From aae02c543a8b17fb9fb47edf4989936f2b929499 Mon Sep 17 00:00:00 2001 From: Thomas Garrity <31856350+poortom1004@users.noreply.github.com> Date: Mon, 19 Oct 2020 10:59:00 -0500 Subject: [PATCH 01/14] Update active-directory-security-groups.md --- .../access-control/active-directory-security-groups.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/identity-protection/access-control/active-directory-security-groups.md b/windows/security/identity-protection/access-control/active-directory-security-groups.md index 61198672fc..5e7db538d0 100644 --- a/windows/security/identity-protection/access-control/active-directory-security-groups.md +++ b/windows/security/identity-protection/access-control/active-directory-security-groups.md @@ -3368,9 +3368,9 @@ This security group has not changed since Windows Server 2008. ### Server Operators -Members in the Server Operators group can administer domain servers. This group exists only on domain controllers. By default, the group has no members. Members of the Server Operators group can sign in to a server interactively, create and delete network shared resources, start and stop services, back up and restore files, format the hard disk drive of the computer, and shut down the computer. This group cannot be renamed, deleted, or moved. +Members in the Server Operators group can administer domain controllers. This group exists only on domain controllers. By default, the group has no members. Members of the Server Operators group can sign in to a server interactively, create and delete network shared resources, start and stop services, back up and restore files, format the hard disk drive of the computer, and shut down the computer. This group cannot be renamed, deleted, or moved. -By default, this built-in group has no members, and it has access to server configuration options on domain controllers. Its membership is controlled by the service administrator groups, Administrators and Domain Admins, in the domain, and the Enterprise Admins group. Members in this group cannot change any administrative group memberships. This is considered a service administrator account because its members have physical access to domain controllers, they can perform maintenance tasks (such as backup and restore), and they have the ability to change binaries that are installed on the domain controllers. Note the default user rights in the following table. +By default, this built-in group has no members, and it has access to server configuration options on domain controllers. Its membership is controlled by the service administrator groups Administrators and Domain Admins in the domain, and the Enterprise Admins group in the forest root domain. Members in this group cannot change any administrative group memberships. This is considered a service administrator account because its members have physical access to domain controllers, they can perform maintenance tasks (such as backup and restore), and they have the ability to change binaries that are installed on the domain controllers. Note the default user rights in the following table. The Server Operators group applies to versions of the Windows Server operating system listed in the [Active Directory Default Security Groups table](#bkmk-groupstable). From f11c8139d7340f866cf435bf471d6dc35133b96f Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Tue, 10 Nov 2020 09:24:57 +0100 Subject: [PATCH 02/14] Update vpn-conditional-access.md Updating the note describing prerequisites for using SSO with information relevant for AAD only joined devices. --- .../identity-protection/vpn/vpn-conditional-access.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/security/identity-protection/vpn/vpn-conditional-access.md b/windows/security/identity-protection/vpn/vpn-conditional-access.md index fc09e68a62..002d10e812 100644 --- a/windows/security/identity-protection/vpn/vpn-conditional-access.md +++ b/windows/security/identity-protection/vpn/vpn-conditional-access.md @@ -77,7 +77,9 @@ Two client-side configuration service providers are leveraged for VPN device com - Upon request, forwards the Health Attestation Certificate (received from HAS) and related runtime information to the MDM server for verification > [!NOTE] -> Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the user’s VPN profile. This will enable the user to access on-premises resources. +> Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the user’s VPN profile. This will enable the user to access on-premises resources. +> +> In the case of AzureAD-only joined devices (not hybrid joined devices), if the user certificate issued by the on-premises CA has in Subject and SAN (Subject Alternative Name) the user UPN from AzureAD, the VPN profile must be modified to ensure the client does not cache the credentials used for VPN authentication. To do this, after deploying the VPN profile to the client, modify the *Rasphone.pbk* on the client by changing entry **UseRasCredentials** from 1 (default) to 0 (zero). ## Client connection flow From 99dca4838c0fda5a1d603ba6124aae6a88b068d1 Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Tue, 10 Nov 2020 15:03:00 +0100 Subject: [PATCH 03/14] Update vpn-profile-options.md Adding additional information for the scope / limitation of the VPN proxy settings configuration --- .../security/identity-protection/vpn/vpn-profile-options.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/security/identity-protection/vpn/vpn-profile-options.md b/windows/security/identity-protection/vpn/vpn-profile-options.md index 29b5df1daf..ccb29a9823 100644 --- a/windows/security/identity-protection/vpn/vpn-profile-options.md +++ b/windows/security/identity-protection/vpn/vpn-profile-options.md @@ -34,7 +34,6 @@ The following table lists the VPN settings and whether the setting can be config | Routing: forced-tunnel | yes | | Authentication (EAP) | yes, if connection type is built-in | | Conditional access | yes | -| Proxy settings | yes, by PAC/WPAD file or server and port | | Name resolution: NRPT | yes | | Name resolution: DNS suffix | no | | Name resolution: persistent | no | @@ -45,6 +44,9 @@ The following table lists the VPN settings and whether the setting can be config | LockDown | no | | Windows Information Protection (WIP) | yes | | Traffic filters | yes | +| Proxy settings | yes, by PAC/WPAD file or server and port | +>[!NOTE] +>VPN proxy settings are only used on Force Tunnel Connections. On Split Tunnel Connections the general proxy settings are used. The ProfileXML node was added to the VPNv2 CSP to allow users to deploy VPN profile as a single blob. This is particularly useful for deploying profiles with features that are not yet supported by MDMs. You can get additional examples in the [ProfileXML XSD](https://msdn.microsoft.com/library/windows/hardware/mt755930.aspx) topic. From 074bc73f723625fc63563ed01df40586cef1d216 Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Wed, 11 Nov 2020 11:37:35 +0100 Subject: [PATCH 04/14] Update windows/security/identity-protection/vpn/vpn-profile-options.md Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- .../security/identity-protection/vpn/vpn-profile-options.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/windows/security/identity-protection/vpn/vpn-profile-options.md b/windows/security/identity-protection/vpn/vpn-profile-options.md index ccb29a9823..4c4e67842d 100644 --- a/windows/security/identity-protection/vpn/vpn-profile-options.md +++ b/windows/security/identity-protection/vpn/vpn-profile-options.md @@ -45,8 +45,9 @@ The following table lists the VPN settings and whether the setting can be config | Windows Information Protection (WIP) | yes | | Traffic filters | yes | | Proxy settings | yes, by PAC/WPAD file or server and port | ->[!NOTE] ->VPN proxy settings are only used on Force Tunnel Connections. On Split Tunnel Connections the general proxy settings are used. + +> [!NOTE] +> VPN proxy settings are only used on Force Tunnel Connections. On Split Tunnel Connections the general proxy settings are used. The ProfileXML node was added to the VPNv2 CSP to allow users to deploy VPN profile as a single blob. This is particularly useful for deploying profiles with features that are not yet supported by MDMs. You can get additional examples in the [ProfileXML XSD](https://msdn.microsoft.com/library/windows/hardware/mt755930.aspx) topic. From ea38b9d7d7c0644c7d50a5b031f9fdd2a195981a Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Wed, 11 Nov 2020 11:41:25 +0100 Subject: [PATCH 05/14] Update vpn-conditional-access.md --- .../security/identity-protection/vpn/vpn-conditional-access.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/vpn/vpn-conditional-access.md b/windows/security/identity-protection/vpn/vpn-conditional-access.md index 002d10e812..fa1a76285a 100644 --- a/windows/security/identity-protection/vpn/vpn-conditional-access.md +++ b/windows/security/identity-protection/vpn/vpn-conditional-access.md @@ -79,7 +79,7 @@ Two client-side configuration service providers are leveraged for VPN device com > [!NOTE] > Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the user’s VPN profile. This will enable the user to access on-premises resources. > -> In the case of AzureAD-only joined devices (not hybrid joined devices), if the user certificate issued by the on-premises CA has in Subject and SAN (Subject Alternative Name) the user UPN from AzureAD, the VPN profile must be modified to ensure the client does not cache the credentials used for VPN authentication. To do this, after deploying the VPN profile to the client, modify the *Rasphone.pbk* on the client by changing entry **UseRasCredentials** from 1 (default) to 0 (zero). +> In the case of AzureAD-only joined devices (not hybrid joined devices), if the user certificate issued by the on-premises CA has the user UPN from AzureAD in Subject and SAN (Subject Alternative Name) , the VPN profile must be modified to ensure the client does not cache the credentials used for VPN authentication. To do this, after deploying the VPN profile to the client, modify the *Rasphone.pbk* on the client by changing entry **UseRasCredentials** from 1 (default) to 0 (zero). ## Client connection flow From 02c827d6519422a73e2deff16618d5425aeaac76 Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Fri, 13 Nov 2020 08:41:35 +0100 Subject: [PATCH 06/14] Update windows/security/identity-protection/vpn/vpn-conditional-access.md Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- .../security/identity-protection/vpn/vpn-conditional-access.