@VD7p)Qwd%p#k8!wtzi?F zH`Yc7>+y_}{I4?LL#^?O{ld)&rXNma^<7r5iW`0apu_RI7m=`64ZVPKec zPs6|by1Tp7&G;b7p~=dYa9yD+G@nJYj5{pMm#-WqbtzVjKA)GRIiNEuL29U63CK4g z%*|-^q=XSbp^kJ!)zE?nGe+(s!8B8}++w!#`_aX}rqQTDG;7L&Ir>-iOM#&sz_Hj-{y8U)UvY zstURH`?yor7#1J-pSZ{V{y<$pSOy_huRJ5#rkPJuR$uEy>_F1uBg&~{50=K&h4I!! zWqobympT?!NK@9)woS!#pBvBkb;IldQbLE-GnU+~IuS+Vq!4UNx(ctC(=-$BC&; zg@%TbCG(F?C-(OC=K3g1#H0fz%HiySIH=y^%kWXk|NdNd)6kmTyEa8oG{sM-`IW6S zL|naVep*}Ze7r(zaZH|NYzOj*QyZPHGghAf4Ny4q`n3|->D%YLbj#)GUOf#Vj^~v0 zhvF|Sn2g%{t~cfL1YrMy z^Lg`R&H@?L(n>W z@XVNgKh5%GR{{2kl;3>kN(rrP9 zrov;a_5%8=(ri&{eV>*rQw_+BY}TVpv2~obu5Z@vMaV&d*%c!)#dc!i^#>t203O~RU8P7DPDJH3$QnD(jYP8qlC+dA<`Wacnn(zo zdKqXGd-d%DMsl%uVZf;qJ`@+SLi~2a0di3^cf#|choS9$u@b*p1cvHQsZq<7%bWb% zYAU`mrYzasi(>fp%{g1Ed3wJsS_C(hNLj%bzUtdID(xfRT%3_Temo33S8&&Cz%^4q zu9+i0K5LaDJnNV$`--6YZ1*;oEvv+(e8VE(k zV0)!{90R@6lI^T|Jp%95ameM3#b0JxR4$6kt7F;=Ian_U4C zn*UDd*Y=-IhBlbB1#89+U~tcunORQmck&w^Y9IAd|t zh;IAH!&5I`DTcV*-;7q&#z(jnW{s49gm|@3a`P4ZDJKi#3KW{_lERH`GpjWH1#H~8 zr7GUEnb}=9kbAFj^+Csl7|>k>vZs7v@|W_wa{i*4Ide*;1@%z+co&013ka6>b`C!m z2gWuvCwo+xK_k4QCWm!ZK{j?E7=e*)!6U3!6n>bDuV24{|A4*DqMZokw!tx0Cw$jE z7VTQ>Yf5L5TkHp=nL>=yb6O;ZQaDX|v_$)-F%|>#QUbGaj1VI3(Lu}vpTdLR@E>2~hq?6LEk>9anhc2hF zR&d=;rCji8CNf-J!pQc7J*64Wky%If1>`n`HU#%R#h>4BE{H2A>r7g_Soiq5sy~R3 zl+#;w@D~UNZtZN8=6HTWHCaK~hY?B9U-;+t@v>K~nn@j*ep$NgJk`H8-WCgu>ZcC& zMJ(NpfR=|@Bk==b?!GE0UGA?CvAI|dr~GR`K@`?!er21g!<>~kCc~*?($Y~ezM|sq zxNPbjKbRNX4tJ~YTC}BR4|f~Q@De0gWAr9!1?+FP-_xBiwPI{gWnBiHu3#}K)Yj4I zm3{nPo0d)74?sL2U=AAH;D&$A5Zl_Ek1!Os|BrYb@4c-pXCK*r(Fh`jLDrymCMG9i z_U#tEabIN^;w9Ndoe*t>Kv!d|tU+Na^LQiSs3kW?zO7)=ZoM^qE6o8_YP-VuL$S$K z4Fzi`7|L?bWn#ga94A$2&u?H7Ihg+Yc6l2gmGO)o7y11bBO=Ep)g~ER_62ds>dX7f zj3re)Zj0P>?AdB=c9>~QLCk1N=wE$Kt}ojrTP#OYIQyM^?js~~D(I-a!x zeG0ANao5oga}P7|AHdNi8PfyXNILU(t0b?t$f8d$;F>$1KwfZfLf(XQ0cO(*-as+w1>Ung8|A0;jPSYBudwhk66%jX;L z(dKup>T>)~n5`a=(TqHvsifLzl_P%{Ao&D_~xrnp*BLdv&o?qUI}TQ1KT>toB16 z#5Mi+01oR)qKlf|U}npnkttu%WxA-v--c$gP2TB5pDvfps+;wg%zZo{Oz7(E?QyS! zaMjw}gm{D3jguUNxwxw<=zHt`{mH*U9LP&p5BxNj>H)`oXxLM63E`6*SS*j}p3;i( zXDDWCG`N*Qp^Pvwsq&>4ohvVv?O+__0Z7y9#XbIE>U`x`M(p?l13kkgH6*cTh6@~Tq$^W)W(36BV9p+Q5>rIBw1c~8 zFjJ`8&E?OdE0y*hpOai;C?8xet8}GwmArx#MWGHdd~oGCm>a}w^|=|I?9uj>1u#mK z?6v1li=rfc85|%~2W)4|x?Y%Yk8gZM8Fz+~|GRx8cQvjOMF{F~$wGCPo;i=yp~c3qLl2|BOEdI{J>S z2dXbXDj^1CA?jFyl99U5kwbLwiZgL!O9g)XA0M!c6#BaRf9H>jGz}lfd$%6w&%%6A zm>*w|t}Pc4*MG4z_l8AtO_E2ZzP6m9B``6x|3CKXg$cDddDLAOGE9!>&EXEzo?wvH zkm(51xSFZ66&QYO*60~FknW~wUGlmGaZ{A0`{yzNscu9_ zqkKkOo{S+QQ}8T~L#ql9rFE$@OXC3~;rH1K4pc11dUueXjicoM)OF@jOkX48x5Hw<`v}i?Cz!ecuiO3=x9YqnXV2M`ZQl$ebwpb$wf-+PMajOclV-?#G z5W-q?46+F&vSS$#!aVN{c3RFE{^&WC&+og-yWM+#&$Y%q+G^lu42$Nxwz)Rg;_(fT z7L9v@YNWTH;Ra%h0Z$n_R8m{6)1L@!!mXBVCfS1?J{G*vWkk=8xiLB3Bt_a@$DK0OZ|YswvtY{3 z>e2x@0(-&LZ>^%Y3mn<|4bMGjIy66W_kL`9vcqw1aq!5B@2J1w@AXSF9L*S;Bv| z;*9h`HCI<}>lyp?ielFwk(8a(*Iki_PHw_piS$qv*T^tH-dA<`3OnkebCXQl%sI7Psoh!Co}T{EOwHE3=3eS+l5*(tTZanf?- z!4$)rPj~0=qqho{vMvKz=yOqnrXZk@Q4ng~d6OF|0X%ejrY&Y)Gsf49hSFMgTuGA` z3SMc&HKO|kVWHS6W55N?tFh-iBFz)p=ukfj;6?x)>fd6A^*?R+N_rcu22nC$z6oFv zVivQv8z)T#ByQy_^I+K5uH)2ZeM4$-4QugkJVDOn|4(}mt&At3Pnmemt2OCgqNpJQ z$fk!F6Tu))7Y3%le&P0@c%A-k@FLs%<^`SYCy3Jnm_ltPFoj;E@99cy9%8sgnfUM+ zJ#lXuP#FLQ(u*}*BO_|k~HFhVipIp0DjqXQNl5 zEx)_QcQDk(IYl%#+E*aWf5p`^Jy%}wxi3Bf42eja2`yS1DilGgD4W(Yw_t|u(Abz- z-?`(}VUhW70zm1Rr!Y>2hgA@c`e3IM^9{qD3AWMTRTyi8qjH&E0@y}ZNR&pN&^JKq z6-@{o->_#Go0&j#Gr%V4nU`o#;jROLpUM9oq)@>egu-MUPg7Fn=*5|<@7gi4N#kp^ zBqPabr#LYcC{-Bz&VTcY%J^|>ndKOrt0mU18bYGjjb+;MFIm@T1Fo}+7X4Xzq>4M$ zNciUVw8zi6GS9_jb7G6a@F zZIEJQ$;Oe)lDkd^4T*i$@NQ)@2GI;!oj8}&ZJJjZOy1jc0k4tTuWq^|?Rw7DH%-~BZrJBkYXC#Y zmKpnH7>2cP1a&t8fnE(9!wkp7(-NYASpz;YMk~m5Jf{HX-Y{_~vEdCK0j$Z>#%JE@ zd2spd(3{Wmewv`t+MUbh>$tnO(a=1e`zgRo6lVn%tEEnTFw+4HwzKY(z!2RS*O-PO(%cgC5EGT@B-Xaf^wy^2KCpza7fyD!Pyso!uWIiG;XrAQ9 zx;q#WT>TW=Z6KZm!eX8C5lf!iP2n$>0XHlnAe|a$Ug|0BYqJ0j?=T#`#3zoohYxyN zkGOp2cU=DVqa%UlF>t+IZHee+HldhD7Usv3H0`A6HGs2=hX5QU~MpuQZ~p+Wmq+Jiqce($6QfKx>5xjcb_wUF=F1GYA8e}zXx zT5!?IU$w$-!MaF&^w5dauO$Jvc!x&EY|;-E|KK~htR^uJ#9~dy-*T$iibuZeTXn`o zmzeX+iTTqa33NU5Q6-A9HlU3@S-g-O8t&w!GTU-|?A0Zyq=7q?Keq9Qr#eyXajlHO z&EH|`_=HtR0%BK7;KOB+e)P6@vz^9ZK62okA%zAHVvK9nB(v-R8e?>IjPmw8f-6257 zVv$3s5z-=&*Zvloa=}MFUNb|JJmLbQZg^?DdMH1z5BeRHM1nC#G(w!n%Ec@*n%8IA zR(SO)Wt60R>UnY>l2DO6OOJiIfUig%V)DTn@)Oxa^?Dq zkAIunE}q9hxiBwlWv`6Vwab^4 z%cyI5MiH~=WhBZ3<=aem>^xjE z{C!wfY9`h<#_w$qvIl2+u4ctkvy60uR5vc?ELsFDl0d1FL4ZIMeZ=9)mF&YaVyl*C z$YAB9_n^ylKz6I3&e9DIS-)dE(u;ZCU}_wjd^7n%5_3RDhsk-{neyYlIh;uk0FkCe zb&|a8#fQvF^=8OIPz_!V*a-hPHI4U`KN2t!r?s+P^Yy)^d7a*i*w?3|+Un{a%DMre z!V}!5vks+s-q>i(=d9)aJM4|g#XDsLXTvl<+r%lIgD}@fDyE%YmB+meu7LGisr-mJ zoT*=E7A6Vz_+SWg0rWkc$kA^o$*XnCz8)Hin{hN#ZJw$`31mQ8)8_T0<%I~hv617K zLJC)6wL5lr|C0D`>6sR;!3;+`N?~~AHA+Z^rW|=Ze3O*U1uD_Tfxi9WiCN#U;h7oo zkBZwReYIZDcv1z8RMKdzh2o4#9j{OB(0tc6?uLv68E@8$0H|!Krl?bqR+eD?_uo6* z^gU`1@=@iFnOIIxx@-FUeiUsdq3O>SEBIPVO7oADR8vQ8vNzyNbt#C=Y-Lav_ATJ(6vkxKy0pJ zz4a@_+UiSJVe>=%eFmsV&O97<_!HuFnMyf2QeTx5TEFIC&%tE|%-L=7S7BlFkPvjC z(^>=+P>CH_wCr=!Dy@%EN5CNucD3KF!bSm<-u-WqKV@StNrD2ejwz|5L@LNkI&#XS zOC}snS3ZM!0&*2f(qW=as=@pr(vGE{HW)n(x;t?2Bso}))idCeei9|v99`aZxDjhG z+Aqj9x>JP`6OeN+0v2x8$)vTn$#7vX7Bdo(ebm3V<2r_RQdqj%s15oSv+I_|D=a6c zMpDD*|0LAw(QH5c zZ}(=l8OV-%aVsKqKEPUCQbTmV-PY5j%s^<&C$ZL5ZBK6uc_)@73)9{-JC!6Rlf)kI z4l3#X6#paGefj-QsS~MF1e3pYx7v-4izuyJ%J4=dMjSbkX*hNYsEFcEnwA9548*uX zcwmQPT8W~h`34HXa7iPtf0jS4cK-c~Ii*gy4&4#{IhS!nO+)n45`#H(r2}*rb{OZb z_M$6D1f;7ZNe=cldX<7hpBMqFSKKxV_5S%@7kQ^$M9Sz%`+O<{Cb)G$Vwv(oB{a=Q z!-Wm{rOMt%$1!yAkfPVm*tGQ2f&IWKB(|}2T-s|(#Otq z1N?(2i|W|b5BQ$Ic$H)GsF!g#NnV@hzYQL_2xF;%#Xa2h!|tshp?m-8m#^qD*FXF$ zs?Na515P5uzR=kDZh;?F!abmA$bm99qjp~mSndC9OR~S3lu8=!K1qKyw0q;;xG7Y) zRKrMP+^7_XpVdeTz2lqA{z9 zGewilzHNDb%MOlkFBD<;QxE#Jp33kon-83Q*-~&Tl|le zs_J@SjUmpoM*oKMELKp^AW@eL$EN>j^e>;iZI-B;<7*Ug^<8c0wQA{bw{Q1}(NE>? vQup8m^M+NDp_}aCQNzvQSQpg}tB1AMl`UV|r)M8PZ&>c+y7b0kzoY*JHJl%4 From d35fedd8bbc2019af604317cadcff53621d481b5 Mon Sep 17 00:00:00 2001 From: Harman Thind <63820404+hathin@users.noreply.github.com> Date: Thu, 28 Jul 2022 01:23:34 -0700 Subject: [PATCH 089/109] error state update @tiaraquan FYI --- .../windows-autopatch/prepare/windows-autopatch-fix-issues.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md index 13b48f4d5d..4e430a1b6d 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md @@ -25,7 +25,7 @@ For each check, the tool will report one of four possible results: | Ready | No action is required before completing enrollment. | | Advisory | Follow the steps in the tool or this article for the best experience with enrollment and for users.

    You can complete enrollment, but you must fix these issues before you deploy your first device. | | Not ready | You must fix these issues before enrollment. You won’t be able to enroll into Windows Autopatch if you don't fix these issues. Follow the steps in the tool or this article to resolve them. | -| Error | The Azure Active Directory (AD) role you're using doesn't have sufficient permissions to run this check. | +| Error | The Azure Active Directory (AD) role you're using doesn't have sufficient permission to run this check or your tenant is not properly licensed for Microsoft Intune. | > [!NOTE] > The results reported by this tool reflect the status of your settings only at the time that you ran it. If you make changes later to policies in Microsoft Intune, Azure Active Directory (AD), or Microsoft 365, items that were "Ready" can become "Not ready". To avoid problems with Windows Autopatch operations, review the specific settings described in this article before you change any policies. From f558227ff4453a8dae29cf1b83079d2729c04243 Mon Sep 17 00:00:00 2001 From: Aaron Czechowski Date: Thu, 28 Jul 2022 10:48:05 -0400 Subject: [PATCH 090/109] Update windows/deployment/update/waas-wu-settings.md Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- windows/deployment/update/waas-wu-settings.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/update/waas-wu-settings.md b/windows/deployment/update/waas-wu-settings.md index fd23bbc902..4604ac1c8e 100644 --- a/windows/deployment/update/waas-wu-settings.md +++ b/windows/deployment/update/waas-wu-settings.md @@ -100,7 +100,7 @@ By enabling the Group Policy setting under **Computer Configuration\Administrati Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like Microsoft Update, the Microsoft Store, or the Microsoft Store for Business. -Use **Computer Configuration\Administrative Templates\Windows Components\Windows update\Do not connect to any Windows Update Internet locations** to enable this policy. When enabled, this policy will disable the functionality described above, and may cause connection to public services such as the Microsoft Store, Microsoft Store for Business, Windows Update for Business and Delivery Optimization to stop working. +Use **Computer Configuration\Administrative Templates\Windows Components\Windows update\Do not connect to any Windows Update Internet locations** to enable this policy. When enabled, this policy will disable the functionality described above, and may cause connection to public services such as the Microsoft Store, Microsoft Store for Business, Windows Update for Business, and Delivery Optimization to stop working. >[!NOTE] >This policy applies only when the device is configured to connect to an intranet update service using the "Specify intranet Microsoft update service location" policy. From a9265b070ae630a37f1a47e3f4cb0ce8ee9bcfad Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Thu, 28 Jul 2022 08:04:12 -0700 Subject: [PATCH 091/109] Being nit-picky. --- .../windows-autopatch-device-registration-overview.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index 38189a3bfc..a0194753bf 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -72,7 +72,7 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 3. **Pro Workstation** 5. If the device meets the operating system requirements, Windows Autopatch checks whether the device is either: 1. **Only managed by Intune** - 1. If the device is only managed by Intune, the device is marked as **passed all prerequisites**. + 1. If the device is only managed by Intune, the device is marked as **Passed all prerequisites**. 2. **Co-managed by both Configuration Manager and Intune** 1. If the device is co-managed by both Configuration Manager and Intune, an additional prerequisite check is evaluated to determine if the device satisfies the co-management-enabled workloads required by Windows Autopatch to manage devices in a co-managed state. 1. The required co-management workloads evaluated in this step are: @@ -93,7 +93,7 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 1. This group has all devices managed by Windows Autopatch. 2. **Modern Workplace Devices Dynamic - Windows 10** 1. This group has all devices managed by Windows Autopatch and that have Windows 10 installed. - 3. M**odern Workplace Devices Dynamic - Windows 11** + 3. **Modern Workplace Devices Dynamic - Windows 11** 1. This group has all devices managed by Windows Autopatch and that have Windows 11 installed. 4. **Modern Workplace Devices - Virtual Machine** 1. This group has all virtual devices managed by Windows Autopatch. @@ -103,8 +103,8 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 3. The Azure AD device ID of the device successfully registered is added into the Microsoft Cloud Managed Desktop Extension’s allowlist. Windows Autopatch installs the Microsoft Cloud Managed Desktop Extension agent once devices are registered, so the agent can communicate back to the Microsoft Cloud Managed Desktop Extension service. 1. The agent is the **Modern Workplace - Autopatch Client setup** PowerShell script that was created during the Windows Autopatch tenant enrollment process. The script is executed once devices are successfully registered into the Windows Autopatch service. 9. IT admins review the device registration status in both the **Ready** and **Not ready** tabs. - 1. If the device was successfully registered, it shows up in the **Ready** tab. - 2. If not, in the **Not ready** tab. + 1. If the device was successfully registered, the device shows up in the **Ready** tab. + 2. If not, the device shows up in the **Not ready** tab. 10. This is the end of the Windows Autopatch device registration workflow. ## Detailed prerequisite check workflow diagram From 8dcc4b2adc9de0ad95a0973ec07c507149ef383d Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Thu, 28 Jul 2022 13:19:42 -0400 Subject: [PATCH 092/109] Update BC --- windows/security/breadcrumb/toc.yml | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/windows/security/breadcrumb/toc.yml b/windows/security/breadcrumb/toc.yml index c7cf229b3f..56a1f207bc 100644 --- a/windows/security/breadcrumb/toc.yml +++ b/windows/security/breadcrumb/toc.yml @@ -6,7 +6,11 @@ items: - name: Windows tocHref: /windows/ topicHref: /windows/resources/ - items: - - name: User security - tocHref: /windows-server/security/credentials-protection-and-management/ - topicHref: /windows/security/identity + items: + - name: Security + tocHref: /windows/security/ + topicHref: /windows/security/ + items: + - name: User security + tocHref: /windows-server/security/credentials-protection-and-management/ + topicHref: /windows/security/identity From 9833d8552467c14a363c206482b13da94c7944e1 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Thu, 28 Jul 2022 12:16:35 -0700 Subject: [PATCH 093/109] Added hyperlink on how to clean up stale AD device records. --- .../deploy/windows-autopatch-device-registration-overview.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index a0194753bf..cf47404f87 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -59,7 +59,7 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service. 2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Azure AD device attributes gathered and saved to its memory in **step 3a**. 1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the **Prerequisite failed** status, then added to the **Not ready** tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune. - 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with anymore. To remediate, clean up any stale Azure AD device records from your tenant. + 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with anymore. To remediate, [clean up any stale Azure AD device records from your tenant](/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices#clean-up-dual-state-of-hybrid-azure-ad-joined-and-azure-registered-devices-in-your-azure-ad-tenant). 3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days. 3. **If the device is a Windows device or not**. 1. If it’s a Windows device, Windows Autopatch evaluates the following requirements: From 990bb42d449203eeecda2c72255244c4154c7d76 Mon Sep 17 00:00:00 2001 From: itsrlyAria <82474610+itsrlyAria@users.noreply.github.com> Date: Thu, 28 Jul 2022 23:46:20 -0700 Subject: [PATCH 094/109] Update policy-csp-update.md Added a detail about the policy behavior with respect to scan time. --- windows/client-management/mdm/policy-csp-update.md | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/windows/client-management/mdm/policy-csp-update.md b/windows/client-management/mdm/policy-csp-update.md index 69a315b2b4..aff7ce985b 100644 --- a/windows/client-management/mdm/policy-csp-update.md +++ b/windows/client-management/mdm/policy-csp-update.md @@ -3253,10 +3253,7 @@ The table below shows the applicability of Windows: -> [!NOTE] -> This policy is available on Windows 10 Pro, Windows 10 Enterprise, and Windows 10 Education. - -Enables the IT admin to schedule the time of the update installation. +Enables the IT admin to schedule the time of the update installation. Noting that there is a +/- 30 minute window to allow for higher success rates of installation. The supported data type is an integer. From eca3e156cbc3d33eadddead0e7b505c3abe6b4e2 Mon Sep 17 00:00:00 2001 From: Salman Hossain Saif Date: Fri, 29 Jul 2022 15:26:00 +0600 Subject: [PATCH 095/109] Update overview-of-threat-mitigations-in-windows-10.md Updated the file with a cleaner phrase on line 61. Regarding the issue: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/10490 --- .../overview-of-threat-mitigations-in-windows-10.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md b/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md index 436d94ab00..b4ab4b2171 100644 --- a/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md +++ b/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md @@ -58,7 +58,7 @@ Windows 10 mitigations that you can configure are listed in the following two ta | **Credential Guard**
    helps keep attackers
    from gaining access through
    Pass-the-Hash or
    Pass-the-Ticket attacks | Credential Guard uses virtualization-based security to isolate secrets, such as NTLM password hashes and Kerberos Ticket Granting Tickets, so that only privileged system software can access them.
    Credential Guard is included in Windows 10 Enterprise and Windows Server 2016.

    **More information**: [Protect derived domain credentials with Credential Guard](/windows/access-protection/credential-guard/credential-guard) | | **Enterprise certificate pinning**
    helps prevent
    man-in-the-middle attacks
    that use PKI | Enterprise certificate pinning enables you to protect your internal domain names from chaining to unwanted certificates or to fraudulently issued certificates. With enterprise certificate pinning, you can "pin" (associate) an X.509 certificate and its public key to its Certification Authority, either root or leaf.

    **More information**: [Enterprise Certificate Pinning](/windows/access-protection/enterprise-certificate-pinning) | | **Device Guard**
    helps keep a device
    from running malware or
    other untrusted apps | Device Guard includes a Code Integrity policy that you create; an allowlist of trusted apps—the only apps allowed to run in your organization. Device Guard also includes a powerful system mitigation called hypervisor-protected code integrity (HVCI), which uses virtualization-based security (VBS) to protect Windows' kernel-mode code integrity validation process. HVCI has specific hardware requirements, and works with Code Integrity policies to help stop attacks even if they gain access to the kernel.
    Device Guard is included in Windows 10 Enterprise and Windows Server 2016.

    **More information**: [Introduction to Device Guard](/windows/device-security/device-guard/introduction-to-device-guard-virtualization-based-security-and-code-integrity-policies) | -| **Microsoft Defender Antivirus**,
    which helps keep devices
    free of viruses and other
    malware | Windows 10 includes Microsoft Defender Antivirus, a robust inbox anti-malware solution. Microsoft Defender Antivirus has been improved to a considerable extent since it was introduced in Windows 8.

    **More information**: [Microsoft Defender Antivirus](#microsoft-defender-antivirus), later in this topic | +| **Microsoft Defender Antivirus**,
    which helps keep devices
    free of viruses and other
    malware | Windows 10 includes Microsoft Defender Antivirus, a robust inbox anti-malware solution. Microsoft Defender Antivirus has been improved significantly since it was introduced in Windows 8.

    **More information**: [Microsoft Defender Antivirus](#microsoft-defender-antivirus), later in this topic | | **Blocking of untrusted fonts**
    helps prevent fonts
    from being used in
    elevation-of-privilege attacks | Block Untrusted Fonts is a setting that allows you to prevent users from loading fonts that are "untrusted" onto your network, which can mitigate elevation-of-privilege attacks associated with the parsing of font files. However, as of Windows 10, version 1703, this mitigation is less important, because font parsing is isolated in an [AppContainer sandbox](/windows/win32/secauthz/appcontainer-isolation) (for a list describing this and other kernel pool protections, see [Kernel pool protections](#kernel-pool-protections), later in this topic).

    **More information**: [Block untrusted fonts in an enterprise](/windows/threat-protection/block-untrusted-fonts-in-enterprise) | | **Memory protections**
    help prevent malware
    from using memory manipulation
    techniques such as buffer
    overruns | These mitigations, listed in [Table 2](#table-2), help to protect against memory-based attacks, where malware or other code manipulates memory to gain control of a system (for example, malware that attempts to use buffer overruns to inject malicious executable code into memory. Note:
    A subset of apps will not be able to run if some of these mitigations are set to their most restrictive settings. Testing can help you maximize protection while still allowing these apps to run.

    **More information**: [Table 2](#table-2), later in this topic | | **UEFI Secure Boot**
    helps protect
    the platform from
    boot kits and rootkits | Unified Extensible Firmware Interface (UEFI) Secure Boot is a security standard for firmware built in to PCs by manufacturers beginning with Windows 8. It helps to protect the boot process and firmware against tampering, such as from a physically present attacker or from forms of malware that run early in the boot process or in kernel after startup.

    **More information**: [UEFI and Secure Boot](/windows/device-security/bitlocker/bitlocker-countermeasures#uefi-and-secure-boot)
    | From 50be04dc5eb2f78fc4a4825c270d7aa4a4439d68 Mon Sep 17 00:00:00 2001 From: Andre Della Monica Date: Fri, 29 Jul 2022 08:19:21 -0500 Subject: [PATCH 096/109] Latest updates --- ...windows-autopatch-device-registration-overview.md | 12 ++++++------ .../deploy/windows-autopatch-register-devices.md | 2 +- .../prepare/windows-autopatch-prerequisites.md | 9 +++++---- 3 files changed, 12 insertions(+), 11 deletions(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index cf47404f87..a4df2a5a86 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -59,7 +59,7 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service. 2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Azure AD device attributes gathered and saved to its memory in **step 3a**. 1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the **Prerequisite failed** status, then added to the **Not ready** tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune. - 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with anymore. To remediate, [clean up any stale Azure AD device records from your tenant](/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices#clean-up-dual-state-of-hybrid-azure-ad-joined-and-azure-registered-devices-in-your-azure-ad-tenant). + 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with it anymore. To remediate, [clean up any stale Azure AD device records from your tenant](/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices#clean-up-dual-state-of-hybrid-azure-ad-joined-and-azure-registered-devices-in-your-azure-ad-tenant). 3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days. 3. **If the device is a Windows device or not**. 1. If it’s a Windows device, Windows Autopatch evaluates the following requirements: @@ -85,17 +85,17 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 2. If the Windows Autopatch tenant’s existing managed device size is **>200**, the deployment ring assignment will be **First (1%)**, **Fast (9%)**, remaining devices go to the **Broad ring (90%)**. 6. Once the deployment ring calculation is done, Windows Autopatch assigns devices to one of the following deployment ring groups: 1. **Modern Workplace Devices-Windows Autopatch-First** - 1. The Windows Autopatch device registration process doesn’t automatically assign devices to the Test ring represented by the Azure AD group (Modern Workplace Devices-Windows Autopatch-First). It’s important that you assign devices to the Test ring to validate the update deployments before the updates are deployed to a broader population of devices. + 1. The Windows Autopatch device registration process doesn’t automatically assign devices to the Test ring represented by the Azure AD group (Modern Workplace Devices-Windows Autopatch-Test). It’s important that you assign devices to the Test ring to validate the update deployments before the updates are deployed to a broader population of devices. 2. **Modern Workplace Devices-Windows Autopatch-Fast** 3. **Modern Workplace Devices-Windows Autopatch-Broad** -7. Windows Autopatch also assigns devices to the following Azure AD groups: +7. Windows Autopatch also assigns devices to the following Azure AD groups when certain conditions apply: 1. **Modern Workplace Devices - All** 1. This group has all devices managed by Windows Autopatch. - 2. **Modern Workplace Devices Dynamic - Windows 10** + 2. When registering Windows 10 devices - **Modern Workplace Devices Dynamic - Windows 10** 1. This group has all devices managed by Windows Autopatch and that have Windows 10 installed. - 3. **Modern Workplace Devices Dynamic - Windows 11** + 3. When registering Windows 11 devices - **Modern Workplace Devices Dynamic - Windows 11** 1. This group has all devices managed by Windows Autopatch and that have Windows 11 installed. - 4. **Modern Workplace Devices - Virtual Machine** + 4. When registering virtual devices - **Modern Workplace Devices - Virtual Machine** 1. This group has all virtual devices managed by Windows Autopatch. 8. In post-device registration, three actions occur: 1. Windows Autopatch adds devices to its managed database. diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md index 1d44162fb9..14e592ed12 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md @@ -65,7 +65,7 @@ It's recommended to detect and clean up stale devices in Azure AD before registe To be eligible for Windows Autopatch management, devices must meet a minimum set of required software-based prerequisites: -- [Supported Windows 10/11 Enterprise and Professional edition versions](/windows/release-health/supported-versions-windows-client) +- Windows 10 (1809+)/11 Enterprise and Professional edition versions (only x64 architecture). - Either [Hybrid Azure AD-Joined](/azure/active-directory/devices/concept-azure-ad-join-hybrid) or [Azure AD-joined only](/azure/active-directory/devices/concept-azure-ad-join-hybrid) (personal devices aren't supported). - Managed by Microsoft Endpoint Manager. - [Microsoft Intune](https://www.microsoft.com/cloud-platform/microsoft-intune) and/or [Configuration Manager Co-management](/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites#configuration-manager-co-management-requirements). diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md index e5755ced5e..2d7ad54d04 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md @@ -39,11 +39,12 @@ Windows Autopatch is included with Window 10/11 Enterprise E3 or higher. The fol | [Windows 10/11 Enterprise E5](/azure/active-directory/enterprise-users/licensing-service-plan-reference) | WIN10_VDA_E5 | 488ba24a-39a9-4473-8ee5-19291e71b002 | | [Windows 10/11 Enterprise VDA](/windows/deployment/deploy-enterprise-licenses#virtual-desktop-access-vda) | E3_VDA_only | d13ef257-988a-46f3-8fce-f47484dd4550 | -The following Windows 64-bit editions are required for Windows Autopatch: +The following Windows OS editions, builds and architecture are supported in Windows Autopatch: -- Windows 10/11 Pro -- Windows 10/11 Enterprise -- Windows 10/11 Pro for Workstations +- x64 architecture +- Windows 10 (1809+)/11 Pro +- Windows 10 (1809+)/11 Enterprise +- Windows 10 (1809+)/11 Pro for Workstations ## Configuration Manager Co-management requirements From a02a2982f5ed1b61d6da7528e0668ebcc19a3c71 Mon Sep 17 00:00:00 2001 From: Sunny Zankharia <67922512+sazankha@users.noreply.github.com> Date: Fri, 29 Jul 2022 07:39:07 -0700 Subject: [PATCH 097/109] Update faq-md-app-guard.yml --- .../microsoft-defender-application-guard/faq-md-app-guard.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-application-guard/faq-md-app-guard.yml b/windows/security/threat-protection/microsoft-defender-application-guard/faq-md-app-guard.yml index b641427ea4..4e72f94860 100644 --- a/windows/security/threat-protection/microsoft-defender-application-guard/faq-md-app-guard.yml +++ b/windows/security/threat-protection/microsoft-defender-application-guard/faq-md-app-guard.yml @@ -169,9 +169,9 @@ sections: 10. Choose **Apply to this Service** and select **Internet Connection Sharing (ICS) Shared Access**. - question: | - How can I disable portions of ICS without breaking Application Guard? + How can I disable portions of Internet Connection Service (ICS) without breaking Application Guard? answer: | - ICS is enabled by default in Windows, and ICS must be enabled in order for Application Guard to function correctly. We do not recommend disabling ICS; however, you can disable ICS in part by using a Group Policy and editing registry keys. + ICS is enabled by default in Windows, and ICS must be enabled for Application Guard to function correctly. We do not recommend disabling ICS, this will stop Application Guard from working; however, you can disable ICS in part by using a Group Policy and editing registry keys. 1. In the Group Policy setting, **Prohibit use of Internet Connection Sharing on your DNS domain network**, set it to **Disabled**. From fdc2a7a3348b12b37be945bcfee7178041c27d31 Mon Sep 17 00:00:00 2001 From: Aaron Czechowski Date: Fri, 29 Jul 2022 11:05:35 -0400 Subject: [PATCH 098/109] remove technet gallery links --- .../internet-explorer/internet-explorer.yml | 36 ++--- .../app-v/appv-auto-provision-a-vm.md | 4 +- ...eploying-microsoft-office-2010-wth-appv.md | 15 +-- .../app-v/appv-performance-guidance.md | 51 +++---- ...v-application-template-schema-reference.md | 28 ++-- .../ue-v/uev-prepare-for-deployment.md | 30 ++--- ...synchronizing-microsoft-office-with-uev.md | 9 +- .../ue-v/uev-whats-new-in-uev-for-windows.md | 36 +++-- ...-custom-templates-and-the-uev-generator.md | 45 ++----- .../update/windows-update-errors.md | 23 ++-- ...lients-allowed-to-make-remote-sam-calls.md | 124 +++++++++--------- 11 files changed, 157 insertions(+), 244 deletions(-) diff --git a/browsers/internet-explorer/internet-explorer.yml b/browsers/internet-explorer/internet-explorer.yml index 17fad3f1dd..05e93f6e25 100644 --- a/browsers/internet-explorer/internet-explorer.yml +++ b/browsers/internet-explorer/internet-explorer.yml @@ -6,9 +6,9 @@ metadata: title: Internet Explorer 11 documentation description: Consistent, reliable web browsing on Windows 7, Windows 8.1, and Windows 10, with the security, performance, backward compatibility, and modern standards support that large organizations need. ms.topic: landing-page - author: lizap - ms.author: elizapo - ms.date: 07/06/2020 + author: aczechowski + ms.author: aaroncz + ms.date: 07/29/2022 # linkListType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | sample | tutorial | video | whats-new @@ -38,14 +38,6 @@ landingContent: url: https://www.microsoft.com/download/details.aspx?id=49974 - text: Cumulative security updates for Internet Explorer 11 url: https://www.catalog.update.microsoft.com/Search.aspx?q=cumulative%20security%20update%20for%20internet%20explorer%2011 - - linkListType: learn - links: - - text: Getting started with Windows 10 for IT professionals - url: https://mva.microsoft.com/training-courses/getting-started-with-windows-10-for-it-professionals-10629?l=fCowqpy8_5905094681 - - text: 'Windows 10: Top Features for IT Pros' - url: https://mva.microsoft.com/training-courses/windows-10-top-features-for-it-pros-16319?l=xBnT2ihhC_7306218965 - - text: 'Virtual Lab: Enterprise Mode' - url: https://www.microsoft.com/handsonlabs/SelfPacedLabs/?storyGuid=e4155067-2c7e-4b46-8496-eca38bedca02 # Card - title: Plan @@ -62,8 +54,6 @@ landingContent: url: ./ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md - text: Manage Windows upgrades with Upgrade Readiness url: /windows/deployment/upgrade/manage-windows-upgrades-with-upgrade-readiness - - text: 'Demo: Plan and manage Windows 10 upgrades and feature updates with' - url: https://techcommunity.microsoft.com/t5/Microsoft-Ignite-Content-2017/Windows-Analytics-Plan-and-manage-Windows-10-upgrades-and/td-p/98639 - linkListType: how-to-guide links: - text: Turn on Enterprise Mode and use a site list @@ -125,11 +115,7 @@ landingContent: - text: Out-of-date ActiveX control blocking url: ./ie11-deploy-guide/out-of-date-activex-control-blocking.md - text: Update to block out-of-date ActiveX controls in Internet Explorer - url: https://support.microsoft.com/help/2991000/update-to-block-out-of-date-activex-controls-in-internet-explorer - - text: Script to join user to AD with automatic Local user Profile Migration - url: https://gallery.technet.microsoft.com/scriptcenter/script-to-join-active-7b16d9d3 - - text: Scripts for IT professionals - url: https://gallery.technet.microsoft.com/scriptcenter/site/search?query=Microsoft%20Edge%20or%20Internet + url: https://support.microsoft.com/topic/update-to-block-out-of-date-activex-controls-in-internet-explorer-39ced8f8-5d98-3c7b-4792-b62fad4e2277 # Card - title: Support @@ -137,25 +123,19 @@ landingContent: - linkListType: get-started links: - text: Change or reset Internet Explorer settings - url: https://support.microsoft.com/help/17441/windows-internet-explorer-change-reset-settings + url: https://support.microsoft.com/windows/change-or-reset-internet-explorer-settings-2d4bac50-5762-91c5-a057-a922533f77d5 - text: Troubleshoot problems with setup, installation, auto configuration, and more url: ./ie11-deploy-guide/troubleshoot-ie11.md - text: Disable VBScript execution in Internet Explorer for Internet Zone and Restricted Sites Zone - url: https://support.microsoft.com/help/4012494/option-to-disable-vbscript-execution-in-internet-explorer-for-internet + url: https://support.microsoft.com/topic/option-to-disable-vbscript-execution-in-internet-explorer-for-internet-zone-and-restricted-sites-zone-3a2104c0-5af0-9aae-6c57-8207d3cb3e65 - text: Frequently asked questions about IEAK 11 url: ./ie11-faq/faq-ieak11.yml - text: Internet Explorer 8, 9, 10, 11 forum url: https://social.technet.microsoft.com/forums/ie/home?forum=ieitprocurrentver - text: Contact a Microsoft support professional url: https://support.microsoft.com/contactus - - text: Support options for Microsoft Partners - url: https://mspartner.microsoft.com/Pages/Support/get-support.aspx - - text: Microsoft Services Premier Support - url: https://www.microsoft.com/en-us/microsoftservices/support.aspx - - text: Microsoft Small Business Support Center - url: https://smallbusiness.support.microsoft.com/product/internet-explorer - text: General support - url: https://support.microsoft.com/products/internet-explorer + url: https://support.microsoft.com/windows/internet-explorer-help-23360e49-9cd3-4dda-ba52-705336cc0de2 # Card - title: Stay informed @@ -167,4 +147,4 @@ landingContent: - text: Microsoft Edge Dev blog url: https://blogs.windows.com/msedgedev - text: Microsoft Edge Dev on Twitter - url: https://twitter.com/MSEdgeDev \ No newline at end of file + url: https://twitter.com/MSEdgeDev diff --git a/windows/application-management/app-v/appv-auto-provision-a-vm.md b/windows/application-management/app-v/appv-auto-provision-a-vm.md index 90d51b1e29..ce0946e52d 100644 --- a/windows/application-management/app-v/appv-auto-provision-a-vm.md +++ b/windows/application-management/app-v/appv-auto-provision-a-vm.md @@ -33,7 +33,7 @@ Provisioning your new VM includes creating a VHD file, setting up a user account #### Create a VHD file -For this process to work, you must have a base operating system available as a VHD image file, we recommend using the [Convert-WindowsImage.ps1](https://gallery.technet.microsoft.com/scriptcenter/Convert-WindowsImageps1-0fe23a8f) command-line tool. +For this process to work, you must have a base operating system available as a VHD image file, we recommend using the [Convert-WindowsImage.ps1](https://www.powershellgallery.com/packages/Convert-WindowsImage/10.0) command-line tool. #### Create a VHD file with the Convert-WindowsImage command-line tool @@ -122,6 +122,6 @@ After you sequence your packages, you can automatically clean up any unpublished ### Related articles - [Download the **Convert-WindowsImage** tool](https://www.powershellgallery.com/packages/Convert-WindowsImage/10.0) -- [Download the Windows ADK](https://developer.microsoft.com/windows/hardware/windows-assessment-deployment-kit) +- [Download the Windows ADK](/windows-hardware/get-started/adk-install) - [How to install the App-V Sequencer](appv-install-the-sequencer.md) - [Learn about Hyper-V on Windows Server 2016](/windows-server/virtualization/hyper-v/Hyper-V-on-Windows-Server) diff --git a/windows/application-management/app-v/appv-deploying-microsoft-office-2010-wth-appv.md b/windows/application-management/app-v/appv-deploying-microsoft-office-2010-wth-appv.md index 34683ed7d8..afe22af405 100644 --- a/windows/application-management/app-v/appv-deploying-microsoft-office-2010-wth-appv.md +++ b/windows/application-management/app-v/appv-deploying-microsoft-office-2010-wth-appv.md @@ -1,5 +1,5 @@ --- -title: Deploying Microsoft Office 2010 by Using App-V (Windows 10/11) +title: Deploying Microsoft Office 2010 by Using App-V description: Create Office 2010 packages for Microsoft Application Virtualization (App-V) using the App-V Sequencer or the App-V Package Accelerator. author: aczechowski ms.prod: w10 @@ -33,15 +33,6 @@ The following table shows the App-V versions, methods of Office package creation Sequencing Office 2010 is one of the main methods for creating an Office 2010 package on App-V. For more information, see [How to Sequence a New Application with App-V 5.0](/microsoft-desktop-optimization-pack/appv-v5/how-to-sequence-a-new-application-with-app-v-50-beta-gb18030). -## Creating Office 2010 App-V packages using package accelerators - -Office 2010 App-V packages can be created through package accelerators. Microsoft has provided package accelerators for creating Office 2010 on Windows 10/11, Windows 8, and Windows 7. The following pages will show you which package accelerator is best for creating Office 2010 App-V packages on your version of Windows: - -* [App-V 5.0 Package Accelerator for Office Professional Plus 2010 – Windows 8](https://gallery.technet.microsoft.com/App-V-50-Package-a29410db) -* [App-V 5.0 Package Accelerator for Office Professional Plus 2010 – Windows 7](https://gallery.technet.microsoft.com/App-V-50-Package-e7ef536b) - -For detailed instructions on how to create virtual application packages using App-V package accelerators, see [How to Create a Virtual Application Package Using an App-V Package Accelerator](appv-create-a-virtual-application-package-package-accelerator.md). - ## Deploying the Microsoft Office package for App-V You can deploy Office 2010 packages by using any of the following App-V deployment methods: @@ -73,7 +64,7 @@ The following table provides a full list of supported integration points for Off |Primary Interop Assemblies|Support managed add-ins|| |Office Document Cache Handler|Allows Document Cache for Office applications|| |Outlook Protocol Search handler|User can search in Outlook|Yes| -|Active X Controls:
    - Groove.SiteClient
    - PortalConnect.PersonalSite
    - SharePoint.openDocuments
    - SharePoint.ExportDatabase
    - SharePoint.SpreadSheetLauncher
    - SharePoint.StssyncHander
    - SharePoint.DragUploadCtl
    - SharePoint.DragDownloadCtl
    - Sharpoint.OpenXMLDocuments
    - Sharepoint.ClipboardCtl
    - WinProj.Activator
    - Name.NameCtrl
    - STSUPld.CopyCtl
    - CommunicatorMeetingJoinAx.JoinManager
    - LISTNET.Listnet
    - OneDrive Pro Browser Helper|Active X Control.

    For more information about ActiveX controls, see the [ActiveX Control API Reference]().|| +|Active X Controls:
    - Groove.SiteClient
    - PortalConnect.PersonalSite
    - SharePoint.openDocuments
    - SharePoint.ExportDatabase
    - SharePoint.SpreadSheetLauncher
    - SharePoint.StssyncHander
    - SharePoint.DragUploadCtl
    - SharePoint.DragDownloadCtl
    - Sharpoint.OpenXMLDocuments
    - Sharepoint.ClipboardCtl
    - WinProj.Activator
    - Name.NameCtrl
    - STSUPld.CopyCtl
    - CommunicatorMeetingJoinAx.JoinManager
    - LISTNET.Listnet
    - OneDrive Pro Browser Helper|Active X Control.

    For more information about ActiveX controls, see the [ActiveX Control API Reference](/previous-versions/office/developer/sharepoint-2010/ms440037(v=office.14)).|| |OneDrive Pro Icon Overlays|Windows explorer shell icon overlays when users look at folders OneDrive Pro folders|| ### Connection Groups @@ -82,4 +73,4 @@ The following table provides a full list of supported integration points for Off ### Dynamic Configuration -* [About App-V Dynamic Configuration](appv-dynamic-configuration.md) \ No newline at end of file +* [About App-V Dynamic Configuration](appv-dynamic-configuration.md) diff --git a/windows/application-management/app-v/appv-performance-guidance.md b/windows/application-management/app-v/appv-performance-guidance.md index 16d57ffc8b..8b935473ac 100644 --- a/windows/application-management/app-v/appv-performance-guidance.md +++ b/windows/application-management/app-v/appv-performance-guidance.md @@ -1,5 +1,5 @@ --- -title: Performance Guidance for Application Virtualization (Windows 10/11) +title: Performance Guidance for Application Virtualization description: Learn how to configure App-V for optimal performance, optimize virtual app packages, and provide a better user experience with RDS and VDI. author: aczechowski ms.prod: w10 @@ -36,11 +36,11 @@ You should read and understand the following information before reading this doc Finally, this document will provide you with the information to configure the computer running App-V client and the environment for optimal performance. Optimize your virtual application packages for performance using the sequencer, and to understand how to use User Experience Virtualization (UE-V) or other user environment management technologies to provide the optimal user experience with App-V in both Remote Desktop Services (RDS) and non-persistent virtual desktop infrastructure (VDI). -To help determine what information is relevant to your environment, you should review each section’s brief overview and applicability checklist. +To help determine what information is relevant to your environment, you should review each section's brief overview and applicability checklist. ## App-V in stateful\* non-persistent deployments -This section provides information about an approach that helps ensure a user will have access to all virtual applications within seconds after logging in. This access is achieved by uniquely addressing the often long-running App-V publishing refresh. As you'll discover the basis of the approach, the fastest publishing refresh, is one that doesn’t have to actually do anything. Many conditions must be met and steps followed to provide the optimal user experience. +This section provides information about an approach that helps ensure a user will have access to all virtual applications within seconds after logging in. This access is achieved by uniquely addressing the often long-running App-V publishing refresh. As you'll discover the basis of the approach, the fastest publishing refresh, is one that doesn't have to actually do anything. Many conditions must be met and steps followed to provide the optimal user experience. Use the information in the following section for more information: @@ -54,7 +54,7 @@ Use the information in the following section for more information: - Steps to Prepare the Base Image – Whether in a non-persistent VDI or RDSH environment, only a few steps must be completed in the base image to enable this approach. -- Use UE-V as the User Profile Management (UPM) solution for the App-V approach – the cornerstone of this approach is the ability of a UEM solution to persist the contents of just a few registry and file locations. These locations constitute the user integrations\*. Be sure to review the specific requirements for the UPM solution. +- Use UE-V as the User Profile Management (UPM) solution for the App-V approach – the cornerstone of this approach is the ability of a UEM solution to persist the contents of just a few registry and file locations. These locations constitute the user integrations\*. Be sure to review the specific requirements for the UPM solution. [User Experience Walk-through](#bkmk-uewt) @@ -122,8 +122,7 @@ The following information displays the required steps to prepare the base image - Enable the App-V client as described in [Enable the App-V in-box client](appv-enable-the-app-v-desktop-client.md). - Enable UE-V and download the App-V Settings Template from the UE-V template Gallery, see the following steps. - - Configure for Shared Content Store (SCS) mode. For more information, see [Deploying the - App-V Sequencer and Configuring the Client](appv-deploying-the-appv-sequencer-and-client.md). + - Configure for Shared Content Store (SCS) mode. For more information, see [Deploying the App-V Sequencer and Configuring the Client](appv-deploying-the-appv-sequencer-and-client.md). - Configure Preserve User Integrations on Login Registry DWORD. - Pre-configure all global-targeted packages, for example, **Add-AppvClientPackage**. - Pre-configure all global-targeted connection groups, for example, **Add-AppvClientConnectionGroup**. @@ -144,7 +143,7 @@ For critical App-V Client configurations and for a little more context and how-t For every package that meets the above conditions, effectively twice the work will be done during publishing/refresh. - If you don’t plan to pre-configure every available user package in the base image, use this setting. + If you don't plan to pre-configure every available user package in the base image, use this setting. - Configure in the Registry under `HKEY_LOCAL_MACHINE\Software\Microsoft\AppV\Client\Integration`. - Create the DWORD value **PreserveUserIntegrationsOnLogin** with a value of 1. @@ -170,12 +169,10 @@ For more information, see: - [Get Started with UE-V](/windows/configuration/ue-v/uev-getting-started) -In essence all that is required is to enable the UE-V service and download the following Microsoft authored App-V settings template from the [Microsoft User Experience Virtualization (UE-V) template gallery](https://gallery.technet.microsoft.com/Authored-UE-V-Settings-bb442a33). Register the template. For more information about UE-V templates, see [User Experience Virtualization (UE-V) for Windows client overview](/windows/configuration/ue-v/uev-for-windows). - > [!Note] > Without performing an additional configuration step, User Environment Virtualization (UE-V) won't be able to synchronize the Start menu shortcuts (.lnk files) on the target computer. The .lnk file type is excluded by default. -UE-V will only support removing the .lnk file type from the exclusion list in the RDS and VDI scenarios, where every user’s device will have the same set of applications installed to the same location and every .lnk file is valid for all the users’ devices. For example, UE-V wouldn't currently support the following two scenarios, because the net result will be that the shortcut will be valid on one but not all devices. +UE-V will only support removing the .lnk file type from the exclusion list in the RDS and VDI scenarios, where every user's device will have the same set of applications installed to the same location and every .lnk file is valid for all the users' devices. For example, UE-V wouldn't currently support the following two scenarios, because the net result will be that the shortcut will be valid on one but not all devices. - If a user has an application installed on one device with .lnk files enabled and the same native application installed on another device to a different installation root with .lnk files enabled. @@ -306,7 +303,7 @@ This following process is a step-by-step walk-through of the App-V and UPM opera Upgrading a package is a crucial aspect of the package lifecycle. To help guarantee users have access to the appropriate upgraded (published) or downgraded (unpublished) virtual application packages, it's recommended you update the base image to reflect these changes. To understand why review the following section: -App-V 5.0 SP2 introduced the concept of pending states. In the past, +App-V 5.0 SP2 introduced the concept of pending states. In the past, - If an administrator changed entitlements or created a new version of a package (upgraded) and during a publishing/refresh that package was in-use, the unpublish or publish operation, respectively, would fail. @@ -318,37 +315,23 @@ In a non-persistent environment, it's unlikely these pended operations will be p The following section contains lists with information about Microsoft documentation and downloads that may be useful when optimizing your environment for performance. - +#### Windows Server -**.NET NGEN Blog (Highly Recommended)** +Server performance tuning guidelines for [Microsoft Windows Server 2012 R2](/previous-versions/dn529133(v=vs.85)) -- [How to speed up NGEN optimization](https://blogs.msdn.com/b/dotnet/archive/2013/08/06/wondering-why-mscorsvw-exe-has-high-cpu-usage-you-can-speed-it-up.aspx) +#### Server roles -**Windows Server and Server Roles** +- [Remote Desktop Virtualization Host](/previous-versions/dn567643(v=vs.85)) -Server Performance Tuning Guidelines for +- [Remote Desktop Session Host](/previous-versions/dn567648(v=vs.85)) -- [Microsoft Windows Server 2012 R2](/previous-versions//dn529133(v=vs.85)) - -- [Microsoft Windows Server 2012](https://download.microsoft.com/download/0/0/B/00BE76AF-D340-4759-8ECD-C80BC53B6231/performance-tuning-guidelines-windows-server-2012.docx) - -- [Microsoft Windows Server 2008 R2](https://download.microsoft.com/download/6/B/2/6B2EBD3A-302E-4553-AC00-9885BBF31E21/Perf-tun-srv-R2.docx) - -**Server Roles** - -- [Remote Desktop Virtualization Host](/previous-versions//dn567643(v=vs.85)) - -- [Remote Desktop Session Host](/previous-versions//dn567648(v=vs.85)) - -- [IIS Relevance: App-V Management, Publishing, Reporting Web Services](/previous-versions//dn567678(v=vs.85)) +- [IIS Relevance: App-V Management, Publishing, Reporting Web Services](/previous-versions/dn567678(v=vs.85)) - [File Server (SMB) Relevance: If used for App-V Content Storage and Delivery in SCS Mode](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj134210(v=ws.11)) -**Windows Client (Guest OS) Performance Tuning Guidance** +#### Windows Client (guest OS) performance tuning guidance -- [Optimization Script: (Provided by Microsoft Support)](/archive/blogs/jeff_stokes/the-microsoft-premier-field-engineer-pfe-view-on-virtual-desktop-vdi-density) - -- [Microsoft Windows 8](https://download.microsoft.com/download/6/0/1/601D7797-A063-4FA7-A2E5-74519B57C2B4/Windows_8_VDI_Image_Client_Tuning_Guide.pdf) +- [The Microsoft Premier Field Engineer (PFE) view on Virtual Desktop (VDI) Density](/archive/blogs/jeff_stokes/the-microsoft-premier-field-engineer-pfe-view-on-virtual-desktop-vdi-density) - [Optimization Script: (Provided by Microsoft Support)](/archive/blogs/jeff_stokes/hot-off-the-presses-get-it-now-the-windows-8-vdi-optimization-script-courtesy-of-pfe) @@ -404,7 +387,7 @@ Removing FB1 doesn't require the original application installer. After completin ### Creating a new virtual application package on the sequencer -If, during sequencer monitoring, an SxS Assembly (such as a VC++ Runtime) is installed as part of an application’s installation, SxS Assembly will be automatically detected and included in the package. The administrator will be notified and will have the option to exclude the SxS Assembly. +If, during sequencer monitoring, an SxS Assembly (such as a VC++ Runtime) is installed as part of an application's installation, SxS Assembly will be automatically detected and included in the package. The administrator will be notified and will have the option to exclude the SxS Assembly. **Client Side**: diff --git a/windows/configuration/ue-v/uev-application-template-schema-reference.md b/windows/configuration/ue-v/uev-application-template-schema-reference.md index a3d3387c57..039d7669a1 100644 --- a/windows/configuration/ue-v/uev-application-template-schema-reference.md +++ b/windows/configuration/ue-v/uev-application-template-schema-reference.md @@ -66,9 +66,11 @@ The XML declaration must specify the XML version 1.0 attribute (<?xml version **Type: String** -UE-V uses the ```https://schemas.microsoft.com/UserExperienceVirtualization/2012/SettingsLocationTemplate``` namespace for all applications. SettingsLocationTemplate is the root element and contains all other elements. Reference SettingsLocationTemplate in all templates using this tag: +UE-V uses the `https://schemas.microsoft.com/UserExperienceVirtualization/2012/SettingsLocationTemplate` namespace for all applications. SettingsLocationTemplate is the root element and contains all other elements. Reference SettingsLocationTemplate in all templates using this tag: -`` +```xml + +``` ### Data types @@ -102,7 +104,7 @@ ProcessVersion defines a type with four child elements: **Major**, **Minor**, ** Architecture enumerates two possible values: **Win32** and **Win64**. These values are used to specify process architecture. **Process** -The Process data type is a container used to describe processes to be monitored by UE-V. It contains six child elements: **Filename**, **Architecture**, **ProductName**, **FileDescription**, **ProductVersion**, and **FileVersion**. This table details each element’s respective data type: +The Process data type is a container used to describe processes to be monitored by UE-V. It contains six child elements: **Filename**, **Architecture**, **ProductName**, **FileDescription**, **ProductVersion**, and **FileVersion**. This table details each element's respective data type: |Element|Data Type|Mandatory| |--- |--- |--- | @@ -117,11 +119,11 @@ The Process data type is a container used to describe processes to be monitored The Processes data type represents a container for a collection of one or more Process elements. Two child elements are supported in the Processes sequence type: **Process** and **ShellProcess**. Process is an element of type Process and ShellProcess is of data type Empty. At least one item must be identified in the sequence. **Path** -Path is consumed by RegistrySetting and FileSetting to refer to registry and file paths. This element supports two optional attributes: **Recursive** and **DeleteIfNotFound**. Both values are set to default=”False”. +Path is consumed by RegistrySetting and FileSetting to refer to registry and file paths. This element supports two optional attributes: **Recursive** and **DeleteIfNotFound**. Both values are set to default="False". Recursive indicates that the path and all subfolders are included for file settings or that all child registry keys are included for registry settings. In both cases, all items at the current level are included in the data captured. For a FileSettings object, all files within the specified folder are included in the data captured by UE-V but folders are not included. For registry paths, all values in the current path are captured but child registry keys are not captured. In both cases, care should be taken to avoid capturing large data sets or large numbers of items. -The DeleteIfNotFound attribute removes the setting from the user’s settings storage path data. This may be desirable in cases where removing these settings from the package will save a large amount of disk space on the settings storage path file server. +The DeleteIfNotFound attribute removes the setting from the user's settings storage path data. This may be desirable in cases where removing these settings from the package will save a large amount of disk space on the settings storage path file server. **FileMask** FileMask specifies only certain file types for the folder that is defined by Path. For example, Path might be `C:\users\username\files` and FileMask could be `*.txt` to include only text files. @@ -138,7 +140,7 @@ Settings is a container for all the settings that apply to a particular template |Element|Description| |--- |--- | |Asynchronous|Asynchronous settings packages are applied without blocking the application startup so that the application start proceeds while the settings are still being applied. This is useful for settings that can be applied asynchronously, such as those get/set through an API, like SystemParameterSetting.| -|PreventOverlappingSynchronization|By default, UE-V only saves settings for an application when the last instance of an application using the template is closed. When this element is set to ‘false’, UE-V exports the settings even if other instances of an application are running. Suited templates – those that include a Common element section– that are shipped with UE-V use this flag to enable shared settings to always export on application close, while preventing application-specific settings from exporting until the last instance is closed.| +|PreventOverlappingSynchronization|By default, UE-V only saves settings for an application when the last instance of an application using the template is closed. When this element is set to 'false', UE-V exports the settings even if other instances of an application are running. Suited templates - those that include a Common element section- that are shipped with UE-V use this flag to enable shared settings to always export on application close, while preventing application-specific settings from exporting until the last instance is closed.| |AlwaysApplySettings|This parameter forces an imported settings package to be applied even if there are no differences between the package and the current state of the application. This parameter should be used only in special cases since it can slow down settings import.| ### Name Element @@ -208,7 +210,7 @@ Version identifies the version of the settings location template for administrat **Type: String** -Author identifies the creator of the settings location template. Two optional child elements are supported: **Name** and **Email**. Both attributes are optional, but, if the Email child element is specified, it must be accompanied by the Name element. Author refers to the full name of the contact for the settings location template, and email should refer to an email address for the author. We recommend that you include this information in templates published publicly, for example, on the [UE-V Template Gallery](https://gallery.technet.microsoft.com/site/search?f%5B0%5D.Type=RootCategory&f%5B0%5D.Value=UE-V). +Author identifies the creator of the settings location template. Two optional child elements are supported: **Name** and **Email**. Both attributes are optional, but, if the Email child element is specified, it must be accompanied by the Name element. Author refers to the full name of the contact for the settings location template, and email should refer to an email address for the author. We recommend that you include this information in templates published publicly. ### Processes and Process Element @@ -250,7 +252,7 @@ Filename refers to the actual file name of the executable as it appears in the f Valid filenames must not match the regular expression \[^\\\\\\?\\\*\\|<>/:\]+, that is, they may not contain backslash characters, asterisk or question mark wild-card characters, the pipe character, the greater than or less than sign, forward slash, or colon (the \\ ? \* | < > / or : characters.). > [!TIP] -> To test a string against this regex, use a PowerShell command window and substitute your executable’s name for **YourFileName**: +> To test a string against this regex, use a PowerShell command window and substitute your executable's name for **YourFileName**: `"YourFileName.exe" -match "[\\\?\*\|<>/:]+"` @@ -269,7 +271,7 @@ A value of **True** indicates that the string contains illegal characters. Here -In rare circumstances, the FileName value will not necessarily include the .exe extension, but it should be specified as part of the value. For example, `MyApplication.exe` should be specified instead of `MyApplication`. The second example will not apply the template to the process if the actual name of the executable file is “MyApplication.exe”. +In rare circumstances, the FileName value will not necessarily include the .exe extension, but it should be specified as part of the value. For example, `MyApplication.exe` should be specified instead of `MyApplication`. The second example will not apply the template to the process if the actual name of the executable file is "MyApplication.exe". ### Architecture @@ -279,7 +281,7 @@ In rare circumstances, the FileName value will not necessarily include the .exe Architecture refers to the processor architecture for which the target executable was compiled. Valid values are Win32 for 32-bit applications or Win64 for 64-bit applications. If present, this tag limits the applicability of the settings location template to a particular application architecture. For an example of this, compare the %ProgramFiles%\\Microsoft User Experience Virtualization\\templates\\ MicrosoftOffice2016Win32.xml and MicrosoftOffice2016Win64.xml files included with UE-V. This is useful when relative paths change between different versions of an executable or if settings have been added or removed when moving from one processor architecture to another. -If this element is absent, the settings location template ignores the process’ architecture and applies to both 32 and 64-bit processes if the file name and other attributes apply. +If this element is absent, the settings location template ignores the process' architecture and applies to both 32 and 64-bit processes if the file name and other attributes apply. > [!NOTE] > UE-V does not support ARM processors in this version. @@ -342,7 +344,7 @@ For example, in a suited application, it might be useful to provide reminders ab ProductVersion refers to the major and minor product versions of a file, as well as a build and patch level. ProductVersion is an optional element, but if specified, it must contain at least the Major child element. The value must express a range in the form Minimum="X" Maximum="Y" where X and Y are integers. The Minimum and Maximum values can be identical. -The product and file version elements may be left unspecified. Doing so makes the template “version agnostic”, meaning that the template will apply to all versions of the specified executable. +The product and file version elements may be left unspecified. Doing so makes the template "version agnostic", meaning that the template will apply to all versions of the specified executable. **Example 1:** @@ -368,7 +370,7 @@ File version: 5.0.2.1000 specified in the UE-V template generator produces the f ``` -**Incorrect Example 1 – incomplete range:** +**Incorrect Example 1 - incomplete range:** Only the Minimum attribute is present. Maximum must be included in a range as well. @@ -378,7 +380,7 @@ Only the Minimum attribute is present. Maximum must be included in a range as we ``` -**Incorrect Example 2 – Minor specified without Major element:** +**Incorrect Example 2 - Minor specified without Major element:** Only the Minor element is present. Major must be included as well. diff --git a/windows/configuration/ue-v/uev-prepare-for-deployment.md b/windows/configuration/ue-v/uev-prepare-for-deployment.md index 38b78b9d47..81cf471c17 100644 --- a/windows/configuration/ue-v/uev-prepare-for-deployment.md +++ b/windows/configuration/ue-v/uev-prepare-for-deployment.md @@ -15,13 +15,13 @@ ms.topic: article **Applies to** - Windows 10, version 1607 -Before you deploy User Experience Virtualization (UE-V), review this topic for important information about the type of deployment you’re planning and for preparations you can make beforehand so that your deployment is successful. If you leave this page, be sure to come back and read through the planning information in this topic. +Before you deploy User Experience Virtualization (UE-V), review this topic for important information about the type of deployment you're planning and for preparations you can make beforehand so that your deployment is successful. If you leave this page, be sure to come back and read through the planning information in this topic. ## Plan your UE-V deployment With UE-V, you can synchronize user-defined application and operating system settings across all the devices that a user works from. Use UE-V to synchronize settings for Windows applications and custom applications, such as third-party and line-of-business applications. -Whether you want to synchronize settings for only default Windows applications or for both Windows and custom applications, you’ll need to first deploy the features required to use UE-V. +Whether you want to synchronize settings for only default Windows applications or for both Windows and custom applications, you'll need to first deploy the features required to use UE-V. [Deploy required UE-V features](uev-deploy-required-features.md) @@ -29,7 +29,7 @@ Whether you want to synchronize settings for only default Windows applications o - [Enable the UE-V service](uev-deploy-required-features.md#enable-the-ue-v-service) on user computers -If you want to use UE-V to synchronize user-defined settings for custom applications (third-party or line-of-business), you’ll need to install and configure these optional additional UE-V features: +If you want to use UE-V to synchronize user-defined settings for custom applications (third-party or line-of-business), you'll need to install and configure these optional additional UE-V features: [Deploy UE-V for custom applications](uev-deploy-uev-for-custom-applications.md) @@ -49,11 +49,11 @@ The workflow diagram below illustrates a typical UE-V deployment and the decisio ### Planning a UE-V deployment -Review the following topics to determine which UE-V components you’ll be deploying. +Review the following topics to determine which UE-V components you'll be deploying. - [Decide whether to synchronize settings for custom applications](#decide-whether-to-synchronize-settings-for-custom-applications) - If you want to synchronize settings for custom applications, you’ll need to install the UE-V template generator. Use the generator to create custom settings location templates, which involves the following tasks: + If you want to synchronize settings for custom applications, you'll need to install the UE-V template generator. Use the generator to create custom settings location templates, which involves the following tasks: - Review the [settings that are synchronized automatically in a UE-V deployment](#settings-automatically-synchronized-in-a-ue-v-deployment). @@ -79,11 +79,7 @@ This section explains which settings are synchronized by default in UE-V, includ - A statement of support for Windows applications setting synchronization -For downloadable UE-V templates, see: - -- [Microsoft Authored Office 2016 UE-V Templates](https://gallery.technet.microsoft.com/Authored-Office-2016-32-0dc05cd8) - -- [User Experience Virtualization (UE-V) settings templates for Microsoft Office](https://www.microsoft.com/download/details.aspx?id=46367) (for Office 2013 and Office 2010) +For downloadable UE-V templates, see: [User Experience Virtualization (UE-V) settings templates for Microsoft Office](https://www.microsoft.com/download/details.aspx?id=46367) ### Desktop applications synchronized by default in UE-V @@ -91,7 +87,7 @@ When you enable the UE-V service on user devices, it registers a default group o | Application category | Description | |-----------------------------|-------------------| -| Microsoft Office 2016 applications
    [Download a list of all settings synced](https://gallery.technet.microsoft.com/Authored-Office-2016-32-0dc05cd8) | Microsoft Access 2016
    Microsoft Lync 2016
    Microsoft Excel 2016
    Microsoft OneNote 2016
    Microsoft Outlook 2016
    Microsoft PowerPoint 2016
    Microsoft Project 2016
    Microsoft Publisher 2016
    Microsoft SharePoint Designer 2013 (not updated for 2016)
    Microsoft Visio 2016
    Microsoft Word 2016
    Microsoft Office Upload Manager
    Microsoft Infopath has been removed (deprecated) from the Office 2016 suite | +| Microsoft Office 2016 applications | Microsoft Access 2016
    Microsoft Lync 2016
    Microsoft Excel 2016
    Microsoft OneNote 2016
    Microsoft Outlook 2016
    Microsoft PowerPoint 2016
    Microsoft Project 2016
    Microsoft Publisher 2016
    Microsoft SharePoint Designer 2013 (not updated for 2016)
    Microsoft Visio 2016
    Microsoft Word 2016
    Microsoft Office Upload Manager
    Microsoft Infopath has been removed (deprecated) from the Office 2016 suite | | Microsoft Office 2013 applications
    [Download a list of all settings synced](https://www.microsoft.com/download/details.aspx?id=46367) | Microsoft Word 2013
    Microsoft Excel 2013
    Microsoft Outlook 2013
    Microsoft Access 2013
    Microsoft Project 2013
    Microsoft PowerPoint 2013
    Microsoft Publisher 2013
    Microsoft Visio 2013
    Microsoft InfoPath 2013
    Microsoft Lync 2013
    Microsoft OneNote 2013
    Microsoft SharePoint Designer 2013
    Microsoft Office 2013 Upload Center
    Microsoft OneDrive for Business 2013 | Microsoft Office 2010 applications
    [Download a list of all settings synced](https://www.microsoft.com/download/details.aspx?id=46367) | Microsoft Word 2010
    Microsoft Excel 2010
    Microsoft Outlook 2010
    Microsoft Access 2010
    Microsoft Project 2010
    Microsoft PowerPoint 2010
    Microsoft Publisher 2010
    Microsoft Visio 2010
    Microsoft SharePoint Workspace 2010
    Microsoft InfoPath 2010
    Microsoft Lync 2010
    Microsoft OneNote 2010
    Microsoft SharePoint Designer 2010 | | Browser options: Internet Explorer 11 and 10 | Synchronize favorites, home page, tabs, and toolbars.
    **Note**
    UE-V does not roam settings for Internet Explorer cookies. | @@ -120,7 +116,7 @@ UE-V includes settings location templates that capture settings values for these | **Application Settings** | Windows applications | Close application
    Windows application settings change event | Start the UE-V App Monitor at startup
    Open app
    Windows application settings change event
    Arrival of a settings package | | | Desktop applications | Application closes | Application opens and closes | | **Desktop settings** | Desktop background | Lock or log off | Log on, unlock, remote connect, notification of new package arrival, or scheduled task runs | -| | Ease of Access (Common – Accessibility, Narrator, Magnifier, On-Screen-Keyboard) | Lock or Log off | Log on | +| | Ease of Access (Common - Accessibility, Narrator, Magnifier, On-Screen-Keyboard) | Lock or Log off | Log on | | | Ease of Access (Shell - Audio, Accessibility, Keyboard, Mouse) | Lock or log off | Log on, unlock, remote connect, notification of new package arrival, or scheduled task runs | | | Desktop settings | Lock or log off | Log on | @@ -150,7 +146,7 @@ Printer roaming in UE-V requires one of these scenarios: ### Determine whether you need settings synchronized for other applications -After you have reviewed the settings that are synchronized automatically in a UE-V deployment, you’ll need to decide whether to synchronize settings for other applications as your decision will determine how you deploy UE-V throughout your enterprise. +After you have reviewed the settings that are synchronized automatically in a UE-V deployment, you'll need to decide whether to synchronize settings for other applications as your decision will determine how you deploy UE-V throughout your enterprise. As an administrator, when you consider which desktop applications to include in your UE-V solution, consider which settings can be customized by users, and how and where the application stores its settings. Not all desktop applications have settings that can be customized or that are routinely customized by users. In addition, not all desktop applications settings can be synchronized safely across multiple devices or environments. @@ -164,7 +160,7 @@ In general, you can synchronize settings that meet the following criteria: ### Checklist for evaluating custom applications -If you’ve decided that you need to synchronize settings for custom applications, use this checklist to determine which applications you’ll include. +If you've decided that you need to synchronize settings for custom applications, use this checklist to determine which applications you'll include. |   | Description | |-------|--------------------------| @@ -266,7 +262,7 @@ For more information, see the [Windows Application List](uev-managing-settings-l ### Custom UE-V settings location templates -If you are deploying UE-V to synchronize settings for custom applications, you’ll use the UE-V template generator to create custom settings location templates for those desktop applications. After you create and test a custom settings location template in a test environment, you can deploy the settings location templates to user devices. +If you are deploying UE-V to synchronize settings for custom applications, you'll use the UE-V template generator to create custom settings location templates for those desktop applications. After you create and test a custom settings location template in a test environment, you can deploy the settings location templates to user devices. Custom settings location templates must be deployed with an existing deployment infrastructure, such as an enterprise software distribution method, including Microsoft Endpoint Configuration Manager, with preferences, or by configuring a UE-V settings template catalog. Templates that are deployed with Configuration Manager or Group Policy must be registered using UE-V WMI or Windows PowerShell. @@ -298,7 +294,7 @@ Specify your requirements for UE-V with standard disk capacity and network healt UE-V uses a Server Message Block (SMB) share for the storage of settings packages. The size of settings packages varies depending on the settings information for each application. While most settings packages are small, the synchronization of potentially large files, such as desktop images, can result in poor performance, particularly on slower networks. -To reduce problems with network latency, create settings storage locations on the same local networks where the users’ computers reside. We recommend 20 MB of disk space per user for the settings storage location. +To reduce problems with network latency, create settings storage locations on the same local networks where the users' computers reside. We recommend 20 MB of disk space per user for the settings storage location. By default, UE-V synchronization times out after 2 seconds to prevent excessive lag due to a large settings package. You can configure the SyncMethod=SyncProvider setting by using [Group Policy objects](uev-configuring-uev-with-group-policy-objects.md). @@ -339,7 +335,7 @@ Before you proceed, ensure that your environment meets these requirements for us > [!NOTE] > - Windows Server 2012 operating systems come with .NET Framework 4.5 installed. The Windows 10 operating system comes with .NET Framework 4.6 installed. > -> - The “Delete Roaming Cache” policy for mandatory profiles is not supported with UE-V and should not be used. +> - The "Delete Roaming Cache" policy for mandatory profiles is not supported with UE-V and should not be used. There are no special random access memory (RAM) requirements specific to UE-V. diff --git a/windows/configuration/ue-v/uev-synchronizing-microsoft-office-with-uev.md b/windows/configuration/ue-v/uev-synchronizing-microsoft-office-with-uev.md index c2a81519f1..051be1125c 100644 --- a/windows/configuration/ue-v/uev-synchronizing-microsoft-office-with-uev.md +++ b/windows/configuration/ue-v/uev-synchronizing-microsoft-office-with-uev.md @@ -17,14 +17,11 @@ ms.topic: article Microsoft User Experience Virtualization (UE-V) supports the synchronization of Microsoft Office application settings. The combination of UE-V and App-V support for Office enables the same experience on virtualized instances of Office from any UE-V-enabled device or virtualized desktop. -To synchronize Office applications settings, you can download Office templates from the [User Experience Virtualization (UE-V) Template Gallery](https://gallery.technet.microsoft.com/site/search?f%5B0%5D.Type=RootCategory&f%5B0%5D.Value=UE-V&f%5B0%5D.Text=UE-V). This resource provides Microsoft-authored UE-V settings location templates as well as community-developed settings location templates. - - ## Microsoft Office support in UE-V UE-V includes settings location templates for Microsoft Office 2016, 2013, and 2010. In previous versions of UE-V, settings location templates for Office 2013 and Office 2010 were distributed and registered when you installed the UE-V agent. Now that UE-V is a feature in Windows 10, version 1607, settings location templates are installed when you install or upgrade to the new operating system. -These templates help synchronize users’ Office experience between devices. Microsoft Office 2016 settings roamed by Office 365 experience are not included in these settings. For a list of Office 365-specific settings, see [Overview of user and roaming settings for Office](/previous-versions/office/office-2013-resource-kit/jj733593(v=office.15)). +These templates help synchronize users' Office experience between devices. Microsoft Office 2016 settings roamed by Office 365 experience are not included in these settings. For a list of Office 365-specific settings, see [Overview of user and roaming settings for Office](/previous-versions/office/office-2013-resource-kit/jj733593(v=office.15)). ## Synchronized Office Settings @@ -56,6 +53,6 @@ You can deploy UE-V settings location template with the following methods: For more information about using UE-V and Windows PowerShell, see [Managing UE-V settings location templates using Windows PowerShell and WMI](uev-managing-settings-location-templates-using-windows-powershell-and-wmi.md). -- **Registering template with Template Catalog Path**. If you use the Settings Template Catalog Path to manage templates on users’ computers, copy the Office template into the folder defined in the UE-V service. The next time the Template Auto Update (ApplySettingsCatalog.exe) scheduled task runs, the settings location template will be registered on the device. For more information, see [Deploy a settings template catalog](uev-deploy-uev-for-custom-applications.md). +- **Registering template with Template Catalog Path**. If you use the Settings Template Catalog Path to manage templates on users' computers, copy the Office template into the folder defined in the UE-V service. The next time the Template Auto Update (ApplySettingsCatalog.exe) scheduled task runs, the settings location template will be registered on the device. For more information, see [Deploy a settings template catalog](uev-deploy-uev-for-custom-applications.md). -- **Registering template with Configuration Manager**. If you use Configuration Manager to manage your UE-V settings storage templates, recreate the Template Baseline CAB, import it into Configuration Manager, and then deploy the baseline to user devices. \ No newline at end of file +- **Registering template with Configuration Manager**. If you use Configuration Manager to manage your UE-V settings storage templates, recreate the Template Baseline CAB, import it into Configuration Manager, and then deploy the baseline to user devices. diff --git a/windows/configuration/ue-v/uev-whats-new-in-uev-for-windows.md b/windows/configuration/ue-v/uev-whats-new-in-uev-for-windows.md index 89fb778fef..dccc836fe6 100644 --- a/windows/configuration/ue-v/uev-whats-new-in-uev-for-windows.md +++ b/windows/configuration/ue-v/uev-whats-new-in-uev-for-windows.md @@ -10,22 +10,22 @@ ms.author: aaroncz ms.topic: article --- -# What's New in UE-V +# What's new in UE-V **Applies to** - Windows 10, version 1607 -User Experience Virtualization (UE-V) for Windows 10, version 1607, includes these new features and capabilities compared to UE-V 2.1. See [UE-V Release notes](uev-release-notes-1607.md) for more information about the UE-V for Windows 10, version 1607 release. +User Experience Virtualization (UE-V) for Windows 10, version 1607, includes these new features and capabilities compared to UE-V 2.1. For more information about the UE-V for Windows 10, version 1607 release, see [UE-V Release notes](uev-release-notes-1607.md). -## UE-V is now a feature in Windows 10 +## UE-V is a feature in Windows 10 -With Windows 10, version 1607 and later releases, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack. +With Windows 10, version 1607 and later releases, UE-V is included with Windows Enterprise. It's no longer part of the Microsoft Desktop Optimization Pack. The changes in UE-V for Windows 10, version 1607 impact already existing implementations of UE-V in the following ways: -- The UE-V Agent is replaced by the UE-V service. The UE-V service is installed with Windows 10, version 1607 and no longer has to be deployed separately. Performing an in-place upgrade to Windows 10, version 1607, on user devices automatically installs the UE-V service, migrates users’ UE-V configurations, and updates the settings storage path. +- The UE-V Agent is replaced by the UE-V service. The UE-V service is installed with Windows 10, version 1607 and no longer has to be deployed separately. Performing an in-place upgrade to Windows 10, version 1607, on user devices automatically installs the UE-V service, migrates users' UE-V configurations, and updates the settings storage path. -- The UE-V template generator is available from the Windows 10 ADK. In previous releases of UE-V, the template generator was included in the Microsoft Desktop Optimization Pack. Although you’ll need to use the new template generator to create new settings location templates, existing settings location templates will continue to work. +- The UE-V template generator is available from the Windows 10 ADK. In previous releases of UE-V, the template generator was included in the Microsoft Desktop Optimization Pack. Although you'll need to use the new template generator to create new settings location templates, existing settings location templates will continue to work. - The Company Settings Center was removed and is no longer available on user devices. Users can no longer manage their synchronized settings. @@ -33,11 +33,11 @@ The changes in UE-V for Windows 10, version 1607 impact already existing impleme For more information about how to configure an existing UE-V installation after upgrading user devices to Windows 10, see [Upgrade to UE-V for Windows 10](uev-upgrade-uev-from-previous-releases.md). -> **Important**  You can upgrade your existing UE-V installation to Windows 10 from UE-V versions 2.1 or 2.0 only. If you are using a previous version of UE-V, you’ll need to upgrade from that version to UE-V 2.x before you upgrade to Windows 10. +> **Important**  You can upgrade your existing UE-V installation to Windows 10 from UE-V versions 2.1 or 2.0 only. If you are using a previous version of UE-V, you'll need to upgrade from that version to UE-V 2.x before you upgrade to Windows 10. ## New UE-V template generator is available from the Windows 10 ADK -UE-V for Windows 10 includes a new template generator, available from a new location. If you are upgrading from an existing UE-V installation, you’ll need to use the new generator to create settings location templates. The UE-V for Windows 10 template generator is now available in the [Windows 10 Assessment and Deployment Kit](https://developer.microsoft.com/en-us/windows/hardware/windows-assessment-deployment-kit) (Windows ADK). +UE-V for Windows 10 includes a new template generator, available from a new location. If you are upgrading from an existing UE-V installation, you'll need to use the new generator to create settings location templates. The UE-V for Windows 10 template generator is now available in the [Windows 10 Assessment and Deployment Kit](/windows-hardware/get-started/adk-install) (Windows ADK). ## Company Settings Center removed in UE-V for Windows 10, version 1607 @@ -57,21 +57,21 @@ Administrators can still define which user-customized application settings can s With Windows 10, version 1607, users can synchronize Windows application settings and Windows operating system settings to Azure instead of to OneDrive. You can use the Windows 10 enterprise sync functionality together with UE-V for on-premises domain-joined devices only. -In hybrid cloud environments, UE-V can roam Win32 applications on-premises while [Enterprise State Roaming](/azure/active-directory/devices/enterprise-state-roaming-overview) (ESR) can roam the rest, e.g., Windows and desktop settings, themes, colors, etc., to an Azure cloud installation. +In hybrid cloud environments, UE-V can roam Win32 applications on-premises while [Enterprise State Roaming](/azure/active-directory/devices/enterprise-state-roaming-enable) (ESR) can roam the rest, e.g., Windows and desktop settings, themes, colors, etc., to an Azure cloud installation. To configure UE-V to roam Windows desktop and application data only, change the following group policies: -- Disable “Roam Windows settings” group policy +- Disable "Roam Windows settings" group policy -- Enable “Do not synchronize Windows Apps” group policy +- Enable "Do not synchronize Windows Apps" group policy -For more information about using UE-V with Enterprise State Roaming, see [Settings and data roaming FAQ](/azure/active-directory/devices/enterprise-state-roaming-faqs#what-are-the-options-for-roaming-settings-for-existing-windows-desktop-applications). +For more information about using UE-V with Enterprise State Roaming, see [Settings and data roaming FAQ](/azure/active-directory/devices/enterprise-state-roaming-faqs#what-are-the-roaming-settings-options-for-existing-windows-desktop-applications-). Additionally, to enable Windows 10 and UE-V to work together, configure these policy settings in the Microsoft User Experience Virtualization node: -- Enable “Do Not Synchronize Windows Apps” +- Enable "Do Not Synchronize Windows Apps" -- Disable “Sync Windows Settings” +- Disable "Sync Windows Settings" ## Settings Synchronization Behavior Changed in UE-V for Windows 10 @@ -100,7 +100,7 @@ Printer roaming in UE-V requires one of these scenarios: ## Office 2016 Settings Location Template -UE-V for Windows 10, version 1607 includes the Microsoft Office 2016 settings location template with improved Outlook signature support. We’ve added synchronization of default signature settings for new, reply, and forwarded emails. Users no longer have to choose the default signature settings. +UE-V for Windows 10, version 1607 includes the Microsoft Office 2016 settings location template with improved Outlook signature support. We've added synchronization of default signature settings for new, reply, and forwarded emails. Users no longer have to choose the default signature settings. > **Note**  An Outlook profile must be created on any device on which a user wants to synchronize their Outlook signature. If the profile is not already created, the user can create one and then restart Outlook on that device to enable signature synchronization. @@ -112,11 +112,7 @@ To enable settings synchronization using UE-V, do one of the following: - Do not enable the Office 365 synchronization experience during Office 2013 installation -UE-V includes Office 2016, Office 2013, and Office 2010 templates. Office 2007 templates are no longer supported. Users can still use Office 2007 templates from UE-V 2.0 or earlier and can still get templates from the [User Experience Virtualization Template Gallery](https://gallery.technet.microsoft.com/site/search?f%5B0%5D.Type=RootCategory&f%5B0%5D.Value=UE-V&f%5B0%5D.Text=UE-V). - - - - +UE-V includes Office 2016, Office 2013, and Office 2010 templates. ## Related topics diff --git a/windows/configuration/ue-v/uev-working-with-custom-templates-and-the-uev-generator.md b/windows/configuration/ue-v/uev-working-with-custom-templates-and-the-uev-generator.md index d0f06bd548..f53af25e62 100644 --- a/windows/configuration/ue-v/uev-working-with-custom-templates-and-the-uev-generator.md +++ b/windows/configuration/ue-v/uev-working-with-custom-templates-and-the-uev-generator.md @@ -1,6 +1,6 @@ --- title: Working with Custom UE-V Templates and the UE-V Template Generator -description: Create your own custom settings location templates by working with Custom User Experience Virtualization (UE-V) Templates and the UE-V Template Generator. +description: Create your own custom settings location templates by working with Custom User Experience Virtualization (UE-V) Templates and the UE-V Template Generator. author: aczechowski ms.prod: w10 ms.date: 04/19/2017 @@ -14,7 +14,7 @@ ms.topic: article # Working with custom UE-V templates and the UE-V template generator **Applies to** -- Windows 10, version 1607 +- Windows 10 User Experience Virtualization (UE-V) uses XML files called ***settings location templates*** to monitor and synchronize application settings and Windows settings between user devices. By default, some settings location templates are included in UE-V. However, if you want to synchronize settings for desktop applications other than those included in the default templates, you can create your own custom settings location templates with the UE-V template generator. You can also edit or validate custom settings location templates with the UE-V template generator. @@ -33,9 +33,9 @@ Discovered settings are grouped into two categories: **Standard** and **Non-stan The UE-V template generator opens the application as part of the discovery process. The generator can capture settings in the following locations: -- **Registry Settings** – Registry locations under **HKEY\_CURRENT\_USER** +- **Registry Settings** - Registry locations under **HKEY\_CURRENT\_USER** -- **Application Settings Files** – Files that are stored under \\ **Users** \\ \[User name\] \\ **AppData** \\ **Roaming** +- **Application Settings Files** - Files that are stored under \\ **Users** \\ \[User name\] \\ **AppData** \\ **Roaming** The UE-V template generator excludes locations, which commonly store application software files, but do not synchronize well between user computers or environments. The UE-V template generator excludes these locations. Excluded locations are as follows: @@ -57,7 +57,7 @@ If registry keys and files that are stored in these locations are required to sy Use the UE-V template generator to edit settings location templates. When the revised settings are added to the templates with the UE-V template generator, the version information within the template is automatically updated to ensure that any existing templates that are deployed in the enterprise are updated correctly. -**To edit a UE-V settings location template with the UE-V template generator** +### To edit a UE-V settings location template with the UE-V template generator 1. Open the **Start** menu and navigate to **Windows Kits** > **Microsoft User Experience Virtualization (UE-V) Template Generator** to open the template generator. @@ -91,7 +91,7 @@ Use the UE-V template generator to edit settings location templates. When the re After you edit the settings location template for an application, you should test the template. Deploy the revised settings location template in a lab environment before you put it into production in the enterprise. -**How to manually edit a settings location template** +### How to manually edit a settings location template 1. Create a local copy of the settings location template .xml file. UE-V settings location templates are .xml files that identify the locations where application store settings values. @@ -108,14 +108,14 @@ Use the UE-V template generator to edit settings location templates. When the re 6. Validate the modified settings location template file by using the UE-V template generator. -7. You must register the edited UE-V settings location template before it can synchronize settings between client computers. To register a template, open Windows PowerShell, and then run the following cmdlet: `update-uevtemplate [templatefilename]`. You can then copy the file to the settings storage catalog. The UE-V Agent on users’ computers should then update as scheduled in the scheduled task. +7. You must register the edited UE-V settings location template before it can synchronize settings between client computers. To register a template, open Windows PowerShell, and then run the following cmdlet: `update-uevtemplate [templatefilename]`. You can then copy the file to the settings storage catalog. The UE-V Agent on users' computers should then update as scheduled in the scheduled task. ## Validate settings location templates with the UE-V template generator It is possible to create or edit settings location templates in an XML editor without using the UE-V template generator. If you do, you can use the UE-V template generator to validate that the new or revised XML matches the schema that has been defined for the template. -**To validate a UE-V settings location template with the UE-V template generator** +To validate a UE-V settings location template with the UE-V template generator: 1. Open the **Start** menu and navigate to **Windows Kits** > **Microsoft User Experience Virtualization (UE-V) Template Generator** to open the template generator. @@ -129,35 +129,8 @@ It is possible to create or edit settings location templates in an XML editor wi After you validate the settings location template for an application, you should test the template. Deploy the template in a lab environment before you put it into a production environment in enterprise. -## Share settings location templates with the Template Gallery - -The [User Experience Virtualization Template Gallery](https://gallery.technet.microsoft.com/site/search?f%5B0%5D.Type=RootCategory&f%5B0%5D.Value=UE-V&f%5B0%5D.Text=UE-V) enables administrators to share their UE-V settings location templates. Upload your settings location templates to the gallery for other users to use, and download templates that other users have created. - -Before you share a settings location template on the UE-V template gallery, ensure it does not contain any personal or company information. You can use any XML viewer to open and view the contents of a settings location template file. The following template values should be reviewed before you share a template with anyone outside your company. - -- Template Author Name – Specify a general, non-identifying name for the template author name or exclude this data from the template. - -- Template Author Email – Specify a general, non-identifying template author email or exclude this data from the template. - -Before you deploy any settings location template that you have downloaded from the UE-V gallery, you should first test the template to ensure that the application settings synchronize settings correctly in a test environment. - - - - - - -## Related topics - +## Next steps [Administering UE-V](uev-administering-uev.md) [Use UE-V with custom applications](uev-deploy-uev-for-custom-applications.md) - - - - - - - - - diff --git a/windows/deployment/update/windows-update-errors.md b/windows/deployment/update/windows-update-errors.md index 7da37ac391..aaf93bbafd 100644 --- a/windows/deployment/update/windows-update-errors.md +++ b/windows/deployment/update/windows-update-errors.md @@ -7,7 +7,6 @@ ms.author: aaroncz manager: dougeby ms.reviewer: kaushika ms.topic: troubleshooting -ms.custom: seo-marvel-apr2020 ms.collection: highpri --- @@ -42,7 +41,7 @@ The following table provides information about common errors you might run into | Message | Description | Mitigation | |---------|-------------|------------| -| BG_E_VALIDATION_FAILED | NA | Ensure that there are no firewalls that filter downloads. Such filtering could lead to incorrect responses being received by the Windows Update client.

    If the issue still persists, run the [Windows Update reset script](https://gallery.technet.microsoft.com/scriptcenter/Reset-Windows-Update-Agent-d824badc).| +| BG_E_VALIDATION_FAILED | NA | Ensure that there are no firewalls that filter downloads. Such filtering could lead to incorrect responses being received by the Windows Update client.| ## 0x80072EFD or 0x80072EFE or 0x80D02002 @@ -84,7 +83,7 @@ The following table provides information about common errors you might run into | Message | Description | Mitigation | |---------|-------------|------------| -| WU_E_CALL_CANCELLED | Operation was canceled. | The operation was canceled by the user or service. You might also receive this error when we're unable to filter the results. Run the [Decline Superseded PowerShell script](https://gallery.technet.microsoft.com/scriptcenter/Cleanup-WSUS-server-4424c9d6) to allow the filtering process to complete. | +| WU_E_CALL_CANCELLED | Operation was canceled. | The operation was canceled by the user or service. You might also receive this error when we're unable to filter the results. | ## 0x8024000E @@ -96,19 +95,19 @@ The following table provides information about common errors you might run into | Message | Description | Mitigation | |---------|-------------|------------| -| WU_E_SETUP_SKIP_UPDATE | An update to the Windows Update Agent was skipped due to a directive in the Wuident.cab file. | You might encounter this error when WSUS is not sending the self-update to the clients.

    Review [KB920659](/troubleshoot/windows-server/deployment/wsus-selfupdate-not-send-automatic-updates) for instructions to resolve the issue. | +| WU_E_SETUP_SKIP_UPDATE | An update to the Windows Update Agent was skipped due to a directive in the Wuident.cab file. | You might encounter this error when WSUS is not sending the self-update to the clients.

    For more information to resolve the issue, review [KB920659](/troubleshoot/windows-server/deployment/wsus-selfupdate-not-send-automatic-updates). | ## 0x80244007 | Message | Description | Mitigation | |---------|-------------|------------| -| WU_E_PT_SOAPCLIENT_SOAPFAULT | SOAP client failed because there was a SOAP fault for reasons of WU_E_PT_SOAP_\* error codes. | This issue occurs because Windows can't renew the cookies for Windows Update.

    Review [KB2883975](https://support.microsoft.com/help/2883975/0x80244007-error-when-windows-tries-to-scan-for-updates-on-a-wsus-serv) for instructions to resolve the issue. | +| WU_E_PT_SOAPCLIENT_SOAPFAULT | SOAP client failed because there was a SOAP fault for reasons of `WU_E_PT_SOAP_*` error codes. | This issue occurs because Windows can't renew the cookies for Windows Update.

    For more information to resolve the issue, see [0x80244007 error when Windows tries to scan for updates on a WSUS server](https://support.microsoft.com/topic/0x80244007-error-when-windows-tries-to-scan-for-updates-on-a-wsus-server-6af342d9-9af6-f3bb-b6ad-2be56bf7826e). | ## 0x80070422 | Message | Description | Mitigation | |---------|-------------|------------| -| NA | This issue occurs when the Windows Update service stops working or isn't running. | Check if the Windows Update service is running.
    | +| NA | This issue occurs when the Windows Update service stops working or isn't running. | Check if the Windows Update service is running. | ## 0x800f0821 @@ -145,7 +144,7 @@ The following table provides information about common errors you might run into | Message | Description | Mitigation | |---------|-------------|------------| -| E_ACCESSDENIED; General access denied error | File system or registry key permissions have been changed and the servicing stack doesn't have the required level of access. | This error generally means an access was denied.
    Go to %Windir%\logs\CBS, open the last CBS.log and search for “, error” and match with the timestamp. After finding the error, scroll up and try to determine what caused the access denial. It could be access denied to a file, registry key. Determine what object needs the right permissions and change the permissions as needed. | +| E_ACCESSDENIED; General access denied error | File system or registry key permissions have been changed and the servicing stack doesn't have the required level of access. | This error generally means an access was denied.
    Go to %Windir%\logs\CBS, open the last CBS.log and search for ", error" and match with the timestamp. After finding the error, scroll up and try to determine what caused the access denial. It could be access denied to a file, registry key. Determine what object needs the right permissions and change the permissions as needed. | ## 0x80070570 @@ -158,14 +157,14 @@ The following table provides information about common errors you might run into | Message | Description | Mitigation | |---------|-------------|------------| -| ERROR_PATH_NOT_FOUND; The system cannot find the path specified. | The servicing stack cannot access a specific path. | Indicates an invalid path to an executable. Go to %Windir%\logs\CBS, open the last CBS.log, and search for “, error” and match with the timestamp. | +| ERROR_PATH_NOT_FOUND; The system cannot find the path specified. | The servicing stack cannot access a specific path. | Indicates an invalid path to an executable. Go to %Windir%\logs\CBS, open the last CBS.log, and search for `, error`. Then match the results with the timestamp. | ## 0x80070020 | Message | Description | Mitigation | |---------|-------------|------------| -| ERROR_SHARING_VIOLATION | Numerous causes. CBS log analysis required. | This error is usually caused by non-Microsoft filter drivers like antivirus.
    1. [Perform a clean boot and retry the installation](https://support.microsoft.com/help/929135/)
    2. Download the sysinternal tool [Process Monitor](/sysinternals/downloads/procmon).
    3. Run Procmon.exe. It will start data capture automatically.
    4. Install the update package again
    5. With the Process Monitor main window in focus, press CTRL + E or select the magnifying glass to stop data capture.
    6. Select **File > Save > All Events > PML**, and choose a path to save the .PML file
    7. Go to %windir%\logs\cbs, open the last Cbs.log file, and search for the error. After finding the error line a bit above, you should have the file being accessed during the installation that is giving the sharing violation error
    8. In Process Monitor, filter for path and insert the file name (it should be something like “path” “contains” “filename from CBS”).
    9. Try to stop it or uninstall the process causing the error. | +| ERROR_SHARING_VIOLATION | Numerous causes. CBS log analysis required. | This error is usually caused by non-Microsoft filter drivers like antivirus.
    1. [Perform a clean boot and retry the installation](https://support.microsoft.com/topic/how-to-perform-a-clean-boot-in-windows-da2f9573-6eec-00ad-2f8a-a97a1807f3dd)
    2. Download the sysinternal tool [Process Monitor](/sysinternals/downloads/procmon).
    3. Run Procmon.exe. It will start data capture automatically.
    4. Install the update package again
    5. With the Process Monitor main window in focus, press CTRL + E or select the magnifying glass to stop data capture.
    6. Select **File > Save > All Events > PML**, and choose a path to save the .PML file
    7. Go to %windir%\logs\cbs, open the last Cbs.log file, and search for the error. After finding the error line a bit above, you should have the file being accessed during the installation that is giving the sharing violation error
    8. In Process Monitor, filter for path and insert the file name (it should be something like "path" "contains" "filename from CBS").
    9. Try to stop it or uninstall the process causing the error. | ## 0x80073701 @@ -183,19 +182,19 @@ The following table provides information about common errors you might run into | Message | Description | Mitigation | |---------|-------------|------------| -| WININET_E_CONNECTION_ABORTED; The connection with the server was closed abnormally | BITS is unable to transfer the file successfully. | Encountered if BITS is broken or if the file being transferred can't be written to the destination folder on the client. This error is usually caused by connection errors while checking or downloading updates.
    From a cmd prompt run: *BITSADMIN /LIST /ALLUSERS /VERBOSE*
    Search for the 0x80072EFE error code. You should see a reference to an HTTP code with a specific file. Using a browser, try to download it manually, making sure you’re using your organization's proxy settings. If the download fails, check with your proxy manager to allow for the communication to be sucesfull. Also check with your network team for this specific URL access. | +| WININET_E_CONNECTION_ABORTED; The connection with the server was closed abnormally | BITS is unable to transfer the file successfully. | Encountered if BITS is broken or if the file being transferred can't be written to the destination folder on the client. This error is usually caused by connection errors while checking or downloading updates.
    From a cmd prompt run: *BITSADMIN /LIST /ALLUSERS /VERBOSE*
    Search for the 0x80072EFE error code. You should see a reference to an HTTP code with a specific file. Using a browser, try to download it manually, making sure you're using your organization's proxy settings. If the download fails, check with your proxy manager to allow for the communication to be sucesfull. Also check with your network team for this specific URL access. | ## 0x80072F8F | Message | Description | Mitigation | |---------|-------------|------------| -| WININET_E_DECODING_FAILED; Content decoding has failed | TLS 1.2 is not configured correctly on the client. | This error generally means that the Windows Update Agent was unable to decode the received content. Install and configure TLS 1.2 by installing the update in [KB3140245](https://support.microsoft.com/help/3140245/). +| WININET_E_DECODING_FAILED; Content decoding has failed | TLS 1.2 is not configured correctly on the client. | This error generally means that the Windows Update Agent was unable to decode the received content. Install and configure TLS 1.2 by installing the update in [KB3140245](https://support.microsoft.com/topic/update-to-enable-tls-1-1-and-tls-1-2-as-default-secure-protocols-in-winhttp-in-windows-c4bd73d2-31d7-761e-0178-11268bb10392). ## 0x80072EE2 | Message | Description | Mitigation | |---------|-------------|------------| -| WININET_E_TIMEOUT; The operation timed out | Unable to scan for updates due to a connectivity issue to Windows Update, Configuration Manager, or WSUS. | This error generally means that the Windows Update Agent was unable to connect to the update servers or your own source, such as WSUS, Configuration Manager, or Microsoft Endpoint Manager.
    Check with your network team to ensure that the device can reach the update sources. For more info, see [Troubleshoot software update scan failures in Configuration Manager](/troubleshoot/mem/configmgr/troubleshoot-software-update-scan-failures).
    If you’re using the public Microsoft update servers, check that your device can access the following Windows Update endpoints:
    `http://windowsupdate.microsoft.com`
    `https://*.windowsupdate.microsoft.com`
    `https://update.microsoft.com`
    `https://*.update.microsoft.com`
    `https://windowsupdate.com`
    `https://*.windowsupdate.com`
    `https://download.windowsupdate.com`
    `https://*.download.windowsupdate.com`
    `https://download.microsoft.com`
    `https://*.download.windowsupdate.com`
    `https://wustat.windows.com`
    `https://*.wustat.windows.com`
    `https://ntservicepack.microsoft.com` | +| WININET_E_TIMEOUT; The operation timed out | Unable to scan for updates due to a connectivity issue to Windows Update, Configuration Manager, or WSUS. | This error generally means that the Windows Update Agent was unable to connect to the update servers or your own source, such as WSUS, Configuration Manager, or Microsoft Endpoint Manager.
    Check with your network team to ensure that the device can reach the update sources. For more info, see [Troubleshoot software update scan failures in Configuration Manager](/troubleshoot/mem/configmgr/troubleshoot-software-update-scan-failures).
    If you're using the public Microsoft update servers, check that your device can access the following Windows Update endpoints:
    `http://windowsupdate.microsoft.com`
    `https://*.windowsupdate.microsoft.com`
    `https://update.microsoft.com`
    `https://*.update.microsoft.com`
    `https://windowsupdate.com`
    `https://*.windowsupdate.com`
    `https://download.windowsupdate.com`
    `https://*.download.windowsupdate.com`
    `https://download.microsoft.com`
    `https://*.download.windowsupdate.com`
    `https://wustat.windows.com`
    `https://*.wustat.windows.com`
    `https://ntservicepack.microsoft.com` | ## 0x80240022 diff --git a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md index 3193b11f86..5649bb9859 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md @@ -2,63 +2,55 @@ title: Network access - Restrict clients allowed to make remote calls to SAM description: Security policy setting that controls which users can enumerate users and groups in the local Security Accounts Manager (SAM) database. ms.prod: m365-security -ms.mktglfcycl: explore -ms.sitesec: library -ms.pagetype: security +ms.technology: windows-sec ms.localizationpriority: medium -author: dansimp ms.date: 09/17/2018 +author: dansimp +ms.author: dansimp ms.reviewer: manager: dansimp -ms.author: dansimp -ms.technology: windows-sec --- # Network access: Restrict clients allowed to make remote calls to SAM **Applies to** -- Windows 10, version 1607 and later -- Windows 10, version 1511 with [KB 4103198](https://support.microsoft.com/help/4013198) installed -- Windows 10, version 1507 with [KB 4012606](https://support.microsoft.com/help/4012606) installed -- Windows 8.1 with [KB 4102219](https://support.microsoft.com/help/4012219/march-2017-preview-of-monthly-quality-rollup-for-windows-8-1-and-windows-server-2012-r2) installed -- Windows 7 with [KB 4012218](https://support.microsoft.com/help/4012218/march-2017-preview-of-monthly-quality-rollup-for-windows-7-sp1-and-windows-server-2008-r2-sp1) installed -- Windows Server 2019 -- Windows Server 2016 -- Windows Server 2012 R2 with[KB 4012219](https://support.microsoft.com/help/4012219/march-2017-preview-of-monthly-quality-rollup-for-windows-8-1-and-windows-server-2012-r2) installed -- Windows Server 2012 with [KB 4012220](https://support.microsoft.com/help/4012220/march-2017-preview-of-monthly-quality-rollup-for-windows-server-2012) installed -- Windows Server 2008 R2 with [KB 4012218](https://support.microsoft.com/help/4012218/march-2017-preview-of-monthly-quality-rollup-for-windows-7-sp1-and-windows-server-2008-r2-sp1) installed +- Windows 10 +- Windows 8.1 +- Windows Server 2019 +- Windows Server 2016 +- Windows Server 2012 R2 -The **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting controls which users can enumerate users and groups in the local Security Accounts Manager (SAM) database and Active Directory. -The setting was first supported by Windows 10 version 1607 and Windows Server 2016 (RTM) and can be configured on earlier Windows client and server operating systems by installing updates from the KB articles listed in **Applies to** section of this topic. +The **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting controls which users can enumerate users and groups in the local Security Accounts Manager (SAM) database and Active Directory. +The setting was first supported by Windows 10 version 1607 and Windows Server 2016 (RTM) and can be configured on earlier Windows client and server operating systems. -This topic describes the default values for this security policy setting in different versions of Windows. -By default, computers beginning with Windows 10 version 1607 and Windows Server 2016 are more restrictive than earlier versions of Windows. +This article describes the default values for this security policy setting in different versions of Windows. +By default, computers beginning with Windows 10 version 1607 and Windows Server 2016 are more restrictive than earlier versions of Windows. This restrictive characteristic means that if you have a mix of computers, such as member servers that run both Windows Server 2016 and Windows Server 2012 R2, the servers that run Windows Server 2016 may fail to enumerate accounts by default where the servers that run Windows Server 2012 R2 succeed. -This topic also covers related events, and how to enable audit mode before constraining the security principals that are allowed to remotely enumerate users and groups so that your environment remains secure without impacting application compatibility. +This article also covers related events, and how to enable audit mode before constraining the security principals that are allowed to remotely enumerate users and groups so that your environment remains secure without impacting application compatibility. > [!NOTE] > Implementation of this policy [could affect offline address book generation](/troubleshoot/windows-server/group-policy/authz-fails-access-denied-error-application-access-check) on servers running Microsoft Exchange 2016 or Microsoft Exchange 2013. ## Reference -The SAMRPC protocol makes it possible for a low privileged user to query a machine on a network for data. -For example, a user can use SAMRPC to enumerate users, including privileged accounts such as local or domain administrators, or to enumerate groups and group memberships from the local SAM and Active Directory. -This information can provide important context and serve as a starting point for an attacker to compromise a domain or networking environment. +The SAMRPC protocol makes it possible for a low privileged user to query a machine on a network for data. +For example, a user can use SAMRPC to enumerate users, including privileged accounts such as local or domain administrators, or to enumerate groups and group memberships from the local SAM and Active Directory. +This information can provide important context and serve as a starting point for an attacker to compromise a domain or networking environment. -To mitigate this risk, you can configure the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting to force the security accounts manager (SAM) to do an access check against remote calls. -The access check allows or denies remote RPC connections to SAM and Active Directory for users and groups that you define. +To mitigate this risk, you can configure the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting to force the security accounts manager (SAM) to do an access check against remote calls. +The access check allows or denies remote RPC connections to SAM and Active Directory for users and groups that you define. -By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. -If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to the SAM. -If the policy setting is left blank after the policy is defined, the policy isn't enforced. +By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. +If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to the SAM. +If the policy setting is left blank after the policy is defined, the policy isn't enforced. -The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers, and allows Everyone access on domain controllers. +The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers, and allows Everyone access on domain controllers. You can edit the default security descriptor to allow or deny other users and groups, including the built-in Administrators. -The default security descriptor on computers that run earlier versions of Windows doesn't restrict any remote calls to SAM, but an administrator can edit the security descriptor to enforce restrictions. -This less restrictive default allows for testing the impact of enabling restrictions on existing applications. +The default security descriptor on computers that run earlier versions of Windows doesn't restrict any remote calls to SAM, but an administrator can edit the security descriptor to enforce restrictions. +This less restrictive default allows for testing the affect of enabling restrictions on existing applications. ## Policy and Registry Names @@ -71,29 +63,30 @@ This less restrictive default allows for testing the impact of enabling restrict | **Registry type** | REG_SZ | | **Registry value** | A string that will contain the SDDL of the security descriptor to be deployed. | -The Group Policy setting is only available on computers that run Windows Server 2016 or Windows 10, version 1607 and later. +The Group Policy setting is only available on computers that run Windows Server 2016 or Windows 10, version 1607 and later. These computers are the only option to configure this setting by using a user interface (UI). -On computers that run earlier versions of Windows, you need to edit the registry setting directly or use Group Policy Preferences. -To avoid setting it manually in this case, you can configure the GPO itself on a computer that runs Windows Server 2016 or Windows 10, version 1607 or later and have it apply to all computers within the scope of the GPO because the same registry key exists on every computer after the corresponding KB is installed. +On computers that run earlier versions of Windows, you need to edit the registry setting directly or use Group Policy Preferences. +To avoid setting it manually in this case, you can configure the GPO itself on a computer that runs Windows Server 2016 or Windows 10, version 1607 or later and have it apply to all computers within the scope of the GPO because the same registry key exists on every computer after the corresponding KB is installed. > [!NOTE] -> This policy is implemented similarly to other "Network access" policies in that there is a single policy element at the registry path listed. There is no notion of a local policy versus an enterprise policy; there is just one policy setting and whichever writes last wins. -> -> For example, suppose a local administrator configures this setting as part of a local policy using the Local Security Policy snap-in (Secpol.msc), which edits that same registry path. If an enterprise administrator configures this setting as part of an enterprise GPO, that enterprise GPO will overwrite the same registry path. +> This policy is implemented similarly to other "Network access" policies in that there is a single policy element at the registry path listed. There is no notion of a local policy versus an enterprise policy; there is just one policy setting and whichever writes last wins. +> +> For example, suppose a local administrator configures this setting as part of a local policy using the Local Security Policy snap-in (Secpol.msc), which edits that same registry path. If an enterprise administrator configures this setting as part of an enterprise GPO, that enterprise GPO will overwrite the same registry path. ## Default values -Beginning with Windows 10, version 1607 and Windows Server 2016, computers have hard-coded and more restrictive default values than earlier versions of Windows. -The different default values help strike a balance where recent Windows versions are more secure by default and older versions don’t undergo any disruptive behavior changes. -Administrators can test whether applying the same restriction earlier versions of Windows will cause compatibility problems for existing applications before implementing this security policy setting in a production environment. + +Beginning with Windows 10, version 1607 and Windows Server 2016, computers have hard-coded and more restrictive default values than earlier versions of Windows. +The different default values help strike a balance where recent Windows versions are more secure by default and older versions don't undergo any disruptive behavior changes. +Administrators can test whether applying the same restriction earlier versions of Windows will cause compatibility problems for existing applications before implementing this security policy setting in a production environment. In other words, the hotfix in each KB article provides the necessary code and functionality, but you need to configure the restriction after you install the hotfix—no restrictions are enabled by default after the hotfix is installed on earlier versions of Windows. -| |Default SDDL |Translated SDDL| Comments | +| |Default SDDL |Translated SDDL| Comments | |---|---|---|---| -|**Windows Server 2016 (or later) domain controller (reading Active Directory)**|“”|-|Everyone has read permissions to preserve compatibility.| +|**Windows Server 2016 (or later) domain controller (reading Active Directory)**|""|-|Everyone has read permissions to preserve compatibility.| |**Earlier domain controller** |-|-|No access check is performed by default.| -|**Windows 10, version 1607 (or later) non-domain controller**|O:SYG:SYD:(A;;RC;;;BA)| Owner: NTAUTHORITY/SYSTEM (WellKnownGroup) (S-1-5-18)
    Primary group: NTAUTHORITY/SYSTEM (WellKnownGroup) (S-1-5-18)
    DACL:
    • Revision: 0x02
    • Size: 0x0020
    • Ace Count: 0x001
    • Ace[00]-------------------------
      AceType:0x00
      (ACCESS\_ALLOWED_ACE_TYPE)
      AceSize:0x0018
      InheritFlags:0x00
      Access Mask:0x00020000
      AceSid: BUILTIN\Administrators (Alias) (S-1-5-32-544)

      SACL: Not present |Grants RC access (READ_CONTROL, also known as STANDARD_RIGHTS_READ) only to members of the local (built-in) Administrators group. | +|**Windows 10, version 1607 (or later) non-domain controller**|`O:SYG:SYD:(A;;RC;;;BA)`| Owner: NTAUTHORITY/SYSTEM (WellKnownGroup) (S-1-5-18)
    Primary group: NTAUTHORITY/SYSTEM (WellKnownGroup) (S-1-5-18)
    DACL:
    - Revision: 0x02
    - Size: 0x0020
    - Ace Count: 0x001
    - Ace[00]-------------------------
      AceType:0x00
      (ACCESS\_ALLOWED_ACE_TYPE)
      AceSize:0x0018
      InheritFlags:0x00
      Access Mask:0x00020000
      AceSid: BUILTIN\Administrators (Alias) (S-1-5-32-544)

      SACL: Not present |Grants RC access (READ_CONTROL, also known as STANDARD_RIGHTS_READ) only to members of the local (built-in) Administrators group. | |**Earlier non-domain controller** |-|-|No access check is performed by default.| ## Policy management @@ -110,16 +103,16 @@ Audit-only mode configures the SAMRPC protocol to do the access check against th |Setting|RestrictRemoteSamAuditOnlyMode| |Data Type|REG_DWORD| |Value|1| -|Notes|This setting can't be added or removed by using predefined Group Policy settings.
    Administrators may create a custom policy to set the registry value if needed.
    SAM responds dynamically to changes in this registry value without a reboot.
    You can use the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script to parse the event logs, as explained in the next section.| +|Notes|This setting can't be added or removed by using predefined Group Policy settings.
    Administrators may create a custom policy to set the registry value if needed.
    SAM responds dynamically to changes in this registry value without a reboot.| ### Related events There are corresponding events that indicate when remote calls to the SAM are restricted, what accounts attempted to read from the SAM database, and more. The following workflow is recommended to identify applications that may be affected by restricting remote calls to SAM: -1. Dump event logs to a common share. -2. Parse them with the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script. -3. Review Event IDs 16962 to 16969, as listed in the following table, in the System log with event source Directory-Service-SAM. -4. Identify which security contexts are enumerating users or groups in the SAM database. -5. Prioritize the callers, determine if they should be allowed or not, then include the allowed callers in the SDDL string. + +1. Dump event logs to a common share. +1. Review Event IDs 16962 to 16969, as listed in the following table, in the System log with event source Directory-Service-SAM. +1. Identify which security contexts are enumerating users or groups in the SAM database. +1. Prioritize the callers, determine if they should be allowed or not, then include the allowed callers in the SDDL string. |Event ID|Event Message Text|Explanation | |---|---|---| @@ -127,14 +120,15 @@ There are corresponding events that indicate when remote calls to the SAM are re |16963|Message Text: "Remote calls to the SAM database are being restricted using the configured registry security descriptor: %1.%n"

    %1 - "Registry SD String:" |Emit event when a new SDDL is read from the registry (either on startup or change) and is considered valid. The event includes the source and a copy of the queried SDDL. |16964|"The registry security descriptor is malformed: %1.%n Remote calls to the SAM database are being restricted using the default security descriptor: %2.%n"

    %1- "Malformed SD String:"
    %2- "Default SD String:"|Emit event when registry SDDL is mal-formed, causing fallback to default hard-coded SDDL (event should include a copy of the default SDDL). |16965|Message Text: "A remote call to the SAM database has been denied.%nClient SID: %1%n Network address: %2%n"

    %1- "Client SID:" %2- "Client Network Address | Emit event when access is denied to a remote client. Event should include identity and network address of the client. -|16966|Audit Mode is enabled-

    Message Text: "Audit only mode is now enabled for remote calls to the SAM database. SAM will log an event for clients who would have been denied access in normal mode. %n"|Emit event whenever training mode (see 16968) is enabled or disabled. +|16966|Audit Mode is enabled-

    Message Text: "Audit only mode is now enabled for remote calls to the SAM database. SAM will log an event for clients who would have been denied access in normal mode. %n"|Emit event whenever training mode (see 16968) is enabled or disabled. |16967|Audit Mode is disabled-

    Message Text: "Audit only mode is now disabled for remote calls to the SAM database.%n For more information"|Emit event whenever training mode (see 16968) is enabled or disabled. |16968| Message Text: "Audit only mode is currently enabled for remote calls to the SAM database.%n The following client would have been normally denied access:%nClient SID: %1 from network address: %2. %n"
    %1- "Client SID:"
    %2- "Client Network Address:"|Emit event when access would have been denied to a remote client, but was allowed through due to training mode being enabled. Event should include identity and network address of the client.| |16969|Message Text: "%2 remote calls to the SAM database have been denied in the past %1-seconds throttling window.%n
    "%1- "Throttle window:"
    %2- "Suppressed Message Count:"| Throttling may be necessary for some events due to expected high volume on some servers causing the event log to wrap.