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/vpn/vpn-conditional-access.md b/windows/security/identity-protection/vpn/vpn-conditional-access.md index fa1a76285a..7368d59e07 100644 --- a/windows/security/identity-protection/vpn/vpn-conditional-access.md +++ b/windows/security/identity-protection/vpn/vpn-conditional-access.md @@ -79,7 +79,7 @@ Two client-side configuration service providers are leveraged for VPN device com > [!NOTE] > Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the user’s VPN profile. This will enable the user to access on-premises resources. > -> In the case of AzureAD-only joined devices (not hybrid joined devices), if the user certificate issued by the on-premises CA has the user UPN from AzureAD in Subject and SAN (Subject Alternative Name) , the VPN profile must be modified to ensure the client does not cache the credentials used for VPN authentication. To do this, after deploying the VPN profile to the client, modify the *Rasphone.pbk* on the client by changing entry **UseRasCredentials** from 1 (default) to 0 (zero). +> In the case of AzureAD-only joined devices (not hybrid joined devices), if the user certificate issued by the on-premises CA has the user UPN from AzureAD in Subject and SAN (Subject Alternative Name), the VPN profile must be modified to ensure that the client does not cache the credentials used for VPN authentication. To do this, after deploying the VPN profile to the client, modify the *Rasphone.pbk* on the client by changing the entry **UseRasCredentials** from 1 (default) to 0 (zero). ## Client connection flow From 776ea6eefc2364f08d6d3c2cc8f325e0914b032e Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Fri, 13 Nov 2020 08:45:06 +0100 Subject: [PATCH 07/14] Update windows/security/identity-protection/vpn/vpn-conditional-access.md Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../security/identity-protection/vpn/vpn-conditional-access.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/vpn/vpn-conditional-access.md b/windows/security/identity-protection/vpn/vpn-conditional-access.md index 7368d59e07..9aee353de2 100644 --- a/windows/security/identity-protection/vpn/vpn-conditional-access.md +++ b/windows/security/identity-protection/vpn/vpn-conditional-access.md @@ -74,7 +74,7 @@ Two client-side configuration service providers are leveraged for VPN device com - Collects TPM data used to verify health states - Forwards the data to the Health Attestation Service (HAS) - Provisions the Health Attestation Certificate received from the HAS - - Upon request, forwards the Health Attestation Certificate (received from HAS) and related runtime information to the MDM server for verification + - Upon request, forward the Health Attestation Certificate (received from HAS) and related runtime information to the MDM server for verification > [!NOTE] > Currently, it is required that certificates used for obtaining Kerberos tickets must be issued from an on-premises CA, and that SSO must be enabled in the user’s VPN profile. This will enable the user to access on-premises resources. From 3daba7dd0096a341b433d3e002bd78ff5a259ede Mon Sep 17 00:00:00 2001 From: msarcletti <56821677+msarcletti@users.noreply.github.com> Date: Fri, 13 Nov 2020 08:57:59 +0100 Subject: [PATCH 08/14] Update windows/security/identity-protection/vpn/vpn-profile-options.md Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- windows/security/identity-protection/vpn/vpn-profile-options.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/vpn/vpn-profile-options.md b/windows/security/identity-protection/vpn/vpn-profile-options.md index 4c4e67842d..077c2d4c8f 100644 --- a/windows/security/identity-protection/vpn/vpn-profile-options.md +++ b/windows/security/identity-protection/vpn/vpn-profile-options.md @@ -47,7 +47,7 @@ The following table lists the VPN settings and whether the setting can be config | Proxy settings | yes, by PAC/WPAD file or server and port | > [!NOTE] -> VPN proxy settings are only used on Force Tunnel Connections. On Split Tunnel Connections the general proxy settings are used. +> VPN proxy settings are only used on Force Tunnel Connections. On Split Tunnel Connections, the general proxy settings are used. The ProfileXML node was added to the VPNv2 CSP to allow users to deploy VPN profile as a single blob. This is particularly useful for deploying profiles with features that are not yet supported by MDMs. You can get additional examples in the [ProfileXML XSD](https://msdn.microsoft.com/library/windows/hardware/mt755930.aspx) topic. From 8e927d1b64c04bd1e46efd67f158ba9669fca1e4 Mon Sep 17 00:00:00 2001 From: Max Stein Date: Fri, 13 Nov 2020 17:43:08 -0800 Subject: [PATCH 09/14] Updating Intune screenshots Uploaded new VPN policy settings that are available today within the Microsoft Endpoint Manager admin center: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/8637. --- .../security/identity-protection/vpn/vpn-connection-type.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/identity-protection/vpn/vpn-connection-type.md b/windows/security/identity-protection/vpn/vpn-connection-type.md index 92c4d2b8c5..d825487b05 100644 --- a/windows/security/identity-protection/vpn/vpn-connection-type.md +++ b/windows/security/identity-protection/vpn/vpn-connection-type.md @@ -7,7 +7,7 @@ ms.sitesec: library ms.pagetype: security, networking author: dulcemontemayor ms.localizationpriority: medium -ms.date: 07/27/2017 +ms.date: 11/13/2020 ms.reviewer: manager: dansimp ms.author: dansimp @@ -61,11 +61,11 @@ There are a number of Universal Windows Platform VPN applications, such as Pulse See [VPN profile options](vpn-profile-options.md) and [VPNv2 CSP](https://msdn.microsoft.com/library/windows/hardware/dn914776.aspx) for XML configuration. -The following image shows connection options in a VPN Profile configuration policy using Microsoft Intune. +The following image shows connection options in a VPN Profile configuration policy using Microsoft Intune: ![Available connection types](images/vpn-connection-intune.png) -In Intune, you can also include custom XML for third-party plug-in profiles. +In Intune, you can also include custom XML for third-party plug-in profiles: ![Custom XML](images/vpn-custom-xml-intune.png) From 044dd98a2779c6eb6fc0d8329cc6ff4267f62502 Mon Sep 17 00:00:00 2001 From: Rafal Sosnowski <51166236+rafals2@users.noreply.github.com> Date: Mon, 16 Nov 2020 09:54:28 -0800 Subject: [PATCH 10/14] Update bitlocker-overview.md added requirement for non-active partition --- .../information-protection/bitlocker/bitlocker-overview.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/security/information-protection/bitlocker/bitlocker-overview.md b/windows/security/information-protection/bitlocker/bitlocker-overview.md index 2b79e081bc..fe5a483d05 100644 --- a/windows/security/information-protection/bitlocker/bitlocker-overview.md +++ b/windows/security/information-protection/bitlocker/bitlocker-overview.md @@ -74,6 +74,8 @@ The hard disk must be partitioned with at least two drives: - The operating system drive (or boot drive) contains the operating system and its support files. It must be formatted with the NTFS file system. - The system drive contains the files that are needed to load Windows after the firmware has prepared the system hardware. BitLocker is not enabled on this drive. For BitLocker to work, the system drive must not be encrypted, must differ from the operating system drive, and must be formatted with the FAT32 file system on computers that use UEFI-based firmware or with the NTFS file system on computers that use BIOS firmware. We recommend that system drive be approximately 350 MB in size. After BitLocker is turned on it should have approximately 250 MB of free space. +Fixed data volume or removable data volume cannot be marked as an active. + When installed on a new computer, Windows will automatically create the partitions that are required for BitLocker. When installing the BitLocker optional component on a server you will also need to install the Enhanced Storage feature, which is used to support hardware encrypted drives. From 1e28417ea7a49671c0cf1d6ed1cca69a0c4f91e6 Mon Sep 17 00:00:00 2001 From: Max Stein Date: Mon, 16 Nov 2020 14:28:11 -0800 Subject: [PATCH 11/14] Updating Intune images --- .../vpn/images/vpn-connection-intune.png | Bin 11428 -> 56241 bytes .../vpn/images/vpn-custom-xml-intune.png | Bin 2460 -> 11868 bytes 2 files changed, 0 insertions(+), 0 deletions(-) diff --git a/windows/security/identity-protection/vpn/images/vpn-connection-intune.png b/windows/security/identity-protection/vpn/images/vpn-connection-intune.png index bf551eabb764e9f20275876a994e544316a9505c..8098b3445e40129245a4d95cb11707d7c4027925 100644 GIT binary patch literal 56241 zcmcG#byQnj_byt6LQ7~%@c^ZGDQ>|lxE6QP7I&ATZ7HO3UQ$NT8lSk@96cDHT;U{}Al+pTi+ zZ{3;_lN5QQ?5w+mJWa+QY1j=;M$OMA3nlNm3)t=oCcC2l@Dktq^Z)~gEeMOv$9W;- zYYH1l_)1KA+dT-V<<^UtY`tMT%xB`?Q}_!pUic~e`U>!4@)9Xm5D_sKt$a!ucZg{4 z(X24to>bb^sWaR45TYn<&oUj!Q!yJk@i@v;xqykI$ARMTk&CcF*<)jiNIn;xZblnE&Q;Vz^fe*>|sgNG~0L)Is>EF()}Epc(n#! z`qCKyM$YF*-w$UY^c|G|_?E$xFcA}EC{qCTXSOi-SyZ7qHDI-Cc?z*J*FekFHUcn0 zjYfKB-cR>d8&+HPA?rKZJZ7X*?ft41~GfYpRk!6g{;^AH?Bu;!0V6>}Sa=%V3$!O?%IQA5^K^4f~<@`1KyzR1Pea!4|%{Q1yMjsA; z0!c|=&b;-O0&ja379G;k)n2)+2u3XWGST_!Nxub1oIqM*0!fdu`V|^zr_RSdTT&AH zle>KU_yM7dB$@hy={knYre1$EHCo{20PU()R|Krre(ZH*cw6SQTI(&$CsKS7`p%== zdPc7914_%Rh%*=5`17a1u7}dfWrJ2U_;Ud@?Hu3K`HA0>n`8>O4X#~8Qti}hF)(Gh zYXSc3UDzWIXmFcQ)moeV>fOEIsA=SY>?Jjqo}1K+SsvY}z1-Wj#NFBfk2~aO%%8KB z4Mj=H4KXu#)>1j(!#zhaxYT zBeQ~2X7F9BicjUsAkC&*o({{)c@2Cs9}!R?n99LO-}L3lQRM@je4OC5p)93(dh`;! zW;FQ*)5u`zz4X}R>T?xYsbsEwi|L9ss#=l=D*wtNjmq+$1)k@%{OOOL?lVK*^M(hz zEoJaqWJO9pyzk3m;DYkmRQc(=%!h@Iumam1L=s+VHqX%iQhBp+xsB|`mX0o*%2l0d zSf~$9usv(!`blawbwa$VyS_4yz+Bk&@ zfrEiR17Cg)?gJ&XP7aPUX-?HRlz=bA2`nb+j`o^I2*J)rRJAUogd2Pj6Ghe&aocq~ z1@)(0MK%81Ib@a=+mvVO-8;dEVDpwOu?A_xu6C92j<*_%n!mYpZ@xW+IoPp;cOI)t zxnOd3lvI;ed|IZvF**TJJXNUm!N)HW1dL@AED(akn4f3D&y=Unew23u->?m;fk958 zMZOdGD=Cccm{%(WOE+pkxrZ$rMkljO-9?QjU82amppAe)vkLfG$KVwPz1HD`!DGe- z&Fyo@etgfss+#9bAmz?^y}OsU!^ctH+JO~Vn=$6Fr|o}uO;wDPw0BT z!wt0s)M!K!Bh-K{6?rh%%_3C}-x%GWS}##iapEtY1!3$^q)CrA>~GOS1EB_WV^;4y z!w`Bq+udoG5XN(wA2ZORvA96z!eANjab92UTWe^g3qSKpXO!j1Eiq=Pjc2TZ=y<6q{Fm-H>`$zC1<%YoN2d|gXYNf+6 zQS&MVJ`EO7=Yf1N4#~hCtdD>>Rf7yApj_9-BVH|v0=4vm-jv`EZjB~hRj#6H>Np&K zOb}8t>v##yXODvCwuc!v5-KbG!^f@xdRRsY7=)Dt;hA>(0bq6j7B3DcLiFDCFxuP7 zB)q}vIm?^?JU)sVUi4?aDAinp6k=Gp3p=WG+kK z0pbEr;E}t_P`Ot5qv8vZbd3(fpY9H5N0=A)4s^Bg6=*JZ4 zu3t-mpkbw(AYqDKmfE$?G0oxyw0n@dEWSPBaXnZ?bphxe&DVcWdD4TCN#;7+%UHGH z6x+Fl;W~IgzhrAa=FE)#W>+%^# z?T>UdJLP^bsFh429Ib&3_{et}$3M?9MwRF+p>tNsV+i?YgwM8aCQ@Y)3w}F>E2k)$ zq598!Bmt{b6g9f{hc<$Dj<*xp0qt%QwJoA2G+2C`uiT|&8{XS@P%?vke&l;6^E))bBaU7+@}>d$G*a5q)$|b z=P{R85?@b{9((6hUlidx?lQ>q=9?p2Sb~Wy3{-_B$2_ZCDf(Xx*0H%9b)RR%(~R&M zcc~U^%sTRC_yXF21%;isi4gJMPZG?1HC%hlPhCQteE0|Ruj2u(Ax_9aX#U|mCSf0K znheWg>T&+9I?Unj556ooEec2CSuD(_gTJ)Q4vlgNEFwj?#@*p@7J2!vTfZs9&PHP# zTj?a6)T=zRk9%P2y!(s&U~ZB6x5F_?IH9>Xl7*fEd$ZZ0N{o_Zo}3Hzid}CmGq$$7 z6R`TDv0~oc5<-I#&jVg_Fin?IQ!a7KSh_)WHFwc!QBd11R)!K#5 zhO1POTG+3ri6X4V3#Ywjx+H7q?S2mP;2*xQTf?pS==D<5{rd-abNs_@avrK9M&5*d zd=7kiXw{5@Wg5%|(=7gsRqQbHwxFNb)2ae(`-5gtX*J972IfqXP7NIow}r&)z=TN? zCuVJDqmRqKEZr$1@-eQQ_^{LgFvxdx8pW>B2Y-;QySp$1Z>UqttIGbCqX}AS&Lnl* zTys0|LZV$?og!{cXo!2S7T*T`@s6&ORy2~|rL+em_=t~Y^(~T&b-7iMOzw_OCU)u{ zN?|`KC9u41&X|15v^Ty&3u>b)2kTSkFrsw(IUd5o%o{vqEBB5~@a)0S4t^wAP;TLA zz}L8guH;7R*D7j`yT|z6nw72{_$!Nj3*0=fw0EqQ#~CR~dX*`hM*Y)J_l`q~rbf3% zr=A?|&NODJWk)-KmKjyut)|kaWgvLu1vpL{xR`FIT?TuQGQ{poDgD}uA!;KS-tIVK zv^Yg-)VI0GS_za%iaFPn8dA7PY(ejno{y99$MiF97Rz4Uyj2ba%83QgK+2pqXVu1X z5m@QbJ82(x64p*jBmDYM(hl;ESQk-WzR0VAk{lEkMj-orf`%d`ogVi6*nB~G}6TL$>P6Kax$Mv>uCp$$Di-k z^{bQ7{YQR|L!P-+0MXxv1b%_NVNzr|_7S?y07Y;CpOx*41|#R* zGw{WOX;BNzB zJ`P+K9WR**jRE-`$+nn(vr>8skD&xPxb*_ZxX1aq?qu;ZY+i=;CH`#INP6LfbC0vZ9yGlMZed9749gkIf$(z7V zdZg+*75~WrxV}t3HLt0|p%RCu*1274++3_a2ybz)lYQvq&&Xsf?Y5;~M~j@O({=uk zxgo?Z-Fr#=MlZke8G3n>X!$g6HveWDzS6=6Ks>6#Mm(K%^2!-fB)LdxoLA}OXRCX>u)n@hBIIP>_4=mi&5dW5@+J5Vc_M|;IAgrv zR16@X1q3gisx? zBtxMh2|a9T0!|y>1UW1x7g6K~-K+Wo?Tt{8())}rl>KjD^nEf+;dtec24&WkmR?L0 zkv%4IuLx`v7`ktmJi;hjOYenPnkXR?9>)PEQa5aHhp+W`c$d4)n8(k$o( z?am$-lFpv39KBoifR2_Grgfqnfc?$%ec$TNPY-rMod6tz7XCk|`6 z5jm%+jm%|!*}me5Zf*A;s^P|QFgJHks5tl1(h|S4k9{Mq{1VX#_`;TkV^XK}CHo?H5Ga??Ib=2YjBs%^!QSy> zJA`}Y?zN+0#U4gxew73#U5y z1YlP{;sgP!r}0@EVRZfL@@1gb<<+=t-Ji`#p?y_7?gi@8O4B7K7AQUMq%r`9FCJ~b zW^SF!MS>=tkr1msVawkNnAq1^vOXgyCvqG$ewsO(80kr)^)oFS+a2UPHX`C}QEQY% z010n7UQMY~9BPM~YkbgEjt3z+75x`=72+3XKiM^A8a2oc0N0YOz|Qd{`VdJ!TXLJ} zVPDf`4&f))&i;!+iY0_&Z+sWX<_Q_-MAa-#VuJ0$G^!-f2Ii8tWi2)dDJy(j=sl^@ zy8|O8pLIkq)GkS?72z<+9s0#Va{^$#-Lb5j@Ok&jBv)(>SzdUZ^?#mx5UbaCaLNci zy@;H`t=o^Jm_FN(!;R%y-*^4PMr8*&I#~vI^AJcX>reD{S(&CP;LD!x5A$v@!+h@%TKrWdZ4# zbv)}WR<}z(z3iQmJ<9-FhMPC}CB5VYDqJve89C(f13Ac^1b4pK&R9Xff3#|R+7=%y z7b(u6Nt8blO2|p44LyLZTE%5W%Wdz>WfL;~ElZ}qo&gv&56lUjloH}LUSxW)xULVA zf-6_V>^1_YWNI(uKpR?czXvKx=#`+aoD+OUD3m+KK{CK-+CKBAUUneD4x~jO!?C`~ zgbS7YU}ssgcTdo@+2O8&@ZZSo!?TOv_c+MP3X89=9>774a5n#1Ww0SdB*O~X*kbT+4i1R6 z0YQ4J*D5cUJe|WAtcTSy>v~aaeD5Ov!XMH7D;Vz52L?57mY-TzSAU9{ojz=x+WrJN zU|R9K;N%Orco0uH0(VB)$*I9B$o^W`YYX^nb zKC7n%?*g?ZNYuP5;9C|DEo%7bYfU)h+Mc!x8}#_07B z5G^C9v8dzye|<(;Bk&)ecl+ua6UTr3AQY!C^=%VFG*}&=U&7idi2Wd2?N*m z5{o6?KwXZpVhPas-Y<`EOSD0Aih5hXS}%8=mt;dh^@WeAxn zq&93M1||X=i!6D*EBrtU!=k#rvX7sH%?n@L9esYp3!GRJ#hv#+3rv~GEyitM%QI5# zjze12n;L>A&qp)OD7c3jVQkpg0~-V!3moHw`Z+Iva@l#Ei`MlaI-n2I410EMCaf5_{qO{+Va>&C`MUfr(Ag6Kp2gF%o0~t7uC!!b-)97f6X={C z>an{YmC1Klz5fvfNzu`p+YfxgIVKB^B5H^0kYmi- z>W3&pHfrVTxX0SgbFWU~x+lfEqV*!mrIeb2zN`B7WIg)CcAup8xo!54^1{}ka{j%( zQwt8b%GRJFldMlBf$SnQIUAB+!%~cHqo-~wMFtSx@>_#%vov1n?uBKO@93aTX78S( z&Z=-(Tx`8HsLx>CUGPJJva>=2s?_>mC=Bgr@j<}Q7+`!_fSd27BziS(t(iuPfUmLYV6Ke{sPn@eR7Eh} z)!jMpiTQqMn2UWzrImK^#qLgDeut*%u0 z4C1mPjCo@By)&LM%GwpTWggn_^28`!^~GKTa$)dS>iz_hC)2;GaWM z{@HQFPXFkuXp`_#x2fd03Do69w%WGfpG&6rQAsIu5R(hDnPHznP8H0(2Z+S`4fYXR z$eCmLn)i+OfVB=2<(EDxs|6%7KbmA8VYF)ltv}UnRd&%2-`FvDOQp)u4u3%F7Ck;w zLl|q#<__#S-+2+|vBJla5_|_K@=2elfG0#Ck4nPG`HXLoAcD)*lG57+7_?7BpyMel z&q-#Xrlk2JI;}pWm6xxss7gYq)E_;aTl>;vfYmvabMji;Q84&;31+CdK5&j)pTiY` z8llb)&QSD#)hrxj7}2w|$OY>bo$oA3HJ0JyQR?Lm&~Lt_k!se)qc@#Zue=2()OObX8H7`ZCt zoVLauINRl8xKz~fDSuu9BX?CLK?#GC3s+E=BAA0#c*DLE)NLP*Qm@Kel@E@*)IC1& z^K`BL^GiDZO3~BV~_0arTf!EfS!d^p$J+hCRv>w0QKPG7P5h1S+kp!{)*ixuzPd0|7xcJ?s+q z9?7F!mb!zI927Uw)Jz9YaoqOm}hk!S% zK}Jkq+mUcaH7idB6~fEC+nv7=%|1@YsAa-@iikOsn@eEEJ#S-l-{43w_L$P6U(z?% z8jwK%!Q+iZ&q26MMr|90g)L6Z;3WiP`8Jj_F377j3XgHXxs1j*^f$sVl6%Yl%;E)e z(^O9It~Ismp^Lh4$UPOiK=s^xK>KiuVZoow+iGmPcy^APwL(R--%JRv9oVE78jIHv zGrUGeUSq{t2k{R1(w;1z4-rO!)`-F0&GX7f)2G_d3#l{2+0Fy(0VzJ9fmOXnWQW8L zQ7l=}CB7~`pphZ9(Xc~$*Pf1&`Zwh^IXa5~5?2@~VKg6&Uss0pAwU5F<2^0f43zVw zmC81HRl_TRi#?#2)eQ6Wf2GS=-Fpl--u(1KRytM)ctFERIUt@P6V#+Zrl)B?IA2*V z1PrazC27nYeSr>7u4~GAe&}Im6a)E9HrS3XF|ND;@juB=i6|KWGqpgJ;=1q4`QR#9 z|K}~StHjgyKNX;^(0|gJs}d9M)0->>o!+tBI?6j`Wwcw{p4?d{9_Yu`67lUhQyHp zaWDRnK{d<+Fd9rvexyheTFM6V@_tUE2l3i}byJDkumeHlku65FOsA{eC?Wz9Sm})<(uRq3bpD-a4a`7NkwCCR{BaoorFle zF$+|Gu;nR=%LWW+^xc#V3%vsGygFW%pQy}V2-KTz^ z$kgOF+U6Yp0~n+ponj{z8+*?&vPDcG>qfK$T6BjeGFoZ%qS!?E49f2QC!22gg{Ol& zjczj!6S|`n>TV~qU)@KMZ7n*3zqon`l>4A5B^b<7HxOn&Ec0JWe%gnRI@y)JoGaTs zvjSi4mmHWbZk3^!=tVk7cRnebn!imCd#^7yoNt-BNw1;Mki%Wg)VDILsKgt-Xss+& z`YB0@>`9l%%?3l`v)gijC!bjp%C(CIg`Ag{2d%f@nGM*0V@aO9uqCHbT~a}3Vds@G zkBf^M2_7pLicTc#YF!kXg{SY$ezY?d4zE;*h`p%^=UM^#nvyL>J$=01``v6-c0Mr4 zYkHOcDk%S-Z9cJRr#Xt*z2iUrR`i`Mb>|j*uLFS~>lF1@I|CixdnWJyRvz!?{d$*; z8(zIi@wXa8Eb6#T=Ha&ahpHd9c=oJnL<^O7l-eVe_UcYfSEKv6f5@ znOP!9?#@S#e;V~C&D1$f#rjEbcbXfe$o)I%Ds*ZTLA6|no4vT*d+tf*VGa9}T)F$O zM<$OtUO!6Z7Lda2Pg6Gw^a2eOy?tsTrILmkt$pu$|07=fIu{!OCAe($zEABolTb_T zLs(59zvcYKrR1{(H!H>MD7Q0$1iMOwXHz~M3)@G~Ry_ZgF_e*4`rIo{QsCfsdvx$!ci zel4p810zl^FE7Ekx2b=|pgun8>}tr(6@QjSXSEgz)QNaJUnRp#KSo*A@>rkvaA`75 zDI}T&-011)o-7+t(YBJxAo%$Fcsm^8&AUp<``Gru(reCYwdF}R@q-4$Y#n0O)nJr4 z=eE+tbxymDJGGlj)xrlo9NY|PQH#uV z!#mz}JDR2XoqdV?+utUM_9%(?ufRScStx?4)wl%Av8d4DFh8nsbl5yKJc7@_b1dTyCte@!Kx7?JgzJ!E?^R$E&Zm+ypx` zOD&gw@K(6x{@g;5#1or~GFNrs7iFq4r5sk18fm$#6I0ubkiD>oCJl;>^35|WKKO%p zO>mWO4}Y@(xpF$v2A+ZC4#@icya$hcpQV@T<6-0mV3N}+qN~H5FC$N^t@jRX@Uk2b zJn5_NwmbK9ymcJ8U6qX{jmhhDyki#yU4cC-VbNfZ2|1e3pS$P{6b0trRj|Z=H`-s{ zwKNLP*x~do(x=PjlT6+B;FfU3IW>0(l%StrhbYymG4cabqwZ36P=AtAA5Ch7M=&4B;YQA27_xyw|{uQQZ z4na5!x*}{A+afu5kETeQoIp=$+TYX!4OnbGCFr1a+%)F<7~(VLgqi>7aB|{o&NKfl zFQhDo2g$^xfDb8abR9hLwM&-SH744CZhun>j-kehb!!Qj@P32$GzN5;^p&e&C_8|H zXMMbAiYIquQPsc2fw~!a*UR0`5XkHgh-W*8H@n6Dc4arg67b3>?7nF30w)MaW&_8M zt^0Y0^zHE44ZIIYm7ToYuG2`CIN~v2PM|s#4p9Fnh;5 z6AtdC^`#A#_&aAdzR6UFt2!2J>4r~i@u+2eD2-LgkU2dXk~J(_AKXWV(HL|` zG0}QyD6roXZz?o4oT;HZq4Zey(XO3{@~o^@YM!&VV-WnYV7-(=il#o`<&itt>Gzh; zxy5p;K|ZioH>4g+PN4VP*c`{smpHN=$AVYv_u~?pE+2(dlxYfrK~ZPewqz6DH)>UE63)8*hoi{dw*7adfn9cBJS(~q7}i)^Z7@KL z*Opx3EL}px`?$=?pV81aIL>Bfqe+J!BTC!l+vGMEC}D5NC9Nnkb$NzIkQ-EKr{$NssdE+ae27r8 zRzd!=;!R!VqY0kh9I|nqh$x+`J9sSW3d;E7wusop_QaaC&njQ zNL$Zr&SL8fp%b&yp)7%=>9V=!zTaY_p39IYgf$7iL5f#@mZ|Nr6crAZIfqBQ>#}F; z;yB68PGZM(m5g33kvaE{ft2TZQOIviR&>j7h7Jo;3Sazz;p;}`)+Xz4>XCdRq3IxJ z zh1diRgGbr%9ZwkJOu{ME*&N>OZ}!ngH_1w*B_tT8t)o3&7H+%j`28nn)Pvd$@A=E! zGD$Zno}#<#v*B++8|d>m6NWDEOX!YyXd3m*7EDne4^7-C$`ah{aUXwX$xR(GDnhGY zdFU2yqVckfol*iT6Lahp3ENdLQeh61%j+c0ZFurDk@e+MCifvp?`CFfT!AlIf)lZN ze+1>rBuOC$?Y0d(X?cs*UHl2D%SOTRtjL|5;*ZtU7t>ga^1AiCao-m$oo6$4tHreg znJ5)Bw|Ks#0SaQ7=;Uz#Mx!tjcf!d;ORv9v_8Xm0DmlM=?U+Synp9+^Z|k3N!E z7Vu|?9jJ>7ivoZv_#B_#sYdXq9QmgwDc_TolrP~RdSc};f0o=~Qouy3A7bj=EL&_3|JxOhqODw&Mx? zh1taU-WrFeY*2Sdf6S4A8>DObw)lxFQB~1}UlZ%7XlZQvqMp=G6<^lPvufF?&w*gL zEf-rE2J|uNOBT5{2mhz5(A2aE1bp|wmgFbT+j$x4TY&HwZXrOwx)Vc zq=k)&j#oJDU1%72Z0aBEtK&mB%6nK;e@HWfPl*ts)t%x!+MxI44Q!IFNY`1Pu(DK` z%~8N{2DjYoC~^c@HI`(yAZ^N!Ocb`-fK{i2D$+R5&b;?oF>buo^9Knv+k+(Sq~~R> zU0sVqLbX&<$%kR>@)2p~qiccw&%IFPQ6|3Q)Y%0FQQV<}NORV&4ki?GBgj_{Q3SDB z#23~|lk^OimX8#tJ?PPk7q9PFm!@4?z#L=ZG=DLJuG?N#Uf5owe=yYg{9J#P$GN!< zn_s(QhesnMfmx30yd^{0Fg6k#%^ZVVq?M6_WQ+%j#xwTj;s)V_%5q6{M~i5TL5XJI zA(v%^l8llsbqNf8HX;hrtKA3ULPa|Zx+=R+5h^;)UM+gG|`~w ziTV+r#oHrf57A|hshCa*#aAje(4Z#P&y9F~#Fq3Xt5;6C)uOeJj_p2%G_nP~pcCd{ zPA+wVA0|H$iYwXW3^u9@?>8B`)zONN_G!eVCuHxegA(IfLR_X{F5I?rj$-6MW?*8a-@m(zoQ8^9$ zbirbA8WSvgn&9{bb8EGdYAeXrLFge|W`|s&v6D7~9|(iAGWplaQ21BAD2sxszS{9s z9yXwperTA_2b_uJU=#A>o^eh9$NgMAZM}l>&vH;RNtpiGoJfb#?|XvZD4MZ%)-6|$ z@P@zNxx`bm-mHCuAJSgfy%@cS9s0-v9@Z{ch{Mjr5N5d=FEWI%`x$+Y&;srjzY7%x{(Si;WQ$#O&z`P(|+gC?u!c^)S9rR&XjDQP)) zUrk~?^hk}x$@pGXTE3X+X=zc!^W_|e`m^qr9wr!`q8t|7Po9O6F(afS##{L^uOhVrC!nRK%2P7Rv$(otaEeYm7NE?P=| zG|17RXqPwsIgnqGU8jiFgB<$UBo~VL5;z??a1U~D3IpKZ_k9rfx{w&Ms3#+*cPu6W z!o&C7SW{}PQy|LI1Dm;~B`~zn_R+4{fZn;!D73t?v4~x(xvk98_mBd^kX9wEFbeg^ zXzht0>&hRF6=sdm;zk1Z-uq=EjOqjP#Daj;PEsR3Bi7=;NFFRK*u241iGJ;w-{H3k zFEs0&Fo9oGAacf}e~wcHM})zgWU@rp;>8Tyn96>73*xjzOrl-X1_wdXT_ClV!0}4Q z4`!eI(S6SN$APek!E9CDk6%4F3f-2;-gR5myCVT5Z2aW0cGJ#Cg4i>_Q8gZOjq8WH z@p!Vk?lb<$92&B%Q8<>G`C{5MM)~|eJ(lcV2J^`hJ*AI3op^K;wKz;rICoiLWLaxG z*AV=HYup*wy_;iP@XhkqRY>ll4-^P!EG4EJQm7OP zV;g2>K?(E&Vr^Jn8R`1rZ`!-~Jh*H>$8`@)<;4RdKgRchBNw6!2BN##WciMl4hSB_ zAkuu2>Pxm(I|gOYNe&(q;egH%+`Y`G50l*jeG$0kwH8@t$zpWmT$?*wPSqpfQ6Elz zMR^}rlst?oXcR;f2WCqa29@m3WIypf)q3Su5}S&`9g=MC5=&-L&96^CS>l@Y^J>!u zj%&u42{H0q{>1BB*VR)C^-D|@{>g2Y`I4PYYX%G7LQW>* zMw8-lx#JjP<@s9+C(>Q+nvO z!}EJ4-=^{bPG2&xYIb45{@yABu~~qV;-JdN3>doGQ+F`u;@bC39F;y!+0v z*F44j@SRDbEn+(?qKkv3Ev?uh>-VPZ=ELT#+nyXB?J`DM%qKHW5Q;-D#@YtG^8L)d z(1H?-l0L7jXD0)mJ|T(KM5pL({}#VwJRDw2KQ#!|?_i(+%w856X9zh1owpQAILG2< zQ_;JgBrIE*b#~_YRe5auG=RZ=sMIq? z{-!>s$Gp&6P1y>NgJl*nt>F%lpE+SG#ewa$1Y>bfJHkWo5C4_A*Bj|YtsX~n+CL6a zdW4NPeR138EAFCWKrk4!4WlPGi>j$qei zKc3h~5se6zq`K{Wn*1tr7J!9T-AS0q)AoLqIWDi%+>Yn-zGIhdBjqQV0RxL052>D)eLY8@m&JL^7|wd%j^eIUnO>?