    Note: There's no throttling of events when audit mode is enabled. Environments with a large number of low-privilege and anonymous querying of the remote database may see large numbers of events logged to the System log. For more info, see the [Event Throttling](#event-throttling) section. -Compare the security context attempting to remotely enumerate accounts with the default security descriptor. Then edit the security descriptor to add accounts that require remote access. +Compare the security context attempting to remotely enumerate accounts with the default security descriptor. Then edit the security descriptor to add accounts that require remote access. + +### Event throttling -### Event Throttling A busy server can flood event logs with events related to the remote enumeration access check. To prevent this, access-denied events are logged once every 15 minutes by default. The length of this period is controlled by the following registry value. |Registry Path|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\ | @@ -143,7 +137,7 @@ Setting |RestrictRemoteSamEventThrottlingWindow| Data Type |DWORD| |Value|seconds| |Reboot Required?|No| -|Notes|**Default** is 900 seconds – 15 mins.
    The throttling uses a suppressed events counter that starts at 0 and gets incremented during the throttling window.
    For example, X events were suppressed in the last 15 minutes.
    The counter is restarted after the event 16969 is logged. +|Notes|**Default** is 900 seconds (15 minutes).
    The throttling uses a suppressed events counter that starts at 0 and gets incremented during the throttling window.
    For example, X events were suppressed in the last 15 minutes.
    The counter is restarted after the event 16969 is logged. ### Restart requirement @@ -153,22 +147,24 @@ Restarts aren't required to enable, disable or modify the **Network access: Rest This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -### Vulnerability -The SAMRPC protocol has a default security posture that makes it possible for low-privileged attackers to query a machine on the network for data that is critical to their further hacking and penetration plans.

    +### Vulnerability + +The SAMRPC protocol has a default security posture that makes it possible for low-privileged attackers to query a machine on the network for data that is critical to their further hacking and penetration plans. + The following example illustrates how an attacker might exploit remote SAM enumeration: + 1. A low-privileged attacker gains a foothold on a network. -2. The attacker then queries all machines on the network to determine which ones have a highly privileged domain user configured as a local administrator on that machine. +2. The attacker then queries all machines on the network to determine which ones have a highly privileged domain user configured as a local administrator on that machine. 3. If the attacker can, then find any other vulnerability on that machine that allows taking it over, the attacker can then squat on the machine waiting for the high-privileged user to sign in and then steal or impersonate those credentials. ### Countermeasure + You can mitigate this vulnerability by enabling the **Network access: Restrict clients allowed to make remote calls** to SAM security policy setting and configuring the SDDL for only those accounts that are explicitly allowed access. -### Potential impact -If the policy is defined, admin tools, scripts and software that formerly enumerated users, groups and group membership may fail. To identify accounts that may be affected, test this setting in [audit only mode](#audit-only-mode). +### Potential affect + +If the policy is defined, admin tools, scripts and software that formerly enumerated users, groups and group membership may fail. To identify accounts that may be affected, test this setting in [audit only mode](#audit-only-mode). + +## Next steps -## Related Topics [Security Options](./security-options.md) - -[SAMRi10 - Hardening SAM Remote Access in Windows 10/Server 2016](https://gallery.technet.microsoft.com/SAMRi10-Hardening-Remote-48d94b5b) - -
    \ No newline at end of file From cbd0c71910b25f076bffc746036682f662c6b3bf Mon Sep 17 00:00:00 2001 From: Tiara Quan <95256667+tiaraquan@users.noreply.github.com> Date: Fri, 29 Jul 2022 08:25:20 -0700 Subject: [PATCH 099/109] Update windows-autopatch-prerequisites.md Added OS 10 and 1809 build as per Andre --- .../prepare/windows-autopatch-prerequisites.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md index 2d7ad54d04..2f4d13cfe0 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md @@ -39,7 +39,7 @@ Windows Autopatch is included with Window 10/11 Enterprise E3 or higher. The fol | [Windows 10/11 Enterprise E5](/azure/active-directory/enterprise-users/licensing-service-plan-reference) | WIN10_VDA_E5 | 488ba24a-39a9-4473-8ee5-19291e71b002 | | [Windows 10/11 Enterprise VDA](/windows/deployment/deploy-enterprise-licenses#virtual-desktop-access-vda) | E3_VDA_only | d13ef257-988a-46f3-8fce-f47484dd4550 | -The following Windows OS editions, builds and architecture are supported in Windows Autopatch: +The following Windows OS 10 editions, 1809 builds and architecture are supported in Windows Autopatch: - x64 architecture - Windows 10 (1809+)/11 Pro From 52b10ad8fe85089021d1f4314b33a65a58f6dbdd Mon Sep 17 00:00:00 2001 From: Tiara Quan <95256667+tiaraquan@users.noreply.github.com> Date: Fri, 29 Jul 2022 08:27:38 -0700 Subject: [PATCH 100/109] Update windows-autopatch-device-registration-overview.md --- .../windows-autopatch-device-registration-overview.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index a4df2a5a86..30c9b47f12 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -91,11 +91,11 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 7. Windows Autopatch also assigns devices to the following Azure AD groups when certain conditions apply: 1. **Modern Workplace Devices - All** 1. This group has all devices managed by Windows Autopatch. - 2. When registering Windows 10 devices - **Modern Workplace Devices Dynamic - Windows 10** + 2. When registering Windows 10 devices, use **Modern Workplace Devices Dynamic - Windows 10** 1. This group has all devices managed by Windows Autopatch and that have Windows 10 installed. - 3. When registering Windows 11 devices - **Modern Workplace Devices Dynamic - Windows 11** + 3. When registering Windows 11 devices, use **Modern Workplace Devices Dynamic - Windows 11** 1. This group has all devices managed by Windows Autopatch and that have Windows 11 installed. - 4. When registering virtual devices - **Modern Workplace Devices - Virtual Machine** + 4. When registering virtual devices, use **Modern Workplace Devices - Virtual Machine** 1. This group has all virtual devices managed by Windows Autopatch. 8. In post-device registration, three actions occur: 1. Windows Autopatch adds devices to its managed database. From f9530554f985a650162d989bf81b9fd35e217640 Mon Sep 17 00:00:00 2001 From: Aaron Czechowski Date: Fri, 29 Jul 2022 11:31:14 -0400 Subject: [PATCH 101/109] Update windows/client-management/mdm/policy-csp-update.md Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- windows/client-management/mdm/policy-csp-update.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/client-management/mdm/policy-csp-update.md b/windows/client-management/mdm/policy-csp-update.md index aff7ce985b..53012c6503 100644 --- a/windows/client-management/mdm/policy-csp-update.md +++ b/windows/client-management/mdm/policy-csp-update.md @@ -3253,7 +3253,7 @@ The table below shows the applicability of Windows: -Enables the IT admin to schedule the time of the update installation. Noting that there is a +/- 30 minute window to allow for higher success rates of installation. +Enables the IT admin to schedule the time of the update installation. Note that there is a window of approximately 30 minutes to allow for higher success rates of installation. The supported data type is an integer. From 1a7fe7381f1882d09eece61c3af0da84c535b829 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Fri, 29 Jul 2022 11:33:55 -0400 Subject: [PATCH 102/109] Update BC again --- windows/security/breadcrumb/toc.yml | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/windows/security/breadcrumb/toc.yml b/windows/security/breadcrumb/toc.yml index 56a1f207bc..6c5b49c520 100644 --- a/windows/security/breadcrumb/toc.yml +++ b/windows/security/breadcrumb/toc.yml @@ -9,8 +9,4 @@ items: items: - name: Security tocHref: /windows/security/ - topicHref: /windows/security/ - items: - - name: User security - tocHref: /windows-server/security/credentials-protection-and-management/ - topicHref: /windows/security/identity + topicHref: /windows/security/ From 4ab66d679d662bddd4e99141c862978955e9380d Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Fri, 29 Jul 2022 13:34:53 -0400 Subject: [PATCH 103/109] Remove reference to broken script --- ...lients-allowed-to-make-remote-sam-calls.md | 92 ++++++++++--------- 1 file changed, 47 insertions(+), 45 deletions(-) diff --git a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md index 3193b11f86..3494cc9cc3 100644 --- a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md +++ b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md @@ -8,7 +8,7 @@ ms.pagetype: security ms.localizationpriority: medium author: dansimp ms.date: 09/17/2018 -ms.reviewer: +ms.reviewer: manager: dansimp ms.author: dansimp ms.technology: windows-sec @@ -17,47 +17,47 @@ ms.technology: windows-sec # Network access: Restrict clients allowed to make remote calls to SAM **Applies to** -- Windows 10, version 1607 and later -- Windows 10, version 1511 with [KB 4103198](https://support.microsoft.com/help/4013198) installed -- Windows 10, version 1507 with [KB 4012606](https://support.microsoft.com/help/4012606) installed -- Windows 8.1 with [KB 4102219](https://support.microsoft.com/help/4012219/march-2017-preview-of-monthly-quality-rollup-for-windows-8-1-and-windows-server-2012-r2) installed -- Windows 7 with [KB 4012218](https://support.microsoft.com/help/4012218/march-2017-preview-of-monthly-quality-rollup-for-windows-7-sp1-and-windows-server-2008-r2-sp1) installed -- Windows Server 2019 -- Windows Server 2016 -- Windows Server 2012 R2 with[KB 4012219](https://support.microsoft.com/help/4012219/march-2017-preview-of-monthly-quality-rollup-for-windows-8-1-and-windows-server-2012-r2) installed -- Windows Server 2012 with [KB 4012220](https://support.microsoft.com/help/4012220/march-2017-preview-of-monthly-quality-rollup-for-windows-server-2012) installed -- Windows Server 2008 R2 with [KB 4012218](https://support.microsoft.com/help/4012218/march-2017-preview-of-monthly-quality-rollup-for-windows-7-sp1-and-windows-server-2008-r2-sp1) installed +- Windows 10, version 1607 and later +- Windows 10, version 1511 with [KB 4103198](https://support.microsoft.com/help/4013198) installed +- Windows 10, version 1507 with [KB 4012606](https://support.microsoft.com/help/4012606) installed +- Windows 8.1 with [KB 4102219](https://support.microsoft.com/help/4012219/march-2017-preview-of-monthly-quality-rollup-for-windows-8-1-and-windows-server-2012-r2) installed +- Windows 7 with [KB 4012218](https://support.microsoft.com/help/4012218/march-2017-preview-of-monthly-quality-rollup-for-windows-7-sp1-and-windows-server-2008-r2-sp1) installed +- Windows Server 2019 +- Windows Server 2016 +- Windows Server 2012 R2 with[KB 4012219](https://support.microsoft.com/help/4012219/march-2017-preview-of-monthly-quality-rollup-for-windows-8-1-and-windows-server-2012-r2) installed +- Windows Server 2012 with [KB 4012220](https://support.microsoft.com/help/4012220/march-2017-preview-of-monthly-quality-rollup-for-windows-server-2012) installed +- Windows Server 2008 R2 with [KB 4012218](https://support.microsoft.com/help/4012218/march-2017-preview-of-monthly-quality-rollup-for-windows-7-sp1-and-windows-server-2008-r2-sp1) installed -The **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting controls which users can enumerate users and groups in the local Security Accounts Manager (SAM) database and Active Directory. -The setting was first supported by Windows 10 version 1607 and Windows Server 2016 (RTM) and can be configured on earlier Windows client and server operating systems by installing updates from the KB articles listed in **Applies to** section of this topic. +The **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting controls which users can enumerate users and groups in the local Security Accounts Manager (SAM) database and Active Directory. +The setting was first supported by Windows 10 version 1607 and Windows Server 2016 (RTM) and can be configured on earlier Windows client and server operating systems by installing updates from the KB articles listed in **Applies to** section of this topic. This topic describes the default values for this security policy setting in different versions of Windows. -By default, computers beginning with Windows 10 version 1607 and Windows Server 2016 are more restrictive than earlier versions of Windows. +By default, computers beginning with Windows 10 version 1607 and Windows Server 2016 are more restrictive than earlier versions of Windows. This restrictive characteristic means that if you have a mix of computers, such as member servers that run both Windows Server 2016 and Windows Server 2012 R2, the servers that run Windows Server 2016 may fail to enumerate accounts by default where the servers that run Windows Server 2012 R2 succeed. -This topic also covers related events, and how to enable audit mode before constraining the security principals that are allowed to remotely enumerate users and groups so that your environment remains secure without impacting application compatibility. +This topic also covers related events, and how to enable audit mode before constraining the security principals that are allowed to remotely enumerate users and groups so that your environment remains secure without impacting application compatibility. > [!NOTE] > Implementation of this policy [could affect offline address book generation](/troubleshoot/windows-server/group-policy/authz-fails-access-denied-error-application-access-check) on servers running Microsoft Exchange 2016 or Microsoft Exchange 2013. ## Reference -The SAMRPC protocol makes it possible for a low privileged user to query a machine on a network for data. -For example, a user can use SAMRPC to enumerate users, including privileged accounts such as local or domain administrators, or to enumerate groups and group memberships from the local SAM and Active Directory. -This information can provide important context and serve as a starting point for an attacker to compromise a domain or networking environment. +The SAMRPC protocol makes it possible for a low privileged user to query a machine on a network for data. +For example, a user can use SAMRPC to enumerate users, including privileged accounts such as local or domain administrators, or to enumerate groups and group memberships from the local SAM and Active Directory. +This information can provide important context and serve as a starting point for an attacker to compromise a domain or networking environment. -To mitigate this risk, you can configure the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting to force the security accounts manager (SAM) to do an access check against remote calls. -The access check allows or denies remote RPC connections to SAM and Active Directory for users and groups that you define. +To mitigate this risk, you can configure the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting to force the security accounts manager (SAM) to do an access check against remote calls. +The access check allows or denies remote RPC connections to SAM and Active Directory for users and groups that you define. -By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. -If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to the SAM. -If the policy setting is left blank after the policy is defined, the policy isn't enforced. +By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. +If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to the SAM. +If the policy setting is left blank after the policy is defined, the policy isn't enforced. -The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers, and allows Everyone access on domain controllers. +The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers, and allows Everyone access on domain controllers. You can edit the default security descriptor to allow or deny other users and groups, including the built-in Administrators. -The default security descriptor on computers that run earlier versions of Windows doesn't restrict any remote calls to SAM, but an administrator can edit the security descriptor to enforce restrictions. +The default security descriptor on computers that run earlier versions of Windows doesn't restrict any remote calls to SAM, but an administrator can edit the security descriptor to enforce restrictions. This less restrictive default allows for testing the impact of enabling restrictions on existing applications. ## Policy and Registry Names @@ -71,21 +71,22 @@ This less restrictive default allows for testing the impact of enabling restrict | **Registry type** | REG_SZ | | **Registry value** | A string that will contain the SDDL of the security descriptor to be deployed. | -The Group Policy setting is only available on computers that run Windows Server 2016 or Windows 10, version 1607 and later. +The Group Policy setting is only available on computers that run Windows Server 2016 or Windows 10, version 1607 and later. These computers are the only option to configure this setting by using a user interface (UI). -On computers that run earlier versions of Windows, you need to edit the registry setting directly or use Group Policy Preferences. -To avoid setting it manually in this case, you can configure the GPO itself on a computer that runs Windows Server 2016 or Windows 10, version 1607 or later and have it apply to all computers within the scope of the GPO because the same registry key exists on every computer after the corresponding KB is installed. +On computers that run earlier versions of Windows, you need to edit the registry setting directly or use Group Policy Preferences. +To avoid setting it manually in this case, you can configure the GPO itself on a computer that runs Windows Server 2016 or Windows 10, version 1607 or later and have it apply to all computers within the scope of the GPO because the same registry key exists on every computer after the corresponding KB is installed. > [!NOTE] -> This policy is implemented similarly to other "Network access" policies in that there is a single policy element at the registry path listed. There is no notion of a local policy versus an enterprise policy; there is just one policy setting and whichever writes last wins. -> -> For example, suppose a local administrator configures this setting as part of a local policy using the Local Security Policy snap-in (Secpol.msc), which edits that same registry path. If an enterprise administrator configures this setting as part of an enterprise GPO, that enterprise GPO will overwrite the same registry path. +> This policy is implemented similarly to other "Network access" policies in that there is a single policy element at the registry path listed. There is no notion of a local policy versus an enterprise policy; there is just one policy setting and whichever writes last wins. +> +> For example, suppose a local administrator configures this setting as part of a local policy using the Local Security Policy snap-in (Secpol.msc), which edits that same registry path. If an enterprise administrator configures this setting as part of an enterprise GPO, that enterprise GPO will overwrite the same registry path. ## Default values -Beginning with Windows 10, version 1607 and Windows Server 2016, computers have hard-coded and more restrictive default values than earlier versions of Windows. -The different default values help strike a balance where recent Windows versions are more secure by default and older versions don’t undergo any disruptive behavior changes. -Administrators can test whether applying the same restriction earlier versions of Windows will cause compatibility problems for existing applications before implementing this security policy setting in a production environment. + +Beginning with Windows 10, version 1607 and Windows Server 2016, computers have hard-coded and more restrictive default values than earlier versions of Windows. +The different default values help strike a balance where recent Windows versions are more secure by default and older versions don’t undergo any disruptive behavior changes. +Administrators can test whether applying the same restriction earlier versions of Windows will cause compatibility problems for existing applications before implementing this security policy setting in a production environment. In other words, the hotfix in each KB article provides the necessary code and functionality, but you need to configure the restriction after you install the hotfix—no restrictions are enabled by default after the hotfix is installed on earlier versions of Windows. @@ -110,16 +111,17 @@ Audit-only mode configures the SAMRPC protocol to do the access check against th |Setting|RestrictRemoteSamAuditOnlyMode| |Data Type|REG_DWORD| |Value|1| -|Notes|This setting can't be added or removed by using predefined Group Policy settings.
    Administrators may create a custom policy to set the registry value if needed.
    SAM responds dynamically to changes in this registry value without a reboot.
    You can use the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script to parse the event logs, as explained in the next section.| +|Notes|This setting can't be added or removed by using predefined Group Policy settings. Administrators may create a custom policy to set the registry value if needed. SAM responds dynamically to changes in this registry value without a reboot. | ### Related events There are corresponding events that indicate when remote calls to the SAM are restricted, what accounts attempted to read from the SAM database, and more. The following workflow is recommended to identify applications that may be affected by restricting remote calls to SAM: -1. Dump event logs to a common share. -2. Parse them with the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script. -3. Review Event IDs 16962 to 16969, as listed in the following table, in the System log with event source Directory-Service-SAM. -4. Identify which security contexts are enumerating users or groups in the SAM database. -5. Prioritize the callers, determine if they should be allowed or not, then include the allowed callers in the SDDL string. + +1. Dump event logs to a common share. +1. Right click the System log, select **Filter Current Log**, and specify `16962-16969` in the Event IDs field. +1. Review Event IDs 16962 to 16969, as listed in the following table, with event source **Directory-Service-SAM**. +1. Identify which security contexts are enumerating users or groups in the SAM database. +1. Prioritize the callers, determine if they should be allowed or not, then include the allowed callers in the SDDL string. |Event ID|Event Message Text|Explanation | |---|---|---| @@ -127,12 +129,12 @@ There are corresponding events that indicate when remote calls to the SAM are re |16963|Message Text: "Remote calls to the SAM database are being restricted using the configured registry security descriptor: %1.%n"

    %1 - "Registry SD String:" |Emit event when a new SDDL is read from the registry (either on startup or change) and is considered valid. The event includes the source and a copy of the queried SDDL. |16964|"The registry security descriptor is malformed: %1.%n Remote calls to the SAM database are being restricted using the default security descriptor: %2.%n"

    %1- "Malformed SD String:"
    %2- "Default SD String:"|Emit event when registry SDDL is mal-formed, causing fallback to default hard-coded SDDL (event should include a copy of the default SDDL). |16965|Message Text: "A remote call to the SAM database has been denied.%nClient SID: %1%n Network address: %2%n"

    %1- "Client SID:" %2- "Client Network Address | Emit event when access is denied to a remote client. Event should include identity and network address of the client. -|16966|Audit Mode is enabled-

    Message Text: "Audit only mode is now enabled for remote calls to the SAM database. SAM will log an event for clients who would have been denied access in normal mode. %n"|Emit event whenever training mode (see 16968) is enabled or disabled. +|16966|Audit Mode is enabled-

    Message Text: "Audit only mode is now enabled for remote calls to the SAM database. SAM will log an event for clients who would have been denied access in normal mode. %n"|Emit event whenever training mode (see 16968) is enabled or disabled. |16967|Audit Mode is disabled-

    Message Text: "Audit only mode is now disabled for remote calls to the SAM database.%n For more information"|Emit event whenever training mode (see 16968) is enabled or disabled. |16968| Message Text: "Audit only mode is currently enabled for remote calls to the SAM database.%n The following client would have been normally denied access:%nClient SID: %1 from network address: %2. %n"
    %1- "Client SID:"
    %2- "Client Network Address:"|Emit event when access would have been denied to a remote client, but was allowed through due to training mode being enabled. Event should include identity and network address of the client.| |16969|Message Text: "%2 remote calls to the SAM database have been denied in the past %1-seconds throttling window.%n
    "%1- "Throttle window:"
    %2- "Suppressed Message Count:"| Throttling may be necessary for some events due to expected high volume on some servers causing the event log to wrap.

    Note: There's no throttling of events when audit mode is enabled. Environments with a large number of low-privilege and anonymous querying of the remote database may see large numbers of events logged to the System log. For more info, see the [Event Throttling](#event-throttling) section. -Compare the security context attempting to remotely enumerate accounts with the default security descriptor. Then edit the security descriptor to add accounts that require remote access. +Compare the security context attempting to remotely enumerate accounts with the default security descriptor. Then edit the security descriptor to add accounts that require remote access. ### Event Throttling A busy server can flood event logs with events related to the remote enumeration access check. To prevent this, access-denied events are logged once every 15 minutes by default. The length of this period is controlled by the following registry value. @@ -153,18 +155,18 @@ Restarts aren't required to enable, disable or modify the **Network access: Rest This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation. -### Vulnerability +### Vulnerability The SAMRPC protocol has a default security posture that makes it possible for low-privileged attackers to query a machine on the network for data that is critical to their further hacking and penetration plans.

    The following example illustrates how an attacker might exploit remote SAM enumeration: 1. A low-privileged attacker gains a foothold on a network. -2. The attacker then queries all machines on the network to determine which ones have a highly privileged domain user configured as a local administrator on that machine. +2. The attacker then queries all machines on the network to determine which ones have a highly privileged domain user configured as a local administrator on that machine. 3. If the attacker can, then find any other vulnerability on that machine that allows taking it over, the attacker can then squat on the machine waiting for the high-privileged user to sign in and then steal or impersonate those credentials. ### Countermeasure You can mitigate this vulnerability by enabling the **Network access: Restrict clients allowed to make remote calls** to SAM security policy setting and configuring the SDDL for only those accounts that are explicitly allowed access. ### Potential impact -If the policy is defined, admin tools, scripts and software that formerly enumerated users, groups and group membership may fail. To identify accounts that may be affected, test this setting in [audit only mode](#audit-only-mode). +If the policy is defined, admin tools, scripts and software that formerly enumerated users, groups and group membership may fail. To identify accounts that may be affected, test this setting in [audit only mode](#audit-only-mode). ## Related Topics [Security Options](./security-options.md) From 118df2ce9498b394c700602319165fc355e2cf9a Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Fri, 29 Jul 2022 13:42:20 -0700 Subject: [PATCH 104/109] Reformatted steps into a table to make it easier to read. --- ...-autopatch-device-registration-overview.md | 79 +++---------------- 1 file changed, 12 insertions(+), 67 deletions(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index 30c9b47f12..1d55fce3d7 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -39,73 +39,18 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto :::image type="content" source="../media/windows-autopatch-device-registration-workflow-diagram.png" alt-text="Detailed device registration workflow diagram" lightbox="../media/windows-autopatch-device-registration-workflow-diagram.png"::: -1. IT admin identifies devices to be managed by the Windows Autopatch service. -2. IT admin adds devices through direct membership or nests other Azure AD assigned or dynamic groups into the **Windows Autopatch Device Registration** Azure AD assigned group. -3. The Windows Autopatch Discover Devices function hourly discovers devices previously added by the IT admin into the **Windows Autopatch Device Registration** Azure AD assigned group in **step #2**. The Azure AD device ID is used by Windows Autopatch to query device attributes in both Microsoft Endpoint Manager-Intune and Azure AD when registering devices into its service. - 1. Once devices are discovered from the Azure AD group, the same function gathers additional device attributes and saves it into its memory during the discovery operation. The following device attributes are gathered from Azure AD in this step: - 1. AzureADDeviceID - 2. OperatingSystem - 3. DisplayName (Device name) - 4. AccountEnabled - 5. RegistrationDateTime - 6. ApproximateLastSignInDateTime - 2. In this same step, the Windows Autopatch discover devices function calls another function, the device prerequisite check function. The device prerequisite check function evaluates software-based device-level prerequisites to comply with Windows Autopatch device readiness requirements prior to registration. -4. The Windows Autopatch prerequisite function makes an Intune Graph API call to sequentially validate device readiness attributes required for the registration process. For detailed information, see the [Detailed prerequisite check workflow diagram](#detailed-prerequisite-check-workflow-diagram) section. The service checks the following device readiness attributes, and/or prerequisites: - 1. **Serial number, model, and manufacturer.** - 1. Checks if the serial number already exists in the Windows Autopatch’s managed device database. - 2. **If the device is Intune-managed or not**. - 1. Windows Autopatch looks to see if the Azure AD device ID has an Intune device ID associated with it. - 1. If **yes**, it means this device is enrolled into Intune. - 2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service. - 2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Azure AD device attributes gathered and saved to its memory in **step 3a**. - 1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the **Prerequisite failed** status, then added to the **Not ready** tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune. - 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with it anymore. To remediate, [clean up any stale Azure AD device records from your tenant](/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices#clean-up-dual-state-of-hybrid-azure-ad-joined-and-azure-registered-devices-in-your-azure-ad-tenant). - 3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days. - 3. **If the device is a Windows device or not**. - 1. If it’s a Windows device, Windows Autopatch evaluates the following requirements: - 1. Whether the **Windows OS version** is **greater or equal to 10**. - 2. The **OS build** is **greater or equal to 1809**. - 3. The **architecture** is **x64**. - 4. **Windows Autopatch checks the Windows SKU family**. The SKU must be either: - 1. **Enterprise** - 2. **Pro** - 3. **Pro Workstation** - 5. If the device meets the operating system requirements, Windows Autopatch checks whether the device is either: - 1. **Only managed by Intune** - 1. If the device is only managed by Intune, the device is marked as **Passed all prerequisites**. - 2. **Co-managed by both Configuration Manager and Intune** - 1. If the device is co-managed by both Configuration Manager and Intune, an additional prerequisite check is evaluated to determine if the device satisfies the co-management-enabled workloads required by Windows Autopatch to manage devices in a co-managed state. - 1. The required co-management workloads evaluated in this step are: - 1. **Windows Updates Policies** - 2. **Device Configuration** - 3. **Office Click to Run** - 2. If Windows Autopatch determines that one of these workloads isn’t enabled on the device, the service marks the device as **Prerequisite failed** and moves the device to the **Not Ready** tab. -5. Once the device passes all prerequisites described in **step #4**, Windows Autopatch starts its deployment ring assignment calculation. The following logic is used to calculate the Windows Autopatch deployment ring assignment: - 1. If the Windows Autopatch tenant’s existing managed device size is **≤ 200**, the deployment ring assignment is **First (5%)**, **Fast (15%)**, remaining devices go to the **Broad ring (80%)**. - 2. If the Windows Autopatch tenant’s existing managed device size is **>200**, the deployment ring assignment will be **First (1%)**, **Fast (9%)**, remaining devices go to the **Broad ring (90%)**. -6. Once the deployment ring calculation is done, Windows Autopatch assigns devices to one of the following deployment ring groups: - 1. **Modern Workplace Devices-Windows Autopatch-First** - 1. The Windows Autopatch device registration process doesn’t automatically assign devices to the Test ring represented by the Azure AD group (Modern Workplace Devices-Windows Autopatch-Test). It’s important that you assign devices to the Test ring to validate the update deployments before the updates are deployed to a broader population of devices. - 2. **Modern Workplace Devices-Windows Autopatch-Fast** - 3. **Modern Workplace Devices-Windows Autopatch-Broad** -7. Windows Autopatch also assigns devices to the following Azure AD groups when certain conditions apply: - 1. **Modern Workplace Devices - All** - 1. This group has all devices managed by Windows Autopatch. - 2. When registering Windows 10 devices, use **Modern Workplace Devices Dynamic - Windows 10** - 1. This group has all devices managed by Windows Autopatch and that have Windows 10 installed. - 3. When registering Windows 11 devices, use **Modern Workplace Devices Dynamic - Windows 11** - 1. This group has all devices managed by Windows Autopatch and that have Windows 11 installed. - 4. When registering virtual devices, use **Modern Workplace Devices - Virtual Machine** - 1. This group has all virtual devices managed by Windows Autopatch. -8. In post-device registration, three actions occur: - 1. Windows Autopatch adds devices to its managed database. - 2. Flags devices as **Active** in the **Ready** tab. - 3. The Azure AD device ID of the device successfully registered is added into the Microsoft Cloud Managed Desktop Extension’s allowlist. Windows Autopatch installs the Microsoft Cloud Managed Desktop Extension agent once devices are registered, so the agent can communicate back to the Microsoft Cloud Managed Desktop Extension service. - 1. The agent is the **Modern Workplace - Autopatch Client setup** PowerShell script that was created during the Windows Autopatch tenant enrollment process. The script is executed once devices are successfully registered into the Windows Autopatch service. -9. IT admins review the device registration status in both the **Ready** and **Not ready** tabs. - 1. If the device was successfully registered, the device shows up in the **Ready** tab. - 2. If not, the device shows up in the **Not ready** tab. -10. This is the end of the Windows Autopatch device registration workflow. +| Step | Description | +| ----- | ----- | +| **Step 1: Identify devices** | IT admin identifies devices to be managed by the Windows Autopatch service. | +| **Step 2: Add devices** | IT admin adds devices through direct membership or nests other Azure AD assigned or dynamic groups into the **Windows Autopatch Device Registration** Azure AD assigned group. | +| **Step 3: Discover devices** | The Windows Autopatch Discover Devices function hourly discovers devices previously added by the IT admin into the **Windows Autopatch Device Registration** Azure AD assigned group in **step #2**. The Azure AD device ID is used by Windows Autopatch to query device attributes in both Microsoft Endpoint Manager-Intune and Azure AD when registering devices into its service.

    1. Once devices are discovered from the Azure AD group, the same function gathers additional device attributes and saves it into its memory during the discovery operation. The following device attributes are gathered from Azure AD in this step:
      1. **AzureADDeviceID**
      2. **OperatingSystem**
      3. **DisplayName (Device name)**
      4. **AccountEnabled**
      5. **RegistrationDateTime**
      6. **ApproximateLastSignInDateTime**
    2. In this same step, the Windows Autopatch discover devices function calls another function, the device prerequisite check function. The device prerequisite check function evaluates software-based device-level prerequisites to comply with Windows Autopatch device readiness requirements prior to registration.
    | +| **Step 4: Check prerequisites** | The Windows Autopatch prerequisite function makes an Intune Graph API call to sequentially validate device readiness attributes required for the registration process. For detailed information, see the [Detailed prerequisite check workflow diagram](#detailed-prerequisite-check-workflow-diagram) section. The service checks the following device readiness attributes, and/or prerequisites:
    1. **Serial number, model, and manufacturer.**
      1. Checks if the serial number already exists in the Windows Autopatch’s managed device database.
    2. **If the device is Intune-managed or not.**
      1. Windows Autopatch looks to see **if the Azure AD device ID has an Intune device ID associated with it**.
        1. If **yes**, it means this device is enrolled into Intune.
        2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service.
      2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Azure AD device attributes gathered and saved to its memory in **step 3a**.
        1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the **Prerequisite failed** status, then added to the **Not ready** tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune.
        2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with it anymore. To remediate, [clean up any stale Azure AD device records from your tenant](windows-autopatch-register-devices.md#clean-up-dual-state-of-hybrid-azure-ad-joined-and-azure-registered-devices-in-your-azure-ad-tenant).
      3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days.
    3. **If the device is a Windows device or not.**
      1. Windows Autopatch looks to see if the Azure AD device ID has an Intune device ID associated with it.
        1. **If yes**, it means this device is enrolled into Intune.
        2. **If not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service.
    4. **Windows Autopatch checks the Windows SKU family**. The SKU must be either:
      1. **Enterprise**
      2. **Pro**
      3. **Pro Workstation**
    5. **If the device meets the operating system requirements**, Windows Autopatch checks whether the device is either:
      1. **Only managed by Intune.**
        1. If the device is only managed by Intune, the device is marked as Passed all prerequisites.
      2. **Co-managed by both Configuration Manager and Intune.**
        1. If the device is co-managed by both Configuration Manager and Intune, an additional prerequisite check is evaluated to determine if the device satisfies the co-management-enabled workloads required by Windows Autopatch to manage devices in a co-managed state. The required co-management workloads evaluated in this step are:
          1. **Windows Updates Policies**
          2. **Device Configuration**
          3. **Office Click to Run**
        2. If Windows Autopatch determines that one of these workloads isn’t enabled on the device, the service marks the device as **Prerequisite failed** and moves the device to the **Not Ready** tab.
    | +| **Step 5: Calculate deployment ring assignment** | Once the device passes all prerequisites described in **step #4**, Windows Autopatch starts its deployment ring assignment calculation. The following logic is used to calculate the Windows Autopatch deployment ring assignment:
    1. If the Windows Autopatch tenant’s existing managed device size is **≤ 200**, the deployment ring assignment is **First (5%)**, **Fast (15%)**, remaining devices go to the **Broad ring (80%)**.
    2. If the Windows Autopatch tenant’s existing managed device size is **>200**, the deployment ring assignment will be **First (1%)**, **Fast (9%)**, remaining devices go to the **Broad ring (90%)**.
    | +| **Step 6: Assign devices to a deployment ring group** | Once the deployment ring calculation is done, Windows Autopatch assigns devices to one of the following deployment ring groups:
    1. **Modern Workplace Devices-Windows Autopatch-First**
      1. The Windows Autopatch device registration process doesn’t automatically assign devices to the Test ring represented by the Azure AD group (Modern Workplace Devices-Windows Autopatch-Test). It’s important that you assign devices to the Test ring to validate the update deployments before the updates are deployed to a broader population of devices.
    2. **Modern Workplace Devices-Windows Autopatch-Fast**
    3. **Modern Workplace Devices-Windows Autopatch-Broad**
    | +| **Step 7: Assign devices to an Azure AD group** | Windows Autopatch also assigns devices to the following Azure AD groups when certain conditions apply:
    1. **Modern Workplace Devices - All**
      1. This group has all devices managed by Windows Autopatch.
    2. When registering **Windows 10 devices**, use **Modern Workplace Devices Dynamic - Windows 10**
      1. This group has all devices managed by Windows Autopatch and that have Windows 10 installed.
    3. When registering **Windows 11 devices**, use **Modern Workplace Devices Dynamic - Windows 11**
      1. This group has all devices managed by Windows Autopatch and that have Windows 11 installed.
    4. When registering **virtual devices**, use **Modern Workplace Devices - Virtual Machine**
      1. This group has all virtual devices managed by Windows Autopatch.
      | +| **Step 8: Post-device registration** | In post-device registration, three actions occur:
      1. Windows Autopatch adds devices to its managed database.
      2. Flags devices as **Active** in the **Ready** tab.
      3. The Azure AD device ID of the device successfully registered is added into the Microsoft Cloud Managed Desktop Extension’s allowlist. Windows Autopatch installs the Microsoft Cloud Managed Desktop Extension agent once devices are registered, so the agent can communicate back to the Microsoft Cloud Managed Desktop Extension service.
        1. The agent is the **Modern Workplace - Autopatch Client setup** PowerShell script that was created during the Windows Autopatch tenant enrollment process. The script is executed once devices are successfully registered into the Windows Autopatch service.
        | +| **Step 9: Review device registration status** | IT admins review the device registration status in both the **Ready** and **Not ready** tabs.
        1. If the device was **successfully registered**, the device shows up in the **Ready** tab.
        2. If **not**, the device shows up in the **Not ready** tab.
        | +| **Step 10: End of registration workflow** | This is the end of the Windows Autopatch device registration workflow. | ## Detailed prerequisite check workflow diagram From 284e553ef58ee88b56e186712376be34b83a2086 Mon Sep 17 00:00:00 2001 From: Angela Fleischmann Date: Fri, 29 Jul 2022 16:10:50 -0600 Subject: [PATCH 105/109] Update hello-hybrid-aadj-sso-cert.md https://microsoft-ce-csi.acrolinx.cloud/api/v1/checking/scorecards/d0e0503d-1a23-49be-b642-4ac390655030#CORRECTNESS Line 339: Sign-in to the certificate authority or management workstations with an _Enterprise Admin_ equivalent credentials. > Sign in to the certificate authority or management workstations with an _enterprise admin_ -equivalent credential. Line 854: When finished click **Select**. > When finished, click **Select**. --- .../hello-for-business/hello-hybrid-aadj-sso-cert.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md index f8ba4366ea..53931e113c 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md @@ -336,7 +336,7 @@ The certificate authority may only issue certificates for certificate templates > [!Important] > Ensure you publish the **AADJ WHFB Authentication** certificate templates to the certificate authority that Microsoft Intune uses by way of the NDES servers. The NDES configuration asks you to choose a certificate authority from which it requests certificates. You need to publish that certificate templates to that issuing certificate authority. The **NDES-Intune Authentication** certificate is directly enrolled and can be published to any certificate authority. -Sign-in to the certificate authority or management workstations with an _Enterprise Admin_ equivalent credentials. +Sign in to the certificate authority or management workstations with an _enterprise admin_ -equivalent credential. 1. Open the **Certificate Authority** management console. @@ -851,7 +851,7 @@ Sign-in a workstation with access equivalent to a _domain user_. ![Azure AD new group creation.](images/aadjcert/azureadcreatewhfbcertgroup.png) -8. Click **Members**. Use the **Select members** pane to add members to this group. When finished click **Select**. +8. Click **Members**. Use the **Select members** pane to add members to this group. When finished, click **Select**. 9. Click **Create**. From 81a6f6814b1542fa5d0746e674e29ef60c9656da Mon Sep 17 00:00:00 2001 From: Aaron Czechowski Date: Fri, 29 Jul 2022 16:16:17 -0700 Subject: [PATCH 106/109] fix broken links --- education/index.yml | 34 ++--- .../windows/set-up-students-pcs-with-apps.md | 33 ++--- .../configuration/wcd/wcd-firstexperience.md | 22 ++-- ...f-windows-10-with-configuration-manager.md | 119 +++++++++--------- windows/deployment/windows-10-poc-mdt.md | 28 ++--- windows/hub/breadcrumb/toc.yml | 2 +- 6 files changed, 112 insertions(+), 126 deletions(-) diff --git a/education/index.yml b/education/index.yml index 26aa73e3a7..d9e629b791 100644 --- a/education/index.yml +++ b/education/index.yml @@ -44,24 +44,24 @@ productDirectory: imageSrc: ./images/EDU-Lockbox.svg links: - url: /azure/active-directory/fundamentals/active-directory-deployment-checklist-p2 - text: AAD feature deployment guide - - url: https://techcommunity.microsoft.com/t5/Azure-Information-Protection/Azure-Information-Protection-Deployment-Acceleration-Guide/ba-p/334423 + text: Azure Active Directory feature deployment guide + - url: https://techcommunity.microsoft.com/t5/security-compliance-and-identity/azure-information-protection-deployment-acceleration-guide/ba-p/334423 text: Azure information protection deployment acceleration guide - - url: /cloud-app-security/getting-started-with-cloud-app-security + - url: /defender-cloud-apps/get-started text: Microsoft Defender for Cloud Apps - url: /microsoft-365/compliance/create-test-tune-dlp-policy text: Data loss prevention - url: /microsoft-365/compliance/ - text: Microsoft 365 Compliance + text: Microsoft Purview compliance - url: https://social.technet.microsoft.com/wiki/contents/articles/35748.office-365-what-is-customer-lockbox-and-how-to-enable-it.aspx text: Deploying Lockbox # Card - title: Analytics & insights imageSrc: ./images/EDU-Education.svg links: - - url: /power-bi/service-admin-administering-power-bi-in-your-organization + - url: /power-bi/admin/service-admin-administering-power-bi-in-your-organization text: Power BI for IT admins - - url: /dynamics365/#pivot=get-started + - url: /dynamics365/ text: Dynamics 365 # Card - title: Find deployment help and other support resources @@ -69,11 +69,9 @@ productDirectory: links: - url: /microsoft-365/education/deploy/find-deployment-help text: IT admin help - - url: https://social.technet.microsoft.com/forums/en-us/home - text: TechNet - - url: https://support.office.com/en-us/education + - url: https://support.office.com/education text: Education help center - - url: https://support.office.com/en-us/article/teacher-training-packs-7a9ee74a-8fe5-43d3-bc23-a55185896921 + - url: /learn/educator-center/ text: Teacher training packs # Card - title: Check out our education journey @@ -98,9 +96,9 @@ additionalContent: summary: Learn how web applications can use the API to provide a locked down experience for taking tests. url: /windows/uwp/apps-for-education/take-a-test-api # Card - - title: Office Education Dev center - summary: Integrate with Office 365 across devices and services to extend Microsoft enterprise-scale compliance and security to students, teachers, and staff in your education app - url: https://developer.microsoft.com/office/edu + - title: Office dev center + summary: Integrate with Office 365 across devices and services to extend Microsoft enterprise-scale compliance and security to students, teachers, and staff in your education app. + url: https://developer.microsoft.com/office/ # Card - title: Data Streamer summary: Bring new STEM experiences into the classroom with real-time data in Excel using Data Streamer. Data Streamer can send data to Excel from a sensor or application. @@ -111,15 +109,7 @@ additionalContent: # Card - title: Microsoft Partner Network summary: Discover the latest news and resources for Microsoft Education products, solutions, licensing and readiness. - url: https://partner.microsoft.com/solutions/education - # Card - - title: Authorized Education Partner (AEP) program - summary: Become authorized to purchase and resell academic priced offers and products to Qualified Educational Users (QEUs). - url: https://www.mepn.com/ - # Card - - title: Authorized Education Partner Directory - summary: Search through the list of Authorized Education Partners worldwide who can deliver on customer licensing requirements, and provide solutions and services to current and future school needs. - url: https://www.mepn.com/MEPN/AEPSearch.aspx + url: https://partner.microsoft.com/explore/education # Card - title: Education Partner community Yammer group summary: Sign in with your Microsoft Partner account and join the Education Partner community private group on Yammer. diff --git a/education/windows/set-up-students-pcs-with-apps.md b/education/windows/set-up-students-pcs-with-apps.md index 30b657f9b6..2f08fa227c 100644 --- a/education/windows/set-up-students-pcs-with-apps.md +++ b/education/windows/set-up-students-pcs-with-apps.md @@ -1,11 +1,7 @@ --- title: Provision student PCs with apps description: Learn how to use Configuration Designer to easily provision student devices to join Active Directory. -keywords: shared cart, shared PC, school, provision PCs with apps, Windows Configuration Designer ms.prod: w10 -ms.pagetype: edu -ms.mktglfcycl: plan -ms.sitesec: library ms.localizationpriority: medium author: dansimp ms.author: dansimp @@ -15,17 +11,19 @@ manager: dansimp --- # Provision student PCs with apps + **Applies to:** -- Windows 10 +- Windows 10 - -To create and apply a provisioning package that contains apps to a device running all desktop editions of Windows 10 except Windows 10 Home, follow the steps in [Provision PCs with apps](/windows/configuration/provisioning-packages/provision-pcs-with-apps). +To create and apply a provisioning package that contains apps to a device running all desktop editions of Windows 10 except Windows 10 Home, follow the steps in [Provision PCs with apps](/windows/configuration/provisioning-packages/provision-pcs-with-apps). Provisioning packages can include management instructions and policies, installation of specific apps, customization of network connections and policies, and more. -You can apply a provisioning package on a USB drive to off-the-shelf devices during setup, making it fast and easy to configure new devices. -- If you want to [provision a school PC to join a domain](set-up-students-pcs-to-join-domain.md) and add apps in the same provisioning package, follow the steps in [Provision PCs with apps](/windows/configuration/provisioning-packages/provision-pcs-with-apps). +You can apply a provisioning package on a USB drive to off-the-shelf devices during setup, making it fast and easy to configure new devices. + +- If you want to [provision a school PC to join a domain](set-up-students-pcs-to-join-domain.md) and add apps in the same provisioning package, follow the steps in [Provision PCs with apps](/windows/configuration/provisioning-packages/provision-pcs-with-apps). + - If you want to provision a school PC to join Azure AD, set up the PC using the steps in [Use Set up School PCs App](use-set-up-school-pcs-app.md). Set up School PCs now lets you add recommended apps from the Store so you can add these apps while you're creating your package through Set up School PCs. You can also follow the steps in [Provision PCs with apps](/windows/configuration/provisioning-packages/provision-pcs-with-apps) if you want to add apps to student PCs after initial setup with the Set up School PCs package. - - - name: Drivers and compatibility questions: - question: | @@ -74,12 +70,9 @@ sections: - question: | Which deployment tools support Windows 10? answer: | - Updated versions of Microsoft deployment tools, including Microsoft Endpoint Configuration Manager, MDT, and the Windows Assessment and Deployment Kit (Windows ADK) have been released to support Windows 10. + Updated versions of Microsoft deployment tools, including Microsoft Endpoint Configuration Manager, MDT, and the Windows Assessment and Deployment Kit (Windows ADK) support Windows 10. - - [Microsoft Endpoint Configuration Manager](/mem/configmgr) simplifies the deployment and management of Windows 10. If you aren't currently using Configuration Manager, download a free 180-day trial. - - > [!NOTE] - > The Microsoft Evaluation Center is temporarily unavailable. To access this download, see [Accessing trials and kits for Windows (Eval Center workaround)](https://techcommunity.microsoft.com/t5/windows-11/accessing-trials-and-kits-for-windows-eval-center-workaround/m-p/3361125). + - [Microsoft Endpoint Configuration Manager](/mem/configmgr) simplifies the deployment and management of Windows 10. If you aren't currently using it, download a free 180-day trial of [Microsoft Endpoint Configuration Manager (current branch)](https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager). - [MDT](/mem/configmgr/mdt) is a collection of tools, processes, and guidance for automating desktop and server deployment. diff --git a/windows/deployment/windows-10-poc-sc-config-mgr.md b/windows/deployment/windows-10-poc-sc-config-mgr.md index 2a14609c52..5e58c2a014 100644 --- a/windows/deployment/windows-10-poc-sc-config-mgr.md +++ b/windows/deployment/windows-10-poc-sc-config-mgr.md @@ -123,10 +123,7 @@ The procedures in this guide are summarized in the following table. An estimate Stop-Process -Name Explorer ``` -1. Download **Microsoft Endpoint Configuration Manager** on SRV1. - - > [!NOTE] - > The Microsoft Evaluation Center is temporarily unavailable. To access this download, see [Accessing trials and kits for Windows (Eval Center workaround)](https://techcommunity.microsoft.com/t5/windows-11/accessing-trials-and-kits-for-windows-eval-center-workaround/m-p/3361125). +1. Download [Microsoft Endpoint Configuration Manager (current branch)](https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager) and extract the contents on SRV1. 1. Open the file, enter **C:\configmgr** for **Unzip to folder**, and select **Unzip**. The `C:\configmgr` directory will be automatically created. Select **OK** and then close the **WinZip Self-Extractor** dialog box when finished. diff --git a/windows/deployment/windows-10-poc.md b/windows/deployment/windows-10-poc.md index 70f2060fee..f69d28d3bf 100644 --- a/windows/deployment/windows-10-poc.md +++ b/windows/deployment/windows-10-poc.md @@ -180,11 +180,9 @@ Starting with Windows 8, the host computer's microprocessor must support second When you have completed installation of Hyper-V on the host computer, begin configuration of Hyper-V by downloading VHD and ISO files to the Hyper-V host. These files will be used to create the VMs used in the lab. -1. Create a directory on your Hyper-V host named **C:\VHD**. Download a single VHD file for **Windows Server** to the **C:\VHD** directory. +1. Create a directory on your Hyper-V host named **C:\VHD**. Download a single VHD file for [Windows Server](https://www.microsoft.com/evalcenter/evaluate-windows-server-2022) to the **C:\VHD** directory. > [!NOTE] - > The Microsoft Evaluation Center is temporarily unavailable. To access this download, see [Accessing trials and kits for Windows (Eval Center workaround)](https://techcommunity.microsoft.com/t5/windows-11/accessing-trials-and-kits-for-windows-eval-center-workaround/m-p/3361125). - > > The currently available downloads are Windows Server 2019 or Windows Server 2022. The rest of this article refers to "Windows Server 2012 R2" and similar variations. > [!IMPORTANT] @@ -194,10 +192,7 @@ When you have completed installation of Hyper-V on the host computer, begin conf 3. Copy the VHD to a second file also in the **C:\VHD** directory and name this VHD **2012R2-poc-2.vhd**. -4. Download the **Windows 10 Enterprise** ISO file to the **C:\VHD** directory on your Hyper-V host. - - > [!NOTE] - > The Microsoft Evaluation Center is temporarily unavailable. To access this download, see [Accessing trials and kits for Windows (Eval Center workaround)](https://techcommunity.microsoft.com/t5/windows-11/accessing-trials-and-kits-for-windows-eval-center-workaround/m-p/3361125). +4. Download the [Windows 10 Enterprise](https://www.microsoft.com/evalcenter/evaluate-windows-10-enterprise) ISO file to the **C:\VHD** directory on your Hyper-V host. You can select the type, version, and language of installation media to download. In this example, a Windows 10 Enterprise, 64 bit, English ISO is chosen. You can choose a different version. From 1390d2504fd675554255892242a19660b4c98ccb Mon Sep 17 00:00:00 2001 From: Office Content Publishing <34616516+officedocspr@users.noreply.github.com> Date: Sat, 30 Jul 2022 23:32:10 -0700 Subject: [PATCH 109/109] Uploaded file: education-content-updates.md - 2022-07-30 23:32:09.9464 --- education/includes/education-content-updates.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/education/includes/education-content-updates.md b/education/includes/education-content-updates.md index 825288c869..8c86acd85f 100644 --- a/education/includes/education-content-updates.md +++ b/education/includes/education-content-updates.md @@ -2,6 +2,17 @@ +## Week of July 25, 2022 + + +| Published On |Topic title | Change | +|------|------------|--------| +| 7/26/2022 | [Upgrade Windows Home to Windows Education on student-owned devices](/education/windows/change-home-to-edu) | added | +| 7/26/2022 | [Secure the Windows boot process](/education/windows/change-home-to-edu) | modified | +| 7/25/2022 | Edit an existing topic using the Edit link | removed | +| 7/26/2022 | [Windows Hello for Business Videos](/education/windows/change-home-to-edu) | modified | + + ## Week of June 27, 2022

    cC#sQ#SI&%To=^8Zd7|_zLu!XeU$GLm90S{i%8oJ?$lQReR8~XQxt5 zYwDRcf7c|p#!;)E%X~Bz*SCb$&vbRx`69h%lf{s%$B9YSzbjA*q~mq>m1(<56`g(Q ztdgs~#-q*7t+^V1mS%iaX_ul~hQGy3N_)l>g4u17wJ<8f>629sS{QL<@9{K#CP^tH zw$*U3U+{>ycEE*Sv|VQnL&mLU)M8?KlusBKYz{CHMi-aNuHKP!zF65f*9n{o0|FGn9Y~A_@mo@V4MOne1cTGivg3rjy9P5Wk zQ(vhB5RKqA-qmYg5U@XyAG&I~zyI9egvglxf~A;GnyY*3=?vyEDa5oa{=|=;48~$h z)53$yW}E@Azs!Bp-{_FOW{6`%(#5nnt_Y_|#a zV;?=K)l;9Hn^c?p!Y~6@?cmBN8#hl#H~1}CU31I7_J)7eB{*W=^ zIeqgA96J|>zv?2S_`r`Os-JJvPm}GaOf>7sQYX*URk}xrXesKHs|h>l&Aj$03GkkC=+Vhe=wa z!qKm_JiBa5QYbVyYRUF0bo-`i)75~?qIFg&!^(vhp?K0nH^Z@G&Cn$F5o+mEEdpyg zx4~vIrTWrD_t)TMtVdZZ5B@Qx>*tYG)1pXUAUBzM7F6Ri-5k@aDJFhYP3wE{o$<%i zjWmdf=7qnMg_nzr#2b|{`Ls<3gVB}fauKEG8qKI6(;pofM4-3hnKg0`vbW5^1<(x;1 z-(Aw0cd;J^-AZS{e_RW8gX~Za&s?jmfEKxu(2GUm!N^u5PQ3kRzzB9 zuAmZBt`=EWZ?kY?O3IR()%uJM181w0&wZVVUImPqBF+<>fsjVom%kQ>flQ226t!fj_t^m z@x2z*cXzi~md1fQ?!HNNk>XFEJ`ERfO}37+DpNV>!pw`LG})F}Z!K-&UOhAt1&%`h zyn^ESEn7eezhs(; zFfTNQo(vk#9thvj9$`xz81UKpr0l7M`bhQcQFj9gB+fX)QH-^@!&UCBvarVV5-t-zh>{D5N=2<_zeENxe;A_7L=-)kv)_nx zmQ?k1ly9Aq;OFJkL(=;nCFopZmfEOOox|t92oVHk$DTC_{*D8SU~Bv6>gT`0fcw04 zs1x%3a!941!aj!~!P~vQYJYt`usbeTDGi^LmG3!*z6XYMZcc#moN$59pO!%ULV*y0 i0@=NF7iSvB<*Ex!&wXfEC5685n4ZDmv_rrC=l=n56ka|6 delta 349172 zcmb5Wc{r2}*gk9*LZM_Y6+%2AYYb6YvLsvCLzc1|vfiQ+S(2FS`@W2Q%@Sqbx3TZ* zj3qIHVP?L2dU~Gsd5_=kJHF%luRmr?b6?weo#%PYz$x#{F>l}-(n_)y9l%Qc?j5DZ z?WTMyp6A$XHeBfmlea=$@+pwKAmeQxcj*{B5vAgwjx>qAz#EFC!#r*us*^^Ug~0nUuAMYTOO9$Np=y~|3J+R;2O>G3G)athLJbH zRqnlyG%V9aNU?w6RKz<|q+NOY@~bciTDz~Mr7p|u5yizf1(IAZ_V)IMM@2QC{_2s0 zJ*8=26*UV-wwY+JZaup&7YBnG8t!tR$GI~nvAi`8&N%)OTkxT{U>$>zG>9D+PA(*) zJ*)~XCAkgc_Os}U7!%Ivi>Qa53i*y9S>ic+kG6Jq+d{*SKWL9LMt)AT0MJPNjq#Mf zI$#)*3(wEL&+UWWza9$<-=G|;)R1Vty_Fx_*XN7(dPLoS+{(xXAl+K8SqbDZUN}m> zRT?m8E%DwXtu~$iv8a#cxy5tmEt>Dv%}}QG_Xe~B{Dn#`ETg1J6jgzBCsScL>B@=0 zPF_ly&uwij88tj_2JOFZ|M201l3*n7_A$x5jaOyr~}(XNe4&+d>;*$4TMVej*iCg2JjAs$?{T3{5I5uvE8x*eK9|9iJo?wlX% zrm(AoWq6Wb1RCqtX$B*grL~NyK9ls7A@kZ*5wFK$Nw_vI65kVx$N1LpiV-_QIG6&uC2G6rBE zr;{9~-4}z)=NxDKdsfY77|5%;UKz&%e2P5fsV=l;t(<+O>6goM*nc1{#Q=5&GVx<-0QRKwO!C+mZ**gFhoMZ<;OpTaFHg@RhR?!sa&khZL&_^aabqi4 zMiMl(siA=m_i-<`H6xez(qLT8G!1t$eDK4v&*W zCDYjiyx5}8>XIJhnTXxKO=(s6%1AVw`8$6RtQ0>(Cm;3=7O6cNVawY&`nV1u#`lYP zTm$Km3dZNXPmtO9(d&xA)wn?bx+LqG{QG&uysPI|JiPGZ++OcB#o%|_*Z;)r`=6KG z*FR)SYpW+#+q-YXcUvW*vexT01FK~X-=e-lhfRQ!#_0`HWm$3w=LFI?SH?cW_}W4| zpy0L4G2alH`GT8THyV~R9wx$Ywk~+1&4FhzE~E z5S}>Kl00w-knP~S&3qBbl$Ll%{Rs&sW$(LdNy3sZ8xSc}(7LQ^!?9}|o8A2;PoEa- zE0Y_uDMDVncrjDZ+uzxoH+p-lEP4IQX7f>2<4Yq7++XgaTFF8LS>8gS4k@5G_ty&< z8!O5UUe+ATQ45Zms=!`Ng_#PEc?a#?I$`?~~Mogz|t(oG&wQSC$#m zl4PN@+!-d8-qriJ$g!bJX|GSGDeMZ3hmc0q=@s=lu6D4?@g<3C56M^IA?Q!)1kBbM zUD6+RDb5+*-P>P>E~8WPbDxP-m6tPReHvxVAC>bnN}>kTaQsVM=3J}Y5^Nj6u zWEgk8eIu>ONJ;on-LG9Bv_IDG-g_{=x@t2e#2Qc2O(N^=8Jqmj&RiySuSc|*Gc*u$ zw8F{xe6x3D ztWUpz{Zu|pAFm{s&fV8=cEQrqGtM|zPmxg29KnB}N>LD%Q}ui!YvinehaKxC(_`N> zfM3x+Nbl1g&nC-IrY=D}XmK`BAzG}z#Ea#rBaBaboX zv}Q_E>cG&VuK(_1|0Jpje`c;PnTL@VXNT+5UmIZ1{9axyiQz_iF{h<|d3d+tF*Y^<{;usF0=HW>n`a^KD! zC7iwh%rk$rPFC#Be3k2xIGQwe#&zZLG}YJpU=HjDUVF~|smdK@99Ue(gxa5L5d1O( z`N6npeQBakX-1|xFQW9LS|AnuNpRliAqEo{7x#sY<|UQjcD~`-r*~*Z1tU|_x8GV@ zTer4^@3_cXwiK5edOpu`j~z@Cd9V*G{rDh3BJiHAEjB>0pyHWre^PphpNZW3{^%$R z%MT?<&pA7?lWvoB3892Rh}7h(ZnGyp-e6*7ngkI$cYXbyP3CB7XuAWOA^W%7W8A(u zIvtqqz6DEX;LXY2-ri_R*JMk7!$X~OQg6{ruWDVFsldN+SNmQIHft!S1Sq!WPq9&QlK!8pz6J+FW&Y^w`2jwf!L$ZXkAI%u?A=&D~)EPRvhKFPlcEdcvQ0(~lcqlXf7oM({7GxS>qWZ9JLu7xE z<4?U|2Sa4a01<;6si4oiAQLff;yfP883hu!v;*@>z zgWXr2Mi3V7%TWAPQ`G@POrizzW=80r%s(ng6C>Kx0fBe# zZEeUTmgWl@O{o7Z1AzG29qL);f98TxFNwU2OgvAUa7j!PGKtjZSDh5YCN*)sj5>4A zupuez{C;U@&ZvnitrP2jfG9rXXtzZFU~R_7&%**v#*4ucKp!bH;xuIlChd&j=F+|x zurLf$yzgTZ4NF?cC5J9~9DuWo7&zchkCf@hl1DWMEHA)Lcj9*IjtVr|YTREwBDZ|4 zW)%+>W){Q<>9IO0M)_E$sP}qua`NhUU0vPS*w_n7V`Jk-47XnUcg#Fi433mZ0Ov;c z2TFQ(St&_LyQrzVGG05JaqH{r_G*$+Qub}}QSleU%LQ>l^P@;6Apq5;DVb6ZPlD8n zbr?2mZRrsPEbCd(;5G zY$jgqJnm+36t+(DfVv>pPt0SqiZ$Z(R$0+nOVhBvV+xnu`ASg*8G6b0r#j(Nbg4#h zgvLhsLgT!3RF@_Os70PyduRuGvS*|OHhn7-Ru9BaAWA&8oGlywr%jc_RM!vuJwGbM zNZI!wpFF+(r{5D_CsPfM{t#$~D`zf!uxen+moJxkjV=+NaejalDK@k!lny~{BI24H zUfKkpVBn00k@Wf6_yJ4fYzy28BM<@>(Ts=m;rrUB31ya?b9LVP;G~(yVQR9cZ=^o< zeFl9&*xA`J1a=Qa{P#D(YWg1a<3G^Ds*qsbZ+48wI5r}eEF2%WtWRW6wcd>ZV^;=w z15VFIN0IzrPpu!&m_iWBq-{wv_!K^0y2=3SQ>o^5XgI-D8D@`KA2KQ@OUJ(6D@Y1$|osHQ7Fj z&wlcCYWJ-F6S+q)7)K`=J5Zz%=rm^5@;?uTScKM<=-j4e)ITUWn#BLtO4sS7HEbZ1 zPchZcvoO7p*yxZ4iPT zoA(1oyfaDBy8$QDfcFjx>wB6Ggp`z&NQ$!l7e1R{3EPQ~Co`{LllBBXEi%)uoAq>H zd|rX^A&Y4rrr4;)rH6uZsr$4Oe4NI~&k{5WvU*3GC2xBwAewjj%I7Y%f zpFDjUwiQ|)(dH9co&TU2R#8^LD5f{O+RGTDVdynJC0vfM80^69w@^8{j5;IZBS{{j3- z*Lk+WWgw=I_p!)UUDw4&>-?FJpGT+^l5Ghkc~bvit0!RhJJFvG*pU5qs;IexjqfDv z+51=H*A+7_B-F6}r*#s`ip>(YIVKO5ClMitrBT>L>OZ)Bzn-C}gknRrhWM0=4{GKc zTE%Dmm&@#;Kox9J?;@QVu}&36vbwzf@rwgja4>G9-9F0oI}H@aTU zdy6M7K43I^x7I=QKuR^52&4NCWM|{WjV>jcH+=1ZJ7?CIa(C#c=V}hgd#E zuUYMjtgP{Q?3;m4nlC2+u%+JKhk!L)VjhRX<(brld2BOnzQNlEE(J|()`C;0R>L&1 zJgwx|Ki)tN?C?{CDeD8NxtbF?7TY%VP@$*Eg)Nc!Agcy%YO_33KN9RVu9q<*QZK)vQ$ z=#pA=V<+;BZ$wm7Zrv{JY-{V?kFN(m(NQyAqxV}lqjcH|$N zCmut>LeE|e`!~FQuOw`+GvwsgflM!Y#M!~GhE%7r%nMoxaM2pf?j0~e7AM#{7BR)f zQILZ{r#+#$=>E45T<|7@FonRcj4%>3_n21#6H}6;kJs9%wqc?sN8<;qVG;6ntpDy^ z%!n@65yHZc8hkFSx@>cofZyG|Hpt#lx4@}9Dr=-zsL!Ve)NC^j$75y0#jV`cq@<)` zKgX|qbr=CL@aN!Q@-+{^Y-m7$8KyK^zBC}PufMWBP)uH4lY?(`=fWWO7?t`0RUXZ@ zxJ>s&fjkIKoaN!uh^VRAVdi@K0di07NhqoY?(c`o~EVtT{PkOFUc9exa_ zn>YEz%Y3^Qmb+a!xcF^Nc6xADAVnch$iv>L(vx(e;Bs2Z4CU6=mJWri+)D-@A5R_r zDHX`Q4n|FKjXn-~@mL0pe#5>t>H=Gvq&ga$coD1x5StgVY;0jpOMaKf|1&~Kft0-x z8Den_diGoG(<#&^yH)DSVb`v^b+sv+!;HibVzVkbmi+APM6m@tW5-}&gbaZ=22R8= z;F~4vMSJ`+cm`11c7@C5K*D41fPGwJ3QNq0G>cPtJg)l$!uF*^$TrJezgCOtY8o64 zpT2m-o48jFiFlugct}4u?=vtyq)-Io6e2?KKMR?10!cAtQJ}A7dic>&sYl_Kwj+?ZxUA9;Q{DEz#JUKr&NZ{ z4O`MXoXT6K2E?81DVkc*zvRngO{Dm9Pvhe!W@ZeD8sN9yG{2E(Wo0EUF5Ycwz+Q+B zwz09jUw=FoaAUi+m_jiW1*B+JB%-Kz~*{7+@^ zL?LZ)CHZ8{c2d9o>3QU!^FHubJpVn6al}T2U~g>-jHiobIgTo z)1uZ+Sm|-^*Xl*M$VFf?1F|8n7`!#NZXQ;YaC2`T;K3zYNuSD9$tX{nMP?u;_ZFFMwYL>YV%E=P7^l{*7R_M<1)&d$t1kEjZc6RnZ^LrY>pDXZ+b+7x*jqVr3|PVzp*}D znTNkae-iPiq{CSy(K~447>y1oHcEG-BbO^J2f=;ic;dbZzx?PfpCZItn@nP(H44=N zeTGig3S2|PgP3m&41LTj;nH=hMi8asO`9xJ(NMd3lq8skX3pri#eECv%xK1$RrD5Z{x%qhrfcMkUa1l0sjVuSv|?P%WkB_N@C-L!)zHtUw`yD@vdJa;o&4qfCUxFXuq)6*Kh z5UB1;aYwMmYNJTLL8RqZcXv0qan;f;WQic|IOse@ZmDi(GWU5hk@S3E75(*!a>-(O zz(>p{AJ};|V6Ney&HHcqxd>|j%xMifA)%rK|G5s|p`P&0szEQyLbU^Tgu<>YO#^&)!6Gl(G zSL1C{K#mC#fYzUwX@b&WyygJlxRtUf08^vzYvp^F6nqA^XR-mu|44;^sb+pOJAaH} zZGPqGpBykZI}0{J0P+<*^`i8U(+*+!H)Cx5{daE@JzY&SD)wEZY)#wY6d#o^TKL`7 z>?U~LjKO2KwzqHB*!tL64`@zLPe+T?56U=y)Lfyg4C!YQa@W7vmN%{Z;u)hwZ{xZ6 zlAfv+^wn@++D&ds+(SC!)bEacKj}#>Zi%*20VrY}gt$)z>wPMNNK5Bc7@h_{U8X)z zKBTbAy@I3};vi2Xncc_Rv&nMt--e5y{;JCKHxiWzcM^3awv$i=2m~T79)nj1+|UB4 z!e=YD6Fk;!Eqqd!J|gMp=qf5Ipv|Ju&+k^E=iQ0n4;WZcb+ZFo%$bc;d_Pnhc6o{H z66rgb%o3RrFupr8DeGU@o8MPjTYIVK#GD7&kq+6&uc+hM9vG&H9@t@NN^*~?CCgD^X5Dh;?Tt<*Fh{qS;{yW@*J09(ff#20lFWUILTtQ1`W zo06nhBE*T$Y_Bn8?*>7R)JqQN!$2xcZ1CS3;R<@F6ObwODE`CdG~EI>8VIIJi0j1I zNR-XdbpEsWYh52>i0KB_Oa^QqJGRMtmLn2nHP#0p7^-a0w4gLSV*4_eE1e}vS8x(> zl$kIfn#qViot>X=c3p1o@7FRCwMTV8m&E_(yNezM-an1XnvF7WhR#aALo|v29*HCl z(1cKKq_R~1(|3=w0f)1k3iwOALGXlq8z(2HmoHzsxw*Nz-dbL_L!VR-_Idgrg}lRL z)b;0?6(ksPq_2(h1*mEt)F(aN0E0h6;nMVm-oJz~(2Wxt>=^wnpt8rZ`$B$6dx7uH z#^XAWNB>_7IPm|yfrDxZhfT|_m@9e2wB5|ZfO^NY&rX{ysfYW zD^>pFXKvHahUWc>nz?dJgOt-(_kBM8SNH|i=8t$VvcPG22>!YElYl(BLi2#d;|Cob zV&Il;zbQc3FkQLH7a;sE;p3XjS%;?UE9ZGWISLc~wu;R>bFrD@$J z7e8W*hG!s~=>c!n;VAik0h=kAM(8ziL17nr$ zR55n4XnyuSfIMjcH$CFGwK)fBhuSHYfWob2gyV!zs);l56 zgjAB6elU-n2^eSKfQJG9gQxM`a(BmKg?uwQy3~xRKDj&;n)G9t+>*q`B*(ndur`1~B(@*@oy)lZGyB~~l*C}w`G!FH{#B&;o^Zt{V$sENr=Pw!gbt)X_3?G5WhN*6`Lw7 z)6q%Botx!{{NJTV;Qy*Ux?ERuf4wUb4+}PS;Ovi0KKw#LFXnm#7Fm{V2yS4`2L+Op zJk40aTnDozmqn1;-EG2oCi^qvrm)zpw$%Fi`l-Q`{}3x~XVDKtx08-PNCoVDF#n4* z!Fb*i5(E-n_pEw&^X_vem|H_=1_tQg$WLl|n@-Q6pxA3uH!6E)XD#T@f6 z#>q)a-X|wZZD?p1XB;tU@901^aXi=R1y)wBT`*uuc|-u!Zk2_Sc`|9kl7YFolwwG4 zh8qpbgcbbw_}JoU;JIQrJQpJ*Bs38=To!(A5?mB9az~&<`ZAUjIiUaXI5J6ALn$`x zvO?Guj|9?o((PwBo$rz0_AgL4u`42-@sNQcQnikSq`gS+OLB4*Mq1=0y(bTVJ%?=f z`7{a?N~eu2+}svd-&Msi3mC%9vW<7LgLD92GdrDksUYT_BXhB|(l-%#iBqy|>Fb*U{Q( z3qDR>A?_xEuKvq{4E$d%4r<4^eqF{^c2*(T{W zU-EGr``yW0SbpVg&bp;;%`mA9$}+9)TZ+CRvoRLdN#lb^;vJvEGdi{ zTa5QjCxc>qMDWkfQEWdz`{ZT53-YWO zCN6UrmOe>#6_E5n4EBLaWK%<>w~Qny`{<9wie~hABsgqLjLjJxEP-|0A~Xyw1YVwaYl9Z{jp z4$ux*;M5;PsWRsbG+o_XmN~=#7)H zCTW3n(MoDcjUV)~jjua_ed)A*$@5ppj5q)KCHnb7bPz@z6=VNxw0V1gYvAgq@d{ua zuEkrc-a|R#voj-uq$P_h_BX9j8WLD4$sFb$dTe#?f-;w#S`pAAu$cn<=JEqViQ=BU zufCa4+Rsm)rec=iLYsn(PJx|fxnIXnC8{KQi;?9uS1J1syQA;cIbj^mYHXiLc6wVJ zwec$dAx?s`gJaHFAiGM;=^9Y=xp6zdNGDRX6xKZodHrntUS!M0xh-{zffMRy!SiLQ zl}JXT=PplYo!{#j0waOh+1CZC6`=Lut}!FreF=W#*M2!P9!c4pX2@>rLbfXN#Y*?eR;POUny zGWyhxoM72#{RSR_WQ1PN36S8XtQwp)GhC!bWLvn3%AzI#qjH|%lND#b-5fB|An-na158R-|7@|%w9R!e)1BeUB1V7~4aZ1~} zVSNAgG;tTH^G99$Oq8D1Vuhl4`Wfj(h-3<8!pc@V)y#kIp5To2Hp1L{HUEKvIq>r3 zlt}CUkn}ND+2W-2I~pdfLo+f?dG@6`Fp`M31~}3`?fy4U{0~9#AAX`O4~6?1S7xnP&{UHy6K7ohze@_}1UgaPtvxi_=g?bH}g= z@;>@sj0l=0ET-vlCADZhd(LcprFi1oa|;1g3oYSjotl1ZCadL0L7M22A6-)M%GGtR z1f~mC2Gr!6bgKM4*>p4MTK*0?^^JN@2^Wv)YP=RV5H#-2xKhF;&Jny0RX2QG>Ni$f24^YXMPiu>GDub z=T~`k6fs)?8N(2VY&o7cbcGZFcFre^8cK{0Ale$yz-{WNr}YWJ4{jzm&>;(ABWxYu z49;lMLu%pWzw+CRo8ck$AJWRwrjwjysDGv`Ek ziop^LU~ex-S|f^0AGG~sUJ9h)iHs-cZvc17@apaX(5wP@_`N)Ar$3SbSH~YjF0=X2 z7X;6n$%#_HDYB4QrLWyzMAT0z&cg@=^M$DsCeyjddwlK~_+_-7@m^Z{%7% z_ktA_(ob680KE(;jczjOuMDvY-HMlc)|^-q8-A+1$Y6=_f@`9WP;8Ol3O$m!0Rm=E2s_CU((}dW6M%|qp|rpx?)(cP;ZD$ z2NF$lYS0~HR_bZnAUzU|Rf#sfyh%6v@FR+RMNB;2O4%9;WkRi&jJQ4a;C_;IcycJ%p`TO>aJt-MLsRXdxpf_d)X~ za~2uufy#2U1y@dPZgB~)fb!xHjtw9|ui;+%OrOyEUGybT74EwPav`n-2YLx$lQIaDwZ@BPa1K4tkjH5W3_+jm61LzE-PEd&|QZ@5SHjM z3bF-h8%?YsY@>p{l5C{|T;w~9M=Rb1B3HP2sx=O(Az9lXtnSjx^ZrQdkxh%D%+t>X zxHUXXDP?bEde3Z!+H-uMmJ2`Zg5A?4zXJT9?vM%QG*|LsiVgGACDz30T?J4gDqbqx zk4ZfR-8&4Z>l{KtAY*pKXpA6oub$2`XB;dEQUDGC&Y7m_COk;eE;Gt|9KT(6p07uP zk~zr3(Ar=YwYN=9Zg}iuyBV7M?HP}lr!ilaF9KlyT_}1%Ie5O#eVw?K%9Hxk>Wo-i zNhP6Y$51c+vG{5Ju?n=nsA6db<#$u#tnzp`Ia%gQ=ESozw$PN4&3@S>z1RG&3i%47 zgp3od(syHzv&*Zfu^0q$in3=^-^tX8tr<&M`dRC(`BT8y7wK`&bl&+LAw%43`TA6F6yw3ZVBDM67tQiMpSo$hd&&%D%@Q&$s|MU@qVoCfQH?V`QX2AWT=}?sLs5S7 z8*+0`mo=Z~)6fW>B(0`#zVow?Z%dwT$19f6tj19`k{!WpRr6<)7F>-9FCMosUc8hT8ZC`n=5MnG`xxnyavYC-HAVv^{Jfm(P2LCfoir zm5X=%Dp6f8=nN;n%b(M(G^wn%?I=W%f3292Eeq@zV1FmJ_sh=%+xHy<&Q^d*T7f&& z256v`&f-}B6G?~2gHSM~0XP(3zHIb`1V?0?s$E}!z9yng?JYV;3T{Gd;%^}--XOIU zr1uNou$uxpp@`NGkQ)R&tGKp-$5DQBS~oPgeC1^oJVD=2+H=(M|7h!7uH!?F~=)zB(jL}2aJSXneHyOq?cFzg`7ded}Q$PBpa_oDH{B24C-JJ5yP1z#h zZ!Y+L{RKbQ#oZ&RGCZ;zE5E=uVPwi1ch&d&rr>oebG8sbg6vH|ZRqVQNSQE_*YeO8 zMa~BUGbh3Qmmh0y&eVu8bW;sF+dgKM6`9UgTnQO07waHX&mk=SPM_RVosg>?% zo3|Olp{MTpF!fbFUH*bg)l~V{eqH6|Qc9yPoL(@DqvM5SXu%uccD~KgHw2CzFVL5AJ%)KS9gt$wBimPd<^Q1f3C3zouWk z;zVGdO6ZQs$NhRs$BIAN;Rq=;yGsCmZHCN$b-S)gISO*1^fg3jVk?rjRI#x?3iU6c z`P=!#DC)p2{Fgl-47N*I4EXMUw0ZA8($3FpB^$CzENK6b&Z=*U?gMh2n%@~Zb%RL# z`Hl_fJT-qszD)*+op&r$C?IcM$w_(MqM9E6k;fn1laZgxmN7VxEJuAEtGQCCLU!^H zcV5a#x46ikh4(vk>ZA7?{5O+j70P-=HOIMA4Jtt;a_j<9wMMU9NzMSf&NoIe@uVBH zuSh;MHm1{k?M6p(H>;ftivA4ybwVZtJb5zYO#Il~&yoA@x^*usAK%q0t3T=i2RNI< ze+(*!D#HM(jqdrSU2_Pj{3vwx3#blV__RPv&XrnQO+6BH3S~riCn0{eRa~+XiO?_M zy7AIqhZp*)w4UpRi~sxf^DS;RqI%k|7<5UuZ%0mpJnV9<+X;n7{+l^i`Y9PRaKpC$ z8Sc#4+Ps0|{q;?yzBiiV3hX(zL?jLv^SrhgRj7?NLlQ4}DiQJ<`$q)urFWo67AaC+ z;QcEq^xR3kIsqxuVxWcrNB`K^Ly~Nrj#uhG*21T-){1wEfgO=ZfMA$u*x#%{7`5^4 z#EU}cp{<&EKvqm=O1sM!>?7btY(Ond_8X`bL|&eYVeH)P5Y?Ws?Ats%M_Fv5M>_ZM zJ_3+vt;(^riy9BNm10l@cYb~kKg}x}ozDoS#Jqx*(x2pB3dfHgdV$)mDQ`si|6&Fa?(www zDKCq#bED^g->|b;-LL+>#0o}$mJW(H$9;fw?103`f+*R@dw6LbRPZ)Ey}!^%9Ml0@ol8ZY=03gy=Uy+ zxwZKywF5c$?hA!?=I$IXQx-uK>TbxEs8W5w8?}C_)^wHM7-xJydzSvvjl36G767}Qp2&S#n@^? z_h&f;X=q0$r{RZ2zC&LjfqtB|H|pm}?CUlzNl?|I&Zq@l?~b6VZY;f#m)ven5^V9* zz3Gi3r2%5An&jK-rV5~fdHe%GKJ8X1x{E}73LMQ>g7&!A9#7UbCkU&#>HYek zD=CYvut$3MwR)&Wt0tyN592L3jldd4-8*@XgzHVE%~2zik3&659177^US*g*cwv|W zixl>eReD;d0;6YTfbfI7{~LD={J-7Jya$gp)?91-QR75$4pjF94?vFzO=9g?YXX>; z#Qw>{#d880lZv#&UDq*=(yu2$5XzE8_5wH#Zj_85At4;7sVM2aU622Bm-COgG%_8( zkq&)sG_@fJ>KGS?x;S8btm<7LWV?QG2OT^))vM2U+?;N4VKe|)b&kNG(TY3b5{m1ccnXDp9}`FEI5M01O#%S+wshz$ejOLXPuQ823{ z$?^fGFt_(8CW?;s_Uf7%AzUD6vUnmspB`D#&#i8)2H3%utD60taTDBT>*lgIpXjVm z>$PjTFssv`+M7VCnAcPb>w_obyFpfhyf!sI4=;*3RUNt$6pK&SGou#690vdG0a3Xl zPBVDfQS`u;Z!!Z@UxPpi?JJT19p-hmTO9ho}-<6lvjR7i1d^s#N&vOwMiBGt;y|Pd7Fg zm2TR$RjI{D=FX2(KX|in=JR{$1?C>vCuWLIwJ!~}m2DGrUF`dgLgos=Mya%&HNq%$ zOUIx_wWi&mqdZb-m_{m{FJC@Vwu)cV18pQ-RMCMBk=*cAVt)mcE?Ja>9DBmUn^j&o zi+XXv3y)9Crj15JunLnfT5|HMTA5xEb7u#$)PDPX!PW=v@MqCP+fr&H+Q1UcVaJI3 zTMa1?%PQvS0o^61KjC=Vl2)J4Ek}@Z-zT~Y{!xToVZP+#!hpG%*%~aLgM%Z#vB|Hh zj&I7QaK!JaW#d|dBPj5FFP40*+|X&JZd#Y{XdvL$SqV6|L!`de%Xb5LDb?TC(1!0{ zY6adMz0)BfZ$|nSG`44vg~8ZY^3DrjckZZCM*G`vUL&3o%vihMz7$thRtB2CK?^u2 z8ChJoWo}{uSn~?2;?4=Y=diVX6OuMQJ%6)-kAcgba#Z)PynWH+IES~LO=3<#i45M{ z=L>t(%m>WVDq}%vxF|!jtoO-SvHz5I!g|hVax?TlDYXAPg_2n886-q~CK8AoE!e(P ztW(VnCALLGW5EShVL|YXegq2;zJ72Zu|q4Ndk*y=t$_2!PqwU2oo0we(66ixnQ`bi zPfR50+PiL|p5&&2S5Lb4?(!m;C+P%0K_~8s4hr=+_bP)&>vN{kmu{&fIpuL%alXy~hvTN%14P>B38UM{V@WjaoJok|Q z3Np3eRv|&kPFIX2Cwc|}kWz|S`y(GLXaq};Vwc?^&vKdiPOh-Yn$Ex7m#V#bGA4!^ zT1%KPzA)zQjZ_0fV)fEW8@lQN9cl>k5=+jMa5(mPYrRkoIx2PJRe) z0)>g1GtYHiY}p&IQQI(<`qCXgN(F}lEwb{vC8%hebk|-m@LJ4KPI+**9{LQLfJUBP zf5;~XUM+a|ET~afr($A=w^e1DmrqK~ECv!T$LdW5M-y*4etRK7+Vo>JE7j-YWAD`k z0KD1R&cUpFLCG?2L))HhkD$zCyF0-o{dvf?bth9113HIv5&9yj90|=kU7=hLwl3s* z`;(lIQ?Uw$MFOB#N_0oI^;DAOUo<8+7kxnvY1xI$mE_t zSE$ivIiAk#KEZ)ou}x%wA>w#fjX({>-I*uU(V!U}s%J(o4Jx>sS;QySUPT||6*pdo z_e42dm;~jV{pXC^cIcrdZn7%XRl?lQ8%)tO4(ZE&iy}%6fN9kudR>}3z=n)!L~M;S z^lLEqfMkn)YYUe=Ky5*x`aD975#2yDs67`$LSO%rxT+fYuYmc=#~=qe?gE|J#9KN& zkkNUyQUf9KI7G7@5e^xAxXqO#@bK@SLjBB=Q~x?$q;yrH>rz*EEgC zmNk({*!FyT9lhYQDZ?p?DT$h(}j{=r6(e}B88{)&!!5$ zt9F#nT0_$Sx0;<~ZNn>JTlcaIx#0^r0*7yjzHny3_c*33rb)y0bjK2^+ z-CQBxF3?%8>zgq4<8>YD(L;B3rw%>9I7cBZM!*zK=gu>?9Lzz%2zEA#iIV}%;%b1dNs(LkhKG?fw_ z9zmtJwGN}m-8&U^AV+~$DN6=0vLq{zB3M?vn-nNO>|-#x_E6va?-zQp&T^5=rh>7H z1v;HgPG3u7D`n$cv%-eK!?oUXQYEx6oYkQE3kwUE%MHb$2bl}gNfvaU4REgkB14J1 zD6rn2oOxYQKHJ!L7GOdm2`ivkVe}C|MW6c1Dq_gtlm{|He{p9QByRFd$U-dJ8q*AZ zF^V4yl&0J5Ngz0>9yMPWkJ^4}08zlDdc7#R65Y6cy6_XnlgB_0CHXy^g479t?L(SZ z18oxI=vG1!^=P3Wb0g!|>Z5ia;SZOmn9PI}ieFxfPCXB1>=-E``*N&6$CQF_;DP#e zeh?DgX+LOU<>wnXW5My_)ox7O5ZM)AGt>O|+xNF9ut2VTtMM1+I&EN~E6g=+A6EguhRWM#g~R8SUI zP`k}HE^7Q=2Rj+QWCuSpa=w8#AfR7CsSSS_*kSeuol(!9uRRT(Hv%_@kWsLcKN3-Q z{`(Mrx#)jotT&;OQ`>ZYAw|ahow1v-YYx?H_R523&(MHW4VU*>mA?`mt~_lL0lL=w-JNAX)n-S{S}m=& zzke#}3g?-qozeWqKQE3l#rBN(ae8!ai7VaQi8NC7^9<*Bq-3X5^h|U|_2ePpo0!yI zOE#F?r7zPJfWUp$9!1mSl+2hjE#>8@6YK>vI_K^vem4+QypWiZQjH^R39z?UtFw#C zOL<0dpbZdBUx$p~!S!zgnsF7vZbNn?6GhcWfj+3uC771gJ(C8YI0~hk2i?(RtRmrb zwJ8&B=_GO~OJNUcVq#*BeU?TdDJP<_pit-paQ~#?K;>>rYq2QecOMjxHKa4p|} z$Gtp%&a~|YQ+RN#mS++V%hk*B69l#o30+g-M*X5$73ov` zNXzS6E%&Wfjq3q>mf)86>ywDIxex8|QnQcaBUG=`6lSbZY-7~RSD(`Fy(z&yz&-99 z*aLP64qhy|W)b*a6VEDXX+Hurt*UaeOH8Blm3$x#bFa8Gtd!hI{i@5N5-w<46&JgG0mem12Kk?om?yxY*JJ&h9l z$o!oL!5k*dd$D_O2qVR{H8{)v`wSP9rNBGf_iSm$*SgX*CT{gE$!-?*v!(H;`YwMA z2n3A+cZoj*F_cJJ@5uRu9G5IA-yfeyb3i=WBti%9rclzrph-+-57dDFYPZ#)JK-^H zIt59m2C!>`+q-&QzwjaGoJNC{q4ZX#!`4Xjzn}t;2G525Y1V(Z%ByhH7-W9btCCm_ zLudo};hQBfb4c)r0QB5rP;)z{wR4aD7)<}6F%4xgHKk@^?DaT@@mAEOi_)*UxKnFu zhp56Y)Tx6mQp?$gukQQ$hd3UV7xC@yPk!q`Lb*u_(gEipn*sfn-5#1qp}gy*y(=@L z{!&re5xZC?v(>4B$f&5R3TOE&-&>n|eI)`nBh&dHy0@k(0eb3LbOOhm;~;AWnaR>3 zD@s)#G@4!=?RQAX&%ePLv>gGOwxQ^k+#wHBl^RSMeQxiXThj*Fc*z(S_h0pM)7RNO zJT7ztWcE3qn47~ykXSWSdL_!luGxb>=1^_&X-+Rq!E(A0tv85l zq1Q*Is>0pf{IJd2hUaTJ&U#XY>=NpKNsNNq6F!^fWXv;1H0Skk2ixFJxs$|pf_YiZfA_?FY+PuhxfjR zV~s~?f0WIQ&_)BF;xwpoV8vMQ7!bT7H%bJR=$2I`MAsSANlifL-0f#HgQnjt*ZCn& z{FZtw8!51L0|C#iY_1ovZq3!YVh%Pz_`9DA{6+M9{=Pbj6+*$k68#Q)=z&wbAs;`{ z*iZa90PuGKXysS}@Yn%-(J(OWQ_t|Ppz5{)HYVT?EBY@fDmLX)xckYs5H;ra`zXdI z&pm~srAT@hlzo-Vz$EVYHIhomE&cqPjRFNGq@m-2LG#>uRt$z<=R`rWB`Qu3ZOPeE2RfarBl!I+HI;PcYQC^f!= z=}D&1*Kje542w7_(P+F`Q(hn~z`;9Z8_C);6J2x809@l%_=a!s2iH&t|3JodOS?P> ze-Vq{jq`Udp_=;q>@zA*U@qVs7da@p z!4#Rv#eiF8gb}w*a~~G^xv2d3BLA3$;Lc{yr>^>(^L48!xReIvnf%~cA#|ugNrr0U zxJ8$&v}qN6J-J_J#_&{Ky=bjXAbAwQF3YUVsb~FgkTw=K&MPmQXEi|(HT!xdxq*4~ zW`gq<&T>MrQ3{)yYI9mk7&-ZVDDG`T4p*A125lL8dGcRwk_SEW` zpzzvz2un*`I1>Fab|shwX|-$U-59p@x?VjiQ)Ne0452?2Y{$xZIk=12-Nxp6`9RHG zWGZLz|35Mm_?rz)|9@C}^LVKD|L-3|QldgC%M^tYDvm8<2npG~8IjmD&t@N{x{ZK%>cZZx3r8Z3$A!)Mr;#y6Ap16*j0c12*H#c;F z!W*?(klzVJU>rBV~S@7?Jp@A^uMbp_oC zzB{{hEUtoGb>5dbnhPg|X|8|scs{*A6goL?$n?ap0Mjf^xNmvo#7d(TZTVRNaU6Ba zjn4YcC*sCHU>Q5O@Jc+fQRAe-*MeKfO~(%eBth_~P1XJc0Xd%;R=y={UtCjUBky$A zyLO*E{u-Suc(n9{`ir?bS$3JThW#bM+;k^#S!oDe;Jpe{gFH~}3<)H3LNP?kLmp$^ zs~#GW1Iy$k7YD%(^vZenm$vOy4NKAZ-KA4XK1Z@A$*`LwlO##_*E>M+7?5gwpgIRY zjLP2Zec+Qr13!tz?-mishoLPdB z{_V<7**0ZKS8pPv)xm&}73uSC;+FE)hW1aEs%RK}Zv>tx3ts~N`8wSfEMS@J0xMAc zEdN+FYT=fN#~x5J)ZS+B{I?3eQ4w_iC*+j zmei56Es=gvp!3%yJ**oi^bx)SCxCxFynR0~R#9jr;4A9%{F6)PAC^4;en%!M+X;uO27R`Z^0 z{}%#?7mp)Jf4WzmWLypMe@^0Hv`X$}{MjIb@i?5RSv&{ePJ3C^JCm{7W0ybKBVX_<+w96~N0a?|EHJEGRny(bQV;-5E@Sq=Ae)J#WiDMhectQm>wT zP&Wxpa?k>|sGL#M*Y%%2qpOFGIJV{Ho4JE8X`x+83r`I^1|VOePo<(&w`uQkGVB0g ztT+BtdB?Gwo`sCX&174%S37JwP+NL>dUgCfR4wU8y35F12MV}8*xg6lI{u|1PiN<# z9T{|CGG&gUFm3(xx+iX!8~m2HY@$J;d0;JU1+M$U_Q)~t0RK2GSDun94k^G*g@7uA z7g>wyQg7`4`Zmp!;ZAK+Tqfz;E<=LABPr2o=d-VQUg)@cbF6s|OMgVW-prWDcM^NJ%l}qPzo| zsw)93nXCRW7tZ%9dNz6DDbiu#|YG#Lj~s?+74hK`GDzd7DDthehMx(S#D!S_~+a6EM7bmYO#?pg}i zypjURAwx5-$-5Z_o?dsLi?72hSUBdzjic?Cq69rutY|8l1FgoPtwB|I(+yp%iP3+Py=Cd{X_iWKbWa(Aie|FN~l(nk+!0|T&Qt;G&=5By1Qwn~f!wefF#P&lF{La0xp&|3zSQ2bQ(bRo+-NIgr zLP(7+lZkvkH#^%Y^T$PP6}vaLTJTnnEHcwJPG$}RC(s3^rtq#Lu~RouS6g$qv`cdC zCuU#rsdDzR8|2@&5=bH525#B}D;Zf&uP-zupA(wGLs^!hhS+{&Dyz%go&A(oema4f znRx+P>~4ZBm4f>t`SgzqZP-)2=K#;`Hd_k7|CHlj<^kbE`vP&6xZTh=i{2a}E;kbU za!vLf+V+3d>^G?HZi6I$2HGAPBck!t!toj3;T~-%@R}q_D_mw0w*Bu9s|?zN5X4C0 zROrk`5!$XGvbuPioBPvbL~W4smh^J1Uxh?|*gX$m5wUm7jHNHV znRX^mQb|c^*v2KW+dWWgd1mI(E5$kal<|b*_*+lIIGA2PvW89XJjlHe^$<%UhuVK` ziRA=B(}42cb7Pe2{=nZi^mfoeki-6^^J#kyrVyMk7)6{I zLR!cO*$VvDoc>kL-2{UN5djz{bZ6y!)wu+P4bfM{cpx$;B+Rh%{MNLN9wOF$=hF3w z1lo@JkeDOKfegfsP#-w2Xge}EsJIl>VB=y?)Uvs`dCxD^<%M4V#rFoZa%DBbMxsB& zq9cXU&Pb^*7x4jlU}R!!rMta7U2}$JS{8g)b?OzA0mb~FeHd=_tn}h5RDPR<(}+TA}(ElK;W`5j*|+x&;0B{EkmZAN8)NevhTWq8{V< zPr@ZyKn%1Y1L@549J83#o;jH|ow{|YS?-0!t7E|XcM-JVxw77$3(1auNxZkul-NA= zBN9m(r6*1$1|}U{xNN;o^JY(?+c5j3zw9BWDbej_ix==g15qKqq2Y-3l`j{zWR~G< z^d4@*^%SlWWRuur2Tj+BNk13ls(_`iEtlrO3S)iv!76cUeQ0I$U|IlJA8UsD_c6pa zfa8U*dqrhYc7(;3^4EtaRtL^a#g2`-UOKM_-vgOmvCe;V zUrCqeImG`>8vP$HLgAAq^yfU|HmD3qiSa|%%f&a(i2x#E?hm`73RxUS7q5%W^Wqto z)D&9>2OWHV(Fu*Z$w>|pITQ$>a-2~P4(<2|z_2^bF~>!`s^AQcgo48J-`M!)aifwZ7T%-|Qb9O+|x1GzX+= zb)UJOMZ*mgGR?&_q32D2D|Av0yp`^$6csSyL8YGkQE~0+e!qs_eGWpiX!5)6&y6=l z%;e_-kGwh5duY8p|6#}7!^6Yc+S=Q^&IJXKv3gH8YUkoVT13hkujljRIbdr34ApH-z{wx8;Srj5nU|?(VidDqS@;%^nqYkXp|Oa0ueRZwGOphTz(-yGbFQlPQr4BCo&A z;vag>F+;}+Ll(=fCiA96f6t9T#0}(I+uF8bA>k7kk4ER&nHj5-^F9jgz(Ne{V1*=v z(2yeX9qU;02UC2bW4-c|;fSVB`ruV|PZi;Y8K=cHzlLQX6i`vG^TDhQw3(G1`S%a$ zU$aurNnZHj67XnA^~T||N8+~$(02UFqj0BdA^*x;CI9!-bxyeUV1EN5;D@nw&_P;7 zNywjiez-zK#Xk*1QW#-1z<5Eh^AISczYc=QC}@V1s@%~XtJzZ8%mKZqWe&Rf98iJW zjNq`av9SRNEt=8`>-FbmYPF}vSi#$Ti3X_6hBH>UYW_W1j6GC~z-N0Me^b9{(5a^L zNGsDFF5Oq&c8$>vup+9l;@GIDs0&ON@_IB+x^E5v&ZMb+*C#_YDC4nTds&%Sj~ywx zPbNgcuV3?sVUi!j|MOZvt4G!62pd5L$acy10rW^T*D01>gWUDy%)5@lELaF+Kcuf=Xjm(2r#ZeSDr57%$Ty1L^ODDswjVGb55j`!__ zB(Fl5w}9{Gm9cx}=UFiKiRFlV`HzTwZ!7+Nj{@1$OI%m$mxC2tB<91Wm7t0^*w5W-xUW|TcPZ87F$3kLJqRKxf`229PUa&0P+)Q6sr0;g% zQ+7=;kSkM*9>unzV2V@AZS7{RY$&0XqD@+mDAkoGyO&++g}{LtKNlgE40pb_36w6Z zeE=|=QuX7*aSeqO#Mu+SkH+tITTNd`UR5akscH#=RxLJV6s&)_OF7LRA=DOWY9hDg8<^# z2tfwZ?h8=S-I<=h--8rQ2Ww`S%}ZA{T_c)~h(n&3{=7rYQ%``p?QVAn2UUd?6ZQ2T ze9_I=wXPH;>8n0D?u6QR&Zng>AOZaO`mHal$~QgA(Ue3mDc=FCQ(Bf|F@%ftiJ(we zOMj=Eo0L0RniBs%VND2qrbjlYUoi}TW4JpHLf@InBIx`+Zbt$TduUik5*@P8-Ba@)wk6w+XF zbAJ0=ZQdLp3Yx1^6e@djVQIkN7C5o(2p>UM?$Vz1rnuAp8y5_c5>juEo_>W|X4O(N zJ_xk+ACcq|xYLJ;@ue=OdVg+vi5(H3E065#9=IGsq_Z>d>_Q?BGnza5DH!7~=cE%? zsO1=tXE2q_FiwHc(LX!{r6OmXF4Sl8#^yVtOTkSuKW}~BYF(mZ80i!%)H54gcu_)z zpO5dxjyxtv0A_P$W42wsEE|W-udI|17H-fYqX!?ZGKS_lOn~x(s1pT7;yUaSyZylS zC=ujzYA>CCoVr|25w+o{gQw=qAYBQ&7!3M4Ob7-DI+&vCFfH;(%<&sA1@dl;)(zNo z*yL9lOyCU|iu^d{;08>T+#Dlv6Q)bvheG(fHw`mB$Oh*HE|*b#$`rZeBBhlm*z{ZXP{* z6=bI}Jx;Z3=iwi(2oXRH*LwfdzHknm1Rrz$ zbb)vxb23F+jT?wB{X_ntqjmY#r9lad{oOSAxHFlL%jL0)NS?y$w7P`)%^`75691y; zN5I|0@Dv9lnth>pHIQVDEeF>KiT-19D^JexFtKSmDGcN z`r^nc<{*}n4~JOOExBfIWid;SUvwlj8FMIx;+gI&`k@1}4XFY@<~U~%y}HwI|E*3< zK?VdWfY}Maw+KKrt>SYJs7SiGriHUl&)U%PYhw`dl(Y%%NKSy}KE!taZq){x^)0a# zu^*E%KxVrh6i{0^*C@YGX=GyA-b3|mOkJ-Q>AW$S7niWU9djOkO6KEGQZYAG;G)xG z#zkzI+uDPAXWxZi2Y{#lr^Jy25r&Lz(P45z&Yro6^9W~7_ItU1qjTxo9_eP|vtACM z4H;dnwtqFHQ(tx$K%1r<<1>zKq-TTqtpFe29|D-|4^cJr+F;tH?eLyqERz*)ylb5T z@U_9u2XiGWR=XXl0=5iwb@S+@6K)~h5#r&%{CW!?^hEk{MkHZkS15~~d9~$Ap{Gsw znXjc|*V9-re&c|e@xKGt{!F$JE|r;F)c3)Tk)da|NxDsE+pX3LrsH;rhL(%BM+TKB zK{~A7p+P*#CL(9bj1aDO_Vz|J>lOCzm#2SZf1pWJd{uENZ-rTFnd)Gz8-O4T6 zJhjM2h1gt5h3hw{60}&(g|23_jyFHmXpYX2#d(RRoQ}$*JLxU*-TzxyAo4_@o%~nn z#M-i22>!l1+oz(r(8+s+>rE*M0jJRW(rvdwNkG$HxurO@~NdS<>j| zs>GkY?M9Qn>?F54K>q9}%%a4MmG^YRYDV`CzoZxxKvG%fzyk=a_j0mNpp%Ej z<1=CiM@X6P%923uUd|&M)iAZczNfm`N&o%Hr`q9=iXHvJyCdgZC%AJLB)X3FI*oe7 zfiB)@AWhRJfN!Y>%gTDHswZx39uJxPB~pb%?aqFs?Kr!){y&l5l0;yxBWvuetUc4? zw;PjGuJbiDE|t!oAcpIOyK6V{Gg^eJsnykg+ykYpxmH2GhECbpTW=ev_W|?7>)^gc zo&aZfyH?}^t%J=e3CklzUbLAX1oZS;n$O?Y$8JKKLRgtob3Zz#TQJ#h_T1)gSA*{; z>)w#q&}>{Tq~>`5l)URQX9Mo)kf{&d&1i|0`{BS?^D(@cjFoK(R2B~%#%{?^KVY^G z9(7+cjZz58&g-e8kQj1dz#kD-r%dNY6^RBlGpW6);GD&!XB@?g-K)7AQ8np(hx>F<^&A#RmpZS&yq`YBL>F5p#0x;(9m1h| zU?GRlmt>Xjz5XW65@zawBp|ki1@4it`h~^H%a$@lf3Upo&BRpy6ZDOL)Q3h-YI_YD zTE5Awax^S96ecg3^q_D!IU(PeLZv&|;R6lsgIurpfHHWiT_yoBNR^`L3qN1`x=~Jz z;moszm#&+X=V5r&c17&G-nm|RRuVA(_k0&*4u|BsF7;U^TGFVU=sFU-v-jMTtb9hN zo{v0dgH_Ejz-MP8hsi&X%_QtooP6fr_vK$;Jm^m{-VL_!ca`JU`1qLm;yk(bDNgJk z?W19AV3=}yb?hPZYwFhb1uQ#$Ws-1_J7GQDn(JZsjTm8Ds|D(Qd6k-Q3a~2aKfI=( zoC3JC62H0NpZ}>M)fJ zXW4tPA=Q0$l*5Qsq-tXORARPw4d@bJU5}KF%~t4Znl$u!k6lFyMI!j4jNaV3S?>30 z&_%P4s5$YE`S^4KXiJo{3<1N)!mm~Q$bah#)ujNR^i|KS*X0oFkLFS~@UIbXY@p8i zRJktRR>vv2o5jds1EeM@DTFV=I^xQT?{9t)@}5n9YL-W%@ud18yWfw{RF@v#X?;)o z;2GYoHHvBNV{8PV0(qsVLA=zf^{jV`E;9&Tl`=9q8l7`J6^GkO>0PQz-I$`lXSM#J zvk88@EeGikW@!2u_LOIj^i^Nyw`kt1s^9`A{~REu@p$3T3-t&_Rb2Db?!v3DT1&+i zC}_=GuQN`gHJt}#9Z9Xz8u2-(Kne|9X&_{av*{v(B^EOr?Cmw?`Kdz)cZim%J&=#{ zobTTC3qAsC*$^9@ZB`DKRBh7A;zvh@z#P~;7l;~o%(hgmShsjTPTda567x-Q9x~D1(`U%-4x)4d-6z9&e89=!Qzt$fI>E8c zzAANFV{{w|$BCQ?e}8RYkg8o{Gej>hGh0OUbfh$Mb{)`rf5@gl@Zr)Ytjwm7)$pc% zaJ2Y0!`g!q752fry?5zj?|@(&s$DN?%5wt`>j8K1n_^tn$0c^K#pfKMZVva6Mi!TT z^#q5JYma*}E?uz9WS5nTjN9WEtJE?Z7N{~gJW(T+@%0Po3Je6_UP~S@wm8J4>S4%6 zK2_BoorBIYyZL^`{OmCnn7n!5^mD`YOa`3n{fj>8S|!;O_^Up>i8;Eo7O%}1z^UMEo=j$S@C)R1mM6e3!0ww&;be-Wzp_-?k>pJRnmazJg$6dlbd4ESN1 z6YoCqqOdDYx-EXitcr}T!i~RRN(b+4n8)jzDE2f@e^DovpmdXj)06sk6P=Ls$NR!t zK7Lbny8J$tJq2Cii%ie%_Hh|%a2Wmi|K0!q{nr%$UqJ_0&ArmYUroV+&dO*w?0uYj z$%Cc*s7JVWdK}T#xq8u2)~9wa_A3_bJxy`@kTg*FPBrF{Y_8_kwKStH;#jDwo_6(u z9$&Zd(k)Ilhv}zogVWc?)NlBnRvp*ISY9J#n1eArOgzC-=v71Lhq5~BVx4|fKS9K) z`hHY}brLghFVRn^%WupyE5tmeqXVUSp*->9Id1M~70+q@`uCf~`;AX#nk0L>SBfVB zj=h)BMaoiXRSPP%tG&jnHwNzY%*&z~-TO7=Z)pTMyC*p-d~z|_{MBP@p=GQpR8xAM zS(hk&>!kSn`u9Od-*aaob?oJZRqFi3aU(*jlkDDay^2}q6N+l_|1cd*Fn4K zx291U47}imE4OD?touXQ=f0@+i3i`Iay%8{3R-mm;>$>P1CFgZtP=cM#f8HCE%aK76I z?|a}NO<+!#2T-Mx@p&%fIqf_ngGooVqmHDh#7{DRN5A!o`_?MV^rtQyYN5d?$ zO~VG8Ri4$o%$*^5Zrw?-8!_`_DfbUnMDh;!)cSMDnArcoE5v#?vT`MG*KJmv30fo% z>x-jGzZ3Y#chS!Aq=<2b&k4G`KIn$;lZ?t-Qh8zuVDO_m1U@*$OJg z1fmX3WO(dmF(q|~Ghi;|{5tp>+XN7N`WL&6E8A9wAEteK&TEcjEFYD(XkhcPe^dwB#YJ#^U=Ocwb;WUAqR@raTHiYd`N!C# zAIU4XXf3E&{^DH`B>&L=@z|2zi24b8szT($ivA=z4TZ=RX+|$xd=Ikr-50cy601X} z%gXEOS<4T%MjIi0jo6O`PZ@D3)~%P(|OVawAV&D-3zqs z0s!GhY9`HZa}`UTxrP2{#V@~PF<~nkcqH2TWw4nZgbS#&?UqVGki{Y7|0^ zpUQ8vqORZlAG<<#!!b`+&(XnE9WRN;eRVs!Yx(+{Ge$-R#z0~J5Th#tTctW2Y+`gC zz_=kt5SV?^|kNl@{K3I|AuRFNG-U95Zm zkW8s3ZT(XR>(Y*5REef|%P?_Z>UU!!P%kN8979u$gStlOmKCT=2+gbsgEP z3LWIhP8)2(Q`;ti))OLI{yMX4M_j+)sq)E__mq|yKvH+O420C*vG5#Ncqs*~JU6zc ze{s9dJr>Hf${p1XSFxPd9#rDEX1DC%5k>dp@_D##m8_Hl8c4%z?CEYjlf#{86!5wu z^LEQT;CiN@UGsvZMH5Lf5gBX&Wu;?%W^jVA4t z2IQX`yV-v107t-9vt=c~wrfy&{Y5bGy8;kGCU(V+DB;e%B*#(wvHJ43}+3ivs zm6~|!Nfz#xo>p6MPI7mYVRhma`eu8fVbO}>&Z43bhooXB7s zJl%QuugV~cW5>=osCfZMhqG36Vq@tkx%T1^IW&~l%B&z^lL=$nLa)Eq4wx^=@E+_w z3cj<-j*2;?2d0i0(L*AG$RQ$=5z6E%qBU+kLd8ZtSEIvOqM6J@Z4(U=5)5N*tjp?k zl0_+ubvkP48hOfzcU+Vg@BCT5@@RcY={aybvZ*=tMZ#6ZO0LWP79zkH!q*(}8eVZ>h&Y+6ua#F)yN-uD| z2E(p~$4rT_#iz?S+AZUxBk?c`;svf%cn`hg_5?{{cYVv zVpw8a&#htyT@m^0UAB~30~>nBN}(nsW`2#Yi?7H1%(&acJ8_Qo55mFX$4%QenvPH( z5jE}|dtx-ST)e;m+|gNNrryagHrveu-`Jlxp|2;z#l!iYHyi^{lhu0pwpbGL^efnX@+rZii;mt!5`Pz)iF)VGCc>($^6-&FzxDi8=b- z{FBl%tc;Ot`G>i3?&n%yQw#6wb2X-LD)J_J+%y-RS(m%}{n@&^9Drqf8$Jjp9 zX&%wDE92bhm)GGxk1wjr2Um?A>n($HrkJs+N~{7VQAq)F=y2J!Ap8qgwrV!!w=5@S zpN3p}g_uMxqGzHx;ip?ST&!g5nrBH%1unJ!VaQ5@k| zv#5kEi|~3g?yr`Sg#PhzS#cHeeojS49;2rpL#A^Lo7pAHXgt?Es{n|7v=5?jTNsS{ z7F55JZ**$yjeSMp;yXXuS-Je}!jPrlF7-2Vk8`y(b)KP%cJ@UA`=2*-irqey{s2*l z*8UmkRA0BwAS{||C$Y3$Ai@7Fp6&Fpwp)vGf(dj%v!X`1K1;9qfzRoarLM^AsYU_s z$j5}V#dEsPBEiUPoF(v$nD<=bVVJp za4-;ykQ@Z3hCP@46z>Fs93$MR6(tc0vMR=yd??&Ffou-d?gktgIO57~vOIFr0Un-h z@2fFug8L-FsvpZ?a!VsEk(u{`M~FIgZ~|h_HH*HMfz!n1n~5IB=Dk!uCe5r(GPK~* zAxP=UiM%33|OE=nrzfn>b_)5-HsIM!a=6zo^^I;fs{O4AG&L4z)ZXE_v z4xb#s4RoX*(mu@np%x3DFYJ5F^*C21%r!9^b+EAnW^tzRWps14!Gl$w4d;Z4r}YVY zPEL_a#Lw;ZPrY0@G>E_M9!krg-|mh7mWB#c_%USrYi00!O`5F|E`bwS2%T?heY`7~ zsG<15DarWvbaZrCDpt84K33iA7TJ>NBDi>4<_;@sq-7qsEsvG~T59hToO_vw z`}%Rz{7%mXBit?vj`b4H6Sp>ipjw;SQT# zvGZz|>OE){dE=)N7Tizt8{j^_Fu`Wl;z;W7hl5%B8^S z+A>MYc$giK#NowNF~g^I4*{jGXU2F3d11aeV`JS3^c+MV!X*9`el``LXcYP`Cu-#| z0sPXJWOLnJ{F5sFMIq5 zZTKW;d2vlau(JqWR9e)?9bFb=L~^4lPE5s#IYCx%lpNOD;aS^?rs+Flq*?A6%X$AY zaJn_OC(>;gRi~@d_9H!9tEVC}v&3o{)b7JkcMTn~RXC70XLeF5rZ>fm!XwM+T$uj& zcv*o{>b$XtW92ZLYx>&I$?JM4&x$?p%x!UIql{&@jGrA{y-}m@k;=?4D zb7Ni!!Wbd2!0@{#$jO+|B&2#~xEF;`$J*pO@^;(G@bJ9wSYgTNsjP*FBkkOPetrHW zy8||EZO+opPB~no7T?#+CZhxRC28$$g(XoX<;L3`#tyuT1@Tz5ZT=%9L?Kl9lfAv6 zGe6)2Rn);&!$noReIR-#^+m3d2JzE9{T%2)U=qM~O)?C?csww^BmVj>h8L0+MxL^> z7j3z`MZX_hFy(cT>69t$Elzr3Jqjf_R$EF@?LW)xe2R7EM{0Bg2p)XQ#C)<|#{u|X zkNXH-`m(j=_OdnT`6Hw?kk7>V>@=H=>qy9;$M~?9zlKDL+6}2Umop~ZrOgda^1t#v zC@rNC&Oj)IFM z3>aG>lTwSFRNon$)+WC-u}dlJlVSH#;Ui#UT@FspNjiHiNhWXeDKEI?KUsQtAMaLum)+P*v)*!x0U0&cX?B_1#lrX4`rWc3^}tHi{xdEIMtPiclr+PmQgWY z2rZCc@U0qDJN2{XL`LuP+rb5#cc~b8YgVRGU0Jg>=`pv3Nt$>`d=&hiVJZ9X8n6l~fRDI{bjFABP{mvg3T3=MW(y(O+ZY!I)0Dm|?i z;!_ifx3WOgdnn&Jjm;k2nDc(_!KGd{7<;6r_YPn;mQX)N?FKEDeKNT;>y9zL%;5>T z$A4Nrmf>Kd)o*C!ExQ+{Bi#qr&l=654!rK=($>;t4I4FuvsD7*SX7Ra*!npV?WUqa ziT=saBn0Z#vlKM8K>$j)AS>QMkTGVL!*jjLGc-zJLKwiQ(iB+BOLHTko&f;s00px$ zrKZ@5wS`xYNFG2JuO@8w78`CJH!e5o$~~%huDa@J*}hlUD=7dZeW1e& z(14Ys(QRa_L>w=dLxS>~kSnuFkdo3aK47b%k>%%c*Tr|1Dmh)WOgWpd%|ZwNBe?DD z-Ft2ROh4)IeA}U}2_+J4kBZCbggNQ+5c@Z>AJ&cj5shUHjiILAG#>#q7QXw4c$`X=93 zi+jclIItbP#yiXM3O-b-op#Rjym+2RD)F(VzG_tOniu!)^QgfK&bHprCW&3xsQ1sv z!vdrLkq4%K$q6IFNa91VCE`!aletNSM&FoQya{#jk&4&i$VSashcg>=P<)edNw?>B z3CB`_X)d2zyUnc3(>7%N;}ap}TQE{S`mM#_!F)M)8t?qN+D^#63lQ{z;~4=@@WVPY zVx4bloN9uG@GS?e?*!8&@`#Uryt!aH2J7eGASP{8QypLloc4?vuU;Ztizwuz*y44y|LB2tWj-q^8Fu)OWze~g z1*+4slh(`C=fQYSJlE-kKH_tq+_kPGUoC$~G9kV>v#>$HGfKNGq8-$uU}uSvTY#o} zeCi6@VoE<=Ay?-o@@jpyby>OMlpEOY5D z?@Bufh0NGdMIe5R^KB(1*?Ynbo*H&IX@5Ce5+Y}c790yLYRA04laP%t^QP0}@8DMt zVVDtzRfJTNtLI!b)d7^z`}cG9lrXR3<-KbA+6&{P9;CqSgL6C+R061DP0qXeWQSJ? z>5ber%D$r0A!f`edfz991t*c{cM{Sg3R84lp2=nD=rxwE+AjS?U6j44=^ook`}xAv zzJ@w{NnEzdDSOhz98q<5DF~E3zgMwEkRfi|=p5-kLmILL^pSQq<_m*OzdkLOb0Sau z+;-SMUG*3YYAOQj^A>iWo^cyI$LoAf8qX#(Eg1K_JZ^QZhZ~A*kB(aLGRu8Re$Cs< zOX9~LeUZA;4k_~`g`27+o--oi)(s_mJRDte$s!WQnG3#pHGCEkRjoT}G5CvnD&96W zSF@PM-!X7ZzH={0iIG2u$~$n%l}oQvUEyG?N=OBX14`V7 zy72e{P5(f8UsNWspzj;`{lRYAVysB98iPGh0j?)CgpQ7w>jn5f$v-@`$uRd!FUy$0 zZc&e?TgEs*Z`2&R-YH48gZZ(zBcW zYCNKco*R3O^&0=;!h?r3KZk!@R^P6;7bEYUkA=L8JdCkv`Jt(u6l-LDDKS`PQCszf?Z_9BHo>;R* zt>hE>RHf)qv3$vLzcaM~;{2L+)ym@XFos?iv}dhW!}Rrn7B1#p&+yVZT&VGlLA zP*s0%GZJ3o^F+0!_vDMIBJpD>aX%R#A^3oGe6&)6tCLCJ(Aseos~3Z*hsSq4A+C^{ zacP+Meuqu5p;+T*SJDdTM4cs#r_j-s@-?CLq;Va52~H@f1PCd`yW~>iGOCmt?`2$L zKF~yhFe@BYjN|xZ$&4;kVlNW?7&ug%XMA;jSbSZ;=vZ_T{x}b;8l4Jl6+W<`2N>36 zUvaj%J)qKC&lSGish#%DM?(y4UHKEE`SM84v!C>K7xalyOAq8SU9_asJ*hGh%HV8n zj3w#P`L;D8&n&79uMNEd%@#jWW%JPC`+}-B)b|&(fR=+C|Lc3??v2(h@`ZaolDmuA zq>Y_UfEyqJ(J$WvD-;1h)%>F!>kFg4TOmL`EHQLc!T?K*lAf-p+&o9$jwGvKE`B;N zHkJmLcnrER?KzgM?V}T7ktU;av3|im=i=10Ac>|ms%bYZd!Y`e&U*sPw)>ctVJp$_ zQKtkh(TAo>hkWsT1CqAZYwel2>JklV@u(n#z9n~cX)Ct8+C`2veO!-iO?qB#fyz`0 zX+;(D@#s8YKWgV(t?dMWAe<=xGbYTX)MPxHj$;5fq@CHOSX~^AYLvd z3eUph`asM05PPmlCL-)f{{9IjQwQ!~318|q5weyG?-(9pM?aun{S2_5xY*@8$lpc2 zpRB_|VjS6w@rdY40vl#eqy1-b9~b*zyno;#(~Y(|j56mLnwXRbS9V6lHxo9>X$2)_vA1j~2zyVfhLbBE z&l}olKm(bd(q(=H%w+(j(hZLT4zjnPR2U z@ZIBGj0m%MeoEdBHKdgVu+r5gr-9#Li(lm!8NIUeTgMw8m8UlZ@^C1khwm%wwO3Uq z!g|X-WqV0R@o%y>XdB!0bg(BQLh~dCKjmb4q*^|(Kv;n2dPf!HEPv6Dp+o%f7d_jt zQhn^GxelJZQMu1ObmImfnj%!S3}Fj>3Jrfp51&8*PwJ3)$I6X{uwg% z^(p3Pt#@~+aVoXgayogOtU>3oKQl9rr`xD1wi?%KwsTFY7G8_|AbO$D-IVD`k&aOU zrWOLT!y)A!oKR>AXw4++EIkMpzk3-qm9b^+Z!!1!QO+IEW$&d|^JiNXAnf z*OW@Ad5yAP)!38ifxXF1svgL8EiJIeO5Oje=!LC&q&ynq8cgfgo8PJ&;SGSaH}U^f z{5}|Fm*bC~Q}hV~6MrDv1`6G(AqM80cr@A*1ZC+=QJ;@Lw;&14#-5&@7YY(oAYGoC zFPY%t=3cwz+HgrWb>q@N_9-0kx|u!j_zU8KpYF!>H9>;bHk63AgWO3ck+N69IH%)lDs@DOH8Zig9u2ooW%!Z2FE zd|_*oa+tRkFdgzy%&Gt}XmD)je)=r)H5r;A{BXN;yz8jyq;_Q+`*wWc z{EjE5n{k2#m*wrz&Ge&2W8|9Tl@W1vt2ME*s%BBRVaoRxn3B;kJ#baaLUkbyq@qNy zYjCz+Ly5z_tK;^JW<5p*&@>umiVx39gePE zUA4J7Gz~?9PFQ$(cU}}_1kt!CB-HU?u5#3h@5jaEWw5?Lrj9xSB7Z*WN-bwKw&k6b z5LX7zT%6r?w!_S|#g(T#M%vIVKUm_+u+L@LJn0RWCkRObnRrT~qF+zVRpGY_mKL{W zR_e=WZVC5DH*P4g-OR$sf*)J1-AVkR5w$MEZDh|9pU7stp@6dcvgHvFa`y9@er6oLu=LBV!N>a78EaB(y?#LW1h@0<(Wu1=F~EN6!F#elRyEDd1z@?4p_tJ}fLI(%F)_v7PlU~ z8-H*5_JBKew?p^4Cqd5d_u^=qpvG2Zlo;Z(g9bF$EUmCo@8qIFpI+0Oe=pYLszI!) zI&?s^L|0?;Amap%^Mf$&w6^7o9G+ZW36k245w{<{;qd(UBz%wa0B?eytH6Pecp=`* z?1h?9nL7f3RrF*>z2Qu!Q+rqcj9ZiqgZKqdpaZBmhY!VSJp*a8ry>vwt#|UpqwV^N z%F9n&wMBiX**v0_lO6s<%w^_fukUM$tqRLCyYhNM(3I9~@gHAFlIA~=spi1)*>4P% z=eeQwhh#?Fn~C3NEwq!-fjQ~tH{GKeqOun}29;zRjJH{K7x)A$O6wy=!MGrCjb|Nf z_DHz+65W;Q`pZN{H#sD%+^=50cc9<}t~#e=ikWfWK?i_-! zRuoAhdqp8cq~zEkd+%{<2_fSc$9Rd#jLZ{d?>(}GD3m>pky&(%V`XRmo_c?Jzx#Z@ zpYQkgyZ!p3y4|8Wuh;W=J+JF}KCb(t$?1E3xN}43p*po~y?Uf-g0zXyMWR)vA+1kp zhAH%zlb1h~ug3YIQx|%rxTJ}D7k6KUUP=}S(7x9IYT(+ua&eYFdM*De`xgQYg}eIy zHt_~79e!)feiL@AwuV?=>z3q*i~;NVkq5XYTYLNhN*D~DDAof5Mm@Ks55JTRKcP5}SpV&LHs-`b$l`Y0m z1^+nb9j63xnl8XNM}}fOav>~{WdAn94h*&cE+7xt>EqBsUp6w_F0wyaSz8-l%N!qO z=Iplt6R}HE)35K5gMqpJccxtFt2LU8R|1YgRE3AJOkmaq9k>2m2_237S6?M ziB}u}u%~Jf(s00L@={A}Yv_-{s*=xkT0E)b+c_px?{g}v7rQQLSCUaByw4dm)6xc$sC3(|XT0Kkd{%!FQFpf6KLin=0Qylk_T)7so{c(X7&YEi^ zK_Jp{UN5cGsL7#MiTLG1QZ18))p)9rjp z2%Y$IG$T7eI&~mson(|eh>b+u=O=CJJkT4oGBwd==6;a4Ps$`No9bfzxnWdT_{340 znN%53cY{1_ZlZwB1_*P0YKwWHhfQAh@m4j-Ham&0mF!rkUY#jn_qX=gEi=BnqkK-2 zoYd%BDwPbTL!$U<$5CreoecF3VtuUzBCDeEK4h2KD50v}`T4PYEJ_@RN#rK+WVZo^ z4jDv4+8hs$-2yvWQo$-KAd=G%GHeFh&xZ;~S|y~8py zL@GB^?jvf)do?Y{CtOrt#))%YJgez9d7vMGmF7CaVW=sN!It@x+Kn?B(Hb!xNQk~i zR_zd97tN{dpUB$SMd=f(layPOE|2oQN6Fj)lM(;p1;Ugp!>PLaH}eeaq8Ryqnsr0K zvf|goc#jZT(y6$9b9Vo|+rhJ^L$zGUtobHxyH$>o>6D{BiqunI&0qFBZoLONn3~0o z$+B7!mP)mG2aMi3GYFWpKX~u}iA*ezd>bo!XCF%`vk6-Yc+?rE|9N!ul?!JPe|(zE z_B^|BP?k_01oYxk3;_td;tv~=3v#uTco=s$WYN?kSNr&E%YMW0lTi7i82M@LTc$vo zxv_&~T9#Ljy`>Ry6afJ*_}txc!ycRLH)Ix(tiVDql9UA6KR5IK&4Yj;0GIm6gm|gQ z>djdBg6zTz3&sVfuClO>GXVK1L8AKRuKB!ojB}fWoziQ{j~(vtp&U#4G-G?<-}JoH zOzw+K@uj$Va&e$D{!LW+r@dZnSE4acZGTLpFv=j3Hs}QoH&{}}QgXxHuP}(v^5Sq< zK?Qd3$E7O=rH;IFjPsWLiI6d)`gPUvvgOFp?UBFH5WC4gsSyo%rM6-@nM}yqqAbl_3G1OW9elPhC3<& zk?frZ)pY|_&qx`0>T4o_pmG5k)ifMRx(^i3MBYsffDUUT3X+$WMqY9F&$3;mz2b+R zm2mQ-cje-UktfP}6}>9>HGa_@NUXNvO4{QXQg;916Nigc$)#mPm(%LC?46>DH-o9| z?48ugI+kdJ0Q3Vkif;Ujkgj*7=FCg!dNQjVo{Snw1u|Jhdcloph(FWTx8`#4Ao2n4 z^*m+^5G#K7=lJmj9i#u(ff=&d*}6X#sO~?@^IyGWTHK_jGw1JKBV23&gGHO0n}Bml z+VlayG8%>ko!sg+2O;%dNDnyUxhAqY3{N+os^6fXJykB#Ns4W+CE>29maq~)*UNp`U zdz2}ZClP#jmh&{q7rB!}2qmeJ^r^*Ow_bt<0Zs^a#xmx{*~703H!tdY8_8gU^x>0i z4t!S_9We}R`mRZ7=N^j;csbQv4s+;QAXW?oC@ zF&aFelXCbom_K6WntDUUwEHA44sqM<)pRqwv5XXIi9||GxKY# z#(_($+(M1vB1cEV0~A0~c}{A)-L%@ zm&A0o-r{?XrCz4*$cUPzfm&#tBSB>*=au7WS)5KFQFP%p530cEGErh9m9)Oi@(xek zV{C72@Z3<$5laI7*mG)<=O63NH(O}gk-RtjMS>tiyE8)$X`sA+@~c;$BF%rnEhUZ|@wO=JLA6U(V+-I{+ez<{3(SOC8@gFqXYY6*e04TuSAYtuE(8LJ|-bAIg3K6uNF{A0fJ*96I$(UIY~VhO}f4X?xHCd}la$Rj@r zQK#&i6+4Nz+yggA5xPuP*p&Vy*^YIO+e^joK|NA( zC%ciqO@5Xxr5aUI(iAMhUw+{H;Y z!elZ@H-!BhJ>Xt_RW0$Z$1k||G-Dvst9L83q24V6N>JiiT@(ca@Z|l#bZv|m>Nh%I z+Sdrf=lS)B;0xg#p(L78cDotoMGo;v$Q6)m1lfw@{3c2i#(RzhZt(-PlsI1)t1;Y{|K z$iR}`8%cZfxBQ2>hv}nXgnAC33jQ#(;RriZKEI`xs969|pMcV8j6_m_I6<-j3N^By z$BIyR@*hvSpSXKG>~G-Nzj$Y*$NyD=o1LM{W>Y$ZjI^E+_SftDO z?ZCjmEuNQ0J3Cc=xnrQTl|vPJ;H%)$qxL=Uxu`4cN9N|{UNOqHwY6>C+K)N{zXEeX zl!zz3$X&ph{&C;ipJh3&b_|dr^hxQ(x30Wuh78qkI>A^!Q9T}IL!DuNBTu5UzmSoj z`ddQ`C|J~aWzEyz)yJ@JL0cZVCDTlfM;7cU2@jg#SaU?PX^?^Kzttgfb0 zj^Vqvq9uMYr2h4}z`e^as?`7m9L31^H8o&4V(*nRu^?E@h!U8;h&!M{~YfW@MD(zfe}M9Dq` z9j8CIMqIydfPPut{gMxENdvyO)v#=b{)W+>Vn5F52(%-omdi80PWt!CA^Cke#VSsf z+Zr&QSBZ&<$;or&vYWJnpS!xcuvji3*&jB2MJI>6qThi|_%(%c>Gkd>&nbqe`d__y z^IgDIXf9iV(?K4Ka|ez`_qnP7l=PeUrz=cZm}bkM=(`Ih|HD8JGX)tqk*4Wv1a26R_?djO8bRh4QLnoYsjQKK1P5dpF| zH%=GXk2YKXysqx<&tyL7?C7$vq$Y!%9nZA!^!E04jA>f%+!bDS-gj*(52FATA(fId z@f}D^(i*a}vtQv|xSJ&?(+xd(ZQ`fxb*Evw1ZfDjPTS~MpPZPmf(%B_wD}kK7vSyO z<#mka_m4no0!Gdjn8%Qb9J+udV$Kw!N_FfgZgVz|WAQKK5MPnP#V(LxuiP1-ZFmOr zXI|XMXz0W5C+lzA=q=_vsDDOF`0utPr+h61H8*1#=cDGIVFkSJOS1~BPf4-hpk#%C zIbv!X+%{its?3uQ_XYe2vo|l0UOw$1Uj>b+zi#5#!9iK??)DG)@${7jqhvIJo@%SV zW=uw~Yrl1yeg9BmiD82hW)a;h8mY97XXWfb6%&mlxJ*=dxfU55|$d_%LdPc*^7va zN7Tsf{KznNkbVA%%tLQbN$;qr$1i|Qv!rx~D*zX_FYhdd^8*+(wI#c9idIqZ=1HSC z)r}U~SWBP}qp;fkJNY*vK4BC5AZz*&Z0l5$`AhKO{=URrNZwWZlK`zQew1|D(~_W+ z{`gh^ph=yEO#a3<{-xjeC9(g|zXlEs>2Lwkj}%v#pA{A6 zr(vpg&sxFqfS?cx36CgL(LPf;@~#EIVWk?XCj_f?ga;MhW=E)Dj=6$#guhfNmRC!? zOdi(VdEBW|Smef|WpiD(TA#58s_mSav7i9`gVrm#S;=$6864_mo4kSOrc0@VE{NqH z%$aztqUA)uE=6=!J}1|!q@ zmXX?9cpME(OsqlYmXn~kwfkHblwkkar;T-+ESBW;e$Et^T>R@t0Rp)^)bASwI9_j$ zERO(nG>F1c_a3G^aG5`vjd`s-9svw-w*Y~9wI%&m4~-MCt&E6^TO>2Cyd^1z$?yL* zjkTM2zFqP*C)gbf;O!7yD=`Jv`Q^r~=9ZRhxnKOAxzv7km&L{%Lqz|5n)x3>o&xu8 zk@oO4NkDcxb-Vr}TM-!h|4hREdEgMoe@nuSh5@L<1OW5^N;M$>AXXkY7@o2*|oE2ZZ(jyp$Y2XJ^g1kdPKZGP>5tnS>teYrcQ;A#J-lZgq2k3f~*iQ>}=f=XqdRdWeh}|jA`Gj-d&tK72ledg^Tq=LV@*BIo8rM;v z-x2^t4PN|(b+U}D>9W}o3ZJ39f|FUJaOdy+(|tE$@EiR=O*wow7)nkP?@u{fkwk(X-E zO%?La0}r&a1+(Cj7xa+Ok32iM9m+-EAE|SFAS?6eMQ)4A{;hA>oYX16oUjpSxBr<( zOVyDe_~Z4TN@@SX`kcb>ZTbE@H^7&DmdE~QKY~B(2%z771PB57--c!U{br{w1mDH` z6C$2p82qc8Dvmk*ul#m&`j=1SLTzJNSuOD(pQ0JJozoBWf?Sm0d|Zy5O|_NRL0e| zU=G#H05u5GT0Si@fB>J#>|uh*E-^@!gyFZ@bHO-Sym@-NyZhf`^O)(0PVJq;aR15n z0XeaLHRw-<|GVEM(QB~jSI7Dhf0RAO9BkRYyv$Cm%=&gw%k=nE(12XiMqmiZ$Oj~_ z{W#qUTm4G@eqYx|>Vr>Vk-SNH=T6-{RF>oFZwU$M&C3Z>fW(AS7;|N`qvwOo;yt}u zjaB)QL*}?sm?aanx~kXdD9pg7Ff2Wzv7tdl;`-f401{28n(7Cp@xqyoy){zt+^OIa zy8OcRThOgr;0~y{0!(hC}|^u*m}&x?H_EUe}5C1V>2fSaDJgVAllkV&B!n(Z zLk^I^?un&jSOTsOf;O=?%vLzO_?D`$yO+08$yP*^#xSMrQWMD$AT;tAqS*WTB9U-u z@BYf<#rgI$Um_qK{N39V040k8RJx@&a@f67_jFUKHj^cn*~g!PVssB$cJ7qv1TccV z9NLq~0L<#z+Ti(|$7R#-1_2K*8=Iio9P%3GS4l~&KQAvUa=BXJc4D#@j<3YrN}^?U zz^nL$-oFbgn5E$VcsBR?(>xCpTS3)V#2WD5>^`d8!BMRt+0pSf_fUn07oFl8Y%O0i zt*0a>XI}_NENYt3%VWX$`OUX7AhP)0tqQ*T3ZYjQwBqx}aTeVE`}cQP7-W%vqKO(Z2fqKr7%RUsq#Wa(8$jhYnuLSlR*j(%L=RN%H>UQe+S@PP0q0VoS>1$@{ z)G*{x*HZ%lH2y+?iI;e~#o1Vw{kTab!#yI0Q`mHclAoV$*pPvFl?#Qpl1JT*s87dt zEBI(${j(eYNx~KNkPD#j@9GNIMO-6uXZCr&W#I4p#SqWi^y;ni6L|(dbW-Yh8ZH^j zBF^B{sH>NVnmCqIQ>g1fyvw&{GmhV$L9rB!uSeh#m>*3U1Z^I#e^$vaI!(tNF99#Y zK0uM`)uG=xTZP9Hx5RL}!4C>7KD)exb#l#S15Aa$Ng`$*US42S?AAndk}sh?J2s1# zKOaKD@u+gX^F%v*c@SsJJ#UGu%9>5RSd2G%Q7@NFNGHPH9BTLlZ27xL1WI3!J#8PT zO8{%*;`ek43R7go#iP%Da3xkVi!oN~(CltENv9W`8lPI7QriDS1Rdo8EUCH7he|QP zrLNA1;7YTg$)F!2Ij!`o0*+E#`#Z>JN+W`h?#s`A8LpU}K#@}iweD25oKMG0zT}Ns-&7G57;FB$O_wHBSmg`5F5)*Z$ zrF~7v0ByY%j79_7LQn+s{5|@g(G`Nfjz z8l)s8F=DO`CGi0#pRT=JK|Z%-mN>y(HNxz-Eq0hwH>*q%F|H`LZ#D!V0r)pRwJo(s z7cmYF4&ZX-c0ERHH8$3g>v5hQJH-*`@8>`d07P12^+J#H0*C6GQh*q)Fa;t?7?@Em z-L<6zogD7SupOFhz^$^bl{q1y2FGOH$zFdm-U6qGgG2XmB*PO(=60Rax1V8SKpnFG zEn;Utjxj|8d-G76sbsk}v|;(M14mj-8^XXS?liRRn(0O7owSBgZ!?P%ST{pz+Pw>s zW*;t=B?mWE+9;V*#C}pkHxDqq<{Kdt9%Sw--#;RFlHUJ;?Sy5Ph%}h11kwDf3+)-Tf zI-S*W@%)_t4PS%)GJ>ELV;pgq*tE>7_t|s7oD_dW_Kem;_x$w$=nebzHWH+t#jt1MBkizsVQ>U)a5{ zO+Bm&OR24o&l}U0Z!vY-8HJ2I+WSOaz6IUy#NEYl8rVKHu?3!pZ3a&IBa@E4ZGU)2 zKSTb_8D6`n1V(=ZDFDx~P&I{gdc}fPN_Q)9lw$c=@ADl&Lc~s?>xZ>)jdA6O3#G^c z}+ zlqy)$>^F>|_So!Ufc0FRl=rJB_7S7v4b{R`MzNDy#BN(`pe>iKlE_^0Ful_&(?~PP z8&l#mN=!e#mB$=CvPeWw*~UazDthPWe!Qd6p|;e?)7VVkE#>!|o)rW{pyPfE zFxpqe^8zN_FreOv{;1*H`Sf}>-n(u* z9lE`caT#SEg-?B>-MCjKjzPz9_5Bu`kBRz;+{@RaM#%I6G9&oR*Cl*9Y}MR=gVucz zvs@!qfVD+XoaKB8PVmS3E>~}q^!6O++iDW%&U<){kB@s+@wqpI zB`K4ClF$R8U|Csyl)T<%Dk?3RQd%gUtI;OQUWi z*JrPbwtPU`g%l)VYZ&S-Xx}3-XQu!LoeGimuCA``?z*^ggJubt)2*z?T;Yx^e)Fw` z>9I`_!=4k=<7j+F0x;$7jEaiJr-g#|wTB0XgK|f#8$S%c_H}1ktgxBS#FaXO)|5H% zHd7;Jk=RNdw&?||-kE%0nbbo_ly=`ct5*Hdu90}n_RbOK^vjB0)0hy?)4(`(KYKcI^LCG)#=T7^}htVg#2_IaVf`RSBCUPH8) zPpuf*DYnTY6XlfJWAbG{MsDPzMDt6T2EA=&(#Z?^U}z$hsq)^nF#JQYHo>N4#U6UG2Ay}0wB3kdJz3Yfob;<0{6-+OlNG|P1Hgj3rTjB~rEbO0M; z9fg8f+ECWl17k+mty!NY8(M`U`sw;bl+siDtI+wpVvZF-y*OG#-*!(=w(S7fH2IGk zOixU9$KBE9=OqM#bA5;?kDgYWDP9boifZ#txyuG|s6jZ08nZu?cbJ`^X}-_64YU zU~KT#o0~R5)@h$!RBe~otNW*8BuwYO7TlfM-rg?#W&&=+(iqge3JL&v^Z~qHzu}w5 zXhnkZF%eD{_dESQZ(9Fj2IcN$k}jP}{Szz~tgb>F(H@rUbTZ#uB{Gxk0r_9Htj&WK z_dJFto@%iTJh?$v8ERp%vb(cm6#~(1_=LPq;P!rYrgOvc;4(I2!diFS@r7AQ26OV7 zy1JL+HQ4lKlCfX91Deh_gd-j&&x+Uv=3|3CvL7^h= z?bNb4InmNK=XoxR z@zfo)mjkR!>_}^pGgbBO6x}D*v@Iz+XDLYShDIFI68Qz8hfJ zu37Az^iE9^jznSRlgxY#cR8vhmR0Xse7{g4M!tmlQdx9Pts?W)*%vl71i%QVF}yIY zh2Z@{**lSO$li;kPNaK}CRuThfZa_N#= zJ&}xJQJ4Ku`K5a_FJxu3-K&#Q>P;348}ny^7mYgd zNGL|g>N^A41uXQV89IOC?Ncmks$uwOL@u!j(+Cp+)eJ z`VA2{x!MiBSe5z;fx&W)?yP%P7Nt+^i#SJxGhbZqw(5I?M{~|vQ;7lSUD2G44U#k1u ze&mj(WzW1tvx}e5W57QOTMf`BD->Kznu9(^`>$^3SNAk#?s6#Hc$gftTFL6QzKUJY<+u;NooO*0+58aW^z>k2c#A zJ|Sf-IvRu&QFFES*}L%MCR2l|*e&n1j+$gLV zWiTE@$Q-I^Vc<2O5o?r~tLh)#gX6Wes`*-<=YD_ou2A~E^5z+9cpL>{#ZTD8+px!U z^Fnn}&mm@P&^<1uk^|lf-Pdb293aooDR<_!q>xLBH(hqgzIDz>82i*dP0qo=L6*@h z4%4D#q^0^rQ=>FjF4I0|EG{Vba@gGd9tP0BYL0~9_S;fbU1do)W^$oyVj^z>b6(n2z0bQq&mHH zNQz((fPbHkLoO9FR(F>)YNyO6EJ*Avp&b0DM6`o)p-I4Gm?Z|eKVm2O~n04{X;pf{U7(dAPgbgkIndH~R7zr3@)6MI?_W~x zomg0S7;j3}yRy~gP4wgNvn*ZE<*y;JGoX7>?&&YjJ4BMW@5#Ag(PjhZ8q;dowU&!u zXwI2Pd3u|oAs@MCG{uLL)p#tdWOFrI4xYdt)w+4(+$Xox4xT1y+nm7eeCNU^8}?y^ zVpt@H<_@H6X-K%L94U`Fb8GN=eq5F%9X)2?uA|@wg6%|?{JOr+89g_p8V(;+37Ehc z*R|2Y8qqHA=nUIYGo7;#3gK{JkV~!bO|FCjxq7{Q8}OWW zoz8SYG%nBsn8q_TH8qaBQ~@US5k9eKx|uwC zJ_{xXUM%*CsF|f`KW>3XR7W6J_slHq-A?Ip&ob(N0_hOVDP7?r?IXtdYYdrp)180d zO^|)@nMr4&!R3YCZO&5&CCgZd-ePNfLo{w3wRNI@*3`mkjhmB|p7JBv|D?g?0KOuAjT&ymY3R*2hbuXZK< za)-B~g1b7V(Jv@wezw-m&vtky9dGCqeAvIJ4}MozDIo$BBskh`|iLW_Cc)To^q&?-7dibWuM~%dS>5OIiq&^paGT)w8mHEv(W1;)vHB*ct?#g;L{_yu) z{E=U?;-?{xST)lX(Fm2|*LcJm?HeqcF>g(l-Uani>iLUY`ja z6ejx|K^^-BUI+I=tLHXHjZ+Z$#+D0^4vRC zo-gEtPzkq>IrfMa9Iy#{G7gmV}I}+f7>h7g=au3;#ng!(jsVTmK3|qLAb!z zMV9hzVs_=yl9m5991g6pi%>`7>nI;UUw`ScFNuDW5+b z_G#FR2#;uzW>@3ERg8y~&pkpgbc69swXuY(R5gb@>pH?k-@IRSCI3osyf~P1xum1{ zt=rLB{-Dnjx5jN8pX(QA^Jeoz2GbsEWC!Zs`r<{S*gd_t&2v6iIRV}1g`Ut`DMjZU_{6%C@#IM-b$vG;85L0@y=d^n-5Y)|- z$xlBcBPCt0{&>}|z0gyP-!LP!>6#T-$7+hrjjSq5H+A_5BzX^;oKEMwzv8|-kyVyC15VM42#nP;_#mTCc za29U7`PA`+mnpUBdJ|p4dBsoK6D9g72HbMegl0avetpHy&nZ5m5iN`}B2}yiVc7&P zYOwrL7lo8)3ir4J-A6qWaN3TI1@z#cmEB&PZMY`wb9h5aH{qf0^ALDpwd#0T2GUZP zJ8#RcOjK+b9Kxsj8|rl@T!{%!f)CJN z=TsN%!utFBI|h#*(4^28Wq4Y3_B3ENoW_aoO4wkC43gbDsm(&eTEV&%GSritrqsX&3tl5to?!|dgAbHn{5cB_q=52bi=f-4g<16Les!MX`SXj*V%N5fL+Ks=e_Wvu)0rdvth_>s=W% ze$p2=mzvAdRBJdJ1Jw_+4105@YSHb19Ud^GT!zQ9u3KN|C=$cA>b+RO`asnc-R4GdIVM_^8#a(RL&& z@r~eXC!@a$S0s}C0zbwE>a#b-Vj2RAJ@heaXV(+vr0bb|k)j;w0Yhti>Lr8g!7KT@ zx_1(HJX#PzKsq&TaVNE*fymCs1Y9 z;K^u?P@UUESC?GiO0?D8huo|b>XH)MzgFFqnprbEG)(KiJyTA zTusN5VD5lGRA})y-gMJuH>(CUH=vuC(_zrKmepesNTa5qiZ^j(R+zf?0Lj}I7O^Z8 zv$0?`Yhu5Y%Z%jv@jYFI;?c8a)_4k*kd4Rn+BKA^&kasEy?mZZeIDZFXG$8yGlR_Sj;$>>o}7&g zqI6$_6rYTH9b)mZ-aJxs`hG2V1@Ic;{Ya+t*+Ido3$ZCBuL*W8c$Ipre-m4UM-%_F zk|QI!Q*?-y67+kby7`u#rHPB^bFIjy!2NJ9w@+4ad56f9`|eQL6wIMrb&1qFf7fi3 z@ln8nm|7@z?lOnj8i;W+4|2%MMu8nqCC+iH!S#Q*e~|F%)FC%7In9z?eJZ$ z`QRrOc#g{Vd3We?r2K;ZnH15K%`I8R*!B_(`^DN71jUbvNYCZ#h^zBoXjpe(@wbw9 zE|bAOJFh-tg-;UZ{q!X^l)A>jnKQ!{=T+*6W>eo17go4&nyJrfrxQ`vhc|TYDAoJh zVqF^ZxAQXMwLMK#QoruE99;81d}M5#HsecICC|uW0)xH|d&%OzlKq@!<6(N9ibt(0 zBfxqWp2^U=MpOnrYLa??Bc1v>lWiPreHXASCpm`>qnmPS2fy8=&b?gj43z~VsaJy4 zD$j~*WDQt`nGt1ilcCa|zGIHKCNtFfQy#73La9@yXc7@A*}NCD9jFscw=djtL%}ZX zAVqNc-n}zD8*FJI*ohMjFOC5frmAtxL_y%*Nb0vdGNmWdj9WQtG z(M4{GQi!X3$ScKvqoTlO$&7j%Wj2COhjRFiPXpnn+KbX~`CM#$Yac$M#l884yA6fW zOg%)7J<4^B54)%p(T;B;%*2YqG8*{$rRtP>z$mv@Bb|sd-oIXOu1xAc2N2d?8`MjTlc(EO9CL>FrX2U}g@ zb|InSxJ*1wWKI{=)js<+X1wdg{;YOv-P9is73^>ujF0zSTr?*5)Dt*%>aJe?=-J3d zIIw*`kLi1)7w3kOI97Yco@F6!JM~8PUcf8n+y~f@HCBaqj$vgq=1Gs=EgU*W!=#|R z$0h?J>I@c0#)LQ`PAJwKlQv-4yb^R&u(V38 zeLRdZVHRg6nfvC-?N}Q_HzRfE$h3ctX5?l)-^$FMUTehqdTqGr6nC=u1e-c$^9;2$ z6Pwt+tkXqF7c9>1H-56~^ENlDq8BCWBa5!)Nup8<@SX6wSW)DK_=?a}rDyIv6m`|! z(f!&(ehD>l7;}7k-Vo~~pEK37$i3M-c5Gd)b)Bl|U9|_h^!ts3+f)b#);V0vQg%ld z#ab1N9`Bkh#+yrm+MGfolKLpOJxttPeLp4>cX5>Mj9ilWJ-&3yYj4d|imAg|PuM1h z4|4CPnYc?(w7S|_LzbwCLi|uD%?B>|Tt8XgWwGpf9$(yXy;HoLr1{n8t9i02?+~R% zAgljZA?iW+uy3)l8}F7NM^?0PK?Xj1lLR)E#H<-TLe6Zh zYo)Xwt|F^DJ@2PKsIiD=PQ}}X;Rt#?&}|*2m{w;AY`mqaNisL`+QI=o?vP_i$BKHe z_E4s<;c6wsaj)aXS#61h2f4gFtVr5eOq%|lBYbb0DloRw)Krx>^gy=5OI?+4R#617W73vmXx__4xEp5`vW?W&scgTS_|58t?&$Kt4G&Z&=PQ*j$Qf9XEFq_h7? z#)XPS_qDll&+V7z8})hGxuNWsMCr>>*5sU#0yZ$4CjzsgA-d9-i!1kPMbS$KUWra= z0u|mI`r>5TbGYI2>4i)k7y|DiZ-U=#mkvT`LG>W;*Wop+AP0)n>?^-+gPnlE?zVJa zPTi{L+jYDU$DiCOIp6sQr0Zt5+apDxV^P$D-7L81N&K2$+EOjgfy(t=C2LEr#q(j) z9X9JevM*bgtnm~tA);Du(L`QKV6rb1h)fp0n2?!cbVK2cfgi3l$F}hv)AJHY-QP`& zPp?r=Bg>pyBT@#grk|i%R?euC61Q^6NEm!A)6nBNS$r;?xjh_1lI?`d03L~lyN9_~ zZ!^U{ny~J>*(4B~GMLwn3=2{gZsNKX?^=y53UgmBp31f4wr#|r?HE7Pfc{tN*o(v$ zd^lhNdd`T8I!qp^0+G;g^wcCm#X`8z=NXD9`Hma+V&!hM zP-w>oB}ufk2MV74W7{ig!elnGa&;FDa|?7W-+g=~r}A7>gSrgGo_F^k?Zd~PfkmeE z>nNHpPTxl>1=i^5gU3%}yet+ouYPe;h9<-vG$B`Jielg>o-e=)x6p_qL3|W!y;3Hb zrX`=YSrIAm;2yD~1HaZEuUpcFPwwO&s>)7ZXU~&;(Q|10ltX6`NnNW?mvT7;>G57C z_0balko|1}ZLH_39BKyd5n#<1xeM;QB5q4tFg-aeWX6zVJR9zCo%AF#2)jJRT{mEa zwSx9k*X_0BvBjSdS_E%6+3h**kmjLS!!TDn{tMjHwKv~)c$-|c^ObY-BZv%T*92vC zlTX8Y)~;ZfUP%EDnSZ+9r)onPw(RzvbLEEtbyHqton-~+@DoZzNLd5H=IkvdN)4M= zqq=(CX7w8F6((iYYYgLzk>rbAky;e_c-!x1?H@fl?;9@dM6b}5LHB9vEV3tU26AN2 zJEQk#w}%9VAHDD92b$_E0 z`JiY&G=e^1QRYHm$AM<8j+<6~J*K>!oKyT)D6if)lHOBIW??$Wn&*p)hjo6IyTqH7 zd=&i-E=o)V78-51Shw5I&3s<$J<_KeSFZ<;I|`K>Z5JLQIo@+Ua{+83u6)7NpZd1o zW4$b%>~ag`%6C&P5Fd&_hY+iuFhDOBYZiGTsjOk@C)0N%9-?yCCBCM!uL*H&<`Q;n zOEcOlM8<{q^O)p4HdY$B&!5yfvaDA-Rrj!c60;|9&IcKT5yOG{`r<`morsYu%+s?7k0uR+WY0Sp>G1bS(&6)ZTu{xUZp!}+GSh+MT zl%4DTVHepN!rYZL7jCW}O23k8&qyp3AnS9lmDjm)+7)kvtUhN|hdJdI;AQagx3%ZT zGpUVfK+##xhFg3a-TY#nO{II@F7D|aHEl)prl6l~>B}!-HZ$KXmyrrcS^M1=Pucah zZ8ZCV3PR!YK&DGRtYR+T!Nmq$%B~f+wy3FHczAeWaj`(Qs3S3_ghRADY}1vT$ux#; zN_M6eaJ^_sJgymLi8G~?)7jKbg#fF|4N{FmX7@wc4KzBoN*>Os27>-B9;Z$;Xgfbo zdlcv8Uq!!Lu;DQ-vqoiUjVDtzST^ahVvW&Qk%izT^y)zdqGm&+&z$)vBNus0!UU37 z;~&8K>Z1p9)Z~&r{!CoKACpWv!LT!na<>`O{G>o$e7#3R&!QPDv^&96||i6PrVffLeV>k zi%TD2WvYc>F5vGY%hrFjjybe((0;uCo|*Wko_1O}pgSC~ue?^ayD6F#EL)mv?NM$RLe*lweJT02&(WS`gHG*3MzpvCnD zn5I*152Nd&;S9eTj6S*_ZOBPRU8a%V^Q9)FV<}rS03}_G-^KV~PqqsmbOgD3V-D|! zBYh0PgfC=|mJ6j)lXnyBRrAIOl|HsQ_D{hSQVPC7*g=+`!l4I)chc}$3<9(+H&@cR0*Lbajs zSgH_raZF3uW<9-dO;?P9bAvTElyW+cnhQqLkqNrfIW#dibGB0*;q5ktO)Q-;=zHxp zg@?J8hC{C~k#~{=pd!H+8~D8Ul+hv`y&k5X18;5|>m8ix4I6`-aR4BbsY-lvO}7Ej z9|1=jz2HqwJC14c`$D+TAdLv#FBFu_I2N%h!R@;}^W3CJ=raYG820u&ZV&dQT&5d5 z?dIfFlkpexxNZ1F1K-771vq1(d-&x1kEa=@OCF3kx5OC&(f=gcHN@kK)TKu1T&58f-QSlT#WX`+0JRc+@1eJ+MCBi z-M(+*mWc|f>|~S{LS!jnY)MkdQrWjGx1H<^W{OH>nItB%FQM#f)=5Ih5@TO8S;x{~ zEW_}-M!M_s{XO63`Tl;-Ki&81WqZ&2x~}s&&*M1G8y)b$C(-PJ)iupL4yV76$!=1-q!+65qf$&0SQp}A)MT;llMe{!#x zb& zZ8plKgpr?R`xyWoD&-O?{+6BvE>0u0z=JNUq_v?rDULo~1vbTmw>|v8wLF2BRHB#D zMtDDi_MiOxj{_=8oG7;jX!`s<2UZ`uWL^8pr!5ns zd)}0oCp|-%)}?0hMi=o)(ph$U@QjJSA2yfl@>tI@{88Mh zPvQTYRRebdK*(kL|2q;5PWB$DX!^P^#dU_eLFGs1T+J)yw&Nl6hNu0uyPsH8eRhK; zrS~s$PxIH@);thYkO80r6Joo-zN1KxCgq=)5i*idcsWyfxBaqaprdor`nvI%0eQW5 z=030Mmk$+2;2Kf4HC^|y;uBd4;5t0LsHeU!v4MmEeA*LOpCE@T9^2v<3|At*T5}$x zEP$@L_eQ$S*o>UlWi4m3qb)2CK~C4BD(7YBLWKV?n1NEmHMMzD6oi?O9ho~eoeS+0 z7oqVZ;zyro^j}2X+U)e)^71h0%F4c1Rr-GU$v95vlH?VW&p!JsFUua(jBwfUAb+we zjXJJ;%FP#?Uy)3ii|Y;a*uHF*Ci+1s@`DI9+LLZD;iz=hAkB7Td!I4-RPm*y^K z#`xyVrX{wp`;~_8Ox~Kd_yJe*TNQXFMld zGSspoO#p53o7AS8{{H>@h%p18i#&CD5;>DF=N0{z+)!mVvLmT`q!$tN)eavSJ4~>3 z$7g)lCnBLpL6jLo(iP^ECl;+spEFv|$bL^*k~^|NBe}A~@8{jI5YNlW%?-*J9;Ig^ z&W_r$EivrHeS%>ax&Fe)KtL%xd-hC!ta+4$p*m`Cwcqs2+@%D3)0_%;w?y zwa9ukmG=<-Zb!`SU!mluBQmA5^xBm;n$L!p11!{(V#VgsPciFay#flJR@Sm_%W{r2 zGft+-|giWyhP#)=|Dw}C8 zJ(a2{-&A(w`-I!J49;b56MKtYT4xTu(FK(R^BDhUtBUCuwC)hdXjk)0Yx2&7_6E$A zLPJDqmdei}0-&BlJh$7&mHm%Ct5`r-`d6K9TcVQRH&!k-n|7vVNnRx*;V50>)S(oT z9uv!iwm7F!^^pC1DGzb@olSBX`-&`8lN-ArItVk?vV=5tkgX>TSsvhT znV_Cuabse+(o==hLgsb!Tu8AmPb_Zf`nDMckmpA}H3@It)Uik<2#bfP4b05UtQ&cx z^n5l{7t#Wfv|8tGBaZn#?P{m@?z%7*5P{`Y!5!vk^I##f`Xkjex0)mrPV{Y7tA6Fx z=rZAX&NTVy_>l%x*qtnIZ_JU1+%bKq|B@$PTjb%5z}zh)a>o!~eO_GrgbBw5tV*c~ z>yr=)mHFaatGCbakCA&~pnD9(EB9ns@t*>R4}tFI_g}HEEU-&~W`(LnG!x$SxydNA z=Z(2l9}$#ox2#kjCV28W5Oki#K7(hgPiIRfm30|FMbE8CPt-<<&ZZP@O?a_tN!9rH z-%W5re>OyF=m7oG(@`5j%M~cigwK;aAoGgFr3`jdNg&qTai^X zFxM{b@rMd?sQ=py_JYz#*3WJ*bLcBY-M1e82i;8W#(T6K#9Miz8@GX}9Rmo)b{S@) z6^cupQPh%3mML9u&Qm6u&wOY?aZj%P(8b>7KRb0+F|w>nUD$yrm;LpJG_V8imG&q4 z0(&eGgtN0K{OW<1uc}*Uo>vXSJNAX5U3AQ@Ho&eKm7WNfmxp+Ua<~aeZ{+SLKKU}o z8&;!n>KzwdyDoWK!RYh?QbfsWRk3vcK=qah$J50t`7+LEfHGXc-DQXtfScBS`LdsX z;@qv|bDW7`?O_tP^?dVhyLM6CJ%Uf1xH6x7tNoKc{MA|EK)s_-t>VvM!M+>R%^IxI?kX*#-sq(E)HonF?>@KTka@~p90rFy1;0m}c{z>SCz}aW zCi@8fqq%QXY9iam%QJ_NrUk0a8_Mj=#h569@gvh$lMID0je#Q-;okAGg|Gru`z1l> zeeFmDG$Qw9>TF8e`Q&BySTQB533p}dDz8(MdXeDxb*(8-(h$pWO1Xb0$c70NNqj6x zw)8wbn%2mtr}LUpmoEz6mQ_8Kynl9Ce^izH-ks;75|3pl+H#5ZD99}fZpn7$4OdC~ zFD+%5n)05fm730kKJYB;CAr~|7oD7)0q5aGczOla)7d3r$ANL@<)P`bn5fK{^u6XD zKj<`NkoUF7NhTu9P8nOY4z9i2&bAhYG+~J@8R0^oe%TfR<3~jI6u5WWuYkd$ia1H` zyUJ?5N-FVDw6jQ@Wo3~$kmzMvy4%&|XxI?oC!>K$waNLc(8e?RJA(^RX z1n37Rzp+ck7x8!9^$Ym6qa3!~A9DdHAy{{n5W;{Jtk}_~2L-1^ybr|omtR08(23sK zytgwOH7d>^c#K(sTR};N`QfM0SJ5~i5k}4!Q*V}h7#CTMUw!OY>xHoJbO zz|w!?4WiyXx}En+%nW~5InfOUrM{E@1l&k!s8{AfSfh=NeQP_$N7}Ee+iT+uW_Ie0#g5|r?r}orLQqjpUV`!S&F$950$8kMRqy=smZj8fDN z%N%*?VMwcLjp(raeJ^E$PYT=*NG5>mtXvR;3LxXY5{0st;Gc^Eyn8R0B=67Fs>-7x z9KNcax$Jf_sdva_ED{M4gDNb6^|Q}xihq0xG*3;IgV1dj+G{7%RdW3;i|8z=qNz*4 z{s2=jfd8)b#_POw*S%(AgvQ}i`SwM(oj<`Fl{c0t$#^3w2X?XXP~N7SP0H6!%hdBA zLNDJLKdnOO=bw44%LXnRzkscELZ$=Wwj+~vI3Rxij@q5#D=mDRnx{f~#~MLmhb>UM zDnOE;1St&X2*z3-0ceuEO!E+{%(LZjGRd^Mce41 z9hzt_B5gL5-!{Iyfqn|0D!^zyy!Y-VRlEhvM_B`kH!t%*QN>S&i8pv$US#Y@>T-DF zS%`;ADXGO5eUh!cT?-0WLRv77_2ud=*rpoBYZ(gf9Sft#Tkpb`U$$2JK+m!_UnVsV~d3it!=m5FE z&&)DzEdsiGqj(NXryo;F$g$YU529zbXX(p@X&(1OW#niwqXa$Tr02&`ts!`IsB&_Hnj_id(x4qeM5j*mc#3<2*FArj zm2See+3K~&xYInNu4S`K9s}XL-EW>E0}d2T7r-2%S~THVgH+WSnTNC!i2#gBtL6{L zX)!%;_3G98FKdrn2dR$0nKK{u7loqK{l<2XUIJzO z;I0p*w*ABPO1RPiBfA6%CE63$r)VJ&Pk`)lnxt zMTd8n98}VnCAB2-X{ogcDIkw7o4Ye!%_&qMY^1p{Xc^Y0GTsaq(t*zHtItOKjG33< zpNJ2WX6~~P$$&>JDPgxQWI+np!QbiK7Y;Wy54mQhudjvaKAV09)m*2lLGl%mQEvL? zQc!XIR}@7$iz@pIlM$~c(BX~*gl0ACh1;uFX^)v1M~HrgSAtmus{ben z&0Zj?R2M26H_b;S67@-Rb{lOmm+d7`AJV4jtp+do7QW?qwbS0T?2kcD zGN60qCHujoxU%#-CJiY{u-5xEyH5lYEiKcP|Zn0jB@jq7aa=oQ$G-n(40lwY|M%`9yvX z;S8=3TpTTgZ}PPF6EPJPLVQ>I>mD)2NTc5?O|5_Sxp^)5-1@n7^yLm(N!plf656|i z)*d;X-f1*brf9{AsU*_HmRWKTuNKxkg4rqGg?94%4&ja#59o$VEE8uxtc=OF;R8Ps z9xtnS#m#mIPt8nMTrI>!=m}1LLG=T>LK{NT5`tD%OnRy<-tx7ei(W?3oHQrI=8lLE zN}w6$@f<&XDAOkWvi#WdvnZE?XtQs$K-hW?z4(pR8VML*tnjAF2CNBxN0_{(Y@KpZ zXj!pr&5t&3a4$@LO5jOiK6dFm4EEI_%GSq;rKibxhHq!(tALrm_4{E@_G@wCHJl1Sq}oXF>jsTdm_Z31} zES?E(un0*jLPCF>ZXQ?0a(&H_LQQp@6L?jZ+%gbZ1fo`yVwrcwM^_!~<*uQ%K{%rxcW712`9c`({NvrRh zU-EE;EzE2rJ5+n>ZX>##kUWW#46)O$EK!7F$%IR;DH5oLR1F=5iSKra=7#X+!Y^{a z05NUfZTZ!**zJ!gfoC?OCK+Zu9np4?BoCN}GY9s^S(J3Bk5%qg>phKxk?A4cc{lbv zldBtVhFn6<$Vvv~4j!3`c{Q#>`gX(HSGK!fQ>hZp5+$oURJr}}3{nMgOiivy1)j9* zgNiyZQ16aOc)wZw@Gl7Dq!La&Ynz)LoT)og`#VmGne^X-o_|q67kwPK8UfQt17qV? z30z6k64OWpeuXSQ<6A%dXM4*Qn1R}&QeUwrC$hE&m^t2m=eRbkPdS?vUBIF1e)?6U zN*3YXZG;HSS-2Ti4aD4dH*J3rB;qoo*7dEwKN5n1Pz za0(doAX|^Ry9wPi)CH|CP?_%F-+0OAlol+Q%~4u3DgV~0;oANVzvr`ui3WBLu96ia zy+8>h7|A;eEUsYlz>w;0gZmcN3pe2W#*Fgw?hxY_lMJ%0mSF4lJVOUyXa!_{Z1fUQ zdWU#rS$70dYn)?VzZRV89~%0h^CFGCwd@9+(rDEt?@BJHV7;}OdmjFJbV?HHi0&At z6-B<8hM)AFoY{%sEx47yA|FmQ+%gZUV7-;FFs9PUA3v;K9z0xLQ==dy_3GTbpkn?l zFV(U=Xm5}!NzPu3a*o=ApqiT#>%eCU@fbeWS3rV+2(C%=S&K>w3}2!Gr;C!Oj7*zt zkU}uGT)iM?#fi(-=D|Oh z0X(8ok!brMT(<6!=MrqXaLfu04mtxEvlqwo{26eRJoXZ}WDy|HV%+Q;|}zX#q4F@xOQ-7TVE5x=6}JFHjd zL%B>TU&{XPlTr)hEc_jCr3jN%NTrsYWu!G+o9i#q2Eew252@tMT1O?F3&ge){Z4QudqDI*@Q96w*9=+jRuS+ck?>z_QKc(HjDN-k<4)eiP(De6bQ&4tRP{!{Y@Nyn_ z(v6ZZ5Ee2O#g&kRv!F8OZ&#X?5Lcs>Qu@){e2}Awipe6u3>e|jf%3bw1;e-U5a{vG z5D)Kh4Zj{Zdywk)aY_fTaFKcMfzrT!Dc&1s%)M)H_3IN-zB~)w*DsOlGxRDgL>bAL zhM2{kjeTwN&p$8kXhErC0SHeMn<2a$^stw{or?Ud-E2Aq+6ju0-2?J#r^o!^#^=Gy zzK1-#_h~hNhW6iH%xXMY@~-9g9?(x8~&i`}h>{fuH}?)PZ(o zf^Z-o)OLY3a9axnw;$Koku#mAMVlErs3L%=(3DPoLBWaY#tDITT}+K9^5@kDBlV<$ z-H7t*A+`UkCpSfc#mB$*kb|=qmEQasOwmt8t}}xN3~onHGVHQAzuxTa;gh?v6C~CK zyjkMT&4J-RuMm9Sk8-fy|7Tb~!94(2T$aB!^Z5=?JaJRHX#mKJ01e4(N5^3_&j4lB zxq0TE9Lk@ZxxDjvO018{DK?4XTMAZpPS0=HCFkF#`h95kV6h{Ao))}1Kx1HJ%kI$@ zQ`&N7BB*0~-`RME6(33wrS*8LwptElY8_iA;EK*&lDl}Z6j@bOm7fo6G39|YCIU!r zR}16D%l}uP(O)`sW08YW=@4)U;BY(fVNab#M8jo1%2F|Vn)gY+f z%5&;z%Ef=9;`MBMPR`ED&HV>Dea4(EyYCdz>gUSe^3PwQkkvbhadF4^_{q!y|s(`Y>UzqxO(<&nY1mZE%39Qq>pgvHi zH!z%MDA1G-j4=6+P@{~&tEi}W9Hv>>N>iu=4<)wfS-CzjF~QoK06a<3r-wzS0D#m) z&pSBSkg*YHldDGS0eZc&BLh-WCG+*9LODR)nDQq&g1t(a_wIRmcOR((%H=nTC#AFq z-wFK_f)2b&+(K_dAX-iR zEEI(TfKZnjCsSe4J?J+M*)_O@MM_oggb!B|uoEz9!<3eK0c3}6rT$WfT}={-V*A!p z1kOSTtf%(l^zKeS_$#daM)pDZTRP8dSF`t2X{P_)fuMMr)r((M!S^8d5}#ce?`}HW z-$pg8?MMBeQK7a6v$P2Sb$|}fyfWoXV&+pYMluzRSjN*$*O?hPbBck}kQR>!z;A!K zp-1zF)MF0aEYwL8RI#j2pJOf~S zMn*<)xdhS1BT0i%Qys}Fp)(f#)(awi7oichZ_`SjsWCQpSyfsD!2{2 zG*Wgi1v;;w26I9e4dgBJy8M+he7z7=FACdw9HGpzVe~}V@awD30WWoHjf0Sx4w~v% zM&qG!Y<(9MS~(a?oiF@L5`4yjJj-*0SDe zZf^Er11<2NmN~mHIGPX}d--UZkc&6?4qMy(H-IZ)B-R4-^iUd|4=YMbdjpd8E6ucs zz_PjL8IHb#<1vpugD#A68Krofv}J0}$19lnE?^u1eILE%n?DG_5`PN zf457iogIa7`vmV+l0Qk|1spW6z7sB-LU?6gY^=6k#wV#+19E4I_a-dfY-4 z&cBbIWSs!SJqB#z;t~>{>^|1repPlO4OJ5QX~1E=cYK_mEyagTE}A}(ktLLimsevM z3_F&U6Rt((S`)I51+Ko7Mn9&0`ih>_eDRKU6p_&a(Jx&KBA>nt7dTjkP>VxFUEX|5TO^-_5yKe`Dix78tK+PRseLYzF9c(JDl!iFu$S^B}Ljx z??7eYfo1+Hb)`T8zZ$l8RryCv|4aVz5Q{!XQJ~-L{qV+o(DigO*xBNo9n`vfia$x_ zJfQl59}dU?ZvOc$EtO{{KrR#I3rb4xVSoB&)q@v}bM+8Zklj}_-+cCxq$G={>^@IN zi?jSTHa6BOuk_sJW=@!B-fe$s!8}YYIqy zdgnRn++)pR)>#%pv#~;6vqeZ;ruxjl=v=}6Xi)bR#hEn&JGKj;6zJ2IOo#H%gb6#r$989%F2Hvk< z%-T-&7Q#N;x2CG08pwAY5)_dNllSTyL0@&V~y0KcgQW5@XXtgnSdApE6aK4nQAH9VO`R8P$ctn%rUo0*%!>pv7r4A*I->S>`iFezRTp~D>0C7;vI7iT>JFR52=vgZ9`-cU z*5;fcG0}zPcXDZ3sr33ZL?Aiy;L$bZT-n&(Y- z?a3HjBdZPVqqE2HibrNm7CFXJL@;pAm24K`EGQ&09il{_wg8Y)KZjKU2~)-8Bjt`b z^RLH+1-`!phplM7F~9~L?)yR3u&Bz!Ivfrw24nFGw+1}=S&&~f^x&yQ^Y$!)0)_%v z=dc2)dOVqSg+58}t3aV;8wI){USd&G8im{JEt>zAh34+y$6w{eUIN2~J^+D;g4(l2 zJ2diOiuM8Q6bMTbhHeSnjm-H9K6KNX{@a&1hyXJq-N_hcua=!HjIrPk;lK`t`5Ag0 z6w(9~n+baZi2bV7C97+wp_q5B$h%{OXz>=654}LW8&dJ|m3(YcRR*w;saEp$tvnvW z(K*rkD%bUXD(}S>7KbDS4D!05$w+IVz#I6G_4JZQbW5sX=k%wJ3nO09!4uj|6P~)T zcY(D^grydVHy%$82!a*xJFbl&Dn(zHt$RT7UrD+l(ui03=#`pFXJ}@Il8v|kYvr)o zkdrrMHG{6ncd;25>_m~Z{8$?=*ucJb&iO#FnsJvRW{$U{YP{OSSj@_V-!Lh{Twx0S za!P(UR$a)}8}Z`3f|t+(#;C#JDF9OL86kmD3Y3A1d;6Rc#Qtr?U&&o---9(N;ZJF! z$qeI2yE2jt%#3uoqc_21Ax*SAgU2g1=#>}PVL|2@F*2!#T+2fZ=fG#6RsiznWp|82 zyHScr=%LEgMk&bvCDx}){&^1+#KmhFL8~il9@gb{PzQn~JhS61M~j*~myKw29dt!M zT&;k$NqNqBzNK~I=g9+IkKD|ag>h-7V!c6EMZj=Um4P&cc%<5sTc5Fhc`X~={Ngf7 zFrrri@Ok>UWz4FlEPq>MO3mLF&rOIO*0CZO?9>X_)GsWcS1rK6#@PYULUF1Iv}lXS z+ajM=&qMNun_&hpZTh;A(^gRPy1~9*Yd=0auu__U zxY?+2CH}s4wxZ2xHHT=NvSaJ1$2}sA4vhs-r%ImYfUd6Q`9Shtd;6aU4PiY-cyB|e z?MMIj$@wYd51HNx==+sRfw3^-BVX3{*^krT{TtJzP2vMKVdRam+8}i%Lg6VlDr_@s zX*H_)^|v)HWxBAIknYHV&I{Yl;6PRm^z`*{z6^Ty?7%H5rjR$j>W`PqV^u`l^FW7Q zF90(Qpj^j_2=Hf1N#_~gXGtF>mLtn$=6J8y2P9`4JOA>grsi$P(^?^{B{Y7B%0j5I z;E7JIO-zR5;#)6Y1VTam+^l@OF)L5mkXHl<>uy=P+WzT{WhOgkdzZm_%;pSlnAt_B z$$Gu8sPmZ?y2`FuTs(r$%b#q#kuLCB?GfTTl`8Q?$(dzg$%7w#e$?s;N?0DyLbO?g zFe-&yL%nGm2Yo4a+EXGNC*B@w@A*3Z&`EZlVtb|b^RzYk)OW9v;)EMa4JHaeqsm{>J7nf>A-muitwyJIrRN8lS}H3Y&Z2cI zQK5D0x(?E~c5ADu>KhekXZtKpnP#!VO8CU^6ou;r!!qCYvy#6LmAl`05yy4`VDV9W zY~9zj=4XEJJDzS0UWePNh7qEmqh4fzo}j*Z@;e~7n|~LaZ;tIwv{Sou_^0*f@&%R)kNA9O)YJ;jIQ|EZj zcGZFeJno?(eMG0F!^LOx_IV;P;UXcPVmR`~_DBY{{LFbco%_Pv^r@*j|5cb7Bm@dhZy zjw)UG_YP^EhdsHHB*6%8Ps*~rJEPEAHul_na)xk)qTeyY_d1X8DEMyN7Rx*I8r&Us zn3M86!zv8h`}*_^zt6xtNV?&vj2=l*WjyhL>h?$Ck%8dek-fUe;c7>AIvU#Q*k3%g}3w&-H) z!&MU#lh&n1#tHIx%B4fO<9PW>CY-ja@xTvQRmf&~I+%W=E@bZCAHx&?5*U6q9TsNZ zO{8i(e^R*S&G(#{!I^4F9^O?QVuv!@+uPlv>ta~gs3tUZlq@Y`Xt9a(4l!BeWGEe=XMk5(C>iSK0r22rLT( zsyOFUGOTZ=zCRxW3LK5`rm-2YPAZGsRY#CX>dWxsEoT zb7vIadr7b=GW$~1*uR|BH`sQcYIC)d@&FykowtBpBHzhu`mm(0)w&6`_e0^r4woyF z2v1bm#nxo(C0cHqF@G(ps``4w-A)M&#c7*2P~5T<6up^hLH(b}7tWw?@uJr(5_`5^ z(-L9*#p9EzE9M^?o3j=w6Fx^h>rLU>s5N$+LxU4w(dP%fr6;$K>Hs4evb%x>aN_?{d#TE9*E9$+VB^ z{q)`+(Y%#3V%ZAL7Tahp!XhIIY3i&|UsOcxtXi=uA3|YpU^Kt2I%23vMP`^SNsOzf z<|gV_6{#uav^|aSA%iTQ84CNz|NDGtfez@_%@hBEJlTr0r`M@ zxF`Qqp}Ri@KyZWgElj?%*sN0}eM3WOXjVMvsQsE6;VsEqyu5uCZB-6i;<&ZvI(BFF zrW+s#y$BQ4Z%3S~OeYLXOwzym*xK462bZoGSw&~mK&d>VZXarMt7#9kkLHinzBAToYzMyyxbwm2y*9GLKUEOKkOd_e6_DT zZmjXa1jq>M`ME}wb#HYN34tRaB|f&2b%4gR*eWGzwdFm}L1oNPqPZLr_*-Evbe<8y zl?(PPmlAI~YfymAFIPT-qESaot|$v9*~+0$zb6a$dBXw(t3vO^k$8iO)x@nO9X0ZA z5>E=d^BrTd@zq77i;6t`?PMI<@xjG;EzPkTL50*LwKJpUn4?Ua$$w#-PM$o-T}CC* z3IG3_`T=3Zk_i%G~?luyyAwZ8x++IKNiFk5kdi1`Nd;^LG-i;x!8g3dc6VNH`(DUP2#cHO4X{xSTuTSKb(wj_*OF#n1 zl&8eW11H|w5DzExK*Ghg&p?t+sXIj#Az+Ju%?D8Ou5TkkU4&LDc70*EQrcx?OK~ew z@q;C4yLyuR@ZaosC)Mo3&rNiXEBmKnMhZY%NoP)4BHNQ@Nn)#1UEJ11Ccww;WtE0f>5LbFHjg=hngqnp z9jfwa8-d%MzO2WFoR1mE9C2mUipW?6FoCeJFd%!;H2cjHz?_sP_gFfCfvl#Bc=Bzn z!KlZCrhncwpH!Rtma0}ToK~uDViKQ_pb$Xv2o(_59KyRHXjGwETsBDMl`C#GU}z>I z5OE#nk*<(X^avXj2|m3-Bzl%7K3oCW;j3eVDKz(cEYhlG_M3;6zUP!JPeI20A#{U+}1Q?!~fIk=}gd#AW(TS3dq8*@JA zok~^*Um7mSJmP1JZz@vTCpYk=?J?&Ss|FTFJ%W-Ewf>Fy@R7`to}M1TgH~T=lPhtm zEJb(xiNxNs$EufySwWb5`zoA8O5>@Kz!F|HeBSTq+Fo|EO(WXNKd#X|f6 zuvLRw`4lf#3PjG$@P&$8OV5{Ny$J5S<;m7WSyw`$-Ok8`uNUW-_aL`4Q?n|sDKQl0 z`Eon>uBHl)}$jb>wP6LE69MELE{K<d!BfMLaUtF+#B8+ufv%JWtOpVf+={oSRe{oWegKS(QwTzM>-r;`yU=PjBpIBi>LPPOuv?_UR| zf`mM__UaXmxs*tAnuHeg2EkNs|wN4e(rkzy!CXJYB@~M zf5Ya0zJtBJy{Bghu+9?^5jn5_7&1R@a2fQW^o-?YKWCg{y*NA+c|Fqxc}Q=rx3jYo z(DydCZ5_I-#pd)K1g$63ZuYk}y?&LxkH3W|@kiZV4dcGZHm(KwbNJ1x&O!#Ns54j$fAd`2L~Si&6Syvm#BY2qSY0hi-}`WrSe zCA#eGaZj5(z^YC7fPVmwjv|P>Zc9`@m-&@>H3!i8W_5I(VY>ZPVRf^4KXtBwC@i2GDnxT}^@{RG$wMF1o&Cu9_Q9y1eDz09&Cz=w4DJ54S zawTyy=e;7iQ`LCf6{)lAbWqa_hKdOYhtr5zQ3Mvgil_d(G>RJKSBK``MVHL4-17fe zby@H_-U)ke*aQ&DRvX?4dfF^>@-VRFn^EJnxtK7)&cPv!lgVEx#qp~p&{reZZlvB8 zDA5}XfO^DW0L<<6GFV?AAnljRY5R1E7U8t`fG9%Ue{*%dwY3$v4DFzIEC@f|J0a^% z?rntFX}wX*8m%Jc{>ChK!kWu)h3C#T8EDAHL(^Pt-+#MQUvGuX6i9Nx0)Rad!TDDL zOz~RSO@N;nI@thPeDKB}tataLz5^t{o(m{&ZS#OT72WbOLD5YEWv#w|7CSrp+l-7x zqo0^QcM<@60a3^kpitu&E7n(zn4gqi$ptuAtW+Mo1u`CdtPI@N)s`8coWpXJR#Y_K z=8xXh;n(KkfhW=^71hp)`W59nn4N7fpeW|CFa^yhTU5N3vpq+8v%6BXsmzJS+e5u#rWgb;tY=$Zogb_z ze0?TU@{Z{j30kSXQogqvXxtR-H6&=SlGsb!_k)u)BS%reg&W-j+8|LevApbTk#pzb zWj&vZ-t%{MbaZ?p(8>XGuhv|94;aoFDb3Lt(7rz8Dy6kckw2uA{|;DLf+@a^SL8VMVd^DqKMl-ghTl#ugBIt+t%#eGfKjv zmEJB64h(8*m5Vi%g@u5Wk49_^Rc3uRl3Enl3ryx-8r;x7QgMW~N_-)63vlvj2?s^+>{BN{e$B~?;0=&GutgL6gR47Oqd zV`5^8Y}&`cO@qZ#bo$VU367w5|Jm{Sr$hzP3ZUJn7`;dPJ+jP*>YU&jCwFX+5_qdY zK}u#d{u`a?H`FrFh-tm(NnPgx$p;H0lqY2=6iMA{i)Wb$oPzp*svf{`aK zn(YW<@_$<1cBw8wsFCmGZNAx6Qv_s;e(>Cx?$z6_+xgDCy}9Fi#O5WKeiwIFS5FW3 zvz@WQ-Asy(Q241xh+WgHfeJkCC!oGHAKZ@l7g7e>jv|=+rM5}Y9ps800nS-LIRfw9 zLO|AkEiooWefE&Pfx%2MEGW&a(wDi~0f-IHwBmnPoV!<2=PjTJr+qN6pQQ?S`DC-w z6WtoWwFR&nCMPF}_+AhdMt!H^frzPW6tS68HbSb;6WdNlR-E^D+b9#QL4CQk2M-0k z6Em%3SdNi=kM!N@PTZD8+a7>S(2z^eng<~~OfxgWia(bbkTZ#*TV%BNL5Ru0fuYLa z8o2lc^$@hu8m$!iCg-VKEu|Vyy~Bl z?mKH{0q7r05CiHVw8A0C85)6G=zk7Do=|^9&mV%QP!rJN%#a(9*&HMp{eT%#xKFYX zlNgJZJ`B;PwnM)-3}L4(EXz0yfl%*fV31JSiAjt{7af7zI$ejXT#6ah2Lbb9V!ZW( zo+9_E%otHE-lgc{+)2JSelFXH?yQuZISOH;rXE1USRlsKkI^wK5Q%;3E_&O9vJMsq z4K?)~x{DR^kh-YsE*r#_nwpHRVTbTQ5^9#*(ZlSJQ`Cqu8V(2-^}&!l>mHkJGUczI z=7i`{bD;e>AxhNsW!0RJOVrfz=v6L=I&}?Ni5tRBvprCz&kbpy0bl0hg^W;Br=z!_ zkYm&U!{&paX=pU#(8VVp;(QZtvf>ZQI+^{sYrs-~OGUG$f?&2CQU>9NEKr{^TPN`- zx{f!A*>wfnRIc1S_UGHr;xRuLb(wbt%Gggq3aP2#=%&+<%UmNEQxd%xrl@X{@3#sm ze$IxBZbzRw0~VsD3~`3?Vb{@90+936%V3$Ynedn{Kk_V8lV$1%#*_}7H=U#BUDF2_QW|sCOQ6V{#Ff4zzx_K3 z4{x`%x1;4drd2z<(-jhp~aYekwf@Tt1ft32bs130af?z6) z@ypVes;51*A~|8jc0#D0bd~}M#i#H{a+s{dGAyW_HLbcu{@P!g|nB0 z@=WNwO+hRS$vihyCAs8 z6jATF_4W17pCJm8SJl+G4kORgzEDo+ZC?E(rE8<~miB^%ii@nBxAB8!AFZs$YSAFL z;Npd4^Gd9CTV~_dz`m6!$I9ak4&GW1Ct&aROZ;HPErhged|E+%K9zielv1c(Q#zV= zN?al3q;^D_$<{VV1ui208C_bp{3N4n1de~hF~UhM>D`{QG36qmT@V{Qy)wr=yw_BJ>k8;@VqEdt z1U=`iKCICP|E*pOX<)IMGzmIz2V+#%F`tN4p&_iuM6~C`_@jO{i~5uV+&OCchgU}~Xq41b7tDNNt7xeG1MX-QJ8YupdoE{BhnN$3e5o(c5={CL(R-SC~c$Nzlh+QBoeE~+3xQU#b_CK@V|9C`r zH$N@keQDH{tpRuY@eiTS!FjRz*NL(=CDAKjLQ-5XFr%6F%zf6IGPwbI-k!PrQ=!GX zOBU?Abp&R4fB5OrXXP4TJ;r-h5Sa3@pLIhx3#1)R&0 zfA#5yiE|-c{Ud%ES^3?pn6jFk5;?l8Ytx#sJ1uPy7E3rZAm&8P%Tz^&|drqMEjxQa>>B57|yXez;ln+ z@jXQsEhD^|A*y+Ti-$+fdjUDr)1#Z=yIS-g)o&-Jg3))v)tx%wrqqJxMj5rWi?fX4 z3l%VU?40`J-ut$;nG&YByq41jtFiBY00E=6fJBsimDNATL#NhDt|eeEPS9g{7Q|lU z2224n^YJJd_M^v_fSZ@`t2Fi%EG1D*deUtgvsR3R9g=<6+K0>8u|$EF zdY01A@OEuFI!NsBgKfP0!ab;h|I?u1LzC!I9_Dw1nl9!MWY$?Pmbq``WHNsnA2 zREA(ki|mSW0pBqjC3@s3#T_uJ4!PYmswlf5Bzkzgju==)>@oWAbWG=Ed7>SAZF(@O zQzGPkG0ddMQ1dIoYDB{#%7UgOOt$xUN7d;M$Q^_nvy{sL9emBknKwN12}B6xH*PN{ z?rcqAw#jl{t4+LZl-*g$Tf_LheIwdv=j)?|DInxu18H?nj?vlza=4D^+)iSX8ec#f z&%pY=!(+p}NfwlTjk!k&fB})y4D#&ckq2_4g(b$caKAhb!-O25vTFK{RZSpg?{#f| z%cz*k0QDSbcc|^!&w79ID_8$jk1^_- zUiD=%{)0jun{&+PD}#9j>4j&Zz^Yz9hCVTFg8%b1J>FXyNR6}5`PbdaTwMB&;37qeFs#NYttKA*d)K&5lx~qjc#dydcd& z6(J&0lqMp*caRcLdat2FAhbZ}gxn{H=R4nj?|)tE$U0{&J@3$G6;mQ(EHsF;)Ram(+K~4#WE?G`BA+57@Jp5* z>*JUB(DM@w`smh;`&wr>=d-JAOO*8XO6Gr&-}Q{_On$sChD)LP_=3KXbN}FAsRvOi zM$TptIr-}(X6-i(qnVrQcp#4+?aQAmhK=Pnd#KbBly91c$Y{&i9IZ-(F@NYv9%_LK zu_K|Z%yEsx(u~HlEj|x(F24ZA>DIFRc0?r$U}3#gOT$J*7wj-EyrkiSR5R1=g;$Gh z$NhjS`!cD4fFlX_cEIrU0^QFn&-THQIko6Ff+z(pfp+USHGw%+Sl(M;nc+Kl<(PY= z4o6n^Ti0e3bz&+YM<6z9CS#H=@Jm3Ym{`SHn2emmgk z%t{)U?GhdVHMKK3@{+b=3UAGf&0RjmZphIkJurK>ynD<_V>@Wxpw?m-{Oga;3V2Wh zY3tDUVxZQvv8lo2^k2fmbN^?9qcr7L@C;oTLcPAQdy-$c(4g>X{FKixHZBm+spU}DcfD?PQ47Htj$-sTidez@? z&`Rd{8OYAqrJsX&{?0*xQ!&oRqWsWqkMlpd_A&vUv+koXxkVy|t`t{kii;}b$v6te zNCrrUk(sUFU2HI5K2Fdg!8Vf}f$Qq5^kV68S#{50s{8A9IqX+wYJa**_8%n zJytmv$tGs|PiR2cB>YzjwY&pAVw-t&@Od4;sGXgl`ds@|%hT)7G}!nAZY{!EXjc2i zueS&QZ}J^1G^#xD0Q$6jybXrOW`R!nu|uGOT|MiKMF|y1ZU4k#dAVyr%iZ!g)W=_& z$Ge!}nVpySXl=t_I0x@U_u-{W_V;Q5K>>lUViF~mGT*K8uAUQV`T(*cg4W`E`uV>= z?t$gji!~=#*W&OqN6V54Q(v1?j$otn4OM|+%uu1u?9=EtWBf?qv}Lm}i$xTo$^YKx zs9bL8oGq=si<}KxE>m769rDu>5P4?s#oPn3h1kUB@3 zvRs9{J_Q%RmgR8~&+P1ScEJ^)*t;Tf{_A3R0Dv1N!1b&xYX#G{q2}bQ*clI?QFo!V zZH%MmnIRAdBfA>i01D9amz|ajN?P5%+rhA*sC3Y`#v;S9u0`PFkg_)eC5b5qnpQ%H zDdd348MI>>5a;Zo)uo;5Q`UKp%W`y0qxFB^KH>n1cI-chB$nILoqmsb4g})(hoQHi6tRK)qzUz1SWCUD%G7~(8Ui_r-(o2F5SU|e4jY=@1u!$|+!3&y zn#V2QMyy`;5&|<4X*}(Fj*SEcTA6wMXqk*%c~l&Gt+egMkPD*(*@!g$9g1e20TfL7 zigs%#h`yVnVGxQ;I)BEoO&-;D--0^A{9J0}I{zg->HSZa5+HTSjk2c=_Z*Om-x9`K zoGVRmDn?kQftol{MZLSYotBoiJ`6!QR|)YJ>h^Lvm!E)d%LyLM^Q1YtWJMpeRob@2 zJo@tO$k;1o1_4n=gc5@3TRvqJg=Of_G57V7;hU)-ajy# zME>)!*fsCtX&KYyi(YkQzu?3+IC80q78ua6yR8HnkblB~l*eM(I;W*N?s9rT;bVF3 z55US1sar^;>=fE;X08}e52fnUZK{38=314ZFuI}I_d;>(dd|~{zOUb>U|L)&@+%P( zmdRRFxhYn3_8K9s^0pcZAzS|B!%;z0p4PG)0%UX>+n+f&hU3=~L$GephQFvO|c_>%tLN!Q>Hs;)PI`g@e?||p& zlY{AG16ycaHP2}E%tqN;I+C1H1Y|SF92Hm%eO;LWBsm0DC8peZ*cdp2OeG#71>;$Y zo`c%_X2(arwG@6BdG+e|9d@2Yz)Qb;>p6GG*wy>e=i?Uix%8UJ?#fHii|+pM*KiS@ z&^mQx0Sqi9U`DZBN11-GrRKEeR?MoF+~9#xU9*AM6@1L0T&uh_`u*Dml5d^PY(KnX zX7;;gQ$Rx^&-Mzv;E1ED>;DyT{5z;tk_Nr8r&oSBZ@1Nn!?h*tO!0P5svv2BSa79m z%fFyK+ca?R%>`Lqm!PzPelpV+YK#^J8@C*fZnc*i0>;^~>N2oF+aK+P%vcp{yef^U znCZ2JmlSrEMsGZgojmbn`>DxMUB9us2EwsN(maHl)Up6k%MZ+eBmB>kdSlPmQT!!v zJ(nO0ji2Jxj2&;;biP6FES}hc^xZ$W7oIfpGK}3y)`Uh1#^T>1AzL7z$_9kh&y9^j zg6aQ9TcH0VW(f^#ZA@xGSC+f8DmI%S!q3LwE)sG%yk*CGQja*aZJikI7DQevG)+0= zZ$pJ0x=xU3pkc)NOsO6wwoZ7w69wxu84igi**+h+`l{TtU%?0&@!(vJoVW8M;WEYW z7P^q3V{!9F-nXK@8c+Jrl%KyszL0wHCCr0eM+QgTr=^Fhh7Mb~?G}s`xbLW6*pZC2 zGNW5ep;(A-@AUXdPQ~}pmGO$nd*4x~&Qx=a`4OAt+CB+fZ4rp1+xqv^%)C)2Uv%$tO6x<-I7k8~-7Thm2!g)LPRHBDC}d zWVu{p%Gb*lM`@-&8uG*Zn`WL*u{G7N$YRtcap2-6t8bS|jeKFzIMk;g=jz&N8X_R3 z9vp_ITlsPK_>xFoYwYgDDE@8Z4*hQxFsk!6P@A`5d`B5FIb~ZxPbCOWI>{?hMtLy6IH0<@qvW-O76cjl zO{J6M)&>x}MO`R26K_yN##G8AaD_GUa~!iB0Z?90lVDIU)O(AFwMvs7GZ4wD6s zEyxTxm2+hzQ8D)Om6lUiedH+F-VIAr3?0j~MJhidgDFaHr>magxuwZnjF&5sM@MBX z9mjp%5Z{1B2Of4fH)=oZbrZ9WWs zXSa#T6i6^`)YzY!B?Aj(^c|d&qgCNf+8HC!ZJU2%$2&Kr^11p<^gw zw*w76lLYS7LlbSxP({Ut8$@c1uFY*I1JW^ujdr(7FOR~kH6~on?({RYl3*K&ab%OO zQhY9#;p~nID)3a{hmh{XsqG#%)u`#Wy`rDh<~54X-+dR>d7A8S47Wn;ZyX12!OE>Y z`Yt`@!c181Le!d|7|QYv46aB^1WD+I+EQu(o#L9tga$`$V*0I`k5>B2FnCN;m*MaZPCE{gK=Bhu*)~itLOypv1WMUju}Yw~N2f zB^)@QboKmyf--D9jsgf!canvsH$H&kh)}dtrrOuPb)|n(wB$014-iN@2lmmKF7TT; zPM9vQXASS-dpOIZe&wFt3qSSR=K(*<@<6%R;$zkMJOJWAkm>o}%C*t)5ACGi!q`fC zn4N`_Q?1$e)s!wRnA8xli&t-PU#`{gQ`c2nIS@TX-kKS2Q_o!>F=2o2KfUEOQn$%z z4i(U0{xRJJxB;}sHd;h*IcJM}JEPzj_45NlWJj}iPJe!zaoS($JMchm-6~#_Ita9n z>`@gZ)Xe ztRP4EKeRZ!%eq0oHRw+TdIfvk;Xv$$V^u~@&SR!MF=6dR2{KKPpFgfWTcH1Dj8`Xe z2h5w*+WY^F1d|AO9=%PKDTD{-uE$uDp3==h*8gn{fAR}Z!K!EiP@yskwr7iDf-H;l zOM7F1B;M56*jS{zlgnE0e|N}NN%dWh)@=Yi+R2-zBslfVvQ~Dwm86j_E|HG{rPS}g zQ(Ku6N1B-Utparusiuy_;$Xe@(;RuSa&mHi#Ce=D$mc%uD%N>LLwK4V1X1f5Vx|u+ zI(ecppMs<%`!eF zEdBpW8>!?gT*f(sc4T=u%#JzKD|>yCa{CT?Gvtx1h)5V&W6BemI54j4zVnt73mQ=k zY7h51&+lc3`#+uv0+`^|l%z-c?(WVU7EYQOf7or6g<4Vt--cn0o6&K897Bhb|0B3* z5Q_tDiNF-j3Wv9hiHnJ~XEW=9y7s|$%de;P{!4qa4?@HDU=wOLmGe9U|;1qw2HY&Z45YR$8=Z_ugjQ#(2FB0ZPQtul(`B31^14nRshFgDoYfnI=BpOR-SS; zBb7@_HZKKEh^|W=!5I}0f+5$bFu`(Rpt1i+5Gx9bw*f;WO2;ANd}X(U1j+Hsz+gLZk`&yac2lEX!dfa&YQUt z?PR<2{aj@8Q?6)#_4}u5far-zPj^A!@X-8Q4&c~XPj`G4aXKXuYb!{?dYCAEa*op= zEuHc%sYJ=D!dRgH1yL*!YHM#w`N&U6mOR`bfugf#fVI6xQ!m%$USf2G0Q%=>tzlT5 zAF*=nZDF8Y1aLj|L5x7L&K^`yp6H?SX9#)?O3rCUe1e}|&zJz}u%?C-WB7~AXMjLv zZ9BQLsRT6Y^h3P%5!0Xr?qlujbKl33K#}D4mB#e+^sl*}4@hu^`iJ_s-1Xp}yglzD zB?sPZp-%e2Ng%D6mW_Di?73{XSXd06vBD;+Qs&8o`@1K4zKinTxt2DpsiLZyX#54# zRe4G^D?g2AU}Vg~+}EZ&5v0{J@eMwIP@d90>1@B%V@T#lUU_-Y{LB0=PRHkC=DA;# zv$x3kd4!K$x8y~jd;FWJl&#M@Q;i+zT)GL3 z^FKQ&B{eN($C0wM8PYbpdx)=Xl=666-#&&q)oH5B=uNl9lS*Q$R{xz zWXAf~fACrIHsQXQ^n9`q-rvGtA?2zf( zHYu>{IUCAgz&X%!5e_a@eWyQ&<*#6QhFn>20%C2A6hk*<2_+s|gy(D1!r*#e6kr!N z29#>3A{b|L@b=TUGUOu2!VmSzY-R7SFSHj$DCVp5Rev8BRk|D(&-sf}Z&ENUn)d6= z@l_GBbcCny6~wqn#9>jqg=3?@BaN@gA69xv?t2A%yNBAsF2^yCtM zc>0i}!|VxzZyjN8M;>SM@N!xXj1?