|v=v1DiE z5(bSW_Cuo233-t1{4p`=V>S=1)9O}0h0B*zi&NpTn-P}#$#@B)93FmrmVT-**Y9(& z6*BN*=Q_b_M4;`wX%-R`w#Gmd|{{i(LwI$0?5*jtQY=yh}C=Cu(2+LefQ>x&9PZg`0b}KvLBo8Cf zmyX`U$5<9jz+%X$`u(YHfi!;nAm;6%mc@dReQgs{;fnREJs(aJA-ZvVdNbLxt(Jb^ z#k#yak+8=_wY>X2-tq6NZo{o%v3HBscfytO8=ho3X0)t%5N$j9Azl3gp`?2u$x(OvXko5=V$a<&v2QldP+a9#v-NJLT)y{~W`=jXcF*SS*NFhFEwfhbs7iVnSOm1x3bl zWsMt64sTftouA5I*uz5Ys(@Th{^v;3{)bfpwFgObV5t5&qetyUlJ(K3e3GM?`h&M4 z!!3V1RA{0_I!B`=hXrX{4AtQ2I{UWnACvvu6G>aaQ%Z=?yxC4y3r!X(; zSBrC@{q>D=@*0Pn0L&4lf4g$4*4)sevEFx{vd9M8Q&(XP?S%8!dr2OdU_teZ9V^E~ zm!pSoC?BZ&%N0H1O~9!`)$aA;DtfLmPdT+Qx%O*Ut9ghDHx9|687k7~rW|Yv`^}4u zTQ^!y1wc4<7MSi@xv~Cf10NMD2q3#LX9bZf4cT)Sa@71}&(cO_z~%8gkB;vX|Nak2 z6D`U}7xe*Igq!pkS$xLBhV;jrQ^cnVS4O5Qbm=%x6CPyg{h z{MV1@R^O(h$IqP#^e9;xib2S%s_eOwW2d9yc=UI$fk6^7LDB<0;vbc;r}Xotx_Q+l zXpgIzQ_=ml#I)Iu99Ws3e=714+%#g*BdI9%_zhk38lLk%_nWJQ7h27oR9?Dw%VMIN z<$SP{&ghy+0Oe_=S3Cce6fZ#D*wP6%RYiB^o3~?2pCencDoPl(*zp!!&Zy&KM>6=(Z6^xk z_?_%srWq4Lw9s4Sj1K60?c}iOqhB_a=YCx-)Wv;cq&Oc;B}k?}By~kEFb4;&fA!6B zXP9HJX3}M}1)07ef}|^UxyyYS8?h}O4TjkqxAg@5T5{&5+R;(?G37gnfBtxx)BIC} zQlWue)-fu__LJR$t^!^dz$m3%lSB(Aa%iHk)GD_Sib^+{J!%MMiiuyNyE@`-th8YR z!awr1+Yzi?tx&u_QQiU{?==gHdPhp`KQ_0(Pt382SXHmbeI#P6^bC4IV1JV0mV4w5 z`r5!YY-X!W;cw<`q=4Z$xLVU{7EE(k}SvJ{>I+7CF2fW?2<0Y+=?~ed`}P@Q-%DKuPb;tR_x&km*YTse=f#A)45X!f?<*s zJU+EDa>ViQ@HL%17ageph;wSWCD0&E#$}(W`g@JvkYM&w7t7Q&FXFcXXD=MMZv_=R zjArrksMK#yG@CuSFz0e#+amNbf1vW-|J*uDCN|8}>d{p|73+5b5U=w$KJ;hDFLJPy z2q>j^*~%LQ3Rd-dA)q15fkKipWZB!$J--(8vMk)Ej2DEr6$ghtiyfOx%!nIb_6 zS@Tl?Crn%@2lf#Ky@bx!@`q0~51Vc+iw$Z^{pezGWiWx5+JTC)A6!o?5%-F2!9%@$;*Yd{!h@mC+TKAA2u@-($$|>0uh}hp*InDm^1qb) zee_v=^uZ0_UkXX$HEr_7FI-nGvi@SkbK(E#`~I&JNQPIf<)9v`xC8`fR7YS|5kNn; z>a`~xF>(}o5E2BRHx)OYcB`Okw@^=5-v@{9d44wsrO+6;JGUP+s(UJU>et@5?*)!E zp^A-cF;>mQ%%}P<$A^}n^>fvg2dd{GUw<)>Yjk|Z02V4kw15RRvhQ7e^v1!XDTQu` ztSYGM;?xS_d-tXD7BLE*?Y16(3K0>eQ7237`Zp#Lf*e#xlb6&UhO!{nd|>jYxv|{7 z?B|(9q!t*7 z&uRGIK6H}H$_+U=vx1N&6uM~LbvS1L3lyGr6AEsj2TZ3z1SAJea|?_UW~7%e{+DYF zs&k1R8Xy!n^j2CuXFwl$@R0iH^48r8?H`YMq?8-@rm(#&Ds4kgpRg!z?P_Up=Azky z3LepAS6MqOZ)OKj;S3UXsZN%M| zcK}1IF8Y*P0a`^s9Dn-Bq~}E^9x3UvX*mPCV@JUcKCyq<5oo&T1)0=Lap!Kt0gCnW znE;0c=V_gqWLo0LdecTpglh?vbxTP#dCaeJ5&x&m^tx5@VT+f*;oJYEaJvqtB7r6T zgPvU@c@To5-J@Opw1;gj^lE8l7~uLXB_d)p)*$wHG&8!uLHs53OaJ<_n^nk=gBME4xfa3uQbB&|@Ph-B=X{{b zp~7tohtZeu>DEZ@THI{#1WCK25pZ@RS{0kw556 zE<&|1Mux(b67mZ<=cx6Gv?5)UJhRs#w*ZO0VS|8qeIzAvd`b4jds~+ z=lVgbFhDdzQYH989eYUho|1=9C{I+B)3Un(rRta^S_e2R3T>F9zKDByzj#pVF>tJX! zACTTk0ZvnDU7vPJ6hiw&I!kk>d|_W`V_k!GAiS`*zk8PhS}V3>$av7j$kHF{E()J@ zO~?$zip9^T@|VHZ7su(}m4zlra0dZ#vyaD`M3M zxbTs=VOKWxF=Wv^#+JW!-*o+cG)>-D*zGTQXbSMvY^BNg(6cpiQ~Ma5D7oOUbts19 ztHb7KcfvJRqK-3Z2w~Q5cqL`XZI!4ZvGvm2VQA7ISJc;HLUh2#2h+vCCFQrlpi*so zmqCcVQiPonpHWk#f(56kRmB; z{Wq_rm1#%vP`_SQKqvK52#Q)c zgn0Z(&-P$*ov3Ow3-7W+o6X6h#q97nF|u|tVM1-3xWh-Pe|Mbw9{t?H)|+Y3bZv2c zh2ioFJT$Rx+4BYFg0|GUk760kdk5=8=~-IzP+NS^tn~NzK)EZ!1?K9t!zCVrKRtc+ z_23DIo}ny7kYqq0r21Pm75)Fi+U-2A~mNfs;bddu_7XU_S& zz$;->9wU%3l!;SLK*~5R-clAOQKZfJk!5+4X`CM%$7Lf>f#bwKe5jc$D(53%=rBLZ z&M3A`tqsh|b9O3UvfA*6^b3MsP-g$c%%2z7@paMid}Zh~JSh*fH09`Ho&A_na=@QNAhlhME;Oi&UdDf} zAmC{wxk{GDlb!;75uK0iV|1&ufs50;7YDqEm+*%`Sds_W;#{s`j?hATi0_`g2Cx;X zYCB9Uc0!Uqw*-MT`SIqYdw$0~ROc8TJ|4_Hpy6-SvGheoNbF;b6MjmY$uo9jEOxMPupj_QXucp5*9=llQ=ySdo%$~$`b_Yk96x;Y`@0A2- zoBNb5irC>WBi!7ulELXmH%eN2h@@zp%@*MnD{dQAZ#GlS0;r@YfH3GK9QmK$OysLu z2?-t4x_cxLWt7#jbRCdoW(atJLBAe-_;Z4UNK&DW?0lB?6VW>`81!uBoy2F$2S7T# z0s8m+092=2GslM^lxW;0fnBbFFczzWzO7-MaC+0finOUYF9A^r(Opk9h!pWyU5TS8 zbT;UF-2h-beIu7A=bE7F1b`p~eEsX_yk{(*0b0^Qke8nJ^7S+yJ>0yl!Kz#(e#}|X zb_&Su)ahHo63}nphCex^!EhjoNt<@JefN?Y1DuYMx1P+)ZH7AdmmkTte*^BEugHC_ z*~&FF2iCJ6l86Rrutt17pj}mK#5mRd;eG=6PR-#0t!E|8c)jq>WIZ-#Q`5_P?KBUq zB4-a-Z7H*_pA%Tu{)h^niSS&TIltHg9l>v6hr2U%z8t%k6wTm&NhZ2`gL(9_~>uX?RfivM8D@-M{YHw^4e zXyS~r&#ALvCIZU?fIURMNAXF|k6y)lBMNzdR8iX)0C!jh06!s zz*ghQq^K}SJa7h;75)-OTs#}Y1+ziOM>|6*chlQ3-|krq2h>eHdhjn=0fn@Ad5)A@ z>5DGrX@=KW`s36cW)?qg3ZlME9t9gryY%pkCS63OCSmO^Tn1zqZqkdZyst+(>AJl_ zEXiEkB5J_~cGsdM$%x$|+x6(cib+qj^Nm?F8fsKzZPkK;EFZm%C??dR9+j#Z3ej@V|p0sYhYa- z6Cntug=-|CRo{?g-UNqfYYyNU@WuW|U?}C(U1g>KEH^QBn8knzM@O+eq_$U*b79Y4 zhWeypZ&Y`#m@?PYKjT@_)i;CB!aLXReLD8dX%j0@Tvt!BvlzmNKNF83(a>R#|%V_cT==wKk$KBLg z^RCh2N&1wwy7)y}rbg`^m8K_7u|jB`hk!=$@+;WX}CFjvr3D&-Q8PB0G+iZZ@%JQSugnG_MjmbkP={|#d!Y|u8%ZL8?%sBjCTzy1a%H}`vm&)UEWu?*Hp2d~WPT~R{pVHj@_pM9Zu`lAf{l!>>4NUw# zHvGnTte6#m?EdXb(&zqv^VZ)`__FlJYS?;vrRdWDT-!(MuJ09phxbX~Qq!IUIi96d zSi`xEhSf35I;tg%Z@ z-L3vHb(>GW)ohoknIfyW|`iQ6K=;V=)u_-TL2YKg=Bz(DVYB%L~c z_~nquQla2mb;o__H>zeXviZ;+hqy^HR{aCnXq!eo!UF7GQ8H}vVw$Rob=lKHdH|og zc4I_m%g20=rFfIVYt|=T!=)XPq_b6RH_fj1d(y6M;zDpCp>o~Jd9+UuSGgKz!(SdN z01ivaLf2zrYU%R-lH5`Wf~3HTntA!;%Oy79=i$4rr~Mk(W!AL@gd26N(p+_WJ$N{O z#4$^FzbZ91HF!muxz|A%@Vo%`N8U^JwL zlsKo=9P=;RVoomV>G1Vj%wNgZCmu}q)RU({adp#Fr3BHX ze&FM-176_^yIct>*8X7QEo&T-s%mQ7^paE63GU7&oc&@cb}0xfRpA@^nVU$`OF-T{06Q)GtNJX(%dxE&$Z`=2xJn z7&HtC)h;kF4NeL?rWxI%9TY&GjvbmCWjw3M?3W9@V7hoXg~~Kzw#yK3M0xEyCw`L! zGM3afSj$26AYlR@{ct^`l=m599y(#=+gDgGT z)gNG9)a_&)JTDfhRdY{iII!~^*VXK08Nt-;E*r+Q(FN^yS>*M$DToI{AvUO6R45#R zP_%A?g9Cxp6il7R9DTt*%)hNg&v^ZN=jD z@s7kOKSTO~phF%&TkI7@D_*_wlIQY1hqs`*G^m5g3;iNOvx~#;Y4nYLm z34F_0vwT;f1}O!ZFPC!g9Kfo>FuIo$Bwiq0deT`-M-^sfEpHaKd3Sd-NMCNxK)S5B zglEz5W7W_#f7;+nST2W(WRvg5DZu&ngw?Dyj25}QCdeB{>=kAJ%)cKGa?0nY`AlM{ z>{4NCyooPV;ui%!F2kq4SJ5G%o*S2-UAT)>JS+l$17pWnXbZ=|mnC2pme zG%Rx;AU!UO4(F9-O#mF9g17I@fHQ&O*_53$?K0Bc0-bm&c>N6RbHptCW@)ZWzkVST zF=3ZWb-bpUzwbW^to;Jbt?>ibD4Cd%4^B@wFHZ~dHR83SUR&H;az8#^i0{cX3EYMT zMH_x`2s&V^5IjqvD5tsSwlwSv>kF)6t)8nw7#!s>RW@VlxQ>_W@2a05^m?j>CL#bU z5SkgPlnrmA!ylCT-|Wvc;;W63f{FS*o;@s{u;)LkmQs8f`0^R$HEsiX_06gjX;ocH zf=b)cJCk36v6$2j<&@zPZ^#;aPO~f8pOam}+w`#_-)E2%B4=cB<6g)v8+|fYE+~6v zbeO$pXrvh^>! z*h0pwQ*TmJ=pSxwug9S;5Td%Lt#EugEX?c7We(acz5z0OjsCq|`7wUeK3PyX$c4#| zaa_j=r#(tIZyloTJ*l01QaEk9v;FQB8{54Jt>XL9T%msUkPW}L34p~|K<3Gc5{wzK zx7f3XR>!;Yfx?~$7W^66hzYTg+|Bfzrn!gSL2cJPIXIgY?3}sPIvmj5oNw0vnD_u1 z^4Klt5T(^8Zx8JP#r@WVHJ^yUu_)=Ay+vacb;RYbf(SxJ{pW0MEW9-`y7XZS;Rjar zi18#1k@$tttICBwZ6J2El)8L~Dn7JNdsYL|!;dG2$`lc-1zsbIOl))_bQeY2ZSGl&yo z0Rgzj)6T%Z5>2X(`nAIlo+#Rln9KOGPRFb5=!((HtuY`R1hRtjUb`7%FiJGV&E{uL z-N#J|6Xg)DexFuD`Cwi;tBl?>t^AC6Z@Hd>j?dnLyx|3zeDAlp(vtqwqkaLS7zl+? zW0bV<1TVPRYjs-_{%|OszXpo-WvLh07G>U^Mt~}iv3)843Ne!XgTMn+5U<_7ITb(T zE80Ib?N=03Kv|9CPwC|U-;!s67yv27o&#xJ!}3SR-jfpf0=I3#zvJSxacE0p4pQb; zhO`)HsZX`{bagsB`FMTCP6&QfO`lIFSjf`;;f-E8VfG35k#5a)B~S5q&FWAh;-p1@m3xNU8*|q!P&fdGJBsmOW@CxN3zz6s4uf3P}j5 zMPh=i*bdOG{;@p|ic5`uzU5x>3UvczUrP1{ZMBP|9B(r`2@#-mf{=tmB(*3uEET7= z<4E|{1$X%SJ<*Tcw#uYn{OuucLMc4GA*cOr3#+p!vtbHWaU4m`otJ7H_I2~3j$Fz3 z4+Z={`5+IvCF~;E8?@fN{gZXq>^q(oTG--zDA6!jRo4eseY=eMAz`6+R}znBP|F5h zFh@M^``v;VPdc#&9Eu3f=e73%+c+fYsKY8Ebc;Cvxsp4X>IO3VOkaLW@pU^MaGUE7 zb11?JVqF)o+^xPH75>c~5S(G_gnq7U-p!(UCTKZOGDv2p&V&@RvJ)_ycrfk>d?x=? ze_!?IQDv7>N=_5&)~g)6;>nSHJ!Zn+xBZn;;fDSSAubIbE~kX3*tXfM*4tU0#&$5>7wu{GEW^>By;46`181R_WqPJCLF`oTsM<~Z81QS9V8~b0?9kY- zEFG5n6m@_17Z8X>l-V6mkiZd#$CT-Fqw6Z#*xKd%d>3lYv)0F4uX!v(4l#7I*^Mn| z3ceMAm{OBQKykWQ;J)$8SC6naS-`e6k_t%!+Lx#1oBQJX-5dYQ2)g>1-(BP0zC0!0 z$~q-}C0X#KCWntWwZQ5V?)TcRh}$2p`E#B8+m(4N5PXAz3m*2LD z+|_P81N{wpLjPQy9$jw|$LwAtzlMM(-h1ZVM(Y?BoIdPuorCTHP`kO9O!-B5m#R0G zGOLzsc!^%+J7RFJYJm^9;yhn;SdInKmu;P%fbRj4%|5A((cS?jsLlTJ=U zVsdQTeDTCqyN9w}q5RDvowmx!^`6uX?{=HxgHt%D8EtDax-@!ImNH?1G^?<82fvH( z@DB;tV?7dF+{wE7vfyU2+!nK<>ZL^kz#?s1OnS@{NQDw#LIclmm^sRf4P8_T_rf4! zKFJAYVuHGWRA|m2W!gI{$upevK-d+!5a~-L!EdD*oXP{@Th|h0_6^9h$D| z2lrLN8O44>QH*0btH_GO_Z9=wgF_3j%>gLYh=6}m6+QcRAyw+b~`$#~f_19l0)Xop3DnZkxz< zQ_0bVmQ%O4&NCl(?XNZBfayiL$Ia^K6RTheQo9x=bNL_<@ZJ*l!L5G6pUt>_LZPip zvICE?U(O^(gN8dPA3q*FmKWlww+`HALR`;V@qj?%GaN+FtTbUvF z*l6a_<5T2M0r%OX_xt=0lV_roHnogUueQ?1sysI51G&yz)}`$sfn>) zg)~+ac!M3ZZ@_Oq5M$NyDrZl$CS9POWXb*GcZRJLPgF;CQh~wO!HNOJXAN(sZp73H z&AGIUNcU07sy*J2rNKelI>%RI`kV9ZEiSi`TD!TxGP!l^t`$3EZC*7iH;#BCehwYA zW)H!*t7Kj4Fl*f2u7oS~Khz`tvEtfAt}{2R2KwhbNEhp^nO$zm%Gext8>*)a*R93m zWKxEmZ#ep=sLJ63zG*STZ)yC?OvAk07nq(%LwXg(2i_^tsXN4iAW}j%$xH)Y?=SA(6?-JSA%dIyNJo)ZG+|bX3YxXaqK|jhhHgg{ z%S@BrEUJ!Gy|9@Qgb!tMI-@!_R*3`ZOI(Xbj%E_5!k&mI4Y1q?^hvY=Wp*zq47-YV zESd2bp3M6Kl->@s(1wAX=khWNHCG6Sbqe!X8#VXL3QBAqSyKHZBr521Wn}Ho`vLl(06HOdG!zH@6o)imS5rs?EtjI_Ji3p zOS+)~nGC3E+YQi;HvDEBx=ee4o#fT(WbJ)w=3)8+#iC3^^u-U^Y2ND%+$tmt$=Q?Y)y%Zy#DSj0mTVw_U{VPXX)0gn zw9C3Tk&fzn=K1iM?hPfnZ0D4o-}OOv2S4s7 zIoWi5OOn=PTu&(bSMstR=y~)v`6FbA;O3X*JzIzO!mg9>C6XdI}4_={_rG+xlm$_jvbu&5gT;ZlbZ8oc!tZa8Px#QLz@dAV$sIpOz%TxnCu9 z{n2``Y0HK=*IYrE!aaE+OP$bqk)+tjT{SDxU29KZS6CQ#nc)}3ok)uKEWc;;)uKYV|!~oVwo%cJ?HK}YXPHJ`#8DxP>6+_c>kJZN0LS^$bWQL;3bf| z{LST$KLw+dU4_2m))Id-9BijCNc z0ly;iKN)fEy_U<)Q5pny1*s{NG9J z2N?N=*-ECnsi)^`N+Y{xHNnM%8d5o>|5kTXk*^q4{}fv&=kr?)r+e$?v7@(Lk*FRZ&AjcigCYW!Y1@$dbibPe9j6P zQr*0E(&0t*i>vuXNhA*f66nXPO8relyJlj&ZI47g+`M$hEa3%7Q708|O<9;-nIPf! zUy!flqK8I`!BtQ05q^c7;m%HraKkX6^S&T5gQ-*7lH()9#WedTQ`$3)!=LMBz61*I@B z5kGsD#B<(%^c+6{Zr6=Lgs{>Y%&aO5O!b2*3|2N&e@TS8JvI`enJHrM8$Vj<+R~ zs7Ji4Lkq$019%yOU;f7+!Fu91vRK`Ilk z0+kk{xw20vP}jS~#b~kx6<^fj;b-@9c*lC_FblZMX>Csg$&p0Ne({qD@4qtA+bk`gb@zzi zlY=1d8`Tqz`o}~bvCa^Md}9URZVa12QmILIx1!Kvm>iN;YHyRkPlIBLk34@2)qdA2 zu69C-9o}al8@lOF3A77fPHGJ%n?9Hg*4dE%^hceLf$V*_b#LnR1|Zt-S_ys3sU`;w zD}O!lv`r!`%z`ZBmETWks8A%ChG%)A#YCgWPmvkdNuVIUjt^bJtbNMJit{nobXV zlRq*@Cs8dtSDDV$rT@aOIWgaaMm7b~8J!@W81*8o|tBr;jsa4D*OM`*T$k ziEZ0&6urdmJ_$2NXzn}nD4p_{ehHfZl$fTlW0Mq_^u+s6rA71H2PUez>I!=qgGjY* z_?>jFkz~=_C1^T#B3nhM{f%_f*!%&pN>EA!oag<_>jah6p_8ipX57Z z5AbvH?4(p&NKIQ&W;uPsK(Wt^F45fswQki-E)gT@F%#^olcUE3k~$&pl3UXa0&MqF zdpCuj!7Mu4=?cHTn6GZ{=UixfWc(SlG?u?5U@>?mX>c(Y9ECWje~kB+(>t~P50h(5 z!WI!}%y)R4UaGR|mNiBt%cM0WFg6EPWoG06DhxRLva-9Z5rnFFQru1_ay&mWSa9R> zD7Sj3@gTQK0gaD(ZgzN;neMccsSXX#2D2(sBwE5gKjSyht>@Wfib}_Tx zdJfm_`gnM)dMy2vP$3?*gNC|k4ki*#XFp?B>)@6$+0NEmiLhWW)gb$$Pa(}1u=`0d;9XU%Jf29xhgt{m_%{pll)FtxrI zgB2AHLS#1Mhq^0CO^&`BA6}#+kNFmrV2ZwKH2eQ5jI5kS0X=^hAhUs31BWS-5y1fU z*o46h4=M54XkLFFd#|}NK9Nwr-yyqQfwxe;jAH2>`tkaXk)%*kIklI!*6wfmE(ZnV zewQT;Lyf&x11nCkMQuWFdbGAB^Uu0aY_#@sFGH=Ff_|%)3v=86F?i{1gl5l#pSp_! z?=H7CVm>@428i=994XuTg0gFeN!!`N23xR86wDhZRo1GMu-h?ci*2rfoz5STg^TWY zHEQ2dC-sJK61#tc2u70SR{!d{-~Eh{EJC`L=5B5KGa}lXJF3wPG7r?~WAmD$6FjeK zsFkdOvOR>2h$q!$ZK7ohoN1mh|E^FT7G*Z5dRn75-JKTMp)L^gOd#p;9gb=L8EdCa z31HUHwsG3Ox*^UWrW^I^oj5}wGlPidw2YMuuQ*ZGm;-UoQPHj94g2&bGqKURiu`5V zLZMNDbV=$%Z!#SQje_oE+sE4FsyjnE%yKq*$%)A8GqXZMGn&V8!jc*F1e316B2*Hd zW#hTO>Ixxgr9qgEj*hGg_#CXI7mHM?I!