^9Q zt&T!Nvj>M4H|M7B-lb-sX>((Xl9%$IIawdDTY2-6jDt(7p~joZHya!02RJM6Bff`y zi)Y{FsUmsMf(5_3_;9RBc&x*Z8}8Y&-{Rrlt+L({KE~b^>{-iS^)xWMI2K7eS!EHn z+YK~p%?#OIPBj}$U0G<-lU`pL2o@tplMhdQCR%zpBW^mq-t$Vl{}Y>pB2#~BJETkq zz503c^_$|>Vi9$cy31YG@Vl^+5Hc;kT4R=dU;`v2Bb%F{wYfeO+Qw>6tZKk!{K=Od z9_6Jv2NZP1!0~?NVc{1Lc-cl4(A30AG%ZsX$ry4`o*kIs=dt7DpDSt?YPu;}biK$K zZ@||ff8SQ#`e>6v3QZSu_L;lI(d^t@!nxIsKq{8t7E!&B8ExiAI;Hfo>RmZ7lnud0%n4Kbhs#P3m$ zu}4tPlz_(obHp*erjwDGhZFuuBHM+tKY#20^JXqQe5GF687Q%T3wtTU`aeW#mh4$g zMWV+V8&yhV7`_oOqYoa}ODtG7#(REK1_i`?)*Ajsoelx0aqy39`MkYR>qeDrPn<}_ zk7|2SP%ncf`#?yq^{z&|5!g&KQ-|`mH!4kBD(B|-QQgi)DQF#mX|C1c&s9pqwSwQ= zi^pnE4)eE--7fR<+oXJwKhP{w7+3zevq(Uzf<5Cxz09P%>JfD0<551G%QO*uWV&&dNzFZN0K5*{XXT2*>J%sFE@f4Y;NsKS*|lTHVY}{!CsNMsg4i?Li$tR zyY($={{_<>BKBuXV!`ZV7=jX}aiQY%qZ2DFXz55M4%n8yXrCXcq68c=`#fi?qhQiHo0qRn?kd{kMX5>n5u0h$5xy z)ve9t3&uIF*+=tpWNbX`s2U~hYbn#)3h zX5<~ES|5LMzRwMEG9bsQ&3r}DjG5^s{>2H;dC)5O%JqjMDVtr?N<;d`(D{ziLc%L4`6~e$@AFINi6mR0qd=Kk(lB zaLpSxDfex$h9uT;Cz8vGh=okAsblXIvC83zE1uiLeljqgAq zj{e?3T8#9uE2pemamuEosXA!(veU!h_Q4kCvYo0Zftx}g7V|lB{UF!=Zw4jY)VW8l zf4Fg#p*8e&!VAnn_{_N<8LV-!YytLa4>t>qw6G2i4$T{3No8ea2u2M+79&99cjd~F zceOjLH?G~d;jJ9{<=glxw$=yq@UISCA1RA{Tzk8>z=WEpTx+P4`gP;v(*%~Ff*lXf zjN@2_`bW(_(2QVQ*UG@$Ptgg*b6Vkm$ViVGk#JIRi+a6-CTU34|du48C@ z!kf>TpJ%mOWaBQ-a`vW$1CEs+LH*KYafjRFvT65tzi!IIUrMYY`k*(a_ry{rXhzX0KV7-E`-Ts$F*a?e2fl1~V>I9q&7y z1$7xrXr{x5U#9BOQH1(_&Tv6Bl{_~#^n@>3ADS4g2NggxzCuJIaZn*HN+U|c2S(mu zX+6?cPaB!)R=J$1hAzF2{!x#2E?s5L&~rW_C(!U+>ww>Q7eu#eWBC9rtq~~W>P19d z5jL027_hRWA$Ts_kkuaOyy%DH(ulDUtcO>$?QQE%4gX!aXZ-0K=G@>K%gSxqp}wJ% z^#RjzhsJD0-~`Sgr2J?xYaDfPFu_@d^W%^t;$WSC?=;WV6unP6;1-KI)S3gH{q1+! zOr(Rzh32NF17kqzr08PY1AwlY!ec2fU%sqXwqEF1<7xH8Gb0KV$?VFP_PIz)NqzoM z=g7*=ZhxPRpw~Qc=*W1dXuZmipiJh=mp>q0mzalkto%5&(9AU<&2uFHiN=Z zg9nw;xM@7tB(LLde8PlbW2}Dpp;v=-UU?plvw09#22?-fYaZF)ShJ^S^@k3B-=)_J ziFEDW{oTJ7b!b)IMP8t+a#xupGBw5$V~acC>C%`QC@_M1x-t>bR4gDinVHH~!aP4t=UrPcE&a-TxJVlX=>k?>M82aW z^Jxs-Or`xW#XL^?YJxWgqgx!md{;wbdLZrXFQymj6{01tyC1oU$cO#Jd09Ld8jR)O z;7CG`+uEtWlII+#acK>EKA3Os(L8+!n`lU3KP99WUrW2J1@`)&<06Kv+={fYXk;ky za_O_ZJNp_AcdC8{K^3*$nJ>^i&CP-`r=B!}3JN>EpAwJ0hr{t%qUKN2^{k&ie{N}+ zH%>L7zg$;$tKxIb^0PjHJ8o_zvBMR-9x|C*bXcD#kj+0Dq^P#itU0+f6fC~8BcV9b zbK_FD0atvRnUuS#xOF0{)U~srnJ6^_7$+<_DTyCtV*rzc0b#sCRGI;dg_@nc5mj#h zJAZ6joYK%XriaKw8e2`I@5RyLL7y5-lopU#Kr6ruC1nV+rDkQNL!}$SE>ZjY>!1b< zVI~*Aut+bNGdSBSzu7$-y=t8Y3#cv9o$|PVbBz=4BnI?&tp}k@jbLhUXJ==AkptEe za?e!e=$op6oVrlKWmRjFS$iW1+c6lb(+I|Q1vGV^;e&M~J{G#UHl_#$euk=>x7M|TL{kbW4s6Kp{VDr1cnRLu&#b-Rw%ZrjALBmq-{q@4J zH#?J~FGdnNAy$Ee79V#XuDdsxcE7`+^dKFhK9$I z>m9)|LVIeRF3H9*B7X2^6T)WD&ih%u*S&qeC&spKgoUW>McFR*;hx>*IoT#jZBM8- zigfX`KO22FHb(1v8EYKh6GVIB@fk=#DpW1u_)JZYvFE9;M|4$IY02l;M(;l;w|;C% zUIPt|u+Kb9z~PUBO&l$kF)o+uTTWR|C$*3^N=UN}1#(U!gRvyE)6xqGDVI1wFKdHQ zlzn-^%K2!)8Fx!0aX^PzsD_9$RV2OhuBb9^Xd41?$0#28>s_Ww!?Ravdy8Xd#{A3jLiftHtM?^tJ@b!vZy-|l0gaE4YdQzfvy zS1&t=$kW=#M*l#M<3TxLL_`DzgZY6!2y{yd1z~Hy*q9tYcszF$YL{&5Jeh%F8Ubt~ z9rzet9|UqG%d<>^#D}7lO67Lhb76#L^+C$F3VX+RWZm*25&33uHnY$1>?}Y_wdD) z#_aBh$b}nHXHp6mPRAjmQ|p4dv@|u%%z|nS%A2pW4h}YYURjp+Rz}%k0X|mnVs~D= zU8!5TK>or?nxa_zZ1Kxxj`-U~o~N$AzMg4)XYFtdLVP_VmLqy+M00bvWABSX)$%iT zF|_YU_ib~SWQuvvmzy!FkuH%C( z>#;lUPNxi^lrC(PTQYMk7iw!oq9&f^uT+Zr|#uddszR`gJU-2+cI>~bQ>(t0O~ z<2W3%MUB2c5}dks*b3JV-n+QB(wCs5gzdy?039#|ojnY#>cfVfH0LK$l!%0x4uViY zUY_K|z}lX!E+GoS`uYQ4c16pIiu!`57wS-6V=y+Q>nECH3F0u7I^WV|=Q#0ZU=aXv z!Ehuw@BRHdy-w!@JX>~crcck0x0Kp8AkqB+iw^sS#YlNZu{n7+!(Tv~ggS2lyDCms z5c8#1=4whoK|u!^U|MVf!)qD4DTabq!2NcFni?6^SQajp8wo#mJ%jk>Qntp>s^>iB zjtaE^PW$iymAV7v+55ibU5bZO!r0!4EI-o=DXiq-B&|7*@sMPi7By~p4Wk+MH|bL+ z2|xdvw9bsa^7eft3*UZ_F!?t|F!2n!6>ltONY$=%)4rL4Lss~y3FlomS7l{-)kcsu z8Qt*nqp`Y~dc^TQ+f-H>c+KUU%?}2)2&k%gKnEQ0U0Fakcs3L+X;e~|wJn&Q(7@Bd>d$#&+RyZJT#{I@M=jmgr}6V@Ek98-Uq)-_=_#-wami z2C`=KwcXzTvF^8dHi0IZFYjC50dX>-qb#r;&A|HJcw~bhDM8iHFSv%z8~W~2w7T9f^P z8gnBB5>U)M#`SDWFYW`(2>g}V?Asnx+H+toeaInH?RXf13B-#1skmQ~8r@Vj#6jE) z^OV(Y0m5|~+J-leueQ8livD!@{y{Fs6YLa{$C5Z)p;FM(D`Ks?>)3O1z3Y-H-7q?? z1zM_-Hf`C;XkWhlXAL+ULT0sOv2;tC;rnjdH^$OG#{S?vVF1av6d=imEfkE0pa_M8 zu(!B!%Ko0B7jr7I;dk0<7&J9C>%cEG+TYJ_7Ke*=9Y!9xjA?nGp@H@UWQg{r(<@;7 zkEW%rnRs6C?V;X-3i}WH94eiBBoW|9#9R+eztq)}+7?fb!;QK+Ck5M$*3{xiYa5H7 zilH%ZW$SuRL`Y+bi?>K+JOMV3z#0$kw)!8CoBT*z>V{UTM<;f&w{^q6^e!6SRV&+B z_Sz~o{q$*LYoVt?%zoL3&Lx3*?zj$)wV;^rkM^D(CcE(7CuWR$O4pSLCqWyfU3WH?JmImt@m{H(Ni4 zIUS_y)7~DdS?)4$w&>Y!aCufXymk9O7C>TqU37*Ow|AC07cVW#&Wl&NVnM#&MrvkvVDB|q_}%!;P;at&Pa>dw~M$)HGZUDXw~pL`n@HMbH-Z# zNKf}z?)wGVE{QMdJ-xK!#@z6orw)T0tD;pUffI9_TsF44bcyM&r5KZ<>0*M?A=l|< z4onEuX^#%?to?U(BJj^UJ8k8O$urkDcWg9=E56cH$`oD%w(bu-JIa7&kL(Q7;uJnkS>dAf-r6u`6G=JGP-TsZA%~+* zg}ucE(s=Mbhvanq>>qRae0#c+b(nr5$R4c7T~A6jk1$Qba|A^k@K~hEO7^f%D&aHV zG1S`>UfpDp+W=cK)d`87Y8i^wYy>EF541KsZY3>~MB3y;-%)nUw6c42RA-jk?c4u5 zd*lj0!i^Lhfwz?1A||+_A1X{Uw6<}F8BbB>rSTklgJGzyu1@kF2eCZX!|M5S+xwru zb$;~U@P7ZT0(1`ncyDC&1G6=Dnj|)I9rHtjsC7C0Ns+D2mhS0c^RS*ZM;@DZM`u1e z=ejNb+@|-k9dDl-8(vMfvW+9YsD0(MY}HGkqFZ6`lMHc0KoKD<*K+-v z){|<98FZ!jZ(>hDDn(y5Z;4A&Bak&t`5WzwJQ*jU7#v`X&{(YQ<_@$gPAT|uRS(*l zG8BJoT_ikNSu8T#hDPW-MeYuUC#5@Ax4m=IWkqag%3Q6O3ua;$sQlTUmk*UIFo}-E zy2}>1uZRgh$+x!(JbC?fe@&gZTeg>=as`RFSg};INiU)?Bp-P}#^cy*2B+&O!5_^k zs^rCo|3*QA<-|4hwFP8S%FINIhsiC|N@rfAV7X`gH0Q9t&eGPXo?NLYA~1gXl%dFe&%dXAbN{qKz_MoXt=CkkUHrN@wY~g08To!CDCfKb&IKG8 zSmw2Rs}%dNYVSuwJRGYGV3a~6|6n=3G6URtWhlKF_r=L0dl~&mBZ&Qp;uIB2G|@<} zMbwI~d$)KQTa$v%+f*1T4B^5R3cZ|}EhrHXV=wDviRvGScINgNsyjrI2WC*DH`DI` zTbv|uC1dOzY1$Mcu;ZpN{7z7&qtpI;xbRStdovr8JJMF4OK2^9MueFsHfRnHN?JnB z$;j;o08!r%8!PzgilPAh?pRoVoxZ@|0Amy-9|eO`wxga!ff+vRid)LS4!KIDJ zSTK!ok;>+QY)7wWxg;o)%Ke~X;5EgHyyN~vhSZJ_o3e-uuk$h zDH*SNQnG!BP%O4T)@lysi5>bu8y`UcaP{q(Bi2z=#iO_eqwH_aAv`frKcyPjf~ih$ zGG!{?!|%OTveCYH2So{KzCP40W_Nbv9wx45nzT|eQzkVR^obf*;jWmxYj3=|X{P}U z7n|XO!ZeA!=i2xs?whTl{!Bk4BLZN2pAEs_fyPclPuOp9YwijTKBN&N$Mx5i!GX`$ zRH*gBmW=82B4ZHSyVZiA40bqOyWBml+-hpfD1Ae3cV`*`o6#NH&$^|Rtj4i3B@PM- zww7-2Kx;WaHuu?whWu7rXse*imLZ310fZ(DMrxPL_4rpAAN)Ded;EJiO!6Vvgtx8{ zu!OKfv*t9|qk_@$ZGhUw@XqNwDGz6tMymxxRqgCnDl6sBU=A~a48tKwRt9IYI&Q6z z);9`gdtAPJ2J{)obO=Z>I)Vt54jn6pWYantY1Q=yQPAq@ISKX{E+M2&NF< z=D9$ovi7d2j{^iC-Z%b~mWcAJ%MU9vw5#?QLVQE)@RPF1AQUyObWIL2oE%9pdZ1A{ zimk1#$-6{_tNX5hT!!fSmlDm3+;EFq8o`DLv2ZVInQ-zk`6Apq7<= zQXj7Phqp2U=oe|XHHt!W8D!RmC{v4)T7%++nD@QKS9#R#H_$J@1NgW_Xw9x{M9>@DM7Qbe_ZpGM027;1fc^UfF{(dP5iFy_)j?E$!^FsYeCX1`lsebz* z3IkIYMVnkp}_6lKNyK5#{9yP-U01{gC!{RFonkDBhs zw0h^|HNsCl4v1;JA}}kZZ0L>nSdS%k=^Ze;11C;5ZKxPJICRB4-ym}%8=Lk_JjL(6-HnS`@ark+8Z z4VxAGiOM{QGaYuydB98`z?qg{L1?-TC0?#|2Upu)PDG?*aPV{fM!G7d@qhxzSR~$0 zSzB|wWNB#`;lDYKmk`&_z~l2S-v2fr(5N20YbXs!isUZGmm-c|2vZ`p?%KMT zC4JAxSTAdqIO}lb>Q!T@XOxX1fnC77)G#qHJmU)vN@EZU@mjgzJvyqN3`J;?_6f2E zG7hw0FVpacZ>$c}s5B;)ak@_PEP9mgUiQT0Mq0f)K$t9lGYQVY(Be|NBmnml*v76( ziIE3Cf}}rGAn?*F@&&Q66=ky~GloL#wQX0<`t(NFz^Xse02k=JczYwsXHj{hJC_uj zLWk9vX!dN)=xdVW%ek7lgQ^0)(Br)A;CQvr#QENr{dcY*1 z)2GKT)NBAGaZUzd4?zfV#>0oDF5b}6I!*Y2F+)^v{WT3A1po{?-Sl(*v|!R!1=%=s zlrG>_NSnh7g6x22vziP}70}TAQN7Gjw$TyZHQl1qHxM1Sy*Xlz@7&2gec+OK48MRL zf{?l%iU1kF6u#XFTmv*2RbXq+r&O%XrUY&{Ly%4-r`d>f`yxbgbJyF##s`;g&(;FJ zG66>zsuQsQLro=!wyNiol1<^n)SBKB!Fkd`s(;L+MQcFC#@Yb5@^Tz~E4>=!J2l=+ zx<&4+TkShLWK+W1YaW-3UJi(sURQZ=d@Y<-v)KMDN3?}>G>sYmV5v(Ojad{Wn~lvB z@87htFKX}&jN=h~0QsGqL&?b&SX>c*d^qNgm_w~CEdcCT36$mz zGpGd5wdGFr7#rf7^1}3paOj~LJpm0m=2fn+Yx~kxe^kY(2M`DCB|Fs>?qu98(ipc3 zZk?_yf&cN*KH%0w!008=cSFXfYi$*?i*q%XyeU^INEo;Jo%Y?uvn-o}>gwDL;SUdK z0hmtaZ;jk$T8J;ENSiB8S#OOQiddXMZLcjf8{DA1AK+2FzK%jW0w9yvS9^O}0eA_J z>y7*7N->}*e%wX^qup#JOMO;RQL(522v6DAT;ZqUbaHo>$-JuWv2siLBI63^h_(q^ zEaL>Cq!KbRDo3wyEPk~?rM94O_ULP#QJMW{M?uQ#Wt<=xISz2( zzH3v&=fuuIxX7gK&CvMcJc5l8SL9Bl246stV>@yF|Jc=Yc>0Ur)={0#-jFBTRdIQ7 zlEJc@?BXPxr^Vih<6DLs!0jb^q<#?EErVEwn;pW>7i56}-J@_7_-VH56CI(l@zm6t zD~7Bk+=#JZNw;poZnGLdx#s|cY7lGJW4YZbmW z)Pd{0U-)0NOJ8|$q-QnWrL;|7TqJV?l)OhA0oktU$36$fsyA1h<3Vb#umNH3eCx$4 z=NM*tnk8&!wPKcY`e7y}5wNMP_QhZ0+jt|W@qZnX{d;A=1Yfr>*A{FdJm8O8SySZ~ zcc?vW_#l*{`Hf-;kD_UMb_KJv+=n<|Dt6Y9wu3pX)I%N~C_Qf&8v-oAum-f`kt8;! z@K(dG-CbP!gAtoKv9fF7f{5K|Xbs#K@bK(}h^Xp-+>5b9=UC4Lbc^<9cd&yhs6ubp zQ)pwOBH+rYSojL>bi*PFBsn13 z3!Rl7>j2x9FW7x!GstRt=GW{$T+CO+3ryvw)SCoLFfmEr@RT3o^hnrolCue0!DU|g ze{f*D#p7msDCKJAL9To$vHN(hy4l%F6aM)x zdvoMp?9D1anTm)0#l?q$$E26x0*I&tPWSwHtL{!*MEiaR9GGY zJ5?3~KwJ$qub8#y+2~JBG0&x~_)i(C2uJz|i;5bhGSGOG2JgcT`(xc?)DdMc)Pb3{ z{=qI24k#VPV3o1-(L^sO5(h_WH*d(_>2Mp~tdwcpkLo6Mss&4rT(@{?QTpqJXI&2u zTb$(}eXzeZ=b{Ig#iBhvAqef-HB&V8ePU)l6%#bKIUgzFGNva>m}`h7Hl}vb zYoLREc%k@p$#`9FCuX7MG#)3GxsiOv=ZMzv!w)D7d!nVC%slH*=iQBeGV=^mFlGn& zn--TG?(88NEn>*dn#}!RhG+zLft@Xo+d1+fG9`tF)7|E|tx!+l7J#&u*E)kkrU4hC z#>l~(5_09o>Al+x0(30}aca>;b+RAF?LOQOAr9|{5Qa2B|5|f7=iCjcl-JDwfGJ-1 z-AKNGKIC|RzKKGoYO7Dc)%ldsyLHB2wpk{4jQ(E5uYPs+(Thg)F&>ogi#Ue9|t zp!d4*>H{Dve~yoi{rnlZkPdhNCIOvSRtrW3_|8~2_uicvP0QG+H=6076 z_}|JXC_~qdC{tZL?y1#s_bJkL({%u$*T3=$!~`J1+7DynCmc`B*tJV=`}DrFv8Q6m zJ_I7kopF7@vPJLowS4|Sv(>OhBFx1@tId5mCfYOs;g̣_S9FaM%y2nxp)KKxh?Py5CfwJyppnTgzF+cpZ`2V%72bToX{sWivnT4+zaat2LHYCK`C@hOze8F3Vs4-Yj z>ZELl4`0=dii-3XLq2oa3Os>w*Edh|(W;-1 zDjq9TtW?D+Q;WR&-IIF7>OlW6;^DtIUTHD$RvT}^5dw=`fu|~ra&f11rIFt!9cl2>U$AOXu@2|6z7Un~-2l{}o z+;{p6t)82J0WPHL?CP?`*cW&VBcC|7g|F$351E)9_I?kPMQF#6)VUdUU7jzotz5TW zk-2ia+C6%a>`h$=)JSqdzjy12=>!$D&xZ}Q1hYp=xafCpt(pY#Y_9Gx;dx@J4u%#l ztewUJHynm*4M0X9>*h!y>?LblMbCwXRHzDj9P3B8biUk9NLV|}p1;&?jXx;+SZ?7H3&}lBFjVb(T*Z}; z4=7XP*I=9Io! z|K825sxum;f8FOkNV3&NK#c?i{y4XPP!gk}pq%5*7`E|IPh!Uj>BA3I(esVNtL6UE zY_4$wEiJ>kI;Sn2b={{yLeWBsJ(L1&29lb3kxR92Xs`}w*@Bo+;2B6uf^ffG@J4AX zHUr543}8Q8=lJyMmRHStsPN#LwXRG+QrV^!0%r9}&%YT8PAE))yjW&{;k}k{z^suE zFe=fG1`F=6#d~s{1ljc6lS2vSfvoiX*r=%Z=umJo@(K!q0|G!l(8+L99$X%npnag* zn=ASwC`dvJKXVy!1}S;=A%r~_Uhb*Gxrrx0oN6?I;pQaeU&!S}28+f&n3g#>R{n|R z%p_co7SPb@z0-SIes4;G;(L-HzmEC#v@)*?*<3+??bUec9D9f94}HahS(`QzRPJ%1 zT@>@d*6a%bKehlV&eYk{r2UzlgT*;1r6J|{&c>H89{Bbz6r8kzz%9--exj9^T<kX68%&?}pZ z_&s(RJTr-vtthkL#3E%o@U>bqb~@DvTR>xE55%4AVK{b%4y%1N?z7u`-Z)~j0Ys_}_t_8_hE~dXauK*aaua!7OvNZxmWm7M$m zpSc>(#KdHWDg}S$;=ibro(kthkXo8+zQsixGUdYp<3>tfmmM7W6I#%O!nmo4TahUK zP#D`$FyZB{p5jrT6@Z^wYYT=CqclPRLs12y$naq0{6Z@ltRXt+(MsVhMr?{NQ(G}e zmg!uVy-k~!2J*Z%g_(V0%D=gF{?LRq_GA-x|4H(=wCh+hUusKiN%mgSb1X)q4ulL9 z?yH&(b!0}6n*j11mLzw&>63sx?mP)CuTCsC4M>=$df6k*PG}#yZb8Kkf%p8w+>>S# zT}DPL0Q+T1iCpah&UNv#taNL~N?4g2w1HxxwfGe=4Va%7*a@X%OcV*cc?5pM8@#b( zIjJjG92eLf;0Vm$lYfE2V1TIu1cT!%%)o%Mq9N$O1y8cQfiT$Kk0?#QOf7oqZ5r)N zg5N4o&@_yzj2lf5JwHK?9`<1Nx4omUa{c_D8;sVWuoBVROY52t3wr+#WnUc?<=VxI zFoGzh(rKe2AxH>AScpL=Dj+e0h%`vo3@D0{TwR~KUiYMLqTl;CG4q$gI%b-3e zG+X-2$Vk`KpAk88&#^cE39&H25OnQ{jP%@e`Lp1FK*v~I*QWp^fCbdnqYXeACKH?xts@|MEQi1Huq|H;7+ADX~YDaaU3H!vOg;g2^ ziNro=Z<864#*4O5P($Y>b1}!Mt#LgoAt=gyJ@3udB?Ke8#P5;a#mAF(*TIVo-6dq( zmk=dBw35tJCM;9Tuay;*E5*El)og-%_)Jl?0sz9zp%iYfWJRD;n-EMMk84>HaKXWnBa9OZhxND zxm^c8lN7UmqhM8|uG#5rF3Xv_W{wlBslzu45n);Xu?1JgVkJLjDId2&8x*(1b6a7H*z~_TjLrQB+m}9vUX6sf-XS+mW@drhW~9WO z|0!)q&Q#^cOJsHa{U#jBTjg@*4Gl!`eMUVt{k&bu#f*cU{xqHnap>Bwk>{@Lx19?{Y}oW)|%+Sw?^jVL%T7J+pouFrI{j%v0|hW zjP=Et7;Es$$KJw6fR|Ek@JB?4KT{_vrd6yvb+b#uG_7zNk=YQ7EgHQ(Khj$BgB33U z^o;J|?gM0tGKX=%d`ac)t%DmZ4jZU4Wvc1D z63eZBANuX`4~Wsq+Ut(S=CjMch<@uor@km|zSic`>8rbv4_dhIa1KvS*!rDE01{b; zSz+QMp$VYA`EF6%RNuxdNF|`Vz4_FF6G1HY_PI7AuZQ87(K7O%a>xIYe?$?m%fsngFHphJ2i2%QjOF>Y~m5 zq)CH6zELcxkoX$NR-R$ceRj8%hyv%lNhlOvJqbdEvizQ%eS$K;ioZUaw_{|$Ee|Q# zaS`q;d(1}eg4UuP=&*3k854y}@S=)5-hqD~4AW$&p;121>G^SZjrT5nkG$3ls_Iu8 z8QW}%##$z-vINVSj5vsiema+#nMusGbaH#x`{VhGAyCg>dJ{eW|3=f>B+(T9F8{fx z6`taV{n15(o+CJk%iAvlh!0F&%8!jH$GwBmhfmplOQ2IZ+60QYwy6?13&U>yOw7B$hy!2;4 zY~g$tM1a>rlYQud`Lo=-bZ~$|0eJU&12{WAQgo0}Wx%0XRDY7@451X4`$d*CGvejVkG z1POnNybZw-#GwpLYv;a!Hj)0r!uM{5GfhC$mfPCey1LB0d-hE$T@GET zrH`>{hOO#0WSZs-%Z*sHniR@{E5nc(C5eft{z{M z3Ug)J#l_%)bksJ3km z=C8>;_ChDNL{zL;##w+~rw0TvmnkshfH@XOynUZx%I2W4NjZS}W$%A^T3goA>QLv8 z{z-ZFUC~AYwP$bi<6p%ma{FJIVFPEInD7NLw7vbi@88z-aeKZ0NxdquIU+gJ$9>;G z7a<**&E_zx!CCym9>cY#zBq>^T=Wo52L`^lK%LL(EIQ8}U^rqS9&@51acf4Up z_oS0x_CDxJd!|uX=CN+^>CI02qdx}`4&7`_+<(=#TLmP!Sh*_1J`5OW^gM>v@1=uR z^hw|ILR~YDm2oyO&>20oKz_OnP8!3pF#V>tn_BS;)I$$8Lh} z8JAUwxumJU8CV5RxQw5+St*1&$e43EGxMx-;v^ewNgzdi8u3+qQ|RdRrzI^GU4rSf zIJ3SN_b!Yhat<}Dq~KL8{jmNw0GarWb-lm&XU_U^VCIr1D#xkI@9V%@ zEmeyv?#&JsBs(&x7-}e%_g(T*`DJpVoEt<7AI3_|0z)Y0DEv!}4(IHypUjO=xuEWu zn)er;{O}K~=da|G73U7j>IL+g{89s1^SGmxm5{m(_zvO9aYk}37)VyX;f@V0$E)t0 zIIO0!KwYzW!2A?W#;)-CzJ43+oEwO7>fYaIN_U)_R_M!@FZ9gjw@?N*Zfx9^;={Da zF1zIsW$m|i69l*T)xYW08pX)R$mJgtO)wDc6}|drTEo2L9Tlqz&0VRvUoAV%FjX&mua_d@&ys&cK@xJ_S25FCvG2qm#N*GWeRH;fnd7T-F+Zl?psq+ zrI3I?w=GX~s=f&d=E_5NRe%PO-dACI<7aGfxlSvGeNuim~5xvwSpif#KAL@R7Q5U@Cv0^cv^V5?lg07=oI1KQ> zg^};&*#|xEVjkWk9~d4Qk|CjyPsZW6Vj<9`=i#9O$oFWZ@qaq^R8ZAHLnA6TGviE& z&npXKvCwx_f=TmY9-{uP56&2+x~w>?YATW0x~zTrzW1!CXz`4&lE4p-@&b3*RQ1&R z75*LzZHKhky3kQHpnYG`(t1x`7(Dy%vZulQ>@#Rib`17XK3`O7Ma%~a=kAOcu6nY9 zT?=!G61L|KBibY1zjupujsH2#R7>NA;^eAp5!HNQO?!TA1#?YXlXfab^tF2|i2>Gt z{rGAY+3_Je^p)m%7sa$U?o(04x~E4Tr00!4e%PC(-s6YV{A65FQ6bQYn*|H=Fj@Z~ z!w+vIUkXf1V@mWn&U(`Ww3PK{tLZ(y9lPia(PY}~FQN)>zs4md`mm7DdNJ;+^0^h` zfXUe@rrWrz!};R^|H!f#2eBb3D|X!7_0vUaOEL@`4#;IexAncL_tTPo6QP#ALD9|n z)n(lJ&tiV+if&sKy1>uqAZ7HzKZr&=EPzex(~KbpNg&_zeNyR?Ag+(s^^R9HwjQDL|^NN5wK zKAtCEhw)ixDHB(8x2-(;WrApATj@$FEv*?$fyMeacOH#E_nTSOtybYHBxrpA|J z=ab8l7A%XMjR52LX=z2@cg>H7<9KWIB5D6csU(hlpcr#`S3G9R z4{t@(Wp-6RB|VK@0)m43s!;Vd6q$E9<}Y1gHb2_Krxe~c7irltD}!!zPSxe?!hDNd zm|4VjHmMyMeHXh5LV7f^#42j2e%GYB0tu$mCDzLVZET{GBur->tyDj^(+w#*x9LFI zPdN6c4@ElO+t<|z=vpRx&Hb~=heG4AP zvX`8#VeMcOZ9n%UMpI1Jbrsz6m=_$0TO!*-SS^~JhcJ7GKi*s(%&S}Y=7ZrF-f|c# z`)4hEaGqdQ6Q#97b>slB+M5bJ*ds@0v!)5r)(kxtOC-cUH{p8rCoEJf72NYJnB_TAz5(B1d zs3b}jnxn^$)O1xgR%B|11O|vPE*3}PQ{h{+(9oul<78^KTzhzz(yt8pEchVvA=`6Q zc+19@Umo2M<+j75Ed{xR2a8#f`Zb#QaWRl~EVQ<&34z6Fo$tXxgQ{Sbii!)PP0iro z;Al!bjYGy!Tzj@Ec4)T`tDX#I@%oj;>(9Tc_FZf^H3x7<@u}+QBB-#ElA|6#gefdr3F!YW}AprUKTz?xtQ6FlS#*10MbQr@qzH9f?fyN}@W^X~p z!Jv2-z{=UNq12eJ{gl&9ZEtH~RcC>+Km@0%X!X0npNJ^DGRdckOgYI>%Zf-~l$1{E z9Zz0`coCUm%gpRb{%alWrQeX@?#Bw_LhqXynV6j6Sd$DnT)z4VYDLW&QZ4soTv*mi zy-w>Q_4xDe4Ve5O-bPK}<3pnuPO4a)zUR>fAC5jd!;guQSECLOT3~v2xuv=~B2_!j zEQqx8YAl6-m>4r3_d;u~lbsAjdwoq!cVnFrBBM;xI4Cp~&lb zW6@?I2;+Ew^Rj`mhwhkH(CDG@E?ifymkj6Q>~LnHTFrAV?*i=tt3(3oY*d7cV6!Z* zXS&c)rHpJ2zr`u4Nt-+TNqi<#a#ixk1&h%9#Kh`5#7X7D8I6S!Yr0e6O|zQ~#*~fZ zFLmi{TX7{h%&ecn)jEDuuI=PkQ8BZSp`aCm9@@weQJ-m%j?_yUkH`A*Sti75-Cy*n$%O zd=}pE1}6DVU-63Sl_V1nGc&U)hOpa%T520_OZjrut6fXtI_-u;_@1m_zcSvT*%fv| z$2kK@Me{}Rn>|kCSp(8TxL~@C@&iMF*63WJM8Qk>&0GXTobe>bTK_+o&#vaM#s0{0 zmBh^Tw>ll`Lqy^uau{R>7`PBx{w3MKUv0U44OK8EotL{Z-ocMP{XjlpfKbS!dBr{E ztk_lP6IGkQ$H%sP3#8}~FPkk{;G0WC^ma29;eQA&5FI(X;n3)QLpI0q%_w39-IRsg z@mJzUU?Ml(xSE{?={hBjdE>7Jqb42OZe}eBTRBYct{@A)Hz)3)>2f44Xumb2>VTbC zq0$$J6mgoBNptY5oF8<$UYSvfyElnn(=_SScouw*^)boYnL*014$x$O5~xT*nsr#c zR*;up5O2Z* zqjZYA9eRJ#xO80q04FJXaZK7cR}FuWt;A6?{D4&T(#^}$u3G0MW|Qq_Fb0)+GNp5( zlrIO5;erdb?1EIJjC0f#^=^mA9a(H)eJ3qNN1HD$)P2$e4{zq9rq>-@$iFjoojOK%C$Tb=UI$h~x0t;%4MTx=bTa>&ZHg zi{@J2lNKn{HDtMo2I6`4JT7yMll=X*{T+5qQ93kYuVOcrztd_sxX18{U3AreWiBqy zh4&R51wK7(?)&$1?S~QTv^N>N)h#)qUH5;dRv|({H(z_N2-eR-vt0(-E&s7d>4jJp z?1L7>A&Jp@9dS2E%Aqzb;UOW)Wg#`x^ zDF}Abh0oaG6a*g`SVOR^sR$0TUyvx~HzW$l3uB^WdT?k!-9H>AxBkS>&kur@gHr22 zyYe3*4a#71h_1<=Z28t`vF6L0(DphDV53X@$xDw@dy5B`Nwk{sSM4x8KB?QcwfW(jCv_}l+p9XL5G}|YUSoj$tHeFr9!lp2NY$v z(;BMvbj3L7RRuQo^)2YOHm)Af0Y^*^cK@OD55ak6e9bb*Bu(FzS>zn!gWyGtNjB~h ztGs%@_A7?r*hZSn?4ChzP{vKI-v)EX@%BD!UGIz@(@_i>hh#LIyOVD|(vI1yayFbS zdv*s$bL8dRr7VUM1j|gy$o|imD8k$Q0?bbOUbIbZSxW_n*>(+{4!7{lO()Sz@j5YGV$&#lLOk6-1S`U0C+%*qgLz3i-a!ABj1sy@8@hVn&a>Ts64Y0~)G*Th68)UlBI&sg_im`AAzB4NhK5dW~^ z@UF4>ATh7P4U<=TPq67oP0d+j!*KM=__&BZq$j8k<&dYk)x4!Bcj+bNp_yv`7q28v$TzOKiVr%G)0cZ?G=HM34QRYfWIJ z{{99i9MIcJFF8J38ZgzkoE0)xkCN~`K!DaslV&&z)ZTy-XZ%U zU1iaH+UT~Zs0H8Z%Bhvl8tay#H{ctLa7R8N%o}_otV{Fg8IOphUs~Ka_BDDVHDK*Y zYFKfgJkbwnbdxAQCeDSMh}y|#MAYO4O#`f|_z-$@$MDBT%Yi$Vhn+xv?~eQ$4=$NL z!L)(=bc6VyE=;^Z%+cHd>Y8uTU2*a|cUzN_Np~9X5ayK|Rquy(tWJp-TAM%MRNiR1 zSZB3%=T?ci9NZQ#b;(kVv|KUFpBj2oAtEjwC`_B)8?G>ITRIX@b(ixv@IURIO(EzZ zP^`=3glH~0H^mP^+Lijp#K9NUkwJ$WKP?o&$Zm$2%YCzc2~^FvqG|S~rh>Wd{Zh*N zsxF+85||Lg7pMeeO*}gKmaDk`*!X!#OfE|^c1F9W>-!qKJ&`%27}2KfLBW8})1MRRV{u4JK(pt#%bg&OX;PexO` zzYfFlGM7|bg*RxJFpz#tc@a6@PH*OMz!({mN4z5lx*XsC+z~_p^~%x~>9%{q4&19z z=;{1X5D*V-8833)R&-G% zU5hO${a!q@Cz>BfIuBlZQK_5(nB3PX=r}wk;EJhRhyWh258h zxFNLZkN-Wily@R_j}qq=c^B(}5#W3?3_t?0P0R%un&=Rw$Fs3-vk-iRcYcCHBO)+gJJwxkF)fAn@@`oZyszb3v!lh zGQYHQ{pmf+Y#W>E3JUw^c zI^it?WA0(<*x1p{dVuGkVs|SDcdN-ZaZ4~hTc>yrgAP$^U4J}=JabBc~a`x2IQdJq; zP>`zG$P3Y;D9~SH);t&Za&X_w^yzCSfPXL=`LxvkII+-D?-H%`%Ftnp*cL_thf zW)j0vWBMal=R3FTFP)j4)cxY*4-t_Mqy5uYk=(?y+Qma}pDtZ%XE!bUUX zE$kdQZm^i?rikuXA7G>(S}N+H8?L|UqyAb-R8*yeea9))P-M`D)T=*VfC2yFeHVq4 zb7Mbz71ACNUzkl+=|c(_1+mhJ2=Yy$etRtWmpk8swZ@cF8LoZ`a&pKa0dRKGyC0Z* zvtILCBGm~KA@WD|!R!!C6C79-R<6v}XnDXDfA_3^=@Iz`YHDgiD0c1bbIqHd=;zkg z(KEWel9NF(nY_uK7!5j~VvxNzE`1yuly%&HmH~6-+!1`LBVDEX^MWa?+z`+T!9@(& z0?ffuF5+}on0;=xyiEGxO=zrBWg$`Mnuh5yXhmoehbkCX)LmL*)pJV1rxd9Q)TK6( z;h!J9xH5&Q+bQ=Bc#8E@X;TFc#{BsRiqD}pBswZ}Iu;?7sEdpn3{{k zT6T+*Ze)-@R##Ui6PKa3itSprg=Xo@7r&*j(1VN?H!Q1)sS!Ws@k!96!b+i}=;3B^OoO%|269xf3RBr*Cfe0bIL~ z&k52W^wP-Jky&M;ocqLOlxo&|?Ki3fy}yO$_>*l6il~iv(Ph)A;jksgRZEq-2h+~7 zQ*6uO+@>hH*esc;*L2&DXEGGOkE82!k>geG8fDP!O^d}x z-B#raTRFwp*{NRdPeRjhNwHTIY;ZrF&X}u+PY0!+a78RR2QX$28JatSF&vTaAh$;v01 znD;ccwvIIBJ~}O>BDuJ<<_;r)@u0&*0C{g}l+mso2$0L3bf%( z@^Wy_cxz$k4}|-J-tzPT63iY7+o&VXJ1Kq2<=6RY)^KaP=#FDDs2Atn60-V6a3pI- z1N_cPJoM_I;EM4zGZ^*&$~1Wkt@J*pZldu zoPC2TFeg`k#_w`sNJMJ^1MO1h+K9?yUAM$)Ox|mk2^`8_#Hyy_RZs%4X*76uPLi9xje&YAVr zH5!?Z4bro#{U1XKB8_I1`3|eGFCX@T;)TTNpzGB0i}_6Q>GH_-7unh)4&zp1q2eSj zzDuth$=FD7EI79D{OX;Fl>Wh!io0!?Yi=}LCv^^)9O*_^T4x`6Ta1(4F?zpJca%?1 z=HNm+I90Tkt#E;U*raL@%n+>>^pXDbX*{I)P?OS?X)-Xrs#V(*pU*H1AH-W(E)G522cLWclRuqGxZ*5_D~%r9Rq zhIH~q{Br-7^XJc64P4I^CGaMy9N@HIx=3!VJEdk!<)r4d_u{}O3Te#xH9Buv4gFgO z@<*`~c_uU3JJHAiz8VK!C27X$tFGf*b{$2ObO9UAWcs^ar@Gt9kwUhxzo115`YdLN zV6&L+JkY}zgNSxq+JhT^NsC3S{S4#cQE|E;GX89Sg79P7>W$xgo3ofyw_DmZAH41y zz|>TSPu)yFhbUMm_LB@jp09xj+2yIhJ))$h-xS{rWS`mc(!|jjC6PiNIq& z-zF>Jaz=asr-LnMEwl=2Xro;qV|G zETZTrH16~C`FXtq&#RZyA1#h}V)D1k3nDZoo=uBf^du^tLY8@jKski zijiT2aaUVBQVbzz;KHY)ls=QcMzb+=`ps3fB}&DX=>unNI%5LO279@%3ruo(wk2m6 zeO9E3W-^pg8riIa`E8_h!lhtq1@6sP9^IXLDzGLyXC{iNd1&AA?)y4I5Lyp=*P9VV z7K_=~IPqSNKH0=UNySy1#(iIJ&ZOB|{yb?$nQGxNZAUn{pkwixWg>rtm3a*cpIpOH zmbI)Y4X0mjxDOUr{0ZT6%o40ht4p#}9Ue#)nCudwb@Vf7M6D^}u<{i}} zcElvVnqihJSuV~FIZ?`r@xdReMTV>PFZKRNEg~D>A6$-7TnNQ4)4%dyv47NK-)OY6 zTumE!;v#fn*)`V63pQaVhn}SKCC0Xiz zR@k*REWbP{Z<_Sz3Lvv7tl?H(LhBn$yC28%@m)wjsw)*Q7=`XMBMS+X2*vR1YIkIH z&aPsumR_G7q%G<|*b!rI@u?%w2Gb`C8>4+Mr*8=D&%khj|Cwg=b%4jfs0a~U&u0lh z4^#wLdpoT&FyNOad{&Wa1nQbgAq^KWU{-6NvuN0TzyCc=2BpKp1~Qx23O8(f5yI)x zor(>q&4?v+h*!D0OE*4bVuM|3}L9(*(q3HcIbLVx|*_U8*E0~hf={SZ2Py6m-j|peDv(HUC z^~qRFXm-7I57$(wxO8#gEdPvF+xt&KoryOEQ48-mL$R$R-@{DU z#PP#kkbX)T z%w%*3Zk%|yY5n<6v2suhJjuiuWZNbF5e(N>{LdxgV@$HG`e#x}rydhfp8A;6yGKz_ zCFbTp4M`-jyg3&%oU-?u|43Z9!=~Phz`O`?Wl6-MY*&{17Gwq=N=M%`R=!H{2qL<1 zm@(D!CI-#@-$A=Z$E-MAO_CeGfeVmqmvCO31b^Ti7pNLs<_e8*OE4xZFE9H>AEh2- zAaDM$IC-kPzVf*zRUR7n>JbvkWMP8kIhpi__vaY#IT;L*Hm}ml*Vk6m(3)J1A#Rvd z6Rkl%zrEa=IE64vfF~NK7yHkg-e{+r*C5rmh`dqX-->3UnSXp(Cg#938>;_d$ zbD2Cb5WdeT;*;+r>iPci?j~Aohv^N|v!e0p=wa=k5$yOntSy7E%Ugd!+M?TN$-|qG zX6ZHNoM1f~|1<6S@r9VY4INC+l|NA}OPFUfXzV(*r+QNue?=IO|3ZZ#;i>C~i%IXI zyM8=`%!Jb-48McfZWD;Awz*$e;qn7Ac+8s~155(-bCZM4gXiZ|)lQhr>pL;@yCsCL z1SBT#Vb47qqm+=?8u_|?xIv$nqf)jTytFQ98ROY*OmoHrc^gy(7(77A7R=+UgAba4HmWoly( z|FXCWwG*EoS1>)^s^2YNE~q{;GID2Zv|^YnGI395=5r?crlY>aW$aao9FdUn56yvj zc_w858T`HBdlFa^Kg5wgE+3HKdX^Cdfaz_y8xn#l&eQ~=rkhQT_gA)C%S}+gSX{eS z4jngmq0>A&!I0G2%DO1ew5{y)CoYii>oTc5WbE(=&x=Cl60Y( zT_DG1p6LGJr^Zx(Bk8wZj0@FVez3!g8xF58o!x8j^aK1|&q77#vts;W z2Rvh7GBh;ECHQJvZ+y$rGUZX_4igWo5|GfB_Q72{(7B5+OHDQ+!hI&lz0e?D)JkN~ zTsqBsX<;~+FN-Laxn8~$O=N0so9P}&&_3Y9a4a}1YvP3H=yiyRxp;_H^kAy8r!@cY zy>cwmdvF*LHRo3#mp(2rapK4G{q_@MV{?PJDVwk)vyEWCW@YrvTMplBn?U>zfeNr; zfEaLcZp%oul{vEtExoRRu4&sgD)uEaY|CRb;CSupa>OieWLS>C3UpQga{oNJZO2fr zWJT})Oin?ALF5)*%59vJF?U~K;UDFJuBn54OPSusq6l0@KIhQ#vf~gWTQyEmn5cEM zf6FzbFj`;C^Yym@Xll2eC>>Ym0=5`v;DzpPZAhmfq=J@#(G$XiY|4E)GWT@4ba-S{ z<_I8>qXeMfZ``i~cjyUS;{%=C;X$f+76Sw<(g@z0PFmzapw4Qb^^qf8a$_(tGAe7j zA{KhDftSIEP5AN7`Xi#}dX5d1-g{LpmMz0s&n)_6M!7iPsSjbI|09)B#))?HZfX7l zAtv&_b?}Fn2Zx-GXr8;Pu3mnEwxx0Tckl^z+!jok;Qp1MHg5h!%M>+@e#MC(#Vw7T z^J36PIO;zV`_E)N(?7ND<|aA?&t)HX_UfV>kTq<5=pw@Uiss3KY22fDqHk+6q(l)S z@_}b@umH;|G*Z()vgfGOmASaM28G0}!UvwyIt9*P?9~erx>Qd+Z2(F3t8(+F_~e|K zGm7%^r>QPmf5sNSntc69U9y>vvHJGm@Ki~N2so$n6rdHeLp23+Dg8?#8OapPf7Q*0gtUD~E)!&F3Si8kJ|t zDNyQGMRmj&5~7o2SLu9#9iPbo)S3~zmHEV!Z%(^%ss8M+r7X(=Z1hjWDRx;|*{eJ_ z2P^zk1~|A}Q=AseILm?YsjjG~$4>l293p%0U>BCY79mas%M`FTY7r>@-;(*%ZOObb zeS?py^-X`GHw4nn;GH0TIlqv7Y*#Jf{5ALoGQ->wn<59V(U2sAFLGxR{`?Nm>=}Dp zApo6soy|-31gWPTfu+LgrRJ;BBZWk~iXGn}t$$ApW-LdaubQj)LzqK;&#)$S2tgtY zihW;)I6*q_1zQ0>xxufT%L#SES&kZ{^V@GO{QqJ=htW(+d#?izyEwjnB!;~*V+v`$ zv!?zLrh=L7wBx<$Ex%NP-p3O;T%a(zGY5mu0;jt1$p=E);UA_()HpZOU11x}HL4oZ z#+tO&JE72pND^vyCsXU-$TzjpQ}@&f16^YTf)$utoXv|$M+gJX@rjA%u(INI5Nk`d z9)>05riu!aPce()et~DQ5dew2WduNNrsf9(s!#L^iHSXXsJr8d<$FWl9*~v4-0?-9 zEIl-!vpEU>@UFffkb!)PjgE&icT=u9q{IvEAe_}mnzVeL7~$9+z5{K~I&p`FzuV2zxR5+9^J2>WV?Pkq&^YG(!%SX}3k*#2>_P zkmUVIZ!7-U=WHjk-Ny+5WBUPRkLgLoOmU7cKxEE#n9u*Mp;O_tqOB+1OGC-qAixx1C#_eD&ByN%a<1>frDqce}HUcN54VN4HOEq zIN1Z@@Ls{m43_{0zZ*h%X8onN&5tm8TAq_NA}hqZ*PxLnEA8&?@4MJP^O1B)D$iRp z!@SwbB+6=rPg&GH>Ug|*^*3a(HwS(k=5GF2c0i0C!SWffXkaaT!AlKUv`sGe@5ynq zeFo1tD8dD2TwCj0$gIyglvLIK@{0Y3RqT=}p4BpnMQ?{`wz+QRC!S8`pcmE($X3a- z;#R^n{KPQyzJF`<1zNITxO(Atb*E+_?3>tF$`&=lWc2O$@Kf6&fFD{UxHDLQHA8Pc zRzIn?$Nc2_Ucge29DYfmFCcT~wCWrPXhaRN!$xpiVEI25L2Z?F0W~?@HBKE}R#6KPVw`~qPIDw#N+1f=>%GgvaNDkN3 zvJq!f%noASEOy-*wAsQhg|+h{ZvSaBtfjYXmA1JbUaVCS^V8Ej^D>-s@fy3wxWRV! zYo<#7nH3iq*`|5va+ParM)0P_r^8OO6^;}UYRG;)Gcxip;7Rk-B!03jxyTC+#gG1R zU?CV({y}VN^|g@(%*Iv1ib-1`9_n|96W%5rctZ`_ib1er?A@k{XnvlZkW&@i%7_JD z@$he7@xOd#o_7oHCjKcR#iAqsP`4i*mQa!wmf9$}G5Cx3GP5*ZtV|SKEe%6>6-MSx z!=$7y2^)d4zMMC?(Cl|kkdJH@^2l!BpIR#snJzOv1uXjlTxidhR?k@HeWk z87FuhqsoQ?NR? zH>V|SkZ!te`E=TSX?8bNl5vm+?R$RlP5FgQ|JSG2#7y=r`i1n(C2Y7o;t=L{<`=QL zslj-0iC2gB?ZktkKT|&>9m4gn)d?G~8NL|dC#JAAzV?wq!{ncC_&^&HNVrjod|f$S zX$E5g9Vg4#+r-VYPiEB_h(;)zt-* zVN;VGpc*-PE!=U3rGkt9IrqbmzgfUHZNl|bjT(O@eF)Aul6MJrM!;$VY9%zSXY@Ffw^f${gJo4$DHGH&JZ1I)^6v;zd^I&9)`C z^!tnB`a8DjlWA^ZVj^UTtQD6Xnwp_^YG+MeBf3$!<=pzW7`a}iJ*N7Hp7YKA=za$WY9%WGOXn?eZtR>6Mb z#YJDcS+kGeh>Q`Dax9nqML8CnP(Rj{sdNS!2(B7fy%KwTK?wC`P9{u}Ah;`8QpbaM zE&waJ$|j1v5RW*8+0J58NBI=$R+VTR0j|&d3VvVYiPemcZ8Nh7b+nD~X06rDY)OAs!nNJ$`p?reCh}8%GX{sIO+Q zdXbM6E}@QQge`rBS8XSqZcstzZioRSUfZVazFYQC?*?pXKX5@>+BwM=tPKnl>YAJF zN1KxYYfnBy4^I~8OCT{%q@||^X;nUCRhQo+idM zg|39Im;WAZ>v@03L9v#WerVm>_e9NjFsK3d@i9lNPnCwt7pHyc=6|d|P2RlpWo1__ z*Yyy%^{h55{SbP9r`wIs2$h$W)t*QEeHDqn?}B4zY?XcQ?-Yr82bqkc&MMXdkG%@&t;*>$vCvEVT2* z9PFEc3|RgigcaF6!BT8w4}ur76(SAM<|;%AJ@Hi6@l+HE@f}n{ZSkOY@Bht%Ms(a| zQ%E1mf7)W#MZNs8$>k@R=A*{}fNt?wb^%VP&!{U=Fir{X_ShY*6BDEBzf16|+y70Z zBltg5I>MjYE>=N6vBK2?do$QSJ~`8zH)W4hSr6IV=>ToMNIvVwKQ}Znu4bWcD}b4y zbDdZfP2B(E2$dTzQaibDIv#%@thHdXv1Yf?r}#*>Cvo3=Az$FST0LSk=m2hqcukkf z=F0{dYyL@p6}+wV-=rS$Ax$jO30CrKZ)dpDalHc6fC^=XuW%dTy$$v^7h^I{BRqmGVFWevLk zyZKiY^&p;jKxA#NClO8hf;5Yp5b&XpQHy_fb7k-Udk8}K{44|#2fhP@Yp=Jc)0ba8 z@tq(^@!+ufv~97xN)md@v4PpD>BRJ)G^vDx_X7_x)<~`V6^Ve_=*<|I}RhAKEJRaVN+0MXmaj%vwBON z-Pqmva{20S2PmtzR{KoZB8U*NiCVD=7^13BtJq5&;I-yvRhhxh$$LS|Lqg+4im(nF zi`k|I#zg+=W3hVuh!bQW55xNOBRKZM8W~q_cR9~hwGE8+r7~$j!ADqJKj6{CBD$ZL z2Os#3Ffx)q1@motYjZPmiJk3d@@*@5@?2zWUI+E zGEx4w(6^(uX)?$~K?@`KK%(af3<0&hGHR*4EatfMQsJH!Q{<8bP$h51f#nAQ13B zL+-}o@5pn7WG=%-8?$jp)!!a%Lpjw;uBfZmIOhx}CZgxY%UH zeOcK6xRaQa$8*^TND;ZD5{qn;!0B z;*1RFLreQ-DPb|u-Oe@Mm|ux+Qad)$pyNt^y-0e+{0hz%@vHNwaL%M*cc84>pW#`9 zKD4Qsw{L_OuW1?^6G}>+5mo*W&oVira8=o4oi|~-@~?4hRsP{2gz$YN(qt;=b`@_7 z1$)JmeNGJ0&HV7HB0VSrda}NJoEj^+)K5Ve8E-a(M{X&*m{asqQv)~?MAcD0In^Bh z+PI)%2!v508fO<;j|=#m_~Ex_IVTcVCU7g`*$KDK*VB!;TSE7O=&`t4YZNK*Y@jLm|FbkE0g+w%>KMUU05JAg3UOAi*7{>hGfipO zz3nh{tM4{`_{WzQJU+N}2`0}mc2->}%`$hLw>briyR4LnQBEtc$h9g9@T$k&LEN~2 z@;#*&(h|3?NdWhLR&A$6u6$=jN0;P#vDx8fBf~i|%Qhd>G9dwZzMgT^1ujWe`p&M> zv_=<&nd4F?f=9gCKIZ0jm^OcW_$VY|g?z|s1xLM3)%bv1AzlMLGEQRX3W(F3%r&U*$-qC)Pj01(ivvqi2uFp zhzQRUw8y-DwP-NC0a}w=%omy?P;P5X-(2NYYi+f9FT?|MB@c~d7EU;$zb7Xr-xCbr zp|!b}8X$Zn0ke4PVOs~P?rd^!4}cfAx%luCnMR5H=o?njo~%zbX*bi07VN;F-GzLiNF5zz zXl`!DCb&^lxvTHH{hkzbXCdAaV{(4rywv5FtDwMnbQ!TqQu&6Wti7E*5HftFci)(bJt@zWrzxsl&Fym`ZU!Spzzxk#WZ47o*^iK=+* ztxdO7Ld^^BJ-^{OH-)Nmqn2uYs z=Ryryt|^npxVw6oSXwL96%{XclF>8h&-f7huSSCYZS;KI zWP8C>aBk2X>|cCP_|!W-bJ{!@vcDkzfjyqX6b-t-HCQ9l@b&#W$ww0!CHb^yx-Z96 zdO*o+$Hb_y!#(Cw^DwCX`XJ>ce?_7tDogqR#d=YZl-M)nL{vIv2P6Kh6v~7FFP(N5 z{jydBO<`NXZpNRqPvg=REpD@Y{lk;jK|eB<7AXli(%aUz?x z-|l^<1BbZvabJosmv)5j_fMUCC8Hmy7LmQj$i6SiO_vW(C=eG|-by*2&UbFLrbel; z^_valYp%uOuNxSHVq2eNQ5q-IT~m6bm;x#iXRXZFLQ(NgbFO ztBP)GcNH&6ax0lvJT^aPa%4WfdYU3{^!*XFM9)HCT}T`1v12(<`~SIep)XGRtBxyY zQ0STpM*0>ptMC_c0V;)rya^^{Oq0+F=!7rE1x#_6PW(OETEYrN$R2>pY|Xa(zKO{f zDbBzhfdY9)^=?`k-IYeKiWL%VL7*`~p~BkUrlr2irOd*-DW>{Pa(ZBG+VjWsqL$XF zMX7^b0@TbH;_l@ot%~RR9@@xq{C+7j<}UPDn7J!hYzNY33cbNb4UiWf?W1_An89zE z6ul0+G^Ab!pZ@r5rel{2Y}bKldR7LqX|{8N9Np)vvKgh`o(q1<;oqgow%L0e?ib%Cn= z>1 zd_V5wQ1C9BsqYhYy#<=~i_3A3@0b8Vv1&V#Bn+%QN2ee3@~;&;;pH#rF4;@odb^p- zYvy5)q>=(^A-1HdDL#6tx?|%NdB~JQUV~~sY{TJxB6EHtzDa7wFivW9P!JJLWtYN)!vBbUx(MyfX<;4~cziOc=_Q4tZ3>loOel=@W; z8@>t|ad=8PH83W-1TM4p;m8c0Xt~j29GE2J9R;%Dua1+sRe4R7{IuT2oE*XQB70ZD zM$s(3`-LIv!6QEE@$?Vd$# zs2D%2F#S~HaL5X09rshaI8w~MeptpTyDvJ*r}r%cRgj*YI{V17vzld*eM+?d`-ZdS z&DH=ThuWPv#UvpOLe!@^6Gfff-v=M(mC8}oZ1-DYxe#->Hr}8B`5kQvvR~aq3+k1A zQTuk}Wz6>g!P@xfnF|OpChkbkKE4d=`eeBK=bEyNVKS@OlW(hC$6ecenZD?xUjQF^ ze=@(}BBy?q%asB_{LhoV9)7EL3MS4jcD_6$5#q-~RUZJLfv{2WcQ;5-eR7~W2Wc+o28{pcO4Fo zNX6}|Xl7qT`KdF%+uUxt{M^RJ5_5z#dL9ddWoGaym1~^xCozQ;IP3nmh$gUAF?pL)V4D6`d{;rI{ zW>MSB%nabqKrfosd2jfWuo__54;2fK>{J2x_jX9@p{N4>K;FyFbcM3JV9V>$f72F_ zyy(NzsGd%$+rstr^(nLaULh^XVk&U3(g)Izb70%?UvvCKiF*f=S2AX`n^;Oft|Ie# zuy%LEwU~)q=C)jgXb}Ssluq$IZn8xv(~MjsqNoY8%f$5b+>Wf+mEjk~3&aZp6cf|x zKVtDp3s5O0^T%wsHOt`Dl;s5@(b==6GE>+GH&|QJ8F0+@1)wYZ-S(C3!-@9(*fmw% z5Gh7(B~Xn%vonaxk(@CVT)Y@IWu*JOEpUYKE1Z}xSAqNp;-^eK1_lO_9wecSc8|vk zg?%2c0|9{SXO~3SJmaId*HC-1*~ByjzIA?J@9HzS2e|1Aj9^UU9w#bj{p#NI>I4|v zPDaqkzyZI{nYqtWR%kp>YHB@z#+1H4A*%To))enTxw)K&e+4d1n%I8Zsc%UEKgYfv z!}L#M65Tc&)ea)QX>_rxPOiV7;>tZUG>EOEDD*72 zl;>@o&1sO?w{fz=-Jr<&V~{J3n3X#DsJqg}$>{*%7P^j9xA1acNS4Q}6-UV94#$8& zE5aDNQtZUe{-U_ak7Tvs{U84Y01*P=>0BHF2V0ta$PO-FPH-uIU2384KV+-0LSCOq zS?G}9sQH6iU(@>}b4py?75)lD@Z!E8x$EwuILGD$po2Ee+2nEV?F(CiDz>2B?ug!} z;g+W-s6B$;HoaM_1?DEK^c0PrehDbh>3{4~`w=@m(FQ~rc3nPh3X4Q|455X)V;lk< z+3fgUZ~xq}e^>X_bsbno7uMYa6tF9{Mz^; zeEdDk(7x(ppCuMg;UE84CE#9pgZGK`mT{9|+V7Y|C%nt|`v-DRdrk1K3Rx%bTuC@5kMpjy_L2w8q~VnkBh5nNgk=upO^baC<`pqJKSUEVCkk>X~F1_Pt!g+FstcoGY29$GIDARj0Jd^qsD1> zfy64S-Cf-y5I$&Q{C;F$OgMLwHtBkS{poLN2?J!R;R>BO*)uUQF+MI0pph!sTjK8< z7RD87G$bnGf%GGA&DfI#yJEKznTE~>EBOyuC;59X+GXF8EYC3ZKDmVSb@Q1P%J9fY zd+)XN`!@WYCS6HJqNI{-5#=lq-s# z5^coxE89JDaF{3YYt3H>E(F}W#5^`8_K@x*a@`!i;m_tn$1$SGq*uYB9*^g?`-a>N zAt)P375=a{-&z4UKCS{}qJ#hjOj+0&k@^C2(BDduH2FVYX8C|M?DZA>xNk?hNi^s< zm)bh?V5wx91}~sjvQl8^e``$cuR7#gsLjuOrV1?(6bl%C-+cesCus8Z2{UarAb=qQ zlcefq3}mG68EzX|c~U1jFd8x}o%l>{%(&IGhl%n&)_G0ns4E_AO~kt1UY z3tMjF`@>50@>cS7K(C9dWoWB-S^*>yJ)MJ9Q5qSgOH&9a=DeAsfmiM_wP+T*wEK_1 zj9qJNobb0#&#{>85mu8sTkB`D6)Y?`56rIso-p1!WWFIBOehP_*kuK zf*^V3Zw-1*XmEI)cnPebV2_g4C;+-G^sekE z%=%U{Cj&3AXMWAgGc|N{bTIK7yC!(VqGxP#6+uh$pDF~Tl3%Ojs^9VOk?P&uT|m@a zF}?QgH*f)g;nE-E;t!5#P`bbQ(L|y})!SQo!+{0TxG)>)&vtZ`z_okWWeM|Pi0&xuGhq}kYcCfb- zv8W0_?hO@?lXuUkcc)mSfxoejf&GNAfk<4F_y5crh+F9>Iid-=hGVPb^19x4QUN(* z(phIX7B^%d_~b1sjWj)B3j1z-cw9$fH(k}ph}AVTS8vh6UGZ6b6!C{9FM|)$_n!$w zKofa^)Q$1}9vFFwAmkvPsvSM;dW%*hs~Ynur5Lj}#9lJ=~Vl0z(FP z^g4jn3NN~1*sCvHj|h}avD?OFrbJ+eR^=;Bz+g!#z5fV=s;uBRpVssC1NP=~m34_o z08YA}3u!uTDf*7wyTeL95JWJ5Q90eCdpOIEUt&&vahHmUs<^lqKTiYO-M~<7$cWA% z$p7Q)0&Yc70S-b#5zyWlyr8LH^I|D=&zD~n&90m9#{Yw<02dCVZ&4*vT-Nw+ROM)Q zBuo{MLN{MN$A`!esJ2FXwVt%g)52D$9_lk^(8j|2=Qz%)7S>}jj<;zm#n)1{w|8f> zyTCR&CfjH7yMhb|9>fXHKbpwXLF^t~rmumV30d>U&ORW|v;SR4=<{EF261Lu@AK1@ zmtJRGSkor*bs$WO%S@a!Ch_r<-hqlYBSIdZ4?j2$=D`-vxxsLZVR5@l3-ea-Bz-~< z$5zDZ;&&cIQj4EC)G^ocMqZi3AYmmz$3u_?qQ~DJx=*+-j8GS-KJn@2w>v~}{B#o!m?#8{jxwU&9f3L_e44(WVg%9?;qN!!KS+Evea|nN zy~CZda)o^+bf=r9Q>$^W9$xZXcCpWY-NuB9qASqruwvjtCy0P)(cp3>&sNx6n|M98 z<<`M|N{(s;EQn`i{3E$d4kbmRrhd3|gWPA*vZK48{w(A`{&c^$^xF1BOhOV-9n4dHE0ePC=MDE_IG6XTYE8%O^ECUe{e(%1LqNcPz zW3siiHPUwvpiW2CUse>Q{#$1N5yo_|IEIhgOse)d+BrTxF0~t$!yV2Vlsf_!A*3KC zY2j8Bwf=|c_@1hN)cGi?lKyZxtB3TW_f4YM+&{iI+^(?bya;j3UUYvFtH3rPvCW+Y zl+AP`!4UsuHwQ<87ZwdDcKwyb9==5jg&uMDW3R)EXu^8wq1gMex;{WnligIRDeq{# zS5bk75I>G@gI`Ob{5H_aw2%2q@xpTbYcy8g8<%IDj`@7o{xaW5%moEy{_lSxh5Etd z$2y5&5SZ>{QnX+wsE&`FdkK&47pbJnd>fNIm;}8&C`Ttc@uXwxApc{3edm>0u7g>M zh!Bq}u8PabO9R`4jwIq`e5yu&Qci}bL%|N%o#9NzC{uXUsox{`1_Qy4gxKcnXi)_W z3M{i9%#zL%nv>U0RJ$0xO)?vnkUXwoL0#wGm9%KZbH)1m}co7#uGR_>?uSuzz%%!`jnmBp*dN)pI1aOt-7#SE$b=jOoK~l8%QEf3V zFz2MAi1X-3f~Iei4#^fAeTk3l<$c=e1ol2F+g08QPqx#BG=19+LSWupy)tEe9;Gq6 z8^PlCk68>`SC;lYpFP*WbqyAhte|Mvbf zszct7;xwmP$P*uq^N4KA!$I?aL$K~a^@4h`{g+fd-*=Kt8i1l=dsdwejReqk z#xGVJxnZ)%u12$O;?E-$*fN7;`X8$l7i=Wmx{Rbc-1eV6S#aiYJ7CbZS{zncohpIe z{oH>VNU?;=0E}(xT4T?Ju&!MR51^PyH}CN)tes$I^>0i9BCrbo4NCN_LnTKM^o&m3 zwnwJJt{oPtBORXFtHo!l7?Vk>x`9{_<=s?uu!ehf2y5LR_+wYm_Q^l25+`X=F-WM! zWwDDLxAkTkk2{cXn);p%U@gKR^<&#o$L8_Yz-Ep~(tn)6A%L{oszRFqP54QOAr?I; zcDhH+#;?v7Q--ZtgJP-Fne5Jxb;BwCkGbEqn#o8&RX*h1a(dC(^=h-q-y^PH7-Fj? zeb+Kuw*g4WHo}kFZ@#BY>J}P4hFaSgGa9Pcm`pu??<|fa$X(MrDWX=+0};JG>I_*J z@CFOe0-u&;UPfJEO{|TtcddRzoRHg0H^3uTu@ANfD}?{6R*&%qYW3>eYbt-)`VK&= zKNxU|su?fyEqrzOdKr2iNI_pEPWa?#@`fnZpM6tRZ{540Gl%MH2m$c|9j8Y9 z!N;%G^u)MLvKz}H4Q^?Uc%g5n$|aQ0^U}hP4v=X_Qg<-g7FE8}Gj77H9okOBtZFm^ zqJ^))R#jd2j&7Wi1JJ&{6p=uN*1054@ts+#2biD!ru{QQIaenWBX@g?{qK2e+tE<^ zC$%I}0Di(^J97CiA|b6&p1UbuEp#1dT^e}eoGfPlcz%uBowV6$5qs)~+v`{TUPkY}y(n)unF1NqJo=SF^7g2!sK;_krE(S#2RdMp5 z3YlG{i-?dcmpmP`y)V`Sb@nWK8)v`2)lTv0d{Rfxx{%ND&g^cKIqbNb-qOX^_$$>c zA)Um$$&3)aL$Tc(q{`2Kd8@V;$SkIb9lmy3sr@u8X$Zt3+3x~njQx(~ou|p+_Ms<6 zdR=Q$=NxaN$EoDZwj~{tc1~0u9wo$P(8@liJgoEIA!iCs5c&ljS*x#}+kZj|JdsI} z2|qeJw`HZ9K#FZx?_l0eN*dSG zg;{QOe{*eSj!OrR@Gm*c>cgMFltWO!FHTeGwJ2m@Zw!QPmu6;N8(o0DNtcu0^;|B= zLnDT=ra(S(KKuS8%=;^QqN2ZN1?SZs7t?`Hb?d-Vk0wKLD2aM;aZw|CU~g~Fe|Gb@ zyM>!7kNh?WJ^#>9`pGj2j$h^@k0v)^@JHMLFQlWV2X~Uw9=%rFeYh$D>6b+~3!YNH zx$FdW1qQz?$@(L^0TFaJz)qj6i0AK3+fngOvDGpI0LaBkZ76t(_8HV4zcmyef8gsY zyAfbN$a0Hr8emFXOkux_M_x99MGDclCZKD2!W`_kkj!tZ+`Ea6U2NK=Hj|{?wB7}Y zYbKlwcRB}}AOaS;Kb>D~DTUtTkO-V?dkr*0fG-W{N*(=aawF+o@9xPvnX|jzd6Qm2 z*Rlv^xnOYq-23gB!GE^jmh6T$`)bulD`?XjAD<|a>r5t&#l9$R_E+h}z8DNmxui-6 zU)d>#hU|BPYE?Qq3~?n%&co@-1oquIrdU zES3A-yK3x8=x$m`-U}!`c+y-i z@J?2pw(vU%cs}3;HJ&m2b!+FjG8mZ|-m6i)wmd#S)cF!;SpgP2ii(_9hw}dgpUni& zWEf{=o)7+x#JwpGk4U4;CMS@>{<&AlKLmaE8t;NijWh8H&K%*oB*{e6`bNU85=}S-e{$e7#@Bm zF{%O64>s$-)`Oj7!_WX&-2ES|Vyx3?q$uU(q8+?JWo4{SOa5z98WOPbGsGUUjvUvN z5al`*np?T^=^;as(&Go`-?n5W4i>)at_G`2@>AbFU4P%=M=*ZLW3%$<`qkgrWL3}O zWXcBF_?-F08JZOII;rNwk@eH3TSpsZ>5A9oMpLTY5HYk7-JI`WT35~meQ)~b)&JT?) z>et&IG(O6dC2#7rHH8eAR>@1vJa?clF#*8O_@n*xSIUS$$)JbsMZ4iCW&u!+^}ukA zBz60JpMBwt9-Ww28xZq9ZhpF)gn2woDvxtZbNOu;r3%{O!ImP8{<&@oJU{KBSHU6E zP&tB_X^W>(`sKz1C|QcTY-`FPnA`UvOvS+zhFC{ z8V<y5j{`r5|lyvJ~ zN8GD@-6j@Ee1?rA5#%{b0e*ZE;LXT_aFMSf#4*ERVD+pF4*Q7>1Y3H*qVylCFP31y6#BL|MQ-dxL*BTo9 zOuTh&F@mOqowhX~k{~8g*Jb3)3O9H$3DzVSs3}7wa`OHwp#IlRNAtI#ausl~wFp_l zMUet?8WGV~Wqhyf>8Mi}?#@)cFKIEXB)CHo>D z&4@AB?e5zbSFrdQ0Ugf*cW6+_${*tnkVwzn1uzo<1`4hK|J39YmzBj%d2c2#Fkt|q zo_~PIlbtQN<@?9)hY$p8Rq?A(&7sHIIv`Feactu-o84Vqf&v1UW@aNG`8v1Nq4n`{ zfUK=&TH##`-?}N`K_JBw&D-f?Rxbu%U zY1`=eqb{<`uW3&A_yjuitlcE4eMSH;^6?L*(VzrlL%ioPAoz#R>TUxLr#>e@ z$aw2blYnulU9kp@>HYD!mP8s2R_5ZfqU`SF?(WtZeAT&LPs?n@qs+_ro@SSnpm5Q5Wy`PTa<;)bM(W?Ou#2ur46dml5oR#N$7IZhKk`ExSt5g#_NZoYcMO zT>1ETCj{RDG5mB(zPRwJ(p2yh75J9Ljo*c};JwVhFS~lxPAOah+GZcy<^~2d1>yV` zD8VWyz`dN0tk)_AVTNq9`T4FD)&qLK*dD5HuQqLTe-!eaS*=+5c6Kd7?#!dKOshi8 z96d+3A7m~KhW8-3&)A&-wWS`+{=VGehmI+B=v*5e-B<3M(xQ@Z=Z}x~PSg_VV;M5q zldbZJ`?Es_DU;1CR)uy?cB4p^+z=9Z7KHyv^T~L!9wox3B$$rP5bh#Ztb=QR`}S=X z9qKA!Bde!sF*NjN(cRWsV?_4JDkhJ%{$qrcMFnIZ;>_zOw^vu&zTe)}Hke*#Hpyh; zR=Wi{{@1rsY|-?cvE=79I`C4*pZWYwN=lsG$^H537qI*OHZc+J)7;k9ro?eJ>@KOl zU(4(ZsRVZ17KzTSj_}zKD62?c4MX$-c&=r!B1s_pS z4FNhN4!sJ>&-Tsso&KV=?^aHaOM?3Rr<~{+CNg(SkVhS@A3BU#s(*F#W~cO6?su%~ z<35wR^zI#nk#9HBvpylk*77TE&e=a(H_SlfC|%*BN}lJo>M3gXi*L^o@Pql*m;0jz z7z8Z@nIt8Qh^rhob1ej+Paz9k(-^n6|2aNh+_UAMKZ2b)Mibxon{je+e9<4sCelw} z)?bfTw^%Sn47<85mZk_BKN*cEIP0uMsPnAqMB7HX-HnHR#_=DKYjAhc_m*zS>_*R&@qv(B%$L-f{KovlaXTw!WmQD3K zgC-n`fw#^l(bLnTrlS@2XO!&JLf**`*&VYZUvga??0zF8}Er-8*sTTY&$01_*xnp?b$qSqHE=l41STO@u09B{0SStpNP&IZhp?_ zqF!z&v>lA2Fi^x(*+`OzeablOQN+NAG&C;?+) z{S9`w000mK1z}j!FaViB6Mbm7!qL-U+Ovw1N_bp7DQ8<+>j9fX9v-~J2=q#+S~nQ} zJ}JVtuz2}X=?AXRHso!0*xo}Axa?=%G_Jd2AS~|rO_qq3`JL_~pE_NEoayL!Wh-Br z$0a8PuAoT*=B?{L$U2W=%#qczUsk2rtMXDx1U`R>o!4$5{Pd;)ecgGsFgwRw}EJzTTEM^ ze^TYD?I%J!z=~PHuxPhbeNQTCYHIu8#T;u~D4jw;d|WejwlDhQUWh`6(;E=#*dmlU z&LXEbw>{z?^JqhHosj!%7gm0y=r|-P9LHm4-q^2V_9yCr;1|N(y7?v(*U7aA9nDtD zvoiQ@&G_fQ_K$oTOrM*Zb3{K-QBj$9mfTAg#OF~a4~AElF!Sj9Ka*^T)HwDk#O%&J zWIvP=ta{#xUJ!Q@i9ALeJx%H)pmQ%6&KR z+-Db|PV&3p1xBGBYu^t1PaxJ6#vf%W()~Rtjad9zO%5!vc1P##10|)>+?T{+1FnJ; zpF&iAz^RfWP$m`=h!!G|1t@RnRs_quy7lTGfR7n=Ppek(Huzc%f=kKC8JxvO_GK0Y#-bnuY`D|l=E-YuEb zBXPU6X+vimJs!6~IH&1N_QFu#6nGT_883wHG`SmYxL07f=QPq-B79ZA$l zZ*`W-+pW4WG+LGJ_vane*Vm&~hhIRb`>II~@!)Jk;qv`tJ?$3j96iq1G|;X4RDl3* zDZ&_bH=rSTdK1oMQ$6WeJjy2HvDHLxa@_2UN8oW&i7(;&DKBe9_MjCO9KAei^f>Z( zTo|Q`6o%l;E|tRYaqa~qW~dgws~Y2k#9J1ytx7C7TL^+L<9WwOY@GTU;|t8@G#jo% zt^<`Kye5&aookF;LwTj6CD|e}`o*k6c6xr+5#DNHlCRUt@gKoq+~>gdD3ZYP+?K`2hUK%h#*0I`YOi zyAu=PzLvtWP0UU;gX=-HKaW)JezlIma&DyWjXo_lV}B=`J-!}eClB87Y*^RR;z~p4 z%o{ooELV2AN5nh2^!JBXgg*q=dCU-puL>IQM1YHl5;U>VM!@Kpr8lg)z@=9GIL^uF z6Y@QbtOp!XFo5jbR>*qPI?-8wFX2d=BvtbNoJ)Boa(-$Gd;Piq(wz2eZ-16DG4NM5 znCy~W2I;lkr;-SrFYQnpE`>yx3dY`ycv=@}_fj^Mtj8<=M`~nKQxgJ-^Kx`7P`f(k zEU85bmRuWuex2St@Q?xd@aOZahl+80DNVi{V`uQ|21yTz_rMk52kS!n)p|so%uaF62HTW9<`%2GF2B>8yL}gl z&A)Dg$E<@zIRbXvNl1`Q_`~K`7F$U%Z0!gJC8fQn6?G!tC8#IGt(%dt(dtJN-TV{q zFMPeD*9oPi?ll_jj2L|3VX+?3=_i7mZlX^Fi%UxOfN}=mG~C_Gz-jCr+24o*N;PeB z-@hx}WI1y(0F)mfJc%rAZ@(}I*1QGh`w|vu!;vGZMdUl%WQ?X=OwppuVvBw z6c|_%yFj@-*zNpDU4Rah81!^>nkdmMtaz&h$9cUQmX~{J7H??;ZknK88oK^8y;$y& zq#O!PML)v(^Y6-69Jzf7*Tt*WE8{B;JMc>$zV!!t;LHdi68h29^#hbwHuzC;ppnENaDno$PydLgy7_KAs7`-> z%5)Pz?x;)|>|z|0Jn*UoGsR(qNegz6$Kiq8&6~RYhYGSTf9fnU7j+G`x2k0*DG*cT zs>ynsBbg3%LNKX)cal}ad;0tPKYsl9yMDTp+6xZw0K#Z7mh>-2J+R>o;{M{WH_eLV zC+k7hVCvt#wUKUhR9{IfM0{uKpWQayWIT0(<3lSrY4Fuj#ChGC#WZWhdM$9i+;UWL zRod>$1N1L{@+a8P^iv(@VzROkPs6byegRrO%(j~@?y$9omPO6#_V-mHf;ZC&Y zQ(FiB&S9`yN`&aEPl&5BWcez=B< zs2_}ik8|87(fZm zTr-LM*GJu|#7TaI09YbarAgvY;NPqq!?XmtPgf}*OU2F2&GF&hbq4AaBp}-Xm79l# zT#q@%MsP)U6DNP4joevjWyElZZ+ev68&HgHx$s5D#>Yq5$pfLCrNQnUevvHJ zk};L@T2H7bTGb~a_oro^UjWI}E9e!u&$h@ZW3{X^)BO9oG{FTmUXyH$~i zZLjm}3~>tAWqjd{Id9_ZtUry*<>MH|<(9_TWM*d&q1n6fM~z#)c_Kwf(TfU*YB?tG z3K1G6Le@q6tuU3825zqC6P+$id^q-{rntC2OJhm|#L?)@Tze-+KEI$a6jV&=QVF~K z$(d2p-DBzmSb}@1=<7Y=y?ph|vuD+f7`*F5)=m>+l-IZl5!7!QN1V(zKR@E`U)}>~OE||@ zrzSRcclVgV?h-RwiVs}YP`1yJwcGIxS=q3F@`%khXNY^6g z0pIUmE$@T0dH?iLPaq;pm;8ma{9I$W0`BC=Ro)?OpT%zyLTe-n`2!QU{;m>GS4PQM ztk(nWOY7)E!o{3$9j2-(Y$Sd36io;?elRS(GeTNjmaAi6Im-w~fp&AnY` zNaTAQOky*lATNCda7qmG&DoAR<0Jrv*}o?g%j*oDGMt6>Cq05~kAEGsJXk*qv_O=C5gH9~z6^1a1|` zZaH}&MJl?uPUMFh4ZYK@l(XupkvS6y% z)^@)nDn#KSaf$K0G{mHmbh|AX)PwiHb<=a2nAXzjY7AZV3yK}m_}kW-f@se1=kukx zaGtCOm>)RW*@<>hM{7ZX_wBs^j!<9=*e?Yp$Z&6q3j4+*V4Jrc!?hY7A#7MS`2Q-X z_9PdcJ$x9VzE+d5yV&iN41xAK@7YcUFX)>Mu4U#c!qlQfVgmyMkB*K;M@Mg^To)DP zwCWkPcXxJv!j}S+|1aFWy>|b+lBV*skF^qI@}|@+aFzz$Ba6{(XU=-xU1Lw*U?iMn zW@cs~O?032n%1C}d|^4+nkQ;HVvzKUcvhg2ymO*cLqEEpWlJlJEI`WQVAIswtsk4U|_v1oH45JvmiQv14kU^O-Vv z{&i`UPP7<0Jvp74DM>b|yTcN|G#Xr=BgM`-Btb{z7Eg#|SHc+2o*hhBqvhe@DRhad zvR)I`T6QVa)ue}MBU$2LGTJn6hqyy1vl?$`5ry3rXUQ~Ek0M!8xCG6hyo>~grwuXY z(-a-J{?waqedjsLWg~f6#{~^A74W0t=;=zAOi(jrX13hR-2e>pd&as}-d6lO+uPfz z$`MS{x5Swb4IlXK1n=#|4cF*)ByKV`G95J1wA3-Y1pByo!5{8jVT-V^_GdjYq``aT z8(V|sy%Wt|k4ru-f&1vSTzq{fY~>G%6~c zVwZxS)_v<6WFhNG?$YbP&K9LdzDa+m2!YzcyioV55v>#f@REFVS{Q_;-~exq9HjhG zl@M7E&8=skjHvn;aKgX#%6|0C_w|o8j8LAXebzlMTa;FxgiywC2t0JI=O*jX-TEq) zL$aiH^$JMms_vaK^=Zg`HQQ4H8s_`HoLs&8>zX&I&Kqa!Z!bo z2A=+uP+mr@W50{I$YCF!CGA#JZ&moL1vNZBM*fsFZe2O?_U3q!w0Pf`?D5OtmNj?j zA-TMO8WOSIu{5HpqCGu^)w_eBDqTg7vq+Xnjs#i6S)`R71h83Jc%xRdIQd5N_EkU6 z_P31#Fvk84{$2Z^3HfJ`1R(c&;gtgYNC0+eEPUGhwz!)=#MV+_Ry5d68;2~kvAbbALFK}lL)lai7`V=yf`=rA8k%QSFf zY;<=60m$i6(#0}M_r+Q*XETu&&AQ9OEa7QA`TlasRY@(8|^6tyaWl24bvIPAQE z4gxPINOKo~R~^NLQ5?N&zWCNCZ9vunnf)NCP<}8sNpZi@w%cHg;(Wg9wQC-JWcMkP z3)9T98=c=;41=t$$#)TuRQ{ICk2Cun%OU6Cu@^(&^n7OGFHT2y!RT&;JC<)p!L zc`Vawa|Ut7MC7ac{Zmr~NHwR3%>Zz74$W=a-QwcdWxYy@Vm6MCc1421JXx2RX?_97 z=#25#b!jun=VLn!nIiXz$aY$p0n~y4Z49R5^ z1yg4*Z*9j`Z^Uel7AsGwCx}ey%6ERqC9%;c7~iWwB2A_=XHJVtHg%Q>Tl*uZUjy#Jii;x3Q=KE2#4p2~>{96!zs@=VfG#301 zEkUAbwQ}mepg`re^BZi^c@`}YBO{=5tI?;;a8%%|!$$}untMT^`n<{S;8Q3qKrb6G zAltF|eI?UeP1?|m>54vF-_$brTVG&+n1GY+F=gPb--zBHm}+siauRaP?3V;M&L%EE z2eVP?P9r}p8iaWGJ0Rz={2FqVq5g5__WXx?-yO@}+)B~MG<qCvZ zyg@AT@K=b4$X(4Mf7lI)?nf#~Oq6C0QqQ~IiLa*b#uzkeKYH}0@uzcT8k%vJi_knj z%Zu}%7}ChgA5k%d$S<3e4m{|bBvwzKpG`Zrw)3^lw5eewm0kfq^Da|vwOZJ4NUgHU zT}~5s`hGMvi*j~#7~yosyYQ!BZGum|+c-)g(j~( zpKgYsYze^#-Da2pe36gLgt^_&cZF}9zjR^eZmv+aOcuw$Tz2{+>>qldb^ z{)5kfno2ypicaBn{$eB(p>i7NzPR#!cC_6k7Xd zKGdC$YH98&G8{UY4jHYU$7uVvD3$inv&qy)azC5_`1|p(PoXZDVl?=#f>8utbR-i9 z#c8(5>+aQ^PgiRt%kXnsb?0LO=4$#OSJXYnuFb-A3O3f7Q}~^YPmC_h$6pK{kW9bXsXFpTKmiC zk9Y3Ha0yuGuEac`_czwn{S+71Zw&(3kGg*ROs<6JPvmW*^kF z?X$*4lY~6tGy5LWo<(^L9?*j|otEN^eUCikTvviL!0@8?bA*$vI6l;u>w7+6k@dQ; z&flUeB?IAPc2ZIK4+rvG>yUZGG15N>H|vcLzptE+44rBAkB z`FOs8GA$^Z4|}x_=IW}+e%|NZO1Eh1y;~}!3kFfs9<=g4y)U+2IewR~w7^8^QTf`>ArI&NE}Q+)3D0O=of{G@nT^s+>TR~`c31=6 z=r}o4)%x}}N?pIaRyfay*sEzjTF38XjZQSy$-ZtT>-Lmpfn&kUp_-ExBDUcj*6$G{ zaEIYE<9RdNh|JJ%Z3G#BZGMh+>iw&eEUO{%0wh?lsnPs7rD&y_D|o#fmBf}?Xx*Kt zc6D!Wv--akKm5HA85?l|93ey|aQfL&N2Gvr&PgtweWp4l$DGI#J4n$kj9nH3xiV( zg3PR}zU!sKq4e;nu2ocyZ&Drp+)_#`@c@J~TJ^3De zi^^MB`z9n-g(Nrwy75c$Urw@*edbOi)wvpxYYcv{(Y4(%6b#Ut^{wJ&)6!eOXV zFn_rrydTcLF5K|;?Tr8d^%Y};zxJ?y4C&baB5@~3ej{-YPnUE)m4;cBlzJb6D0uVx zpJqb6r8bw9#tC{Rh_^7(YWbC`eC3>C!SI;*4=wLK&gfF~!!>sdcrt@-Z?`|p^J;{J z=iIOI+|7`adorIYrG)or0bxO_5a54vyslYyPijU-9JghC$@$*12%58VK3BCKUP*fB z+eQ)^oZ~6-<=jzC?qGbID-p$IrmzRERBe^gv;DWf??J-8#_wTQS{6y#dX0@F)CY-{ zH7-`ZPF4j4vac}(is|N_U-KtzG-gG!V5&oN_ey6}eiu()zdZV8&(Nv|xW0Cs%y4A^ zi;lr=-8e%*IFNkAV4q;)?_B}K1tJ!t9<)skENGtfcCbD?I4d%bTTO*n?9-5mefeOs zp(6C9Y%w=~v-^Qybb`@5w8Jf4eO*ebN?#tl^C>054f}d*pZ1kY%i!3G`lak;lX=fp zFcf>{^u=8;8f)s9!+D}6VHxp46K|{Ys(^2rehz4}`RX{Ax_q~&m7RL*e7;6}%Dghw z8KaNaet@Q5ndCRqv0-9I2}WD0Bi2kVDfBMFgV$UFnb`ZMgLt)b2M3_&-8mHeu#>FrhTulxpjK}YoAQlgxRpdW1Yu>m5rYm=WzMu#U*xW#Uryd$_~Xm7l^ zKQv;8dcOCEj&7CvW8xAH>vFf|^GYT8U`jfm7V4YU?D5J*BRl=!WSng>0BFII#0!Nu zFpLG|fx*XP5s zl!U(YAuavAf`tu(UTXF??A1O}A?M^XLa9aCh}kMx*_a%8sz~00!cS(fSW+M4xhAN4 zQckmL6-3;(@&>Ox&_)!-YK0}#-OC$cD-$da>Jx%yWcKQ?|1AnO?x92%PTdt?pbly@ z%d-OGq>pWu#d^z12-pp+GyZi_=heCN6q5mTptdUH?m6Pvdh+{;O0-LOJIY85R)8y; z+n9u^BXccFnM~|U(}>HaqM`SkdkGKo*9T9<_u^=X%HA`8N6f^F_Q)x3q>f~AToZrf zWL$0zd+8lkpGE(6<@(e5}x!|f|YKS4lj~~L)YoA zGbKB-94%po#Y|l9X%>VB5(OKlhGuGd%fe~j$Jtg3cWm*60=(#z+F0&v_r=fQ(+cdW zM*VXFe%yb-CtH^Pp=daC&%Z|KuE*cZnpj1xERyHqP29dfU6mIU*uAEW0TRJ8xAI-= zsST)yc5c1bSbUI=m0A7MY)<%-^+eD4NSt*L0>#Ra^ArGbF$|b{U-C2QBr7394)LCl zkPxrau5w8_;ypli5CC|;nJ?QOny2@8Ugon}UjvmK0DHDoR@SV|SPq7~;%j&-(chpV z^Za0R(&1grFSa0HV8F#e>*y$ITir)va$fQHENWFUkuR$`(R}jT$;&?ZFzd|VVeUS^ z@unK~g@~8vmvdTs7Pd4w5AOSNq+|pL=Y{R_(Bit#BeSL?; zJqpS`dKGj{|0>Lu&9YX(kd;QC^o2C-yitpSUh8>JB;{_+udG`JAe^!5&?5}%s8NA# zzkq6~9Whl3PE?RUd8?GQ;q(Jv7=r*s9haH$Dfz#t+i z-xfj{rR}AL(`~tX)tSq;rWdYl2TmDZvp-xLSzX3v#XhY`ZMTaRisa{m$Ba-$EC9Wpr3^()_Ld3ou+R*$)}sx^Nem@+F8pI`1 z5+!4jsX^_NWB5>wOib=_X1dSv+tUMGL!vrlJsF1O7A`1_6QL0ii18@~*v{f&DS|!2 zu3d&U$$r(1rE<**{5)|IW8&DiHZ4z@$eodf#6~;NQg3Qg)1B;dKoJ#Co{oIjT1rOk zZzMeCITs8*&u^|BU;vH2W8V2D%b~3)V{zTsO9V)YM~T8dpI44Y;H?bsulYMS858An zrlqy*q2)dz>DC8Ilo^^01OP>Geow%y4k0v9X@t4J0ZdnB{v+7>` zgaYkKBnEF}+p=kRs|oembtOAXWrRVwAq?it2r3u~6Dp+C*& zX?Wl19&BmwcCc9Qg;##oxP3YAECI)KuW_Anwi|gD;TN&sDph#WY~of5Z5<~_Zh*`u zE*?m49(Map4w`W_)mSubXmtMKC)907$u4s6gyp8T-fsrX;E+jeb75rEQ$9O;a;6*b z4ue+cj#}lI+^m0g?bro`$2Dp#mOMgkBS&p8k2uaADgo(5?EqWE)MNMik;7<-$2q?9 zM_cWNM)JDn6yzgkY`(v3*OV8@;%43d>Ls|BZK-6H0aMT~7>V$r$9j!Jx6tY>=WMbU zGhjr)C7K#fvi5B=?Q>LGEK2)ZWFmb?A#d)^3vK-TaVRCD8qX#Yo6>qBCWdF9rFMw1 zdbQ2^Nf+!QtTh&Rf;j#acxeCOamq zce!QIc(0g$^a^_nl)bXH)txe>l;n4aG~eWC-!E;sFogNws5SaNyNtrzK?pIPU88~<-);sx7EX4 z8$Jx6rGN$&+|oRHCquTv&}%yK7QQbk4S^Z$=D|ah3mBAT_CMi?>RzM@BpH&<^VKCU zo=I%ks4 zUYaQyR2n-bj?1{`>_*ATx>BjeS>`Bz=^6@~J(mo6&r)zd#*n!oT(_;{Z|VQi0N_kt zowMx{wpBv}vU_iDT6a%g>dFdw=u(P){c8a}-GMN(b*K8d$SIOpixm_3-qUw;I+@fS z#_C$g#EC3k{1^CX1V|A>F89YHb4C4}!)Pa~u&q>PlP*!?pW^;7j_eA$^lk$Y(bm@1 zv2~}Znrzz)vnH1f^EZUl_9f^W3t_tQMC;TJ5nD81Zpr!_J_n+%Fc{3;ovsDmDMrQ# zv5Z5`9-w~&f&KS5tOMT!;}6fhDBCg&{Qk_^1HH5nj8Dw0yw$o3R1m${c{^wOkT_r4 z(@Q-A#gPvKMLydPRhWAf>JH>4sSLx0hBX+kd=Y1`>xcz8cNNjoZKXx1ud-$H zMrg!LVK}hHPFee&KCM=2+pcQEDIb#>wvK!RZ9LKQru6c@v);6agkGGp2|kUG$=!?` zU|4~|IJGg%JX&$No0L}X%n+8;aB%f!vm@OQPWk#dXALk;>7m2$Y}l5re!Fsyi`r(9 ze!i#GV8wM5XIlEQQ|^gKahx{g!A_JH{PYj_#TNGUbS{QoxXJ$B9)tQ(ADfrxU<6yi zP2bSP2cb)CBsM-&l$_TL9KeGItSY#pJed$3PKj8|J~@fI3&?(2%Dvm)-+u@f)Ponx zlii{H7oz;8&RU)deoBGN{M_$R-2Y@|xQ_yvG!58fyHVzQJ*cCMf4bP32Hvbd#zqN{ zOJLNTu7i((Zzzz3kOF`M?xRR{nS6WF->D9(2TxNZ<37m_m-X7Sf%hnqT|4z3kQ7dK zi%j4I*dmOAi{B! z;TG9T;x@SPZ88o1B6gc!G8ZU67i`p&0e;k&1bV!zj|EgtAX;+Rviy#VO`73;El-5u zCvCuzMfvzO@tzxT>xa?3LmNLAABW8l9Y#k?gfGo$vpeO+Ud|Rgms4w~-nR!m(+mVI zZ)3BCIab*?48nL`W7OEq1LQbPzHtR_6!H*-7-{WJk{7Bx8+{KC&Hy~5;5j>0@;h2y z*_$uze2m-p?feGbh!_cJXzp`9s+8j%EP-^&1S2wvoQ!t?-@*8%3;RRdKiwGT|8!%0 z%Ow|1&hH-GO7Rn?TBRQn$+LUHcEwU9%G*;xY4GDk@~=1Y4Tw%>pqR!#w=>yXX-!w0 zcUKVeD0tu@EiDZMKZCr_yEUsmun0ttM_)v=gw`T~1Q;X;(pSF+$&C~ds{M`0+{If? zh$%-)OUowMoL+6rOHyd|1YkZacCk{oe~&VMQCmAEnPa$aEi7_M%W;Jr6xG?{&dbV4 zt(Vq^S(9QjB1)npL{Ox*ws|8FGJ)G48p1m1ug~j7rn6r!9UivBGO_On=;zo~D9oe7 zQQtfYpgriURso%8y|Q*?jo~Q8|DDYMYl#*2jr-+44HJs;WXf|5gyHnB(D|C#0G+J* zH|YqlF8%%e+ml}Lq4xId{~yNQJFe#b{~u2|b`esNveQtaP+CZ#NZNbSE?U|zgpf+8 z(~ij_TEc{v^(0nbNW4A=TzeI{(OJ^ab4H#x-M?c>pWkN=i_l-kGRE%@-V-| z_f|;&BrvW;A?RW;y2Hg(wsOg20nQRbi)m42`qhJ#d4OR=en^J=15-WwO4U9mKE_U} zDPBx6wt-#x``}YA9}D@DrecTf7wub8g9j(noNk`#erEN->=-s#1&?hSl$Sqy!{S|3 z|C<<_wLLU*UXc^nH@()8F4rGvzP)~Fj88ZbrSZH8#bQeMxe9Omqu^K`cF#+1arohV~D1AG+ntNxPl^zEiJ8P3J7@B#feT80v>;|w&eNfBV7gpA3G zTix9SIx;YAfkH}i$ITZ{V)Ww#<>^IT44sN#ea7L`~dK9!2PZ^Wg7Zo-sl!dd%tH#01dQQ{Sal%+V zu`#bSJlsDZV#>(K*J8hPbn66l6@9fOj-s_*!`<_#AhOwaOk7UjIZv&{;#`V_92-B4 zllw%88ZNPR;_qXzLfM%(SX$$bGHCWAAK4<*L^6CY9cna9tmns4_5r&XYmzwB46NPS zlNl-R!ozP?1q)dad?EIKKfZU$dYpr2^Si1RK zq>^~QvUfaY9Z6E_MG|WXGJD3{C;m)G>xv79-uELvN3MR*ykN3*QQKU`HOJFl=5hCi zIb#%*@`4XXsc7qdkeW+k;$a-WO9S?j>hQH&-JSfi$DS$|#4B-%9V zM>Clk5%#dw)YTotwdXpiGWXpag+3^ z>55&l{KOa^MM6t63Nh9)oYg$&l#FwZy50f>hAmq8W9MC%W{eHBSj_MF!H z+nWO0^Reyp14lOt#rj)Zmz5XssP!w9F!Wf!X}V&~9WZp)qiQTB%SMgz_}JN-s`mVl zA51^}xNN|W#6p4$(#?NN)G-&AZgw?ZiH{NSo|C+$YPI88Ch-01F?!{FhqV} zEhyfh7|bn-D|QRlIv4n}*4Ym1{V~sHPoevv{%tfa=1`-yl$^-i;siasies;zI@3vo z8D8$Tx{h@o>g)U1+fa1wS?W*A_)$A~#5*OlNvnT{Hqf5lJI+mp6+*P}Ub}AJ4Gqkm z@`@2Er`scb`bGE4UU&=2t^1Y=oZq>FGQKjV>-b@ztYCygxOZ*>U7f99@Re|oOpma~ z@%3Gi7g5xhQEo4zI?&3X{8V&G(;HJQ^5I8I7M_Y%i))^n?U+1!TkO@;1|vj1vsG5> zY+QorTVj^@uStSTJRWNeeTi96Wz%Mq zei6NX4B2yBS+Dd7UD5hqUo%t0MNKE34ZDrLPB?CV>8HD#L)xLJDSMHz*SUEe&5kmM z6eTF%^wvUKdCh+#q5IzD`(o@Vbain>xgEAYE}wnBZte@V`XPp1sKGzh@aQJos~1JqcO$|!41$t=0X5BuUQh7p^f zi`k5HDT=FRyMoB!LDzRhVGD=tWfEnDG8W2{MGc={$8OqlC}Q|6?DU)&P-*eZS$nMM z7h+&gEH_DMD=#hWSwFWS_4RPsOoWNp;TRU(4_24UN@+&f``;(yG`P0FkuiucdcQ7p z@CZ9Wx>2-D@%g+|y3hA?XTI(O)GG1_h zWv}VfD?ghd|HjD8{d;ml;kF4C%W8=&4*JhGGURg*;$I(k*T3n0uy$Q~e2=k|~x;4gndz;0p(?u&lx z9se#FTG#(&S}dTV(ZSLL#5O1##@$S#X|+)Js%7L(T4-+!g-Z7rK`ut?A|Ih|f{Eoy zF8(|(WBYB9O#)vSN~aA3Pu0GpYwL2VL2jr^>~I;g8~vncvb9#Eu#tgFHQwo_#@q+# zoWulw=XdL8?|I{I#weT&uHE|Wus30Y_u$FBji#Wsh+p;#m9<+&iUX&ao#3vsvFHOo z6OH4x90yRAy5=j}RK!{5;K5M3yi5I@i`MS1ooQ%j%svRE<0A@hPn3w{tdU)O_A}y{M$TrM zi!Wj`PO2Ca;%1u8a1hbsV4Wkw@AQzj8AZ5V;l?bP^rm~hM_Bi!2!{tlhm5#M!8Arz zV-|bqB?owPd4hV^BRLo2i}+{M3f&~%z1dxDfzR`fG2xzF*W-4rp-z_;Sd|9mpgux? z(KM!T)38D6(frsKiBq}B@7N4DXN~Zrp=sHQf{Fs3*wc$%xZ3+tE88NZN?$-xHQc{a z*<5m!(6YiGGyzUpTB3^*`R~mT5sk!Yqo;vyHGslYYm`FUn5eh!QF5y>ymTjY8HfG; z+hsiD_5=%0gXn63Pg;D_=w?Y1-J%8o@2)+rj-$NYC!%<-dJH$A-|nQEKll^Ce~}sq z=LG13w!5D#zNK~}wedWhZAzb$0>RP2IS!(}GK6zie%3uc%E60V*bC-LvLFqKkB(bQ z>12H{G?JBLXB^PtgOdv8r~NsLXg0(odc{ZMcps}6-k(N!E>MM~ zvz)aQ_7iTX*U%M=4auu^T;16f`Ou4^avj(+e&(c{0wMEIl6q!UZ)}e67sjcfmac>! za|cRox;tlneLUSsjEis5-hyptm6q-4>h5g%^rW=$S1&N?W9-&xo@s5T?^IGEF!LQn zXTDIQs4Ex%$EU~;CmY)e#JL{#KOxR*+J8Wt;{sDb{ItTH_fWjCGR&Ebk-zn*UD2BQxBKubOCscs&BjPTkHqwy3-Jd6XU%L6Cz# zBGOSq9<^V&^2@!FkZn1gXqWUw7_?5|)9z&leUiEd^f?`r zWNg;)?e&kX_pR5WqA@m#?a8M~aDw|nk%|McbXw}F85E2$Ei`>3rLz{7jm7^EMw*%l z3kcYQSFZA<&vwBxHbc!onm-1QX2jt=gL%QLMUyq(GBqgFjYSH}Z19Y`ck|RnGP88= zF8ymjM52zw=$&K!81^zeJRCf#sF$az3S8Vjw9a75u1ZTwU%LhtG9}JkPsJ$j-&@#v z2V_?nZKkJGhgT7I4*f3&(@z>QoyIoU=cwCZ3}iq|e?^1*59I}|vo5!Ly0-?pc4UaG zfKfi$(awc85d5UQ%O|ZfOog?uViEM}rvkj`ce!1}&9zwJ^_@&#o;%RWSr{X4y@odq zw^s}G@qkkLt;H(qfQLO0NCH*{a57NEZ_>rpgi-{DXj8rCX!730Hb;_d5fza0Z9spy zOuSsfgSCPbY@FErmoR&gG@HP*RGY0VXY>p1jAd3GEWBf>e6^?z@(rQu=&cG#Ocnw< z3XHG-(H!T2+gW8^n@ge0T<}SrRf+W^vH`W7>)peh7T;H;%_Q%jb+b zaVY5HPzVzsS;KK>LhVM~=qY%#1+qQlJ{jgn(DUf9IrZmsH@>GUi-=eowo=hdgH=7+@ayDEI3}JZo9xD`yVdiYv zKMN5K4KD$>00CYIzhz;R4wrhda`y-9xrkmNNz1)(NtuH5= z8y@bGXEx`6PnUH6D{TO=(v^$T9Ta+oc;;VOr=Eq&#e^h%1w%a^TJEGW>4`=XH$^a>|#SSr=8$z-dgU);5V9hEl2AjND+PVk8{4*GP@q! z8Yv-HcwM?`^=Wn(9PBGM2%4CZUfcLfD82^=~53vZ4k~vVT*o-6FB+ zEHAHBnjUPv0(NEus|oE9gi!9`dw&?@rPrNAbYjQN9q)b%Fh?322LX6B!bkF3=sq@m z3|?dL;9={srN$Hes1tH~UA~HNIZX7`{P+>NGZ1V^bekT56Y;_i(79ZLC>!Jp$#OO| zPXHe%zgX+3)x^ffp0+;<173`PFg7YJ_6w zjb7tRhrecy|8V1Gw2r$8Q!$oHT_ubqyS<~XPB+#0#-Z&z{yuS2xot1Y=-zT3XbHQ$vX#4d}j|VbEEeLayrH)osyk3{;CvvX_Laf2>>#lWY#Eo@=K1L_8?H4eI zk)p)s=^)O%YqWNK)zZr(V~z7@^BXRAJRn5q;p6tng4*zYZSEbrFDKH~2+t4Kbz9g8 zGUs)2H&o5Mgl8E3ft55Aaeh~-OiI=D!)|BUZ~PD)iek1Z_fr`E$b#2xYU(~e+12zY zc$KgTxlcY7*$AvrS1kRp?{Dl}hP4ytll_-mA#So7HI&xn(u$ADdfbLi#DMKs5 zjToW3Zuv)d4T38&hKKwC;)MkfI8B)3%{xa0Eo&T?;wE73ngTh_8PiNF<1Lc=d@gXh zn`P{gyam$N8;ouR@4x6|7SzHRSG~~(S{~!oc19rI zFTc`-{$a;HU`d3RJ34HK7DiO7{ ze9dRECv`Dg+rYG6ft5JmRcoyz0A$z^>>XXqrDMPGxeJ4U&w(r6I!AqQlz%+PNBUhP zGI8e(%-!H6@CgMk0k%gMbAbw$^hqillyeXZQ z_umKZ_s_K?#*w6%2+fk|rddUiW8dpxjv*d+5&oRvhuz;WZQtEIR6QOtnVU~S^|7_F zG(JigTVJ_ikNRqDy0h#hw4ME9_P9@4$C+q!qa}~L0#9l{#TC}yv`-AsK8*L1R20-H zs2j|s(Le}0{Q|Iq#uMUvpuOw?L>(#$$Ufo;`;bg$Le}$0T5pp#EIl99c(49FXTg?? zc!$bj2Ci6Xvy8TGUamg7n-11ybC9qB#uS@H>Hu)*gOgr9UD4)z0uk3$H)4;gO^NDp z0%tn2lvLU@KdBobfunNLF+bqo?hG#pe>2J0=O~YTm0@H#3Uk0tfico=H?t%(juicWr-M6fJ#Depc(upKT1)t%2xmr79E_hk*P~aft z0VUy|dSo`gc1#1aVl;~q4>mYaGmi-4aW~x?1Rf2P=ZlsT=?w8?Juv!_^g@Ak4&kA;Slll3;d#?(0gj7&-O zF58V(mE{2`I-z2)>5;P{u2{Ez-S}1Q?e*f`@iRVHFC7?57+6>`RvIukce!7zQP25v z$teXpN1F1BJ9;&HZe62(^!_0e%x1M?wRUCk+8jPCFh6c5al_Yn8QqJzqUDT?j5cw9 z+5Ut^e$ul0QAh(iV2dA&Wi8f-0G-@=ML|^@L7S$bci_-TtsSQCZZ=FGWVh@`?6kDL zfi=j|i;p=13&%;{-5q@lJ&BPgKb^`QRmWS>)zZsoHhqs<-cv{GY$0~aT+fpA%S zk=poVOW;)g0L|r)h^+O3KDE4=G^sK7u|F=rL-;ZHxLy?ck>4-pK|JZ@^c(Q3!dTWU zLDm@na-gr~E0WE}CpIK$0fd2`MP1YLkSOAH>0O;+bW=(1_@nb{%J%z+qvs>sNTS$+ zV|wh~6UG;DZ|^nO0H@`j&RYFCGq5QC6yWMry|TRs;egi@uY}sIjD5Wu-Bb1OQ?~S% zCnybmdUvJhh+MzPB?L7)&3|f6BFZFj)0;^(+`D8PIQv+PIe;E!HckC*;ZzDG zLHF%ELdQo^?s6)Y=piKOZXw+lw}Ma&f=Sj?O77RveYAZ0bdRa0P-IzTzvVT~)vsc< z_NP%%QPF!J7Iwj01bWtv4lZdnzz1xf@>b91*-skX)a~o<_bPmoQIw#TX#E(P+faR> zFT}lgkXY+&NwhG<@DbJ3)$J4ZC8@;sDO-EUcz*&z%Vs}f$bOq`eW-I7%VC6JmaP(@ zPX28OI9H!d!Du9aU8{-(G$0^0JiNfx6F;M-{L!#1Tvb=;+WS;3Kd;Rm=-?-b z4t{h#T%5Wv_$3zHaJ{)zQtKv;rq7LwmhXhJyf&WFz$tsb%N5xk3lAC~Bcfwm9~pJR z7$ZhEvR#%sH6}`(?5;fVf99{SLvH_Y7X35JZf3Kqs$H4>*zefIYb=}HYCJ30>OTe z9aanTs$g5uEh^Y|CK%Z@s@NG5%<(lhv23Q8E9`soPPD>c`!$-D$u@7ytBp1&F8_}3 zcwtFc^bmA{00Gcfel2=A0DMl1I>0h={pc^1#C|_{L!xkm)bpy{T?cbhM%d)y` z@lo=5YCRD=wBT=N;5z3jUZld?_J=zS*oy*4{fM+DE0~wxV6G z3}dV`JIE?L&UgFL*n0QR)eXed+8SpbN;iW2p$DY3%O`Ut20C@Pd`;cR(8cn13t=?l0106@Yl?D*mR`{N=akgn~PKZITL46_4EBaYdCz=fC6VsHLugVI(Bim2X` zuHwc2Ql)H#$dtohmc?|3S;=C$QykpfE2H2`HW#t_ndjc=188c%*)WG)mR%ESCBUR# z#ZR99i3WHXKGn$P4Bvn&eKu^&>y(T&Hpd*L0uwRT#~i~(`yZP&w%QzXnO)tuNLdn4 zF&Ir8^UhA&=}CHy`?=vO{`(SRFWkm(BEkEUdp-kMnYeYvsJ)W+oLOKn$EPDT^%{9! zPoxJ%I6r4)H^P3Z-^y_HE?xi{^Jj$4T&K2rku1JohcU`cfJ=zS&@oMe;I1Y?9onhw z?A~2ewKH>*gAq&$CR;Db#i!7EM{$UvI!(_kmGrrt#uHUc@S+xzA_$dM;aS%()dOFv zje4K^Hj#DPMQZi0%j}S-NdYiHf$|oPF3oehU%)&^_n&!=o%7;q1%Q2eap~q{mS|2i$EK>$6#Iq;{T`nNOFH1z+TEhI zzna3p#54q|dGwM9li59|mV}suUhOipZ@iSZkc?KbyZ9`t{+AD9*cpdE6!tb)8p5KC z_crry-@XN_97q|p9N)mLqG6EAagJ)E;*dmx)ZoppF%Y$ZPLBTjM0l{96fygbepZw7 zi`B$@G)go3z|!4PK{a}rQyl^XmQn369{G#kl6EGbQspDaZwD6*0&x(mNsh10n1ZnK zh#c zJ5la6N&o&vq5_3_w~e^rgRf_V6m{OIpihO`AYu+-VPvdLtXA9Tt~kW9$H=?Pps#A6 zDWovC9Ug~07>~TV(h5fs)FCM|!g;4G7ao?2W~n$>clXfs;~SzYA?38m6;jN!)244i z+1D5Pmy)-J&_&0Zvs`#BpgCc)ym~HluBmF!%ab9$s_NGU+MGA&s(v z5}Jy@Yy8V58%)=un?-kTm*raI9E15C;9KvL#Pf?4VG+}&{;TdzYDsU2VyYLLPGJe= z7$)R*g=&OgP;Sm7_q|onXPA~FhSGcg>N9+se7k&yXP!N~xo_JBExRWLI!dSBKh)wc z>9**jmZb4v;k@Wg$Nz@gS!`nHCEacq(|zzI3g(H7tfwohy%}V7t1!duXL~K%ew2}r z2kYU*2NCsb;Kk%Tro>f*cOT8{$cq;Gb+x;OT_OM+h+R+Bvtd;cin^9|fi1Ov?ZlLT zcbVin5W0-o>gkCI#rD3}iBH)y+FZ{Jrl4+RrWbvgQ6}6l9sKxzm}@uo=%kF9J0gDq z)@+uOx*rPx*RjQE^v6U@KZ+nB2q2e$%2;14_vqno)cSSu3To|wUqY?_2CY3HC+&|; zWKU<3=DL@!>Iz5gA^T>$@H(1fy0{c`GdrW-%c2#WOSXq(ayC@?4*#R%vGz&)7CqTV zlw@s5?otW^X0ns`L?6p=7jtkYELbbtarlOFd|u+HSpV9vQG=!gtn^)s6gAuY{hqRh z5(0H|ioPc{>Mlm?*l(=awHuiY$?@oWcPB?9J*msFXR@5!e)zherN<1wX6$ZT3=d-8 zSTe9hsi+B}L5&Zf+ABW*59V;&Xa$ z0d?I3y~@i$dfQzC@eMO~t*v)g86Fp|m6AatTn~+HcXAYMjV(2qWRnvaI607M3PtNc#RSm_z>oyZ4Lr zBT;&W5U-o>3W3S684i5^XEs!ITddA)JK!a{@7wq+5a)IMscraE0rAs4&BRyv^VgIh zg9Ha0Vw)eYM^o7; z(bm@H&e|xaj5s)fHmNJ~M2_y&x^wQn3$6l8hc0EFREZgs?%Ltq%9THw4-Wbx{0xTC z1c=#mPnBciqIVMY5c2ZBvLIrMcEUCPTfO>M;EcuWVXEIzR8m#z*B@BVk=S&=rSw`E z7@DVqSy71h90}qLri)QI4}ePQe~`eLg|EGNID_!0$ul9D%>!uus3cbH4=CGm$M{am zM)1{ffv>K76iC@j&zlsI5M**ekz8(~IX|s&T5~WoV*el?ng~31Z@520vPz9BE%Q8_ zlH>Bn6>l`D7aqxg>FZL+JDE*E0IEey4^P@FI&M6V3sm90w{EwzyecP@3`HhHi6=3q zGL^kjTvC4UInTL-Be06GxBGtTP790yZ(Wh{UHR;5r|NlwNi|tvnek;m$K`;|Zq{8v z{`0ZYp&T7V&!B@hD9{Y(I$4YC1+CJ)M__-54-gLFXX@4H8yvKn4$6&L&Ap0hxv> zZ-}5mQ3U^|ajp9to|RJev8auj6ii()ELUsTmXVs;ml;g}7UOC|;SU%e5b!kAw>jW6 zWIv&4qObuq=G3pDA>K((tS`jVo!S870#96n5=YhCwcnF>M$?otL<(=WTq|=DW)ZjXx5?fcpmx00yH$7k z**b%#Q}R=u*h}+t#zBfqEb?w!fFu%EneTl$U7!KB=T}o>cHvnna&?H|rrn7#5jYQM z8-pjY+ng~x3;}twpKXO8=kK75_m0(|tgMdpS^Xl}Gc$U12Nj zUxF(rf1)$y99^~zY)ac>c=;-Uf<*EKyj+SU*~tN?OJ|if3~23YRL4`3-rRigjoqw1 z^z%wFw(u6$XZ-ONFG8*&GztJnSRCSx;je7sp$~XTR&d`RzK#~jz;v}NzQ?nVG9TNq z(o<8frSy#iNMfAca`(6Z;Q1`&PMlOq+u4oHL^U5iiBc{xqA^C5Yi) zBKxO3%b20We)w?okr~A2KSE8&UDpM%o*Ec>toj|ydL(UF1Ln5P`oFs7wR($k#f}&= zRWyyxKLBCbt0fs#uFzfpXB_Rw+6&7oF(Ev|j>4KpcRmvj18*}aocg=GZ&Tm7-`BN~ zPI83H5F;7{Xp}A~&=VRw`|aBsnfV-JMOb#w-l0ee0e-}Wy&Q+xe;QciL5wK7*Bt{r#l3C=TW~aM@N)mzM?M%6C!lyKki4G zRx;7_JZ#q9NmGk!R?L2`!dRpH5m3p;B|4V%wSg9Y8xZwgkqn4EXL`=|2>YyIOQTJG zSd8MfJx4gsYHfaRhU$LQb#n1`4i4FO%-^6xKx2mY7`p8^Ql~gj@}8X44>k zc-Y*~kjEKY9YtxNlmY7ExK&)TsSIK1fZ9KfI=|^(fWd_cHLlaxwa+ly{twImNR2zZ zn%LpZ<=_9oANz6xXu$u-{56@CnE{hmAtK86)_!5rjV?U{$D6MgM21Lyf%iJ?GpwzmhQFRi?k zSWg!W2jd3iL2a^MLOKPveM$Or_9QaggmrSmFk{DDF!ZN{>Yxg@G!CAzXeoo?zI9iF z+FE}s0%}ElFZRe){B2go3V-`L7&~kXV?K|tu-PB#M4=(nfUVd4A~&K7(c)^XAdmRI zt>A{{>DCl5&*U>H$bkvJeD8n2H~yX@8VSF_H#}4F50|0MD~v7Ae;HdW@*Km&S6%?Q zU~m%|?>v(j8XId2F^a8Ct;l%y{h32PT&TM|U6OC<#p&C9GbZYzE}K2pToH!x6(Q5@ zEsLcRW)6oAN=!DeEW(ltcR|03JV=i1UjT4FVs_aL=S%;$k}$@ItRxgH2rO7AQ1fYJ z++TK&q(_(0YhQ1&4d@>Y-Rv*q$W$$mr>#Qg)t2G;?UqTInb8!Cry8X#do>a>AaoNt zny5P(C@ux=1jwoG?!LlD81(1V2VCAXJB^#NqD*85ZB5Fx2Kj#qrNaLdN|CkOUo8&( z{FqzXg*?hs;(-7Sh=7IQK*tqZmy{h)I5{7isz^F19?xZAb*=P@85O$*%&2<{lop#f z?-d@2ionw?2@8(9u1XG*>SFKkDhgq2cZg?3jBG>sR}?*H>+$?UiuPB%vJ zZtg1fs|bckdzB${{Wusx6`6Zsa%CU?2f-Y{A0Zf#*M=|5*#P$uH+mm!u-r7xf%41c z=gK9@D@tP+tLecn;HP(x0=U{?ErI7!;JI8wHHDXu2J4(rWDOzR{ z(X|9^9z6P_Fl3Ux=>P&_A?#Y{z_m3r+?3-@T)X);xY?Tqy{CX)wGCCHpf;Y!qZ-%J zfwW(-RJ=m=23~YIgjmHFIj#FeH>g;f?kn(B7wFu%b?XSW>}E;}6icZi;jlhq!?ysM z+^$Q1Jw8#ui3y&Mc|NX)L#m z%RDoDSbh@)xKdx0L{PkUQUZalQM(5zrxy+0$7aQ2Sdd?-lLC-r8hU3eI5-%{&@i9O z&oEjEFN|COseCF|N*i8$b36>th-S?f(v}`BQY#djv-B~qUiMc0=lk>#cJ{z(0Eqr2 zWnh9^AIRSfW)Ol{35?z>x|K570Uq-|P39Zuu8v$%D3jK-(DCDK6&EtwK89~W2NEnFXpE} zXIb$YRw?b4FPAogQMkWIcqd4R!wRn^+@4e9=eX(`RAIeg;VAm?k z9Np;^%iMR=GRJ_7#21~o<+SoT&WtsqqC*}o8MW?d%I5pCKrUz*QgHN(k> z_y3vCwpp&-8#B;bx>+O^wM8G&OQA?kOC&?p3g*+Gra_fIWDV}}hs9ou#O&fT{N)JL zKB~W+w7Y%#eW~*VWgm6U@HN=xvkWRz5|#^$kSq?vEO|NbKTfad5at3}B55v?n(W;C z#iNvr?Eun_QcG42U1Lvfnq&Y2X6J}%XZ2Fb+u@&UmLGD7ui z7Sy?BeO6F^&BV!bl?6NSYmxbY4{F2~h9j-JpH~Rc;x8GU{U_tRB?S9L2(u6AO#C%0 z!oL9N(tyzbZ26)4lH4p#v}ONtyuv2D2u_W!1H>w_($J?1;WW%iHX+~2r8uZUy0jHe zS(pXHDwlZDX#faTG)vsMtdZ3zSm+H|w@Om9ZvfORd_j^3WslB|@ovh#F6o`3`RnHF zBE}7P=TNceqjEYxFi)O1p~HJjhR}zmm=Jaqw_xkXSqsUb$1(xG?ceqP^pGu$uyQb$DF@S0}2AUGd={OG&$~ zbLcfVjuUNKUP|=`v{FYcyS1(wmJT`Qg3QWrk6Xd?r#OB4ya%GBkgP*BqebeP`jR;XrH-ktt*b{a`oo5ZtN692Sw?YJhl(5OqS;I5b3YG~dnIR3_7 z*j}z+FRr717;8BBs-c1Vej7A;s)cchzUy0aZ+-Ga;gIUa7Zvl2XlnG7J38M& zL;3smjVO^27YCnAW5UBJdz?YPO}2X~T)U)nVZOVhSug8c@y5H?Jx9Mi6PoX3nIpCY zS}pG-OuRg{*Ld(_chPFuUPEx)|z9Xug?`_ z-T*cp#2SV2`Aj_h+KZeGk zKv0)%p`ighqdv+?qW}=R(FZRF=E-~W@J`ouiJH^%m(W1uFVa6dmPah<`z~o_?l>!A zHfR)-w>1Buq0b0GauJzqI=D#0dS$vwh6m;E2)7>dePTnI)>uaM;s(N>xieLRDyXVg zp4v)~x#)D5*6}`4?AG6@1B$_D>OdQhLHX|~v{S%tm@HTEJpr+=SD>-%9mha)8V(>{ zwx|71qy0fDcV0?g%2aB+^!)B>{av&*S$b}3V(CQlgulgF&m)C_|BM|w2#kgN znp8GGrG!I<0k8xQ`td8ls8Sac4^db8ROZcBCyiMVqE8MDI6IHl5H&v#HQTrTnw90N zkRZLBsBI++9W7;-s`V5%co>Z&>@3VfNYmq$E zqpc*6?YJq=BObWE!iB|)b6%hwmE7SLGm2A3;JheiI?4XC8$qBQ`Li2IIk{Y22J8-l z_%S|$Mg3Jb=e-1xx~G#j_7-$W6Eq3G+H^1cdRI;#UOF4KJlN7#T?wvqo{b;(K;}az zlLI~y&rj`*2--l)CxpH(e}}oWD4Sfi$V9%vG5q;c?}Xp;0v%Y>Kw7^=nij~R+4Btq zh}q1u9_t`SQss^61v@)5ykBl(hK8VxnQceg7*S|ruI6ZPM@XMx3ikE=xU)>}1Pl*N zzg>A6#rtSwyq}vE`D3c*Y@|*ZZ?Z&|O`AIZi(CGaS{@n!GusH9aPfxmS1{d75}u&C zA9ekKxU8?-^l3uQ3xlG+wl4m1yTq=VF`KZ|vTJdr^DNegtR*g72$_@FHKD$d7Qf9X z9=m??y^06*qTF0uF^qj!sTfdd{hlMpHsZJld~M3h#oAy2Qo1uFqN2Q;YHn!Xff#QSQPERfa1hFDOky)$EqS*7 zrA9+m({m(4AZ50wBSeH-K#o3FBoqeb>h*pgI?)hMPdR-0l@nwXXH=X&9W(0x^ zVL1Rf$Z$?~1xI^ya(eXYcr!OuNr_?0(9u238hn?Q*r8ql+fR?HW=MM5SlEteD@f|r zzh`SN8F|Z!zWbW3CXGX>UzlzvUgzjeNn;S@oXxs?=h$Mu--9BN41~=KSiTCdGZfCD z*0i!qgJZeWz9hp^!XEw*F4o5Hqg_QQo88bFu_g0Wp;~m4qyCcZv&O(qV7~j;j`X%% z?xdz_BuIYi69d=d@sqaCO+SZ?S-*knBMA+T2i*XC^j9SiPcFLeP1CZj7Rh!+XO*V= zc?;4S5>~a%zg{LTvKr;Lrhfbj4ha9i&=}HlyuD%p8_gR_r`?JN%cwX?N;LB1XRE@VoLl*m) zjo&=AIhFRKjOye5!>g0%VBM#V?#pG(EHno|4~rdug`%*j0cnR#4P*=N@8O0x$z7=xGS);}iwg_?tg0v|# z9IXtxvNuR(-FDr7n{|=@<<>=4gDI>~z8U_3QtRzFMQn&T(=mkqW}DCK((m_4jaQ{Z z|0%J5x9fsv?4mfwv{-6bpDM-vA|DGjgXsIgK|#mRAWsdWHxM%{$PB9;Nqa$;f?yF+ z5-egvT$4*5I4`JUa<|l|UBgrn#TUXQ6A*&iD7xtdf&|9!a2jTw&%9gdDDFc?5q;nA z0oyCEKhZ_dMKDCD-elX-wTCUS` zrISeKSj=N)!HIYkF|XCD3N7Y({KSSP?N=F&N&5kl-j$2(u+6w$RF~@IY7Z2W?~Gp0 zKvBBp|ADGQH2{+#*%oYKCk8jDKrhJ=yx;LAF=c$~2%828RhMt50{bMYGk<&O&~{H$ z1eN&t^|@7MU|J!emUs6|k~qj7D7v=G%e&ve0fn`Hj@f?;9+8X_Y`xRz|3UXA<8`2T z5y3+F%IusYVtIBhPu-?OEy~$>qpb5l+Hl@<=`?(ScbylfU+&m3_Btw=Wo3D4v(G|) zP2aB_r{qH;ox{|LX+C*P+wp=C)-0Y4cOo>f?cR`cMvl6Ji32{~lJBuG@*UvG^~aV7 z+&vXQ%IPkU!eCNMVO7Y?eQWRY( zn_etsbG=qdiq4vetTv$)^58+{H&XT_LV_(AC6>Y`S4r0VHp^C0_QfCRt?t&dkACw5 zU7IXY=|reP^hUq1ZqADMn)>nQn5;3V&43yqd8k&m#`ca0E()T#TlVN>fYBH zQIS(8!kuVn@n^zy%R8A(Dbu&!qpBpi`VrLDPw#foMA{y-r5FBz}Q zsB*qP{C25GJbF`#_fDo;GD~*q&_HZ}Aelb+XOYmC*ct=j4&U|PN=w1vU{z&!adiR( zFDj<4uPmzlAITrcCd;Jom8cI?dT@yZVAu~v?dY=|fsQG>cJaU>?5kJ=45MR4ZgRYg z@6=SK*TE8liNvjrZKus%ZQEK&7;#M;Har)#DeQvTv_qofu(!y9O9*a(K14G+V(wE} z-b{sgbueEwI;f$C>C?E#LN@n0^;byDI+esWs+N9$HS}6HXmwFEU->p8n|PmVmm6&V z%T(hEsJL}vH=t=7)=n@Q1XS3NDL+`pHj_L;rumN z3qsS8-`aKoUAK+CTL0mM|ILWQHF}4+!tqhK8>U+ITxD=quAG9l+I@3v?eC{^qZfY# z@%RxN%DKbl>~ttE7k4iVQgsF^Z&)|qIalI2h0i8@x+$oU6yo6G5{Zm3GOD^hCKB62 zz8~Q?euHj-g$L&*UfDS-|83-O#?Fxv>GXjj6{3-(STjv=geWsb`u2UuV^^vgSQx02 z^yKOltY9h>X|kQiDK9GzHvGW*Hs6%TfG%T!r2y{Rjs|Crf+51$ z0EQIG!o&jm>*>kW2u2_|kuVNNBiNkFZCAs(7p9dOh2y7qAs7;j6_@`vt${4@8h_Fn z@K}>nmaTm_y80GNL0h%lh4F=jh3KjyxlW(B>X7zXKH4q0xsjM@_Qi$PwBf~3mi99a z3fq%ZL=uvcLUJc+t2Bt4bwB(JIw&D-))8mOztYSP_-LjS5=Vw}eFKmHRVAh41ij74 zo%=(Bq)e&7&F!~0onfrV_6!r4jQ+2-=66@~Di}=NCf)-d+D|^tTNop4;`aEntzo$E zoV5_7aAdqzn%1pg&;}i;>EVh=`dnSHxi<6DrHpq6Kw+SU48iC z;Em{v{BzOJ%Z&fg%j6^fyO$YFOC|egGbGc@icT%ZIQ&96&LgWJkS_EMyMAc9=#p$hIi-@1}%kRCk?!}sawaLL(!)+F!w$8hB zq2t@Pvl1TPrs}X7p9%1i!5&=XmY|}f$WkGKjfoeSLrR^xCaX3-dZ4z}9^4SlX${lD zVq#^8HB;-lHL4q}ug5frc2!&b=1aqj-ca4Yr|~GsK|i#4)(p3cjcz)29^xU8!JoL5ZDU5+sn%^m;8qUWstyzv zAri~+K05(%*O7v$sH%C7}Jgk-o=PSuPZ{*Y2;Xr%*e68@VP5W7f@PqU{FqU zJ?AN!L3^ls(hsX1NoTZ*-w*=Kg|%hop2;&s4%C|e3S9(EdTy&GDvx8__rMf(S5*}W zxN|EiZqD*DtUZtW)Ak2Ozs9e<<2Wz}KqXa7)Zl|0ypF+1NSYarsRnTZ?=j{0#fU0p z3V4`9vt8TkhW*h8Ip<<~mDEHutadMK|oX73BY6Sjxv-v}F^pSHNS>5RBK#98Fa%}N|TbE7~U?C%kE{bC1r zcz9@OTnWx1xi_HiAdhkSf1o--p`_YZ5Np)x@u?N%m|#=H1Ojp5!;`Bpof$@kO^@K{ z!=yZ*pR=pWvk6e)xWZ`=x zi}Rb_9iP4hAaktyGv+1cr*LzL#F2SqL4sgTSeq#)mUa!42YG|yytLSHC=@ zbL_q<8M8W!rbBHYCvzc+ZBfI~%#6lz%`1W?5#P*bEENH}nIw&ZuFk?y>2&CJfT0Br z&Lz%mGc9Gv9rN4QgDu?MgXX_)%^RQ3n}%aX7|pcY9_lJ9pXjuRK8OwG6M@0(>a1I< zOWOCGHbZXv{ccUqjdjk(Y8xN-u0l5~MMQ@!?KF z3p}RV4&%~`Viq`@`PV6e2r&$%A+OdxJ>EHZz<5UaJ@ZiYCc>QN;c?m>U;wvX>g-6Q z$i`P^4l|-=#4v!8^du76PTulnfNWbhLpRW-k4X~2QTIv`XGZk z7jdK6cjbkNv%TiT{t%fhQ&U$CC=9XayuDtPH~$H`U$>I-u{=)tKGGLd$E}FE9?19g z87!rNpb|bq^#uVG>W9<3UpSZuJY-6{!q-8@uDV?Eo3K0?u=Db7BHhstkE+-huzDK0 zXK!u69%Ch~!tJ%mq|P@Hos8(np1*qb&(8p1m7AU`nJT%jF@ zdpTHg9$j^~Yb*P_OjVYoVijL)a_Lm)>~ahQF7sy&|1TC1=N!2??2kE5f5=6M3gqr} zp2>%HIib7&n!tt0`{s)Vow?bk&At)cIv2#p8d??okmXcz z$C6<9BoXuQ7xy;_sDvT&P>+tKr7W!Lhzp4*M^kGqmd8*qzQeVfVUfsh5X8c+NQnB; z58O!wV~9Qv;35jJEG)csbC*QL?5y3ajHQv$09tz|*Wd9YJ~Pa{w8rWtR|mhv&o0Ye z;XE5^I}0637XZ_WWjWGa)5evKTIJwh^b6FXnV#hK0*nuf3lcs&ony{o?2Eg0?E>dG zyz^avb88mr6RI#WyzL( zpLeB_WJ`s}(885{9lPxN64}PS4l#CP8DqX@NcVp3?eqP8AHVshdOYsq&b(jm*E#2T zp67Ya>Dx8C=+>TDxmN(zt!P_;$imiEB=l;zVG3}fySKxxoKC#snfFU0pj-S;bsv_9 zSL4HeE@^p1DZgE$Flzai7erT}FyJf%+SuF;LXGhcamZzp48I|Ae^Qd!Owr6M%ruSd zwb!p*(<$Uyu_ha*+e*c5;z<~fMMjHePIl@ZtX5lNPC0nyaZ2cBv*!mvwJEr6W7_+K zS;InvSkH1HA3zD*2m@s)o2$7;pgr<1-?2WsSA9ylQ0{H-vDA9co zjrh5X1TC*|k#E`>o{wlDJ__jcEzj~;YDOn!O0Uiq)8u_TsSR%FS8AMjhT?bMf_I=u z#a-DyBc83pg3qL>9Jb{`hlLmg?n?O8;pT2_eShWiz)aTnvqTcgzXCEIxomU1ggMM( zl!b9gNq>NPDJj<@_cuOx-m|AMW|PXBf_3B51aDxtziP?Dy?!JGrHB8x&-yiVksw2Z@dd`=Y-FtN;MfVxjBZ0e;%KJF3FC&MfUF0SB%IXO8m)8!XF?uz{E>{_-K zMQJp#rjc|=tX5S3fgWf=k(uUiG`JE&BaBp|B9~_sk8oeCZS3ff zqznlE-qd9HDc7+BudFS7;1gQLji9(SPrf0}Mep0jTAI;oJTdkC-#`hPt$lr0B;Y}K zme{H)Z~YtlvcHP%Q*k@x?4hjGKIj5bd|Ly%nYX#c?tb5hW@iGc+}d7FWG1XPaz@|U zT44VQBQR5mc|CK}6QZC_Q0uA8);>8RD}LavggfOd@w;Y3rw0HV!%eL-%R-Uxl&$Sy_of*dXhn--juVH<}ux);k z8Mc`I4EG2HGEso7LVn8FnAvSAUk`eSOHg|1k8`DJPkwl?&QQg3D~u(7UUw62@Ub0U z8K6Rh!aa8&C~AK8o|dW${w}eV3c4?4O#fMLqvaH8ehy7g^ZTaz1^vylZTzA&C8nHI zAwqH{hs6jpE+nRu*q$6!o-Yc zWp$4F_~eGQw`XLuMbIa4Xg^FbNirFlQzQs}`TBGvJyqrw<2Egi^c>#Z7FYOPgg@M? zqE~!P^JNE&_1a@v_0UU%Zr_nD>1X?CAMtJZb624vLiI_$Df;4_iJRk`--8wwYHGin zSBv^WwLd~x^-n&u>v$bTBu)3|ExjW=@!MC_Nf#Cx3V~LeC5Y?(Q9P9LyJ{^+IuxflL&I_Cn{jr6p&P(D3kZd28q%7-b_F2|}VgZ10s}v|A#> zQ3*j;apXO(e0y(>*+iY?tPv^~<`qOs)w?q~b+sid4eFVFC&@Yl@@ zwdA0wMKl}Qaf+(0FuG*<)70HtoAI76@;psr-syCWwok7;!?dW=g`Duy?#9N^+1a5q zbGa4M5R!#om5wG5oxhUt=ub9Gx>PIokoMZA!)4>HHRwyl^ok@Kk=!!@@ z*QMtgJ&O)RlQk)48E`|DV>qzF70YM5k}jmeY z_iI=DFzNM$vqv(YSE?C{zNw3Ywzz1O+RqDe2Ud#4ac$Sv4vt4~xz@13uZ5#e|2XT1 zF!9PXi>m3~PS{iN7WAd{Qy_XkL&3yL4xwcnl;R&7SBD=$VF1c_A zN}yJqp~=z7X%YGdgN?KBu#M^t2{_$@6Ns1NbvXT(AC;UQo=C`8@k#f;0K)9MGR+%pPrhM)QSohdDDb)v{d{3w`uwPRfqPC2 ztzfsii2`5f!dqROZkHlgx-PWUVDb{ zHM~aNi_@l(Cr{eI2D>~~nMgGB)I}-RI=3b2l<=NvEjzGafDa$vVKgY=v6W?SN2*0? z@saW^rs0(-RO~U1A*7KJWTc1f@)~+=K}wWWD5ha;?Fe}}%68+XHwYzaFE@~JkC?XZ z3^$ma--mk}Vyi(_mv-fP&6%M6KMy@NZW(zY20?6#>u3J4i7g$rLNzQ1Puyo~*biD75w zTx(+W5Nq6Cg^^qAh<91D`E?6Eg}RR;M6?ySfm-A_JWvaQ|(?cwx4RvAS)?HbT zyhq^x)f2UgG$scI2H*wP*4C~o$PU7=-2(>>K>r3OCu+I3khp;BSrg(!#t}4m2#<7n zlv}O7Jnb!Sc>n$jxSy$9Now!}{S>Nl zGpmekF-3OR308d$zY>zfd{z#nMSW`jH-GrwSS4;5wN(r@h_AX$MZ#8=O%u)Uxh$6{ zaCyWorwo5SDv(OWuAG_)N2r_bPAX%aTSO*nLlbckmf4FDPRj4Av5f9SJ9OPU-2J5R z4Wo}$&7PzZbdBm6Ii`5vC|LTW2-Q+0bd$_}l)d;jh}9ErFeXA0o_8YQKvh%*ZWAtY4V zt<{oC&Jmdi_2TSuTI?>d&VLg_t~l%<=VpQKK8~G@@MExdo2+GflDE~q(&p8M-{g&X zHN^LjCGbVRq#(MFXN0Xd+-|&8FnkzDo>}=tY=(JA@Cm&F_pzqWu$Zo+qhq7t38+n3 zSrjZbBKI#BNpZd)mlaN84#=V95CnDqKHr-wbqx(^D{L~6T-UAQQRSMdBmwT*o_4Gc zxQB)+FhecH(%qLyeCWfXFyFLs*mv(2L%i#^jqQZNm>(EfO`LE>7F zNyC6nkL~u^eoT++Jip#0@+ixDxz*1?B8-yP*JBRFi_d^t;J$TPI$?oDM65Bs(+)9@ z1jDs~W=5D8rCZ?cVrFJ$V`F1wHCgQ8dR1h zA>l#!J2f|>e09=3nnsvQIotN>tR&4G^aqnX0{y=2N(#<&mK7F$P{HAJ>hx)7Y=&JE ztlj<{k6iALZ9S+1H&akohL$Mz4t91}kpqY|_aprgnYlrA25H|TlB=A>3ir)n7kh(l zc-UNqUif>DB_+M^u!wpr(q`9Cur&Iy=%CC;vcBJuA&H;A`gQYmJLa=Kio-KQtr1kw z9DUg*j&b)C?VoD`H<+ZI{Wz${hgGP)p#jET(6OG7*K-eUX>eZE)9fjqvV!WqogHEa zw@OJ#$+W?nK_&~lUABS4r0_%VcAX3+!mFi2&v+T^IHGTae=}ex?cj)(uMH154a+eR zxXj46(@S@!To$Dpm+BdPHw*+HusW*$1HBg39CALW>PWOo_ygS>`<*6X-~ub|`pjL8 zxQk_rzAkX_=V2mzv2d6U4i1NsjCv-uy#C;0+wCspc`RA(tTsKnR zTOlZIDM7U69dAx{6>57klF_BLEv7pP3w7Ib#WTrX%3`OomM6Y{Z|-&dnlE>%xU8e& zt=rU?oXr*&IKUIpw^~tIg=7zQ1dyRVPjMK=~%9(&o6SrMA@oPnM zTHq*qO7@p-DS+@|c&qsG6a^P4B*e$V+(0u>6?B)r>|P7?&lErAJZO@hZ9BXRYj^$v z<0vgpgVmU5_SQXnI|?i~OPH=lg)CA!C?m!U)U>rrg=WCP#=yaNb%uZu`3p zCtWogydva2S=DS^DD{|k9%d54Tav(O>*^YBy_&hQpz-tA?%Lh{iwc`>T&kpaN%FP` zW{aubBsRqbW;?4B-E-f)dk5th^C&lAT$4>g^3~(b-;R(E<=?-_avh za=7~NbACJpYd>E)Z_EquyDWiq#VXpeMaoyDp74&gCTK~FQNX0j6!5fowZ_GK=>avl z!5M_qKL(3gYJ!D~u3u0>(lHxIP$%PgWu~zmJCCyN$*)5$gXO;FZHWekdG=#X5XYa= z!HTLOSZrAz&at-A%P4>5lA3JRTij}+R{eU=<&EL1FLbjQP$CoT$<|&cUBJr0_ksro z12DW_w#~+V_D|+=ObP2rj1<|HHmBeP*n!z`$pRGlOAJIM~B?=pTzL|cH zbFGic$PnZ7|9Fq4JdIl?2wnPSztjZZm{2O-3vaF z`~i-h$*!iLQ*Q3t3}LtK#RKW`Zh3T57a7Crc986J3f{bUZebqYOvS`;Or}SkOZ1R3 ztmh4eU1Y{k9OvO-@-A&}Z=ar??)m6RZt>qV-EglP~TAP2-+5b|&7KrjddzrpFV}eDx;A z#y|;bYH8)a!X0Eka6mai8hmBmqDg#bAtwChz3g3)HAT6PBXX&7h!fJ7!kyWLFT>DK z+?`SEo^5(1#FMwuh$GKJ>{#?RJpzO6keRGE3M$E5n-N0w(Q3WN)L&GZ@~2rF9Pm5! zS++#180zM@%pE&+Je*4Ifqk+1N^J!hKXY!eydfTy*|D1=hkwh77td9x!JXcn=@-DICm|M zDTEXGF1FO;Hf2y;n(kf2q;mY&tz44mbtyd8f&Px@x)S%z2+IBDCSbQai|j#|@TmU* z-WnLHXt!@SOu6IXk*~fGPOp10OrE=x!)tm()0u{rhoDeH}`+3MQq)44nh>K~T9I12dZQCnW7IkN1#itRdJ>W0jB& zirlfZJGyj*_4*?HZi80`+1QHU8Zia&L^nQtN^>>F)P=O-a5Z^#@zR50GhF!TLq0#b z5XG|B`BbiulLRV02@bd#)fVwuWfQz1ztCG+^Q-|7)f(XaSAHvw}4g6s=cOY8!>cc#% zuVH6l_ZzAD4L`(1K(AKx^RPDEZ7Sahc9$)UITdy|uE?$QgpunW^~x@cSEV%vJHNQo zxO`*-i8ZU$^NhSjR?AiK$~|SLmfo23EH89UG0>A@L3d`jrFjIB5)fL!5Jchkx=5}g zy-M5^p+UM~+x4=|`*rK&o2;$&r`QE2u|Z0bZ;s$NB0qYSpKfP_Ex7vnkqHU(6`ATw z?ovq(G!=t_CZN2_NdB;8^wr#n54aN#Q4XewS)}0_t;zhDn2#m15C;Kb)M=gb8pFZu z8mREoD6pLwfH2utip({LMhTO$Ht(0Ev^sVAa|;gXv2}!IK3q%gmlMz?2{+);%g)33 z_fC%-__oz;&Vir%);){F!3i(3X^N|l9sKOMf#4{V0gQ`-xHah!>E-3s5FrE0aOR=a zoO6_O32QgCI>qTRzJ7ql2QSW6dn~7Q@%Sb=tog^q9e|Os;x|{DJRjfE`v9>5}5&PLR61dBc1)CPejQ#&&Ym z-mn*&e(cjLzME7W-tyI|ap$Ue-3!#H@(YEUPHOfq+A zaeGp^RA_zywgjYhNy3Tx6o$NgaS$w3XrkMES(H&`DXoG)iH~W|CEFtc1fp+IXaY*= z>i<38?Z^H(IwmH$oGIDWp$}EflzfgtV#J872g!tIF$IKe!iQy?EvnTgk%R85K|H

    %hHbSNPmiXuac zbc%Eh4N~&m51!Zi^SiF!-{%~U^X$FvSod1%_CVFY0;*96^9+Or)Z%nzYE?HTB4=n} z!+|yHQuBiEbq34;@&6@&LAO)O9)15g33&9hWNacRKdLmp^LZfohvCr+$mE<%K`@nQ z&*b0qXt<^8)7W6+n|)L}%lzT=yn;`0Gu8-ytJ+3)PrV3Hy$09QtAb;uW(j?lS_yIg z`Ejp&=^3|+OvV>_{SR=DpxLKBZ*A7$cV~H%H=XR8DH^nFY!js{(&|@e=HPg@bjrfr zO!6Nn(rtlbqR%Z-dWx=eMaIA-f(Axnj{ZPaOD*w9kkN`8(2ZHX?TQ$M?jDeh_o#$6 z6oN5Zd(m+xO|9j#dY2FI4(V%tU9=O$2K>|^(Ji%inWlaay<8lxDtoC*`R|lGi0mrp zdSt7}CS{4}d_-!Js1MIq(b7k$V-*o>n!*asZic$Ct%b!*DuMm}Xs&}Jj}x03FLncsxL7{atvsCR0Zr0_K=CZkoXdq;wTR;XU&49V3uzpA1Zgu$zc9B z0oI~J=pifDDb3~zs|A9sd!Z(PHs!<;AP9625EnQB{!=_llk&MJm=lbE(QS(gN!sFN zJP0tmbC8%G9RI_{Gog=;X4l%Xr?QB+arz$1-|nLtd_ai8&NU~UtnU&XF{)eZD^t&T zCuMH__T0vZY1Ik2wGrTLgIA6~cc|UYK*T-T+%TycXi;cQ6QbzxGA?7@DGLr{DL4Vy zZ(?AmNI0Wc@ZHUF?)CTC?E|i^(16P&blFSHVY;PnX|N+ER1vVK|Ey?*SiE0_Ei&5%>;s!YadhPdJ zPs=MS(`077?~4W?ebG=Ld!GMAHqy-`y&92^c7C}+Pg~V3e-+EgLrygXy)tCC02)zn|E}D?R1&XVO2BT~RXi(y173>djle!dI_#yOS<6~k z99IsPIQ{~I2`+JQjtDJ%OKDBkri6guy3WUB@}ej>e{4qUjoI(i@s+=+qU3Q?L6e~8 zoeZV{H?<_{U-2G@;+5YQ!pspZSWY@X6Epkf^b3?10r6$%9IrXJvyeT8s{lBazE4+7 z@}Esc-2czz!B}xok|NX@74#71e+Rr25=Tg4PM0Q%YIJ3Vsbd3g36C)@6>wd^>(WR3 zU4h^OwTYRDGxns@SJ%cp6s#qQEx?~X0ziSrF(4XnZPl+Q-yFEr!8m}MVKBIHh|nk< zX>^fTp=QvH`GOvP_(*WwJGqPZ)Q;hKj_2DcGf1(*;#!Kq2dSExsQyR!8M z@ehkvzCR|57M*+{mlzRUEieK}bs#ndFX_I92oS_LOG=gu-@4UesJ3$J zK4||zv;UZqk=N=eFm1UrQJ{!?G1e_f)s$+_&Q%i&h!>W4A+fO&b5Cb{7uh_5Tj_S+ z3^CC(X%#95E%BHd5v;maISg3K7rorQjU%d*Bc=LqpY7dn#=0In+(|W%jpa}?`mEI8 zZCCQ}^na%V8ql0VdNW9o-Q_3nbsJnQ6)oB6{oG{ec!WD`8N&diWBbGJLJ5DuT*jrz zK+D&}X9%A7AcgjW;br^KpuU0o=){I#6IVfmSY(Pv%0b`>2{@`-V52qU`M9|sZr z$Gh_74O|CtDcVT{`-9eRhfRO12R*~h2pFW)+UKhtcPn&oghSI3w+4Rbu|Uw=^y*^U z8$c726wfA50Vx^)J(r79WLM;8>4i)su{JrF#E5h!;z;oeJjo zKew*8S3K-1b32$i1K`HRSjjAW{{d!ieLy09h1;sB0GMKS>IGvk1;CRu^KEtk@syqS z(Z6nNbZkte6^z%S-^W(-4X!yWx7LL!h1Tk^YxPDaxx(YiEW4QmGQCcpBGOnIUKuFi z8v&wCpyU7i%!fqkrRSjl9-3jThnD@%K+7!B{ZbQ(dnEj346ic)0N=1a@9gfb))z-GZYdq}GSZ2D3?q>Z{=z zTdq^_1HLTz+~y>NQ6#w`WsAJs>#n=w&0B>?_}mj3rU^jA#l8QpVY~N!nN{@OBdhB4 z+C^sDXOfYlFAT(b!QYls8!yI_O|NAzG>7NTq^WhQ`MooAJpGVSBZNZ6j{y}!MsdF3IM{?#UNImX1q+d2*-daLSbx;BLmrG3V`z<02SAI16QEN7(9kY1N5@6 zT58hL!OAi4n}5|=!-}pf3nAjHeca;1*^?A23B)}hUkB50dZ3K@yP~BO>!F|we9rxE zHoSv?nlf)3A`LGifIB1ta3BIB}vHi<~8PSaQ%fV{=YL? zeUusw+T@nfIt52Ozk0rN7!D1d-%nWE{(JU_T@VTSlzaog`9$l}ZHuXB$z-xyL7*uG zzcmkh_&pq8doYwjPnez5+^Vmfm0Ww$#)G7fj`7GabJ{WHQ^G5@JCgOjVE+OXs z=K~UF=BL_4@=b~fGhfyBW*_TKg&7%n#6m+M6>hmhTN%282(gDd;+IyB`sI<1V43hIC4c{HmTvugs zQsu24zN)V0p@OwyKDE>D%1h8O4Kn8w{mJ{$-$v>x0m%jZdl{?FLK6baeeIh;2IlO9 z_D_?g5}y^47xb~jXKK>ba(hbRau~n=fP)2^_ddLz0-pK&ddx=eeMJIM#78dwJqf8& z!gZM+BvSU4tGIzj_qzpBzO<@#?V{sZfE*Xl-clZd8k&A(*araHJ1}L7 z|Bqcn#&g9kg0PCTCm^}FYlvtTl7oqGH7{@6XQEX5Xco=qrK#!1cMGS|)6$fDPAiZe zkeCf`)igjZbtl@sJjX(THN~vDu{LJ*sh~KcxN~qzgWA8F&lkf}=~p-^c-6yz4}BP2 zt!sK-O+2}Fz5ktgqUWPQOx%oI1y2Y<_b3{_GEAfn149DS>xj?4Bb~ zW&1fVL|l_hWo&ORVf1V18($ISMU|*d6GAwP{c7v_kSt{_tAg%}=g&XD@qMBKb=3@h z2=A!-KG;^B0GPP>_+4-%wXdAuxPD4IH~|AH@a@2GyqUE@0cb`c3o_t~dS$q(t${%1 zC*|iGV8gh94_ex}6g_CdI;7acecRf&K@w1;sO7=X*VkWut|=D*i$k=+i|GQ@VFxMUg1w)Ke*TP^vA+?8>VOM$1}S7DSXWY~skRKbCYJ zLw#w?7)G%WHmby=`^;0u2!u#yrKSlT($dfA#b62?>}aV~$<^@>36ERXD*pvBqR%n; z_Bbi#)fq83PeSO@30-X--M?0I-0k!IOST|ap#Z1c6gr=11iOjRlLLw7y;Sja-6nbn zp#RS?mp75uSKw0llvKfL;Yt_5z@wn|TMIWeU^h|W3gts>Q;u6a81S~u%u z8i}MEeSUIpk#x=10eNBM`dxI}<7Ef$+8X9nIlK9Q;e~ zZ4w?Dwx!h?45T}TnB+kOWo<-aY9*lf?x;2`GtDsy$OqnRF;ZykYpjX+CU2ndWf7+` z*m202eV!eU!kyV@Kq_FnA7VXIc#7?St~2g33V^lQxAS+Kz&O7(8FG4r!mmDe+!Ywl zdVy@#=)P|!rbIW6p&fB>E!$30D@>|ITWtXU$um_=Xf2>rb`nt!m1`jWFl#LAX zWM|1v#G4nmGOV4%yxbd2uANri4?#?lU;*aRu{D4V8;b$RNsrK;D1y77u8k^+TpyDFH&)F53g@tcM}$Wrhv6!UO$>u&N)_NpbI%UIAyE7Q{a%pCSdMpieeHLCbT>-+X)+ z+*i)-bsuwoeoe@1gZSb@u{K~rzL{Ot-~DLD`iAMrt>T2f+nnD31r|mAR*A*<=y@%d z1W)CDwf+)34}^W9f;L$-#>DSn5Em+^!{fI0r4@e=MKFu-KkOLTa$fU>*^}6X=f~nr zI%-V*Qc+dCGi1)IWZ()8h&$wLYj-BUMO*&Mdt0VN{o8Fn(r~T;O++El6Q;NZ;;(8yw1<(S z5dE}RnV2As@lH=(q{hgm!RGwgIQc)Us_1CmA)+|n<8jj`)+e-fccdPc7qfaEL|5O; z5J<{g%xNyi6U~hgyA@L&G-GIqh<#ekC<@ogMlnXxbeN4$u=IElJb2}%V4;#4h zrJtAa7iX7?@^x}C6XNn;(UiaY16x+8vOu&8oBq`4Q)A@RMjQ=-rw))1|6qv1r2)7@ zfmpxO=#}1wv*W=gEWxkq4qKv`0`$dCO<YC!X~QV!ut6XJ|v^7$!QN7&|fbU$~E# z-CZ^OO&2)Lv@%}CJM*THq#qDXpTQXdqlT+F!k9-K^!O+OaliW1l*vmO=-oi-BNV z4yJM}kF9PGwX@y}z?m58pcj6QIGfyaL9He9O-iOjOv;k&FVLjq%&aA9>Eagal1(%} zMcH+dm7`3D;~1$3;ucyCb1-f}>kIzFIP{}MAL1C}3^lcA<4If%R zDZjbw8M67nld4n&GikbR>YJ&P{o0a!T3Ud?ihmzPS4*G9`^@xw@)jbq54D2EPKD)F zS<2L5pb?&xF(e}3#)k0{0b0O%tg!ZW=7`F4+qJIGVc;jve-r@&fI_sqW=GZwu8(4a zRcp~WAQ2>rh6kK*Nj_?lvT$^MY*V=b@^BwZ0GeU%)+Pnzb#temt8r!18p3gccanUo zO9Zhjmu0RkQu)0~fflo73u?;wCK2|~@qT?Vq%77TsmJVC%F#S=gYd$4u8g+ZJv<8O zmmZPEe)CKSQcI)qv*23jKF%1p+uiaJ@=R z10QlN29|G0o=`UYz7O_}NI22wxhHG8vqcR?(t~!|9%p0_0+h|>c#?jU-M2_XH%{o& zCYa5(CL|=N7Sj2RPd6VdDlhjEw>Am+CU1S>wpWSzxOrT(<7V*^6jgs$ejdE>0>M;S zmKz*F(D%LQ@}Sq|z_q_6-@+7^BvgRQdDF&vN6dsYiv8Hqsj1&zfL!R9UoL?wG=%G; zNhi%GO3VdZYK~`S;weQ{Tozo!8_=*ZBo$bXH&q41V!)VhK}P}D^i0kxEGJdNiJ1Pq zlArnLNl1DC_Q%1Skya?JT1HS~t6xp>EpKY8dx{1at#m$szf}9~Pc}l^^HdwbF^43s`ThO{#S!J@*woOTMA7lu9sUQ#kb~c{87jTYY1R9jvg#$U&$eyYcj{If z0t_!;{qV_cY3%FO6(jlzt{AU5TU3`ld7vt$|ATvgy8}SXN2<&~g_Ruc4&rEM_!8ks zgy}lZ%jxI0fDh2n$6DIG17Wwo@}|%a44uz9E%&)UrF4Tw=R}ZP^uTo@z_rPa)HEBs zQ|%O=YHSwnuzBEu$aoI}Mh&H3h--$T3Z<9Zv%3Ym|80<&5^@WIIH47B6JR>u8QeQ9 zbcf)pur*cDgn8RsT_r&r;H;0A;cnjUC|Mt(uu@sH2ML+c>DnHJqsC@r$M#!M3QV2I z-#EIg`zaU@7Y`K2UHSu;TbTcY1P1U@1Ydf9MGKI?vsjGAAs%8)DI6 z2?MfCC-f!TZF}y1>&OR8o5fC4MIwCl-KW?R&dkBEgh6E8R+!&~4S?b9DSlwUGPRk} z31lZUmZc`+XQk$yY#!S%gNy1|rYV@>k3`DtayIWXN@7+=tVL1^)Zp)yJiL+FQ6--8 zDKSr()nOumhpK>G^f$Vf1>WEMaG#wMU{)y$Y0u?-0(~+%!L1uf`L+YGhdpFKo7BHM z2ePjVR5h>1W{_$T2;a_b*Amr zOGWjZ^;ZR}aDqW$q5z+=uRE?Fdx5`TAU#|ou^SDP+~^bHJ-59Mell7qtA=;rDp#|c zf~zbWy7c*pBh3HpSM}wSc0lF$WEKT-#nE%hp#pPqL74yjZV=-?R)JGk1Lk?*5lf&+ zf!KMaY5((VLzX!2e5mKUPhn?-n;%KIK}ZdISk)+c$?h2p^QvGfg}Wqs(BB@qjhN zl)VuSo{nQ<>l6&BLe6I?^Arfd)p9VaMXOY_Bu2Rft8k8a9{Dk0tC9)2T68^qU-2GM zh^poq(vM!M&wpqh6Rnn7w>zj&`ekEb>thidcZnvL8wP{WRx}`Ly1i^ZXBTvR01LOw z2hYw7)V;vhM_=h@S^tEqSCeEc4K6b1Okzf+#c*KDfe?wUXl+rU=!&&eTH|uw z7$><4bT4IImQqa>;W79VqH$kDT|n+z#$V0tI=d@)>x-?)l7o>&EHS5kSX}x0#4+y^ zsr3aPeq0YZ+cn!wYpaWeQ^xKUb%MUF*V>b%mPS-JDc;^+dEV^y4CU$^V>_DY`gQK> zBKn|SvnklcYQ0cbSgNHjSgb=S;5m&8a77udsfSorFaP@igbfWZ`}twKePB`nwC}$G zf!zNAzco1Q;Lg3by%ULPtjo5T5_!_Ug&-mT^xqmki+Bj$YR*TI#bp*=!xl}aPcuK- z%y&KrPl&m!Rtn#%nc8a9zw;@Yj(11reWbL@SgdF;R<>fR!MuM{t{^Q591(c*5<$Mr z9-K+kLH0vbK){0ZNtG^Y%4&Vp$n9%YYs2nO+NoFKcQX+u-2FKdNDyA~2%J%cff z0}5z3?rvOh^Q(ot)*BC^deWWjj{;+BvB;D(G<~M`H(SOOim8%OIC#Y+sxO#euo+J3C)!g^mgD8QXq%5V14wa;M zdm>C**yE)|=h@D}?tngZ--eUOe(faOHQk zFyWUX3G4#uLxQ}uEIV<62iek&r092wlu12gNtyO;Lg>lpYdKq8!Zu^5!+Qwv$8O|a znvT4!%(Y^Ta@#GcioO&DOId2{+u}D=ctlo!Nz;{QExL*?DKx1{F8@UKwu16SBokCcjwfydG!NwE_Cgg7CM){8mBHx#&ye8q~VN@ z!hyv|r{(=VcFsLbug{x8nCJj^KEhq(*L?4gO_$k}NEY~5E2V>%m(;e>_ggTUS{L0I zJH^Q2sB|HC&&=EC_l#PW_V($c>XDP?c*c;RFHr(Sx1^FoiIDprSbh z#;aiG1)*z3)}yG>YyOXb_HSY6y0P*CC~;6>OS`~!kM7OWCn#r-&HkBO4T{7dXaCVP zwL8FML!^@m4#=DBI(aLvUWb?+G9ofr9%x8T&x^6gM zhB!7W9#+j7{C>ip`Fu@7J2-L`a8q4PXoe6DoT%7hl)^qK&J0ya=5&}_CK>^ z7!TyeJObRj0dX<=xB%eO+%IANFR=3o&%nN)qDQ%X?Ux*TURGdnA7h`z9j1pA6rsfcN6?( zLyd)!9N71D@Tb)1?Dz`^}Q*<1m z{_f7!z~StRzOksRBN9*h_sdLP$Nw%0n)R@(@$<83L)DzDk--oZe#_hL7lnFwXQ%$h z^T+s42QszC%>_f!moUY>Ad2so^`1-O%azM*scrG%2_+C1JPfJSeZba$4J`q{ols4t zFj6B>6#e1}@=F3)Zj6^Pl<xob@z-JnnM}W{(01^k~-m{Ixy~ISI^&;j+klzhkP)mf7|2IAu11 z2BEc^QXBy`4w@c?KliV`*TW-w0YMA3Y z=~$+Wj;PmNU{?LG#<79XP!ku@zFT=p+|8}MpDoxABgvwxlQ^(bDRmlS{ z%SHMVpz7u!yJK0ep8Z>);PS-p(r?F68B*MLP?@4#v!zczfNn|nmrIi+?hPPf-m1b# z+jzSvKwr~+IxkO->Zhy38DFM!XiA)Rz%ukpoT`ksPM1nda{cVDZ&IAe?%X~T37{bY zdxWpAuVpx{zBBcL{;%6N+6KLk5sfu}4ROPsZ1p%rDG|WuC@whNMRS%75+laPA_oKB zdVkN&DjL+!_W3#cfHQ@*CU!bNu<-4zC$3{d2Kkw#jQ^Q|on_@} zKtt{6Mob-kForv>O%S#_rlEnED>L6W8yUJhXgizp5`^R~^I%Rwi3`i#go9QLgVv@Q;AT(c+ie)oGN%09Ke`<4;aclYV#GpV0|E1us+?D;cz&VD z{}dQ(F*2bzzzQ`|OiTYY{!+R%zoWTJ0mDdz1fS4yVfp9S1Wkn3r*}Ki(dHER>&U0c z%JUI^t`=*o6c1RZb9yA@hHgJfB*(Bx!mHnCWR?B2_L#-n*>g3W-h;sf=FrOGVLCkX z>QBu4M$XUQc=>8R*gC~4>NYxEOgxV@)!bq>XVR|y8dY&ul9Ft4V%^q}lFPwy(?Hj? z3qRg&`sBQGN3nxU6HQUugw!~EuqHA!jj`RV165s8aXEiGE>FcTRA^&TGw$Di2Zz=n zHbN-9XvaP&E?gCouexc3K8Ns}v5T3{pq8C*lo6m_H=^!YbL}r@UKI z(!^onL{TN&WZS+>dGp&JhXrzrcb1&XGy{SZ(~q}R2+3~ZI~7fMDBx8h&ViHcZY+D^WV{vS4kp&-JMRkM6i)*6&_~B7gyoq+vy|^2s!e zD9mbWi|x8&pGr@~bM-zS;Hu&T%xll)zOv!l#|k@nrNh=4@0zays~@l>@$=uGqRM8m zFY0ZVfSw0J3(p2#9^G~N8z2O{P*s?F2d~1oKV0{-xeKJlni*~Ke3q`!E#&?jyYJ!5 zn;kr~w=V_826WDZ-EJNj*KE=L__8E=TuJ)v6uV?_u9~j$k_QXx?+8XzyB#-!bv2I? zdZ~&P_p#Lkh>@*iXYFL6=}R>?)5z4<1&8;7ytx;qt8>!0C7HUTO>24p+HP=%WHLkF zWBXP-S~+l#g|6ks?t-HL2oV?)Wd@woAR!H{)3HvPVFLe=`ye2oQN;!Q0~NfT^)4p|8}{x#iW51aD&f*%VRSR*hO@?xOUm!!&R(d65Ke0EFE$5QWh~}lFzqi znBAgnMo-o+-jf9tZg7_sd zKOdua)%kZjHEjQGh)4*nrNi37{l zNaf7wqGa(ueS3&aNng;737MKVaVv9QM1dF5*%Kq}M-6KyNud{4TFX*a6^s!|81P`Lc&mn8O~xr&I}g}TTAJGGH6#6_gsM>PA56)0fi9yuGA z$VWcnliaxNb~sG<3_F%mqL^CUw*N1Eo(tnrY3o1RWb_K}5eMb7nK-1{2E>idvR&Op=W z_sYaFzPr8A$e%a{GM?mgX3*BF&RJX{G=XEjnN zBND|`W2A4Y*7Y%se1C}O>b2`=iiZXR7Ej`!ip(?O#tK~qQQ3>KRPt&*6t7aPl+l}D zcZ-4Oy+%4IRWEDQ187Sm7%Cn61uDo*ULLlcMP1HbP+51zo@19|_p}>jTZ1M9EL;7- zVMV`tliRqn9*i_PK8-KV!WLCQum|RyzW{v>5(>#MDg;0_IZ~i%eZJ}!dbufnu1h*Q zv->x$MAwnvJ0-h+>e~Zs&;Le_D$A+@u{f{Yc%qdrm(nhu^+d&i+u%KSIXUUOv}BVj zeg{TP8@G6wbXj>>dYq-b6?@k9p}FQeZZRXpTb-Uc1 z+bHOSkVG)}Du6J^pl5xYQbOI@^_VJ$G4{bp3!Tmmb=0=VV3Tp$nu`04o{<;9_Zm*5 z-ba2ul8)?I*wUj@U#y6Y+~n&`Uiq_g$X58RPc5P83(b-bcTjr3OACpc6l-?%rVZcc zGLor2a9~ZpA!(R<{pZy;@!puc$HihXqPIcL&lpgAr<^FVd-+G)<5D3;KA(}kL1}mc zZ0qGLg)WaOupT*5M{CAf1xWk^UsSe5fr1BCowA%SzAqhY+V7oAQ^{kAM50GA1o~}` z#LBv8JJ^4rA6o%7#1^7gLkEsDugslfq$5GAQ4x;5Cpj zLYF5X?O#dy9xz-!-Pm<(!q@HwX%ft+56Fagb&fo!VU7-Y?p=8A`q(4AFr(?L&heWX zb`ES6+*--4!-1g{kSz~TeE(H2v6|o#)n$%R^hVy#*c#f?W+fwG+Rz5C1RBl;6ZH1N zN$k5h69Iv7W6S6GZ=^A@=OJwQugxGY+2_o^uW~J*W>TUST4&_vrr*{q^%D%@hve&6 zF_UHTK#4IuH@MG0)YgG~EF{|W+9cRHz8C}>&sS6cIi2CWPO)-g2Y{_UQ4uylm;0Y? zma|TeXvwvE(rMTsoxcsz3W$GK-^%ZL_}ghI*0ic_0cM@=#E<^(&~m};^Yl0Ch4o-gZ6H6Vxpi&h0a>Vmrt0{wcdy|)m0L% z_!A=NIE*&ODN{p4eF5=jrCNwKj)CLuIfZ4(D@OTiE>PF32TJdaOHsp6k%qTa+WxXB zio^sQz9F%rj)=^mvVQ%e)8J_&$GmGcV!I>Mt?8x!qfC*Kz$4Hc{~-mz#szcYMaY;2 z^O=kA?UrApG$;5IJ1oBxGiP&{=71}g;rF@^Jy^D*|NmjfSEM(w&tvcd@nbDpq z;jWk}i{?D}_uNuxG0ao^b->gOZ!V;DG035!sWzHPy|@3xH92y5xH@Uk_fyM7e>i07 zXY}IeuNEheOz^oO*UKC)ozh1x@j!V188qU9HD-r{v{vE!M1-7VEM(v49<)h;{koeZ zqx7XPQR&w!&o?msDN>(B6DWJi^1e)*Li<}0h0T!@GvB8 z)+4+KfDJ0gDD26ZuRgVb%*ddvVwSyy(}Q3HG}FVYaIa5Rm&RY4K zZ^cR&Kpd=SdFEr#?rTc?wFs5Y=yRyDm*7)l~XcRyl;m$ z9Fxq!jbP($&SXmy4sV*+)H(FbXq>4qaG+MYtZI725nDluAwWMzLpFPIz_LjZqdUHg zRj-i}GG#y$D#wNOKH`?TN4JqHieUD!*x&jgsEI2@bW2_pbTdzY<`K-LNUgh!Tek zbq=9r7l!#yDQ>T^;;nB?49BbKZ2|i5i@^GBMbppZ1x(q2;wU z_}^^^)O8$KzVLSXxrYQ7L99jcYi+D)U7iCj!1X>#AgF3P^AR<$j3paB6UWYgV<{49(u zq9lR-$4-`hxtl%d6~k0m;qpQI6k*S}YmsQCK4HvVk|0XmD!1pBW(XIeA04dbiHZe@ z;Rl3X!I`0_U=w7hbcRiTUy1NL-M;g&NKnxv#*7h@WswekQUkHUo!ja_ zrUI5{c$TJVXMj3lPs^R|eUO1evcUb3nb#j0I)Y7b>|@*N;BMO0JDmnzdG%&mu1_mW z)*C{sLjwEX?cKg*i22>9zq1AJA+p$RWv9IT9l!`qoYQCb zsS;`~;J0Ws?lf4ud_C7aoVZO2+WaDG-Tyq9rVi5?=)g@yyQs`d+Pbf*Pp()pw+`h4 z&lWH{-{=>fCvnsr*?LG+HF1bhm)TtrN9|R^K#ug=RTspE*W0Y2dVkop)YQ<2{Ms6x zitMA-MUsmNBB;F}@Xf^$z zyd81RF}RPmLm0C$_iSF*QT;UWeWsA8^+lk2mSLZOU)Sj7wGdlDmj%7L!Q!IgD|(`l z)=w-LB%6!xYCc^Q&_)MH(eY{NufnYJX+gCVI+yeNB0!n-ntuxEnx_jBY5?na6&!v^ z=mB=ON+r89wU}l#BoW0Nge}SJc2TxTMF_nFYotw6M-M@=%zjKuII9)%lKUmLWqh$T z^e=Sq4ZY1k{WMAcLLp+y#?C%rh8=4v4VsQL;b`*UnJw2o{~<8nb;6FNGj*{oiRG@U z1d3)vIRrC@&JxPpTOuo=_?gP ztn<<^+aKHmIl8P|{Y*b8Ft;Pi62)UfjPE^&A!1mp8Hd`=#g!?8Jy_7Dwt|V^`%eb} z-u3~D<0M0otj-T31~tgchM8LB1UpH+d?BuSA?)|(H z6bap?&@JS4nxk+|@WadK+HHlSjU%-NgGBVLm^M4~{Q1d=hsWBXgNH$5@psl{C$e1Z zjRbJ-4@=vy(owJn+ z&RK^!&gdW5Yjr*!!N)}D|2P9Ed!KF!0(x;`s+DyvPdcI40?F2TRE6R-|Ys-E4e zA66vhc6~@Y*L^YU>K2@TikM(jVX`t*h?{Gzz_jvW#3sNvsi*j2sHhs7g@MMHWP>FT zuMsrwGyF-fgFXzG88~smHmPqNxId_F!g$!Y6%7B@rKXsuJ_cH++QCU*27%mDI~OfP zvt?^7Z1_iD-qrtXdWwKU0D*^O%XfuuTpN;9Yb>zVA|PYu|Tg+Fdm)N083{Pr4t zdPuolo=#sNdadi_|0;sy0(a))Kid-5-(xw;xq%e^#4@A1MaOc%JMAaOAEm{xG`VJM z_i%BydLziI984XVq|)8D-K|O6NY^^(zMJ)okay_EO)E5mAY34Wwv}qbG_&GsGD2|d zwqSuhT>3e#xO-JEQOnG@3H6@0vQ-?%#H3v+QGPFe*#IRlQDaHM}Of%S^fOb=yJa z3ogJcKLzYC3Xtz$+`bUN_Nes z%YzP;>p^)Euhdl}fhHt$rvz<~WijZnW zc&|Pr>tV>3Xqivyv?8HQn)9zBWgMHGSUFUJT&hvE;lsyVJ-jS4Rq_`v*O^{?vai0o znBAO;1Lt!5v>{V*aF8TK^re>XHh2^uw zEpGIPYJ$R25u}<2g?Q48%3xhF*uZVPOae$;Mc`U;o5cQ=7*67SU%UI*4>zJart%|) z(#%{2fRtX8j;!P1kfct}oS%DpcU@P13;8K2wG>R?vqN>~?`84nF^=LS?!Q>XS)A}+ z9M50{me({yLP2VSD2o>XfPP)bmoatW!r}6~O!!n!?=fiI@XJ&vq*?4}E6elqzY$w! zud$e?RS~)&+hQh>j>k(RZ`rsV!&TK7zBSKfBrNs>bQyC0O-*l7M9tYr_4Vcy%FO;o zkim~KPnA41Rz7U16*M){u)o?b7$3{)^}plz%XPxo4MIKdySUB%Kq>GbNZ|BSbv;A) zcEfelzAw;ZF(L!A8il?YVdZM)A~+s%ExYTQy;I*1;o|VS5>DYfPwy7tfFSyl=JI=> zC#~!SN61P5OogXkrG)fb-p(HiMZK}1PS@l23KhQ9#O9VZHl;kACt~;$rgc*Wa5$Hj z+R-<6M_rxn9z)QIhoET{p4GTTV@icw{}$odCG+C~@XGr$wUt93@Z;S0;gq&8<2IMX zB_1l+MY+{l`0;oT?7M)L6dJ6kbc-qYGB)g&apUKM?NrcyF1KtAsfMQGS;JU+A@N5T zhurhbltX{m`F%rJhp7Io7D7=)fg7?$4~p}G97_STucaVp3KVJ1 z)Lm`p?DUrdx6CuAYlBa9tJPvF9~~Rp-Sh8$dyE~)n`HRdET{7f_%RjoIZ(AD!l|x) zIm=ZC5-&X&#oF=3ayc=b^{y3s1-aQ2rySecn@(S>fN(4Rso|e1&4`*ii4|+IH;39G zwuX`TrWY5%jS5KhEXdyhH-DGX6Dy5(_R2~eHvFtuL*#bUTuwd>)q`H1eUsq)8}t!$ zJokl%9*0FU#!g7Kj#S5OshJhIejP4FV8ME3dGP77JcFt^d2mEmg=vFA*8A6OU-1&*vcM2!KwDA?UEd)j`=F$IOSRJCl^4Ox>p+TM{c2q*fM z*9>0lzcVmd`t|vK`HoYvQ}i=y>r(OIs{WbrsE{4beC|&N7*=dkW+s}Ka8IFYEVN<@ ztxz4AW&lx%6p-9t?pk4_CV(opiX=0h$UbfsP^tRduXfpH4m;G;B#r_FKdRKx79BgupI`c6=)+2a6M}a5O$7N0&h5EX! z9#indB-lK2Olx$_dGi|V5HNr4J?!v2+M*T6f^y{&n6vnvHS_kTAN>(|pW;V(laq(> z&NowT(BRM`3F{DDU7yB7cJ&TGYz75l_pf(qlA#_%fuWwk%IvxB(yPXK*XYuWgMmJd z;$cUseXRFZeTZ!}Oj{yfdzSs{H?0;y4W9F1TZHG zKb0ZA+e3F3P6s~P*!VGJ04u}P)~B)!JC(hy+t}0J18!Pz^yo=?!Ego1TyJFG+*Q~! z?e{N-f&vM^386h-z5+A6s^LBV4XDX@p{b*p+Ay|y$(KBLWonR}=3)uWZ(7!q6viRI zVmdN=uoqwkKLnJXO|TL5A%p^~+V21EVmi2sK(`_Swe%j4#l2~vJNPI{;9mLw{p?~T zmZr%UT)sE~{SNaqa8nydT2Xo^c0hi4+saNlJGt<`>Iy0lM@w*wDEe&p=N9UQ2J(Zk(3W`+u zr0KAtiGuC!-DxKf{UU0ecEfm5@ghg=G1BqfKEI77O7zb+f*qe+ctj$R2DY1WV_2Vp>I0by% zm5PFpKwU;-cqy&wJuDH=<{w& zg%veGIgGWTU>7u8xZpsEfOo)(@AkB|G4ru}lOfv0gYu@jkD1(Vaw2%hPogZPq-yla zhbM$*iC)dfEqgAQ$Cggrz?9xqFZlbV6>A8r>kYQ-`XcH8zETN*ZvaiTDyWku#Z}aQ zo!OyLqu4dqBzToTIw1dK^V=k6zF>MD4V%7`?pTuSIu^sv$CUDkA91j1K5loG5hK&_ z=kcH&NnouK_8*5ca$JtikUBVZRu}zA0bU6`Kt~?MJWT-9=6fSl?tpYVRbP-hc?e@H zd)&8P55^aV%+1otG})-;qHG#xQtj^uM(|p7{`Xn~0af-LUcrh7b$f5=nhHzXTY-q< zE^473|A}_v)9`7cZz&kv_o$SOY{91(cL#`t_FS3l?wy#w6263TVzXWMkF6SKzh*A( z+ikuM(D1^{KL>uU1|FOpg=1%R{riA$T>M6R-0Qq@@!-q{I1PrPT&3why)BE?gI4sB z#I@0pDVU9cpYi3sa^O+rVSzIUX#c4QIKc!xqx;Pf7^@SiMVDbvuY1L@Y&lp(*euP^m%9~^^ktS~ns?**>jD4&v~l{A2Vn2C@ykVgr#+%E zI;~{1w}}Xsx&aUQH!1Muz|z$3GY@5Jf!5gX&chw^VE}>J$B_Q~xop1BKmQ7(=8fF) z4yOpu7Q^-HOu*`{e=8=sjc@LshnOt>S96L?=S4>8DLq3g@_CsDi3}wvnc76`_>&Vq=@}3oeF)8EPc0uqo^fmA=AZK1-^%-C)1wtQ?{Xl6j>q-w??w{y4>VpW%Q0D5>AcscQ^c!$c<#v2 zIrsMUrHD7b64dNmRH9h4hqHjuVpA@=Q1*9{)Ia&G>p#5?jNb>F8%IYI(dze$Maf60 zvRG9Elk&qWH-sPj#mx$PBrBQM!9)HH9x_nEubv-d4H#tuvuuE$aXV0fh?4%_2kxfs z)2uwSlkXW$>{6cU53aG^dfnm3dlUk~oojgxe@MlX8d$UjBG%h93#|&G+-=&tCZ!9$ z6;Ry|4s3wwUc%|VkpIg*O=5!G<~rGA8n9o~N(Ed=;5vE*i>cEdi{FK;80>Kp-ht1@ zQ;ZfU9%4*NY@mFdc9ZA&RVorFSJ*oQb)E4wU?8L{5Z~n8Bqc7r3u>BFbFt76!ZiYf zGC%j^fbKV z7gj*7BG%v;5pdRyTeRk!_b)q8a@>)PT#bGJj#Pu}48VYVqq3G`v*s!VJ?znqX4GNw zT?-K9PkkS%D;_skf&CZ7Mp6O_QvWi2Ck8Ec@^O+aAfz%-$o} zvO?Bvk4hmSTd3@nQTE;$5s^{ou~#BWh?0>_R#pf}X1{aYe7?WGpPt)wy{~g#=XGA^ zyw6cI>$yoy#y0#6Da++f0OFyFb4&E#?8H_sD^YeLJM4`oSmaKk;FjU1$bhWoweBZ0;BCWpQ7H`D3wkl`w|Y)f(FDX)>P1SQoi6 zOp5UpanY0Do#pu_qN>)TXOZM@(@@lAirXs3K)t!Hi+u-!$);7fTl{X*4FbkM4!|7}n8|F~pLLU*Wouu%; z1*&T7AgHRkHqot+$<_Kh+@TOJU`Rx>S5c6n(tWCEKPaCh7tcQ~U|jIUHEYCo0md-C zYgj+-@kA1Ia$ z`8FDG_K*XiixOvh!M6NigS`Jz@7Km2<`3&6{)re_Hm7Md5kU_B` zo4~wmzNwVH$bZ zOkYZ!mwu%!At~?UHbdng4U?LrjZvgZH*#m2Pb`3%OqxA;W9Yx}wM^vOW=Z6R^95Q@ z`^6FG8z6JRgucEvpciLcz^S69As_k|xi^iAIkQ+~enymx2l8c5bo7X&7bmygB zmf*VLCyd8T7N~WULT~_bkBsY=Fs4!%vP0M%$@Sxs+v_HiN|Y|MQvA6xnJ`=W{l`+w z04Xe-E^_8I&;8z(8-~a0?lJ-b0#hqf6FCWGkMA=kI!G%&zJpFJz=o0OnhY`A(SFRpRluKU3 z$YZF%ZW3*&s1SM>)P-#smhf0y@+yZt8b{3Qkd(uUI{tj@!z>Bbo$7|Tzvan{Qr1_I z(Z(P}3rBTw`phy208vcdg-+$}%Zq}PeaQresOysL268dPm%kIB7|OeWhz>Fs$o1iZ zUl4D@Sltip);}S&wBYWU(s_9+@XGKPNaGObNv?)PE(|n!atA*r+|Y19vZo;{xZC9kj;`yQ1e=a7ar!q zMmtr*>&XMKvPXBm)h3JKxIKdU8}ayXYb)gSQyw>|E~r28vxTVF4=iutc7X`gxOOO%1q~^q= zvWd?AWd(zxm#zjTU-fmb>f&X-QiPMS;@}-8SXD3~jn3PGJNA|0t}6DKr#B!zz1Fy% z#c7VWz6TiA4R$RDddN}Q25XQE6*E2e&Lsl-i4maeK3eI(F)j9;n6`TJ9*iw2YX*$1OUv(e z{AbL086x_^zWm$FR*B)+JE!o4)o7a!9bAGC6Kl_46i z&>QaSZb^rO4Mor~#H$3Zxg{{pLKnZYhb%lK$Q`r2*Z6gNiUC}+w_3!s%t&K~|Ba_F z+>~l^V)e5!XB<|m8$hd#Ye6%L5=W-tSFz)@Xf0vPQ zaZhd~)0r{M=5T?IZC~S3ttM3F`s^QOy;p9Vt?MZZpnF;Hmq{&+mwAuj0QwZ)GXH7| zv>v^eG)}~7C`*h|7Ak|7his8JPs#z=MlCYRv_kmhv^_LwAbX@=)oR=_3D$JD2Ef}; zO$mpgX}F4bnDq}HG&Vvhbx%X$KOPK4!YtDpqVXve0m+5`6_Hd)VrMqE8F7VZ!a`yv z1q`jRa>2R|mADVupWC`h1_l7_S)Tz+?fA{Vz%;>N{%-A#=9ESw3roBqL)#TLRhzx^*KLov& zRwxpE3LOaL5#Ph|w4)78^8a|uWrX>3Os`@MJ87rk>eHUmuudyz*&aWdDI7aXa)+8v zU-oQ+Ms~14fufCb>}H>Zaov#PvRhIt6lQZCU%LwPz?<)u7B*@pz2*iyv?4xBl6390 z{(1~M9y09=nr?V+Tqryz5iU;ToG*lveJ?rYh$7D|Agn)^vA#}8<3UEvyEh#YOcdc#`5sP@9ljT>jRv1b9mL}9k-6D8pO-FD$|T!K@}DS8_2;*s~lO*FMvx|z|);I z)I?u_-u5|i_lzvLlosN&Pin+rx3UQbu#WJaLoF!D#nU0a$g_Y%QLT?m(fno zGch$cZ}A9vCzV{3U!s<+Q_$R4;>}>Vb_*t{o0&-r-A(ex1JCYs25|lTJ0>&C^-0sW zP725@Es`Xm$qcFlqGiQwYMI=eYhFzz?8mAv8yXrCJJ71NqmDJz^sBKVQLk-|BdYx; zEm-=$*EGa=3tVy!TBj~F7@th1ccCqRvLc}oz&|lyQ-z}D>}R<-pm8ZtI2S%6MDZc9 z@d229f#_!a=-zF?UTrwIMVAX+R)I@VCB1e{f))V*IR?0daBho{Hpaj@cr{>A-^9=5 z-A_n|^EZ)#4Vc-|Nr9YSK?X22aJc0Pzev9)XOX^`lwPu(JQZhLub-uUCU9X7&23EG9@V z2i5ak3}4i+G_Gh~whUXj8xSxxWqiD9j;!6IO@7W%r?$4;EU~nlR`(h%RN8TTYLOAs zB=5`@`rn4+8#*tSIrm<|IFy9=YHcVa56NJpkfeG|6cs2ddT$i|bC_$+EE!&HuoRqq z^G?399I2`H9cQdP2Tp`O1y%3xva1J z#%cTiN;DCErOGN5&TP#lo8!v4mJ#aL0R~+0;Q;6Eq-ZS6BSwNEq2dQ|%Tr+eg~k~W zXRGS$?@5ttx*#7z`&HD-%G{Cbf{p3m1A#*{G8Et1%@qBkSiv&i0HJ~~r(}+EuM0te zFra(;y<7d5{k9B9dnBGNOcC$8PMiLmTYZxpI_P(PHNWrqVw+U^(!rp1oG&rEmp!$) zi;oKeeScfcne#A9N8Gi!u-(59To|G^dzfk<#3lF~e zjZMZf7=``0IIFuZO*e&s!2+-v&Eg^Wh`4|`+}(J%tnG- zBfgL9svGV`?$9~sjrpF=?Y_m0tPI(;+*W)jAr}=6(>8T5g`2a~EauKMB}lo!g6`sP zYxr-19-|XDiHjU#lmt;_ImZml@toKZqd8#M-KU0~aNYWM{2`BsSlL5F{58k9XZT{_ z;##1*qf}RFhOlx?K2zboV$Rm=WqUjOjt5s#um240RO|U>6y=wY=+x~bR&$YV2*$wE z632=&!a*Xt8H$lv3jqX~FTN@unmlx;gs9-BPwgdb{l{QoyF?WhsUCR+Ml^)(3)@*G z9lozG`fQ6urwoOhk*yaQM5)a57QXvC*f`q3FC9L+=fmX9#9%eJSj_qu&GG|T+d(dh zbPeWu7yrgYWQn?y0*zM?H*9_}P8)MYal^LE=i61|A;D^$ZE}x=ssFVdo)`RGG~?p+ z_wo8fky5&XVYpfr%;5F>?JI9~L;Hnq+ta6LItoQ`L>+MiNhLD~Y=S#c-5MEdN0WIj zv3}>!73Z3g7@W}2MS@oZ>s;LE;pjg^j#77gjvfO^zOF_cfBUsvEuRz3OP=G17~mUD z(lNb93eo=xf-vRr7M$KG4pBs4fdvT>aH-(-q_@Qxtg07aLy|w?Mn^Ap2dwmxr4)Cw z0YckU)h2 zIlJ7PSE_5xd~xyDUY!Ix!Rl0dlLl$pXFZFph*?Wy!rKa2ivKyZq77#rm?Wf~nrWi#bn0S|AzI5pwxV6@>ez1y+{F^4~5mVy@YhJWjlb{Ahc)sC zm?n7@45x-&*~fO@3o|x6V`5ez9Jjhl9CAxs{*vsVIyCH9({tg)vi0B-mw&lM<7-n4 zggX`GrKRcEV-NTO)6cIBz^FxGX?BU(%2M_{!=4n{%JSveYA#Y}xwgG)TeS6>I_KFl zsnu?lO%%PWpo2B-c1=-4ICfmgSUgK0JAt81Z);Dc=%?weQv`*I8M)}7Z zzzztIp;IAX3`oO%hdfhPU6ck zJR%pVS4OvMSzh|D7^p8v?)0j9V6>MD5+XuHoNyFjW0TWvEqu2f+i2B6)A)k3e5g%! z8{gtQB)f=m0oCQF%BG~n(hg^`B%KOmu{&pBR8#L$PILZUacBhO0IeMZ6}>_YhiW-w z+ICF(c)kC3=-#u*^UK9Ov4FklNEZ&h2*t$5 zd+xo36ap4`@v+Wtz|@4}xPNL+9oMo%WyF0!CD|XZ{?C}e$whidOdD&1x~#OclctBA zEs*L{zCk(!51DkVy)Sbbt6dzasVXO#Ibr6ps>4!)G?LB@Nx7QDnpB)!)AQV>Qx-O&fxTOlllx@ z2{eX^v|ZDcOl%%~+uuD?gO@JK~rJeNTpNeoPR^-~OYcX?rs$(m(0qt9boh zuAe_GV$AJM(ssE`mTsR)a`JFKB)7zT`sV(#F`axnoldqM@RCX^(NiBX*PP7tdlZ0&!sa|tQFreQ3+(i?y z!n>y%T8JGC^C1!;ExHj9&(hDYyS}Eojbs;q*@5+GbgYp}K{6Gp9lsE{Y<9GZ5}XaEHf7LZEd)<^v3W)H-`8 z+2!odJJAmt@Y*h5*+2m}Lbi1ZIY$kdj;0~vV{<2B!fnGF8kZ-&_NCMQctKkCR^m1_ z858b$YzWK*ej`}x+tIhVSa}s7fdI0kYiFrAzak>7f1>_6bf;yF`aa430WaWjKlvpx zu%IxA(zf`K`0cRa8zZYb+5x;M73fV8KYZUu$BvZ3?kYB24kdE<`Sn8hzG1SptZnLi zBB?w%RgrRmky?G8{6u$=XKlBiWg55gMS+rnK}`YfBrFxE$b`aF;YKfKagFi>Ii+SN zc!Vp+-gUe?vK6i`D)J@}*@RwYldcQd9@oRqR#H)5Q&NVg^^yQEe!habv{mk$NicxysuA9sUm0Dh)Z+w@<)~1 zKb?j1!$QuF{Pg@tA6z`TJsT{Ch(d%ehGtD)c|L)s8;Yx_R+{U{9yd;=j0h+<8P~YE z-32SOEg=kj)%TsF&GxMQupKWtT#W}-bka@QZlSAKB4As0^_H?1kNEQ{7z4)6rXXwy z^jkaW8PdyK0@aB;Ol5xRmwESs2?c{1>l5k#P8?z-(Cv|1lsvs!U@%}&eVnetASVtq zab^zAYixaR{qhpRQ_RF_4z$w+JQVLLyVtI~-_HcEF%YW)*B6Twe!)0xaANyH;M%h0 z{m(uvmMg`2}zbm>wJ@P_gs5bFT16A_;SSE*DsM0YN*kd1o=$S z#H#tkUdK=lQ?*!O;FdNbN|Xqpb5tzO zSo&7qcz}%BmWH@u%v7dkr0QDKXlZd?>JwOi>){n<)b&@`f?5|zmTo=X2c6cXix?1>l(3Q=T|cPHT?Ce2iQU~go{CY1sD@G#W^cSG0w zn_hgTj`Q@L&cuWVzKZI1y_)`&H00qFUHuqUMEXTCI^-c!;dK~lhS?AYtDcKj=o|0A z@`{3aNG6O0JVq2&LP61d8AFtWsTutH7EBk3dx%sJXHbwe7e;3dl1q!_RlEd%ZG?*= z>zwx{8*7r(4h|;PRh82+RgtKoEh`0MnAxL4T%`LS^0{-k;8m}RT@#=fYkGrlr)Wd2 zx{OUl_S6Sw%ig#MpB^Ay{XZq|NR2HjHTaSqu!tpq?q=Il`H3CBU3huQ5H$*F7r^*1GQ3- z3K~weF2`$JJP)xcW?oWoki{Er{_o=?BjY`?d38>7CA>W2?5{8?0HD*i9C6*z1ewNh zE95+3l~}sAlu9W5FftMh_IupFJNg9XenVDBTD3r#U+Ii6pvrjR4MdMM{kR=%^olFP zQ^YX>Inwx(Bh6j*Y|EQ~5#+OrzsMnl)~1jup#af2g#KlrcOUVMN}dOZNw#w<>#EQY zO}Z8w7%r(9;?Su#N?hF)Vid`^V`-^m^yEArYxSH&LvIX0zoQL<6&s_-f^zEc*~0bD zef*=t>5^X6u}{)D6`&0h6?4*oxH|k!C&V>Ap~(pTYDzFKvlY^iaT%_P+1>=41bz_`a@0;lzsW1HvKU@rc4 zKVw)~d)d{G8Aygr3fB{AZ`CvW*}=+^y}c77Xs7Xq-Bj`e$*flo3MtUwaigC@fhJfj znnYfq!ZkE+@c}~CXj}~E=J(y;%4`n16osw5N%gKU$LqO!_5^o0+f?QLs-~@LB{ou+ zNog&<_ETYaF%nC3N2S)dGZ-9s*e$0~77|(wVr1>@aC%N>pBvDa=!3XlG`STJ^_%AK zC*JpM=gp6O21?aN@xjVJar*DV7_>|VWk4ZrylK|qPLjXIL^3p)a;jW0m_V*vkdqSy zwaKYjh^D)wQ2#3nhpU-l5POfc7k`j`S>_`EOUz@>HyROO7)Q(Sb}Z2!?n5m*l|6iz_ef zytB4A=e#-#-!$jOAq-sTl!0erCYCM)fZ+!abYJ;Q2|mpopEa0wI{lz(9(o;gLOp+R z%^B6x(9mdCfP`FyU!7brsT=QC)|}jxK$WP3AEN#1n{} zE&|Gx_ppqPcGAUoKX@yY`eDFNNNH-%KcAQ$d-GoJUMsHfB=0;}rLXNt(+)05j4eQ+ zLwsWklDCMt04M*%cYFQh7WXgf6J`!ccOLOTgRve|)s(YM%f4rq@v*|-NSQd_fPlB4 zp0p$@H`Ux+DZW>QhD_ahF0n`<(;qe<@fP^1*&q5i9+JK$ag0KWJ0Yijo5wyA0J>!X zQ%?3%0k62{S@R^@@Gc}11-8h)o>XCBuBuq7L0}HHM&FS8zVQOCnD$-<5|Amx+%T zt^w|O?83-T`=rB)1ubAa?7O7K$jwnjtIi!B>Ta`glMq)HBKVNRD%A1Vz}C1PY~xr+ zA~Q_`y~dl~XT0a!t8B0vx5c`IXhi^fuu}K)m*1Z)3!)SbvaxU!OVVAa-&IXxi3c;H z+q5w4srsbw#n?70`VRkyBz0Cz(+i`hAK7|b#voOuhzyMkWqTVn`JWnPf&_K7q>o;f zh$Y5eo)PsRc>|>8?#I7FV%6B|H@(1Xg%Pi%J@s1dsKXz<=hOY!70NdKEpqR}`BAet z>ZRvJLeHMmZo+Nq7|vK4!8i4=@P^{r70L3i0xFec2KfdBYQ5wpinVhc4Z;NsjSuh5 zjqUIy1bJE&EMXpo33*V`wp>Cx8;BdXBBjgWENpvX0K#%zv;NX*6Qo2 zY~Yyy#Sx+pf|t^rT=IjF4_tRJTh-48Jr|ke6#`_;`-55$f;)DUEw6N80!9$B=Nj_r zmAZDFey8~~iE#A!e%OmP@PRlc($>R8?uq@M^t{ji%d3Ch4UbEaG?aSYUgoBA+6$Blw zI^W8tUhUwzdJMNzzFzqBR@;&buZNv0D^+{O^9{GG+SNL~gCYM!%qatda#4yye@UVq zz^PWv?&k5bwqJamQf(Z*Orv7Y!Fzqt?uo`0h@52NY5w0Mr3}K*PAMP~xs4Kt!kG3M zr29$sy$y?^PS-zLOchrm8A2BQx-@kCK0gYE2FS0%Jvu@^^MVhOPK&wv+ENTBw;ND9 zTu)y2aqc05ArXk-MaF~|KuC&!KLimE?L;kf(0a+|M2?LMjiDg38^wI$SY-!@^d zA#Br{u+xhg3>RFnSoWrlKNs$#PTXYGwy-fs&fJ#9TjYD?nZ`1W@LdgE`-n>zBv^?! zMFJ(LBtT!)@K}J&C$@`749Ax$$%lnvWp+JC;)(Jj$oSTtUJcED#9zLA885{G(oi(% z@>)e%*PgcQlMo|BxV%_K=xn;ubXh0x)!sPLd9EeYGkb+gwCZp5 zC28j(F@zKJwxF@Zta50Cd~+sK1Mq`xw|ZPKcN01O0oB0o>GNC64E2E+Oelv&f=k*` z-RviU-h(=W^P-elPuf%H2t(z->;PpcGuNTn!n^*74-QC*uw3(vC%IT4riM%$95bIo?aGGB+`44)qfmT(i+D3)l2u6a3Xy#$~1`{zsXJWU+sm+}KA! z$;`oNAkZLX7s5F&i&Tj;EKLtptA}*^+L%H;G)Y&5eZ53|n>O#w??*OJR?fP8W6fH7 z?Yee(`WP2~Mi)69D^jcYmW<)0}YLSJ0ND zEtn65G^N~v7HWOC$5Sc#y@7W<_2X%Rs-{%s>wnrtFt7yCcqsbvO%ZY1aT1TTz_rzO zcX1D1Vl`wtlVSKf9s(yuc;(9Cf#rg*sr#uW@_7>01-m3xaIPj+CrP7yNT|`)!@qeW#w)VhR!4;5A|GB)a|I(|dnxbF zRo=;A^v9%4MQwVDi;~=(oggVLB)a*5KACe{ zs;lH=k53SBa;+&ZvGBwHsD9-5XW@yDK&@}$VrW+SgB$heh<>E0mpq6a;(HU4-0(uJ z0c-Gzb9%?-|*CA~@ zV2JZhAwMCBvZvu@lxH_PFPGA_PE$Wp6zR9i)t)H$@#ml2#=k3bn#bW^HqIDRnuU~J zY@2=cJ^JiYKPMyk0l8<6AXz*M<-J4e$D6jSvTr+8&V&t3l%6&C`{*8SbnG({Hc8z# z%CmSEvb=lsKC5&KMp5~p$KNN~;2K%Sgeu(~*u&SdV5ARD_gA}Key^c%HGg1oQ7`-I z25o4C?hUVJmluC8zm(b8JHJ31EUrv9G;V1OmlBpnr)j;I$9>T_#&QW{%SXL(jXz1f zTb};iIhYE+U`n2&<^10 zC6D5WCUDFzU|~mJHr|4pCRA&;-G{cDrFd=#H7ZYDbp7W0&t~|WvQ0|Y>j^Skx+p>B z9sNf$8HdEI5}NyL9Yl=t8-(xyNtQbqc@(g;1Mv7&>%V&c7FVvNL~%ZLpLbx7CJ?O) z^u9kc>aly_SG0IFTKzW8f-YO-E#{gXRPmD0lk#25XmRB-Nm<#0CoP8yKS!(n+&iCm zmOX1>tmf{Yd+vnql29^_Q5y3>g3L>$jIWJxXUq2zqV9cVtHs;HZ?srcM@rNHi@jXH{oeZt;J zGn1_Y2dhAtENOApp{jE>_~{z6{}$u(fJAPijrO#%@Tji1bRT!=5xm0AI139J-bXGT z=Oh)@-{afbNY4dFLU)RkSmT0%r@@~QZYH(=ID>@P6e*=yqX`-{G!_Ef{5}|6F`Fm2 z-nDHffW;f5=4f30=FMuYwSK*RtX1L%90~8gb!TmaxRti};OjN^-iyOmB@M8R8rE)L z>0Az1*tEj>3$DgvBloMVYW46Y%KqsgFFEHk!9Xu~A4zy0m%W<`d(sh;EH?vG2nDdY zmFmB8!Z*YG)29(Bta}T`nPuT&2_JAqlZ0*yzIg4v3C};`Tm0d8=3PV4nRju*HY@LZ z0tADszLu4D9$ajyU^&xI^5R}V!12Yvy-(nKYty4mo@<#-B)06HT6jxw}~5hdM`F!Ofvv-{$6K`2#8ammjh}YBGyw>P03$oc}`$ zE-P|8@isT1yO|G+kr(}z^ti5FNYy5VZg3;u8BZyp;^Ul+W;XO?n`7pR=pZ@XxnOWe zVdfD+dHhs5A`7PwMjf=CmY`D5pdLl{at+Cl@BtrEoPsz^iT9_5~8$86@g=<@%ePUm|7 ztD>=eK^g|Pd@2g)vHMaGI~7Y3!0oEThPSwWT){+5x?}r5fjpP6(tA+v8Ld_(8!GnZ z`fCc#XO{wt;4|U7yt%za7SPi3w%$e{k7)nR2pmQ&bC3bKi@5X;bu4s(DBY!I-^h2Z zD)5=;`!|$22N!Jlw(~EkV-YtFrH(1cSp-lA4GPl{=Ds3KP$307UH^WYYI$InVt6I! z5j-F`o`7droVYS-rD)>r?2kWDWg)OK4QH|{(7Uyno06x@=nqBiICr!XB-5tb%$cXBt0f_n0j2& zUS>ThU?S9R_^5p<6%c&+BiBO5>I(~&2GP0)AC0i}NoLfz*d^qGs0G*M;_xh<`86sg z_#46>DHVLvxJddp_m+>(u+bH41Yxe}gUReMVd2C3guB0*^du#&+Qk|S1LK)gJ2jr* z%K=b28(bRrN~nhyr^->ozR~iNf2O3F%(Rvnbxm2%v%|R941QmTZPa*`cNfP}hCx)F zCLW(6hd9^Rl_rWyHo2;A_Oq2KnZqxy1T$Rsl*`PWhX=Uu-%~>G=ezPbgwc`V>f>;s zbFA%%0ExGhDyuww-tKZsUI_km&4PS#Wo#mFms64%olY6VKn`-t_Nl3SOHTGEz1Pzq zYvab~_2_7USb07uPR-Hd4;k6#-{pHVet+I)1wNo(iXZW~hsj@zH_^eO%$E*k)5>sB3ozaLM#i2F@+On;CfWJ%1WEl;4=NAl)j3BV6l%Y|ePw;|G)Dpn zfpxr#M{ljduGL&Hz=%Et#B}RNCn#z!!quILZm0#cX{EC-_}1ED&xE`K?-OPl9k=2a zU^b-n4b8KpbGhU;lQdr%SO|Z?C*Zt7PbRnP9*i#>MClwb5!w5a6M@T|%IF{$!BEalYSIW6MHlwm$aJi>ou5fnPDTE1h5rTS`~<2*s+`CLG% z?uHW=tCjmJ#yoZ5L|b@1!Zh3jMr_VR9QcM0J%_Z@ZV@B;L`qw03mX@k2$!NDcpP#}Tm(mS;;JUd=WQK<#~)mO#}jzwVB!7i>8f{F+Dm&= zS;+#lj|Zapidc@{|92aCi}L=WJrU*+HL2Sd@tXQm1ukxkX)2a48A!Ab0 z;I}+`1ALF$es&urhusyFj{a$!RK;rN{wixhs`$|rh@VzSu*f+DFiC?eB@mi_$mqkq z6Y^YEh7yVKIZlb|(NC3e2c zIa{Hu(#Pwmp6cDo>m8suzFid^ls0fxfKqc3OB0(TTZkM^YXSV)I zEkfheiC%Em+#x^*2ICsGvNjIICf7a?>?KEjj}@M=_J1G?0sq5(BXE?y;Whlx_<;BM z=IQV8FM%u6`TcVE@ztho^ayz~j>K)S2ZSM-sDDIr&bivG;&b-aV&bL(31 z5Fa^oy1jF$GYwHu$=i{xEt|k?M|{yaEgL`Cb9+-ZTd7(CrVswJSE7FSn7n~qD$u?qB5rxO6;eF5L^@yfD5xApRL9z!R4AYl@#PU%L!0^2JSIPJ( z(RZberNNF;RHaUa!u43X!S(CfnUjaZ)xz#Pf0`>{cb{Jek8|R3KLZINwYVXpI2iBv zUnK~4sBF>jEY`hsHuwfPFp6p_%z38BsUH%^f5=U?6DT^`Mwew=>nNztbZ z`5Lb@(^TMS%}yViCbOOK=l2g=*(Qo@Z#~Bru03jhd^6#2@bUKUw0y-*A2S%D6#R4D z@>`rm$~?mwnux z9NevCZq$Ovv`e7&*}gzh*Hg*q&jldaB!({hmy!4y;({EtC1m=t`j1@^Y8kRV3!q7E zEN7wwp0L>pL=d3|-)E*J@9>;`G(Y}nIvx&Q^4Q~P?%{ub#AqpG^gJIp<+Q^o_qd^O zXVhZ9r|qEBDvugi&Lllq$YSwwlCM4s@yxTkU=|ZadV*a)`Tme*WpRIX6{s+V!}0|n zY)1(UB}n;%zHvrHe-uus9(4^#kYx0Eo|yS);g|uQojUK9+-(dSUIfk>IgSaBjk20Y zZ6D@J(XUbuf>{NuH|@``g*qsCpTqU3k{@~W#Ap}LRI!6!{XYbuPIP=fbS@8Ij2>wt?S$D=K zkPx>Rb)KJ5J3G5_F31XUEhOK5r85rM#o7yaiiZzA8C{V?FF)$}TBe)kx)WtCfO-Vx zL3m0Nx(o~(0(TGOhJ&|&Fo42>0-`1ZObCfYyhkp!x8zpkAcZjQ_su}`7(GOfQ8&3b znh9`yo~#@QIpof3K$blrt1n`H+VXEbvW$RLt9!C%>5)fJi}D(K?per$9h&b;h?yR% zHe-y%Qnix?4CE>X53O~HlI+3^rQj=G@BmH9YYG1(eq|sGn#M(Vdr5Q#e@PO6(G(G3 z*igz8f<&mtrxsq#+x!if$H3j*rz|APw9>Ze>CvTqXq|2(a4Sw+1VUH&qTnwiA5;PD zscHQEY>Uqzf=|AKe|tBvTiy+c+UlVKkm+VC(Zowe#S&=FxcpJfK`6Mq8KEvA!no;= zU239(=9>ZF7|G-|S9fCwY;^;2?p$T9&yufHtv4XXXfZ)Oyh>XIeoG|ar3i-?l51Lz zGi^cNxcgwSqAXm{IdI)g%5Of>#begG2*K+h_!x9iCsY$1K`DYsfv!v)enKlDq=g`M zaBzwC4AB(6>$d-f&QD?yrL8>(Pn1B$qs`d3@8IGCyeuYu$bUg|d(ur-=tQtV%`2Id ziNy;M6k!9w-k=QpGN!6HhQyf;97Gx+_q83`HTQIuXJrgw=4SkN=k$P{s9#V`QIAi7gzJlFr*eQ_ce{dmX- zd+;FmexQZ*BQ?j&6c$lH#XbH0V#K~qp4yP(qotE%?fLSajxfOUK4ZQyen2O{qje}8x&EpB z_x=wyX7>M&5dBJZRUls{i#ZQQl$OMk3NK7rFvD>7Ioj`?e^^-6)N4-E+hZAjXiqJuW0S9g#mih8MdwiAe-`b*MXVC=yso z0SO-~f1q|){e!@}B0iy%X7``P04F*9G%;pE_bEj48M)%{9QgtGE~dOs1Q$wGsqh{j zM#=<0CXnMJyTsf$oQ{m#KWowz= zp_vmcmWE*mPJ`!Ty1h}EU3a!i7TT7dg(|Pq8#sEBU8ZO!o7W&p;)&P00T@)qs`Gxt zJGYuMgE@xoA2lta&p2`AQY{(PMKHI2d4DCh9Wf>LQ&;BZvt%m@I7s}|+Sj!y*6ho7 z$yIwshP^RX&2ctmHDc@4M-P?U&ieNc)kQ~NF)->!`g`VG=mNa**Qn*G;1k`syAVkrxX zkTiIS)5i78Zr_S9{QSdi`D*ZET}|_)0G}oX*?@G%XrVmQNtteMQ616TWaJGVoxVW_ zy6I|z*DOZfB0u4l3*Y~WgdPOvw%ZpJ-rJu0%;$0gdtT|;AUeUn7Hp|Q!(5}m>kcLj zecyHOX`tj8Vjih#3S+rOB^EO4Ool!YSkta|90yOEf;Nxzune_W~^d%DpPnl&tfq!a<8=B5QB;<033`<+neJ zZ4RwUc@4T*|UD@_bmEP`QmznG9w@1F=^to1q+`;Yg%4um@V`rrYJ^qky zD?l2s^VXC1==nuK8u%kGzWRhPzKH2FW+gyy*!=#Dlh0!Sw%(2A4Xa$rtHR~W#Q}>M zJPE{r=Q58G)Fe73k|>+YQBR$h1MiS@|B@f@`6@4NIDTjM`#{Fj^}4D<_Lj%mi+E!$ z2X29odH!0H3}y9!NORT~Vv8qJ#2zml8JM~q)D^72u^ksr$ z=DO%0akQUk+M9#$V+@wKKlt}Sn1GV)TdbJn|(wj6Q<@E z{gZ{c^RnxK0PlMb2;|e%$X75WYuM5|e!6B*1WfX$47rqZD<|;K#$Z9_$@~ckcce^% zo9m1?A?Gvcz@l+gMeO-Q4rlbgzwS1^JCqeHbXl(UU1aRxG>uXB^M5}W*3V5oiBZh{ zB{~R}+|A5Df(xfkG{Dki;xes60)}N}3OMPlRx87HPX{!A#d!O59 z|9&3cKn98e+12&imn50Jp?m>hql{zG@zMOu2CQtbA8T)MelMc}(QJUNEo7cRDD9nQ z01c7A6&?zgL1NcqwtV?ME=XteS^^Sl*D-m>FhEa9BI(!PD_mYT_f=(7Fyzxh@T72r z8=l5@mF)BOcKDy?rjwqSggOZ(Qt^Q!Sje5irq1u+|1gPNt98UnRZ{zc+OL3&b;FO? zWfT8n&sCl0EVVv6w@RW+itl9s_O!!#m(DSFnk>ZF9nAv18&zzQE0$7f>7QLSyWtD3 zks`|My}pb+7tD)iP}6yKM$K92+J!#)?%_Q!spq&=S7^vMLrX1-2@GlwJZJjP@7J>S z#>?^e0JcVAds^h#C{Le_sUTSz(Xw9bBdWwMCT`Hvjj98-JD0#izqj2--X|In!#7?F zU`jZUZRg&G_djN%rH)ff(Sm5eA%{M1EGP356pfphJfm{eSsq1nHS9BC(wEqlU0`m~ z-QM3JF4R)$haI#{WcGMA{7lMr^dNiozhgSk=dtzA zvsyCpdVF~f%1w#_pa?=a=fuqU>mVD*x^m%D18E3<=Yw-+1d!N?VklYLLDl;0-*(L^|Am@Mpk~Rhsc@f`S@Ps}!db)Ql^?TN8_e2MiDbeUJ zG8CL~glo|^jQ8eV+iIsh@AQB4wBDd;$svpeshpyc3UIqVji$5ik${y%{^C)@58X>B zju5|P6QX;#)5|9IVeI-FV2x-;yv$?ySyH zGxU3t0Zi7Rzde;G=_3>`bD2S2rYw&s{L9mr3z8dWG?;f$JVCz;K@#xW$?vkO#7bK} zTk%*;gvFC5g`VTDOT;tX#hHhPci4`+^?0y2!jE6Do}M{|DiX*HG-(D>UQf1y z;uS&!{J>b6pyE;yWC~AD)ZbEt+hxTIPmd4Ia;M~7;f;%l-Aoc7dm^YlZ}IOJYnrV+ z6r&hy6&-(X2r6xjZpGum8w{_%D+07QQvRBXWUkfTgWr)tawH8>68ehG1e8q+1abgZ zsQ4vS{93vF>$*qihSO&x_ZO}sRfDP%H{Bh3eg;FpknHr>A*1%lV&}-9cexv^z-3JO<*i9ShWc%M-wYoi!5+kiuGi5oVl(06By*INl-**{`V)}F(Xfpe14jJt9t=_|GT z#yLw>G=Z_4YyN!ma}6?aEe5g*=?HOV)e zQM#)SM+`C9tN5c}-}9do_(A;hB^l%}?s=z(1SYKUX9pGkJ%>aS)N+P*it-`aBdrQ;4%h8iS_6x|jwl5l!M*0OI%HZeB<*@Wl=Tt3!l^&I$d zi_lr6-av}? z>lvPaqnstYTw6q1Q`*A#WhY38`c+7X>A(S+X(30>r|+^Ojw#zwD%Z&nfIBoaV`@A| zMG^J#RKrP8&LEM8B5GG3I=ugJl2tl0wMnp=BTv`fB1FGBJ4AfVmF%{*e>5*b`A>1S z^W8kqm_6F>M^{{NIaLER;Exf;8D5=#0uGY zk1OD%t{W!(Kc>Dr9_zP#-`;yi_8!?3Df6~BktAEl%C2l8E9*8xWG5BLOhwrvL`j4q z6bjkvcfM~vzwh(c^SoZ4ZukAZ-q&@W$9Wvbd0yNT6W0J5;|VO55x-IUP319i>Z%1U zO*Pca_}vc|t>y+K{zCBggMW#UeX)rRhx?He?JK1TTAeOZ-ue3)LNvh$iRE<1NYgOl z{{jg`)W`w|h2o@(MJeN#;AKOsm>58m>o8_7;H&P5unDBpQfaE)^M@itlL7X39RSK3 z%LW(D8QfqmZ=LAKoBlcviGXN3CdLZSRMnFcBtpQ7sWaAGWF+QfL!wbEehH~g&NHJI zEQysI|1sc%cM<{Acv*Ni%-=|bv-n6w0M8g!oqc$mAK(}V0_0tfF~ZwoG+r%2M@p&X z%y#`#6+YnVl!B=L-MQF*>^NXg9%6p2wqU^g#YXQGj#~*mo~}KV^;RSa`WWup`x96C z`P6pcUHJgcB1(oVi(%f$L9>91Se0R)<6<(W>ORE z6KYco-i-QXcDCF*P1F9>2*+uv)<|+5HdN(vCU8O-#>IqwofZ-q*BJ<@Cd~#WM-S*s zyl`@*elQk&;N2iqUc0xNMB7Xx@BsEr@0^h(rRFebkky<;{|VftZ0-UEI>335tZPflrq{joZ< zLbr$%(y_*>%>Z9&DH2Ei=R}|#fsgOUGKH!mD|wgsKXnWM-Zx1SZ{=LCIG?E@g(besY+Z6X7euaYWj+LJw9Vr-U3QE%-&WfG^%A%(4!-yqC=xP<#J$?L-v& z86W`b7kBW%1;AH4-;<&N%vyv98=%Txz~l~Z+AC1GBVydNjsM*Te~WIymPdtP7Z@Y? z>EI+k4G9!7BIJiom9v;!ofh8xx`LD(`Z;EP2q{{KKKk0^DHTsrHw3O9z-%F!53525 z=RcgPQtKbHAspqvty3kd+TGqrJukGc(uXTfyolGnHY}MH%e8OcA&S#e5Os~JDca10 zrtKRhKE8+ZdFwV}vI?&j+^Ud2_{-0ij2LAKNP2=FBb3LmZf&Nb$ytHnQ}yX#e1la3 zxsqGJhk-B(ORavg$+?sLuZ#4D*P3bhgw=h8Q1Cn8W~dDh+`Hs~p0bA2WGkb zh#`F0Cm(jfOIzt$?Txj5^9O?@{Gklc1goINjCzHZ#<}xZJGL#!|(_ z0bnK&r*V0?%UBIm!p7B)Di-h^M%|tVNO3u~JvZX1=n*ney%Co21E4a*dGV2BNWU`n zxA#BA35yPdS+l@(qwqde z@D6YbBJe8qmlIhic!}(|{1g>_TRywgv!sOXRg7EWvhnqmPd>A=ns=>*?(}A9mw^<( zVo=derLHHfecZ>qjJMoXW=Bz&;Ed7q#7Q84dBf+bAS;7!x7F5@1is#{eqrKdvrZFOH5T=vy?%EUV z1RgnN!jIO62T=ywVaX{w2FYnl#QB#bwB4C%g_oex9dQ8>Kk!9FB_nUrLcQ8Lb#}$J<*g2G0g}UL4iazw?c@qw-n$wtcKY^rbUVomHoC!%4ANL zmurbi?sZV$waq%iPfd-CkyZ`+8zT@2u$FI@UEiPDa15A^BdWDtI1Uj0$mduPdv+C` zbhuYh?sDbX^DP+V%|TZ`p}K+t*fJ@4JX&B1IyMn=j`kG$rx3mpG4G;KZXn<#eJiPb z5UI@#?`|DC2NE+zPIgHlV&;VyP^S0>Hta_XlbuX^VTOx#%Sej3!V5&C+_;G_fI3~L zO|XVU02->_W~ffKxy{hU0I|Xy-fc?PvpPlW0kO5p{-ARX14&y%fOE5QL)E^Zl(2_i zfQ_jsbiV<7NeUN89e#uNZ<=N1n8+z-ol)nYR-}3XY#;+o5D;eYL13xG^MTBoNTEd^ zduyDKr2O6zvHp#!mn@j6a!$Gi1mfK-z;(C})UYPi@!R;Dh+#?xfeAKlmURE$V2pSch7h_w z71VRE;p5WSzk}wqA9PHN!iOc-7rg(ce$2M5o z@C>WnyG!3)AIqd*ny4;hhxozoCl-kJMV%Je`h0H>#RZwq!2mQ71aeR%KXmi<=A@2dX)T+bO?|;I zN$#7^wk3S#nkA(GlG~H_@o2Y5>B{D3n=mIC9pxcIV(k4d&50-***i2E7;YeG0x5(R zt^D}UzX77=gC7USPsEe4juT6(KI&YoGQ-ZMoKkf6IhSu%$ltHpN>=-Yp*4XH`rXwp zPkdl~q-v>6Jt;JXG%j*GjlaS-Qu>$yIMW90>D*x91i`oAB(EvHB{T|iEDV{h>(74sch zy@<9~w9){isSxHmWtwrPM)Y0@=82szu*stZWhN5Prn{FEZ**j6nvFHdC{6=Y)9a(;&m z;ICG)0;2_D*Z-^?nrTDd`@s~a*0JZujf1hmTT2>5FtGiEP` z-v{}G=JY%Q^nYz@&glQk z>Uqzh^wRs43_VxZl@aihC&|_&jVj=9Y3MMX>DszydQJczo~G545MjNJB|y~4(^Nns z5pP50ZzZLhP)KhSrNnW8A0(X`yv2j$+87rVEU_|hFuAEqNz>PCOb<`V2t>`>nnI?v zScv7IMP5Jm1bxU|Bf%pZu<||o=Majwg~QFMKuOLuK}1r*4|I=jwBjj z+B<&*8B_oYK=DlICf7!sssY_1DN+FNXk7H3T>~0JoB$&Gv2h1cLeyZGyFGPjZct!W#{c(`Znui5@8;4^% zc4)6=4W*{Xtg<}rgW!;^Z{rriFCYNR-40(<@?#)sfd@*C7m5dv{(sG|`}tFQjbxZ~ z;A$gk@*Dw+TgmwpH|PIEj(PU!L`e0?_$#8%w@BAB^xdx`DlxF&G69aFQ_gy}8{R*NttvLaD4iOHXbAk7w zW>B-8330T<=m8BE#d)&J?+!NP9!OJ1XL(!0{U`c5A^`h zLUay({4-pNFRM@8Su@$g0B6%a#myzIS-qnQ-Uvp4yFuyqCRCAtru?75?h)$W!*NUp zT{%#k(?7}>%EQ@OmHEUHVmxH{`18;Jbtl7T8HdRVt&rajC>3cW(qJf#r`MSiwR(bq z1qEaP_tyGJUf(DU>O2THB4DmyN;)l9-8ca8%u=AfF(2_`;m{~CBuzk6x_L)I05;ke zZLFT>7~`Sf_M>dz%)J0q703f-1*0$23_rr1@5Zcty$XUx&Q8ojtEhw>Mzx4F=w>6k zfyLr z|L_ht&W=M7Goq&)bA!#3%Z#Geap+Ubgipe>Hg!@s#!S2=th`qKFcfbb)s;^3je`;% zU3-qwjbIMxiNVuN@ZwHTi|vH&m*FzJ?uY-uPeVo^!wmmpoXaD;*B@hwK|``hSF|(4 z$AEMA5XLZC-5~byu3k9j63|gf0mUU(I+h_TlBi)z@qiwFoil)F=WZQ#Dmd)ZxUivJ zLxWF~7fTuik|_VR_i%zPrPV3J?j0vMW;3%89hLhN5Jp2pM;x{B$?PucY1&xMaqMHK z=*9^INN3cU(!a?98Qu+T2I z+ZRwZuVTmOKCfJ+xfl%O#UQy)wNo#^^JG_YWTefzjofNX9H&2dY*T@mI#IjA?j z?)W2UNO^R{!4M&`o^$Emhqa#vYGtL1m?V5bGuiu1aEQSW$eA{XDU=|hZ9}F2SrEJc zs5mQ)nykM)1r_Uz3Y6-;1jkrV9!zc$2Lc5**R0m<&mC}08LG%jurXI;O`I^!$N}Qw z5Jc+!I~Hla1cK|9VbVMDS_6vS4BmIXKo=y0YC{%ySt;-uUc&y@<~)NleB9rp;&m?v z!eP!Fd!j$J_ZlX`{QZwS#1g7QQrUm#ywOWome^yNJ7#8h{EEpqaN0`GF5;+QkEkw>6t(?&dj*ze`3%A^+5ZiLt5Vc2?7H9x!T8JHwnV*o8_*#l2 zK(`xP(`i!#>!fFcaDJ7|R?odQgHA^op+{ilc4Ul2u;G6#f2@cUllLlui`)z(gBBni z2Cd$gLk?2YegR0t`4eD&fEJsu=VJtSa2(!9DKa@n4ZDHLiwGhzMPI@kx_7(~WOo@^ zY~yM6G=J)~!M*47H^$P$u$)Qy2~4BBxOFu>Wg+Vjbk78o2FRQfLChn^Eh&SiVV$*@ zH>-oNhoAFXV+|6Od{OdXJss~M^SDTw1!8#zB2G^pQ_e~HU(7upW5h<>!6+!!+`eDj zBJ9wFUwqY}1QmgHt_S{Vy(sn{SkWpQDlR5JLCRB<$Cv&CrRlDeX$r(>$p%UI^5r3@ z@&KX`&GB7PYv!arv~^+R#GNo@*UXTngkp!{bylgSW&M_I?~ph}j7y)g_%3Xl4eP*)%a$-Wa(7IQ0^3lHjp z$U7=3ni=+Nf9fXvZs~p$6$gG_vic&#b3yoK!Be#G#W@#}uIFUTkzsSP0{BVu>xBuv-^jSMp;(tA09Jd@+7qX7YC69*~;S^(v!OG#Q`ZRW+H2byZKfyOc2hDE`vlFnP_J>+LM=S{q5c*rwWE?TQ;S9{Jc|YVFISdFI0I+Ah8b8I zgcR?2B<;;XLrU>K{NdJx3+nIy8#e#g1Z|q|v3yyM!%9#b%>aB1KrtB5;OChA@QJybP^0$x6ffU{=xpxpIScd z)A>Ppgj=@0WR7toC}Bsj6ka_DHA{B&(`C|gGXalKPOjm{#`P0uQmj-WOx|8IYE6N8p=P$w!B~lq5lz@dK z+i^5Cz6w#NdIO6mdN14tv0GT|@rbJVpp#|gMKqH`@4>=70$0Z2Ri8IrC1je}(ri#2 zP4u(0LvR=tj3s^c>eUTlY#PeBa7|kuYEYwrW^$ro zeXJz!f>;>k4MNs5`N?ZDL&{Fw8u_HU39IPTgWzRMj~xf?ak6%9DcWsK`zHFo?b<>WiH?N+)%qABG76I+3Vo+GA71+tB3|R4 zrbt=cu3QX8$4Nd#f1uKut(F*fVv8s7YaCzW!F@_={~0^F5MzgdJuc)9W_Y;((4lKkfEr4HWcuR( zQTqX;3kahDx7Yqpx~L@t6o*7)S)eZ`S{dl%Hi?AWqW*E*q7bjm3FQPKuu7FpxWFEm zLGkO<9kMW)g2pb(NRT&)o{(vHp1m4^+V{-BYkNS|Aj=-ZjEOimDuO%RV`Z#2?uigoIwlIYc} z*XXt$!?a8|vp|R7RgLf@b)jFrN0Vt|uUui!1kK?{@(G=N1+;=QFGB;T|1=jo7Y^SX z{zKRnc;zB63L}UUNk>W=S_JQ3wxncAk<3y}R=Cot=nT834Y1YWz(y~|5*JpNQrZq( z%#mU*1&29o704wZnz(|?6_SmAOt!WD{_X`0){au$6+3Z4cjzq82PsOTkrb@O3W+;@ z*+rI#1dHpxA+T2?8S&Q1b3A}X-%h@b9`6-alG;4)W`fs0cyGfT0>R;dz283{2}0H9 zs1?7v328=ZZnLWRR9hg^dyV-WLOGMsuXg4w=2%-4_~ZIV_kEh9zeC}!S3kZ{!FX*_ zN@w^Fb5~FEfj$@wRVaGLbm=^%;#M{5<XTN+?KEMm2g38>#~%%T?nkU zzGNj}2jd81K#H^9nh&pN&FN#E86+R3SpD!pnKM00h1ms)`gRY=Q*?_QP=jf$_h~Uu z7K4&(;x?u|&RITFU${vmw$gXz}b+f0AF5J zi`O6IDN{TA?&#EOo3MdMH){+O_g!X2TO6);3|Fa>pe;%Fm2x-}kVc)ZQ^!eg-1a!i zZIcd4?E0#=J%~>`+=ullGZ({uP#p+P!8;rsC+uNshW&r(k-FiaXbpSfPlAjy|=5V$> zFrw0+ZhEg6w#-$VQ7e=_yTMb5BmWbr(M5S?`rDxw=8n%DURm1$O^HPr+N2rI2_nBM z(2>RJshlDfUxinWF1qJ%31bS^f_jRi`*-+#q@~Bd6Tj_&A5;O}+6j|>Pc*fpT=*tk zk&bDeK5~5IFl3*U*QCkCR9(s7h!CwleFMDnJgQG4VH}OV@w*9W;~_L+UljXH=MwF8 znpg8$2LFS4Hl`#+tLVVS_elGQaU(Ln#gC&Pjmh==Cm_(OeSR>36WW+74<9nxO(^~$ z@3`^WFgd=D=D1ax5=!e$`1=5?5}R^&8rbKdlUEb^E!c}d6EUgL zQ*KK%d~sX>*_$|dN!Ufo0;E1G9!c7jEIHCK(p)%edJFV^nmb>H)AZ&=9epcPC>)V^ zdyYY>0SoIm?P=yo`eaJ@7JP;Bg5>qaQ!f~`1>r8ecRmdbR!Xt!lWH9}5O^&@oNps6 z2vcxzes=Q$+mWdjLlXLCq#=jpL^r282tIu`Xfx=XWB|f1n($S4T{nLZotVNGeou!< zpa%RPl_c)J8xvI_T|7&a9-Uo9Sm1+B_y$>Ud$)6c&0ofUJoh^KtaLMC>qim-d3=Iq7KvCrhzUlg`n1@FzD6sXEKBN&W!X%L_ z@U(P0#+Y6smuM#F!OAyrD%>Y?LU#joaB4hqw$(3k~X`eLw5;v z3L3R@Zm5ysF(8;0=Ec<1iq{u-pqC>eRVGOQ`UMbQnni~sneeaRu^eO!3|&bkq!{Lj zy0uRpdJxMUhQiyBJ_A|d`|x%%LwVrsvhd#c7Vzc+Eib7ro6%kFTif-CV?Twep@Y%K zc)4CFR&0S-R$t#-202z4UKs|m zO~YTr`g@Fdxlt3@c%b>P-^&%&Ecmwf+|PT??z!V*(SDCx%oUn=XHDN%gLuMnn&qiD zE8Zl033|CQfX_A*yD`PAQj#R|T@a(3@WAT^`k+l_ZEo5wcwG!L(Q)TKeINKS_M8lo z$N8hcy7)o15QWQz$KK&J4sx2%ENOv+Ho+qFD7}jk;$pcmDA1NTSb#ug>V-_&e%^;D zWANA-Ma-VcP=+?hq83Cb1}Fi<0Q9)A@CrKQ7kO!)f78U3s4ge>Ri>N~LXXZV%07jD zDl)*zSlGu{h$m*Tan$0%@E`sb@~zEH2j0)0KQB+68;%P$7u;Ft+^zI>>S}!RxXpo`3YDCa{yu~?($_;S{+A(L1hCUTwe z16$g1LxK1msxF4^*Lh%;fTx6SHUmvmonU1x_q*_g}E5vu_ z-srVQhH7p6M*E6}~UaD(H0Q+60brI+Ah;3} zjUCi?`g_jM!Tq+-jAK&mN&L8`TX08#p&kFn|^*WFHe(iIP35cebIBe!16`Udp0ZJ;lqdZ@j$~; zY7F2)1?&9)uVTWh=BIIJ7ap8NC*WJa6d_78s}5GcAK_31g9b&Mx^5tH*=pcQu{R+{ zO%waQ+8Gvu8QUI+CZAzbyiWe5*Nv)F9SJI!}qRs5|s4V zf1QrKU;SKhX4EyKB$uPInNEEV8R~)=TH~lwl<2l?ajcXbhb(xliDiGq9f8?w)_+-G znfMQUHao?qB24TcltSwTX39_s$z0PkQ_Jn<%I{9sufr80Re6Lpfpjz9tj18pfPSWd z%xkr1OAlIk*)U;Edht#q(k?9z|M1htzzTP5T4>{YbC1rO z9kgAjuQB%c-?fQ?$hqQ6i?Q~X7>!wNWWKq&mtnO#3WIfnRrb!DIg?E}`iJt*07Qs; zaKqBKgU#iy{zf=m-z65na^>~Zi#O(}n|x!M6~Yku5rhtFqH1R8W+?^=5 z&MGkSPhcK|VD|f2T!CKi(5iJk=90;8rWMyQ>*RXqWoTHus+Cr{K1(JG?Tlj^(BPW1 zvYO=8OjH3`i;It4>E>{8Eb6nvaIw)!(Kk~UA!vu?NM^)?+^jElVW;|C%hJf%}t)A$98nm?+z)CHwSd$e($(GwL&2wA0Mk_am+$wB0vzE?p`9s=b>Hf^~X&F&#E*r%x zo_!2kZ}JEGEQE{VsfK)ZJ}lMlZcc{y!0(^`++nYCYY{aj5MmMW=JRxTLF*AU0wO+4 z(|8%IKt(dwv5|LVs{+lGLnMeRE+k9dtB^zq1$FQK7i}0$VZFsC#vAy9L~uCz$-IbO zJ@c8G5c_VY!IFXiPECYZ{vPcbyM!rM*C`Cl3#94N4>>&IiF0wC+Vebq@(6+5&|*!XZBE?}^O6{I)0Le=g?B#q#Pbw89FF5?%r z(Y85-Zh`^&TqZ(IiLlnN5y6KxJD>%#93-#${_wx*EveAxEwSyamCo$MJ5;640^zhz zdL>Ic64E{E2@~z4*(@a+WT-veGI`0BfpUgMed2ZSSJB;1-@bht9v+6cQNcHmf1$ad zAiK#bH=Co6 zdH2Jxxk18eA>EqV(Rz>Q!q(BmpS2t(EjMn)tBF-rRf=a@U*70(^0oXhdQ)e1(Me0` zleXEY`&kQei&M8Uf&-NVS=`%#`5*FLjw!6X@QuMod#CsZvI$$Rd3^u)pxBi4rUPVa zVbjTRWs zpRts@{1}c_f|4AcUFfAZ0Krj~Y!8_$ai8=lh}f}USm-f5MqWO%^3UI#HM8CR#*N-j zEM`8ioi57ueYf+)3-$9GHDeZsOO1ttdp}&Ci7#QiiQbZQYw?s)?jj73;|Q7y5omw; ztU?~ArhigZ^+h0^bs}6dmC?)pGM+#L!nr)$*DFH2=7{I8m!&~Su4iuaNuA}+RJZ!y zkFI#Le!4&D>|dR6N?6sJ-1+j_wnL!jj?Z z>K<-@SifQPzvtBh`@2}+&ew=UTeGj|L%hvvWY_$WEde7e-l?}+1wVyGb5v>F%P{4wC?XF@~BFcuSeY)Xx{+3Oxtn7h13Mgn}e zWRMcD6{>3wqcYx1#nyqmK6I@o(1s8cYQ&$V)On&^d1ycT0R+3_hWye~dC~Zo=Nkmx z>abV$-dZ1eFOR<*eYXFPR`ms?ChPjbmlxMFGcsl!k<0sfKT2ecyq$|qW}Fxwmo!M3 z?-B0$`bC@i&Ye5P8V!9EYr9Ud$?4S_uXL$A^Zl1o1C z?289}Ufp~XgempU4YplJM!lX1T8@hDW>j)K7!pZgl-8MT>7(g1n3*yAYVG_xm^UeB zF3nTA-fX22e=E-BY2w;dAB@J%!){L?y+sgLL5zD}ulc|^>6U{PtQ zJm{^{yTsYa0LqKquBRV#{h0WOjNvLwiDO6+yC2&6R*dJiv&;p}e7ZAXQ{umsbe^C9 z;0)(h?u4XbHK{c|G_YJDtO3X2<@KES9c8qrlAH5L`Y+}*2+dmpw9S?ItoME`r9Hy` zvQBxYnTR;K)O1O*A7fr;3UMUIx?iHZbO;0th3=BaCPV9Rm^9;${olQ+@gr!H7K?di zDvzjtDGP;_==bWy&dPiclsSSGypBU5H{uJ?5teJYT`_RcCN^%i;>lCQn&fk4Z|vG8 zw3VdacLBz;vRhf_QH*}7kG-3^VJuL#VfR-be8SUwR0*jX!OascyaIFIKDVtr#`%JM zRVe(D*o}AJzU5m8Ai-()nL})_+qBWv`xns(6$bxt8ZOU|HLN&7}eSDC7a~HRm9ot6z zE6WQc=H#&vhf9?L} zS7~2zc_C5|tE!-AZke*a*5{^Q=9uqPs3osYSd^^k=z!|l+L&H=q zZrCblGiLgdi`H)UUrxCS)J*PYt=rSyGR-`l2GeSb$3^7}*oIv%Ma)*R`Qd?*w&PEo z!#DqMEFlzWe+wh_+kW)!a7OvX!OgU`cYnnsD9?cPsQyx=Mg#Sg@OTQ=cdzi@BFJ}^ z5K0oqdXs%`03I%a*ja|1qVhndR9ZVft;Mrk8oTCSqJ@Y-%MA;I7y2wAymfk-({jW< z1p+Ae*Q+!6lb3!tt$MjoNB9!oHwVe7VG6t%B*}H5-3Z=iN(~C`QCY1@TmP&?zl{@*cxRuds9nwpV8M+@bZQF@tSD= zq523shB=Sg>aDysch{q|`_=6ohsDU?<(DyR#A$}n_?DA7tAwX-h(^v_UMtJ*D*DCZ z3yFb6P-`%oVNkT!>dhH8L-37{7vgVO?t>VE!J)B-Vj#qN-pGIOO6p5 z&w>MBuB9rlnfE)^rrwzLCrI^3?zG7H+v?X?f;xdEv4OW zYVSEHb~K8xy>c^jS{WHH{jmHO4UC$Yxksfte*JUB@?L+Hw}qRMX8XKu13mU$%;jvyipX_s`X41K{>gXZwXf@8Z>0UX zBJ$*3P`rC#XLL1f3jNV`ef;2Qmn^@fRN62Ht;n)FXF1J(J~O{!S4dHlV*if0bcEqG z3ih#sWq&=U)mXLd9yx9hjL(cY?&oNJ2i6MhP55}m8owld32Hs(-=3J6xt$dD{bfh< z&(=_5dL)Zc?=XDzc(eJx*~2?gSLS*1W2Nt5ts-oq&8+}~EF?#4YGRSx+jS#{H*(^u zmSc0*9l;%gRS~jq`}K40Yh=&CRWqd#Mt|TEr%gso?4%6S6$GD}%A13!csyQi zstU@DYtKJlJ?48>q)oJG-W5w0QLr5j(ZWV9KOOMWxl z+}*Qzwe4_b@*Ch@h>V6>BGmR5hTVfhNXyH(8jT7QHyGwW@n>{$X1r`onft#57X0eJ zK$z_yvo!2UNszh8H8!%6xL-9(W4RC$CDlDnA>&&Wq`H-7a9^V0MMHxCd#hKYJ%RN{ z5k`pEs`bdKU)|j)v-(_^K9v2dheuGM*!1kC5D?F!7*7D}u5^8dUKR~cD43aGj->FB z@VoZnUjjF$s|Rml3EZu{V(F`x45US?_9sKTugY?Md#ENd)#h1RnAbqqq))Ln7SyW! zOv6Uy@Upcb)2?d%zGt{q6d$NBt6O)iiT>dj3eN3+eEORj>_x4+pACyuFZh#C3W67&xr@lgX>Vc>A^UMn{6(d*$ zS$F#ewjuS~&uP+Vv9Rz@WO|k171O7<6AuVyd?3_A%F^Q*w`oCK~`DbuN-VrS>8_bW8 zs?|O&evWN)Y{swmg1=oXgE?_S{@#a1>MKI-+_q%8+PEFSvoZS?Rgo676eo^k?1e*L zGUJnLqsWI!O(ni)?lP}zl>D~M#F^xBFTR|^>B23MD5e}Tt!9{oj&|FzhVcv=u11!O zO6JfLN0%FPd~$dVTox~x+WmNh9~rN^2yGAsl{65e1&@9i7&a^`Mgzw{TSZs44_}^$o&2AsV>#{`1qeF zvYn3?{c|6`2uwIA3^MM2H9lsc0Lk!+^3O(O!F3=;_ocS>3qP}ATdPm~Dv2Kub0@`E zHYYjfC%(pbKwGdsr!e=ZL-)}6H_LFh@y_%OhAF!>d8bXOuz64%r7~#E4rSC1YQ|GlSonfZ!P zlLqsot8Z$4T=g$11-j2}|HF?N5g+}drjvUxBL490%Htn3fk*}ADry-XxF;i_458k5 zN7>`Zq=(s8 zXV>b7%l}-Q8K+=wGJ9RPr{6%i;@y94_Xfj+T}kNhFR-i7=f+>f%m^ycmMbzd>d~Iz zbc8ul!QNjW;IO~~wLjXP{rw3X0eNLteNyK}^X9@R{_;;z1)DcP`~BF<9pDnb%fozh zEs(Am8;w7RPgkqwprmb6GJ*slc0nKifG%cWyxUNlQ!Y!0qvE05o`MS${8BcD z!2uP@*Z_6v_rYl|tnvY*A0`?be6jkWOyUf*mr#Pj@Ir4ty$C#$+1}i;tJ`K5$fTAj zPUY)p3*&@1EFd%DybGf&jA5WV8E&cE8N-1`t+&mtIB<9I)%;mDDmCfQM!l(nlI+rM z?OTVBWR4}P|C?2V4#fiuU7Lx^5UL>whVU24Q6RTX3M@Ucbt8Xv|5bqnm)H$Py|;6Y z_jo;s$n-*HSj1@68rii0uWbG~Ui+C;!z@S#nT1z;`k|I^$%G?U9#B;!Pi`%iyoY%6n1!h%C2kKE&kBfvSEwgzs(+0qPLb+Tgc}jFQLs=KRekJ^`SJ)cgpa zEbUX^)?^dk|8v(W>X%?jIV=~<5G+t0R&uo`kbXmW#Urmyxt zzMP602{53PWNcVsi_BKGo28E~RrLBzr87b0wGmT#g=$T-RAmW&QW)>I6u|U`0EC;4 zf4ycBc+cDX9q)q%psaU3OouR5SJgH&IA>5ktrKVOIlNgsktqA^wa*9UtAs~P_gkD= z&&Y1_PmYhL)+dkNt5QOtEwZ}R9g$wo%cDZti?9^P1XJr0xTt05!fjJoTa=7_09M-i zv&+DriD-W+`!#NbWq38`h4@@>WO~ITbbgy^+^f>y^tEjX(;AZ{2h2p!L9fRcTs!e?U-Nd zY-#)cJz04lE<{={f7J%CTnC5iC`D0ElIRxo3&XA>$Ji%hpFU01r@kt>li4cGrP}>b zFZkA@S1C^(@BhC3&r6PVKVU0chWh8bUG)P)`K_T@N5_|Q%TYRMGv6vFMw9hy^KWzs zj}gA+^>h`&d&ccKV`iCugMygzk8o(tT-`5oUXR+bD{?gxrpY<}Ln(!wk3)T9iR-hN z{-ia{aW(dRP8L5EpO226U+ zVO1bgdURj!7vs*d4JodsM#L6w#mrMRZz0hOcVh%gwm{kmcY`@p;MVCjfA>kX9bHHn zF^m21X!&`(VF@rO`|c~5$D@>-ul!agDp_WHa(%HR4v@hZ<6{6wVBhROlK1`VZ@Mz2 z`yoFS>)y3nzy-r$k-qL-oI!>jB3mvg0#7h=m_7MtjDpimZmK@y;!Bf{ndk#gDB8V;|>YMXOYGpM8GuGRatItmNI3XV1Rg z#wQE5-WzkUP(T)Y$8b{)7p_v+5DAc(ZLI4^xh&%-?C$O^81sI5)$lt)dM-W~-{;@V z!N)8pBK2N0yTd?P&H4r#Wpe#YdwJ1A=-U7GW+Kq7LI6_Tubd><{+A}g9$Apx!sT6i zqc@wCHRwV5r4?zIOvNl*RBn=1fteU!W;yB zZZvSZUnsU@b-QIwluC$m$oO7V#SwkpT@*7RSVimL_T45W2X=~h`)jibur07pWIeYaCeXpblJ9s^z-L9-Ot-*L6R0cH z@AdI(z311KjVjpwx5_{NUS3}Q^7wIkdwc79@-?nbzR#DftXOkaXW;lmen{_$)S{ZT zs;g7i>HYj?>!6RQ&ESlLKOfQcV#<=VdZLRp`z{xsSpvJSDqB$@XpqE;wQH7oMj_C7 zu~Su$MbBE8vsdqKYa*YeOkG8PT>CW>x-WJEYH`(o5p1$KV#Cf;O7e|n9RIKoRcuIK5$2Uv62jKv@&cd2#K!Uz>$-lAnLmLmSQgk)i)2u8Q~7tA1_K)elabgI z>1BfDUd*GBrhk>(3e{e2q0r|!fhfENvy5lg6%4gWC~w`|^DY5R=?T0ppxDZ$%vo3Z ziLuJDj}=HhZ}4MQXl4b7NWMyh+V<-+lF}pbeSVT=X_aeVKC!G?;jH-a-J)*SWY?a* zrhRD7NN@HXIu&2vm`R*i8jsVG-OyCuEw0&ke2qOXw+QS*Y`M+4DNsg+;v~!0> zgpb&lsl!QC_@`zCKL}FnVsT2Ghe;_@&*xknic5wo-KU$?@s;=$2UqU!C{Fkbs`CI- zIQJLuN=b}Au2Lg9Rt<3?m;3@38UCNAbZ;Upc-F2vKRvtXoC)weF1URSmN?n7e9D-d zg#5Emts@zOX55ipb-bZ$hYfb^6=A+#U5(P0&z5W-tlHa0&Au?tX;Zy6_1X@J`}~*z zB})Ym;^D?2)7XSooaOJKHy=OvnjwXJI!Dq-qbZkMe?-n-rNMfi{oIaPHI=W4-A8U6 zEda~FGX=LBgN)^Yp1$Alk<9NBAHoNpOrx+5a&K%W#1cU7DSZkGoo1S=$*_*5C>Hur z2YutxzFnnHAcxFeZ+q>G#M1T6(LE)a@5WCN)I_RZ14d~Zg%I56*mFNH&M3cs$k4n^ z0w4)5y0~xQuCALcI6e=k=sY4j2sgR1R)qKlm*X=!rL_c(wVoFy4Mec+0Bgkl}O%vd2J>DUD`pU{DrDXsr;Y zwzUZE--yvh?30C3Y|#XI?R=i;S%7f|AJAk*s0&H9);?f{Boo``gMXz*F_N6zJNo{u zr&#i;i%!~S>+*k^{e4|6X-sE0ilC~!@y};Ifd4t{S(d*^r1X3vPStd%^%5642Kfm0 z>gl=RLW)m9W^tXQ?OclXd0VU6s8tj;;9%RUAywg$6oO^i9waym!0EF(Du^@iQee5H znpIBSSdY&gWL|vVZ6SR*tq^7Axe)etP!w)vDed+&vGZBDVMgS6G!EJqZl)qF(|^v_(k0H1oGc;fwec+wz(5mwR zzbHB`;48lf!p4hPAtiykcBWy*N8a3I?{8^RLS=N*mmOBiiTFdYSYNOwWu_du9NhW{ z_dLY8Ny}kj9sSc%Q#K_x<2JLqZY5{5XTD78-@z}2j64;y0+7_jVAZBA$R8@$7l{uu ztB!@pq7?N|k$UH)R5`5Lws+eHN;!GWw;(Lp1f#v(xRO5ll>o+`oI49E5f}QFuw)f( z%`3(0_OZj}16*DWw;IhM{T51J1$=@Xb_N%fd4<^eOnA7Q7yjf(_x9?+W{y*@SR&fm zt(jXk=CE&#LcMw4F=(h(gIlF!xjn_)Oyp=&K(E9v$U59H|Cf$(PfpgqTr;NSiLn8n zBP_wKwS&aq3-;Ex=!TY*ga^rC0V1GrS4lX`OvjbN;5m+VN=9KV%koEsm8P-k$-gu@ zD3&-68Sm00!cPyK%B5h;4YCPBPBsBH;~19jgWOKLA4%SuEb^rmxVNTk9REGyS-WRN zU&(d16J(~%QDG%+`bMMI#cFR7G#cM_h>#c1Ijk~8O3$P=B@tqwbz&>!j8+en_N`0o zb(V&kEshEmU3X9&0#2ZY}08G za(!2vD=^xn1iBjR*O{;jP-x4$qY6*Y!CVJe3psj&Sx(B)j5bwmRPeQ?(J)x5s{bpY+%_@Tz0?RAx*}&k2T?y4c9@^b94)hZni-w+lO1k;bfF&+nC1y8WC;VhwMK+n^v3S4c ztcTAStLIQz8$rTa>)E{USgnCtvNin+4Q5fSIIih=nWx!H)SyCLLv%$zDXYIMIQl z0d&VtAW=k9e6EP#XbeOp!T`6CYI8w+(A3Zn|6tbk(jC(h*SAel&f8!q-GS-P^tr!}-6cZl|L*@kw%$9Q>OSrtKN3o$ z5|MF?WREhlh3vBT%FImYSQ$}NWbdtv$R;Bp%AQ#fLPlg}@AG?oblvy;{o{B2b=CDa z*Wvwne_r!B_as>Zh0^yneI#0?B9YHN{$`I%x+^+%aoUj*F= z+|yql7KIr-d&H{qMCc3dJS~%5Gaz2RlWWhkDhTPmHdktppRe|9oxy&df2WvX*T?Oo3SAbp_?}cB#HcK$8#tlQjvAlRu?~diOec~QBE;5PDVb6@ioXT3{yY@<0Cb}n zjv0YCkkitdu@y#@cf(|_fwCv&)d~RuV_dt_LcTEkhuD5$TN_SYQC1_U?HA5GXvV3_ z-_D5AFk4b)&(VP5O>NJFq2`P^XuJx7NcMl2C^6Lhh1vb0&HIaKuCz)8h0!MqQFwSz z6>dAQ!P>%E`qC=}78}(WdZ2>>Y>DN0@<(p4q^QU=$-LE0go8>c2S=>fKOh>XF4phW z-1^~>Jp+kH`5Ri;P*rYW|1@(BE7SgtfK_K-{bq|1#wITUqp z%P4-R0V}Z91X_wO&(|oJS&rSJom%2yrhcK;& z^XGFx7xK!v6Nw+O5-%lKPB(v@XO%k}Nzgp$8@9v{ayLPX`$V-7B`oI|T|(dTKX}6T zP4K%m2w!GZWC&A)9G1K6e-YwG??0*d*O`>I&yRLFUu1?mU#0-*$?G7)+{~4ak|bc! z3s|fU22G`uN$=ojjlVLqF)&%#_FedXL<1ot>}=mOGCc}E^$!jFAah}%`;=6!gg*^p z;z*J?*In&=d#I!L-{;gH7jwOax8;XCaIDo;aLM3Ry;y2#rgC${Z_ua>-%n;>L>_d9 z1l@!EEgvw1b70~(bYu?}L1*#?pG7jW3!;hGl#n+cv zVDR`lVyhy*p}MBUxrpIXHBTux#UmRZAP*SGbk?km-TrYeCKDtWU58|?)2CkjimUW zPv{reQ9kvE=1hrk#jD}SX(B#C-esk2*B`HfsETApCS@cqs+x{wmhbK%8P8elsKu50 zm*LZ>XUQwkRGBAwJ%hn2V!{=tUy9CP0~4;&h;k>_mZ>~iyzU5C9Anx(CkYqnexEPv@urA*MbRDlT*|D_vZZ# znI#_|az`6IYXpMFx?uW0%}5QDUPM&tO|&-x0MWT&qffAE{7F8bKZIx?9BC5roy6ez zcDLSp#BpmYV)695^RWK_+peKo&p`y}5uze#F^_BrD%A0iQOGBwzrQYdz-JNIOIafs zNYoK!g%R9*t%1NgeH6YflhS`K(qL z(Xn%5!)`_~{7F_^I|?vbAKh=7A-KieXG&Ze#WRV(aTQ&&`d)UGTsUGt^cEEZ zcm>dPU)8rB^TDeMw4u&VILc7)&`JF(cyo1M{e*kJ^Eb{D>4$o3|W%dslZw5T6%MsoikIE$Zr z5g;4)#Nk^GpZZfNWi7!?y1lVWi74XrQ6+x9@V*?AvZAR!{HSu-L5;y3k`v;;@vR7T z>77`(sKZbZIh&-V&+uv)-OcE_E`+~6~DG(Chug$-oiAbq&B}2q5)xcJ}eFJE;OEgq)EJAM$h%eJmgzonf zF};W&KuNa$`yKu=`AK3b$_Y!{Pd0>z)(z$;PmYm{!uCH|iqVVF z)Nkgu==RtOgK%EZ2M66#m`%NJ=7kc{9^AoIa8X3WZut)xVD=FIEYgZ4sDlMiC@^ia zo%U^7VvuRw%bDBzi|Vy)wC#5sq0_VdUS#}?3a74f^+ku4Pr4P90`h2* zOdMR)(|zu@t#-}&--u&>Sh@BW;1mA3iAdA?ef{r>C9UP9&$y7@LQ%v_+$B^b?z%pE z$%ip(E;x}-9Y?mpZK3T6=1Tb0`lN)t!$vEr*Qj1~tqGEAA6Ql3>+4`YtW&6H@fUSH zGn4Yqwvp$|QpDa8SGv`4WhYl7&zQ`4R5RV{N?qLuzU90#?CWj0BDu%An}4#heYnpE zo;n2!@k9*GihH|Ws|5Y7?A`bi1!hSPC@G$a)9OBcdl99NoS*WltiY zoyfU0R@DfysF!m>2(+WESZGdyKO$)p{+OJ^yI4|qyMmUd1a@zOjJ3x1fTL=~xDhsS zf8Sw{J>@SW^BSV0F6fX4nr@~#@44VtO#w>CUc2kfeEGAHtC(wK;T+g~xo$mCq^qfr zR*fgcM}7SL=SUK0(8He7h!V_NsS4t64Dj_OTP=GeQhtqo@fZHbB9u3{ezQQJOx!c! zt2u)UQV4m5>Gwr1pe`$Zt>Qb(3#EW0bLo?fhOD@KfCmm71imH34KB0?)M;z?RTiFH zBkP5E9JNxn1YkY`IN$w^e_3-Rp727c;=>2aih^+LXqJQNP=fTSK{bZvEIE7j7`cRa zO_$u|W-=hJn_lz8Z#!A;(40&QPK3-rf{mW|5z|}R+L6nf2S>1L{~=*pSy$(?{JyP4 zcUE?3=Qp=+HSArC5?^;p_*5?F6tK}mL|>5rY_)s;e(;md{hTj-@_3*8vxM1=@ke(4Xgu~ZH~3XJZ~Xc`{diLa%3R{ z5ycGJHv_-O%*6+>q;Cnl;s@hU>721a<*PgeNsgP_%Lcr5ZjWQmZCWO#r3q3E**Fz? zh2-~5>bG4gYoxwZpz25`of6&Adt#f??t)b5TwAbJc=zAgAz>|=t&fQR1rn-)k>1iG zvB`X6`mW>1qJaevjwpU5r=%De8d6i=%a8V6Wh^~~S*R-Xu;G}&Vr&F%Vs}$2Y3gqU zCaW>mOBCOJ`5-Tc@A0G1J8Y_7VHojrc0kSg*Tx^v2|%==JW;m4eFb?tb?J$(F~xWd zx|N-Vrj6G&3s7X_=4+*o$@k9iPfQ@Cq+YaCH9`t;c`jS6vj2~xPPl6#SaXK<7T#V` zEBA>~6Uy&YwEb1BG_@p^{Deje@5a}Dh`@*L^*vHu7}S-iDzx9p7h8hYFT8Tvs)dPrj z1np|bRmP%hqJ$w;5FyRK^*jjP;Sf1Wl6;0PRYp+WLY1F`f<`J-Pc$=aY%jb!R{tM8 zL##V6mp3NgyQ65S?~xH>aElJ5&mr{^?GuCeiH(hgGYWF!CDHrsnSUe8A=5e()>K|b)hO%6d`FOeSEb6g(seyJ%)iT1Aevz%%0f2)An$egC z=cn%Y6^_0fjSjzSvl2_ych(fh)@I-st8iO*Ie+A(HC-5U3J2}}%vw_ueb5_kj?#tL z*x1gu>!kp?#w@T$rEQ&&6U+oulWCQWeJ^d6x^B7P zq(nH7lQ4O!Gn9S7NzY&U{hVhece)b)a;Lc_M8X$dzN`!4KwT2 zW(!gJN7a7hf9u`g=#+APKHXG6^+qG(Uj-R0f+z{lVW3hec-P9TXrX_3>dxm9L=Mg* zDqSYcjLk)dQT)EMEQf@9g}`Uf*)&p)-p6(!3NEW@BDYO&R6`vO4BdJcN%M+e&u zHLk%4^9{dP7md4%0J^*Zr$npHT6?p{JBwdCIIk;c;g>W)N;`JVB&=zUe+f$ zXb4rNZS6g?unl(06v;X&xeW1!o^d6^Td!V~o3hggf-n&N^>2gew-MT?146e9*C7vc z%;~bLf$#QuMw5`1CUG^#$Vgw`nPe~lp*<}AxaiT}#>>>P7#~LWKjA&`!v9C_N8VK=J6^zhTsa8qylS!bHh8kgO>CKV?