$E=Hb8MxN$_Ys}O4nM&hgl|r24ugmt=>vlht4L0!CCLN{Ge-l8kH(c$`~!`{QW9=esmF5#{HZ zmw16A`lPX~7d9e_Y=td;eb@5i&ZkOHf{kC~J@am$R6rPL5qUN0z8@_!DqxnF$0j57 zc>||(bkw6#!-mYPk6dy5`u%tFtf@I#Wtnupm+E=EdOFV>`0JhuOjKxKAsdt(NL!}8 zx`Npvmm15FJ^T3?a$QY_@NRf)Ua~InNv7tD04BkYz^-w@?Q$lYd~;DK&3KT~0IC0&X=f$Ex?#S=|@nHLG<-e9*E$krvBq z!F^n@{26&0ZUr!3871oHM_wXAIT{`kGy!VoCB-wK5#6N2{uXa=7_+rN?a!6F2o>CX zlqh5M;2O!rVE{rl2f$MR-H11PCLA_7F|gH`!N~|rmSt#j!-4TN3XW1`qHz6rZ~X4N z1X0V?49uN381+wV*+g?*_(q&Y7NbbA{iDC&B2_*iZ(n;sm@7H;HSa)v_AsQ2hBt3O zgjJ$S(PYqIaA3{jY*2m1WRTxk8Rs&nu>ww5g`U$=Z?JeXPgw8=19PYIga~$$iBtcb zD!mi`FeBVlm%ij`+)UL|W`6q{EmDIIW2Dt^Pik5q^!B!Nl?zn>+gHoAHjA5AVBvE# zS5I*y+n_h^}Iq>yeURfcgG-@0ueLUZd3 zy3S(xddk@`+*LKaZGMOe*QWIRa!(aH`Dx_2C9=8+zy)h795V;|Lps#)PUn1d-c$YA z-n&U{3;U<@?%263)V`)n-t$YkCk-9N3ebDdHG2%r#w3j0l>1~$+QIcUK!eG;Oi^ZG zO5>~6r!pn`+fF14`umuWTO4$j>>XD?X{Xe|ycTmVB zYtkd3iZgoW%H*T{<6bJ#=rp<_+D*m&SV_!O@LK-L!`|8Yj>T^IOc8LD`G7jdoAux~ zlmQ}16g&FjxAh6Fm?7YtP#0%N#YZIhnwoGZeu^IAcNXQk)Ud#{zy-I~&`Ab||4UUdBnKSjVAu_)a=*{@F#snv|U zr>T&=nY8<~3zEdo7=|(5tRvzB(R_PJ;hU*}RAD-rnQiRSK(CUCS4K8q6p!XnLxZY! zB~6-l#AV7SsCtcozg!T=_&!vjeb)Xjxmv(v2k5_YK6cNP629L#ZJ4Q&!*&3R)IHVx zvA+^%AV~j~Q?JvZSscp-^n4mVD>E+NvuvQ)3xotEIu+QWqW;#vpAH;*l2jnSRdu~=45 zN;|x(02z&GRQT9$@{ACHRa!j)VH0_UcPP0&lIqZIKxeCl-XvPe|I^7KOVuBFvj0O2 zgzMzXV}6@&(u8sP(5n59WpuItSP|uiT)7fj@sC{4NuUjr2KrZ3ewhpY;jsR%ovxE7 z{P%3_IsRLM{fFB5mx})%joaVu0RQ~A|BXgTm)ZOu2Jio49s6q*|0Q4VVu;U&6Xz&( zW98N``yc%uP`m|uA1WaPjuMP;SToZ@)xqM6ymI&ZYG-$b% z%Xuc!)MxD@H7`UCVtq{PA}L&(`91*w%YQjv107@d_xrf?r(mrkSTqd7k-lZ)uH-ba z=*r-QZ7bbRGg7)}4%ZB>KLP%pSXIQ_`2@%ypL425I=TUj`H^dn2wX)TgLgJ_I&<8odgeE0dx&dJ%FlrJO~$ zlx9)(O#VDcr(dQC_rVb6`Zb$;HI_jAC(VL79BJ{=`_sX_-*)YdE z*YbN2V$xl?Gc;wMf>}=@L~D22X>jna=RTb~tuyVP<>Vu_pmiVuvWB%W;X^{@ANr5VN%C|u3{ehP zY9{*Vw?w_q;+^JfW-WTJ)ojELHIlBy*)1Gl%;o0f<&-YcnA#@aq_e5`=-OyX>!uY| z@+DW2IQ+rMJ^>oa=9%ud^_g<8*EVau7)@NBkBPR5VqJyZ6cJj;e1dgve0kM?B7jP9 zAV~U0QO}3qIh*vm3$!v`TVO?Plmm!CL+!P-TDdVV_j8l1x#l5(=GLrooKKM5A+ZCG zj5EY1Mn2`IhQ6s_qT?SdO(hjD;CBs&!Pd@JSuAzX2D^&}1~V5`XEUcSvy?`e{Ljx{ z4SE_m_1T-@=QBh*L2f%Or{3zJcbvzMwh4Gn-Z{^@29=eCN;b9koN7FA7EqKg6kCT* zNhas#&O?8^l>$0u6lV@NQzP;$;r1;Pum0H&BmqZouuJE?gWEjx01XW`S#37iK!`%u z0YcoB)bkyrp*85Vl{EEuXEgz>;+RZ$dw7;y{!1o!sq?8;+l0P!SsK~Si z{Yaqh0%6bYAQ_RJKUC5A&wes-a64g(p0Fqyz*3_~86j6iHeD`r(Zs*^v7)o{?wb14 zRufh_H>FWd?G+-vs0$O#(x^qmlN^r>3{?OEQzf|+SwO%vOiD~Pb_nwSdyPFe1UfgU zl8FdyG#17jWL~V_9bsk>jjn2FGJJia)|-ZO6|;xxEQo;T?h6sVi&6Pla{tS=j%5!N zV%apCU|p3%kvK(azi9Jm$J1P2=iH{{jLkO7V7Sr=@;963S3oXs%)l{SM3HhG-Ky)kG#%t`S+3f17NAupJn%dz+>f4f4l#= z`6mA#5caaE=VgDpG+MxzNxQ;wxUgzQ0ERp7Vu!C20~9eaTU&?VD9Yri&G{@dJJ@sC zzo9tr2gTRadvbB?$%3w%r6ygt^CeNT;1Zf>V> zlQ_S6zAG8cw2A1a1D7UTLdRR+a-Q{*-uH}L#ABZuEx#z&kBMwZ8K^8 zkx8Ce3{tj%4o2Kdbmd=&1d@u`y=U_gdV79l9QOv2MZ9+j2~&J*zXrT9;RI!~{v}!^ zbs4V#zZe?jDJ$M5RKpXVgX6C|r7)I>;(N4ZRx~~7As;Q9L6t{Zl3Lxc8Y!qzbHtr2 zb!~|e3YP=o0C=~Nxw$!DQSYUlCezLo=Yq*6fy8NQ;C?TZGkd%V_)pfs8iH}JyX zV89;$gf<+TaSQEC#W$;ta);<+i zFAe%rQ?tL$Nf)Rh1VFWgit_xv?!>8fqvSE40MWpFzVv~KZcKBI7_e1lNIosA<|;Jo zh+?*=-@mFL*{Z_lI$OBqVl_N4voTrKo5)vOT->Wg5&u=IM4+_&2SlS#y8M}Rl4m_WO!_tRA zZQ${gVot^A5LVg^j z>1lgc5w7(YoB>pKR->xuOx`>OJ`c_$35$Q2{aCF`pq8-hu4-L?)J35lA3E5VE{P{l zc#YQo_YLkqbrsyBVp_dS^I(tZkNPYpM{{F7bXb|B%>cet4i);f=Axz#ny+QC3TY$R zmR6;i+*2_RZJJ^L>8b8yWCd%ZVwj=#qzYVgx}lWHYC`&+xHoNPM5e8uqWt1eV$sFh z9}m*)dz^+x_%ojA0DSD`VXhwe0{TQ3P@CX*-lfb1(47conB5TM5@HQL*LsgTKLOCz zx@=SFam=Z7VYuS7n}yeFkL<5;Tmm%dBx4GR6_Ihj-aZpJ3QIXMyl)kzOivZYcu2R( zR)Kf4-0bNxiPZq$YV(MNOlMPx4d{r(in76*CQP%{xM4(+f2rX7T!v)~n3pc9Zk z{@quG?wMo*AAbD8*!VprQdeIJL+*T1E*^aOIyLgXhToiWa|W#*RYmoOR-KmFHUS?D zyB_{a`kj);jZu32t=L$IuwhOgZ{nHJ{`_w<9TOsiw1 zrh)t95%SsZX2acAwcwoPlZ%IaX1tH(1An3%do!HzOpNQL|p!_2_fd<7o^8o}M*L&?xx6+jq|~ zE5%~w341+%i2HHt2lc?q!;M>cg3xhT4&T}})T5(kjMN@dQlcCtT|8U3=DgdkO$(zc z%Ai~NzRp|2*}0*d`mOH{Ab+qt?lCI%!7ACo>Mv}L&SE@IhgCRv<8T_-XPQjvunySQ zz5sZ8C~_s%h2Zc;U~*mog&=P$raFh4NJr}ZSF&P8;}MD0j@$mJk+eO*!+TpQo~6FgG)Y|VR$QI6l;6lYn!<3XY{E%MlJg`Q?{Zj#IJEy`+%>`i%Cpy zbO+cu5(1wB*i5U+RrC89;$^Rv3wEW-n1T&+$EJI~KAwpUiki|+u?yUh8zG;4q)pNj zn~O+*`f6JuZ**jsCZm5=$g+o;tdSQj{8ZOQZ(K}N%zCFY1AsD}lJ)I-_AGx-5gU{! z_?cMCV~AvFeC4rJTT$Ww*!!^xVU?7+|K%P($pnab{i@5@TM^*%PYVVV&%~Z)rwlJC zIXyke4yqdY<`1YSG7mA2MCZU^I}ESa9h=i3Kp)ci_rxFu-&FVYpsFEBKO!HCmtJAZ za;~EG=c{^c#XfpI;nj;XkCjMIo{1|Rt)Zw$`0}gjSoKpNBXPIjK+~K>)3zSAt`T=ZhvpQ*!t2GMJBI+`FX`N_VKU)^@lR;Vbq8Ng>Bh45p#Xj!% zQ14{xp^fhH5t&6pn1L=q6{)(JoMAZW*=Sx5sVlCp2u`>XaZ zUT8>z z$+E7^KH;&s)@N*70A&i4ASP_tsm*lKlLJp{ghi z!Le6>(hms3k6)wdg^?hs&{TUW9(qt)L(yWkoa{PueJnA&*JCdCs8GQHBo%k~1k3At zti7M}T*aTuet-dv+aoEvgO5FLpxqijUcko>1zjvCyhl0grY|*@(_mR-o)?S_e=jMJLS!CL!)@!4k4ZlX>Cth(!Hg;UaKVz4UsVB-B zo>PF_DXsB%MrpVfYwnk${X}78Y#B+U_QNp!VW6(wUdFZ>M+Flxx*8&>^zDs06MNr- zSw9gM=e4I(wNI2W_95z^V%d8A>P6?r4vTn)=)0v%MZ5MLGlD|A z^c6Tu7G)cf%1$(c{(kCn;>fmzs^&t*xUwQ6<*fUoIYlY@a7_|^Hr&kpmX523XFJ|tVj*K-k!3lv7RX<2JSXXr&DvqlZ(%~^}xj5$64r#}DnGP_Z zYBvph9D3V&5t=>>UMJDCwz~G~cpPBIi_`_z&V^C`6V(Mc1x$cEE7*0^mZOYG z{6L!SxqZz6p|Wq_>vRIYR%BLOu09(e5a(m$pL+8;2Cbq>slM?ue{>eA>oI^CbDpEJ znqQ4&rDO4@UG1}n(6-!7zAAZl&iGUo*VgNRGFutQJkKR|Xv(76+N;0HtsUv8^lxbD zsQB6{2Yq?B2(OEYaO{~%zi8JMVwx!sAkO8`Zmx>1&V))$mnr**UhJ(A=l|$*<-s{U za+l(CH5MWcWQuT&9)DmisNX&C2IWI{Cy+Oqo1q8Lnt-L>IF#P@wLBU4Fj>xq{vlUl z0R)JU@%xjj;w<6|cV&#NVlQJ|;~dd}xbp?-cMtB%l>w6+P*h`AloniP>fCW~%d28y zVwZ`GRdK!P(pAYA0DBJZcvTpe6MqUUy2A<>g z2)7=&E_0gpn}waMlG$qQwZK#O&x^7bj{3AT;S~dy6pZ(1UGfl9RA4AhoJ7)RyRIRQXMd*M=8f$a2RZKSr{y64!3c4_CUJ3A0KYiW3KsPknZ8&GnM|tZJnil`;9utp z_rfhQh{EA2$$Dq(2ayVoR<&;rG~WS^1@X?fAhb&UV-qe`Tau!;*sFX?m)l^TdcjcxLih=C!e&E2%7z`EO_u8Qj9{mV_M5MZER#cV z4m#7e6TGqgR97L$JTwjv{LC(ns(cO*iiow0Y&IeD-Tp?E{zfT9tnSus$HmF=QqkF* znbL*U&j*>ES`i@+5=dA!pi?@QHADbrDDcI3Z3KAqCc92cNWA|_Vx_lw%$1KIU`~D- z;rE-bQsqkcBvVCZyGV-9r_GAjqXOR%$wsW+3xvy-zMddJK3?p~R^7 z@-+%;4@PvBdQ)LQ;;MJ;N}qjukAkheLq^mj)r{%TKe_iM#%O-o8s`5Kd)NOZ^e_=o zC9Mc>kllw~VW@ecFYWf+9#GA}w7~Qj12qJ46H&5Cn-uHyFSYDd}3G zbc1w@x@Zuj8(f4S-7V~EaSI0C&->r+-oIymdHmo9xVWw}=A4;hX3k?yf)M2B34=hr zmqlm|RQ%#eq@k3?#gxVeH%n@Z0)zO3kakgar43*k(F|A+zH;-pzcG@bi{=9tDV2{Z zYvHzP6X=9`OXjKBR)urT)~ap?@R~KpC4IrCRjGe|L1od4$t4eXAk5tuQda!O3rdBW z7J+N`07VM&mzS>}j~E#(5X2WMLPnNS0dgL6fXV<#Q*b;CfRRuY13NwP*I6K=&GNua zM*M$<_5|;(TW{8DLk9$Kp9r$VFB;`f2r%@Fzw>k=F828ni%bYGUVwJXBbUdBO!?8Z zx%oIGIjQ~bgs=M&;b5#q^;%1-y{VyE`8LHb`~a-iT}=5tAQqV0$i{{5nF+iGDq{%T z8kOzOH86r<+DOg>_4I87=0;tRmFq_7yQ5#ooTKk3#t99t@O_fy-uG<}IrtXQBz&_6>x<{L0V zZ*a#O$P-ryfQOCZJh=dKa<Zk@D*{@Q{NE)VQziZNMvKiOmQ||f zTSvK5!oKytqi55N{JLD3@%5J0cl@p_3=j`h!`Irw{v)?$y6A(Bqg~NQoct$S)ffzC z8lFrPCm_0ArxxsApm-%IP3cXt1gBnbTjpVEIMkghUZs{i#vD2>y%}ywuGy@4)m$IE496}YFbjX2tgJf2jcatE9w>djqD)c zTx5(hC3q1Ynn4#h$8AuT|B{h57&c;fUw?`!REaD}>YUO|wgS=@A4w=}^w@G%CrFhv zJAA%hVm4nP&@Y)>q|YMZVJOKu!zuxdHC(M}Fg4HFd4quAwgZM#wAk8} z$aQ%`B07c;g95w9249n8qcoO)$b406k>9+gwq~@tM^N34j_%%cPPam<;@t#1ucXn8 zFQxGrS;I5tS{ELZa73l4G7juArWQ8;IMLAp_GHS`e(RS|au^>g_|aslDPIZBc*$6R zWA$Z1itA!NHrw6H#&L`k@;<8OA9M?))E2JIC~ERp=vZjUD6d4_`2sP)^8~X3>Q2WA ze38F#0sZ<+n74Ke_KR73)fo$;Oo99^qt(x(k~?Ovyp@^dTbZ1tGA!z%EqdpBtke{= zG4maKy(6W%J5#UV^)lGrO63v#9v5U!pH1>WHk%ownGB1~v^ZUKPCje~1i?gkipP{D z$+QnuD7}^a17HGa{u6I|9x~lhUEdrH8^2r~M);O4McZ*o^Ly8OfDFsp?7Hz&Gbh01 z6LIWL@^(gdVbD@^8DowJXR-x*8MS=VxuaacLLJMN?hND)T+t;UH4hK6Z^U8isjUvF zyev2E&6(PcgXLKCFc#KZNnBVJ#j;Tj8W6EuvvaWeeLr+`N zXBNf|N?HKfKJQdZVCyzX(t2IAndC$qVV`ry0-;pz=S4e0h@enz7D&~9GDP&9ID61_ z1-g(|a=&P$VClP09$AvjWYvcfL5z=x!}gT#SJI@f zkE%;04oeKnvoK7>;oF@LzBXy%rBmJ?ON=b)Z%4aH?P40e3@=Czikji84*zUGa!B{Z z5X>}Vr5W6O6_#zSKm8sk{8YUYtV8VlqHh|~!p-%r%Zj&(O6#e2y?MB?UFFACgMCf| zbCQyZ9sF)BR!KVd>}Y;!(93iGXqR1evtT$eiVNb^%S%l+|Ap_Yk3gshsL6Op9E!z7 z`{^1e5aUEOLAMbO9QdMihfZSxP!w0d?o2|YU%h>e21R)Z*vNl&6&v9At%xbRdtUSz zoLCRF!*T|4h@CsL>E1hUp}+mke1?bF_OJ+`ow*ZKK{xTc9o?TS;vG&G0D&Z%YBV04qFL|_96a+XEfo(y*{2`L^ z{-NOE;dU)r$AUM%_ZLI2wVYXFQQZ(+@um^{>9K1gtkZ|)%PF5NPn?pPmyPzBaM$@y ze7NG5QW;&#xXV=CMSaswYT1V_t-D|+3?c}~fl76?HEVP0#4Rrjr5|KIAmG=QSAi3= zBPnx<$|Ry1IR|=%QwM_dK1G}N{_yy(PsG{epl{`2d_pqrA@dBtEABNQuKTFw%8#+y zf(L<$^W!S|q4VpSQH|?RO0R1|MQ{cIAeEmyHLAY!ItCVaTHO6X2)N4wcuLSPX9Y54 zCuBDMn4|PBKL;|!VpaDjn!#j%yCu3N0;{%&Dk0qUnb{klpk)3>e&$j zREX1h?d8Truk<}QGvPB6-;8 z47M1$u_+v)Cl#n9BusTf)IhTVv@<;$;bOna%s%GY;KLu1<=m|4Ru~p?NZoYfh25Ti z%QGqeNB`LNp3(*CnTx4mW+ST)H4EM@v;1!1U*NW=pAHwvpmn^^z;Foy(l5*=RDJGr zB}<$CGKRW`|3(ib+0tKc8k+~13u2Oa z=hd5CBnp$(@WZ$k?#erY@3YX>6f1g5F^G0rYo?7l5okH?1KN=dN1Txc*jX@a;gs(7 z3Gl&rNFXhBS%Y-a;uN`9{f3%kUXGMe=8Goaf+P?FO5LB|Q&4C{*Pw>J$-)zS-Sm*o z>e-C+$kh^)`YQ@iE3};s58+9Bnq|~p=3XUMMqeP7e#KdpLYEQ)fnzlRDLg$d7uIDd zfHZLOZt?86)Kq4tN0-gDQ~@$kPHvo}F1wEr0JF^;z~hcDUD`n#db;zQNoRBC1B0K?tSJ!gY&B=nzFfDF0s;su; zG$JzmeU#MItpdqp0b^q!k=Iu4kxx~^Pd3;q8bk9UD{*+5`HPdw9W6X@ViwmjK>kmt z%ZrinuRU$1ayCF z(;Sd5Y2nt`eIZ%kB$0(W{`%pu?gtuS)pEbWAC7tWjeY64{FXMmy(F&qAk*m=kM-zf z;4Dx;pWR7o@*}4EbWQvrcjTGnY(Pw@-WLTZ+Y=7}4R|tMq%s9g5-~KKJ+{C1Y1t+O zd}&(d=dvLa%YRW2$O5G|tbb7)$c!ypjLc1JG%BAt)t@I8xJ>ldp97be{`vkhTye*r z<2soYG4%JJ%YIsf4`PC13*?G`-n>|(ya29Q@ec+xKk&B^`{^T6pB8(@^uh-oUz|fj z>Ru$Ky!2hqEPnmwsj@&~R||&nlVg^$MFB0!=CD5~PuO%~v%%a5 zjvwSRF~h9<_<`!udIUUgSZg5lYYL>qZTWHBEcs{tta~~Ih0~h%GV-$>Vd(pykOKkm1XC3`n@a@pjI^`5|lsD70f4nh9>yUR6b&=vP>--K?7~RB;>&fQEi1$dAUc<&g9^|AC_x`D)4bGlATST>)Yg0=Oc&Xs7b2lmlE`SWk@o!n zj^Y_f7K}lhjDO(ZEn(1XFsy%({W^t#=skw(3T-s}kD!yU_5Hq(1@xC>bkhj+)^Lry zx|c;3ozc;;#^ZlEr_>SjSpHN3gM0RD!I|{w2JYdP@(DVB41;f#a0@I=&lB5Z+-(laTg#UCBGvIy_-m*T z5b*bS&c9?=H%TCdoyXs@6o;XbvNEC|nBCjVKBHC4=*l{vv=dpNndzStl?xEG)13(T zTB;WMX|D+_2cE7`KTkrj>rFkpm{T>7LZ9Ycg zUHr7G3YSn?GDM_H+wa3>h9=VB7o%|dWlFEfyu2kmiA5*xw7L2ym0FEwei_n)y)K*A zji{6PL{85?5$WkGJh4?Ap+U_inYmz|#+M#NUz(lrBFt{0s9m*$e$$d1blvyo*}gLl zHHOfep>8$QsrY9IVEccRV)MYk67$bjB@Sb{WsVO0G9B3UOetHp134;Lb|pk_MJ1fc zO6{>>p<>nXhWUpjx0z>LW04p^)jcxr=hcSuZdVOp}qlxmU^#mDj zk7{^jDK-cf|3nw@s|Nu01+Il_)YizM*E`UfiPQ0fa^R>b6Xw;Qi@Mwb#i;qFEHT+= zVnH~M8pi)hLba5tzKxjM8Zyg+9mbCJ#20h|L6JH=6L0s?$jlswx3jgAKmM zxcGz_nl<6B%UX{hP-Xg*qYbn>V>8=d%zCgq$jBEQ^AT9oqB@kDUSY?z_v%v*Z_z^o zWhkDWdfDV&fTr3;qpXIBU{w+?GPrb~R{SQ=C*amC*NZibPUo4^_%QB=gCnNq(U1$5hAk!ukkBcO>BuXJln*?emR4UP?xH)9_*9Z^!Daj9aFjw<4FD>U>hRH=NVZQZ# z661rx;l^40FOUbAUt>Xi_wDC^eodz~;=~i15+GOhhvGqvbCl_TOK;BG8^QCs zHZ$iyLlHl9&QK+e*_-}H3N~DaBRPlFR)^NCcm{4R>AXV`R=Oq<4~~MZ4@Z>0?Z$&X3LwVqLh+8(5+Q- zJsl(T6J1qcwGaptd+IO&N@^dnwJ>O$-lEF$O!|UK?7=3VAy5V&_u%HJKrsPu)Y9Rr zdE4)GGKz#3d)D&K7YKCvYFk9fYlzFF^s&~Y$qV6t#GFn~;=7&}+du6;M#?