@AX*BGBAc9M%s&^ zKI>kk9*(}UgZq$;Gb#s%6Pjnqi!c*$VCzzqjlL!8KrM~Zf5kzI1G{GUBXZ1oqGO-N zbZKA7l)6`K85$CiRKpvs=MG4qgUS|B+2Q*7KRX9pkG{ZG*=RpTk85e-QN_;}@Jy5v zt@&#dg2Np|gto*YIB1#XBuk3iuN|e_%yY)2OngIRuYKd2+D|TwUAc4c;hiz}aSH)7 zl!njX4S{$&=!e8xC8R2`h;Dk@XP|9%+tH$zqH~Cztk9@tXmM+4!hw>{$Qvfs;Ch5Qts;F;?#k0f6SrMJVo%2-g0N zx`0Mh@1G!rvX4^rx40DkBsYLCpKm-i3i0m#TsCGzPvGKzW+S}Vw`If=aOD&WdJFIN z5sk&+EUnU2*Gw-Ez>(H3=)(}-Ez6F6TuLmzadW7JI}4UegS#9maC|c#T_t3Z8@h~W zR)xdZj;qN5qs8Ma_;Ys-C<3D2ih~Jxdm?p;eZv|>byyM{m6XlzPvrlkH{A#=Az|rI z!8_RT8*Y)1LB9j3dH8O?uq*x@50BUh`Wbjc&x6 zuuuE(*mb|snb@Xjkow*62@xIz&OgKl9^*+B2?R zh&;qLfLPuoVDZX>Zz8I0DW;=jm1j{4{pLb;tqT~CoQSQkSy~@o-OxHMqXN2h=~d@v zT%)w#JNw6w7lF6|xy4_nKQBki%dB|2e@zWZ4a+tS|9*0i4{P6~=Os47b87dop=Dc8 zLgvwtf99fz%P+W(rERY3k6=LOrLxYOcfP(d$7-(pNbufe*;J7>^7v<|{m`{RyH4xT z0(Z#l%1{dzh)aj=qg1v2ThCMy}^5ay?xof?Gh}wm#|4m4)pI#MDLlt$##K zLBY4|i>>`eK9;{>wJhBdPk!Z!3ZBQS!x7jk|NbaL<`@I8QxT!^O8BR|oNqV#7eLil zWRrETo|7$3y{#>+-OO=$-B*ubL-jMUmQu>r*5jH@b}VC0PtRzU+^bJEMc;Wz&U*Yc zWh64nY6wGr%BM)A7-hakIW|eUVyP*Iu=S(t;&ndmJ(AOZ7!~#z;#&Oep&8U`O>mt* zdTJ-n%SR7F8h7yuUc5ZDK4o%s;R$&d!leCz|4)MerAq5Hyw$C|KMVlfQVS4O#%w7gg?DQ80s&x5;T)Ko(?&2@UlWiPJw*VQQype7O`VW1newVvQo{w1XSs98NT%u zf=-RYw#s$#7I9>gzs$?r{fj=Wk>hN(*nu+M$&Gk5JMA<&=0ND1L{L=x;RBgH-(Eei zluGzTOT9aT{66H028#EOMTO=aspek zZxfi-g^!6`_I!ExjkHI_1wsbUV+HGp$9HecNE3^p{Iy=GNVyHpJnoD%?Rq|NgJh4e zu5L7SJ#pQ)tT)1zOZRiccglR5ka9dWL=C{H{V@=|rf@EjMmp9V4y*j^0JfU3=ZM0V z@q#w4<+m2x{)CmA(fOiC=T?EJr_8&Phb{MbGYJ|ex+SyB1G)`C&zg&^uTH8O)c^s^ z#g($1Vv#P_K24z0RQ;u$@f`s5qeJ4VyXJLVrtR(&S4iVYr?tOt+PxPcVUBj0e?QU^ zN)+1CW?ddeQ=$}h`H99xq9er(o~nbxxEMKeZjoIX=IzVoOSK`0nrsBG3oMM0Eizo7 zl3O?>Km=X@N_yMfD-eH`Z&yn=iP;1;zXdbCy>{(W;UUVU?%;Zfpf|nM>su2lHWrjn z=~5rYNo0N^l*eDF zM)JiF5;1t_=x{TMsDcWep6E01Zp?Q3Fs4L>Y5r5}ieGZ81P-%;pFz7`C7P#o=s>{o z%g~TE&+8$IM6=JTKjjk^MOwwJhb^q0dv|{in=Tb-&2hSQ9zQ|2@tDSXku2#hwerXF zRXt4X0`W`@lpp6-VrC^47Z;^>A`}KMdi~At>YdnvYPn%{z0~UErw@8JAK2Km4g6ij zxuxmUIh@r(X5>9b6c4{r{u<)eI! za^6p9FvZj)n`_i{F``@p$}cU#82VGnr|iwdtk#3}dww<65quf5J-}Y?e9Jn~C7rnM z$eseSi>ky>1^eG}LBLu={V|HnA*WP#CuC|^Bpi}?2vJ5L`8__lx%g`Hi9?n?bP@Zr z%Xtfrl7fFY(hfkuwf-BH>RoS_34cWJyCp?K3Q8X`;x`8Jw*SoRwQ&7o6FPLCy_3nE zy?UcWQmCC?*|@{ikrc)iJbMU19r#)g!vJ%gBIdO{e75-?r?M3bfTS{+UDCi=ej~h% zG^inS=`yqR7y`4c!iDG5Jg(^7C<}yZvXV6;QSs-|A?0dQ6y7j1wS%xk*VFvKT%PD$ zMx@#@E?M~Mm{c<|eJl_+$U8W8CrWM>D>u4SU~jy`v3EH;n~|(j+L1lscYEM^8q;7W zIZqAaa6p3*^K&n~T$?L2lpn{I`-d~VE3cQ*EWJ77p{LPbtQ0owOI~?Xx|*Np=Y!r} zk_W8<)KB8taEUkhNlG_D{_aEEQf&?8X$fHD{)LHhDl$F&P|f0;rlLaDwJsx@%^#kF zJc1=WNAu}%4#&|Gr#2q^!dWZLbFBGRfUihz@?_@&p`yReYY}RgS+^oHYbon8cX>C> zv)%SvkLi3RU3z=3ohg_k5x7+*C*54pjPj*eS^CD4KsJ>)rIgXDeZ1!Lu?*J9(pKZNU?l4A;0v%+XJ3Reo+10z>Xq=tUI_rnF z?{DLvbtYF~)}unrbYh#%5>BNcW;p}Wo~58JmFZau)wn;u>+>>}UOH^YgDbO{a~2LL zzjzoHH+T$_753bP`o+{<@!ob3tL*eazrMe^w9|Feb974lfX7?ftu)!?kin;}_*PSs z114%uFz=I?sJs+;wA>d)iLM5l{C?BpoGc3v}iQ_S3xh^=H_ zmoYea&|e*b+amr=6M*AF1`of&)ezt4wchd+8xfL5J8R?zgitkz6V7=Nke1Ch0nccR z$QC(^7_X5@ydbW)L4k7wCUR9tuII%JagU!or1w3q9?FtNoz_0!Iuf#;KlxI9gyV8R zu9nP#MsJXIaM$Y{iCu~!Zmi(B=cAUl#Xm?a8rLzFe#OR5J3P%}y)WKpaBbWGly;x8 zm1i-JP9arOATlfcn9wAx(B}bhcJTYtpFSd{g3%Io_+Y4o0nLJbSmLYVF;No^R(8>M&- z2*G4UVGO*e>ZGI;EKZ$ejFoIJ?fM1d6vbS}uYKLdM;P&fqz0Gb*AKo{C>;N-;ibRt0^`=7Hx=h&W{SLx|;fuZp znzeCi%q#YK3|Dg{^|ndt%CelZ6k}bo2<4N}rNbp0w2EwQjxTUfDt|>@N=j8P@Z3qGQxT3Do=S&Pc%`XH=01C-&@xBbq z#Yq(f9?1RtQGbX0vK0XiYb$SX5DXS_`Vm!k9UPITTcg!QTziec7ck-@7gQ36Rclls z3+-YHtMxy-6z97oIRuENpYPiOgPA%nVZNnBv!I)17@c&1rF60)^_ z+<&ypA@acKZXNG7`MVa(;dyJKAX<=AR;BS4Egoqb9X}75d*&sQx$R({!}8ZLM2LVf zURr_1pe99|0N<9z_rehRS>)_Pf-3u727%qIkU!1%^{yp<^KTfd_`Z4~31<$xD<{~a z-W19w7yZs9_NG3!zUw)(@TH3IOzQo8Q9AHQcr7PQL6^wjEFQco?ODp#5Wzp~yf|P7 zf-3@){R^OyWYi9oHIo2)G|MB@gIG|Hftk0B!-jqar8wTXp8x{M@yWlR7@R_$#2-ZN(V3y{1g%EG{7J|ma5)BYIf0+#*sO= zC93G|uPP(nPSgf9UBKZt!Z%4%+FVq}l24IvHr@GfszrPB#}9o&!_D`2hd2%X5C8P1 ztz-NjwM|xI7A_vC98HPdkMqgOk324A7*4|2Y`ff^6PZzl$cb8jLDqr20xFGRz( z3KaaiehQzJe3a7p3)DbT4^*Z8@oQ0uZ%<4eFGZx?7Vsav4o}Y({1qbaI(FTcb(3V?R;QBSUGZk{e>cZ%9v{(5xjEm zliBvNaTi)S|Gi`FSDSH{sfV79R2=zC^jO@GkXX&WbLF>H8~#QRjbM(O6M4y0_UVJ7 z3!SHjnttxrEq>>wW+lCF&@4^HJh94w%zaetE6A8C;vS9V6se&fS zztyFB0>%CJEUyIz@kId43NxWwFHcaXlpu7Z)i9F>H+j6gN#8Pmb?Zdv+f!FXdKtz$et}eO?179__22#Y(Qy>YHfrujvJaNm>8wza z{4a237<`l}uEGne@V7n{qn0y1X8c#8)CAFER5U@!KT8e=OGSKU+yB*`3NnMo*j{>6 zopw7h1MtF%;uiy%o@QFaG)aSYS(LTd^i$0FMd*%>d?e!0UfW9}FjGZyeHIgomsqO0 zRU1(Df>`j;ci-ox*NeM*c6rz&V%m^^ip&T*(;T&CS=*Bm|20UjcP|Dy-bmv>d*UiF z4_|3nVcd9E?CZ;pA^K{p?I99Z{6*qS*ZD|@yDg7KTj1Hf?b*RB+MiAvfbg}O;a?PA zI3|h9SRtk8aimKpy%a#*;cIq;K;fBfbzqEK7BdMbi2+G?W)A8P#Q*R8qYrNRCy~DM zcuQ#~J7YsKfUKvScIURrrTtEMkjV$7HWA^i3hiNCEN<6sHB0-N$D+)HC zFEQQDKeR!MghD;iiN=g2|7_6v8klrxsovjf2&n&uCN~raNu-Uxeu`UTMxBGHx~rMq zjhY93xpXIe$J4~R41-QR2$o@ldJ4H5N}&RSqX@N~;NUjx)sJI0!az}>(yT>t$ug!g zYWX3pGo{uEo%dHu=BIp*S5OVerL8XiPe@&p-YYV6Nq>6rwD)kLz@&j+k6K;x&{oXo9eQm01rhK;VOkd>T z`adbLn(FI|JTjn(qH%R7ZQvG+wLP6%bY#7U>yI}vkRu_Bj@zspo~*K1GpyNsah$!6 zdjDSrOw+9SQyYR0F^sAPea4)yM2yKs&%RRe8%L5 z@h`+Eo=ZPsLHiw5M^CfdrE-AP=Nqmt1U#s_972=1G~=tV{Dv!1fGT4W40*~qmB5+6 z`S0-&`h#+reX#?AO4bcOgjLSfl_(rj%>;|Tsz2=cgZxKt<>U2H?z&h8?0vogNiV-H zsb2(go|A_Ek&aVOp7mUT2lvG%giy<={9Y-WkGy=^@VWWM#dup7EqC^E&Q-aYn3z-s z*S%T}9(HaKWm}q-{nxU#j{bmM9{*aWwE4rQ*(?qn!lXPOPQh}y%J$=w$_GvtL`m#lO)?Ht&UzD1 zM*JZCCruhZugl(RTe>6goT{0y)F%G9tg_JVEH@%T2eAPAPJ)iYi~srYWp6`uUq`1i zBUy5r%ztq6+hKaJNFpP=UBY;*UEs<6Ru6z`RT9OpHx(}YelT6+do(?E%f|2c(SG@% z{4?2DrM;;j3CFQ_48PtT4>Wnwk^YuWfBi9{N%|Ig$fe#D_4!&NXmch4SpA8ZuaB~v zm(^TP5SQVu`TdN(0a_SlzFPTjb<#KEdvEzow_0JCrknU_RP=1zuJ^bvVw>^?5sxRR z^~JVyCHZ!C|F9d;(76BoV1V@?e6x3TqOyk#G3*)_WM?7EqEugr>)yK{uMK#v$dBS? zzl+;Rq;MSlS4?mEXN+--m>w5T&uumXrRpt~5GDdvQ;6=v8@7a5GHw<)`a{};w}RWOgXVw2WXKN2v9UrS(ky$0BxRjux*`l- ztrl;>8&z9l!c+~+AC$s~eBKG;62qkCfQ|BaZ1;w-Nv>7Z+aEkswo9D7>Ah3;Iqe&bXK4!hN za{%M3;WKmTX9?;LX9E_JXElaf>Ws2Z>XbKOO8Y%zKH3Wn0WIQA|0TFAQ*Zxgbq#E7 zw3Q^9^>N>XZs{D{DD;Woec~l;{2n}TXv*uczv&i8Bn}^~TL^`F+9#wQn>()bjGKlDwQ329q4RovY!CDQB;_l&So- z{;%gQ&E=M|37NhNK>MsOz^GNqC&_pY9k;k5a+xQXM3mn%*8chW1MgIu%@!c#kC#;M zS>Nu=pyb`U$-iZNv&+P1&%Cnp9M|LQLGZ&S{q&rjjENXW^_8Rb-`*Bns%oc)@URo= zQG$4tlQMdO8E$rVyQYmL-1Elt@lTho-zMm2NuT)jtstW~xUN)*AeI~0__NkMsarXB zsJJ4Yrutj>`25t|$YH;7an!8QJGSBFY~w8Y?DlgnZTtVqRL5-BV)2r=!HI6mlyKb7 z1#7)wr2iiK{~J-Av=)i@E;NkoA`Cc!&|QL2ilSAWVDAF^K}IX-*R^$Suiy0mHrJDcQ60W-#6@t>-AK9|Ltqc({J{h+y%TlbUa(?~TF^d@!4fcP zESsI@ydfe|Q(j(PSI33U`M!w9XxNC2ccdExV%?TpHZa{i@H|v%=H=}**)P1G%SjIB zT>Ytb%v&WsN3XV~;=Qk7Au`+&dfIE^wFXsbYN^an%e|YwhJRCko6t0F5XXGwI#SeQ z!depRk$Uitd~4vzD(>0K>#Gfsfx2kHwjGQ3ndI0%#3p<)=Q+1dF+0;HL13+v_&d|^ zN1XalmN(Q&c6TM;e-I09LEI#1=E1PZr5E89D1jz<&vKtQh@c1WtYVdaswv7He0?d= z?-6}f)q*9?{X~j53aqVQ|EIKPqFeJ$8V02=yQJd&kseTz>zksjhQAOqAFirL(>>SX zr6fE*InQ;b-Ir&oh8o#kv^bwn`oAjDcr4}wH|Tfmu~2YO@-N$(`}ZDU&c9Dy7JC>5 zO7@Qag@-L%>ec%tqUZjP65W5`xzR+&-az3vQ70xMBC@$bC@AK>Mhj&@v9H%ySzuvm zf)3hCvr1u7y`PJXqoV2A=#PNa(bb)CeY}HT!`>FOWZSC`s}uSf_P-i$4_CVIejL9O z$`nG;?tqroe#jz`_B@+p zzC@oDS8|e8sc{|SG>xZWTP0H>(@a4`%#}pPuBd>76J~oyV?L05`YCvum*oGIL^8A< zLRWrZNlqd`$HvlU`XQ#5t$|KWnP-SPq>FWlG!#h)>ii<>?@UJYw(i_IB7~uYW)_l} z#|{!N-fBiymG|6&{**GzWvQoy}{*k0T(-Tl+rh!D7Rw9}8 zjBF3N0xh;XJIgi7cd8}UX38kR;--(37x$f>o}MVcbMt&FDku8Rym|tMjmr|exuX-d zN#GbY8)fT>N38_5S}-rL99#l)@5hI3J3ULWS#IU`k|8)YGCeM*0pJo0gqiIz?K>#| zTdF-=%{S7-v0)sP7(D=U&gj6A1MXRCl~Z}z#n#^)Ah?&}A-Zf6)$L_it}a9W3}GPY!OFZi&#$- z;AR890?1yh(9pj4z7<3okDrWUXY@eak6(hP?)zeO^#`Aj+S{p)e>zCBlo%YG_r9lD zaw;j~dC1kw8(6748z>L1bB_9GZEZbkInLJRJ996Jn{K;QTrft*SZ+w=XKOgNriUF% zdDuEfe;>OoZ@Dwpu!(joJCl3;;WeePq;}ikmgDuf8<$8~43vqC*nN9mnZ9jXBr;lw zKWU*IH}Drpy++I@?qUjaOvUy3;Di z{#hBLcuGu(8sH0P0Wh{{{q5!6-rm-d`I~0#9_ZSb(+04U7}j1&LC3>{?_l5&XE4*` zyVq2wqX4o4eV1rOy26t;p^((?!v6RnOU83F0jmz%;2FI!k9@<^^jWJjnP~bYwBF4) zzt=YyBAV%_#xTR7!&!R~#Eun`8gi50N+yO4`hDX_tDHOBPT4?@ciTYh$!<%h@~{b4 ziL%O(2UW=UrTqc~fd6eNDw7hN=yV)k{X9_JQTc%rk^vlm^=U3{uAJZ>&K^Md1tdgb z?HMzJHs{D4STfeQ#z!RfOWBPThk4Xi=$@`ix+FTB10xw}lQCxW*P&1m%=RkOIYHM? zmy`I`EKp-D32HvCKd_H2r4I}J?x0o?uPUCOWI($VY`zoWp$X^`vc>RbBxaEwXS0_E zdpjObcZg5DIJkTpFq}TKC%pr;==Rfxd+4>{0M!sdyz!#z6LG_8fVi2?`04M z;7>S)aGF+;sh*El1opu0Mv;G{$Jm8&+nL)Rr*iI%a=DOM<~vs1q!m&~r2oI3LIZk= zCARNR=Y1>2A%g-O&Vi)#VcWXtSQl)R&2iNsXVW|>#BxdV22gl@XrQJnlRKL;OAk%Y zm$;MWq6zI09d^t0vKImqB>jY0PRv~}7Nv0OpBSij=Mn0>k{_8yCE_lUyAZ~Cb>Au? zN3$d@;wre=bl!gqeBJR>iK1()>%HsaZduCCeb&Qa5s#$LMy8EcnX}_OD041zk5`xG zBANZQgGl9`eH$M7a?|_SQH>^)j&n`VKSdZ3mOtD4<&bj(n-7_^Y9S%&r~aFi+aK_X z1i%t!K7V=H)|z|I(rPYjXLb1?Rtnf~eA3QCSKs1%8Z!Y{2B`8U*HW;vyB~dFEr119Odt`u+{eZ$R+A4~ zA_K{UKGhU_5}*Cm(B$UXoNGe0Nen9efC;If6$ROQ@9iDz?o`l2;nu+zQs(0jjl^Lf zTFiErM+=liQd*n<*XbNSSpMaay(^>jdmX|bbK7M@a>0P_$44=nbNDV6^6Z`i$sqwQ zkFL}v(N-H9aGWv$h0Bta&dF;Q(m%`H$%z)Obm$Y;h1x$Ie)V!V+hr`oOpmgrmDEc^ zkD=pep^NbrCb*532ylU5O>zeWm*{p4Z;Fq~5o z2_Yuo;If&M=(YGn+9&Eas=BiDiv!pa{a1VsI)m2ZD5TSj*S2D8OTLIySj&x{3QUex zPHE^e&H;`DevX?C+djP=9>{vsmDf!Ds}9^uzNClTFo{N1Bqv@t`cX~h2QKxmi2lm= z!u_kPsLn+k`t!EeAom z(cwc+$dSqsI)!g!Gjp8LBGRHuJg*LEwIn~vZV!fKj&b7Qw_UUg8)t;cBX6Y*27|G& zu>pzS5Zv9USEYof+2YFe34HaG+h**!>oZmu(_ncb{Pz2Si*dvv9>~4DJvyxR-nrT8 z#w);VGw@#GI9*SbLK;{9D|Q`X8ijJ1fe{x1Luv4;jvSS78O@F}i7MT@0ivQe_a}am zZDX!o%yE5U|GLQRhOEz-ptBcmfQaMLzspwjr6{5y;pC>_%-Z)1rb)r|vc$MyKY2Y% zwprv5bR2d|^YhuV&g7G3GUg)a%}+#LA|oymOVKp|8ZR(+Mf;@jWxg)iP&~6E9QEnN zZQ+W!E#ewi*W<+jfvw6B!GdKPr5St{Ge!!Vb+>XOz7SD1ba6iGyieR1@we9RPTtJjHcVBF&^Ig+#!ts)16z_Q%>i+=g;tndY? zaa1pp=S{Uc4B$#oKKPnyD&1NvE3<~IZBLGpnX`|9^HJhuzprg1L-aLnB1uOLPnfOZ1tBXYtxVxTs{i8P3^fnSgu%v z@$&`CSy$crKH#noE^&8)2jnWR8V%(kkzJSPYXI_M%^}+?{qUw~1g&daxhbJAdmc6Z zmf)jKbW*)6#N7X4kyBOKobyJuQNmgKmQ|7`Clt(bq2EZU``einZ=S;Uwgphilq1{{ z4u!jbJa<;(vef+`wHfPorv@$m78kjHB_TMa$Y-1%C$dx{crMQh<`*Z+s>fiI*UPU{ zcv#yrDzB$oY^RRT)a(7H!J}4xKtw7qO(E6w?;` z0;0!vQj;6TJ%wIlb#{MH8t0F*XU2SWPL0pDJePC}0@20h_4PEj5GR_c{SLQ@Bad^x zUaDN0uLA|nwaYs3MW@Qu0^ql0Wr_;|8U~N-ML(&&2EN*A-An4bV}5?~y4df;l1%*O zG9<3P*sNz(F2PWwS$`;|DrBx3z@8&?2^SJ3NRL_-{f%lxw_miHZ-6 zeHI5aaReKh(Y5~|BMYE3? z5+o+m+=-Y-Cj^E}fdHH|y3p#%eM4vnJ_^qRg44BqY;3}-hB#K8)Z+})>uwP@zl4e)Gmm(s{&PF;3Scj)Timan~fue2D{Iki7ic=8$? z!~-N|NPOM}=C*%UjV80(7y94+ zBy?x-O;u2Z5)Qn`@M4T|S$5HqgIE9iUI65rBtpM$)e2{%HG&y>r#NV@GcLmb_DF;h zIL7VQI${1^VT=z#mr44g#5&EmF?`Yp!3Eq8WzI)-{{ohv(GC+)dx^~?DBP!azFpo1 zcrl3l+cjUh z?-A#Hb_cY5;t53ZSHus1o({56uapAjAWhZwS%^o&FtNR5b*?E^JT#ZXjQd^Ly~5q) zP7MpMANA)b%%^K|sstmkqXA1V^mLzj-{v=YKc);T!B|KFAE)P3Mtf8;#_At_&$|ZO z2}FM>s|eH`Vp1Qgc10%#%sj2wsPDk2;k~l>%VQa0NUM%Te7_$nN8FL`o_<=v&nm2xSCC1eD?cnKA_JwySmz_B5VtL%1l{lnJ_XuMX8`C`}X@$s9_nD9$?y z7~DEKU)e|T&!h6I}(P9Z!)@VHxiBZHxk_3;aYFubv` zQPKR(LHUkiLWcEUCpEE^?pk#$K(?$h!m-?(-n<`6fh2^cy7Q-|646mJ5OT+z@~L0F zzC-jg$uflOoV@qWe)k8v?{^aAH7)op2oi#xJ?WfOF=wx?tYju3F3bpD7I01MxHf7L zQpr2hPwXAb_)wT)fUmhZF6eMX>Gp9nS=20O%T{1;V1^)y_v$bB6aWQCQtp~F34@M> zrGVh_#~83Vo|!JNR*8GIWBrm^fMQ+(g@ZIUc<&Q1*BYmj@@kNE`6eYFkFc*GJd?c zd!#*OEF)f2zi@r^<-NYLsIbXZZ8_lrDHHXIG6VL?JaJ!kytHvAD!Jq7RT@1l!RRS@ z8eev@i%-bEuVSc}cV$BJm7UJCY2dpR+T-YPMU%P6eRw||yGu}i5AkQ1sA&IY;G`8? z+!IDkaVvc80Z0Bk+)uR)>Bl5s<1)Uog6{A4UERx8J>J);af|{9;{1|7Ih2vwNN|wC z)5!e7#c8ZTEJ?)_)AZ%C4L@1uY(^MC-`7*uuN^7&hea7@7@dxBP3R&g?c1tQQmX}~ z4sY%I29l?&eY!OK5}Hb&1N7bX4OL+X0jM}4td7qo95*v^BtQmR~(r02=y`c~IH=;-^WvD`+#U_)QAkH!W)+ zC1!QH-f!K{Xg3V%>au!5z z+F($8N@!*N>ew#D=(`rFO+c8$|v| zp{qBauYW7rF|^w*?sU!F4J&)dH8Wg$*E}*c1v@0Y=iO#1dY{MTS(=9hPdbb4y&6p; z-;0}1$Vz$`idJc_?%TFMqS$n>3`(3`hZPP^X_GQdT#Lng!|K;&zOR$yTy=RZ&UP^# zSfi_1B{;@5?N+q7_o^2B|#g!4u?XtRmnN6B=KD;v4?{#6EY2R5H{$f|-jiWgM)oqqsi0l+hR z4l66w3wjqj&;2!5GW&ZgFnB~r;A5L?z;JySQQ(W#L>T7|XPLY%F}tg3BJh2Zov4;_ zHT~Cn`h(Wvhw-LNF_T=@JiQN=9B%#`#lsO*r{5Mnmf~-2cKaqL3v=I=<cBz7s46ZP(xb*mp6jmJlW zGvgMy4~-jEIhK}}+xnk>3iZ$wzG?N6rLQ1dc;zLa7tQ*19*whjSQ=~z^=0thyWt-l zj9E}acV*dJSkEbVB$H~1rq~`@&sZ`CCmhBt;ihY1B1g55g0ub})-d+OS7uNAV$bC^a zi>pWKFpFTM5Gw%US!QSG_`yZkSp5SVbv|fb2mtsXlEM+nJ$7%;J2Qipc5>bS zIF;t%G{JlNG+AT0)9Ci%9De&@@ z16a&809#uT%*F$jup0i*OVpylIkzmP)H-n!?of;#g{ucqJ?@)u+d0|H{`*%v3@hJH zzP|)5n0-}_OBBfj$0NkV#k zWV}f~j>U%Z*pMb`ecf@be^Rlc{vzBXqn@zu4i#q4` zf40q%g)|0V2q6{8UYCUP#gl9q&UCMdM;to0=hyrrwkCU)% zzF3K>y)dj7_Q3ZK_mVp58Y<;bvSzjJ(1}1|wy8s2!9SW|aRa-zYx4Dn8UU!y*9P%i zw}v*$t!3Ju#ZbP@-QPW)PW9TEZ=e{vWzKWhN)9+EOMn?NND>_kM>G(w;9kWn=$ID` z>v6YyHSK+YeGq}lGvx?X^GVI1EcCOy#ciN%OaTzwF9t8N(c@K*)Yj(zF zXYXt@b6t;<%ctSrnmoMLCRWoTusEypMMF_=q_(x!IC4?rwD)g?suit#6M@!DGd_zL zcm=#{fgxlD7jLKWusb4mVFSHoGGW5?YDf4vZ16KvQzo>imCyh3wV1-xKGCh2e^H+* zC4O=0_l-viEJQmp_3sUy+`}6)Ao0e-mYpVuAC(C(vY8qhnGp98Ag*bhjtt!8rV!a3 zwrR6}iZ+;9gg#v{79i9W7AJSaN;jWu3ljFJ8uR0jed`rRpIDPtBL z>!n76H&4TJp7p{GkzhxCHC`RIm~g!|h5+8Z25|51Lc6cIvO=O`by%;TOcxuRb&wWW zf(%7x4ocDV{qI9P$FN)24lLhp#2@7hgV!tbj)G5|MAy==a@d)P`mHc56?Osp*#waz zrgMRs6Ss&>-*6CmPP{yENF!)Pe6tiV` z5qp*vS*;VRmW0tz=1;znBdXba|5ux%>SBrB{Dui;UYNjtFg(Q!Ep+J_J~$mWDB}0L zRvU5x*dwWz2#^JYi?1GsZlJG1^or04P?MCZiZc@aOyW$sp6^dZZGJH4Lnr5w^idzy z+1m+8Who=k9j~b{4oYO1l>7DEo$<6g^}dVfBql%w(M;E^I&g!~s}H!&N|1#P$JQQN zxGOGPZ@ENCQ8;>OGle;$ep;0aF92SU(X;;_S63bnW!SaHQj$Gu$xIst%*%;^tt&fp|ee{inwHkiKNA)fA*(Ub)ghA_7(c07WD0QDfenRlwL z+#hoqGa?H3;CwFUsK+dbU+&hK#GRnT2KpofqTuoCeDv)*gSA1F>2rGwkx`Bdmi9^| zZe5V5@uSanU`=@r)M7K-Wx+KeaQwwln=D@?@T2s-TW(_!oOJu3LbSmse_I{Wa90?% zzz!W_;fI|DhyyM{9US(7So75MXZ7h!We*n3;~xf9{190Iw%45IisrnqaSw}6*S%Tx zp|s3XXh*)u=m(|ePy5HVTo!j)xjJ$$d5qDuN|-_4epit1P({SO6F^iA6v5QyVX#8E4f zxK#Q_Xt)l_7+ve8*{y303B5MQOz_=4kLLf>9aCZ(9&Z6A<;HUIu};AvsGX zgJVdE`=)`vZWJ7gJMD2{H{)AIuLor$^DCpbso;QR@{OVORzbM5lZVHrTbOFXR_82! z1;Lo0wGDgGeiR66F}-%Y2wxkM`s+`jfp|qZ_*p+}R24X;zi|tkq3HF3Gsgt1B-UAd zV2DNB0ei@~DwCHBUPQ%l%h%SczW%{R&Dv^A-U)zamw`LdZ>i~7@UMEXb{g~xxX}vY zyM-?|`@8BQHj%u*TL<=-9+jLT2QMOycOL7In>lso6fWmPV>-NgY)$O@ac;_6)gQCK zb5h!Ab}U~HT!MZ(2Zv+uD-yWY88JW0cq&#~akOWAdeLDWox;j~VbYeVWV5}yV;saYZ zPF850Xg=4%m(USA9<4&{*T}ZPls357e5N{Krcjt%DwDXE{HlZLF+mKR&TV7HML>I; z)wd^KnRZAm@Np+VTV53^S5L#w1I$Wzt`T{<=rQ^|%(eK(@^NK^V2%Z=-*5)AzaD+o z?yVW=$zNcqGrLt{_|3_czzD4D%i{HR@z2_E?0X@p$|q8D(ZbDNCG2^Is&BOsUj%3I z;v(_wx;Rp-AP;W z@v}c%mV0>o$zPlN3tu;ev?W-#(z|qchR}dewG71IBt#^x(%TlVq2I(EF8^F&IB0y! zU3>jYz6-n2@#BlT2JZ8a9f@rREh}&c`F6#I(UFYNQ*c`6p(3ihDFnsEZh2zbKeMl51!N`dA{5Nr#h zP`l$D@9=ZKL+&K~h()*`{Wy@Awq8V}3BS=hzvFepVHbHn7W31|VTvo%euL$XG_UTH zMmzEY@$Z+bnTY0bf9^+nf`Uf~F!|hl+wyhDjy(NW#R_4xgkQtp5OGU`DN1?VIGo{b zaiwjteiDEj1BCwRvB#h5l**!zOje`hc1gF0$7F!rWkj)*_1!TA;v;cK{G%ok$WQxA zH>Tm+hw#bcdv5uT?25(uiMZ8=Nj5E}I7h1iX#(qUA6Ri}$DIk=BoIiU0t?*~cM3S& z_4jL(z8*~M5sz~HEkQ%LWrzoKh~C*-jxwUxr;{xr><>CFX$bnCrc3j@NGEf>nT_Xd z<4mTXz1R0#{<0qfYR8xwCDNMX!JHzr}nrJWV7@foc*U~LzbWAXBwSLp2JD@|i; zUxeLgyDktEkT5zTSqn3G8O2K$IR8Zc@ryH#zKW!F++WWAXrQ+xSN|wEbVOf2aFfbHUZk&CNqMD|cV3wL!Ygt3t}|ef!EcQh50cq2}l_z|cXJ zptQ6!U+MhBg^!~uCD&G*S$FO+80RO_M-0Y$##(qH`UlE0S$*b;%NuA%+fZAv9V~5r zeYgsb>Bg&|Wu0E%(%Dc_ON15GuMQy5gfmZlM&HBmsV&DSlyOG0R$|voLO-UrOy{*| zG=(?c4hSt%=o`I9@()+^u=2_lXt3@k~Xfo3i!=?h+2k^QNaMT~F zPSK^|xDnrvC?EFG%3v6Fj<>31`m`aIM$ZC9lrV?1iMY<>y~&+J%1J%*9mBa!8q@SH z%uNjKt&g-O%T2W$8mQ+U9)psPo4Vx91^9&+jT^O9l5d5&iXqMj)kd=<404auyC^&{ zzg$Wt)!R5J{eX~<>|TB)nXQ@=ruPah?>;E~xHRXUr44K{Y5<*^o7;rIJ3jSyZ7hor z?1~c4vpN?RZyewkq3*)6y;W}0DgAgL;85oCE!H~!RojlHA3p-EtPbUy&bM9KNwd^( z;2YzHhS0L~7xLYOze>}9A|%>cX(9sHti)w|D+rC2PKS6oPqyXAqlCz@3Uh@K4JjSUiIwo`Jv?Jqhs@k(Acm&TcGwB5wcO^W)sny?e% z{u2g0Oh-Z>rkvL}n_hTkc(MhKZ`KalbfiKc>CqMXGt53#vX$YH`;7u*q9T2g$)!E_ zq7){dJe03sWtD5sqDuFK%)O7)lsvZqz2Tm7@*!PXQ+~oCcmS4zAM&rQ3wW$?P8;6r z^-O%@I$-5CYJx&_RFVGt=z=#M9{Q0`h9>l2UX(5JF6<|xgIMeIOR)ROefPZQ+3@`D zf)Bz+l@@IiUAJBFG@-a1^^q!{l6jO=BGPw9{hmI@?^QA5jZUhZKQ(lSX1#sz+a%Set1JuyYnvROF~s2Z8vDGkw+0QOBIeH@SLyW7*rSvc}{h1k$iH4sS=E z^sP0i%Ew~0vXIp-2Te*{0}>w5l}~q2T;~rx;OZVf((6_3t;siX#=kGIy_Y5TE&tX{ zA-jE&B05`xS>!h^>Wws*ZP7`C?KdNc=lY$a)2Zje$I{*jw5;>h9ArFO*d7jn_TOKo z_|<^&*@~ntF#C*~!|sVhtkOfFG7h+PD227>Q?4OR_n-V3Dv+-4e}jNQo;H13q<;c( zmg&3Ks-Bnr0m)IZq1kUH6w6@Yl^CgY21g zlR|S>8y>4PmtN_@(7sJi5JS~;6gj0|sqJKY#%Wf1pLa!f>5#_55?$DH*uaZd>`K(v zsu-7gTM;@^&xk}URZ^616lZ2-xjEN;arf}h;q5Dn=g53{;|;+edErWmR?d@N-kJn> zZ@r6E^;{Ap{rtBR zB%gJ#N^6#vtLv`A-jP{Ev3BTT>D2f*AWaUTEJNLo`Rbw^Ev!T|_0LnBbx%?WX%JIP ztyhnpj%+2pFPFl&Fp{L6Uz=D2JsoB(o+_W1I{6m18(7;KCUTcqAaNDyA&u3dOX@ln zr7C-UdaH|~uS~G)TE#khtY&FE_h{}CS-xMW{5Bc7xY+b~Y%|Sr?CuJW>ENS2iU!yn z+>Pt0x$jHTXlo+<;&>jOeI46DDw2UMfAOV+fm5TXNFrpkfXDut9cjQe>itBwl7Gl$ zvW>OcN^uHJA+C-~t0u$4K}}1DU@vyjR0Ds@O#_@ns$*i_}`Y%PECejnXsdi{CtTjT7RXQO|@xgPiP< zyR)ieho>81BkG~RwGt;nqh)637#Z{M5yNL1{#BeMdW z#e@7uaDTkrv7HqE42m&;omXE6qw22Bf6{AHviAP<*xvZfbN}9t(z2xW1DRrpGT*|C zqe2A=$a+HUg}U?59w$sny!b0?r5XA;TZ?`X@(ZDfS>bPr=ULBEUmnRY;)&H2UlZIdec@)eudTe3?BdY! z-s8cZYyWN*5q3SN_K{E}%A!u`oXkDsx5ci=X?BXGdr5tdwxmP1&BS1JGjj8EFu||S z4)I=I#SCtRy?t30BdAla6C=q)GW056e3=F7frm#T=D+I!;O&7ja@M1iw1m9X&kG4q z_u7-&&{HF**R5dzrffAgD~TV%(bPR$gFrrC(~yihQJ}g;A9z59u$8=cgVD*+)wNiC zaI-Sr{YlOf;gWkPQ9oP^gb3^75=ZKkBS=+$sHF^~;G$2=sCw%_&Uf$Dy6!-f?fy#vp!U$G!3b+Re_3hwD>Le_V%u)iC=Xe!$1zcl$G7_V$nTgj7T0@ zQud&vfj$JztIVUDt?(%Y;gBzg$9zt_U}?Cn&hV%iv+8s5+2nrjJNDb1R_M)xEtczQ zRZyqm93EVs{$9B)c7QhDHnil06cm129gafd%C}Faf+)o;i2lX>G1N6qj#-bVfp?EK zXJ@gLvNFw<>L&y4H6*y7dh;X7*i%j5sbcDM4Dw4?+ghz;O1$jzO&_*V#3?#W7drbv2hLzhe1eD~A~ESTaK-_+9I7&5fB3JYu7ZfeJSUN=j-OZ@ zuHSzUGp8S_(04*^Jsg`hu5>20l6(iVMN;ir^i0Sik$xGEtH469RzeFr@9 zeF=&yAa3r8K(7{eQ<@sc5fc-M97CRZGTD4`f!%qb>N?S)o!W#lB<4s5drjH(*wA0| zwztqDbX~}of|n8ej`PKqfhkcOE3P;7)?QqCF!}7U=j2_URaf=2)-UcnHy1=CI58-p zsBmw10_VprE4K)akDT=V!#Y)>suzSywRo1E;!?yJAvDhDNboq)lNy(;F=`gJ;$062?iq6_QN zYkj2z$Y;MmCIo&1nj5RYuFmSL=G*3ULA=WWPZGG9xKyPtGyB8xoQ#C0(B_B0N^$4p zgoH4O;%KF?3^#|D4q>NwxsCTFs8@`FLbO=x95o~%5X(>|I@7zP8j|F^u@(=clLucK zy3M>}O=L0cpm(NO`V#M>6xuZ)&{Vrvc~NypsU*DGmo2!641@O3_t9LhkoD&Q*x}>? zm|yq>@WhK4LF1)k^m zi|Z_Rlb$`b$ddreE-Wri?xh-MH7E?y2)0UR0joPjTIlpIg6PseIRz-oo50 zxoVc`3jf|~KF9Rxw#xdtQ{(lHgLadbrAF_0d$3ryiN6)KQcdhmW*6|DH%}}+aJ7ef zSrwL3d%b=Xy|-9wz5=u0t6p=tsBGztEfbZFHRBp~otc9;HOsEM!Uf)HX+%%_vVIkYSJxP&gbT4axkY0e0P2Nnl&lx9oR+7m(2UDTqO%*%E~(N(G;&7`WLIV z8+KY3yLNl1y*`($-qXYSO-^me`<+>86ttehmXgx!J$faGF34Bs-5G8yGSO!aLA*xkP30$#At8TOPoivAJ`Q2>X={vjys(T??puL^Sn zp$ieF^p~L9Dij_VrV{4MFQKp(oCldB^=4-yGP0hF61jiAgMEN&^ z`NAp&YCUL zg#t#KH3nCjzxaB1c+^9=Xcz3J`*3_Ac2_WR6voLRu0i zjJWa);U!Vx+76AK=tdmU@~ws-0Hk832OzJSx36Int2wwE?RM`duCG^|#Wa((*G(T| zC1lsr%`fpCyB9%lzGs$9XzVzc{00W34-@&V7o{|>`P!t`>aurNLF{XW;$*%q=Mu>P zAnF>etrDG_{~?E7*Eo-wR=x=xgwUPE&5doO9&HU8ogGtVy=9;-^s9$APhU^3hq5}R zJ7;_MvbD&pyg2Q8`l4&{5>jx9)voG}xt*GtT7GVB91r`t!)O_qLitNcfqZLXzc03) zS^Daf;#U&7Iv?i$AIUf-Ivz*(GiQ+)fdxyezFSH;^SEb0s`w%v4N33olY(4SMmm*t z75o^24X9Bl^bCk$sUGF;KJc9+Ozn4FwhdJ<0zJQ1=$F>eOlc_|H5x^Uof_p{h7u34 zIP^t+A%A5F?(9%GIAmA_#y-`Z18Ng;?BEON9zpyQCb|bfU*qUbj}msb*tq3o4T-WW zJX?LVol@c@etEfmr4dUfYa0>1dmkIQhy|Sy+xP`k>6fBqhQB2;86<)YVAfC*Vtu2H z(-)c=%jUGMcD1_vsdfmIrAAW?Nu75-JwAOLd^+0N#f^gM%5xnmhWY62F^KB6yAk%s zUBM!T{KO*FoP?yLfq?`bD$FL?V}aOZn}>_BRT|J8`vB9$fdn6$X}e_#Zrzi2s8@{t zKi1Z2NIn2I?++tR4)p{%7c?SIsJflB%VhUz3sY> zPnM|sxEsflMfp0vT?M|0H9PS_(wlw!!jtRspL_uDL#oz`;&H#bOfJ8jpTlQ`FDpm4 z*i=?IhF1H7vx+@dMv>Y%``?z{%!aniZtUl}jdIyVGz7m>m=_6=)aD)J;NX}KBDlmp z2BMf$hD-jUo$Q;A;=K7!bhNaDgU^RsgFQVOz2aA;mqIGlR%+WpLuY2XY&WEmaXX8$ zDF}!YKHxU~FWOWBv?-NY^)yb}=wNJ-(%T<2f~%;hEzCveQ>OkCAA;U zgcxnvZSA~)u~!2O(XLaadB8s^7D+nSGLZ@%c5A4_h;H^_rAy<=h#Ba1+k66vkE(Fb zPVHD+_Af#h#$UtJQD6G#L4Lof6q?)#lB)EjQ(8%haBX|xPP{|zd}k-&rDFU8G|5*7|)MgqkvvzBCIU1uhwijY}I~Y9xo~Kudy6s0o z6vLWMIu_>=3K7iMzDINj+l3gKn+CdZ7U3j} zc+q*T>YNzQspW+D2|^86@E-1=XB0K%CPu~x!^6?TEx&uCp939{GTzIXsTU=~!6zRi z-stB5kNXlV!(G}iZpXdt5e-sx1~FzM1Cd=S%VPGv{L%?8Lw>1wd6*D|o;+;;HQf|z zGBLhuG0gKvCyTmDWM)uvbP|i^dsBu}S@a6k$^9cDM?d;o&K6}NQdAz&cQRjg>B`Er zc|`ZNaiMrjR2p^AIA)`ETU^=9QnR%!ZREtLv4bEb$o?8~P0aC@cVH@9!a7_5J_3u#bxo$ANb+f!>;O+TEb5sC?F z8`Gy$Va;Bf_9dzK5|l(SwBQz8 zYgiZNvmDi3$M^aL?_;-`$kL2rN=UT)tNu}ZJW>R9y3h&N+%tNo7>gyGE#gRa;&_bI z1{gnr`B<$k-~RZ+LcYX?LK|rGE850g-pJYNyn~iB^cGdsqtB^rxX(@|eOtEn!07od zuSZ&H)|KJc!?$xCymAi)ExbyloN&?7>(MBMBmM!(_NGs`dND3u4@!Qoiz|uNejVHV zQSu%b16bbE3od9rrKaPABpo=vpKpoYX3++4weiU=R_I z?}gkyu5n&;+}i=@(Brqa)7{+-UY>Htm*-fXWAh>X&bPEXsk5BgHr`BaQUo_g$6p7iwvt{S9e6S^6Yg1t$P|nv=k?i_A zrD~2`P~qRK-t=akx+U>dc!>dIS$f^{6T5|8VF#IZrX7lt8nO+Q;4*}4St%$er~@@K zHK26oMK6a_DxPtG4C|uKj2mxWZ%P|$JBcpTMhZW0PRf<}Ga1cXvYem#OVr2Y0hv zsTjfMQW`@QiZUqTDpUQj6_O@a_&uur)UoToPj+50uo%X&4=Ai z^P2R1O2z8sK9P0h zmD&du`^}eK1MVGhG|9}iqDh|Tf0+w3MK_tycw~cP7>aiUw;!4ND3w)8c)dPcyz)Tg zvamSat>S(sO}>`aBFC63LFfS^t6vYiz22$rO5LbiuqEcIz4%_W6;t6QtR8rWBfkbx z8~5;@IX({#wOE1Kn6eJ}9DH=v(OYzh^mdb%(avp!=1aFFrLIW9?m4|W6UBVQ{wg1N zvf1d*oewpSyC^U_L{``I*pW$JlqPCs_+%Oc;U02=d(8u(R-dn(X^TBLphX>SQ@}E z+3d+sNGp6KrXd&>J}`UZc(9qqVtvQGzU6+NRK9eLbee~~@0k;MC(r36wsBPt`a^nB z)aq7IsN)XdSlWW~|4d1Gq9%;Vd&DhvjI6Szp!-LTrkXtpKD?nm&ssS*oF~mUs=0is z79YsPky(tU-0E$2go<;HI@8gHzW2WJIs@s}TWvHw?DZh@XKoc$s4#3C)g z+d45{jS|z;1hL*K7X$w)^Fq?x!cDqL9$>*H2GGHbZxKK@4yJ)TPu)Gb?Z|vJ!G;^N z?gawv4PzfS{>r68PeZr($h+}xk$vRe1AZa6==cso#EFzwnQEuf#<=qhGcmwPj>Gt~ zgX&9|YW1V#u=S*FsTkc4M*8}Uv&_@d6$j-b3h})CTni&bX}Dll*3r4Yp)EQbm8@bc z!|l{c?LcLH21Wf|OUm`-ZW_Bq__^ML_1+QrE|H_dhu+dWk}9kb;`6XCRD38i2|BRf zEaP!Pbo}<(vdBuc0;MIB6TKnp3ox z#cQMA^kSZTvmNB(=r-nqZ5`+qrq%_>t*eMtwI9Kac&={I!vhM7Vn(}zk9sU~#CMFA0!5>|cBHfL|U+!Cp}cV}#HLAdFg|UrNiP<}!qT)0FD-hXk-| z+=jlE5b*{qK14q7XO5PCMPJsI^(_$o&V26BbGsh@$yinQ{@->E$IMsSys>KNVxt~U zUgcJVymYchXD|z}S7heB7dEfBGbthKbL?OHO&N;{IsE7{BphEg*mGK!cc$Q#uJT1% zK5Nh?@b+0Pu2>i)Y*gWb-(D8S1&Q^0*`N~4Y^G6EB?*T{EKlHHY}%~f_UH93WF0B^ zQ5#?@R5|mINGI0(wF02C&wr}Y$wF4?7xZKiLv6Sp?t4j3H{MCR{3>W!*2TIr?W_Ho zQq;KMiG=*O>X@D`(j8|CF-rF5SX5@PH*#R)tMw-bjs>HS|z#;WGTaJkjGQCzH| z0AsCjUYh)pnv1~}d?U2mX`?YH99wAk=zm5O=9-1L56BWwdM)cG971mB=MI3;>6Tbi z9fl0gOr%QvU~0Nhco8&_5OEv#U2mox25V$A@)NSY zr+izPX@wjYz%#pK&<*;Q@gjJ{7l6G@&*PHDdtJ@G&d&&-{cI;6b_|AYgs!i1FOd$l zl7CF%wsY{Y(h2((p)KAzFk#hiD6V_*Xnf}jLu*A=W~IbDOVd|+EGiG@F$Sw_Xj}*? z&vbF;5;z_l7)3tyNP2bf>hucPeBlP==EJDOh4IyWGKW^%g^n2$)%&D9xgkI{B<7~b zzq!d@e?Q3Kh0}f-Cep`w&c~617_tKXo!xgJWPl4iN+TFp+&4{&j4V_5j+Oefz^P&* z*>$aw%mRybWD{uftHSq`FO!Uikkc+(X~HH0o4&-F2PKR6rVD*j9LI!aHi}b}p}XS& zNdwbThXh+C^iaasb}?4~Qxu01M!LjsnV3z+QH^cke+&#!&jBmyGm{(PVuRTKoPM%Q z*d7}d!wl5w9Bb=9qO))=aT2dV&gO6<@b>qah(O8|b5suIw-gfsqJ&QT@lzpACcZqeR3G_jNU*!|DIZm%6oiOF$_2imOkBFNp!O7 zi1(NsiTl{yUWi)91`oHJI1J4@2~vDZ@Aj*JVbcUw@vXhh=T6;Fn>2AF0;&R%yrimx zPt4Jt_nWp-gg-sJu#!ilF^7i>gExWT!jCkciw8-WU#Sb(9Ns3If^W zw(+!N|C@y}c-*czeI026d_)R+^I4$Xde_3#dh-Wj_Sq%YF^N9?PAqi2+z1vf8yhcO zt|1B{tX2Vurs_ySzf3S6#Rz%EO&aT6sB*F=Q)|5uJ#PKc$jdG$Bs)`w9<}>apOJCD zCaLg`qRvD~Q4BNeFE%>knblp6AFToeg^4+=3uF~?lQQ|jNYgf5a;8nP-o8zY%lCre zq13qitK$8&pN5u_I31j&sO`QAx869~njO2Z7HrTU_ki@y> zn}=8+ny#_^%Ua?mE&$e+3N)O>_NrRljZcHSE{F;_EAN|pgpo;Y{93j(>MPO>EGYb4 z@tvDydITtsssN zbzA%({VfZagrdA-bx>fs;^X6ySt@fALj6b&0ViEW`Os=kJ}X1A(F!)D;ZD(cZA*{P z41wu_EXx#_i*Dm>{~D2wT)mzo>~FRWpGuh6<&Dzw!0+;mIC_ETxg8-qPN-K5(moVb z8DIMNH^*Ano3;DoCMSdUl$H$+>J4`RHfndoxg8YyG`KMh%lLlG^RpKJP@D9>DK?UQ zWv{kMo_nEf!B<+4zsCq}zg=Fgi`F)*SS|N*(bv`O_NSR@-_no?ZwQ$Sl8CQHOPuSy zZ~Bnh<48nWo3~Fiv8e4X@A3CDBio~SLp5GooKUW#JMpBAGDJ$r3&|dwzFAoh;&QRF%!z1*%+L1PPB7mR#ccP95vxr(SXEJWf*E+FYJ%7&yQnO|NUJt|qe_L!HPW zT{3{%myAhoidAQ(!!oU9AoDjR77!M7)3hIkBgUf&c`vxF4rO2SvxO6xC=cmQ>L*|_ zGJFT=(s_^F8w$DOuwk?Czk<0L3(Fw`9%Yu#z3^+F%jbkT1>(IrJVUUg?e74j@7gDh z2Z>#ApM9c()w*abr^7M!9i@@aJI~UBjAQMT${vzNuU(q8srQxh%F@uud9p+8wX8M! zJqq+;&SkkW4?YRuenX<1iTF;q>-hIK5mT2vsjj(V1%Xj%7Z2t|iQ2QHj9R5(gS$@? z9}jN2Fr&`wmprecyZ>xC{!1)c^*thi2psMC#H#8}8g&9kT{j%Mdeg1<--+r+&EG1& z29*&{n&D*bTIqY`OzY}&CpsbT#w_3obE{n;_O%L$P>K{J&9Vx@uIx=E-nOcd^Zc&I ztq6%rvm9J~11v#^UeW%wl&V#-ItBJRM1;3sI16j@E7ww2y+psPlc0`Ccqp{+VT4>F zuSJ=+wpMd|x6NqVlH>U4sOWb1)a%!Lwtx$9{K5?-vc{w&e%cHY*<)M(VdWopG9lP+ zMU!+^`TW99@!YTK`dVWXCD9IKc0|U3VQ6|73zK&4A^EJP#A=3V^JX{HtXrgW{~7}3 zEc*tAXuqP<*#|q&GD2hD?r!J3l$b_=8*@TC|H&}*+q_Z?6~5z)u4H<5Owb9$MlYKY z+ZVpQTZNDsd&=@CL67B_Iiq)Bb%A|?(BoU8Bx(-mq*goj%| z$*14Zsi5jAwZ~;gAo_uNr71U=BTS48YS6Xgnxoef64$&*V^0b|D(qeVtyEs2 zA;jSTQC@m?RsAk!GcZNs3y=+yniAt40Qw}#I-nAn$ZD=*<_O^(A#Nb4a1HOu&jr1r z5R+;H8FU+_`I}Lc(J>XaNnF_dPZ}+TO=X<$Q8p`zA(DzzqA*#7x;$*UOwL`8AK6&Kc#Z zesS>;8~vo=T4al?bnh-6ZfOY>>o23^>9>AzyaQdU=41B4hBg*0P=rq;VL}ZRR~IyKiRo&y#O@@P~sh^cGz*)OH0|v&&@5y_zuW_Y0sH4g4i495R|hXViWk z1(I-I0|AiZm^$yb6ZG*DhqCn!v z=Sef0HI#zeMv~5`Zm+$7SJdF*_k+yEm~5o2k$`9S}8PdKA$_vq;XNz>;x>VGB>x)0ar z!I0|9uomz#P7311JET}Jp1#(==bCjC-8t)q6%3q2j*cS(UcP!d(U3*k)!2t3r0)lm zuR4`y*3wa)$L46~V9))K(#S^aT|P_?+_^{2(wvC&_|!Map~EqRl^>dZ!oS*xoQ~lK z9X!=@|JYx_Ctw}YU@9ehlDV3Tf-uoxcb()jFL6#f{8Yc_AitO~fGHt54cz?b$!oq-JX!m7>#|q2o6D~8~4*3KdllVtG%}ZfyE1$-- zf5PS7x0)@l0ms;?VOTffPc&l6tZZ;2BcH514qAEd`fsW-IQTAR$YmXM_?|h}xg6_N z-uYbA-?`R>1@Aj`oY_6s8@grA2O=?6hC64ZW4o+HN9J)7nDn~+A%)k3|1B@Czz})& zDkPQ}cVp+2$>iF#lwN-;$;^2$0az47204L7_o(6vnS1KvtECD9n*-)B+dt|y zKIy6w%ymY(cvkMX+;p5wkpD1!eCOgfMZ7J})ea%`ZSh9-TOHO!AVxwgk?@6l`(zm)Yp#>)U&XfO<4fF7sHb{F4Q+XIa~7#j zI3<3??O?mJRTa2WJxR=qpF{gLwK53#A<)^r`n&neR;^T&50hM7_AW1nS#`FgAaQxHajZBY8TUs zh>xD49N0_egCvTg0ykFWdR=PME~+l&xX1pOl!i^}S=)3(@TGA5?sZz1S^Re(V{Jt4y3Ly02(<4%&gcR7VXM2+=Z!ja+d>ocR}XJW`r zwWL?Ly29_{$}d;clm{K%1-(xj&>VT2&7@s&&~(mWh8x3Y)jWKy~3pyf+&-dn6<-&dTg&Y(gc` zbVKoHX!Kx475t4Jb0MHQxXsN?l<>+kqIw%>FQl(4mN;X;(6xz-{ZIq-A&#$<6yZCP zj$YP@t6`hse2?LIW5`}t_uyIIWu>{j(D!E-iua?NK>h~8LPqyi*O-RNoxL~%j^9T7 zJ2P{+#+eERO~4GjF`Tr0-y6)vm+^ReTid2;JC26vjv4hpGE?=b0x*+WUj_B!c;y+b zUw^yuqPXs*4Sy8Dyx!L?t5bFBF*d7y-Sh&SSEavtAPr!eM3F|>V!$6z! z264y1#TuZJ5d6@Ph_BDrs%w-SR(*;@MKf9l)c($$&jJ?-hH}%LN+rTCu636(N+B@` z%q<0C&9oa(>P!zWc5?Ap1GN1sJR5-KbEPAu~NU0=~PiEZ*? zoNEeaA(q{s0yrLU<@J(u8DRgNzJzCj4M$|;e|mOq>~kyJus`<)PPXB>eS; zytTI;Yj!6n;E-`n?F}V&re<%l02^QjP3vH(D%y)%6b{T~=h|tk6xU#6ESG!%*?5Sx9-Ain3;_2l|gPX9~>066JmL3SRNz3j*ds0 zR(w5z)O^(8nCm*8U74nsl)9NC!+<~<%*4!$;vufTdA>j z*Jd^OM!fnQS9RJ?j7GPiUH%YAqn;OZ!EqY&h0Y-)B5ym7&!1bTsDGK=-R(a@5dS;X z7n%pvhG>8h_y~qJQzMEH%dcQi5e0o@c_lzQ<6qv-T|X%kSlx>N%K6wlNzG;bdZH+Y z61hCAu|7i*)Yh?2A$0&Nu|F~}9I)VGB3|>8Ke69tS8*a!gwxKHnO$|H~G9)$N{GvDI zB?-22X8Pc1bGLAtL@UVqvxMzek^#jZ;`!J5T&18{GCBh6Sy|wphD%G>18D8+39QER z5w8!lN*sM5&Z-D)eImTK1C`_+rF_Ot-Z>CN^xTpZMT25JYHfl~obdr}Om57Emnw#fo+G;>w+ zYH`XM-4HzXxYP#~!#b%vI`nAoQ32H+Lh5W}=yMSBcMm~RbmD?>A0`>NAVFgf@Qxol zvNSDwAn!mr@*0HU)Kh6p=)PtL$U*@=(x|(I^A$yVL&KLoM!)qOUy?l_k*!cwgO66P zAU;F$hD+ezeY0J@tN$rl0p)*1zu2C>w$j=cM40#<&dz;- zANGNDe=KnI~6XYz&8`cfj8p*?cD4?CF=lEQM@ZDuGIW9 zzu8HwpizV4XFFms9t1lUX$?>vW^xdrdtx5o$9lQeaFZvZ6amVDWT@c(7M=@seTEF% z>^Q)JDPML-q}P_#gk%a#YF>-OQPXY^-o{{#0?6AaNZ{#aG^Y?V$b9 znKCkis*oTx_vCUCT_qOLB z2Rr0Yz)?Pf$wG@%u?j3)trx2R5>>ZI98I3f{GZEpiXawocGuNGKZq5xV&p878srpl z`Ro0pk${*E94%K@EhiyC+W|t-Mcmm-q#1S~GncK2mE_O(KT3kQS)#%sEan)(-S($c zcC~>f#X+Zcp!c~U6gXtb1#-?F+-x)xh0x1_(EZth2WpLXVAo?SUJ)kQeR6@Ucgviy znxwL905rPF9X&^WZ>*KobG&mI9F|P{ajJ1ANTE4#^jB6?Km88k$o~grWy#NK`#?XT zOJ~Ssum3fO=}T&ACMOZ64qTAWXF;9%vvC8gHhxNjE`Or3j|l`gFh%u%wfRHT+(k$! z(Non0ymeUO3@|AxJEgxF>=^-w8ojcqaM>~3iAayhAP zs;nzRBOA$Q=D&Gu8Ayc%y48DZ+23Dr3TJ@m5f|=%?mq1a*l`BTY<~bw5e$&FfeclN z{B#X-a=qj-#PS63f&$~KSVsw2$Ulh@oeK*0brDUh2T@go&=b9Wa{)dRVLHIDFv80y zdm1Q9lfhmNjQ=$8cmH0}XX03#SAP`a3rw`BAUT`CI@=L*LbH6&16!qJ>A~;)@zH@| zBo?%SEBM`;Mm;KAWMrn3*_uB)>qIIW2C8^K2RR;h3sic5K&IC}agcXR-hjOW(7;W^ z!?`vhE1{E3TSwy`0^xFdiu}u70Pd%NrsB5` zSK8r_ z6;jBRic%3tky1&i5ScPWk|?CfJZn&qNXYnG>zu>4_xI2H`MlqIbI;j(ujzT7wRRjH z?q#Van&)0YAG`bN_-X8ud=_d&1rtg29$KkwyHaCYypvlLJe4t%B9w&7SEbt@uXztd zvN)jfOkcNNXKOxW(+<w zAJ$bu4?Xi_t9`i6zzKDh5h2x>P`liAF}{#d?&Uu83`!}88LPMj zk`BCZ!DZ*hn;QY=JLDA9*7qGyn(w_OGZXaZa%CR|R;cgF@6^39eO#i%U1NM)jAjI+Rh;^Ox{_hS~V^ki$1#pSoFb? z_5c_Tz7zgV?DB}f4c?p4I;|l-(ON+0s#>-UJ2lIFXH9CKKZ&oOcc3n1eZ#Ux*8k z3^e=h)wH6zXEPPnAy;-5uRozkWj8E@Pub>IhX-qGOj79FnY92Rhb6mGD^GB+)R{Qc zZn_}OBQrMjr{jp%(JgQyg|(Ffmw@sl+dfP_)smD={MXgh@!`l~@LJDZYbOaQU(xYc zblAx$DsrlAAa^+QAXof)DXpNOP`zw>f46H_xvjz`D=3X7UtUnNs45APF4h3`SWmL< z*P&$GA_cU_9Qh{SZcWqJxm{z{g2`l=F231DlvH_t6#x1XP%6fO&Up>CET_xQ5v9+# zp9`R+T4Od|yJvU&rsaTn3D4aSaMUrx8pRxLoWuoNh@#b`0#o;Q?=ps+{6q} zG;)m6i&Px=v43GgB$1f`r;y^{w#G!$h%H%$CfL2T@n<+V&!6$UGFwOUmRBFZDbtyC znLHD3?&clY0f;a7yL_ES@#PTzAhT^n&Hb4Byv{o<3sSRNk-{bVo!f!xlm;Bk!NF+x z;<6dugLsyEXRd(|?h!?kw(oZsUO%gWa5|D6Ie4}Q=48@Oc1=*CkA z75N!WpGDlRo?4Ppykfq}Zv*FE$E@IX2^%X;Rxj?+bvzdX@u?d7cx1EyNFP^PxPpQ~ z*+!UVXr^tg7i`N99u$p21|_=u&+#LD0Ta5r9Z$y zGX9O&x5EHpbbHYB5kbh46U@)*KG{_+{XP7P@+2Sv2VYA6^{kKdEi=j~oVIoAR-EXN z1n6Jve(ux7?_Gj)uZkZ%3*IJt?e1GT#d2ZAWp3C;RBrL8lmrS6a;-*{!5Xt6jigThl1b2< z#`xIfq18t>PpxAZA#IXAv#De=mBy0{9XKUp;rnInM89oJl3`JC;lc&f+T1!hs4(If zZW|=yFy3$7L#O9c4i=xZgN>g%()ki*&;WZG`MowPa2{|GLjem;8$Eba;4oB8-w0*b3>J08Q;A6&V2CrL#W)% z{>M>58&~^1DaW4g(@ww`BgcY{XfqGFpa|*RqO;*Nbbr+zzH`p;B7XhRY6d?ZNrP^rlc2ItkW zJDW3`BV8W6=Pje0Z|z<#gyb>NV3v>6BSp_Yj@CSc3-o{jwYq*~2BZ~9lCdn(OGGQ) zIAfk&&V|)5Ca7p)m(%ZA250>u-p~A``~JO?n%1Wg`t?q)JDd)JknZHAf?YSjX}zz~ z(9lo`5l|P(3tqfHty6TN)o}lnW%hA)noX;!KTBrM4V|lc{>$RCrRD*>i5IJYKRJ47 z!F4aicZM^pua_oExJjP$n&Pt4OkIA)`L=*V4IAOADzkLua;x<1ilr+|=BFI~d1E~B zMUbO=i~C5bQ%}vt38eo!!#F4={pl*yw&aAcj_KvLwgyiBP(&$C7t+iEX`RlvgN_vd zan$WJg|A3F%GI=kbQU@;SZ~my(6enI2MPmeHvpS1o>f^>E|hIvb(pWV@N~|1`5Ad~ zTP4g{MZn0p<|VL&jtJ(tsDbO23YjC&Zua$0XO|4PhdMbCspGqC?IM?aT&$JQJLkXy z9ngJfWj(IA73XUH#XqRjEm8{Pa^K#AzNbL2siIOM*?8WhV!0y|GaVDN4%iR9i2T0x zaxbhom8ZBdGPF5162Pry`%?za35Q6l80@Jf zL0W7eEtU2ot&b7fHw;qzxkZq8F==6|eDAwS33If*q#vA-Yq{WZIesBNoQti6;Lup6 zpzCAu7epZyRk4H6PSn3-b%<8=a^of8cih1}+V{5vQqIpAVsP9ar-|=dK}T6&_vEIK z`P5S|?V#>8+bPU2-6SP8zV0MH3|N^eJwy1*t@JzJMW3#>%OoS8a5`MWrsO?|JzF>h`4b?;u&djdiJSb88ogMKnSi4lKi(Q!6JN2{w~^&3`{g+I7_+f6eo6azS*j@UFn>~zsGX4u7`0YQcQR3Eb z!>9w=u4D}L?EcoAHf=j$3E?^B3V~vwPfZLOIa@=1l^jA903<%rv?P@D%lxv5xp-c8 z@G39s2BswHufH|k7bmPA|GuU`9*C0N?3%Yg9@PF}s+Umw?QF3ZhW1W6l3!r5!Jj~F zMuxd9ZmVHS%8tnp=paxU9{uGGO6d(pE}pwBW!P!^BPG3Vr$B01y{lo^%DW#^2Btn& zD0lMR8UML78g}>@V)xaRd%(K;vF?+Q>+Org0CdruC+aJw`Z_?Jt~`+Bh)Tc+u(BFz zjmkfoR2EP+>rOxypa71(d&h=ekyatb&b_(ayugGX{os%K3TY3z{AUYCJ8=jb$;+`L zzEB33g!b_-9w4G=!jGx2qt2pl@V?fwWMACgI1g;Oq8a*j4hvWB+@=&(wqjlaiJrgK+&zG_m>lEpE4f}HGU|MPwtnoD1MLxq8d_14N02UkbC zLn>w;S5sH#s*64*-RrCD3T?9H9D@ypwr1> z@2tPMVXsFHzq*jz`dk$>g{Goa)}5&;F;)Y!OlM-Gnv1XSi>ZjbEKRO`7K++-Ec6{e zX+;b~#og!eAUG2!hydv?JB9kvZ;RlFZ#u?dslvP)rQ(Bn&5dp7oI00nE)VL`_1~sf zx#xddL{udHt*pk+hnZ7gv^$sn&gIv&eRV!WFX%kP#HIqb^p%rWd3<;RTh{;E1`5NN zW$Jx8>FAbV1_{T+R-h| z;Xa+~`lhC3uZrKVPo0S%M9rSFE^cs6;YAzQGKvq)-AI6a`ZAMbP*j0^B3@6dTcgRp;AQH@ZfKQM>I(Ru?=%CN9_LXMsIr*L=~H4bJo z?TOkClR1vuk_31mc;BpLFZSY4u|Wr{9O?J;c<9?J++_6U-MqY`!Z0D^7gzR?ji%F= z-Bfy{7ndXMSdtzvbxmgZ(btwPzo$MAT%469YHz<%L2bkAs$;9`cnwpR?n;_KN7>p- zj56B05^Dw8gV^#MS;fWf!=vSJwrz3))=$!@DZgCTKxrR=JpG&(sObH>pAM|XJp<6TmU1Z33r27pnziC&#GbOn-oz za>-LZ1=k$ZW%lbty2aUf%DyeJ6G+(p+;pF#CU>&x@9vB31%Oazx1Wg>Z}A~S6Elq3 zs9!I7P>dr)c7mDlTxg-D$bdK)eNY6&IVdnXeb#HvP8MA&Nlap1If`2;724nqCu*|Y z6g|y4m&{4^=K+)aH?4G5qiZoYv6gaxhZLreY15~JUI9Z&y~y8f!yPetau*|>!Mn>S zZ@fFye8*_Q5y4fa-a?^4x-h`$z0$~4D0X>WeG1PNtl^7x$I*#)kt;y%R9tsyqP}!X z8Lw--tn1*;th<*>Ppw*cdB<={NU~jIaqXh1NrNDE>uT$3sGqD>{_ANDs{@J`yT>nI4W1fq z{1vQRtJURgKQue2**I=%%Hk6d7jFhSgBI8E;z^^f?EJlin=OS9NB&9#0)(o>dna?0okh~*N$?nHA|V4yA|psK z<{FE8c3*%JZP$-(-Ote6;K;RS{n}>W_HgMK?kv|5yvN!?r z8=Pd}zbI2XO$H^hf7opm{^rV)Nxxi#5BP;k&hy>{sY`?$j)(^oj`Iu+(AQtCS) z+T9--Nh8ZFVGe2JW361su(H;OMrMmQ#Yw*b*-_5}g|OEkZ~S?1`SJ5jlYbmAP~4Bw zyLPjR{$dkLgpTSSy>LB4oP6YU%N%bcvzjq#7e=RSz$SocFyCr7vM3Y=odm5(jWIC@jeRH^)vt z>ht55TFN(h3J_}vget<`HT|lH`KObZN`^=UPhY+FQ$DCg024KMcVnba=kha`B~}Yv z@}#{BpM#`L{p+ghM#n$!<{UhDP%pFR-oTH990T>`Ukg4@O0wK{|Ce}CYh#K;(pjsI z`vWbkB&W{OKI!5Xwpwq4^26xI6%yu&Gr)q3nuC|Vewel9fZdlf;)NtQ?ku1-wcPl+ z2sx}V+nVp%M{cEiOZ++jJSQe$gu=OOB^>2+`tj4=Ep`m2Bx~A3F18dxN~1;gEb*?F9k(4i0QLM@&7QGr*|PZ`j=mKdnzbQ0F%hc8 z8j0U;?_99ZPuaORP*X!Ay(clL^4-g_nDMHy8xr2mek04jV1t$UA&VOdU#ucjP;nKf zG8-cCbr`~wI}!85J)j%~HNacQjzBt)`x^KHC|24tH?=Q!9JOgdZ} zl)LoSCgs5J+B6~7<#9&mo+Y>?K=#i)Ui4L^66k)pupuLWE{Tf;(Qg|IEB*?V-%{oMc z6&UnU0!iA8)!tbu7O|0FVpSo?94x40n1hA?qFl4w@{SDC{x``gF3Stl9*z-~2il%b z^FG7D-j2tn`QW~eQ)#;P0n5EPt2PfF_e6@+*K++RF~fyBd+mu$rTgN}g)bwueFW~) zRxZVjsxxZd4e{q;GVm3XN(FBjNrTv?uUi)~gu-B~K_{MIxHn;;e*=H>JWustY*6D0 znwX?3IypuQm>C;QPF5}M^TIUL-X^5J5MjyK<=JRnR(gd*5&i{MF=~2-qZjx8v4gZCQ?hG)>UvechEO|Lz6_)Sg85?AQy+}6Pr`*OEB(Zi8zG9rM4L5)}M zkQxiKtf+~=GI!9UO?Q(5HS%)@B5cZ>qAM5czF~b7VUHSF3Lw>s&E1_=<0vgotBH#L z$JmxT@bOvU0fuUNpgf}ajUo{~j9am3QjWB4-K5RcPvqwX?LltEF`MRAIuT@)ThkX4 zMGr-CMGt7?d==&rEfOQm48tm{on+#Lf)tw?adkhgO$X@;7k(pS^bnEe|Dn)00RZLd z<@u5%E8_(q(O)-@h9f3Pi(z5F`dAClTk+z8SN6g{a_m?52wBPRryZ#pDI#Rg1<0}W zf>@T>A7}$ygOH+yn<;U?7vlh$zoQ)`x&b1E8$vh;TUDv7E@koJ10&ffHs1 z>H&244Ncthivj3+`Xv=a8~7~em}l8joL%-P4O5mN_Lwo(3QT@OT_ zr;Q8<#mf4h6${3RFT=T1q78E(hGS$KyoO^q$vVu0 zaS1cwiwINj_p0m_)e{DJ&kda7Ji}O$SBhcXvBQqE&^ytF=0E+je|fb~Di@in=`$yi zXf9aqF;?Rf@3ad$kkue^=QC@XLOp*h^%fzb$lU0~gG)+NcL=CEB=ZD}XI!ZT!$4GG zG9RpvWomR;GiW0XM0Due{|7|qaWZaDw9w(G%tXgD=bI63tEu$<>e25>{J ziIXMD9NA#hg`-mMTErOewkN^Gcn-(`CAuVp10?cPKOP!8RAaei1b6LUCLQV51VtyJ(QAJYu@~gfD@<9^@dovpJ zyPJ?ZwIw=I?0NHCr?iE!G!q-N2n}Xg;fw*Q<2r-txaJbphx8&lAubL?51=^-Vli%) zo3AZ#12sTB{~ax%gQ;bJ$?GYBX^vs?XQ0G_F83t3Diww+33HQtlg#?t!Lzu=wG zpkkemZjl22;?Xu1(byWXA4+u_G&`R@j`?ep8Un}u_sL|;i*E5J8oD?e0J+Q-F?{$B`DLCP%vH`j-K z_z(GD1&^-GIqhp4XCQ|N$Vd^WU=!AXe?y~QD5N;;`(8hwge|!xJAlA!Ff{EN`iSO? zOScJE7SabqIA8MAYBO?$hgIgsv!4X$3hY zsc9#57S^0sUz{~;Nr}>Gg8;Ar6_c0dKMs)he`10?gttn?ux(b{^ss^6xa2jZf+U(3 z*J`WJIW`zBel{=YF^V4Wqw&;7(B29Ey))TFQ_hBms4|pNkSEi;X;VK*k|Vbycwx%9 zhuO+8@`v1D*I`}95cBAb!+n|+iZETeArnGZR>y7mzp1YT{lKWBsnEA)be>)|N+|SE zk7&t8xnhH^sZ}*6>lJ0&;^_`eV~&gi>Agr#Rr4!z-;0w?1$6Bd#CI)+FTV_?D$IZH z1|4#9ZxH$)k5W5&cTpZzbJIy_oQj^+RcPA6KmCmvCDGGv=)8QAGy-kK~S@Hc)CG6Yhlsi#bIA02dJCg6ej3o6h5l1$xeH5M>RM16Fpt5VI?zNj5Ys%!ti63XD%Ro z{z9Z*Q8-2oh+~!ML{9-tm!CGU`r}XKo4ME=P||bhW>0v}!A?e3qADvatwIf}Xbp6_ zQi=n%Imjkv9!$_OpFTDybUHa$IpgwNXzd^S!~eYhA^QAeDjv48bq&^^${wy7Og#d1 zNr#8c0a&rW4v??2zT*Z}p)M;e%~7HEbBY^hnH@Et>I)2#IAO;j^8(kb4fn!hfI*$2 zHqe-V?;W-O6xsW&=yX8uc5ZCkktNcH4=9vrgKx-Ej#MmF;b6P`k8e8;xegrGwlBpB zP(yd?$UM5H#?K-12Y<|<$w)qzjh$IG;&d$%v=&`|3?2+0` zJ@_~~_g(3Y8uoSmT_p>XmtEC9o&eOd{Qo#O1r&%WhHr!Ppq)Ev z3g@;?TAIi1#`RB{6V$8@c6wI2OlQ{%9wLdxZZ%Q0n$u%AZ zuSpN6eD!*3P*h=0%l@LLfPIf8LIU8fYR-pmOF9p@9o<*gplpiA3@VO~_}&7@zW}ZP z&RLG1Xo_egFNQMBFBOgo^)X(#P{ax4O808;WN$BeHU7^?Pff(H|#Fqe@h< zoVt6Fu-yK2?uFNW8EyvI9~hk*2oeDrb8nD0={isA?1?0LajUJ3bLOim!T+#q^6m;L zd744j9$Nq%h^l_UI6%*GR#XG?Q7!lUK*w_H0F%!|#*R4^Rl*bAhpmIuKLQeI^sQWurp){zLVsX34Qc60?AnO_ijl7?I);n*~N4RB(W+0VoqvOW$?4U&sz)! zIBZL3=%b^?3ZajuCeRrB?{lesM>(l?BPBp}ilhtS4iBsKPp$6+B!Q#1qC$x?ZB$ur zeH6i{l9fCM56~x(`j`#!Z}nx5Xd#=^^a~aoWGWMPldS$)Da?1V97Q@RioA}td!0GR z7{r4AaV%y{9#?4r>RVV!Kx2MCT^ZAtIgVJN9F{DErU9v0mCfccECom<9do=|y}S(8 zWg2{hy`uh-3}>%uB#tPE$xWeg`ud8O|7oUz7BZgx95snR*u&;`=eNMKJzT=}&==70 zV=vPVCi$ z{ysoS(tc&4E~58^xWzPDGegQT`Rr++lb@KrW$W%BFk&On@Nx}9=BZ#<=bcp&^iTbL^+^hJ_zFl zxY*I>ddRdx`uL(u0wh!IJW((?_5xqYrJm;Ay^x$1&i^;d-bnQ_U&CJJa}#qXj5zP1 zbz-W>-?8uZ4P8-N!rn@i=Y|E-LO*4fPL2Mt^FnI<0)P&A5~&VU#)`bcb6JY$GW z*7ScurqH5iMbn_GFiY`Lj800 zBRG-6_jn{~pF-EI5}mV=<1ls)+a|_Op?dZLj}?aJwwr=N0A%ds_`eR$M-QN)n)6ZH z=u_qPv!1=JZ5katiBsG!mhbDcK_akfw;XCPl%=(El0~>RPKx8FvKg_A1qX80wJ`e} z)^Qs1?iv!dq#4R}&|^R4#I>QjTL|1IHI^p`odilZwPs}kmDI70p;kugFAZA}b^~=@ zU!a_3I2Q&-LF-d&Z{3D{L^7#Yn{c;Z2UdLiSXE%=_&->m+^yT`Bqt48P{c#0rxGy%&Av3)8|P_Fc90~NNQ*ulydpcrp~6%%{YpQRj(}vImrY-;hDdBpHgL|-bD}z zG|o`mWx(eahiYXoplHj=s|5{2thXDXWy@ynTgyR`!9?E%XO z*=gdWY#H@A?=A;t0IQW0R^2M%amSs1^dIO%;`h?UMy@O1hR)TBn+`(w?R}QY2t%B3 z9{JeuwS7a=L7C1jPzr5Iji?sV3kOba)iaPeBODsF7om(!e;Py53up4HS@s94T8zKl zLe*+IHYTz!j2oV$0lZ?8tQ<^%d4)KJZZ&2uG^EQGXY8x&1pEn9KFmBLKRn6*6U0mO zp#ypm&1ZSZ|8`qMiNWf(^}JOGw!XL;Tu#=8B&PS1#GzX%I}h-eoPew$BwMv?ez@un zLv@BROq-l~y%xGXtk>vWLxN7>Gd&)P>|_>)WoKnDJyZpT+)y9}`y|5}OYg%5R#Pf< zCp-VmqPV8>MbCKjVs%o`dM-x2Y9{-K#5T>?-FtTPRKnuHDB~i3?N~1SYLL_X5-Kr+ zh788TB`*j%rjopD-FFVrllcAr5q`41A}{e%Xa%g`dV%~Kp6l-dU7(d6^XakT00$lo zsv>Burz-_@qlJs1ULN3@C4w>HZbdmgQ+M=RFox$tsKjV1E?a^c*m!>>=K>O?Hu^ZT zoYuxqviT${0_m19@1tw?IcTNSXjLZUV*R_uym34PvJ)Eoa^A1+hJSJ-te5zj-K*(y zDHV66dAzcJ4w}UcQ$|5S>?xxbV`BDw^e3Ux{A(aycQ384w8B_vZ!s4E<@Iu zwJ<vUKyBe5-l= zuMTz&z*xHuF}nkFI>l1QS03#EisHd>cAO%RdFsk=Hm}tRF@CGowQkO_@uX}vnwBOr z3Qp?D6jTxgbI}JkeblEJtj1z8FB8l)s--x4=t(Lh2X_Jjw*Stb8T_&&Meu ztd7TC=)U3w5qQymK{c*y0NHtdK7KXiBO=XcX1vzptcH*cSoTEWurzYa0dg+&F%H$p^7W5wys`ZR<1b4i-KF03AKf<9jj^yXtfzZ_6N9}iNvxt*sri0Oy%d;ec= zTh#J@>%p?UK>xMHyjOtMDt1H=CZq<{3@zP?1Etwoyq`obO!-nYJAdL%t*Yj5b&^Y{ zhYZ2~PNgPbP!I7s`+j;Znf~Rx&|DDVGUv3l8th6Y>=8D!v3(e*OzU#Yr{_=Lat^?t zgu7ct(vEkIc+H4^Jkmb0Ter4hM0-Pa?0MHeLn9xaaFL(`c!w!mb=Cov&|dytq3X(^ z9U>0-NU`31%QSVfl&Pn=f&GOrVW-N|U@ND?>PA)>VEfZ1aFTB9EMyPE#E;uaq7dF7 z_NGXyu<#>+U>af|*)qOiz^tm@qm-vO7l6$H7zt{XrS&MuAWInf|3`j0W^jG~`Jn&J zjb(O(yaQg+3Yt1w19BC&gGAz*;fa;lJ`K0t-Ow@Vk}shqR1@k7NA}ZZ@rVAQaCce# z*D^-y&I+WS`~lp82o*Ucc^EJ2J*egMZXE9D_0bcqYc=68vaPmMy$Wl|^zCZ-Q3+@? zKg5CiBZJ>A#AZJ9?tQXPj08<)7A^J1*zDH;fh7~LUk!NJTNe6ZN>+TPzG5h^5j<6*RW6m+wH2I7-y>MoP+;++PU zg?RNCbns>0u46aA6`LzKAlazhlhQOAYRY8)&R*7Mnm? zrI{rCSV^|l%Lm|SEwBrh`hlI1-C7~AUYzr-wzkD z!YG<_>cpDU?~Aaf=^foAXa=han?(A_-|N%o&LI`6%P@ z{o&tt0pe#Lglw34$e&&J3+i?(w1j_(7YE!>H<|Vs+AWYtVXq7al==LzgU+{j`)~FQ z^}!{>^?oInaNsKs{4Aa~iRj$A9dn_XV7bCE=!L@(+yjrUX8ie5PqkB$GHE8{b-%=+ z$CE66zVp+<9BbfFRkJv#AFkhnCt9BLGitc*>j6Wke1qUhQ+PNo>=360Ep(q47^qSB zJMGZg>2Q8990*h*Of^usNBCqtV3RK;U17B_5LxDO9uW*$DSSkbCB(>q0u$+aAPjtvl}FZZ-k6T%r*Bs zQxNLRgnIewaBk~6EZ%}j0px|w7&4xrR@holXQK~-?*Xnz(e|x+-)^BusN=Tv=o|&2 z+0`)|vpn4)8(c^1V?t!~@lHut#g+Wmd{qG%KfJN*D#Q(}a?4oRY+j*fe;& zcHQET^`m5o~oW*h-aQUR`z_gJl1rAkSoKKN-Dyrq~MaJ>w~hG z$nP_IS8@;m^FKGV>pEQn{&Z+n?B^s&pc6+oo6bSAPj37_%3%j6qziSwujjrTSbzuE zoZbT!VQM|gfC_Gz)m=ts>>ZD-=r&+bJfjV(&s(8&>}c}MA@*g|O=#&csyj0N1g zSMK&aS&!t^seKUso_w7Lon6Cq4K6P$;x@wr{&@zsstdp!BG5PNq(+N)+-ChKhg_X% zk59kgd6}~}e9oltAf~4ts2rXIs*m%5W0x8=E`x+Eu{|rOiH?n zqNSq7A@i%XDmA@g5$M>NQ>eni*0DWPnE77Xjmv&oTbes>k$`?8j0A#-32_h!^dJ%# z(~%(eJk2yG*6c`wTr7=>z;7X!?b_d|rHyf9&H_o|Gz*P2pCjxF4(1b#P@{(u7 za``|Uk1x^80z!CRk@#Klo0GX8agt`HiJAS3qWMHuz_~Fw@%AhL#Jx?4Yls4|RKZ2_ zt879)rX>Ib5aVne-qFe=hXZve9f*6>!xg>*?31s4hH|l3)Y{?M{X!A0_qAtk0gK%YO|0VE-$CK;l4U>Tm#9K%}17y#(j9Y z{e^n_VyMoSQ6xObmhTYI8oT*$MS@donIi5q8}Q;U@6er(qP>H)mKlP#F*qL zombUmDuld=;RX{Ev@Kgt#xO*f&wtG?L?9nyz`W)6(L@2ykO^T-bUSqS?om%Srv|UE zEs#~YA!bU^PmHouSOFsoTq+DVSYPD04uzkO)cTM?PLjTZT2*Thp6XdanO}aK73pco zS)^RMaVp$aF#32i>67W$YPEj+Ryoz&!~M5qXW4b!-m_jyMJ@;36&k6J+k05O*MR3< zh0+68FMkaT68o@47A7j}n$4-B#oMJ&HE^;rxSmn$PY~op3Tu>i$Jl=iQ#UAzu!=V37x=UU?SQSSXIB0QU zQqf!WXteOZO_{>R#^GG>qST;1$yAsKuO&rMmlx*1sbhfS#u#k&JZ+rX$3F+WI9ngK zDsc;@7!TVq4n#m404RcbEORU$ebNE;nUG(S^jMn55#hHbPey0Z}rbR~ZbX6k$s+PbD)RRdT-abRJ>_ z(iK!+^v0@yCKNku8w-XoHA|^O!vrz4%yZ^&RYI!FYe#|U?o&W4NUfG)-qbRG{J$rt z|ErcawQ*+sI1;pgNfz>TKsvB{;xAxG22?6#;Ui&bv@gG!R7ex@3=jfl0TJq>K}%7q z3?G@oy6$2HFCMMNM5zvj8{(L$te}472?|jYL+SA&Rmee}+9!I4kND3-7rt;xI@=03 zE+vIm*aU;XjsUt=no%Nqo->ZTa>6w|yb*7%s7(ntl8(KW0fzx4O{C&q?GoImNC67K zr_z{(uJmkjhf~?0*{WK3atY|~sIy>!4F)Hz0|wq%QK`|cv{Ax^QKr(GQ)zWz^_+JY zuLV#KP?a_>0<%Z5sIeZzUySid%{c79)thtw*T4u#k@Tkkt_A<#hnL!n=O$kfV&67v zPV!5dIXC4o4?^b1*^8)ta!~ z5m^YDfENc1`8;_z?+>tOTos{3R5Do1#1dh(rs8}g5p>o=eE>*sR$BcfPXcK?TCB$3 zBi`?)J8y$53yS}sqfA{l;-Jxll9zyl~%1P4PJNFs% zJYIuD@BM}Jk-D$JaG3D&E(p9q1dIPPzv?0d~4f;X(92f4^x#+{P` z#u%>exCPr)E3FZV7?6kkC|pW^L$7Z*m!dB=$zcVyhwEr87&udb$y|mc9xd*)St{cE z+R=KA`KPfTCK0OG!%!B6H@Sg7OyPwkYWBfQy-4_}^~A54(Py$Ea7p3r-nq#fL=^9) zWF>Js?3i_1#bHN?s*hMTSSb<*&3MBnD+${?K_^>2PJR|J&t|DFmfC=Tc+{i|(9`=W zQ=b0hW@?~|$TLVFlw@HccR>^4U|zrWq1&pp!`@H(Ee>0l|KKJ>HIUAq^aLa`R=;Rn zzkFfFH{o=5gL-SF8KBlfVGlc>H(y>b&WM_W7G0qliim?TGt`L-^B5mYjYV3zWF@hs~jH3m~He}5g`b}AT@t&ind_?9k6Fs6KZLP6S-bRgi4rUeH zt6y$Ay5LKxr7^<{;f5#xCUS~%3Q?tRx)jnzg?xBADnIy!F>+l1#7MoJ2Es=bxVHIs zZsjDwg^WZ0gaW5^0obwSR~eFa2xy%S!$q?lKQrfI5FGD0@FWcu6_*E3z)ZoL|CTr0 zht=Pk7j2DreO7cgssOSdV`C)bi$U|ylWwvE7#DG zCV4PW8x{5m@5O}c`5XXPgu{7>-aN+9i+=99FYa2`#$0lub8ehqMD6i`py!Z4XaI69 z1We*_@2X%6C!c`3(I99mNwg-YcB6t((VUiR;JYQC=YwIPj^Crgz&U*yT&9fA`VLBb z4JVTwATklwM;ZT-lFO(_CUQ8Ip6xQBVY3@5tSM`}Wn_GXmhlJeV(de%45zF;3#Z!i zS1o`F__osVFXpr0$sq3-SNb71DJ`}hq(nyjz`k5L%1Njk1`)Yt`0^8Nr{2PGV9RLUA; zfUI}nz5uBi`Q=#H9wI+~@Dl&WNJ!Y-j{cNp3NGC(F2v$M*MpKD`+$E@MUmM!N=8H# zu8Sbw1|?BFQlsJ#I#P#obhQ0^zUD@O=8?3pQYWM zHIB_Ha7fkIpne+v>$iQ3yW8_*3MW#1SD#2~HS5$TAmSaV>I$e_y)t1PEJ}EEZ_@l& z0Mt>v-kG6y)XhwpzmgdW~VOuk_Yk<_!Q=GAxlMh!Fw4V0ERv*ku( zR}lhocNL%zpgOV~s^9Oa_wYRkY%rdb{Bv#k+(!38;QUoDUImKf4|Nys07_a|dJdQN z4rA5b6K*U6ReQpa(_t$K$;lGf5_d&|$V^9zj(&$d0Ml#&Ol+EgAEKD_xP_xF0Bku# z&V$zb43uCU-OzTPzhUD^u~-m9j|P)G27A$2ijo1{Iw@)2{E5J4tlJFpxOkkB-5=ip zAOgMP^Ev>yUNlUA4Py$9XhTbZ$7sM!bJBCRW(PMUol}HAjYynK95$=jmWn^mh)BU( zde?3mwQ9(i0K6rvozSqo;Q6wjr<{C||9qSX5D*0r6H>%9B>??;+7%dhtL;a8Aq~Jf z!f*^GCWJcA#?NXuLB-QP<6T(8F=KC;AmAuZW~y_LcM#Qa`}Jl@PO2(N+eRsz$78=( z_LS80{c4N=H@Xtt;EkD7;`sJFR476_ z)_)lUK}sf=w=9$2Eh`dV@tyB7=qdrzV;3nKcbGkTVJQmQS<3I&L-Go}4%;3HR080K zpNT+S)lUT!u*p8nk8I#@JIGo0}bS2OE^r7g0+^+4%>)a~Cxp?6ahI!*K}P6)yGa0i%G=4-2F0 zxpiXLOKy$d>{wm{A#8efLXP1gKgZOKK?m2@0brXwN%@XLLeNl_K3g$LaZVx&?v# zf#H;7ToF^|(lkBSH{SBE75Kh)roUrgz6=6?dr)flecIAkK!b}M)!VCQLG2DYqu$jH zMZ=U8H!)Ux3Hm>P)2NDjVhV%sCIq)iOFkU`v)JGy#BUVm5-Yebjl!t<#xSbxogjR` zap0wf&Nll9D+A+S;f37DAxKL0&+UGOA!M>cz;ZRvUY9TtdJ(*u$Yi;NP-zCO9>Iw< z@QnaS>R<}IJsQU+=rqji2_LK%Sn;RQ@5!*{VnVne_#=c6Z2{LA=uFC7c?2~@yK3LT z&8J*D((0?RdoD3+7M3NHN+w8tSFNh0Px>Z6sJ8JDJsitHuFAsf;948~@h!WyemI;T z%1KliH9q?irHT#y4Y|*?PqjiAFt^xKEGn4s#4714a3j?~ONIge}MholCV?!>yydrnaB z&{ec^KB_H<%6O`hpoP?-ik`WC(*!puJBKs2ag zrT~oM+Gtg^7QCo<5sV;2whJB#nyRRWx{4iLuF9Hoe;6J&IriiIB(7Cdjs}+SklEzT zwxbe{vY1@M8HIA7V#P)%b}`?s-b2jDSDgr)KwvaOLb*6(9Um!VCQ%U8MtVS&y4<1{ zf8W$iunIoZ1ut-#vo|3)*uva-!iVEKi#_shF$kC`Ao4Q9rX=2!cewlhDxQqR`)OG|k&&W|eMh5X(kQm2h{GW4-r?BYCnFF# zN5#&C=dk+AEfe<+X=eepCH4op%z*#mZ{yVi^l`?G=P$bSmwcaNx(Pz0+#h&08Rps6 zVmc{%{7$5QLwQlg*^CacDR3r}@LFS50mDSjT5YmgGZi!BbXLHC76Nb<%3UqJNc%hl!@l_8vTrKG81*resYhf#$3An9BUwxCulZ z0lQDQfk(;Nl)c6^KtPp3wCJPe3LU45Yl9QTJH_HAoVkGm;k zQe)&$8>NJv>V?AjwSI_OZVgu~6^88K?4Z#Nbb$7sad2{G!FF6h&0EpwhLZq_Wg^H! z{)YX216;bOSm1NO+u@2;sIruUumL!&mQt&3cDK8PiS5&T{@WJ@&qSvFSSfL!VrK+(Q$}aFj$Aw)4Q0Z&T_%)N46;<^S_I7;mq4+THc0o~l zUvw#G1l^iF+vG_WKLvqNjSa(U0E9YpX0Km;x|xkC((+(M$regsl_Cuy2UFHE``JD1Ws<|JI-(wW}060F3 z2fYD)PhvuC@OqHGD4nsfp*q~R%gpvzJdHpHI-C~DgF>O6CgqjTH@%ThZZWnRK;CVI zQ(gs%q z;0ybq54L(O-n+gW3oMYr&|>8%RFS4UA#7) zkld8f^S?w=r5-iDde!T@Pd&{R)tK0b_s7D?%zugc^|Hs82CD%zDUV-=>SvGr4gf8P z?4L;d;htTrE=dk-G`B+@5DvG7l62SF89xiTHaw27k)fes;SYC=IQZ37@(#+UGOZ%PU38V7hKZp& zo_^pXY-}td!q`I&RpohwvHiJRxQut#fl#_{2+L5yJ&scrusOTC=db}Sj*lU3$aiKD zS&<$)E^bqm*zn#pCoaTQHF?>$xQRGX-1;yG1L$;b{X9(f?sU1Nz>S#4r+X-uD+&g} zKoN-O81h+Ss=^{ZVK8h z>hnB=Nn77hQaO34yqD4x@=3_A047`Rvj#=~r@N!H$jJOM`~Xnw|P+S|hqfGaTW4GRvQ9?`Z- z5_<7rXc~1yXD0ng%i+y>l{e(W)f9jm^J$tgp=Hw~4lhMGzsSDGa>XB=Qj`EsOL(_t z2UI7tIy+g`>Beb53O0G)7%ypp7h{{Jqu>Ekd0~cpCWA(&ulWotg8neOoJ*7=6ah!b zG@qp#1ELTAqCR21X_tcOGTRD)Ad3c{O#5{ZkxTFF2A&Nj3S%nWI2AyZf!DbYTpFY` z04?b~W^etqpb&(Y@FD1JlVOm5=yWLNH*{LBx$4yfA7Ffj4{(_bVYIjL*~hcg2J%3Y zcAeRFTWH2L0z!odoM?1bVmFp4Dbpmq2;~;prOQMiX=mG z$PA=SR~Q0o20Ew%Ig@y=`L6($4Rgd~vE7lKC`9r&&-9%TnCu2iSuOh1@Fz+j?&L9@S=QljPH~(D+l~=J zux)*6W>bM77Dm2e?{oHAll|FhkcT;A!l={-S>SdnBS{n&hqjbMySH;Ch#m1uYI+15$2dfs*lyz- znq)%5J%q-WuDDKLbi^KI&V?sQoG-;&26$0H&sQ=Hc$S;WKpkR5{1&2${?$u1+d#PT z{j}*O$oH7qDpTdM*40 zbT`-kP@SFNK(+Rac=rs?T~yk3e#+qS%(qIi0nZ*h3*atR;dfLuR;@jwtmAJZVZB1C zMTWB{<~G}}G9cgFR;6>c2(QDmWsEm04AD;Z|c<}5j?~Fl_ z-{()oR&IW%)a%god8m?`w8@z{`<>Mxxkf*;ueVP+Rq#dE`&~%g{<5(uR_$ZkwU^1@PysE23i^a>6fo-PzG! zCb+G=F|esf))XWrlq3m)0(rLo`+#xjf^@t9N{p_w9ZimGMJ#t@wdYMT>=G z$bjKlo|ka4D^vb#kotN&(m-u>cHUxxGaW*M_l6$6|5#B~UUJAAEY=UFnzz09qkX(M z-oV7{Xs6D>`7eKe)ZQ@MZRn`ovCp|9Dl;jueDGL9lObUM#>G>qP0sGdmM!Y zJUEX1>>_5Upt+n?WB>Wl4kw&+I$0_L?Kc+8&*a|cuhjllc594mVe!R{H*}- z3V~S6B@z!p)S~@;Qj=%+)NUZQG0b9RCd2yVIX3JId$8qHKvnGL8+$EgDP~zHY4(b- zXSKl*H`>4BX5I?Bi63U1((Qwl?8%Mc3;czX$^Opg zj@t1qz@il>o#13|!ehs=vugW~LlbL~C0^0SR9vbS+Up7DF&NkJ!{;F%oyEV*{=|=T z?sW@}jnC?vxrBoZt!GR)p(Y{bv3|womK<;Ch^Z~lBJM_(|F~{nHz}MqcP8KaGV~Ge zO|s#iJ=?r^d)$!#JgI?)?~4U0mkj-pP36q3*XwN5fc(ifvHND-{vF2Y>-QTiD##o7 ztkki$HaS;>%)1DlMB*VlosFsbW4p@xr)OMugs;3Rs4fh#tCHM0x%BaVpIKz1EUvqg zS-o^0I*^#>TAy>kkhP5caKg^wV*PDQzwtRK2+G!m-7lhI~vr#GhZa`nvVwwb+TGS`z~7nW zY2Ll;jZarU`g9R^tok3fUz}SJ{>!GOVx({3^2E*H759jdX{TYSmw(=UYFSOj-=3EB z2d%wpJv3{+&Aqy@$xqU8*2LTy%(MD3XFR6pwz=Q%aIR4O3Psrul4Si{h_yXMVCPkT z4&Lu<$O$y`Yx?{B#@rbeuZ&{vn>-F1@|#TruuQF-Yc{O#_u!8&GnEvM4LE=9uKn0{ z>HgH~l6Kjq=irI2GhVUsF)Z8l!EX_5!KwG34<&qpU5c#NYbhIPp3dGIub*`Ip2~*B zO%rc)PLIDt$Vm6P)hjn&ICHA^^{fr?))pr=KUdp(B9)_(Uw+0kSV7BQc)m)ccT6w; z+zcjHbv1ffZKx4(>c*owbhzWs!S|x`rBiM!9-MfIG!|moJ#ZKN+xyS$uoHe=@u$I~ zFOPHKYiTNnSS7G3qgimWAEYVUVLL8uJlfoO2OhZKDc1*U*Y01%mEhLkYdj7=6Q)Gg z>&t(Lt$LjoDOA~i_xum@d%Ai;s`paD8ya zifP(U4}E^!*Ir|xl-;X)dz0GKEAu&t?iE=23n^QF{El31p_Gwe5m?bU*GQn}Se9|D z zhjUJbb;+AW$i22J;!W+B1oiuz?|5XKm7YmjLC|{v0^c+#eSM2z+i%7DEOk3vzkm2Y z&b~4(3bcEBOb`VO6hz8ER8$NQlvGwxl#oUmL_$*OR4EHkQBjZ*>8_z91Qih_grSBZ zl^nVmhI!9D#QvZ6lkAt>{VjFJiR)bFy3Yg_J#bnO8M-OR@zJr_gu4oIsfT*`4!=7P zqB9~@cUB&QX|>>xY+%uBGK?H9vyo9dc*ZvO9EZ<3oh|X=d(O$bPW#5V%Vd=-h0nos zYV4Pf9T9JYa(iUVxtaBH7$F8gGgidJ6!%Y3(%z+Q-~92@^-+x=d-=JrC|L zUU*LeqYl|F!Z=pcyoPH>cR09HdhTJ|$d5NTIiDdEL2aUQQ^7EBo$F6Z|$ zH>?}RW3WU;#Ixq_67hoBIxQ7O!V>=@-%wdmLGL;R9nbOCh`P#eGN z1-m#FDQ>hsbg~6Q1V5+Vzt+G&m}MJB@vwGA-W@~LwC^2v(iDxYS=x%KJ5zgPhhNx$ z*Q`^kT#qSxjh6qgr>f}aWcl&O(`qrYuIk?WToBAcT0Ql8J7&q7Q#2`=HHK#c?A^d& z0r=lDh``Nl_j;=(Kb$5Twy?dnDPw4u@ngzxjQyW4j7=R1T9mFbgkwDxGqgnR>(_-J z)i2uFek?m@tHVJZTBhIRHxx60FM@vpM$wNJYKN7LwS_r=js65@m~>;86fD# z2)5DL!dek@Rl)R1FXn2$Sm)`&c`QGP+!taHJazS^Q56LFkyp&(pQAr*YM5bmBb^bJj~Bk`kCKG=Qd;MBB2870 z1a7H*UYA%KBQEa5u=*wA1QpnKC^1T_~R^&{{j*!NgiiEZt@&X(M9M+c#z zt*!p&oUzk_9xW>9io~bHMD1-;-HC)hlvQ z@oTYQ#veBbU#GJbbiiWXW(~vRaID-V? zsl%-wReLZtdlzw<)VC1fS#?sY->p&1;WI2aE=H;pR#=w`1q#aELPr>c&Yw+q{+zF9?U0PC zUAZYAGY0}@6q|ipMI6FE+HbKYI^9)=_V@hQCFFmGDuM! zdJEo?Q4o~}C%F)~4a0!uYWM{~pxx}2Uh#Wff|Y3N_>IUY#z9&2J+QQXXZ7pTn;n6B zv3j=TUl)ZEU4AG91dLvrOJAyou503|OUD5U`MTya9se!&Q@hemO*yBy%|MJ6%Gt6+ znxY-Y8~kREy3J#Bd6zb{y)vZ2o!e<-XQ;R+jiZg@=C+Ka;QWFyh;i0K4drIy%3hJz zj#1bED6WIX$h{IsPwLqLTE9752!-rbMwWR+Uc)HzHe?*9xVu2WgF_J7iXedkhp6f2 zNr$RWL4-EWnd>BV;y_bDLx$EuttJ$0Y^h7paQxU&wp(Ji;(1j&XD0?aGltWzb}2z! zToxTFszc7GJ=JVwQZy04PQtW@do~$?X_=`=L)B>qP{}Mx4Mpbk@(c8$BE$6YYrZXl znDevAI#uqwoz!f*fAmaFI;aRc7S8oZv~mh*_SobF(UZbR0~d+wFboI@N~dSmJuEVf z@2`n;P;t(H&|s*39Xy$cFNe5z-2LdEqMd8n+pmmb+Ix+^9f_2el++m$b*?3o@7qrr z)kEE4z5t`&hV&0=~d??cV~ZHKIp}jLe^+ zjiN2Aoc=uZ9$+4#h2mC?r2y%gu*zPdh{^!+f#x!b?`rC^kmud>oF58^%p2~k&B`et_ew?OWVhq_5F}i4u{T-$368P$DapM%d+IJ z?i4Zn2^?Z()EWCgS zR3Ajrq>AAHNyvrp;Yl@A?8HmB5aQs{2bN*Bq1|C=k1w)r=(zR0C9_Uc4@?a@IEm6S zN4Y{-oRhjqm9I%f*~|5~t1(2Kc3rrTa2BJg?!ZhRZ5}x{^$LF4fv_{j=cml=3f}cs z{_1MX4$0fkw?22XL{)$nhwI`_ruojF0XN$rU%zVA+!+oIhwNDmO+AM!D{ zO|JFEFk|eN3e+z*Zp^uK{T0<>|WdMYa*rRa~8_{o0RV&l433&>IokAxr4Wpk399!psox7OeW2bZ**t{KL9c} zY79O;Jmd^MYfhQ7Gc+&pht&Ocs#(j0p+Y{y|gOzpGd^U~Pswj?`|s`IpgxTdVT z@kz`zP$Y*e45z|3!=)hh<%{zOSJ8S4C9hh%@9|-glViVcOjYgxej%jQe)MzK)hbmA zs>$|VS**$VYw_7(KHg(jo4e~?@s5g2hgV#jsJ9R89UeTeMmOvuIp+@6_H^(I1+QEa z1WUi4-0BwJ_i~6GG7_t%gmsl`D zmr*P){&v}IH$Jx6Rp^#I1lPfr-i|6J<2?C zLr~EG<_!xf_&5>@!*ued{yv;5TTkfKE2YkSXpR(-b92e31@RA^oZtD zpQ~dz`!Ve!P=tn?O%MHHE}~B)6scbXa+5)|6OP{n#VqkpQeXkuxtQv$OBiUQ=>lHD zJI~={=wNH2d$Z8=z)icuTFN=qp*I%JYQ6|Vb#rul$qZx&`2CIUddX%hGPvPG-0Cet*R``n5^dUqEaDuoY)ZTFEy1VTcehh8IJ=`f!B0k93=~ zaA1VY;A)IBCnw!roGd*ELBK<_zC0kT>RmaFed3w|$?F98i?Z&eb+Ar^pP%B_VSIp7 z#cbHz(8VMBo4H6>C5L60L_Ri`|C*5}H+_3mu8~&jOtzw%R4hQ@xkz)2vENddTQ_MP z=REeiXEXEICyv_=Gvm2;XLb1|=N&~lME6k0B;tc}%7N2q4kYUa)oDz1Hu!3Y+eNk` z*VGU|Qt?XzG8#g8Q??Xh!gvr$!mu#{nt&ovK4@X#V_$0lA70FBeH`G6uGbieb?82IT{ZoEuJ&1-XFpy}deTKC-6%|AS<)3r{N96CRJm63={#gnvzJ`)y5jYOxC} zG38T;!K$xbRQF+=_u0R6q&6R1g4|w3`XKK+C`0Q=np=veAO&sOgjFH zcpu;UxyCa}Ic{xaJY~rEb}Xf6ysL;aIfrkdhtgU!#kUa2FElYS?;$9+@+)-n$^P9( zN+Q$oT>b@`6+UzgU47O0FAKy+ibi!7e6kBk!}BqeCUJ5DW!BiWh19o3V%@UWcK>)g z&x&=%QA*D>Dziu}?jbF8Yc{(lq>6z7Eeh{6g+vJ$ru0#U+{fh>k|>?xmpvi?Kw6M% zFSTsMOf>;Z{Kl#O^mP@)dSNdhx;lM^kr-z_{uunRlqT7Qry^&M^{<`pi;Q8L_b{A{KKmOnQ=P=_!DG!IfB zE;(KB zx$3vM$aT-b2uf4POhvtXN7o66{0Ah;3{dP?&Vubh@&P1kj6Ol}W&hmd{DW*~;JySC z2e`i(-1d~>CY~4|YBTeFr6)ml90%Y{nG@%f*)cutK4s~{JB0FXHa*7o)j?`+h4oKs z!F+#~vsUhQ!5>7HuW9Ck5&~g!<7;$-X51Rz;*P8Z58!-913*WKzzz?Gi4=+XvIAlb2F#V~CoL7A(tP&%x z)X(v|=5UEY_Sx?dQ*2QPoU1?fIlBoHbPXcmPk~b}bTWt3pgJ)h$OG*Ec*J30zJgQ4 z@F#&+GuOycOhg_W{MKQPn4aW0otqfrqv$M-XdX6V{s`Z}05yGf(g6I4Hp){=4IbIg z<|F~AsN4s1-pMVV0}B6$j0|3LulvdlYOloiPR9ke$vlI}(S~-deIj#Uw#Yyw_*6n)Bb_L%I3Bg}T=z!-U%Nwj zqm}1k`F#HR*Rt_8%PEC?^4+L4mmEA<|9Lq^nbet=tL4)uEwg6A7$1N=@Ymt9XLsKA z&r0C(hwoC#8cdJ+G+QK2>4AfHU$B%y0Co@NUN?wvC7$ovHFlMtZJK?aW8Kq{*m&Gy z=iY`Vl&V^O>!Nq__RuBkqQ^+=k9tJq1iIC9hR2J7?I#60JbXuJZF^)}N+pua63In8 z6av4s&*l+_br@m>Y!1pg=>+o(Xj-VhJWb9;ST9?VT5po>tYN#dlpS6I?+6=GE1=Z; z(%ml-?*v@n2OZ9ZsXghhgUSbja{7EXhIi!~efIQ*&~<&O z$p52ukdK8#XPIMu*d?ZO=FGzwEpr&m7mEI2(Z88mZA1i`OAFw%-Rklo0b(ZwxRC;iz9Cd z0vBia1<4+g(64>?L~o<7zzF&!rP4r>LU6wDlLFL+;VidDBvj};8dmg_QYImIOVbUY6Tp6E$(e-ZWVxjT@R=lI zl~J2XTqV|`keowse}a+cTCB?tm3h$2TAm@r%DR8e9J~>!I}A%XNAAux`u8ZUF22)B zp1L0LK%}+Mm$P9|v?MZ~eDmZ94AbY&^b*gf3fp6@J}VQu=-^4GI^m2I3g2HWMx&rE z0PcBN{{0g@E%*icSqa#R?cBP_0xQ+z9=*F;rwuYd}3g zZLsgW_hQNA&JMMdyJs}%*wT$PnsUJ^zm|0|khtNm(ILR%ea?Dck>+3umL9$=4`0Um z((c~+3wzZu+vy>W;<%x6CY=0Hq<7Fq3!<|L?~?iv~#!f71`GCV+@(JMXPsKEsVH3ESeGpOpdbJ+<8)PqipCP>H|hmx5bTUKtqU$wn}F z(L%hH&e4q%^vv*u7$$pyFP`GFASsb6#^RiK~w*A$y}4saxZ2|(buK*-%OEg}!b z)5wD&Di8rlF+WkE3oSPTUbcrLqGwUjmGtI_i(D&Y9gQ`I-~&jhCufja&I-1tKQTML zhT^C=7>7f%N#qyTSF9*f5;ZjE)Z*A(;`PzdAIE+2X4StdY|(@jmi3Qq+};tL=;)8k z!Y^RiRnYnnoW^HcSG^r*81EKU3H%C0IsJN9?JZmAuRwZ)MJDdqtk@)Y zvj9r`LBLXG8^U4k3l&8B@v4rsnGHqdQB-VFhZSwQueF%}d%6Gc^3KBb_Wv&DOXCWG zo{X6DnYNpJSz$$w(pgwAbo!ke!$mw~a3ZdA6&u`mI-;wenWqP$7EvxAa<`)<)D~O# zS#O{5C-sHA#CXz%Vcj;{JMOLNNPgjw1q>W?v45R{3x{r61dm;*o^gSO$mop1RLI-@ z-*RmzMoR2mq_e}>0s@e4Cu=|OrD6GP-ErZ6EYTzH+aO2B_1$LA%1SP@42q?$EU{zl z*?cg?Jb;56_x!HubA9yxc{Q-1@3V@UPnJZUD(3PB;3h@`EdtEC%n`R)FuF|dGYR0o zND;ux77s-U;{4m*PX@U-ieuNx!xLr1aULowa7N2Z(B3C<#Di`u=MMK!s?NV*CxBwPogJrJsrN??pAv9_gngBu85xgrLMw>2P@`!IB`BsL1KU2rHui4~` znEUG;ugQKbm_%8E32Aodv!=z(;LD@)vw^>VCT-mQdt37N>423K(@er|um_kkVN9~0 zV88rKYOqRb?tcQK!SGwwkbNSrUyHRBvWr)4Iqd0KE{+T4-tUd$U#4WbWu zIfPyhu=WELaK}~^$6XTXq}t&M5p+C0Vra#CesL(mr)%=r#llxuc0bDR5B#6V10FL_ zucZtZ5x`T#Z$sHUUQoAyoQET;^%&|{XIh*|02P84*q$#m%nhK`l3_`3LL#BwM+6v@ zyc`+_@emsG)>!Hb|dZu2Vmmd#Rnvc=f^x+OA zz?#QD>iEGqf;fdC$8xOpS`>mSErTAQDUwa?cXnLI>3WFl+SSSNe_+oI^}Ze_mu!lW=m?mH z`<_%PSXvG_*RkFfM74Y8>}q+frx2QLNm|u z<-Y6(kALpUioItUZA4SkTl@#ldDD^3O~C_11bw= z;F`?5N|xN782nKik>M&B)+M2v^xZ$w3mTO}wo_(M1vzgitLO6HBRCd11pIA_74c&<~+9erjL&1uVS9n@F z-}7DqzQ07=Ln*KCmc`RJPC$}T1{|9Wz-6cfZWn#v_+nfd1bFxhNCa4K8j*)=sKAL2 z721~le>~sp=7A#Op!Ot0a;QpRx$}Ls)_8;;SFoE*2HyU`mRAdZBuuBLBt|{l1-VAQ`3WONGZG93bSD_y`V5e zJhX|rnF_#ztr{H&q9#VJ^@%{a-LX!ZhGK1f<<1DL)S@72x}g_jKCA>&e0X$ zU+S-%^7Zd28a2B?ZUgfgAaeHii+I@{lJ1yu%)Asl!EQLK$VFl=Q9p(qw27~8PT)yo}u5cc|RWxUI z!HehDcWIIGHOPTBz&|8*bBKOVG1{Y$ZCQ3&Wb5);*fub7{AMnpj}x}<+|7XU-^#fp z_EhZ&dg1s-TBOwVAXG><7i%_?4Q499@u9A8k`-||l$j``fYCq&Lgray9Jw{rO*DhX z!rLNZQOu#blzvNLhz^d!Nh@b-)nNE?PPO{ynrwGqsgE`(^*d@buGoe8I>l2}?`Fq# zy`n*&_!Usl2-#KWEFrr!MHf%9tpP^KsT0EwnS`2}Ec80YN30fZS4$?+Fm^toN9rM} zNlKrBhFc?tzVB1EMjZj}l>=aBKK`5ei;o&9#6*rS=u55CaMRZ9uQJ;?7Zi?)C2nCJaLF3)2oM@92kAM5p@ZuXp&o9hmx+slmAil z*AVi$z^iT?eS%dnlgVy^`zyJu+aO%O$K^bw*`^VU-tozS^YqG z3@$&(>F1FaCRTmk>QB&E2F=5_P_ao?Xds|MwGqh+pdny&pd~*L;z|2J=NE@lNK?JI z8ZUMAv-4h(rKL3Usxpt3A+6N+U%z@3W5zcBUYERsXKL6<6TW}tO4{b;dNPd06A0^) zBO>@LFFU4!k+LD3+ApVuB&0~D;;+;I;G>X;X8aHi%KSw>(PN2=mby5DW#g!HKk1~4 z+IYTXlu4=fF_xIZ*&WOjB1Sg+^J{O~lIym|!a{#!UE04ttgX=3D4h}2*vmoeaI$83 ziX&s9Y^cb~=>&8(A_e4}Q&4%{AO<1z0+`2Fm2jhux3)++yy?{uk&L0Eq5ubxt_)cW z+uqHaeMT%Uf}C#cKT~g4%*D3rk{d|TY&%K&Rhh6KemHivHe9@lOe9c5S{OFh^6F@eRvh6|-*N zlANVtO_4@ToTAQq$*HjAbg^R9b?Kt;t^g7grf4%89-gb>jaP{sSCv_;~KG zmw$qgseN3kzIjy#1gO;H)Tc!bGrdO(_3U}e*Vx%W&t+;ZHxM4C2n;bl2D3BJ)$6DT zZqyG~(*w*-SxN>l|)jF%b6D7@7hVTvZHXT6A#v<{h z1C#ob^0G37 zG{$_jX;>{g3G`E=oSQdWkE1(V3?};%aC0xL9YL`&`_UY9UxrCF9yBzRTSfW$OCYZJ zq=4Y`AE%FHJEdR?F7vPjJt#I-@TOGxcu$yR3rLl1+}I1u=^5Rxe0>*W+AXY%KEK{C zbtrBPNEJaDaSXebgj&jh+`XXp5(m)?c5UhxkZ(2d8oAp#4Vkv=e+gr6${In$wb0)8 z$%C)xby7dHX!rjlF$69p=;E~0^zA9(mTe2FfjHc^Ukb#-_m_>q#j)#gf4}pc^p5|5 z4DGQ{x(5ETADT~iG9cw&_>{jriPIUvY5V0HbJZM zR`lxWM(VPi_lh(?ddj^yZW`D`lf`8+tz-zM&r8USdZH_JgYgkCVW}!`L*xMua4RKt zvECaOM|W@*V(#015W+7~YTeLcAqv1pA-HXQOnLwe<-N5iK0KiQV;KZct!+7~V`PBV zYd-{i0c#+?noM!a3`21Tyyg%Qa6aqo9gUitEjoPqyciuXPJL`4GsF|L&JRJ_8i^aZ4$8AjP3A1HW7s#8Bu-%M?>` z1H4i3f;?jN(W{~KxH!co9?8E3Bh>!(gbt}r3s6?PhZ_ml47KI}D=hYo%kap1p4^;9 zp~_+tH@M{nNbXc5i`lS@3>Ix@DbZkpfSHtd1iArq0Iy@BQFo6@sxbWl@&(By0?sKr z*tNL{uxqUGOM_PzTKfLjdeqNyq9udG%CCRG#yjGdeQWgQqU35UvS0on;ic2{6w{Y%A8>`Kdft;1-J@&T&A-n@h zd}wUl8n~{w(tz`eg*GoD(PG?DCyB~L7oWU~5?#C+a$5sVwoQL~^v3A`TeVvC762JR zmDNbcW{ZRs&f8*0f;XGIbXv|4^|Rt|NW(5o=$RaPSxl92BL)v>5LN8 zpg5U|Ovr$S4Q43(opBh412u=90rA2aR6Ql2zRG=rTY#LJsOdkr1_ox?F(Xiv~`*njZi&Kvu&FdFrK6AuH9CQD-rQajCPo z9d7deNc@|E?V+Lhtd<`8p`ib}i2E}QVit<(taVQ483UL@+8&|S(3Ay7)2TaCN1h`C z2R)=dZ}D|zHwn5F=gGiNXcPE$S}0@xE(%CywjR6jjFAY)m%c_E^9ov0wFzw~05bW( z;PJn668=vh=7e3xM8&9sSG$m`xv@jRv$L}rI$8KZp=PCogoN7K+8sM~Slf1rFPsz; z6B7`~%E@67Zf|^Z1H@*xjye-A3yl44rt&3bHBQ+=(+!(#*Y{IqD9#HyWbt{%gup`g zDassQhK6!3yi(W|mV9~i-oC#|k5*9UAW>pccGdE&4~XsIc^88VkH$6c44hY)%K6gCX-VNDG=>6P|UO9~WcZ%R5dra?jccLrDd37(6Kz}aH?Pr{R_#)1Y%u`h0W*xAWtw>--_JN2_# z_*~d5Z$E8nYU*!!04F4sO)E&qv*mSL>(k$^DDq%Q(6{;OilEQxDT2RKM0sg}T-k-+ zDWt-`jWxwlq9=BE+(1}VT1n?D);;kTbk!cMWI?V=BGI9zltR?BhI=52Nhm5R;C9ECdKJR^^T2-l3UNb3k&lXoId#OTGn81uQ6M5 zfz`o9=fWjFNX@pgAaftR$#}t5P_gbCA>TfOP+3_SO|$o%$txA94(WPkzsA~#OAYhOP*~)bNujn&!ir8!7Of*(wV$-(Bqs+HTn59{b|*FvTS3FPj)&dkD|C{ zAX!zvZ2>{~A0u2sHX329)7q9h#MiUEUfuH7otPb40MexC#%CqaA-B0{K1!lF&V4HL zMv~CP?A`DGG@kjq_j1HWxEUOcUVuing_paOl$3$uu?ns&-j%7!J0F}ldGfmNG{^7j zlQd7BJh3(wEGc+`r*v_4h?G83RuH;uH9bUVBm_@zU6YYf=Jd?pF|~Wh#0gW%&S=z^lZN1Ae?ih#F)RCL8PQgVGACv*pc)a8cR1vVF#~?%qyetz^Q&rkLS0!}iHu3W z$az~%kJJRKYNA@71kOX=97h)3%daFzKh;6M@y;m%X9rmO2@a*6U7oHg`_DJVn+l%* z?h@f}ZAS%!OHhg{NrS41^|-UQ^k^(Z;J+$Rbaj>@u!h&0l?c2ycT&JZ*Va~m!F54| zED*fkWvkD^aW7V-=;-K9dI3EjTvB9Yq(-g8FYBJ3o-TPKz47?7v0+C3zuvCbU}V13 zX3uk7c6`oS3Q0ZJWypIJ%#DJ)`46nN>&M?Gp|lCa5rmK9tm% zv`)0?Zc^#HojDmCQ8eu7>f}Ik=Tw1siHQ$h>>JJDkGo)-uM5^AZCij&u{D&)tKBL^ z#8g}u#0S{*ClR4X1?fHqxLI%Rr9J#y&&GzIfvhE3$Av$0rDh}klEDW_xog)xM^yIv zJdw9TXHw>vbQDj*j+6fBEu7NGad~{kbnL>y?ww z2YTB)oN+Xo+~OsaxyQPqa`!H+3!HhEjcnn5gp@M6#GH#rSI+6jFoC}LK=1ym?`zZI zKP7$IeLf~~VmhRnEIUbF+{BP`t%Aq{0GP-7E}$nEK;aAhTK)33v;eLE{Fw2|XQkNl zG1u3Bf1`z2JmqajNRmZRP|#yZfx~rNPaG~c58B~U&08e7H?Vnj3)P)Jr@7U~={1(# z{tSaTk0?_?%rW8&ms0k|(ea{z{cRDo+w4UG`uh6f^@hvhH)fO5qn(+=+v=w6OZ@C1 zg+2_U5U`BH3nABHq#W?ILN-g{IPIW*D*faY2^tE1&8aP~I_Li+}7W`pJ0by^}58m2D7AyHS4YvL!lwS1$+r7D>j{T^r z@{ubwP;d>36IT%yqs1kipPwJL`(aP36P^mxV_dcRmFxSP(AG|93lPa_5SsO@zOMyr8EE>UjPEL6@nqYEjQq$m5KR*?E<Clzf|qNz;d( zD(USGxhd5$dhM4->a;=DjU-bSef@o|9nFJNew+3e#Jckkmp5ll8X0OUw{h~!cX<`8 zyCliuRbG+g`N4bjYOAKxN{^+W1@dDFLDIe`T#JAk5fSBPHgLwyq8${i?2O19`{V!lh{vh^V|{p)nf$4vHCp! z=}{!R2|la7R0i+I(|4XW1a6A6%rqO1o57aI>bI%tsrE&iR)ySb+oboQIkh$<-h#ff z$31(nG=h)OP4|xLX=PF8a?Ka4j38P2kKEQv13Cix?;mVdk z=l=H1n{NubCCOM(r)Ie}ogCT!-@$VHhZ7`67dw)~EM7D~gW6J|){PzMMzO1aXj7ew zN|c*VwxBB79q_-I`5SNzQ}wp`8SgxRE%8Y>(=QP+;AV-*$tv`audIzNOB_{%x7h7` zSZ$Hrb&I`|<49WMZMj=zG!fKTpv8G|M~Gie*ITpTlQm^&3Nu$7luBbd64;s_^w*kC zl0#AlH`OUqgA0DDgHROEG_{RE`pPJ6NkS7ENb*E2e#G=(`@Q`@lddvqNVLHK9H@m2 zdABHr1QpB!qHAmxfkore3uhc@l2j5*gWtS)C>dK*}z8Mmv|Si(YRlH~J>D^&o}Y%b4m)*q?8DyVUSQMp9(gf8EFSaaCgs z*w(iXqazMqBW~rx2%v(OxB(cIlZ?26L-4B2IA?VTOl(Q$VrH&~q}#_QJ`Z)j4GT-D zpBQAhk(QTt!*=7Kov`23R@1FE(wIJt@2_Y}#0Gi-Ja;7Mv-a!J9lnCHaZ9AooN}Yw zcmDEyEP43R^RZNKXb}BkFyNsgUPXK;9D2oR{ggxE1UGHAtel)r@PiX9c00{TJ2%ad zWG~04ir>%cujg`Gun$oXnd-Y);(&X`e%#k`&#Pb8;6WLczo}IS0Yw-n7b0!~d$CF@ zw7U(_2F$prqy&vKL9d$Xqw}1nEwZ95-Q2_&Y+nZroLmnUsC4k)!FVjBW2?lM;oHP$ z!(?S-26KF_WnI}`dCW|EQ;g~#d!_V$9@*4F)sTRTf4{4wNUxMhb(@{Gz_js-dB(hX zWM0Md?k+21`u-t@gL)rL8%b&DeCH3E<(O+;LZM@}(!Fzv$ zD5>-cRXYgucJ8<``w}tHkDuJ$L2edmoKhRb-pbFI$f>9xKurTZfJaG46u#QPE($}B zkczv>sf0@0G&Y+Z_NQiMW1hp5_XNM)+;CrYUZLhY_$>%|SppW3D0M*rs4;z3OpL>C zr-iSphFLxi!oPb=8Z|0b9sv{U7)@dQ6&ZB&`0-mcj2*QnSS;cz#f3YyPaU+gO=Rjw z6NuSQ%V^-_kWFv2DZhDch6eA(Lu@P6*i9_=9F5llnT{;i#m7o>51*briquvhpVS^u zSe8%9v#x%t1xRWOFLs*rOHf%D1P>|AqCD*K$$1C;hJN<AARkyg}~-=@Y6pp}fN`LHk55NlA4blBz^6tDitnT#{;g-2!rE zmAESv2X}xtp4SZZXfD77Iij~g*W^Hh_1WI&nwlDoV1+!XtsC)!b}jcJV}Wu9o%PL> z$8jYx&>+9y0YvpG&+*&Qk2+$|uF?=hqbn9gB7R|Z`L3|RoI?}Cu(g=zXcbje174{H zn9T)B%b(gD1E{#cUVui@YX4p=_&I7;o7L!|NJI5?tB(b4WG8EDYdggmE*DnI_QsrP zr~1tY|EwOj%Bwf23B!Y2tY)e<8nDHS30~6J72Jr1;&M^m=nZ&(l^3%W_*$fA(cpcv zsAs_lpk5QqwQ_DsY=8$CKF|d5U44n({~O8_{@=2 z8n4y6C6NjCpA$%Af`&_|VDjivVvXG1e$&3J=y);8WcAKnhWa>2wmf+s`GmGZ5u3)E z-k-?wD@+P1$>(x`BG%}TU%g@YML?;G#)>3uNmR`dK-xmP$YldhKtLU-h}bw*9V?5i zGe8Fg{Sq^ET~s$9rd|azheq{*7$}3e(TOT-x4QfvPUHL1d#2lKQ7d8!&2QVFYY9!% z$ro1*{=*qOT9Qa4tXcH1wI{exzNpgrsclJ>+dGW&W78R-gV?j+w9OOrkJaZ1ztlycW`zod+HOTcP3g0@1ff4NA%g%9RA%=dC~f*0VGudYSG~sFFyF8G-R`-G8vf z&?SF7HlLuHGdYu}Af`V@Ya!I0=mS&pXz64|jk9h*Z42mEpHl!JHyQz%@?+Ui-KXIq zLCSU0zfpGpk`$V!<8S}rKdj>onv$i?Cbl$lRr>z_t|Ar+rm~or7-nYX(xi?yC==t) zZvCB>1fG<%n{JZ&n(tK#^iQ_kN+aHHj)C66?!rr>#Zn-yTO~|xKa@*0bwbIjTxTVD zy^Qm3_g+`&)a%dWA70Jm4}~@W=9w!p`2-Gj_M|gS*!%6!<3FCp)N#?dPf{4m;S90Z z$iK?1VbSQjI{ab8F~$ zwD(3iWa0-+1GpH{Lco})jq1K-VTS9ErQtlz5)3&=?`U*4bM@{m-QYSnz5M#)Wy=5l z@%6Za=jY#5Qm4-vK=*GJ0$18(qZ){Idg0{^dpQ?8d|Bne!yvmw`Npo9D3EWo-f7Wp zX-51vFmX^6#p@wrovhV(qUD^ZD7$#dreM!eAS`n3jc`&}*x5sZg8G>r07EfQc0*H> zjgvFw%oYu0QLP7iO1g37H>VBD5`74vM%?eTd#@O=c>0%Kj-iP^1x*=oc_Extv!2L1 zJAw4U^QEd0g~~HI{w@xB{Uj>RZi*c-d1CW4ff$3rxSg|Do?W|aBO+LDJE@j|LzYg53dRN9N)BU@}Ea} zM-xBfTeWrF((ojgMF$aYKj*;bofj3F{EM(I?6H>|6*1#1{qXQt(-kphUFRx~X*Hz6Rk_y`#v~siZ4mY0h)xJk07=Io1_4oIY zDJcRvNL{W`LqOq5`8JJ6?!23#6ZWB~sU&i+qbrrdMLZHB39&0R3|NnMzq_q(4FoH3 zdTM>4KNBS-WX8eqyI-wibQ8JbfI+Qn$^G~c&!iG8PPV(Jr*u}eOQR@<+MkjT!u7u! zV63bkeruE1%K6SF(MGIKt*`fdV8E6T>)wPD3WPe67Q-Bg)%Lj^%hV2^UYNkx3300F zw)4txUykd53w{pS?l|Id-S5}LkyX=^hbmAWJvzv-^ya1SCnCrTEpI1(nxA*ERWt-2 zY8_Fg6M7hC8E@nc-ISV?e$o#MSF*s%h*MeI{`)VBPO5n_{j4S(Jm1#SWSWJldGnW& zP7>*A0drav7ShkTUzug&+Of}f;6sa5`YinX{IH;im{WfIyLTarmS?wRqmus=bfyMJ zKW$1ku${f|fnM0vkW^TaKgVkOf+H&F6ZeEZni#B$1`$0?lBxt#hDkOVB>Xcp!fy0v z1xSxp$;%%427)WCU1wn6C@NnYzgr+8{px&Yk4_ZJ1L@aJ5Ev3hkuV}c#w6jW-(J)r zVNJJs?DVt*=)i5hvu?+}UvKTtm1=*; zf9pDX6zJdzzPKThP&M z!pdxquwT;Fq)aUe0Ik+@wxSoa)0x+8Z~jVOJ=(blFYATzd2f^cBs4&kkoJl&@X|@1 zTfpYK{N>z@O)5Cu>cee&zZ_Z*bUB?NZJDp6#?4RkeJv$4%B3nH=^XK&bhCS!F2)!P zzHxk>ez||sw!Za{@w=*rlzoQAo_U9;N<9j*l(s)Wde3t>_PtvP!Pd#jPDJJVlTDq~ z(XztCVd@?~gi6m~iJ5{<*&}X_AUGfjh$9sQ2t?B+FTVly#Evsq1>RwPy?bo+lxX-Y zzzd|THruNczbq5(s{mWh`kWH#_5A&gUChjiXU=~#SNv`r+r#uh*DLi3TXQA$K5fW_ z-TnQd1^+m##}C=@^)!9KmPz~H3_Rf{8^O}IzJx|JR8s4lO`|(o^FH=-{ACdwg}b1$ ztt>fggfj^f=HQKGePCYHgmuldw+);g6Nn#(@}csxXtc%?_ho*z1f=~zg#2~M+OqA& z2Vz#AW?7R--v?ph3{249rP1VJ`lt=K%=!889+d=TdT)OtBclX=W@d`AuC&05C|yr) z(~noZFFY$@fbi2LZ)w61X9TRtT)0~$zS%C@`E1n(f`yMO@T6W?X*xnICvS*^@k2=s z&*1pbqvXA8`&vHrM{^O~@u&L^u;(#PN?MY_abBbGdxbkbl+o}sj;fuXyEE+Y!X%a1 z#L^_eDipK}9ntYIZVYehc8D8=qlACOW;x+!sZqmK!x|V!$QN;0qw82YozBDkTZ32M zS20dplJZSD$HAcC>}I=rL#+iGNn^Kx6@7lBj%$kw;;L1%qnVz<$@nTM3RA}+|~}IuAlfO>OpW3PydlNyNxH|{(v|j;w*#fPL6q-+lIi9J2whn z@frGpxV*$t50yZU;v^onOHS@q57_;I2cI#^*JCAK%&Ra-SSY-7rTc^F1&Oejw3^SN#PvKtgtM3 zz35oy_L>mrk(jh*7r{dW7z{txFRN#n_N{wGBxY!%(M~By9llCDcL`uUG5v(|(i<4V zYSiuUas%32S?MzbfsaYA18YpPpmjfKZTv*g{gnk>XSJPvS(~%dmAj420Sd?ZjWl4# zB(bW@Y;(zd=LlY=Cm^raI6s!!3LOx8$M7SE-$m7W)Lw}Ze(~XMY?zfhW2Il2v`!*X z8%(^-KDYS@e1BR($~GF^vTrd^cdM!VR-FF!l$;=2vy;HtDvw?$*PmK_X&GbyOf|~s z8=T|dQviT^fbsjBA2hw8fICvt1?M}8mBA(Hov;P$;GppnN^jfSjdE;r`C$11H%V^8E4lWbBlei6KnchniSw?6~&erEPkGf!C-0`tU%{huR#m5XAyTd4xIkJyoTj zBt$0xH2;tU%xX5-Pr9ssbWe0qK0No?MssUPxLvrS$!s=*%DSnX^V%eP$F?IsD$?@* z!yO)kDSdxHeT!8}(T*zWaNh>El~p}lpQM3<<|A(__OP!iCm@lpdlrrx9{2P{#P*!B zkTgpQYdXKDY{V8@{FGt$qN1>7C7XKMiwS-_}01exo3u8~)@up2h;gnY)(k?t^C#3=!RotBOJ28|$=nJGtcc)CMkQ`}ct|5MoO zRGn?VI@B&-JvcHr9xPPe#Rr#kn}{?zCE5%?yGW?i>LnL(FTDz<=ck-c4VsSt<>Q90 zlO;qiUHlN@LlPDj55v-Nddel-{U$5)?ow8Hy|6-DN1Z2zgJG6JuTJUD$7Uj zUAEU^M7h~&;L4PBpa;P8qD!{W^rJl|YC#MG>whD|IhhBnoOh25ntT{C?$!YB(J$;| zN6%_j2}p(h0TMeeCBG05?Zu)hcWYQhmwwUD84oake1c!L`S+4j{TGZxv-A?2K1;s1 zur==hmrdUl9!>_WD$c(2EABmKk%F~#AGes9sLFKGuPfe+of|du6;J8;q*?NGSVVt( zAzPBBKON0pvP8Tju}>5ly`V-*VjVS%?i903#!N9 zcbf!2ZDUtLy0PvN3@|d#3uZ2d4>(zE*MXq|&^yxL|8b-y?l)8II0IU=Sz{SGb*RgI zB|~InWXyklqjm0O60hNYxwo(NF5=+ot$Ky(N-gZ2Lq9>0vTOS`u_S$&crA11M5}`# zSZSW!VzEKIdg2Q{2#P`XeR#l^PFNXs*5+ zS{wmQ6sp8FIB;2F`>F(J&juY}Jipd-_jQTX9#o$H$A7Nz$UC{LE2(8=scwQELV1jH z&Q>o>@my|&G_Eaw3f{T+`{?Qr7GF=C$ygEJntPx4W5|>1E>H|ZnmRr`#WTa3rqwdS z#o*6*d^-yPuYx7&3u1_^P#dBKX?Ng?-gS>I47_jJJ)}r~28OF4jXd*zi2xr!&-UQ8 z@;dosAfuu@FM*URI0Wxjhep16JrW*@f?<-YO^@qNFUe7zKCZ}7F(+t2Ex-tRkJGY< zCWHo5S$*k_?lR(MyF{yQt?0U>ESLqS{Dpnze>gGB(i6F)&sV`U=21-rpI~I#C+Q4j zjamN{G$p*Zi9TOulvc4HUllY*YMt+GKlg@-wvFj2>_VnhMND=p{= zh#2boDrFCXqC#%uR!;Q({qcddATUhCi>+4CGEl#E5*SjYSaGbH+; z@lODyqwJ|AHnoG+u1ipN`e;tPs0^CsZ2F2uacGY;owY%aZzS)wB;LCHtZdCcXiD1? z(y{-r(^TYUDO>+_Gd6Evg%M+a`u}nE=7CV}-yg7Yi#Bez-C9vXMK@d4MBYx*{iW;r!mUD3`HnqZ!CkE?CTi&U@Xu1Nd2DY`Rg~o`{(!GFXlb(^FHUi zmUDCwTxWfZ6Wbe&jLZ6jKRkG@z-7^56M-2NOd{mB9)J&zJMRP+i!4|pk@?ykx_WrO z=P`&$PR*hzopU> zsmRc@1Q>#I7y}L4LKB4w1AEeJ8xmlw7PApf@PgtA*@tnVL>GR!HnIqAQ@mNlNhvT> zNO>f0&uQQENDkQHdo|tfWVd+O$Sg zE*Y8BF#d#~OFxWRc{a%o{v2M;>&KZ#N_{t2_)}RL@Ic)YKFLzG!PHBo6RnYX<+2u_ zws>zo_b*IFoR_TVgOWU_Z>WWj z<#W`-%LqtK7;k0`iL3t|9_}P`i@~ZQ%!{XP89;C$-%Wl>mdP($$<_yd!*51}71+Mt zLLa{w5J--nCm6s4qH+OwptPO;81!WRFli8E$mHDo_|wFvHBs~CYG+w^0ypS7P1p4~ zkPicHAk`snGCc#%Qx5VbU|mzr8Zah>$r^FE31RnjiameDT*WGY_|Yp?pn?ltH5OA~ zA%Lm^ne!+$_FK}!`v_d~cLLh=T+R`d^$NdE-P|EmC2(Cc2Bd*LKJuX2TzZ)BjwxN} z173u)fDsusyvB$H30X6PYeY0pV3C5B1?b$0-Vo#{Ynf8}Pt9Q<{q=k^#x-C|{BWnFve;I=-wtWaL4H@Uxqu|||!ny#U} zeCN8%Z6as3D6&gSE!*Um=Xj!S19D!GPO9jBe*Z?q2S{hab!xEV6UwCJe~S_s%jo5QjeCd0W~Ukm#1bI!<3`K=7wQ zTC+Oo8z@lCYqS)m!tfcIEUw6S4#X60^KxU>W3e=Xv$>KV0r2K=RqdE&wy!Xs!~4Yy z`pxH!hYC9O-m7-6Tn+0DNp}D4>-e4L zUAPbZic#x#gJ%C&k#T`#Bkh%8@*Y&XgrZ_u(U$W{5Tqbad8PU6=jg`?&35hlp-Pb6d8OyXq1#!1s0qY5NZ3+YC1(_wcZZCj`GX=;5FSpM4KOY#6C|--*AP9=t z5Dk9k%#l_o!rTp2tH2@qNG)~g@D-J*{Q3*p#OVC(E&8RlYid)U!LUIj>M5P&$zn>+ z8*c|J2jg`Qbe0E=%!H5t8u^g|lqC+fUfsXnS7&Nl_v4AQ&1i1147qfq5O;nnM-^O5 z#MW`+Zv;dqn~T8(LWWaQ7q5=aXHxfs2fBh&9bi8qn;VTBRNxZXE2tA4uouJHc&y4# zg*hvNAR^}l4~mgk)Nf~bc37@+(chr-gLZw42f|6(8#?z~iZCAlQ+VmefXCcVKlen% z>rc1YB^O`XGJk%C6ef;tQ^2iXr!2;~o5yxTy@fqJwm!A0L=3=F9?usw@Yqe+1V_Ra z0e1cXHQZ7m!}?xfo)z}>>+NFM#2OuWjt6@&$CmKx;#0HjlLzc1!+(jOk@-n9A+V$ev`I~={-ZTEn$NB7RZ_S$UGH$=WA`~X^ z#lKQdpl5fQtf*N4mfoi?bDM`0-u-cOx#bQQN7F#RXbIt~GH9aXycY^v3a-;)VrHk< zX)EzDcbKwCbyJ3rnI7w7eHnwGmV{e}(|_piTUpa#)%+gu2v~0w1sn8~KSD{EkEM)^ zh*2DKOcSMLN8Sk)>S=7-#&6&UahiqKud|`z#q_!}WEV}qR9L8azoWM&-p8~eHAd^+ zm^qp5uROn{cJB&dJL~Ry%^;1sv&SMsJdAw9lgEg$Z?M;_t>59 zHE8Y8v$u?8DxI&(^t2PwTUbN8KhFO6?&1;e>JlXyGdPAz5FxnPWtOYDW7w$7`2vHB z;Cn|b^w#}Iow=T-YRg`M6-#4$H7jc1eO)fxMp|VGuiq)a3T?V|aYhrz5)z|gMYhq|6`=;G|`Jhnsxi%dxgX{t~eX5p9;X&R}?IT1FSY$@DXSy}fo!z%~p z!W#4yE8ii;E2*I0`ma1OsQHSobok-m9LJ|@u(Vt7ip@@!NWM%DZ9bhbA~5ieO-y$4 z+XE&6l{E=x*^QFh`X?QEjmp)%b~riADO+%OajdmsuN$@7!o`~J>T3{G;5&Vpe(ZU` zpcwtm*#iP~S9|>0i_<)8r)DdS+V%1p zmgGyQ+M6Ma@@h(Wk`m#+F7wUMtjIUxgheKBJCj<*R(6va$|X$2{{v(>()y6@%)a$~ zHelA-1J)Wg~r-^>lWg7nMKq@x_+)wfBN@ z3)EBNM0Jc_?(Mxw{p7i3nN(BxI6cXVJ?s{`Iz8!zu)MQF8lJ)Ty+No%@=Dp1zh*~l z0s8!Z;~Xh*5+XgT`h7j&y^RI{I>mFn^*LR8N2tr|z7Sfzg80LPgJjHhWRJ@_@3K+mU>qeX7#nBkH(K5+s*eT5B8fa6iKI4X4Ny zTaNwxJv-BLZMe;Cob$a)zVb>dZpYJt?Owxu6W?hXf7Tb39hA{vNk?_k{d@XkNQ+Z! zp&&T}jufl;cCPqccAI+&^qvTJUefLLxMK}Q4E62#;c`ouPx6WYvp^$W=<*-8x#3B4K5lxk8Eqv%!^y_Fo>D( zy2^WESi&PYJ2X2?CO5rBvBf==zoFR%OU=fVM5heeU*{Q(Uq2Cxai&j19|29uz1G(C zA3RTT3v-{H-l52Co&RDlW?a6{f^BXP$|U>Lzb)&WvNMz0jELGYC2}zn8ln3I+2&BO zWzyf?YgK6W#HJ7j&kJo-uY(^M>@kYnSW^s+mjWbTCrWY-J6bQCUrPnJu7q>Ay8xJ$(BoD>_c)E@P z_UJsuB5F#bb0-|`c5B^sJ9lp_HuxRn3)Jw*e7oA#!s;f?nEiFtSZQ0Tny9(oQvF!p zp1ghEJBz_QWkXeVJy6WfS^xdJ?#h+FJGw`lO+#%A9Gp41w_3ikGd_q2ad|(uZgeD4 zJ+0O-!COUpoQ%zmgQR8RJ&#y~F5G3y5cxJo#6imhb6E}*$Y&u3c3CWG?%Wy8sJWNv>|3YTP_U=(BR2O&Tc%9hAI>;{S;C0j0RMA~ z)Vl~)UDKs@HQ%omoCby!h9kMnl9s+`%u+34@!N&%9Zu0I36w^WNKTn54=$!o*%GmC z;oXmIAA7|_R=I|B$M80s^P21%=97BsEK4+*5aw~(Fsi(g{x!>TEdCVQ0$Bn0J^uZL z;80erb+zuTmAg5C-##B-3SU4@r%-Z>t&J#FvYDK(73`93>**;=_(7lAPWjrSqb&xW zkG^|eg|tq^&yV9xe_a_f~S3W|ex;tq?hI};B zMHJu}Ux_zns)YLxg6M@2pQT740<*1;z&dA-bPvzQWJS*$J7R<@?lXP~w*!ZLFZss7 z`FiTboT))gBd^gh4OnxN8*uAcvF8jh(hIp^_P&Tg=53Bmf(<$jUgzS0iAP3#yLju* zF;W5(z1qdMnWoqtplfM+?Rp4E#R3BF?Tr@sR<-Vu;Hce{>i&nrto4;jpnT>=;Hna@ zsyPj}wv8@1p97Nr_!IHJmi)s13a#U^M8zC$R41IeVrI!TT1M1|fSh|&@~7g&o7nsB zq8Me=w+3oq<`%&!*yjA0`Hm3||DUHv%$jgCE)@2T)0IoVLy=OW#k^AF>q(;dxiZ%r zss0)xf6V^3M`=L3bhS7m=NU{`efC#_4`Msyp~mxx@4mD9AaZU4i9gScffpO-K2z|< z4!-w!+bp}F#1-`&w?#WjTH7`rGB7ZbmodK3g48rA*u30k8e@}e_a}(2U_mJI%)kA1TBwxrTga&~%)Pj4MIe?CdFSQ)*^ z*3immq^wKgYxk4Hm5jJ%Brt~!=8SSmu9sVmndcQ3bD=tQDNYn_J5fdk6`g#VXU|5L ziVeBGG4pu7<729O(uqftN25(##&UFy<=vHb;ld{w<=jYYaldD66lmUlCNMKAsxp~D zX2dc|Xv&g&pBf4-hncs7I_x{>yT~6w0rK6gy~cRrDDRt=bAkle2A$Wb>YhpFEKX!D zzlS0S>}x_a&Kp5s=K+aqS7(KB@h7A!1U~EVAue}R=9f2T{=?B&_)+cOEiYP>dbG60 z=3bIc6VtXW=tK$*`Y2~=)c&q}bzV2IhDyon_yrMU5v8_YAC7Ww?KnpvcuB))uD+xb zdH^|E9;V$MOIb3!8(;FPII4r<=<4J%Uu6zONq-nNYa(DX%(W z>fYS%J<*s0e352rz!;1`s<5^M4dM2{42>h~Jyqv8Y}NbBUW17B@wT+3-A6w|1+FI* z+mU~&bUd}&j(Z|o4`!>k+$HAEmDyyLGx#2bjHckOJ3(p59)KV^&Z@4Zej`shINZFV z{IUaVgd&`uICBu(T>p~7%X;}fqWd)RGMDPEA+9QT6l^{k5lRV4Z0Ti71qWhU^Pm`T zG2G3CBIo9%#_EKe3e-Z0Q7+oxa1Pzqy5e(ertJUJdg~Lb=IWMD?a(Q;Rp5)*KE-DuVj(R5&SdeqNb1I?jUuDQU_KAT>59tOKn^7n+{rLZNnG9n=?CY zsQJt699s%r&Oqd z(Z1uIxsqt}Oz?rWck8XZ{oB&T;YD}Ml0JZTb9s3#9hPip)W1rvaQXAB1Q@lnzR+8^ z!~|S*{DA4kDS__zsQk$u3gNy7k9wdg0wB3N1-$eN-}BC;V)Spe># z7$`0lzQTi8`CS|Pdj8AK6hEX_7Xy$;dv_Ze?@SSov0pfB2QMdY#}ty*j&z!3cb4!d z1}AoIql?Z{Q*xelD^{?cvv6Z-JcqqR7nsCai-^BXVjNwdq>Va>vD#&8)2)U6VvTmO zHm1ieg+dsP$QXjIu5fNA%&jOePV5BK+OhRYyC6>{qdQ$gBQeZgHRCaUYUY$%Dqr=r zQqiH z*z#YG1nhzywo}pC6*pW+$Z5q}WjPlM{Cw5#$X$Unr{d%~sJ!qL6iLNoxsrCOfcy(T z*AS-YhGdx1x=v#EMV^Y+PI%tt_BS`pN}u7hf-L?+4@!qX_oX^~W8{ z0Pd=|24g(~RrS#KK~xY}vx)tzmOC%UQmiM}vF;dkC^TpcavGbhfm_kiV$xs8Z5SaS zH{mMlx#4`Ka(KMOhKxeAOUHxmBjcIBt8e%sg?lsGy$#)7hdeUM6RAKvZ`x{3!Fq|4 zm^atuf5?1hDgj&oF0{RPDfd^P*z1DAC=vH_ps9_PHlnNSzNg1?21ZR}kn|#9YBrO^ z?un*#$HNrN^jdcyZ$V}}+V{h}P8ZJ6b&J~E!boiIH9gD?KBl?cc$tmKcsMH!WR@eq zH}CezI3~G6=K)+OLd<E~IDpK`7Q}-D zEe_gCBTVrseD$^O<(W1>oUepN3&U#>Q1PrBd?B(dZ;y<)QD~kI zg~O_yW?mVgnZIh8sPU-gmy4Fg{`)Uy=*$PD)dAm|=t)%lsu0lMG9;w>!%r;miHwhq zuTgztcd1W3xb%gofH{sV?#}l-MFhM8?@M|DYs#k(OED~7DPIctVf`q851SvN0*qtR^_??i zD6L>}b_4x>f~f@6Xb;bl+qP+$nXjMLLybkIxB~MBGH6_TbNXss$69|+=UNSDmV#Z^ zeHT-TqcF(phN3(qmYT0prGUPt@ga4X#NyfQT$ zOMx+RAAQ!f5hC6^s`Pl0UJ0R+J`=*6e&F%C{B@21oM+0M9n09(O|t1?y0L(KBz_>n z?4{vY;;;8kNiM~GHgx^>e$WI?x$zMmeCxcZF^%?8lJ-lhzD9>orizJy4JGO+)K9n8 zzF|;#thO4kdJHWm;=1jCi>z@;Fh!gS1)k!fd~8eEKmAlTQrhsYNaZa%*(hWcC%Mo5 zJdInA4Hz;4t1w%$&+1Kh@4Ev`McUP3VDw<0PQ(79)JZA9en*4}%1yEl1sX6bH zmJytb4zaHQ3du}-*$DmTr%ox}RzDAxQPa1!VHUl%*x<>&4`kT=!ft8L*gY+H*XD6!-EJl7tSpUlgQG>JG#n0>RiN#}L4Xfx-!&*yXbe(Wo`vj%5to>3Mr1**bs;y;jq@teW%&hijh?(pzs z;ikiX!esqFHC`27A2`Aip9!^-+WW$}zS(J;ydSvlBgAK8+WC&6rFR3=r!E77JQGW+ ztgfy$U~S7X9-~t%ZY(s7!#~_TP0_@zuA8gqTTV`AY4eInD3Q1tHvW^RP7O3g(tXZS zg1mQZoj1OzaD@I)I(PC%^>^G1(c5^`hE_XIwzIqYBQb7}B43^ei>1wVS38_aopSeL zT-By5pde*IhNB;boeGDM+5d-;{n3AblZ)lH@E*4e`9D~kVamOX8Q*GWT#;9i;f%i3 zXzL=1KdWEg9hCwS5Zi0yzio3m|13V2jQps^M!;Hpg74yFj z?3128b?{|B<3osoXFfXLE%|kdM)Km)Xj~XWou}uZxh5<(d7k86x{J66rVfMSU^A2} zEDw=+;OCK6ssOe-_-5$Zk2JHE-anjgZ1x^$H#vzxb>s%fWeS9@A`k|?c1;=z@@~O_PzG8 zmFsC2&$(WdobP}>8K!Mr#J6GN;u=u7oQju~ILljKFW>}MUIds#xLR^?c-Ex2>AtS0 zkCAKhuI=jT>h0})Cy_dpD>)}orzRUDQ7~A?I5ZT>oha9$Ds5n_s30jJpyqLke{mvN zKq5e4cvdTabX!Dk6P(MY^kM)vxS5|Go_l=?%GA;(E$$Crlh0+=W+HwZ_-mdJ_%#J1uI=l5ifgdel9l*0;a@ zC~_LAy>)kiry1WTEmSGgm1b9=T*Gt3*xf70AtbnzCX~YHl1K`(xzrpGS=Fqzb8>Fn@i57(z2Sx2h}` zYs1u~`lFNFsnA)XgY&g+iyC7H9iN=A&0odNjQDaIR`OrY1H}&qOf&z&%Q`}u@sIRt zZImLt+CmJ_U)&Mo+OK?LkCA@Eaq9WNOZ!-^9h%@@d&KQgso~*lLk**}O$z0^sg?6N zS5P%FC#cz7^kVF}rNO-eG^I5~@lyYylPJ6Xrib&ENvP}rgS;md zeQ*XNVktd7_HUVt?A?_wt>3!85^vtL^7L?Z7^~^3?F1>Lu*abhe!daoC~}aR=VFrE zy}9GUsPY~Ihs4tO+8y~8sg6l;ExSYKZ%uH^=sJY*?nt=jTE%|cQFYKv}{&o#`doYhgQ(^Oe{A}{g6$F`c2G<7F4_Np-7E@8eu zk)18;H}DT+Q^p^#1p2{w$a?9%|*J3 zRMg?@p24JO?Kwr8tu;mcQ*vRBzW&n3P(E}HW{)iFM?p-v7T)CT{)&j#Cb5J?dP7l! z+eAD&=2F*T%==q;A*%H2E&$5pOUKB$Wf9VE)OKFRP7h}$?5q?;MMXwV=Nlv*BK5G3 z49Uxi^T;=i%{9MDauSV;Fv2)j5C>9CXZ+9TGE!!47#V5szuviKoY!}a)Mk`q+`M8* z`H<9A>HIC%AkW;&Zfi@hrcv{Rn$l2HtK(P_+Nqgyq^-2akFz;}Bz*+Kv6B*=iy}+C zP-P>fo_Xu-S^QzvTK3^=5%s#2uj!ZS>PtDoE0d-Nyg#5XS3mXlh%)6d&L$Md@f>W* z5?ft3QZUV-Hg%a6Js8yF6TqKTTKMyT)dT8OSO;84TG>|CZ1y}EMWy2Ox>F)yS`4(z z>M{P&LBWAl-6)F8bhl`#Lu0Uz(cB~T|8-7#`KNXqEy(18Je}c|F61_o6<+m9V7!DU zmr?s4@e*IRHnF3O>{?hk$<;mI`q%sH@3kYBN!!@frlU z{~gVx#t<{RLKWEQ>r56GFO@tutXPT{3#Q-h`52ULG?dwq|Gk48K_zr|)ylzh2m@qM zCH zuZvw)I|D?EA`0*X{k6mYzr)H?AfJrKAxXFnf4cY78g(T}fm|<>w%W1;k6SbO?sDek zVAl$wYLY2-s*P)?E92!$dC$o?spj-STUH1>v%?sUaj*Qou5VE5$jiR)spIw!ex=Ih zuaqTAl$UK(44QT6Z>qH5H(N-Y@qZ{l2@u4TjoQM6GRMT)#!-#ak9X);<`b5NM71~3 zV)tT_D71n#;ZSm|GZ7#9DZVx;U2hL$qDGakeW>fA3J!Lv+J@ydRP>WIv|} z2jC*rP&PIaeL+71E`6}+VN=_`YW&58h3(|zzn7alDnBGlsCX?K`#6+p6fo!zYH5S5 zI;jR?SxOzXxKbq@d9IOTT|NbZBQafLbJK%SwO*FU;czs=dOcTszKWy)sCndqE$iuQ7x)@9~=o)W!E&)g1jAcb=|ilQ{-N`L%+?$6x2 zyXm%)icr0_y(WZ0_%ts^&9s=!&{)$`E$woZL?PBV`6z8oT7|{eK*wIUU>)RS$A;dK zNXJE9G7t@%8U9fAEKrrFlpy?y`*ZouovDWXyI3pv4Pva|Nka!+T+*-rnc|)Gs{;>_ zgVs25bGYHTL{HUl62nPZMU-+4g(55+$Q~n4^Q3Jj$`!X}ET)x4&7=E{4QwI$EQS-R zUv+a3Z<5_dcw>FQnKgN$Ii)G;=JS>tT8ffG36Y821i=;3bN<}EFZv2Fp_NNV{xFEU ze-`=d$of6@PoH-E>;V3){S+g@xrxOXmg61om?uxvl%Ley(NCHiSQ<09HhnzHxFqsG z8}Hi~?cJAeWRpH8GN3r4ehziLrOc&W&L`OYMkFFJW>-_!hrGPJWrokk6C;N`I(t|T z1iH>F2;JO2EY#i~v_^AwqJTDv5DzJjTi0bYr5SOjQPXhVJq)dq4~GJ+(;t_ji%bSvN5y z&-@spb9Q$f2H6>>*{EgfMMHqDEp@FB?S&gxHe+M6q+ydnTyND*`d%o18>>kgd)Vo9 z%wv{CRk5eELBrgqZ$xC8gB58GVqIOoD7ST{t)9%B`I5-WI4z<${A0yO3Bxg=y=r+l zrgJi?*}{#(_ohn*yxFsoQW?4-v({wsM#YLr)uCOi0mYoOv1fg@C1pjj1bL&ngybtJ zyn43p_Hj?t5S8_&-BK5Omq ze=?Y5-${`=>+GiG8bI-F;3T=3ihth)Bg-DIXOGdak?+sNLH7;{E=ej(zM zL;GANmFLlX17lT{!MR;Et=`Oi$`;=y$|gU(ElRTZ;!=E%&9m>3)h(^}uFpACzT(i! z_)H=hk|*z({fT6BYx&_H)G5En`<&Lah+NdyNxv}ZojlH5w$xZ8g)QkY8tyHqL$2yU zhxuv!K%*T>k3sFjzdDp-RejRMYT$y^XPonMPy-@K>&)s=CUH)n;v zhel_>yTNNu$t%;)(C{cQpkjkUIYOm59}DCr@`O68kEpa1gsm3X)Z$R~6(igYjNGKe z(x51~{|>VbuYDDQS`%dF6d%}irv zuq(Y8U+2ycIj+jo*-sC5%p;9%Mv>0-f_h(u{jq|IkF}1i4#=RtOf&AgQ=`@cyoO6F zKIHj~dB?8X|HxbzZQ$mJG@^_@%4~nKTm5_00>6Rr92{LnWeT)B59MXEX>WS{IAXO* z-s+0|45;J54Qbcp3}GQ2UbNupg_v7JFq( zEVGt}Qx~lQPu|VisT`;ZB|q)iN|N-Q2`^#73r^1<=|%OrhDx!xSrP83Rc(9=(xwhd zkcUDuOvtBhR%i5Eh;wOV`=dhGZg~MJS4u`dG`NPL76GtRT#B^j+vVv z?jm#F>|fc-6F$VrTC$(4YJkA=vdG27#V+Z|<3iq4QeKxsw$-K?8Gh-~_65y~!_!a> zP`aP^@rQd~OXn!b%?+2{sTS3`T3A~7Vc7a4$u?rXgTr)0`OKMQr`c_#46$Hy=MrC( zr$_$lLmI!Df@U)v`Ow)~u2|8QQvHkU`$mWc1gVw@O{b@X6W6ZWTH3n@Yw$}fztP|z zMki&qOCJ`98J#>0wPb>wmX#gXrBW}9J-zlBOt$3I3}pu9`k?HIkw$8^$c6}Ytd5G^ z<0DusmT@{=vw6Y56b(xW-5VXd)XOPKCsvN|jzZPMhI`4o$~hti*r_ev3csIRaNpb< zk)XSkhAW~edU=rd1Z}xYin}iNF|v5bZh1}uG1c|;S`*fX(1ei(9-TiPW$vq@9;+MS z7;1|2;~;bNU6wv;Y$>pEC`og~Z#w^Dz#!U0onF-aB1tJ>@KbG#o>x#=b^iQQ$!19@ z-{?g;YnB9>m$;ec%rO%98i!YS=(b$ta57erQsTVEu)1K=)8HS9|_BxRQMdfZ%uZ8p*e$JD{GcY2jT1%4G5kHB2d ziuRGq>gwu(f`Y*FYJ#VmM3zg5qFPc@TP`d0H~A61Y)f6umzUMCGD5I|s8zRb#^hJd zW7D$DD;H!#o$EbjK9q?jw_KDopi7l4IZw_?N>X(BxU{{x-T7pba?S6T%aB^*Y+{OL zJR~{)rygR5=BkF7_JPG@3>qtV2@J-D)$6(l%af*SryOpD!(Uw*JnP3IS1x4|fY(%)Yg zJ%wE|&NrEPWq(|?TV0t!Xo-|8gqA3$E=L$`G6db^j81b1z-iMQlVzvm3$JN9Az1rk zq`_7{55#I;h7jyX`d^YCECF*HkNNvzMs5*nZl<%{Q?|T{K(_NiJKV(AMZfkATXOohW zYQ}r8I)9+95=I6(tV~1^EPp8s*QJiEbz$=Nw0e~~K#`JHmZeK_9*ScW?PHOp!567P zFUP0kxYn(#8jpVI{sU%v%4RVGDoh@SKU-<_Zi3-$xKRjHw)uPjPN_rIX=ui3zo;ZZ z-fM;y=OiiwLp6pAnR)=QjEzp=Ldklkuv`!a6DYj0P+7sTpZOFz>v7S@Tnpw7qUJV4 z%qzJ#18b_frdY#iyOo#lL(d`~VsUQFie%LWl}1rS7_7};@`e^dsp>YeN+&v&xS~C2 z*zaK_n|`3j6vzvcN^yEQdg-~slKuKx$l@*l*8cY-(t|!=bC7gq=xi`LJ6c6?U9H8j zOs<|pZo3Y3slN?hfZQCR5T;M~o!6`l1E{x57q?_UzRQ<}bnLb~aGS`R36}^^1GbRK zyAX-|O{WOfZ5t5Rb{1Og#_iP?aT%;1T4xi5UNilNcD8txPWAXIX72wHA)DveQ?EpK z5@jj93oSo#b0rVujWw^(u4_*WCc*9zUIS)Y4EM}mU;ZwWlCp)qfUfNTN|7HrUFY~e#QKGJ|~tM z35^&H(-}@qPK)X$hK7cpE$sbFR(YfL7@Wve1ILIB*+xT_YnYKm`9g z1w6I9e_u$|dgt@cZH2B>Lpw;WyT5E1VJ{lV#OoWZF^;u*825gFK9~=UJuXz0h;C?U z3s6v?FH%;HBymUoFc7)?9ig+r>^!=Xz?s%n1dxlt1 z`ZImZd^pcmjE8o8pC2pRF*zGJso*FCipw`h7U&N)VC8@;=`m~jI(jb#3Iy*ER^aaY z-1wsQ%$%C_BzW(_drF&~5Hfmw_a5N3$D?#CBX_r+2lkuEz$`-o6Ib^;Fx4fX7XSKe ztJ1<@1V+k(qFTlBsU?-EHAWv#{-tYd{T+N1K>0jM!X4u1i#aen2AxlomP`DNtL_u?e`NWu$0B6ou~6qhAnB$b zNXKjOrPFY55W4%w(W@S_3L(8`t_0SE3^Z`N-{<%I56OxI&v&ntk;FrupnS!NGyTLi zZfTP?NClEIaugvcJyyQx+a3E4R*?K4%JD2kscB}W^|eVb-;WW zMpFD<{H1g61UY$iR!bkAQIhZ_pXcK;%4suO`|AyY<2_O9hxEaZ($L(e|2+!jwsQNgpUezuH+^*gz}H(zx-vlMSoKi zX=EqW`(e+OfKsz~b$$!}q!@G~pLY2Kx9^K_?x+_~#SR1?NfZ;Y^qnmujT{*ftxsgF z+;*J$;o0%v1e|PxyzKOH*qODg;A2(h-^6aq^dCDnUC;=Wg1;X;@e*~!FPs{?H19h! z>PcKmt&}ifBoxt-RaUM^l1h?NQ`EJduG(2bxg(S3nDAOy9la3Ou-@)6U7{H~ZPYvY z>-A1pfk=t^u@n9Rr#7eS98|ZvAb{bh5RL@$SWM-{K1+P5*`Icys-{+|`;tJ;li8Pe z_JF_NSp;s8@&|l4Q7O}cO{G8K;piBjVi*!Bw(%?Xum2~mqrI==g;buC4%r~EW*F-P z$U|wv2dwuF>NADQi)X!T<1aD3s%K_`zC9g1+l{8S0`-Y$9#>soKkGpasA^fDA};lJI$#OdyKcu+xmk)PIbDy zM^E+?zEUT>JLgU|i}$uz6bYLbI-Y(%S}7w**8LbYmQkVZ^a;VqzF!ro+x`CFL2wf= z*ASe)4-MWKmoe`=A3Q>$B0aP9zgV37Grv#9j+B03i88BXo7}MD%?*}emSZp z;L-W)fSjBhkh+OONeM#br+RNL#Q>^l;oYFdiOq*PcL{xZ3H4%K$(oAFSS zLS20Yg8FUou~uH*c@gPnq@|_3TdKb+YK1~A^(JTOXhv9i7NIK)-by@CF-}AhVsxB4 z?HanuBlqs7kDQ?;Z2oTNrup@n6<;N-xa}jg40$<~`xrss}J^`pW>gqNc?vQC8V3OKH+h z3SH6Xn#}gthXdz?jDR#W__~PHP?v6cdrfo|l@?CiI@WRIjq96#!aADjQ!N}7xI8T4 zzhEtfj*nx{J6zTMILz(`hKEGAE7fXK?QS*w@gE+$zEx|E)-IZNW_5FQeH|Az_=9-b zud?(uyr0sLw7u_>ZMeat59D9XcpWpwx#mmOHPjwK*)7B760y@&gR#GJ3n z-Hm@LU}-w7yp0P8bju`Ohvr#bjzE!vyk=MLp67AqfWp@!cOZWGN!!Frp1p-Ha`Cxp zPA3F_;2CLyE^)98sBNtahsr)w0|(}Xe{=4KwchG3r2COAo(Xc-CiJK5* zXL`gAqE{Kxs6p>nw2woZ=`TAP-ZY_m#%>X+*?8A)|Hu%xOpK4`hV6B1IWLE~WoMTK zJ%K4lu(-^Lj9bo+lwH)RopMKCytzijLNJ3J;hV}&QrLM9{MBC9i`(b(P&UhL{7#Hd z&6nkt-?WWMvUM29>blsek)?FxP6&d^>?^l_(w=%vKe5w4j{r?qm@assn`+!0J-^5! z1r4M=+ln%u{`!Y5`@&DOrg^gqoy>X4!E|l+WEd2NIRsH+bJ_3AFNc!3lW@wm4sA9d zddNc6MYm_Oo`i~AFhT)I6Gr3H{%hL3RX|6clo}R(#KIR6}r~$-l4st#dlzvPGI++daW;{PhSw+(LGXfwZ zZ_~B}KV~|Q-`v4zcLiXPQa6@v{>3fYA&12yy{VJX~xS z_dO35Py0^@WPFmG&f;_UKXj`V%-6EmYmdxr0J{J@v?D zwGm znnCIHR+J=6Wo-@DLB$`~p=jD&Sfb3%yu7xfyP&w3^p^kaPSaa*p7Ezpe2zb#u-PIg@?5y6 z@d1L=GO0$zdr;{eBs+j6fLHzo;4DziH*tR{t3e6LjdzMiOE)d=OXlr#;M1GF$cK*U z5j!2@vGhqIc4w-k?h)QEljl+elF)QQ9CeQ(1i50SGk@)w09MszO9?EO-W|2#Z?g^~ z7E~onk3eoi5rszgBslvse99TMY+Pyesb{?TtCth4C~31!eAH5CQ~a;*Bh6LuDI&1*UQ8tz?6|nJQAGFmfT| zl@=wV?HE!!`7_W|DDg(xMB;8kBU})iP>VZw1g*aGX2wn|Py1f3NO1pWO2uUG2+zDi zkcgzYOn6e09rv1OyL`Tu^8ipqBrU z?GbT28lx6QzZQCUewX!SRcl{Q=&L{F2@>;CS0S1+%odutENgm7pG!Di)%s+eES9-6 ze6%}qcK~mF=)vH2nPHJoq$z({*LsxNzWil?!glSjrqes1)JW5V51l7_UPR6Ai_*p? ztSY^{*0U4&oq7tyqb`-ETUcT8&VEzO`;1Ve!E`$|PNtdx@ zgf-dcE|=tNbj^yMqfwX!fVMJB_okwY`Q$90(98qJjg+rV`QV<;VMK1 zSC+JCO(BRh-`%4t`7=@Hj}$o=P))wE= z-31CZ+q);ugenr~b z#RtKXrJ-g->iE}3onLIvmLD$r3w)yCTO}tW?Z3|gN~xfN0prP;gY?CFd^#7$fDW{Z zxCP*8$NC+9zzVM$$Ni(ZV{rDLagDo}{?-t=o#)izPkemWhfILvFMT=^V_0Or&Kb)B zk9tqXaLevs{`tq9T6t@i!H;@0L#Y1Vs*TO;43b zfbgfl_2MY%%ye7FQaQ2g#i+vZ!{K6?K3svDD^8Zs!dmSzOUL-U_MNqnE7%)Z5ap(!1{Ehc#z=2z}@ z2ove+w=*xn5ii@wv5|Y%AMMRQZUcdc^z!7P?pl5&MC+saFlr-16Nc53r4e(Rqv#(@ zbDAH_);0AR6~CjwgdV#8ZyntVVW2S+7E8y|ut)(dBTdo)R6+O($Z+Pn9qQQe< zQ7C)3WBCpkz}1J#jT95D`jZ=OdQBs_h3NkT|%>fv+!a zej&#G-;Fq?|NA?R|BPe$jX+s!$j@Xe5&0Pum5yVAH+Wz5zRSr0`LymeUXWJHMBfGm z1H}z$;1L<1xAp$3Mi^x2ozs%*xXh9Zv^Q(h8CLk-_|%0{BH$IlaDY^< z0iYDq;McupWJ42c`PDL3oz*KiNQjNi_f4BTD$kELB#QBd_ktsGx{-|^03Pc2c>gYV zRDjb7NlbR%3&0=1dDQREk?xRo_C>uE>R`WHuF@1h2_BW1ACJKoZ6@|-^}CG+hmr9e zTq#f=4C>3=VE(VZ1iq|>F2euA*;~g&y>;!wqu3tBE=om2N>n5yO*)j6R*(=Sq#Ha2 zA_CIVDj?Db(y6FO=g=uVNDmFeZ|wm+xA*6L&OP(`H-2Zw%4=O~ZMB38tSH&v)QZpkmt_24h+{%7|sxBD)<_aHaszIfSkCf<>~FMnEoz$S9fy#%#@NixZX@ zi$lKaUTpoJL1sFy!^T*P7S?!z0jmZDHn*Gw~eRQ&jDwvL^ zfb#5S>8*PQTt}Jrmc3u@0V%S-eG|yLSk9@P;uALkX}m%K91IDUg!Mcv-y|pAb1`7I zqIS9&1`xvN331-=+$@Wx37N&@gIgAD7wpG?;1m}io73;OavJ*0d9uj9Lu(1dT|iVl zrzRkOYPu%!+(r`;fHO4f!Xb!Al>HI!tWOZZV}>2+lp54_&x^sZPgWmlaiLlHNNMr# z%>6a`+}K;B@gT|W5T#MvQ_{bP>i1$mS6Q^0XGBUwz6gIw3k! zktNzvYz!+Au}f-+=iC1enTeWXohs zHHXWT<3}YvundtB`kN?+)1uX1be25+MK&A@K?It}r)}GOVC({!0lQWIS~CgDp5OHO zZ`{()MLM{uJ@O9GyuEQvskep#(FyV&dS`mQnDeb+G`UXfGPpuf(N*(;XQXs4RPr6< zQn5->If4Y8+jhp>8J`~`yhG*-aJj`}Jmkq?|2kU@0Z5Eu+H0-|wpp3!7B|{4n#M${ zaHzPpR<>i@;F&PdYro0!&h7r{2I{_47iZd8s46ufIuPixsg_3nn+O$%u-!w+Onmx0 zbVuMAE7%JKWks-Gr(Qo#7=j+Mr*tmD=@#6pY6LTz}Z zs3|pZ$PhZm#<(Ch_Ti@PQiI@dY{~%t4KS>Qw03{g{oC+x_YE3)E(XxcSSk8mnw@4X zJyz#R)*1nDezj|jmQ*KS?epBL@q=Gljht2K*cs3EXdZ~&_vNi4oL+FeARA z+NYDN-6sk0^nwkZ;e`{r;A3kXHyjqGAD||I>Ph@ON+4<}-bxEECpi*?d}liliCR@* zP<%zDvT6h|>DG}j^#!9o4xfVd5x=PDB0p%xYTGd`J2vqRp*gnNzH4EX^WKq#egm6D zM5E^4#z^XI4SK9GD-OI?1QY*uW#@(J^zkm?>9_igzhWO}AL-|teV`4Tlwn91^U?^t zR)81+INvJ(#IS-`{@Wyz@riTDfb73fnzQ~DbQ!$bKw@+7>qn4foGQESG7NH0ggwsK zK*9t$u%hwPfAA5>znEwx*ONH6q*`jN4>9FXTC5z)K_FdiJoyd4uz*n~&AeSLtEYTM zEYkYSR)`r$nG|qQ4}x#hCIVesCPc6HaBDK*&Tx5XRov{w-*D5dNzsX0djQ=fWki#+ z2kNQ?RZ{j-!LF&2Vps2xWo9@_o22!(K8um@u~Fp3fl#h<+d$!09I~FV60$kQ0!MX$ zxmBL?ddV|n9OSOgYlqhGZs%Hu(~gjRYs}>;yI;&@jL(Pw!~#x_pvvtS3nZkeUAZ(Q z-v7~;t5#j-iGc#(AB6NNC8Lc$7J)@(Ti%LTWX32ycXpkvl;y7#$^gDK0r-`2BUB&H z!^x#ujLwchAB9&M2*8@R6FGYJkoD zl?z=%NPVE$cJZ6#i$r`a0XhrnhFmp%Q~)YP(iJ}g>3)CUS^Dt(vFAE(cQrzA1@~Qq zRDD>v7C=t#3qW1-sD!)jkZCRxtG2TLM#*wcmM}TIsonZD$ztsa>d7O#p-sl8vQL zXEu?zBa`*Ox;^rt4IC$ND$_Rea@ZmoSm0^6ih*FLe*%(%;AIFIOhc@$15z8!QAJ0Y zL{Hk-GmP}pU$oVOEx(!ts&{}U(fhkOt@1)Q-iqXwnaG5RLGbl}N4aH)2R12IC`zIx zb)Cp+FW^R)+jh3!GtRmkh^i#|k1Am_26jNo4@NhqAOHC;iXZgQ#`AIic*4XO`fDKKjs&ozP9=|pMGP9D_jla zkcqa3S}j)5Q3{hoA`%mGQ1XUNmU*bZ2grD;irT+&oY+y3Mnn{;z1`K`=EYd}9Xn6%Nv6**aFE24vT`u9_~LZO@t0zZTiP$0 z=zP(hgLVrPl__F8dba?GqIpRtKpG3=qyCLEFpYzhDSeoepCD%3JuDBv_Q4Ft@`S<< zEo&^UH~-W&ow-e#_Ibi!L0`ho2B?n=?0o{WtVuedGsk{ai#NU{R*M0WrYL^18k6Ic zQD2`Hw8UU?1FuAZW0`tkEoAiu(i|tK4TYc11r^ zi27hUnqZ7cA|XpYs8a&5vtzxwk?FP1M$~dm}`O;MdY+=3ehf5{AY)l0q+H{s@PVr1;#Qw>2jP4dQuN zgbW7#0T)1`a*35B6Z>yqMW8FWc7AjiTxD57iUw8h1Y~AXjHJ#*D*S?5qtddfpmH$Z zN?TPz;URQqP?o_))D!y}kvH+c!nWvB{5vc|(TJkI8#meTqprkD&o@6NVYVhlG6ewt z#-}@b6>mj?$2&sf22^*@j`0I80)IS!3R~0&O{2+UksgHgR9dP-`|0dMxEuKX|C(Ba z=>lr#vz1fJ5LyxF$IrB^Rfoeue-l11xikQPz3?cvwzIhYxEO?GH-~5}#0FIfu=vZ+ z-uA!dSz<(?LmJ(6!Vxx5?VQYMZKI7U5XV-{B+7eAA|rVaq3D=gDflJipv7DH;^;-J z&-?WUzo`$<0SGt=_%mjKvG|TN zpXn8{Kju=B{xg<2PBP5vUi75J5D6UnoimI9E`*dvqADkb+jCqLg=7QmudGRQO3o-< z03Q(B7x53f$h$>0kZuf>v%@djPk zV?a@jE>n`d%0DbashAcP++DD2zwacJE=e*@U1_K@_~tb4FM1wh4d{Syd=9WwU`B_f z(Z((T8^hG$jf=t{D=*3~s8x-m0FBsfkGPM2*COx}Fi10&kfQ(rp(_`f z`_1B9XPu-G{9|Ig)A8=1)Y<|QV)J{~Gh2z>v@s}r7d+qt)Mt`3;mkX5*QhDgKBEd)d%zx_5=cs@fpxROF+s-A8^JL_VgQFJ z{sG!dL~x^jhY5o(*0>Ad_kPFM>ju*w$nrzvDqh9IdHj1%=r!xe1%P`A7}B?N$eke5 z<^)&Z5Rm)X?!j73C+Q>7mBqxiO|OIDK179c=Vuch{muV0FKUaYJc=Q!Zv7xtqCFbH z8+l3#4-y%8VaP1Ddr5EY}PQ=lg$r z2ww)_&OP`Ht||o;Er3!3nII38jetR{)bcF}E(Lyw9t+s|yf%PaBt;|R{)po7<#_{? z;D{l#wG!%A2Q13T{Wmpf{jSniOtc`ABllC20Y(;3`ML%Aju`1I0U~$ zl6}rqfOY0^@g9R%&6*EUmo}FYyNEX)eK#S;kLVDlcws)`rz6h^z_SG;ewSix%IJ1E z35b4(k>}?Js@5jjUzmsC@L(%&9mx=hilPqr^K|J!M?I}}b)ztJ-n^TEREw1ZE`!Le zpRE7wU#NY+c%ksh={^#N)e#LxGa*p`nX`h49z#O+qnt8wM?i*A;4gDf18QQV9hU^k zDAO*dsl!F+5=%6}D5=(ZG6RaDC_)i(0*!q~8N&kKO|t^k*$P2Y)qSi9=|`m^Q9n#h z5buQ@&B?|{KQ03F%=PGUT*S}X7(h@Qp!OGj>LZCTBBmp6&1n3MT_rqqzg!DSm#?A0 zdFpKoXCdGG8=5ufZ6JZF*shZ_T924La*q+ciWDFV(-9EobQ%C(O*U1wX~-}MEO_b$ zAa?H_{s041iJZOlCMnd%zS3s_^t5~Bhz+|R;i0e0&Zi`ABLadR)DEtai#UcemMa=Y zPrMNDo;NEs&A6I#z&`fSuzjVU2LsqVk=OX9GGr^M*`Rd+BrsGo`6jDLevu=Q%J(Vc z7nRR>FYY@Nt=K}baPzDHn$%6GDAFf2&OLo|m4~ZRrh)@dn8Ixt7oc9uhcXUc+MY^Q>< zH2`HyBG$#60APZ+^-VcHBK5X;`+#F&pnfk$aDMvUN}%l#Fi~h^7vb{nX?p9=tn1)k zy={oI0Th#ipDQ5)5*rLcoPeRf(7-@o1q6!18i~v*I^ka>eay+C50TaRM?9XU7gB9{=87gUO8o zq8$X`yaXsT2mmNQ?>m8j2LK205bz69Qv*+!qY+wehQk1(mnc?z6h7yF4mDA=+yr8YtMH4R9usX5!hk^lgG;ZBTas$nwC16j5nn@-DC4-?;xs|H z10f2+X&nks+OCGWo!52cy|XUlBNa{F61|F)rO0NiZu@(}20TFh0KzG0-utaR5GH&= zK?zB|@9LVK=zJJ8A<|~IqW20=NwZTI)wkekLSQZwfK?>d3U@UEDGFRPyM!h5t3=Ne zlaAd$;is8+QrVXGbNj|FXeT1MROnodrqO{RP#jVG1*6v9Mp4t!0=x#7w#tjcEW+DM zr0;rmt@!#Rr)UlQtrPeq;;JlbQ%o@?Fz1-$@?&9%2@LoG=(KFIJ+`uK-X4u4iIPB- zp!|4Cho!R5=!KV!$QqMeE5t~@fYSp{dz!^M4pps?>5rnQokhMF+bGZMpoz>cOu^zM z=S27RgPl)#W|awcei%`2OBdHhO)OacW9bXQ*pgf+#W2c1^%|mD9VTOiyK;cy=9+f=4A*FkUlCg%w<3Z)q7NLU*TIz1I<<3haUQofIC#n-X7zd1`7WJ5`proBH` zrxFHm<|&}5ga{Dn8-bE6ZWzW7oE#GoPZ)1U<(Z>b_BtiLF2Qt=hsTF zgsJqr<(@;_8k=J0uYrw5cYoJKc}|k^QPd%WNNxdr`9)~7 ztC0?p0W_?7^v-WK0LBA6-$?{llQ3i-bIW_J+R3_*fU2EDYne0!-e))W6dZ87B&GvK zgpqOEzZe1S#=jW>rp~LH^xjB)t+a{!80lsR!O)P9meqE42f^ehNbhYFR@EI#!!ix? z=p=T)KsWTV63OetxUVq))|ns%!0HTt^x%L+1aXWEkpO_P4kkyA_CfXz1!8+;3NsB}^oZy-;o8Yjb?1q-8Am!^CJIpPCyvP86p(0+ z0Il^BQ7n1+SwRqNQII3^)D5fIWnDt_0B#u_378IwaC)a2(F`cYk}=)sY_<%v6Bb)l2f2P);vTL~QoLLr9jrq{r`A>#85M3FuU z96r*2_>0W~{_Bq)ZZbm4N!A|B$=V^jX8m6SH1p?1GVDJtqjCnK&q=6Z*C-23 zXQ2weXANMsTqZ++&Rj~*&{WHok2Zzmd};h^MezLhD*zOMYiBKUMF9kH)ao!F%D19t z^JApn5o;Qd8)J6C056h_)ve?F4hvehyT9ViL%&S)b8<}maE|f<%bnz2{ykyr3p`Qi zzViT}k3gn6N{&A*EU{W%aFdJ1;oW-@JcS%T8 z|E_ecJIYFq7`RT4ce~X^568P_s0W>)%n#{UmG0lLB$_5P&HfuHL8Ho zhoQAzWMx?I_^dP}Wg2%=jlHW3bNG-KD$}EY)JM;Ns6GNalPY$=vmZbW+!aF3DQ#Go zX+0<>XOa0WC%!IPli&W8Ouxb^ZG@@p1u>gL9K`7zz?=|*$7d|Ye`DR4kS%0rzO#?+ zgAbMU*6h>WF6`+UQ%pM`w$}zwBc&-bb`6!E9$#y=_E7%EBS>!}>pE(O^IiqTQgC)C zIpAyDqGhIBcR|nyAuHea>FF*y7%h#xabzq5 zItH>v^uXe#y`jpo_zQr2PTm8(2qWI;yjO$_1vj}2diSF|koRiDc8h5P!6J&)nF4Iv zJ>y`4!aSgHZMMm4VE2eBdXSY!GsH+AC+Cp1PLwcO*b7_XEbcJ^7>p<)4YVlIAyPzW zfV_irq9v*x!c*Wb^eSRd{}LHl_9x>4?5D$_u^f7nHXeAGGUMA?BAo%981opLo zQwn-9FkA-}z%$ktx}GG%E%R)x42gNfk*&yW+%HEnbUlVzM06SB>;uoHk?i1hbyNgf z+!5Y9j2}8E6W+g<7P-v(W8%s##IPLf&l(fNKyIyDbgCP3>l`@=$!9*Zcfj8<3>8?^ zY^IZwo1Wvb=ygcas9@xOx^{_*^q!jFyM=(4egud^%{Jxa1?RO4>jP_T>C?(o&&ue^ zoDkFA*%iFYiY^!|xVgTQm{+&RF@A-WVF}vjG*m^lO!6dd@qE{Di>43w$<@*mbDeEK zI079orf@DHM+ctahUzHHxP=?v{LSyd4b|i*iTN!elPh^Mo&K(Nvnx|(v>TmW8OhM9 zXSn_f-lN(}M>xLsG|}_RrZuS2ep(q@Sx^qloFy!9daf@7t`HgcWm@v}&3C9{5yg+| zIDe2W1w4CrOOu>)dw*Izw(jgsRr-+SCc({vuwaJQyHtT3~`FLk8I(}B39@=N0EItG{(=1 zn^W1t1S>=m+wvXC!=dJf@c>;jFZ7@+l%o^CzEMR>x7 zBCz-9;WLMNA57^A_IHcHtKAOdL`!cMdVP3ldbV)t0y#7DZ+;lfUWl3%FwlTXhWJ_x z$%4o<@t*qJvoL*7uQIo(qp~2KM&f00k;}aP|Bu}n+pqY+V0HhsMidDn#NW zb4^pap&n-)^SC}o#ANL5tx++yfo>*p#U@NpKntEQ-%Tq;WB0O{XgFX>z4KNyS_eYa zh~deV#TA&aR7ofxWMCV*RiF;!x$^<3MWyw8cIlPhtqp0IVU;~QCaqH~d|{EVE`rlQ z(chAU!Xg9 znN@|cX^F`2(>m&0;nk9rmfTSuy>l`ql)4ud(_fL46QBLWNcs{#7U=SeLFHsvp; zOP5+3`W^MWa?Sd@0+{_>-4Af}EbESopxbkuhO7^28ww|icjFMuPsX>$A)cB7|D;z% z%Rq>T!9Q?wbAicqCvHE6RJP?6r}Enyg9aSF;z&#B1M(rlF8jqYT*=t zXCC?P9f9Re?<+*Mf>1$Wg1V<3-SqM?$SX-|Kq%Zgfgf@U4CK8Ou{|yGRn<5T`qr92 zUgp(6ohKK@C~uQWn2`1m@zk)NyG`?U!g07Z%HF6L+RQO0Ai|Bk%qxue{sRKX&XKw} z*U466cJMo=+-DW^s`^uT1>xY1qV`vyxH89TUqu(1%Xk%LWRZjj^V~J+h_5@}ArUIL ztYya+UONGIig8CrcY|g#QAr$*0`-%`qr;D6pw-=Uw^9a+Z9R7;y!-=PA;x{}{MPf$ zB%pHf?8C1AHWlM5dIKw$f3j8)y6sqYwQXbHQcKf5DBPaiZW7VX^jYdt!Vm2;c?>tT z+*+t4#4&C16MBU5Uj>&%KS)Jh@kf+rN8)wwTF1m}+o4m_eta zB2D`qDvQBy6$$D&`L9CCU2^=ua$Jngx~DY8Gp)bBoAR1CoMmZSTAWpg?Z@ZiqQtY@K6vm?Gk@j`X2aXx z&so=I%Jnf|UMIj}k`ISonEE=}uGwaxL<6FWR!SImVL!<@mDm6=CT4J^R>W9oH|=al zvybK@L9qP)p=N(kzzf+&xL4axw3yua6g1XjS|BaP1h+iduKBZd_N&9}@|X&9eT0n# zya2Xoa{)+`aT`D%nAfdqi{|*MjgIzSwFrqv>)aB^v66FIquePSN+Ot>^%8V>>c{y< zFQhUiU3U7@Z$5np_wD}sz4LFO%uIO*8is*5hcr^2mTX>+(6h$xc1`dzX(f9-HRQqs@fKE74K?v33uS{ynL|4mASEl8DVWVHqxEK23S-D3a~riXPy+u^mbx0 zUXW-zh>L5;wzrs>mXQ`ZGikry(s@1O*c?PXEc=EGh&e^#5hr zh#gG&!DUK%D<%{5Xq!L&G7@jMv2ScIrj^6_D^4fmFj+L_c#a8LT@NXif`o!3VMlMq zzZN)|q}Jgu+Ldl)sW`upC7z8jz0=|6hcVjaua88+2t(Cwb}lpA7W!S|RLPf0XU`}s z=)M#0tZjWt7n`5Ql4ML6(klvgeCfo|25ss8>3#lP+zd^+$M)t_=Bq{RXH{iL?i-VZeR@RRl03a+$Zeeht`^6f3SRzhwHkh23S9g`nbAhvQ* zdsr1Rb_n4|B64Q`$}`dLGO6Tu7M#xcq(pmRvOKidN}=HID1%l$J|{=Qc&}gCeDqg? zKXZhCzxkU^PPyhYRMAdq47*uXTBZ4y#za=`ja3tZ~fN zGNW_z^F;wkmHpv|S^i|B{oiH}Ny04wDUGb9!tYZG3m2^nFML>T6|oZHwm#}|xUk>y zR#z9jNLaJwk8WH*tvZ~VIc$D@_S-hHHbQ6Cm^hkqCUd&igW3FbEXYvyN<#F`zo^TH zHePgL?69A?SJav0$k}euX=lg2ZIo~Tr-yhZE%=dWYa z_fiU3_YO5~+S!-6{?=Bzry7}yP1;!Y_c@Mm5q)u~^CI8(kZQY;qimBsC{zHH(t^a# z8)LH_tOwvoE}S>v5!r`f8IOC@*=hH)1lK5!1>*)b$&A36a)=y(%BTd>0QdJ^Ya{RQ zOn0bE?)?4A6BtF~mBKiXS|4110v41%Z+zBuDYf^%x{Uu%hfZ|yFf&Q%w9}M~P~6)M zy!Sv0C~0jLstdcRuVLDp^R6rwa4jw4lp2&9cq~UQv|BWAui#VN!Zk~Ul;AF*)`D3Ll%D;M6JdoD>74E8U_SS{ z-hXc^9seZ$&BLM#_c56|Gdo9CTE=JNI&a0mrl<+{M@u>Fc(NpAA2{ds2e=w$*4Om~ zG%Hoh6iNNg>u#x|1IY+!(pWwuu?!w|X}Gczqe_>RHew{;cYyEI|NM*s4)Soku{)e55RhwJ@I*mdyvhM*YoCFqx1iq!|Ohj*MlF7F7v$%v4qy^cTc{-*w$WxurMy z3VR3F()H;pMh2ZvJ}m`zZXice|DF|dhp%jBO-=6??vllL4X z2!4=%Tnu4Ir5EPn`KleXO~?U>wAY{9O5Ug9OIQNN;2I1*7sQOw%Vv z{Vn)sW5~a|;MW<8ohufcP2ng|0e|&<9p<8a(hlnEskua4Kp2W4gqD8xEb$DAkhRz* zi{x}AKa-x%jbU)B4@>2<+R zI_v55ZkO0_`&hfmpP-*yLPr+M+|IR;R4!iO+`41!f_qiGX0mFUOSB(wtcfO!aYs5vaIDOjECow zNRL?kz{#{A9kCU{HhQj%gZt#~qr|6)c<{>!tP5(fx_w57X#qyMk{+8%Lpx4wt8$zQYbl)`UsEx?1$o5z00wig~O_3 z+~>$K4(B1~$nU9-z{WeqLe$4aiKhszdid}W#I|Yz2V|GKf5a^P+yXPrNRIq2_B`|& zh+|roM}ZQ5Ddl}d@M20bPvyaIXQF^Ft<5qdzs5MxBwG2c@7hQFBdzSeBP zwEVQa=(KyCP*{#7r_j~Ue}bO>ZqCNL_2`TRvLb@2WTqij9N6l3%Z%^5$=qZ%w`&Ocuk3o(V0$Cday4OV+ zo}-Cjhhhjl1)AkmzRu)`PH?k;-i&X&9B&0>z<ur#Q&NyIfQt{Pa|8vO)UAkk`sv}Z*4czmEp7t$7Ow@u;Hb< zwK3mu$px!@0t@cHj56pbS$A835HYFtXp|LBstFdB@^f3iw)Kugh~rZHRv-bAtij1K zk{VgLkZ2m<99vyoG^u!e2PW4k{v>3C#fCA)peV`l$JIai*#GXFo8&FS`EFLUM%(_V z(3`p{SZDwNvOat}PNWnvzEETm%vH!ioRV#Rt+9guX5dxv#5%<>SMKnHFy~7==k>_Gg<7{>S_saYNc{> zn0wQ0T@P{1-b6W;3AZE%0ldE_r-~+C_a|gOj<>pQg?-+fxo(!$F2(k98{|oVS5HyA z|4Np$d;(QN>9X$60*jxFHU!$PZ$D{TGzD(U=HY8v=MUFwk>TZ>D{jqZJ;Ith#6qCj zJ8$PqWjQdRj=jmlC2wWM5Oj3FksBlu zP*@ab=NzmD84tGZBz8QSu6N)D3pudlLMu^c>!WRr#xI6tZO)7t<$F;7FTB zPPX{E0A_fqDa~^a)uncj{hK}!K+$PySl9O&6yjC%lf%g>{Re7 zTzrHaU~Eu(WulW^F%=IO8*5cFMcWaC%uM$-Ly(W)yifJyWSY*7oHl)vkfp{dFQC|m z_(7LVJ3CRXHEsiypsCat9dd+Y8L4C9yFmb222oI|M_KdY#S2MkX%A1&fr7}bW*4ahZw!2>YYDX#~BCzDdyea3Vfk&tDV0IA$v*W-p8rt<2rc(SE82tMJ#`7T>dMrXT|?XJ+JN|atj)$=X?hFtU;SFDe-2~&cOzFFKs4%A zPKI-fHtCM^y>%)rOG`^%zFh6FedPP{*$MWvi+oiES41bC^+CELFY_jW(W+cMr$x=! zj-0T3p=zya6cp~%`<;XMQyhyw+?tb0<1~X{L&i;8_U_$Vaksp@yf^BA{(!RKv&kn} z7EH8qa&i^NghfQAYS|i!nP@j}+G%v*L!Rv}6eRcCwvywltDQD664azBjRD*(Ed0c; zTCjUE&|%^lA*X0?aIm~w(sAC69X-LZo$B_TJ9pZDP$?#c>ZK7Hj(ydp*?D8A2iohw zWGGg>MW}zpbUKjbNltcNue7ZYlHy9{?K}knqjB7#f~j9&GJa1_&-U%xE4WfqQ*HM1 zicV}90Neq7K_1me%u3k)WWM~nhaThrqpQR*MT`xJKamv$lb0qYCUR?dbx%P#!1Gyp zsCA|-HNxKdy;aExD5~`|R(j1jISK$F19ctnTG-(&lc@JxME2Z1U0vPDS|xW-IvE*w z=zu$zVTcVjHs8nY?(QBn9Vv3|a*INml(Lwyv0`?pkdt6&>*vpx&G61ONZ_JsR#g3adZE5y%na{6TqzwGdC;H%=u<5q7m=n=}6e^ZQSd%Yw3BDK$NudIIf2k12jvTX&5ClT*+KS6{^f5aj2UXri<_Em zb{KtNV`OBUx~C2gCQb@Bx_fwV4a4o)#FW+7%coX=R;AX4MqdvM3p3&xY@i8Bo`h`| zD_aPQnyWBVM9I#C5WFf2=B>QA7itaI867r+X6^CAXPy5<-L6~k0{1?WgOxpMuMw99 z+G{bEbJ9{1m#-dLJA1-7V|{42@d6>>ke9ST{u%D!dzQmXM&o`sS6>{e1uCaIlOwC) zpyJsmc)aBZbryb^f(MiHYym&KdPjJ@j~ro0xOMyXZ36@5yr37Jo&hJ^m{VV06@B6E z-WQd`Oa-?0Jj-2|3UOY=)Y=%1&-BZDhCb$}`$rNb*g4%;_*-fHdE-n60|Nui-7AjO zeyH88r>8e1EZ`>)5aMPoQ)^e}6nFgv+_a5^Ez@$2O&J_p)(H04ks*~JB_C5CzRubu z`Vr=WH}s_^LS-}-Vn->nRc)Entz~z5S+>TX7^0rEY>bN2PZtYPq8jS7vG{t4SuESX zpRMn5?N)BSpG%e&o!uu4>vFRvt8}ik3FfBSo+28PzgqvCApSorrwoEwIoX_A$FJCU zJ6`FVf{BqLu9si^d?tP9@Zq}$4jwpw%oZ-7RF&6^TD<-<9&fIJdudsl+j7|K`s6-d z%Jx(27U36pGfvtaU&(uyI&wQE)!@KE_q(FTB`dg?pIILU-NhR$FANc)0}crI?1{Uv zG2T2(W?Hu7@LluKbo*+zO?s>gmu9b@){C*bIVxPcy!D;mQVUL~Q#iYJ>9d7^rL|ds zZbtpGv4Da=0PP{0{0n(p+=Tb|@;s`H zd|LV9QEvU4$jj!V$-PYG(bnfL(3HT1!L?K#dcqlENa+@)pd5dhPBDr@=y>}~ZcAUk zhP13HckH5?k?HKROlgj{dB4qcc5Zf4#=RQKY!@9l{?hiFxXNfBW3HPc1Hr5dBg`W4 zTH;0v1E#}Efbrt8K7wRIz#PocW>{@NQa zz$j3iuo=n@CS*QfM(V$VX-xAv9tIZzh=%k6wSx z_cbE&P-H-mpHZLs-JV?hH!3j26q-vRXS8-!kJA(wMdp)7P%tbYQI%Qd&EucK9Z%~`ZX6q3$1T0W6W&P{?*s3S zLIrHd(yYhQxvFa8kM_@5L?^ztCU7Rd=J;|9jNsh{zNvjdl8>J}d9pMcQ2H>I{|SEJ z?XX+6SE_owtezjpi+|xW;q3R`jw$i9cBhScO>6BWmcG2@^;F$iPk%H*o0X z*$S3xEmx*w{i3g@P-S=4Cj7j!Loet3N1fE7C|TOtO$8D%f>guYSH1xWGO2k5q&+jBDM$AFs?ryfB5(!X06T8Bvw7s#$hown`f6E#fn|{bfuUd3+^W zH9h`c;kByV`Y68gw{=TP_EWgQLH&hPFyKbHz8x;77@HT3@Eu}NKT}~B_h0&odh8Dq zi?fIDB37>+s2ki$A7F+Q>Dlsfw-90RtHEVLrzb%vEX??!y}y7Qzp$|I0e45y;R-EV zPWA+0F*E&{W@;@*$9$W#I$4`-5fKp;3*ypUo2t@V#bs%qf2=6w)+h;Uw7ihVanhgH zDD_ouK@MKJ_|>ad`Wm4@LE=s`bFb|N9iB}}iB8sPO&%!IX*ln{yzjvBLOVXGnYW4W zV}Y$O6i)Tb_ESlafm~J7ot2JeiG8pK4%k5)$2ME-VZxHwC=}WVMC6SL^Bga%Va4~Ihcp54inu<7@ zQYHny+$_yh3*fel8x~P2c*Y>hoArFhpB&=<5uH;&?LjehB1QwSxaa}Zqv3;lm}tQ^ zGn~|}VSVKNqMBy>!ybmQTe`aM=8NAx*vcUDh7YS{YnyGu1Rlpi-}JyF9k+eD-?b`c zwv+RoI~gY4Ebhr>%N{Vgml={WFq#p`rztp$%k1mTF*enEERr&q#@II{RcuJ82~14c z(?{+9eB~5XWZYnf%>b6o!rRX@$$OODX<%pEEwA83PE|U@p|O=jrKo;pu0N^U|6ad( zO&Jo%t5orgm_-`p(@eT*P#T?j_wJppo}Ps0rP@%f>%MAF=jZ1k71{IpCBchuUzV#@ zF!-xD@AavUZ*Rq@#XRNR%zaJ6hDIO@yxVhvhIhF+en2WI$161fobFKPU556&$~!LR zihU=_cH7-FuX0l<>ht9gOX`nG3cFqF&^BqntCjt6cy`X-^*U3u*MTXjeCANe)Jyb+ z;hHx;m{<4b4N2B^)IO|rio5DL=^AYqWPDjgaz!d2bx>i}zoRKPDwmt)G~3CcYMrwV z4f8u_jD9rUcOWVuBX-nmbFf6yMRH7u;P}!Cb)0TbfrGhKSg^5+{ab_`H`-wg=!j^P?Z&o}Y5Qp#3eQ*QB!zL%pR?`@z zKD;hVmjk>@YaH4-#+Vr)SLm#cn&MFDrb%SAjhaszu5BNjkP@|Z@?q(FTYE4*(p0{d ziS0<4>D~g}VQqvZ`5;t(($$EX47mIvo%OBWc>^v2s&;10TfPbmEE!l(0B<`K1t$91 zm2KHl($c4oygtLn*UFduwwFFKgWV!tM~)4m-yHT6BQ`NtlIHL8u~{e%RgG?NF+ZoR zt!?Ah$7+}7ht-hg^}+pB7hW;Mxu}fK9E$h1Rl3lP_tfn%LU})zn1)Ieo++B8G$+%j zM&9FNlLNP{{b8{8%rxA~%?>^R6&sXC22vhErB6j5COxbTs2m1@Jv&IHyP`trAO#{! zaZ;_Is#Mmz<9S|Q+x#mU>LT-n164^U?0fyg40#{scKU^uyQ_kS8VUA&zF(y^#~Y%D zevz{r96kXJk!?*KR%ug4ZC@6{XETG0B?bad*rYiSlkJ-hz*VgfNxwmk39kVzrmED} zXkMUKQC1Y`p5x%CTRQ!%xOi%hq3PHM#yA%&-RUp`!4!9Lw))Hn7`w4Ca{!)}?wv{w zM5&t4bMR=nSIhW;Du%O30}g6MG?{B1$vJaV>Z{Y@;3)rD%HWdT-aAtfufoDAB|ese z4UZ2~0+_bW-hhf6U}{%8;w;Kdcv9P(lqrV;5EANKI#n4i6ds@-2o)fOsyKN7a=GZ* zo|2Q&T(v5W5sCAfLm;=SP1E^r-@XNDegT)F@z#$RHh4`#aVV(D2oNvQxv7_fb4{~? zT%cgT2plRKHCis8iDB@!lbs)H5lze1fQZPurtc<42HrqUpj1)R3D{nk-)8-AVxc|F z5#Q)eT@vu)Kif_Iz4H2a1_d=RHkD>kjQAmeE9~+z35aUp_||X(IkrF_n9+(;8+;uoF4FgfM; zT`dUUzCDMymzQju6^ZH5qkD)if5ot!och9#AS7Ck3k>Jp@H0?WD-w(FKT*TPlo^>{ zvUOT8#-3OLLT(?EjdQv!;IP=#dyultXOVYK4|Yf|p*5kxjyUb>1V>)H*7Q$Xa1%>v zs#fGU$xOtyhcy92;TPSzt_5fHC`rC5k%-WzS&+lyel{%Pl)%_ccVSX8%sV;>VUcSE z0N1;9jvkO_D^(=|o3Xr#-0u=*oz$g1j~%u>CQ~x&Hr3cCG*^p2f0~=~6%QDdv_i*f zj|dj$e*jz*+j9@PWBQHaIml5ewb{Ikj3bXa`92DHexH2;PPJbgJukVZF@bCO4drMr zq*K{A0HjZ_v+0_erZlsvn`)?BPE~F(B-qi9%JM$!e-?b^YY$Lnu|0@z7nJj%k{r2z zU=eM-WH2~ub2Xpc_r;?V><`)v>gX1_r2QoZX{rDrslMO9=c*0)PBZHW7rWsXb(N8U zCK+Ny$sT%U{2>e`_GMrm{yS#2s}Ye^4gPXOLG{3x((~ekWWvB1@MMe6I5;>eHn|TC4M9k! z`-qtQZ)z@Qq9vAu$vadftLGwNo&!LLZre8Ow6m_Ru3~reyLW)dv$3*9DwVmi?XQLX zblk6|@7H#?-;W+VYF8J4#(0bb>Un!e9Qgk4$;-32pocPk13kutP$~IoK~GOVR0Z)5 zg!KI;Zo;&Y6}7g_C&k8S=;*50tzyzOZ{F13sRSC>FO_86#`>=AyM!j^*|TTiJbyBa zt!Us!q%yChUP|?54chP_woDnDr-BW0`*>+!V`X`H@Pdep=1`q2Az(X!X9Rod_7_E7)H#5*vAiJ4sO~qh4LS!6bq= zVctv)n{co4%n1L=vcgdMd8+dP)ogiZ^IDd-&Jg?(l&zi@cYO(;I*U4{NG{|YO*Ggf zs1W8^ux_9#+}JXVfX;R)=R1|dU69U#Y8|5wAx}nWPBR;~KRD<1Zj<@R?dHr(n*^kj zYVIq>&zLGYCMo6&eES)&o6^rbeo~g#ydyh0YV?l9RtEpKb$F${Vv2T3c20xX$^gI4 z1`FRiT3T;y?wXr_47sCH&Te%|nR$MUoy{V^o3rh`Rz-M^fw6j4;3pSoO=jMSaW?e=euqF* zMbJo{^kl7tPF`D;`Lq6;Lzjd6BB!n>W7XM8j)+YeKy@K0@f_vb+_UY4x%jAl4^Asb zIICt>!_Hil$SGqD+{D9o9OV+4Dn;%F@gNXI2`rsOqjjg0LRl9aSQ`BtrEKo%6r^z4 zjeoDh?gf$@>DJ^m(D)K{yNr#Vi$JS6Z^5_%!#-3Q0az@_F=oRKb73|B$<3eTnyYVB z8x&N$5Ll8Z|3ufJhW~Ga6|oE9qX9=CbHBqdi~Ba)78v`|H}dH>StWTUKA6C1vGwl2 z{F7nvXGJJD#U)SX1ev=SMFPIBm2^7lj;eX*$jRLi8&uCbovaAIcEM;iz#t~aH-1Fe zBLAL3cu$LwI`7rgrsbSLdkOEEaLqZ{tp`e+G#lgN$Cc7m+L>sfr_0jpi^ZSqxBqSf zwxCK# zBfuxVS0ll&ieVy>52g=^9VmefD$hutbPKy(@_De*;pV)$I!;@hvF?8IV20KWhN-C1 zvQxuD{pVTwXcZ?8>*Vpt>#S}JY4cQqDsxWc&*U5Gm$U2`C>WUFEfCFS1MpuzbIvqT zKOoCA{|%;jZefD1e}0bYy6`O2YXHXzN_M7gMey%piIY>{j}Q7SUuA7}_1%fx^>~lt zjcXTJb((WsAs0{awo6MF;2smtPUScP$#BIc3H2K~F?`Amd_7dW)0q}!9oT;CotU^& z;o9B-im%%~RJQxeyLne2YY{JhY+ps5IzBiRSt`qjhNTN!ZY2iB?XodvD*}C$;^I!( z91k61cDdP|bUzId-*8*urfve8WVNq$gVw);>emkv1aDLnqDD5P#ud6SzHiCJW8gfKxL1hhV!*;a|cg3=}&9* zI{W3f9Ua+w0_042gM`Wgxw&rx{5_w#WFMQ;$Q0U}{@10M%Z=g; z*duTJ%^Xx`WGSn~#LF2R1*8S53sLx)eyn)&Yp4`h$J97Pl&UH&UhwBm9BF`5=lpQR zgR+iNU4{E1Q+8_jQH$XT7S)8&eV&a%7ecM_Akrhfcu3 z-Pwn>;a3*!1S|REeteaCt;#UlFO>Vj!HRy4^dop=#0}h2L@Cl$*EUVP7%N*|Rr1{J6^4*`w8lWHYp$5NXBaSw=PNU-q%c zCi+XU5Np1{7VjwW$@Zq6Di_Xl7H`$sKf zcfSUe}?)vwZ*dN)bd*F~g zib7eaYuJyi2Nz@$6TK%bIXU?ZkY6mrBEOnv-ig`pFiQHJjS?Z^O3VG4kuqCebEwP% z?5Z78H~cYOAYkvPN66p{N6`a$l1pszm_9f`(U@Ffb{K z*84->!HvywG3^(dJ?3rh+mB6Aw$*k_knqg;kWQs=Kxy$pM^^%iQu~I06GL{dG;`r7=n_p{W8{x}PBBPzlg1IY@yp#?hk$Ri=ZLp{GIVdwXskUKBV z`Wd)ta5*JML{~(exQ=ZPA1r9%M3XxL?pBv1(*gO4OwS)Y8T1 zuBZCoJ3qFXJ{)=**to>MO~o@M zwQH8oD}9`V7^NLG$4)>qwp!`{Sz*_+IKHpi#Dv)~p)!dz@HpsTg7^AtAWQWoBpG*> zugqFEf~)9Q$cDQvJ^CIvIRhiSthUulEf#TkA$Ok48tkx>u2tx5%!Ybwz?EpHUT*wH z@PBq&@8&h%s-Z~eP4usJxt758Il{~8fx72%WB{<2`mkT|;Op{l+=E8z@dha=slJf| zZvT(H_l#>Y+ulIq;K%E>4+3XKu|!WcO4y3P$D8-ibxGz zdX0`ED!l}xE4?FxPy!@(?O6UY_c%k&r~Bdh;hf*`_`cci-fOS^JnOKcM0J{e?xkmM zw|JN&T|*d{GKijx6qjqkZRid2s|XQ$u=lf?qji~}^DW$#y7OVwyTMB_{N<;_Nqpdv zoE`Lipdev*2=}`p?}Jl&tR35!)`_v-pHl1CExZ^KQdAI(b?iQ2rEyl5)SuU)9FQNk?SNLOOvD0PA1o+WvFV@b^@DchMRu zbo^KHO!5msUgR+e6e(114T|?K>TZ|h0GE7k4S|(qYifjkVyM@13M2h7ugItZ_xb}s zo9!YVT8EJOtNZ;+tRO&}E_gWR7gJhWTf49-%5%{w{nYOT!|g2dhAgp+SV}r*ZygmO zJon5^!)Ze?`fWT_6I%Wt34@MYJt_^sQiqxmh>z55#8~PV@I0xIW<{MbN+qRG`;ZY4 z5pmY1$Ww#}m@BL@hbO~^no-4u;RG(-i~f}!<)frB%ICwI06FK8nj*o7xL+df0CP%z z2SVt-pf~q3nBqQKINV+aX?KJXN6B&ul6JOK1pZ_AP2lEW~TdiTTU=i0lVb@CP7X5kOY` z48I8)iHMR5&=Ju~U(?J}nx<4XO6fCN!>L7mBEstkfFPFK&sKBL5!?w#-zmALY!0}Z{PXM&>|}YNl=lHyw(#k#0Fc9{i!fb+GtvA0Q@h(y&p)4B8 z?xtzVG*lG;T+5Zy(Xw?ip#cxqp@K{D4s>d!;dOd-E-lH;(u(6M@wplnuc0=SncEjN zNHFh4WryNH?qa5cb=h`Skujd}0oQ)LFMLix{3CQ!K3j|~Oi_~z^&gjf1;Ih)&S6t< zpNT?yiGWtB^m=xKk!!Yi9>^aoB&lP@xZXkM#xo=vNG%C_1|Gf(i!hCCg=UA$O11n= z;Kf$1+G+E&$Yf8YX({}y$9X|;0-Ot3dn@W?;Cq!;o`|;#(R4d;P+YuabH^FQc}311 z6>ZOLgBqmO`r6lCI2Ab;=Ms9)(;zfhjIUsaFh)?DL z-Hki>j4xc+E>Jvi;%?T!$+Us2+w3^Vz-I+Na`T4x+H_~)wEwBN=3V9nmNB0F#0C~K z)5%7|y+=0fJj|o7Kzd!Z`~E|1wHTIn%Fu)*qbTlmjk`{)Uq#z_TX>lYjoKMMN%Vi) zYX8`+MURBLHff$)sZ=*7Xp=;bcQ%us5^^rAGh{$j)`*S)ai8!Gg4w{IlCsqWyMJ9v zcb@NyLO)q(=@bt7to@TzCw99OH7Jo zcwoc_3jpe_5}Imr*(qS`;29m{KAjH|(?{GvYp;LCOBnf>m;V{fjfkMEr2k-Hq)I=)2|YVjzyh!(fKH{b zNhrg#zEhIHg z?KeGt{z-F`(4MD$@WV<-nG$(EMmx^RHQSDV@_FW8wO&W$7arZAfx&8|Fk|KH$8G=I zSl4|~oZofQ#LEZk8#YYWG(kYY7@tqGWC#Ss3m>DQQXY>eeXw!;frDIUYZE0-8#mwa z#{Rl--x|Vz^rd)M#4SIQn+G1s;UXOB_;!KG92_;@Y54#p&4%02VM0oxKQ^N7ROo1s z_}sIXa%^Rl_Vfm~I$#5KBorD+o~%w06cGs=r@n(ew;o3W?R7g5 z)WPp+t;9m~EnSeJx(gibiq7NEWq*isN4RztbUN@knEr9dWrP%WP9bCDZIElpz{kA1 z;Qe-M{N86u2G+AffPXP-2y%n{vyaJnAp?GkyHl%z7DGo>Rnb@=o#@3MksgsDD`xGDPj za$#)Sva8rp)%2F#igbWsaH!tl*er2D=4KBk_JE)TLc=}aGer($4n z6Ry$%q)|S%E|%3oupuf+*vXI`?gyt$%a{bjZQ`)pOsMXN<`yfx7!X1JN{B}OCg<#Z z8rw&UVzhU(`>o%3|3YoUy_hQxrt3p&YZcs-f(t4oENlvh#)9Ym1mVwD5d zrY{EvRw_0&;C@oF_qsFCQgc91(1u!2Rocf5t3_L^Y#wI!lljf5PK$nc-XzSl-&}Cf z5!!u5#JG~0^Aw;=zQH`#TyU_0BP2Y$(t5Todj4b?|FEKC-s@)@!D~~Sevq2b7MrD; z|GX%X9oIMu6lnk?g=j?_nqqB9jG;X}_b<3dhdx%#2D^hz?vHyXTFi4a+6yZFrpWz5 zM(ntp2^=^G#@qCPM}~#qcH1R}ix%)mK3sRp@05{)L(ZI|2~>Qn+n<~>&V8u->=J#Y zfD7q9DxP-KTV9zCzWdK8c<=e7QHGGN%5=3IL2Jy2?0Mm074eXR-iRBher-33R_g2r ztM~F5dw6(&eJegBC|H}UVQp?lu%R~*bKQVO6jA8#$(_aT{e@>S*JVCh-aMv0b-UQR z>_ZZ|ht3)A-1sm@F;|?h5IdIipsRKjolWP7#ztxcp@PAcrg>f~*b;$yLlGN_la!_K z!GqVR1#(OhF1xKyg4*^`EVL9+cCii-xm2PYeq>W6CxV;x>Le8eZZJ^DRH<_n5~-oL zk^bfmWJ#AxG*TF8`W;aIYIC2^UifwPOt|P&%>ne-=uZG5WFa!TwNua_8YZBb#7Js` zLZo+a9`yv82C1Vr_s9!=@;Vbz0 zjH^y4dLu%Et408;tqsZEVjCltiW^#norm9Y5f3lYL!{}NdWf}Oy?TYPE1X&%&{~1| z0kI7;O4neG;K}#vt$}|Bbt8YkeuzVaGI+BpI2dSIsbZ8%BA1RcOi(4m@lHOMdR}P@ z^pg-`Br#V3FoHx%0M6~@7Z}~g5mnU_3OJ+EsG8Hx)V71()tdE{P~v=p5+nMyWCn32 z067TI&7Q;-GUsguj<+^suM?Wx$BaDIWivttX(U9)J7gi&97HYnat0&%nKef!k-m9P z5Zn59T>t;ve0^mVG!1G#{j#_c<~%{>FAN56B!L#$V^wxA16JF}KM$yYES`T|9M3F9 z^aGvJ=Rl$~V#dQ*2r?jr&v&6x9Pzq49#$E)g;GKIm6>8NrgLHzQdPz7}Z#C>`hB+(stgah4#K!UJFLgw6V;Lzw@$ zwqlf-KRXu-R2>>OXL8xbCDA?WV@iGwRFbI?I}+(BTHW=G_=`sCf#5HFOOYxWcoW_{ zox_xi9k_ZG9folaP%}${i{VkTk`WvJ{uUUCVwC!ymJL%4u53rP2Y-_176WS5UrbN>l^KdoQK zPzjUlRKhsmRCHDWmm#jVmJaipy-_&?w3e{oWGw4vRlYBsSCj`HFklE=rb=Q8 zs{juqG2+)mNW2Zu37r^xBS;ORM|w?GM@c`)8n!FD=z_RP1rSU@ky|Dh(fR{+K#Y%Q z&2|AND6LW5Ihp(YR>X!xH%otL00OD6U(S$`lGkZx=z=EJc&H;V8QTogq7~$Wp~p!> zYNc8`P+%{_EPL(-y*sC1aUd;CS%yW(A?b`93vNTYPw9>3{A06A;$xK@ctv%8qq-SPlyS4 zfp0*a5fu@LirPspsBs7&h>Fx}Fux~z%1{i6X@x-83n;qZrWolF!R*UG9JL*t4X|~d zP!T@$6Xqw%bZt9vydV)SQV3#F{E5N{CgJ)9#QkOQhL8v|1rQTm6%(fGFtDov8NC_V z$7(3mkvp>Jniy?%9^#heD~o_uaG-^UIvb$Iiy9fWuE8At1V}v~3P&~uQh<*|!JnX_QSTrkXY!LX9NbR>l4ryhF=BytOd;DmM~g!=aa>ytKd%4jdLZQ2{z8a5Pg)Z)Fx+!-487VC zJed)-BUq?uXT$Y-ycv`A+7U;Mrep`UJYI{1Q8>##4`B%*dn;hUPU5>B_m!z#4DpkRn)}pC7NEE>TjARHtoIqtG<)58nP@H(}7AD;WMgVjouJL|d^g`0OvpOR| z&()jzJv;^xJ@~onYN%og6HRObG3jIUCgQYbnc%ln5PB+M;?S~7=+EyX%5iy5_gE$7 z-S$AbglPJYuP`b`H2o+JCzPq7X(lj7|~jYE!+_Ckn@UIII;m(d5;jGRoC^pf#I9p z*F`9)qQJzGxs8Z195A%YYM#0tHVos6kcX{{S=N29Z=EtqM;MFFgpHV^biTG&SD9kz8yhtwHa|6^6d8;hA+ZC zYKF>cq8Txet3X5>Out^=04^Pkt_Z{MLt&njX5`lq6bl%!&v``1hju}`jn>6lN+5DwT9IErCZ2^)RDIgUa=c5nMH9*cisifb?c5ZBC#M>5(pQ1s_E$ z0W&c9Dy-TA*cpk|@r8i>)`rill#vN!1h`|=ey&7(9wnudZ^#Y9nNk7lDVBu+vg~6_ zUI3Y`K+S;M%8p3LT>&LLr(Jf9kqeZZx!N-l75p{Fo=4k5LJ%A+RC5=5jS-22pYUAh zqag!Fze}2aF+;q%SE8Wv4E1fi;~6+($VsIFI2olRx7uSCd*R5rx6W0f zktRc7olv5mnFx}0aRm=};pqj2(qLEeV9$^{vNtTs5s}}+xky8z17PfVU?#TSz^oYM zYN3G`m$=)_peah7qz+^vZ?5;OB5ZGDM0d(6BPwHPW(@pFG;VD@GX!{NcW4o#_Fgq+LU&{OY}E|`D8 zqq;A<3S~;lgRUaV=(GWg%b;+f%WeT>h74DWGBj|f_Ov_&QnRNa{P z{3Ntlp;-wsY*sK&eA!*Q7=A}+WrGy&G{PtEZIMl+rb6AM01Er`*Oi-n$v=iR&_Tt37a{$7!?B<7Q~ZlSb&m*lt51f5Z58&s+YH!)<<9`25KF5C5N}-r znl#~f{&XTa87}DV&gWB>6`jgwVYK72tvlv<93%A77^8Yd{1HsLIU`$+d7s6I-+z2`+pfLN}r$g|8M*Mdp0WlZ~ng`?KSIY3sbaw z%7o`kYBj6mxh*p?)bSfb#4$=!8%O$l1uzX6G5uH{_A{6{s|nR=uGIOO5$Lr zN53KMakVQm=I_&le~7q^+DRo>&%u-NQ@xyNo(sMAi!Ng@UCV_kv~+WOIzNR+lfVA> z{Lh%*rI)EAqNKk5cvc^0BK^nJF&N5nd!