@e)JHeZ zku5&BrmywItxDXPnKDy*n<9kje4uW>yeP$$WrV2VB;S~(cP&h0iIHA9wn@1;zpt-FOc zrw3Y7ro`XRfPk?4iSq`SP7&BMYyrmJDcPhOS(!NLUE`0n0;iwy63W)E#s*|K%-R@( zBPpb|8t`MlH|)R|&EY$(#YANl4w0fm))iJ*gl<+P;e-kyx03mMKW;I*6I^&B;dy~4 z_3jH6lQ(a&5dDoMbe$PbHm)?We+?axglbqMd}6{Iq1zx;UE z`HQ!-ISEl$QYPP$&iDcW4AdnBX=66Mmxj8&cgU5mkvB+14o0a|Cz_bbz;3Oq(RQ&i z*;>3*ntL;sLlW7h8+U#e(08N`;MM0mj$since?a!?~hedraek-^8DTEZgXh{Bp{H| zsm-=axw?(G1~h?uU4z$^5`1u6Zm?kM;!Y zPFe!ft^0CHK6QS@3wM}{;)3+_2}SLB zi%RYbYXN5zQVP&_Z57Xk3*X&X&9s51F5qj;MmZ(Ts3T)>bLZ|Sw9oS7!JM?E#Xbb8 zeIKn^bf5HC)f2`K4(li4Fq8;NS@lOHD+M#PlzhzgH)~6>0g9y+Vg{{@dBv#y`7o?RRZAdzJXY6?_}3nJyS9(YUTVmi!%3j&1!$GgJ2MZaf6 zd9jAaUmxpFO!^N9Ou;!0()|mR{HN6r5PSL0Y|;PE<;ryg19i)dn>l4%N=SCbws%yq z$H_{;d-$a3isrW8N1e{yQ^Y&<9s$aPV++|o0|D;pSI*bCI*DJxe0KAizORdyr?XLC zav@yJe-dD=TgZ{P1OUN^Pwyp z*tbXtLj#uS(&H(Z9R^Dr4uDSdGzy7n?rx*|mdxqyd~Mc@S#plhZk-i*?IvbnPXoPb z?5i`VVVll8{`1SFj{rUuV@-sAZlmV7b#cBTmC<>4Zn^L>e@0#K=v*2@MD|5ckHk+s zf()o2!!g)UWAT~KQW=t>eSF=_>LGzo;!2%9@}qj^K6x7V+$wOcBQ!V0kct-_Mc8S6 zbW@-0-|6#MF=sO4F7B4!9Q&%6 z+@o1-W&$LI>D#V>xPNN06WK)~>w%>UL?vi6Ce$-8pD#@A2-;mzgSh^VKtW4*JeK)tPA_JD~Jmsp*?|qb}77z zaCB-=?B>`bo%?-?%fe*7M39U&TUk!c*~{?DgoQD;RW%-XINgk3BBD6Q9qdXQ(uRnc z|L8`zype~WDG0^QdC>VFuZ%9k^#RI7YIr!K2D^I2NPWCpLAhm`5lXXeEJpteGVzye zdj6Q|nQ(vhfh%D;#mS|M+V)^CbiZQqc_%y&_s;;&Z$S*qRJ_MTX0ko0jdYC(jX2;9 zb;7-f)ORb?#4SGeamCg-LZ$$Y_ai(G$D}wG@uZaGH-l6R@q~mlNzmm;|SHkiRre)4nG~oC4aMelc6^lVirP`{Lm9w$$ zV$>2}BtP3NjGowDkwAG!%EE0OEzm>QPyg`F2$btVO9V2z+a7T}fcDv|Oj&tUT<8_v z9o10i{$vIbL^H?+pM{=-Dmsek)&+Ij7ubP0Nsk+(b?7neh^t!~A8h4>tj9x`<@=d9 zzH)|4x$Qx!0TPfq7=&8!4$jPJGIL}63xE+0pTobTu%&EMCaP7RklUdCT;gcTP@9$5N5+z3%<;dC*7?`ipe^gDQ z9Vu81M~_)xwpE>tHs>YbzD0)94cVfyDj=sM@H^Be&dq36l$j0Xil%VQDEsCUb z;PVoI5D?>mP?w=>fa-TvHz}Ub5l7Q{X|mvm*a0`#_>`KSfB(}0Ku-TK0x5lfzXWS0 zeo})6So-KN2zZD$1_vhv46|!*q_HCpB3vNR%K1RZ**T3wz5O!l@ z3=D68lFUzH@2};H0 zB`gz~-fKF68?INJ*Y}G2K%3Tw+dzK?2S?u##YXFrb3!|Z`j_vGijb{*{?1$d^5XQF zsBt@>ov^r!+jkJ>XRhy85{|>iqlJzc>)fkh+d?1pwHlnM^}~28tt# zbVDPu0LgJ;wyLQ@YLJCU2|p}RydN2-Zg}G)p06p-`eNHp-aqQ%zG0ieVAOdriJv&? zBr^(l0Y>-@?yK8*;vpD=MUG(WOpIw#^pRG6*oHLEYm$8kwdf?Sv9VKrJV$pacS%5H znEOQ_=S_TytdDP>0l5r2VeE8Rc;~nI%Uqv4-v{J6Za-Dt5Z?l;%>+&!zBhlUxkFKP ze(>cyPvJJK++;H<&cK4+!JOI*#qtnBFufSd%upd;Xp*m%Cz8gfqvFf`IcG@_)+20e zi^W;j(B=#l(9eJ5r1nun4jqW!|HNLWQrM4xOsEQqHEuhF#+7=#Z(W|SAsno#6XCf} zl=)Vq-aLgLR=zJzSJ5;^jKYJ*k5)U-vlnd@VOc3?P*6NoPGXT%$D`!{Hg|8JQF{}e z7zXbo4T_Q%Zso@K)nuM{-+3K~2q!RO^?*QdQ@CxdJ|A)NBZourg@7=iE3sXcxRCoB zNN05+Wjhr7453AHyHmAPO(fJWdS zX^;!Qv>>!Yj+?6&Az5#cs(F1V)xUvW+kt|K-K`aTsST2dL|bU(1JJ*@N`v6C$KIFcZ*&`6bp* z@h|xXCKFxzd>@M*O@I=JbPpo}AB2segBq^?@=Q67Sx17fQx>Kc*EJ8Q#u82{h};ip zrshCU6ppW_#?vD+auV6(+OCzgY#+1%!fdxq{D8C6gtPHo(U7@y zTXvre9gRv1mhk-jY{?|*CP1?U!ZT5Trg|~Iq^|(WN9OSPRwlg+{)5g-dk~>U{A#p( z)9%8G-ro70y-2s2&?|ELs4xEl9ZS5(l(U*MTgNULiBD+Pjk2RBCsi69BoKRNl6sR3 zQcZhLSW}L<%XY-x^hOhr_cYY~?`AjEKNKfnE~F za|1|!mU#e~ug>Vbf?Y<0M_H?}5Yh1g5lQY?DZ^<(<)-Z#Mp6%+kb0YCEMcEFhU z!_`{^Vc^hfxD}u4-vS}xs%_qgrqRCgK zfX+3x;KP0MY5=k?N}m~5g*9-PIQ&jm;@@)k>h8htg8aURTI8f(#+pO@nU4}1#qwGD znD+baMs8m^^439>{fpud-iL%qKhQ~3o%W{MkRb=F6OiYA@4%|*90N_C(HFrz6SiRY zt%U-O2N`j<5(Nb2=5zqYPKM(WuHOP%f5~Ud)9ypa8W=J_xA{EOQJ^)=wKMe~{9O+>5!dR5 zd#r4(WKqI-sDhVER2U^GDc2WnWx+eIiWdUiAEag>iZ7Td%sd^DQ~7+6Nw?XJEI8IF zdp&As;4iPt2!uDk7+?q_#~(u%AU(U{K*YA&q#*&`IjY*MVk$9nMpiw{iyIK!uL}^6 zg;q!Hfp|`zKV<rTA;|ER=e?L_6neBo+G&FVJEMN@&1qI} z6JXO6k9Mw!#>toY0;#)(di25Cl5lRn*4dFRd^c4j@~(^q*8Asxq750&wr(^9dN&C_ zWeU8viQOJp*$ViLlOB4%pYWjRuA3-`nNz%^{}gbJV1nb4`?TVbNdD7K6^B5x_7 z93q8+o&LzQ(7M72Y%!0#p~0_pWH35lQ9_al&-`{NjpJ!ePY?O!mjwSMpfd&{DhcR# zlZiBzz2A+NK%qFR&un;re#Yo1lg4DSUnByxR5NI4N z99HICEo}ON*&Wqvi?D~j4e!P%+`lG8V?rna>R;rD6OniRGai5d_KpkuPPb*`Ega}r z$mu-7aPO&2WZK6OAA;w}h?tB46F(oV=lc+k$wZ*;Vk;_x+XiSi<>GIZYdWb95_ZmsGzsz_Vf`Zk!LwI(%8@ zm$V0^oy&L1d>1;`b+_QdTo^@fi;a7Al~Kxj6Sc8+&UmiKjegcDXpJfT`arHMm2Egy zvoOGU@)Iugi~zEZ1lK^K)1Tdms6EStPu?L|T;{!(Q0~i(Fh(KbICng6*plzgeRQ?* zWjxeX3xPW~Rb>3K6aT2iaf2H&A%^3yKrk`x}044Pjg z2>OJ(XcACnM*HlMabd<31w`hvDC&dlxBZI4u-k>+BL-`-OT>@cub+ljPb@5jIc0Et zNRd8-j4sP%=&0&l2`c&lWTeR&2sX+2?BCyDr)A0PCkHr_RjL=A zwU;fE8kr-4?5vQmf*$vF?Zq3#4%uq9TVt-$ha3m8kY zMpxy^Z59Bfzu`KI!T4q&)n9JcmzxerHCueFFE?MczNX@Sp@D9n>K${PRF}D$qa0l- zSp|DN;ri%PDqT*(ckVQh33H7Iz0qFg3O7wFTOzgZM=&(F@rxIOKlW}O-IwPx_;52 z(6V*jK;yhPStW27smc(Xvye$NdPtHHp;0@Q<#!N$*Ea8V7!TQFyOZ(dI=GX!XBysh ze|NB*C$jj#&%U7bP_wBUYvw@5TU`#WOZbsdXt)+)w-CF`<<4qA|NE#JU%TMUeBa;h z&P5Y)eJ}5hHDg*knl_t=z|5*q!J5&k|9wK!1cuP{UL8Zv@0tUFW*dRP^{@ zt6QJS$vF?cRW35^&*6mI97T<`dEGLdhF!DNpB_E-+b$GiDqA=}e7#_Mgv zI!8|W7rRi(42K-t%a2xGE@qDes)$(D=NLG6)K{Y>Sdh=3x8In-e!Z?w@($6;x!TZY z*tDmmJ<23(QdX;X2r}B@9k2X-ITAhggkc>b`wJ$`a?WWg!p=BmLS+d@rn|N!&sB0& zmTZp8&GYXW5JYlMCUuY2GXGZ$^{$_FOtLDM+)cDo*Pmfp)zudO@x)0s1J^Yx? zKul4^O&#|8$Z|a<<{`>au=RPR!YtJI;bz1Q(Ka&#T+ZIBt5(E$9M*`_!A}9xdAb-* znL{B+`IgLeFScwuef_Zfl{MzR+G;{~d`Mh@gFj?KOL`Jo#_+DI*%)hPXBbSryWz~_ z?Vj9?#o!*P6*(l*yyg2D0&0&^Qou^5z>*>o&V;*U0rTv^1uF&0gQ%bX_m! zdiic;_e-z&#tQAcO}oRuvtA>bdFDxpuQZe{Ul(Y-+!7ri78kyGLmSgjCYn+&Dt=|> zcNhHzpWamg_d>93jNKNPySYSn^#$CJU!R#J1$#qzU^0IZ8m@SScKdmyo3A;|%EA}< z9SqdM5Sk*vhOebN9F1tQQQ^>Gf{o5C2M-s~c@`&SQTxM;RjctO_J*vN0`U4zqt(Oq z8(JyR&s84yB35W|B4Lw$MI&6IW=r3eyZmj|B(NCvLwH2`D3qW4zUqkwH11$3dE~bX zMbz4r>(lJFzIxzg@pxg4k0*jvv74DLJx2LKG)RU0TZ>@ft1CM znYj6lTJPzWeE4cbR_Y(7fyLkne)ptzd+J`dz(f!$G&jL%a$&ivC?DPlp}4A0=!c@p z26Syy7A6TUj#Tj=Z@)9g+mXxHOoL^{c8w|8dEIs0Zf35>wbGs$eX@Dmp>5969eg=N zFyFdJnv-9Iobt5=|JnwZjiIL=1@Ei-#nnNJ?s~Pafm%TKW^WhEO{D>m4q8vDRt zzSiJ^s?v%2WZZ(hAu6C1O-2NI8#*2;6o!EJS}XD&>;x3h*?_)8p3Z1OfNWOkM)M3G ztSXzGEk92oE5HxsVA$kj#zr{D`g#y+W^1i=zUrGd&XSE25#M$qh}8*$+5S|C?XBq_Ey$crMfS_64+Tu0_8KFY$#zr zLX5~rPNWQx5_QwMb*g3}13?=v3`=xx%cUuaC>Q32F*0lL>soiH*a-_;Fv_ZB^SXmu z1$ArdMn54+Kn5zO)6K7fu6v8|91(l&11&2&)|E<4RgTVw1NEA8-~80UEoBT-E^>V2c5SBn#6}&dG!|_^{FK6Wq1{pR z8UqmCpa(;j-7Z*P_1925gh?vAz0Xh&+_x#3Tw^Dk2z)^}?{-nZb!I z0<1;~Y*n3;q5d#z9@22#=%CKR)FKZH%UcX2?Jk6$Dzobr(@EOh`e&QxA${x!0kSuK zmUk?`n-9TVstX7)b|X198}R&P8+wWE=T4k9%L`j&tt$CgO7x@rWx>17nV-;vdLh~! z2fMwSYnMkRG8?vw1}k-e7RR*jSz1nwt>dx4bqv7IxvUqOXCiu%5wa2mP?VbIzsdE` zi+RYK%LTNLz@X{>;xQ8BV}Pjre?0a-Z~J3;|IgQL7v^VQJHEKJ+z?+DZD=qaR2Ej1 zz0u*l!$JO*=bh~s|GY`?e zy5KO3uJ86PdI*jq_&Z%eB&U}1h48Vm>97IAMRy-~n{sc&x{^pb>I$?~eU~cL=Ms|J z!UQS(^!NUeRKr4O_)zPXS)1}gS6ltpCAYCQ;_~xovuYW8wcO+lm_30{dzoq}0_ zyI(o$WG}|$EP^(u|IjyH_u+EdRh$f@?K{sb`lE@~gFnp`fIOQ|56H1MIu#ALVTS|F z#5Olj5O2-74x~#SberxBmQKe+5Tssuqjcgj{&%>v|92ha|9RUVh~b|FnX)Ho|L#>b zTpKTPX`8PKE_&2jb&w$8w7-ui$ac@0y#2WS)GYomo9vIk&N|S%n^)o!o7?>4?HvU@ z-+C^rWCq0d7Jyzg{UK3AONbj|i|p9L;A9z+_QsI1=u+Fq6ep&*6!}i^8_oHBkhQKP z1n5ZoRKou8B@P6z%m&^!i)_lmE2{R4zB4_xJ~JL0u#CXZWjF&Z>n9riY z3g&1dm-^MBgnwNY-W-fND}Exc|Bn8rW_V#eDk8O&f7mK@uG>W^r_KTi6uk4XTJ{TT}R_qR-^XV2VON8tS!$hrfEB zeGo~>1oD3nFw%{nDPT^Y=GQBdl1!nUQv&eWv6cwE9b-&7(;<3vu!4Zw)PCP;Wv@Nh znG9JTuRTIQDc>C(?gRgpu@5h=@G5F7S1os8Du#1>f^!pgTPhOV{M5|N+TB+CL?hCV z=6DAJZpS1e4mSG@%|9Fh>>6DY-{LSa)Sv7J>JAyh?C2%w}_=EIytef1RE-y?0&P7G&D( iArzCwz~gbSb7XLPm8R1&M-$1#B`2jUnJ0el>Hh)@bJt4% literal 11428 zcmd6NcT`i~wr&vp(G(OARGJN>2vKR$6-1B{BE5y8B7zWVKtK|erlO!!DFH)~CPh&K zfe-`~0SO{ON(dm*5+Kx20)e;V`JMC58{^$^@3?QgH{Kr^N%r1rt-02m>zm*F_Id(^ z7#-j}#tQ<04qP+7VhIB6$p(Qqg1GkpSHycE7lAL1AWI{CPz6z(3jEpYdD;9j2=p$I zZ`*wz@Sn%u*dYi6;%{MpINJP*Z-GE(HLhK`Y<QwH!yjn6&*kc6qPXQ+&Y5$7-MW`vZ=D;eLs5Gk$dQ#N26aq0?z1y4)&x z$>J)qmv}_pA6~lQ>9=P!>QMHEQirbTrCoro54ED<3VdY zAdvk&eF@Nm)Z-)$kUh_T@8=UI3ED!#l9*pZb-x4%^w+u>rg6QbSnDdUsoke4o@4y; zqq{HZWm4C?tcsDVJG!evW;R-q7=Dm_vL`R&#d~ulLN2d#ow+xz2~vN4VN}-1B9^(e z73$-0lsODt?^R%?pC270RBC}hZ#$JokfBGNKNpye*4_sj;Ef0Uiyag!VsWH~nIG9u zF3_-iH&Y8C_UqvRqC80}{+{cNAK^-*&JFO_9$A#v_dV0kTYkOHa(RV8dk+xHJCZNp z@k_`h*eCOg@{N~3ApaZP+i`(1Md&~*FC(N-No+Eb(GC^Rv2zd`@TtM0>n*YMCqDlE z{#k-Mea36}-1C9*dG}qS7Cwv<aYJ&?nX0AHzm9+Ez6 z_+wg9=@>0!YLov8qr7ltEqibe$lt{7AWdWUzRJ*xpu5ibn%0wey>M%@SQi6Df=Xo! zyTKY%vt-KDpr<^+#TEn_yXt(oIL>(O$yqVO$0F^pQvS{0l$y4RNUI>Pi>j?W`Z_P< z4$gxfh=m@;(5=h`-*xp1;qQi}UX5a7mtPd0YB!r$QnPn#H~;)S3VDZtDt#jXS2=D9#1_(2R(muKmNk^tfO7(@%?_K=&g^4ay9f}jMb z$}CzF1X8#R3|S@k|JhHwqqO?@sc!>5q2XhHNvvH+W?f#7{uXdZh!Zqc3bQGea?bIq z!A)PgPxr|lc`U=;XJutP2<%m`5Pss6-nqVl)U%oE_2rV9p8KIO~=# zwbX9?X-cZuN5V*rmv6q^t4yV_c_{_2h@#NJv~N&B)}8Ls@r;z*OCKMRArSZkW&Jei+yanu(! zGnRqZ>?$VNSUW4fv7K10xDAf^JXFz-brQ`)&lDe2^ ztFqlCEd9Luix6p&mBQdEnV#8r_?TfdQ~6c4G6tCvKyL%t*Y!r@>UVhS7GqS`;md;d z&LzFeJ+a|tOsLh)(I0ncf|Uk*&r!RK=H4TG5*-K)ZgenTjM?dwiAtF|gHV@}YsRWU zb=}H6f>MQE&(?IP-JkZSPaQ`zi^`lR%8<#}QYp_2c#2gwj(Q4pHEF)O!4tlTP6yjz zWC`uZXq#_8w&o%-9|eoaP$9O5jgq~GsNz;E>+hScb~%YsvhX4q>gvj1hUU`T@FicN z6XoOSrlSTve4sNSPoa8q>w@Nndr}YG*t}mNI;w`a)$2Fgb5Ex$RWZ~s0e=k-RV;c; z*oeJY@)u3Sws(;=!C&}Xtc<7J|6KQJ8-Fpzt+#aXvs7gjuvWi*Z)<~w%t+EbC6f?x zZ1~Bkxm)2oFUoEj^?T#5>wnaCF0~C2ySe~rk>%|!@tH~S1&OT{9XD$6nQXQC zSaa>g)Y$?EZ7&EiXN?_A6s;sMVlF(5p$;jEC2?8xv$888ht!5zT{?PSQ}pW!W>0H} z_JB24&2)LXngeAlXDqvZ`fO#qimK}6rWQ-^_IkqUyyeR}OA_8eV4}lBXkYf@o2Ap5 zCvzRM>sW&^ugrv24jnZ;i~68-AYW45w+ODRoU4N4Kh_z8F6H*C&3W0c##5lp3I>h+ zr3fbd-Zv!k9CpHRGgHY3TTf|45cXG{)cP0~oEmC49m6zpludtah}?2GtlX1brAkI_ z*UpPOFSa(PsB7Fa%dHF3C`^kiGt933>i1qQ_?F#3m-)hC6UZWK=Uq2nux$s1% zx8NV9bnm{Ry&KN@{m9XAeaBOz`|AbsN2|RY53)YCLK9D*!I>)<$r{5TN~qn$y~tcV z3tq9|{u++qBdI9JA=pl8eQqOjhc`<*+4|GZ6yGeB5t8`0)5|#Gr<+WbE?8Ge&{|^v z6pz;shWUlg}iTA2dM z3A7h*-R;LsW;093(VFnOWlnB4ZD17ePBp5~337%MO70rG?c}=<>ICbY?rXSPKR9FQ z%3BCOm|%)DCD)vb38yRbbG>!hqJC8rbI>0D$38wj28y|boBS3Ru6w#3_e#l*)-6ces{zOS)BJfq0${x! ziA-J)q)kD#Vhms%mhQTlak_K0tOPRVpMx&!{v>=?Y};2Y-LA;t({j-#ZokM5_;&(7 zqCUE@XAlJbrRR`PRU7B8)6}I9ihW`U(jbpFB zIp71-f)oMsZ$7+B*o?sK8=Kew?a6lnnovf!VgKfGSJv}>1YcA8635=F*bk#6yCX(Y zk#Ds?5M$l&-7yXni~pG~;3(I|6^bisSqwET6&WK6b~%IeMQwHIZPC|P^SRy3I(ZQQ zwf6dd%-q7e-BC4zG&K+?%KipBSyxY3|B{b_*Jx3~)EbNMbigM0cs@k#OjZ=VjzZC$ zhn)f_!#P}G4AVU*D6Xhn08`s3|~1gr+n=dnK$Z z_ffk%%Hz~Nmkx-l$c+mqy>spIF^y8WuQ6tt>G_{cbYgHNY4WwNePwPA>QmJb3cbcF zPh#LnNca@l>=+uLIL@s{FiL~BZ(f+l?t%iRD2!DcV%2dT4c>cqg>7UH+)nOf)R14rO;H zm#DPvC$(@;BpM!xP-Dq8}1wm1A(_BBsOxjDvkA zy9%C$W!NXt3T*Q(-UU|OKU+GMN&DI#GyW6DngYnF%?VN^EJ!