}pl(q_v!V};Z5<2>iXJr`}I$Jb)6mn=8_ z&U#0nipeatjz1bJ%Au4QcDyNM!bB}Q^JPgw`(8lWVnNC6oNJQlCzW6@%g@ENE(}MK z>IsXd%xjWT=%3C5pAKVDmlaUg9HoEyku?0bPyZQnec3aXvTDA5I<|Q7^QU7lQH13N z6{Az=(_N;1yZrUj=T~3`1eR+^Bo@DZdi_57sV|tqr~5AV)6ddBT}40-cCQM)BeL^X zjBMv}8S&2!!xf37jyfvEkLjZ~%~@hFQ#{L+*h=a|kSIKQ=G%`mVPs{HJzt=;<`;H~ zC%GC<&8s#C&0ibOwmo(2#Sw+m8OMLt8}-}nvLb%tRrWn<*&Dbt<)VLGwPuHK&8Myn zYgYbpTj4J2g}GmL%U$G&*`c&YlRfd)e^yxa$gLAAceYvAeb}b@QpAhQir@%eL(`G| z{<*mU-a}G-B><%8>Srr1DkhYq7o6T^QFG@CoL)6>a)gro(H9bLvmMPi~^QA zF&tSJ8|uCg3zOhlUA@Z^o$$v6xq*tf z3_f&MLeuIeOeh-ae5kXR$(l&AKlAmcnJ`A=W&iZt*Pni7)(G$Ey^qnck1LsogH)(}X?QYQl}K!xbID6f^uj!_lCr+W#!~i*FtHa#YFs zM6~9#6_<+kb-Ia6#1{wMc9FABxMS}y%(c3+TXz$s$hgC}Cmpao zft|mJFP)I1gNDNgf1AB71#{9>FtX~v`81F`j$8ORQZK{LacD2`1?7C#{?>pYBmFi~ z*yV1s$-Gq+dy4sjWZIoeXdPWrXI)rkI-D2Yx;{F4doQJp^zlIu~g zrApHW&Hi5hbvilhh(@NPaII6L(9=#Lb{c{N<0F)7Wq z6*Aa{RAGV;-%>#Gk2OKfks#Xaxs0o462s1zojv=gV6(84%{H9XbDT=};e*uaxUPWw z^TZ4;?vkn54$)QDF8;J~;zhZtJEbd)O=hvYTeU-dYLv6FImPkh)=h^}_`;W{?SJ~+ zjh)SEe7YJ+iFv);UNshzKJNX@V*&<&VnY|J`Q<5N^OwqaE=cH@bhwYsEec$rQ0^9b zOUuaLCwI8a;i~mHW&90!IhLmD|KW%MQKFPc)S%k@k`2;1PMb_Ki=>)Qgk~lA$y?7a zgfL4x%_VMi!X!1pS4z82G=YXHa$4O&ghNn1RvZ^xx?CX@SMc^yvk(sO+6?Xno)?*7Xv?otn8*x?!>P1^J8)cqJzOL?Rx;MA% zUrG=z?VcwrT&A){HCIV5)?Zjj!X3*Kr;MVDmUiNDc+0afk{Q-%CcED@c!gbV`^`e> zLC;G)wXNQwvDvR(tiul<2<{Z^TgrC$&$}pl4%+SFKvy8SnNZ7Wd>f(1YT23BUl}e| zj0yhulndv!_)5Q2ul{WR{CK#y%?^TV#nQpg|Na9}(~EvGkK0}3Cr+>nPYzhl8@|tS zy{hfI57RRHp*P;wO3$$9NQ%9Af}=~80&IV|9_u_FP?8pzm*iA#+6XdxS7x+woL7k9wGV^HZW=Dm9-s*grxE5$(Vbtw z)NG3^nH^TwYuu35T2YYKFIuneKPUJ1O#BZmWzq~mLI3{p))=gZ#|LV3Ym>c2 zc>z=P;$B`BjA*@U+LSvINC}-Lo$9l+=+vd@lYh|AU(eG7bdzy$E{A(bDqPobcjMog z*I>%K>Nk42!w+?tBoEh}9-nHs=y9WPX#?CpsXyS<$%}ES*$IvVSVHZo>4FoYX>(Jh zhW#)K+PQeXg#?1hVQr!hx2Ra0V(H;uxU}_e882r+FCS^qu_G6pz!r}dYg4X0#-y)v zU>g%hyX}~nn$e+`=9Vo(sMcrnit3Q#c=taZC*%(F+jF(&cvOc;*gn9dM@v(KIwM-1 zr8+4lZ5h^WtvrHVrlTXv45qm2Vb_Zx2g`+ut!uH&5%Zd?Y?#oGa4WgTiZh)w(HrMM zGxRtXmNP2ZNjgInDN;pvf2mwIBz7eBi!xZnO9-%PfZXO9PCJ;UA-w5UC)g?sta!~+aP|Hi1fWG?lZkQ z<0*2TsY77f3z;2zA7i3kNV^SA&@bRs&7i_7H;Nd2E#=%?U#7!aELhg^35@K@V`8}K*hBA3wt@ar7;|t8Pm+uFB`Rve> zUp_l1b?CV*;T@V1Jzmry1KPh-89ZMZ>7Y)U=CWNnu=mJP=?JSeNr459meD3F(vFF( z!Q2@PZ<<$?ba0)p&=$5aI)M8rX=!)Dzu&8L@sq0O4(BeK$(fxJE^w|y3SJN+d(pL{ zO{~q;Y{FMtc&@ZWk|SA-QPJNEzP|JM{+n{D^cQ;xNJTJVuFtmo?0k=$jBF|Hmn1(% zPyV-a;K)XE#;^OhBB?Gy)G@+oWV*{;6sze=}6Y>d(eo@;Woln4sUFl#-1q8%xfZK6NX6)!Gx zl?J*M`@7cPCOrSELHIotBC!p{xp*FstUsyGhsYn5adc;knz(85ew+-Ay(gv9eDj*yaczsI)qTOKmzYmZ8VF>!o zq0vdbA1Q{eXnh=I*3csihKIJB!5+wCi&HjnsHtq-RADUtx8X=X%ny7uB1ia8>^=2f z1F1XZxf@nw2wFDq9K&ZsWUKS~_I%_yxXdX3tMBsrgYtO?_I6?7-7>3Asl0t@-OL5= zpNw+)Ol;E(?E_obb7Th}qwn-iTrdCHrIDlE9&E;p!C?8m*&C^j5LBDe-k@$D^{p zkBF{$K! zU4*(Y&r&+zhnxhg;s5Z?u82$yOpdt2|)rlul(Zu1AW5a zZiH#~GgZ8t;2qy{;-Ln*gc-YjVf27P&;dya(GRGpm#Lz%Y>vHDc-0Dc@s7nt2{olp;(XzlGsO{!6=J>3n=*J>o(p- zS?ljw2bS@|J72c3cmh7wxmQY-*Db5t@4{n6;(}*^@{&;={~o-u*g&#ugZ}5`1z69#T2(j6U`JN@fz*Kxkv;XbY&{_?SXjM@RMwo)m=9`TQ$ z0N)Oetg!M`rEu>(5djVfa>Z^Wo@ev|2iQZL45^;z^(cR3V8(XUb_6USq$DnU3W3C4 zS=?=g*VqU*HJTaXcPq#;7gYh=QVeAZCi>lI#m-kOHZgeJj7-8&hTw)*B-O;=Jlj>F z;u$4FL267WgfeWZDvX8+$x(^pC42>jc)F_ud-&{QhlJ0zgphr+jBefryTQeh==pGn zg^F^pANpFsW4gc&`2`86XE7(fUW&>1aY^E<=xM$Cax>bkX{*B~TU@S(S&wrvJq>GO zXR1YsL>s&yqiYP9gj@%^yEXWR#nx+jvdNHiLi$g~4$@qbr-T_!EvP}*qcc?uNvwWN zcv&wL5CmRFYp8d+hj`&l8UEx~*%Lx?Wy<7QU-?PA%XJew@NX_0E?6k*pS(m|!=QnC z;jOUVq;}%eblWq?^ctwKrQf6bNOw>%>VJCQCQn!O+6nX$XDO-YlP-`2_gT9~^Qq}E zMx}TT(w4rE?GW!^7LW;Os%PRWgsQ>5Rk0|`YOKY?X!@jl9EwFg299u5iymT)cDhk3 zm`d{wLA6EFRCwud<9}D7=?nW=$Q;FEkgb(7P-IJAhcZPM&V3POuatnL?X~}|ao#EQTT1Q?e-(g3}=R zRL0kqiJ~z5v049_9^om>zJ5r;>fbxnpF`uro!iH#$D(73N=^lBD2Luu!<78k(O_KQ zM7#z|$a+R2rCvMBg_E_NYAA8*%p&#NTYTdEXemY*spDl!GDnp)+p8;IXs&n|8x0&dK-j7y0x81 z%II%HQ5Ui~!J%-_lDAU+HjwXMQwm1SkWJeyu7`&rKt)pjiY*`DaM@pKtf!t|%95}Q z$qj?bua;fTdR%)%Qzg@(mr!tfvMG@+YZ(Dc;i$`bTY2OdpLnYuGzb(pUpJkFf@G@Ncj(=I;lC!AqSbk;l34Hx>4w7 zBn%ZL=il|VF)C}5!4Y|I2K*rbQe9|K$ZNMCg7kwK@ z7?o?6=3ieZIy+(F&hWDGimc^p>wTx%gS0D{4!wnBsKGsLdYISz8>5a*VA*VIn0G`D z?N1fwQb}3=5ocR7L4(*(=puO8ti-703oJuEu#_coTD_gG-xfo6{eiH3mjbp*YiYaM zGOp(u2ub!7G((hwPM~)Z!$NB6T#Vk7jRL#1mOB}?E+3$sWkdUwyqT&ZAZm4xZrK1anYXaNlc{>lnhD} z=r<}lO9f7ctE&utmvFKCVzpo*u#Ou-1yAABcLAk#v+le3OdU(4j``KH&=Vf0*5 zili(Ll+IH(<XO~VO{K=!D5b?=HT=5Q1jKG5}J0{`DQiI?%6ko$-4 zgv@>4pOcvTcIbM32wk{fh;0aDw9Ilf6Y?GEQyEZ6>eZaYsF3G`*w~GmP<)=s@X9`z zhKbw63>c%kj$W1xx2yEMJvi3?)63?mZ@9gs9Z>KFllT(pZp;YX<~98<-$}JIt1XlE z?7KmK8|ostFd_~aL+tY3cGWq7*Yhl7irXantHS4JyK!vX(vNAkPx*HpNrEUHrE<8H z9n2GQ2aJ(o*M55}SKMP^_APfzb$<3!{LOgJqdf%cXUDu)W9wPi*!l_Gkf=-AR0ypX zmEA4RmfKNPb%i>f_&S2hJvY7+7@Vp)Q_DTmce}g06O}3&c?T!z)~ZQfA}<==ew{<@ zfyOTJhrKpPoN?}uIDpT$>hT$#`fnBLkA7y{3&Ai^1W4XnVS$S`H;dT4P%8lpLC0VhO??uDf3mrWdCdyb89TYa| z@^5pS{pe-8esz#Xv`*6 zhU2d0%-B8HtW|soI6p=C&&jja9Z9s-X!4J#_V=eb5jeu#YR6zErrj%4eR|oXq~fhusQcG+4`Ij$lGLstj#rQ@lTwA}oX@BX?&*o)!^wqhcJd43NabN3d;}+~seO$+M4ZaEkaU~9N#tZbSe5$I;|Fb{w7~pf}@>Jy>^{Kt0b-pI)-{b7}nrt4k{1 zv}w~D6~1$ena~-59dEmR`!>GcmNGTi*6^$7VER7jJW26J&xiNgpf(6xG0DZ#U^`)N z&-_UmHu(ItNqII4C#S>Kl}CX?P=oE$!W=2z{A1tYH^4?qCaPUK#Ib{XYv|r!L%zBB z=fxkU_DGd}f+W!;c=;DB=Z_8A0atH%&D9l?IxpC93o~otRU@&mVnbRyE$jTt+Y6;i zhaJb-EPj*FSv#sGxen*ZYAcx=o2TfduM5&Ed>J10c{6!w)Hq4Fl!vx>^Q9M?D)8}- zQ>insyS)NBcc$6`u^F{vzn61M+D!Jm9lFQ0rYV?=MBw;k?=r|{}$)eHX@`nF>nVW>y0lV=N|>I7-+pj-7BwtSgU$|UtJO(Djz7% zq%QdozPA7VO4;MPN{ww|oGK#O+0M2fD1C}|Hg(RL&M1=h$OgHC|MTL-7>WbT<`b>m zq$VkTNi)uA>tJEp@+GVB>{PzKb_gwSw8H%sC8MIK7r%4!mM!mE7mXqa zO$%&ctUAIR1Z94G%j_dI-tX!ntG9zjAxgrA767KQ_Jvw6c_K-!q#D?z?Sqd#3``OdbJ62A5ET+dva?hyl0_Bjd|$qNIXBF$SL5gZGgr~W5|!4T6dH8~ zSg_;$u-3-`Y<>633+TU3COA2RAO07 zrKc%Ps`Fa>Fd?NIdax205ard%6A5^gKzUj+H_8RM^F;@ z#j(QiDiwaDH7r3%>trvCT6-p)Z7KcFNJnvDOBC^AV8xv|!_l^(Bqi=TU3_(RQ7s#X zUES0p)7wYb>z*d5iJ1~-j%mnm(?7qc>DN^|Ho+mP6Mw4WQG{DZLFx7gTZ?MF1)a+d z6$`mn`ftkzcT@HeP2c|Ekv7Mj)A4Lp-(u9G=Hg(r8Hjg{#Syqwm43Zv?9w%y-4`tU z#%*uFNx4!ENJ^e_Pwl;*D&ahN(aI9WZ2F0Yo~O#6;&AyC!+LpljBTZ)Jxqt8@Qtq9 z+48e&1M`)38`B4`PQv_3`1vUE@3w9Bu`S6WWz(Y(YEMdT>k>Bx?ivdT+45(Sc3K<@ zp8xVFwstEn^;uq6Xm^ugz#c5hO$xfTk9hXvE;mBt+XXi>kPr7d&S{5pVc?tV;+H?b z_F}heQR>{~#m1d#yRy!!Xwcri<3)yX*|mBck@K;HW2%KBbMjf!`$EB+Kl(|>TRsfA z?_4-sr>)ryw}+LiNzC9Gd^b;_)OpswAf0G}+e4mClyXnak#YKDw0P0GyJ^*`Rd|+% zlrt4=Nt6e^fsT1FStL9DzHPm|z3bwE`X_kfs*2wdUuu~uwQ6)$(Zrg}6dnC2C$g1W zM7g$w@3*#VhqE!0mRD#Oa6dKFADEhNp;*VF6}FRHS=B#t_SJbak*Y^IX(9^oUS9O;Z~j6yWSiyHiLTPAPT1+b z`=-bFV_s*OwCvlA#ik1Jon_kC=iGB~EwhX#)s3uq5XfwOAH?u9@e{r59v8i|C*Q5} z0!_49WgR6RR?BQ$0#uH9HoF|#z8lKaZmy1z;ry`@%W}CW2uU_h5 z*B|`^6N%O0N8MkHvXdjK2&Q&VTC6{_2%TPaWE%^s63 z1+smsf-xWNqa1rna|4j8(rHlalFjOpK$OQ~u~jNfmHlttZfBJyy+LkQN)z$!wt($r zPpa-Ia3kT3-{+8Atuvw{Torog%+_t@jt^qmoiF>$|Jrw2##^`g@WF!*eZ_{g?R8E} z^t86OZ*?r5^2m-dl*wvj$K7SRIVT;2I;@OLy~|1+bD#~aT4_)0Ba18glu!9CUDC9= z#h@8N$|E(U#Mh0pwA}27yfTlO>Os|5_$%R@Dgv3dQ1)uEVf4%2=M}!oSr7cuAGCXPO$kIP@H?#Kcm{2DdmCZ>&mVi+wbdBTj0K1v76iRnBwHTb`@; z^p1lXLx;RVZu}&~gS}S2#=hfK1rs$zrQ*0+uiXx2Hf)88jEIojg|+Cw@DHc1Uc2m5 z6_HgX8`6EIVhiQ;crg1J)=}(u1?OXOSG|Cad)U}^QT^OIda2c#7yrx(1-r#J^^54e z*5H?02~8?W6FL-fBO%Ojg5rdtlhC1Gn%|=lK7T|&NKmc8t!Kg77*}jTTLsw z6Rx~Zf6}s#=HC92P3D|1R>FZ#bkV4BblB*R#=|%9Qg1!0&26+>Pq}N_Zat8%$ZP4& zPQ3eYyZTctndy)xY>I`(jiXFVO!j!wdjS9flayKFc7k%#%heVj$!Y3r4;zc_ zW~q>g#3XH7b)P9>8z&5U(qe}3v7(VYygrAWvX!q5)I0&r1G7Jgs|L4R18rtkn!Msa zZ~st}916Z`_h-KOsZ4ClwU_KTImy_3A}+dpbE~=I#?_XppjUjTxUz%y_;~7;OZKbTSc6y(soPDIQzjN#tWlw1zhv~t{caG}iYR=x0 z;O5iydS~o3Om~=s8N+LzomQ;3%6@?)QQb%U)^^LsVSP48f2TQy@JKw>-+iLsA-=eM zXLf5wdvU{!wS&hpl#|4;3WX#sj>YvAPdwN~i$;zX7V2D@@3OMkL+}9gbp2<*CRmme zJicxOeVbr6D*5^8D#6Nrf#z?3{#G=JZ|?MGY5Ws^irR_w0bx5iaTqCCHD2}#dB0r` z^gP`<#5Y76eAG=;)p)fzrV>AGXPKW^9D8mwxkaCNQdx3vus**2h2wZfxK+9u^C5QL z6xByLZ&mo~w2306cU#&O3a8Inq=^JOKX*x+3(hw#Xf7Ntk?^#Ux)D9FDtpelx#|z! znz8)sP}+DvjCE343s;Uu(P)HcArBuI$Cl=JPnW)2TFR#SM?*%7^L?HRku1Y|o+YVC z!hEaF{k2j0Z;qyP7)hH(^xg&!#^#et&|Hj6MNz~KeMMr&*u$1loyaU<@2(+Y5>fjt z@a2B`bd{PaS9o)WEwgHaL{(X`{3T5p@BCa<(cqk|oSe$qI*B)xy$dfnI*MM2#8I{n z7uN-7@TZ{9AsZw?;mGLxE<%e;N&gd)1kD;Q7xuU@D*y-*_oo6QB^*(%) z^Yzw>tVc=VnuSTB=C!;k5?ZQH!@FY0cPU3>o!G1ArUvWDa$0I;3F^kCNPAY$ei@Bu zJvo^4^P<697B)SZ4u@(_U;3_B!LEm%NC`QD?O#PryP$s))cbrJO?SpCwjrNt=tgU% zN!WUv6oxhj18&0E9>+l!rxz#ZhDGXD5e?)%9|&?K9K*`|{N=V5b(pLbV;xk&PdfxP zSe1#5?Oark=}1DMJR*80ud&^FaqPogm$JFwIl5S9MhGg7`uqD6MKbq}MYp%Nr@KoJ zh2g<_O5<*ULXze^BLF#m|HsHdS#@F)Y@9xJNYSfcwkq(#4Z~w*wldx@p=Fx>p?@#oKFiPuKnXW&g{#@aQN`MI7@@OOj~j9Je*nrm`j1hbTsWn%x_ zVcTlO;>tfxot1gKV>H+|@+`iR?%8kTRWZ~Yb-xdx#gy$S!&vStafR6SaS0lKYe@B4 zt4+BXcRKgwe>^{2);c!V`RSKL_q)|*Pw?!x5c|;)Lhty1RwvCQA$XGGY(K?QaIRFQ z5f?wEVV4dy&+_4JZJ(hhJLksd%r`zeog^9@9IO!8f4WCLCeWhHLH^W`WuND#sr;5D zyGn_%m5hb4#1>&n6d})t83vikE^5 zM>J@YqgdFCt}aNNGRtn-?y*<{Fe9D+w!4ZG2_%WV_f;k~ZP|hsNjfI_kWk4Zc7YX1 zV74pSj7#(?+RRw3$b>sWIyFD@O<3q<7ve)W9P21=w@SMm7G3;s8%Gb8RQOx|ly3VJ zJZg0yTbr{&(x|wpF4DGr_+eM*YEtL3a51D0h#V8HJ4Ge0EIPGH(KxYBa;Ex)RFU@u zQ-;I|PqplzD=9#nvYT&>eZ z%n9X*dXjU;ztJmP_-A8Zf2~nPYN1?Vjh91N(MOiJX^Wd7%p)VVsj9VOTP)BPILHS} z@ICcVTD@3o75w7NxWu7Dk036Fh|e6NJ82Z%+3dll%y9)o--Ims{xqB+|D?NvcxiXd zlVikH@NtzYB-@u@eI>y9KBQUMygc9wGZ(-Hi?-SLx+cb2nzlRn-mKt~%ovC?VkOJv zL}Zjy>5_z7+DnhNZgf{C8o&}u@h2x{0k`M97CN@R+Xf7#!s^K$Y-XRMMrcUa1l%m` z))=<@L1s`&2_>PbzOooTqGyK^+*nao4GTc7hF<&l97*(rT_ARR7s zl=Mt#Z_1JEh%D*aikN`27Re{#hngmeyZ)239sYDX~|MSvjDoERADMS|Ys554j|*e7iZ$ zOMkHvA3uJCD1!cL#*INh`R^BIde~#ZiELSCRhB;p_4EapOy-y0>AU>kkUUEX%u=VQNYB8=ShZSO_<=k120R4%5VihTI z!L*jplPrC01Cd?(0 zb*SAUUOc{RHaLS+9-W$dw6U~Rn|Pp>9XIn8=5jBMu-+$?a|f??#BPNTFTsAelV%c zPHKyBpTNOk#bK7Z%{VRzEh%sDftZqe4Z)wI{*7f_7XOEh}%JDl{?8Wj@YaX-bsQNZBj#s^`k zyy^|iiPkX(hmY(X{Dr7(-f35EUOv^iz1DcGsyQpMl(#foYe-MQt5QX#BpU+#!oslb zRR7X;4foBNR0>&8-MC|02|d-?^eyST|<~)H6zQqqpQFnY|*mn@Ll6F-^zQ+yV*Aq9wqTtxND-cCFF3bQuv2fdg-c)&-jvm zt_DxLrTqsx;f2lo&A-H6AC=fVdxsT^k^*D@bKpi?0s##8lPsfQjb zlt`(Va2ig(*R{W;y}iw`7}8wxlS4vPE|-sRc}_-LKx1u}>{aIFpstLl1>bj*@lJ5v zdwQK^rja|623zGc)|Ov1_!#AYb-PzlD3m@{Rs~*s&dI`Di6)lr9pJ&VyYLLY89h}z zkQ6?6TU%47MiB|?amg4Nbz=%%T%piEF3BR-*!_jjG46+Sop6#aw3k;G^k&&y#>-LG zCiz5~e~$BFSOZhVtR40JSp6NY%)IZPEw*xcA7dXzd1G%R-xAl7_YC$Eem(*kZ_d6a_g7@lEZ?_V-mEJv_{# zRL7qs-7!>xU%eYSeU5n}7u4S(lH!rqXTYvSKPsfC*P7QxN_kL@~r`$H5 z_oSgUx77)<8MnPukZ;xF5_Hj*#}Rn6&Su9s@$Dx(y@v2&+rw!a<_v`>)3Y>j!jY zyjt*u8JGw%nT1!A42Gl8Bzwf|zGp6XF^WBVO7zF>!m0oK$u zKM>T|Cmm4PL@lq|s{v_tlXww&RWFPvX_7zn0$}F*-@m>eT1*ipTeP)T)se$}q-OfQ zbAV(LP|RuhI~ux{Y$~j~r~6OO>4mQMk#>j~FDX)rAOb~x(&s)DeN?vmr{`J`n1b>i zHTx#@=;}knaR^4`fY>dF9-kicA?$yhI%Q4$Tqpm2#TYw)xgq3YUb7l*FXcV#>gPgz zf2Z~C*QwC`)?cT*{ahU`pDzfo7iz``Z}SRd-T2$vFg zso3}8q{R>8O4G>hM514WnEod0*W~)&^aL-k# z8y<7VIxYE$8oAGBX0$o$)FVJCJlcp_N5HC-CIsxoUD}73VZZ*hjFa=OuLn6g@^AJBr`-noPyEF7{klX+a1T7_SC!CM#{rbZX zNp&OX)>it;II9}$W2=!w==KW@O0*BvJT0gj==)!i-3X30Lf)G^5ZA1&JY}gHMDK+8 z81Jcj?<^#ILgcdofMn|XXTHf@xpDGLV{|;d6br+E4%-wrkGk z-p?7;(!19U;GrGR7IYtBTy#;R_{S^I5VYjEZ>K+*hY%h0^qz+c*eJyg*VwITRaV73 zIFo&F=t~~@w&i6r@>J;lLZBadn-z7V$cAnrbW2U@YYAqo$a2dLPRhEmSJ~{?E754O=b2 z4Lx`Wid1w78?_m*>w8b&HRvt#S712p_YYyd?Zh)WwxyZA6ISpP(o`2>!~tdaxpi;J zQ~$TXPVTv5waw@*6rrc+jZ<`VnmoOG@cXC!?}YmR5-MlL*KN;kM@Gn3MbSXOTz3M z1y{mHa4!+Mu$_O=6Z?^@Ki)sydS)t@e!$gC$yus~3-*F1Vs#JV4EG^MrSJcIlZyHV zM?+X2bpE2Q%+&)cv>IwHhkXQx>P}mKZW{gmvH!b_nVEXyy9?S7EDb$W1$Um_0^fiD zc`q)@{ZMgT4nKs0PCt4VE;NJSH-!U|=oBy${nJBXuwk{mU_KtwpQEF;!V$Fhb7%4Q zOZ>m{y5eGSE!oVnb{MXQfWT8`oo$FdXH)1dYL@8d9^&tx!+hJ4PDH9wJccaDW@wCd z0@ZopoD%WzuV;R=iJb^c(FANkA=-6J$+zemzaIb*qBvcaA1Vw1az=DhtP4`i!C0ea zpjIf^^azg7uPk}hk2KQ;8${UTI|Fv5%4cvzVAGdvzgY)XsGJEks4w}ZZ}-HTt}!Nj zEf<{)RN2yt=zy8+K(P}lpM>xL-#_(D4{osO4TE0`vH*O8v!c}VgW?62?t)umJv;hq z@tc37GGY;(OYIEgaDsyxnD~MK(ZFte1`lxJ-Y5U?)H!Omtz0K3+>atW)+m3g)0lRt zj@=jhSAxZ=zeQ-@?(!bsX5gn7;OUJ;$;>(&0E5(3}q?2Am&o7c4 z32#;pudphii{hVZ`do`5Y-;xb*!}&Ee3PktyH$eZWWdV;4x-rL23(+=1|MP!;4hToAYni-U$1C;$3MLNd zk@mih1SAmx#W`85`_ZQ80_u`o>Hr<8CO3@{t-LxOUi!h-JV6wv!UDzb|NdiRsF^YR z6TiQH_(y;}g35lUJi5Z_4-~TTROgS%ls{D? z{pbk13q?Fk(fwqbA*AmS$YvhMLO=NWu?8T;NC^#+KhSeEE4!_&_fo$8;Oemz;zO|H z-LD^iL0D}|bpC;CM*RvLaL)$35<%hb5y)d6cnrdM4_Vy9ba^?$^8>YYF4}Q~Nq1~u27?6s{fRqAK zF>~hrjoQk~-bYLqMpc~GATZ^U2ftpXOOH^T#We|C=BPt?=PX9~6Y3k~If(~6Rt3}P zn?Ks0r}Sp<2cI|g1+z}_*Nqi`!+Q5rHS3{8A5t`oAmR)5FmqYg36IklZSw}OCJ2{+}6kCYFenZ9k#U~EuzB~lHj8jQ{JiI+9_1t zQ0NkB2*whTr)46L?Duyg3|zhae`lIMA@}Co-#O=Ze!t&6-_O}3$>bkc3Tf?plDKc4 zkhs5jjLY-?2m9q?db459Qj)nGU9Za`6xaJp@}ZRUJ-s51V^VKO-$tTr} zY~+$kf~X^_nvp2>LewBB;mgWsBwX-Uc{idtcXIyb$}z8J8?WD*m3BX~hmnqz^JQ9Q zxmz4`$_|_1KNrC@KV1-jGYfiDFq4T_@nvd6iVG=@J+Ou0>bQKwb+KpqzIz^tF)H{T z%J546wfOF90onqu%_l?1Eikl?CtK-O?#O8B_Onu?4g^w=CZDUmr-%rC*_Day3D&5i z^S-8CJmDFRuY5#V>HIeZERs6DES;IDPwx~1jkHc$#Z^4`BbNU|v?R%ck3gw+Smayh zjNp-UnUOErLw$*64p+~HWJ=R6hS{C&xK26(77OwwkEf5?fhnoYsCQ3m@I=IEDE4j& z8`i5RD3ciY8VT`*2!~|OcK?1qWk3;;gizzcy@sw&eE*Fbn?^>t0)Q%INl7g_Y>{4 zONlwQnB3x>5aii&22*xk5FZbC*qX5D*V_8XN9iRt;MQ23csF8p^R5w9YO^wb;dO^#bq(J#hnpVNMIvdL<1 zN5>;27ol7K4o6c3qo`3a`!r`8Bcs%l#|y5(5yjKrhaAJ%+A?DPc$ z6oL9x9KJ1FUV<@(leN&B<=D)A>-W3`U9}aR!qNh{+U z2}lQ1e|)lUWbZXysU7JI1JI8O2?%(Mo({<4C~*l}eU-*=r}1stdpPAY+4PPmup=qB zzilSCBgu{bG&809OJoJ)A@w(lQO}_`uKS&@arDNNTL9Sos0z42n*r?}qF#aa(j>#N zn0FwZpshRJ5`~tYlp`^*0TVOUa|kCuO}op)@V>hdvhcR{A*LN9ki|hyXS;w9q^C0U zo)r=QGdYU=5<2uzvFyJ0t8ozsD+Q)(5ti(6NX=^x&+s!rcxR%@S!vwL{cu9GD)zaz zay^Mp$=J`g&f6U25CxGX?>QjYMXE#&RPt4Z96ASb`X1l$Ifl@=YVz$=l+Yi`pv4tW zQizE14@-D|>7IC)arYkJI;&${ec8qPiSjWNs$WCap6ZyBN8yAbqLI{Ceouw#sj>tV zwWKsy0Gld$sy-Uq-oWM2^Y%KA|3YhSYfc`f{wElz+5Ib z>_{3)+Tz6FTXnCaQdLPBL@&YL;o%_x=tD6mUg%I~NVh8C%aR7}f7OCQIXJDB2Nz!D z=;L$1McrmdrD-BF$O3(34QDnzo1)dXL-h@e0fnOpqCMs@-8k`jv>!OJyW24uyDk(- zji}pVBc_Ek#V;R&1jC4;7?sFNov*ea$%Hs+7%K?QP%5S}@M2qaEUG=Ee>cpGEkl73WD)?a&I64Yj2 zAh0fWu_Cp$nl2)*N>&*8mSvGw9=mb5@1QcW>^$~mk%7M5w=BR{4bSiKKeaCLN4&bo??GV~i*JZDgNBFvg>`N5f%O8%JwSkYm0x|Mr^IXM z$Bi$ry{P&1&t5rbY5WXfwD7h3cOgu(J|HI5d558Rz-xyeQgSzYg%F!y(OqeMF%~HQ zNK0qlU}D`1UM+0z+R@lYjBkIZ7YlKc5d+*NDywDNPj^@m5Rd2AT7(h;W{?-&R?J>2 zl&)&VRDoEu3?#jx&iHhex500yiMctVu(X2Z^UMQby%{iYXZx^5W@Bq_Q&fwyx>=zT z+@|%PLjJtGAg?m-rnPb5{V+L2+}mqNpFGX0@_0T6u(yhw(cXQ%6{WGtplT6puTBc@ zIaRc;VL5B?P*s80!$-z^oX*#C(_S1bCh`oi?j&MsUMc|B?A? QqUZ)&1>5~EZVW&6KOzgvm;e9( literal 0 HcmV?d00001 From 06de0a8fb66581fd6601c92d32769cf305a4f467 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Wed, 27 Jul 2022 15:05:09 -0700 Subject: [PATCH 086/109] Added hyperlink to Register your devices. --- .../deploy/windows-autopatch-device-registration-overview.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index a837e4d35b..8c9c21dfed 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -14,7 +14,7 @@ msreviewer: andredm7 # Device registration overview -Windows Autopatch must register your existing devices into its service to manage update deployments on your behalf. +Windows Autopatch must [register your existing devices](windows-autopatch-register-devices.md) into its service to manage update deployments on your behalf. The Windows Autopatch device registration process is transparent for end-users because it doesn’t require devices to be reset. From 689d6574edb3acfdeb2d7ea102d12c66a2c6666a Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Wed, 27 Jul 2022 15:08:12 -0700 Subject: [PATCH 087/109] Updated the metadata to be more accurate. --- .../deploy/windows-autopatch-device-registration-overview.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index 8c9c21dfed..c82e0ab0ee 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -1,10 +1,10 @@ --- title: Device registration overview -description: This article details how to register devices in Autopatch +description: This article provides and overview on how to register devices in Autopatch ms.date: 07/28/2022 ms.prod: w11 ms.technology: windows -ms.topic: how-to +ms.topic: conceptual ms.localizationpriority: medium author: tiaraquan ms.author: tiaraquan From 6e5559c92541ee1f03c4f3f936aca7c5444b24b1 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Wed, 27 Jul 2022 20:33:34 -0700 Subject: [PATCH 088/109] Fixed typo, typography style. --- ...-autopatch-device-registration-overview.md | 4 ++-- ...autopatch-device-registration-overview.png | Bin 34390 -> 34433 bytes ...h-device-registration-workflow-diagram.png | Bin 572636 -> 573007 bytes ...ch-prerequisite-check-workflow-diagram.png | Bin 324531 -> 324449 bytes 4 files changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index c82e0ab0ee..38189a3bfc 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -58,8 +58,8 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto 1. If **yes**, it means this device is enrolled into Intune. 2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service. 2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Azure AD device attributes gathered and saved to its memory in **step 3a**. - 1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the Prerequisite failed status, then added to the Not ready tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune. - 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with anymore. To remediate, clean up any stale Azure AD records from your tenant. + 1. Once it has the device attributes gathered from Azure AD in **step 3a**, the device is flagged with the **Prerequisite failed** status, then added to the **Not ready** tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn’t enrolled into Intune. + 2. A common reason is when the Azure AD device ID is stale, it doesn’t have an Intune device ID associated with anymore. To remediate, clean up any stale Azure AD device records from your tenant. 3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days. 3. **If the device is a Windows device or not**. 1. If it’s a Windows device, Windows Autopatch evaluates the following requirements: diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-overview.png b/windows/deployment/windows-autopatch/media/windows-autopatch-device-registration-overview.png index df6d9ac790aa3ab8bd6712f8e4572c0d36617279..a2e0785741b64bd7e612e70af6a6826477abccd7 100644 GIT binary patch literal 34433 zcmdSA_dk{Y{|A1dsE~>Xp%N-HGBVR3S;;1jviIhM<0wTEij2%8d++TSA$uMijuB?1^Lp`E{_e}0pM&4`H!OAIm-e7 zf|ykvD(XN@*CuIqu3N$u;Jql5UqPi58ogH&uau%l)M=cz-#ZCG<*pV`D>ZG7=B@H7 zM(_vSkUV+yj1o(rBGbi-(Ta>B=SYg&&=-`HVsuheomVP0dwa{I;63+cGuY=U$ zmx7)DoxQxgT;u7vi}P$)@UF?t&B?{RsyW2!=g4zcaeSwdis94i*C&n)a*2tyQ33y(p`-EMnM?K!`r3^K z+ye$Vi^`D!65tSFB2>RKC}K<8xeG{6T$LF)UdPG-U=|gbXQa5)NH-+2|K=pE*QDoY zf>X^+wejECnaMtD_7EAnU%rDXe6J`4-uGYJkp*x=*F0xa^7(LO-i6~aI|{%)_R^Er zArcK?rg!X;#0Ytm$gIi;da`PluYsyL##l|0i2K1SG6o_e9xC$7WeG-y0$B?bV-g$4 zLVwR5>i|GN&UuBnA_`Esg9$|55k0sghtfW;ND*^J2Kj@TRrUP&nB?GVG9>Jvs&JSB zRUvrOiJACQjrVdp$(}GT0E4t!qU&nM!q+E0Y$qUY9XzP_FR%71-0royn(&=f!eMN) z*SkSmtc!x?@+XdG_GK_4cER4N=Uc7shVQg*JBPQ$hE_rKe7rv55Lt2SRV%-#>q3%u z(1eo3!9i%J5DJ>V7hUN0cgP-HOyT^h%lJ%loF$d-ccrBB@wGfEgQc5^?@K)}ffwOH z_Q6{u}JQO^A42C zEn!T3c*HgBAnD1VpHOo0+9#`F^V=uA<2U&rEDq=8PQcebnrPxbwmJm5OUhTqGMAY& zG3%`}RI~H`#VwE3zs6ugab8X4Uy6+_?Yu(JUaY>1R_~4S{f_KOL$>G8Juz%|d&Z5W zrFw<^4CoUt3kU6~oeasP!g;@mi7BhV0q9M0s&y!5)Z1&JlHWb;G`I|Xbh_mDC-jo@ zo-o411oD=1^7Yt1btk@Waol?)Vo6y<-CiT3K9J}&3MVeW*Qs`j8T2Bp4Oph|^O6$| zA5Of;fD=Y9^6QP&-vGv_hW|nnLMwk7w>y=fW~F{~o3VeY-TL{^F$taB7bP3jW;DGq zKCcr0ZKn7!CW&{J4^nzl@l`u}E$4)edKq)^PCC{T%SFO)i9hg~Q{EkXQ^8*T&hzlW zdZ|%r;rx`dz*h*18*VSFJu9KpA$oZA!b#r<6>ot>!SeBk6b8Q<;~2p-6zfy+m2W6} zQA6+L?);(M9rd|bec)OAVkyd}gc~PS?le}^G^^j0PidZ0^yIZl6f`D40}7 z+k(8QV$eZsX4E9NnW=t;$rU>KgT;B8y6m z4FsT%uR!D$*^Z=02|Mc;=Ol@Jigfy*T+l%m$szy5>pT68DB!MLg#%MZ7;}eL!$Z!jXJqYewbbuXE^VjxVZ7 zfb3GB`ud|)3f{Zg4~qEnZ$Le64*hf*9(S8CO0eb&m!7an>517o`*lY% zrKvLip!iGOkiojSaCP!QwB-k?BBq_eSw0EWef?C0$5`ufH3$b%*J8Mh4<_SX5oxR| zk}#GZUtM*RcHHti2koJnqlq9Hk6V;L2b|zM>xgHGP>)K8)HEsK9uR#nrDguqc*MG^ zjoq5t2oVc?M?A*~$Gc9?pu-TnhxzefoLrH26n&xj2KH(YRf6HpXAJ047(-hdM6Ra# z-aM%15nGCh6IEYz+qfT@*=j|b5cfH$=f3&gY0ZlNyLAUDo<6npPB1lAXL-GOzGHKD zX>OA8VwQ5#YCe1%Klqc)Z?HC&ZxYt3711lqDKGhp6CA!bKU>#hrPtPwS-aB{jvHXDRf%-uH+96ycveT$ z|M77!bacUU8(?zW^qorT%ML<%3Vyi3KUws?X*bR&3}3$WtPazfD_E`D8m8-Kuh%qX zz8Zc~E|X};N4EBZM`UZuUng|xH+(;DETOf?ixd2Mz}pf2Q1$Gq(t$_#h7Z=IigsVu zcET{%9mK3Jc7OV~Wa1@OG9io#Nux&baOEl7sI`kkxouploq1?H>n8c_3Ub(XMW8lq z(t8?4INU|~b~_nk>{O?+yI`xLUUEbo1h&U{gzZkL5FhEe^>C*NT2;B+Wc`WVUT|bz zjv%LI-(=jIf@eh-bA5iE${du?Rr7sL#(a9YRHC66dDnptk9NHY8wfT1LIZ>=ywu$}sc4+r)Ho>z&OE@WvH zD&YUTW@n!~3@i_3?MuYDw@3PVlNHjcfuzKB$4ok?7t5%}^LneUy7Elac`QAfD2h~H z<+WQ`Wy3GLN^;zuNXBwo^VT}HMx^7D;?eCw=A-6)np<5hAr^nleQlj4{yM$rA$~H+ zl$(l#iC2fdDR{X(p@+@qIa16j_J&Ptv3d~e_p?tGj$;1-sMk4(8(&s`70zV*(@E)% zQ6}}@C!%}PiWeEa=tTJzpZ_t|H#io%;>MWmZ0)zv0F@o6P-a}S&@r~&8win0L?`?l zVRZgDnUrB;zZUGCTslYk%WGexzT2MsknJY4s6wT}2oflGF`|?p*_Xcg*;nQh&Br;;Fs_0H(! zx?h*X88b^!<^Yx$IOF3Lzb@mcNSVjwvY%ixy=|THft=0Qg%sz6RHXkw3)jdZpLf+p z1Z;oOJ3@KE9Q169&nZp@H@N-6_fVk{!Si9i5c~BTwyGt?SG`qdX|8o%_iu2*@_I#s z2uC1nz!lIHQR`ilYF-$$BR^CiqZ@ScZtd)@fxedNO*Ym9L-+BaWE1R|X}n|Y8^Js@ zmr{PIAB29?`^MredARGe5cH#{SMHA^M@Pyq@1(F5WRsaK-D!{?_h-)zC>(a2{b^zB zxOzUO`u?;M{0=+02sM!jvh<_JagUe-rnh1$->%5WmT!kvbu68B4{Zn|+Q=S73%SYg z`0z<2bhQp5BRJ9v-xHnWj=>U*I2WXtXVD*K%Av4J<9$u<*7UY7V zLN)JqRu(4~BVs6vKE1xZa?G^LSjghPf)ETgE!62q@?N`zjybvG5lK`!X5LFj?78&) zF?*LhVh4ARNxC#GnY%h%J!+2v2QA5tw>tH&C-@RhMHb0_EYgGPNaVkUiQ4iOd7VXt zW06B=z;%@RjzxZbNnYph<3Ev|9^`cfjE_ZTaFW;Y2kA1n^}xYk^453G9g9pR8zas6 zSme$T^wl3XGU@t9A{mZF!pK`!(md+d0u+~C9El7#)>7eU>z>CVeU6;9^qp$p6pA@j3aAt{wMOtS~163vfd+KI{u#zE|FKY zxqQ58(~<4|Yx07a$a|$e-YcsC`NsHTOIkvYZanV&z9^F0wlw);i4Tr8r+%yl^=0xh z(#Kn+lObyr{okTTd^_hjctjbAkn!NG0W7mmRl4aaD4tvXFvZ=KGC-KOUOvlTR#dEX#GYu1E5%>Y@ zAIaj*P>g+k{rT82_kr-wug`M>n!%=TX_*C}B-}JtLG0eJwr2fad7<3mx4<$8Z4_YE zzr4DCYs2Al)n+p-SSAWpL@ zMsTQi8|>gflzCd!sj+j{S{g|47*z3LQoii^uu8u4RAVEUdDcAO0z~vRV1XUE?H25G zQ4OX>4QLnt>yG)Sa44c)?Z|bWThb$%&xa;a{AGA7!+zTErZ)0?K~|m-^uVHQO2ehY+<#PF7(Y?DJ4U!kppA}xuGOqnDgdqHfO@PIV zlr9uqjTP)Wk}T~u@Xb?=*qr+7!-4h6yzXuKuyc%v>mEp&2gD~u*g4Bm;nS0UXvdLS z2{Zug(<`xe?umllBQFjcr0Tb`y;4t=G|P z#;N(w*;zB~2gco~icFBwQCQlF=c_84k0QT@PA9l+{Ic#ZA)dRFRLO3pXJh>c5c)<} z=eeS%gxd}Q5(|xh@YWR0>uEeHN=82PKe?~gvLM83a}IdUN0>xjWde4duCL!lY1$Po z%G7L;x8t~{hmm>Wgse|=>%58EKp-Zy{DgV-%Zvgy#-d;i*J}wDNj@y^xy&&!D{fx0 zOw(+kDSkKIm4iU}6^nm00ilW)EkP}3Wdv$-Ey@(2CuaOq`rQ9QE?~N@OlU{l>`-ks z74a9wrzrG`Rg7quLxZNZ0FQ?e(}xm9kNG8=X$uz_`ufur6QJ?OzDBPRJWM zh*>PL8naG;c^In7ZM^CmGFfbJ=&AWs$8Cdf#9^W4&%IRdz%PsQpO|?gsF}<-z=S|1 zUz;$Rb7r($|HUM`2KYS2@l(3oJ~>04VbEN5Y2=QOy^vhaf$zET9G;=&JG|dUcgoSg_+q-t6ATKu=M4_X2 zSdUXWV|rm0Hd#|E?SqzC)4jUd@*n$6L)^ z+@vl$ITEv~PY}9})A+nPm?S3+(ZzTj=F7vIV(hK*Em}WZByut#G^72TJDuWwGKQvj z0rlSr7bvO>E(ElSilh;mz)2$@G7B@f+f#DYiUZjeaGKJ^(qiWL3b4*x zI58vrtC8H#k_+%V;5j2JwDGw9oC{dtree7GUmbDb{?$lsYW`h_W)j`pJTA>w0m=7t zvLeUz?o?yXH7W)&c?5t12Wb-L`g>s!#gA5;mjv z`L#9M{}!3})mZw!B34CZF~fSy8Nem!MK=YGi{yP^osJbc|33lVA#}3F|5Hasi8}e} z|HMslQ}vyp-1Jz*_K>Q(M#Bv%*P2{70Ff)c$zCl&d;*61r?{^ILyAE1nXbl#f`wWa4C&eGd;;K;p9wT{-IUe3E($8~%I6nU3|e+yfx_&Gvc?nsRdjfm=Gde!;{YadM^-;$scUjbo=} zMj(R@jVt6Yyu5Ju7LYv|{2X3We`{y!R1^R_aQ&6(R1DP32qPGIDS-KwSx?CcDTwE~ zBjmSts_%OMT`q1cvFg>zz7siyGlu6Nd_KQr2Y^!No;Dh9-~DIl)AiH)I}D1#4UP}0 zC;$875va2f@qE}?M8nct4O!&C-vtOkqc(&N z&2?f%1J#b$%Q@%!Lcjn&qRyZorvv)p4(?!oG1R#-cj38b3hY$fk|L3v51>ng;cF)@ zIvZ4DI8Bh7QyRe|0n=7jsP<1#RLQVR`j(qgk+-`x2ieBwPG^T?=Hc&Godx35SthIW zT)j8;C(XD>@e3*C_Zc;@%Q@tbeTve8d2MP^uTxRFC`-uIwQ4~30`FOM92$!cL|mi* ztOhb@xGETv`>K~4L~Mh3yd8&sPEOT({9UGLz790bB)*zRXB)KcTaooZ(cGETB!S62 zd_F+tCFJyGA;r(tg>RmWeD|puKl%)@IBWOAh=%;lyYC5?%baE(+5ne+@T@pb&ao@o z%BB!3Q=-{7in)NAnPmQ!>!O=w=L2fZNaxgqKmJvy5>xw-hbn2(_$meZzoQWlaSta2 z*D|^8OL?NUeBGyLMjib6HQvhq(XRaTn!?PC$#v~c-+}p59DzZnbw+p^ab4{imF7i? zD$hMt{pFp|(aFoamW$Em(~(i3Q-{Rm%AkMX`_^$QcukdTgJS`UcLlSn<3}Ry_gqN3w-;=25?}G*>*KzlwVrR zWM2U)9|=?8rV2ZWC-)3gN2cu{7oeE(jakWJ;9DQl%Qas_&UQhyf|_92pMtPG$Qy`X zZx5cA8R#zS8b#Y!%kxteqC~gozKyLoqcQ|J zAPKAM)qmAjz0Kcn>!k>wW^x&(s|@k;O)A_mFLLqqo*2lJ%n=<|C86dkB7# zmjItfX+9^1r4A3@H zC_EHX$8Hf+%jm=E@Zh80)=I}Je9Uep#C1QkuNpO&Z9UwkkfZ*x$c`iyYu_2`Y?SFZ zv;Upqn>m}W{YO}noPL8XR{4u6?8KDWPFU-0gY?@ZdxZNuc7++Tzsce4JbCFEGaE7% z$U{S?Okz_?wrF!=pYL<(qJJMg_4S*}(n|37wVS!JTZE_a4x$;NtY_NA*Ad$gB^z|t z(_^1ZCkr`7mZz1}jO+A8c=7yh+W8n%3Sv3wCd4G&r=xmWca6}%?sxr()^Or5XQmMQ z?zjS&M~T=T-U&Pw%+44(lm+8P%=N&pBiL65q}pmgi2zsC{)JG>=Xnbh1xn zO8*Y0ordqHlWU}_+=*sGkshGVZBFiFYC&asY_4)`1%$48_2SD3k>&F7iITvRVQ>xk z?C4ys8<*^#F^Tu3XDxB}hB`f;AXpcLI!}-R-*UoCfmL0L>0&HL^a{zDrhD-zsdcnL z)qM3qEbQA_U!@x=*fdyJX8Z3b>D`5l?^Y$RU z09z8s4`OKZ(lo-LGUuRVMa{U>GO&E^uDAcAo_M*8bmq}6neNHdE@#8S+m?8t60q30 z@3dB?Y$0_)?^inMVmM^M=jNXF67n|OQSJpbnpDwqq~8S~1Ycuq`GQyY!(pBUfuz70 zSBg^ze`-8U;~Ota`nw=M+m;}2F|L^xme?Cca)+i_02Ez(*41Tn(p zk=m=-5s_YbCZfSNv1av4VS!O8rpW~?*NqO()^!heFV!7X*q+U2U9NngM3RhjD}*~6 zvcxF(I9H`|NuOziG{8fW2z@IQ#ZuHML_%oGuo4WL;kow+@?99Dddc9o{;iWQ>?$uU zS6X|K6kIL`f>Qzh7j_ID=L2>{iw00Ac4=9&E6>^t7tw@pC-{2YRa<+`PjS#akxVSu=A4$Y1M9xy znWs}AN7_Ry_YJ=b2Pw;oXSUY<+nj6b2wtBhx8B%_O5 zGMEL8@ibZUAV?R6?|_ttwIJ37%s+c!_#&3S#S`@8T`v$5(o+Y(LUg`B@^z}eX152m zyeG1C`4Nq&_sgoO{2;2$$lc22CNdR0kO%C>cQ%=28puE!tnw}fU9MGo01}=rg+%bg z&o43=ikj=KohOQ9a|RvOi`KFpgrtzViMIz?Mj?#6o>{*E{H*xG*oz!CTTN+FqbnRkWIop++)RJ5F26VePD=)E41^J@;FqPX? zI7o|~C{SqNTg%zzq+gdh9N_Lsy{=I6LkforDm%s`nQjMJY8cZY$Mc%t`LDKyl)SbCxHcISqJ2#pIu;YLH2L# zyEh7H)I1L=DBD7=2`>f{8lc8irpTpf_@QqC-L9{VlGrA0!~byMXM`!X!=;{Ioq8s) zfv|({B(t>#+CaG=sVQk$hg^+j&BH(V=L(ti8!vC%d7jN_t=g^^rF#W1zS8}AKObshkfeT!UBU59u zrPc-XF*%J$$PmW9Lpw<}3D0sxomkm2|tNOvwJL%&_kl~5ow z8-V5Vw@+K@LgBDHVas?Vcm-7FeV!5GQD8b5fm~p2!9qAN8(2m8S)m|uXF~{JQJ@`_ z8886kH)}HCls;I7b-F(3{zS0D3G~sgip1bc^=wia@KfsKPy>=}!P0<)-hBQQ4Pp-8 z0|E+M>VTzzsN|XNlFkU4mJFI*>xRu6&8hStI|e(OaTgwQFv*1xmU0Rd^k5n5oSl%! zGlIarHCS~8fg1dJ3a{vXNNq}7tWQYs6L`M#(44|R!f}>c3X}*ezC#_V=Q$lU)PPys zug23y4LU%_%qsP7Xb^Cfn@Z;R%gd}|$5$TwYWz2F2alOi^MdmTFv9ENw&~OW^86s+ zu4o@?+|f)L*tT>M6FKVhf%#rPE38kX#R)_>y5Q(!p>iNCpt}jve4AHC_33q zzz?Kqw=l%{a=ygk|wGavB@%AP6fhjwI<#Vwo1<{`voC;weJBep3*RrCf$TX2^c zqpTnNGl)44RfDaJNhAvo;^P1>Yg}dbqUJOMOzYOIPL?Vs<6TeL+4NLoCi_ipF?@ba zJ~?)k)rFeV2r#Y2B(pqsmtCq9>ueN85QUiwYwzA6OA0_q4%5k&0e+2@5p&%O;f{w( z+$3xYQ4$eCJ{3sUaYbzN8|7xEo(YC;8V7xEx!AwtO_=m`BD}OA`vC|PsiTw40`UC$ zob^kY5pUIk&N})otH@#PD;!PjgwNT_`uf@|S~xlWJ`SzKiuraX&|88+m-x zPw%holgEv*X@I8#6F4Q3>XDEyL$*5VD`~4=f ze5{~x#*RHB`DqC_C%Tv?VX7h_g2UIY*W~73^%lFnuXX3&Gs*5iR8QlHna{ESzow8u zQR7hF-)`vlYm5H4wMxq_<^<@$?_m4ygBg+eyluJQ(8uTj{&bOMw@JRxWw&2fjVqld zi{DuH zylJ*R*1}uK$?O5{`nkaKdG==4vwcoV>uF=f&&~f$%#}0vi*+zyeKH)M=^yIyRv&!rjRC6fV+0V7`}mXF6FQ-)?G62 zDA&KamPUh_%>Bwv_j$L!uSD{q8+ft3?p_!g>f;3Tn&c1F^HCTSk05OGjA`X5!biKk zkCOe4Wzdm;19RiQYBKEy&9uTh4%O0!)$?!uu=Zu+mxkP_T-NQ%c`&*?jN0+##+vfj zKV-k0O!$nu!S-)xIX{$V0ip{Vczyv4nE4U4|NF_1LNy<{{{=d-&E+e2AbP>LOaTENPSBbn}E|3t~v&VzyalhJV&jP?@q0eBR6 zAS`L@no$d@bz-r3NT&0oGlBq~h>A^ugQo_jODt7oTSu>)OgP^qR13rHfe!<=R!jRv zzO*nXpsjKPj%cxgdHCt3E- zrw0z0pJUMmBf1&78WlL?L&v~pSyrXM<-S7Hmniqqr$wyA7LGAl7Xw&?o-eXLHFO2b zSE2Lx-?u!&9xJP@`$2o4eebp9^w#szf*Y^nLb)YOp6j;HTIlWtBXiBk(Me0^p>`<^m8W5gxXeDkX8IN;AJ^7NyUH zYfDhr(%(1rT6<6#d|QakZH{4s*geiqrcMjbx5G=Vo_cAi-vyj}2 zWn@ZsOYwmGut!8#o0PP~?s6Y1#ahyxcw@v)Pg*aeQi@YTJ10eU_u-{Q$tSD^zg@9u z`|J;Y!W zZ(Zh|Bpd$Xn<`tEYa^=!Fby;BXvWpO#J@rka%wM?Q}a)J)KZZ$OyFFdPnxD!=LPt^ zZ^C$LjdJD=Blv`2gzv@=qCCQz)`xTXxJ`VThjSIa2AikBvTky+hq-zh4QH*qj55!0q6cd1+GT%zofpE$p5(N=oD&B6sP z-$Bua1dH$GQpNm@wQf6KdcIdC#tUsI`O z=Pmf+L)or`dpaa1!8W%z25O?*ZX|7c#~9)FHw9hlX)bETY1)eY?st<)VRxIv9)t@k zaZiPVloky(WLGu4UfNL@fSreR3jcKC4njJ*Y(!Sy&(z!1(SNHrUjb*k7_^&p`us z_cdK#Fc7yN1XdGv`lA%=cqlf0HBQ1$$@TyOJ;@WF%22YgrV?qrpL_MR7bL*V)yDMq zU?w5bYe6iqofvPJ7bD9vr2SIG$ zV&Q}WE?yarTiL-C5@LhZ_S+-VhhzJ_2Ztvzb-g9V(#1aJSSi;y4ffvqhYF9a7a9gx z&*Tt`2lCD&r6#1A@4S6uhhL1-Sv);>ppvFS7?hmy*nKdq+13Vb)der79DRSjGzG^V zN+deV0qqczGKMU_WQ*_l?TCb%UfN#tH7oB5;gd_&u&3Gr{)` z$tW<>Y4R|)Z+yRYe{y|$+M{oOAHA}KB{LxKQF)fQexYgosHrcCZP_n+3&f{7a?kiH zDk;t%h{@=6ETT@!(IvRE51&YV)MdMSP%zae_1-umUhXGux{pKzhpjAZRd1cBYdwPA z*qQ&Z=UoQFiyZQAJlxm$lTxeVr6uCy%EUZezz}=-T#$n!p^WeGgu?sij~`THPMW2+ zOG*1Xw39CD&X)ms1_^jzjY9_RIQqt3c3{W~e;S0i)q=T?gpz6BN9#1bnA!2()rc*l z5u`LML41JoopWRl2^A{jw?!g4EDfexC%U$Q43$~Hz^qzd1&Sc-mFheXi=PSMOFs3v z1Xh2lQ9WtGtVc~Z_wXn#Lt{n;kK&R#d_JbIM`4N>6?7KkbU47+N9_L~&dx!tEN&OKI+#w;Ry zuPN_Bnr4W0df!IVGsd}3UqMzkI>X|?`EIP<+aE5K4Ru9?&gOS&V6cQATCFo+*|%94 z$t-<9m>z=FoaTgnE2Tq+0s>))6ElKxj2HK}l85K{xN^7q8bFWSHB>mD_La zoUq-XDUQ7A+R@pj#qhzuN&d<1qt((`sgnnPp)W6kyZ&^-EZS-UBt^0#K4E7Xy_QQ# zby1xJvENXCNJ!G19N=;cI@=1+!+FKL#$5T(Fo{56h=vm;Q;%*Hyq1Gz;m}jWv8h!$0Ww{}}#9 zy*p%y?r(0`5QN_&D2A*+r~dy@0OQi}K|8BeM}b8;;q4rDj%g-#F2vR1m&pSO0GF?# z6T;F*U*?M15mPvP5sI$fo={1{@HOscpUw-Z?P!!c)A(!~P3>H_my<#PZJn$nu6LQb zZFWK8>*#Wjfttju@uR&z&?sn{t4$oxspcfAP;ncamERuB z@Ba^{Y?sjb(k%~>!^K+q`C?_RV6cd2iTiux8EJls@ju7UN*9|a_0H~2LwmCCVY^oH zCGnX)|3FC%3je#wHm*i24nbPe6useix!1m}p(`V+-T`wZj^MElhOz{|s7OcXC~j)I zB|ie|9k8O!_?CM8I@LZupqk{)UWfUhsvbx9EgtQOw)ignK@-#UQtW5tINlUh&J$`J zTLN(|y_v?W!=mZGAb7J2iBWxIGBk39xHXhkG5TY@S;OI1!QF;^6dGJ_&_)O|+)wF+E@*|AwtSCM1b|rJW zcm0h~Hu%L$axVtScxQCAZ2j%{fuaDrf~Jw{ner~oQ?!EU?u+Von(7!cR!BJCVE|e$ z+2p~6fM`mGAT;BB80LT`ckVX4?h9ooq-XMat!GzM#H2e3M&$1&4)r6!GPAPY??t_C z0u;DA1&U9MJu_ZU*l)4-H*48W6}pbdVurs>s7LafCQQE*Y7dQ_rdydM-g?q`Kd&aE zk83(d!(l&5e1Uof+T*{GkOJMo?N8oa+NcI&m0xdg1~X|9JE@poMVOM?^YdYGA+iW* zIN24B$Q>NOv4sd?kG=EbjL~eRvzVOI_tP}8!kV16fb7}jj>oadBD>2fnl?-5(LYVS zPs)q?gtgT<*gfsu^fxkswlLUwoL!7u9k?y7Xfxg+P7E}VaLC}z>EsKu0%Z@a58IJ- zis@XCxSlVX!?ayOW5T2;M{{`l;>p(f6l|!S3ZUV%+i8*@#79x}$Lgp3FFhydUc#)4 z%q;+S4TD!W=x7NRl6Cmb@EUm{^>nV?@_|zcLdcMv6SbG4Ak`gi-tkatFV6cisX%)= zR?VT7mxJzR`UZg?A?igu42FU?J>nZ~Gn0Jfq2u}=!R6a7b6vOJGNbLBV)4hYcq71J z)}IXYt?Gn)J;Al@uHktuXHxfqkks5qvHR{LX}qWMWvZ9RZ_s2v*lJ`ycgm=ypH=+3WZ?-a;qrN%GbG)jywgW969JPD}XO%T8*( zeu`}`vZUM$mmx`-Qx)m0?_Y#y#N1*HXsKWK7?_6L^yt0-q9ei1<`1Z7sgR*We=%BS zpz5k=QJ3AuP(b{VN_Y824?vY{hR5voLQO$mlrerk4qJ>nBud%nsgLl%WNZU|Cbppt zC+Am@v3t4*S)D>e<1|wI0jE9CZk(!UwgF();TavGg zBD?9o<{WUNrF4z3`KFlhFSpzu*kXHboNB~$>NY^@w*K&%j8IQJ>xg&XsK-~+gC2F; z9ad;aSj|?|lK@sq+W2wu_6i9$56;kYtd3CmZ@;szkc|ytI<7Q_! zS}IW==BQtdMp%pST`YufU*OWQlpGw*2$Ap^a*(+6MBkr zuP&e0x|owK>;oojn%@0mt{1q_z#9S5=F$4iO@(3kq5a(WxYd-XT#VC*kj3;Bzu=8_ zHRZKUT}*E^5=I;oEH)~Zno=%71$WZNZOSE-M}g}?BZ;us@0QYrCr#7vbo_-fi7ua5g%TPZ){_qNQ8zJo6!H)s%|Hgf2P6H%W}{r( z;~E?2VCtMRS%cvNQ>V(dKhC|ZgKHEVI!T<3V&<4Lj=D?R;5zhI z9syNd)f!tW#E?kn1{kjS9W5WO^%L(DcgDfHo1HntqlD}AVZ$m4aGlmh=FA_}WcToX z2kLcCASMJv4x=}AIZu)&zVV*w8F?$+?i~g5=qOPPcn6p1EC^xa8Dq-Sdc(jndvYy@ z!@F|nmJFZZR|RjnA6;yI2f=hk5$pV{C0R=JK@Jm%ld+Svg%wZ{rWka`$kVlRg?=N8fT97V7b|>>TpmPLLRuUv$Qz2;3p41_)+UJm*aGVnjY&yloLw}B zWY!rU56zhQ9H>=2VPxUrr>Ul&t060+HTWvlnw# zq2Y32Q-O~sqK~VbhciGomNZl@?Dv~C6L-2uZG~3*i+)dl*1Y@ zktMD0KArcJqhVGyoh%iF0qDI?cc_pKVRDsO4f9=6)}J8+rrl^`)4kudHZFsaiZqKl}rja)L% z-Fma8n{=cw*t=pucYdoxjTh~v9ye{9OWZGI{ON8GJ5%8o2N1b8_UJngWFp%yd*@C5 zz!FLp?V1h=32`0Q(i&j4>}kd+1oX7Q&OV%7Q$RZ!eh%~wn_Hri=%&L7vzzW9SW@fE z>H3lT)G|Hy9FA%Ay{j} z-imho_RV^~GYztarMzomJx*%qCa^>LF<)IsTs(7&opM)aY#|rZCHo5LYi`I=lJHaS zqGURRvvzvXAq7&$Baf($#px!!pWRW;s@AB@NiFAb@{uulZHObrjr))nllO3%$h$i3_Ax8d-lj( zBR;}tHp0Dhg%mg{Sk@Kali4165I+}&nI0(*iAj&*LUR}+{mFJTDt>#&3bmqi`3mL| z^*6S{*`v~1&Zhetq!IQR%cBpEjDlf%W(|hUr@c<Hgz=UF?oNh>gF3Joet*1kY&` z*Fa}&w%5%;)mL8t>v=gGWRAq^pz)XM=M$y69=$|c-49#F zP!oUl_b3;-#DDaHOo&MknWY#4x0=nQ`ssd{zxOKC$!E_!d4;R@x`KIBtwdOj2hu=i z`<34lS>wM_qfwuotmT@XK@wl+bPQdBge7z+urk`;v_~0|HVVCl)GMcJ7kXPWx5_p3 z7to^zw<~mfmS=%Pzj{j%-L)gtTjxEt$*M0Xakb{+Pp*TfJuERHX0!~XmLXDKu(%dS z%l@T``zyCj%Dk0drPo2Vr*B~uNRp8FJCwPn@8iUCz;2AEWzveDJz!16ojE`-yG^Y9 zw>C!CecnGYfxc0q6w~MIPF2L)M*58;BGh_-y!f3X+$227je2c;6Hvue(|2f3E9$N= zmYSyZIz9zisa?~($XJqIl$G*&e--aOvg zR%K_;4r8uVMSo#~_osgd_6|l)PSQ@E4QL%7S5(6|OWD%i zH9{I`H?!e!Qwc8XjXZt*jlU|Mfu~xP+B@uE>~r1tPtZ z<1mYfv$?ozQFcMA<@}`1<$zNA(hyhq(~=t&bArYq-n4xA$saw8*G?0^s=3{L#Wt5a zr8eb)fl504bO@ZUP({o6eb!pD=Tfr7sZ~ViE?%wakckt*m8K@UG+!qXbU_3!w7u91 zD-XUWZomk;`~2t&NBE0Q$f$o4n2KFJrcc}UkeIWI=`2ePG8*SLS-uEI!&uwwlMkmF z=f51tJ=TX2L&Bp#&ev6LHb};)>K?rdPj#7ZH%C=-yN}CCJQ9FG`=5H1FC|;S=#3n` z2*g)Y#e5w5s|!RWug_A=H}=Q7HB%s;PS<-jYhby4f@~@#;rTl{*(eI=FqoTB@)fIU z0S7McZ-K~qaOH{Yfb<8S=>3o?eq$E3lAS_%`{|7-Z(lE>gZ`fQ^}qZ4Bg)9Rc49$| zv=e%F?cu3}MTGPE#FB6vn*KfiQJj`NwSRKf!_Qjo!QYK%9Xp&O4~#RJ11txdoJuf) zx^7HpzVUO{8=i|?9#B6CVya_JUX$`3m2@pzEIq=nR~med;-o64s98m?mK3oKLf@kP zoYmIGFt&fhSzV~zz9`q!Rr~N-+W2UO_vSQYu2r0r%OJP9kwG|Jq$9PD%{Ev54JoXK>iQY@-PDy?$`c9UsKzZr6{9^P3;kCn#wUIX*Pvrx;A;|Qr_6?Z zKi&F@z`H&JvAx1e4UD;t8rRIT^f`%D`v+V7bEr@HrkYwCHzhJy&GfT)NF2v`slq$ow{DvI=81f*E# z1f+!?P!vQ3lqwyi_nt@%3W9W{_aI0QJ#<3eJqdoE@AY2KKk)n}=A13FGqbaEX7Br+ z>E~6OJzZB<+cpb|TZyJ6vmDNS$t@-|cHW;F1$L{sa@M=ff_rCErBnp-blN6|T;@JG zbs3I|h2ua=r53Ib^DQdJ26%m=J9m|07(b-znveE_fV9m}Xx8lJ!2X6(-FZ%x%#*}M zPR_hPuPu2-Y@(|_yM9wI=!s{QsMjuDo6c8_hM!2M&330BSbbsG1`;Lcw8Rs#9oabT zSgBxys6DsCaY2k|xn1OtzzV@80EgZmFLp(2U`>5qdwyBO7G5pI-vWbi;{UYcShOYd zLY9cMEi2YIx!JJ6yIIrCiPH#S>48@@aF9|hP77DCoMC}NC|po+#@*d*>5bu*B$4Wi zIR5jafivQzEh{g1m$(Mp_HZpi$PraXhY!17_j;f0hczk!N8Dzpy$|I_?Kjg@PST9o zo%l4uyGAm43tiQS7nV0*p%P!hrAB@*P0KL^XLG?U)p_4M%?s>w{~|b!w#cYov(%5P z*4B+zTPU$LR+u_h#!^nvkK#(~3NOsd`&#_K1qko8q0ny+)f(Ew&#P`(&pZpV|7NLz z3EC}uvH}6eD?Q~)Ft)1=DTm{na7UMl)!ilnP%GL}82PheM39&8Mt~0}B+5aWlv?9O0&$OelvzWj#pAo_W5#3Hn^!|uI*Xfqe?|PUB^p1lSK=s+yd;9KDyt5 zqfGf1q3tKte_Lt5-0N&yTMmzxKW>6m)VFCO6>@HQSE2I^P}7|$_^8lz^x2fkBWDEGQYwesmV}mBwLB{!i=I_&nUs+ z1N|U_UKb{5PFa}8b-Y>;)-Ii3QZ)#xvq#^-Gg$kZd#5s%=s@XP*-2IX?HSQkX|b6AZ%XIVXUkfZwFi^p?|Z38 zQ`wY~JO_QkBjAp*9^dhMDA*&D)TW8q`Ndd4gjeA>`Zv*EuA&&wZinM;*nGozJ$Q5` zdxB$fiTQ~^%P6;0>(&6ud^Bvlc{ExnluxayVsls{H5Na;0v4KJsJ#l(N4GPnb6QEK z*+Q|%y%V=sX0+P$oI0(dKnVPh9)L=D?5#A)3GjzcikqRfq9@>z%<50$a)Ejx`h5AI!usFbzGMC) ze_v>bLgCEl#^LG@(s#G`x*gcH)<5&O5V60ixXNld>;7t$P9ecr5 ztL&aB>aijR#R{D0Tum74Tmeu1G2(euaF#4&uiO9Lt)kOJIuk)EAv*Rf7t|n_*HGtz z1E3xVjQL7V`!yyue2^NUN=rW5XxLI01)G4`#RvzzY-&YB-Icm7&=Mo){^tcEys_OK z34g!%q?@%$#At6eUpLG+yvL$rrI)&q5&qiqlb7sT>-66%w;xeuTn8CqZBd&}LAR_h zcE=&}6nf4xR`nB?LjQ8}aXzbewz2z2INUE#kDkhZ#P?p-N-1AV%V%pO#fBsU*K8mI zna#trM-izvWcr?(^#mqr{OQlsUwz)(mpS5f%1?Q*!Wnx$SHxFLd{=datuYgZd-s0O zqCj&q^6=QOIgfN*|e@ktIAX8aydWxeov-ZQ}My;zu|N|+bnuD9(9ICWOvf*Tes z9(ci{lSXf4)2k$DK+Ukn(|JXl4tNzq`mBvf0o`Ir`^w^!V7pcPXGQOFLl_5>EnL{U zD(q3-qwvI;E8xLbZCO(NsvO64%RO&&rh!~9Fy(A^wsj>A&F#0FwJV7j69-^QMeGRv?L^>&QT*dfI zM!t8yTF^}Kwbj8?9IRp0QC$Vh4K|RI2Wz+{Qz()CJLy5eueip1_HmBDR+p^Rt0Kbb$w$5Ozh&!_X6k^Me&LcQP$BI--And977 z44BTu1c6P{%~1ODM^<^aIXU%AZ@X?j4~EoY#v#}{5&4_$Qw6v6Z;|H2Pnwf1U)gVgn2v>(=rZF3(TD;?(rJ4_ zG;hyWc2$YGx-BZn#B={m(o|7PN;_Sfw0^fb@x6Xxb!NwPVjKd*GHG|_4VhBWuM8?>rrz#4c`38-F*(E zt8Bi!P1*?4ef*J{Z~tue*Y0=CzM56QX0L7>&e>ArBkFk3Crbjq)h#YI$0VDn*y1*b z_}R(bz;emHY|9DJC(R493^mT?Kfcw*Y_i(p&_6z2xw)lUKWd;^7>jZ8ZWD7<*8MZ{38=VfN;7d; z_fgYV^f#?3Jn?CEGdP(3L@#IkjoA~^K)euv!0P%TZ6zB4W#(fG#Tg0E;D3R^Um20y8U0dhE(YWC2q7#9t(+#(CqJ8P z>Up_Z*}Jjz;0aQ^rocTQOm{V~;0a`IliiA#&P|xqZ=n7q>Y}=rJ064cwM91 z45mLK>3rh&cOwmm^<_@5(cdn_2AR*nBnug_0mYdXl+U-xOUf6eAxuyzpj=J`OG+=4 zm;F37b-)He*_;G92!4Gz0<={b3xia@IB8|Y=dGWCNU*fXJmpviOiVtA$FTF4!bKL} z{-&bXnQxuUzn6bdb5@K!AjqO7l>Jwf>>{4Zok%Jf%lA>^JjLXF&HB;>%;q!6aNX^^ zIA46%Yg%R#fYbQdng>#6gE}40yQn?u-;-NedX?{YI)*mz$AQUQSnHM*n=@y4o2}s* z5-b5Mu6xh|Byu+lyIPbAWT-T~d@c*#RxKSV!<@t4=?q5)9MheKYy#x>c=sT+nnAA=ci1hcOzkAWcqaKes^=!%m`y{p{Y~@F`SI-h z$$=jJduzR`0Dlvve=G2Uwf{@49Ok48%V0B%Ubsoc)M0wT*JfqQcW=&SFZ4}rC~{&a zM>(-a<1wXt4=@z4<4@@J{DkyvG$uCFhP)Ac5fu>y1~Ss$Sy&r*h*jX>-W#4B_wNpE z2@k6j7L~?ZIMfCw) zdFh@+{RNvxbu(%{Kc#}tv8{Ldf8o^umIl;ounaY@^F6}E?~KMmkENizD*mCZIog7< z@P|c91@bn($*{#6EY+TQeoMI^(LKQC|0g5Z*I)^YM%l+bSETnn;Tw|ZV@XYRAQ4g= z8CqeJw(ef@W=Vq0Z(_GIUfm7lRP^KvS-0fQ*l-b))G42rIiC#^%hYD48Qc2so*flb zX?QBMQSUYV&pbtvJ#OTrW zAK=WYRCU}7A1it1m@ePG!Ru8Yba{AEt;x7CnvJd&REJu^hf6&G+G`i#u=`u-3r1Ax zW%=3GRnzW}>%Fih;%e8e92yc^I>$*mla;Qw4l}3YU#_#iToAz@!qdtOWy0*b$^t5T zrBC?I?c({wPc6lcOZzU`r&_@BJs_VnSd6lf^=8t)L2X|s@*bVOvYd6^M!TIb?6H#Z zjgfGyR8>VUvAQ5N!U7)fR9&KdQQ{_S-l^*2<)=SV!F#~tq0Z%H;rV>%Y9l)yE5v?I zu6p5mr!8r31MPOa=&EC23x}uT6gn~q*-PW|woR|_6#qDlpYZ|wsKH$y;%t9yx)b+{uSFB&Y;(yHWq0vUyZOF(iBVW{o$Tnkm15b! zPW9X_Sn1k;9peKkPPxAVr$UA7c491(Y$-o#4qQ^Z_QQ?c6jeW7@+0!SlXupz?ubic zwbvq34G#j;oChNE?g1INI(01^9pFV~FR-X_w|l!uEcj@5NYQh!t*sQbC zP5hW>UK9u$QIM)j)g_Xw)lxdrcZ*kmjZQl<=R5FkV2crdU?oIQ;-q{&3A8KfO6DyU zUJt|Ncj|N+tnX!i2dm%xDV-jcAZuV*b?UViv8qqGsH->m{_$JOH#_!b0^#&4>1XVm ztB`rkGPgmYM?7j@G}Nv*G#38FxHo=KY?pvPMzUQ-P-g?_rjLvEr2o%nJEclP;a=nB zQq|{An&*5Z#Y8|9!3^LSa0_)Bwr8Xz*8NMEMO|g8bnH(@`E;QBNqR}|D^G>1#%ld> z+)1+KxCDNa(7w#H?%@>*konUL5sWnMLFZThX?8Hx7v6-N+u%{vYMy7dIBj@RX1#Xl zPZhU}I+NXsUmwcAhSH^$`3>4X`=?Rk=%5>ujq)Jyw_KssR@5qEPBCf0ezk~6>d!@p zPqbossj$W~PUrjrn6iNB~lI3CGo8I+mOa~T>cWT6BKLVI@ zydae1kIfjs^HtN2 zr`!oY+~&}80?18sL66BCWJj+x&t0qWQB3jXxOtz>EhtJbbiCV!grckTxa^lMzlS=- zqUk^>9Ld^C!)?96rqX(2^3r=}w|!>|)zUiws%S_5`&7FtDk~=g1jpxB9N$OEiz)gQ z8BMe#KEydK8cz$DJ6k*uo}^rspm~<=BjS4Z;glHIK!lU5jVB?VK-OdSAmVm=Vea;RWwg=%)YC;Pu?hO0arQbtBcP;VWy(UK6K8=u+PSuOfKCX@O}8j z?c-nHqxF=kMun|XyuR;NiE&RhXO`aWKMrBgUGUKQi;7ZIz;$ipoxt?8IiFzZE+8X6~_fijfvAcWwJQSXwOB+Ii zJufq$yv@VqW2$#D+1)pM?lCR3!r$sDJ8(YLw{4V<7BIHaRs)wSvS`LYP}*IX^U*;$ z2<)CVx}uQra`J13>rIlkh7=iXwpo48(|+?wBtbC+Dgr6N7pF53;rcN!9A6W^k@Fth z{eIU3c1-|NISy~9uT4P>zbtArGu~K0JDFA3)ByRIFw=O=+V$I70p?GD1f# z&_|e9SZ}c`*xxTDh6xpKZe>*OR`}WQF!rI)%ij@On8Ga=;}BVj_G(FE`#Ft#;E$;j z?5_Sa&ZR=X~rnsmmg)YBqD)_C?42z1ESxWH}SlPrEBU{<-emO;nZvfOqdP`Rnm=c2tgrV;%*>C#_p6%j?MumAA zjO=-2F>}B4=d<(v{J^Xk#mdSA-f?hZKRiYf9ilflf`K`#MdsAozVq=o+nB=q0-PiFx;}`6bDY+FxC z?-Cme(ZpjhYAEB|#-Hcj+n;%SUA}#}FGgIfT#}i!lmT`UKUs>0j16O-I{r<`+rU+2 zlz8fw(Dy{ejJW1j?Z<~xf>?vC9gT!yIB3i&nKLT8;tWc7B;JApm!o*zal}HA_K%(| z0~oNM*z&{V>V?l~khY`<7}P8UZ~kpEF|Himdhg=pcD9moQ{45!Xv~nR9)GpZdt~Au#Q%9daDeJMy^)xN4}TxbA}pov0=pToZ{U zZCvl7evLvwr$FV$w={e!=A6>c0#BOD3k`VizBjYGV^mI$^7cIC7hY*Qaqj_eXBGk( zJ>T+WA7&@B%F@;XHz^!VDj5IFQ|bnt>ANp0@0t*uax;csR##v}5HyLo^=?xL(Zv3( zp~lRf25`UNgrDUMt+rgA7%7!Pss7~~uy#HcrcF!(wHeX#DO=A^^4|SoNF8&702>|? zr&Ao#n9Kpo2b4s!(R#hbIQv<_h=TRkG3@)|mVK`ahz7$O@83*s@(KfM+&`r+b$xdT zcv5RQkZ?_o8Xf^Pe%Qh9q|6Y%F;pk*RmiS`63^Dvp1*1ekEa>~4W~7-sHlG$0qF^= zbw~?qm7~5th7xt(OpModYb4xg@`IXo-{jR>@Bw|7s1B3lUEBCrIoN^xGrrYt#aTls zB?oH7Y|0!-wPNn4==Y(cL+w|h=m=~Nx_y9>%{-dxBMEXXldxfsF9Wl>Yzyx3!U+TF zax}SM`x`9N7$W6b7Sfv^aEZATCbgYrli;d5qPyq#A{h86piN=}5zZ;ZxKrw-b=xv8 zi?pY>SO)6n(ULw5BdW+KFGZk~{Sz)i{XHp*>3h~4A?DTN41dE{)5fRRj8=}(E~1kS z0dOf;x~I&nTIz+_z2~%ZW$>?1kn0Yuel~D?cq8eFU^UKUWV0tqHaw{5xD?4rp>iQ7 zKF~8t3iGx$^~X&ER!v{j08qzDuq~i!ghZ>f(B7NYOSTiFgo2}W8%YBFUt6>y)=g`T zi`KBogZ1})iRg{awJY;jxYS1K1mFokUn9_lLWLx4+#9a#TXCPnE+@8SL}cxd3QN0d zMp8{!t6#3oju$_6>*g1b9H zhX|(`HHoy&eF?*fYNkXRJib%rcE%6*&jo`HmcfYHpEbxbi}THFmDH4FI)S4J(^IVWD?>Sf7Vq}|ec4Rm*%+8PVdXS_gNWsuR2?&-?rTF(hDEbpk zFs_}e9APRB+1YuR9&$>;Cmx&`bvDYT1fTi-*=^}HU2oE&a?WXrV;RawVmo%T|43J!a>w}r87GvI_a}o+O%jwtqLK?rzOqVLi-7W=)n`2EjDAKEAPJFSkULx_&aXQ` z^7WL{vp68Oh03hqxiOMA*W>)$0;<31M2uuU{W9l_-J)V(lkpXU4QW3b^Wxe3d?>xumf}Hj zAps<;i>E)l%>kwbB^Suz*!+>-vZ6M`x5>n6+TNZ;J0L9=!;VBKD+!djHwDiz`W&g{ zCnfUEm$$I8`Mr~+0F@s6Ye%1Jp`4ORl39s=_%;QJtAaK!Kk!Ii2he?^KrPEwSrILtvN0aZa2rC>nX(0Oo2u|JeBD0~94V==m(m7~6i%kNig;Y9+xwBksCb63Ymo`UZXLs)?F}NQ?-OH$B&e|=QbCNLR<``1eTrFxq%+wRuK3XV{!y~m3 z&T~fKQGe$zG4L4^PE;`l8G+8ajPbcCQm%K3^RYZeD025npSkb#2Ct=I{Y=yL1a0PG zuK;)bF;Rqag8&mJPl7$nejNnDN)1iy(Meyt7pL1x)cyHS#)FIqydopgT`iREEw$K6 ze|X3{Srt^056Ya7{ZK)VE2v;_$2ljBv*wgC<_mWr?Z~I8P%}|w^+)akEk%7L`y9xv zKVlH|Plwm&8jhI=-95u1cV}0@^(?CdIouGj!nz=Vc%e4E|0TG59ixgLdDSsX6e%!+ zZ*)-OOk0z{1@0B8qky)9k>9wYo2UuE<;P!VayLj-#WO;{ zXi9NZV-Q?&fXl)M!wOZ?wk0Q09p3%a9cHoEq}47LL>PxW%~-0Q(6?F?xF~74nE1_P ztj2OV=!cP3m5x)q2nX*?s07jH6$+fz^0`)3tDC*KdR5Cd>+}(x`rC>{Gyli{J_VS9cZCh*`!X{-=+Q45R8uEk=D`i7({2F+gzw$`{aGzaB^#ZR8?W33wpml6n%k`(e6#zqH7jd~ z@xAfrL^fOv8}>3SY$A1qEx61~8#sfW2Ubg|zwIt(Ie`1Yu;ES+Ld@!SAO54oGbIAE zeRIN6-%D|RwI7yCC9S^moNH9|S>qKg3plrluD5tp72~e-83!YT(#EKBpV`ewsJh`m z9^smK2J$iHJqUjGAHO+gQAIHqRdOoI)g;}?zeAis(`t2K>h@w~la7!qK*{=Vm<&(i635ouryw}XXj z$~-X;nN8u)5G`RhWRz{@D9HN=! z5KF0~8k!$$??wC^NI*@Aul~FQ-{c5AaZerTeK&CQ9l=MevM#iv?@cuCC++c@_DP8& zKZ8(E)DeW)eIqD&5<%M|QfWEk&#`c3huM$jS{yVT&Fz{T_8mZC^}XGTCY0qV<@0l_ zgv`P-_&=}J-}h-82s&Llx!_LesUc9U@?Mo#&m;4ASJf1b*w?hZ5(LBHxuz3M>{XMm zj!qU&$4?8`s!ll|W4AxZ9cSrrPS1bfV10PZdS20T#z?&|y1bg=$K!_6Sc$Ae+&K$3 z^q9kZg`MieuH{hp5MB9Fq8J9$Q1>M73z#vA%54m3p>#F~7v0oshc($^s!C2fG-alR z@&BH5=hCLAd~K5}j=-H|?H9)12}RHz9?SomZh8TxuT!(sAnCZ0fUMfo?|kEiM{P#C zCvL%;uov*C$2@8En_5nA$L=B{=Lh_bu-=gcfQNz*H8E=KUHigZ{nLK6r(tckdOH6z z*P+6$HEX%I&j~Skv(Xa+-di_p22w(01~a^FmauSf5LApqM>~(ycJ+osmxU_^M)>Q! z`i2t_-xhDWbriHD3c0m1)fWl7U7dEGd&x<+t`S@L@hSS*m$W0bR`Z%-m6V1y;J(q z%F{Ii_1d*?D z#i|&oOHcx=1fWnSriY#p?KtatkJi?lQpG!$IYl=oXfsZzr>a(cv?onRzF}aOKXl}f z3Rr@?*GH-q7Ebgu@g$wYEbje^Trvtv$|?z>dbf4tmwgYd$4G^1lhWQOAx(NC-)9n` z8+NrOd$ob2XQYumZ*{v)MH%ZZmQ>&JbmRx4!H+R-MdyKY{>JzZj!J{WVd$t@e zS0mvWC)M%H$*QF#LL$Fq7M7WftKM+Zc2UXN)`ckk;46}jWY1g`r(GPJ#=kHJxHcAQ zNUyT08?*XHYME58!|G1>Whm_CN;FQy_5AOkBoMUlH?l$NcS?*Ggb}ntz~7ZJUL1cv zXAJ;l0z3A4hl75+`R^-)_TR8kC*1rPAnACbsNjBngc|WL! z0SghyP&?{W5f2}1wxJ%|>Bg8A$#s@Uc7?mT2|@ z@`3ziBe!GMRxVbQ-F{7SExd=vwp9GS%DMaDN4b&x4PF6y<~Oa8m}?akWSpDMog&Wm zqIIuE)iX^C&WP~znO>Yj1kW|KMjE^E1@r@(`ISDuYK~(lJ*Oo;ef2}jn!e7v%z9EM zP)8Fg9T%Pw7gDhF|MyWtK+d8@Hv{?O0&Y>MaB*yG-YLWHLO71JroK_XKvr~R z4sBnh;GnG*Y_J^Kz1J4Cciw%^F`s{Y)=-(bg=P(!D`FcsWQi ziuPLlV8Hfcj_FXt`6l|>re2FAdSi|p9)RKKFzURgzr--~s@-QQAlPBQll}Ac^x$?O zW5O&zJeYlghBew#r0Z9{uCw17)4!>DPKNF8)$@-8dDO1>Xn@KWfPU&V=E@Vmm+)zR z3Ffu+UiR2V`{@Ud)U!wLxZ18pj@ZH47d|?sw$j&@voT_XoJ_eCbwZXTOg`JQGx_;^ z9HuXfd%MmBD*%wARK7lI>73Fh#c0_FQG_fAaRMMIUKeR7{mqh|sSi2g`?xb>{rt6f zIQsb%JetFI_e-H;*9S=yCm)-9dZyD(q_e)M<9BvuXgpYTKPDN1v(EjR4?%8Pe_PrD z9cg-4MKUY_Xuh2=8wNWJ%MDs-qC~-P(Iu&0wM5(}zvsGyC-9Corg0%oZ zLXQdTFbf!y1R>6LbS=~^&|-#0qOKI52RZH6BZtlb)2dm21u&@zZMN!1*aDk+6fsWq zs+NQaO1|%rYOM}1RJSF_uS+GYe)eVPU3+#)W+L+RVYATKrpaMg{4RwZ*kL26B#9?q z1_>k1Wr$ASOM#v}tT^Zt7(Uo3X20g_{Z!Tz`BX?)HEcC*)V%ARM=hj)laQclcR z760kdKl`A~E){<-d)v7yt3Z78tf^297AICe&ul7(Xm_8ix!ly-u%?m<7-VEz7v?N| zt$tYA_q$IFHh$;+LWQ<--wQKB?e#X+xP3Rz@x0Y4>Jng&#{j8Re6y#399oChcYyH> zfz@T~YCkN=wAk?(pO*D%7hNJ@-&gZFv-?eWpYb=*jehGIgbzKQkxNvxXb_G@MnE2FTHL0rj6 z`zzgO*tMKq2amPr#VrR;!Xg0H|7@5|DdXM6DX_B-un1rAR2R(9v3IKgAAFbQhy9Dy zC+OP->lgsQ@0)XDnR$PE=<%a>j&r^nkYdj{d>#EYdrfyu1mc?qim`Yo!cZs0N|7IO#xa8C)Ojim*7Jyx(_Ak z`_=EuQ-H4^5UmcZuGqXKs*%%I>KP{HK1}`qKJ7gHC9voG!xXC%{sdf_nFwGO18>l^ ze&__d#e6aGLd0Idd1A(c^zX#(g!^Q20tMq}cr%PdeDhg-cv!(IyLU*a00SC4>FHd{3#4aUs@%cQKmE^cx=FgaDIoy+ZM zj`gaCp2s@{KbgA_c<#xaJ{h^**U!ZAhU*HkBB0hfK4jY4lL@Q@1OixMUkmLwWmjf) zVmg{8|1z2}WHyx8#_NaUV!aI4`(Zfe!ASro4&frkh~c2^VeYgfGeBT5trXqAkL7v^ ziWzfpbEb>y5iLBmphZ}^`7+dG&*h@t)xygiw_rxSsxo0c#VZ+=+)eo_#|SlHUO_yA z$6VdKX&@xS+Iv$MpeUgN7t;U)3rdDu!+k3FHfTE@ha_B^4-iM}+dFU68BLnRT`&n! zuL9fILYLX@;eMoy;kf7l8CL5TaYZow#E`As>UG(YGMH4Py3bScx=yvKgH>C0i9btt z66G7&m#;@=v(otXD9w~b4YvQf0OL5MtsZct*J~rsSn{d(=DFD*G76oF&1h!<9S=Z zZaUv*W+PfaTvUXF##s|Pgy#bQjm*Q&lWY$A3JOnWhP@UmW&lF^ITAwSZNWC@oyb3j z$5a^{1_0)K+pi@v`c~il3}Q9F`6i<%;ydCqph-l@?v7f@Ac&I}K75ul9Vy)_WRp1? z3qeWVCVoJgYf!kiMbUTE?DVV3`f%0XaCrhIyx)K(#)tYsYdd<85POHpY@4Vj2+%k8 z%@r(W>K)O>%b$mcGGxrl#0!Lq&s1ibXT65<`*A@c|)tlJ8qd&$b986sxFu0ijR(lVZb(S0fO}sQNfI$F& z=KcwSB>77?75hl;c&)``gBJu;4Mgl3UBG^)CzrCuXBgnt-o`_?oICIFlFiGMB-ZU# zhE4|xGUh4W;aT)qG7@TlA71hd`JWaXvuHZ<1Fd464vGh$sE<>zt7JSup&SLw0lQeO z%0+_OTat%?l?39AC=QySn?;k6EMcvuIvvapnqW!AlF7|rLTm~cQIc)J%&0#g=OF?a zAW7^;BpaEz#n0pt0i2FV-i~m82Y!Owu;*L+&^7Yd@F!={j^u`C*gGBA$Yc8@n2IG6 zxWSSiC}0-I_=>kpKOl|B{4IVa=Lx7_a>HE@b{5Dqaj^9F_#t|7!zzpb_w-=Itept2XoiCk3v@b=iS=N~_fxU^WFxz6q<}f#;`7t{fZQc}aah|W!p4CpSmk#Xc*r9b z3BnJN8UJ8bK=K`|$7>lNqWMp#6F+{5cRF;4viSMpQ#hp|K6s2*;%&$l5g<4a{=ZSgqQpuq8quL zgnu-LM`}mT6WTA5h9-37@YwMWNXyft<%7t1h7>UW!>gkUy8Dj`XqW?ZN0zJqU6}pR zSvQEN5xB|Z6MjRtci5@_YqH@Zl7@`%2^i+S8l++`kk=V{?Zm8`*?+Ia-Q8jT$L@D{ zO#TCs=72#Eye8ARM4~AIgy|PxefM_Q0aq>P4H~k90_J}hidbgd03q7JKyoe++A05g z5NLw)0g3xD3U{qk?Dl`eLsBO@mmd8$EP+tG|lsT+F9oE|5{eWoFywYU2{B*S*PH!0}Y6ohNTBUB7v1?^}4qdq)O zDKyI*{O`dk=t1p&EnWjH{yu*&EV*M~AR_-}10Y<%YX^FH<302m+1b=4)18N2J9Y3{ z2?yxSis4{bF~>n8rT=DwgG4g;k4sS=8VR5VAq(goG&eHhwcnkXa;O79K|<2ERy{~u z$_E-?aRut`pUeS4rXpsB<6n12AmLFR{Iw6sB>iCFlscg9v=5lH(mJ5-{^REy0^R)p zISObiyfbSFbw_qgwaIuPs5^+;9C!_loik8({|G^=Araw0v|(->{xRjT}Gd?JCsUC-sA2fzNp0HFAh>Hewta zmehewXpwsRw{Y@M`v>B=d=t!!;z0ai&@gHbMyLo$@%cg9P-|3A4*q~-_~L*q^)xMb z<@|vmzCET1pteeptNcYKnAc+0Ft0K&SNN@iPFR0AHSxICBcT zC>yyZ-ne?Bm-66*e07BN3 z9zS^QX|z5`vwO|lZwcCqF#Hu-MyA$#CHZn$9g$8!#^l_j!KU{^115#0gOPj`?}I4* z(Ccr{K0N(ikTUrC&6_uad8Z%Zs6I@GgrDiYJxzN(cp`M%K)9J!Bw&I=k>y1UG3-!w zr>9wK2>jCq|80yMrXp7g!9VoU%IcDq;Sk)AKw=OGkh~92l3sLEoVrcA8VjBaAS1nS z2?S_K*Do}ujY-!=gUbLp>BZtHG8WSHHuITA(lwyw|KCfnd|n@~k|P|<&72K5b1WLm zXS?xAyV2r6T3WO7By9vd&;+K+Ul00WCKV|uFB~hxSmPEzoad9fLQYP7th(FRxdJ*G z?*|>LjrJ)=KnN}E-IH&WfJ?%+jgR%!_|=TO_+ud1m1AuNN3)aeJJxx?16C&R&3j43 zW0O#3UIu7bS$5t7w8m4fIlcxytQJnGuo*#Dj2KaIx@s8GJZ8*Kh`c-d*0CXaajdqD z9s%nu^euvDe?8@P5Cq&ZGwv2RbvuAdztR>VSci&cf7mNW#LXt%B92~gNBUu?xI7!} zQxq`d#WEf>2eT2)8Ha-lfPq7p?Mq8t*htY$jh@ltRrpA&4Dw-uC}`X#-A2}m;Ib-X zGe5FZy(iag7r!cS)M&k!>3ct>gjY2LZ@DdQtr9wW~+yW&Gxnn%$+r=+d3rWlJ z>2ZiPU8Wp`20vSpLKe@FvD}BhOvLwx$zCknFm8G=$a9!GXm7n-_cfBrSieCRel(;7 zJ9XN4#Z%t{l0?SxY*B)VL2mt-g0G@kDqYX zCKksud<1c9qIeaVBFZauI3KglbV=Z*eMpH-spr-#bHlQ{I9{^PtG8Wt|BlbuspYM+ z^Wr5*IR$eHTU4Giu) z*u1Ebn=kzGc_YuXin47<2t7{Gr`c8*n^3AeU)eR9)PL2wVw>#6uf{LjpiASk0xh;v zqEt114_ZRes#~8?zecm_7X%yzAU%hX9`((X>01r&>8j_vR4%-`HT5>`hoqm`ilzW2 z$5!97^t$TqP;qf?Uge8|`@$~&(N`fxnm$uEvT>}Hdm)*GVCV{X3(aC@DD(X96tgaD1=O$>x=)hUmVG%L+Q8>8ZKKdskV};xHS6TJ# zr))NUP^%=q*Fix`|FtqCzJ>VqWSw5%bU-=VYKsl%wfv4>99e)KghBgh5wYAu$~0s4 zf7sLpxt$?HXZ^%5PNp5W+K=N^iZY6m&n*hfIt4Y0_rAC`2lYP7Q@wZ`cn<)|ejo9% zovlo|LA&B4A1&$BuE_Ux@6egyvPlAbQl(K^YoT=Px46ux5)%ao^p;z*tsQ=Lch}~0 z)!EoWkM2qt9cofn25|kCD(7YXzQ8V;5k(Q6_T0&z3v1>AnL(}nxB_+6Hjg@!=Yw=M$whHa0Yv_KJ{}Jk7CmNUT}&BW+1c-F7tYup2mZGT)8xv>U%O2lLGPP~i z%u-@#Z`25>;W#4FloO~vAXJ?ah0WvAy`tmCQhRe^h0vMl_M8==FA>=<>$`=Etc54h zFJO7|Q(y`f*YD8zXm*r?P(c@L@oV%8wyK8uYx3ovBUz^DDnPz0qwFD@_~)RH%CSSW z!_#oq>05`|r)&2wMU}Pp@+zHsiq6q@E6P-kZ(~S&ZzGUzU0KzzZnrjEP!^s(+Ujt;a1rzn>5)a zW%gUnj}lTfyYy`PfoV-&!@TpXN8Ani#%KM?5s*QjcQYkGv8B60i&%5PY5NUB$`=>Csj>yMdv|frI z9<0M;^~I;|vJV`kx6tfnZ;qNq9iCk(#KjIc3~@L%l5M?;q4qhCnpd*Kd`MdnC9B58 z^!SDFbZ~ip4npb+#}tO&7;F*5T)F1;(zder9V-HHOVk3gX*T&TO}T^W!-6a(x~oH6 zW4m)+(D%7e&(!3+;A2r}#s8Q4dRK}F&N>}8xA33>#X~xpS`|A(NmBYGR{$t)pXRz& zdR4hj=~3Ur150<4rcu%GJ3Nmx-NltCTV}OvueiskK7Y|^$e;eIvx6@!AK}dX1O-dH zqAMMp$_vCpOVd-8w*?XmhvtqBqEzA6<6=a6=W=RyRtzH`Al_Pm4P z{GfvNQ97D?YIv8#V|6o;)P3-AcMU?URj@@o{+5KQGMi1hCUrqTa=u4_d8_?qY7gZP z^Wj0=wwU6cWbNCJgtI&lL%#~)W_*!sX7RqIgbY-!l0}!_TNEds9%FpnDT*H!iIu&j zRAV3-7%76J`L&>GnS?6mgKH<21Wn`Tg!c52M>+xzMAn?Q``i=+CR!U@pN}sHnspL1 zwzVtj+6P^9v%cnC%*TzkKJBQ;ty2CqTG0Mj`H^A{RE?G7?GOF~$XQNtAHbI7g`S4O zDI}EKujx7evO&(ZYM~-K9w({3=97Kj|DU~ZK;_<_WJNBo3@HB^BUpTNj~)*k-7=`Y zZM2x9StN&_4`*keJc_BvX6;MHy0k}Q9eL97;TqlsXxFxTYf*q;U!>g9Ob@r`&nYiG@WARLj)VI5u!_8()eO}v-FBHyv z#$TyZ@qzJRt+&rn7`84}Rcz}k3+g;A9Qthd{i|V{IIH(#PUE9vb1;DBxIg+;qx32~ zD5>=7K=dOc_D?nmY@hi%Mxj*N(i+cHxmp!In#d`e@{KI;K7;ff4B*jQkM+4#%Y!xT z5)hVr`>xIo7xdNYh4&p3zgJXn_j>h4662F@HR%kc`CNFNG2JnC6Jg>}Dec2Q^PRsKjdeCf^%I z>Wp)Zar$mHZNYh;UXrbhU#y(W5lhaJn-?teg{Y!m^lRG^O8k8OxO^725i^g!ZWUjm z8p@@aH*|qyyg(4xv7BMovaa55V(`DMGWNRl9h1A({_SbhlXBcg-DV9bMK#e2GHdx| zw#JE^LV`y1qiSEuC1aqLtGF92Yb&pAaNX|$s|-#eu)Ld;!fJw_cabCb(6;#~k>wl7 zKIocCHa!#x8hr3~4#N^AJU}q#=_Xz=7=7&^#9=r6$H=OvCR2UiplKIJbqHTc=Qm2 zu;sa)yHWO~oOcj9>~&%0h5c0noO_hUSIA9ogLNoC=lq4EU#B+5L9FEH7nbdw`ZkFp z^>)?r_;TdfakZiaLCO8RGt_=&?f9`*CGNPgw6{{L)mxH}kqRE7=Sj*YBlRSD@=um; z(D|y%9-7IOJ*SsFn5Ge|4%l5ItrU6+go^_nCx|_frtu-ALeUAPe=SO46)%5+wpU0l zx_j}Y1GscdsCYs+Mol8zIDzS}1&#?xG6Dc)X3sI4cpGDo}6fNhckI>lG3MoFKYAX5cCb z!!5I&^cs`Lyk?(lx$>NZv}=P;x{{IOEzh59dGGI*e;d2t-^YSrhi+Kq-<09x1~I3%dvl5j1cKoE7p@$xhP12sGcxzblmU^|06U!CInH~ zu~<>Zgk&d#sU&vNU;iT{wN398PAs|NMj}jnbV9gsO!&_rWT#1l)F*_Y$9^+*LddE@ zB3wOj0rMv$!kqIbI|d%JD)^6(nY5$c39GDTB*Lr{8O?J@gkLV45R#FMWy3i5CHY7 z@yQ7%SAh0kjc?BfSUz(2NkMbTcliIku~lQevd=jJ`Nv}%jGk_tsRuuJ6g`|l_p;WlDe1ScFhHr!d@ehbj< z(vaQNO%7yT?-MxXC_8ll=zoJ69;yr*D{o`8t6YKKO<8Z#;buMifnO(IV=-+x7z`!j zr>CbirO8Fc()3SH`^F+KxR)m>dDlu=b7Q8neAN2w$pCG$q8XGujz zi;so+dc?t&H)8pbrJ3(RP$u>t3Zg;*Q~rp2>h+ ztSxoA$+w<#o`Vp_X8I1yxUAZ{cw1a#`mjM8j2F?D6-2eotl|4z2EVs966JjcNO=ed z8ncdy2NPyyS=Jf2$nHWas@`}PV}6q2=lopNnv@x|{=n^HGM;S1tms8tBD42sP`x zW%kiSi8ua8}ABahEFOR*E1?fYz2mX_}ot<0zA!bsvk5afW@>#dn2P^+NNe#)^#K)HkD$vL^5KqCN&yoeuC?tWjq6y}HOgI$>v=Kr)B;%ls{| z0rQ^XK3VK?DSEGdNk*OFTYD+b+QaSeuj`d|OLMVK2(ba2(;u*Dq8XO1x)We-Q{{7pj(9dx)sQfDDw8AJ)+b0SQ!K1R+!HhM*!Su7Di1fKIoGdi3{CBH{Z8Ipi~$iZ0skf% zqhgC5HoG^?H0@SU`f~w0JTiSu^*qr|k1Dy_WyBH^Ky}oZu;+!)Ft0jD8}zqnj8~;c z$=;iaj76f&s{%pQc+k9#T2At=J4)#DZ9{*b=^}s*0s>k&*1P;2AEWb&Z}?y82zyxC zU1C$1$+I?Hb;(y;Y5Tsofil;xO(*i*h$+J9X%nu1jRwrr0TB%Bf9?@f^;pc+Y{VmJEQL5iK_q?nfaPzm~U^+2z0*1Bw8sG0zMFGh| z9x7KU9H_To_LGL3GU$~3!gFpWcG2a&V0v1Nvs<1O_%hluEA+hG9&=W_(j>_#M*8FE zG;gZCvT|h};aoI6p-z)Z#&VUJ=V{>dwDqj%w>!^CCFSS?KzsQCQ23r!+VlVQK9!Qy zbM&OFk!Ed_T(?gu*Xik%Pk~|Y{uPqyOJ>ugo`!^Lz*#vBtEcDx$ZS9|mj97?gJf_1 zN9Jxe-E@LY9s>5KSUp+(N5=k;k_-4B+2Y4QY~=sQG|i@sPO2S9#>QF={~wwDeM