_vJzKv2jLAI#cJ~5j z?RDn$z31M1j=}vCbhr_qrvO-K>PtKr2QVoC%JrHZ=%+{=vTRKH4{kdli>1^&dv2F` zJg0<2e40+4hL^>mIk6%b{%7!LXre>osINL1Hc;WLLMkkx>^ySie83UOD05|5Q}OE~ zy*Cf&OB|sXV|Loz7YtZc&wG$Bve#$lglSH&2Y$^J(V+vCg3eE80WM?EwTi#2sVSl1!hhts8D~$mQhR`%Cez+k@T6 zH(Ns72)AGZ3ev6@L*I0wE5Rp6rzn)AjM)7QbLWsEu`xAL z%ml8rZhK|>EdxW}abS($>sTZFnfmx%@gqP1@C@Dx?I%y&z$)0%O0+$~aGb7%5%QuZ zp3N(+LM<6T`7;gh{o+UX*-vg__{XmN7hLyG&x(lB#(%ZM`2opibB1bksOgo6Fii@z z4b(|Mlz0JAQW%Xp%>=-#RdrwOWs1NUK4P7IY<*!AwK(>vexY$|m14Gh`blMUb$-<2-6K0#oLJ3&f_@UI7AN7 zevL%%A{;cWMI~Gs?!jhFb%U3C>hBbr<_Xc7^3Hk`LW)<$5m8`$341PETEo4ilca~K zZiU2nQT8RCe_gU)HDN{QZN|H5#Ot!WaUh$@t#ubxa;|ncucu25xm$N59FZbg>9hf~ zM*t5~3jMw{l^wg6`8_ngZ7aVcl?a~9EbS<^PD52vrsS#1ZIVQL$tQRy_o$F4j+YR+r~#oW$we_7^H~W z(3E?YXyrqfXw54AmTid6Eq`@agW|YiNX9X{`OA=*)g(|F=X)X~e)$sfZKIS~G;VEB zO+XbGXXfv5bW+V?!ev*n!?0nKV!KcZIeklVk!n|%ORL#5G(gwW8?K@b(V8^(uV^ux z1=A_izwR;O0+VJ1r_we>!D40wXa zC20o5jFRd!N`!J<#kQtuJ`e*$lYFOf6N#qh$4L)+-dS?JX7A*;00IIaC7}QSB=BgP ziNpiIsDIt&b1jilV=gMc)40Ffj>PuitE=&IVop{cHBXm^*!1+6Vc~n~=YJxC2jVFC z;%iy+5bVQ!r+^L=?-wEgp$td8rfpHU5~7^(KK%eg-eyyCIEVZUplENR;1QDYa`xH!6G>RBcUYJD7lOkuK*9a)%;@RQT z#FoAGB{vU7Gas=Qf5m%xf_1ksbeGh-w2%z==XU-YON-%0wa z`d9dexm)i?!_s|1a{k%*niiwAqAJQXE}SuWoGR&UfG^cAzUgcb8(tI(7W60;r7nb+ z<-cgeSN`R@SNL-^t2Hb|$09f)$5gGpuQZpas?jBDB!(zd@^X}hAEpUT$eG;q2vyco zF~N=&W?o|^?IP|a4;mJC9=CB5q8;gfff*?g%=;+6+Gkm-CVFFZ>XkK^&vT2%#xjr$2D}PN-S%gWVbk{;*jT0`^; zn!~@&ZIoO^U%wv}7+7KKlsoDhdGd)w*&HDl2NifY1gp;3A;_Ldc4zFj{_6n4U&5?k z0}l_Oy+W2!aES#<71PROi&EzgrS)I84;>O!?qS zgKwY$rfc3Mk(to$vdt1FdXu7>cQLkK9}9Elnvdy|TaWAuInowF$sqdZy{VzTp`POD z>UC=lc2!aEl%CV>(CDjA%_HCTw(^ZM)M})qkd>yka&;Wneb%(1O2e5U(U7v=MUFEG zNfAo?TQ@&fP5J9cSL^A7|7IGn{JGT|C(RzM5jUxJG>~IUERHah(djyHq5lfjVRc;W zNUx|_FTzu;nl(T}lGl4f1UFAf5I)@{=DZ4%^o?jwCEu(o*RwsK{0q=EB8&ah+5>veX>Ih|j{k=~vemmM;{?^dYLq^LtU}Q>W1IsjVl;KVb7S z?lzepIbS8^RbMP@CARc`lPQ`$Oi>fM!}}=jWsd^ZV};c%;hW&G1KmA6o10KFbl0OZ zlOyXhgn4S|s z*Vvqn;u3H{u@DZGXDo8Gd&0XvLzso5vraLPBVs4+5*9YmTdS1run_)ch%9^L*B zZ}#zfR%U`V%k^Bx(Y@nba7$U|hyRk#g^V71li4S9?aG?L;SW&V_Q;LfvZ$Elgper&zP9{5Rj6x^QDA zUw&a8vW9BC9(3`*pm>MT_QTa0>n)qI5x8Wz)eB*~%u*awk~@FG()F%4|EAfucF6Pe zvnNUWF#N-{@ko%xVqBoS%ZVs@p{fhGGs!z zeEb#1EV0884wig7ZH+xE%*9I3X@AqS*mlyXXv6*RZ{j*?XQpO)Ir@!EawiNkT73Yl z)n}sdlsD2&@k9FXYii)QxOqHtSOLg+#gnnj`E%)FMzg_z(yZ}E_ci+$m^?_~Kk1Nl z8`gE0z%Mkakb(53m=RPlL=y@7J^H})!Na2?&4;T)?*>S0C%#{498H6YvR(Xdsg%-e zM`OB{^9=1a`uxz<(tHF4|hqisGv3YSsu9H*?7{1@607m=@vX zQuCRNoEdqB!8Da4U}YJ#e>YR=q#d5eUWQ#m0DXSWx2xan%XE_`RjzsY2)4;3N*4wm zG?8oz!yQtG=egU7OVNH*X-@#WhlpA`KW`Kr&YJw~c!*}e&i6pNbU9nOvS-M%R48-{ zqr@>J6Q$s&>3frfPIGT zSpGnV$nQ5WPOf@61(wF>r;dgYZRac&;x`8A;}Jr)$C0vB)>AZ2>N$9(!Ots+CDeA~ zPp#ot5`XZ8(jAq&56#xad{VN8mS6k>0?BI_lXqz#vC;40Jt)A6t&&-zv z^}5s$6{pk|oES208EkLdEGMao-G`h}(!Q-vS=to+eJ0Mqsa?oNlc+2yHSk~3hAul*UeWKs} zNKcZ7D-#-OgoGNi&Z)1%w=O4eBU~LuqhE)Oma21fUSU(gZ4;fhVLD=BUgqM>KJp}3 zsi9o9rITU?5281!i$qGb06)K4lF=yv+c3$Ak&F&jGMGuA_MY$kdgu;sL~nw}lS{50wN8A9&CzTx$_9dLq zXw7q)wlt71P}C))YJvcMo`18D{}P+d{`YQ+xfSN*tV=gr5tW!#l^HT?hrF3?A7Ue# z2S}V|^QSs_r#1tVeZgmSpTU!|pX=~x_-QOHMt?ZoAkf&VdkjH4>tD~dEv?Zq{kvk0 z1&x#HZ2+^X3fsF85FT(Rr!D*=AXvN@$Nj!Af_|wJc`cH4<3pFgorT&DZtbOiJRo1o| zHo@+-%)PK_eWbKVqkf8debU|8^;ArFL}N$e%_WC9>Z;+4d`k3#_0Q3oe*!JfjwYys zxZ{;Gxr!(e?lp~m5rQx?iP@iw%KTVjg2~A=z9vrc2$|7KF;;))q#-=@{foOMsmN7g z+gtZmDL*VSDuahHbzd>kVjDw3A+9=(Pn|=E)IMi#ns}EI)71huQ?n~|yn@%4yQ_Q- zoNl+w+4tjC^~>V=`GB1o(o>Y71ts?y8zC_oddC$0nb7Wf_k%&cYyjsI z=2?F}cBF~mEd@^J3G&E`8NWZ8WUBVzs+kr~N7X{$MYW{>`?L9EXu6}DjIv_U=cI*Qp1f@Qd zv7oNa6DarcO1kszVvE2>!3Q30zy@Ipu(-$K6=MGt-gqSw$X3Iv`1GPUogSJ2Ujq&>iRtw#s?rA9@3OSb!AZcGER6 z{AYRogKF^9TN3McXKCAOn{WZA`qL|Wt2bU*kA<-F%YiD(^cRfot(=JMb_S3U|Lmo| z>`P1wq=xe}bdPK6Qk*xoby}wr>WzxFep4N$Ha|_&qrt%z2m0Fz+s@=q7ZsUahR^1L z8!0raFBG9Ron=V{;B3Jkpwi7F?F)MR3lIoSRgx(9@UB2?Yoc#UZ1-)Hb?N2+ar{z9 zp`<=VI@0E-Js{m4q5QC;$<;_ZF!;B9icPO+%G*ePn{=h#5gX9&XqMML9qMG1+2)~B zbsIn-Tudct1s`A`I%s!|+Ib~MskYyEyo&(~0?VVE4&KTNbiL6(d0Nw- zgKs|~7ZlS!(rYkX_Yj)vb6cQcJu~N;waWK=k2C4n#0%xLTOxM~MoYF(3qQ;^)JVV? z3U2jZ*Mi6L(vHzIIJW6abvY@N+OdWl>kRI@;*Ew@l6U7+RPI2p(E_+9Q3@|@#4dQ>BS%f5fVz@H*|GRYIa zKbq+UXdV1x!LfV@vA7)k2Xd(w+0UM3gF63=96&~@fF-HioWgh!G-A9>GLbx)VWVRo zW;t2xE_pq&mC>h%-pnWdr=>6IyvU9gkVmVxp_NKMyFQYg>*C*dsMpxKUe|N^ig;b6 z6=_&`#wLMsl%i&wNM=nwf;WC4^dYlQhL1u z8LcB(|9ne1NLFSx)UwF3TrXAZ3ji&S-o@$PQdhT4v2@}7sXSZP2t_QT+slVEDkR0N0&y+p#3=2cNb%h1bD#hE@yggbaXPlYq)e{=_VP4t}o;X>vW3T#cxe5@q zfMRQVEJ}brT({DpP}#s*BLg6t2Gj9JJT)UYejHJIveYc8@& zAdJxW^*PM06ope~a~Q-EfwA5q3n`uO)n-2MOboF$V!gsP{I97F@y$-}+Si#~O)hxf z-uGFwW24te>slcxZ(bid^RrAtD_o;zpr@sjR91EsAL#V+TZ!x|ts(KwZT6fa8{c?W zrYhe3%ZE3KSf3eABfg%IPB%-0F7_pq+zV$HGe8+7-QyZgEu7AYfb49JeTwRLMZtc~ zwkMyl_%NbuEIQSiMzR~r3$Z$nP!=n5A-}}mSKp^7^ab&Gu&49MQ|RIi8(PfyA+O*! zo^9EB=)rtttK3X8^4HMfeO-4%GrTeCsuEQ9$gjlX=gK1_5E8JZ*1t2xKg&p?NETyj z^F3T3&Y&(N=q$pD&Jb4JCI<8*)tNT-ld=v(5lJ^Je8pTf1dbmzK$kXP?|Rw@iwBUz zAqHx3%ZE@+W{m@tj*O6%JLpFRGpbZVsC$Yt?XG#(iQFd|gC$F857;Z*BQRF71Fe9< zjLrAe@z>++Ke>d=n)<{0%pbo80*R6NNU|%rCQ}QFzG7=Z>S+%l&%A3&C~V;}?A`3m z(4!6HbZVHJ%cR%q6FkLSLP}Eug%2|;9PfbZF85BhYGjHq>cCv=Kz)ee*XGM5B5rj@ zsveR0lMmZ)!OCc;9&jwEHXvH_XKP&Ow2}q}IS;IaDLcsn{FYVqM8NUDkLvzr1M*zd z(3N{RS@c#-P{JR=y~3L>FShQ!JPDgs?aV)>&CVMq0J8a0?QI#ff3!Hx^&RKMW9+=r zkQ$ykbHf`zBYie-N0pPvSJ>sL^q)-SS~6Q6{BCnOo$xlxr6T~C25^M#Px|A?{$H8; z{}~bg4_d>4LSQAOW@G=)ayd;vO(xFq?LMx7D1fH_B-{IiIk`oR>8oqq))csNT6_yK z{en{swmx!zUbDwviJjEP?Py*l5>hES`V>htFG8}CUz{y(tA8`0fa_pBMNn+nVhPlu z9F!gZ=kfx{3OPNBDVn?|Msqxc{kxZQ3XIlaWVehT;qO(;9xX8f7Rj8wNPo-W?0Opn zVY4+LJ8C}YWxM9z6!YSnx(@*DCTx3SDc>lO4v@8JqQu}&PLK#YNZE`GA7Qs!Es(Rf zF2y*{v;wv9E6$Op=>i*{*zc~`EA;0@dM#U+FOV_@-E=eojvHi@h a)XNZ#6XFq{KLRIWQ-#yqsS1D1P~BpOqgW~T2w$mKvZS{6#+>g zfCvc$2m}S0OCZb;BM@X(!kCcoV%@&?^?mF1?e5pT-h1n<`s1wR+vl8bTHpTd-~R3M z;F_fgKS&$|0095hE0?YVz!T4cDCv}6;nLI(?lWLx$M%w=XY~tf ze!4=uWa=g>@vEbtWPI?EvTaw#YMytC$GuLjZ02JkF$<;n`PnO@D^pW_4O5Z6ws1H# zG7Gb1Kr!sn+FMiGTkG4~?aKs!`|q{H)SRPN8@JX@0>DdTk6P?b7oV8wj0pf-qUD^q z8?`kV&iKnM2zvn1$mrGI`56GL33M^i_WN-JDNkk}a2V~Y3L{ijRi*uIz~KxG(yK4OC)JbueihY(=xAw2 z<#<`Oy#x(Mw&qziaZt{Ofx{0*#a75RBp11v-={0)_tv%OJ70sEScpbyu#+IFbZ8taY8NEFN_LOccTO$;VWLwz65gtu%iris`voBXIp>4vozzla_ z#QmYl=>D~gEPtBw&O-8rol)#>ZyMbr*mL?m{3TYxfTa|B%vuHKB zLkp_vT!g0V(foVXS3q0Lj`aG>)^HH@4s$AZ41TC#b6T)`PV5_srMVhek8tz}M(GY` zv@<4ThQQFFHSVBM57+%PBFwtqBGq)_a(y9tjT66y{V>qi(ZE_yn~2L@iHT-!Ebtt! zsDPmQdMMAvULq@uf^5KydTQj?>;ga7oh@>kRTHa->a%zJCetd%Z`XreS}`$n=p&9e zOVfsBsy5 zUDR?XPy)Db46O+`0nxDXbR8*JjPfzN@_@usQ+%f0|da)Kc z&{~lpvlzQq(=IT?kXM_yKfE_at1uv1`&H{>TICbYN3Ifgjs`?;QzDJ^dLug|NMi;~ zA@eneiO2K_7VnlVgBTaK^5}`PPyXhbpgY-dLPEaOemzp@u3_91znOlD6zAx zlOvcIP*(mbp&*J514Bq6nF*EtV*6axfGq^}D) zYx+o?ip_8ZydkECRsU5ioWiH$J|K68vhJH|7ke^|n&^A5W;huYF9d8#T1@p1|7ExA z2%8sAjoh? zqg3`{PKIoW8jM0v(~>z|$H9?4;H_L-h~@dZ}K_ez(sQv;kdq!$Zm?@Nyf;008FCNh2XPQ!Dr$4F{ zc@cHS*9t}_H%6vIa}#8$_T4pnuYJnt+>GaS!Z4#|P#V7Ht)<{+)Dkv<|(<5iXND zucyMJa8h5FYmt<^HiL5w^DT6+ zyx896#~v1@aem4sms4C`_lu+M(S|U@nA8aA4Lw$s4}ji3CX8dtva|4=kz+?;TWBvL zTDxgW-UNkZB@j|5dzwR{GFybNoi2I+H=|3uDZYYoW1Noi$IV%-wko#T#f=&i*KG0RRq~!UDiyq3`kK5)A+} ztj_}H%>S9m!xOE~$|FK1gSNtZ>2;aCM&GinVwqi#52-g$UuV;@A$PtE6rjGKcU{5W zJ8PqFD;ko-`Xf~eB3@4Vj*VR`B$kDLtn5jtJzgHQC4``JgBJGJQDI!ClT4PTYbi3E z%Fe!tn2P?qa;92&f=_UgJ)5wiTB}YDL;K>NWO#Sg*CFk0kE=Y3`K;e6&(|rHyd(@D zLp74fMQ+K8rr2YjFt+UaSCrx5s3Wu7~rEk+qVyJo^{;H*6@H`~?x8=iQio zq?XN3zV#PP+XuSqSo&7NX7q>v#QtWHn+MSnPQ_uK(%Bn35wsURDC=U>#=^>M@sAWg zC?Uh`o(9@%Mj-T-RQRFUl*IWr$Ys&~g`SW0?T^Btt1oj_QV#=2bk^`uRru#cgST7K z49$~*NeAKwCXqhDcaFqB#+Gfp=TmP+)5I|<;n=5xV0i@?e%8S7p(F8JdSi$@)f?&XlCfmRB8I)XzwJyopct{8hr>~(%n<`DoVT&(~LR$N7> z7mpk=G8=_`&egC!?2GxuTAy^IxX0Lq5UD5AdK|0;x%1koZ2WRvPX=5V zH-cb@^Nvf7TLaDevn*&wESkj=eVNGH6g&0I(&*Y37^zZUXAms9|~~Ie-*5f7r4`cyLQ$U)W4b@0czf@>jqoW?kaLEX$q2+XN3hE zWI?>j0%#sl?t+po((Yb<6VA6ajbJ-!LI6>+oh@O`Y9jK>r}6~L2AIXOJGy;&5{PH@ zb013aYdo&T$`@(cL-w0e4vym=1eLTcags)ky;-LadtcJmH_(ts^-;qgM4M~p#+|4} zk&7=1OS%TU=N36;^2YYr{Bu?^x_3VB?7IG}AW3g|EF3WVwX;dnJ6L66tYWWiSP;e< z;g`8u{9s)jvadTk4;0>)R*26KV=6fkBK*R9g#{R{jv#zk0DGIWUXy1h91s&qy~nOu zKC9NF8y&QK2OJz~*rQMk_U4Nyck^r?U4^hd@Is!N3q^>k$A&3S;QL6s@8jlu^R);o z&}j^_m(~JnS@&b8@4U~O!MgwD#2QNPeI45t9v+L^MR9g@1oJt|)E$o3YSfxgL3j1t9q@VD!PYk~ zk#@g~J+j>bGuB1j38&TJBbIhTv(Mbh^$gyJO!;ZVFY@UaRO0NML~*H(fz51opB}Df zf9Qg+0N5)V1RcD+1n&&+JXRh!V8<7{aHKS>_2$I;0+;PY{Z&(!CyGJyzNr0KU?CCQ zeN!mm^wHUN!?8zx)&!J|%4N&b^#=|zSXs%6FzeF9mX9fFu<+)%xNfDChL{p&3ySW^pON|X!5`ulS|4?+D7JBZ7v!YrX%D}%?6 zKG2qR62p~QyLnjRD@sAo6dF@R{xmG&tJcYi*OPqeW*HU8(ARDJ!ii-oM8m33CMiSj3ESBRt?RdvAKi2WyRwnN%lqMv#HoaJoY_m3l27o zFT;j6ur_DApWRZ1nNq&hB6~t&ssm@Y7k+am7)(wUEm5EF;1p~`a6es)ovZ-=J~``K z>Z9}QiT8fT(Tw7PfuevMverP4XlLJbdZk_d9n{iMRcp!J<8PNG3yR(uIK-3pMWMS4 zs2LAzYtrz{yG2~Ld;fDWlH!V!e7Vo;yCY6xRAKC?@nZet<|Bp3=FdNZ<9To(uD42Z zz4Zv!TifFV%bNayn>)i?tV&?a#>amL3je79`)`L~SJ3Vr?E`v#PmovnX-MZzY&1_& z%igqvgTnk)r@;YN4vc=R1lcUiMV2f7YOV>~1zqAU@ddK^#3&!y3DOix{RZA?NhzyX z(XWhjlu_V@ z^BRo7FZJ%CSB0a}{QL0urkM4iizZf?B?G;~>`cptWttMb1x7(%-!XPtPFy?N9d}A` zqI0Zn_xZ6Pl`!EVq{Cr-k(KrSD`2IOr{naH#w7C# zmibaL(2MT&lE~P->J;DVb9s8`)^5jsa#6i)_OW+m@G>*FnNR-}&jk$_{)!{P&4eA+ zCK^CM#y*PMfeYNbn)Moa*|wf+*P;Mf`55n!MBd2tQ4G5NQAItA+U{pgOEk4RloA$A ztLKrH^l%QG5ecmj&ibWGKOXydfEv|J7nt3F7Z^heULz^3%X~Vug>lIAWuBwZySTpxR>x1f4BkwCL=(-55D`*xt~$-HFXYPV?#9SuIZ<7$MsUIW-8D zAV*Hw2;-W*l+Y{-o_S9tV275E*pURGy^2FQ4am?ZW7(7tqT5Hz+nU|L^qb9?oy$_b z80g?iJt`EGkX9W#Fo=3n1Ol?%FLuvLymbKW-!dB1Rje0okh}}$L zk2XVCfar-KYu)@(!3sTCPmETvTaFLbv^cIb-oGAPKWJe?@T?!bu;bV%S=%YpmnzkI zDltyxx7xhv>Ze(}UDpU`jr&5CcT^eCPIA{N##0MC8Q%$kNfy~It}f{QLFH3i&`H78 zBR8TDxhrS(n|0@(mPDd|`u_!!tO@Y7e_=dw)Bi3G6(i?{1is5(#5ZB8eN7?W>^nKt z_45evh1t}Cj#MAaDZzq?522HbgvYIN=bP^SMdPd{o(RtqzDj(QE6$~HN~ z8%3{`C)zsFTe0n9ZppV;Brt;TfA#of`f1V#k>@uYE$5 z?zE;D&a9fWxeKGLC6pu%rGyIz(m};uxd|O=O@qpV1Ca6B)6_d>9zy^AtQer|ppGz{9Hk;U=U%w*N{%w@Od*N<8F#Bqc;$1S+U`bPcu_@%aNW8V zWZ%-eOK7E+{USJ!@lIeWm#+xpsJ3QlPZ9&}wd@*sx`Uv$7&qkGX})2pub+-H61l`B zs;K#pBV7abBqQwQ(IPDkC6LaQVOKvLR~C7;q<`UZV7suuh}M6WN}W=epnsK(Uv1S& zE*;QXtIRj$o1;M&vpnQF$5XY~U#rw6zTOcQsP_0z;NCG1loVlaj5|FXFW_w$Q&$XN-5N~?Y{52j>H zN~EAqQWS^tY&?K&RnEpBEsio5QF-@PR9(#Mh_q+sLLWM7&#<4Vh7JhhvIA&Ie5u|B>8HjEjJH&Cl!2_BO4D z{cq=dFOkHVb}F;l0|l739pb|W2F*5e84l|0+cFs{X|fh&6SHERkhdic=F~wMlyVM@-n=2gZ=2xd-&LOQznxvW0rPm}GBW(c zpvLPtNo)!IqTc!b&D@Fzd!vU;VJvG<^6FL6xkhvk-&@;bQ|n7%XbIgTpVk~6lgrEU zx&&(tN+WSd+7ODZ(}emo)*i5ZMbqL{!p={w^0oR@jNiIEnc2ad3u{6zS~UjTrI_On zn95Ig(pu&ntyK&HY1-|6ERBf~yGpN}k#?gndUseRYu)dL9AxAjm-1QXL3^Gpgg5Ux z`3L9E%8anov3leG8;E%R*=RSV;>``jsovVLln_XczZ|o)QByrU; z=9w>6UkqpXiU}+v^n`ViH{`wXY0&}uMHF4R1qI&P#EH#5xr}P$q;6$ZZH`s#f?vm6 z^K&~1`PA7^Y*$OMP~llPQRxC0jvzJt@Rm=Qc)M@&-KXFBc6Sic2JCSXgWWf^H6w47 z{T-^8ckJ1&sY7nax{6p>QUT4g{=ubSW7~n9_8J3=gIr~%sPr{zFjY#X@x|lKspy_F zzC{)KqN*SBZ;MQ>FxjH=&_H!})gMQ?{L-tW7#R-z`#?(xP>B>Ijz$F7_3Kkag%nuCI{uPkqIX7Qc2w z=HvAjY;*`7gMwHU+suck+>Vc}JYns>%{ei5`XKlLQ5^f2G=E=~K=Lz_p0JdnYVSKi z6enM+Y@9dMwltzqP20P z#|o~@W;^CHmPZ|~2mBI9chIXztPVhSj6{p`RNwl{DBt$?8%8Uk))Klr4*qg1s$XQz zw(;wS)<_IQqy1XGssBj*0}FXn*Qe&Y8FE2e6TyAIal3Y*VZbVT(U~Q;m@g0|TxD!7 zR&StwJ|&G@1g?!NdEum-R~6SoudW(f+71>ZNOI45ucX8#eGLTN^TSIh$M#0m&m2N+ z^D>C#T60iRn$ZQK8jO232dZy&t?he~IwhX*3OU=8_~ts>rX89jRH{2V_RZe8s=nnq zZu}AccesB4s8)mIj9>}HNnt1;tSZ6?dCV`WDP8_T?1KuFTUXz8%NvBfqKLa~ zW1U$CZuIWWmaOd2a;dumRxykOY6IJf6k*hN5Kuk^J`J-=<03h?P}y59RZ#3utpbz6 z1jJE7g1NeP0@PlhOkg^S3)QA;vS>4Z)~5vN`Q1UCK03GH+4aF3lxd7`Z+%4HimQ8C zrG0PmwpzKJ$Zd}qC_g4Xcum#PUdqCLyfinbM8_r+djl_yuepi^g$I=zyt))>D?cn? zbtc~I*-kGnVvjqsFKKYd}9{Uvo|rBU7#u(wt(mtI!e*3uXE%yUwXAj0)VIKM%1opxHabLFiy$-52-OMx+t^jGnYs#K&+TGMO}TB$T+bHTsqwf zO7O|Wws+nO(}`57bzC*00WigdpD)zwiA?|2a!VavkrVDQ#i1WkkI<_&0t^ORw1p8_&RjH33-xtsMe>8ETXX}NFaU49G=k& zg`TJ7tU^D=?>csVc6#FMvzOc(QcW9PK*idj$zRdz}x`k2)qVns{rV3-=En{!u0 zpgH}781A8I{jZ@yvm&L$b0V2Tj{|H}Zdsll`>r3d?K7zjqXC|=KjRcrYYV7S4iU|* ze^n8Clep!V6ODI0&*UfzQMyY_-fdvZox^mh9Wk7MVqJE)uG;Uhyj`nZ_5=JIn?x0P zjQi^hMG$m1+;n}fG|^otg%_Y-4pi}J9e{6{@LY4gtRohHe1JWcH{iU;jZ~YO+;wIS z&}klMCDoFijp!MXc=uuHVxfMoovn$BJ~wEE7jOy8OD2I{sj-wp=-J;=(t_&gf^9 z-B$VG_GH>=W}HlXZQj6Yq$RiN;CkYZ)Z8hETRT$UM{x~MzvP7C{;w2Sq(mVK!^JDa z|5?@SpCXj!H3BaH-1&45hR%o$9#+akOby||Y~xR|P;UbHI}BUHG!y`39?23r2A2XVPw9)|qO;6-2*P!(E_;xZ?!+FY zm7EA_QCXp8Wbm5+Gw`DYO>nJ_TIdrye7#*hPA)O|X~TMrTUX(R*}6L+Flu*no;6-L z>Ba)?2AVq&W@0(aMVCnC?)_ZogjUk_tE7+b5t$T}h(01`*Qja|vOUEz0 zL|!zm1_4L=@>OAZPxWNo4|>EP+ESjy^AO{!&`MslM2R;xv>aXF?)*p;dT~m`%=Yqp zf@xvkLgav&{k5K@uD2U3Bph2i(kp<*^5(Sp1L}rR$V1Q)MVoa`#!{0`>v$F%!L%D& zK9iJeTjsRIsfh9CDtvB9JO=^4E@@@%d9>o{0QoG|mRuksk!Z|~uV8M&yn13 zom`D(`j-+%g;)BE_QLI00)VTv0izpSVG&R6Y2JnN0^J2NoUaKHKJvl=2eql4Y1y(J z5!>OhTlkZ~+T*Yck^gCZjpVD@u}|riz1n*bEwS-MtckH|6ur8~8P_qP_r0S#>1sZa z)fE)Mg-_?X?6UR!q`)mo;A}O-&uaSkPC9k$! zqZ!+sef;nRIT?eLJ;v?aj&?;e9yH8?NbgONn8SNT!P2oJ!_i76o{wecUXWD=|29~_ zi@#3#@22PUx(9y*s06qgy{Hezc|Sl;C8x={>vh08jnOBsI$Lmu)hy=DLJl>yIz*BiBeS6=lu;?>mWR$| zIhHfZQ^e|^opNx_hIwebH0=C5jM(hhY`Z^O$L+pew?BTr-}mYB{k%W#_viEbezX02 zJPq~D^dS(4p%>cS9|F+`0NeL;H-hiozrXzz{AgVA_dEjmsmB}uJ6e&h-mVZxZJxnu zgf`gMyNC|C1c4Z}uRR*9xXLr&7{bfl^+fXNIbJAZo2SOh52>Z8xl681_kSLjzO?j? z%Ak3>&73~>$jj^auGZ^p&XMP6?a2yXrytN3+rL4gafI2SOWzBgNX|R83>;jMmv6=s zTT4z6mFImdW$)%j8Vk4F>cm-v1|hV=i8y^b4TLr|ovMj(!D#HXpg~MF1*Gd`S-sTi zFb&uIf76_swnoMU0wW`Sb$9NT%&x2L9xwVgLl1|UcZNnbU8-|R5{6%fkEZ%v<2N02 z#500q3**kGkGkXYFFwsNdR-8-)ICKV!8IF!R)!La^rd9b19P=! z=FE7A_FNg!a%i;C8)Iy|XvYxG(Wyq;zUI7^KQVA4Y~qaPTWP@!-5gA31hn9@D}kZJ ze_RvPODaYT;9b@!Z}32K`?tsZl-d)Md1zh?Lun!c6=M&Y1}%ELckXi+7)ow;X37G=nS;Qj?uq4B8;7! zC?Go0fER4tDK<&(0FyB@Lels;rRUg|fWd)P#N44G|I26}9gC7p=s<&i zc;hQgC;^ZYlDtFTF5z!a8@P~j*z#T$Z?0sv_iX{faKu|;!?d35X`GkmEgjr(258fI zFvbR1wZtB$>dx;<%|sA z^Aew#5O?jQ^mr9j6CF>)0CGIu(LOH~dv&$GeU4C^`mh&ah$X*sOj&N^6$%Mlmc3y} zQX2_D8983Uja-!tlNjvyno%F+7^@u*Ak3V0+J(arhQs-fPqB?J9(*+-Yfn271?wuk zlzQcfk4Q)Ynt_HEIPXvD4Z-C0u-2n-em>=rMtFSW&?c_^KYw&Gb5#tF6Iy(b$o;H| z!D?muJ3kEP`Qw@DJUmh9x>w@8F)>!E9}C z%w~mk3g7-R7;8gOyj!IA;v--&j#IPy5!L9XV^vcVCHrXmGMi)C1A%BGc`&`k@H6%O zeI9^P%Eu-T!_pdFtc+uAx7@0DJK5^1XjtW@DZZlD7Z2g3%bsbcMq85hjA~Z;M)kFH zdtkG{(Sd3d>kF6GW1;(rn6Ve)#|JelgU`{y4MAVaF6Zb|d4LX1zmHKD_>3i@NKlj= z=_&UcrZaK@>9zqrC5q3j)iAD~#;3?zQLld&iaYD(k?HK9ZYU>ae`jBz#)fV88lsn} zZ3-dmeblo}tqUHlKyPe07W#11h%ZW7a5LwW>Ub&jN?GQ2SGJWE`n63Ar?{)7WXO3u_vUWh&4j|S_o zm}6otTQaAMpAJGj59q&g(hHZst=ZIExv_7cJVCc+AE~+-21fH0Q~piv-pH_`jjSx*YUBoTYc;kL$N9(t6FMkqSAh?m1Hs%^AaF3{Zm%i=1hU zHhH``rBT`vrAT5Y6CZ$?GCLi4JwsmSP4^Fcoe&KVu7t>|@&FrVyoc@@i8%e=Dv`83 zW2OORrUQqoK!5KUou-vo75xTra-?e98lfF^0>%;i*W{K1Do3RP z$SX3*4U-|gzeX{V$WMyb@?(JH!#LP%D?g@62727Po2u2vFdAn4EK$+Sx}0yt#_x5@ zPOEVEVom;n&UQbSt7OPi^hVw>3hSwyQX?Im=Vs#VkUg(pO8z1EfsC%Ni9hFvjO zb#j1M$O12f_H^*@8u(dPOd3?R{ytUH9wehN&6?&SKNf09gHW8a02?*vY%7<4OR3}; zxEkK!ETHRuCIT=S&VIvHAS8aF+T)i2={LZ`t_-vSN%%O~ackYm4Lk+?NEqYN zG^xT_1F~#E>s`-$=5BRxs|fiWb-+fr=B!U?i^1v7X0U_SP%5aWQ+9u Date: Tue, 17 Nov 2020 14:10:32 +0200 Subject: [PATCH 12/14] Update configure-server-endpoints.md Clarifications to avoid customer confusion about requirements when onboarding via Azure Defender for Servers. We've had support cases where this was not clear enough and customer did not add the workspace configuration so onboarding never happened. --- .../microsoft-defender-atp/configure-server-endpoints.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md index 0af0c2d391..90716095ee 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md @@ -128,6 +128,10 @@ Once completed, you should see onboarded Windows servers in the portal within an After completing the onboarding steps, you'll need to [Configure and update System Center Endpoint Protection clients](#configure-and-update-system-center-endpoint-protection-clients). +> [!NOTE] +> For onboarding via Azure Defender for Servers (previously Azure Security Center Standard Edition) to work as expected, the server must have an appropriate workspace and key configured within the Microsoft Monitoring Agent (MMA) settings. Once configured, the appropriate cloud management pack is deployed on the machine and the sensor process (MsSenseS.exe) will be deployed and started. +> This is also required if the server is configured to use an OMS Gateway server as proxy. + ### Option 3: Onboard Windows servers through Microsoft Endpoint Configuration Manager version 2002 and later You can onboard Windows Server 2012 R2 and Windows Server 2016 by using Microsoft Endpoint Configuration Manager version 2002 and later. For more information, see [Microsoft Defender for Endpoint in Microsoft Endpoint Configuration Manager current branch](https://docs.microsoft.com/mem/configmgr/protect/deploy-use/defender-advanced-threat-protection). From ea1ec0d6d398d8c3a0b4c502ecf7d1f36a61f486 Mon Sep 17 00:00:00 2001 From: amirsc3 <42802974+amirsc3@users.noreply.github.com> Date: Tue, 17 Nov 2020 14:22:01 +0200 Subject: [PATCH 13/14] Update configure-server-endpoints.md minor edit for better readability --- .../microsoft-defender-atp/configure-server-endpoints.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md index 90716095ee..3e1ede3c5e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md @@ -128,9 +128,10 @@ Once completed, you should see onboarded Windows servers in the portal within an After completing the onboarding steps, you'll need to [Configure and update System Center Endpoint Protection clients](#configure-and-update-system-center-endpoint-protection-clients). -> [!NOTE] -> For onboarding via Azure Defender for Servers (previously Azure Security Center Standard Edition) to work as expected, the server must have an appropriate workspace and key configured within the Microsoft Monitoring Agent (MMA) settings. Once configured, the appropriate cloud management pack is deployed on the machine and the sensor process (MsSenseS.exe) will be deployed and started. -> This is also required if the server is configured to use an OMS Gateway server as proxy. +> [!NOTE] +> - For onboarding via Azure Defender for Servers (previously Azure Security Center Standard Edition) to work as expected, the server must have an appropriate workspace and key configured within the Microsoft Monitoring Agent (MMA) settings. +> - Once configured, the appropriate cloud management pack is deployed on the machine and the sensor process (MsSenseS.exe) will be deployed and started. +> - This is also required if the server is configured to use an OMS Gateway server as proxy. ### Option 3: Onboard Windows servers through Microsoft Endpoint Configuration Manager version 2002 and later You can onboard Windows Server 2012 R2 and Windows Server 2016 by using Microsoft Endpoint Configuration Manager version 2002 and later. For more information, see [Microsoft Defender for Endpoint From 69f1e8d666aa1c59bcf8252f0bda97fd8d9bdefe Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Tue, 17 Nov 2020 08:46:53 -0800 Subject: [PATCH 14/14] Update windows/security/information-protection/bitlocker/bitlocker-overview.md Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- .../information-protection/bitlocker/bitlocker-overview.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/security/information-protection/bitlocker/bitlocker-overview.md b/windows/security/information-protection/bitlocker/bitlocker-overview.md index fe5a483d05..551b239d72 100644 --- a/windows/security/information-protection/bitlocker/bitlocker-overview.md +++ b/windows/security/information-protection/bitlocker/bitlocker-overview.md @@ -74,7 +74,7 @@ The hard disk must be partitioned with at least two drives: - The operating system drive (or boot drive) contains the operating system and its support files. It must be formatted with the NTFS file system. - The system drive contains the files that are needed to load Windows after the firmware has prepared the system hardware. BitLocker is not enabled on this drive. For BitLocker to work, the system drive must not be encrypted, must differ from the operating system drive, and must be formatted with the FAT32 file system on computers that use UEFI-based firmware or with the NTFS file system on computers that use BIOS firmware. We recommend that system drive be approximately 350 MB in size. After BitLocker is turned on it should have approximately 250 MB of free space. -Fixed data volume or removable data volume cannot be marked as an active. +A fixed data volume or removable data volume cannot be marked as an active partition. When installed on a new computer, Windows will automatically create the partitions that are required for BitLocker. @@ -100,4 +100,3 @@ When installing the BitLocker optional component on a server you will also need | [Protecting cluster shared volumes and storage area networks with BitLocker](protecting-cluster-shared-volumes-and-storage-area-networks-with-bitlocker.md)| This topic for IT pros describes how to protect CSVs and SANs with BitLocker.| | [Enabling Secure Boot and BitLocker Device Encryption on Windows 10 IoT Core](https://developer.microsoft.com/windows/iot/docs/securebootandbitlocker) | This topic covers how to use BitLocker with Windows 10 IoT Core | -